<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://docs.snic.se/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kent+Engstr%C3%B6m+%28NSC%29</id>
	<title>SNIC Documentation - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="http://docs.snic.se/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kent+Engstr%C3%B6m+%28NSC%29"/>
	<link rel="alternate" type="text/html" href="http://docs.snic.se/wiki/Special:Contributions/Kent_Engstr%C3%B6m_(NSC)"/>
	<updated>2026-06-18T11:33:44Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.10</generator>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Support&amp;diff=8034</id>
		<title>Support</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Support&amp;diff=8034"/>
		<updated>2025-02-27T12:16:07Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): SUPR support form can also be used by non-logged in users.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Support alternatives:&lt;br /&gt;
&lt;br /&gt;
; Guides&lt;br /&gt;
: This site has a number of guides on a variety of subjects, see [[:Category:Guide]].&lt;br /&gt;
&lt;br /&gt;
; Centre, Swestore and SUPR support&lt;br /&gt;
: Go to [http://supr.naiss.se/support http://supr.naiss.se/support]. The support form there helps you fill in a good support request. This is by far the quickest way of getting your problems solved, and this is where you should address all your support questions. In case an issue cannot be immediately solved by these support queues it will be forwarded to the right place for you. &lt;br /&gt;
&lt;br /&gt;
; Interactive support sessions &lt;br /&gt;
: The [[Zoom-in|SNIC zoom-in]] is a virtual meeting room in which you can discuss the services offered by the SNIC centres and how they can be used for your computational needs, help you process your data and visualise your results. &lt;br /&gt;
&lt;br /&gt;
; Application support&lt;br /&gt;
: e-mail: [mailto:application-support@naiss.se application-support@naiss.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: This mail address can be used if you have support questions that are not directly regarding how to run a given application on a specific SNIC HPC resource, but regarding how to use the application itself or how to solve an issue with the application that is not specific to running it on a certain resource. &amp;lt;br&amp;gt;&lt;br /&gt;
: The application-support queue is monitored by all the application experts, who are distributed over all the six SNIC HPC centers, so there is a good chance that someone who knows the given application will see the support request and help answer your questions or solve your issue. &amp;lt;br&amp;gt;&lt;br /&gt;
: If you don’t know whether or not to use the application-support address for your support request, then just send your request to the support address at the HPC center where you run your jobs. Then someone monitoring that support queue will in turn move your support request to the application-support queue if they find that your request is better handled there.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Support&amp;diff=8033</id>
		<title>Support</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Support&amp;diff=8033"/>
		<updated>2024-04-09T09:21:26Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): Fix snic.se -&amp;gt; naiss.se, leave other SNIC references untouched&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Support alternatives:&lt;br /&gt;
&lt;br /&gt;
; Guides&lt;br /&gt;
: This site has a number of guides on a variety of subjects, see [[:Category:Guide]].&lt;br /&gt;
&lt;br /&gt;
; Centre, Swestore and SUPR support&lt;br /&gt;
: Go to [http://supr.naiss.se/support http://supr.naiss.se/support]. If you can login to SUPR you can use a support form that helps you fill in a good support request. If you cannot login you will get a list of email addresses to use for your support request.&lt;br /&gt;
: This is by far the quickest way of getting your problems solved, and this is where you should address all your support questions. In case an issue cannot be immediately solved by these support queues it will be forwarded to the right place for you. &lt;br /&gt;
&lt;br /&gt;
; Interactive support sessions &lt;br /&gt;
: The [[Zoom-in|SNIC zoom-in]] is a virtual meeting room in which you can discuss the services offered by the SNIC centres and how they can be used for your computational needs, help you process your data and visualise your results. &lt;br /&gt;
&lt;br /&gt;
; Application support&lt;br /&gt;
: e-mail: [mailto:application-support@naiss.se application-support@naiss.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: This mail address can be used if you have support questions that are not directly regarding how to run a given application on a specific SNIC HPC resource, but regarding how to use the application itself or how to solve an issue with the application that is not specific to running it on a certain resource. &amp;lt;br&amp;gt;&lt;br /&gt;
: The application-support queue is monitored by all the application experts, who are distributed over all the six SNIC HPC centers, so there is a good chance that someone who knows the given application will see the support request and help answer your questions or solve your issue. &amp;lt;br&amp;gt;&lt;br /&gt;
: If you don’t know whether or not to use the application-support address for your support request, then just send your request to the support address at the HPC center where you run your jobs. Then someone monitoring that support queue will in turn move your support request to the application-support queue if they find that your request is better handled there.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=8030</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=8030"/>
		<updated>2023-02-15T13:02:55Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): Removed redirect to Swestore Documentation Moved&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page has been moved to the [https://docs.swestore.se/access/certificates/sectigo Swestore documentation].&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7875</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7875"/>
		<updated>2022-05-02T11:38:09Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Hitting the maximum number of valid certs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Preparations ==&lt;br /&gt;
&lt;br /&gt;
Two requirements needs to be fulfilled in order to be able to request a grid (aka eScience) certificate:&lt;br /&gt;
* Your organization must be set up to allow this (see [[#Organization Support]] below)&lt;br /&gt;
** A tool for testing this is the Sectigo SSO check page on https://cert-manager.com/customer/sunet/ssocheck&lt;br /&gt;
* Your identity must fulfill the requirements for requesting personal certificates, within Sweden the requirement is SWAMID Assurance Level 2 Profile (SWAMID AL2), or higher.&lt;br /&gt;
** Enabling this only needs to be done once. Routines for this vary among organizations, it typically involves visiting a helpdesk to show an identity document to verify your identity.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate ==&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading ''Digital Certificate Enrollment''.&lt;br /&gt;
&lt;br /&gt;
A common error for first-time users is your identity not fullfilling the requirements for requesting personal certificates, see [[#Preparations]] above.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate with server-side generation of key ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Term 395 days (should be the only option)&lt;br /&gt;
* Select Enrollment Method = Key Generation&lt;br /&gt;
* Select Key Type with approproate number of bits&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate using a locally generated key and CSR ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:4096 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Term 395 days (should be the only option)&lt;br /&gt;
* Select Enrollment Method = CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above or paste it into the box below&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
=== Hitting the maximum number of valid certs ===&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
''2022-05-02 Very are rather sure that the behaviour for some time now has instead been to automatically revoke older certificates to keep the window to two certificates (the most recent ones) per certificate profile.''&lt;br /&gt;
&lt;br /&gt;
== Using the certificate ==&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate in the web browser ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate with grid tools ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
== Revoking a certificate ==&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
== Appendix ==&lt;br /&gt;
=== Organization Support ===&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers Tekniska Högskola (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Kungliga Tekniska högskolan (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunds universitet (verified OK 2020-04-28 by Anders A and Magnus U at Lunarc)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Failed verification&lt;br /&gt;
&lt;br /&gt;
* Sveriges lantbruksuniversitet (does not handle AL2 2020-12-18 by Jens L at NSC)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at [https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal here] and they are welcome to contact tcs@sunet.se to get help with the setup.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7819</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7819"/>
		<updated>2021-09-22T07:28:18Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Preparations ==&lt;br /&gt;
&lt;br /&gt;
Two requirements needs to be fulfilled in order to be able to request a grid (aka eScience) certificate:&lt;br /&gt;
* Your organization must be set up to allow this (see [[#Organization Support]] below)&lt;br /&gt;
** A tool for testing this is the Sectigo SSO check page on https://cert-manager.com/customer/sunet/ssocheck&lt;br /&gt;
* Your identity must fulfill the requirements for requesting personal certificates, within Sweden the requirement is SWAMID Assurance Level 2 Profile (SWAMID AL2), or higher.&lt;br /&gt;
** Enabling this only needs to be done once. Routines for this vary among organizations, it typically involves visiting a helpdesk to show an identity document to verify your identity.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate ==&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading ''Digital Certificate Enrollment''.&lt;br /&gt;
&lt;br /&gt;
A common error for first-time users is your identity not fullfilling the requirements for requesting personal certificates, see [[#Preparations]] above.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate with server-side generation of key ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Term 395 days (should be the only option)&lt;br /&gt;
* Select Enrollment Method = Key Generation&lt;br /&gt;
* Select Key Type with approproate number of bits&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate using a locally generated key and CSR ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:4096 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Term 395 days (should be the only option)&lt;br /&gt;
* Select Enrollment Method = CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above or paste it into the box below&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
=== Hitting the maximum number of valid certs ===&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
== Using the certificate ==&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate in the web browser ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate with grid tools ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
== Revoking a certificate ==&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
== Appendix ==&lt;br /&gt;
=== Organization Support ===&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers Tekniska Högskola (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Kungliga Tekniska högskolan (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunds universitet (verified OK 2020-04-28 by Anders A and Magnus U at Lunarc)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Failed verification&lt;br /&gt;
&lt;br /&gt;
* Sveriges lantbruksuniversitet (does not handle AL2 2020-12-18 by Jens L at NSC)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at [https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal here] and they are welcome to contact tcs@sunet.se to get help with the setup.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7809</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7809"/>
		<updated>2021-06-09T15:28:20Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a certificate using a locally generated key and CSR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Preparations ==&lt;br /&gt;
&lt;br /&gt;
Two requirements needs to be fulfilled in order to be able to request a grid (aka eScience) certificate:&lt;br /&gt;
* Your organization must be set up to allow this (see [[#Organization Support]] below)&lt;br /&gt;
** A tool for testing this is the Sectigo SSO check page on https://cert-manager.com/customer/sunet/ssocheck&lt;br /&gt;
* Your identity must fulfill the requirements for requesting personal certificates, within Sweden the requirement is SWAMID Assurance Level 2 Profile (SWAMID AL2), or higher.&lt;br /&gt;
** Enabling this only needs to be done once. Routines for this vary among organizations, it typically involves visiting a helpdesk to show an identity document to verify your identity.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate ==&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading ''Digital Certificate Enrollment''.&lt;br /&gt;
&lt;br /&gt;
A common error for first-time users is your identity not fullfilling the requirements for requesting personal certificates, see [[#Preparations]] above.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate with server-side generation of key ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Term 395 days (should be the only option)&lt;br /&gt;
* Select Enrollment Method = Key Generation&lt;br /&gt;
* Select Key Type with approproate number of bits&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate using a locally generated key and CSR ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:4096 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Term 295 days (should be the only option)&lt;br /&gt;
* Select Enrollment Method = CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above or paste it into the box below&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
=== Hitting the maximum number of valid certs ===&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
== Using the certificate ==&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate in the web browser ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate with grid tools ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
== Revoking a certificate ==&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
== Appendix ==&lt;br /&gt;
=== Organization Support ===&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers Tekniska Högskola (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Kungliga Tekniska högskolan (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunds universitet (verified OK 2020-04-28 by Anders A and Magnus U at Lunarc)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Failed verification&lt;br /&gt;
&lt;br /&gt;
* Sveriges lantbruksuniversitet (does not handle AL2 2020-12-18 by Jens L at NSC)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at [https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal here] and they are welcome to contact tcs@sunet.se to get help with the setup.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7808</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7808"/>
		<updated>2021-06-09T15:27:14Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a certificate with server-side generation of key */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Preparations ==&lt;br /&gt;
&lt;br /&gt;
Two requirements needs to be fulfilled in order to be able to request a grid (aka eScience) certificate:&lt;br /&gt;
* Your organization must be set up to allow this (see [[#Organization Support]] below)&lt;br /&gt;
** A tool for testing this is the Sectigo SSO check page on https://cert-manager.com/customer/sunet/ssocheck&lt;br /&gt;
* Your identity must fulfill the requirements for requesting personal certificates, within Sweden the requirement is SWAMID Assurance Level 2 Profile (SWAMID AL2), or higher.&lt;br /&gt;
** Enabling this only needs to be done once. Routines for this vary among organizations, it typically involves visiting a helpdesk to show an identity document to verify your identity.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate ==&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading ''Digital Certificate Enrollment''.&lt;br /&gt;
&lt;br /&gt;
A common error for first-time users is your identity not fullfilling the requirements for requesting personal certificates, see [[#Preparations]] above.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate with server-side generation of key ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Term 395 days (should be the only option)&lt;br /&gt;
* Select Enrollment Method = Key Generation&lt;br /&gt;
* Select Key Type with approproate number of bits&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
=== Requesting a certificate using a locally generated key and CSR ===&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:4096 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
=== Hitting the maximum number of valid certs ===&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
== Using the certificate ==&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate in the web browser ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
=== Using the certificate with grid tools ===&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
== Revoking a certificate ==&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
== Appendix ==&lt;br /&gt;
=== Organization Support ===&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers Tekniska Högskola (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Kungliga Tekniska högskolan (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunds universitet (verified OK 2020-04-28 by Anders A and Magnus U at Lunarc)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Failed verification&lt;br /&gt;
&lt;br /&gt;
* Sveriges lantbruksuniversitet (does not handle AL2 2020-12-18 by Jens L at NSC)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at [https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal here] and they are welcome to contact tcs@sunet.se to get help with the setup.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7494</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7494"/>
		<updated>2020-04-28T15:01:24Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers Tekniska Högskola (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Kungliga Tekniska högskolan (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunds universitet (verified OK 2020-04-28 by Anders A and Magnus U at Lunarc)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal and they are welcome to contact tcs@sunet.se to get help with the setup.&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7493</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7493"/>
		<updated>2020-04-28T14:59:30Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* KTH (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunds universitet (verified OK 2020-04-28 by Anders A and Magnus U at Lunarc)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7492</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7492"/>
		<updated>2020-04-28T14:58:06Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
&lt;br /&gt;
[[Grid_certificates#Requesting a certificate|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Switching to a new provider =&lt;br /&gt;
&lt;br /&gt;
On 2020-05-01, Digicert is no longer the provider of this service. See [[Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal]] for instructions on how to use the new provider's portal.&lt;br /&gt;
&lt;br /&gt;
= Browser Support =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has never supported it. Safari still supports it (as of September 2019), and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate directly in the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
If that is your case, you can [[#Requesting_a_personal_grid_certificate_directly_in_the_browser|follow the simpler instructions below]].&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to [[#Requesting_a_personal_grid_certificate_using_CSR_created_outside_of_the_browser|follow the more complex instructions below]]. &lt;br /&gt;
&lt;br /&gt;
For some background, see https://knowledge.digicert.com/generalinformation/keygenfirefox.html&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see [[#Browser Support|Browser Support]] above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login. (Note that the page is very slow, and it may take several seconds before what you type is even visible in the input field.)&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate using CSR created outside of the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Edge&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
### Chrome&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
# Generate a CSR using 'openssl req' (remember any pass phrase used to encrypt the key) and display the CSR:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
 cat usercert_request.pem&lt;br /&gt;
&lt;br /&gt;
#Paste the CSR text into the &amp;quot;CSR&amp;quot; text box&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and you will get to a page listing all you personal certificates. Scroll to the bottom if needed to find the latest one generated now and use the Download button to save the ZIP file (the name of the file depends on your name).&lt;br /&gt;
# Unzip the ZIP file and make a PKCS#12 file from its certificate together with the key you generated above, remembering that your exact names for the directory and certificate file will vary. You will need to reenter your key passphrase from above, and then set a new passphrase for the PKCS#12 export file itself.&lt;br /&gt;
&lt;br /&gt;
  unzip mitt_namn_namne12_foo_se.zip&lt;br /&gt;
  openssl pkcs12 -export -inkey userkey.pem -in mitt_namn_namne12_foo_se/mitt_namn_namne12_foo_se.crt -out my_cert.p12&lt;br /&gt;
&lt;br /&gt;
# Import the PKCS#12 file into your browser(s):&lt;br /&gt;
## Firefox: Select ''Preferences'', type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'my_cert.p12' file created above, provide the passphrase. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
## Chrome: Select ''Settings'', access the search icon and type 'certificate', click 'Manage certificates', click the 'Import' button, select your 'my_cert.p12' file created above, provide the passphrase. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
## Other browsers: ''Please help us out by providing instructions''.&lt;br /&gt;
# Quit your web browser, start it again, try accessing a site protected by your grid certificate (making sure you select the new certificate) and verify that it works.&lt;br /&gt;
# Remove the userkey.pem and my_cert.p12 files (or take care of them in some other good way) as they do contain your private key.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;br /&gt;
&lt;br /&gt;
[[Grid_certificates#Requesting a certificate|&amp;lt; Grid certificates]]&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7491</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7491"/>
		<updated>2020-04-28T14:55:22Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* KTH (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunds universitet (verified OK 2020-04-28 by Anders A at Lunarc)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7490</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7490"/>
		<updated>2020-04-28T14:54:13Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* KTH (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunarc at Lunds universitet (verified OK 2020-04-28 by Anders A at Lunarc) - other subdomains under lu.se not working yet&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
* Uppsala universitet (verified OK 2020-04-28 by Daniel K at UPPMAX)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7489</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7489"/>
		<updated>2020-04-28T08:32:32Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* KTH (verified OK 2020-04-28 by Lilit A at PDC)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunarc at Lunds universitet (verified OK 2020-04-28 by Anders A at Lunarc) - other subdomains under lu.se not working yet&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7488</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7488"/>
		<updated>2020-04-28T06:48:09Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Lunarc at Lunds universitet (verified OK 2020-04-28 by Anders A at Lunarc) - other subdomains under lu.se not working yet&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7487</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7487"/>
		<updated>2020-04-27T15:09:10Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Hitting the maximum number of valid certs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
''2020-04-27 This behaviour will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.''&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7486</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7486"/>
		<updated>2020-04-27T15:08:17Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a certificate */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
== Hitting the maximum number of valid certs ==&lt;br /&gt;
&lt;br /&gt;
If you get the error message &amp;quot;Sectigo Certificate Manager enrollment request failed. Please contact your security administrator.&amp;quot; when you have clicked the SUBMIT button and accepted the click-through license, it may be because you have hit the limit of two valid certificates per identity and certificate profile. Ask your local certificate administrators at your organization to revoke one of your existing certificates. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;br /&gt;
&lt;br /&gt;
*2020-04-27 This behavious will also be reported as a bug to Sectigo to ask them to handle this in a smoother way.*&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7485</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7485"/>
		<updated>2020-04-27T15:04:41Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a certificate */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get at this point.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7484</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7484"/>
		<updated>2020-04-27T15:04:03Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Chalmers (verified OK 2020-04-27 by Mathias L at C3SE)&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7483</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7483"/>
		<updated>2020-04-27T13:02:04Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent E and colleagues at NSC)&lt;br /&gt;
* Umeå universitet (verified OK 2020-04-27 by Erik A at HPC2N)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7482</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7482"/>
		<updated>2020-04-27T11:54:59Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* Linköpings universitet (verified OK 2020-04-24 by Kent and colleagues at NSC)&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7481</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7481"/>
		<updated>2020-04-27T09:39:20Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;br /&gt;
&lt;br /&gt;
= Revoking a certificate =&lt;br /&gt;
&lt;br /&gt;
Currrently, you cannot revoke your certificate from the portal. If you need you certificate revoked, please talk to your local certificate administrators at your organization. If you cannot reach them and it is urgent, contact tcs@sunet.se and provide the details of the certificate you want revoked.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7480</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7480"/>
		<updated>2020-04-27T09:24:15Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01 (and before that for testing).&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7479</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7479"/>
		<updated>2020-04-27T09:19:42Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Organization Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
Instructions aimed at your local organization's TCS and IdP administrators are found at https://wiki.sunet.se/display/TCS/SUNET+TCS+2020-+Information+for+administrators#SUNETTCS2020-Informationforadministrators-ConfiguringyourIdPandtheSCMtoenabletheportal&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7478</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7478"/>
		<updated>2020-04-27T09:17:50Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Using the certificate with grid tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7477</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7477"/>
		<updated>2020-04-27T09:17:30Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Using the certificate with grid tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got certs.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at[[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7476</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7476"/>
		<updated>2020-04-27T09:16:44Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Using the certificate */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you can follow the instructions at [[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
If you uploaded a CSR and got cert.pem back, you can do it in one of two ways. The first one:&lt;br /&gt;
&lt;br /&gt;
* Create a PKCS#12 file yourself using the OpenSSL command in the web browser section above, and then proceed with the instructions at[[Preparing a client certificate]].&lt;br /&gt;
&lt;br /&gt;
The other more direct alternative:&lt;br /&gt;
&lt;br /&gt;
* Put the userkey.pem file you generated in your ~/.globus directory as ~/.globus/userkey.pem&lt;br /&gt;
* Put the certs.pem file you downloaded in your ~/.globus directory as ~/.globus/usercert.pem&lt;br /&gt;
&lt;br /&gt;
FIXME: This section needs testing, feedback and updates from people using grid tools and/or staff directly supporting those users&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7475</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7475"/>
		<updated>2020-04-27T09:08:53Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Using the certificate in the web browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web browser. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7474</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7474"/>
		<updated>2020-04-27T09:08:32Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Using the certificate in the web browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
If you had the key generated server-side and got a certs.p12 file back, you are ready to import it into your web broswer. If you uploaded a CSR and got cert.pem back, you first need to create a PKCS#12 file yourself by doing:&lt;br /&gt;
&lt;br /&gt;
 openssl pkcs12 -export -inkey userkey.pem -in certs.pem -out certs.p12&lt;br /&gt;
&lt;br /&gt;
To import the certs.p12 file into your web browser:&lt;br /&gt;
&lt;br /&gt;
* Firefox: Select Preferences, type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'certs.p12' file created above, provide the password. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
* Chrome: Select Settings, access the search icon and type 'certificate', click 'Manage certificates' (you may have to click &amp;quot;More&amp;quot; first to see this), click the 'Import' button, select your 'certs.p12' file created above, provide the password. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
* Other browsers: Please help us out by providing instructions.&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7473</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7473"/>
		<updated>2020-04-27T09:02:59Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a certificate */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
You request a certificate at https://cert-manager.com/customer/sunet/idp/clientgeant where you will be required to login with your local credentials at your organization.&lt;br /&gt;
&lt;br /&gt;
If you login and you organization is set up correctly, you will get to a page with the heading &amp;quot;Digital Certificate Enrollment&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
FIXME: Discuss error messages you can get.&lt;br /&gt;
&lt;br /&gt;
To proceed, you will need to choose if the key for your certificate should be generated by you on your computer, or at the server side. The different methods are described in the two following sections.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If there is a policy reason for you to refuse to have the key generated on the server side&lt;br /&gt;
* If there is a technical reason that needs the key to be genereated locally&lt;br /&gt;
&lt;br /&gt;
To use this method, first generate a key and a CSR (certificate signing request) on your computer. If you are not required to use another program, use OpenSSL:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chmod go= userkey.pem&lt;br /&gt;
&lt;br /&gt;
Then, after logging in to https://cert-manager.com/customer/sunet/idp/clientgeant&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Upload CSR&lt;br /&gt;
* Use &amp;quot;Choose File&amp;quot; to upload the usercert_request.pem file you created above&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate in a PEM-format file called certs.pem.&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
Use this method:&lt;br /&gt;
&lt;br /&gt;
* If you can accept that the key is generated on the server side&lt;br /&gt;
* If you want to avoid having to do local openssl commands or similar to get a certificate for your web browser&lt;br /&gt;
&lt;br /&gt;
To use this method, login to https://cert-manager.com/customer/sunet/idp/clientgeant and&lt;br /&gt;
&lt;br /&gt;
* Select Certificate Profile = GÉANT IGTF-MICS Personal&lt;br /&gt;
* Select Private Key = Generate RSA&lt;br /&gt;
* Provide the P12 Password that will be used to encrypt the PKCS#12 file you get back&lt;br /&gt;
* Click the SUBMIT button and accept the click-through license&lt;br /&gt;
&lt;br /&gt;
After a short pause, you will be offered to download your certificate and key in a PKCS#12 file called certs.p12.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7472</id>
		<title>Requesting a grid certificate using the Sectigo SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Sectigo_SSO_Portal&amp;diff=7472"/>
		<updated>2020-04-27T08:46:27Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): Created page with &amp;quot;= Organization Support =  The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.  This section docum...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Support =&lt;br /&gt;
&lt;br /&gt;
The TCS service has changed backend provider from DigiCert to Sectigo. This page describes how to get a certificate from 2020-05-01.&lt;br /&gt;
&lt;br /&gt;
This section documents organizations known to have done all the setup required to enable this for their users:&lt;br /&gt;
&lt;br /&gt;
* LiU: verified OK 2020-04-24 by Kent and colleagues at NSC&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate using a locally generated key and CSR ==&lt;br /&gt;
&lt;br /&gt;
== Requesting a certificate with server-side generation of key ==&lt;br /&gt;
&lt;br /&gt;
= Using the certificate =&lt;br /&gt;
&lt;br /&gt;
== Using the certificate in the web browser ==&lt;br /&gt;
&lt;br /&gt;
== Using the certificate with grid tools ==&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7085</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7085"/>
		<updated>2019-09-26T12:53:24Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a personal grid certificate using CSR created outside of the browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Browser Support =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate directly in the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
If that is your case, you can [[#Requesting_a_personal_grid_certificate_directly_in_the_browser|follow the simpler instructions below]].&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to [[#Requesting_a_personal_grid_certificate_using_CSR_created_outside_of_the_browser|follow the more complex instructions below]]. &lt;br /&gt;
&lt;br /&gt;
For some background, see https://knowledge.digicert.com/generalinformation/keygenfirefox.html&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Browser Support above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate using CSR created outside of the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Edge&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
### Chrome&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
# Generate a CSR using 'openssl req' (remember any pass phrase used to encrypt the key) and display the CSR:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chown go= userkey.pem&lt;br /&gt;
 cat usercert_request.pem&lt;br /&gt;
&lt;br /&gt;
#Paste the CSR text into the &amp;quot;CSR&amp;quot; text box&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and you will get to a page listing all you personal certificates. Scroll to the bottom if needed to find the latest one generated now and use the Download button to save the ZIP file (the name of the file depends on your name).&lt;br /&gt;
# Unzip the ZIP file and make a PKCS#12 file from its certificate together with the key you generated above, remembering that your exact names for the directory and certificate file will vary. You will need to reenter your key passphrase from above, and then set a new passphrase for the PKCS#12 export file itself.&lt;br /&gt;
&lt;br /&gt;
  unzip mitt_namn_namne12_foo_se.zip&lt;br /&gt;
  openssl pkcs12 -export -inkey userkey.pem -in mitt_namn_namne12_foo_se/mitt_namn_namne12_foo_se.crt -out my_cert.p12&lt;br /&gt;
&lt;br /&gt;
# Import the PKCS#12 file into your browser(s):&lt;br /&gt;
## Firefox: Select ''Preferences'', type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'my_cert.p12' file created above, provide the passphrase. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
## Chrome: Select ''Settings'', access the search icon and type 'certificate', click 'Manage certificates', click the 'Import' button, select your 'my_cert.p12' file created above, provide the passphrase. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
## Other browsers: ''Please help us out by providing instructions''.&lt;br /&gt;
# Quit your web browser, start it again, try accessing a site protected by your grid certificate (making sure you select the new certificate) and verify that it works.&lt;br /&gt;
# Remove the userkey.pem and my_cert.p12 files (or take care of them in some other good way) as they do contain your private key.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7084</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7084"/>
		<updated>2019-09-26T12:51:10Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Browser Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Browser Support =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate directly in the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
If that is your case, you can [[#Requesting_a_personal_grid_certificate_directly_in_the_browser|follow the simpler instructions below]].&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to [[#Requesting_a_personal_grid_certificate_using_CSR_created_outside_of_the_browser|follow the more complex instructions below]]. &lt;br /&gt;
&lt;br /&gt;
For some background, see https://knowledge.digicert.com/generalinformation/keygenfirefox.html&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Browser Support above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate using CSR created outside of the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Edge&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
### Chrome&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
# Generate a CSR using 'openssl req' (remember any pass phrase used to encrypt the key) and display the CSR:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chown go= userkey.pem&lt;br /&gt;
 cat usercert_request.pem&lt;br /&gt;
&lt;br /&gt;
#Paste the CSR text into the &amp;quot;CSR&amp;quot; text box&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and you will get to a page listing all you personal certificates. Scroll to the bottom if needed to find the latest one generated now and use the Download button to save the ZIP file (the name of the file depends on your name).&lt;br /&gt;
# Unzip the ZIP file and make a PKCS#12 file from its certificate together with the key you generated above, remembering that your exact names for the directory and certificate file will vary. You will need to reenter your key passphrase from above, and then set a new passphrase for the PKCS#12 export file itself.&lt;br /&gt;
&lt;br /&gt;
  unzip mitt_namn_namne12_foo_se.zip&lt;br /&gt;
  openssl pkcs12 -export -inkey userkey.pem -in mitt_namn_namne12_foo_se/mitt_namn_namne12_foo_se.crt -out my_cert.p12&lt;br /&gt;
&lt;br /&gt;
# Import the PKCS#12 file into your browser.&lt;br /&gt;
## Firefox: Select ''Preferences'', type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'my_cert.p12' file created above, provide the passphrase. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
## Chrome: Select ''Settings'', access the search icon and type 'certificate', click 'Manage certificates', click the 'Import' button, select your 'my_cert.p12' file created above, provide the passphrase. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
## Other browsers: ''Please help us out by providing instructions''.&lt;br /&gt;
# Quit your web browser, start it again, try accessing a site protected by your grid certificate (making sure you select the new certificate) and verify that it works.&lt;br /&gt;
# Remove the userkey.pem and my_cert.p12 files (or take care of them in some other good way) as they do contain your private key.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7083</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7083"/>
		<updated>2019-09-26T12:38:10Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a personal grid certificate using CSR and key generated outside the browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Browser Support =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate directly in the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
For some background, see https://knowledge.digicert.com/generalinformation/keygenfirefox.html&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Browser Support above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate using CSR created outside of the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Edge&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
### Chrome&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
# Generate a CSR using 'openssl req' (remember any pass phrase used to encrypt the key) and display the CSR:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chown go= userkey.pem&lt;br /&gt;
 cat usercert_request.pem&lt;br /&gt;
&lt;br /&gt;
#Paste the CSR text into the &amp;quot;CSR&amp;quot; text box&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and you will get to a page listing all you personal certificates. Scroll to the bottom if needed to find the latest one generated now and use the Download button to save the ZIP file (the name of the file depends on your name).&lt;br /&gt;
# Unzip the ZIP file and make a PKCS#12 file from its certificate together with the key you generated above, remembering that your exact names for the directory and certificate file will vary. You will need to reenter your key passphrase from above, and then set a new passphrase for the PKCS#12 export file itself.&lt;br /&gt;
&lt;br /&gt;
  unzip mitt_namn_namne12_foo_se.zip&lt;br /&gt;
  openssl pkcs12 -export -inkey userkey.pem -in mitt_namn_namne12_foo_se/mitt_namn_namne12_foo_se.crt -out my_cert.p12&lt;br /&gt;
&lt;br /&gt;
# Import the PKCS#12 file into your browser.&lt;br /&gt;
## Firefox: Select ''Preferences'', type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'my_cert.p12' file created above, provide the passphrase. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
## Chrome: Select ''Settings'', access the search icon and type 'certificate', click 'Manage certificates', click the 'Import' button, select your 'my_cert.p12' file created above, provide the passphrase. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
## Other browsers: ''Please help us out by providing instructions''.&lt;br /&gt;
# Quit your web browser, start it again, try accessing a site protected by your grid certificate (making sure you select the new certificate) and verify that it works.&lt;br /&gt;
# Remove the userkey.pem and my_cert.p12 files (or take care of them in some other good way) as they do contain your private key.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7082</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7082"/>
		<updated>2019-09-26T12:35:27Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a personal grid certificate directly in the browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Browser Support =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate directly in the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
For some background, see https://knowledge.digicert.com/generalinformation/keygenfirefox.html&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Browser Support above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate using CSR and key generated outside the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Edge&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
### Chrome&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
# Generate a CSR using 'openssl req' (remember any pass phrase used to encrypt the key) and display the CSR:&lt;br /&gt;
&lt;br /&gt;
 openssl req -new -newkey rsa:2048 -out usercert_request.pem -keyout userkey.pem -subj '/CN=Mitt Namn'&lt;br /&gt;
 chown go= userkey.pem&lt;br /&gt;
 cat usercert_request.pem&lt;br /&gt;
&lt;br /&gt;
#Paste the CSR text into the &amp;quot;CSR&amp;quot; text box&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and you will get to a page listing all you personal certificates. Scroll to the bottom if needed to find the latest one generated now and use the Download button to save the ZIP file (the name of the file depends on your name).&lt;br /&gt;
# Unzip the ZIP file and make a PKCS#12 file from its certifikate together with the key you generated above, remembering that your exact names for the directory and certificate file will vary. You will need to reenter your key passphrase from above, and then set a new passphrase for the PKCS#12 export file itself.&lt;br /&gt;
&lt;br /&gt;
  unzip mitt_namn_namne12_foo_se.zip&lt;br /&gt;
  openssl pkcs12 -export -inkey userkey.pem -in mitt_namn_namne12_foo_se/mitt_namn_namne12_foo_se.crt -out my_cert.p12&lt;br /&gt;
&lt;br /&gt;
# Import the PKCS#12 file into your browser.&lt;br /&gt;
## Firefox: Select ''Preferences'', type 'certificate' in the search box, click button 'View Certificates', click button 'Import', select your 'my_cert.p12' file created above, provide the passphrase. You should find you new certificate listed in the 'Your Certificates' table.&lt;br /&gt;
## Chrome: Select ''Settings'', access the search icon and type 'certificate', click 'Manage certificates', click the 'Import' button, select your 'my_cert.p12' file created above, provide the passphrase. You should find your new certificate listed on the page, after unfolding the right organization heading.&lt;br /&gt;
# Quit your web browser, start it again, try accessing a site protected by your grid certificate (making sure you select the new certificate) and verify that it works.&lt;br /&gt;
# Remove the userkey.pem and my_cert.p12 files (or take care of them in some other good way) as they do contain your private key.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7081</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7081"/>
		<updated>2019-09-26T12:03:01Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Browser Support =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate directly in the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
For some background, see https://knowledge.digicert.com/generalinformation/keygenfirefox.html&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Browser Support above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7080</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7080"/>
		<updated>2019-09-26T11:35:09Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Caveat */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Caveat =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate inside the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
For some background, see https://knowledge.digicert.com/generalinformation/keygenfirefox.html&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Caveat above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7079</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7079"/>
		<updated>2019-09-26T11:30:09Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a eScience (grid) certificate directly in the browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Caveat =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate inside the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a personal grid certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Caveat above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7078</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7078"/>
		<updated>2019-09-26T11:28:13Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a eScience (grid) certificate directly in the browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Caveat =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate inside the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a eScience (grid) certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Caveat above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox up to version 68 (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox up to version 68 (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox up to version 68 (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7077</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7077"/>
		<updated>2019-09-26T11:27:01Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Caveat */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Caveat =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate inside the browser, you need to be using one of these:&lt;br /&gt;
&lt;br /&gt;
* Safari&lt;br /&gt;
* Internet Explorer&lt;br /&gt;
* Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a eScience (grid) certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Caveat above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7076</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7076"/>
		<updated>2019-09-26T11:25:41Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a eScience (grid) certificate */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Caveat =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate inside the browser, you need to be running:&lt;br /&gt;
&lt;br /&gt;
- Safari&lt;br /&gt;
- Internet Explorer&lt;br /&gt;
- Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a eScience (grid) certificate directly in the browser =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Caveat above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7075</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7075"/>
		<updated>2019-09-26T11:25:12Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Caveat */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Caveat =&lt;br /&gt;
&lt;br /&gt;
Browser support for the &amp;lt;keygen&amp;gt; feature used to request and receive certificates directly in the browser is fading away. Google Chrome removed it in 2017 and Firefox removed it in 2019 (from version 69). Microsoft Edge has not supported it. Safari still supports it as of today, and Internet Explorer has another mechanism available that provides the same feature.&lt;br /&gt;
&lt;br /&gt;
Thus, to request a certificate inside the browser, you need to be running:&lt;br /&gt;
&lt;br /&gt;
- Safari&lt;br /&gt;
- Internet Explorer&lt;br /&gt;
- Firefox ESR (as long as they are based on Firefox before version 69)&lt;br /&gt;
&lt;br /&gt;
For other browsers you need to generate the key and CSR outside of the browser, paste in the CSR, download the certificate and import it into the browser (if that is where the cert is going to be used). We hope to be able to update the instructions for that soon.&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a eScience (grid) certificate =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Caveat above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7074</id>
		<title>Requesting a grid certificate using the Digicert SSO Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Digicert_SSO_Portal&amp;diff=7074"/>
		<updated>2019-09-25T09:45:38Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Caveat */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:Swestore]]&lt;br /&gt;
[[Category:Swestore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
= Caveat =&lt;br /&gt;
&lt;br /&gt;
Due to Google wanting to promote alternatives to client certificates, '''you can no longer use Google Chrome/Chromium''' for getting a Digicert certificate. '''Firefox, Safari and Internet Explorer still works'''. We have reports that '''Microsoft Edge does not work'''.&lt;br /&gt;
&lt;br /&gt;
= Set a master password =&lt;br /&gt;
&lt;br /&gt;
When using Firefox, or any browser on Linux/Unix, it is highly recommended to use a Master Password to protect stored logins and passwords.&lt;br /&gt;
&lt;br /&gt;
Instructions for Firefox: https://support.mozilla.org/en-US/kb/use-master-password-protect-stored-logins&lt;br /&gt;
&lt;br /&gt;
= Requesting a eScience (grid) certificate =&lt;br /&gt;
&lt;br /&gt;
# Start a suitable web browser (see Caveat above for details):&lt;br /&gt;
## Windows:&lt;br /&gt;
### Internet Explorer&lt;br /&gt;
### Firefox (does not use OS certificate store, obtained certificate is only available to Firefox)&lt;br /&gt;
## macOS:&lt;br /&gt;
### Safari&lt;br /&gt;
### Firefox (does not use OS Keychain, obtained certificate is only available to Firefox)&lt;br /&gt;
## Linux/Unix:&lt;br /&gt;
### Firefox (obtained certificate is only available  to Firefox)&lt;br /&gt;
#Go to  https://digicert.com/sso&lt;br /&gt;
#Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
#:[[File:Digicert-idp.png]]&lt;br /&gt;
#Login at your home university.&lt;br /&gt;
#Select the ''Grid Premium'' product.&lt;br /&gt;
#:[[File:Digicert-product-select.png]]&lt;br /&gt;
#Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
#Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
#Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
= Exporting the Digicert certificate =&lt;br /&gt;
&lt;br /&gt;
If you need to use the certificate with other programs it needs to be exported to a file and imported where appropriate.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Digicert certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
= Adding certificate to OS certificate store =&lt;br /&gt;
&lt;br /&gt;
Some operating systems have a built in keychain/keystore. If Firefox was used the certificate needs to be imported to keychain/keystore in order to be available for other programs.&lt;br /&gt;
&lt;br /&gt;
* [[Add client certificate to keychain on macOS]]&lt;br /&gt;
&lt;br /&gt;
Windows: '''FIXME: Investigate and update instructions accordingly'''.&lt;br /&gt;
&lt;br /&gt;
= Using the certificate with grid tools =&lt;br /&gt;
&lt;br /&gt;
To use the Digicert certificates with the ARC grid client they have to be exported from the browser into a file and then converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare an exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Support&amp;diff=6730</id>
		<title>Support</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Support&amp;diff=6730"/>
		<updated>2017-02-21T15:01:27Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Support alternatives:&lt;br /&gt;
&lt;br /&gt;
; Guides&lt;br /&gt;
: This site has a number of guides on a variety of subjects, see [[:Category:Guide]].&lt;br /&gt;
&lt;br /&gt;
; Centre, Swestore and SUPR support&lt;br /&gt;
: Go to [http://supr.snic.se/support http://supr.snic.se/support]. If you can login to SUPR you can use a support form that helps you fill in a good support request. If you cannot login you will get a list of email addresses to use for your support request.&lt;br /&gt;
: This is by far the quickest way of getting your problems solved, and this is where you should address all your support questions. In case an issue cannot be immediately solved by these support queues it will be forwarded to the right place for you. &lt;br /&gt;
&lt;br /&gt;
; Application support&lt;br /&gt;
: e-mail: [mailto:application-support@snic.se application-support@snic.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: This mail address can be used if you have support questions that are not directly regarding how to run a given application on a specific SNIC HPC resource, but regarding how to use the application itself or how to solve an issue with the application that is not specific to running it on a certain resource. &amp;lt;br&amp;gt;&lt;br /&gt;
: The application-support queue is monitored by all the application experts, who are distributed over all the six SNIC HPC centers, so there is a good chance that someone who knows the given application will see the support request and help answer your questions or solve your issue. &amp;lt;br&amp;gt;&lt;br /&gt;
: If you don’t know whether or not to use the application-support address for your support request, then just send your request to the support address at the HPC center where you run your jobs. Then someone monitoring that support queue will in turn move your support request to the application-support queue if they find that your request is better handled there.&lt;br /&gt;
&lt;br /&gt;
; SweGrid support&lt;br /&gt;
: e-mail: [mailto:support@swegrid.se support@swegrid.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: For support regarding the [[SweGrid]] resources.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Support&amp;diff=6729</id>
		<title>Support</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Support&amp;diff=6729"/>
		<updated>2017-02-21T14:59:22Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Support alternatives:&lt;br /&gt;
&lt;br /&gt;
; Guides&lt;br /&gt;
: This site has a number of guides on a variety of subjects, see [[:Category:Guide]].&lt;br /&gt;
&lt;br /&gt;
; Centre, Swestore and SUPR support&lt;br /&gt;
: Go to [http://supr.snic.se/support http://supr.snic.se/support]. If you can login to SUPR you can use a support form that help you fill in a good support request. If you cannot login you will get a list of email addresses to use for your support request.&lt;br /&gt;
: This is by far the quickest way of getting your problems solved, and this is where you should address all your support questions. In case an issue cannot be immediately solved by these support queues it will be forwarded to the right place for you. &lt;br /&gt;
&lt;br /&gt;
; Application support&lt;br /&gt;
: e-mail: [mailto:application-support@snic.se application-support@snic.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: This mail address can be used if you have support questions that are not directly regarding how to run a given application on a specific SNIC HPC resource, but regarding how to use the application itself or how to solve an issue with the application that is not specific to running it on a certain resource. &amp;lt;br&amp;gt;&lt;br /&gt;
: The application-support queue is monitored by all the application experts, who are distributed over all the six SNIC HPC centers, so there is a good chance that someone who knows the given application will see the support request and help answer your questions or solve your issue. &amp;lt;br&amp;gt;&lt;br /&gt;
: If you don’t know whether or not to use the application-support address for your support request, then just send your request to the support address at the HPC center where you run your jobs. Then someone monitoring that support queue will in turn move your support request to the application-support queue if they find that your request is better handled there.&lt;br /&gt;
&lt;br /&gt;
; SweGrid support&lt;br /&gt;
: e-mail: [mailto:support@swegrid.se support@swegrid.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: For support regarding the [[SweGrid]] resources.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Terena_eScience_Portal&amp;diff=6146</id>
		<title>Requesting a grid certificate using the Terena eScience Portal</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Requesting_a_grid_certificate_using_the_Terena_eScience_Portal&amp;diff=6146"/>
		<updated>2015-09-01T08:27:39Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:SweStore]]&lt;br /&gt;
[[Category:SweStore user guide]]&lt;br /&gt;
[[Grid_certificates|&amp;lt; Grid certificates]]&lt;br /&gt;
&lt;br /&gt;
NEWS: In July 2015 the TERENA TCS service switched backend provider from Comodo to DigiCert. That also meant switching the grid certificate portal from the TERENA-run Confusa service (https://tcs-escience.sunet.se for the SUNET instance) to a vendor-provided portal (https://digicert.com/sso/). Also, TERENA has been merged/renamed and is now ​GÉANT.&lt;br /&gt;
&lt;br /&gt;
These instructions have been updated to point to the new service, but they could be improved with screenshots, more explanations etc. Please feel free to work on them.&lt;br /&gt;
&lt;br /&gt;
To request a TCS grid certificate&lt;br /&gt;
&lt;br /&gt;
1. Go to  https://digicert.com/sso&lt;br /&gt;
&lt;br /&gt;
2. Type the first characters of your university (or similar) and then select the Identity Provider to use for login.&lt;br /&gt;
&lt;br /&gt;
3. Login at your home university.&lt;br /&gt;
&lt;br /&gt;
4. Select the ''Grid Premium'' product.&lt;br /&gt;
&lt;br /&gt;
5. Normally, leave the CSR field blank to get a key generated in your browser.&lt;br /&gt;
&lt;br /&gt;
6. Press &amp;quot;Request Certificate&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
7. Your certificate is generated and should be automatically imported into your browser.&lt;br /&gt;
&lt;br /&gt;
=== Exporting the Terena certificate for use with Grid tools ===&lt;br /&gt;
&lt;br /&gt;
To use the Terena certificates with the ARC grid client they have to be exported from the browser and converted into a suitable format.&lt;br /&gt;
&lt;br /&gt;
See [[Exporting a client certificate]] for detailed instructions on how to export a Terena certificate from the most popular browsers.&lt;br /&gt;
&lt;br /&gt;
See [[Preparing a client certificate]] for detailed instructions on how to prepare the exported certificate for use with grid tools.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Support&amp;diff=5296</id>
		<title>Support</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Support&amp;diff=5296"/>
		<updated>2013-09-13T13:52:17Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Support alternatives:&lt;br /&gt;
&lt;br /&gt;
; Guides&lt;br /&gt;
: This site has a number of guides on a variety of subjects, see [[:Category:Guide]].&lt;br /&gt;
&lt;br /&gt;
; Centre support&lt;br /&gt;
: [http://www.c3se.chalmers.se/ C3SE] e-mail: [mailto:support@c3se.chalmers.se support@c3se.chalmers.se]&lt;br /&gt;
: [http://www.hpc2n.umu.se/ HPC2N] e-mail: [mailto:support@hpc2n.umu.se support@hpc2n.umu.se]&lt;br /&gt;
: [http://www.lunarc.lu.se/ Lunarc] e-mail: [mailto:support@lunarc.lu.se support@lunarc.lu.se]&lt;br /&gt;
: [http://www.nsc.liu.se/ NSC] e-mail: [mailto:support@nsc.liu.se support@nsc.liu.se]&lt;br /&gt;
: [http://www.pdc.kth.se PDC] e-mail: [mailto:support@pdc.kth.se support@pdc.kth.se]&lt;br /&gt;
: [http://www.uppmax.uu.se Uppmax] e-mail: [mailto:support@uppmax.uu.se support@uppmax.uu.se]&lt;br /&gt;
: This is by far the quickest way of getting your problems solved, and this is where you should address all your support questions. In case an issue cannot be immediately solved by these support queues it will be forwarded to the right place for you. &lt;br /&gt;
&lt;br /&gt;
; Application support&lt;br /&gt;
: e-mail: [mailto:application-support@snic.se application-support@snic.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: This mail address can be used if you have support questions that are not directly regarding how to run a given application on a specific SNIC HPC resource, but regarding how to use the application itself or how to solve an issue with the application that is not specific to running it on a certain resource. &amp;lt;br&amp;gt;&lt;br /&gt;
: The application-support queue is monitored by all the application experts, who are distributed over all the six SNIC HPC centers, so there is a good chance that someone who knows the given application will see the support request and help answer your questions or solve your issue. &amp;lt;br&amp;gt;&lt;br /&gt;
: If you don’t know whether or not to use the application-support address for your support request, then just send your request to the support address at the HPC center where you run your jobs. Then someone monitoring that support queue will in turn move your support request to the application-support queue if they find that your request is better handled there.&lt;br /&gt;
&lt;br /&gt;
; SweGrid support&lt;br /&gt;
: e-mail: [mailto:support@swegrid.se support@swegrid.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: For support regarding the SweGrid resources&lt;br /&gt;
&lt;br /&gt;
; SweStore support&lt;br /&gt;
: e-mail: [mailto:support@swestore.se support@swestore.se]&lt;br /&gt;
: For obtaining support regarding the national storage.&lt;br /&gt;
: See also [[SweStore]]&lt;br /&gt;
&lt;br /&gt;
; SUPR support&lt;br /&gt;
: e-email: [mailto:support@supr.snic.se support@supr.snic.se]&amp;lt;br&amp;gt;&lt;br /&gt;
: For support regarding the [https://supr.snic.se/ SUPR] SNIC portal.&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[FAQ]] - Frequently asked questions.&lt;br /&gt;
* [http://www.pdc.kth.se/about/contact/support-requests More information on how to contact PDC support]&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=LiU_Certificate_Instructions&amp;diff=4797</id>
		<title>LiU Certificate Instructions</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=LiU_Certificate_Instructions&amp;diff=4797"/>
		<updated>2013-03-15T15:22:20Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;See instructions at http://www.liu.se/insidan/it/irt/personliga-certifikat?l=en&lt;br /&gt;
&lt;br /&gt;
Remember that it is the  eScience version you should choose.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=LiU_Certificate_Instructions&amp;diff=4796</id>
		<title>LiU Certificate Instructions</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=LiU_Certificate_Instructions&amp;diff=4796"/>
		<updated>2013-03-15T15:20:25Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): Created page with &amp;quot;See http://www.liu.se/insidan/it/irt/personliga-certifikat   You should go to the person responsible for computer accounts at your department. You should bring a valid Swedish ph...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;See http://www.liu.se/insidan/it/irt/personliga-certifikat &lt;br /&gt;
&lt;br /&gt;
You should go to the person responsible for computer accounts at your department. You should bring a valid Swedish photo ID (e.g. driver's license or passport). The account responsible person will check your identity and update your status at account.liu.se so that you can request certificates from the Terena portal.&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
	<entry>
		<id>http://docs.snic.se/w/index.php?title=Grid_certificates&amp;diff=4795</id>
		<title>Grid certificates</title>
		<link rel="alternate" type="text/html" href="http://docs.snic.se/w/index.php?title=Grid_certificates&amp;diff=4795"/>
		<updated>2013-03-15T15:17:33Z</updated>

		<summary type="html">&lt;p&gt;Kent Engström (NSC): /* Requesting a certificate */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Grid computing]]&lt;br /&gt;
[[Category:SweGrid user guide]]&lt;br /&gt;
[[Category:SweStore]]&lt;br /&gt;
[[Category:SweStore user guide]]&lt;br /&gt;
[[Getting started with SweGrid|&amp;lt; Getting started with SweGrid]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[SweStore|&amp;lt; SweStore]]&lt;br /&gt;
&lt;br /&gt;
=Introduction to certificates=&lt;br /&gt;
&lt;br /&gt;
In order to get access to computer and storage resources on the grid or [[SweStore]] you must have a valid (grid) certificate. This certificate is used instead of a username and password when accessing the resource. The resource have a certificate that tells you that you have contacted the right resource. This is exactly the same mechanism used when you use a web browser to contact your bank.&lt;br /&gt;
&lt;br /&gt;
A certificate is the similar to a passport in real-life. In the same way you have prove your credentials when you acquire a passport the same is true for a certificate. A third party, the Certificate Authority or CA, that both you and the resource trust has to vouch for your identity and sign your certificate.&lt;br /&gt;
&lt;br /&gt;
A certificate consist of a public key, some user information and a signature of the CA. In addition to the certificate you have a private key. The private key is secret and should be kept as secure as possible.&lt;br /&gt;
&lt;br /&gt;
For more information regarding certificates and public key cryptography:&lt;br /&gt;
&lt;br /&gt;
[http://en.wikipedia.org/wiki/Public-key_cryptography http://en.wikipedia.org/wiki/Public-key_cryptography]&lt;br /&gt;
&lt;br /&gt;
[http://en.wikipedia.org/wiki/Public_key_certificate http://en.wikipedia.org/wiki/Public_key_certificate]&lt;br /&gt;
&lt;br /&gt;
[http://www.nordugrid.org/documents/certificate_howto.html http://www.nordugrid.org/documents/certificate_howto.html]&lt;br /&gt;
&lt;br /&gt;
* The grid certificate and the private key are stored in your web browser and/or located in ~/.globus at the host(s) from where you will be accessing the resource:&lt;br /&gt;
      usercert.pem&lt;br /&gt;
      userkey.pem&lt;br /&gt;
* The certificate contains your public key, your name and organization and a signature by the CA. It is does not contain any username.&lt;br /&gt;
* The certificate is valid for 13 month and should be renewed yearly.&lt;br /&gt;
* The private key should be handled with great care. It should only be readable by you (i.e. ``chmod 400 userkey.pem''). Store the key on trusted computers and transfer the key between computers using encryption (using for example scp).&lt;br /&gt;
* The private key is encrypted using a passphrase. Anyone that can decrypt the private key will be able to authenticate as you to grid resources. This is similar to the private key in SSH. You must choose a strong passphrase for the private key. This passphrase must not be used anywhere else. You must never ever give away the passphrase to somebody else.&lt;br /&gt;
* You should not share the certificate with someone. It's personal. &lt;br /&gt;
&lt;br /&gt;
For more information regarding certificates and public key cryptography:&lt;br /&gt;
&lt;br /&gt;
[http://en.wikipedia.org/wiki/Public-key_cryptography http://en.wikipedia.org/wiki/Public-key_cryptography]&lt;br /&gt;
[http://en.wikipedia.org/wiki/Public_key_certificate http://en.wikipedia.org/wiki/Public_key_certificate]&lt;br /&gt;
&lt;br /&gt;
= Requesting a certificate =&lt;br /&gt;
&lt;br /&gt;
Certificates are issued by a Certificate Authority or CA. For Swedish users there are two relevant CA:s that can issue grid certificates, Terena and Nordugrid. The Terena CA is preferred if it is available for your university or research group, but many sites has not enabled this service yet. The Nordugrid CA can also be used but requires more manual work by all parties.&lt;br /&gt;
&lt;br /&gt;
Recommended procedure for each university:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
| University&lt;br /&gt;
| CA&lt;br /&gt;
| Specific instructions&lt;br /&gt;
|-&lt;br /&gt;
| LU&lt;br /&gt;
| Terena CA&lt;br /&gt;
| [[LU_Certificate_Information|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| LiU&lt;br /&gt;
| Terena CA&lt;br /&gt;
| [[LiU_Certificate_Instructions|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| CTH&lt;br /&gt;
| NorduGrid CA&lt;br /&gt;
| [[Chalmers_Certificate_Instructions|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| GU&lt;br /&gt;
| NorduGrid CA&lt;br /&gt;
| [[GU_Certificate_Instructions|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| UU&lt;br /&gt;
| Terena CA&lt;br /&gt;
| [[UU_Certificate_Instructions|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| KTH&lt;br /&gt;
| Terena CA&lt;br /&gt;
| [[KTH_Certificate_Information|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| SU&lt;br /&gt;
| NorduGrid CA&lt;br /&gt;
| [[SU_Certificate_Information|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| KI&lt;br /&gt;
| NorduGrid CA&lt;br /&gt;
| [[KI_Certificate_Information|more...]]&lt;br /&gt;
|-&lt;br /&gt;
| UmU&lt;br /&gt;
| Terena CA&lt;br /&gt;
| [[UmU_Certificate_Information|more...]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Requesting a grid certificate using the Terena eScience Portal|Instructions for the Terena CA]]&lt;br /&gt;
&lt;br /&gt;
[[Requesting a grid certificate from the Nordugrid CA|Instructions for the NorduGrid CA (use only if Terena eScience isn't available at your site)]]&lt;br /&gt;
&lt;br /&gt;
= Requesting membership in the SweGrid VO =&lt;br /&gt;
&lt;br /&gt;
SweGrid and SweStore resources are currently being allocated for VO:s, virtual organizations, rather than individual users. A VO is basically just a list of users. To be able to use a SweGrid or SweStore resource a membership in the SweGrid VO (virtual organization) and a corresponding subgroup is required. To apply for membership, make sure that the NorduGrid root CA certificate and your personal certificate is installed in the browser. &lt;br /&gt;
&lt;br /&gt;
The NorduGrid CA cert can be installed by clicking on the following link:&lt;br /&gt;
&lt;br /&gt;
 [http://ca.nordugrid.org/cacrt.crt http://ca.nordugrid.org/cacrt.crt]&lt;br /&gt;
&lt;br /&gt;
Make sure you check the &amp;quot;Trust this CA to identify web sites.&amp;quot; boxes in the dialog shown.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:certinstall.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
When certificates have been installed in the browser go to the following URL:&lt;br /&gt;
&lt;br /&gt;
 [https://voms.ndgf.org:8443/voms/swegrid.se https://voms.ndgf.org:8443/voms/swegrid.se]&lt;br /&gt;
&lt;br /&gt;
and follow the instructions. In a couple of hours you will be added to the SweGrid VO. &lt;br /&gt;
&lt;br /&gt;
To be added to the correct SweGrid project send a mail to [mailto:support@swegrid.se support@swegrid.se] and specify your DN as shown in the Terena portal or from the '''arcproxy --info''' command and which SNIC-project to be added to.&lt;br /&gt;
&lt;br /&gt;
To be added to the correct Swestore allocation send a mail to [mailto:swestore-support@snic.vr.se swestore-support@snic.vr.se] and specify your DN as shown in the Terena portal or from the '''arcproxy --info''' command and which Swestore allocation to be added to.&lt;br /&gt;
&lt;br /&gt;
= Proxy certificates =&lt;br /&gt;
&lt;br /&gt;
Authentication on the grid is done using special short lived ''proxy'' certificates. There are several tools available for creating, checking and destroying these proxy certificates.&lt;br /&gt;
 &lt;br /&gt;
== Creating a proxy certificate ==&lt;br /&gt;
&lt;br /&gt;
To create a short lived proxy that can be used for authentication with grid services, the '''arcproxy''' command can be used. A 12 hour (default) proxy is created in the following example:&lt;br /&gt;
&lt;br /&gt;
 $ arcproxy&lt;br /&gt;
 Your identity: /O=Grid/O=NorduGrid/OU=lunarc.lu.se/CN=Kalle Kula&lt;br /&gt;
 Enter pass phrase for /home/kalle/.globus/userkey.pem:&lt;br /&gt;
 .++++++&lt;br /&gt;
 .....++++++&lt;br /&gt;
 Proxy generation succeeded&lt;br /&gt;
 Your proxy is valid until: 2011-03-11 03:00:14&lt;br /&gt;
&lt;br /&gt;
The proxy file itself will be created in the '''/tmp''' directory with the format '''x509up_uid''', where uid is the user id number for your account.&lt;br /&gt;
&lt;br /&gt;
In some cases a longer lived proxy will be needed. This is achieved using the '''--constraint''' switch. A 24-hour can be created by issuing the following command:&lt;br /&gt;
&lt;br /&gt;
 $ arcproxy --constraint=&amp;quot;validityPeriod=24H&amp;quot;&lt;br /&gt;
 Your identity: /O=Grid/O=NorduGrid/OU=lunarc.lu.se/CN=Kalle Kula&lt;br /&gt;
 Enter pass phrase for /home/kalle/.globus/userkey.pem:&lt;br /&gt;
 ....++++++&lt;br /&gt;
 .....++++++&lt;br /&gt;
 Proxy generation succeeded&lt;br /&gt;
 Your proxy is valid until: 2011-03-11 15:03:19&lt;br /&gt;
&lt;br /&gt;
== Checking proxy lifetime ==&lt;br /&gt;
&lt;br /&gt;
The remaining lifetime of a proxy certificate can be checked using the '''arcproxy''' command with the '''--info''' switch.&lt;br /&gt;
&lt;br /&gt;
 $ arcproxy --info&lt;br /&gt;
 Subject: /O=Grid/O=NorduGrid/OU=lunarc.lu.se/CN=Kalle Kula/CN=1567862803&lt;br /&gt;
 Identity: /O=Grid/O=NorduGrid/OU=lunarc.lu.se/CN=Kalle Kula&lt;br /&gt;
 Time left for proxy: 11 hours 55 minutes&lt;br /&gt;
 Proxy path: /tmp/x509up_u500&lt;br /&gt;
 Proxy type: X.509 Proxy Certificate Profile RFC compliant restricted proxy&lt;br /&gt;
&lt;br /&gt;
In this example the proxy certificate is valid for 11 hours 55 minutes more.&lt;br /&gt;
&lt;br /&gt;
== Destroying a proxy certificate ==&lt;br /&gt;
&lt;br /&gt;
A proxy can be destroyed with the '''-r''' or '''--remove''' switch.&lt;br /&gt;
&lt;br /&gt;
 $ arcproxy -r&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
 $ arcproxy --remove&lt;br /&gt;
&lt;br /&gt;
= VOMS certificates =&lt;br /&gt;
&lt;br /&gt;
As long as you are a member of only one VO or VO group, you can&lt;br /&gt;
authenticate to a grid service with the regular grid proxy certificate&lt;br /&gt;
as defined in the previous section. If you are a member of more than&lt;br /&gt;
one VO or VO group you may want to select which membership you want to&lt;br /&gt;
be authenticated as. For example, if you are a member of&lt;br /&gt;
''swegrid.se:/swegrid.se/ops'' (operations staff) and&lt;br /&gt;
''swegrid.se:/swegrid.se/bils'' and want to write a file, who should&lt;br /&gt;
be the owner? Ops or bils? You need to provide some additional&lt;br /&gt;
information. In the grid world this is done with a voms proxy&lt;br /&gt;
certificate which basically is a regular proxy certificate but with a&lt;br /&gt;
so called voms extension that contains a list of your VO group&lt;br /&gt;
memberships (and roles and attributes, which we don't use in&lt;br /&gt;
Swegrid/Swestore at the moment).&lt;br /&gt;
&lt;br /&gt;
'''Please note, if you only have one membership you can skip this section!'''&lt;br /&gt;
&lt;br /&gt;
The voms extension of the certificate is signed by the virtual&lt;br /&gt;
organization management server, or VOMS server. The same VOMS server&lt;br /&gt;
you used when applying for the swegrid.se VO membership in the first&lt;br /&gt;
place. To enable this signing process you need to add a few&lt;br /&gt;
configuration files to your system. First add this to the file&lt;br /&gt;
'''/etc/vomses''':&lt;br /&gt;
&lt;br /&gt;
   &amp;quot;swegrid.se&amp;quot; &amp;quot;voms.ndgf.org&amp;quot; &amp;quot;15009&amp;quot; &amp;quot;/O=Grid/O=NorduGrid/CN=host/voms.ndgf.org&amp;quot; &amp;quot;swegrid.se&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Next create the necessary directories and the file&lt;br /&gt;
'''/etc/grid-security/vomsdir/swegrid.se/voms.ndgf.org.lsc''' with the&lt;br /&gt;
following contents:&lt;br /&gt;
&lt;br /&gt;
   /O=Grid/O=NorduGrid/CN=host/voms.ndgf.org&lt;br /&gt;
   /O=Grid/O=NorduGrid/CN=NorduGrid Certification Authority&lt;br /&gt;
&lt;br /&gt;
== Creating a VOMS proxy ==&lt;br /&gt;
&lt;br /&gt;
VOMS proxies in ARC1 can be created using the '''arcproxy''' command&lt;br /&gt;
and the '''-S''' or '''--voms''' switches as shown in the following&lt;br /&gt;
example (if you are a member of the /swegrid.se/ops group. Adjust as&lt;br /&gt;
necessary):&lt;br /&gt;
&lt;br /&gt;
 $ arcproxy -S swegrid.se:/swegrid.se/ops&lt;br /&gt;
 Your identity: /O=Grid/O=NorduGrid/OU=lunarc.lu.se/CN=Kalle Kula&lt;br /&gt;
 Enter pass phrase for /home/kalle/.globus/userkey.pem:&lt;br /&gt;
 .....++++++&lt;br /&gt;
 ............++++++&lt;br /&gt;
 Contacting VOMS server (named swegrid.se): voms.ndgf.org on port: 15009&lt;br /&gt;
 Proxy generation succeeded&lt;br /&gt;
 Your proxy is valid until: 2011-03-10 23:33:06&lt;/div&gt;</summary>
		<author><name>Kent Engström (NSC)</name></author>
		
	</entry>
</feed>