Installing The CA

On RISENet, HTTPS and other services that use TLS will require the installation of a root certificate. This is the ultimate source of cryptographic authority for all RISENet domains, email and HTTPS.

The file can be downloaded here, and is also available as raw ASCII and a curl command below.

Setup instructions for popular operating systems are found below. You may find that though commandline tools will work after the certificate is installed on your OS, depending on configuration your web browser may not respect these settings. Instructions for specific web browsers can also be found here.

Windows

iOS

Clicking the download link should prompt you, telling you that you're downloading a profile. Click 'Allow', this will download the profile and then you'll need to head to Settings.

CA download prompt Profile downloaded prompt


Scroll to the bottom of 'General' to 'VPN & Device Management'. You should see the RISENet Root CA profile, which you can install by tapping it.

VPN & Device Management location Profile install prompt


You have now installed the CA, but you still need to trust it. For this head to 'General > About' and scroll down:

Certificate Trust Settings location Certificate Trust Settings view


macOS

472e8118c70b9612a4126b10eee750ad.png

7d3111afb7102658f2ac90ce28d0aeb8.png

Double click the certificate 5b9c53e1b5735c1d738ca6d748dbeebc.png

Linux

Linux instructions vary between distribution, so not everything is covered here. Email memphis@dotmail.rise or ping @aurillium on Discord if you have instructions for other distributions.

Debian / Ubuntu / Kali / Raspberry Pi OS

sudo cp risenet_ca.crt /usr/local/share/ca-certificates/risenet_ca.crt
sudo update-ca-certificates

Arch / CachyOS / EndeavourOS / SteamOS

sudo cp risenet_ca.crt /etc/ssl/certs/risenet_ca.crt
sudo update-ca-trust

NixOS

# RISENet certificate
security.pki.certificates = [
  ''
  RISENet Root CA
  ===============
  -----BEGIN CERTIFICATE-----
  MIIDB...(rest of certificate)...uC2ME=
  -----END CERTIFICATE-----
  ''
];

Firefox

In about:preferences (settings), search 'certificate' and click of 'View Certificates...': e893101a80501269e5347ddd2a4c6449.png This will open the certificate manager. Select the 'Authorities' tab: 3fe19e6141f71e5f7fc370a3cc78aef0.png Click 'Import...' and select the RISENet CA file. You should get a prompt asking what to trust the certificate for. Choose all available options here. 542c71a69a7f164a0dd2c3f0b3f45c9d.png Press OK and then OK again to exit the certificate manager. The certificate should now be installed. You should be able to see the certificate in the authorities list of the certificate manager now. bbabafe2577ffab4cddcf0197895f6a2.png

Raw CA File

Direct link: https://rise.aurillium.space/risenet_ca.crt

Curl from RISENet (jq required):

curl -sk --resolve ca.risenet:443:10.128.128.128 https://ca.risenet/roots | jq -rc '.crts.[0]' > 

Raw ASCII file:

-----BEGIN CERTIFICATE-----
MIIDBDCCAoqgAwIBAgIQCLbB3x7xePQgx0GmOoY0BDAKBggqhkjOPQQDAzAaMRgw
FgYDVQQDEw9SSVNFTmV0IFJvb3QgQ0EwIBcNMjYwNjE0MDYzMjA1WhgPMjEyNjA2
MTUwNjMyMDVaMBoxGDAWBgNVBAMTD1JJU0VOZXQgUm9vdCBDQTB2MBAGByqGSM49
AgEGBSuBBAAiA2IABOX7ahSQbmc54wKDd9ZfloCiJ88qTjeeyCyOG6OQt4E5pP4Q
/h+4r4O/SQhpcfF2/MJ8EX1u6bUzGPcwilu73xvDwKD7QwNv1F921PRwSv0hU7WK
vgh5UE9K05WUAOqyCqOCAZEwggGNMA4GA1UdDwEB/wQEAwIBBjASBgNVHRMBAf8E
CDAGAQH/AgECMB0GA1UdDgQWBBTs8oShrXuuFTB8WfyTshdZ4R7ipzCCAUYGA1Ud
HgEB/wSCATowggE2oIIBMjAMggpyaXNlbmV0LmF1MAmCB3Jpc2VuZXQwB4IFcmlz
ZW4wBoIEcmlzZTAEggJycjAJggdyZWRyb29tMAeCBWNhc3NhMAmCB3N0dWRlbnQw
CIIGYWx1bW5pMAmCB2ZhY3VsdHkwCIIGaGFja21lMAWCA3B3bjAFggNjdGYwBYID
bnlhMAaCBGJvcmswBYIDdXd1MAWCA3JzcDAMgQpyaXNlbmV0LmF1MAmBB3Jpc2Vu
ZXQwB4EFcmlzZW4wBoEEcmlzZTAEgQJycjAJgQdyZWRyb29tMAeBBWNhc3NhMAmB
B3N0dWRlbnQwCIEGYWx1bW5pMAmBB2ZhY3VsdHkwCIEGaGFja21lMAWBA3B3bjAF
gQNjdGYwBYEDbnlhMAaBBGJvcmswBYEDdXd1MAWBA3JzcDAKBggqhkjOPQQDAwNo
ADBlAjAgKrxpJbuKK9mFRTWD6fXZXs5WrL4TBVXrG6dJU1RgEdWVoM2tZdn6HE27
rbTvLSYCMQCvZQqiek1c2CiOq6bqR53WUwBcFMqVsux481m/JqibmbFPYV1SlcLA
oLDlOAuC2ME=
-----END CERTIFICATE-----