EMSWe RIM Sender Integration – Access Point Setup Guide

Sender-side overview for integrating via AS4 / RIM

Sender Access Point Documentation

Use these guides together when preparing a sender-side Domibus Access Point for EMSWe RIM messaging.

Current guide

Access Point Setup Guide

Architecture, responsibilities, message preparation, certificates, authentication and operational prerequisites.

Configuration guide

Domibus PMode Configuration

Sender-side PMode example, Finland C3 environment values, import guidance and readiness checks.

Open the PMode Configuration Guide →

Reference document
This document is a concise technical overview for senders.
For authoritative requirements, detailed field definitions, validation rules, certificate policies, and legal references, always refer to:
Finland EMSWe Domibus Sender Integration Guide.pdf

Purpose

This document provides quick, practical guidance for senders integrating with a Member State backend through the Reporting Interface Module (RIM) using AS4 (Domibus) within the European Maritime Single Window environment (EMSWe).

It focuses on:

This guidance applies to both:

as defined by EMSWe and the RIM architecture.

Architecture Overview (Four-Corner Model)

flowchart LR
        C1["Sender Backend (C1)"]
        C2["Sender AS4 Access Point – Domibus (C2)"]
        C3["Member State RIM – Domibus (C3)"]
        C4["Member State MNSW Backend (C4)"]
        C1 -->|ASiC-E payload| C2
        C2 -->|AS4 UserMessage| C3
        C3 -->|Validated payload| C4
    
CornerRoleResponsibility
C1Sender backendGenerates EMSWe formalities and signs ASiC-E
C2Sender Access PointAS4 messaging, WS-Security, TLS
C3Member State RIMAuthentication, validation, routing
C4Member State backendBusiness processing

The sender fully controls C1 and C2 only. All communication beyond C2 takes place via secure AS4 exchange.

AS4 Access Point Requirement (Key Rule)

There is NO shared or Member State–provided AS4 Access Point.

The Domibus AS4 Access Point software is publicly available and can be downloaded from the EU DIGIT eDelivery website. Each sender must install and operate its own Domibus instance and configure communication between:

This applies regardless of whether the sender submits messages directly or via a service provider.

Role of Data Service Providers (DSP)

A Data Service Provider (DSP) can be characterized as a technical service that:

Important clarifications:

From the RIM and Member State perspective:

Message Preparation (Sender Backend – C1)

Before transmission, the sender backend must create an ASiC-E container that includes:

Signature requirements:

The ASiC-E container is handed over to the Access Point unchanged.

AS4 Message Mapping (Access Point – C2)

The Access Point (Domibus) wraps the ASiC-E container into an AS4 UserMessage.

Mandatory header metadata includes:

FieldDescription
SenderSender Access Point identifier
ReceiverMember State RIM identifier
Authorization.IdentifierSender EORI
Authorization.TypeDECL or DSP
Authorization.SubDomainCountry code
originalSenderBusiness identifier of C1
finalRecipientMember State MNSW
Servicerim-messaging-service
Actionemswe-formality-request
MessageIdUUID
TimestampISO 8601

Critical requirement: The EORI value must exactly match the value registered in URAM, otherwise the message is rejected.

Certificates and Security

PurposeUsed byCertificate
ASiC-E signingC1eIDAS QES / AdES
AS4 signing & encryptionC2X.509 (Domibus keystore)
TLS transportC2 ↔ C3X.509 TLS
Trust validationAllCA certificates

Minimum cryptographic requirements:

Registration and Authentication (URAM)

Before sending any messages:

The RIM validates every incoming AS4 message against URAM.

Configure Domibus PMode

After the Access Point, certificates and network connectivity have been prepared, configure Domibus with an EMSWe RIM-compatible PMode. The PMode binds the parties, endpoints, service, actions, payload profile, security policy, reliability settings and message retention into an executable AS4 process.

Use the dedicated PMode guide. It contains a complete sender-side example, Finland C3 values for DEV, STG and PRD, explanations of each PMode section, and import and readiness checklists.

Open Domibus PMode Configuration Guide →

Access Point Configuration and Changes

A bilateral AS4 agreement between the sender and the Member State defines:

Any change (certificate, endpoint, key) requires: