česky | english
New and archived (obsoleted) CAcert Roots
New Root Certificates
Because they are nowadays actively disabled by operating systems and applications, older MD5 signed certificates are not of any help to access a website with HTTPS. As a rule of thumb, this is generally by now a poor idea to download and install any certificate with "MD5" labelled on it. Deprecation of MD5 algorithm for PKI purposes started in 2011; since the end of 2016, MD5 cannot be used at all for X.509 operations.
In order to address this challenge, CAcert re-signed its Root CA and Class 3 Root certificates, with the modern and secure SHA256 hash function. CAcert's Root SHA256-signed certificates remained otherwise unchanged (same keys, same validity period), exceptions being an updated serial number and the new signature. They are fully compatible with all certificates issued by CAcert previously.
20190410: the SHA256 signed root certificates, both Class 1 and Class 3, were placed to the CAcert operating server (http://www.cacert.org/index.php?id=3). Their filenames for download are: root_X0F (Class 1 root) and class3_X0E (intermediate Class 3 root). The hex. number following "X" is the unique serial number of the certificate, thus 00000F and 00000E, respectively. CAcert users are advised to substitute both older certificates (with serial numbers 000000 and 0A418A) with these new ones. |
This page also gives here below access to "refreshed" SHA256-signed Class 1 root certificate (#00000F), which replaces the old Class 1 root certificate MD5-signed (#000000). Please use the "refreshed" SHA256-signed Class 1 root certificate definitely since 2018-01-01. This page also offers access to the new intermediate Class 3 root certificate (#00000E) replacing the old intermediate Class 3 root (#0A418A). You can find an explanation and the procedure here.
Want to smoothly replace an obsolete MD5 signed certificate by an up-to-date SHA256 signed one ? The procedure is here.
How can I import the root certificate? See Import Root Cert, Browser Clients, and e-Mail Clients
SHA256 CAcert root signed using the SHA256 algorithm: for Windows - PEM format, for OS.X, iOS and Linux - PEM format, binary - DER format
- Class 1 root, signing algorithm SHA256, serial number 00000F
fingerprint SHA1 = dd:fc:da:54:1e:75:77:ad:dc:a8:7e:88:27:a9:8a:50:60:32:52:a5
Important note: After you have installed the SHA256 signed CAcert root certificate (#00000F), don't forget to delete the MD-5 signed CAcert root certificate (#000000)!
- Class 1 root, signing algorithm SHA256, serial number 00000F
SHA256 CAcert Intermediate root signed using the SHA256 algorithm: for Windows, for OS.X, iOS, and Linux - PEM format, binary - DER format
- Class 3 root, signing algorithm SHA256, serial number 00000E
fingerprint SHA1 = A7:C4:8F:BE:6B:02:6D:BD:0E:C1:B4:65:B8:8D:D8:13:EE:1D:EF:A0
Note: After you have installed the SHA256 signed CAcert root certificate (#00000E), don't forget to delete the CAcert Class 3 Intermediate root certificate (serial #0A418A).
- Class 3 root, signing algorithm SHA256, serial number 00000E
SHA256 CAcert Roots in one package, valid at 01.12.2018: CAcert_chain_X0F_X0E.pem, contains roots:
- Class 1 Root, signing algorithm SHA256, serial number 00000F
fingerprint SHA1 = DD:FC:DA:54:1E:75:77:AD:DC:A8:7E:88:27:A9:8A:50:60:32:52:A5
Important note: After you have installed the SHA256 signed CAcert root certificate (#00000F), don't forget to delete the MD-5 signed CAcert root certificate (#000000)!
- Class 3 Root, signing algorithm SHA256, serial number 00000E
fingerprint SHA1 = A7:C4:8F:BE:6B:02:6D:BD:0E:C1:B4:65:B8:8D:D8:13:EE:1D:EF:A0
Note: After you have installed the SHA256 signed CAcert Class 3 root certificate (#00000E), don't forget to delete the CAcert Class 3 Intermediate root certificate (#0A418A).
- Class 1 Root, signing algorithm SHA256, serial number 00000F
obsolete: CAcert Roots in one package, valid at September 04, 2015: CAcert_chain.pem, contains roots:
Class 1 Root, signing algorithm MD-5, serial number 000000; disabled by main browsers and operating systems since 20170101
fingerprint SHA1 = 13:5C:EC:36:F4:9C:B8:E9:3B:1A:B2:70:CD:80:88:46:76:CE:8F:33
- Class 3 Root, signing algorithm SHA256, serial number 0A418A
fingerprint SHA1 = AD:7C:3F:64:FC:44:39:FE:F4:E9:0B:E8:F4:7C:6C:FA:8A:AD:FD:CE
Where can I find the root certificate in a format that is suitable to append it to /usr/share/ssl/certs/ca-bundle.crt?
SHA256 cacert-bundle_X0F_X0E.crt - Class 1 (#00000F) and Class 3 (#00000E), both SHA256 signed
Important note: After you have installed the SHA256 signed CAcert root certificate (#00000F), don't forget to delete the MD-5 signed CAcert root certificate (#000000)! Note: After you have installed the SHA256 signed CAcert Class 3 root certificate (#00000E), don't forget to delete the CAcert Class 3 Intermediate root certificate (#0A418A).
obsolete: cacert-boundle.crt - Class 1 (#000000) and Class 3 (#000001) certificates, both MD-5 signed); disabled by main browsers and operating systems since 20170101
SHA256 Installable package for Windows - CAcert_Root_Certificates_X0F_X0E.msi - Class 1 (#00000F) and Class 3 (#00000E) certificates, both SHA256 signed - procedure