﻿<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom">
  <channel>
    <title>Newest KB Articles in SSL</title>
    <description>Recent additions to the knowledge base from Winhost</description>
    <link>https://support.winhost.com/kb/c264/ssl.aspx</link>
    <pubDate>Tue, 09 Jun 2026 22:05:58 GMT</pubDate>
    <generator>SmarterTrack Enterprise 100.0.9553</generator>
    <atom:link href="https://support.winhost.com/RSS.ashx?catid=264&amp;type=newestkbarticles" rel="self" type="application/rss+xml" />
    <item>
      <title>SSL Certificate Flow Chart - Quick Flow</title>
      <link>https://support.winhost.com/kb/a1778/ssl-certificate-flow-chart-quick-flow.aspx</link>
      <pubDate>Thu, 23 Apr 2026 00:10:42 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1778</guid>
      <description>&lt;!-- ============================================================
  Winhost Knowledge Base Article
  Title: Ordering an SSL Certificate on Winhost — Quick Flow Chart
  Per Frank's direction: high-level flowchart only.
  Full step-by-step with screenshots lives in the detailed KB article.
  SmarterTrack-ready: no SVG, no Unicode arrows, CSS-drawn triangles.
============================================================ --&gt;&lt;div style="font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,Helvetica,Arial,sans-serif;color:#2b2b2b;line-height:1.6;padding:10px;font-size:14px;max-width:960px;margin:0 auto;"&gt;&lt;h1 style="font-size:24px;color:#0a4d8c;border-bottom:3px solid #0a4d8c;padding-bottom:8px;margin:0 0 4px 0;font-weight:500;"&gt;Ordering an SSL Certificate on Winhost — Quick Flow&lt;/h1&gt;&lt;p style="color:#666;font-size:13px;margin:0 0 12px 0;"&gt;&lt;em&gt;Winhost &amp;gt; SSL&lt;/em&gt;&lt;/p&gt;&lt;div style="background:#eaf4ff;border-left:4px solid #0a4d8c;padding:10px 14px;border-radius:4px;margin:14px 0;"&gt;&lt;strong style="color:#0a4d8c;"&gt;The short version:&lt;/strong&gt; getting an SSL on your site is now just two choices - &lt;strong&gt;order an SSL Cert from us&lt;/strong&gt;, or &lt;strong&gt;upload a PFX you already own&lt;/strong&gt;. Either way, the certificate should be issued &lt;strong&gt;within 10 minutes&lt;/strong&gt;. No CSR to generate, no files to copy, no back-and-forth.&lt;/div&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;The flow at a glance&lt;/h2&gt;&lt;div style="display:flex;gap:8px;flex-wrap:wrap;margin:8px 0 12px 0;font-size:12px;"&gt;&lt;span style="background:#e6f4ea;border:1px solid #34a853;padding:3px 8px;border-radius:12px;"&gt;&lt;strong style="color:#1e7e34;"&gt;Green&lt;/strong&gt; = automatic / YES&lt;/span&gt; &lt;span style="background:#fff4d6;border:1px solid #e0a800;padding:3px 8px;border-radius:12px;"&gt;&lt;strong style="color:#8a6100;"&gt;Yellow&lt;/strong&gt; = you do it&lt;/span&gt; &lt;span style="background:#fde7e9;border:1px solid #d93025;padding:3px 8px;border-radius:12px;"&gt;&lt;strong style="color:#a82319;"&gt;Red&lt;/strong&gt; = NO / stop &amp;amp; read&lt;/span&gt; &lt;span style="background:#e8eaf6;border:1px solid #3f51b5;padding:3px 8px;border-radius:12px;"&gt;&lt;strong style="color:#283593;"&gt;Blue&lt;/strong&gt; = decision&lt;/span&gt;&lt;/div&gt;&lt;!-- ============================================================
    FLOW CHART - pure HTML with CSS-drawn triangle arrows
  ============================================================ --&gt;&lt;div style="background:#fff;border:1px solid #d6e4f0;border-radius:8px;padding:20px;"&gt;&lt;!-- START --&gt;&lt;div style="background:#0a4d8c;color:#fff;padding:14px 20px;border-radius:30px;font-size:18px;font-weight:bold;text-align:center;max-width:360px;margin:0 auto;"&gt;START: I need an SSL&lt;/div&gt;&lt;!-- big down arrow --&gt;&lt;div style="text-align:center;margin:14px 0;"&gt;&lt;div style="display:inline-block;width:0;height:0;border-left:18px solid transparent;border-right:18px solid transparent;border-top:26px solid #4a5568;"&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;!-- DECISION: Order or Upload PFX --&gt;&lt;div style="background:#e8eaf6;border:3px solid #3f51b5;border-radius:12px;padding:16px;text-align:center;max-width:620px;margin:0 auto;"&gt;&lt;div style="color:#283593;font-size:18px;font-weight:bold;"&gt;Go to SSL Manager. Pick one:&lt;/div&gt;&lt;div style="color:#555;font-size:13px;margin-top:4px;"&gt;These are the only two options. Choose whichever fits.&lt;/div&gt;&lt;/div&gt;&lt;!-- A / B branching lanes for Decision 2 --&gt;&lt;table style="width:100%;border-collapse:separate;border-spacing:12px 0;margin-top:14px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;!-- PATH A LANE --&gt;&lt;td style="width:50%;vertical-align:top;"&gt;&lt;div style="text-align:center;"&gt;&lt;div style="display:inline-block;background:#8a6100;color:#fff;padding:7px 18px;border-radius:22px;font-weight:bold;font-size:14px;"&gt;A — Order from Winhost&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align:center;margin:8px 0;"&gt;&lt;div style="display:inline-block;width:0;height:0;border-left:14px solid transparent;border-right:14px solid transparent;border-top:22px solid #8a6100;"&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background:#fff4d6;border:2.5px solid #e0a800;border-radius:10px;padding:12px;"&gt;&lt;div style="font-size:13px;line-height:1.8;"&gt;1. Click &lt;strong&gt;Order SSL Certificate&lt;/strong&gt;&lt;br&gt;2. Pick a type (RapidSSL, Wildcard, etc.)&lt;br&gt;3. Click &lt;strong&gt;Order SSL Certificate&lt;/strong&gt; to submit&lt;/div&gt;&lt;div style="background:#fff;border-left:3px solid #8a6100;padding:8px 10px;margin-top:10px;font-size:12px;color:#5a4100;line-height:1.5;"&gt;&lt;strong&gt;Note:&lt;/strong&gt; We will use &lt;strong&gt;HTTP validation&lt;/strong&gt; by default and fall back to &lt;strong&gt;DNS validation&lt;/strong&gt;.&lt;/div&gt;&lt;/div&gt;&lt;!-- arrow --&gt;&lt;div style="text-align:center;margin:10px 0;"&gt;&lt;div style="display:inline-block;width:0;height:0;border-left:12px solid transparent;border-right:12px solid transparent;border-top:18px solid #4a5568;"&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background:#e6f4ea;border:2.5px solid #34a853;border-radius:10px;padding:12px;text-align:center;"&gt;&lt;div style="color:#1e7e34;font-size:14px;font-weight:bold;"&gt;DigiCert verifies your domain&lt;/div&gt;&lt;div style="font-size:12px;margin-top:4px;"&gt;It's automatic. Should issue &lt;strong&gt;within 10 minutes&lt;/strong&gt;.&lt;/div&gt;&lt;div style="color:#1e7e34;font-size:12px;font-weight:bold;margin-top:4px;"&gt;You do nothing.&lt;/div&gt;&lt;/div&gt;&lt;!-- arrow --&gt;&lt;div style="text-align:center;margin:10px 0;"&gt;&lt;div style="display:inline-block;width:0;height:0;border-left:12px solid transparent;border-right:12px solid transparent;border-top:18px solid #4a5568;"&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background:#e6f4ea;border:2.5px solid #34a853;border-radius:10px;padding:12px;text-align:center;"&gt;&lt;div style="color:#1e7e34;font-size:15px;font-weight:bold;"&gt;Cert installed automatically&lt;/div&gt;&lt;div style="font-size:12px;margin-top:4px;"&gt;Confirmation email sent.&lt;/div&gt;&lt;/div&gt;&lt;!-- Verification-fail branch --&gt;&lt;div style="background:#fde7e9;border:2px solid #d93025;border-radius:8px;padding:10px;margin-top:14px;font-size:12px;"&gt;&lt;strong style="color:#a82319;"&gt;If verification fails:&lt;/strong&gt; that means we can't reach your domain (rare). You'll need to add a DNS TXT record yourself to finish. &lt;sup style="color:#a82319;"&gt;*&lt;/sup&gt;&lt;/div&gt;&lt;/td&gt;&lt;!-- PATH B LANE --&gt;&lt;td style="width:50%;vertical-align:top;"&gt;&lt;div style="text-align:center;"&gt;&lt;div style="display:inline-block;background:#8a6100;color:#fff;padding:7px 18px;border-radius:22px;font-weight:bold;font-size:14px;"&gt;B — Upload my own PFX&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align:center;margin:8px 0;"&gt;&lt;div style="display:inline-block;width:0;height:0;border-left:14px solid transparent;border-right:14px solid transparent;border-top:22px solid #8a6100;"&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background:#fff4d6;border:2.5px solid #e0a800;border-radius:10px;padding:12px;"&gt;&lt;div style="font-size:13px;line-height:1.8;"&gt;1. Click &lt;strong&gt;Upload SSL PFX File&lt;/strong&gt;&lt;br&gt;2. Choose your&amp;nbsp;&lt;strong&gt;.pfx&lt;/strong&gt; file&lt;br&gt;3. Enter the PFX &lt;strong&gt;password&lt;/strong&gt;&lt;br&gt;4. Click &lt;strong&gt;Upload&lt;/strong&gt;&lt;/div&gt;&lt;/div&gt;&lt;!-- arrow --&gt;&lt;div style="text-align:center;margin:10px 0;"&gt;&lt;div style="display:inline-block;width:0;height:0;border-left:12px solid transparent;border-right:12px solid transparent;border-top:18px solid #4a5568;"&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background:#e6f4ea;border:2.5px solid #34a853;border-radius:10px;padding:12px;text-align:center;"&gt;&lt;div style="color:#1e7e34;font-size:15px;font-weight:bold;"&gt;Cert installed&lt;/div&gt;&lt;div style="font-size:12px;margin-top:4px;"&gt;Takes a few moments. Confirmation email sent.&lt;/div&gt;&lt;/div&gt;&lt;div style="padding:10px;text-align:center;font-size:11px;color:#888;font-style:italic;margin-top:12px;"&gt;&lt;span style="font-size: 12px;"&gt;(No domain verification needed — the PFX is already a valid cert.)&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;!-- Merge label + big down arrow --&gt;&lt;div style="text-align:center;margin:20px 0 8px 0;"&gt;&lt;div style="display:inline-block;background:#f0f2f5;color:#666;padding:4px 14px;border-radius:12px;font-size:12px;font-style:italic;"&gt;both paths merge here&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align:center;margin:0 0 14px 0;"&gt;&lt;div style="display:inline-block;width:0;height:0;border-left:18px solid transparent;border-right:18px solid transparent;border-top:26px solid #4a5568;"&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;!-- FINAL STEP --&gt;&lt;div style="background:#fff4d6;border:3px solid #e0a800;border-radius:12px;padding:14px 18px;max-width:620px;margin:0 auto;text-align:center;"&gt;&lt;div style="color:#8a6100;font-size:17px;font-weight:bold;"&gt;Final step — Turn on the HTTPS redirect&lt;/div&gt;&lt;div style="color:#333;font-size:13px;margin-top:4px;"&gt;So no one lands on the old &lt;code&gt;http://&lt;/code&gt; version and sees “Not Secure” message&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;!-- Asterisk note per Frank's instruction --&gt;&lt;p style="background:#fde7e9;border-left:4px solid #d93025;padding:10px 14px;margin:16px 0;font-size:13px;"&gt;&lt;sup style="color:#a82319;font-weight:bold;"&gt;*&lt;/sup&gt; &lt;strong style="color:#a82319;"&gt;Reissue / DNS note:&lt;/strong&gt; if you handle DNS validation yourself, or if you reissue the certificate later, you will need to redo this verification step.&lt;/p&gt;&lt;!-- Link out to full detailed KB article --&gt;&lt;div style="background:#eaf4ff;border:1px solid #c5dcef;border-radius:6px;padding:12px 16px;margin:16px 0;font-size:14px;"&gt;&lt;strong style="color:#0a4d8c;"&gt;Want the full step-by-step with screenshots?&lt;/strong&gt; See the detailed article: &lt;a href="https://support.winhost.com/kb/a1775/order-an-ssl-certificate-through-winhost.aspx" style="color:#0a4d8c;"&gt;Order an SSL Certificate Through Winhost&lt;/a&gt;.&lt;/div&gt;&lt;!-- Tiny FAQ --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;Quick answers&lt;/h2&gt;&lt;table style="border-collapse:collapse;width:100%;margin-top:6px;font-size:13px;" class="fr-table-selection-hover"&gt;&lt;thead&gt;&lt;tr style="background:#0a4d8c;color:#fff;"&gt;&lt;th style="text-align:left;padding:8px;border:1px solid #0a4d8c;width:40%;font-weight:500;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Question&lt;/span&gt;&lt;/th&gt;&lt;th style="text-align:left;padding:8px;border:1px solid #0a4d8c;font-weight:500;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Answer&lt;/span&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;&lt;strong&gt;Do I need to do anything for domain validation?&lt;/strong&gt;&lt;/td&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;If the site is currently &lt;strong&gt;hosted with us&lt;/strong&gt;, OR if the &lt;strong&gt;DNS is pointing to our name servers&lt;/strong&gt;, you don't need to do anything — validation happens automatically.&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background:#f6f9fc;"&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;&lt;strong&gt;Do I need to generate a CSR?&lt;/strong&gt;&lt;/td&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;No. Winhost handles the CSR for you behind the scenes.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;&lt;strong&gt;How fast?&lt;/strong&gt;&lt;/td&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;DV certs should issue &lt;strong&gt;within 10 minutes&lt;/strong&gt;. OV/EV take 1–3 business days because DigiCert has to verify your organization.&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background:#f6f9fc;"&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;&lt;strong&gt;I already have a cert from someone else — can I use it?&lt;/strong&gt;&lt;/td&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;Yes. Use Option B and upload your &lt;code&gt;.pfx&lt;/code&gt; file.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;&lt;strong&gt;Does my site go down?&lt;/strong&gt;&lt;/td&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;No. It stays online the whole time.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;&lt;strong&gt;What is a PFX file?&lt;/strong&gt;&lt;/td&gt;&lt;td style="padding:8px;border:1px solid #d6e4f0;"&gt;A PFX file is a password-protected file that bundles a digital certificate, its private key, and any intermediate certificates into one package. It’s commonly used on Windows systems to secure SSL/TLS connections, sign code, and verify identities.&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;!-- ============================================================
  End of SmarterTrack-ready HTML.
============================================================ --&gt;</description>
    </item>
    <item>
      <title>Purchasing an SSL certificate from a third-party provider</title>
      <link>https://support.winhost.com/kb/a1777/purchasing-an-ssl-certificate-from-a-third-party-provider.aspx</link>
      <pubDate>Fri, 27 Feb 2026 19:47:47 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1777</guid>
      <description>&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;' id="isPasted"&gt;Introduction&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;' id="isPasted"&gt;This article outlines the general steps for obtaining an SSL certificate from a third-party provider and installing it on your website using the control panel.&lt;span style="color:#404040;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;You will first generate a CSR (Certificate Signing Request) on your computer. This CSR is submitted to your chosen SSL provider. The CSR is required for the SSL Provider to issue your certificate. Once the certificate has been issued, you will export the certificate as a PFX file. You will then upload this PFX file to your control panel, where it can be used for installation on your site.&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;strong data-start="685" data-end="694" id="isPasted"&gt;NOTE:&lt;/strong&gt; We understand that some customers prefer to manage their SSL certificates independently. If you&amp;rsquo;re looking for a more streamlined process, you also have the option to &lt;a href="https://support.winhost.com/kb/a1775/order-an-ssl-certificate-through-winhost.aspx"&gt;purchase an SSL certificate through us&lt;/a&gt;. In most cases, we handle the setup and installation, which usually requires little to no action on your part.&lt;/p&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;What Is a CSR and Why Do I Need One?&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;A CSR (Certificate Signing Request) is a small file you generate on your computer. Think of it like a job application form. It contains information about your website and your company. When you want to buy an SSL certificate from a third-party provider (like GoDaddy, Namecheap, or another CA), they need this file from you in order to create your certificate.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Once they have your CSR, they will verify your information and issue your SSL certificate. You will then need to install that certificate. This guide walks you through the whole process, step by step.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;What You Will Need Before You Start&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;A Windows computer (Windows 10 or Windows 11 is fine).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;IIS (Internet Information Services) &amp;mdash; this is a free feature that comes with Windows. It is not turned on by default, but we will show you how to turn it on below.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;The domain name you want to secure (for example, www.yoursite.com).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Basic information about your company (name, city, state, country).&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 1 &amp;mdash; Turn On IIS (If You Have Not Already)&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;IIS is a built-in Windows feature that is usually turned off. Here is how to turn it on:&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click the &lt;strong&gt;Start&lt;/strong&gt; button (the Windows logo in the bottom-left corner of your screen).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Type &lt;strong&gt;Turn Windows features on or off&lt;/strong&gt; and click on it when it appears.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=499" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="3" style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In the list that appears, look for &lt;strong&gt;Internet Information Services&lt;/strong&gt;. Check the box next to it.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;OK&lt;/strong&gt; and wait for Windows to finish. This may take a couple of minutes.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=500" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: cornsilk; padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#8B6914;"&gt;Tip: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;If the box next to Internet Information Services is already checked, IIS is already installed and you can skip to Step 2.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 2 &amp;mdash; Open IIS Manager&lt;/h2&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click the &lt;strong&gt;Start&lt;/strong&gt; button and type &lt;strong&gt;IIS&lt;/strong&gt; or &lt;strong&gt;Internet Information Services Manager&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click on &lt;strong&gt;Internet Information Services (IIS) Manager&lt;/strong&gt; to open it.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=501" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 3 &amp;mdash; Create the Certificate Request (CSR)&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;This is where you generate the CSR file that you will send to the SSL certificate provider.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In IIS Manager, look at the left-hand side panel. Click on your &lt;strong&gt;computer&amp;#39;s name&lt;/strong&gt; (it will be at the very top of the list).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In the middle section, look for an icon called &lt;strong&gt;Server Certificates&lt;/strong&gt;. Double-click on it.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=502" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;div style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;ol start="3" style="margin-bottom:0in;list-style-type: decimal;"&gt;&lt;li style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="color:#404040;"&gt;On the right-hand side, click &lt;strong&gt;Create Certificate Request...&lt;/strong&gt; A window will open asking for your information.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=503" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Fill in each field as follows (do not worry &amp;mdash; it is just basic information about you and your website):&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border: 1pt solid rgb(204, 204, 204); background: rgb(213, 232, 240); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Field&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-image: initial; border-left: none; background: rgb(213, 232, 240); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;What to Enter&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Common Name&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The full domain name you want to secure. Example: www.yoursite.com. If you want a Wildcard certificate that covers all subdomains, use *.yoursite.com.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Organization&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The legal name of your business or organization. If you are an individual, you can use your full name.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Organizational Unit&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The department handling this. If you are unsure, you can type IT or just your company name again.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;City / Locality&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The city where your organization is located.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;State / Province&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Your state or province. Spell it out fully (example: California, not CA).&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" style="width: 32.0513%; border-right: 1pt solid rgb(204, 204, 204); border-bottom: 1pt solid rgb(204, 204, 204); border-left: 1pt solid rgb(204, 204, 204); border-image: initial; border-top: none; padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Country&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" style="width: 67.9487%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(204, 204, 204); border-right: 1pt solid rgb(204, 204, 204); padding: 4pt 6pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;span style="font-size:13px;color:#404040;"&gt;The two-letter country code. For the United States, enter US.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=504" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="4" style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Next&lt;/strong&gt;. On the next screen, you will see a Cryptographic Service Provider and a Bit Length. Leave these settings as they are (the defaults are fine) and click &lt;strong&gt;Next&lt;/strong&gt; again.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;On the last screen, you will be asked to save the file. Click the &lt;strong&gt;...&lt;/strong&gt; button to choose where to save it. Save it somewhere easy to find, such as your Desktop. Name it something you will recognize, like &lt;strong&gt;&lt;em&gt;mysite_csr.txt&lt;/em&gt;&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Finish&lt;/strong&gt;. Your CSR file has been created and saved!&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=505" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: cornsilk; padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#8B6914;"&gt;Tip: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Do not delete or move this file after you save it. You will need it in the next step.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 4 &amp;mdash; Submit Your CSR to Your SSL Provider&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Now that you have your CSR file, it is time to purchase your SSL certificate from a third-party provider (such as GoDaddy, Namecheap, Comodo, or any other provider of your choice).&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Open the CSR file you saved in the previous step. You can do this by right-clicking the file and selecting &lt;strong&gt;Open with &amp;gt; Notepad&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;You will see a block of text that starts with &lt;strong&gt;-----BEGIN CERTIFICATE REQUEST-----&lt;/strong&gt; and ends with &lt;strong&gt;-----END CERTIFICATE REQUEST-----&lt;/strong&gt;. Select all of this text and copy it (Ctrl + A, then Ctrl + C).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Go to your SSL provider&amp;#39;s website and start the SSL certificate purchase process. When they ask for your CSR, paste the text you copied into the box they provide.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Complete the purchase and follow any verification steps your provider requires. They will email you when your certificate is ready.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: rgb(217, 232, 245); padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#1F6AA5;"&gt;Note: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;Every SSL provider is a little different. If you are not sure where to paste the CSR, look for a step in their checkout or order process labeled &amp;#39;Enter CSR&amp;#39; or &amp;#39;Configure Certificate&amp;#39;.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 5 &amp;mdash; Complete the Certificate Installation in IIS&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Once your SSL provider emails you the certificate, you will need to complete the installation in IIS. This connects the certificate to the request you made earlier.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="margin-left: 28px ;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Save the certificate file your provider sent you to your computer (usually a .crt or .cer file).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Open IIS Manager again and go back to &lt;strong&gt;Server Certificates&lt;/strong&gt; (same as Step 2).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;On the right-hand side, click &lt;strong&gt;Complete Certificate Request...&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click the &lt;strong&gt;...&lt;/strong&gt; button to browse to the certificate file you saved. Give it a friendly name you will recognize (for example, &lt;strong&gt;&lt;em&gt;MySiteSSL&lt;/em&gt;&lt;/strong&gt;) and click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=506" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Your certificate is now installed in IIS. The next step is to export it as a PFX file so you can upload it to Winhost.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 6 &amp;mdash; Export the Certificate as a PFX File&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;Winhost needs the certificate in a specific format called PFX (also known as PKCS#12). This file bundles your certificate together with its private key. Here is how to export it:&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="margin-left: 28px ;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;In IIS Manager, go back to &lt;strong&gt;Server Certificates&lt;/strong&gt;. Find the certificate you just installed in the list.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click on it once to select it, then on the right-hand side click &lt;strong&gt;Export...&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Choose where to save the file and give it a name (for example, &lt;strong&gt;&lt;em&gt;mysite_certificate.pfx&lt;/em&gt;&lt;/strong&gt;). You will also be asked to create a password &amp;mdash; write this down, as you will need it when uploading to Winhost.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;OK&lt;/strong&gt;. Your PFX file is now saved on your computer.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=507" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;h2 style='margin-top:14.0pt;margin-right:0in;margin-bottom:5.0pt;margin-left:0in;font-size:17px;font-family:"Arial",sans-serif;color:#1F6AA5;'&gt;Step 7 &amp;mdash; Upload the PFX to Winhost&lt;/h2&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:4.0pt;margin-right:0in;margin-bottom:4.0pt;margin-left:0in;'&gt;&lt;span style="color:#404040;"&gt;The last step is to upload your PFX file to the Winhost Control Panel so it can be installed on your site.&lt;/span&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;ol style="margin-left: 28px ;"&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Log in to your Winhost Control Panel and go to &lt;strong&gt;Sites &amp;gt; [your domain] &amp;gt; SSL Manager&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Upload PFX&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Browse for the PFX file you exported in Step 6 and enter the password you created for it.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#404040;"&gt;Click &lt;strong&gt;Upload&lt;/strong&gt; to install the certificate on your site. That&amp;#39;s it!&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;img src="/AvatarHandler.ashx?kbattchid=513" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:6.0pt;margin-right:0in;margin-bottom:6.0pt;margin-left:0in;border:none;padding:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: rgb(217, 232, 245); padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#1F6AA5;"&gt;Note: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;After your certificate is installed, remember to set up a forced HTTPS redirect so visitors always use the secure version of your site. See the Force HTTPS with URL Rewrite knowledge base article for instructions.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;margin-top:3.0pt;margin-right:0in;margin-bottom:3.0pt;margin-left:0in;'&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellspacing="0" cellpadding="0" width="624" style="width:6.5in;border-collapse:collapse;border:none;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" style="width: 100%; border: 1pt solid rgb(204, 204, 204); background: rgb(217, 232, 245); padding: 6pt 8pt; vertical-align: top;"&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&lt;strong&gt;&lt;span style="font-size:13px;color:#1F6AA5;"&gt;Note: &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:13px;color:#404040;"&gt;If you run into any trouble at any step, contact Winhost Support. Have your domain name and the step number from this guide ready &amp;mdash; it will help us assist you faster.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style='margin:0in;font-size:15px;font-family:"Arial",sans-serif;'&gt;&amp;nbsp;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Order an SSL Certificate Through Winhost</title>
      <link>https://support.winhost.com/kb/a1775/order-an-ssl-certificate-through-winhost.aspx</link>
      <pubDate>Wed, 25 Feb 2026 20:37:10 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1775</guid>
      <description>&lt;!-- ============================================================
  Winhost Knowledge Base Article
  Title: Order an SSL Certificate Through Winhost
  Updated per Frank's direction: no CSR generation step.
  Two paths only: (A) Order from Winhost or (B) Upload PFX.
  Styled to match the Quick Flow chart KB article.
============================================================ --&gt;&lt;div style="font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,Helvetica,Arial,sans-serif;color:#2b2b2b;line-height:1.6;padding:10px;font-size:14px;max-width:960px;margin:0 auto;"&gt;&lt;!-- OVERVIEW --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;Overview&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;Winhost makes ordering an SSL certificate simple. When you order through the Winhost Control Panel, everything is handled automatically. Just follow the steps below, and your certificate will typically be issued and installed within&lt;strong&gt;&amp;nbsp;10&amp;nbsp;&lt;/strong&gt;&lt;strong&gt;minutes&lt;/strong&gt;.&lt;/p&gt;&lt;div style="background:#eaf4ff;border-left:4px solid #0a4d8c;padding:10px 14px;border-radius:4px;margin:14px 0;"&gt;&lt;strong style="color:#0a4d8c;"&gt;Good to know:&lt;/strong&gt; you have two options for getting SSL on your site — &lt;strong&gt;(I) order a certificate from Winhost&lt;/strong&gt;, or &lt;strong&gt;(II) upload a PFX file&lt;/strong&gt; of an SSL certificate that you obtained elsewhere. You no longer need to generate a CSR yourself; Winhost handles that behind the scenes.&lt;/div&gt;&lt;!-- BEFORE YOU BEGIN --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;Before You Begin&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;You will need a &lt;strong&gt;Max plan or higher&lt;/strong&gt; to use SSL. If you are on a Basic plan, upgrade first:&lt;/p&gt;&lt;ol style="margin:6px 0 10px 22px;padding:0;"&gt;&lt;li style="margin:3px 0;"&gt;Log in to the Winhost Control Panel.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Go to &lt;strong&gt;Sites &amp;gt; [your domain] &amp;gt; Change Plan&lt;/strong&gt;.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Select &lt;strong&gt;Max or a higher plan&amp;nbsp;&lt;/strong&gt;and complete the upgrade.&lt;/li&gt;&lt;/ol&gt;&lt;!-- TWO OPTIONS SECTION --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;Your Two Options&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;Inside the SSL Manager you will see two choices. Pick whichever fits your situation:&lt;/p&gt;&lt;table style="width:100%;border-collapse:separate;border-spacing:12px 0;margin-top:10px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="width:50%;vertical-align:top;"&gt;&lt;div style="background:#fff4d6;border:2.5px solid #e0a800;border-radius:10px;padding:14px;height:100%;"&gt;&lt;div style="color:#8a6100;font-size:15px;font-weight:bold;margin-bottom:6px;"&gt;Option I — Order SSL from Winhost&lt;/div&gt;&lt;div style="font-size:13px;"&gt;Let Winhost buy and install the certificate for you. Best for most customers — takes about 10 minutes end-to-end.&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="width:50%;vertical-align:top;"&gt;&lt;div style="background:#fff4d6;border:2.5px solid #e0a800;border-radius:10px;padding:14px;height:100%;"&gt;&lt;div style="color:#8a6100;font-size:15px;font-weight:bold;margin-bottom:6px;"&gt;Option II — Upload a PFX&lt;/div&gt;&lt;div style="font-size:13px;"&gt;Already bought a certificate elsewhere? Upload your &lt;code&gt;.pfx&lt;/code&gt; file and we install it on your site.&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;!-- ============================================================
    OPTION A - ORDER FROM WINHOST
  ============================================================ --&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=518" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:28px 0 8px 0;font-size:18px;font-weight:500;"&gt;Option I — Order an SSL Certificate Through Winhost&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;In the Control Panel, go to &lt;strong&gt;Sites &amp;gt; [your domain] &amp;gt; SSL Manager&lt;/strong&gt;.&lt;/p&gt;&lt;ol style="margin:10px 0 10px 22px;padding:0;"&gt;&lt;li style="margin:4px 0;"&gt;Click &lt;strong&gt;Order a New SSL Certificate&lt;/strong&gt;.&lt;/li&gt;&lt;li style="margin:4px 0;"&gt;Select the type of SSL certificate you want (for example, &lt;strong&gt;RapidSSL&lt;/strong&gt; for a standard single-domain, or &lt;strong&gt;Wildcard&lt;/strong&gt; if you need to cover subdomains).&lt;/li&gt;&lt;li style="margin:4px 0;"&gt;Enter the common name (&lt;em&gt;your domain name or sub-domain name, for wildcard SSL Certificates, you must enter *.[domain name] without the []&lt;/em&gt;), organization name, organization unit, city/locality, state/province, and country.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=519" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;ol start="4" style="margin:10px 0 10px 22px;padding:0;"&gt;&lt;li style="margin:4px 0;"&gt;Review your admin contact information and confirm your &lt;strong&gt;Admin Email&lt;/strong&gt; address. This is where your SSL certificate details and renewal reminders will be sent — make sure it is correct.&lt;/li&gt;&lt;li style="margin:4px 0;"&gt;Click on &lt;strong&gt;Continue &amp;gt;&amp;gt;&amp;gt;&lt;/strong&gt; to review your information and then &lt;strong&gt;Order SSL Certificate&lt;/strong&gt; to submit your order.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=520" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div style="background:#e6f4ea;border-left:4px solid #1e7e34;padding:10px 14px;border-radius:4px;margin:14px 0;"&gt;&lt;strong style="color:#1e7e34;"&gt;That’s it on your end.&lt;/strong&gt; Winhost handles the CSR, sends the order to DigiCert, and installs the certificate automatically once DigiCert verifies your domain.&lt;/div&gt;&lt;!-- ============================================================
    DOMAIN VALIDATION
  ============================================================ --&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;&lt;span style="font-size: 20px;"&gt;BEHIND THE SCENE&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;Domain Validation&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;Before your SSL certificate can be issued, DigiCert (our certificate authority partner) needs to confirm that you own or control the domain. There are three ways this can happen — in most cases, it is fully automatic.&lt;/p&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;!-- Option 1 HTTP validation --&gt;&lt;div style="background:#e6f4ea;border:2.5px solid #34a853;border-radius:10px;padding:14px;margin:12px 0;"&gt;&lt;div style="color:#1e7e34;font-size:15px;font-weight:bold;margin-bottom:4px;"&gt;Option 1 — HTTP Validation (most common, fully automatic)&lt;/div&gt;&lt;p style="margin:6px 0 6px 0;"&gt;If your domain is already pointing to Winhost, HTTP validation is used by default. Here is what happens:&lt;/p&gt;&lt;ul style="margin:4px 0 6px 22px;padding:0;"&gt;&lt;li style="margin:3px 0;"&gt;Winhost automatically places a small hidden verification file on your site.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;DigiCert checks for that file to confirm you control the domain.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Your certificate is usually issued within &lt;strong&gt;2&lt;/strong&gt;&lt;strong&gt;0&amp;nbsp;&lt;/strong&gt;&lt;strong&gt;minutes&lt;/strong&gt;.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Once issued, the certificate is installed on your site automatically.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style="background:#eaf4ff;border-left:4px solid #0a4d8c;padding:10px 14px;border-radius:4px;margin:12px 0;font-size:13px;"&gt;&lt;strong style="color:#0a4d8c;"&gt;Note:&lt;/strong&gt; no action is needed from you for HTTP validation. The process is entirely automatic as long as your domain points to Winhost.&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=521" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;!-- Option 2 DNS auto --&gt;&lt;div style="background:#e6f4ea;border:2.5px solid #34a853;border-radius:10px;padding:14px;margin:12px 0;"&gt;&lt;div style="color:#1e7e34;font-size:15px;font-weight:bold;margin-bottom:4px;"&gt;Option 2 — DNS Validation (automated for Wildcard certificates or domains not yet pointing to Winhost)&lt;/div&gt;&lt;p style="margin:6px 0;"&gt;If you are ordering a Wildcard SSL certificate (e.g., &lt;code&gt;*.yourdomain.com&lt;/code&gt;), or if your domain is not yet pointing to Winhost, DNS validation is used instead. If your domain’s DNS is managed through Winhost, this is also fully automatic:&lt;/p&gt;&lt;ul style="margin:4px 0 6px 22px;padding:0;"&gt;&lt;li style="margin:3px 0;"&gt;Winhost automatically adds the required DNS validation record for you.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;DigiCert detects the record and verifies your domain.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Your certificate is issued and installed automatically, typically within&lt;strong&gt;&amp;nbsp;10 minutes&lt;/strong&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=522" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;!-- Option 3 DNS manual --&gt;&lt;div style="background:#fff4d6;border:2.5px solid #e0a800;border-radius:10px;padding:14px;margin:12px 0;"&gt;&lt;div style="color:#8a6100;font-size:15px;font-weight:bold;margin-bottom:4px;"&gt;Option 3 — DNS Validation, Manual (DNS hosted elsewhere) &lt;sup style="color:#a82319;"&gt;*&lt;/sup&gt;&lt;/div&gt;&lt;p style="margin:6px 0;"&gt;If your domain’s DNS is managed at a third-party provider (such as GoDaddy, Cloudflare, or another domain registrar), you will need to add a DNS record yourself:&lt;/p&gt;&lt;ol style="margin:4px 0 6px 22px;padding:0;"&gt;&lt;li style="margin:3px 0;"&gt;After placing your order, the Control Panel will display a &lt;strong&gt;DNS TXT record&lt;/strong&gt; value.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Log in to your DNS provider and add the TXT record shown in the control panel.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Once the record is added, DigiCert will automatically detect it (this may take several minutes to a few hours depending on your DNS provider).&amp;nbsp; Click on the &lt;strong&gt;Validate Now&lt;/strong&gt; button to complete to process.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;Your certificate will be issued and installed automatically once validation is complete.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=523" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div style="background:#eaf4ff;border-left:4px solid #0a4d8c;padding:10px 14px;border-radius:4px;margin:12px 0;font-size:13px;"&gt;&lt;strong style="color:#0a4d8c;"&gt;Note:&lt;/strong&gt; DNS changes can take time to propagate. If your certificate has not been issued after a few hours, contact Winhost Support for assistance.&lt;/div&gt;&lt;!-- ============================================================
    OV / EV
  ============================================================ --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;Organization Validated (OV) and Extended Validation (EV) Certificates&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;If you are ordering an OV or EV SSL certificate (such as TrueBiz or an EV certificate), there are additional manual verification steps required by DigiCert on top of the domain validation above:&lt;/p&gt;&lt;ul style="margin:4px 0 6px 22px;padding:0;"&gt;&lt;li style="margin:3px 0;"&gt;DigiCert will reach out to verify your organization’s details (name, address, phone number, etc.).&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;For EV certificates, DigiCert may call you directly to confirm your identity. The certificate will not be issued until you respond.&lt;/li&gt;&lt;li style="margin:3px 0;"&gt;This process is separate from domain validation and cannot be skipped.&lt;/li&gt;&lt;/ul&gt;&lt;div style="background:#fde7e9;border-left:4px solid #d93025;padding:10px 14px;border-radius:4px;margin:12px 0;font-size:13px;"&gt;&lt;strong style="color:#a82319;"&gt;Heads-up:&lt;/strong&gt; OV and EV certificates take longer to issue because of the additional manual review. Plan for at least &lt;strong&gt;1 to 3 business days&lt;/strong&gt;.&lt;/div&gt;&lt;!-- ============================================================
    OPTION B - UPLOAD PFX
  ============================================================ --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:28px 0 8px 0;font-size:18px;font-weight:500;"&gt;Option II — Upload Your Own PFX Certificate&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;If you already purchased an SSL certificate from another provider (or have one exported from another server), you can install it on your Winhost site by uploading a PFX file. No domain validation is needed on our side — the PFX is already a valid, signed certificate.&lt;/p&gt;&lt;ol style="margin:10px 0 10px 22px;padding:0;"&gt;&lt;li style="margin:4px 0;"&gt;In the Control Panel, go to &lt;strong&gt;Sites &amp;gt; [your domain] &amp;gt; SSL Manager&lt;/strong&gt;.&lt;/li&gt;&lt;li style="margin:4px 0;"&gt;Click &lt;strong&gt;Upload SSL PFX File&lt;/strong&gt;.&lt;/li&gt;&lt;li style="margin:4px 0;"&gt;Choose your &lt;strong&gt;.pfx&lt;/strong&gt; file from your computer.&lt;/li&gt;&lt;li style="margin:4px 0;"&gt;Enter the &lt;strong&gt;PFX password&lt;/strong&gt; (the password you set when the file was exported).&lt;/li&gt;&lt;li style="margin:4px 0;"&gt;Click &lt;strong&gt;Upload&lt;/strong&gt;.&lt;/li&gt;&lt;/ol&gt;&lt;div style="background:#e6f4ea;border-left:4px solid #1e7e34;padding:10px 14px;border-radius:4px;margin:14px 0;"&gt;&lt;strong style="color:#1e7e34;"&gt;Done in seconds.&lt;/strong&gt; Your certificate is installed on the site immediately and a confirmation email is sent.&lt;/div&gt;&lt;div style="background:#eaf4ff;border-left:4px solid #0a4d8c;padding:10px 14px;border-radius:4px;margin:12px 0;font-size:13px;"&gt;&lt;strong style="color:#0a4d8c;"&gt;Don’t have a PFX yet?&lt;/strong&gt; If your certificate provider gave you a &lt;code&gt;.cer&lt;/code&gt; or &lt;code&gt;.crt&lt;/code&gt; file plus a private key, you will need to combine them into a single &lt;code&gt;.pfx&lt;/code&gt; file before uploading. Contact Winhost Support if you need a hand.&lt;/div&gt;&lt;!-- ============================================================
    AFTER YOUR CERTIFICATE IS ISSUED
  ============================================================ --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;After Your Certificate Is Issued&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;Once your certificate is issued, Winhost receives a notification from DigiCert (or completes the PFX upload) and automatically installs the certificate on your site, you will receive a confirmation email when everything is in place.&lt;/p&gt;&lt;div style="background:#fff4d6;border:2.5px solid #e0a800;border-radius:10px;padding:14px;margin:14px 0;"&gt;&lt;div style="color:#8a6100;font-size:15px;font-weight:bold;margin-bottom:4px;"&gt;Final step — Turn on the HTTPS redirect&lt;/div&gt;&lt;p style="margin:4px 0;font-size:13px;"&gt;To avoid a “Not Secure” warning in browsers, enable a forced HTTPS redirect after installation. See the &lt;a href="https://support.winhost.com/kb/a1523/force-https-with-url-rewrite.aspx"&gt;&lt;strong&gt;Force HTTPS with URL Rewrite&lt;/strong&gt;&lt;/a&gt; knowledge base article for instructions.&lt;/p&gt;&lt;/div&gt;&lt;div style="background:#eaf4ff;border-left:4px solid #0a4d8c;padding:10px 14px;border-radius:4px;margin:12px 0;font-size:13px;"&gt;&lt;strong style="color:#0a4d8c;"&gt;Note:&lt;/strong&gt; if domain validation is not completed within 30 days, the validation token will expire and a new certificate order will need to be placed. Contact Winhost Support if you need help.&lt;/div&gt;&lt;!-- ============================================================
    RENEWING
  ============================================================ --&gt;&lt;h2 style="color:#0a4d8c;border-bottom:1.5px solid #d6e4f0;padding-bottom:4px;margin:22px 0 8px 0;font-size:18px;font-weight:500;"&gt;Renewing Your Certificate&lt;/h2&gt;&lt;p style="margin:6px 0;"&gt;SSL certificates must be renewed annually. You will receive a renewal reminder by email &lt;strong&gt;30 days before&lt;/strong&gt; your certificate expires. To renew, follow the same steps as ordering a new certificate through SSL Manager — the process is identical.&lt;/p&gt;&lt;div style="background:#eaf4ff;border-left:4px solid #0a4d8c;padding:10px 14px;border-radius:4px;margin:12px 0;font-size:13px;"&gt;&lt;strong style="color:#0a4d8c;"&gt;Note:&lt;/strong&gt; the &lt;strong&gt;Renew&lt;/strong&gt; button becomes available 30 days before expiration. If you receive a reminder but cannot see the button yet, wait a day or two and try again.&lt;/div&gt;&lt;!-- ============================================================
    REISSUE / SELF-DNS ASTERISK NOTE (per Frank)
  ============================================================ --&gt;&lt;p style="background:#fde7e9;border-left:4px solid #d93025;padding:10px 14px;margin:16px 0;font-size:13px;border-radius:4px;"&gt;&lt;sup style="color:#a82319;font-weight:bold;"&gt;*&lt;/sup&gt; &lt;strong style="color:#a82319;"&gt;Reissue / self-managed DNS note:&lt;/strong&gt; if you handle DNS validation yourself (Option 3 above), or if you &lt;strong&gt;reissue&lt;/strong&gt; the certificate later, you will need to redo the DNS TXT record verification step each time.&lt;/p&gt;&lt;/div&gt;&lt;!-- ============================================================
  End of SmarterTrack-ready HTML.
============================================================ --&gt;</description>
    </item>
    <item>
      <title>Obtaining a Multi-Domain Let’s Encrypt  Certificate</title>
      <link>https://support.winhost.com/kb/a1761/obtaining-a-multi-domain-lets-encrypt-certificate.aspx</link>
      <pubDate>Fri, 29 Aug 2025 16:02:56 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1761</guid>
      <description>&lt;h4&gt;While our site can have a primary domain and additional domains as the domain pointers pointing to it, only one SSL certificate can be installed per site. This is a stopping factor for those who need to point multiple domains to the same site and require all of them to be protected with https protocol. The only solution in this case it to purchase and install Multi-Domain certificate from some other SSL reseller as we do not resell Multi-Domain certificates.&lt;/h4&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;While the prices of Multi-Domain certificates can get very high, fortunately, there is a free Multi-Domain certificate we can obtain from Let’s Encrypt. The process of obtaining, approving, and installing Let’s Encrypt certificate manually can be tedious, confusing, and frustrating, but luckily for us, there are software called ACME clients that will simplify those tasks. For the purpose of this tutorial, I will use the following domain names all pointing to the same Winhost site:&lt;/div&gt;&lt;div&gt;&lt;br&gt;alaskafoxes.online – Primary Domain&lt;br&gt;alaskafoxes.shop – Domain Pointer&lt;br&gt;alaskafoxes.store – Domain Pointer&lt;/div&gt;&lt;div&gt;&lt;br&gt;All of the domains are using CloudFlare DNS Services. I will use &lt;a href="https://certifytheweb.com/"&gt;Certify The Web&lt;/a&gt; Desktop ACME client to obtain and manage Let’s Encrypt certificates. It will be connecting to the CloudFlare account and will create DNS entries to use DNS-01 Challenge validate the domain. It is important to note that this is the only challenge type that can be used to obtains Wildcard type certificate.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;All of my three domains are now using CloudFlare DNS services and A Records are pointing to my Winhost site, so I can go to the next step of obtaining &lt;strong&gt;Global API Key&amp;nbsp;&lt;/strong&gt;from my CloudFlare account. Login to your CloudFlare account and navigate to &lt;a href="https://dash.cloudflare.com/profile/api-tokens"&gt;API Tokens section&lt;/a&gt;. Click on &lt;strong&gt;View&amp;nbsp;&lt;/strong&gt;button next to &lt;strong&gt;Global API Key,&amp;nbsp;&lt;/strong&gt;enter your CloudFlare account password and press View button. Copy the Global API Key shown and save it to a secure place. This key with CloudFlare email address will be used by Certify the Web client to create DNS record required to obtain the certificate.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="1024" height="585" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_05-57-58-1024x585.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_05-57-58-1024x585.png 1024w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_05-57-58-300x171.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_05-57-58-768x439.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_05-57-58-400x228.png 400w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_05-57-58.png 1483w" sizes="(max-width: 1024px) 100vw, 1024px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now, let’s download and install &lt;a href="https://certifytheweb.com/home/download"&gt;Certify the Web desktop certificate manager / ACME client&lt;/a&gt; on a Windows machine.&lt;/div&gt;&lt;div&gt;When Certify the Web is installed, open it and go to &lt;strong&gt;Settings –&amp;gt; Certificate Authorities&lt;/strong&gt;. Select &lt;strong&gt;Let’s Encrypt&amp;nbsp;&lt;/strong&gt;option in &lt;strong&gt;Prefer Certificate Authority&amp;nbsp;&lt;/strong&gt;drop-down box and hit &lt;strong&gt;New Account&lt;/strong&gt; button&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="826" height="647" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-01-02.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-01-02.png 826w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-01-02-300x235.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-01-02-768x602.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-01-02-400x313.png 400w" sizes="(max-width: 826px) 100vw, 826px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Select &lt;strong&gt;Let’s Encrypt&amp;nbsp;&lt;/strong&gt;from &lt;strong&gt;Certificate Authority&amp;nbsp;&lt;/strong&gt;drop-down box, enter your email address, agree to the terms, and hit &lt;strong&gt;Register Contact&amp;nbsp;&lt;/strong&gt;button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="591" height="467" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-05-49.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-05-49.png 591w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-05-49-300x237.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-05-49-400x316.png 400w" sizes="(max-width: 591px) 100vw, 591px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Let’s Encrypt account was registered successfully, and is shown on &lt;strong&gt;Settings –&amp;gt; Certificate Authorities&lt;/strong&gt; page&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="820" height="642" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-10-19.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-10-19.png 820w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-10-19-300x235.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-10-19-768x601.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-10-19-400x313.png 400w" sizes="auto, (max-width: 820px) 100vw, 820px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now let’s connect our client to CloudFlare: go to &lt;strong&gt;Settings –&amp;gt; Stored Credentials –&amp;gt; Add New Stored Credentials&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="818" height="404" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-16-56.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-16-56.png 818w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-16-56-300x148.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-16-56-768x379.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-16-56-400x198.png 400w" sizes="auto, (max-width: 818px) 100vw, 818px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;On the Add/Update Store Credential page, select &lt;strong&gt;CloudFlare DNS API&lt;/strong&gt; from &lt;strong&gt;Credential Type&lt;/strong&gt; drop-down box, enter the name for your credentials such as CF, and paste you &lt;strong&gt;Global API Key&lt;/strong&gt; you obtained earlier in &lt;strong&gt;Auth Key&lt;/strong&gt; filed. Enter the email address of your CloudFlare account in &lt;strong&gt;Email Address&amp;nbsp;&lt;/strong&gt;filed. Hit&lt;strong&gt;&amp;nbsp;Save&lt;/strong&gt; once done.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="783" height="797" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-08-42.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-08-42.png 783w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-08-42-295x300.png 295w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-08-42-768x782.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-08-42-50x50.png 50w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-08-42-400x407.png 400w" sizes="auto, (max-width: 783px) 100vw, 783px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now let’s create another stored credential to store a password that will be used to protect PFX file of the certificate. We will use this password to import PFX file to Winhost site. &amp;nbsp;Hit &lt;strong&gt;Add New Stored Credentials&amp;nbsp;&lt;/strong&gt;button again and in &lt;strong&gt;Credential Type&amp;nbsp;&lt;/strong&gt;drop-down box select &lt;strong&gt;Password.&lt;/strong&gt; Give the stored credential a name such as &lt;em&gt;PFX Password&lt;/em&gt;, enter the desired password, and hit &lt;strong&gt;Save&amp;nbsp;&lt;/strong&gt;button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="983" height="802" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-16-12.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-16-12.png 983w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-16-12-300x245.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-16-12-768x627.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-16-12-400x326.png 400w" sizes="auto, (max-width: 983px) 100vw, 983px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now go to &lt;strong&gt;Managed Certificates&lt;/strong&gt; section and hit &lt;strong&gt;New Certificate&lt;/strong&gt; button&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="826" height="647" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-34-25.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-34-25.png 826w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-34-25-300x235.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-34-25-768x602.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-34-25-400x313.png 400w" sizes="auto, (max-width: 826px) 100vw, 826px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now let’s add all common names to the certificate we would like to protect. There will be three wildcard common names and three “naked” domains, i.e. this certificate will protect all domains, and all their sibdomains: everything. I will need to add the following entries:&lt;br&gt;alaskafoxes.online&lt;br&gt;*.alaskafoxes.online&lt;br&gt;alaskafoxes.shop&lt;br&gt;*.alaskafoxes.shop&lt;br&gt;alaskafoxes.store&lt;br&gt;*.alaskafoxes.store&lt;/div&gt;&lt;div&gt;I will start pasting those entries one by one in &lt;strong&gt;Add domains to certificate&amp;nbsp;&lt;/strong&gt;field and hitting “&lt;strong&gt;+&lt;/strong&gt;” button to add them until I have them all listed as shown on the next screen shot. I decided to set *.alaskafoxes.online as my primary domain under &lt;strong&gt;Primary&amp;nbsp;&lt;/strong&gt;column. When adding wildcard common name the message warns you that you need to setup DNS challenge for that type of certificate which will do later on.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="956" height="703" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-51-16.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-51-16.png 956w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-51-16-300x221.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-51-16-768x565.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-51-16-400x294.png 400w" sizes="auto, (max-width: 956px) 100vw, 956px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Navigate to &lt;strong&gt;Advanced&amp;nbsp;&lt;/strong&gt;section and select &lt;strong&gt;Let’s Encrypt&lt;/strong&gt; from Certificate Authority drop-down box&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="994" height="698" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-55-06.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-55-06.png 994w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-55-06-300x211.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-55-06-768x539.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-21_17-55-06-400x281.png 400w" sizes="auto, (max-width: 994px) 100vw, 994px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Navigate to &lt;strong&gt;Signing &amp;amp; Security&amp;nbsp;&lt;/strong&gt;page, scroll down &lt;strong&gt;Security&amp;nbsp;&lt;/strong&gt;section, and select PFX Password that we created earlier from the drop-down box .&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="988" height="965" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-25-23.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-25-23.png 988w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-25-23-300x293.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-25-23-768x750.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-25-23-50x50.png 50w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_06-25-23-400x391.png 400w" sizes="auto, (max-width: 988px) 100vw, 988px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Next, go to &lt;strong&gt;Authorization&amp;nbsp;&lt;/strong&gt;section and in &lt;strong&gt;Challenge Type&amp;nbsp;&lt;/strong&gt;drop-down box select &lt;strong&gt;dns-01.&amp;nbsp;&lt;/strong&gt;Select &lt;strong&gt;CloudFlare DNS API&lt;/strong&gt; in&lt;strong&gt;&amp;nbsp;DNS Update Method&lt;/strong&gt; drop-down box. Select CF credential that we created earlier in &lt;strong&gt;Credentials&lt;/strong&gt; drop-down box. Click on “&lt;strong&gt;…&lt;/strong&gt;” button next to&lt;strong&gt;&amp;nbsp;DNS Zone Id&lt;/strong&gt; filed. The domains of your CloudFlare accounts will be populated in the DNS Zone Id filed. I am selecting my first domain, alaskafoxes.online. It will be replaced with a Zone Id identifier. Since DNS propagation takes time, the default 60 seconds is not enough. I will increase it to 600 seconds. Hit Add Configuration button.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="933" height="938" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41.png 933w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41-298x300.png 298w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41-150x150.png 150w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41-768x772.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41-50x50.png 50w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41-400x402.png 400w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-08-41-200x200.png 200w" sizes="auto, (max-width: 933px) 100vw, 933px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;When you hit Add Configuration button, in the configuration above that we just filled out there additional text box appears called&amp;nbsp;&lt;strong&gt;Domain Match&lt;/strong&gt;. The software hides this filed initially not to confuse the users as most of the users are ordering certificate for one domain. However, when Muti-Domain certificate is ordered, we will need to enter the exact common names separated by a semicolon. So go back to Authorization Settings of the first domain, alaskafoxes.online and enter the following in Domain Match text field:&lt;br&gt;*.alaskafoxes.online;alaskafoxes.online&lt;br&gt;Verify the configuration for the first domain, and scroll down to the configuration section of the next domain&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="928" height="998" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-48-41.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-48-41.png 928w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-48-41-279x300.png 279w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-48-41-768x826.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_10-48-41-400x430.png 400w" sizes="auto, (max-width: 928px) 100vw, 928px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I will have the same configuration for next Authorization Settings for another domain, alaskafoxes.shop, except selecting &lt;strong&gt;DNS Zone Id&lt;/strong&gt; for alaskafoxes.shop and in&amp;nbsp;&lt;strong&gt;Domain Match&lt;/strong&gt; filed entering&lt;br&gt;*.alaskafoxes.shop;alaskafoxes.shop&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="923" height="1000" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-06-50.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-06-50.png 923w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-06-50-277x300.png 277w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-06-50-768x832.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-06-50-400x433.png 400w" sizes="auto, (max-width: 923px) 100vw, 923px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I will do the same for my last domain, alaskafoxes.store, adding the following in the Domain Match filed:&lt;br&gt;*.alaskafoxes.store;alaskafoxes.store&lt;/div&gt;&lt;div&gt;Now it is time to save changes by hitting &lt;strong&gt;Save&amp;nbsp;&lt;/strong&gt;button and then proceed with certificate request by pressing &lt;strong&gt;Request Certificate&lt;/strong&gt; button in the top-right corner.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="929" height="995" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-13-41.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-13-41.png 929w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-13-41-280x300.png 280w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-13-41-768x823.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-13-41-400x428.png 400w" sizes="auto, (max-width: 929px) 100vw, 929px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The certificate manager will create required TXT records in CloudFlare and will attempt to verify them in 10 minutes as we entered 600 seconds in Propagation Delay Seconds. If all information are entered correctly, the certificate will be issued and placed to the following directory on your machine:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;C:\ProgramData\certify\assets\&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;To verify the certificate was issued correctly and includes all domains, I will import / install that certificate on my local machine and check its subject alternative names&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="928" height="550" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-23-15.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-23-15.png 928w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-23-15-300x178.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-23-15-768x455.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-23-15-400x237.png 400w" sizes="auto, (max-width: 928px) 100vw, 928px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Everything looks correct, so I will proceed installing that certificate on my Winhost test account following the instructions in &lt;a href="https://support.winhost.com/kb/a1745/importing-an-ssl-certificate-from-a-pfx-file.aspx?manage=true"&gt;this article&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;The certificate was successfully installed. The site was assigned with an Unique IP address and all domains and subdomains are now protected.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;figure&gt;&lt;img width="1014" height="974" src="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-30-28.png" alt="" srcset="https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-30-28.png 1014w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-30-28-300x288.png 300w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-30-28-768x738.png 768w, https://blog.winhost.com/wp-content/uploads/2025/08/2025-08-22_11-30-28-400x384.png 400w" sizes="auto, (max-width: 1014px) 100vw, 1014px" class="fr-fic fr-dii"&gt;&lt;/figure&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The Certify the Web certificate manager will display the list of the current certificates and their expiration date.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=450" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The certificate will be renewed automatically by the certificate manager. All you need to do after the certificate renewal is to grab PFX file of the new certificate and install it on your Winhost site. The renewal settings tells when the certificate renewal will take place. By default, the renewal mode is set to 75% of the certificate lifespan. Therefore, if Let's Encrypt certificate is being issued for 90 days, then the renewal will occur on the day 63 from the date when the certificate was issued.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=451" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;</description>
    </item>
    <item>
      <title>CloudFlare SSL Support</title>
      <link>https://support.winhost.com/kb/a1755/cloudflare-ssl-support.aspx</link>
      <pubDate>Fri, 23 Aug 2024 22:04:39 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1755</guid>
      <description>&lt;div&gt;If you are routing your DNS through CloudFlare, you can enable SSL support by logging into your CloudFlare account, selecting the site, and then SSL/TLS. &amp;nbsp;Checking "Flexible" is the easiest way to add SSL support for your site. &amp;nbsp;When checking this option, make sure you remove any SSL redirects on your site, otherwise, you'll create an infinite loop.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=416" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;</description>
    </item>
    <item>
      <title>Exporting an SSL Certificate to a PFX file</title>
      <link>https://support.winhost.com/kb/a1746/exporting-an-ssl-certificate-to-a-pfx-file.aspx</link>
      <pubDate>Sat, 13 Apr 2024 05:25:58 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1746</guid>
      <description>&lt;div&gt;In cases where a certificate is installed on a local Windows machine, the certificate export can be performed with Microsoft Management Console (MMC).&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;1. Enter &lt;strong&gt;mmc&lt;/strong&gt; in the Search bar and then select &lt;strong&gt;Run as administrator&lt;/strong&gt;. &amp;nbsp;(&lt;em&gt;For older versions of Windows, click on the Start menu and then Run. &amp;nbsp;Enter &amp;quot;mmc&amp;quot; and click OK.&lt;/em&gt;) &amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=392" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;2. Click on the &lt;strong&gt;File&lt;/strong&gt; menu and then &lt;strong&gt;Add/Remove Snap-in...&lt;/strong&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=393" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;3. Select &lt;strong&gt;Certificates&lt;/strong&gt; and then click on the &lt;strong&gt;Add &amp;gt;&lt;/strong&gt; button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=394" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;4) Check &lt;strong&gt;Computer account&lt;/strong&gt; and then click on&lt;strong&gt;&amp;nbsp;Next &amp;gt;&lt;/strong&gt;.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=395" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;5. Check &lt;strong&gt;Local computer&lt;/strong&gt; and then click on &lt;strong&gt;Finish&lt;/strong&gt;. &amp;nbsp;Click on &lt;strong&gt;OK&lt;/strong&gt; to finish adding the snap-in.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=396" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;6. Expand the &lt;strong&gt;Certificates (Local Computer)&lt;/strong&gt; folder, then &lt;strong&gt;Personal&lt;/strong&gt;, and click on &lt;strong&gt;Certificates&lt;/strong&gt;.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=409" style="width: 2268px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;7. In the middle pane, &lt;strong&gt;right click&lt;/strong&gt; on the SSL Certificate, select &lt;strong&gt;All Tasks&lt;/strong&gt;, and then &lt;strong&gt;Export...&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=410" style="width: 2268px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;8. This will launch the Certificate Export Wizard. &amp;nbsp;Click on the &lt;strong&gt;Next&amp;nbsp;&lt;/strong&gt;button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=399" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;9. Check &lt;strong&gt;Yes, export the private key&lt;/strong&gt; and then click on the &lt;strong&gt;Next&lt;/strong&gt; button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=400" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;10. Check &lt;strong&gt;Personal Information Exchange - PKCS #12 (.PFX)&lt;/strong&gt;, &lt;strong&gt;Include all certificates in the certification path if possible&lt;/strong&gt; and &lt;strong&gt;Enable certificate privacy&lt;/strong&gt;. &amp;nbsp;Click on the &lt;strong&gt;Next&lt;/strong&gt; button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=401" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;11. Check &lt;strong&gt;Password&lt;/strong&gt; and enter the password twice. &amp;nbsp;Click on the &lt;strong&gt;Next&lt;/strong&gt; button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=402" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;12. Enter the path and certificate name directly or use the &lt;strong&gt;Browse&lt;/strong&gt; button to find the path &lt;strong&gt;&lt;span style="color: rgb(65, 65, 65); font-family: sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;where you want to certificate saved&lt;/span&gt;&lt;/strong&gt; and then enter the filename. &amp;nbsp;Click on the &lt;strong&gt;Next&lt;/strong&gt; button to continue.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=407" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;12. &amp;nbsp;Click on the &lt;strong&gt;Finish&lt;/strong&gt; button to export and save the certificate. &amp;nbsp;You can then &lt;a href="https://support.winhost.com/kb/a1745/importing-an-ssl-certificate-from-a-pfx-file.aspx" rel="noopener noreferrer" target="_blank"&gt;import the SSL Certificate&lt;/a&gt; at Winhost.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=408" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;strong&gt;Additional Resources&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="https://www.digicert.com/kb/ssl-support/certificate-pfx-file-export-import-iis-10.htm" rel="noopener noreferrer" target="_blank"&gt;Exporting at DigiCert&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="https://www.godaddy.com/help/download-my-ssl-certificate-files-4754" rel="noopener noreferrer" target="_blank"&gt;Exporting at GoDaddy&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="https://www.sslshopper.com/how-to-move-or-copy-an-ssl-certificate-from-one-server-to-another.html" rel="noopener noreferrer" target="_blank"&gt;Exporting from Apache, Tomcat, or Java server&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;</description>
    </item>
    <item>
      <title>Importing an SSL Certificate from a PFX file</title>
      <link>https://support.winhost.com/kb/a1745/importing-an-ssl-certificate-from-a-pfx-file.aspx</link>
      <pubDate>Thu, 11 Apr 2024 00:30:39 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1745</guid>
      <description>&lt;div&gt;You can import an SSL Certificate from a .pfx file that was exported. &amp;nbsp;Make sure that the exported .pfx file is protected by a password.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;To get started:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Log into the control panel on Winhost.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div style='margin: 0px; padding: 0px; -webkit-tap-highlight-color: transparent; text-size-adjust: none; color: rgb(34, 34, 34); font-family: sans-serif, Arial, Verdana, "Trebuchet MS"; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;'&gt;Click on the &lt;strong&gt;&lt;a href="https://cp.winhost.com/sites/" rel="noopener noreferrer" target="_blank"&gt;&lt;strong&gt;Sites&lt;/strong&gt;&lt;/a&gt;&lt;/strong&gt; tab.&lt;/div&gt;&lt;div style='margin: 0px; padding: 0px; -webkit-tap-highlight-color: transparent; text-size-adjust: none; color: rgb(34, 34, 34); font-family: sans-serif, Arial, Verdana, "Trebuchet MS"; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;'&gt;&lt;br&gt;&lt;/div&gt;&lt;div style='margin: 0px; padding: 0px; -webkit-tap-highlight-color: transparent; text-size-adjust: none; color: rgb(34, 34, 34); font-family: sans-serif, Arial, Verdana, "Trebuchet MS"; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;'&gt;Click on the site account.&amp;nbsp;&lt;/div&gt;&lt;div style='margin: 0px; padding: 0px; -webkit-tap-highlight-color: transparent; text-size-adjust: none; color: rgb(34, 34, 34); font-family: sans-serif, Arial, Verdana, "Trebuchet MS"; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;'&gt;&lt;br&gt;&lt;/div&gt;&lt;div style='margin: 0px; padding: 0px; -webkit-tap-highlight-color: transparent; text-size-adjust: none; color: rgb(34, 34, 34); font-family: sans-serif, Arial, Verdana, "Trebuchet MS"; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;'&gt;Click on &lt;strong&gt;SSL Manager&lt;/strong&gt; icon under &lt;strong&gt;Site Tools&lt;/strong&gt;.&lt;/div&gt;&lt;div style='margin: 0px; padding: 0px; -webkit-tap-highlight-color: transparent; text-size-adjust: none; color: rgb(34, 34, 34); font-family: sans-serif, Arial, Verdana, "Trebuchet MS"; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;'&gt;&lt;br&gt;&lt;/div&gt;&lt;div style='margin: 0px; padding: 0px; -webkit-tap-highlight-color: transparent; text-size-adjust: none; color: rgb(34, 34, 34); font-family: sans-serif, Arial, Verdana, "Trebuchet MS"; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;'&gt;Naviate to the following &lt;a href="https://cp.winhost.com/sites/importSSL.aspx" target="_blank" rel="noopener noreferrer"&gt;Import SSL&lt;/a&gt; link: &lt;a data-fr-linked="true" href="https://cp.winhost.com/sites/importSSL.aspx" id="isPasted"&gt;https://cp.winhost.com/sites/importSSL.aspx&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;1. Click on the Browse button and select the .pfx file on your local computer.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=389" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;2. Enter the PFX password.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=390" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;3. Click on the Submit Certificate button.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=391" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;</description>
    </item>
    <item>
      <title>Force https with URL rewrite</title>
      <link>https://support.winhost.com/kb/a1523/force-https-with-url-rewrite.aspx</link>
      <pubDate>Thu, 05 Jul 2018 21:52:37 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1523</guid>
      <description>&lt;div&gt;For most sites, after installing a SSL certificate, https can be forced by adding a URL rewrite rule to the site&amp;#39;s web.config file. &amp;nbsp;Though, please note it will not apply to all sites, for example it may not work for those using routing or it may conflict with any existing URL rewrite rules. &amp;nbsp;In the case of a CMS like WordPress or nopCommerce, it is often a setting within the CMS itself. &amp;nbsp;The URL rewrite rule will not always work for ASP.NET Core sites (see below for more information).&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;URL rewrite rule to redirect all requests to https&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;pre class="prettyprint"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot;?&amp;gt;
&amp;lt;configuration&amp;gt;
  &amp;lt;system.webServer&amp;gt;
    &amp;lt;rewrite&amp;gt;
      &amp;lt;rules&amp;gt;
        &amp;lt;rule name=&amp;quot;Redirect to https&amp;quot; stopProcessing=&amp;quot;true&amp;quot;&amp;gt;
          &amp;lt;match url=&amp;quot;.*&amp;quot; /&amp;gt;
          &amp;lt;conditions&amp;gt;
            &amp;lt;add input=&amp;quot;{HTTPS}&amp;quot; pattern=&amp;quot;off&amp;quot; ignoreCase=&amp;quot;true&amp;quot; /&amp;gt;
          &amp;lt;/conditions&amp;gt;
          &amp;lt;action type=&amp;quot;Redirect&amp;quot; url=&amp;quot;https://{HTTP_HOST}{REQUEST_URI}&amp;quot; redirectType=&amp;quot;Permanent&amp;quot; appendQueryString=&amp;quot;false&amp;quot; /&amp;gt;
        &amp;lt;/rule&amp;gt;
      &amp;lt;/rules&amp;gt;
    &amp;lt;/rewrite&amp;gt;
  &amp;lt;/system.webServer&amp;gt;
&amp;lt;/configuration&amp;gt;&lt;/pre&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;Redirect to https in Core&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;For Core apps, UseHttpsRedirection middleware can be used to force https by adding app.UseHttpsRedirection(); to the program.cs as in the example below&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;pre class="prettyprint"&gt;var builder = WebApplication.CreateBuilder(args);

var app = builder.Build();

  &lt;span style='color: rgb(22, 22, 22); font-family: SFMono-Regular, Consolas, "Liberation Mono", Menlo, Courier, monospace; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: pre; background-color: rgb(254, 247, 178); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;' id="isPasted"&gt;app.UseHttpsRedirection();&lt;/span&gt;&lt;/pre&gt;&lt;div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;More detailed information can be found after the link &lt;a href="https://docs.microsoft.com/en-us/aspnet/core/security/enforcing-ssl"&gt;https://docs.microsoft.com/en-us/aspnet/core/security/enforcing-ssl&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;Securing domain pointers with a single domain certificate&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Because multi-domain certificates can be cost prohibitive or less than straight forward to order, a workaround is using domain forwarding and flexible SSL through cloudflare.com. &amp;nbsp;Flexible SSL means the connection is secure between the client and cloudflare, but is not secure between cloudflare and the site. &amp;nbsp;So it shouldn&amp;#39;t, for example, be used to secure a subdirectory pointer. &amp;nbsp;But is sufficient when a domain pointer is only an alternate address for a site. &amp;nbsp;Please note that this will assume some familiarity with cloudflare since it is an external service.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=486" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Add the domain pointer as a website in cloudflare and then when viewing the domain Overview, expand SSL, click Overview, then Configure, select the Flexible radial button and then Save.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="/AvatarHandler.ashx?kbattchid=488" style="width: 750px;" class="fr-fil fr-dib"&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now create the domain forwarding rule by expanding Rules then clicking Page Rules.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;In the &lt;strong&gt;URL&lt;/strong&gt; field enter the domain pointer&lt;/div&gt;&lt;div&gt;For &lt;strong&gt;Then the settings are&amp;nbsp;&lt;/strong&gt;select &amp;quot;Forwarding URL&amp;quot; and &amp;nbsp;&amp;quot;301 - Permanent Redirect&amp;quot; and enter the primary site domain in the &amp;quot;Enter destination URL&amp;quot; field&lt;/div&gt;&lt;div&gt;Save and Deploy&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
    </item>
    <item>
      <title>Browser security warnings after installing SSL certificate</title>
      <link>https://support.winhost.com/kb/a1465/browser-security-warnings-after-installing-ssl-certificate.aspx</link>
      <pubDate>Fri, 14 Apr 2017 16:50:17 GMT</pubDate>
      <guid isPermaLink="false">kbarticle1465</guid>
      <description>&lt;div&gt;&lt;span style="font-size:16px;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;Some of the most popular web browsers now display an &amp;quot;insecure&amp;quot; warning when visiting&amp;nbsp;&lt;/span&gt;pages that &lt;span style="font-family: arial,helvetica,sans-serif;"&gt;are not accessed via HTTPS. &lt;/span&gt;The &lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&amp;quot;insecure&amp;quot; warning may also be triggered on an HTTPS connection if certain page elements -&amp;nbsp;such as images or external scripts - are not accessed via HTTPS.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;

&lt;div&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: 16px;"&gt;After you have installed an SSL certificate for your domain there are still some things you may need to do to prevent any &amp;quot;insecure&amp;quot; warnings in your visitor's browser. If you install an SSL certificate but don't properly direct site traffic to use it, you will get the warnings.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;

&lt;div&gt;&lt;span style="font-size:16px;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;That's because installing an SSL certificate makes https available, but it does not automatically send your visitors to an HTTPS URL. &lt;/span&gt;To force all incoming connections to use HTTPS you'll want to add an entry to the system.webServer element of your web.config file (go ahead and create the file if you don't already have one) that uses the IIS URL rewrite module to redirect all non-HTTPS traffic to HTTPS:&lt;/span&gt;&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;

&lt;div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;

&lt;div&gt;
&lt;pre class="prettyprint"&gt;
&lt;span style="font-size:16px;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot;?&amp;gt;
&amp;lt;configuration&amp;gt;
    &amp;lt;system.webServer&amp;gt;
        &amp;lt;rewrite&amp;gt;
            &amp;lt;rules&amp;gt;
                &amp;lt;rule name=&amp;quot;Redirect to https&amp;quot; stopProcessing=&amp;quot;true&amp;quot;&amp;gt;
                    &amp;lt;match url=&amp;quot;.*&amp;quot; /&amp;gt;
                    &amp;lt;conditions&amp;gt;
                        &amp;lt;add input=&amp;quot;{HTTPS}&amp;quot; pattern=&amp;quot;off&amp;quot; ignoreCase=&amp;quot;true&amp;quot; /&amp;gt;
                    &amp;lt;/conditions&amp;gt;
                    &amp;lt;action type=&amp;quot;Redirect&amp;quot; url=&amp;quot;https://{HTTP_HOST}{REQUEST_URI}&amp;quot; redirectType=&amp;quot;Permanent&amp;quot; appendQueryString=&amp;quot;false&amp;quot; /&amp;gt;
                &amp;lt;/rule&amp;gt;
            &amp;lt;/rules&amp;gt;
        &amp;lt;/rewrite&amp;gt;
    &amp;lt;/system.webServer&amp;gt;
&amp;lt;/configuration&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;

&lt;div&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: 16px;"&gt;That will take care of forcing all incoming connections to HTTPS, though for the sake of consistency you may also want to update your site navigation and internal links to use the HTTPS URL.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;

&lt;div&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: 16px;"&gt;&lt;strong&gt;If you still see insecure site warnings after implementing the URL rewrite&lt;/strong&gt;, try:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: 16px;"&gt;Updating local image links (also references to images or scripts from outside of your domain) that use an HTTP absolute path URL to use the HTTPS URL.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
	&lt;li&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: 16px;"&gt;If you're using a database-driven application like WordPress, you may have to update the HTTP URLs in the database. There are &lt;a href="https://wordpress.org/plugins/better-search-replace/" target="_blank"&gt;&amp;quot;find and replace&amp;quot; WordPress plugins&lt;/a&gt; that can help with that.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;</description>
    </item>
  </channel>
</rss>