<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=222868361777687&amp;ev=PageView&amp;noscript=1">
Skip to content
English
  • There are no suggestions because the search field is empty.

How to request a Peppol certificate with a CSR

With CSR-based enrollment, you generate the private key yourself and submit only the certificate signing request (CSR) to OpenPeppol. The private key never leaves your environment. You then download the signed certificate from the DigiCert enrollment portal.

You need OpenSSL and access to the OpenPeppol Service Desk. The whole process takes three stages: generate the CSR, submit it, and complete the enrollment within 10 days of receiving the credentials.

Before you start

  • Test certificates require a signed Peppol Service Provider Agreement and a business registration extract that is less than three months old.
  • Production certificates also require that you have no outstanding OpenPeppol fees and have passed the relevant test suite in the Peppol Testbed.

Generate the CSR

Step 1. Generate a password-protected 2048-bit RSA private key. OpenPeppol requires RSA 2048.

openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 \
  -aes256 -out ~/peppol-signing-key.pem

Step 2. Create the CSR. Leave the subject empty, since the Certificate Authority sets the subject, SAN and extension values based on your Service Provider details.

openssl req -new -sha256 \
  -key ~/peppol-signing-key.pem \
  -out ~/peppol-signing.csr \
  -subj "/"

Step 3. Verify the CSR.

openssl req -in ~/peppol-signing.csr -text -noout

Store the private key and its password securely. You need them to install the signed certificate.

Submit the CSR

  1. Log in to openpeppol.atlassian.net and create a certificate request in the OpenPeppol Service Desk.
  2. Select the certificate purpose (TEST or PROD), the certificate type (AP or SMP), the certificate version (G3) and the enrollment method (CSR-based).
  3. Wait for the enrollment credentials, which are sent by email and SMS once the request has been processed.
  4. Log in to the DigiCert enrollment portal with the credentials, paste the full content of ~/peppol-signing.csr and download the signed certificate (PKCS#7).
  5. Complete the enrollment within 10 days of receiving the credentials. After that, the enrollment code expires.

Repeat the process for each certificate you need, for example one Access Point certificate for TEST and one for PROD.

After you have the certificate

Agree with your Qvalia contact on how the signed certificate and the private key are installed on your hosted Access Point. Never send the private key or its password by email.

If it still does not work

  • If the enrollment code has expired, request a new one through the OpenPeppol Service Desk. If you have lost the private key or its password, you must generate a new CSR and request a new certificate.
  • Check that the CSR contains a 2048-bit RSA key with openssl req -in ~/peppol-signing.csr -text -noout, and that you selected G3 and the right purpose and type in the request.
  • For questions about the request or the enrollment, contact the OpenPeppol Service Desk. For installation on your hosted Access Point, contact your Qvalia partner manager, or reach Qvalia Support via qvalia.com/contact-support.