Setup
Your ROS certificate
Filing to Revenue is signed with your digital certificate. Brickie never receives it — the signing happens inside your browser, on your machine.
On this page
Getting the file
You need the certificate as a file — normally named something like brendan_oneill.p12.bac — plus the password you set when you downloaded it. The .bac ending catches people out: it is not a backup copy, it is the certificate. It is the same certificate ROS uses to identify you.
If you have only ever logged in to ROS through the website, the certificate may be sitting in your browser’s store rather than saved anywhere you can find. In ROS, under Manage My Certificates, you can download a fresh copy and set a password for it.
The password is not your ROS login
The certificate password is set at the moment you download the file and is separate from your ROS website password. If you cannot remember it, you cannot recover it — you download the certificate again and set a new one.
Importing it
On the Certificate page, choose the file and enter its password. Brickie reads it in the browser, confirms it can sign with it, and shows you the name and expiry date it found so you can check you imported the right one.
You then set a passphrase for Brickie itself. That passphrase encrypts the certificate for storage in your browser, and you enter it once per session to unlock signing.
Where it actually lives
In your browser’s local storage on the machine you imported it on, encrypted with a key derived from your Brickie passphrase. It is not uploaded, not backed up, and not recoverable by anyone at Brickie.
This is a deliberate reading of the ROS certificate policy, which places responsibility for the private key with the subscriber. It also caps what a breach of Brickie could cost: a server that has never held a certificate cannot leak one, and there is no single place holding every customer’s signing key.
What this means day to day
| Because the key stays local | The consequence |
|---|---|
| Brickie cannot file on your behalf | No scheduled filing, no overnight catch-up, no support engineer re-sending a rejected notification for you. Every filing needs you, present, with the certificate unlocked. |
| Each browser needs its own import | Moving from the office desktop to a laptop means importing the certificate there too. Nothing syncs. |
| Clearing browser data removes it | Keep the original certificate file somewhere safe. Re-importing takes a minute; getting a new one from Revenue takes longer. |
| A shared account is a shared certificate | Anyone who can unlock the browser profile can file as you. Treat the machine accordingly. |
This is the trade being made
A product that held your certificate could file automatically and chase rejections without you. Brickie cannot, and never will. In exchange, there is no scenario in which Brickie files something in your name that you did not initiate.
Renewal and revocation
ROS certificates expire. Brickie shows you the expiry date after import and will not be able to file with an expired one — Revenue rejects the signature rather than accepting it quietly.
- On renewal, download the new file from ROS and import it in Brickie the same way. It replaces the old one.
- If a certificate is compromised, revoke it in ROS first. That is what stops it being used. Removing it from Brickie only removes this copy.
If something goes wrong
| What you see | What it usually is |
|---|---|
| The password is not accepted | The certificate password rather than the ROS website password. If neither works, download the certificate again from ROS and set a new password. |
| Revenue rejects the signature | Most often an expired certificate, or one that has been revoked and replaced. Check the expiry shown on the certificate page. |
| Brickie asks for the passphrase again | The unlocked certificate is held only for the session. Closing the tab or leaving it long enough clears it, by design. |
| Nothing happens when you try to file | Filing needs the certificate unlocked in that browser. If you imported it elsewhere, import it here too. |