Generate the certificate request from IIS, website “directory security” property page and save locally
Use start.com to renew the certificate and the following if your personal cert has expired
- create new account on start.com; validate it via the return on email
- install and backup the personal certificate on Chrome
- use the “validations wizard” to validate the domain
- validate it again via the return email
- start the certificate wizard for the domain, skip the step to create another personal certificate
- paste in the previously extracted certificate renewal
- accept the root domain name; and then set to “mail” as the subdomain
- save the new certificate as ssl.cer
- re-import into IIS property pages for the website and view certificate to ensure it’s valid
use start, run certmgr.msc if there are certificate chain issues to help resolve