About This Page
Trust-chain reference for the Entrust Managed Services Federal Shared Service Provider (SSP) PKI, covering both the production and test hierarchies. Download individual CA certificates, or the PKCS#7 (.p7c) AIA and SIA bundles where a full certification path is needed. Revocation lists for every chain are in the CRLs section.
Check revocation before you trust. Relying on a revoked certificate can have catastrophic consequences. How often to refresh revocation data is the relying party's decision, weighed against the risk of trusting a certificate whose status cannot be guaranteed.
2026 CA Key Update
The Entrust Managed Services (EMS) Root CA and Federal SSP Issuing CA are being re-keyed to RSA-3072 / SHA-384. Existing certificates remain valid and current CA certificates are not revoked. Relying parties should install the new certificates on receipt and trust both the existing and new chains before cutover, so newly issued certificates validate without interruption.
| Activity | Date | Status |
|---|---|---|
| Entrust Managed Services Root CA — key update | 2026-07-07 | Completed — cutover live |
| Entrust Managed Services SSP CA — key update | 2026-07-07 | Completed — keys on hold |
| Publish new Entrust Managed Services SSP CA certificate | 2026-07-15 | Published to this page |
| FCPCA G2 → Entrust Managed Services Root CA — cross-certificate issuance (from Federal Common Policy) | 2026-07-13 | Completed — issued by Federal PKI |
| FCPCA G2 → Entrust Managed Services Root CA — import cross-certificate to EMS Root CA | 2026-07-14 | Completed — imported to EMS Root CA |
| Entrust Derived Credential SSP CA — key update | 2026-07-13 | Completed — keys on hold |
| Publish new Entrust Derived Credential SSP CA certificate | 2026-07-15 | Published to this page |
| Entrust Derived Credential SSP CA — cutover | 2026-10-02 | Scheduled |
| Entrust Managed Services SSP CA — cutover | TBD | Pending validation |
| Certificate | Issued By | Valid From | Valid To | Serial | Key / Signature | SHA-256 Thumbprint | Status | Download |
|---|---|---|---|---|---|---|---|---|
| FCPCA G2 → Entrust Managed Services Root CA (Fed Root cross-certificate) | Federal Common Policy CA G2 | 2026-07-13 | 2035-12-31 | BA204BE0…E6F4 | RSA-3072 / SHA-384 | 91272DA1CF906991388E068832F5FAF236F3F7ADD94ED863DEA831E967635CB1 | Live — published 2026-07-13 | Certificate |
| Entrust Managed Services Root CA (Fed Root)OU=Entrust Managed Services Root CA, OU=Certification Authorities, O=Entrust, C=US | Self-signed | 2026-07-07 | 2035-12-07 | 448239F0 | RSA-3072 / SHA-384 | F2C5199574BF458DB5E031478E4D6D079B5D7F4ECECD4ED216D87D9D30FDA4CB | Live | — |
| Entrust Managed Services Root CA (reverse-link — new key signs previous) | EMS Root CA (2026 key) | 2023-07-11 | 2030-12-11 | 448239F1 | RSA-2048 / SHA-384 | 09E993D9CA86E1AFF41CB1E7193F4186DA5CA566AC2DE61DD5030D337E570125 | Live | Certificate |
| Entrust Managed Services Root CA (forward-link — previous key signs new) | EMS Root CA (2023 key) | 2026-07-07 | 2030-12-11 | 448239F2 | RSA-3072 / SHA-256 | 4C82400312CA1A9F569D83BF8C5A51377245A535C34E38227D8B8F82B9697E0C | Live | Certificate |
| Entrust Managed Services SSP CA (Fed SSP Issuing)OU=Entrust Managed Services SSP CA, OU=Certification Authorities, O=Entrust, C=US | EMS Root CA | 2026-07-07 | 2035-11-07 | 44823A31 | RSA-3072 / SHA-384 | B0F5E7D15A3B040DCDA597EF42E3BEA4D673E31DB6EFBC2538D1E13C663F31E7 | Staged — keys on hold (cutover TBD, pending validation) | Certificate |
| Entrust Derived Credential SSP CA (Derived Credential Issuing)CN=Entrust Derived Credential SSP CA, OU=Certification Authorities, O=Entrust, C=US | EMS Root CA | 2026-07-13 | 2035-11-13 | 44823AF5 | RSA-3072 / SHA-384 | 79CA3432B9C02F1D7F3E3B12C2E95E9F72F2BA8D77E206127D4F5CF9BB4A3169 | Staged — keys on hold (cutover 2026-10-02) | Certificate |
AIA Bundle — Certificates Issued to the EMS Root CA
The PKCS#7 bundle below contains the certificates issued to the Entrust Managed Services Root CA that establish its Federal PKI certification paths — the Federal Common Policy CA G2 cross-certificates and the key-rollover link certificates. Relying parties can install this single bundle to obtain valid certification paths from the EMS Root up to the Federal Common Policy CA G2 trust anchor.
Download bundle — CertsIssuedToEMSRootCA-20260713.p7c
View AIA bundle contents (5 certificates)
| Certificate | Issued By | Serial | Valid From | Valid To | Key |
|---|---|---|---|---|---|
| FCPCA G2 → EMS Root CA cross-certificate (2026, to new RSA-3072 key) | Federal Common Policy CA G2 | BA204BE0…E6F4 | 2026-07-13 | 2035-12-31 | RSA-3072 |
| FCPCA G2 → EMS Root CA cross-certificate (2023) | Federal Common Policy CA G2 | 25DA3CCA…0C3A | 2023-07-14 | 2030-12-28 | RSA-2048 |
| FCPCA G2 → EMS Root CA cross-certificate (2020) | Federal Common Policy CA G2 | 215E78D9…E595 | 2020-11-18 | 2029-08-14 | RSA-2048 |
| EMS Root CA (2026, key signs 2023 key) link | EMS Root CA (2026 key) | 448239F1 | 2023-07-11 | 2030-12-11 | RSA-2048 |
| EMS Root CA (2023, key signs 2019 key) link | EMS Root CA (2023 key) | 4481B22C | 2019-08-13 | 2029-08-13 | RSA-2048 |
The FCPCA G2 → EMS Root cross-certificate to the 2026 RSA-3072 key was issued by the Federal PKI on 2026-07-13 and is included in this bundle. The superseded self-signed root and forward-link certificates are intentionally omitted.
SIA Bundle — Certificates Issued by the EMS Root CA
The Subject Information Access (SIA) bundle lists the subordinate CA certificates the Entrust Managed Services Root CA has issued — the Fed SSP Issuing CA, the Derived Credential SSP CA, and the HHS-FPKI Intermediate CA. Relying parties building paths downward from the EMS Root can install this bundle to obtain the current subordinate CAs.
Download bundle — CertsIssuedByEMSRootCA-20260713.p7c
View SIA bundle contents (7 certificates — 5 published, 2 staged for 2026 cutover)
| Certificate | Issued By | Serial | Valid From | Valid To | Key |
|---|---|---|---|---|---|
| Entrust Managed Services SSP CA (2023, current) | EMS Root CA | 4481B22F | 2023-07-11 | 2030-11-11 | RSA-2048 |
| Entrust Managed Services SSP CA (2019) | EMS Root CA | 448107B6 | 2019-08-13 | 2029-07-13 | RSA-2048 |
| Entrust Managed Services SSP CA (2026, re-keyed — staged, keys on hold) | EMS Root CA | 44823A31 | 2026-07-07 | 2035-11-07 | RSA-3072 |
| Entrust Derived Credential SSP CA (2022, current) | EMS Root CA | 44817BA9 | 2022-05-09 | 2029-07-09 | RSA-2048 |
| Entrust Derived Credential SSP CA (2026, re-keyed — staged, keys on hold) | EMS Root CA | 44823AF5 | 2026-07-13 | 2035-11-13 | RSA-3072 |
| HHS-FPKI-Intermediate-CA-E1 (2026, current) | EMS Root CA | 448223B1 | 2026-01-08 | 2030-12-08 | RSA-2048 |
| HHS-FPKI-Intermediate-CA-E1 (2022) | EMS Root CA | 44817282 | 2022-02-23 | 2029-07-23 | RSA-2048 |
Two re-keyed RSA-3072 subordinate CA certificates are staged in this bundle with their keys on hold until their scheduled cutovers — Entrust Managed Services SSP CA (cutover TBD, pending validation) and Entrust Derived Credential SSP CA (cutover 2026-10-02). See the 2026 CA Key Update schedule.
Production Fed EMS Root and SSP CA — 2023 Generation
Live production chain issued 2023-07-11. This chain remains valid and in service after the 2026 key update — it is not revoked; it is simply no longer the latest issuing generation once the 2026 keys cut over.
| Certificate | Issued By | Serial | Valid From | Valid To | Key | Status | Download |
|---|---|---|---|---|---|---|---|
| Entrust Managed Services Root CA (2023, Fed Root)OU=Entrust Managed Services Root CA, OU=Certification Authorities, O=Entrust, C=US | Self-signed | 4481B22B | 2023-07-11 | 2030-12-11 | RSA-2048 | Current | Certificate |
| Entrust Managed Services SSP CA (2023, Fed SSP Issuing)OU=Entrust Managed Services SSP CA, OU=Certification Authorities, O=Entrust, C=US | EMS Root CA | 4481B22F | 2023-07-11 | 2030-11-11 | RSA-2048 | Current | Certificate |
| Entrust Managed Services Root CA (2023, forward-link) | EMS Root CA | 4481B22D | 2023-07-11 | 2029-08-13 | RSA-2048 | Current | Certificate |
| Entrust Managed Services Root CA (2019 self-signed) | Self-signed | 4481077A | 2019-08-13 | 2029-08-13 | RSA-2048 | Superseded | Certificate |
U.S. Federal PKI Common Policy CA Certificates
Federal Common Policy roots and the cross-certificates that link the EMS Root CA into the Federal PKI. Downloadable copies of the same certificates published by the Federal PKI Management Authority.
| Certificate | Issued By | Serial | Valid From | Valid To | Key | Status | Download |
|---|---|---|---|---|---|---|---|
| Federal Common Policy CA G2 (2020) | Self-signed | 21E5B9A0…FBEA | 2020-10-14 | 2040-10-14 | RSA-4096 | Current | Certificate |
| Federal Common Policy CA (2010, SHA-2) | Self-signed | 0130 | 2010-12-01 | 2030-12-01 | RSA-2048 | Current | Certificate |
| Federal Common Policy CA (2007, legacy SHA-1) | Self-signed | 293647AA…61AF | 2007-10-15 | 2027-10-15 | RSA-2048 | Legacy (SHA-1) | Certificate |
| FCPCA G2 → EMS Root CA cross-certificate (2023) | Federal Common Policy CA G2 | 25DA3CCA…0C3A | 2023-07-14 | 2030-12-28 | RSA-2048 | Current | Certificate |
| FCPCA G2 → EMS Root CA cross-certificate (2020) | Federal Common Policy CA G2 | 215E78D9…E595 | 2020-11-18 | 2029-08-14 | RSA-2048 | Current | Certificate |
| FCPCA → EMS Root CA cross-certificate (2019) | Federal Common Policy CA | 734A | 2019-08-14 | 2029-08-14 | RSA-2048 | Current | Certificate |
Derived Credential SSP CA
Issues PIV-Derived credentials. A 2026 key update is scheduled for 2026-07-13 (cutover 2026-10-02) — see the 2026 CA Key Update schedule.
| Certificate | Issued By | Serial | Valid From | Valid To | Key | Status | Download |
|---|---|---|---|---|---|---|---|
| Entrust Derived Credential SSP CA (2022, current)CN=Entrust Derived Credential SSP CA, OU=Certification Authorities, O=Entrust, C=US | EMS Root CA | 44817BA9 | 2022-05-09 | 2029-07-09 | RSA-2048 | Current | Certificate |
| Entrust Derived Credential SSP CA (2026, re-keyed) | EMS Root CA | 44823AF5 | 2026-07-13 | 2035-11-13 | RSA-3072 | Staged — keys on hold (cutover 2026-10-02) | Certificate |
HHS CA
The HHS-FPKI-Intermediate-CA-E1 operates under the Entrust Managed Services Root CA and is cross-certified into the Federal PKI through the Federal Common Policy CA G2 trust anchor. Current generation shown first; the superseded certificate is retained for path validation.
| Certificate | Issued By | Serial | Valid From | Valid To | Key | Status | Download |
|---|---|---|---|---|---|---|---|
| HHS-FPKI-Intermediate-CA-E1 (2026, current)CN=HHS-FPKI-Intermediate-CA-E1, OU=Certification Authorities, OU=HHS, O=U.S. Government, C=US | EMS Root CA | 448223B1 | 2026-01-08 | 2030-12-08 | RSA-2048 | Current | Certificate |
| HHS-FPKI-Intermediate-CA-E1 (2022) | EMS Root CA | 44817282 | 2022-02-23 | 2029-07-23 | RSA-2048 | Superseded | Certificate |
Download trust-anchor bundle — CertIssuedToHHSEntrustCA-20260709.p7c
View HHS trust-anchor bundle contents (3 certificates)
| Certificate | Issued By | Serial | Valid From | Valid To | Key |
|---|---|---|---|---|---|
| HHS-FPKI-Intermediate-CA-E1 (2026) | EMS Root CA | 448223B1 | 2026-01-08 | 2030-12-08 | RSA-2048 |
| Entrust Managed Services Root CA (2020, cross-certificate) | Federal Common Policy CA G2 | 215E78D9…E595 | 2020-11-18 | 2029-08-14 | RSA-2048 |
| Federal Common Policy CA G2 (2020, trust anchor) | Self-signed | 21E5B9A0…FBEA | 2020-10-14 | 2040-10-14 | RSA-4096 |
Federal PKI G2 (Entrust Managed PKI)
The Entrust Managed PKI Federal G2 hierarchy — a Federal Root CA G2 cross-certified by Federal Common Policy CA G2, with a subordinate Federal Issuing CA G2.
| Certificate | Issued By | Serial | Valid From | Valid To | Key | Status | Download |
|---|---|---|---|---|---|---|---|
| Entrust Managed PKI Federal Root CA G2 (2024)CN=Entrust Managed PKI Federal Root CA G2, OU=Certification Authorities, O=Entrust, C=US | Federal Common Policy CA G2 | 29237F41…0883 | 2024-07-09 | 2034-07-09 | RSA-4096 | Current | Certificate |
| Entrust Managed PKI Federal Issuing CA G2 (2024)CN=Entrust Managed PKI Federal Issuing CA G2, OU=Certification Authorities, O=Entrust, C=US | Entrust Managed PKI Federal Root CA G2 | 6C64ACE1…8A4C | 2024-06-28 | 2034-06-28 | RSA-4096 | Current | Certificate |
NFI CA
Non-Federal Issuer (NFI) hierarchy, cross-certified to the Federal Bridge CA G4. Current generation shown first; superseded certificates are retained for path validation.
| Certificate | Issued By | Serial | Valid From | Valid To | Key | Status | Download |
|---|---|---|---|---|---|---|---|
| Entrust Managed Services NFI Root CA (2021, current root)OU=Entrust Managed Services NFI Root CA, OU=Certification Authorities, O=Entrust, C=US | Self-signed | 4AA96956 | 2021-10-12 | 2030-11-12 | RSA-2048 | Current | Certificate |
| Entrust Managed Services NFI Root CA (2016, prior root) | Self-signed | 4AA8A60D | 2016-11-16 | 2027-12-16 | RSA-2048 | Superseded | Certificate |
| Entrust NFI Medium Assurance SSP CA (2021, current subordinate)OU=Entrust NFI Medium Assurance SSP CA, OU=Certification Authorities, O=Entrust, C=US | EMS NFI Root CA | 4AA96994 | 2021-10-12 | 2030-09-12 | RSA-2048 | Current | Certificate |
| Entrust NFI Medium Assurance SSP CA (2017) | EMS NFI Root CA | 4AA8B9EA | 2017-05-16 | 2027-11-16 | RSA-2048 | Superseded | Certificate |
| Federal Bridge CA G4 → EMS NFI Root CA (2024, cross-certificate) | Federal Bridge CA G4 | 1747DE49…80BB | 2024-09-11 | 2027-09-11 | RSA-2048 | Current | Certificate |
| Federal Bridge CA G5 → EMS NFI Root CA (2026, cross-certificate) | Federal Bridge CA G5 | 45F19CE8…9BF0 | 2026-09-01 | 2027-09-11 | RSA-2048 | Current | Certificate |
The certificates issued by the NFI Root CA (its SIA contents) are the Medium Assurance SSP CA certificates listed above; a standalone NFI Root SIA bundle is not published at this time.
Certificate Revocation Lists (CRLs)
Combined (full-scope) CRLs for each trust chain, published at the URLs referenced in the CRL Distribution Point (CRLDP) extension of the certificates above. Each CRL is signed by its issuing CA key — the Authority Key Identifier (AKI) of the CRL matches the Subject Key Identifier (SKI) of the corresponding CA certificate. Partitioned CRLs (the c### shard files) and expired generations are intentionally omitted; only currently valid generations are listed. Retrieve fresh revocation data at intervals appropriate to your risk posture.
| CRL | Signing key (AKI = CA SKI) | Generation |
|---|---|---|
| Entrust Managed Services Root CAOU=Entrust Managed Services Root CA, OU=Certification Authorities, O=Entrust, C=US | ||
| EMSRootCA5.crl | B2C62EA2…1E44 | 2026 (current) |
| EMSRootCA4.crl | 1C21F5E3…0B65 | 2023 |
| EMSRootCA3.crl | 4954914C…9810 | 2019 |
| Entrust Managed Services SSP CAOU=Entrust Managed Services SSP CA, OU=Certification Authorities, O=Entrust, C=US | ||
| EMSSSPCA4.crl | 9B7FB629…5096 | 2023 (current) |
| EMSSSPCA3.crl | E6DD1A07…3727 | 2019 |
| EMSSSPCA5.crl | — | 2026 (pending cutover) |
| Entrust Derived Credential SSP CACN=Entrust Derived Credential SSP CA, OU=Certification Authorities, O=Entrust, C=US | ||
| FedDCSCA1.crl | 4B1801BB…5AF3 | 2022 (current) |
| FedDCSCA2.crl | — | 2026 (pending cutover) |
| HHS-FPKI-Intermediate-CA-E1CN=HHS-FPKI-Intermediate-CA-E1, OU=Certification Authorities, OU=HHS, O=U.S. Government, C=US | ||
| HHSEntrustCA3.crl | 24F150F9…8CF5 | 2026 (current) |
| HHSEntrustCA2.crl | 2FEC9E66…ACC3 | 2022 |
| Entrust Managed Services NFI Root CAOU=Entrust Managed Services NFI Root CA, OU=Certification Authorities, O=Entrust, C=US | ||
| NFIRootCA3.crl | F3ED39B9…3E39 | current |
| NFIRootCA2.crl | FADF2301…655E | prior |
| Entrust NFI Medium Assurance SSP CAOU=Entrust NFI Medium Assurance SSP CA, OU=Certification Authorities, O=Entrust, C=US | ||
| NFIMEDIUMSSPCA2.crl | 7BD6D0FE…0C85 | 2021 (current) |
| NFIMEDIUMSSPCA1.crl | 66F92598…D6A6 | 2017 |
| Entrust Managed PKI Federal Root CA G2CN=Entrust Managed PKI Federal Root CA G2, OU=Certification Authorities, O=Entrust, C=US | ||
| FedRootG2CA.crl | 0BC04A7E…9ADA | current |
| Entrust Managed PKI Federal Issuing CA G2CN=Entrust Managed PKI Federal Issuing CA G2, OU=Certification Authorities, O=Entrust, C=US | ||
| FedSSPIssuingCAG2.crl | 3B831F4C…30EB | current |
| Upstream Federal PKI (trust anchors) | ||
| fcpcag2.crl | F4275CA9…17E3 | Federal Common Policy CA G2 |
| fbcag4.crl | 79F00049…076F | Federal Bridge CA G4 |
Generations reflect the CA key each CRL is signed under (not the CRL's rolling NextUpdate). Pending rows will be published after the 2026 key-update cutover.
Test / Demo CA Information
Non-production test hierarchy published from the demo directory (dsspdir.managed.entrust.com) for interoperability testing only — not valid for production trust. These CAs mirror the production hierarchy above so relying parties can validate configuration before go-live. Current generation shown first per CA; superseded certificates are retained for path validation.
| Certificate | Issued By | Serial | Valid From | Valid To | Key | Status | Download |
|---|---|---|---|---|---|---|---|
| Entrust Managed Services Demo FRoot CA (2025, current)OU=Entrust Managed Services Demo FRoot CA, OU=Certification Authorities, O=Entrust, C=US | Self-signed | 6494DD91 | 2025-12-11 | 2035-12-11 | RSA-4096 | Current | Certificate |
| Entrust Managed Services Demo FRoot CA (2023) | Self-signed | 64947D91 | 2023-06-26 | 2033-06-26 | RSA-2048 | Superseded | Certificate |
| Entrust Managed Services Demo FSSP CA (2025, current)OU=Entrust Managed Services Demo FSSP CA, OU=Certification Authorities, O=Entrust, C=US | Demo FRoot CA | 6494DDB2 | 2025-12-11 | 2035-11-11 | RSA-4096 | Current | Certificate |
| Entrust Managed Services Demo FSSP CA (2023) | Demo FRoot CA | 64947DAC | 2023-06-26 | 2033-05-26 | RSA-2048 | Superseded | Certificate |
| Entrust Derived Credential Demo SSP CA (2026)CN=Entrust Derived Credential Demo SSP CA, OU=Certification Authorities, O=Entrust, C=US | Demo FRoot CA | 6494F320 | 2026-06-29 | 2035-11-29 | RSA-3072 | Current | Certificate |
| Entrust Managed Services Demo NFI Root CA (2016, DComRootCA)OU=DComRootCA, OU=Certification Authorities, O=Entrust, C=US | Self-signed | 4D382351 | 2016-07-31 | 2030-12-31 | RSA-2048 | Current | Certificate |
| Entrust NFI Test Shared Service Provider (2021)OU=Entrust NFI Test Shared Service Provider, OU=Certification Authorities, O=Entrust, C=US | Demo NFI Root CA | 4D38D770 | 2021-10-20 | 2030-09-20 | RSA-2048 | Current | Certificate |
| Entrust Managed PKI Test Federal Root CA G2 (2023)CN=Entrust Managed PKI Test Federal Root CA G2, OU=Certification Authorities, O=Entrust, C=US | Self-signed | 41CFE87C…610D | 2023-04-18 | 2033-05-18 | RSA-4096 | Current | Certificate |
| Entrust Managed PKI Test Federal SSP Issuing CA G2 (2023)CN=Entrust Managed PKI Test Federal SSP Issuing CA G2, OU=Certification Authorities, O=Entrust, C=US | Test Federal Root CA G2 | 1E18BF61…CD8C | 2023-04-18 | 2033-04-18 | RSA-4096 | Current | Certificate |
| Demo HHS-FPKI-Intermediate-CA-E1 (2025)CN=Demo HHS-FPKI-Intermediate-CA-E1, OU=Certification Authorities, OU=HHS, O=U.S. Government, C=US | Demo FRoot CA | 6494D3C7 | 2025-09-12 | 2030-12-12 | RSA-2048 | Current | Certificate |
Demo FRoot CA rollover links & AIA bundle (2023 generation)
- Demo FRoot CA AIA bundle — certificates issued to the Demo FRoot CA
- Demo FRoot CA reverse-link certificate — 64947D92
- Demo FRoot CA forward-link certificate — 64947D93
- FCPCA G2 → Demo FRoot CA cross-certificate (2023)