Manage organisation certificates

As a user administrator, you can order, renew, and revoke an organisation and system certificate.

This page is relevant for:

  • user administrator

If you do not know which role you have in MitID Erhverv, you can log in to MitID Erhverv and check your own profile. You can find the roles you have under “Master data”.

Organisation administrator is responsible for modifying the organisation’s certificate settings. You can find the relevant guides here:

Modify the organisation’s certificate settings

Rights administrators can view the settings of each certificate.

If you are not a user administrator, but would like to order an organisation or system certificate for your organisation, you should contact your user administrator.

You can contact MitID Erhverv Support to obtain the name of the user administrator in your organisation.

Contact

What is an organisation certificate?

You can find general information about organisation certificates here:

Certificates

How to manage organisation certificates?

Find the topic you need guides on below and tap it to access the relevant guide.

You can:

Order an organisation certificate

Before you begin ordering an organisation certificate, ensure you have the following:

  • You have the role of user administrator in MitID Erhverv.
  • You know which organisation or system certificate you need.
  • The organisation administrator has allowed the use of organisation certificates under “Settings” in MitID Erhverv.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates": Menu > Certificates.

To order an organisation certificate, you must first create a certificate profile. A certificate profile includes the following 6 details:

  • Name of certificate profile/certificate.
  • Email address in the certificate.
  • Name of contact person for the certificate.
  • Email address for the contact person.
  • System rights assigned to the certificates.
  • Seal generation: Specify whether the certificates can be used to sign on behalf of the organisation (applicable only if your organisation allows seal generation).

These 6 details will be specified in steps 4-6.

Certificates created under the same certificate profile will have identical details. There may be one or more certificates linked to a certificate profile.

If your organisation has up to 8 certificates in MitID Erhverv, the "Create certificate profile" option is located after the last certificate profile.
If your organisation has 9 users or more, the "Create certificate profile" button is located above the list of certificate profiles.

After tapping "Create certificate profile", the “Order certificate profile” window will appear.

There are 2 mandatory fields:

  • Certificate profile and certificate name: You must assign a name to the certificate that is easy for you to distinguish from other organisation certificates, e.g. use a name that indicates the certificate’s purpose within your organisation.
  • EAN number for invoicing: This field only appears when organisations using invoicing via NemHandel (EAN). If your organisation has registered only one EAN number, it will be pre-filled. If your organisation has multiple EAN numbers, select the appropriate EAN number from the drop-down menu.

There are 5 optional fields:

  • Email address in certificate: If you enter an email address in the field, it must be validated. This can be done by following the link in the email sent to the provided address after completing the order. Without email validation, you cannot issue the organisation certificate. The email address must not contain the characters Æ, Ø, or Å, otherwise the certificate will not function.
  • Name of contact person.
  • Email address of contact person: It is recommended to fill in this field so you receive a notification before the certificate expires. The email address must not contain the characters Æ, Ø, or Å, otherwise the certificate will not function.
  • P number: If your organisation has multiple P numbers and needs to register the certificate under the correct P number, you can select the appropriate one from the drop-down menu.
  • SE number: If your organisation has multiple SE numbers and needs to register the certificate under the correct SE number, you can select the appropriate one from drop-down menu.

Note that the fields for P number and SE number only appear if your organisation has multiple P numbers or SE numbers.

This menu only appears when the organisation has activated Local IdP.

To access services in MitID Erhverv via the API interface, a system certificate is required. You must add system rights to the certificate to use these services.

There are 2 services in MitID Erhverv available:

  • IdM (Identity Management) services: Used for creating and managing users from the organisation's own system, for example, an identity management system.
  • Certificate services: Used for ordering, issuing, and revokeing certificates.

For detailed instructions on using the API for MitID Erhverv, refer to this documentation:

Local IdM

Organisation certificates can also be used to generate a seal for the organisation. Seal generation works like a personal signature, but for a company or organisation. Just as an individual uses their signature to approve documents, the seal is used by the organisation to, for example, authorise or confirm official documents. Tick the box if the certificate should be used to create a seal for the organisation.

This field only appears if your organisation allows seal generation. An organisation administrator decides this under Settings.

In the drop-down menu “Types of certificates”, choose whether you want an:

  • OCES organisation certificate
  • OCES system certificate

When ordering a certificate, the user who will use it must verify their identity to ensure it is issued to the correct person.

From the drop-down menu “Method of identification”, choose how the person who will issue and download the certificate will verify their identity:

  • User login: If you select user login as the identification method, you will also be prompted if you would like to proceed directly to the issuing process after completing the order. If you would like to do so, tick the box “Yes, go directly to issuance”.
  • Identification via API.

The most common method is "User login", which all organisations can use. If you select "User login", the user will receive an email with a link that they must follow to log in with own MitID Erhverv.

If your organisation's IdM (Identity Management) system is integrated with MitID Erhverv via API, you can choose for the system to verify the user’s identity, enabling it to issue and renew certificates automatically.

For a comprehensive guide on API integration, refer to this documentation:

Local IdM

You decide how to issue the certificate. Depending on the identification method you selected in step 8, different options will appear in the drop down menu “Issuing Methods”.

If you selected “User login” as the identification method in step 8, you will have the following 2 options:

  • Internet Browser: The user issues the certificate directly through the browser, and it will be installed or saved on the computer.
  • Hardware.

If you selected Identification via API as the identification method in step 8, the following method will be pre-selected. This choice cannot be changed:

  • System (EST API)

Tick the box under “Publishing certificate” if the certificate should be added to the public certificate database.

Once you have completed the relevant fields and are ready to create the certificate profile and order the certificate, tap "Create Certificate Profile and Order Certificate".

The "Confirm certificate order" window, which summarises your order, will be displayed.

Check the details and tap "Confirm order".

If you chose to issue the certificate directly, proceed straight to step 14.

If you did not choose to go to the issuing process, proceed to step 13.

A receipt for your order will be displayed.

You can now issue and download the certificate via one of the 2 following methods:

  • Email, which you will receive from MitID Erhverv.
  • A notification in MitID Erhverv.

You can use one of the following 2 guides:

Issue and download an organisation certificate via email

Issue and download an organisation certificate via notification in MitID Erhverv

A receipt for your order will be displayed.

Tap "Issue certificate".

You will then be logged out of MitID Erhverv, and the login page will appear.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Once logged in, the "Issue Your Certificate" page will be displayed. Tap "Next".

The "Terms & conditions" page will be displayed. Tick the box "Yes, I accept terms and condition". The "Next" button will then become active, and you should tap it.

The "Password to Your Certificate" page will be displayed.

The password is masked with black dots. You must tap "Show" to view the password.

Make sure to note the displayed password.

Alternatively, you can tap "Copy to clipboard". This will allow you to copy the password.

Store the password securely.

Finally, tap "Next".

The certificate is now ready for issuance. The download of the certificate will start automatically.

If the download does not start automatically, you can tap "Download certificate".

Once the certificate is downloaded, tap “Close”.

Issue and download an organisation certificate via email

If you have not chosen to issue the certificate immediately after placing the order, you will receive an email with the subject "Download an organisation certificate" or "Download a system certificate".

You can download the certificate to your computer by following the link in the email. You will be redirected to the MitID Erhverv login page.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Once logged into MitID Erhverv, you can tap "Next".

The "Terms and conditions" page will be displayed. You accept the terms by ticking the box "Yes, I accept terms and conditions". The "Next" button will then become active, and you should tap it.

The "Password to Your Certificate" page will be displayed.

The password is masked with black dots. You need to click "Show" to view the password.

Make sure to note the displayed password.

Alternatively, you can tap "Copy to clipboard", which will allow you to copy the password.

Store the password securely.

Finally, tap "Next".

The certificate is now ready for issuance. The certificate download will start automatically.

If the download does not start automatically, you can tap "Download certificate".

Once the certificate is downloaded, you can tap "Close".

Issue and download a certificate via notification in MitID Erhverv

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

You can find notifications next to your name at the top of the page.

If you did not choose to issue the certificate immediately after placing an order, you will receive a notification in MitID Erhverv with the subject "Download an organisation certificate" or "Download a system certificate".

The "Terms and conditions" page will be displayed. You accept the terms by ticking the box "Yes, I accept the terms". The "Next" button will then become active, and you should tap it.

The "Password to your certificate" page will be displayed.

The password is masked with black dots. You need to tap "Show" to view the password.

Alternatively, you can tap "Copy to clipboard," which allows you to copy the password.

Store the password securely.

Finally, tap "Next".

The certificate is now ready for issuance. The download of the certificate will start automatically. If the download does not start automatically, you can press "Download certificate". Once the certificate is downloaded, you can select "Close".

Renew an organisation certificate

Your organisation certificate is valid for 3 years, but it can be renewed.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates": Menu > Certificates.

You can view the list of certificate profiles your organisation has. A certificate profile includes the following details:

  • Name of certificate profile/certificate.
  • Email address in the certificate.
  • Name of contact person for the certificate.
  • Email address for the contact person.
  • System rights assigned to the certificates.
  • Seal generation: Specify whether the certificates can be used to sign on behalf of the organisation (applicable only if your organisation allows seal generation).

Certificates created under the same certificate profile will have identical details. There may be one or more certificates linked to a certificate profile.

You should identify the required certificate profile by:

  • name
  • email address
  • status

If your organisation has 9 certificate profiles or more, you can search using:

  • name
  • email address
  • contact person

You can select a certificate profile in 2 ways:

  • Tap the certificate profile name.
  • Tap the three dots next to the certificate profile and choose "Edit certificate profile" in the menu.

The certificate profile window will then appear.

The “Certificates” menu is located just above the "Close" button at the bottom of the "Certificate profile" window.

Once you select "Certificates", locate the certificate(s) listed under the certificate profile.

Once you locate the certificate you would like to renew, tap the three dots next to the certificate name.

A menu will appear. Select “Renew certificate”.

The “Renew certificate” window will then appear.

The “Renew certificate” window contains details such as:

  • certificate type and price
  • identification method
  • proceed directly to issuance

If the information displayed is correct, tap the “Renew” button at the bottom.

If “Proceed directly to issuance” is stated as “Yes”, you will be directed to the issuance step. Follow from step 13 in the guide “Create an organisation certificate” above.

If not, you will return to the "Certificates" menu in the "Certificate profile" window, where you can find a new certificate marked as “Pending”.

Revoke an organisation certificate

You can revoke an organisation certificate if:

  • the organisation no longer exists
  • there is suspected misuse, e.g. as in the case of a stolen computer
  • the certificate information is no longer correct, e.g. due to a name change.

Please note that once a certificate has been revoked, it cannot be reactivated. Instead, you must need to order a new certificate.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates" list: Menu > Certificates.

You can view the list of certificate profiles associated with your organisation. A certificate profile includes the following details:

  • Name of certificate profile/certificate.
  • Email address in the certificate.
  • Name of contact person for the certificate.
  • Email address for the contact person.
  • System rights assigned to the certificates.
  • Seal generation: Specify whether the certificates can be used to sign on behalf of the organisation (applicable only if your organisation allows seal generation).

Certificates created under the same certificate profile will have identical details. There may be one or more certificates linked to a certificate profile.

If your organisation has 9 certificate profiles or more, you can search using:

  • name
  • email address
  • Contact person
  • UUID

You can select a certificate profile in 2 ways:

  • Tap on the name of the certificate profile.
  • Tap the three dots next to the certificate profile and choose choose "Edit certificate profile" from the menu.

The certificate profile window will appear.

The “Certificates” menu is located just above the “Close” button at the bottom of the “Certificate profile” window.

Once you select “Certificates”, locate the certificate(s) listed under the certificate profile.

When you locate the certificate you want to revoke, find the three dots next to the certificate’s name.

A menu will appear. Select “Revoke”.

The “Delete certificate profile” window will appear.

The “Delete certificate profile” window will warn you that you are about to revoke a certificate. Tap the “OK” button at the bottom of the window. You will then return to the “Certificates” menu in the “Certificate profile” window, where the certificate will now be marked as “Revoked”.

Please note that a certificate cannot be reactivated once it has been revoked, but you can always order a new certificate.

Delete an organisation certificate order

You can only delete an organisation certificate order before the certificate is issued. If you need to delete a certificate that has already been issued, refer to the guide on revoking an organisation certificate.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates" list: Menu > Certificates.

You can view the list of certificate profiles your organisation has. Locate the certificate profile you need based on name, email address, or status.

If your organisation has 9 certificate profiles or more, you can search by:

  • name
  • email address
  • contact person
  • UUID

You can select a certificate profile in the following two ways:

  • Tap the name of the certificate profile.
  • Tap the three dots next to the certificate profile, then choose "Edit certificate profile" from the menu.

The certificate profile window will appear.

The “Certificates” menu is located just above the “Close” button at the bottom of the “Certificate profile” window. Once you select “Certificates”, locate the certificate(s) listed under the certificate profile.

Find the certificate for which you would like to delete the order. The certificate status should be “Pending” You will find three dots at the end of the line where the certificate’s name is displayed.

Tap the three dots to open the menu, then select "Delete certificate".

The “Delete certificate order” window will appear.

The “Delete certificate order” window will warn you that you are about to delete the order for a certificate. Select "OK" to confirm. The certificate will then be now deleted.

The certificate will be removed under the “Certificates” menu in the “Certificate profiles” window.

View the list of your organisation’s certificates

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find: Menu > Certificates. Here, you will find an overview of the organisation’s certificate profiles.

Organisation certificates can be found under each certificate profile.

Modify master data of an organisation certificate

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates": Menu > Certificates.

You can view the list of certificate profiles that your organisation has. A certificate profile includes the following details:

  • Name of certificate profile/certificate.
  • Email address in the certificate.
  • Name of contact person for the certificate.
  • Email address for the contact person.
  • System rights assigned to the certificates.
  • Seal generation: Specify whether the certificates can be used to sign on behalf of the organisation (applicable only if your organisation allows seal generation).

Certificates created under the same certificate profile will have identical details. There may be one or more certificates linked to a certificate profile.

You should identify the required certificate profile by:

  • name
  • email address
  • status

If your organisation has 9 certificate profiles or more, you can search using:

  • name
  • email address
  • contact person
  • UUID

You can select a certificate profile in 2 ways:

  • Tap the name of the certificate profile.
  • Tap the three dots next to the certificate profile and choose "Edit certificate profile" in the menu.

The certificate profile window will then appear.

The “Edit” option is located at the top of the "Master data" menu at the top of the certificate profile window.

Tapping “Edit” will allow you to modify the “Master data” fields.

You can modify the following information:

  • Name of the certificate profile.
  • Email address in the certificate — optional field.
  • Name of the contact person for the certificate — optional field.
  • Email address for the contact person — optional field.

If your organisation has selected NemHandel (EAN), you can also edit the following information:

  • P number — optional field.
  • SE number — optional field.
  • EAN number for invoicing — optional field.

To save your recent changes made to the certificate profile’s master data, tap the “Update” button.

Modify system rights of an organisation certificate

This applies only if you have activated a Local IdP.

The organisation certificate’s system rights are access to:

  • IdM services in MitID Erhverv: IdM (Identity Management) services, allowing your organisation to create and manage users directly from your own system, such as an Identity Management system.
  • certificate management: Provides services for ordering, issuing, and revokeing certificates.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates": Menu > Certificates.

You can view the list of certificate profiles that your organisation has. A certificate profile includes the following 6 details:

  • Name of certificate profile/certificate.
  • Email address in the certificate.
  • Name of contact person for the certificate.
  • Email address for the contact person.
  • System rights assigned to the certificates.
  • Seal generation: Specify whether the certificates can be used to sign on behalf of the organisation (applicable only if your organisation allows seal generation).

Certificates created under the same certificate profile will have identical details. There may be one or more certificates linked to a certificate profile.

You should identify the required certificate profile by:

  • name
  • email address
  • status

If your organisation has 9 certificate profiles or more, you can search using:

  • name
  • email address
  • contact person
  • UUID

You can select a certificate profile in 2 ways:

  • Tap the certificate profile name.
  • Tap the three dots next to the certificate profile and then choose "Edit certificate profile" in the menu.

The certificate profile information window will then appear.

The “System Rights” menu is located just below the “Master data” menu.

Tap “System Rights” to expand and display its options.

Under “System Rights,” you can tick whether the certificate should provide access to:

  • IdM services in MitID Erhverv
  • handling certificates.

Your changes are automatically saved in MitID Erhverv, and a confirmation of the update will appear.

Note that you must create a new certificate that includes the changes you have made. This can be done under the “Certificates” menu, where you can tap the “Order new certificate” button.

Modify seal generation settings for an organisation certificate

Seal generation works like a personal signature, but for a company or organisation. Just as an individual uses their signature to approve documents, the seal is used by the organisation to, for example, authorise or confirm official documents.

Please note that you cannot modify seal generation settings if your organisation does not allows seal generation using certificates. The organisation administrator must enable seal generation.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find the "Certificates" list: Menu > Certificates.

You can view the list of certificate profiles your organisation has. A certificate profile includes the following details:

  • Name of certificate profile/certificate.
  • Email address in the certificate.
  • Name of contact person for the certificate.
  • Email address for the contact person.
  • System rights assigned to the certificates.
  • Seal generation: Specify whether the certificates can be used to sign on behalf of the organisation (applicable only if your organisation allows seal generation).

Certificates created under the same certificate profile will have identical details. There may be one or more certificates linked to a certificate profile.

You should identify the required certificate profile by:

  • name
  • email address
  • status

If your organisation has 9 certificate profiles or more, you can search using:

  • name
  • email address
  • contact person

You can select a certificate profile in 2 ways:

  • Tap the certificate profile name.
  • Tap the three dots next to the certificate profile and choose "Edit certificate profile" in the menu.

The certificate profile window will then appear.

When you tap the “Seal generation” menu, it will expand. You can now view whether the certificate may be used to create a seal for the organisation.

Tick or untick the box labelled “Certificate profile may be used to create seal for the organisation”.

Your change is automatically saved in MitID Erhverv, and a confirmation of the update will appear.

Please note that you will need to create a new certificate that reflects the change you made. This can be done under the “Certificates” menu by selecting the “Order new certificate” button.

Export the list of organisation certificates your organisation has

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates": Menu > Certificates.

Tap the “Export certificate profiles” button above your organisation’s certificate profiles. You can now download the list in CSV format.

Search in the list of organisation certificates your organisation has

If your organisation has 9 certificate profiles or more, you can search through the profiles to find the organisation certificate you are looking for.

You can view the list of certificate profiles your organisation has. A certificate profile includes the following 6 details:

  • Name of certificate profile/certificate.
  • Email address in the certificate.
  • Name of contact person for the certificate.
  • Email address for the contact person.
  • System rights assigned to the certificates.
  • Seal generation: Specify whether the certificates can be used to sign on behalf of the organisation (applicable only if your organisation allows seal generation).

Certificates created under the same certificate profile will have identical details. There may be one or more certificates linked to a certificate profile.

You need to enter your MitID user ID. Then, approve the login using your authenticator.

MitID Erhverv: Login

Find "Certificates": Menu > Certificates.

When entering search terms in the “Search in certificate profiles” field, you can use terms, for example:

  • name of the certificate profile/certificate
  • UUID
  • name of the contact person for the certificate
  • email address for the contact person
  • email address in the certificate.

Tap “Search”.

A list of certificate profiles that match you search term will appear. You ca identify the certificate profile containing the certificate you are looking for by:

  • name of the certificate profile
  • status for certificate, e.g., pending, active
  • email address in the certificate
  • name of the contact person
  • email address for the contact person.

The certificate profile window will then appear.

The “Certificates” menu is located just above “Complete” button at the bottom of the “Certificate profile” window.

Once “Certificates” is selected, locate the certificate(s) under the certificate profile.

Related topics