Difference between revisions of "How To Install The Root Certificate"

From ECE Information Technology Services
Jump to navigationJump to search
m (Reformatted iPhone screenshots as a gallery)
(Obsolete)
 
(3 intermediate revisions by one other user not shown)
Line 1: Line 1:
−
Some of ECE's SSL-encrypted departmental and research group websites each have
+
This page is obsolete. ECE no longer runs its own certificate authority, as of May 30, 2019.
−
server certificates which have been signed by the Department's Certficate
 
−
Authority (CA).  Being self-signed, the Department's Root Certificate is not
 
−
recognized by any web browser, be it Mozilla Firefox, Internet Explorer or
 
−
other. Therefore, your web browser will warn you that it cannot the identity
 
−
of the webserver when when accessing these websites.
 
−
 
 
−
To avoid these warnings, you should add the ECE Department's Root Certificate
 
−
to your browser's list of trusted certificate authorities.  After adding the
 
−
Root Certificate, you should no longer receive warnings about our server
 
−
certificates (until the ECE Root Certificate expires in May 2014).
 
−
 
 
−
To install the Root Certificate, please find application-specific instructions
 
−
below.  Please note that you may need to delete the previously installed ECE
 
−
Certificate Authority certificate (aka Root Certificate) before installing the
 
−
new one.  Instructions on managing certificate authorities is included below.
 
−
 
 
−
Please ensure that the certificate you retrieve has the following
 
−
fingerprint(s):
 
−
* SHA1 Fingerprint=CF:E2:09:72:EF:E8:DC:43:03:19:0E:EB:FF:25:D7:62:CB:6F:57:D2
 
−
* MD5 Fingerprint=87:56:19:C1:5D:A7:17:B5:C3:8A:E5:C8:3B:51:2A:4B
 
−
 
 
−
 
 
−
===Internet Explorer, Safari, and Google Chrome on Windows===
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [http://help.ece.ubc.ca/CA.ece.ubc.ca.crt CA.ece.ubc.ca.crt], to download the certificate.
 
−
# Open the downloaded certificate.  If using Internet Explorer, click on the "Open" button in the dialog that appears.  If using Safari, double-click the ''CA.ece.ubc.ca.crt'' file that is saved to your Desktop to open it.  In Chrome, open the downloaded file through the status bar.
 
−
# In the "Details" tab, verify that the SHA1 thumbprint matches the one listed shown above.
 
−
# In the "General" tab, click on the 'Install Certificate...' button in the window that opens.
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one,
 
−
if necessary):
 
−
 
 
−
# In the Windows Control Panel, select "Internet Options" to open the "Internet Options" dialog box.  (In Internet Explorer, the "Internet Options" dialog box can also be accessed via the "Tools" menu.)
 
−
# Select the "Content" tab and click on the "Certificates..." button to open the "Certificates" dialog box.
 
−
# Select the "Trusted Root Certification Authorities" tab.
 
−
# Find the certificate you wish to manage / remove.  Our certificate appears as "ECE Certificate Authority".
 
−
 
 
−
 
 
−
===Mozilla (verified with Mozilla version 1.7 and Netscape 7.1)===
 
−
Note: The Netscape browser (6.0 and above) is a rebranded Mozilla browser.
 
−
 
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [http://help.ece.ubc.ca/CA.ece.ubc.ca.crt CA.ece.ubc.ca.crt].
 
−
# On the dialog box that appears, check all three boxes:
 
−
::* Trust this CA to identify web sites.
 
−
::* Trust this CA to identify email users.
 
−
::* Trust this CA to identify software developers.
 
−
# Click on the "View" button and verify the SHA1 and MD5 thumbprints with those above.
 
−
# Click the "OK" to install the certificate.
 
−
 
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one,
 
−
if necessary):
 
−
 
 
−
# From the "Edit" menu, select "Preferences..." to open the "Preferences" dialog box.
 
−
# Expand the "Privacy & Security" group and select the "Certificates" panel.
 
−
# Click on the "Manage Certificates..." button to open the "Certificate Manager" dialog box.
 
−
# Select the "Authorities" tab.
 
−
# Find the certificate you wish to manage / delete.  Our certificate appears under "University of British Columbia."
 
−
 
 
−
 
 
−
===Mozilla Firefox (verified with Mozilla Firefox 2.0)===
 
−
 
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [http://help.ece.ubc.ca/CA.ece.ubc.ca.crt CA.ece.ubc.ca.crt].
 
−
# On the dialog box that appears, check all three boxes:
 
−
::* Trust this CA to identify web sites.
 
−
::* Trust this CA to identify email users.
 
−
::* Trust this CA to identify software developers.
 
−
# Click on the "View" button and verify the SHA1 and MD5 thumbprints with those above.
 
−
# Click the "OK" to install the certificate.
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one,
 
−
if necessary):
 
−
 
 
−
# From the "Tools" menu, select "Options..." to open the "Options" dialog box.
 
−
# Click on the "Advanced" icon, then click on the "View Certificates" button to open the "Certificate Manager" dialog box.
 
−
# Select the "Authorities" tab.
 
−
# Find the certificate you wish to manage / delete.  Our certificate appears under "University of British Columbia."
 
−
 
 
−
 
 
−
===Safari and Mac OS/X 10.3 (verified with Mac OS/X 10.3)===
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [http://help.ece.ubc.ca/CA.ece.ubc.ca.crt CA.ece.ubc.ca.crt], and download the file to your Desktop.
 
−
# Double click on the ''CA.ece.ubc.ca.crt'' file.  The "Keychain Access" application will open and a certificate import dialog box will appear.
 
−
# Select X509 Anchors from the drop down list in the import window.
 
−
# Click on the 'Install Certificate...' button.
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one, if necessary):
 
−
 
 
−
# Open the "Keychain Access" application (usually found in ''/Applications/Utilities/'')
 
−
# If X509Anchors is not one of the keychains listed in the right hand pane, select "Add Keychain..." from the "Open" menu.  From the "File Open" dialog box, select ''/System/Library/Keychains/X509Anchors''.
 
−
# Find the certificate you wish to manage / delete.  Our certificate appears under "ECE Certificate Authority."
 
−
 
 
−
 
 
−
===iPhone and iPod Touch (verified with iPhone OS 3.0)===
 
−
To install the Root Certificate:
 
−
 
 
−
# Open this page in Safari, and open this link, [http://help.ece.ubc.ca/CA.ece.ubc.ca.crt CA.ece.ubc.ca.crt].  You should then see an "Install Profile" screen.
 
−
# Tap "More Details", then select the certificate.  Verify the correctness of the signature (BC AD 39 E7 EA 98...) and key identifier (E6 D2 D9 0C 06...).
 
−
# Go back to the "Install Profile" screen and tap the "Install" button.
 
−
<gallery>
 
−
Image:RootCertIPhone1.jpg|Opening the certificate
 
−
Image:RootCertIPhone2.jpg|Verifying the certificate
 
−
</gallery>
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one, if necessary):
 
−
 
 
−
# Open the "Settings" application
 
−
# Under ''General → Profiles'', select "ECE Certificate Authority".
 

Latest revision as of 12:42, 2 January 2020

This page is obsolete. ECE no longer runs its own certificate authority, as of May 30, 2019.