Downloading certificates, certificate chains, and keystores¶
You can download both certificates and keystores from Certificate Manager - SaaS at any point after you have issued a certificate, using either Certificate Manager - SaaS or the API.
Downloading a keystore
You can only download keystores when Certificate Manager - SaaS issued the key pair. If another tool generated the key pair, Certificate Manager - SaaS doesn't have the private key, so it can't generate the keystore to download.
For information on using the API, see Downloading a certificate.
-  Sign in to Venafi Control Plane. 
-  Find the certificate you want to download by doing either of the following: -  Go to Inventory > Certificates and use filters to find the certificate you want to download. Or, 
-  Go to Applications and find the application that the certificate is assigned to. In the certificate's row, click the number in the Certificates column. This opens the certificate inventory filtered on this application's certificates. 
 
-  
-  Click the checkbox next to the certificates that you want to download. Use the tabs below for the download instructions, depending on whether you want to download the certificate itself, the certificate chain, or the keystore (if it's available) - In the local menu bar, click Download.
- Select the Certificate only radio button.
- Click the Choose an export format drop-down and select one of the following certificate formats:- PEM
- DER
- PKCS7
 
- Click Download.
 - In the local menu bar, click Download.
- Select the Certificate only radio button.
- Click the Choose the chain order drop-down and select one of the following chain orders:- End entity only
- Full chain (EE first)
- Full chain (Root first)
 
- Click Download.
 Downloading a keystore Keystore download is available only when Certificate Manager - SaaS generated the key pair. When Certificate Manager - SaaS generates the key pair, it has access to the private key. If another system generated the key pair, Certificate Manager - SaaS doesn't have access to the private key, so it can't generate the keystore. - In the local menu bar, click Download.
- Select the Keystore radio button.
- Choose an export format.
- Enter a password, which will be used to encrypt the private key.
-  Optional (for PKCS12): To use the legacy encryption algorithm, select the Use legacy algorithm checkbox. Changed behavior Certificate Manager - SaaS now uses a modern encryption algorithm by default when generating keystores in PKCS12 format. Previously, the legacy algorithm was used by default for PKCS12. 
-  Click Download.