Before you request an advanced signature (level2), an advanced signature with a qualified certificate (level3) or a qualified signature (level4), you may want your participant to possess the appropriate certificate.
Universign Certificates service allows you to initiate a registration session request to verify your future participant’s identity and issue, if successful, the appropriate certificate. The service is compliant with European eIDAS regulations and ETSI (European Telecommunications Standards Institute) standards.
In the process, the identity verification relies on Optical Character Recognition (OCR) technology combined with deep learning algorithms to combat fraud.
To consult the list of accepted identity documents:
List of accepted ID documents for LCP certificates issuance.
List of accepted ID documents for QCP and QCP-n-qscd certificates issuance.
In addition to the OCR verification, and only for QCP and QCP-n-qscd certificates, a video selfie is requested and cross-analysis between video and photo data extracted from the applicant’s ID document is followed by analysis by fraud-trained human operators. This process of recording a video is called “proof of life” and is meant to strengthen the fight against identity theft.
Before requesting a certificate creation, ensure that the Certificate creation feature is activated on your workspace.
Request a Certificate creation
From the left sidebar of your workspace dashboard, you can access the Create a Certificate section.
To submit a new certificate request:
1. Click the Create a Certificate button.
2. Enter the participant’s information.
Note that only the participant’s email and the desired certificate level are required to request a certificate. However, If you fill the participant full name, s/he will need to confirm it before his/her identity is verified. If the participant refuses to confirm (for example, in case the full name does not match his/her identity card), you will need to create a new certificate creation request.
3. Click the Confirm button.
Important: If you submit a request to create a certificate using information that matches an existing certificate, the request will be blocked and you will be notified that a certificate already exists.
The Certificates dashboard
From the certificates dashboard, you can:
- display all certificate creation requests made in the last 30 days,
- search for a certificate creation request by email, participant name, or mobile number,
- track the progress of the certificate creation request.
Note that each certificate creation request must be completed within 7 days. After this period, it expires.
Create a certificate as a DRO (Delegated Registration Operator)
As a Delegated Registration Operator (DRO), you are authorized to create signing certificates at the QCP via DRO level for your signers, carrying out the identity verification yourself.
To ensure a high level of security, this feature requires prior activation with your account manager, the DRO role enabled on your member profile, and the configuration of strong authentication through the Namirial Wallet application.
Note: only DRO members with active strong authentication can create QCP via DRO registrations. The other certificate levels (LCP, QCP via PVID, QCP-n-qscd via PVID) remain available depending on your workspace configuration.
1. Activate my DRO access
DRO access relies on strong authentication that you configure only once from your member profile, using the Namirial Wallet mobile application.
Strong authentication proves your identity each time you create a QCP via DRO registration. It ensures that only the authorized DRO can trigger the creation of a qualified certificate.
Important: This setting displays only if the DRO feature is activated on you workspace and that your email address is linked to a DRO profile.
Install and configure Namirial Wallet
From your workspace:
1. Go to the My profile section, then to the Strong authentication section.
2. Click Activate.
3. A window opens with two QR codes to download the Namirial Wallet application: the Google Play QR code (Android) and the Apple Store QR code (iOS).
4. Scan the QR code matching your smartphone and install the Namirial Wallet application.
5. Open the Namirial Wallet application on your smartphone and complete the enrollment.
Activate my DRO access
Once your Namirial Wallet enrollment is complete, you must activate your DRO access in each work session in order to create QCP via DRO certificates.
Note that an active session lasts 10 hours.
From the Services section, go to the Create a certificate section:
1. Click the “Activate my DRO access” link displayed at the top of the page.
2. Open Namirial Wallet on your phone and scan the QR code that appears.
3. Validate the authentication request in the application.
4. Once authentication is confirmed, the window closes and a Your DRO access is activated message is displayed.
The “Activate my DRO access” link is then replaced by the green “DRO access activated” badge.
2. Configure my phone number
To allow you to reset your strong authentication on a new phone (in case of loss, replacement, or device change), you must enter a phone number associated with your DRO profile.
Note that the phone number can only be configured once the identification has been created and you are logged in as a DRO.
Enter my number
Go to the My profile section, then to the Strong authentication section:
1. Once your Namirial Wallet enrollment is complete and your DRO access is activated, a “Phone number” field appears.
2. Enter your number in international format (e.g. +33612345678).
3. Click Save.
Entry rules: the number must be entered in a valid format, otherwise the Invalid format message is displayed and saving is blocked. The field cannot be emptied once filled in: to update the number, simply enter the new one and save.
Reset my strong authentication on another phone
From the Strong authentication section:
1. Click “Reset to use another phone”.
2. Follow the procedure matching your situation.
Case 1 — My phone number is filled in
1. Enter the OTP code received by SMS.
2. Once the code is validated, your previous strong authentication is revoked.
3. The Reset button is replaced by the “Activate” button to start a new enrollment.
Case 2 — My phone number is not filled in
1. A window prompts you to confirm the request.
2. If you confirm, a support contact form opens in a new tab to handle your revocation request manually.
3. Fill in the form to allow support to proceed with the revocation of your strong authentication method.
Note that once your strong authentication method has been revoked, you must complete a new enrollment via Namirial Wallet.
3. Create a QCP via DRO registration
Once your DRO access is activated, you can create a QCP via DRO level registration from your workspace. This registration allows you to carry out the signer’s identity verification yourself, without going through a PVID workflow.
Important: the QCP via DRO option only appears in the certificate creation form if your workspace has the feature enabled, you are identified as a DRO in your member profile, and your DRO access is activated in the current session.
1. Enter the signer’s information
From the Create a certificate section:
1. Click Create a certificate.
2. Enter the Email (required), the Full name (optional), the Phone number (optional), and the Certificate type (required) — select QCP via DRO.
3. Click Confirm.
2. Verify the signer’s identity
Once the creation is confirmed, the window closes and the new registration appears in your registrations dashboard. You are designated as the operator of this registration, and it opens automatically in a new browser tab.
As a DRO, you follow the journey to verify the signer’s identity (without proof of life, unlike PVID).
3. Confirm the extracted data
Once the verification is complete, you validate the data extracted from the signer’s identity document and confirm the information to be used for the certificate creation.
4. Choose how to continue the journey
You must then choose how to finalize the journey with the signer.
Option 1 — I continue the journey with the signer
You stay with the signer (in person) to finalize the journey:
1. The signer accepts the Terms of Use and the Personal Data Protection Policy.
2. The signer accepts the certificate creation attestation.
3. The signer receives an OTP code by SMS to confirm.
Option 2 — Send an email to the signer
The signer finalizes the journey on their own, from their own devices:
1. A toast confirms the sending: “An email has been sent to the signer”.
2. The signer receives an email with the subject Continue the certificate creation journey containing a “Finalize the journey” button.
3. The signer accepts the Terms of Use, the Personal Data Protection Policy and the certificate creation attestation.
4. The signer receives an OTP code by SMS to confirm.
5. Confirm the certificate creation
Once the creation is finalized, two confirmation emails are sent: to you, as the DRO, to confirm the certificate creation, and to the signer, the user of the certificate.
Note: the QCP via DRO level only appears in the certificate type drop-down list when DRO access is activated (eligible workspace, member profile identified as DRO, and DRO access activated in the current session).
