# ID-Authentication certificate ( applicationId = IDA, refrenceId=PARTNER )

**URL:** <https://community.mosip.io/t/id-authentication-certificate-applicationid-ida-refrenceid-partner/318>\
**Category:** Developer\
**Created:** [February 7, 2023, 1:34pm UTC](https://community.mosip.io/t/id-authentication-certificate-applicationid-ida-refrenceid-partner/318 "2023-02-07T13:34:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bch](https://dub1.discourse-cdn.com/flex017/user_avatar/community.mosip.io/bch/32/438_2.png) [@bch](https://community.mosip.io/u/bch)\
**Post date:** [February 7, 2023, 1:34pm UTC](https://community.mosip.io/t/id-authentication-certificate-applicationid-ida-refrenceid-partner/318/1 "2023-02-07T13:34:30Z")

</div>

Hi,

By testing the authentication-demo-ui i need a certificate with applicationId = IDA and refrenceId = PARTNER.  
Otherwise the other module certificat are generated using keygenerator-service, but the IDA certificate is not created.  
Any idea how to generate this certificate.

---

<div class="post-metadata">

**Author:** ![LoganathanSekar7627](https://dub1.discourse-cdn.com/flex017/user_avatar/community.mosip.io/loganathansekar7627/32/218_2.png) [@LoganathanSekar7627](https://community.mosip.io/u/LoganathanSekar7627)\
**Post date:** [February 7, 2023, 3:38pm UTC](https://community.mosip.io/t/id-authentication-certificate-applicationid-ida-refrenceid-partner/318/2 "2023-02-07T15:38:30Z")

</div>

This certificate is generated using getCertificate endpoint which is exposed via IDA internal service.  
[https://domain/idauthentication/v1/internal/getCertificate?applicationId=IDA&referenceId=PARTNER](https://domain/idauthentication/v1/internal/getCertificate?applicationId=IDA&referenceId=PARTNER)

This can be located in IDA internal service swagger.  
[https://domain/idauthentication/v1/internal/swagger-ui.html](https://domain/idauthentication/v1/internal/swagger-ui.html)

---

<div class="post-metadata">

**Author:** ![bch](https://dub1.discourse-cdn.com/flex017/user_avatar/community.mosip.io/bch/32/438_2.png) [@bch](https://community.mosip.io/u/bch)\
**Post date:** [February 7, 2023, 3:53pm UTC](https://community.mosip.io/t/id-authentication-certificate-applicationid-ida-refrenceid-partner/318/3 "2023-02-07T15:53:34Z")

</div>

hI @LoganathanSekar7627  
for test case can i test getCertificate with keymanager service ? ( beacause i have a security issue by runing the same API in authentication internal service).

In this case when i test the getCertificate with keymanager-service i have this issue:

{  
“id”: null,  
“version”: null,  
“responsetime”: “2023-02-07T16:59:06.283Z”,  
“metadata”: null,  
“response”: null,  
“errors”: [  
{  
“errorCode”: “KER-KMS-002”,  
“message”: “ApplicationId not found in Key Policy. Key/CSR generation not allowed.”  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![LoganathanSekar7627](https://dub1.discourse-cdn.com/flex017/user_avatar/community.mosip.io/loganathansekar7627/32/218_2.png) [@LoganathanSekar7627](https://community.mosip.io/u/LoganathanSekar7627)\
**Post date:** [February 7, 2023, 5:03pm UTC](https://community.mosip.io/t/id-authentication-certificate-applicationid-ida-refrenceid-partner/318/4 "2023-02-07T17:03:21Z")

</div>

No @bch, since the IDA key is stored at IDA only, its endpoint only can be used, and keymanager cannot be used.
