To request an SSL certificate is now a SHA-2 Certificate Signing Request (CSR) is required. Using the MMC on a server environment or the certificate manager on a desktop environment allows you to generate a CSR with SHA-2 algorithm.

    1. Open the Local Machine Certificate Store on a server via the MMC (Start  →  Run →  MMC) or go on a desktop to C:\Windows\System32\certmgr.msc.
    2. Right-click on the Personal folder and select All tasks → Advanced operations → Create custom request.

    3. A window appears entitled  "Certificate Enrollment". Click Next.

    4. Leave everything at default and click  Next.  Note:  If you are requesting the certificate for TMG Server, you must  (No template) Legacy  choose.

    5. Click the button next to   Details, and then click Properties.

    6. In the tab  General  you type a  friendly name  in and go to the next tab.

    7. In the tab Subject enter the following data:

      Common name 
      Organization unit

      Click Add again before moving on to the next. When everything is added to the right side, go to the next tab.

    8. In the tab   Extensions, click the arrow to the right Extended Key Usage (application policies). When  Available  options, click  Server Authentication → Add. Do the same for  Client Authentication. Now go to the last tab.

    In the tab Private key, click the arrow to the right of Cryptographic Service Provider. Select only RSA, Microsoft Software Key Storage Provider. Under Key options, select Key size: 2048 and check Make private key exportable if you want to be able to export the certificate to a .pfx file. At Select Hash Algorithm you can indicate which algorithm should be used to encrypt the CSR. This is SHA1 by default, select SHA256 here.
    10. Click Apply → Ok.

    11. Click  Next. In the next screen, click  Browse ...  to select the location where the CSR should be saved and give the file a name (for example: CSR) and click  Save.

    12. Click Finish.

    13. Copy the entire contents of the created CSR,  including start and finish lines, and go to the order page on our website to order the certificate.

