Extract Required Certificates and CRLs from a Single SSL Certificate

If the Certificate Authority provides all the required certificates and certificate revocation information in a single certificate file, use this procedure to extract those items from that certificate.
3-4
If the Certificate Authority provides all the required certificates and certificate revocation information in a single certificate file, use this procedure to extract those items from that certificate.
Follow these steps:
  1. Copy the certificate to a convenient location on a local Windows computer.
  2. In
    Windows Explorer
    , navigate to the location of the certificate file and open it.
    A
    Certificate
    dialog opens.
    ExampleCertificate_main.jpg
  3. Select the
    Certification Path
    tab, where the trusted root CA is displayed at the top of the
    Certification Path
    pane, your device certificate at the bottom, and intermediate certificates in between.
  4. Select the
    Details
    tab.
  5. Scroll down and select the
    CRL Distribution Points
    field.
    The value appears in the window under the fields list.
    Example_CRL_URL.jpg
  6. Select and copy the URL value.
  7. Paste the URL into a browser.
    When prompted to open or save the CRL file, select
    Save
    . For convenience, save it to same location as the certificate.
  8. On the
    Certification Path
    tab, select the intermediate certificate.
    ExampleCertificate_Intermediate.jpg
  9. Select the
    View Certificate
    button.
    A new
    Certificate
    dialog opens for the intermediate certificate.
    ExampleCertificate_intermediate_view.jpg
  10. Select the
    Details
    tab on the
    Certificate
    dialog for the intermediate certificate.
    CopyCertToFile.jpg
  11. Select the
    Copy to File
    button to save this certificate.
    The
    Certificate Export Wizard
    opens.
  12. Follow the prompts in the wizard. For convenience, save the certificate to same location as the device certificate and CRL file.
  13. Return to the open
    Details
    tab of the intermediate certificate dialog.
  14. Scroll to the
    CRL Distribution Point
    field.
  15. Copy the URL of the CRL Distribution Point as you did for the device certificate.
  16. Paste the URL into a browser.
    When prompted to open or save the CRL file, select
    Save
    . For convenience, save the intermediate certificate to same location as the certificates and other CRL.
  17. On the
    Certification Path
    tab, select the root certificate.
    ExampleCert_Root.jpg
  18. Select the
    View Certificate
    button.
    A new
    Certificate
    dialog opens for the root certificate.
    ExampleCert_Root_View.jpg
  19. Select the
    Details
    tab on the root certificate.
  20. Select the
    Copy to File
    button to save this certificate.
    The
    Certificate Export Wizard
    opens.
  21. Follow the prompts in the wizard. For convenience, save the root certificate to same location as the other certificates and CRL files.
The root certificate does not have a CRL Distribution Point field.
You should now have certificate files for each level of the Certification Path, and CRLs for all but the root certificate.
file icons.jpg file icons.jpg