Skip to main content

Authentication & TaxCore (S3-S4)

§3 — Authentication & token acquisition

Access to TaxCore.API requires a bearer token obtained by authenticating with the on-card PKI certificate. XPOS ESDC performs a mutual-TLS request to /api/v3/sdc/token in which the client certificate and private key are the SE's PKI key, exposed through OpenSC PKCS#11. The private key never leaves the card — the TLS handshake's client-certificate signature is computed on the SE.

TLS renegotiation

The FRCS token endpoint requests the client certificate via TLS renegotiation (the initial handshake asks for no certificate; the server then issues a HelloRequest to demand the card certificate). XPOS ESDC performs this exchange over TLS 1.2 with client-initiated renegotiation supported, using the card key via PKCS#11 for the certificate-verify signature (PKCS#1 v1.5, SHA-256). The server certificate is pinned on first use.

The returned token is cached and refreshed before expiry, and presented as the TaxCoreAuthenticationToken header on all subsequent data calls (§4).

§4 — TaxCore.API & command processing

All communication with TaxCore uses the token from §3. XPOS ESDC receives and executes the full command set, in the order received, and reports the result of each command back to TaxCore.

CommandAction
SetTaxRatesInstall/replace tax-rate groups, including future-dated groups (§6).
SetTimeServerUrlSet the NTP server used for time synchronisation (§13).
SetVerificationUrlSet the base verification URL used on receipts (§8).
SetTaxCoreConfigurationApply TaxCore configuration parameters.
ForwardProofOfAuditApply a proof-of-audit to the SE via End Audit (§9, §12).
ForwardSecureElementDirectiveRelay a directive to the SE.

Commands are processed consecutively (first to last); each result is reported so TaxCore has an accurate record of execution.