PKS CA portal for qualified electronic certificates

An integrated public and internal portal for the Certification Authority of the Chamber of Commerce and Industry of Serbia, covering the submission, processing, issuance, and delivery of qualified electronic certificates.

Client
Privredna komora Srbije
Sector
Software development
Year
2025
Status
In production
PKS CA portal for qualified electronic certificates

Project overview

The PKS CA portal digitizes the complete process of issuing qualified electronic certificates to individuals and authorized representatives of legal entities. Users submit requests through the public portal for cloud certificates, smart cards, or USB tokens, while CA operators use the internal portal to review and process requests, verify payments, issue certificates, organize delivery, and send notifications. A streamlined request process is available without prior registration or sign-in. The solution connects the customer journey with internal operating procedures and numerous government, financial, security, and document-processing services. Available at: https://potpis.eusluge.rs/

Challenge

The main challenge was securely connecting the public user portal and the internal CA operator portal into a unified and traceable certificate-issuance process. The system handles sensitive personal and business data and must reliably coordinate request review, payment verification, electronic sealing of contracts, certificate issuance and delivery, invoicing, and notifications. REST and SOAP integrations, mutual TLS, LDAP authentication, and connections to multiple external systems with different protocols and availability levels add further complexity.

Result

A unified solution was developed that simplifies request submission for users and gives CA operators a central workspace for managing the complete lifecycle of requests and certificates. The portal integrates with the TSP Gateway for electronic contract sealing, the Bitimpeks service, Banca Intesa online payments, LDAP authentication, National Bank of Serbia APIs for IPS QR-code generation, the Treasury Registry of Public Funds Users, and the Serbian Electronic Invoice System. It supports legal-entity search, payment verification, secure data exchange, digital signing, and automated email notifications when certificates are ready.

System architecture

The system architecture connects the key project components into a unified data flow.

  1. Public request portal
    Users submit requests without registration.
  2. Internal CA operator portal
    CA operators manage the complete lifecycle.
  3. Central business logic
    Spring Boot executes central business logic.
  4. Persistent data storage
    PostgreSQL stores requests, payments, and certific
  5. Authentication and communication security
    LDAP and mTLS protect system access.

Technical information

Technologies

JavaSpring BootPostgreSQLLDAPTSP GatewaySMTPOnline Payment API

Standards

REST APISOAPMutual TLS (mTLS)LDAP authenticationPKIX.509 certificatesQualified electronic signatureDigital signatureElectronic seal