Edit this page

Federal PKI Activity Report

Updated: August 13, 2019

This report provides a technical and policy compliance status for each Federal Public Key Infrastructure (FPKI) Affiliate.

Resolve issues by contacting one of the teams:

Federal Agency and Affiliate PKI Status Summary

The operational status for each Federal Agency or affiliate connected to the Federal Common Policy CA (FCPCA) or the Federal Bridge CA (FBCA) is summarized below. The overall operational status identifies issues that affect technical interoperability and non-compliance with applicable Certificate Policies (CP). The status is not used for any other purpose such as ranking or rating.

Federal Agency or Affiliate PKI FPKIMA CA Status
CertiPath Bridge FBCA & SHA1FRCA No Issues
Department of Defense FBCA & SHA1FRCA No Issues
DigiCert/Symantec NFI FBCA No Issues
Entrust Managed Services NFI FBCA No Issues
Exostar NFI FBCA No Issues
Government Printing Office FBCA No Issues
GSA Access Certificate for Electronic Services (GSA ACES) FBCA No Issues
IdenTrust NFI FBCA No Issues
WidePoint/ORC NFI FBCA No Issues
SAFE BioPharma Bridge FBCA No Issues
STRAC Bridge FBCA No Issues
TSCP Bridge FBCA No Issues
US Patent and Trademark Office (PTO) FBCA No Issues
Verizon Business NFI FBCA No Issues
Department of State FCPCA No Issues
DigiCert/Symantec/Verisign SSP FCPCA No Issues
Entrust Managed Services SSP FCPCA No Issues
WidePoint/ORC SSP FCPCA No Issues
Department of the Treasury FCPCA No Issues
Verizon Business SSP FCPCA No Issues

Federal Agency or Affiliate PKI Status Legend

Status Description
Significant Technical and/or policy issues that will adversely affect interoperability
Moderate Technical and/or policy issues that may or may not adversely affect interoperability
No Impact Technical and/or policy issues that will not adversely affect interoperability
No Issues No technical or policy issues were found in the last thirty days

FPKIMA Certificate Activity

The activity listed in this section is limited to the certificates issued BY or TO the Federal Bridge or Federal Common Policy CA.

The following certificates were issued BY or TO the FPKI Trust Infrastructure in the last 30 days.

Affiliate Subject CA Issuing CA SHA-1 Hash Issued Date
TSCP TSCP SHA256 Bridge CA Federal Bridge CA 2016 874007002A4A2FFF3EDCF90EB41ADCE7C2FB4915 08/06/2019
DoD DoD Interoperability Root CA 2 Federal Bridge CA 2016 73050D5B629CF6286BE972AFDDFA31D2864B4F35 08/06/2019
WidePoint WidePoint NFI Root 1 Federal Bridge CA 2016 92BC06FE6B27CBE4723F309F34681FC57C8166CE 08/06/2019
Treasury US Treasury Root CA Federal Common Policy CA 48CE02A99AE2CC4f790F2989AA153ED565B7E4D2 08/14/2019
Entrust Entrust Managed Services Root CA Federal Common Policy CA A09655170C87D0FBFE0328B99A7BAF4A1CF0B5D9 08/14/2019

The following certificates have been removed from the FPKI Trust Infrastructure in the last 30 days.

Affiliate Subject CA Issuing CA SHA-1 Hash Expiration Date
Verizon CT-CSSP-CA-A1 Federal Bridge CA 2016 687066BCE56B6E20AEA0C605B9B6679342269F21 Revoked - 08/06/2019
Verizon Federal Bridge CA 2016 CT-CSSP-CA-A1 73DCCF6418522B69A50A96721AEB96441E6EF3C0 Revoked - 08/08/2019
TSCP TSCP SHA256 Bridge CA Federal Bridge CA 2016 949E7F407D71EEE663709D5D2A680460146CE530 Expired - 08/11/2019
WidePoint Federal Bridge CA 2016 ORC NFI CA 2 E5B1E78672EEA3702A7C713B63D238DB1EBC601B Revoked - 08/14/2019
WidePoint ORC NFI CA 2 Federal Bridge CA 2016 B055C6EE104E01EB688C8FB4F87CF77CA376AFDB Revoked - 08/14/2019
DoD DoD Interoperability Root CA 2 Federal Bridge CA 2016 949E7F407D71EEE663709D5D2A680460146CE530 Expired - 08/15/2019

The following certificates are expiring in the next four months and may be re-issued.

Affiliate Subject CA Issuing CA SHA-1 Hash Expiration Date
FPKIMA Federal Common Policy CA Federal Bridge CA 2016 E5AE09B5237F70B25EF517381D781FA0067FE40C 11/08/2019

Repository Availability

Respository availability is an uptime metric for Certificate Revocation List availability. The table only contains Certification Authorities directly certified with the FPKIMA. A metric of “99” in the table below means the Certificate Revocation List was available for 99% of the given month, in other words, the file was not available for 1% of the month (18 minutes depending on the month). The last column is the 12-Month average.

Federal Agency or Affiliate CA FPKIMA CA July 2019 Average
CertiPath Bridge CA - G2 FBCA 100 99.99
CT-CSSP-CA-A1 FBCA 100 99.99
DigiCert Federated ID L3 CA FBCA 100 100
DoD Interoperability Root CA 2 FBCA 100 99.92
Entrust Managed Services NFI Root CA FBCA 100 100
Exostar Federated Identity Service Root CA FBCA 100 99.99
Federal Bridge CA 2016 FBCA 100 100
GPO PCA FBCA 100 99.74
IdenTrust ACES 2 FBCA 100 100
IdenTrust Global Common Root CA 1 FBCA 100 100
ORC ACES 4 CA FBCA 100 100
ORC NFI 2 CA FBCA 100 100
ORC NFI 3 CA FBCA 100 100
SAFE Bridge CA 02 FBCA 100 100
STRAC Bridge Root Certification Authority FBCA 99.26 99.84
Symantec Class 3 SSP Intermediate CA - G3 FBCA 100 99.31
TSCP SHA256 Bridge CA FBCA 100 99.99
USPTO_INTR_CA1 FBCA 100 99.94
DigiCert Intermediate SSP CA - G5 FCPCA 100 99.69
Entrust Managed Services Root CA FCPCA 99.84 99.57
Federal Common Policy CA FCPCA 100 100
ORC SSP 4 FCPCA 100 99.99
Symantec SSP Intermediate CA - G4 FCPCA 100 99.07
U.S. Department of State AD Root CA FCPCA 100 99.99
US Treasury Root CA FCPCA 100 100
Verisign SSP Intermediate CA - G3 FCPCA 100 99.52
Verizon SSP CA A2 FCPCA 100 100
CertiPath Bridge CA SHA1FRCA 100 99.99
DoD Interoperability Root CA 1 SHA1FRCA 100 99.93
SHA-1 Federal Root CA G2 SHA1FRCA 100 100