RIT
Systems and Technologies

RIT Certificate Authority

The RIT Certificate Authority, created and maintained by ITS, provides a chain of trust for electronic communications. It forms the basis of a public key infrastructure for services (particularly those protected with SSL/TLS encryption) of value to the campus.

We recommend that all RIT-owned computers import and trust the RIT Certificate Authority. Importing the certificate for the RIT Certificate Authority (CA) allows your computer to accurately identify other certificates that are chained from it. Trusting the imported CA certificate avoids presenting dialogs to you when it encounters a service that has been signed by it.

The RIT CA certificates may be imported and trusted on your personal computer, as well.

Install the certificates and set up trust

We provide standalone installer-based tools for you to import and trust the RIT CA. These are the easiest methods of importing and trusting the relevant certificates, so we recommend you use these installers if you have administrator-level privileges on your computer.

The installers import multiple RIT CA certificates and set up trust for the RIT CA itself in the operating system’s default certificate store:

  • On Windows, this store is used by the operating system and the Microsoft Internet Explorer Web browser.
  • On Mac OS X, the store is used by most applications, including the Apple Safari Web browser. The certificate store is available through the Keychain Access utility.

The installers do not currently affect third-party applications that do not make use of the operating system’s certificate store. The most common example is the Mozilla Firefox browser.

For this operating system and hardware … Download and install this installer …
Microsoft Windows XP, Vista, and 7
(32 and 64 bit editions)
RIT Certificate Authority installer for Windows
Executable MSI installer

SHA1: fce667aa63d90ce0ba8ea50221ff0b5d28474d12
MD5: 80916d4443c233c7d415fc35d302886a
Apple Mac OS X 10.5 or 10.6
(PowerPC or Intel)
RIT Certificate Authority installer for Mac OS X
Disk image with package installer

SHA1: d71cf9e67dce6f3e74596950a3804e9717959b1f
MD5: c31b1e3b1d1c26968eeca638b53eb7c8

The installers above are suitable for use on your own computer as well as managed RIT-owned computers. However, Microsoft Windows computers bound to either the MAIN or FINANCE Active Directory domains already trust the certificates and do not need to run the Windows installer linked above.

Manually import and trust the RIT Certificate Authority

If you do not have a computer or device compatible with the installer tools above, you can manually import the RIT CA files. Operating systems and Web browsers typically provide a way to do this.

Importing the certificates and trusting the RIT CA manually is one way to set up the RIT CA in certain third-party applications, such as Mozilla Firefox, that do not use the operating system certificate store.

Download bundled certificates

Download the RIT Certificate Authority certificates as a single “p7b” bundle if the installers above do not work for your system or device. This method works with the Microsoft Internet Explorer Certificate Import Wizard, for example.

For the certificate bundle … Download this file …
RIT Certificate Authority
(trusted root and intermediates)
RIT Certificate Authority bundle.p7b

SHA1: f0dadf40df99b40a4bc18fc6cb2f89406122ebf1
MD5: 734097448a618512181fb194cd8ce29e

Download individual certificates

Download the RIT Certificate Authority certificates as individual “DER” files if the bundle does not work. The individual certificates work better for use with the Keychain Access utility on Mac OS X systems, for example, and can be double-clicked in the Mac OS X Finder.

If you get only one of the files below, be sure to get the “RIT Certificate Authority.cer” file, as that is the most important one — it’s the root certificate that you will want to trust.

For this certificate … Download this file …
RIT Certificate Authority
(trusted root)
RIT Certificate Authority.cer

SHA1: 9b0ab342f0d74852cb3469609d4f7b63adde6f46
MD5: 696d7fd6f0b40b056c1c208918040176
ITS Certificate Authority
(intermediate)
ITS Certificate Authority.cer

SHA1: 354960498812e4b16b8cb100413f122f9780a764
MD5: a774cff1f9c0db7fc08ffc5e51e9d339
RIT AD Certificate Authority
(intermediate)
RIT AD Certificate Authority.cer

SHA1: 7fa01e896d084245645a54ece5bfb264aa44301f
MD5: c08cb268814fa2b211899c07417a71dd

Contact us for help

To request desktop support, please contact the ITS Service Desk via

  • Phone - (585) 475-HELP
  • TTY - (585) 475-2810
  • E-mail - helpdesk@rit.edu
  • In person - Gannett Building, Room 7B-1113
Note: For assistance with connecting student-owned computers to the RIT network please go to the RESNET home page.