Difference between revisions of "MIFID2"

From E-fileWiki
Jump to navigation Jump to search
(Blanked the page)
 
(24 intermediate revisions by the same user not shown)
Line 1: Line 1:
<div style="text-align: right; direction: ltr; margin-left: 1em;">[[Welcome_to_e-file_and_Fundsquare_FAQ|Home page ]][[File:Home.png|Return homepage|link=Welcome_to_e-file_and_Fundsquare_FAQ]]</div>


= Introduction =
Three tabs are available in the '''e-file administrator''' module: '''Users''', '''Groups''' and C'''ertificates''' (Figure 1).
[[File:3Tabs.png|800px]]
(Figure 1)
'''Users tab'''
* Create a new user
* Assign groups to an user
* Force password change
* Lock/ unlock user
* Delete user
* Manage user profiles
* Assign groups to the '''Sending Service''' user
* Subscribe the '''Sending Service''' user to '''alerts'''
'''Groups tab'''
* User management at group level
* Add user to a group
* Assign a group to users
* Manage user profiles at group level
'''Certificates tab'''
* Order a new '''Luxtrust certificate'''
* Renew your '''Luxtrust certificate'''
* Activate '''Luxtrust certificate'''
= Users tab  =
== Create a new e-file user ==
<u>'''Step 1</u>:'''
Connect to [https://e-file.lu e-file.lu] with your '''e-file administrator''' login (adminXXX) and click the '''Administration module''' icon (Figure 2).
[[File:AdminModule6.png|border|350px]]
(Figure 2)
<u>'''Step 2</u>:'''
The '''Users List''' screen opens. Click the '''Create a user''' button (Figure 3).
[[File:3UsersList.png|800px]]
(Figure 3)
<u>'''Step 3</u>:'''
The '''Create a user''' window pops up. Complete the form as shown in the figure below and click the '''Create''' button (Figure 4).
[[File:4CreateUser.png|300px]]
(Figure 4)
The '''Create a user''' window closes and you return automatically to the '''Users List''' screen. At the same time a '''confirmation''' window pops up on the top of the screen indicating that the user creation was successful (Figure 5).
[[File:UserSuccessful.png|800px]]
(Figure 5)
<u>'''Explanations'''</u>
<u>Move the mouse over the user you just created. Five icons will appear allowing to perform the following '''Actions'''</u> (Figure 6).
<u>Action 1</u>: Edit user settings
<u>Action 2</u>: Force password change. If you press this icon, an email is sent to the user with a web-link to reset his password.
<u>Action 3</u>: Unlock user. The icon is greyed out if a user never logged in to e-file (e.g. new user).
<u>Action 4</u>: Lock the user.
<u>Action 5</u>: Delete the user.
[[File:2Actions.png|1000px]]
(Figure 6)
=== Sort functions in the Users List ===
The '''Login''', '''Name''', '''Email''' and '''Last connection''' columns can be sorted (A to Z or smallest number to largest).
<u>Example</u>:
If you want to sort the ''' Name'''  column from A to Z or Z to A, click directly on ''' Name'''  on the top of the column. The direction of the arrow shows whether the sort is ascending or descending (Figure 7).
[[File:2Sort.png|1000px]]
(Figure 7)
=== Filter functions in the Users List ===
<u>Example</u>:
If you want to display in the '''Users List''' only the users to whom the '''Group FATCA''' and the profile '''Manager''' have been assigned, you have to select the filter criteria as shown in the figure below and press the '''SEARCH''' button (Figure 8).
[[File:2FilterFunc.png|1000px]]
(Figure 8)
== Assign groups and profiles to users ==
<u>Example</u>:
If a user has to send '''FATCA reportings''' to the authority, the e-file administrator must assign the <u>group</u> '''Rapport FATCA''' and the <u>profile</u> '''Manager''' to the user.
<u>'''Step 1</u>:'''
Open the '''User management''' screen in the '''Users''' tab and click the '''Edit''' [[File:EditGroupSD.png|20px]] icon of the user to whom you want assign [[ProductCoverage|'''groups''']] and a specific [[E-file_Administration#New_e-file_user_profiles_.28e-file_v2.29 |'''profile''']] (Figure 9).
[[File:3Edit.png|900px]]
(Figure 9)
<u>'''Step 2</u>:'''
The '''User details''' screen opens. Click the '''Groups''' button (Figure 10).
[[File:2AddGroup.png|500px]]
(Figure 10)
<u>'''Step 3</u>:'''
The '''User details / Groups''' screen opens. Click the '''Edit button''' (Figure 11).
[[File:2GroupDetails.png|500px]]
(Figure 11)
<u>'''Step 4</u>:'''
The '''User details / Groups''' screen opens in '''Edit''' mode (Figure 12).
Click the '''ADD A GROUP''' button [[File:AddGroup.png|100px]], select the [[ProductCoverage|'''groups''']] and '''profile''' you want to assign and click the '''Validate''' button.
[[File:4Add group.png|800px]]
(Figure 12)
The '''User details / Groups''' window closes and you return automatically to the '''Users List''' screen.
At the same time a '''confirmation''' window pops up on the top of the screen indicating that the group assignement was successfully saved (Figure 13).
[[File:AssignmentsSaved.png|800px]]
(Figure 13)
Please be informed that you can find detailed information on all groups on our Wikipage [[ProductCoverage|'''Product Coverage''']]; column <u>e-file user account: "groupe"</u>.
=== User profiles ===
====Administrator / Administrateur ====
The Administrator profile allows the e-file administrator to order and activate LuxTrust certificate(s), manage user accounts, groups, user profiles, lock and un lock user account.
==== Guest / Visitor ====
* The Guest can consult the information or documents of his affected group(s).<br>
* He can access the follow up tools and open the documents linked to the group(s).<br>
* The Guest cannot submit reports or documents via e-file.
====Manager / Responsable====
* The Manager can consult the information or documents of his affected group(s).<br>
* He can access the follow up tools and open the documents linked to the group(s).<br>
* The Manager can submit reports linked to his group(s) via e-file.
====Operator / Opérateur====
* The Operator can consult the information or documents of his affected group(s).
* He can access the follow up tools and open the documents linked to the group(s).
* The Operator submit reports linked to his group(s) to validation by a Validator.
====Validator / Valideur====
* The Validator can consult the information or documents of his affected group(s).
* He can access the follow up tools and open the documents linked to the group(s).
* He validates or rejects reports awaiting for validation linked to his group(s).
== Sending Service management ==
Select the '''Users''' tab of the '''Administration module''' and press the '''Sending Service Management''' button. The '''Sending Service List''' opens (Figure 14)
[[File:2AdminSD.png|900px]]
(Figure 14)
<u>Explanations</u>:
1. '''Status''': the green check mark [[File:GreenTick.png|30px]] indicates that the [[Sending Service|'''Sending Service''']] is active.
2. '''Login''': it is the login of the [[Sending Service|'''Sending Service''']] user.
3. '''Last connection''': date of the last connection of the [[Sending Service|'''Sending Service''']] to e-file.
4. '''Version''': when you move the mouse over the [[File:Info.png|30px]] icon, the name of the latest [[Sending Service|'''Sending Service''']] version available pops up.
5. The number indicates the '''Sending Service version''' of your current [[Sending Service|'''Sending Service''']] . If you want to '''update''' your Sending Service press the download button [[File:DownloadButton.png|80px]] and download the latest Sending Service version with our [[Sending_Service#Installation_with_Sending_Service_Installer|'''Sending Service installer''']].
6. If you want to close a [[Sending Service|'''Sending Service''']] account, press the lock icon [[File:DesactivateSD.png|20px]] '''Deactivate'''.
7. '''Group''' filter function in the '''Sending Service List'''
<u>Example</u>:
If you want to display in the '''Sending Service List''' only the Sending Services to which the '''Group FATCA''' is assigned, you have to select '''FATCA''' in the drop down list and press the '''SEARCH''' button.
8. Click the '''Edit groups''' [[File:EditGroupSD.png|20px]] icon to get more detailed information on the [[Sending Service|'''Sending Service''']] user.
=== Assign groups and subscribe your Sending Service to alerts ===
<u>Example</u>:
If you want to submit '''COREP''' reportings through the [[Sending Service|'''Sending Service''']], you have to assign the group '''COREP''' to your Sending Service.
Please follow the steps below:
<u>'''Step 1</u>:'''
Select the '''Users''' tab of the '''Administration module''' and press the '''Sending Service Management''' button. The '''Sending Service List''' opens (Figure 14).
<u>'''Step 2</u>:'''
Click the '''Edit groups''' icon [[File:EditGroupSD.png|20px]] of the [[Sending Service|'''Sending Service''']] to which you want to add the ''' COREP''' group (Figure 15).
[[File:SDMmgt.png|900px]]
(Figure 15)
The '''Change groups of Sending Service''' page opens (Figure 15).
[[File:ChangeGroupSD.png|900px]]
(Figure 15)
<u>Explanations</u>:
All '''Groups''' assigned to the [[Sending Service|'''Sending Service''']] are listed here '''(1)'''.
The only possible '''Profile''' value for a [[Sending Service|'''Sending Service''']]  is "Sending Service" '''(2)'''.
If the '''Alerts''' checkbox is checked [[File:Tick.png|30px]]'''(3)''', it means that the [[Sending Service|'''Sending Service''']] will receive '''replies''' (= feedbacks) from the regulator.
These '''replies''' will be dropped automatically into the respective [[Sending_Service#Sending_progress_and_follow_up|'''replies''']]  directory of your Sending Service folder.
<u>'''Step 3</u>:'''
Press the [[File:EditButton.png|70px]] button (Figure 16).
[[File:EditSD2.png|900px]]
(Figure 16)
<u>'''Step 4</u>:'''
The '''Details''' page of your Sending Service to which you want to add the '''COREP''' reporting opens in '''Edit mode''' (Figure 17).
Click the '''ADD A GROUP''' icon [[File:AddGroup.png|100px]], select the group you want to assign, click the '''SUBSCRIBE''' to Alerts button and '''VALIDATE''' your changes (Figure 17).
The window closes and you return automatically to the '''Sending Service List''' screen.
At the same time a '''confirmation''' window pops up on the top of the screen indicating that the group assignement was successfully saved.
[[File:EditModeSD.png|900px]]
(Figure 17)
= Groups tab  =
[[File:EditGroups.png|900px]]
= Certificates tab  =
== LUXTRUST certificate purchase order==
All reporting files transmitted to the supervisory authorities must be encrypted.
The only certificate authorised for the file encryption by the reporting entity are SSL certificates from the certification authority [https://www.easyssl.lu/?product=e-file LUXTRUST].
Please check the [[Transmission_Module#System_requirements|system requirements]] to run the e-file applications.
=== Key and Certificate Request generation ===
Please be informed that during the next steps <span style="background:yellow"> <u>two files</u>  </span> will be generated:
<span style="background:yellow"> 1- </span> the keystore file '''keystore.ks''' containing your new keys
<span style="background:yellow"> 2- </span> the certificate request file '''Certificate Request.csr''' containing a copy of your new keys. <u>This file must be uploaded on LUXTRUST's website during your purchase order</u> . [[Transmission Module#Finalize your LUXTRUST purchase order|=>Chapter 3.2 Finalize your purchase order of LUXTRUST e-file SSL certificate]]
  <span style="color: #C00000">'''Important note : the Luxtrust SSL certificate purchase order and its activation have to be performed on the same computer workstation.</span>'''
<u>'''Step 1</u>:'''
Connect to [https://e-file.lu e-file.lu] with your [[E-file Administration|'''e-file administrator''']] credentials (adminXXX) and click the '''Administration module''' icon (Figure 16).
[[File:AdminModule6.png|border|350px]]
(Figure 16)
<u>'''Step 2</u>:'''
Click the '''Certificates ''' button (Figure 17)
[[File:AdminModule2.png|border|500px]]
(Figure 17)
<u>'''Step 3</u>:'''
The '''Certificates Management''' screen opens. Click the '''Generate a csr''' button (Figure 18).
[[File:AdminModule3.png|border|1200px]]
(Figure 18)
<u>'''Step 4</u>:'''
The '''Certificates Management Module''' opens. Click the '''Certificate''' tab and click the '''Generate a CSR''' button (Figure 19).
[[File:AdminModule 12.png|border|800px]]
(Figure 19)
<u>'''Step 5</u>:'''
The form '''Generate keys and certificate request''' opens (Figure 20) :
[[File:AdminModule8.png|border|700px]]
(Figure 20)
<u>'''Step 6</u>:'''
Complete the form
a. <u>Generation / Update of the keystore file</u>
Click the '''Browse''' button. A '''Save As''' dialog box opens. Complete the required information.
-Select directory:
If you order the certificate for the <span style="background:yellow"> <u>'''very first time'''</u>  </span>, select the folder where the keystore file will be stored.
In the case you have to <span style="background:yellow"> <u>'''renew'''</u>  </span> your certificate, you <u>must</u> select your '''current''' and '''valid''' keystore.ks. Normally, the system remembers the path where it has been stored.
<span style="color: #C00000">'''Important note : please ensure that you have write access to this folder. We suggest to use a personal folder e.g.: C:\Users\xxx\efile\workdir.'''</span>
- File name:  choose your keystore name, for example '''keystore.ks'''
- File type : .ks
Click the Save button.
b. <u>Password </u>
If you order the certificate for the <span style="background:yellow"> <u>'''very first time'''</u> </span>, you have to define a brand-new '''keystore password'''.
In the case you have to <span style="background:yellow"> <u>'''renew'''</u> </span> your certificate, e.g. its validity date expired, you <u>must</u> use the '''keystore password''' that had been created when you ordered the certificate for the '''very first time'''.
  <span style="color: #C00000">''' Important note : the keystore password has to be shared with all e-file users who have to transmit encrypted documents or decrypt feedback files received from the supervisory authorities. </span>.
  <span style="color: #C00000">''' Important note : if you loose your keystore password, you will have to generate a new key and order a new certificate. </span>
c. <u>Confirm the password</u>
Re-enter your password
d. <u>Request for the generation of the certificate (.csr)</u>
Click the '''Browse button'''. A '''Save As''' dialog box opens. Complete the required information.
- Current directory: select the folder where the Certificate Request file will be stored.
  <span style="color: #C00000">'''Important note : please ensure that you have write access to this folder. We suggest to use a personal folder e.g.: C:\Users\xxx\efile\workdir.'''</span>
- File name:  '''CertificateRequest.csr'''
- File type : .csr
e. <u>Name</u>, <u>Department</u>, <u>Entity</u>, <u>City</u>, <u>State (USA only) </u>, <u>Country (ISO code) </u> should be completed as indicated in the print screen above.
f. <u>Generate</u>
Click the '''Generate button'''.
A window will pop up and confirm that two files have been generated: '''keystore.ks''' and '''CertificateRequest.csr''' (Figure 21).
[[File:AdminModule10.png|border|600px]]
(Figure 21)
<span style="color: #C00000">'''Important note : if you renew your certificate, please ensure that the modification date of your current kestore.ks has been updated. If it is not the case it is highly probable that Java has no write access to the folder where the keystore.ks is located ''' </span>
<span style="color: #C00000">'''Important note : we advise you to back up the keystore.ks and CertificateRequest files.''' </span>
===  Finalize your LUXTRUST purchase order ===
-Open the [https://www.easyssl.lu/?product=e-file LUXTRUST easy SSL e-file website].
-Browse to SSL Certificate section and click the E-FILE icon (Figure 22)
[[File:Sans titre.png|100px]]
(Figure 22)
-Choose the period of validity of your certificate and click the ORDER E-FILE button.
-If you do not have a LUXTRUST easy SSL e-file account you have to get registered.
-Once registered, complete the whole order form, upload your '''CertificateRequest<span style="background:yellow">.crs </span>''' file, accept the TERMS AND CONDITIONS and click the PLACE ORDER button.
-Shortly afterwards, you will receive an e-mail from LUXTRUST confirming your purchase order.
-Please follow all instructions provided in the e-mail and its PDF attachment (Send signed PDF by post with all required documents to the address indicated inside, process the payment etc.)
==  Activation of your LUXTRUST certificate ==
The certificate file will be sent to the e-mail address you provided in your purchase order.
The extension of this file will be .txt, in order to prevent your firewall from blocking the attached file.
<u>'''Step 1</u>:'''
<span style="color: #C00000">'''Important note: save the file .txt on your computer workstation and <u>replace</u> the .txt extension by <span style="background:yellow">.cer </span>  </span>
Double-click the <span style="background:yellow"> .cer </span> file. You should be able to see your certificate as shown below (Figure 23):
[[File:Certif_Visu.jpg | 300px]]
(Figure 23)
<u>'''Step 2</u>:'''
  <span style="color: #C00000">'''Important note : the Luxtrust SSL certificate ordering and its activation have to be performed on the same computer workstation.</span>'''
Connect to [https://e-file.lu e-file.lu] with your [[E-file Administration|'''e-file administrator''']] credentials (adminXXX) and click the '''Administration module''' icon (Figure 24).
[[File:AdminModule6.png|border|350px]]
(Figure 24)
<u>'''Step 3</u>:'''
Click the '''Certificates ''' button (Figure 25).
[[File:AdminModule2.png|border|500px]]
(Figure 25)
<u>'''Step 4</u>:'''
The '''Certificates Management''' screen opens. Click the '''Activate a certificate''' link (Figure 26).
[[File:AdminModule13.png | 1200px]]
(Figure 26)
<u>'''Step 5</u>:'''
The '''Certificate Management Module''' opens. Press the '''Activate a certificate''' button (Figure 27).
[[File:AdminModule11.png | 600px]]
(Figure 27)
<u>'''Step 6</u>:'''
The '''Certificate Management Module''' window pops up. Select the '''Certificate''' tab. Complete the '''Activate your certificate form''' as described in picture below (Figure 28).
(Figure 28)
<u>Certificate upload</u>
Select your certificate file ('''.cer''')
<u>Password</u>
Enter your keystore password
<u>Activate</u>
Click the Activate button (Figure 29).
[[File:AdminModule14.png | 600px]]
(Figure 29)
A window will pop up and inform you that the activation has been done successfully.
Your keystore.ks is now activated. It contains your LUXTRUST certificate and your encryption keys.
<span style="color: #C00000">'''Important note : we advise you to back up the activated keystore.ks and its password''' </span>
<span style="color: #C00000">'''Important note : if you loose your keystore and/or its password,you will have to generate a new encryption key and order a new certificate. </span>.
==  Deploying the keystore ==
The activated keystore, containing your LUXTRUST certificate and your encryption keys must now be provided to the workstations of each e-file user.
[[Transmission Module#Installing a new e-file workstation|=> Installing a new e-file workstation e-file v1 and e-file v2]]
'''Sending Service'''
In the case you are using the Sending Service for your automatic reporting transmission, the activated keystore.ks must be provided as well.
[[Sending_Service|Wiki-Sending Service]]
==  Registration of your LUXTRUST certificate with the CSSF ==
For some reportings, the LUXTRUST e-file SSL certificate used by the reporting entity must be registered with the CSSF, before sending any files, according to the registration procedure described in the CSSF 08/334.
The LUXTRUST e-file SSL certificate must be registered with the CSSF for the below reportings:
- FINREP (CSSF circular 08/344)
- COFREP (CSSF circular 08/344)
- ESP (Special enquiries; CIRCULAR CSSF 08/344)
- PFS reporting (Other professionals of the financial sector; CIRCULAR CSSF 08/369)
- SICAR (Sociétés d´investissement en capital à risque)
- Bank Reporting (CIRCULAR CSSF 10/457; CIRCULAR CSSF 15/624)
- Management companies (CIRCULAR CSSF 10/467)
- Payment institutions (CIRCULAR CSSF 11/511)
- Electronic money institutions (CIRCULAR CSSF 11/522)
- OTHER reporting
- AIFMD reporting (CIRCULAR CSSF 14/581)
[[Media:ManuUtil EFile CSSF Certificate registration EN.pdf |=> e-file User Guide: CSSF Certificate registration - General]]
[[Media:ManuUtil EFile CSSF Certificate registration AIF EN.pdf |=> e-file User Guide: CSSF Certificate registration - AIFMD]]
=Forgot your e-file administrator password?=
For security reasons, we are not allowed to reset administrator passwords without following a specific procedure.
Your password reset request must be sent by email and paper mail. The paper can be replaced by a fax to speed up the process  =>  '''Fax sending to 28 370 491'''
<u>'''The request must be submitted on letterhead of your company with the following information'''</u>
* administrator's login adminXXX
* Email address which is linked to the administrator
* A brief explanation of the reason why you need to change it
* Send your email to '''[mailto:cso.desk@fundsquare.net cso.desk@fundsquare.net]'''
The email must come from the administrator stated above and include all information specified in the fax.
If the administrator has left the company, the fax has to be signed by a legal representative of the company.
Once Fundsquare has received and checked your request, we will send you an email with your new temporary password.
<u>'''IMPORTANT NOTE:'''</u> The temporary password has to be changed within 7 days upon receipt.
If you have further questions do not hesitate to contact our [[How to contact us|'''Client Support & Operations Desk''']].
= e-file password policy =
[[File:Password.png|300 px]]
(Figure 15)
The password you will have to provide must follow the rules below:
* At least one upper and one lower case letter
* At least one number
* At least one special character from this list: ! # $ % & ( ) * + , . /: ; < = > ? ^ _ @ { | } [ ] ~
* At least 8 characters and at most 20
<u> Please note that </u>:
The validity of your password is not limited in time.
Our system blocks the user after 3 incorrect attempts and it is the e-file administrator who has to unblock the account.
Passwords are encrypted in our database and we do not keep them. You may re-use them.
[[Category: FAQ e-file]]

Latest revision as of 15:16, 15 January 2019