You now need to take the CSR file to a third-party SSL certificate provider. For instance, if you choose to use GoDaddy, ...

You now need to take the CSR file to a third-party SSL certificate provider. For instance, if you choose to use GoDaddy, you need to search GoDaddy's instructions to fulfill the CSR. Other third-party providers include Verisign and Thwart. Once the certificate is issued, download the completed CSR to the AD FS server. It's important to keep track of the location of this file and not delete or move it. The server won't be able to find it for verification if the file is moved or deleted. Leave the default self-signed token signing certificate that comes with AD FS 3.0 in the Computer Store. Staying current with your SSL certificates is very important. You can extend the date, but renewals can cause a new key to be generated. This means that you may have to revisit this step or a version of it at another time in the future.