Frequently Asked Questions
UBC Mathematics: MathNet FAQ [MathNet Certificates]



UBC Mathematics: MathNet FAQ [MathNet Certificates]




Question: Where can I get/verify certificates used by MathNet SSL enabled services?
Author: Joseph Tam
Date: Feb 12, 2014

Right here. All our SSL enabled services (e.g. https://sites, remote mail protocols, etc.) will have their security certificates published here. You can either download them and install it into your certificate repository, or use the fingerprint information here to check that the certificates received by your browser or mail reader is authentic.

Self-signed vs CA-signed certificates

Our certificates comes in 3 flavours: self-signed, local CA signed, and third-party CA signed.

  • Self-signed: a stand-alone certificate that asserts its own authenticity. This is used for test sites and non-essential services. These certificates usually require users to acknowledge or accept the certificate when initially connecting to the service. Users can also manually store the certificate from here -- users should check the fingreprints of the certificate here before accepting them. These certificates will be phased out by the next 2 types.
  • Local CA signed: a certificate signed by our local CA certificate (see UBC MathNet CA below). Importing this local CA certificate into your certificate authority cache will allow your reader to automatically validate all service certificate signed by this local CA certificate. If you elect not to import our local CA certificate, you can still accept service certificates individually.
  • Third-party CA signed: same as above except the CA is a third-party authority -- usually a commercial company that is paid for their signing service. An advantage of these certificates is that they are automatically accepted by browsers and mail readers.

Installation

Third-party CA signed certificates usually do not have to be manually added. Self-signed and local CA certificates can be downloaded in one of two formats: DER format is usually acceptable to most systems, but some will recognize the CRT format. To install:

  • Some systems (e.g. Windows, MacOSX) recognize certificates by their filename extensions: you may be able to download and double-click on the certificate file to install them. This will usually allow the native browser (Safari, Explorer) to start using them. Third party software may require you to install them using their own procedure, like ...
  • Firefox manages its certificates from their menu: Preferences (or Options) -> Advanced -> Encryption -> View Certificates.

Certificates

  • UBC MathNet CA
    • Download: [math-ca.der] [math-ca.crt]
    • Service: used to sign other certificates.
    • Type: Local CA certificate.
    • Expires: Dec 31 10:55:17 2037 GMT
    • Fingerprints:
      • (MD5) 9F:42:0F:8D:ED:77:BC:B3:06:A7:45:96:64:D3:F0:07
      • (SHA1) 6F:F6:DC:D0:4B:4D:6E:08:B4:BD:35:62:C8:5C:B2:C4:A0:6C:8D:06
  • www.math.ubc.ca
    • Download: [www.der] [www.crt]
    • Service: our department web site including MathNet User Services
    • Type: signed by UBC MathNet CA
    • Expires: Dec 5 00:38:08 2016 GMT
    • Fingerprints:
      • (MD5) 1B:B1:28:C1:1A:C2:6E:EF:F2:3B:C5:E3:AD:23:86:C4
      • (SHA1) A8:49:4A:F9:94:83:AB:53:1C:FF:4F:A9:41:CD:5A:AD:39:BE:AF:EE
  • secure.math.ubc.ca
    • Download: [secure.der] [secure.crt]
    • Service: our internal web site
    • Type: self-signed certificate
    • Expires: Oct 6 01:36:47 2031 GMT
    • Fingerprints:
      • (MD5) 8C:9D:B0:14:EE:C9:5B:FB:23:B9:76:F0:A1:6E:AB:BC
      • (SHA1) 9A:28:24:D8:63:6B:8D:84:BF:90:DB:77:24:96:C8:1B:59:71:E6:9C
  • webmail.math.ubc.ca
    pop.math.ubc.ca
    imap.math.ubc.ca
    mailhost.math.ubc.ca
    wiki.math.ubc.ca

    • Download: [math.ubc.ca.der] [math.ubc.ca.crt] (usually no need to pre-load)
    • Service: remote mail services and wiki
    • Type: third-party signed certificate
    • Expires: Sep 12 17:58:13 2018 GMT
    • Fingerprints:
      • (MD5) 38:5A:46:63:F1:A2:6D:41:F3:79:EF:5D:52:80:AE:39
      • (SHA1) 29:28:C3:38:FB:7D:BD:46:DD:5D:59:A7:0E:92:48:C4:3C:8A:65:E2
 
Top