← All GlobalSign nv-sa certificates
Intermediate Certificate

GlobalSign RootSign Partners CA

GlobalSign nv-saCCADBCA Organization name as it appears in the CA's CP, CPS, CP/CPS and audit statements.
⚠ This certificate has been revoked
Browser Trust
Apple
AppleCCADBCertificate status in Apple: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
CCADB status only
Chrome
ChromeCCADBCertificate status in Google Chrome: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
No direct match
Microsoft
MicrosoftCCADBCertificate status in Microsoft: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
No direct match
Mozilla
MozillaCCADBCertificate status in Mozilla: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
No direct match
Certificate Details
Record TypeCCADBCCADB field: Certificate Record TypeOne of two values determined when certificate is added to the CCADB:
  • Intermediate Certificate
  • Root Certificate
Intermediate Certificate
Subject DNComputed locallyThe certificate's own distinguished name, parsed from its PEM. This identifies who the certificate was issued to.
CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE
Issuer DNComputed locallyThe distinguished name of the CA that signed this certificate, parsed from its PEM. This identifies who issued it.
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA ↗
SHA-256CCADBCCADB field: SHA-256 FingerprintA SHA-256 hash of the certificate generated by the CCADB when adding a certificate PEM.
20BBB89108079E0701D86B8A893A2A9546E698FECBB70A567A41253887E5724A
Parent SHA-256CCADBCCADB field: Parent SHA-256 FingerprintA SHA-256 hash of the parent certificate, as generated by the CCADB when the parent certificate PEM was added.
EBD41040E4BB3EC742C9E381D31EF2A41A48B6685C96E7CEF3C1DF6CD4331C99
Valid From (GMT)CCADBThe notBefore value extracted from the certificate PEM.
2003.12.16
Valid To (GMT)CCADBThe notAfter value extracted from the certificate PEM.
2028.01.28
AKICCADBCCADB field: Authority Key IdentifierThe authorityKeyIdentifier value extracted from the certificate PEM.
YHtmGkUNl8qJUC99BM00qP/8/Us=
SKICCADBCCADB field: Subject Key IdentifierThe subjectKeyIdentifier value extracted from the certificate PEM.
VoTstXGl52PY21EE1vrm8EhSSc4=
Operated ByCCADBCCADB field: Subordinate CA OwnerThis is the subordinate CA Owner's name as it appears in the provided audit statements. CA Owners MUST NOT leave this field blank unless both control of the private key and domain/IP control validation activities are performed by the organization listed in the audit statement of the parent certificate.
ConstrainedCCADBCCADB field: Technically ConstrainedA boolean value configured by the CCADB when the certificate PEM was added. Set to FALSE if the certificate does not contain an Extended Key Usage (EKU) extension. Set to TRUE if the EKU does not contain id-kp-serverAuth or anyExtendedKeyUsage. If the EKU contains id-kp-serverAuth, then set to TRUE if the certificate includes the Name Constraints X.509v3 extension with constraints on dNSName, iPAddress and DirectoryName. Otherwise set to FALSE.
False
RevocationCCADBCCADB field: Revocation StatusOnly applicable to the Intermediate Certificate record type, the revocation status for this certificate as configured by the CA Owner.
  • –None–
  • Not Revoked
  • Revoked
  • Parent Cert Revoked
✗ Revoked
Salesforce IDCCADBCCADB field: Salesforce Record IDAn internal unique ID for this certificate in the CCADB. This value is assigned by the CCADB.
001o000000fn7suAAA
Capabilities
EV OIDsCCADBCCADB field: EV OIDs for Root CertThis field is updated once daily by a batch program in the CCADB. It includes the union of all EV OIDs, as specified by Root Store Operators.
Status of RootCCADBCCADB field: Status of Root CertRoot Store inclusion status for the root certificate that this intermediate certificate chains up to in the CCADB. (Updated via hourly batch process)
Apple
Included
Google Chrome
Removed
Microsoft
Included
Mozilla
Included
TLSCCADBCCADB field: TLS CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Server Authentication.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Server Authentication.
  • Otherwise set to FALSE.
TLS EVCCADBCCADB field: TLS EV CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Apple EV Enabled' is set to TRUE, or 'ExtendedValidation.cpp OIDs is not null, or 'Microsoft EV_SSL_Enabled is set to TRUE, or 'Google Chrome EV Enabled' is set to TRUE.
  • Set to TRUE for an intermediate certificate record if 'EV SSL Capable' is set to TRUE.
  • Otherwise set to FALSE.
Code SigningCCADBCCADB field: Code Signing CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Code Signing.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Code Signing.
  • Otherwise set to FALSE.
S/MIMECCADBCCADB field: S/MIME CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Secure Email.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Secure Email.
  • Otherwise set to FALSE.
VMCCCADBCCADB field: VMC CapableNot documented as a separate field in the CCADB data dictionary. Computed by CCADB using the same Trust Bits / Derived Trust Bits mechanism as the other capability flags, for Verified Mark Certificates.Document SigningCCADBCCADB field: Document Signing CapableNot documented as a separate field in the CCADB data dictionary. Computed by CCADB using the same Trust Bits / Derived Trust Bits mechanism as the other capability flags, for document signing EKU.
CAA IdentifiersCCADBCCADB field: AllCAAIdentifiersReportCSVV2A separate CCADB report, not part of the main certificate record (AllCertificateRecordsCSVFormatV5) used elsewhere on this page. CA Owners disclose the CAA issuer domain label(s) they use in DNS CAA records, tied to the specific intermediate certificate and Subject Key Identifier each declaration applies to.
Recognized CAA issuer identifiers published by CCADB for this CA certificate.
Not Applicable
Audit
Audit FirmCCADBCCADB field: AuditorA picklist value for the name of the Audit Firm that issued the audit statements, as selected by the CA Owner.
Firm LocationCCADBCCADB field: Audit Firm LocationNot documented as a separate field in the CCADB data dictionary. Disclosed alongside Auditor.
Same as ParentCCADBCCADB field: Audits Same as Parent?A boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if the current or next audit of the parent certificate includes this certificate. Otherwise set to FALSE, and all applicable audit fields must have values provided by the CA Owner.
true
Inherited from parent
Standard
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
WebTrust
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2026.06.29
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2025.04.01 – 2026.03.31
NetSec
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (i.e., CA/Browser Forum "Network and Certificate System Security Requirements") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
WebTrust
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2026.06.29
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2025.04.01 – 2026.03.31
TLS BR
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (CA/Browser Forum "Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
WebTrust
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2026.06.29
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2025.04.01 – 2026.03.31
TLS EVG
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (CA/Browser Forum "Guidelines for the Issuance and Management of Extended Validation Certificates") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
WebTrust
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2026.06.29
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2025.04.01 – 2026.03.31
Code Signing
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (CA/Browser Forum "Baseline Requirements for the Issuance and Management of Publicly-Trusted CodeSigning Certificates") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
WebTrust
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2026.06.29
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2025.04.01 – 2026.03.31
S/MIME BR
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (CA/Browser Forum "Baseline Requirements for the Issuance and Management of Publicly-Trusted S/MIME Certificates") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
WebTrust
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2026.06.29
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2025.04.01 – 2026.03.31
Policy & Documentation
CP URLCCADBCCADB field: Certificate Policy (CP) URLThe URL to CP documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CP Same as Parent' is set to FALSE.
CP Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same Certificate Policy (CP) information as the issuing certificate (or a subset). Otherwise set to FALSE.
true
Inherited CP URLCCADBThis field is blank on this certificate because CP Same as Parent is TRUE. Shown here is the parent record's own CP URL, which CCADB's rules say governs this certificate instead.
Inherited CP EffectiveCCADBThis field is blank on this certificate because CP Same as Parent is TRUE. Shown here is the parent record's own CP effective date.
CP EffectiveCCADBCCADB field: CP Effective DateThe date the CP documentation specific to this certificate became effective, as configured by the CA Owner. This value must be populated if 'CP Same as Parent' is set to FALSE.
CPS URLCCADBCCADB field: Certificate Practice Statement (CPS) URLThe URL to CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CPS Same as Parent' is set to FALSE.
CPS Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same Certification Practice Statement (CPS) information as the issuing certificate (or a subset). Otherwise set to FALSE.
true
Inherited CPS URLCCADBThis field is blank on this certificate because CPS Same as Parent is TRUE. Shown here is the parent record's own CPS URL, which CCADB's rules say governs this certificate instead.
Inherited CPS EffectiveCCADBThis field is blank on this certificate because CPS Same as Parent is TRUE. Shown here is the parent record's own CPS effective date.
CPS EffectiveCCADBCCADB field: CPS Effective DateThe date the CPS documentation specific to this certificate became effective, as configured by the CA Owner. This value must be populated if 'CPS Same as Parent' is set to FALSE.
CP/CPS StatementCCADBCCADB field: Certificate Practice & Policy StatementThe URL to the combined CP/CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CP/CPS Same as Parent' is set to FALSE.
CP/CPS Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same combined CP/CPS information as the issuing certificate (or a subset). Otherwise set to FALSE.
true
Inherited CP/CPS URLCCADBThis field is blank on this certificate because CP/CPS Same as Parent is TRUE. Shown here is the parent record's own combined CP/CPS URL.
Inherited CP/CPS EffectiveCCADBThis field is blank on this certificate because CP/CPS Same as Parent is TRUE. Shown here is the parent record's own CP/CPS effective date.
2026.06.15
MD/AsciiDoc URLCCADBCCADB field: MD/AsciiDoc CP/CPS URLThe URL to the combined Markdown or AsciiDoc CP/CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'MD/AsciiDoc CP/CPS Same as Parent' is set to FALSE.
MD/AsciiDoc Same as ParentCCADBCCADB field: MD/AsciiDoc CP/CPS Same as ParentA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same combined Markdown or AsciiDoc CP/CPS information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
Infrastructure
CRL (Full)CCADBCCADB field: JSON Array of All Full CRL URLsNot the exact documented field (the data dictionary describes an older single-URL "Full CRL Issued By This CA" field); this is its JSON-array successor in the current V5 report, holding the full CRL URL(s) for certificates issued by this CA, as configured by the CA Owner.
CRL (Parts)CCADBCCADB field: JSON Array of Partitioned CRLsWhen there is no full CRL for certificates issued by this CA, the CA Owner can provide a JSON array whose elements are URLs of partitioned, DER-encoded CRLs that when combined are the equivalent of a full CRL for certificates issued by this CA. The JSON array may omit obsolete partitioned CRLs whose scopes only include expired certificates.
ACME DVCCADBCCADB field: DV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Domain Validated issuance, as configured by the CA Owner.
ACME OVCCADBCCADB field: OV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Organization Validated issuance, as configured by the CA Owner.
ACME EVCCADBCCADB field: EV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Extended Validation issuance, as configured by the CA Owner.
Test (Valid)CCADBCCADB field: Test Website URL - ValidThe URL to a website with a valid TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Test (Expired)CCADBCCADB field: Test Website URL - ExpiredThe URL to a website with an expired TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Test (Revoked)CCADBCCADB field: Test Website URL - RevokedThe URL to a website with a revoked TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Policy OIDs
Certificate X.509 certificatePolicies
No certificatePolicies extension in certificate
CCADB EV OIDs for Root Cert · administrative declaration
Declared on root: GlobalSign Root CA
CA/B EV TLS2.23.140.1.11.3.6.1.4.1.4146.10.1.11.3.6.1.4.1.4146.1.1CA/B EV CS2.23.140.1.3
Comparison
Root declares EV OID(s) but this certificate has none
Chain Validation
Certificate Lint (zlint, live)
pkimetal
Certificate (PEM)
crt.sh via Matador
By SPKI SHA-256 → All CT log entries sharing this public key, deduplicated — the broadest CT search for a CA
By SHA-256 → Look up this exact certificate by its fingerprint
By SKI → All certificates sharing this Subject Key Identifier
Issued Certificates → Resolve crt.sh issuer CA ID, then paginate all certificates issued by this CA
Mozilla OneCRL
StatusNameIssuerSerialBugModified
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000103F037E445 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000012945C3AB1C 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000012596C45382 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 040000000000F97FC62329 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 040000000001094550F4DA 1155145 2016-11-28
enabled Revoked intermediates CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000116AA006682 1312150 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000012507408E29 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 040000000001331BC2F5B9 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000100998F8DF4 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000127FB9F45D8 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000011C944A3290 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 040000000001047628205B 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000118C1B41A6C 1155145 2016-11-28
enabled Revoked intermediates CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000012C5E7F1D76 1312150 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000118C1A37ED6 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000127FB9F420F 1155145 2016-11-28
enabled Revoked intermediates CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000133A777674B 1312150 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000132B4BBB768 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000011E4487952A 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 040000000001281FCE1AA2 1155145 2016-11-28
enabled Revoked intermediates CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000011E4487922D 1312150 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000011C944A3669 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000012CCFFBAA39 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 0400000000011E44878F3F 1155145 2016-11-28
enabled GlobalSign certs CN=GlobalSign RootSign Partners CA, OU=RootSign Partners CA, O=GlobalSign nv-sa, C=BE 04000000000100FA6E561D 1155145 2016-11-28

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action