Print these instructions: We strongly suggest printing this page before enrolling for your ECA Certificate.
1. Hardware Ordering Instructions
- Send an email to ECA Sales (eca_sales@symantec.com) to order a FIPS 140-2 compliant smart card or USB token and pre-pay for your Medium Token Assurance certificate. In this email, please attach the ECA Administrator Kit Order Form and either your company's purchase order or a completed credit card authorization form for payment.
- If you order a smart card, we will send you a package with a smart card, a smart card reader, a CD-ROM of PKI Client software, and a sales order number to claim your Medium Token Assurance certificate.
- If you order a USB token, we will send you a package with a USB token, a CD-ROM of PKI Client software, and a sales order number to claim your Medium Token Assurance certificate. Note: Please download latest PKI Client software from AR1752. Windows 7 users must download this software.
2. Hardware Installation Instructions
Do not proceed with these steps until you have received your smart card or USB token package.
-
Install the PKI Client software on your Windows XP, Vista, or 7 computer.
Note: Mac OS, Apple Safari, Google Chrome, and Internet Explorer 9 are not supported at this time.
Note: If you have ordered a smart card and smart card reader, Windows Plug And Play does not always install the smart card reader driver. In this case, you need to download and install the smart card reader driver from the Athena Smartcard Solutions web site (http://www.athena-scs.com/downloads.asp):
- 32-Bit Version: http://www.athena-scs.com/docs/reader-drivers/setup4004x86-en.exe
- 64-Bit Version: http://www.athena-scs.com/docs/reader-drivers/setup4004x64-en.exe
- Plug your smart card or USB token in your computer.
- Change the default password on your smart card or USB token. Enter default password 1234567890 in Current Password field.
- Enter a new password in the New Password field - it must be at least 8 characters and include at least one letter, one number, and one special character. You must create a new eToken password. Once this password is successfully created, you can move on to the certificate enrollment instructions.
3. Certificate Enrollment Instructions
Do not proceed with these steps until you have received your smart card or USB token package and installed the PKI Client software. You must have your smart card or USB token plugged into your computer at the time of enrollment.
- Plug your smart card or USB token into your computer.
- Go to the ECA Certificate Enrollment form. Note: Internet Explorer 9 web browser is not supported at this time. If you have Internet Explorer 9 web browser, you will need to downgrade to Internet Explorer 8.
- In the Select Enrollment Method section, select the Subscriber Enrollment using Trusted Agent radio button.
- In the ECA Certificate Subscriber Information section, complete all mandatory fields marked with a red asterisk. Note: Enter your full legal name exactly as specified on your passport or birth certificate in the First Name and Last Name fields. Note: If you have a suffix after your last name (e.g. Smith, Jr.), enter both your last name and suffix in the Last Name field. Note: Only enter your company's legal business name in the Organization field.
- In the Select Enrollment Type section, select Token Enrollment.
- In the Enter Payment Type section, enter your sales order number received via email for the ECA certificate in the Sales Order Number field – DO NOT enter the sales order number associated with the token itself. Note: You must add an “11” to the beginning of your 8 digit sales order when enrolling.
- In the Enter a Challenge Password section, enter a password in both the Challenge Password and Re-enter Challenge Password fields.
- In the Subscriber Agreement section, read the terms and conditions of the Subscriber Agreement.
- Click the Accept and Purchase button to submit your certificate request. Then, follow the prompts to install the CA Root Certificate.
4. Identify Proofing Instructions
The Symantec ECA Authentication team cannot approve your certificate request until you submit your ECA Subscriber Enrollment form.
- Download and print ECA Subscriber Enrollment form, but do not sign this form yet. You must sign the ECA Subscriber Enrollment form in the presence of a Notary.
- Fill out Section 1 of the ECA Subscriber Enrollment form.
- Take the ECA Subscriber Enrollment to a Notary Public. You must present your valid Passport or Birth Certificate, valid Driver's License, and your Work ID Badge to the Notary. Use this checklist to help collect the necessary documents the Notary will require. Note: If you do not have a Work ID badge, you must download and print the Subscriber’s Organizational Contact form. Then, a separate full-time employee of your company must fill out and sign the Subscriber’ Organizational Contact form. The purpose of this form is to verify the ECA subscriber's employment within the same organization.
- Sign the ECA Subscriber Enrollment form in the presence of a valid Notary. The Notary must list and confirm viewing of your ID documentation, stamp, and sign Section 2 of the ECA Subscriber Enrollment form.
-
Mail the signed ECA Subscriber Enrollment form to:
Symantec Corporation
Attn: Symantec ECA Authentication Support
350 Ellis Street
Mountain View, California 94043 - Once the ECA Subscriber Enrollment form has been received by the Symantec ECA Authentication team, you will receive an email confirmation within 7 to 10 business days.
5. Certificate Installation Instructions
You must have your smart card or USB token plugged into your computer to pick up your certificates. The Root Certificates must also be installed before proceeding.
- After reviewing your ECA Subscriber form, the Symantec ECA Authentication Support team will approve your certificate request. You will then receive an email stating your ECA certificate has been issued. This email contains an approval PIN required to pick-up your ECA Identity certificate.
- Plug your smart card or USB token into your computer. Click the link in the email to access the ECA Certificate Installation web page, enter the PIN, and click the Continue button to download and install the ECA Identity certificate on your smart card or USB token.
- After installing the ECA Identity certificate, you will immediately download and install the ECA Encryption certificate on your smart card or USB token. Note: Windows may prompt you to select a certificate to pick up the ECA Encryption certificate. If you get a pop-up window, select your ECA Identity Certificate and click the OK button.
6. Install CA Certificates Instructions
You must install both Symantec ECA CA and DoD Root CA certificates to create a chain of trust. Web browsers (e.g. Internet Explorer) and email software (e.g. Microsoft Outlook) validate your ECA Identity and Encryption Certificates by verifying this chain of trust.
Step 1: Download & Install all Symantec ECA Root Certificates
Internet Explorer (Windows Vista & 7)- Open the Internet Explorer 7 or 8 web browser
- Download the first certificate: https://eca2048.verisign.com/CA/ECARootCA2048.cer
- Click Save button which launches Save As window
- Select Desktop location, click Save button, and click Close button
- Click Windows Start button
- In the Search Programs and Files field, enter mmc, and click Enter button which opens a Console1 window with a Console Root sub-window. NOTE: You may need to click Yes to confirm that you wish to allow changes to your computer
- Click File > Add/Remove Snap-in… option
- From the Availablesnap-ins list, select Certificates option, and click Add button
- Select Computer account radio button and click Next button
- Keep Local computer radio button selection, click Finish button, and click OK button NOTE: You may not be prompted to select an account. If not, just click OK.
- From the left pane under Console Root in blue, expand Certificates (Local computer or current user) option
- Expand Trusted Root Certification Authorities option
- Select Certificates folders and right-click your mouse
- Select All Tasks > Import… which will launch a Certificate Import wizard.
- Click Next button
- Click Browse button and go to your Desktop location
- Select ECARootCA2048.cer file and click Open button
- Click Next button, click Next button again, click Finish button, and finally click OK button
- Close the Console1 window Note: Click No button unless you wish to save the setup
- Download the second certificate: https://knowledge.verisign.com/library/VERISIGN/ALL_OTHER/eca.tech.files/VeriSignECA2048-G3.cer
- Click Save button which launches Save As window
- Select Desktop location, click Save button, and click Close button
- Go to your Desktop and double-click VerisignECA2048-G3.cer file which launches a Certificate window
- Click Install Certificate.. button which launches a Certificate Import wizard
- Click Next button and select Place all certificates in the following store radio button
- Click Browse button, select Intermediate Certification Authorities option, and click OK button
- Click Next button, click Finish button, and click OK button
- Close Certificate window by clicking OK button
Internet Explorer (Windows XP)
- Open the Internet Explorer 6 or 7 web browser
- Download the first certificate: https://eca2048.verisign.com/CA/ECARootCA2048.cer
- Click Save button which launches Save As window
- Select Desktop location, click Save button, and click Close button
- Go to your Desktop and double-click ECARootCA2048.cer file which launches a Certificate window
- Click Install Certificate.. button which launches a Certificate Import wizard
- Click Next button and select Place all certificates in the following store radio button
- Click Browse button, select Intermediate Certification Authorities option, and click OK button
- Click Next button, click Finish button, and click OK button
- Close Certificate window by clicking OK button
- Download the second certificate: https://knowledge.verisign.com/library/VERISIGN/ALL_OTHER/eca.tech.files/VeriSignECA2048-G3.cer
- Click Save button which launches Save As window
- Select Desktop location, click Save button, and click Close button
- Go to your Desktop and double-click VerisignECA2048-G3.cer file which launches a Certificate window
- Click Install Certificate.. button which launches a Certificate Import wizard
- Click Next button and select Place all certificates in the following store radio button
- Click Browse button, select Intermediate Certification Authorities option, and click OK button
- Click Next button, click Finish button, and click OK button
- Close Certificate window by clicking OK button
Firefox
- Open the Firefox web browser
- Download the first certificate: https://eca2048.verisign.com/CA/ECARootCA2048.cer
- Keep Save File option and click OK button
- Download the second certificate: https://knowledge.verisign.com/library/VERISIGN/ALL_OTHER/eca.tech.files/VeriSignECA2048-G3.cer
- Keep Save File option and click OK button
- In the main toolbar, click Tools > Options which launches Options window
- Click Encryption tab and click View Certificates… button which launches Certificate Manager window
- Click Authorities tab and click Import… button which a Select File window
- Select ECARootCA2048.cer file and click Open button which launches Downloading Certificate window
- Select all three checkboxes and click OK button
- Click Import… button again which a Select File window
- Select VeriSignECA2048-G3.cer file and click Open button which launches Downloading Certificate window
- Select all three checkboxes and click OK button
- Close Certificate Manager window by clicking OK button
- Close Options windows by clicking OK button
Step 2: Download & Install DoD Root Certificates
Internet Explorer (Windows XP, Vista, & 7)- Open the Internet Explorer 6, 7, or 8 web browser
- Go to DoD Class 3 PKI web site: http://dodpki.c3pki.chamb.disa.mil/rootca.html
- Click on Download Root CA 2 Certificate (filename: rel3_dodroot_2048.p7b)
- Click Save button which launches Save As window
- Select Desktop location, click Save button, and click Close button
- Click on Download External Certification Authority (ECA) Root CA (filename: dodeca.p7b)
- Click Save button which launches Save As window
- Select Desktop location, click Save button, and click Close button
- Click on Download External Certification Authority (ECA) Root CA 2 Certificate (filename: dodeca2.p7b)
- Click Save button which launches Save As window
- Select Desktop location, click Save button, and click Close button
- Exit Internet Explorer web browser
- Go to your Desktop and double-click rel3_dodroot_2048.p7b file which launches a Certificate window
- Click Install Certificate.. button which launches a Certificate Import wizard
- Click Next button and select Place all certificates in the following store radio button
- Click Browse button, select Trusted Root Certification Authority option, and click OK button
- Click Next button, click Finish button, and click OK button
- Close Certificate window by clicking OK button
- Go to your Desktop and double-click dodeca.p7b file which launches a Certificate window
- Click Install Certificate.. button which launches a Certificate Import wizard
- Click Next button and select Place all certificates in the following store radio button
- Click Browse button, select Trusted Root Certification Authority option, and click OK button
- Click Next button, click Finish button, and click OK button
- Close Certificate window by clicking OK button
- Go to your Desktop and double-click dodeca2.p7b file which launches a Certificate window
- Click Install Certificate.. button which launches a Certificate Import wizard
- Click Next button and select Place all certificates in the following store radio button
- Click Browse button, select Trusted Root Certification Authority option, and click OK button
- Click Next button, click Finish button, and click OK button
- Close Certificate window by clicking OK button
Firefox
- Open the Firefox web browser
- Go to DoD Class 3 PKI web site: http://dodpki.c3pki.chamb.disa.mil/rootca.html
- Click on Download Root CA 2 Certificate http://dodpki.c3pki.chamb.disa.mil/rel3_dodroot_2048.cac (filename: rel3_dodroot_2048.cac)
- Select all three checkboxes and click OK button
- Click OK button twice to ignore warning messages
- Click on Download External Certification Authority (ECA) Root CA http://dodpki.c3pki.chamb.disa.mil/dodeca.cac (filename: filename: dodeca.cac)
- Select all three checkboxes and click OK button
- Click OK button twice to ignore warning messages
- Click Download External Certification Authority (ECA) Root CA 2 Certificate http://dodpki.c3pki.chamb.disa.mil/dodeca2.cac (filename: filename: dodeca2.cac)
- Select all three checkboxes and click OK button
- Click OK button twice to ignore warning messages
- Exit Firefox web browser
