Skip Navigation

Enterprise PKI Services

Changes have been made to the way that software certificates are requested and how one manages key recovery.  This site will provide links and URLs to the Sponsor and Registrar Portal, FAQ's, training materials and updates on the new processes.

For help obtaining a certificate with the current system or questions about the new system, please contact a Registrar (former Local Registration Authority (LRA)) or your OPDIV's local help desk.

Updating Windows Certificate Chain

The Windows Certificate Chain and the Firefox and Mac Certificate Chain are guidance documents for use by HHS users and system administrators. Please note that these are draft documents and domain administrators may need to test and tailor the Windows Certificate Chain or Firefox and Mac Certificate Chain to their respective environment.  

Software Certificate Request Form:

Certificate Request Form

HHS PKI Trust Anchors:

Common Policy Trust Anchor Link (*HHS Recommended)CyberTrust Root Certificate LinkDST ACES Device Certificate Link

HHS Domain Device Root CA CRL:

HHS Domain Device Root Certificate Revocation List contains list of certificates (or more specifically, a list of serial numbers for certificates) that have been revoked by the HHS Domain Device CA, and therefore should not be relied upon.

HHS Domain Device Root CA CRL

HHS Domain Device Certificate Policy 

Certificate Policy governing the public key infrastructure (PKI) component of the network infrastructure within the Health and Human Services (HHS) Agency. This policy is specifically only for devices within a domain operated by or on behalf of any HHS Operational Division.

HHS Domain Device CA Certificate Policy

HHS Domain Device Root Certificate Authority self-signed root certificate

HHS Domain Device CA

 

Click here for information on requesting a TLS (Transport Layer Security) Certificate

 

The following link to the Software Certificate Issuance Subscriber Training Document will provide users with step-by-step instructions on the process the Subscriber must complete in the software certificate request and collection process using the Windows Operating System.  In addition Subscribers can also download the TLS Root Chain Link.  

If you are NIH staff, please go to http://ocio.nih.gov/pki in order to obtain your digital certificates and training.