How To: Export an Installed Certificate and Its Private Key as a PFX File

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article covers exporting a certificate and its private key from the Windows Certificate Store as a single PFX (.pfx) file, for example to move the SecureAuth appliance certificate to another server. To combine a certificate and private key that already exist as two separate files into a PFX instead, see How To: Merge Separate Certificate and Private Key Files into a PFX.

     

    Export the Certificate Using the Certificates Console

    1. On the server, search for and open Certificates Console. If a warning prompt appears, click Yes.

    Windows search results showing the Certificates Console desktop app as the best match.

    1. Expand Personal > Certificates, and find the certificate to export — for example, the appliance's localhost certificate. Right-click it and choose All Tasks > Export...

    Certificates Console with a localhost certificate selected, right-click menu open showing All Tasks then Export.

    1. In the Certificate Export Wizard, click Next.
    2. Select Yes, export the private key and click Next.

    Certificate Export Wizard Export Private Key page with Yes, export the private key selected.

    1. On the Export File Format page, confirm Personal Information Exchange - PKCS #12 (.PFX) is selected, along with Include all certificates in the certification path if possible, Export all extended properties, and Enable certificate privacy. Click Next.

    Certificate Export Wizard Export File Format page with PKCS #12 (.PFX) selected and three checkboxes checked: include all certificates in the certification path, export all extended properties, and enable certificate privacy.

    1. On the Security page, check Password, then enter and confirm a password — a password is required because the private key is included. Click Next.

    Certificate Export Wizard Security page with the Password checkbox checked and a password entered in both the Password and Confirm password fields.

    1. Click Browse, choose a save location, and give the file a name — the name has no effect on the certificate itself. Click Save, then Next.

    Certificate Export Wizard File to Export page with the Save As dialog open, showing a file name entered and Personal Information Exchange (*.pfx) selected as the save type.

    1. Review the summary on the final page and click Finish.
    2. The exported .pfx file is now in the folder chosen in Step 7.

    File Explorer window showing the exported PFX file in the destination folder.

    1. Copy the PFX file to the target server. When importing it there, select Local Machine as the destination certificate store, and check Mark this key as exportable. This will allow you to back up or transport your keys at a later time. if the certificate may need to be exported again later.


     

    Special Considerations

    • The exported PFX file contains the certificate's private key — store it and its password with the same care as any other credential.
    • Use a password that can be remembered or securely recovered; the same password is required again when the PFX is imported into another certificate store.
    • Delete the PFX file from disk once it has been imported into the target certificate store, rather than leaving it in an unsecured location.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.