An ECA is necessary to access the IL4 instance of Integrate.
External Certificate Authority (ECA)
To access the Integrate IL4 instance, you'll need to complete an onboarding process that includes the following:
Step 1: obtain an ECA certificate. An ECA, or External Certificate Authority certificate, is a digital credential that verifies your identity and allows you to securely access government networks. Since the Integrate App operates on secure government networks, an ECA is required to authenticate your access and ensure that all users are properly vetted and authorized.
Step 2: set up your Platform One (P1) account. Platform One is a DevSecOps platform created by the U.S. Department of Defense (DoD). It provides a secure environment for developing, deploying, and operating software applications on government networks.
Step 3: access Integrate. Once you have an ECA and have completed Steps 1-3, use the instructions in this article to access the Integrate IL4 instance.
Part 1: Apply for Your ECA
Go to the IdenTrust partner page. The "Federal Program" field will be pre-populated with "Integrate." Leave it as-is.
Select whether you live in the United States (Yes or No).
For "Please Choose a Certificate," select ECA Medium Token Assurance | Hardware Storage.
Click Continue through the next screens.
Search for and select your organization when prompted (if you do not have one, create an organization), then confirm the details.
Note: Once you create an organization, others from your company will be able to select it when they apply.
Fill out the Personal Information section.
Note: The address you enter is where IdenTrust will ship your USB token.
π CRITICAL: You will create a password during this step. Do NOT lose this password. You will need it later to download your certificates.
Enter your payment information and complete the purchase.
Download your forms from the confirmation page. You will need these for notarization.
Check your email for a verification email from IdenTrust. Use the link and your password to verify.
Part 2: Complete Your Paperwork
Page 2 of your downloaded forms (Organization Officer Verification):
The left side is pre-populated with your information.
Identify an Organization Officer (your CEO, manager, or someone above you who can verify your employment).
Have them sign, date, and fill out all fields on the right side. Must be typed or in blue/black ink.
You may list yourself as the main contact if you are the one filling out the application.
Page 4 (Identity Verification):
Choose which documents you will use for identification (e.g., passport from List A, or driver's license from List B).
Fill out the identification section.
Page 5 (if applicable): Fill out second-citizenship information. Skip if not applicable.
Get Notarized:
Bring your ID documents plus pages 2, 4, and 5 (if applicable) to a notary.
If you are in or near Seattle, WA, contact [email protected] for help. Otherwise, use a UPS store, shipping center, or mobile notary.
Verify the notary uses their official seal. Missing the seal means starting over.
Mail Your Documents:
Make copies of pages 2, 4, and 5 for your records.
Send originals to IdenTrust with tracking. Without a tracking number, IdenTrust may not confirm receipt.
After Mailing:
IdenTrust will call the Organization Officer's number (from page 2) to verify your application. If missed, they can call IdenTrust back.
Once verified, your USB token ships to the address you provided.
Wait for the USB to arrive before proceeding to Part 3.
Day 1 | Documents notarized and mailed |
~Day 4 | IdenTrust receives your application |
~Day 5 | IdenTrust ships your USB |
~Day 9 | You receive your USB token |
~Day 10 | Download your certificates (do not wait!) |
Day 30 | β οΈ Deadline to download ECA certificates |
Part 3: Download Your Certificates
β οΈ You must use a Windows computer for this part. Mac users: find a Windows machine first.
Do not insert your USB token until prompted.
Step 1: Install OpenSC
Go to the OpenSC releases page and download the latest Windows installer (.msi file).
Run the installer and choose the "Typical" option.
Restart your computer after installation.
Step 2: Log In to IdenTrust
Find the email from [email protected] with subject "Your IdenTrust-Issued DoD ECA Certificate is Ready!"
Go to www.identrust.com/install and click "No - Download and Install the Software Now."
Enter your activation code (from the email) and password (from Part 1).
π Known bug: If login fails, click "I forgot my password," then reset via the URL in the email you receive (second bullet under item 1).
Step 2.1: Install ActivClient
Download and run the installer. Click "Install the Utility Software" and follow the prompts.
Restart your computer after installation.
Step 3: Retrieve Your Certificates
After restart, go to www.identrust.com/install and log in again.
Click "I'm Ready - Please Check if my System is Ready," then "Yes - I Am Ready to Retrieve."
Click "Download" and open the downloaded file.
Drag the key to the lock as instructed on screen.
Now plug in your USB token. Wait for the ActivClient window to appear.
Create a PIN for your ECA. Write it down and store it safely.
Click Next, then write down your Unlock Code and store it safely. Click Finish.
When prompted, enter your new PIN.
Click "Import" to load the certificates onto your USB.
Enter your PIN, click "Generate Keys," enter PIN again, then click "Done."
If you see a security warning about installing the certificate, click "Yes."
π Save these securely: Your PIN and Unlock Code. You will need them to use your ECA.
Mac Users: Additional Steps
If you normally use a Mac for work, complete these extra steps after finishing Part 3 on Windows:
Return to your Mac. You no longer need the Windows machine.
Go to the OpenSC releases page and download the latest .dmg file for Mac.
Run the installer and restart your Mac after installation.
Unplug your USB before restarting.
Things to Remember
Do not lose your IdenTrust password, USB PIN, or Unlock Code
Mail documents with tracking or risk starting over
Ensure the notary seal is on your documents
Complete everything within 30 days of notarization
Windows is required to download certificates
Contact [email protected] if you need assistance, or
Go to Identrust Contact page, their team is very responsive.








