Download of the GLOBALTRUST Root certificates issued under Microsoft operating systems and information on the validity check

20. April 2017

Certificates issued by GLOBALTRUST/A-CERT can be downloaded via the secured website https://www.globaltrust.eu/status.html – this requires correct setting of local firewalls – content filters must be set in such a way that the PKCS* * files must be accepted – the validity of the root certificates is checked via Microsoft http://www.download.windowsupdate.com

GLOBALTRUST/A-CERT certificates are issued in various formats, in particular pfx format (also PKCS#12 format, with the ending .p12), PKCS#7 format (with the ending .p7b) or base64 format (with the ending .crt ) available for download.

So that this download can be carried out, your own firewall or your own computer (including a local personal firewall) must be suitably configured. An https connection (SSL) to https://www.globaltrust.eu must be permitted and the above certificate formats must not be excluded from the download.

The Microsoft pfx format is often excluded as a “dangerous” format in the default settings of content filters in firewalls. If the formats are excluded, you get an empty (“white”) web page instead of the download file.

Installation of the GLOBALTRUST/A-CERT root certificates

Basically, the GLOBALTRUST/A-CERT root certificates are already in Microsoft’s repository for valid certificates. Depending on the operating system, it may still be necessary to first download it from Microsoft via a Windows update.

For this, your own computer (your own network) must allow a connection to the update server from Microsoft (http://www.download.windowsupdate.com). The connection is established via port 80. Furthermore, the operating system may require certain files to be transferred and updated on the local computer. They are http://www.download.windowsupdate.com/msdownload/update/v3/st…
and http://www.download.windowsupdate.com/msdownload/update/v3/st…

The process takes place fully automatically and in the background. If a firewall is set restrictively (content filter) or if updating the certificate administration on the local computer is prohibited, problems may arise when recognizing the root certificate. In these cases, the GLOBALTRUST root certificates can also be installed manually. You can find out how this works in our corresponding support article (https://www.globaltrust.eu/php/cms_monitor.php?q=PUB&s=08305wjt). If you have any further questions or problems, GLOBALTRUST/A-CERT Support will be happy to help.

You might be interested in that

Sign and encrypt emails using an Apple iPhone

Sign and encrypt emails using an Apple iPhone

User guide for signing and encrypting emails with the GLOBALTRUST CLIENT certificate on your Apple iPhoneAs of May 10, 2023 1 Basic 1.1 Goals of this document A step-by-step guide on how to add the certificate to your iPhone to then sign and/or encrypt emails. This guide was created for an Apple iPhone (iOS version:...

read more
Sign and encrypt with the UPC token in Outlook

Sign and encrypt with the UPC token in Outlook

User guide for signing and encrypting emails using the GLOBALTRUST UPC token V2.0 (issued from May 15, 2023) in Microsoft Outlook.As of May 9, 2023 1 Basics 1.1 Goals of this document A step-by-step guide on how to add the certificate in Microsoft Outlook to sign and/or encrypt emails.These instructions were created...

read more
On letters, stamping and (e-)seals

On letters, stamping and (e-)seals

On letters, stamping and (e-)seals Still stamping or already sealing? Fully automated and at the highest security level? If no, you should think about it: You can use the electronic seal as a digitization turbo and make it the central game changer of your organization. Did you know that there are administrative...

read more