SecureNT Intranet SSL

SSL/TLS Certificates for Internal Networks.

FAQs

Those might have popped-up in your mind.

How to encrypt On-Premise SharePoint traffic with Intranet SSL? ?
Technical
keyboard_arrow_down

Microsoft recommends using HTTPS for all SharePoint web applications to ensure secure communication over port 443, as outlined in their official documentation.

Step-by-Step: Encrypt SharePoint with SecureNT Intranet SSL

Follow these steps to secure your SharePoint 2016, 2019, or Subscription Edition deployment with SecureNT Intranet SSL.

1. Generate a Certificate Signing Request (CSR)

Following steps are applicable for all versions of IIS. Windows Server should be domain joined.

  • Open the MMC console and add the Certificate snap-in to it as Local Computer. Right Click Personal node on the left and Select All Tasks –>Advanced Operations –> Create Custom Request.
  • Choose Proceed without enrollment policy and Click Next. Choose No Template Legacy Key for compatibility reasons. Use PKCS#10.
  • Click Next and click Properties. Give a friendly name for the certificate (e.g., SharePoint SSL) and a description. Ensure that you hit Apply as soon as you are done with the tab.
  • Click on Subject tab and add all the hostnames under “Alternative Name“ e.g., sharepoint.company.local. Under Subject Name, enter the Common Name (CN) e.g., sharepoint.company.local, Organization (O), City (L), State (S), and 2 letter Country (C) code values. Click Apply.
  • Under the Extensions tab, expand Extended Key Usage (application policies) and select Server Authentication and Client Authentication. Click Apply.
  • Under the Private Key tab, set the Key size to 2048 (or 4096) and SHA256 algorithm under options. Tick Make Private Key exportable. Select Exchange as the Key type. Click Apply. Click OK.
  • Select a location to save the file. Choose the file format as Base 64. Click Finish.

CSR is generated with SAN values.

Note: If you don't wish to generate CSR then you can simply fill in all certificate details e.g., Domain = Common Name (e.g., sharepoint.company.local), Organization Name, City, State, and Country. And Auto-CSR will be generated by us.

2. Obtain a SecureNT Intranet SSL Certificate

  • Visit intranetssl.net. Request Free or Paid certificate.
  • Upload the CSR to the Certificate request form.
  • Download the signed certificate (.cer format) and CA chain bundle.

SecureNT certificates are X.509-compliant and trusted across your domain once the SecureNT Root CA is deployed.

3. Install the Certificate in IIS

  • In IIS Manager, go to Server Certificates > Complete Certificate Request.
  • Upload the .cer file and assign a friendly name.
  • Under your SharePoint web app, go to Bindings, add an HTTPS binding on port 443, and select the installed certificate.

4. Configure SharePoint for HTTPS

  • In SharePoint Central Administration, update Alternate Access Mappings (AAMs) to use https://.
  • Optionally, redirect HTTP traffic to HTTPS using IIS rewrite rules or network policies.

5. Deploy the SecureNT Root CA

  • Two SecureNT CA certificates (root and intermediate) are sent along with the certificate.
  • Distribute it via Group Policy under Trusted Root Certification Authorities. Here are the steps.
  • Ensure all domain-joined devices trust the CA.

No Comments Yet.

Tags

Copyright © 2025 Secure Network Traffic. All rights reserved. SecureNT is a registered trademark of Secure Network Traffic.