Ask a Question

Advanced Search

Solution ID : SO22090

Last Modified : 05/31/2019

Managed PKI for SSL - Installation Instructions for Microsoft Exchange 2013


This document provides instructions for installing SSL Certificates into Exchange 2013. If unable to use these instructions for your server, DigiCert recommends contacting Microsoft.

NOTE: To install a SSL certificate onto Microsoft Exchange 2013 using the Exchange Management Shell perform the steps located here.

This solution contains two Methods to install your SSL Certificate:

Method 1: Installing the certificate received via e-mail.

Method 2: Installing the certificate downloaded from Managed PKI for SSL subscriber service page.
Method 1: Download and Install SSL certificate sent via e-mail

Step 1: Obtain the SSL certificate sent via email:

  1. Once your Managed PKI for SSL administrator has approved your Certificate request, you will receive an email
    with the Certificate attached (cert.cer), as well as in the body of the email itself.
  2. Copy the SSL certificate and make sure to copy the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE-----
    header and footer. Ensure there are no white spaces, extra line breaks or additional characters.
  3. Use a plain text editor such as Notepad, paste the content of the certificate and save it with extension .txt 

    NOTE: If you selected Microsoft IIS  5.0 or above during enrollment, continue with the installation from here

  4. If you are not sure which server software was selected during the enrolment, proceed with Step 2 bellow.
Step 2: Download and Install the Intermediate CAs:
         To download and install the Intermediate CAs follow the steps from this link: SO22016
Step 3: Install the SSL certificate:
         To proceed with the installation steps for your SSL certificate click here

Method 2: Download and Install SSL certificate in PKCS#7 format

Step 1: Download the SSL certificate from Managed PKI for SSL subscriber services page:

         Download the certificate from Managed PKI for SSL subscriber services page by following the steps from this link: SO6621

         Make sure you download the certificate in PKCS#7 format and save it with the extension .txt or .p7b 


Step 2: Install SSL Certificate

  1. Go to Start > Administrative Tools > Internet Information Services (IIS) Manager.
  2. From the left menu, click the corresponding server name.
  3. In the Features pane (middle pane), under Security, double-click Server Certificates.
  4. From the Actions pane (right pane), select Complete Certificate Request.
  5. Provide the location of the certificate file and a friendly name.
    NOTE: The Friendly Name is a reference name for quick identification of the certificate for the Administrator.
    Be sure that the Personal store is selected, then click OK.


Step 3: Bind services to your certificate using Exchange Admin Center:

  1. Use Internet Explorer to browse to the Exchange Admin Center located at https://localhost/ecp
  2. Login using your domain credentials.
  3. Select Servers.
  4. Select Certificates.
  5. Select your certificate.

  6. Select the Edit icon.
  7. Select Services.
  8. Select the services you want to secure with your certificate.


Step 4:  Verify certificate installation:

  1. Verify your installation with the DigiCert Installation Checker
  2. In some rare cases, a restart of IIS or a reboot of the server may be necessary in order for the changes to take affect.