Blog · August 16, 2026

How to Install MUP, Pošta and Chamber of Commerce Certificates — A Guide

How to Install MUP, Pošta and Chamber of Commerce Certificates — A Guide

Electronic certificates have become a necessity — without them you can’t submit an e-invoice, you can’t use eUprava (the e-Government portal), and many banks require Halcom or Pošta CA for business accounts. But since it’s all “new” to most users, the installation isn’t obvious. I’m writing this guide from experience — a few thousand installations at our shop over the years.

What certificates are and why these ones

In the simplest terms — a certificate is a digital document that confirms you are who you say you are when you sign something over the internet. Instead of going to the bank, standing in line at a MUP counter, or carrying a facsimile stamp around everywhere — the certificate does that for you. EU countries have been doing this since 2014 (the eIDAS regulation), Serbia since 2016 (the Law on Electronic Documents).

Here we have several issuers (CA — Certificate Authority):

  • Pošta CA (Pošta Srbije) — the largest, cheapest, and most universal. For e-invoicing, eUprava, and Customs.
  • Halcom CA — primarily for banking, but increasingly for e-invoicing too. Most banks require either Halcom or Pošta CA.
  • MUP / CYBER — a qualified certificate on the biometric ID card. You need a reader.
  • Chamber of Commerce of Serbia CA — for companies and sole proprietors.
  • CACertSrbije (Republic of Serbia) — the state root, for certain specific uses.

If you only need it for e-invoicing — Pošta CA is usually the most practical.

Why people fail on their own

Technically — a certificate is just a file (most often with a .pfx or .p12 extension). But for it to work properly, it has to be in the RIGHT PLACE in the system. That’s where the problems start.

Problem 1: Browser certificate store vs. system store

Windows has its own “system” certificate store. Chrome and Edge use that system store. But Firefox has its own separate one. If you install the certificate in the system store, Firefox doesn’t see it. If you install it only in Firefox, Chrome and Edge don’t see it.

For e-invoicing (SEF) and Halcom services you need it in BOTH places. Users don’t know this, install it in one, “it doesn’t work,” and give up.

Problem 2: Missing root CA

For the system to trust your certificate, it has to know who issued it. Pošta CA is a newer organization — Windows doesn’t ship with the Pošta root CA installed. It has to be installed separately. If you don’t do this, the certificate will work but every site will show “this certificate is untrusted.”

Problem 3: Smart card readers — elusive drivers

If you use a hardware certificate (MUP biometric ID, eToken USB, Aladdin), you need:

  • A hardware driver for the reader/token (from the manufacturer — SCM, Gemalto, Aladdin)
  • Middleware that “translates” between the token and Windows (SafeNet Authentication Client, the MUP CA application)
  • Browser integration so the certificate becomes visible in Chrome/Firefox

Three layers, and each one can fail. In the latest versions of Windows 11, Microsoft updated Security Mode, which caused a lot of older middleware to stop working. A typical call we get: “I bought a token 3 years ago, and it doesn’t work with the new Windows.”

Problem 4: Java applet pages that portals use

Many Serbian portals (e-banking at most banks, some government services) still use Java applets for signing. Chrome and Edge dropped Java applet support back in 2017 — they simply don’t work. You need an older browser, most often Firefox ESR or a portable Pale Moon, plus the exact Java JRE version (usually 8.x).

Users don’t know this. They try Chrome, “it doesn’t work.” They try Edge, “it doesn’t work.” They give up, thinking they broke something.

Problem 5: Multiple certificates at the same time

If you use Halcom for the bank and Pošta CA for e-invoicing, when you log into a portal the system sometimes picks the wrong one. Especially if the certificates have similar names. The browser usually asks “which certificate do you want?” — but Chrome remembers your last choice and picks the same one next time. Confusing.

A concrete example — Pošta CA + e-invoicing

The most common scenario in practice. The user is a sole proprietor who has to submit e-invoices (mandatory since 2023 for everyone doing business with the state). They bought a certificate at Pošta, and now they have it on a USB. What should they do?

  1. Setting up the USB: Plug in the USB. Windows 11 usually recognizes it generically, but Pošta CA tokens need SafeNet Authentication Client version 10.6+. Download it from the Pošta site and install it. Restart.
  2. Setting up the root CA: Download the root CA (.crt file) from the Pošta site. Open it with a double-click, click “Install Certificate,” and choose “Local Machine” → “Trusted Root Certification Authorities.” Restart Windows.
  3. Checking the token: Open SafeNet Authentication Client, click the icon, and you should see your certificate. If you don’t, your USB isn’t being recognized properly.
  4. Registering on SEF (the e-invoicing system): Go to efaktura.mfin.gov.rs. The site asks for your certificate. Pick it from the drop-down (your name + Pošta CA should appear). Accept the terms of use. Now you’re registered.
  5. Configuring it in your accounting software: If you use Minimax or Pantheon — they all have “SEF integration.” You need to enter the certificate or the token PIN. This step is specific to each program.

That’s a set of 5 steps, each with its own pitfalls. If you skip #2 (root CA), the certificate works but the browser says “untrusted.” If you skip #1 (SafeNet), the token isn’t seen at all. If you skip #3, you have no idea whether the certificate is even on the token.

When to call a shop

Honestly — if your work matters to you but computers aren’t your passion, just call. The time you’ll spend reading forums and fiddling is worth more than an installation at our shop. Plus you get a guarantee that it works once we’re done.

The calls we usually get:

  • “I have Pošta CA on a USB, and after reinstalling Windows it doesn’t work” — the most common
  • “I can’t log into the e-invoicing portal, the certificate isn’t showing up” — the second most frequent
  • “The MUP site rejects me, my reader doesn’t work” — biometric ID card
  • “My Halcom certificate expired, I don’t know what to do” — renewal
  • “I switched the director’s laptop, I need the certificate on the new one” — migration

For each of these scenarios we have a standard procedure. Typically 30–60 minutes of work.

Tips for those who still want to do it themselves

If you really want to give it a try, here are a few things that will help:

  • Make a backup of the PFX file before you start. If something breaks, you have a copy.
  • Write down the PIN and password that came with the token — if you lose them, Pošta issues you a new token for an extra fee.
  • Don’t install certificates in the “Personal” store if you’re an employer and others use the same computer — “Trusted People” or “Other People” is better.
  • After a major Windows upgrade (e.g., 10 → 11, or a big feature update), check the certificate — its trust often “gets lost.”
  • Scan the token for viruses before installing — especially if someone else used it before.

Prices and what we include

A certificate installation with us (price in the price list) includes:

  • Placing the certificate in all the necessary system locations
  • Installing the root CA if needed
  • Setting up the token/reader driver
  • Testing communication with the specific portal (e-invoicing, eUprava, your bank)
  • Backup of the PFX file — we return it to you, we don’t keep it
  • A mini guide on what to do if it “gets lost” after a Windows update

For companies or anyone with multiple certificates, the package is more affordable. Contact us for a personalized quote.

What to do now

If you need an installation — check out our detailed page or call 069 1303 111. For urgent cases (the e-invoice has to be submitted tomorrow, the bank needs a signature right away), we try to solve it the same day if you drop off the device before 2 PM.

We have three locations in Belgrade — Arena, Piramida, and Centar near the Botanical Garden. If you can’t come in yourself, our courier service picks up and returns the device.

Computer broken?

Get in touch — diagnostics are free and a courier picks the device up at your address the same day.

Contact us →