# Mesh Central - SSL certificate generation steps (New Implementation)

**URL:** <https://community.sapphireims.com/t/mesh-central-ssl-certificate-generation-steps-new-implementation/538>\
**Category:** Remote Desktop\
**Tags:** how-to\
**Created:** [April 6, 2021, 1:52pm UTC](https://community.sapphireims.com/t/mesh-central-ssl-certificate-generation-steps-new-implementation/538 "2021-04-06T13:52:18Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dharmaraj](https://avatars.discourse-cdn.com/v4/letter/d/a587f6/32.png) [@dharmaraj](https://community.sapphireims.com/u/dharmaraj)\
**Post date:** [April 6, 2021, 1:52pm UTC](https://community.sapphireims.com/t/mesh-central-ssl-certificate-generation-steps-new-implementation/538/1 "2021-04-06T13:52:18Z")

</div>

Below are the steps which needs to be followed -

1. Convert certificate and generate the proper CRT and Private key using the below link  
[https://support.stackpath.com/hc/en-us/articles/360001081206-How-To-Convert-pfx-to-a-crt-key-file](https://support.stackpath.com/hc/en-us/articles/360001081206-How-To-Convert-pfx-to-a-crt-key-file)

2. Validate the new CRT and Private key files are proper not using below link.

> **[How to check if the certificate matches a Private Key?](https://myssl.ssl247.com/kb/ssl-certificates/troubleshooting/certificate-matches-private-key)**
>
> Secure your website and online business continuity with premium SSL certificates, PenTest and web security products from Symantec, GlobalSign, Comodo, Entrust…

1. Then rename the CRT and Private key files as “webserver-cert-public.crt” and “webserver-cert-private.key”

2. Make the copy of same CRT and private key file and rename as “agentserver-cert-public.crt” and “agentserver-cert-private.key”

3. Place these files mentioned in step 3 and 4( totally 4 files) under \<%MeshCentral Installation Path%\>\meshcentral-data

4. Restart the MeshCentral service

**Note:** Open SSL is required for this.
