Certyfikaty
Peppol PKI i cykl życia certyfikatów.
Only certified Service Providers receive Peppol PKI certificates; they exist in two parallel hierarchies (test and production) and two roles (AP and SMP).
What integrators should know even when using a provider:
- You never need your own Peppol certificate as an end user — your provider’s certificates sign and encrypt everything.
- Certificate pinning is wrong here — provider certificates rotate (2-year validity); validate against the Peppol root CA instead.
- Receipts (AS4) are signed with the receiving AP’s certificate — store them; they are your legal proof of delivery.
- The classic outage on self-hosted stacks is an expired AP certificate: automate renewal and monitor expiry with alerts weeks ahead.