Espejo público independiente de anclas de confianza PKI nacionales, no una autoridad. Los certificados son publicados por cada PKI nacional (ej. BCCR en Costa Rica); este sitio los replica y estructura.
Certificados
30
Raíces
0
Intermedias
30
did:pki
30
Actualizado
Modelo
CAs acreditadas (Lista de confianza ETSI)
Marco legal
Reglamento eIDAS (UE) 910/2014 · Decreto-Lei n.º 12/2021 (execução do eIDAS) · Lei n.º 37/2014 (Cartão de Cidadão / identificação civil)
Algoritmos de clave
RSA-4096, RSA-2048, EC P-384
Estándares de firma
CAdESPAdESXAdESASiC
CapacidadesQualified e-signature & e-seal (eIDAS)Qualified timestampingQualified website authentication (QWAC / PSD2)

Portugal's qualified-signature trust is a federation of accredited QTSPs (DigitalSign — Certificadora Digital, MULTICERT — Serviços de Certificação Electrónica, Global Trusted Sign, and the state Cartão de Cidadão / Chave Móvel Digital certification entities operated by AMA — Agência para a Modernização Administrativa, among others) supervised by the Gabinete Nacional de Segurança (GNS) — the Autoridade Credenciadora acting as Portugal's eIDAS supervisory body — and published in the Portuguese national eIDAS Trusted List (TSLPT.xml, ETSI TS 119 612), the SCEE (Sistema de Certificação Eletrónica do Estado). The 30 currently-granted CA certificates were promoted wholesale after verifying the Trusted List's XAdES signature through the EU LOTL chain of trust: the LOTL signature was checked against the pinned European Commission signing anchor, and the Portuguese TSL's signature (signer: C=PT, O=Gabinete Nacional de Segurança, CN=PORTUGUESE TRUST LIST SCHEME OPERATOR; cert SHA-256 13b31474c9d6e1b5d0edff4b1963051ff2ffe91deedd1bc51652a4dbfc8cf7f0) against the identity the LOTL declares for Portugal, so the list's single seal vouches for every certificate it contains (eIDAS Art. 22). Only services with a currently-granted status and a CA / qualified-certificate service type were selected; withdrawn, deprecated, and non-CA services were dropped. Verification evidence is in VERIFICATION.md. Key algorithms across the set are mixed: 19 CAs use RSA-4096, 7 use RSA-2048, and 4 use EC P-384. No certificate in the set has passed its notAfter.