Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate (Personal eid) WISeKey 2010 / Alinghi 2010 Smartcards



Similar documents
Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate on Aladdin etoken (Personal eid)

Guide for Securing With WISeKey CertifyID Personal Digital Certificate (Personal eid)

Using etoken for Securing s Using Outlook and Outlook Express

Personal Secure Certificate

VeriSign PKI Client Government Edition v 1.5. VeriSign PKI Client Government. VeriSign PKI Client VeriSign, Inc. Government.

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

User Guide Using Certificate in Microsoft Outlook Express

DIGIPASS CertiID. Getting Started 3.1.0

Yale Software Library

Personal Secure Certificate

PKI Contacts PKI for Fraunhofer Contacts

6. Is it mandatory to have the digital certificate issued from NICCA? Is it mandatory for the sender and receiver to have a NIC id?...

Digital Signature Certificate Online Enrollment Guide using etoken

User Guide May Using Certificates in Outlook Express

Entrust Managed Services PKI. Getting an end-user Entrust certificate using Entrust Authority Administration Services. Document issue: 2.

Digital Signature Certificate Online Enrollment Guide using etoken Pro 72K (Java)

Using Entrust certificates with Microsoft Office and Windows

TrustKey Tool User Manual

MyKey is the digital signature software governed by Malaysia s Digital Signature Act 1997 & is accepted by the courts of law in Malaysia.

TCS-CA. Outlook Express Configuration [VERSION 1.0] U S E R G U I D E

Jumble for Microsoft Outlook

Guide Installing Digital Certificates in Outlook 2000

CHARTER BUSINESS custom hosting faqs 2010 INTERNET. Q. How do I access my ? Q. How do I change or reset a password for an account?

SECURE USER GUIDE OUTLOOK 2000

E-CERT C ONTROL M ANAGER

How to Publish Your Smart Card Certificates Using Outlook 2010

Entrust Managed Services PKI

Managed Services PKI 60-day Trial Quick Start Guide

PROCEDURE FOR DSC CONFIGURATION. A. Installation of the driver has to be done for the first time and only once.

How to use Certificate in Microsoft Outlook

User Guide. Digital Signature

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on Mail Tab.

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on. User Information

Receiving Secure from Citi For External Customers and Business Partners

Shakambaree Technologies Pvt. Ltd.

PROXKey Tool User Manual

Instructions for Secure Cisco Registered Envelope Service (CRES)

Client configuration and migration Guide Setting up Thunderbird 3.1

CSOS Certificate Support Guide. Version: 1.1 Published: October 1, 2006 Publisher: CSOS Certification Authority

Reading an sent with Voltage Secur . Using the Voltage Secur Zero Download Messenger (ZDM)

Setting up secure communication with Ericsson. Guideline for Ericsson partners

Entrust Certificate Services for Adobe CDS

Procedure for How to Enroll for Digital Signature

Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice.

User Guide. The AMF's File Transfer Service (FTS)

How to install and use the File Sharing Outlook Plugin

Using Voltage Secur

V-RMTC PKI ENCRYPTED

NICCA User Guide for digitally signing Using Digital Signature Certificate (DSC) in Outlook Express

eadvantage Certificate Enrollment Procedures

I. Configuring Digital signature certificate in Microsoft Outlook 2003:

USER GUIDE WWPass Security for (Outlook) For WWPass Security Pack 2.4

Bridging People and Process. Bridging People and Process. Bridging People and Process. Bridging People and Process

PaperClip. em4 Cloud Client. Manual Setup Guide

Follow these steps to configure Outlook Express to access your Staffmail account:

HOW WILL I KNOW THAT I SHOULD USE THE IAS CONTINUITY SERVICE?

Code Signing Digital IDs GCC Certificate Installation Guide Rev 1.4

3. On the Accounts wizard window, select Add a new account, and then click Next.

Getting Started with University Gmail

Configuring an Client to Connect to CASS Mail Servers

PersonalSign Digital IDs GCC Certificate Installation Guide Rev. 1.2

Accessing the Media General SSL VPN

Microsoft Windows Server 2003 Integration Guide

Check Point FDE integration with Digipass Key devices

Encrypting Your Using the free COMODO Secure Certificate

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on Mail Tab.

NeoMail Guide. Neotel (Pty) Ltd

Encryption. How do I send my encryption key?

Technical notes for HIGHSEC eid App Middleware

1. How to Register Forgot Password Login to MailTrack Webmail Accessing MailTrack message Centre... 6

MessageGuard 3.0 User Guide

SecureStore I.CA. User manual. Version 2.16 and higher

Configuring Outlook to send mail via your Exchange mailbox using an alternative address

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

etoken Enterprise For: SSL SSL with etoken

How To Configure Using Different Clients

Update Instructions

MICROSOFT OUTLOOK 2003

How to use SURA in three simple steps:

How to use Certificate in Outlook Express

Entrust Managed Services PKI Administrator Guide

GlobalSign Solutions. Using a GlobalSign PersonalSign Certificate to Apply Digital Signatures in Microsoft Office Documents

Exostar LDAP Proxy / Secure Setup Guide. This document provides information on the following topics:

Entrust Managed Services PKI. Getting started with digital certificates and Entrust Managed Services PKI. Document issue: 1.0

Remember, this is not specific to your address alone... the METHOD you retrieve your is equally important.

USER GUIDE WWPass Security for Windows Logon

GlobalSign Enterprise PKI Support. GlobalSign Enterprise Solution EPKI Administrator Guide v2.4

Overview of Registered Envelopes. Registered Envelope Notification Message

Update Instructions

The IceWarp SSL Certificate Process

Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice.

Move Your to AT&T Website Solutions

IceWarp SSL Certificate Process

TIBCO Slingshot User Guide

SafeGuard Enterprise Web Helpdesk. Product version: 6.1

Secure Part II Due Date: Sept 27 Points: 25 Points

Enterprise Public Key Infrastructure (EPKI) Manager. Version 3.5

Client Configuration Secure Socket Layer. Information Technology Services 2010

ADP Secure Client User Guide

Transcription:

The World Internet Security Company Solutions for Security Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate (Personal eid) WISeKey 2010 / Alinghi 2010 Smartcards Wherever Security relies on Identity, WISeKey has the solution. Date: February 2010 Version: 1.0 Authors: WISeKey SA

TABLE OF CONTENTS About this User Guide... 1 About Personal eid (Digital Certificate)... 1 Copyright... 1 Document Conventions... 2 Pre-Installation requirements... 3 Install Smartcard reader... 3 Install Smartcard Software... 3 Free Secure e-mail eid... 4 Creating your profile... 4 Creating your Profile... 4 Email Verification... 6 Keypair Generation... 6 Install Certificate... 8 Verify that your certificate has been installed... 9 What Next?... 11 Support... 12

About this User Guide This manual describes the steps followed to obtain a WISeKey CertifyID Digital Certificate (eid) for securing your e-mail transactions, on the Alinghi 2010 branded smartcard. About Personal eid (Digital Certificate) Digital certificates provides users with the highest level of security; enabling identification, authentication, secure encrypted communications (e-mail, web site etc.), electronic signatures, and non-repudiation. WISeKey Personal eids associate the identity of a person with a digital identity. On one hand a digital ID, or eid can be viewed as Digital Passports that informs Internet users about their interlocutors' identity and ensures electronic message confidentiality. Digital certificates integrate seamlessly with the majority of existing systems. They are user-friendly, each action being performed via Windows-like active icons. An eid enables you to: Create digital signatures on electronic mail messages, thus ensuring message integrity and authenticity with your correspondents; Receive confidential information from any of your correspondents that only you can decrypt and read using S/MIME (You can also send confidential information to other eid users); Increase security for your applications, replacing passwords with eid authentication protection (for PKI enabled applications); Securely encrypt files and share them with other eid holders using available applications such as the free WISeCrypt Personal Edition, available from WISeKey s web site. Copyright No part of the contents of this document may be reproduced or distributed in any form or by any means without the prior written permission of WISeKey SA. is a registered trademark of WISeKey SA. is a registered trademark of WISeKey SA. Written and published in Geneva, Switzerland, by WISeKey SA. Copyright 2007 WISeKey SA. All Rights Reserved. User Guide 1/14 PROS-TR-0002

Document Conventions This User Guide uses the following conventions: NOTE means reader take note. Notes contain helpful suggestions. IMPORTANT means the reader must follow the instructions strictly. Descriptions for significant fields are available. User Guide 2/14 PROS-TR-0003

Pre-Installation requirements All software should be available on the WISekey web site at the following location: http://www.wisekey.com/en/projects/alinghi/10/help/pages/default.aspx INSTALL SM ARTCARD READER Before proceeding you should have installed your smartcard reader, and its software drivers. Ensure you have installed a Smartcard reader. If you have a WISekey SCR3xxxx Smartcard reader then you can download the smartcard drivers from the web site and install them. INSTALL SM ARTCARD SOFTWARE Before proceeding you should have installed the WISeKey Smart Security Interface, please refer to its manual for installation instructions. Download and install the WISeKey Smart Security Interface software drivers (Windows only). These drivers provide support for MS_CAPI, CSP and PKCS#11 cryptographic interfaces. Please refer to the WSSI manual to install the software, and change the default PIN of your smartcard from 11111111 to your personal password. After you have successfully installed your card reader, and inserted your card into your reader, and preferably changed the smartcard PIN, then please continue below to obtain your free digital certificate. User Guide 3/14 PROS-TR-0003

Free Secure e-mail eid Creating your profile CREATING YOUR PROFILE Steps Instructions 1 Open Internet Explorer. Type https://secure.certifyid.com/certifyid/accounts in the address bar. 2 Click Sign Up to CertifyID Account link in the homepage. 3 In the Create your CertifyID Account page, fill in the details according to your choice. Note: Enter a valid email address in the Email Address field. Your password will be sent to this email address. Accept the terms and conditions by enabling I Accept check box. Click Create Profile button to create your profile. User Guide 4/14 PROS-TR-0003

User Guide 5/14 PROS-TR-0003

EM AIL VERIFICATION Steps Instructions 1 You must use a valid email address. An email verification code will be sent to this email address and you should check your email to retrieve the message. NOTE: Use an email address that is accessible from an S/MIME capable email application. Examples of S/MIME capable applications include Outlook, Outlook Express, and Mozilla Thunderbird. The email address you submit must be in the exact form as used by your email application, do not use mapped emails. E.g. if your email application accesses your account using jdoe@somecompany.com, then please use this address for your CertifyID Account. Even though john.doe@somecompany.com may be a working alias for jdoe@somecompany.com, it will not work in some SMIME capable applications. You will receive two emails notifying you of the registration on the address that you provided. One of these messages will be titled: CertifyID Account email verification. Note: As these emails are automated messages, some Email providers may identify them as SPAM, so if you fail to receive them, make sure to check in your spam folder. If it has not been received, click browser s back button and check your email address in the Create your CertifyID Account page. If the email is correct and you have not received a your verification email, then go to the CertifyID Account email verification page and click the Send verification code again button in order to send a new verification code to your email account. 2 In the CertifyID Account email verification, you can click on the email verification link. Or you may log on to CertifyID Account, and in the CertifyID Account email verification page you can enter the verification code received in your email, then click the Verify Button to verify your email address. KEYPAIR GENERATION The following procedure should be used to generate your cryptographic key pairs, and request your digital certificate from WISeKey. NOTE: Only CertifyID Account users that have verified their email address can obtain a digital certificate. User Guide 6/14 PROS-TR-0003

Steps Instructions 1 Ensure that your smartcard is inserted properly in the smartcard reader, and that the smartcard reader is functioning properly. Log on to CertifyID Account, and go to the Certificates page. Click on the button title Online Web Enrollment, or the Enroll menu item. You will arrive in the CertifyID Registered User page. If necessary click on the Requests menu to arrive at the requests page. Check the box to agree with the CertifyID Subscriber Agreement. Select the WIseKey Smart Security Interface User (CSP) Cryptographic Provider and click Generate button. Note: If you would like to store your private key on your current computer, you can select Microsoft Enhanced Cryptographic Provider v1.0 (which is the default). Your key pair and certificate will be generated and stored in your current user account and PC using Internet Explorer browser 2 Click Yes in the Internet Explorer message box. User Guide 7/14 PROS-TR-0003

3 If you have already changed your smartcard pin (see WSSI manual), then enter your new PIN, otherwise enter the default PIN in the WSSI CSP Generate keypair dialog box. Default PIN is 11111111 When you have entered your PIN, click the Login button. INSTALL CERTIFICATE Steps Instructions 1 The certificate should be immediately generated and the following page should appear: Ensure that your card is still in the reader, and select Install to install the entire certificate chain to your smartcard. You may see the following prompts several times, always click the Yes button when the following prompts appear. User Guide 8/14 PROS-TR-0003

2 You should then see the following page, indicating that the certificate is installed and ready for use in your PKI enabled applications. 3 Click Logout tab in the right hand top of the page to logout from the application. VERIFY THAT YOUR CERT IFICATE HAS BEEN INS TALLED The digital certificate should also have been installed in your Windows operating system, and the Internet Explorer browser store. Steps Instructions 1 Open Internet Explorer. Click Tools > Internet Options > Content > Certificates. You should see your certificate appear in the list, with your email address as the Common Name. User Guide 9/14 PROS-TR-0003

User Guide 10/14 PROS-TR-0003

What Next? You can now use your digital certificate to Access Web Sites securely https://secure.certifyid.com/certifyid/accounts o You should now be able to logon to your certifyid account using your digital certificate. Ensure that you certificate is inserted in your smartcard and have your PIN ready for this process. Accessing web-sites with your digital certificate offers the following advantages: o Increased authentication security it is impossible for an imposter to access your account with a fake certificate, as your key and certificate are unique and are accessible only with your smartcard, or computer. o Increased communication security in order to access a site with a digital certificate, a secure communications channel, called SSL is built. This assures you that your communications with that web site remain confidential. Send digitally signed messages Configure your digital certificate in your email application. You should now be able to configure your digital certificate in your email application in order to use your digital certificate to send digitally signed messages. Digitally signed email has the following advantages: o o Recipients are assured that the message is from you, and that it is not spam. If the message was changed or tampered with during transit then the recipient will be automatically alerted. Receive secure confidential messages Once you have configure your digital certificate in your email application, and have sent signed messages to recipients, those recipients can add your contact details to their address book, along with your digital certificate. They can thereafter send you encrypted S/MIME (secure email) messages. Such messages are confidential and can only be decrypted and read with your private key, which is stored on your computer or smartcard. Note that some email packages require that your recipient also obtains a digital certificate before they are able to send you encrypted email. WISekey provides some guides to configuring your digital certificate with some popular email applications. These guides can be found in the support section of WISeKey s web site http://www.wisekey.com/en/support. User Guide 11/14 PROS-TR-0003

Support Should you require support at any stage of this procedure then please contact WISeKey SA :- WISeKey SA WTC II / 29 Rte de Pré Bois Geneva CH-1215 Tel. +41 22 594 3000 Email : support@wisekey.com User Guide 12/14 PROS-TR-0003