Digidentity is a Dutch digital identity company, headquartered in The Hague. It provides digital identity verification services for people and businesses to prove who they are online. Its core products include eHerkenning (the login method Dutch businesses use to access government and public-sector services), digital signing, and issueing digital certificates.
Tilted helped build the new digital certificate store, meeting tight deadlines and stringent requirements.
As a trusted certificate authority Digidentity must meet strict industry requirements and undergo regular independent audits. Failing to meet those requirements or experiencing significant security or operational issues, browsers and operating systems may distrust its certificates.
The existing certificate store was outdated and did not meet the requirements for the new PKIoverheid certificates. As Digidentity wanted a totally different certificate purchase workflow, it was decided to rewrite the application from scratch.
As Digidentity’s default technology stack, using Ruby on Rails for the new application was an easy choice.
By using Ruby on Rails with Turbo and Stimulus we were able to create an application that was both accessible and interactive. Using Rails for rendering HTML allowed us to get a working application running in no time. By setting priorities and focusing on the core requirements we were able to implement everything within the given deadlines.
The external auditors were impressed with our new solution and Digidentity got their stamp of approval.
Purchasing a digital certificate is a challenging process. It requires a customer to have deep technical skills (using Unix command line with hard to use tools like OpenSSL).
Due to recent cryptographic support in Javascript, we were able to create a much more user friendly certificate request experience. Making this the worlds’ first browser based certificate purchase process. The CSR (Certificate Signing Request) was created in the browser of the customer, no longer requiring the customer to create a CSR on the command line.