Transition to new CA and new certificates
During Q3 this year, Commfides will launch a new Root CA and thus new certificates with new certificate profiles. We do this for several reasons, but the most important reason is that the regulations we follow are updated and we move to stronger encryption in our certificates.
Background
We are now moving from the national certificate profiles SEID v.1.0 to the new updated certificate profiles SEID v.2.0, which are in line with the common European standard and law, called the eIDAS regulation for trust services. The background for the change is to increase confidence in digital transactions within the EU and create a common basis for securing digital interactions, so that everyday life becomes easier.
What are the benefits for you?
The benefits are several, but mainly this will contribute to:
-
- Increased security with stronger cryptography
- Better interoperability for the use of Commfide’s e-ID throughout Europe
- Standardization in accordance with common European regulations
What do you need to do?
Commfides Business Certificate, Employee e-ID and Private e-ID issued from existing CA are active until June 1, 2022. All businesses that handle digital transactions with e-ID certificates must make technical changes to the systems. We recommend everyone to start preparing well in advance. In Q3 in 2021, our new test and production certificates holding the new SEID 2.0 profile will be available. Contact Commfides and ask to receive new certificates so that you can get started with the technical preparations.
The end user of Business Certificate, Employee e-ID and Private e-ID does not need to do anything for this transition. Our customers who have received e-ID certificates with SEID v.1.0 profile, can use their e-ID throughout their lifetime.
Timeline
Commfides will have a transition period from Q3 this year until June 1, 2022 where we will issue Business Certificates, Employee e-ID and Private e-ID from both existing CA and new CA. E-ID certificates issued on existing CAs will continue to live after this date and until their expiration date
Technical preparations
For anyone handling digital transactions with e-ID certificates, it is important to prepare the technical systems for changes in the certificate profiles.
Once you have received new test and production certificates from Commfides, you can look at the following:
-
-
- Add new CRL and OCSP links to check validity on Business Certificates:
-
CRL – http://crl.commfides.com
OCSP – http://ocsp.commfides.com
The CRL and OCSP services operate from Q3
-
-
- Add new Root CA and intermediate SubCA Public Root
-
Link coming in July
-
-
- Update new OIDs in the certificate checking system, if enabled
-
Examples of OIDs are coming
-
-
- Check that the new fields in the Business Certificates are read and that they are read correctly
-
Examples of fields are coming
-
-
- Perform a test to check if the Business Certificates work as expected in both the test and production system
-
Do you want to know more?
This page is continuously updated with dates and more information about the certificate profiles.