<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Letsencrypt on Michael’s Domain</title><link>https://jeltsch.org/en/tags/letsencrypt/</link><description>Recent content in Letsencrypt on Michael’s Domain</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright © 2002 - 2026 Michael Jeltsch.</copyright><lastBuildDate>Fri, 24 Jul 2026 00:18:18 +0300</lastBuildDate><atom:link href="https://jeltsch.org/en/tags/letsencrypt/index.xml" rel="self" type="application/rss+xml"/><item><title>Free digital signing of documents under Linux - an impossibility?</title><link>https://jeltsch.org/en/free_digital_signing_of_documents_under_linux_an_impossibility/</link><pubDate>Sun, 01 Dec 2019 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/free_digital_signing_of_documents_under_linux_an_impossibility/</guid><description>&lt;p&gt;The whole story started when I tried to sign a LibreOffice document. When you belive the internet, document signing is inbuilt into LibreOffice. I still have to find the person that managed to digitally sign a LibreOffice document. This experience shows, that despite 
 &lt;a href="https://en.wikipedia.org/wiki/Edward_Snowden" target="_blank" rel="noopener noreferrer nofollow"&gt;Edward Snowden&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 most people do not proactively care about security and privacy. Debian removed scdaemon from the gnupg2 package and as usual, one needs to be a command line ninja to fix this. The scdaemon gives smartcard support (which I do not have, but without the scdaemon the Kleopatra key manager refuses to run). I am using the default Ubuntu 18.04 installation and it was quite an odyssey to get a document signed. In fact, I still do not have a satisfactory way to do this. However one does it, something&amp;rsquo;s not right. Ubuntu 19.10 has fixed at least the invokation of the key manager from LibreOffice and I can invoke SeaHorse from the document signing dialog, but I still have no clue how to make my gpg keys visible to LibreOffice. Anybody figured this out? Until somebody shows me how to sign with LibreOffice, I use the very good, but proprietary software 
 &lt;a href="https://www.qoppa.com/pdfstudio/" target="_blank" rel="noopener noreferrer nofollow"&gt;PDFStudio&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 to import my GPG keys and sign my PDF files.&lt;strong&gt;Signing services (DocuSign, HelloSign)&lt;/strong&gt; So what do you do if you need to sign e.g. a PDF and you have no means or do not want to subscribe to one of the document-signing certificate service like 
 &lt;a href="https://www.docusign.com/products-and-pricing" target="_blank" rel="noopener noreferrer nofollow"&gt;DocuSign&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
? Even with DocuSign&amp;rsquo;s budget plan a single digital signing costs $2. DocuSign has a 30-day free trial, but I do not know whether the certificats that you generate during the trial with continue to be valid after the end of the trial. HelloSign (
 &lt;a href="https://www.hellosign.com" target="_blank" rel="noopener noreferrer nofollow"&gt;https://www.hellosign.com&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
, now owned by DropBox ) has also a free tier (allowing to sign 3 documents/month) and when signing, it embeds an invisible signature (which was invalid for some strange reason when I tested it even though HelloSign is in Adobe&amp;rsquo;s approved trust list).&lt;strong&gt;Self-signing, cacert and StartSSL&lt;/strong&gt;Technically you can created your own signatures (self-signed certificates), but if such PDFs are viewed with Acrobat Reader, the signature will be flagged as invalid and the fact of self-signing is displayed. There used to be 
 &lt;a href="http://www.cacert.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;http://www.cacert.org/&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
, but to my knowledge, all browsers have removed the CAcert certificates and the same is likely true for Acrobat. StartSSL used to give out free certificates, but they do not exist anymore (they were seriously challenged with their own security).&lt;strong&gt;PDF Viewer support&lt;/strong&gt;Interestingly many PDF Viewers do anyway ignore the signing (e.g. the inbuilt PDF viewer from Firefox does not display anything). Other PDF viewers will display the signature, but NOT indicate, that it is not trusted (e.g. the Chrome Browser&amp;rsquo;s PDF viewer and Ubuntu&amp;rsquo;s default PDF viewer Evince). Since you have no idea what viewer your target will use to display your signed PDF, you are anyway in a bad situation (even if you subscribe to a document signing service). &lt;strong&gt;Letsencrypt&lt;/strong&gt;To increase the trust in the signing, one can use a 
 &lt;a href="https://letsencrypt.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;Letsencrypt&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 certificate for signing. This signature certifies that the author of the document controls a specific website (in my case jeltsch.org). That is more than a self-signed certificate (and if the website is trusted, this is arguably also more than buying a subscription from DocuSign), but the re-purposed Letsencrypt certificate is not being trusted by Adobe since obviously the Letsencrypt endeavor was never meant for document signing (&amp;ldquo;Signer&amp;rsquo;s identity is unknown because it has not been included in your list oif trusted certificates and none of its parent certificates are trusted certificats&amp;rdquo;). However, the maximum lifetime of such a certificate is 3 months, after which it becomes invalid. It can still be used, but it will display that it is not valid because it has expired (or is not valid yet).&lt;strong&gt;How to misuse the Letsencrypt certificate&lt;/strong&gt;First, you need a web server, that uses Letsencrypt certificates to verify the web site identity. This is out-of-scope for this blog post, but there are several good tutorials (e.g. from the 
 &lt;a href="https://letsencrypt.org/getting-started/" target="_blank" rel="noopener noreferrer nofollow"&gt;Let’s Encrypt people themselves&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 or from 
 &lt;a href="https://www.digitalocean.com/community/tutorials/how-to-secure-apache-with-let-s-encrypt-on-ubuntu-18-04" target="_blank" rel="noopener noreferrer nofollow"&gt;Digital Ocean&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
). Once you have your Let&amp;rsquo;s Encrypt certificates, this is the process to &amp;ldquo;misuse&amp;rdquo; them for signing documents:Since Letsencrypt requires certificate renewal every three months, there will be lots of fullchain.pem and privkey.pem files in the same directory and they are numbered. You obviously want to use the newest (the only valid) certificate and perhaps you want to renew the Let&amp;rsquo;s Encrypt certificate immediately before exporting it for document signing:&lt;code&gt;certbot --apache --force-renewal -n -d jeltsch.org&lt;/code&gt; or if you want to renew all certificates: &lt;code&gt;certbot --apache --force-renewal&lt;/code&gt; If you choose to renew all certificates, certbot will try to issue a single certificate for all domains that exist on your server (this possibility did not exist in the beginning of the Letsencrypt ecosystem, but was introduced later). If your server serves more than one domain, you need to manually specify the domain name, for which you want the certificate.For more details about how to use the certbot script, see 
 &lt;a href="https://certbot.eff.org/docs/using.html#certbot-commandsThis" target="_blank" rel="noopener noreferrer nofollow"&gt;https://certbot.eff.org/docs/using.html#certbot-commandsThis&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 is the command, that converts the certs into a PKCS#12 file:&lt;code&gt;openssl pkcs12 -export -out signing_certificat.p12 -in /etc/letsencrypt/archive/website-name/fullchain1.pem -inkey /etc/letsencrypt/archive/website-name/privkey1.pem&lt;/code&gt;The PKCS#12 file stores the certificate and the private key in one encrypted file (with the file extension .p12). Therefore, the command will ask from you a keyphrase, which you absolutely need to remember to be able to use the certificate. Then you can transfer the p12 file to your desktop computer and use it to sign PDF files.&lt;strong&gt;Time stamping servers&lt;/strong&gt;If your PDF application asks for a time stamping server, you can use one of the free services, e.g. ca.signFiles.com/TSAServer.aspx or 
 &lt;a href="http://zeitstempel.dfn.de" target="_blank" rel="noopener noreferrer nofollow"&gt;http://zeitstempel.dfn.de&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. However, also these time stamping services are not trusted by Adobe Acrobat.Here the commands to generate a self-signed certificate (it asks for a (temporary) passphrase, just make up something and remember it, you need it in the second step):&lt;code&gt;openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 3650&lt;/code&gt;Conversion into a signing certificate (it first asks you for the temporary passphrase from above and then for the final passphrase, which you need to remember in order to use the certificate:&lt;code&gt;openssl pkcs12 -export -out signing_certificat.p12 -in cert.pem -inkey key.pem&lt;/code&gt;&lt;/p&gt;</description></item><item><title>OpenBIS for Dummies</title><link>https://jeltsch.org/en/openbis_for_dummies/</link><pubDate>Tue, 06 Sep 2016 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/openbis_for_dummies/</guid><description>&lt;p&gt;If you have considered 
 &lt;a href="https://jeltsch.org/en/tags/eln/"&gt;moving from paper to electronic lab notebooks&lt;/a&gt;
 as we are at the moment, you might have come across the 
 &lt;a href="https://wiki-bsse.ethz.ch/display/bis/Home" target="_blank" rel="noopener noreferrer nofollow"&gt;OpenBIS&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 solution. You want to install OpenBIS, but have not clue how to go about it? I didn&amp;rsquo;t have much of a clue either and therefore tried repeatedly until I succeeded. Luckily, I got some help from the ETHZ OpenBIS and our local computing support team, but obviously they cannot compensate for the lack of insight into Jetty and postgresql…If you just quickly want to try it, it might be easier to download the VirtualBox image, where everything is preinstalled and preconfigured (
 &lt;a href="https://wiki-bsse.ethz.ch/display/bis/openBIS&amp;#43;ELN-LIMS&amp;#43;Virtual&amp;#43;Machine" target="_blank" rel="noopener noreferrer nofollow"&gt;https://wiki-bsse.ethz.ch/display/bis/openBIS+ELN-LIMS+Virtual+Machine&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 ). However, I didn&amp;rsquo;t have any fast hardware to run the VirtualBox image and concluded that it would be fast enough on bare metal using an old computer.The notes below are written from memory and from the final configuration files that worked. However, I will still setup the server from scratch executing only what I have been writing down below in order to make sure I have not missed anything important. However, in the meantime I want to get this information out. I would have been happy if I had found some &amp;ldquo;OpenBIS installation for Dummies&amp;rdquo; instructions. In order to have a very long support, I chose for the installation Ubuntu 16.04 Server (the VirtualBox image uses Ubuntu 14.04 Desktop) and the latest version of 
 &lt;a href="https://wiki-bsse.ethz.ch/display/bis/Production&amp;#43;Releases" target="_blank" rel="noopener noreferrer nofollow"&gt;OpenBIS 16.05.1&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 (you need to apply for an account to be able to download the software). The electronic lab notebook (ELN) plugin comes bundled with that release. Doing that, you have a problem with Java 7 support (it is not going to maintained for long and I will try to run OpenBIS ELN with Java 8 soon, but this walk-through uses a Java 7 PPA for Ubuntu 16.04).1. Do a fresh install of Ubuntu 16.04.1 Server. Create during the install the admin user &amp;ldquo;openbis&amp;rdquo;. When it asks for software selection, choose OpenSSH and Postgresql in addition to standard system utilities. Upon first login (as openbis user), update and upgrade all the software to the latest version and install emacs (or whatever text editor you prefer) and unzip:&lt;code&gt;sudo apt install unzip emacs24-nox&lt;/code&gt;2. Install Java 7. Thi sis just one way how to do it:&lt;code&gt;sudo add-apt-repository ppa:openjdk-r/ppa sudo apt-get updatesudo apt-get install openjdk-7-jre-headless&lt;/code&gt;3. To setup postgresql correctly, change the configuration file /etc/postgres/9.5/main/pg_hba.conf. All lines ending in &lt;strong&gt;peer&lt;/strong&gt;, the &lt;strong&gt;peer&lt;/strong&gt; should be changed into &lt;strong&gt;trust&lt;/strong&gt;! After that, reload postrgresql:&lt;code&gt;sudo systemctl reload postgreql&lt;/code&gt;4. If you are installing to a virtual machine like virtualbox, it would make sense to install the guest utilities as this will make you life easier (virtualbox-guest-utils). Make a shared (permanent, automout folder) and add openbis to the vboxsf group:&lt;code&gt;sudo usermod -a -G vboxsf openbis&lt;/code&gt;4. Place the compressed openBIS installer file into the home directory of the openbis user.5. Untar/gzip the installer:&lt;code&gt;tar -xvzf openBIS-installation-standard-technologies-S233.0-r36799.tar.gz&lt;/code&gt;6. Change into the uncompressed directory:&lt;code&gt;cd openBIS-installation-standard-technologies-S233.0-r36799&lt;/code&gt;7. Change the following things in the console.properties file:&lt;code&gt;INSTALL_PATH=/home/openbis/DSS_ROOT_DIR=/home/openbis/dataELN-LIMS = truePATHINFO_DB_ENABLED = trueINSTALLATION_TYPE = server&lt;/code&gt;For this try I have not changed the password of the keystore, but you should do it for security reasons if you use the server for production!8. Run the installer (not as root, but as openbis user):&lt;code&gt;./run-console.sh&lt;/code&gt;9. When the installer asks to enter the password for the openBIS &amp;lsquo;admin&amp;rsquo; user, type in the password you want to use when logging in as admin into the web interface.10. When installation is done, go to ~/openbis/servers/openBIS-server/jetty/etc and edit the file &lt;strong&gt;service.properties&lt;/strong&gt;. You actually have not to edit anything for the installation to work, but we needed to configure the system for login authentication via Ldap.&lt;code&gt;authentication-service = file-authentication-service =&amp;gt; authentication-service = file-ldap-authentication-service&lt;/code&gt;If you use ldap alone (i.e. authentication-service = ldap-authentication-service), you need to have some special users in the ldap directory. We are authenticating via our university&amp;rsquo;s ldap serer only regular users of the system and hence, e.g. the admin user needs to be authenticated locally. This admin user is setup during the install, but you need to have both file and ldap authentication active for this to work. This is our ldap server address as specified in the service.properties file. It contains the authentication base, which you need to ask from your sysadmins:&lt;code&gt;ldap.server.url = ldap://ldap2015.it.helsinki.fi/OU=people,DC=helsinki,DC=fi&lt;/code&gt;This is the ldap user and his password on the ldap server (don&amp;rsquo;t ask me why the ldap people use such complicated word monster for such a simple concept):&lt;code&gt;ldap.security.principal.distinguished.name = OU=openbis,OU=login,DC=helsinki,DC=fi``ldap.security.principal.password = PASSWORD&lt;/code&gt;The following paramters are specific to our ldap server. We use OpenLDAP and since OpenBIS seems not to support TLS, we use ssl:&lt;code&gt;ldap.security.protocol = ssl``ldap.security.authentication-method = simple``ldap.queryTemplate = (&amp;amp;(%s))&lt;/code&gt;OpenBIS requires https. You can either leave the self-signed certificate (provided by the ETHZ) or install an own certificate. If you keep the self-signed certificate, all users will get a warning when they try to log into the web service. There seems to be an additional problem as the uploading of files seems not to work with the self-signed certificate since the https request via port 8444 doesn&amp;rsquo;t result in an intercept that is presented in the browser window to users to override.Hence we had no choice but to get a real certificate, which is luckily easier today than still one year ago due to the 
 &lt;a href="https://letsencrypt.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;letsencrypt&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 folks. Nevertheless, getting the certificate stuff right took us some time. We are operating the OpenBIS server inside the University network and it is not visible from the outside. Users who want to access it from outside need to use a VPN.Therefore we had to install a temporary &amp;ldquo;fake&amp;rdquo; server with the same name on a publicly reachable IP and generate a letsencrypt certificate (letsencrypt is not yet automated for jetty). I used the automated method for apache2 on my own server at Digital Ocean and then retrieved the two important files (fullchain1.pem and privkey1.pem) from the /etc/letsencrypt/archive/eln.jeltsch.org directory and moved them over to our OpenBIS server. To convert them into the correct format for the java keystore, I used the following commands:&lt;code&gt;openssl pkcs12 -export -out keystore.pkcs12 -in fullchain1.pem -inkey privkey1.pemkeytool -importkeystore -srckeystore keystore.pkcs12 -srcstoretype PKCS12 -destkeystore keystore.jks&lt;/code&gt;The first command asks for an export password. It doesn&amp;rsquo;t matter what you use (I used 12345678). The second command asks for a destination keystore password. Enter here &amp;ldquo;changeit&amp;rdquo; if you have not changed the default keystore password (&amp;ldquo;changeit&amp;rdquo;) during the setup. Then it also asks you for the source keystore password (which is the 12345678 that I just used above).Then you still have to add the contents of this keystore to the already exisiting keystore. There are probably many ways to do this, but I used a graphical tool called 
 &lt;a href="http://www.keystore-explorer.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;Keystore Explorer&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. You simply open both keystores (you need the &amp;ldquo;changeit&amp;rdquo; password for this), you delete the existing entry for ETHZ and add the only (letsencrypt) entry from the newly generated keystore. Replace the files &amp;ldquo;keystore&amp;rdquo; and &amp;ldquo;openBIS.keystore&amp;rdquo; in the directory ~/openbis/servers/openBIS-server/jetty/etc/ with the modified keystore. Both files are identical, I don&amp;rsquo;t know atm the relevance of this duplication. You also have to replace ~/openbis/servers/datastore_server/etc/openBIS.keystore with the new version of the keystore. For some reason, uploading did not work and in order to enable uploading, the service.properties of the datastore server needs to specify the host-address of the datastore server:&lt;code&gt;https://eln needs =&amp;gt; https://eln.jeltsch.org&lt;/code&gt;. Since we used a different host for the certificate generation, there was a host name mismatch and we had to override manually the hostname settings:Change it in the files /etc/hostname and /etc/hosts, then reboot. However, the installer took only the first part of the full name for the service.properties files of the datastore server. Our server&amp;rsquo;s name is eln.jeltsch.org and it resulted in https://eln, which did not resolve in our network, since we got the letsencrypt certificate signed on another server. After we changed the service.properties files and after rebooting we were finally ready to test the server:11. Starting the server: Log into the server as openbis user.&lt;code&gt;cd ~/openbis/bin/./allup.sh&lt;/code&gt;12. On another computer, navigate in your web browser to &amp;ldquo;
 &lt;a href="https://eln.jeltsch.org:8443/openbis/webapp/eln-lims%22" target="_blank" rel="noopener noreferrer nofollow"&gt;https://eln.jeltsch.org:8443/openbis/webapp/eln-lims"&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. If you have not installed a publicly trusted certificate, the browser will now warn you that the connection is not secure. Just click &amp;ldquo;Advanced&amp;rdquo; and confirm the security exception. You need to login as admin/PASSWORD (which you specified during the install).There are some 
 &lt;a href="https://wiki-bsse.ethz.ch/display/openBISDoc/openBIS&amp;#43;ELN-LIMS&amp;#43;Tutorial" target="_blank" rel="noopener noreferrer nofollow"&gt;tutorials&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 on how to use the ELN. However, the people in my lab told me that the UI is not very intuitive and that I need to teach them the basics. I think it might make sense to describe in a tutorial the typical setup in a typical small life science lab: what work spaces with what access rights for whom and to describe common scenarios (e.g. if some reagent lists need to be accessible by outsiders, etc.). I also have many ideas for improvements. It would be e.g nice to get more &amp;ldquo;ELN previews&amp;rdquo; for uploaded documents. At the moment, images are previewable, but e.g. PDF files not (I have not tried SVG files yet, but we use them quite a lot for image annotation). This certainly is not my last post about OpenBIS and until we take it into production use (likely beginning of next year) I still have to learn much.&lt;/p&gt;</description></item></channel></rss>