Technische Universität München


This describes how to apply for and install the RBG certificate.

Note: Due to the corona pandemic, these conditions apply for activating the certificate.

0. General Information on TUM Informatics and Mathematics Certificates

After requesting a certificate you can find it under:

or on (Students or Informatics Employees), (Mathematics Employees), if you requested it before.

With a certificate you can visit certain websites or even send encrypted E-Mails. For the installation the passphrase is needed, since the certificate is encrypted. After getting your passphrase, your certificate can be found under the mentioned directory or on or

1. Where and how do I request a certificate?

1.1. Students

1.1.1. Freshmen

Usually you will receive your passphrase, the and so on during the preliminary courses in the Infopoint Informatics.

If you did not participate at the preliminary courses you can receive your passphrase from the Infopoint Informatics.

1.1.2. If your certificate expired

In this case you have to request a new certificate via and you can collect the passphrase at the Infopoint Informatik..

1.2. Non-Students

A certificate can be requested either with your User Request (Benutzerantrag) or via (Informatics Employees), (Mathematics Employees) and you can collect your passphrase at our service office (00.05.041) on Mondays or Thursdays from 10:00 to 17:00 with your ID card.

On this page you can retrieve current information regarding working hours.

Note: For each of the described cases holds that a valid photo ID (personal ID or passport) is to be presented during passphrase! collection!

2. How do I request for certificates?

Click on Login at the top left on or

Log in with or

Select the Certificate option on the left.

Select Standard mode here and click Continue, if you also want to download the certificate's private key. In Expert mode you have to create it yourself.

If you want to continue, click Yes.

If the certificate has been requested, you will see detailed informations regarding your certificate request on Self Service Portal.

Click here on Continue. Then you will receive an email with the certificate application. The creation of the certificate requires personal ID control. Please bring the signed application and your valid official photo ID with you.

When your certificate has been issued, you will receive an email and can collect the passphrase of the certificate:

  • Employees: You can collect the passphrase with your ID card from our service office (00.05.041) on Mondays or Thursdays from 10:00 a.m. to 1:00 p.m. and from 2:00 p.m. to 5:00 p.m. On this page you will find current information on opening hours.

3. How long is the certificate valid and how do I renew it?

The new certificate is valid for one year from the expiry date of the old certificate. Before the expiry date you will receive an E-Mail at your

The validity can be reached via this [[] []] (for IT staff and students) or [[ ] []] (for mathematics employees) after the RBG certificate has been applied for once in the SSP and downloaded with the private key.

Note: After the first application for the certificate in the SSP, the certificate with the private key must be installed in the browser so that the certificate can be renewed.

Once you have applied for an RBG certificate in the SSP portal, you can renew it again in the SSP.

To do this, log into the SSP with your valid RBG certificate (must be installed in the browser) and click on Certificate on the left and then click on the plus sign at Extend your certificate. You will then see the details of how to renew the certificate. Then click Request.

Then answer the question with Yes.

Next click on Continue so that your certificate is sent to your RBG E Email address is sent.

You will shortly receive an email with the serial number of the process. Finally, your new RBG certificate will be emailed as follows:

Good afternoon,

Your certificate is in the attachment. You had a certificate the DFN-PKI requested. The serial number of the process is xxxx.

RBG system group

The certificate is now ready to be installed. If you miss to renew your certificate a new request must be made via or

You can receive the passphrase at the service office of the rbg (employees) or at the Infopoint (students), which means that you have to personally pick up the passphrase with your photo identification again. That's why we recommend the Self-Service renewal of the certificate.

  • Employees: On this page you can retrieve current information regarding working hours.
  • Students: On Infopoint Informatik you can retrieve current information regarding working hours.

Exception in the Corona period:
The creation of the certificate requires personal ID check with an appointment. The ID check for issuing the certificate usually takes place via video chat ( / However, we can only accept certain types of ID. You can find the list of accepted ID documents here. If documents are not accepted, they must appear in person.

A smartphone or webcam is required for ID verification via video chat. The camera should have a good resolution and should be able to display the ID badge when it is held close to the camera. This is necessary in order to be able to carry out the ID check in accordance with the requirements of the DFN.

So that we can make an appointment to check your ID, please send us:

  • A scan of your signed certificate application (the form of the signature on the application must match the signature on the ID)
  • The country of issue and the type of ID to be checked
  • The date of issue and expiry of the card

When we have received the required information, we will suggest dates for ID verification. You are welcome to tell us suitable days of the week.

To prepare for the video conference, please note:

  • Have the ID you gave us ready
  • Have the application form you sent us as a scan ready
  • Good lighting conditions are very helpful

We usually provide you with a passphrase through the chat function in BBB during the video conference. Prepare to write them off or take a screenshot.

You can find more information about the certificates on our wiki page:

4. How do I copy the certificate on my computer?

Download from the Self Service Portal

The user certificate can be downloaded from or with the private key.

Copy from the Lxhalle

For the data transfer between the computer hall and your personal computer you can use this instruction.

For Windows Users there is an additional instruction for copying the certificate to one's computer and also a how-to for importing the certificate in the Internet Explorer and Firefox.

5. How do I install a certificate?

The following instructions were made for certain configurations (OS + Software). If you use a different configuration or have problems with the installation please feel free to visit the Helpdesk.

5.1. Browser

5.1.1. Google Chrome

Google Chrome was tested in the Version 65.0.3325.181 under Windows 10 & Mac OS High Sierra. Chrome uses the certificate via the intergration in the OS (look below). Despite the successful installation of the certificate it did not work under Mac OS High Sierra with the Chrome Browser.

5.1.2. Firefox

  • For the Installation of the certificate you have to open the Preferences:

  • Under the Menu go to → Privacy & Security View Certificates:


  • There go to Your Certificates and then on Import . Afterwards choose your certificate with the suffix .p12 and click open.


  • In the next window you have to fill in your passphrase:

  • Your certificate was imported successfully.

5.1.3. Safari

Although the certificate was installed successfully the certificate could not be used with the Safari Brwoser under Mac OS High Sierra.

5.2. Email-Client

5.2.1. Thunderbird

The installation of the certificate in Firefox and Thunderbird is identical.
  • In the Menu choose EditPreferences

  • Then Advanced → Certificates_ and afterwards click on Manage Certificates

  • Choose Your Certificates and then click on Import...

  • Go to your certificate location and choose the certificate (LOGIN.p12) and click on Open

  • Now you have to enter the passphrase (received from the Infopoint or the System Group) and confirm the successful installation of the certificate. Blank spaces and capitalization rules should be considered.

Now under Your Certificates your certificate should be visible.

4.2.2. Windows-Outlook 2016

  • In the Menu go to FileOptions:


  • Now go to Trust CenterPreferences for the Trust Center...


  • Then go to E-Mail-SecurityImport/Export:


  • In the next window click on Open... and choose your certificate with the suffix .p12.
  • The passphrase can be entered in the field Password. Verify your password with OK:


  • The following message can be accepted with OK:


  • Your certificated was imported successfully into Outlook.
  • Using the folllowing settings you can set the encryption/signature as default:


  • You can go to Options and use the following options to enable or disable the encryption/signature:


4.2.3. Mac-Outlook 2019

First click Outlook in the tab, then Preferences.

Select Accounts.

Then select your RBG (in.tum / ma.tum) account in the open window on the left and click on Advanced.
Screenshot 2020-06-19 at 09.38.48 advanced.png

Click in the Security tab and select the RBG certificate for signing and encrypting the emails.
Screenshot 2020-06-19 at 09.39.12-certnotselected.png
Screenshot 2020-06-19 at 09.14.46-chooseacertificate.png
Screenshot 2020-06-19 at 09.15.04-certauswaehlen.png

Confirm your selection with OK.
Screenshot 2020-06-19 at 09.13.31-certausgewaehltok.png

5.3. Operating Systems

5.3.1. Windows

The certificate is installed on the whole OS, which means that it can be used by Internet Explorer and Windows Mail (but not for Firefox - look here). Windows 7 x64 was used for this guide.
  • usually you can double click on the certificate and the certificate-import-assistance will start, then you can click here to continue - if the certificate-import-assistance wont start, follow the guide that follows:
  • In the startmenu click on Control Panel and afterwards choose Internet options.

  • Then choose Contents and then choose Certificates:

  • Go to Your Certificates and then choose Import...:

  • Now the certificate-import-assistance will start, click on Continue.
  • Click Open and choose the certificate - choose the suffix .pfx, or .p12 , else you wont be able to see the files.

  • Click on Continue
  • Enter the passphrase
  • Also choose to make your key exportable and then click on Continue.

  • In this windows just click on Continue.

  • In the end click on Finish verify the last window with OK.

  • Your certificate should be visible under Your Certificates.

5.3.2. Mac OS X

  • Double click on your certificate
  • Now in the Add Certificates - Window click on Add

  • Enter your certificate-passphrase

  • The certificate is now ready to use and can for example be used in Apple Mail to sign and encrypt your messages.


Important KB entries (only available in the MWN network):

1 - Welchen ID I need for issuing the certificate

5.2.3. Windows-Outlook 2019 Install certificate

Open Outlook and click File in the tab.

Then open Options in the left area.

In the opened window select Trustcenter

Click the * Settings * button for the trust center.

In the next dialog box, click Security Center and then on E-Mail Security. Under the Digital IDs (Certificates) section, select Import / Export.

In the opened window go to Search. Select the correct certificate and confirm with OK. For Import / Export digital ID enter the password that was assigned during the export process from Firefox has been. Then click OK.

You can complete the process with OK, then the medium security level will be selected. You can also click Set security level to adjust this setting.

You can choose medium or high security levels.

If you select the high security level, you must choose a password that you have to use before encrypting and decrypting the e-mail.

Confirm the change with OK and then close all windows. If you want to select the medium security level, you have to click Set security level again.

If you want to write an encrypted email, you have to enter the chosen password.
10emailverfassen.png Sign and encrypt emails

Your RBG certificate has now been imported into Outlook and you can select it under Encrypted e-mail messages using the Settings button for the e-mail address.

You should see the certificate you just installed under Signature Certificate and Encryption Certificate. If this is not the case, you still have to select the certificate by clicking the Select button.

Here you can see the issuer of the certificate and the expiry date.

