Cisco Email Security Appliance (ESA)

Generating a new CSR

Use the Network > Certificates page in the GUI or the certconfig command in the CLI in order to create the self-signed certificate, generate the CSR and install the trusted public certificate.

Configuration Steps on the GUI

In order to create a self-signed certificate, click Add Certificate on the Network > Certificates page in the GUI (or the certconfig command in the CLI). On the Add Certificate page, choose Create Self-Signed Certificate. Enter this information for the self-signed certificate:

Certificate Information Guidelines

Location - Enter the location where your business operates, not where your server is located. If you are an international customer in a country without a State/Province or City/Locality, leave those fields blank.

  • Country Name - Enter the two letter International Organization for Standardization (ISO) abbreviation of the country where your organization is legally located.
  • State/Province - Spell out the entire name of your state or province. For example, if your business operates in Texas, enter "Texas" and not "TX".
  • City/Locality - Spell out the entire name of your city or locality.

Organization - Enter the full, unabbreviated legal name of your business. Include any applicable suffix, such as "Inc" or "LLC". If your company name is registered in an abbreviated form, then you may use that abbreviation if you want.

Organizational Unit - This field will not be included in your certificate, so you can leave it blank.

Common Name - Enter the web address of your site. It must be a fully qualified domain name. Both and are acceptable. Do not include http:// or https://. When ordering a wildcard Server Certificate, you will use *

Email Address - Enter the address of the person responsible for digital certificates in your organization. This field is optional.

Duration before expiration - The number of days before the certificate expires.

Private Key Size - Size of the private key to generate for the CSR. Use 2048-bit.

Click Next in order to view the certificate and signature information. Enter a name for the certificate. AsyncOS assigns the common name by default.

To get your CSR, click Download Certificate Signing Request in order to save the CSR in Privacy Enhanced Mail (PEM) format to a local or network machine. Click Submit in order to save the certificate and commit your changes. If you leave the changes uncommitted, the private key will get lost and the signed certificate cannot be installed.

Protect your new private key for a digital certificate

  1. Never give this file to anyone outside your company. Also restrict the access to it to the smallest possible group of employees.
  2. When you get your certificate, you must install this private key in a secure folder that has limited access to a root user and is protected with read-only permission.
  3. Backup your private key. There is no way to recover it if it is lost. Protect that backup with additional security such as an encrypted or password-protected backup. Your private key is integral to the digital certificate process.
  4. If you suspect that your private key is compromised, alert SecureTrust™ immediately. SecureTrust will revoke your certificate so that you can generate a new private key and CSR. You can then submit the new CSR for SecureTrust to reissue your certificate.

Submit the CSR to SecureTrust

Now navigate to the location of your saved CSR and open it with a suitable text editor such as Notepad, TextEdit, or vi. Copy the entire text - including the top and bottom dashed lines. You can paste this text directly into the SecureTrust Control Center - Submit your CSR to proceed to validation.