Last modified by Aysegül Omus on 2025/01/31 12:25

Hide last authors
Aysegül Omus 113.1 1 = Install CIT Client Certificate =
wikibot 1.1 2
Aysegül Omus 113.1 3 This describes how to install the CIT certificate.
wikibot 1.1 4
Aysegül Omus 113.1 5 On this [[page>>https://xwiki.rbg.tum.de/bin/view/Informatik/Helpdesk/BenutzerZertifikate]], you will find further information on applying for and extending the CIT user certificate.
wikibot 1.1 6
7
8
Aysegül Omus 113.1 9 {{toc/}}
wikibot 1.1 10
11
12
Aysegül Omus 113.1 13
14 The following instructions were made for specific configurations (OS + Software). If you use a different configuration or have problems with the installation, please feel free to visit the [[Helpdesk>>CIT.ITO.Docs.Guides.Helpdesk.WebHome]].
15
Aysegül Omus 112.1 16 == 1. Browser ==
wikibot 1.1 17
Aysegül Omus 112.1 18 === 1.1. Google Chrome ===
wikibot 1.1 19
Aysegül Omus 113.1 20 Google Chrome was tested in Version 65.0.3325.181 under Windows 10 & Mac OS High Sierra. Chrome uses the certificate via the integration in the OS (look below). Despite the successful installation of the certificate, it did not work under Mac OS High Sierra with the Chrome Browser.
21 {{id name="WinFirefoxAnchor"/}}
wikibot 1.1 22
23
Aysegül Omus 112.1 24 === 1.2. Firefox ===
wikibot 1.1 25
Aysegül Omus 113.1 26 * For the Installation of the certificate, you have to open the Preferences:
Aysegül Omus 76.1 27 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_0.png||alt="firefox_0.png" height="572" title="firefox_0.png" width="316"]]
28
Aysegül Omus 113.1 29 * Under the Menu go to **→Privacy & Security →View Certificates**:
Aysegül Omus 76.1 30 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_1.PNG||alt="firefox_1.PNG" height="727" title="firefox_1.PNG" width="671"]]
Begüm Balat 77.1 31
Aysegül Omus 113.1 32 * There, go to **Your Certificates** and then to **Import**. Afterward, choose your certificate with the suffix **.p12** and click **open**.
wikibot 1.1 33
Aysegül Omus 76.1 34 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_2.PNG||alt="firefox_2.PNG" height="453" title="firefox_2.PNG" width="920"]]
35
Begüm Balat 77.1 36
Aysegül Omus 113.1 37 * In the next window, you have to fill in your passphrase:
Begüm Balat 77.1 38
Aysegül Omus 76.1 39 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_3.PNG||alt="firefox_3.PNG" height="153" title="firefox_3.PNG" width="598"]]
Begüm Balat 77.1 40
Aysegül Omus 113.1 41 * Your certificate was imported successfully.
wikibot 1.1 42
Aysegül Omus 112.1 43 === 1.3. Safari ===
wikibot 1.1 44
Aysegül Omus 113.1 45 If the certificate is imported into the keychain (Schlüsselbund), it will automatically be integrated into Safari.
wikibot 1.1 46
Aysegül Omus 112.1 47 == 2. Email-Client ==
wikibot 1.1 48
Begüm Balat 77.1 49
Aysegül Omus 113.1 50 === 2.1. Thunderbird (Windows/Linux) ===
wikibot 1.1 51
Aysegül Omus 76.1 52
wikibot 1.1 53
Aysegül Omus 113.1 54 On the bottom left, you'll find a cog wheel; click on it to open settings.
wikibot 1.1 55
Aysegül Omus 113.1 56 [[image:1710762049501-575.png]]
Begüm Balat 77.1 57
wikibot 1.1 58
Aysegül Omus 113.1 59 Next up, click the Lock Icon on the left bar and scroll until you find the certificates section. Click on "**Manage Certificates**".
Begüm Balat 77.1 60
Aysegül Omus 113.1 61 (Make sure you downloaded your "**certificate with private key**" from https:~/~/my.ito.cit.tum.de/zertifikat/ )
62 [[image:1710762103262-173.png]]
wikibot 1.1 63
Begüm Balat 77.1 64
65
66
Aysegül Omus 113.1 67 Go to the "**My Certificates**"-Section, click on **import**, and select the certificate you previously downloaded.
68 [[image:importieren.png||height="506" width="1021"]]
Begüm Balat 77.1 69
wikibot 1.1 70
71
Aysegül Omus 113.1 72 You'll be prompted to enter the passphrase you received when requesting a certificate on the website mentioned above.
73 [[image:passphraseeingeben.png||height="517" width="1042"]]
wikibot 1.1 74
Aysegül Omus 109.1 75
76
77 (% class="box infomessage" %)
78 (((
Aysegül Omus 113.1 79 (In case you forgot it, request a new certificate, wait a bit, refresh the website, download the certificate, and try again.)
Aysegül Omus 109.1 80 )))
81
82
Aysegül Omus 113.1 83 Lastly, click on the icon **above** the **puzzle piece**.
84 [[image:1710762127504-179.png]]
Aysegül Omus 109.1 85
86
Aysegül Omus 113.1 87 On the left, in the light grey column, click **End-to-End-Encryption** and scroll down until you find **S/MIME**.
88 [[image:1710762116312-799.png]]
89
Aysegül Omus 109.1 90
91
92
Aysegül Omus 113.1 93 Click on **Select**, and you'll be offered only one option: select it.
Aysegül Omus 109.1 94
Aysegül Omus 113.1 95 [[image:zertifikatauswählenfüraccount.png||height="448" width="1106"]]
Aysegül Omus 109.1 96
Aysegül Omus 113.1 97 Confirm any window that may pop up right afterward. That's it, congratulations!
Aysegül Omus 109.1 98
Aysegül Omus 113.1 99 [[image:zertifikatauswählenfueraccount3.png||height="522" width="1101"]]
Aysegül Omus 109.1 100
101
102
Aysegül Omus 113.1 103 [[image:zertifikateausgewähltfueraccount.png||height="532" width="1122"]]
Aysegül Omus 109.1 104
105
106
107
108
Aysegül Omus 112.1 109 === 2.2. Windows-Outlook 2016 ===
wikibot 1.1 110
Aysegül Omus 113.1 111 * In the Menu go to **File** → **Options**:
Aysegül Omus 76.1 112 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_0.PNG||alt="outlook_0.PNG" height="472" title="outlook_0.PNG" width="754"]]
wikibot 1.1 113
Begüm Balat 77.1 114
Aysegül Omus 113.1 115 * Now go to **Trust Center** → **Preferences for the Trust Center...**
Aysegül Omus 76.1 116 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_1.PNG||alt="outlook_1.PNG" height="545" title="outlook_1.PNG" width="756"]]
wikibot 1.1 117
Begüm Balat 77.1 118
Aysegül Omus 113.1 119 * Then go to **E-Mail-Security** → **Import/Export**:
Aysegül Omus 76.1 120 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_2.PNG||alt="outlook_2.PNG" height="549" title="outlook_2.PNG" width="759"]]
wikibot 1.1 121
Aysegül Omus 76.1 122
Aysegül Omus 113.1 123 * In the next window click on **Open...** and choose your certificate with the suffix **.p12**.
124 * The passphrase can be entered in the field **Password**. Verify your password with **OK**:
Aysegül Omus 76.1 125 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_3.PNG||alt="outlook_3.PNG" height="550" title="outlook_3.PNG" width="1096"]]
wikibot 1.1 126
Begüm Balat 77.1 127
Aysegül Omus 113.1 128 * The following message can be accepted with **OK**:
129 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_4.PNG||alt="outlook_4.PNG" height="389" title="outlook_4.PNG" width="354"]]
wikibot 1.1 130
Aysegül Omus 76.1 131
Aysegül Omus 113.1 132 * Your certificate was imported successfully into Outlook.
133 * Using the following settings, you can set the encryption/signature as default:
Aysegül Omus 76.1 134 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_5.PNG||alt="outlook_5.PNG" height="569" title="outlook_5.PNG" width="782"]]
wikibot 1.1 135
Begüm Balat 77.1 136
Aysegül Omus 113.1 137 * You can go to **Options** and use the following options to enable or disable the **encryption/signature**:
138 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_6.PNG||alt="outlook_6.PNG" height="127" title="outlook_6.PNG" width="493"]]
wikibot 1.1 139
140
Aysegül Omus 112.1 141 === 2.3. Windows-Outlook 2019 ===
wikibot 1.1 142
Begüm Balat 77.1 143
Aysegül Omus 113.1 144 Open Outlook and click **File** in the tab.
145 [[image:20file.png||width="900"]]
wikibot 1.1 146
147
Aysegül Omus 113.1 148 Then open **Options** in the left area.
149 [[image:1options.png||width="900"]]
wikibot 1.1 150
151
Aysegül Omus 113.1 152 In the opened window, select **Trustcenter**
153 [[image:2trustcenter.png||width="1000"]]
wikibot 1.1 154
155
Aysegül Omus 113.1 156 Click the **Settings** button for the trust center.
157 [[image:3trustcentersettings.png||width="1000"]]
wikibot 1.1 158
Aysegül Omus 113.1 159
160 In the next dialog box, click **Security Center** and then on **E-Mail Security**. Under the Digital IDs (Certificates) section, select **Import / Export**.
161 [[image:1trustcenteremailsecuritsimportexport.png||width="900"]]
162
wikibot 1.1 163
Aysegül Omus 113.1 164 In the opened window, go to **Search**. Select the correct certificate and confirm with **OK**. For **Import / Export digital ID** enter the password that was assigned during the export process from Firefox has been. Then click **OK**.
165 [[image:35importexport.png||height="814" width="743"]]
166 \\You can complete the process with **OK**. Then, the medium security level will be selected. You can also click Set security level to adjust this setting.
167 [[image:16setsecuritylevel.png||width="900"]]
168 \\You can choose medium or high-security levels.
169 [[image:17highsecuritylevel.png||height="584" width="775"]]
170 \\\\If you select the high-security level, you must choose a password that you have to use before encrypting and decrypting the e-mail.
171 [[image:18createapassword.png||width="900"]]
172 \\\\Confirm the change with **OK** and then close all windows. If you want to select the medium security level, you have to click **Set security level** again.
173 [[image:91importinganewprivateexchangekey.png||width="900"]]
174 \\\\If you want to write an encrypted email, you have to enter the chosen password.
175 [[image:30emailverfassen.png||width="900"]]
176
wikibot 1.1 177
178
Aysegül Omus 113.1 179 Your ITO certificate has now been imported into Outlook, and you can select it under **Encrypted e-mail messages** using the **Settings** button for the e-mail address.
180 [[image:Out51.png||width="900"]]
wikibot 1.1 181
182
Aysegül Omus 113.1 183 You should see the certificate you installed under **Signature Certificate** and **Encryption Certificate**. If not, you still have to select the certificate by clicking the **Select** button.
184 [[image:Out61.png||width="900"]]
wikibot 1.1 185
186
Aysegül Omus 113.1 187 Here, you can see the certificate issuer and the expiration date.
188 [[image:Out71.png||width="900"]]
wikibot 1.1 189
190
191
Aysegül Omus 113.1 192 === 2.4. Windows Outlook 2021 ===
wikibot 1.1 193
194
Aysegül Omus 113.1 195 In Progress
wikibot 1.1 196
Aysegül Omus 113.1 197 === 2.5. Mac Outlook 2019 ===
wikibot 1.1 198
Aysegül Omus 113.1 199 First, click **Outlook** in the tab, then **Preferences**.
200 [[image:outlookpreferences.png||height="335" width="235"]]
wikibot 1.1 201
Aysegül Omus 113.1 202 Select **Accounts**.
wikibot 1.1 203 [[image:accounts.png||width="900"]]
204
Aysegül Omus 113.1 205 Then select your CIT account in the open window on the left and click on **Advanced**.
wikibot 1.1 206 [[image:advanced.png||width="900"]]
207
Aysegül Omus 113.1 208 Click on the **Security** tab and select the ITO certificate to sign and encrypt the emails.
209 [[image:4certnotselected.png||width="900"]]
wikibot 1.1 210
Aysegül Omus 113.1 211 [[image:5chooseacertificate.png||height="191" width="425"]]
wikibot 1.1 212
Aysegül Omus 113.1 213 [[image:6certauswaehlen.png||height="676" width="728"]]
wikibot 1.1 214
Aysegül Omus 113.1 215 Confirm your selection with **OK**.
216 [[image:7certausgewaehltok.png||height="526" width="724"]]
wikibot 1.1 217
218
Aysegül Omus 113.1 219 == 3. Operating Systems ==
wikibot 1.1 220
221
Aysegül Omus 112.1 222 === 3.1. Windows ===
Begüm Balat 77.1 223
Aysegül Omus 113.1 224 The certificate is installed on the whole OS, meaning it can be used by **Internet Explorer** and **Windows Mail** (but not for Firefox).
Begüm Balat 77.1 225
Aysegül Omus 113.1 226 * Usually, you can double-click on the certificate, and the certificate-import-assistance will start; if the certificate-import-assistance doesn't start, follow the guide that follows:
227 * In the start menu, click on **Control Panel** and afterward choose **Internet options**.
Aysegül Omus 76.1 228 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/internetOptionen.png]]
wikibot 1.1 229
Aysegül Omus 113.1 230
231 * Then choose **Contents** and then choose **Certificates**:
Aysegül Omus 76.1 232 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/inhalteZertifikate.png]]
wikibot 1.1 233
Aysegül Omus 113.1 234
235 * Go to **Your Certificates** and then choose **Import...**:
Aysegül Omus 76.1 236 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatImportieren.png]]
wikibot 1.1 237
Aysegül Omus 76.1 238 {{id name="WinAssistentAnchor"/}}
wikibot 1.1 239
Aysegül Omus 113.1 240 * Now the certificate-import-assistance will start; click on **Continue**.
241 * Click **Open** and choose the certificate - choose the suffix **.pfx or .p12 , else you won't** be able to see the files.
Aysegül Omus 76.1 242 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatFormat.png]]
wikibot 1.1 243
Aysegül Omus 113.1 244 * Click on **Continue**
245 * Enter the passphrase
246 * Also choose to make your key exportable and then click on **Continue**.
Aysegül Omus 76.1 247 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatPassphrase.png]]
wikibot 1.1 248
Aysegül Omus 113.1 249 * In this window, click on **Continue**.
Aysegül Omus 76.1 250 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatSpeicher.png]]
wikibot 1.1 251
Aysegül Omus 113.1 252
253 * In the end, click on **Finish** and verify the last window with **OK**.
Aysegül Omus 76.1 254 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/importvorgangErfolgreich.png]]
wikibot 1.1 255
Aysegül Omus 76.1 256
Aysegül Omus 113.1 257 * Your certificate should be visible under **Your Certificates**.
258
Aysegül Omus 112.1 259 === 3.2. Mac OS X ===
wikibot 1.1 260
Aysegül Omus 113.1 261 Double-click on your certificate.
Aysegül Omus 76.1 262
Aysegül Omus 113.1 263 * Now in the **Add Certificates** - Window click on **Add**
264
Aysegül Omus 76.1 265 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/appleCertificate.png]]
wikibot 1.1 266
Aysegül Omus 113.1 267
268
269
270 * Enter your certificate passphrase
Aysegül Omus 76.1 271 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/applePasswd.png]]
wikibot 1.1 272
Aysegül Omus 113.1 273
274 * The certificate is now ready to use and can, for example, be used in Apple Mail to sign and encrypt your messages.
Aysegül Omus 76.1 275 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/applemail_1.png||alt="applemail_1.png" height="307" title="applemail_1.png" width="466"]]
wikibot 1.1 276
277
278
279
Aysegül Omus 113.1 280 == 2. FAQ ==
wikibot 1.1 281
282
Aysegül Omus 113.1 283 === My certificate is in .pem format, but my program only accepts .p12 format. What should I do? ===
wikibot 1.1 284
Aysegül Omus 113.1 285 The certificate you downloaded from the Self-Service Portal (ssp.cit.tum.de) is in .pem format, and some client programs do not support it. This problem is easily solved. All you have to do is find a program that accepts .pem files. Firefox is one of them, and since it is widespread, we'll assume that Firefox is being used for this guide.
wikibot 1.1 286
Aysegül Omus 113.1 287 Now to the real issue: 
wikibot 1.1 288
Aysegül Omus 113.1 289 1) Make sure your old expired certificate is installed in Firefox. If it is not installed there, you must export the old certificate from another application and import it into Firefox. How to export a certificate can be found in our [[Wiki instructions>>https://xwiki.rbg.tum.de/bin/view/Informatik/Helpdesk/ZertifikatExportieren#Firefox]].
wikibot 1.1 290
Aysegül Omus 113.1 291 2) Import the new certificate (.pem-file) in Firefox. How to install a certificate can be found above on this page.
wikibot 1.1 292
Aysegül Omus 113.1 293 3) Export the new certificate from Firefox.
wikibot 1.1 294
295
Aysegül Omus 113.1 296 Voilà! Now you have a new .p12 file, which can be imported into other programs as usual.
wikibot 1.1 297
Aysegül Omus 113.1 298
299 **Note**: Please be aware that when importing the new .p12 file, you must change its settings as usual. In particular, you must also adjust the account settings for Thunderbird. Select the new certificate under **Account Settings** -> **End-to-End Encryption** -> **S/MIME**.
300
301 If you encounter some problems, contact: support@ito.cit.tum.de