Skip to main content

Order your PKIo Private Services Server Certificate

A PKIo Private Services Server Certificate is a PKIoverheid, EU non-qualified certificate issued to an organisation for server authentication and encryption (OVCP + PTC).

The PKIo Private Services Server certificate is available in DigiCert's European instance of CertCentral, where we store your data in our Europe datacenters. To learn more about DigiCert privacy policy and data collection, see our PKIoverheid products article.

Before you begin

This section outlines some things you may want to consider or tasks to finish before ordering your PKIo Private Services Server Certificate. For example, you may want to learn more about using a DigiCert-provided domain. Or you may way want to generate a certificate signing request (CSR).

CSR requirement

Before DigiCert can issue your PKIo Private Services Server certificate, you must provide a CSR. You can include a CSR with your request. Or, when DigiCert finishes processing your order, and is ready to issue your certificate, you can generate the CSR in the browser.

Our PKIo Private Services Server Certificate supports the Rivest-Shamir-Adleman (RSA) algorithm and 2048 key length. This certificate doesn't support the Elliptic Curve Cryptography (ECC) algorithm.

  • Include a CSR with your request

    Generate the CSR before you order the certificate. For your certificates to remain secure, it must use a 2048-bit key size. Learn how to create a CSR (certificate signing request).

  • Generate the CSR later via the browser

    To generate the CSR via the browser, submit your certificate request. When your certificate is ready, DigiCert sends the certificate requester instructions for generating the CSR and certificate via their browser. See the Getting your PKIo Private Services Server Certificate section of these instructions.

Domain validation

Before DigiCert issues your certificate, you must demonstrate control over the domains on the certificate order. Use one of the following domain validation options to demonstrate control over the domains:

Using a DigiCert controlled domain—qvtl.nl

DigiCert recommends using your own domain in the Subject.CommonName field of your PKIo Private Services Server Certificate. However, if company policy allows it, you can use a DigiCert-controlled domain instead. With a PKIo Private Services Server certificate, the Subject.Serialnumber is the important certificate content, not the domain name. To use a DigiCert-owned domain, we validate your organization and authorize it to use the DigiCert-provided domain name, qvtl.nl.

Organization validation

Before DigiCert can issue your certificate, we must validate the organization. Organization validation is valid for approximately 13 months. To learn more about organization validation, see How do we validate your organization.

Adding a new organization or an organization with expired validation requires DigiCert to revalidate the organization as part of the order process.

Order your PKIo Private Services Server certificate

  1. In CertCentral, in the left menu, go to Request a Certificate > PKIOVERHEID > PKIo Private Services Server Certificate.

  2. On the Request PKIo Private Services Server Certificate page, in the For menu, select the division to manage the certificate.

    The For menu appears if using Divisions in CertCentral.

  3. Add your CSR

    You may add your CSR now or generate it in your browser when DigiCert finishes processing your order and is ready to issue it.

    1. Generate the CSR in the browser

      To generate the CSR and your certificate via the browser, select Generate CSR in the browser.

      For this option, we send instructions to the certificate requester for using the DigiCert KeyGen tool to generate the CSR and certificate in their browser.

    2. I have my CSR

      To include a CSR, you must add it while placing your request. You can't add or update a CSR afterward.

      Your CSR must use the RSA algorithm, as the ECC algorithm is unsupported. For certificates to remain secure, the CSR must use a 2048-bit key.

      1. To include a CSR with your request, select I have my CSR.

      2. Upload or enter your CSR in the box.

        Your CSR must include the -----BEGIN NEW CERTIFICATE REQUEST----- and -----END NEW CERTIFICATE REQUEST----- tags.

        We use the information in your CSR to auto-populate corresponding values in the order form: Common Name, SANs, and Organization. If you leave any of this information out of the CSR, the corresponding field in the form is left blank.

        If using an organization from your CertCentral account, we auto-populate the Organization Contact card using the contact assigned to that organization.

  4. Common name and subject alternative names (SANs)

    CertCentral uses the data in the CSR to auto-populate the Common name and SANs boxes on the request form. You can update the common name, reorder, add, a remove SANs as needed.

    Note: The PKIo Private Services Server Certificate supports fully qualified domain names. You can’t include a wildcard domain or IP address in your certificate.

    1. Use a DigiCert-controlled domain—qvtl.nl

      If company policy allows it, you can use a DigiCert-controlled domain name instead. With a PKIo Private Services Server certificate, the Subject.Serialnumber is the important certificate content, not the domain name.

      To use a DigiCert-controlled domain, select Use a DigiCert qvtl.nl domain.

      DigiCert validates your organization and authorizes it to use the DigiCert-provided domain name, {organisation_name}.qvtl.nl.

  5. Validity period (optional)

    Select a validity period for the certificate:

    • 1 year, 2 years, or 3 years

    • Custom expiration date

      The expiration date must be within 1095 days of the date you request the certificate.

    • Custom length

      The maximum length allowed is 1095 days.

  6. Domain control validation (DCV)

    Using a DigiCert-controlled domain? You can skip this step. DigiCert handles the domain validation by validating your organization and authorizing it to use the DigiCert-provided domain name. You can't validate a domain you don't control.

    Before DigiCert issues your certificate, you must demonstrate control over the domains included in your certificate. While placing the order, you must select one DCV method for all domains on the order.

    Afterward, on the certificate's pending Order # details page, we show you the domains that need validating. You can use the selected DCV method or a different one for each domain if needed.

    1. DCV method

      Use the default DCV method. Or, in the DCV method menu, select your preferred DCV method to demonstrate control over the domains.

      DigiCert-supported DCV methods:

      • DNS TXT Record (DNS Change)

        To validate the domain, add a DigiCert-generated random value to the domain's DNS as a TXT record.

        Note: You need permissions to modify the domain's DNS (Domain Name System) record to include a TXT record and add the DigiCert-generated random value

      • Using the Verification Email DCV methods

        DigiCert sends two sets of DCV emails for this validation method: DNS TXT-based and constructed. To demonstrate control over the domain, an email recipient follows the instructions in a confirmation email sent for the domain.

        • Email to DNS TXT contact

          Use this method if you can modify the domain's DNS Record to include an email address. To learn how to use this DCV method, see Email to DNS TXT contact.

        • Email to Constructed email addresses

          Use this method if you created a pre-approved email alias for the domain, such as admin@{domain_name}. To learn how to use this DCV method, see Constructed email method.

      • DNS CNAME Record

        To validate the domain, add a DigiCert-generated random value to the domain's DNS as a CNAME record.

        Note: Use this method if your domain has a CNAME record pointing to another domain, for example, example.com points to example.net.

      • Using the HTTP Practical Demonstration DCV methods

        Use the HTTP Practical Demonstration DCV methods to validate domains exactly as named. Learn more about the HTTP Practical Demonstration DCV methods.

        Per industry regulations, you must use the HTTP Practical Demonstration DCV methods to demonstrate control over IPv4 and IPv6 addresses.

        • HTTP Practical Demonstration

          Use this method if you can host a file containing a DigiCert-generated random value at a predetermined location on your website: http://{domain-name}/.well-known/pki-validation/fileauth.txt.

        • HTTP Practical Demonstration with unique file name

          Use this method to host a file with a DigiCert-generated filename that contains a DigiCert-generated random value at a predetermined location on your website: http://{domain-name}/.well-known/pki-validation/{unique-filename}.txt.

    2. Email language

      Use the default language. Or, in the Email language menu, select your preferred language for the email. This option appears if you select the Verification email DCV method.

    3. DCV scope

      Use the default DCV Scope setting that aligns with your CertCentral Domain validation scope settings. Or, in the DCV Scope menu, select the scope for demonstrating control over the domains on the request.

      Note: CertCentral administrators can go to the Preferences page to configure their Domain validation scope settings (in the left menu, go to Settings > Preferences).

      Domain scope: Submit base domains versus Submit exact domain names

      • Submit base domains, for example, subdomain.example.com

        When submitting subdomain.example.com, you validate the base domain, example.com. Validating the base domain also validates all subdomains of the base domain, such as subdomain.example.com and sub-subdomain.example.com.

      • Submit exact domain names, for example, subdomain.example.com

        When submitting subdomain.example.com, you validate the domain exactly as named, subdomain.example.com. Exact domain name validation means the validation applies to that domain and no other domains.

  7. Additional certificate options

    1. Signature hash

      By default, DigiCert issues RSA certificates with a SHA-256 signature hash and RSA signing algorithm. We recommend using the default RSA settings. Unless, you have specific reasons for using a different key size or signing algorithm (for example, company policy requires an RSASSA-PSS signature).

      In the Signature hash menu, select the signature hash and signing algorithm you want DigiCert to use for your certificate:

      • sha256WithRSA

      • sha256WithRSAPSS

    2. Server platform

      In the Server platform menu, select the server or system on which you generated the CSR. When we email your certificate, its format aligns with the format supported by the server or system.

      You can always change the format by downloading the certificate from the certificate's Order # details page in CertCentral. See Download a TLS/SSL certificate from your CertCentral account.

  8. Organization

    Add the information about the organization. DigiCert includes just the industry-required details on the organization on the certificate, such as the organization's name.

    Add organization

    You can add an existing organization from your account or a new organization. If you add a new organization, it gets added to your account.

    Select Add an organization, and in the Add Organization window, do the following task as needed:

    1. Add an existing organization

      1. Select Existing organization, in the Organization menu, select the organization, and then select Add.

        If an organization isn’t validated for PKIo Private Services Server certificates, or its validation has expired, DigiCert validates the organization before issuing the certificate.

      2. Organization and technical contacts

        DigiCert automatically adds the contacts assigned to the organization to the request form. Under Contacts, you can see the organization and technical contacts.

    2. Add a new organization

      DigiCert must validate the new organizations before we can issue your certificate. Learn more about organization validation.

      1. Select New organization and enter the following information as needed.

        Legal name

        Organization name exactly as it appears in corporate registries, such as local government registration records.

        Assumed name

        Assumed name or doing business as name.

        Adding an assumed name requires extra validation, which may delay organization validation and certificate issuance.

        Country

        Country where the organization is legally found.

        Address 1

        The address where the organization is legally found.

        Address 2 (optional)

        More address in formation, such as a Suite #.

        City

        City where the organization is legally found.

        State/ Province/ Region

        State, province, region where the organization is legally found.

        Zip/ Postal Code

        Zip or postal code where the organization is legally found.

        Organization phone number

        This should be a number we can check against an online third-party address listing.

        DigiCert must call a verified organization phone number to confirm your authority to order a certificate for the organization. We verify this phone number against online third-party address listing sources like Google Business.

        Learn how we confirm your authority.

      2. When ready, select Add.

  9. Organisation Identification Number (OIN) or Dutch KvK-number (HRN)

    When you've added your organization, you may include a serial number (OIN/HRN) in your certificate.

    重要

    For most customers, a PKIo Private Services Server certificate must include the Subject.SerialNumber field with an OIN or HRN. This field is required to connect to the services available via DigiPoort

    • The OIN is a 20-digit number assigned to government organisations (OIN register) and entered in the Subject.SerialNumber field of the certificate.

    • For commercial organisations without an assigned OIN, the Dutch KvK-number (HRN) is used. The HRN is converted into a 20-digit number and entered in the Subject.SerialNumber of the certificate.

    • Include a serial number (OIN/HRN) in the certificate’s subject distinguished name (DN).

      • No validated serial number (OIN/HRN)

        If your organization doesn’t have an assigned and validated serial number (OIN/HRN), use the menu to enter your organization's serial number (OIN/HRN).

        Note: DigiCert must validate the serial number (OIN/HRN) assigned to the organization before we can include it in the certificate.

      • One validated serial number (OIN/HRN)

        If your organization has an assigned and validated serial number (OIN/HRN), we automatically add it to the request form for you to review

      • Multiple validated serial numbers (OINs/HRNs)

        If your organization has multiple assigned and validated serial numbers (OINs/HRNs), use the menu to select the one to include on this certificate.

    • Do not include a serial number (OIN/HRN) in the certificate’s subject distinguished name (DN).

      Before selecting this option, ensure that you don’t require a serial number (OIN/HRN) in your certificate.

  10. Contacts – authorized representative

    Add an existing or new authorized representative to your certificate request.

    重要

    What is an authorized representative, and why must I add one?

    The authorized representative must be in the company registry and represent the organization. They must have the authority to approve your PKIo Private Services Server certificate requests. Before DigiCert issues your certificate, the authorized representative in your request must approve the order.

    DigiCert validates the authorized representatives in your request. Then, we send them the approval email and wait for them to approve your order. The representative must approve the order before DigiCert issues your certificate.

    Under Contacts, select Add authorized representative. In the Add authorized representative window, do the following task as needed:

    1. Add an existing authorized representative

      1. Select Existing contact and in the Contacts menu, select the contact you want to use as the authorized representative for this request.

        Note: If you select a contact who isn’t an authorized representative, we must validate them.

      2. When ready, select Add.

    2. Add a new authorized representative

      1. Select New contact and enter the contact's first and last name, job title, email address, and phone number.

      2. When ready, select Add.

  11. Contacts – Organization Contact

    The organization contact is the person we contact to validate the organization and verifying your authority to order a DigiCert certificate for the organization. They may also receive the following notifications: Order status updates for organization-related certificates and Domain status updates for their organization controlled domains.

    Items to note about adding an organization:

    • If adding a new organization, DigiCert automatically adds the certificate requester as the organization contact.

    • If adding an existing organization, DigiCert automatically adds the contacts assigned to the organization to the request form.

    To use a different organization contact

    1. To delete the organization, contact automatically populated for you, select the trashcan image.

    2. Select Add contact.

      If you've already added a technical contact, select Add Organization Contact.

    3. In the Add Contact window, in the Contact Type menu, select Organization Contact.

    4. Add the contact:

      1. Add an existing contact.

        Select Existing Contact, in the Contacts menu, select a contact, and select Add.

      2. Add new contact.

        Select New Contact, enter the contact's first and last name, job title, email address, and phone number, and when ready, select Add.

  12. Contacts – Technical Contact

    We may contact the technical contact for inquiries regarding certificate orders for the organization. They may receive the certificate lifecycle-related emails: certificate issued, reissued, and expiring.

    If adding an existing organization, DigiCert automatically adds the technical contact assigned to the organization to the request form. If one doesn’t exist, you can add one if needed. Adding a technical contact is optional and not required to issue your certificate.

    To add a technical contact or change technical contacts

    1. To delete the existing technical contact populated automatically for you, select the trashcan image.

    2. Select Add Technical Contact.

    3. In the Add Contact window, in the Contact Type menu, select Technical Contact.

    4. Add the contact:

      1. Add an existing contact.

        Select Existing Contact, in the Contacts menu, select a contact, and when ready, select Add.

      2. Add a new contact.

        Select New Contact, enter the contact's first and last name, job title, email address, and phone number, and when ready, select Add.

  13. Additional emails (optional)

    Enter the email addresses of the people you want to receive the certificate issuance, expiring certificate, and expiring order emails. Use a comma to separate addresses or enter them on separate lines.

    These recipients receive the certificate-related emails. They can’t manage the order.

  14. Additional order options – Order Specific Renewal Message

    To create a renewal message for this certificate, enter a renewal message with information that might be relevant to the certificate’s renewal. Comments and renewal messages aren’t included in the certificate.

  15. Select payment method

    Under Payment information, select a payment method to pay for the certificate.

  16. Master Services Agreement and Qualified Certificate Terms of Use

    Read the Master Services Agreement and the Qualified Certificate Terms of Use and select the following options to continue:

    • I have read and agree with the Master Services Agreement.

    • I have read and agree with the Qualified Certificate Terms of Use that apply to the eIDAS, PKIoverheid, or Swiss Qualified Certificate requested.

  17. Select Submit request.

What's next

CertCentral takes you to your certificate's Order # details page. Where you can view the order status, discover what you need to do, and see what DigiCert needs to do before issuing your certificate.

Domain validation and organization validation

Before we can issue your certificate, you or DigiCert must do the following:

  1. Demonstrate control over the domains on your order

    Validate the domains on the certificate order. If you've added new domains or domains with expired domain validation, you must demonstrate control over these domains. See Supported DCV methods for validating the domains on certificate orders.

    Note: If using a DigiCert-controlled domain, DigiCert handles the validation by validating your organization and authorizing it to use the DigiCert-provided domain name. You can't validate a domain you don't control.

  2. Complete organization validation

    DigiCert must verify your authority to order a certificate for the organization included on your certificate. To do this, we call a verified phone number and speak with someone who represents you, like the organization or technical contact.

    To get organization consent for your certificate order:

    • Answer the organization/validation phone call (preferred method)*.

      • Tell the organization contact, technical contact, and company receptionist you’ve ordered a PKIo Private Services Server Certificate.

      • Let them know DigiCert calls the verified phone number to speak with one of them to finish the organization validation/authentication.

      • *This phone call usually takes place within 24 hours of the order being placed.

    • Respond to the organization consent message.

      • If the DigiCert validation agent can't contact someone, they leave a message with a call-back phone number and a verification code.

      • Make sure that the organization or technical contact responds to the message and provides the verification code.

Getting your PKIo Private Services Server Certificate

  • Opted to generate the CSR in the browser

    When we've finished processing your order, CertCentral sends the certificate requester an email with a link to generate the CSR and PKIo Private Services Server Certificate via the browser. Learn how to Generate your certificate using DigiCert's KeyGen tool.

  • Included a CSR with your certificate order

    When we've finished processing your order, we issue your certificate and email you a copy. You can also download a copy of the certificate from CertCentral. See our Get a copy of your TLS/SSL certificate instructions.