User Certificate generation Internal Certificate Authority CA O2
Transmission activations codes User (PKI-SILNA-AUTENTIZACE) she´ll get activations codes are divided into parts (via e-mail: Reference Number + Part1 Authorization Code , via SMS: Part2 Authorization Code ). The certificate has to be generated before the delivered codes expire (.1 month after they are created). Example: (e-mail: Reference Number + Authorization Code Part1: 21250030, FCHG- SMS: Authorization Code Part2 : KVZC-UKVF Activations Codex (example): cn=Jan Pokus + serialNumber=AA004321, ou=AUTH USERS, o=O2, c=cz (pro zaměstnance O2 CZ a O2 SK) cn=Jan Pokus + serialNumber=x0504321, ou=EXT, o=O2, c=cz (pro externisty) Reference Number: 21250030 Authorization Code: FCHG-KVZC-UKVF (Authorization Code Part1+Part2 9/21/2018 8:10 PM
WebConnector The personal certificate for strong authentication has to be generated in WebConnector at the address in e-mail. Use : „Create Web Browser Certificate“ 9/21/2018 8:10 PM
Choice User fill out „Reference Number“ , „Authorization Code“ and choose „CSP type“ and „CSP“ (RSA full, Microsoft Enhanced Cryptographic Provider 1.0): 9/21/2018 8:10 PM
Dialogue – certification creation Follows the dialogue between user and MS CAPI. Choice : YES 9/21/2018 8:10 PM
Dialogue – Key generating and Protecting Select OK. (Security level set to Medium) 9/21/2018 8:10 PM
Dialogue – certification creation Storage certificate to PC Attention ! Dialogue is different from MS Windows 2000, MS XP, language, version etc Choice: YES 9/21/2018 8:10 PM
End of certificate and key generation After successfully key and certificate generation you can close the window with WebConnector. 9/21/2018 8:10 PM
Check certificate in MS store (CSP) You can find yourr new certificate in Internet Explorer: Tools, Internet Options, Content, Certificates See next slide for more information … Export Is possible export the certificate from MS store (CSP). Simply select Export. See next slide for more information You can export certificate only (format *.cer) or certificate with private key (format *.pfx / PKCS#11) . Format *.pfx use for archive your credentials or for install certificate with key to another PC (for example with Windows Vista)… 9/21/2018 8:10 PM
9/21/2018 8:10 PM
More information on the CA website intranet: http://webca. cz More information on the CA website intranet: http://webca.cz.o2/ Internet: http://ca.cz.o2.com/