Intended Audience: Software Suppliers
Date: 01 July 2020
Situation
User certificate sare valid for 2 years and will start to expire from Autumn 2020, with large numbers expiring in Q1 2021. Because the current system requires manual intervention to renew user certificates this may lead to high volumes of support calls to software suppliers. A solution will be introduced to the UK MVS with Release 1.08 in November 2020.
Affected software suppliers must move quickly to update their software.
Background
The NMVS uses multi-factor authentication: Software must present a valid set of user credentials and certificate to transact with the UK MVS. Manual certificate renewal is problematic due to the dependency on expiry notification emails being delivered and read, and because many suppliers manage numerous certificates on their users’ behalf. Currently, certificates can be renewed in 2 ways:
If the user does not receive the TAN notification email or does not take prompt and appropriate action, then they will be unable to connect to the UK MVS when their certificate expires. This issue is addressed in Release 1.08 to be released in November 2020. Documentation to support development is available now.
Solution
A new endpoint will allow the systematic renewal of certificates. This additional endpoint authenticates using current certificate and credentials and will provide the new certificate that is automatically generated 60 days prior to the expiry of the current certificate. This endpoint is independent from the TAN delivered in the certificate renewal email, and so no user intervention is required.
Recommendations
Download this article here.