•  CSR is created from the correct machine [Not needed in most of the cases]
  • Always keep public and Private key file .pem. This will be used to convert the certificate in other formats.
  • If installing SSL on windows, convert crt to .p12 file using OpenSSL
  • Install the SSL on MMC
  • Install the root certificate too if provided in MMC.
  • In MMC, when adding the certificate set Checkbox for importing the private key.
  • Go to IIS, Open the settings/properties for application pool where application is running set LoadUserProfile to True.

