Independent public mirror of national PKI trust anchors, not an authority. Certificates are published by each national PKI (e.g., BCCR for Costa Rica); this site mirrors and structures them.
Certificates
5
Roots
2
Intermediates
3
did:pki
5
Updated
Model
National hierarchy
Governing law
Código de Comercio, Título Segundo «Del Comercio Electrónico» · Código Fiscal de la Federación art. 17-D (e.firma)
Key algorithms
RSA-4096
Signature standards
CAdESPAdESXAdES
Capabilitiese.firma (FIEL)Certificado de Sello Digital (CSD)Firma electrónica avanzada

National hierarchy for the e.firma (FIEL) / CSD infrastructure. The root — AGENCIA REGISTRADORA CENTRAL (ARC), O=BANCO DE MEXICO — is operated by Banco de México's Infraestructura Extendida de Seguridad (IES); two currently-valid self-signed root generations are mirrored (ARC5, RSA-4096, valid to 2034; ARC6, RSA-4096, valid to 2039). The SAT operates the subordinate issuing CAs that grant e.firma and Certificados de Sello Digital to taxpayers: AC5 (valid to 2027, chains to ARC5) and AC6 / AC7 (valid to 2031, chain to ARC6). Certificates were promoted from the SAT's official production bundle (Cert_Prod.zip). Chains cross-verified with openssl (AC5→ARC5; AC6,AC7→ARC6). Expired generations (ARC0–ARC4 / AC0–AC4) and OCSP-responder certs are archived out of current/. RSA-4096 throughout. Note: the AC6 certificate carries a mis-encoded (double-UTF-8) common name in its issued bytes — the manifest reproduces those exact bytes faithfully; see VERIFICATION.md.