Grantor Certificates

Agencies are required to obtain and install a personal user authentication certificate on their application server in order to use the system-to-system feature with There are three steps to this process: (1) obtaining the correct type of digital certificate, (2) requesting installation of the certificate, and (3) authorizing the certificate in

Obtaining a Certificate

Your personal user authentication certificate must be purchased from a recognized Certificate Authority (CA) such as Comodo, DigiCert, Entrust, GoDaddy, Incommon, Symantec, or Thawte, and then sent to for installation.

Your certificate must have a 2048 bit public RSA key and use a SHA-2 based digital signature (for example SHA256RSA), so care must be taken when ordering your certificate.

Personal user authentication certificates may be difficult to find on the Certificate Authority websites, so we recommend that you contact sales departments directly and explain that you need a 2048 bit SSL client certificate that uses SHA-2.

Additionally, you must utilize Port 443 with the SHA-2 based digital signature. Please note that all intermediate certificates in the certificate chain must also be SHA-2 in order to work with port 443.

  • Port 443 will only support:
    1. SHA-2 Certificates
    2. TLS v1.1 and TLS v1.2
  • Port 446 will only support:
    1. SHA-1 Certificates
    2. SSL v2, SSL v3, and TLS v1.0

Users should obtain a new SHA-2 based digital signature certificate from a recognized CA and move to port 443 by December 31, 2015. Port 446 will not be available in any environment beginning January 1, 2016.

Note that you are responsible for monitoring your certificate expiration date in order to obtain a renewal from the CA before your certificate expires. Renewed certificates must also be sent to for installation. no longer accepts self-signed certificates as these cannot guarantee your identity and do not meet federal security standards.

Requesting Certificate Installation

Once you have obtained a certificate, fill out the Certificate Request Form and return to by following the instructions on the form. will notify you by email once it has been installed. You have the option to use separate certificates for the Production and Training environments or to use a single certificate for both environments.

Authorizing the Certificate

Login to as a grantor and assign roles to the certificate through the Manage Agency Users menu item.