Peppol PKI 2025 - Certificate Authorities

Peppol PKI 2025 - Certificate Authorities

Glossary

Abbreviation

Meaning

Abbreviation

Meaning

AP

Access Point

CA

Certificate Authority

G2

Refers to the legacy generation of the Peppol PKI

G3

Refers to the next generation of the Peppol PKI

PKI

Public Key Infrastructure

PROD

Production environment

SMP

Service Metadata Publisher

TEST

Test environment

Purpose & Scope

This page documents the Peppol PKI 2025 hierarchy and the certificate authorities (CAs) that form it. Execution steps for migrating from G2 → G3 are covered in the PKI Migration Plan 2025.

Summary

This table summarises the CAs that are expected to be entrusted as part of the Peppol PKI 2025.

The “In Service” column is the date from when the CA needs to be entrusted in its designated service area.

Legacy G2 CAs remain trusted until a decommission date is announced in the PKI Migration Plan 2025.

Environment

Type

Service

In Service

File

File MD5 hash

SHA256 Certificate Fingerprint

Environment

Type

Service

In Service

File

File MD5 hash

SHA256 Certificate Fingerprint

PROD

Root CA

-

2026-01-01

ce7fdd24392f324c56553bdccad4a557

B6:07:5B:9F:86:55:E7:56:77:7F:18:2D:14:07:C0:04:94:42:D3:A2:F5:7D:FF:97:81:52:38:28:F3:31:F2:11

PROD

Intermediate CA

Peppol AP

2026-01-01

dbead09e15dd17abc04e4b2a34613c20

B6:5E:37:5A:58:26:AD:A1:65:17:B2:AA:8A:88:1B:6F:CA:FF:5E:48:E7:55:9B:9E:96:BB:A5:C6:49:21:F9:00

PROD

Intermediate CA

Peppol SMP

2026-01-01

e9c0ef135499e0db6e0c3f3b4c83539f

D9:E1:74:67:C6:9E:51:FC:4F:5C:52:63:54:2F:C6:8D:2A:BB:A5:DF:AA:E6:2E:87:FB:D6:82:9F:1D:E6:21:C4

TEST

Root CA

-

2025-07-01

fde9d752044c674b9a5cfb5a26a4e0f3

8B:4E:0E:5D:C7:C8:20:8C:BA:88:ED:EB:FA:D3:1E:06:47:40:D8:96:AB:6E:18:DE:0B:03:38:6F:D2:4B:E7:34

TEST

Intermediate CA

Peppol AP

2025-07-01

157c68b5b006098dfb2346211a15bebb

D2:44:5A:0F:11:5E:E6:4C:C1:41:A8:49:FE:14:29:27:FE:57:01:B7:D9:B5:8D:3E:6F:53:99:31:62:11:5C:C0

TEST

Intermediate CA

Peppol SMP

2025-07-01

602caf96fd0303872ccf9283f965ca6c

EB:78:DA:BB:62:2B:BC:70:15:92:F0:85:BC:27:AB:81:7F:E1:C0:D4:75:3A:E8:29:68:2E:81:27:B3:B0:0C:E7

To verify the SHA256 Certificate Fingerprint the following command can be used (adopt the filename to the actual one):

openssl x509 -in PEPPOL_Root_TEST_CA-G3.pem -noout -sha256 -fingerprint

PKI Hierarchy Overview

The PROD and TEST hierarchy is mirrored so that all production scenarios can be verified using a test setup.

PROD

image-20250612-220512.png

TEST

image-20250612-220545.png

Certificate Authorities (detailed)

Detailed summary of each one of the CAs.

PROD CAs

PROD - Root CA - G3

Filename: PEPPOL_Root_CA-G3.pem MD5 File Hash: ce7fdd24392f324c56553bdccad4a557 SHA256 Fingerprint: B6:07:5B:9F:86:55:E7:56:77:7F:18:2D:14:07:C0:04:94:42:D3:A2:F5:7D:FF:97:81:52:38:28:F3:31:F2:11

Issuer: C=BE, O=OpenPEPPOL AISBL, CN=PEPPOL Root CA - G3 Common Name: PEPPOL Root CA - G3 Organization: OpenPEPPOL AISBL Organization Unit: Country / Region: BE State: Locality: Signature Algorithm: sha256WithRSA Valid from: January 14, 2025 19:01:10 Valid to: January 14, 2035 18:59:40 Serial number: 22C4013475D4B7E0972B9CD7633ADD244AFC01C0 OCSP URL: None CRL URL: None Key Usage: Digital Signature, Certificate Sign, CRL Sign Basic Constraints: CA:TRUE Subject Key Identifier: CC:EE:8C:EC:A2:92:9E:49:BB:5F:84:3F:B6:69:24:46:55:7E:AD:66
-----BEGIN CERTIFICATE----- MIIFXDCCA0SgAwIBAgIUIsQBNHXUt+CXK5zXYzrdJEr8AcAwDQYJKoZIhvcNAQEL BQAwRjELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEE9wZW5QRVBQT0wgQUlTQkwxHDAa BgNVBAMTE1BFUFBPTCBSb290IENBIC0gRzMwHhcNMjUwMTE0MTgwMTEwWhcNMzUw MTE0MTc1OTQwWjBGMQswCQYDVQQGEwJCRTEZMBcGA1UEChMQT3BlblBFUFBPTCBB SVNCTDEcMBoGA1UEAxMTUEVQUE9MIFJvb3QgQ0EgLSBHMzCCAiIwDQYJKoZIhvcN AQEBBQADggIPADCCAgoCggIBAMjkcoKwACKWUNAsyeOf8AU6hQGi4CRaJV5N7LnV XL1AxJ6S2oBT/NxIaoF4ZBLxGqz3sTZyvb+rswlpSUNwY8+gkFHOmIo9PFsVk8jB T3/W73ZGxHzR4sXGmiN3asmP0zWWrSO9rADzThEBKwc4lJBhhUI6Y8KKp/vZvjHX XuXVs7iaruQbfRUOnRGDvevEkJ+Ns8LxOivq8TXMB106BhwuCm0AE97rkZBNqX4W naUm9fDaW/nUpUV3DkcJGMXw7MypxrxWjesxbLjTkV5bcJHzIbLQo02IsQik1VF3 ttPlpJ0omCQ23AKFzTlVOKo+1rp+gmaYhJPv95J92oU+nBuMQNgIanObWaGUPkM0 xfsn0BtcOeYtSWZna1MRdryJiPdoWzrwulPUf5OzbU8pctPQM9UEa2gZ8YEDOiYi 6k2FQ8WAcYJcsvUenQNkMKvdclOE0RWAoVWlYWOSh6eNEwS3V0SpEeAmYmwsPXQH ij63RRYN7KFH3umdsnewxau8CYypkrWT4abGfZWhTVUzs7Zc6eC00a8zsra19U12 F1uAfRKASCxWAjauWVkoXS7lWZ7QAj9ROKF4M4EdszWS/+7vhTV0bP6DwrGgQ1ea ei05UoPQDAGqViOYkZXU7fiuItYBhtvlwtvfe4Qt9OFe6Ekb7MxURDJX7/yXCWeS y9SBAgMBAAGjQjBAMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFMzujOyikp5J u1+EP7ZpJEZVfq1mMA4GA1UdDwEB/wQEAwIBhjANBgkqhkiG9w0BAQsFAAOCAgEA Y/R05/0me44zDd6Pc1TMWHNn/J1vC6ydp8kpZ1mNLgwh8QlnxI0FcPmIoXLDFaP8 lTbHIZ+ImmKoKrhhI4C1JKDuytgNh8YuTZqCvwyJKzjGEqXVJyju6y76/tBZcdl8 p42Clvfs5Jm+4GwPGjSVbbaOAO9gisvTuJJ11p9coe48YpbZOqJCMLhAUgzv5Uuu DCb79eoTUv30P61vBsRVukkm8CO6v6Y1uEzDPJNcwYq9flNY78hCexqRIzUcZHxr AELFFvcMcxyAyKJ7PvlPlGNzHVZfkt3sPLj0KT4zbOkCrK3TJEMe8N2VVH6fsGEo 3nrGlk8fJpVVymGStNgdqWIoZlH52xIQy9jICgTKGhZRzjZ+rGlg8i/Scz8DtS6Z Ba8on9iHRSiNvPmeF0pEm8Uh5q4KeD+S03YeuCdqyR2obsm9/lZxc151577AKoma D3GaS6yrl4xICiAyBjANFD6AqnmuVxnj0Ifsg+wHNITExbSav8EjhczfvQkj+ZCH ZPaQX39SrvXqjaHrBOgBzV9Bm2N3Q9h4b+Vvvy14gyYKF86367kWMSgBdRzanYQh sMt/xlo48vQKBHimL7kZBuAairWnYTeBsgDv4Vh2EiOTBlUIsGHThHJ5wKnaI6qP TkzxlPjeEjaGIVTYD7ZYAzKrFUvnW+tYK2XiH+leObc= -----END CERTIFICATE----- 

PROD - Peppol Access Point CA - G3

Filename: PEPPOL_ACCESS_POINT_CA-G3.pem MD5 File Hash: dbead09e15dd17abc04e4b2a34613c20 SHA256 Fingerprint: B6:5E:37:5A:58:26:AD:A1:65:17:B2:AA:8A:88:1B:6F:CA:FF:5E:48:E7:55:9B:9E:96:BB:A5:C6:49:21:F9:00

Issuer: C=BE, O=OpenPEPPOL AISBL, CN=PEPPOL Root CA - G3 Common Name: PEPPOL ACCESS POINT CA - G3 Organization: OpenPEPPOL AISBL Organization Unit: None Country / Region: BE State: None Locality: None Signature Algorithm: sha256WithRSA Valid from: January 14, 2025 19:04:51 Valid to: January 13, 2035 18:59:40 Serial number: 331F6542DB4398F91A14EFA798B28EF39BF49EFA OCSP URL: http://ocsp.one.nl.digicert.com CRL URL: http://crl.one.nl.digicert.com/PEPPOLRootCA-G3.crl Key Usage: Digital Signature, Certificate Sign, CRL Sign Basic Constraints: CA:TRUE, pathlen:1 Subject Key Identifier: FC:32:56:48:AB:CB:C1:B8:F9:83:9A:2F:80:0B:28:CC:F7:FF:EA:D1
-----BEGIN CERTIFICATE----- MIIGUjCCBDqgAwIBAgIUMx9lQttDmPkaFO+nmLKO85v0nvowDQYJKoZIhvcNAQEL BQAwRjELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEE9wZW5QRVBQT0wgQUlTQkwxHDAa BgNVBAMTE1BFUFBPTCBSb290IENBIC0gRzMwHhcNMjUwMTE0MTgwNDUxWhcNMzUw MTEzMTc1OTQwWjBOMQswCQYDVQQGEwJCRTEZMBcGA1UEChMQT3BlblBFUFBPTCBB SVNCTDEkMCIGA1UEAxMbUEVQUE9MIEFDQ0VTUyBQT0lOVCBDQSAtIEczMIICIjAN BgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAnYHtmOL395qTaKVqRSzhjyVew/IZ Wlaz+2fS4Xhyzn32TNHuoj+UeTk2Xj/wPtynZ96re9eCTYCHRsSPvtOgoS/kIF6K hiFuZTFl/3QwNgeTDu2oFaWjEJZzRGopL7QXBQ2LHHRKUFrDctfT6bQlEu5qUOKk U8jE91tP3j79rFcwzMgOnWRtWikbdLYAPQCk4ROwWPqP8V2UNbqx4IleGkkVGKWA sZr5ZrQB9N5WxH3wpbUZAI2EaJ80I9PAGp72OJPuxFOHxll8r99u67i1rDAOilvl Lspze/u7xFuv7AnxyAhW/J6QJ1bsykno37ClwIPo3Fa9xulbuj3awd6f/KYJIrmr ArhgCn1QzK3l7jZ+f5RcROP4Ejx++Y40i8y7H3xsnfQfbcTVGCM3pYJJTLWbzcwt Hnw/jyqVbJXpkwSgqaGM42m8imghdioZPvvbtL4r/mKTHwtcG8DT0KbIB+kwnO1m 2Z487WWsX/MhfAXYjRvPT1BjvpDP170veZwGiqm7/PuiJl99lUxSSccjF5me3n2o 7kawE/FBBfkZYZGSr3asJkuIn1IUvBQPc1S2I3PkU2TfqLaDrWqidG4PbgzsMu8L UzWTQrfAcijm1NJAbjkSYA72Lrr8cUIp/bowoJoUasby3UTby/sYuY0eLOpT90ik O3t0xKlazzwRrx0CAwEAAaOCAS4wggEqMBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYD VR0OBBYEFPwyVkiry8G4+YOaL4ALKMz3/+rRMB8GA1UdIwQYMBaAFMzujOyikp5J u1+EP7ZpJEZVfq1mMA4GA1UdDwEB/wQEAwIBhjB/BggrBgEFBQcBAQRzMHEwKwYI KwYBBQUHMAGGH2h0dHA6Ly9vY3NwLm9uZS5ubC5kaWdpY2VydC5jb20wQgYIKwYB BQUHMAKGNmh0dHA6Ly9jYWNlcnRzLm9uZS5ubC5kaWdpY2VydC5jb20vUEVQUE9M Um9vdENBLUczLmNydDBDBgNVHR8EPDA6MDigNqA0hjJodHRwOi8vY3JsLm9uZS5u bC5kaWdpY2VydC5jb20vUEVQUE9MUm9vdENBLUczLmNybDANBgkqhkiG9w0BAQsF AAOCAgEARh7lWcI/Zw7kopkddKuN4puJp1ZjhHV773HdithdvI28Mo81tjUbOWFU PPeiGFeR31+h+G5lzWkmo+xH/gpnMRIzoj85URKxoaNDiBWDqWBjhCTR6b/6bOtK KMSsdcpJzyP7GMXMWzFQIjmqpvOQFU/Xt3fZYoSqsVHlAzuenbidhUKti91LjVg/ aWgJXKH4bbqdL6X5dZblVE4uqWzwUfryVMJkNVD6y2FWOj3pNz0fT6QQDIQih8iV E3fNlW3YykKyGE86lLYvafs5xDJga1Kepaoy5puNgrUTSd0Bhc6yEb4ImdlOegXB C+ycKqHslMKrzm69IRsUtxPxlGMOxB8hnRhjFdGwIVktjG3MD8amet7dGOsXravz lJpr4Lz1b94Ie0BvCkfpFyARgTdJj7pC2efA13jdeBqhPgaEgcjqBaqe8ZcI/HqZ Mls70LTz+Ry8y8FngXbFobf7I3ZWow0wUZG22FDhj94qd+LY8rjTYMQGsAyWc/Hh Be32cYNjxCdtw/LVhbG6p+QoXgGWC12Mq84Uinr46f9aewZ66oqrMIc297tX9wvY +IwHAVort2ScCnokQS4eXkOYbkgC6cXtcR8dcuv75rgvNkJ/SB1F8b94QGht5UQe ROxR0ofeQqQCtVxF9HEucpQssF/wJSs04f+CAt1vTFGeIvcbMvA= -----END CERTIFICATE-----

PROD - Peppol Service Metadata Publisher CA - G3

Filename: PEPPOL_SERVICE_METADATA_PUBLISHER_CA-G3.pem MD5 File Hash: e9c0ef135499e0db6e0c3f3b4c83539f SHA256 Fingerprint: D9:E1:74:67:C6:9E:51:FC:4F:5C:52:63:54:2F:C6:8D:2A:BB:A5:DF:AA:E6:2E:87:FB:D6:82:9F:1D:E6:21:C4

Issuer: C=BE, O=OpenPEPPOL AISBL, CN=PEPPOL Root CA - G3 Common Name: PEPPOL SERVICE METADATA PUBLISHER CA - G3 Organization: OpenPEPPOL AISBL Organization Unit: None Country / Region: BE State: None Locality: None Signature Algorithm: sha256WithRSA Valid from: January 14, 2025 19:10:48 Valid to: January 13, 2035 18:59:40 Serial number: 4B475A54F3187AB330E5508A7C9170C179E8ABA1 OCSP URL: http://ocsp.one.nl.digicert.com CRL URL: http://crl.one.nl.digicert.com/PEPPOLRootCA-G3.crl Key Usage: Digital Signature, Certificate Sign, CRL Sign Basic Constraints: CA:TRUE, pathlen:1 Subject Key Identifier: 1D:DC:C2:85:5C:56:83:CD:E8:08:C7:FA:92:93:43:C5:E1:F6:8E:D1
-----BEGIN CERTIFICATE----- MIIGYDCCBEigAwIBAgIUS0daVPMYerMw5VCKfJFwwXnoq6EwDQYJKoZIhvcNAQEL BQAwRjELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEE9wZW5QRVBQT0wgQUlTQkwxHDAa BgNVBAMTE1BFUFBPTCBSb290IENBIC0gRzMwHhcNMjUwMTE0MTgxMDQ4WhcNMzUw MTEzMTc1OTQwWjBcMQswCQYDVQQGEwJCRTEZMBcGA1UEChMQT3BlblBFUFBPTCBB SVNCTDEyMDAGA1UEAxMpUEVQUE9MIFNFUlZJQ0UgTUVUQURBVEEgUFVCTElTSEVS IENBIC0gRzMwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDVmMiHUchr dLqW8Rl0x/xR5Hq9WJpXrwlpM3EBl+7Zg4bZF2tiBoxG0FuUtqU4MvJ9xpckQE/d 97X6WqwFoY4vO3sht7VWdPG6tnsHSZG3OUKHTEjQxbJzMATP+R9S5UCz/FqwZviD sLTbxdXJGWG5FNEATPur4F1zji1QXZzihfT89sPehVy+S0uGkH+tpL3q/UcCVOQD 4fFDgmBYR007rBMr6Rs5Z3pwUE7q5xM5dIBEN6Y1fw9TKQeQOpTAw0agdZGf7J4N oXihrljP6N1o5N1D6SupFeNx8RqIhZ+HBV99qM1vXJFVALBHvRZbRqiJi863/wZL pRD/ZzDnNG6YTTmw+1ZSm15rBdX7XBmtvjcrzBr660deZjBKJo8IzWNGk38th2Kr GC3uMsbQfHOdPkcLmdq/bOn199xsaVj/9Y3jPUz+nUj3aB3ackOq7Gd8b+J5u/Z1 FvKj3BicFSjOFa4F9uMAlQ1/oRIwsnYkXL/YFewhcnf7//4dlXIJmgwCYxufWgQ+ M+xuLMSoxMv00+GEN8i7ob8R3xek/Zs7QwAVe4X7OfqqcO3ep80SAuWRDWj+S8tT 01J+PyvvwjcqJ+DH9hwsAtchiYUmgxfj43nks3kq1CsxDogLouK13XW9purettj2 L1wxVpH5F5WzvCQa28EY0SZc5kIaEazGtQIDAQABo4IBLjCCASowEgYDVR0TAQH/ BAgwBgEB/wIBATAdBgNVHQ4EFgQUHdzChVxWg83oCMf6kpNDxeH2jtEwHwYDVR0j BBgwFoAUzO6M7KKSnkm7X4Q/tmkkRlV+rWYwDgYDVR0PAQH/BAQDAgGGMH8GCCsG AQUFBwEBBHMwcTArBggrBgEFBQcwAYYfaHR0cDovL29jc3Aub25lLm5sLmRpZ2lj ZXJ0LmNvbTBCBggrBgEFBQcwAoY2aHR0cDovL2NhY2VydHMub25lLm5sLmRpZ2lj ZXJ0LmNvbS9QRVBQT0xSb290Q0EtRzMuY3J0MEMGA1UdHwQ8MDowOKA2oDSGMmh0 dHA6Ly9jcmwub25lLm5sLmRpZ2ljZXJ0LmNvbS9QRVBQT0xSb290Q0EtRzMuY3Js MA0GCSqGSIb3DQEBCwUAA4ICAQCyCfSUH/bBWcZEe2vtq+NgQpVD4NXKkmnCsUNx TGtwbBxPdHZQd8xctFxaN8UFIr5EQl3/QZtIGsQ6d+bVlxjkuA8XBnSM0ztGdZ0g RgRrgUKG+2vdb5mZ4ceenc4VnT1pCran8K9sjuVa1Qhv65ZEyHCSbrG4ib5i07Zq TQADT/ORsDmJ5iEWjLbvmUxXgbCfPqd72SGhWbADTPS09IuTClrbrA0r3d5nKsqA rRM+IvUCM2UbRMgGV5zd0vI+0WC1I+kfd7kHJccvkr16wxYKN0kEZDhwdugOyPeL LXJ8u4KYWJTFCFTQvhpm2uZ74IjJltOTBaowf+CLiBAEnyK5sP1SDeEy3iLExtiW Dtasdz9JLx1OnrqNwjS8dTtSTcagJg4kLUXWT6a2B4wuiETufOQWtZ8Z1RBJwFLO zwTd7LjEMONXf5t4HRFt6e7eORmWzapyMUxjddhXJ4PVr2RVXf3E3yCry6YIWvzV DJ/rbbqXH56/+k7zwzpGwEFcraZaqlWemaQuYuNgY4FzhejWsOKhymjL021fSJuM XFxEWgktxAezCqm1nhvKWHPZwtax6yDyKHQ/SnUJkRnmExD9klpOpgmbH7SqWdXc 5fub9xFh3OgmCgGsrWgvTB6gvys9YjYBzlR6GCzxolZSuLz6EfE4ZedEd+m/gaHC IaAEQg== -----END CERTIFICATE-----

TEST CAs

TEST - Root CA - G3

Filename: PEPPOL_Root_TEST_CA-G3.pem MD5 File Hash: fde9d752044c674b9a5cfb5a26a4e0f3 SHA256 Fingerprint: 8B:4E:0E:5D:C7:C8:20:8C:BA:88:ED:EB:FA:D3:1E:06:47:40:D8:96:AB:6E:18:DE:0B:03:38:6F:D2:4B:E7:34

Issuer: C=BE, O=OpenPEPPOL AISBL, OU=FOR TEST ONLY, CN=PEPPOL Root TEST CA - G3 Common Name: PEPPOL Root TEST CA - G3 Organization: OpenPEPPOL AISBL Organization Unit: FOR TEST ONLY Country / Region: BE State: None Locality: None Signature Algorithm: sha256WithRSA Valid from: January 14, 2025 18:49:55 Valid to: January 14, 2035 18:47:39 Serial number: 617E487C47F71E24EF891DD094693CE85E85051E OCSP URL: None CRL URL: None Key Usage: Digital Signature, Certificate Sign, CRL Sign Basic Constraints: CA:TRUE Subject Key Identifier: 6E:54:8D:E4:12:2E:BB:FE:20:68:CC:3F:57:B8:50:05:6E:5E:7C:C4
-----BEGIN CERTIFICATE----- MIIFljCCA36gAwIBAgIUYX5IfEf3HiTviR3QlGk86F6FBR4wDQYJKoZIhvcNAQEL BQAwYzELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEE9wZW5QRVBQT0wgQUlTQkwxFjAU BgNVBAsTDUZPUiBURVNUIE9OTFkxITAfBgNVBAMTGFBFUFBPTCBSb290IFRFU1Qg Q0EgLSBHMzAeFw0yNTAxMTQxNzQ5NTVaFw0zNTAxMTQxNzQ3MzlaMGMxCzAJBgNV BAYTAkJFMRkwFwYDVQQKExBPcGVuUEVQUE9MIEFJU0JMMRYwFAYDVQQLEw1GT1Ig VEVTVCBPTkxZMSEwHwYDVQQDExhQRVBQT0wgUm9vdCBURVNUIENBIC0gRzMwggIi MA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQC+q+EpAlKZoWP8KZhGGKCCSdsg oP7TUrcDwOfHXi/KZlRpH/vNU/MLaKMZVSzplpgGQoUo4zBruQ85lTGCTzIYmqsQ J108WkcCHAKYi/TfVg90VxU6g9mtdQ5wRwu8sjnEjjWzOzn2uD7lhTNKlIBK40Fe 5ZDCDcnSLOSOkZfvF6BIv97MnYiVTiV35cA7fKFC9a8Vn+c/3roLAai1OWqVX2D5 1GyLA3tP7uLgDlIn74cwCLWs8byTUvn6UTpkKqkfVlhdpVvpINofUdYRP9VnAz7C iJSMQKEm0Ddil53pLwnfq53CCwly09a7qVvOxWFOWLH/h/XyW95johSIJUa5KBJW NsviJmTrJBBuHn51tLQGXoHB8bbq29f7knEWt4GmgzYYXOyrGi8bUDFblgIib4AN Fu6+qal3S2PwbedQzW2ExVkDGqWYB0I6xPqw4FjAkyDR5RIZwVfh1OvCI+0pTnBS ZjJJhkjzJqvhEtWnZZE+U1BPlKyf9s/TIJESEesFEGxfnOI+sxwa3+dA5NindPPn amDA1+1RacIKcABJrdx0CdH4ZoIo5jTcwKmgPgiVZthibxNVYqmwm+UIHtlkon9L Q0DU2ChiC625zRTF+dYSxgY/erxlT+MHGqf+C7nJTr0SxTqeUiDhzDXWfSmcqEGg iTMc3isTk3th5UKE5wIDAQABo0IwQDAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW BBRuVI3kEi67/iBozD9XuFAFbl58xDAOBgNVHQ8BAf8EBAMCAYYwDQYJKoZIhvcN AQELBQADggIBAHskOTT6fMRsixR2C42NOcspc4dSl87CxoBP+1ntvoNO8Cr9GwRN ki5e8cgrPU3Cub8yFCJzPe56fXE63HeUknoyWzohK7Kqb7Ow278TNbWyC6iZ82bM QbdWPlfjvEtKtmVga8u1aHelWC4GhKs+G5zU81fqN1JzYQMkbYv3d0bhlPlxkBXJ jkltwvaLm1wGQlwcGwKu4Dn47ogq/adS+oumT5E0PcY1rIZbi6rc3mNZfyh0axP4 pNKhTO24CEN2SBtE2Bv1o6GdNxmiTjY+kxdzLwY4sRfUX0GFbIEoCkRhnOjs2gsR X+y/x2hvvJaxqbJE04fapUf36F1rR07o8XcP72IKzI1hZPnfqKtNs7GWIizZpKCz NGCKKXRpSEC7YVrtEsLK3pSH+yCkRWKadclIIg2RNnoeAoJlaVbijb434hqmD+L2 rQOTkImHF06nWqTOGfO8QfkUjwxl2h424BhLE/sgI+3jWWThjvymNA2FGIwLD+wG 2B7cuqlRQ9VRbcpa1VeRhozyLFZffnUkGR5aWpw7EKt4TORBwEawU9TaI7g0hGkl I73GYCM5QWwIAIlAvR7hboli20iu4QkrclHqoDsS0+2Cn61sQX5NMXVEKyBLe3c3 txIEvEdT+lep1u01xHKfJO6oJxQQK88tcLB/+28Cis2jpR9H3TSy6oHd -----END CERTIFICATE-----

TEST - Peppol Access Point CA - G3

Filename: PEPPOL_ACCESS_POINT_TEST_CA-G3.pem MD5 File Hash: 157c68b5b006098dfb2346211a15bebb SHA256 Fingerprint: D2:44:5A:0F:11:5E:E6:4C:C1:41:A8:49:FE:14:29:27:FE:57:01:B7:D9:B5:8D:3E:6F:53:99:31:62:11:5C:C0

Issuer: C=BE, O=OpenPEPPOL AISBL, OU=FOR TEST ONLY, CN=PEPPOL Root TEST CA - G3 Common Name: PEPPOL ACCESS POINT TEST CA - G3 Organization: OpenPEPPOL AISBL Organization Unit: FOR TEST ONLY Country / Region: BE State: None Locality: None Signature Algorithm: sha256WithRSA Valid from: January 14, 2025 18:53:02 Valid to: January 13, 2035 18:47:39 Serial number: 6F186FE4393249F2158E572631C71BDE8840E774 OCSP URL: http://ocsp.one.nl.digicert.com CRL URL: http://crl.one.nl.digicert.com/PEPPOLRootTESTCA-G3.crl Key Usage: Digital Signature, Certificate Sign, CRL Sign Basic Constraints: CA:TRUE, pathlen:1 Subject Key Identifier: B3:CC:44:EF:76:AF:81:C9:DF:F3:5F:A5:9E:88:71:AD:9F:A0:F7:70
-----BEGIN CERTIFICATE----- MIIGlTCCBH2gAwIBAgIUbxhv5DkySfIVjlcmMccb3ohA53QwDQYJKoZIhvcNAQEL BQAwYzELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEE9wZW5QRVBQT0wgQUlTQkwxFjAU BgNVBAsTDUZPUiBURVNUIE9OTFkxITAfBgNVBAMTGFBFUFBPTCBSb290IFRFU1Qg Q0EgLSBHMzAeFw0yNTAxMTQxNzUzMDJaFw0zNTAxMTMxNzQ3MzlaMGsxCzAJBgNV BAYTAkJFMRkwFwYDVQQKExBPcGVuUEVQUE9MIEFJU0JMMRYwFAYDVQQLEw1GT1Ig VEVTVCBPTkxZMSkwJwYDVQQDEyBQRVBQT0wgQUNDRVNTIFBPSU5UIFRFU1QgQ0Eg LSBHMzCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAJ5+YqcELAJJlH96 2mIVx0e+inbirHX5T+0fzPjuq7MK8C+GllA9v+Za1pYyc8BuwcRO5m9NF4WPVAjY wr9DtAXLFVAd89ft6awNOWzj8mbn/sIGhq0aFm4dwcg4bQhBLYDKg1KL1tm0keFE bhVGbEelG6Lx21TGfqBuGJZwJfdsWwWTgnGcqKbqsN4td8ASbgyQkBuQT+fffIxD sNo30yBHtQARCAFQDULLtkOtRuKNn55xae4E1q6yaLL6PDPd21KbsZV6tDWqDY4A xBDsXkTyl7c9Mehw/hH0r0sp83D7RlBj3qTj1p8xqCxrKzQtr3ffZqPaQOD1Sb6g l+6nV653IxKmNe2VHhbagMH2dsG6/5RffJaI6mlbL5Nr2yczA5EoGFBwqRZHe9w7 9VbWXk9r52RzZqNkpL1HRUYsApi1vKSXy9cop/eCnK6unSoMatQ695oTp5j0D1y9 X13rc+slHBc2beDj7ytSIEjLjobVnkCFyN58FSROD45xR8BKiIG+/oPFE9KYh6Vj EtLiM+itd/X4xIEQwmHfP3lTxZYtKSLzI8eM5EutmBZWpWdOzFfyGt22Qq7zxtxz htA3fBApQHhsirbh1doWXhJO4TGkXJUT+OCqMMFRyKiSw/cjFNXiGN8RgWlia7W8 UvVDfUBdYbngKogtpLvmYmI20kaxAgMBAAGjggE3MIIBMzASBgNVHRMBAf8ECDAG AQH/AgEBMB0GA1UdDgQWBBSzzETvdq+Byd/zX6WeiHGtn6D3cDAfBgNVHSMEGDAW gBRuVI3kEi67/iBozD9XuFAFbl58xDAOBgNVHQ8BAf8EBAMCAYYwgYMGCCsGAQUF BwEBBHcwdTArBggrBgEFBQcwAYYfaHR0cDovL29jc3Aub25lLm5sLmRpZ2ljZXJ0 LmNvbTBGBggrBgEFBQcwAoY6aHR0cDovL2NhY2VydHMub25lLm5sLmRpZ2ljZXJ0 LmNvbS9QRVBQT0xSb290VEVTVENBLUczLmNydDBHBgNVHR8EQDA+MDygOqA4hjZo dHRwOi8vY3JsLm9uZS5ubC5kaWdpY2VydC5jb20vUEVQUE9MUm9vdFRFU1RDQS1H My5jcmwwDQYJKoZIhvcNAQELBQADggIBAEmODwQ9D8igiTxfA08yR4Lyo66dTvt6 9Nl5bMSfOyegJVzZdu+BBxIVb+aSnFNyjt2yDoAJSXGqIAK5WSZ3W9ok+RkxgqT4 vkAGyrLZDJHcUo6VRWlv3QmKuvSTIfVrmN7reG3i6xCZyb1HtBrvV2L1BvV4t+zR 8b2yvTxew581Y3kGuXopmsFiE29fntd8xI6gHzKWeLSY6HgnRzj+KN+xQrmVERUQ SD9Rztg/if6CbYtlwIhOxNmnG0fJMGBgN6ELYW6WDqHoj1d0G1PmGA+IoPMCWW/U PsarMqwYG/1TpxY55ukBip2XZQfkZ4ws2UmZmVU5WVjkVGIu7ocs9nI/fI5N9WxZ k6g/s3HXkyvKT+ebIERJm9o0DB7dq7ZUBBUskAy7lvc80EeuJUS8TUhYol0MculY kL0qqSbr1DJCdSASNzOjHQ8c+EjG4oOHIhpNnA2ZV0FaTZfpIiVII8IT5h8Sr5Cp jcijTbzRIiC/5+MaS+TLc2SNOml2y0iI8h65zInBXQIKBMqQ2CC0Lz52FfZI3QnQ Os8YanFT1H7w3AzJ4ZvMNyugHuSUJOnDmjZZ0iGdkTACdet4iqlEKm6igSpryVGu IeLinavXfO803JP67A9MnwIVgUXWOFkDUrA/YC4clz0s+Ep8J2ClcDGQNK0/IA3O K/YPl6iVIyQg -----END CERTIFICATE-----

TEST - Peppol Service Metadata Publisher CA - G3

Filename: PEPPOL_SERVICE_METADATA_PUBLISHER_TEST_CA-G3.pem MD5 File Hash: 602caf96fd0303872ccf9283f965ca6c SHA256 Fingerprint: EB:78:DA:BB:62:2B:BC:70:15:92:F0:85:BC:27:AB:81:7F:E1:C0:D4:75:3A:E8:29:68:2E:81:27:B3:B0:0C:E7

Issuer: C=BE, O=OpenPEPPOL AISBL, OU=FOR TEST ONLY, CN=PEPPOL Root TEST CA - G3 Common Name: PEPPOL SERVICE METADATA PUBLISHER TEST CA - G3 Organization: OpenPEPPOL AISBL Organization Unit: FOR TEST ONLY Country / Region: BE State: None Locality: None Signature Algorithm: sha256WithRSA Valid from: January 14, 2025 18:58:38 Valid to: January 13, 2035 18:47:39 Serial number: 692058C4551F4556DD1535C23293EC78084B4197 OCSP URL: http://ocsp.one.nl.digicert.com CRL URL: http://crl.one.nl.digicert.com/PEPPOLRootTESTCA-G3.crl Key Usage: Digital Signature, Certificate Sign, CRL Sign Basic Constraints: CA:TRUE, pathlen:1 Subject Key Identifier: 57:D8:4F:38:97:6C:D5:4B:97:47:E4:1D:32:BF:68:9B:05:A4:48:6B
-----BEGIN CERTIFICATE----- MIIGozCCBIugAwIBAgIUaSBYxFUfRVbdFTXCMpPseAhLQZcwDQYJKoZIhvcNAQEL BQAwYzELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEE9wZW5QRVBQT0wgQUlTQkwxFjAU BgNVBAsTDUZPUiBURVNUIE9OTFkxITAfBgNVBAMTGFBFUFBPTCBSb290IFRFU1Qg Q0EgLSBHMzAeFw0yNTAxMTQxNzU4MzhaFw0zNTAxMTMxNzQ3MzlaMHkxCzAJBgNV BAYTAkJFMRkwFwYDVQQKExBPcGVuUEVQUE9MIEFJU0JMMRYwFAYDVQQLEw1GT1Ig VEVTVCBPTkxZMTcwNQYDVQQDEy5QRVBQT0wgU0VSVklDRSBNRVRBREFUQSBQVUJM SVNIRVIgVEVTVCBDQSAtIEczMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKC AgEAwSXXzEzRb0Qvn+5ByItKGXY4vlsqIT6jFJ3C/u1mRIcJF6zkNsJIJtnyBGWP i5IDEkq5/ytJCyETM3HZNgn58k9v9jQMheQBdSRjXbKfaLAGsqK4ZNnUgOV2l6mq ClLJDnDmrcDsx+eQYQizIM7ah1d4VsneGX+3nD6AyJkyGUsMPFihPMeBZ7S3b/uN R3s/x6KCFafotnUmZ/St/tpOXUed97FZl3al36JZ+BRFCV4MqIDAMq0a5SyvjLHf cLSp7j45FOsKU9qU0DLpRCnF39BltdOHTtPAzz5Js+HFA/6k7qrt+dfSBwJDwXKe rL+gA2kUS9nMQV0tMmiUSfhEqxwfl+ldR0zQyytx3BNPEznjAK+1RWVPAgGQSy77 O8EInfzHGjXcp7UbTl2uUnw0iVCkNvbzqR4849r3KFtgMjbHh0AFjBXkUXpvSdKA 8dGQH7HVMB6uRWd4wdyVLGzPupMr5Z5DcEc/7YTjBXyGifpuu27T5n2MYL1r9S2N fb2aBjGIZ+m84TYyoTVpaiqslIPzuPovoGY/qSzkmY7Hxmo531Blj5p93qcm25mT TgpUTeAgp1tfM6ZV5hsgjweVBKTCHUlgyIGrcFomBbnFhC7ASL9R8lWQMLiYdNdC S7nFXI7heFRWBFtVhlVcxte2mHJ5TtLzdbAdh58AORLNgEcCAwEAAaOCATcwggEz MBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYDVR0OBBYEFFfYTziXbNVLl0fkHTK/aJsF pEhrMB8GA1UdIwQYMBaAFG5UjeQSLrv+IGjMP1e4UAVuXnzEMA4GA1UdDwEB/wQE AwIBhjCBgwYIKwYBBQUHAQEEdzB1MCsGCCsGAQUFBzABhh9odHRwOi8vb2NzcC5v bmUubmwuZGlnaWNlcnQuY29tMEYGCCsGAQUFBzAChjpodHRwOi8vY2FjZXJ0cy5v bmUubmwuZGlnaWNlcnQuY29tL1BFUFBPTFJvb3RURVNUQ0EtRzMuY3J0MEcGA1Ud HwRAMD4wPKA6oDiGNmh0dHA6Ly9jcmwub25lLm5sLmRpZ2ljZXJ0LmNvbS9QRVBQ T0xSb290VEVTVENBLUczLmNybDANBgkqhkiG9w0BAQsFAAOCAgEAE+qJqwbEUaYX MSWbJRZOEEXB8yAmQjk3zWICIqO+8t/aT7ZyF4s1Ht7seNFs73vPgCpWfq0+u9Cu yPMfWckssW7BasKGgK6u6YJbQopTamA9tlnB/+QsTanqh0gsodjZbFvQS5khY/G2 gjqLhOsfW/B0T9SCI7p0uLjmh1SycRMb8cF2/2TIqHcw8H/uUAaehm46mMhtlUMi /XbDCIYogF6g2q08yAOeHzSL/KEaRECLjgYWZ104MULGFdwybC6C0+MPsnM9SBcp LwP4/EUkW06uBFGMHsa6dMbuTUI6QaHBBIEs7DEs0saNzBStW2tPs2Qj4I6IUlTe aRJCaCMGK9SoPDEUpVJ6R/L7K2ZbTVkFT5N8vIIzhuutKSTQ7c9FOn1WMJN2WzPu pViaWBFii9vl9U5GEDTmbTGKasttTht5ob9DBC2Ji2Qv7KFyfZd1uAhB+amLieUW ZRnrGuiMP5uIWaxCgFy4Xef3z+5BMNQlXBC6O2tt7dzhcrGx9cg4YP5VlJIeQ7ee HxqeyIbASYBCClwdYUvzN0bxoHyXL/ZvPQPV+wGyTGALpwHGTRf21ixq2Ny6XZyP 79XtVdEnmQJJRm15UHc0QbRTyTjJx/udFw/H5HB7+u1sHKb6abIVKLCuAqaU/xYb 4mOAGMLUomVPSjyE3/77Rh0fMKjZol0= -----END CERTIFICATE-----