Hierarchy
Two-tier hierarchy. The root is kept offline on a hardware token and is only used to certify issuing CAs. All end-entity certificates chain to the issuing CA; relying parties only need to trust the root.
CA certificates
manufactAI Root CA G1 OFFLINE
Trust anchor. Kept offline; used only to sign issuing CA certificates and the root CRL.
| Subject | CN=manufactAI Root CA G1 |
|---|---|
| Issuer | CN=manufactAI Root CA G1 |
| Serial number | ECA87B223A8770D6A57F826B940970B2 |
| Valid from | 2026-08-23 14:06 UTC |
| Valid until | 2046-08-18 14:06 UTC |
| Public key | ECDSA P-384 (384 bit) |
| Signature | ECDSA with SHA384 |
| Subject key identifier | 18:58:48:A9:B9:B1:71:05:05:9F:34:B6:CA:46:F6:30:9B:AC:6B:78 |
| SHA-256 fingerprint | EB:E2:11:B9:0D:66:0F:57:CC:35:1F:1F:9D:8D:B0:C3:EE:CD:23:C9:CB:62:4C:FE:02:FC:FC:F9:EA:3C:0A:86 |
manufactAI Issuing CA 1 ONLINE
Online issuing authority. Signs all end-entity certificates (TLS server, mTLS client, internal services).
| Subject | CN=manufactAI Issuing CA 1 |
|---|---|
| Issuer | CN=manufactAI Root CA G1 |
| Serial number | EA7795525496D7360559D86834791256 |
| Valid from | 2026-08-23 14:07 UTC |
| Valid until | 2031-08-22 14:07 UTC |
| Public key | ECDSA P-256 (256 bit) |
| Signature | ECDSA with SHA384 |
| Subject key identifier | 3E:92:74:A0:DF:46:1D:B7:CE:62:15:8A:D8:35:C9:8B:D5:A6:FC:3C |
| SHA-256 fingerprint | 61:B1:C7:1A:CA:B5:93:F3:CB:FD:E0:34:9A:40:0E:E6:B4:97:8A:96:98:B9:ED:4A:4D:E8:1A:45:BE:2D:CE:AA |
Certificate chain bundle
Issuing CA followed by root CA, PEM encoded. Use this as the CA bundle for TLS clients and reverse proxies that validate our certificates.
| SHA-256 (bundle file) | 20:99:46:85:25:54:FB:EF:CB:09:0A:0A:6D:62:31:78:00:05:EB:E5:50:F3:A3:72:4F:59:53:5B:5E:67:A2:80 |
|---|
Certificate revocation list
Issuing CA CRL current
Regenerated by the issuing CA on every revocation and republished here within 15 minutes. The distribution point embedded in our certificates is http://pki.manufactai.com/manufactai-issuing-ca-1.crl, served over plain HTTP so that strict validators can fetch it without depending on the public web PKI.
| Issuer | CN=manufactAI Issuing CA 1 |
|---|---|
| This update | 2026-08-23 14:31 UTC |
| Next update | 2026-08-30 14:31 UTC |
| Revoked certificates | 2 |
| SHA-256 (DER) | 62:05:2C:A9:20:69:F1:6D:E4:DB:AD:20:50:A1:5D:0D:1A:D9:BE:9E:F7:09:0F:46:2B:C4:F4:9C:BC:98:42:52 |
Root CRL current
Signed offline by the root CA. It states whether an issuing CA has been revoked and is referenced by the CRL distribution point inside the issuing CA certificate: http://pki.manufactai.com/manufactai-root-ca-g1.crl.
| Issuer | CN=manufactAI Root CA G1 |
|---|---|
| This update | 2026-08-23 14:07 UTC |
| Next update | 2027-08-23 14:07 UTC |
| Revoked CA certificates | 0 |
| SHA-256 (DER) | 59:4D:E3:69:41:38:19:39:3F:39:D6:DB:88:6E:71:70:6E:7C:2C:CF:3E:AA:0D:D1:5F:0A:52:57:A7:8C:04:B3 |