When requesting a PKIoverheid Server certificate, your Certificate Signing Request (CSR) must meet the current PKIoverheid requirements.
Some software used to generate CSRs still uses an outdated format. This can cause your CSR to be rejected or prevent the certificate from being issued.
My CSR is rejected
Check whether your CSR contains all required fields. For PKIoverheid Server certificates, this includes:
- organizationIdentifier
- Subject Alternative Name (SAN)
Check whether the software you use to generate the CSR supports the current PKIoverheid requirements. If necessary, contact your software provider.
I see the message 'Certificate request is not valid'
In some cases, the CSR is accepted but the certificate cannot subsequently be issued.
In that case, check whether your CSR contains the following fields:
- ST (State or Province), for example South Holland
- L (Locality), for example The Hague
Then submit the new CSR again as part of your certificate request.
What if my software cannot generate the correct CSR?
If your software does not support the required fields, or automatically adds fields that should not be included, contact the provider of the software you use to generate the CSR.
Your CSR must meet the current PKIoverheid requirements before Digidentity can issue the certificate.