I'm pleased to announce the release of ADSS Web RA Server v2.10.0 - the latest update to our industry‑leading certificate registration and vetting platform. This release changes how identity gets verified, tightens control over certificate requests and renewals, and puts the platform on a newer, more supportable foundation.
ADSS Web RA Server puts organisations in control of the digital certificate lifecycle - registration, enrolment, renewal, revocation, recovery - across people, devices, and applications. It integrates with multiple CAs and trust service providers, so certificate management scales with you, not against you.
In‑person identity checks don't scale. Not for remote users, not for high‑volume onboarding, and definitely not for organisations trying to move fast without cutting corners on trust.
Remote ID Verification and Digital Onboarding. ADSS Web RA Server v2.10.0 introduces a policy‑driven remote ID verification and digital onboarding framework, delivered through the Ascertia Mobile Onboarding Application. Users verify their identity using NFC chip reading and camera‑based document capture, right from their phone. Behind the scenes, administrators define exactly what each certificate type requires - and every verification decision leaves a digitally signed, auditable evidence trail.
That means RA operators get high‑volume onboarding without the operational overhead. Auditors get the paper trail they need. Users get a certificate without setting foot in an office.
National ID‑Based SigningHub Registration. Not every identity system runs on email. This release lets Web RA pass National ID data straight through to SigningHub during registration - and generates a placeholder email automatically when one isn't provided. A gap that used to block registration outright is now just... not a problem.
Verifying identity once isn't enough - it has to hold up over the life of the certificate.
Chained Certificate Renewal Limit. Left unchecked, a certificate can be renewed indefinitely, chain after chain, without ever forcing a fresh identity check. v2.10.0 puts a configurable cap on that. Once the limit hits, it's a new certificate request - not another renewal. Quotas get validated, everything lands in the audit log, and compliance posture gets stronger by default.
Exclusive Document ID Pairing. One email address, one Subject Serial Number. That's the rule now. Web RA locks the pairing on first use - multiple emails can still map to the same SSN, but a single email can't be spread across multiple identities, even across different enterprises. Loose identity pairing is exactly the kind of gap bad actors look for. This closes it.
Under the hood, v2.10.0 keeps Web RA current:
None of these are headline features on their own. Together, they're the reason Web RA stays fast, secure, and easy to run for years to come.
If you're a Trust Service Provider, enterprise, or managed service provider, v2.10.0 hits the three things you're always balancing: identity assurance, compliance, and operational efficiency.
Remote onboarding and National ID registration mean you can verify and register users at scale - without cutting corners on evidence or audit trail. The renewal limit and email/SSN pairing rules close the gaps that quietly erode identity assurance over a certificate's lifetime. And the platform upgrades mean none of this is running on borrowed time.
With ADSS Web RA Server v2.10.0, we're continuing to build the platform Trust Service Providers actually need - one that verifies identity remotely and reliably, keeps certificate requests and renewals honest, and stays current under the hood.
That's Web RA's job: a scalable, policy‑driven platform for certificate registration, validation, issuance, and lifecycle management across people, devices, domains, and applications. v2.10.0 pushes that further. Visit Ascertia.com