IdExchange 1.9.1

Frequently Asked Questions

Q: Is this system compatible with any mobile device?

A: The systems uses PKI standards for certificate request and certificate generation. When requesting a certificate, the PKCS10 standard is used. When delivering the certificate, the X.509 standard is used. These standards are well supported by all major operating system vendors.


Q: Is this system only available for users which already have an existing credential?

A: In order to receive a derived credential, the user must already have a primary credential. If the user does not already have a primary credential, they must for undergo the identity proofing processes and be issued a primary creential.


Q: Can they have just mobile credentials?

A: If an organization creates a policy where the primary credential is mobile based, the user can just have mobile credentials.


Q: How do I go about registering my device?

A: The device can be registered using the secure registration portal. In this portal, device information and the certificate request information is added.


Q: Do I only have to verify my identity by providing my existing credentials?

A: During the derived credential sponsorship phase, various checks are performed to ensure the identity is still in good standing. Once approved, the only thing required by the user to request the credential is their existing credential.


A: Where are the keys stored on the device?

Q: The IdExchange API delivers the certificate via a REST API. The client requesting the certificate determines where to place the keys. For example, a custom mobile application may store the keys in the application's trust store. Another application may store the keys in the device's native key store.


Q: What credential issuance and mobile device management systems are supported?

A: Airwatch, HID CMS 5.0.2


Q: Does my organization need an MDM?

A: No, an MDM is not required. The derived credential issuance processes can be used via REST API.


Q: Is anything installed on my phone/Do I need an app?

A: No application is required to use the IdExchange. The only thing installed on the phone is the x.509 certificate (the credential). 


Q: Does this system force me to set a PIN to access my credential?

A: No, the IdExchange is responsible for verifying the identity, ensuring the device belongs to the correct person and managing the certificate request and publication process. It does not install any software on the device. Therefore, any PIN management must be controlled by the organization or by the user's security settings.