Certification Hierarchy

SK ID Solutions is currently using 4 different certificate chains:

  • SK ID Solutions ROOT G1E (Elliptic Curve CA, active, issuing)
  • EE-GOVCA2018 (active, issuing)
  • SK ID Solutions ROOT G1R (RSA CA, not issuing, backup)
  • EE Certification Centre Root CA (not issuing, revocation only)

The relations between root certificates and their subordinate CAs and the services (end-entity) are shown on the following figures below.

SK ID Solutions ROOT G1E and ROOT G1R (2021-2041)

There are two ROOT G1 chains in parallel. One uses Elliptic Curve Cryptography (SK ID Solutions ROOT G1E) and other is based on RSA (SK ID Solutions ROOT GR).

SK ID Solutions ROOT G1E CA (ECC) is active issuing CA and associated intermediate CAs are used to issue end-entity certificates. 

RSA CA chain is not actively issuing any end-entity certificates.

For more info see SK Github.

EE-GOVCA2018 CHAIN (2018 – 2033)

EECCRCA CHAIN (2010 – 2030)

Intermediate CA’s ESTEID-SK 2015, KLASS3-SK 2016, EID-SK 2016 CA and NQ-SK 2016 are not issuing end-entity certificates.
Revocation service is available of valid certificates or until their expiry.