PKI Service Integration Guidelines (For Developers)

Ensuring the proper integration of Public Key Infrastructure (PKI) services is essential for maintaining the security and integrity of digital systems. RISA offers crucial services for certificate validation and timestamping, which are foundational to secure a proper use of the digital signature service. When using the digital signature and other PKI services, it is important to adhere to specific guidelines that ensure the authentication, integrity and reliability of the provided services. This document outlines the key areas of focus, including certificate validity check, revocation, certificate expiration, and signature validation check, to help users and developers to meet these critical standards.

Certificate Revocation

Objective:

Ensure your system correctly performs the certificate validity check.

Guidelines: 

Certificate Expiration

Objective

 Prevent the use of expired certificates in your system.

Guidelines

Signature Validation

Objective:

Validate the authenticity and integrity of digital signatures, including Long-Term Validation (LTV) or Time-based validity.

Guidelines:

Password Management

Objective:

Ensure secure handling of user certificate passwords.

Guidelines:

Timestamp Validation (Optional)

Objective:

 Validate the timestamps associated with digital signatures to ensure their reliability and time synchronization.

Guidelines:

By following these guidelines, developers can ensure that their PKI service integration meets the required standards for security and reliability. Implementing these practices should be a fundamental part of the development process to ensure compliance with industry standards. Before deploying the PKI services, developers must contact RISA at pki@risa.gov.rw . RISA will then perform the PKI service integration assessment.