As the root certificate “Root SK” of the Sertifitseerimiskeskus expires in summer 2016, it will not be possible to issue 5-year ID-card certificates from the certification chain starting from this summer. Due to this SK has to implement a new certification chain.
This change will have an impact on all systems using ID-card, Digi-ID and Mobile-ID certificates or in other words all information systems and applications, where it is possible to authenticate and provide a digital signature with an ID-card, Digi-ID or Mobile-ID. Also all information systems, where it is possible to verify the validity of digital signatures.
All new certificates are available on the webpage of the SK and it is possible to make all necessary configurations in information systems in advance.
The first ID-card/Digi-ID/Mobile-ID identification certificates will be issued from the new certification chain July 11, 2011.
In case the new certificates have not been added in the configuration of the system, persons, whose ID-card/Digi-ID card or Mobile-ID certificates have been issued after implementation of the changes or who have updated their ID-cards after implementation of the changes, cannot authenticate in a relevant e-service. Besides, it is not possible to verify the digital signatures given by these persons after implementation of the changes.
Compared to the current certificates there are some changes made in the new certificates. It is important to check that the new certificates are compatible with your information system.
The description of the existing certification chain of SK is here and the description of the new certification chain is here.
If earlier some systems (for instance Microsoft Windows certification storage) were provided with the root-SK certificate automatically, then in addition to the service certificates and validity confirmation certificates also the new root certificate (EE Certification Centre Root CA) must be set manually in the system.
To provide you with a possibility to test the impact of changes made in the certificates in your service, you can order test cards with new certificates from SK. To order test cards please fill in the form on the webpage of the SK.
All certificates of the Certification Centre can be downloaded here http://www.sk.ee/en/repository/certs/
IN ADDITION to the support of existing certificates the support of all new certificates must be added in all web servers meant for personal identification with an ID-card and application servers using ID-card authentication.
New certificates must be added in the list of accepted certificates and to set the validity control of certificates issued by new certification applications, use the validity confirmation service (OCSP) of the SK or revocation list (CRL) service.
In the case of both certifiers – “ESTEID-SK 2011” as well as “EID-SK 2011” the answers to the inquiries regarding validity control of the certificates issued by these certifiers must be verified with the “SK OCSP RESPONDER 2011“ certificate. For the sample configuration, including all required additions related to the new certificates, please see OCSP PHP sample client application on http://www.id.ee/?id=10736
In addition the new certificates must be set for other systems that use the certificates of the ID-card (VPN-clients, log-in solutions to the computer network).
Users who use DigiDoc libraries in digital signing applications must add all new certificates in the configuration files of DigiDoc libraries.
The packages of DigiDoc libraries with new certificates are available on http://www.id.ee/28729
The users of a DigiDoc COM library can get an updated library in their user computer by downloading the DigiDoc Client version 2.7.11 of the Certification Centre, which is available on http://installer.id.ee from the beginning of May.
SK will add new certificates to the DigiDocService web server itself and thus the users of DigiDocService must make no changes in their communication system.
In order to give a digital signature with new certificates with DigiDoc client software and to verify the digital signatures given with new certificates it is needed to update the ID-card basic software in the computer of the end user.
The basic software version 3.4 of the ID-card supporting the new certificates is available on the address https://installer.id.ee from May 9th.
Please send all additional questions regarding the changes on e-mail address support[at]sk.ee.
Viimati uuendatud: 22.06.2011