Installation and setup
Set up Memida Signing with an app password and your company certificate. The certificate and private key are stored encrypted on your computer.
You do not need a Memida account for local sealing. Seal verification also works without a certificate of your own and when the certificate store is locked.
Fig. 1: Initial setup of Memida Signing
Install the app
- On the download page, download the package for your operating system and computer architecture.
- Install the app: on macOS, copy it from the DMG file to Applications; on Windows, run the MSI package. On Linux, use the AppImage.
- Start Memida Signing.
The production documentation provides the production version; the staging documentation provides the test version. The app footer shows Production, Test environment or Development. Backups and sealing requests must come from the same environment.
If you still use 0.4.x, follow the one-time manual upgrade to 0.5.0 or later.
Linux: AppImage
The Linux download is an AppImage for 64-bit (x64) systems. Save the file permanently in a dedicated folder, such as ~/Applications. Enable execution permission in the file properties and open the AppImage.
Your user account must have write access to the AppImage file and its folder so that the app can install offered updates itself. The file path stays the same during an update. The app verifies the update signature before installation.
If you currently use a DEB package, first export a backup and quit the existing app. Then start the AppImage for the same environment. It continues to use that environment's existing certificate store.
Set an app password
Under App password, enter a password of your own with at least ten characters. Confirm it under Repeat app password and select Set app password (1).
This password unlocks your stored certificates. The app password is separate from your Memida password and the password for the certificate file.
If you have an existing backup, select Import backup and follow the restore instructions.
Save the recovery key
- Select Download recovery key (2) and save the file in a safe place.
- Confirm I have stored the key safely.
- Select Continue to certificates.
You can use the key to reset your app password. It does not replace a certificate backup. Store the two separately: anyone with both the key and the backup can access your certificates.
Add your first certificate
For DAkkS eAttestations, you need a valid seal certificate containing your laboratory's approved digital accreditation symbol. The eAttestation guide explains how to apply.
Select Add certificate (3) and import your .p12 or .pfx file using its certificate password. Check the organization and validity.
Then create a backup. The app is now ready for local sealing and Memida requests.
Unlock and lock the app
The app locks automatically after five minutes of inactivity. Select Lock app to lock it yourself.
Fig. 2: Unlock the certificate store with the app password
Enter your App password and select Unlock app (1) to use your stored certificates again.
Under Settings → Security, you can set up device authentication on supported computers, for example with Touch ID. Enter your app password and confirm the operating system prompt. Each sealing request still requires separate approval.
Device authentication is not included in the backup. Set it up again after changing your password or restoring a backup.