e-invoicing

Authentication and client certificates

TrustWeaver uses mutual TLS (mTLS) for authentication, requiring a valid client certificate for every API call.

All communication with TrustWeaver is secured through SSL/TLS with client authentication. This means both the client and the server authenticate each other during the SSL handshake using X.509 certificates. All TrustWeaver signing operations reject requests without a valid client certificate.

How authentication works

When your application connects to TrustWeaver, the SSL handshake performs the following:

Server authentication
Your application verifies the server's certificate. Include the Certificate Authority (CA) certificate of the TrustWeaver server certificate in your trust store. Confirm the certificate's validity, signature, revocation status, and host name.
Client authentication
TrustWeaver verifies your client certificate. Your application must have access to a valid client certificate and its corresponding private key.

The SSL/TLS channel provides both confidentiality through encryption and authentication of both parties.

Client certificate requirements

Your client certificate must meet the following conditions:

  • Issued by Sovos for your specific environment (UAT or production).

  • Not expired or revoked and trusted by TrustWeaver.

  • Accessible to your application at runtime, along with its corresponding private key.

CAUTION: A certificate issued for the UAT environment can't be used in production, and vice versa. Using the wrong certificate results in an authentication failure.

Request a certificate

Contact Sovos support to request a client certificate for each environment you need access to. When you request a certificate, specify whether it is for UAT or production.

Install a client certificate

How you install the client certificate depends on your client environment. A common approach is to import a password-protected PFX file into your platform's key store. Your Web Services stack then references the key store when establishing the SSL connection.

After installation, configure your stack to present the client certificate during the SSL handshake. The exact configuration steps vary by platform and stack.

Certificate checks on the server certificate

When your application authenticates the TrustWeaver server, perform the following checks on the server certificate:

Validity
The certificate is within its valid date range
Signature validation
The certificate was signed by a trusted CA
Revocation
The certificate hasn't been revoked (CRL or OCSP check)
Host name
The certificate matches the host you are connecting to