Independent public mirror of national PKI trust anchors, not an authority. Certificates are published by each national PKI (e.g., BCCR for Costa Rica); this site mirrors and structures them.
Certificates
5
Roots
0
Intermediates
5
did:pki
5
Updated
Model
Accredited CAs (ETSI Trusted List)
Governing law
Reglamento eIDAS (UE) 910/2014 · Elektronisko dokumentu likums (Latvia's Electronic Documents Law)
Key algorithms
RSA-4096, EC P-521
Signature standards
CAdESPAdESXAdESASiC
CapabilitiesQualified e-signature & e-seal (eIDAS)Qualified timestampingQualified website authentication (QWAC / PSD2)

Latvia's qualified-signature trust is issued by the accredited QTSP VAS Latvijas Valsts radio un televīzijas centrs (LVRTC / NTRLV-40003011203), which operates the eParaksts and LV eID qualified certificate services, supervised by the Digitālās drošības uzraudzības komiteja (DDUK), the Digital Security Supervisory Committee acting as Latvia's eIDAS supervisory body and national Trusted List scheme operator, and published in the Latvian national eIDAS Trusted List (latvian-tsl.xml, ETSI TS 119 612). As an EU / eIDAS participant, Latvia is referenced from the EU LOTL. The 5 currently-granted CA certificates were promoted wholesale after verifying the Trusted List's XAdES signature through the EU LOTL chain of trust: the LOTL signature was checked against the pinned European Commission signing anchor, and the Latvian TSL's signature (signer: C=LV, O=Digitālās drošības uzraudzības komiteja, CN=Latvian Trust List Scheme Operator; cert SHA-256 8b044cf46b90f954f44383fc8ef252d66f1f7a6a1da8ca4f9b5ed9aff024dae2) against the identity the LOTL declares for Latvia, so the list's single seal vouches for every certificate it contains (eIDAS Art. 22). Only services with a currently-granted status and a CA / qualified-certificate service type were selected; withdrawn, deprecated, and non-CA services (including the legacy E-ME SSI/PSI PKI, which is not under supervision) were dropped. Verification evidence is in VERIFICATION.md. Key algorithms across the set are mixed: the eParaksts and LV eID issuing CAs of the 2017 and 2021 generations use RSA-4096, and the LV eID ICA 2025 uses EC P-521. All 5 entries are LVRTC issuing CAs (eParaksts ICA 2017 / 2021 and LV eID ICA 2017 / 2021 / 2025), all issued by the self-signed eParaksts Root CA, which is not carried by the list and must be sourced separately if root-anchored path building is required. The eParaksts ICA 2017 and LV eID ICA 2017 have passed their notAfter and are retained as archived-but-granted entries; they surface under the Expired status filter.

Expired certificates are hidden by default; they remain useful only for validating older signatures.

  • eParaksts ICA 2017

    Intermediate CAExpired (102 days ago)
    Issuer
    eParaksts Root CA
    Valid
    to
    Serial
    3dc7d632b0…1b3516
    SHA-256
    b3cd228247…a7eac00bae

    Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.

  • eParaksts ICA 2021

    Intermediate CAValid (1270 days left)
    Issuer
    eParaksts Root CA
    Valid
    to
    Serial
    287a8600ed…39096c
    SHA-256
    adecfba900…31e4497cf9

    Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.

  • LV eID ICA 2017

    Intermediate CAExpired (174 days ago)
    Issuer
    eParaksts Root CA
    Valid
    to
    Serial
    6ddd894549…675408
    SHA-256
    c77d160833…a644869e25

    Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.

  • LV eID ICA 2021

    Intermediate CAValid (1270 days left)
    Issuer
    eParaksts Root CA
    Valid
    to
    Serial
    1ba4103e7f…2f9f84
    SHA-256
    292efebd08…b54679a431

    Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.

  • LV eID ICA 2025

    Intermediate CAValid (2704 days left)
    Issuer
    eParaksts Root CA
    Valid
    to
    Serial
    36535a2c96…70b138
    SHA-256
    a14385c34d…c4e76352cc

    Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.