Repository — trust anchors, revocation information and certificate policy
Private, closed-ecosystem certificate authority. Certificates issued by
this CA are trusted within the ECGrid ecosystem only. This CA holds no WebTrust or
CA/Browser Forum audit, and its root is not distributed in any browser or operating
system trust store. Relying parties install the root explicitly.
Not yet in service. This certificate authority has not been
commissioned. No root or issuing key exists yet, no certificate has been issued, and
no revocation list is published. This page is a reserved location; the trust anchors,
the Certificate Policy and Certification Practice Statement, and the certificate
profiles will be published here before the first certificate is issued.
What will be published here
Root CA certificate, with its SHA-256 fingerprint, for installation as a trust anchor
Issuing CA certificate and the full chain
Installation instructions per platform and per AS2 product
Certificate Policy and Certification Practice Statement, current and superseded versions
The certificate profile: key usage, extended key usage and validity periods
A contact for reporting a compromised private key or requesting revocation
Revocation
Revocation status will be published as a certificate revocation list at
http://crl.myas2.com/. That host is served over plain HTTP deliberately:
fetching a revocation list must not require validating a TLS chain, because that is
circular. No OCSP responder is provided, and certificates issued by this
CA carry no OCSP URL — do not configure OCSP checking against them.
Verifying what you download here
Any fingerprint published on this page travels over the same channel as the file it
describes, and therefore proves nothing on its own. Before installing a root
certificate as a trust anchor, confirm its fingerprint through an independent channel.
The channel will be named in the Certification Practice Statement.