Call for e-Service providers using Lithuanian Mobile-ID: Add the new “EID-Q 2021E” and “EID-Q 2021R” certificates!

23.08.2024
Starting October 1, 2024, all new Lithuanian Mobile-ID accounts will be issued using the new intermediate certificate “SK ID Solutions EID-Q 2021E.”
This change will affect e-services, applications, and information systems that rely on the authentication or signature capabilities of Lithuanian Mobile-ID.

To ensure that e-services can continue leveraging Lithuanian Mobile-ID certificates, e-service providers must add support for the new “SK ID Solutions EID-Q 2021E” intermediate certificate, in addition to the existing “EID-SK 2016” intermediate certificates, to their MID-REST client’s Trust Store configuration.

Please note that no changes to the end-entity certificate profiles are planned compared to the certificates issued under “EID-SK 2016.”

This change, scheduled for October 1, 2024, affects all information systems and applications that provide digital authentication or signatures using the Lithuanian Mobile-ID service provided by SK.

At the same time, continued support for the “EID-SK 2016” intermediate certificate is necessary for existing Lithuanian Mobile-ID accounts. It is important to note that all valid Lithuanian Mobile-ID certificates issued under “EID-SK 2016” will remain functional until their individual expiry or revocation.

Please keep in mind that only the “EID-Q 2021E” intermediate certificate will be used for actively issuing new Lithuanian Mobile-ID certificates, while “EID-Q 2021R” will serve as a secondary backup CA. We strongly recommend that you support both certificates simultaneously to avoid future inconveniences.

Please ensure that you have updated the certificates in your systems before October 1st 2024, or have confirmed that the Trusted List has been updated with the latest version.

Failure to add the support of new intermediate certificates configuration will result in Mobile-ID users, whose account is created stating 01.10.2024, being unable to authenticate or provide digital signatures in your service.

Please ensure that your system is compatible with the changes taking effect on October 1, 2024, by testing it in our DEMO environment. You can use a Mobile-ID test number with the new certificate chain for this purpose.

Information for testing and implementation:

  • Test numbers for testing the changes in the demo environment are available here.
  • More information on how to verify the authentication response can be found here.
  • An example detailing the implementation of this change is available here.

General information for 2024 PKI changes:

  • The previous news article about the overall changes in the CA hierarchy during 2024 can be found here.
  • For more details on the 2024 certificate changes, visit the GitHub PKI information page.

Please let our support know if you encounter problems during testing or if you have any questions: support@skidsolutions.eu

previous next