PKS CA portal for qualified electronic certificates
An integrated public and internal portal for the Certification Authority of the Chamber of Commerce and Industry of Serbia, covering the submission, processing, issuance, and delivery of qualified electronic certificates.
Project overview
The PKS CA portal digitizes the complete process of issuing qualified electronic certificates to individuals and authorized representatives of legal entities. Users submit requests through the public portal for cloud certificates, smart cards, or USB tokens, while CA operators use the internal portal to review and process requests, verify payments, issue certificates, organize delivery, and send notifications. A streamlined request process is available without prior registration or sign-in. The solution connects the customer journey with internal operating procedures and numerous government, financial, security, and document-processing services. Available at: https://potpis.eusluge.rs/
Challenge
The main challenge was securely connecting the public user portal and the internal CA operator portal into a unified and traceable certificate-issuance process. The system handles sensitive personal and business data and must reliably coordinate request review, payment verification, electronic sealing of contracts, certificate issuance and delivery, invoicing, and notifications. REST and SOAP integrations, mutual TLS, LDAP authentication, and connections to multiple external systems with different protocols and availability levels add further complexity.
Result
A unified solution was developed that simplifies request submission for users and gives CA operators a central workspace for managing the complete lifecycle of requests and certificates. The portal integrates with the TSP Gateway for electronic contract sealing, the Bitimpeks service, Banca Intesa online payments, LDAP authentication, National Bank of Serbia APIs for IPS QR-code generation, the Treasury Registry of Public Funds Users, and the Serbian Electronic Invoice System. It supports legal-entity search, payment verification, secure data exchange, digital signing, and automated email notifications when certificates are ready.
System architecture
The system architecture connects the key project components into a unified data flow.
- Public request portalUsers submit requests without registration.
- Internal CA operator portalCA operators manage the complete lifecycle.
- Central business logicSpring Boot executes central business logic.
- Persistent data storagePostgreSQL stores requests, payments, and certific
- Authentication and communication securityLDAP and mTLS protect system access.