Meerkat TLS Test Certificate Factory
Issue a BR-compliant DV TLS certificate from the Meerkat Test CA. Only DNS SANs are accepted — IPs, email addresses, and other SAN types are rejected. CN is always derived from the first DNS SAN; all other CSR fields are stripped. Accepted keys: RSA ≥ 2048 or ECDSA P-256/P-384/P-521.
Certificate repository
Browse TLS CA material and issued certificates at /htmldir/tls →
DCV Challenge
HTTP✔ Certificate Issued
⚠ This is a precertificate (RFC 6962). It contains the CT poison extension
(OID 1.3.6.1.4.1.11129.2.4.3, critical) and cannot be used for TLS. It is
intended for submission to Certificate Transparency logs and linter testing only.
Revocation reason: