Entrust Managed Services · Federal PKI

Federal SSP CA Certificates & Trust Chains

The authoritative reference for the Entrust Managed Services Shared Service Provider (SSP) Federal PKI — download CA certificates, PKCS#7 trust bundles, and revocation lists for production and test relying parties.

Last updated 2026-07-15 · Certificate Policy & Practices (CP/CPS)

About This Page

Trust-chain reference for the Entrust Managed Services Federal Shared Service Provider (SSP) PKI, covering both the production and test hierarchies. Download individual CA certificates, or the PKCS#7 (.p7c) AIA and SIA bundles where a full certification path is needed. Revocation lists for every chain are in the CRLs section.

Check revocation before you trust. Relying on a revoked certificate can have catastrophic consequences. How often to refresh revocation data is the relying party's decision, weighed against the risk of trusting a certificate whose status cannot be guaranteed.

2026 CA Key Update

The Entrust Managed Services (EMS) Root CA and Federal SSP Issuing CA are being re-keyed to RSA-3072 / SHA-384. Existing certificates remain valid and current CA certificates are not revoked. Relying parties should install the new certificates on receipt and trust both the existing and new chains before cutover, so newly issued certificates validate without interruption.

Key update schedule
ActivityDateStatus
Entrust Managed Services Root CA — key update2026-07-07Completed — cutover live
Entrust Managed Services SSP CA — key update2026-07-07Completed — keys on hold
Publish new Entrust Managed Services SSP CA certificate2026-07-15Published to this page
FCPCA G2 → Entrust Managed Services Root CA — cross-certificate issuance (from Federal Common Policy)2026-07-13Completed — issued by Federal PKI
FCPCA G2 → Entrust Managed Services Root CA — import cross-certificate to EMS Root CA2026-07-14Completed — imported to EMS Root CA
Entrust Derived Credential SSP CA — key update2026-07-13Completed — keys on hold
Publish new Entrust Derived Credential SSP CA certificate2026-07-15Published to this page
Entrust Derived Credential SSP CA — cutover2026-10-02Scheduled
Entrust Managed Services SSP CA — cutoverTBDPending validation
EMS Root CA & subordinate certificates (2026 key update)
CertificateIssued ByValid FromValid ToSerialKey / SignatureSHA-256 ThumbprintStatusDownload
FCPCA G2 → Entrust Managed Services Root CA (Fed Root cross-certificate) Federal Common Policy CA G22026-07-132035-12-31BA204BE0…E6F4RSA-3072 / SHA-38491272DA1CF906991388E068832F5FAF236F3F7ADD94ED863DEA831E967635CB1 Live — published 2026-07-13 Certificate
Entrust Managed Services Root CA (Fed Root)OU=Entrust Managed Services Root CA, OU=Certification Authorities, O=Entrust, C=US Self-signed2026-07-072035-12-07448239F0RSA-3072 / SHA-384 F2C5199574BF458DB5E031478E4D6D079B5D7F4ECECD4ED216D87D9D30FDA4CB Live
Entrust Managed Services Root CA (reverse-link — new key signs previous) EMS Root CA (2026 key)2023-07-112030-12-11448239F1RSA-2048 / SHA-384 09E993D9CA86E1AFF41CB1E7193F4186DA5CA566AC2DE61DD5030D337E570125 Live Certificate
Entrust Managed Services Root CA (forward-link — previous key signs new) EMS Root CA (2023 key)2026-07-072030-12-11448239F2RSA-3072 / SHA-256 4C82400312CA1A9F569D83BF8C5A51377245A535C34E38227D8B8F82B9697E0C Live Certificate
Entrust Managed Services SSP CA (Fed SSP Issuing)OU=Entrust Managed Services SSP CA, OU=Certification Authorities, O=Entrust, C=US EMS Root CA2026-07-072035-11-0744823A31RSA-3072 / SHA-384 B0F5E7D15A3B040DCDA597EF42E3BEA4D673E31DB6EFBC2538D1E13C663F31E7 Staged — keys on hold (cutover TBD, pending validation) Certificate
Entrust Derived Credential SSP CA (Derived Credential Issuing)CN=Entrust Derived Credential SSP CA, OU=Certification Authorities, O=Entrust, C=US EMS Root CA2026-07-132035-11-1344823AF5RSA-3072 / SHA-384 79CA3432B9C02F1D7F3E3B12C2E95E9F72F2BA8D77E206127D4F5CF9BB4A3169 Staged — keys on hold (cutover 2026-10-02) Certificate

AIA Bundle — Certificates Issued to the EMS Root CA

The PKCS#7 bundle below contains the certificates issued to the Entrust Managed Services Root CA that establish its Federal PKI certification paths — the Federal Common Policy CA G2 cross-certificates and the key-rollover link certificates. Relying parties can install this single bundle to obtain valid certification paths from the EMS Root up to the Federal Common Policy CA G2 trust anchor.

Download bundle — CertsIssuedToEMSRootCA-20260713.p7c

View AIA bundle contents (5 certificates)
CertificateIssued BySerialValid FromValid ToKey
FCPCA G2 → EMS Root CA cross-certificate (2026, to new RSA-3072 key)Federal Common Policy CA G2BA204BE0…E6F42026-07-132035-12-31RSA-3072
FCPCA G2 → EMS Root CA cross-certificate (2023)Federal Common Policy CA G225DA3CCA…0C3A2023-07-142030-12-28RSA-2048
FCPCA G2 → EMS Root CA cross-certificate (2020)Federal Common Policy CA G2215E78D9…E5952020-11-182029-08-14RSA-2048
EMS Root CA (2026, key signs 2023 key) linkEMS Root CA (2026 key)448239F12023-07-112030-12-11RSA-2048
EMS Root CA (2023, key signs 2019 key) linkEMS Root CA (2023 key)4481B22C2019-08-132029-08-13RSA-2048

The FCPCA G2 → EMS Root cross-certificate to the 2026 RSA-3072 key was issued by the Federal PKI on 2026-07-13 and is included in this bundle. The superseded self-signed root and forward-link certificates are intentionally omitted.

SIA Bundle — Certificates Issued by the EMS Root CA

The Subject Information Access (SIA) bundle lists the subordinate CA certificates the Entrust Managed Services Root CA has issued — the Fed SSP Issuing CA, the Derived Credential SSP CA, and the HHS-FPKI Intermediate CA. Relying parties building paths downward from the EMS Root can install this bundle to obtain the current subordinate CAs.

Download bundle — CertsIssuedByEMSRootCA-20260713.p7c

View SIA bundle contents (7 certificates — 5 published, 2 staged for 2026 cutover)
CertificateIssued BySerialValid FromValid ToKey
Entrust Managed Services SSP CA (2023, current)EMS Root CA4481B22F2023-07-112030-11-11RSA-2048
Entrust Managed Services SSP CA (2019)EMS Root CA448107B62019-08-132029-07-13RSA-2048
Entrust Managed Services SSP CA (2026, re-keyed — staged, keys on hold)EMS Root CA44823A312026-07-072035-11-07RSA-3072
Entrust Derived Credential SSP CA (2022, current)EMS Root CA44817BA92022-05-092029-07-09RSA-2048
Entrust Derived Credential SSP CA (2026, re-keyed — staged, keys on hold)EMS Root CA44823AF52026-07-132035-11-13RSA-3072
HHS-FPKI-Intermediate-CA-E1 (2026, current)EMS Root CA448223B12026-01-082030-12-08RSA-2048
HHS-FPKI-Intermediate-CA-E1 (2022)EMS Root CA448172822022-02-232029-07-23RSA-2048

Two re-keyed RSA-3072 subordinate CA certificates are staged in this bundle with their keys on hold until their scheduled cutovers — Entrust Managed Services SSP CA (cutover TBD, pending validation) and Entrust Derived Credential SSP CA (cutover 2026-10-02). See the 2026 CA Key Update schedule.

Production Fed EMS Root and SSP CA — 2023 Generation

Live production chain issued 2023-07-11. This chain remains valid and in service after the 2026 key update — it is not revoked; it is simply no longer the latest issuing generation once the 2026 keys cut over.

CertificateIssued BySerialValid FromValid ToKeyStatusDownload
Entrust Managed Services Root CA (2023, Fed Root)OU=Entrust Managed Services Root CA, OU=Certification Authorities, O=Entrust, C=USSelf-signed4481B22B2023-07-112030-12-11RSA-2048CurrentCertificate
Entrust Managed Services SSP CA (2023, Fed SSP Issuing)OU=Entrust Managed Services SSP CA, OU=Certification Authorities, O=Entrust, C=USEMS Root CA4481B22F2023-07-112030-11-11RSA-2048CurrentCertificate
Entrust Managed Services Root CA (2023, forward-link)EMS Root CA4481B22D2023-07-112029-08-13RSA-2048CurrentCertificate
Entrust Managed Services Root CA (2019 self-signed)Self-signed4481077A2019-08-132029-08-13RSA-2048SupersededCertificate

U.S. Federal PKI Common Policy CA Certificates

Federal Common Policy roots and the cross-certificates that link the EMS Root CA into the Federal PKI. Downloadable copies of the same certificates published by the Federal PKI Management Authority.

CertificateIssued BySerialValid FromValid ToKeyStatusDownload
Federal Common Policy CA G2 (2020)Self-signed21E5B9A0…FBEA2020-10-142040-10-14RSA-4096CurrentCertificate
Federal Common Policy CA (2010, SHA-2)Self-signed01302010-12-012030-12-01RSA-2048CurrentCertificate
Federal Common Policy CA (2007, legacy SHA-1)Self-signed293647AA…61AF2007-10-152027-10-15RSA-2048Legacy (SHA-1)Certificate
FCPCA G2 → EMS Root CA cross-certificate (2023)Federal Common Policy CA G225DA3CCA…0C3A2023-07-142030-12-28RSA-2048CurrentCertificate
FCPCA G2 → EMS Root CA cross-certificate (2020)Federal Common Policy CA G2215E78D9…E5952020-11-182029-08-14RSA-2048CurrentCertificate
FCPCA → EMS Root CA cross-certificate (2019)Federal Common Policy CA734A2019-08-142029-08-14RSA-2048CurrentCertificate

Derived Credential SSP CA

Issues PIV-Derived credentials. A 2026 key update is scheduled for 2026-07-13 (cutover 2026-10-02) — see the 2026 CA Key Update schedule.

CertificateIssued BySerialValid FromValid ToKeyStatusDownload
Entrust Derived Credential SSP CA (2022, current)CN=Entrust Derived Credential SSP CA, OU=Certification Authorities, O=Entrust, C=USEMS Root CA44817BA92022-05-092029-07-09RSA-2048CurrentCertificate
Entrust Derived Credential SSP CA (2026, re-keyed)EMS Root CA44823AF52026-07-132035-11-13RSA-3072Staged — keys on hold (cutover 2026-10-02)Certificate

HHS CA

The HHS-FPKI-Intermediate-CA-E1 operates under the Entrust Managed Services Root CA and is cross-certified into the Federal PKI through the Federal Common Policy CA G2 trust anchor. Current generation shown first; the superseded certificate is retained for path validation.

CertificateIssued BySerialValid FromValid ToKeyStatusDownload
HHS-FPKI-Intermediate-CA-E1 (2026, current)CN=HHS-FPKI-Intermediate-CA-E1, OU=Certification Authorities, OU=HHS, O=U.S. Government, C=USEMS Root CA448223B12026-01-082030-12-08RSA-2048CurrentCertificate
HHS-FPKI-Intermediate-CA-E1 (2022)EMS Root CA448172822022-02-232029-07-23RSA-2048SupersededCertificate

Download trust-anchor bundle — CertIssuedToHHSEntrustCA-20260709.p7c

View HHS trust-anchor bundle contents (3 certificates)
CertificateIssued BySerialValid FromValid ToKey
HHS-FPKI-Intermediate-CA-E1 (2026)EMS Root CA448223B12026-01-082030-12-08RSA-2048
Entrust Managed Services Root CA (2020, cross-certificate)Federal Common Policy CA G2215E78D9…E5952020-11-182029-08-14RSA-2048
Federal Common Policy CA G2 (2020, trust anchor)Self-signed21E5B9A0…FBEA2020-10-142040-10-14RSA-4096

Federal PKI G2 (Entrust Managed PKI)

The Entrust Managed PKI Federal G2 hierarchy — a Federal Root CA G2 cross-certified by Federal Common Policy CA G2, with a subordinate Federal Issuing CA G2.

CertificateIssued BySerialValid FromValid ToKeyStatusDownload
Entrust Managed PKI Federal Root CA G2 (2024)CN=Entrust Managed PKI Federal Root CA G2, OU=Certification Authorities, O=Entrust, C=USFederal Common Policy CA G229237F41…08832024-07-092034-07-09RSA-4096CurrentCertificate
Entrust Managed PKI Federal Issuing CA G2 (2024)CN=Entrust Managed PKI Federal Issuing CA G2, OU=Certification Authorities, O=Entrust, C=USEntrust Managed PKI Federal Root CA G26C64ACE1…8A4C2024-06-282034-06-28RSA-4096CurrentCertificate

NFI CA

Non-Federal Issuer (NFI) hierarchy, cross-certified to the Federal Bridge CA G4. Current generation shown first; superseded certificates are retained for path validation.

CertificateIssued BySerialValid FromValid ToKeyStatusDownload
Entrust Managed Services NFI Root CA (2021, current root)OU=Entrust Managed Services NFI Root CA, OU=Certification Authorities, O=Entrust, C=USSelf-signed4AA969562021-10-122030-11-12RSA-2048CurrentCertificate
Entrust Managed Services NFI Root CA (2016, prior root)Self-signed4AA8A60D2016-11-162027-12-16RSA-2048SupersededCertificate
Entrust NFI Medium Assurance SSP CA (2021, current subordinate)OU=Entrust NFI Medium Assurance SSP CA, OU=Certification Authorities, O=Entrust, C=USEMS NFI Root CA4AA969942021-10-122030-09-12RSA-2048CurrentCertificate
Entrust NFI Medium Assurance SSP CA (2017)EMS NFI Root CA4AA8B9EA2017-05-162027-11-16RSA-2048SupersededCertificate
Federal Bridge CA G4 → EMS NFI Root CA (2024, cross-certificate)Federal Bridge CA G41747DE49…80BB2024-09-112027-09-11RSA-2048CurrentCertificate
Federal Bridge CA G5 → EMS NFI Root CA (2026, cross-certificate)Federal Bridge CA G545F19CE8…9BF02026-09-012027-09-11RSA-2048CurrentCertificate

The certificates issued by the NFI Root CA (its SIA contents) are the Medium Assurance SSP CA certificates listed above; a standalone NFI Root SIA bundle is not published at this time.

Certificate Revocation Lists (CRLs)

Combined (full-scope) CRLs for each trust chain, published at the URLs referenced in the CRL Distribution Point (CRLDP) extension of the certificates above. Each CRL is signed by its issuing CA key — the Authority Key Identifier (AKI) of the CRL matches the Subject Key Identifier (SKI) of the corresponding CA certificate. Partitioned CRLs (the c### shard files) and expired generations are intentionally omitted; only currently valid generations are listed. Retrieve fresh revocation data at intervals appropriate to your risk posture.

CRLSigning key (AKI = CA SKI)Generation
Entrust Managed Services Root CAOU=Entrust Managed Services Root CA, OU=Certification Authorities, O=Entrust, C=US
EMSRootCA5.crlB2C62EA2…1E442026 (current)
EMSRootCA4.crl1C21F5E3…0B652023
EMSRootCA3.crl4954914C…98102019
Entrust Managed Services SSP CAOU=Entrust Managed Services SSP CA, OU=Certification Authorities, O=Entrust, C=US
EMSSSPCA4.crl9B7FB629…50962023 (current)
EMSSSPCA3.crlE6DD1A07…37272019
EMSSSPCA5.crl2026 (pending cutover)
Entrust Derived Credential SSP CACN=Entrust Derived Credential SSP CA, OU=Certification Authorities, O=Entrust, C=US
FedDCSCA1.crl4B1801BB…5AF32022 (current)
FedDCSCA2.crl2026 (pending cutover)
HHS-FPKI-Intermediate-CA-E1CN=HHS-FPKI-Intermediate-CA-E1, OU=Certification Authorities, OU=HHS, O=U.S. Government, C=US
HHSEntrustCA3.crl24F150F9…8CF52026 (current)
HHSEntrustCA2.crl2FEC9E66…ACC32022
Entrust Managed Services NFI Root CAOU=Entrust Managed Services NFI Root CA, OU=Certification Authorities, O=Entrust, C=US
NFIRootCA3.crlF3ED39B9…3E39current
NFIRootCA2.crlFADF2301…655Eprior
Entrust NFI Medium Assurance SSP CAOU=Entrust NFI Medium Assurance SSP CA, OU=Certification Authorities, O=Entrust, C=US
NFIMEDIUMSSPCA2.crl7BD6D0FE…0C852021 (current)
NFIMEDIUMSSPCA1.crl66F92598…D6A62017
Entrust Managed PKI Federal Root CA G2CN=Entrust Managed PKI Federal Root CA G2, OU=Certification Authorities, O=Entrust, C=US
FedRootG2CA.crl0BC04A7E…9ADAcurrent
Entrust Managed PKI Federal Issuing CA G2CN=Entrust Managed PKI Federal Issuing CA G2, OU=Certification Authorities, O=Entrust, C=US
FedSSPIssuingCAG2.crl3B831F4C…30EBcurrent
Upstream Federal PKI (trust anchors)
fcpcag2.crlF4275CA9…17E3Federal Common Policy CA G2
fbcag4.crl79F00049…076FFederal Bridge CA G4

Generations reflect the CA key each CRL is signed under (not the CRL's rolling NextUpdate). Pending rows will be published after the 2026 key-update cutover.

Test / Demo CA Information

Non-production test hierarchy published from the demo directory (dsspdir.managed.entrust.com) for interoperability testing only — not valid for production trust. These CAs mirror the production hierarchy above so relying parties can validate configuration before go-live. Current generation shown first per CA; superseded certificates are retained for path validation.

CertificateIssued BySerialValid FromValid ToKeyStatusDownload
Entrust Managed Services Demo FRoot CA (2025, current)OU=Entrust Managed Services Demo FRoot CA, OU=Certification Authorities, O=Entrust, C=USSelf-signed6494DD912025-12-112035-12-11RSA-4096CurrentCertificate
Entrust Managed Services Demo FRoot CA (2023)Self-signed64947D912023-06-262033-06-26RSA-2048SupersededCertificate
Entrust Managed Services Demo FSSP CA (2025, current)OU=Entrust Managed Services Demo FSSP CA, OU=Certification Authorities, O=Entrust, C=USDemo FRoot CA6494DDB22025-12-112035-11-11RSA-4096CurrentCertificate
Entrust Managed Services Demo FSSP CA (2023)Demo FRoot CA64947DAC2023-06-262033-05-26RSA-2048SupersededCertificate
Entrust Derived Credential Demo SSP CA (2026)CN=Entrust Derived Credential Demo SSP CA, OU=Certification Authorities, O=Entrust, C=USDemo FRoot CA6494F3202026-06-292035-11-29RSA-3072CurrentCertificate
Entrust Managed Services Demo NFI Root CA (2016, DComRootCA)OU=DComRootCA, OU=Certification Authorities, O=Entrust, C=USSelf-signed4D3823512016-07-312030-12-31RSA-2048CurrentCertificate
Entrust NFI Test Shared Service Provider (2021)OU=Entrust NFI Test Shared Service Provider, OU=Certification Authorities, O=Entrust, C=USDemo NFI Root CA4D38D7702021-10-202030-09-20RSA-2048CurrentCertificate
Entrust Managed PKI Test Federal Root CA G2 (2023)CN=Entrust Managed PKI Test Federal Root CA G2, OU=Certification Authorities, O=Entrust, C=USSelf-signed41CFE87C…610D2023-04-182033-05-18RSA-4096CurrentCertificate
Entrust Managed PKI Test Federal SSP Issuing CA G2 (2023)CN=Entrust Managed PKI Test Federal SSP Issuing CA G2, OU=Certification Authorities, O=Entrust, C=USTest Federal Root CA G21E18BF61…CD8C2023-04-182033-04-18RSA-4096CurrentCertificate
Demo HHS-FPKI-Intermediate-CA-E1 (2025)CN=Demo HHS-FPKI-Intermediate-CA-E1, OU=Certification Authorities, OU=HHS, O=U.S. Government, C=USDemo FRoot CA6494D3C72025-09-122030-12-12RSA-2048CurrentCertificate
Demo FRoot CA rollover links & AIA bundle (2023 generation)