etoken Enterprise For: SSL SSL with etoken
System Requirements Windows 2000 Internet Explorer 5.0 and above Netscape 4.6 and above etoken R2 or Pro key Install etoken RTE Certificates from: (click on the logo)
etoken Enterprise For: SSL Configuring SSL on Web Server
Configuring SSL on Web Server 1. Install etoken RTE 2. Click on Start 3. Scroll up to Settings 4. Scroll over to Control Panel 5. Click on Add/Remove Programs
Configuring SSL on Web Server 6. Click on Add/Remove Windows Components
Configuring SSL on Web Server 7. Click Certificate Service 8. Click on Yes when the Microsoft Certificate Services Dialog Box Appears
Configuring SSL on Web Server 9. Click Next 10. Click on Stand-alone root CA and click on Next
Configuring SSL on Web Server 11. Enter the information and click on Next
Configuring SSL on Web Server 12. Click on Next for the Data Storage Location
Configuring SSL on Web Server 13. Click on OK when Microsoft Certificate Services dialog box appears: 14. Click on Finish
etoken Enterprise For: SSL Requesting a Server Certificate
Requesting a Server Certificate 1. Run the Web Server Certificate Wizard by starting Internet Services Manager, right-clicking on the virtual site that you want the certificate for, clicking Properties
Requesting a Server Certificate 2. Click on the Directory Security tab, and then clicking Server Certificate
Requesting a Server Certificate 3. Click Next
Requesting a Server Certificate 4. Click Create a new certificate, and then click Next
Requesting a Server Certificate 5. Click Prepare the request now, but send it later, and then click Next
Requesting a Server Certificate 6. Type in a name for the certificate and select 1024 as the Bit Length, then click Next
Requesting a Server Certificate 7. Fill in the organization information and click Next
Requesting a Server Certificate 8. Type in the command name for the site and click Next
Requesting a Server Certificate 9. Enter the Geographical Information and click Next
Requesting a Server Certificate 10. A certificate request is saved in a file that you specify. By default, this is C:\Certreq.txt
Requesting a Server Certificate 11. Click on Next
Requesting a Server Certificate 12. Click on Finish
etoken Enterprise For: SSL Using Microsoft Certificate Services
Using Microsoft Certificate Services 1. Open IE, and browse to http://localhost/certsrv where localhost is the IP address of the server 2. Choose the Request a Certificate option and click Next
Using Microsoft Certificate Services 3. Click on Advanced Request, and then click Next
Using Microsoft Certificate Services 4. Click Submit a certificate request using a base64 encoded PKCS #10 file or a renewal request using a base64 encoded PKCS #7 file, and then click Next.
Using Microsoft Certificate Services 5. Under Saved Request, copy the content of the file you created in step 10, and then Submit.
Using Microsoft Certificate Services 6. Your request has been submitted, and now you must approve it.
Using Microsoft Certificate Services 7. On the Programs menu, under Administrative Tools, start the Certificate Authority management console
Using Microsoft Certificate Services 8. Under the Pending Request folder, there should be a certificate 9. Right click the certificate request, point to All Tasks, and then click Issue 10. Close the Certificate Authority management console.
Using Microsoft Certificate Services 11. Go to URL: http://localhost/certsrv, click Check on Pending Requests, then click Next 12. Make sure that the request you just created is selected, and then click Next
Using Microsoft Certificate Services 13. Choose Based 64 encoded, and then click Download CA certificate 14. Select Open this file from its current location, and click OK
Using Microsoft Certificate Services 15. The Certificate property pages are displayed. Click the General tab, and then click Install Certificate
Using Microsoft Certificate Services 16. Click on Next on Certificate Import Wizard
Using Microsoft Certificate Services 17. Select Automatically select the certificate store based on the type of certificate, and click Next
Using Microsoft Certificate Services 18. Click on Finish
Using Microsoft Certificate Services 19. Click on OK when the import is completed
Using Microsoft Certificate Services 20. Go back to the Internet Services Manager, double click on the Server name 21. Right-click on Default Web Site, point to Properties
Using Microsoft Certificate Services 22. Click on the Directory Security tab. 23. On Secure Communication, click on Server Certificate
Using Microsoft Certificate Services 24. Click on Assign an existing certificate to see a list with your certificate in it. Click you certificate, and then click Next
Using Microsoft Certificate Services 25. Click Next on Certificate Summary
Using Microsoft Certificate Services 26. Click on Finish. Your SSL Server Certificate is now installed.
etoken Enterprise For: SSL Requesting Client Certificate
Requesting Client Certificates 1. Attach an etoken to the computer 2. Open Internet Explorer and go to URL: http://localhost/certsrv 3. Select Request a Certificate and click on Next
Requesting Client Certificates 4. Click on Advanced Request
Requesting Client Certificates 5. Select Submit a certificate request to this CA using a form, and click on Next
Requesting Client Certificates 6. Enter the information on the Advanced Certificate Request Form. 7. The Intended Purpose is Client Authentication Certificate 8. Select etoken Base Cryptographic Provider for CSP 9. The Key size should be 1024 10. Click on Submit
Requesting Client Certificates 11. Enter etoken password when etoken dialog box pops up 12. You will get an Internet Explorer dialog box that reads When you read information on the Internet, it might be possible for others to see that information. Do you still want to continue? 13. Click on Yes 14. Exit out Request a Certificate page
etoken Enterprise For: SSL Installing Client Certificates
Installing Client Certificates 1. Click on Start and scroll up to Programs 2. Scroll over to Administrative Tools 3. Click on Certificate Authority 4. Under the Pending Request folder, there should be a certificate 5. Right-click on that certificate and go to All Tasks 6. Click on Issue
Installing Client Certificates 7. Go to the Issued Certificates folder
Installing Client Certificates 8. Double click on the Certificate that you just issued, the Certificate Box pops up
Installing Client Certificates 9. Click on Details tab and click on Copy to File
Installing Client Certificates 10. The Certificate Dialog Box appears and click on Next
Installing Client Certificates 11. Select Based-64 Encoded X.509 (.cer) and click on Next
Installing Client Certificates 12. Type in a file name for the certificate and click on Next
Installing Client Certificates 13. Click on Finish
Installing Client Certificates 14. You will get a dialog box of The export was successful
etoken Enterprise For: SSL Installing Client Certificates onto etoken
Installing Client Certificates onto etoken 1. Click on My Computer Icon and double click on C: 2. Double-click on the client certificate 3. The Certificate Box appears
Installing Client Certificates onto etoken 4. Click on Install Certificate
Installing Client Certificates onto etoken 5. Click on Next on the Certificate Import Wizard
Installing Client Certificates onto etoken 6. Select Place all certificates in the following store and click on Browse
Installing Client Certificates onto etoken 7. Check the box for Show Physical stores and double-click on Personal folder 8. Click on etoken and click on OK
Installing Client Certificates onto etoken 9. Click on Next
Installing Client Certificates onto etoken 10. Click on Finish
Installing Client Certificates onto etoken 11. You will get a dialog box of The Import was successful. The Client Certificate is now installed onto the etoken
etoken Enterprise For: SSL Creating HTML file as Default Page
Creating HTML file as Default Page 1. Use Notepad.exe to create a html file 2. Copy this file to C:\Intepub\wwwroot directory
etoken Enterprise For: SSL Configuring IIS to work with etoken
Configuring IIS to work with etoken 1. Click on Start and scroll up to Programs 2. Scroll over to Administrative Tools and point to Internet Services Manager 3. Double click on the Server name and double click on Default Web Site 4. On the right side of the windows, right-click on the html file you created earlier and go to Properties
Configuring IIS to work with etoken 5. Click on File Security tab and click on Edit in Secure Communication
Configuring IIS to work with etoken 6. Check Require Secured Channel (SSL) and check Require Client Certificate
Configuring IIS to work with etoken 7. Click on OK and click on Apply in the Properties window 8. Go to URL: http://localhost/filename.html where localhost is the IP address of the server machine and filename.html is the html file that you created earlier 9. Click on Yes on the Security Alert Dialog box 10. Select the Client Certificate that you want to use in the Client Authentication box and click on OK. 11. Enter etoken password when etoken dialog box appears
Any Questions?