Tools

Your eHealth certificate, without the hassle

Requesting or renewing an eHealth certificate currently goes through the government tool, whose setup defeats many a practice. Here is the same ceremony, in an application that installs like any other and talks to your eID card.

Download

v0.1.1

Windows, macOS and Linux. Nothing else to install, not even the Belgian eID middleware.

The application is free: no account to create, no email address to hand over, and nothing measured about how you use it.

What the application does

  • Request a new eHealth certificate with your eID card
  • Complete an accepted request, even one started in the official tool
  • Renew your certificate and activate the replacement ETK
  • Check the status of your certificates with eHealth, without a card
  • Revoke a certificate you no longer use

The .p12 file is written to ~/ehealth/keystore, the official tool’s folder, and in its format. A request started here can be finished there, and the other way round.

What you need

Your eID card and a card reader
The reader is driven directly, without the Belgian eID middleware. Readers with their own keypad are not supported yet: the PIN is typed into the application.
A Windows, macOS or Linux computer
There is no mobile version: the eHealth ceremony assumes a card reader. On Linux the pcscd service is installed along with the application.
A password for your keystore
You choose it when you make the request. It protects the .p12 file holding your certificate: without it the file is unusable, and nobody can recover it for you.

What stays with you

Your certificate’s private key is generated on your computer and never leaves it. Your PIN is asked for at every signature: it is never stored, never cached and never sent anywhere.

No data passes through Kiné Helper. The only network traffic goes to the eHealth platform services, the very ones the official tool uses.

Worth knowing before you install

Windows shows a warning

The application is not signed for Windows yet: SmartScreen asks you to go through “More info › Run anyway”. On macOS it is signed and notarised by Apple, so it opens without a warning.

Not affiliated with the eHealth platform

Kiné Helper is affiliated neither with the eHealth platform nor with the FPS Public Health. The application reproduces the exchanges eHealth documents publicly, so that it interoperates with the official tool and its files.

Frequently asked questions

Do I need to install Java?
No. The application is a standalone program that ships with everything it needs: there is nothing extra to install or keep up to date.
Do I need the Belgian eID middleware?
No. The application talks to your card reader directly, through your system’s smart card service.
Can I finish a request started in the official tool?
Yes. Pending requests are kept exactly as the official tool keeps them, in the same place and the same format. A request can therefore start in one and end in the other, in both directions.
Where is my certificate stored?
In ~/ehealth/keystore, the folder the official tool uses, as a .p12 file protected by the password you chose. Keep a copy somewhere safe: eHealth cannot generate it again.
Is my PIN sent anywhere?
No. It is only used to ask your card for a signature, on your computer. It is never transmitted or stored, and the application never retries a PIN on its own.
Do I have to be a Kiné Helper customer?
No. The application is free and works independently of the software. The certificate you obtain is yours and works with any program that accepts one.

One more tool from Kiné Helper, the software built by a physio, for physios. All the tools