Containn
Product
Who it’s for
DocumentationPricingAcademy
Log inSchedule a demo Español

The digital seal certificate: how to upload it and where it lives

What the CSD is, how it differs from the e.firma, how to upload it, and why its private key is not stored in Containn's database.

Documentation · Invoicing

What it is

The digital seal certificate (CSD, certificado de sello digital) is the certificate the SAT, Mexico's tax authority, issues to your hotel to seal its invoices. It has three pieces: the .cer file (the certificate), the .key file (the private key) and that key's password. It is not the e.firma: the e.firma is the hotel's advanced electronic signature for its filings with the SAT, and it cannot seal invoices.

When to use it

Before your first invoice and every time you renew it. You generate it at the SAT, in CertiSAT web, with the hotel's valid e.firma; the setup screen includes the link.

Step by step

  1. In Settings → CFDI Invoicing (SAT), enter and save the Issuer details first.
  2. On the Digital seal (CSD) card, use Choose .cer file and Choose .key file, and type the Key password (.key): the one you chose when generating the CSD, not your e.firma password.
  3. Decide whether to tick Also save for cancelling invoices (see below for what it changes).
  4. Click Upload digital seal. Before sending it, Containn checks that the .cer and .key are a pair, that the password opens the key and that the certificate belongs to the issuer's RFC (taxpayer ID).
  5. Once the card says Digital seal (CSD) loaded and your hotel's account with the PAC (authorized certification provider) is connected, use Test connection (uses no folio) to validate account, seal and details without stamping.

Where it lives

The private key and its password are not stored in Containn's database. They go to the authorized certification provider (PAC), inside your hotel's account, and Containn keeps only the record that the seal is loaded and which RFC it belongs to.

Cancelling an invoice requires signing the request with that same seal, and you have two options:

  • With the box ticked (recommended). A copy is kept on the server, outside the database, and is never shown again. Once our team connects it, your cancellations are signed without asking you, and guests can cancel and invoice again from their link.
  • Without the box. Every time you cancel, you upload the .cer, the .key and the password. They are used only for that signature and are not stored.
Never upload your e.firma here

You need the e.firma to generate the CSD at the SAT, but only the CSD is uploaded to Containn. And never share your e.firma password by chat or email.

What can go wrong

  • The password does not open the key, or the files are not a pair. The message tells you before anything is sent.
  • The certificate belongs to another RFC. Only the CSD of the issuer's RFC is accepted.
  • The seal expired. An invoice sealed with an expired certificate has no tax validity, and in production Containn does not sign cancellations with it. Renew it with the SAT and use Replace digital seal.
  • Your hotel changed its PAC account. The seal lives inside each account: upload it again.
  • The card says it is a TEST seal. Invoices go out with a test RFC and no tax validity; replace it with the real CSD before invoicing guests.

To upload it you need the Facturación CFDI (SAT) permission under Settings → My team.

Related articles

Didn’t find what you were looking for?

Schedule a demo and we’ll reply the same business day.