Installing Digital Certificates For Internet Explorer


Contents

Root Certificate Installation
Client Private Key and Certificate Installation

Root Certificate Installation

In order for Internet Explorer 5, Outlook98 and Outlook Express 5 to be able to trust certificates issued by an Issuing Authority, it is necessary to install the Issuing Authority's Root Certificate into the system Registry. N.B.  For Subscribers, this is most easily accomplished during the installation of the Client private key and certificate.  However, for Relying Parties who will of course not be installing their own certificate, the following process may be used to install just the Issuing Authority's Root Certificate.

The following steps illustrate how an Issuing Authority's root certificate may be installed, using a fictitious example of an Issuing Authority called "Trustis Test Root CA".
To get the real root certificate for these Digital Certification Services click here and follow the simple steps below

If installing from a web page, just Right-Click on the link that points to the Issuing Authority's Root certificate and choose
"Save Target As ...", then choose a suitable place to store the root certificate file.

Once stored, or If installing from a local or networked .p7b or .cer file, use Windows Explorer to locate the file, Right-Click on the root certificate file and choose "Install Certificate".

The Certificate Manager Import Wizard starts.

Click Next

.

certmgr3.gif (42378 bytes)
Choose the default setting of automatic selection of the certificate store

Click Next again.

certmgr4.gif (13387 bytes)
Click Finish certmgr5.gif (26354 bytes)
 

the Root Certificate Store message will appear
click Yes

certmgr16.gif (5257 bytes)
A dialog box like the one opposite will appear, confirming success

Click OK

certmgr6.gif (7103 bytes)

The Issuing Authority's Root Certificate is now installed.  Client certificates issued by this Issuing Authority will now be trusted by Microsoft security-enabled applications, (provided they have not time-expired or have not been revoked).

Return to table of contents


Client Private Key and Certificate Installation

If installing from a web page, just click on the link that points to the client certificate.

If installing from a local or networked .pfx file, use Windows Explorer to locate the file, and double-click on the client .pfx file.

In either case, the Certificate Manager Import Wizard starts

Click Next

certmgr3.gif (42378 bytes)
If installing from a file, click Next again certmgr8.gif (14375 bytes)
to reach the Password Protection for Private Keys dialog box

and enter the transport password previously supplied to you.

Select both options: Enable Strong Private Key Protection and Mark the private key as exportable.

Click Next

certmgr9.gif (12325 bytes)
Accept the default setting of automatic selection of the certificate store and click Next again. certmgr10.gif (13667 bytes)
Click Finish and the Private Key Container dialog box appears certmgr11.gif (22836 bytes)
Click the
Set Security Level
button
certmgr12.gif (20529 bytes)
and select
High
in the next dialog box.

Click Next

certmgr13.gif (28861 bytes)
select
Create a new password
for this item.
(This will be the password used to protect future accesses to your private key - see
Private Key Protection
for useful hints on choosing a password)

Enter a suitable name for this key container in the
Password for: text box,
choose and enter a new, user password in the password: field
and the confirm: text boxes.

(Ignore any name in the Use this password to access this item box, this refers to any existing key container, if present.)

certmgr14.gif (24367 bytes)
Click Finish and a further dialog box appears, Importing a new private exchange key!

Enter the new, user password you just created, DO NOT enable Remember password.

Click OK

certmgr15.gif (20457 bytes)
 

the Root Certificate Store message will appear
click Yes

certmgr16.gif (5257 bytes)
finally,
The import was successful
will appear

click OK

certmgr6.gif (7103 bytes)

The client private key and certificate and the Issuing Authority's Root Certificate are now installed and available for use by Internet Explorer 5 and either Outlook98 or Outlook Express 5

Return to table of contents