4.2. Client Certification Installation¶
Client certificate is used when accesing to the Fugaku website. Please install to the browser which accesses to the Fugaku website.
This indicates how to install the required client certificate to access to the Fugaku website of Supercomputer Fugaku. This work is not required if installed the client certificate by refering to the Startup Guide.
Please prepare the followings before installing the client certificate.
Client certificate :”user account name .p12” file
Client certificate pathphrase
- Client certificate
Once the account issue is compleded, the client certificate is sent via e-mail to the e-mail address you entered when applying. Please save the attached “local account name.p12” file to the device (e.g. PC) which installs the client certificate. To “local account name.p12” file, the client private key, the client certificate (a public key) and the route certificate of the client certificate issuing authority.
- Client certificate pathphrase
The passphrase is sent in written form or PDF file separately from the client certificate. It will be required when installing the client certificate. Please store at the safe place.
This section describes the procedure for registering a client certificate on your PC.
Note
If you use a different browser than the specified browser, confirm the certificate management method of the browser yourself, and install the client certificate in the browser to be used.
4.2.1. Installing the certificate to Firefox (Windows)¶
This indicates how to install Firefox on Microsoft Windws. The difference may be seen depending on the version of Firefox. If the screen is different, please try with confirming the Firefox information.
Start Firefox and open [Option]. Click on [Privacy and Security]‘s [Display certificate].
Once the certificate manager is started, select [Your certificate] and click on [import…].
Client certificate: Select “local account name.p12” file and click on [Open].
Input the client passphrase to Passwordand click on [OK].
Confirm if the client certificate is registered.
Select [Certificate authority certificate] and from the list, select “RIKEN R-CCS” and click on Display.
Please confirm if the certificate’s Fingerprints is (SHA-1):
EEED846F FC733A73 328F4561 39BDB995 D5174BBC
.
Next, set the password to be entered when using the client certificate. Click on Security device….
Once device manager is started, select Software Security Device and click on Change password….
Set any password required when using the client certificate, click on OK.
After registering the password, close Device Manager. This is the end of setting the password when using the client certificate. The password set here is used when using the client certificate.
4.2.2. Installing the certificate on Firefox (Mac)¶
Start Firefox, click [Preferences…]from menu.
Click [View certificates…]in Privacy and security tab.
Once certificate manager started, select [Your certificate] then click [Import…].
Select the “local account name.p12” file saved on your computer, click [Open].
Input the passphrase of the obtained client certificate to Password area, click [OK].
Confirm that the client certificate has been registered, click [OK]and close the certificate manager. This completes the client certificate installation process.
Next, set the password to be entered when using the client certificate. Click Security device….
Once device manager starts, select Software Security Devicethen click Change password….
Set an arbitrary password required when using a client certificate, click OK.
Click OK.
Click OK and close devicce manager This completes the password setting procedure when using a client certificate.
4.2.3. Installing the certificate to Chrome (Windows)¶
This indicates how to install Chrome on Microsoft Windws. The difference may be seen depending on the version of Chrome. If the screen is different, please try with confirming the Chrome information.
Start Chrome and open [Setting]. Click on [Privacy and Security]‘s [Security].
Click on [Manage certificates].
Click on [Manage imported certificates from Windows].
Once certification manager is started, select [Personal] and click on [Import…].
Once certificate import wizard is opened, click on [Next].
Click on [Browse…].
Change the file type to [Personal Information Exchange(*.pfx,*.p12)].
Select “user account name.p12” file and click on [Open].
After setting a file name, click on [Next].
Input the client certificate passphrase to Password and check the import option [Strong the security of private key then click on [Next].
Check Automatically select certificate store based on certificate type and click on [Next].
Click on [Finish].
The “Import new secret exchange key” screen will be displayed continuously, click on [Set security level].
Check [High] and click on [Next].
Set the password and click on [Finish].
Click on [OK].
Click on [OK].
If a security warning is issued, confirm that the thumbprint is (SHA-1):
EEED846F FC733A73 328F4561 39BDB995 D5174BBC
and click on [Yes].
Installation of client certificate is all done.
4.2.4. Installing the certificate to Chrome (Mac)¶
This indicates how to install Chrome on Mac. At macOS, the client certificate is managed at “Key chain access”.
Client certificate: Double click “user account name.p12” file. The password input screen is show first. Enter the client certificate pass phrase and click on [OK].
Open “Key chain access” screen and double click on the server certificate (RIKEN R-CCS) that issused the client certificate.
Click on “Route certificate authority” - “Trust” and from the list of “When using this certificatie”, select “Always trust” and close the screen.
You will be prompted for your Mac administrator username and password to reflect the change in trust settings. Input these and click on [Update setting].
On the “Keychain Access” screen, hold down the Control key and click the client certificate (the local account name is shown in the name field), select [New identify preference].
To “Location or Email Address:”, input “https://www.fugaku.r-ccs.riken.jp/” and click on [Add].
With the same steps, register “https://api.fugaku.r-ccs.riken.jp/”.
Confirm if “https://www.fugaku.r-ccs.riken.jp/” and “https://api.fugaku.r-ccs.riken.jp/” ‘s “Identify preference” is registered to “Key chain access” and close the screen. Installation is all done.