X-ERP Help

10. Set up certificate

Select, import and protect a valid server certificate that matches the DNS name of the X-ERP address and whose expiration is monitored.

The lock in the browser is small, but its importance is great: it confirms to the user that access data and business data are being exchanged with the expected server.

Why this station counts

For TLS, the DNS name, certificate name, trust chain, private key, and IIS binding must match. A certificate without a private key cannot serve as a server identity.

The resilient process

  1. Apply for or choose a final DNS name certificate.
  2. Import it into the designated computer storage with private key.
  3. Check subject/SAN, issuer, chain, validity and purpose.
  4. Limit access to the private key.
  5. Deposit process monitoring and responsible renewal.

Functional test - only then continue

  • DNS name is included in the certificate.
  • Browser trusts the full chain.
  • Private key is present and protected.
  • Expiry warning reaches a responsible person in a timely manner.

If the result is not correct

  • A wildcard certificate is used everywhere without risk assessment.
  • Missing intermediate certificates only generate warnings for some clients.
  • Renewal without monitoring ends in a sudden failure.

This is what you take with you

The X-ERP address has a verifiable, trusted server identity.

Video

Set up certificate

Further information / source

Related topics

  1. For system administrators – setting up servers and creating company databases › 11. Bind certificate to port
  2. For system administrators – setting up servers and creating company databases › 14. Updates and operational documentation

Frequently asked questions

**Which names have to fit?**

The DNS name called must be included in the Subject Alternative Name of the certificate.

**Is a self-signed certificate enough?**

For isolated testing, it can be deliberately distributed; productively, the entire client landscape should trust the issuing body.