1# Chrome Root Store. 2# 3# proto-file: googleclient/chrome/security/pki_metadata/chrome_root_store/root_store.proto 4# proto-message: chrome_browser_chrome_root_store.RootStore 5# 6# Comments before each entry list the certificate Subject, and for entries 7# containing EV policy OIDs, the URL for the EV test sites. 8 9# Version # should always be incremented up whenever this (or any pem file that 10# it references) is changed. 11version_major: 15 12 13# CN=Actalis Authentication Root CA, O=Actalis S.p.A./03358520967, L=Milan, C=IT 14# https://ssltest-a.actalis.it:8443 15trust_anchors { 16 sha256_hex: "55926084ec963a64b96e2abe01ce0ba86a64fbfebcc7aab5afc155b37fd76066" 17 ev_policy_oids: "2.23.140.1.1" 18} 19 20# CN=Amazon Root CA 3, O=Amazon, C=US 21# https://good.sca3a.amazontrust.com/ 22trust_anchors { 23 sha256_hex: "18ce6cfe7bf14e60b2e347b8dfe868cb31d02ebb3ada271569f50343b46db3a4" 24 ev_policy_oids: "2.23.140.1.1" 25} 26 27# CN=Amazon Root CA 2, O=Amazon, C=US 28# https://good.sca2a.amazontrust.com/ 29trust_anchors { 30 sha256_hex: "1ba5b2aa8c65401a82960118f80bec4f62304d83cec4713a19c39c011ea46db4" 31 ev_policy_oids: "2.23.140.1.1" 32} 33 34# CN=Amazon Root CA 1, O=Amazon, C=US 35# https://good.sca1a.amazontrust.com/ 36trust_anchors { 37 sha256_hex: "8ecde6884f3d87b1125ba31ac3fcb13d7016de7f57cc904fe1cb97c6ae98196e" 38 ev_policy_oids: "2.23.140.1.1" 39} 40 41# CN=Amazon Root CA 4, O=Amazon, C=US 42# https://good.sca4a.amazontrust.com/ 43trust_anchors { 44 sha256_hex: "e35d28419ed02025cfa69038cd623962458da5c695fbdea3c22b0bfb25897092" 45 ev_policy_oids: "2.23.140.1.1" 46} 47 48# CN=Certum Trusted Network CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL 49# https://juice.certum.pl/ 50trust_anchors { 51 sha256_hex: "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e" 52 ev_policy_oids: "2.23.140.1.1" 53} 54 55# CN=Certum Trusted Network CA 2, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL 56trust_anchors { 57 sha256_hex: "b676f2eddae8775cd36cb0f63cd1d4603961f49e6265ba013a2f0307b6d0b804" 58} 59 60# C=DE, O=Atos, CN=Atos TrustedRoot 2011 61trust_anchors { 62 sha256_hex: "f356bea244b7a91eb35d53ca9ad7864ace018e2d35d5f8f96ddf68a6f41aa474" 63} 64 65# CN=Autoridad de Certificacion Firmaprofesional CIF A62634068, C=ES 66# https://publifirma.firmaprofesional.com/ 67trust_anchors { 68 sha256_hex: "57de0583efd2b26e0361da99da9df4648def7ee8441c3b728afa9bcde0f9b26a" 69 ev_policy_oids: "2.23.140.1.1" 70} 71 72# CN=Buypass Class 2 Root CA, O=Buypass AS-983163327, C=NO 73trust_anchors { 74 sha256_hex: "9a114025197c5bb95d94e63d55cd43790847b646b23cdf11ada4a00eff15fb48" 75} 76 77# CN=Buypass Class 3 Root CA, O=Buypass AS-983163327, C=NO 78# https://valid.evident.ca23.ssl.buypass.no/ 79trust_anchors { 80 sha256_hex: "edf7ebbca27a2a384d387b7d4010c666e2edb4843e4c29b4ae1d5b9332e6b24d" 81 ev_policy_oids: "2.23.140.1.1" 82} 83 84# OU=certSIGN ROOT CA G2, O=CERTSIGN SA, C=RO 85# https://testssl-valid-evcp.certsign.ro/ 86trust_anchors { 87 sha256_hex: "657cfe2fa73faa38462571f332a2363a46fce7020951710702cdfbb6eeda3305" 88 ev_policy_oids: "2.23.140.1.1" 89} 90 91# OU=certSIGN ROOT CA, O=certSIGN, C=RO 92trust_anchors { 93 sha256_hex: "eaa962c4fa4a6bafebe415196d351ccd888d4f53f3fa8ae6d7c466a94e6042bb" 94} 95 96# CN=CFCA EV ROOT, O=China Financial Certification Authority, C=CN 97# https://www.erenepu.com/ 98trust_anchors { 99 sha256_hex: "5cc3d78e4e1d5e45547a04e6873e64f90cf9536d1ccc2ef800f355c4c5fd70fd" 100 ev_policy_oids: "2.23.140.1.1" 101} 102 103# OU=ePKI Root Certification Authority, O=Chunghwa Telecom Co., Ltd., C=TW 104trust_anchors { 105 sha256_hex: "c0a6f4dc63a24bfdcf54ef2a6a082a0a72de35803e2ff5ff527ae5d87206dfd5" 106} 107 108# CN=SecureSign RootCA11, O=Japan Certification Services, Inc., C=JP 109trust_anchors { 110 sha256_hex: "bf0feefb9e3a581ad5f9e9db7589985743d261085c4d314f6f5d7259aa421612" 111} 112 113# CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE 114trust_anchors { 115 sha256_hex: "49e7a442acf0ea6287050054b52564b650e4f49e42e348d6aa38e039e957b1c1" 116} 117 118# CN=D-TRUST Root Class 3 CA 2 EV 2009, O=D-Trust GmbH, C=DE 119# https://certdemo-ev-valid.ssl.d-trust.net/ 120trust_anchors { 121 sha256_hex: "eec5496b988ce98625b934092eec2908bed0b0f316c2d4730c84eaf1f3d34881" 122 # TODO(cclements,hchao): remove non-CABF OID once it is not used anymore. 123 ev_policy_oids: "1.3.6.1.4.1.4788.2.202.1" 124 ev_policy_oids: "2.23.140.1.1" 125} 126 127# CN=T-TeleSec GlobalRoot Class 2, OU=T-Systems Trust Center, O=T-Systems Enterprise Services GmbH, C=DE 128trust_anchors { 129 sha256_hex: "91e2f5788d5810eba7ba58737de1548a8ecacd014598bc0b143e041b17052552" 130} 131 132# CN=T-TeleSec GlobalRoot Class 3, OU=T-Systems Trust Center, O=T-Systems Enterprise Services GmbH, C=DE 133# http://www.telesec.de/ / https://root-class3.test.telesec.de/ 134trust_anchors { 135 sha256_hex: "fd73dad31c644ff1b43bef0ccdda96710b9cd9875eca7e31707af3e96d522bbd" 136 ev_policy_oids: "2.23.140.1.1" 137} 138 139# CN=Certigna Root CA, OU=0002 48146308100036, O=Dhimyotis, C=FR 140trust_anchors { 141 sha256_hex: "d48d3d23eedb50a459e55197601c27774b9d7b18c94d5a059511a10250b93168" 142} 143 144# CN=Certigna, O=Dhimyotis, C=FR 145trust_anchors { 146 sha256_hex: "e3b6a2db2ed7ce48842f7ac53241c7b71d54144bfb40c11f3f1d0b42f5eea12d" 147} 148 149# CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE 150trust_anchors { 151 sha256_hex: "16af57a9f676b0ab126095aa5ebadef22ab31119d644ac95cd4b93dbf3f26aeb" 152} 153 154# CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US 155# https://global-root-g3.chain-demos.digicert.com/ 156trust_anchors { 157 sha256_hex: "31ad6648f8104138c738f39ea4320133393e3a18cc02296ef97c2ac9ef6731d0" 158 ev_policy_oids: "2.23.140.1.1" 159} 160 161# CN=DigiCert Assured ID Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US 162trust_anchors { 163 sha256_hex: "3e9099b5015e8f486c00bcea9d111ee721faba355a89bcf1df69561e3dc6325c" 164} 165 166# CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US 167trust_anchors { 168 sha256_hex: "4348a0e9444c78cb265e058d5e8944b4d84f9662bd26db257f8934a443c70161" 169} 170 171# CN=DigiCert Trusted Root G4, OU=www.digicert.com, O=DigiCert Inc, C=US 172# https://trusted-root-g4.chain-demos.digicert.com/ 173trust_anchors { 174 sha256_hex: "552f7bdcf1a7af9e6ce672017f4f12abf77240c78e761ac203d1d9d20ac89988" 175 ev_policy_oids: "2.23.140.1.1" 176} 177 178# CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US 179# https://www.digicert.com 180trust_anchors { 181 sha256_hex: "7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf" 182 ev_policy_oids: "2.23.140.1.1" 183} 184 185# CN=DigiCert Assured ID Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US 186# https://assured-id-root-g2.chain-demos.digicert.com/ 187trust_anchors { 188 sha256_hex: "7d05ebb682339f8c9451ee094eebfefa7953a114edb2f44949452fab7d2fc185" 189 ev_policy_oids: "2.23.140.1.1" 190} 191 192# CN=DigiCert Assured ID Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US 193# https://assured-id-root-g3.chain-demos.digicert.com/ 194trust_anchors { 195 sha256_hex: "7e37cb8b4c47090cab36551ba6f45db840680fba166a952db100717f43053fc2" 196 ev_policy_oids: "2.23.140.1.1" 197} 198 199# CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US 200# https://global-root-g2.chain-demos.digicert.com/ 201trust_anchors { 202 sha256_hex: "cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f" 203 ev_policy_oids: "2.23.140.1.1" 204} 205 206# CN=CA Disig Root R2, O=Disig a.s., L=Bratislava, C=SK 207trust_anchors { 208 sha256_hex: "e23d4a036d7b70e9f595b1422079d2b91edfbb1fb651a0633eaa8a9dc5f80703" 209} 210 211# CN=emSign Root CA - C1, O=eMudhra Inc, OU=emSign PKI, C=US 212trust_anchors { 213 sha256_hex: "125609aa301da0a249b97a8239cb6a34216f44dcac9f3954b14292f2e8c8608f" 214} 215 216# CN=emSign Root CA - G1, O=eMudhra Technologies Limited, OU=emSign PKI, C=IN 217# https://testevg1.emsign.com/ 218trust_anchors { 219 sha256_hex: "40f6af0346a99aa1cd1d555a4e9cce62c7f9634603ee406615833dc8c8d00367" 220 ev_policy_oids: "2.23.140.1.1" 221} 222 223# CN=emSign ECC Root CA - G3, O=eMudhra Technologies Limited, OU=emSign PKI, C=IN 224trust_anchors { 225 sha256_hex: "86a1ecba089c4a8d3bbe2734c612ba341d813e043cf9e8a862cd5c57a36bbe6b" 226} 227 228# CN=emSign ECC Root CA - C3, O=eMudhra Inc, OU=emSign PKI, C=US 229trust_anchors { 230 sha256_hex: "bc4d809b15189d78db3e1d8cf4f9726a795da1643ca5f1358e1ddb0edc0d7eb3" 231} 232 233# CN=Entrust Root Certification Authority - EC1, OU=(c) 2012 Entrust, Inc. - for authorized use only, OU=See www.entrust.net/legal-terms, O=Entrust, Inc., C=US 234# https://validec.entrust.net 235trust_anchors { 236 sha256_hex: "02ed0eb28c14da45165c566791700d6451d7fb56f0b2ab1d3b8eb070e56edff5" 237 ev_policy_oids: "2.23.140.1.1" 238} 239 240# CN=AffirmTrust Commercial, O=AffirmTrust, C=US 241# https://commercial.affirmtrust.com/ 242trust_anchors { 243 sha256_hex: "0376ab1d54c5f9803ce4b2e201a0ee7eef7b57b636e8a93c9b8d4860c96f5fa7" 244 ev_policy_oids: "2.23.140.1.1" 245} 246 247# CN=AffirmTrust Networking, O=AffirmTrust, C=US 248# https://networking.affirmtrust.com:4431 249trust_anchors { 250 sha256_hex: "0a81ec5a929777f145904af38d5d509f66b5e2c58fcdb531058b0e17f3f0b41b" 251 ev_policy_oids: "2.23.140.1.1" 252} 253 254# CN=Entrust Root Certification Authority - G2, OU=(c) 2009 Entrust, Inc. - for authorized use only, OU=See www.entrust.net/legal-terms, O=Entrust, Inc., C=US 255# https://validg2.entrust.net 256trust_anchors { 257 sha256_hex: "43df5774b03e7fef5fe40d931a7bedf1bb2e6b42738c4e6d3841103d3aa7f339" 258 ev_policy_oids: "2.23.140.1.1" 259} 260 261# CN=Entrust.net Certification Authority (2048), OU=(c) 1999 Entrust.net Limited, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), O=Entrust.net 262trust_anchors { 263 sha256_hex: "6dc47172e01cbcb0bf62580d895fe2b8ac9ad4f873801e0c10b9c837d21eb177" 264} 265 266# CN=AffirmTrust Premium, O=AffirmTrust, C=US 267# https://premium.affirmtrust.com:4432/ 268trust_anchors { 269 sha256_hex: "70a73f7f376b60074248904534b11482d5bf0e698ecc498df52577ebf2e93b9a" 270 ev_policy_oids: "2.23.140.1.1" 271} 272 273# CN=Entrust Root Certification Authority, OU=(c) 2006 Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, O=Entrust, Inc., C=US 274# https://www.entrust.net/ 275trust_anchors { 276 sha256_hex: "73c176434f1bc6d5adf45b0e76e727287c8de57616c1e6e6141a2b2cbc7d8e4c" 277 ev_policy_oids: "2.23.140.1.1" 278} 279 280# CN=AffirmTrust Premium ECC, O=AffirmTrust, C=US 281# https://premiumecc.affirmtrust.com:4433/ 282trust_anchors { 283 sha256_hex: "bd71fdf6da97e4cf62d1647add2581b07d79adf8397eb4ecba9c5e8488821423" 284 ev_policy_oids: "2.23.140.1.1" 285} 286 287# CN=Entrust Root Certification Authority - G4, OU=(c) 2015 Entrust, Inc. - for authorized use only, OU=See www.entrust.net/legal-terms, O=Entrust, Inc., C=US 288# https://validg4.entrust.net 289trust_anchors { 290 sha256_hex: "db3517d1f6732a2d5ab97c533ec70779ee3270a62fb4ac4238372460e6f01e88" 291 ev_policy_oids: "2.23.140.1.1" 292} 293 294# CN=GDCA TrustAUTH R5 ROOT, O=GUANG DONG CERTIFICATE AUTHORITY CO.,LTD., C=CN 295trust_anchors { 296 sha256_hex: "bfff8fd04433487d6a8aa60c1a29767a9fc2bbb05e420f713a13b992891d3893" 297} 298 299# CN=GlobalSign, O=GlobalSign, OU=GlobalSign ECC Root CA - R5 300# https://2038r5.globalsign.com/ 301trust_anchors { 302 sha256_hex: "179fbc148a3dd00fd24ea13458cc43bfa7f59c8182d783a513f6ebec100c8924" 303 ev_policy_oids: "2.23.140.1.1" 304} 305 306# CN=GlobalSign, O=GlobalSign, OU=GlobalSign Root CA - R6 307trust_anchors { 308 sha256_hex: "2cabeafe37d06ca22aba7391c0033d25982952c453647349763a3ab5ad6ccf69" 309 ev_policy_oids: "2.23.140.1.1" 310} 311 312# CN=GlobalSign, O=GlobalSign, OU=GlobalSign Root CA - R3 313# https://2029.globalsign.com/ 314trust_anchors { 315 sha256_hex: "cbb522d7b7f127ad6a0113865bdf1cd4102e7d0759af635a7cf4720dc963c53b" 316 ev_policy_oids: "2.23.140.1.1" 317} 318 319# CN=GlobalSign Root CA, OU=Root CA, O=GlobalSign nv-sa, C=BE 320# GlobalSign Root CA 321trust_anchors { 322 sha256_hex: "ebd41040e4bb3ec742c9e381d31ef2a41a48b6685c96e7cef3c1df6cd4331c99" 323 ev_policy_oids: "2.23.140.1.1" 324} 325 326# OU=Starfield Class 2 Certification Authority, O=Starfield Technologies, Inc., C=US 327# https://www.starfieldtech.com/ 328trust_anchors { 329 sha256_hex: "1465fa205397b876faa6f0a9958e5590e40fcc7faa4fb7c2c8677521fb5fb658" 330 ev_policy_oids: "2.23.140.1.1" 331} 332 333# CN=Starfield Root Certificate Authority - G2, O=Starfield Technologies, Inc., L=Scottsdale, ST=Arizona, C=US 334# https://valid.sfig2.catest.starfieldtech.com/ 335trust_anchors { 336 sha256_hex: "2ce1cb0bf9d2f9e102993fbe215152c3b2dd0cabde1c68e5319b839154dbb7f5" 337 ev_policy_oids: "2.23.140.1.1" 338} 339 340# CN=Go Daddy Root Certificate Authority - G2, O=GoDaddy.com, Inc., L=Scottsdale, ST=Arizona, C=US 341# https://valid.gdig2.catest.godaddy.com/ 342trust_anchors { 343 sha256_hex: "45140b3247eb9cc8c5b4f0d7b53091f73292089e6e5a63e2749dd3aca9198eda" 344 ev_policy_oids: "2.23.140.1.1" 345} 346 347# OU=Go Daddy Class 2 Certification Authority, O=The Go Daddy Group, Inc., C=US 348# https://www.godaddy.com/ 349trust_anchors { 350 sha256_hex: "c3846bf24b9e93ca64274c0ec67c1ecc5e024ffcacd2d74019350e81fe546ae4" 351 ev_policy_oids: "2.23.140.1.1" 352} 353 354# CN=GTS Root R3, O=Google Trust Services LLC, C=US 355trust_anchors { 356 sha256_hex: "34d8a73ee208d9bcdb0d956520934b4e40e69482596e8b6f73c8426b010a6f48" 357} 358 359# CN=GTS Root R1, O=Google Trust Services LLC, C=US 360trust_anchors { 361 sha256_hex: "d947432abde7b7fa90fc2e6b59101b1280e0e1c7e4e40fa3c6887fff57a7f4cf" 362} 363 364# CN=GTS Root R4, O=Google Trust Services LLC, C=US 365trust_anchors { 366 sha256_hex: "349dfa4058c5e263123b398ae795573c4e1313c83fe68f93556cd5e8031b3c7d" 367} 368 369# CN=GlobalSign, O=GlobalSign, OU=GlobalSign ECC Root CA - R4 370trust_anchors { 371 sha256_hex: "b085d70b964f191a73e4af0d54ae7a0e07aafdaf9b71dd0862138ab7325a24a2" 372} 373 374# CN=GTS Root R2, O=Google Trust Services LLC, C=US 375trust_anchors { 376 sha256_hex: "8d25cd97229dbf70356bda4eb3cc734031e24cf00fafcfd32dc76eb5841c7ea8" 377} 378 379# CN=Hongkong Post Root CA 3, O=Hongkong Post, L=Hong Kong, ST=Hong Kong, C=HK 380# https://valid-ev.ecert.gov.hk/ 381trust_anchors { 382 sha256_hex: "5a2fc03f0c83b090bbfa40604b0988446c7636183df9846e17101a447fb8efd6" 383 ev_policy_oids: "2.23.140.1.1" 384} 385 386# C=ES, O=ACCV, OU=PKIACCV, CN=ACCVRAIZ1 387trust_anchors { 388 sha256_hex: "9a6ec012e1a7da9dbe34194d478ad7c0db1822fb071df12981496ed104384113" 389} 390 391# OU=AC RAIZ FNMT-RCM, O=FNMT-RCM, C=ES 392trust_anchors { 393 sha256_hex: "ebc5570c29018c4d67b1aa127baf12f703b4611ebc17b7dab5573894179b93fa" 394} 395 396# CN=TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1, OU=Kamu Sertifikasyon Merkezi - Kamu SM, O=Turkiye Bilimsel ve Teknolojik Arastirma Kurumu - TUBITAK, L=Gebze - Kocaeli, C=TR 397trust_anchors { 398 sha256_hex: "46edc3689046d53a453fb3104ab80dcaec658b2660ea1629dd7e867990648716" 399} 400 401# CN=Hellenic Academic and Research Institutions ECC RootCA 2015, O=Hellenic Academic and Research Institutions Cert. Authority, L=Athens, C=GR 402# https://haricaeccrootca2015-valid-ev.harica.gr 403trust_anchors { 404 sha256_hex: "44b545aa8a25e65a73ca15dc27fc36d24c1cb9953a066539b11582dc487b4833" 405 ev_policy_oids: "2.23.140.1.1" 406} 407 408# CN=Hellenic Academic and Research Institutions RootCA 2015, O=Hellenic Academic and Research Institutions Cert. Authority, L=Athens, C=GR 409# https://haricarootca2015-valid-ev.harica.gr 410trust_anchors { 411 sha256_hex: "a040929a02ce53b4acf4f2ffc6981ce4496f755e6d45fe0b2a692bcd52523f36" 412 ev_policy_oids: "2.23.140.1.1" 413} 414 415# CN=IdenTrust Public Sector Root CA 1, O=IdenTrust, C=US 416trust_anchors { 417 sha256_hex: "30d0895a9a448a262091635522d1f52010b5867acae12c78ef958fd4f4389f2f" 418} 419 420# CN=IdenTrust Commercial Root CA 1, O=IdenTrust, C=US 421# https://identrust-commercial-ev-valid.identrustssl.com/ 422trust_anchors { 423 sha256_hex: "5d56499be4d2e08bcfcad08a3e38723d50503bde706948e42f55603019e528ae" 424 ev_policy_oids: "2.23.140.1.1" 425} 426 427# CN=ISRG Root X1, O=Internet Security Research Group, C=US 428trust_anchors { 429 sha256_hex: "96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6" 430} 431 432# CN=Izenpe.com, O=IZENPE S.A., C=ES 433# The first OID is for businesses and the second for government entities. 434# These are the test sites, respectively: 435# https://servicios.izenpe.com 436# https://servicios1.izenpe.com 437trust_anchors { 438 sha256_hex: "2530cc8e98321502bad96f9b1fba1b099e2d299e0f4548bb914f363bc0d4531f" 439 ev_policy_oids: "2.23.140.1.1" 440} 441 442# CN=SZAFIR ROOT CA2, O=Krajowa Izba Rozliczeniowa S.A., C=PL 443trust_anchors { 444 sha256_hex: "a1339d33281a0b56e557d3d32b1ce7f9367eb094bd5fa72a7e5004c8ded7cafe" 445} 446 447# [email protected], CN=Microsec e-Szigno Root CA 2009, O=Microsec Ltd., L=Budapest, C=HU 448trust_anchors { 449 sha256_hex: "3c5f81fea5fab82c64bfa2eaecafcde8e077fc8620a7cae537163df36edbf378" 450} 451 452# CN=e-Szigno Root CA 2017, organizationIdentifier=VATHU-23584497, O=Microsec Ltd., L=Budapest, C=HU 453trust_anchors { 454 sha256_hex: "beb00b30839b9bc32c32e4447905950641f26421b15ed089198b518ae2ea1b99" 455} 456 457# CN=Microsoft ECC Root Certificate Authority 2017, O=Microsoft Corporation, C=US 458trust_anchors { 459 sha256_hex: "358df39d764af9e1b766e9c972df352ee15cfac227af6ad1d70e8e4a6edcba02" 460} 461 462# CN=Microsoft RSA Root Certificate Authority 2017, O=Microsoft Corporation, C=US 463trust_anchors { 464 sha256_hex: "c741f70f4b2a8d88bf2e71c14122ef53ef10eba0cfa5e64cfa20f418853073e0" 465} 466 467# CN=NetLock Arany (Class Gold) Főtanúsítvány, OU=Tanúsítványkiadók (Certification Services), O=NetLock Kft., L=Budapest, C=HU 468# https://valid.ev.tanusitvany.hu 469trust_anchors { 470 sha256_hex: "6c61dac3a2def031506be036d2a6fe401994fbd13df9c8d466599274c446ec98" 471 ev_policy_oids: "2.23.140.1.1" 472} 473 474# CN=OISTE WISeKey Global Root GB CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH 475# https://goodevssl.wisekey.com 476trust_anchors { 477 sha256_hex: "6b9c08e86eb0f767cfad65cd98b62149e5494a67f5845e7bd1ed019f27b86bd6" 478 ev_policy_oids: "2.23.140.1.1" 479} 480 481# CN=OISTE WISeKey Global Root GC CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH 482trust_anchors { 483 sha256_hex: "8560f91c3624daba9570b5fea0dbe36ff11a8323be9486854fb3f34a5571198d" 484} 485 486# CN=QuoVadis Root CA 3, O=QuoVadis Limited, C=BM 487trust_anchors { 488 sha256_hex: "18f1fc7f205df8adddeb7fe007dd57e3af375a9c4d8d73546bf4f1fed1e18d35" 489} 490 491# CN=QuoVadis Root CA 2, O=QuoVadis Limited, C=BM 492# https://www.quovadis.bm/ 493trust_anchors { 494 sha256_hex: "85a0dd7dd720adb7ff05f83d542b209dc7ff4528f7d677b18389fea5e5c49e86" 495 ev_policy_oids: "2.23.140.1.1" 496} 497 498# CN=QuoVadis Root CA 3 G3, O=QuoVadis Limited, C=BM 499trust_anchors { 500 sha256_hex: "88ef81de202eb018452e43f864725cea5fbd1fc2d9d205730709c5d8b8690f46" 501} 502 503# CN=QuoVadis Root CA 1 G3, O=QuoVadis Limited, C=BM 504trust_anchors { 505 sha256_hex: "8a866fd1b276b57e578e921c65828a2bed58e9f2f288054134b7f1f4bfc9cc74" 506} 507 508# CN=QuoVadis Root CA 2 G3, O=QuoVadis Limited, C=BM 509# https://evsslicag3-v.quovadisglobal.com/ 510trust_anchors { 511 sha256_hex: "8fe4fb0af93a4d0d67db0bebb23e37c71bf325dcbcdd240ea04daf58b47e1840" 512 ev_policy_oids: "2.23.140.1.1" 513} 514 515# OU=Security Communication RootCA2, O=SECOM Trust Systems CO.,LTD., C=JP 516# https://www.secomtrust.net/contact/form.html 517trust_anchors { 518 sha256_hex: "513b2cecb810d4cde5dd85391adfc6c2dd60d87bb736d2b521484aa47a0ebef6" 519 # TODO(cclements,hchao): remove non-CABF OID once it is not used anymore. 520 ev_policy_oids: "1.2.392.200091.100.721.1" 521 ev_policy_oids: "2.23.140.1.1" 522} 523 524# OU=Security Communication RootCA1, O=SECOM Trust.net, C=JP 525trust_anchors { 526 sha256_hex: "e75e72ed9f560eec6eb4800073a43fc3ad19195a392282017895974a99026b6c" 527} 528 529# CN=COMODO Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB 530# https://secure.comodo.com/ 531trust_anchors { 532 sha256_hex: "1a0d20445de5ba1862d19ef880858cbce50102b36e8f0a040c3c69e74522fe6e" 533 ev_policy_oids: "2.23.140.1.1" 534} 535 536# CN=COMODO ECC Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB 537# https://comodoecccertificationauthority-ev.comodoca.com/ 538trust_anchors { 539 sha256_hex: "1793927a0614549789adce2f8f34f7f0b66d0f3ae3a3b84d21ec15dbba4fadc7" 540 ev_policy_oids: "2.23.140.1.1" 541} 542 543# CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US 544# https://usertrustecccertificationauthority-ev.comodoca.com/ 545trust_anchors { 546 sha256_hex: "4ff460d54b9c86dabfbcfc5712e0400d2bed3fbc4d4fbdaa86e06adcd2a9ad7a" 547 ev_policy_oids: "2.23.140.1.1" 548} 549 550# CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB 551# https://comodorsacertificationauthority-ev.comodoca.com/ 552trust_anchors { 553 sha256_hex: "52f0e1c4e58ec629291b60317f074671b85d7ea80d5b07273463534b32b40234" 554 ev_policy_oids: "2.23.140.1.1" 555} 556 557# CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, ST=Greater Manchester, C=GB 558trust_anchors { 559 sha256_hex: "d7a7a0fb5d7e2731d771e9484ebcdef71d5f0c3e0a2948782bc83ee0ea699ef4" 560} 561 562# CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US 563# https://usertrustrsacertificationauthority-ev.comodoca.com/ 564trust_anchors { 565 sha256_hex: "e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2" 566 ev_policy_oids: "2.23.140.1.1" 567} 568 569# CN=Secure Global CA, O=SecureTrust Corporation, C=US 570trust_anchors { 571 sha256_hex: "4200f5043ac8590ebb527d209ed1503029fbcbd41ca1b506ec27f15ade7dac69" 572 ev_policy_oids: "2.23.140.1.1" 573} 574 575# CN=Trustwave Global ECC P384 Certification Authority, O=Trustwave Holdings, Inc., L=Chicago, ST=Illinois, C=US 576trust_anchors { 577 sha256_hex: "55903859c8c0c3ebb8759ece4e2557225ff5758bbd38ebd48276601e1bd58097" 578 ev_policy_oids: "2.23.140.1.1" 579} 580 581# CN=Trustwave Global ECC P256 Certification Authority, O=Trustwave Holdings, Inc., L=Chicago, ST=Illinois, C=US 582trust_anchors { 583 sha256_hex: "945bbc825ea554f489d1fd51a73ddf2ea624ac7019a05205225c22a78ccfa8b4" 584 ev_policy_oids: "2.23.140.1.1" 585} 586 587# CN=Trustwave Global Certification Authority, O=Trustwave Holdings, Inc., L=Chicago, ST=Illinois, C=US 588trust_anchors { 589 sha256_hex: "97552015f5ddfc3c8788c006944555408894450084f100867086bc1a2bb58dc8" 590 ev_policy_oids: "2.23.140.1.1" 591} 592 593# CN=XRamp Global Certification Authority, O=XRamp Security Services Inc, OU=www.xrampsecurity.com, C=US 594trust_anchors { 595 sha256_hex: "cecddc905099d8dadfc5b1d209b737cbe2c18cfb2c10c0ff0bcf0d3286fc1aa2" 596 ev_policy_oids: "2.23.140.1.1" 597} 598 599# CN=SecureTrust CA, O=SecureTrust Corporation, C=US 600# https://www.securetrust.com 601# https://www.trustwave.com/ 602trust_anchors { 603 sha256_hex: "f1c1b50ae5a20dd8030ec9f6bc24823dd367b5255759b4e71b61fce9f7375d73" 604 ev_policy_oids: "2.23.140.1.1" 605} 606 607# CN=UCA Global G2 Root, O=UniTrust, C=CN 608trust_anchors { 609 sha256_hex: "9bea11c976fe014764c1be56a6f914b5a560317abd9988393382e5161aa0493c" 610} 611 612# CN=UCA Extended Validation Root, O=UniTrust, C=CN 613# https://rsaevg1.good.sheca.com/ 614trust_anchors { 615 sha256_hex: "d43af9b35473755c9684fc06d7d8cb70ee5c28e773fb294eb41ee71722924d24" 616 ev_policy_oids: "2.23.140.1.1" 617} 618 619# CN=SSL.com EV Root Certification Authority ECC, O=SSL Corporation, L=Houston, ST=Texas, C=US 620# https://test-ev-ecc.ssl.com/ 621trust_anchors { 622 sha256_hex: "22a2c1f7bded704cc1e701b5f408c310880fe956b5de2a4a44f99c873a25a7c8" 623 ev_policy_oids: "2.23.140.1.1" 624} 625 626# CN=SSL.com EV Root Certification Authority RSA R2, O=SSL Corporation, L=Houston, ST=Texas, C=US 627# https://test-ev-rsa.ssl.com/ 628trust_anchors { 629 sha256_hex: "2e7bf16cc22485a7bbe2aa8696750761b0ae39be3b2fe9d0cc6d4ef73491425c" 630 ev_policy_oids: "2.23.140.1.1" 631} 632 633# CN=SSL.com Root Certification Authority ECC, O=SSL Corporation, L=Houston, ST=Texas, C=US 634trust_anchors { 635 sha256_hex: "3417bb06cc6007da1b961c920b8ab4ce3fad820e4aa30b9acbc4a74ebdcebc65" 636} 637 638# CN=SSL.com Root Certification Authority RSA, O=SSL Corporation, L=Houston, ST=Texas, C=US 639trust_anchors { 640 sha256_hex: "85666a562ee0be5ce925c1d8890a6f76a87ec16d4d7d5f29ea7419cf20123b69" 641} 642 643# CN=SwissSign Gold CA - G2, O=SwissSign AG, C=CH 644# https://testevg2.swisssign.net/ 645trust_anchors { 646 sha256_hex: "62dd0be9b9f50a163ea0f8e75c053b1eca57ea55c8688f647c6881f2c8357b95" 647 ev_policy_oids: "2.23.140.1.1" 648} 649 650# CN=SwissSign Silver CA - G2, O=SwissSign AG, C=CH 651trust_anchors { 652 sha256_hex: "be6c4da2bbb9ba59b6f3939768374246c3c005993fa98f020d1dedbed48a81d5" 653} 654 655# CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW 656# https://evssldemo3.twca.com.tw/index.html 657trust_anchors { 658 sha256_hex: "59769007f7685d0fcd50872f9f95d5755a5b2b457d81f3692b610a98672f0e1b" 659 ev_policy_oids: "2.23.140.1.1" 660} 661 662# CN=TWCA Root Certification Authority, OU=Root CA, O=TAIWAN-CA, C=TW 663# https://evssldemo.twca.com.tw/index.html 664trust_anchors { 665 sha256_hex: "bfd88fe1101c41ae3e801bf8be56350ee9bad1a6b9bd515edc5c6d5b8711ac44" 666 ev_policy_oids: "2.23.140.1.1" 667} 668 669# CN=TeliaSonera Root CA v1, O=TeliaSonera 670trust_anchors { 671 sha256_hex: "dd6936fe21f8f077c123a1a521c12224f72255b73e03a7260693e8a24b0fa389" 672} 673 674# CN=Certum EC-384 CA, OU=Certum Certification Authority, O=Asseco Data Systems S.A., C=PL 675trust_anchors { 676 sha256_hex: "6b328085625318aa50d173c98d8bda09d57e27413d114cf787a0f5d06c030cf6" 677} 678 679# CN=Certum Trusted Root CA, OU=Certum Certification Authority, O=Asseco Data Systems S.A., C=PL 680trust_anchors { 681 sha256_hex: "fe7696573855773e37a95e7ad4d9cc96c30157c15d31765ba9b15704e1ae78fd" 682} 683 684# CN=D-TRUST BR Root CA 1 2020, O=D-Trust GmbH, C=DE 685trust_anchors { 686 sha256_hex: "e59aaa816009c22bff5b25bad37df306f049797c1f81d85ab089e657bd8f0044" 687} 688 689# CN=D-TRUST EV Root CA 1 2020, O=D-Trust GmbH, C=DE 690trust_anchors { 691 sha256_hex: "08170d1aa36453901a2f959245e347db0c8d37abaabc56b81aa100dc958970db" 692} 693 694# CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE 695trust_anchors { 696 sha256_hex: "cbb9c44d84b8043e1050ea31a69f514955d7bfd2e2c6b49301019ad61d9f5058" 697 ev_policy_oids: "2.23.140.1.1" 698} 699 700# CN=GlobalSign Root R46, O=GlobalSign nv-sa, C=BE 701trust_anchors { 702 sha256_hex: "4fa3126d8d3a11d1c4855a4f807cbad6cf919d3a5a88b03bea2c6372d93c40c9" 703 ev_policy_oids: "2.23.140.1.1" 704} 705 706# CN=GLOBALTRUST 2020, O=e-commerce monitoring GmbH, C=AT 707# https://testok-2020-server-qualified-ev-1.e-monitoring.at/ 708trust_anchors { 709 sha256_hex: "9a296a5182d1d451a2e37f439b74daafa267523329f90f9a0d2007c334e23c9a" 710 ev_policy_oids: "2.23.140.1.1" 711} 712 713# CN=HARICA TLS ECC Root CA 2021, O=Hellenic Academic and Research Institutions CA, C=GR 714# https://tls-ecc-valid-ev.root2021.harica.gr 715trust_anchors { 716 sha256_hex: "3f99cc474acfce4dfed58794665e478d1547739f2e780f1bb4ca9b133097d401" 717 ev_policy_oids: "2.23.140.1.1" 718} 719 720# CN=HARICA TLS RSA Root CA 2021, O=Hellenic Academic and Research Institutions CA, C=GR 721# https://tls-rsa-valid-ev.root2021.harica.gr 722trust_anchors { 723 sha256_hex: "d95d0e8eda79525bf9beb11b14d2100d3294985f0c62d9fabd9cd999eccb7b1d" 724 ev_policy_oids: "2.23.140.1.1" 725} 726 727# CN=HiPKI Root CA - G1, O=Chunghwa Telecom Co., Ltd., C=TW 728trust_anchors { 729 sha256_hex: "f015ce3cc239bfef064be9f1d2c417e1a0264a0a94be1f0c8d121864eb6949cc" 730} 731 732# CN=ISRG Root X2, O=Internet Security Research Group, C=US 733trust_anchors { 734 sha256_hex: "69729b8e15a86efc177a57afb7171dfc64add28c2fca8cf1507e34453ccb1470" 735} 736 737# CN=NAVER Global Root Certification Authority, O=NAVER BUSINESS PLATFORM Corp., C=KR 738trust_anchors { 739 sha256_hex: "88f438dcf8ffd1fa8f429115ffe5f82ae1e06e0c70c375faad717b34a49e7265" 740} 741 742# CN=Telia Root CA v2, O=Telia Finland Oyj, C=FI 743trust_anchors { 744 sha256_hex: "242b69742fcb1e5b2abf98898b94572187544e5b4d9911786573621f6a74b82c" 745} 746 747# CN=DigiCert TLS ECC P384 Root G5, O=DigiCert, Inc., C=US 748trust_anchors { 749 sha256_hex: "018e13f0772532cf809bd1b17281867283fc48c6e13be9c69812854a490c1b05" 750} 751 752# CN=DigiCert TLS RSA4096 Root G5, O=DigiCert, Inc., C=US 753trust_anchors { 754 sha256_hex: "371a00dc0533b3721a7eeb40e8419e70799d2b0a0f2c1d80693165f7cec4ad75" 755} 756 757# C = US, O = Certainly, CN = Certainly Root E1 758trust_anchors { 759 sha256_hex: "b4585f22e4ac756a4e8612a1361c5d9d031a93fd84febb778fa3068b0fc42dc2" 760} 761 762# C = US, O = Certainly, CN = Certainly Root R1 763trust_anchors { 764 sha256_hex: "77b82cd8644c4305f7acc5cb156b45675004033d51c60c6202a8e0c33467d3a0" 765} 766 767# CN=AC RAIZ FNMT-RCM SERVIDORES SEGUROS, organizationIdentifier=VATES-Q2826004J, OU=Ceres, O=FNMT-RCM, C=ES 768trust_anchors { 769 sha256_hex: "554153b13d2cf9ddb753bfbe1a4e0ae08d0aa4187058fe60a2b862b2e4b87bcb" 770} 771 772# CN=ANF Secure Server Root CA, OU=ANF CA Raiz, O=ANF Autoridad de Certificacion, C=ES, serialNumber=G63287510 773trust_anchors { 774 sha256_hex: "fb8fec759169b9106b1e511644c618c51304373f6c0643088d8beffd1b997599" 775} 776 777# CN=Security Communication ECC RootCA1, O=SECOM Trust Systems CO.,LTD., C=JP 778trust_anchors { 779 sha256_hex: "e74fbda55bd564c473a36b441aa799c8a68e077440e8288b9fa1e50e4bbaca11" 780} 781 782# CN=TunTrust Root CA, O=Agence Nationale de Certification Electronique, C=TN 783trust_anchors { 784 sha256_hex: "2e44102ab58cb85419451c8e19d9acf3662cafbc614b6a53960a30f7d0e2eb41" 785} 786 787# CN=vTrus ECC Root CA, O=iTrusChina Co.,Ltd., C=CN 788trust_anchors { 789 sha256_hex: "30fbba2c32238e2a98547af97931e550428b9b3f1c8eeb6633dcfa86c5b27dd3" 790} 791 792# CN=vTrus Root CA, O=iTrusChina Co.,Ltd., C=CN 793trust_anchors { 794 sha256_hex: "8a71de6559336f426c26e53880d00d88a18da4c6a91f0dcb6194e206c5c96387" 795} 796 797# C=DE, O=Atos, CN=Atos TrustedRoot Root CA ECC TLS 2021 798trust_anchors { 799 sha256_hex: "b2fae53e14ccd7ab9212064701ae279c1d8988facb775fa8a008914e663988a8" 800} 801 802# C=DE, O=Atos, CN=Atos TrustedRoot Root CA RSA TLS 2021 803trust_anchors { 804 sha256_hex: "81a9088ea59fb364c548a6f85559099b6f0405efbf18e5324ec9f457ba00112f" 805} 806 807# CN=Sectigo Public Server Authentication Root E46, O=Sectigo Limited, C=GB 808# https://sectigopublicserverauthenticationroote46-ev.sectigo.com/ 809trust_anchors { 810 sha256_hex: "c90f26f0fb1b4018b22227519b5ca2b53e2ca5b3be5cf18efe1bef47380c5383" 811 ev_policy_oids: "2.23.140.1.1" 812} 813 814# CN=Sectigo Public Server Authentication Root R46, O=Sectigo Limited, C=GB 815# https://sectigopublicserverauthenticationrootr46-ev.sectigo.com/ 816trust_anchors { 817 sha256_hex: "7bb647a62aeeac88bf257aa522d01ffea395e0ab45c73f93f65654ec38f25a06" 818 ev_policy_oids: "2.23.140.1.1" 819} 820 821# CN=SSL.com TLS ECC Root CA 2022, O=SSL Corporation, C=US 822# https://test-root-2022-ecc.ssl.com 823trust_anchors { 824 sha256_hex: "c32ffd9f46f936d16c3673990959434b9ad60aafbb9e7cf33654f144cc1ba143" 825 ev_policy_oids: "2.23.140.1.1" 826} 827 828# CN=SSL.com TLS RSA Root CA 2022, O=SSL Corporation, C=US 829# https://test-root-2022-rsa.ssl.com 830trust_anchors { 831 sha256_hex: "8faf7d2e2cb4709bb8e0b33666bf75a5dd45b5de480f8ea8d4bfe6bebc17f2ed" 832 ev_policy_oids: "2.23.140.1.1" 833}