﻿<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom">
  <channel>
    <title>Newest KB Articles</title>
    <description>Recent additions to the knowledge base from DiscountASP.NET</description>
    <link>https://kb.discountasp.net/kb/c0/root.aspx</link>
    <pubDate>Tue, 09 Jun 2026 15:05:48 GMT</pubDate>
    <generator>SmarterTrack Enterprise 100.0.9553</generator>
    <atom:link href="https://kb.discountasp.net/RSS.ashx?type=newestkbarticles" rel="self" type="application/rss+xml" />
    <item>
      <title>Purchasing an SSL certificate from a third-party provider</title>
      <link>https://kb.discountasp.net/kb/a1777/purchasing-an-ssl-certificate-from-a-third-party-provider.aspx</link>
      <pubDate>Fri, 27 Feb 2026 19:47:47 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1777</guid>
      <description>&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;' id="isPasted"&gt;Introduction&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;' id="isPasted"&gt;This article outlines the general steps for obtaining an SSL certificate from a third-party provider and installing it on your website using the control panel.&lt;span style="color:#404040;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;You will first generate a CSR (Certificate Signing Request) on your computer. This CSR is submitted to your chosen SSL provider. The CSR is required for the SSL Provider to issue your certificate. Once the certificate has been issued, you will export the certificate as a PFX file. You will then upload this PFX file to your control panel, where it can be used for installation on your site.&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;strong data-start="685" data-end="694" id="isPasted"&gt;NOTE:&lt;/strong&gt; We understand that some customers prefer to manage their SSL certificates independently. If you&amp;rsquo;re looking for a more streamlined process, you also have the option to &lt;a href="https://support.winhost.com/kb/a1775/order-an-ssl-certificate-through-winhost.aspx"&gt;purchase an SSL certificate through us&lt;/a&gt;. In most cases, we handle the setup and installation, which usually requires little to no action on your part.&lt;/p&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;What Is a CSR and Why Do I Need One?&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;A CSR (Certificate Signing Request) is a small file you generate on your computer. Think of it like a job application form. It contains information about your website and your company. When you want to buy an SSL certificate from a third-party provider (like GoDaddy, Namecheap, or another CA), they need this file from you in order to create your certificate.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Once they have your CSR, they will verify your information and issue your SSL certificate. You will then need to install that certificate. This guide walks you through the whole process, step by step.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;What You Will Need Before You Start&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;A Windows computer (Windows 10 or Windows 11 is fine).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;IIS (Internet Information Services) &amp;mdash; this is a free feature that comes with Windows. It is not turned on by default, but we will show you how to turn it on below.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;The domain name you want to secure (for example, www.yoursite.com).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Basic information about your company (name, city, state, country).&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 1 &amp;mdash; Turn On IIS (If You Have Not Already)&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;IIS is a built-in Windows feature that is usually turned off. Here is how to turn it on:&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click the &lt;strong&gt;Start&lt;/strong&gt; button (the Windows logo in the bottom-left corner of your screen).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Type &lt;strong&gt;Turn Windows features on or off&lt;/strong&gt; and click on it when it appears.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=499" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="3" style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In the list that appears, look for &lt;strong&gt;Internet Information Services&lt;/strong&gt;. Check the box next to it.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;OK&lt;/strong&gt; and wait for Windows to finish. This may take a couple of minutes.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=500" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: cornsilk; padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#8B6914;"&gt;Tip: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;If the box next to Internet Information Services is already checked, IIS is already installed and you can skip to Step 2.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 2 &amp;mdash; Open IIS Manager&lt;/h2&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click the &lt;strong&gt;Start&lt;/strong&gt; button and type &lt;strong&gt;IIS&lt;/strong&gt; or &lt;strong&gt;Internet Information Services Manager&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click on &lt;strong&gt;Internet Information Services (IIS) Manager&lt;/strong&gt; to open it.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=501" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 3 &amp;mdash; Create the Certificate Request (CSR)&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;This is where you generate the CSR file that you will send to the SSL certificate provider.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In IIS Manager, look at the left-hand side panel. Click on your &lt;strong&gt;computer&amp;#39;s name&lt;/strong&gt; (it will be at the very top of the list).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In the middle section, look for an icon called &lt;strong&gt;Server Certificates&lt;/strong&gt;. Double-click on it.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=502" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;div style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;ol start="3" style="margin-bottom:0in;list-style-type: decimal;"&gt;&lt;li style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="color:#404040;"&gt;On the right-hand side, click &lt;strong&gt;Create Certificate Request...&lt;/strong&gt; A window will open asking for your information.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=503" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Fill in each field as follows (do not worry &amp;mdash; it is just basic information about you and your website):&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border: 1pt solid rgb(204, 204, 204); background: rgb(213, 232, 240); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Field&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-image: initial; border-left: none; background: rgb(213, 232, 240); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;What to Enter&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Common Name&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The full domain name you want to secure. Example: www.yoursite.com. If you want a Wildcard certificate that covers all subdomains, use *.yoursite.com.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Organization&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The legal name of your business or organization. If you are an individual, you can use your full name.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Organizational Unit&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The department handling this. If you are unsure, you can type IT or just your company name again.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;City / Locality&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The city where your organization is located.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;State / Province&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Your state or province. Spell it out fully (example: California, not CA).&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Country&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The two-letter country code. For the United States, enter US.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=504" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="4" style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Next&lt;/strong&gt;. On the next screen, you will see a Cryptographic Service Provider and a Bit Length. Leave these settings as they are (the defaults are fine) and click &lt;strong&gt;Next&lt;/strong&gt; again.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;On the last screen, you will be asked to save the file. Click the &lt;strong&gt;...&lt;/strong&gt; button to choose where to save it. Save it somewhere easy to find, such as your Desktop. Name it something you will recognize, like &lt;strong&gt;&lt;em&gt;mysite_csr.txt&lt;/em&gt;&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Finish&lt;/strong&gt;. Your CSR file has been created and saved!&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=505" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: cornsilk; padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#8B6914;"&gt;Tip: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Do not delete or move this file after you save it. You will need it in the next step.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 4 &amp;mdash; Submit Your CSR to Your SSL Provider&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Now that you have your CSR file, it is time to purchase your SSL certificate from a third-party provider (such as GoDaddy, Namecheap, Comodo, or any other provider of your choice).&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Open the CSR file you saved in the previous step. You can do this by right-clicking the file and selecting &lt;strong&gt;Open with &amp;gt; Notepad&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;You will see a block of text that starts with &lt;strong&gt;-----BEGIN CERTIFICATE REQUEST-----&lt;/strong&gt; and ends with &lt;strong&gt;-----END CERTIFICATE REQUEST-----&lt;/strong&gt;. Select all of this text and copy it (Ctrl + A, then Ctrl + C).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Go to your SSL provider&amp;#39;s website and start the SSL certificate purchase process. When they ask for your CSR, paste the text you copied into the box they provide.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Complete the purchase and follow any verification steps your provider requires. They will email you when your certificate is ready.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: rgb(217, 232, 245); padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#1F6AA5;"&gt;Note: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Every SSL provider is a little different. If you are not sure where to paste the CSR, look for a step in their checkout or order process labeled &amp;#39;Enter CSR&amp;#39; or &amp;#39;Configure Certificate&amp;#39;.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 5 &amp;mdash; Complete the Certificate Installation in IIS&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Once your SSL provider emails you the certificate, you will need to complete the installation in IIS. This connects the certificate to the request you made earlier.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="margin-left: 28px ;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Save the certificate file your provider sent you to your computer (usually a .crt or .cer file).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Open IIS Manager again and go back to &lt;strong&gt;Server Certificates&lt;/strong&gt; (same as Step 2).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;On the right-hand side, click &lt;strong&gt;Complete Certificate Request...&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click the &lt;strong&gt;...&lt;/strong&gt; button to browse to the certificate file you saved. Give it a friendly name you will recognize (for example, &lt;strong&gt;&lt;em&gt;MySiteSSL&lt;/em&gt;&lt;/strong&gt;) and click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=506" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Your certificate is now installed in IIS. The next step is to export it as a PFX file so you can upload it to Winhost.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 6 &amp;mdash; Export the Certificate as a PFX File&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Winhost needs the certificate in a specific format called PFX (also known as PKCS#12). This file bundles your certificate together with its private key. Here is how to export it:&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="margin-left: 28px ;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In IIS Manager, go back to &lt;strong&gt;Server Certificates&lt;/strong&gt;. Find the certificate you just installed in the list.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click on it once to select it, then on the right-hand side click &lt;strong&gt;Export...&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Choose where to save the file and give it a name (for example, &lt;strong&gt;&lt;em&gt;mysite_certificate.pfx&lt;/em&gt;&lt;/strong&gt;). You will also be asked to create a password &amp;mdash; write this down, as you will need it when uploading to Winhost.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;OK&lt;/strong&gt;. Your PFX file is now saved on your computer.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=507" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 7 &amp;mdash; Upload the PFX to Winhost&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;The last step is to upload your PFX file to the Winhost Control Panel so it can be installed on your site.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="margin-left: 28px ;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Log in to your Winhost Control Panel and go to &lt;strong&gt;Sites &amp;gt; [your domain] &amp;gt; SSL Manager&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Upload PFX&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Browse for the PFX file you exported in Step 6 and enter the password you created for it.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Upload&lt;/strong&gt; to install the certificate on your site. That&amp;#39;s it!&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=513" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:6.0pt;margin-right:0in;margin-bottom:6.0pt;margin-left:0in;border:none;padding:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: rgb(217, 232, 245); padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#1F6AA5;"&gt;Note: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;After your certificate is installed, remember to set up a forced HTTPS redirect so visitors always use the secure version of your site. See the Force HTTPS with URL Rewrite knowledge base article for instructions.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: rgb(217, 232, 245); padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#1F6AA5;"&gt;Note: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;If you run into any trouble at any step, contact Winhost Support. Have your domain name and the step number from this guide ready &amp;mdash; it will help us assist you faster.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&amp;nbsp;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client Authentication Extended Key Usage (EKU)</title>
      <link>https://kb.discountasp.net/kb/a1772/client-authentication-extended-key-usage-eku.aspx</link>
      <pubDate>Sat, 07 Feb 2026 21:52:05 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1772</guid>
      <description>&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;' id="isPasted"&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;Overview&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Client Authentication Extended Key Usage (EKU)&lt;/span&gt;&lt;/strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;&amp;nbsp;is a certificate attribute that allows an SSL/TLS certificate to be used for &lt;strong&gt;client authentication&lt;/strong&gt;, most commonly in &lt;strong&gt;mutual TLS (mTLS)&lt;/strong&gt; scenarios.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;In mTLS, &lt;strong&gt;both sides authenticate each other&lt;/strong&gt;:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;The &lt;strong&gt;server&lt;/strong&gt; presents a server certificate&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;The &lt;strong&gt;client application&lt;/strong&gt; presents a client certificate containing the &lt;strong&gt;Client Authentication EKU&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;This is commonly used for:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Secure API integrations&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Partner gateways&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Financial and insurance systems&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Zero-trust architectures&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;&lt;br&gt;&lt;/span&gt;&lt;/div&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;What Is Client Authentication EKU?&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Extended Key Usage (EKU) defines &lt;strong&gt;what a certificate is allowed to be used for&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;The Client Authentication EKU is identified as:&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-size:13px;font-family:"Courier New";'&gt;1.3.6.1.5.5.7.3.2 &amp;nbsp;(Client Authentication)&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;A certificate containing this EKU can:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Identify a &lt;strong&gt;client application&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Be presented during the TLS handshake&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Be validated by the remote server as a trusted client&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Without this EKU, the certificate &lt;strong&gt;cannot be used for mTLS client authentication&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;Industry Change: Public SSL Certificates No Longer Support Client Authentication EKU&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Due to &lt;strong&gt;industry-wide security and browser root program changes&lt;/strong&gt;, &lt;strong&gt;public Certificate Authorities no longer issue SSL/TLS certificates that include Client Authentication EKU&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;This affects:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Sectigo&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;DigiCert&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;RapidSSL&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Other publicly trusted CAs&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;As a result:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Public website SSL certificates are now &lt;strong&gt;Server Authentication only&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Client Authentication EKU is &lt;strong&gt;no longer available&lt;/strong&gt; in public SSL certificates&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;IIS hosting providers cannot install or issue such certificates&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;This is expected behavior and &lt;strong&gt;not a hosting limitation&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;Supported Alternative: Private PKI Client Certificates&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;For mTLS and client authentication, the supported solution is to use a &lt;strong&gt;Private PKI client certificate&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:18px;font-family:"Times New Roman",serif;'&gt;Key differences&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" style="border-collapse: collapse; border: medium; width: 100%;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="border-width: 1pt 1pt 1.5pt;border-style: solid;border-color: rgb(153, 153, 153) rgb(153, 153, 153) rgb(102, 102, 102);border-image: none;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;text-align:center;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Public SSL&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="border-width: 1pt 1pt 1.5pt medium;border-style: solid solid solid none;border-color: rgb(153, 153, 153) rgb(153, 153, 153) rgb(102, 102, 102) currentcolor;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;text-align:center;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Private PKI Client Certificate&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153);border-image: none;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Website HTTPS&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153) currentcolor;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Application identity&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153);border-image: none;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Installed in IIS&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153) currentcolor;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Loaded by application code&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153);border-image: none;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Publicly trusted&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153) currentcolor;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Trusted by specific partner&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153);border-image: none;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;No clientAuth EKU&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(153, 153, 153) rgb(153, 153, 153) currentcolor;padding: 0in 5.4pt;vertical-align: top;"&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Includes clientAuth EKU&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;How to Use a Private PKI Client Certificate on Shared IIS Hosting&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;On shared IIS servers:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Certificates &lt;strong&gt;cannot&lt;/strong&gt; be installed into the Windows certificate store&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;IIS &lt;strong&gt;does not&lt;/strong&gt; manage outbound client certificates&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Instead, the certificate is used &lt;strong&gt;directly by the application&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;Recommended Setup&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:18px;font-family:"Times New Roman",serif;'&gt;1. Store the certificate securely&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Upload the &lt;strong&gt;PFX file&lt;/strong&gt; to a non-public folder such as:&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:0in;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-size:13px;font-family:"Courier New";'&gt;/App_Data/cert.pfx&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Ensure:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;The file is not web-accessible&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;The password is stored securely (config file, environment variable, or secret store)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:18px;font-family:"Times New Roman",serif;'&gt;2. Load the certificate in application code&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;The application loads the certificate &lt;strong&gt;only when making outbound HTTPS calls&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Example: .NET / ASP.NET (HttpClient)&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;pre class="prettyprint"&gt;using System.Net.Http;
using System.Security.Cryptography.X509Certificates;
var certPath = Server.MapPath(&amp;quot;~/App_Data/cert.pfx&amp;quot;);
var certPassword = &amp;quot;your-pfx-password&amp;quot;;
var clientCert = new X509Certificate2(
    certPath,
    certPassword,
    X509KeyStorageFlags.MachineKeySet
);
var handler = new HttpClientHandler();
handler.ClientCertificates.Add(clientCert);
using var client = new HttpClient(handler);
// Example API call
var response = await client.GetAsync(&amp;quot;https://api.partner.com/endpoint&amp;quot;);&lt;/pre&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;This:&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Sends the client certificate during the TLS handshake&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Enables mTLS authentication&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Requires no IIS configuration&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:18px;font-family:"Times New Roman",serif;'&gt;3. Partner establishes trust&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;The external system (e.g., API gateway):&lt;/span&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Registers the &lt;strong&gt;public portion&lt;/strong&gt; of the certificate&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Trusts inbound requests signed by that certificate&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Local &amp;ldquo;Not Trusted&amp;rdquo; warnings are &lt;strong&gt;expected&lt;/strong&gt; for Private PKI certificates.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;What You Do NOT Need to Do&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Segoe UI Emoji",sans-serif;'&gt;❌&lt;/span&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;&amp;nbsp;Do not install the certificate as a website SSL&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Segoe UI Emoji",sans-serif;'&gt;❌&lt;/span&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;&amp;nbsp;Do not add IIS bindings&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Segoe UI Emoji",sans-serif;'&gt;❌&lt;/span&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;&amp;nbsp;Do not replace your public HTTPS certificate&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Segoe UI Emoji",sans-serif;'&gt;❌&lt;/span&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;&amp;nbsp;Do not enable IIS client certificate authentication&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;&lt;br&gt;&lt;/span&gt;&lt;/div&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;strong&gt;&lt;span style='font-size:24px;font-family:"Times New Roman",serif;'&gt;Summary&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul type="disc" style="margin-bottom:0in;"&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Client Authentication EKU enables &lt;strong&gt;mTLS client identity&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Public SSL certificates no longer support this EKU&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;This is an &lt;strong&gt;industry-wide change&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;Private PKI client certificates are the correct solution&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;On shared IIS hosting, the certificate is loaded &lt;strong&gt;by application code&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;span style='font-family:"Times New Roman",serif;'&gt;IIS configuration is &lt;strong&gt;not required&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;br&gt;&lt;/p&gt;&lt;p style='margin-top:0in;margin-right:0in;margin-bottom:8.0pt;margin-left:0in;line-height:normal;font-size:16px;font-family:"Aptos",sans-serif;'&gt;&lt;br&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Known issues related to new EU Data Center Migration</title>
      <link>https://kb.discountasp.net/kb/a1771/known-issues-related-to-new-eu-data-center-migration.aspx</link>
      <pubDate>Fri, 19 Dec 2025 18:22:28 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1771</guid>
      <description>&lt;div id="isPasted"&gt;&lt;strong&gt;Known Issues After Migration to the New EU Data Center&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;SMTP connections to external mail servers&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;If your application sends email through an external SMTP server (that is, not using localhost) over port 25, you may encounter connection errors after migration.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;This occurs because our new data center provider blocks outbound port 25 traffic to help prevent spam abuse.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Resolution:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Update your application to use the SMTP Submission port instead.&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div&gt;Recommended port: 587&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;strong&gt;MIME type configuration errors&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;If your application defines MIME types in web.config without first removing existing entries, you may receive configuration errors.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;This happens because the new servers may already have the MIME type defined at the system level.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Resolution:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Modify your web.config to remove the MIME type before adding it.&lt;/div&gt;&lt;div&gt;Example: &amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;pre class="prettyprint"&gt;&amp;lt;remove fileExtension=".woff2" /&amp;gt; 
&amp;lt;mimeMap fileExtension=".woff2" mimeType="font/x-woff" /&amp;gt;&lt;/pre&gt;&lt;div&gt;&lt;code&gt;&lt;br&gt;&lt;/code&gt;&lt;/div&gt;&lt;p data-start="1040" data-end="1074" id="isPasted"&gt;&lt;strong&gt;MySQL ODBC driver compatibility&lt;/strong&gt;&lt;/p&gt;&lt;p data-start="1076" data-end="1211"&gt;If your ASP or ASP.NET application connects to a MySQL database using the MySQL ODBC driver, you may experience errors after migration.&lt;/p&gt;&lt;p data-start="1213" data-end="1421"&gt;The new servers use the MySQL ODBC 5.3 driver, while the previous servers may have used version 5.1 or 5.2. MySQL ODBC drivers do not support side-by-side installation, which can cause driver mismatch issues.&lt;/p&gt;&lt;p data-start="1423" data-end="1518"&gt;Resolution:&lt;br data-start="1434" data-end="1437"&gt;Update your database connection string to reference one of the following drivers:&lt;/p&gt;&lt;ul data-start="1520" data-end="1586"&gt;&lt;li data-start="1520" data-end="1555"&gt;&lt;p data-start="1522" data-end="1555"&gt;{MySQL ODBC 5.3 Unicode Driver}&lt;/p&gt;&lt;/li&gt;&lt;li data-start="1556" data-end="1586"&gt;&lt;p data-start="1558" data-end="1586"&gt;{MySQL ODBC 5.3 ANSI Driver}&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;pre id="isPasted"&gt;
&lt;/pre&gt;</description>
    </item>
  </channel>
</rss>