|
New versions of the Safari Web browser provided with Mac OS 10.3.3
and later include support for client certificates. The Keychain
application stores the digital certificates. (The default location of the
Keychain Access program is in the Applications/Utilities folder.)
Getting a Digital Certificate
To get a digital certificate, follow the instructions provided below:
- Consider what you will be using for a password; see Selecting a Password for tips.
- Click on the following link: https://collegeca.dartmouth.edu/index.jsp. A new
browser window will open. If the new browser window covers the previous window,
move it to the right so you can see these instructions.
- On the Dartmouth CAPSO v.1.0 Certificate Authority & PKI Solution Web
page, click on Request a Personal Cert under Certificate
Requests.
- At the Dartmouth Web Authentication Web page, enter your full
name as it appears in the Dartmouth Name Directory (DND) [e.g.,
Susan Q. Jones] and your DND
(BlitzMail) password, then press the
LOGIN button.
- When the Certificate Contents Web page appears, verify that the fields
contain the following entries:
- Common name - Enter your full name as it
appears in the DND (e.g., Susan Q. Jones).
- Email - Enter your Dartmouth e-mail
address (e.g., susan.q.jones@dartmouth.edu).
- Keysize - Change the setting to 1024 (Medium
Grade).
- Certificate Type - Select Software
Certificate.
- Click the Submit button.
- When the Confirmation Data Web page appears, verify the data, then
press Install Certificate.
- The Web browser will ask if you want to retrieve the certificate. Click
OK.
- In the download window that appears, take note of the certificate file's
name (e.g., Cert2Install.der) location, then close the
download window.
- You now need to install the certificate to your computer's Keychain
Access application:
- Use the Finder to locate the Keychain Access icon in the
Applications/Utilities folder.
- Drag and drop the certificate file into the Keychain
Access icon.
- The Keychain Access application opens and you are prompted to add
the certificates from the file to a Keychain. Select the Login
keychain. Click OK.
- A list of all your Keychain items appears. You can verify your new
certificate by selecting My Certificates. Your certificates
will appear and the recent addition will have a date two years from today.
- Keychain Access now contains your certificate, public key,
and private key. Quit the Keychain Access application.
Get the Dartmouth College Root Certificate
- Return to the Dartmouth CAPSO v.1.0 Certificate Authority & PKI
Solution Web page and click on the Root
Certificates link under Download.
- When the Download Certificates Web page appears, click on the
Dartmouth CertAuth1 CA (Dartmouth Root CA) link.
- The certificate file DartmouthCA.cer will download to your
Macintosh.
- Drag and drop the certificate file onto the Keychain
Access icon in the Applications/Utilities folder.
- The Keychain Access application opens and you are prompted to add
the certificates from the file to a Keychain.
- For Mac OS X 10.4 and earlier, select the X.509
Anchors keychain. Click OK.
- For Mac OS X 10.5, select the System keychain. Click
OK.
- Keychain Access will now contain the Dartmouth College Root
certificate. Quit the Keychain Access application.
Verifying a Certificate
To check a certificate:
- Open the Keychain Access application.
- In the Category column,
click Certificate.
- A list of certificates currently installed on your Macintosh appears. You
can double-click on any of them for their details.
Importing or Exporting a Certificate
On Mac OS, the Keychain Access program is used to store private
keys and certificates.
Importing a Certificate
- Open the Keychain Access application in the Application/Utilities
folder.
- Select Import from the File menu and
browse for the certificate you wish to import. Click
Open.
- Enter the password you supplied for the P12 file when you
created it.
You can also drag and drop the certificate file onto the Keychain
Access icon.
Exporting a Certificate
- Open the Keychain Access application in the Application/Utilities
folder.
- Highlight the certificate you wish to export by clicking
on it.
- Select Export from the File menu and
browse for the certificate you wish to import. Click
Open.
- Choose a location for the exported file, then click
Save.
- Enter a password to secure the certificate file,
then click OK.
|