← All Sectigo certificates
Root Certificate

Entrust Root Certification Authority - EC1

Sectigo
Browser Trust
Apple
Apple
Included
CCADB status only
Chrome
Chrome
Removed
No direct match
Microsoft
Microsoft
Included
Directly listed
Mozilla
Mozilla
Included
Directly listed
Trust Bits (root)
Server AuthenticationClient AuthenticationSecure EmailTime Stamping
Certificate Details
Record Type
Root Certificate
SHA-256
02ED0EB28C14DA45165C566791700D6451D7FB56F0B2AB1D3B8EB070E56EDFF5
Parent SHA-256
Valid From (GMT)
2012.12.18
Valid To (GMT)
2037.12.18
AKI
SKI
t2PnGt2N6QimVYOk4GpQQWURQkk=
Operated By
Constrained
False
Revocation
Salesforce ID
001o000000TNaMfAAL
Capabilities
EV OIDs
2.23.140.1.1; 2.16.840.1.114028.10.1.2
Status of Root
Apple
Included
Google Chrome
Removed
Microsoft
Included
Mozilla
Included
TLSTLS EVCode SigningS/MIME
CAA Identifiers
Recognized CAA issuer identifiers published by CCADB for this CA certificate.
Entrust Root Certification Authority - EC1
SKI B763E71ADD8DE908A65583A4E06A504165114249
sectigo.com comodo.com comodoca.com usertrust.com trust-provider.com entrust.net affirmtrust.com
Audit
Audit Firm
Deloitte
Firm Location
Canada
Same as Parent
false
Standard
Audit URL
Type
WebTrust
Statement
2025.11.19
Period
2025.03.01 – 2025.09.17
NetSec
Audit URL
Type
WebTrust
Statement
2025.11.21
Period
2025.03.01 – 2025.09.17
TLS BR
Audit URL
Type
WebTrust
Statement
2025.11.19
Period
2025.03.01 – 2025.09.17
TLS EVG
Audit URL
Type
WebTrust
Statement
2025.11.19
Period
2025.03.01 – 2025.09.17
S/MIME BR
Audit URL
Type
WebTrust
Statement
2025.11.19
Period
2025.03.01 – 2025.09.17
Policy & Documentation
CP URL
CP Effective
CPS URL
CPS Effective
CP/CPS Statement
MD/AsciiDoc URL
Policy OIDs
Certificate X.509 certificatePolicies · cryptographic fact
No certificatePolicies extension in certificate
CCADB EV OIDs for Root Cert · administrative declaration
CA/B EV TLS2.23.140.1.12.16.840.1.114028.10.1.2
Comparison
CCADB declares policy OIDs but certificate has none
Marked TLS EV Capable in CCADB but certificate has no policy OIDs
Chain Validation
No parent certificate in CCADB — chain lint requires issuer
Infrastructure
CRL (Full)
CRL (Parts)
ACME DV
ACME OV
ACME EV
Test (Valid)
Test (Expired)
Test (Revoked)
Certificate (PEM)
External References

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action