Set Up Your DigiCert Provided eToken (2024)

Learn how to set up your code signing DigiCert-provided hardware token.

Before you begin

Before you begin, make sure you meet these prerequisites:

  • DigiCert-provided hardware token: SafeNet 5110 CC, SafeNet 5110 FIPS, or SafeNet 5110+ FIPS.
  • Access to your certificate's Order details page in CertCentral.
  • Code Signing or EV Code Signing certificate order number.
  • Verify whether the eToken is blankor comes with the certificate preinstalled.
  • Administrator permissions on your computer.
  • Secure password manager.See Passwords 101.

Important:

This process will require you to supply multiple passwords. If you incorrectly enter or lose a password, you can permanently disable your eToken. We recommend using a secure password manager to track the passwords used for initializing your eToken. 

How do I know if my eToken is blank or comes with the certificate installed?

In your CertCentral account, go to your certificate's Order details page. In theCertificate actionsdropdown menu, what option do you see? The menu option lets you know if the eToken is blank or has the certificate preinstalled.

Menu options:

  • Install certificate
    This option means the eToken is blank, and you must install the certificate on the eToken. SeeInstall your code signing certificate on your hardware eTokenbelow.
  • Initialize token
    This option means the certificate comes preinstalled on your eToken. You need to unlock the eToken to access your certificate.See Initialize your eTokenbelow.


Install your code signing certificate on your eToken

  1. In your CertCentral account, in the left main menu, go toCertificates > Orders.
  2. On theOrderspage, select the certificate's order number.
  3. On the certificate'sOrder detailspage, in theCertificate detailsection, in theCertificate actionsdropdown, selectInstall certificate.
  4. Use the following link to download and install the DigiCert Hardware Certificate Installer:
    Download the DigiCert Hardware Certificate Installer
    1. You must install theSafeNet Authentication ClientToolson any system you plug the eToken in to sign code.
    2. Learn how toinstall the SafeNet Drivers.
  5. Copy the initialization code for your order.
  6. Open the DigiCert Hardware Certificate Installer.
  7. In theDigiCert Hardware Certificate Installeron the Initialization Codepage, in theInitialization Codebox, enter the initialization code from your CertCentral account and then selectNext.

    Set Up Your DigiCert Provided eToken (1)

  8. Plug in your eToken.
  9. On theToken Detectionpage, checkRe-initialize my token and permanently delete any existing certificates and keysand then selectNext.
    If you are installing an alternate chain or key type and need to keep your current certificate on the eToken intact, leave theRe-initializeoption unchecked.

    Set Up Your DigiCert Provided eToken (2)

  10. On theKey informationpage, do one of the following tasks and then selectNext:
    • RSA
      1. Under Key Type, select RSA.
      2. Under Key Size/Curve Name, select 4096.
    • ECC Key Types
      1. Under Key Type, select ECC
      2. Under Key Size/Curve Name, select p-256 or p-384.

        Set Up Your DigiCert Provided eToken (3)

  11. On theToken Setuppage, do the following tasks:
    1. Add aToken Name.
      The token name is used to identify the eToken. This name is helpful when you have multiple eTokens.
    2. Create aToken Password.
      This password (sometimes called a token PIN) is required to access the certificates saved on the eToken.

      Set Up Your DigiCert Provided eToken (4)

  12. READ THIS BEFORE YOU CONTINUE

    On theAdministrator Passwordpage, do one of the following tasks:

    1. If you haveNOT changed the Administrator Password since receiving your eToken, leaveUse factory default Administrator passwordchecked and selectFinish.
    2. If you have set a new Administrator Password (done outside of DigiCert Support using the SafeNet client), uncheckUse factory default Administrator password, enter the current Administrator Password, and selectFinish.

      Set Up Your DigiCert Provided eToken (5)

  13. On theCertificate Installationpage, be patient and wait.
    Someof the steps may take several minutes to complete. Wait toremove the eTokenuntil the whole process is completed.
    Generating an RSA 4096-bit key will take time. Let the process complete.

    Set Up Your DigiCert Provided eToken (6)

  14. When the process finishes, selectClose.

    Set Up Your DigiCert Provided eToken (7)

  15. You can now use the code signing certificate on your eToken to sign code.

Initialize your eToken

  1. In your CertCentral account, in the left main menu, go toCertificates > Orders.
  2. On theOrderspage, select the certificate's order number.
  3. On the certificate's Order details page, in the Certificate detail section, in the Certificate actions dropdown, select Initialize Token.

    Important: Do not proceed without your DigiCert-provided hardware token. You need the eToken to complete these steps. Additionally, some information is only shown one time.


  4. On the initialization page, confirm you have your eToken.
    If you have not received your DigiCert-provided hardware token,do notproceed. You can use the link to check your tracking information. However, come back once you have your DigiCert-provided token.
    1. Now that you have your DigiCert-provided hardware token, checkI have received the hardware token.
    2. When ready, selectSubmit.
  5. On the confirmation page, copy your preassigned eToken password and store it in a safe place.

    Warning:Your preassigned password will only be visible once. Make sure to take note of this password. You need it to access your certificate on your DigiCert-provided hardware token. SeePassword 101.


  6. Use the link to download and install the DigiCert Hardware Certificate Installer.
    1. You must install the SafeNet Authentication ClientToolson any system you plug the eToken in to sign code.
    2. Learn how toinstall the SafeNet Drivers.
  7. Change the eToken password.
    The eToken password is used toaccess the eToken certificate store.
    1. Open the SafeNet Authentication Client and then connect the eToken to your computer.
    2. In the SafeNet Authentication Client, on the top of the page, click the cog icon (Advanced View button).
      You should now see the eToken listed in the tree menu on the left side of the page.
    3. Right-click on the eToken name and selectChange Password.
    4. On the change password page, enter yourCurrent Token Passwordfrom theInitialization pagein CertCentral.
    5. Next, create a new password.
    6. Save theNew Token Passwordin your secure password manager.
    7. When ready, selectOK.
  8. You can use the certificate on your eToken to sign code.


Password 101

Warning: The SafeNet eToken uses multiple passwords for authentication. If anAdministrator Passwordis entered incorrectlyfive times, the eToken is permanently locked.


The SafeNet eToken uses the following passwords:

  • Administrator Password:

    The default Administrator Password is"0" 48 timesas provided by the manufacturer. If "this" password is lost, you are permanently locked out of the eToken and must purchase a new one. DigiCert does not set up this password.

  • Token Password:

    This password is used toaccess the eToken certificate store. If lost, you can reset the eToken and reinstall the certificate.

  • Personal Unlocking Key (PUK): Default PUK is 000000.DigiCert does not use the PUK in our process.

Minimum Password Requirements:

  • Your password should contain at least 8 characters.
  • Your password should include both upper-case characters and lower-case characters as well as numerals and special characters (for example: !, $, %, #).
  • The minimum password length and character requirements apply to both the Token password and the Administrator password.


Troubleshooting

  1. My token appears as "SafeNet Token JC 0."
    Your eToken has been permanently disabled due to incorrect password attempts. Please contactDigiCert Supportto order a new eToken.

    Set Up Your DigiCert Provided eToken (8)

  2. I lost my Administrator password.
    The administrator password is required to reset the device and is unrecoverable. Please contactDigiCert Supportto order a new eToken.
    Note: The manufacturer sets this password,not DigiCert.
  3. I lost my Token password.
    The Token Password is used to access the eToken certificate store. Use the Administrator Password to reset the eToken password if lost.
    If you have lost your Token Password, you can reinitialize the eToken and create a new Token store when you reissue/rekey your certificate.
    1. Reissue your certificate.
      • Reissue or re-key a Code Signing certificate
      • Reissue or re-key an EV Code Signing certificate
      • Rekeying Your DigiCert Document Signing Certificate
    2. Re-initialize your eToken.After DigiCert reissues your certificate, install it on your eToken. SeeInstall your code signing certificate on your hardware token.

      Note: Items 4, 5, 6 and 7 refer to troubleshooting errors for the DigiCert Hardware Certificate Installer.


  4. Error "The Initialization Code was invalid, has already been used, or has expired."
    • Scenario 1: The user has an existing order in a reissue state.

      Solution
      :
      1. Log in to the account > Certificates > Orders > Click on the order number > Certificate Actions > Reissue Certificate > Provisioning options > Use existing token > Submit request.
      2. Return to the order > Certificate Actions > Install certificate > Copy the new initialization code.
    • Scenario 2:The new order does not have the "install certificate" option in the CertCentral account.

      Solution:
      Reissue the certificate when the install certificate option is not displayed under certificate actions.

      1. Log in to the account > force a reissue using the link below in a new tab on the browser where you are logging in from:https://digicert.com/secure/orders/{order-number}/reissue
      2. Select Provisioning options > Use existing token > Submit request.
      3. Return to the order > Certificate Actions > Install certificate > Copy the new initialization code
    • Scenario 3:Some time has passed before an install attempt has been made which resulted in the above error.

      Solution
      :
      Force reissue the certificate when only the install certificate option is displayed under certificate actions.
      1. Log in to the account > force a reissue using the link below in a new tab on the browser where you are logging in from: https://digicert.com/secure/orders/{order-number}/reissue
      2. Select Provisioning options > Use existing token > Submit request.
      3. Return to the order > Certificate Actions > Install certificate > Copy the new initialization code.

        Set Up Your DigiCert Provided eToken (9)

  5. Error:8-0x00000062

    This error is caused by trying to install your certificate on a token that does not support RSA above 2048.
    You will need to choose ECC in the DigiCert Hardware Certificate Installer to complete the installation or reissue the order and purchase an additional token that will be compatible.ECC is not always compatible with all signing tools, so this option is only if you need to sign urgently and the signing tool you utilize supports ECC or are unable to purchase a new token at the time.It is recommended that you have a supported token.

  6. Error: 5-0x00000030This error is related to not having the latest Safenet version. To solve this issue please update to the latest Safenet version which you can find here.
  7. Error: 8-0x00000031This error is related to having too many code signing certificates on the same token. To solve this issue please remove some of the certificates to ensure sufficient space is availbale for another certificate.Once you have removed the certificates, please reattempt the initialization process.
Set Up Your DigiCert Provided eToken (2024)

FAQs

What is the default password for DigiCert eToken? ›

Note: The Default Administrator password is "0" typed out 48 times (see above). This is not changed by DigiCert.

How to unlock DigiCert token? ›

On the Administrator Setup page, if you want to set up an administrator password, check Set Administrator Password. We recommend that you setup an administrator password. If the token becomes locked, you can use this password to unlock the token. You can also use the administrator password to reset the token password.

What is the administrator password for DigiCert? ›

Administrator Password:

The default Administrator Password is "0" 48 times as provided by the manufacturer. If "this" password is lost, you are permanently locked out of the eToken and must purchase a new one. DigiCert does not set up this password.

How to reset eToken password? ›

In the SafeNet Authentication Client Tools window, select Change Token Password. On the Change Password Token page, do the following tasks: In the Current Token Password box, enter your current password. In the New Token Password and Confirm Password boxes, enter and confirm your new token password.

How do I reset my DigiCert password? ›

Once logged in to the User Management portal, choose the option for Manage Profile from the left-hand sidebar or click on Edit Profile under the welcome message on the Dashboard page. Select the Change Password option from the menu on the left.

Can I create my own code signing certificate? ›

While technically, it's possible to generate a self-signed certificate for code signing; however, it won't serve the purpose of security and legitimacy. If you still want to get a self-signed code signing certificate, here's a guide on how you can create one.

How do I generate a certificate in DigiCert? ›

Run the DigiCert Certificate Utility for Windows (double-click DigiCertUtil). On the Create CSR page, under Certificate Details, provide the following information below and select Generate. For Certificate Type, select SSL. In the Common Name box, enter the fully qualified domain name (FQDN) (e.g., www.example.com).

How to verify code signing certificate? ›

In Chrome, go to Settings. On the Settings page, below Default browser, click Show advanced settings. Under HTTPS/SSL, click Manage certificates. In the Certificates window, on the Personal tab, double-click the code signing certificate that you just installed.

How do I get a private key from DigiCert tool? ›

The private key will be located on the system or appliance the certificate signing request (CSR) was generated. On a Linux machine: The most common way to create a CSR is by using openssl commands. The commands used will generate the CSR and private key files wherever is designated, typically in the same folder.

How do I recover my token password? ›

iToken does not support the retrieval of security passwords.

If you forget the security password, and you lose your mnemonics, you can only try by repeatedly entering the security password.

How do I find the admin password? ›

Finding the Admin Password In Your Computer's Settings

Access the computer's BIOS menu – this is usually done by pressing the Del or F2 key. Here you can usually find the complete password in plain text. If it is not available in the BIOS, look for the “security tab” in your computer's settings.

How do I login to DigiCert One? ›

By default, DigiCert ONE requires a username and password. We recommend using your email address as your username. After adding a user, DigiCert ONE sends them the Update Your Account email and requires them to create a password before signing in.

What is the default admin password? ›

A default (admin) password is a piece of alphanumerical text for the user to log in to a service for the first time. Common default passwords include “admin” and “guest”. Default login credentials can be found in user manuals. Many websites share lists of default login info as well.

What is the default password for Safenet eToken? ›

Plug in and reset the password. Note: For the new Safenet eToken 5110 CC (940), the default password is "0000". For old tokens, the default password is "1234567890".

What is the default password for Digi terminal server? ›

Log into the Digi One TS/PortServer TS 2/4 as root by enter- ing the following : • At the login prompt, type root. At the password prompt, type dbps (which is the default password. If the password has been changed, use the new password.)

What is the default password for DSC token? ›

Step 2: Click on Login Button. Enter Default password i.e 12345678 & click on OK. Step 3: Click on Change User PIN.

What is Digi default credentials? ›

The default user name is admin and the default password is the unique password printed on the label packaged with your device.

Top Articles
Latest Posts
Article information

Author: Delena Feil

Last Updated:

Views: 5358

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Delena Feil

Birthday: 1998-08-29

Address: 747 Lubowitz Run, Sidmouth, HI 90646-5543

Phone: +99513241752844

Job: Design Supervisor

Hobby: Digital arts, Lacemaking, Air sports, Running, Scouting, Shooting, Puzzles

Introduction: My name is Delena Feil, I am a clean, splendid, calm, fancy, jolly, bright, faithful person who loves writing and wants to share my knowledge and understanding with you.