It is recommended that the person designated as responsible for the service has an administrative profile, but there is no problem in assuming a higher profile, as long as he can personally carry out the functions that are his own.

The main tasks of the service manager are detailed below:

Access to the subscriber folder

The subscriber's folder is the space that the AOC Consortium makes available to users of the certification service so that they can quickly and conveniently access the main management related to certificates.

From this application, as the person in charge of the service, you must confirm receipt of the T-CAT cards, record their delivery to the respective holders and have them previously sign the associated documentation, as well as complete the generation of the device certificates through their delivery and unloading.

To access, enter your employee T-CAT on the card in the reader and access the subscriber's folder . Next, a drop-down will appear to select your T-CAT and enter the PIN .

Select certificate

Once you have identified you will automatically enter the application.

Consult the organization's digital certificates

From the subscriber's folder you can search for certificates issued by the organization. Once you have accessed the application, go to the " Certificates issued " section:

Issued certificates menu

Next, the list of certificates will be displayed, these can be in a valid, revoked, expired or suspended state. If you want to search for a specific certificate, you can use the filter shown below and access all its data and its history:

Filter to search for digital certificates
Check the status of a certificate request

Once digital certificates have been requested through EACAT and handled by your T-CAT Registry Entity, as a service manager you can view ongoing certificate requests and their status in the " Request status " section of the subscriber's folder .

Request status menu

status requests

To have more details of the request, you can hover your mouse over the status icon or also access for more detailed information.

Certificate request details

In the event that a request does not appear in this section , verify that it has been registered in EACAT (in the exit register of your organization) or that you have not received, as the person in charge of the service, an email informing of the denial of the application certificate request for some error.

Delivery of the PIN and PUK codes of the T-CAT card

To be able to deliver the PIN and PUK codes of a new certificate, access the subscriber's folder in the " Pending delivery " section.

Section pending delivery

To find the certificate you want to deliver, you can search with the magnifying glass located in the upper right or by expanding the number of records per page:

Filter to search request

Once you have found the certificate, download the associated documentation found in the " Actions " column and have the holder sign it:

Download documentation

Note: The subscribing body must keep this documentation for a period of 15 years from the expiry of the certificate.

Once the holder has signed the documentation, to deliver the PIN and PUK codes click on the envelope icon located in the " Actions " column

Icon about deliver

Then the following screen will open showing the certificate details and click on the button Issue PinPuk .:

Deliver pin and puk

The application will ask for your signature as a certificate operator accepting the delivery conditions of the service manager, once read press the " Accept " button

Acceptance conditions

Finally, a screen is displayed that confirms the sending of the PIN and PUK codes to the e-mail of the certificate holder and this disappears from the list of certificates pending delivery.

pin and puk sent

Recover PIN and PUK from a T-CAT card

To recover the PIN and PUK codes of a T-CAT card access the subscriber's folder and go to the " Delivered " section.

Menu delivered

Find the certificate in question and select the envelope icon located in the " Actions " column :

Icon about deliver

Then the following screen will open showing the certificate data. To retrieve your PIN and PUK codes , click the Deliver PinPuk button.:

Deliver pin and puk

The application will ask for your signature as a certificate operator accepting the terms of delivery of the service manager, once read press the " Accept " button.

Acceptance conditions

Once this is done, a screen is displayed that confirms the sending of the PIN and PUK codes to the e-mail of the certificate holder.

The same certificate holder can also recover the PIN and PUK codes of their card certificate.

Delivery of the certificate T-CAT P

Important: The holder of the certificate must be present to be able to indicate the password required for the subsequent download of the certificate.

To deliver a T-CAT P you have 30 calendar days from when the certificate is pending delivery. As the person in charge of the service, you must access the subscriber's folder in the " Pending delivery " section:

Department pending delivery

To find the certificate you want to deliver, you can search with the magnifying glass located in the upper right or by expanding the number of records per page:

Filter to search request

Once the certificate has been located , download the associated documentation found in the " Actions " column and have the holder sign it:

Download documentation T-CAT P

Once the documentation has been downloaded and signed by the holder, the padlock icon will be activated in the "Actions" column to create the password. Press the padlock icon and the owner will have to enter the personal password that will be used to download the T-CAT P later:

Password T-CAT P

Create password T-CAT P

Once the password has been entered, the envelope icon will be activated in the "Actions" column which will allow the download email to be sent to the certificate holder. Press the envelope icon.

Marked envelope icon

Then the following screen will open showing the certificate data. To deliver the T-CAT P click on " Deliver email "

Select the deliver email option
Deliver marked email

The application will ask for your signature as a certificate operator accepting the terms of delivery of the service manager, once read press the " Accept " button.

Acceptance conditions

Once this is done a screen is displayed confirming that the delivery has been made and the certificate will appear under 'Delivered'.

Important: From this moment, the holder has 10 days to download the certificate. If you do not download it within this period, it will be automatically revoked.

Delivery and download of application certificates (CDA and Electronic Seal)

To be able to deliver an application certificate, access the subscriber's folder in the " Pending delivery " section:

Menu pending delivery

To find the certificate you want to deliver, you can search with the magnifying glass located in the upper right or by expanding the number of records per page:

Filter to search request

Once you have located the certificate, download the delivery slip from the " Actions " column (if you do not download the delivery sheet the tool will not allow you to download the certificate)

Documentation download stamp

If you have already downloaded the delivery sheet, click the download icon

icon download stamp
Certified notice is only downloaded once

Then the following screen will open showing the certificate data. To download the certificate select the " Send email and download" button

Certificate details and send email and download button

The application will ask for your signature as a certificate operator and show you the details of the certificate that will be generated next.

Accept the download of the certificate

If the computer asks you if you want to open or save the file, it is very important to click "SAVE" at the time of download. When saving the certificate will be saved in .p12 or .pfx format in the folder defined by the downloads on the computer where the whole process was done.

Computer asks if the file is opened or saved
Find certificate saved in downloads

Once saved, the certificate will already be downloaded and will appear under "Delivered".

How to download the public key of a certificate from the subscriber folder

Once any type of certificate has been delivered or downloaded through the subscriber folder, the person in charge of the service has the possibility to download only the public key.

The public key is used to consult the data contained in the certificate, as well as to authorize the use of the certificate by third-party applications.

Below is more information on how to download the public key of a certificate from the subscriber folder.