Certificate Authority Repository

Trust, verify and validate certificates issued by manufactAI.

  • Offline root, online issuing CA
  • Short-lived certificates with automated renewal
  • Revocation list regenerated on every revocation
Issuing CA operational CRL current · next update 2026-08-30 14:31 UTC · 2 revoked Updated 2026-08-23 14:45 UTC
Structure

Hierarchy

Two-tier hierarchy. The root is kept offline on a hardware token and is only used to certify issuing CAs. All end-entity certificates chain to the issuing CA; relying parties only need to trust the root.

manufactAI Root CA G1ECDSA P-384 (384 bit) · until 2046-08offline
manufactAI Issuing CA 1ECDSA P-256 (256 bit) · until 2031-08online
End-entity certificates · TLS server · mTLS client · internal services · ≤ 90 days
Trust anchors

CA certificates

manufactAI Root CA G1 OFFLINE

Trust anchor. Kept offline; used only to sign issuing CA certificates and the root CRL.

SubjectCN=manufactAI Root CA G1
IssuerCN=manufactAI Root CA G1
Serial numberECA87B223A8770D6A57F826B940970B2
Valid from2026-08-23 14:06 UTC
Valid until2046-08-18 14:06 UTC
Public keyECDSA P-384 (384 bit)
SignatureECDSA with SHA384
Subject key identifier18:58:48:A9:B9:B1:71:05:05:9F:34:B6:CA:46:F6:30:9B:AC:6B:78
SHA-256 fingerprintEB:E2:11:B9:0D:66:0F:57:CC:35:1F:1F:9D:8D:B0:C3:EE:CD:23:C9:CB:62:4C:FE:02:FC:FC:F9:EA:3C:0A:86

manufactAI Issuing CA 1 ONLINE

Online issuing authority. Signs all end-entity certificates (TLS server, mTLS client, internal services).

SubjectCN=manufactAI Issuing CA 1
IssuerCN=manufactAI Root CA G1
Serial numberEA7795525496D7360559D86834791256
Valid from2026-08-23 14:07 UTC
Valid until2031-08-22 14:07 UTC
Public keyECDSA P-256 (256 bit)
SignatureECDSA with SHA384
Subject key identifier3E:92:74:A0:DF:46:1D:B7:CE:62:15:8A:D8:35:C9:8B:D5:A6:FC:3C
SHA-256 fingerprint61:B1:C7:1A:CA:B5:93:F3:CB:FD:E0:34:9A:40:0E:E6:B4:97:8A:96:98:B9:ED:4A:4D:E8:1A:45:BE:2D:CE:AA

Certificate chain bundle

Issuing CA followed by root CA, PEM encoded. Use this as the CA bundle for TLS clients and reverse proxies that validate our certificates.

SHA-256 (bundle file)20:99:46:85:25:54:FB:EF:CB:09:0A:0A:6D:62:31:78:00:05:EB:E5:50:F3:A3:72:4F:59:53:5B:5E:67:A2:80
Revocation

Certificate revocation list

Issuing CA CRL current

Regenerated by the issuing CA on every revocation and republished here within 15 minutes. The distribution point embedded in our certificates is http://pki.manufactai.com/manufactai-issuing-ca-1.crl, served over plain HTTP so that strict validators can fetch it without depending on the public web PKI.

IssuerCN=manufactAI Issuing CA 1
This update2026-08-23 14:31 UTC
Next update2026-08-30 14:31 UTC
Revoked certificates2
SHA-256 (DER)62:05:2C:A9:20:69:F1:6D:E4:DB:AD:20:50:A1:5D:0D:1A:D9:BE:9E:F7:09:0F:46:2B:C4:F4:9C:BC:98:42:52

Root CRL current

Signed offline by the root CA. It states whether an issuing CA has been revoked and is referenced by the CRL distribution point inside the issuing CA certificate: http://pki.manufactai.com/manufactai-root-ca-g1.crl.

IssuerCN=manufactAI Root CA G1
This update2026-08-23 14:07 UTC
Next update2027-08-23 14:07 UTC
Revoked CA certificates0
SHA-256 (DER)59:4D:E3:69:41:38:19:39:3F:39:D6:DB:88:6E:71:70:6E:7C:2C:CF:3E:AA:0D:D1:5F:0A:52:57:A7:8C:04:B3
Navigate

Quick links