CESKÁ REPUBLIKA (CZECH REPUBLIC)
Transcription
CESKÁ REPUBLIKA (CZECH REPUBLIC)
ETSI 2014 - TSL HR - PDF/A-1b generator Ing. Rado mír Šimek Digitálně podepsal Ing. Radomír Šimek DN: c=CZ, cn=Ing. Radomír Šimek, o=Ministry of the Interior of the Czech Republic, serialNumber=ICA - 10371691 Datum: 2016.07.25 10:46:05 +02'00' CESKÁ REPUBLIKA (CZECH REPUBLIC) : Trusted List Tsl Id: TSL_CZ Valid until nextUpdate value: 2017-01-10T10:00:00Z TSL signed on: 2016-07-25T08:31:16Z PDF generated on: Mon Jul 25 10:33:14 CEST 2016 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 1 ETSI 2014 - TSL HR - PDF/A-1b generator TSL Scheme Information TSL Id TSL_CZ TSLTag http://uri.etsi.org/19612/TSLTag TSL Version Identifier 5 TSL Sequence Number 42 TSL Type http://uri.etsi.org/TrstSvc/TrustedList/TSLType/EUgeneric Scheme Operator Name Name [ en ] Ministry of the Interior of the Czech Republic Name [ cs ] Ministerstvo vnitra České republiky Street Address [ en ] Nad Stolou 3 Locality [ en ] Prague 7 Postal Code [ en ] 17034 Country Name [ en ] CZ Street Address [ cs ] Nad Štolou 3 Locality [ cs ] Praha 7 Postal Code [ cs ] 17034 Country Name [ cs ] CZ PostalAddress PostalAddress ElectronicAddress URI mailto:[email protected] URI http://tsl.gov.cz/index.html Scheme Name Name [ en ] CZ:Trusted list including information related to the qualified trust service providers which are supervised by the issuing Member State, together with information related to the qualified trust services provided by them, in accordance with the relevant provisions laid down in Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 2 ETSI 2014 - TSL HR - PDF/A-1b generator Name [ cs ] CZ:Důvěryhodný seznam obsahující informace o kvalifikovaných poskytovatelích služeb vytvářejících důvěru, nad nimiž vykonává dohled vydávající členský stát, spolu s informacemi o kvalifikovaných službách vytvářejících důvěru poskytovaných těmito poskytovateli, v souladu s příslušnými ustanoveními nařízení Evropského parlamentu a Rady (EU) č. 910/2014 ze dne 23. července 2014 o elektronické identifikaci a službách vytvářejících důvěru pro elektronické transakce na vnitřním trhu a o zrušení směrnice 1999/93/ES. [ en ] http://tsl.gov.cz/doc/scheme-information_en.pdf Scheme Information URI URI Status Determination Approach http://uri.etsi.org/TrstSvc/TrustedList/StatusDetn/EUappropriate Scheme Type Community Rules URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/schemerules/EUcommon URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/schemerules/CZ Scheme Territory CZ Policy Or Legal Notice TSL Legal Notice [ en ] The applicable legal framework for the present trusted list is Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC. TSL Legal Notice [ cs ] Platným právním rámcem pro stávající důvěryhodný seznam je nařízení Evropského parlamentu a Rady (EU) č. 910/2014 ze dne 23. července 2014 o elektronické identifikaci a službách vytvářejících důvěru pro elektronické transakce na vnitřním trhu a o zrušení směrnice 1999/93/ES. Historical Information Period 65535 Pointer to other TSL - EUROPEAN UNION 1.EU TSL - MimeType: application/vnd.etsi.tsl+xml TSL Location https://ec.europa.eu/information_society/policy/esignature/trusted-list/tl-mp.xml EU TSL digital identities TSL Scheme Operator certificate fields details Version: 3 Serial Number: 694395474722160626358886281620874695673047986886 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 3 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGgTCCBGmgAwIBAgIUeaHFHm5f58zYv20JfspVJ3hossYwDQYJKoZIhvcNAQEFBQAwgZIxCzAJ BgNVBAYTAk5MMSAwHgYDVQQKExdRdW9WYWRpcyBUcnVzdGxpbmsgQi5WLjEoMCYGA1UECxMfSXNz dWluZyBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTE3MDUGA1UEAxMuUXVvVmFkaXMgRVUgSXNzdWlu ZyBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSBHMjAeFw0xMzEwMzAxMjI3MTFaFw0xNjEwMzAxMjI3 MTFaMHoxCzAJBgNVBAYTAkJFMRAwDgYDVQQIEwdCcnVzc2VsMRIwEAYDVQQHEwlFdHRlcmJlZWsx HDAaBgNVBAoTE0V1cm9wZWFuIENvbW1pc3Npb24xFDASBgNVBAsTC0luZm9ybWF0aWNzMREwDwYD VQQDDAhFQ19ESUdJVDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJgkkqvJmZaknQC7 c6H6LEr3dGtQ5IfOB3HAZZxOZbb8tdM1KMTO3sAifJC5HNFeIWd0727uZj+V5kBrUv36zEs+VxiN 1yJBmcJznX4J2TCyPfLk2NRELGu65VwrK2Whp8cLLANc+6pQn/5wKh23ehZm21mLXcicZ8whksUG b/h8p6NDe1cElD6veNc9CwwK2QT0G0mQiEYchqjJkqyY8HEak8t+CbIC4Rrhyxh3HI1fCK0WKS9J jbPQFbvGmfpBZuLPYZYzP4UXIqfBVYctyodcSAnSfmy6tySMqpVSRhjRn4KP0EfHlq7Ec+H3nwuq xd0M4vTJlZm+XwYJBzEFzFsCAwEAAaOCAeQwggHgMFgGA1UdIARRME8wCAYGBACLMAECMEMGCisG AQQBvlgBgxAwNTAzBggrBgEFBQcCARYnaHR0cDovL3d3dy5xdW92YWRpc2dsb2JhbC5ubC9kb2N1 bWVudGVuMCQGCCsGAQUFBwEDBBgwFjAKBggrBgEFBQcLAjAIBgYEAI5GAQEwdAYIKwYBBQUHAQEE aDBmMCoGCCsGAQUFBzABhh5odHRwOi8vb2NzcC5xdW92YWRpc2dsb2JhbC5jb20wOAYIKwYBBQUH MAKGLGh0dHA6Ly90cnVzdC5xdW92YWRpc2dsb2JhbC5jb20vcXZldWNhZzIuY3J0MEYGCiqGSIb3 LwEBCQEEODA2AgEBhjFodHRwOi8vdHNhMDEucXVvdmFkaXNnbG9iYWwuY29tL1RTUy9IdHRwVHNw U2VydmVyMBMGCiqGSIb3LwEBCQIEBTADAgEBMA4GA1UdDwEB/wQEAwIGQDAfBgNVHSMEGDAWgBTg +A751LXyf0kjtsN5x6M1H4Z6iDA7BgNVHR8ENDAyMDCgLqAshipodHRwOi8vY3JsLnF1b3ZhZGlz Z2xvYmFsLmNvbS9xdmV1Y2FnMi5jcmwwHQYDVR0OBBYEFDc3hgIFJTDamDEeQczI7Lot4uaVMA0G CSqGSIb3DQEBBQUAA4ICAQAZ8EZ48RgPimWY6s4LjZf0M2MfVJmNh06Jzmf6fzwYtDtQLKzIDk8Z tosqYpNNBoZIFICMZguGRAP3kuxWvwANmrb5HqyCzXThZVPJTmKEzZNhsDtKu1almYBszqX1UV7I gZp+jBZ7FyXzXrXyF1tzXQxHGobDV3AEE8vdzEZtwDGpZJPnEPCBzifdY+lrrL2rDBjbv0Veildg OP1SIlL7dh1O9f0T6T4ioS6uSdMt6b/OWjqHadsSpKry0A6pqfOqJWAhDiueqgVB7vus6o6sSmfG 4SW9EWW+BEZ510HjlQU/JL3PPmf+Xs8s00sm77LJ/T/1hMUuGp6TtDsJe+pPBpCYvpm6xu9GL20C sArFWUeQ2MSnE1jsrb00UniCKslcM63pU7I0VcnWMJQSNY28OmnFESPK6s6zqoN0ZMLhwCVnahi6 pouBwTb10M9/Anla9xOT42qxiLr14S2lHy18aLiBSQ4zJKNLqKvIrkjewSfW+00VLBYbPTmtrHpZ UWiCGiRS2SviuEmPVbdWvsBUaq7OMLIfBD4nin1FlmYnaG9TVmWkwVYDsFmQepwPDqjPs4efAxzk gUFHWn0gQFbqxRocKrCsOvCDHOHORA97UWcThmgvr0Jl7ipvP4Px//tRp08blfy4GMzYls5WF8f6 JaMrNGmpfPasd9NbpBNp7A== -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer CN: QuoVadis EU Issuing Certification Authority G2 Issuer OU: Issuing Certification Authority Issuer O: QuoVadis Trustlink B.V. Issuer C: NL Subject CN: EC_DIGIT Subject OU: Informatics Subject O: European Commission Subject L: Etterbeek Subject ST: Brussel Subject C: BE Valid from: Wed Oct 30 13:27:11 CET 2013 Valid to: Sun Oct 30 13:27:11 CET 2016 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:98:24:92:AB:C9:99:96:A4:9D:00:BB:73:A1:FA:2C:4A:F7:74:6B:50:E4:87:CE:07:71:C0:65:9C:4E:65:B6:FC:B5:D3:3 5:28:C4:CE:DE:C0:22:7C:90:B9:1C:D1:5E:21:67:74:EF:6E:EE:66:3F:95:E6:40:6B:52:FD:FA:CC:4B:3E:57:18:8D:D7:22:41:99:C2:73:9D:7E:09:D9:30:B2:3D:F2:E4:D8:D4:44:2C:6B:BA:E5:5C:2B:2B:65:A1:A7:C7:0B:2C: 03:5C:FB:AA:50:9F:FE:70:2A:1D:B7:7A:16:66:DB:59:8B:5D:C8:9C:67:CC:21:92:C5:06:6F:F8:7C:A7:A3:43:7B:57:04:94:3E:AF:78:D7:3D:0B:0C:0A:D9:04:F4:1B:49:90:88:46:1C:86:A8:C9:92:AC:98:F0:71:1A:93:CB:7E: 09:B2:02:E1:1A:E1:CB:18:77:1C:8D:5F:08:AD:16:29:2F:49:8D:B3:D0:15:BB:C6:99:FA:41:66:E2:CF:61:96:33:3F:85:17:22:A7:C1:55:87:2D:CA:87:5C:48:09:D2:7E:6C:BA:B7:24:8C:AA:95:52:46:18:D1:9F:82:8F:D0:47:C 7:96:AE:C4:73:E1:F7:9F:0B:AA:C5:DD:0C:E2:F4:C9:95:99:BE:5F:06:09:07:31:05:CC:5B:02:03:01:00:01 Policy OID: 0.4.0.1456.1.2 Policy OID: 1.3.6.1.4.1.8024.1.400 CPS pointer: http://www.quovadisglobal.nl/documenten QCStatements - crit. = false id_etsi_qcs_QcCompliance Authority Info Access http://ocsp.quovadisglobal.com http://trust.quovadisglobal.com/qveucag2.crt Authority Key Identifier E0:F8:0E:F9:D4:B5:F2:7F:49:23:B6:C3:79:C7:A3:35:1F:86:7A:88 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 4 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://crl.quovadisglobal.com/qveucag2.crl Subject Key Identifier 37:37:86:02:05:25:30:DA:98:31:1E:41:CC:C8:EC:BA:2D:E2:E6:95 Key Usage: nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: F1:BC:DD:11:7B:15:54:17:38:13:A4:21:83:C5:4D:B9:7E:3A:7E:10:9D:0A:FA:98:F4:BC:D3:26:75 :4A:03:51 EU TSL digital identities TSL Scheme Operator certificate fields details Version: 3 Serial Number: 21267647932559079066510326516695893879 X509 Certificate -----BEGIN CERTIFICATE----MIID/DCCAuSgAwIBAgIQEAAAAAAAWgS4SGkJJUcHdzANBgkqhkiG9w0BAQUFADAzMQswCQYDVQQG EwJCRTETMBEGA1UEAxMKQ2l0aXplbiBDQTEPMA0GA1UEBRMGMjAxMzA2MB4XDTEzMDcxNzE3NDQw OFoXDTE4MDcxMzIzNTk1OVowbjELMAkGA1UEBhMCQkUxITAfBgNVBAMTGFBpZXJyZSBEYW1hcyAo U2lnbmF0dXJlKTEOMAwGA1UEBBMFRGFtYXMxFjAUBgNVBCoMDVBpZXJyZSBBbmRyw6kxFDASBgNV BAUTCzYwMDIxMjExOTE5MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCMv+7DvhzLwG3prirU DGaYRS2+jBZtN2cYXuloKSqAc5Q58FEmk0gsZRF+/4dkt8hgCvbBcpmG6FcvTfNxQbxPX88yYwpB YsWnJ3aD5P4QrN2+fZxwxfXxRRcX+t30IBpr+WYFv/GhJhoFo0LWUehC4eyvnMfP4J/MR4TGlQRr cwIDAQABo4IBUzCCAU8wHwYDVR0jBBgwFoAUww/Dck0/3rI43jkuR2RQ//KP88cwbgYIKwYBBQUH AQEEYjBgMDYGCCsGAQUFBzAChipodHRwOi8vY2VydHMuZWlkLmJlbGdpdW0uYmUvYmVsZ2l1bXJz Mi5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3NwLmVpZC5iZWxnaXVtLmJlMEQGA1UdIAQ9MDsw OQYHYDgJAQECATAuMCwGCCsGAQUFBwIBFiBodHRwOi8vcmVwb3NpdG9yeS5laWQuYmVsZ2l1bS5i ZTA5BgNVHR8EMjAwMC6gLKAqhihodHRwOi8vY3JsLmVpZC5iZWxnaXVtLmJlL2VpZGMyMDEzMDYu Y3JsMA4GA1UdDwEB/wQEAwIGQDARBglghkgBhvhCAQEEBAMCBSAwGAYIKwYBBQUHAQMEDDAKMAgG BgQAjkYBATANBgkqhkiG9w0BAQUFAAOCAQEAEE3KGmLX5XXqArQwIZQmQEE6orKSu3a1z8ey1txs ZC4rMk1vpvC6MtsfDaU4N6ooprhcM/WAlcIGOPCNhvxV+xcY7gUBwa6myiClnK0CMSiGYHqWcJG8 ns13B9f0+5PJqsoziPoksXb2A9VXkr5aEdEmBYLjh7wG7GwAuDgDT0v87qtphN02/MAlJcNqT3JU UAotD7yfEybmK245jKo+pTYeCHGh7r1HzVWhbUDcQ/e1PpQXjVqBmr4k1ACtuu4H19t6K1P5kf7t a5JFEJPFgy3Hxt6YqzoY07WTVEpS4gJqtleIdX1Fhse7jq83ltcCzlfysBRqY/okUzipo1rbQw== -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer SERIAL NUMBER: 201306 Issuer CN: Citizen CA Issuer C: BE Subject SERIAL NUMBER: 60021211919 Subject GIVEN NAME: Pierre André Subject SURNAME: Damas Subject CN: Pierre Damas (Signature) Subject C: BE Valid from: Wed Jul 17 19:44:08 CEST 2013 Valid to: Sat Jul 14 01:59:59 CEST 2018 Public Key: 30:81:9F:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:81:8D:00:30:81:89:02:81:81:00:8C:BF:EE:C3:BE:1C:CB:C0:6D:E9:AE:2A:D4:0C:66:98:45:2D:BE:8C:16:6D:37:67:18:5E:E9:68:29:2A:80:73:94:39:F0:51:26:93: 48:2C:65:11:7E:FF:87:64:B7:C8:60:0A:F6:C1:72:99:86:E8:57:2F:4D:F3:71:41:BC:4F:5F:CF:32:63:0A:41:62:C5:A7:27:76:83:E4:FE:10:AC:DD:BE:7D:9C:70:C5:F5:F1:45:17:17:FA:DD:F4:20:1A:6B:F9:66:05:BF:F1:A1:26: 1A:05:A3:42:D6:51:E8:42:E1:EC:AF:9C:C7:CF:E0:9F:CC:47:84:C6:95:04:6B:73:02:03:01:00:01 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 5 ETSI 2014 - TSL HR - PDF/A-1b generator Authority Key Identifier C3:0F:C3:72:4D:3F:DE:B2:38:DE:39:2E:47:64:50:FF:F2:8F:F3:C7 Authority Info Access http://certs.eid.belgium.be/belgiumrs2.crt http://ocsp.eid.belgium.be Certificate Policies Policy OID: 2.16.56.9.1.1.2.1 CPS pointer: http://repository.eid.belgium.be CRL Distribution Points http://crl.eid.belgium.be/eidc201306.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: FF:EA:7F:0E:D2:9B:EB:07:73:EA:3B:0C:47:29:BB:F8:00:A6:C3:90:B6:21:95:CB:27:0F:12:A4:A A:62:F2:84 EU TSL digital identities TSL Scheme Operator certificate fields details Version: 3 Serial Number: 21267647932559078025136389726459194295 X509 Certificate -----BEGIN CERTIFICATE----MIID/TCCAuWgAwIBAgIQEAAAAAAAWcxEUPr16SDrtzANBgkqhkiG9w0BAQUFADAzMQswCQYDVQQG EwJCRTETMBEGA1UEAxMKQ2l0aXplbiBDQTEPMA0GA1UEBRMGMjAxMzExMB4XDTEzMDcyNDAxNDUz MVoXDTE4MDcxODIzNTk1OVowbzELMAkGA1UEBhMCQkUxIjAgBgNVBAMTGU1hYXJ0ZW4gT3R0b3kg KFNpZ25hdHVyZSkxDjAMBgNVBAQTBU90dG95MRYwFAYDVQQqEw1NYWFydGVuIEpvcmlzMRQwEgYD VQQFEws4MzEyMTQyNDEwMjCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAjbr1T8USYkuh4X+Y i+coykq7mbF8PjgyjWQ28uODqRCkynuqJz468tCIYxsM/+/QdqEFq4Z5Z1YDbBYb5KsxfBmkzr9D +Gt49iWVt9Ig+FhngbOexwCW108t6Q/+NAo6gwl6IKkzv2wpEJIwtc51VFzvM+WkE1mNmclphYRT L5UCAwEAAaOCAVMwggFPMB8GA1UdIwQYMBaAFLws1Y0dT3YXfAzva5To9R51FmNhMG4GCCsGAQUF BwEBBGIwYDA2BggrBgEFBQcwAoYqaHR0cDovL2NlcnRzLmVpZC5iZWxnaXVtLmJlL2JlbGdpdW1y czIuY3J0MCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5laWQuYmVsZ2l1bS5iZTBEBgNVHSAEPTA7 MDkGB2A4CQEBAgEwLjAsBggrBgEFBQcCARYgaHR0cDovL3JlcG9zaXRvcnkuZWlkLmJlbGdpdW0u YmUwOQYDVR0fBDIwMDAuoCygKoYoaHR0cDovL2NybC5laWQuYmVsZ2l1bS5iZS9laWRjMjAxMzEx LmNybDAOBgNVHQ8BAf8EBAMCBkAwEQYJYIZIAYb4QgEBBAQDAgUgMBgGCCsGAQUFBwEDBAwwCjAI BgYEAI5GAQEwDQYJKoZIhvcNAQEFBQADggEBAHNRipzOD4aXB7Oo4FgfBbWgPkmUGTqkz2jK9U2t EWUbyQrhirgqhxK6YMAHBvzL+7BHouMEAuxycZG3ozAfEDRZiznFWyqS8QlnHUe0ThaAvs8v5wYO UO7lJ6vnaNLLvQj7W3L5kCnEva5h0Jh9wMytlNp89dd02l7MD4BsidXoMN21AE8su39tBmNayLF6 YrFLe3Zob4fQCuIEbx/pj3kYIVC4WM7uuDx+QpEJdNBtB41o2q2JJFqusRP7W0phkxX7sPtYkot6 RXLdgaZNoB4YIRwGozIvcegydRVqpcYrvFSoppNHQqd8ZNzswjGzqBhlWYPsxdjjsxJiUyk7T1c= -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer SERIAL NUMBER: 201311 Issuer CN: Citizen CA Issuer C: BE Subject SERIAL NUMBER: 83121424102 Subject GIVEN NAME: Maarten Joris Subject SURNAME: Ottoy Subject CN: Maarten Ottoy (Signature) CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 6 ETSI 2014 - TSL HR - PDF/A-1b generator Subject C: BE Valid from: Wed Jul 24 03:45:31 CEST 2013 Valid to: Thu Jul 19 01:59:59 CEST 2018 Public Key: 30:81:9F:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:81:8D:00:30:81:89:02:81:81:00:8D:BA:F5:4F:C5:12:62:4B:A1:E1:7F:98:8B:E7:28:CA:4A:BB:99:B1:7C:3E:38:32:8D:64:36:F2:E3:83:A9:10:A4:CA:7B:AA:27:3 E:3A:F2:D0:88:63:1B:0C:FF:EF:D0:76:A1:05:AB:86:79:67:56:03:6C:16:1B:E4:AB:31:7C:19:A4:CE:BF:43:F8:6B:78:F6:25:95:B7:D2:20:F8:58:67:81:B3:9E:C7:00:96:D7:4F:2D:E9:0F:FE:34:0A:3A:83:09:7A:20:A9:33:BF: 6C:29:10:92:30:B5:CE:75:54:5C:EF:33:E5:A4:13:59:8D:99:C9:69:85:84:53:2F:95:02:03:01:00:01 Authority Key Identifier BC:2C:D5:8D:1D:4F:76:17:7C:0C:EF:6B:94:E8:F5:1E:75:16:63:61 Authority Info Access http://certs.eid.belgium.be/belgiumrs2.crt http://ocsp.eid.belgium.be Certificate Policies Policy OID: 2.16.56.9.1.1.2.1 CPS pointer: http://repository.eid.belgium.be CRL Distribution Points http://crl.eid.belgium.be/eidc201311.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: F7:BC:0D:16:4D:EC:8F:36:70:9A:BE:85:FC:57:02:2F:3B:16:84:70:0A:80:4C:36:8D:34:32:90:04:9 0:DF:CB EU TSL digital identities TSL Scheme Operator certificate fields details Version: 3 Serial Number: 505234932823532549198528995630307842349301805796 X509 Certificate -----BEGIN CERTIFICATE----MIIGgDCCBGigAwIBAgIUWH+El24rfQt9YeTtrAZC9UzssuQwDQYJKoZIhvcNAQEFBQAwgZIxCzAJ BgNVBAYTAk5MMSAwHgYDVQQKExdRdW9WYWRpcyBUcnVzdGxpbmsgQi5WLjEoMCYGA1UECxMfSXNz dWluZyBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTE3MDUGA1UEAxMuUXVvVmFkaXMgRVUgSXNzdWlu ZyBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSBHMjAeFw0xNTEyMDQxMjA5MzVaFw0xODEyMDQxMjA5 MjRaMHkxCzAJBgNVBAYTAkJFMRAwDgYDVQQIEwdCcnVzc2VsMRIwEAYDVQQHEwlFdHRlcmJlZWsx HDAaBgNVBAoTE0V1cm9wZWFuIENvbW1pc3Npb24xEzARBgNVBAsTCkRHIENPTk5FQ1QxETAPBgNV BAMMCEVDX0NORUNUMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtXQoPmP4DPSZDKuH cecqX6durKKczAuiEimbZAuuOgMQ9P7g2EIWrACuwNLXKxFXikxOSJWg+nYytJ/ty+1njYa8Nmhp 4MYc4UoF3WzQCiz63atK9AuNOMrODBaAGrQNYqXyuEet+i5NaibRYPEtptXzoY0Pif6Zv3qauBlC Jnf7kbGkHq9sh8sEXnMaWGjm0EHna8NTh1LjnzCb6N2capQDt+RRrUiBee3YMST3Fo3kKQTKaBvv cYAJ4Mgs/9+Dvwm52dIaMc1vaP1MN2dUW45EWDKtaRfV9flkAy0iT8P8qvUkyGn1XBXnM/gyohOq 9cSaP09vPMX6ArmFPlQSiwIDAQABo4IB5DCCAeAwWAYDVR0gBFEwTzAIBgYEAIswAQIwQwYKKwYB BAG+WAGDEDA1MDMGCCsGAQUFBwIBFidodHRwOi8vd3d3LnF1b3ZhZGlzZ2xvYmFsLm5sL2RvY3Vt ZW50ZW4wJAYIKwYBBQUHAQMEGDAWMAoGCCsGAQUFBwsCMAgGBgQAjkYBATB0BggrBgEFBQcBAQRo MGYwKgYIKwYBBQUHMAGGHmh0dHA6Ly9vY3NwLnF1b3ZhZGlzZ2xvYmFsLmNvbTA4BggrBgEFBQcw AoYsaHR0cDovL3RydXN0LnF1b3ZhZGlzZ2xvYmFsLmNvbS9xdmV1Y2FnMi5jcnQwRgYKKoZIhvcv AQEJAQQ4MDYCAQGGMWh0dHA6Ly90c2EwMS5xdW92YWRpc2dsb2JhbC5jb20vVFNTL0h0dHBUc3BT ZXJ2ZXIwEwYKKoZIhvcvAQEJAgQFMAMCAQEwDgYDVR0PAQH/BAQDAgZAMB8GA1UdIwQYMBaAFOD4 DvnUtfJ/SSO2w3nHozUfhnqIMDsGA1UdHwQ0MDIwMKAuoCyGKmh0dHA6Ly9jcmwucXVvdmFkaXNn bG9iYWwuY29tL3F2ZXVjYWcyLmNybDAdBgNVHQ4EFgQUQX94XsDFzQFNiSGpboQqB53MiyAwDQYJ KoZIhvcNAQEFBQADggIBAJfRbSpp2RTfVtyu4G1TDVXE6RgoIQ5XrUASAmhDWktT5PJReSg5INMF xi3jSPAO7p29bEU32wllZGPVN+A9b2SZmhHyYx9ZoBTMekKlx0qHkU4FfcicIznXo9EVplMtgjpl qRltiLqxwXU5uIxKJ2R6BJwjokUWcpei1ifs14SgAve8firXwiG1kFcoClfLjyj4SuDFxT+0e/dh fGfQMfvVBp4xa5tOGYDS7kzf7xvftYlPHW1AbEzjuPmViGgen8ZD/WkuqzdygizOocFQNshGH/mF nQxT4ILAubWJX5gcvmjaZ9N/Lxh041Ra2s8YK5l1DHBcZzz6y2j9OhxPgCvzz3/71DsiGVaK/TO5 HxJNcjKlkBblXE4dgy3wqjpUzqkVltC+Xli23Ljny4tenz0QNOx3SQBA1R/hZE5QKD0L0wOc4Np1 VxGZbCWGFqta8KKhEA19KlW03Yix9aqe86iNKoJm3n/4BBgdYGu5c+DnqKWj3D7NnxCVZwuLOKzW SCEisl2kHdgnZ3Qix5Vc5QYWexSHeQfCuJAARCDvhdnOidUyiZRnQ6R4VHt0GgNQcYKrmz+UdEro SeQCuSvXIh+LIEJpayWSo9vxi3OgO2IRSi+7Kh5h7LAfWcIwpVY8u0BpRoNJg5xMjvF49GDJc1Qe KdlqCBm05N4c2d5t5/aa -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer CN: QuoVadis EU Issuing Certification Authority G2 Issuer OU: Issuing Certification Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 7 ETSI 2014 - TSL HR - PDF/A-1b generator Issuer O: QuoVadis Trustlink B.V. Issuer C: NL Subject CN: EC_CNECT Subject OU: DG CONNECT Subject O: European Commission Subject L: Etterbeek Subject ST: Brussel Subject C: BE Valid from: Fri Dec 04 13:09:35 CET 2015 Valid to: Tue Dec 04 13:09:24 CET 2018 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B5:74:28:3E:63:F8:0C:F4:99:0C:AB:87:71:E7:2A:5F:A7:6E:AC:A2:9C:CC:0B:A2:12:29:9B:64:0B:AE:3A:03:10:F4: FE:E0:D8:42:16:AC:00:AE:C0:D2:D7:2B:11:57:8A:4C:4E:48:95:A0:FA:76:32:B4:9F:ED:CB:ED:67:8D:86:BC:36:68:69:E0:C6:1C:E1:4A:05:DD:6C:D0:0A:2C:FA:DD:AB:4A:F4:0B:8D:38:CA:CE:0C:16:80:1A:B4:0D:62: A5:F2:B8:47:AD:FA:2E:4D:6A:26:D1:60:F1:2D:A6:D5:F3:A1:8D:0F:89:FE:99:BF:7A:9A:B8:19:42:26:77:FB:91:B1:A4:1E:AF:6C:87:CB:04:5E:73:1A:58:68:E6:D0:41:E7:6B:C3:53:87:52:E3:9F:30:9B:E8:DD:9C:6A:94:03: B7:E4:51:AD:48:81:79:ED:D8:31:24:F7:16:8D:E4:29:04:CA:68:1B:EF:71:80:09:E0:C8:2C:FF:DF:83:BF:09:B9:D9:D2:1A:31:CD:6F:68:FD:4C:37:67:54:5B:8E:44:58:32:AD:69:17:D5:F5:F9:64:03:2D:22:4F:C3:FC:AA:F5:2 4:C8:69:F5:5C:15:E7:33:F8:32:A2:13:AA:F5:C4:9A:3F:4F:6F:3C:C5:FA:02:B9:85:3E:54:12:8B:02:03:01:00:01 Policy OID: 0.4.0.1456.1.2 Policy OID: 1.3.6.1.4.1.8024.1.400 CPS pointer: http://www.quovadisglobal.nl/documenten QCStatements - crit. = false id_etsi_qcs_QcCompliance Authority Info Access http://ocsp.quovadisglobal.com http://trust.quovadisglobal.com/qveucag2.crt Authority Key Identifier E0:F8:0E:F9:D4:B5:F2:7F:49:23:B6:C3:79:C7:A3:35:1F:86:7A:88 CRL Distribution Points http://crl.quovadisglobal.com/qveucag2.crl Subject Key Identifier 41:7F:78:5E:C0:C5:CD:01:4D:89:21:A9:6E:84:2A:07:9D:CC:8B:20 Key Usage: nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 59:C8:0D:CC:74:29:CC:FD:8C:2B:15:90:FE:88:5F:B4:F6:C7:7F:7C:9C:BB:4B:82:A6:2C:B1:C2:7 F:F4:E2:46 TSL Type http://uri.etsi.org/TrstSvc/TrustedList/TSLType/EUlistofthelists Scheme Territory EU Mime Type application/vnd.etsi.tsl+xml CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 8 ETSI 2014 - TSL HR - PDF/A-1b generator Scheme Operator Name Name [ en ] European Commission [ en ] http://uri.etsi.org/TrstSvc/TrustedList/schemerules/EUlistofthelists Scheme Type Community Rules URI List Issue Date Time 2016-07-25T08:20:00Z Next Update date Time 2017-01-10T10:00:00Z Distribution Points URI http://tsl.gov.cz/publ/TSL_CZ.xtsl URI https://tsl.gov.cz/publ/TSL_CZ.xtsl CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 9 ETSI 2014 - TSL HR - PDF/A-1b generator 158 - TSP: First certification authority, a.s. TSP Name Name [ en ] First certification authority, a.s. Name [ cs ] První certifikační autorita, a.s. Name [ en ] I.CA Name [ en ] VATCZ-26439395 Name [ cs ] První certifikační autorita a.s. Street Address [ en ] Podvinny mlyn 2178/6 Locality [ en ] Prague 9 Postal Code [ en ] 19000 Country Name [ en ] CZ Street Address [ cs ] Podvinný mlýn 2178/6 Locality [ cs ] Praha 9 Postal Code [ cs ] 19000 Country Name [ cs ] CZ TSP Trade Name PostalAddress PostalAddress ElectronicAddress URI mailto:[email protected] URI http://ica.cz/English URI http://ica.cz/ TSP Information URI URI [ en ] http://www.ica.cz/Certification-policy URI [ cs ] http://www.ica.cz/Certifikacni-politika.aspx CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 10 ETSI 2014 - TSL HR - PDF/A-1b generator URI [ sk ] http://www.ica.cz/Certifikacna-politika 158.1 - Service (granted): (1) I.CA - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (1) I.CA - issuing qualified certificates Name [ cs ] (1) I.CA - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10000001 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 11 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGWjCCBUKgAwIBAgIEAJiWgTANBgkqhkiG9w0BAQUFADCCAQ0xYTBfBgNVBAMMWEkuQ0EgLSBR dWFsaWZpZWQgcm9vdCBjZXJ0aWZpY2F0ZSAoa3ZhbGlmaWtvdmFuw70gY2VydGlmaWvDoXQgcG9z a3l0b3ZhdGVsZSkgLSBQU0VVRE9OWU0xCzAJBgNVBAYTAkNaMS8wLQYDVQQHDCZQb2R2aW5uw70g bWzDvW4gMjE3OC82LCAxOTAgMDAgUHJhaGEgOTEsMCoGA1UECgwjUHJ2bsOtIGNlcnRpZmlrYcSN bsOtIGF1dG9yaXRhIGEucy4xPDA6BgNVBAsMM0FrcmVkaXRvdmFuw70gcG9za3l0b3ZhdGVsIGNl cnRpZmlrYcSNbsOtY2ggc2x1xb5lYjAeFw0wMjAzMjIwMDAwMDBaFw0wODAzMjIwMDAwMDBaMIIB DTFhMF8GA1UEAwxYSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlIChrdmFsaWZpa292 YW7DvSBjZXJ0aWZpa8OhdCBwb3NreXRvdmF0ZWxlKSAtIFBTRVVET05ZTTELMAkGA1UEBhMCQ1ox LzAtBgNVBAcMJlBvZHZpbm7DvSBtbMO9biAyMTc4LzYsIDE5MCAwMCBQcmFoYSA5MSwwKgYDVQQK DCNQcnZuw60gY2VydGlmaWthxI1uw60gYXV0b3JpdGEgYS5zLjE8MDoGA1UECwwzQWtyZWRpdG92 YW7DvSBwb3NreXRvdmF0ZWwgY2VydGlmaWthxI1uw61jaCBzbHXFvmViMIIBIjANBgkqhkiG9w0B AQEFAAOCAQ8AMIIBCgKCAQEAxY4zPwz335OskTfhoAjgk8PLTZ+h2D9FN3wdSCVfxtgbzkBD7L3V ajOZHoyM0bfsGrQJRHM0Cwb/x0zBBSkEOMqkja7sbXqvXW4cqk6ZCCQli1AELtek+lil8yBIYvav A6DOX0SNHe5fLB5DF+57jhoLE4jFyLrV6cCtI3EspPrSRajcUpfUnIAwgv7xlnNsiqtrxsih1iW3 TtKt6TV/6Al6L6v5xvrsx9k8q0BSZLC21sVN0yP0e2Kf3yGoH+YaOnObup61zD2e0TXJgUVgQLLC 21yTWgqEuDREC3dq6VpIyFZLswBjYdoFlMcJiL5C8zXLHKkTvZQmaDZPN7eIxQIDAQABo4IBvDCC AbgwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwKQYDVR0RBCIwIIELb3BlckBpY2Eu Y3qGEWh0dHA6Ly93d3cuaWNhLmN6MGkGA1UdHwRiMGAwHqAcoBqGGGh0dHA6Ly9xLmljYS5jei9x aWNhLmNybDAeoBygGoYYaHR0cDovL2IuaWNhLmN6L3FpY2EuY3JsMB6gHKAahhhodHRwOi8vci5p Y2EuY3ovcWljYS5jcmwwgcUGA1UdIASBvTCBujCBtwYKKwYBBAGzYQEBBDCBqDAvBggrBgEFBQcC ARYjaHR0cDovL3d3dy5pY2EuY3ovcWNwL2NwcXJpY2EwMS5wZGYwdQYIKwYBBQUHAgIwaRpnVGVu dG8gY2VydGlmaWthdCBqZSB2eWRhbiBqYWtvIEt2YWxpZmlrb3ZhbnkgY2VydGlmaWthdCBwb3Nr eXRvdmF0ZWxlIHYgc291bGFkdSBzZSB6YWtvbmVtIDIyNy8yMDAwIFNiLjAdBgNVHQ4EFgQUK1oK fvvlDYUsZTByvGN701mca/UwGAYIKwYBBQUHAQMEDDAKMAgGBgQAjkYBATANBgkqhkiG9w0BAQUF AAOCAQEAUHd7gP8KdZZOtsQ6WCaenOmkTP7yVbwaXNAzsuUn0aI7w9rZn/rodHkjc58M+R5uLqAJ iLkzN2mIftEQqW9Yn2hpVFkWw0Y1G8yyQXzbJUWesUMRlrYyPVDBs0aOBsJmUICRfggXvmJbro2T 5Rfpn69INijg6iSmOtFoQuw3lPbbxnUJoEe+VoHSNpwvbMPk8PGuGC2Vx3vZFSUOkLxjMbiXLJRI 5dASq77NS8Hntu42rQA32rhYF41BbjiR5N23i8toiWDM4z7Utbqh4RT7m/s25rdNXKBcl/vARfAf lbHoY4KIbFFJoW8wfFB8gJFd5lD88YVCBnIa0+33AXuN2w== -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: První certifikační autorita a.s. Issuer L: Podvinný mlýn 2178/6, 190 00 Praha 9 Issuer C: CZ Issuer CN: I.CA - Qualified root certificate (kvalifikovaný certifikát poskytovatele) - PSEUDONYM Subject OU: Akreditovaný poskytovatel certifikačních služeb Subject O: První certifikační autorita a.s. Subject L: Podvinný mlýn 2178/6, 190 00 Praha 9 Subject C: CZ Subject CN: I.CA - Qualified root certificate (kvalifikovaný certifikát poskytovatele) - PSEUDONYM Valid from: Fri Mar 22 01:00:00 CET 2002 Valid to: Sat Mar 22 01:00:00 CET 2008 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C5:8E:33:3F:0C:F7:DF:93:AC:91:37:E1:A0:08:E0:93:C3:CB:4D:9F:A1:D8:3F:45:37:7C:1D:48:25:5F:C6:D8:1B:CE: 40:43:EC:BD:D5:6A:33:99:1E:8C:8C:D1:B7:EC:1A:B4:09:44:73:34:0B:06:FF:C7:4C:C1:05:29:04:38:CA:A4:8D:AE:EC:6D:7A:AF:5D:6E:1C:AA:4E:99:08:24:25:8B:50:04:2E:D7:A4:FA:58:A5:F3:20:48:62:F6:AF:03:A0:C E:5F:44:8D:1D:EE:5F:2C:1E:43:17:EE:7B:8E:1A:0B:13:88:C5:C8:BA:D5:E9:C0:AD:23:71:2C:A4:FA:D2:45:A8:DC:52:97:D4:9C:80:30:82:FE:F1:96:73:6C:8A:AB:6B:C6:C8:A1:D6:25:B7:4E:D2:AD:E9:35:7F:E8:09:7A:2 F:AB:F9:C6:FA:EC:C7:D9:3C:AB:40:52:64:B0:B6:D6:C5:4D:D3:23:F4:7B:62:9F:DF:21:A8:1F:E6:1A:3A:73:9B:BA:9E:B5:CC:3D:9E:D1:35:C9:81:45:60:40:B2:C2:DB:5C:93:5A:0A:84:B8:34:44:0B:77:6A:E9:5A:48:C8:5 6:4B:B3:00:63:61:DA:05:94:C7:09:88:BE:42:F3:35:CB:1C:A9:13:BD:94:26:68:36:4F:37:B7:88:C5:02:03:01:00:01 Basic Constraints IsCA: true Subject Alternative Name [email protected] http://www.ica.cz CRL Distribution Points http://q.ica.cz/qica.crl http://b.ica.cz/qica.crl http://r.ica.cz/qica.crl CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 12 ETSI 2014 - TSL HR - PDF/A-1b generator Certificate Policies Policy OID: 1.3.6.1.4.1.6625.1.1.4 CPS pointer: http://www.ica.cz/qcp/cpqrica01.pdf CPS text: [Tento certifikat je vydan jako Kvalifikovany certifikat poskytovatele v souladu se zakonem 227/2000 Sb.] Subject Key Identifier 2B:5A:0A:7E:FB:E5:0D:85:2C:65:30:72:BC:63:7B:D3:59:9C:6B:F5 QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: 5D:FF:58:6C:9B:78:49:B9:0A:DB:3A:99:79:44:7D:00:2C:E3:CF:B7:10:EF:8A:A0:E8:26:EC:0C:0 A:89:B0:30 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.1.1 - Extension (critical): Qualifiers [QCNoQSCD] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 13 ETSI 2014 - TSL HR - PDF/A-1b generator Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.6625.1.1.4.6 Policy Identifier nodes: Identifier 1.3.6.1.4.1.6625.1.1.4.4 158.1.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 158.1.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (1) I.CA - issuing qualified certificates Name [ cs ] (1) I.CA - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject OU: Akreditovaný poskytovatel certifikačních služeb Subject O: První certifikační autorita a.s. Subject L: Podvinný mlýn 2178/6, 190 00 Praha 9 Subject C: CZ Subject CN: I.CA - Qualified root certificate (kvalifikovaný certifikát poskytovatele) - PSEUDONYM X509SKI X509 SK I Service Status K1oKfvvlDYUsZTByvGN701mca/U= http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 14 ETSI 2014 - TSL HR - PDF/A-1b generator Status Starting Time 2002-03-22T00:00:00Z 158.1.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 15 ETSI 2014 - TSL HR - PDF/A-1b generator [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.6625.1.1.4.6 Policy Identifier nodes: Identifier 1.3.6.1.4.1.6625.1.1.4.4 158.2 - Service (granted): (2) I.CA - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [ en ] (2) I.CA - issuing qualified certificates Service Name Name CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 16 ETSI 2014 - TSL HR - PDF/A-1b generator Name [ cs ] (2) I.CA - vydávání kvalifikovaných certifikátů Service digital identities Certificate fields details Version: 3 Serial Number: 10100000 X509 Certificate -----BEGIN CERTIFICATE----MIIEODCCAyCgAwIBAgIEAJodIDANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4wHhcNMDUwNjAxMDAwMDAwWhcNMTEwNjAxMDAwMDAw WjBoMQswCQYDVQQGEwJDWjEqMCgGA1UEAwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmlj YXRlMS0wKwYDVQQKDCRQcnZuw60gY2VydGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4wggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDwM/o7kB8GPi+JDF5A12G4+UryCybpTeHU1Pa6cSQN 6zDjSReYEfqLuTGsNEDVs76Eu0qOQ3pJ9lLQjWnaTL4SaG575z17Zt+gOhwt0UjJQhv6AQb2totz BJOGFL7tE/nE0yav1/yB7l2FwFNcWw/8alnDj6T07boHCZ2T82cash/Z0up4VbgeFprLwHpYpeVO GmYcJYxgLOhfeV4OBbSpoKjLOly4L2ChEsDbmB88gxew4dorgyKuL0k1ClCLtKgp/rNHxTskLKcx J2KpyFOdQL4QtLC32l9RdvDwdzGRcm3A78H7eoiuBDsSxkI9uFAaGbmqhc9LoLzwjAhKeSKFAgMB AAGjgekwgeYwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwgaMGA1UdIASBmzCBmDCB lQYLKwYBBAGzYQEBBAUwgYUwgYIGCCsGAQUFBwICMHYadFRlbnRvIGNlcnRpZmlrYXQgamUgdnlk YW4gamFrbyBzeXN0ZW1vdnkga3ZhbGlmaWtvdmFueSBjZXJ0aWZpa2F0IHYgc291bGFkdSBzZSB6 YWtvbmVtIDIyNy8yMDAwIFNiLiB2IHBsYXRuZW0gem5lbmkuMB0GA1UdDgQWBBRRLl9ZgSX/0f6G 6Icu1o0NWTQrvTANBgkqhkiG9w0BAQUFAAOCAQEAOEbPkZXGrEFoe1iRTp5shex+cA+2zguFTD2I quQr1pfq1AoiJ4sqBOIJBfctLnGu8I1e6YCYS2X9j2rmCNyB0J37osTc63zzXJyXVJPEsGX1WYyh tvWZpq2i9G1UMva6iU44s69ZYz7rEX7+2v2ptZPJ8OfEQOukkie0Bky5Y/Itxoq23wWcLZSsH0A0 PE37y1SU3cdk3DWgTcSOWZIqnsaRRAN7H7+V0Zm1ppv86uZa6w9VTWh7blmhw9NIZuO7qBPDRKpd hN+gUUzXxWmjvm2uwwYKSyvTis3hif25w++P+r9j557ZnWW5zcvOjAYlKYXdziSu96cnB4yyhPhG sQ== -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified root certificate Issuer C: CZ Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Qualified root certificate Subject C: CZ Valid from: Wed Jun 01 02:00:00 CEST 2005 Valid to: Wed Jun 01 02:00:00 CEST 2011 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:F0:33:FA:3B:90:1F:06:3E:2F:89:0C:5E:40:D7:61:B8:F9:4A:F2:0B:26:E9:4D:E1:D4:D4:F6:BA:71:24:0D:EB:30:E3:4 9:17:98:11:FA:8B:B9:31:AC:34:40:D5:B3:BE:84:BB:4A:8E:43:7A:49:F6:52:D0:8D:69:DA:4C:BE:12:68:6E:7B:E7:3D:7B:66:DF:A0:3A:1C:2D:D1:48:C9:42:1B:FA:01:06:F6:B6:8B:73:04:93:86:14:BE:ED:13:F9:C4:D3:26: AF:D7:FC:81:EE:5D:85:C0:53:5C:5B:0F:FC:6A:59:C3:8F:A4:F4:ED:BA:07:09:9D:93:F3:67:1A:B2:1F:D9:D2:EA:78:55:B8:1E:16:9A:CB:C0:7A:58:A5:E5:4E:1A:66:1C:25:8C:60:2C:E8:5F:79:5E:0E:05:B4:A9:A0:A8:CB:3 A:5C:B8:2F:60:A1:12:C0:DB:98:1F:3C:83:17:B0:E1:DA:2B:83:22:AE:2F:49:35:0A:50:8B:B4:A8:29:FE:B3:47:C5:3B:24:2C:A7:31:27:62:A9:C8:53:9D:40:BE:10:B4:B0:B7:DA:5F:51:76:F0:F0:77:31:91:72:6D:C0:EF:C1:F B:7A:88:AE:04:3B:12:C6:42:3D:B8:50:1A:19:B9:AA:85:CF:4B:A0:BC:F0:8C:08:4A:79:22:85:02:03:01:00:01 Basic Constraints IsCA: true Certificate Policies Policy OID: 1.3.6.1.4.1.6625.1.1.4.5 CPS text: [Tento certifikat je vydan jako systemovy kvalifikovany certifikat v souladu se zakonem 227/2000 Sb. v platnem zneni.] Subject Key Identifier 51:2E:5F:59:81:25:FF:D1:FE:86:E8:87:2E:D6:8D:0D:59:34:2B:BD Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 17 ETSI 2014 - TSL HR - PDF/A-1b generator Thumbprint: EE:71:1E:70:3E:77:05:0E:5C:BF:18:6A:81:EB:8D:16:9D:05:BF:04:38:DB:C6:55:E7:0E:FF:17:43: 6E:0E:A2 Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted Service status description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.2.1 - Extension (critical): Qualifiers [QCNoQSCD] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.4 Policy Identifier nodes: Identifier CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ 1.3.6.1.4.1.23624.1.4.10.3 Page 18 ETSI 2014 - TSL HR - PDF/A-1b generator Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.2 Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.1 Policy Identifier nodes: Identifier 1.3.6.1.4.1.6625.1.1.4.6 158.2.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 158.2.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (2) I.CA - issuing qualified certificates Name [ cs ] (2) I.CA - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Qualified root certificate Subject C: CZ X509SKI X509 SK I US5fWYEl/9H+huiHLtaNDVk0K70= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2005-07-01T00:00:00Z CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 19 ETSI 2014 - TSL HR - PDF/A-1b generator 158.2.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 20 ETSI 2014 - TSL HR - PDF/A-1b generator [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.4 Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.3 Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.2 Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.1 Policy Identifier nodes: Identifier 1.3.6.1.4.1.6625.1.1.4.6 158.3 - Service (granted): (11) I.CA - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 21 ETSI 2014 - TSL HR - PDF/A-1b generator [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (11) I.CA - issuing qualified certificates Name [ cs ] (11) I.CA - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10300000 X509 Certificate -----BEGIN CERTIFICATE----MIIEOTCCAyGgAwIBAgIEAJ0qYDANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4wHhcNMDgwNDAxMDAwMDAwWhcNMTgwNDAxMDAwMDAw WjBoMQswCQYDVQQGEwJDWjEqMCgGA1UEAwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmlj YXRlMS0wKwYDVQQKDCRQcnZuw60gY2VydGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4wggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrCIik8HTyn/jb1neNMBk+psXHisW93eYCro49UHW4 r302q/717QhntACKmMEDY4hR8hs2iXRaLcjEgsQ/uYj9bP06HRUFRJWAGqaGyyF1kIVcsHAAhzSo 0R9J/Ww4bWqsuEWfvBTXZtQh4ycKjXXgWi8KS7TnfnOjKr1w8ZGGCI+/kIQch6n1mSUllMHjbgfB SwdbVPw0y0Y3nMWhIM6mrIepgzw4T8BA8+n/m9c5duQTI3W1/6FCrlyGT8VOQ7aZC1JTIKizwkzT ACwV0llsCp8htXMWeR6GJe4a+5OerWPxTOJ2MV437/zQqTbk+RHpevxQ50EjAzS4fboOz91TAgMB AAGjgeowgecwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwgaQGA1UdIASBnDCBmTCB lgYMKwYBBAGBuEgBBAABMIGFMIGCBggrBgEFBQcCAjB2GnRUZW50byBjZXJ0aWZpa2F0IGplIHZ5 ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCB2IHNvdWxhZHUgc2Ug emFrb25lbSAyMjcvMjAwMCBTYi4gdiBwbGF0bmVtIHpuZW5pLjAdBgNVHQ4EFgQUaJ1+1sQlOfs7 oDfWT9yM0XrwVlkwDQYJKoZIhvcNAQEFBQADggEBAHL1vAaN0iyW8oLbWHtH8EBk5S4b7/rg+tPx ckgBRPKI9N6YgVOE531OR+cxN1aus8Ewb8arSIP1mFNSaSoowUBl62XntDAL8KsOpRIlv/RQXb+j fuXRdPgKKK5CnLAUUsSgYF33RRdCukItm5L7bpSzcEcgCJ1T8LCtvamEWt0HKgzNK21hKN87kijs UYF/UXyOLn+d6bzBND2LrYGt8R50ZkM8QU24LjNPsToe2xLfNo5x/1djsdaPtD2GEmrPQjC0kxbq meoCW/4I7rJPcL8zAOd6Sjih8kiRph7LI7I4nfAuSaLJiFZlZY46Z0WMjAviqrFLB/+xH7oUz3L6 p3g= -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified root certificate Issuer C: CZ Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Qualified root certificate Subject C: CZ Valid from: Tue Apr 01 02:00:00 CEST 2008 Valid to: Sun Apr 01 02:00:00 CEST 2018 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:AB:08:88:A4:F0:74:F2:9F:F8:DB:D6:77:8D:30:19:3E:A6:C5:C7:8A:C5:BD:DD:E6:02:AE:8E:3D:50:75:B8:AF:7D:3 6:AB:FE:F5:ED:08:67:B4:00:8A:98:C1:03:63:88:51:F2:1B:36:89:74:5A:2D:C8:C4:82:C4:3F:B9:88:FD:6C:FD:3A:1D:15:05:44:95:80:1A:A6:86:CB:21:75:90:85:5C:B0:70:00:87:34:A8:D1:1F:49:FD:6C:38:6D:6A:AC:B8:45: 9F:BC:14:D7:66:D4:21:E3:27:0A:8D:75:E0:5A:2F:0A:4B:B4:E7:7E:73:A3:2A:BD:70:F1:91:86:08:8F:BF:90:84:1C:87:A9:F5:99:25:25:94:C1:E3:6E:07:C1:4B:07:5B:54:FC:34:CB:46:37:9C:C5:A1:20:CE:A6:AC:87:A9:83:3 C:38:4F:C0:40:F3:E9:FF:9B:D7:39:76:E4:13:23:75:B5:FF:A1:42:AE:5C:86:4F:C5:4E:43:B6:99:0B:52:53:20:A8:B3:C2:4C:D3:00:2C:15:D2:59:6C:0A:9F:21:B5:73:16:79:1E:86:25:EE:1A:FB:93:9E:AD:63:F1:4C:E2:76:31:5 E:37:EF:FC:D0:A9:36:E4:F9:11:E9:7A:FC:50:E7:41:23:03:34:B8:7D:BA:0E:CF:DD:53:02:03:01:00:01 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 22 ETSI 2014 - TSL HR - PDF/A-1b generator Basic Constraints IsCA: true Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.4.0.1 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat v souladu se zakonem 227/2000 Sb. v platnem zneni.] Subject Key Identifier 68:9D:7E:D6:C4:25:39:FB:3B:A0:37:D6:4F:DC:8C:D1:7A:F0:56:59 Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: 1A:A9:80:C8:C0:D3:16:F2:50:29:97:89:82:F0:33:CB:B3:A3:F4:18:8D:66:9F:2D:E6:A8:D8:4E:E0: 0A:15:75 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.3.1 - Extension (critical): Qualifiers [QCNoQSCD] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 23 ETSI 2014 - TSL HR - PDF/A-1b generator Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.5 Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.4 158.3.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 158.3.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (11) I.CA - issuing qualified certificates Name [ cs ] (11) I.CA - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Qualified root certificate Subject C: CZ X509SKI X509 SK I aJ1+1sQlOfs7oDfWT9yM0XrwVlk= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2008-04-01T00:00:00Z 158.3.3.1 - Extension (critical): Qualifiers [QCNoSSCD] CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 24 ETSI 2014 - TSL HR - PDF/A-1b generator Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 25 ETSI 2014 - TSL HR - PDF/A-1b generator [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.5 Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.4.10.4 158.4 - Service (granted): (16) I.CA - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (16) I.CA - issuing qualified certificates Name [ cs ] (16) I.CA - vydávání kvalifikovaných certifikátů Service Name Service digital identities CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 26 ETSI 2014 - TSL HR - PDF/A-1b generator Certificate fields details Version: 3 Serial Number: 10500000 X509 Certificate -----BEGIN CERTIFICATE----MIIFHjCCBAagAwIBAgIEAKA3oDANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0wOTA5 MDEwMDAwMDBaFw0xOTA5MDEwMDAwMDBaMIG3MQswCQYDVQQGEwJDWjE6MDgGA1UEAwwxSS5DQSAt IFF1YWxpZmllZCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSwgMDkvMjAwOTEtMCsGA1UECgwkUHJ2 bsOtIGNlcnRpZmlrYcSNbsOtIGF1dG9yaXRhLCBhLnMuMT0wOwYDVQQLDDRJLkNBIC0gQWNjcmVk aXRlZCBQcm92aWRlciBvZiBDZXJ0aWZpY2F0aW9uIFNlcnZpY2VzMIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEAtTaEy0KC8M9l4lSaWHMs4+sVV1LwzyJYiIQNeCrv1HHm/YpGIdY/Z640 ceankjQvIX7m23BK4OSC6KO8kZYA3zopOz6GFCOKV2PvLukbc+c2imF6kLHEv6qNA8WxhPbR3xKw lHDwB2yhWzo7V3QVgDRG83sugqQntKYC3LnlTGbJpNP+Az72gpO9AHUn/IBhFk4ksc8lYS2L9GCy 9CsmdKSBP78p9w8Lx7vDLqkDgt1/zBrcUWmSSb7AE/BPEeMryQV1IdI6nlGnBhWkXOYf6GSdayJw 86btuxC7viDKNrbp44HjQRaSxnp6O3eto1x4DfiYdw/YbJFe7EjkxSQBywIDAQABo4IBLjCCASow DwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwgecGA1UdIASB3zCB3DCB2QYEVR0gADCB 0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGplIHZ5ZGFuIGpha28ga3ZhbGlm aWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtvbmEgYy4gMjI3LzIwMDAgU2Iu IHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0ZW0gY2VydGlmaWNhdGUgYWNj b3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4wHQYDVR0OBBYEFHnL0CPpOmdw kXRP01Hi4CD94Sj7MA0GCSqGSIb3DQEBCwUAA4IBAQB9laU214hYaBHPZftbDS/2dIGLWdmdSbj1 OZbJ8LIPBMxYjPoEMqzAR74tw96Ti6aWRa5WdOWaS6I/qibEKFZhJAVXX5mkx2ewGFLJ+0Go+eTx njLOnhVF2V2s+57bm8c8j6/bS6Ij6DspcHEYpfjjh64hE2r0aSpZDjGzKFM6YpqsCJN8qYe2X1qm GMLQwvNdjG+nPzCJOOuUEypIWt555ZDLXqS5F7ZjBjlfyDZjEfS2Es9Idok8alf563Mi9/o+Ba46 wMYOkk3P1IlU0RqCajdbliioACKDztAqubONU1guZVzV8tuMASVzbJeL/GAB7ECTwe1RuKrLYtgl MKI9 -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Qualified Certification Authority, 09/2009 Subject C: CZ Valid from: Tue Sep 01 02:00:00 CEST 2009 Valid to: Sun Sep 01 02:00:00 CEST 2019 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B5:36:84:CB:42:82:F0:CF:65:E2:54:9A:58:73:2C:E3:EB:15:57:52:F0:CF:22:58:88:84:0D:78:2A:EF:D4:71:E6:FD:8A :46:21:D6:3F:67:AE:34:71:E6:A7:92:34:2F:21:7E:E6:DB:70:4A:E0:E4:82:E8:A3:BC:91:96:00:DF:3A:29:3B:3E:86:14:23:8A:57:63:EF:2E:E9:1B:73:E7:36:8A:61:7A:90:B1:C4:BF:AA:8D:03:C5:B1:84:F6:D1:DF:12:B0:94:7 0:F0:07:6C:A1:5B:3A:3B:57:74:15:80:34:46:F3:7B:2E:82:A4:27:B4:A6:02:DC:B9:E5:4C:66:C9:A4:D3:FE:03:3E:F6:82:93:BD:00:75:27:FC:80:61:16:4E:24:B1:CF:25:61:2D:8B:F4:60:B2:F4:2B:26:74:A4:81:3F:BF:29:F7:0F :0B:C7:BB:C3:2E:A9:03:82:DD:7F:CC:1A:DC:51:69:92:49:BE:C0:13:F0:4F:11:E3:2B:C9:05:75:21:D2:3A:9E:51:A7:06:15:A4:5C:E6:1F:E8:64:9D:6B:22:70:F3:A6:ED:BB:10:BB:BE:20:CA:36:B6:E9:E3:81:E3:41:16:92:C6 :7A:7A:3B:77:AD:A3:5C:78:0D:F8:98:77:0F:D8:6C:91:5E:EC:48:E4:C5:24:01:CB:02:03:01:00:01 Basic Constraints IsCA: true Certificate Policies Policy OID: 2.5.29.32.0 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Subject Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB Key Usage: keyCertSign - cRLSign CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 27 ETSI 2014 - TSL HR - PDF/A-1b generator Thumbprint algorithm: SHA-256 Thumbprint: C0:C0:5A:8D:8D:A5:5E:AF:27:AA:9B:91:0B:0A:6E:F0:D8:BB:DE:D3:46:92:8D:B8:72:E1:82:C2: 07:3E:98:02 Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted Service status description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.4.1 - Extension (critical): Qualifiers [QCQSCDStatusAsInCert] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.1.30.3.0 Policy Identifier nodes: CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 28 ETSI 2014 - TSL HR - PDF/A-1b generator Identifier 1.3.6.1.4.1.23624.1.1.30.3.1 158.4.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 158.4.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (16) I.CA - issuing qualified certificates Name [ cs ] (16) I.CA - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Qualified Certification Authority, 09/2009 Subject C: CZ X509SKI X509 SK I ecvQI+k6Z3CRdE/TUeLgIP3hKPs= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2009-09-01T00:00:00Z 158.4.3.1 - Extension (critical): Qualifiers [QCSSCDStatusAsInCert] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati nell'ambito del servizio (RootCA / QC o CA / QC ) ha individuato in "service digital identity" e in seguito identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" individuato servizio fiducia che insieme preciso di certificati qualificati per i quali queste informazioni supplementari è necessaria per quanto riguarda la presenza o l'assenza di una firma sicura dispositivo Creation (SSCD) sostegno contengono le informazioni machineprocessable indica se o meno il certificato qualificato è supportato da un SSCD. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 29 ETSI 2014 - TSL HR - PDF/A-1b generator [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati nell'ambito del servizio (RootCA / QC o CA / QC ) ha individuato in "service digital identity" e in seguito identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" individuato servizio fiducia che insieme preciso di certificati qualificati per i quali queste informazioni supplementari è necessaria per quanto riguarda la presenza o l'assenza di una firma sicura dispositivo Creation (SSCD) sostegno contengono le informazioni machineprocessable indica se o meno il certificato qualificato è supportato da un SSCD. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) oder geprüft (Akkreditierungsmodell ), dass alle qualifizierten Zertifikaten unter der Service (RootCA / QC oder CA / QC ausgestellt ) in "Service digital identity" und weiter durch die Filter verwendet Informationen identifiziert, weiter zu ermitteln im Rahmen der "Sdi" identifizierten Treuhandservice, die genaue Menge der qualifizierte Zertifikate, für die sich diese zusätzlichen Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signatur erforderlich Erstellungseinheit (SSEE) unterstützen, enthalten die machineprocessable Informationen anzeigt, ob das qualifizierte Zertifikat von einer SSCD unterstützt. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) oder geprüft (Akkreditierungsmodell ), dass alle qualifizierten Zertifikaten unter der Service (RootCA / QC oder CA / QC ausgestellt ) in "Service digital identity" und weiter durch die Filter verwendet Informationen identifiziert, weiter zu ermitteln im Rahmen der "Sdi" identifizierten Treuhandservice, die genaue Menge der qualifizierte Zertifikate, für die sich diese zusätzlichen Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signatur erforderlich Erstellungseinheit (SSEE) unterstützen, enthalten die machineprocessable Informationen anzeigt, ob das qualifizierte Zertifikat von einer SSCD unterstützt. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) oder geprüft (Akkreditierungsmodell ), dass alle qualifizierten Zertifikaten unter der Service (RootCA / QC oder CA / QC ausgestellt ) in "Service digital identity" und weiter durch die Filter verwendet Informationen identifiziert, weiter zu ermitteln im Rahmen der "Sdi" identifizierten Treuhandservice, die genaue Menge der qualifizierte Zertifikate, für die sich diese zusätzlichen Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signatur erforderlich Erstellungseinheit (SSEE) unterstützen, enthalten die machineprocessable Informationen anzeigt, ob das qualifizierte Zertifikat von einer SSCD unterstützt. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service (Racine / QC ou CA / QC ) a identifié dans "service digital identity» et encore identifié par les informations des filtres utilisés pour identifier d'autres sous le "Sdi" identifié service de confiance, l'ensemble précis de certificats qualifiés pour lequel ces informations supplémentaires sont nécessaires en ce qui concerne la présence ou l'absence de signature sécurisée Dispositif de création (SSCD) support ne contiennent les informations machineprocessable indiquant si oui ou non le certificat qualifié est un SSCD. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCSSCDStatusAsInCert Criteria list assert=atLeastOne Policy Identifier nodes: Identifier CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ 1.3.6.1.4.1.23624.1.1.30.3.0 Page 30 ETSI 2014 - TSL HR - PDF/A-1b generator Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.1.1.30.3.1 158.5 - Service (withdrawn): (9) I.CA - Qualified Time Stamping Authority, nCipher DSE200 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (9) I.CA - Qualified Time Stamping Authority, nCipher DSE200 Name [ cs ] (9) I.CA - autorita kvalifikovaných časových razítek, nCipher DSE200 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10106572 X509 Certificate -----BEGIN CERTIFICATE----MIIFDDCCA/SgAwIBAgIEAJo2zDANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4wHhcNMDYwMjAxMDAwMDAwWhcNMTEwMjAxMDAwMDAw WjB+MQswCQYDVQQGEwJDWjEnMCUGA1UEAwweSS5DQSAtIFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5 MS0wKwYDVQQKDCRQcnZuw60gY2VydGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4xFzAVBgNVBAsM Dm5DaXBoZXIgRFNFMjAwMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxFbYLQl+tUvY ++dg0z4JlLKXo893YhTa0CfJ2ry77RLJwVQ/z+ntIyUh486ShzRwimyNXT7j2BhzqR8/4xZkW7Vn v5L4ZC1zSTJXIwzsQHyqPKWh0+odsS0BN6nD1pO0vqZTFQZeNnW/SBLBGzILG7FM2tVaWf/8efHI YZ65P0pZPnS2Bbs8hFbhyVRI912O9UbWpxUhkRIELbyGKKBS0J5qqMsFRgzx0vkJQRDb0Iap1UoD 6Iq1ML7TwgSa/H9Zby5im18Ii78sT45ESsNy2YQ0hIHTzeCP7mi6ex1aU9MigOqxBl8FcbO3Ib1Q j3yMkYXej3lK7WW+Ncrn8oL3awIDAQABo4IBpjCCAaIwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMIGZBgNVHSAEgZEwgY4wgYsGDCsGAQQBgbhIAQQNATB7MHkGCCsGAQUF BwICMG0aa1RlbnRvIGt2YWxpZmlrb3Zhbnkgc3lzdGVtb3Z5IGNlcnRpZmlrYXQgVFNBIGplIHZ5 ZGFuIHYgc291bGFkdSBzZSB6YWtvbmVtIGMuIDIyNy8yMDAwIFNiLiB2IHBsYXRuZW0gem5lbmku MB0GA1UdDgQWBBTmfh7VaSxiwPnTJxxV5q0/JmlkjDAfBgNVHSMEGDAWgBRRLl9ZgSX/0f6G6Icu 1o0NWTQrvTCBgQYDVR0fBHoweDAmoCSgIoYgaHR0cDovL3FjcmxkcDEuaWNhLmN6L3FpY2EwNS5j cmwwJqAkoCKGIGh0dHA6Ly9xY3JsZHAyLmljYS5jei9xaWNhMDUuY3JsMCagJKAihiBodHRwOi8v cWNybGRwMy5pY2EuY3ovcWljYTA1LmNybDAYBggrBgEFBQcBAwQMMAowCAYGBACORgEBMA0GCSqG SIb3DQEBBQUAA4IBAQBPRRpXGvlbqAhk5tFos10jKQkKaOwUGcOmXatq7AR4nKIPkzGUVKl6SDzq +KS/hhKQ+FzlMHC1Fl8zTvgfqyj14UpTNU0yFNzpG6yRCLkJzIaw5J2szDOwQOqbGzZ18HXc/ogA HYenXtr+goxvOcmpk8mw7wlLcHssSj5hQpf5l97FqARRen0rHW8wgOxdjSycB2Ji/YtywAEUWDiI awMXheRANFHsVIixYN6H/CEQgyKXG4xJDocLIwgCPB2M9NHNKYmkXWTRWcS+SvQ2pOICKjPmWqLw HuoJwyKXhSZa7oCGI7l2g2AicrRbvc6VB8Wk+s/a+E4ZxR4Bd+gdQtWF -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer O: První certifikační autorita, a.s. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 31 ETSI 2014 - TSL HR - PDF/A-1b generator Issuer CN: I.CA - Qualified root certificate Issuer C: CZ Subject OU: nCipher DSE200 Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority Subject C: CZ Valid from: Wed Feb 01 01:00:00 CET 2006 Valid to: Tue Feb 01 01:00:00 CET 2011 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C4:56:D8:2D:09:7E:B5:4B:D8:FB:E7:60:D3:3E:09:94:B2:97:A3:CF:77:62:14:DA:D0:27:C9:DA:BC:BB:ED:12:C9:C 1:54:3F:CF:E9:ED:23:25:21:E3:CE:92:87:34:70:8A:6C:8D:5D:3E:E3:D8:18:73:A9:1F:3F:E3:16:64:5B:B5:67:BF:92:F8:64:2D:73:49:32:57:23:0C:EC:40:7C:AA:3C:A5:A1:D3:EA:1D:B1:2D:01:37:A9:C3:D6:93:B4:BE:A6:5 3:15:06:5E:36:75:BF:48:12:C1:1B:32:0B:1B:B1:4C:DA:D5:5A:59:FF:FC:79:F1:C8:61:9E:B9:3F:4A:59:3E:74:B6:05:BB:3C:84:56:E1:C9:54:48:F7:5D:8E:F5:46:D6:A7:15:21:91:12:04:2D:BC:86:28:A0:52:D0:9E:6A:A8:CB: 05:46:0C:F1:D2:F9:09:41:10:DB:D0:86:A9:D5:4A:03:E8:8A:B5:30:BE:D3:C2:04:9A:FC:7F:59:6F:2E:62:9B:5F:08:8B:BF:2C:4F:8E:44:4A:C3:72:D9:84:34:84:81:D3:CD:E0:8F:EE:68:BA:7B:1D:5A:53:D3:22:80:EA:B1:06: 5F:05:71:B3:B7:21:BD:50:8F:7C:8C:91:85:DE:8F:79:4A:ED:65:BE:35:CA:E7:F2:82:F7:6B:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.4.13.1 CPS text: [Tento kvalifikovany systemovy certifikat TSA je vydan v souladu se zakonem c. 227/2000 Sb. v platnem zneni.] Subject Key Identifier E6:7E:1E:D5:69:2C:62:C0:F9:D3:27:1C:55:E6:AD:3F:26:69:64:8C Authority Key Identifier 51:2E:5F:59:81:25:FF:D1:FE:86:E8:87:2E:D6:8D:0D:59:34:2B:BD CRL Distribution Points http://qcrldp1.ica.cz/qica05.crl http://qcrldp2.ica.cz/qica05.crl http://qcrldp3.ica.cz/qica05.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 20:E9:D7:B8:3E:BE:1E:B0:BB:FB:CD:EE:B4:4A:39:87:04:F7:49:7F:A4:37:44:C2:12:1A:FB:EC:3 5:A4:6A:C7 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 32 ETSI 2014 - TSL HR - PDF/A-1b generator [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.5.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (9) I.CA - Qualified Time Stamping Authority, nCipher DSE200 Name [ cs ] (9) I.CA - autorita kvalifikovaných časových razítek, nCipher DSE200 Service digital identities X509SubjectName Subject OU: nCipher DSE200 Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority Subject C: CZ X509SKI X509 SK I 5n4e1WksYsD50yccVeatPyZpZIw= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2006-02-01T00:00:00Z 158.6 - Service (withdrawn): (10) I.CA - Qualified Time Stamping Authority, Time Stamp Server 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 33 ETSI 2014 - TSL HR - PDF/A-1b generator [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (10) I.CA - Qualified Time Stamping Authority, Time Stamp Server 1 Name [ cs ] (10) I.CA - autorita kvalifikovaných časových razítek, Time Stamp Server 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10146890 X509 Certificate -----BEGIN CERTIFICATE----MIIFCjCCA/KgAwIBAgIEAJrUSjANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4wHhcNMDcxMDA0MTIwMDAwWhcNMTIxMDA0MTIwMDAw WjB8MQswCQYDVQQGEwJDWjEgMB4GA1UEAwwXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxLTArBgNV BAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjEcMBoGA1UECwwTVGltZSBT dGFtcCBTZXJ2ZXIgMTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALmqLuTS773u7L31 tVeGpNGGtedHhAOHXEto3hO5UAMizEQFLkRln51BvFeNeF8NdxGyKfhc0pdErd1vIcCx9Xsrhvbx Cmu4nLFWTVHd9giyWFft1jAEYy3g/DeSAOw5dEZir61PrkzcuR5K9TOytCqmHBKVkmQBSU0WyKGm wXEzZ15ngMitXoBhBW8Q4BM83D4/zJXt0rJ73wW/xav+XhchC9ZR0T508hrALsi+tV/3WWvZ/CwO qs2M1xf/2BKDY9XPd7vTdMMLgNSoXGufhKQfSUHkMt/OiC/Ke2yZXj7tB6LVrJXhUVlp1qlakOmM 6lde0MB53TuQ1cXaWoA9DrUCAwEAAaOCAaYwggGiMA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8E DDAKBggrBgEFBQcDCDCBmQYDVR0gBIGRMIGOMIGLBgwrBgEEAYG4SAEEDQIwezB5BggrBgEFBQcC AjBtGmtUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZpa2F0IFRTQSBqZSB2eWRh biB2IHNvdWxhZHUgc2UgemFrb25lbSBjLiAyMjcvMjAwMCBTYi4gdiBwbGF0bmVtIHpuZW5pLjAd BgNVHQ4EFgQUUg8dzQRsLAN9t3HQwfbZUFTiZu0wHwYDVR0jBBgwFoAUUS5fWYEl/9H+huiHLtaN DVk0K70wgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAxLmljYS5jei9xaWNhMDUuY3Js MCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA1LmNybDAmoCSgIoYgaHR0cDovL3Fj cmxkcDMuaWNhLmN6L3FpY2EwNS5jcmwwGAYIKwYBBQUHAQMEDDAKMAgGBgQAjkYBATANBgkqhkiG 9w0BAQUFAAOCAQEAEvbKCNp3oxoJ9W5nAxXTxWaxF4OPQOqanKOG/Z8xTkHG684Pq8eKK1Voweo/ QALOBu9j17NpnhwT/SvaFBJjQyqORVe3X0IUIgRdjHuMQeaequLsqDUSMzjYAuPZv4Ezod2YmlSY /h/M98CO8Q6B0fFMeu8UdqRa4U0rysbw8/o0AC/5fX8/er1l9RIU2Z29UM0VclpCdBGCTbmY84Sk f3mz5i40XQKwzdEdz1sqJADFXcrZ+/Tm5Aihczd4rLecCSPj/VnkhR3fiRTtUSvYHn0FMwubh4KW e6fMpKFoCDSKsIdq18FVbXMI3Q3yLtOIXErqjddreQrKblcfbsv4pA== -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified root certificate Issuer C: CZ Subject OU: Time Stamp Server 1 Subject O: První certifikační autorita, a.s. Subject CN: Time Stamping Authority Subject C: CZ Valid from: Thu Oct 04 14:00:00 CEST 2007 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 34 ETSI 2014 - TSL HR - PDF/A-1b generator Valid to: Thu Oct 04 14:00:00 CEST 2012 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B9:AA:2E:E4:D2:EF:BD:EE:EC:BD:F5:B5:57:86:A4:D1:86:B5:E7:47:84:03:87:5C:4B:68:DE:13:B9:50:03:22:CC:44 :05:2E:44:65:9F:9D:41:BC:57:8D:78:5F:0D:77:11:B2:29:F8:5C:D2:97:44:AD:DD:6F:21:C0:B1:F5:7B:2B:86:F6:F1:0A:6B:B8:9C:B1:56:4D:51:DD:F6:08:B2:58:57:ED:D6:30:04:63:2D:E0:FC:37:92:00:EC:39:74:46:62:AF:A D:4F:AE:4C:DC:B9:1E:4A:F5:33:B2:B4:2A:A6:1C:12:95:92:64:01:49:4D:16:C8:A1:A6:C1:71:33:67:5E:67:80:C8:AD:5E:80:61:05:6F:10:E0:13:3C:DC:3E:3F:CC:95:ED:D2:B2:7B:DF:05:BF:C5:AB:FE:5E:17:21:0B:D6:51: D1:3E:74:F2:1A:C0:2E:C8:BE:B5:5F:F7:59:6B:D9:FC:2C:0E:AA:CD:8C:D7:17:FF:D8:12:83:63:D5:CF:77:BB:D3:74:C3:0B:80:D4:A8:5C:6B:9F:84:A4:1F:49:41:E4:32:DF:CE:88:2F:CA:7B:6C:99:5E:3E:ED:07:A2:D5:AC: 95:E1:51:59:69:D6:A9:5A:90:E9:8C:EA:57:5E:D0:C0:79:DD:3B:90:D5:C5:DA:5A:80:3D:0E:B5:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.4.13.2 CPS text: [Tento kvalifikovany systemovy certifikat TSA je vydan v souladu se zakonem c. 227/2000 Sb. v platnem zneni.] Subject Key Identifier 52:0F:1D:CD:04:6C:2C:03:7D:B7:71:D0:C1:F6:D9:50:54:E2:66:ED Authority Key Identifier 51:2E:5F:59:81:25:FF:D1:FE:86:E8:87:2E:D6:8D:0D:59:34:2B:BD CRL Distribution Points http://qcrldp1.ica.cz/qica05.crl http://qcrldp2.ica.cz/qica05.crl http://qcrldp3.ica.cz/qica05.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 00:87:62:13:F0:3D:D0:5B:1D:55:7A:FB:F5:1A:60:6A:88:4D:F7:C8:8E:FE:A4:0E:02:D5:4F:D6:87: A9:B0:80 Service Status Service status description Status Starting Time http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. 2016-07-01T00:00:00Z 158.6.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 35 ETSI 2014 - TSL HR - PDF/A-1b generator Service Name Name [ en ] (10) I.CA - Qualified Time Stamping Authority, Time Stamp Server 1 Name [ cs ] (10) I.CA - autorita kvalifikovaných časových razítek, Time Stamp Server 1 Service digital identities X509SubjectName Subject OU: Time Stamp Server 1 Subject O: První certifikační autorita, a.s. Subject CN: Time Stamping Authority Subject C: CZ X509SKI X509 SK I Ug8dzQRsLAN9t3HQwfbZUFTiZu0= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2007-10-04T12:00:00Z 158.7 - Service (withdrawn): (12) I.CA - Qualified Time Stamping Authority, Time Stamp Server 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (12) I.CA - Qualified Time Stamping Authority, Time Stamp Server 2 Name [ cs ] (12) I.CA - autorita kvalifikovaných časových razítek, Time Stamp Server 2 Service Name CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 36 ETSI 2014 - TSL HR - PDF/A-1b generator Service digital identities Certificate fields details Version: 3 Serial Number: 10153426 X509 Certificate -----BEGIN CERTIFICATE----MIIFCjCCA/KgAwIBAgIEAJrt0jANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4wHhcNMDcxMTIwMTUwMDAwWhcNMTIxMTIwMTUwMDAw WjB8MQswCQYDVQQGEwJDWjEgMB4GA1UEAwwXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxLTArBgNV BAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjEcMBoGA1UECwwTVGltZSBT dGFtcCBTZXJ2ZXIgMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMyCbm+sGQuxGBE3 NRsQfWM+ai6k8YixTtYmY/oMHiMkYpkW66SMrRzQmSoHZGcD+MhD6AvLcBe2LAPZtGr3xzVOoFd4 KCYE4XGYOjPYE6emBv8V3hCUyYr7NZobQAAc2KaQnBCoCy0XPMsKRRkTGXwe57qGBODiRfcYl6TG KwssyGXfqyUiQb5dhAvYrZxTd+HEmqlahTvKV0pMYepBXdvDWvmXKXmGU1zbpLXxVpAx5n0PRh/F UQCDazXzdBowQ1nFmT0KR1ZYibqPPT0kJSo2Me+Fa09XC9B4dzLYvAuExjq4SeMwI7rHgWEPltPP GwtJ+DDquToP97MfT6PInuMCAwEAAaOCAaYwggGiMA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8E DDAKBggrBgEFBQcDCDCBmQYDVR0gBIGRMIGOMIGLBgwrBgEEAYG4SAEEDQIwezB5BggrBgEFBQcC AjBtGmtUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZpa2F0IFRTQSBqZSB2eWRh biB2IHNvdWxhZHUgc2UgemFrb25lbSBjLiAyMjcvMjAwMCBTYi4gdiBwbGF0bmVtIHpuZW5pLjAd BgNVHQ4EFgQUMygooX8Bhw3zSSrGDXpcF1jpF5AwHwYDVR0jBBgwFoAUUS5fWYEl/9H+huiHLtaN DVk0K70wgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAxLmljYS5jei9xaWNhMDUuY3Js MCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA1LmNybDAmoCSgIoYgaHR0cDovL3Fj cmxkcDMuaWNhLmN6L3FpY2EwNS5jcmwwGAYIKwYBBQUHAQMEDDAKMAgGBgQAjkYBATANBgkqhkiG 9w0BAQUFAAOCAQEAZAwj1ACoHsIXSGII/ETo9vqHWVZximMwOIjkZ5rr8tDrTro6VEXuhHzDcRlp CWwwIejd4rIHKUhweykuAFVwEHFhMUjUiXkeb8GN17cr4IHyTPHkvcIJB0UkE54IOf3j877pD06e /DjHFGnukKfcHqtv7tu0BKjHYyNiIkt1mDa9NjE05PuaNOv4X0iW6LqQXdfFRqnGPeXQ9Gx9hxRZ qnF9JeIe4Pm1XcJbqz70RkiJyaTQmSuw9YfWV8+RUEGU+ZknU53wnpHktV7gHCKDQ/VTbF0gHY0V qqDRd8SpVUnLyD7tO9DCzdV+zamBX7LTCeKlrRLrCv7izqa2Q3DW+w== -----END CERTIFICATE----- Signature algorithm: SHA1withRSA Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified root certificate Issuer C: CZ Subject OU: Time Stamp Server 2 Subject O: První certifikační autorita, a.s. Subject CN: Time Stamping Authority Subject C: CZ Valid from: Tue Nov 20 16:00:00 CET 2007 Valid to: Tue Nov 20 16:00:00 CET 2012 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:CC:82:6E:6F:AC:19:0B:B1:18:11:37:35:1B:10:7D:63:3E:6A:2E:A4:F1:88:B1:4E:D6:26:63:FA:0C:1E:23:24:62:99:16 :EB:A4:8C:AD:1C:D0:99:2A:07:64:67:03:F8:C8:43:E8:0B:CB:70:17:B6:2C:03:D9:B4:6A:F7:C7:35:4E:A0:57:78:28:26:04:E1:71:98:3A:33:D8:13:A7:A6:06:FF:15:DE:10:94:C9:8A:FB:35:9A:1B:40:00:1C:D8:A6:90:9C:10: A8:0B:2D:17:3C:CB:0A:45:19:13:19:7C:1E:E7:BA:86:04:E0:E2:45:F7:18:97:A4:C6:2B:0B:2C:C8:65:DF:AB:25:22:41:BE:5D:84:0B:D8:AD:9C:53:77:E1:C4:9A:A9:5A:85:3B:CA:57:4A:4C:61:EA:41:5D:DB:C3:5A:F9:97:2 9:79:86:53:5C:DB:A4:B5:F1:56:90:31:E6:7D:0F:46:1F:C5:51:00:83:6B:35:F3:74:1A:30:43:59:C5:99:3D:0A:47:56:58:89:BA:8F:3D:3D:24:25:2A:36:31:EF:85:6B:4F:57:0B:D0:78:77:32:D8:BC:0B:84:C6:3A:B8:49:E3:30:23: BA:C7:81:61:0F:96:D3:CF:1B:0B:49:F8:30:EA:B9:3A:0F:F7:B3:1F:4F:A3:C8:9E:E3:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.4.13.2 CPS text: [Tento kvalifikovany systemovy certifikat TSA je vydan v souladu se zakonem c. 227/2000 Sb. v platnem zneni.] Subject Key Identifier 33:28:28:A1:7F:01:87:0D:F3:49:2A:C6:0D:7A:5C:17:58:E9:17:90 Authority Key Identifier 51:2E:5F:59:81:25:FF:D1:FE:86:E8:87:2E:D6:8D:0D:59:34:2B:BD CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 37 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://qcrldp1.ica.cz/qica05.crl http://qcrldp2.ica.cz/qica05.crl http://qcrldp3.ica.cz/qica05.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 61:B7:8A:3D:94:57:66:67:5E:A3:5F:F6:2F:B1:FF:A0:41:01:8B:9E:16:1E:E4:D7:98:A6:CF:28:FD: F3:82:E4 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.7.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (12) I.CA - Qualified Time Stamping Authority, Time Stamp Server 2 Name [ cs ] (12) I.CA - autorita kvalifikovaných časových razítek, Time Stamp Server 2 Service digital identities X509SubjectName Subject OU: Time Stamp Server 2 Subject O: První certifikační autorita, a.s. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 38 ETSI 2014 - TSL HR - PDF/A-1b generator Subject CN: Time Stamping Authority Subject C: CZ X509SKI X509 SK I MygooX8Bhw3zSSrGDXpcF1jpF5A= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2007-11-20T15:00:00Z 158.8 - Service (withdrawn): (17) I.CA - Time Stamping Authority, TSS/TSU 1, 12/2009 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (17) I.CA - Time Stamping Authority, TSS/TSU 1, 12/2009 Name [ cs ] (17) I.CA - autorita časových razítek, TSS/TSU 1, 12/2009 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10516812 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 39 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGPDCCBSSgAwIBAgIEAKB5TDANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0wOTEy MjEwMDAwMDBaFw0xNDEyMjEwMDAwMDBaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDEsIDEyLzIwMDkxLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAOAL3309Bu7aBb8ATwFuENJGts+1qKlrfSqeF5YxXLgaPJNqG2JBRIkw Aix9kybMMf1H2RKzW0JNf80xTY5Mi/IcvCuxazysIS/QQ5RJH/Pf2H9a1ULUKZNyAOgjr90eOUW3 NiRLUTHyIHWOBaKBdmd308lkHWMC9iAp5rMDLB3U5RFfSfePxur/t5MfqJuPxL22SlRQ/GGA84bF MFuHbs8ipZjgG5pKQ7F5fAV/sF8aXACQfAVsvExIDCz4U9W8TNNtmTTOS35zeDCRyQOD0LMmfY3V hjZ/PmdzB8JENTRjgbKFkh9I0Cnrvx9r16lJtwevOUBxCIO+67ait8OQjDkCAwEAAaOCAkswggJH MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDATCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUATQz1VE9CEHWLuddiAOe8EGLXzYwHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwGAYIKwYBBQUHAQMEDDAK MAgGBgQAjkYBATA6BggrBgEFBQcBAQQuMCwwKgYIKwYBBQUHMAKGHmh0dHA6Ly9xLmljYS5jei9j YV9uYnVzcjA5LnA3YzANBgkqhkiG9w0BAQsFAAOCAQEACdsiKRUCZQMBfhs+QyPxrRV5DMZ4f4rA j7cwxU9jjl4EzeJHMG7GUrNwYMm9ijncMJOZ+u9i7dmuf6fFlSrNxnfEepXUa1+QR3mHqc1q41nA OFuVtNpqHZ3HKRVx8AmfYaN85oeH47P1yfW3M4U6G8H+lbGoAXCWPpUD9A9QRX8/oZZfjQAj+6Dt TcM/SR3fN8M2E6NUtRHWDWGNZ9gpFSsp0PIdZaw+N3VyOSt5Lqcnfr/C3S7rKNqcR6jnbmfxrcdf zKlhv2ZyAhgPQKRDXtl56+8Gzz1KMQUoSf2YXkqHMmv+Dpyil4DaFaJqwgaX01RA5Lu+xtgoCidQ pd7O4g== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 1, 12/2009 Subject C: CZ Valid from: Mon Dec 21 01:00:00 CET 2009 Valid to: Sun Dec 21 01:00:00 CET 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:E0:0B:DF:7D:3D:06:EE:DA:05:BF:00:4F:01:6E:10:D2:46:B6:CF:B5:A8:A9:6B:7D:2A:9E:17:96:31:5C:B8:1A:3C:93 :6A:1B:62:41:44:89:30:02:2C:7D:93:26:CC:31:FD:47:D9:12:B3:5B:42:4D:7F:CD:31:4D:8E:4C:8B:F2:1C:BC:2B:B1:6B:3C:AC:21:2F:D0:43:94:49:1F:F3:DF:D8:7F:5A:D5:42:D4:29:93:72:00:E8:23:AF:DD:1E:39:45:B7:36: 24:4B:51:31:F2:20:75:8E:05:A2:81:76:67:77:D3:C9:64:1D:63:02:F6:20:29:E6:B3:03:2C:1D:D4:E5:11:5F:49:F7:8F:C6:EA:FF:B7:93:1F:A8:9B:8F:C4:BD:B6:4A:54:50:FC:61:80:F3:86:C5:30:5B:87:6E:CF:22:A5:98:E0:1B:9 A:4A:43:B1:79:7C:05:7F:B0:5F:1A:5C:00:90:7C:05:6C:BC:4C:48:0C:2C:F8:53:D5:BC:4C:D3:6D:99:34:CE:4B:7E:73:78:30:91:C9:03:83:D0:B3:26:7D:8D:D5:86:36:7F:3E:67:73:07:C2:44:35:34:63:81:B2:85:92:1F:48:D0:2 9:EB:BF:1F:6B:D7:A9:49:B7:07:AF:39:40:71:08:83:BE:EB:B6:A2:B7:C3:90:8C:39:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.1 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 01:34:33:D5:51:3D:08:41:D6:2E:E7:5D:88:03:9E:F0:41:8B:5F:36 Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 40 ETSI 2014 - TSL HR - PDF/A-1b generator QCStatements - crit. = false id_etsi_qcs_QcCompliance Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: D3:FD:94:CE:11:B8:BE:C7:E7:B0:8F:C0:65:D5:13:3A:12:07:E8:4D:4E:69:A5:07:05:94:21:C7:2E: 80:C3:FC Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.8.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (17) I.CA - Time Stamping Authority, TSS/TSU 1, 12/2009 Name [ cs ] (17) I.CA - autorita časových razítek, TSS/TSU 1, 12/2009 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 1, 12/2009 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 41 ETSI 2014 - TSL HR - PDF/A-1b generator Subject C: CZ X509SKI X509 SK I ATQz1VE9CEHWLuddiAOe8EGLXzY= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2009-12-21T00:00:00Z 158.9 - Service (withdrawn): (18) I.CA - Time Stamping Authority, TSS/TSU 2, 12/2009 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (18) I.CA - Time Stamping Authority, TSS/TSU 2, 12/2009 Name [ cs ] (18) I.CA - autorita časových razítek, TSS/TSU 2, 12/2009 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10516813 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 42 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGPDCCBSSgAwIBAgIEAKB5TTANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0wOTEy MjEwMDAwMDBaFw0xNDEyMjEwMDAwMDBaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDIsIDEyLzIwMDkxLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAMyaXZ79ae2fhC73CENUiSGlE9DDQvUWvEdQAV5eT+5SSK8lxaE3gAPJ TF/BVhbx0d2icjmkBjjTluzUYls8cLOppCMB4xsMZ8D933BESAnfAxhbnpDiTOA5oZEPGJOg3xTd NrA3HG1c5oEh83gZxFmlx9iSeaXHcNUymbpP1XiO9sKnO+omrD3bwyyBPCjDcl4z8Ms5X4xehofb QR/JQmu8bOCdlim7+t7V6Xoa0fjzivFlFOCQE4CIZHD9jKXi1k+kF9k2eUdS2jDFFxkKPogD2aMJ cyEFCzdr69jBO6uQ6YaC24ZTPHVM1KN5SrLoTzjRCg9jhe3Q82Gjm0MCkmkCAwEAAaOCAkswggJH MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDATCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUQvRV9kgkFHMHddWHurnCPvALEyowHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwGAYIKwYBBQUHAQMEDDAK MAgGBgQAjkYBATA6BggrBgEFBQcBAQQuMCwwKgYIKwYBBQUHMAKGHmh0dHA6Ly9xLmljYS5jei9j YV9uYnVzcjA5LnA3YzANBgkqhkiG9w0BAQsFAAOCAQEAf9dNpnT6fkvVJJ1Z3Gwhv97XvszI+ZAA Rvo0RBvKkkM5+Fa8lP14qxlZZIV8bw460gG1kijH/sfodWDjeFhwTqIiRN3ky+PRo6YqeEf95/Mm usNOYUECNIyZDQK4nHwNQ7ls+yBbSOEeeYbsdhMa7AMPshp113JUyIWKllykt2KU+VpaCYy0VTlf K+A7EHka3+Y4Zst30B0qxfubqnu58lDKrsimicqy2fAZCoSl/51/RQJsD7RR0BngjJB0zDwiHvhp 8BzpKLK72qKKmgESZy8kVgxJydCp/N6278pMtTw03Eodh/m5j7Glz3QXpBMwfUnhZnvwxoZNTeK8 KeWrtA== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 2, 12/2009 Subject C: CZ Valid from: Mon Dec 21 01:00:00 CET 2009 Valid to: Sun Dec 21 01:00:00 CET 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:CC:9A:5D:9E:FD:69:ED:9F:84:2E:F7:08:43:54:89:21:A5:13:D0:C3:42:F5:16:BC:47:50:01:5E:5E:4F:EE:52:48:AF:25 :C5:A1:37:80:03:C9:4C:5F:C1:56:16:F1:D1:DD:A2:72:39:A4:06:38:D3:96:EC:D4:62:5B:3C:70:B3:A9:A4:23:01:E3:1B:0C:67:C0:FD:DF:70:44:48:09:DF:03:18:5B:9E:90:E2:4C:E0:39:A1:91:0F:18:93:A0:DF:14:DD:36:B0:3 7:1C:6D:5C:E6:81:21:F3:78:19:C4:59:A5:C7:D8:92:79:A5:C7:70:D5:32:99:BA:4F:D5:78:8E:F6:C2:A7:3B:EA:26:AC:3D:DB:C3:2C:81:3C:28:C3:72:5E:33:F0:CB:39:5F:8C:5E:86:87:DB:41:1F:C9:42:6B:BC:6C:E0:9D:96:2 9:BB:FA:DE:D5:E9:7A:1A:D1:F8:F3:8A:F1:65:14:E0:90:13:80:88:64:70:FD:8C:A5:E2:D6:4F:A4:17:D9:36:79:47:52:DA:30:C5:17:19:0A:3E:88:03:D9:A3:09:73:21:05:0B:37:6B:EB:D8:C1:3B:AB:90:E9:86:82:DB:86:53:3C :75:4C:D4:A3:79:4A:B2:E8:4F:38:D1:0A:0F:63:85:ED:D0:F3:61:A3:9B:43:02:92:69:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.1 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 42:F4:55:F6:48:24:14:73:07:75:D5:87:BA:B9:C2:3E:F0:0B:13:2A Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 43 ETSI 2014 - TSL HR - PDF/A-1b generator QCStatements - crit. = false id_etsi_qcs_QcCompliance Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 2B:97:10:EC:C9:E7:5B:FA:73:AB:35:5C:18:FB:C9:58:73:A5:66:40:61:4D:A4:AA:12:A5:21:F9:9E :1B:3E:E3 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.9.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (18) I.CA - Time Stamping Authority, TSS/TSU 2, 12/2009 Name [ cs ] (18) I.CA - autorita časových razítek, TSS/TSU 2, 12/2009 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 2, 12/2009 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 44 ETSI 2014 - TSL HR - PDF/A-1b generator Subject C: CZ X509SKI X509 SK I QvRV9kgkFHMHddWHurnCPvALEyo= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2009-12-21T00:00:00Z 158.10 - Service (withdrawn): (19) I.CA - Time Stamping Authority, TSS/TSU 3, 12/2009 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (19) I.CA - Time Stamping Authority, TSS/TSU 3, 12/2009 Name [ cs ] (19) I.CA - autorita časových razítek, TSS/TSU 3, 12/2009 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10516814 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 45 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGPDCCBSSgAwIBAgIEAKB5TjANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0wOTEy MjEwMDAwMDBaFw0xNDEyMjEwMDAwMDBaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDMsIDEyLzIwMDkxLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAJYUOQ0JlJbW1qvziyE4OiAjWabAjj0qHD4FRSAW48e0Pq4jGia48Z8s 6hRXyU5TXJUTeYJ5wr6J9wU2/lZJBfffhFXHJwhhOZl++msbWokHi6xaUHO7sD1n5ec4deygmEnT i7376koz3R6oM8zA64VsfnsLggVEXyhkNbcUIY01s+x/2roO+QmTXQqHgPcS96r6pbJeeKhwnsCR lnLxOWZNoDHEXAJLVKiOn02rVUvkIVehkxnyLz5ELoehFeXTfrOb851aLr7KsSbGEQDStutLTjzZ nziv1Rwu1suE85S/l03B/zXqAHzS2iHhOH2xk5D1KqX16ujutIDrUzCKFVsCAwEAAaOCAkswggJH MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDATCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUKCcTR2PUT3HVNlYI384SqxTHsA8wHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwGAYIKwYBBQUHAQMEDDAK MAgGBgQAjkYBATA6BggrBgEFBQcBAQQuMCwwKgYIKwYBBQUHMAKGHmh0dHA6Ly9xLmljYS5jei9j YV9uYnVzcjA5LnA3YzANBgkqhkiG9w0BAQsFAAOCAQEAa3tPcx5bBm3dgcFlZKgCyVdFgtb7mVer WBL2d2MS4ZnFpBatSLCQKaPEVHX9JpUnso4hLyB/JzuudaWolyTUd4hXnpi7ECIO5O9cURaSPejf 5czfSqTFh32+NxbPHcCQ9uVZ8jM9TwO7kzNeK0gRVtAf+FOnBxT74ZY13P6L6ongNHP/VSONHVvU jT6yQOkrZa2hArbHYQeElS8DUu7+lf1m0SufWkBsibS2mJ933akGi64bApRIfqgKNEtxNnzCJ2LH zqTef0b3YDUNNyZxOFZmqGitodPzvSqf5gpWf5HmXB1o6df2/4+GSXWOXISbVbpCBVhkTqKKl9ZS bkGRRA== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 3, 12/2009 Subject C: CZ Valid from: Mon Dec 21 01:00:00 CET 2009 Valid to: Sun Dec 21 01:00:00 CET 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:96:14:39:0D:09:94:96:D6:D6:AB:F3:8B:21:38:3A:20:23:59:A6:C0:8E:3D:2A:1C:3E:05:45:20:16:E3:C7:B4:3E:AE:2 3:1A:26:B8:F1:9F:2C:EA:14:57:C9:4E:53:5C:95:13:79:82:79:C2:BE:89:F7:05:36:FE:56:49:05:F7:DF:84:55:C7:27:08:61:39:99:7E:FA:6B:1B:5A:89:07:8B:AC:5A:50:73:BB:B0:3D:67:E5:E7:38:75:EC:A0:98:49:D3:8B:BD:F B:EA:4A:33:DD:1E:A8:33:CC:C0:EB:85:6C:7E:7B:0B:82:05:44:5F:28:64:35:B7:14:21:8D:35:B3:EC:7F:DA:BA:0E:F9:09:93:5D:0A:87:80:F7:12:F7:AA:FA:A5:B2:5E:78:A8:70:9E:C0:91:96:72:F1:39:66:4D:A0:31:C4:5C:0 2:4B:54:A8:8E:9F:4D:AB:55:4B:E4:21:57:A1:93:19:F2:2F:3E:44:2E:87:A1:15:E5:D3:7E:B3:9B:F3:9D:5A:2E:BE:CA:B1:26:C6:11:00:D2:B6:EB:4B:4E:3C:D9:9F:38:AF:D5:1C:2E:D6:CB:84:F3:94:BF:97:4D:C1:FF:35:EA: 00:7C:D2:DA:21:E1:38:7D:B1:93:90:F5:2A:A5:F5:EA:E8:EE:B4:80:EB:53:30:8A:15:5B:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.1 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 28:27:13:47:63:D4:4F:71:D5:36:56:08:DF:CE:12:AB:14:C7:B0:0F Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 46 ETSI 2014 - TSL HR - PDF/A-1b generator QCStatements - crit. = false id_etsi_qcs_QcCompliance Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 7D:55:13:DA:0E:92:08:25:88:6B:5D:3C:F4:C3:81:96:A5:2C:99:41:03:3B:FD:13:07:E4:83:A3:40:B D:45:BA Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.10.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (19) I.CA - Time Stamping Authority, TSS/TSU 3, 12/2009 Name [ cs ] (19) I.CA - autorita časových razítek, TSS/TSU 3, 12/2009 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 3, 12/2009 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 47 ETSI 2014 - TSL HR - PDF/A-1b generator Subject C: CZ X509SKI X509 SK I KCcTR2PUT3HVNlYI384SqxTHsA8= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2009-12-21T00:00:00Z 158.11 - Service (withdrawn): (34) I.CA - Time Stamping Authority, TSS/TSU 1, 12/2011 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (34) I.CA - Time Stamping Authority, TSS/TSU 1, 12/2011 Name [ cs ] (34) I.CA - autorita časových razítek, TSS/TSU 1, 12/2011 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10685327 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 48 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGIjCCBQqgAwIBAgIEAKMLjzANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xMTEy MjEwMDAwMDBaFw0xNjEyMjEwMDAwMDBaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDEsIDEyLzIwMTExLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAMUqG0g6Eq4K04wfhbb6kHD0wcxFyO2x3Fv/tX2neJFX0K0ZGtaBX9Sv IOgiga86UOOSTT8BlcpfF5VZ+njXlv6+suimf8M5Kvd199+O9QA7My55Pfbaq8aDcs82ism8ze7c 4bI07iVULlRAzNl1bwE2ose1vaIqPGbCBmsqR5Z5tJo341d2FkFsg6W01paWrgpBCnamS23FTV9u ViAYQKV8CDa3AIFHzq3wTYtq6Dwb//MBLAfSlY2V9ykZsRbImZ1hSbI0oP8A+QSFbCEGqQLO4i8X Ijg5BSdNPh59TFuWWiPQuzzC10GX6qCaO4ZguMddKEd5Ci/6eZ9spqRF2zcCAwEAAaOCAjEwggIt MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDAjCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUvPd0KSCY02mVVxsZS+QOuG4+sNYwHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwOgYIKwYBBQUHAQEELjAs MCoGCCsGAQUFBzAChh5odHRwOi8vcS5pY2EuY3ovY2FfbmJ1c3IwOS5wN2MwDQYJKoZIhvcNAQEL BQADggEBAEf4uDT9qAWOEcLma46w9RDcdblvSKn16/lDgSXs0TcbIbNT8qT4Ob+t030D+zDbqgjG H1yLgkW2/2BwTitGgAAxkNbOKYljJhiYtMgIxKKySj5ACrxwN2/fC7RkvUajzc2MCmW1vmI6tbh3 1HWQlPcC/4GPTgq+JUwgFNgnVBSIdAcQ3l7VeXObQ9gNrENefoumAaJydXf4b3IVGvTsNRhsEf+l 3UZ5sUAxpQJXVsNNrKx4NLuqjXOwM33dcsGhYJIbWEkupXP469cFNv1oZ42nHvjF+MfX+a8YY3fE rl9yGzlyKXyImeukFpq9pn3Su3zWqqjDlkx0Emlidg8MOWM= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 1, 12/2011 Subject C: CZ Valid from: Wed Dec 21 01:00:00 CET 2011 Valid to: Wed Dec 21 01:00:00 CET 2016 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C5:2A:1B:48:3A:12:AE:0A:D3:8C:1F:85:B6:FA:90:70:F4:C1:CC:45:C8:ED:B1:DC:5B:FF:B5:7D:A7:78:91:57:D0:A D:19:1A:D6:81:5F:D4:AF:20:E8:22:81:AF:3A:50:E3:92:4D:3F:01:95:CA:5F:17:95:59:FA:78:D7:96:FE:BE:B2:E8:A6:7F:C3:39:2A:F7:75:F7:DF:8E:F5:00:3B:33:2E:79:3D:F6:DA:AB:C6:83:72:CF:36:8A:C9:BC:CD:EE:DC: E1:B2:34:EE:25:54:2E:54:40:CC:D9:75:6F:01:36:A2:C7:B5:BD:A2:2A:3C:66:C2:06:6B:2A:47:96:79:B4:9A:37:E3:57:76:16:41:6C:83:A5:B4:D6:96:96:AE:0A:41:0A:76:A6:4B:6D:C5:4D:5F:6E:56:20:18:40:A5:7C:08:36:B7 :00:81:47:CE:AD:F0:4D:8B:6A:E8:3C:1B:FF:F3:01:2C:07:D2:95:8D:95:F7:29:19:B1:16:C8:99:9D:61:49:B2:34:A0:FF:00:F9:04:85:6C:21:06:A9:02:CE:E2:2F:17:22:38:39:05:27:4D:3E:1E:7D:4C:5B:96:5A:23:D0:BB:3C:C2 :D7:41:97:EA:A0:9A:3B:86:60:B8:C7:5D:28:47:79:0A:2F:FA:79:9F:6C:A6:A4:45:DB:37:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.2 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier BC:F7:74:29:20:98:D3:69:95:57:1B:19:4B:E4:0E:B8:6E:3E:B0:D6 Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 49 ETSI 2014 - TSL HR - PDF/A-1b generator Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 2C:A5:ED:9F:16:6B:D8:E2:AD:3D:C9:43:17:AA:C1:FC:D3:2C:8F:49:CE:8A:95:72:A4:0D:F3:9D: 7F:2F:CF:E6 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.11.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (34) I.CA - Time Stamping Authority, TSS/TSU 1, 12/2011 Name [ cs ] (34) I.CA - autorita časových razítek, TSS/TSU 1, 12/2011 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 1, 12/2011 Subject C: CZ CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 50 ETSI 2014 - TSL HR - PDF/A-1b generator X509SKI X509 SK I vPd0KSCY02mVVxsZS+QOuG4+sNY= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-12-21T00:00:00Z 158.12 - Service (withdrawn): (35) I.CA - Time Stamping Authority, TSS/TSU 3, 12/2011 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (35) I.CA - Time Stamping Authority, TSS/TSU 3, 12/2011 Name [ cs ] (35) I.CA - autorita časových razítek, TSS/TSU 3, 12/2011 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10685329 X509 Certificate -----BEGIN CERTIFICATE----MIIGIjCCBQqgAwIBAgIEAKMLkTANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xMTEy MjEwMDAwMDBaFw0xNjEyMjEwMDAwMDBaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDMsIDEyLzIwMTExLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAPf5pmpZOP9eNH5Bj6X0XFztP/RHYn63MnR7/6lSJjYSaOfYBKgnIs37 N+2euamASGD/b4rXeO8pTMH2qPpeJVCeIZW8xfYZHj+BdSCRhQex417WuioXkwjvrGszHsvnEguT S4/ki0Te5O8BSA+NkYEVKarArDupd6lL8eD6TslYr8Vq1Qhl9/ChTboWO0u6SiU7y10QeV4ABXBA inbK5see7IwH28gbM/Ss7H/FE3tyOLJR4ISLuXiMm6Fti1qwLcdz9qP43VHtu7ViU4zqce8gHfu9 1ycmAgX0fKueViDybELJEi4nxQkk/ydNdmShfAULANAfWF6IgBZqERLPxjECAwEAAaOCAjEwggIt MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDAjCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUBfHCrjtYlv57DxyO7w1ZkLvCmuwwHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwOgYIKwYBBQUHAQEELjAs MCoGCCsGAQUFBzAChh5odHRwOi8vcS5pY2EuY3ovY2FfbmJ1c3IwOS5wN2MwDQYJKoZIhvcNAQEL BQADggEBAFB+JhaKGdIXvzdJ/ViXLp6OWFUMsdOHRrc4ir9RteLve5N2dfO120zWHrdjdXE25+Wr No61pziUDcjIbJ6Wdvj4d/t1qmCU8j7VA1OWmrGKrQQ6VNwqP7W8hi9T0byyypWUwAcNUSRCsazP eARvd2BniWYsryhkt3iUQTw6PsNVmUk2ZlYJbD7ClymP43LDpB0no2Lte5rbJ6TERHbAWYl1Av4/ dFJK88GVUyY1YaGrDzwgHN8pUNEfBqU2wzdgB5vMR3oCMhIK4jtRbWOWlaO8RsHMLpW2qJDvknE1 FtJAxW86qRCdVtdCnwhNirp0fXfDvDNhT9ZnF1QwJ12/ftg= -----END CERTIFICATE----- CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 51 ETSI 2014 - TSL HR - PDF/A-1b generator Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 3, 12/2011 Subject C: CZ Valid from: Wed Dec 21 01:00:00 CET 2011 Valid to: Wed Dec 21 01:00:00 CET 2016 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:F7:F9:A6:6A:59:38:FF:5E:34:7E:41:8F:A5:F4:5C:5C:ED:3F:F4:47:62:7E:B7:32:74:7B:FF:A9:52:26:36:12:68:E7:D8: 04:A8:27:22:CD:FB:37:ED:9E:B9:A9:80:48:60:FF:6F:8A:D7:78:EF:29:4C:C1:F6:A8:FA:5E:25:50:9E:21:95:BC:C5:F6:19:1E:3F:81:75:20:91:85:07:B1:E3:5E:D6:BA:2A:17:93:08:EF:AC:6B:33:1E:CB:E7:12:0B:93:4B:8F:E 4:8B:44:DE:E4:EF:01:48:0F:8D:91:81:15:29:AA:C0:AC:3B:A9:77:A9:4B:F1:E0:FA:4E:C9:58:AF:C5:6A:D5:08:65:F7:F0:A1:4D:BA:16:3B:4B:BA:4A:25:3B:CB:5D:10:79:5E:00:05:70:40:8A:76:CA:E6:C7:9E:EC:8C:07:D B:C8:1B:33:F4:AC:EC:7F:C5:13:7B:72:38:B2:51:E0:84:8B:B9:78:8C:9B:A1:6D:8B:5A:B0:2D:C7:73:F6:A3:F8:DD:51:ED:BB:B5:62:53:8C:EA:71:EF:20:1D:FB:BD:D7:27:26:02:05:F4:7C:AB:9E:56:20:F2:6C:42:C9:12:2E: 27:C5:09:24:FF:27:4D:76:64:A1:7C:05:0B:00:D0:1F:58:5E:88:80:16:6A:11:12:CF:C6:31:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.2 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 05:F1:C2:AE:3B:58:96:FE:7B:0F:1C:8E:EF:0D:59:90:BB:C2:9A:EC Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 65:D3:A1:6F:34:E0:5E:D6:14:13:36:D4:89:09:FE:36:D6:61:41:00:98:19:43:04:C7:62:BC:82:EC:C 0:1F:63 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 52 ETSI 2014 - TSL HR - PDF/A-1b generator Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.12.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (35) I.CA - Time Stamping Authority, TSS/TSU 3, 12/2011 Name [ cs ] (35) I.CA - autorita časových razítek, TSS/TSU 3, 12/2011 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 3, 12/2011 Subject C: CZ X509SKI X509 SK I BfHCrjtYlv57DxyO7w1ZkLvCmuw= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-12-21T00:00:00Z CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 53 ETSI 2014 - TSL HR - PDF/A-1b generator 158.13 - Service (withdrawn): (36) I.CA - Time Stamping Authority, TSS/TSU 2, 12/2011 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (36) I.CA - Time Stamping Authority, TSS/TSU 2, 12/2011 Name [ cs ] (36) I.CA - autorita časových razítek, TSS/TSU 2, 12/2011 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10685328 X509 Certificate -----BEGIN CERTIFICATE----MIIGIjCCBQqgAwIBAgIEAKMLkDANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xMTEy MjEwMDAwMDBaFw0xNjEyMjEwMDAwMDBaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDIsIDEyLzIwMTExLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAMTTMhpsmFpza0wMeN6tQY5O31b9IQNPlXb3MPV5ASoKOT/oJjyR/eWR Dy0z6siuMzcbQus3F3O6iv60+whKtTTGgxGo6sy53nh8KIZUzVlOTa+XOF0HyO6XCMs7tCVbQPCs EDeX8X6q+8WXVRd4WCEhXMPU/8WoqhPteOlNXIFJj/T+krfnfjDXGO/RMIS9R/GourFIgjvu4ctu 9G5bE5MPXENurbS/pa5Nu0ZHnjTONgi6hBJ4x+HfRPTuLoszWmNvsHchcROVOK6RvyQ3ukcUwE1f //eFURZnfpNa9O24w7cICF8iD6Fp9N6hsSye1+LVelWrzLnnNjia2s+d7IUCAwEAAaOCAjEwggIt MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDAjCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUn/DdvxuZhJbG5OlGeip4juwz2wIwHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwOgYIKwYBBQUHAQEELjAs MCoGCCsGAQUFBzAChh5odHRwOi8vcS5pY2EuY3ovY2FfbmJ1c3IwOS5wN2MwDQYJKoZIhvcNAQEL BQADggEBAKGx2/X1dIHrsv+YaFIU/13UoI/VUAbBjGSleL4mXzcpFqpBFtG0+ZkhGz/xsqngZ2Tw SAwn8QPJN7U9PK4kmzGf50GIiL3B+IaYd/EIQ3V8IpYcQsUrwYtj4ejJErtXiQcytlzD7y6DDiCS F6XDSYfwT3tkcQbu1lxKTcFq6mBEKt6vgCZC+SIji3iK4oWcnjRs3LmvAfa9S3RdLI6/ABXet2kC mfDho16cssUGE46ntUYC1nvH5K7u/xW/GQIS5NPqsYNKjLQQu/+bWP+gRDIHePZ0l1W0c5eXTdik ebcypoRPgzX9UcRdK+kKKIJ1gjtdY+E6Mtc4wtbVdqKWMf0= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 54 ETSI 2014 - TSL HR - PDF/A-1b generator Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 2, 12/2011 Subject C: CZ Valid from: Wed Dec 21 01:00:00 CET 2011 Valid to: Wed Dec 21 01:00:00 CET 2016 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C4:D3:32:1A:6C:98:5A:73:6B:4C:0C:78:DE:AD:41:8E:4E:DF:56:FD:21:03:4F:95:76:F7:30:F5:79:01:2A:0A:39:3F:E 8:26:3C:91:FD:E5:91:0F:2D:33:EA:C8:AE:33:37:1B:42:EB:37:17:73:BA:8A:FE:B4:FB:08:4A:B5:34:C6:83:11:A8:EA:CC:B9:DE:78:7C:28:86:54:CD:59:4E:4D:AF:97:38:5D:07:C8:EE:97:08:CB:3B:B4:25:5B:40:F0:AC:10: 37:97:F1:7E:AA:FB:C5:97:55:17:78:58:21:21:5C:C3:D4:FF:C5:A8:AA:13:ED:78:E9:4D:5C:81:49:8F:F4:FE:92:B7:E7:7E:30:D7:18:EF:D1:30:84:BD:47:F1:A8:BA:B1:48:82:3B:EE:E1:CB:6E:F4:6E:5B:13:93:0F:5C:43:6E: AD:B4:BF:A5:AE:4D:BB:46:47:9E:34:CE:36:08:BA:84:12:78:C7:E1:DF:44:F4:EE:2E:8B:33:5A:63:6F:B0:77:21:71:13:95:38:AE:91:BF:24:37:BA:47:14:C0:4D:5F:FF:F7:85:51:16:67:7E:93:5A:F4:ED:B8:C3:B7:08:08:5F:22 :0F:A1:69:F4:DE:A1:B1:2C:9E:D7:E2:D5:7A:55:AB:CC:B9:E7:36:38:9A:DA:CF:9D:EC:85:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.2 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 9F:F0:DD:BF:1B:99:84:96:C6:E4:E9:46:7A:2A:78:8E:EC:33:DB:02 Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 9F:B5:F3:19:FE:4B:7D:CD:BA:51:83:F7:9E:2B:12:5A:26:51:03:3D:9A:09:06:84:82:8B:4F:4F:F5: F8:3F:20 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 55 ETSI 2014 - TSL HR - PDF/A-1b generator [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.13.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (36) I.CA - Time Stamping Authority, TSS/TSU 2, 12/2011 Name [ cs ] (36) I.CA - autorita časových razítek, TSS/TSU 2, 12/2011 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 2, 12/2011 Subject C: CZ X509SKI X509 SK I n/DdvxuZhJbG5OlGeip4juwz2wI= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-12-21T00:00:00Z 158.14 - Service (withdrawn): (53) I.CA - Time Stamping Authority, TSS/TSU 1, 11/2013 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 56 ETSI 2014 - TSL HR - PDF/A-1b generator [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (53) I.CA - Time Stamping Authority, TSS/TSU 1, 11/2013 Name [ cs ] (53) I.CA - autorita časových razítek, TSS/TSU 1, 11/2013 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10869991 X509 Certificate -----BEGIN CERTIFICATE----MIIGIjCCBQqgAwIBAgIEAKXc5zANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xMzEx MDYwNzQyNDVaFw0xODExMDYwNzQyNDVaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDEsIDExLzIwMTMxLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAK1lVOCVu47By5BiOGzsG0XbJ55WvySjm2ZjoZPczK9EMo/XZct2A/Lq wTAToTtYhTO3EuHccQdZYR8L+Z6AABkmu8cy72TO+nALzgGOZkFIN5UlLzU3XHaq6MpeOGjeDtnp mpMHndG7mND1TqsGhsjqdAPei+/qptutBLOHFnNO9sjkt+T1yAqqBFdIG2n7QcVs7JMak01QSV5M qN3RNwYEuA7aTZckkhwhHFBOcqTiqjcfr7Z8+hfv4TlAJAIp/2dqgxOdkeMhRxCz50Fwx6PZg5xQ EvxhPUJJFf7FmlidT1Jkl6oB4cyV2eewALZ8AdgxbWaRyc865Yw3jVisuT8CAwEAAaOCAjEwggIt MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDAjCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQULjPA/zl0PC/HYE1viXET51w4WHowHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwOgYIKwYBBQUHAQEELjAs MCoGCCsGAQUFBzAChh5odHRwOi8vcS5pY2EuY3ovY2FfbmJ1c3IwOS5wN2MwDQYJKoZIhvcNAQEL BQADggEBAFMb2479AC6sTzm/PuSef53g+mfP1uKVh74dwsT3zM/FP9IdP8+O+3leWcRjf1cxqadj 9iHjXwem6RIsJCn8COaGupizTkkcLTs7kahPJJkO1T0YAjcV97go/ult27OFo+xkxOo52Nccx4f8 yFp1jng7E+E7SnMHHgcLY34tZlazPlLMq3dWnwVoSu2xY4/i/02cbi8Fk+eOXU39eUPK+/x0SBZ1 bvSS5qUTWzwDCSwEew9zhc/DFSPeb/p59s/1L2xM6ejZ6Df/nZrBd5k2Z0h6kHEx4fAPe8SbRBi9 8JZQCGG5jkS2eVQLOLKxy/5SfYbhDJWMxlAMvvUVqy9hcEs= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 1, 11/2013 Subject C: CZ CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 57 ETSI 2014 - TSL HR - PDF/A-1b generator Valid from: Wed Nov 06 08:42:45 CET 2013 Valid to: Tue Nov 06 08:42:45 CET 2018 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:AD:65:54:E0:95:BB:8E:C1:CB:90:62:38:6C:EC:1B:45:DB:27:9E:56:BF:24:A3:9B:66:63:A1:93:DC:CC:AF:44:32:8F: D7:65:CB:76:03:F2:EA:C1:30:13:A1:3B:58:85:33:B7:12:E1:DC:71:07:59:61:1F:0B:F9:9E:80:00:19:26:BB:C7:32:EF:64:CE:FA:70:0B:CE:01:8E:66:41:48:37:95:25:2F:35:37:5C:76:AA:E8:CA:5E:38:68:DE:0E:D9:E9:9A:93: 07:9D:D1:BB:98:D0:F5:4E:AB:06:86:C8:EA:74:03:DE:8B:EF:EA:A6:DB:AD:04:B3:87:16:73:4E:F6:C8:E4:B7:E4:F5:C8:0A:AA:04:57:48:1B:69:FB:41:C5:6C:EC:93:1A:93:4D:50:49:5E:4C:A8:DD:D1:37:06:04:B8:0E:DA: 4D:97:24:92:1C:21:1C:50:4E:72:A4:E2:AA:37:1F:AF:B6:7C:FA:17:EF:E1:39:40:24:02:29:FF:67:6A:83:13:9D:91:E3:21:47:10:B3:E7:41:70:C7:A3:D9:83:9C:50:12:FC:61:3D:42:49:15:FE:C5:9A:58:9D:4F:52:64:97:AA:01:E 1:CC:95:D9:E7:B0:00:B6:7C:01:D8:31:6D:66:91:C9:CF:3A:E5:8C:37:8D:58:AC:B9:3F:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.2 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 2E:33:C0:FF:39:74:3C:2F:C7:60:4D:6F:89:71:13:E7:5C:38:58:7A Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 6A:63:0D:5C:F0:78:8C:D3:A6:C0:50:AD:01:F3:9A:CA:E6:E9:DD:D3:C1:50:01:7F:2D:7F:C4:B0: 1D:F7:6A:09 Service Status Service status description Status Starting Time http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. 2016-07-01T00:00:00Z CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 58 ETSI 2014 - TSL HR - PDF/A-1b generator 158.14.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (53) I.CA - Time Stamping Authority, TSS/TSU 1, 11/2013 Name [ cs ] (53) I.CA - autorita časových razítek, TSS/TSU 1, 11/2013 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 1, 11/2013 Subject C: CZ X509SKI X509 SK I LjPA/zl0PC/HYE1viXET51w4WHo= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-11-06T06:42:00Z 158.15 - Service (withdrawn): (54) I.CA - Time Stamping Authority, TSS/TSU 2, 11/2013 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 59 ETSI 2014 - TSL HR - PDF/A-1b generator Service Name Name [ en ] (54) I.CA - Time Stamping Authority, TSS/TSU 2, 11/2013 Name [ cs ] (54) I.CA - autorita časových razítek, TSS/TSU 2, 11/2013 Service digital identities Certificate fields details Version: 3 Serial Number: 10869992 X509 Certificate -----BEGIN CERTIFICATE----MIIGIjCCBQqgAwIBAgIEAKXc6DANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xMzEx MDYwNzQzMzJaFw0xODExMDYwNzQzMzJaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDIsIDExLzIwMTMxLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAMt29xvkQdYtkiCOmSBB6jDK7Qe+c4BJlKB+KY6Yl2oBrzeYDjSXo3Ki fGuQajrT/naJmgN7iLo2xDarzik9fKytMXbC1NrbQ1QpaO7Wsusjk/dDyM68F/ob1d//hfnvs9cr 8dvxwucE3A7cwq+4mWNlKhU1imBtoxCxxbVoVBHzCK398wDrpo6IUNylSj2vKHb9XUQ/YMxnnwhM pIUDuje01Cmho2+xAkHXX8zOYSSizZhgufzDs36ugRbmYaI+vtVMNltYHZyV7SX0rsvY0uLEyAGF iJRxYTFMSUqTa1LNFWj/YUCucsyazjpA4iuaO7AlFqE78bewQ62rml0hWzkCAwEAAaOCAjEwggIt MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDAjCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUO+l6ZoaREq6zXhZGihkdmeXv4WowHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwOgYIKwYBBQUHAQEELjAs MCoGCCsGAQUFBzAChh5odHRwOi8vcS5pY2EuY3ovY2FfbmJ1c3IwOS5wN2MwDQYJKoZIhvcNAQEL BQADggEBAIWWcZJqP6L/aJJKgyzo5gXNAw7xhoDry2DIgS9nrnh1S/R7TkoPVC5316tSIvB7Zqln c23HGMLUDqB5JSVUBG458fiIgi9NVlwRALavtznXjzrsx1S8rk+AdBd07AqgQTOW1DC9zSvSb0Pb AYs9ULIh5DQb7virky9PKjTnIgWL4w7aIrhQCTcyF8jR550kB3oDB05zDVTXXcbto/JTBznOAnXp 4ncK0/uRh10u9HdDxLtIiNYUxBRrI7MKykiLtvGg/ICssnJ7GlIWzdbIOyt6ZB+Ea4UdFa8za3QP +UT3uxrjxWAPjcRVc2+8e7FZQQSRPBRrDV1WP6zHBAYYBiM= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 2, 11/2013 Subject C: CZ Valid from: Wed Nov 06 08:43:32 CET 2013 Valid to: Tue Nov 06 08:43:32 CET 2018 Public Key: Extended Key Usage 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:CB:76:F7:1B:E4:41:D6:2D:92:20:8E:99:20:41:EA:30:CA:ED:07:BE:73:80:49:94:A0:7E:29:8E:98:97:6A:01:AF:37:98 :0E:34:97:A3:72:A2:7C:6B:90:6A:3A:D3:FE:76:89:9A:03:7B:88:BA:36:C4:36:AB:CE:29:3D:7C:AC:AD:31:76:C2:D4:DA:DB:43:54:29:68:EE:D6:B2:EB:23:93:F7:43:C8:CE:BC:17:FA:1B:D5:DF:FF:85:F9:EF:B3:D7:2B:F1 :DB:F1:C2:E7:04:DC:0E:DC:C2:AF:B8:99:63:65:2A:15:35:8A:60:6D:A3:10:B1:C5:B5:68:54:11:F3:08:AD:FD:F3:00:EB:A6:8E:88:50:DC:A5:4A:3D:AF:28:76:FD:5D:44:3F:60:CC:67:9F:08:4C:A4:85:03:BA:37:B4:D4:29: A1:A3:6F:B1:02:41:D7:5F:CC:CE:61:24:A2:CD:98:60:B9:FC:C3:B3:7E:AE:81:16:E6:61:A2:3E:BE:D5:4C:36:5B:58:1D:9C:95:ED:25:F4:AE:CB:D8:D2:E2:C4:C8:01:85:88:94:71:61:31:4C:49:4A:93:6B:52:CD:15:68:FF:61: 40:AE:72:CC:9A:CE:3A:40:E2:2B:9A:3B:B0:25:16:A1:3B:F1:B7:B0:43:AD:AB:9A:5D:21:5B:39:02:03:01:00:01 id_kp_timeStamping CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 60 ETSI 2014 - TSL HR - PDF/A-1b generator Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.2 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 3B:E9:7A:66:86:91:12:AE:B3:5E:16:46:8A:19:1D:99:E5:EF:E1:6A Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 44:9C:F7:B1:76:92:A6:08:93:C1:4D:25:EA:16:13:BF:2F:B9:C0:13:BD:2F:0C:4A:64:14:3E:EA:79: 4A:1D:0A Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.15.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (54) I.CA - Time Stamping Authority, TSS/TSU 2, 11/2013 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 61 ETSI 2014 - TSL HR - PDF/A-1b generator Name [ cs ] (54) I.CA - autorita časových razítek, TSS/TSU 2, 11/2013 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 2, 11/2013 Subject C: CZ X509SKI X509 SK I O+l6ZoaREq6zXhZGihkdmeXv4Wo= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-11-06T06:43:00Z 158.16 - Service (withdrawn): (55) I.CA - Time Stamping Authority, TSS/TSU 3, 11/2013 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (55) I.CA - Time Stamping Authority, TSS/TSU 3, 11/2013 Name [ cs ] (55) I.CA - autorita časových razítek, TSS/TSU 3, 11/2013 Service Name Service digital identities Certificate fields details CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 62 ETSI 2014 - TSL HR - PDF/A-1b generator Version: 3 Serial Number: 10869993 X509 Certificate -----BEGIN CERTIFICATE----MIIGIjCCBQqgAwIBAgIEAKXc6TANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xMzEx MDYwNzQ0MTdaFw0xODExMDYwNzQ0MTdaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDMsIDExLzIwMTMxLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAM5yjHh4flC1OhCCsiVd4f8siLVxe+H3lVvp7x17NszXd5ZH3mbfaIcD GUwoEm2yga7Rh24UKV+ZUqM7oDCWfoDkN8fB4UxTfTszPdFv372XnHLTaKkqsPA5QV/Kr6bCCq3K LDLZpZGzhDqCxhShzAdtrA20ZjNEUhfNpr3z2Dhvl+xcnsgBc2wz/jz7nom9VoLPVV13NzeTZ6Cz QtnEk11S3FsB5u749OQrJNt28abJtwdYwkPDvZPHsD7a6tUaqnFjS5whtzM8M6b3xGQQH+tXxdfO WdV78Khwiu/ZYqaoMGTkAApBXO8kq2V8Ku/hWZEQ0oiM9Z7FRTbTw8J1Fn8CAwEAAaOCAjEwggIt MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDAjCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUDuDHElXcE+Fl5Yt69OccL9r1hBIwHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwOgYIKwYBBQUHAQEELjAs MCoGCCsGAQUFBzAChh5odHRwOi8vcS5pY2EuY3ovY2FfbmJ1c3IwOS5wN2MwDQYJKoZIhvcNAQEL BQADggEBAGbPZIUGlJo3hpH6D01jUExXUgzXOugmkXzhfJYD2VoRknuVD/2nEmRnM3L6fpNkUKuz jn9Pq4qGs2zTeHy1GJDIOXdHwv+7svWUaVOFryN5qIaP6zB4sFmrwJbQLffNGODPVsMExyuw7Bo+ gPfyWrsPkEgtr6tr1Mix5KitBfvLf1gY6HaN+fguB7xuJgJbORfN6B08pylPPxgzYRuRKD29XdRz py6qVjydioF9kwgW2jfXHjA7EA/9snIwK66mfYwOnTCCdzAriqL5weEeNSqArAzORx5QuDq5aREl 7Un803WLQvOTD6hYRnOfk/sdr8TOjCibTJv8Qd7y4bq0AQA= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 3, 11/2013 Subject C: CZ Valid from: Wed Nov 06 08:44:17 CET 2013 Valid to: Tue Nov 06 08:44:17 CET 2018 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:CE:72:8C:78:78:7E:50:B5:3A:10:82:B2:25:5D:E1:FF:2C:88:B5:71:7B:E1:F7:95:5B:E9:EF:1D:7B:36:CC:D7:77:96:4 7:DE:66:DF:68:87:03:19:4C:28:12:6D:B2:81:AE:D1:87:6E:14:29:5F:99:52:A3:3B:A0:30:96:7E:80:E4:37:C7:C1:E1:4C:53:7D:3B:33:3D:D1:6F:DF:BD:97:9C:72:D3:68:A9:2A:B0:F0:39:41:5F:CA:AF:A6:C2:0A:AD:CA:2C: 32:D9:A5:91:B3:84:3A:82:C6:14:A1:CC:07:6D:AC:0D:B4:66:33:44:52:17:CD:A6:BD:F3:D8:38:6F:97:EC:5C:9E:C8:01:73:6C:33:FE:3C:FB:9E:89:BD:56:82:CF:55:5D:77:37:37:93:67:A0:B3:42:D9:C4:93:5D:52:DC:5B:01: E6:EE:F8:F4:E4:2B:24:DB:76:F1:A6:C9:B7:07:58:C2:43:C3:BD:93:C7:B0:3E:DA:EA:D5:1A:AA:71:63:4B:9C:21:B7:33:3C:33:A6:F7:C4:64:10:1F:EB:57:C5:D7:CE:59:D5:7B:F0:A8:70:8A:EF:D9:62:A6:A8:30:64:E4:00:0 A:41:5C:EF:24:AB:65:7C:2A:EF:E1:59:91:10:D2:88:8C:F5:9E:C5:45:36:D3:C3:C2:75:16:7F:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.2 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 0E:E0:C7:12:55:DC:13:E1:65:E5:8B:7A:F4:E7:1C:2F:DA:F5:84:12 Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 63 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 57:8A:39:4E:88:54:5E:EC:16:33:74:2D:91:DE:A4:7A:07:22:32:D0:9F:5C:03:A2:33:35:97:51:55:11 :0C:AF Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.16.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (55) I.CA - Time Stamping Authority, TSS/TSU 3, 11/2013 Name [ cs ] (55) I.CA - autorita časových razítek, TSS/TSU 3, 11/2013 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 64 ETSI 2014 - TSL HR - PDF/A-1b generator Subject CN: I.CA - Time Stamping Authority, TSS/TSU 3, 11/2013 Subject C: CZ X509SKI X509 SK I DuDHElXcE+Fl5Yt69OccL9r1hBI= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-11-06T06:44:00Z 158.17 - Service (withdrawn): (56) I.CA - Time Stamping Authority, TSS/TSU 4, 11/2013 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (56) I.CA - Time Stamping Authority, TSS/TSU 4, 11/2013 Name [ cs ] (56) I.CA - autorita časových razítek, TSS/TSU 4, 11/2013 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 10869994 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 65 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGIjCCBQqgAwIBAgIEAKXc6jANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xMzEx MDYwNzQ1MDBaFw0xODExMDYwNzQ1MDBaMIG4MQswCQYDVQQGEwJDWjE7MDkGA1UEAwwySS5DQSAt IFRpbWUgU3RhbXBpbmcgQXV0aG9yaXR5LCBUU1MvVFNVIDQsIDExLzIwMTMxLTArBgNVBAoMJFBy dm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5DQSAtIEFjY3Jl ZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBAI4wGFZM+q2lvc9ZhhU2EXrzbiR4fZRakwYuubYG4kkN4mwIP8TlKaUG aClAbMCeKRE8PrQBjd9jaT4NJVbEMpIvGpp4Yh48Oml1L4yuO2gmYgCkyGsSphkyjGmMYdG+sU2H +YsjsLIF/MIpJDGkl62VEaMXIr6n2+KEh8JErfp25pEQuwwndzPWeWtxqrRM0LMvBGphYj8Cxvpy 5JOFJ56R1CIYW8trcv6hXVODpdcFEuoZrngVVyHCV6NOsslrivygPmKycMryT3wxGcH5ZI3y2Mpe cJqQMAT0+Aqb8zbWUq90NQT8hcKlfHntwcbJ1uNkiyYgbT49ipJpkj4HuuUCAwEAAaOCAjEwggIt MA4GA1UdDwEB/wQEAwIGwDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDCCAQEGA1UdIASB+TCB9jCB 4gYNKwYBBAGBuEgBAQoDAjCB0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGpl IHZ5ZGFuIGpha28ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBwb2RsZSB6YWtv bmEgYy4gMjI3LzIwMDAgU2IuIHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0 ZW0gY2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAgQ29sbC4w DwYNK4EekZmEBQAAAAECAjAdBgNVHQ4EFgQUS7pGq6+wldn3+jg2T2WB96FHbJgwHwYDVR0jBBgw FoAUecvQI+k6Z3CRdE/TUeLgIP3hKPswgYEGA1UdHwR6MHgwJqAkoCKGIGh0dHA6Ly9xY3JsZHAx LmljYS5jei9xaWNhMDkuY3JsMCagJKAihiBodHRwOi8vcWNybGRwMi5pY2EuY3ovcWljYTA5LmNy bDAmoCSgIoYgaHR0cDovL3FjcmxkcDMuaWNhLmN6L3FpY2EwOS5jcmwwOgYIKwYBBQUHAQEELjAs MCoGCCsGAQUFBzAChh5odHRwOi8vcS5pY2EuY3ovY2FfbmJ1c3IwOS5wN2MwDQYJKoZIhvcNAQEL BQADggEBAFuCYmHto6fQrhO82PH1fwMx9bmthqp7j7XHV2qk7LrRIgqTTwY82qpykvsypxfzw3KU u/06AN0C5SrhWQMUPyn4LhcCmZt4Uw8TGbOQfqhYgkrZVyXFy6GsGW2/q75LQOMqYh2GWPEbjNBt gjeadVHVJIUpYaWlynEMMZNHQAx6cx5KFLqt3Pz7WbgeDJjV93/VxwtWbD0aukE7v/wcQ2Hy7HqU F5vhZ5b61aA9D8yg2zWGXbcFihfxY+avsgytwE30kEyYtMckaJwiO5EkpzVnKyewXwkY6ix/FCgD oCDkYB1ziK5vD8i/2qdd7QZouX+/KwrALGoUpyNUTmWCVww= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 4, 11/2013 Subject C: CZ Valid from: Wed Nov 06 08:45:00 CET 2013 Valid to: Tue Nov 06 08:45:00 CET 2018 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:8E:30:18:56:4C:FA:AD:A5:BD:CF:59:86:15:36:11:7A:F3:6E:24:78:7D:94:5A:93:06:2E:B9:B6:06:E2:49:0D:E2:6C:0 8:3F:C4:E5:29:A5:06:68:29:40:6C:C0:9E:29:11:3C:3E:B4:01:8D:DF:63:69:3E:0D:25:56:C4:32:92:2F:1A:9A:78:62:1E:3C:3A:69:75:2F:8C:AE:3B:68:26:62:00:A4:C8:6B:12:A6:19:32:8C:69:8C:61:D1:BE:B1:4D:87:F9:8B:2 3:B0:B2:05:FC:C2:29:24:31:A4:97:AD:95:11:A3:17:22:BE:A7:DB:E2:84:87:C2:44:AD:FA:76:E6:91:10:BB:0C:27:77:33:D6:79:6B:71:AA:B4:4C:D0:B3:2F:04:6A:61:62:3F:02:C6:FA:72:E4:93:85:27:9E:91:D4:22:18:5B:CB :6B:72:FE:A1:5D:53:83:A5:D7:05:12:EA:19:AE:78:15:57:21:C2:57:A3:4E:B2:C9:6B:8A:FC:A0:3E:62:B2:70:CA:F2:4F:7C:31:19:C1:F9:64:8D:F2:D8:CA:5E:70:9A:90:30:04:F4:F8:0A:9B:F3:36:D6:52:AF:74:35:04:FC:85: C2:A5:7C:79:ED:C1:C6:C9:D6:E3:64:8B:26:20:6D:3E:3D:8A:92:69:92:3E:07:BA:E5:02:03:01:00:01 Extended Key Usage id_kp_timeStamping Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.10.3.2 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/This is qualified system certificate according to Czech Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 Subject Key Identifier 4B:BA:46:AB:AF:B0:95:D9:F7:FA:38:36:4F:65:81:F7:A1:47:6C:98 Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 66 ETSI 2014 - TSL HR - PDF/A-1b generator Authority Info Access http://q.ica.cz/ca_nbusr09.p7c Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 64:0F:E0:4F:A8:D9:5D:F1:3C:64:34:0E:89:A6:B2:3B:6E:D8:D0:4D:33:18:E3:85:23:59:CE:89:35:8 6:4D:20 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.17.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (56) I.CA - Time Stamping Authority, TSS/TSU 4, 11/2013 Name [ cs ] (56) I.CA - autorita časových razítek, TSS/TSU 4, 11/2013 Service digital identities X509SubjectName Subject OU: I.CA - Accredited Provider of Certification Services Subject O: První certifikační autorita, a.s. Subject CN: I.CA - Time Stamping Authority, TSS/TSU 4, 11/2013 Subject C: CZ CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 67 ETSI 2014 - TSL HR - PDF/A-1b generator X509SKI X509 SK I S7pGq6+wldn3+jg2T2WB96FHbJg= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-11-06T06:45:00Z 158.18 - Service (withdrawn): (77) I.CA Time Stamping Authority TSS/TSU 4 12/2015 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (77) I.CA Time Stamping Authority TSS/TSU 4 12/2015 Name [ cs ] (77) I.CA - autorita časových razítek TSS/TSU 4 12/2015 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 11083035 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 68 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGwTCCBKmgAwIBAgIEAKkdGzANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJDWjEmMCQGA1UE AwwdSS5DQSBRdWFsaWZpZWQgQ0EvUlNBIDA3LzIwMTUxLTArBgNVBAoMJFBydm7DrSBjZXJ0aWZp a2HEjW7DrSBhdXRvcml0YSwgYS5zLjEXMBUGA1UEBRMOTlRSQ1otMjY0MzkzOTUwHhcNMTUxMjA4 MTMxOTU4WhcNMjIwMTE1MTMxOTU4WjCBjjELMAkGA1UEBhMCQ1oxNzA1BgNVBAMMLkkuQ0EgVGlt ZSBTdGFtcGluZyBBdXRob3JpdHkgVFNTL1RTVSA0IDEyLzIwMTUxLTArBgNVBAoMJFBydm7DrSBj ZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjEXMBUGA1UEBRMOTlRSQ1otMjY0MzkzOTUwggEi MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCzGCdX3FkEzc3QAbjAucSs0H9J2DFUacR9iCIs eGy+y44rJnHgKyj837hZHg9pTrlfYDVRVvjkeKSSVI1WhbWHGLKgR+Y9M8y2r77a9Evoo7kEhUUB FE/cTAPhdtQizwIMAMLaZE26etteKgSDlimMKwtJgrS090p8YynF3nUOQSVjjhkuoVoVkyzQKBoF UGOM3r5WenH+TbsZBxoDC+N3jfv5yavNfaz202nazmk8aUXSyLJMUGAjVd5ymG1HPVYznrT5k1n8 /tQ1Rgn2Y3itEBbzdUdJpo6eSTJABDpbZaQcIuSn7ea+COlDkKOCLc+qK3YdW5ccYkxrAy225bP9 AgMBAAGjggI1MIICMTAJBgNVHRMEAjAAMIHxBgNVHSAEgekwgeYwgdIGDSsGAQQBgbhICgEgAQEw gcAwgb0GCCsGAQUFBwICMIGwGoGtVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlm aWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwIFNiLiB2IHBsYXRuZW0gem5lbmkv VGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5nIHRv IEFjdCBOby4gMjI3LzIwMDAgQ29sbC4wDwYNK4EekZmEBQAAAAECAjCBjAYDVR0fBIGEMIGBMCmg J6AlhiNodHRwOi8vcWNybGRwMS5pY2EuY3ovcWNhMTVfcnNhLmNybDApoCegJYYjaHR0cDovL3Fj cmxkcDIuaWNhLmN6L3FjYTE1X3JzYS5jcmwwKaAnoCWGI2h0dHA6Ly9xY3JsZHAzLmljYS5jei9x Y2ExNV9yc2EuY3JsMDkGCCsGAQUFBwEBBC0wKzApBggrBgEFBQcwAoYdaHR0cDovL3EuaWNhLmN6 L3FjYTE1X3JzYS5wN2MwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMB8G A1UdIwQYMBaAFGyBJ1kz4qKaIRiLKRS8OG3Uc3k9MB0GA1UdDgQWBBSgZ4s6gYIr+JYa8YJ/0sst 6LJHUjANBgkqhkiG9w0BAQsFAAOCAgEAVmiy6lHlpSF27uv+zGyKiA5k2ovOfkLf5L/858dOMtQ9 mqN7B89wr1YC/0tgUluqXOyNQ6uUtPk+e996FW42XWqfP3xw7ECN6oWO1AnNUd6kcFF/0KHDA/qU G6sUuK2p1I5DaEFWo4jhRCbKhDNMMBR5WQbECjTbMEchSdxfqChrA2xHMe9vBvZ1D+uVLgsh82YF IcZbEAcCxi6Edaveh/rr0Ru6F1N0mmDb4gYYiB8NplyMRMjhcTLiNBvmdvdt+9YpeRBviIgOPj25 ymZbcnKIrOYo3JAkREPlScqIi4W34n7SjywBXn6OI4Zu5Xpr84+xoamgwNXtE4XZ770nCa/OYTH9 iXriZGEQMRrPr64aZ45HFmkEE261JFXS9S+FOS3ejLWaLJoCFYE7D/yhCcxwQJ5Tr6wcDnL6jC5O 1BCfLTiJFZE3j+PTiW8bQ+34dghNLU24tjQVzRLLHDVLsTcUztcH8xSrA6UAAGxoJM5cLz7yc0gX jOwDuOXs84IUvxpAXR09D2CIAYkJTILRtIcT+fs5O+moYhME7DsfreGspVCzUVQoHLtAE1X0QK8t 0XfpPDHUGy+roGPLBrkIzjdEu6+IY/mExiFAuMHw1XqNeKjJLuO/EnLyv5bdWVGmMkTIfUuaC2si TBGTbgl2VxLtxOGvSOcBIJBEaQw+cjg= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer SERIAL NUMBER: NTRCZ-26439395 Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA Qualified CA/RSA 07/2015 Issuer C: CZ Subject SERIAL NUMBER: NTRCZ-26439395 Subject O: První certifikační autorita, a.s. Subject CN: I.CA Time Stamping Authority TSS/TSU 4 12/2015 Subject C: CZ Valid from: Tue Dec 08 14:19:58 CET 2015 Valid to: Sat Jan 15 14:19:58 CET 2022 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B3:18:27:57:DC:59:04:CD:CD:D0:01:B8:C0:B9:C4:AC:D0:7F:49:D8:31:54:69:C4:7D:88:22:2C:78:6C:BE:CB:8E:2B :26:71:E0:2B:28:FC:DF:B8:59:1E:0F:69:4E:B9:5F:60:35:51:56:F8:E4:78:A4:92:54:8D:56:85:B5:87:18:B2:A0:47:E6:3D:33:CC:B6:AF:BE:DA:F4:4B:E8:A3:B9:04:85:45:01:14:4F:DC:4C:03:E1:76:D4:22:CF:02:0C:00:C2:D A:64:4D:BA:7A:DB:5E:2A:04:83:96:29:8C:2B:0B:49:82:B4:B4:F7:4A:7C:63:29:C5:DE:75:0E:41:25:63:8E:19:2E:A1:5A:15:93:2C:D0:28:1A:05:50:63:8C:DE:BE:56:7A:71:FE:4D:BB:19:07:1A:03:0B:E3:77:8D:FB:F9:C9:A B:CD:7D:AC:F6:D3:69:DA:CE:69:3C:69:45:D2:C8:B2:4C:50:60:23:55:DE:72:98:6D:47:3D:56:33:9E:B4:F9:93:59:FC:FE:D4:35:46:09:F6:63:78:AD:10:16:F3:75:47:49:A6:8E:9E:49:32:40:04:3A:5B:65:A4:1C:22:E4:A7:ED: E6:BE:08:E9:43:90:A3:82:2D:CF:AA:2B:76:1D:5B:97:1C:62:4C:6B:03:2D:B6:E5:B3:FD:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 1.3.6.1.4.1.23624.10.1.32.1.1 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000 Sb. v platnem zneni/This qualified system certificate was issued according to Act No. 227/2000 Coll.] Policy OID: 1.3.158.36061701.0.0.0.1.2.2 CRL Distribution Points http://qcrldp1.ica.cz/qca15_rsa.crl http://qcrldp2.ica.cz/qca15_rsa.crl http://qcrldp3.ica.cz/qca15_rsa.crl Authority Info Access http://q.ica.cz/qca15_rsa.p7c Extended Key Usage id_kp_timeStamping CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 69 ETSI 2014 - TSL HR - PDF/A-1b generator Authority Key Identifier 6C:81:27:59:33:E2:A2:9A:21:18:8B:29:14:BC:38:6D:D4:73:79:3D Subject Key Identifier A0:67:8B:3A:81:82:2B:F8:96:1A:F1:82:7F:D2:CB:2D:E8:B2:47:52 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: AE:A7:B3:C1:87:FC:BD:C0:1D:E4:AE:35:BE:62:B6:CD:15:B6:2D:84:BA:00:CD:72:58:AB:10:D9 :1B:1B:1F:B0 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.18.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (77) I.CA Time Stamping Authority TSS/TSU 4 12/2015 Name [ cs ] (77) I.CA - autorita časových razítek TSS/TSU 4 12/2015 Service digital identities X509SubjectName Subject SERIAL NUMBER: NTRCZ-26439395 Subject O: První certifikační autorita, a.s. Subject CN: I.CA Time Stamping Authority TSS/TSU 4 12/2015 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 70 ETSI 2014 - TSL HR - PDF/A-1b generator Subject C: CZ X509SKI X509 SK I oGeLOoGCK/iWGvGCf9LLLeiyR1I= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2016-01-25T13:15:00Z 158.19 - Service (granted): (78) I.CA - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (78) I.CA - issuing qualified certificates Name [ cs ] (78) I.CA - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 100001006 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 71 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIHpTCCBY2gAwIBAgIEBfXk7jANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJDWjEtMCsGA1UE CgwkUHJ2bsOtIGNlcnRpZmlrYcSNbsOtIGF1dG9yaXRhLCBhLnMuMRkwFwYDVQQDDBBJLkNBIFJv b3QgQ0EvUlNBMRcwFQYDVQQFEw5OVFJDWi0yNjQzOTM5NTAeFw0xNjAyMTExMjE3MTFaFw0yNjAy MDgxMjE3MTFaMH8xCzAJBgNVBAYTAkNaMSgwJgYDVQQDDB9JLkNBIFF1YWxpZmllZCAyIENBL1JT QSAwMi8yMDE2MS0wKwYDVQQKDCRQcnZuw60gY2VydGlmaWthxI1uw60gYXV0b3JpdGEsIGEucy4x FzAVBgNVBAUTDk5UUkNaLTI2NDM5Mzk1MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA yMALHP/YeXEtOEHHJXTrhOrZWZ5SeX3f8phlvUiCIxoJt2yZ4CI2Y26tSuD+Ard7c539buJlzoZn uFs6xswvSVJwpwoKF3pflZ5DZjyqUhPpDZdEXQyne1U9uo1T9wD1WWKQ/yONzKcawxfH2tr0ourI LIjVtB6I99u5uA7flA/mynGucR1C4PC9WbY4MrRV+YkSAzWb88K1wyhVZ0Tq50+jINrL8xCGzRNL SPbMw9lBsWNPfcom2ajPbmIfyaf3uMBGNdNxUjQoiBjC0mYWkrEd95K6S0dkOA8KgelI/3Kyut/k xc1RsLXgIo0DNSQ9F38q2I8KWpmxm2sOAHBR191fNEwhnfomCi1jjx6nHpIhHR1Vs5KcjL6z8Qr4 2otM55qtEBhOnM1juPZs5+GYjpHG08e9cATWBC3GLd59hN6uSdZjNSb6LVg0hB194Jb29WpaNj0w zEx98zR1W4NQy+EXSaBfj8bb7UZrxtSoJzF2YMNAPb/oYlRVNuP4tmnUsW3m6r09j7cltBXCo/Yf XDRX0rWNlJ7p+gDRHU1+nPlih6LWgyI/yrhJqGg4dg63YyywvuuoDI0zfjlhBSkqQymNwNelg1mD cEFUVxk8LKzXPXJlFNEt33+qT+CMXlR+IkUC0jOI1SZV3uwcAwgbQWazNljKFpoJjGXc4fwh2A8C AwEAAaOCAjYwggIyMIHXBgNVHSAEgc8wgcwwgckGBFUdIAAwgcAwgb0GCCsGAQUFBwICMIGwGoGt VGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUg emFrb25hIDIyNy8yMDAwIFNiLiB2IHBsYXRuZW0gem5lbmkvVGhpcyBxdWFsaWZpZWQgc3lzdGVt IGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5nIHRvIEFjdCBOby4gMjI3LzIwMDAgQ29s bC4wEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFHSCCJHj2WRo cYXW6zHkct+LJrFtMB8GA1UdIwQYMBaAFHa5A0j71RihoTeg7cxogkxSNDYNMIGMBgNVHR8EgYQw gYEwKaAnoCWGI2h0dHA6Ly9xY3JsZHAxLmljYS5jei9yY2ExNV9yc2EuY3JsMCmgJ6AlhiNodHRw Oi8vcWNybGRwMi5pY2EuY3ovcmNhMTVfcnNhLmNybDApoCegJYYjaHR0cDovL3FjcmxkcDMuaWNh LmN6L3JjYTE1X3JzYS5jcmwwYwYIKwYBBQUHAQEEVzBVMCkGCCsGAQUFBzAChh1odHRwOi8vci5p Y2EuY3ovcmNhMTVfcnNhLmNlcjAoBggrBgEFBQcwAYYcaHR0cDovL29jc3AuaWNhLmN6L3JjYTE1 X3JzYTANBgkqhkiG9w0BAQsFAAOCAgEAELc0LBZqU0XQuG/F43zqtPRspgixVwl4TQBW+9uQXPz0 Og3C2Qf7FHZwlB93EXz9D4jxQwffA0fugp/eRu6eZ6v55tR7M5Vvl3rlBPFVlDs1+8CWLABLtX61 hcXslU1Sdtqi6lGab9pDoBMdvLOky/CLMdQvA01XMEjCUIslT+U6UlCUhGG3Oh/KBqIORdFcWase oInsJrBpiAA8+wohMKZGomKSXYlUtuwywZ/GNrkHhJd5nN7auEDnM39uAYINSeQ7pHYFtyb4Xik8 jOsk5LaQcgC/yOOcVVcZhmPJFamwA+xBhJY+ynoB7cJyLx2IxiO/7PHSBNsobUaFobfAVNJgoY8X +FYmlcGv5526v8dHH6FEdyq/0mxeXlFpqLrscfJj4zWNcs8+zmrphCrRgeWrrZkciJ+f6tceW+hd DYtpoHDhpJHnUJRqc2R67x88t55DL9vjcbGNB8CTOthlOUv1UWzmIVO0FOEomUKy7d6cf4g2qbF6 Fbq9I3WzkYyxlizNmEAFVDhT2YdK19lWK8dlabxjIH9KF1yuhIG71NJWM6EVz9058ebJcfPdpTRh NkZd+X84+YeFDsxYtOd8Q+L3CmX2Xzj9GrssN9ewTVeW7acSLa5gcdzAiTUF92rQUfuVwr0zGuvZ LnsoLIIsaWrx+pgHcBnL49PVJQV5w4c= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer SERIAL NUMBER: NTRCZ-26439395 Issuer CN: I.CA Root CA/RSA Issuer O: První certifikační autorita, a.s. Issuer C: CZ Subject SERIAL NUMBER: NTRCZ-26439395 Subject O: První certifikační autorita, a.s. Subject CN: I.CA Qualified 2 CA/RSA 02/2016 Subject C: CZ Valid from: Thu Feb 11 13:17:11 CET 2016 Valid to: Sun Feb 08 13:17:11 CET 2026 Public Key: Certificate Policies 30:82:02:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:02:0F:00:30:82:02:0A:02:82:02:01:00:C8:C0:0B:1C:FF:D8:79:71:2D:38:41:C7:25:74:EB:84:EA:D9:59:9E:52:79:7D:DF:F2:98:65:BD:48:82:23:1A:09:B7:6 C:99:E0:22:36:63:6E:AD:4A:E0:FE:02:B7:7B:73:9D:FD:6E:E2:65:CE:86:67:B8:5B:3A:C6:CC:2F:49:52:70:A7:0A:0A:17:7A:5F:95:9E:43:66:3C:AA:52:13:E9:0D:97:44:5D:0C:A7:7B:55:3D:BA:8D:53:F7:00:F5:59:62:90:FF :23:8D:CC:A7:1A:C3:17:C7:DA:DA:F4:A2:EA:C8:2C:88:D5:B4:1E:88:F7:DB:B9:B8:0E:DF:94:0F:E6:CA:71:AE:71:1D:42:E0:F0:BD:59:B6:38:32:B4:55:F9:89:12:03:35:9B:F3:C2:B5:C3:28:55:67:44:EA:E7:4F:A3:20:DA: CB:F3:10:86:CD:13:4B:48:F6:CC:C3:D9:41:B1:63:4F:7D:CA:26:D9:A8:CF:6E:62:1F:C9:A7:F7:B8:C0:46:35:D3:71:52:34:28:88:18:C2:D2:66:16:92:B1:1D:F7:92:BA:4B:47:64:38:0F:0A:81:E9:48:FF:72:B2:BA:DF:E4:C5:C D:51:B0:B5:E0:22:8D:03:35:24:3D:17:7F:2A:D8:8F:0A:5A:99:B1:9B:6B:0E:00:70:51:D7:DD:5F:34:4C:21:9D:FA:26:0A:2D:63:8F:1E:A7:1E:92:21:1D:1D:55:B3:92:9C:8C:BE:B3:F1:0A:F8:DA:8B:4C:E7:9A:AD:10:18:4E: 9C:CD:63:B8:F6:6C:E7:E1:98:8E:91:C6:D3:C7:BD:70:04:D6:04:2D:C6:2D:DE:7D:84:DE:AE:49:D6:63:35:26:FA:2D:58:34:84:1D:7D:E0:96:F6:F5:6A:5A:36:3D:30:CC:4C:7D:F3:34:75:5B:83:50:CB:E1:17:49:A0:5F:8F:C6 :DB:ED:46:6B:C6:D4:A8:27:31:76:60:C3:40:3D:BF:E8:62:54:55:36:E3:F8:B6:69:D4:B1:6D:E6:EA:BD:3D:8F:B7:25:B4:15:C2:A3:F6:1F:5C:34:57:D2:B5:8D:94:9E:E9:FA:00:D1:1D:4D:7E:9C:F9:62:87:A2:D6:83:22:3F:C A:B8:49:A8:68:38:76:0E:B7:63:2C:B0:BE:EB:A8:0C:8D:33:7E:39:61:05:29:2A:43:29:8D:C0:D7:A5:83:59:83:70:41:54:57:19:3C:2C:AC:D7:3D:72:65:14:D1:2D:DF:7F:AA:4F:E0:8C:5E:54:7E:22:45:02:D2:33:88:D5:26:55: DE:EC:1C:03:08:1B:41:66:B3:36:58:CA:16:9A:09:8C:65:DC:E1:FC:21:D8:0F:02:03:01:00:01 Policy OID: 2.5.29.32.0 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000 Sb. v platnem zneni/This qualified system certificate was issued according to Act No. 227/2000 Coll.] Basic Constraints IsCA: true - Path length: 0 Subject Key Identifier 74:82:08:91:E3:D9:64:68:71:85:D6:EB:31:E4:72:DF:8B:26:B1:6D Authority Key Identifier 76:B9:03:48:FB:D5:18:A1:A1:37:A0:ED:CC:68:82:4C:52:34:36:0D CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 72 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://qcrldp1.ica.cz/rca15_rsa.crl http://qcrldp2.ica.cz/rca15_rsa.crl http://qcrldp3.ica.cz/rca15_rsa.crl Authority Info Access http://r.ica.cz/rca15_rsa.cer http://ocsp.ica.cz/rca15_rsa Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: 07:6A:BC:22:69:32:7E:EF:50:0A:0C:57:52:72:62:BA:C8:31:F9:D2:DF:4E:F2:D4:39:E7:4C:E1:70: 36:AA:3A Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 158.19.1 - Extension (critical): Qualifiers [QCQSCDStatusAsInCert] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 73 ETSI 2014 - TSL HR - PDF/A-1b generator Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.3.6.1.4.1.23624.10.1.30.1.0 158.19.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 158.19.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (78) I.CA - issuing qualified certificates Name [ cs ] (78) I.CA - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject SERIAL NUMBER: NTRCZ-26439395 Subject O: První certifikační autorita, a.s. Subject CN: I.CA Qualified 2 CA/RSA 02/2016 Subject C: CZ X509SKI X509 SK I dIIIkePZZGhxhdbrMeRy34smsW0= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2016-06-15T05:55:00Z 158.19.3.1 - Extension (critical): Qualifiers [QCSSCDStatusAsInCert] CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 74 ETSI 2014 - TSL HR - PDF/A-1b generator Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati nell'ambito del servizio (RootCA / QC o CA / QC ) ha individuato in "service digital identity" e in seguito identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" individuato servizio fiducia che insieme preciso di certificati qualificati per i quali queste informazioni supplementari è necessaria per quanto riguarda la presenza o l'assenza di una firma sicura dispositivo Creation (SSCD) sostegno contengono le informazioni machineprocessable indica se o meno il certificato qualificato è supportato da un SSCD. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati nell'ambito del servizio (RootCA / QC o CA / QC ) ha individuato in "service digital identity" e in seguito identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" individuato servizio fiducia che insieme preciso di certificati qualificati per i quali queste informazioni supplementari è necessaria per quanto riguarda la presenza o l'assenza di una firma sicura dispositivo Creation (SSCD) sostegno contengono le informazioni machineprocessable indica se o meno il certificato qualificato è supportato da un SSCD. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) oder geprüft (Akkreditierungsmodell ), dass alle qualifizierten Zertifikaten unter der Service (RootCA / QC oder CA / QC ausgestellt ) in "Service digital identity" und weiter durch die Filter verwendet Informationen identifiziert, weiter zu ermitteln im Rahmen der "Sdi" identifizierten Treuhandservice, die genaue Menge der qualifizierte Zertifikate, für die sich diese zusätzlichen Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signatur erforderlich Erstellungseinheit (SSEE) unterstützen, enthalten die machineprocessable Informationen anzeigt, ob das qualifizierte Zertifikat von einer SSCD unterstützt. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) oder geprüft (Akkreditierungsmodell ), dass alle qualifizierten Zertifikaten unter der Service (RootCA / QC oder CA / QC ausgestellt ) in "Service digital identity" und weiter durch die Filter verwendet Informationen identifiziert, weiter zu ermitteln im Rahmen der "Sdi" identifizierten Treuhandservice, die genaue Menge der qualifizierte Zertifikate, für die sich diese zusätzlichen Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signatur erforderlich Erstellungseinheit (SSEE) unterstützen, enthalten die machineprocessable Informationen anzeigt, ob das qualifizierte Zertifikat von einer SSCD unterstützt. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) oder geprüft (Akkreditierungsmodell ), dass alle qualifizierten Zertifikaten unter der Service (RootCA / QC oder CA / QC ausgestellt ) in "Service digital identity" und weiter durch die Filter verwendet Informationen identifiziert, weiter zu ermitteln im Rahmen der "Sdi" identifizierten Treuhandservice, die genaue Menge der qualifizierte Zertifikate, für die sich diese zusätzlichen Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signatur erforderlich Erstellungseinheit (SSEE) unterstützen, enthalten die machineprocessable Informationen anzeigt, ob das qualifizierte Zertifikat von einer SSCD unterstützt. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service (Racine / QC ou CA / QC ) a identifié dans "service digital identity» et encore identifié par les informations des filtres utilisés pour identifier d'autres sous le "Sdi" identifié service de confiance, l'ensemble précis de certificats qualifiés pour lequel ces informations supplémentaires sont nécessaires en ce qui concerne la présence ou l'absence de signature sécurisée Dispositif de création (SSCD) support ne contiennent les informations machineprocessable indiquant si oui ou non le certificat qualifié est un SSCD. [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 75 ETSI 2014 - TSL HR - PDF/A-1b generator Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCSSCDStatusAsInCert Criteria list assert=atLeastOne Policy Identifier nodes: Identifier CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ 1.3.6.1.4.1.23624.10.1.30.1.0 Page 76 ETSI 2014 - TSL HR - PDF/A-1b generator 159 - TSP: The Czech Post, s.p. TSP Name Name [ en ] The Czech Post, s.p. Name [ cs ] Česká pošta, s.p. Name [ en ] PostSignum QCA Name [ en ] VATCZ-47114983 Name [ cs ] Česká pošta, s.p. [IČ 47114983] Street Address [ en ] Politickych veznu 909/4 Locality [ en ] Prague 1 Postal Code [ en ] 22599 Country Name [ en ] CZ Street Address [ cs ] Politických vězňů 909/4 Locality [ cs ] Praha 1 Postal Code [ cs ] 22599 Country Name [ cs ] CZ TSP Trade Name PostalAddress PostalAddress ElectronicAddress URI mailto:[email protected] URI http://www.postsignum.cz/index.php?lang=en URI http://www.postsignum.cz/index.php?lang=cs/ TSP Information URI URI [ en ] http://www.postsignum.cz/certification_policy.html?lang=en URI [ cs ] http://www.postsignum.cz/certifikacni_politiky_qca.html CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 77 ETSI 2014 - TSL HR - PDF/A-1b generator 159.1 - Service (granted): (4) PostSignum - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (4) PostSignum - issuing qualified certificates Name [ cs ] (4) PostSignum - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 28 X509 Certificate -----BEGIN CERTIFICATE----MIIGLjCCBRagAwIBAgIBHDANBgkqhkiG9w0BAQUFADBZMQswCQYDVQQGEwJDWjEsMCoGA1UECgwj xIxlc2vDoSBwb8WhdGEsIHMucC4gW0nEjCA0NzExNDk4M10xHDAaBgNVBAMTE1Bvc3RTaWdudW0g Um9vdCBRQ0EwHhcNMDUwNDA3MDgzMzE3WhcNMjAwNDA3MDgzMjI2WjBdMQswCQYDVQQGEwJDWjEs MCoGA1UECgwjxIxlc2vDoSBwb8WhdGEsIHMucC4gW0nEjCA0NzExNDk4M10xIDAeBgNVBAMTF1Bv c3RTaWdudW0gUXVhbGlmaWVkIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsWvw IoOTm8tAM8GOrDPt7532/qvT4rh7iDWPKP7PIHNnvIY7l1HJIenOWA0qPqtccu1VZxtg+PAIrSw2 CbopaWOPiDG8W5WFZbxI0xPAHr1mPvla4rSW84Gk0iptmHtfMHBVTJxRtBAd6+WFThuELG8qoN1h qu/9Q77mb891WKlR5q1GBsbf0+WXuS3N5LU0sMPzSszYFpyX1wJO331Cubda3JFU69Jjnz+5l3bc KliZhcDhEhdDQFTDglwc5MB/hxR7J4pzPgvIlmUipQlHefVmvCdwnu3tm/oLLDpLUT773EFiBB0j 5MoQPiP5DSzziWvGuJf58VlFbY/QveyFKwIDAQABo4IC+zCCAvcwgaEGA1UdIASBmTCBljCBkwYE VR0gADCBijCBhwYIKwYBBQUHAgIwexp5VGVudG8gY2VydGlmaWthdCBieWwgdnlkYW4gamFrbyBr dmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZpa2F0IHZlIHNteXNsdSB6YWtvbmEgMjI3LzIw MDAgU2IuIGEgbmF2YXp1amljaWNoIHByZWRwaXN1LjAPBgNVHRMECDAGAQH/AgEAMA4GA1UdDwEB /wQEAwIBBjCBgQYDVR0jBHoweIAUKx3RnXn11XgeAjyCSujd7kOvKUShXaRbMFkxCzAJBgNVBAYT AkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEcMBoGA1UE AxMTUG9zdFNpZ251bSBSb290IFFDQYIBATCCAYsGA1UdHwSCAYIwggF+MDCgLqAshipodHRwOi8v d3d3LnBvc3RzaWdudW0uY3ovY3JsL3Bzcm9vdHFjYS5jcmwwMKAuoCyGKmh0dHA6Ly9wb3N0c2ln bnVtLnR0Yy5jei9jcmwvcHNyb290cWNhLmNybDCBiqCBh6CBhIaBgWxkYXA6Ly9xY2EucG9zdHNp Z251bS5jei9jbiUzZFBvc3RTaWdudW0lMjBSb290JTIwUUNBLG8lM2RDZXNrYSUyMHBvc3RhJTIw cy5wLiUyMFtJQyUyMDQ3MTE0OTgzXSxjJTNkQ1o/Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdDCB iqCBh6CBhIaBgWxkYXA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jbiUzZFBvc3RTaWdudW0lMjBSb290 JTIwUUNBLG8lM2RDZXNrYSUyMHBvc3RhJTIwcy5wLiUyMFtJQyUyMDQ3MTE0OTgzXSxjJTNkQ1o/ Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdDAdBgNVHQ4EFgQUp5+2jomTmmV2CZqV+ER+aYJq3gsw DQYJKoZIhvcNAQEFBQADggEBACkRE++TGTBboYXi1SkhlR66Y9Eo4xvJctW4Pao6VCZJlU5M3cHy 2dM1Du4OvHwlKHvcP/w66xo++ves30sCrg7OQaqLR8KfJsX4wkvBKYC6D2K7aZqUAfCVABcWZkVd r9fwMp+59Yl39UyCxRlPvH1unHylO/ibSxH9Lsl+N0ioFugmW50vYEFP4vy6blRPMW5Akwa+SP00 vV2YejRn5I6RHxV/nq9A0gGxBZq4U4sSbg+oLs0szBqTWt4EEYLMleexttp+7H1eOX3spsn3Wodb hcSWXDyVjR29Ezbhs5Lo6aAQSl5ZL38h8L1AiCSUFG/SmwjJmnpCGDrRwEsZXr0= -----END CERTIFICATE----- Signature algorithm: SHA1withRSA CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 78 ETSI 2014 - TSL HR - PDF/A-1b generator Issuer CN: PostSignum Root QCA Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum Qualified CA Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Thu Apr 07 10:33:17 CEST 2005 Valid to: Tue Apr 07 10:32:26 CEST 2020 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B1:6B:F0:22:83:93:9B:CB:40:33:C1:8E:AC:33:ED:EF:9D:F6:FE:AB:D3:E2:B8:7B:88:35:8F:28:FE:CF:20:73:67:BC: 86:3B:97:51:C9:21:E9:CE:58:0D:2A:3E:AB:5C:72:ED:55:67:1B:60:F8:F0:08:AD:2C:36:09:BA:29:69:63:8F:88:31:BC:5B:95:85:65:BC:48:D3:13:C0:1E:BD:66:3E:F9:5A:E2:B4:96:F3:81:A4:D2:2A:6D:98:7B:5F:30:70:55:4 C:9C:51:B4:10:1D:EB:E5:85:4E:1B:84:2C:6F:2A:A0:DD:61:AA:EF:FD:43:BE:E6:6F:CF:75:58:A9:51:E6:AD:46:06:C6:DF:D3:E5:97:B9:2D:CD:E4:B5:34:B0:C3:F3:4A:CC:D8:16:9C:97:D7:02:4E:DF:7D:42:B9:B7:5A:DC: 91:54:EB:D2:63:9F:3F:B9:97:76:DC:2A:58:99:85:C0:E1:12:17:43:40:54:C3:82:5C:1C:E4:C0:7F:87:14:7B:27:8A:73:3E:0B:C8:96:65:22:A5:09:47:79:F5:66:BC:27:70:9E:ED:ED:9B:FA:0B:2C:3A:4B:51:3E:FB:DC:41:62:04: 1D:23:E4:CA:10:3E:23:F9:0D:2C:F3:89:6B:C6:B8:97:F9:F1:59:45:6D:8F:D0:BD:EC:85:2B:02:03:01:00:01 Certificate Policies Policy OID: 2.5.29.32.0 CPS text: [Tento certifikat byl vydan jako kvalifikovany systemovy certifikat ve smyslu zakona 227/2000 Sb. a navazujicich predpisu.] Basic Constraints IsCA: true - Path length: 0 Authority Key Identifier 2B:1D:D1:9D:79:F5:D5:78:1E:02:3C:82:4A:E8:DD:EE:43:AF:29:44 CRL Distribution Points http://www.postsignum.cz/crl/psrootqca.crl http://postsignum.ttc.cz/crl/psrootqca.crl ldap://qca.postsignum.cz/cn%3dPostSignum%20Root%20QCA,o%3dCeska%20posta%20s.p.%20[I C%2047114983],c%3dCZ?certificateRevocationList ldap://postsignum.ttc.cz/cn%3dPostSignum%20Root%20QCA,o%3dCeska%20posta%20s.p.%20[I C%2047114983],c%3dCZ?certificateRevocationList Subject Key Identifier A7:9F:B6:8E:89:93:9A:65:76:09:9A:95:F8:44:7E:69:82:6A:DE:0B Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: 6E:79:23:E2:86:CF:C4:A7:90:37:CF:C9:12:5E:1C:66:71:88:7B:1A:A5:E3:67:3A:F9:8F:38:A4:67: DF:96:C3 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 79 ETSI 2014 - TSL HR - PDF/A-1b generator [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.1.1 - Extension (critical): Qualifiers [QCNoQSCD] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.110 Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.100 Policy Identifier nodes: Identifier 2.23.134.1.4.1.5.121 Policy Identifier nodes: Identifier 2.23.134.1.4.1.5.120 Policy Identifier nodes: Identifier CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ 2.23.134.1.4.1.5.117 Page 80 ETSI 2014 - TSL HR - PDF/A-1b generator Policy Identifier nodes: Identifier 2.23.134.1.4.1.5.116 Policy Identifier nodes: Identifier 2.23.134.1.4.1.1.121 Policy Identifier nodes: Identifier 2.23.134.1.4.1.1.120 Policy Identifier nodes: Identifier 2.23.134.1.4.1.1.117 Policy Identifier nodes: Identifier 2.23.134.1.4.1.1.116 159.1.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 159.1.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (4) PostSignum - issuing qualified certificates Name [ cs ] (4) PostSignum - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject CN: PostSignum Qualified CA Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 81 ETSI 2014 - TSL HR - PDF/A-1b generator X509 SK I p5+2jomTmmV2CZqV+ER+aYJq3gs= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2005-08-02T22:00:00Z 159.1.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 82 ETSI 2014 - TSL HR - PDF/A-1b generator [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.110 Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.100 Policy Identifier nodes: Identifier 2.23.134.1.4.1.5.121 Policy Identifier nodes: Identifier 2.23.134.1.4.1.5.120 Policy Identifier nodes: Identifier 2.23.134.1.4.1.5.117 Policy Identifier nodes: Identifier 2.23.134.1.4.1.5.116 Policy Identifier nodes: Identifier 2.23.134.1.4.1.1.121 Policy Identifier nodes: Identifier 2.23.134.1.4.1.1.120 Policy Identifier nodes: CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 83 ETSI 2014 - TSL HR - PDF/A-1b generator Identifier 2.23.134.1.4.1.1.117 Policy Identifier nodes: Identifier 2.23.134.1.4.1.1.116 159.2 - Service (granted): (21) PostSignum - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (21) PostSignum - issuing qualified certificates Name [ cs ] (21) PostSignum - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 113 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 84 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGXzCCBUegAwIBAgIBcTANBgkqhkiG9w0BAQsFADBbMQswCQYDVQQGEwJDWjEsMCoGA1UECgwj xIxlc2vDoSBwb8WhdGEsIHMucC4gW0nEjCA0NzExNDk4M10xHjAcBgNVBAMTFVBvc3RTaWdudW0g Um9vdCBRQ0EgMjAeFw0xMDAxMTkxMTMxMjBaFw0yMDAxMTkxMTMwMjBaMF8xCzAJBgNVBAYTAkNa MSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZ UG9zdFNpZ251bSBRdWFsaWZpZWQgQ0EgMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB AKbRReVFlmMooQD/ZzJA9M793LcZivHRvWEG8jsEpp2xTayR17ovs8OMeoYKjvGo6PDfkCJs+sBY S0q5WQFApdWkyl/tUOw1oZ2SPSq6uYLJUyOYSKPMOgKz4u3XuB4Ki1Z+i8Fb7zeRye6eqahK+tql 3ZAJnrJKgC4X2Ta1RKkxK+Hu1bdhWJA3gwL+WkIZbL/PYIzjet++T8ssWK1PWdBXsSfKOTikNzZt 2VPETAQDBpOYxqAgLfCRbcb9KU2WIMT3NNxILu3sNl+OM9gV/GWO943JHsOMAVyJSQREaZksG5KD zzNzQS/LsbYkFtnJAmmh7g9p9Ci6cEJ+pfBTtMECAwEAAaOCAygwggMkMIHxBgNVHSAEgekwgeYw geMGBFUdIAAwgdowgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czASBgNVHRMBAf8ECDAGAQH/AgEAMIG8BggrBgEFBQcBAQSBrzCBrDA3BggrBgEFBQcwAoYraHR0 cDovL3d3dy5wb3N0c2lnbnVtLmN6L2NydC9wc3Jvb3RxY2EyLmNydDA4BggrBgEFBQcwAoYsaHR0 cDovL3d3dzIucG9zdHNpZ251bS5jei9jcnQvcHNyb290cWNhMi5jcnQwNwYIKwYBBQUHMAKGK2h0 dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNyb290cWNhMi5jcnQwDgYDVR0PAQH/BAQDAgEG MIGDBgNVHSMEfDB6gBQVKYzFRWmruLPD6v5LuDHY3PDndqFfpF0wWzELMAkGA1UEBhMCQ1oxLDAq BgNVBAoMI8SMZXNrw6EgcG/FoXRhLCBzLnAuIFtJxIwgNDcxMTQ5ODNdMR4wHAYDVQQDExVQb3N0 U2lnbnVtIFJvb3QgUUNBIDKCAWQwgaUGA1UdHwSBnTCBmjAxoC+gLYYraHR0cDovL3d3dy5wb3N0 c2lnbnVtLmN6L2NybC9wc3Jvb3RxY2EyLmNybDAyoDCgLoYsaHR0cDovL3d3dzIucG9zdHNpZ251 bS5jei9jcmwvcHNyb290cWNhMi5jcmwwMaAvoC2GK2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9j cmwvcHNyb290cWNhMi5jcmwwHQYDVR0OBBYEFInoTN+LJjk+1yQuEg565+Yn5daXMA0GCSqGSIb3 DQEBCwUAA4IBAQB17M2VB48AXCVfVeeOLo0LIJZcg5EyHUKurbnff6tQOmyT7gzpkJNY3I3ijW2E rBfUM/6HefMxYKKWSs4jXqGSK5QfxG0B0O3uGfHPS4WFftaPSAnWk1tiJZ4c43+zSJCcH33n9pDm vt8n0j+6cQAZIWh4PPpmkvUg3uN4E0bzZHnH2uKzMvpVnE6wKml6oV+PUfPASPIYQw9gFEANcMzp 10hXJHrnOo0alPklymZdTVssBXwdzhSBsFel1eVBSvVOx6+y8zdbrkRLOvTVnSMb6zH+fsygU40m imdo30rY/6N+tdQhbM/sTCxgdWAy2g0elAN1zi9Jx6aQ76woDcn+ -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Root QCA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum Qualified CA 2 Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Tue Jan 19 12:31:20 CET 2010 Valid to: Sun Jan 19 12:30:20 CET 2020 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:A6:D1:45:E5:45:96:63:28:A1:00:FF:67:32:40:F4:CE:FD:DC:B7:19:8A:F1:D1:BD:61:06:F2:3B:04:A6:9D:B1:4D:AC: 91:D7:BA:2F:B3:C3:8C:7A:86:0A:8E:F1:A8:E8:F0:DF:90:22:6C:FA:C0:58:4B:4A:B9:59:01:40:A5:D5:A4:CA:5F:ED:50:EC:35:A1:9D:92:3D:2A:BA:B9:82:C9:53:23:98:48:A3:CC:3A:02:B3:E2:ED:D7:B8:1E:0A:8B:56:7E: 8B:C1:5B:EF:37:91:C9:EE:9E:A9:A8:4A:FA:DA:A5:DD:90:09:9E:B2:4A:80:2E:17:D9:36:B5:44:A9:31:2B:E1:EE:D5:B7:61:58:90:37:83:02:FE:5A:42:19:6C:BF:CF:60:8C:E3:7A:DF:BE:4F:CB:2C:58:AD:4F:59:D0:57:B1:2 7:CA:39:38:A4:37:36:6D:D9:53:C4:4C:04:03:06:93:98:C6:A0:20:2D:F0:91:6D:C6:FD:29:4D:96:20:C4:F7:34:DC:48:2E:ED:EC:36:5F:8E:33:D8:15:FC:65:8E:F7:8D:C9:1E:C3:8C:01:5C:89:49:04:44:69:99:2C:1B:92:83:CF:3 3:73:41:2F:CB:B1:B6:24:16:D9:C9:02:69:A1:EE:0F:69:F4:28:BA:70:42:7E:A5:F0:53:B4:C1:02:03:01:00:01 Policy OID: 2.5.29.32.0 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] Basic Constraints IsCA: true - Path length: 0 Authority Info Access http://www.postsignum.cz/crt/psrootqca2.crt http://www2.postsignum.cz/crt/psrootqca2.crt http://postsignum.ttc.cz/crt/psrootqca2.crt Authority Key Identifier 15:29:8C:C5:45:69:AB:B8:B3:C3:EA:FE:4B:B8:31:D8:DC:F0:E7:76 CRL Distribution Points http://www.postsignum.cz/crl/psrootqca2.crl http://www2.postsignum.cz/crl/psrootqca2.crl http://postsignum.ttc.cz/crl/psrootqca2.crl Subject Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 85 ETSI 2014 - TSL HR - PDF/A-1b generator Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: 3A:E4:F4:DE:5F:3E:20:70:A1:18:45:BD:FE:6D:CA:6E:41:2B:B7:E4:ED:84:FD:4F:1B:7B:49:6C:A D:FF:2C:AC Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted Service status description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.2.1 - Extension (critical): Qualifiers [QCQSCDStatusAsInCert] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert Criteria list assert=atLeastOne Policy Identifier nodes: Identifier CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ 2.23.134.1.4.1.7.200 Page 86 ETSI 2014 - TSL HR - PDF/A-1b generator Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.210 Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.300 Policy Identifier nodes: Identifier 2.23.134.1.4.1.17.100 159.2.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 159.2.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (21) PostSignum - issuing qualified certificates Name [ cs ] (21) PostSignum - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject CN: PostSignum Qualified CA 2 Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I iehM34smOT7XJC4SDnrn5ifl1pc= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2010-01-19T11:31:20Z CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 87 ETSI 2014 - TSL HR - PDF/A-1b generator 159.2.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 88 ETSI 2014 - TSL HR - PDF/A-1b generator [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.200 Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.210 Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.300 159.3 - Service (withdrawn): (13) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (13) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (13) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 89 ETSI 2014 - TSL HR - PDF/A-1b generator Service digital identities Certificate fields details Version: 3 Serial Number: 249526 X509 Certificate -----BEGIN CERTIFICATE----MIIHGjCCBgKgAwIBAgIDA862MA0GCSqGSIb3DQEBCwUAMF0xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4GA1UEAxMXUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EwHhcNMDkwNjIyMDg0MjMwWhcNMTIwNjIyMDg0MTE2WjB+MQswCQYDVQQG EwJDWjEsMCoGA1UECgwjxIxlc2vDoSBwb8WhdGEsIHMucC4gW0nEjCA0NzExNDk4M10xIDAeBgNV BAsTF1RpbWUgU3RhbXBpbmcgQXV0aG9yaXR5MR8wHQYDVQQDExZQb3N0U2lnbnVtIFRTQSAtIFRT VSAxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0j5zSERTjerTE0RyGy/SuBKWDtKF zlA9AC1c9brebf0lnqJwyXcltYdEnSWty6GEs4hKnypv6Z7HwY0rIs1IQHR8a7LUcaP0qIHk0270 AQJow9y6qGinv7hR1Fitn/SkVUe8X2PE4ir6zeny9zRUxXhER40Am/2YV2Shsim4UYSrVG9eec+p Et0HadVzo8OZhS3IqmRInFL0Qa9F4gSA3jOxuMlsIlSinwaItKg0zYLCSowTgLzsVvsH6rzJrs4g 1eTWlMQI0H3CZWexwlcTanNgE5nKmpSjbrykR5j+YYJ+VyIoIZXxFWtRRvIhbhBQV+atLoQ93IAl 4hC9ByO2LwIDAQABo4IDwDCCA7wwCQYDVR0TBAIwADCCAR8GA1UdIASCARYwggESMIIBDgYIZ4EG AQQBB24wggEAMIHXBggrBgEFBQcCAjCByhqBx1RlbnRvIGt2YWxpZmlrb3Zhbnkgc3lzdGVtb3Z5 IGNlcnRpZmlrYXQgYnlsIHZ5ZGFuIHBvZGxlIHpha29uYSAyMjcvMjAwMFNiLiBhIG5hdmF6bnlj aCBwcmVkcGlzdS9UaGlzIHF1YWxpZmllZCBzeXN0ZW0gY2VydGlmaWNhdGUgd2FzIGlzc3VlZCBh Y2NvcmRpbmcgdG8gTGF3IE5vIDIyNy8yMDAwQ29sbC4gYW5kIHJlbGF0ZWQgcmVndWxhdGlvbnMw JAYIKwYBBQUHAgEWGGh0dHA6Ly93d3cucG9zdHNpZ251bS5jejAaBggrBgEFBQcBAwQOMAwwCgYI KwYBBQUHCwIwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMIGBBgNVHSME ejB4gBSnn7aOiZOaZXYJmpX4RH5pgmreC6FdpFswWTELMAkGA1UEBhMCQ1oxLDAqBgNVBAoMI8SM ZXNrw6EgcG/FoXRhLCBzLnAuIFtJxIwgNDcxMTQ5ODNdMRwwGgYDVQQDExNQb3N0U2lnbnVtIFJv b3QgUUNBggEcMIIBowYDVR0fBIIBmjCCAZYwNKAyoDCGLmh0dHA6Ly93d3cucG9zdHNpZ251bS5j ei9jcmwvcHNxdWFsaWZpZWRjYS5jcmwwNKAyoDCGLmh0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9j cmwvcHNxdWFsaWZpZWRjYS5jcmwwgZKggY+ggYyGgYlsZGFwOi8vcWNhLnBvc3RzaWdudW0uY3ov Y24lM2RQb3N0U2lnbnVtJTIwUXVhbGlmaWVkJTIwQ0EsbyUzZENlc2thJTIwcG9zdGElMjBzLnAu JTIwJTViSUMlMjA0NzExNDk4MyU1ZCxjJTNkQ1o/Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdDCB kqCBj6CBjIaBiWxkYXA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jbiUzZFBvc3RTaWdudW0lMjBRdWFs aWZpZWQlMjBDQSxvJTNkQ2Vza2ElMjBwb3N0YSUyMHMucC4lMjAlNWJJQyUyMDQ3MTE0OTgzJTVk LGMlM2RDWj9jZXJ0aWZpY2F0ZVJldm9jYXRpb25MaXN0MB0GA1UdDgQWBBTcxgSTyd4iNsepHxiq AP3PqrIl/zANBgkqhkiG9w0BAQsFAAOCAQEAe6PaIHnaMrx0uFi17VAo7EiA1jHQmxdYoTBEkdv1 3mopXc7GqUuZM4C2kMS1N9WiFJyY6S3x6cjO8GiQotXnhC1IW3KOme6pQVmnxW80JEn98mrYNlfQ k6eLARDxznitADLyHfrrz4WTqhU6EslMCSSGCEE62BV5GqDzz0S1wIA7zt2UlMy89KyZw6hgT0Jh zgkJTA1e6py1hqyhrX1gx+9qmJa16ybLuTq5DYQNd6Rvzy/cTlsZCJB3sX9jTp+xQcSIysuhqFex YsPuDUid09v82iFScMC078cq+3a7LE9TNkjlMO4aKTOUxBAkebNyQpewYmvwDqbbIafIIqI44Q== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Jun 22 10:42:30 CEST 2009 Valid to: Fri Jun 22 10:41:16 CEST 2012 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:D2:3E:73:48:44:53:8D:EA:D3:13:44:72:1B:2F:D2:B8:12:96:0E:D2:85:CE:50:3D:00:2D:5C:F5:BA:DE:6D:FD:25:9E: A2:70:C9:77:25:B5:87:44:9D:25:AD:CB:A1:84:B3:88:4A:9F:2A:6F:E9:9E:C7:C1:8D:2B:22:CD:48:40:74:7C:6B:B2:D4:71:A3:F4:A8:81:E4:D3:6E:F4:01:02:68:C3:DC:BA:A8:68:A7:BF:B8:51:D4:58:AD:9F:F4:A4:55:47:B C:5F:63:C4:E2:2A:FA:CD:E9:F2:F7:34:54:C5:78:44:47:8D:00:9B:FD:98:57:64:A1:B2:29:B8:51:84:AB:54:6F:5E:79:CF:A9:12:DD:07:69:D5:73:A3:C3:99:85:2D:C8:AA:64:48:9C:52:F4:41:AF:45:E2:04:80:DE:33:B1:B8:C9: 6C:22:54:A2:9F:06:88:B4:A8:34:CD:82:C2:4A:8C:13:80:BC:EC:56:FB:07:EA:BC:C9:AE:CE:20:D5:E4:D6:94:C4:08:D0:7D:C2:65:67:B1:C2:57:13:6A:73:60:13:99:CA:9A:94:A3:6E:BC:A4:47:98:FE:61:82:7E:57:22:28:21: 95:F1:15:6B:51:46:F2:21:6E:10:50:57:E6:AD:2E:84:3D:DC:80:25:E2:10:BD:07:23:B6:2F:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.7.110 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 90 ETSI 2014 - TSL HR - PDF/A-1b generator Extended Key Usage id_kp_timeStamping Authority Key Identifier A7:9F:B6:8E:89:93:9A:65:76:09:9A:95:F8:44:7E:69:82:6A:DE:0B CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca.crl http://postsignum.ttc.cz/crl/psqualifiedca.crl ldap://qca.postsignum.cz/cn%3dPostSignum%20Qualified%20CA,o%3dCeska%20posta%20s.p.%2 0%5bIC%2047114983%5d,c%3dCZ?certificateRevocationList ldap://postsignum.ttc.cz/cn%3dPostSignum%20Qualified%20CA,o%3dCeska%20posta%20s.p.%20 %5bIC%2047114983%5d,c%3dCZ?certificateRevocationList Subject Key Identifier DC:C6:04:93:C9:DE:22:36:C7:A9:1F:18:AA:00:FD:CF:AA:B2:25:FF Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 23:94:C6:82:09:27:D7:19:54:4D:B2:1A:27:02:C4:A5:A0:0C:2B:E9:01:50:CB:A5:47:3C:1A:3C:82: 88:75:B0 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.3.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (13) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (13) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 91 ETSI 2014 - TSL HR - PDF/A-1b generator X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I 3MYEk8neIjbHqR8YqgD9z6qyJf8= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2009-06-30T23:00:00Z 159.4 - Service (withdrawn): (14) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (14) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (14) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 249619 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 92 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIHGjCCBgKgAwIBAgIDA88TMA0GCSqGSIb3DQEBCwUAMF0xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4GA1UEAxMXUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EwHhcNMDkwNjIyMTAxNDM1WhcNMTIwNjIyMTAxMzAwWjB+MQswCQYDVQQG EwJDWjEsMCoGA1UECgwjxIxlc2vDoSBwb8WhdGEsIHMucC4gW0nEjCA0NzExNDk4M10xIDAeBgNV BAsTF1RpbWUgU3RhbXBpbmcgQXV0aG9yaXR5MR8wHQYDVQQDExZQb3N0U2lnbnVtIFRTQSAtIFRT VSAyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqJhuaXD6j4+mHjkAI5AsO+cq0r58 7lLglJVMwqOAeN0kYIx8lVM/WOBHoLM4G7LWSOcC+9jXG51NZQ9t4wu2nU9OGlZStT313GWzhAWH ugwBUE3daSXShJO5WwYx7ZoJn+ERzpPNGDudANRV7XXYEo2qIKSfpe1MTyJ4uYALDWPN7xtAJr1+ 4S42AHk5aYZboH3PYwu5TzBSscYTHbYzEmdYjgys6BAzTdVjselGqtcB6xlxRyC08Qe0VxwlowXY mZX+dSEHbQRs+hWtpvidkOCV3Dm4rTqzgnVZy/vVzyiBJnl82lRLdjE0s4kdrlMIfuUUVqA+IDYW 4ChGmFXwQQIDAQABo4IDwDCCA7wwCQYDVR0TBAIwADCCAR8GA1UdIASCARYwggESMIIBDgYIZ4EG AQQBB24wggEAMIHXBggrBgEFBQcCAjCByhqBx1RlbnRvIGt2YWxpZmlrb3Zhbnkgc3lzdGVtb3Z5 IGNlcnRpZmlrYXQgYnlsIHZ5ZGFuIHBvZGxlIHpha29uYSAyMjcvMjAwMFNiLiBhIG5hdmF6bnlj aCBwcmVkcGlzdS9UaGlzIHF1YWxpZmllZCBzeXN0ZW0gY2VydGlmaWNhdGUgd2FzIGlzc3VlZCBh Y2NvcmRpbmcgdG8gTGF3IE5vIDIyNy8yMDAwQ29sbC4gYW5kIHJlbGF0ZWQgcmVndWxhdGlvbnMw JAYIKwYBBQUHAgEWGGh0dHA6Ly93d3cucG9zdHNpZ251bS5jejAaBggrBgEFBQcBAwQOMAwwCgYI KwYBBQUHCwIwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMIGBBgNVHSME ejB4gBSnn7aOiZOaZXYJmpX4RH5pgmreC6FdpFswWTELMAkGA1UEBhMCQ1oxLDAqBgNVBAoMI8SM ZXNrw6EgcG/FoXRhLCBzLnAuIFtJxIwgNDcxMTQ5ODNdMRwwGgYDVQQDExNQb3N0U2lnbnVtIFJv b3QgUUNBggEcMIIBowYDVR0fBIIBmjCCAZYwNKAyoDCGLmh0dHA6Ly93d3cucG9zdHNpZ251bS5j ei9jcmwvcHNxdWFsaWZpZWRjYS5jcmwwNKAyoDCGLmh0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9j cmwvcHNxdWFsaWZpZWRjYS5jcmwwgZKggY+ggYyGgYlsZGFwOi8vcWNhLnBvc3RzaWdudW0uY3ov Y24lM2RQb3N0U2lnbnVtJTIwUXVhbGlmaWVkJTIwQ0EsbyUzZENlc2thJTIwcG9zdGElMjBzLnAu JTIwJTViSUMlMjA0NzExNDk4MyU1ZCxjJTNkQ1o/Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdDCB kqCBj6CBjIaBiWxkYXA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jbiUzZFBvc3RTaWdudW0lMjBRdWFs aWZpZWQlMjBDQSxvJTNkQ2Vza2ElMjBwb3N0YSUyMHMucC4lMjAlNWJJQyUyMDQ3MTE0OTgzJTVk LGMlM2RDWj9jZXJ0aWZpY2F0ZVJldm9jYXRpb25MaXN0MB0GA1UdDgQWBBSEx/S2hXHG79nQBEzi 8zgvmahXMTANBgkqhkiG9w0BAQsFAAOCAQEAlUUZ/yvLWp9Bm2bz32Ft0Q1y2tEfd062sCZqSN6d QNJP5lE8tuslXg4y1M+ljEnfNgDJ1sjITLPj+MnXd4DTw/3kp53stAl0UINt5qddcUhcTX6XhA9o yUotXByrkbww9JnXxhENqLXiu2Ax4UxD8UL2LAvh1idE2RM/qAXUKVuH/37kvUi/LmdAr7ujq7Ls /7iv3yxSn/SSSzbpS/hdXdAeN34KHv834LI60E0AYFeX+uufxdM5VOT/zmWKfyFjSUhSiLX6bb6J HO8jOd0FXidkrJUQuh7CSMUtXgw2eHr6Zd9s1bL4s5AWXEAvSD3h8poQLP2Tu6cP/lUzvEIZ+w== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Jun 22 12:14:35 CEST 2009 Valid to: Fri Jun 22 12:13:00 CEST 2012 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:A8:98:6E:69:70:FA:8F:8F:A6:1E:39:00:23:90:2C:3B:E7:2A:D2:BE:7C:EE:52:E0:94:95:4C:C2:A3:80:78:DD:24:60:8 C:7C:95:53:3F:58:E0:47:A0:B3:38:1B:B2:D6:48:E7:02:FB:D8:D7:1B:9D:4D:65:0F:6D:E3:0B:B6:9D:4F:4E:1A:56:52:B5:3D:F5:DC:65:B3:84:05:87:BA:0C:01:50:4D:DD:69:25:D2:84:93:B9:5B:06:31:ED:9A:09:9F:E1:11:C E:93:CD:18:3B:9D:00:D4:55:ED:75:D8:12:8D:AA:20:A4:9F:A5:ED:4C:4F:22:78:B9:80:0B:0D:63:CD:EF:1B:40:26:BD:7E:E1:2E:36:00:79:39:69:86:5B:A0:7D:CF:63:0B:B9:4F:30:52:B1:C6:13:1D:B6:33:12:67:58:8E:0C:A C:E8:10:33:4D:D5:63:B1:E9:46:AA:D7:01:EB:19:71:47:20:B4:F1:07:B4:57:1C:25:A3:05:D8:99:95:FE:75:21:07:6D:04:6C:FA:15:AD:A6:F8:9D:90:E0:95:DC:39:B8:AD:3A:B3:82:75:59:CB:FB:D5:CF:28:81:26:79:7C:DA:5 4:4B:76:31:34:B3:89:1D:AE:53:08:7E:E5:14:56:A0:3E:20:36:16:E0:28:46:98:55:F0:41:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.7.110 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Extended Key Usage id_kp_timeStamping Authority Key Identifier A7:9F:B6:8E:89:93:9A:65:76:09:9A:95:F8:44:7E:69:82:6A:DE:0B CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 93 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca.crl http://postsignum.ttc.cz/crl/psqualifiedca.crl ldap://qca.postsignum.cz/cn%3dPostSignum%20Qualified%20CA,o%3dCeska%20posta%20s.p.%2 0%5bIC%2047114983%5d,c%3dCZ?certificateRevocationList ldap://postsignum.ttc.cz/cn%3dPostSignum%20Qualified%20CA,o%3dCeska%20posta%20s.p.%20 %5bIC%2047114983%5d,c%3dCZ?certificateRevocationList Subject Key Identifier 84:C7:F4:B6:85:71:C6:EF:D9:D0:04:4C:E2:F3:38:2F:99:A8:57:31 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: A5:CD:7E:6D:F5:18:3C:BB:2A:C0:D6:ED:97:95:FF:99:0C:9E:E6:93:62:E2:B4:8E:81:9D:87:48:D 6:81:12:A0 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.4.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (14) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (14) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 94 ETSI 2014 - TSL HR - PDF/A-1b generator Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I hMf0toVxxu/Z0ARM4vM4L5moVzE= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2009-06-30T22:00:00Z 159.5 - Service (withdrawn): (15) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (15) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (15) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 251061 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 95 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIHGjCCBgKgAwIBAgIDA9S1MA0GCSqGSIb3DQEBCwUAMF0xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4GA1UEAxMXUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EwHhcNMDkwNjI1MTIwNDE2WhcNMTIwNjI1MTIwMzE5WjB+MQswCQYDVQQG EwJDWjEsMCoGA1UECgwjxIxlc2vDoSBwb8WhdGEsIHMucC4gW0nEjCA0NzExNDk4M10xIDAeBgNV BAsTF1RpbWUgU3RhbXBpbmcgQXV0aG9yaXR5MR8wHQYDVQQDExZQb3N0U2lnbnVtIFRTQSAtIFRT VSAzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArSE5GHYB/EOz47Fl049bCuco9OUo ycoFEqY+EjjThLxXB5R+MB59Ks//NvRyuRE/0RnHf3vMZ8k5hOXSWjk3HMm9JghBqEG8YE3xO3fU uKDbFfku1c8SvlXKSzVFLSUzdQ3fmB6ORyGJ2NRxACkUVbVNtWMAZYBlQMV6X5q0UBLyWV6eMaPN LAPZsJJSFNR8y8j00mH8XBVndzT5HvTcsqkg0g9o0AyahsNt3ze4UFVe7ZcI9FHtg+aYal+eINTJ 6RKKUVpOfU+npWAE3I9aTXunZF7s6mBSnwfB7WWDiclO9kSPZnCcsbmtRnZ5WQR6CGttGP8a/ukF N1Rv7amrAQIDAQABo4IDwDCCA7wwCQYDVR0TBAIwADCCAR8GA1UdIASCARYwggESMIIBDgYIZ4EG AQQBB24wggEAMIHXBggrBgEFBQcCAjCByhqBx1RlbnRvIGt2YWxpZmlrb3Zhbnkgc3lzdGVtb3Z5 IGNlcnRpZmlrYXQgYnlsIHZ5ZGFuIHBvZGxlIHpha29uYSAyMjcvMjAwMFNiLiBhIG5hdmF6bnlj aCBwcmVkcGlzdS9UaGlzIHF1YWxpZmllZCBzeXN0ZW0gY2VydGlmaWNhdGUgd2FzIGlzc3VlZCBh Y2NvcmRpbmcgdG8gTGF3IE5vIDIyNy8yMDAwQ29sbC4gYW5kIHJlbGF0ZWQgcmVndWxhdGlvbnMw JAYIKwYBBQUHAgEWGGh0dHA6Ly93d3cucG9zdHNpZ251bS5jejAaBggrBgEFBQcBAwQOMAwwCgYI KwYBBQUHCwIwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMIGBBgNVHSME ejB4gBSnn7aOiZOaZXYJmpX4RH5pgmreC6FdpFswWTELMAkGA1UEBhMCQ1oxLDAqBgNVBAoMI8SM ZXNrw6EgcG/FoXRhLCBzLnAuIFtJxIwgNDcxMTQ5ODNdMRwwGgYDVQQDExNQb3N0U2lnbnVtIFJv b3QgUUNBggEcMIIBowYDVR0fBIIBmjCCAZYwNKAyoDCGLmh0dHA6Ly93d3cucG9zdHNpZ251bS5j ei9jcmwvcHNxdWFsaWZpZWRjYS5jcmwwNKAyoDCGLmh0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9j cmwvcHNxdWFsaWZpZWRjYS5jcmwwgZKggY+ggYyGgYlsZGFwOi8vcWNhLnBvc3RzaWdudW0uY3ov Y24lM2RQb3N0U2lnbnVtJTIwUXVhbGlmaWVkJTIwQ0EsbyUzZENlc2thJTIwcG9zdGElMjBzLnAu JTIwJTViSUMlMjA0NzExNDk4MyU1ZCxjJTNkQ1o/Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdDCB kqCBj6CBjIaBiWxkYXA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jbiUzZFBvc3RTaWdudW0lMjBRdWFs aWZpZWQlMjBDQSxvJTNkQ2Vza2ElMjBwb3N0YSUyMHMucC4lMjAlNWJJQyUyMDQ3MTE0OTgzJTVk LGMlM2RDWj9jZXJ0aWZpY2F0ZVJldm9jYXRpb25MaXN0MB0GA1UdDgQWBBSqypcxDztc4E8EHUbj qQtBpzfk8DANBgkqhkiG9w0BAQsFAAOCAQEATSGrXVU6tA1V8Snz83tjhmmX1fpN8B6LDqrjEzUQ JYnPTl9dP5ILU5HpM/wG9GPbvR2zjr0rnt7B6e7iXzSsP2kSiFD2E2QKluK6i3569rsgBofhBQBM MDb87kWnlOuPu6f+T7Z7VvEsalN0/Flrvaiodb8UMvvrJZtFJ8eOZ0N7QFYA4yG1+22YPLdL17LJ ybwQxZCjr4kMH2WfQgXyB1EkruTJXtWa3Beu6A95L6HnhFGwgM2rffpl1Tfj/Ii448lrnlpWophK OzlOOA9YyQtxyJ2J4I2Unx+IwXcTP7ntJBRM0qg5X5aDGTu45y52Z3gRqaGk85s+MmHG4aI4dg== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Thu Jun 25 14:04:16 CEST 2009 Valid to: Mon Jun 25 14:03:19 CEST 2012 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:AD:21:39:18:76:01:FC:43:B3:E3:B1:65:D3:8F:5B:0A:E7:28:F4:E5:28:C9:CA:05:12:A6:3E:12:38:D3:84:BC:57:07:94 :7E:30:1E:7D:2A:CF:FF:36:F4:72:B9:11:3F:D1:19:C7:7F:7B:CC:67:C9:39:84:E5:D2:5A:39:37:1C:C9:BD:26:08:41:A8:41:BC:60:4D:F1:3B:77:D4:B8:A0:DB:15:F9:2E:D5:CF:12:BE:55:CA:4B:35:45:2D:25:33:75:0D:DF:98: 1E:8E:47:21:89:D8:D4:71:00:29:14:55:B5:4D:B5:63:00:65:80:65:40:C5:7A:5F:9A:B4:50:12:F2:59:5E:9E:31:A3:CD:2C:03:D9:B0:92:52:14:D4:7C:CB:C8:F4:D2:61:FC:5C:15:67:77:34:F9:1E:F4:DC:B2:A9:20:D2:0F:68:D0: 0C:9A:86:C3:6D:DF:37:B8:50:55:5E:ED:97:08:F4:51:ED:83:E6:98:6A:5F:9E:20:D4:C9:E9:12:8A:51:5A:4E:7D:4F:A7:A5:60:04:DC:8F:5A:4D:7B:A7:64:5E:EC:EA:60:52:9F:07:C1:ED:65:83:89:C9:4E:F6:44:8F:66:70:9C:B 1:B9:AD:46:76:79:59:04:7A:08:6B:6D:18:FF:1A:FE:E9:05:37:54:6F:ED:A9:AB:01:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.7.110 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Extended Key Usage id_kp_timeStamping Authority Key Identifier A7:9F:B6:8E:89:93:9A:65:76:09:9A:95:F8:44:7E:69:82:6A:DE:0B CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 96 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca.crl http://postsignum.ttc.cz/crl/psqualifiedca.crl ldap://qca.postsignum.cz/cn%3dPostSignum%20Qualified%20CA,o%3dCeska%20posta%20s.p.%2 0%5bIC%2047114983%5d,c%3dCZ?certificateRevocationList ldap://postsignum.ttc.cz/cn%3dPostSignum%20Qualified%20CA,o%3dCeska%20posta%20s.p.%20 %5bIC%2047114983%5d,c%3dCZ?certificateRevocationList Subject Key Identifier AA:CA:97:31:0F:3B:5C:E0:4F:04:1D:46:E3:A9:0B:41:A7:37:E4:F0 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: D3:D5:2E:3E:AD:12:A9:5F:2F:1D:A1:F3:92:1A:B7:C6:64:32:D7:8E:30:0F:8F:89:F1:68:A9:49:38: 48:1E:66 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.5.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (15) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (15) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 97 ETSI 2014 - TSL HR - PDF/A-1b generator Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I qsqXMQ87XOBPBB1G46kLQac35PA= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2009-06-30T22:00:00Z 159.6 - Service (withdrawn): (25) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (25) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (25) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1042771 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 98 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDD+lTMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMDA2MjMxMTI0MjVaFw0xMzA2MjMxMTIzNTdaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDQrmiZlsSOK7L8yVyBjmN+yHrL h500PSSMHn+pSvKhEshZIo6P+NX1XGfutSGj8ENT2dLtqJ1UevJUc2FqXHHEupBhJfV79buz583w N113K7phpeAifSfH1y9+yuHenISBdNJWdIH+AWdYvi0SM0+Tuf3B6GGiM370Q7Vy4jVlYfxdc2Ga DKgJo5zwu7Zt8P/1NJj4xAP+RiUY28wj9Qte2so8P8x3oe7kkqaYm5PZf4ZGdS5DGQdxGWqVaLKM HxyTI8PLWNVBGrrPIcHDuOEVVxxEbH8mH04l3OYdlMR8W+zkcfhIv/+XTZdQh4fzHkZmURxKF1ux aR81VCoz5JT5AgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUGIqDoLLMuQ0Boo3fiakrdHuD/1AwDQYJKoZIhvcNAQELBQAD ggEBAHtnWvEEHa72Iy74L35MRn6XrLderRmC7KaYBohx/S7a92ZKJ0jK8lfc8mSQccXHyHNe4E3H zmzMcsPHEqE5asjm2qjlwEZqOgIk71HP6orR+g8aXBtB3DlwHTespi7jSxtkYSdVVx2Ti6k6brMl brguoGIphJ54M+CwGkscG/qzpxMyPGyUM/AiAI5pjmBsjqmlUeGVeakNRTE97XbHkE55xD5hEwlj kertQeZqR9ltwMIhqV0ON/ECqArDwWaW7BuxGOeksE+JO17+mWHI6zzDSNbtWoRY64ak/EfY7u7O VR74qnF0UP6+z1W+Yy/hEnU+SmKgtJMoreXpFc7d0dQ= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Jun 23 13:24:25 CEST 2010 Valid to: Sun Jun 23 13:23:57 CEST 2013 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:D0:AE:68:99:96:C4:8E:2B:B2:FC:C9:5C:81:8E:63:7E:C8:7A:CB:87:9D:34:3D:24:8C:1E:7F:A9:4A:F2:A1:12:C8:59: 22:8E:8F:F8:D5:F5:5C:67:EE:B5:21:A3:F0:43:53:D9:D2:ED:A8:9D:54:7A:F2:54:73:61:6A:5C:71:C4:BA:90:61:25:F5:7B:F5:BB:B3:E7:CD:F0:37:5D:77:2B:BA:61:A5:E0:22:7D:27:C7:D7:2F:7E:CA:E1:DE:9C:84:81:74:D2 :56:74:81:FE:01:67:58:BE:2D:12:33:4F:93:B9:FD:C1:E8:61:A2:33:7E:F4:43:B5:72:E2:35:65:61:FC:5D:73:61:9A:0C:A8:09:A3:9C:F0:BB:B6:6D:F0:FF:F5:34:98:F8:C4:03:FE:46:25:18:DB:CC:23:F5:0B:5E:DA:CA:3C:3F:C C:77:A1:EE:E4:92:A6:98:9B:93:D9:7F:86:46:75:2E:43:19:07:71:19:6A:95:68:B2:8C:1F:1C:93:23:C3:CB:58:D5:41:1A:BA:CF:21:C1:C3:B8:E1:15:57:1C:44:6C:7F:26:1F:4E:25:DC:E6:1D:94:C4:7C:5B:EC:E4:71:F8:48:BF: FF:97:4D:97:50:87:87:F3:1E:46:66:51:1C:4A:17:5B:B1:69:1F:35:54:2A:33:E4:94:F9:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 99 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 18:8A:83:A0:B2:CC:B9:0D:01:A2:8D:DF:89:A9:2B:74:7B:83:FF:50 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: FC:E4:64:6B:4C:6A:7A:CD:A7:FD:77:03:70:A2:CF:18:A5:D2:64:89:A4:65:14:35:A0:95:78:B0:5D :89:A7:5A Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.6.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (25) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (25) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 100 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I GIqDoLLMuQ0Boo3fiakrdHuD/1A= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2010-06-23T11:24:25Z 159.7 - Service (withdrawn): (26) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (26) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (26) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1042775 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 101 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDD+lXMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMDA2MjMxMTI1MjVaFw0xMzA2MjMxMTI1MDNaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDCk/g5/hQ/pVT/h+ZUjXBsxOQQ aE4qTwaV1KlbvqBPCxWeEOAC79EZ7blB6bUl06yh13WverWnIDdv/2yR+83ZBfRRqX5stSSWxsuF iUQsXmQOlFTe25WWyC4f++wJOPEngoJdvpkTx6oe1+7K1F/2DysFI7pxWqczHkiGwqfqh418Z5s3 ux5EKU1QXt2z415+8eL6y1W9dRGPFcHfWRJnqx3zjG202jdyi3uahUInmZCk9vkXoAQx6wfvTd0B kTiJculsWm7Tp3NsF2SQxo/wBT9JNBTtQN6NyfZxiEACqGP4pgu68bDARnCIBHLQ7GZYW/vxDF5N Lgtujb6qW1yRAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUdLoDZIWdLsqYiOPF5FAskyE+ZBkwDQYJKoZIhvcNAQELBQAD ggEBAF9EHObHhVwtDzT9KYCPDN4zOMXK3C295FlbWy308y1B1TMIKcXn4Nb2zmR83h8kvVYH4fMs USrOQ25EEEqgokPZaPqp7saP+5PkGB6kTEgOXBjlxVMyCG45akgI9emn9iwDygmLaZ0jKxyGmWdc A90lO/XuV/yrcCNvCja09Ov2EVQ51d/ZJGvhCv48korAGKMasCABFMgQCHGNqkuvUX4TLArUGjDF RpT0Fusv1WIN5SMvbChsxf43HCQVUZ0ZnEC8rR2loTCsjLuYomrF0HWitWAqy2x+TDDf85PWxbo7 RBHQBr9RukUN5DxFRUrtLipTLLemKb/uhzR9xIjGfvU= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Jun 23 13:25:25 CEST 2010 Valid to: Sun Jun 23 13:25:03 CEST 2013 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C2:93:F8:39:FE:14:3F:A5:54:FF:87:E6:54:8D:70:6C:C4:E4:10:68:4E:2A:4F:06:95:D4:A9:5B:BE:A0:4F:0B:15:9E:10 :E0:02:EF:D1:19:ED:B9:41:E9:B5:25:D3:AC:A1:D7:75:AF:7A:B5:A7:20:37:6F:FF:6C:91:FB:CD:D9:05:F4:51:A9:7E:6C:B5:24:96:C6:CB:85:89:44:2C:5E:64:0E:94:54:DE:DB:95:96:C8:2E:1F:FB:EC:09:38:F1:27:82:82:5D: BE:99:13:C7:AA:1E:D7:EE:CA:D4:5F:F6:0F:2B:05:23:BA:71:5A:A7:33:1E:48:86:C2:A7:EA:87:8D:7C:67:9B:37:BB:1E:44:29:4D:50:5E:DD:B3:E3:5E:7E:F1:E2:FA:CB:55:BD:75:11:8F:15:C1:DF:59:12:67:AB:1D:F3:8C:6 D:B4:DA:37:72:8B:7B:9A:85:42:27:99:90:A4:F6:F9:17:A0:04:31:EB:07:EF:4D:DD:01:91:38:89:72:E9:6C:5A:6E:D3:A7:73:6C:17:64:90:C6:8F:F0:05:3F:49:34:14:ED:40:DE:8D:C9:F6:71:88:40:02:A8:63:F8:A6:0B:BA:F1: B0:C0:46:70:88:04:72:D0:EC:66:58:5B:FB:F1:0C:5E:4D:2E:0B:6E:8D:BE:AA:5B:5C:91:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 102 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 74:BA:03:64:85:9D:2E:CA:98:88:E3:C5:E4:50:2C:93:21:3E:64:19 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 84:C2:71:11:73:5B:73:43:46:56:11:61:AD:F0:42:D3:0B:C5:03:99:59:C8:5D:8F:21:74:96:3E:E0:E2: 74:51 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.7.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (26) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (26) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 103 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I dLoDZIWdLsqYiOPF5FAskyE+ZBk= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2010-06-23T11:25:25Z 159.8 - Service (withdrawn): (27) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (27) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (27) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1042121 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 104 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDD+bJMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMDA2MjIxMDAzMTlaFw0xMzA2MjIxMDAyNTlaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCz7FDm/Ucn1HKrVEHa7g++yQwV +pyYKR/vW7LHFqef/U+heXVdRP0SYImu51YfY7yTQDJM5fmWXsnkWuz/w+S3bgNFRk2rJBc9YXeX Ihp3C2OHPa32fYvuRK1DJPteXo8jSjcOInRPKi0+NQB1fQDJf+mHqkFIB9jDPvCW44UUMUT9ukMw NRmdPM8WACMQ94R+grRsRUuUc/ehNPG/Q1qLz/R4D2pRQ1TgDC2q4opXfyZCdaeTKDpAQPMB/E6H nLMICNvw2hHAwnBrDcD3dKlZTJk6ql7gioBUb1/2KNlM8iBS1E1qMJ1+mr7b2X7K1nOqpcJNI4x3 Fgy3mA0XwAETAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUjD+eIbBIL6KY+nPLmdBHIbqwU74wDQYJKoZIhvcNAQELBQAD ggEBAGL0xHOehCknkXwyro5vskaQUXbMypfyYWPrILVQmEAjcr76fzPzbQXqg9vJBsSjeALBI33N HigsoejmlPWbFDkSl8AsvlJKOyVaMYPw7ZNqZusQFularKVwPQplPj3gxXIa+XnsxDNw1+jwNoSP BcI5WBEVZsIMubHi80UGhjqR3wr/CCiQGjNjwCV0BzCgQ4C8z3H+nNMtsbxUxUHemZsFKe5HnMLV VrF6RixEDEU9cOYODriY/58PmyJ2LlKNsWVvT66Qoss1ZEh3SOFhpfp8fC4UxZiv60lxN+WAW3Ye o6BubNQfQ+znNvkx502p4NpGQqlYIGF2xLAK3S2Wpzg= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Tue Jun 22 12:03:19 CEST 2010 Valid to: Sat Jun 22 12:02:59 CEST 2013 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B3:EC:50:E6:FD:47:27:D4:72:AB:54:41:DA:EE:0F:BE:C9:0C:15:FA:9C:98:29:1F:EF:5B:B2:C7:16:A7:9F:FD:4F:A1 :79:75:5D:44:FD:12:60:89:AE:E7:56:1F:63:BC:93:40:32:4C:E5:F9:96:5E:C9:E4:5A:EC:FF:C3:E4:B7:6E:03:45:46:4D:AB:24:17:3D:61:77:97:22:1A:77:0B:63:87:3D:AD:F6:7D:8B:EE:44:AD:43:24:FB:5E:5E:8F:23:4A:37:0 E:22:74:4F:2A:2D:3E:35:00:75:7D:00:C9:7F:E9:87:AA:41:48:07:D8:C3:3E:F0:96:E3:85:14:31:44:FD:BA:43:30:35:19:9D:3C:CF:16:00:23:10:F7:84:7E:82:B4:6C:45:4B:94:73:F7:A1:34:F1:BF:43:5A:8B:CF:F4:78:0F:6A:51: 43:54:E0:0C:2D:AA:E2:8A:57:7F:26:42:75:A7:93:28:3A:40:40:F3:01:FC:4E:87:9C:B3:08:08:DB:F0:DA:11:C0:C2:70:6B:0D:C0:F7:74:A9:59:4C:99:3A:AA:5E:E0:8A:80:54:6F:5F:F6:28:D9:4C:F2:20:52:D4:4D:6A:30:9D:7 E:9A:BE:DB:D9:7E:CA:D6:73:AA:A5:C2:4D:23:8C:77:16:0C:B7:98:0D:17:C0:01:13:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 105 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 8C:3F:9E:21:B0:48:2F:A2:98:FA:73:CB:99:D0:47:21:BA:B0:53:BE Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 7D:4C:7E:2A:21:84:CA:03:29:B3:4C:EC:A8:86:5F:D5:91:55:93:D4:EB:5C:62:66:D1:1B:CB:70:3 A:89:00:50 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.8.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (27) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (27) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 106 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I jD+eIbBIL6KY+nPLmdBHIbqwU74= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2010-06-22T10:03:19Z 159.9 - Service (withdrawn): (28) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (28) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (28) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1171141 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 107 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDEd7FMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMTA1MjMxMjQxMDZaFw0xNDA1MjMxMjQxMDZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCTQZVBZ3+XN0uPrfkwm0kaXFpy G4xPhQLH4AcwN0E2xcYMNt4SwJf4bTKsLttAS+YsGkYwbIgoDmHaivy6yQIkDLJWLqnrQ+/uGFQU yN5viRauMTe4wInKmlgb5BmjJoHRp8jgVle45hSN4uw3H+zF9cqRH5HJM2ycOAAgGPA7oihQ49Ls wkrm9uIvXiJ4UgS0UYolZN+u4/adwjpO1BV57hQ6Uh7y/aqwKyI52iN/nGtVwYl8HaWvCYQb+Vsv 4trxFsNv8ACHOONOXBgyeEHsVwQLeXG+Q4QwgkzNpMnaxuj5wSioEUosjiYhh4DldOWAVClDXRUA YcdZEdzlAeK1AgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUE5k9vn63wuci4W1XE5O1UKFGkNgwDQYJKoZIhvcNAQELBQAD ggEBAJdhY2Uuwg35dgDkGoVD4saz/JSO9G6h8+8He+jUE0WvDy7jchOAXaGZX0cgscEFIS7UpWDW bGw36xubWVbCWdA8Vp0CR0man4tJ+ii2noYaS9gVr+PZU7TPPU9Y5LEAPpOFUiHGN3OlesA3Vr3t A0e6uZ9XOw13/O1EYlRqkz7l3sQXnXZRgswEjNjtkPCfPFFtWZbfh6e7FwUvgmITlvQDY0xVE8f2 Z/Mtz5gCFZ+xiyHamSM8T2dox+KmtAVMJIr5F2DwS/GCziUILohIyQtgTMUlt2POdW9eebAlZqcP BdIKJV58WLKaiVcIQcbJUJhVmn1uTllW/zrfg23Dnp0= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon May 23 14:41:06 CEST 2011 Valid to: Fri May 23 14:41:06 CEST 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:93:41:95:41:67:7F:97:37:4B:8F:AD:F9:30:9B:49:1A:5C:5A:72:1B:8C:4F:85:02:C7:E0:07:30:37:41:36:C5:C6:0C:36: DE:12:C0:97:F8:6D:32:AC:2E:DB:40:4B:E6:2C:1A:46:30:6C:88:28:0E:61:DA:8A:FC:BA:C9:02:24:0C:B2:56:2E:A9:EB:43:EF:EE:18:54:14:C8:DE:6F:89:16:AE:31:37:B8:C0:89:CA:9A:58:1B:E4:19:A3:26:81:D1:A7:C8:E 0:56:57:B8:E6:14:8D:E2:EC:37:1F:EC:C5:F5:CA:91:1F:91:C9:33:6C:9C:38:00:20:18:F0:3B:A2:28:50:E3:D2:EC:C2:4A:E6:F6:E2:2F:5E:22:78:52:04:B4:51:8A:25:64:DF:AE:E3:F6:9D:C2:3A:4E:D4:15:79:EE:14:3A:52:1E: F2:FD:AA:B0:2B:22:39:DA:23:7F:9C:6B:55:C1:89:7C:1D:A5:AF:09:84:1B:F9:5B:2F:E2:DA:F1:16:C3:6F:F0:00:87:38:E3:4E:5C:18:32:78:41:EC:57:04:0B:79:71:BE:43:84:30:82:4C:CD:A4:C9:DA:C6:E8:F9:C1:28:A8:11:4 A:2C:8E:26:21:87:80:E5:74:E5:80:54:29:43:5D:15:00:61:C7:59:11:DC:E5:01:E2:B5:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 108 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 13:99:3D:BE:7E:B7:C2:E7:22:E1:6D:57:13:93:B5:50:A1:46:90:D8 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: A5:46:C4:CB:38:C9:32:6D:A3:32:2D:F0:9D:42:90:B4:98:74:B7:E9:C9:58:56:C2:97:48:56:D4:A9: 50:C6:FA Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.9.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (28) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (28) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 109 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I E5k9vn63wuci4W1XE5O1UKFGkNg= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-05-23T12:41:06Z 159.10 - Service (withdrawn): (29) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (29) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (29) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1171146 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 110 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDEd7KMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMTA1MjMxMjQzMDRaFw0xNDA1MjMxMjQzMDRaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCZrK0902FeioIjDcRu1CxpET6+ Dod/APvDBP8Rj7OU6sN2+HB6ldowITc8tCZk4Ck3hqTkQMlPuTPKpYzR7WFbA2fOKVSimiMzuCWo XkK2fx1v7UDg9gdONQFZPPL+r6zkYmTdz14JCOMRAgCinObbVQgaUf6u9nLCw61uZHSdzsgf1PXh 97ShGz7VQeCCritoc8E1W4Kwp1DcOQyJ214Q5PgdL4Pj0HL5rYsabgtb24vbRCOJwHX4iWqYmNPj cTbWK4yPw3ezvm8kpii7wrH+KVYPYPDm+LsieEEAMJeMFDbSyYhT4cWEwtdlptlCF2BFss3g5Q3L 4AFWOpqBdgXVAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUdjFeMDY0zD0R09UN20RowJoizWwwDQYJKoZIhvcNAQELBQAD ggEBAE3oh83WDxb1JXa0UjGxkOLLCRSRlVktep2qweXOH1l7mCCzUooh1f8k3nrNtL8ooCxbGBzy sgeAfjna/f0u8aabcRvaXCmVt0PJNSsbjaEPatKIRQkYsS8umGFsCyu/p5vqAAJvAaMaS8mk/fzk cyV91/xUxJ+mQz/MkTUeteeO4/b75++gZ9blZddtMAoIJ1pBGBamSqR1JGUX0ky1AFlwmcqkhkss esZm0zKnZ7mlxTiNlNUcucE45OsNkgHeanOWFEDvDxq3tmUVbRwDpbSzHF5SfStjMVbYXu3sHHCI eSUL9xSE5BJwPFc4JY+tfAeBcrSFGDtCMNhLYvQ8bn4= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon May 23 14:43:04 CEST 2011 Valid to: Fri May 23 14:43:04 CEST 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:99:AC:AD:3D:D3:61:5E:8A:82:23:0D:C4:6E:D4:2C:69:11:3E:BE:0E:87:7F:00:FB:C3:04:FF:11:8F:B3:94:EA:C3:76: F8:70:7A:95:DA:30:21:37:3C:B4:26:64:E0:29:37:86:A4:E4:40:C9:4F:B9:33:CA:A5:8C:D1:ED:61:5B:03:67:CE:29:54:A2:9A:23:33:B8:25:A8:5E:42:B6:7F:1D:6F:ED:40:E0:F6:07:4E:35:01:59:3C:F2:FE:AF:AC:E4:62:64:D D:CF:5E:09:08:E3:11:02:00:A2:9C:E6:DB:55:08:1A:51:FE:AE:F6:72:C2:C3:AD:6E:64:74:9D:CE:C8:1F:D4:F5:E1:F7:B4:A1:1B:3E:D5:41:E0:82:AE:2B:68:73:C1:35:5B:82:B0:A7:50:DC:39:0C:89:DB:5E:10:E4:F8:1D:2F:8 3:E3:D0:72:F9:AD:8B:1A:6E:0B:5B:DB:8B:DB:44:23:89:C0:75:F8:89:6A:98:98:D3:E3:71:36:D6:2B:8C:8F:C3:77:B3:BE:6F:24:A6:28:BB:C2:B1:FE:29:56:0F:60:F0:E6:F8:BB:22:78:41:00:30:97:8C:14:36:D2:C9:88:53:E1: C5:84:C2:D7:65:A6:D9:42:17:60:45:B2:CD:E0:E5:0D:CB:E0:01:56:3A:9A:81:76:05:D5:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 111 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 76:31:5E:30:36:34:CC:3D:11:D3:D5:0D:DB:44:68:C0:9A:22:CD:6C Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 00:AE:EC:1F:25:6C:15:3B:BB:8C:CF:55:DA:DE:CA:21:34:F1:05:70:F1:DB:B8:95:A1:92:85:AC: CD:F2:38:C5 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.10.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (29) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (29) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 112 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I djFeMDY0zD0R09UN20RowJoizWw= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-05-23T12:43:04Z 159.11 - Service (withdrawn): (30) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (30) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (30) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1171148 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 113 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDEd7MMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMTA1MjMxMjQ0NDhaFw0xNDA1MjMxMjQ0NDhaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDDbjtJ9syWTJuL/JZdLPTIKsxl UKpGUR6UapF3fn82SJqZsumWIq8x57GKvpxyTzj9xEMHiFAU0JEevY1EARwYMLhh1hE3gofmfYWr o2d2yZr7QSHGN+2vV6InL/gheQcvMHX1aR/3G50Dx2zipdhQmv1dv664u/OUXl+frRjytKj5a42B W9y4Nwcq/PLb86mN4s0Dgkmq+//fQ1DRCpx1YGY9gNywNx4a0CRC2kWoC3fx/lUUHWcbTYhqWnjZ cQm90XTda1X+f6uoNTVD0cr1mCJ2LESQ3CAs3HECisIOKAk90S+lokKbKSzvRCQlDlNwOAfxuhj2 hV4Ydl1REHzHAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUduaTBj2xQV6xvkvZVjmv+ePgSxMwDQYJKoZIhvcNAQELBQAD ggEBAD2Obbl+o+pRR3V2u2KPi8izuX7LYdVXCrgE5GXyKLZh+2/ljvlZi+ynNYh/GwxY2zWWzM0R sQuIocwo3sK3CUyF4vZLbeg+kc9Vw05WG8Dqq1/m0OP/IJGqDnkI/cjOalt7rSxFVGWnwnA15wzn KRNN6M0VsPNghEfR2PWjEqYOGjtafd7JYD3uw7qz7qR34kwWKw9d8/2mJeipWe/F/OMKdIUnsf2I MmRdDIIqw4+NWwkqdb4qDoSWilq+lb/k0pKjEIoPgybDdC2w9VOiIhyalEpu1nzMqsXuzBIt8TS0 if0/kbj6MsEx8iNcv3gKRvtRPNZZJkDdS2sOkfsmyVY= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon May 23 14:44:48 CEST 2011 Valid to: Fri May 23 14:44:48 CEST 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C3:6E:3B:49:F6:CC:96:4C:9B:8B:FC:96:5D:2C:F4:C8:2A:CC:65:50:AA:46:51:1E:94:6A:91:77:7E:7F:36:48:9A:99:B 2:E9:96:22:AF:31:E7:B1:8A:BE:9C:72:4F:38:FD:C4:43:07:88:50:14:D0:91:1E:BD:8D:44:01:1C:18:30:B8:61:D6:11:37:82:87:E6:7D:85:AB:A3:67:76:C9:9A:FB:41:21:C6:37:ED:AF:57:A2:27:2F:F8:21:79:07:2F:30:75:F5:69 :1F:F7:1B:9D:03:C7:6C:E2:A5:D8:50:9A:FD:5D:BF:AE:B8:BB:F3:94:5E:5F:9F:AD:18:F2:B4:A8:F9:6B:8D:81:5B:DC:B8:37:07:2A:FC:F2:DB:F3:A9:8D:E2:CD:03:82:49:AA:FB:FF:DF:43:50:D1:0A:9C:75:60:66:3D:80:D C:B0:37:1E:1A:D0:24:42:DA:45:A8:0B:77:F1:FE:55:14:1D:67:1B:4D:88:6A:5A:78:D9:71:09:BD:D1:74:DD:6B:55:FE:7F:AB:A8:35:35:43:D1:CA:F5:98:22:76:2C:44:90:DC:20:2C:DC:71:02:8A:C2:0E:28:09:3D:D1:2F:A5: A2:42:9B:29:2C:EF:44:24:25:0E:53:70:38:07:F1:BA:18:F6:85:5E:18:76:5D:51:10:7C:C7:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 114 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 76:E6:93:06:3D:B1:41:5E:B1:BE:4B:D9:56:39:AF:F9:E3:E0:4B:13 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: B2:00:F0:B4:B7:0A:63:7C:D1:FE:A2:08:6C:26:74:64:7D:85:C1:EE:C5:1B:57:C8:06:B4:9D:15:62: 3F:5F:70 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.11.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (30) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (30) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 115 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I duaTBj2xQV6xvkvZVjmv+ePgSxM= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-05-23T12:44:48Z 159.12 - Service (withdrawn): (31) PostSignum - Qualified Time Stamping Authority, TSU 4 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (31) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (31) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1238721 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 116 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDEubBMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMTExMTAxMDMxMDZaFw0xNDExMTAxMDMxMDZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCS1+el3PBB2YBr2fPybqL0Unby 9r7n/aQAJqyPv6udZcFKep1pd0zXloLrLW8bVynYyjUWwtZ0HJ8x/S4y4YHVCdWPM6ND+60hhPEs Mwi3E2PYpF1pB06ZVerPW8QddrOkmXADTSNCuUGy3g4KTj8JHC7IUKlcEnI8/5RyDIOLb6MQEHYe ETzV9q2yF9J2KUI0ySZvNWclYTyA1m/5AZWIyBxsoMxeaLtI9nNIGWzO714q6gcqSJGhDlSNo9UT 4X+P/xf/F9n7R2ZazUSZ6yuJFIRcHHCrkVRHrIKTMaQ1lgJ1FDury2z+rTkWFrQnrrKazA9eSqN0 fXw2aha3RKtvAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUdtW7mkFW1c5hDOKEUv5UAbhm3XkwDQYJKoZIhvcNAQELBQAD ggEBAG/rBxVrS79+WJ+0hExNI4V9PTRIXxQiMOcjLGKit3xMlCkhzxXNSzSczHdpEc5zp6pwN2uN VqrT50PXoGb9Lzm738A/ugKv1tW4aRLI00qcHzLAZ5q6Q9AzfDJb6n7X606yM9XNcwhIBVjydveD XS7faFHuU9QBdILxrJ15a79JD5b44izAzplpdEBEvJdy82XhmnL6QYzvM9z6UDDvyep3hwUvTJqg qUkS3ybV3zoDE4v4BzErTuRGUKmzrDQyxZvxuzP1nHYQFRB0GHL+1LkW7It7dPjjM4UHwkkSb1BZ j6TweeWoRwFhgNqBvCKax4EKSWNQ67+XthDSUDL6y38= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Thu Nov 10 11:31:06 CET 2011 Valid to: Mon Nov 10 11:31:06 CET 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:92:D7:E7:A5:DC:F0:41:D9:80:6B:D9:F3:F2:6E:A2:F4:52:76:F2:F6:BE:E7:FD:A4:00:26:AC:8F:BF:AB:9D:65:C1:4A :7A:9D:69:77:4C:D7:96:82:EB:2D:6F:1B:57:29:D8:CA:35:16:C2:D6:74:1C:9F:31:FD:2E:32:E1:81:D5:09:D5:8F:33:A3:43:FB:AD:21:84:F1:2C:33:08:B7:13:63:D8:A4:5D:69:07:4E:99:55:EA:CF:5B:C4:1D:76:B3:A4:99:70:0 3:4D:23:42:B9:41:B2:DE:0E:0A:4E:3F:09:1C:2E:C8:50:A9:5C:12:72:3C:FF:94:72:0C:83:8B:6F:A3:10:10:76:1E:11:3C:D5:F6:AD:B2:17:D2:76:29:42:34:C9:26:6F:35:67:25:61:3C:80:D6:6F:F9:01:95:88:C8:1C:6C:A0:CC:5 E:68:BB:48:F6:73:48:19:6C:CE:EF:5E:2A:EA:07:2A:48:91:A1:0E:54:8D:A3:D5:13:E1:7F:8F:FF:17:FF:17:D9:FB:47:66:5A:CD:44:99:EB:2B:89:14:84:5C:1C:70:AB:91:54:47:AC:82:93:31:A4:35:96:02:75:14:3B:AB:CB:6C: FE:AD:39:16:16:B4:27:AE:B2:9A:CC:0F:5E:4A:A3:74:7D:7C:36:6A:16:B7:44:AB:6F:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 117 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 76:D5:BB:9A:41:56:D5:CE:61:0C:E2:84:52:FE:54:01:B8:66:DD:79 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 18:EA:34:13:68:86:E8:50:A7:AA:83:B9:85:E0:3E:48:07:2B:9A:0A:9D:AD:F3:65:9F:07:BA:0E:D6 :53:AE:EA Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.12.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (31) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (31) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 118 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I dtW7mkFW1c5hDOKEUv5UAbhm3Xk= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-11-10T10:31:06Z 159.13 - Service (withdrawn): (32) PostSignum - Qualified Time Stamping Authority, TSU 5 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (32) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (32) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1238723 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 119 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDEubDMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMTExMTAxMDMyMTBaFw0xNDExMTAxMDMyMTBaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqv0qAAQ7NTJFIKo0OQ3zwN4Jz PdvYEGcf2MretSZizE2b1+gh7hUXRSYWNhEazmYRc05rmQ/cRdd+0xGkK/duFXG7asD+2UwlQCY/ om0nbtHw2femd0QIh11ir0jGrz71VPNubHADMrZZuBgOMoTLqTMvbizpeayxX6mYvAEiB0ba0IrP 7/d6KopAvn3STO80sT5WupvH3gEVQzTHlHxi0Opynh8ZdzVVXlDnEIs/P3OizUTCWThPfJaSnHmR 2X+vcE328n55VFpfVcgYXL0cdtgPWiyaFj3N7UD1oKoPr+pN1tpbTDX2i84/oM4Ehxm4Qtcbux9g CJJSK+9p/nz9AgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUYQ5Rg11ohd7tftwapvcD9X6sQSAwDQYJKoZIhvcNAQELBQAD ggEBAAtitsGxXhnk80ED0T9n95GVMAiau/ARANTJaW1k3NZtTkdjZQOSyzp3pjdTVH0NhgkqikYV 0PRhEMOubFdg7PGvr9fTqHOF0bf8ysuS1ufMLeyJgqIgHGgqnkUpNiyv8dSYJej6g6DCQO2EoQxE tvnkNLca3A750CLrN7J0NO9FmUd4pClh6fzOmpWy2puYwW+BQVaVDaBkg1KbDI0umvxcd8HzsFEJ vgNT+kpXStZyXya5PXES9dq0kzEWHZ8gse3FQwW7/S3SPqONBtKlOowmAfRNXQYdf3ztiWoG2j5m B2fJ+MAjtKvObXHYSd3mPg1ELcoWOLjbgvZYvcwBDqg= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Thu Nov 10 11:32:10 CET 2011 Valid to: Mon Nov 10 11:32:10 CET 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:AA:BF:4A:80:01:0E:CD:4C:91:48:2A:8D:0E:43:7C:F0:37:82:73:3D:DB:D8:10:67:1F:D8:CA:DE:B5:26:62:CC:4D:9 B:D7:E8:21:EE:15:17:45:26:16:36:11:1A:CE:66:11:73:4E:6B:99:0F:DC:45:D7:7E:D3:11:A4:2B:F7:6E:15:71:BB:6A:C0:FE:D9:4C:25:40:26:3F:A2:6D:27:6E:D1:F0:D9:F7:A6:77:44:08:87:5D:62:AF:48:C6:AF:3E:F5:54:F3: 6E:6C:70:03:32:B6:59:B8:18:0E:32:84:CB:A9:33:2F:6E:2C:E9:79:AC:B1:5F:A9:98:BC:01:22:07:46:DA:D0:8A:CF:EF:F7:7A:2A:8A:40:BE:7D:D2:4C:EF:34:B1:3E:56:BA:9B:C7:DE:01:15:43:34:C7:94:7C:62:D0:EA:72:9E :1F:19:77:35:55:5E:50:E7:10:8B:3F:3F:73:A2:CD:44:C2:59:38:4F:7C:96:92:9C:79:91:D9:7F:AF:70:4D:F6:F2:7E:79:54:5A:5F:55:C8:18:5C:BD:1C:76:D8:0F:5A:2C:9A:16:3D:CD:ED:40:F5:A0:AA:0F:AF:EA:4D:D6:DA:5 B:4C:35:F6:8B:CE:3F:A0:CE:04:87:19:B8:42:D7:1B:BB:1F:60:08:92:52:2B:EF:69:FE:7C:FD:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 120 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 61:0E:51:83:5D:68:85:DE:ED:7E:DC:1A:A6:F7:03:F5:7E:AC:41:20 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: FF:CB:B1:6E:CB:B9:62:9E:12:AB:A6:21:13:C5:1B:05:C0:E6:3B:1C:C8:7E:26:5B:60:75:15:3C:04 :B3:07:79 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.13.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (32) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (32) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 121 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I YQ5Rg11ohd7tftwapvcD9X6sQSA= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-11-10T10:32:10Z 159.14 - Service (withdrawn): (33) PostSignum - Qualified Time Stamping Authority, TSU 6 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (33) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (33) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1238727 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 122 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDEubHMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMTExMTAxMDMzMDBaFw0xNDExMTAxMDMzMDBaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCgsLZdGKey9GvwARRCX8kNZqD6 L9waesaBQ30PLBrwN6HdpqwcU0zAY1hKOlEMZwEdPTIwDGA83h61vrAcDYfWYvOeot/H8EWe8L1v EaaWs1089rRh0Eh+DaEpOMImBGGs3hSgl34WmsqYAV9WAes/H2i7nCOpH4RMTWK6F/uAKwRAhsjv 2LNqa90EEKQGrYyGTgT4FPOspZwsh6ZhhJAf1dnrjqe/mLG2DSJ3womwZbacvJWDa6o4zE4Yt7Pn knnrzxjc2SbqCBEa0eJVRq6g+k6Npjse92bgieUmp+niRYIaR247E65Go2ylcdeXHh3lKfsiXV1S +nvCXw60KtG7AgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUvpADygkLVAKfggc5U+Pmci5sRxAwDQYJKoZIhvcNAQELBQAD ggEBAEhRo7kng8WNc1IXFTHWi2YyM32QqVDIHTSFUshsKtNA+G0BZga0XAYU10EhTNKMSx+j6hgo kJQRiybxUm/VBxeqcgVa6foZX6XQruW4v1kKc7sq4zYK3H1M4vpGHAI5M6kytvOfrDaJdJ3J6Rt2 RecRmYLchySMp1vGstQXMrqvRnzUeihC4DcA/LqWwPDzUB3rT5qYRf7wSMvPi9JjcOQpAvbCENfj Lg9XZ9HL+5qSuPXGqre3yLOZ2syYYE8YIhYAyWXOeY6VVcumlvrvw4vJ13nq6Ge47zVB0XG0IEzW 2ktyMcSgrQy3kGCbCyo9MOz1eKi3jh5MnL/+meQuBl0= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Thu Nov 10 11:33:00 CET 2011 Valid to: Mon Nov 10 11:33:00 CET 2014 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:A0:B0:B6:5D:18:A7:B2:F4:6B:F0:01:14:42:5F:C9:0D:66:A0:FA:2F:DC:1A:7A:C6:81:43:7D:0F:2C:1A:F0:37:A1:D D:A6:AC:1C:53:4C:C0:63:58:4A:3A:51:0C:67:01:1D:3D:32:30:0C:60:3C:DE:1E:B5:BE:B0:1C:0D:87:D6:62:F3:9E:A2:DF:C7:F0:45:9E:F0:BD:6F:11:A6:96:B3:5D:3C:F6:B4:61:D0:48:7E:0D:A1:29:38:C2:26:04:61:AC:DE: 14:A0:97:7E:16:9A:CA:98:01:5F:56:01:EB:3F:1F:68:BB:9C:23:A9:1F:84:4C:4D:62:BA:17:FB:80:2B:04:40:86:C8:EF:D8:B3:6A:6B:DD:04:10:A4:06:AD:8C:86:4E:04:F8:14:F3:AC:A5:9C:2C:87:A6:61:84:90:1F:D5:D9:EB: 8E:A7:BF:98:B1:B6:0D:22:77:C2:89:B0:65:B6:9C:BC:95:83:6B:AA:38:CC:4E:18:B7:B3:E7:92:79:EB:CF:18:DC:D9:26:EA:08:11:1A:D1:E2:55:46:AE:A0:FA:4E:8D:A6:3B:1E:F7:66:E0:89:E5:26:A7:E9:E2:45:82:1A:47:6E :3B:13:AE:46:A3:6C:A5:71:D7:97:1E:1D:E5:29:FB:22:5D:5D:52:FA:7B:C2:5F:0E:B4:2A:D1:BB:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 123 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier BE:90:03:CA:09:0B:54:02:9F:82:07:39:53:E3:E6:72:2E:6C:47:10 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 18:ED:43:4F:4B:22:84:7A:3D:46:6A:60:E7:0E:9D:FA:19:15:41:FC:6B:56:12:6E:2B:66:DD:05:B7: B6:60:52 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.14.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (33) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (33) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 124 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I vpADygkLVAKfggc5U+Pmci5sRxA= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2011-11-10T10:33:00Z 159.15 - Service (withdrawn): (37) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (37) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (37) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1311206 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 125 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDFAHmMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjA1MzAxMzAwMDNaFw0xNTA1MzAxMzAwMDNaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCmufEcRN6IVr+RX6IXGA7eX4/K Jk+L3g8AREA9uYg4NEnV99j2hlbLGU1P4klauMDwTQwe9boe36II7HT/ZZCWaC4/RX1B3aXDHVI5 dOyP8G/JNCdkgRaLU3K8xDaVibpYerVBRq0/8iUBWmwJ2MNEswBTTigLCd/V2cvjO/P5MISvisjz 2mAiyjBCDkFGujKfB7BzEdR/LBASRRhgnDql6uMRDZHrKMJjDK6r7lXAJ+vK/bumKye27Vubz8KV MJxNe+mZVuL6FcVj2gM8CHmLcD/kkag66+2V+QtSO+DOd9jlVr0vdqUUPvuY1/lLMaizyY+GgJNt L6D+0UeqfiWPAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUeNIgEqQo5683wacqO44RzytvcKQwDQYJKoZIhvcNAQELBQAD ggEBAAjBlQIoVPcHmVJ2D4d3VnIqzxYuTUh83Z4eUZMbuOVv5rOzajn+/5egN5SMVJGkLhcUA6LP WFwuICPFWCuKMLsVikRnlcpar2nOiSv4byKVyaNNxKX/aW01UB5u4ir/ouOjXwnsrYY2BI5WHvpp u6uo9Xw4FmAiSXC90bjG9NPmQugtmeAzSn+0LtoA+trT56XcN/PwmVgJMOAZUBKWJ9cjZpqq5sq9 Qp46A4idWAjZPOhH+fm/1qQhtpzw0T+kNWbrF+cDsNfTjnBAWzKbdoHCFdrAmIUPv7fKvQjoJx+o mXSlklbtBKXc5/LWc/5JzD49lkl6ZFhG4YDqWqH05u8= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed May 30 15:00:03 CEST 2012 Valid to: Sat May 30 15:00:03 CEST 2015 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:A6:B9:F1:1C:44:DE:88:56:BF:91:5F:A2:17:18:0E:DE:5F:8F:CA:26:4F:8B:DE:0F:00:44:40:3D:B9:88:38:34:49:D5:F 7:D8:F6:86:56:CB:19:4D:4F:E2:49:5A:B8:C0:F0:4D:0C:1E:F5:BA:1E:DF:A2:08:EC:74:FF:65:90:96:68:2E:3F:45:7D:41:DD:A5:C3:1D:52:39:74:EC:8F:F0:6F:C9:34:27:64:81:16:8B:53:72:BC:C4:36:95:89:BA:58:7A:B5:41: 46:AD:3F:F2:25:01:5A:6C:09:D8:C3:44:B3:00:53:4E:28:0B:09:DF:D5:D9:CB:E3:3B:F3:F9:30:84:AF:8A:C8:F3:DA:60:22:CA:30:42:0E:41:46:BA:32:9F:07:B0:73:11:D4:7F:2C:10:12:45:18:60:9C:3A:A5:EA:E3:11:0D:91:E B:28:C2:63:0C:AE:AB:EE:55:C0:27:EB:CA:FD:BB:A6:2B:27:B6:ED:5B:9B:CF:C2:95:30:9C:4D:7B:E9:99:56:E2:FA:15:C5:63:DA:03:3C:08:79:8B:70:3F:E4:91:A8:3A:EB:ED:95:F9:0B:52:3B:E0:CE:77:D8:E5:56:BD:2F:7 6:A5:14:3E:FB:98:D7:F9:4B:31:A8:B3:C9:8F:86:80:93:6D:2F:A0:FE:D1:47:AA:7E:25:8F:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 126 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 78:D2:20:12:A4:28:E7:AF:37:C1:A7:2A:3B:8E:11:CF:2B:6F:70:A4 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 79:66:FA:B9:FA:26:C8:37:AF:D5:DD:46:65:35:4E:5C:B6:17:EE:F0:77:5B:93:56:0D:6B:C5:C6:B3 :37:9F:C3 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.15.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (37) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (37) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 127 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I eNIgEqQo5683wacqO44RzytvcKQ= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-05-30T15:00:03Z 159.16 - Service (withdrawn): (38) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (38) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (38) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1311208 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 128 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDFAHoMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjA1MzAxMzAxNTNaFw0xNTA1MzAxMzAxNTNaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCRZFI4XJsKLsh9CrboehM1DpCJ LtOuCuVaHrKYflQK2+He7hp95r7m60xfzbz7nksIQJwAAVW/hpr/c34tjrHHxFOHNFDybAb3kT7G 6OsXxj8yQQcoVfIQn8ikQs28Ym1jWN7WPeU4WgssL3DCekRsJXWqCqsPlIrvN8BJWr9uDMbLT9Va GMsQpsHLS9QerFDOL1a5c1R3TPt+ygsb0TyZ5FFLYLL4vZB/vriazRUQsDAPdtcGJGKA36NSQUB0 Vlzvx3LU6S9WfnQfDe7AxKtjXxSdmlXlZqkQNRaCI/xcL3iIqJFPQFuDmV7knntqGVBBbZsTIjVS MmndKaWA3hilAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUtJg//0fCuUxrXggvZMcSKziJykYwDQYJKoZIhvcNAQELBQAD ggEBAE0ciGnXHIA14q3F/7jnzvksw4OJ+8q5k+q7V+anijtjZ0FOUJEprEo/zkBpepYK2yG/BmWZ y8XtBNPki+mFdVrLOrjcsMyFojgeeSF2ivmqLD8sdhCQX54LXJucZ1KDy+TRGHs1poDCAwaO/ml3 qe20DPdVDXKrOzHLJcOczP0E+Z1EYzc77lK2IlL8N1qJDZz9Ir1rvVo/fAz7MQ4mxIDQN3CeFH7l d7sdFFDKdhHwbP3OrmW10zxL/l6Mg29pBmHcrw58smaa4+vs/qjvWUYuxyl4f9wczI8s6rAUbLOD Qsd25DYiwBLBhVBnpf1/I5nhrltOnv9XAKTzT3FVWNk= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed May 30 15:01:53 CEST 2012 Valid to: Sat May 30 15:01:53 CEST 2015 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:91:64:52:38:5C:9B:0A:2E:C8:7D:0A:B6:E8:7A:13:35:0E:90:89:2E:D3:AE:0A:E5:5A:1E:B2:98:7E:54:0A:DB:E1:DE: EE:1A:7D:E6:BE:E6:EB:4C:5F:CD:BC:FB:9E:4B:08:40:9C:00:01:55:BF:86:9A:FF:73:7E:2D:8E:B1:C7:C4:53:87:34:50:F2:6C:06:F7:91:3E:C6:E8:EB:17:C6:3F:32:41:07:28:55:F2:10:9F:C8:A4:42:CD:BC:62:6D:63:58:DE: D6:3D:E5:38:5A:0B:2C:2F:70:C2:7A:44:6C:25:75:AA:0A:AB:0F:94:8A:EF:37:C0:49:5A:BF:6E:0C:C6:CB:4F:D5:5A:18:CB:10:A6:C1:CB:4B:D4:1E:AC:50:CE:2F:56:B9:73:54:77:4C:FB:7E:CA:0B:1B:D1:3C:99:E4:51:4B :60:B2:F8:BD:90:7F:BE:B8:9A:CD:15:10:B0:30:0F:76:D7:06:24:62:80:DF:A3:52:41:40:74:56:5C:EF:C7:72:D4:E9:2F:56:7E:74:1F:0D:EE:C0:C4:AB:63:5F:14:9D:9A:55:E5:66:A9:10:35:16:82:23:FC:5C:2F:78:88:A8:91:4F: 40:5B:83:99:5E:E4:9E:7B:6A:19:50:41:6D:9B:13:22:35:52:32:69:DD:29:A5:80:DE:18:A5:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 129 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier B4:98:3F:FF:47:C2:B9:4C:6B:5E:08:2F:64:C7:12:2B:38:89:CA:46 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 88:EE:9F:01:5A:45:61:14:33:5C:7C:36:08:7A:2A:82:EE:01:91:4A:25:2E:B9:91:A4:AC:63:FF:66:B D:16:7D Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.16.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (38) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (38) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 130 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I tJg//0fCuUxrXggvZMcSKziJykY= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-05-30T15:01:53Z 159.17 - Service (withdrawn): (39) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (39) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (39) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1311116 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 131 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDFAGMMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjA1MzAxMTMyMTdaFw0xNTA1MzAxMTMyMTdaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCiJSQfRiYkMr32l9oTs7A+fx9S 2m8XW5UMYM9rDjaGEPD1zctpNaDt+veNvmIo42tnu/52UeQ7gqb0bymlKfH1V/4USmMs2eg6FPMv 7d4OcKPkX/otN6Ywt86quwEsAWOGoYtIMWc/41C1Uc3yqcHciBxkcAadCXJyOtj/oIzb54p6AROM NGFw8P1S/erwpI2kwu4Y9Bo2unCibX43xGOQBVL39hRC/+LkL85ErZcMxasDgAdZsgfezcSQh/92 1h2hIP3GiqWK0Kqg+MW04DWMcj1/vXtrGsNJqhPImLAsIkXfXmnp2R6sMzUqDbWhJUX/LXoRDtEU 4HoTzoD/nitbAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQUT1En8WWeQRBG/eD7PPYvr4rODOswDQYJKoZIhvcNAQELBQAD ggEBAEuOOGiYn4QoWE36vYJGMWtbG3GX1SbZu3UjuEjtatt9RdLpNGgEK8ZdExkJZE/he7i3bu6d ePwhd1x/XBvpwlW7R4mg4AfFugR7l3QdhFsl3RmNq6SHnOilxn3vq8cnhsbEucHoSaYM37OoYIkO ODLGsy4tB7Fx3siCNi93DB2fBr+xG1BRGdT9cN+RygwPx/AJvf4WJNWWNdJ3m/UDGszHXw63oqt6 VQ7i/NzfoxNPUpR0mqAnhf3Yq+7B+ZSMfyKsTAYHi4Pr9teVJ6tJ+3BBXdUTL8EEXi/1Pqdwpv5g NuhRApStNtj4cYpuXAdDie2fCDKnfJJfMk4Koz/wB8o= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed May 30 13:32:17 CEST 2012 Valid to: Sat May 30 13:32:17 CEST 2015 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:A2:25:24:1F:46:26:24:32:BD:F6:97:DA:13:B3:B0:3E:7F:1F:52:DA:6F:17:5B:95:0C:60:CF:6B:0E:36:86:10:F0:F5:C D:CB:69:35:A0:ED:FA:F7:8D:BE:62:28:E3:6B:67:BB:FE:76:51:E4:3B:82:A6:F4:6F:29:A5:29:F1:F5:57:FE:14:4A:63:2C:D9:E8:3A:14:F3:2F:ED:DE:0E:70:A3:E4:5F:FA:2D:37:A6:30:B7:CE:AA:BB:01:2C:01:63:86:A1:8B: 48:31:67:3F:E3:50:B5:51:CD:F2:A9:C1:DC:88:1C:64:70:06:9D:09:72:72:3A:D8:FF:A0:8C:DB:E7:8A:7A:01:13:8C:34:61:70:F0:FD:52:FD:EA:F0:A4:8D:A4:C2:EE:18:F4:1A:36:BA:70:A2:6D:7E:37:C4:63:90:05:52:F7:F6:1 4:42:FF:E2:E4:2F:CE:44:AD:97:0C:C5:AB:03:80:07:59:B2:07:DE:CD:C4:90:87:FF:76:D6:1D:A1:20:FD:C6:8A:A5:8A:D0:AA:A0:F8:C5:B4:E0:35:8C:72:3D:7F:BD:7B:6B:1A:C3:49:AA:13:C8:98:B0:2C:22:45:DF:5E:69:E 9:D9:1E:AC:33:35:2A:0D:B5:A1:25:45:FF:2D:7A:11:0E:D1:14:E0:7A:13:CE:80:FF:9E:2B:5B:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 132 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 4F:51:27:F1:65:9E:41:10:46:FD:E0:FB:3C:F6:2F:AF:8A:CE:0C:EB Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: D6:90:B5:BE:A4:C8:90:C6:E1:3E:FC:5C:3C:FE:7A:5A:E5:68:4B:8C:A5:A5:DF:F6:8F:86:96:E8:D 0:00:78:5E Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.17.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (39) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (39) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 133 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I T1En8WWeQRBG/eD7PPYvr4rODOs= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-05-30T13:32:17Z 159.18 - Service (withdrawn): (40) PostSignum - Qualified Time Stamping Authority, TSU 4 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (40) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (40) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1311119 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 134 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGkTCCBXmgAwIBAgIDFAGPMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjA1MzAxMTM0MzVaFw0xNTA1MzAxMTM0MzVaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC21WRCQ61p+BK1HSiIoKkKbiVO KYKcn7Tyga39w5VxMW5+8cRcfhP+3F04c+IEGAVFnEhhXiKssmFkI9D7gLDukrDOzVvAg8Irb9zR Y9SZCS8NcoVH1UQFrmjNzWLqHvg/sl4a04aHhw1oR5iY3Y3Ox7Mwyz8LqAVDiWutKt1JS9As5lDj jyL2jWtojFCmKKc6PG4KOPYqvnUBIDNK4SAcJe9V7eo2IXO05BnrsO3JprWNMjnp0tbRF6weoSQB 0p7ykZeHUmVHacA3kWrO1NFVShRaxGpZ7SoDifo5jX/DUN/bdA3H558hqbAkOczXR/KQy288craS icp1PBIcVPhVAgMBAAGjggM1MIIDMTAJBgNVHRMEAjAAMIIBHwYDVR0gBIIBFjCCARIwggEOBghn gQYBBAFleDCCAQAwgdcGCCsGAQUFBwICMIHKGoHHVGVudG8ga3ZhbGlmaWtvdmFueSBzeXN0ZW1v dnkgY2VydGlmaWthdCBieWwgdnlkYW4gcG9kbGUgemFrb25hIDIyNy8yMDAwU2IuIGEgbmF2YXpu eWNoIHByZWRwaXN1L1RoaXMgcXVhbGlmaWVkIHN5c3RlbSBjZXJ0aWZpY2F0ZSB3YXMgaXNzdWVk IGFjY29yZGluZyB0byBMYXcgTm8gMjI3LzIwMDBDb2xsLiBhbmQgcmVsYXRlZCByZWd1bGF0aW9u czAkBggrBgEFBQcCARYYaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6MBoGCCsGAQUFBwEDBA4wDDAK BggrBgEFBQcLAjCByAYIKwYBBQUHAQEEgbswgbgwOwYIKwYBBQUHMAKGL2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MDwGCCsGAQUFBzAChjBodHRwOi8vd3d3 Mi5wb3N0c2lnbnVtLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwOwYIKwYBBQUHMAKGL2h0dHA6 Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcnQvcHNxdWFsaWZpZWRjYTIuY3J0MA4GA1UdDwEB/wQEAwIG wDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDCDAfBgNVHSMEGDAWgBSJ6EzfiyY5PtckLhIOeufmJ+XW lzCBsQYDVR0fBIGpMIGmMDWgM6Axhi9odHRwOi8vd3d3LnBvc3RzaWdudW0uY3ovY3JsL3BzcXVh bGlmaWVkY2EyLmNybDA2oDSgMoYwaHR0cDovL3d3dzIucG9zdHNpZ251bS5jei9jcmwvcHNxdWFs aWZpZWRjYTIuY3JsMDWgM6Axhi9odHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3JsL3BzcXVhbGlm aWVkY2EyLmNybDAdBgNVHQ4EFgQU1pikUn5nnkFZXTCsRqwoKSGIIhQwDQYJKoZIhvcNAQELBQAD ggEBABfpcl/MQQxTQx07s3tbUMr9wqwfZGXcZltAp705y1HLVmxXnuLeMXBH618OjeEafd+Mgh35 f4VYQYfcwLXLSmkk87y/rN/BgPF9I6z+X2zlM/gOpQUl+wZ+1NQXy18jhi8VXoYxgeyprIxvbwIl pnEiAo27iWkhAHCNYD8GqvjwHGhtegmYjvOuY4zbKb9t9VXCBO9PXw3X/EfkSsc4nyTcuDW40W1r 4hWGthWvFBvYPsWJVHMwvcAkxYSR1M2FP60dKeG75coMqFPttaSceqyC4rqNZlnK4qg8AESOEFVD U0FWjD7ISPKRg9neIKpboYVHu0XQ2J5ElzPyujv6vec= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed May 30 13:34:35 CEST 2012 Valid to: Sat May 30 13:34:35 CEST 2015 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B6:D5:64:42:43:AD:69:F8:12:B5:1D:28:88:A0:A9:0A:6E:25:4E:29:82:9C:9F:B4:F2:81:AD:FD:C3:95:71:31:6E:7E:F 1:C4:5C:7E:13:FE:DC:5D:38:73:E2:04:18:05:45:9C:48:61:5E:22:AC:B2:61:64:23:D0:FB:80:B0:EE:92:B0:CE:CD:5B:C0:83:C2:2B:6F:DC:D1:63:D4:99:09:2F:0D:72:85:47:D5:44:05:AE:68:CD:CD:62:EA:1E:F8:3F:B2:5E:1 A:D3:86:87:87:0D:68:47:98:98:DD:8D:CE:C7:B3:30:CB:3F:0B:A8:05:43:89:6B:AD:2A:DD:49:4B:D0:2C:E6:50:E3:8F:22:F6:8D:6B:68:8C:50:A6:28:A7:3A:3C:6E:0A:38:F6:2A:BE:75:01:20:33:4A:E1:20:1C:25:EF:55:ED: EA:36:21:73:B4:E4:19:EB:B0:ED:C9:A6:B5:8D:32:39:E9:D2:D6:D1:17:AC:1E:A1:24:01:D2:9E:F2:91:97:87:52:65:47:69:C0:37:91:6A:CE:D4:D1:55:4A:14:5A:C4:6A:59:ED:2A:03:89:FA:39:8D:7F:C3:50:DF:DB:74:0D:C7 :E7:9F:21:A9:B0:24:39:CC:D7:47:F2:90:CB:6F:3C:72:B6:92:89:CA:75:3C:12:1C:54:F8:55:02:03:01:00:01 Basic Constraints IsCA: false Certificate Policies Policy OID: 2.23.134.1.4.1.101.120 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 135 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier D6:98:A4:52:7E:67:9E:41:59:5D:30:AC:46:AC:28:29:21:88:22:14 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 65:76:4B:F7:C1:3A:73:10:67:80:73:32:5B:A1:7E:17:E2:28:2C:F0:C5:E2:06:E9:4C:5D:3C:D8:C9:6 5:5A:F6 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.18.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (40) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (40) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 136 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I 1pikUn5nnkFZXTCsRqwoKSGIIhQ= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-05-30T13:34:35Z 159.19 - Service (withdrawn): (41) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (41) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (41) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1360049 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 137 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFMCxMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjEwMDExMjQ1MDRaFw0xODEwMDExMjQ1MDRaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCXRHXd/righxqDl2I8f2kOJpJa BZQPhRgzKnhLiprivCKbiFGcUaSt6vy9X7H9a520T722G7aOnjVMWmU83BsAhgmYQo2mymDtb7Jz cerCGXHRuH43arImehZCjl/H/NFIPm8a/2WKbClw4BvQHt0dagbtrc5u9WKeyuuYohqpN8NHDA9j AZDfvpIzQSrGTCHngtRT31B/vzkzYBqYeQsAi13yhTimKaxHn2LXaxc2b9PDa8cxeK1F3daYg3IG U4MbJObskuEV/EyNwSMJ+KOJDtsXegcqdAxpAp2L46Gj8S0w1f/rt/51MWPXhyDCMyM5P1cZFtOj 3Q/SJTZHFWJTAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBQmKu+gWiyd3GFFRCVqj81jwqzv6jANBgkqhkiG9w0BAQsFAAOCAQEAXBZGRkCr 7nM37aARPkWvukqtKGu9L0elhd2hC1L/rrj7i9EzdkFCgfWE4ZUkcY18QWM510DawE0M1abeEn4C Tz8kxy2tDVVB6TSJNTLspwe93RN/u23yilHFjVyYqETXoa1FrR1CqchzmmJ6fcwqOZu89KNGxmV9 tRHACqW/6Qr1hdvlXm5z1vpeeJd0rWiiQfzwhBLRIKBVotIIZ5NTPcADgJI++u3Na/jn4rFLkFLi QQWUAw/P7Y1UHY3rdw6yZ2Eo41b5Lkq8KL8HGyqQRC2SZvfgo0jLZ4kR+JxVCSQVPBBBGT0Wt+vL xMOnyJvSnSNW7QVp3/YD6nP9eGn0Kw== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Oct 01 14:45:04 CEST 2012 Valid to: Mon Oct 01 14:45:04 CEST 2018 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:97:44:75:DD:FE:B8:A0:87:1A:83:97:62:3C:7F:69:0E:26:92:5A:05:94:0F:85:18:33:2A:78:4B:8A:9A:E2:BC:22:9B:88 :51:9C:51:A4:AD:EA:FC:BD:5F:B1:FD:6B:9D:B4:4F:BD:B6:1B:B6:8E:9E:35:4C:5A:65:3C:DC:1B:00:86:09:98:42:8D:A6:CA:60:ED:6F:B2:73:71:EA:C2:19:71:D1:B8:7E:37:6A:B2:26:7A:16:42:8E:5F:C7:FC:D1:48:3E:6F: 1A:FF:65:8A:6C:29:70:E0:1B:D0:1E:DD:1D:6A:06:ED:AD:CE:6E:F5:62:9E:CA:EB:98:A2:1A:A9:37:C3:47:0C:0F:63:01:90:DF:BE:92:33:41:2A:C6:4C:21:E7:82:D4:53:DF:50:7F:BF:39:33:60:1A:98:79:0B:00:8B:5D:F2:85: 38:A6:29:AC:47:9F:62:D7:6B:17:36:6F:D3:C3:6B:C7:31:78:AD:45:DD:D6:98:83:72:06:53:83:1B:24:E6:EC:92:E1:15:FC:4C:8D:C1:23:09:F8:A3:89:0E:DB:17:7A:07:2A:74:0C:69:02:9D:8B:E3:A1:A3:F1:2D:30:D5:FF:EB: B7:FE:75:31:63:D7:87:20:C2:33:23:39:3F:57:19:16:D3:A3:DD:0F:D2:25:36:47:15:62:53:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 138 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 26:2A:EF:A0:5A:2C:9D:DC:61:45:44:25:6A:8F:CD:63:C2:AC:EF:EA Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 16:E3:C6:95:F5:6E:75:73:BB:8D:C1:08:8B:59:F3:7F:35:42:38:8D:C6:60:B4:70:D4:1F:EC:BE:66:F C:8F:36 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.19.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (41) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (41) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 139 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I JirvoFosndxhRUQlao/NY8Ks7+o= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-10-01T11:45:04Z 159.20 - Service (withdrawn): (42) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (42) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (42) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1360051 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 140 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFMCzMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjEwMDExMjQ2MzhaFw0xODEwMDExMjQ2MzhaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCzSGFZhrj3Yyc8z1vAUqZvMYop Ww3FFUVXQHdSNQGgQkhV8EgVB2jT8LO8VqxfglDhOfiD0XW/qBs4imAHFaykuUyy0K6/+sGtS7Rg 3XREDR4yUjaQJISwoIIWaKRGUhjwUe+sU5rZqz5fL98AcBlRXcNYIFUKxth5Mr1BEj5dIGUx4HqL mOUH0flXjZJW0gzJOchOQfnetkZ0W/8SOCAg/sahLZS2BbELvIGti9p+3fcuBDS1Twx/m+VzY/70 190Oy8IUmLCPYH+A1v644S/6kd3fr6UFv9+F9aNsIZyXUvM0ZiaZZ1LDfJ18wCS8EyNPEGMO/onH JC3Ks7YMENY7AgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBQ38ohqgBAjle5qfwdWVcKVEdwGJjANBgkqhkiG9w0BAQsFAAOCAQEAQBkwSo7e pYWVVVVy98Bt5+4HBpamw4/Zp/CwZ8OFR4dQesWDQ0uqjOwcnp9P6X/jne9FpOBBcUUrw3ZVyUiH JjrCc00uuBi1oMGbGWTuxt0x0sURf9VhFW8KhRW0gwsT6f+Lah0wLTUfuL7y8KuDQQDuwDfvnujQ 8KWkLCdnGlL7MWIX8uY+ykwjyoYGrCzeQSN8Y0TVHKUBlV9WoJo3p6ElJXOuldlIhDs421kJZFl5 UV19JS0ZvZ/nKIZ8XVeepYxFgCOPrsJPN1d6VnLuilW3CoJA8CQN+nRRuOg41rddmnpbITIbW+XA oydKjFHkUyG1wH0HNxtKtR7fLR1xWQ== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Oct 01 14:46:38 CEST 2012 Valid to: Mon Oct 01 14:46:38 CEST 2018 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B3:48:61:59:86:B8:F7:63:27:3C:CF:5B:C0:52:A6:6F:31:8A:29:5B:0D:C5:15:45:57:40:77:52:35:01:A0:42:48:55:F0:4 8:15:07:68:D3:F0:B3:BC:56:AC:5F:82:50:E1:39:F8:83:D1:75:BF:A8:1B:38:8A:60:07:15:AC:A4:B9:4C:B2:D0:AE:BF:FA:C1:AD:4B:B4:60:DD:74:44:0D:1E:32:52:36:90:24:84:B0:A0:82:16:68:A4:46:52:18:F0:51:EF:AC:53 :9A:D9:AB:3E:5F:2F:DF:00:70:19:51:5D:C3:58:20:55:0A:C6:D8:79:32:BD:41:12:3E:5D:20:65:31:E0:7A:8B:98:E5:07:D1:F9:57:8D:92:56:D2:0C:C9:39:C8:4E:41:F9:DE:B6:46:74:5B:FF:12:38:20:20:FE:C6:A1:2D:94:B6:05 :B1:0B:BC:81:AD:8B:DA:7E:DD:F7:2E:04:34:B5:4F:0C:7F:9B:E5:73:63:FE:F4:D7:DD:0E:CB:C2:14:98:B0:8F:60:7F:80:D6:FE:B8:E1:2F:FA:91:DD:DF:AF:A5:05:BF:DF:85:F5:A3:6C:21:9C:97:52:F3:34:66:26:99:67:52:C 3:7C:9D:7C:C0:24:BC:13:23:4F:10:63:0E:FE:89:C7:24:2D:CA:B3:B6:0C:10:D6:3B:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 141 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 37:F2:88:6A:80:10:23:95:EE:6A:7F:07:56:55:C2:95:11:DC:06:26 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 14:B8:49:38:7E:A8:93:40:F8:2A:ED:36:47:45:11:31:4E:5A:09:F6:90:E7:66:87:7B:1A:A6:EF:39:2 D:AA:3D Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.20.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (42) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (42) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 142 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I N/KIaoAQI5Xuan8HVlXClRHcBiY= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-10-01T11:46:38Z 159.21 - Service (withdrawn): (43) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (43) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (43) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1360053 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 143 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFMC1MA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjEwMDExMjQ3MzRaFw0xODEwMDExMjQ3MzRaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCKNaaJWSycVWhjWKSUdm2ZZMGi gHO1uUn8MVYwtSGCJw2peN8UrZDU6yipsdS1qETQmCPmCi9kb+nHHEPely/6B7iSdoQExreiFpv9 S7wMwUW1mWke1RQVu7ftwnb5CuxX9zi4ZiPXsfMz8lS/jaGSPGlQQYi1o5nlkS043jTYzoveUq6u A7jrsiManJsdlZmpTgFJQt/jQOWIQzUNTnmVL+O8m1CcbmTxzwTw9j6MeFARbfgtwUCk0h60LlzB HdVwmUMYowzGPsmj/ZMBitQdsr/HIBO3Fy/u+/E5JzyNzny9eJQmPKawty2Ei4i+ouJF7QJTBmqG iEd59etbddVvAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBTfGYBRIkqRSswf9AzZf6ZEmpFOrzANBgkqhkiG9w0BAQsFAAOCAQEAfDyEG+rl mW4hj8E7ao5iA823Va/yTQ0hUDzEh/A3yqA5wU8q8t+OfqYYCEtGA7WYW8JzSEWR2se/LNwUMJjB ZoO/Zb1k6nr5rYWveJ1q90IvOF7IlDNtkThK9+O2HoRFFuJpE4lUG4K+Lmgo6fqx5Y5TVBiVNkJ+ 8Soq4NHQewxZ9egnsc40dPZ2RGWGsfX7+w/3sWD7xi0aUK26fKP0H+VArJdCkP3yYV5yjg3V6qBV P4TLT701pDs1syG4+bXhWmrsOTu9CFzQkAmhr0FZFeo49qMb8zzpmplFwgWXWCJMRuxuWijUkILw mszYTWZ9WNC18uBMmLX4Ak14Jlyu0A== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Oct 01 14:47:34 CEST 2012 Valid to: Mon Oct 01 14:47:34 CEST 2018 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:8A:35:A6:89:59:2C:9C:55:68:63:58:A4:94:76:6D:99:64:C1:A2:80:73:B5:B9:49:FC:31:56:30:B5:21:82:27:0D:A9:78: DF:14:AD:90:D4:EB:28:A9:B1:D4:B5:A8:44:D0:98:23:E6:0A:2F:64:6F:E9:C7:1C:43:DE:97:2F:FA:07:B8:92:76:84:04:C6:B7:A2:16:9B:FD:4B:BC:0C:C1:45:B5:99:69:1E:D5:14:15:BB:B7:ED:C2:76:F9:0A:EC:57:F7:38:B8 :66:23:D7:B1:F3:33:F2:54:BF:8D:A1:92:3C:69:50:41:88:B5:A3:99:E5:91:2D:38:DE:34:D8:CE:8B:DE:52:AE:AE:03:B8:EB:B2:23:1A:9C:9B:1D:95:99:A9:4E:01:49:42:DF:E3:40:E5:88:43:35:0D:4E:79:95:2F:E3:BC:9B:50:9 C:6E:64:F1:CF:04:F0:F6:3E:8C:78:50:11:6D:F8:2D:C1:40:A4:D2:1E:B4:2E:5C:C1:1D:D5:70:99:43:18:A3:0C:C6:3E:C9:A3:FD:93:01:8A:D4:1D:B2:BF:C7:20:13:B7:17:2F:EE:FB:F1:39:27:3C:8D:CE:7C:BD:78:94:26:3C:A 6:B0:B7:2D:84:8B:88:BE:A2:E2:45:ED:02:53:06:6A:86:88:47:79:F5:EB:5B:75:D5:6F:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 144 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier DF:19:80:51:22:4A:91:4A:CC:1F:F4:0C:D9:7F:A6:44:9A:91:4E:AF Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 63:3F:13:B0:73:1E:52:F1:28:45:79:5E:8E:78:47:44:31:98:46:58:39:24:73:76:A3:4F:9E:B2:35:C4:4 D:24 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.21.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (43) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (43) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 145 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I 3xmAUSJKkUrMH/QM2X+mRJqRTq8= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-10-01T11:47:34Z 159.22 - Service (withdrawn): (44) PostSignum - Qualified Time Stamping Authority, TSU 4 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (44) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (44) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1360056 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 146 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFMC4MA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjEwMDExMjQ4MTZaFw0xODEwMDExMjQ4MTZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHrpx3FJxhtEilaYggiuOPEwJT ZuKcOIcooPNRqMXLy8k/8+nPb6ZHWLTsY7VSaAQ54xrQaWzgMuro8+gdUW9lATG2ghW9QtJPkWn+ VBwPKQaBRUhbTCSHVHycSJmU1a/thV6ireOSqCWNlMyZdin9ofxss/yEORSOcy7KlNG4X0JvDPUC L6eZPx1NCx3EsMJzSH+q820aOA5IdGSq3Oy49Lj7RH9LvfSKiZlNusOpE265tcmZ5W6uBVrAaNXl txscl+TOrgeF1/p9T392dRufq5twuTaT2Gdx+tvLK22rsvGBwjkQZZClf1/ofPQEz5ASV1K4Kprd /HyGtldfBOOpAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBT5pbsuA05iHBsNsfuAtCNZiKaokTANBgkqhkiG9w0BAQsFAAOCAQEAXD46h8Ch M26JyeuZQSb5rbia52ncRtcRb3C+9VjVhlcu58jxC+9NBwQmOSV40VaqWgNFLupN66W12kF2yv3f dTEF/61rj1Mdom4CvDNuiHAFzeXBV1MZRGkMHUTNIpWOzLaLVmhlHeamxHGOpNOUzK7zQM5Xa+Q2 dWiR5tOtHMzgynlTnYEMRYblYFveXp4DpMc/dpS1xK6WOIR1qc22fMh6an+hJtqmobIXNy+nd+ch GDlwExTiLeSHNhsRBUd/O6ZoqTBAD7qBmbGa3XLB+pSXgjsvABb1NE2n3vbihlePqxPk4y4r+Jnq xqbPYRK3OhuwlJdF5L1eHE557CH/Gw== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Oct 01 14:48:16 CEST 2012 Valid to: Mon Oct 01 14:48:16 CEST 2018 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C7:AE:9C:77:14:9C:61:B4:48:A5:69:88:20:8A:E3:8F:13:02:53:66:E2:9C:38:87:28:A0:F3:51:A8:C5:CB:CB:C9:3F:F3 :E9:CF:6F:A6:47:58:B4:EC:63:B5:52:68:04:39:E3:1A:D0:69:6C:E0:32:EA:E8:F3:E8:1D:51:6F:65:01:31:B6:82:15:BD:42:D2:4F:91:69:FE:54:1C:0F:29:06:81:45:48:5B:4C:24:87:54:7C:9C:48:99:94:D5:AF:ED:85:5E:A2:AD: E3:92:A8:25:8D:94:CC:99:76:29:FD:A1:FC:6C:B3:FC:84:39:14:8E:73:2E:CA:94:D1:B8:5F:42:6F:0C:F5:02:2F:A7:99:3F:1D:4D:0B:1D:C4:B0:C2:73:48:7F:AA:F3:6D:1A:38:0E:48:74:64:AA:DC:EC:B8:F4:B8:FB:44:7F:4B :BD:F4:8A:89:99:4D:BA:C3:A9:13:6E:B9:B5:C9:99:E5:6E:AE:05:5A:C0:68:D5:E5:B7:1B:1C:97:E4:CE:AE:07:85:D7:FA:7D:4F:7F:76:75:1B:9F:AB:9B:70:B9:36:93:D8:67:71:FA:DB:CB:2B:6D:AB:B2:F1:81:C2:39:10:65: 90:A5:7F:5F:E8:7C:F4:04:CF:90:12:57:52:B8:2A:9A:DD:FC:7C:86:B6:57:5F:04:E3:A9:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 147 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier F9:A5:BB:2E:03:4E:62:1C:1B:0D:B1:FB:80:B4:23:59:88:A6:A8:91 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: A7:E9:EC:7B:1B:2E:B1:D6:18:F5:C3:65:4C:59:1C:DE:A8:F4:6B:7F:AC:5D:9A:91:0F:49:C7:50:6 9:76:1A:5E Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.22.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (44) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (44) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 148 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I +aW7LgNOYhwbDbH7gLQjWYimqJE= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-10-01T11:48:16Z 159.23 - Service (withdrawn): (45) PostSignum - Qualified Time Stamping Authority, TSU 5 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (45) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (45) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1360061 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 149 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFMC9MA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjEwMDExMjQ5MTRaFw0xODEwMDExMjQ5MTRaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+cSd8oVtBwVRRTVpj85ADuQfN 9ADAuhrXdFSxebmz/vIj1wv3EA6f3Dvnog3vASjeoDVO8sCWwuAQV3T6O9vPYn5sZZmW9t5Ip+Ku nqUyWa0rzzkImRrO74nOTm87zz4n2KFrEqr92ZD4QOp1FtvrRz6kecKAclrtb68mnwWgXhKu99Wu /CbGYx0uuCu0YfSMs2t1N5ypMtwGvMwxbOjJ1ScbvlTo9N+lKF88QCt9Ex+fKd3i3nIrx7X47bmm MW2ySoUXSVtZ8QyU7rfO1q5c6y7CFm0OTYlifcCGy7gcaaO2g80l2+fLKOAX86ePeIKM0NHm9eRx AbvvHuFZ2j5PAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBTKFI94uLKAvKsLtXPSIM8Wr6o8QDANBgkqhkiG9w0BAQsFAAOCAQEAV1+8I71F w7/w7v32PmDopJAb/R94IENwU9PDLErSh8TdUx1zeMKHcxD9CHN5Cxt1kjJBm70rTCcO0YJcPifF H8gDXDMyEzYQSxm7VKRRoHrAbmfMMQeUpvJMhgCOt41PWHT8kTA+CQwmbqHU6yE18F1EDJ99Dc/H hVZb6POSnlvvpfxSW4XqXZqxw3oKfC0Md4RM+xD83SNheA42nM/nNjQIZFXz113q5VGaWdkW9hYf EImN6kRqBGiK6ElNXYYHTO9fVI4/cbGIg2/2AQsWb7IjkKM5XWBbkPMY4u10KwgEoSV2ZfRlgQXB rnus3/FwCDj0yH0s7yvhdfDLv6VYqQ== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Oct 01 14:49:14 CEST 2012 Valid to: Mon Oct 01 14:49:14 CEST 2018 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:BE:71:27:7C:A1:5B:41:C1:54:51:4D:5A:63:F3:90:03:B9:07:CD:F4:00:C0:BA:1A:D7:74:54:B1:79:B9:B3:FE:F2:23:D 7:0B:F7:10:0E:9F:DC:3B:E7:A2:0D:EF:01:28:DE:A0:35:4E:F2:C0:96:C2:E0:10:57:74:FA:3B:DB:CF:62:7E:6C:65:99:96:F6:DE:48:A7:E2:AE:9E:A5:32:59:AD:2B:CF:39:08:99:1A:CE:EF:89:CE:4E:6F:3B:CF:3E:27:D8:A1: 6B:12:AA:FD:D9:90:F8:40:EA:75:16:DB:EB:47:3E:A4:79:C2:80:72:5A:ED:6F:AF:26:9F:05:A0:5E:12:AE:F7:D5:AE:FC:26:C6:63:1D:2E:B8:2B:B4:61:F4:8C:B3:6B:75:37:9C:A9:32:DC:06:BC:CC:31:6C:E8:C9:D5:27:1B: BE:54:E8:F4:DF:A5:28:5F:3C:40:2B:7D:13:1F:9F:29:DD:E2:DE:72:2B:C7:B5:F8:ED:B9:A6:31:6D:B2:4A:85:17:49:5B:59:F1:0C:94:EE:B7:CE:D6:AE:5C:EB:2E:C2:16:6D:0E:4D:89:62:7D:C0:86:CB:B8:1C:69:A3:B6:83: CD:25:DB:E7:CB:28:E0:17:F3:A7:8F:78:82:8C:D0:D1:E6:F5:E4:71:01:BB:EF:1E:E1:59:DA:3E:4F:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 150 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier CA:14:8F:78:B8:B2:80:BC:AB:0B:B5:73:D2:20:CF:16:AF:AA:3C:40 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 92:89:17:63:BB:BD:B5:F8:49:D1:1C:41:A2:56:6D:7B:1D:87:3F:57:5C:52:B5:CE:F7:B7:A0:B0:EE :78:31:F8 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.23.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (45) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (45) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 151 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I yhSPeLiygLyrC7Vz0iDPFq+qPEA= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-10-01T11:49:14Z 159.24 - Service (withdrawn): (46) PostSignum - Qualified Time Stamping Authority, TSU 6 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (46) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (46) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1360065 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 152 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFMDBMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMjEwMDExMjUwMDBaFw0xODEwMDExMjUwMDBaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCglLSuAI0YVDYXNRST8cXT84+A RaU4Iy/LkYYwFrf2ubu3hEbdm0tbvAnnAjcP1PvJmQFDhe8BZbM50hNSyQsNvkkz3M3sz/Vsxp2J B/+BFqm72Kp35AXZU+Ptgo0/HCsOqFpIEcoPEe9wCDYh4qkBI9YrGKcghXq/PV5s+/Ddf1oamgTg V0paRLickDRS7Tc/KP+SXyANs7oaXR5PmOxUPC4svG8voRFMknEcgV+lgYMsAQeJ9MtQsg/aHLcT +hwbysRj3BDkI1Xn/HzE/h5fteJ61sA9VZcCk9cEmnBZUticBDYjir3R0Xyary4Jg7Wfktwn5Y4i 9RUcIigerea7AgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBRkgJxvQEWjvo8UGG9h/pCaEXsXYjANBgkqhkiG9w0BAQsFAAOCAQEAmS5zTWYm V34gjSJLinutwVqqGJn48a6o+61825CgYLs+KrvQcdZMpqiGlPE5+wRfsCHEOTEOsFJv13Ev51xz ScO5laDWua/wusON1GFFGZjBN4XGYIxgrA1uwQ1h4I+ZXlLNKKxOgbRIMM5hTF7OQ/B63Zart6II fXzsbYVXSSN7PIR4wn8pSF2maRSzvFFfs0K6hF/OsCLxVEoao68zOMr52KzS4hQu6aG06xMAXpre CR9zsufDrWzuauheeiHmSkN8wFPNPre+K58OF2PytRqG4KFrDP70eVKqwCZADGm5i17rU6seI5rG eXr8dftrYTF/rWPp25hjlGTB5o9D9Q== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Oct 01 14:50:00 CEST 2012 Valid to: Mon Oct 01 14:50:00 CEST 2018 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:A0:94:B4:AE:00:8D:18:54:36:17:35:14:93:F1:C5:D3:F3:8F:80:45:A5:38:23:2F:CB:91:86:30:16:B7:F6:B9:BB:B7:84: 46:DD:9B:4B:5B:BC:09:E7:02:37:0F:D4:FB:C9:99:01:43:85:EF:01:65:B3:39:D2:13:52:C9:0B:0D:BE:49:33:DC:CD:EC:CF:F5:6C:C6:9D:89:07:FF:81:16:A9:BB:D8:AA:77:E4:05:D9:53:E3:ED:82:8D:3F:1C:2B:0E:A8:5A:4 8:11:CA:0F:11:EF:70:08:36:21:E2:A9:01:23:D6:2B:18:A7:20:85:7A:BF:3D:5E:6C:FB:F0:DD:7F:5A:1A:9A:04:E0:57:4A:5A:44:B8:9C:90:34:52:ED:37:3F:28:FF:92:5F:20:0D:B3:BA:1A:5D:1E:4F:98:EC:54:3C:2E:2C:BC:6 F:2F:A1:11:4C:92:71:1C:81:5F:A5:81:83:2C:01:07:89:F4:CB:50:B2:0F:DA:1C:B7:13:FA:1C:1B:CA:C4:63:DC:10:E4:23:55:E7:FC:7C:C4:FE:1E:5F:B5:E2:7A:D6:C0:3D:55:97:02:93:D7:04:9A:70:59:52:D8:9C:04:36:23:8A: BD:D1:D1:7C:9A:AF:2E:09:83:B5:9F:92:DC:27:E5:8E:22:F5:15:1C:22:28:1E:AD:E6:BB:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 153 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 64:80:9C:6F:40:45:A3:BE:8F:14:18:6F:61:FE:90:9A:11:7B:17:62 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 56:19:59:5F:D8:71:1B:FB:6D:9A:DE:19:84:03:B3:14:A1:78:DF:C2:94:6A:94:5B:35:A6:F6:30:0C: B2:E5:7E Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.24.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (46) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (46) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 154 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I ZICcb0BFo76PFBhvYf6QmhF7F2I= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2012-10-01T11:50:00Z 159.25 - Service (withdrawn): (47) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (47) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (47) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1497754 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 155 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFtqaMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMzA4MjYxMDA4MjBaFw0xOTEwMDQxMDA4MjBaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDKLN71W9DFr95qA8AO7KPfeQw0 Wc8q/WUTytfPAcPaacltj1lNlVE8+3zgi5C+wPtM4tq5D3xTLBMx4od5JEoJoFq4RcYF6eCWOmvS kHG4YlpFoJ++3voNbEL3DXssJMbWEb5xEy6JcsCkYzwhqpCMBUZ7xnyovu0L4Bjb0mPIbLr7GZij z1mX34OS7w+oiCRHWwbs3Kad7AUBGLnVQz8SosupBEATdYTumo2dEpCQt/8SpqP2kdEwaFUALAjI qm7SJi1BrqYVlaXL9UyC7dwrtvZkJ0Bdldb8lfyKhH/71t25uG33+mxyPm/QN90DBASsk9ziTKuB 2LFH1CxBka55AgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBSVawnyimp2d+o2bXuARlabYNSQrTANBgkqhkiG9w0BAQsFAAOCAQEAgr0ujiLz +vn34mtxJKOTzW+1XC3JZGVmhY2U/qvcqNZfDcAE/76KBK0Vy8IAMQYtFQ0eVT2oMV07PZJ7dB59 /fdJWzxk4bTtUI+21BosVunYiB+4kr9kAbhHYISi5INyTRwWBsLPi0uHlj6YP0DIvfinUDwqTSbM CFaPDTVvOsi555ClVm7IY18TidCLCjkqrSdjofywRiTac4hh1vWIHz3ijQtp6AzQINefAvmuMMd0 70S95Jm8p/Pa7w95qkx6IHIsvz+xWH6cSZoWT0VnpX3KwRJKRrBQuHyieVNQHp3ZvHpT04kRmd0R qjd51XdMvOKRhsbI8FQdRX5GQCwZuQ== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 26 12:08:20 CEST 2013 Valid to: Fri Oct 04 12:08:20 CEST 2019 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:CA:2C:DE:F5:5B:D0:C5:AF:DE:6A:03:C0:0E:EC:A3:DF:79:0C:34:59:CF:2A:FD:65:13:CA:D7:CF:01:C3:DA:69:C9 :6D:8F:59:4D:95:51:3C:FB:7C:E0:8B:90:BE:C0:FB:4C:E2:DA:B9:0F:7C:53:2C:13:31:E2:87:79:24:4A:09:A0:5A:B8:45:C6:05:E9:E0:96:3A:6B:D2:90:71:B8:62:5A:45:A0:9F:BE:DE:FA:0D:6C:42:F7:0D:7B:2C:24:C6:D6:1 1:BE:71:13:2E:89:72:C0:A4:63:3C:21:AA:90:8C:05:46:7B:C6:7C:A8:BE:ED:0B:E0:18:DB:D2:63:C8:6C:BA:FB:19:98:A3:CF:59:97:DF:83:92:EF:0F:A8:88:24:47:5B:06:EC:DC:A6:9D:EC:05:01:18:B9:D5:43:3F:12:A2:CB: A9:04:40:13:75:84:EE:9A:8D:9D:12:90:90:B7:FF:12:A6:A3:F6:91:D1:30:68:55:00:2C:08:C8:AA:6E:D2:26:2D:41:AE:A6:15:95:A5:CB:F5:4C:82:ED:DC:2B:B6:F6:64:27:40:5D:95:D6:FC:95:FC:8A:84:7F:FB:D6:DD:B9:B8 :6D:F7:FA:6C:72:3E:6F:D0:37:DD:03:04:04:AC:93:DC:E2:4C:AB:81:D8:B1:47:D4:2C:41:91:AE:79:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 156 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 95:6B:09:F2:8A:6A:76:77:EA:36:6D:7B:80:46:56:9B:60:D4:90:AD Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 36:5C:67:63:5C:AF:A5:E7:E3:D5:2D:C4:23:4A:8E:94:E2:CB:90:31:76:EB:9B:03:1D:0D:C6:47:1A :D5:CF:22 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.25.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (47) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (47) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 157 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I lWsJ8opqdnfqNm17gEZWm2DUkK0= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-08-26T09:08:00Z 159.26 - Service (withdrawn): (48) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (48) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (48) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1497757 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 158 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFtqdMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMzA4MjYxMDEwNTZaFw0xOTEwMDQxMDEwNTZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCxN1VlLfgp8l4KQJMt8pbbTHEW XE4q+5qC6/5yPWVoE+pccbulItfP79PkRo3FZpRCgBx8BT/pwSfd0VuTOpHm5beTTGkpHgnzBQ3b LSkMtrUSydbcGJSv6h9tBLpTdsp1sAvyZySlHPIz0WVbYEQse2xWb/R1SasRRfxOSsi9yGsmKhj9 jkTNs1FThUVfL19d0R71rX9npbN16H2RbgdwFARBM+wsxJKgVe35RnUDdBdb4j6sSAYBD7oRJwwh aDE53g9zNi6EaP+WaVzjdxQJiC+B8tqwjkHcXndeuiQBm2ZfcQ5mIzMQ3glX9M+UvU3U0J4Qv4HU ZGvi/EpeqxWtAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBTv0HZgWnNo5jiYSKTi31turdCLHDANBgkqhkiG9w0BAQsFAAOCAQEAmkNmYiCZ L9XeFeg6vxkUObeBC0rREQIXz11OffJFdEL9jpX94M7HB7e/zNJ0sehAMlHP62opb1vum+eToMCP gOrmeSBP+Pp0C3iTOZYLalsdaNqUU5Y3+BFdganBC1F9/cTKmYDhLS3YvCMsUVS3TQC/ub2tOb+z wkn8UgZc0p0jJcgAtG8Zcqx8IfTBzqzX/sT3CB+Zi6I+MKgcayXXRfunKn1T2hfC4pBbJvogVoiq LuUsFlbsYF4qZ7rBLb1EnhTIWYotHVtgsE3XDLy1uSvPcBk92TYio3XiTsHj/JGnnxKwCKaw72N3 IAF8habQyQW6DAeCmBXcMHqVwRoLYg== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 26 12:10:56 CEST 2013 Valid to: Fri Oct 04 12:10:56 CEST 2019 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B1:37:55:65:2D:F8:29:F2:5E:0A:40:93:2D:F2:96:DB:4C:71:16:5C:4E:2A:FB:9A:82:EB:FE:72:3D:65:68:13:EA:5C:7 1:BB:A5:22:D7:CF:EF:D3:E4:46:8D:C5:66:94:42:80:1C:7C:05:3F:E9:C1:27:DD:D1:5B:93:3A:91:E6:E5:B7:93:4C:69:29:1E:09:F3:05:0D:DB:2D:29:0C:B6:B5:12:C9:D6:DC:18:94:AF:EA:1F:6D:04:BA:53:76:CA:75:B0:0B: F2:67:24:A5:1C:F2:33:D1:65:5B:60:44:2C:7B:6C:56:6F:F4:75:49:AB:11:45:FC:4E:4A:C8:BD:C8:6B:26:2A:18:FD:8E:44:CD:B3:51:53:85:45:5F:2F:5F:5D:D1:1E:F5:AD:7F:67:A5:B3:75:E8:7D:91:6E:07:70:14:04:41:33:EC :2C:C4:92:A0:55:ED:F9:46:75:03:74:17:5B:E2:3E:AC:48:06:01:0F:BA:11:27:0C:21:68:31:39:DE:0F:73:36:2E:84:68:FF:96:69:5C:E3:77:14:09:88:2F:81:F2:DA:B0:8E:41:DC:5E:77:5E:BA:24:01:9B:66:5F:71:0E:66:23:33:10 :DE:09:57:F4:CF:94:BD:4D:D4:D0:9E:10:BF:81:D4:64:6B:E2:FC:4A:5E:AB:15:AD:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 159 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier EF:D0:76:60:5A:73:68:E6:38:98:48:A4:E2:DF:5B:6E:AD:D0:8B:1C Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 21:A6:D9:3B:46:25:57:3C:A9:74:84:DE:4B:CB:ED:17:64:87:04:28:E6:59:0C:DF:EC:A4:98:F5:C4: 62:3F:74 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.26.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (48) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (48) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 160 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I 79B2YFpzaOY4mEik4t9bbq3Qixw= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-08-26T09:10:00Z 159.27 - Service (withdrawn): (49) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (49) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (49) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1497761 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 161 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFtqhMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMzA4MjYxMDEyMTZaFw0xOTEwMDQxMDEyMTZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDCeka8Pp2GEn1N6fydw3OXt88e uaF5Z+iVwk2zCJWEPGJlxtVCMW6no0tiyEAVzf3hVDIei4iu3eVBQdsnO9fKPy9zikRixVA1m88F LHbVf/A1aRyOuZkD6FBmU2hNwGhIqnv59T2r/IFd5Uamio7sSD1t+6OApms54LRhJN69tp2DANgw PleJg3deKcxKM02X/hPfdhJPfrTy+6BXDm6kqLrQeiEohE9alfroRHmXcGdYk+ny6aNaji+w1Tlm AjVcVYDv1nRe9O1+hoy2vNIxYyk+cDewsPXlkYVJKNWACf8roWKTZAVrNK8MFbLzxeEw8XB3d9iZ xTkrJpm39ebnAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBQnsKdTQDOBHNV3v2CdSfmUKXNTnzANBgkqhkiG9w0BAQsFAAOCAQEAI4OiU1EU gTXY4KiG8AvnxxjtHmbWngAxiMXJF8cjtlmKiQkkeFSJE2vMaXJi742qSV8BZtQd72wzF9VyABrc hTijAYn0NjZKjedMoaI6DStvQSeXmal8gKGwSFWPn2ffTLuKU4d03pJOqlcM5wxMDe7lBPzd8vGf 2xkk8cxD0juUW2o6KhAkCvT4rKHtrXaWrE30L3g7X7TvngacBBqv7Fa0V+6ibV8ittN1IhpR5hEH 7jXmPo9RfKP21nwwKQHm4HVag7pDczREOU4/7fmwtb0TA17CbpT9o3P0YR0vuq5up/4stlP2e6tr RtSouarvjfnVVix9962nPCsEsGnOfg== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 26 12:12:16 CEST 2013 Valid to: Fri Oct 04 12:12:16 CEST 2019 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C2:7A:46:BC:3E:9D:86:12:7D:4D:E9:FC:9D:C3:73:97:B7:CF:1E:B9:A1:79:67:E8:95:C2:4D:B3:08:95:84:3C:62:65: C6:D5:42:31:6E:A7:A3:4B:62:C8:40:15:CD:FD:E1:54:32:1E:8B:88:AE:DD:E5:41:41:DB:27:3B:D7:CA:3F:2F:73:8A:44:62:C5:50:35:9B:CF:05:2C:76:D5:7F:F0:35:69:1C:8E:B9:99:03:E8:50:66:53:68:4D:C0:68:48:AA:7B:F 9:F5:3D:AB:FC:81:5D:E5:46:A6:8A:8E:EC:48:3D:6D:FB:A3:80:A6:6B:39:E0:B4:61:24:DE:BD:B6:9D:83:00:D8:30:3E:57:89:83:77:5E:29:CC:4A:33:4D:97:FE:13:DF:76:12:4F:7E:B4:F2:FB:A0:57:0E:6E:A4:A8:BA:D0:7A :21:28:84:4F:5A:95:FA:E8:44:79:97:70:67:58:93:E9:F2:E9:A3:5A:8E:2F:B0:D5:39:66:02:35:5C:55:80:EF:D6:74:5E:F4:ED:7E:86:8C:B6:BC:D2:31:63:29:3E:70:37:B0:B0:F5:E5:91:85:49:28:D5:80:09:FF:2B:A1:62:93:64:05 :6B:34:AF:0C:15:B2:F3:C5:E1:30:F1:70:77:77:D8:99:C5:39:2B:26:99:B7:F5:E6:E7:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 162 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 27:B0:A7:53:40:33:81:1C:D5:77:BF:60:9D:49:F9:94:29:73:53:9F Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 29:53:83:62:52:4D:53:10:77:A4:81:7D:1B:58:4D:6F:68:A5:D4:E6:7E:65:B8:AA:7B:AE:2A:96:61: 66:30:1D Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.27.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (49) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (49) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 163 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I J7CnU0AzgRzVd79gnUn5lClzU58= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-08-26T09:12:00Z 159.28 - Service (withdrawn): (50) PostSignum - Qualified Time Stamping Authority, TSU 4 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (50) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (50) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1497763 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 164 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFtqjMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMzA4MjYxMDE0MDZaFw0xOTEwMDQxMDE0MDZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC2jvCDoLJ3Y/DUH70YGbFWfZee SP33a6DJ/S0QcXFtv0yytaJbCaA9dpquaiJUkl31LBo3MsPZQwy/ytH20Cl3cjJRpe/CpPJfYCQC j9LEi8UvDbD+CIba+wlZNOmZBO1lD0GDJ2tqzZmwdDCNLcK+JG5RYEq7S3sjqTwo8YZYn2MiaDJ9 ePitV9tlAlQrpZ52vVIeY16eRWJiyV1Tz3GTdIp2hOlROYyyYTFo+jPGF/rlQAOt7G9DkZLtbD1t iZuijaRL6Cfd5x8IH0JjVahy4AfNnCsVSEwC85kWldLkGHOFE2JwpWnDZq/NOQahqH7Z8oZ0h537 mlZUPhqb3dW9AgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBSCdfydiM/NAxxUg1l+Za+4fmn4YTANBgkqhkiG9w0BAQsFAAOCAQEAK5qCOWBX FMjg4uGkvWruWTRpNLBHXDgcYpHPZjaPYI+eUGOI0Ss6hNyNz1g7v38O6mf+G3dwGVhxg6/k96UV tKWqabSJXH+3y2t4Gju/D35Rd0Sdq9/lphqvR7SpCrxw3xEGKIeBQw+YKo1NhoEd2+7gEBRRyLw3 NTIX5QeYsyxCu/VRTdJrqPTeJGtlPj1chKVHyAuS+3emILpM5Re7xVJyDwkr0JtAy7DDJdyf1Pas mP3HsdIGS7/yT0rBAyBqv2bY62AFdmXZzfYviMI8eRqcrruXFRj5XFX8bl9JjwI8kVKFpysv2jG5 hrLrykI3p13D9RZ9DTIkmsoRZaGmTw== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 26 12:14:06 CEST 2013 Valid to: Fri Oct 04 12:14:06 CEST 2019 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B6:8E:F0:83:A0:B2:77:63:F0:D4:1F:BD:18:19:B1:56:7D:97:9E:48:FD:F7:6B:A0:C9:FD:2D:10:71:71:6D:BF:4C:B2: B5:A2:5B:09:A0:3D:76:9A:AE:6A:22:54:92:5D:F5:2C:1A:37:32:C3:D9:43:0C:BF:CA:D1:F6:D0:29:77:72:32:51:A5:EF:C2:A4:F2:5F:60:24:02:8F:D2:C4:8B:C5:2F:0D:B0:FE:08:86:DA:FB:09:59:34:E9:99:04:ED:65:0F:41:8 3:27:6B:6A:CD:99:B0:74:30:8D:2D:C2:BE:24:6E:51:60:4A:BB:4B:7B:23:A9:3C:28:F1:86:58:9F:63:22:68:32:7D:78:F8:AD:57:DB:65:02:54:2B:A5:9E:76:BD:52:1E:63:5E:9E:45:62:62:C9:5D:53:CF:71:93:74:8A:76:84:E9:5 1:39:8C:B2:61:31:68:FA:33:C6:17:FA:E5:40:03:AD:EC:6F:43:91:92:ED:6C:3D:6D:89:9B:A2:8D:A4:4B:E8:27:DD:E7:1F:08:1F:42:63:55:A8:72:E0:07:CD:9C:2B:15:48:4C:02:F3:99:16:95:D2:E4:18:73:85:13:62:70:A5:69:C 3:66:AF:CD:39:06:A1:A8:7E:D9:F2:86:74:87:9D:FB:9A:56:54:3E:1A:9B:DD:D5:BD:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 165 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 82:75:FC:9D:88:CF:CD:03:1C:54:83:59:7E:65:AF:B8:7E:69:F8:61 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 3C:CC:19:CA:FD:70:E5:86:25:0F:D9:55:EE:00:2D:CB:D6:EF:6D:A7:76:D6:B5:19:3B:47:1B:80:7 1:B9:5A:BF Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.28.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (50) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (50) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 166 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I gnX8nYjPzQMcVINZfmWvuH5p+GE= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-08-26T09:14:00Z 159.29 - Service (withdrawn): (51) PostSignum - Qualified Time Stamping Authority, TSU 5 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (51) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (51) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1497769 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 167 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFtqpMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMzA4MjYxMDE1MTZaFw0xOTEwMDQxMDE1MTZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCS6Ss6yz45hdTxKm4IRUfPV0gt gSSGpplsfxA/5BKCv4eJiojE/fLfQr8k8InGuzOwuxbUVoWzuaSnhrX9TCHSjySe1PHTXCF5fxqH G3yFzJhvdED/dF/SG2mFspywsXwjeKoDc5pPnJo4OMQ7w5adRq3fFOZlsutdinrJSjqOPESr0tTI fb+TLeTSx93UJY70deiRULwptvBizjHHOleFPI0whpUgH8xotOg24//n0f9hsdtVPjY0PqshaSKG hax9z/bJEORLBNSrHqrApzTPlHvY/fRM/mCGc1JokajgzOq+u3Pdnz9mmTv4cSilbkLsGNy3LB8R +4d0ZiNuF3OrAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBQsLp0e8s/2kgwqwhM302leBMTzVDANBgkqhkiG9w0BAQsFAAOCAQEAaaDTYS/Q Py9v4YFU/S9FPBkV6a7b8ZHoCwc0WYVWJQqjnvyOcVuK/zOFUntozvnJbbsvnsXNet5NDKElfrJ1 x2MYnBTnBn/OQQ+HGdVLr6ZNJTyvGdR4O54Q3NJQKLnF6JwkGHx5JkzxyDqbwR9+i4ojCtLfSkxY 33OQiKDKd4PFNs/ZaLonT9LaytZy19heZLl57jG0OTGYV68iR2169dcHJsCHXwsRZ72872FfYzvf EG9MP2jGrBe2NNkcvuKClmg0tSSyrDXqgAYYvsgm6mbbSm6zP7O4fNNkIQWSdVw2gX2Vo0trQBAK ZT+Ov5vCMWMrwnv6zvu/h3gvp4T94A== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 26 12:15:16 CEST 2013 Valid to: Fri Oct 04 12:15:16 CEST 2019 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:92:E9:2B:3A:CB:3E:39:85:D4:F1:2A:6E:08:45:47:CF:57:48:2D:81:24:86:A6:99:6C:7F:10:3F:E4:12:82:BF:87:89:8A: 88:C4:FD:F2:DF:42:BF:24:F0:89:C6:BB:33:B0:BB:16:D4:56:85:B3:B9:A4:A7:86:B5:FD:4C:21:D2:8F:24:9E:D4:F1:D3:5C:21:79:7F:1A:87:1B:7C:85:CC:98:6F:74:40:FF:74:5F:D2:1B:69:85:B2:9C:B0:B1:7C:23:78:AA:03:7 3:9A:4F:9C:9A:38:38:C4:3B:C3:96:9D:46:AD:DF:14:E6:65:B2:EB:5D:8A:7A:C9:4A:3A:8E:3C:44:AB:D2:D4:C8:7D:BF:93:2D:E4:D2:C7:DD:D4:25:8E:F4:75:E8:91:50:BC:29:B6:F0:62:CE:31:C7:3A:57:85:3C:8D:30:86:9 5:20:1F:CC:68:B4:E8:36:E3:FF:E7:D1:FF:61:B1:DB:55:3E:36:34:3E:AB:21:69:22:86:85:AC:7D:CF:F6:C9:10:E4:4B:04:D4:AB:1E:AA:C0:A7:34:CF:94:7B:D8:FD:F4:4C:FE:60:86:73:52:68:91:A8:E0:CC:EA:BE:BB:73:DD :9F:3F:66:99:3B:F8:71:28:A5:6E:42:EC:18:DC:B7:2C:1F:11:FB:87:74:66:23:6E:17:73:AB:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 168 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier 2C:2E:9D:1E:F2:CF:F6:92:0C:2A:C2:13:37:D3:69:5E:04:C4:F3:54 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 9D:07:E2:26:B1:E4:52:B7:C7:6E:90:73:6C:E2:4B:57:99:89:B2:41:FC:F0:65:F5:45:A8:72:D3:5C:B E:05:C0 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.29.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (51) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (51) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 169 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I LC6dHvLP9pIMKsITN9NpXgTE81Q= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-08-26T09:15:00Z 159.30 - Service (withdrawn): (52) PostSignum - Qualified Time Stamping Authority, TSU 6 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (52) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (52) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1497773 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 170 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDFtqtMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMjAeFw0xMzA4MjYxMDE2MjRaFw0xOTEwMDQxMDE2MjRaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDhDHhr9EKFUixGioQzDGUQkPHS bhRgvx5wvGD0hYnnDWBO/MJrZ6kuv0h8XJabuSrHjQZ8a3gnIIPboWp5/1PTRiKcKRjRHSykY+Ut P0Dl+8zWy0A0SCoF9Ook3Mz1CG0Y1e5XeDf8ZJFYAeuLePSOFjXFX/+w8bCk4FlsF124mWcQIkL3 Q5xDqlhecmgcrQQh+l5TKcCI/ruoSpClJUWl9YQObU2Qm1AkrXg2Fb7TTUgcWJRJ/hMvtL+BPIzX wItHqdNcE1iGrdlWRsfXOgwKKB7pKu87ivg6a9JmziNmxPwqf+AhQGj/VZAKNBfz/VECf3XTgEPg Dt1YqKKl2I8hAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYECMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EyLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMi5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFInoTN+LJjk+1yQuEg565+Yn5daXMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTIu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMi5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTIuY3Js MB0GA1UdDgQWBBTmvK1NFplYdbc5vWIgqMCkZiW6WTANBgkqhkiG9w0BAQsFAAOCAQEAGM0qR6w+ ic1rZiBTQrd07JxN0rZDsPsAznuJafMEEFSog7M3WYv27icR5gF2tEmvHNoGq7wJSAwBk3hwr2jZ jezIosO6F0/TeHrmsnn237kSnBdvhxxfKTglU8MpCN8gPtPm4a2Pq3zjkzDZ1Nn9sOtks1Om6JkJ D45dAooOHhUGvshhPUKLEikHY3ZPJSg3FV5k+c7Tz2hZUYFP5PCbHSPhihHZl3oRHHw85u1bT3sm PZ/Nh6o1ewMseC+c9fTNieyM2vgv6UxMuEMNuRJozrQIVR5JcpBYxY0DUb+GsGSg4Bm5F+hlbTGa Aha99FinWg/FpoffUxSB9JT4vAv8HA== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 26 12:16:24 CEST 2013 Valid to: Fri Oct 04 12:16:24 CEST 2019 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:E1:0C:78:6B:F4:42:85:52:2C:46:8A:84:33:0C:65:10:90:F1:D2:6E:14:60:BF:1E:70:BC:60:F4:85:89:E7:0D:60:4E:FC: C2:6B:67:A9:2E:BF:48:7C:5C:96:9B:B9:2A:C7:8D:06:7C:6B:78:27:20:83:DB:A1:6A:79:FF:53:D3:46:22:9C:29:18:D1:1D:2C:A4:63:E5:2D:3F:40:E5:FB:CC:D6:CB:40:34:48:2A:05:F4:EA:24:DC:CC:F5:08:6D:18:D5:EE:57 :78:37:FC:64:91:58:01:EB:8B:78:F4:8E:16:35:C5:5F:FF:B0:F1:B0:A4:E0:59:6C:17:5D:B8:99:67:10:22:42:F7:43:9C:43:AA:58:5E:72:68:1C:AD:04:21:FA:5E:53:29:C0:88:FE:BB:A8:4A:90:A5:25:45:A5:F5:84:0E:6D:4D:90: 9B:50:24:AD:78:36:15:BE:D3:4D:48:1C:58:94:49:FE:13:2F:B4:BF:81:3C:8C:D7:C0:8B:47:A9:D3:5C:13:58:86:AD:D9:56:46:C7:D7:3A:0C:0A:28:1E:E9:2A:EF:3B:8A:F8:3A:6B:D2:66:CE:23:66:C4:FC:2A:7F:E0:21:40:68: FF:55:90:0A:34:17:F3:FD:51:02:7F:75:D3:80:43:E0:0E:DD:58:A8:A2:A5:D8:8F:21:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.130 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca2.crt http://www2.postsignum.cz/crt/psqualifiedca2.crt http://postsignum.ttc.cz/crt/psqualifiedca2.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier 89:E8:4C:DF:8B:26:39:3E:D7:24:2E:12:0E:7A:E7:E6:27:E5:D6:97 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 171 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca2.crl http://www2.postsignum.cz/crl/psqualifiedca2.crl http://postsignum.ttc.cz/crl/psqualifiedca2.crl Subject Key Identifier E6:BC:AD:4D:16:99:58:75:B7:39:BD:62:20:A8:C0:A4:66:25:BA:59 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 53:01:3F:9C:42:29:30:D8:79:26:11:9C:F5:81:74:F3:2D:9C:B8:60:04:20:73:C2:FD:C9:F7:EB:9E:C 4:94:EE Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.30.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (52) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (52) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 172 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I 5rytTRaZWHW3Ob1iIKjApGYlulk= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2013-08-26T09:16:00Z 159.31 - Service (granted): (57) PostSignum - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (57) PostSignum - issuing qualified certificates Name [ cs ] (57) PostSignum - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 164 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 173 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGYDCCBUigAwIBAgICAKQwDQYJKoZIhvcNAQELBQAwWzELMAkGA1UEBhMCQ1oxLDAqBgNVBAoM I8SMZXNrw6EgcG/FoXRhLCBzLnAuIFtJxIwgNDcxMTQ5ODNdMR4wHAYDVQQDExVQb3N0U2lnbnVt IFJvb3QgUUNBIDIwHhcNMTQwMzI2MDgwMTMyWhcNMjQwMzI2MDcwMDM2WjBfMQswCQYDVQQGEwJD WjEsMCoGA1UECgwjxIxlc2vDoSBwb8WhdGEsIHMucC4gW0nEjCA0NzExNDk4M10xIjAgBgNVBAMT GVBvc3RTaWdudW0gUXVhbGlmaWVkIENBIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB AQCXOu7d2frODVCZuo7IEWxoF5f1KE9aelb8FUyoZCL6iyvBe7YaL1pH4FJ5DPFbf3mz6rLnSiDY /YSpipstdNUHM2BZkhiEulb7ltvMC+v4gf+H9ApVkmNspEWcO8+Thj4bm0anXJ8oFKRCkPQYAPQQ yRq0erqlXTkXS4NePI0TU4mvtaokZCqBBqzP6GnXOvZAzxo/KkK7nvgEwibZEXnrI3ZN20dzmvT/ m+igHsPfBuTJsRXO1ytqxD+xz8L9eoAXyOWbQTLJI9FXE3utZ9fr0mhEUc0xcaQfVwdGahJ6/ex1 asZH7XFD2VyHaTSqXomDiyo71Zp0EnGjdLACkUtdAgMBAAGjggMoMIIDJDCB8QYDVR0gBIHpMIHm MIHjBgRVHSAAMIHaMIHXBggrBgEFBQcCAjCByhqBx1RlbnRvIGt2YWxpZmlrb3Zhbnkgc3lzdGVt b3Z5IGNlcnRpZmlrYXQgYnlsIHZ5ZGFuIHBvZGxlIHpha29uYSAyMjcvMjAwMFNiLiBhIG5hdmF6 bnljaCBwcmVkcGlzdS9UaGlzIHF1YWxpZmllZCBzeXN0ZW0gY2VydGlmaWNhdGUgd2FzIGlzc3Vl ZCBhY2NvcmRpbmcgdG8gTGF3IE5vIDIyNy8yMDAwQ29sbC4gYW5kIHJlbGF0ZWQgcmVndWxhdGlv bnMwEgYDVR0TAQH/BAgwBgEB/wIBADCBvAYIKwYBBQUHAQEEga8wgawwNwYIKwYBBQUHMAKGK2h0 dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcnQvcHNyb290cWNhMi5jcnQwOAYIKwYBBQUHMAKGLGh0 dHA6Ly93d3cyLnBvc3RzaWdudW0uY3ovY3J0L3Bzcm9vdHFjYTIuY3J0MDcGCCsGAQUFBzAChito dHRwOi8vcG9zdHNpZ251bS50dGMuY3ovY3J0L3Bzcm9vdHFjYTIuY3J0MA4GA1UdDwEB/wQEAwIB BjCBgwYDVR0jBHwweoAUFSmMxUVpq7izw+r+S7gx2Nzw53ahX6RdMFsxCzAJBgNVBAYTAkNaMSww KgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEeMBwGA1UEAxMVUG9z dFNpZ251bSBSb290IFFDQSAyggFkMIGlBgNVHR8EgZ0wgZowMaAvoC2GK2h0dHA6Ly93d3cucG9z dHNpZ251bS5jei9jcmwvcHNyb290cWNhMi5jcmwwMqAwoC6GLGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3JsL3Bzcm9vdHFjYTIuY3JsMDGgL6AthitodHRwOi8vcG9zdHNpZ251bS50dGMuY3ov Y3JsL3Bzcm9vdHFjYTIuY3JsMB0GA1UdDgQWBBTy+MwqV2HaKxczWeWCLewGHIpPSjANBgkqhkiG 9w0BAQsFAAOCAQEAVHG9oYU7dATQI/yVgwhboNVX9Iat8Ji6PvVnoM6TQ8WjUQ5nErZG1fV5QQgN 7slMBWnXKNjUSxMDpfhtN2RbJHniaw/+vDqKtlmoKAnmIRzRaIqBLwGZs6RGHFrMPiol3La55fBo a4JPliRTFw5xVOK5FdJh/5Pbfg+XNZ0RzO0/tk/oKRXfgRNb9ZBL2pe8sr9g9QywpsGKt2gP9t0q /+dhKAGc0+eimChM8Bmq4WNUxK4qdo4ARH6344uIVlIu+9Gq3H54noyZd/OhRTnuoXuQOdx9DooT p6SPpPfZXj/djsseT22QVpYBP7v8AVK/paqphINL2XmQdiw65KhDYA== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Root QCA 2 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum Qualified CA 3 Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Mar 26 09:01:32 CET 2014 Valid to: Tue Mar 26 08:00:36 CET 2024 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:97:3A:EE:DD:D9:FA:CE:0D:50:99:BA:8E:C8:11:6C:68:17:97:F5:28:4F:5A:7A:56:FC:15:4C:A8:64:22:FA:8B:2B:C1 :7B:B6:1A:2F:5A:47:E0:52:79:0C:F1:5B:7F:79:B3:EA:B2:E7:4A:20:D8:FD:84:A9:8A:9B:2D:74:D5:07:33:60:59:92:18:84:BA:56:FB:96:DB:CC:0B:EB:F8:81:FF:87:F4:0A:55:92:63:6C:A4:45:9C:3B:CF:93:86:3E:1B:9B:46: A7:5C:9F:28:14:A4:42:90:F4:18:00:F4:10:C9:1A:B4:7A:BA:A5:5D:39:17:4B:83:5E:3C:8D:13:53:89:AF:B5:AA:24:64:2A:81:06:AC:CF:E8:69:D7:3A:F6:40:CF:1A:3F:2A:42:BB:9E:F8:04:C2:26:D9:11:79:EB:23:76:4D:DB: 47:73:9A:F4:FF:9B:E8:A0:1E:C3:DF:06:E4:C9:B1:15:CE:D7:2B:6A:C4:3F:B1:CF:C2:FD:7A:80:17:C8:E5:9B:41:32:C9:23:D1:57:13:7B:AD:67:D7:EB:D2:68:44:51:CD:31:71:A4:1F:57:07:46:6A:12:7A:FD:EC:75:6A:C6:47 :ED:71:43:D9:5C:87:69:34:AA:5E:89:83:8B:2A:3B:D5:9A:74:12:71:A3:74:B0:02:91:4B:5D:02:03:01:00:01 Policy OID: 2.5.29.32.0 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] Basic Constraints IsCA: true - Path length: 0 Authority Info Access http://www.postsignum.cz/crt/psrootqca2.crt http://www2.postsignum.cz/crt/psrootqca2.crt http://postsignum.ttc.cz/crt/psrootqca2.crt Authority Key Identifier 15:29:8C:C5:45:69:AB:B8:B3:C3:EA:FE:4B:B8:31:D8:DC:F0:E7:76 CRL Distribution Points http://www.postsignum.cz/crl/psrootqca2.crl http://www2.postsignum.cz/crl/psrootqca2.crl http://postsignum.ttc.cz/crl/psrootqca2.crl Subject Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 174 ETSI 2014 - TSL HR - PDF/A-1b generator Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: D3:5E:25:0C:B0:2E:27:BB:3F:C5:2D:1F:1A:0D:FD:88:FA:98:13:BE:1B:77:73:20:AA:E9:12:B5:4 E:3B:1F:02 Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted Service status description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.31.1 - Extension (critical): Qualifiers [QCQSCDStatusAsInCert] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert Criteria list assert=atLeastOne Policy Identifier nodes: Identifier CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ 2.23.134.1.4.1.7.300 Page 175 ETSI 2014 - TSL HR - PDF/A-1b generator Policy Identifier nodes: Identifier 2.23.134.1.4.1.17.100 159.31.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 159.31.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (57) PostSignum - issuing qualified certificates Name [ cs ] (57) PostSignum - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject CN: PostSignum Qualified CA 3 Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I 8vjMKldh2isXM1nlgi3sBhyKT0o= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2014-03-26T08:01:32Z 159.31.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 176 ETSI 2014 - TSL HR - PDF/A-1b generator [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 177 ETSI 2014 - TSL HR - PDF/A-1b generator Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 2.23.134.1.4.1.7.300 159.32 - Service (withdrawn): (58) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (58) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (58) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000203 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 178 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLceLMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNDA4MjUxMDU5MjhaFw0yMDEwMDIxMDU5MDZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChHYiAXyubz/EruYTdVmlh+2+G fvFVgE3KAIF5xV9ouctj+Yx5vNcnWmUa8OB2sow3QUdmW7dxpuHito1vIC4jmIPVKMzQyPg+hufE mB+6TWOxqEGK6p8/Aglw6IoQQgbtCbrGnQ11HpwCk1eq0WhAN0TOLjOY5Myd8TYBuxXKdGUBAHw+ 7LZGqFakbnzL6eZm1gO/5E5jpo1Mns31MMB0qq51TmN2VhKTi/as/a1gAn8qsryOjZEfxmdC2efJ WD54FSHiwM+NIaHCKYMvVPZcaIga55eKNqaRqMpJtbc/OFTegwU/vqTwELkY+B290d1De3/S+ZIc BiitVE80JPvHAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBSshQeX9Y+FhGOQks6xhauAS7V6nTANBgkqhkiG9w0BAQsFAAOCAQEABdUy0Sln dlZv3CZykm++kK4eFDkNVOtO7fX1Y/WXP6uABM5FS1qzRAKIfhJLPgPtHPWR5srQSSEWmmHz//vu 3xmwZjY1yMiRA6Qwcj5G+WI2ChUUPP3n2eYLueFxe1n5RUlSSPbAN08zMZooWMPOom38GwUz3O2a z2nsWtKIDQLe6U0tOW3xeEJovazoNFFl9tVc47bXwSqDbVcKBDKc/dVln+6k3D27q3DyOCkTJIFa kaL74mjRhN1JdwCfNuvfg6nkpBaduz9sprhnhndgVV4AQaCD52UKHt22mrQI4aHsf+MiYTnuk5Sn /F3B184PprWOfZ746aNYCKfpYxfNtA== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 25 12:59:28 CEST 2014 Valid to: Fri Oct 02 12:59:06 CEST 2020 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:A1:1D:88:80:5F:2B:9B:CF:F1:2B:B9:84:DD:56:69:61:FB:6F:86:7E:F1:55:80:4D:CA:00:81:79:C5:5F:68:B9:CB:63:F 9:8C:79:BC:D7:27:5A:65:1A:F0:E0:76:B2:8C:37:41:47:66:5B:B7:71:A6:E1:E2:B6:8D:6F:20:2E:23:98:83:D5:28:CC:D0:C8:F8:3E:86:E7:C4:98:1F:BA:4D:63:B1:A8:41:8A:EA:9F:3F:02:09:70:E8:8A:10:42:06:ED:09:BA:C6: 9D:0D:75:1E:9C:02:93:57:AA:D1:68:40:37:44:CE:2E:33:98:E4:CC:9D:F1:36:01:BB:15:CA:74:65:01:00:7C:3E:EC:B6:46:A8:56:A4:6E:7C:CB:E9:E6:66:D6:03:BF:E4:4E:63:A6:8D:4C:9E:CD:F5:30:C0:74:AA:AE:75:4E:63: 76:56:12:93:8B:F6:AC:FD:AD:60:02:7F:2A:B2:BC:8E:8D:91:1F:C6:67:42:D9:E7:C9:58:3E:78:15:21:E2:C0:CF:8D:21:A1:C2:29:83:2F:54:F6:5C:68:88:1A:E7:97:8A:36:A6:91:A8:CA:49:B5:B7:3F:38:54:DE:83:05:3F:BE:A 4:F0:10:B9:18:F8:1D:BD:D1:DD:43:7B:7F:D2:F9:92:1C:06:28:AD:54:4F:34:24:FB:C7:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 179 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier AC:85:07:97:F5:8F:85:84:63:90:92:CE:B1:85:AB:80:4B:B5:7A:9D Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: F0:90:18:6C:07:69:F6:FF:B0:1D:80:13:3E:FF:F6:CB:33:EF:E5:7F:26:85:0A:94:D6:4B:A2:AF:01: A7:F6:83 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.32.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (58) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (58) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 180 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I rIUHl/WPhYRjkJLOsYWrgEu1ep0= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2014-08-25T10:59:28Z 159.33 - Service (withdrawn): (59) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (59) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (59) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000204 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 181 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLceMMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNDA4MjUxMTA5MTBaFw0yMDEwMDIxMTA4MzlaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCsQzlahOaIfSLbk8lCt4we/hC9 uCq7psz4/zRoFu9sqE7lYnknfwTHU4/0I8woyFFM1p0zzCqh4JGJE/HCbdspj5BDQzAGD0RffL9/ 27Xs6qGBQ4biDnHUcYyhwNtwNWbHY8Kn3ggkVy71X3EeIPghr1ytbvE3J80055yHIyfV1gywjf2C roDrRcQ9rKfPVhIGnlqXI4KkYgWMcYy7gUpU4v426AzJRHF1hwux7rIRorcg2s1f6BcE/5YI2+U+ mp8WF45NcX57Ok7qul535ze70FTt+LlSUN4EUC6F6gmwHlHjxKYYNbR+yj0jm9pBSFfyPQscRuLg M9XrBHuHyoobAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBRqPA6jNi/oIltl0ZG/KPzFAamxDjANBgkqhkiG9w0BAQsFAAOCAQEAfDM2wiZs AFjoZ1/THRvcOfjyMZwwYhgS4HgyeN7Mtw/pnFu+LA2HdVwLwX53maVuWDXh4Ne9eqZ6SkiqP2qp LyC8d29F2ZKnDie+e2klziLvDi/nbevSHQum3m0V3zj1zRsOn9InbHnUxxWoFE2/jnlvKCdVNlLh gZ5kxI7PCoQdTGxlR/kzClHbVCAo5L3ugER3KYBZ5Ms7Lb1Th38wGO/hdbiOc2nGylojfB03ZiBo yPj6c0zf69Uj6kzMavB6DZKw++PVS4jGXsLX8pWZI2T5Jh2CxdVyIS3/Qo1x7sQCWm4UL78BpURM UlXpaiWCslQ2cWhYa1DkGB54ouT07A== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 25 13:09:10 CEST 2014 Valid to: Fri Oct 02 13:08:39 CEST 2020 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:AC:43:39:5A:84:E6:88:7D:22:DB:93:C9:42:B7:8C:1E:FE:10:BD:B8:2A:BB:A6:CC:F8:FF:34:68:16:EF:6C:A8:4E:E5 :62:79:27:7F:04:C7:53:8F:F4:23:CC:28:C8:51:4C:D6:9D:33:CC:2A:A1:E0:91:89:13:F1:C2:6D:DB:29:8F:90:43:43:30:06:0F:44:5F:7C:BF:7F:DB:B5:EC:EA:A1:81:43:86:E2:0E:71:D4:71:8C:A1:C0:DB:70:35:66:C7:63:C2:A 7:DE:08:24:57:2E:F5:5F:71:1E:20:F8:21:AF:5C:AD:6E:F1:37:27:CD:34:E7:9C:87:23:27:D5:D6:0C:B0:8D:FD:82:AE:80:EB:45:C4:3D:AC:A7:CF:56:12:06:9E:5A:97:23:82:A4:62:05:8C:71:8C:BB:81:4A:54:E2:FE:36:E8:0C :C9:44:71:75:87:0B:B1:EE:B2:11:A2:B7:20:DA:CD:5F:E8:17:04:FF:96:08:DB:E5:3E:9A:9F:16:17:8E:4D:71:7E:7B:3A:4E:EA:BA:5E:77:E7:37:BB:D0:54:ED:F8:B9:52:50:DE:04:50:2E:85:EA:09:B0:1E:51:E3:C4:A6:18:35: B4:7E:CA:3D:23:9B:DA:41:48:57:F2:3D:0B:1C:46:E2:E0:33:D5:EB:04:7B:87:CA:8A:1B:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 182 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 6A:3C:0E:A3:36:2F:E8:22:5B:65:D1:91:BF:28:FC:C5:01:A9:B1:0E Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: FB:B6:6F:6E:46:DA:4B:CF:38:13:80:C1:51:FE:70:53:EC:CD:62:47:19:28:7B:A4:07:9E:2E:B8:F1: 8A:7A:B8 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.33.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (59) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (59) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 183 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I ajwOozYv6CJbZdGRvyj8xQGpsQ4= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2014-08-25T11:09:10Z 159.34 - Service (withdrawn): (60) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (60) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (60) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000205 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 184 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLceNMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNDA4MjUxMTEwMjBaFw0yMDEwMDIxMTEwMDVaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCe/BqSAP6CHdPXdJeGe7oNIzEM 86NdQuX3JUfh5AZIjUAsruKSWqCpENAuKeOiSX/WkvS9K3FbvmVXlYyevOssefv8Ak1qbwYrcZoU nd5pDbTMy4ZZ87ph/0myr8yVuEEjnJSD5JME4tGJoQ5zVnxPqlHToAiXCuyjZ4/9dUe9rzbVs7PG JaCLpDUmkWTvQ1oKN7eOtXlbrP2FMqNLRZNXp4pTe2tI07RmJmS0jEr8md/2O+ty0uqB/wQe2aIm 2w7QKmfzZkSeBA+/L+2A3jqbKtpn+LHUtHxuEjrVCFGkZWn83Xvrq70qddd7oov89VbSurbZlaM3 Gu619pwFcGflAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBSB8VaJg/xs/n5+eekom0LAoKyeOjANBgkqhkiG9w0BAQsFAAOCAQEAZP/QOwiz iDAUlxjOD7AAKZzTRlP02HoSsQrkD5L1lwU6TY4alMS7AX4DVWDmXZ5S4owhRaGJIyUK2uyR+As2 T33HtycZi2hcE9wpUYgvSU5Qv2OqnGiylJQcn+8178LmKipd5WKy3rASM9veW03dG6h7ww9SxgkE 9UfeSPSlqSxDK/AN2yEF37TIw/xoSo9lrulfJdfhCKsno/5SsPGPJSaGGH1bJPj/lbfJc/kVZNdJ 4q4rjYoWFv5Bna05jvvQ+WHahRnQ6j3Rt4UvV8kAakL4+ZamY1dWLPZwn1f6Dnscsi7ySuhFhA1A ElGpZsAsYFqLTA8u32Q793W/F4xstQ== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 25 13:10:20 CEST 2014 Valid to: Fri Oct 02 13:10:05 CEST 2020 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:9E:FC:1A:92:00:FE:82:1D:D3:D7:74:97:86:7B:BA:0D:23:31:0C:F3:A3:5D:42:E5:F7:25:47:E1:E4:06:48:8D:40:2C:A E:E2:92:5A:A0:A9:10:D0:2E:29:E3:A2:49:7F:D6:92:F4:BD:2B:71:5B:BE:65:57:95:8C:9E:BC:EB:2C:79:FB:FC:02:4D:6A:6F:06:2B:71:9A:14:9D:DE:69:0D:B4:CC:CB:86:59:F3:BA:61:FF:49:B2:AF:CC:95:B8:41:23:9C:94: 83:E4:93:04:E2:D1:89:A1:0E:73:56:7C:4F:AA:51:D3:A0:08:97:0A:EC:A3:67:8F:FD:75:47:BD:AF:36:D5:B3:B3:C6:25:A0:8B:A4:35:26:91:64:EF:43:5A:0A:37:B7:8E:B5:79:5B:AC:FD:85:32:A3:4B:45:93:57:A7:8A:53:7B: 6B:48:D3:B4:66:26:64:B4:8C:4A:FC:99:DF:F6:3B:EB:72:D2:EA:81:FF:04:1E:D9:A2:26:DB:0E:D0:2A:67:F3:66:44:9E:04:0F:BF:2F:ED:80:DE:3A:9B:2A:DA:67:F8:B1:D4:B4:7C:6E:12:3A:D5:08:51:A4:65:69:FC:DD:7B: EB:AB:BD:2A:75:D7:7B:A2:8B:FC:F5:56:D2:BA:B6:D9:95:A3:37:1A:EE:B5:F6:9C:05:70:67:E5:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 185 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 81:F1:56:89:83:FC:6C:FE:7E:7E:79:E9:28:9B:42:C0:A0:AC:9E:3A Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 32:A6:A7:48:AE:A3:C3:9E:D2:EC:EA:90:02:03:50:DF:86:55:39:9F:02:79:57:DE:FC:86:B3:14:19: EF:FA:31 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.34.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (60) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (60) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 186 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I gfFWiYP8bP5+fnnpKJtCwKCsnjo= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2014-08-25T11:10:20Z 159.35 - Service (withdrawn): (61) PostSignum - Qualified Time Stamping Authority, TSU 4 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (61) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (61) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000206 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 187 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLceOMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNDA4MjUxMTExMTFaFw0yMDEwMDIxMTEwNTNaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC5sNB1/JrQyW8qb0JMC8+apRY9 lbL6g610aGPYD2FwUqbCWLrdUkHf9SK1JkjSsu+PDVvKj5lvFBJ0fLzfSNVs6rGzfHeddcrWTvZu KptYbHU193gg5PhAC4rNOZ9vbfbPHMjeqMl+3XJhE93sr7Hv+HtYlUfeSH+3ZXBreEcfQ+lM9cvf Kd3bnYtOWSanmijXRlYWnul0WgArNDNZ6S0aBydHQhozgVwPcqunuhe5kg5FSBHvJTMWY+s8E/FG ivLw8LiI3TkazYk44gP8Ud6mk5hmorR+knasbWpiRMcN3xYUaQErze/QP5q7Djdxm0qhDTQNsMcf u9KZtWhVCf4hAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBR20RoP/zyDGFc0fTxxowGGoW/1fzANBgkqhkiG9w0BAQsFAAOCAQEALyzjPawB 6EQlmGuyJJ0Mv+AXDEN2GJbgU6OUMg+00C8wWmE9km/qUnconbs3lCanw6D5rfxH8S3k8N9s7ztr xaRtb8O9cxINbvhs1ijvZiCxmrGyMLIpXcXSrnMjpsWwas/GUaZOMtfM3dt0O3BPtVEftc8Q/Cq4 H8rbiDXJ0oJdeXzlcVuQbyGwKYb+IRaW5RecwyVLVfs7RtupQa0qtohdWuLNof/hv6qC2CwMZZfl sU9QknGaeMX3XaNriuUBmBsnqsxib8bWVeefaPfulTcZAgAgzXYzy54wPTlCdU0PwtLtAx88MqMA oqyHIAkS26vPWTo86Lu9A/Yr4+Cx2w== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 25 13:11:11 CEST 2014 Valid to: Fri Oct 02 13:10:53 CEST 2020 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B9:B0:D0:75:FC:9A:D0:C9:6F:2A:6F:42:4C:0B:CF:9A:A5:16:3D:95:B2:FA:83:AD:74:68:63:D8:0F:61:70:52:A6:C2: 58:BA:DD:52:41:DF:F5:22:B5:26:48:D2:B2:EF:8F:0D:5B:CA:8F:99:6F:14:12:74:7C:BC:DF:48:D5:6C:EA:B1:B3:7C:77:9D:75:CA:D6:4E:F6:6E:2A:9B:58:6C:75:35:F7:78:20:E4:F8:40:0B:8A:CD:39:9F:6F:6D:F6:CF:1C:C 8:DE:A8:C9:7E:DD:72:61:13:DD:EC:AF:B1:EF:F8:7B:58:95:47:DE:48:7F:B7:65:70:6B:78:47:1F:43:E9:4C:F5:CB:DF:29:DD:DB:9D:8B:4E:59:26:A7:9A:28:D7:46:56:16:9E:E9:74:5A:00:2B:34:33:59:E9:2D:1A:07:27:47:4 2:1A:33:81:5C:0F:72:AB:A7:BA:17:B9:92:0E:45:48:11:EF:25:33:16:63:EB:3C:13:F1:46:8A:F2:F0:F0:B8:88:DD:39:1A:CD:89:38:E2:03:FC:51:DE:A6:93:98:66:A2:B4:7E:92:76:AC:6D:6A:62:44:C7:0D:DF:16:14:69:01:2B: CD:EF:D0:3F:9A:BB:0E:37:71:9B:4A:A1:0D:34:0D:B0:C7:1F:BB:D2:99:B5:68:55:09:FE:21:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 188 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 76:D1:1A:0F:FF:3C:83:18:57:34:7D:3C:71:A3:01:86:A1:6F:F5:7F Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: CD:3E:0F:80:88:50:D9:D8:19:D7:49:FF:49:6E:49:E6:9A:D1:83:22:75:09:C8:B2:CC:CF:B2:9C:CB :20:AF:0B Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.35.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (61) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (61) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 189 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I dtEaD/88gxhXNH08caMBhqFv9X8= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2014-08-25T11:11:11Z 159.36 - Service (withdrawn): (62) PostSignum - Qualified Time Stamping Authority, TSU 5 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (62) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (62) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000207 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 190 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLcePMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNDA4MjUxMTEyMDJaFw0yMDEwMDIxMTExNDRaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTpad/3PWpEJ0ISkfjTmr6Sz0d 45iY6qCF+BxlSE191OiODN2kce36RQPcGEwsDEyO2DOS8jAKdK2ejrYqnLxP8Xv5prfDNe6MN2Py QqOa6WSg2BkfHrCZBNj9AA2fNmnkxCv8hTdMHwm2U+FdFAjYGYT4DerD6rH74H8Rudrstf6inE/o oVp0/iCCD8ECXeUxpuDdL0uxlV++n83XahHtYt+li3FlEGXMcfpXTpsX2daCWwDS0ZO3xeIxVqad sLE9pVt6wshJhM6JoYhpt4pk0sp1swy1Q5OewmN0B8KVWzmvR2r5ocUmRStKD5ok20fK5s5ALd78 R6swX7OUip2lAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBT7DO23q8DTfY91UqRU/PLxJytJ9DANBgkqhkiG9w0BAQsFAAOCAQEAadKF0j8W K+N832ScvwQxhlGIwETNM9ObI/6td16oj9PUojaSEKUHYHzIQfqa3xvuBZGVRAO98cP9rwyIKrh3 170FeDT7JQhhdsHRJZ2HK6fKhKnFLpz2mkiEzZPsAtgYcAkkNCydLIov0qdbclLVJgcGTxf03rFD rmqMEnvc1RO+EidiRinNP3ZuJo3X3epNPiR9IUHB67RdOoH45AppJtNmqhRl7CfzPZgavxD3fulU MpeCTF/XkKSpKSyLyc8k9SNbFoatg6vaItOUl7YFxFJ58vwGrJq/EV9JKzEQkwg8ZjxfOwtgob5u GZOH9BH+rkNFmeSeL9XmiBmVPiPhhw== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 25 13:12:02 CEST 2014 Valid to: Fri Oct 02 13:11:44 CEST 2020 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:D3:A5:A7:7F:DC:F5:A9:10:9D:08:4A:47:E3:4E:6A:FA:4B:3D:1D:E3:98:98:EA:A0:85:F8:1C:65:48:4D:7D:D4:E8:8 E:0C:DD:A4:71:ED:FA:45:03:DC:18:4C:2C:0C:4C:8E:D8:33:92:F2:30:0A:74:AD:9E:8E:B6:2A:9C:BC:4F:F1:7B:F9:A6:B7:C3:35:EE:8C:37:63:F2:42:A3:9A:E9:64:A0:D8:19:1F:1E:B0:99:04:D8:FD:00:0D:9F:36:69:E4:C4: 2B:FC:85:37:4C:1F:09:B6:53:E1:5D:14:08:D8:19:84:F8:0D:EA:C3:EA:B1:FB:E0:7F:11:B9:DA:EC:B5:FE:A2:9C:4F:E8:A1:5A:74:FE:20:82:0F:C1:02:5D:E5:31:A6:E0:DD:2F:4B:B1:95:5F:BE:9F:CD:D7:6A:11:ED:62:DF: A5:8B:71:65:10:65:CC:71:FA:57:4E:9B:17:D9:D6:82:5B:00:D2:D1:93:B7:C5:E2:31:56:A6:9D:B0:B1:3D:A5:5B:7A:C2:C8:49:84:CE:89:A1:88:69:B7:8A:64:D2:CA:75:B3:0C:B5:43:93:9E:C2:63:74:07:C2:95:5B:39:AF:47:6 A:F9:A1:C5:26:45:2B:4A:0F:9A:24:DB:47:CA:E6:CE:40:2D:DE:FC:47:AB:30:5F:B3:94:8A:9D:A5:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 191 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier FB:0C:ED:B7:AB:C0:D3:7D:8F:75:52:A4:54:FC:F2:F1:27:2B:49:F4 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: BE:22:70:46:3A:BC:D3:FD:20:45:AB:EA:B1:51:55:0F:A9:64:00:29:49:9B:F3:22:82:14:D7:96:23: DB:A8:74 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.36.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (62) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (62) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 192 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I +wztt6vA032PdVKkVPzy8ScrSfQ= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2014-08-25T11:12:02Z 159.37 - Service (withdrawn): (63) PostSignum - Qualified Time Stamping Authority, TSU 6 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (63) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (63) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000208 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 193 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLceQMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNDA4MjUxMTE0MjBaFw0yMDEwMDIxMTE0MDVaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+la5pFEuLUKijlyX63PjYlTV2 z3MlmsaKeOSb5XZmU3pmP9UlK6Tm4dCAh8KUHDiejJmmaEjDR6pEXGCw3jf4aX9bq0adwqS1LCq6 TKZSQOW8dvEdYFH7Vf1XqL+SJnbEcjXVsuk9K8Ku3rLIKZ/M9vLmK7/MZ3L8omnlCQ1Xqri1WNjC OayK3tgfDt4FIA9rbIO63MWzl1gbBQspqBCwmEKH+URSmfk5visE9tby9LpOP0yrP5xI2WvxIiEy lmeSZpV0Jnu0Wcs5pRLJuK0COnBdtpBWs7ltzyUAwTJlF+p1aZkFXBrtFUabFeoqSSV2VN6FluFY sM50c5Yc0p6vAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBRUSXcC1iz8/XDtRXnbJ/z59pN8KTANBgkqhkiG9w0BAQsFAAOCAQEAIDGwd1P6 XuNPpRtxSHNsIf06V6NgY9NyWEXz4xdbnLwD4fsMef32gYuGhLmtLj4Ft119pgShX/vpafYwlPk9 36nQLjInxjA8CDZwTtV8S8tGxgeLeUuA3zUPkfx6/I7TuBqD2CzPt3RKCtZAjDskDpfk+HWWcDO/ rOYaFA8Imq6KYeQGnlZeVLzoBkbb3dZXuVZOsBTnAibRPMEkgWaxVRiH/l85xHBsqjLha5SzGQLz +sEfoSjDY1vbtbbVl6PyYweVglH4Ohn+ujFGifbDLCM82vM3oPRMB2XKj2gvGp/1WmHpe2iX4v9Q BFZMr6aukK57+aqCWB2yDOFpZO/XXQ== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Mon Aug 25 13:14:20 CEST 2014 Valid to: Fri Oct 02 13:14:05 CEST 2020 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:BE:95:AE:69:14:4B:8B:50:A8:A3:97:25:FA:DC:F8:D8:95:35:76:CF:73:25:9A:C6:8A:78:E4:9B:E5:76:66:53:7A:66:3 F:D5:25:2B:A4:E6:E1:D0:80:87:C2:94:1C:38:9E:8C:99:A6:68:48:C3:47:AA:44:5C:60:B0:DE:37:F8:69:7F:5B:AB:46:9D:C2:A4:B5:2C:2A:BA:4C:A6:52:40:E5:BC:76:F1:1D:60:51:FB:55:FD:57:A8:BF:92:26:76:C4:72:35:D 5:B2:E9:3D:2B:C2:AE:DE:B2:C8:29:9F:CC:F6:F2:E6:2B:BF:CC:67:72:FC:A2:69:E5:09:0D:57:AA:B8:B5:58:D8:C2:39:AC:8A:DE:D8:1F:0E:DE:05:20:0F:6B:6C:83:BA:DC:C5:B3:97:58:1B:05:0B:29:A8:10:B0:98:42:87:F 9:44:52:99:F9:39:BE:2B:04:F6:D6:F2:F4:BA:4E:3F:4C:AB:3F:9C:48:D9:6B:F1:22:21:32:96:67:92:66:95:74:26:7B:B4:59:CB:39:A5:12:C9:B8:AD:02:3A:70:5D:B6:90:56:B3:B9:6D:CF:25:00:C1:32:65:17:EA:75:69:99:05:5 C:1A:ED:15:46:9B:15:EA:2A:49:25:76:54:DE:85:96:E1:58:B0:CE:74:73:96:1C:D2:9E:AF:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 194 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 54:49:77:02:D6:2C:FC:FD:70:ED:45:79:DB:27:FC:F9:F6:93:7C:29 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 06:1A:A1:77:6F:2E:82:57:E7:BD:28:A9:91:2A:A1:AB:5C:25:16:EE:7C:F1:34:EC:AF:09:80:03:6C :D9:D8:2C Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.37.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (63) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (63) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 195 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I VEl3AtYs/P1w7UV52yf8+faTfCk= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2014-08-25T11:14:20Z 159.38 - Service (withdrawn): (68) PostSignum - Qualified Time Stamping Authority, TSU 1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (68) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (68) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000603 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 196 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLckbMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNTA4MjYwODMyMjhaFw0yMTEwMDMwODMxMTRaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCb75WqiO7CKDUt5DOB9zhqI38Q IDnR1HZnBwDC+68PmbviZ9HCYlgQAwK/UP2QmZWMtfUWP95c6M7+m2KVdqlMigC/YH+EcOmKM6we Ulr7wMsJOOxgPcvTKfQbtUXtpWME6z/jdmG1mjHKU62F4lYelLzbGKVkvhtSjlCyGsr5VTzi52fz pD1RkOr1KBUsjGMJg961cn2hmuKZqRFm91M0RhTmspSIRYafOjfbOrdH0tt4fjoWCL8+ZhZWP5kF l4TBFbwjwYsHKozlZQr0t9fHz+/Xuy7V1n5epV831HdXEFzErRGVltYqhUq6CeQ7rgFBc/MMTw9e 0BPuMVcwkPqzAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBQjZWoR/lNn+38iwLXpYQnik2zhCTANBgkqhkiG9w0BAQsFAAOCAQEAEDQM6U3g 8UuuyamfPVv8glntLrg4axiD+U5mjOdVyeXpfNeRgJ/v4fomObH6TuSuzTMu3tWbaqjDQmq98nRV MVmODkiCjqReV1g6T7cv+rJMzzXJ9hcmNe2UVGXRu5Dsq7Y5nBQqlMogmrYepL8K4UBdM8ykBeHC 8u41zzjM4T4r6o3Y+YM80xNQh5tD9JK/dQr1EmsHN6LePW8hS48xQzV9gzYOqvkt4Ne7zz9IkxXt Dlttq+mbv6/WcxB5TRoI/xMgCGiHSqN8PlIjhz6DoONr74FqZAfaG4nZsJ2iS0QOYpkVkKiHHx8o 5J6FCAt5MernTs7zIB1jyPCOkwKIlA== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Aug 26 10:32:28 CEST 2015 Valid to: Sun Oct 03 10:31:14 CEST 2021 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:9B:EF:95:AA:88:EE:C2:28:35:2D:E4:33:81:F7:38:6A:23:7F:10:20:39:D1:D4:76:67:07:00:C2:FB:AF:0F:99:BB:E2:67 :D1:C2:62:58:10:03:02:BF:50:FD:90:99:95:8C:B5:F5:16:3F:DE:5C:E8:CE:FE:9B:62:95:76:A9:4C:8A:00:BF:60:7F:84:70:E9:8A:33:AC:1E:52:5A:FB:C0:CB:09:38:EC:60:3D:CB:D3:29:F4:1B:B5:45:ED:A5:63:04:EB:3F:E3: 76:61:B5:9A:31:CA:53:AD:85:E2:56:1E:94:BC:DB:18:A5:64:BE:1B:52:8E:50:B2:1A:CA:F9:55:3C:E2:E7:67:F3:A4:3D:51:90:EA:F5:28:15:2C:8C:63:09:83:DE:B5:72:7D:A1:9A:E2:99:A9:11:66:F7:53:34:46:14:E6:B2:94:8 8:45:86:9F:3A:37:DB:3A:B7:47:D2:DB:78:7E:3A:16:08:BF:3E:66:16:56:3F:99:05:97:84:C1:15:BC:23:C1:8B:07:2A:8C:E5:65:0A:F4:B7:D7:C7:CF:EF:D7:BB:2E:D5:D6:7E:5E:A5:5F:37:D4:77:57:10:5C:C4:AD:11:95:96:D 6:2A:85:4A:BA:09:E4:3B:AE:01:41:73:F3:0C:4F:0F:5E:D0:13:EE:31:57:30:90:FA:B3:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 197 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 23:65:6A:11:FE:53:67:FB:7F:22:C0:B5:E9:61:09:E2:93:6C:E1:09 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 3C:6C:B8:0F:F8:EF:6B:D5:E8:82:29:B8:2F:FC:12:D9:47:CD:B0:E8:3C:A4:46:87:A7:40:F9:C6:39: 62:AE:AC Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.38.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (68) PostSignum - Qualified Time Stamping Authority, TSU 1 Name [ cs ] (68) PostSignum - autorita kvalifikovaných časových razítek, TSU 1 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 1 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 198 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I I2VqEf5TZ/t/IsC16WEJ4pNs4Qk= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-08-26T08:32:28Z 159.39 - Service (withdrawn): (69) PostSignum - Qualified Time Stamping Authority, TSU 2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (69) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (69) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000604 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 199 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLckcMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNTA4MjYwODQxNDJaFw0yMTEwMDMwODQxMjBaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDB/7FnOzObvGGLbHqEWWj08RN4 6BEeeVQyoDoP3L3mK6bLuXK7BUacMx6qxy9tQEpec9NyIgVnR7UxokRYh7g0jA+jB3Dz5L6CmHQZ IZK/SSGRg4yVEFVuSOuqaM6FKEgw/DlS9h5m+nSg5RM8aHv0U/yCu9GSSCEhjB5/bUe1SUPon1FU gr2j9EDotqNw7NT382kE7tHyHbVgn7DMDGsklBmLgA/3lJ2QiJdEdLVzx5Xv3pKykjxvHMyLplIo VgB/y7S1aaF5HFuh3iXgivmgthBb+2yoiPYezzsuT+t9NRHLvJtBuWcJG3Uq8bcAjBc7bmhWECLg tvel74Fx+ZxzAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBRxwbndVtdHitPESFRPIFhINGR3TDANBgkqhkiG9w0BAQsFAAOCAQEAQFBUs3D9 whqFvOyb81ZzgFCrtpPFSzaGefwETYOagAHij1TXszk3HgEIkcznzEh7MaqtEex8q8SwtjurJ1tm beMf1MZ/eADR/W/5TEqdipeLOy1xYmUcwZTm8OMCxv3JnjhDBvlxaWLUMbSxoZT+x31+GOK7S8gZ N+o6vQx7dWjFnYRocRHJM028c4iVaW/UeQMOwzFswS6R8K17Si2fW5y1QVAblICbcUSv2F1VpPN1 AL7bQDy+4r3zrhhG+23ybgOGBfcGXlCpkZONE3KcUaUnwQx47eOj0ztY0mHpuR/mKnekZt+BWJjd 1tsmJzt96Ru2nKW7vXDA4onP7pWP6w== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Aug 26 10:41:42 CEST 2015 Valid to: Sun Oct 03 10:41:20 CEST 2021 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:C1:FF:B1:67:3B:33:9B:BC:61:8B:6C:7A:84:59:68:F4:F1:13:78:E8:11:1E:79:54:32:A0:3A:0F:DC:BD:E6:2B:A6:CB: B9:72:BB:05:46:9C:33:1E:AA:C7:2F:6D:40:4A:5E:73:D3:72:22:05:67:47:B5:31:A2:44:58:87:B8:34:8C:0F:A3:07:70:F3:E4:BE:82:98:74:19:21:92:BF:49:21:91:83:8C:95:10:55:6E:48:EB:AA:68:CE:85:28:48:30:FC:39:52:F6: 1E:66:FA:74:A0:E5:13:3C:68:7B:F4:53:FC:82:BB:D1:92:48:21:21:8C:1E:7F:6D:47:B5:49:43:E8:9F:51:54:82:BD:A3:F4:40:E8:B6:A3:70:EC:D4:F7:F3:69:04:EE:D1:F2:1D:B5:60:9F:B0:CC:0C:6B:24:94:19:8B:80:0F:F7:94: 9D:90:88:97:44:74:B5:73:C7:95:EF:DE:92:B2:92:3C:6F:1C:CC:8B:A6:52:28:56:00:7F:CB:B4:B5:69:A1:79:1C:5B:A1:DE:25:E0:8A:F9:A0:B6:10:5B:FB:6C:A8:88:F6:1E:CF:3B:2E:4F:EB:7D:35:11:CB:BC:9B:41:B9:67:09: 1B:75:2A:F1:B7:00:8C:17:3B:6E:68:56:10:22:E0:B6:F7:A5:EF:81:71:F9:9C:73:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 200 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 71:C1:B9:DD:56:D7:47:8A:D3:C4:48:54:4F:20:58:48:34:64:77:4C Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 95:99:A2:46:44:F1:23:9B:4C:C0:6C:6A:96:3F:A0:2D:10:07:75:0F:43:F9:8A:00:29:AE:D5:05:AB: E6:02:A4 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.39.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (69) PostSignum - Qualified Time Stamping Authority, TSU 2 Name [ cs ] (69) PostSignum - autorita kvalifikovaných časových razítek, TSU 2 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 2 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 201 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I ccG53VbXR4rTxEhUTyBYSDRkd0w= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-08-26T08:41:42Z 159.40 - Service (withdrawn): (70) PostSignum - Qualified Time Stamping Authority, TSU 3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (70) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (70) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000605 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 202 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLckdMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNTA4MjYwODQzMDJaFw0yMTEwMDMwODQyNDZaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCN+UWP1wHjmOw8DpoXNhRqHS5o wpi1P9kYJ46oA/vGBTUio0y/d9JeQUiyPHsix1G0z/5ShLMlmuX6mf9oNGDHlzr7dMZR+ysR/G/I pUJZnKsLlInd78KTWM1PKzLJBlVn5ad9e9xShHL7cI3RYScWMbZTERof98ib7aAs/0x6XEMvn/ER o7T7T1vOHRCZhzi52IObiPmmaOptFw5dqd0FWEivW4rTF80QSUb7qIjvWd7nSJYJQYMZkzdf7ybi Bkm7mN2UkioQ1GG5saXTHR/csXaRvk7Z7TiddNSxXhJM846BSaeOywJg8KSrXCCGykC+/aDH9aE9 QGbi/qBKVwsFAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBSKNyNlUbbrcTfAFUTS0YSGmrysxjANBgkqhkiG9w0BAQsFAAOCAQEAIYO6FXCh W6V2GeVE7PzmeQBOmJppwCQ8Y8ttzBa5jcXrQYA7opRhuh93ZvkigDK1i2/RRaN+b5a0MML7PEz0 dLGSlmMl6pq54u/C7NrfV2eEFtdSQoUr0fCipAth297ZhfVA6SoT3Q9Sb3kkxWGp5Qua58XRuSH/ BtAbVE4ogIbHSswnUIOgxljI/vNHK/XO6nS7gu2tj07gS4wMG3iCA0edwgvO8QlZOsnxKCW/xCY4 XtCTy9tMD5jJNjFU8eXam71zstEEPLPLe/hreEYt/M9vDy9RTEF2/49AyMOTZajXSYQ7lz0P4vkS gzqydOzvW1jHuV/NJynQi419hF/7jw== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Aug 26 10:43:02 CEST 2015 Valid to: Sun Oct 03 10:42:46 CEST 2021 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:8D:F9:45:8F:D7:01:E3:98:EC:3C:0E:9A:17:36:14:6A:1D:2E:68:C2:98:B5:3F:D9:18:27:8E:A8:03:FB:C6:05:35:22:A3 :4C:BF:77:D2:5E:41:48:B2:3C:7B:22:C7:51:B4:CF:FE:52:84:B3:25:9A:E5:FA:99:FF:68:34:60:C7:97:3A:FB:74:C6:51:FB:2B:11:FC:6F:C8:A5:42:59:9C:AB:0B:94:89:DD:EF:C2:93:58:CD:4F:2B:32:C9:06:55:67:E5:A7:7D: 7B:DC:52:84:72:FB:70:8D:D1:61:27:16:31:B6:53:11:1A:1F:F7:C8:9B:ED:A0:2C:FF:4C:7A:5C:43:2F:9F:F1:11:A3:B4:FB:4F:5B:CE:1D:10:99:87:38:B9:D8:83:9B:88:F9:A6:68:EA:6D:17:0E:5D:A9:DD:05:58:48:AF:5B:8A: D3:17:CD:10:49:46:FB:A8:88:EF:59:DE:E7:48:96:09:41:83:19:93:37:5F:EF:26:E2:06:49:BB:98:DD:94:92:2A:10:D4:61:B9:B1:A5:D3:1D:1F:DC:B1:76:91:BE:4E:D9:ED:38:9D:74:D4:B1:5E:12:4C:F3:8E:81:49:A7:8E:CB:0 2:60:F0:A4:AB:5C:20:86:CA:40:BE:FD:A0:C7:F5:A1:3D:40:66:E2:FE:A0:4A:57:0B:05:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 203 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 8A:37:23:65:51:B6:EB:71:37:C0:15:44:D2:D1:84:86:9A:BC:AC:C6 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 1B:E8:35:4B:00:02:5C:11:89:FF:A9:E9:0E:8B:43:6C:CB:33:B2:98:C7:64:21:24:B6:14:4F:4E:18:4 8:09:1D Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.40.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (70) PostSignum - Qualified Time Stamping Authority, TSU 3 Name [ cs ] (70) PostSignum - autorita kvalifikovaných časových razítek, TSU 3 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 3 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 204 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I ijcjZVG263E3wBVE0tGEhpq8rMY= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-08-26T08:43:02Z 159.41 - Service (withdrawn): (71) PostSignum - Qualified Time Stamping Authority, TSU 4 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (71) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (71) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000606 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 205 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLckeMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNTA4MjYwODQ0MTFaFw0yMTEwMDMwODQzNTBaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCbTCA28AcWrH7y8MjtiqS3Azss 1pv/W51FeVXsHHeVQjUOFUoNN/iBXALglcHbRWRs36LJ6q7vKBa1v0oz/3MEElgMF0vTMT3lcG2G zAytLkcZpTXKOKcLdhy7hCLsgFrmU7MMML0PQGCLJZID7nB770sQ/Nzd5q/u+NgxRX7v4n2FJ/4Z eds0lrCHi36g4OmX9shtVALtWGsUKHbsZcFZkLHHvaFPrziI/oa5JrjnAdEDYEWolujWT7gMzgj8 fX9BpKGdAMze71bysz6LUYBRr07RWnRkxMkYJmfzbJ3yGkndzsYfD+CMGh+nZYNbrlVlVSafPeyW S1SsW0UOe2NJAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBRTVDRfFdSvsUHxUoNHmwIfNKnOdTANBgkqhkiG9w0BAQsFAAOCAQEAbS8rim1p gPUgmRI8F1uDnEvanY3/VHiJS3jevrfNeqRD+zrN6Mpj2oie0fugvYnQIkYy58OQ1a1y1JpHEtJX 0I5IeukNTG70ultWsGPLF0kfGjkE82ybF1hUTgitKikfGGMqaCe2AyZE3CTubSkx2QHBpAcQOTsk TCB6TYVzU4WCNUT++Dkvfz66ABtH7DDNVb3berktvj3GvgBJU8hrryG+bRCtcGmYzZfaXHBBUi/O qQ8doUknHO4voeOYx6c4OOMv9kgC9E834Xq3aIIfT9r6EKDQKd9CuDViD4n6WzMoG58dwjtpg/96 UT+ccHtuokqMfevmG2tK//wl6EJnVQ== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Aug 26 10:44:11 CEST 2015 Valid to: Sun Oct 03 10:43:50 CEST 2021 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:9B:4C:20:36:F0:07:16:AC:7E:F2:F0:C8:ED:8A:A4:B7:03:3B:2C:D6:9B:FF:5B:9D:45:79:55:EC:1C:77:95:42:35:0E:1 5:4A:0D:37:F8:81:5C:02:E0:95:C1:DB:45:64:6C:DF:A2:C9:EA:AE:EF:28:16:B5:BF:4A:33:FF:73:04:12:58:0C:17:4B:D3:31:3D:E5:70:6D:86:CC:0C:AD:2E:47:19:A5:35:CA:38:A7:0B:76:1C:BB:84:22:EC:80:5A:E6:53:B3: 0C:30:BD:0F:40:60:8B:25:92:03:EE:70:7B:EF:4B:10:FC:DC:DD:E6:AF:EE:F8:D8:31:45:7E:EF:E2:7D:85:27:FE:19:79:DB:34:96:B0:87:8B:7E:A0:E0:E9:97:F6:C8:6D:54:02:ED:58:6B:14:28:76:EC:65:C1:59:90:B1:C7:BD: A1:4F:AF:38:88:FE:86:B9:26:B8:E7:01:D1:03:60:45:A8:96:E8:D6:4F:B8:0C:CE:08:FC:7D:7F:41:A4:A1:9D:00:CC:DE:EF:56:F2:B3:3E:8B:51:80:51:AF:4E:D1:5A:74:64:C4:C9:18:26:67:F3:6C:9D:F2:1A:49:DD:CE:C6:1F: 0F:E0:8C:1A:1F:A7:65:83:5B:AE:55:65:55:26:9F:3D:EC:96:4B:54:AC:5B:45:0E:7B:63:49:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 206 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 53:54:34:5F:15:D4:AF:B1:41:F1:52:83:47:9B:02:1F:34:A9:CE:75 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 2A:C4:06:21:C5:82:DD:D9:68:4F:A8:D8:91:65:BE:D0:1D:F7:34:53:42:0F:20:1E:53:8C:D9:C7:81: ED:48:53 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.41.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (71) PostSignum - Qualified Time Stamping Authority, TSU 4 Name [ cs ] (71) PostSignum - autorita kvalifikovaných časových razítek, TSU 4 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 4 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 207 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I U1Q0XxXUr7FB8VKDR5sCHzSpznU= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-08-26T08:44:11Z 159.42 - Service (withdrawn): (72) PostSignum - Qualified Time Stamping Authority, TSU 5 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (72) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (72) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000607 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 208 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLckfMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNTA4MjYwODQ1MDNaFw0yMTEwMDMwODQ0NDhaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDL4aAj73Nebabrr4+d/X+5vB0s lnUIhqaQE2c3snXlNHwETUnlEqd4xT1mz5zZMzC0Pv3VGGhVFt17o9zJGp+o4XFqGOt5qQJS4nB1 kYV5VEPjlk4A9gRmUdUPY8jcrheceelmvWAGgMI0llyg9Hmf9C+K6CsbD/q9Wo09hX1ASWkBRtyF QzsivwMXNgbFf/AN/tvu4jeya8JFTbacHCQXLmuAXeI079OgFSefTWJBRQqVQp5HnPdMIxQ5UcZ3 67nALh0J8r4RjY1PusKH6mcQ+Dm1tgq+4nCj2UwITI+m2G5iBfCne5mKLH/tdavMziDDyFh8CS16 pNljxDLAE3J/AgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBREikRO54/hpjXbZUDOR6Ggpczo8TANBgkqhkiG9w0BAQsFAAOCAQEALo4WYmu5 Vgp8GIksl2etY6nTXOWck3PBWLGShKReRW4B5/WkM+L4NV9MlCSpgt9qDJiYbQSScpUVHVMzjX9g mPsPtpAOiR2QdZwFgV0EbxlkfSUFgLgpBIeT3cXChh+zlaqtr6h9RnpHI8K7zsUovlkUd2NV4dDN nXGdHZLdRu2xVI2eUk+44yeJVNWsT8YA1qo7WYY9xAIVZAlXd9mWL4qLroG7IvvfCOEuBze4L4VC 90RQQsS880ZY2ZA8YbILuvOj0uOvSfUQdLlKP2+Vhkk9pcZw6Jyv6rmQYWVaV89f6huURPBszJtJ P0Th9hwDupatcPqiVBL2NB3M+3RcJg== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Aug 26 10:45:03 CEST 2015 Valid to: Sun Oct 03 10:44:48 CEST 2021 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:CB:E1:A0:23:EF:73:5E:6D:A6:EB:AF:8F:9D:FD:7F:B9:BC:1D:2C:96:75:08:86:A6:90:13:67:37:B2:75:E5:34:7C:04: 4D:49:E5:12:A7:78:C5:3D:66:CF:9C:D9:33:30:B4:3E:FD:D5:18:68:55:16:DD:7B:A3:DC:C9:1A:9F:A8:E1:71:6A:18:EB:79:A9:02:52:E2:70:75:91:85:79:54:43:E3:96:4E:00:F6:04:66:51:D5:0F:63:C8:DC:AE:17:9C:79:E9:66 :BD:60:06:80:C2:34:96:5C:A0:F4:79:9F:F4:2F:8A:E8:2B:1B:0F:FA:BD:5A:8D:3D:85:7D:40:49:69:01:46:DC:85:43:3B:22:BF:03:17:36:06:C5:7F:F0:0D:FE:DB:EE:E2:37:B2:6B:C2:45:4D:B6:9C:1C:24:17:2E:6B:80:5D:E2: 34:EF:D3:A0:15:27:9F:4D:62:41:45:0A:95:42:9E:47:9C:F7:4C:23:14:39:51:C6:77:EB:B9:C0:2E:1D:09:F2:BE:11:8D:8D:4F:BA:C2:87:EA:67:10:F8:39:B5:B6:0A:BE:E2:70:A3:D9:4C:08:4C:8F:A6:D8:6E:62:05:F0:A7:7B:9 9:8A:2C:7F:ED:75:AB:CC:CE:20:C3:C8:58:7C:09:2D:7A:A4:D9:63:C4:32:C0:13:72:7F:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 209 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier 44:8A:44:4E:E7:8F:E1:A6:35:DB:65:40:CE:47:A1:A0:A5:CC:E8:F1 Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: A3:F1:A7:FB:AF:38:1E:C7:E9:CC:43:FD:1D:09:1A:65:5C:00:1B:60:71:5C:91:4A:E4:8A:AC:D4:8 0:F0:01:91 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.42.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (72) PostSignum - Qualified Time Stamping Authority, TSU 5 Name [ cs ] (72) PostSignum - autorita kvalifikovaných časových razítek, TSU 5 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 5 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 210 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I RIpETueP4aY122VAzkehoKXM6PE= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-08-26T08:45:03Z 159.43 - Service (withdrawn): (73) PostSignum - Qualified Time Stamping Authority, TSU 6 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (73) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (73) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 3000608 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 211 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGhzCCBW+gAwIBAgIDLckgMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAkNaMSwwKgYDVQQK DCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEiMCAGA1UEAxMZUG9zdFNpZ251 bSBRdWFsaWZpZWQgQ0EgMzAeFw0xNTA4MjYwODQ1NTdaFw0yMTEwMDMwODQ1NDFaMH4xCzAJBgNV BAYTAkNaMSwwKgYDVQQKDCPEjGVza8OhIHBvxaF0YSwgcy5wLiBbScSMIDQ3MTE0OTgzXTEgMB4G A1UECxMXVGltZSBTdGFtcGluZyBBdXRob3JpdHkxHzAdBgNVBAMTFlBvc3RTaWdudW0gVFNBIC0g VFNVIDYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQD3LslmpHGB107JtJjOS21wIHeQ WRJ4lQy9AAXlJ89RhEia3DRO0xA5/01yovzsI5mhK8J7B3M9VxfEuLYZ5isXOyibALYIGJvUMaKb 2F5lJiPa9wwjc1OdHkrsQqSXSZnPg/aXNnme3a0pGf5HlGdkWhkZkMKAhY4uJNEal3MW/N/5kCJo 7k8eSMzvSbmCeJemela/ituqCLi1/ZXBrm0/+AZedGek0RZW+rRzU1zFzLFOT3OzKF/e/ayL5TiX Qoffg3FurtFcz2IGIKhiwc5VVEAVr4FSaqnidUd8CGiNgHMF3dvLHnC37Q3TsM6GNpwDbMZAsscn flEP+AnuLuSBAgMBAAGjggMrMIIDJzCCASAGA1UdIASCARcwggETMIIBDwYJZ4EGAQQBZYEMMIIB ADCB1wYIKwYBBQUHAgIwgcoagcdUZW50byBrdmFsaWZpa292YW55IHN5c3RlbW92eSBjZXJ0aWZp a2F0IGJ5bCB2eWRhbiBwb2RsZSB6YWtvbmEgMjI3LzIwMDBTYi4gYSBuYXZhem55Y2ggcHJlZHBp c3UvVGhpcyBxdWFsaWZpZWQgc3lzdGVtIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5n IHRvIExhdyBObyAyMjcvMjAwMENvbGwuIGFuZCByZWxhdGVkIHJlZ3VsYXRpb25zMCQGCCsGAQUF BwIBFhhodHRwOi8vd3d3LnBvc3RzaWdudW0uY3owGgYIKwYBBQUHAQMEDjAMMAoGCCsGAQUFBwsC MIHIBggrBgEFBQcBAQSBuzCBuDA7BggrBgEFBQcwAoYvaHR0cDovL3d3dy5wb3N0c2lnbnVtLmN6 L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwPAYIKwYBBQUHMAKGMGh0dHA6Ly93d3cyLnBvc3RzaWdu dW0uY3ovY3J0L3BzcXVhbGlmaWVkY2EzLmNydDA7BggrBgEFBQcwAoYvaHR0cDovL3Bvc3RzaWdu dW0udHRjLmN6L2NydC9wc3F1YWxpZmllZGNhMy5jcnQwDgYDVR0PAQH/BAQDAgbAMBYGA1UdJQEB /wQMMAoGCCsGAQUFBwMIMB8GA1UdIwQYMBaAFPL4zCpXYdorFzNZ5YIt7AYcik9KMIGxBgNVHR8E gakwgaYwNaAzoDGGL2h0dHA6Ly93d3cucG9zdHNpZ251bS5jei9jcmwvcHNxdWFsaWZpZWRjYTMu Y3JsMDagNKAyhjBodHRwOi8vd3d3Mi5wb3N0c2lnbnVtLmN6L2NybC9wc3F1YWxpZmllZGNhMy5j cmwwNaAzoDGGL2h0dHA6Ly9wb3N0c2lnbnVtLnR0Yy5jei9jcmwvcHNxdWFsaWZpZWRjYTMuY3Js MB0GA1UdDgQWBBSujABkFsvTmtQbayDgBRAA0xPwnDANBgkqhkiG9w0BAQsFAAOCAQEAbE/e74hk u4BQ3cNs0ZvLVnGy2P1rw6dq/HAxw6eKjCSb/rFKDf/PE9PCsi7+qgnge9c3P3v+mDOMHFJoaRDV DrpmGKM7mG5oipiz6KGY8rAnGE91ZxUIaw9UFsy2HVAPbUsVhRJ8CTyCgDI1nNaPzGlvyWmNrRIi o0jdcdLDx2G7XXr1poihW9ObX6fFJild6dgNy5TcrIql9dPrEYVBYPg+aVd6Mmi7snKg3BgTbyVA D/JZf4gWQLOM2iHdfyPX8ynLbPX68dRTRp0uxBFpn8MUrg4n81UrHAZqOLFgXIGbdnj6yHB2F7eC 7abGf2dT1WDlW7ZL5cuzITLz6uRwBg== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: PostSignum Qualified CA 3 Issuer O: Česká pošta, s.p. [IČ 47114983] Issuer C: CZ Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ Valid from: Wed Aug 26 10:45:57 CEST 2015 Valid to: Sun Oct 03 10:45:41 CEST 2021 Public Key: Certificate Policies 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:F7:2E:C9:66:A4:71:81:D7:4E:C9:B4:98:CE:4B:6D:70:20:77:90:59:12:78:95:0C:BD:00:05:E5:27:CF:51:84:48:9A:DC :34:4E:D3:10:39:FF:4D:72:A2:FC:EC:23:99:A1:2B:C2:7B:07:73:3D:57:17:C4:B8:B6:19:E6:2B:17:3B:28:9B:00:B6:08:18:9B:D4:31:A2:9B:D8:5E:65:26:23:DA:F7:0C:23:73:53:9D:1E:4A:EC:42:A4:97:49:99:CF:83:F6:97:36 :79:9E:DD:AD:29:19:FE:47:94:67:64:5A:19:19:90:C2:80:85:8E:2E:24:D1:1A:97:73:16:FC:DF:F9:90:22:68:EE:4F:1E:48:CC:EF:49:B9:82:78:97:A6:7A:56:BF:8A:DB:AA:08:B8:B5:FD:95:C1:AE:6D:3F:F8:06:5E:74:67:A4: D1:16:56:FA:B4:73:53:5C:C5:CC:B1:4E:4F:73:B3:28:5F:DE:FD:AC:8B:E5:38:97:42:87:DF:83:71:6E:AE:D1:5C:CF:62:06:20:A8:62:C1:CE:55:54:40:15:AF:81:52:6A:A9:E2:75:47:7C:08:68:8D:80:73:05:DD:DB:CB:1E:70: B7:ED:0D:D3:B0:CE:86:36:9C:03:6C:C6:40:B2:C7:27:7E:51:0F:F8:09:EE:2E:E4:81:02:03:01:00:01 Policy OID: 2.23.134.1.4.1.101.140 CPS text: [Tento kvalifikovany systemovy certifikat byl vydan podle zakona 227/2000Sb. a navaznych predpisu/This qualified system certificate was issued according to Law No 227/2000Coll. and related regulations] CPS pointer: http://www.postsignum.cz Authority Info Access http://www.postsignum.cz/crt/psqualifiedca3.crt http://www2.postsignum.cz/crt/psqualifiedca3.crt http://postsignum.ttc.cz/crt/psqualifiedca3.crt Extended Key Usage id_kp_timeStamping Authority Key Identifier F2:F8:CC:2A:57:61:DA:2B:17:33:59:E5:82:2D:EC:06:1C:8A:4F:4A CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 212 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.postsignum.cz/crl/psqualifiedca3.crl http://www2.postsignum.cz/crl/psqualifiedca3.crl http://postsignum.ttc.cz/crl/psqualifiedca3.crl Subject Key Identifier AE:8C:00:64:16:CB:D3:9A:D4:1B:6B:20:E0:05:10:00:D3:13:F0:9C Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 61:6F:33:2C:AC:F6:A9:06:F4:D1:4C:38:B1:C6:2D:DE:B0:2C:0E:3E:19:CC:9C:2E:EF:7A:34:8B:E E:0A:E3:AB Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 159.43.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (73) PostSignum - Qualified Time Stamping Authority, TSU 6 Name [ cs ] (73) PostSignum - autorita kvalifikovaných časových razítek, TSU 6 Service digital identities X509SubjectName Subject CN: PostSignum TSA - TSU 6 Subject OU: Time Stamping Authority CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 213 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: Česká pošta, s.p. [IČ 47114983] Subject C: CZ X509SKI X509 SK I rowAZBbL05rUG2sg4AUQANMT8Jw= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-08-26T08:45:57Z CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 214 ETSI 2014 - TSL HR - PDF/A-1b generator 160 - TSP: eIdentity a.s. TSP Name Name [ en ] eIdentity a.s. Name [ cs ] eIdentity a.s. Name [ en ] eIdentity a.s. Name [ en ] VATCZ-27112489 Street Address [ en ] Vinohradska 184/2396 Locality [ en ] Prague 3 Postal Code [ en ] 13000 Country Name [ en ] CZ Street Address [ cs ] Vinohradská 184/2396 Locality [ cs ] Praha 3 Postal Code [ cs ] 13000 Country Name [ cs ] CZ TSP Trade Name PostalAddress PostalAddress ElectronicAddress URI mailto:[email protected] URI http://www.eidentity.cz/ URI http://www.eidentity.cz/ TSP Information URI URI [ en ] http://translate.google.cz/translate?hl=cs&sl=cs&tl=en&u=http://www.acaeid.cz/CpoliticStatic. html URI [ cs ] http://www.acaeid.cz/CpoliticStatic.html CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 215 ETSI 2014 - TSL HR - PDF/A-1b generator 160.1 - Service (granted): (8) ACAeID - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (8) ACAeID - issuing qualified certificates Name [ cs ] (8) ACAeID - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 4 X509 Certificate -----BEGIN CERTIFICATE----MIIHrjCCBpagAwIBAgIBBDANBgkqhkiG9w0BAQUFADCB9TELMAkGA1UEBhMCQ1oxFzAVBgNVBAoM DmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBjZXJ0 aWZpa2HEjW7DrWNoIHNsdcW+ZWIxKjAoBgNVBAcMIVZpbm9ocmFkc2vDoSAxODQsIDEzMCAwMCwg UHJhaGEgMzFjMGEGA1UEAwxaQUNBZUlEIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlmaWNhdGUgKGt2 YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kgQ0EpMB4XDTA1 MTExNTEzNTIzN1oXDTExMTExNTEzNTIzN1owgfsxCzAJBgNVBAYTAkNaMRcwFQYDVQQKDA5lSWRl bnRpdHkgYS5zLjE8MDoGA1UECwwzQWtyZWRpdG92YW7DvSBwb3NreXRvdmF0ZWwgY2VydGlmaWth xI1uw61jaCBzbHXFvmViMSowKAYDVQQHDCFWaW5vaHJhZHNrw6EgMTg0LCAxMzAgMDAsIFByYWhh IDMxaTBnBgNVBAMMYEFDQWVJRCAtIFF1YWxpZmllZCBJc3N1aW5nIENlcnRpZmljYXRlIChrdmFs aWZpa292YW7DvSBzeXN0w6ltb3bDvSBjZXJ0aWZpa8OhdCB2eWTDoXZhasOtY8OtIENBKTCCASAw DQYJKoZIhvcNAQEBBQADggENADCCAQgCggEBANf6VjTG8r+dcFKsL9Jo2sWL4jRUIpuh9cGGxUC3 MzkxNcRzRI08Ewc4+EG2DGZgFeZvPzpyPdV5ifE4fnGSi5iMM5y0XB9sHQvYVPQ2p19hPhSfq+jx D0XQb1kWApTx6l5Wr+yJYmlLb0wngjaB506ygevQqU2VpIIXbIr4xW3ToN512r+XvfOezWfuL9rb 3gKBc+P8+bgujXhD5B99A+BQNxqAdCBvWzP363Q/+5DTP7561rrzINXJu+fRCxAI7kTzDwLtVWMq 08WoGhZdFbof0L6sXVGe/M7r8+bA/DJwegw1bRxf1TsHoRWdL5cddgTt9WMQ7aqTrnfEnhAV/+MC AQOjggNBMIIDPTAdBgNVHQ4EFgQUn1Q9CzBwBbp6d/Is8xlv6/XBrbAwggEUBgNVHSAEggELMIIB BzCCAQMGDCqBS4z26CkBCgMBATCB8jAxBggrBgEFBQcCARYlaHR0cDovL3d3dy5hY2FlaWQuY3ov cm9vdC9jcC1ycXNjLnBkZjCBvAYIKwYBBQUHAgIwga8agaxUZW50byBjZXJ0aWZpa+F0IGplIHZ5 ZOFuIGpha28gS3ZhbGlmaWtvdmFu/SBzeXN06W1vdv0gY2VydGlmaWvhdCBwb2RsZSB64WtvbmEg MjI3LzIwMDAgU2IuIC8gVGhpcyBpcyBRdWFsaWZpZWQgU3lzdGVtIENlcnRpZmljYXRlIGFjY29y ZGluZyB0byBDemVjaCBBY3QgTm8uIDIyNy8yMDAwIENvbGwuMBIGA1UdEwEB/wQIMAYBAf8CAQAw ggEkBgNVHSMEggEbMIIBF4AULpqPT6x8e0nAEzClbX9UjaXCJeShgfukgfgwgfUxCzAJBgNVBAYT AkNaMRcwFQYDVQQKDA5lSWRlbnRpdHkgYS5zLjE8MDoGA1UECwwzQWtyZWRpdG92YW7DvSBwb3Nr eXRvdmF0ZWwgY2VydGlmaWthxI1uw61jaCBzbHXFvmViMSowKAYDVQQHDCFWaW5vaHJhZHNrw6Eg MTg0LCAxMzAgMDAsIFByYWhhIDMxYzBhBgNVBAMMWkFDQWVJRCAtIFF1YWxpZmllZCBSb290IENl cnRpZmljYXRlIChrdmFsaWZpa292YW7DvSBzeXN0w6ltb3bDvSBjZXJ0aWZpa8OhdCBrb8WZZW5v dsOpIENBKYIBAzCBnQYDVR0fBIGVMIGSMC6gLKAqhihodHRwOi8vd3d3LmFjYWVpZC5jei9yb290 L2NybC9hY3R1YWwuY3JsMC+gLaArhilodHRwOi8vcHViMS5hY2FlaWQuY3ovcm9vdC9jcmwvYWN0 dWFsLmNybDAvoC2gK4YpaHR0cDovL3B1YjIuYWNhZWlkLmN6L3Jvb3QvY3JsL2FjdHVhbC5jcmww DgYDVR0PAQH/BAQDAgEGMBgGCCsGAQUFBwEDBAwwCjAIBgYEAI5GAQEwDQYJKoZIhvcNAQEFBQAD ggEBAJoLmG86mT6FOU9Mhp84UCPt5vVZcwFKjEIw5WMA/6WY+/qbOjZHUmmx/apcyz/FhG+up6am bUIt885kDAugQGJ7hzvAJ6nFGPW4b1dVa7rjjo8DVsujKSmT3Cnk/zR8wPf5aN6llh5zrAF6DHPS r5+AV2qWriCng9OskI5jjPMNdUw5oRV/RuuI6z+fFeIBtn7P6qCKKWiwpn7ViEWUP2cPQaN2XmHo 7CbKMnD/hyb/rFbftJDigvF2OxjB8hf9qDt59jqqPm53reuPCZ0rFZM/yI4YTCMsucdP8uuUTpkB GYyv8ROP2yA5vIefAC/5gNu/o7lwIsbTpIfAx10HuaI= -----END CERTIFICATE----- CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 216 ETSI 2014 - TSL HR - PDF/A-1b generator Signature algorithm: SHA1withRSA Issuer CN: ACAeID - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: ACAeID - Qualified Issuing Certificate (kvalifikovaný systémový certifikát vydávající CA) Subject L: Vinohradská 184, 130 00, Praha 3 Subject OU: Akreditovaný poskytovatel certifikačních služeb Subject O: eIdentity a.s. Subject C: CZ Valid from: Tue Nov 15 14:52:37 CET 2005 Valid to: Tue Nov 15 14:52:37 CET 2011 Public Key: 30:82:01:20:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0D:00:30:82:01:08:02:82:01:01:00:D7:FA:56:34:C6:F2:BF:9D:70:52:AC:2F:D2:68:DA:C5:8B:E2:34:54:22:9B:A1:F5:C1:86:C5:40:B7:33:39:31:35:C4:7 3:44:8D:3C:13:07:38:F8:41:B6:0C:66:60:15:E6:6F:3F:3A:72:3D:D5:79:89:F1:38:7E:71:92:8B:98:8C:33:9C:B4:5C:1F:6C:1D:0B:D8:54:F4:36:A7:5F:61:3E:14:9F:AB:E8:F1:0F:45:D0:6F:59:16:02:94:F1:EA:5E:56:AF:EC:89: 62:69:4B:6F:4C:27:82:36:81:E7:4E:B2:81:EB:D0:A9:4D:95:A4:82:17:6C:8A:F8:C5:6D:D3:A0:DE:75:DA:BF:97:BD:F3:9E:CD:67:EE:2F:DA:DB:DE:02:81:73:E3:FC:F9:B8:2E:8D:78:43:E4:1F:7D:03:E0:50:37:1A:80:74:20 :6F:5B:33:F7:EB:74:3F:FB:90:D3:3F:BE:7A:D6:BA:F3:20:D5:C9:BB:E7:D1:0B:10:08:EE:44:F3:0F:02:ED:55:63:2A:D3:C5:A8:1A:16:5D:15:BA:1F:D0:BE:AC:5D:51:9E:FC:CE:EB:F3:E6:C0:FC:32:70:7A:0C:35:6D:1C:5F :D5:3B:07:A1:15:9D:2F:97:1D:76:04:ED:F5:63:10:ED:AA:93:AE:77:C4:9E:10:15:FF:E3:02:01:03 Subject Key Identifier 9F:54:3D:0B:30:70:05:BA:7A:77:F2:2C:F3:19:6F:EB:F5:C1:AD:B0 Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.1.1 CPS pointer: http://www.acaeid.cz/root/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: true - Path length: 0 Authority Key Identifier 2E:9A:8F:4F:AC:7C:7B:49:C0:13:30:A5:6D:7F:54:8D:A5:C2:25:E4 CRL Distribution Points http://www.acaeid.cz/root/crl/actual.crl http://pub1.acaeid.cz/root/crl/actual.crl http://pub2.acaeid.cz/root/crl/actual.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 217 ETSI 2014 - TSL HR - PDF/A-1b generator Thumbprint: 6E:C5:00:C0:0E:41:BD:A5:71:A8:53:2F:17:BC:D5:DF:73:7E:E9:FC:EF:39:CA:D3:4A:85:A8:EE: DD:C2:6B:96 Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted Service status description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 160.1.1 - Extension (critical): Qualifiers [QCNoQSCD] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.5 Policy Identifier nodes: Identifier CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ 1.2.203.27112489.1.10.1.1.4 Page 218 ETSI 2014 - TSL HR - PDF/A-1b generator Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.3 Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.2 Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.1 160.1.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 160.1.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (8) ACAeID - issuing qualified certificates Name [ cs ] (8) ACAeID - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject CN: ACAeID - Qualified Issuing Certificate (kvalifikovaný systémový certifikát vydávající CA) Subject L: Vinohradská 184, 130 00, Praha 3 Subject OU: Akreditovaný poskytovatel certifikačních služeb Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I Service Status n1Q9CzBwBbp6d/Is8xlv6/XBrbA= http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 219 ETSI 2014 - TSL HR - PDF/A-1b generator Status Starting Time 2005-11-15T14:52:37Z 160.1.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 220 ETSI 2014 - TSL HR - PDF/A-1b generator [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.5 Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.4 Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.3 Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.2 Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.1.1 160.2 - Service (granted): (23) ACAeID2 - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 221 ETSI 2014 - TSL HR - PDF/A-1b generator [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (23) ACAeID2 - issuing qualified certificates Name [ cs ] (23) ACAeID2 - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 148224687 X509 Certificate -----BEGIN CERTIFICATE----MIIGxDCCBaygAwIBAgIECNW6rzANBgkqhkiG9w0BAQsFADCB+zELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBj ZXJ0aWZpa2HEjW7DrWNoIHNsdcW+ZWIxLzAtBgNVBAcMJlZpbm9ocmFkc2vDoSAxODQvMjM5Niwg MTMwIDAwLCBQcmFoYSAzMWQwYgYDVQQDDFtBQ0FlSUQyIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlm aWNhdGUgKGt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kg Q0EpMB4XDTEwMDIyMjE3MjkzOFoXDTE2MDIyMjE3MjkzOFowggEBMQswCQYDVQQGEwJDWjEXMBUG A1UECgwOZUlkZW50aXR5IGEucy4xPDA6BgNVBAsMM0FrcmVkaXRvdmFuw70gcG9za3l0b3ZhdGVs IGNlcnRpZmlrYcSNbsOtY2ggc2x1xb5lYjEvMC0GA1UEBwwmVmlub2hyYWRza8OhIDE4NC8yMzk2 LCAxMzAgMDAsIFByYWhhIDMxajBoBgNVBAMMYUFDQWVJRDIgLSBRdWFsaWZpZWQgSXNzdWluZyBD ZXJ0aWZpY2F0ZSAoa3ZhbGlmaWtvdmFuw70gc3lzdMOpbW92w70gY2VydGlmaWvDoXQgdnlkw6F2 YWrDrWPDrSBDQSkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDO1n5ilsig+Kknf116 cY9pI3yzq/KqkJMKaLdMdIjaTbUUYcMD47WS7LWeQawcAYv2UW8RtQtlAb2xtuFt6t1aQm/fsbdn zSzXgm+AxQlbedrOgfrHjjmaM77ggIlewckRX+Fz7yANqp0rZWuoYXDKMGDvXDmjWvNjiFPEZntf lpTe9+e3mednvFabpJI6eGdeCwZWIigwiwm+6UIU8wtpZKlEZuOlcYcyTFPcUAvLHWfcWcgk0e5U E/g9z/21bIqUauXb+AgDT9d1Drqv6jUQRzrSoYtos3+vlMr6zPo/GtRyfMS0a+Q9RxXfHigcMRsr JAyTBm+VYZRuq9NlK0enAgMBAAGjggJFMIICQTAdBgNVHQ4EFgQUu/44pZ6RYXGZ33Cljdig/kJ9 pj0wggEcBgNVHSAEggETMIIBDzCCAQsGDCqBS4z26CkBCgMCAjCB+jAyBggrBgEFBQcCARYmaHR0 cDovL3d3dy5hY2FlaWQuY3ovcm9vdDIvY3AtcnFzYy5wZGYwgcMGCCsGAQUFBwICMIG2DIGzVGVu dG8gY2VydGlmaWvDoXQgamUgdnlkw6FuIGpha28gS3ZhbGlmaWtvdmFuw70gc3lzdMOpbW92w70g Y2VydGlmaWvDoXQgcG9kbGUgesOha29uYSAyMjcvMjAwMCBTYi4gLyBUaGlzIGlzIFF1YWxpZmll ZCBTeXN0ZW0gQ2VydGlmaWNhdGUgYWNjb3JkaW5nIHRvIEN6ZWNoIEFjdCBOby4gMjI3LzIwMDAg Q29sbC4wEgYDVR0TAQH/BAgwBgEB/wIBADAfBgNVHSMEGDAWgBSV/iNQL8pjcNPAwSUSIXLFuuae XTCBoAYDVR0fBIGYMIGVMC+gLaArhilodHRwOi8vd3d3LmFjYWVpZC5jei9yb290Mi9jcmwvYWN0 dWFsLmNybDAwoC6gLIYqaHR0cDovL3B1YjEuYWNhZWlkLmN6L3Jvb3QyL2NybC9hY3R1YWwuY3Js MDCgLqAshipodHRwOi8vcHViMi5hY2FlaWQuY3ovcm9vdDIvY3JsL2FjdHVhbC5jcmwwGAYIKwYB BQUHAQMEDDAKMAgGBgQAjkYBATAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADggEBAKwd M0AQvcRYz98f1+i2r20rP+FW/LDKg5Gljza0SxgXrlmd1zqQS9yVC2DeQTF4nLxtyrF36HfsLfU8 vjzo/HhaXPulJUZIFYp5CisEa1FWDnPwE3FPGZ/cP6ZeMXihKW2tpOSePvkpqYsVX5beHzpOAghc 0rAC4wV3mon+pBHJlAVdV1RB1Zrpild5URpyc+9Gy4ehvahz9nAgb5j4R/oNFxMF2TtajsYWJTDp ea1CJF7t1pia24j0zmGUg786s/iUC1/pLhYjmXtkJ5FWcqlPo+6Ds0DejpQP7fH42UBod/xNXzig 7YL0GOqca80/5K+AZwp9RGA+Y20bz6RndcE= -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: ACAeID2 - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184/2396, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: ACAeID2 - Qualified Issuing Certificate (kvalifikovaný systémový certifikát vydávající CA) Subject L: Vinohradská 184/2396, 130 00, Praha 3 Subject OU: Akreditovaný poskytovatel certifikačních služeb CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 222 ETSI 2014 - TSL HR - PDF/A-1b generator Subject O: eIdentity a.s. Subject C: CZ Valid from: Mon Feb 22 18:29:38 CET 2010 Valid to: Mon Feb 22 18:29:38 CET 2016 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:CE:D6:7E:62:96:C8:A0:F8:A9:27:7F:5D:7A:71:8F:69:23:7C:B3:AB:F2:AA:90:93:0A:68:B7:4C:74:88:DA:4D:B5:14: 61:C3:03:E3:B5:92:EC:B5:9E:41:AC:1C:01:8B:F6:51:6F:11:B5:0B:65:01:BD:B1:B6:E1:6D:EA:DD:5A:42:6F:DF:B1:B7:67:CD:2C:D7:82:6F:80:C5:09:5B:79:DA:CE:81:FA:C7:8E:39:9A:33:BE:E0:80:89:5E:C1:C9:11:5F:E 1:73:EF:20:0D:AA:9D:2B:65:6B:A8:61:70:CA:30:60:EF:5C:39:A3:5A:F3:63:88:53:C4:66:7B:5F:96:94:DE:F7:E7:B7:99:E7:67:BC:56:9B:A4:92:3A:78:67:5E:0B:06:56:22:28:30:8B:09:BE:E9:42:14:F3:0B:69:64:A9:44:66:E3 :A5:71:87:32:4C:53:DC:50:0B:CB:1D:67:DC:59:C8:24:D1:EE:54:13:F8:3D:CF:FD:B5:6C:8A:94:6A:E5:DB:F8:08:03:4F:D7:75:0E:BA:AF:EA:35:10:47:3A:D2:A1:8B:68:B3:7F:AF:94:CA:FA:CC:FA:3F:1A:D4:72:7C:C4:B 4:6B:E4:3D:47:15:DF:1E:28:1C:31:1B:2B:24:0C:93:06:6F:95:61:94:6E:AB:D3:65:2B:47:A7:02:03:01:00:01 Subject Key Identifier BB:FE:38:A5:9E:91:61:71:99:DF:70:A5:8D:D8:A0:FE:42:7D:A6:3D Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.2.2 CPS pointer: http://www.acaeid.cz/root2/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: true - Path length: 0 Authority Key Identifier 95:FE:23:50:2F:CA:63:70:D3:C0:C1:25:12:21:72:C5:BA:E6:9E:5D CRL Distribution Points http://www.acaeid.cz/root2/crl/actual.crl http://pub1.acaeid.cz/root2/crl/actual.crl http://pub2.acaeid.cz/root2/crl/actual.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: 0A:F0:95:67:AE:FB:2E:6B:8C:76:FE:45:9C:F2:CC:E0:D5:18:2A:6D:09:3D:01:BE:A2:1C:64:23:E D:C4:7B:46 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 223 ETSI 2014 - TSL HR - PDF/A-1b generator Status Starting Time 2016-07-01T00:00:00Z 160.2.1 - Extension (critical): Qualifiers [QCNoQSCD] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.2.2 160.2.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 160.2.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (23) ACAeID2 - issuing qualified certificates Name [ cs ] (23) ACAeID2 - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject CN: ACAeID2 - Qualified Issuing Certificate (kvalifikovaný systémový certifikát vydávající CA) CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 224 ETSI 2014 - TSL HR - PDF/A-1b generator Subject L: Vinohradská 184/2396, 130 00, Praha 3 Subject OU: Akreditovaný poskytovatel certifikačních služeb Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I u/44pZ6RYXGZ33Cljdig/kJ9pj0= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2010-02-22T17:29:38Z 160.2.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 225 ETSI 2014 - TSL HR - PDF/A-1b generator [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.2.2 160.3 - Service (withdrawn): (24) ACAeID2 - Time Stamping Authority TSA1, TSU1 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 226 ETSI 2014 - TSL HR - PDF/A-1b generator [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (24) ACAeID2 - Time Stamping Authority TSA1, TSU1 Name [ cs ] (24) ACAeID2 - autorita časových razítek TSA1, TSU1 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 491568712 X509 Certificate -----BEGIN CERTIFICATE----MIIGFDCCBPygAwIBAgIEHUy+SDANBgkqhkiG9w0BAQsFADCB+zELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBj ZXJ0aWZpa2HEjW7DrWNoIHNsdcW+ZWIxLzAtBgNVBAcMJlZpbm9ocmFkc2vDoSAxODQvMjM5Niwg MTMwIDAwLCBQcmFoYSAzMWQwYgYDVQQDDFtBQ0FlSUQyIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlm aWNhdGUgKGt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kg Q0EpMB4XDTEwMDQyMzEwMjUxMFoXDTE2MDQyMzEwMjUxMFowRDELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMQ0wCwYDVQQLDARUU0ExMQ0wCwYDVQQDDARUU1UxMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8sB3A+aY8LwPFncm3Zk68ZuHBl7bsIejWmp/qVNudAH5 JoMe+Scdn6XIFgIZo68w/iR0oSf9m6xazsHnL9HKYcy7OELqNlQ6ihHM0e1YNVoiDa6oonlZtMBn Zumg8+8Nl0LQujzsU0jItR2MjSlkgIq6OjZrgTeZloQ1Gjd3QltAjrUc2UECT28U5R0+LHBIzWyT OYlyx0Ti1G59QXL9/Z3MjFXutOCYGKz1EW0rVb36rjoP83K2tt4xv7bxIeb4Dk6vYhYh2gO9fdcm 6p8DNle1Hfh/a8xBhXkDjQn0/l/xfbsQUt+dIK2cg48Yp4W86ivOTtPaNi4TCPIZ3r+6kQIDAQAB o4ICVDCCAlAwHQYDVR0OBBYEFGlousizCDfLl9lHFk1+BgKCwjEfMIIBHAYDVR0gBIIBEzCCAQ8w ggELBgwqgUuM9ugpAQoDAgMwgfowMgYIKwYBBQUHAgEWJmh0dHA6Ly93d3cuYWNhZWlkLmN6L3Jv b3QyL2NwLXJxc2MucGRmMIHDBggrBgEFBQcCAjCBtgyBs1RlbnRvIGNlcnRpZmlrw6F0IGplIHZ5 ZMOhbiBqYWtvIEt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IHBvZGxlIHrD oWtvbmEgMjI3LzIwMDAgU2IuIC8gVGhpcyBpcyBRdWFsaWZpZWQgU3lzdGVtIENlcnRpZmljYXRl IGFjY29yZGluZyB0byBDemVjaCBBY3QgTm8uIDIyNy8yMDAwIENvbGwuMAkGA1UdEwQCMAAwHwYD VR0jBBgwFoAUlf4jUC/KY3DTwMElEiFyxbrmnl0wgaAGA1UdHwSBmDCBlTAvoC2gK4YpaHR0cDov L3d3dy5hY2FlaWQuY3ovcm9vdDIvY3JsL2FjdHVhbC5jcmwwMKAuoCyGKmh0dHA6Ly9wdWIxLmFj YWVpZC5jei9yb290Mi9jcmwvYWN0dWFsLmNybDAwoC6gLIYqaHR0cDovL3B1YjIuYWNhZWlkLmN6 L3Jvb3QyL2NybC9hY3R1YWwuY3JsMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQE AwIGwDAYBggrBgEFBQcBAwQMMAowCAYGBACORgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBZfD2XJ7Ad /InxiCtSsowPG7ffrh/+BLPcSfE833Ddu5Tl2F86EdBKARe4lezDAPAfvP5WvyZTOeXvQplu80IC fDYRvdhUTbezFPsMuQjp1KNu1y+jR/XVRpfAxO5u2JHt9aGb0VfKwQB7FIymX0/bF5KeMnhiK1GR 5AVO4HAHqaveenSjqT8wm1xUdmLhECWNV+9BvG37JNAAkR2VhKqBCsFnlxsHDGF9Ak9EMtSZyURP NQ8+0WvygReanjbXWmBeSyADxvV86q3zK01CZkDBM4erR40gODjRq283Yz3nD44nDEUsapDs/4Jn EY1ROQc6W4NNdvf5eGIYdk7zVoaJ -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: ACAeID2 - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184/2396, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: TSU1 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ Valid from: Fri Apr 23 12:25:10 CEST 2010 Valid to: Sat Apr 23 12:25:10 CEST 2016 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 227 ETSI 2014 - TSL HR - PDF/A-1b generator Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:F2:C0:77:03:E6:98:F0:BC:0F:16:77:26:DD:99:3A:F1:9B:87:06:5E:DB:B0:87:A3:5A:6A:7F:A9:53:6E:74:01:F9:26:83 :1E:F9:27:1D:9F:A5:C8:16:02:19:A3:AF:30:FE:24:74:A1:27:FD:9B:AC:5A:CE:C1:E7:2F:D1:CA:61:CC:BB:38:42:EA:36:54:3A:8A:11:CC:D1:ED:58:35:5A:22:0D:AE:A8:A2:79:59:B4:C0:67:66:E9:A0:F3:EF:0D:97:42:D0: BA:3C:EC:53:48:C8:B5:1D:8C:8D:29:64:80:8A:BA:3A:36:6B:81:37:99:96:84:35:1A:37:77:42:5B:40:8E:B5:1C:D9:41:02:4F:6F:14:E5:1D:3E:2C:70:48:CD:6C:93:39:89:72:C7:44:E2:D4:6E:7D:41:72:FD:FD:9D:CC:8C:55:E E:B4:E0:98:18:AC:F5:11:6D:2B:55:BD:FA:AE:3A:0F:F3:72:B6:B6:DE:31:BF:B6:F1:21:E6:F8:0E:4E:AF:62:16:21:DA:03:BD:7D:D7:26:EA:9F:03:36:57:B5:1D:F8:7F:6B:CC:41:85:79:03:8D:09:F4:FE:5F:F1:7D:BB:10:52: DF:9D:20:AD:9C:83:8F:18:A7:85:BC:EA:2B:CE:4E:D3:DA:36:2E:13:08:F2:19:DE:BF:BA:91:02:03:01:00:01 Subject Key Identifier 69:68:BA:C8:B3:08:37:CB:97:D9:47:16:4D:7E:06:02:82:C2:31:1F Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.2.3 CPS pointer: http://www.acaeid.cz/root2/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: false Authority Key Identifier 95:FE:23:50:2F:CA:63:70:D3:C0:C1:25:12:21:72:C5:BA:E6:9E:5D CRL Distribution Points http://www.acaeid.cz/root2/crl/actual.crl http://pub1.acaeid.cz/root2/crl/actual.crl http://pub2.acaeid.cz/root2/crl/actual.crl Extended Key Usage id_kp_timeStamping QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 49:32:3A:9A:F5:B8:D4:FB:79:F2:83:76:6C:22:35:1A:0A:72:5B:D2:1C:47:28:EB:8C:F1:CA:52:49: 55:F0:A5 Service Status Service status description Status Starting Time http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. 2016-07-01T00:00:00Z 160.3.1 - History instance n.1 - Status: accredited CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 228 ETSI 2014 - TSL HR - PDF/A-1b generator Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (24) ACAeID2 - Time Stamping Authority TSA1, TSU1 Name [ cs ] (24) ACAeID2 - autorita časových razítek TSA1, TSU1 Service digital identities X509SubjectName Subject CN: TSU1 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I aWi6yLMIN8uX2UcWTX4GAoLCMR8= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2010-08-19T23:00:00Z 160.4 - Service (granted): (64) ACAeID2.1 - issuing qualified certificates Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/CA/QC [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [it] Un servizio di generazione di certificato, per creare e firmare certificati qualificati basati sull'identità e altri attributi verificati dai servizi di registrazione pertinenti. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. [de] Ein Zertifikat Generation Service Erstellung und Unterzeichnung qualifizierte Zertifikate basierend auf der Identität und andere Attribute, die von den jeweiligen Registrierungsdienste überprüft. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 229 ETSI 2014 - TSL HR - PDF/A-1b generator [fr] Un service de génération de certificat et la signature de la création de certificats qualifiés sur la base de l'identité et d'autres attributs vérifiées par les services d'enregistrement pertinents. [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Name [ en ] (64) ACAeID2.1 - issuing qualified certificates Name [ cs ] (64) ACAeID2.1 - vydávání kvalifikovaných certifikátů Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 1091149965 X509 Certificate -----BEGIN CERTIFICATE----MIIGxjCCBa6gAwIBAgIEQQmgjTANBgkqhkiG9w0BAQsFADCB+zELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBj ZXJ0aWZpa2HEjW7DrWNoIHNsdcW+ZWIxLzAtBgNVBAcMJlZpbm9ocmFkc2vDoSAxODQvMjM5Niwg MTMwIDAwLCBQcmFoYSAzMWQwYgYDVQQDDFtBQ0FlSUQyIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlm aWNhdGUgKGt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kg Q0EpMB4XDTE1MDIwMTE4MDU0NFoXDTIxMDIwMTE4MDU0NFowggEDMQswCQYDVQQGEwJDWjEXMBUG A1UECgwOZUlkZW50aXR5IGEucy4xPDA6BgNVBAsMM0FrcmVkaXRvdmFuw70gcG9za3l0b3ZhdGVs IGNlcnRpZmlrYcSNbsOtY2ggc2x1xb5lYjEvMC0GA1UEBwwmVmlub2hyYWRza8OhIDE4NC8yMzk2 LCAxMzAgMDAsIFByYWhhIDMxbDBqBgNVBAMMY0FDQWVJRDIuMSAtIFF1YWxpZmllZCBJc3N1aW5n IENlcnRpZmljYXRlIChrdmFsaWZpa292YW7DvSBzeXN0w6ltb3bDvSBjZXJ0aWZpa8OhdCB2eWTD oXZhasOtY8OtIENBKTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALPfe5EsBaWR+tbo W2AC7CmnoakJ5iOqDaHtIG1T9j3uM24i3DrwL1C0GXQsjw41Ue77b/NT4AfNA+uKPSRwxDI/8eEt C7NSbDAUiY+IGu/QP+vKGOE67bmryW0PFqu7rOTJo62uRY1iO0jlUrJ7QTcwJu2lV+Zhr5ernrcZ z4Gd07Sh25QmmRv7dmpHCSGPY/Z4GBmxxvb0FOjbaR7nAJO19VOG2Wc1X96l4zuTwlgNxJArts2j aNH8GeZ15uo6v4MBnQ9VeCmlKnsSHmO/GH2PrPKWrhtxBbFlJ/BlcYSE1P0OihsADRTyoeUzLyEY UB83vKgT8FSdyLBMnh0XZicCAwEAAaOCAkUwggJBMB0GA1UdDgQWBBRsVM52ll7TsCnrR3W27769 jyIvODCCARwGA1UdIASCARMwggEPMIIBCwYMKoFLjPboKQEKAwIDMIH6MDIGCCsGAQUFBwIBFiZo dHRwOi8vd3d3LmFjYWVpZC5jei9yb290Mi9jcC1ycXNjLnBkZjCBwwYIKwYBBQUHAgIwgbYMgbNU ZW50byBjZXJ0aWZpa8OhdCBqZSB2eWTDoW4gamFrbyBLdmFsaWZpa292YW7DvSBzeXN0w6ltb3bD vSBjZXJ0aWZpa8OhdCBwb2RsZSB6w6Frb25hIDIyNy8yMDAwIFNiLiAvIFRoaXMgaXMgUXVhbGlm aWVkIFN5c3RlbSBDZXJ0aWZpY2F0ZSBhY2NvcmRpbmcgdG8gQ3plY2ggQWN0IE5vLiAyMjcvMjAw MCBDb2xsLjASBgNVHRMBAf8ECDAGAQH/AgEAMB8GA1UdIwQYMBaAFJX+I1AvymNw08DBJRIhcsW6 5p5dMIGgBgNVHR8EgZgwgZUwL6AtoCuGKWh0dHA6Ly93d3cuYWNhZWlkLmN6L3Jvb3QyL2NybC9h Y3R1YWwuY3JsMDCgLqAshipodHRwOi8vcHViMS5hY2FlaWQuY3ovcm9vdDIvY3JsL2FjdHVhbC5j cmwwMKAuoCyGKmh0dHA6Ly9wdWIyLmFjYWVpZC5jei9yb290Mi9jcmwvYWN0dWFsLmNybDAOBgNV HQ8BAf8EBAMCAQYwGAYIKwYBBQUHAQMEDDAKMAgGBgQAjkYBATANBgkqhkiG9w0BAQsFAAOCAQEA pcrAUznYp/byh5lup26zZ2nUQR0N1ay9Sykz6QtOF+sar3YkP6clmXMgqwODFz4M0R8jqScWp9Mq 8iU+SP8nV1kvoXv9it+vt4ykd94cWLvhdfVfPVj6UM8hhgZwDnXjfZVclIL7HcDikNjFq6zaHwBp 3u1Kn4q2v4xJHrKgyDjXY1P1rD1gL3v0bq7lvdDHx0BpBzWlWiI3ZMeFvVIiyod+qRRTwqDAtuoQ Kg1uvHUb2qI58iujoBpUmSVbJqLHt1aTeX8yejCtuRAPE1f/YaJ0pzpIUbeVye8t7jZJWh9S6iQD OQprUJbKpp8QgxnPCZjztgpkootYJTHV81HMsQ== -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: ACAeID2 - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184/2396, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: ACAeID2.1 - Qualified Issuing Certificate (kvalifikovaný systémový certifikát vydávající CA) Subject L: Vinohradská 184/2396, 130 00, Praha 3 Subject OU: Akreditovaný poskytovatel certifikačních služeb Subject O: eIdentity a.s. Subject C: CZ CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 230 ETSI 2014 - TSL HR - PDF/A-1b generator Valid from: Sun Feb 01 19:05:44 CET 2015 Valid to: Mon Feb 01 19:05:44 CET 2021 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B3:DF:7B:91:2C:05:A5:91:FA:D6:E8:5B:60:02:EC:29:A7:A1:A9:09:E6:23:AA:0D:A1:ED:20:6D:53:F6:3D:EE:33:6 E:22:DC:3A:F0:2F:50:B4:19:74:2C:8F:0E:35:51:EE:FB:6F:F3:53:E0:07:CD:03:EB:8A:3D:24:70:C4:32:3F:F1:E1:2D:0B:B3:52:6C:30:14:89:8F:88:1A:EF:D0:3F:EB:CA:18:E1:3A:ED:B9:AB:C9:6D:0F:16:AB:BB:AC:E4:C9 :A3:AD:AE:45:8D:62:3B:48:E5:52:B2:7B:41:37:30:26:ED:A5:57:E6:61:AF:97:AB:9E:B7:19:CF:81:9D:D3:B4:A1:DB:94:26:99:1B:FB:76:6A:47:09:21:8F:63:F6:78:18:19:B1:C6:F6:F4:14:E8:DB:69:1E:E7:00:93:B5:F5:53:8 6:D9:67:35:5F:DE:A5:E3:3B:93:C2:58:0D:C4:90:2B:B6:CD:A3:68:D1:FC:19:E6:75:E6:EA:3A:BF:83:01:9D:0F:55:78:29:A5:2A:7B:12:1E:63:BF:18:7D:8F:AC:F2:96:AE:1B:71:05:B1:65:27:F0:65:71:84:84:D4:FD:0E:8A:1 B:00:0D:14:F2:A1:E5:33:2F:21:18:50:1F:37:BC:A8:13:F0:54:9D:C8:B0:4C:9E:1D:17:66:27:02:03:01:00:01 Subject Key Identifier 6C:54:CE:76:96:5E:D3:B0:29:EB:47:75:B6:EF:BE:BD:8F:22:2F:38 Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.2.3 CPS pointer: http://www.acaeid.cz/root2/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: true - Path length: 0 Authority Key Identifier 95:FE:23:50:2F:CA:63:70:D3:C0:C1:25:12:21:72:C5:BA:E6:9E:5D CRL Distribution Points http://www.acaeid.cz/root2/crl/actual.crl http://pub1.acaeid.cz/root2/crl/actual.crl http://pub2.acaeid.cz/root2/crl/actual.crl QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: keyCertSign - cRLSign Thumbprint algorithm: SHA-256 Thumbprint: CA:A0:25:8C:B1:98:42:17:CF:52:D6:64:DA:A7:C9:F6:87:92:F1:96:37:E6:3C:59:F5:32:45:D2:1B: 6D:6A:2E Service Status Service status description Status Starting Time http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. 2016-07-01T00:00:00Z CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 231 ETSI 2014 - TSL HR - PDF/A-1b generator 160.4.1 - Extension (critical): Qualifiers [QCNoQSCD] Qualifier type description [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.2.4 160.4.2 - Extension (critical): additionalServiceInformation AdditionalServiceInformation URI [ en ] http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures 160.4.3 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/CA/QC Service Name Name [ en ] (64) ACAeID2.1 - issuing qualified certificates Name [ cs ] (64) ACAeID2.1 - vydávání kvalifikovaných certifikátů Service digital identities X509SubjectName Subject CN: ACAeID2.1 - Qualified Issuing Certificate (kvalifikovaný systémový certifikát vydávající CA) Subject L: Vinohradská 184/2396, 130 00, Praha 3 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 232 ETSI 2014 - TSL HR - PDF/A-1b generator Subject OU: Akreditovaný poskytovatel certifikačních služeb Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I bFTOdpZe07Ap60d1tu++vY8iLzg= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-02-01T18:05:44Z 160.4.3.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [it] è garantito dal fornitore di servizi di fiducia e controllato (modello di supervisione) o controllati (modello di accreditamento) dello Stato membro di riferimento (rispettivamente il suo organismo di supervisione o di accreditamento) che tutti i certificati qualificati rilasciati sotto il servizio specificato in "Service digital identity" e ulteriormente identificato dalle informazioni dei filtri utilizzati per identificare ulteriormente sotto il "Sdi" Servizio fiducia identificato che insieme preciso di certificati qualificati per i quali è richiesto queste informazioni supplementari per quanto riguarda la presenza o l'assenza di Secure dispositivo Signature Creation (SSCD) sostegno non sono supportati da un SSCD (ossia che la chiave privata associata alla chiave pubblica nel certificato non è memorizzato in un dispositivo di creazione di una firma sicura conforme con la legislazione europea applicabile). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 233 ETSI 2014 - TSL HR - PDF/A-1b generator [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [de] es wird von der Treuhandservice-Anbieter gewährleistet und durch den entsprechenden Mitgliedstaat (bzw. seiner Aufsichts-oder Akkreditierungsstelle) kontrolliert (Aufsichtsmodell) bzw. geprüft (Akkreditierungsmodell), dass alle, die qualifizierte Zertifikate unter der in "Service digital identity" Service und ausgestellt weiter durch den Filter verwendet werden, um weitere Informationen unter der "Sdi" identifizierten Treuhandservice zu identifizieren, die eine genaue Satz von qualifizierten Zertifikaten, für die diese zusätzliche Informationen in Bezug auf das Vorhandensein oder Fehlen von sicheren Signaturerstellungseinheit (SSEE)-Unterstützung erforderlich werden nicht unterstützt identifiziert von einer SSCD (dh, dass der private Schlüssel mit dem öffentlichen Schlüssel im Zertifikat zugeordnet ist, nicht in einer sicheren Signaturerstellungseinheit konform mit der europäischen Gesetzgebung gespeichert). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). [fr] elle est assurée par le prestataire de service de confiance et contrôlée (modèle de contrôle) ou vérifiés (modèle d'accréditation) par l'État membre de référence (respectivement son Organe de surveillance ou organisme d'accréditation) que tous les certificats qualifiés délivrés dans le cadre du service identifié dans «Service digital identity» et en outre identifié par les informations des filtres utilisés pour identifier plus précisément dans le cadre du "Sdi" de service de confiance identifiés, l'ensemble précis de certificats qualifiés pour lesquels cette information supplémentaire est nécessaire en ce qui concerne la présence ou l'absence de dispositif sécurisé de création de signature (SSCD) de soutien ne sont pas pris en charge par un SSCD (c'est à dire que la clé privée associée à la clé publique dans le certificat ne sont pas stockées dans un dispositif sécurisé conforme à la législation européenne applicable de création de signature). [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD Criteria list assert=atLeastOne Policy Identifier nodes: Identifier 1.2.203.27112489.1.10.1.2.4 160.5 - Service (withdrawn): (65) ACAeID2 - Time Stamping Authority TSA1, TSU2 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Service Name CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 234 ETSI 2014 - TSL HR - PDF/A-1b generator Name [ en ] (65) ACAeID2 - Time Stamping Authority TSA1, TSU2 Name [ cs ] (65) ACAeID2 - autorita časových razítek TSA1, TSU2 Service digital identities Certificate fields details Version: 3 Serial Number: 1435499340 X509 Certificate -----BEGIN CERTIFICATE----MIIGFDCCBPygAwIBAgIEVY/7TDANBgkqhkiG9w0BAQsFADCB+zELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBj ZXJ0aWZpa2HEjW7DrWNoIHNsdcW+ZWIxLzAtBgNVBAcMJlZpbm9ocmFkc2vDoSAxODQvMjM5Niwg MTMwIDAwLCBQcmFoYSAzMWQwYgYDVQQDDFtBQ0FlSUQyIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlm aWNhdGUgKGt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kg Q0EpMB4XDTE1MDMxNzE0MjYzOFoXDTIxMDMxNzE0MjYzOFowRDELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMQ0wCwYDVQQLDARUU0ExMQ0wCwYDVQQDDARUU1UyMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs4JluU+Nn0d+1p8YlAniYbR2EuIN4BJq8kPD81mHMcjY fReYsX21osWj1vy4di2S0dxGDe/Bn5itAQ/FhKjxF3+dnWgAXLIiahrbMhud6+lJvnrVaJkSewxP 7+pvU5SLdVMq6CkDZKMF6w62shkmbZPzzNvPAxycTAi9KTuZc7NIEZHkxGciWrHp8l0zad312DmM SnQCKerS5kbatnzkklg5W5uXMflKkzgmVkrEI+8v5qi3juQkbWB7ez5CnKwResaFARmW8SX/a92R 3QvXpkcmBzFYr0eVm7rL1vPhcdz1H3VKf5/uGBOuzSTBEn+X0bbQsbcjXMVL16stqV/2FwIDAQAB o4ICVDCCAlAwHQYDVR0OBBYEFATvf+PdLvbOVx7ZWAu+iqpVcwQdMIIBHAYDVR0gBIIBEzCCAQ8w ggELBgwqgUuM9ugpAQoDAgMwgfowMgYIKwYBBQUHAgEWJmh0dHA6Ly93d3cuYWNhZWlkLmN6L3Jv b3QyL2NwLXJxc2MucGRmMIHDBggrBgEFBQcCAjCBtgyBs1RlbnRvIGNlcnRpZmlrw6F0IGplIHZ5 ZMOhbiBqYWtvIEt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IHBvZGxlIHrD oWtvbmEgMjI3LzIwMDAgU2IuIC8gVGhpcyBpcyBRdWFsaWZpZWQgU3lzdGVtIENlcnRpZmljYXRl IGFjY29yZGluZyB0byBDemVjaCBBY3QgTm8uIDIyNy8yMDAwIENvbGwuMAkGA1UdEwQCMAAwHwYD VR0jBBgwFoAUlf4jUC/KY3DTwMElEiFyxbrmnl0wgaAGA1UdHwSBmDCBlTAvoC2gK4YpaHR0cDov L3d3dy5hY2FlaWQuY3ovcm9vdDIvY3JsL2FjdHVhbC5jcmwwMKAuoCyGKmh0dHA6Ly9wdWIxLmFj YWVpZC5jei9yb290Mi9jcmwvYWN0dWFsLmNybDAwoC6gLIYqaHR0cDovL3B1YjIuYWNhZWlkLmN6 L3Jvb3QyL2NybC9hY3R1YWwuY3JsMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQE AwIGwDAYBggrBgEFBQcBAwQMMAowCAYGBACORgEBMA0GCSqGSIb3DQEBCwUAA4IBAQB9REaVhGap BeiMNzkqNg8N+xGvaSSrA5TjV09eyE2BS8jtpuXWy9EYwiWdno711jVXYec4A3kqAfU86GFMCkie IMAikIPJ+gsn/zN/fvBPUc+7vUY6bGTEVQyqWPYkmJ0+HaA7p/yY4gtQsBtAZlw7UadWbvB3hYPv aKOk1wh/0KYdIGraL4t1l/mL9E/E6K2YKvotCxqEWEXFzYh1asY8uXnDYTV/ITd0uMIun+Vuq9HQ yWFJ9g8g1bMq5Di51iW5EkKwE3JbV7zdpAnVUtnu9lBKb/CK+pFZ+7wVznh/6V4STh8UbeRuQS8O 1ypIATC9SWQ+PlyOgW/LFQkBUXVM -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: ACAeID2 - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184/2396, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: TSU2 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ Valid from: Tue Mar 17 15:26:38 CET 2015 Valid to: Wed Mar 17 15:26:38 CET 2021 Public Key: Subject Key Identifier 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:B3:82:65:B9:4F:8D:9F:47:7E:D6:9F:18:94:09:E2:61:B4:76:12:E2:0D:E0:12:6A:F2:43:C3:F3:59:87:31:C8:D8:7D:17: 98:B1:7D:B5:A2:C5:A3:D6:FC:B8:76:2D:92:D1:DC:46:0D:EF:C1:9F:98:AD:01:0F:C5:84:A8:F1:17:7F:9D:9D:68:00:5C:B2:22:6A:1A:DB:32:1B:9D:EB:E9:49:BE:7A:D5:68:99:12:7B:0C:4F:EF:EA:6F:53:94:8B:75:53:2A:E 8:29:03:64:A3:05:EB:0E:B6:B2:19:26:6D:93:F3:CC:DB:CF:03:1C:9C:4C:08:BD:29:3B:99:73:B3:48:11:91:E4:C4:67:22:5A:B1:E9:F2:5D:33:69:DD:F5:D8:39:8C:4A:74:02:29:EA:D2:E6:46:DA:B6:7C:E4:92:58:39:5B:9B:97 :31:F9:4A:93:38:26:56:4A:C4:23:EF:2F:E6:A8:B7:8E:E4:24:6D:60:7B:7B:3E:42:9C:AC:11:7A:C6:85:01:19:96:F1:25:FF:6B:DD:91:DD:0B:D7:A6:47:26:07:31:58:AF:47:95:9B:BA:CB:D6:F3:E1:71:DC:F5:1F:75:4A:7F:9F: EE:18:13:AE:CD:24:C1:12:7F:97:D1:B6:D0:B1:B7:23:5C:C5:4B:D7:AB:2D:A9:5F:F6:17:02:03:01:00:01 04:EF:7F:E3:DD:2E:F6:CE:57:1E:D9:58:0B:BE:8A:AA:55:73:04:1D CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 235 ETSI 2014 - TSL HR - PDF/A-1b generator Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.2.3 CPS pointer: http://www.acaeid.cz/root2/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: false Authority Key Identifier 95:FE:23:50:2F:CA:63:70:D3:C0:C1:25:12:21:72:C5:BA:E6:9E:5D CRL Distribution Points http://www.acaeid.cz/root2/crl/actual.crl http://pub1.acaeid.cz/root2/crl/actual.crl http://pub2.acaeid.cz/root2/crl/actual.crl Extended Key Usage id_kp_timeStamping QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 2B:A2:D8:AE:62:53:25:29:EB:10:F7:F4:83:48:F9:4B:52:1C:65:4C:48:6C:4B:6F:33:52:9B:72:AC:E B:E6:90 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 160.5.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (65) ACAeID2 - Time Stamping Authority TSA1, TSU2 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 236 ETSI 2014 - TSL HR - PDF/A-1b generator Name [ cs ] (65) ACAeID2 - autorita časových razítek TSA1, TSU2 Service digital identities X509SubjectName Subject CN: TSU2 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I BO9/490u9s5XHtlYC76KqlVzBB0= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-03-17T14:26:38Z 160.6 - Service (withdrawn): (74) ACAeID2 - Time Stamping Authority TSA1, TSU3 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (74) ACAeID2 - Time Stamping Authority TSA1, TSU3 Name [ cs ] (74) ACAeID2 - autorita časových razítek TSA1, TSU3 Service Name Service digital identities Certificate fields details CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 237 ETSI 2014 - TSL HR - PDF/A-1b generator Version: 3 Serial Number: 602067676 X509 Certificate -----BEGIN CERTIFICATE----MIIGFDCCBPygAwIBAgIEI+LS3DANBgkqhkiG9w0BAQsFADCB+zELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBj ZXJ0aWZpa2HEjW7DrWNoIHNsdcW+ZWIxLzAtBgNVBAcMJlZpbm9ocmFkc2vDoSAxODQvMjM5Niwg MTMwIDAwLCBQcmFoYSAzMWQwYgYDVQQDDFtBQ0FlSUQyIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlm aWNhdGUgKGt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kg Q0EpMB4XDTE1MDczMTEwMDUwMFoXDTIxMDczMTEwMDUwMFowRDELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMQ0wCwYDVQQLDARUU0ExMQ0wCwYDVQQDDARUU1UzMIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1wGnjthcQ7U+A0pI2t5uzli9Jz7+Ym/KrfrcqoGyiSDg FJaZh1sB0o6LEDHYtbo3CfFKvVGulle/QDQqAlkoRZploQIeF+XiriKQ61FIIO1gsLF6ODCFqQzo yyxuYzl0hsQc2/2VLKitPKu+vabaAQcU7JRdQa46rjn46i9D7dyOST9Vo9KYUkELaEWfzeYq2BFb XHRHlBxL5P/7Nen/6az2KmZwUVHqg3G4/Jj7b8moRCyjCDJUqZSEecOxtXHmkrMA3qo4gtnt+gUU k+xnUYExnPg2DzCvvUWjLAtIgnCaDHAU6svl5+W/8nOXY+6PmUgjM0XqF34awk2yjAxQMQIDAQAB o4ICVDCCAlAwHQYDVR0OBBYEFFlLWoSCSDMWsmprBE66xEafTFZtMIIBHAYDVR0gBIIBEzCCAQ8w ggELBgwqgUuM9ugpAQoDAgMwgfowMgYIKwYBBQUHAgEWJmh0dHA6Ly93d3cuYWNhZWlkLmN6L3Jv b3QyL2NwLXJxc2MucGRmMIHDBggrBgEFBQcCAjCBtgyBs1RlbnRvIGNlcnRpZmlrw6F0IGplIHZ5 ZMOhbiBqYWtvIEt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IHBvZGxlIHrD oWtvbmEgMjI3LzIwMDAgU2IuIC8gVGhpcyBpcyBRdWFsaWZpZWQgU3lzdGVtIENlcnRpZmljYXRl IGFjY29yZGluZyB0byBDemVjaCBBY3QgTm8uIDIyNy8yMDAwIENvbGwuMAkGA1UdEwQCMAAwHwYD VR0jBBgwFoAUlf4jUC/KY3DTwMElEiFyxbrmnl0wgaAGA1UdHwSBmDCBlTAvoC2gK4YpaHR0cDov L3d3dy5hY2FlaWQuY3ovcm9vdDIvY3JsL2FjdHVhbC5jcmwwMKAuoCyGKmh0dHA6Ly9wdWIxLmFj YWVpZC5jei9yb290Mi9jcmwvYWN0dWFsLmNybDAwoC6gLIYqaHR0cDovL3B1YjIuYWNhZWlkLmN6 L3Jvb3QyL2NybC9hY3R1YWwuY3JsMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQE AwIGwDAYBggrBgEFBQcBAwQMMAowCAYGBACORgEBMA0GCSqGSIb3DQEBCwUAA4IBAQAaxpHVB6cA uEzJDAEWi5VX1rDLgm7HHeL99fyiMFgqYoaajn+Hgw5bytYcHDDUyYgt+wAsu1gfmbnfPByo1wQu yzQoS6lwqF40aRMjL6YHZBqxoyYG5ToNnzUwKzXUK1MuSklv2GcpFMeIZ3kSanW8NHUPZzzFABan L91AqclOGedWLvMnfSPVA/i6KTbWRMhQctxrOkjaT8tZjSfQw1GlMhYc2DTpZO9FoHfmqmZBT4RW sY+NHLA7+SB5tGcwICi9oHwGtLJVAe5ks+KZjzAJtqme7ytAw4AAjLdVxu8BtR0lxjQSd+ZPgxQ9 D75gp4O+Nbc334vHiymZqJstKOm7 -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: ACAeID2 - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184/2396, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: TSU3 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ Valid from: Fri Jul 31 12:05:00 CEST 2015 Valid to: Sat Jul 31 12:05:00 CEST 2021 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:D7:01:A7:8E:D8:5C:43:B5:3E:03:4A:48:DA:DE:6E:CE:58:BD:27:3E:FE:62:6F:CA:AD:FA:DC:AA:81:B2:89:20:E0: 14:96:99:87:5B:01:D2:8E:8B:10:31:D8:B5:BA:37:09:F1:4A:BD:51:AE:96:57:BF:40:34:2A:02:59:28:45:9A:65:A1:02:1E:17:E5:E2:AE:22:90:EB:51:48:20:ED:60:B0:B1:7A:38:30:85:A9:0C:E8:CB:2C:6E:63:39:74:86:C4:1C: DB:FD:95:2C:A8:AD:3C:AB:BE:BD:A6:DA:01:07:14:EC:94:5D:41:AE:3A:AE:39:F8:EA:2F:43:ED:DC:8E:49:3F:55:A3:D2:98:52:41:0B:68:45:9F:CD:E6:2A:D8:11:5B:5C:74:47:94:1C:4B:E4:FF:FB:35:E9:FF:E9:AC:F6:2 A:66:70:51:51:EA:83:71:B8:FC:98:FB:6F:C9:A8:44:2C:A3:08:32:54:A9:94:84:79:C3:B1:B5:71:E6:92:B3:00:DE:AA:38:82:D9:ED:FA:05:14:93:EC:67:51:81:31:9C:F8:36:0F:30:AF:BD:45:A3:2C:0B:48:82:70:9A:0C:70:14: EA:CB:E5:E7:E5:BF:F2:73:97:63:EE:8F:99:48:23:33:45:EA:17:7E:1A:C2:4D:B2:8C:0C:50:31:02:03:01:00:01 Subject Key Identifier 59:4B:5A:84:82:48:33:16:B2:6A:6B:04:4E:BA:C4:46:9F:4C:56:6D Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.2.3 CPS pointer: http://www.acaeid.cz/root2/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: false CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 238 ETSI 2014 - TSL HR - PDF/A-1b generator Authority Key Identifier 95:FE:23:50:2F:CA:63:70:D3:C0:C1:25:12:21:72:C5:BA:E6:9E:5D CRL Distribution Points http://www.acaeid.cz/root2/crl/actual.crl http://pub1.acaeid.cz/root2/crl/actual.crl http://pub2.acaeid.cz/root2/crl/actual.crl Extended Key Usage id_kp_timeStamping QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 4D:76:86:2B:0C:CD:C7:3E:92:88:E9:04:66:0B:4A:59:65:2F:21:FF:97:A8:4D:F0:14:7D:54:93:1D:7 1:C0:E4 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 160.6.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (74) ACAeID2 - Time Stamping Authority TSA1, TSU3 Name [ cs ] (74) ACAeID2 - autorita časových razítek TSA1, TSU3 Service digital identities X509SubjectName CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 239 ETSI 2014 - TSL HR - PDF/A-1b generator Subject CN: TSU3 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I WUtahIJIMxayamsETrrERp9MVm0= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-07-31T10:05:00Z 160.7 - Service (withdrawn): (75) ACAeID2 - Time Stamping Authority TSA1, TSU4 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (75) ACAeID2 - Time Stamping Authority TSA1, TSU4 Name [ cs ] (75) ACAeID2 - autorita časových razítek TSA1, TSU4 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 773696552 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 240 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGFDCCBPygAwIBAgIELh2sKDANBgkqhkiG9w0BAQsFADCB+zELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBj ZXJ0aWZpa2HEjW7DrWNoIHNsdcW+ZWIxLzAtBgNVBAcMJlZpbm9ocmFkc2vDoSAxODQvMjM5Niwg MTMwIDAwLCBQcmFoYSAzMWQwYgYDVQQDDFtBQ0FlSUQyIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlm aWNhdGUgKGt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kg Q0EpMB4XDTE1MDczMTEwMDUwOVoXDTIxMDczMTEwMDUwOVowRDELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMQ0wCwYDVQQLDARUU0ExMQ0wCwYDVQQDDARUU1U0MIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnxJ9UZNrLq8Dgnh+Sm84SZrLuntojyy55d6THS8eatQf /MsqEs0gVGGbkALW38JVsvJfYf06xpKa6RJL9e85jKdQoHp0TTTltkWTew/9cman7EHDj7yeUI8g 6mfw+hB7y8bQ8/Tj41TQt4Ursm6eOeaz7lXeumfJZoHto8PK8nJJTVOZOl8iUBF9mm4wYQgayO1f Tq61UTcprYEvXBGLM77tzi3PLK87k+X5FraYdaRzK9nYm2CknlDIF4LC6eFGMUtvgaM0lMbab83c k4w41TM8wThnkiMy5sX2KeMAnOutbzNZOfXNulBJlSUAt4fsdX4GTlaYYcwBIkt/McVgBwIDAQAB o4ICVDCCAlAwHQYDVR0OBBYEFMjWlShGDRUqRW8vaQlz9c8QxkdaMIIBHAYDVR0gBIIBEzCCAQ8w ggELBgwqgUuM9ugpAQoDAgMwgfowMgYIKwYBBQUHAgEWJmh0dHA6Ly93d3cuYWNhZWlkLmN6L3Jv b3QyL2NwLXJxc2MucGRmMIHDBggrBgEFBQcCAjCBtgyBs1RlbnRvIGNlcnRpZmlrw6F0IGplIHZ5 ZMOhbiBqYWtvIEt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IHBvZGxlIHrD oWtvbmEgMjI3LzIwMDAgU2IuIC8gVGhpcyBpcyBRdWFsaWZpZWQgU3lzdGVtIENlcnRpZmljYXRl IGFjY29yZGluZyB0byBDemVjaCBBY3QgTm8uIDIyNy8yMDAwIENvbGwuMAkGA1UdEwQCMAAwHwYD VR0jBBgwFoAUlf4jUC/KY3DTwMElEiFyxbrmnl0wgaAGA1UdHwSBmDCBlTAvoC2gK4YpaHR0cDov L3d3dy5hY2FlaWQuY3ovcm9vdDIvY3JsL2FjdHVhbC5jcmwwMKAuoCyGKmh0dHA6Ly9wdWIxLmFj YWVpZC5jei9yb290Mi9jcmwvYWN0dWFsLmNybDAwoC6gLIYqaHR0cDovL3B1YjIuYWNhZWlkLmN6 L3Jvb3QyL2NybC9hY3R1YWwuY3JsMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQE AwIGwDAYBggrBgEFBQcBAwQMMAowCAYGBACORgEBMA0GCSqGSIb3DQEBCwUAA4IBAQDTcy1JWGIu eEYj4XKuBD8Utb1w6gdVDEwVLRXgrJLmfKbdvnsy1aW/iYD9mEsGi+CjZCK4QGISo0XepcTI/nxv LILs0CQY84AIvBkblD9iV8+CQ8Ct4s39y8V4mhYojTy1FC2P9Sl5rWl4BCFlvUaUKIzzQRjRTuRD hikE/7ufh8/KxuXsQjrE12FwpK5265GPAA8FXgkRBz2DKQPOaKdqRYcwULtqx4ETi2wa1+HgBdT5 9lKACe2jtIae4S0ohdduHaI+WsTSNbeAcAX5Zjng/6rEoE5AIoIZqfDWpZCs7jH4i9TO3Es/EdYc otCEqouqVfDpL4sw6mImE+BKennI -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: ACAeID2 - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184/2396, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: TSU4 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ Valid from: Fri Jul 31 12:05:09 CEST 2015 Valid to: Sat Jul 31 12:05:09 CEST 2021 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:9F:12:7D:51:93:6B:2E:AF:03:82:78:7E:4A:6F:38:49:9A:CB:BA:7B:68:8F:2C:B9:E5:DE:93:1D:2F:1E:6A:D4:1F:FC: CB:2A:12:CD:20:54:61:9B:90:02:D6:DF:C2:55:B2:F2:5F:61:FD:3A:C6:92:9A:E9:12:4B:F5:EF:39:8C:A7:50:A0:7A:74:4D:34:E5:B6:45:93:7B:0F:FD:72:66:A7:EC:41:C3:8F:BC:9E:50:8F:20:EA:67:F0:FA:10:7B:CB:C6:D0: F3:F4:E3:E3:54:D0:B7:85:2B:B2:6E:9E:39:E6:B3:EE:55:DE:BA:67:C9:66:81:ED:A3:C3:CA:F2:72:49:4D:53:99:3A:5F:22:50:11:7D:9A:6E:30:61:08:1A:C8:ED:5F:4E:AE:B5:51:37:29:AD:81:2F:5C:11:8B:33:BE:ED:CE:2D :CF:2C:AF:3B:93:E5:F9:16:B6:98:75:A4:73:2B:D9:D8:9B:60:A4:9E:50:C8:17:82:C2:E9:E1:46:31:4B:6F:81:A3:34:94:C6:DA:6F:CD:DC:93:8C:38:D5:33:3C:C1:38:67:92:23:32:E6:C5:F6:29:E3:00:9C:EB:AD:6F:33:59:39:F 5:CD:BA:50:49:95:25:00:B7:87:EC:75:7E:06:4E:56:98:61:CC:01:22:4B:7F:31:C5:60:07:02:03:01:00:01 Subject Key Identifier C8:D6:95:28:46:0D:15:2A:45:6F:2F:69:09:73:F5:CF:10:C6:47:5A Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.2.3 CPS pointer: http://www.acaeid.cz/root2/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: false Authority Key Identifier 95:FE:23:50:2F:CA:63:70:D3:C0:C1:25:12:21:72:C5:BA:E6:9E:5D CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 241 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.acaeid.cz/root2/crl/actual.crl http://pub1.acaeid.cz/root2/crl/actual.crl http://pub2.acaeid.cz/root2/crl/actual.crl Extended Key Usage id_kp_timeStamping QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: FF:F3:12:9D:D3:B9:12:8B:F3:7F:76:AC:18:92:1E:51:5A:84:49:7D:CB:45:78:11:9F:22:5D:F4:E0:0 0:13:FD Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 160.7.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (75) ACAeID2 - Time Stamping Authority TSA1, TSU4 Name [ cs ] (75) ACAeID2 - autorita časových razítek TSA1, TSU4 Service digital identities X509SubjectName Subject CN: TSU4 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 242 ETSI 2014 - TSL HR - PDF/A-1b generator Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I yNaVKEYNFSpFby9pCXP1zxDGR1o= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-07-31T10:05:09Z 160.8 - Service (withdrawn): (76) ACAeID2 - Time Stamping Authority TSA1, TSU5 Service Type Identifier Service type description http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [it] Un servizio di marcatura temporale per la creazione e la firma qualificata di token time-stamp. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [de] Ein Zeit-Stempeln Generation Service Erstellung und Unterzeichnung qualifizierte Zeitstempel-Tokens. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. [fr] Un service de génération horodatage création et la signature temps timbres jetons qualifiés. [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Name [ en ] (76) ACAeID2 - Time Stamping Authority TSA1, TSU5 Name [ cs ] (76) ACAeID2 - autorita časových razítek TSA1, TSU5 Service Name Service digital identities Certificate fields details Version: 3 Serial Number: 731128227 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 243 ETSI 2014 - TSL HR - PDF/A-1b generator X509 Certificate -----BEGIN CERTIFICATE----MIIGFDCCBPygAwIBAgIEK5QhozANBgkqhkiG9w0BAQsFADCB+zELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMTwwOgYDVQQLDDNBa3JlZGl0b3ZhbsO9IHBvc2t5dG92YXRlbCBj ZXJ0aWZpa2HEjW7DrWNoIHNsdcW+ZWIxLzAtBgNVBAcMJlZpbm9ocmFkc2vDoSAxODQvMjM5Niwg MTMwIDAwLCBQcmFoYSAzMWQwYgYDVQQDDFtBQ0FlSUQyIC0gUXVhbGlmaWVkIFJvb3QgQ2VydGlm aWNhdGUgKGt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IGtvxZllbm92w6kg Q0EpMB4XDTE1MDczMTEwMDUxNFoXDTIxMDczMTEwMDUxNFowRDELMAkGA1UEBhMCQ1oxFzAVBgNV BAoMDmVJZGVudGl0eSBhLnMuMQ0wCwYDVQQLDARUU0ExMQ0wCwYDVQQDDARUU1U1MIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqkhpzKjJW03vqQKm3d8nMPnXVF5AepzaAA7xWKezeqHd 3PoNAur2V9FDQ1kLX4IMg1H5TH2J3uo6349m2vFiQNeJfx46okKzCushP1bmX4KebvmTJ25Hy3wp jszcZzLVj5ggBIUGnhd71k1/0Gto3X7XLTFzL37Zm/qjVYSuAiQcFVQ66PXQdxw0tP0SEyHWK77L vNqUZjyZjTpcRK/13UEKu6CHsjdH3ZTu5UbggXajxnWN/mwjoUQm3IxoEvNQyWfZ5aMkrzzVGTwY j7PC+4qgZHlsOcJ5n7T02IcrBpArdD8NgQFG1M4Z/OIs1aliI54TrlPmRTXmvlW6jcb87wIDAQAB o4ICVDCCAlAwHQYDVR0OBBYEFIEx/pi5KFFvKevZF3h346CES8tzMIIBHAYDVR0gBIIBEzCCAQ8w ggELBgwqgUuM9ugpAQoDAgMwgfowMgYIKwYBBQUHAgEWJmh0dHA6Ly93d3cuYWNhZWlkLmN6L3Jv b3QyL2NwLXJxc2MucGRmMIHDBggrBgEFBQcCAjCBtgyBs1RlbnRvIGNlcnRpZmlrw6F0IGplIHZ5 ZMOhbiBqYWtvIEt2YWxpZmlrb3ZhbsO9IHN5c3TDqW1vdsO9IGNlcnRpZmlrw6F0IHBvZGxlIHrD oWtvbmEgMjI3LzIwMDAgU2IuIC8gVGhpcyBpcyBRdWFsaWZpZWQgU3lzdGVtIENlcnRpZmljYXRl IGFjY29yZGluZyB0byBDemVjaCBBY3QgTm8uIDIyNy8yMDAwIENvbGwuMAkGA1UdEwQCMAAwHwYD VR0jBBgwFoAUlf4jUC/KY3DTwMElEiFyxbrmnl0wgaAGA1UdHwSBmDCBlTAvoC2gK4YpaHR0cDov L3d3dy5hY2FlaWQuY3ovcm9vdDIvY3JsL2FjdHVhbC5jcmwwMKAuoCyGKmh0dHA6Ly9wdWIxLmFj YWVpZC5jei9yb290Mi9jcmwvYWN0dWFsLmNybDAwoC6gLIYqaHR0cDovL3B1YjIuYWNhZWlkLmN6 L3Jvb3QyL2NybC9hY3R1YWwuY3JsMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQE AwIGwDAYBggrBgEFBQcBAwQMMAowCAYGBACORgEBMA0GCSqGSIb3DQEBCwUAA4IBAQDOch5WGmQ/ Bb4gvhvXIg2hMRG6YrmcLVZX/yTzWGOmM0hztYQt3lEVnrTVuzJaqZjpRl/iLqaIg5ut4KOAPKWK 7YHfskA8ZVMexvzvEOFaNMU+iF0lGkeMZ0L0VfFWEJKGac7IiDJQ0NECQrhF4qlibebz9TF7LGTe zZvHAwS0wgf64hR8DdUUmYvszXy/6i/HkYQhl9yvg9nKg80szhg10dpwLDD/S5/n/K0iikkiHSuq KWXLAuozvuPGawjSqN+A6+hrpqAxWqW1v1u+cr5S35l1ACsUVq7DuV7hrLXk+LlPzwfig+DLiGTa 9gNh4N+eV4WhBmZwGqe4o/XhPT/6 -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer CN: ACAeID2 - Qualified Root Certificate (kvalifikovaný systémový certifikát kořenové CA) Issuer L: Vinohradská 184/2396, 130 00, Praha 3 Issuer OU: Akreditovaný poskytovatel certifikačních služeb Issuer O: eIdentity a.s. Issuer C: CZ Subject CN: TSU5 Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ Valid from: Fri Jul 31 12:05:14 CEST 2015 Valid to: Sat Jul 31 12:05:14 CEST 2021 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:AA:48:69:CC:A8:C9:5B:4D:EF:A9:02:A6:DD:DF:27:30:F9:D7:54:5E:40:7A:9C:DA:00:0E:F1:58:A7:B3:7A:A1:DD: DC:FA:0D:02:EA:F6:57:D1:43:43:59:0B:5F:82:0C:83:51:F9:4C:7D:89:DE:EA:3A:DF:8F:66:DA:F1:62:40:D7:89:7F:1E:3A:A2:42:B3:0A:EB:21:3F:56:E6:5F:82:9E:6E:F9:93:27:6E:47:CB:7C:29:8E:CC:DC:67:32:D5:8F:98: 20:04:85:06:9E:17:7B:D6:4D:7F:D0:6B:68:DD:7E:D7:2D:31:73:2F:7E:D9:9B:FA:A3:55:84:AE:02:24:1C:15:54:3A:E8:F5:D0:77:1C:34:B4:FD:12:13:21:D6:2B:BE:CB:BC:DA:94:66:3C:99:8D:3A:5C:44:AF:F5:DD:41:0A:B B:A0:87:B2:37:47:DD:94:EE:E5:46:E0:81:76:A3:C6:75:8D:FE:6C:23:A1:44:26:DC:8C:68:12:F3:50:C9:67:D9:E5:A3:24:AF:3C:D5:19:3C:18:8F:B3:C2:FB:8A:A0:64:79:6C:39:C2:79:9F:B4:F4:D8:87:2B:06:90:2B:74:3F:0D: 81:01:46:D4:CE:19:FC:E2:2C:D5:A9:62:23:9E:13:AE:53:E6:45:35:E6:BE:55:BA:8D:C6:FC:EF:02:03:01:00:01 Subject Key Identifier 81:31:FE:98:B9:28:51:6F:29:EB:D9:17:78:77:E3:A0:84:4B:CB:73 Certificate Policies Policy OID: 1.2.203.27112489.1.10.3.2.3 CPS pointer: http://www.acaeid.cz/root2/cp-rqsc.pdf CPS text: [Tento certifikát je vydán jako Kvalifikovaný systémový certifikát podle zákona 227/2000 Sb. / This is Qualified System Certificate according to Czech Act No. 227/2000 Coll.] Basic Constraints IsCA: false Authority Key Identifier 95:FE:23:50:2F:CA:63:70:D3:C0:C1:25:12:21:72:C5:BA:E6:9E:5D CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 244 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://www.acaeid.cz/root2/crl/actual.crl http://pub1.acaeid.cz/root2/crl/actual.crl http://pub2.acaeid.cz/root2/crl/actual.crl Extended Key Usage id_kp_timeStamping QCStatements - crit. = false id_etsi_qcs_QcCompliance Key Usage: digitalSignature - nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 3D:C7:A6:E1:F4:2E:F1:F3:CD:46:12:D7:82:99:01:B1:6A:92:AE:FC:21:A9:9E:60:14:F0:49:A4:AE :A7:F8:B8 Service Status Service status description http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn [en] undefined. [it] undefined. [en] undefined. [it] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [de] undefined. [en] undefined. [fr] undefined. [en] undefined. Status Starting Time 2016-07-01T00:00:00Z 160.8.1 - History instance n.1 - Status: accredited Service Type Identifier http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST Service Name Name [ en ] (76) ACAeID2 - Time Stamping Authority TSA1, TSU5 Name [ cs ] (76) ACAeID2 - autorita časových razítek TSA1, TSU5 Service digital identities X509SubjectName Subject CN: TSU5 CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 245 ETSI 2014 - TSL HR - PDF/A-1b generator Subject OU: TSA1 Subject O: eIdentity a.s. Subject C: CZ X509SKI X509 SK I gTH+mLkoUW8p69kXeHfjoIRLy3M= Service Status http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited Status Starting Time 2015-07-31T10:05:14Z CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 246 ETSI 2014 - TSL HR - PDF/A-1b generator 161 - Signature node - Id: id-1043278fb84f5a2368db2c80a0992485 Signing Time 2016-07-25T08:31:16Z TSL Scheme Operator certificate fields details Version: 3 Serial Number: 11130858 X509 Certificate -----BEGIN CERTIFICATE----MIIFqDCCBJCgAwIBAgIEAKnX6jANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjY3JlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0xNjA1 MDQxMTE4NDdaFw0xNzA1MDQxMTE4NDdaMH4xCzAJBgNVBAYTAkNaMR0wGwYDVQQDDBRJbmcuIFJh ZG9tw61yIMWgaW1lazE3MDUGA1UECgwuTWluaXN0cnkgb2YgdGhlIEludGVyaW9yIG9mIHRoZSBD emVjaCBSZXB1YmxpYzEXMBUGA1UEBRMOSUNBIC0gMTAzNzE2OTEwggEiMA0GCSqGSIb3DQEBAQUA A4IBDwAwggEKAoIBAQCT+BNWDhQwCdestMlomCrMrdq46o2WNVqVDerllZwLd4Z7s/SjiptJ9QFQ hrR3xMtIag4t8UA8EDL+UqEfiuLNwyqIqaucB5mRuzkUslhQnLduFFT1tsYGXN5JoqSnE+LloLHP WcFgPkR/hFK/GJFnbObrjXfEHaQE9Lu9PZFrPuicJQW+rt9Fn1DkBPwJgZKejBXFkNPPJ+86NpR7 kwoja/sE626L9BJ99z7mrAFncs265cDcnvZkCC4ghgcoxyYu9R2EUSJWBpC/Rxcyt77gR2Xeujih 0qJeoBjaWljcYRE+M8wsnAqiIbIzJRoLf/2tKeH8OVQPfFFvL8baJ9hJAgMBAAGjggHyMIIB7jAR BgNVHSUECjAIBgYEAJE3AwAwgd8GA1UdIASB1zCB1DCB0QYNKwYBBAGBuEgBAR4DATCBvzCBvAYI KwYBBQUHAgIwga8agaxUZW50byBrdmFsaWZpa292YW55IGNlcnRpZmlrYXQgamUgdnlkYW4gcG9k bGUgemFrb25hIENlc2tlIHJlcHVibGlreSBjLiAyMjcvMjAwMCBTYi4gdiBwbGF0bmVtIHpuZW5p L1RoaXMgaXMgcXVhbGlmaWVkIGNlcnRpZmljYXRlIGFjY29yZGluZyB0byBDemVjaCBBY3QgTm8u IDIyNy8yMDAwIENvbGwuMIGBBgNVHR8EejB4MCagJKAihiBodHRwOi8vcWNybGRwMS5pY2EuY3ov cWljYTA5LmNybDAmoCSgIoYgaHR0cDovL3FjcmxkcDIuaWNhLmN6L3FpY2EwOS5jcmwwJqAkoCKG IGh0dHA6Ly9xY3JsZHAzLmljYS5jei9xaWNhMDkuY3JsMAkGA1UdEwQCMAAwDgYDVR0PAQH/BAQD AgZAMBgGCCsGAQUFBwEDBAwwCjAIBgYEAI5GAQEwHwYDVR0jBBgwFoAUecvQI+k6Z3CRdE/TUeLg IP3hKPswHQYDVR0OBBYEFBIoVGvnrWW3pMqkEcFrRgzug2yfMA0GCSqGSIb3DQEBCwUAA4IBAQCN MpAim4qAlSpGtdt2N9sDdsxBDyBU7GGHAqd8ggrJuOP3i/gZVFA/TX6K5UD5iilY1JSuEqun95GE 4ip/2JuII3lkQO2HqGSrs7omkN0OoegNOnzYTEHTDDr1M2YI+Kz4yFPTMVCNJPzrmy1VX9qcfKoU h/F3u1/qxecIGMgsbQT9WzF2CcSQsAtBk0RZnj1jysPMqSJmXrmOO5dVXGzljGeu7rAMKmrT0zqR J+3hYn9yPmhKoS+f2rnTpLk4gnYHd5TXczBd5Yv8PMoCUydbjg6e6tdlm5bPDHgLRkpiUVoXb/fG ZSVkhkh0PXmMmhGYlEHHedl4izP1cgXvfs8X -----END CERTIFICATE----- Signature algorithm: SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services Issuer O: První certifikační autorita, a.s. Issuer CN: I.CA - Qualified Certification Authority, 09/2009 Issuer C: CZ Subject SERIAL NUMBER: ICA - 10371691 Subject O: Ministry of the Interior of the Czech Republic Subject CN: Ing. Radomír Šimek Subject C: CZ Valid from: Wed May 04 13:18:47 CEST 2016 Valid to: Thu May 04 13:18:47 CEST 2017 Public Key: 30:82:01:22:30:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:03:82:01:0F:00:30:82:01:0A:02:82:01:01:00:93:F8:13:56:0E:14:30:09:D7:AC:B4:C9:68:98:2A:CC:AD:DA:B8:EA:8D:96:35:5A:95:0D:EA:E5:95:9C:0B:77:86:7B :B3:F4:A3:8A:9B:49:F5:01:50:86:B4:77:C4:CB:48:6A:0E:2D:F1:40:3C:10:32:FE:52:A1:1F:8A:E2:CD:C3:2A:88:A9:AB:9C:07:99:91:BB:39:14:B2:58:50:9C:B7:6E:14:54:F5:B6:C6:06:5C:DE:49:A2:A4:A7:13:E2:E5:A0:B1: CF:59:C1:60:3E:44:7F:84:52:BF:18:91:67:6C:E6:EB:8D:77:C4:1D:A4:04:F4:BB:BD:3D:91:6B:3E:E8:9C:25:05:BE:AE:DF:45:9F:50:E4:04:FC:09:81:92:9E:8C:15:C5:90:D3:CF:27:EF:3A:36:94:7B:93:0A:23:6B:FB:04:EB:6 E:8B:F4:12:7D:F7:3E:E6:AC:01:67:72:CD:BA:E5:C0:DC:9E:F6:64:08:2E:20:86:07:28:C7:26:2E:F5:1D:84:51:22:56:06:90:BF:47:17:32:B7:BE:E0:47:65:DE:BA:38:A1:D2:A2:5E:A0:18:DA:5A:58:DC:61:11:3E:33:CC:2C:9 C:0A:A2:21:B2:33:25:1A:0B:7F:FD:AD:29:E1:FC:39:54:0F:7C:51:6F:2F:C6:DA:27:D8:49:02:03:01:00:01 Extended Key Usage id-tsl-kp-tslSigning Certificate Policies Policy OID: 1.3.6.1.4.1.23624.1.1.30.3.1 CPS text: [Tento kvalifikovany certifikat je vydan podle zakona Ceske republiky c. 227/2000 Sb. v platnem zneni/This is qualified certificate according to Czech Act No. 227/2000 Coll.] CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 247 ETSI 2014 - TSL HR - PDF/A-1b generator CRL Distribution Points http://qcrldp1.ica.cz/qica09.crl http://qcrldp2.ica.cz/qica09.crl http://qcrldp3.ica.cz/qica09.crl Basic Constraints IsCA: false QCStatements - crit. = false id_etsi_qcs_QcCompliance Authority Key Identifier 79:CB:D0:23:E9:3A:67:70:91:74:4F:D3:51:E2:E0:20:FD:E1:28:FB Subject Key Identifier 12:28:54:6B:E7:AD:65:B7:A4:CA:A4:11:C1:6B:46:0C:EE:83:6C:9F Key Usage: nonRepudiation Thumbprint algorithm: SHA-256 Thumbprint: 16:27:F8:D5:07:F7:1C:BC:6A:9F:1B:5B:02:D2:D2:C4:29:7F:FE:13:81:A2:21:27:F1:D4:53:8D:CD: BA:FE:DD CESKÁ REPUBLIKA (CZECH REPUBLIC) - Trusted List ID: TSL_CZ Page 248
Similar documents
ROMÂNIA (ROMANIA) - Trusted List ID: ID_5
EU TSL digital identities TSL Scheme Operator certificate fields details Version:
More information