How can I set up CIT certificate?

Last modified by Aysegül Omus on 2024/03/18 14:45

x



Install CIT Client Certificate

This describes how to  install the ITO certificate.

On this page you will find further information on applying for and extending the CIT user certificate.

1. How do I install a certificate?

The following instructions were made for specific configurations (OS + Software). If you use a different configuration or have problems with the installation, please feel free to visit the Helpdesk.

1.1. Browser

1.1.1. Google Chrome

Google Chrome was tested in Version 65.0.3325.181 under Windows 10 & Mac OS High Sierra. Chrome uses the certificate via the integration in the OS (look below). Despite the successful installation of the certificate, it did not work under Mac OS High Sierra with the Chrome Browser.

1.1.2. Firefox

  •  For the Installation of the certificate, you have to open the Preferences:

firefox_0.png

  • Under the Menu go to →Privacy & Security →View Certificates:

firefox_1.PNG

  • There, go to Your Certificates and then to Import. Afterward, choose your certificate with the suffix .p12 and click open.

firefox_2.PNG

  • In the next window, you have to fill in your passphrase:

firefox_3.PNG

  • Your certificate was imported successfully.

1.1.3. Safari

If the certificate is imported into the keychain (Schlüsselbund), it will automatically be integrated into Safari.

1.2. Email-Client

1.2.1. Thunderbird (Windows/Linux)

On the bottom left you'll find a cog wheel, click on it to open settings.

1710762049501-575.png

Next up, click on the Lock Icon on the left bar and scroll down until you find the certificates section. Click on "Manage Certificates".

(Make sure you downloaded your "certificate with private key" from https://my.ito.cit.tum.de/zertifikat/ )

1710762103262-173.png

Go to the "My Certificates"-Section and click on import and select the certificate you previously downloaded.

importieren.png

You'll be prompted to enter the passphrase that you received when you requested a certificate on the website mentioned above.

passphraseeingeben.png

(In case you forgot it, request a new certificate, wait a bit, refresh the website and download the certificate, and try again.)

Lastly, click on the icon above the puzzle piece.

1710762127504-179.png

On the left, light grey colored column click on "End-to-End-Encryption" and scroll down until you find "S/MIME".

1710762116312-799.png
 

Click on Select and you'll be offered only one option, select it.

zertifikatauswählenfüraccount.png

Confirm any window that may pop up right afterward. That's it, congratulations!

zertifikatauswählenfueraccount3.png

zertifikateausgewähltfueraccount.png

1.2.3. Windows-Outlook 2016

  •  In the Menu go to FileOptions:

outlook_0.PNG

  • Now go to Trust CenterPreferences for the Trust Center...

outlook_1.PNG

  • Then go to E-Mail-SecurityImport/Export:

outlook_2.PNG

  • In the next window click on Open... and choose your certificate with the suffix .p12.
  • The passphrase can be entered in the field Password. Verify your password with OK:

outlook_3.PNG

  • The following message can be accepted with OK:

outlook_4.PNG

  • Your certificate was imported successfully into Outlook.
  • Using the following settings, you can set the encryption/signature as default:

outlook_5.PNG

  • You can go to Options and use the following options to enable or disable the encryption/signature:

outlook_6.PNG

1.2.4. Mac-Outlook 2019

First, click Outlook in the tab, then Preferences.

outlookpreferences.png

Select Accounts.

accounts.png

Then select your CIT account in the open window on the left and click on Advanced.

advanced.png

Click in the Security tab and select the ITO certificate for signing and encrypting the emails.

4certnotselected.png

5chooseacertificate.png

6certauswaehlen.png

Confirm your selection with OK.

7certausgewaehltok.png

1.3. Operating Systems

1.3.1. Windows

The certificate is installed on the whole OS, meaning it can be used by Internet Explorer and Windows Mail (but not for Firefox).

  • usually, you can double-click on the certificate, and the certificate-import-assistance will start; if the certificate-import-assistance won't start, follow the guide that follows:
  • In the start menu, click on Control Panel and afterward choose Internet options.

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/internetOptionen.png

  •  Then choose Contents and then choose Certificates:

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/inhalteZertifikate.png

  • Go to Your Certificates and then choose Import...:

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatImportieren.png

  • Now the certificate-import-assistance will start; click on Continue.
  • Click Open and choose the certificate - choose the suffix .pfx or .p12 , else you won't be able to see the files.

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatFormat.png

  • Click on Continue 
  • Enter the passphrase
  • Also choose to make your key exportable and then click on Continue.

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatPassphrase.png

  • In this windows just click on Continue.

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatSpeicher.png

  • In the end, click on Finish and verify the last window with OK

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/importvorgangErfolgreich.png

  • Your certificate should be visible under Your Certificates

1.3.2. Mac OS X

 Double click on your certificate

  • Now in the Add Certificates - Window click on Add

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/appleCertificate.png

  • Enter your certificate-passphrase

https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/applePasswd.png

  • The certificate is now ready to use and can, for example, be used in Apple Mail to sign and encrypt your messages.

applemail_1.png

1.2.3. Windows-Outlook 2019

1.2.3.1. Install certificate

Open Outlook and click File in the tab.

20file.png

 
Then open Options in the left area.

1options.png

 
In the opened window select Trustcenter

2trustcenter.png

Click the Settings button for the trust center.

3trustcentersettings.png

 
In the next dialog box, click Security Center and then on E-Mail Security. Under the Digital IDs (Certificates) section, select Import / Export.

1trustcenteremailsecuritsimportexport.png
 

In the opened window go to Search. Select the correct certificate and confirm with OK. For Import / Export digital ID enter the password that was assigned during the export process from Firefox has been. Then click OK.

35importexport.png
 

 
You can complete the process with OK, then the medium security level will be selected. You can also click Set security level to adjust this setting.

16setsecuritylevel.png
 

 
You can choose medium or high security levels.

17highsecuritylevel.png
 

 
If you select the high security level, you must choose a password that you have to use before encrypting and decrypting the e-mail.

18createapassword.png
 

 
Confirm the change with OK and then close all windows. If you want to select the medium security level, you have to click Set security level again.

91importinganewprivateexchangekey.png
 

 
If you want to write an encrypted email, you have to enter the chosen password.

30emailverfassen.png
 

1.2.3.2. Sign and encrypt emails

Your ITO certificate has now been imported into Outlook and you can select it under Encrypted e-mail messages using the Settings button for the e-mail address.

Out51.png

You should see the certificate you just installed under Signature Certificate and Encryption Certificate. If this is not the case, you still have to select the certificate by clicking the Select button.

Out61.png

Here you can see the issuer of the certificate and the expiry date.

Out71.png

2. FAQ

My certificate is in .pem format, but my program only accepts .p12 format. What should I do?

The certificate you downloaded from the Self-Service Portal (ssp.cit.tum.de) is in .pem format, and some client programs do not support it. This problem is easily solved. All you have to do is find a program that accepts .pem files. Firefox is one of them, and since it is widespread, we'll assume that Firefox is being used for this guide.

Now to the real issue:  

1) Make sure your old expired certificate is installed in Firefox. If it is not installed there, you must export the old certificate from another application and import it into Firefox. How to export a certificate can be found in our Wiki instructions.

2) Import the new certificate (.pem-file) in Firefox. How to install a certificate can be found above on this page.

3) Export the new certificate from Firefox.

Voilà! Now you have a new .p12 file, which can be imported into other programs as usual.

Note: Please be aware that when importing the new .p12 file, you must change its settings as usual. In particular, you must also adjust the account settings for Thunderbird. Select the new certificate under Account Settings -> End-to-End Encryption -> S/MIME.

If you encounter some problems, contact: support@ito.cit.tum.de