Apply for server certificates (HARICA)

The content on this page was translated automatically.

Registration in Harica CertManager

To create a server certificate via Harica, first log in to the browser at
https://cm.harica.gr/login.

On the login page, select "Academic Login".

(opens enlarged image)

Select the University of Kassel from the list.

If it is not displayed immediately, you can search for it using the search bar.

(opens enlarged image)

You will now be redirected to log in with your UniAccount and the corresponding password.

After this step, you are logged in and can apply for a server certificate on the website.

(opens enlarged image)

Apply for a server certificate

As soon as you have completed the registration, you can select the "Server" button on the left-hand side of the dashboard under the "Certificate Request" tab.

(opens enlarged image)

In the window that now opens, enter the information about the desired server certificate in the next steps.

The "Friendly Name" is optional (here, for example, "Webserver Universitaet Kassel").

Under "Add domains", enter the name of the server (in this case "webserver.uni-kassel.de"). If there are alternative names for the server, you can add these by clicking on "+ Add more domains" (here "meinwebserver.uni-kassel.de").

Then click on "Next".

(opens enlarged image)

In the next step, please select the option "For enterprises or organizations (OV)" under "type of your certificate" (pay attention to the correct addition in brackets!) and click on "Next".

(opens enlarged image)

Now confirm your selection with another click on "Next".

(opens enlarged image)

You can also confirm the information about the organization by clicking on "Next", as this is provided by the registration.

(opens enlarged image)

Under the overview for the application, check the box for approval before clicking on "Next".

(opens enlarged image)

Your next step depends on whether you want to have a CSR (Certificate Signing Request) generated automatically or whether you want to upload a CSR generated via OpenSSL yourself.

Generate CSR automatically

If you want to generate a CSR automatically, first click on "Auto-generate CSR".

(opens enlarged image)

You will now be asked for several details:

  • The encryption algorithm and the corresponding key size
  • Set and repeat a password
  • Check both boxes

Then you can click on "Generate Private Key, CSR, and submit order" to complete the process.

(opens enlarged image)

To download your private key, please click on "Download".

The private key will now be saved in the download folder of your PC as privateKey.pem.

(opens enlarged image)

If the download of the private key has been completed without errors, you can check the box and confirm the download and return to the overview by clicking on "Go back to dashboard".

(opens enlarged image)

Back in the dashboard, you will now see the certificate request, which must now be approved by one of the authorized persons in the ITS.

(opens enlarged image)

Upload CSR manually

If you want to upload a self-generated CSR, first click on "Submit CSR manually".

(opens enlarged image)

Now copy the content of your CSR and paste it into the dialog box that opens.

Then check the box and complete the process with "Submit request".

(opens enlarged image)

Download certificate

After the certificate has been approved, you will receive an email from Harica.

Click on the link to the "Dashboard" contained in the email and log in to the website again.

(opens enlarged image)

You will now see your approved certificate in the dashboard.

Click on the download icon to download the certificate.

(opens enlarged image)

The certificate can be downloaded in various file formats.

We recommend choosing "PEM-bundle". This contains the actual certificate and the certificate chain.

(opens enlarged image)

When downloading the certificate, the browser may report that the page is not responding.
Click away the error using the "Wait" button until the download is complete.

(opens enlarged image)

If you need the certificate file as a .p12 file, you can convert the file using a tool from Harica at
https://www.harica.gr/en/Tools/PemToP12.

You will need the .pem file and the PEM-bundle file (both available via the download) as well as the privateKey.pem file.