eParaksts ICA 2017
Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.
Latvia's qualified-signature trust is issued by the accredited QTSP VAS Latvijas Valsts radio un televīzijas centrs (LVRTC / NTRLV-40003011203), which operates the eParaksts and LV eID qualified certificate services, supervised by the Digitālās drošības uzraudzības komiteja (DDUK), the Digital Security Supervisory Committee acting as Latvia's eIDAS supervisory body and national Trusted List scheme operator, and published in the Latvian national eIDAS Trusted List (latvian-tsl.xml, ETSI TS 119 612). As an EU / eIDAS participant, Latvia is referenced from the EU LOTL. The 5 currently-granted CA certificates were promoted wholesale after verifying the Trusted List's XAdES signature through the EU LOTL chain of trust: the LOTL signature was checked against the pinned European Commission signing anchor, and the Latvian TSL's signature (signer: C=LV, O=Digitālās drošības uzraudzības komiteja, CN=Latvian Trust List Scheme Operator; cert SHA-256 8b044cf46b90f954f44383fc8ef252d66f1f7a6a1da8ca4f9b5ed9aff024dae2) against the identity the LOTL declares for Latvia, so the list's single seal vouches for every certificate it contains (eIDAS Art. 22). Only services with a currently-granted status and a CA / qualified-certificate service type were selected; withdrawn, deprecated, and non-CA services (including the legacy E-ME SSI/PSI PKI, which is not under supervision) were dropped. Verification evidence is in VERIFICATION.md. Key algorithms across the set are mixed: the eParaksts and LV eID issuing CAs of the 2017 and 2021 generations use RSA-4096, and the LV eID ICA 2025 uses EC P-521. All 5 entries are LVRTC issuing CAs (eParaksts ICA 2017 / 2021 and LV eID ICA 2017 / 2021 / 2025), all issued by the self-signed eParaksts Root CA, which is not carried by the list and must be sourced separately if root-anchored path building is required. The eParaksts ICA 2017 and LV eID ICA 2017 have passed their notAfter and are retained as archived-but-granted entries; they surface under the Expired status filter.
Expired certificates are hidden by default; they remain useful only for validating older signatures.
Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.
Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.
Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.
Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.
Issuer "eParaksts Root CA" is not present in this mirror, so the chain cannot be fully resolved here.
No certificates match your filter.