Site Tools


guides:apex_user_guide

This is an old revision of the document!


APEX User Guide

Overview

APEX is CeRTNA's 2nd generation Electronic Recording Delivery System. The software is based on Microsoft's .NET Framework and their “Click-Once” software delivery architecture. APEX supports the following major features:

  • Secure transport of XML transaction files.
  • Reporting (Work in progress.)
  • Administration (Work in progress.)
  • Direct Order Entry (Work in progress.)

Other lower level features include:

  • Digital signatures, encryption, and decryption based on PKI technology.
  • Multi-threaded processing for improved throughput.
  • Improved error handling and recovery.
  • Multi-workstation support.

The following pages provide a comprehensive outline of APEX functionality.

HW & OS Requirements

Hardware and software has changed significantly since CeRTNA's original launch in 2008. Since that time the CeRTNA ERDS application environment is transitioning from a simple web client application to a more sophisticated thick client application named APEX.

Hardware Requirements

The following workstation specifications are designed to satisfy the requirements for running APEX and are current as of May 10, 2025:

  • Processor: Intel i5 or greater
  • Memory: 16 GB Minimum / 32 GB Recommended
  • Disk Storage: 100 GB Recommended (Depends on your environment. See note.)
  • USB Port: Available USB 2.0 port (See note.)
  • Network Adapter: 100 Mbps or higher.

Notes:

  • The SafeNet eToken requires a USB 2.0 or 3.0 style port. USB-C adapters are not supported.
  • CeRTNA exchanges files with the recording vendor software using a Windows folder. This folder can be either a local folder on the local hard drive of the workstation, for example the C: drive, or it can be a shared network folder, for example \\your_server\shared_folder\. If you use a network share, the CeRTNA ERDS workstation will need to have network access to the shared folder or UNC path where the CeRTNA ERDS XML transactions will be accessed for submissions, stored upon retrieval, and or picked up for return. Please refer to the section Folder Structure in the Workstation Installation Guide for a description of how the standard CeRTNA ERDS folder structure should be created.
  • In most cases, the Disk Storage requirements for CeRTNA are minimal. The XML files that are submitted by an agent or returned by a county are moved to a PROCESSED subfolder and APEX automatically keeps the subfolder cleaned up based on a “Number of days to keep files” setting in CeRTNA's agent and/or county configuration record. The current default setting for the “Number of days to keep files” is 45. The larger that number is, the more storage space that will be used. Allocating 100 GB of storage space will most likely cover any storage requirements needed by APEX.
  • If you will be using a standalone workstation, you will need a security cabinet for your ERDS workstation. You can click this link to see a security cabinet that CeRTNA recommends.
  • If you will be submitting transactions, you may need to acquire a scanner and scanning software. The brand of scanner/software is left up to the submitter, however, any scanner/software selected needs to be able to produce, black & white, CCITT T.6 (Group4-Compressed), 300 dpi, TIFF image files.

Operating System Requirements

CeRTNA will certify and support the CeRTNA ERDS software (APEX) and the required tools on the following Microsoft Windows platforms:

  • Windows 10 Professional (32-bit or 64-bit versions.)
  • Windows 11 Professional (64-bit version.)
  • Windows Server 2012 Standard/Enterprise (Installed as a VM.)
  • Windows Server 2019 Standard/Enterprise (Installed as a VM.)

Important: Home Editions of Microsoft Windows operating systems are not supported because they do now have support for Local Security Policy.

Firewall Considerations

APEX communicates using SSL port 443 (https) and some communications take place using port 80 (http). The following table contains a list of hosts that must be reachable in order for APEX to be installed or be used after the installation:

Host IP Address Description
dev-ws02.certna.org 204.246.133.236 APEX installation
apex-setup.certna.org 204.246.133.236 APEX installation
apex-prd.certna.org 204.246.133.237 APEX production ERDS web
apex-prd.certnag2g.org 209.170.199.196 APEX production G2G web
reports.certna.org 204.246.133.238 APEX production ERDS reports
reports.certnag2g.org 209.170.199.202 APEX production G2G reports
*.sectigo.com * PKI and SSL certificates (Note 2)
*.usertrust.com * SSL certificates (Note 2)
*.digicert.com * PKI certificates (Note 2)
*.ssl.com * Code Signing certificate (Note 2)
*.godaddy.com * SSL certificates (Note 2)

CeRTNA no longer interfaces with Entrust, therefore, the references to *.entrust.com and *.entrust.net shown above have been stricken out.

Note 1: CeRTNA recognizes that different firewalls are in service at our customers and that firewall features functions can vary broadly. CeRTNA prefers to minimize the amount of IT administrative support required by creating rules based on the following tolerance and/or capabilities of your firewall:

  1. Use wildcard domains if possible. (Ex: *.certna.org or *.certnag2g.org)
  2. Use host names if possible. (Ex: apex-prd.certna.org or reports.certna.org)
  3. Last resort, use IP addresses.

The preceding list is sorted in order of preference.

Note 2: Several digital certificates are used in support of CeRTNA/APEX, these include SSL certificates, PKI certificates for digital signatures, PKI certificates for encryption/decryption, and code-signing certificates. The CeRTNA APEX application uses core WCF & .NET functionality to verify that the PKI certifcates are still valid and have not expired. Further, during the APEX installation/update process, the code-signing certificate is validated. The lower level WCF & .NET API's communicate using port 80 for OCSP and CRL certificate validation functions. It is important that your firewall team take this into consideration.

Workstation Support

In addition to the locations listed above, there are some additional hosts that you also want to allow in order to facilitate the retrieval of Windows Updates and for CeRTNA remote support.

Host IP Address Description
*.microsoft.com * Top-level Microsoft domain, to avoid issues with Windows functionality. (Note 3)
*.update.microsoft.com * General Windows update domain.

Configuring the firewall rules for Windows Updates and other fundamental OS support, for example, virus definition files for Endpoint Protection or other 3rd party system management tools is the responsibility of your organizations IT staff. The information provided in the preceding table is here simply point out that there are additional URL's that may need to be accommodated beyond those that are required for APEX and/or CeRTNA functionality.

Note 3: Support for Teams meetings and screensharing is also required for remote support of the APEX software.

APEX Installation

APEX is based on the Microsoft “Click-Once” software architecture. This means that the installation files are accessed over the Internet. You can initiate the installation of APEX by clicking on the following URL:

https://dev-ws02.certna.org/APEX/Setup/index.html

The following page is displayed in your browser:

Click the Install button. You should see the following prompt at the bottom of the browser window:

Click the Run button.

Applications that are installed over the Internet should be signed so that you know that the application software is distributed by a trusted source. The following Application Install Security Warning is displayed:

Optionally, you can display the CeRTNA Code Signing Certificate by clicking the link labeled California Electronic Recording Transaction Network Authority. If you click the link, the following panel is displayed to so CeRTNA's code signing certificate information:

When you are finished viewing the certificate details, click the Ok button to close the window.

From the Application Install Security Warning window, click the Install button. The APEX application will be installed and a progress window will be displayed as shown below:

Once the installation completes, the APEX client application will automatically launch as shown below:

This completes the APEX Installation process.

APEX Login Panel

To access the APEX Login Panel, click the User Login button, located on the main APEX ribbon:

The following Login Panel will be displayed:

Field Descriptions:

Field Description
User Name This is your CeRTNA ERDS or G2G userid.
Password This is your CeRTNA ERDS or G2G password. (Not your token password.)
Platform Select from the list or type in Production-ERDS or Production-G2G
Status Icon When you select or type in a Platform value, APEX will verify that it can communicate with the selected platform. A green circle with a white checkbox, means APEX communicate with the selected Platform. A red circle with an X means APEX is not able to communicate with the selected platform.
Refresh Icon This icon can be clicked to tell APEX to try communicating with the selected platform again.
Show Password Clicking this checkbox will cause your password to be displayed in plain text.
Forgot Password Click this link if you need to reset your password. (More detail later in this document.)
Register Workstation In order to use APEX for sending or retrieving transactions, your workstation must be a registered, certified ERDS workstation. Use this link to submit a registration request for your workstation. (More detail later in this document.
Login Button Once a userid, password, and valid Platform name have been entered, this button will be enabled. Click this button to continue logging into the CeRTNA ERDS and/or G2G workstation.
Cancel Button Click this button to Cancel and close the Login Panel.

After you have entered your User Name, Password, and Platform you can click the Login button. APEX will then initiate a variety of actions including, verifying your credentials, retrieving and verifying configuration information associated with your user and your organization and APEX will retrieve and verify your PKI Authentication Certificate.

While APEX is performing these actions, the following panel will be displayed:

Once the login initialization and verification process completes, you will be presented with the main APEX UI as shown below:

Documentation for the APEX UI can be found further down in this document.

Forgot Password Panel

When you click Forgot Password link on the main Login Panel, the following pop-up window is displayed:

In the User Name field, enter the userid for the platform that you selected on the Login Panel and then click the Request Password Change button.

A temporary password will be sent to the e-mail address that is associated with the userid that you entered.

When you receive the temporary password, enter the temporary password into the Password Change Code field and then enter your new password into the New Password and the Confirm New Password fields.

If you are uncertain about the password formatting rules, you can click the question mark icon and the following pop-up window will be displayed, showing you the rules for creating a password:

If you have entered a new password that meets the password formatting requirements, the Change Password button will become enabled and you can click it to change your password.

Register Workstation Panel

Workstations that are used to transmit ERDS or G2G transactions (payloads) must be certified by CeRTNA. The certification process includes a verification that the workstation is configured as outlined in the document Preparing For A System Audit and that an acceptable Microsoft Baseline Security Analyzer report has been submitted to CeRTNA.

The Register Workstation process is the method that APEX uses to ensure that only 'certified' workstations are used for transmitting ERDS or G2G transactions (payloads). If you have installed APEX on a workstation that has not been registered, the buttons for sending and retrieving transactions will not be displayed, which means you will not be able to send and/or retrieve transactions.

If you are installing APEX on a workstation that has been certified by CeRTNA, you can register the workstation by clicking the Register Workstation link on the Login Panel. When you click the Register Workstation link, the following pop-up window is displayed:

All fields are required. Once you have completed filling in the form, click the Register Workstation button and a workstation registration request will be created. CeRTNA staff will receive an e-mail notification that the workstation registration request has been created and a staff member will verify that the ERDS or G2G workstation has been certified. If the workstation has been certified, CeRTNA staff will approve the workstation registration request and this will cause APEX to enable the functionality required to send and retrieve ERDS or G2G transactions.

A confirmation e-mail will be sent to the address provided in the registration request to inform the requester about the status of their registration request.

Continue documentation here.

guides/apex_user_guide.1509032717.txt.gz · Last modified: by administrator