Zde můžete vidět rozdíly mezi vybranou verzí a aktuální verzí dané stránky.
Obě strany předchozí revize Předchozí verze Následující verze | Předchozí verze Následující verze Obě strany příští revize | ||
en:ch-tcs-crt-crl.html [2014/10/24 12:27] bozon@cesnet.cz TERENA SSL CA 2 |
en:ch-tcs-crt-crl.html [2015/06/02 18:14] bozon@cesnet.cz DigiCert |
||
---|---|---|---|
Řádek 1: | Řádek 1: | ||
- | ====== Root Certificates and Revocation Lists ====== | + | ====== TCS Server certificates ====== |
- | Here you can find descriptions, certificates and revocation lists for Certificate Authorities providing the service CESNET TCS Server. | + | You can get your server certificate on [[https://tcs.cesnet.cz/|https://tcs.cesnet.cz/]]. |
- | ===== AddTrust External CA Root ===== | + | ===== New CA Root - DigiCert ===== |
- | ^ CA name | CN=**AddTrust External CA Root**, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | On July 1<sup>st</sup> 2015 there will be a new supplier of TCS certificates - DigiCert company. After this date, the certificates will be issued under this root only. |
- | ^ Issued by | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | |
- | ^ Validity | since May 30<sup>th</sup> 2000 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | 1D:35:54:04:85:78:B0:3F:42:42:4D:BF:20:73:0A:3F || | + | |
- | ^ Fingerprint SHA1 | 02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68 || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/AddTrust_External_Root.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/AddTrust_External_Root.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.comodoca.com/AddTrustExternalCARoot.crl|Download]] || | + | |
- | ===== UTN-USERFirst-Hardware ===== | + | * [[en:ch-tcs-ssl-ca-3-crt-crl.html|New server certificates - chain a CRL]] |
+ | * [[en:ch-tcs-esci-ssl-ca-3-crt-crl.html|New grid server certificates - chain a CRL]] | ||
- | ^ CA name | CN=**UTN-USERFirst-Hardware**, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, ST=UT, C=US || | + | ===== Comodo ===== |
- | ^ Issued by | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | |
- | ^ Validity | since June 7<sup>th</sup> 2005 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | 73:BE:83:E2:0B:42:A2:69:3B:50:0D:70:0C:14:94:D3 || | + | |
- | ^ Fingerprint SHA1 | 3D:4B:2A:4C:64:31:71:43:F5:02:58:D7:E6:FD:7D:3C:02:1A:52:9E || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/UTN_USERFirst_Hardware_Root_CA.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/UTN_USERFirst_Hardware_Root_CA.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.usertrust.com/UTN-USERFirst-Hardware.crl|Download]] || | + | |
- | ===== USERTrust RSA Certification Authority ===== | + | From the reasons specified above, it will be no longer possible to issue new TCS certificates under the old Comodo root after 2015-07-01. Existing certificates remain valid (until the expiration or revocation). |
- | ^ CA name | CN=**USERTrust RSA Certification Authority**, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US || | + | * [[en:ch-tcs-ssl-ca-2-crt-crl.html|Normal server certificates - chain and CRL]] |
- | ^ Issued by | CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE || | + | * [[en:ch-tcs-esci-ssl-ca-2-crt-crl.html|Grid server certificates - chain and CRL]] |
- | ^ Validity | since May 30<sup>th</sup> 2000 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | DB:78:CB:D1:90:95:27:35:D9:40:BC:80:AC:24:32:C0 || | + | |
- | ^ Fingerprint SHA1 | EA:B0:40:68:9A:0D:80:5B:5D:6F:D6:54:FC:16:8C:FF:00:B7:8B:E3 || | + | |
- | ^ Fingerprint SHA256 | 1A:51:74:98:0A:29:4A:52:8A:11:07:26:D5:85:56:50:26:6C:48:D9:88:3B:EA:69:2B:67:B6:D7:26:DA:98:C5 || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/USERTrust_RSA_Certification_Authority.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/USERTrust_RSA_Certification_Authority.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl|Download]] || | + | |
- | ===== TERENA SSL CA ===== | + | ==== Certificates with SHA1 ==== |
- | ^ CA name | CN=**TERENA SSL CA**, O=TERENA, C=NL || | + | TCS certificate portal can't issue the SHA1 certificates nowadays. If you are sure you want a SHA1 certificate, please contact us at <tcs-ra@cesnet.cz>. Certification chains for SHA1 certificates remained the same. Certification chains and CRLs are below. |
- | ^ Issued by | CN=UTN-USERFirst-Hardware, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, ST=UT, C=US || | + | |
- | ^ Validity | since May 18<sup>th</sup> 2009 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | F6:2C:D1:54:6A:8E:F1:4E:31:BA:1C:E8:EE:CD:23:4A || | + | |
- | ^ Fingerprint SHA1 | 3A:88:17:64:47:2B:64:41:DD:B3:AF:DD:47:C6:B8:B7:6E:E7:BA:1D || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.tcs.terena.org/TERENASSLCA.crl|Download]] || | + | |
- | ===== TERENA SSL CA 2 ===== | + | * [[en:ch-tcs-ssl-ca-crt-crl.html|Normal server certificates with SHA1 - chain and CRL]] |
- | + | * [[en:ch-tcs-esci-ssl-ca-crt-crl.html|Grid server certificates with SHA1 - chain and CRL]] | |
- | ^ CA name | CN=**TERENA SSL CA 2**, O=TERENA, L=Amsterdam, ST=Noord-Holland, C=NL || | + | |
- | ^ Issued by | CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US || | + | |
- | ^ Validity | since October 9<sup>th</sup> 2014 | until October 8<sup>th</sup> 2024 | | + | |
- | ^ Fingerprint MD5 | BB:32:B8:80:29:A6:8C:E1:E5:9C:21:80:CF:EF:0F:5C || | + | |
- | ^ Fingerprint SHA1 | 38:52:5C:71:40:D2:85:04:0E:02:DD:2A:7F:3C:7D:BA:21:04:2E:01 || | + | |
- | ^ Fingerprint SHA256 | 2F:F1:83:2D:E6:F9:50:6A:AC:9D:2C:77:57:EA:07:57:64:EC:68:CC:9C:70:A0:EC:E3:3E:CC:61:60:7C:BE:43 || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA_2.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/TERENA_SSL_CA_2.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.tcs.terena.org/TERENASSLCA2.crl|Download]] || | + | |
- | + | ||
- | ===== TERENA eScience SSL CA ===== | + | |
- | + | ||
- | ^ CA name | CN=**TERENA eScience SSL CA**, O=TERENA, C=NL || | + | |
- | ^ Issued by | CN=UTN-USERFirst-Hardware, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, ST=UT, C=US || | + | |
- | ^ Validity | since May 18<sup>th</sup> 2009 | until May 30<sup>th</sup> 2020 | | + | |
- | ^ Fingerprint MD5 | 5F:EE:A3:5A:B0:1A:37:3F:11:52:19:70:6F:1F:57:BD || | + | |
- | ^ Fingerprint SHA1 | 93:BF:A8:70:C2:17:83:F9:16:6C:34:1D:FB:7E:01:86:F6:A0:31:3D || | + | |
- | ^ CA certificate | [[http://pki.cesnet.cz/certs/TERENA_eScience_SSL_CA.crt|Install (DER)]] | [[http://pki.cesnet.cz/certs/TERENA_eScience_SSL_CA.pem|Download (PEM)]] | | + | |
- | ^ Current CRL | [[http://crl.tcs.terena.org/TERENAeScienceSSLCA.crl|Download]] || | + | |