Last modified by Aysegül Omus on 2025/01/31 12:25

Show last authors
1 = Install CIT Client Certificate =
2
3 This describes how to install the CIT certificate.
4
5 On this [[page>>https://xwiki.rbg.tum.de/bin/view/Informatik/Helpdesk/BenutzerZertifikate]], you will find further information on applying for and extending the CIT user certificate.
6
7
8
9 {{toc/}}
10
11
12
13
14 The following instructions were made for specific configurations (OS + Software). If you use a different configuration or have problems with the installation, please feel free to visit the [[Helpdesk>>CIT.ITO.Docs.Guides.Helpdesk.WebHome]].
15
16 == 1. Browser ==
17
18 === 1.1. Google Chrome ===
19
20 Google Chrome was tested in Version 65.0.3325.181 under Windows 10 & Mac OS High Sierra. Chrome uses the certificate via the integration in the OS (look below). Despite the successful installation of the certificate, it did not work under Mac OS High Sierra with the Chrome Browser.
21 {{id name="WinFirefoxAnchor"/}}
22
23
24 === 1.2. Firefox ===
25
26 * For the Installation of the certificate, you have to open the Preferences:
27 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_0.png||alt="firefox_0.png" height="572" title="firefox_0.png" width="316"]]
28
29 * Under the Menu go to **→Privacy & Security →View Certificates**:
30 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_1.PNG||alt="firefox_1.PNG" height="727" title="firefox_1.PNG" width="671"]]
31
32 * There, go to **Your Certificates** and then to **Import**. Afterward, choose your certificate with the suffix **.p12** and click **open**.
33
34 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_2.PNG||alt="firefox_2.PNG" height="453" title="firefox_2.PNG" width="920"]]
35
36
37 * In the next window, you have to fill in your passphrase:
38
39 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/firefox_3.PNG||alt="firefox_3.PNG" height="153" title="firefox_3.PNG" width="598"]]
40
41 * Your certificate was imported successfully.
42
43 === 1.3. Safari ===
44
45 If the certificate is imported into the keychain (Schlüsselbund), it will automatically be integrated into Safari.
46
47 == 2. Email-Client ==
48
49
50 === 2.1. Thunderbird (Windows/Linux) ===
51
52
53
54 On the bottom left, you'll find a cog wheel; click on it to open settings.
55
56 [[image:1710762049501-575.png]]
57
58
59 Next up, click the Lock Icon on the left bar and scroll until you find the certificates section. Click on "**Manage Certificates**".
60
61 (Make sure you downloaded your "**certificate with private key**" from https:~/~/my.ito.cit.tum.de/zertifikat/ )
62 [[image:1710762103262-173.png]]
63
64
65
66
67 Go to the "**My Certificates**"-Section, click on **import**, and select the certificate you previously downloaded.
68 [[image:importieren.png||height="506" width="1021"]]
69
70
71
72 You'll be prompted to enter the passphrase you received when requesting a certificate on the website mentioned above.
73 [[image:passphraseeingeben.png||height="517" width="1042"]]
74
75
76
77 (% class="box infomessage" %)
78 (((
79 (In case you forgot it, request a new certificate, wait a bit, refresh the website, download the certificate, and try again.)
80 )))
81
82
83 Lastly, click on the icon **above** the **puzzle piece**.
84 [[image:1710762127504-179.png]]
85
86
87 On the left, in the light grey column, click **End-to-End-Encryption** and scroll down until you find **S/MIME**.
88 [[image:1710762116312-799.png]]
89
90
91
92
93 Click on **Select**, and you'll be offered only one option: select it.
94
95 [[image:zertifikatauswählenfüraccount.png||height="448" width="1106"]]
96
97 Confirm any window that may pop up right afterward. That's it, congratulations!
98
99 [[image:zertifikatauswählenfueraccount3.png||height="522" width="1101"]]
100
101
102
103 [[image:zertifikateausgewähltfueraccount.png||height="532" width="1122"]]
104
105
106
107
108
109 === 2.2. Windows-Outlook 2016 ===
110
111 * In the Menu go to **File** → **Options**:
112 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_0.PNG||alt="outlook_0.PNG" height="472" title="outlook_0.PNG" width="754"]]
113
114
115 * Now go to **Trust Center** → **Preferences for the Trust Center...**
116 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_1.PNG||alt="outlook_1.PNG" height="545" title="outlook_1.PNG" width="756"]]
117
118
119 * Then go to **E-Mail-Security** → **Import/Export**:
120 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_2.PNG||alt="outlook_2.PNG" height="549" title="outlook_2.PNG" width="759"]]
121
122
123 * In the next window click on **Open...** and choose your certificate with the suffix **.p12**.
124 * The passphrase can be entered in the field **Password**. Verify your password with **OK**:
125 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_3.PNG||alt="outlook_3.PNG" height="550" title="outlook_3.PNG" width="1096"]]
126
127
128 * The following message can be accepted with **OK**:
129 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_4.PNG||alt="outlook_4.PNG" height="389" title="outlook_4.PNG" width="354"]]
130
131
132 * Your certificate was imported successfully into Outlook.
133 * Using the following settings, you can set the encryption/signature as default:
134 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_5.PNG||alt="outlook_5.PNG" height="569" title="outlook_5.PNG" width="782"]]
135
136
137 * You can go to **Options** and use the following options to enable or disable the **encryption/signature**:
138 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/outlook_6.PNG||alt="outlook_6.PNG" height="127" title="outlook_6.PNG" width="493"]]
139
140
141 === 2.3. Windows-Outlook 2019 ===
142
143
144 Open Outlook and click **File** in the tab.
145 [[image:20file.png||width="900"]]
146
147
148 Then open **Options** in the left area.
149 [[image:1options.png||width="900"]]
150
151
152 In the opened window, select **Trustcenter**
153 [[image:2trustcenter.png||width="1000"]]
154
155
156 Click the **Settings** button for the trust center.
157 [[image:3trustcentersettings.png||width="1000"]]
158
159
160 In the next dialog box, click **Security Center** and then on **E-Mail Security**. Under the Digital IDs (Certificates) section, select **Import / Export**.
161 [[image:1trustcenteremailsecuritsimportexport.png||width="900"]]
162
163
164 In the opened window, go to **Search**. Select the correct certificate and confirm with **OK**. For **Import / Export digital ID** enter the password that was assigned during the export process from Firefox has been. Then click **OK**.
165 [[image:35importexport.png||height="814" width="743"]]
166 \\You can complete the process with **OK**. Then, the medium security level will be selected. You can also click Set security level to adjust this setting.
167 [[image:16setsecuritylevel.png||width="900"]]
168 \\You can choose medium or high-security levels.
169 [[image:17highsecuritylevel.png||height="584" width="775"]]
170 \\\\If you select the high-security level, you must choose a password that you have to use before encrypting and decrypting the e-mail.
171 [[image:18createapassword.png||width="900"]]
172 \\\\Confirm the change with **OK** and then close all windows. If you want to select the medium security level, you have to click **Set security level** again.
173 [[image:91importinganewprivateexchangekey.png||width="900"]]
174 \\\\If you want to write an encrypted email, you have to enter the chosen password.
175 [[image:30emailverfassen.png||width="900"]]
176
177
178
179 Your ITO certificate has now been imported into Outlook, and you can select it under **Encrypted e-mail messages** using the **Settings** button for the e-mail address.
180 [[image:Out51.png||width="900"]]
181
182
183 You should see the certificate you installed under **Signature Certificate** and **Encryption Certificate**. If not, you still have to select the certificate by clicking the **Select** button.
184 [[image:Out61.png||width="900"]]
185
186
187 Here, you can see the certificate issuer and the expiration date.
188 [[image:Out71.png||width="900"]]
189
190
191
192 === 2.4. Windows Outlook 2021 ===
193
194
195 In Progress
196
197 === 2.5. Mac Outlook 2019 ===
198
199 First, click **Outlook** in the tab, then **Preferences**.
200 [[image:outlookpreferences.png||height="335" width="235"]]
201
202 Select **Accounts**.
203 [[image:accounts.png||width="900"]]
204
205 Then select your CIT account in the open window on the left and click on **Advanced**.
206 [[image:advanced.png||width="900"]]
207
208 Click on the **Security** tab and select the ITO certificate to sign and encrypt the emails.
209 [[image:4certnotselected.png||width="900"]]
210
211 [[image:5chooseacertificate.png||height="191" width="425"]]
212
213 [[image:6certauswaehlen.png||height="676" width="728"]]
214
215 Confirm your selection with **OK**.
216 [[image:7certausgewaehltok.png||height="526" width="724"]]
217
218
219 == 3. Operating Systems ==
220
221
222 === 3.1. Windows ===
223
224 The certificate is installed on the whole OS, meaning it can be used by **Internet Explorer** and **Windows Mail** (but not for Firefox).
225
226 * Usually, you can double-click on the certificate, and the certificate-import-assistance will start; if the certificate-import-assistance doesn't start, follow the guide that follows:
227 * In the start menu, click on **Control Panel** and afterward choose **Internet options**.
228 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/internetOptionen.png]]
229
230
231 * Then choose **Contents** and then choose **Certificates**:
232 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/inhalteZertifikate.png]]
233
234
235 * Go to **Your Certificates** and then choose **Import...**:
236 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatImportieren.png]]
237
238 {{id name="WinAssistentAnchor"/}}
239
240 * Now the certificate-import-assistance will start; click on **Continue**.
241 * Click **Open** and choose the certificate - choose the suffix **.pfx or .p12 , else you won't** be able to see the files.
242 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatFormat.png]]
243
244 * Click on **Continue**
245 * Enter the passphrase
246 * Also choose to make your key exportable and then click on **Continue**.
247 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatPassphrase.png]]
248
249 * In this window, click on **Continue**.
250 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/zertifikatSpeicher.png]]
251
252
253 * In the end, click on **Finish** and verify the last window with **OK**.
254 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/importvorgangErfolgreich.png]]
255
256
257 * Your certificate should be visible under **Your Certificates**.
258
259 === 3.2. Mac OS X ===
260
261 Double-click on your certificate.
262
263 * Now in the **Add Certificates** - Window click on **Add**
264
265 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/appleCertificate.png]]
266
267
268
269
270 * Enter your certificate passphrase
271 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/applePasswd.png]]
272
273
274 * The certificate is now ready to use and can, for example, be used in Apple Mail to sign and encrypt your messages.
275 [[image:https://xwiki.rbg.tum.de/bin/download/Informatik/Helpdesk/BenutzerZertifikate/WebHome/applemail_1.png||alt="applemail_1.png" height="307" title="applemail_1.png" width="466"]]
276
277
278
279
280 == 2. FAQ ==
281
282
283 === My certificate is in .pem format, but my program only accepts .p12 format. What should I do? ===
284
285 The certificate you downloaded from the Self-Service Portal (ssp.cit.tum.de) is in .pem format, and some client programs do not support it. This problem is easily solved. All you have to do is find a program that accepts .pem files. Firefox is one of them, and since it is widespread, we'll assume that Firefox is being used for this guide.
286
287 Now to the real issue: 
288
289 1) Make sure your old expired certificate is installed in Firefox. If it is not installed there, you must export the old certificate from another application and import it into Firefox. How to export a certificate can be found in our [[Wiki instructions>>https://xwiki.rbg.tum.de/bin/view/Informatik/Helpdesk/ZertifikatExportieren#Firefox]].
290
291 2) Import the new certificate (.pem-file) in Firefox. How to install a certificate can be found above on this page.
292
293 3) Export the new certificate from Firefox.
294
295
296 Voilà! Now you have a new .p12 file, which can be imported into other programs as usual.
297
298
299 **Note**: Please be aware that when importing the new .p12 file, you must change its settings as usual. In particular, you must also adjust the account settings for Thunderbird. Select the new certificate under **Account Settings** -> **End-to-End Encryption** -> **S/MIME**.
300
301 If you encounter some problems, contact: support@ito.cit.tum.de