Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: updated name to Identity Manager

When a digital ID card is expiring, then it can be renewed in PRIME Smart ID Self-Service. 

Standard workflow


ActorActionOptionPhysical IDDigital ID
1PRIMEIdentity Manager

On a configurable interval, PRIME Identity Manager runs the Expiry check, which finds all card certificates that will expire within the coming period.

For each affected user, the steps below are done.

Automatically requests to renew all cards that belong to active AD users.

-

2Self-service userReceives an email with instructions. Puts the card in the card reader. Logs in to PRIME Smart ID Self-Service and chooses Renew card.-

-

3PRIMEIdentity ManagerRemoves expired authentication and signing certificates from the card. Keeps and reuses old encryption certificates.--

4CA

Issues a set of new certificates, as needed. The certificates are stored in PRIME in Identity Manager and on the smart card.

-

-


Expiry check:

PRIME Smart ID Self-Service renewal:

Technical references

...