Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 15 additions & 15 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,14 +24,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do

1. Update source files in domain/

2. Build PDF document
2. Build the PDF document from the repository root

```bash
# Export English version
pandoc domain/index.md -L kramdown-toc.lua -o eID_Auth_Guide_EN.pdf
pandoc domain/index.md --resource-path=domain -L kramdown-toc.lua -o eID_Auth_Guide_EN.pdf

# Export Estonian version
pandoc domain/index.et.md -L kramdown-toc.lua -o eID_Auth_Guide_ET.pdf
pandoc domain/index.et.md --resource-path=domain -L kramdown-toc.lua -o eID_Auth_Guide_ET.pdf
```

## Editing and building "Apache2 SSL Configuration"
Expand All @@ -40,14 +40,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do

1. Update source files in apache/

2. Build PDF document
2. Build the PDF document from the repository root

```bash
# Export English version
pandoc apache/index.md -L kramdown-toc.lua -o apache_SSL_EN.pdf
pandoc apache/index.md --resource-path=apache -L kramdown-toc.lua -o apache_SSL_EN.pdf

# Export Estonian version
pandoc apache/index.et.md -L kramdown-toc.lua -o apache_SSL_ET.pdf
pandoc apache/index.et.md --resource-path=apache -L kramdown-toc.lua -o apache_SSL_ET.pdf
```

## Editing and building "Nginx SSL Configuration"
Expand All @@ -56,14 +56,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do

1. Update source files in nginx/

2. Build PDF document
2. Build the PDF document from the repository root

```bash
# Export English version
pandoc nginx/index.md -L kramdown-toc.lua -o nginx_SSL_EN.pdf
pandoc nginx/index.md --resource-path=nginx -L kramdown-toc.lua -o nginx_SSL_EN.pdf

# Export Estonian version
pandoc nginx/index.et.md -L kramdown-toc.lua -o nginx_SSL_ET.pdf
pandoc nginx/index.et.md --resource-path=nginx -L kramdown-toc.lua -o nginx_SSL_ET.pdf
```

## Editing and building "IIS SSL Configuration"
Expand All @@ -72,14 +72,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do

1. Update source files in iis/

2. Build PDF document
2. Build the PDF document from the repository root

```bash
# Export English version
pandoc iis/index.md -L kramdown-toc.lua -o iis_SSL_EN.pdf
pandoc iis/index.md --resource-path=iis -L kramdown-toc.lua -o iis_SSL_EN.pdf

# Export Estonian version
pandoc iis/index.et.md -L kramdown-toc.lua -o iis_SSL_ET.pdf
pandoc iis/index.et.md --resource-path=iis -L kramdown-toc.lua -o iis_SSL_ET.pdf
```

## Editing and building "ID-software Administrator View"
Expand All @@ -88,14 +88,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do

1. Update source files in admin/

2. Build PDF document
2. Build the PDF document from the repository root

```bash
# Export English version
pandoc admin/index.md -L kramdown-toc.lua -o admin_view_EN.pdf
pandoc admin/index.md --resource-path=admin -L kramdown-toc.lua -o admin_view_EN.pdf

# Export Estonian version
pandoc admin/index.et.md -L kramdown-toc.lua -o admin_view_ET.pdf
pandoc admin/index.et.md --resource-path=admin -L kramdown-toc.lua -o admin_view_ET.pdf
```

## Support
Expand Down
Binary file modified admin/img/image10.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified admin/img/image11.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified admin/img/image5.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file removed admin/img/image6.png
Binary file not shown.
Binary file modified admin/img/image7.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file removed admin/img/image8.png
Binary file not shown.
Binary file removed admin/img/image9.png
Binary file not shown.
46 changes: 17 additions & 29 deletions admin/index.et.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**[In English](index.md)**

**Versioon:** 26.04/1
**Versioon:** 26.06/1

**Väljaandja:** [RIA](https://www.ria.ee/)

Expand Down Expand Up @@ -30,6 +30,7 @@
| 16.06.2025 | 25.06/1 | AWP asendatud IDPlug-iga. — Muutja: Raul Metsma
| 31.10.2025 | 25.10/1 | Lisatud SmartCard Client. — Muutja: Raul Kaidro
| 19.05.2026 | 26.04/1 | Avaldatud veebidokumentatsioonina. Lisatud Edge NativeMessagingAllowlist konfiguratsioon. — Muutja: Raul Metsma
| 11.06.2026 | 26.06/1 | Uuendatud GPO-MSI levitamise juhiseid ja kuvatõmmiseid. — Muutja: Raul Metsma

---

Expand Down Expand Up @@ -79,15 +80,15 @@ Selle paigaldamisel kustutakse kaardi lugejast eemaldamisel Windowsi kasutaja se

#### Digidoc_ShellExt

See komponent lisab võimaluse alustada hiire paremklikiga kiiresti ja mugavalt dokumendi allkirjastamist ning krüpteerimist DigiDoc4 rakenduses.
See komponent paigaldab klassikalise (*legacy*) Windows Exploreri kontekstimenüü laienduse, mis võimaldab alustada faili paremklõpsuga dokumendi allkirjastamist või krüpteerimist DigiDoc4 rakenduses. Windows 11-s kuvatakse selle laienduse käsud menüü *Show more options* all. Kui laiendus on Windows Explorerisse juba laaditud, võib selle paigaldamine või uuendamine nõuda Exploreri või arvuti taaskäivitamist.

#### DigiDoc4

DigiDoc4 on rakendus, mis võimaldab dokumente allkirjastada ja digiallkirjastatud dokumente valideerida, dokumente krüpteerida ja dekrüpteerida, saada ülevaadet ID-kaardi sertifikaatidest ning ID-kaardi PIN- ja PUK-koode hallata.
DigiDoc4 on rakendus, mis võimaldab dokumente allkirjastada ja digiallkirjastatud dokumente valideerida, dokumente krüpteerida ja dekrüpteerida, saada ülevaadet ID-kaardi sertifikaatidest ning ID-kaardi PIN- ja PUK-koode hallata. Nii DigiDoc4 MSI kui ka Microsoft Store'i rakendus paigaldavad Windows Exploreri moodsa kontekstimenüü laienduse; MSI teeb seda AppX-põhise lahenduse kaudu.

#### ID-updater

ID-updater on kohustuslik komponent, mis sisaldab teiste ID-tarkvara komponentide jaoks vajalikke kolmanda osapoole teeke (Qt, OpenSSL jms). Installatsiooni käigus luuakse ka *Task Scheduleri* käsk `id updater task`, mis vaikimisi kontrollib uue tarkvara saadavust kord nädalas ja uuenduse leidmisel pakub selle kasutajale välja.
ID-tarkvara EXE-paigaldus paigaldab alati komponendi ID-updater, mis sisaldab teiste ID-tarkvara komponentide jaoks vajalikke kolmanda osapoole teeke (Qt, OpenSSL jms). Vaikimisi loob EXE-paigaldus ka *Task Scheduleri* käsu `id updater task`, mis kontrollib kord nädalas uue tarkvara saadavust ja pakub leitud uuenduse kasutajale. Automaatkorralduse loomise saab keelata parameetriga `AutoUpdate=0`, kuid ID-updater paigaldatakse ka sel juhul. Kui ID-tarkvara komponendid paigaldatakse eraldi MSI-pakkidena, ei ole ID-updater vajalik.

![Näide: ID-updater leidis uuema versiooni tarkvarast (EST)](./img/image3.png)

Expand All @@ -103,11 +104,11 @@ Keskmistes ja suuremates ettevõtetes paigaldatakse tarkvara tavapäraselt mõne

Lisaks interaktiivse installatsiooni puhul saadaolevatele konfiguratsioonivõimalustele on automaatsete installatsioonide puhul võimalik kasutada EXE-installatsioonidel järgmiseid võtmeid:

1. `ChromeSupport=0` — ei lisata Chrome laiendust, vaikimisi 1.
2. `EdgeSupport=0` — ei lisata Edge laiendust, vaikimisi 1.
1. `ChromeSupport=0` — ei paigaldata Chrome laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1.
2. `EdgeSupport=0` — ei paigaldata Edge laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1.
3. `ForceChromeExtensionActivation2=1` — Chrome laiendus aktiveeritakse automaatselt, vaikimisi 1.
4. `ForceEdgeExtensionActivation2=1` — Edge laiendus aktiveeritakse automaatselt, vaikimisi 1.
5. `FirefoxSupport=0` — ei lisata Firefox laiendust, vaikimisi 1.
5. `FirefoxSupport=0` — ei paigaldata Firefox laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1.
6. `InstallCertSynchronizer=1` — installeeritakse vaikimisi `OTCertSynchronizer`, vaikimisi 0[^3].
7. `MinidriverInstall=0` — ei installeerita minidraiverit, vaikimisi 1.
8. `Qdigidoc4Install=0` — ei installeerita DigiDoc tarkvara, vaikimisi 1.
Expand All @@ -116,6 +117,8 @@ Lisaks interaktiivse installatsiooni puhul saadaolevatele konfiguratsioonivõima

> **Märkus:** Ülaltoodud installivõtmed on tõusutundlikud.

> **Märkus:** Kui `ChromeSupport`, `EdgeSupport` ja `FirefoxSupport` on kõik seatud väärtusele 0, ei paigaldata ka native messaging rakendust.

Näiteks käsurida `Open-EID-<version>.exe /q AutoUpdate=0 IconsDesktop=0` installeerib ID-tarkvara vaikimisi režiimil, ei aktiveeri automaatset uuenduste otsimist ega paigalda ID-tarkvara ikoone töölauale.

Vaikimisi piisab tarkvara installeerimiseks EXE käivitamisest, mis paigaldab tarkvara vaikimisi seadetega.
Expand Down Expand Up @@ -144,15 +147,7 @@ Juhendis järgnevalt kirjeldatavad MST failid on allalaetavad asukohast <https:/

Palun märgake ka seda, et uute MSI versioonidega on ka mitmeid MST faile uuendatud ja kindlasti kasutage uusi — vanad ei toimi.

##### ID Updater

Kohustuslik komponent, soovituslik installeerida esimesena.

Kohandused:

- Juhuks, kui automaatset uuenduste otsimist (ajastatud käsk `id updater task`) ei soovita aktiveerida, tuleb koos selle MSI installiga kasutada ka transformfaili `2410-no_autoupdate.mst`. Usutavasti on selle keelamine mõttekas, kuna MSI installatsioonid ei toeta sel viisil tarkvara uuenduste kontrolli.

![Näide transformfaili lisamisest GPO-MSI installile](./img/image6.png)
> **Märkus:** Võrreldes juhendi varasemate versioonidega ei ole GPO-MSI paigalduste puhul enam vaja paigaldada komponenti `ID-updater` ning komponendid ei vaja enam transformfaile, mis sunnivad tarkvara paigaldamist samasse kausta `PROGRAMMIFAILID\Open-EID`.

##### IDPlug

Expand All @@ -179,26 +174,19 @@ Vajalik, kui soovitakse paksu kliendiga sertifikaate hallata, allkirjastada ja k

Kohandused:

- GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-DD-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`.
- Vaikimisi MSI installatsioon töölauale vajalikke ikoone ei paigalda. Kui on soov seda teha, tuleb installatsioonile lisada ka transformfail `2410-DD-Shortcut`.

![Näide transformfaili lisamisest GPO-MSI installile](./img/image7.png)

##### Windows-ile paremklikiga allkirjastamise ja krüpteerimise lisamine

Windows paremklikiga allkirjastamise ja krüpteerimise lubamine.
DigiDoc4 MSI paigaldab Windows Exploreri moodsa kontekstimenüü laienduse AppX-põhise lahenduse kaudu.

Kohandused:
![Näide transformfaili lisamisest GPO-MSI installile](./img/image7.png)

- GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-DD-Shell-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`.
##### Windowsile klassikalise paremkliki-laienduse lisamine

![Näide transformfaili lisamisest GPO-MSI installile](./img/image8.png)
`Digidoc_ShellExt` MSI paigaldab Windows Exploreri klassikalise kontekstimenüü laienduse. Windows 11-s kuvatakse selle laienduse käsud menüü *Show more options* all. Kasuta seda ainult siis, kui moodsa, DigiDoc4 MSI-ga kaasneva laienduse asemel on vaja klassikalist laiendust. Kui klassikaline laiendus on Explorerisse juba laaditud, võib selle paigaldamine või uuendamine nõuda Exploreri või arvuti taaskäivitamist.

##### Web eID

Brauserite laiendused ja omarakendus (*native app*). GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-Web-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`.

![Näide transformfaili lisamisest GPO-MSI installile](./img/image9.png)
Brauserite laiendused ja omarakendus (*native app*).

MSI kohandatud pakkide loend näeb GPMC halduskonsoolis välja nii:

Expand All @@ -208,7 +196,7 @@ GPO-MSI installatsioonide puhul ilmuvad kõik installeeritud programmid ka progr

![MSI installatsioonid programmide loendis](./img/image11.png)

> **Märkus:** MSI-de installatsioonide järjestus ei ole oluline, ent kõik sõltuvad MSI-st „OpenEID Updater". Samuti on oluline minidraiver, millest samuti teised komponendid sõltuvad.
> **Märkus:** MSI-de installatsioonide järjestus ei ole oluline, kuid vajalik minidraiver peab olema paigaldatud, sest teised komponendid sõltuvad sellest.

> **Märkus:** MST failid on allalaetavad asukohast <https://www.id.ee/artikkel/open-eid-administreerimise-ja-paigaldamise-juhised-administraatoritele/>.

Expand Down
46 changes: 17 additions & 29 deletions admin/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**[Eesti keeles (In Estonian)](index.et.md)**

**Version:** 26.04/1
**Version:** 26.06/1

**Published by:** [RIA](https://www.ria.ee/)

Expand Down Expand Up @@ -30,6 +30,7 @@
| 16/06/2025 | 25.06/1 | Replaced AWP with IDPlug. — Changed by: Raul Metsma
| 31/10/2025 | 25.10/1 | Added SmartCard Client. — Changed by: Raul Kaidro
| 19/05/2026 | 26.04/1 | Published as online documentation. Added Edge NativeMessagingAllowlist configuration. — Changed by: Raul Metsma
| 11/06/2026 | 26.06/1 | Updated GPO-MSI distribution guidance and screenshots. — Changed by: Raul Metsma

---

Expand Down Expand Up @@ -79,15 +80,15 @@ When it is installed and the smart card is removed from the card reader, all ID-

#### Digidoc_ShellExt

This component allows starting signing and encryption in DigiDoc4 by right-clicking on the file.
This component installs the legacy Windows Explorer context-menu extension, which allows signing or encryption to be started in DigiDoc4 by right-clicking a file. On Windows 11, commands provided by this extension appear under *Show more options*. If the extension has already been loaded into Windows Explorer, installing or updating it may require restarting Explorer or the computer.

#### DigiDoc4

DigiDoc4 is an application that enables the signing, validation, encryption, and decryption of documents as well as managing the PINs and PUKs of ID-cards.
DigiDoc4 is an application that enables the signing, validation, encryption, and decryption of documents as well as managing the PINs and PUKs of ID-cards. Both the DigiDoc4 MSI and the Microsoft Store app install the modern Windows Explorer context-menu extension; the MSI does so through an AppX-based solution.

#### ID-updater

ID-updater is a mandatory component that bundles shared third-party libraries (Qt, OpenSSL, etc.) required by other ID-software components. During installation, the task scheduler task `id updater task` is created, which checks the availability of new software once per week and suggests any identified updates to the user.
The ID-software EXE installer always installs ID-updater, which bundles shared third-party libraries (Qt, OpenSSL, etc.) required by other ID-software components. By default, the EXE installer also creates the scheduled task `id updater task`, which checks for new software once per week and offers any available update to the user. Creating the scheduled task can be disabled with `AutoUpdate=0`, but ID-updater is still installed. ID-updater is not required when the ID-software components are installed as separate MSI packages.

![Example: ID-updater found a newer version of the software (EST)](./img/image3.png)

Expand All @@ -103,11 +104,11 @@ In large and medium enterprises, the ID-software is usually installed and contro

In addition to the configuration options available in the GUI, the following command-line parameters can be used for unattended installations:

1. `ChromeSupport=0` — the Chrome extension is not added, 1 by default.
2. `EdgeSupport=0` — the Edge extension is not added, 1 by default.
1. `ChromeSupport=0` — the Chrome extension, registry entries, and native messaging manifest are not installed, 1 by default.
2. `EdgeSupport=0` — the Edge extension, registry entries, and native messaging manifest are not installed, 1 by default.
3. `ForceChromeExtensionActivation2=1` — the Chrome extension is activated automatically, 1 by default.
4. `ForceEdgeExtensionActivation2=1` — the Edge extension is activated automatically, 1 by default.
5. `FirefoxSupport=0` — the Firefox extension is not added, 1 by default.
5. `FirefoxSupport=0` — the Firefox extension, registry entries, and native messaging manifest are not installed, 1 by default.
6. `InstallCertSynchronizer=1` — installs the component `OTCertSynchronizer`, 0 by default[^3].
7. `MinidriverInstall=0` — the minidriver is not installed, 1 by default.
8. `Qdigidoc4Install=0` — the DigiDoc software is not installed, 1 by default.
Expand All @@ -116,6 +117,8 @@ In addition to the configuration options available in the GUI, the following com

> **Note:** The installation keys shown above are case sensitive.

> **Note:** If `ChromeSupport`, `EdgeSupport`, and `FirefoxSupport` are all set to 0, the native messaging application is not installed either.

For example, the command line `Open-EID-<version>.exe /quiet AutoUpdate=0 IconsDesktop=0` installs the ID-software in unattended mode, does not activate automatic updates, and does not add the ID-software icons to the desktop.

By default, running the EXE installs the software with default settings.
Expand Down Expand Up @@ -146,15 +149,7 @@ The MST files described below in the manual can be downloaded from the location

Below is a brief overview about how to configure GPO-MSI installations.

##### ID-updater

ID-updater is a mandatory component. It is recommended to install it first.

Options:

- If you do not want to activate the automatic software update functionality (deferred `id updater task`), use the transform file `2410-no_autoupdate.mst` with this MSI installation. And it probably makes sense to disable it, since MSI installations don't support software update checking in this way.

![Sample about adding a transform file to the MSI installation](./img/image6.png)
> **Note:** Compared to earlier versions of this guide, `ID-updater` no longer needs to be installed for GPO-MSI deployments, and components no longer need transform files that force installation into the same `PROGRAM FILES\Open-EID` folder.

##### IDPlug

Expand All @@ -181,26 +176,19 @@ DigiDoc4 is a necessary component if you want to sign and encrypt documents as w

Options:

- For GPO-MSI installations, it is necessary to use the transform file `2410-DD-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers.
- The default MSI installation does not install the necessary icons on the desktop. However, if desktop icons are required, the transform file `2410-DD-Shortcut` must also be added to the installation.

![Adding transform files for MSI installation](./img/image7.png)

##### Adding right-click signing and encryption to Windows

Enables right-click signing and encryption of files in Windows Explorer.
The DigiDoc4 MSI installs the modern Windows Explorer context-menu extension through an AppX-based solution.

Options:
![Adding transform files for MSI installation](./img/image7.png)

- For GPO-MSI installations, it is necessary to use the transform file `2410-DD-Shell-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers.
##### Adding the legacy right-click extension to Windows

![Sample of adding a transform file to a GPO-MSI installation](./img/image8.png)
The `Digidoc_ShellExt` MSI installs the legacy Windows Explorer context-menu extension. On Windows 11, commands provided by this extension appear under *Show more options*. Use it only when the legacy extension is required instead of the modern extension included with the DigiDoc4 MSI. If the legacy extension has already been loaded into Explorer, installing or updating it may require restarting Explorer or the computer.

##### Web eID

Browser extensions and native app. For GPO-MSI installations, it is necessary to use the transform file `2410-Web-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers.

![Sample of adding a transform file to a GPO-MSI installation](./img/image9.png)
Browser extensions and native app.

The list of MSI custom packages in the GPMC management console looks like this:

Expand All @@ -210,7 +198,7 @@ For GPO-MSI installations, all installed programs also appear in the software li

![MSI installations in the program list of the Control Panel](./img/image11.png)

> **Note:** The order of MSI installation components is not important, but all components depend on the MSI `Open-EID updater`. The minidriver is also important, as other components depend on it.
> **Note:** The order of MSI installation components is not important, but the required minidriver must be installed because other components depend on it.

> **Note:** MST files can be downloaded from <https://www.id.ee/en/article/administrators-guide-for-administration-and-installation-of-open-eid/>.

Expand Down