Certificate Manager

This section describes how to use the Certificate Manager. If you are not already viewing the Certificate Manager window, follow these steps:

  1. Open the Edit menu and choose Preferences.
  2. Click Privacy and Security.
  3. Click Manage Certificates.

In this section:

My Certificates

Web Site Certificates

CA Certificates

Security Devices

 

My Certificates

The My Certificates tab in the Certificate Manager allows you to examine and work with the certificates you have on file that identify you, and to set related security passwords. To select a certificate, click its name. To select more than one certificate, hold down the Shift key and click the names of those you want to select.

To perform any of the actions listed here, select the certificates on which you want to act and follow these instructions:

The following actions don't require a certificate to be selected first:

Return to beginning of Certificate Manager section ]

 

Choose a Certificate Backup Password

A certificate backup password protects one or more certificates that you are backing up using the Backup or Backup All button in the My Certificates panel of the Certificate Manager. The browser asks you to set a certificate backup password when you back up certificates, and requests it when you attempt to restore certificates that have previously been backed up.

Important: When you click the Backup All button, the browser attempts to back up all of your certificates and associated private keys stored on the browser's software security device. The Backup All button does not back up any certificates that are stored on security devices other than the browser's own software security device. For example, Backup All will not back up any certificates in the list that are stored on a smart card inserted in a smart card reader attached to your computer. Certificates stored on devices other than the browser's software security device must be backed up by selecting their names and clicking the Backup button.

If someone obtains the file containing a certificate that you have backed up and successfully restores the certificate, that person can send messages or access web sites while pretending to be you. This can have negative consequences, for example, if you digitally sign important email messages or manage your bank or investment accounts over the Internet. Therefore, it's important to select a certificate backup password that is difficult to guess. It's also important to record the password in a safe place—and not anywhere that's easily accessible to someone else. If you forget this password, you can't restore the backup of your certificate.

Return to beginning of Certificate Manager section ]

 

Delete My Certificate

Before deleting any of your own certificates—even one that has expired—make sure that you won't need it again some day. For example, you can use your own expired certificate for reading old email messages that you may have encrypted with the corresponding private key.

Return to beginning of Certificate Manager section ]

 

Web Site Certificates

The Web Site Certificates tab in the Certificate Manager allows you to examine and work with the certificates you have on file that identify web sites.

To perform any of the actions listed here, select the certificate on which you want to act from the list of web site certificates, then follow these instructions:

 

Edit Web Site Certificate Settings

When you select a web site certificate and click Edit, you see a window titled Edit Certificate Settings. Here you specify whether you want to trust the selected certificate for identifying the web site and setting up an encrypted connection with it.

If you select "Do not trust the authenticity of this certificate" and click OK, Certificate Manager will no longer trust this certificate for the purposes of identifying this web site or setting up an encrypted connection. If you select this setting and then attempt to visit the web site, you will see one or more warning messages before you can access the site.

If you select "Trust the authenticity of this certificate" and click OK, Certificate Manager will henceforth trust this certificate for the purposes of identifying this web site or setting up an encrypted connection. If you select this setting and then attempt to visit the web site, your browser will access the site with few, if any, warnings.

In addition to specifying these settings for the certificate shown, you can specify trust settings for the certificate authority (CA) that issued the certificate—that is, you can choose to trust or not to trust different kinds of certificates issued by that certificate authority. For example, you can choose not to trust any web site certificates issued by that certificate authority.

To edit the certificate settings for the certificate authority that issued the certificate described in the Edit Certificate Settings window, click the Edit button.

Return to beginning of Certificate Manager section ]

 

Delete Web Site Certificate

Before deleting a web site certificate, make sure that you won't need it again for the purposes of identifying a web site and setting up an encrypted connection.

Return to beginning of Certificate Manager section ]

 

CA Certificates

The CA Certificates tab in the Certificate Manager allows you to examine and work with the certificates you have on file that identify certificate authorities (CAs).

To perform any of the actions listed here, select the certificate on which you want to act from the list of CA certificates and then follow the instructions:

 

Edit CA Certificate Settings

When you select a CA certificate and click Edit, you see a window titled Edit Security Certificate Settings. Here you specify the kinds of certificates you trust this CA to certify. If you deselect all the checkboxes, Certificate Manager will not trust any certificates issued by this CA.

If you select "This CA can identify web sites," Personal Security Manager will trust certificates issued by this CA for purposes of identifying web sites and encrypting web site connections. If you deselect this checkbox, Certificate Manager will not trust web site certificates issued by this CA.

If you select "This CA can identify mail users," Personal Security Manager will trust certificates issued by this CA for purposes of signing or encrypting email. If you deselect this checkbox, Certificate Manager will not trust email certificates issued by this CA.

If you select "This CA can identify software makers," Certificate Manager will trust certificates issued by this CA for the purpose of identifying software makers. If you deselect this checkbox, Certificate Manager will not trust such certificates issued by this CA.

Click OK to implement the settings you have selected.

Return to beginning of Certificate Manager section ]

 

Delete CA Certificate

Before deleting a CA certificate, make sure that you won't need it again to validate certificates issued by that CA. If you delete the only valid certificate you have for a CA, Certificate Manager will no longer trust any certificates issued by that CA.

Return to beginning of Certificate Manager section ]

 

Security Devices

[text to come]


5/9/2001

Copyright © 1994-2001 Netscape Communications Corporation.