Retrieving Your Software Certificate
These steps will help you complete the retrieval on your software certificate. You may also check out our instructional video, New Browser Based Certificate Retrieval.
Instructions
Open the email with the subject line “Your IdenTrust Certificate Has Been Approved!”
Look for the activation code listed in the email. Copy or write down the activation code.
Follow the link in the Email to www.IdenTrust.com/install.
"Welcome! It's Time to Get Your Certificate.”
Enter the activation code from the email, and the account password you created during your online application.
Click “Next”.
Download and open the retrieval application.
After you run the retrieval application you will see a picture of a lock. Drag and drop the picture of the key from the original window onto the picture of the lock in the retrieval application.
If you're having trouble moving the key onto the lock, you can also click on the "Copy key" button, then click on the text box next to "Retrieval key" in the retrieval application, and click "ctrl + v" on your keyboard to paste the key.
After the key is on the lock, the retrieval application will say "Welcome," then it will load while it verifies the retrieval key. The original window in your web browser may change a few times during this process - do not move from the screen or close anything.
Leave the drop-down menus on the default options, then click on the blue "Generate keys" button at the bottom of the window.
Click “Set Security Level”.
*“High” request permission with a password.
*“Medium “requests my permission when this item is being used.High” security is recommended.
High security you will be prompted to Enter and Confirm the “CryptoAPI Private Key” certificate password.
The "Creating a new RSA exchange key" window will pop back up, click on "OK" to continue.
The retrieval application will go back to a "Generate keys" window. This is to generate the keys for your encryption certificate. Click on the blue "Generate keys" button again at the bottom of the window.
"Choose a Security Level" window, set the security level, then click Next.
"Create a password" window, type and confirm the same password you set for the signing certificate.
Click "Finish."
The "Creating a new RSA exchange key" window will pop back up, click on "OK" to continue.
The retrieval application will finish generating the certificates.
During this step, you may see a "Security Warning" window pop up, with a message that starts with "You are about to install a certificate from a certification authority (CA) claiming to represent...." If that window pops up, click on "Yes" at the bottom to install the certificate.
At the end of the certificate installation, the retrieval application will bring up a window that says "Would you like to back up your certificates now?" Click "Yes."
After you click "Yes," it will ask which certificate you would like to back up. The signing certificate is the one which you will use to sign documents or log into websites. Click "Signing" to start backing up the signing certificate.
If you are an eNotary, be sure to make a backup of the signing certificate. The signing certificate backup is the file which you will upload to your online notary platform when you register.
The encryption certificate is mainly used for encrypting email messages. If you won't be using the certificate for email encryption, you can back up just the signing certificate. If you will be using the encryption certificate, please back up both certificates.
After you click "Signing," the Certificate Export Wizard will pop up. On the first page, when "Welcome to the Certificate Export Wizard" appears, click Next.
Export File Format." Leave the file format on the default, Personal Information Exchange, then click Next.
Check the boxes
“Include all certificates in the certification path if possible”
“Export all Extended Properties”
Click “Next”
On the Security page, check the box next to password, then type and confirm the same password you created for your certificates.
File to Export" page, you may name the file and where to save it. By default, the backup file will be saved to your desktop, with the current date and your name as the file name. The encryption certificate backup also saves onto your desktop with the date and your name, but with "_encr" at the end of the file name.
If you want to save the file somewhere other than your desktop and/or give it a different name, click on "Browse" to choose the folder to save it to and the name you'd like to give it. Then, click Next.
If you want to leave the default file location and name, simply click Next.
"Completing the Certificate Export Wizard" page, click Finish. A window will pop up asking for the password for your CryptoAPI Private Key. That is the password you set for your certificate. Type the password, then click “OK”.
A window will pop up saying that the export was successful. Click “OK”.
You will repeat these steps to back up your Encryption certificate.
The retrieval application will say "Your signing and encryption certificates are both installed."
"See My Certificate." Will allow you to view the information on your certificate.
"Test My Certificate" will help you to test the certificate in a web browser. If you choose this option, a window will pop up asking you which web browser you would like to use. We recommend using Google Chrome or Microsoft Edge.
Close any windows and tabs you have open in your web browser before selecting it for the test. The test works best if there are no windows open.
Click "Done" to close the retrieval application.
Once you close the retrieval application, your web browser will ask you to click Next to verify the information on your certificate. Make sure that the certificate information is correct, then click Next.
You will be given instructions to test your certificate. If you've already done the test in the retrieval application, you can skip this step and close the window. Click Next, and a window should pop up asking you to select a certificate.
Click on your certificate issued by IGC CA 1.
Click “OK”.
A window will pop up from Windows Security that says "Credentials Required" and ask for your CryptoAPI Private Key password.
Enter the password you set for your certificate.
Click "Allow."
Congratulations, Certificate Retrieval Completed.