Following up from my last post about generating a CSR, I went through the motions of testing the full cycle for said CSR. I'd sign it with a bogus (but locally trusted) authority certificate, install the signed cert locally, export the PFX, install it on a Web server, select the cert for TLS on an IIS website, and hit it with a bunch of desktop browsers. The certificate works as expected.