Step 1: Open up CertManager certlm.msc and go to Personal
Step 2: Right-click on Personal > All Tasks > Advanced Operations > Create Custom Request
Step 3: Select Proceed without enrollment policy
Step 4: Change the Template to Legacy Key
Step 5: Select Properties
Step 6: Enter the details under the tab Subject.
The country must be included along with the common name, and we recommend the DNS value. Any additional values are not imperative.
Step 7: Private Key
Please select Microsoft Enhanced RSA and AES Cryptographic Provider.
The key size minimum supported is 2048, but 4096 is a good choice.
If you need to export the certificate later, please don't forget to select make private key exportable.
Step 8: Select ok and then next, and you will be asked where to save your CSR.
Step 9: Open the file and paste your CSR to the portal to request your certificate.