The certificate file contains cryptographic keys and certificates. The certificate file creates the link to a user account in Mein ELSTER. As the certificate file can be copied as often as required, like any other file, a backup copy can be easily created.
As copying can also take place unnoticed, e.g. when stored on a network drive or by malicious software, the certificate file entails risks that the user should be aware of.
It is technically possible to gain access to one and the same user account from several workstations. However, this option harbors security risks and is prone to errors. Securing a user account is based on a combination of knowledge (password for the certificate file) and possession of the certificate file. If the certificate file is passed on, the owner of the user account relinquishes this security feature on their own responsibility. If the ELSTER infrastructure is misused by a copy of the certificate file, the original owner can be identified and held responsible.
Mein ELSTER user accounts are designed to be personal. The parallel (in the sense of simultaneous) use of a user account by several users with certificate files is technically possible. However, the flow control of Mein ELSTER does not explicitly support multiple user operation for a user account. The results of other users' actions are only visible with a time delay or only after a new Login. This can lead to confusion and errors. Parallel use is therefore not recommended.
When passing on the file, please note that
- the number of copies cannot be restricted,
- all copies of the certificate file are equivalent,
- it is not possible to trace which copy of a certificate file was used to carry out a transaction,
- all copies of the certificate file are affected when a user account is revoked,
- and it is not possible to block a single misused copy.
There is another possible source of error when updating the certificate file. For security reasons, the validity of the certificate file is limited (currently to 3 years). The user is informed by e-mail with a certain safety interval to the end of the validity period that a certificate renewal can be carried out. The next time you login to Mein ELSTER, the renewal will start automatically and you will receive a new certificate file once the process is complete. From this update onwards, only this new certificate file will be valid. All other copies lose their validity and Login with these copies is no longer possible. The old copies must therefore be replaced with the new version as a follow-up action to the certificate renewal.
In order to maintain security aspects, we therefore recommend the use of a security stick in the case of multiple use of a user account, e.g. for married couples or within an organizational unit of a company. In this case, use can be controlled by organizational means; it is not possible to copy a security stick certificate.