fd53 sign-in

One account for the fd53 fleet: your directory name, your password, and your passkey. Pick what you came to do.

Trust the fd53 certificates

Sites inside the fd53 network (*.mesh.fd53.net) use certificates from the ITYS Mesh Root CA. Install it once on each device that reaches them, after checking its fingerprint.

SHA-256 fingerprint, which must match before you trust it:
40:84:80:02:32:60:14:20:26:3B:1C:60:31:A4:79:EC:08:05:9E:3E:20:E7:01:39:5B:D4:9C:A4:8F:EF:E0:49

How to install it

Ubuntu, Debian: sudo cp itys-mesh-root.crt /usr/local/share/ca-certificates/ && sudo update-ca-certificates

Firefox: Settings, Privacy and Security, Certificates, View Certificates, Authorities, Import; tick "trust to identify websites".

Chromium, Chrome on Linux: they use the system store above, or Settings, Privacy and security, Security, Manage certificates, Authorities, Import.

macOS: open the file, add it to the System keychain, then in Keychain Access set it to Always Trust.

Windows: open the .der file, Install Certificate, Local Machine, Trusted Root Certification Authorities.

Android: Settings, Security, Encryption and credentials, Install a certificate, CA certificate.

iOS: open the file in Safari, install the profile, then Settings, General, About, Certificate Trust Settings, turn it on.

Check that the fingerprint your system shows is the one above. Never trust a copy whose fingerprint differs.

Changing your password

Passwords live in Kerberos. On a machine set up for fd53, run kpasswd. The new password works everywhere at once, the web included.

Something wrong?

Five wrong passwords lock your account for 15 minutes. A passkey you do not recognise on your account: tell an admin at once.