Obtaining a Comodo Certificate

From Mumble Wiki
Jump to: navigation, search

This article describes the process of obtaining a User Certificate. The certificate will represent the trust in that the user owns the email address they specified.

Servers identify themselves with a different kind of certificate. If you are looking for server certificates, this guide is not for you.

Obtaining a Class 1 certificate from Comodo (Instantssl) using Internet Explorer

Icons oxygen 48x48 actions view-pim-notes.png
Getting the certificate with Chrome/Safari (webkit based) might seem to work at first, but you end up with an incomplete certificate bundle! Consider using an alternative browser.

Comodo supports IE, Firefox, Opera and Flock, for obtaining the certificate. All images are click-able if more details are required.

  1. Go to http://www.instantssl.com/ssl-certificate-products/free-email-certificate.html
  2. Click the Get it free now button next to 'Free Secure Email Certificate'
    Instantssl ie 1.jpg
  3. Fill in your details.
    Instantssl ie 2.jpg
  4. Press agree & continue.
    Instantssl ie 3.jpg
  5. Wait for the confirmation mail to arrive in your mailbox.
  6. Follow the instructions in the mail (or go to this link), it should look something like this:
    Instantssl ie email.jpg
  7. Enter your email address and the security code given in the mail
    Instantssl ie 4.jpg
  8. Certificate should be collected and installed in your browser
    Instantssl ie 5.jpg
  9. Export the certificate to a file
    Export the certificate (Internet Explorer 8)
    Select from "Tools" -> "Internet Options" -> "Content" -> "Certificates" -> "Personal" and locate your certificate from the list. If this is your first certificate it will be listed under the name "UTN-USERFirst-Client Authentication and Email". Click on "Export" -> "Next" -> "Yes, export the private key" -> "Next" -> "Next". Choose a password for your file and click "Next", choose a name for this backup file and save it at a known location.
    Export the certificate (Firefox 3.5)
    Select "Preferences" -> "Advanced" -> "Encryption" -> "View Certificates", choose the "Your Certificates" tab and locate your certificate from the list. The certificate will be listed with "UTN-USERFirst-Client Authentication and Email" as its name. Select the certificate and click on "Backup", choose a name for this backup file, provide a password and save it at a known location.
    Export the certificate (Opera 10.10)
    Select "Tools" -> "Preferences" -> "Advanced" (tab) -> "Security" -> "Manage Certificate" (button) -> "Personal" (tab) choose your certificate and click "Export" (button).

Importing a certificate from file into Mumble

  1. Select Configure -> Certificate Wizard
    Import mumble 1.jpg
  2. Select import certificate. Click Next
  3. Locate the certificate file. It should end in .p12 or .pfx depending on which browser exported the certificate.
  4. Enter the password for the certificate
  5. The certificate details should now be filled in. Make sure that it is the correct certificate. Click next.
    Import mumble 2.jpg
  6. Confirm that you want to change your certificate by pressing next.
    Import mumble 3.jpg
  7. Done! Press finish to close the guide.
    Import mumble 4.jpg

I cannot connect after installing my certificate

If you cannot connect and "SSL Error: The root CA certificate is not trusted for this purpose" is logged to the server log, this is usually due to having an incomplete certificate bundle.

Please export the certificate using Firefox and try again. Chrome and Safari are known to create incomplete certificate bundles.