Install Supporting Certificates for Email, Client Authentication, and Document Signing on Windows 10

If you are having problems using one of’s Email, Client Authentication, and Document Signing certificates, it’s important to make sure that all necessary supporting (intermediate and root) certificates are installed on your system. This how-to will step you through retrieving these certificates and installing them in MMC on Windows 10.

Note: If you are using an certificate installed on a YubiKey or other secure token, it is still necessary to install these supporting certificates on your computer.

1. Log into your user account and navigate to your certificate order, then click the download link.



2. Find the certificate download by platform table, then click the download link for Other platforms.



3. Download the zip file.

Save file


4. Locate the zip file on your computer, then unzip it by right-clicking it and selecting Extract All… from the menu, then clicking the Extract button in the window that opens.

Extract All...


5. Open MMC on your computer. You can find it by typing “mmc” into the Windows search bar.

Open MMC


6. Choose File > Add/Remove Snap-in… from the menu.

File > Add/Remove Snap-in...


7. Select Certificates from the left-hand pane, then click the Add > button.

Select Certificates, then click Add button


8. Make sure Local Computer is selected, then click the Finish button.

Select Local Computer, then click Finish


9. Click the OK button to close the Add or Remove Snap-ins dialog box.

OK button


10. Select Certificates (Local Computer) from the left-hand pane.

Certificates (Local Computer)


11. Right-click Intermediate Certification Authorities, then select All Tasks > Import… from the menu.



12. The Certificate Import Wizard will open. Thick the Next button.

Next button


13. Click the Browse button.

Browse button


14. In the file open dialog, navigate to SSL_COM_CLIENT_CERTIFICATE_INTERMEDIATE_CA_RSA_R2.crt in the unzipped folder from step 4, above, and click the Open button.

Open intermediate certificate


15. Click the Next button.


16. Click the Next button again to accept the certificate store location.

Next button


17 Click the Finish button.

Finish button


18. Click the OK button.

OK button


19. Next, navigate to Trusted Root Certification Authorities > Certificates, and make sure that the following certificates are installed:

  • Certum Trusted Network CA
  • Root Certification Authority RSA (issued by
  • Root Certification Authority RSA (issued by Certum)

Trusted Root Certification Authorities


20. If any of these certificates are missing, right click on Trusted Root Certification Authorities > Certificates, select All Tasks > Import… from the menu, then repeat steps 12 to 18 for any missing root certificates:

  • For missing Certum root, install CERTUM_TRUSTED_NETWORK_CA.crt.
  • If either root is missing, install SSL_COM_ROOT_CERTIFICATION_AUTHORITY_RSA.crt.



21. Close MMC by selecting File > Exit from the menu.



22. Click the No button to dismiss the dialog box. Alternately, you can click Yes and create a filename to save your MMC settings for later use.

No button

Thank you for choosing! If you have any questions, please contact us by email at, call 1-877-SSL-SECURE, or just click the chat link at the bottom right of this page.