diff --git a/app/owlca/templates/owlca/certificate_pickup.html b/app/owlca/templates/owlca/certificate_pickup.html
index 87bbf9eee86fd996065cf655b5f49568aee0586f..9488d99311a40ac7ec1a397bad5b89a2d1487d88 100644
--- a/app/owlca/templates/owlca/certificate_pickup.html
+++ b/app/owlca/templates/owlca/certificate_pickup.html
@@ -33,6 +33,16 @@
   <strong>{{ certificatesigningrequest.verification_text }}</strong>
 </p>
 
+<div class="alert alert-info">
+  <p>To use the certificate in your browser,</p>
+  <ol>
+    <li>combine your private key with the certificate
+    <pre>openssl pkcs12 -export -out cert.p12 -inkey key.pem -in cert.pem</pre>
+    </li>
+    <li>and import the <code>cert.p12</code> in your browser.</li>
+  </ol>
+</div>
+
 {% if certificatesigningrequest.verification == 10 %}
 <ul class="list-unstyled">
     {% for cert in certificatesigningrequest.certificates.all %}
diff --git a/app/owlca/templates/owlca/certificatesignrequest_create.html b/app/owlca/templates/owlca/certificatesignrequest_create.html
index cd858a16f8a125bcc1935f67a44c1fca16bb36b6..f90391a934f17275b6149820a1d89a99b0b51544 100644
--- a/app/owlca/templates/owlca/certificatesignrequest_create.html
+++ b/app/owlca/templates/owlca/certificatesignrequest_create.html
@@ -32,9 +32,9 @@
         <p>Generate a new private key and create a certificate signing request
         (CSR). For example, execute the following command and enter the
         prompted information.</p>
-        
-        <pre>openssl genrsa -aes256 -out key.pem 2048
+        <pre class="mb-3">openssl genrsa -aes256 -out key.pem 2048
 openssl req -new -key key.pem -out csr.pem</pre>
+        <p>Keep the file <code>key.pem</code> safe and secure</p>
       </div>
     </div>
   </div>