CA Certificates
Which certificates do I need?
In most browsers, you probably only need to “Browser Import” the Root certificate (trusting it to sign web certificates) into the Trusted Roots section of your certificate store and you’ll then be able to access websites whose certificates are signed by our eScience CAs.
RPM Package installs for these certificates are avaliable from the EUGridPMA repository
IGTF-accredited UK eScience CA Certificates
Frequently Asked Questions
Q: What are the SHA-1 fingerprints?
These can be used to prove that the certificate you have received is the correct one. Note that you also have to trust the source of the fingerprint which is why they should be provided on different servers. The example below shows that the two eScience Root CA files are for the same certificate
$ # openssl v1.X.Y
$ openssl x509 -in 7ed47087.0 -noout -fingerprint -sha1
SHA1 Fingerprint=59:7C:1A:AA:EC:65:7E:4A:F5:6A:00:1F:E2:16:44:48:96:35:DB:B1
$ openssl x509 -in 7ed47087.0 -noout -fingerprint -sha256
SHA256 Fingerprint=76:F3:A5:94:2E:22:01:2D:7E:10:E1:1B:41:6F:B2:EE:A2:1D:8F:45:83:F2:D2:FC:79:9B:D4:CE:D0:21:03:23