[KB6763] Export a certificate or public key from ESET Security Management Center (7.x)


ESET business product in Limited Support status

This article applies to an ESET product version that is currently in Limited Support status and is scheduled to reach End of Life status soon.

For a complete list of supported products and support level definitions, review the ESET End of Life Policy for business products.

Upgrade ESET business products.

Required user permissions

This article assumes that you have the appropriate access rights and permissions to perform the tasks below.

If you use the default Administrator user or are unable to perform the tasks below (the option is unavailable), create a second administrator user with all access rights.

  • Export a Server certificate, an Agent certificate or a Certificate Authority (CA) public key from ESET Security Management Center Web Console (ESMC Web Console) for use during the installation of an ESET Security Management Center (ESMC) component


As part of the installation process, ESMC requires a peer certificate authority and a peer certificate for Agents. These certificates are used to authenticate products distributed under your license. You can create new certificates for use on additional client computers. For example, a server certificate is required for the distribution of ESET server products. You may also want to create a new certificate to set specific parameters for a certain group of client computers, for example, a group of computers that will only be in use for six months might use a certificate with a different expiration date than other client computers.

Your Certificate Authority (CA) is used to legitimize certificates distributed from your network. In an enterprise setting, a public key can be used to automatically associate client software with the ESET Security Management Center Server to allow for remote installation of ESET products.



A Peer certificate or Certification Authority must be present in ESMC Web Console.

Export a certificate or public key

Default certificates

Peer certificates and Certification Authority that are created during the installation are by default contained in the All Static Group.

  1. Open ESET Security Management Center Web Console (ESMC Web Console) in your web browser and log in.

  2. Click More Certificates Peer Certificates (or select Certification Authorities to export a public key).

  3. Select the appropriate certificate. The type of certificate you export will depend on the component you are installing. Export a Server certificate for use when installing server components. Export an Agent certificate for use when installing the ESET Management Agent. See below for examples of when to use each option:

    1. Export - Export your certificate (.pfx file ) or CA (.der file). During product installation, the setup wizard will prompt you for this certificate.

    2. Export as Base64 - Export your certificate or CA as a .txt file. Open this file in a text editor to access your unique certificate or public key for use when creating a transformation (.mst) file or in other applications where it is necessary to enter unique strings from your certificate or CA to submit your credentials.

Figure 1-1
Click the image to view larger in new window

Convert custom certificates to Base64 format

Base64 is the only format accepted by ESMC components to connect to the ESMC Server. For more information on how to convert certificates, see Linux man page and Mac OS X man page.