Certificates and useful links
Certification authorities and trust service components
To ensure the reliable validation of all trust services, both qualified and non-qualified, issued by “Evrotrust Technologies” AD, it is necessary to install and trust the certification hierarchy and related validation components, as outlined below:
- Root Certification Authorities (Root CAs) – One or more top-level CAs acting as trust anchors.
- Intermediate Certification Authorities (Intermediate CAs) – CAs that issue certificates to subordinate issuing CAs.
- Operating Certification Authorities (Operational CAs) – CAs that issue certificates to end-entities, including natural persons, legal entities, websites, and services.
- Signing Units (SU) – Electronic seal certificates used by the QTSP to deliver services such as time-stamping, validation, electronic delivery, etc.
- OCSP Responder Certificates (OCSP) – Certificates used exclusively to sign OCSP responses, in accordance with RFC 6960.
- Certificate Revocation Lists (CRLs) – Authoritative lists of revoked certificates, published regularly as required by applicable policy and in accordance with RFC 5280.
For reliable validation of our trust services, please ensure that the complete trust chain (Root, Intermediate, and Operational CA certificates), as well as current CRLs and OCSP responder certificates, are correctly installed and trusted in your systems.
I. Access to the electronic certificates registry
1. Certificates used by Evrotrust in its activities
- [Root CA] Evrotrust RSA Root CA
SHA256: 0xB49CF652B72E586498DB42CD007500912FD1672AFC3DFF0B11B927EA97D41A2D- [CRL] Evrotrust RSA Root CRL
- [OCSP] Evrotrust RSA Root CA OCSP
SHA256: 0x77D7A7B05EC6BEA6AD3C80EFDAB2C0CA769F239821659EE7A86BEBE631217F12
- [Operational CA] Evrotrust RSA Operational CA
SHA256: 0x6B2A9FD517A78AF2A62185F33457764FC91EBEE84A55F63F186278DCFDE68A75- [CRL] Evrotrust RSA Operational CA CRL
- [OCSP] Evrotrust RSA Operational CA OCSP
SHA256: 0x10DDCB60DCB2E600FA2ACE15DC79BEF9A3F2E6E375E2722CDBCE6319DD14968E
- [Operational CA] Evrotrust RSA QOperational CA 2024
SHA256: 0xFCBA8818597D593BF2D57B04CBD12DE5D232AD4640602DE44714B3128FFCE663- [CRL] Evrotrust RSA QOperational CA 2024 CRL
- [OCSP] Evrotrust RSA QOperational CA 2024 OCSP
SHA256: 0x0190A31070AAA04B124DC25102ACA1AA32730D0B450D23283842955D094B6126
- [Operational CA] Evrotrust Services CA
SHA256: 0x5C7AC0F5ADA82E251B4CB8D701A43A4A5BAF369289D4F29E27AB2690A88162EC- [CRL] Evrotrust Services CA CRL
- [OCSP] Evrotrust Services OCSP 2024
SHA256: 0x26650D3F5880E76D1E124A85A0B745EF141477D14073583879D606960EB64C8E
- [Operational CA] Evrotrust RSA REG.KE Operational CA 2025
SHA256: 0x693AE86123967F9AE3F9AD2512EF41DA40DF152C262507A74FAE6241E6605914- [CRL] Evrotrust RSA REG.KE Operational CA 2025 CRL
- [OCSP] Evrotrust RSA REG.KE Operational CA 2025 OCSP
SHA256: 0x8F0B8708C9B24B2505C0F24DD71E74297750FB533315066DD65FEBE8746321AF - [Cross-certificate] Evrotrust RSA REG.KE Operational CA 2025
SHA256: 0xC32F4019044CDF79B17FB1BA6E172B678432A7C4E8B1D871F969E172035DAE6F
- [Intermediate CA] Evrotrust RSA REG.KE Intermediate CA 2025
SHA256: 0xFE20C047580C501434D41C1411E464EB846EFDA65F27F4D660AB7F0F54CF9BC5- [CRL] Evrotrust RSA REG.KE Intermediate CA 2025 CRL
- [OCSP] Evrotrust RSA REG.KE Intermediate CA 2025 OCSP
SHA256: 0xAE94F90A3FC0EB97C1407097067A3BF2230E54A2C8668AF3E1753E040956DC87
- [Operational CA] Evrotrust RSA Advanced Operational CA 2025
SHA256: 0xD9673957ECA2DF4E106633D0A3036D3A2BFDA48CD12688D3E35561E6D3860DC2- [CRL] Evrotrust RSA Advanced Operational CA 2025 CRL
- Evrotrust RSA Advanced Operational CA 2025 OCSP
SHA256: 0x050B08994160002A7109F1B5A45440D82E6329E6EB2BBDE2826C661019FDDFB1
- [Signing Unit] Evrotrust Timestamp TSU 2024
SHA256: 0x42A1B2CFAADE274964DCD9C482EB9150FE33DE3CE41F79396E58A4F91196518F - [Signing Unit] Evrotrust Qualified Validation Service SU 2024
SHA256: 0x9A316F92F02ABD0A23224223BFC5079BB18D5DFE01C61E9305E01C9762198E43 - [Signing Unit] Evrotrust QERDS SU 2024
SHA256: 0xC061C60E9B60556C7B87439DACCDC935C5ECD190D42F84460FD4EA02463CAA77 - [Signing Unit] Evrotrust QREMS SU 2024
SHA256: 0xC5D9232C1ADD867E0121A20E28E9E6C76ECD4EC31292CB9EAAE74975EBEDA740 - [Signing Unit] Evrotrust QPSES SU 2024
SHA256: 0xEB7E513144A7FB7E543529E031B618B7C6C9FEBD3E6D02DAFBC35570EB609A90
Important: In order to download the certificates, you need to select “Save link as” from the context menu of the link.
Archive
Evrotrust Services OCSP
SHA256: 0x49F0685953E721A913494BB825833F0EF9E250D6516F0F6F338A790FEC1B9E29
Evrotrust Timestamp TSU
SHA256: 0xE6EA4EB4B13CBB2DC233DFB7C3C6164EFCE529B121F47541D5656449173218E1
Evrotrust QERDS SU
SHA256: 0x0479822A7D7985A1AA159090D5948AEDE330866F16EB50DB3C2C94651C3FD7A4
Evrotrust QREMS SU
SHA256: 0xC353EBF28B34B0910D7A74E1D0211CD4220A92002D166240A6BC4C923BCF78EE
Evrotrust QPSES SU
SHA256: 0xF3A87F31B7CB2F1963F768C7923DCFD9FA7C03B1DED36921379F259D9D8C3873
Evrotrust Qualified Validation Service
SHA256: 0xECC709818E0A04E56C00B835C586FF7EC66CE712F1A009F6C8B041F627F70E7B
Evrotrust Qualified Validation Service SU
SHA256: 0xC43E0882978F98CECA29360083AB1EA5A277740714E9C6DBCC023B1618D3549A
2. Access to issued certificates
To receive access to an issued certificate, please fill in the form here.
Application form for updating the access to an issued qualified certificate.
3. Certificate revocation list/CRL
The certificate revocation lists are downloadable, as follows:
- Evrotrust RSA Root CRL
- Evrotrust RSA Operational CA CRL
- Evrotrust RSA QOperational CA 2024 CRL
- Evrotrust Services CA CRL
- CRL Archive
Important: In order to download the CRL, you need to select “Save link as” from the context menu of the link.
II. Trust services
1. Certificate status verification service (OCSP)
Evrotrust provides a service to check the status of issued certificates in real time in an automated, reliable, free and efficient way. This service is available at any time and even after the period of validity of the certificates, based on Online Certificate Status Protocol (OCSP). Each relying party, when accepting a qualified certificate, can verify its real-time OCSP status at: http://ca.evrotrust.com/ocsp. The service is accessed through automated OCSP integration using a dedicated OCSP client, for example by using the OpenSSL library’s “ocsp” command. The result of the check is an issued certificate of status, which is electronically signed by Evrotrust and has legal value. The service is provided in accordance with the requirements of RFC2560.
2. Qualified electronic timestamp service
The Qualified electronic Timestamp service provides the user of the service in real time with a time stamp token (TST) that confirms the content of an electronic document at that time. The service is available for private use for non-commercial purposes under HTTP protocol at: http://ts.evrotrust.com/tsa, by using a dedicated Timestamp client, e.g. by using the OpenSSL library’s “ts” and the CURL library for transfer of the query to the service. The result is an issued time certificate, which is electronically signed by Evrotrust and has legal value. The service is provided in accordance with the requirements of RFC3161 and ETSI EN 319 422.
In order to use the service with a respective service level or in automated manner, it is necessary to sign an agreement with Evrotrust.
3. Qualified validation service for qualified electronic signatures and seals
Evrotrust provides a qualified validation service for qualified electronic signatures and seals in an automated and reliable manner. As a result of the validation process, the service produces a detailed report in PDF or XML format, according to the ETSI TS 119 102-2 requirements, describing the status, reason, date and time of the provided status, as well as additional data. The report is signed with a qualified electronic seal of Evrotrust. The service ensures that signatures and stamps are created and verified in accordance with European legislation. Evrotrust provides access to the validation service for private, non-commercial purposes at: https://validation.evrotrust.com.
In order to use the service with a respective service level or in automated manner, it is necessary to sign an agreement with Evrotrust.
4. Management (suspension, renewal and termination) of qualified certificates
5. Smart cards software
| Software | OS | Version | Download |
| Evrotrust Auto Installer (THALES) | MS Windows 11 64-bit | 1.0 | Download |
| Evrotrust Auto Installer (THALES) | macOS | 1.0 | Download |
| THALES software for smart cards Gemalto/Safenet | MS Windows 64-bit | 10.9-R3 | Download |
| THALES software for smart cards Gemalto/Safenet | MS Windows 32-bit | 10.9-R3 | Download |
| THALES software for smart cards Gemalto/Safenet | ARM64 | 10.9-R3 | Contact us |
| THALES software for smart cards Gemalto/Safenet | Linux | 10.9-R1 | Contact us |
| IDEMIA software for smart cards | MS Windows 64-bit | 5.3.4 SR1 | Download |
| IDEMIA software for smart cards | MS Windows 32-bit | 5.3.4 SR1 | Download |
| IDEMIA software for smart cards | macOS | 5.3.4 SR1 | Contact us |
| IDEMIA software for smart cards | Linux | 5.3.4 SR1 | Contact us |
| Charismatics software for smart cards | MS Windows 64-bit | 5.4.3 | Download |
| Charismatics software for smart cards | MS Windows 32-bit | 5.4.3 | Download |
| Charismatics software for smart cards | macOS | 5.4.3 | Contact us |
| Charismatics software for smart cards | Linux | 5.4.3 | Contact us |
Important:
- The Signatory/Creator must always use a licensed and up-to-date version of the smart card software. The current versions provided by Evrotrust are listed on this page.
6. Expiry date of the certification of smart cards/devices for secure signature/seal creation (SSCD) offered by Evrotrust Technologies AD:
| Name of device for secure creation of electronic signature/seal (SSCD) | Expiry date of the certification |
|---|---|
| Thales/Gemalto: ID Prime 940C / IAS Classic v5.2 on MultiApp V5.0 platform | 04/11/2031 |
Important:
- Smart cards/devices for securely creating a qualified electronic signature/seal (SSCD) must not be used after the expiry date of the certification, as in this case the electronic signatures/seals created with their use no longer meet the requirements of eIDAS. This period refers solely to the validity of the certification of the device as an SSCD and does not refer to the warranty or the technical service life of the smart card itself;
- The full list of all Qualified Signature/Seal Creation Devices and Secure Signature Creation Devices used in EU countries and their expiry date can be found here: https://esignature.ec.europa.eu/efda/notification-tool/#/screen/browse/list/QSCD_SSCD.

