Skip to content

Importing SB2 Root CA and Subordinate CA Certificates into Truststore

When using Security Keys with digital certificates for authentication to an SB2 site, the SB2 Root Certificate Authority (CA) certificate of the site is a critical component in establishing trust between your browser and the site. It ensures the digital certificate on your Security Key was issued by that SB2 site and is currently valid.

B1 Prerequisites

  • MacOS 13 and above
  • Safari 26.0.1
  • Internet Connection

B2 Access the SB2 PKI Portal

All required CA certificates are available for download from the SB2 PKI landing page at https://www.strongkey.com/sb2pki.

Import SB2 RootCA

B3 SB2 CA Certificates

Next, download the three SB2 Production CA certificates from the left side of the page.

Note

Download the certificates starting with the Root CA.

Import SB2 RootCA

B4 Downloading the SB2 Root CA

First, click the Download Root CA button. The download will begin automatically, and you’ll see a dialog box confirming the file name once the process is complete.

REPEAT this process for the Sub CA 1 and Sub CA 2 certificates.

Import SB2 RootCA

B5 Access macOS Finder

To get started installing the certificates, open the Finder application by clicking its icon in the Dock or by selecting it from the menu in the upper left corner of your screen.

Import SB2 RootCA

B6 Locate Downloaded SB2 RootCA File

Navigate to the Downloads folder in Finder. Locate the SB2 Root CA file and right-click it.

Note

Please note that your specific SB2 certificate files may have a different name. Ensure you know the correct file name before proceeding.

Import SB2 RootCA

B7 Open Keychain Access

Launch Keychain Access by searching with Spotlight [⌘ + Space] (refer to Image 1), or by navigating to Applications in Finder (see Image 2).

Image 1 Import SB2 RootCA

Image 2 Import SB2 RootCA

B8 Navigating in the Keychain Access Application

After launching the KeyChain Access application, the following screen appears. Select System in the sidebar, followed by Certificates in the top menu.

Import SB2 RootCA

B9 Importing Certificates

Next, drag the Root Certificate into the Keychain Access window to begin the certificate import process. The macOS will prompt you to authenticate using Touch ID or an account password to complete the import.

Import SB2 RootCA

B10 Access the SB2 RootCA Certificates

Right-click on the imported SB2 RootCA certificate, then select Get Info to view its details.

Import SB2 RootCA

B11 Trust the SB2 RootCA Certificate

To view the Trust details, click the down arrow next to the Trust option. Then, select Always Trust for both Secure Sockets Layer (SSL) and X.509 Basic Policy.

Import SB2 RootCA

B12 Authenticating the Changes to the SB2 RootCA Certificates

After the SB2 RootCA Get Info window is closed, macOS prompts for authentication, using either Touch ID or the macOS account password, to confirm changes to the Trust settings.

Import SB2 RootCA

B13 Confirming the Trust Changes

Click Next to continue. To confirm the trust settings, right-click the SB2 RootCA certificate and select Get Info. A successful import and trust is indicated by the message: “This certificate is marked as trusted for all users.

Import SB2 RootCA

B14 Accessing the Downloaded Subordinate Root Certificate Files

To get started, launch Keychain Access by searching with Spotlight [⌘ + Space] (refer to Image 1), or by navigating to Applications in Finder (see Image 2).

Image 1 Import SB2 RootCA

Image 2 Import SB2 RootCA

B15 Navigating in the Keychain Access Application

After launching the KeyChain Access application, the following screen appears. Select System in the sidebar, followed by Certificates in the top menu.

Import SB2 RootCA

B16 Importing Certificates

Next, drag the SB2-SubordinateCA.crt file into the Keychain Access window to begin the certificate import process. The macOS will prompt you to authenticate using Touch ID or an account password to complete the import.

Import SB2 RootCA

B17 Access the SB2 Subordinate CA Certificate Details

Right-click on the imported SB2 SubordinateCA certificate, then select Get Info to view its details.

Import SB2 RootCA

B18 Trust the SB2 Subordinate CA Certificate

To view the Trust details, click the down arrow next to the Trust option. Then, select Always Trust for both Secure Sockets Layer (SSL) and X.509 Basic Policy.

Import SB2 SubCA

B19 Authenticating the Changes to the SB2 Subordinate CA

After the SB2 SubordinateCA Get Info window is closed, macOS prompts for authentication, using either Touch ID or the macOS account password, to confirm changes to the trust settings.

Import SB2 SubCA

B20 Confirming the Trust Changes

To confirm the trust settings, right-click the SB2 SubordinateCA certificate and select Get Info. A successful import and trust is indicated by the message: “This certificate is marked as trusted for all users.

Import SB2 SubCA