CES and CEP must use Secure Sockets Layer (SSL) for communication with clients (by using HTTPS). Each service must have a valid certificate that has an Enhanced Key Usage (EKU) policy of server authentication in the local computer certificate store.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Install the IIS service in the server.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Log in to the CEP server, and then add the Root CA certificate in the Trusted Root Certification Authority store.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Launch the IIS Manager Console and then, select Server Home.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From the main view section, open Server Certificates.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Actions > Create Certificate Request.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Distinguished Name Properties window, provide the necessary information and then, click Next.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Cryptographic Service Provider Properties dialog, select the bit length, and then click Next.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Save the file.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Get the file signed by the CA that you are planning to use for CEP and CES.
Note: Make sure that Server Authentication EKU is enabled in the signed certificate.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Copy the signed file back to the CEP server.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From the IIS Manager Console, select Server Home.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From the Main View section, open Server Certificates.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Actions > Complete Certificate Request.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In Specify Certificate Authority Response window, select the signed file.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Type a name, and then in the Certificate Store menu, select Personal.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Complete the certificate installation.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From IIS Manager Console, select the default website.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Click Actions > Bindings.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Site Bindings dialog, click Add.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
In the Add Site Binding dialog, set Type to https, and then from the SSL certificate, browse for the newly created certificate.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
From the IIS Manager Console, select Default Web Site, and then open the SSL settings.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Enable Require SSL and set Client certificates to Ignore.
![](https://publications.lexmark.com/media/ids_assets/images/transparent.png)
Restart IIS.