DoD Certification Authority Certificates 5, 6, 7, 9, and 10
1.0 Purpose
The purpose of this document is to inform CAC/PKI users, system administrators (SA), trainers, and engineers of the known problems that exist with the new Certification Authority (CA) 5, 6, 7, 9, and 10 certificates and the recommended solution.
2.0
Problem
The problems that occur when new Certification Authority CAC certificates, e.g., CA 5, 6, 7, 9, and/or 10, are registered on workstations or laptops that contain the old root certificates, e.g., CA 3 and/or 4: 1. A user is unable to use their new CA 5, 6, 7, 9, and/or 10 CAC certificates to digitally sign and/or encrypt an email message. The following or similar message appears:
2. A user is unable to use their new CA 5, 6, 7, 9, and/or 10 CAC certificates to authenticate to a DoD secure website. 3. A user is unable to verify registered CA 5, 6, 7, 9, and/or 10 CAC certificates and receives the following error messages:
1
4. A user is unable to publish new CA 5, 6, 7, 9, and/or 10 CAC certificates to the GAL and receives the following error message:
3.0
Solution
The recipient of the new CA 5, 6, 7, 9, and/or 10 certificates will need to download and install the new DoD CA Intermediate certificates on their computer. The instructions to download and install the new DoD CA Intermediate certificates are provided below. In order to authenticate to a DoD secure website, the web administrator or master will need to update the web server with the new DoD CA Intermediate certificates. The instructions to import the new DoD CA intermediate certificates on the web server are not provided. Consult your local web master for instructions. INSTRUCTIONS: Connect to the DoD Class3 PKI website: http://dodpki.c3pki.chamb.disa.mil. Click Download Root CA Certificates. Click Download Class 3 Root CA Certificate.
2
Click “Save” to begin saving the file.
Select a location for the file to save in, change the file extension to .p7b, and click “Save”.
3
Click “Close” to complete the download. Go to the location where the file is saved in. Right-click on the .p7b certificate file and select Install Certificate.
Click “Next” to begin the installation wizard.
4
Select “Automatically select …” and click “Next”.
Click “Finish” to complete and exit the installation wizard.
5
Click “OK” to acknowledge that the certificate was imported successfully.
6