Difference between revisions of "E-file Administration"

From E-fileWiki
Jump to navigation Jump to search
Line 22: Line 22:
The '''Administration module''' opens. Tabs are available in the '''e-file administrator''' module: (Figure 3).
The '''Administration module''' opens. Tabs are available in the '''e-file administrator''' module: (Figure 3).


[[File:Users, Groups and Certificates (Figure 3).png|700px]]
[[File:Users, Groups and Certificates (Figure 3).png|900px]]


{|
{|

Revision as of 11:48, 4 December 2023

Home page Return homepage

Introduction

The instructions below will explain you how to access the e-file Administration module.

Step 1:

Connect to e-file.lu with your e-file administrator login (adminXXX) (Figure 1).

Administrator login (adminXXX) (Figure 1).PNG


Step 2:

Click the Administration module icon (Figure 2).

Administration module icon (Figure 2).png


The Administration module opens. Tabs are available in the e-file administrator module: (Figure 3).

Users, Groups and Certificates (Figure 3).png

Users tab Groups tab Certificates tab Sending service tab S3 keys tab
  • Add users to a group
  • Assign a group to users
  • Manage user profiles at group level
Sending service user's management :
Sending service user's management - V2 :

Users tab

Create a new e-file user

Step 1:

Connect to e-file.lu with your e-file administrator login (adminXXX) and click the Administration module icon (Figure 4).

Administration module icon (Figure 2).png

(Figure 4)



Step 2:

The Users List screen opens. Click the Create a user button (Figure 5).

Create a user button (Figure 5).png

(Figure 5)



Step 3:

The Create a user window pops up. Complete the form as shown in the figure below and click the Create button (Figure 6).

4CreateUser.png

(Figure 6)

Important note : You do not have to create a password for the user, an automatic mail will be sent to the new user to activate his account and create a password


The Create a user window closes and you return automatically to the Users List screen.

At the same time a confirmation window pops up on the top of the screen indicating that the user creation was successful (Figure 7).

User creation was successful (Figure 7).png

(Figure 7)


Explanations

Move the mouse over the user you just created. Five icons will appear allowing to perform the following Actions (Figure 8).

Action 1: Edit user settings

Action 2: Force password change. If you press this icon, an email is sent to the user with a web-link to reset his password.

Action 3: Unlock user. The icon is greyed out if a user never logged in to e-file (e.g. new user).

Action 4: Lock the user.

Action 5: Delete the user.

Following Actions (Figure 8).png

(Figure 8)




Sort functions in the Users List

The Login, Name, Email and Last connection columns can be sorted (A to Z or smallest number to largest).

Example:

If you want to sort the Name column from A to Z or Z to A, click directly on Name on the top of the column. The direction of the arrow shows whether the sort is ascending or descending (Figure 9).

Sort is ascending or descending (Figure 9).png

(Figure 9)

Filter functions in the Users List

Example:

If you want to display in the Users List only the users to whom the Group FATCA and the profile Manager have been assigned, you have to select the filter criteria as shown in the figure below and press the SEARCH button (Figure 10).

SEARCH button (Figure 10).png

(Figure 10)

Assign groups and profiles to users

Example:

If a user has to send FATCA reportings to the authority, the e-file administrator must assign the group Rapport FATCA and the profile Manager to the user.


Step 1:

Open the User management screen in the Users tab and click the Edit EditGroupSD.png icon of the user to whom you want assign groups and a specific profile (Figure 11).

A specific profile (Figure 11).png

(Figure 11)



Step 2:

The User details screen opens. Click the Groups button (Figure 12).

2AddGroup.png

(Figure 12)



Step 3: The User details / Groups screen opens. Click the Edit button (Figure 13).

2GroupDetails.png

(Figure 13)



Step 4:

The User details / Groups screen opens in Edit mode (Figure 14).

Click the ADD A GROUP button AddGroup.png, select the groups and profile you want to assign and click the Validate button.

4Add group.png

(Figure 14)



The User details / Groups window closes and you return automatically to the Groups List screen.

At the same time a confirmation window pops up on the top of the screen indicating that the group assignement was successfully saved (Figure 15).

AssignmentsSaved.png

(Figure 15)


Please be informed that you can find detailed information on all groups on our Wikipage Product Coverage; column e-file user account: "groupe".



User profiles

Administrator (EN)/ Administrateur (FR)

The Administrator profile allows the e-file administrator to order and activate LuxTrust certificate(s), manage user accounts, groups, user profiles, lock and un lock user account.


Guest (EN) */ Visiteur (FR) *

  • The Guest can consult the information or documents of his affected group(s).
  • He can access the follow up tools and open the documents linked to the group(s).
  • The Guest cannot submit reports or documents via e-file.

Manager (EN)/ Responsable (FR)

  • The Manager can consult the information or documents of his affected group(s).
  • He can access the follow up tools and open the documents linked to the group(s).
  • The Manager can submit reports linked to his group(s) via e-file.


Operator (EN) */ Opérateur (FR) *

  • The Operator can consult the information or documents of his affected group(s).
  • He can access the follow up tools and open the documents linked to the group(s).
  • The Operator submit reports linked to his group(s) to validation by a Validator.

Validator (EN) */ Valideur (FR) *

  • The Validator can consult the information or documents of his affected group(s).
  • He can access the follow up tools and open the documents linked to the group(s).
  • He validates or rejects reports awaiting for validation linked to his group(s).


(*) Available depending the group

Change an existing account's e-mail

Step 1:

Connect to e-file.lu with your e-file administrator login (adminXXX) and click the Administration module icon.


Administration module icon (Figure 2).png


Step 2:

The Users List screen opens. Click the Edit button on the line of the account to be changed.

AdminModuleChangeEmail.png


Step 3: Click the detail tab, then Edit button

AdminModuleChangeEmail2.png


Step 4: Change the e-mail then click Validate button

AdminModuleChangeEmail3.png

Sending Service management

Select the Users tab of the Administration module and press the Sending Service Management button. The Sending Service List opens (Figure 16)

2AdminSD.png

(Figure 16)


Explanations:

1. Status: the green check mark GreenTick.png indicates that user account / login for the Sending Service is active.

2. Login: it is the login of the Sending Service user.

3. Last connection: date of the last connection of the Sending Service to e-file.

4. Version: when you move the mouse over the Info.png icon, the name of the latest Sending Service version available pops up.

5. The number indicates the Sending Service version of your current Sending Service . If you want to update your Sending Service press the download button DownloadButton.png and download the latest Sending Service version with our Sending Service installer.

6. If you want to close a Sending Service account, press the lock icon DesactivateSD.png Deactivate.

7. Group filter function in the Sending Service List

Example:

If you want to display in the Sending Service List only the Sending Services to which the Group FATCA is assigned, you have to select FATCA in the drop down list and press the SEARCH button.

8. Click the Edit groups EditGroupSD.png icon to get more detailed information on the Sending Service user.



Assign groups and subscribe your Sending Service to alerts

Example:

If you want to submit COREP reportings through the Sending Service, you have to assign the group COREP to your Sending Service.

Please follow the steps below:

Step 1:

Select the Users tab of the Administration module and press the Sending Service Management button. The Sending Service List opens (Figure 17).

SDMmgt.png

(Figure 17)



Step 2:

Click the Edit groups icon EditGroupSD.png of the Sending Service to which you want to add the COREP group.

The Change groups of Sending Service page opens (Figure 18).

ChangeGroupSD.png

(Figure 18)


Explanations:

All Groups assigned to the Sending Service are listed here (1).

The only possible Profile value for a Sending Service is "Sending Service" (2).

If the Alerts checkbox is checked Tick.png(3), it means that the Sending Service will receive replies (= feedbacks) from the regulator.

These replies will be dropped automatically into the respective replies directory of your Sending Service folder.



Step 3:

Press the EditButton.png button (Figure 19).

EditSD2.png

(Figure 19)



Step 4:

The Details page of your Sending Service to which you want to add the COREP reporting opens in Edit mode (Figure 20).

Click the ADD A GROUP icon AddGroup.png, select the group you want to assign, click the SUBSCRIBE to Alerts button and VALIDATE your changes.

The window closes and you return automatically to the Sending Service List screen.

At the same time a confirmation window pops up on the top of the screen indicating that the group assignement was successfully saved.

EditModeSD.png

(Figure 20)

Groups tab

The Groups tab allows you to manage existing users at group level


Manage users at group level

Connect to e-file.lu with your e-file administrator login (adminXXX) and click the Administration module icon (Figure 21).


Administration module icon (Figure 2).png

(Figure 21)


Example:

If you want to know the users to which the group Group FATCA has been assigned or if you want to add a new user to the group, please follow the instructions below.


Step 1:

Press the Groups button. The Groups list page opens. All groups assigned to your company are shown here (Figure 22).

3GroupList.png

(Figure 22)



Step 2:

Click the Edit groups icon EditGroupSD.png in order to view all the users assigned to Groupe FATCA group (Figure 23).

2EditGroup.png

(Figure 23)


The Group detail page opens. Here you can find detailed information on the Group FATCA (e.g. Status date, number of inactive users, number of locked users) (Figure 24).

GroupDetailPage.png

(Figure 24)



Step 3:

Press the Users button (Figure 25)

GroupDetailUsers.png

(Figure 25)


The Group detail / Users page opens. All users assigned to the Group FATCA are listed here(Figure 26).

GroupUsrsList2.png

(Figure 26)



Step 4:

Press the Edit Users button EditUserButton.png (Figure 27)

EditUsersGroup.png

(Figure 27)


The Users page opens in Edit mode (Figure 28)

UsersEditGroup.png

(Figure 28)


The following actions can be done here:

1. ADD A USER. Select the user and his profile you want to add.

2. Change the Profile of the user

3. Delete the User

4. Once you have made your changes, press the VALDATE CHANGES button ValidateChanges.png



The Users window closes and you return automatically to the Groups List screen.

At the same time a confirmation window pops up on the top of the screen indicating that the assignment was successful (Figure 29).

AssignmentsSaved.png

(Figure 29)

Certificates tab

LUXTRUST certificate purchase order

All reporting files transmitted to the supervisory authorities must be encrypted.

The only certificate authorised for the file encryption by the reporting entity are SSL certificates from the certification authority LUXTRUST.

Please check the system requirements to run the e-file applications.


Key and Certificate Request generation

Please be informed that during the next steps two files will be generated:

1- the keystore file keystore.ks containing your new keys

2- the certificate request file Certificate Request.csr containing a copy of your new keys. This file must be uploaded on LUXTRUST's website during your purchase order .

 Important note : the Luxtrust SSL certificate purchase order and its activation have to be performed on the same computer workstation.


Step 1:

Connect to e-file.lu with your e-file administrator credentials (adminXXX) and click the Administration module icon (Figure 30).

Administration module icon (Figure 2).png

(Figure 30)




Step 2:

Click the Certificates button (Figure 31)

AdminModule 2.png

(Figure 31)




Step 3:

The Certificates Management screen opens. Click the CERTIFICATE REQUEST - ACTIVATION MENU link (Figure 32).

AdminModule 3.png

(Figure 32)


Result: A new screen opens displaying GENERATE CERTIFICATE KEYS - BEFORE LUXTRUST WEBSITE ORDER on the left side of the page


Step 4:

Configure your keystore (Figure 33).

Configure your keystore.png

(Figure 33)

a. Select the keystore import method

If you order the certificate for the very first time , select Create a new keystore file option and indicate a keystore name.

In the case you have to renew your certificate, you must select your curent keystore file by using the browse file or drag & drop feature to import it.


Important note : in both case, the new keystore will be generated in the configured download folder of your Web browser e.g.: C:\Users\xxx\Downloads


- File name: choose your keystore name, for example keystore.ks

- File type : .ks


b. Password

If you order the certificate for the very first time , you have to define a brand-new keystore password. A confirmation is required

In the case you have to renew your certificate, e.g. its validity date expired, you must use the keystore password that had been created when you ordered the certificate for the very first time.

  Important note : the keystore password has to be shared with all e-file users who have to transmit encrypted documents or decrypt feedback files received from the supervisory authorities. .
  Important note : if you loose your keystore password, you will have to generate a new key and order a new certificate. 


c. Certificate request name (.csr)

You have to define a name for the technical certificate request file required by Luxtrust, for example CertificateRequest.csr

 Important note : the certificate request will be generated in the configured download folder of your Web browser e.g.: C:\Users\xxx\Downloads.

- File name: CertificateRequest.csr

- File type : .csr


Step 5:

Verify the Company information. (Figure 34) :

Company information.png

(Figure 34)


The related fields will be pre-filled in with information we currently have in our system. Feel free to make changes if necessary.


Step 6:

Click the Generate keys button.

A window will pop up inviting you to download the Keystore file and Certificate Signing Request (Figure 35).

Keystore CSR download window.PNG

(Figure 35)

You must click on each of the Download buttons in order to activate the OK button.
Then click OK to clear the message window.


Both keystore and certificate request files will be generated in the configured download folder of your Web browser e.g.: C:\Users\xxx\Downloads
Important note : the updated keystore will be generated with a new name as follows: 
The name of the previous keystore + a timestamp displayed as yyyymm + onhold.

Example: oldname : MyKeystore.ks / new name : MyKeystore_202212_onhold.ks


Important note : we advise you to back up the keystore.ks and CertificateRequest files. 



Finalize your LUXTRUST purchase order

Before to start order in the Luxtrust website make sure that you have process the previous part (Key and Certificate Request generation).  


-Open the LUXTRUST easy SSL e-file website.

-Browse to SSL Certificate section and click the E-FILE icon Sans titre.png


-Choose the period of validity of your certificate and click the ORDER E-FILE button.

-If you do not have a LUXTRUST easy SSL e-file account you have to get registered.

-Once registered, complete the whole order form, upload your CertificateRequest.csr file, accept the TERMS AND CONDITIONS and click the PLACE ORDER button.

-Shortly afterwards, you will receive an e-mail from LUXTRUST confirming your purchase order.

-Please follow all instructions provided in the e-mail and its PDF attachment (Send signed PDF by post with all required documents to the address indicated inside, process the payment etc.)

Activation of your LUXTRUST certificate

The certificate file will be sent to the e-mail address you provided in your purchase order.

The extension of this file will be .txt, in order to prevent your firewall from blocking the attached file.


Step 1:

Important note: save the file .txt on your computer workstation and replace the .txt extension by .cer   

Double-click the .cer file. You should be able to see your certificate as shown below (Figure 36):

Certif Visu.jpg

(Figure 36)



Step 2:

 Important note : the Luxtrust SSL certificate ordering and its activation have to be performed on the same computer workstation.

Connect to e-file.lu with your e-file administrator credentials (adminXXX) and click the Administration module icon (Figure 37).

Administration module icon (Figure 2).png

(Figure 37)


Step 3:

Click the Certificates button (Figure 38).

AdminModule2.png

(Figure 38)


Step 4:

Click the CERTIFICATE ACTIVATION – AFTER RECEPTION OF LUXTRUST CERTIFICATE link (Figure 40).

Certificate activation.png

(Figure 40)


Step 5:

Configure your keystore (Figure 41).

Certificate activation steps.png

(Figure 41)

a. Select the Group you need to use (by default Principal)

b. Import the keystore that was generated at the same time as the Certificate Signing Request (from previous step )

c. Enter the keystore password

d. Import the certificate you received from Luxtrust


Step 6:

Click the ACTIVATE CERTIFICATE button.


A window will pop up and inform you that the activation has been done successfully.

Your keystore.ks is now updated. It contains your activated LUXTRUST certificate and your encryption keys.

AdminModule 15.png

Note: The display and the position of the pop up may differ regarding the Web browser you are using


Important note : the updated keystore will be generated in the configured download folder of your Web browser e.g.: C:\Users\xxx\Downloads.
Important note : the updated keystore will be generated with a new name : the name of the previous keystore + a timestamp displayed as yyyymm + completed.
Example: previous name : MyKeystore.ks / new name : MyKeystore_202212_completed.ks
Important note : if you loose your keystore and/or its password,you will have to generate a new encryption key and order a new certificate. .

Deploying the keystore

Manual file transmission

The activated keystore, containing your LUXTRUST certificate and your encryption keys must now be provided to the workstations of each e-file user.

Step 1:

Open the Transmission module

Icon1.png


Step 2:

Keystore selection After(1).PNG

Automatic file transmission

In the case you are using the Sending Service for automatic file transmission, the activated keystore.ks must be provided as well.


Registration of your LUXTRUST certificate with the CSSF

For some reportings, the LUXTRUST e-file SSL certificate used by the reporting entity must be registered with the CSSF, before sending any files, according to the registration procedure described in the CSSF 23/833, naming convention part.

The LUXTRUST e-file SSL certificate must be registered with the CSSF for the below reportings:
(list extracted from Transport et sécurisation via les canaux de transmission externes)


  • COREP/FINREP reporting
  • ESP – Special enquiries
  • SIC – SICAR reporting
  • PFS – Reporting PFS and support PFS
  • EDP – Payment institutions reporting
  • EME – Electronic money institution
  • SGO – Management companies reporting
  • OPC – Fund XML reporting (O1.2)
  • DOC – Non-structured electronic documents (circ. 19/731)
  • OTH – Other
  • OCB – Other reportings for CSSF and BCL
  • AIF – AIFM and AIF reportings
  • SUF – XBRL reportings for subfund-based structured products (IORP)
  • O4.x – Edifact report


=> e-file User Guide: CSSF Certificate registration


S3 digital key management in e-file

The CSSF has updated its submission methods to allow AIFMs to file specific regulatory reports via the CSSF’s API from 2nd November. Please note, this is not the deadline to make the change, it is the point at which the new method is available to use. FE Fundinfo are ready to support you through the transition. Your current setup in e-file will remain in place and only minor one-off changes are required from you to ensure the continuation of your existing functionality on e-file and future proof the communication method for all reporting and filing with the CSSF going forward.

See our online webinar for more explanations : November 21st webinar in English and the related presentation

Webinaire en français


The below is a step-by step guide to appoint FE Fundinfo as a delegate within the CSSF’s eDesk platform, the easiest path to allow us to maintain our services. Once the set-up is complete you can continue to use your familiar efile interface and do not need to interact with eDesk as this will all be channelled within your existing workflows in efile.

To perform the set-up in eFile you have two options:

  • You as IT expert import the S3 keys on eFile
Step by step guide for eDesk IT Epets to connect CSSF’S eDesk to FE Fundinfo’s eFile system click to expand



Steps Actions Additional information

Step 1

Your entity’s appointed IT Expert will need to log into the IT Management area of eDesk (here). This must be using the same LuxTrust Device and account that the IT Expert role was assigned to. Please note, that these steps can only be implemented from the appointed IT Expert account

Step 2

Once logged in, go to the ‘S3 ACCESS DASHBOARD’ at the top of the page, which will take you to a screen similar to the below

S3Dashboard

Step 3

Select ‘Create Access’

S3CreateAccess

Step 4

This will provide you with an option to select a ‘scope’ which will be the reporting type you have been appointed as IT Expert for and select create:

S3CreateScope

Step 5

This will create a line in the S3 access dashboard with the report type, the status (this should show ‘Granted’) and the date of this creation.
Each report type generates 3 codes on eDesk, (the Bucket code, the Access Key, and the Secret Key). To reveal these keys, click the magnifying glass with a ‘+’ icon under the actions column (located on the far right of the screen).

S3Granted

Step 6

This will reveal the information about the who the access has been granted to, when and what report it is for. It will also provide details of the unique codes specific to the entity, report type and individual.

S3Access

Step 7

Once the Keys have been generated, keeping your connection to eDesk open, in another window, open your efile environment. Log in using the efile Admin account for your entity and open the ‘Keys Management’ tab.

efileMenu

Step 8

Select ‘Add Key’ on the far right of the screen

eFileAddKey

Step 9

A pop out will appear and provide you with several drop down lists to complete. Under ‘Scope’ you should choose the report type that you are providing the Keys for. In this instance AIFMD should be selected.

eFileScope

Step 10

Returning to eDesk, copy the Bucket code, the Access key and Secret key and paste each of these into the applicable boxes on efile.

BucketCopy


  • Grant us with the IT expert role to perfomr such changes for you
Step by step guide on how to assign FE Fundinfo as a CSSF IT Expert on eDesk click to expand



Steps Actions Additional information

Step 1

Log into eDesk with the Advanced User account using your LuxTrust Device and Password. Please note that these changes can only be implemented from the Advanced User account

Step 2

Once logged in, go to the top right corner of the screen, click on your account user name, and select ‘Entity Management’

EntityManagement

Step 3

Now select ‘Access Requests’ from the tabs at the top of the screen:

AccessRequest

Step 4

As FEfundinfo will have made a request to connect from our Fundsquare account, you will see us on a list of users requests to connect with your entity. You will be able to identify our request as it will be with the LuxTrust SN: 100115278245548987357

LuxtrustSN

Step 5

Once you have identified the FE fundinfo request from our Fundsquare account, you can go to the far right of the screen and select ‘ACCEPT ACCESS’ or ‘REJECT ACCESS’. Remember to only accept requests and provide access to users you are associated with. You will need to ‘ACCEPT ACCESS’ on our request:

AcceptAccess

Step 6

Once you have clicked accept, go to the ‘Specific roles within entity’ tab:

SpecificRole

Step 7

Under the ‘Specific roles within entity’ tab, on the right of the screen, click the ‘Add’ button:

AddSpecificRole

Step 8

You will now be able to click on the ‘User’ box and select a user within the list of approved users connected with your entity. One of these will be FE fundinfo’s Fundsquare account, select this option and the user details will populate automatically:

FSQUser

Step 9

Now you can select a role for that user, in this case you will need to select IT EXPERT for FE fundinfo in the drop down selection and click save on the top right to make the change

ITExpert

Step 10

You have now completed all you need to ensure continued use of efile and secure submission of your reports to the CSSF! FE fundinfo will do the rest and can now ensure that the changing transmission methods gradually introduced by the CSSF over the next 18 months are updated as needed without any impact on you


Change of administrator in e-file

Each e-file administrator account is linked to a single email at a time.

If you have access to the account, change the email of the administrator by using the administration module and update the administrator account's owner (name, firstname). Then the new administrator has just to request a new password.

If you do not have access to the administrator account or to the email of this account (in which case you can always use the "forgotten password" button on https://www.e-file.lu) for security reason you will have to follow this specific procedure:

Your request must be sent by email and paper mail.

The paper can be replaced by a fax to speed up the process => Fax sending to 28 370 491.


The request must be submitted on letterhead of your company and signed by a legal representative with the following information:

  • Administrator's login adminXXX
  • The current email address which is linked to the administrator
  • The new email address to link to the administrator
  • A brief explanation of the reason why you need to change it
  • Send your email to cso.desk@fundsquare.net


Once Fundsquare has received and checked your request we will update your email and send you the procedure to update the password.

If you have further questions do not hesitate to contact our Client Support & Operations Desk.

e-file password policy

Password.png

(Figure 42)

The password you will have to provide must follow the rules below:

  • At least one upper and one lower case letter
  • At least one number
  • At least one special character from this list: ! # $ % & ( ) * + , . /: ; < = > ? ^ _ @ { | } [ ] ~
  • At least 8 characters and at most 20


Please note that :

The validity of your password is not limited in time.

Our system blocks the user after 3 incorrect attempts and it is the e-file administrator who has to unblock the account.

Passwords are encrypted in our database and we do not keep them. You may re-use them.


Alert notifications

Please be informed that you can receive alert notifications by email triggered by specific events.


Example : Court orders sent by the Luxembourgish judicial police (=> CSSF - Circular 13/566)

If you want to be notified by email each time the Luxembourgish judicial police sends you court orders, you have to follow the steps below.


Step 1  : Connect to e-file with your user credentials : https://www.e-file.lu/e-file/



Step 2  : Select Update my profile

Select Update my profile.png



Step 3  : Verify that your email address registered in your e-file account is valid.

Your e-file account is valid.png

IMPORTANT : if your email address is not valid, please ask your e-file administrator to replace it by a valid one.



Step 4  : Select Customize your notifications.

Customize your notifications.png



Step 5  : Select group.

Select group555.png



Step 6  : Select the Alert type.

Notification.png

IMPORTANT :

A green window will pop-up stating that the update has been saved.


Optional Step 7  : Receive only your alerts and not the group's ones.

Ticking also the group box, the sends from other users of the same reports group will be ignored.

Alerte Notification.png