A PKIoverheid Server certificate is used to verify the identity of a server and secure communication between systems.
Before you can request a Server certificate, you must first register for Digidentity Certificate Manager.
Follow these steps:
- Start the registration for Digidentity Certificate Manager .
- Complete the full product registration.
- Once completed, log in to the Self Service Portal .
- Select your organisation.
- Select Certificates.
- Select Request new certificate.
- Select the required PKIoverheid Private Server Certificate.
Register for Digidentity Certificate Manager
During the registration, Digidentity will verify your identity, organisation and authorisation to act on behalf of the organisation.
If additional authorisation is required, authorisation letters will automatically be generated. These letters must be signed and submitted according to the instructions provided on the letter.
More information: Tips for submitting authorisation letters .
Once your Certificate Manager registration has been fully completed, you can request a Server certificate through the Self Service Portal.
Request a PKIoverheid Server certificate
After selecting the Server certificate in the Self Service Portal, complete the required certificate details.
- Enter the domain name for the certificate.
- Select whether the certificate should use a KvK number or OIN number.
- Complete the domain validation. A verification code will be sent to the specified email address.
- Enter the required certificate details. You can add up to 10 names.
- Review the details and costs and complete the required checks.
- Confirm the request and generate the certificate.
You can let Digidentity generate the Certificate Signing Request (CSR) or provide your own CSR.
Important
Store the certificate and associated private key securely after generating and downloading them.
If the required certificate files or private key are lost, you may need to request a new certificate.
Using your own Certificate Signing Request (CSR)
Advanced users can provide their own Certificate Signing Request (CSR) instead of having one generated by Digidentity.
Your CSR must meet the current PKIoverheid requirements. In particular, check that the required organizationIdentifier and Subject Alternative Name (SAN) values are included.
Important
Digidentity cannot provide support with generating or configuring your own CSR.
If your CSR is rejected or you receive the message “Certificate request is not valid”, check that the CSR meets the current PKIoverheid requirements before submitting it again.
Install the certificate
Once generated, the Server certificate can be installed in the server, application or system for which it was requested.
Digidentity does not provide support for installing or configuring PKIoverheid certificates in third-party systems. Please contact your system administrator or software provider if you need assistance with the implementation.
Validity and expiry dates
The Digidentity Certificate Manager registration and the PKIoverheid Server certificate are separate components and may have different expiry dates. You will receive separate notifications for each.
More information about PKIoverheid certificates can be found in our PKIo Certificates Help Centre .