Skip to content

Chain of Trust

(Last update: March 12, 2021)

Root Certificate

Our root certificates are stored offline and only used to issue intermediate certificates, physically present.

  • Active:
    • CASTLE Root RR1 (RSA 4096, C = ES, O = CASTLE Platform, CN = CASTLE Root RR1 CA): der, pem, txt
  • Inactive:
    • CASTLE Root RSA (RSA 4096, C = ES, O = CASTLE Platform, CN = CASTLE Root RSA CA): der, pem, txt

Intermediate certificates

Intermediate certificates are used to issue client or final certificates. IREX intermediates are used for signing ACME Email certificates. IRVX are used for signing VPN certificates.

  • Active:
    • CASTLE IRE1 (RSA 2048, C = ES, O = CASTLE Platform, CN = IRE1): der, pem, txt
    • CASTLE IRV1 (RSA 2048, C = ES, O = CASTLE Platform, CN = IRV1): der, pem, txt
  • Inactive:
    • CASTLE S1 (RSA 4096, C = ES, O = CASTLE Platform, CN = CASTLE S1 CA): der, pem, txt
    • CASTLE V1 (RSA 4096, C = ES, O = CASTLE Platform, CN = CASTLE V1 CA): der, pem, txt