Request user certificate
FAQ
General
When someone sends an email with a digital signature, you can see in your email program whether a certificate was used and, if so, which one. This is also a prerequisite for sending encrypted emails to that person – because to do so, you need the public key from the recipient’s certificate.
Outlook (Microsoft 365)
Open the sender’s email. For a digitally signed message, a red seal icon (a red ribbon with a bow) appears in the message header.

Click on the symbol. A small window will open with the message “Digital Signature: Valid.” Click on “Details,” then “Signatory:,” then “View Details...,” and finally “View Certificate. ..” to view additional information about the certificate, such as the holder’s name and the issuing authority.

Outlook automatically adds the sender’s certificate to your contacts, so you can then send encrypted emails to that person.
Thunderbird
Open the sender’s email. For a digitally signed message, a seal icon appears in the top-right corner in the message header.

Click on the symbol. A window opens showing whether the signature is valid. If you click the “View Signature Certificate” button, you can view the full certificate details, including name, email address, and validity period.

Thunderbird automatically saves the sender’s certificate. Once you have received the certificate, you can also send encrypted emails to that person.
Horde webmail
Open the sender’s email. If the message has been digitally signed, an icon with a padlock and a note about the signature appear in the message header.

Click on the “Click HERE to verify the information” prompt, and then click on the sender’s name next to “From:” to view details about the certificate used – including the owner's name, email address, and the issuing certification authority.

Yes, there are also instructions on how to do this in the right-hand section of the website.
The user certificate has a validity/period of 730 days (2 years).
Outlook
No FAQ's found.
Thunderbird
Error message in Thunderbird: "Certificate management cannot find a valid certificate that can be used to digitally sign your messages with the address <vorname.nachname@uni-hohenheim.de>."
- Navigate to the "Account Settings" under the "Extras" menu.
- Select "End-to-end encryption" on the left.
- Click on the "Select" button under "Personal certificate for digital signature" and under "Personal certificate for encryption" and select the new valid certificate.
Error message in Thunderbird: "Sending the message failed: You have chosen to digitally sign this message, but the application could not find the signing certificate you specified in your account settings or the certificate has expired."
- Navigate to the "Account Settings" under the "Extras" menu.
- Select the "End-to-end encryption" on the left.
- Click on the button "Manage S/MIME certificates".
- Click on "Import" and select the new certificate.
- Click on "Empty" for "Personal certificate for digital signature" and for "Personal certificate for encryption".
- Click on the "Select" button under "Personal certificate for digital signature" and under "Personal certificate for encryption" and select the new valid certificate.
PDF signature
The eIDAS Regulation distinguishes between three levels:
- EES – Simple Electronic Signature: Any form of digital declaration of intent, such as a typed name at the bottom of an email or a scanned signature stamp. Does not provide technical protection against tampering or identity theft.
- FES – Advanced Electronic Signature: A cryptographically generated signature that uniquely identifies the signatory, is under the signatory’s sole control, and makes any subsequent changes to the document detectable. Complies with the technical standard achieved through HARICA certifications.
- QES – Qualified Electronic Signature: An FES that is additionally created using a qualified certificate from an accredited trust service provider and a secure signature creation device (e.g., a signature card). Only the QES is legally equivalent to a handwritten signature under Section 126a of the German Civil Code (BGB).
Technically, yes – HARICA S/MIME user certificates can be used in Adobe Acrobat or Reader to sign PDF documents. However, they are not suitable for externally verifiable signatures: The signature will not automatically be displayed as trusted on any device – neither on the signer's nor the recipient’s unless the HARICA root certificate has been manually imported beforehand.
The warning appears on every device where the root certificate has not been imported – that is, on both the sender’s and the recipient’s devices. This applies regardless of whether a user certificate of the “emailonly” or “IV+OV” type is used.
Yes, the warning will disappear provided that the root certificate “HARICA Client RSA Root CA 2021” has been manually imported into Adobe Acrobat on the respective device and marked as trusted. The root certificate is not currently being rolled out automatically.
The root certificate can be downloaded: HARICA-Client-RSA-Root-2021.p7b (SHA-1: 46:C6:90:0A:77:3A:B6:BC:F4:65:AD:AC:FC:E3:F7:07:00:6E:DE:6E)
Important: HARICA S/MIME certificates are technically intended for email signatures, not for document signatures. Manual import is therefore only useful when documents are reviewed exclusively within a controlled group of recipients. PDF signatures that are accepted by the recipient without any prior configuration require dedicated document signature certificates (see the FAQ “What alternatives are available for PDF signatures which can be validated externally?”).
Adobe Acrobat zeigt bei PDF-Signaturen mit HARICA-S/MIME-Nutzerzertifikaten folgende Meldung an: „Gültigkeit der Unterschrift ist UNBEKANNT – Die Identität des Unterzeichners ist unbekannt, weil sie sich nicht in der Liste der vertrauenswürdigen Zertifikate befindet und keines der übergeordneten Zertifikate ein vertrauenswürdiges Zertifikat ist."
Ursache ist die fehlende Verankerung des ausstellenden Root-Zertifikats „HARICA Client RSA Root CA 2021" in der Adobe Approved Trust List (AATL). Adobe erkennt dieses Root nicht automatisch als vertrauenswürdig an. Die Warnung verschwindet, sobald das Root-Zertifikat auf dem jeweiligen Gerät manuell in Adobe Acrobat als vertrauenswürdig importiert wurde – das Dokument selbst wurde dabei in jedem Fall nach dem Unterzeichnen nicht verändert.
Getestet am 26.05.2026 mit Adobe Acrobat Pro Version 2026.001.21529 (64-Bit)
PDF signatures that are recognized as trustworthy by the recipient without any prior configuration require dedicated document signature certificates – such as HARICA Advanced eSignature. These are issued via the AATL-listed roots “HARICA Document Signing RSA 1” and “HARICA Document Signing ECC 1,” respectively, and contain the correct EKU id-kp-documentSigning; however, they are subject to a fee. If necessary, please contact kim-pki@uni-hohenheim.de.
Do you have questions or comments about this site? contact form