Certificates and useful links

Certification authorities and trust service components

To ensure the reliable validation of all trust services, both qualified and non-qualified, issued by “Evrotrust Technologies” AD, it is necessary to install and trust the certification hierarchy and related validation components, as outlined below:

  • Root Certification Authorities (Root CAs) – One or more top-level CAs acting as trust anchors.
  • Intermediate Certification Authorities (Intermediate CAs) – CAs that issue certificates to subordinate issuing CAs.
  • Operating Certification Authorities (Operational CAs) – CAs that issue certificates to end-entities, including natural persons, legal entities, websites, and services.
  • Signing Units (SU) – Electronic seal certificates used by the QTSP to deliver services such as time-stamping, validation, electronic delivery, etc.
  • OCSP Responder Certificates (OCSP) – Certificates used exclusively to sign OCSP responses, in accordance with RFC 6960.
  • Certificate Revocation Lists (CRLs) – Authoritative lists of revoked certificates, published regularly as required by applicable policy and in accordance with RFC 5280.

For reliable validation of our trust services, please ensure that the complete trust chain (Root, Intermediate, and Operational CA certificates), as well as current CRLs and OCSP responder certificates, are correctly installed and trusted in your systems.

I. Access to the electronic certificates registry

1. Certificates used by Evrotrust in its activities

Important: In order to download the certificates, you need to select “Save link as” from the context menu of the link.

Archive

Evrotrust Services OCSP
SHA256: 0x49F0685953E721A913494BB825833F0EF9E250D6516F0F6F338A790FEC1B9E29

Evrotrust Timestamp TSU
SHA256: 0xE6EA4EB4B13CBB2DC233DFB7C3C6164EFCE529B121F47541D5656449173218E1

Evrotrust QERDS SU
SHA256: 0x0479822A7D7985A1AA159090D5948AEDE330866F16EB50DB3C2C94651C3FD7A4

Evrotrust QREMS SU
SHA256: 0xC353EBF28B34B0910D7A74E1D0211CD4220A92002D166240A6BC4C923BCF78EE

Evrotrust QPSES SU
SHA256: 0xF3A87F31B7CB2F1963F768C7923DCFD9FA7C03B1DED36921379F259D9D8C3873

Evrotrust Qualified Validation Service
SHA256: 0xECC709818E0A04E56C00B835C586FF7EC66CE712F1A009F6C8B041F627F70E7B

Evrotrust Qualified Validation Service SU
SHA256: 0xC43E0882978F98CECA29360083AB1EA5A277740714E9C6DBCC023B1618D3549A

2. Access to issued certificates

To receive access to an issued certificate, please fill in the form here.

Application form for updating the access to an issued qualified certificate.

3. Certificate revocation list/CRL

The certificate revocation lists are downloadable, as follows:

Important: In order to download the CRL, you need to select “Save link as” from the context menu of the link.

II. Trust services

1. Certificate status verification service (OCSP)

Evrotrust provides a service to check the status of issued certificates in real time in an automated, reliable, free and efficient way. This service is available at any time and even after the period of validity of the certificates, based on Online Certificate Status Protocol (OCSP). Each relying party, when accepting a qualified certificate, can verify its real-time OCSP status at: http://ca.evrotrust.com/ocsp. The service is accessed through automated OCSP integration using a dedicated OCSP client, for example by using the OpenSSL library’s “ocsp” command. The result of the check is an issued certificate of status, which is electronically signed by Evrotrust and has legal value. The service is provided in accordance with the requirements of RFC2560.

2. Qualified electronic timestamp service

The Qualified electronic Timestamp service provides the user of the service in real time with a time stamp token (TST) that confirms the content of an electronic document at that time. The service is available for private use for non-commercial purposes under HTTP protocol at: http://ts.evrotrust.com/tsa, by using a dedicated Timestamp client, e.g. by using the OpenSSL library’s “ts” and the CURL library for transfer of the query to the service. The result is an issued time certificate, which is electronically signed by Evrotrust and has legal value. The service is provided in accordance with the requirements of RFC3161 and ETSI EN 319 422.

In order to use the service with a respective service level or in automated manner, it is necessary to sign an agreement with Evrotrust.

3. Qualified validation service for qualified electronic signatures and seals

Evrotrust provides a qualified validation service for qualified electronic signatures and seals in an automated and reliable manner. As a result of the validation process, the service produces a detailed report in PDF or XML format, according to the ETSI TS 119 102-2 requirements, describing the status, reason, date and time of the provided status, as well as additional data. The report is signed with a qualified electronic seal of Evrotrust. The service ensures that signatures and stamps are created and verified in accordance with European legislation. Evrotrust provides access to the validation service for private, non-commercial purposes at: https://validation.evrotrust.com.

In order to use the service with a respective service level or in automated manner, it is necessary to sign an agreement with Evrotrust.

4. Management (suspension, renewal and termination) of qualified certificates

5. Smart cards software

SoftwareOSVersionDownload
Evrotrust Auto Installer (THALES)MS Windows 11 64-bit1.0Download
Evrotrust Auto Installer (THALES)macOS1.0Download
THALES software for smart cards Gemalto/SafenetMS Windows 64-bit10.9-R3Download
THALES software for smart cards Gemalto/SafenetMS Windows 32-bit10.9-R3Download
THALES software for smart cards Gemalto/SafenetARM6410.9-R3Contact us
THALES software for smart cards Gemalto/SafenetLinux10.9-R1Contact us
IDEMIA software for smart cardsMS Windows 64-bit5.3.4 SR1Download
IDEMIA software for smart cardsMS Windows 32-bit5.3.4 SR1Download
IDEMIA software for smart cardsmacOS5.3.4 SR1Contact us
IDEMIA software for smart cardsLinux5.3.4 SR1Contact us
Charismatics software for smart cardsMS Windows 64-bit5.4.3Download
Charismatics software for smart cardsMS Windows 32-bit5.4.3Download
Charismatics software for smart cardsmacOS5.4.3Contact us
Charismatics software for smart cardsLinux5.4.3Contact us

Important:

  • The Signatory/Creator must always use a licensed and up-to-date version of the smart card software. The current versions provided by Evrotrust are listed on this page.

6. Expiry date of the certification of smart cards/devices for secure signature/seal creation (SSCD) offered by Evrotrust Technologies AD:

Name of device for secure creation of electronic signature/seal (SSCD)Expiry date of the certification
Thales/Gemalto:
ID Prime 940C / IAS Classic v5.2 on MultiApp V5.0 platform
04/11/2031

Important:

  • Smart cards/devices for securely creating a qualified electronic signature/seal (SSCD) must not be used after the expiry date of the certification, as in this case the electronic signatures/seals created with their use no longer meet the requirements of eIDAS. This period refers solely to the validity of the certification of the device as an SSCD and does not refer to the warranty or the technical service life of the smart card itself;
  • The full list of all Qualified Signature/Seal Creation Devices and Secure Signature Creation Devices used in EU countries and their expiry date can be found here: https://esignature.ec.europa.eu/efda/notification-tool/#/screen/browse/list/QSCD_SSCD.

Looking for the best trust services to digitize your business?

Evrotrust’s reliable, well-rounded toolkit will meet all digitization needs your company faces.

Happy office workers