Espejo público independiente de anclas de confianza PKI nacionales, no una autoridad. Los certificados son publicados por cada PKI nacional (ej. BCCR en Costa Rica); este sitio los replica y estructura.
Certificados
5
Raíces
0
Intermedias
5
did:pki
5
Actualizado
Modelo
CAs acreditadas (Lista de confianza ETSI)
Marco legal
Reglamento eIDAS (UE) 910/2014 · Elektronisko dokumentu likums (Latvia's Electronic Documents Law)
Algoritmos de clave
RSA-4096, EC P-521
Estándares de firma
CAdESPAdESXAdESASiC
CapacidadesQualified e-signature & e-seal (eIDAS)Qualified timestampingQualified website authentication (QWAC / PSD2)

Latvia's qualified-signature trust is issued by the accredited QTSP VAS Latvijas Valsts radio un televīzijas centrs (LVRTC / NTRLV-40003011203), which operates the eParaksts and LV eID qualified certificate services, supervised by the Digitālās drošības uzraudzības komiteja (DDUK), the Digital Security Supervisory Committee acting as Latvia's eIDAS supervisory body and national Trusted List scheme operator, and published in the Latvian national eIDAS Trusted List (latvian-tsl.xml, ETSI TS 119 612). As an EU / eIDAS participant, Latvia is referenced from the EU LOTL. The 5 currently-granted CA certificates were promoted wholesale after verifying the Trusted List's XAdES signature through the EU LOTL chain of trust: the LOTL signature was checked against the pinned European Commission signing anchor, and the Latvian TSL's signature (signer: C=LV, O=Digitālās drošības uzraudzības komiteja, CN=Latvian Trust List Scheme Operator; cert SHA-256 8b044cf46b90f954f44383fc8ef252d66f1f7a6a1da8ca4f9b5ed9aff024dae2) against the identity the LOTL declares for Latvia, so the list's single seal vouches for every certificate it contains (eIDAS Art. 22). Only services with a currently-granted status and a CA / qualified-certificate service type were selected; withdrawn, deprecated, and non-CA services (including the legacy E-ME SSI/PSI PKI, which is not under supervision) were dropped. Verification evidence is in VERIFICATION.md. Key algorithms across the set are mixed: the eParaksts and LV eID issuing CAs of the 2017 and 2021 generations use RSA-4096, and the LV eID ICA 2025 uses EC P-521. All 5 entries are LVRTC issuing CAs (eParaksts ICA 2017 / 2021 and LV eID ICA 2017 / 2021 / 2025), all issued by the self-signed eParaksts Root CA, which is not carried by the list and must be sourced separately if root-anchored path building is required. The eParaksts ICA 2017 and LV eID ICA 2017 have passed their notAfter and are retained as archived-but-granted entries; they surface under the Expired status filter.

Los certificados vencidos se ocultan por defecto; solo sirven para validar firmas antiguas.

  • eParaksts ICA 2017

    CA IntermediaExpirado (hace 102 días)
    Emisor
    eParaksts Root CA
    Validez
    a
    Serie
    3dc7d632b0…1b3516
    SHA-256
    b3cd228247…a7eac00bae

    El emisor "eParaksts Root CA" no está presente en este espejo, por lo que la cadena no se puede verificar completamente aquí.

  • eParaksts ICA 2021

    CA IntermediaVálido (quedan 1270 días)
    Emisor
    eParaksts Root CA
    Validez
    a
    Serie
    287a8600ed…39096c
    SHA-256
    adecfba900…31e4497cf9

    El emisor "eParaksts Root CA" no está presente en este espejo, por lo que la cadena no se puede verificar completamente aquí.

  • LV eID ICA 2017

    CA IntermediaExpirado (hace 174 días)
    Emisor
    eParaksts Root CA
    Validez
    a
    Serie
    6ddd894549…675408
    SHA-256
    c77d160833…a644869e25

    El emisor "eParaksts Root CA" no está presente en este espejo, por lo que la cadena no se puede verificar completamente aquí.

  • LV eID ICA 2021

    CA IntermediaVálido (quedan 1270 días)
    Emisor
    eParaksts Root CA
    Validez
    a
    Serie
    1ba4103e7f…2f9f84
    SHA-256
    292efebd08…b54679a431

    El emisor "eParaksts Root CA" no está presente en este espejo, por lo que la cadena no se puede verificar completamente aquí.

  • LV eID ICA 2025

    CA IntermediaVálido (quedan 2704 días)
    Emisor
    eParaksts Root CA
    Validez
    a
    Serie
    36535a2c96…70b138
    SHA-256
    a14385c34d…c4e76352cc

    El emisor "eParaksts Root CA" no está presente en este espejo, por lo que la cadena no se puede verificar completamente aquí.