How to Request an S/MIME Client Certificate
This guide outlines the process for requesting S/MIME client certificates for your primary @berkeley.edu account. S/MIME certificates are used to sign and encrypt email communications.
Note: S/MIME certificates are issued with the subject CN=University of California, Berkeley. This is standard behavior; your specific email address is included as a "Subject Alternative Name" (e.g., rfc822name=user@berkeley.edu).
Requirement: You must be familiar with your specific email client (Outlook, Apple Mail, etc.), as CalNet does not provide support for third-party client configuration.
Enrollment Process
- Open a Private or Incognito browser window.
- Navigate to the Sectigo Certificate Manager Enrollment Page.
- Select the CalNet login option and log in with your credentials.
- Locate Enrollment:
- If you have never had a certificate, you will be prompted to enroll immediately.
- If you have existing certificates, click Enroll Certificate in the top right corner.
- When prompted for an Access Code, enter:
oski - Set Certificate Term: Choose the desired duration (the dropdown defaults to the shortest term).
- Select Key Type: We recommend leaving this at the default setting.
- Click Submit.
- Choose Key Protection Algorithm:
The default Secure AES256-SHA256 may not work with all clients. If you use a Mac or iOS device, select
TripleDES-SHA1. - Set Certificate Password: Enter a password for the certificate's private key twice.
Important: You must remember this password to import the certificate into your email app later. - Click Download to save the certificate file to your computer.
Support
If you have questions about the enrollment process, please contact calnet-admin@berkeley.edu.