- Install the NDES certificate.
- Bind the NDES certificate in IIS.
- Configure request filtering.
- Bind the certificate in the registry.
Install the certificate
Perform the following steps to install the NDES certificate:1
On the NDES server, open the Windows search bar and look for
certlm.msc. Open it.2
In the left toolbar, right-click Personal and select All Tasks > Request New Certificate.
3
On the Select Certificate Enrollment Policy page, select [ Active Directory Enrollment Policy ]. Select [ Next ].
4
Select the NDES certificate created earlier, and select [ More information is required to enroll for this certificate. Click here to configure Settings ].
5
On the Certificate Properties page, make the following changes:
- For Subject Name, select [ Common Name ] and enter the Fully Qualified Domain Name of your NDES server. Then, select [ Add ].
- For Alternate Name, select [ DNS ] and enter the Fully Qualified Domain Name of your NDES server. Then, select [ Add ].
6
Select [ Apply ] and then [ OK ]. Then select [ Enroll ].
Bind the certificate
Perform the following steps to bind the NDES certificate in IIS:1
On the NDES server, open the Windows search bar and look for Internet Information Services (IIS) Manager. Open it.
2
Expand your Server Name > Sites and then select [ Default Web Site ].
3
On the right side of the screen, locate Edit Site and select [ Bindings ].
4
On the Site Bindings page, select [ Add ].
5
Change the Type to HTTPS and select [ Select ]. Select the NDES certificate you just installed and select [ OK ].
Configure request filtering
Perform the following steps to configure request filtering in IIS:1
On the NDES server, open the Windows search bar and look for Internet Information Services (IIS) Manager. Open it.
2
Expand your Server Name > Sites and then select [ Default Web Site ].
3
Locate and select [ Request Filtering ].
4
On the right side of the screen, locate and select [ Edit Feature Settings ].
5
Change the Max Url length and Max query string values to
65534. Select [ OK ].Bind the certificate
Perform the following steps to bind the certificate in the registry:1
On the NDES server, open the Windows search bar and look for System Registry Editor. Open it.
2
Go to
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MSCEP and locate GeneralPurposeTemplate.3
Change the value to the name of your certificate template created for NDES. (Not the display name.)
4
Close the registry editor and restart the NDES server.

