Last modified by Aysegül Omus on 2024/03/18 14:45

Hide last authors
Aysegül Omus 109.1 1 x
wikibot 1.1 2
Aysegül Omus 109.1 3 ----
wikibot 1.1 4
Aysegül Omus 109.1 5 ----
wikibot 1.1 6
Aysegül Omus 109.1 7 = Install CIT Client Certificate =
wikibot 1.1 8
Aysegül Omus 109.1 9 This describes how to install the ITO certificate.
wikibot 1.1 10
11
Aysegül Omus 109.1 12 On this [[page>>https://xwiki.rbg.tum.de/bin/view/Informatik/Helpdesk/BenutzerZertifikate]] you will find further information on applying for and extending the CIT user certificate.
wikibot 1.1 13
14
15
Aysegül Omus 109.1 16 {{toc/}}
wikibot 1.1 17
Aysegül Omus 109.1 18
19
20 == 1. How do I install a certificate? ==
21
22 The following instructions were made for specific configurations (OS + Software). If you use a different configuration or have problems with the installation, please feel free to visit the [[Helpdesk>>Informatik.Helpdesk.WebHome]].
23
wikibot 1.1 24 === 1.1. Browser ===
25
26 ==== 1.1.1. Google Chrome ====
27
Aysegül Omus 109.1 28 Google Chrome was tested in Version 65.0.3325.181 under Windows 10 & Mac OS High Sierra. Chrome uses the certificate via the integration in the OS (look below). Despite the successful installation of the certificate, it did not work under Mac OS High Sierra with the Chrome Browser.
wikibot 1.1 29
Aysegül Omus 76.1 30 {{id name="WinFirefoxAnchor"/}}
wikibot 1.1 31
Aysegül Omus 109.1 32
wikibot 1.1 33 ==== 1.1.2. Firefox ====
34
Aysegül Omus 109.1 35 * For the Installation of the certificate, you have to open the Preferences:
Begüm Balat 77.1 36
Aysegül Omus 76.1 37 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_0.png||alt="firefox_0.png" height="572" title="firefox_0.png" width="316"]]
38
Begüm Balat 77.1 39
40
41
Aysegül Omus 109.1 42
43 * Under the Menu go to **→Privacy & Security →View Certificates**:
44
Aysegül Omus 76.1 45 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_1.PNG||alt="firefox_1.PNG" height="727" title="firefox_1.PNG" width="671"]]
Begüm Balat 77.1 46
wikibot 1.1 47
Aysegül Omus 109.1 48
49 * There, go to **Your Certificates** and then to **Import**. Afterward, choose your certificate with the suffix **.p12** and click **open**.
50
Aysegül Omus 76.1 51 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_2.PNG||alt="firefox_2.PNG" height="453" title="firefox_2.PNG" width="920"]]
52
Begüm Balat 77.1 53
Aysegül Omus 109.1 54 * In the next window, you have to fill in your passphrase:
Begüm Balat 77.1 55
Aysegül Omus 76.1 56 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_3.PNG||alt="firefox_3.PNG" height="153" title="firefox_3.PNG" width="598"]]
Begüm Balat 77.1 57
Aysegül Omus 109.1 58 * Your certificate was imported successfully.
wikibot 1.1 59
Aysegül Omus 109.1 60 ==== 1.1.3. Safari ====
wikibot 1.1 61
Aysegül Omus 109.1 62 If the certificate is imported into the keychain (Schlüsselbund), it will automatically be integrated into Safari.
wikibot 1.1 63
Aysegül Omus 109.1 64 === 1.2. Email-Client ===
wikibot 1.1 65
66
Aysegül Omus 109.1 67 ==== 1.2.1. Thunderbird (Windows/Linux) ====
wikibot 1.1 68
69
Begüm Balat 77.1 70
Aysegül Omus 109.1 71 On the bottom left you'll find a cog wheel, click on it to open settings.
wikibot 1.1 72
Aysegül Omus 109.1 73 [[image:1710762049501-575.png]]
Aysegül Omus 76.1 74
wikibot 1.1 75
Aysegül Omus 109.1 76 Next up, click on the Lock Icon on the left bar and scroll down until you find the certificates section. Click on "**Manage Certificates**".
wikibot 1.1 77
Aysegül Omus 109.1 78 (Make sure you downloaded your "**certificate with private key**" from https:~/~/my.ito.cit.tum.de/zertifikat/ )
Begüm Balat 77.1 79
Aysegül Omus 109.1 80 [[image:1710762103262-173.png]]
wikibot 1.1 81
Begüm Balat 77.1 82
wikibot 1.1 83
Begüm Balat 77.1 84
Aysegül Omus 109.1 85 Go to the "**My Certificates**"-Section and click on **import** and select the certificate you previously downloaded.
Begüm Balat 77.1 86
Aysegül Omus 109.1 87 [[image:importieren.png||height="506" width="1021"]]
Begüm Balat 77.1 88
89
wikibot 1.1 90
Aysegül Omus 109.1 91 You'll be prompted to enter the passphrase that you received when you requested a certificate on the website mentioned above.
wikibot 1.1 92
Aysegül Omus 109.1 93 [[image:passphraseeingeben.png||height="517" width="1042"]]
wikibot 1.1 94
95
Begüm Balat 77.1 96
Aysegül Omus 109.1 97 (% class="box infomessage" %)
98 (((
99 (In case you forgot it, request a new certificate, wait a bit, refresh the website and download the certificate, and try again.)
100 )))
101
102
103 Lastly, click on the icon **above** the **puzzle piece**.
104
105 [[image:1710762127504-179.png]]
106
107
108 On the left, light grey colored column click on "**End-to-End-Encryption**" and scroll down until you find "**S/MIME**".
109
110 [[image:1710762116312-799.png]]
111
112
113
114
115 Click on **Select** and you'll be offered only one option, select it.
116
117 [[image:zertifikatauswählenfüraccount.png||height="448" width="1106"]]
118
119 Confirm any window that may pop up right afterward. That's it, congratulations!
120
121 [[image:zertifikatauswählenfueraccount3.png||height="522" width="1101"]]
122
123 ==== ====
124
125 [[image:zertifikateausgewähltfueraccount.png||height="532" width="1122"]]
126
127
128
129
130
131 ==== 1.2.3. Windows-Outlook 2016 ====
132
133 * In the Menu go to **File** → **Options**:
134
Aysegül Omus 76.1 135 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_0.PNG||alt="outlook_0.PNG" height="472" title="outlook_0.PNG" width="754"]]
wikibot 1.1 136
Begüm Balat 77.1 137
138
139
Aysegül Omus 109.1 140 * Now go to **Trust Center** → **Preferences for the Trust Center...**
141
Aysegül Omus 76.1 142 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_1.PNG||alt="outlook_1.PNG" height="545" title="outlook_1.PNG" width="756"]]
wikibot 1.1 143
Begüm Balat 77.1 144
145
146
Aysegül Omus 109.1 147 * Then go to **E-Mail-Security** → **Import/Export**:
148
Aysegül Omus 76.1 149 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_2.PNG||alt="outlook_2.PNG" height="549" title="outlook_2.PNG" width="759"]]
wikibot 1.1 150
Aysegül Omus 76.1 151
Aysegül Omus 109.1 152
153
154 * In the next window click on **Open...** and choose your certificate with the suffix **.p12**.
155 * The passphrase can be entered in the field **Password**. Verify your password with **OK**:
156
Aysegül Omus 76.1 157 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_3.PNG||alt="outlook_3.PNG" height="550" title="outlook_3.PNG" width="1096"]]
wikibot 1.1 158
Begüm Balat 77.1 159
wikibot 1.1 160
Aysegül Omus 76.1 161
Aysegül Omus 109.1 162 * The following message can be accepted with **OK**:
163
164 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_4.PNG||alt="outlook_4.PNG" height="389" title="outlook_4.PNG" width="354"]]
165
166
167
168
169 * Your certificate was imported successfully into Outlook.
170 * Using the following settings, you can set the encryption/signature as default:
171
Aysegül Omus 76.1 172 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_5.PNG||alt="outlook_5.PNG" height="569" title="outlook_5.PNG" width="782"]]
wikibot 1.1 173
Begüm Balat 77.1 174
wikibot 1.1 175
176
Aysegül Omus 109.1 177 * You can go to **Options** and use the following options to enable or disable the **encryption/signature**:
wikibot 1.1 178
Aysegül Omus 109.1 179 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_6.PNG||alt="outlook_6.PNG" height="127" title="outlook_6.PNG" width="493"]]
wikibot 1.1 180
Begüm Balat 77.1 181
wikibot 1.1 182
183
Aysegül Omus 109.1 184 ==== 1.2.4. Mac-Outlook 2019 ====
wikibot 1.1 185
Aysegül Omus 109.1 186 First, click **Outlook** in the tab, then **Preferences**.
wikibot 1.1 187
Aysegül Omus 109.1 188 [[image:outlookpreferences.png||height="335" width="235"]]
wikibot 1.1 189
190
191
192
Aysegül Omus 109.1 193 Select **Accounts**.
wikibot 1.1 194
Aysegül Omus 109.1 195 [[image:accounts.png||width="900"]]
wikibot 1.1 196
197
198
199
200
201
Aysegül Omus 109.1 202 Then select your CIT account in the open window on the left and click on **Advanced**.
wikibot 1.1 203
Aysegül Omus 109.1 204 [[image:advanced.png||width="900"]]
wikibot 1.1 205
206
207
208
209
Aysegül Omus 109.1 210 Click in the **Security** tab and select the ITO certificate for signing and encrypting the emails.
wikibot 1.1 211
Aysegül Omus 109.1 212 [[image:4certnotselected.png||width="900"]]
wikibot 1.1 213
214
Aysegül Omus 109.1 215 [[image:5chooseacertificate.png||height="191" width="425"]]
wikibot 1.1 216
217
Aysegül Omus 109.1 218 [[image:6certauswaehlen.png||height="676" width="728"]]
wikibot 1.1 219
220
221
222
223
Aysegül Omus 109.1 224 Confirm your selection with **OK**.
wikibot 1.1 225
Aysegül Omus 109.1 226 [[image:7certausgewaehltok.png||height="526" width="724"]]
wikibot 1.1 227
228
Aysegül Omus 109.1 229 === 1.3. Operating Systems ===
wikibot 1.1 230
231
Aysegül Omus 109.1 232 ==== 1.3.1. Windows ====
wikibot 1.1 233
Aysegül Omus 109.1 234 The certificate is installed on the whole OS, meaning it can be used by **Internet Explorer** and **Windows Mail** (but not for Firefox).
wikibot 1.1 235
Aysegül Omus 109.1 236 * usually, you can double-click on the certificate, and the certificate-import-assistance will start; if the certificate-import-assistance won't start, follow the guide that follows:
237 * In the start menu, click on **Control Panel** and afterward choose **Internet options**.
wikibot 1.1 238
Aysegül Omus 109.1 239 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/internetOptionen.png]]
wikibot 1.1 240
241
242
243
Aysegül Omus 109.1 244 * Then choose **Contents** and then choose **Certificates**:
wikibot 1.1 245
Aysegül Omus 109.1 246 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/inhalteZertifikate.png]]
wikibot 1.1 247
248
249
250
Aysegül Omus 109.1 251 * Go to **Your Certificates** and then choose **Import...**:
wikibot 1.1 252
Aysegül Omus 109.1 253 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatImportieren.png]]
wikibot 1.1 254
255
256
Aysegül Omus 109.1 257 {{id name="WinAssistentAnchor"/}}
wikibot 1.1 258
Aysegül Omus 109.1 259 * Now the certificate-import-assistance will start; click on **Continue**.
260 * Click **Open** and choose the certificate - choose the suffix **.pfx or .p12 , else you won't** be able to see the files.
wikibot 1.1 261
Aysegül Omus 109.1 262 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatFormat.png]]
wikibot 1.1 263
264
265
266
Aysegül Omus 109.1 267 * Click on **Continue**
268 * Enter the passphrase
269 * Also choose to make your key exportable and then click on **Continue**.
Aysegül Omus 83.1 270
Aysegül Omus 109.1 271 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatPassphrase.png]]
wikibot 1.1 272
273
274
275
Aysegül Omus 109.1 276 * In this windows just click on **Continue**.
wikibot 1.1 277
Aysegül Omus 109.1 278 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatSpeicher.png]]
wikibot 1.1 279
280
281
282
Aysegül Omus 109.1 283 * In the end, click on **Finish** and verify the last window with **OK**.
wikibot 1.1 284
Aysegül Omus 109.1 285 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/importvorgangErfolgreich.png]]
wikibot 1.1 286
287
288
289
Aysegül Omus 109.1 290 * Your certificate should be visible under **Your Certificates**.
wikibot 1.1 291
Aysegül Omus 109.1 292 ==== 1.3.2. Mac OS X ====
wikibot 1.1 293
Aysegül Omus 109.1 294 Double click on your certificate
wikibot 1.1 295
Aysegül Omus 109.1 296 * Now in the **Add Certificates** - Window click on **Add**
wikibot 1.1 297
Aysegül Omus 109.1 298 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/appleCertificate.png]]
wikibot 1.1 299
300
301
302
Aysegül Omus 109.1 303 * Enter your certificate-passphrase
wikibot 1.1 304
Aysegül Omus 109.1 305 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/applePasswd.png]]
wikibot 1.1 306
307
308
309
Aysegül Omus 109.1 310 * The certificate is now ready to use and can, for example, be used in Apple Mail to sign and encrypt your messages.
wikibot 1.1 311
Aysegül Omus 109.1 312 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/applemail_1.png||alt="applemail_1.png" height="307" title="applemail_1.png" width="466"]]
wikibot 1.1 313
314
315
Aysegül Omus 109.1 316 ==== 1.2.3. Windows-Outlook 2019 ====
wikibot 1.1 317
Aysegül Omus 109.1 318 ===== 1.2.3.1. Install certificate =====
wikibot 1.1 319
320
321
Aysegül Omus 109.1 322 Open Outlook and click **File** in the tab.
wikibot 1.1 323
Aysegül Omus 109.1 324 [[image:20file.png||width="900"]]
wikibot 1.1 325
326
327
Aysegül Omus 109.1 328
329 Then open **Options** in the left area.
Begüm Balat 77.1 330
Aysegül Omus 109.1 331 [[image:1options.png||width="900"]]
wikibot 1.1 332
Begüm Balat 77.1 333
wikibot 1.1 334
Aysegül Omus 109.1 335
336 In the opened window select **Trustcenter**
wikibot 1.1 337
Aysegül Omus 109.1 338 [[image:2trustcenter.png||width="1000"]]
wikibot 1.1 339
340
341
342
Aysegül Omus 109.1 343 Click the **Settings** button for the trust center.
wikibot 1.1 344
Aysegül Omus 109.1 345 [[image:3trustcentersettings.png||width="1000"]]
wikibot 1.1 346
347
Aysegül Omus 76.1 348
Aysegül Omus 109.1 349
350 In the next dialog box, click **Security Center** and then on **E-Mail Security**. Under the Digital IDs (Certificates) section, select **Import / Export**.
wikibot 1.1 351
Aysegül Omus 109.1 352 [[image:1trustcenteremailsecuritsimportexport.png||width="900"]]
353
Aysegül Omus 76.1 354
wikibot 1.1 355
356
Aysegül Omus 109.1 357 In the opened window go to **Search**. Select the correct certificate and confirm with **OK**. For **Import / Export digital ID** enter the password that was assigned during the export process from Firefox has been. Then click **OK**.
wikibot 1.1 358
Aysegül Omus 109.1 359 [[image:35importexport.png||height="814" width="743"]]
360
wikibot 1.1 361
362
Aysegül Omus 109.1 363
364 You can complete the process with **OK**, then the medium security level will be selected. You can also click Set security level to adjust this setting.
wikibot 1.1 365
Aysegül Omus 109.1 366 [[image:16setsecuritylevel.png||width="900"]]
367
wikibot 1.1 368
369
Aysegül Omus 109.1 370
371 You can choose medium or high security levels.
wikibot 1.1 372
Aysegül Omus 109.1 373 [[image:17highsecuritylevel.png||height="584" width="775"]]
374
wikibot 1.1 375
376
Aysegül Omus 109.1 377
378 If you select the high security level, you must choose a password that you have to use before encrypting and decrypting the e-mail.
wikibot 1.1 379
Aysegül Omus 109.1 380 [[image:18createapassword.png||width="900"]]
381
wikibot 1.1 382
383
Aysegül Omus 109.1 384
385 Confirm the change with **OK** and then close all windows. If you want to select the medium security level, you have to click **Set security level** again.
wikibot 1.1 386
Aysegül Omus 109.1 387 [[image:91importinganewprivateexchangekey.png||width="900"]]
388
wikibot 1.1 389
Aysegül Omus 109.1 390
391
392 If you want to write an encrypted email, you have to enter the chosen password.
393
394 [[image:30emailverfassen.png||width="900"]]
395
396
397
398
399
400 ===== 1.2.3.2. Sign and encrypt emails =====
401
402 Your ITO certificate has now been imported into Outlook and you can select it under **Encrypted e-mail messages** using the **Settings** button for the e-mail address.
403
404
405 [[image:Out51.png||width="900"]]
406
407
408
409
410 You should see the certificate you just installed under **Signature Certificate** and **Encryption Certificate**. If this is not the case, you still have to select the certificate by clicking the **Select** button.
411
412 [[image:Out61.png||width="900"]]
413
414
415
416
417 Here you can see the issuer of the certificate and the expiry date.
418
419 [[image:Out71.png||width="900"]]
420
421
422
423
424
425 == 2. FAQ ==
426
427
428 === My certificate is in .pem format, but my program only accepts .p12 format. What should I do? ===
429
430 The certificate you downloaded from the Self-Service Portal (ssp.cit.tum.de) is in .pem format, and some client programs do not support it. This problem is easily solved. All you have to do is find a program that accepts .pem files. Firefox is one of them, and since it is widespread, we'll assume that Firefox is being used for this guide.
431
432 Now to the real issue: 
433
434 1) Make sure your old expired certificate is installed in Firefox. If it is not installed there, you must export the old certificate from another application and import it into Firefox. How to export a certificate can be found in our [[Wiki instructions>>https://xwiki.rbg.tum.de/bin/view/Informatik/Helpdesk/ZertifikatExportieren#Firefox]].
435
436 2) Import the new certificate (.pem-file) in Firefox. How to install a certificate can be found above on this page.
437
438 3) Export the new certificate from Firefox.
439
440
441 Voilà! Now you have a new .p12 file, which can be imported into other programs as usual.
442
443
444 **Note**: Please be aware that when importing the new .p12 file, you must change its settings as usual. In particular, you must also adjust the account settings for Thunderbird. Select the new certificate under **Account Settings** -> **End-to-End Encryption** -> **S/MIME**.
445
446 If you encounter some problems, contact: support@ito.cit.tum.de