NOTE:
As of November 12, 2024, Entrust introduced a new TLS certificate hierarchy as part of the deployment. The TLS certificate delivery now includes two certificate chains. The delivery of these certificate chains can be in the form of:
- Individual files. Intermediate 1 (filename: intermediate1.crt ) and Intermediate 2 (filename: intermediate2.crt ) or
- Concatenate PEM file (filename: CertificateBundle1.pem ) or
- P7B format file (filename: Certificatebundle.p7b )
Both intermediate/chain certificates must be installed in your environment.
Step-by-step:
1. Click the Download button in the pickup wizard to download your certificate files. Clicking the download button will produce a zip file that includes your Server Certificate, the Entrust chain/intermediate certificates(s) and the Entrust Root certificate. Extract the files from the zip file.
2. On the server, go to Start > Run > type MMC and hit enter .
3. Click File > Add Remove Snap-in.
4. Select Certificates and click Add .
5. Select Local Computer and click Finish .
6. Click Close .
7. Expand Certificates on the left hand side of the console window.
8. Expand the Trusted Root Certification Authorities folder and click on the Certificates sub-folder.
9. Right click on the Certificates sub-folder under Trusted Root Certification Authorities and select All Tasks > Import .
10. In the import wizard, browse to the Root.crt file downloaded in step 1 and complete the wizard.
11. In the MMC console, expand the Intermediate Certification Authorities folder. Right click on the Certificates sub-folder and select All Tasks > Import .
12. In the import wizard, browse to the Intermediate.crt file downloaded in step 1 and complete the wizard.
NOTE: As of November 12, 2024, the intermediate certificate came with two files: intermediate1.crt and intermediate2.crt. These intermediate/chain certificates must be imported into your server/appliance.
13. Click on Start , search for the Skype for Business Server Deployment Wizard and open it.
14. Click on Install or Update Skype for Business Server System .
15. Click Run under Step 3 (Request, Install, or Assign Certificates).
16. Click on the Import Certificate button to launch the Import Certificate window.
17. Browse to the location of the ServerCertificate.crt file that you downloaded in step 1 and uncheck the box that says "Certificate file contains the certificate's private key". Click Next .
18. Click Next in the Import Certificate window.
19. Click the Finish button once the task is completed.
20. On Default Certificate section, make sure that all of the desired services have been selected. Click Assign .
Click Next to continue.
21. Make sure you have selected the friendly name that associated with your Entrust SSL/TLS certificate. Click Next button to continue.
22. If the services assign correctly, the Task Status will show as Completed . Click the Finish button.