---
title: "Generate Office 365 certificates"
canonical: "https://docs.aryaka.com/space/KNOW/1270153585/Generate%20Office%20365%20certificates"
format: markdown
---
Aryaka provides a number of performance optimizations for Microsoft Office 365. One of these optimization offerings is SSL, which requires Office 365 certificates. The following options are available for generating and signing the certificates: Generated and signed by the customer Generated by Aryaka and signed by the customer Generated and signed by Aryaka This document describes how to generate and sign the certificates required for Office 365 SSL optimization with Aryaka. Prerequisites You must have a fully set up private certificate authority (CA) with permissions to sign new certificates. Otherwise, Aryaka must sign the certificates. The ability to access the  OpenSSL  toolkit and run secure sockets layer (SSL) commands.  Create OpenSSL configuration files The procedures described in this section use OpenSSL to generate the certificate. Optionally, you can have Aryaka create the conf files, and then generate the CSR and private key for you. If you choose this option: Aryaka sends the CSR to you to sign. You sign the CSR using your CA (described later in this topic). You send Aryaka the signed certificate to process by email. Create a conf file for Outlook Modify a clean openssl conf file with the following lines to provide the SANs required for CSR generation: [ alt_names ]
DNS.1 = *.outlook.com
DNS.2 = outlook.com
DNS.3 = office365.com
DNS.4 = *.office365.com
DNS.5 = *.internal.outlook.com
DNS.6 = *.outlook.office365.com
DNS.7 = outlook.office.com
DNS.8 = m.outlook.com
DNS.9 = portal.office.com
DNS.10 = *.office.com Create a conf file for Sharepoint Modify a clean openssl conf file with the following lines to provide the SANs required for CSR generation: [ alt_names ]
DNS.1 = office365.com
DNS.2 = outlook.com
DNS.3 = *.sharepoint.com
DNS.4 = *.sharepointonline.com Create a conf file for Lync Modify a clean openssl conf file with the following lines to provide the SANs required for CSR generation: [ alt_names ]
DNS.1 = *.lync.com
DNS.2 = *.cqd.lync.com
DNS.3 = *.infra.lync.com
DNS.4 = *.online.lync.com
DNS.5 = *.resources.lync.com
DNS.6 = skypemaprdsitus.trafficmanager.net
DNS.7 = pipe.skype.com
DNS.8 = *.pipe.aria.microsoft.com
DNS.9 = quicktips.skypeforbusiness.com
DNS.10 = swx.cdn.skype.com
DNS.11 = *.config.skype.com
DNS.12 = config.edge.skype.com
DNS.13 = *.sfbassets.com
DNS.14 = *.urlp.sfbassets.com
DNS.15 = *.skypeforbusiness.com
DNS.16 = *.api.skype.com
DNS.17 = *.users.storage.live.com
DNS.18 = graph.skype.com
DNS.19 = aka.ms
DNS.20 = *.microsoftonline.com
DNS.21 = broadcast.skype.com
DNS.22 = *.broadcast.skype.com
DNS.23 = browser.pipe.aria.microsoft.com
DNS.24 = mlccdn.blob.core.windows.net
DNS.25 = ajax.aspnetcdn.com
DNS.26 = *.msecnd.net
DNS.27 = amp.azure.net
DNS.28 = pipe.skype.com
DNS.29 = *.streaming.mediaservices.windows.net
DNS.30 = *.keydelivery.mediaservices.windows.net Generate a CSR and private key You can generate a certificate signing request (CSR) and a private key using OpenSSL. Create a CSR and private key for Outlook Run the following command and when prompted, provide the common name as outlook.com: openssl req -new -config outlook.conf -out outlook.csr -keyout outlook.key Create a CSR and private key for Sharepoint Run the following command and when prompted, provide the common name as sharepoint.com: openssl req -new -config sharepoint.conf -out sharepoint.csr -keyout sharepoint.key Create a CSR and private key for Lync Run the following command and when prompted, provide the common name as lync.com: openssl req -new -config lync.conf -out lync.csr -keyout lync.key Sign the CSR with customer CA Sign each CSR generated using your certificate authority (CA) by issuing the following openSSL commands for each of the Office 365 applications: openssl ca -config <path to CA Conf file> -in <path to csr>/outlook.csr -out <path to certificate>/outlook.crt -extensions server_ext
openssl ca -config <path to CA Conf file> -in <path to csr>/sharepoint.csr -out <path to certificate>/ sharepoint.crt - extensions server_ext
openssl ca -config <path to CA Conf file> -in <path to csr>/lync.csr - out <path to certificate>/ lync.crt -extensions server_ext You must enter the CA password when prompted by each of these commands. Upload the certificate After the certificate is generated and signed, sent it to Aryaka as follows: If Aryaka generated the private key, zip the certificate, complete the trust chain, and email them to  support@aryaka.com . If you generated the private key, upload it to Aryaka using MyAryaka along with the private key and trust chain as a bundle. Run the following commands to create a p12 archive file for each of the Office 365 applications: openssl pkcs12 -export -chain -CAfile -in <path to cert>/outlook.crt - inkey <path to key>/outlook.key -out <path to bundle>/outlook.p12
openssl pkcs12 -export -chain -CAfile -in <path to cert>/sharepoint.crt -inkey <path to key>/sharepoint.key -out <path to bundle>/sharepoint.p12
openssl pkcs12 -export -chain -CAfile -in <path to cert>/lync.crt - inkey <path to key>/lync.key -out <path to bundle>/lync.p12 In this topic Related topics Office 365 trust chain Manage static certificates Add static certificates Converting certificate file formats