This document describes how to export the SSL Certificate from a Microsoft IIS server. If the Palo Alto Networks device will be inspecting incoming traffic to a Microsoft IIS server (including the front end servers for Exchange 2003 OWA or Exchange 2007 CAS) using SSL, the server's certificate and key can be loaded for inbound SSL inspection. The following steps outline what needs to be done to export the existing IIS SSL server certificate and key.
Exporting the SSL Server Certificates and Key
Using the Internet Information Server (IIS) Manager MMC (Microsoft Management Console) plug in, connect to the desired server. The default location for the plug in is Start > Programs > Administrative tools > Internet Information (IIS) Manager.
Select the Properties of the Default Web Site instance. Note: If a different website other than the default for the SSL service is used, select that instance instead.
Launch the Web Server Certificate Wizard by selecting the Directory Security tab from the Properties window and pressing the Server Certificate button under the Secure communications section.
Select Next from the Welcome page. Then, select "Export the current certificate to a .pfx file" and click Next.
After the export occurs, the .pfx file can be directly imported into the Device > Certificate page on the web GUI.