# Introduction to DIVOC

Digital Infrastructure for Verifiable Open Credentialing

![](/files/4PUQim7QmhfOpr5teJFW)

## What is DIVOC?

The <mark style="color:orange;">**Digital Infrastructure**</mark>**&#x20;for Verifiable Open Credentialing** or <mark style="color:orange;">**DI**</mark>**VOC** is an **open-source platform** that enables countries to digitally orchestrate large-scale health campaigns such as vaccination and certification programs.

Learn more about the platform on the [**DIVOC**](https://divoc.dev/) website or [**Contact us**](https://divoc.dev/#get-in-touch) for more details.

## **Facilitates last-mile delivery of health programs at scale**

* Built in India for the world as a <mark style="color:orange;">**digital public good**</mark>, DIVOC is a flexible and extendable software that can be used across multiple health programs.
* Its scalable and data-driven architecture allows it to deal with diverse country-specific scenarios. In a vaccination programme, for example, it gives countries the ability to manage and control vaccines, facilities, and vaccinators systematically across geographies, as well as generate digitally variable certificates that are compliant with international standards.

## **Our Key Modules**

* The platform is modular, enabling countries to use the components together or as an individual standalone solution, according to their need, for end-to-end vaccination and certification.
* DIVOC has two core modules:

&#x20;            1\. Issue and Verify Certificates

&#x20;            2\. Analytics

![](/files/GrlaujcnbAq5shfi6k5N)

* Reference Implementation: There are other components of DIVOC that countries can customise according to their requirement -&#x20;

&#x20;             1\. Program setup via the orchestration module

&#x20;             2\. Facility app

![](/files/j4x4gQT6WBP9DQ5vkrVb)

&#x20;             3\. Citizen portal

&#x20;             4\. Feedback        &#x20;

![](/files/cvkfvOL8zbHON7FtLalB)

* <mark style="color:orange;">**DIVOC Demo**</mark>**:** Click [<mark style="color:orange;">**here**</mark>](/v2-2/divoc-demo) to play around with the modules.

## **DIVOC’s journey so far: Country stories**

Acknowledge as a Digital Public Good by the [**Digital Public Good Alliance (DGPA)**](https://digitalpublicgoods.net/), the platform has enabled India and four other countries to issue over 2 billion COVID-19 vaccination certificates to its citizens.

<table><thead><tr><th align="center">Launched at Scale: India                                            </th><th align="center">Now live in…</th><th data-hidden align="center">Coming soon…</th></tr></thead><tbody><tr><td align="center"><mark style="color:orange;"><strong>Over 2 billion</strong></mark> digitally signed vaccinated certificates via Cowin. </td><td align="center"><p>DIVOC’s certificate component went </p><p>live with digital vaccination certificates </p><p>in <mark style="color:orange;"><strong>Sri Lanka</strong></mark> in July 2021, in the <mark style="color:orange;"><strong>Philippines</strong></mark> in September 2021, and in <mark style="color:orange;"><strong>Jamaica</strong></mark> and <mark style="color:orange;"><strong>Indonesia</strong></mark> in December 2021. </p></td><td align="center"><mark style="color:orange;"><strong>Indonesia</strong></mark> and <mark style="color:orange;"><strong>Jamaica</strong></mark> are currently planned for Covid-19 vaccination certificate roll-outs.</td></tr><tr><td align="center"><p>DIVOC has enabled the Indian Council of Medical Research (ICMR) to </p><p>issue digitally-signed </p><p><mark style="color:orange;"><strong>COVID-19 test reports</strong></mark>.</p></td><td align="center">Plans are underway to issue COVID-19 test result certificates in both <mark style="color:orange;"><strong>Sri Lanka</strong></mark> and <mark style="color:orange;"><strong>Philippines</strong></mark>.</td><td align="center"></td></tr></tbody></table>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# What DIVOC is and what it's not

This document will tell you what DIVOC can and cannot do. For example, do not expect DIVOC to correct data fraud or mistakes at the source, or store medical history with high data-storage requirements.

| What DIVOC can do                                                                                | What DIVOC is not meant for                                                                                                              |
| ------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Holds information on individual events or claims.                                                | It is not meant to store historical data (for example, a person’s medical history). The size limitation is 1 KB.                         |
| It is tamper-proof, and hence, can ease access to welfare funds linked to identity and a claim.  | Cannot expect it to rectify data errors at the source.                                                                                   |
| The output can be hybrid (PDF plus QR code).                                                     | Not a good idea if the expected verification to issuance ratio is low.                                                                   |
| Modular architecture can support more health credentialing other than COVID-19.                  | Not suitable if there is no purpose on the demand side.                                                                                  |
| DIVOC supports multi-lingual use and multi-distribution methods (such as paper, and smartphone). | Not the best option if the issuer and verifier are in the same network (in such cases, we recommend using simpler, and cheaper options). |

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC Docs Index

Most useful links:

* [Release notes](/v2-2/platform/release-notes)&#x20;
* [API documentation](/v2-2/platform/tech-docs/api-documentation)
* [Setting up DIVOC development environment](/v2-2/platform/tech-docs/setting-up-divoc-development-environment)
* [Setting up DIVOC in k8 cluster](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster)
* [DIVOC's Certification and Verification Component](/v2-2/platform/configuration/configuring-the-certification-and-verification-component)
* [Configuration management via ETCD](/v2-2/platform/configuration/configuration-management-via-etcd)
* [Source code](https://github.com/egovernments/DIVOC)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Platform

This section will include the following:

* [Release notes](/v2-2/platform/release-notes)
* [Specification](/v2-2/platform/tech-docs)
* [Features](/v2-2/platform/divocs-verifiable-certificate-features)
* [Architecture](/v2-2/platform/divoc-architecture)
* [Installation](/v2-2/platform/installation)
* [Configuration](/v2-2/platform/configuration)
* [Performance report](/v2-2/platform/performance-report)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Release Notes

This page lists all DIVOC releases till date. It covers new features, enhancements, and fixes

### Release notes for supported versions are given below:&#x20;

* [Release notes 1.24.0](https://github.com/egovernments/DIVOC/releases/tag/1.24.0-generic) (on-demand EU-DCC and FHIR-DDCC export)
* [Release notes 1.23.3](https://github.com/egovernments/DIVOC/releases/tag/1.23.3-generic) (minor enhancements and UI fixes)
* [Release notes 1.23.2](https://github.com/egovernments/DIVOC/releases/tag/1.23.2-generic) (bug fixes and enhancements)&#x20;
* [Release notes 1.23.1](https://github.com/egovernments/DIVOC/releases/tag/1.23.1-generic) (UI enhancements and bug fixes)
* [Release notes 1.23.0](https://github.com/egovernments/DIVOC/releases/tag/1.23.0-generic) (secondary dosage flows and design enhancements)
* [Release notes 1.22.1](https://github.com/egovernments/DIVOC/releases/tag/1.22.1-generic) (minor enhancements and UI fixes)
* [Release notes 1.22.0](https://github.com/egovernments/DIVOC/releases/tag/1.22.0-generic) (design enhancements and bug fixes)
* [Release notes 1.21.0](https://github.com/egovernments/DIVOC/releases/tag/1.21.0-generic) (facility application enhancements)
* [Release notes 1.20.2](https://github.com/egovernments/DIVOC/releases/tag/1.20.2-generic) (minor enhancements and bug fixes)
* [Release notes 1.20.1 ](https://github.com/egovernments/DIVOC/releases/tag/1.20.1-generic)(minor enhancement on appointment)
* [Release notes 1.20.0](https://github.com/egovernments/DIVOC/releases/tag/1.20.0-generic) (registration and appointment)
* [Release notes 2.0.0](https://github.com/egovernments/DIVOC/releases/tag/2.0.0-generic) (generic) and [2.0 release features](/v2-2/platform/release-notes/divoc-2.0-release-features)
* [Release notes/features 3.5](/v2-2/platform/release-notes/divoc-3.5-release-features)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC 2.0 Release Features

## Version release date&#x20;

* March 25, 2022.

## **Release summary**

If your country is implementing DIVOC 2.0, it is important to know the additions/changes that we have made as part of this release:

* **Configuration management via** [**etcd**](https://etcd.io/)**:** You can make configuration changes to DIVOC’s certificate module via etcd without needing a new deployment. Click [**here**](/v2-2/platform/configuration/configuration-management-via-etcd) to know more.
* **Support for EU compliant digital certificates and Smart Health Cards:** DIVOC’s **EU-DCC** and **SHC** adapter services facilitate easy travel for residents from DIVOC’s adopter countries. Know more about DIVOC’s [**EU-DCC**](/v2-2/platform/divocs-verifiable-certificate-features/divocs-eu-dcc-adapter-service) and [**SHC**](/v2-2/platform/divocs-verifiable-certificate-features/divocs-shc-adapter-service) adapter services.
* **Print certificates at the facility:** We have added the capability to print vaccination certificates when a beneficiary walks into a facility. Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/printing-certificates-at-a-facility) to know more.
* **New API for revocation services:** A new Revoke API has been introduced that can be used to revoke an issued certificate for manual revocation use cases. Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/revoking-a-divoc-certificate) to know more.
* **Deployment activities automated reducing installation time:**&#x20;

&#x20;        \- Automating our infrastructure setup has reduced our deployment time from about 3 days  to 1 day.&#x20;

&#x20;        \- DIVOC’s [**installation process**](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/how-to-install-divoc) has been streamlined with the introduction of the new scripts. The details of the scripts are given below:

1. Install the prerequisites and set up the various hardware clusters.
2. Push the docker images to the appropriate registry.
3. Deploy the code from the registry into the Kubernetes cluster.

* **Enhanced performance of PDF certificate generation:** We have fine-tuned our PDF generating algorithms, which has lowered the consumption of system resources.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC 3.5 Release Features

## Version release date

January 24, 2023

## Release summary

With this release, the DIVOC platform provides a user interface (UI) for tenants to log into the DIVOC platform to create and manage different tenants and schemas required for issuing verifiable credentials (VCs).

## Terminology

A list of the common terms used in this document:

* [**Verifiable credentials (VCs)**](https://www.w3.org/TR/vc-data-model/#:~:text=A%20verifiable%20credential%20is%20a,certificates%2C%20and%20digital%20educational%20certificates.) represent information found in physical credentials, such as birth registration and driving license, as well as objects that have no physical equivalent, such as ownership of a bank account. VCs are typically QR codes whose information is being signed and can only be modified by the issuer making it a tamper-proof QR code. The QR codes can be read and verified by the verifiers using the public key issued by the issuer and by using the libraries/algorithms used by the issuer system. When a digital document (for example, a lab test report) has a normal QR code, anyone can modify its value and generate a new QR code and then replace it with another QR code with different information. Whereas the information in a verifiable QR code cannot be replaced as the original data or information cannot be changed without a “private key.”
* Issuer: Refers to an issuing authority who can issue claims about a particular entity or individual that can be validated. An issuer gathers the information that needs to be contained in the VC from the entities and sends it across to DIVOC through tenant software. Example: Medical Councils.
* Tenant: Refers to any source system of issuers linked to the DIVOC platform to issue VCs. Examples: Council Software, University software, etc.
* Source systems: The tenant software that interacts with the DIVOC platform to issue VCs.
* Schema: A schema is essentially a template that tells the issuer the content, type, and description required for an attribute that needs to be part of the VC.

## New Features

<table><thead><tr><th width="270.5">Enhancement</th><th>Description</th></tr></thead><tbody><tr><td>UI for tenant onboarding portal</td><td>An interface through which source system administrators can log into the DIVOC platform and connect it with the source system.</td></tr><tr><td>UI for credentials management</td><td>A UI-based interface through which tenant administrators can regenerate their API keys to connect to the DIVOC platform and generate access tokens.</td></tr><tr><td>UI for multiple schema creation and modification</td><td>An interface through which tenant administrators can create and manage different schemas required for issuing VCs. This provides functionality to ingest the schema from a JSON or use the user interface to add fields to the schema, as well as set various attributes to them.</td></tr><tr><td>UI for schema creation preview</td><td>Test and preview the certificate being generated before the schema could be published.</td></tr><tr><td>UI for managing certificate templates</td><td>Add and modify templates for certificates generated by the DIVOC platform.</td></tr></tbody></table>

## Enhancements from the previous platform release

<table><thead><tr><th width="272.5">Enhancement</th><th>Description</th></tr></thead><tbody><tr><td>Bug fixes and upgrades</td><td>This includes minor changes in certification and management services to support the upgraded Sunbird registry for updating schema and some UI-specific services.</td></tr></tbody></table>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Specification

Developer documents

## Purpose

The guide covers everything developers need to know to set up and run DIVOC on their local machines.&#x20;

## What will it cover?

* [API documentation](/v2-2/platform/tech-docs/api-documentation)&#x20;
* [Setting up DIVOC development environment](/v2-2/platform/tech-docs/setting-up-divoc-development-environment)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# API Documentation

## This section includes the following:

1. [Admin API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#/admin-portal.yaml)
2. [Vaccination API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../india/interfaces/vaccination-api.yaml)
3. [Certificate Access API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../main/interfaces/certificate-api.yaml)
4. [Registration API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#/registration-api.yaml)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Setting up DIVOC development environment

## This will cover the following:&#x20;

* [Running DIVOC on a local machine](#running-divoc-on-a-local-machine)&#x20;
* [DIVOC walkthrough](#divoc-walkthrough)

## Running DIVOC on a local machine &#x20;

### Steps

**Step 1:** Install prerequisites and dependencies

* Update package list - sudo apt-get update.
* Install docker - sudo apt install docker.io.
* Install docker-compose - sudo curl -L "<https://github.com/docker/compose/releases/download/1.29.2/docker-compose-$(uname> -s)-$(uname -m)" -o /usr/local/bin/docker-compose.
* Install git - sudo apt install git.
* For additional details on Docker, you can find the instructions [**here**](https://docs.docker.com/compose/install/)**.**
* You can find the basic Docker Compose commands below:

&#x20;      \- Starting services [**docker-compose up**](https://docs.docker.com/compose/reference/up/).

&#x20;      \- Restarting services [**docker-compose restart**](https://docs.docker.com/compose/reference/restart/).

&#x20;      \- Checking the status of services [**docker-compose ps**](https://docs.docker.com/compose/reference/ps/).

&#x20;      \- Monitoring service logs [**docker-compose logs**](https://docs.docker.com/compose/reference/logs/).

**Step 2:** Install DIVOC

* Clone DIVOC repository onto your local machine - git clone [**https://github.com/egovernments/DIVOC**](https://github.com/egovernments/DIVOC).
* Navigate to DIVOC directory - cd DIVOC.
* Configure DIVOC: Configurations are provided as environment variables and a default set of configurations is provided in the ‘.env.example’ file. Make a copy of this file named ‘.env’ that docker will pick up. Edit these configurations as per your need.&#x20;

```
   'cp .env.example .env'
```

&#x20;   **Step 3:** Start all services in the detached mode.

```
docker-compose up -d
```

* [**Verify the state of containers**](https://github.com/egovernments/DIVOC/blob/main/docs/developer-docs/index.md#docker-compose-ps)**.** All containers should be up.
* Some services might fail to start because the dependent service may not be ready yet. [**Restarting the failed service**](https://github.com/egovernments/DIVOC/blob/main/docs/developer-docs/index.md#docker-compose-restart) should start it successfully in this case.
* On Mac/Windows, services may crash with exit code:137, if sufficient memory is not set for docker. This can be changed in the Docker desktop preferences, resources tab, as shown[ ](https://docs.docker.com/docker-for-mac/#resources)[**here**](https://docs.docker.com/docker-for-mac/#resources)**.**

**Step 4:** To build docker images locally after making changes, run following commands&#x20;

```
make docker
make docker docker-compose up -d
```

**Step 5:** Explore DIVOC

* The following are the routes to access local apps. The remaining routes can be found in `nginx/nginx.conf.`

|         Address         |  Application |
| :---------------------: | :----------: |
|        localhost        |  public app  |
|     localhost/portal    |  portal app  |
| localhost/facility\_app | facility app |

## DIVOC walkthrough

In this section, we will go through the steps involved in a typical flow, starting from setting up facilities to generating a certificate after vaccination.

### Set up Keycloack

* Login to keycloak console (`localhost/auth/admin`) as `admin` (password : `admin`)
* Hover on `Master` on the left top corner and click on `Add realm.`
* Click on the `Select File` button (import option).
* Select `realm-export.json` in the keycloak directory. `path:DIVOC/keycloak.`
* Click on create.

### Set up CLIENT\_SECRET for `admin-api`

* Login to the keycloak console (`localhost/auth/admin`) as `admin` (password:`admin`).
* Click on `Clients` in the configure section on the left pane and click on `admin-api.`
* Go to the credentials tab, click on `Regenerate Secret` and copy the new secret.
* Change the `ADMIN_API_CLIENT_SECRET` to the copied secret in `docker-compose.yml.`
* Rebuild and restart the services that use `ADMIN_API_CLIENT_SECRET.`

```
docker-compose up -d --build --no-deps <service1> <service2>...
 docker-compose restart nginx
```

“For example - sudo docker-compose up -d --build --no-deps certificate-processor portal-api certificate-api gateway.

### **DIVOC application configuration**

DIVOC uses [**etcd**](https://etcd.io/) as a configuration store for templates and other configurations. A default set of configurations is available in the default-configuration/etcd folder. The instructions to configure these are available [**here**](https://github.com/egovernments/DIVOC/tree/main/default-configuration/etcd).

### Create `admin` and `controller` users in Keycloak

* Login to the keycloak console (`localhost/auth/admin`) as `admin` (password : `admin`).
* Click on `Users` in the Manage section on the left panel and click on `Add User.`
* Give the username as 0000000000 and click on save.
* In the `Attributes` section, add a new key as `mobile_number` and value as 0000000000. Click on Add and save.
* Go to the Groups section, select `system admin` in the available groups and click on Join.
* Similarly, create another user with `username` and `mobile_number` as 0000000001 and join the `controller` group.

### **System admin activities**

Login to the portal as `system admin` (Mobile Number : 0000000000, OTP : 1234).

**Upload Facilities.csv:**

* Click on the Facilities tab and click on `Download Template .csv.`
* Click on `Upload CSV` button and upload the downloaded csv.
* You should see the success message for a facility.

**Create a vaccine:**

* Click on the Vaccines tab. Fill in all the fields on the form, mark the status as Active and click on save.
* You should see the new vaccine on the right pane in the list of registered medicines/vaccines.

**Create a vaccination program:**

* Click on the Vaccine Program tab. Fill in all the fields on the form, mark the status as Active, and click on save.
* You should see the new vaccine program on the right pane in the list of registered vaccine programs.

**Pre-enroll recipients:**

* Click on the Pre-Enrollment tab and click on `Downloaf Template .csv`
* Click on `Upload CSV` and upload a CSV file containing all the fields given in the template.
* You should see the number of recipients successfully enrolled and errors if there are any.

### **Controller activities**

Login to the portal as `controller` (`Mobile Number: 0000000001, OTP: 1234).`

**Activate facilities for vaccination program:**

* In the Facility Activation tab, select the vaccination program added in the previous step, select the type of facility as government and mark the status as Active.
* You should be able to see at least one facility in the search results.
* Click on the checkbox for the relevant facility (make note of facility code) and click on `MAKE ACTIVE.`
* The activated facility should disappear from the search results.

### Facility admin activities

Get admin mobile number for the facility code (noted in the previous step), from the `facilities.csv` uploaded.

Login to Facility Admin portal (`localhost/portal/facility_admin`) using the mobile number and OTP: 1234.

**Add facility\_staff user:**

* Click on the Role Setup tab and click on the add role icon.
* Create a role with type `facility staff` and mobile number `1111111111`. Set the status as enabled and set the rate of 50 for the vaccination program.

**Add Vaccinators:**

* Click on `Vaccinator Details` tab and Click `Add Vaccinator.`
* Fill in all the details. Select the vaccination program previously created in the certification dropdown.
* Click on Add and click on Back.
* Click on the `Make Active` button to activate the vaccinator.

**Bulk Certification:**

* Certificates can also be issued in bulk by the facility admin by uploading a CSV file.
* Go to the Upload Vaccination details tab and click on the download CSV template button.
* Now upload a CSV file, containing all the fields in the template.
* The generated certificates can be viewed on the public app (`localhost`).

### **Facility staff activities**

Login to the Facility app (`localhost/facility_app`) (`Mobile Number: 1111111111, OTP: 1234).`

**Enrolling and certifying recipients:**

* Click on enrol recipient, fill all the details and proceed.
* Click on Recipient Queue, to proceed for certification.

**Certifying pre-enrolled recipients:**

* Recipients pre-enrolled by facility admin can be certified by the facility staff.
* Go to the app home and click on `Verify Recipient` to proceed for vaccination.

### Recipient activities

* In the public app (`localhost`), recipients can:
  * `Download`/ vaccination certificates
  * `Verify` certificates by scanning a QR code
  * `Report` any side effects/symptoms after vaccination
* For the above operations, you need the recipient mobile number (given during pre-enrollment/vaccination). Use OTP: 1234 for all logins.

### Deployment note

Change the admin password of Keycloak console

* Go to the admin console, click on the Admin menu in the top right corner and select Manage account.
* Change the password in the password section on the right.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC's Verifiable Certificate Features

## Purpose

This section describes the key features of DIVOC and how they work.

## What is DIVOC's issue and verify certificate module?

* Countries can use the DIVOC's certificate module to issue <mark style="color:orange;">**digitally verifiable certificates**</mark> to the entire population at speed and scale in a controlled manner post-vaccination.
* This module is responsible for issuing a QR code-based digital certificate for any registered health event. It can be adapted to other areas too where there is a requirement for secure and tamper-proof documents, such as educational certificates.&#x20;
* The certificates can be issued in both digital and physical forms, which includes print, pdf, and other formats.&#x20;

![Once the certificate is issued, multi-channel distribution and print schemes should work to ensure users and countries have a choice.](/files/h0PsObe1aTY1z6E3yxqu)

* The module supports multilingual vaccination certificate templates.&#x20;
* Generates WHO-DDCC (World Health Organisation- Digital Documentation of COVID-19 Certificates) compliant digital vaccination certificates with a W3C (World Wide Web Consortium) JSON schema, for every resident after successful inoculation.&#x20;
* To aid travel into other countries, the certificate module supports on-demand services for travellers to export their vaccination certificates to other formats (e.g. EU-DCC, SmartHealthCard), used in the destination countries.&#x20;
* The module supports additional services, including certificate verification, certificate update/correction, and certificate revocation.&#x20;
* The public key of the adopter country can be published using DIVOC’s verification page that can be embedded into the country's vaccination program-specific website/portal.

## What will it cover?

* [Creating a DIVOC certificate](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate)&#x20;
* [Distributing a DIVOC certificate](/v2-2/platform/divocs-verifiable-certificate-features/distributing-a-divoc-certificate)
* [Verifying a DIVOC certificate](/v2-2/platform/divocs-verifiable-certificate-features/verifying-a-divoc-certificate)
* [Updating a DIVOC certificate](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate)
* [Revoking a DIVOC certificate](/v2-2/platform/divocs-verifiable-certificate-features/revoking-a-divoc-certificate)&#x20;
* [DIVOC's native COVID-19 certificate specification](/v2-2/platform/divocs-verifiable-certificate-features/divocs-native-covid-19-certificate-specification)
* [DIVOC's EU-DCC adapter service](/v2-2/platform/divocs-verifiable-certificate-features/divocs-eu-dcc-adapter-service)
* [DIVOC’s SHC Adapter Service](/v2-2/platform/divocs-verifiable-certificate-features/divocs-shc-adapter-service)
* [Difference between a normal QR code (that you may see on a food menu) and a verifiable QR code (for example, DIVOC's QR-code based digital certificates).](/v2-2/platform/divocs-verifiable-certificate-features/normal-qr-code-versus-signed-verifiable-qr-code)
* [What information goes into a QR code?](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code)
* [WHO master vaccine checklist](/v2-2/platform/divocs-verifiable-certificate-features/who-master-vaccine-checklist)
* [EU master vaccine checklist](/v2-2/platform/divocs-verifiable-certificate-features/eu-master-vaccine-checklist)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Creating a DIVOC Certificate

## Purpose&#x20;

The purpose of this document is to provide information about the certificate generation service of DIVOC. It has the following sections:

* [Overview of DIVOC’s digital certificates.](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate/overview-of-divocs-digital-certificates)
* [What information is included in the DIVOC digital certificate?](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate/what-information-is-included-in-the-divoc-certificate)&#x20;
* [Certificate generation service: How does it work?](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate/divocs-certificate-generation-service-how-does-it-work)&#x20;
* [Compliance with internationally used COVID-19 certificate schemas.](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate/compliance-with-internationally-used-covid-19-certificate-schemas)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Overview of DIVOC’s digital certificates

Using the DIVOC certificate generation service, a country can issue a QR code-based digitally verifiable certificate, which serves as proof of the health event, such as the COVID-19 vaccination. It involves an issuer (for example, a government department), a holder (for example, the citizen of a country), and a verifier (for example, security personnel at the airport).

### Globally accepted W3C-Verifiable Credential Data Model

* All DIVOC issued digital certificates are based on the globally accepted W3C-Verifiable Credential Data Model 1.0.&#x20;
* DIVOC uses this [**data model**](https://www.w3.org/TR/vc-data-model/) for encoding the event data into the digital certificate’s QR code. DIVOC also uses a PKI mechanism to cryptographically sign all QR codes in the issued digital certificates.&#x20;
* Popular cryptographic signing algorithms (like RSA, EDDSA) are adopted in the DIVOC certificate QR signing process.

![Credit: Figure taken from W3C Verifiable Credentials Data Model v1.1](/files/U6G9qIodBIEtMesdGXI9)

### Key roles of a verifiable credential

**A. Holder:** Someone who possesses one or more verifiable credentials as a proof of an event/identified use case and is responsible for generating presentations from them. In DIVOC’s vaccination use case, it is the vaccine recipient or beneficiary.

**B. Issuer:** Reefers to a legal entity that asserts claims about the holder or subject about a verifiable event or an identified use case by issuing a verifiable credential to a holder. Issuers may include central/state governments, authorities, corporations, etc. For instance, in the COVID 19 vaccine scenario, the issuer could be the issuing country or legal authorities.&#x20;

**C. Subject:** An entity about which the verifiable claim is made by the issuer, for example, beneficiary or vaccine dose recipient.&#x20;

**D. Verifier:** An entity who is responsible for verifying an issued credential. In the COVID-19 travel scenario, verifiers are the arrival country authorities that require a verifiable COVID-19 vaccine proof for allowing access to services and border entries.&#x20;

**E. Verifiable data registry:** This refers to a role that a system may perform by mediating the creation and verification of identifiers, keys, and other relevant data, such as verifiable credential schemas, revocation registries, issuer public keys, and so on, which may be required to use verifiable credentials.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# What information is included in the DIVOC certificate?

DIVOC’s W3C-based digital certificate consists of three core components:

1. Credential metadata (schema version credential/certificate ID, etc).&#x20;
2. Claim (vaccination event details).&#x20;
3. Proof (issuer details, date of issue, time stamp, signature, etc).

![Credit: Figure taken from W3C Verifiable Credentials Data Model v1.1](/files/7NlxOrz53W7HwH3gT7hG)

### Data structure

The DIVOC digital certificate QR code includes the following data structure:

| Basic components                                       | Information sections         | Description                                                                                                                    |
| ------------------------------------------------------ | ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| <ol><li><strong>Credential metadata</strong></li></ol> | Certificate context          | Sets the context, which establishes the special terms.                                                                         |
|                                                        | Certificate identifier       | Specifies the identifier for the credential.                                                                                   |
|                                                        | Credential type              | Declares what data to expect in the credential.                                                                                |
|                                                        |                              |                                                                                                                                |
| 2. **Claim**                                           | Credential subject           | Assertion about the subjects of the credentials.                                                                               |
|                                                        | Event block                  | When the credential was issued.                                                                                                |
|                                                        | Issuer details               | The entity that issued the credential.                                                                                         |
|                                                        |                              |                                                                                                                                |
| 3. **Proof**                                           | Signature type               | Digital proof that makes the credential tamper-evident. Cryptographic signature suite that was used to generate the signature. |
|                                                        | Date of signature            | When the signature was created.                                                                                                |
|                                                        | Digital signature value      |                                                                                                                                |
|                                                        | Identifier of the public key | That can verify the signature.                                                                                                 |

### Sample certificate payload

To illustrate the data structure of DIVOC certificate outputs, a sample certificate payload is outlined below:

![](/files/M7mOnBWHfgl8SvfgrSJj)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC’s certificate generation service: How does it work?

This section covers the following:

* Certificate generation process&#x20;
* Certify APIs
* API structure

## Certificate generation process

It involves the following steps:&#x20;

* Recording of a health event against a unique beneficiary, either in the source eHealth system (or in the DIVOC vaccination module, if used by a country, for their vaccination campaign). This results in the creation of the dataset for the specific event.&#x20;
* The event records all transactions associated with it (e.g. beneficiary demographics, vaccinator/facility details, certificate metadata, and timestamp, among others).&#x20;
* Marking the completion of the "event" in the system triggers a DIVOC certificate generation API (or “Certify” API), with the event data populated as per the defined API structure.&#x20;
* DIVOC’s certificate module receives the event data.&#x20;
* A digital certificate, encompassing both a QR code and a human readable document (e.g. PDF) is then issued, which holds the event data for the beneficiary, along with a unique certificate ID.&#x20;
* The QR code is signed with the issuing authority (e.g. national/provincial health agency) private key.&#x20;
* A summary of the health event is then used to populate the “human readable” part of the digital certificate.

![](/files/98M27qgEm9RyDXTC2huG)

### Output

The generated output has two parts:&#x20;

* It has a human-readable document (e.g. the PDF) and the machine-readable QR (the signed QR).&#x20;
* The digital certificate can be presented back to the source system in either of the ways (i.e. either just the signed QR as an image file, or the entire PDF output with the signed QR).

### Sample

A sample DIVOC certificate output is further illustrated in the image below:

![](/files/mp7KjiMIhbhIU6LdPnny)

## Certify APIs

The DIVOC certificate generation service provides a “Certify” API for other eHealth systems, to generate digital certificates for specific events. Currently, DIVOC provides two certify APIs for a “COVID-19 vaccination certificate” and “COVID-19 test result certificate” respectively.

| API type                         | API reference link                                                                                                                                                               |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| “Certify” for vaccination events | [**https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L722**](https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L722) |
| “Certify” for test result events | [**https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L877**](https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L877) |

## API structure

The API structure for the Certify API includes the following:

1. **Recipient information:** This section contains information about the beneficiary of the specific health event (e.g. COVID-19 vaccination or test event).&#x20;
2. **Vaccination event information:** This includes details about the vaccination event such as name, batch, and vaccination date, as well as the vaccinator.&#x20;
3. **Issuer information:** It contains information about the issuing authority.&#x20;
4. **Certificate information:** It includes details such as certificate ID and expiry date, among others.&#x20;
5. **Meta:** This part is used to populate related information about a previous event in the human-readable PDF twin of the digital certificate that can be used by the verifier for cross-reference. It contains additional information, which is not part of the current QR code (the QR code only contains information about the current event), such as the number of past doses taken. For example, If a QR code is generated for the final dose certificate, the QR code will contain all information about the final dose. If a country wants to show information about the previous dose, that can be populated from meta in the certificate PDF.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Compliance with internationally used COVID-19 certificate schemas

Digitally verifiable certificates have emerged as a solution to help open up businesses and travel globally during the ongoing COVID-19 pandemic. There are four major COVID-19 certificate schemas popularly used in the world today:

* [EU-DCC](/v2-2/platform/divocs-verifiable-certificate-features/divocs-eu-dcc-adapter-service)
* [DIVOC (native COVID-19 certificate schema)](/v2-2/platform/divocs-verifiable-certificate-features/divocs-native-covid-19-certificate-specification)
* [Smart Health Cards](/v2-2/platform/divocs-verifiable-certificate-features/divocs-shc-adapter-service)&#x20;
* ICAO-VDS

As the interoperability of these certificate schemas is critical to streamline the international travel process, DIVOC has added the ability to issue digital certificates in the EU-DCC and SmartHealthCard formats, in addition to the [**native DIVOC COVID-19 certificate format**](/v2-2/platform/divocs-verifiable-certificate-features/divocs-native-covid-19-certificate-specification). This will enable citizens of a country, which is using a DIVOC certificate system, to export their native certificates in a format that is acceptable in the travel destination country. <br>

Note: DIVOC will also add the capability to export the certificates in the ICAO-VDS format in 2022.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Distributing a DIVOC Certificate

## Purpose&#x20;

The purpose of this document is to outline the features of DIVOC's certificate distribution service.

## **Overview**

* DIVOC offers several ways in which countries can distribute certificates at scale.&#x20;
* The platform is designed to facilitate multiple certificate distribution methods, which includes:

&#x20;     \- Printed paper certificate with QR code.

&#x20;     \- Digital certificate distribution - download and share QR code via URL link, email  attachments, smartphone with user authentication.

&#x20;     \- By integrating with a country's vaccination portal, health wallets, PHR, consumer, or travel applications.

&#x20;     \- Countries can also distribute certificates for a health event via DIVOC’s Citizen Portal.

![](/files/szC4adkSjhDyr9Wn0qOa)

* After a health event such as vaccination, citizens can log in to the Citizen Portal with their registered mobile number, and they are given the option to securely download the certificate in PDF or other formats with added user authentication.
* If using DIVOC’s citizen portal, the home screen of the Citizen Portal has a “Download” button in the “Download your Vaccination Certificate” section.  Citizens can click the button and they will be asked to log in using their registered mobile number to download the certificate. To understand how it works, you can check our demo section on [**downloading certificates**](https://divoc.egov.org.in/divoc-demo/citizen-portal#2.-for-downloading-a-certificate).

## Certificate API&#x20;

The DIVOC certificate distribution service provides a get API so that certificates can be downloaded or printed for specific events. For fetching the right certificate, the get service requires a “pre-enrollment code,” and the latest certificate is fetched.

### **How does it work?**

* The get certificate receives the preEnrollmentCode (beneficiary id) as input:&#x20;

{% hint style="info" %}
GET {domain}/certificate/api/certificatePDF/{beneficaryId}
{% endhint %}

* Once it receives the input, it,

1. gets all certificates associated with preEnrollmentCode from the database.
2. gets the latest dose certificate by grouping the certificates by dose, and order\
   them by their timestamps.
3. creates the QR code from signed certificate data.
4. using the above-generated QR code and certificate information, it creates a PDF.

* Similarly, there are APIs in certificate-api service which can return the QR code as a png image, which follows the same step as above (till the third point):

{% hint style="info" %}
GET /certificate/api/certificateQRCode/{beneficaryId}
{% endhint %}

* We also have an API to check if a beneficiary has a certificate generated, which follows the same step as above (till the second point):

{% hint style="info" %}
HEAD  {domain}/certificate/api/certificatePDF/{beneficaryId}
{% endhint %}

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Updating a DIVOC Certificate

## Purpose&#x20;

The purpose of this document is to outline the features and workflow of DIVOC's “Update Certificate” service.

## **Overview**

* DIVOC provides an “update certificate” feature to help beneficiaries make changes in a certificate if any information was captured incorrectly during the beneficiary registration or vaccination process.&#x20;
* For this purpose, DIVOC provides an “*Update Certificate API*,” for a source system (e.g. a vaccination platform) to update the vaccination as well as beneficiary details in digital certificates issued by DIVOC.
* There are multiple ways of using this service. The issuing authority can enable a self-service portal, or set up a call centre, or the source system can capture the update requests directly, which can then call the Update API to facilitate the updates/corrections to the specific certificates. The key requirement here is that the “Update Certificate API” is called by the source system(s) to update an issued certificate. Using this API, the source system can update a beneficiary’s latest as well as previously issued digital certificates.

## **Update Certificate API**

As outlined earlier, DIVOC’s “Update Certificate” API is used by source systems to perform updates to already-issued certificates. You can refer to the update API specification link [**here**](https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L722)**.**

## **Sample API Payload**

```
[
  {
    "preEnrollmentCode": "987456126",
    "recipient": {
      "name": "John Doe",  
      "dob": "1987-04-21",
      "nationality": "Dutch",
      "identity": "872550100V",
      "contact": [
        "tel:1691742639"
      ]
    },
    "vaccination": {
      "name": "Covishield",
      "batch": "41202025",
      "manufacturer": "astrazeneca",
      "date": "2021-10-17T13:10",
      "effectiveStart": "2021-10-25",
      "effectiveUntil": "2022-10-24",
      "dose": 1,
      "totalDoses": 2
    },
    "vaccinator": {
      "name": "Bartjan Verduijn"
    },
    "facility": {
      "name": "MOH Gothatuwa"
    }
  }
]
```

## **What can be updated/corrected?**

1. An issued certificate’s QR code contains the two categories of information:

&#x20; \- **Personal information**, for example:

* Beneficiary name&#x20;
* Gender&#x20;
* Date of Birth

&#x20; \- **Event details**, for example:&#x20;

* Vaccine type/prophylaxis&#x20;
* Vaccine name/brand&#x20;
* Manufacturer Vaccine batch&#x20;
* Vaccination date&#x20;
* Facility ID/name&#x20;
* Country of issuance&#x20;
* Issuer&#x20;
* Dose number&#x20;
* Total dose count

2\. Any or all of the above fields can be corrected/updated by calling the Update Certificate API by a source system.&#x20;

3\. The Update Certificate API requires beneficiary ID/enrollment code and dose number as an input to fetch the right certificate that needs to be updated.&#x20;

4\. Once the certificate is fetched, the update API updates the information against the certificate ID as provided in the API payload input.&#x20;

5\. Once the certificate is updated, a new certificate is issued with a new certificate ID and updated information. The older certificate gets revoked by an automated revocation workflow using DIVOC’s “Revoke API.”&#x20;

6\. The revoked certificate is moved to the Certificate Revocation List (CRL). If the older revoked certificate is scanned by a verifier, the verification screen will show “certificate revoked.”&#x20;

7\. For update scenarios, DIVOC can also enable configuring a custom message for beneficiaries trying to verify the older corrected and revoked certificate as: “certificate revoked, please download the updated certificate from the portal.”&#x20;

8\. Updates/corrections can be made in the provisional and final certificate for any of the fields present in the QR code as per the issuing authority’s requirements and approved flow.&#x20;

9\. It is strongly recommended that an issuing authority should allow information correction/updates only after verifying the required proofs uploaded by the beneficiary.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Revoking a DIVOC Certificate

## Purpose

This document refers to the revocation of a digital certificate issued to a person. DIVOC’s certificate revocation service will help stakeholders of a program to revoke digital certificates, according to the issuing authority’s predefined policy.

For example, during a COVID-19 vaccination campaign, the vaccination certificate issued to a person, as digitised proof of the event, can get revoked due to multiple reasons like:

* errors in the information encoded in the digital certificate.&#x20;
* wilful tampering of the digital certificate (QR or PDF output) by external entities who have gained unauthorized access to the certificate data contents.&#x20;
* or if a specific batch of vaccines is found to be faulty, among others.

The purpose of this document is to provide an overview of the certificate revocation service offered by DIVOC. It describes the steps involved in the revocation process, as well as the maintenance of the revoked certificate list for verifiers.

## **What is DIVOC’s certificate revocation service?**

### **Revocation API**

* DIVOC has enabled a “Revoke API” that can be used to revoke an issued certificate for manual revocation use cases.&#x20;
* The API uses a “beneficiary ID/pre-enrollment code” and either the “dose number(s)” or the “all doses” flag as input parameters to search and fetch the certificate(s) that need to be revoked from the certificate registry.&#x20;
* If the “dose number(s)” parameter is passed, it must be a sequential list of doses that includes the latest dose.&#x20;
* DIVOC stores the revoked certificate ID within a centrally-maintained “certificate revocation list (or CRL).”

### Revocation List

* DIVOC maintains a certificate revocation list to store certificate IDs of the revoked certificates. The revocation list can be hosted by an issuing authority (either inside or outside its central certificate registry) or can be periodically downloaded as a file and stored by a verifier application.&#x20;
* When a revoked certificate’s QR code is scanned using the DIVOC’s online verification service, the service searches the CRL for the certificate ID to check if the certificate is a valid or revoked certificate.&#x20;
* If the certificate ID is found in the CRL of the scanned QR code, the verification screen displays the certificate as revoked.

![](/files/TmRHX0H3Wz9mAGKiHdoT)

* Each CRL has a serial number, time, and date on which the certificate was revoked.&#x20;
* It includes the date and time when the CRL was published, and when the next update to the CRL will be published.

## How does it work?

* A revocation is triggered when the revocation API is called by the source system (for example, a vaccination platform), on specific transactions (for example, the correction or update of a certificate).&#x20;
* As input parameters from the source system, the revoke API receives beneficiary ID/enrollment code and dose number(s) or the all doses flag.&#x20;
* The relevant certificate is fetched and DIVOC performs a “soft delete” of the certificate (also referred to as the “revocation” process).
* The revoked certificate’s "certificate ID" is then moved to the certificate revocation list.
* Certificate IDs of all revoked certificates are maintained in the CRL within the certificate registry. The revoked certificate IDs can be indexed in chronological order against the respective unique certificate ID, along with its revocation date and time.
* The certificate revocation list will be regularly updated to support the verification flow by approved domestic and international verifiers.
* If the certificate was revoked, the same information will be displayed to the third-party verifier application in real-time. On scanning, the verifier application will display the result as an “Invalid certificate.”
* DIVOC’s certificate revocation list can be configured to support both offline and online verifications flows. For instance,&#x20;

&#x20;          \- On scanning a revoked certificate, a third-party verifier application can call the APIs (i.e. fetch APIs provided by DIVOC to the country’s issuing authority) to fetch the certificate revocation list to validate the “revoked” status of the digital certificate.&#x20;

&#x20;         \- The certificate revocation list can be downloaded by the third-party verifier application (in their local system) on a periodic basis.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Verifying a DIVOC Certificate

The verification component of the DIVOC certificate service checks for two things:

1. An issued certificate is valid (that is, the document is currently ‘live’ and is not a revoked document).&#x20;
2. The document is authentic (that is, the document has not been tampered with).

## **For verifying authorities**

### **Offline verification:**

DIVOC supports offline verification of the QR code-based digital certificates to support verification of certificates in connectivity restricted regions and make it more user-friendly.&#x20;

The QR code can be verified by third-party authorised verifier applications to enable domestic and cross-border verification of DIVOC-issued certificates.&#x20;

Use the following steps to verify a DIVOC certificate:

1. Scan to detect the QR code.
2. The verification component uses the QR code reader libraries to read the contents of the QR code embedded in the certificate.
3. Once the QR code is detected by the camera, it reads the binary data encoded in the QR code. (the binary data will be in zipped format).
4. The decompressed Json in the QR code is authenticated using a signing method mentioned in the proof section of the QR code content
5. After unzipping it, you will get a certificate.json file (certificate.json will have the signed, json-ld formatted VaccineCertificate).
6. Json-ld signature will be verified against the public key that is issued by the issuing authority.
7. On successful verification, the revoked API is called to check if a certificate has been revoked or not.
8. Once the signature and revocation are verified, the success screen is shown with beneficiary and vaccine details.
9. Since it is offline verification, the verifier will need to download the CRL within the verifier application. The verification service will also go through the CRL and check for the certificate's revoked status.
10. Please note: In addition to supporting verification by third-party verifiers, DIVOC also provides a verification portal. The portal works on a web browser as well as on a mobile phone browser, and it can be also used by verifying authorities to verify DIVOC-certificates in an “offline” capacity.

### **Online verification:**

* DIVOC provides a public portal that allows verifiers (including self-verification by beneficiaries) to verify certificates.
* Certificates can be scanned and verified on the following URL: [**https://demo-divoc.egov.org.in/**](https://demo-divoc.egov.org.in/) and clicking on “Verify.”

![](/files/YOcbcAYkYGjEreuyV9Qp)

Next,

* Scan the QR code.
* On successful verification, certificate details will be shown on the screen.
* On unsuccessful verification (unauthenticated/fraudulent certificates), the message will be shown as “Certificate Invalid.”

![](/files/y44GBbiWa7aZlpjt6r8d)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC's Native COVID-19 Certificate Specification

When the “Certify API” is called by a vaccinating system, a unique QR code is generated for that specific event. This document specifies the data structure that can be used to generate a QR code-based digitally verifiable certificate for a registered health event.

## QR payload structure

The payload structure follows the JSON Web Token (JWT) digital signature and is defined in [**RFC 7519**](https://datatracker.ietf.org/doc/html/rfc7519). The payload is transported in a DIVOC certificate. JWT includes the following:

* Header&#x20;
* Payload&#x20;
* Signature algorithm

### Header&#x20;

This contains the information about the certificate, which is based on the [**W3C verifiable credentials data model**](https://www.w3.org/TR/vc-data-model/). The header also indicates the type of certificate being issued.&#x20;

### Payload&#x20;

This is divided into several parts:&#x20;

* The first part contains the details of who is issuing the certificate along with the timestamp.&#x20;
* The second part contains the details of the beneficiary to whom the certificate has been issued.&#x20;
* The final part contains details on the event for which the certificate has been generated. The event part has details of the health event (such as vaccination) along with a timestamp, which includes information on the type of vaccine, dose details, and location of the vaccination.

### Signature algorithm&#x20;

DIVOC is capable of self-generating a public-private key pair. It also supports a signing configuration where the country has onboarded a CA (certificate authority) responsible for generating the keys. In the latter case, DIVOC will use the private key issued by the CA and sign the QR code.

* The DIVOC certificate is flexible and multiple signing algorithms can be used.&#x20;
* Self-generated keys or the keys from a country’s PKI service provider can also be used. DIVOC currently uses two default signature algorithms:&#x20;

&#x20;              1\. PS256 - Using "crit" with "b64"&#x20;

&#x20;                 ([**https://w3c-ccg.github.io/security-vocab/#RsaSignature2018**](https://w3c-ccg.github.io/security-vocab/#RsaSignature2018))

&#x20;              2\. ES256&#x20;

&#x20;                  ([**https://w3c-ccg.github.io/security-vocab/#EcdsaSecp256k1Signature2019**](https://w3c-ccg.github.io/security-vocab/#EcdsaSecp256k1Signature2019))

* Click [**here**](https://github.com/egovernments/DIVOC/blob/f3c524ff0e8e9a2f09193a37758a67e9b7198c31/public_app/src/utils/credentials.json) to see the various versions of the algorithm.&#x20;
* The public key along with the method of signing will be provided to verifiers to authenticate certificates.&#x20;
* Based on the algorithm that is being used for certificate generation, the certificate can be verified by the verifier.

### Sample Payload

```
{
   "@context":[
      "https://www.w3.org/2018/credentials/v1",
      "https://cowin.gov.in/credentials/vaccination/v1" 
   ],
   "type":[
      "VerifiableCredential",
      "ProofOfVaccinationCredential"
   ],
   "credentialSubject":{
      "type":"Person",
      "id":"19882120590",
      "refId":"77889950",
      "name":"Juan Dela Cruz ",
      "gender":"Female",
      "age":"33",
      “dob”:””,
      "nationality":"India",
      "address":{
         "streetAddress":"114/1/15,Horahena Road, Kottawa",
         "streetAddress2":"",
         "district":"colombo",
         "city":"",
         "addressRegion":"Western",
         "addressCountry":"IN",
         "postalCode":"121212"
      }
   },
   "issuer":"https://cowin.gov.in/",
   "issuanceDate":"2021-06-28T07:21:39.684Z",
   "evidence":[
      {
         "id":"https://cowin.gov.in/vaccine/448086902",  
         "feedbackUrl":"https://cowin.gov.in/?448086902",
         "infoUrl":"https://cowin.gov.in/?448086902", 
         "certificateId":"448086902",
         "type":[
            "Vaccination"
         ],
         "batch":"batch-01",
         "vaccine":"Pfizer",
         "manufacturer":"US",
         "date":"2021-06-28T05:30:28.187Z",
         "effectiveStart":"2021-04-21",
         "effectiveUntil":"2022-04-21",
         "dose":1,
         "totalDoses":2,
         "verifier":{
            "name":"ss"
         },
         "facility":{
            "name":"MOH Gothatuwa",
            "address":{
               "streetAddress":"df",
               "streetAddress2":"",
               "district":"wew",
               "city":"",
               "addressRegion":"w",
               "addressCountry":"IN",
               "postalCode":"121212"
            }
         }
      }
   ],
   "nonTransferable":"true",
   "proof":{
   "type":"RsaSignature2018",
      "created":"2021-06-28T07:21:39Z",
      "verificationMethod":"did:india",
      "proofPurpose":"assertionMethod",
      "jws":"eyJhbGciOiJQUzI1NiIsImI################4v_Gq6tIkDfhQQ"
   }
}
```

* Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code) to know more about what data set goes inside the QR code.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC’s EU-DCC Adapter Service

Conversion utility for generating EU-DCC compliant QR code

## **What will it cover?**

* [What is DIVOC’s EU-DCC adapter service?](#what-is-divocs-eu-dcc-adapter-service)&#x20;
* [How does the conversion utility work?](#how-does-the-conversion-utility-work)&#x20;
* [References:](#references)

&#x20;             [1. DIVOC’s EU-DCC adapter service: Technical details ](#1.-divocs-eu-dcc-adapter-service-technical-details)

&#x20;             [2. EU’s technical specification for third-countries](#eu-technical-specifications-for-third-countries)&#x20;

## **What is DIVOC’s EU-DCC adapter service?**

DIVOC is an open-source platform that can be used to issue and verify certificates that are consistent with WHO’s minimum data set specifications. Digital certificates issued by DIVOC are based on the globally accepted [**W3C Verifiable Credential Data Model**](https://www.w3.org/TR/vc-data-model/)**.** Besides the native DIVOC COVID-19 certificate format, DIVOC has enabled an adapter that can convert a native W3C DIVOC issued certificate QR into an EU Digital COVID Certificate (DCC)-compliant QR code.

### **Need for the EU-DCC adapter service**

* The EU has published technical and operational [**specifications**](https://ec.europa.eu/health/system/files/2021-07/covid-certificate_equivalence-decision_en_0.pdf) for third countries to onboard the EU gateway and facilitate smooth travel for their citizens by enabling digital verification of citizens’ COVID-19 vaccine certificates issued by the home country.
* The key design principles on which DIVOC has been built are 'interoperability' and 'coexistence.' The EU-DCC adapter has been developed to ensure interoperability and verifiability of the DIVOC’s natively issued certificates with EU verifier apps.
* This utility was required to facilitate restriction-free travel for residents from DIVOC’s adopter countries by enabling conversion of a DIVOC-issued vaccine certificate to an EU-DCC QR code.

### &#x20;                   **Sample EU-DCC certificate PDF template**

![](/files/wIiqlButFeFVZxwmHhfP)

## How does the conversion utility work?

* The utility is an on-demand service enabled by the DIVOC platform. The service can be triggered by using an “export as” function or calling an API for the EU adapter service. The service uses DIVOC’s “fetch service” to fetch an already issued, digitally signed DIVOC certificate post the holder authentication. Once the W3C JSON is fetched, the adapter takes inputs on holder details, vaccine event, and issuer information from the JSON and converts it into an EU-DCC QR code. The EU-DCC QR payload is then digitally signed using the ECDSA cryptographic signature algorithm. DIVOC facilitates the digital signing of the QR via a self-signing process, by using a DIVOC generated public-private key pair. Alternatively, it also supports signing the QR code using a public-private key pair issued by a country’s root certificate authority.

### **Steps to generate an EU-DCC compliant QR code**

1. To generate a valid EU-DCC compliant COVID-19 certificate for travel into the EU member states, the authorised user (certificate holder) can first provide the enrollment code (of his/her COVID-19 certificate that was generated by the issuing authority) via the national system used by the country to download these certificates.
2. To ensure the privacy and security of the certificate holder, DIVOC authenticates the user via a “mobile OTP” or a “user-password” authentication method.
3. DIVOC’s certificate fetch service uses the enrollment code to fetch the correct certificate from the certificate registry.
4. DIVOC then uses the EU-DCC conversion utility to convert the original W3C JSON payload into an EU-DCC compliant payload.
5. The payload is structured and encoded as a CBOR with a COSE digital signature. This is commonly known as a “CBOR Web Token (CWT)” and is defined in [**RFC 8392**](https://datatracker.ietf.org/doc/html/rfc8392). The payload is transported in a hcert claim.
6. This payload is encoded in a QR code and signed using the ECDSA signing method.
7. DIVOC also supports the generation of a PDF template, as defined by the adopter country. Hence, after a successful conversion process, an EU-DCC certificate document (encompassing both, the EU-DCC QR code as well as the PDF template) is generated.
8. The user can then download the EU-DCC certificate onto their mobile phone or export the same to an integrated digital wallet platform, authorised by the adopter country.

### **Sample EU payload**

```
{
	1: "IN"
	6: 1635179074, 
	4: 1735179074,
	-260: {
		1: {
			"ver": "1.0.0", 
			"nam": {
				"fn": "Doe",
				"gn": "John"
			},
			"dob": "1986",
			"v": [{
				"tg": "840539006", 
				"vp": "1119349007", 
				"mp": "Covishield", 
				"ma": "ORG-100001981", 
				"dn": 1, 
				"sd": 2, 
				"dt": "2021-10-17", 
				"co": "IN", 
				"is": "Govt Of India", 
				"ci": "URN:UVCI:01:IN:331936150"
			}]
		}
	}
}
```

## **References**

### 1. DIVOC’s EU-DCC adapter service: Technical details

* Click on the following URL to see the API details: [**https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../main/interfaces/certificate-api.yaml**](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../main/interfaces/certificate-api.yaml)
* [**https://github.com/Path-Check/dcc-sdk.js**](https://github.com/Path-Check/dcc-sdk.js) SDK has been used to generate a CBOR/COSE-based verifiable QR credential from the EU certificate payload.

### 2. EU technical specification for third-countries:

* Click [**here**](https://ec.europa.eu/info/live-work-travel-eu/coronavirus-response/safe-covid-19-vaccines-europeans/eu-digital-covid-certificate_en) to know more about the EU digital green certificate.
* You can check the EU specifications for onboarding third-countries by clicking on the following link: [**https://ec.europa.eu/health/system/files/2021-07/covid-certificate\_equivalence-decision\_en\_0.pdf**](https://ec.europa.eu/health/system/files/2021-07/covid-certificate_equivalence-decision_en_0.pdf).
* Click [**here**](https://ec.europa.eu/health/publications/third-country-covid-certificate-equivalence-decision-checklist_en) to see third country COVID-19 certificate equivalence decision checklist.&#x20;
* List of all EU specifications are given [**here**](https://ec.europa.eu/health/ehealth-digital-health-and-care/ehealth-and-covid-19_en).&#x20;
* To check the JSON specifications, click on the link mentioned below: [**https://ec.europa.eu/health/system/files/2021-06/covid-certificate\_json\_specification\_en\_0.pdf**](https://ec.europa.eu/health/system/files/2021-06/covid-certificate_json_specification_en_0.pdf)**.**
* For QR code specifications, click on the following link: [**https://ec.europa.eu/health/system/files/2022-02/digital-covid-certificates\_v3\_en\_0.pdf**](https://ec.europa.eu/health/system/files/2022-02/digital-covid-certificates_v3_en_0.pdf).
* To know the value sets for EU Digital COVID Certificates, click [**here**](https://ec.europa.eu/health/publications/value-sets-eu-digital-covid-certificates-update_en).
* Guidelines on verifiable vaccination certificates - basic interoperability elements, can be accessed [**here**](https://ec.europa.eu/health/publications/guidelines-verifiable-vaccination-certificates-basic-interoperability-elements_en).

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC’s SHC Adapter Service

Conversion utility for issuing a Smart Health Card (SHC) compliant QR code

## What will it cover?

* [Overview of the Smart Health Card specification](#overview-of-the-smart-health-card-specification)
* [What is DIVOC’s Smart Health Card adapter?](#what-is-divocs-shc-adapter-service)&#x20;
* [How does the conversion utility work?](#how-does-the-conversion-utility-work)&#x20;
* [References:](#references)&#x20;

&#x20;            \- [Technical specification](#technical-specification)

## **Overview of the Smart Health Card specification**

A Smart Health Card (SHC) is a globally popular HL7 FHIR (Fast Healthcare Interoperability Resources) and [**W3C verifiable credential standards**](https://www.w3.org/TR/vc-data-model/) - based open standard for generating tamper-proof health credentials.

* An SHC provides a framework that facilitates the generation, storing and verification of the SHC holder’s clinical information.
* To enable people to access a digital record of their COVID-19 vaccine history, SHCs ascertaining an individual’s vaccination and test result status, have been rolled out in US-States (California, Colorado, Connecticut, Delaware, Hawaii, Illinois, New York, and 9 others), Canada, and Japan.
* You can find the registry of verified Smart Health Card issuers for vaccinators [**here**](https://www.commontrustnetwork.org/verifier-list) and [**here**](https://smarthealth.cards/en/issuers.html).

| Information an SHC can contain         | Information an SHC cannot contain |
| -------------------------------------- | --------------------------------- |
| Legal name and date of birth           | Phone number                      |
| Clinical information                   | Address                           |
| Tests: Date, manufacturer, and result  | Government-issued identifier      |
| Vaccinations: type, date, and location | Any other health information      |

&#x20;                                          *(Information courtesy* [***SMART Health Card***](https://smarthealth.cards/en/)*)*

* To understand how they work and where they can be used, click [**here**](https://smarthealth.cards/en/) and [**here**](https://smarthealthit.org/health-cards/).

## What is DIVOC’s SHC adapter service?

Besides it’s native COVID-19 certificate schema, the DIVOC platform has also developed an adapter service to convert a native DIVOC W3C-JSON certificate into a Smart Health Card-compliant QR code.

### **Need for the SHC-Adapter service**

* This utility was required to facilitate restriction-free international travel for residents from DIVOC’s adopter countries by enabling conversion of a DIVOC issued vaccine certificate to an SHC-QR code.
* The key design principles on which DIVOC has been built are “interoperability” and “coexistence.” The SHC adapter service has been developed to ensure interoperability and verifiability of the DIVOC’s natively issued certificates with the multiple verifier apps used in the SHC adopter countries.

## **How does the conversion utility work?**

DIVOC’s adapter issues a digital certificate, as per the SHC data model, and is presented as a signed-QR code. When a source system calls DIVOC’s SHC adapter API, the following steps are undertaken;

* DIVOC first checks within the certificate registry (using the beneficiary enrolment code, passed from the source system) to see if a certificate is present for the given beneficiary.
* If present within the certificate registry, it fetches the respective certificate and then converts the native DIVOC W3C certificate to a SHC-certificate ([**https://build.fhir.org/ig/HL7/fhir-shc-vaccination-ig/**](https://build.fhir.org/ig/HL7/fhir-shc-vaccination-ig/)) using a custom-built npm module.
* This SHC-certificate payload is then signed and the resulting JWS is used to create a QR code (using the open-source [**https://github.com/Path-Check/shc-sdk.js**](https://github.com/Path-Check/shc-sdk.js) library).
* It returns the generated QR code or the full-certificate PDF (including the signed-QR), based on type parameters.
* The source system can then allow the download of the generated SHC-QR certificate onto a beneficiary’s mobile phone or allow the export to a beneficiary’s digital wallet platform.

## **References**

### **Technical specification**

* To know more on SHC specification, click [**https://spec.smarthealth.cards/**](https://spec.smarthealth.cards/).
* You can check the SHC vaccination and testing implementation guide [**here**](https://build.fhir.org/ig/HL7/fhir-shc-vaccination-ig/).

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Adding a User Type in DIVOC

## Overview

The document will cover steps on how to add a new user.

## Steps to add a user&#x20;

### Step 1:&#x20;

Login to keycloak (demo URL: [**https://demo-divoc.egov.org.in/auth**](https://demo-divoc.egov.org.in/auth/)). Click on the administration console and enter the username and password. Next, click on the "sign in" button.

![](/files/wRIc6ueiiF1xyYYYWYtZ)

### Step 2:

Go to the 'manage' section, and click on 'users.'

![](/files/1DJJiw4MS9toNf59SEUh)

### Step 3:

Click on "add user" to create a new user.

![](/files/qJBT45AsKWwpn2xbbAhu)

### Step 4:

Enter your mobile number as the user name, and click on save.

![](/files/Udm2laiE08xkLAAbd0rn)

### Step 5:

Click on 'attributes' and add the required attribute (mobile\_number) by clicking on the 'add' button. Next, click on 'save.'

![](/files/z6E5RwFLaBRQkut7Z6I2)

### Step 6:

Click on "role mappings" and select the type of role you want to add from the list of "client roles."

![](/files/Xy09nsDQzXJLheve1OAP)

### Step 7:

Select the role you want to add from the list of "available roles" and click on "add selected." Once you have completed this step, you will see the new user in the "assigned roles" section.

![](/files/lLrJ6hk06hdzG0WFfm8L)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Printing Certificates at a Facility

The document will cover steps on how to print certificates at a facility.

## Create a user type

The facility/system administrator can print the certificates. The administrator can also create a user type (from the list of available roles) for a person who will print the certificates. Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/adding-a-user-type-in-divoc) to add a user type in DIVOC.&#x20;

## Steps to print certificates at a facility

### Step 1:

Once the user has been created, the person can log in to the portal using the following URL: [**https://demo-divoc.egov.org.in/portal**](https://demo-divoc.egov.org.in/portal). Enter the registered mobile number, and the OTP, and click on "login to portal."

![](/files/PxULNgDeY0o9D9xyU2uc)

### Step 2:

Enter the phone number and the date of birth given during registration. Next, click on the search button.&#x20;

![](/files/750prjjWohKqEVVqvWtO)

You will see the name(s) displayed on the screen.&#x20;

![](/files/HU9YNJghFs4yIyFRLjXZ)

### Step 3:

Click on 'print' to print the certificate. To save it on your desktop/laptop, click on 'save.'

![](/files/HP8VJfq9XLsv6FfrCtkC)

### Step 4:

Log out once you have printed the required certificate(s).

![](/files/AkH6cPpKzC5QtmkwZxVw)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Normal QR Code Versus Signed/Verifiable QR Code

You have likely seen a lot more QR codes over the last two years due to the pandemic. At many restaurants, for example, which are keen not to share physical menus, customers scan a QR code with their phone camera to open a website for the online menu.

## **What is a QR code?**

* Short for Quick Response, a QR code stores all kinds of information that can be scanned and accessed by a digital device such as your smartphone.
* The machine-readable format can also be printed on a piece of paper.
* While barcodes are one-dimensional, which means that information can be scanned only horizontally, QR codes are two-dimensional. Hence, information on a QR code can be read both horizontally and vertically, allowing it to store more data.
* QR codes allow you to download applications, join WiFi networks without having to key in any password, scan coupons, and much more. They can be embedded on a company’s website to gather feedback, facilitate registrations, collect customer data, and order details. QR codes can be used on physical products as a way to provide more information.
* QR codes are also used for document verification to check if a credential is genuine. This has gained popularity during the pandemic with some countries opting for QR code-based vaccination certificates to open up travel and business.

## Normal QR Code vs Signed/Verifiable QR Code

| Normal QR Code                                                                                                                                                                                                                                                                                                                                                | Signed/Verifiable QR Code                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| A normal QR code contains information that can be read and understood by any QR code viewer. They typically carry a URL and a scan of such QR codes reroutes to a separate site.                                                                                                                                                                              | A signed QR code encodes the verifiable data set or information within the QR itself, rather than on any website.                                                                                                                                                                                                                                               |
| In a normal QR code, information can be edited and altered, making the verification process untrustworthy and vulnerable to hacking. To address this issue, a signed or verifiable QR code is used, particularly in the case of sensitive information. Sensitive data could be your bank details, educational details, and medical information, among others. | The information is secure and cannot be altered or tampered with, nor can it be scanned and accessed by everyone. This is because the original data/information in the QR code is digitally signed.                                                                                                                                                             |
|                                                                                                                                                                                                                                                                                                                                                               | **Example:** In the case of COVID-19 vaccination certificates, for example, data identifying the vaccination event and the beneficiary is encoded within a QR code and then digitally signed, making it tamper-proof. Only a verifying authority with a secure key can validate this information accurately by matching it with the signing key of the QR code. |

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# What Information Goes Into a QR Code?

A vaccination certificate is a proof that a person has received the shot to protect them from an infectious disease such as COVID-19 or the flu. We have given below the type of information (mandatory and optional) that should be there in a QR code-based COVID-19 vaccination certificate, as specified by the World Health Organisation (WHO).

<table><thead><tr><th width="150">Requirement status for proof of vaccination</th><th width="183">DDCC label</th><th width="226">DIVOC label</th><th width="300">Description and definition</th><th width="172">Data type/format</th><th>Examples</th></tr></thead><tbody><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Name</td><td>recipientName</td><td>The full name of the vaccinated person.</td><td>String</td><td>John Tom Brown</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Date of birth</td><td>recipientDOB</td><td>The vaccinated person's date of birth (DOB) if known. If unknown, use the assigned DOB for administrative purposes.</td><td>Date</td><td>1998-01-05</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Unique identifier (primary identifier of the beneficiary)</td><td>preEnrollmentCode</td><td>Unique identifier for the vaccinated person, according to the policies applicable in each country. There can be more than one unique identifier used to link records (example: national ID, health ID, immunisation information system ID, and medical record ID). All the certificate IDs will be linked to the beneficiary's preEnrollmentCode.</td><td>UUID</td><td></td></tr><tr><td>Optional</td><td></td><td>recipientIdentity</td><td>To be used only if there is a need to share/print an additional national ID. By default, it is set as 'null' in DIVOC's case. The above field covers this as well.</td><td>Alpha number</td><td>Driving license</td></tr><tr><td>Optional</td><td>Sex</td><td>recipientGender</td><td>Documentation of a specific instance of sex information for the vaccinated person.</td><td>Male/female/other</td><td></td></tr><tr><td>Optional</td><td></td><td>recipientMobileNumber</td><td></td><td>Numeric</td><td>18767778888</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Vaccine type or prophylaxis</td><td>Need to incorporate in the payload.</td><td>Generic description of the vaccine or vaccine sub-type, such as  COVID-19 mRNA vaccine, HPV vaccine.</td><td>Coding - ICD 11</td><td></td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Vaccine brand</td><td>vaccinationName</td><td>The brand or trade name used to refer to the vaccine received.</td><td>String</td><td>Pfizer</td></tr><tr><td>Optional</td><td>Vaccine manufacturer</td><td>vaccinationManufacturer</td><td>Name of the manufacturer of the vaccine received, such as Serum institute of India, or AstraZeneca. If the vaccine manufacturer is unknown, a market authorisation holder is needed.</td><td>String</td><td>ABC company</td></tr><tr><td>Optional</td><td>Vaccine market authorisation holder</td><td></td><td>Name of the market authorisation holder of the vaccine received. If the market authorisation holder is unknown, a vaccine manufacturer is required. This is needed only if the manufacturer is not listed in the WHO EUL (Emergency Use Listing Procedure) list.</td><td>String</td><td></td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Vaccine batch number</td><td>vaccinationBatch</td><td>Batch number or lot number of the vaccine.</td><td>String</td><td>4121Z104</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Date of vaccination</td><td>vaccinationDate</td><td>Date on which the vaccine was administered.</td><td>Date</td><td>2021-11-30</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Dose number</td><td>vaccinationDose</td><td>Vaccine dose number.</td><td>Quantity</td><td>1, 2</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Total doses</td><td>vaccinationTotalDoses</td><td>Total expected doses as defined by a member state's care plan and immunisation programme policies.</td><td>Quantity</td><td>For Pfizer and BioNTech, the total expected doses are two.</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Country of vaccination</td><td>facilityCountry</td><td>The country where a person was vaccinated.</td><td>Code</td><td>JAM = Jamaica</td></tr><tr><td>Optional</td><td>Administering centre</td><td>facilityName</td><td>The name or identifier of the vaccination facility responsible for administering the vaccination.</td><td>String</td><td>Falmouth Health Centre</td></tr><tr><td>Optional</td><td>Health worker identifier</td><td>vaccinatorName/ID</td><td>If the country does not have a national identifier, you can share the name of the vaccinator.</td><td>ID</td><td>National ID of the vaccinator</td></tr><tr><td>Optional</td><td>Disease or agent targeted</td><td>Available as a certificate header and not as a data element in the current certificate API payload.</td><td>Name of the disease vaccinated against (such as COVID-19). We recommend that you can have it as a data element within the payload.</td><td>Coding</td><td>Certificate header: COVID-19 Vaccination Certificate.</td></tr><tr><td>Optional</td><td>Due date of the next dose</td><td></td><td>Only implemented for India.</td><td>Date - YYYYMM/DD</td><td></td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Certificate issuer</td><td>Issuer (available in the output)</td><td>The authority or authorised organisation that issued the vaccination certificate.</td><td>String</td><td>Ministry of Health &#x26; Wellness, Jamaica</td></tr><tr><td><mark style="color:orange;">Mandatory</mark></td><td>Health certificate identifier</td><td>Certificate ID (available in the output)</td><td>Unique identifier used to associate the vaccination status represented in a paper vaccination card.</td><td>ID</td><td>378855845</td></tr><tr><td>Optional</td><td>Certificate valid from</td><td>vaccinationEffectiveStart</td><td>Date on which the certificate became valid. No health or clinical inferences should be made from this date.</td><td>Date</td><td>2021-11-30</td></tr><tr><td>Optional</td><td>Certificate valid to</td><td>vaccinationEffectiveEnd</td><td>Last date on which the certificate is valid. No health or clinical inferences should be made from this date.</td><td>Date</td><td>2022-11-30</td></tr><tr><td>Optional</td><td>Certificate schema version</td><td></td><td>Only if schema versions are maintained.</td><td></td><td></td></tr></tbody></table>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# WHO Master Vaccine Checklist

This is a list of COVID-19 vaccines approved by the World Health Organisation (WHO) and used by  DIVOC's adopter countries.

| Vaccine Name                  | Manufacturer Name (human readable)                     | Vaccine Code (ICD 11) (vaccine type/prophylaxis; normally in QR) | Vaccine Type/Prophylaxis (human readable description) |
| ----------------------------- | ------------------------------------------------------ | ---------------------------------------------------------------- | ----------------------------------------------------- |
| Zycov-D                       | Cadila Healthcare                                      | XM6AT1                                                           | COVID-19 vaccine, DNA-based                           |
| Covaxin                       | Bharat-Biotech                                         | XM1NL1                                                           | COVID-19 vaccine, inactivated virus                   |
| Covishield                    | Serum Institute Of India                               | XM9QW8                                                           | COVID-19 vaccine, non-replicating viral vector        |
| Sputnik V                     | Gamaleya-Research-Institute                            | XM9QW8                                                           | COVID-19 vaccine, non-replicating viral vector        |
| Pfizer-BioNTech or Comirnaty  | Biontech Manufacturing GmbH                            | XM0GQ8                                                           | COVID-19 vaccine, RNA-based                           |
| Janssen                       | Janssen-Cilag International                            | XM0CX4                                                           | COVID-19 vaccine, replicating viral vector            |
| Moderna or Modema or Spikevax | Moderna Biotech Spain S.L.                             | XM0GQ8                                                           | COVID-19 vaccine, RNA-based                           |
| AstraZeneca or Vaxzevria      | AstraZeneca AB                                         | XM9QW8                                                           | COVID-19 vaccine, non-replicating viral vector        |
| Sinovac or Coronavac          | Sinovac-Biotech                                        | XM1NL1                                                           | COVID-19 vaccine, inactivated virus                   |
| BBIBP- CorV or Sinopharm      | China Sinopharm International Corp. - Beijing location | XM1NL1                                                           | COVID-19 vaccine, inactivated virus                   |
| Convidecia                    | CanSino Biologics                                      | XM9QW8                                                           | COVID-19 vaccine, non-replicating viral vector        |
| Corbevax                      | Biological E. Limited (BioE)                           | XM5JC5                                                           | COVID-19 vaccine, virus protein subunit               |
| Novavax/Covovax NVX - CoV2373 | Novavax                                                | XM5JC5                                                           | COVID-19 vaccine, virus protein subunit               |
| Gemcovac-19                   | Gennova Biopharmaceuticals Limited                     | XM0GQ8                                                           | COVID-19 Vaccine, Lyophilized mRNA vaccine            |

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# EU Master Vaccine Checklist

This is a list of COVID-19 vaccines approved by the European Union (EU) and used by DIVOC's adopter countries.

| Vaccine Type/Prophylaxis (ICD 11) | EU Prophylaxis/Vaccine Type | Vaccine Name (varies for vaccinating system of countries) | EU Vaccine code (goes into the QR code) | Manufacturer Name (human readable)                     | Manufacturer Name (human readable) EU Manufacturer Code |
| --------------------------------- | --------------------------- | --------------------------------------------------------- | --------------------------------------- | ------------------------------------------------------ | ------------------------------------------------------- |
| COVID-19 vaccine                  | J07BX03                     | Zycov-D vaccine                                           | Not in the EU list                      | Cadila Healthcare                                      | Not in the EU list                                      |
| COVID-19 vaccine                  | J07BX03                     | Covaxin                                                   | Covaxin                                 | Bharat-Biotech                                         | Bharat-Biotech                                          |
| COVID-19 vaccine                  | J07BX03                     | Covishield                                                | Covishield                              | Serum Institute Of India                               | ORG-100001981                                           |
| COVID-19 vaccine                  | J07BX03                     | Sputnik V                                                 | Sputnik V                               | Gamaleya-Research-Institute                            | Gamaleya-Research-Institute                             |
| COVID-19 vaccine                  | J07BX03                     | Pfizer-BioNTech or Comirnaty                              | EU/1/20/1528                            | Biontech Manufacturing GmbH                            | ORG-100030215                                           |
| COVID-19 vaccine                  | J07BX03                     | Janssen                                                   | EU/1/20/1525                            | Janssen-Cilag International                            | ORG-100001417                                           |
| COVID-19 vaccine                  | J07BX03                     | Moderna or Modema or Spikevax                             | EU/1/20/1507                            | Moderna Biotech Spain S.L.                             | ORG-100031184                                           |
| COVID-19 vaccine                  | J07BX03                     | AstraZeneca or Vaxzevria                                  | EU/1/21/1529                            | AstraZeneca AB                                         | ORG-100001699                                           |
| COVID-19 vaccine                  | J07BX03                     | Sinovac or Coronavac                                      | CoronaVac                               | Sinovac-Biotech                                        | Sinovac- Biontech                                       |
| COVID-19 vaccine                  | J07BX03                     | BBIBP- CorV                                               | BBIBP- CorV                             | China Sinopharm International Corp. - Beijing location | ORG-100020693                                           |
| COVID-19 vaccine                  | J07BX03                     | Convidecia                                                | Convidecia                              | CanSino Biologics                                      | ORG-100013793                                           |
| COVID-19 vaccine                  | J07BX03                     | Corbevax                                                  | Not in the EU list                      | Biological E. Limited (BioE)                           | Not in the EU list                                      |
| COVID-19 vaccine                  | J07BX03                     | Novavax/Covovax NVX - CoV2373                             | NVX - CoV2373                           | Novavax                                                | ORG-100032020                                           |

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC Architecture

Highly flexible and configurable, DIVOC’s architecture is designed to accommodate changes and allow the addition of new capabilities and functionalities. For example, during a vaccination campaign, you can configure vaccines, vaccination frequency, approved facilities, trained vaccinators, certificate templates, and authentication mechanisms, among others. Built on <mark style="color:orange;">**open source and open standards**</mark>, the DIVOC architecture ensures <mark style="color:orange;">**privacy and security by design**</mark>.

## **Architecture highlights**

![Logical architecture ](/files/GhPsZsOvVEDoTN7wbCyV)

* DIVOC has been built using a micro-services architecture with open API integration capabilities. It can be hosted on the cloud and on-premise cloud.
* It is built on top of the generalised electronic registry and the credentialing framework is available under Sunbird Registry and Credentialing, as well as on-premise bare metal servers.
* DIVOC’s modules can work in various combinations based on a country’s requirements as well as end-user needs. Accordingly, countries can use specific or all micro-services.

![Deployment architecture](/files/dHHfSzwTrRoQYlpC4wS9)

* It is designed to plug and play with different certificate distribution schemes, such as printed with QR code, digital using smartphones, SMS/email attachments, digital lockers, etc.
* Allows interoperability with various ID, payment, and other systems.

![Component architecture](/files/1lw6beMqpedvtTheOcJN)

* DIVOC is designed to cater to the diversity of use cases in terms of the choice of the facility (such as government and to private facilities) across geographies within a country; choice of payment (government funding, employer funding, or individual funding, among others); and choice of IDs (digital IDs, and mobile numbers.
* The platform is extensible. For example, many parts of the software can be extended, as well as replaced with country-specific components without having to customise. This, in turn, facilitates easy upgradability.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Installation

Setting up DIVOC in your country to orchestrate a new health programme? The guide covers everything you need to know to implement DIVOC. The different sections are meant for people who are involved in planning and managing the various aspects of the implementation process, as well as those involved in the technical work. The documents cover the various steps and configurations required. <br>

## What will it cover?

### A. [Skills needed to set up DIVOC](/v2-2/platform/installation/skills-needed-to-set-up-divoc)

### B. [Implementation Checklist](/v2-2/platform/installation/implementation-checklist)

### C. [Setting up DIVOC](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster)

### D. [Backup & Restore: Postgres, Clickhouse, and Kafka](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/backup-and-restore-postgres-clickhouse-kafka-and-redis)

### E. [Infrastructure Recovery](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/infrastructure-recovery)

### F. [Server Hardening](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/server-hardening)

### G. [Certificate and Verification Component](/v2-2/platform/configuration/configuring-the-certification-and-verification-component)&#x20;

### H. [Platform Policy Guidelines](/v2-2/community/about-project-team/platform-policy-guidelines)

### I. [Privacy Policy Recommendations](/v2-2/community/about-project-team/privacy-policy-recommendations)

Each country will have its own set of requirements in line with globally accepted standards for issuing certificates. The guides will walk you through:

* [How to configure the certificate component?](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates)&#x20;
* [How to set up the verification portal for your implementation?](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/how-to-set-up-the-verification-portal-for-implementation)
* [How to configure the update certificate API?](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/how-to-configure-the-update-certificate-api)

&#x20;&#x20;

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Skills needed to set up DIVOC

The technical skills required by DIVOC adopters vary and are based on the level of changes they intend to make to the core DIVOC platform.

## What does this section cover?

* Skills needed for a simple setup scenario&#x20;
* Skills needed for a complex setup scenario

## **Simple setup: Only setup and configuration**

This includes:

1. Setting up infrastructure on cloud or on-premise.&#x20;
2. Deployment of application components/services.
3. Configuration of components to connect to work as a single system:

&#x20;                       \- Configure templates, such as data import templates for facility registry.   &#x20;

&#x20;                       \- Keycloak to change OTP-based login in keycloak to password-based login.&#x20;

&#x20;                       \- Configuration of certificate templates.

## Skills the team should have:

* Experience in setting up Kubernetes cluster / Docker-based deployment.&#x20;
* Experience in setting up and configuring platforms such as Kafka, Redis, Postgres, and Keycloak.&#x20;
* Experience in HTML templates design.

## Complex setup: Setup, configuration, and customisation

Customise DIVOC as per the country-specific requirements and its implementation need, such as:

1. Changes in registry schema: This includes changes in the type of information being captured on various events.&#x20;
2. UI: This includes applying country-specific branding on the various UI pages of the portal.&#x20;
3. Add and Update APIs: This includes the introduction of new API calls within as well as with third-party applications, such as integration with the supply chain system to provide updates on the stock used at the facility level. It also involves updating existing APIs, such as changing mandatory fields to non-mandatory in API payloads and changing response structure, among others.

## Skills the team should have:

* Experience in technologies such as HTML, Jquery, React, JavaScript for UI level changes.&#x20;
* Experience in technologies such as Go for API-related changes.&#x20;
* Experience in OpenSaber and Postgres for registry-related changes.&#x20;
* Experience in integrating platform services used in selected components for customisation and implementation.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Implementation Checklist

## Overview

This checklist can help you plan your implementation. Besides technical and operational details, it covers server setup, QR code, certificate template changes, and updating and verifying certificates.

## QR code

<table><thead><tr><th width="194.6056391555013">Section</th><th>Checklist</th><th>Description</th></tr></thead><tbody><tr><td>Create QR code</td><td>Change the value in context section.</td><td><ul><li>This value indicates the release version of the certificate schema. This versioning will support in introducing validations (if required) on certificates generated in previous schemas such as  "revoking/invalidating certificates with previous schema."  </li><li>For example: For release 1 - It could be "https://moh.prod/credentials/vaccination/v1" and for release 2 - It could be "https://moh.prod/credentials/vaccination/v2" </li><li>For more details and sample QR code content, click <a href="/pages/qWCwnFlpijWa8e2x1Gx5"><strong>here</strong></a>.</li></ul></td></tr><tr><td>Create QR code</td><td>The Id field in "credentialSubject" should be in a URI format.</td><td><ul><li>If certify request payload contains “identity,” set it to “did::” </li><li>Else, use the “preEnrollmentCode” and set it to “did::”</li></ul></td></tr><tr><td>Create QR code</td><td>The date value passed in the payload in the 'vaccination' section should match with the value in the 'evidence' section of the QR code and it should follow the YYYY-MM-DD format.</td><td><p></p><ul><li>The format is as per the WHO-DDCC data standard.</li><li>Validate the date value as it may have impact due to the vaccination system (external), and DIVOC is deployed in servers with a different timezone (UTC). Border cases to be checked as day/date may change.</li></ul></td></tr><tr><td>Create QR code</td><td>The 'issuer' is mapped correctly as per the requirement.</td><td><ul><li>This value indicates the certificate issuing authority. The issuer field is configured in the platform. For more details, click <a href="/pages/F8Bi4WGjBvYEShHArOpE"><strong>here</strong></a>. </li><li>The value of this change to be added here: <a href="https://github.com/egovernments/DIVOC/blob/main/docker-compose.yml#L295"><strong>https://github.com/egovernments/DIVOC/blob/main/docker-compose.yml#L295</strong></a>.</li></ul></td></tr><tr><td>Create QR code</td><td>The vaccine list provided by a country is available in the master list. </td><td><ul><li>The vaccines provided in the platform are listed <a href="/pages/O2sGDWtfuNAeKegG4BH1"><strong>here</strong></a>. </li><li>Validate and add to the list if a new vaccine needs to be added in the list - <a href="https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/ICD.json"><strong>https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/ICD.json</strong></a> and <a href="https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/VACCINE_ICD.json"><strong>https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/VACCINE_ICD.json</strong></a>.</li></ul></td></tr><tr><td>Create QR code</td><td>The vaccine and prophylaxis mapping is as per the country requirements.</td><td><ul><li>The vaccines provided in the platform are listed <a href="/pages/O2sGDWtfuNAeKegG4BH1"><strong>here</strong></a>.</li><li>Validate and add to the list if a new vaccine need to be added in the list - <a href="https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/ICD.json"><strong>https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/ICD.json</strong></a> and <a href="https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/VACCINE_ICD.json"><strong>https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/VACCINE_ICD.jso</strong></a>.</li></ul></td></tr><tr><td>Create QR code</td><td>Vaccine 'manufacturer,' 'batch' values shared in the payload are getting reflected in the QR code.</td><td><ul><li>The sample payload and the QR code is mentioned <a href="/pages/1wl22x0hGGUUFaAf5COy"><strong>here</strong></a>. </li></ul></td></tr><tr><td>Create QR code</td><td>The addressCountry value in the evidence section captures the 3-digit country code from here.</td><td><ul><li>The values are set here: <a href="https://github.com/egovernments/DIVOC/blob/main/docker-compose.yml#L214"><strong>https://github.com/egovernments/DIVOC/blob/main/docker-compose.yml#L214</strong></a>.</li></ul></td></tr><tr><td>Create QR code</td><td>'dose' and "totalDoses" value shared in the payload are getting reflected in the QR code.</td><td><ul><li>For more details, click <a href="/pages/qWCwnFlpijWa8e2x1Gx5"><strong>here</strong></a>. </li></ul></td></tr><tr><td>Create QR code</td><td>The 'Id' part in the evidence section is in a URI format.</td><td><ul><li>For example, 'id' - "<a href="https://divoc.dev/vaccine/710208455">https://divoc.dev/vaccine/</a>&#x3C;certificateId>" Where - certificateId is unique for each certificate. If the certificate gets updated, a new certificate will be generated with a new certificate Id for the same event. For more details, click <a href="/pages/qWCwnFlpijWa8e2x1Gx5"><strong>here</strong></a>.  </li></ul></td></tr></tbody></table>

## Update changes

| Section              | Checklist                                                                                                                                                                                                                                                          | Description                                                                                                                                                                                                                                                                                           |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Update a certificate | Update limits are set according to a country's requirement. The details to configure the update limit are available [**here**](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/how-to-configure-the-update-certificate-api). |                                                                                                                                                                                                                                                                                                       |
| Revoke a certificate | The system should be able to generate a certificate for a revoked dose.                                                                                                                                                                                            | For example, if the dose 2 certificate has been removed from the system, the user should be allowed to generate another/correct dose 2 certificate. Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/revoking-a-divoc-certificate) to know more on DIVOC's revocation services. |
| Revoke a certificate | The system is only revoking the earlier certificate which existed for the specified dose value.                                                                                                                                                                    | For example, If dose 2 certificate has been removed from the system, the user should be allowed to generate another/correct dose 2 certificate.                                                                                                                                                       |

## Certificate template changes

| Section                     | Checklist                                                                                                                                                                                                                                                       | Description                                                                                                                                                                                                                                                            |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Create certificate template | QR code size is 2.5x2.5 inch on a printed A4 size paper.                                                                                                                                                                                                        | Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate/divocs-certificate-generation-service-how-does-it-work) to see a sample certificate.                                                                               |
| Create certificate template | Does the printed certificate show the minimal values based on the WHO-DDCC standard?                                                                                                                                                                            | Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code) to see the  list of minimal data set as per the WHO-DDCC standard.                                                                                        |
| Create certificate template | If the certificate template has a table which shows the current and the previous dose details (if available), then the table should be configured to be scalable to capture details of both the current and the previous dose details in required combinations. | For example, the certificate template should have only one template file to refer to for the generation of certificates with a combination of dose 1, dose 1 and 2, dose 1, 2, and 3, etc. This should be up to a maximum feasible limit based on the template design. |

## Certificate verification

| Section              | Checklist                                                                                                               | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Verify a certificate | SSL certificate has been applied to the verification page.                                                              | The SSL certificate is required to open the camera in the browser.                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Verify a certificate | The verification page has been configured to provide the necessary guidance to the user for the verification component. | <p>For example, the verification page should include following messaging/guidelines/ information: </p><ul><li>How to scan the QR code? </li><li>The possible reason for showing a certificate as invalid or revoked? </li><li>What steps to follow if a certificate is shown as invalid or revoked, such as information of the contact person. </li><li>The possible reason if the verification component is not able to scan the QR code? Click <a href="/pages/NgFHtKsMHzZEIPpazy8O"><strong>here</strong></a> for more details. </li></ul> |

## Setting up the server&#x20;

| Section      | Checklist                                                                                                                                                                                                                                                                                                                              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Server setup | Infrastructure estimation guide.                                                                                                                                                                                                                                                                                                       | For example, if the load goes up, then the system should be configured for scalability.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Server setup | <p>The production environment should support the following recommendations: </p><ul><li>Data backup policy.</li><li>Authentication and password management.</li><li>Error handling and logging. </li><li>System configurations.</li><li>Click <a href="/pages/84WO7cDVfVd9Swp3IZeC"><strong>here</strong></a> to know more. </li></ul> |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Server setup | System is configured to handle network crash or infrastructure crash.                                                                                                                                                                                                                                                                  | For example, if the master/slave nodes go down, are they configured to autostart/auto-deploy? Click [**here**](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/infrastructure-recovery) to know more.                                                                                                                                                                                                                                                                                                                           |
| Server setup | The system should be configured to backup. Click [**here**](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/backup-and-restore-postgres-clickhouse-kafka-and-redis) to know more.                                                                                                                                           | <p></p><p>Back up of the following:</p><ol><li>DB/server setup.</li><li>Online/offline line.</li></ol>                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Server setup | Click [**here**](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/server-hardening) to read the server hardening guidelines.                                                                                                                                                                                                 | <p>The section should cover activities to be performed to ensure security of data and application. </p><p>For example, </p><ul><li>Restrict all the non-essential ports on the public network. Ports of DB/other inter-components should only be accessible within the application. Click <a href="https://github.com/egovernments/DIVOC/blob/main/docker-compose.yml"><strong>here</strong></a> for the list of ports. </li><li>Firewall controls should also be in place, such as  user management, for better access control.</li></ul> |

## Generating signed key pairs

| Section             | Checklist                                | Description                                                                                                                                           |
| ------------------- | ---------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| Sign key generation | It is done as per the standard.          | Click [**here**](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/generating-signed-key-pairs) for more details. |
| Sign key generation | Keycloak configuration related to DIVOC. | Click [**here**](/v2-2/platform/tech-docs/setting-up-divoc-development-environment) for more details.                                                 |

## Operational checklist

| Section        | Checklist                                                                                                                                                                                                       | Description                                                                                                                                                                                                                                        |
| -------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Privacy policy | Privacy policies are based on the recommendations made to implementing partners. They are advised to share it with citizens regarding their personally identifiable information and how it is managed in DIVOC. | As the application contains citizen data, access rights (read/write) should be agreed between parties for staging/production/other environments. Click [**here**](/v2-2/community/about-project-team/privacy-policy-recommendations) to know more. |

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Setting Up DIVOC in k8 Cluster

This section will cover the following:

* [How to install DIVOC](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/how-to-install-divoc)
* [Backup & Restore: Postgres, Clickhouse, Kafka, & Redis](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/backup-and-restore-postgres-clickhouse-kafka-and-redis)
* [Infrastructure Recovery](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/infrastructure-recovery)
* [Server Hardening](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/server-hardening)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# How to Install DIVOC

## Assumptions&#x20;

* Use a Debian-based Linux distribution (preferably Ubuntu)&#x20;
* Experience in running simple shell and bash commands

## Pre-requisites&#x20;

* Debian-based OS (Ubuntu)&#x20;
* sshpass&#x20;
* Ansible&#x20;
* GIT&#x20;
* kubectl&#x20;
* List of servers and ability to access them using key-based authentication&#x20;
* Server map to list servers against software&#x20;
* Access to the DIVOC installer repository&#x20;
* Access to the implementation-specific DIVOC code

## Suggested servers for HA setup&#x20;

The sizing and count of the servers can change based on the load requirements. However,  for a truly HA setup, the following are the minimum requirements:

### Postgres and etcd&#x20;

3 servers for HA setup: one master and 2 replicas. The etcd cluster can also be set up on the same servers.&#x20;

### Kubernetes&#x20;

6 servers: 3 for control plane (or master node can be relatively smaller sized instances) and 3 worker nodes (for deploying the application).

### Kafka and Zookeeper&#x20;

3 servers containing both Zookeeper and Kafka (Ideally Zookeeper and Kafka need to be installed on separate servers but we should be fine to install both on the same machine).

### Redis&#x20;

3 servers&#x20;

### Elasticsearch&#x20;

3 servers&#x20;

#### Docker-registry&#x20;

1 server

## Overview&#x20;

There are three scripts that need to be run to complete the DIVOC installation process:

1. Installing the prerequisites and setting various hardware clusters as detailed above.&#x20;
2. Building the pushing the docker images to the appropriate registry.&#x20;
3. Deploying code from the registry into Kubernetes cluster.

## Installation dependencies

1. Clone the repository available at [**https://github.com/egovernments/divoc-installer**](https://github.com/egovernments/divoc-installer).&#x20;
2. Create an inventory file from the sample inventory file located at [**https://github.com/egovernments/divoc-installer/blob/master/inventory.example.ini**](https://github.com/egovernments/divoc-installer/blob/master/inventory.example.ini).
3. Add the inventory details as per the comments present in the file.&#x20;
4. Run the install.sh present within the divoc-installer with the elevated privileges (we can also use nohup for running in the background):

{% hint style="info" %}
sudo sh install.sh -i \<path to inventory file>
{% endhint %}

* It will install the dependencies like python3, ansible, etc.&#x20;
* It will install the applications and configure them on the servers mentioned in the inventory file.

## Build Docker images&#x20;

* Run the build.sh file with elevated privileges.&#x20;

{% hint style="info" %}
&#x20;sudo sh build.sh -d \<IP Address of Docker Registry> -r \<GIT REPO URL>
{% endhint %}

* Default values for the Docker repository are from dockerhub.
* The Default value for the GIT repo is the master branch of the [**https://github.com/egovernments/DIVOC.git**](https://github.com/egovernments/DIVOC).

## **Install DIVOC application**

1. The sample default Kubernetes deployment files are available at [**https://github.com/egovernments/divoc-installer/tree/master/kube-deployment-config-example**](https://github.com/egovernments/divoc-installer/tree/master/kube-deployment-config-example)**.**
2. Make a copy of the folder and change the internal script files to have the following configurations. It is recommended that you maintain your own configuration in a separate Github repository so that you have version control and backup (you require only the example folder, not the full repository).

&#x20;     a. Within the divoc-installer director, open the divoc-config.yaml file present within the deployment configuration directory and make the following changes:    &#x20;

&#x20;           \- DB\_HOST&#x20;

&#x20;         \- DB\_USER&#x20;

&#x20;         \- DB\_PASS&#x20;

&#x20;         \- DB\_PORT&#x20;

&#x20;         \- KAFKA\_BOOTSTRAP\_SERVERS&#x20;

&#x20;         \- REDIS\_URL&#x20;

&#x20;         \- CLICKHOUSE\_URL&#x20;

&#x20;         \- AUTH\_PRIVATE\_KEY&#x20;

&#x20;         \- AUTH\_PUBLIC\_KEY&#x20;

&#x20;         \- CERTIFICATE\_NAMESPACE&#x20;

&#x20;         \- CERTIFICATE\_NAMESPACE\_V2&#x20;

&#x20;         \- CERTIFICATE\_CONTROLLER\_ID&#x20;

&#x20;         \- CERTIFICATE\_PUBKEY\_ID&#x20;

&#x20;         \- CERTIFICATE\_DID&#x20;

&#x20;         \- CERTIFICATE\_ISSUER&#x20;

&#x20;         \- CERTIFICATE\_BASE\_URL&#x20;

&#x20;         \- CERTIFICATE\_FEEDBACK\_BASE\_URL&#x20;

&#x20;         \- CERTIFICATE\_INFO\_BASE\_URL&#x20;

&#x20;         \- CERTIFICATE\_PUBLIC\_KEY&#x20;

&#x20;         \- CERTIFICATE\_PRIVATE\_KEY&#x20;

&#x20;         \- CITIZEN\_PORTAL\_URL

&#x20;     b. Modify registry-deployment.yaml to change the following:

&#x20;         \- connectionInfo\_password&#x20;

&#x20;         \- connectionInfo\_uri&#x20;

&#x20;         \- connectionInfo\_username&#x20;

&#x20;         \- elastic\_search\_enabled&#x20;

&#x20;         \- registry\_base\_apis\_enable&#x20;

&#x20;         \- taskExecutor\_index\_queueCapacity&#x20;

&#x20;         \- auditTaskExecutor\_queueCapacity&#x20;

&#x20;         \- Signature\_enabled&#x20;

&#x20;     c. Modify keycloak-deployment.yaml to add the following information:

&#x20;         \- DB\_ADDR&#x20;

&#x20;         \- DB\_DATABASE&#x20;

&#x20;          \- DB\_PASSWORD&#x20;

&#x20;          \- DB\_PORT&#x20;

&#x20;          \- DB\_USER&#x20;

&#x20;          \- DB\_VENDOR&#x20;

&#x20;          \- KEYCLOAK\_USER&#x20;

&#x20;          \- KEYCLOAK\_PASSWORD&#x20;

&#x20;          \- ENABLE\_OTP\_MESSAGE&#x20;

&#x20;          \- KAFKA\_BOOTSTRAP\_SERVERS&#x20;

3\. Run the deploy script to deploy the application on Kubernetes.

{% hint style="info" %}
sudo sh deploy.sh -i \<path to inventory file> -p \<Directory containing Kubernetes Config files> -d \<Private Docker Registry IP> -k \<Kube Master Node IP> -s \<Key file to access Kube Master>
{% endhint %}

## Post installation

### Create indexes on database tables&#x20;

The indexes for efficient querying of the database tables do not get automatically created and hence need to be created manually. Execute registry\_index.sql is present within the DIVOC codebase on the database. A restart of the registry service is required for this change to reflect.&#x20;

**Note:** Database tables are only created when the first API request is received.  &#x20;

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Backup & Restore: Postgres, Clickhouse, Kafka, & Redis

## Overview

This is the generic solution for backup and restore. Depending on the backup strategy used, the tools might change.

## Backing up and restoring Postgres&#x20;

* The Ansible script will automatically configure pg\_basebackup, pgbackrest, wal-g and other recovery tools. For the sake of simplicity, we can use pg\_dump and pg\_restore.
* The following command takes a backup. This will create a compressed tarball backup in the directory mentioned:

{% hint style="info" %}
pg\_dump -h 192.168.0.100 -U postgres -F c remote\_db1 > remote\_db1.tar
{% endhint %}

* This can be scheduled using a cron as shown below:

{% hint style="info" %}
0 0 \* \* \* \<path to backup script>
{% endhint %}

* Pg\_basebackup is installed along with psql client

{% hint style="info" %}
sudo apt install postgresql-client
{% endhint %}

* You can restore from pg\_dump as follows:

{% hint style="info" %}
pg\_restore -h 192.168.0.100 -U postgres -F -C -d db1 < db1.tar
{% endhint %}

## Backing up and restoring Clickhouse

The plan is to use [clickhouse-backup](https://github.com/AlexAkulov/clickhouse-backup), which is open sourced under the liberal MIT license. This tool has the ability to create archived backups and upload them to NFS, S3, GCS, AZBlob, SFTP and other remote data repositories.

* Download the latest release from [https://github.com/AlexAkulov/clickhouse-backup/releases](<https://github.com/AlexAkulov/clickhouse-backup/releases&#xA;>)
* Untar the archive

{% hint style="info" %}
tar -zxvf clickhouse-backup.tar.gz
{% endhint %}

* Create a configuration file as follows, call it config.ini

{% hint style="info" %}
general:\
&#x20; remote\_storage: none                   # REMOTE\_STORAGE, if \`none\` then \`upload\` and  \`download\` command will fail\
&#x20; max\_file\_size: 1073741824            # MAX\_FILE\_SIZE, 1G by default, useless when upload\_by\_part is true, use for split data parts files by archives \
&#x20; disable\_progress\_bar: true            # DISABLE\_PROGRESS\_BAR, show progress bar during upload and download, have sense only when \`upload\_concurrency\` and \`download\_concurrency\` equal 1\
&#x20; backups\_to\_keep\_local: 0              # BACKUPS\_TO\_KEEP\_LOCAL, how much newest local backup should keep, 0 mean all created backups will keep on local disk\
&#x20;                                                          \# you shall to run \`clickhouse-backup delete local \<backup\_name>\` command to avoid useless disk space allocations\
&#x20; backups\_to\_keep\_remote: 0          # BACKUPS\_TO\_KEEP\_REMOTE, how much newest backup should keep on remote storage, 0 mean all uploaded backups will keep on remote storage.\
&#x20;                                                          \# if old backup is required for newer incremental backup, then it will don't delete. Be careful with long incremental backup sequences.

log\_level: info                                     # LOG\_LEVEL\
&#x20; allow\_empty\_backups: false           # ALLOW\_EMPTY\_BACKUPS\
&#x20; download\_concurrency: 1               # DOWNLOAD\_CONCURRENCY, max 255\
&#x20; upload\_concurrency: 1                    # UPLOAD\_CONCURRENCY, max 255\
&#x20; restore\_schema\_on\_cluster: ""        # RESTORE\_SCHEMA\_ON\_CLUSTER, execute all schema related SQL queryes with \`ON CLUSTER\` clause as Distributed DDL, look to \`system.clusters\` table for proper cluster name\
&#x20; upload\_by\_part: true                        # UPLOAD\_BY\_PART\
&#x20; download\_by\_part: true                   # DOWNLOAD\_BY\_PART\
clickhouse:\
&#x20; username: default                            # CLICKHOUSE\_USERNAME\
&#x20; password: ""                                     # CLICKHOUSE\_PASSWORD\
&#x20; host: localhost                                 # CLICKHOUSE\_HOST\
&#x20; port: 9000                                        # CLICKHOUSE\_PORT, don't use 8123, clickhouse-backup doesn't support HTTP protocol\
&#x20; disk\_mapping: {}                              # CLICKHOUSE\_DISK\_MAPPING, use it if your system.disks on restored servers not the same with system.disks on server where backup was created\
&#x20; skip\_tables:                                     # CLICKHOUSE\_SKIP\_TABLES\
&#x20;   \- system.\*\
&#x20;   \- INFORMATION\_SCHEMA.\*\
&#x20;   \- information\_schema.\*\
&#x20; timeout: 5m                                    # CLICKHOUSE\_TIMEOUT\
&#x20; freeze\_by\_part: false                     # CLICKHOUSE\_FREEZE\_BY\_PART\
&#x20; secure: false                                   # CLICKHOUSE\_SECURE, use SSL encryption for&#x20;

connect

skip\_verify: false                               # CLICKHOUSE\_SKIP\_VERIFY\
&#x20; sync\_replicated\_tables: true         # CLICKHOUSE\_SYNC\_REPLICATED\_TABLES\
&#x20; log\_sql\_queries: true                      # CLICKHOUSE\_LOG\_SQL\_QUERIES, enable log clickhouse-backup SQL queries on \`system.query\_log\` table inside clickhouse-server\
&#x20; debug: false                                    # CLICKHOUSE\_DEBUG\
&#x20; config\_dir:      "/etc/clickhouse-server"              # CLICKHOUSE\_CONFIG\_DIR\
&#x20; restart\_command: "systemctl restart clickhouse-server" # CLICKHOUSE\_RESTART\_COMMAND, this command use when you try to restore with --rbac or --config options\
&#x20; ignore\_not\_exists\_error\_during\_freeze: true # CLICKHOUSE\_IGNORE\_NOT\_EXISTS\_ERROR\_DURING\_FREEZE, allow avoiding backup failures when you often CREATE / DROP tables and databases during backup creation, clickhouse-backup will ignore \`code: 60\` and \`code: 81\` errors during execute \`ALTER TABLE ... FREEZE\`\
azblob:\
&#x20; endpoint\_suffix: "core.windows.net" # AZBLOB\_ENDPOINT\_SUFFIX\
&#x20; account\_name: ""                                # AZBLOB\_ACCOUNT\_NAME\
&#x20; account\_key: ""                                   # AZBLOB\_ACCOUNT\_KEY\
&#x20; sas: ""                                         # AZBLOB\_SAS\
&#x20; use\_managed\_identity: false    # AZBLOB\_USE\_MANAGED\_IDENTITY\
&#x20; container: ""                               # AZBLOB\_CONTAINER\
&#x20; path: ""                                       # AZBLOB\_PATH\
&#x20; compression\_level: 1                 # AZBLOB\_COMPRESSION\_LEVEL\
&#x20; compression\_format: tar           # AZBLOB\_COMPRESSION\_FORMAT\
&#x20; sse\_key: ""                                 # AZBLOB\_SSE\_KEY\
&#x20; buffer\_size: 0                             # AZBLOB\_BUFFER\_SIZE, if less or eq 0 then calculated as max\_file\_size / 10000, between 2Mb and 4Mb\
&#x20; max\_buffers: 3                           # AZBLOB\_MAX\_BUFFERS\
s3:\
&#x20; access\_key: ""                               # S3\_ACCESS\_KEY\
&#x20; secret\_key: ""                                # S3\_SECRET\_KEY\
&#x20; bucket: ""                                      # S3\_BUCKET\
&#x20; endpoint: ""                                   # S3\_ENDPOINT\
&#x20; region: us-east-1                          # S3\_REGION\
&#x20; acl: private                                    # S3\_ACL\
&#x20; assume\_role\_arn: ""                      # S3\_ASSUME\_ROLE\_ARN\
&#x20; force\_path\_style: false                 # S3\_FORCE\_PATH\_STYLE\
&#x20; path: ""                                          # S3\_PATH\
&#x20; disable\_ssl: false                           # S3\_DISABLE\_SSL\
&#x20; compression\_level: 1                     # S3\_COMPRESSION\_LEVEL\
&#x20; compression\_format: tar              # S3\_COMPRESSION\_FORMAT\
&#x20; sse: ""                                            # S3\_SSE, empty (default), AES256, or aws:kms\
&#x20; disable\_cert\_verification: false  . # S3\_DISABLE\_CERT\_VERIFICATION\
&#x20; storage\_class: STANDARD           # S3\_STORAGE\_CLASS\
&#x20; concurrency: 1                              # S3\_CONCURRENCY\
&#x20; part\_size: 0                                   # S3\_PART\_SIZE, if less or eq 0 then calculated as max\_file\_size / 10000\
&#x20; debug: false                                 # S3\_DEBUG\
gcs:\
&#x20; credentials\_file: ""                       # GCS\_CREDENTIALS\_FILE\
&#x20; credentials\_json: ""                     # GCS\_CREDENTIALS\_JSON\
&#x20; bucket: ""                                     # GCS\_BUCKET\
&#x20; path: ""                                         # GCS\_PATH\
&#x20; compression\_level: 1                   # GCS\_COMPRESSION\_LEVEL\
&#x20; compression\_format: tar            # GCS\_COMPRESSION\_FORMAT\
&#x20; debug: false                                # GCS\_DEBUG\
cos:\
&#x20; url: ""                                           # COS\_URL\
&#x20; timeout: 2m                                # COS\_TIMEOUT\
&#x20; secret\_id: ""                                # COS\_SECRET\_ID\
&#x20; secret\_key: ""                             # COS\_SECRET\_KEY\
&#x20; path: ""                                       # COS\_PATH\
&#x20; compression\_format: tar          # COS\_COMPRESSION\_FORMAT\
&#x20; compression\_level: 1                # COS\_COMPRESSION\_LEVEL\
ftp:\
&#x20; address: ""                                # FTP\_ADDRESS\
&#x20; timeout: 2m                              # FTP\_TIMEOUT\
&#x20; username: ""                            # FTP\_USERNAME\
&#x20; password: ""                            # FTP\_PASSWORD\
&#x20; tls: false                                   # FTP\_TLS\
&#x20; path: ""                                     # FTP\_PATH\
&#x20; compression\_format: tar         # FTP\_COMPRESSION\_FORMAT\
&#x20; compression\_level: 1               # FTP\_COMPRESSION\_LEVEL\
&#x20; debug: false                             # FTP\_DEBUG\
sftp:\
&#x20; address: ""                               # SFTP\_ADDRESS\
&#x20; username: ""                            # SFTP\_USERNAME\
&#x20; password: ""                            # SFTP\_PASSWORD\
&#x20; key: ""                                       # SFTP\_KEY\
&#x20; path: ""                                     # SFTP\_PATH\
&#x20; concurrency: 1                         # SFTP\_CONCURRENCY    \
&#x20; compression\_format: tar         # SFTP\_COMPRESSION\_FORMAT\
&#x20; compression\_level: 1               # SFTP\_COMPRESSION\_LEVEL\
&#x20; debug: false                             # SFTP\_DEBUG\
api:\
&#x20; listen: "localhost:7171"            # API\_LISTEN\
&#x20; enable\_metrics: true               # API\_ENABLE\_METRICS\
&#x20; enable\_pprof: false                 # API\_ENABLE\_PPROF\
&#x20; username: ""                            # API\_USERNAME, basic authorization for API endpoint\
&#x20; password: ""                            # API\_PASSWORD\
&#x20; secure: false                            # API\_SECURE, use TLS for listen API socket\
&#x20; certificate\_file: ""                     # API\_CERTIFICATE\_FILE\
&#x20; private\_key\_file: ""                    # API\_PRIVATE\_KEY\_FILE\
&#x20; create\_integration\_tables: false # API\_CREATE\_INTEGRATION\_TABLES\
&#x20; allow\_parallel: false                  # API\_ALLOW\_PARALLEL, could allocate much memory and spawn go-routines, don't enable it if you not sure
{% endhint %}

* Ensure configuration under clickhouse and general section of the configuration file. The rest are not mandatory.&#x20;
* If automated remote upload functionality is needed, the appropriate section needs to be filled in: sftp, ftp, s3, GCS, AZBlob, etc.&#x20;
* The following command can be run:

{% hint style="info" %}
sh \<path-to-cllickhouse-backup-dir>/bin/clickhouse-backup create -C \<path to config.ini>
{% endhint %}

* The following is the list of possible commands which can be executed:

{% hint style="info" %}
COMMANDS:\
&#x20;tables          Print list of tables\
&#x20;create          Create new backup\
&#x20;create\_remote   Create and upload\
&#x20;upload          Upload backup to remote storage\
&#x20;list            Print list of backups\
&#x20;download        Download backup from remote storage\
&#x20;restore         Create schema and restore data from backup\
&#x20;restore\_remote  Download and restore\
&#x20;delete          Delete specific backup\
&#x20;default-config  Print default config\
&#x20;print-config    Print current config\
&#x20;clean           Remove data in 'shadow' folder from all \`path\` folders available from \`system.disks\`\
&#x20;server          Run API server\
&#x20;help, h         Shows a list of commands or help for one command
{% endhint %}

## Backing up and restoring Kafka

* Backup zookeeper state data

&#x20;     \- Go to file&#x20;

{% hint style="info" %}
kafka/config/zookeeper.properties&#x20;
{% endhint %}

&#x20;     \- Copy location of dataDir property (typically, /tmp/zookeeper)&#x20;

&#x20;     \- Run the following command:

{% hint style="info" %}
tar -czf /home/kafka/zookeeper-backup.tar.gz /tmp/zookeeper/\*
{% endhint %}

* Backup Kafka topics and messages

&#x20;     \- Go to the file kafka/config/server.properties

&#x20;     \- Copy location of log.dirs (typically, /tmp/kafka-logs)

&#x20;     \- Stop Kafka:&#x20;

{% hint style="info" %}
sudo systemctl stop kafka
{% endhint %}

&#x20;     \- Login as kafka user:&#x20;

{% hint style="info" %}
sudo -iu kafka
{% endhint %}

&#x20;     \- Run the following command:

{% hint style="info" %}
tar -czf /home/kafka/kafka-backup.tar.gz /tmp/kafka-logs/\*
{% endhint %}

* Restore zookeeper

&#x20;     \- sudo systemctl stop kafka&#x20;

&#x20;     \- sudo systemctl stop zookeeper&#x20;

&#x20;     \- sudo -iu kafka&#x20;

&#x20;     \- rm -r /tmp/zookeeper/\*&#x20;

&#x20;     \- tar -C /tmp/zookeeper -xzf /home/kafka/zookeeper-backup.tar.gz &#x20;

&#x20;       \--strip-components 2

* Restore kafka

&#x20;     \- rm -r /tmp/kafka-logs/\*&#x20;

&#x20;     \- tar -C /tmp/kafka-logs -xzf /home/kafka/kafka-backup.tar.gz --strip-components 2&#x20;

&#x20;     \- sudo systemctl start kafka&#x20;

&#x20;     \- sudo systemctl start zookeeper

* Verification of Restoration

&#x20;     \- \~/kafka/bin/kafka-console-consumer.sh --bootstrap-server localhost:9092 --topic

&#x20;        BackupTopic --from-beginning

## Backing up and restoring Redis&#x20;

Redis provides an in-built command to save a backup.

* Install redis-cli using

{% hint style="info" %}
sudo apt install redis-cli
{% endhint %}

* The following command takes a backup of the redis-server:

{% hint style="info" %}
echo save | redis-cli -u redis\://\<user>:\<pass>@\<host>:\<port> >> /tmp/redis-backup.log
{% endhint %}

* This will save the backup as dump.rdb within:

{% hint style="info" %}
/var/lib/redis
{% endhint %}

Restoration can be done in the following way:

* Locate the redis data directory, typically:

{% hint style="info" %}
/var/lib/redis
{% endhint %}

* Move the dump.rdb file into this folder&#x20;
* Start redis server
* This will ensure that data is restored automatically

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Infrastructure Recovery

## Kubernetes&#x20;

### Recovering control plane&#x20;

* To recover from broken nodes in the control plane, use the "[**recover-control-plane.yml**](https://github.com/egovernments/divoc-installer/blob/master/ansible-cookbooks/kubernetes/recover-control-plane.yml)" playbook.
* Back up what you can.
* Provision new nodes to replace the broken ones.
* Place the surviving nodes of the control plane first in the "etcd" and "kube\_control\_plane" groups.
* Add the new nodes below the surviving control plane nodes in the "etcd" and "kube\_control\_plane" groups.

### Examples of what broken means in this context:

* One or more bare metal node(s) suffer from unrecoverable hardware failure.&#x20;
* One or more node(s) fail during patching or upgrading.&#x20;
* Etcd database corruption.&#x20;
* Other node-related failures that leave your control plane degraded or nonfunctional.
* **Note:** You need at least one functional control plane node to be able to recover using this method. If all control planes go down, there is no scope of recovery, and you will have to reinstall Kubernetes. Typically, even if the control plane goes down, the application still functions. Kubernetes functions like scaling, creating new pods, upgrading deployments, etc. will not work. The application, as is available, will continue to function.

### Runbook

* Move any broken etcd nodes into the "broken\_etcd" group, make sure the "etcd\_member\_name" variable is set.
* Move any broken control plane nodes into the "broken\_kube\_control\_plane" group.
* Run the playbook with **--limit etcd,kube\_control\_plane**, and increase the number of etdc retries by setting **-e etcd\_retries=10** or something even larger. The amount of retries required is difficult to predict.
* Once you are done, you should have a fully working control plane again.

### **Recover from the last quorum**

* The playbook attempts to figure out if the etcd quorum is intact. If the quorum is lost, it will attempt to take a snapshot from the first node in the "etcd" group and restore from that.&#x20;
* To restore from an alternate snapshot, set the path to that snapshot in the "etcd\_snapshot" variable: **-e etcd\_snapshot=/tmp/etcd\_snapshot**.

### **Adding or replacing a node**

#### Removal of first kube\_control\_plane and etcd-master&#x20;

Currently, you cannot remove the first node in your kube\_control\_plane and etcd-master list. If you still want to remove this node, you have to do the following:

1. Modify the order of your control plane list by pushing your first entry to any other position, such as if you want to remove node-1 of the following example:

{% hint style="info" %}
**children:**\
&#x20;   **kube\_control\_plane:**\
&#x20;     **hosts:**\
&#x20;       **node-1:**\
&#x20;       **node-2:**\
&#x20;       **node-3:**\
&#x20;   **kube\_node:**\
&#x20;     **hosts:**\
&#x20;       **node-1:**\
&#x20;       **node-2:**\
&#x20;       **node-3:**\
&#x20;   **etcd:**\
&#x20;     **hosts:**\
&#x20;       **node-1:**\
&#x20;       **node-2:**\
&#x20;       **node-3:**
{% endhint %}

2\. Run **upgrade-cluster.yml or cluster.yml.** After this, you are good to go on with the removal.

### **Adding or replacing a worker node**

1. Add a new node to the inventory.
2. Run **scale.yml**. You can use **--limit=NODE\_NAME** to limit Kubespray to avoid disturbing other nodes in the cluster. Before using **--limit,** run playbook **facts.yml** without the limit to refresh facts cache for all nodes.
3. Remove an old node with **remove-node.yml.** With the old node still in the inventory, run **remove-node.yml**. You need to pass **-e node=NODE\_NAME** to the playbook to limit the execution to the node being removed. If the node you want to remove is not online, you should add **reset\_nodes=false and allow\_ungraceful\_removal=true** to your extra-vars: **-e node=NODE\_NAME -e reset\_nodes=false -e allow\_ungraceful\_removal=true**. Use this flag even when you remove other types of nodes like a control plane or etcd nodes.
4. Remove node from the inventory.

### **Adding or replacing a control plane node**

1. Append the new host to the inventory and run **cluster.yml**. You cannot use **scale.yml** for that.
2. In all hosts, restart **nginx-proxy pod**. This pod is a local proxy for the apiserver. Kubespray will update its static config, but it needs to be restarted to reload:

{% hint style="info" %}
docker ps | grep k8s\_nginx-proxy\_nginx-proxy | awk '{print $1}' | xargs docker restart
{% endhint %}

&#x20;3\. With the old node still in the inventory, run **remove-node.yml**. You need to pass **-e        node=NODE\_NAME** to the playbook to limit the execution to the node being removed. If the node you want to remove is not online, you should add **reset\_nodes=false** and **allow\_ungraceful\_removal=true** to your extra-vars.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Server Hardening

This is the minimum list of hardening and other steps that need to be performed to secure the Linux server containing the DIVOC platform. The assumption is that the installation happens on a bare metal setup. While the concepts remain the same, the methodology might differ for commercial cloud setups.&#x20;

## Check for open ports

* Identifying open connections to the internet is a critical mission.

{% hint style="info" %}
netstat -antp
{% endhint %}

* Once you have identified the open ports, you can stop/purge the applications which keep unnecessary ports open.&#x20;
* The only acceptable open ports are 22 and 443. Access to the other ports outside the Kubernetes network should be prohibited.&#x20;
* All ingress should be routed through the 443 port only as needed.

## **Secure SSH**&#x20;

SSH is secure, but we need to harden this service as well. If we can disable SSH, then the problem is solved. However, if we want to use it, we have to change the default configuration of SSH. Passwor&#x64;**-**&#x62;ased authentication should be disabled and only key-based authentication should be allowed. The steps for creating sudo users with public and private keys are as follows:

* Create a non-root sudo user

{% hint style="info" %}
adduser \<user>
{% endhint %}

* Add the user to sudo users group

{% hint style="info" %}
usermod -aG sudo \<user>
{% endhint %}

* Login to the machine as the user

{% hint style="info" %}
su - \<user>
{% endhint %}

* Create SSH directory with appropriate permissions

{% hint style="info" %}
mkdir -p $HOME/.ssh\
chmod 0700 $HOME/.ssh
{% endhint %}

* Generate a key pair for the protocol, and run:

{% hint style="info" %}
ssh-keygen -t ed25519 -C "My key for DIVOC server"
{% endhint %}

* Share the public key created with users you expect to connect to the server

{% hint style="info" %}
$HOME/.ssh/id\_ed25519.pub
{% endhint %}

* You can modify your SSH configuration to be more secure by performing the following changes to the configuration file:

{% hint style="info" %}
nano /etc/ssh/sshd\_config
{% endhint %}

* Make sure that root cannot login remotely through SSH

{% hint style="info" %}
PermitRootLogin no
{% endhint %}

* Allow some specific users

{% hint style="info" %}
AllowUsers \[username]
{% endhint %}

* Enable public key-based authentication and disable password-based authentication

{% hint style="info" %}
PubkeyAuthentication yes\
PasswordAuthentication no
{% endhint %}

* There are some additional options that must exist in the “sshd\_config” file: MaxAuthTries 5
* Finally, set the permissions on the sshd\_config file so that only root users can change its contents:

{% hint style="info" %}
chown root:root /etc/ssh/sshd\_config

chmod 600 /etc/ssh/sshd\_config
{% endhint %}

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Configuration

This section contains documents and information required to configure DIVOC

Learn how to configure DIVOC:

{% content-ref url="/pages/v7MEnMr0nEUYiN6TiVrB" %}
[Configuring the Certification and Verification Component](/v2-2/platform/configuration/configuring-the-certification-and-verification-component)
{% endcontent-ref %}

{% content-ref url="/pages/FmXmzjCwM8fTNdO0oHmx" %}
[Configuration Management Via ETCD](/v2-2/platform/configuration/configuration-management-via-etcd)
{% endcontent-ref %}

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Configuring the Certification and Verification Component

DIVOC’s certificate module has been adopted for the ongoing COVID-19 vaccination programs in multiple countries. The guide and its different sections describe the various steps that you have to follow when implementing one or more features of the certification and verification component, depending on your country’s needs.

## Country-specific requirements may include the following:

**1. Certificate Component -**

* Generate certificates&#x20;
* Update certificates&#x20;
* Revoke fake or incorrect certificates&#x20;
* Fetch certificates&#x20;
* Fetch QR code&#x20;
* Notify beneficiaries

**2. Verification component**

## What will the sections cover?

1. [Generating signed key pairs](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/generating-signed-key-pairs)
2. [How to configure the certificate generation component?](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates)&#x20;
3. [How to set up the verification portal for your implementation?](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/how-to-set-up-the-verification-portal-for-implementation)
4. [How to configure the update certificate API?](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/how-to-configure-the-update-certificate-api)
5. [Configuring environment variables in 2.0](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-environment-variables-in-2.0)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Generating Signed Key Pairs

## Certificate signing

Supported key types&#x20;

1. RSA (default)&#x20;
2. ED25519 (recommended for performance)

Environment variable configuration

{% hint style="info" %}
SIGNING\_KEY\_TYPE (possible values: RSA or ED25519)
{% endhint %}

## **Key pair configuration for DIVOC certificate**

Environment variables

{% hint style="info" %}
CERTIFICATE\_SIGNER\_PRIVATE\_KEY, CERTIFICATE\_SIGNER\_PUBLIC\_KEY
{% endhint %}

The expected values for these configurations change depending on the type of key in use:

RSA -

* Private key format: 2048 bit, PEM
* Public key format: PEM&#x20;

ED25519 -

| Key     | Format | Type   | Encoding |
| ------- | ------ | ------ | -------- |
| Private | DER    | PKCS#8 | Base58   |
| Public  | DER    | SPKI   | Base58   |

### **Reference steps for key generation**

RSA key generation using openssl

{% hint style="info" %}
openssl genrsa -out privatekey.pem 2048
{% endhint %}

{% hint style="info" %}
openssl rsa -in privatekey.pem -out publickey.pem -pubout -outform PEM
{% endhint %}

ED25519

Use an external library such as [**ed25519-verification-key-2018**](https://github.com/digitalbazaar/ed25519-verification-key-2018/) to [**generate**](https://github.com/digitalbazaar/ed25519-verification-key-2018#generating-a-new-publicprivate-key-pair) a key-pair in the required format.

## **Key pair configuration for EU certificate**

Generation of key pair for signing an EU certificate:

* Copy the certificate generation script file [**gen-dsc.sh**](https://github.com/egovernments/DIVOC/blob/main/scripts/gen-dsc.sh) and put it in the desired location.&#x20;
* Copy the certificate configuration file [**cert.conf**](https://github.com/egovernments/DIVOC/blob/main/scripts/cert.conf) and put it in the same folder where the certificate generation script was copied to.
* Open the cert.conf file and edit it according to your requirement.&#x20;

| C - Country name (2 letter code)                     | The two-letter country code where your company is legally located.                                              |
| ---------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- |
| ST - State or province name (full name)              | The state/province where your company is legally located.                                                       |
| L - Locality name (for example, city)                | The city where your company is legally located.                                                                 |
| O - Organisation name (for example, company)         | The legally registered name of your  company (for example, YourCompany, Inc.).                                  |
| OU - Organisational unit name (for example, section) | The name of your department within the organisation. (You can leave this option blank; simply press \*Enter\*.) |
| CN - Common name (for example, server FQDN)          | The fully-qualified domain name (FQDN) (for example, <http://www.example.com>).                                 |

* &#x20;Run the [**gen-dsc.sh**](https://github.com/egovernments/DIVOC/blob/main/scripts/gen-dsc.sh) file to generate the key pair for signing the EU certificate.
* For generation of RSA key pair:  `./gen-dsc.sh RSA CSR`&#x20;
* For generation of ECDSA key pair:  `./gen-dsc.sh ECDSA CSR`
* The script will generate the following 3 files:

1. *private key filename - DSC01privkey.key*&#x20;
2. *CSR filename - DSC01csr.pem CERTIFICATE key filename - DSC01cert.pem*
3. *Public key format: PEM*

### **Configuring EU certificate retrieval from the certificate-API service**

1. Generate the key pair required for signing the EU certificate and share the CSR file for signing with CA.
2. In the `divoc-config` configMap, set the following environment variables:&#x20;

* `EU_CERTIFICATE_PRIVATE_KEY` - Private key for signing the EU payload (in PKCS8 format).
* `EU_CERTIFICATE_PUBLIC_KEY` - The certificate provided by CA after signing the CSR.
* `EU_CERTIFICATE_EXPIRY`  - Expiry of the certificate in months (for example, 12).

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Configuring certificates

## Overview

This document will help an implementer configure a certificate (template and QR code) for a health event such as vaccination. This section includes configuring:

* [Generating signed key pairs](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/generating-signed-key-pairs)
* [Certificate generation request](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates/step-1-create-a-certification-generation-request)&#x20;
* [QR code section](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates/step-2-configure-the-qr-code-content)&#x20;
* [Certificate template](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates/step-3-configure-the-certificate-template)

## API&#x20;

The DIVOC platform provides API services for generating digitally verifiable QR code-based vaccination certificates. The API for certificate generation has 6 sections:

1. **PreEnrollmentCode:** This section is linked to the 'dose' in the vaccination section to uniquely identify an event. For example, beneficiary registration number (R101) and dose number (1) as (R101-1) will be used to identify the first dose event uniquely. Similarly, beneficiary registration number (R101) and dose number (2) as (R101-2) will be used to identify the second dose event uniquely.
2. **Recipient:** It contains information about the beneficiary.
3. **Vaccination:** It contains details about the vaccination event such as name, batch, and vaccination date.
4. **Vaccinator:** It contains details about the vaccinator.
5. **Facility:** It contains details about the facility where beneficiaries will get vaccinated.
6. **Meta:** It contains additional information, which is not part of the QR code, such as the number of past doses taken.&#x20;

## Sample for default certificate generation request

* You can refer to the API service call with sample data below:

```
[
    {
        "preEnrollmentCode": "62",
        "recipient": {
            "name": "Sam",
            "uhid": "abc2232",
            "dob": "1990-09-14",
            "age": "31",
            "gender": "Male",
            "nationality": "India",
            "identity": "did:in.gov.uidai.aadhaar:11112222334",
            "contact": [
                "tel:1111111313"
            ],
            "address": {
                "addressLine1": "123, Koramangala",
                "addressLine2": "",
                "district": "Bengaluru South",
                "state": "bihar",
                "pincode": "560033"
            }
        },
        "vaccination": {
            "name": "covaxin",
            "batch": "AB348FS",
            "manufacturer": "Bharat Biotech",
            "date": "2021-07-12T19:21:19.646Z",
            "effectiveStart": "2021-07-12",
            "effectiveUntil": "2021-08-12",
            "dose": 2,
            "totalDoses": 2
        },
        "vaccinator": {
            "name": "Sooraj Singh"
        },
        "facility": {
            "name": "ABCD Medical Center",
            "address": {
                "addressLine1": "123, Koramangala",
                "addressLine2": "",
                "district": "Bengaluru South",
                "state": "Karnataka",
                "pincode": "560033"
            }
        },
        "programId": "6ce74c0f-b1b5-4b20-9fa2-084acbbd857a",
        "meta": { //Meta section stored as an Object and it can contain information in    Key value pair
        }
    }
]\
```

* Refer to the /v3/certify service [**here**](https://raw.githubusercontent.com/egovernments/DIVOC/main/interfaces/../../india/interfaces/vaccination-api.yaml) for details.&#x20;
* Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code) if you want to understand the mandatory and non-mandatory information that should be there in a vaccination certificate, according to global standards.

## Key Functionalities&#x20;

* Generate configured QR code&#x20;
* Generate configured certificate template

## Prerequisite: Get details on API request and field validations

a. Please refer to the existing service details in the ‘certification’ section (/v3/certify): [**https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../india/interfaces/vaccination-api.yaml**](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../india/interfaces/vaccination-api.yaml)

b. The detailed field validations are mentioned here: [**https://github.com/egovernments/DIVOC/blob/4076e69cf152fd76dafa8a0565777895f55b1245/interfaces/vaccination-api.yaml**](https://github.com/egovernments/DIVOC/blob/4076e69cf152fd76dafa8a0565777895f55b1245/interfaces/vaccination-api.yaml)&#x20;

```
// /v3/certify:
    post:
      tags:
        - certification
      summary: Certify the one or more vaccination
      description: >-
        Certification happens asynchronously, this requires vaccinator
        authorization and vaccinator should be trained for the vaccination that
        is being certified. The payload for this API is compliant with DDCC core
        data set prescribed by WHO
      operationId: certifyV3
      parameters:
        - in: body
          name: body
          required: true
          schema:
            type: array
            items:
              $ref: '#/definitions/CertificationRequestV2' //Refer Line 722 in same file 
      responses:
        '200':
          description: OK
        '400':
          description: Invalid input
          schema:
            $ref: '#/definitions/Error'
```

## Making the changes

Click the following to see how you can make the changes:

1. [**Create a certification generation request**](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates/step-1-create-a-certification-generation-request)
2. [**Update the QR code content**](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates/step-2-configure-the-qr-code-content)
3. [**Update the certificate template**](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/configuring-certificates/step-3-configure-the-certificate-template)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Step 1: Create a certification generation request

## Example

Include the beneficiary’s parent name in the certificate. The parent’s name is “Sam Mandosa.” This is a mandatory field.

## **Steps**

**Step 1: Create a certification generation request**

a. Open this file: [**https://github.com/egovernments/DIVOC/blob/main/backend/vaccination\_api/pkg/certify\_handler.go**](https://github.com/egovernments/DIVOC/blob/main/backend/vaccination_api/pkg/certify_handler.go)

b. Add a parameter in the function “convertToCertifyUploadFields” called RecipientParentName.

```
func convertToCertifyUploadFields(data *Scanner) *db.CertifyUploadFields {
	return &db.CertifyUploadFields{
		PreEnrollmentCode:         data.Text("preEnrollmentCode"),
		RecipientName:             data.Text("recipientName"),
RecipientParentName:        data.Text("recipientParentName"),
		RecipientMobileNumber:  data.Text("recipientMobileNumber"),
		RecipientDOB:              data.Text("recipientDOB"),
		RecipientGender:           data.Text("recipientGender"),
		RecipientNationality:      data.Text("recipientNationality"),
		RecipientIdentity:         data.Text("recipientIdentity"),
		RecipientAge:              data.Text("recipientAge"),
		RecipientAddressLine1:  data.Text("recipientAddressLine1"),
		RecipientAddressLine2:  data.Text("recipientAddressLine2"),
		RecipientDistrict:         data.Text("recipientDistrict"),
		RecipientState:            data.Text("recipientState"),
		RecipientPincode:          data.Text("recipientPincode"),
		VaccinationBatch:          data.Text("vaccinationBatch"),
		VaccinationDate:           data.Text("vaccinationDate"),
		VaccinationDose:           data.Text("vaccinationDose"),
		VaccinationTotalDoses:   data.Text("vaccinationTotalDoses"),
	VaccinationEffectiveStart:data.Text("vaccinationEffectiveStart"),
	VaccinationEffectiveEnd:data.Text("vaccinationEffectiveEnd"),
	VaccinationManufacturer:   data.Text("vaccinationManufacturer"),
		VaccinationName:           data.Text("vaccinationName"),
		VaccinatorName:            data.Text("vaccinatorName"),
		FacilityName:              data.Text("facilityName"),
		FacilityAddressLine1:      data.Text("facilityAddressLine1"),
		FacilityAddressLine2:      data.Text("facilityAddressLine2"),
		FacilityDistrict:          data.Text("facilityDistrict"),
		FacilityState:             data.Text("facilityState"),
		FacilityPincode:           data.Text("facilityPincode"),
	}
}
```

c. Add RecipientParentName in the function “createCertificate” to make the field mandatory.

```
recipient := &models.CertificationRequestRecipient{
		Name: &certifyData.RecipientName,
		Age:  recipientAge,
		Address: &models.CertificationRequestRecipientAddress{
			AddressLine1: &certifyData.RecipientAddressLine1,
			AddressLine2: certifyData.RecipientAddressLine2,
			District:     &certifyData.RecipientDistrict,
			Pincode:      &certifyData.RecipientPincode,
			State:        &certifyData.RecipientState,
		},
		Contact:     contact,
		Dob:         dateAdr(strfmt.Date(dob)),
		Gender:      &certifyData.RecipientGender,
		Nationality: &certifyData.RecipientNationality,
		ParentName: &certifyData.RecipientParentName,
		Identity:    &certifyData.RecipientIdentity,
	}
```

d. If the data is uploaded via CSV, then add this column to the CSV template for this field. Open “[**application-default.yml**](https://github.com/egovernments/DIVOC/edit/main/backend/vaccination_api/config/application-default.yml)” and update the certificate section in this file.

![](/files/wFn8SaseD94xwtT6uTLH)

**Note:**

* As a standard practice, we recommend you to update the informative files mentioned in step 1 of this section.
* Make sure the name matches exactly with the name convertToCertifyUploadFields function that you edited in step 1.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Step 2: Configure the QR code content

The template for the QR code generation is provided [**here**](https://github.com/egovernments/DIVOC/blob/main/vaccination-context/vaccination-context.js) under vaccination-context. The QR code structure must match the vaccination-context. Any updates made in the QR code content must reflect in the vaccination-context.js file.

**Steps:**

a. Open the file [**main.js**](https://github.com/egovernments/DIVOC/blob/main/backend/certificate_signer/main.js).

b. Go to the function transformW3 and add the fields according to your requirement. This function will read the data received from the certificate generation API call and convert it into QR code Json format.

```markup
function transformW3(cert, certificateId) {
  const certificateType = R.pathOr('', ['meta', 'certificateType'], cert);
  const namespace = certificateType === CERTIFICATE_TYPE_V3 ? CERTIFICATE_NAMESPACE_V2 : CERTIFICATE_NAMESPACE;
  const recipientIdentifier = R.pathOr('', ['recipient', 'identity'], cert);
  const preEnrollmentCode = R.pathOr('', ['preEnrollmentCode'], cert);
  const recipientName = R.pathOr('', ['recipient', 'name'], cert);
  const recipientGender = R.pathOr('', ['recipient', 'gender'], cert);
  const recipientNationality = R.pathOr('', ['recipient', 'nationality'], cert);
  const recipientParentName = R.pathOr('', ['recipient', 'parentName'], cert);
```

c. Add the newly-added field to the data variable

```
let data = {
    namespace, recipientIdentifier, preEnrollmentCode, recipientName, recipientGender, recipientDob, recipientAge, recipientNationality, recipientParentName, recipientAddressLine1, recipientAddressLine2, recipientAddressDistrict, recipientAddressCity, recipientAddressRegion, recipientAddressCountry, recipientAddressPostalCode,
    issuer, issuanceDate, evidenceId, InfoUrl, feedbackUrl,
    certificateId, batch, vaccine, icd11Code,  prophylaxis, manufacturer, vaccinationDate, effectiveStart, effectiveUntil, dose, totalDoses,
    verifierName,
    facilityName, facilityAddressLine1, facilityAddressLine2, facilityAddressDistrict, facilityAddressCity, facilityAddressRegion, facilityAddressCountry, facilityAddressPostalCode
  };
```

**Note:**&#x20;

Certain constant values are also listed in the [**main.js**](https://github.com/egovernments/DIVOC/blob/main/backend/certificate_signer/main.js)**.** If you want to update any of the constant values such as “certificate controller,” please refer to the [**DockerFile**](https://github.com/egovernments/DIVOC/blob/main/backend/certificate_signer/Dockerfile).

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Step 3: Configure the certificate template

Each country will have a separate certificate template with country-specific branding, and language.

**Steps:**

a. The DIVOC certificate template has been designed in the HTML format. To configure the HTM&#x4C;**-**&#x62;ased certificate template according to your country’s requirement, open [**certificate\_template.html**](https://github.com/egovernments/DIVOC/blob/main/backend/certificate_api/configs/templates/certificate_template.html) and map the dynamic fields in the certificate template.

```
<tr>
        <td><span class="d-flex pt-1 pb-1 font-bold">Beneficiary Name</span></td>
        <td><span class="d-flex pt-1 pb-1 font-bold">Beneficiary Parent Name</span></td>
    </tr>
    <tr>
        <td><span class="d-flex">{{name}}</span></td>
        <td><span class="d-flex">{{parentName}}</span></td>
    </tr>
```

b. Any modifications that you make (such as combining address fields as a single string) to the address value must be performed in controller.js. The dynamic values will be sent from[ **controller.js**](https://github.com/egovernments/DIVOC/blob/main/backend/certificate_api/src/routes/certificate_controller.js).

```
function prepareDataForVaccineCertificateTemplate(certificateRaw, dataURL) {
    certificateRaw.certificate = JSON.parse(certificateRaw.certificate);
    const {certificate: {credentialSubject, evidence}} = certificateRaw;
    const certificateData = {
        name: credentialSubject.name,
        parentName: credentialSubject.parentName,
        age: credentialSubject.age,
        gender: credentialSubject.gender,
        identity: formatId(credentialSubject.id),
        beneficiaryId: credentialSubject.refId,
        recipientAddress: formatRecipientAddress(credentialSubject.address),
        vaccine: evidence[0].vaccine,
        vaccinationDate: formatDate(evidence[0].date) + ` (Batch no. ${evidence[0].batch} )`,
        vaccineValidDays: `after ${getVaccineValidDays(evidence[0].effectiveStart, evidence[0].effectiveUntil)} days`,
        vaccinatedBy: evidence[0].verifier.name,
        vaccinatedAt: formatFacilityAddress(evidence[0]),
        qrCode: dataURL,
        dose: evidence[0].dose,
        totalDoses: evidence[0].totalDoses,
        isFinalDose: evidence[0].dose === evidence[0].totalDoses,
        currentDoseText: `(${getNumberWithOrdinal(evidence[0].dose)} Dose)`
    };

    return certificateData;
}
```

**Note:**&#x20;

* To check the PDF/print version, which will be generated after an update, open the HTML file in the browser and check for the print preview.&#x20;
* The page size should be A4 as the HTML is developed according to A4 dimensions.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# How to set up the verification portal for implementation

## Overview&#x20;

The document will help an implementer make changes to DIVOC’s verification component in line with any changes made to the certificate. It could include changes in the QR code section of the certificate or the logo, among others.

This section will cover the steps to update the verification component by configuring:&#x20;

1. Verification portal home page&#x20;
2. Verification confirmation page

## Prerequisite: Get details **on functions used for certificate verification**

1. The user will be directed to the verification page according to the  route defined in [**this**](https://github.com/egovernments/DIVOC/blob/main/public_app/src/App.js) file:

```
 <div style={{paddingBottom: "3rem", paddingTop: "3rem"}}>
  <Switch>
	<Route exact path={"/"} component={Home}/>
	<Route exact path={config.urlPath + "/login"} component={Login}/>
	<Route exact path={"/side-effects"} component={SideEffects}/>
	<Route exact path={"/feedback"} component={SideEffects}/>
	<PrivateRoute exact path={"/feedback/verify"} component={SubmitSymptomsForm} role={RECIPIENT_ROLE} clientId={RECIPIENT_CLIENT_ID}/>
	<Route exact path={"/dashboard"} component={Dashboard}/>
	<Route exact path={"/verify-certificate"} component={VerifyCertificate}/>
	<Route exact path={"/learn"} component={Learn}/>
	<Route exact path={"/not-found"} component={PageNotFound}/>
 </Switch>
</div>
```

2\. You can configure the timeout period for the camera to read the QR code in **config.CERTIFICATE\_SCAN\_TIMEOUT**.&#x20;

3\. If the camera is unable to read the QR code content, the timeout can be set to retry.

```
const onScanWithQR = () => {
        setShowScanner(true);
        setTimeout(() => {
            if(!result) {
                setShowTimeout(true);
            }
        }, config.CERTIFICATE_SCAN_TIMEOUT);
    };


const onTryAgain = () => {
        setShowTimeout(false);
        setShowScanner(false)
    };
```

4\. The QR code scan is triggered from the ‘VerifyCertificate’ method. Once the QR code is read by the application, it is unzipped using the jsZip library.

## Verification portal home page

#### How to update the verification page:

* The required UI changes, including messaging and branding, can be configured on [**this**](https://github.com/egovernments/DIVOC/blob/main/public_app/src/components/VerifyCertificate/index.js) file.
* You can refer to [**this**](https://github.com/egovernments/DIVOC/blob/icmr/verification/src/components/VerifyCertificate/index.js) file as an example of a country-specific configuration ([**https://verify.icmr.org.in/**](https://verify.icmr.org.in/)).

## **Verification confirmation page**

#### **How to update the vaccination confirmation details:**

Example: Include the beneficiary’s parent name as a mandatory field in the verification confirmation page.

* Open this file: [**https://github.com/egovernments/DIVOC/blob/main/vaccination-context/vaccination-context.js**](https://github.com/egovernments/DIVOC/blob/main/vaccination-context/vaccination-context.js).
* Add a parameter in the function “vaccinationContextV2” to set the schema.&#x20;

```
"Person": {
      "@id": "schema:Person",
      "@context": {
        "@version": 1.1,
        "@protected": true,
        "refId": "schema:id",
        "uhid": "schema:id",
        "name": "schema:name",
        "age": "schema:Number",
        "gender": "schema:gender",
        "nationality": "schema:nationality",
        "recipientParentName": "schema:name",
        "address": {
          "@id": "schema:PostalAddress",
          "@context": {
            "@version": 1.1,
            "@protected": true,
            "streetAddress": "schema:streetAddress",
            "streetAddress2": "vac:addressLine2",
            "city": "vac:city",
            "district": "vac:district",
            "addressRegion": "schema:addressRegion",
            "postalCode": "schema:postalCode",
            "addressCountry": "schema:addressCountry"
          }
        }
      }
    },
```

* Add recipientParentName in the certificate variable inside the function createCertificate.

```
"certificate": {
    "Name": "Name",
    "Age": "Age",
    "DOB": "DOB",
    "Gender": "Gender",
    "recipientParentName":"Recipient Parent Name",
    "Certificate ID": "Certificate ID",
    "Vaccine Name": "Vaccine Name",
    "Vaccine Type": "Vaccine Type",
    "Date of Issue": "Date of Issue",
    "Valid Until": "Valid Until",
    "Dose": "Dose",
    "Total Doses": "Total Doses",
    "Vaccination Facility": "Vaccination Facility"
  },
```

* Build and deploy your changes.&#x20;
* Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate/what-information-is-included-in-the-divoc-certificate) to know what information is included in the DIVOC certificate.

**Note:**

* The ‘recipientParentName’ should match with the key in the QR code Json file available in the [**main.js**](https://github.com/egovernments/DIVOC/blob/main/backend/certificate_signer/main.js).
* To remove any value (such as “vaccine type”) from the UI screen, you can remove that parameter in the certification field.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# How to configure the update certificate API

## Overview

This section will help an implementer configure the DIVOC “Update Certificate” API.

## Intended output&#x20;

* Implementers can use the “Update Certificate” API to process the requested updates - both in the QR code and human-readable sections of a specific certificate.

## API

* The DIVOC platform provides API services for updating vaccination certificates. You can refer to the API service call ‘​/v3​/certificate’ for the method <mark style="background-color:orange;">PUT</mark> [**here**](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../india/interfaces/vaccination-api.yaml).
* The payload of the update service is the same as that of the certificate generation request. Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate) to know more.
* The platform provides flexibility to update values in the ‘**recipient**,’ ‘**vaccination**,’ ‘**vaccinator**,’ and ‘**facility**’ sections. Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code) if you want to understand the mandatory and non-mandatory information that should be there in a vaccination certificate, according to global standards.

## Methods - Get details on the API request and field validations:

a. The update certificate request is processed in [**this**](https://github.com/egovernments/DIVOC/blob/main/backend/vaccination_api/pkg/handler.go#L608) function. The pre-enrollment code and dose-wise certificates will be searched in the system to make an update request. The function will trigger the subsequent process to update the certificates.

```
for _, request := range params.Body {
if certificateId := getCertificateIdToBeUpdated(request); certificateId != nil{
log.Infof("Certificate update request approved %+v", request)
	if request.Meta == nil {
		request.Meta = map[string]interface{}{
			"previousCertificateId": certificateId,
			"certificateType":       CERTIFICATE_TYPE_V3,
		}
	} else {
		meta := request.Meta.(map[string]interface{})
		meta["previousCertificateId"] = certificateId
		meta["certificateType"] = CERTIFICATE_TYPE_V3
	}
	if jsonRequestString, err := json.Marshal(request); err == nil {
		kafkaService.PublishCertifyMessage(jsonRequestString, nil, nil)
	}
} else {
	log.Infof("Certificate update request rejected %+v", request)
	return certification.NewUpdateCertificateV3PreconditionFailed()
}
}
return certification.NewUpdateCertificateV3OK()
```

b. An implementer has the provision to restrict the number of update requests against a specific certificate in order to avoid the misuse of this functionality (that is, fraudulent generation of multiple certificate copies). For instance, the implementer can configure the “Update Limit” to only “5,” in which case the certificate can only be updated five times. The following steps are needed to enable this configuration:

**Step 1:** Open [**this**](https://github.com/egovernments/DIVOC/blob/main/backend/vaccination_api/pkg/handler.go#L660) file and check the function that will limit the number of certificates being updated.

```
if count < (config.Config.Certificate.UpdateLimit + 1) {
  certificateId := doseWiseCertificateIds[int(*request.Vaccination.Dose)][count-1]
	return &certificateId
} else {
	log.Error("Certificate update limit reached")
}
```

**Step 2:** Open [**this**](https://github.com/egovernments/DIVOC/blob/main/backend/vaccination_api/config/config.go#L78) file and update the limit by configuring <mark style="background-color:yellow;">CERTIFICATE\_UPDATE\_LIMIT</mark>.

```
UpdateLimit int `env:"CERTIFICATE_UPDATE_LIMIT" default:"5"`
```

* Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate) to understand how DIVOC's “Update Certificate” service works.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Configuring Environment Variables in 2.0

Environment variables are added in divoc-config.yml in the orchestration node.

### Steps to add the environment variables:

* To display the config map, run the following command:

```
kubectl -n divoc get configmap 
```

* If multiple config maps exist, add environment variables to all the config maps.
* To edit the config map, run the following command:&#x20;

```
kubectl -n divoc edit config divoc-config
```

* Next, add the variables under ‘data.’ Save and exit.
* Restart the services where environment variables have been used by running the following command:&#x20;

```
kubectl -n divoc rollout restart <service_name>
```

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Configuration Management Via ETCD

## Making changes to DIVOC’s certificate module via etcd

We have added etcd as a configuration management tool for DIVOC. This makes it easier for implementing partners to add new vaccines, edit templates or the QR code payload, as well as add new configurations without deploying any components. Use any etcd client that you like - for example, the [**etcd-manager**](https://www.electronjs.org/apps/etcd-manager). Following are the steps to set up the etcd-manager:

* Open the URL: [**https://www.electronjs.org/apps/etcd-manager**](https://www.electronjs.org/apps/etcd-manager) and click on Download.
* To configure the host and port number: open the etcd manager app → go to settings → click on etcd → enter the respective host IP and port.
* If authentication is configured for etcd, enter the authentication credentials. Go to Settings -> Auth -> enter username and password.
* Click on the test connection to confirm connectivity and click on save.
* Next, go to the Manage keys tab on the left. You should be able to see the configurations already setup.

Once the etcd manager app is installed, the following can be seamlessly managed within DIVOC:

* [Adding a new vaccine and International Classification of Diseases or ICD-11 mapping.](/v2-2/platform/configuration/configuration-management-via-etcd/adding-a-new-vaccine-and-icd-11-mapping)
* [PDF template change for vaccine certificates.](/v2-2/platform/configuration/configuration-management-via-etcd/pdf-template-change-for-vaccine-certificates)&#x20;
* [EU vaccine configurations.](/v2-2/platform/configuration/configuration-management-via-etcd/eu-vaccine-configurations)&#x20;
* [Payload changes in the QR code.](/v2-2/platform/configuration/configuration-management-via-etcd/payload-changes-in-the-qr-code)&#x20;

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Adding a New Vaccine and ICD-11 Mapping

There are different International Classification of Diseases (ICD) codes based on the category of vaccines. To add a new vaccine, identify the ICD-11 code to which the vaccine belongs. Once you have mapped the vaccine to the relevant ICD-11 code, you can update the vaccine name and its ICD-11 mapping in etcd.

### Steps to update the vaccine name and its ICD-11 mapping:

* Go to the Manage keys tab of the etcd-manager app. To add or update mappings, two keys must be updated: “VACCINE\_ICD” and “ICD.”
* To add the vaccine name, ICD-11 code, and description VACCINE\_ICD, go to VACCINE\_ICD and click on the Edit key.&#x20;

&#x20;      \- Example of VACCINE\_ICD value for Covaxin:&#x20;

&#x20;        {“vaccineName”: “covaxin”, “icd11Code”: “XM1G90”}

* Click on Save. A popup will appear as “operation successful.” Click on Close.

![](/files/rCv3Hl84VbzG8d8qROel)

* Click on the edit button of the “ICD” key to add ICD-11 code and click on the Edit key.

&#x20;     \- Example of ICD value for Covaxin:

&#x20;      {“XM1G90”: {“vaccineType”: “inactivated virus”, “icd11Term”: “COVID-19 vaccine, inactivated virus”}}

* Click on Save. A popup will appear as “operation successful.” Click on Close.

![](/files/zJu4lk0AsqRtgzm9TyT4)

* Make the certificate generation request call and fetch the certificate to test the changes. Once updated, any new certificate can be issued using the new vaccine name.

![This is a sample certificate generated with the new vaccine type, with ICD-11 code XM6JD5 and ICD-11 term: ‘COVID-19 vaccine, live attenuated virus.’](/files/z0DpYc1778SJ36nBkNaf)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*                                 &#x20;


# Adding a New Vaccine and ICD-11 Mapping Using ETCD CLI

Using ETCD CLI, the same can be dynamically updated in two files (VACCINE\_ICD.json and ICD.json) without any service deployments.

### **Steps to update the vaccine name and its ICD-11 mapping:**

* Go to the specific folder where etcd files are available.
* Open the files to add the new vaccine.
* Run the command: vim VACCINE\_ICD.json.

<figure><img src="/files/GICV7z9oLS13J0gtbmnO" alt=""><figcaption></figcaption></figure>

* Run the command: vim ICD.json.

<figure><img src="/files/sjpvtFbK8veq7Jg3HUOb" alt=""><figcaption></figcaption></figure>

* To reflect the change, run the command: ./updateConfigs.sh. It shows "OK OK OK...." This means that the etcd has been updated with new vaccine list successfully.

<figure><img src="/files/WYLvj7y43dyvFv71cRxQ" alt=""><figcaption></figcaption></figure>

* Create the certificate and generate the PDF with the new vaccine.

<figure><img src="/files/qJp2aI1jpqTRvV6rgwfn" alt=""><figcaption><p>Sample certificate</p></figcaption></figure>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# PDF Template Change for Vaccine Certificates

Any template-related changes can be done by updating the HTML template in the etcd manager. Supported fields include the following:&#x20;

| Beneficiary Details     | Vaccination Details | Previous Dose Details     |
| ----------------------- | ------------------- | ------------------------- |
| name                    | vaccine             | vaxEvents\[].dateOfVax    |
| age                     | vaccinationDate     | vaxEvents\[].doseType     |
| gender                  | vaccineBatch        | vaxEvents\[].vaxName      |
| identity (masked value) | vaccineICD11Code    | vaxEvents\[].vaxType      |
| nationality             | vaccineProphylaxis  | vaxEvents\[].vaxBatch     |
| beneficiaryId           | vaccineType         | vaxEvents\[].countryOfVax |
| recipientAddress        | vaccineManufacturer |                           |
|                         | vaccineValidDays    |                           |
|                         | vaccinatedBy        |                           |
|                         | vaccinatedAt        |                           |
|                         | certificateId       |                           |
|                         | dose                |                           |
|                         | totalDoses          |                           |

### **Example: Adding a field such as ‘nationality’ to the PDF template.**

### Steps to add ‘nationality’ to the PDF templat&#x65;**:**

* Go to the Manage keys in the etcd-manager.&#x20;
* Go to the “vaccineCertificateTemplate” key and click on the Edit key to update the template. In this case, the ‘nationality’ field is being added. The value expected for the “vaccineCertificateTemplate” configuration is html and can be customised as per your needs.&#x20;
* The same will be reflected in the PDF of the vaccination certificate. Click on Save. A popup will appear as “operation successful.” Click on Close.

![](/files/tDbPaXt5zpWH2zV7pyuL)

* Call “GET VaccineCertificate API,” which will return the PDF certificate template. Verify if the new field ‘nationality’ is getting reflected.

![Sample certificate](/files/rNIUSPropCK6vuE3gjYu)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*  &#x20;


# PDF Template Change for Vaccine Certificates via ETCD CLI

Any template-related changes can be done by updating the HTML template using ETCD CLI. Before making any change, the PDF template will look like:

<figure><img src="/files/TNHLDal3YpJ5QHQ7PxKA" alt=""><figcaption><p>Sample certificate</p></figcaption></figure>

### **Example:  Adding a field such as ‘nationality’ to the PDF template.**

### Steps to add **'**&#x6E;ationality' to the PDF template:

* Go to the specific path where etcd is configured.
* Open the file to add the new field that will get displayed in the template (vim vaccineCertificateTemplate.html).

<figure><img src="/files/No6AHrTVtaKW7tCQ3r2K" alt=""><figcaption></figcaption></figure>

* To reflect the change, run the updateConfigs shell script using the command: ./updateConfigs.sh. It shows "OK OK OK...." This means that etcd has been updated with the new template successfully.

<figure><img src="/files/JvNVpb0wd3pz9yUa30Ek" alt=""><figcaption></figcaption></figure>

* Generate the PDF again using GET API.

<figure><img src="/files/yZmORkS23a1JHvRntUAW" alt=""><figcaption><p>Sample certificate</p></figcaption></figure>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# EU Vaccine Configurations

To add a new vaccine to an EU certificate, a country must identify the EU code to which the vaccine belongs. The coded [**value sets**](https://ec.europa.eu/health/publications/value-sets-eu-digital-covid-certificates-update_en) used in EU vaccination certificates include:

* vp: COVID-19 vaccine or prophylaxis
* mp: COVID-19 vaccine product
* ma: COVID-19 vaccine marketing authorisation holder or manufacturer

### Steps to add the extra field in the certificate:

* Go to the specific path where etcd is configured.
* To add the extra field in the template, go to the Manage keys where etcd is configured.
* To add the vaccine code, go to euVaccineCode and click on the Edit key to add the vaccine name and code.&#x20;

&#x20;     \- Example for Covaxin:

&#x20;        {“covaxin”: “Covaxin”}

* Click on Save. A popup will appear as “operation successful.” Click on Close.

![](/files/fUjimxrOlS5VvKE3Koqw)

* To add the prophylaxis, go to euVaccineProph and click on the Edit key to add the vaccine name and code.

&#x20;     \- Example for Covaxin:

&#x20;        {“covaxin”: “J07BX03”}

* Click on Save. A popup will appear as “operation successful.” Click on Close.

![](/files/dBkQy67V6zsisxEkuUpc)

* To add the manufacturer, go to euVaccineManuf. Click on the Edit key to add the new manufacturer.

&#x20;     \- Example for Covaxin:

&#x20;        {“bharat”: “Bharat-Biotech”}

* Click on Save. A popup will appear as “operation successful.” Click on Close.

![](/files/lfaZZcmYWwNafUZpMwu2)

* Once the mappings are available in etcd, you can create the certificate and generate the PDF with the new vaccine.

![Sample certificate](/files/yqs9eXoq1Kc87GI4R1ww)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.* &#x20;


# Adding a New Vaccine and its Mapping via ETCD CLI

With the ETCD CLI, the same can be dynamically updated in the files (euVaccineProph.json and euVaccineCode.json) without any service deployments.

### **Steps to add the extra EU vaccine configurations**

* Go to the specific path where etcd is configured.
* Open the files to add the new vaccine or update the existing vaccine.
* Run the command: vim euVaccineCode.json.

<figure><img src="/files/ovo9Xj56xNsBQq8dNoRh" alt=""><figcaption></figcaption></figure>

* Run the command:vim euVaccineProph.json.

<figure><img src="/files/G56irHkXEjQD0YrbeJ3r" alt=""><figcaption></figcaption></figure>

* Run the command:vim [euVaccineManuf.json](https://github.com/egovernments/DIVOC/blob/main/default-configuration/etcd/euVaccineManuf.json).

<figure><img src="/files/V8oTI4hqDgwCxUnlhnJ5" alt=""><figcaption></figcaption></figure>

* To reflect the change, run the command: ./updateConfigs.sh. It shows "OK OK OK...."This means that etcd has been updated with the new vaccine list successfully.

<figure><img src="/files/Z2zddKSibNtnrQcR99XT" alt=""><figcaption></figcaption></figure>

* Create the certificate and generate the PDF with the new vaccine.

<figure><img src="/files/NZctwne2CAsnzDXkZQWe" alt=""><figcaption><p>Sample certificate</p></figcaption></figure>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.* &#x20;


# Payload Changes in the QR Code

* DIVOC certificates are natively digital, verifiable, digitally signed, and also printable with a secure and tamper-proof [**QR code**](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code)**.**
* The QR [**payload**](/v2-2/platform/divocs-verifiable-certificate-features/divocs-native-covid-19-certificate-specification) structure is based on the [**W3C verifiable credentials data model**](https://www.w3.org/TR/vc-data-model/).&#x20;
* Previously, any changes in the QR payload required changing it in the certificate-signer service and subsequent deployment.
* With DIVOC 2.0, QR payload changes can now be made by changing it in etcd without any deployments.
* Currently, only the optional fields that already exist can be removed. New fields cannot be added as of now.
* Note: Do not remove the [**mandatory**](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code) fields.

### Steps to remove an optional field:

* Go to DDCC\_TEMPLATE. Click on the Edit key if you want to remove an optional field.
* Click on Save. A popup will appear as “operation successful.” Click on Close.

![](/files/zQcjXurJYtPQYh5tJPBa)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.* &#x20;


# Payload Changes in the QR Code via ETCD CLI

Currently, only the optional fields that already exist can be removed. New fields cannot be added as of now.&#x20;

Note: Do not remove the [**mandatory**](/v2-2/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code) fields.

### Steps to remove an optional field:

Run the command: vim DDCC\_TEMPLATE.template.

<figure><img src="/files/nhxSprF0txBQPiNJrCUV" alt=""><figcaption></figcaption></figure>

To reflect the change, run the command: ./updateConfigs.sh. It shows "OK OK OK...." This means that etcd has been updated with the new QR Code template successfully.

<figure><img src="/files/Ggy9mcBWJuTDcVYQ9Yvd" alt=""><figcaption></figcaption></figure>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Troubleshooting Guide

The guide covers some of the most common issues we have encountered while working with our partners. It includes the following:

* [DIVOC services are up, but certificates are being generated.](#divoc-services-are-up-but-certificates-are-not-being-generated)
* [DIVOC services are down but servers are configured and functioning correctly.](#divoc-services-are-down-but-servers-are-configured-and-functioning-correctly)
* [DIVOC services take a long time to return](#divoc-services-take-a-long-time-to-return)
* [DIVOC services are not returning success HTTP status codes](#divoc-services-are-not-returning-success-http-status-codes)

## DIVOC services are up, but certificates are not being generated

### Symptoms

* Vaccination events are successful.
* Certificates are not being generated.
* All other DIVOC services are functioning.
* Verification app is functioning.
* Download of certificates is functioning.
* All DIVOC services are running on the Kubernetes cluster.

### Diagnosis

The most probable cause of this issue can be that the Redis server has stopped responding. This can be confirmed by running the following tests:

* Check the status of Redis

&#x20;     \- To get into the Redis container, use the command “redis-cli”.

&#x20;     \- Inside Redis, use the command ‘PING’ -

&#x20;        1\. If the response is ‘PONG,’ then the server is running.

&#x20;        2\. If the response is blank or anything else other than ‘PONG,’ the server is not running.

&#x20;     \- To get out of the Redis container, type ‘exit’.

### Steps to resolve the incident

* Restart Redis if it is unresponsive or down.

&#x20;     \- Restarting the service mainly involves killing the service and starting it again.

&#x20;     \- Procedure to kill a service:

&#x20;        1\. For killing any service on a Linux machine, we need the process\_id of the service. The process\_id that we get as the output number for further steps in killing the service by running the command is: **$ ps aux|grep redis**.

&#x20;        2\. For killing an unresponsive service on a Linux machine, replace the **process\_id\_of\_service** with the value that you have noted down in the above step: **sudo kill -9 process\_id\_of\_service**.

&#x20;     \- Procedure to start a service:

&#x20;        1\. After successfully killing the service, to start the service, run the command: **$ sudo service redis-server start**.

&#x20;        2\. To check the status of the service, run: **$ sudo service redis-server status**.

&#x20;     \- Note: Check the status of the redis-server as mentioned above.

### Action to prevent similar issue in future

This problem occurs frequently when the resources allocated to the Redis cluster is very less. To ensure that the problem does not occur in the future, we advise to increase the server configuration to have atleast 16GB or more memory depending on the population that the installation serves. Another thing to consider is to have Redis run on its own server infrastructure instead of sharing resources with other software.

## DIVOC services are down but servers are configured and functioning correctly

### Symptoms

* All servers are accessible through SSH.
* Infrastructure is configured correctly - Kafka, Elasticsearch, Postgres, Redis.
* Kubernetes worker nodes are running DIVOC services.
* DIVOC services are not accessible through API endpoints.

### Diagnosis

The most probable cause of this incident is that the Kubernetes client certificates have expired. Currently, to enable communication between the Master and worker nodes, Kubernetes certificate is set to 1 year. What this means is that every year we need to renew this certificate for continued delivery of the platform. This can be confirmed by running the following tests:

* Master and slave nodes of the cluster are reachable.
* On running “kubectl get pods -n divoc” command on the master node, you can an error saying “**Client Certificates generated by kubeadm are expired. Can’t reach the cluster**.”&#x20;
* Execute “**kubeadm certs check-expiration**” command on the master node to check the expiration of certificates.&#x20;
* This will identify that since the certificate has expired, kube-apiserver, kube-scheduler, kube-controller-manager services were not able to manage DIVOC services deployed on worker nodes.

### Steps to resolve the incident:

Run the following commands on the master node to resolve the incident:

* Take backup of the older config

&#x20;      \- cp \~/.kube/config \~/.kube/dec-11-2022-expired-config

* Renew the certificates&#x20;

&#x20;     \- kubeadm certs renew all

* Restart Kubelet

&#x20;     \- systemctl restart kubelet

* Restart Kube-apiserver, kube-controller-manager, kube-scheduler, etcd so that they can use newly generated certificates.

&#x20;     \- List all the running services in default namespace on Master node: docker ps.

&#x20;     \- Stop & remove Kube-apiserver, kube-controller-manager, kube-scheduler and etcd services so that the services get restarted again -

&#x20;       1\. docker stop \<containerId>

&#x20;       2\. docker rm \<containerId>

* As soon as these services are restarted, they will be able to restart the services (certificate-api) which went down on the slave node.

### Action to prevent similar issue in future

In a managed kubernetes service, the certificates are auto-renewed upon expiry. In case of self-hosted/on-prem deployments of k8s cluster, the kube certificates have to be renewed manually. It is also possible to set the expiry to a time greater than a year, but this is not recommended. The best practice is to have calendar alerts for the appropriate dates.

## DIVOC services take a long time to return

### Symptoms

* All DIVOC services are up and running.
* All infrastructure services are up and running.
* All servers are accessible over SSH.
* DIVOC REST services are successful, but take a long time to execute.

### Diagnosis

The most probable cause of this issue is that indexes are not present in the Postgres database table. This can be confirmed by the following steps:

* Connect directly to the Postgres database using psql.
* Check if the following indexes are present for the following columns in V\_VaccinationCertificate table in the database:

&#x20;     \- OSID

&#x20;     \- certificateId

&#x20;     \- Contact

&#x20;     \- Mobile

&#x20;     \- preEnrollmentCode

### Steps to resolve the incident

After connecting to the Postgres registry database, run the following SQL commands to add Indexes on the columns.

* CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_preEnrollmentCode\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("preEnrollmentCode");
* CREATE UNIQUE CONCURRENTLY INDEX "public\_V\_VaccinationCertificate\_certificateId\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("certificateId");
* CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_contact\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("contact");
* CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_mobile\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("mobile");
* CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_osid\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("osid");

### Action to prevent a similar issue in future:

This is a one-time activity that needs to be done as soon as the database tables/registry is created. This dependency exists because Sunbird-RC does not have the capability to add indexes on schema creation.&#x20;

## DIVOC services are not returning success HTTP status codes

Sometimes DIVOC services return non 2XX status codes. We have split this section into sub-sections depending on the various non 2XX status codes received.

### Status Code: 401

You will get a 401 status code when the Authentication/Authorisation Bearer token being used has expired.&#x20;

* Open postman.
* Create a POST request to /auth/realms/divoc/protocol/openid-connect/token endpoint.
* Add the following parameters:&#x20;

  \- client-id as admin-api

  \-  Grant-type as client-credentials

  \-  Client\_secret as \<Value provided to you during installation>
* Once the request is sent, you will receive the auth\_token as part of the payload.
* Modify the ADMIN\_API\_SECRET parameter within the divoc-config.yaml file.
* Restart all the services using: kubectl rollout restart deployments -n \<namespace of divoc installation>

### Status Code: 405

* Check if the Content-Type in the header section is set as ‘application/json’
* If not, set the Content-Type as ‘application/json’

### Status Code: 602

* Check if the payload is missing any parameter value like ‘preEnrollmentCode’, ‘recipient.name’, etc.
* If yes, add the missing parameter and check.

### Status Code: 400

* Check if the format of value in the payload or the json structure is as per the expected structure. For example, the format of date value, dose count is number or string, etc.
* If not, correct the value type in the payload.

### Status Code: 504

* Check if the DIVOC system is reachable from the source system or if IP/domain of the DIVOC system is mapped correctly.
* If not, correct the IP/Domain name or check the network &#x20;

### Status Code: 502

* Check if all the DIVOC services required for the generation of certificates are up and running.
* Steps to be followed to check if required services are running:

&#x20;     \- Login in to the DIVOC orchestration server.

&#x20;     \- Run this command: **kubectl get pods -n \<divoc namespace>**

* If any of the pods are down and dont have a active running container, do the following:

&#x20;     \- Restart the pod with this command: **kubectl rollout restart deployment \<name of the deployment which is down> -n \<divoc namespace>**

&#x20;      \- Run this command again: **kubectl get pods -n \<divoc namespace>**

&#x20;      \- Validate if all the deployments are up again.

&#x20;     \- Check if you are able to generate the certificate.

* If you are still not able to generate certificate, then check the logs of deployments one by one using this command: **kubectl logs -f deployment/\<deployment\_name> -n \<divoc\_namespace>**

## Common Infrastructure Maintenance Issues

### Pods restart frequently

* If you run **kubectl get pods -n \<divoc-namespace>** and see that the number of pod restarts is high. There can be multiple reasons to pod restarts:

&#x20;     \- CPU limit is exceeded by pods: In this case, modify the deployment by increasing the requests and limits on the CPU.

&#x20;     \- Memory limit is exceeded by pods: In this case, modify the deployment by increasing the requests and limits on memory.

&#x20;     \- Memory issue in the machine on which Kubernetes (worker node) is installed: To address this, one can increase the number of worker nodes or increase the memory of worker nodes and then recreate pods if necessary.

&#x20;     \- Code issue: Sometimes there can be an issue with the code or the configuration might be missing. In such cases, one needs to fix the bug.

### How to apply OS updates or patches on DIVOC infrastructure

Typically, DIVOC infrastructure is built over a cluster of Kubernetes, Kafka, and Postgres. As part of the operations, one of the key tasks of the infrastructure team is to apply security patches and updates to the OS.&#x20;

**Note:** One should never directly log into a machine and apply a patch directly on a cluster of nodes. This should be done only for standalone servers and not cluster-based servers. This problem does not occur in Cloud-managed infrastructure. This is an issue only on self-managed or on-premise infrastructure.

In this section, we will discuss how to apply patches to the cluster without bringing down the application.

The general guidelines when dealing with the cluster are the following:

* Disconnect the server from the cluster.
* Apply patches to the server.
* Rejoin the server back to the cluster.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Performance Report

The following is the Gatling report on the TPS system that was processed with the suggested infrastructure for production:

<figure><img src="/files/yl9VYD3mfks51DHme4mm" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/nDdfccAyopxz9mKc5MnY" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/vffZd9quj1aa1N1apiwj" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/m78JQhMPXE8wIVZD48GF" alt=""><figcaption></figcaption></figure>

Link to the map is [**here**](/v2-2/platform/installation/setting-up-divoc-in-k8-cluster/how-to-install-divoc#suggested-servers-for-ha-setup).&#x20;

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Products

Country-specific implementation details

Each section will cover the different features and services of DIVOC that were implemented by the following countries and the standards used:

* [India (COVID-19 certificates)](/v2-2/products/issuing-covid-19-vaccination-certificates-in-india)
* [India (COVID-19 test reports)](/v2-2/products/issuing-covid-19-test-reports-in-india)
* [Sri Lanka](/v2-2/products/issuing-covid-19-vaccination-certificates-in-sri-lanka)
* [Philippines](/v2-2/products/issuing-covid-19-vaccination-certificates-in-the-philippines)&#x20;
* [Jamaica](/v2-2/products/issuing-covid-19-vaccination-certificates-in-jamaica)
* [Indonesia](/v2-2/products/issuing-covid-19-vaccination-certificates-in-indonesia)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Issuing COVID-19 Vaccination Certificates in India

The Government of India launched the COVID-19 vaccination program in January 2021. The roll-out of the Co-WIN application was key to this. While the cloud-based platform covered all the major modules that a vaccination program of this scale should have, it lacked the digital credentialing feature that was critical to open up travel and economy amid the COVID-19 pandemic. DIVOC was integrated with Co-WIN in January 2021, making India the first country where the digital verifiable credentialing was implemented. Over 1.9 billion vaccination certificates have been issued in India so far.

## Platform release version&#x20;

Since India was the first country to implement DIVOC, a component-wise release was done as there was no generic version available back then. Hence, the release versions are component-specific:

| Components                                                                               | Release Version |
| ---------------------------------------------------------------------------------------- | --------------- |
| Certificate generation services: dockerhub/divoc-certification-ack                       | 1.0.16          |
| Certificate generation services: dockerhub/certificate\_processor                        | 1.0.16          |
| Certificate generation services: dockerhub/certificate\_signer                           | 1.0.22          |
| Certificate generation services:  dockerhub/vaccination\_api                             | 1.0.27          |
| Certificate generation services - Commonly-used component: dockerhub/registry            | 1.0.19          |
| Certificate generation services - Commonly-used component: dockerhub/caching-dash-server | 1.0.20          |
| Verification component: dockerhub/verification                                           | 1.0.29          |
| Certificate reconciliation services: dockerhub/reconciliation                            | 1.0.3           |
| Fetch certificate services: dockerhub/digilocker\_support\_api                           | 1.0.59          |
| Fetch certificate services: dockerhub/registry                                           | 1.0.19          |
| Dashboard: dockerhub/analytics\_feed                                                     | 1.0.17          |

## Features and services

[**Certificate generation:**](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate) A certificate is generated in real-time every time a person’s vaccination record is created in Co-WIN. Citizens get the latest dose certificate, which could be provisional, final, or the precaution dose. Two types of certificates are issued: domestic (age is mandatory) and international travel certificates (date of birth is mandatory). Further, DIVOC certificates (domestic) can be generated in 22 languages in India.

[**Certificate download:**](https://divoc.digit.org/v2-2/products/pages/ZewaVGl8Ggsp0imFvYlb#2.-for-downloading-a-certificate) Besides Co-WIN, DIVOC’s certificate module has been integrated with [**Arogya Setu**](https://www.aarogyasetu.gov.in/)**,** [**Umang**](https://web.umang.gov.in/landing/)**,** and [**Digilocker**](https://www.digilocker.gov.in/)**,** so that citizens can download their certificates after vaccination from any of these portals/apps by using their registered mobile number.&#x20;

![](/files/wGM35HfkB4pfGhbc7ujH)

[**Certificate verification:**](/v2-2/platform/divocs-verifiable-certificate-features/verifying-a-divoc-certificate) DIVOC’s integration with CoWIN enables verification of the QR code-based vaccination certificates [**online**](https://verify.cowin.gov.in/) by using DIVOC’s verification utility embedded within Co-WIN.

![](/files/6IvpU0hJhVuRhHTnITP5)

[**Updating certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate) This feature can be used by citizens if the name, age, gender, date of vaccination, or other details on their vaccination certificate are incorrect.

[**Revoking certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/revoking-a-divoc-certificate) This feature is also used in India.

[**Analytics:**](/v2-2/divoc-demo/analytics) DIVOC has set up a [**dashboard**](https://stats.cowin.gov.in/public/dashboards/HT9vhThnsXTQcuLUrFprMz97moerYPnRqtf7WRPn) for India, which gives a snapshot of the total number of certificates issued, and accessed.

![Note: These are April 19, 2022, numbers](/files/O0mBjA8REwTzQBGJ7xp1)

**Reconciliation service:** This service was introduced in India to resolve any initial (bulk) data entry discrepancy such as date of vaccination.

## Standards used

* The international certificates issued in India for citizens traveling abroad are based on the     [**WHO-Digital Documentation of COVID-19 Certificates (DDCC)**](https://www.who.int/publications/i/item/WHO-2019-nCoV-Digital_certificates-vaccination-2021.1) data specification.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Issuing COVID-19 Test Reports in India

## Overview&#x20;

DIVOC collaborated with the Indian Council of Medical Research (ICMR) to launch the COVID-19 report portal. The test report certificates went live in October 2021.

We will give you an overview of the features and services that have been implemented.&#x20;

## Platform release version&#x20;

1.23&#x20;

## Features and services&#x20;

**Certificate generation:** DIVOC generates certificates of RTPCR tests on demand when a citizen requests it on the ICMR portal. The portal allows citizens to easily access and download their COVID-19 test reports.

![](/files/UGgziRKZAQrs5wsZqi2i)

**Verifying test reports:** The verifiable QR code on each test report enables citizens to carry/show their latest COVID-19 test results securely. DIVOC has set up a [**verification portal**](https://verify.icmr.org.in/) that can be used to verify a test certificate by scanning the QR code. These reports can also be verified offline by third-party apps.

![](/files/gnDseMTqQziMa2ThV8sB)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Issuing COVID-19 Vaccination Certificates in  Sri Lanka

## **Overview**

Sri Lanka went live with DIVOC in July 2021. DIVOC has been integrated with an existing platform in Sri Lanka - the District Health Information Software (DHIS2) - to generate COVID-19 certificates for its citizens. DIVOC has also set up a portal to verify these certificates.

Sri Lanka’s Information and Communication Technology Agency (ICTA) in collaboration with the Department of Health (DOH) has implemented DIVOC. The integration of DIVOC with DHIS2 was a collaborative effort by HISP Sri Lanka (local DHIS2 partner) and the ICTA.

We will give you an overview of the different features and services of DIVOC that have been implemented in Sri Lanka and the standard used.

## Platform release version&#x20;

1.23.3 - generic. We are in the process of upgrading it to version 2.0.

## Features and services

[**Certificate generation:**](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate) DIVOC provides the latest COVID-19 certificate on demand for any Sri Lankan citizen, mostly those who are traveling abroad so that they can confirm their vaccination status. So far, 3,68,490 certificates have been generated on demand. DIVOC supports the generation of multi-lingual certificates in Sri Lanka.

[**Certificate verification:**](/v2-2/platform/divocs-verifiable-certificate-features/verifying-a-divoc-certificate) The verification portal can be used to verify the QR code-based certificates after they are generated by the system.

![](/files/2bMBG5PqCWTcXNv8kiyb)

[**Updating certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate) Any mistakes or changes in the certificate (dose 1, 2, 3) are done through this service when a citizen requests it.

[**Revoking certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/revoking-a-divoc-certificate) This service will be provided to Sri Lanka after we upgrade the platform to version 2.0.

## Standards used&#x20;

* All COVID-19 certificates issued in Sri Lanka are compliant with the WHO-Digital Documentation of COVID-19 Certificates (DDCC) data specification.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Issuing COVID-19 Vaccination Certificates in the Philippines

## Overview&#x20;

The Philippines went live with DIVOC in September 2021. DIVOC was integrated with the country’s vaccine-related information system (VIMS).

Under the guidance of the Department of Health, the Department of Information and Communications Technology (DICT) along with SGV (EY) Philippines has implemented DIVOC in the country.

## Platform release version&#x20;

2.0

## **Features and services**

[**Certificate generation:**](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate) DIVOC provides the latest COVID-19 certificate on demand for any Philippines citizen.&#x20;

![Sample COVID-19 vaccination certificate](/files/9LrLDHfF4r965eXWfkSn)

[**Certificate verification:**](/v2-2/platform/divocs-verifiable-certificate-features/verifying-a-divoc-certificate) Using DIVOC’s reference code, DICT along with SGV has built the verification service.

[**Downloading certificates:**](https://divoc.digit.org/v2-2/products/pages/ZewaVGl8Ggsp0imFvYlb#2.-for-downloading-a-certificate) DIVOC’s certificate generation service has enabled a “fetch certify” service that can be used to download certificates.\
\
[**Updating certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate) This feature is also used in the Philippines.

## Standards used&#x20;

* All COVID-19 certificates issued in the Philippines are compliant with the WHO-Digital Documentation of COVID-19 Certificates (DDCC) data specification.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Issuing COVID-19 Vaccination Certificates in Jamaica

## Overview&#x20;

Jamaica went live with DIVOC in December 2021. It was implemented by Jamaica's Ministry of Health & Wellness.

DIVOC has set up the “Digital Vaccination Certificate Portal,” which also serves as the citizen portal, as well as a system admin portal for Jamaica. The vaccination data has been integrated with CommCare.

## Platform release version&#x20;

1.24.0-generic

## **Features and services**

* [**Certificate generation:**](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate) This is in sync with the country’s COVID-19 vaccination event. Once a person gets vaccinated, information is sent to Jamaica’s vaccination system and a certificate is automatically generated via DIVOC.
* [**Certificate verification:**](/v2-2/platform/divocs-verifiable-certificate-features/verifying-a-divoc-certificate) The citizen portal can be used to verify the QR code-based certificates that are issued after vaccination.

![](/files/qEQyGrtqJMlx0zRGOYiI)

* [**Updating certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate) DIVOC has enabled a certificate update/correction API that can be used to update or correct an issued certificate if a citizen requests it.
* [**Revoking certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/revoking-a-divoc-certificate) This feature has been provided to Jamaica and will be implemented soon.
* SMS service: DIVOC’s certificate module has been integrated with the SMS gateway service facilitated by Jamaica. As part of this service, a notification is sent to every citizen after they get vaccinated, informing them to download their certificates from the citizen portal.
* [**Downloading certificates:**](https://divoc.digit.org/v2-2/products/pages/ZewaVGl8Ggsp0imFvYlb#2.-for-downloading-a-certificate) Beneficiaries of the vaccination program can log in to the citizen portal using the 10-digit mobile number that they had used during registration and then click on “download your vaccination certificate” to view and download certificates.

![](/files/xqzuPOQzVRaO44qsvxOq)

* **Print facility:** The staff or administrator at a facility will be provided with a login to use this feature to search for certificates and print them on behalf of the citizens. When a citizen walks into a facility, the staff will use the information (mobile number or date of birth) provided by him/her to search for the vaccination certificate. Once they find the certificate on the portal, the staff can download and print it.

![](/files/DdU5ipq4vgvpuxdA0tic)

## Standards used&#x20;

* All COVID-19 certificates are generated as per the WHO-Digital Documentation of COVID-19 Certificates (DDCC) data specification.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Troubleshooting

Redis service

## Checking Status and Restarting Redis

To check the status of the Redis server:

* For getting into the Redis container, use the command “redis-cli”.
* Inside Redis, use the command “PING” -

&#x20;               \- If the response is “PONG” then the server is running.&#x20;

&#x20;               \- If the response is blank or anything else other than “PONG,” the server is not running.

* To get out of the Redis container: “exit”.

## **Process to restart the service if the Redis server is down**

Restarting service mainly involves killing the service and starting it again.

**Procedure to kill a service:**

* For killing any service on a Linux machine, we need the process\_id of the service. The process\_id which we get as the output number for further steps in killing the service by running the command is: **$ ps aux|grep redis**.
* For killing an unresponsive service on a Linux machine, replace the **process\_id\_of\_service** with the value that you have noted down in the above step:&#x20;

&#x20;      **$ sudo kill -9 process\_id\_of\_service**.

* To confirm if the service is killed: **$ sudo service redis-server status**.

**Procedure to start a service:**

* After successfully killing the servic&#x65;**,** to start the service: **$ sudo service redis-server start**.
* To check the status of the service: **$ sudo service redis-server status**.

Note: Check the status of the redis-server as mentioned above.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Issuing COVID-19 Vaccination Certificates in Indonesia

## Overview&#x20;

DIVOC’s certificate generation service went live in Indonesia in December 2021. It was implemented by Indonesia’s Ministry of Health.

DIVOC has been integrated with an existing mobile application in Indonesia - PeduliLindungi - to generate COVID-19 certificates for its citizens.&#x20;

## Platform release version&#x20;

1.24&#x20;

Features and services&#x20;

[**Certificate generation:**](/v2-2/platform/divocs-verifiable-certificate-features/creating-a-divoc-certificate) DIVOC issues the latest COVID-19 vaccination certificate to citizens on demand. DIVOC supports the generation of multi-lingual certificates in Indonesia.

![Sample COVID-19 vaccination certificate](/files/GqBThqju3RJrWQ9cl7eO)

[**Certificate verification:**](/v2-2/platform/divocs-verifiable-certificate-features/verifying-a-divoc-certificate) The [**verification portal**](https://verify.kemkes.go.id/) set up by DIVOC can be used to verify the QR code-based certificates online after they are generated by the system. Third-party verification apps can also be used to verify the certificates, both online and offline.

![](/files/y6wrcrsW3jLE2Hy8VsfZ)

[**Updating certificates:**](/v2-2/platform/divocs-verifiable-certificate-features/updating-a-divoc-certificate) This service is also available in Indonesia.&#x20;

## Standards used&#x20;

* COVID-19 certificates issued in Indonesia are compliant with the WHO-Digital Documentation of COVID-19 Certificates (DDCC) data specification.&#x20;
* COVID-19 certificates issued to those who are travelling to EU countries are compliant with the EU-DCC data specification.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC Demo

Introduction to DIVOC Modules

Each module or component of DIVOC can be <mark style="color:orange;">**used independently or together**</mark> and integrated with existing systems. This makes it easy for countries to choose, customise and pick up components as per their needs.

## **How this demo works**

The tutorials will guide you on how to use DIVOC:

* There are <mark style="color:orange;">**6 sections**</mark> and you can play around with each to understand how they work as per your specific needs.&#x20;

**Or,**

* You can go step-by-step as shown below: Program setup (via orchestration module) - Facility app - Issue and Verify Certificates - Citizen portal - Feedback module - Analytics.

## Getting Started

### [1. Program setup (via orchestration module): ](/v2-2/divoc-demo/program-setup-via-orchestration-module)

Before you start any public health program in your country, the orchestration\
module helps you establish multiple registries for the program, set up appointment schedules, and add vaccinators, among others.

### [2.  Facility app:](/v2-2/divoc-demo/facility-app)&#x20;

Enables walk-in registrations, verification, queue management, and vaccination. The app lets you:

* Enrol/register beneficiaries who walk into the facility for on-the-spot registration. The process to register is the same as shown for the [**citizen portal**](/v2-2/divoc-demo/citizen-portal). Pre-enrolled recipients can also walk into a facility.
* Verification of beneficiaries via offline or online mode.
* Recipient queue to view and manage the list of beneficiaries enrolled into the system.
* Vaccination event recording and generation of an “immutable vaccination record.”

### [3. Issue & Verify Certificates](/v2-2/divoc-demo/issue-and-verify-certificates) &#x20;

The certificate/credentialing module is an integral part of DIVOC, which can be used to issue certificates after a vaccination event. The module can also be integrated with the vaccination system of the country.&#x20;

### [4.  Citizen portal](/v2-2/divoc-demo/citizen-portal)&#x20;

DIVOC provides a public portal that can be used for citizen-specific activities such as self-registration and appointment booking for one or multiple programs. It can also be used to download and verify certificates.

### [5. Feedback ](/v2-2/divoc-demo/feedback)

Enables digital administrative feedback and reporting of side-effects by beneficiaries or their caretakers. The feedback module can be integrated with a country's analytics system or even with an AEFI (adverse event following immunisation) system for research and analysis of the reported side-effects.

### [6. Analytics ](/v2-2/divoc-demo/analytics)

The performance monitoring dashboard gives day-to-day details about an ongoing public health event such as vaccination.

### *Disclaimers:*&#x20;

* *Each section presents a demonstration of various modules and features of DIVOC.*&#x20;
* *It is an illustration of a sample use case and not a part of any vaccination certification program.*&#x20;
* *The system resets itself periodically. If it is temporarily unavailable, please try again in a few minutes.*

*All content on this page by* [*eGov Foundation* ](https://egov.org.in/)*is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Program Setup (Via Orchestration Module)

Using this module you can create and maintain program, facility, vaccine, and vaccinator registries. Countries that do not have digital health registries can use this module to create digital infrastructure/resources for any kind of public health program. Countries can also create appointment schedules and daily rates of vaccination for different facilities.

<table><thead><tr><th width="201" align="center">Program Registry</th><th width="186" align="center">Vaccine Registry</th><th width="174" align="center">Facility Registry</th><th align="center">Vaccinator Registry</th><th data-hidden></th></tr></thead><tbody><tr><td align="center">Vaccination programs</td><td align="center">Approved vaccines</td><td align="center">Approved facilities</td><td align="center"><p>Trained </p><p>vaccinators</p></td><td></td></tr><tr><td align="center">Active status</td><td align="center">Active status</td><td align="center">Location</td><td align="center">Active status</td><td></td></tr><tr><td align="center">Allowed vaccines</td><td align="center">Vaccination schedule</td><td align="center">Active status</td><td align="center"><p>Training </p><p>certificate</p></td><td></td></tr><tr><td align="center">Start and end dates</td><td align="center">Batch deny list</td><td align="center">Vaccination daily rate</td><td align="center"><p>Associated </p><p>facilities</p></td><td></td></tr><tr><td align="center">Certificate templates</td><td align="center">Max retail price</td><td align="center">Total supply</td><td align="center"><p>Rating and </p><p>feedback</p></td><td></td></tr><tr><td align="center"></td><td align="center">Vaccination method</td><td align="center">Rating and feedback</td><td align="center"></td><td></td></tr></tbody></table>

## Who would typically use this module?&#x20;

DIVOC comes with **three default roles**:

* [**System admin**](#1.-system-admin)&#x20;
* [**Program administrator**](#2.-program-administrator)&#x20;
* [**Facility admin**](#3.-facility-admin)

## Each has specific functions and logins assigned to them -&#x20;

### Steps to follow:

### **1. System Admin**&#x20;

A system admin can be a user from the IT department of the country responsible for setting up initial rules, configuration, and master data upload for a specific program/programs in question.

Use the following URL: [**https://demo-divoc.egov.org.in/portal**](https://demo-divoc.egov.org.in/portal). Log in using 2111111111 and OTP 1234

![](/files/uKw2ir7mFP1cua6hlG96)

**A. Program setup**

1\. Click on **Vaccine Programs**. Register a new vaccine/immunisation program by clicking on **REGISTER NEW VACCINE PROGRAM**.

![](/files/wsMlN1waF136o6Om2CJT)

2\.  Add the program name, program description, program logo, start and end dates, and select vaccine. Click on **SAVE**. You will see a list of all vaccine programs currently active in your country.

![](/files/67i0tNgyrpQlzkQXN32D)

**B. Vaccine registration**

1\. Click on **Vaccines**. You can register a new vaccine, as well as existing ones by clicking on **REGISTER NEW VACCINE.**

![](/files/IlwPTLTg0JdWR8IHIXFF)

2\. Fill in details such as the name of the vaccine, manufacturer, administration type,\
price, duration dose (if there are multiple doses), and vaccine validity. Next, click on\
**SAVE**. It will show all the vaccines active in your country.

![](/files/QaeZ7UyXhmYmQ8GqlHlb)

**C. Facility setup**

1\. Click on **Facilities.** Create a list of vaccination centres as per the given CSV template and save it on your laptop/desktop. You can add details such as facility code, facility name, contact, email, operating hour (start/end), category, type, status, address, website URL, admin name, and admin mobile.

2\. Click on **UPLOAD CSV** to upload this list.

![](/files/ic447fqa6CkcU13Xv2zz)

**D. Recipient pre-enrollment**

1\. Click on **Pre-Enrollment**. Create a list of the number of recipients successfully enrolled as per the given CSV template. You can add details such as phone number, identity, date of birth, gender, name, email, address, and dose number, among others. Once the list is ready, save it on your laptop/desktop. Click on **Select a Program.**

2\. Next, click on **UPLOAD CSV** to upload the list.

![](/files/xbXZuQcQZ8whbGObwcgN)

**E. Set up vaccinators**

1\. Click on **Vaccinators.** Create and save a list of vaccinators that have been identified and trained for the vaccination program/campaign as per the suggested CSV template on your  laptop/desktop. Add details such as code, name, mobile number, email id, status, and facility id.

2\. Click on **UPLOAD CSV** to upload the list.

![](/files/SMa07utf7a4RHphcuSI0)

### 2. Program administrator&#x20;

A program administrator manages facility enrollment and oversees the facility operations aligned with the program objective. The person would be responsible for setting up per day facility vaccination rate, and activating/deactivating the facilities, etc.

Use the following URL: [**https://demo-divoc.egov.org.in/portal**](https://demo-divoc.egov.org.in/portal). Log in using 1111111170 and OTP 1234

![](/files/ioOZeXbygu9gDg7n8y3n)

**A. Facility activation/deactivation**&#x20;

Go to **Facility Activation**. Select Program, Region, and Type of Facility. Select the facilities you want to activate from the list. Click on **Make Active**. To deactivate a facility, follow the same steps and select the facilities you want to deactivate. Click on **Make Inactive** to deactivate a facility.

![](/files/3sxnrqlFWmrr3YF6Px1e)

**B. Adjusting vaccination rate**

Go to **Adjusting Rate**. Select Program Name, Region, Type of Facility. Select one or more facilities to set/modify daily vaccination rates. Click on **SET RATES**.

**C. Notify Facilities**

1\. Go to **All Facilities**. Select Program, Region, Type of Facility. Select the facility. Click on **NOTIFY**.

![](/files/LyuhbFpjyOVIWUo9O1RP)

2\. Write the subject matter and the message. Click on **SEND**.

![](/files/Xz8BJcNXEbvMe1YosBBb)

### 3. Facility Admin

Use the following URL: [**https://demo-divoc.egov.org.in/portal**](https://demo-divoc.egov.org.in/portal). Log in using 3333333341 and OTP 1234.

![](/files/rVyOWLJSuzxaTXFDtwqm)

**A. Set up appointment schedules**

1\. Go to **Program Overview**. Click on **CONFIGURE SLOTS**.

![](/files/fuf8cfECHtQDF9tWCv0b)

2\. Select **Appointment Hours** to set/change the timings, and set up/change the **Maximum number of appointments allowed**. Select **Walk-in Hours** to set up /change the timings, and set up/change the **Walk-in Days**. Click on **SAVE.**

![](/files/YPxgygm6O3qwxxaAycwm)

**B. Add/Remove Vaccinators**

1\. Go to **Vaccinator Details**. Click on **ADD NEW VACCINATOR**.

![](/files/XOn72NGXXMec3Q66zkNy)

2\. Enter details such as name, mobile number, email id, license number, and certification, if any. Click on **ADD**.

![](/files/IKfkTaSt1RkgLYQq4xFT)

**C. Setup facility staff role**

1\. Go to **Role Setup**. Mention role type, name, mobile number, and employee id. Select Enabled to activate status. Click on **SAVE**.

![](/files/jRkxd9ae1LfETjUpRz73)

**D. Create recipient vaccination details**

1\. Go to **Upload Vaccination Details**. Create a list of recipients as per the given CSV template and save it on your laptop/desktop. You can add details such as pre-enrollment code, recipient name, mobile number, age, gender, identity, address, vaccination batch, vaccination date, vaccination dose, vaccination name, vaccinator name, facility name, and address, among others.

2\. Click on **UPLOAD CSV** to upload this list.

![](/files/zdPGVBpOtNwKsftxjJlB)

**E. Check beneficiary list (past, current and upcoming)**

Go to **Beneficiaries**. Select Program, Start Date, and End Date. Click on **SEARCH**.

![](/files/0o8VGul46EGaSVbUDhhf)

*All content on this page by* [*eGov Foundation* ](https://egov.org.in/)*is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Facility App

## Who would typically use this?

It will be typically used by facility staff, including vaccinators and registration desk users, to carry out day-to-day tasks around a particular vaccination program. The app can be used both in <mark style="color:orange;">**offline and online modes**</mark>. This is a multilingual application and the staff can choose the language according to their convenience.

![](/files/q47etjAAQjlyG20zqViZ)

## What does this app allow?

### **1. Verify Beneficiary**

This function can be used to verify a beneficiary against the photo/national ID proof submitted by the beneficiary at the time of registration. If a country has an online ID system (such as Aadhaar in the case of India), the module can be integrated with the national ID system and can perform an online verification.

**Step 1: Log in**&#x20;

Click on the following URL to use the facility app: [**https://demo-divoc.egov.org.in/facility\_app/.**](https://demo-divoc.egov.org.in/facility_app/.) Log in using 9876543210 and OTP 1234. Next, click on **Verify Beneficiary.**

![](/files/k3tGseY8K6s6D0PXJQ05)

**Step 2: Verify**

Scan the QR code or enter the enrolment number. Press **Continue** to complete the verification proces&#x73;**.**

![](/files/YmiIVdoMWBp0M6W1rcF6)

### **2. Add new beneficiaries**

The facility app supports the registration of walk-in patients who may or may not have booked an appointment before the visit.

Click on **New Beneficiary**. Follow the same steps as outlined for users of the [**Citizen Portal**](/v2-2/divoc-demo/citizen-portal#steps-to-follow) to add members.

### **3. Recipient waiting**

All the beneficiaries who have been registered and verified, and are waiting to be vaccinated, will be seen in the recipient queue.

Click on **Beneficiary Queue** to check how many patients are in queue for vaccination.

![](/files/bylGK4qHUgcaANPZq1Vy)

### **4. Issue/Distribute Certificates**

After a vaccination event, the facility app generates a digital certificate in real-time.&#x20;

* Countries that have their own vaccination systems can use the DIVOC certification module to issue certificates that will be auto-generated and stored in DIVOC’s certificate registry.&#x20;
* If configured, the issued certificates will be seen under the “certificate issued” section on the app. They can also be distributed to vaccinated beneficiaries at a facility after they are printed by the facility staff.

*All content on this page by* [*eGov Foundation* ](https://egov.org.in/)*is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Issue and Verify Certificates

## What does this module allow?&#x20;

* It allows issuing authorities to issue digitally verifiable certificates.&#x20;
* The [**facility app**](/v2-2/divoc-demo/facility-app) can be used to generate digital certificates, as well as distribute them.
* The staff of a particular facility can use the [**facility app**](/v2-2/divoc-demo/facility-app) to verify a beneficiary.
* Certificates can also be verified and downloaded via the [**citizen portal**](https://divoc.digit.org/v2-2/divoc-demo/pages/ZewaVGl8Ggsp0imFvYlb#3.-for-certificate-verification). &#x20;
* If the country has an authorised third-party app, it can be integrated with DIVOC's credentialing module to fetch certificates from the certificate registry and view/download them.
* Click [**here**](/v2-2/platform/divocs-verifiable-certificate-features) to know more on the certificate generation service of DIVOC.

*All content on this page by* [*eGov Foundation* ](https://egov.org.in/)*is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Citizen Portal

## **Who would typically use this?**

Citizens can use this portal before and after a vaccination event.

## **What this module allows**

* [Self-registration](#1.-for-self-registration-and-appointment)
* [Appointment booking](#1.-for-self-registration-and-appointment)&#x20;
* [Downloading a certificate](#2.-for-downloading-a-certificate)&#x20;
* [Verifying a certificate](#3.-for-certificate-verification)
* [Side-effects reporting (Feedback module)](/v2-2/divoc-demo/feedback#citizen-portal-to-report-symptoms)

### **Steps to follow**

### **1. For self-registration and appointment -**

**Step 1: Log in to the portal**

Use the following URL for the citizen portal: [**https://demo-divoc.egov.org.in/citizen**](https://demo-divoc.egov.org.in/citizen)**.** Log in using your own mobile number and OTP 123456. Click on **Verify**.

![](/files/PMBsvdIKQJv743yBc4D9)

**Step 2: Add a member**

Click on **+Member** to add members (you can register yourself and 3 more with a single mobile number).

![](/files/GT1C7getpHgyAVHpe3iE)

**Step 3: Register to a program**

Select the program for which you want to register (if there are multiple programs listed). Click on **Continue**.

![](/files/ogGpWh5O4krK6VlyyfaJ)

**Step 4: Check eligibility**

Enter the beneficiary’s year of birth and mention if the person has any commodities from among those listed. Click on **Continue**.

![](/files/XmlgHRWvlyUR4ZbTCBG4)

**Step 5: Add details**

Mention ID type, ID number, name, gender, residence details, contact information, and email ID among others. Once you have added all the details, click on **Continue**. You can book your appointment once you have registered yourself.

![](/files/xXzjrkengUgJC7AMEDRv)

### **2. For Downloading a Certificate -**

**Step 1: Log in**

Click on the following URL to log into the citizen portal: [**https://demo-divoc.egov.org.in/**](https://demo-divoc.egov.org.in/). Go to **Download your Vaccination Certificate** section. Click on **Download**.

![](/files/TOQcORXUV85M7zAy16eN)

Log in with 1234567890 and OTP 1234.

![](/files/dLluWuc5yblCCSdhubPU)

**Step 2:**

Select the person whose certificate you want to download or print.

![](/files/hM5QVueY5BS6UI0b4Sw4)

**Step 3:**

Once the certificate is displayed, click on **Download / Print**.

![](/files/3jzH7mZHTBvsNf6ZYqDa)

### **3. For Certificate Verification -**

**Step 1:**

Click on the following URL: [**https://demo-divoc.egov.org.in/**.](https://demo-divoc.egov.org.in/.) Go to **Verify your Vaccination** Certificate section. Click on **Verify**.

![](/files/IoogVqNwPeesRm9ScA88)

**Step 2:**

Click on **SCAN WITH QR** to verify the certificate.

![](/files/W8yQ7nW7waav4WQ6KNlt)

*All content on this page by* [*eGov Foundation* ](https://egov.org.in/)*is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Feedback

## Who would typically use this?&#x20;

DIVOC has a feedback module that can be configured by countries to receive feedback on facilities that are running health campaigns. It can also configure a list of side-effects that can be reported by beneficiaries with a single click after authenticating themselves with a user ID password or mobile OTP via the [**Citizen portal**](/v2-2/divoc-demo/citizen-portal).

## Citizen portal to report symptoms&#x20;

A citizen interface via DIVOC’s citizen portal has been enabled that can be used to provide feedback against the facility or report side-effects experienced after leaving the facility.

### Steps to follow

**Step 1:**

Click on the URL to open the feedback page: [**https://demo-divoc.egov.org.in/**<br>](<https://demo-divoc.egov.org.in/&#xA;>)

**Step 2:**

Go to the **Report symptoms** section, and click on **Report Side-effects**.

![](/files/l9xL2dxippB25T8PMgRI)

**Step 3:**

A page will be displayed with a list of symptoms that users can choose from. After selecting the symptoms, click on **Confirm Symptoms**.

![](/files/IjcKQRNTZUc3yuVoRHmD)

**Step 4:**

Log in with 1234567890 and OTP 1234.&#x20;

![](/files/ckBe6tN9r1daW5qR5cOo)

**Step 5:**

On successful login, a patient verification page will be displayed. Select the patient who has these symptoms and click on **Submit**.

![](/files/nXGSMQPOQgWSCAplyhyi)

**Step 6:**

Click on **Confirm Patient** after verifying the details.

![](/files/ppcZWKfgCDC8mO2sh5Bh)

**Note:**

Once the feedback is submitted, a notification is sent to the healthcare facility where the patient was vaccinated. The screen will also display details of the nearest health facility that the patient can visit if the symptoms worsen. Click on **Continue** if you want to report the symptoms of another person.

![](/files/J4p2T3uP9J6deDQjvN6e)

*All content on this page by* [*eGov Foundation* ](https://egov.org.in/)*is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Analytics

## Who would typically use this?

During any major health event, countries need powerful visual analytics to manage the rollout, distribution, certification, and other processes. DIVOC’s analytics dashboard empowers health departments of countries to harness their data and find insights that are required to manage future challenges.

## Real-time analytics oversee the entire process

* It uses an open-source visualisation dashboard called “Redash,” which can be configured by countries.
* It is integrated with DIVOC’s [**certificate module**](/v2-2/divoc-demo/issue-and-verify-certificates). Redash can be configured for other modules of DIVOC as well as per a country's requirements.
* Countries can generate customised analytical reports without hampering the actual production database via ClickHouse, an open-source database management system that has been implemented by DIVOC.

![](/files/LXPPcFd7vagMlcy3OiiO)

* You can also see details on certificate generation and its distribution for further analysis on parameters such as geographical region, age, gender, type of facility, type of fund, and other customised indicators.

![](/files/to6zkNu0KUGecH61VK4y)

*All content on this page by* [*eGov Foundation* ](https://egov.org.in/)*is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Roadmap

The DIVOC roadmap is a snapshot of our upcoming features and tools.

Click below to view the DIVOC roadmap:

{% embed url="<https://miro.com/app/board/uXjVPFYgMmM=/>" %}

### Quarter 1+Quarter 2: April-September 2022

<table><thead><tr><th width="245">Feature</th><th>Description</th></tr></thead><tbody><tr><td>Manage multiple tenants</td><td>Services to manage multiple tenants and their respective schema.</td></tr><tr><td>Create verifiable credentials (VCs) from multiple issuers</td><td>Ability to create VCs with different schemas for one tenant and to create VCs from multiple issuers.</td></tr><tr><td>Ability to update schema</td><td>Ability to make changes or updates to available schemas.</td></tr><tr><td>Service to generate and send only QR code (SVG) with provided dimensions</td><td>The tenant/issuer system can fetch images of QR codes in provided dimensions. The image can be shared with the beneficiary directly or can be embedded in the certificate template designed by the issuer/tenant system.</td></tr><tr><td>Services to update certificate</td><td>Capability to update/modify already generated certificates.</td></tr><tr><td>Revocation and suspension</td><td>Capability to revoke or suspense already issued certificates upon expiry, issuance of a newer version, or violation of terms and conditions.</td></tr><tr><td>Notification services</td><td>Capability to notify beneficiaries on the generation of certificates.</td></tr><tr><td>Enabling multi-lingual certificate</td><td>Functionality to manage certificate templates in multiple languages and generate certificates based on selected templates.</td></tr></tbody></table>

### Quarter 3: October-December 2022

<table><thead><tr><th width="250">Feature</th><th>Description</th></tr></thead><tbody><tr><td>Common verification portal</td><td><p>A common verifier portal for verifying VCs created by multiple schemas and from multiple issuers. The portal will have a UI that will be accessible to the public, or those with credentials to access them. For example, a doctor with a VC for council registration created by the DIVOC platform submits the same to an employer (a hospital). The hospital can then go to the common verification portal URL and verify the VC. </p><p></p><p>The verification portal can verify the following:  </p><p>1. Authenticity (If the certificate has been tampered with). </p><p>2. Status (The certificate is revoked/suspended/is valid/is not valid).</p></td></tr><tr><td>Tenant onboarding user interface </td><td><p>A use interface through which the source system admin can: </p><p>1. Log in to the DIVOC platform with the credentials received. </p><p>2. Reset the password if not accessible. </p><p>3. Generate tokens to connect the source system and DIVOC platform.</p></td></tr><tr><td>Tenant creates schema user interface</td><td>A user interface through which the source system admin can define and create schemas for different provider types, and also test and publish the schemas.</td></tr></tbody></table>

### Other features under consideration

* Verification app
* Telemetry capability for the platform
* Capability to issue multiple key pairs for different tenants
* Building trust network for key management
* Proof of concept of the VC capability

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Partner Support

DIVOC is an open source project (MIT license), and it is maintained by [**eGov Foundation**](https://egov.org.in).

Documentation is available at [**https://divoc.egov.org.in/**](https://divoc.egov.org.in) and source code is available at [**https://github.com/egovernments/DIVOC**](https://github.com/egovernments/DIVOC).

If you have questions, please visit our [**project discussions page**](https://github.com/egovernments/DIVOC/discussions)**.**&#x20;

Click [**here**](/v2-2/community/about-project-team/terms-and-conditions-of-using-the-divoc-site) to know about the terms and conditions of using the DIVOC site.

Click [**here**](/v2-2/community/about-project-team/privacy-policy-short-version-for-display) to know about DIVOC's privacy policy - short version for display.

Click [**here**](/v2-2/community/about-project-team/privacy-policy-detailed) to know about DIVOC's privacy policy - detailed.&#x20;

Click [**here**](/v2-2/community/about-project-team/platform-policy-guidelines) to know about platform policy guidelines.

Click [**here**](/v2-2/community/about-project-team/privacy-policy-recommendations) to know about privacy policy recommendations.

Click [**here**](/v2-2/community/about-project-team/common-infrastructure-issues-and-their-recovery-instructions) to know more about common infrastructure issues and their recovery.&#x20;

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Terms and Conditions of Using the DIVOC Site

This website/ (“Website”) has been developed and is being maintained by eGov Foundation (“eGov”). This Website provides information related to the digital infrastructure called DIVOC developed by eGov. The Website is an invitation for users to learn about DIVOC, its building blocks, various use-cases, access technical documentation, and engage with the DIVOC community to learn how to use and/or adopt eGov Foundation (“Purpose”).

eGov Foundation is a not-for-profit registered as a Trust, having its office at 147/J , first floor, 10th Cross, 12th Main, Koramangala 3rd Block, Bangalore 560034.

By using the Website, you have accepted and agree to be governed by these Terms of Use (“Terms”), as may be amended from time to time. The terms ‘you’, ‘your’ refer to anyone who accesses, views or uses the Website. The terms "we", "us", "our" refer to the eGov Foundation.

Set out below are the Terms of Use of this Website:

### Definitions

“Asset” means and refers to a piece of content or software code. A piece of content can be expressed as text, documents, presentations, scripts, graphics, photos, sounds, music, videos, audiovisual combinations, RLO (reusable learning object) or other such mediums of expression and other materials you may view on, access through, or contribute to the Website, and includes all postings on the Website by Users.

"Intellectual Property" shall singly or collectively mean to include, as the case may be, all patents, copyrights, trademarks, trade names, service marks, service names, designs and any other proprietary information or other similar right arising or enforceable under Indian law.

“DIVOC” (The Digital Infrastructure for Vaccination Open Credentialing) is an open-source platform that enables countries to digitally orchestrate large-scale health campaigns such as vaccination and certification programs.

“User” means and refers to all users of the Website who access the Website and Use the Assets on the Website in accordance with these Terms.

“Use” or “Using” means and refers to learning, finding, viewing, using, contributing to, modifying, replicating, downloading, and sharing Assets with other Users, through the Website.

### ACCESS AND USE

As a User you represent and warrant that you are of legal age and are legally competent to consent to these terms (or if not, you've received your parent's or guardian's permission to Use the Website and they have agreed to these Terms on your behalf). If you’re agreeing to these Terms on behalf of a department, institution, organisation or legal entity, you represent and warrant that you are duly authorised to agree to these Terms on behalf of that department, institution, organisation or entity and these Terms are binding on them.

All Users shall have access to all the Assets available on the Website for the purpose of learning, finding, viewing, Using, contributing to, modifying, replicating, downloading, and sharing Assets with other Users, through the Website. It is possible that your access and Use of Assets on the Website may be disrupted due to technical or operational difficulties and with no prior notice of downtime. eGov Foundation makes no guarantee as to the continuous uptime and availability of the Website or the quality of Assets on the Website.

### OBLIGATIONS OF USERS

You access the Website only to Use the Assets. You will be responsible and liable for any activity on the Website by you. You will not attempt any activity with respect to the Website that is in contravention of the laws of India and/or the laws of the jurisdiction in which you are presently located. You will follow these Terms of Use and all the policies of the Website.

### INTELLECTUAL PROPERTY RIGHTS

The Website contains copyrighted material, trademarks and other Intellectual Property owned by the eGov Foundation. All our website content is licensed under the CC BY-ND 4.0 License. It allows users to share, copy and redistribute the material on giving appropriate credit to eGov Foundation without any changes or transformations of the content. You agree to abide by all licenses and copyright notices accompanying any Asset published on the Website. Any Asset (other than software code) you contribute to DIVOC or the Website is licensed under the Creative Commons Attribution-ShareAlike 4.0 International - CC BY-SA License.

You can share and adapt the licensed Assets under the terms of the same license, provided you cite the creator as eGov Foundation, or the relevant party if the creator is not eGov Foundation, include a link to the original publication on the Website with copyright notice, license notice and disclaimer notice, and indicate if changes were made. You may do so in any reasonable manner, but not in any way which suggests that eGov Foundation endorses you or your Use. For any assistance with contributing to DIVOC or the Website or understanding any license, please contact us at <support.divoc@egovernments.org>.

Assets that are software code and are released under DIVOC and made available on/through the Website are licensed under the MIT license reproduced below:

Copyright (c) 2022 eGov Foundation: Permission is hereby granted, free of charge, to any person obtaining a copy of all software and associated documentation files (the "Software") listed on this website under this \_\_\_\_\_\_, to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT.

IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

### PRIVACY POLICY

By Using the Website and/or by providing your information, if applicable, you consent to the collection and use of the information you disclose on the Website in accordance with our Privacy Policy. eGov Foundation takes the privacy of its Users very seriously. Please refer to our Privacy Policy for complete details.

### LIMITED LIABILITY

We do not guarantee the accuracy, veracity, correctness, validity, usability, currency, of any Assets made available on or linked through the Website. We shall not be held responsible for any offensive or unlawful Asset posted, transmitted, sent or communicated through the Website.

### DISCLAIMER

eGOV FOUNDATION PROVIDES THE WEBSITE ON AN "AS IS" BASIS AND GRANTS NO WARRANTIES OF ANY KIND WITH RESPECT TO THE WEBSITE. eGOV FOUNDATION SPECIFICALLY DISCLAIMS ANY IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, OR OF NON-INFRINGEMENT. ACCESS AND USE OF THE WEBSITE (INCLUDING ANY ASSET OR INFORMATION AVAILABLE ON/THROUGH THE WEBSITE) IS ENTIRELY AT YOUR OWN RISK.

### INDEMNITY

You hereby agree to keep and hold the eGov Foundation, its directors, officers, employees and agents, fully indemnified and harmless from and against all claims, proceedings, penalties, damages, losses, actions, costs and expenses arising out of or in relation to your Use of the Website, your breach of these Terms, violation of any law, rules or regulations in relation to your Use of the Website.

### TERMINATION

Any violation or breach of the Terms may lead to automatic suspension or termination of your access to the Website, including while investigating complaints or alleged violation of these Terms, or for use or attempt to use the Website for any purpose other than to share Assets.

### ELECTRONIC AGREEMENT

This document is a written agreement and an electronic record and valid and enforceable electronic agreement / contract under Information Technology Act, 2000 (as applicable in Republic of India) and rules there under as applicable and the amended provisions pertaining to electronic records in various statutes under applicable Indian laws. This electronic record is generated by a computer system and does not require any physical or digital signatures. Your usage of the Website shall be your deemed acceptance of these Terms and all the modifications and updates thereto.

### GOVERNING LAW AND DISPUTE RESOLUTION

These Terms shall be governed by the laws of India and any disputes or proceedings arising hereunder shall be subject to the jurisdiction of the courts in Bangalore.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Privacy Policy: Short Version for Display

At DIVOC (“we” or “us” or “our”) we respect the privacy of our users (“user” or “you” also referred to as ‘your’) and are committed to protecting it. Hence, we maintain the highest standards for secure activities, user information/data privacy and security. This Privacy Policy explains what information we collect about you and why.&#x20;

### Summary

We hope you read this entire privacy policy. However, if you are in a hurry, here is a brief overview of the most important point:

* Primarily we provide recommendations to implementing partners or service providers (include any governmental organisation, agency, department as well as private or corporate bodies) on certain privacy protecting principles and practices. They are advised to share it with citizens regarding their personally identifiable Information and how it is managed in DIVOC.
* DIVOC services follow the [WHO DDCC:VS ](https://apps.who.int/iris/bitstream/handle/10665/343361/WHO-2019-nCoV-Digital-certificates-vaccination-2021.1-eng.pdf?sequence=1\&isAllowed=y)which includes compliance with principles of legitimate use, fair processing, accountability, transparency, purposeful, proportional, minimal and lawful collection, usage, storage and disclosure of personally identifiable information (“PII”), confidentiality and security of data.
* Through DIVOC any implementing partner (national governmental bodies, department, local bodies & their agencies) corporate/private bodies (utility services) (Service Providers) could collect the following datasets -

&#x20;     first name, last name, parent’s / guardian’s name, address, unique identifier, nationality, date of birth, mobile number (optional dataset), age, gender (optional dataset), identification documents (for example passport number), vaccine details (batch number, dosage number, date of vaccination, total number of doses, country of vaccination), payment information ([https://divoc.digit.org/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code](<https://divoc.digit.org/platform/divocs-verifiable-certificate-features/what-information-goes-into-a-qr-code&#xA;>)).

* The service provider may collect data such as vaccine manufacturer, vaccine market authorisation holder, vaccine administering centre, health worker identifier, due date of next dose, certificate valid from, certificate valid from and to period, certificate issuer, and health certificate identifier (certificate id).
* For the upkeep and working of our website we collect information such as Internet Protocol (IP) addresses, domain name, browser type, Operating System, Date and Time of the visit, pages visited, IMEI/IMSI number, device ID, location information, language settings, handset make & model etc. However, no attempt is made to link these with the true identity of individuals visiting our website, implementing partner or service providers application or platform.
* The information collected by us shall depend on the need of the service providers and interests of the users. Datasets collected shall be subject to change from time to time, (please check our privacy policy for any updates/changes as well as changes in the service providers privacy policy).
* We provide a checklist to service providers for data protection , only after which they can install and use DIVOC. Click here to see the [**checklist**](https://divoc.digit.org/community/about-project-team/platform-policy-guidelines). We also provide them with[ **recommendations and guidelines**](https://divoc.digit.org/community/about-project-team/privacy-policy-recommendations) to create privacy policies for their frontend applications.
* We do not store any of your data (for example, we do not store any persons medical history).
* We do not and will not share your information with third parties which you would have not been aware of and consented to sharing.
* We only collect data which you provide to us through the service provider or when you access our website (for example, data supplied by you on subscribing to our emailing list, or any grievance/complaint data).

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Privacy Policy: Detailed

At DIVOC (“we” or “us” or “our”) we respect the privacy of our users (“user” or “you” also referred to as ‘your’) and are committed to protecting it. Hence, we maintain the highest standards for secure activities , user information/data privacy and security.&#x20;

This Privacy Policy explains what information we collect about you and why.

### What is DIVOC?&#x20;

DIVOC (Digital Infrastructure for Verifiable Open Credentialing) is an open-source digital platform that has enabled governments across the world to issue, distribute and verify secure and  tamper-proof COVID-19 vaccination and test result digital certificates, at scale. DIVOC, a Digital Public Good (DPG) by eGov Foundation, is designed in accordance with precise international specifications, is recognised by 120 countries globally and is compliant with WHO and EU standards.&#x20;

DIVOC refers to the services being provided through the DIVOC platform. To know more about the services provided, please refer to our [**website**](https://divoc.egov.org.in/divoc-modules/).&#x20;

Through DIVOC, any implementing partner (national governmental bodies, department, local bodies & their agencies) corporate/private bodies (utility services) (Service Providers) can use DIVOC website/application/services in different ways such as for issuing and verifying certificates, set up registries for streamlines public health program executions, etc.

### ADHERENCE TO DATA PRIVACY PRINCIPLES&#x20;

The DIVOC data dictionary follows the [**WHO DDCC:VS**](https://apps.who.int/iris/bitstream/handle/10665/343361/WHO-2019-nCoV-Digital-certificates-vaccination-2021.1-eng.pdf?sequence=1\&isAllowed=y) which includes compliance with principles of legitimate use, fair processing, accountability, transparency, purposeful, proportional, minimal and lawful collection, usage, storage and disclosure of personally identifiable information (“PII”), confidentiality and security of data.

### WHAT DATA DO WE COLLECT?&#x20;

DIVOC collects information/data (“data”) to improve and provide better public health programme execution. We collect and process PII such as your first name, last name, parent’s/guardian’s name, address, unique identifier, nationality, date of birth, mobile number, age, gender, identification documents, vaccine details (batch number, dosage number, date of vaccination, total number of doses, country of vaccination).

We may collect data such as vaccine manufacturer, vaccine market authorisation holder, vaccine administering centre, health worker identifier, due date of next dose, certificate valid from, certificate valid from and to period, certificate issuer and health certificate identifier ( certificate id).&#x20;

We collect information such as Internet Protocol (IP) addresses, domain name, browser type, operating system, date and time of the visit, pages visited, IMEI/IMSI number, device ID, location information, language settings, handset make & model etc. However, no attempt is made to link these with the true identity of individuals visiting the relevant our website, implementing partner or service providers application or platform.&#x20;

The information collected by us shall depend on the need of the service providers and interests of the users. Datasets collected shall be subject to change from time to time. Such changes shall be reflected in the privacy policy of the service provider (if nature of data changes from the service provider perspective) or our website’s privacy policy (if we change the nature of data collected).

### FOR OUR WEBSITE

The internet address associated with your computer, the type of web browser you use, your operating system, the site that referred you to us, the pages you visited, and the dates and times of those visits.

### HOW DO WE COLLECT THIS DATA?&#x20;

DIVOC collects data directly from the user (when the user uses our services) as and when you register and login into the service providers app/website. DIVOC may also collect data from national governments (union, state, and local governments or any other governing body, including their agents/employees), private bodies (only after our data protection and privacy guidelines are adhered to) as well as receive data that is available openly for public use.

We also collect data that any visitor to our website consensually provide to us (for example, data provided to make a complaint, customer query, or to subscribe to our emailing list).

### HOW DO WE STORE THIS DATA?&#x20;

Your data is stored in a secure manner on the implementation partner provided space. It does not allow your data to be visible to anyone, except persons who are authorised to do so by virtue of their official role. Unless indicated otherwise, this data will be retained for a minimum period as per implementing countries laws and a maximum period of as per implementing countries' laws. You can review and edit your data, as well as delete your data from the app/website by following the procedures as per implementing countries laws.

You may delete your account any time you wish. In case of deletion, we will remove all your PII from the system, so that it is not visible and/or accessible from any regular operation.

After deletion, in case you wish to recreate your profile, the same is permissible and none of the previously captured information will be populated automatically. You need to register as a fresh user.

If you simply delete/remove the application from your mobile device but do not delete your profile or unregister yourself from the app/website, you shall continue to be a registered user of the app and we shall continue to send you all communications that you have opted for unless and until you opt-out of such communications, or as per implementing countries laws.

In case you surrender/disconnect your registered mobile number it is recommended to delete your profile or unregister yourself from the application also.

### WHY AND HOW DO WE PROCESS, DISCLOSE, AND/OR SHARE THIS DATA?

We collect only such data as serves these objectives. Specifically:

* We process this data as necessary to provide you with the services you are requesting (for example, to get your vaccination certificate issued or verified) through the service providers application (for example, in India, the CoWin app is the national government’s application used by citizens for issuance of vaccination certificates).
* We may process, disclose, or share certain metadata, as well as aggregated and anonymised data, in order to assess and improve the status of such service delivery over time.
* We may disclose or share this data to/with employees and/or contractors of the government agencies, service providers, whose role requires them to view or use this information in order to perform their official duties, including providing you the service(s) you are requesting.
* Resolving any disputes that may arise with respect to the transactions/deals that you may conduct using the service providers app/website.
* Detecting, investigating and preventing activities that may violate our policies or that may be illegal or unlawful.
* Conducting research or analysing the user preferences and demographics as statistical data and not as individual data.
* We may disclose or share this data in order to comply with the law or any legal process, including when required in judicial, arbitral, or administrative proceedings.
* Payments made through the government’s or service providers App/website are processed via secure payment gateways.

*We will not process, disclose, or share your data except as described in this policy or as otherwise authorised by you.*

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Platform Policy Guidelines

## Data backup policy recommendations

The following checklist should be followed for data protection:

* Implement least privilege, restrict users to only data and system information that is required to perform their tasks.
* The full backup of data should be taken once a day:

&#x20;      \- Postgres DB&#x20;

&#x20;      \- Redis cache

&#x20;      \- Kafka&#x20;

&#x20;      \- ETCD

* The full backups are retained for two weeks.
* Incremental backups (hourly) are retained for one day.
* Once the full backup is taken successfully, incremental backups can be purged.
* Backup files will be kept in a separate environment.
* Backup files will be encrypted before storing on another environment/server.

## **Authentication and password management**

Authenticating the identity of a principal and verifying its authorisation to act are foundational controls that other security controls are built upon. Organisations should standardise on an approach to both authentication and authorisation. Consider the following authentication and password management:

* The communication channels need to be encrypted to protect authentication tokens. Use only HTTPS POST/GET requests to transmit authentication credentials.
* All keys, passwords, and certificates must be properly stored and protected.
* Disk level encryption should be implemented.
* All authentication controls must be enforced on a trusted system (such as the server). Partition site by anonymous, identified, and authenticated areas.
* Establish and use standard, tested, authentication services whenever possible.
* Use a centralised implementation for all authentication controls, including libraries that call external authentication services.

## Error handling and logging

Exception handling is a programming concept that allows an application to respond to different error states (such as network down, database connection failure, etc.) in various ways. Handling exceptions and errors correctly are critical to making your code reliable and secure.

Error and exception handling occur in all areas of an application, including critical business logic as well as security features and framework code. Error handling is also important from an intrusion detection perspective. Certain attacks against your application may trigger errors, which can help detect attacks in progress. Consider the following:

* All logging controls should be implemented on a trusted system (such as the server).
* Restrict access to logs to only authorised individuals.
* All the system and system access logs should be enabled.

## **System configuration**&#x20;

The following checklist should be followed for system configurations:

* Ensure servers, frameworks, and system components are running the latest approved version.
* Ensure servers, frameworks, and system components have all patches issued for the version in use.
* Restrict the web server, process, and service accounts to the least privileges possible.
* When exceptions occur, fail securely.
* Remove unnecessary functionality and files.
* Remove test code or any functionality not intended for production, before deployment.
* Remove unnecessary information from HTTP response headers related to the OS, web-server version, and application frameworks.
* Implement a software change control system to manage and record changes to the code/ configuration/scripts in both development and production.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Privacy Policy Recommendations

## Privacy notice for citizens&#x20;

We recommend that you include the privacy notice in the platform. This information should be shared by implementing countries with their citizens. The privacy notice should have the following sections: &#x20;

1. Purpose of processing
2. What information is collected
3. Retention of information
4. Grievance officer details
5. Sharing of information with third parties
6. Usage of cookies, what information is stored in cookies
7. Security measures taken for processing/storing information
8. Rights of individuals

## Privacy policy guidelines for an implementing country

We recommend that the following guidelines should be followed by a country that is implementing DIVOC:

* A citizen's consent should be collected against the privacy notice and a centralised database should be maintained to log consent provided by the citizen (wherever applicable).
* The privacy notice should ask people to connect with the privacy officer/grievance officer to exercise his/her right to withdraw their consent.
* Personal data should only be accessible to limited individuals. In case third parties require access to the application for administrative purposes, we recommend you de-identify personal information.
* Organisations should not retain the information for longer than it is required for the purpose for which the information was originally collected.
* A formal document should be created to define the roles and responsibilities of personnel having access to personal data stored in the application.
* Document an access matrix for the application. Ensure that regular reviews are conducted on the access matrix.
* Review user access rights vis-à-vis the roles defined regularly.
* Platform end-users (citizens) should be informed about the mechanisms to update their information through the privacy notice.
* Platform end-users (citizens) should be informed about the mechanisms to update their information through the privacy notice.
* Perform security testing on the application regularly. We also recommend that you fix all the vulnerabilities after the testing is performed, on-time.
* Sign agreements/contracts with third parties, wherever applicable, including relevant security and privacy clauses.
* Obtain explicit consent against the privacy notice from the individuals whenever sensitive personal data is processed.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Common Infrastructure Issues and their Recovery Instructions

## Levels of Support

L1: It is the initial level of support provided by the user help desk. They help to screen the issues and typically handle queries like "how to," FAQs, user creation, password resets, etc.

L2: It deals with support tickets that can be resolved by doing basic configuration in the application or suggesting workarounds. Other activities typically include environment management e.g. server monitoring, server management etc. For L2 support, we expect a team of infrastructure management-related skill sets.

L3: It deals with tickets typically requiring minor country-specific code changes (certificate templates, logo, UI, and not core platform code), analysis of changes in new/patch versions, data queries, handling environment issues that cannot be resolved by L2 staff. For L3 support, we expect a team of software engineering-related skill sets.

L4: It deals with tickets related to product enhancements or product defects. This would typically be worked on by the DIVOC team, which, in turn, will either release a hotfix, patch release, or bundle it in the next release, or defer/deprioritise.

## **Troubleshooting Guide for L2**

### 1. If you are getting the response as 401:

* Possible causes: Token has expired.

&#x20;     \- Check access token is valid or correct for API call.

* Action to be taken:

&#x20;    \- Open postman.

&#x20;    \- Create a POST request to /auth/realms/divoc/protocol/openid-connect/token endpoint.

&#x20;    \- Add the following parameters:

&#x20;       client-id as admin-api&#x20;

&#x20;       Grant-type as client-credentials&#x20;

&#x20;       Client\_secret as

&#x20;    \- Once the request is sent, you will receive the auth\_token as part of the payload.

&#x20;    \- Modify the ADMIN\_API\_SECRET parameter within divoc-config.yaml file.

&#x20;    \- Restart all the services using: kubectl rollout restart deployments -n \<namespace of divoc  installation>

### 2. If you are getting the response as 405:

* Action to be taken:

&#x20;     \- Check if the Content-Type in the header section is set as ‘application/json’

&#x20;     \- If not, set the Content-Type as ‘application/json’

### 3. If you are getting the response as 602:

* Action to be taken:

&#x20;    \- Check if the payload is missing any parameter value like ‘preEnrollmentCode’, ‘recipient.name’, etc.

&#x20;    \- If yes, add the missing parameter and check.

### **4. If you are getting the response as 400:**

* Action to be taken:

&#x20;     \- Check if the format of value in payload or json structure is as per the expected structure. For example - format of date value, dose count is number or string, etc.

&#x20;     \- If not, correct the value type in the payload.

### 5. If you are getting the response as 504:

* Action to be taken:

&#x20;    \- Check if the DIVOC system is reachable from the source system, or if the IP/domain of the DIVOC system is mapped correctly.  &#x20;

&#x20;    \- If not, correct the IP/domain name or check the network.&#x20;

### 6. If you are getting response as 502: Bad Gateway:

* Action to be taken:

&#x20;     \- Check if all the DIVOC services required for the generation of certificates are up and running.

&#x20;     \- Steps to be followed to check if required services are running:

&#x20;        Login in to the DIVOC server.

&#x20;          Go to the deployment folder.

&#x20;        Run this command: kubectl get pods -n \<divoc namespace>

&#x20;     \- If any of the pods are down and do not have an active running container:

&#x20;        Restart the pod with this command: kubectl rollout restart deployment

&#x20;        \<name of the deployment which is down> -n \<divoc namespace>

&#x20;          Run this command again: kubectl get pods -n \<divoc namespace>

&#x20;        Validate if all the deployments are up again.

&#x20;        Check if you are able to generate the certificate.

&#x20;       \- If you are still not able to generate the certificate, then check the logs of deployments one by one using this command: kubectl logs -f deployment/\<deployment\_name> -n \<divoc\_namespace>

&#x20;       \- If you find any errors in the logs or if the logs are not clear to you, share the logs with the L3 team for resolution of the issue.

### 7. If the gateway service is down:

* Action to be taken:

&#x20;    \- Try restarting the gateway service: kubectl rollout restart deployment gateway -n \<divoc\_namespace>

&#x20;    \- If the service does not start, look at the deployment logs and pass on the information to the L3 team: kubectl logs -f deployment gateway -n \<divoc\_namespace>

### 8. If you are trying to generate/update a certificate, check if the vaccination API service is down:

* Action to be taken:

&#x20;     \- Try restarting the vaccination api service: kubectl rollout restart deployment vaccination-api -n \<divoc\_namespace>

&#x20;      \- If the service does not start, look at the deployment logs and pass on the information to the L3 team: kubectl logs -f deployment vaccination-api -n \<divoc\_namespace>

### 9. If the certificate signer service is down:

* Action to be taken:

&#x20;    \- Try restarting the certificate signer service: kubectl rollout restart deployment certificate-signer -n \<divoc\_namespace>

&#x20;     \- If the service does not start, look at the deployment logs and pass on the information to the L3 team: kubectl logs -f deployment certificate-signer -n \<divoc\_namespace>

### 10. If the registry services are down:

* Action to be taken:

&#x20;    \- Try restarting the registry service: kubectl rollout restart deployment registry -n \<divoc\_namespace>

&#x20;    \- Try connecting to the database directly using the following command: psql -h \<DB\_ADDRESS> -U

&#x20;        a. If you are able to access the registry, look at the deployment logs and pass on the information to the L3 team: kubectl logs -f deployment registry -n \<divoc\_namespace>

&#x20;        b. If you are unable to connect to the database, restart the database and try connecting again. If the problem persists, reach out to the L3 team.

### 11. If you are trying to fetch the certificate, check if the certificate API services are down:

* Action to be taken:

&#x20;    \- Try restarting the certificate api service: kubectl rollout restart deployment certificate-api -n \<divoc\_namespace>

&#x20;   \- If the service does not start, look at the deployment logs and pass on the information to the L3 team: kubectl logs -f deployment certificate-api -n \<divoc\_namespace>

### 12. If the SMS/notification services are down:

* Action to be taken:

&#x20;    \- Regenerate a new SMS Auth Key from the SMS provider.

&#x20;    \- Update SMS\_AUTH\_KEY property in divoc-config.yaml.

&#x20;    \- Restart notification service: kubectl rollout restart deployment notification-service -n \<divoc\_namespace>

### 13. If the services are taking a long time to return:

* Possible causes: Indexes not present in database.
* Action to be taken:

&#x20;     \- Check if the following indexes are present for the following columns in VaccinationCertificate DB table in the database:&#x20;

&#x20;       a. OSID

&#x20;       b. certificateId

&#x20;       c. Contact

&#x20;       d. Mobile

&#x20;       e. preEnrollmentCode in

&#x20;   \- If they are not present, run the following commands:

&#x20;      a. CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_preEnrollmentCode\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("preEnrollmentCode");

&#x20;      b. CREATE UNIQUE CONCURRENTLY INDEX "public\_V\_VaccinationCertificate\_certificateId\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("certificateId");

&#x20;      c. CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_contact\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("contact");

&#x20;      d. CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_mobile\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("mobile");

&#x20;      e. CREATE INDEX CONCURRENTLY "public\_V\_VaccinationCertificate\_osid\_sqlgIdx" ON "public"."V\_VaccinationCertificate" ("osid");

### 14. If signed certificates are not being created when  vaccination events occur:

* Possible causes: Redis server is down.
* Possible actions:

&#x20;     \- Check if you are able to connect to redis server using redis-cli: redis-cli -h \<IP ADDR of server>

&#x20;     \- If you are not able to connect, then restart the server.

&#x20;       a. SSH into the redis server.

&#x20;       b. List the redis-server process: sudo service redis-server status.

&#x20;       c. Fetch the process-id of redis-server.

&#x20;       d. Kill the redis-server process (sudo kill -9).

&#x20;       e. Restart redis-service process (sudo systemctl restart redis).

&#x20;       f.  Confirm that we are now able to connect to redis-server using “redis-cli” command.

## Infrastructure Issues

1. Increase the limit on the number of times a certificate could be updated:

Update the “divoc-config.yml” file with a new value (greater than the default value of 100) for “CERTIFICATE\_UPDATE\_LIMIT” property and apply it. Kubectl rollout restart deployment vaccination-api -n **\<divoc-namespace>**

2\. Pod is restarting frequently - If you run kubectl get pods -n and see that the number of pod restarts is high:

There can be multiple reasons why a pod restarts -&#x20;

* CPU limit is exceeded by pods: Modify the deployment by increasing the requests and limits on CPU.
* Memory limit is exceeded by pods: Modify the deployment by increasing the requests and limits on memory.
* Memory issue in the machine on which Kubernetes (worker node) is installed. We can increase the number of worker nodes or increase the memory of the worker nodes and then recreate pods if necessary.
* Code issue: Sometimes there can be an issue with the code or the config might be missing. In such cased, we need to fix the bug.

3\. Kubernetes cluster is not reachable from Kubeadm master node as SSL certs have expired:

If you encounter the following error:&#x20;

\#> kubectl version Client Version: version.Info{Major:"1", Minor:"9", GitVersion:"v1.9.0", GitCommit:"925c127ec6b946659ad0fd596fa959be43f0cc05", GitTreeState:"clean", BuildDate:"2017-12-15T21:07:38Z", GoVersion:"go1.9.2", Compiler:"gc", Platform:"linux/amd64"} The connection to the server 135.122.6.50:6443 was refused - did you specify the right host or port?

Recovery steps are as follows:

1. Check if certs have expired: kubeadm alpha certs check-expiration --config=/root/kubernetes/kubeadm-config.yaml
2. Renew Certs:

* cd /etc/kubernetes/pki/
* mv
* {apiserver.crt,apiserver-etcd-client.key,apiserver-kubelet-client.crt,front-proxy-ca.crt,front-proxy-client.crt,front-proxy-client.key,front-proxy-ca.key,apiserver-kubelet-client.key,apiserver.key,apiserver-etcd-client.crt} \~/
* kubeadm init phase certs all --apiserver-advertise-address \<Specify Master node LAN IP addr>
* cd /etc/kubernetes/
* mv {admin.conf,controller-manager.conf,kubelet.conf,scheduler.conf} \~/
* kubeadm init phase kubeconfig al

3\. Reboot server: reboot

4\. After reboot ensure docker and all Kube\* daemons are up docker ps | grep kube-apiserver

5\. Mandatorily replace the config file with newly created one, to resolve “kubectl localhost:8080 connection refused” issue -

* mkdir -p $HOME/.kube
* sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
* sudo chown $(id -u):$(id -g) $HOME/.kube/config

6\. Issue Kubectl commands

## Resources:

#### Pre-reads:&#x20;

1. [Skills needed to set up DIVOC.](/v2-2/platform/installation/skills-needed-to-set-up-divoc#what-does-this-section-cover)
2. [Implementation checklist.](/v2-2/platform/installation/implementation-checklist)
3. [DIVOC's certification and verification component.](/v2-2/platform/configuration/configuring-the-certification-and-verification-component)

#### Links to the development process and the environments (such as Github, Testing, etc):

1. Source Code - <https://github.com/egovernments/DIVOC>
2. [Setting up DIVOC development environment](/v2-2/platform/tech-docs/setting-up-divoc-development-environment).
3. [Setting up the production environment.](/v2-2/platform/installation#what-will-it-cover)

#### Modifying vaccine certificate and template; Branding changes such as UI changes; Adding a new role; Changing the content to the verification page:

1. [ETCD configuration.](/v2-2/platform/configuration/configuration-management-via-etcd/pdf-template-change-for-vaccine-certificates/pdf-template-change-for-vaccine-certificates-via-etcd-cli)
2. [Configure the verification component.](/v2-2/platform/configuration/configuring-the-certification-and-verification-component/how-to-set-up-the-verification-portal-for-implementation#overview)

#### Wiki documentation & discussion forum:

1. Documentation: [**https://divoc.digit.org/**](https://divoc.digit.org/)
2. Report issues: [**https://github.com/egovernments/DIVOC/issues**](https://github.com/egovernments/DIVOC/issues)
3. Discussion forum: [**https://github.com/egovernments/DIVOC/discussions**](https://github.com/egovernments/DIVOC/discussions)&#x20;
4. Join us on slack: [**https://app.slack.com/client/T109J61DY/C03EC8C65SN**](https://app.slack.com/client/T109J61DY/C03EC8C65SN)&#x20;

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Open Events

Watch out for this space for updates in the future.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Past Events

## **Webinar on DIVOC 3.0**

**When:** Join us on Tuesday, January 17, 2023, to get an insight into the new features of DIVOC 3.0.

**Time:** 2:00 PM - 3.00 PM IST

Click [**here**](https://us06web.zoom.us/webinar/register/WN__4HmKK4hRZCHHrho5j8PBQ) to register for the webinar.&#x20;

### **What will be covered**

The release provides the platform with the ability to generate different types of verifiable credentials. New features also include multi-tenancy capabilities, where multiple tenants can issue VCs with their own schemas and templates; the capability to update/modify certificate content; and the ability to revoke/suspend certificates.

### **Highlights**

* Benefits and features of DIVOC 3.0:

&#x20;      \- Multi-tenancy capabilities \[VC as a service].

&#x20;      \- Multi-schema capabilities by multiple tenants.

&#x20;      \- Universal verifier for all schema.

&#x20;      \- Generate/update/revoke/suspend services for certificates

* Explore how DIVOC 3.0 can fasttrack a nation’s digital health strategy.

##

## ADB-eGov Live Webinar on Digital Health Credentials

**When:** Join us on **Wednesday, March 30, 2022**, to understand the use of digital health credentials for COVID-19 vaccination and testing campaigns, and beyond.&#x20;

**Time:** 2 pm Manila time / 11.30 am IST.

**Register** **at:**

[**https://adb-org.zoom.us/meeting/register/ tJIod-6uqT0uE9SuFBowmJ2FVHVlITyokt34**](https://adb-org.zoom.us/meeting/register/%20tJIod-6uqT0uE9SuFBowmJ2FVHVlITyokt34)

### Schedule

<table><thead><tr><th width="451">Speaker</th><th>Duration</th></tr></thead><tbody><tr><td>Welcome address: Thiam Hee Ng, Director, SARC</td><td>2 mins</td></tr><tr><td>Opening Remarks: Sungsup Ra, Chief Sector Officer, SDCC</td><td>3 mins</td></tr><tr><td><p>Presentation: </p><p>Viraj Tyagi, CEO, eGov Foundation </p><p>Pradipta Kundu, Health Mission Lead, eGov Foundation</p></td><td>30 mins</td></tr><tr><td><p>Comments and Discussion:</p><p>Patrick Osewe, Chief of Health Sector Group, SDSC </p><p>Thiam Hee Ng, Director, SARC</p></td><td>23 mins</td></tr><tr><td>Closing Remarks: Gi Soon Song, OIC, SAHS</td><td>2 mins</td></tr></tbody></table>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC in the Media

Videos, and Articles

## Videos <a href="#divoc-videos" id="divoc-videos"></a>

{% embed url="<https://www.youtube.com/watch?v=vl_EP9fpzh0&feature=youtu.be>" %}

{% embed url="<https://www.youtube.com/watch?v=vJRgkhsVvmA>" %}

{% embed url="<https://www.youtube.com/watch?v=J86YuKJyaEU>" %}

## Articles <a href="#articles" id="articles"></a>

1. [The challenge is we don’t have adult vaccination system, must build it from scratch for Covid-19](https://indianexpress.com/article/india/nandan-nilekani-coronavirus-vaccine-tracker-health-sector-economy-6779867/)
2. [Digital route to deliver Covid vaccine in India](https://economictimes.indiatimes.com/markets/expert-view/nandan-nilekani-on-digital-route-to-deliver-covid-vaccine-in-india/articleshow/79208481.cms?from=mdr)
3. [Aadhaar model can help in vaccinating population quickly](https://government.economictimes.indiatimes.com/news/digital-india/aadhaar-model-can-help-in-vaccinating-population-quickly-infosys-chairman-nandan-nilekani/77757327)
4. [Certificate of COVID Vaccination: Can We Do Better than the Yellow Card?](https://www.cgdev.org/blog/certificate-covid-vaccination-can-we-do-better-yellow-card)
5. [A COVID Vaccine Certificate: Building on Lessons from Digital ID for the Digital Yellow Card](https://www.cgdev.org/publication/covid-vaccine-certificate-building-lessons-digital-id-digital-yellow-card)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Introduction to DIVOC

Digital Infrastructure for Verifiable Open Credentialing

![](/files/4PUQim7QmhfOpr5teJFW)

## What is DIVOC?

The <mark style="color:orange;">**Digital Infrastructure**</mark>**&#x20;for Verifiable Open Credentialing** or <mark style="color:orange;">**DI**</mark>**VOC** is an **open-source platform** that enables countries to digitally orchestrate large-scale health campaigns such as vaccination and certification programs.

Learn more about the platform on the [**DIVOC**](https://divoc.dev/) website or [**Contact us**](https://divoc.dev/#get-in-touch) for more details.

## **Facilitates last-mile delivery of health programs at scale**

* Built in India for the world as a <mark style="color:orange;">**digital public good**</mark>, DIVOC is a flexible and extendable software that can be used across multiple health programs.
* Its scalable and data-driven architecture allows it to deal with diverse country-specific scenarios. In a vaccination programme, for example, it gives countries the ability to manage and control vaccines, facilities, and vaccinators systematically across geographies, as well as generate digitally variable certificates that are compliant with international standards.

## **Our Key Modules**

* The platform is modular, enabling countries to use the components together or as an individual standalone solution, according to their need, for end-to-end vaccination and certification.
* DIVOC has two core modules:

&#x20;            1\. Issue and Verify Certificates

&#x20;            2\. Analytics

![](/files/GrlaujcnbAq5shfi6k5N)

* Reference Implementation: There are other components of DIVOC that countries can customise according to their requirement -&#x20;

&#x20;             1\. Program setup via the orchestration module

&#x20;             2\. Facility app

![](/files/j4x4gQT6WBP9DQ5vkrVb)

&#x20;             3\. Citizen portal

&#x20;             4\. Feedback        &#x20;

![](/files/cvkfvOL8zbHON7FtLalB)

* <mark style="color:orange;">**DIVOC Demo**</mark>**:** Click [<mark style="color:orange;">**here**</mark>](/divoc-wiki-3.0/divoc-demo) to play around with the modules.

## **DIVOC’s journey so far: Country stories**

Acknowledge as a Digital Public Good by the [**Digital Public Good Alliance (DGPA)**](https://digitalpublicgoods.net/), the platform has enabled India and four other countries to issue over 2 billion COVID-19 vaccination certificates to its citizens.

<table><thead><tr><th align="center">Launched at Scale: India                                            </th><th align="center">Now live in…</th><th data-hidden align="center">Coming soon…</th></tr></thead><tbody><tr><td align="center"><mark style="color:orange;"><strong>Over 2 billion</strong></mark> digitally signed vaccinated certificates via Cowin. </td><td align="center"><p>DIVOC’s certificate component went </p><p>live with digital vaccination certificates </p><p>in <mark style="color:orange;"><strong>Sri Lanka</strong></mark> in July 2021, in the <mark style="color:orange;"><strong>Philippines</strong></mark> in September 2021, and in <mark style="color:orange;"><strong>Jamaica</strong></mark> and <mark style="color:orange;"><strong>Indonesia</strong></mark> in December 2021. </p></td><td align="center"><mark style="color:orange;"><strong>Indonesia</strong></mark> and <mark style="color:orange;"><strong>Jamaica</strong></mark> are currently planned for Covid-19 vaccination certificate roll-outs.</td></tr><tr><td align="center"><p>DIVOC has enabled the Indian Council of Medical Research (ICMR) to </p><p>issue digitally-signed </p><p><mark style="color:orange;"><strong>COVID-19 test reports</strong></mark>.</p></td><td align="center">Plans are underway to issue COVID-19 test result certificates in both <mark style="color:orange;"><strong>Sri Lanka</strong></mark> and <mark style="color:orange;"><strong>Philippines</strong></mark>.</td><td align="center"></td></tr></tbody></table>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# What DIVOC is and what it's not

This document will tell you what DIVOC can and cannot do. For example, do not expect DIVOC to correct data fraud or mistakes at the source, or store medical history with high data-storage requirements.

| What DIVOC can do                                                                                | What DIVOC is not meant for                                                                                                              |
| ------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Holds information on individual events or claims.                                                | It is not meant to store historical data (for example, a person’s medical history). The size limitation is 1 KB.                         |
| It is tamper-proof, and hence, can ease access to welfare funds linked to identity and a claim.  | Cannot expect it to rectify data errors at the source.                                                                                   |
| The output can be hybrid (PDF plus QR code).                                                     | Not a good idea if the expected verification to issuance ratio is low.                                                                   |
| Modular architecture can support more health credentialing other than COVID-19.                  | Not suitable if there is no purpose on the demand side.                                                                                  |
| DIVOC supports multi-lingual use and multi-distribution methods (such as paper, and smartphone). | Not the best option if the issuer and verifier are in the same network (in such cases, we recommend using simpler, and cheaper options). |

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC Docs Index

Most useful links:

* [Release notes](/divoc-wiki-3.0/platform/release-notes)&#x20;
* [API documentation](/divoc-wiki-3.0/platform/tech-docs/api-documentation)
* [Setting up DIVOC development environment](/divoc-wiki-3.0/platform/tech-docs/setting-up-divoc-development-environment)
* [Setting up DIVOC in k8 cluster](/divoc-wiki-3.0/platform/installation/setting-up-divoc-in-k8-cluster)
* [DIVOC's Certification and Verification Component](/divoc-wiki-3.0/platform/configuration/configuring-the-certification-and-verification-component)
* [Configuration management via ETCD](/divoc-wiki-3.0/platform/configuration/configuration-management-via-etcd)
* [Source code](https://github.com/egovernments/DIVOC)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Platform

This section will include the following:

* [Release notes](/divoc-wiki-3.0/platform/release-notes)
* [Specification](/divoc-wiki-3.0/platform/tech-docs)
* [Features](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0)
* [Architecture](/divoc-wiki-3.0/platform/divoc-architecture)
* [Installation](/divoc-wiki-3.0/platform/installation)
* [Configuration](/divoc-wiki-3.0/platform/configuration)
* [Performance report](/divoc-wiki-3.0/platform/performance-report)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Release Notes

This page lists all DIVOC releases till date. It covers new features, enhancements, and fixes

### Release notes for supported versions are given below:&#x20;

* [Release notes 1.24.0](https://github.com/egovernments/DIVOC/releases/tag/1.24.0-generic) (on-demand EU-DCC and FHIR-DDCC export)
* [Release notes 1.23.3](https://github.com/egovernments/DIVOC/releases/tag/1.23.3-generic) (minor enhancements and UI fixes)
* [Release notes 1.23.2](https://github.com/egovernments/DIVOC/releases/tag/1.23.2-generic) (bug fixes and enhancements)&#x20;
* [Release notes 1.23.1](https://github.com/egovernments/DIVOC/releases/tag/1.23.1-generic) (UI enhancements and bug fixes)
* [Release notes 1.23.0](https://github.com/egovernments/DIVOC/releases/tag/1.23.0-generic) (secondary dosage flows and design enhancements)
* [Release notes 1.22.1](https://github.com/egovernments/DIVOC/releases/tag/1.22.1-generic) (minor enhancements and UI fixes)
* [Release notes 1.22.0](https://github.com/egovernments/DIVOC/releases/tag/1.22.0-generic) (design enhancements and bug fixes)
* [Release notes 1.21.0](https://github.com/egovernments/DIVOC/releases/tag/1.21.0-generic) (facility application enhancements)
* [Release notes 1.20.2](https://github.com/egovernments/DIVOC/releases/tag/1.20.2-generic) (minor enhancements and bug fixes)
* [Release notes 1.20.1 ](https://github.com/egovernments/DIVOC/releases/tag/1.20.1-generic)(minor enhancement on appointment)
* [Release notes 1.20.0](https://github.com/egovernments/DIVOC/releases/tag/1.20.0-generic) (registration and appointment)
* [Release notes 2.0.0](https://github.com/egovernments/DIVOC/releases/tag/2.0.0-generic) (generic) and [2.0 release features](/divoc-wiki-3.0/platform/release-notes/divoc-2.0-release-features)
* [Release notes/features 3.0](/divoc-wiki-3.0/platform/release-notes/divoc-3.0-release-features)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC 2.0 Release Features

## Version release date&#x20;

* March 25, 2022.

## **Release summary**

If your country is implementing DIVOC 2.0, it is important to know the additions/changes that we have made as part of this release:

* **Configuration management via** [**etcd**](https://etcd.io/)**:** You can make configuration changes to DIVOC’s certificate module via etcd without needing a new deployment. Click [**here**](/divoc-wiki-3.0/platform/configuration/configuration-management-via-etcd) to know more.
* **Support for EU compliant digital certificates and Smart Health Cards:** DIVOC’s **EU-DCC** and **SHC** adapter services facilitate easy travel for residents from DIVOC’s adopter countries. Know more about DIVOC’s [**EU-DCC**](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/divocs-eu-dcc-adapter-service) and [**SHC**](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/divocs-shc-adapter-service) adapter services.
* **Print certificates at the facility:** We have added the capability to print vaccination certificates when a beneficiary walks into a facility. Click [**here**](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/printing-certificates-at-a-facility) to know more.
* **New API for revocation services:** A new Revoke API has been introduced that can be used to revoke an issued certificate for manual revocation use cases. Click [**here**](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/revoking-a-divoc-certificate) to know more.
* **Deployment activities automated reducing installation time:**&#x20;

&#x20;        \- Automating our infrastructure setup has reduced our deployment time from about 3 days  to 1 day.&#x20;

&#x20;        \- DIVOC’s [**installation process**](/divoc-wiki-3.0/platform/installation/setting-up-divoc-in-k8-cluster/how-to-install-divoc) has been streamlined with the introduction of the new scripts. The details of the scripts are given below:

1. Install the prerequisites and set up the various hardware clusters.
2. Push the docker images to the appropriate registry.
3. Deploy the code from the registry into the Kubernetes cluster.

* **Enhanced performance of PDF certificate generation:** We have fine-tuned our PDF generating algorithms, which has lowered the consumption of system resources.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC 3.0 Release Features

## Version release date

* September 21, 2022

## Release summary

With this release, the DIVOC platform can now generate different types of verifiable credentials. It is no longer restricted to vaccination-specific verifiable credentials.

## Terminology

A list of the common terms used in this document:

* [**Verifiable credentials (VCs)**](https://www.w3.org/TR/vc-data-model/#:~:text=A%20verifiable%20credential%20is%20a,certificates%2C%20and%20digital%20educational%20certificates.) represent information found in physical credentials, such as birth registration and driving license, as well as objects that have no physical equivalent, such as ownership of a bank account. VCs are typically QR codes whose information can only be unlocked by verifiers (for example, a medical council registration certificate with a QR code). When a digital document (for example, a lab test report) has a normal QR code, anyone can read all the information inside the QR by using widely available software on the internet. Such software can read the QR code and then replace it with another QR code with different information. Whereas the information in a verifiable QR code cannot be replaced as the original data or information cannot be changed without a “private key.”
* Issuer: Refers to an issuing authority who can issue claims about a particular entity or individual that can be validated. An issuer gathers the information that needs to be contained in the VC from the entities and sends it across to DIVOC through tenant software. Example: Medical Councils.
* Tenant: Refers to any source system of issuers linked to the DIVOC platform to issue VCs. Examples: Council Software, University software, etc.
* Source systems: The tenant software that interacts with the DIVOC platform to issue VCs.
* Schema: A schema is essentially a template that tells the issuer the content, type, and description required for an attribute that needs to be part of the VC. For example, a schema can be as follows with multiple rows for other parameters:

<table><thead><tr><th>Field name</th><th width="160">Type</th><th width="197">Description</th><th width="147">Mandatory</th></tr></thead><tbody><tr><td>Registration no.</td><td>Alphanumeric</td><td>This is the registration number issued to a health professional</td><td>Yes</td></tr></tbody></table>

* Beneficiary: Refers to the holder of the VC. Examples: Doctors, students, etc.
* S-RC - Sunbird R C: This is a [**set of configurable, extendable, modular building blocks**](https://sunbird.org/about-us) for learning and human development designed for scale and open-sourced under an MIT license.
* UI: User interface

## New features

<table><thead><tr><th width="275">Feature</th><th>Description</th></tr></thead><tbody><tr><td>APIs for tenant and schemas</td><td>Multiple tenants can now create and manage schemas through the platform.</td></tr><tr><td>APIs for tenant and schemas</td><td>A single tenant can create multiple schemas required for issuing VCs through the DIVOC platform.</td></tr><tr><td>Ability to update the schema</td><td>This will give you the capability to update schemas that are already created.</td></tr><tr><td>Service to generate and send only QR code (SVG) with provided dimensions</td><td>Issuers can fetch QR codes through the DIVOC platform and this can be shared with the beneficiary directly or can be embedded on the certificate template.</td></tr><tr><td>Services to update a certificate</td><td>We have added the capability to <a href="/pages/2CjsD9BtviK7A8vWKlMN"><strong>update/modify</strong></a> content on already generated certificates.</td></tr><tr><td>APIs for revocation and suspension</td><td>An issued certificate may need to be <a href="/pages/wepff9OSNaDLB7jr5835"><strong>revoked/suspended</strong></a> due to validity expiry, issuance of a new certificate, or violation of terms and conditions. With this release, issuers can revoke and suspend certificates that are already issued.</td></tr><tr><td>Notification services</td><td>The beneficiaries (holders of the VC) will receive an SMS when the certificates are generated.</td></tr><tr><td>Enabling multi-lingual certificate</td><td>We have added the capability to create and issue certificates in multiple languages.</td></tr></tbody></table>

## **Enhancements from previous platform release**

<table><thead><tr><th width="284">Feature</th><th>Description</th></tr></thead><tbody><tr><td>Add support in DIVOC to use S-RC in async mode</td><td>The DIVOC platform has been updated for the services to work in async mode to avoid any data loss during the exchange of high volumes of data.</td></tr><tr><td>Modifications in the response codes for error messages*</td><td>Error codes have been defined and included in the response along with their corresponding error messages.</td></tr><tr><td>Modify Keycloak services for tenant management services</td><td>Configured Keycloak services to support the creation of multiple tenants.</td></tr></tbody></table>

## **Upcoming features/enhancement**

<table><thead><tr><th width="289">Feature/enhancement</th><th>Description</th></tr></thead><tbody><tr><td>Verification portal</td><td>This will enable verifiers to check the authenticity and validity of VCs issued from different issuers by scanning the QR codes through an interface.</td></tr><tr><td>UI for tenant onboarding portal</td><td>An interface through which source system administrators can log in to the DIVOC platform and connect it with the source system.</td></tr><tr><td>UI for tenant multiple schema creation</td><td>An interface through which source system admins can create and manage different schemas required for the issuance of VCs.</td></tr></tbody></table>

### Annexure&#x20;

\*Error codes and their corresponding responses

<table><thead><tr><th width="144">Error code</th><th>Message</th></tr></thead><tbody><tr><td>400</td><td>Invalid input provided.</td></tr><tr><td>401</td><td>Unauthorised (in case the token has expired or is invalid).</td></tr><tr><td>403</td><td>Forbidden (if any required headers/auth header is not available).</td></tr><tr><td>404</td><td>Not found (in case of any unavailable resources).</td></tr><tr><td>406</td><td>Specific for failed verification (during scanning of the QR code).</td></tr><tr><td>500</td><td>Any other internal server error (usually in case the error is not from the list above).</td></tr><tr><td>502</td><td>Thrown by the gateway when a service is not reachable.</td></tr></tbody></table>

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Specification

Developer documents

## Purpose

The guide covers everything developers need to know to set up and run DIVOC on their local machines.&#x20;

## What will it cover?

* [API documentation](/divoc-wiki-3.0/platform/tech-docs/api-documentation)&#x20;
* [Setting up DIVOC development environment](/divoc-wiki-3.0/platform/tech-docs/setting-up-divoc-development-environment)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# API Documentation

## This section includes the following:

1. [Admin API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#/admin-portal.yaml)
2. [Vaccination API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../india/interfaces/vaccination-api.yaml)
3. [Certificate Access API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#../../main/interfaces/certificate-api.yaml)
4. [Registration API (swagger)](https://egovernments.github.io/DIVOC/developer-docs/api/admin-api.html#/registration-api.yaml)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Setting up DIVOC development environment

## Steps

**Step 1:** Install prerequisites and dependencies

* Update package list - sudo apt-get update.
* Install docker - sudo apt install docker.io.
* Install docker-compose - sudo curl -L "<https://github.com/docker/compose/releases/download/1.29.2/docker-compose-$(uname> -s)-$(uname -m)" -o /usr/local/bin/docker-compose.
* Install git - sudo apt install git.
* For additional details on Docker, you can find the instructions[ here](https://docs.docker.com/compose/install/).
* You can find the basic Docker Compose commands below: (DIVOC repo has [docker-compose-vc-issuance.yml](https://github.com/egovernments/DIVOC/blob/main/docker-compose-vc-issuance.yml) file which lists all the services required for VC Issuance)

&#x20;     \- Starting services[ docker-compose -f docker-compose-vc-issuance.yml up](https://docs.docker.com/compose/reference/up/).

&#x20;     \- Restarting services[ docker-compose](https://docs.docker.com/compose/reference/restart/)[ -f docker-compose-vc-issuance.yml ](https://docs.docker.com/compose/reference/up/)[restart](https://docs.docker.com/compose/reference/restart/).

&#x20;     \- Checking the status of services[ docker-compose](https://docs.docker.com/compose/reference/ps/)[ -f docker-compose-vc-issuance.yml ](https://docs.docker.com/compose/reference/up/)[ps](https://docs.docker.com/compose/reference/ps/).

&#x20;     \- Monitoring service logs[ docker-compose](https://docs.docker.com/compose/reference/logs/)[ -f docker-compose-vc-issuance.yml ](https://docs.docker.com/compose/reference/up/)[logs](https://docs.docker.com/compose/reference/logs/).

**Step 2:** Install DIVOC

* Clone DIVOC repository onto your local machine - git clone[ https://github.com/egovernments/DIVOC](https://github.com/egovernments/DIVOC).
* Navigate to the DIVOC directory - cd DIVOC.
* Configure DIVOC: Configurations are provided as environment variables and a default set of configurations is provided in the ‘.env.example’ file. Make a copy of this file named ‘.env’ that docker will pick up. Edit these configurations as per your need.

'cp .env.example .env'

&#x20;**Step 3:** Start keycloak and kafka services in the detached mode.

```
docker-compose -f docker-compose-vc-issuance.yml up -d kafka keycloak
```

* Verify the state of kafka and keycloak containers. If they are up and running, Other services can be started now in detached mode.

```
docker-compose -f docker-compose-vc-issuance.yml up -d
```

* [Verify the state of containers](https://github.com/egovernments/DIVOC/blob/main/docs/developer-docs/index.md#docker-compose-ps). All containers should be up.
* Some services might fail to start because the dependent service may not be ready yet.[ Restarting the failed service](https://github.com/egovernments/DIVOC/blob/main/docs/developer-docs/index.md#docker-compose-restart) should start it successfully in this case.
* On Mac/Windows, services may crash with exit code:137, if sufficient memory is not set for docker. This can be changed in the Docker desktop preferences, resources tab, as shown[ here](https://docs.docker.com/docker-for-mac/#resources).

**Step 4:** To build docker images locally after making changes, run following commands make docker (Available within the individual micro services folder and at parent level folder as well).

```
docker-compose -f docker-compose-vc-issuance.yml up -d
```

**Step 5:** Explore DIVOC

* The following are the routes to access local apps. The remaining routes can be found in nginx/nginx.conf.

|            Address            |    Application   |
| :---------------------------: | :--------------: |
|           localhost           |   tenant-portal  |
| localhost/vc-verification-app | Verification app |

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC's Verifiable Certificate Features 2.0

## Purpose

This section describes the key features of DIVOC and how they work.

## What is DIVOC's issue and verify certificate module?

* Countries can use the DIVOC's certificate module to issue <mark style="color:orange;">**digitally verifiable certificates**</mark> to the entire population at speed and scale in a controlled manner post-vaccination.
* This module is responsible for issuing a QR code-based digital certificate for any registered health event. It can be adapted to other areas too where there is a requirement for secure and tamper-proof documents, such as educational certificates.&#x20;
* The certificates can be issued in both digital and physical forms, which includes print, pdf, and other formats.&#x20;

![Once the certificate is issued, multi-channel distribution and print schemes should work to ensure users and countries have a choice.](/files/h0PsObe1aTY1z6E3yxqu)

* The module supports multilingual vaccination certificate templates.&#x20;
* Generates WHO-DDCC (World Health Organisation- Digital Documentation of COVID-19 Certificates) compliant digital vaccination certificates with a W3C (World Wide Web Consortium) JSON schema, for every resident after successful inoculation.&#x20;
* To aid travel into other countries, the certificate module supports on-demand services for travellers to export their vaccination certificates to other formats (e.g. EU-DCC, SmartHealthCard), used in the destination countries.&#x20;
* The module supports additional services, including certificate verification, certificate update/correction, and certificate revocation.&#x20;
* The public key of the adopter country can be published using DIVOC’s verification page that can be embedded into the country's vaccination program-specific website/portal.

## What will it cover?

* [Creating a DIVOC certificate](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/creating-a-divoc-certificate)&#x20;
* [Distributing a DIVOC certificate](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/distributing-a-divoc-certificate)
* [Verifying a DIVOC certificate](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/verifying-a-divoc-certificate)
* [Updating a DIVOC certificate](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/updating-a-divoc-certificate)
* [Revoking a DIVOC certificate](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/revoking-a-divoc-certificate)&#x20;
* [DIVOC's native COVID-19 certificate specification](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/divocs-native-covid-19-certificate-specification)
* [DIVOC's EU-DCC adapter service](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/divocs-eu-dcc-adapter-service)
* [DIVOC’s SHC Adapter Service](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/divocs-shc-adapter-service)
* [Difference between a normal QR code (that you may see on a food menu) and a verifiable QR code (for example, DIVOC's QR-code based digital certificates).](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/normal-qr-code-versus-signed-verifiable-qr-code)
* [What information goes into a QR code?](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/what-information-goes-into-a-qr-code)
* [WHO master vaccine checklist](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/who-master-vaccine-checklist)
* [EU master vaccine checklist](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/eu-master-vaccine-checklist)

## Important Link

Click on the following link to learn more about 3.0 features: &#x20;

* [DIVOC's Verifiable Certificate Features 3.0](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-3.0)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Creating a DIVOC Certificate

## Purpose&#x20;

The purpose of this document is to provide information about the certificate generation service of DIVOC. It has the following sections:

* [Overview of DIVOC’s digital certificates.](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/creating-a-divoc-certificate/overview-of-divocs-digital-certificates)
* [What information is included in the DIVOC digital certificate?](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/creating-a-divoc-certificate/what-information-is-included-in-the-divoc-certificate)&#x20;
* [Certificate generation service: How does it work?](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/creating-a-divoc-certificate/divocs-certificate-generation-service-how-does-it-work)&#x20;
* [Compliance with internationally used COVID-19 certificate schemas.](/divoc-wiki-3.0/platform/divocs-verifiable-certificate-features-2.0/creating-a-divoc-certificate/compliance-with-internationally-used-covid-19-certificate-schemas)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# Overview of DIVOC’s digital certificates

Using the DIVOC certificate generation service, a country can issue a QR code-based digitally verifiable certificate, which serves as proof of the health event, such as the COVID-19 vaccination. It involves an issuer (for example, a government department), a holder (for example, the citizen of a country), and a verifier (for example, security personnel at the airport).

### Globally accepted W3C-Verifiable Credential Data Model

* All DIVOC issued digital certificates are based on the globally accepted W3C-Verifiable Credential Data Model 1.0.&#x20;
* DIVOC uses this [**data model**](https://www.w3.org/TR/vc-data-model/) for encoding the event data into the digital certificate’s QR code. DIVOC also uses a PKI mechanism to cryptographically sign all QR codes in the issued digital certificates.&#x20;
* Popular cryptographic signing algorithms (like RSA, EDDSA) are adopted in the DIVOC certificate QR signing process.

![Credit: Figure taken from W3C Verifiable Credentials Data Model v1.1](/files/U6G9qIodBIEtMesdGXI9)

### Key roles of a verifiable credential

**A. Holder:** Someone who possesses one or more verifiable credentials as a proof of an event/identified use case and is responsible for generating presentations from them. In DIVOC’s vaccination use case, it is the vaccine recipient or beneficiary.

**B. Issuer:** Reefers to a legal entity that asserts claims about the holder or subject about a verifiable event or an identified use case by issuing a verifiable credential to a holder. Issuers may include central/state governments, authorities, corporations, etc. For instance, in the COVID 19 vaccine scenario, the issuer could be the issuing country or legal authorities.&#x20;

**C. Subject:** An entity about which the verifiable claim is made by the issuer, for example, beneficiary or vaccine dose recipient.&#x20;

**D. Verifier:** An entity who is responsible for verifying an issued credential. In the COVID-19 travel scenario, verifiers are the arrival country authorities that require a verifiable COVID-19 vaccine proof for allowing access to services and border entries.&#x20;

**E. Verifiable data registry:** This refers to a role that a system may perform by mediating the creation and verification of identifiers, keys, and other relevant data, such as verifiable credential schemas, revocation registries, issuer public keys, and so on, which may be required to use verifiable credentials.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# What information is included in the DIVOC certificate?

DIVOC’s W3C-based digital certificate consists of three core components:

1. Credential metadata (schema version credential/certificate ID, etc).&#x20;
2. Claim (vaccination event details).&#x20;
3. Proof (issuer details, date of issue, time stamp, signature, etc).

![Credit: Figure taken from W3C Verifiable Credentials Data Model v1.1](/files/7NlxOrz53W7HwH3gT7hG)

### Data structure

The DIVOC digital certificate QR code includes the following data structure:

| Basic components                                       | Information sections         | Description                                                                                                                    |
| ------------------------------------------------------ | ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| <ol><li><strong>Credential metadata</strong></li></ol> | Certificate context          | Sets the context, which establishes the special terms.                                                                         |
|                                                        | Certificate identifier       | Specifies the identifier for the credential.                                                                                   |
|                                                        | Credential type              | Declares what data to expect in the credential.                                                                                |
|                                                        |                              |                                                                                                                                |
| 2. **Claim**                                           | Credential subject           | Assertion about the subjects of the credentials.                                                                               |
|                                                        | Event block                  | When the credential was issued.                                                                                                |
|                                                        | Issuer details               | The entity that issued the credential.                                                                                         |
|                                                        |                              |                                                                                                                                |
| 3. **Proof**                                           | Signature type               | Digital proof that makes the credential tamper-evident. Cryptographic signature suite that was used to generate the signature. |
|                                                        | Date of signature            | When the signature was created.                                                                                                |
|                                                        | Digital signature value      |                                                                                                                                |
|                                                        | Identifier of the public key | That can verify the signature.                                                                                                 |

### Sample certificate payload

To illustrate the data structure of DIVOC certificate outputs, a sample certificate payload is outlined below:

![](/files/M7mOnBWHfgl8SvfgrSJj)

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*


# DIVOC’s certificate generation service: How does it work?

This section covers the following:

* Certificate generation process&#x20;
* Certify APIs
* API structure

## Certificate generation process

It involves the following steps:&#x20;

* Recording of a health event against a unique beneficiary, either in the source eHealth system (or in the DIVOC vaccination module, if used by a country, for their vaccination campaign). This results in the creation of the dataset for the specific event.&#x20;
* The event records all transactions associated with it (e.g. beneficiary demographics, vaccinator/facility details, certificate metadata, and timestamp, among others).&#x20;
* Marking the completion of the "event" in the system triggers a DIVOC certificate generation API (or “Certify” API), with the event data populated as per the defined API structure.&#x20;
* DIVOC’s certificate module receives the event data.&#x20;
* A digital certificate, encompassing both a QR code and a human readable document (e.g. PDF) is then issued, which holds the event data for the beneficiary, along with a unique certificate ID.&#x20;
* The QR code is signed with the issuing authority (e.g. national/provincial health agency) private key.&#x20;
* A summary of the health event is then used to populate the “human readable” part of the digital certificate.

![](/files/98M27qgEm9RyDXTC2huG)

### Output

The generated output has two parts:&#x20;

* It has a human-readable document (e.g. the PDF) and the machine-readable QR (the signed QR).&#x20;
* The digital certificate can be presented back to the source system in either of the ways (i.e. either just the signed QR as an image file, or the entire PDF output with the signed QR).

### Sample

A sample DIVOC certificate output is further illustrated in the image below:

![](/files/mp7KjiMIhbhIU6LdPnny)

## Certify APIs

The DIVOC certificate generation service provides a “Certify” API for other eHealth systems, to generate digital certificates for specific events. Currently, DIVOC provides two certify APIs for a “COVID-19 vaccination certificate” and “COVID-19 test result certificate” respectively.

| API type                         | API reference link                                                                                                                                                               |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| “Certify” for vaccination events | [**https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L722**](https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L722) |
| “Certify” for test result events | [**https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L877**](https://github.com/egovernments/DIVOC/blob/main/interfaces/vaccination-api.yaml#L877) |

## API structure

The API structure for the Certify API includes the following:

1. **Recipient information:** This section contains information about the beneficiary of the specific health event (e.g. COVID-19 vaccination or test event).&#x20;
2. **Vaccination event information:** This includes details about the vaccination event such as name, batch, and vaccination date, as well as the vaccinator.&#x20;
3. **Issuer information:** It contains information about the issuing authority.&#x20;
4. **Certificate information:** It includes details such as certificate ID and expiry date, among others.&#x20;
5. **Meta:** This part is used to populate related information about a previous event in the human-readable PDF twin of the digital certificate that can be used by the verifier for cross-reference. It contains additional information, which is not part of the current QR code (the QR code only contains information about the current event), such as the number of past doses taken. For example, If a QR code is generated for the final dose certificate, the QR code will contain all information about the final dose. If a country wants to show information about the previous dose, that can be populated from meta in the certificate PDF.

[![Creative Commons License](https://i.creativecommons.org/l/by/4.0/80x15.png)](http://creativecommons.org/licenses/by/4.0/)*All content on this page by* [*eGov Foundation*](https://egov.org.in/) *is licensed under a* [*Creative Commons Attribution 4.0 International License*](http://creativecommons.org/licenses/by/4.0/)*.*




---

[Next Page](/llms-full.txt/1)

