Importing a wildcard certificate into the Personal store for the local computer

To import a wildcard certificate into the Personal store for the local computer

  1. Copy the file containing the exported wildcard certificate to the Microsoft Forefront Threat Management Gateway computer.

  2. Click Start, click Run, type mmc in the Open text box, and then click OK.

  3. In the Console1 window, click the File menu, and then click Add/Remove Snap-in.

  4. In the Add or Remove Snap-ins dialog box, select Certificates, and then click Add.

  5. On the Certificates snap-in page, select Computer account, and then click Next.

  6. On the Select Computer page, select Local computer, and then click Finish.

  7. In the Add or Remove Snap-ins dialog box, click OK.

  8. In the console tree, expand the Certificates (Local Computer) node. Right-click the Personal node, point to All Tasks, and then click Import.

  9. On the Welcome to the Certificate Import Wizard page, click Next.

  10. On the File to Import page, click Browse, and then locate and select the certificate file that you copied to the local Forefront TMG computer. Click Next after the selected file name appears in the File name text box.

  11. On the Password page, type the password that you assigned to the certificate file in the Password text box, and then select Mark this key as exportable.

  12. On the Certificate Store page, verify that Place all certificates in the following store is selected, and then click Next.

  13. On the Completing the Certificate Import Wizard page, click Finish.

  14. On the Certificate Import Wizard dialog box informing you that the import was successful, click OK.

  15. In the console tree, expand the Personal store, and then click Certificates.

  16. In the details pane, double-click the wildcard certificate. On the Certification Path tab, you should see the name of the certification authority (CA) that issued the certificate at the top of the list. If you do not, restart the Forefront TMG computer and open this snap-in. If the CA name does not appear at the top of the list, the root CA certificate is not installed in the Trusted Root Certification Authorities store. Because we installed an enterprise CA and the Forefront TMG computer is a member of the same domain as the enterprise CA, the root CA certificate should be automatically added to the Trusted Root Certification Authorities store.

  17. Expand the Trusted Root Certification Authorities store. In the details pane, you should see the name of the CA that issued the wildcard certificate.

  18. Close the MMC console and do not save the changes.

Note

After you successfully complete this procedure, the next task is to remove the wildcard certificate from the Web server on which it was obtained. For instructions, see Removing a wildcard certificate from a Web server.