Кореневі сертифікати trustedrootcertificates.com. ssl сертифікати, SAN SSL сертифікати, сертифікати для сайта, SSL захист, ssl провайдер, Українский сертификаційний центр Адграфікс Хмельницький Україна 
 Українский сертификаційний центр Адграфікс Хмельницький Україна Центр сертифікації сайтів та верифікації компаній Адграфікс Хмельницький Україна Кореневі сертифікати  Добро пожаловать в компанию Адграфикс Добро пожаловать в компанию Веб Траст Ураина Магазин сертифікатів Магазин доменів Магазин хостинга Certificates Current Site адграфікс - комфорт в інтернет ! Контакт  з адграфікс Пошук на сторінці Версія для друку
Русская версия сайта по продаже сертификатов English version Certificates Shop Українська версія магазину з продажу сертифікатів+A | R | -A | |-| |<->|
Грн. Руб. Дол. * Євро * ( $1=0.85EU )

Сертифіковано в Україні



В своей основе сертификаты делятся на два типа – Single Root и Chained Root SSL. Single (одиночные) Root Certificates как правило считаются более безопасными и более предпочтительными чем сертификаты Chained (промежуточные) Root SSL. Хотя сами Chained Root SSL сертификаты тоже довольны эффективны и безопасны так как они основываются только на доверенных корневых Trusted Root сертификатах.
Chained Root SSL Certificate Single Root SSL Certificate
  • Выдается центром CA, не имеет собственного доверенного корневого сертификата Trusted Root CA Certificate
  • Признается не всеми браузерами, Chained Root SSL зависят от оригинала Trusted Root CA владельца сертификата для признания браузера
  • Не очень надежный; Chained Root SSL сертификаты становятся недействительными как только истекает Trusted Root CA сертификат на базе которого он действует
  • Сертификат может истечь раньше в зависимости от срока действия Trusted Root CA Certificate
  • При установке могут возникнуть проблемы, поскольку она должна проводиться на веб-сервере так же как на сайте. Для инсталяции нужен технический специалист, так как недоступна премиум -установка.
  • Могут работать или нет в стандарте шифрования 128/256 Bit
  • Требуются бумажные документы, выпуск занимает продолжительное время
  • Как правило не предусматривают никакой страховки
  • Отсутствуют гарантии
  • Бесплатная печать сайта может предоставляться или нет
  • Сравнительно низкие цены
  • Выпускается центром CA как собственный корневой сертификатTrusted Root CA SSL Certificate .
  • Признается практически всем популярными браузерами; большинство Single Root SSL сертификатов имеет 99.9% уровень признания браузерами.
  • Высокая надежность; центр CA выпускающий Single Root SSL сертификат работает стабильно и организованно
  • Выпущенные сертификаты имеют такою же силу как и Trusted Root CA сертификат
  • Чрезвычано просты в установке, могут быть установлены без помощи технического специалиста. Доступны Premium Installation пакеты для установки
  • Стандартное шифрование 128/256 Bit
  • Не требуется предоставление бумажных документов. Большинство Single Root SSL сертификатов выпускается в считаные минуты
  • Большинство Single Root SSL сертификатов имею страховку
  • Покрывается гарантией
  • Включена бесплатная печать сайта Site Seal. Визуально сразу же удостоверяет посетителя о безопасности сайта.
  • Цены более высокие, но и надежность и гарантии для пользователей соответственно выше.

Trusted Root – what is that?

This is a question that might stump most people, even those who might be well acquainted with the internet.

The reason for this is that Trusted Root is not an oft used term. Trusted Root refers to Trusted Root Certificate which is related to website security.

A Root Certificate is either an unsigned public key certificate or a self-signed certificate. It is generally part of a public key infrastructure scheme. A company that owns a Root Certificate is generally called a Certification Authority because it normally has rights to issue multiple certificates based on its Root Certificate. When the Root Certificate is widely recognised and trusted, it automatically becomes a Trusted Root Certificate.

Every website that involves online transactions, either monetary or information related requires a secure way of transmitting data. This is achieved through data encryption which is also known as “Secured Socket Layer” or SSL. When a website is SSL secured, the indication for this is generally in the form of an SSL certificate.

SSL Certificates can only be issued by the Certification Authorities. As stated above, the CAs would normally own a Trusted Root CA Certificate. For an SSL certificate to be really effective, the Trusted Root CA Certificate on which it is based must be recognised and present in all web browsers.

Let us understand the reason behind this…

When a website with an SSL certificate is loaded into the web browser, it is the web browser that decided whether to accept the SSL certificate or not. For this decision, the web browser generally turns to its internal records of Trusted Root Certificates. Every browser comes with a list of Trusted Root Certificates which are pre-recorded and recognised by the browser vendor. another is chained root certificate .

If the Trusted Root CA Certificate of an SSL Certificate is present in the web browser, the SSL Certificate will be recognised and accepted by the browser. The more number of browsers in which the Trusted Root CA Certificate is present, the higher the acceptance of the SSL Certificates issued by that CA! This is known as “browser ubiquity”.

Most of the major current CAs such as VeriSign, GeoTrust, Thawte, RapidSSL, etc. can claim 99.9% browser recognition rates. This is because they have been around for a long time and have now formed relations with most browser vendors who recognise these CAs are being trustworthy and stable.

As a result, whenever the browser vendors create a new version of their browsers, they automatically include the Trusted Root CA Certificates of these CAs in the list of recognised Trusted Root Certificates.

When an SSL certificate is based on a Trusted Root CA Certificate, the website into which it is integrated becomes that much more trustworthy and secure. The stability and trustworthiness of the CA in turn carries through to the website and inspires trust in website visitors.

If you have a website for which you are looking to get an SSL certificate, you should ensure that the SSL certificate you opt for is issued by a CA that owns its Trusted Root CA Certificate. Only such an SSL certificate can provide you industry standard security.

The debate over Chained Root SSL Certificates and Single Root SSL Certificate has been waging ever since SSL Certificates came into existence. Most website owners prefer to get a Single Root SSL Certificate for their website because of the fact that such certificates provide additional benefits and have certain plus points over Chained Root SSL Certificates.

Single Root SSL Certificates are generally issued by Certification Authorities (CA) that own their Trusted Root CA Certificates. This makes Single Root SSL Certificates much more trusted and secure. On the other hand, CAs that issue Chained Root SSL Certificates may or may not own their Trusted Root CA Certificate.

Single Root SSL Certificates are preferable on account of the numerous benefits they carry. Chained Root SSL Certificates are viable only if you have a very low budget for an SSL certificate.

There are several other similar points of differentiation that give Single Root SSL Certificates an edge over Chained Root SSL Certificates.

SSL Certificates are issued by Certification Authorities (CA) who generally own their Trusted Root CA Certificate. When we say Trusted Certificate, it means a Root Certificate that is recognised and already present in all the browsers and other applications that require and accept security certificate. An example of such a CA and Trusted Root CA Certificate would be GeoTrust, which is one of the oldest CAs and owns its Trusted Root CA Certificate.

When such a CA issues an SSL certificate, it is known as a Single Root SSL Certificate. There are several other SSL Certificate Authorities that don’t own a Trusted Root CA Certificate; or if they do, they don’t wish to issue SSL certificates based on that Root Certificate. As a result the CA links up with another CA that owns a Trusted Root Certificate and issues SSL certificates on that Trusted Root Certificate.

So when the browser links with the web-server and website, it actually identifies the Chained Root SSL Certificate as originated from the Trusted Root Certificate and accepts it. Unlike the identification process of the Single Root SSL Certificate which takes less than a second, Chained Root SSL Certificates take longer time to be recognised by the browser because they have to pass through two root levels.

A CA that issues Chained Root SSL Certificates is usually not recognised by the browsers and so they have to bank on those CAs that have browser recognition. This can sometimes create a problem in the sense that if the CA with the Trusted Root CA Certificate goes defunct, the Chained Root SSL Certificates issued will automatically become invalid.

Additionally the owner of the Trusted Root CA Certificate has full authority to make any changes they wish to their certificate without intimating the Chained Root SSL Certificate issuing CA. Any such changes can directly affect the Chained Root SSL Certificate. You might also face a few issues with installing the Chained Root SSL Certificate on the web-server; it might require deeper technical knowledge.With all the setbacks, there are also certain benefits of Chained Root SSL Certificates. The first is that Chained Root SSL Certificates cost comparatively lower than the Single Root SSL Certificates. So if you don’t have the budget for a Single Root Certificate, a Chained Root Certificate can easily fulfill your requirements.

Being based on a Trusted Root CA Certificate, Chained Root SSL Certificates generally work on industry standard 128 Bit encryption and security. This makes them just as secure as Single Root SSL Certificate.

If you are a start-up e-commerce website or a comparatively smaller one looking to grow, you can definitely get started with a Chained Root SSL Certificate. Though ideally you would be looking to get a Single Root SSL Certificate as it is the best you can get for your website.

In cryptography and computer security, a root certificate is either an unsigned public key certificate or a self-signed certificate that identifies the Root Certificate Authority (CA). A root certificate is part of a public key infrastructure scheme. The most common commercial variety is based on the ITU-T X.509 standard, which normally includes a digital signature from a certificate authority (CA).

Digital certificates are verified using a chain of trust. The trust anchor for the digital certificate is the Root Certificate Authority (CA).

A certificate authority can issue multiple certificates in the form of a tree structure. A root certificate is the top-most certificate of the tree, the private key of which is used to "sign" other certificates. All certificates below the root certificate inherit the trustworthiness of the root certificate - a signature by a root certificate is somewhat analogous to "notarizing" an identity in the physical world.

Many software applications assume these root certificates are trustworthy on the user's behalf. For example, a Web browser uses them to verify identities within SSL/TLS secure connections. However, this implies that the user trusts their browser's publisher, the certificate authorities it trusts, and anyone the certificate authority may have issued a certificate-issuing-certificate, to faithfully verify the identity and intentions of all parties that own the certificates. This (transitive) trust in a root certificate is the usual case and is integral to the X.509 certificate chain model.

The root certificate is usually made trustworthy by some mechanism other than a certificate, such as by secure physical distribution. For example, some of the most well-known root certificates are distributed in the Internet browsers by their manufacturers.

Root certificate. Mozila FireFox Certificate List

This is a list of companies and certificates included in the Mozilla project Root CA store after March 1st, 2007. Eventually, it is hoped that this list will be extended to include all CAs in the store. In the mean time, the trunk version of the file with all the included roots in it is here.

Note: revocation details (CRLs, OCSP) are given for information only; because a CA can create any number of sub-CAs, and can decide to change its revocation URLs at any time, this information cannot be kept up to date and should not be regarded as comprehensive. Type information is a subjective assessment.


Certicamara S.A.

Sociedad Cameral de Certificación Digital - Certicámara S.A. is a commercial CA primarily serving Colombia and Andean Region

Audit: WebTrust, performed by Deloitte and Touche : Audit Report and Management's Assertions

AC Raíz Certicámara S.A.

This is a new root CA certificate authorized by Industry and Commerce Department of Colombia, to replace the Certificado Empresarial Clase-A certificate. It has one internally operated subordinate CA.

Link Download/Install
SHA1CB:A1:C5:F8:B0:E3:5E:B8:B9:45:12:D3:F9:34:A2:E9:06:10:D3:36
Version3
Modulus (key length)4096
Valid From2006-11-27
Valid To2030-04-02
RevocationCRL
TypeOV
DocumentCertificate Hierarchy
DocumentCertification Practices Statement (CPS) – in Spanish
DocumentDeclaration of Practices
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (401262), Inclusion (486424)
Commentsnone


Certigna of Dhimyotis

Dhimyotis services include Certigna ID and Certigna SSL. Certigna is a French CA for the European market and expects to expand to serve other countries (India, USA, South America ... ) soon.

Audit: ETSI TS 102.042, performed by LSTI - La Sécurité des Technologies de l'Information : Statement of Compliance with ETSI TS 102.042

Audit: ETSI TS 102.042, performed by LSTI - La Sécurité des Technologies de l'Information : 2008 Statement of Compliance with ETSI TS 102.042

Certigna

The Certigna root has three internally operated subordinated CA’s: Certigna SSL is for SSL-enabled servers, Certigna ID is for authentication and digitally-signed email, and Certigna Chiffrement is for encrypting email.

Link Download/Install
SHA1B1:2E:13:63:45:86:A4:6F:1A:B2:60:68:37:58:2D:C4:AC:FD:94:97
Version3
Modulus (key length)2048
Valid From2007-06-29
Valid To2027-06-29
RevocationCRL for the SSL Subordinate CA, CRL for the ID Subordinate CA
TypeIV/OV
DocumentPublic Portion of CPS
DocumentTranslated Portion of CPS
DocumentTranslated Portion of Code Signing CPS
DocumentCertificate Policy for SSL Subordinate CA
DocumentCertificate Policy for ID Subordinate CA
Requested Trust Bits
  • Websites
  • Email
Bugs Authorisation (393166), Inclusion (483889)
Commentsnone


Comodo

Comodo CA Ltd is a commercial CA based in the UK and serving customers worldwide. Comodo has a total of 12 root CA certs included in Mozilla, and altogether 124 subordinate CAs signed by those root CAs. Some of them exist to differentiate between different Comodo brands or products and some are used to re-brand products for its partners. In each case Comodo retains the private key for the subordinate CA within its infrastructure.

Audit: WebTrust, performed by KPMG: Audit Report and Management's Assertions

Audit: WebTrust EV, performed by KPMG: Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria

COMODO Certification Authority

Root CA certificate with subordinate CAs issuing SSL certificates, email certificates, and code signing certificates.

Link Download/Install
SHA166:31:BF:9E:F7:4F:9E:B6:C9:D5:A6:0C:BA:6A:BE:D1:F7:BD:EF:7B
Version3
Modulus (key length)2048
Valid From2006-12-01
Valid To2029-12-31
RevocationCRL, OCSP
TypeDV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)
DocumentComodo Certification Practice Statement, Version 3.0
DocumentComodo Extended Validation (EV) Certification Practice Statement, Version 1.03
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (401587), Inclusion (426568), EV (426572)
Commentsnone

COMODO ECC Certification Authority

Root ECC certificate with internal subordinate CA issuing EV SSL certificates, email certificates, and code signing certificates.

Link Download/Install
SHA19F:74:4E:9F:2B:4D:BA:EC:0F:31:2C:50:B6:56:3B:8E:2D:93:C3:11
Version3
Modulus (key length)SECG elliptic curve secp384r1 (aka NIST P-384)
Valid From2008-03-06
Valid To2038-01-18
RevocationCRL, OCSP
TypeEV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)
DocumentComodo Certification Practice Statement
DocumentECC Amendment to Comodo EV CPS
DocumentComodo EV Certification Practice Statement
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (421946), Inclusion (450427), EV (450429)
CommentsThis is a new EV request.


ComSign

ComSign is a private company owned by Comda, Ltd., a company specializing in information protection products and solutions. In 2003, ComSign was appointed by the Justice Ministry as a certificate authority in Israel in accordance with the Electronic Signature Law 5761-2001, and is currently the only entity issuing legal authorized electronic signatures according to the Israel law. ComSign has issued electronic signatures to thousands of business people in Israel.

Audit: Israel Electronic Signature Law, performed by The State of Israel – Ministry of Justice: Registered CA

Audit: ETSI TS 101 456, performed by Sharony-Shefler: Audit Statement 2009

ComSign CA

This root has six internally-operated subordinate CAs that are used for issuing digital IDs to individuals and corporations in accordance with the Israeli Electronic Signature Law.

Link Download/Install
SHA1E1 A4 5B 14 1A 21 DA 1A 79 F4 1A 42 A9 61 D6 69 CD 06 34 C1
Version3
Modulus (key length)2048
Valid From2004-03-24
Valid To2029-03-19
RevocationCRL
TypeIV, OV
DocumentCert Hierarchy Diagram
DocumentLinks to CPSs in Hebrew and English
DocumentCPS in English
Requested Trust Bits
  • Email
Bugs Authorisation (420705), Inclusion (490487)
Commentsnone

ComSign Secured CA

This root has two internally-operated subordinate CAs that are used for issuing certificates for SSL and for code-signing.

Link Download/Install
SHA1F9 CD 0E 2C DA 76 24 C1 8F BD F0 F0 AB B6 45 B8 F7 FE D5 7A
Version3
Modulus (key length)2048
Valid From2004-03-24
Valid To2029-03-16
RevocationCRL
TypeOV
DocumentCert Hierarchy Diagram
DocumentLinks to CPSs in Hebrew and English
DocumentCPS in English
DocumentSecurity Certificate Approval Regulations For SSL Websites in English
Requested Trust Bits
  • Websites
  • Code
Bugs Authorisation (420705), Inclusion (490487)
Commentsnone


DCSSI

DCSSI is part of the French Government. It issues certificates to French Government websites which are used by the general public. Each department has a sub CA; there are at least 20 at the moment, and potentially up to 60.

Audit: Government -- WebTrust CA Equivalent, performed by French Secretariat Général de la Défense Nationale: Official decision for IGC/A homologation

IGC/A

This is the root certificate of the French Government CA. The IGC/A root issues a subordinate CA for each organization, which can be only a government or an administrative organization. Each of these subordinate CAs may issue end-entity certificates or additional subordinate CAs to be used for divisions within that organization. Each organization is required to follow the CP and the Government RGS/PRIS, and be audited.

Link Download/Install
SHA160:D6:89:74:B5:C2:65:9E:8A:0F:C1:88:7C:88:D2:46:69:1B:18:2C
Version3
Modulus (key length)2048
Valid From2002-12-13
Valid To2020-10-17
RevocationCRL
TypeOV
DocumentPolicies and other useful information specific to this root
DocumentCertificate Policy
DocumentRepository General Security (RGS) Website
DocumentPolitique de Référencement Intersectorielle de Sécurité (PRIS)
DocumentSummary of PRIS
DocumentVariables de temps (for CRL frequency update)
DocumentPC-Type authentification servers (for SSL)
DocumentPC-Type authentification
DocumentProfiles de certificats, LCR et OCSP
DocumentPC-Type cachet server
DocumentPC-type signature
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (368970), Inclusion (477147)
Commentsnone


DigiCert

DigiCert is a US-based commercial CA with headquarters in Lindon, UT. DigiCert provides digital certification and identity assurance services internationally to a variety of sectors including business, education, and government.

Audit: WebTrust, performed by KPMG: Audit Report and Management's Assertions

DigiCert Assured ID Root CA

Link Download/Install
SHA105:63:B8:63:0D:62:D7:5A:BB:C8:AB:1E:4B:DF:B5:A8:99:B2:4D:43
Version3
Modulus (key length)2048
Valid From2006-11-10
Valid To2031-11-10
RevocationCRL, OCSP
TypeOV, EV
DocumentDigiCert Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
DocumentDigiCert Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
Requested Trust Bits
  • Websites
  • Email
Bugs Authorisation (364568), Inclusion (378162)
Inclusion Date2007-06-05
Commentsnone

DigiCert Global Root CA

Link Download/Install
SHA1A8:98:5D:3A:65:E5:E5:C4:B2:D7:D6:6D:40:C6:DD:2F:B1:9C:54:36
Version3
Modulus (key length)2048
Valid From2006-11-10
Valid To2031-11-10
RevocationCRL, OCSP
TypeOV, EV
DocumentDigiCert Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
DocumentDigiCert Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
Requested Trust Bits
  • Websites
  • Email
Bugs Authorisation (364568), Inclusion (378162)
Inclusion Date2007-06-05
Commentsnone

DigiCert High Assurance EV Root CA

Link Download/Install
SHA15F:B7:EE:06:33:E2:59:DB:AD:OC:4C:9A:E6:D3:8F:1A:61:C7:DC:25
Version3
Modulus (key length)2048
Valid From2006-11-10
Valid To2031-11-10
RevocationCRL, OCSP
TypeOV, EV
DocumentDigiCert Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
DocumentDigiCert Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
Requested Trust Bits
  • Websites
  • Email
Bugs Authorisation (364568), Inclusion (378162)
Inclusion Date2007-06-05
Commentsnone


DigiNotar

DigiNotar is a Dutch trusted third party, mainly operating in the Netherlands. They issue certificates based on notary verification of applicants. They service the business, government and consumer markets.

Audit: ETSI 101.456, performed by Price Waterhouse Coopers: ETSI Certificate, Statement of ETSI Compliance

Audit: WebTrust EV, performed by Price Waterhouse Coopers: Assertion of Management and Audit Report

DigiNotar Root CA

This is the top root, used only to issue CA certificates for five application-specific subordinate CAs: DigiNotar Public CA 2025 (non-qualified personal certificates), DigiNotar Qualified CA (qualified personal certificates), DigiNotar Services CA (SSL and object signing certificates), DigiNotar Extended Validation CA (EV certificates), and DigiNotar Private CA (CA certificates for organizational CAs).

Link Download/Install
SHA1C0:60:ED:44:CB:D8:81:BD:0E:F8:6C:0B:A2:87:DD:CF:81:67:47:8C
Version3
Modulus (key length)4096
Valid From2007-05-16
Valid To2025-03-31
RevocationCRL, OCSP
TypeOV, EV (policy OID 2.16.528.1.1001.1.1.1.12.6.1.1.1)
DocumentCPS DigiNotar 30 October 2007, Version 3.5
DocumentOverview of DigiNotar Root Certificates
Requested Trust Bits
  • Websites
  • Code
Bugs Authorisation (369357), Inclusion (431621), EV (493265)
Commentsnone


Entrust

Entrust is a commercial CA serving the global market for SSL web certificates. Entrust also issues certificates to subordinate CAs for enterprise and commercial use.

Audit: WebTrust, performed by Deloitte and Touche LLP: Audit Report and Management's Assertions

Audit: WebTrust EV, performed by Deloitte and Touche LLP: Audit Report and Management's Assertions

Entrust Root Certification Authority

This root was primarily created as the trust root for Entrust EV SSL certificates. EV certificates are issued using the Entrust Certification Authority - L1A subordinate CA.

Link Download/Install
SHA1B3:1E:B1:B7:40:E3:6C:84:02:DA:DC:37:D4:4D:F5:D4:67:49:52:F9
Version3
Modulus (key length)2048
Valid From2006-11-27
Valid To2026-11-27
RevocationCRL, OCSP
TypeOV, EV (policy OID 2.16.840.1.114028.10.1.2)
DocumentEntrust SSL Web Server Certification Practice Statement, Version 2.06
DocumentEntrust Certificate Services Certification Practice Statement for Extended Validation (EV) SSL Certificates, Version 1.01
DocumentEntrust Extended Validation Business Practices
Requested Trust Bits
  • Websites
Bugs Authorisation (382352), Inclusion (387892), EV (416544)
Commentsnone


GeoTrust

GeoTrust is a commercial CA with worldwide operations and customer base; it is a subsidiary of VeriSign, Inc.

Audit: WebTrust/WebTrust EV, performed by KPMG: Audit Report and Management's Assertions

GeoTrust Primary Certification Authority

This CA issues a CA certificate to the subordinate CA GeoTrust Extended Validation SSL CA, which in turn issues Extended Validation certificates for SSL-enabled servers.

Link Download/Install
SHA132:3C:11:8E:1B:F7:B8:B6:52:54:E2:E2:10:0D:D6:02:90:37:F0:96
Version3
Modulus (key length)2048
Valid From2006-11-26
Valid To2036-07-16
RevocationCRL, OCSP
TypeEV (policy OID 1.3.6.1.4.1.14370.1.6)
DocumentGeoTrust Certification Practice Statement, Version 1.0 (January 31, 2008)
DocumentOther documents
Requested Trust Bits
  • Websites
Bugs Authorisation (407168), Inclusion (424169), EV (424171)
CommentsNote that for compatibility reasons GeoTrust has implemented a cross-signing scheme involving this CA. In this scheme, if applications not supporting EV functionality (e.g., Firefox 2 and earlier) encounter GeoTrust EV certificates then they will end up treating this CA as a subordinate CA under the existing Equifax Secure CA root.


GlobalSign

GlobalSign is a commercial CA based in Portsmouth NH and serving customers worldwide.

Audit: WebTrust, performed by Deloitte (Denmark): Audit Report and Management's Assertions

Audit: WebTrust, performed by Ernst & Young: Report of Independent Accountants and Assertion of Management

Audit: WebTrust EV, performed by Ernst & Young: Report of Independent Accountants and Assertion of Management

GlobalSign Root CA - R2

Root CA with one subordinate CA.

Link Download/Install
SHA175:E0:AB:B6:13:85:12:27:1C:04:F8:5F:DD:DE:38:E4:B7:24:2E:FE
Version3
Modulus (key length)2048
Valid From2006-12-15
Valid To2021-12-15
RevocationCRL, OCSP
TypeEV (policy OID 1.3.6.1.4.1.4146.1.1)
DocumentGlobalSign Certification Practice Statement, version 6.0
DocumentGlobalSign CA Certificate Policy, version 3.0
DocumentGlobalSign CP v2.1
DocumentGlobalSign CPS v5.3
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (367245), Inclusion (378163), EV (406796)
Commentsnone

GlobalSign Root CA

Root CA with two subordinate CAs.

Link Download/Install
SHA1B1:BC:96:8B:D4:F4:9D:62:2A:A8:9A:81:F2:15:01:52:A4:1D:82:9C
Version3
Modulus (key length)2048
Valid From1998-09-01
Valid To2028-01-28
RevocationCRL, OCSP
TypeDV, IV/OV, EV (policy OID 1.3.6.1.4.1.4146.1.1)
DocumentGlobalSign Certification Practice Statement, version 6.0
DocumentGlobalSign CA Certificate Policy, version 3.0
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (406794), Inclusion (449883), EV (446407)
CommentsNote that a version of this root CA certificate with the same public key but an earlier expiration date (2014-01-28) is already included in the Mozilla list. This request is to replace the older certificate with this certificate and then enable this CA certificate for EV.


Go Daddy

Go Daddy operates a commercial CA based in the US and serving customers worldwide.

Audit: WebTrust and WebTrust EV, performed by KPMG: Independent Accountants' Report

Valicert Class 2 Policy Validation Authority

Root CA certificate with a single subordinate CA issuing SSL certificates (DV, OV and EV), email certificates, and code signing certificates.

Link Download/Install
SHA131:7A:2A:D0:7F:2B:33:5E:F5:A1:C3:4E:4B:57:E8:B7:D8:F1:FC:A6
Version1
Modulus (key length)1024
Valid From1999-06-25
Valid To2019-06-25
RevocationCRL, OCSP
TypeDV, IV/OV, EV (policy OIDs 2.16.840.1.114413.1.7.23.3 and 2.16.840.1.114414.1.7.23.3)
DocumentStarfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (403437), Inclusion (418958), EV (403437)
CommentsBoth of the CA certificates below are cross-signed to the Valicert Class 2 Policy Validation Authority root for legacy support, so this root is configured to enable EV with both of the EV OIDs associated with the other certificates.

Go Daddy Class 2 CA

Root CA certificate with a single subordinate CA issuing SSL certificates (DV, OV and EV), email certificates, and code signing certificates.

Link Download/Install
SHA127:96:BA:E6:3F:18:01:E2:77:26:1B:A0:D7:77:70:02:8F:20:EE:E4
Version3
Modulus (key length)2048
Valid From2004-06-29
Valid To2034-06-29
RevocationCRL, OCSP
TypeDV, IV/OV, EV (policy OID 2.16.840.1.114413.1.7.23.3)
DocumentStarfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (403437), Inclusion (418958), EV (403437)
Commentsnone

Starfield Class 2 CA

Root CA certificate with a single subordinate CA issuing SSL certificates (DV, OV and EV), email certificates, and code signing certificates.

Link Download/Install
SHA1AD:7E:1C:28:B0:64:EF:8F:60:03:40:20:14:C3:D0:E3:37:0E:B5:8A
Version3
Modulus (key length)2048
Valid From2004-06-29
Valid To2034-06-29
RevocationCRL, OCSP
TypeDV, IV/OV, EV (policy OID 2.16.840.1.114414.1.7.23.3)
DocumentStarfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (403437), Inclusion (418958), EV (403437)
Commentsnone


IdenTrust

IdenTrust is a for-profit corporation serving the private, commercial and government sectors.

Audit: WebTrust, performed by Ernst and Young: Audit Report and Management's Assertions

DST Root CA X3

Link Download/Install
SHA1DA:C9:02:4F:54:D8:F6:DF:94:93:5F:B1:73:26:38:CA:6A:D7:7C:13
Version3
Modulus (key length)2048
Valid From2000-09-30
Valid To2021-09-30
RevocationCRL, OCSP
TypeDV
DocumentTrustID CP v1.3.1
DocumentIdenTrust CPS v2.2
Requested Trust Bits
  • Websites
Bugs Authorisation (359069), Inclusion (394733)
Commentsnone

DST ACES CA X6

Link Download/Install
SHA140:54:DA:6F:1C:3F:40:74:AC:ED:0F:EC:CD:DB:79:D1:53:FB:90:1D
Version3
Modulus (key length)2048
Valid From2003-11-20
Valid To2017-11-20
RevocationCRL, OCSP
TypeDV
DocumentCertificate Policy v20040506_1
DocumentCertificate Practice Statement v4.1
Requested Trust Bits
  • Websites
Bugs Authorisation (359069), Inclusion (394733)
Commentsnone


Keynectis/Certplus

Keynectis is a French company, created by merging 2 previous French certification operators, Certplus and PK7.

Audit: ETSI TS 101.456, performed by LSTI - La Sécurité des Technologies de l'Information: ETSI Certificate

Certplus Class 2 Primary CA

Link Download/Install
SHA174:20:74:41:72:9C:DD:92:EC:79:31:D8:23:10:8D:C2:81:92:E2:BB
Version3
Modulus (key length)2048
Valid From1999-07-07
Valid To2019-07-06
RevocationCRL
TypeDV
DocumentRoot CA Certification Policy for SSL Services
DocumentDeclaration des Pratiques de Certification (CPS)
Requested Trust Bits
  • Websites
  • Email
Bugs Authorisation (335392), Inclusion (379032)
Inclusion Date2007-06-05
Commentsnone


Microsec

Microsec Ltd. is a Hungarian certificate authority.

Audit: Government, performed by Hungarian Government National Communications Authority: Authority statement

Microsec e-Szigno Root CA

Link Download/Install
SHA123:88:C9:D3:71:CC:9E:96:3D:FF:7D:3C:A7:CE:fC:D6:25:EC:19:0D
Version3
Modulus (key length)2048
Valid From2005-04-06
Valid To2017-04-06
RevocationCRL for this root, List of CRLs
TypeOV
DocumentCertificate Hierarchy in English
DocumentCPS in English
DocumentQualified Certificate CPS
DocumentETSI TS 101.456, QCP public CP
DocumentETSI TS 101.456, SSCD CP
DocumentNon-qualified Certificates CPS (electronic signatures)
DocumentETSI TS 102.042, NCP+ CP
DocumentETSI TS 102.042, NCP CP
DocumentETSI TS 102.042, NCP and ETSI TS 102.042, LCP CP
DocumentNon-qualified Certificates CPS (other uses)
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (370505), Inclusion (483852)
Commentsnone


Network Solutions

Network Solutions is a US-based commercial CA with worldwide customer base.

Audit: WebTrust for CAs, performed by KPMG: Audit Report and Management's Assertions

Audit: WebTrust EV, performed by KPMG: Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria

Network Solutions Certificate Authority

This CA has a subordinate CA, Network Solutions EV SSL CA, which issues Extended Validation certificates for SSL-enabled servers. At present there are no other subordinate CAs under this root; however in the future Network Solutions may establish additional subordinate CAs to issue non-EV certificates..

Link Download/Install
SHA174:F8:A3:C3:EF:E7:B3:90:06:4B:83:90:3C:21:64:60:20:E5:DF:CE
Version3
Modulus (key length)2048
Valid From2006-12-01
Valid To2029-12-31
RevocationCRL
TypeIV/OV, EV (policy OID 1.3.6.1.4.1.782.1.2.1.8.1)
DocumentNetwork Solutions Certification Practice Statement, Version 1.4.1
DocumentCertification Practice Statement (CPS) for Extended Validation (EV) Certification, Version 1.1
Requested Trust Bits
  • Websites
Bugs Authorisation (403915), Inclusion (431381), EV (431384)
Commentsnone


QuoVadis

QuoVadis is a commercial CA, based in Bermuda and operating globally. QuoVadis is a Qualified Certification Services Provider in Switzerland.

Audit: WebTrust, performed by Ernst & Young (Technology and Security Risk Services): Audit Report and Management's Assertions

Audit: ETSI TS 101.456, performed by KPMG: Swiss Accreditation Service statement

QuoVadis Root CA 2

This root will be used for SSL/device certificates, including standard "organisation validated" certificates as well as EV certificates.

Link Download/Install
SHA1CA:3A:FB:CF:12:40:36:4B:44:B2:16:20:88:80:48:39:19:93:7C:F7
Version3
Modulus (key length)4096
Valid From2006-11-24
Valid To2031-11-24
RevocationCRL, OCSP
TypeOV, EV
DocumentQuoVadis Root CA2 CP/CPS v1.7
DocumentQuoVadis Root CA2 CP/CPS v1.7
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (365281), Inclusion (378161)
Inclusion Date2007-06-05
Commentsnone

QuoVadis Root CA 3

This root will operate under a similar CP/CPS to our existing "qualified" Root CA 1, primarily used for end user certificates.

Link Download/Install
SHA11F:49:14:F7:D8:74:95:1D:DD:AE:02:C0:BE:FD:3A:2D:82:75:51:85
Version3
Modulus (key length)4096
Valid From2006-11-24
Valid To2031-11-24
RevocationCRL, OCSP
TypeOV
DocumentQuoVadis Root CA CP/CPS 4.3
DocumentQuoVadis Root CA CP/CPS 4.3
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (365281), Inclusion (378161)
Inclusion Date2007-06-05
Commentsnone


SECOM Trust

SECOM Trust Services Co., Ltd are a commercial CA based in Japan.

Audit: WebTrust, performed by PricewaterhouseCoopers Aarata: Report of Independent Certified Public Accountant

Audit: WebTrust EV, performed by KPMG: Audit Report and Management's Assertion

Security Communication EV RootCA1

This request is to add a newly constructed EV root to the NSS database. Note that there is currently a non-EV CA called Security Communication RootCA1 in the NSS database.

Link Download/Install
SHA1FE:B8:C4:32:DC:F9:76:9A:CE:AE:3D:D8:90:8F:FD:28:86:65:64:7D
Version3
Modulus (key length)2048
Valid From2007-06-06
Valid To2037-06-06
RevocationCRL
TypeEV (policy OID 1.2.392.200091.100.721.1)
DocumentSecurity Communication EV RootCA1 Certification Practice Statement, Version 1.00 (Japanese)
DocumentSecurity Communication EV RootCA1 Subordinate CA Certificate Policy, Version 1.00 (Japanese)
Requested Trust Bits
  • Websites
Bugs Authorisation (394419), Inclusion (477134), EV (477145)
Commentsnone


StartCom

StartCom is a commercial corporation with customers worldwide, and is the producer and vendor of the StartCom Linux operating systems, operates the StartCom Certification Authority and MediaHost.

Audit: WebTrust CA, performed by Ernst and Young: Audit Report and Management's Assertions

Audit: WebTrust EV, performed by Ernst and Young: Audit Report and Management's Assertions

StartCom Certification Authority

Link Download/Install
SHA13E:2B:F7:F2:03:1B:96:F3:8C:E6:C4:D8:A8:5D:3E:2D:58:47:6A:0F
Version3
Modulus (key length)4096
Valid From2006-09-17
Valid To2036-09-17
RevocationCRL, OCSP
TypeDV, OV, EV (policy OID 1.3.6.1.4.1.23223.2)
DocumentStartCom Certification Authority Policy and Practice Statements
DocumentStartCom Certification Authority Extended Validation Certificates Policy Appendix
DocumentIndex of Certs
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (362304), Inclusion (383722), EV (490492)
Inclusion Date2007-06-15
Commentsnone


S-TRUST

Deutscher Sparkassen Verlag GmbH is the world's largest smartcard provider and the central certification service provider for all German savings banks. This CA exists to enable up to 40 million German customers (end-users) to use their banking card as a certificate based signature, encryption and authentication device.

Audit: ETSI TS 101.456, performed by TÜV-IT: ETSI TS 101.456 Certificate

Audit: ETSI TS 102.042, performed by TÜV-IT: ETSI TS 102.042 Certificate

S-TRUST Authentication and Encryption Root CA 2005:PN

This root will provide all customers of the German Savings Bank Financial Group with client certificates for their signature-enabled debit cards (smartcards).

Link Download/Install
SHA1BE:B5:A9:95:74:6B:9E:DF:73:8B:56:E6:DF:43:7A:77:BE:10:6B:81
Version3
Modulus (key length)2048
Valid From2005-06-21
Valid To2030-06-21
RevocationCRL, OCSP
TypeIV
DocumentCertification Practice Statement for the S-TRUST Network
Requested Trust Bits
  • Email
Bugs Authorisation (370627), Inclusion (478573)
Commentsnone


SwissSign

SwissSign AG is a commercial CSP that provides certification services for individual and corporate customers. SwissSign operates the certificate authority for the Swiss Post and is mostly focused on Switzerland but Registration Services may be used internationally. The "Platinum G2" Root CA currently has 3 subordinate CAs, the "Gold G2" Root CA has 2 and the "Silver G2" Root CA has 3.

Audit: ETSI TS 101.456, performed by KPMG: Swiss Accreditation Service Certified Bodies List, SAS details for SwissSign

Audit: WebTrust EV, performed by KPMG: Confirmation Notice of WebTrust EV Audit

SwissSign Platinum CA - G2

The SwissSign Platinum CA - G2 root has three subordinate CAs. The SwissSign Qualified Platinum CA - G2 issues "qualified" certificates according to Swiss digital signature law (ZertES). The SwissSign Personal Platinum CA - G2 issues certificates for natural persons and organizations. The Swiss Post Platinum CA - G2 issues the "Postzertifikat", a product of the Swiss Post. (Note that each of the subordinate CAs has its own CP/CPS separate from the CP/CPS of the root.) The Platinum CAs require that keys be generated on Secure Signature Creation Devices (SSCDs); since such devices are not used with servers, this hierarchy is enabled for email and object signing uses only.

Link Download/Install
SHA156:E0:FA:C0:3B:8F:18:23:55:18:E5:D3:11:CA:E8:C2:43:31:AB:66
Version3
Modulus (key length)4096
Valid From2006-10-25
Valid To2036-10-25
RevocationCRL, OCSP
TypeIV
DocumentSwissSign Platinum Root CP/CPS
DocumentSwissSign Qualified Platinum CP/CPS
DocumentSwissSign Personal Platinum CP/CPS
DocumentSwiss Post Platinum CP/CPS
Requested Trust Bits
  • Email
  • Code
Bugs Authorisation (343756), Inclusion (407396)
Commentsnone

SwissSign Gold CA - G2

The "Gold G2" root CA currently has two subordinate CAs: "Personal" issues certificates for natural persons and organizations, while "Server" issues certificates for systems. This root CA may also operate other customer-specific Issuing CAs if and only if they fully comply with all the stipulations of the "Gold G2" CP/CPS.

Link Download/Install
SHA1D8:C5:38:8A:B7:30:1B:1B:6E:D4:7A:E6:45:25:3A:6F:9F:1A:27:61
Version3
Modulus (key length)4096
Valid From2006-10-25
Valid To2036-10-25
RevocationCRL, OCSP
TypeIV, OV, EV (policy OID 2.16.756.1.89.1.2.1.1)
DocumentSwissSign Gold CP/CPS R4
DocumentEnd User Agreement R4
DocumentSwissSign Document Repository
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (343756), Inclusion (407396), EV (492077)
Commentsnone

SwissSign Silver CA - G2

The "Silver G2" root CA currently has three subordinate CAs: "Personal" issues certificates for natural persons and organizations, "Server" issues certificates for systems, and "Switch" is operated for a customer that issues certificates for the academic community

Link Download/Install
SHA19B:AA:E5:9F:56:EE:21:CB:43:5A:BE:25:93:DF:A7:F0:40:D1:1D:CB
Version3
Modulus (key length)4096
Valid From2006-10-25
Valid To2036-10-25
RevocationCRL, OCSP
TypeIV
DocumentSwissSign Silver CP/CPS
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (343756), Inclusion (407396)
Commentsnone


TC TrustCenter

TC TrustCenter GmbH is a commercial company based in Germany, with customers in all major regions of the world. TC TrustCenter offers a variety of products and services including SSL Server certificates and Email certificates.

Audit: ETSI 102.042, performed by TÜV-IT Germany: ETSI TS 102.042 LCP Certificate

TC TrustCenter Class 2 CA II

This root has two internally-operated subordinate CAs which issue certificates for SSL, email, and code signing. This root also has an externally-operated subordinate CA which is used to issue device certificates and email certificates for internal use only. The device name and the email address belong to a company internal domain, so the ownership is guaranteed.

Link Download/Install
SHA1AE:50:83:ED:7C:F4:5C:BC:8F:61:C6:21:FE:68:5D:79:42:21:15:6E
Version3
Modulus (key length)2048
Valid From2006-01-12
Valid To2025-12-31
RevocationCRL, OCSP
TypeOV
DocumentHierarchy Diagram
DocumentTC TrustCenter GmbH Certification Practice Statement (CPS)
DocumentTC TrustCenter Certificate Policy Definitions (CPD)
DocumentTC TrustCenter CA Certificates
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (392024), Inclusion (486759)
Commentsnone

TC TrustCenter Class 3 CA II

This root has one internally-operated subordinate CA which issues certificates for SSL, email, and code signing.

Link Download/Install
SHA180:25:EF:F4:6E:70:C8:D4:72:24:65:84:FE:40:3B:8A:8D:6A:DB:F5
Version3
Modulus (key length)2048
Valid From2006-01-12
Valid To2025-12-31
RevocationCRL, OCSP
TypeOV
DocumentHierarchy Diagram
DocumentTC TrustCenter GmbH Certification Practice Statement (CPS)
DocumentTC TrustCenter Certificate Policy Definitions (CPD)
DocumentTC TrustCenter CA Certificates
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (392024), Inclusion (486759)
Commentsnone

TC TrustCenter Universal CA I

This root has been introduced to reduce the number of root certificates in the trusted root stores. This root will have internally-operated subordinate CAs for each registration strength. “Class 1”, “Class 2”, “Class 3” and “Class 4” represent the registration strength. This root currently has one Class 3 subordinate CA. Over time this root will have more “TC Class x” subordinate CA certificates.

Link Download/Install
SHA16B:2F:34:AD:89:58:BE:62:FD:B0:6B:5C:CE:BB:9D:D9:4F:4E:39:F3
Version3
Modulus (key length)2048
Valid From2006-03-22
Valid To2025-12-31
RevocationCRL, OCSP
TypeOV
DocumentHierarchy Diagram
DocumentTC TrustCenter GmbH Certification Practice Statement (CPS)
DocumentTC TrustCenter Certificate Policy Definitions (CPD)
DocumentTC TrustCenter CA Certificates
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (392024), Inclusion (486759)
Commentsnone


thawte

thawte is a commercial CA with worldwide operations and customer base; it is a subsidiary of VeriSign, Inc.

Audit: WebTrust/WebTrust EV, performed by KPMG: Audit Report and Management's Assertions

thawte Primary Root CA

This CA issues a CA certificate to the subordinate CAs thawte Extended Validation SSL CA and thawte Extended Validation SSL SGC CA, which in turn issue Extended Validation certificates for SSL-enabled servers.

Link Download/Install
SHA191:C6:D6:EE:3E:8A:C8:63:84:E5:48:C2:99:29:5C:75:6C:81:7B:81
Version3
Modulus (key length)2048
Valid From2006-11-17
Valid To2036-07-16
RevocationCRL, OCSP
TypeEV (policy OID 2.16.840.1.113733.1.7.48.1)
Documentthawte Certification Practice Statement, Version 3.5 (January 2008)
Requested Trust Bits
  • Websites
Bugs Authorisation (407163), Inclusion (424152), EV (424154)
CommentsNote that for compatibility reasons thawte has implemented a cross-signing scheme involving this CA. In this scheme, if applications not supporting EV functionality (e.g., Firefox 2 and earlier) encounter thawte EV certificates then they will end up treating this CA as a subordinate CA under the existing Thawte Premium Server CA root.


Trustwave

Trustwave is a commercial CA serving customers worldwide; it includes the former SecureTrust and XRamp CAs. At this time there are no subordinate CAs for any of these roots; instead end entity certificates are issued directly from the roots as noted below, with different classes of certificates under different certificate policies. Note that each root CA is not associated with a single CPS, rather end entity certs are associated with policies that link to the CPS that the certificate was issued under: an EV CPS, an OV CPS, etc.

Audit: WebTrust and WebTrust EV, performed by Boysen & Miller PLLC: Audit Report and Management's Assertions

SecureTrust CA

Root CA certificate utilized for issuing SSL certificates (OV and EV) and code signing certificates.

Link Download/Install
SHA187:82:C6:C3:04:35:3B:CF:D2:96:92:D2:59:3E:7D:44:D9:34:FF:11
Version3
Modulus (key length)2048
Valid From2006-11-07
Valid To2029-12-31
RevocationCRL
TypeIV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)
DocumentSecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1
DocumentSecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1
DocumentSecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0
Requested Trust Bits
  • Websites
  • Code
Bugs Authorisation (409837), Inclusion (418907), EV (418910)
Commentsnone

Secure Global CA

Root CA certificate utilized for issuing SSL certificates (OV and EV), S/MIME certificates, and (in future) code signing certificates.

Link Download/Install
SHA13A:44:73:5A:E5:81:90:1F:24:86:61:46:1E:3B:9C:C4:5F:F5:3A:1B
Version3
Modulus (key length)2048
Valid From2006-11-07
Valid To2029-12-31
RevocationCRL
TypeIV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)
DocumentSecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1
DocumentSecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1
DocumentSecureTrust Certification Practice Statement for S/MIME Certificates, Version 1.6.0
DocumentSecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (409838), Inclusion (418907), EV (418910)
Commentsnone

XRamp Global CA

Root CA certificate utilized for issuing SSL certificates (OV and EV), S/MIME certificates, and code signing certificates.

Link Download/Install
SHA1B8:01:86:D1:EB:9C:86:A5:41:04:CF:30:54:F3:4C:52:B7:E5:58:C6
Version3
Modulus (key length)2048
Valid From2004-11-01
Valid To2035-01-01
RevocationCRL
TypeIV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)
DocumentSecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1
DocumentSecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1
DocumentSecureTrust Certification Practice Statement for S/MIME Certificates, Version 1.6.0
DocumentSecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (409840), EV (418902)
CommentsNote that this root CA certificate is already included in the Mozilla list. The present request is to enable this CA certificate for EV.


T-Systems

T-Systems is a wholly-owned subsidiary of Deutsche Telekom AG.

Audit: WebTrust, performed by Ernst and Young: Audit Report and Management's Assertions

Audit: ETSI 101.456, performed by T-Systems GEI: ETSI 101.456 Certificate of Compliance

Deutsche Telekom Root CA 2

Link Download/Install
SHA185:A4:08:C0:9C:19:3E:5D:51:58:7D:CD:D6:13:30:FD:8C:DE:37:BF
Version3
Modulus (key length)2048
Valid From1999-07-09
Valid To2019-07-10
RevocationCRL
TypeOV
DocumentCPS (German)
DocumentCP (German)
DocumentService Description (German)
DocumentCPS (English)
Document CP (English)
DocumentService Description (English)
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (378882), Inclusion (487647)
Commentsnone


TURKTRUST

TÜRKTRUST is a Turkish CA issuing qualified certificates in Turkey.

Audit: ETSI TS 101.456, performed by Turkish Telecommunications Authority: Letter of Official CA Statement, List of accredited CAs, Audit statement on auditor website

TURKTRUST Certificate Services Provider Root 1

Root 1 is a "legacy" root included for compatibility with previously-issued certificates. The English version of the CPS applies to both roots.

Link Download/Install
SHA179:98:A3:08:E1:4D:65:85:E6:C2:1E:15:3A:71:9F:BA:5A:D3:4A:D9
Version3
Modulus (key length)2048
Valid From2005-05-13
Valid To2015-03-22
RevocationCRL, CRL, CRL, OCSP
TypeDV, IV
DocumentCPS v03 (English)
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (380635), Inclusion (410821)
Commentsnone

TURKTRUST Certificate Services Provider Root 2

Root 2 is the new root that replaced Root 1; Root 2 is used for certificates currently being issued. The English version of the CPS applies to both roots.

Link Download/Install
SHA1B4:35:D4:E1:11:9D:1C:66:90:A7:49:EB:B3:94:BD:63:7B:A7:82:B7
Version3
Modulus (key length)2048
Valid From2005-07-11
Valid To2015-09-16
RevocationCRL, CRL, CRL, OCSP
TypeDV, IV
DocumentCPS v03 (English)
Requested Trust Bits
  • Websites
  • Email
  • Code
Bugs Authorisation (380635), Inclusion (410821)
Commentsnone


VeriSign

VeriSign is a major commercial CA with worldwide operations and customer base.

Audit: WebTrust, performed by KPMG: Audit Report and Management's Assertions

Audit: WebTrust EV, performed by KPMG: CA-supplied auditor's letter re WebTrust EV audit

VeriSign Class 3 Public Primary Certification Authority - G5

This CA issues a CA certificate to the subordinate CA "VeriSign Class 3 Extended Validation SSL SGC CA", which in turn issues Extended Validation certificates for SSL-enabled servers.

Link Download/Install
SHA14E:B6:D5:78:49:9B:1C:CF:5F:58:1E:AD:56:BE:3D:9B:67:44:A5:E5
Version3
Modulus (key length)2048
Valid From2006-11-07
Valid To2036-07-16
RevocationCRL, OCSP
TypeEV (policy OID 2.16.840.1.113733.1.7.23.6)
DocumentVeriSign Certification Practice Statement, Version 3.5
DocumentVeriSign Trust Network Certificate Policies, Version 2.5
Requested Trust Bits
  • Websites
Bugs Authorisation (402947), Inclusion (422918)
CommentsNote that for compatibility reasons VeriSign has implemented a cross-signing scheme involving this CA. In this scheme, if applications not supporting EV functionality (e.g., Firefox 2 and earlier) encounter VeriSign EV certificates then they will end up treating this CA as a subordinate CA under the existing VeriSign Class 3 Public Primary CA root.


Verizon / Cybertrust

Verizon Business Security Solutions Powered by Cybertrust operates a commercial certificate authority service for businesses and governments internationally.

Audit: WebTrust CA, performed by Ernst and Young: Audit Report and Management's Assertions

Audit: WebTrust EV, performed by Ernst and Young: Audit Report and Management's Assertions

Cybertrust Global Root

This root was created to provide a service to customers desiring a root based outside the United States. Relying on the GTE CyberTrust Global Root for ubiquity through cross-certification, this root is used for issuance of EV SSL certificates. There is currently only one internally-operated subordinate CA called Cybertrust SureServer EV CA. The CPS allows for this root to have other subordinate CAs in the future. The sub-CAs are required to follow the CPS and to have regular audits.

Link Download/Install
SHA15f:43:e5:b1:bf:f8:78:8c:ac:1c:c7:ca:4a:9a:c6:22:2b:cc:34:c6
Version3
Modulus (key length)2048
Valid From2006-12-15
Valid To2021-12-15
RevocationCRL
TypeEV (policy OID 1.3.6.1.4.1.6334.1.100.1)
Document Cybertrust CA Certificate Policy
Document Certification Practice Statement
Requested Trust Bits
  • Websites
Bugs Authorisation (430700), Inclusion (493258), EV (493259)
Commentsnone


Wells Fargo

Wells Fargo is a public CA based in San Francisco, California, and serving customers worldwide. This EV CA was created for the purpose of creating an online/intermediate EV SSL issuing authority which will be managed internally, and follow the WellsSecure CPS.

Audit: WebTrust EV pre-audit, performed by KPMG: Audit Report and Management's Assertions

Audit: WebTrust CA, performed by KPMG: Audit Report and Management's Assertions

WellsSecure Public Root Certificate Authority

Root CA with one internal subordinate CA issuing EV SSL certificates.

Link Download/Install
SHA1e7:b4:f6:9d:61:ec:90:69:db:7e:90:a7:40:1a:3c:f4:7d:4f:e8:ee
Version3
Modulus (key length)2048
Valid From2007-12-13
Valid To2022-12-13
RevocationCRL, OCSP
TypeEV (policy OID 2.16.840.1.114171.500.9)
Document WellsSecure PKI Certificate Policy
Requested Trust Bits
  • Websites
Bugs Authorisation (428390), Inclusion (449393), EV (449394)
Commentsnone


WISeKey

WISeKey operates the CertifyID Trust Service, which supports customer-specific CAs under a CA hierarchy rooted at the WISeKey Global Root GA CA and containing Policy CAs (subordinate to the root) and Issuing CAs (subordinate to the Policy CAs). Note that all end-entity certificates are issued by the Issuing CAs under policies set by WISeKey.

Audit: WebTrust, performed by WTE y E. Álvarez Auditores, S.L.: Audit Report and Management's Assertions

Audit: WebTrust, performed by WTE y E. Álvarez Auditores, S.L.: 2008 Audit Report and Management's Assertions

OISTE WISeKey Global Root GA CA

As noted above, the Global Root GA CA is the one and only root for the entire CertifyID system. It issues CA certificates to Policy CAs, which in turn issue CA certificates to Issuing CAs. There are three types of Policy CAs (Standard, Advanced, and Qualified) and three types of Issuing CAs corresponding to these, each issuing a different class of certificates; verification requirements for applicants vary by class.

Link Download/Install
SHA159:22:A1:E1:5A:EA:16:35:21:F8:98:39:6A:46:46:B0:44:1B:0F:A9
Version3
Modulus (key length)2048
Valid From2005-12-11
Valid To2037-12-11
RevocationCRL
TypeIV
DocumentOISTE WISeKey Root CPS 1.01
DocumentCertifyID Identity Validation Overview, Version 1.0
DocumentTechnical Security Controls WD0011 - Version 1.0.1
DocumentTable comparing the three different classes of end-entity certificates issued by Issuing CAs.
Requested Trust Bits
  • Websites
  • Email
Bugs Authorisation (371362), Inclusion (467138)
Commentsnone

Note that the CPS for the root CA addresses only procedures related to issuance of certificates for its subordinate CAs. Issues related to issuance of end entity certificates are addressed in the other two documents references, in particular the CPS for the Advanced Services Issuing CA.

Copyright © 1997-2010 adgrafics ®

Український центр сертифікації сайтів та верифікації компаній компаний ВЕБТРАСТ Україна докладніше...
издатель: Українский сертификаційний центр Адграфікс Хмельницький Україна тематика: Trusted Root certificates, Корневые сертификаты, Кореневі сертифікати, Забезпечення безпеки передачі даних і фінансових транзакцій шляхом ssl, Встановлення SSL сертифікатів на сервер, Забезпечення безпеки передачі даних і фінансових транзакцій, trustedrootcertificates.com Кореневі сертифікати trustedrootcertificates.com. ssl сертифікати, SAN SSL сертифікати, сертифікати для сайта, SSL захист, ssl провайдер,
Створення приватного ключа | Центр сертифікації відкритих ключів Digicert | SSL сертифікат для інтернет-бізнеса | Thawte Wildcard сертифікати | SSL для ВЕБ | Умови використання сертифікатів Networksolutions | Сервіс Посвідчення документів GlobalSign | Довідка: Центр Посвідчення