Qualified Signature Certificates for Natural Persons
Here you will find information on the qualified electronic signature certificate for natural persons – legally binding electronic signatures in accordance with ZertES.
General Information
The Swiss Government PKI (SG PKI) issues certificates in accordance with the current provisions of the Federal Act on Electronic Signatures (ZertES). Class A certificates can only be used in combination with an authorised signature application.
The private key of the qualified certificate is stored on a Swiss Government PKI server, a hardware security module (HSM).
The certificate owner is the person for whom a qualified certificate has been issued. This person acts on behalf of an organisation (Federal Administration, cantons) and, because of this activity, requires a Swiss Government PKI certificate issued in accordance with ZertES (Federal Act on Electronic Signatures).
Certificate Content
The certificate issued by the Swiss Government PKI contains the following information:
- Certificate owner (full name, email address)
- Certification authority (issuer)
- Certificate fingerprint
- Certificate validity
- Serial number
The information in the certificate cannot be changed. If there is a change in the owner's name or email address, for example, the keys and the certificate must be reissued.
Application
- In order to guarantee the correctness of the link between a public key and a requester, the Swiss Government PKI must verify the requester's identity by means of personal identification and official documents (valid passport or ID card).
- The local registration office is tasked with identifying the requester and compiling the information required for issuing a certificate.
- Identity documents from neighbouring countries (Germany, Austria, France, Italy and Lichtenstein) can be accepted for identification purposes. Other identity documents recognised by Switzerland as valid travel documents can be found on the website of the State Secretariat for Migration SEM under Alphabetical list of countries.
Use of the Key and the Certificate by the Owner
Information on the use of signature services in connection with a class A certificate is provided here.
The signature key and the associated qualified certificate may be used solely for generating and verifying electronically qualified signatures on documents. The list of applications with which the certificates may be used is published in the section “Standards, directives and legal basis”.
Use of the key by the owner is subject to the conditions set out in the user agreement and terms of use for class A certificates, and in particular:
- Owners may use their private key solely for the intended purposes and with the approved application (DesktopSigner).
- Owners shall have the basic knowledge required for using the signature key and certificate appropriately.
- Owners must keep up to date with their responsibilities and obligations, as set out in the certificate practice statement.
- Owners bear sole responsibility for their key and the signature device. They must take the necessary precautions to prevent loss, dissemination to third parties, alteration and unauthorised use.
- If it is suspected or discovered that the private key has been compromised, owners must immediately inform the local registration office, in order to block the use of the (certificate's) cryptographic key.
- Owners must arrange to have their certificate revoked if the information contained in it is no longer valid.
Certificate Renewal
- The certificates are valid for three years, unless revoked beforehand.
- The certificate renewal process is the same as that for initial certificate issuance.
Revocation
- The smart card has been stolen or cannot be located.
- The smart card is defective.
- The certificate owner has forgotten the PIN and the PUK for the smart card.
- Termination of employment relationship.
- Change of details (name, organisational unit, etc.)
- Suspicion that the private key has been compromised (revealed) and someone else could use a service, e.g. sign an email.
- The certificate owner is not complying with the rules (non-observance of CPS)
- The LRAO considers that revocation is appropriate for other reasons
- The certificate owner
- Human Resources staff
- Line managers
- The responsible LRAO
- The Swiss Government PKI Officer
- The Swiss Government PKI Security Officer
- The ITSOO
- The certificate owner can go in person to a local registration office.
- They can send the application for revocation by post to a local registration office.
- They can sign a revocation request with their signature key, unless the reason for the revocation request is a suspected or actual compromise of that signature key.
- Outside the opening hours of the local registration office, they can contact the FOITT Service Desk by phone.
If the revocation is not requested by the owner, the request must always be submitted in writing and signed.