16. External components and services¶
This section describes how the CDOC2 system is using external components and services.
16.1 Shared Components¶
The following external components are used by both the Hardware Token/Capsule Server and SID/MID contexts.
16.1.1 LDAP servers¶
LDAP servers are used by CDOC2 client applications (for example, reference CLI application and DigiDoc4) to search for Recipient' certificate. Following servers are used:
- SK public LDAP servers (Documentation) - ldaps://esteid.ldap.sk.ee
- Zetes public LDAP servers - ldaps://ldap.eidpki.ee
16.1.2 OCSP servers¶
OCSP servers are used by CDOC2 client applications and CDOC2 Capsule Server to verify that Recipient's certificate is valid and if the Recipient's key pair is still valid.
- SK OCSP servers (SK validity confirmation service is described at https://github.com/SK-EID/ocsp/wiki and http://open-eid.github.io/#_comp_central_conf_server_interfaces) - http://ocsp.sk.ee/
- Zetes OCSP servers - http://ocsp.eidpki.ee/
16.2 SID/MID Components¶
16.2.1 Smart-ID RP API¶
Relying Party API used by the CDOC2 RP Server to start and poll Smart-ID authentication sessions. The CDOC2 system uses Smart-ID RP API v3 with the ACSP_V2 signature protocol.
- Smart-ID RP API documentation Starts authentication sessions and polls session status
16.2.2 Mobile-ID REST API¶
Relying Party API used by the CDOC2 RP Server to start and poll Mobile-ID authentication sessions.
16.2.3 Smart-ID app¶
Enables to authenticate and sign using Smart-ID. Installed on user smartphone.
(https://www.smart-id.com/et/laadi-alla/)
16.2.4 Mobile-ID SIM application¶
- Needs SIM that supports Mobile-ID https://www.mobiil-id.ee/mobiil-id-tellimine/