%META:TOPICPARENT{name="ODSGenerateWebIDX509CertBrsKeystore"}% ---+Generate an X.509 Certificate (with a WebID watermark) to be managed by the Firefox browser-based keystore ---++ Prerequisites 1. [[ODSSetupSSL][Set up an X.509 certificate issuer and HTTPS listener]]. 1. [[ODSX509GenerateIESetService][Set up an X.509 Certificate Service]]. ---++ Certificate Generation Process These steps will work against any ODS instance where you have the requisite privileges. 1 Go to the ODS home page (local or remote) and log in as an ODS user (registering as such first, if necessary). %BR%%BR%%BR%%BR% 1 After log in, you will have an ODS-generated Person Entity Identifier (an HTTP URI that Identifies "You") of the form: http://cname/dataspace/person/user-name#this %BR%%BR%%BR%%BR% 1 Fill out your profile, if still in default state. (Note: If this step is skipped, the resulting X.509 certificate may not have a human-readable name.) %BR%%BR%%BR%%BR% 1 Go to Security: %BR%%BR%%BR%%BR% 1 Go to Certificate Generator: %BR%%BR%%BR%%BR% 1 Fill out the form, for example: * Country: UK; * Organization: OL; * Valid for: 90 hours. %BR%%BR%%BR%%BR% 1 Click Submit certificate request. 1 Firefox should show that it is generating a private key: %BR%%BR%%BR%%BR% 1 When private key generation is finished, Firefox should report a successful installation of the certificate: %BR%%BR%%BR%%BR% 1 Go to X.509 Certificates. 1 The new certificate should be shown in the list of certificates available for the ODS user: %BR%%BR%%BR%%BR% 1 Note you have now also the option automatic WebID Login set to enabled -- a powerful feature benefits of which we will demonstrate next in our example: %BR%%BR%%BR%%BR% 1 Verify the new certificate by performing the following steps: 1 Log out and access [[https://id.myopenlink.net/ods/][https://id.myopenlink.net/ods/]]; 1 When prompted by your browser, select the new certificate generated above: %BR%%BR%%BR%%BR% 1 You should then be presented with the ODS Log-in form. Click WebID Login: %BR%%BR%%BR%%BR% 1 You should now be successfully logged in: %BR%%BR%%BR%%BR% 1 If you now log in as another user (e.g., demo), you can [[ODSBriefcaseWebIDPerson][share a resource to the above user, using a WebID-based ACL]], which is itself enabled by the new WebID-watermarked X.509 Certificate. ---++Related * [[ODSGenerateX509Certificate][Generating WebID-watermarked X.509 Certificates for Use with ODS]] * [[ODSGenerateWebIDX509CertBrsKeystore][Generate an X.509 Certificate (with a WebID watermark) to be managed by a browser-based keystore]] * [[ODSGenerateWebIDX509CertBrsKeystoreOpera][Opera]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtSPARQLEndpointProtection][Safeguarding your Virtuoso-hosted SPARQL Endpoint]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtTipsAndTricksGuideSPARQLEndpointProtection][SPARQL Endpoint Protection Methods Collection]] * [[http://docs.openlinksw.com/virtuoso/][Virtuoso documentation]] * [[http://docs.openlinksw.com/virtuoso/rdfsparql.html#rdfsupportedprotocolendpoint][SPARQL Service Endpoint]] * [[http://docs.openlinksw.com/virtuoso/rdfsparql.html#rdfsupportedprotocolendpointuri][Service Endpoint Security]] * [[http://docs.openlinksw.com/virtuoso/rdfsparql.html#sparqwebservicetbl][Managing a SPARQL Web Service Endpoint]] * [[http://docs.openlinksw.com/virtuoso/rdfsparql.html][SPARQL]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtTipsAndTricksGuide][Virtuoso Tips and Tricks Collection]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtSPARQLDET][SPARQL Endpoint DET Configuration Guide]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtSPARQLSecurityWebID][WebID Protocol & SPARQL Endpoint ACLs Tutorial]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtOAuthSPARQL][SPARQL OAuth Tutorial]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtTipsAndTricksGuideSPARQLEndpoints][Securing SPARQL endpoints]] * [[OdsSPARQLAuth][SPARUL over SPARQL using the http://cname:port/sparql-auth endpoint]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtAuthServerUI][Virtuoso Authentication Server UI]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtSPARQLSSL][Manage a SPARQL-WebID based Endpoint]] * [[VirtODSSecurityWebID][WebID Protocol Support in OpenLink Data Spaces]]. * Manage ODS Datadspaces Objects WebID Access Control Lists (ACLs): * [[ODSBriefcaseWebID][ODS Briefcase WebID based ACL Guide]] * [[ODSBriefcaseWebIDPerson][Person Entity WebID based ACL Guide]] * [[ODSBriefcaseWebIDGroup][Group Entity WebID based ACL Guide]] * [[ODSBriefcaseWebIDPublic][Public WebID based ACL Guide]] * [[ODSFeedManagerWebIDACL][ODS Feed Manager WebID based ACL Guide]] * [[ODSFeedManagerWebIDACLPerson][Person Entity Specific ACL]] * [[ODSFeedManagerWebIDACLGroup][Group Entity Specific ACL]] * [[ODSFeedManagerWebIDACLPublic][Public Specific ACL for anyone with a WebID]] * [[ODSCalendarWebIDACL][ODS Calendar WebID based ACL Guide]] * [[ODSCalendarWebIDACLPerson][Person Entity Specific ACL]] * [[ODSCalendarWebIDACLGroup][Group Entity Specific ACL]] * [[ODSCalendarWebIDACLPublic][Public Specific ACL for anyone with a WebID]] * [[ODSBookmarksWebIDACL][ODS Bookmark Manager WebID based ACL Guide]] * [[ODSBookmarksWebIDACLPerson][Person Entity Specific ACL]] * [[ODSBookmarksWebIDACLGroup][Group Entity Specific ACL]] * [[ODSBookmarksWebIDACLPublic][Public Specific ACL for anyone with a WebID]] * [[ODSAddressBookWebIDACL][ODS Addressbook WebID based ACL Guide]] * [[ODSAddressBookWebIDACLPerson][Person Entity Specific ACL]] * [[ODSAddressBookWebIDACLGroup][Group Entity Specific ACL]] * [[ODSAddressBookWebIDACLPublic][Public Specific ACL for anyone with a WebID]] * [[ODSPkiSetup][Guide for Set up a X.509 certificate issuer and HTTPS listener and generate ODS user certificates.]] * [[ODSSetupSSL][Configure Virtuoso+ODS instance as an X.509 Certificate Authority and HTTPS listener]] * [[http://virtuoso.openlinksw.com/dataspace/dav/wiki/Main/VirtSetupSSL][Configure Virtuoso instance as an X.509 Certificate Authority and HTTPS listener]] * [[VirtODSPubSubHub][Setting up PubSubHub in ODS]] * [[VirtPubSubHub][PubSubHubBub Demo Client Example]] * [[VirtFeedPubSubHub][Feed subscription via PubSubHub protocol Example ]] * [[VirtPubSubHubACL][Setting Up PubSubHub to use WebID Protocol or IP based control lists]] * [[OdsKeyImport][CA Keys Import using Conductor]] * [[ODSWebIDIdP][Using Virtuoso's WebID Verification Proxy Service with a WebID-bearing X.509 certificate]] * [[ODSWebIDIdpProxy][Using Virtuoso's WebID Identity Provider (IdP) Proxy Service with an X.509 certificate]] * [[ODSBriefcaseWebIDShareFile][ODS Briefcase WebID Protocol Share File Guide]] * [[http://esw.w3.org/topic/foaf+ssl][WebID Protocol Specification]] * [[https://foaf.me/simpleLogin.php][Test WebID Protocol Certificate page]] * [[http://test.foafssl.org/cert/][WebID Protocol Certificate Generation page]]