Zde můžete vidět rozdíly mezi vybranou verzí a aktuální verzí dané stránky.
Obě strany předchozí revize Předchozí verze Následující verze | Předchozí verze Následující verze Obě strany příští revize | ||
en:ch-tcs-crt-crl.html [2014/10/24 12:27] bozon@cesnet.cz TERENA SSL CA 2 |
en:ch-tcs-crt-crl.html [2014/10/30 12:57] chvojka@cesnet.cz |
||
---|---|---|---|
Řádek 1: | Řádek 1: | ||
- | ====== Root Certificates and Revocation Lists ====== | + | ====== TCS Server certificates ====== |
- | Here you can find descriptions, certificates and revocation lists for Certificate Authorities providing the service CESNET TCS Server. | + | You can get your server certificate on [[https://tcs.cesnet.cz/|https://tcs.cesnet.cz/]]. |
- | ===== AddTrust External CA Root ===== | + | ===== We moved to SHA2 ===== |
- | ^ CA name | CN=**AddTrust External CA Root**, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | TCS server certificates, COMODO, started to issue SHA2 certificates. Root certificate and certificate chain remained the same. Only intermediate certificates has changed. If you know what SHA1 means and you are sure you want it, please read next chapter. |
- | ^ Issued by | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | |
- | ^ Validity | since May 30<sup>th</sup> 2000 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | 1D:35:54:04:85:78:B0:3F:42:42:4D:BF:20:73:0A:3F || | + | |
- | ^ Fingerprint SHA1 | 02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68 || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/AddTrust_External_Root.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/AddTrust_External_Root.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.comodoca.com/AddTrustExternalCARoot.crl|Download]] || | + | |
- | ===== UTN-USERFirst-Hardware ===== | + | * [[en:ch-tcs-ssl-ca-2-crt-crl.html|Normal server certificates - chain and CRL]] |
+ | * [[en:ch-tcs-esci-ssl-ca-2-crt-crl.html|Grid server certificates - chain and CRL]] | ||
- | ^ CA name | CN=**UTN-USERFirst-Hardware**, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, ST=UT, C=US || | + | ===== I want certificate with SHA1 ===== |
- | ^ Issued by | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | |
- | ^ Validity | since June 7<sup>th</sup> 2005 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | 73:BE:83:E2:0B:42:A2:69:3B:50:0D:70:0C:14:94:D3 || | + | |
- | ^ Fingerprint SHA1 | 3D:4B:2A:4C:64:31:71:43:F5:02:58:D7:E6:FD:7D:3C:02:1A:52:9E || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/UTN_USERFirst_Hardware_Root_CA.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/UTN_USERFirst_Hardware_Root_CA.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.usertrust.com/UTN-USERFirst-Hardware.crl|Download]] || | + | |
- | ===== USERTrust RSA Certification Authority ===== | + | TCS certificate portal can't issue the SHA1 certificates nowadays. If you are sure you want a SHA1 certificate, please contact us at <tcs-ra@cesnet.cz>. Certification chains for SHA1 certificates remained the same. Certification chains and CRLs are below. |
- | ^ CA name | CN=**USERTrust RSA Certification Authority**, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US || | + | * [[en:ch-tcs-ssl-ca-crt-crl.html|Normal server certificates with SHA1 - chain and CRL]] |
- | ^ Issued by | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | * [[en:ch-tcs-esci-ssl-ca-crt-crl.html|Grid server certificates with SHA1 - chain and CRL]] |
- | ^ Validity | since May 30<sup>th</sup> 2000 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | DB:78:CB:D1:90:95:27:35:D9:40:BC:80:AC:24:32:C0 || | + | |
- | ^ Fingerprint SHA1 | EA:B0:40:68:9A:0D:80:5B:5D:6F:D6:54:FC:16:8C:FF:00:B7:8B:E3 || | + | |
- | ^ Fingerprint SHA256 | 1A:51:74:98:0A:29:4A:52:8A:11:07:26:D5:85:56:50:26:6C:48:D9:88:3B:EA:69:2B:67:B6:D7:26:DA:98:C5 || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/USERTrust_RSA_Certification_Authority.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/USERTrust_RSA_Certification_Authority.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl|Download]] || | + | |
- | + | ||
- | ===== TERENA SSL CA ===== | + | |
- | + | ||
- | ^ CA name | CN=**TERENA SSL CA**, O=TERENA, C=NL || | + | |
- | ^ Issued by | CN=UTN-USERFirst-Hardware, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, ST=UT, C=US || | + | |
- | ^ Validity | since May 18<sup>th</sup> 2009 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | F6:2C:D1:54:6A:8E:F1:4E:31:BA:1C:E8:EE:CD:23:4A || | + | |
- | ^ Fingerprint SHA1 | 3A:88:17:64:47:2B:64:41:DD:B3:AF:DD:47:C6:B8:B7:6E:E7:BA:1D || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.tcs.terena.org/TERENASSLCA.crl|Download]] || | + | |
- | + | ||
- | ===== TERENA SSL CA 2 ===== | + | |
- | + | ||
- | ^ CA name | CN=**TERENA SSL CA 2**, O=TERENA, L=Amsterdam, ST=Noord-Holland, C=NL || | + | |
- | ^ Issued by | CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US || | + | |
- | ^ Validity | since October 9<sup>th</sup> 2014 | until October 8<sup>th</sup> 2024 | | + | |
- | ^ Fingerprint MD5 | BB:32:B8:80:29:A6:8C:E1:E5:9C:21:80:CF:EF:0F:5C || | + | |
- | ^ Fingerprint SHA1 | 38:52:5C:71:40:D2:85:04:0E:02:DD:2A:7F:3C:7D:BA:21:04:2E:01 || | + | |
- | ^ Fingerprint SHA256 | 2F:F1:83:2D:E6:F9:50:6A:AC:9D:2C:77:57:EA:07:57:64:EC:68:CC:9C:70:A0:EC:E3:3E:CC:61:60:7C:BE:43 || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA_2.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA_2.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.tcs.terena.org/TERENASSLCA2.crl|Download]] || | + | |
- | + | ||
- | ===== TERENA eScience SSL CA ===== | + | |
- | + | ||
- | ^ CA name | CN=**TERENA eScience SSL CA**, O=TERENA, C=NL || | + | |
- | ^ Issued by | CN=UTN-USERFirst-Hardware, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, ST=UT, C=US || | + | |
- | ^ Validity | since May 18<sup>th</sup> 2009 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | 5F:EE:A3:5A:B0:1A:37:3F:11:52:19:70:6F:1F:57:BD || | + | |
- | ^ Fingerprint SHA1 | 93:BF:A8:70:C2:17:83:F9:16:6C:34:1D:FB:7E:01:86:F6:A0:31:3D || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/TERENA_eScience_SSL_CA.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/TERENA_eScience_SSL_CA.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.tcs.terena.org/TERENAeScienceSSLCA.crl|Download]] || | + | |