> For the complete documentation index, see [llms.txt](https://idthrivo.gitbook.io/thrivosign-remote-signing-solution/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://idthrivo.gitbook.io/thrivosign-remote-signing-solution/thrivosign-remote-signing-solution-t-rss-documentation/remote-signing-solution/t-ssa/certificate-enrollment-and-issuance.md).

# Certificate Enrollment & Issuance

The process of certificate issuance begins with the initial request for a certificate. The applicant submits the necessary information and documents required for identity verification. Next, the applicant undergoes an electronic Know Your Customer (eKYC) procedure to confirm their identity. Once the eKYC is successfully completed, the details are verified by the Registration Authority (RA) to ensure authenticity and compliance with regulatory standards. Upon verification by the RA, the certificate is issued to the user. This digital certificate can then be used for secure communications, authentication, or other specified purposes, ensuring both the integrity and confidentiality of the transactions involved.

Here are options for the process flow of a certificate application using a SSA :

| Certificate Application | Description                                                               | Action                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ----------------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Manual Approval**     | Best for high-security environments requiring human oversight.            | <p><mark style="color:blue;"><strong>User Action</strong></mark>: The user fills out a certificate application form on the client side (e.g., web portal  or app).<br> <mark style="color:blue;"><strong>RA Action</strong>:</mark> Reviews and either approves or rejects the application.<br><strong>SSA required customization? (Yes/No) No</strong></p>                                                                                                              |
| **Automated Approval**  | Ideal for environments where quick, automated processing is essential.    | <p><mark style="color:blue;"><strong>User Action</strong>:</mark> The user logs in using secure authentication methods (e.g., two-factor authentication) and allows access to the certificate application form.<br><mark style="color:blue;"><strong>RA Action</strong>:</mark>  The RSSP server automatically validates the provided data against predefined criteria.<br><mark style="color:red;"><strong>SSA required customization? (Yes/No) Yes</strong></mark></p> |
| **API-Driven Workflow** | Suitable for users needing immediate certificate issuance without delays. | <p><mark style="color:blue;"><strong>User Action</strong>:</mark> External systems or applications integrate with the SSA via API for submitting certificate requests.<br><mark style="color:blue;"><strong>RA Action</strong>:</mark> The SSA performs real-time validation of the application data received through the API.<br><strong>SSA required customization? (Yes/No) No</strong></p>                                                                           |

<figure><img src="https://content.gitbook.com/content/sRXMZI2vCU8n2yjxKuoA/blobs/DnyCIa5P5KAXKquFraDU/SSA%20Process%20Flow-Cert%20Enrollment.drawio%20(2).png" alt=""><figcaption><p>Certificate enrollment process</p></figcaption></figure>

<figure><img src="https://985735277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsRXMZI2vCU8n2yjxKuoA%2Fuploads%2FIGvgrTLNMSR2DhQoTuCP%2Fimage.png?alt=media&amp;token=ec4f0d5f-8ad8-42bc-9f93-39c496b2f666" alt=""><figcaption><p>User certificate list</p></figcaption></figure>

<figure><img src="https://985735277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsRXMZI2vCU8n2yjxKuoA%2Fuploads%2Fym4Z3LquR1yI3EzofNeL%2Fimage.png?alt=media&amp;token=7c0f9b89-ebb7-4a28-bbcd-7266d8a74ceb" alt=""><figcaption></figcaption></figure>

### <mark style="color:red;">**Note**</mark><mark style="color:red;">: Accessing to CRM Portal and</mark> <mark style="color:red;"></mark><mark style="color:red;">**Automated Approval**</mark> <mark style="color:red;"></mark><mark style="color:red;">requires customization.</mark>
