Independent public mirror of national PKI trust anchors, not an authority. Certificates are published by each national PKI (e.g., BCCR for Costa Rica); this site mirrors and structures them.
Certificates
231
Roots
225
Intermediates
6
did:pki
231
Updated
Model
Accredited CAs (ETSI Trusted List)
Governing law
Reglamento eIDAS (UE) 910/2014 · CAD (D.Lgs. 82/2005)
Key algorithms
RSA-2048, RSA-4096, EC P-256, EC P-384
Signature standards
CAdESPAdESXAdESASiC
Revocation snapshot
current, refresh due Aug 13, 2028
CapabilitiesQualified e-signature & e-seal (eIDAS)Qualified timestampingCarta d'Identità Elettronica (CIE national eID)

Italy's qualified-signature trust is a federation of ~25 accredited QTSPs (Actalis, ArubaPEC, InfoCert, Namirial, Poste Italiane, Intesa, Intesi Group, TI Trust Technologies, Uanataca, and others) published in AgID's national eIDAS Trusted List. The 229 currently-granted CA certificates were promoted wholesale after verifying the Trusted List's XAdES signature through the EU LOTL chain of trust: the LOTL signature was checked against the pinned European Commission signing anchor, and the Italian TSL's signature (signer: AgID) against the identity the LOTL declares for Italy — so the list's single seal vouches for every certificate it contains (eIDAS Art. 22). Verification evidence is in VERIFICATION.md. In addition, the two Ministero dell'Interno / CNSD national eID roots behind the Carta d'Identità Elettronica (2016→2036, 2024→2044) are retained: they belong to the eID-notification mechanism rather than the QTSP list, and were cross-checked against the CIE portal and the AgID list independently.

Expired certificates are hidden by default; they remain useful only for validating older signatures.