{"id":3052,"date":"2016-09-26T14:11:50","date_gmt":"2016-09-26T14:11:50","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3052"},"modified":"2023-04-07T17:25:12","modified_gmt":"2023-04-07T21:25:12","slug":"macos-trusted-root-certificates","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/macos-trusted-root-certificates\/","title":{"rendered":"Changes to Trusted Root Certificates in Mac OS Sierra and iOS 10"},"content":{"rendered":"<h2>Apple&#8217;s Latest OS Trusts 165 Root Certificates.<\/h2>\n<p>Root\u00a0Stores are a database of root\u00a0certificates that a computer &#8220;trusts&#8221; as an issuer of SSL, Code Signing, and other X.509-standard certificates. This list of roots dictates what certificates your computer will automatically allow a connection with, or &#8220;trust.&#8221; Certificates originating from a root that is not on this list will have to be manually accepted, and are not practical for use on public websites or services.<\/p>\n<p>These root certificates belong to Certificate Authorities (CAs), which consists of a wide range of organizations, including well-known cyber security companies like Symantec and Comodo, to regional providers and government offices. The average user will only interact with certificates from a handful of these providers. But their devices, and hundreds of millions of other devices around the world still trust these certificates, which is often criticized as a security risk.<\/p>\n<p>Vendors either maintain their own root\u00a0store, or use an existing one. These root stores often have policies for acceptance, which include yearly audits and compliance reports to show that the CAs are following industry requirements.<\/p>\n<p>Microsoft and Apple maintain their own root\u00a0stores for their operating systems. Mozilla also operates one used by its Firefox browser and many Linux distributions.<\/p>\n<p><span style=\"font-weight: 400;\">Operating Systems usually make changes to their trusted (and un-trusted) root certificates during major updates. Apple updates their trust store with every major release of Mac OS and iOS.<\/span><\/p>\n<p>The newest version of Apple\u2019s Mac OS operating system &#8211; Version 10.12, or \u201cSierra\u201d &#8211; was\u00a0released last week; and iOS 10 was released the week before that.<\/p>\n<p>Oftentimes this means the trusted root store is growing on each and every release. However, with Sierra and iOS 10, Apple&#8217;s trust store has actually gotten smaller.<\/p>\n<p>Here are some quick facts about Apple&#8217;s trust store:<\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Mac OS and iOS trust\u00a0165 root certificates in total. This is 23 fewer total certificates than the previous version (in El Capitan). Only two new roots have been added. (Update: The ISRG Root, used by Let&#8217;s Encrypt, was added in a later update).<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Of the 165 root certificates, 152 use RSA keys and 13 use ECDSA keys. Of the RSA keys, 102 are 2048-bit and 50 are 4096-bit. Twelve of the ECDSA keys are 384-bit and one is 256-bit.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Two root certificates expired before Sierra even released. A third is expiring this October. All all three of those CAs (AS Sertifitseerimiskeskus, E-Turga, and BuyPass) have other roots that will remain trusted for some time.<br \/>\n<\/span><\/li>\n<li><span style=\"font-weight: 400;\">On the other end, the longest-living root is owned by Certum and won\u2019t expire until 2046. At least it uses a 4096-bit RSA key&#8230;<\/span><\/li>\n<li>UPDATE: TurkishCA TURKTRUST <a href=\"https:\/\/cabforum.org\/pipermail\/public\/2016-September\/008475.html\">has announced that they will be suspending their SSL business<\/a> as a result of not getting their new roots added to Apple&#8217;s store. Their current root will expire in December 0f 2017, giving them only one year until their certificates will become inoperable on Apple devices. It is well known within the CA\/SSL industry that Apple&#8217;s CA program is one of the most difficult programs to work with.<\/li>\n<\/ul>\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n<h2><b>Changes to Apple&#8217;s\u00a0Root Store<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">These changes are in comparison to the root certificates that were included with the previous version of Mac OS, El Capitan (10.11). The full list of root certificates comes directly from Apple. The certificate data below is directly from these Apple support pages: <\/span><a href=\"https:\/\/support.apple.com\/en-us\/HT207189\"><span style=\"font-weight: 400;\">Roots in Sierra<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><span style=\"font-weight: 400;\"><a href=\"https:\/\/support.apple.com\/en-us\/HT205204\">Roots in El Capitan<\/a>\u00a0(with the exception of the &#8220;EV Policy&#8221; column which has been simplified for formatting)<\/span><span style=\"font-weight: 400;\">.\u00a0iOS 10 has the <a href=\"https:\/\/support.apple.com\/en-us\/HT207177\">same Root\u00a0Store<\/a> as Sierra.<\/span><\/p>\n<p>Apple\u2019s Root\u00a0Store has three lists\u00a0of certificates: Trusted, Always Ask, and Blocked. Always Ask certificates are \u201cuntrusted but not blocked. When one of these certificates is used, you&#8217;ll be prompted to choose whether or not to trust it.\u201d Blocked certificates are entirely unusable. This latest update has made changes to all three lists.<\/p>\n<p><span style=\"font-weight: 400;\">Without further ado, here are the changes:<\/span><\/p>\n<h2><b>Trusted Root Certificates:<\/b><\/h2>\n<p><b>Added in Mac OS Sierra\/iOS 10<\/b><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Certificate name<\/b><\/td>\n<td><b>Issued by<\/b><\/td>\n<td><b>Type<\/b><\/td>\n<td><b>Key size<\/b><\/td>\n<td><b>Sig alg<\/b><\/td>\n<td><b>Serial number<\/b><\/td>\n<td><b>Expires<\/b><\/td>\n<td><b>EV policy<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Certum Trusted Network CA 2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Certum Trusted Network CA 2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-512<\/span><\/td>\n<td><span style=\"font-weight: 400;\">21 D6 D0 4A 4F 25 0F C9 32 37 FC AA 5E 12 8D E9<\/span><\/td>\n<td><span style=\"font-weight: 400;\">08:39:56 Oct 6, 2046<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Yes<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">OISTE WISeKey Global Root GB CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">OISTE WISeKey Global Root GB CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.thesslstore.com\/blog\/generate-2048-bit-csr\/\">2048<\/a> bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-256<\/span><\/td>\n<td><span style=\"font-weight: 400;\">76 B1 20 52 74 F0 85 87 46 B3 F8 23 1A F6 C2 C0<\/span><\/td>\n<td><span style=\"font-weight: 400;\">15:10:31 Dec 1, 2039<\/span><\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>ISRG Root X1<\/td>\n<td>ISRG Root X1<\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-256<\/span><\/td>\n<td>00 82 10 CF B0 D2 40 E3 59 44 63 E0 BB 63 82 8B 00<\/td>\n<td>11:04:38 Jun 4, 2035<\/td>\n<td>No<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Notes: The ISRG Root (belonging to Let&#8217;s Encrypt) <a href=\"https:\/\/twitter.com\/letsencrypt\/status\/790960929504497665\">was added in an update in version 10.12.1<\/a><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Certum has two \u201cCertum Trusted Network CA 2\u201d root certificates that are identical except for their serial number. In Sierra\/iOS 10, <\/span><a href=\"https:\/\/crt.sh\/?id=12979952\" rel=\"nofollow\"><span style=\"font-weight: 400;\">one <\/span><\/a><span style=\"font-weight: 400;\">of these roots was swapped for the <\/span><a href=\"https:\/\/crt.sh\/?id=6005922\" rel=\"nofollow\"><span style=\"font-weight: 400;\">other<\/span><\/a><span style=\"font-weight: 400;\">. So while this specific certificate is an \u201caddition,\u201d it is not so in the traditional sense.<\/span><\/p>\n<p><b>Removed in Mac OS Sierra\/iOS 10<\/b><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Certificate name<\/b><\/td>\n<td><b>Issued by<\/b><\/td>\n<td><b>Type<\/b><\/td>\n<td><b>Key size<\/b><\/td>\n<td><b>Sig alg<\/b><\/td>\n<td><b>Serial number<\/b><\/td>\n<td><b>Expires<\/b><\/td>\n<td><b>EV policy<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">A-Trust-nQual-01<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A-Trust-nQual-01<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.thesslstore.com\/blog\/generate-2048-bit-csr\/\">2048<\/a> bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 E2 42<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:00:00 Nov 30, 2014<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">A-Trust-nQual-03<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A-Trust-nQual-03<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">01 6C 1E<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22:00:00 Aug 17, 2015<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">A-Trust-Qual-01<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A-Trust-Qual-01<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 E2 43<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:00:00 Nov 30, 2014<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">A-Trust-Qual-02<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A-Trust-Qual-02<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 E2 48<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:00:00 Dec 2, 2014<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">AddTrust Qualified CA Root<\/span><\/td>\n<td><span style=\"font-weight: 400;\">AddTrust Qualified CA Root<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">10:44:50 May 30, 2020<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">AddTrust Public CA Root<\/span><\/td>\n<td><span style=\"font-weight: 400;\">AddTrust Public CA Root<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">10:41:50 May 30, 2020<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">AdminCA-CD-T01<\/span><\/td>\n<td><span style=\"font-weight: 400;\">AdminCA-CD-T01<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">12:36:19 Jan 25, 2016<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Application CA G2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Application CA G2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">31<\/span><\/td>\n<td><span style=\"font-weight: 400;\">14:59:59 Mar 31, 2016<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Buypass Class 3 CA 1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Buypass Class 3 CA 1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">14:13:03 May 9, 2015<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Yes<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">CA Disig<\/span><\/td>\n<td><span style=\"font-weight: 400;\">CA Disig<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">01:39:34 Mar 22, 2016<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Certum Trusted Network CA 2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Certum Trusted Network CA 2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-512<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 B8 59 14 71 3F 57 DF 8F 31 C0 33 3D D2 D6 19 7A 23 17 B4 EB<\/span><\/td>\n<td><span style=\"font-weight: 400;\">08:39:56 Oct 6, 2046<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Yes<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">NetLock Kozjegyzoi (Class A) Tanusitvanykiado<\/span><\/td>\n<td><span style=\"font-weight: 400;\">NetLock Kozjegyzoi (Class A) Tanusitvanykiado<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">MD5<\/span><\/td>\n<td><span style=\"font-weight: 400;\">01 03<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:14:47 Feb 19, 2019<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Secure Certificate Services<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Secure Certificate Services<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 Dec 31, 2028<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Staat der Nederlanden Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Staat der Nederlanden Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 98 96 8A<\/span><\/td>\n<td><span style=\"font-weight: 400;\">09:15:38 Dec 16, 2015<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Class 2 CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Class 2 CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2E 6A 00 01 00 02 1F D7 52 21 2C 11 5C 3B<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22:59:59 Dec 31, 2025<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Class 3 CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Class 3 CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4A 47 00 01 00 02 E5 A0 5D D6 3F 00 51 BF<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22:59:59 Dec 31, 2025<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Class 4 CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Class 4 CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">05 C0 00 01 00 02 41 D0 06 0A 4D CE 75 10<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22:59:59 Dec 31, 2025<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Universal CA I<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Universal CA I<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1D A2 00 01 00 02 EC B7 60 80 78 8D B6 06<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22:59:59 Dec 31, 2025<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Universal CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Universal CA II<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">19 33 00 01 00 02 28 1A 9A 04 BC F2 55 45<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22:59:59 Dec 31, 2030<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Universal CA III<\/span><\/td>\n<td><span style=\"font-weight: 400;\">TC TrustCenter Universal CA III<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">63 25 00 01 00 02 14 8D 33 15 02 E4 6C F4<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 Dec 31, 2029<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Yes<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Trusted Certificate Services<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Trusted Certificate Services<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 Dec 31, 2028<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">T\u00dcRKTRUST Elektronik Sertifika Hizmet Sa\u011flay\u0131c\u0131s\u0131<\/span><\/td>\n<td><span style=\"font-weight: 400;\">T\u00dcRKTRUST Elektronik Sertifika Hizmet Sa\u011flay\u0131c\u0131s\u0131<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">10:07:57 Sep 16, 2015<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">T\u00dcRKTRUST Elektronik Sertifika Hizmet Sa\u011flay\u0131c\u0131s\u0131<\/span><\/td>\n<td><span style=\"font-weight: 400;\">T\u00dcRKTRUST Elektronik Sertifika Hizmet Sa\u011flay\u0131c\u0131s\u0131<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">10:27:17 Mar 22, 2015<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">VeriSign Class 4 Public Primary Certification Authority &#8211; G3<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VeriSign Class 4 Public Primary Certification Authority &#8211; G3<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 EC A0 A7 8B 6E 75 6A 01 CF C4 7C CC 2F 94 5E D7<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 Jul 16, 2036<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Notes: Certum has two \u201cCertum Trusted Network CA 2\u201d root certificates that are identical except for their serial number. In Sierra\/iOS 10, <\/span><a href=\"https:\/\/crt.sh\/?id=12979952\" rel=\"nofollow\"><span style=\"font-weight: 400;\">one <\/span><\/a><span style=\"font-weight: 400;\">of these roots was swapped for the <\/span><a href=\"https:\/\/crt.sh\/?id=6005922\" rel=\"nofollow\"><span style=\"font-weight: 400;\">other<\/span><\/a><span style=\"font-weight: 400;\">. So while this specific certificate is a \u201cremoval,\u201d it is not so in the traditional sense.<\/span><\/p>\n<h2><b>Always Ask Certificates<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">No certificates have been added here. A DigiNotar certificate was moved to the Blocked list.<\/span><\/p>\n<p><b>Removed in Mac OS Sierra\/iOS 10<\/b><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Certificate name<\/b><\/td>\n<td><b>Issued by<\/b><\/td>\n<td><b>Type<\/b><\/td>\n<td><b>Key size<\/b><\/td>\n<td><b>Sig alg<\/b><\/td>\n<td><b>Serial number<\/b><\/td>\n<td><b>Expires<\/b><\/td>\n<td><b>EV policy<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">DigiNotar Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">DigiNotar Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">0C 76 DA 9C 91 0C 4E 2C 9E FE 15 D0 58 93 3C 4C<\/span><\/td>\n<td><span style=\"font-weight: 400;\">18:19:21 Mar 31, 2025<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><b>Blocked Certificates<\/b><\/h2>\n<p><strong>Added in Mac OS Sierra<b>\/iOS 10<\/b><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Certificate name<\/b><\/td>\n<td><b>Issued by<\/b><\/td>\n<td><b>Type<\/b><\/td>\n<td><b>Key size<\/b><\/td>\n<td><b>Sig alg<\/b><\/td>\n<td><b>Serial number<\/b><\/td>\n<td><b>Expires<\/b><\/td>\n<td><b>EV policy<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">*.sslip.io<\/span><\/td>\n<td><span style=\"font-weight: 400;\">COMODO RSA Domain Validation Secure Server CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-256<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 EC 60 FA FC A1 CA 06 AE E9 B7 36 48 0A 28 2F AA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 Aug 19, 2018<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Class 3 Public Primary Certification Authority<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Class 3 Public Primary Certification Authority<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">1024 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">3C 91 31 CB 1F F6 D0 1B 0E 9A B8 D0 44 BF 12 BE<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 Aug 2, 2028<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">DigiNotar Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">DigiNotar Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">00 E9 41 4E AA 63 E3 65 C4 0A 2F E3 FD 52 2E E2 99<\/span><\/td>\n<td><span style=\"font-weight: 400;\">16:27:01 May 14, 2027<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">DigiNotar Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">DigiNotar Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4096 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">0C 76 DA 9C 91 0C 4E 2C 9E FE 15 D0 58 93 3C 4C<\/span><\/td>\n<td><span style=\"font-weight: 400;\">18:19:21 Mar 31, 2025<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Egypt Trust Class 3 Managed PKI Enterprise Administrator CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VeriSign Class 3 Public Primary Certification Authority &#8211; G3<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4C 00 36 1B E5 08 2B A9 AA CE 74 0A 05 3E FB 34<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 May 17, 2018<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Egypt Trust Class 3 Managed PKI Operational Administrator CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VeriSign Class 3 Public Primary Certification Authority &#8211; G3<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">3E 0C 9E 87 69 AA 95 5C EA 23 D8 45 9E D4 5B 51<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 May 17, 2018<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Egypt Trust Class 3 Managed PKI SCO Administrator CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">VeriSign Class 3 Public Primary Certification Authority &#8211; G3<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">12 BD 26 A2 AE 33 C0 7F 24 7B 6A 58 69 F2 0A 76<\/span><\/td>\n<td><span style=\"font-weight: 400;\">23:59:59 May 17, 2018<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">The Walt Disney Company Root CA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Entrust.net Certification Authority (2048)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RSA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">2048 bits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SHA-1<\/span><\/td>\n<td><span style=\"font-weight: 400;\">4C 0E 84 56<\/span><\/td>\n<td><span style=\"font-weight: 400;\">22:22:12 Jan 16, 2019<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Not EV<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Apple&#8217;s Latest OS Trusts 165 Root Certificates. Root\u00a0Stores are a database of root\u00a0certificates that a computer &#8220;trusts&#8221; as an issuer of SSL, Code Signing, and other X.509-standard certificates. This list&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3074,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[219,218,221,136,220],"class_list":["post-3052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-ios-10","tag-mac-os-sierra","tag-root-certificates","tag-ssl","tag-trusted-root","post-with-tags"],"views":54301,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/09\/Depositphotos_61978047_m-2015.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3052"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3052\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3074"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}