Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Tip
titleInCommon Certificate Service SSO and MFA Available

The use of single sign-on and multifactor authentication for accessing the Comodo Certificate Manager is available to any subscriber that also operates an Identity Provider in the InCommon Federation. See this wiki page for details.

InCommon Certificate Types

This page includes links to technical documents and service endpoints for each of the certificate types issued by the InCommon Certificate Service.

Contents:

Table of Contents

...

Anchor
ssl-certs
ssl-certs

...

SSL/TLS Certificates

SHA-2 Server Certificates

The intermediate CA known as the InCommon RSA Server CA, which uses the SHA-2 hash algorithm, was deployed on February 1September 22, 2011. Prior to that date, SSL/TLS end-entity certificates were signed by the COMODO High Assurance Secure Server CA2014.


Tip

To test the freshness of the CRL, type the following command:

$ curl -s http://crl.incommon.org/InCommonServerCA.crl | openssl crl -inform DER -noout -lastupdate -nextupdate

Anchor
ev-certs
ev-certs

Extended Validation SSL/TLS Certificates

Extended Validation (EV) SSL/TLS Certificates became available on March 10, 2011.

  • Certificate Chain:

    HTML
    
    <br><span style="margin-left: 3em; line-height: 150%"><a href="https://support.comodo.com/index.php?_m=downloads&_a=viewdownload&downloaditemid=10&nav=0,1">AddTrust External CA Root</a> [<a href="https://www.incommon.org/cert/repository/AddTrustExternalCARoot.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/AddTrustExternalCARoot.pem">PEM</a>]</span>
    
    <br><span style="margin-left: 5em; line-height: 150%"><a href="https://support.comodo.com/index.php?_m=downloads&_a=viewdownload&downloaditemid=104&nav=0,1,22">COMODO Certification Authority</a> [<a href="https://www.incommon.org/cert/repository/COMODOAddTrustServerCA.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/COMODOAddTrustServerCA.pem">PEM</a>]</span>
    
    <br><span style="margin-left: 7em; line-height: 150%">InCommon Server CA"><a href="https://support.comodo.com/index.php?_m=downloads&_a=viewdownload&downloaditemid=103&nav=0,1,22">COMODO Extended Validation Secure Server CA</a> [<a href="https://www.incommon.org/cert/repository/InCommonServerCACOMODOExtendedValidationSecureServerCA.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/InCommonServerCACOMODOExtendedValidationSecureServerCA.pem">PEM</a>]</span>
    
    <br><span style="margin-left: 7em9em; line-height: 150%">End-Entity Certificate</span>
    


  • Intermediate CA Apache Bundle for EV SSL/TLS Certificates
  • Certification Practices Statement for EV SSL/TLS Certificates
  • Certificate Profile for EV SSL/TLS Certificates
  • Certificate Revocation List:

    HTML
    http://crl.incommoncomodoca.orgcom

    /

    InCommonServerCA

    COMODOExtendedValidationSecureServerCA.crl

  • Online Certificate Status Protocol:

    HTML
    http://ocsp.comodoca.com


IGTF Server Certificates

InCommon offers IGTF server certificates for use by subscribers who are also active with the IGTF grid community. Note: Unless you are running a server as part of the IGTF grid (see the IGTF website) these certificates are NOT what you need. Request a normal InCommon server certificate instead.

The intermediate CA known as the InCommon IGTF Server CA was deployed on July 7, 2014.

  • Certificate Chain:
    • AddTrust External CA Root
    • COMODO RSA Certification Authority [DER]
    • InCommon IGTF Server CA [DER]
    • End-Entity Certificate

Anchor
evclient-certsev
client-certs

Extended Validation SSL/TLS Certificates

Client Certificates

SHA-2 Standard Assurance Client Certificates

The intermediate CA known as the InCommon RSA Standard Assurance Client CA was deployed on September 18, 2014Extended Validation (EV) SSL/TLS Certificates became available on March 10, 2011.

    • Certificate Chain:
HTML

...

<br><span style="margin-left: 3em; line-height: 150%"

...

>AddTrust External CA Root [<a href="https://

...

www.

...

incommon.org/cert/repository/AddTrustExternalCARoot.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/AddTrustExternalCARoot.pem">PEM</a>]</span>

<br><span style="margin-left: 5em; line-height: 150%">USERTrust RSA Certification Authority [<a href="https://www.incommon.org/cert/repository/USERTrustRSAClient_CA.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/USERTrustRSAClient_CA.pem">PEM</a>]</span>

<br><span style="margin-left: 7em; line-height: 150%">InCommon RSA Standard Assurance Client CA [<a href="https://www.incommon.org/cert/repository/

...

InCommonRSAStandardAssuranceClientCA.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/

...

InCommonRSAStandardAssuranceClientCA.pem">PEM</a>]</span>

<br><span style="margin-left: 9em; line-height: 150%">End-Entity Certificate</span>
    • Intermediate CA Bundle for Standard Client Certificates
    • Certification Practices Statement for Standard Client Certificates
    • Certificate Revocation List:

      HTML
      http://crl.incommon-rsa.org/InCommonRSAStandardAssuranceClientCA.crl


    • Online Certificate Status Protocol:

      HTML
      http://ocsp.incommon-rsa.org



SHA-1 Standard Assurance Client Certificates (deprecated)

The intermediate CA known as the InCommon Standard Assurance Client CA was deployed on March 10, 2011.

    • Certificate Chain:

      HTML
      <br><span style="margin-left: 
  • 5em
    • 3em; line-height: 150%"><a href="https://support.comodo.com/index.php?_m=downloads&_a=viewdownload&downloaditemid=
  • 104
    • 10&nav=0,1
  • ,22
    • "
  • >COMODO
    • >AddTrust External 
  • Certification
    • CA 
  • Authority<
    • Root</a> [<a href="https://www.incommon.org/cert/repository/
  • COMODOAddTrustServerCA
    • AddTrustExternalCARoot.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/
  • COMODOAddTrustServerCA
    • AddTrustExternalCARoot.pem">PEM</a>]</span>
      
      <br><span style="margin-left: 
  • 7em
    • 5em; line-height: 150%"><a href="https://support.comodo.com/index.php?_m=downloads&_a=viewdownload&downloaditemid=
  • 103
    • 114&nav=0,1
  • ,22">COMODO Extended Validation Secure Server CA</a>
    • ">UTN-USERFirst-Client Authentication and Email</a> [<a href="https://www.incommon.org/cert/repository/UTNAddTrustClient_CA.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/UTNAddTrustClient_CA.pem">PEM</a>]</span>
      
      <br><span style="margin-left: 7em; line-height: 150%">InCommon Standard Assurance Client CA [<a href="https://www.incommon.org/cert/repository/
  • COMODOExtendedValidationSecureServerCA
    • InCommonStandardAssuranceClientCA.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/
  • COMODOExtendedValidationSecureServerCA
    • InCommonStandardAssuranceClientCA.pem">PEM</a>]</span>
      
      <br><span style="margin-left: 9em; line-height: 150%">End-Entity Certificate</span>
      


  • Apache
  • EV SSL/TLS
  • EV SSL/TLS
    • Standard Client Certificates
    • Certificate Profile for
  • EV SSL/TLS
    • Standard Client Certificates
    • Certificate Revocation List:

      HTML
      http://crl.
  • comodoca
    • incommon.
  • com
    • org/
  • COMODOExtendedValidationSecureServerCA
    • InCommonStandardAssuranceClientCA.crl


    • Online Certificate Status Protocol:

      HTML
      http://ocsp.
  • comodoca
    • incommon.
  • com
    • org


Anchor

...

code-signing-certs

...

code-signing-certs

Client Certificates

...

Code-signing Certificates

The intermediate CA known as the InCommon RSA Code Signing CA (SHA-2) was deployed on September 19, 2014.


The intermediate CA known as the InCommon

...

Code Signing CA (SHA-1) was deployed on

...

June 30, 2011.

    • Certificate Chain:

      HTML
    • <br><span style="margin-left: 3em; line-height: 150%"><a href="https://support.comodo.com/index.php?_m=downloads&_a=viewdownload&downloaditemid=10&nav=0,1">AddTrust External CA Root</a> [<a href="https://www.incommon.org/cert/repository/AddTrustExternalCARoot.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/AddTrustExternalCARoot.pem">PEM</a>]</span>
      
      <br><span style="margin-left: 5em; line-height: 150%"><a href="https://support.comodo.com/index.php?_m=downloads&_a=view&parentcategoryid=
  • viewdownload
    • 24&
  • downloaditemid
    • pcid=
  • 114
    • 1&nav=0,1">UTN-USERFirst-
  • Client Authentication and Email<
    • Object</a> [<a href="https://www.incommon.org/cert/repository/
  • UTNAddTrustClient_CA
    • UTN-USERFirst-Object.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/
  • UTNAddTrustClient_CA
    • UTN-USERFirst-Object.pem">PEM</a>]</span>
      
      <br><span style="margin-left: 7em; line-height: 150%">InCommon 
  • Standard
    • Code 
  • Assurance
    • Signing 
  • Client
    • CA [<a href="https://www.incommon.org/cert/repository/
  • InCommonStandardAssuranceClientCA
    • InCommonCodeSigningCA.txt">Text</a>] [<a href="https://www.incommon.org/cert/repository/
  • InCommonStandardAssuranceClientCA
    • InCommonCodeSigningCA.pem">PEM</a>]</span>
      
      <br><span style="margin-left: 9em; line-height: 150%">End-Entity Certificate</span>
      
  • Intermediate CA Apache Bundle for Standard Client Certificates

The following information is common to both the SHA-1 and SHA-2 InCommon intermediate CAs:

  • Standard Client
    • Code-Signing Certificates
    • Certificate

  • Profile for Standard Client CertificatesCertificate
    • Revocation List:

      HTML
      http://crl.incommon.org/
  • InCommonStandardAssuranceClientCA
    • InCommonCodeSigningCA.crl


    • Online Certificate Status Protocol:

      HTML
      http://ocsp.incommon.org

Code-signing Certificates

...