Difference between revisions of "How To Install The Root Certificate"

From ECE Information Technology Services
Jump to navigationJump to search
(New Page)
 
(Obsolete)
 
(6 intermediate revisions by one other user not shown)
Line 1: Line 1:
−
<!--Originally written on: 2008-Mar-18-->
+
This page is obsolete. ECE no longer runs its own certificate authority, as of May 30, 2019.
−
 
 
−
Some of ECE's SSL-encrypted departmental and research group websites each have
 
−
server certificates which have been signed by the Department's Certficate
 
−
Authority (CA).  Being self-signed, the Department's Root Certificate is not
 
−
recognized by any web browser, be it Mozilla Firefox, Internet Explorer or
 
−
other. Therefore, your web browser will warn you that it cannot the identity
 
−
of the webserver when when accessing these websites.
 
−
 
 
−
To avoid these warnings, you should add the ECE Department's Root Certificate
 
−
to your browser's list of trusted certificate authorities.  After adding the
 
−
Root Certificate, you should no longer receive warnings about our server
 
−
certificates (until the ECE Root Certificate expires in May 2009).
 
−
 
 
−
To install the Root Certificate, please find application-specific instructions
 
−
below.  Please note that you may need to delete the previously installed ECE
 
−
Certificate Authority certificate (aka Root Certificate) before installing the
 
−
new one.  Instructions on managing certificate authorities is included below.
 
−
 
 
−
Please ensure that the certificate you retrieve has the following
 
−
fingerprint(s):
 
−
* SHA1 Fingerprint=03:41:BF:BF:06:6C:CD:8B:6C:38:73:4B:5C:DD:5C:F5:15:C9:70:5F
 
−
* MD5 Fingerprint=0C:15:56:8D:04:A5:9B:FF:D0:A1:F5:AE:06:C4:14:87
 
−
 
 
−
 
 
−
===Internet Explorer on Windows and Safari on Windows===
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [[CA.ece.ubc.ca.crt]].
 
−
# If using Internet Explorer, click on the "Open" button in the dialog that appears.  If using Safari, double-click the ''CA.ece.ubc.ca.crt'' file that is saved to your Desktop to open it.
 
−
# In the "Details" tab, verify that the SHA1 thumbprint matches the one listed shown above.
 
−
# In the "General" tab, click on the 'Install Certificate...' button in the window that opens.
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one,
 
−
if necessary):
 
−
 
 
−
# In the Windows Control Panel, select "Internet Options" to open the "Internet Options" dialog box.  (In Internet Explorer, the "Internet Options" dialog box can also be accessed via the "Tools" menu.)
 
−
# Select the "Content" tab and click on the "Certificates..." button to open the "Certificates" dialog box.
 
−
# Select the "Trusted Root Certification Authorities" tab.
 
−
# Find the certificate you wish to manage / remove.  Our certificate appears as "ECE Certificate Authority".
 
−
 
 
−
 
 
−
===Mozilla (verified with Mozilla version 1.7 and Netscape 7.1)===
 
−
Note: The Netscape browser (6.0 and above) is a rebranded Mozilla browser.
 
−
 
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [[CA.ece.ubc.ca.crt]].
 
−
# On the dialog box that appears, check all three boxes:
 
−
::* Trust this CA to identify web sites.
 
−
::* Trust this CA to identify email users.
 
−
::* Trust this CA to identify software developers.
 
−
# Click on the "View" button and verify the SHA1 and MD5 thumbprints with those above.
 
−
# Click the "OK" to install the certificate.
 
−
 
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one,
 
−
if necessary):
 
−
 
 
−
# From the "Edit" menu, select "Preferences..." to open the "Preferences" dialog box.
 
−
# Expand the "Privacy & Security" group and select the "Certificates" panel.
 
−
# Click on the "Manage Certificates..." button to open the "Certificate Manager" dialog box.
 
−
# Select the "Authorities" tab.
 
−
# Find the certificate you wish to manage / delete.  Our certificate appears under "University of British Columbia."
 
−
 
 
−
 
 
−
===Mozilla Firefox (verified with Mozilla Firefox 2.0)===
 
−
 
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [[CA.ece.ubc.ca.crt]].
 
−
# On the dialog box that appears, check all three boxes:
 
−
::* Trust this CA to identify web sites.
 
−
::* Trust this CA to identify email users.
 
−
::* Trust this CA to identify software developers.
 
−
# Click on the "View" button and verify the SHA1 and MD5 thumbprints with those above.
 
−
# Click the "OK" to install the certificate.
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one,
 
−
if necessary):
 
−
 
 
−
# From the "Tools" menu, select "Options..." to open the "Options" dialog
 
−
box.
 
−
# Click on the "Advanced" icon, then click on the "View Certificates" button to open the "Certificate Manager" dialog box.
 
−
# Select the "Authorities" tab.
 
−
# Find the certificate you wish to manage / delete.  Our certificate appears under "University of British Columbia."
 
−
 
 
−
 
 
−
===Safari and Mac OS/X 10.3 (verified with Mac OS/X 10.3)===
 
−
To install the Root Certificate:
 
−
 
 
−
# Click here, [[CA.ece.ubc.ca.crt]], and download the file to your Desktop.
 
−
# Double click on the ''CA.ece.ubc.ca.crt'' file.  The "Keychain Access" application will open and a certificate import dialog box will appear.
 
−
# Select X509 Anchors from the drop down list in the import window.
 
−
# Click on the 'Install Certificate...' button.
 
−
 
 
−
To manage already installed certificates (so that you can delete the old one, if necessary):
 
−
 
 
−
# Open the "Keychain Access" application (usually found in ''/Applications/Utilities/'')
 
−
# If X509Anchors is not one of the keychains listed in the right hand pane, select "Add Keychain..." from the "Open" menu.  From the "File Open" dialog box, select ''/System/Library/Keychains/X509Anchors''.
 
−
# Find the certificate you wish to manage / delete.  Our certificate appears under "ECE Certificate Authority."
 

Latest revision as of 12:42, 2 January 2020

This page is obsolete. ECE no longer runs its own certificate authority, as of May 30, 2019.