Steps to Enroll for a PKI Digital Certificate on Windows-7 machine *HRA VPN ONLY users please skip to Step # 1 and complete all instructions. PKI Certificate Enrollment for Encryption users with legacy multi-certificates If you are an email encryption user and you have encrypted messages saved / stored dated back to Sep 7 th 2012 when we migrated to 2048 bit encryption, please follow the below instructions so that you are still able to access the legacy email messages. Kindly confirm that you have the knowledge of your current PKI Certificate s private key credentials which are used for Email Encryption and HRA VPN access. Step A (prior to certificate install): Go to https://pki.honeywell.com and then go to TROUBLESHOOTING & SELF-HELP as shown below.
Utilize the following URL to export your previous Digital certificates: NOTE:: Upon completing all export activity and if you know your PKI credentials then skip to Step # 2 & do NOT delete your PTA profile (step 1)
STEP #1 If you are not prompted for your VeriSign PTA password when using HRA VPN or Email encryption, and do NOT know the password you will need to follow the below instructions to generate a new PTA profile. Please use your Windows Start button > Search and enter *.pta as shown below to see if the PTA profile exists. If it exists and you do not know your VeriSign password you will be required to delete the.pta file from your PC. A new PTA profile will then be generated in the following steps during enrollment.
STEP #2. Adding https://pki.honeywell.com site to trusted Site: a. Open Internet Explorer b. Click on Tools (in the menu bar)> Internet Options >Security >Trusted Sites >Sites c. Type in the website: https://pki.honeywell.com and then click on Add If the website is already added to the trusted site you can ignore this step.
STEP #3. Logon to https://pki.honeywell.com STEP #4. Click on Enroll
STEP #5. Complete the enrollment form and a special note for those that do not have the ActiveX PTA client installed on your PC, you will want to install if prompted on the top Internet Explorer information bar. a) Enter your e-mail Address b) Enter your EID c) Enter your LDAP Password d) Enter a revocation Password NOTE: Please use a simple password with no special characters while entering your revocation password (A combination of letters & digits only)
STEP #6. Read the Subscriber Agreement & Scroll down to the bottom of the page & click on Submit
STEP #7. Confirm your e-mail address and click OK to Continue STEP #8. Only for those that deleted *.pta in Step # 1. Those who know their VeriSign password can skip to Step #9.1 below. Click on Next to create a new Profile
STEP #9. In the User Name field your EID will already be populated, you only have to give a password according to your preference > Click Create NOTE: Please remember this password as you would be using the same password for connecting to HRA & for e-mail encryption. STEP #9.1. If you receive the Pop-up message that states You currently have a Profile, would you like to open using that instead? <Click> Yes and enter your EID & VeriSign password again to continue.
STEP #10. Click Continue once the Certificate Enrollment Complete window appears.
STEP #11. If prompted to update your CA certificate with the auto system check, complete the below steps. If your system is current and up to date skip to end. Proceed if your CA requires updating click on OK as shown below:
STEP #12. Click on Open
STEP #13. Click on Install Certificate
STEP #14. Click next once you get the Certificate Import Wizard
STEP #15. Click Next to continue Note: Do not change the default settings Default Settings should be Automatically select the certificate store based on the type of certificate
STEP #16. Click Finish
STEP #17. Click OK to continue
STEP #18. Click Exit and open Outlook to test your encryption as well as the HRA Cisco VPN connectivity. If you have problems with either please see the next 2 pages for location of KB documents. Step # 19. Legacy Certificate Import: Utilize the Import URL below for import instructions to import your legacy certificates.
Troubleshooting Tips and Configuration guides for Post Enrollment problems: Once the enrollment is completed and after using your VPN/HRA & or Outlook email encryption click on Step 2: Post-Enrollment link on the PKI homepage i.e. https://pki.honeywell.com/ to configure your VPN/HRA Client for remote access or to setup your outlook client for email encryption. You will be redirected to the new webpage, where you will find the re-direct link to the VPN/HRA trouble shooting tips and KB documents and instructions to setup and email encryption for Outlook 2003 & 2007.