Urgent Support: E-Seal Incompatibility with EDC/NexU Platform

Hi everyone,

I am trying to issue European Digital Credentials for my students. They are currently waiting for their certificates, and I am in a very difficult and embarrassing position.

We purchased an official, physical all-purposes E-Seal in a USB token format directly from Multicert (managed via SafeNet Authentication Client).

Since Fabruary, the last explanation of  the EDC team: "The EDC/NexU platform requires the signing certificate and its private key to be visible and accessible directly inside the Windows Certificate Store... the signing key itself is not exposed to the operating system in a way that NexU can access it."

Multicert, on the other hand, explicitly states that because this is a secure hardware token, the private key is confined within the USB and can never be exported or exposed directly to the Windows Certificate Store. That is the security standard of the hardware.

I am begging for a solution now:

  1. Is there ANY technical workaround to force NexU to read this certificate directly from the USB token/SafeNet without requiring it to be inside the Windows Certificate Store?
  2. If this Multicert USB is fundamentally incompatible with EDC, can anyone please recommend an e-Seal provider or format that actually WORKS with the EDC platform?

I am ready to buy a new one if necessary, I just need to deliver these credentials to my students. Please help.

Kind regards,

Comentarios

En respuesta a por Özge Özdemir

Profile picture for user Cabral Luisa
Enviado por Luisa Cabral el Jue, 23/07/2026 - 10:48

Thank you for sharing the outcome. We are pleased to hear that you were able to find a solution. As previously mentioned, the ELM Support team is not in position to recommend or endorse specific providers, but we are glad that the Futurium community could assist with the technical aspects of your question. Thank you again for the update, and we wish you every success with your project.

En respuesta a por Aljaž Leben

Profile picture for user Özdemir Özge
Enviado por Özge Özdemir el Mié, 22/07/2026 - 16:34

Dear Aljaz,

Thank you very much for the information. It is very helpful. EDC should give this information but they do not. I try the way that you suggest. Thanks again.

Ozge

Profile picture for user Leben Aljaž
Enviado por Aljaž Leben el Lun, 01/06/2026 - 12:54

Hi,

We were in a very similar situation and managed to resolve it — hopefully this helps.

The root cause you've identified is correct: NexU requires the signing certificate (including its private key) to be accessible in the Windows Certificate Store. Hardware tokens like yours are specifically designed to prevent the private key from ever leaving the device, which makes them fundamentally incompatible with NexU's architecture. This is not a configuration problem — it's a by-design conflict between hardware token security and how NexU works.

What worked for us was switching to a software-based qualified eSeal (e-žig soft) from Halcom (https://www.halcom.si), a Slovenian Trust Service Provider. With a software certificate, the private key is stored in a protected file (.p12) that can be imported directly into the Windows Certificate Store, which is exactly what NexU expects. NexU then sees and uses it without any issues.

The process was:
1. Generate a CSR using Halcom's CertReqGUI tool
2. Submit the CSR and payment to Halcom
3. Receive the certificate, import it to get a .p12 file
4. Import the .p12 into the Windows Certificate Store (Personal)
5. Install Halcom's intermediate and root CA certificates as well
6. NexU then detects the seal correctly via "Windows Keystore"

One important note: Halcom's software currently only supports Windows 10 or later. If your signing machine runs macOS or Linux, that would be a blocker.

Halcom is an EU-qualified Trust Service Provider, so the seal is valid for EDCI purposes. Their contact for certificate requests is ca@halcom.si.

Hope this unblocks you and your students soon!