GlobalSign Security Solutions Secure SSL Certificates  |  Home  |  Contact Us    
Search Technical Support & FAQs  
 
Certificates SSL menu divider Enterprise Solutions SSL menu divider Partners SSL menu divider Customer Support SSL menu divider About GlobalSign

 

 


Customer Support > SSL Certificates > Root Certificate

GlobalSign Trust Hierarchy for ExtendedSSL

IMPORTANT NOTE: For your ExtendedSSL certificate to work on all browsers transparently you must download and install the Intermediate Root CA (named "Extended Validation CA") and the Cross Certificate using the instructions corresponding to your web server. If you have not already copied the Extended Validation CA Certificateand the Cross Certificate to your web server, click here to do so now.

Root Certificate Install Instructions

For Install instructions of the root certificates for your ServerSign SSL Certifcate, please select your web server from the following:

IIS 4, IIS 5 & IIS 6
Apache
Stronghold
Netscape iPlanet
IBM Websphere
Lotus Domino

Microsoft IIS 4.0, IIS 5.0 & IIS 6.0 Intermediate Root Certificate Install

Step 1: GlobalSign Extended Validation CA certificate:

Click on "Install Certificate"

1

Click on "Next"

4

Select "Place all certificates in the following store" and Click on "Browse"

A new window will pop up

7

Select "Show physical stores"

1

Select "Intermediate Certification Authorities" and then "Local Computer"

Click "OK", this window will close and you will see the following screen

3

Click on "Next"

6

Click on "Finish"

7

 

Step 2: GlobalSign Cross Certificate

Complete the same process as Step 1 for the Cross Certificate.

 

Notes for Windows NT Users

ServicePack 3: install the GlobalSign root(s) in your Internet Explorer, and use the IISCA batch file to transfer all root certificates from your Internet Explorer to the IIS (see Microsoft KnowledgeBase Q216339).

ServicePack 4: install the GlobalSign root certificate(s)manually in a specicfic root store: "Show physical stores/Trusted Root Certification Authorities/Local Computer" (see Microsoft KnowledgeBase Q194788).

ServicePack 5 and 6: same as SP4.

 

 

Apache Root Certificate Install

Right click and Save As the following file: Apache EV SSL Bundle File

- Rename the apache_ev_bundle.txt file to apache_ev_bundle.crt

- Save the file to apache/conf/ssl/ - when installed the directory will look like: apache/conf/ssl/apache_ev_bundle.crt

- STOP your apache server.

- Locate the httpd.conf file and open it in a text editor

- Locate the SSLCaCertificateFile directive in the httpd.conf file and remove the leading # from the line.

- Modify the path at the end of the line to reference the location where you saved the apache_ev_bundle.crt file.

For example: SSLCaCertificateFile /usr/local/ apache/conf/ssl/apache_ev_bundle.crt

- Restart Apache

 

Stronghold Root Certificate Install

Stronghold needs to have access to the chain of certificates of the CA (certificate authority) that signed the certificate. These certificates are placed by GlobalSignas defualt in the in a file that contains several PEM encoded certificates :

./stronghold/ssl/CA/client-rootcerts.pem

If the file client-rootcerts.pem does not contain the GlobalSign certificates, then please download them from the following: Here

 

Netscape iPlanet Root Certificate Install

Installing the GlobalSign Root CA

  1. Select SECURITY
  2. In INSTALL CERTIFICATE: select TRUSTED CERTIFICATION AUTHORITIES
  3. Select CRYPTOGRAPHIC MODULE: internal (software)
  4. In "Message is in this file: enter the Path to the local file in PEM format which contains the Extended Validation CA certificate.
  5. In CERTIFICATE NAME: Enter a friendly name for this certificate: for exampleExtended Validation CA certificate

    1

  6. Repeat this for the Cross Certificate

 

IBM WebSphere Root Certificate Install

Before you can add your certificate into the keystore, you must first include the GlobalSign's Certificates chain for the Product you chose. For instance, if you choose for Secure Server, you have to install public certificates. They can be found Here.

You can add this certificates chain from the Signer Certificates screen as shown below:

1

Click on the Add button. A dialog box asking will appear where you have to enter the Data type (Base64-encoded ASCII data), the Certificate file name (the certificate file you received from GlobalSign) and its location. Once all of these information are entered, just click on OK

Lotus Domino Root Certificate Install

You must install the GlobalSign Root certificates into the Server Certfiicate Admin application. Download the .PEM files - can be found here.

For each of the root certfiicates, copy the content in the clipboard - i.e:

-----BEGIN CERTIFICATE-----
CERT
-----END CERTIFICATE-----

You have then to paste it in the Server Certificate Admin application. You may check if they are considered as Trusted Root (they must be) in the View & Edit Key Rings main entry (left on the main screen). If they are not, double click on the certificate that you want to manage and enable this option.

 
   
  SSL Certificate Supported Browsers
GlobalSign Inc (a member of GMO Internet Inc group TSE:9449) offers online security services and has been operating as a
trusted Root Certification Authority
for over 10 years. GlobalSign Certificates are trusted by all popular Browsers,
Operating Systems, Devices and Applications and include SSL, SSL Certificates, Extended SSL Certificates, Code Signing,
Personal Digital IDs
, Enterprise Digital IDs, internal PKI & Microsoft CA root signing.