Entrust Managed Services PKI. Getting an end-user Entrust certificate using Entrust Authority Administration Services. Document issue: 2.



Similar documents
Managed Services PKI 60-day Trial Quick Start Guide

Entrust Managed Services PKI. Getting started with digital certificates and Entrust Managed Services PKI. Document issue: 1.0

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Using Entrust certificates with VPN

Using Entrust certificates with Microsoft Office and Windows

Entrust Managed Services PKI Administrator Guide

Entrust Managed Services PKI

Using Entrust certificates with Adobe PDF files and forms

Installation and Configuration Guide

DIGIPASS CertiID. Getting Started 3.1.0

Personal Secure Certificate

Personal Secure Certificate

VeriSign PKI Client Government Edition v 1.5. VeriSign PKI Client Government. VeriSign PKI Client VeriSign, Inc. Government.

Code Signing Digital IDs GCC Certificate Installation Guide Rev 1.4

Adding Digital Signature and Encryption in Outlook

How To Manage A Password Protected Digital Id On A Microsoft Pc Or Macbook (Windows) With A Password Safehouse (Windows 7) On A Pc Or Ipad (Windows 8) On An Ipad Or Macintosh (Windows 9)

PrivateServer HSM Integration with Microsoft IIS

Using etoken for Securing s Using Outlook and Outlook Express

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Configure SecureZIP for Windows for Entrust Entelligence Security Provider 7.x for Windows

Certificates for computers, Web servers, and Web browser users

Symantec Managed PKI Service Deployment Options

An Introduction to Entrust PKI. Last updated: September 14, 2004

X.509 Certificate Generator User Manual

Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate on Aladdin etoken (Personal eid)

RSA Digital Certificate Solution

Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate (Personal eid) WISeKey 2010 / Alinghi 2010 Smartcards

Guide for Securing With WISeKey CertifyID Personal Digital Certificate (Personal eid)

Microsoft Windows Macros and Visual Basic Signing User Guide

Simple Guide to Digital Signatures

Accessing the Media General SSL VPN

etoken Enterprise For: SSL SSL with etoken

Entrust Certificate Services for Adobe CDS

with PKI Use Case Guide

Check Point FDE integration with Digipass Key devices

SSL User Authentication with the HTTP Security Server

Client Side Digital Certificates User Enrolment Guide

USER GUIDE WWPass Security for Windows Logon

HP ProtectTools Embedded Security Guide

Defender Token Deployment System Quick Start Guide

BlackShield ID MP Token Guide. for Java Enabled Phones

SSL Certificate Based VPN

Defender EAP Agent Installation and Configuration Guide

Microsoft Dynamics GP. Workflow Installation Guide Release 10.0

Requirements Collax Security Gateway Collax Business Server or Collax Platform Server including Collax SSL VPN module

WHITE PAPER ENTRUST ENTELLIGENCE SECURITY PROVIDER 7.0 FOR WINDOWS PRODUCT OVERVIEW. Entrust All rights reserved.

Integration Guide. Microsoft Active Directory Rights Management Services (AD RMS) Microsoft Windows Server 2008

Client configuration and migration Guide Setting up Thunderbird 3.1

How to Secure a Groove Manager Web Site

Set Up Your . HTC Touch Pro.

Installation Guide. SafeNet Authentication Service

User Guide May Using Certificates in Outlook Express

6. Is it mandatory to have the digital certificate issued from NICCA? Is it mandatory for the sender and receiver to have a NIC id?...

Entrust Managed Services PKI Administrator s Quick Start Guide

Deploying and Managing a Public Key Infrastructure

Arkansas Department of Information Systems Arkansas Department of Finance and Administration

ACTIVID APPLIANCE AND MICROSOFT AD FS

Hardware/Software Specifications for Self-Hosted Systems (Multi-Server)

Cox Managed CPE Services. RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft]

Getting Started - Client VPN

Using Internet or Windows Explorer to Upload Your Site

TCS-CA. Outlook Express Configuration [VERSION 1.0] U S E R G U I D E

PaperClip. em4 Cloud Client. Manual Setup Guide

Entrust IdentityGuard Comprehensive

MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory. Chapter 11: Active Directory Certificate Services

USER GUIDE WWPass Security for (Outlook) For WWPass Security Pack 2.4

SEZ SEZ Online Manual Digital Signature Certficate [DSC] V Version 1.2

The Costs of Managed PKI:

MyKey is the digital signature software governed by Malaysia s Digital Signature Act 1997 & is accepted by the courts of law in Malaysia.

Wavecrest Certificate

How to Connect SSTP VPN from Windows Server 2008/Vista to Vigor2950

Copyright 2012 Trend Micro Incorporated. All rights reserved.

How to Time Stamp PDF and Microsoft Office 2010/2013 Documents with the Time Stamp Server

Aventail Connect Client with Smart Tunneling

Obtaining a digital signature certificate

Yale Software Library

Using etoken for SSL Web Authentication. SSL V3.0 Overview

Setting Up . on Your Sprint Power Vision SM Mogul by HTC

Encryption Key Best Practices Nasuni Corporation Natick, MA

AD RMS Microsoft Federation Gateway Support Installation and Configuration Guide... 3 About this guide... 3

Entrust Adobe CDS Individual Certificate

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

Open a PDF document using Adobe Reader, then click on the Tools menu on the upper left hand corner.

Set up Outlook for your new student e mail with IMAP/POP3 settings

Thales ncipher modules. Version: 1.2. Date: 22 December Copyright 2009 ncipher Corporation Ltd. All rights reserved.

ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access. Integration Handbook

Smart Policy - Web Collector. Version 1.1

CONFIGURATION AND SETUP USER GUIDE AND REFERENCE MANUAL

Integration Guide. SafeNet Authentication Client. Using SAC CBA for Check Point Security Gateway

Using TLS Encryption with Microsoft Outlook 2007

Prerequisite. Getting Started. Signing and Encryption using Microsoft outlook 2007

How to Publish Your Smart Card Certificates Using Outlook 2010

CWOPA Broadband Users. Windows Operating System

Setting Up . on Your Touch by HTC

Technical Certificates Overview

Prerequisite. Getting Started. Signing and Encryption using Microsoft outlook 2010

How to request a certificate

Transcription:

Entrust Managed Services PKI Getting an end-user Entrust certificate using Entrust Authority Administration Services Document issue: 2.0 Date of issue: June 2009

Revision information Table 1: Revisions in this document Document issue and date Issue 2.0 June 2009 Issue 2.0 June 2009 Section Recovering your certificate through Administration Services on page 7 Entire guide Description Added instructions detailing how to recover a certificate. Various copy edits. Copyright 2009 Entrust. All rights reserved. Entrust is a trademark or a registered trademark of Entrust, Inc. in certain countries. All Entrust product names and logos are trademarks or registered trademarks of Entrust, Inc. in certain countries. All other company and product names and logos are trademarks or registered trademarks of their respective owners in certain countries. This information is subject to change as Entrust reserves the right to, without notice, make changes to its products as progress in engineering or manufacturing methods or circumstances may warrant. Obtaining technical support For support assistance by telephone call one of the numbers below: 1-877-754-7878 in North America 1-613-270-3700 outside North America You can also email Customer Support at: support@entrust.com Export and/or import of cryptographic products may be restricted by various regulations in various countries. Export and/or import permits may be required. 2 Getting an end-user Entrust certificate using Entrust Authority Administration Services

User Guide Entrust certificates for end-users If you do not have Entrust Entelligence Security Provider installed on your computer (Start > All Programs > Entrust Entelligence), you can obtain your digital certificate using a Web-based application, called Entrust Authority Administration Services. This application installs your certificate within the Windows framework. Depending on your organization s requirements, you can also store your certificate on your computer or on a smart card or token. Note: If you do have Security Provider installed, see Getting an end-user Entrust certificate using Entrust Entelligence Security Provider available under the Resources tab at www.entrust.com/managed_services. At some point, you may be required to recover your user account for various reasons, such as a lost or damaged certificate, a compromised password, or as the result of a change to your certificate. Your administrator generally indicates when you need to perform a recovery. You use the same Web-based application to perform this function as you do to create your certificate. This guide includes the following topics: Getting your certificate through Administration Services on page 4 Recovering your certificate through Administration Services on page 7 Using your certificate on page 12 3

Getting your certificate through Administration Services To obtain your Entrust digital certificate, you must: 1 Get your reference number and authentication code from your administrator. The reference number and authorization code, collectively known as activation codes, are needed for enrollment. If you have not received your activation codes, contact your administrator. 2 Access the Web-based application at the URL provided by your administrator and use your activation codes to get your certificate. Administration Services allows you to create and manage your Entrust certificates. Your administrator will provide you with the URL. Complete the following procedure to obtain your certificate. To obtain your certificate through the Web-based application 1 In a browser, enter the URL of the Web-based application. Note: Contact your administrator if you have not received the URL. The Entrust User Registration and Self-Administration site appears. The landing page may look different than the screen capture below based on the enrollment model of your organization. 4 Getting an end-user Entrust certificate using Entrust Authority Administration Services Document issue: 2.0

2 Click Create My Digital ID. The Create Entrust Digital ID page appears. 3 Click Create Third-Party Security Store. This option stores your certificate within the Windows framework. The Create third-party security store page appears. 4 On the Create third-party security store page, complete the following: a Enter the reference number and authorization code in the applicable fields. Entrust certificates for end-users 5

Note: If you do not have your reference number and authorization code, contact your administrator. b Select Store Entrust digital ID on a smart card if your organization plans to store certificates on hardware security modules (HSM), such as a smart card or token. Ensure your HSM is connected to your computer. c Click Create Security Store. 5 If you selected to store your certificate on an HSM, enter your PIN. A security warning dialog box may appear, which says that Windows cannot validate that the certificate is from the certification authority (CA) it claims to be. This is because the root certificate is not in your Windows trusted certificate store. 6 In the Security Warning dialog box, click Yes so that Windows stores the root certificate in your Windows trusted certificate store. This also ensures that all certificates your organization s CA issues are automatically trusted as well. 6 Getting an end-user Entrust certificate using Entrust Authority Administration Services Document issue: 2.0

Your digital ID and related certificate is installed in the location specified (such as your computer or HSM). Recovering your certificate through Administration Services To recover your Entrust digital certificate, you must: 1 Get your reference number and authentication code from your administrator. The reference number and authorization code, collectively known as activation codes, are needed for recovery. If you have not received your activation codes, contact your administrator. 2 Access the Web-based application at the URL provided by your administrator and use your activation codes to recover your certificate. Administration Services is the same application you used to create your certificate. Complete the following procedure to recover your certificate. To recover your certificate 1 In a browser, enter the URL of the Web-based application. Note: Contact your administrator if you have not received the URL. The Entrust User Registration and Self-Administration site appears. The landing page may look different than the screen capture below based on the enrollment model of your organization. Entrust certificates for end-users 7

2 Click Recover My Digital ID. The Recover Entrust Digital ID page appears. 8 Getting an end-user Entrust certificate using Entrust Authority Administration Services Document issue: 2.0

3 Click Recover Third-Party Security Store. The Recover third-party security store page appears. Entrust certificates for end-users 9

4 Enter the reference number and authorization code for the recovery in the applicable fields. Note: If you do not have your reference number and authorization code, contact your administrator. 5 Select Store Entrust digital ID on a smart card if you are recovering a certificate stored to a token or smart card. Ensure your token or smart card is connected to your computer. 6 Click Recover Security Store. 7 If you selected to store your certificate on token or smart card, enter your PIN. 10 Getting an end-user Entrust certificate using Entrust Authority Administration Services Document issue: 2.0

Your digital ID and related certificate is recovered to the location specified (such as your computer or smart card). Entrust certificates for end-users 11

Using your certificate With an Entrust digital certificate, you can: sign and encrypt Adobe PDF documents Microsoft Office documents (Excel, Word, Outlook) Windows files and folders When you add a digital signature to a file or document, you are confirming your identity, ensuring the integrity of the data, and binding your identity to the transaction (non-repudiation). When you encrypt a file or document, you are ensuring that it cannot be viewed by anyone who does not have the pubic key that corresponds to the private key that encrypted the file or document. authenticate Devices (VPN, handhelds, etc.) Applications Servers Buildings If you do not know how your organization intends to use certificates, contact your administrator. The following table briefly describes various ways to use your Entrust certificate and identifies the task-specific guides you can reference for more information. Note: All Managed Services PKI documentation is available under the Resources tab at www.entrust.com/managed_services. Table 1: Task and related documentation If you want to... See this guide Description sign and/or encrypt PDF documents (files and forms) Using Entrust certificates with Adobe PDF files and forms This guide documents how to configure Adobe to recognize and trust digital certificates, and how to digitally sign a PDF document. 12 Getting an end-user Entrust certificate using Entrust Authority Administration Services Document issue: 2.0

Table 1: Task and related documentation If you want to... See this guide Description sign and/or encrypt Microsoft Office documents sign and/or encrypt files on your Windows operating system. authenticate to a VPN for secure, remote access to your network Using Entrust certificates with Microsoft Office and Windows Using Entrust certificates with Microsoft Office and Windows Using Entrust certificates with VPN This guide documents: Signing and sending messages using Microsoft Word, Excel, and PowerPoint Sending secure messages using Microsoft Outlook Configuring Microsoft Outlook to use a single certificate Removing message encryption in Microsoft Outlook This guide documents how to secure Windows files and folders and send a secure message from a Windows folder. This guide includes information about IPsec and SSL VPN, security issues, and VPN authentication mechanisms. It also provides instructions on how to import your certificate into your VPN client and how to configure your router to trust certificates issued to VPN clients. Entrust certificates for end-users 13

14 Getting an end-user Entrust certificate using Entrust Authority Administration Services Document issue: 2.0