Page 1 Version: 3.5, 4.11.2015 SERVER CERTIFICATES OF THE VETUMA SERVICE 1 (18)
Page 2 Version: 3.5, 4.11.2015 Table of Contents 1. Introduction... 3 2. Test Environment... 3 2.1 Vetuma test environment... 3 2.1.1 Test environment server certificate... 3 2.1.2 of server certificate in the test environment... 4 2.1.3 Root certificate of the test environment issuer certificate... 4 2.2 Signature certificate for SAML messages in the test environment... 5 2.2.1 Test environment signature certificate... 5 2.2.2 of test environment signature certificate (and root certificate)... 5 2.3 Shared domain test environment for federation... 6 2.3.1 Test environment server certificate... 6 2.3.2 of test environment server certificate... 7 2.3.3 Root certificate of the test environment issuer certificate... 7 2.4 Shared domain test environment for identity provider discovery... 8 2.4.1 Test environment server certificate... 8 2.4.2 of test environment server certificate... 9 2.4.3 Root certificate of the test environment issuer certificate... 9 3. Production Environment... 10 3.1 Vetuma production environment... 10 3.1.1 Server certificate... 10 3.1.2 of server certificate... 10 3.1.3 Root certificate of the issuer certificate... 11 3.2 Signature certificate for SAML messages in the production environment... 11 3.2.1 Signature certificate of the production environment... 12 3.2.2 of production environment signature certificate... 12 3.2.3 Root certificate of the production environment signature certificate... 13 3.3 Shared domain production environment for federation... 13 3.3.1 Server certificate... 13 3.3.2 of server certificate... 14 3.3.3 Production environment signature certificate... 14 3.4 Shared domain production environment for identity provider discovery... 15 3.4.1 Server certificate... 15 3.4.2 of server certificate... 15 3.4.3 Root certificate of the issuer certificate... 16 4. User ID Management in Test and Production Environments... 16 4.1 Server certificate... 17 4.2 of server certificate... 17 4.3 Root certificate of the issuer certificate... 18 2 (18)
Page 3 Version: 3.5, 4.11.2015 1. INTRODUCTION This document describes the server certificates used in the Vetuma service. This document is Appendix 1 to the document titled Vetuma Rajapintakuvaus. This document describes the values of the key fields of the certificates. The service utilizes the certificates of two different issuers: VRK and VeriSign. 2. TEST ENVIRONMENT 2.1 Vetuma test environment The url for the Vetuma test environment is: https://testitunnistus.suomi.fi A certificate signed by the Symantec issuer is in use. This certificate is pre-installed in most browsers as a trusted issuer. 2.1.1 Test environment server certificate Valid from 9.4.2014 3:00:00 25 e4 ed f3 7a ec 3e bd 36 da 8d d6 a8 a1 53 eb Valid to 10.4.2016 2:59:59 CN = testitunnistus.suomi.fi OU = Valtori e7 8d 13 58 fa a0 c0 64 f3 25 48 9d 57 7c cb 8a 0c aa 2e 29 3 (18)
Page 4 Version: 3.5, 4.11.2015 2.1.2 of server certificate in the test environment Valid from 31.10.2013 3:00:00 51 3f b9 74 38 70 b7 34 40 41 8d 30 93 06 99 ff CN = VeriSign Class 3 Public Primary Certification Authority - Valid to 31.10.2023 2:59:59 ff 67 36 7c 5c d4 de 4a e1 8b cc e1 d7 0f da bd 7c 86 61 35 2.1.3 Root certificate of the test environment issuer certificate 18 da d1 9e 26 7d e8 bb 4a 21 58 cd cc 6b 3b 4a RSA CN = VeriSign Class 3 Public Primary Certification Authority - Valid from 8.11.2006 2:00:00 Valid to 17.7.2036 1:59:59 CN = VeriSign Class 3 Public Primary Certification Authority - 4e b6 d5 78 49 9b 1c cf 5f 58 1e ad 56 be 3d 9b 67 44 a5 e5 4 (18)
Page 5 Version: 3.5, 4.11.2015 2.2 Signature certificate for SAML messages in the test environment The Vetuma test environment signature certificate for SAML messages resides in the IdP metadata of Vetuma. The url for the test environment IdP metadata: https://testitunnistus.suomi.fi/info/testitunnistus.suomi.fi-idp-metadata.xml 2.2.1 Test environment signature certificate 01 b4 RSA CN = Fujitsu Topsel CA OU = Fujitsu Finland Oy Valid from 24.8.2013 14:55:42 Valid to 22.10.2023 14:55:42 CN = VETUMA TEST SAML IDP OU = Valtionvarainministerio d9 6f 37 2e 75 9e 02 7b 38 62 73 ba 9a c2 57 8a 8a 85 90 fb 2.2.2 of test environment signature certificate (and root certificate) 00 a7 0f f1 b9 15 66 35 18 RSA CN = Fujitsu Topsel CA OU = Fujitsu Finland Oy Valid from 14.3.2012 15:45:55 5 (18)
Page 6 Version: 3.5, 4.11.2015 Valid to 9.3.2032 15:45:55 CN = Fujitsu Topsel CA OU = Fujitsu Finland Oy f5 a7 9d 7a a8 86 30 23 e2 77 bf 92 2e 15 cc 90 8a c0 07 22 2.3 Shared domain test environment for federation The url for the shared domain test environment for federation is: https://vetuma.testifederointi.suomi.fi A certificate signed by the Symantec issuer is in use. This certificate is pre-installed in most browsers as a trusted issuer. 2.3.1 Test environment server certificate Valid from 9.4.2014 3:00:00 40 83 89 e6 7f 7f ac 3d cf 3b 32 a8 05 6c 15 15 Valid to 10.4.2016 2:59:59 CN = vetuma.testifederointi.suomi.fi OU = Valtori 34 e1 ce fa d2 d6 fd d4 66 d3 ed 01 3b 36 21 e8 90 d9 2c 30 6 (18)
Page 7 Version: 3.5, 4.11.2015 2.3.2 of test environment server certificate Valid from 31.10.2013 3:00:00 51 3f b9 74 38 70 b7 34 40 41 8d 30 93 06 99 ff CN = VeriSign Class 3 Public Primary Certification Authority - Valid to 31.10.2023 2:59:59 ff 67 36 7c 5c d4 de 4a e1 8b cc e1 d7 0f da bd 7c 86 61 35 2.3.3 Root certificate of the test environment issuer certificate 18 da d1 9e 26 7d e8 bb 4a 21 58 cd cc 6b 3b 4a RSA CN = VeriSign Class 3 Public Primary Certification Authority - Valid from 8.11.2006 2:00:00 Valid to 17.7.2036 1:59:59 CN = VeriSign Class 3 Public Primary Certification Authority - 4e b6 d5 78 49 9b 1c cf 5f 58 1e ad 56 be 3d 9b 67 44 a5 e5 7 (18)
Page 8 Version: 3.5, 4.11.2015 2.4 Shared domain test environment for identity provider discovery The url for the shared domain in the Leijuke test environment is: https://leijuke.testifederointi.suomi.fi A certificate signed by the Symantec issuer is in use. This certificate is pre-installed in most browsers as a trusted issuer. 2.4.1 Test environment server certificate Valid from 9.4.2014 3:00:00 2b be 86 87 17 65 3e c8 d7 33 07 4c 3c 65 5f b7 Valid to 10.4.2016 2:59:59 CN = leijuke.testifederointi.suomi.fi OU = Valtori 5b 0e 1f 28 c8 5e 6c 2c 8c 21 42 fa 81 01 ef 7c af dd f2 69 8 (18)
Page 9 Version: 3.5, 4.11.2015 2.4.2 of test environment server certificate Valid from 31.10.2013 3:00:00 51 3f b9 74 38 70 b7 34 40 41 8d 30 93 06 99 ff CN = VeriSign Class 3 Public Primary Certification Authority - Valid to 31.10.2023 2:59:59 ff 67 36 7c 5c d4 de 4a e1 8b cc e1 d7 0f da bd 7c 86 61 35 2.4.3 Root certificate of the test environment issuer certificate 18 da d1 9e 26 7d e8 bb 4a 21 58 cd cc 6b 3b 4a RSA CN = VeriSign Class 3 Public Primary Certification Authority - Valid from 8.11.2006 2:00:00 Valid to 17.7.2036 1:59:59 CN = VeriSign Class 3 Public Primary Certification Authority - 4e b6 d5 78 49 9b 1c cf 5f 58 1e ad 56 be 3d 9b 67 44 a5 e5 9 (18)
Page 10 Version: 3.5, 4.11.2015 3.PRODUCTION ENVIRONMENT 3.1 Vetuma production environment The url for the Vetuma production environment is: https://tunnistus.suomi.fi A certificate signed by the VeriSign issuer is used in the production service. This certificate is pre-installed in most browsers as a trusted issuer. 3.1.1 Server certificate 0e c4 de b5 f1 2a 95 58 fa e4 28 f0 1f a3 03 a7 Valid from 5.6.2015 3:00:00 Valid to 9.4.2016 2:59:59 CN = tunnistus.suomi.fi OU = Valtori S = Helsinki 25 7a 95 3c 56 e6 9f 2e 3f 8f 9d 8a 54 c8 34 c6 50 f8 54 b7 3.1.2 of server certificate 51 3f b9 74 38 70 b7 34 40 41 8d 30 93 06 99 ff CN = VeriSign Class 3 Public Primary Certification Authority - Valid from 31.10.2013 3:00:0 Valid to 31.10.2023 2:59:59 10 (18)
Page 11 Version: 3.5, 4.11.2015 ff 67 36 7c 5c d4 de 4a e1 8b cc e1 d7 0f da bd 7c 86 61 35 3.1.3 Root certificate of the issuer certificate 18 da d1 9e 26 7d e8 bb 4a 21 58 cd cc 6b 3b 4a RSA CN = VeriSign Class 3 Public Primary Certification Authority - Valid from 8.11.2006 2:00:00 Valid to 17.7.2036 2:59:59 CN = VeriSign Class 3 Public Primary Certification Authority - 4e b6 d5 78 49 9b 1c cf 5f 58 1e ad 56 be 3d 9b 67 44 a5 e5 3.2 Signature certificate for SAML messages in the production environment The signature certificate for the SAML messages of Vetuma production environment reside in the IdP metadata of Vetuma. 11 (18)
Page 12 Version: 3.5, 4.11.2015 The url for the production service IdP metadata: https://tunnistus.suomi.fi/info/tunnistus.suomi.fi-idp-metadata.xml 3.2.1 Signature certificate of the production environment 0b ed b5 f4 RSA CN = VRK CA for Service Providers OU = Palveluvarmenteet O = Vaestorekisterikeskus CA S = Finland Valid from 30. tammikuuta 2014 10:00:00 Valid to 31. tammikuuta 2016 0:59:00 CN = Valtiokonttori SERIALNUMBER = 0245440-1 OU = VETUMA SAML IDP O = Valtiokonttori 6d ad 83 e3 2f 35 84 8e 1a 9a 8f 2c 67 8a 80 2f b3 ec 7 e 10 3.2.2 of production environment signature certificate 01 88 9b RSA CN = VRK Gov. Root CA OU = Varmennepalvelut OU = Certification Authority Services O = Vaestorekisterikeskus CA S = Finland Valid from 28.1.2003 11:24:46 Valid to 27.1.2019 11:24:02 CN = VRK CA for Service Providers OU = Palveluvarmenteet O = Vaestorekisterikeskus CA S = Finland 12 (18)
Page 13 Version: 3.5, 4.11.2015 57 93 f4 65 15 73 01 0b c1 86 22 07 fc 90 83 17 4a 9c 8e 38 3.2.3 Root certificate of the production environment signature certificate 01 86 a0 RSA CN = VRK Gov. Root CA OU = Varmennepalvelut OU = Certification Authority Services O = Vaestorekisterikeskus CA S = Finland Valid from 18.12.2002 16:53:00 Valid to 18.12.2023 16:51:08 CN = VRK Gov. Root CA OU = Varmennepalvelut OU = Certification Authority Services O = Vaestorekisterikeskus CA S = Finland fa a7 d9 fb 31 b7 46 f2 00 a8 5e 65 79 76 13 d8 16 e0 63 b5 3.3 Shared domain production environment for federation The url for the shared domain production environment for federation is: https://vetuma. federointi.suomi.fi A certificate signed by the Symantec issuer is in use. This certificate is pre-installed in most browsers as a trusted issuer. 3.3.1Server certificate Valid from 8.6.2015 3:00:00 Valid to 9.4.2016 2:59:59 2d c5 a4 f5 d2 b1 64 05 b8 9f d9 4c 4b 88 51 63 13 (18)
Page 14 Version: 3.5, 4.11.2015 CN = vetuma.federointi.suomi.fi OU = Valtori 8c b2 6b 2f 09 88 3b 03 6c 36 e3 3f 29 0e 56 44 f4 c2 cd 6d 3.3.2 of server certificate Valid from 31.10.2013 3:00:00 51 3f b9 74 38 70 b7 34 40 41 8d 30 93 06 99 ff CN = VeriSign Class 3 Public Primary Certification Authority - Valid to 31.10.2013 2:59:59 ff 67 36 7c 5c d4 de 4a e1 8b cc e1 d7 0f da bd 7c 86 61 35 3.3.3 Production environment signature certificate 0b ed b5 f4 RSA CN = VRK CA for Service Providers OU = Palveluvarmenteet O = Vaestorekisterikeskus CA S = Finland Valid from 30.1.2014 10:00:00 Valid to 31.1.2016 0:59:00 CN = Valtiokonttori SERIALNUMBER = 0245440-1 14 (18)
Page 15 Version: 3.5, 4.11.2015 OU = VETUMA SAML IDP O = Valtiokonttori 6d ad 83 e3 2f 35 84 8e 1a 9a 8f 2c 67 8a 80 2f b3 ec 7e 10 3.4 Shared domain production environment for identity provider discovery The url for the shared domain in the Leijuke production environment is: https://leijuke.testifederointi.suomi.fi A certificate signed by the Symantec issuer is in use. This certificate is pre-installed in most browsers as a trusted issuer. 3.4.1 Server certificate svalid from 9.4.2014 3:00:00 2a 1d 2f 36 c5 bf dd 50 35 2f cf 0a 41 ef 13 2e Valid to 10.4.2016 2:59:59 CN = leijuke.federointi.suomi.fi OU = Valtori 48 e1 4d 52 ad 3b cb 1e e2 2e 51 ea 1b 2b 5e 86 db 8f 85 a2 3.4.2 of server certificate 51 3f b9 74 38 70 b7 34 40 41 8d 30 93 06 99 ff CN = VeriSign Class 3 Public Primary Certification Authority - 15 (18)
Page 16 Version: 3.5, 4.11.2015 Valid from 31.10.2013 3:00:00 Valid to 31.10.2023 2:59:59 ff 67 36 7c 5c d4 de 4a e1 8b cc e1 d7 0f da bd 7c 86 61 35 3.4.3 Root certificate of the issuer certificate 18 da d1 9e 26 7d e8 bb 4a 21 58 cd cc 6b 3b 4a RSA CN = VeriSign Class 3 Public Primary Certification Authority - Valid from 8.11.2006 2:00:00 Valid to 17.7.2036 1:59:59 CN = VeriSign Class 3 Public Primary Certification Authority - 4e b6 d5 78 49 9b 1c cf 5f 58 1e ad 56 be 3d 9b 67 44 a5 e5 4. USER ID MANAGEMENT IN TEST AND PRODUCTION ENVIRONMENTS The server certificate for the user ID management of the Vetuma service is a certificate signed by the Verisign issuer. 16 (18)
Page 17 Version: 3.5, 4.11.2015 Address of the user ID management in the production service: https://vetuma.topsel.fi Address of the user ID management in the test service: 4.1 Server certificate https://vetumatest.topsel.fi 12 89 48 bd f3 43 25 ab ad 26 72 e1 bb b5 74 f7 RSA Valid from 8.4.2014 3:00:00 Valid to 9.4.2017 2:59:59 CN = *.topsel.fi OU = Fujitsu Topseli CN = VeriSign Class 3 Secure Server CA - G3 OU = Terms of use at https://www.verisign.com/rpa (c)10 e4 c6 61 d4 bd 14 9c 87 d5 59 7c 0f dd 74 31 b8 28 f0 be b3 4.2 of server certificate Valid from 8.2.2010 3:00:00 0d 44 5c 16 53 44 c1 82 7e 1d 20 ab 25 f4 01 63 d8 be 79 a5 RSA CN = VeriSign Class 3 Public Primary Certification Authority - Valid to 8.2. 2020 2:59:59 CN = VeriSign Class 3 Public Primary Certification Authority - 17 (18)
Page 18 Version: 3.5, 4.11.2015 5d eb 8f 33 9e 26 4c 19 f6 68 6f 5f 8f 32 b5 4a 4c 46 b4 76 4.3 Root certificate of the issuer certificate Valid from 8.11.2006 3:00:00 18 da d1 9e 26 7d e8 bb 4a 21 58 cd cc 6b 3b 4a RSA CN = VeriSign Class 3 Public Primary Certification Authority - Valid to 17.7.2036 2:59:59 CN = VeriSign Class 3 Secure Server CA - G3 OU = Terms of use at https://www.verisign.com/rpa (c)10 4e b6 d5 78 49 9b 1c cf 5f 58 1e ad 56 be 3d 9b 67 44 a5 e5 18 (18)