# ------------------------------------------------------------------------------ # Extended Validation CA Policy OIDs # Last updated: 19 Aug 2014, MKC/KCM # # Each uncommented non-empty line contains a mapping from a CA-defined EV OID # to the certificate file(s) in ./roots which are authoritative for that OID. # These lines are processed by the buildEVRoots script to generate the plist. # # Actalis # source: , # confirmed by http://portal.actalis.it/cms/translations/en/actalis/Info/Solutions/Documents/ActalisCA_Audit_Statement.pdf # # (1.3.159.1.17.1) = 06062B811F011101 # # roots: Actalis Authentication Root CA.cer # 1.3.159.1.17.1 "Actalis Authentication Root CA.cer" # AffirmTrust # source: # confirmed by http://www.affirmtrust.com/images/AffirmTrust_CPS_v1.1_12-23-2010.pdf # # (1.3.6.1.4.1.34697.2.1) = # # roots: AffirmTrust-Commercial.der, AffirmTrust-Networking.der, AffirmTrust-Premium.der, AffirmTrust-Premium-ECC.der # 1.3.6.1.4.1.34697.2.1 "AffirmTrust-Commercial.der" 1.3.6.1.4.1.34697.2.2 "AffirmTrust-Networking.der" 1.3.6.1.4.1.34697.2.3 "AffirmTrust-Premium.der" 1.3.6.1.4.1.34697.2.4 "AffirmTrust-Premium-ECC.der" # Buypass (Norway) # TestURL: https://valid.evident.ca23.ssl.buypass.no/ # TestURL: https://valid.evident.ca13.ssl.buypass.no # source: # confirmed by https://cert.webtrust.org/ViewSeal?id=848 # confirmed by http://www.buypass.no/Bedrift/Produkter+og+tjenester/SSL/SSL%20dokumentasjon # # (2.16.578.1.26.1.3.3) = 0608608442011A010303 # # root: Buypass Class 3 CA 1 Buypass AS-983163327 # # confirmed by email with John Arild Amdahl Johansen on Nov.12 2013 # 2.16.578.1.26.1.3.3 "Buypass Class 3 Root CA.cer" "BuypassClass3CA1.cer" # Certigna # TestURL: http://www.certigna.fr/ca/ACcertigna.crt # confirmed by # 86F27C4BE875508EE8793C4BFC61791530729830 # source # # (1.2.250.1.177.1.18.2.2) # # root: Certigna.cer # 1.2.250.1.177.1.18.2.2 "Certigna.cer" # Certum (Unizeto) (Poland) # source: # source: , # # ( 1 2 616 1 113527 2 5 1 1 ) = 060B2A84680186F67702050101 # # root: Certum Trusted Network CA # root: Certum CA # 1.2.616.1.113527.2.5.1.1 "Unizeto-CertumCA.cer" "Poland-Certum-CTNCA.der" "Certum Trusted Network CA 2.cer" # China Internet Network Information Center (CNNIC) (China) # source: # # ( 1 3 6 1 4 1 29836 1 10 ) = # # root: China Internet Network Information Center EV Certificates Root # 1.3.6.1.4.1.29836.1.10 "CNNICEVRoot.der" # Comodo # source: # confirmed by # # (1.3.6.1.4.1.6449.1.2.1.5.1) = 060C2B06010401B2310102010501 # # root: COMODO Certification Authority # subordinate CA of: Add Trust External CA Root # 1.3.6.1.4.1.6449.1.2.1.5.1 "COMODOCertificationAuthority.crt" "AddTrust External CA Root.crt" # Cybertrust (aka Verizon Business) # source: # confirmed by # # (1.3.6.1.4.1.6334.1.100.1) = 060A2B06010401B13E016401 # # root: GTE Cybertrust Global Root # root: Baltimore Cybertrust Root # 1.3.6.1.4.1.6334.1.100.1 "BTCTRT.cer" "GTEGB18.cer" # DigiCert # source: # confirmed by # confirmed by # # (2.16.840.1.114412.2.1) = 06096086480186FD6C0201 // EV CA-1 # (2.16.840.1.114412.1.3.0.2) = 060B6086480186FD6C01030002 // EV CA-2 # # root: DigiCert High Assurance EV Root CA # previously a subordinate CA of: Entrust.net Secure Server Certification Authority # 2.16.840.1.114412.1.3.0.2 "DigiCertHighAssuranceEVRootCA.crt" # A14B48D943EE0A0E40904F3CE0A4C09193515D3F # F517A24F9A48C6C9F8A200269FDC0F482CAB3089 # DF3C24F9BFD666761B268073FE06D1CC8D4F82A4 # 7E04DE896A3E666D00E687D33FFAD93BE83D349E # DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 # TestURL: https://assured-id-root-g2.digicert.com # TestURL: https://assured-id-root-g3.digicert.com # TestURL: https://global-root-g2.digicert.com # TestURL: https://global-root-g3.digicert.com # TestURL: https://trusted-root-g4.digicert.com # confirmed by 2.16.840.1.114412.2.1 "DigiCertHighAssuranceEVRootCA.crt" "DigiCertAssuredIDRootG2.der" "DigiCertAssuredIDRootG3.der" "DigiCertGlobalRootG2.der" "DigiCertGlobalRootG3.der" "DigiCertTrustedRootG4.der" # DigiNotar # source: # confirmed by # # (2.16.528.1.1001.1.1.1.12.6.1.1.1) = 060E6084100187690101010C06010101 # # root: DigiNotar Root CA # # removed per # 2.16.528.1.1001.1.1.1.12.6.1.1.1 "DigiNotarRootCA2007.crt" # D-Trust # open .D-Trust root certificates # # 1.3.6.1.4.1.4788.2.202.1 # # root: D-TRUST_Root_Class_3_CA_2_EV_2009.cer # 1.3.6.1.4.1.4788.2.202.1 "D-TRUST_Root_Class_3_CA_2_EV_2009.cer" # E-Tugra # source: # Test URL: https://sslev.e-tugra.com.tr # 2.16.792.3.0.4.1.1.4 "E-Tugra.der" # Entrust # 503006091D97D4F5AE39F7CBE7927D7D652D3431 # B31EB1B740E36C8402DADC37D44DF5D4674952F9 # 8CF427FD790C3AD166068DE81E57EFBB932272D4 # 20d80640df9b25f512253a11eaf7598aeb14b547 # TestURL: https://2048test.entrust.net/ # TestURL: https://validev.entrust.net/ # TestURL: https://validg2.entrust.net/ # TestURL: https://validec.entrust.net/ # source: # confirmed by # # (2.16.840.1.114028.10.1.2) = 060A6086480186FA6C0A0102 # # root: Entrust.net Secure Server Certification Authority # root: Entrust Root Certification Authority # # confirmed by 2.16.840.1.114028.10.1.2 "EntrustEVRoot.crt" "EntrustRoot-G2.der" "EntrustRoot-EC1.der" "entrust2048.der" # GeoTrust # source: # confirmed by # G3 root added: # # (1.3.6.1.4.1.14370.1.6) = 06092B06010401F0220106 # # root: GeoTrust Primary Certification Authority # subordinate CA of: Equifax Secure Certificate Authority # 1.3.6.1.4.1.14370.1.6 "geotrust-primary-ca.crt" "Equifax_Secure_Certificate_Auth" "GeoTrust Primary Certification Authority - G3.cer" # GlobalSign # source: # confirmed by # # (1.3.6.1.4.1.4146.1.1) = 06092B06010401A0320101 # # root: GlobalSign Root CA - R3 # root: GlobalSign Root CA - R2 # root: GlobalSign Root CA # 1.3.6.1.4.1.4146.1.1 "GlobalSignRootCA-R2.cer" "globalSignRoot.cer" "GlobalSign-Root-R3.der" # Go Daddy (aka Starfield Technologies) # source: # confirmed by # # (2.16.840.1.114413.1.7.23.3) = 060B6086480186FD6D01071703 # (2.16.840.1.114414.1.7.23.3) = 060B6086480186FD6E01071703 # # root: Go Daddy Class 2 Certification Authority (for 114413) # root: Starfield Class 2 Certificate Authority (for 114414) # root: Starfield Root Certificate Authority - G2 (for 114414) # root: Starfield Services Root Certificate Authority - G2 (for 114414) # previously subordinate CA of: Valicert Class 2 Policy Validation Authority (both) # 2.16.840.1.114413.1.7.23.3 "GD-Class2-root.crt" "GoDaddyRootCertificateAuthorityG2.der" 2.16.840.1.114414.1.7.23.3 "SF-Class2-root.crt" "StarfieldRootCertificateAuthorityG2.der" 2.16.840.1.114414.1.7.24.3 "StarfieldServicesRootCertificateAuthorityG2.der" # Izenpe # source: # source: # confirmed by # # (1.3.6.1.4.1.14777.6.1.1) = # (1.3.6.1.4.1.14777.6.1.2) = # # root: Izenpe.com # root: Izenpe.com/emailAddress=Info@izenpe.com # 1.3.6.1.4.1.14777.6.1.1 "Izenpe-RAIZ2007.crt" "Izenpe-ca_raiz2003.crt" 1.3.6.1.4.1.14777.6.1.2 "Izenpe-RAIZ2007.crt" "Izenpe-ca_raiz2003.crt" # KEYNECTIS (aka Certplus) # source: # confirmed by # # (1.3.6.1.4.1.22234.2.5.2.3.1) = # # root: Class 2 Primary CA # 1.3.6.1.4.1.22234.2.5.2.3.1 "certplus_class2.der" # Logius (aka Staat der Nederlanden) # source: application for root trust store inclusion for Logius EV certificate # confirmed by , # # # # (2.16.528.1.1003.1.2.7) = 060960841001876B010207 # # root: Staat der Nederlanden EV Root CA # 2.16.528.1.1003.1.2.7 "Staat der Nederlanden EV Root CA.cer" # Network Solutions # source: # confirmed by # # (1.3.6.1.4.1.782.1.2.1.8.1) = 060C2B06010401860E0102010801 # # root: Network Solutions Certificate Authority # subordinate CA of: AddTrust External CA Root # 1.3.6.1.4.1.782.1.2.1.8.1 "NetworkSolutionsEVRoot.crt" "AddTrust External CA Root.crt" # QuoVadis # source: # confirmed by # # (1.3.6.1.4.1.8024.0.2.100.1.2) = 060C2B06010401BE580002640102 # # root: QuoVadis Root Certification Authority # root: QuoVadis Root CA 2 # 1.3.6.1.4.1.8024.0.2.100.1.2 "qvrca.crt" "qvrca2.crt" # Secom (aka SECOM Trust Systems Co., Ltd.) # TestURL: https://scrootca2test.secomtrust.net also consider: https://fmctest.secomtrust.net/ # FEB8C432DCF9769ACEAE3DD8908FFD288665647D # source: # # (1.2.392.200091.100.721.1) = 060A2A83088C9B1B64855101 # # root: Security Communication RootCA1 # 1.2.392.200091.100.721.1 "SCRoot1ca.cer" "SECOM-EVRoot1ca.cer" "SECOM-RootCA2.cer" # StartCom # source: # confirmed by , # # (1.3.6.1.4.1.23223.2) = # (1.3.6.1.4.1.23223.1.1.1) = # # root: StartCom Certification Authority # 1.3.6.1.4.1.23223.2 "startcom-sfsca.der" "startcomSHA2.der" "StartCom May 2013 G2.der" 1.3.6.1.4.1.23223.1.1.1 "startcom-sfsca.der" "startcomSHA2.der" "StartCom May 2013 G2.der" # SwissCom # source : SwissCom Root Certificates # TestURL: https://test-quarz-ev-ca-2.pre.swissdigicert.ch/ # confirmed by , # # # previously, we had noted these additional OIDs for SwissCom: # (2.16.756.1.83.20.1.1) = 06086085740153140101 # (the 21.0 OID was listed on # (2.16.756.1.83.21.0) = 060760857401531500 # # (2.16.756.1.83.2.2) = 060760857401530202 # # E7A19029D3D552DC0D0FC692D3EA880D152E1A6B # 2.16.756.1.83.2.2 "Swisscom Root EV CA 2.cer" # SwissSign # source: # repository: https://swisssign.com/english/gold/view-category.html # # (2.16.756.1.89.1.2.1.1) = ... # # root: SwissSign Gold CA - G2 # 2.16.756.1.89.1.2.1.1 "SwissSign-Gold_G2.der" # TrustCenter (DE) # source: # # (1.2.276.0.44.1.1.1.4) = ... # # root: TC TrustCenter Universal CA III # 1.2.276.0.44.1.1.1.4 "trustCenter-root-5.der" # Trustwave (aka SecureTrust, formerly XRamp) # source: # # (2.16.840.1.114404.1.1.2.4.1) = 060C6086480186FD640101020401 # # root: SecureTrust CA # root: Secure Global CA # root: XRamp Global CA # subordinate CA of: Entrust.net Secure Server Certification Authority # 2.16.840.1.114404.1.1.2.4.1 "Trustwave-STCA.der" "Trustwave-SGCA.der" "XGCA.crt" "EntrustRootCA1024.crt" # Thawte # source: # G3 EV root added: # # (2.16.840.1.113733.1.7.48.1) = 060B6086480186F84501073001 # # root: thawte Primary Root CA # subordinate CA of: Thawte Premium Server CA # 2.16.840.1.113733.1.7.48.1 "thawte-primary-root-ca.crt" "serverpremium.crt" "Thawte_Premium_Server_CA.cer" "thawte Primary Root CA - G3.cer" # T-TeleSec # source: T-Systems / Telesec.de root certificates # # (1.3.6.1.4.1.7879.13.24.1) # # root: T-TeleSec GlobalRoot Class 2 T-TeleSec GlobalRoot Class 3 # 1.3.6.1.4.1.7879.13.24.1 "T-TeleSec GlobalRoot Class 2.cer" "T-TeleSec GlobalRoot Class 3.cer" # VeriSign # source: # # (2.16.840.1.113733.1.7.23.6) = 060B6086480186F84501071706 # # root: VeriSign Class 3 Public Primary Certification Authority - G5 # subordinate CA of: Class 3 Public Primary Certification Authority # # Symantec # source: Symantec ECC root certificates May 2013 # # VeriSign # source: Symantec ECC root certificates May 2013 # EV OID correction: EV-enablement for Verisign root certificate already in the keychain # 2.16.840.1.113733.1.7.23.6 "VeriSignC3PublicPrimaryCA-G5.cer" "PCA3ss_v4.509" "Symantec Class 3 Public Primary Certification Authority - G4.cer" "VeriSign Class 3 Public Primary Certification Authority - G4.cer" "VeriSign Universal Root Certification Authority.cer" # Wells Fargo # source: # confirmed by # # (2.16.840.1.114171.500.9) = 060A6086480186FB7B837409 # # root: WellsSecure Public Root Certificate Authority # 2.16.840.1.114171.500.9 "WellsSecurePRCA.der" # Camerfirma # TestURL: https://server2.camerfirma.com:8082 # TestURL: https://www.camerfirma.com/ # confirmed by # # (1.3.6.1.4.1.17326.10.14.2.1.2) = 060D2B0601040181872E0A0E020102 # (1.3.6.1.4.1.17326.10.8.12.1.2) = 060D2B0601040181872E0A080C0102 # # 786A74AC76AB147F9C6A3050BA9EA87EFE9ACE3C # 6E3A55A4190C195C93843CC0DB722E313061F0B1 # 1.3.6.1.4.1.17326.10.14.2.1.2 "ROOT-CHAMBERSIGN.crt" "ROOT-CHAMBERS.crt" "root_chambers-2008.der" 1.3.6.1.4.1.17326.10.8.12.1.2 "root_chambersign-2008.der" # Firmaprofesional # AEC5FB3FC8E1BFC4E54F03075A9AE800B7F7B6FA # Firmaprofesional-CIF-A62634068.der # TestURL: https://publifirma.firmaprofesional.com/ # confirmed by # # (1.3.6.1.4.1.13177.10.1.3.10) = 060B2B06010401E6790A01030A # 1.3.6.1.4.1.13177.10.1.3.10 "Firmaprofesional-CIF-A62634068.der" # TWCA # TestURL (4096): https://evssldemo3.twca.com.tw/index.html # TestURL (2048): https://evssldemo.twca.com.tw/index.html # confirmed with Robin Lin of TWCA on August 13 2013 # # (1.3.6.1.4.1.40869.1.1.22.3) = 060C2B0601040182BF2501011603 # # 9CBB4853F6A4F6D352A4E83252556013F5ADAF65 # CF9E876DD3EBFC422697A3B5A37AA076A9062348 # 1.3.6.1.4.1.40869.1.1.22.3 "TWCARootCA-4096.der" "twca-root-1.der" # ------------------------------------------------------------------------------