Skip to main content

Wallet and Registrar Requirements

Which certificates a wallet accepts depends on the wallet and its environment: a development wallet may accept self-signed certificates, while a reference implementation or national test environment may require certificates from its registrar. EUDIPLO's registrar integration supports the German registrar only; certificates from other ecosystems are imported. Read this after Install and Connect and before Issue Your First Credential; for wallets not listed here, the wallet's own documentation is authoritative.

The certificates are different​

Do not confuse the HTTPS certificate of PUBLIC_URL with the certificates of the credential protocols:

Certificate or keyUsed forTypical source
HTTPS/TLS certificateLets the phone reach the EUDIPLO backend securelyYour tunnel or deployment
Attestation key chainSigns the credentials EUDIPLO issuesSelf-signed for testing; a CA or issuer PKI for production
Access certificateSigns presentation requests; identifies EUDIPLO to the walletSelf-signed in some test setups; the wallet ecosystem's registrar
Registration certificateTells the wallet which data the verifier may request (or the issuer provides)Issued by a registrar

Access and attestation certificates belong to key chains (Keys and Certificates). A registration certificate is a JWT configured per presentation configuration (Registration Certificates).

Registration certificates need a registrar configuration

EUDIPLO attaches a verifier registration certificate only when the tenant has a registrar configuration, even if you paste the JWT into registration_cert.jwt. Without the German registrar integration, presentation requests are sent without a registration certificate. Issuers can publish an imported certificate without a registrar (registrationCertificate.mode: "import").

Choose the wallet path​

The exact acceptance rules can change between wallet releases and sandbox deployments.

Wallet or environmentAccess certificateRegistration certificate
Paradym Wallet test setupSelf-signed can be sufficient: Access Certificate → Self-Signed CertificateUsually not needed for a minimal test
EU Reference ImplementationImport the key and certificate from the ecosystem operator: Access Certificate → External CertificateCannot be attached without the German registrar integration (see above); use a test setup that does not require one
German wallet or German ecosystem sandboxRegistrar Enrollment through the integrated registrar, or import a certificate the German registrar already issuedConfigure registration_cert in each presentation configuration; EUDIPLO obtains it from the registrar
Other walletsCheck the wallet ecosystem's documentationCheck whether verifier requests must carry one; EUDIPLO can only attach it with the German registrar

The wallet compatibility record tracks protocol support and known wallet limitations; it does not replace the current onboarding requirements of the wallet or registrar operator.

Minimal Paradym test path​

  1. Create the credential-signing attestation key chain.
  2. Create the access key chain with Access Certificate → Self-Signed Certificate.
  3. Leave the registration certificate unset.
  4. Issue and verify the test credential with the cookbook.

If Paradym rejects the certificate, check the wallet version and test environment. A self-signed certificate that works with one wallet is not evidence that another wallet accepts it.

Imported certificate path (EU Reference Implementation)​

  1. Obtain the access key and certificate from the reference implementation's ecosystem operator.
  2. In Keys → Create Key, choose Access Certificate → External Certificate and provide the private key (EC JWK or PKCS#8 PEM) and the certificate chain, leaf first. Via the API, use POST /api/key-chain/import (Keys and Certificates).
  3. Select this key chain as accessKeyChainId in the presentation configuration if the tenant has more than one access key chain.
  4. Repeat the health, issuance and presentation checks with the wallet, keeping the public HTTPS address stable.

German registrar path​

  1. Obtain the German registrar URLs and account credentials from the registrar operator.
  2. Configure the registrar for the tenant that owns the issuer and verifier settings (Registrar). The tenant needs the registrar:manage role.
  3. Create the access key chain with Access Certificate → Registrar Enrollment, or import a key and certificate the registrar already issued.
  4. Set registration_cert with a purpose in each presentation configuration that needs one; set privacy policy and support URI once as registrar defaults.
  5. Repeat the health, issuance and presentation checks with the target wallet. A successful health check only proves HTTPS connectivity, not that the wallet accepts your certificates.

Next: Issue Your First Credential.