Acquire and install the e-Boks Certificate

The organization needs a certificate from Nets for SmartPost to work as a dispatch system for e-Boks. The steps in the certificate process are:

  1. Acquire a certificate (Funktionscertifikat)
  2. Import the certificate in to the certificate store
  3. Add the private key of the IIS user to the certificate
  4. Export the P12 certificate to a CER certificate
  5. Upload the certificate to e-Boks
  6. Apply the certificate to the e-Boks dispatcher


Acquire a certificate (Funktionscertifikat)

An employee at the organization must order a certificate from Nets. The employee must be a NemID administrator at the organization and have an employee signature to be able to order a certificate. The employee will receive an email from Nets with an installation code to use to get the certificate from Nets and a password, which is connected to the certificate.

The employee starts the certificate process using the Nets link: https://www.nets-danid.dk/produkter/funktionssignatur/bestil_funktionssignatur/ and follow the instructions. When the process has been completed, the employee will receive an email with an installation code and a link to start the installation process. During the installation process, the employee selects the certificate type PKC#12, enters the installation code from the email, and creates a password for the certificate. The result of the installation is a certificate file.

Important: The certificate file and the password are connected and will be used later in the process.


Import the certificate in to the certificate store

You need to import the certificate in to the certificate store on the server that runs the SmartPost process using the Windows Certificate Import Wizard.

  1. Double-click the certificate to start the Certificate Import Wizard.
  2. On the Welcome page, click Local Machine, and then click Next.
  3. Click Next until you reach the Certificate Store page, and then select Automatically select the certificate store based on the type of certificate option.
  4. Complete the wizard.


Add the private key of the IIS user to the certificate

You must add the private key of the IIS user that runs the WzpSvc app pool, typically that is IIS APPPOOL\WzpSvc, to the SmartPost certificate. This is done in the Certificate Manager. See Apply certificates to SmartPost.


Export the P12 certificate to a CER certificate

The certificate file that is acquired from Nets is a P12 certificate, see the previous section. This certificate will be used by the dispatcher in WorkZone. However, in e-Boks you must register the certificate in the CER format. Therefor, you need to convert the P12 certificate file to a CER certificate file.

Export certificate

  1. Open Certificates Manager.
  2. Expand Certificates Local Computer > Personal > Certificates.
  3. Right-click the SmartPost certificate, and then select All tasks > Manage Private Keys > Export. The Certificate Export Wizard starts.
  4. Click Next until you get to the Export File Format page, and then select BASE-64 encoded X.509 (.CER), and then click Next.
  5. On the File to Export page, enter a name of the file to export, and then click Next.
  6. Complete the wizard.

A CER certificate file is created. The next step is to upload it to e-Boks.


Upload the certificate to e-Boks

You upload the CER certificate file to e-Boks using the e-Boks Administration Portal.

Upload certificate

  1. In a browser, open the e-Boks Administration Portal
  2. Demo:  https://demo-ekstranet.e-boks.dk/

    Production: https://ekstranet.e-boks.dk

  3. Log in with your credentials.
  4. On the Welcome page, select Tilmeldingsmuligheder (Registration options).
  5. Click Afsendersystemer (dispatch systems), and then click the dispatch system, you want to use.
  6. The Rediger afsendersystem (Edit dispatch system) page is shown.

  7. On the Rediger afsendersystem page, scroll to the Certifikat (Certificate) section, and browse to locate the certificate.
  8. Click OK. The certificate is now registered in e-Boks.


Apply the certificate to the e-Boks dispatcher

You register the e-Boks certificate in WorkZone Configurator.

  1. In WorkZone Configurator, click Process > Process dispatchers.
  2. Select the eBoks dispatcher.
  3. Enter the thumbprint of the certificate in the EboksCertificateThumbPrint field.

See also Process dispatcher module in the WorkZone Configurator Installation Guide.