Macedonian Academic Research Grid Initiative

Exporting certificate from Internet Explorer

Export Your Certificate from Internet Explorer

In order to use your certificate with any of the LCG applications you must export both your certificate and private key from your Internet Explorer browser and convert them to the neceassry format.

    1. Open your Internet Explorer browser and click on Tools and then on Options.

    2. Expand the Content tab and select Certificates.

    3. Select your User Certificate and click the Export button.

    4. Click Next on the first window.

    5. Select to export the private key.

    6. Select Personal Information Exchange and check the Enable strong protection

    7. Set a password to protect the key.

    8. Click on browse button to select where to export the key

    9. Select the path and filename and Click on Save button.

    10. Click on Finish button.

    11. And the keys will be exported.

Change your certificate format from P12 to PEM

Transfer the file you have just backed up to the UI(User Interface) your are using.You will need to change this to PEM format. If the edg-utils package is installed on your machine, simply executing /opt/edg/bin/pkcs12-extract will create appropriate certificate and key files and place them in the standard location.If this is not an option then you will have to do it mannually executing the following commands

> openssl pkcs12 -nocerts \
-in mycertificate.pfx \
-out ~user/.globus/userkey.pem
> openssl pkcs12 -clcerts -nokeys
-in mycertificate.pfx
-out ~user/.globus/usercert.pem

The first command gives you your private key; this file must be readable only by you (e.g. unix permission 0600). The second command gives your public certificate (e.g. unix permission 0644). The ~ user should be replaced by the path to your home area. The .globus subdirectory is standard place to put your certificates.