Updated on 2026-10-10 GMT+08:00

Downloading a Private Certificate

Before using a private certificate, you need to download it. Only the downloaded certificate can be assigned to the corresponding certificate subject so that they can install and use the certificate.

This topic describes how to download a private certificate. Only certificates in the Issued state can be downloaded.

Application Scenarios

To enable HTTPS encryption for intranet services (such as Nginx, Apache, and Tomcat), load device identity certificates for IoT devices, or import private certificates into Windows clients, you need to download the issued private certificate from the CCM console to your local PC. After obtaining the certificate and private key files, deploy them on the service side. A certificate cannot be deployed on any server or client unless it is downloaded first.

Prerequisites

Your private certificate is in the Issued state. For details, see Applying for Issuing a Private Certificate.

Downloading a Private Certificate

  1. Log in to the CCM console.
  2. In the navigation pane on the left, choose Private Certificate Management > Private Certificates.
  3. Locate the row of the desired private certificate and click Download in the Operation column.

    Figure 1 Downloading a private certificate

  4. Click the target tab based on your server type and click Download Certificate.

    PCA will use the download tool provided by the browser to download the private certificate to the specified local directory.

    To verify the downloaded certificate, decompress the downloaded package and check the decompressed file list. The files must be consistent with those described in Description of Downloaded Certificate Files.

Installing a Private Certificate

After downloading the private certificate, install it on the client or server.

Description of Downloaded Certificate Files

The downloaded certificate files vary depending on the CSR file type (System generated CSR or Upload a CSR) configured when you apply for a private certificate.

  • System generated CSR
    Table 2 describes the downloaded files.
    Table 2 Description of downloaded files (1)

    Server Type

    Files in the Package

    Tomcat

    keystorePass.txt: certificate password

    server.jks: certificate file

    Nginx

    server.crt: certificate files, containing the server certificate and certificate chain

    server.key: certificate private key file

    Apache

    chain.crt: certificate chain file

    server.crt: certificate file

    server.key: certificate private key file

    IIS

    keystorePass.txt: certificate password

    server.pfx: certificate file

    Others

    chain.pem: certificate chain file

    server.key: certificate private key file

    server.pem: certificate file

  • Upload a CSR

    Table 3 describes the downloaded files.

    Table 3 Description of downloaded files (2)

    Server Type

    Files in the Package

    Tomcat

    server.crt: certificate file

    chain.crt: certificate chain file

    Nginx

    server.crt: certificate file

    Apache

    server.crt: certificate file

    chain.crt: certificate chain file

    IIS

    server.crt: certificate file

    chain.crt: certificate chain file

    Others

    cert.pem: certificate file

    chain.pem: certificate chain file