Signing and mTLS certificates

To validate your request, Rabobank applies the following security checks to ensure authenticity and integrity:

  • Mutual TLS (mTLS) - The request must be authenticated using an EV SSL certificate. For more info read Mutual TLs
  • HTTP Request Signing - The request is cryptographically signed following the IETF HTTP Signatures draft standard. The request must be signed using a different EV SSL certificate. For more info read Signing API Requests
  • Digest header - A hash of the request body is included, as defined in RFC 3230 to guarantee body integrity. Digest information is available in the API reference for each API.
  • OAuth 2.0 - Used to authorize access to the API. For more info read Authorization Services
  • Rate limits - Applied to ensure fair usage and maintain system stability. Rate limit information is available in the Product overview (Guides) of each API.

EV SSL Certificates

Rabobank accepts certificates from the certificates issuers in the Mozilla Certificate Report .

  • TLS Client Certificate: EV SSL certificate from an accepted CA (RSA ≥ 2048 bits, max validity 1 year).
  • Signing Certificate: EV SSL certificate for signing requests.

TLS Certificate

Public

Upload the public part of the TLS certificate (full chain in PEM format) in the Rabobank developer portal under My Organizations → Apps → Configuration → Certificate.

Private

Keep the private key secure in your infrastructure, it is used to set up the mTLS connection.

Signing certificate

Public

The public key should be shared with Rabobank in the Signature-Certificate header of a request.

Private

Keep the private key secure in your infrastructure, it is used for creating the HTTP Signature. Rabobank does not store your signing certificate.

EnvironmentCertificateDomainSignature
Sandbox

Any certificate works for mTLS and Signing;

Rabobank provides downloadable test sandbox certificates and keys for convenience and testing.

TLS

Download Example Certificate
**

Download Example Private Key
**

Signing

Download Example Signing Certificate

Download Signing Certificate Key

Rabobank servers use EV SSL certificates (e.g., api.rabobank.nl).Requires Digest and Signature headers.
Production

Requires Two valid EV SSL certificates from an accepted CA.

One for mTLS, and
another for Signing.

Rabobank servers use EV SSL certificates (e.g., api.rabobank.nl).Requires Digest and Signature headers.

Did this page help you?