installroot/index.htm

DOWNLOAD AND INSTALL THE ECPKI CA CERTIFICATE

The E-Commerce PKI CA is a sub-CA of the WISeKey Common Global Root. Before downloading and accepting the E-Commerce PKI CA certificates, you must install the WISeKey Common Global Root CA certificate as a trusted CA certificate in your browser. For further instructions please visit How to install the WISeKey Common Global Root Certificate.

Install and trust the E-Commerce PKI CA Certificate
Before installing the E-Commerce PKI CA certificate you must install the WISeKey Common Global Root certificate, please follow the "Instructions to install the root" if you have not already done so.

In order to use your E-Commerce PKI CA certificates you must install the E-Commerce PKI CA certificate into the browser that you will be using. These instructions guide you through this process.

N.B. An E-Commerce PKI CA certificate may only be used or relied upon under the terms and conditions provided in the E-Commerce PKI CA CPS and corresponding Certificate Policy. Please refer to the E-Commerce PKI CA Practices and Policies for more information.

Microsoft Internet Explorer version 5.5

These instructions are for Microsoft Internet Explorer version 5.5. Other versions of the browser may have different steps to install a Certificate.

To install the E-Commerce PKI CA certificate into Microsoft Internet Explorer

  1. If you are referring to a printed version of this page then start Microsoft Internet Explorer, and go to the location http://www.wisekey.com/install/E-Commercepki.htm.
  2. Click on the following text "Accept the E-Commerce PKI CA certificate", to begin the certificate download process.
  3. IE may ask you to Save this file to disk or Open this file from its current location. Check Open and click on OK. If clicking on Open results in a dialog which asks you to Select a program to open this file then click on Cancel and repeat from step 2, this time selecting Save this file to disk. Save the file to a location on your system, then use Windows Explorer to browse to the location of the file and open it, and continue at step 4.
  4. A new window will open listing the properties of the certificate. On the first tab verify:
    Issued to: E-Commerce PKI CA
    Issued by: WISeKey Common Global Root
  5. Select the second tab titled Details and then click on Subject in the top panel. In the bottom panel verify:
    CN = E-Commerce PKI CA
    OU = WISeKey Affiliate CA
    O = E-Commerce PKI
    C = CH
  6. Click on Thumbprint in the top panel. In the bottom panel verify that the thumbprint algorithm is sha1 and it value is:
    F51F 5BA6 08CB 3B4F 9DBD 590C 7793 8547 F62B 14F9
  7. If the above details are correct select the first tab titled General and click on Install Certificate
  8. A new window will open called the Certificate Manager Import Wizard. The first screen gives you general info about a certificate. Click Next >
  9. You will be requested to Select a Certificate Store. Select the option Automatically select the certificate store based on the type of certificate and click Next >
  10. The final screen will display the selected info. Verify:
    Certificate Store Selected by Wizard : (Automatically selected by the Wizard)
  11. If correct select Finish
  12. A dialog indicating that the Import was successful should appear. Click OK to finish.
  13. Select OK on the original window to close it.

To verify that the certificate is installed in Microsoft Internet Explorer

  1. From the menu across the top select Tools -> Internet Options
  2. In the Internet Options window that opens select the tab Content
    In the second panel click on Certificates.
  3. In the Certificate Manager window select the tab Intermediate Certification Authorities
  4. Scroll down the list and highlight E-Commerce PKI CA and click on View
  5. In the Certificate window select the tab Details and in the top panel select Thumbprint. In the bottom panel verify its value to be:
    F51F 5BA6 08CB 3B4F 9DBD 590C 7793 8547 F62B 14F9
  6. If the thumbprint matches then you have the correct certificate. Close all windows.

The E-Commerce PKI CA certificate is now installed in MS Internet Explorer 5.5

Go to the top of page >>

Netscape Browsers (Communicator 4.6)

Note that these instructions are for Netscape Communicator version 4.6. Other versions of the browser may have different steps to install a CA Certificate.

To install the E-Commerce PKI CA certificate into Netscape Communicator

  1. If you are referring to a printed version of this page then start Netscape Communicator, and go to the location http://www.wisekey.com/install/E-Commercepki.htm.
  2. Click on the following text "Accept the E-Commerce PKI CA certificate", to begin the certificate download process.
  3. Netscape will pop up a window called New Certificate Authority. Click Next>
  4. More info is provided about Certificate Authorities in general. Click Next>
  5. Information about the Certificate Authority is provided. Verify the following info:
    Certificate for: E-Commerce PKI
    Signed by : WISeKey SA
  6. Click on More Info...
  7. The complete information for the certificate is provided. Verify :
    This Certificate belongs to: This Certificate was issued by:
    E-Commerce PKI CA            WISeKey Common Global Root
    WISeKey Affiliate CA         Root Certification Authority
    E-Commerce PKI               WISeKey SA
    CH                           CH
    Serial Number: 3A:CC:36:71
    This Certificate is valid from Thu Apr 05, 2001 to Sun Apr 03, 2011
    Certificate Fingerprint:
    98:D8:14:DF:0D:C6:0B:B2:4F:E9:0F:B9:0E:63:E0:2C

    OK this window and if all is correct click Next>
  8. You will be requested to check off which services you want to allow this Certificate Authority to Certify. They are:
    Accept this Certificate Authority for Certifying network sites
    Accept this Certificate Authority for Certifying e-mail users
    Accept this Certificate Authority for Certifying software developers

    Check off all three and click Next>
  9. You will be requested if you want to be warned before you send data to sites certified by this CA. This is optional either way. Click Next>
  10. You will be requested for a name for the Certificate Authority. Enter "E-Commerce PKI CA"
  11. Click Finish

Verify the certificate authority certificate is correctly installed in Netscape Communicator:

  1. From the menu across the top select Communicator -> Tools -> Security Info
  2. The security window will open. In the left side panel select Signers under Certificates.
  3. In the right side panel scroll down the list and Highlight E-Commerce PKI CA then select the Edit button on the far right.
    In the window that opens verify:
    Certificate Fingerprint: 98:D8:14:DF:0D:C6:0B:B2:4F:E9:0F:B9:0E:63:E0:2C
  4. If the finger print matches then you have the correct Certificate. Close all windows by selecting OK

The certificate is now installed into Netscape Communicator.

Go to the top of page >>

E-Commerce PKI CA Certificate Details

Certificate:
Data:
Version: 3 (0x2)
Serial Number: 986461809 (0x3acc3671)
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=CH, O=WISeKey SA, OU=Root Certification Authority, CN=WISeKey Common Global Root
Validity
Not Before: Apr 5 09:10:09 2001 GMT
Not After : Apr 3 09:10:09 2011 GMT
Subject: C=CH, O=E-Commerce PKI, OU=WISeKey Affiliate CA, CN=E-Commerce PKI CA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public Key: (2048 bit)
Modulus (2048 bit):
00:ad:25:57:6b:60:f5:52:1c:74:cc:78:ff:0d:36:
91:e7:3a:da:98:df:d0:67:8b:0b:b7:d8:ba:bc:f2:
de:11:c7:e9:7d:28:89:e0:a2:52:79:44:c7:fb:ff:
e8:72:0a:31:b1:07:f3:4b:b5:54:60:5f:e2:e6:6d:
dc:73:af:78:82:f4:e6:65:f3:e1:65:a5:19:34:e7:
b1:12:66:4a:d2:93:79:cb:10:f6:e3:0f:a9:33:29:
e5:f1:eb:98:e6:f0:c2:82:89:01:cb:9f:4b:5e:6b:
ff:27:76:96:14:6c:1c:b2:ac:ff:4b:94:52:0f:fb:
58:1d:3c:26:82:56:ea:b0:91:43:4f:38:4a:71:c6:
c4:48:dc:9b:36:45:a5:6d:30:d2:22:bc:6f:a2:af:
e7:e3:46:1f:fa:12:43:d4:d1:fb:6c:97:d3:08:11:
a9:2c:86:4e:d7:d9:5d:57:46:d0:b8:3a:bd:e1:d1:
bb:fe:13:c6:9e:e3:e6:ca:95:6d:93:46:82:a8:b2:
5b:c4:43:7d:5d:14:1a:78:70:dc:1c:13:dd:02:ab:
a6:ab:81:5f:4c:53:e1:e2:02:ee:e8:e4:46:9e:d3:
62:a1:ff:b0:53:b8:f5:3a:4f:24:b3:39:10:0a:4c:
fd:25:21:88:61:05:a5:b1:6f:f1:88:26:04:ef:e1:
b4:55
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints:
CA:TRUE
X509v3 Key Usage: critical
Digital Signature, Non Repudiation, Key Agreement, Certificate Sign, CRL Sign
X509v3 Certificate Policies:
Policy: 2.16.756.5.14.1.4
User Notice:
Explicit Text: This Certification Authority certificate is m
anaged in accordance with the E-Commerce PKI Certification Practice Statement.
CPS: http://www.E-Commercepki.com/cps/

X509v3 Authority Key Identifier:
keyid:83:55:76:DD:17:DF:61:F1:99:40:6F:EA:D9:14:77:E2:34:A2:45:74

X509v3 Subject Key Identifier:
14:F2:DB:19:83:D4:F5:14:B0:36:AD:45:17:7A:55:FC:D7:C6:3C:CC
Signature Algorithm: sha1WithRSAEncryption
c2:be:e8:5e:c7:3e:55:e8:6c:82:b2:b3:9a:47:78:db:06:7a:
01:8e:8c:22:56:80:80:0a:9d:a3:b0:f2:e8:29:e8:98:14:7c:
70:be:04:2c:bd:50:ac:ec:9a:45:0e:cc:09:0c:a2:ff:e8:53:
a1:2c:16:fe:b5:92:80:6a:0d:22:06:2e:cb:a7:fe:5a:19:4f:
5c:eb:6d:72:fa:89:7a:36:e5:b5:c2:6e:e5:fe:8a:95:ad:37:
1a:1e:7e:d0:9b:2a:21:31:67:7c:0a:c7:2c:24:50:74:4c:c8:
9d:53:99:ba:c3:60:66:db:12:8f:fd:03:22:f3:eb:c2:ae:43:
97:05:88:74:a6:f0:9d:6b:f7:5c:02:a8:b9:70:ac:61:0e:c3:
51:19:b3:d5:63:b8:84:5b:19:98:5a:19:52:36:2c:c8:01:e2:
22:22:02:4b:4f:ac:8d:fc:76:3a:13:2a:db:56:08:f7:33:29:
79:0e:ef:fd:8a:52:cc:3b:44:87:dc:a2:27:0a:fd:86:ff:f0:
c3:14:32:6f:85:41:46:b8:cf:87:87:f6:27:ba:cb:85:8f:73:
10:c0:2f:a3:b7:0d:19:03:8a:7a:b5:c3:e4:21:12:a1:32:ad:
2c:c3:2f:9b:ad:3b:71:03:8a:94:2e:e3:22:bd:02:cd:74:bf:
3b:73:49:83
-----BEGIN CERTIFICATE-----
MIIEiDCCA3CgAwIBAgIEOsw2cTANBgkqhkiG9w0BAQUFADBuMQswCQYDVQQGEwJD
SDETMBEGA1UEChMKV0lTZUtleSBTQTElMCMGA1UECxMcUm9vdCBDZXJ0aWZpY2F0
aW9uIEF1dGhvcml0eTEjMCEGA1UEAxMaV0lTZUtleSBDb21tb24gR2xvYmFsIFJv
b3QwHhcNMDEwNDA1MDkxMDA5WhcNMTEwNDAzMDkxMDA5WjBhMQswCQYDVQQGEwJD
SDEXMBUGA1UEChMORS1Db21tZXJjZSBQS0kxHTAbBgNVBAsTFFdJU2VLZXkgQWZm
aWxpYXRlIENBMRowGAYDVQQDExFFLUNvbW1lcmNlIFBLSSBDQTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAK0lV2tg9VIcdMx4/w02kec62pjf0GeLC7fY
urzy3hHH6X0oieCiUnlEx/v/6HIKMbEH80u1VGBf4uZt3HOveIL05mXz4WWlGTTn
sRJmStKTecsQ9uMPqTMp5fHrmObwwoKJAcufS15r/yd2lhRsHLKs/0uUUg/7WB08
JoJW6rCRQ084SnHGxEjcmzZFpW0w0iK8b6Kv5+NGH/oSQ9TR+2yX0wgRqSyGTtfZ
XVdG0Lg6veHRu/4Txp7j5sqVbZNGgqiyW8RDfV0UGnhw3BwT3QKrpquBX0xT4eIC
7ujkRp7TYqH/sFO49TpPJLM5EApM/SUhiGEFpbFv8YgmBO/htFUCAwEAAaOCATkw
ggE1MAwGA1UdEwQFMAMBAf8wDgYDVR0PAQH/BAQDAgHOMIHUBgNVHSAEgcwwgckw
gcYGB2CFdAUOAQQwgbowgYkGCCsGAQUFBwICMH0ae1RoaXMgQ2VydGlmaWNhdGlv
biBBdXRob3JpdHkgY2VydGlmaWNhdGUgaXMgbWFuYWdlZCBpbiBhY2NvcmRhbmNl
IHdpdGggdGhlIEUtQ29tbWVyY2UgUEtJIENlcnRpZmljYXRpb24gUHJhY3RpY2Ug
U3RhdGVtZW50LjAsBggrBgEFBQcCARYgaHR0cDovL3d3dy5lY29tbWVyY2Vwa2ku
Y29tL2Nwcy8wHwYDVR0jBBgwFoAUg1V23RffYfGZQG/q2RR34jSiRXQwHQYDVR0O
BBYEFBTy2xmD1PUUsDatRRd6VfzXxjzMMA0GCSqGSIb3DQEBBQUAA4IBAQDCvuhe
xz5V6GyCsrOaR3jbBnoBjowiVoCACp2jsPLoKeiYFHxwvgQsvVCs7JpFDswJDKL/
6FOhLBb+tZKAag0iBi7Lp/5aGU9c621y+ol6NuW1wm7l/oqVrTcaHn7QmyohMWd8
CscsJFB0TMidU5m6w2Bm2xKP/QMi8+vCrkOXBYh0pvCda/dcAqi5cKxhDsNRGbPV
Y7iEWxmYWhlSNizIAeIiIgJLT6yN/HY6EyrbVgj3Myl5Du/9ilLMO0SH3KInCv2G
//DDFDJvhUFGuM+Hh/YnusuFj3MQwC+jtw0ZA4p6tcPkIRKhMq0swy+brTtxA4qU
LuMivQLNdL87c0mD
-----END CERTIFICATE-----

Go to the top of page >>

 

Resources
ECPKI Certificate
Revocation List
Agreements
Practices & Policies

Training

FAQ

Policies