# Use Case - Remote Digital Identity Enrolment

## 1. CA-Agnostic Design

SignCloud is independent from specific Certification Authority (CA) software.

It can integrate with any CA that supports:

- Registration Authority (RA) workflows
- Certificate Signing Request (CSR) submission
- X.509 certificate issuance


## 2. Integration with Namirial CMS (Optional)

Although optional, Namirial’s Credential Management System (CMS) provides:

- User registration management
- Approval workflows by Registration Officers
- CA gateway submission to multiple CA backends
- Native integration with SignCloud HSM key container


This allows decoupling:

- User registration
- Certificate issuance
- Remote key storage


## 3. Enrolment Workflow

Typical enrolment process:

1. A new user (Credential Holder) is created in the CMS.
2. Registration Officer reviews and approves the request.
3. Certificate profile is selected.
4. Key container is set to SignCloud HSM.
5. Certificate Signing Request (CSR) is generated.
6. Certificate is issued by CA.
7. Remote digital identity is enrolled in SignCloud.


Example Credential Management System Web Interface: managing approval workflow
Email addressed to the End User and containing the secret codes for the use of remote identity
## 4. Delivery of Secret Credentials

After enrolment, the user receives:

- User ID
- Password
- PIN
- PUK
- ERC (Emergency Recovery Code)


The first two credentials are needed in order to identify the virtual smart card assigned to the End User on the SignCloud platform, while the PIN is used, as for the physical smart card, to authorize the use of the private key, e.g. for an operation of digital signature or authentication; PUK code is used to unlock the PIN code if the number of allowed attempts for inserting a correct PIN is inadvertently reached. Finally, the ERC code is used if a life-cycle management operation, such as a certificate suspension request, is required by the End User to the RA Help Desk.

Delivery methods may include:

- Secure email
- Scratch cards
- PIN mailers


## 5. Purpose of Credentials

### User ID + Password

Identify the Virtual Token on SignCloud.

### PIN

Authorizes signing operations (similar to smart card PIN).

### PUK

Unlocks PIN after excessive incorrect attempts.

### ERC

Used for lifecycle operations such as certificate suspension or help desk requests.

## 6. Authentication Alternatives

Instead of static PIN, SignCloud supports:

- Physical OTP tokens
- Mobile OTP apps
- SMS OTP
- Biometric authentication (optional)


This enables flexible multi-factor authentication policies.