Export Client Certificate in PKCS12 Format

Starting in Niagara 4.15, windows only supports exporting a client certificate and private key in PKCS12 format. This procedure explains how to export the client certificate in the Workbench to authenticate the station via browser, without needing the OpenSSL.

  • Workbench is running and connected to station.

  • You have already generated a client certificate, which places certificate in User Key Store.

  1. In the Workbench, click Tools > Certificate Management.
    The Certificate Management view opens.

  2. To export a certificate on the User Key Store tab, select the certificate and click Export.
    The Certificate Export window opens.

  3. Do the following and click OK.
    • In the Export format, click drop-down to select the PKCS12 format.

    • In the Private Key, click the checkbox as Export the private key and enter the password in the Private key Password(required).

    The File Chooser window opens and save the certificate in the User Home.

  4. Double-click User Home and click Save.
    The certificate is exported successfully.
  5. Navigate to certificate location and double-click the certificate.
    The Certificate Import Wizard opens.

  6. Verify and click Next to continue.
    The File to Import window opens.

  7. To import the file, click Browse or continue with the existing file and click Next.
    The Private Key Protection window opens.

  8. Type the password and click Next.
    The Certificate Store window opens.

  9. To store the certificate, select the certificate as Place all certificates in the following store and click Browse.
    The Select Certificate Store window opens.

  10. Select the Personal, click OK and Next.
    The Completing the Certificate Import Wizard opens.

  11. Click Finish.
    The certificate imported successfully.

  12. In the browser, enter the station address and press Enter.
    The browser opens a window, prompting you to select a certificate to authenticate yourself to the station.

  13. Click OK.
    The station pre-login window opens.

  14. Enter the Username and click Log in with SSO.
    Upon clicking the button, you immediately authenticate to the station.