CESKÁ REPUBLIKA (CZECH REPUBLIC) : Trusted List



Similar documents
UNITED KINGDOM (UNITED KINGDOM) : Trusted List

БЪЛГАРИЯ (BULGARIA) : Trusted List

SUOMI/FINLAND (FINLAND) : Trusted List

UNITED KINGDOM (UNITED KINGDOM) : Trusted List

PORTUGAL (PORTUGAL) : Trusted List

NORGE (NORWAY) : Trusted List

ÍSLAND (ICELAND) : Trusted List

POLSKA (POLAND) : Trusted List

FRANCE (FRANCE) : Trusted List

LIECHTENSTEIN (LIECHTENSTEIN) : Trusted List

Luxembourg (Luxembourg): Trusted List

Certificate Path Validation

Sverige (Sweden): Trusted List

Forum of European Supervisory Authorities for Electronic Signatures (FESA) Working Paper on Qualified Certificates for Automatically Signing Systems

LAUREA MAGISTRALE - CURRICULUM IN INTERNATIONAL MANAGEMENT, LEGISLATION AND SOCIETY. 1st TERM (14 SEPT - 27 NOV)

There e really is No Place Like Rome to experience great Opera! Tel: to discuss your break to the Eternal City!

fulfils all requirements defined in the technical specification The appendix to the certificate is part of the certificate and consists of 6 pages.

Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile

Analysis One Code Desc. Transaction Amount. Fiscal Period

Programme of Requirements part 3f: Certificate Policy - Extended Validation

Certipost Trust Services. Certificate Policy. for Lightweight Certificates for EUROCONTROL. Version 1.2. Effective date 03 May 2012

CERTIFICATION PRACTICE STATEMENT UPDATE

GlobalSign CA Certificate Policy

AT&T Global Network Client for Windows Product Support Matrix January 29, 2015

DECREE 132 of the National Security Authority. dated from 26 March 2009

Implementation of eidas through Member States Supervisory Bodies

X.509 Certificate Generator User Manual

2016 Examina on dates

ETSI SECURITY WEEK EIDAS Overview CEN/ETSI esignature Standardization including standards for TSP Compliance. ETSI All rights reserved

Secure Signature Creation Device Protect & Sign Personal Signature, version 4.1

DEPARTMENT OF DEFENSE PUBLIC KEY INFRASTRUCTURE EXTERNAL CERTIFICATION AUTHORITY MASTER TEST PLAN VERSION 1.0

Statoil Policy Disclosure Statement

2015 Examination dates

SWITCHaai Metadata CA. Certificate Policy and Certification Practice Statement

COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*

COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*

EMA esignature capabilities: frequently asked questions relating to practical and technical aspects of the implementation

on reporting by payment institutions, small-scale payment service providers and electronic money institutions to the Czech National Bank

Ericsson Group Certificate Value Statement

Programme of Requirements part 3h: Certificate Policy Server certificates Private Services Domain (G3)

LuxTrust Global Root CA - Certificate specifications

Future directions of the AusCERT Certificate Service

Protection Profiles for TSP cryptographic modules Part 1: Overview

Specifying the content and formal specifications of document formats for QES

UPCOMING PROGRAMMES/COURSES APRIL, 2013 MARCH, 2014 (MIND KINGSTON & MANDEVILLE CAMPUSES) Hr s

Certificate Policy for. SSL Client & S/MIME Certificates

ETSI TS V1.1.1 ( )

QUOVADIS ROOT CERTIFICATION AUTHORITY CERTIFICATE POLICY/ CERTIFICATION PRACTICE STATEMENT. OIDs:

INDEPENDENT AUDIT REPORT BASED ON THE REQUIREMENTS OF ETSI TS Aristotle University of Thessaloniki PKI ( WHOM IT MAY CONCERN

NIST-Workshop 10 & 11 April 2013

Guidelines for the use of electronic signature

ELECTRONIC SIGNATURES AND ASSOCIATED LEGISLATION

Certum QCA PKI Disclosure Statement

UNIVERSITY OF DAYTON DAYTON OHIO ACADEMIC CALENDAR

SPECIFIC CERTIFICATION POLICIES AND PRACTICES APPLICABLE TO

Best prac*ces in Cer*fying and Signing PDFs

Citizen CA Certification Practice statement

ELECTRONIC SIGNATURES AND ACTS IN ELECTRONIC TOOLS USED IN PUBLIC PROCUREMENT MICHAELA POREMSKÁ *

TTP.NL Guidance ETSI TS

Regulation on electronic identification and trust services for electronic transactions in the internal market

Case 2:08-cv ABC-E Document 1-4 Filed 04/15/2008 Page 1 of 138. Exhibit 8

Security framework. Guidelines for trust services providers Part 1. Version 1.0 December 2013

Certification Service Provider of the Ministry of Employment and Social Security. Profile for Public Employee certificates

UPCOMING PROGRAMMES/COURSES APRIL, 2014 MARCH, 2015 (MIND KINGSTON & MANDEVILLE CAMPUSES)

Certificate Policy for OCES Employee Certificates (Public Certificates for Electronic Services) Version 5

SSLPost Electronic Document Signing

Training Assessments Assessments NAEP Assessments (selected sample)

How To Validate a Digitally Signed PDF document. [7 th September 2006] SECURITY TRUST COMPLIANCE REGIONALITY

SDHNS 3 Hour English Food Handlers Class

UKAS Guidance for bodies operating certification of Trust Service Providers seeking approval under tscheme

OFFICE OF THE CONTROLLER OF CERTIFICATION AUTHORITIES TECHNICAL REQUIREMENTS FOR AUDIT OF CERTIFICATION AUTHORITIES

STUDENT ASSESSMENT TESTING CALENDAR

Certificate Policy for OCES personal certificates (Public Certificates for Electronic Services)

How To Protect Your Computer From Being Hacked In European Security Policy

PostSignum CA Certification Policy applicable to qualified personal certificates

Electronic Signature. István Zsolt BERTA Public Key Cryptographic Primi4ves

Electronic Documents Law

DigiCert. Certificate Policy. DigiCert, Inc. Version 4.03 May 3, 2011

TTP.NL Scheme. for management system certification. of Trust Service Providers issuing. Qualified Certificates for Electronic Signatures,

PEXA Public Key Infrastructure (PKI) Certification Authority Certificate Policy

RECOMMENDATIONS for the PROCESSING of EXTENDED VALIDATION SSL CERTIFICATES January 2, 2014 Version 2.0

Enhanced Vessel Traffic Management System Booking Slots Available and Vessels Booked per Day From 12-JAN-2016 To 30-JUN-2017

E-TUGRA INFORMATIC TECHNOLOGIES AND SERVICES CORP (E-TUGRA)

Milk Market Situation. Brussels, 27 August 2015

Guidelines and instructions on security for electronic data interchange (EDI) English translation based on Swedish version 2.

COUNCIL OF THE EUROPEAN UNION. Brussels, 23 June 2010 (OR. en) 10858/10 Interinstitutional File: 2009/0009 (CNS) FISC 60

ETSI TR V1.1.1 ( )

APNIC Trial of Certification of IP Addresses and ASes

Interoperability Guidelines for Digital Signature Certificates issued under Information Technology Act

ETSI TC ESI PRESENTATION TO CAB FORUM. ETSI All rights reserved

National Authority for Electronic Certification. Electronic Signature in Albania by Eris Asllani- Head of Department

Submitted to the EC on 03/06/2012. COMPETITIVENESS AND INNOVATION FRAMEWORK PROGRAMME ICT Policy Support Programme (ICT PSP) e-codex

Certification Service Provider of the Ministry of Employment and Social Security. Profile for Electronic Office certificate

ETSI TS V1.1.1 ( ) Technical Specification

Sept Sep 2014 To book call or visit bpp.com/aat. Online Classroom Live (OCR Live)

How To Become A Jamaican Teacher

Deploying Certificates with Cisco pxgrid. Using Self-Signed Certificates with ISE pxgrid node and pxgrid Client

DIRECTOR GENERAL OF THE LITHUANIAN ARCHIVES DEPARTMENT UNDER THE GOVERNMENT OF THE REPUBLIC OF LITHUANIA

ING Bank N.V., Prague branch. Payments in ING Online electronic banking. User guide

Certification Service Provider of the Ministry of Employment and Social Securityp. Profile for Electronic seal certificate

Transcription:

ETSI 2014 - TSL HR - PDF/A-1b generator Ing. Rado mír Šimek Digitálně podepsal Ing. Radomír Šimek DN: c=, cn=ing. Radomír Šimek, o=ministry of the Interior of the Czech Republic, serialnumber=ica 1044821 Datum: 2015.10.02 11:20:6 +02'00' CESKÁ REPUBLIKA (ECH REPUBLIC) : Trusted List Tsl Id: TSL_ Valid until nextupdate value: 2016-01-1T09:00:00Z TSL signed on: 2015-10-02T09:04:16.968Z PDF generated on: Fri Oct 02 11:12:48 CEST 2015 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 1

TSL Scheme Information TSL Id TSLTag TSL_ http://uri.etsi.org/19612/tsltag TSL Version Identifier 4 TSL Sequence Number 6 TSL Type http://uri.etsi.org/trstsvc/trustedlist/tsltype/eugeneric Scheme Operator Name Ministry of the Interior of the Czech Republic Ministerstvo vnitra České republiky PostalAddress Street Address [ en ] Nad Stolou Locality [ en ] Prague 7 Postal Code [ en ] 1704 Country PostalAddress Street Address [ cs ] Nad Štolou Locality [ cs ] Praha 7 Postal Code [ cs ] 1704 Country ElectronicAddress URI mailto:radomir.simek@mvcr.cz URI http://tsl.gov.cz/index.html Scheme Name :Supervision/Accreditation Status List of certification services from Certification Service Providers, which are supervised/accredited by the referenced Scheme Operator's Member State for compliance with the relevant provisions laid down in Directive 1999/9/EC of the European Parliament and of the Council of 1 December 1999 on a Community framework for electronic signatures. CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 2

:Seznam stavu dohledu/akreditace certifikačních služeb poskytovatelů certifikačních služeb, nad nimiž je vykonáván dohled nebo kteří jsou akreditováni Ministerstvem vnitra v souladu s příslušnými ustanoveními směrnice Evropského parlamentu a Rady 1999/9/ES ze dne 1.12.1999 o zásadách Společenství pro elektronické podpisy. Scheme Information URI URI [ en ] http://tsl.gov.cz/doc/scheme-information_en.pdf Status Determination Approach http://uri.etsi.org/trstsvc/trustedlist/tsltype/statusdetn/euappropriate Scheme Type Community Rules URI [ en ] http://uri.etsi.org/trstsvc/trustedlist/schemerules/eucommon URI [ en ] http://uri.etsi.org/trstsvc/trustedlist/schemerules/ Scheme Territory Policy Or Legal Notice TSL Legal Notice [ en ] The applicable legal framework for the present TSL implementation of the Trusted List of supervised/accredited Certification Service Providers for Czech Republic is Directive 1999/9/EC of the European Parliament and of the Council of 1 December 1999 on a Community framework for electronic signatures and its implementation in Czech Republic laws. TSL Legal Notice [ cs ] Platným právním rámcem pro tuto implementaci seznamu důvěryhodných poskytovatelů certifikačních služeb, nad nimiž je vykonáván dohled nebo kteří jsou akreditováni, v podobě TSL pro Českou republiku je směrnice Evropského parlamentu a Rady 1999/9/ES ze dne 1. prosince 1999 o zásadách Společenství pro elektronické podpisy a její transpozice do právního řádu České republiky. Historical Information Period 6555 Pointer to other TSL - EUROPEAN UNION 1.EU TSL - MimeType: application/pdf TSL Location https://ec.europa.eu/information_society/policy/esignature/trusted-list/tl-hr.pdf EU TSL digital identities TSL Scheme Operator certificate fields details 1492226578499572866188822785298979252 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page

MIIFKzCCBBOgAwIBAgISESFCgSJf+NfOVIYHRWWewAm0MA0GCSqGSIbDQEBCwUAMGYxCzAJBgNV BAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTwwOgYDVQQDEzNHbG9iYWxTaWduIE9y Z2FuaXphdGlvbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0gRzIwHhcNMTUwMzAzMDg1MTAyWhcN MTgwNDIwMTAwNTA1WjBnMQswCQYDVQQGEwJCRTEQMA4GA1UECBMHQmVsZ2l1bTERMA8GA1UEBxMI QnJ1cNlbHMxHDAaBgNVBAoTE0V1cm9wZWFuIENvbW1pcNpb24xFTATBgNVBAMTDGVjLmV1cm9w YS5ldTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMFBF1FjO2VA4nIvTMtXToyfWMN FYRvJc2SIJFpcZNZcUK9wwNLj/lOB5+eABCTDShJf8fQgmyEcAU7gXhFw9DFgfnXsmmA1a79zz bs5kwzkmawee4lfsycbjocuuavd79oar4vyv7gzmvab8nxuqwvecwzqwt6sl+rx0ogh1bbeko9w Q5lbEgRw1MLlyFH2kUieMhjCwO2nQJ9UMTaLu7px4LpZ7tlaVetY7UpMPiGAD4kct1YIoJWJllY bbz7jmalmradlvvu5y6ice4h4j0kdj/lzliveciorqrx8ngiis1lfnsckvz2sbzjvjvxbqxyaey tzqvwxexdpmcaweaaaocadawgghmma4ga1uddweb/wqeawifodbjbgnvhsaeqjbamd4gbmebdaec AjA0MDIGCCsGAQUFBwIBFiZodHRwczovLddy5nbG9iYWxzaWduLmNvbS9yZXBvc2l0bJ5LzAX BgNVHREEEDAOggxlYy5ldXJvcGEuZXUwCQYDVR0TBAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYI KwYBBQUHAwIwSQYDVR0fBEIwQDA+oDygOoY4aHR0cDovL2NybC5nbG9iYWxzaWduLmNvbS9ncy9n c29yz2fuaxphdglvbnzhbhnoytjnmi5jcmwwgaagccsgaqufbwebbigtmigqme0gccsgaqufbzac hkfodhrwoi8vc2vjdxjllmdsb2jhbhnpz24uy29tl2nhy2vydc9nc29yz2fuaxphdglvbnzhbhno YTJnMnIxLmNydDA/BggrBgEFBQcwAYYzaHR0cDovL29jcAyLmdsb2JhbHNpZ24uY29tL2dzbJn YW5pemF0aW9udmFsc2hhMmcyMB0GA1UdDgQWBBQ9lw0pOEotT5cKTF8vxuW6ZCUhzAfBgNVHSME GDAWgBSWmHxvRwWKVMcwMx9O4MAQOYafDANBgkqhkiG9w0BAQsFAAOCAQEArSonov8KbE8+5Vwe wgbhhilhanliirmlvj1siarxvxl6abmmo8cjw2+vtzaqdndkzuy6cnats0y0qkbecs7fvtvp8qqa iv71+jij6idt9r9ij1sundeqwz6mng98ecmvsduzlyieezxh049tahranscvrtu7kpt06cgbcjn ondg7yvxx2bs9civbexrqkmppvhwup2hw/iphhmifprmxpqfa5fkrqnwjw1brblgloqc1mkj7j uvx108khlwa5cgiohctnoh9dfyuqpwqecbrobwdghl4o0ra+bu/z4j85ypob/+f7roqxrfcpv4z Pdg65pNoPppjFDE4TD2bhg== SHA256withRSA GlobalSign Organization Validation CA - SHA256 - G2 GlobalSign nv-sa BE ec.europa.eu European Commission Subject L: Brussels Subject ST: Belgium BE Tue Mar 0 09:51:02 CET 2015 Fri Apr 20 12:05:05 CEST 2018 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:C1:41:17:51:6:B:65:40:E2:72:2F:4F:7:2D:5D:A:2:7D:6:0D:15:84:6F:25:CD:92:20:91:77:A5:C6:4D:65:C5:0A: F7:0C:0D:2F:78:FF:94:E0:79:F9:E0:01:09:0:D2:84:97:FC:7D:08:26:C8:47:00:5:B8:17:84:5C:D:0C:58:1F:9D:7B:26:98:0D:5A:EF:DC:F:6E:CE:4A:5B:9:26:0:01:04:E2:57:D2:61:C6:C9:A0:2B:94:6A:F0:FB:F6:86:91: E2:FD:F2:BF:B1:99:1:56:9B:F2:75:EE:A9:6B:DE:7:0C:D0:59:E:AC:97:EA:F1:D2:88:21:D5:B6:DE:28:EF:70:4:99:5B:12:04:70:D4:C2:E5:C8:51:F6:91:48:9E:2:18:C2:C0:ED:A7:40:9F:54:1:6:8B:BB:BA:71:E0:BA: 59:EE:D9:5A:55:EB:58:ED:4A:4C:E:21:80:0F:7E:24:72:DD:58:22:82:56:26:59:58:6D:BC:FB:8E:60:0B:99:10:1D:2E:FB:EE:E7:2E:88:71:EE:07:E2:D:24:0C:9F:E5:DF:2:E2:55:E0:A2:9:1A:AB:C7:C9:E0:8A:24:B5:2D: F:52:72:4B:F:DA:C6:F:8D:52:6F:5D:BA:B1:60:01:2:B5:94:2F:C:11:17:74:F:02:0:01:00:01 Policy OID: 2.2.140.1.2.2 CPS pointer: https://www.globalsign.com/repository/ Subject Alternative Name ec.europa.eu Basic Constraints IsCA: false Extended Key Usage id_kp_serverauth CRL Distribution Points http://crl.globalsign.com/gs/gsorganizationvalsha2g2.crl Authority Info Access http://secure.globalsign.com/cacert/gsorganizationvalsha2g2r1.crt http://ocsp2.globalsign.com/gsorganizationvalsha2g2 D:97:0D:29:8:4A:2D:4F:97:0A:4C:5F:2F:C6:ED:D6:E9:90:94:87 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 4

Authority Key Identifier 96:DE:61:F1:BD:1C:16:29:5:1C:C0:CC:7D:B:8:00:40:E6:1A:7C digitalsignature - keyencipherment E2:B6:C:00:9A:FA:80:BC:AB:2E:B5:FE:C5:A2:C4:AE:06:06:AC:A2:05:BA:4E:D6:2F:2F:B7:6C :C1:1E:08:DA X509SubjectName ec.europa.eu European Commission Subject L: Brussels Subject ST: Belgium BE Mime Type application/pdf TSL Type http://uri.etsi.org/trstsvc/trustedlist/tsltype/eulistofthelists Scheme Territory EU Scheme Operator Name European Commission Scheme Type Community Rules URI [ en ] http://uri.etsi.org/trstsvc/trustedlist/schemerules/eulistofthelists 2.EU TSL - MimeType: application/vnd.etsi.tsl+xml TSL Location https://ec.europa.eu/information_society/policy/esignature/trusted-list/tl-mp.xml EU TSL digital identities TSL Scheme Operator certificate fields details 114 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 5

MIIHPDCCBSSgAwIBAgIBcjANBgkqhkiG9w0BAQsFADAxMQswCQYDVQQGEwJFUzERMA8GA1UECgwI Rk5NVC1SQ00xDzANBgNVBAMMBklTQSBDQTAeFw0xMTExMTYxNTExMDdaFw0xNTExMTYxNTExMDda ME0xCzAJBgNVBAYTAkJFMRwwGgYDVQQKDBNFVVJPUEVBTiBDT01NSVNTSU9OMSAwHgYDVQQDDBco U0lHTikgQU5ORUxJIEFORFJFU1NPTjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMw8 81fbxBn5Eq64Hf6pqEqn0Intg49k5D+E2JBMcyeOMYE4WwuzVqs7fuKMX5mhiFw7llVx42S7GIDn Ka6ascF7irISsYTGOtD6dGt8OEOQkG5i24wxTwe6VW1W/PEO0WoRjkPDBqgljnqcLn+WJLrYl 9fpkxyT+Hpl0jnGkGi7UUKEDuoCglFy9Tb1TE+eVNiGWmfskRy6q9Pioujp2FqrwNm95VAkLFGo NF4iZQda79bgjvAYnA5p4QXgr/5sWZjgsaEa9PlRwEvO7C8ndnRE/PTUNwaSmOZsmPH/ksCCnfT DqqehHVnryK6QIUKhRsoT1m60qv4UKrvrsCAwEAAaOCA0EwggM9MF0GA1UdEQRWMFSBHUFOTkVM SS5BTkRSRVNTT05ARUMuRVVST1BBLkVVpDMwMTEYMBYGCSsGAQQBrGYBAgwJQU5EUkVTU09OMRUw EwYJKwYBBAGsZgEBDAZBTk5FTEkwCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCBkAwHQYDVR0OBBYE FEoUEf+0Oe59fVRs/rW2M0KhmlDsMB8GA1UdIwQYMBaAFEft+GPwma9e/n4OXFjL/uI1N6a9MIHg BgNVHSAEgdgwgdUwgcgGCisGAQQBrGYDBAEwgbkwKQYIKwYBBQUHAgEWHWh0dHA6Ly9dcuY2Vy dc5mbm10lmvzl2rwymvmiglbggrbgefbqccajb/dh1rdwfsawzpzwqgy2vydglmawnhdguuifvu ZGVyIHRoZSB1c2FnZSBjb25kaXRpb25zIGFzc2VydGVkIGluIHRoZSBGTk1ULVJDTSBDUFMgKDEw NiwgSm9yZ2UgSnVhbiBzdHJlZXQsMjgwMDksIE1hZHJpZCwgUBhaW4pLjAIBgYEAIswAQEwgYYG CCsGAQUFBwEBBHoweDBBBggrBgEFBQcwAYY1aHR0cDovL29jcBJU0FjYS5jZXJ0LmZubXQuZXMv b2nzceltqwnhl09jcbszxnwb25kzxiwmwyikwybbquhmakgj2h0dha6ly9dcuy2vydc5mbm10 LmVzL2NlcnRzL0lTQUNBLmNydDBGBggrBgEFBQcBAwQ6MDgwCAYGBACORgEBMAsGBgQAjkYBAwIB DzAVBgYEAI5GAQIwCxMDRVVSAgECAgECMAgGBgQAjkYBBDCBzAYDVR0fBIHEMIHBMIG+oIG7oIG4 hogibgrhcdovl2xkyxbju0fjys5jzxj0lmzubxquzxmvq049q1jmmixjbj1ju0elmjbdqsxvpuzo TVQtUkNNLEM9RVM/Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdDtiaW5hcnk/YmFzZT9vYmplYRj bgfzcz1jukxeaxn0cmlidxrpb25qb2ludiyrahr0cdovlddy5jzxj0lmzubxquzxmvyjsc19j U0FjYS9DUkwyLmNybDANBgkqhkiG9w0BAQsFAAOCAgEALIKumRPBo9NIYyzm4LSJklE9CmsirJC8 9MPcFiC9+vg4YrO9Mmakr8G5ZAVZf+Zr6HgLcIf9/BSgE4UDFD9mAROPDElqx2ppg1+foIvlqg5 7EiHH2kOS4IYJEJpWCs4IqcBkSKcS5vJ5XVpNJL4elpeMQjsGoqjmkKDr1IeZQVOxOiW/bNhM9Fw 6R1aMMLbnziwAgHWDpmIj2Se74HuSca0ctm9fAPp/2Y87bgZ1ETs9A6wc4GxYEuGTwh1HPbDB6t gjsnjh0hyqbitjb8im0xgvur9dqkt8ez4dvyxcaflycmflaemf8jljov4uu1yrrt9wesij5gcoe 4cy1cuvRMifqYhoiKPojJaLTV7ASy1X0yuBWyg0jGyvE6aTIAuXGCwdGYB1WnSzEUPJboqcyJ ydkxxxnbkfchw602pvb0ituqitgh+kfix2mqqf+v0rdewquwdadnhc+cqoc7sxkjxko657dyzt/ Ey5MR+gXRm6oK52iXIqjM8kbDqCqAOHVC7u+bUvh0y5B5PjGYuE2K9xK6ooavh5ytF/kY+y0Ju 804CRF00b4wKcibGxplOrU1g+ncONNmBHGbsLULXrum8+fsDO04Mf0t0O9Mt/ZwAZTa8Cwq/0pq OWdRqucV7pq/A7fEnRb5AdBaAzxqrXVaa92NkScAm80= SHA256withRSA ISA CA FNMT-RCM ES (SIGN) ANNELI ANDRESSON EUROPEAN COMMISSION BE Wed Nov 16 16:11:07 CET 2011 Mon Nov 16 16:11:07 CET 2015 Subject Alternative Name 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:CC:C:F:57:DB:C4:19:F9:12:AE:B8:1D:FE:A9:A8:4A:A7:D0:89:ED:8:8F:64:E4:F:84:D8:90:4C:7:27:8E:1:81: 8:5B:0B:B:56:AB:B:7E:E2:8C:5F:99:A1:88:5C:B:96:55:71:E:64:BB:18:80:E7:29:AE:9A:B1:C1:7B:8A:B2:12:B1:84:C6:A:D0:FA:74:6B:7C:8:4:90:90:6E:62:DB:8C:1:4F:7C:1E:EB:75:56:D5:6F:CF:10:ED:16:A1: 18:E4:C:0:6A:82:58:E7:A9:C2:E7:F9:62:4B:AF:76:25:F5:FA:64:C7:24:FE:1F:7A:65:D2:9:C6:90:68:BB:51:42:84:0E:EA:02:82:51:72:F5:6:F5:4C:4F:9E:54:D8:86:5A:67:EC:91:1C:BA:AB:D:E2:A2:E8:E9:D8:5A:AB:C 0:D9:BD:E5:50:24:2C:51:A8:4:5E:22:65:07:5A:EF:D6:E0:8E:F0:18:9C:0E:69:E1:05:E0:AF:FE:6C:59:98:E0:B1:AD:C4:6B:D:E5:47:01:2F:B:B0:BC:9D:D9:D1:1:F:D:50:DC:1A:4A:6:99:B2:6:C7:FE:4B:02:0A:77: D:0E:AA:9E:84:75:67:AF:2D:CA:E9:02:14:2A:14:6C:A1:D:66:EB:4A:AF:E1:42:AB:BE:BB:02:0:01:00:01 ANNELI.ANDRESSON@EC.EUROPA.EU Basic Constraints IsCA: false 4A:14:11:FF:B4:9:EE:7D:7D:54:6C:FE:B5:B6::42:A1:9A:50:EC Authority Key Identifier 47:ED:F8:6:F0:99:AF:5E:FE:7E:0E:5C:58:CB:FE:E2:5:7:A6:BD Policy OID: 1..6.1.4.1.574..4.1 CPS pointer: http://www.cert.fnmt.es/dpcs/ CPS text: [Qualified certificate. Under the usage conditions asserted in the FNMT-RCM CPS (106, Jorge Juan street,28009, Madrid, Spain).] Policy OID: 0.4.0.1456.1.1 Authority Info Access http://ocspisaca.cert.fnmt.es/ocspisaca/ocspresponder http://www.cert.fnmt.es/certs/isaca.crt CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 6

QCStatements - crit. = false id_etsi_qcs_qccompliance id_etsi_qcs_retentionperiod: 15 id_etsi_qcs_limitevalue Value: 200 Currency: EUR id_etsi_qcs_qcsscd CRL Distribution Points ldap://ldapisaca.cert.fnmt.es/cn=crl2,cn=isa%20ca,o=fnmt- RCM,C=ES?certificateRevocationList;binary?base?objectclass=cRLDistributionPoint http://www.cert.fnmt.es/crls_isaca/crl2.crl nonrepudiation 5D:9:E8:F1:16:69:50:E9:97:8:2:AD:26:6F:06:74:2C:C4:A9:48:48:69:DF:61:EF:CB:84:9D:B2:F C:60:4A EU TSL digital identities TSL Scheme Operator certificate fields details 87649 MIIFnDCCBISgAwIBAgIDAVZhMA0GCSqGSIbDQEBBQUAMEUxCzAJBgNVBAYTAkxVMRYwFAYDVQQK Ew1MdXhUcnVzdCBTLkEuMR4wHAYDVQQDExVMdXhUcnVzdCBRdWFsaWZpZWQgQ0EwHhcNMDkxMjIz MTAzNTU2WhcNMTIxMjIzMTAzNTU2WjCCAQYxCzAJBgNVBAYTAkJFMQswCQYDVQQHEwJCRTEcMBoG A1UEChMTRXVybBlYW4gQ29tbWlzc2lvbjELMAkGA1UECxMCTkExJDAiBgNVBAMTG0thcmVsIExv ZGVaWprIE0gRGUgVnJpZW5kdDETMBEGA1UEBBMKRGUgVnJpZW5kdDEZMBcGA1UEKhMQS2FyZWwg TG9kZXdpamsgTTEdMBsGA1UEBRMUMTAxMDAzMzIxMTAwMDQNDkzNzgxLDAqBgkqhkiG9w0BCQEW HUthcmVsLkRlLVZyaWVuZHRAZWMuZXVybBhLmV1MRwwGgYDVQQMExNQcm9mZXNzaW9uYWwgUGVy c29umigfma0gcsqgsibdqebaquaa4gnadcbiqkbgqc96jbqnjcmak4lduzdmu5lngk7/uqnjbl DkUqN2Jb/STQSBJnRJchCY9DnKtqYG9cuSZDRxvIUkssqO/WpFu/I5fO9I4mvLGD9h4ot8/GkRnt belcnmlrkzjkadcshwuqnunpfaz4yggipslry9pbrkfxseenejao0ixiuqjwidaqabo4icvdcc AlAwDAYDVR0TAQH/BAIwADBgBggrBgEFBQcBAQRUMFIwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vYNw Lmx1eHRydXN0Lmx1MCsGCCsGAQUFBzAChh9odHRwOi8vY2EubHV4dHJ1cQubHUvTFRRQ0EuYJ0 MIIBHQYDVR0gBIIBFDCCARAwggECBggrgSsBAQIEATCB9TCBxwYIKwYBBQUHAgIwgboagbdMdXhU cnvzdcbrdwfsawzpzwqgq2vydglmawnhdgugb24gq0ntrcbjb21wbglhbnqgd2l0acbfvfnjifrt IDEwMSA0NTYgUUNQKyBjZXJ0aWZpY2F0ZSBwb2xpYkuIEtleSBHZW5lcmF0aW9uIGJ5IENTUC4g U29sZSBBdXRobJpc2VkIFVzYWdlOiBTdXBwbJ0IG9mIFF1YWxpZmllZCBFbGVjdHJvbmljIFNp Z25hdHVyZS4wKQYIKwYBBQUHAgEWHWh0dHA6Ly9yZXBvc2l0bJ5Lmx1eHRydXN0Lmx1MAgGBgQA izabata2bggrbgefbqcbawqqmcgwcaygbacorgebmbigbgqajkybajaiewacaqacaqawcaygbaco RgEEMBEGCWCGSAGG+EIBAQQEAwIFIDALBgNVHQ8EBAMCBkAwHwYDVR0jBBgwFoAUjZCjB90aEeZ TJKrTUPeP80pZAUwMQYDVR0fBCowKDAmoCSgIoYgaHR0cDovL2NybC5sdXh0cnVzdC5sdS9MVFFD QS5jcmwwEQYDVR0OBAoECEwDOyVeIV5MA0GCSqGSIbDQEBBQUAA4IBAQBStS9gFx5BmEv5VciG 7qEPR5VzqEpBElkjXDYe68Dw7Ol1nCt51CSuAB2/UcTkfCDh6022H7+EtiUpdM6GH/7qDqZdjqYp Qznbu4xkrGTMLrTA1lalhgWugGQIpmCg69kiXns/AXcuJVQSRmABMvJrN5PNaALoguynWCrxRH PTUSpT5J9jCn90ZPAGhxELRxMdZuFZ2UAn8D8XLUxiz0IK9yqdysJiLzWsQazUkZ+lzDG0mPom yrkllzek8hxohkgr+2n760n+styyjwywp/ks/lopqwfufjwqe8jditgodzt4ewvsxunrbh5ls 29aBi0YsT9NYstznKgaR SHA1withRSA LuxTrust Qualified CA LuxTrust S.A. LU Subject T: Professional Person Subject E: Karel.De-Vriendt@ec.europa.eu Subject SERIAL NUMBER: 10100211000474978 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 7

Subject GIVEN NAME: Karel Lodewijk M Subject SURNAME: De Vriendt Karel Lodewijk M De Vriendt Subject OU: NA European Commission Subject L: BE BE Wed Dec 2 11:5:56 CET 2009 Sun Dec 2 11:5:56 CET 2012 Basic Constraints 0:81:9F:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:81:8D:00:0:81:89:02:81:81:00:BD:E8:90:6A:9E:0:A6:02:4E:7:2C:B:99:0C:CB:B9:94:D1:8A:EF:F5:10:9C:90:4B:0E:45:2A:7:62:5B:FD:24:D0:48:12:67:44: 97:21:09:8F:4:9C:AB:6A:60:6F:5C:B9:26:4:47:1B:C8:52:4B:2C:A8:EF:D6:A4:5B:BF:2:97:CE:F4:8E:26:BC:B1:8:F6:1E:28:B7:CF:C6:91:19:ED:6C:49:77:0A:7:25:44:A6:49:90:07:5C:48:7C:2E:AA:7B:8D:A5:F6:99:E :21:86:20:FB:25:47:2F:69:6D:19:1F:5D:27:9E:9D:E2:40:A:42:1:8A:ED:D0:27:02:0:01:00:01 IsCA: false Authority Info Access http://ocsp.luxtrust.lu http://ca.luxtrust.lu/ltqca.crt Policy OID: 1..171.1.1.2.4.1 CPS text: [LuxTrust Qualified Certificate on CCSD compliant with ETSI TS 101 456 QCP+ certificate policy. Key Generation by CSP. Sole Authorised Usage: Support of Qualified Electronic Signature.] CPS pointer: http://repository.luxtrust.lu Policy OID: 0.4.0.1456.1.1 QCStatements - crit. = false id_etsi_qcs_qccompliance id_etsi_qcs_limitevalue Value: not readable Currency: not readable id_etsi_qcs_qcsscd Authority Key Identifier 8D:90:A:07:DD:1A:1:77:99:4C:92:AB:4D:4:DE:F:CD:29:64:05 CRL Distribution Points http://crl.luxtrust.lu/ltqca.crl 4C:0:B:25:5E:DC:85:79 nonrepudiation CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 8

D5:49:51:FE:BB:C5:9D:2C:2E:C0:1A:CC:D9:2C:CD:8C:9D:2C:74:44:C2:E5:51:BA:7E:C0:DE:62: 2C:74:14:8C EU TSL digital identities TSL Scheme Operator certificate fields details 9412574269162772257894872518702697 MIIHSDCCBTCgAwIBAgIQHaaUHzn5vENUk+T/aHIefTANBgkqhkiG9w0BAQsFADAxMQswCQYDVQQG EwJFUzERMA8GA1UECgwIRk5NVC1SQ00xDzANBgNVBAMMBklTQSBDQTAeFw0xNDEyMTkwODQyMzla Fw0xODEyMTkwODQyMzlaMEwxCzAJBgNVBAYTAkJFMRwwGgYDVQQKDBNFVVJPUEVBTiBDT01NSVNT SU9OMR8wHQYDVQQDDBYoU0lHTikgQUdOSUVTWktBIEJBSk5PMIIBIjANBgkqhkiG9w0BAQEFAAOC AQ8AMIIBCgKCAQEAog6nQQcoPlHOrwXYDD+wj8lwn1zbalTTJL7yWN7OgO9/eSCIY5nGgfnsla pc6vso9rbsxwcv4cjcf2ngzdszhxnjpf4ig4cesbyui0ugfantbplfj/r5avf0ordgkti2h/6 sn2swgs4grcrfq5yt/zphoigjxjzk4s6ifmbg1ggrqusdjo+uvcbubcnjdfrozmm9typdv19 4f1NwXRbFOon1WtaIsJNKzw4+MKCAyD9BBVATQxGLYeCT2tZtDFbSSXZbBfSnfwGe7eMc99S12H r/mwapjhuwzzpienadvnlmnwxwutxcdo5hrmodtxv8vh9mklawvn4qidaqabo4idpzccazswwwyd VR0RBFQwUoEcQUdOSUVTWktBLkJBSk5PQEVDLkVVUk9QQS5FVaQyMDAxFDASBgkrBgEEAaxmAQIM BUJBSk5PMRgwFgYJKwYBBAGsZgEBDAlBR05JRVNaS0EwCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMC BkAwHQYDVR0OBBYEFIe8EqP5sxbiNrSKwgNC00FsSfkjMB8GA1UdIwQYMBaAFEft+GPwma9e/n4O XFjL/uI1N6a9MIHgBgNVHSAEgdgwgdUwgcgGCisGAQQBrGYDBAEwgbkwKQYIKwYBBQUHAgEWHWh0 dha6ly9dcuy2vydc5mbm10lmvzl2rwymvmiglbggrbgefbqccajb/dh1rdwfsawzpzwqgy2vy dglmawnhdguuifvuzgvyihrozsb1c2fnzsbjb25kaxrpb25zigfzc2vydgvkigluihrozsbgtk1u LVJDTSBDUFMgKDEwNiwgSm9yZ2UgSnVhbiBzdHJlZXQsMjgwMDksIE1hZHJpZCwgUBhaW4pLjAI BgYEAIswAQEwgYYGCCsGAQUFBwEBBHoweDBBBggrBgEFBQcwAYY1aHR0cDovL29jcBJU0FjYS5j ZXJ0LmZubXQuZXMvb2NzcElTQWNhL09jcBSZXNwb25kZXIwMwYIKwYBBQUHMAKGJ2h0dHA6Ly9 dcuy2vydc5mbm10lmvzl2nlcnrzl0ltqunblmnyddbgbggrbgefbqcbawq6mdgwcaygbacorgeb MAsGBgQAjkYBAwIBDzAVBgYEAI5GAQIwCxMDRVVSAgECAgECMAgGBgQAjkYBBDCBzAYDVR0fBIHE MIHBMIG+oIG7oIG4hoGIbGRhcDovL2xkYXBJU0FjYS5jZXJ0LmZubXQuZXMvQ049Q1JMMSxjbj1J U0ElMjBDQSxvPUZOTVQtUkNNLEM9RVM/Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdDtiaW5hcnk/ YmFzZT9vYmplYRjbGFzcz1jUkxEaXN0cmlidXRpb25Qb2ludIYraHR0cDovLddy5jZXJ0LmZu bxquzxmvyjsc19ju0fjys9dukwxlmnybdanbgkqhkig9w0baqsfaaocagead2cyyrljkbr+hxmw njwzne9q6nw29ulwx4c/kwfwgnxyjo/mbe2khgxfum7e441ih87px1p8jpteohtfvl8cxmsqydg5 6GBNq5NprbagpmKHiNCP77baZiLMFfEvc915ktLlYQEH+wIe5i0gMPmRWjA2urB/M+fXwLgqQdOE e4e0nslr7yjqhel1swqss4r1zk8zgv1uj0v+vamyxwftayyht/c9x+qtvxyafldcbvnpbxjxug7 vqhe7g5/rpx4vvzaznv9d5ibk+scx05drfrqsym4qw1sw4j0w2nxafqwkbfw6np5sgohfc9sh2l rcf/wlvepy8pitxfukrzlseb8zwm2vfzqrnggbxczdykfavdel/gnnhog5q4tn2tvv7yfxle gu7zn+iqbodlatbjxeu60fif9cs5igqwwlbeok8qvogfydxlgiprsijea1whyy+gh1mofsa7u 0wEvooCzohFf4DBv06I4q9aCNBnTo4yki1yFhBm71r60hlAas6aK6TZ+NUoFWwPypMP617SlHdy8 QlFx1sV+rIt2hxUUGddid/FXDKtuUCRqKqx6x8J8bI7DecZsCS7ijPCApjJ84HB8UASRzdGtEwc 97hvnAqXjpCS/tHAVcVvmPisNDu4WtV2LQfL/TIY8zMxUebv/E5JyBKAw= SHA256withRSA ISA CA FNMT-RCM ES (SIGN) AGNIESZKA BAJNO EUROPEAN COMMISSION BE Fri Dec 19 09:42:9 CET 2014 Wed Dec 19 09:42:9 CET 2018 Subject Alternative Name 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:A2:0E:A7:41:07:28:E:51:CE:AF:05:D8:0C:F:B0:8F:7F:25:C2:7D:7:6D:A9:5:4C:92:FB:C9:6D:CD:EC:E8:0E:F7: F7:92:08:86:9:9C:68:1F:9E:C9:5A:A4:2D:FA:BD:2:BD:45:B4:B1:5B:77:15:E0:22:42:7F:69:C6:65:DB:19:1F:1:49:A5:FE:08:1B:80:84:B0:1C:AE:8B:7D:14:18:50:0D:B4:1:E5:16:F:EB:E5:AB:DF:D0:EA:C:18:A4:C8: D8:7F:FA:B0:DD:AC:C2:0B:8:DE:0A:DC:44:54:9:CA:DF:D9:E:1:88:82:5:E:CC:AE:2C:DF:A2:05:0:11:B5:18:64:50:51:20:C9:A:EB:AF:DD:C6:EE:05:C:6:74:5A:E8:DD:99:A6:F5:C:A9:0E:FD:7D:E1:FD:4D: C1:74:5B:14:EA:27:D5:6B:5A:22:C2:4D:2B:C:8:F8:C2:82:0:20:FD:04:15:40:4D:0C:46:2D:87:82:4F:6B:59:B7:70:C5:6D:24:97:65:B0:5F:4A:77:F0:19:EE:DE:1:CF:7D:4B:5D:87:AF:F:0:00:F2:61:5:06:59:A6:27:A7: 69:D5:4D:94:C:56:C7:0B:AD:C5:C0:CE:E4:7A:E6:9:DB:71:BF:C5:61:F4:C2:A5:0:0B:CD:E1:02:0:01:00:01 AGNIESZKA.BAJNO@EC.EUROPA.EU Basic Constraints IsCA: false 87:BC:12:A:F9:B:16:E2:6:B4:8A:C2:0:42:D:41:6C:49:F9:2 Authority Key Identifier 47:ED:F8:6:F0:99:AF:5E:FE:7E:0E:5C:58:CB:FE:E2:5:7:A6:BD CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 9

Policy OID: 1..6.1.4.1.574..4.1 CPS pointer: http://www.cert.fnmt.es/dpcs/ CPS text: [Qualified certificate. Under the usage conditions asserted in the FNMT-RCM CPS (106, Jorge Juan street,28009, Madrid, Spain).] Policy OID: 0.4.0.1456.1.1 Authority Info Access http://ocspisaca.cert.fnmt.es/ocspisaca/ocspresponder http://www.cert.fnmt.es/certs/isaca.crt QCStatements - crit. = false id_etsi_qcs_qccompliance id_etsi_qcs_retentionperiod: 15 id_etsi_qcs_limitevalue Value: 200 Currency: EUR id_etsi_qcs_qcsscd CRL Distribution Points ldap://ldapisaca.cert.fnmt.es/cn=crl1,cn=isa%20ca,o=fnmt- RCM,C=ES?certificateRevocationList;binary?base?objectclass=cRLDistributionPoint http://www.cert.fnmt.es/crls_isaca/crl1.crl nonrepudiation 55:F5:07:DE:A:84:C6:F:29:F0:46:9:F7:0:AD:D1:7:CA:DF:A0:9B:76:AB:07:F5:F9:74:84:12: FD:9A:AA X509SubjectName (SIGN) AGNIESZKA BAJNO EUROPEAN COMMISSION BE EU TSL digital identities TSL Scheme Operator certificate fields details 6088551117099654742827802050024098572 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 10

MIIHYDCCBUigAwIBAgIQLc4fd1CtIihUFtlELwMLDDANBgkqhkiG9w0BAQsFADAxMQswCQYDVQQG EwJFUzERMA8GA1UECgwIRk5NVC1SQ00xDzANBgNVBAMMBklTQSBDQTAeFw0xNDA5MTUxMjE5MTVa Fw0xODA5MTUxMjE5MTVaMFQxCzAJBgNVBAYTAkJFMRwwGgYDVQQKDBNFVVJPUEVBTiBDT01NSVNT SU9OMScwJQYDVQQDDB4oU0lHTikgSk9MQU5EQSBWQU4gRUlKTkRUSE9WRU4wggEiMA0GCSqGSIb DQEBAQUAA4IBDwAwggEKAoIBAQC0sin8VvNtcuOnUuGDWtXjZlTx5SoZzJiDG4/6bOtgeyPIvqH zci8hslijb1yqjnimglti6blhelr/skf8regueyn/ijgio2/89b82rsfm1r+ehsjklmvuu+kj7uu nhrcdlahgnohmpwidedixy4jw0rbdjtyewv7cndedoc4le9iuj71zlsphmedtlfldwif0ay/r5b x1vaiapmzxjdicarsqlhnmnpkyshw+poahzn8tj9vowjhtdsw/ftbnbqaszuk0l2iwd0pxrszso +yw86dx0kan1qsmwxdwz0pax+n9ml2ggug8stirpvlmzdggn6g52msz2grniaulagmbaagjggnp MIIDSzBrBgNVHREEZDBigSRKT0xBTkRBLlZBTi1FSUpORFRIT1ZFTkBFQy5FVVJPUEEuRVWkOjA4 MR4wHAYJKwYBBAGsZgECDA9WQU4gRUlKTkRUSE9WRU4xFjAUBgkrBgEEAaxmAQEMB0pPTEFOREEw CQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCBkAwHQYDVR0OBBYEFIz+jZkpky2xCorjhNpu1m1pDZ76 MB8GA1UdIwQYMBaAFEft+GPwma9e/n4OXFjL/uI1N6a9MIHgBgNVHSAEgdgwgdUwgcgGCisGAQQB rgydbaewgbkwkqyikwybbquhagewhwh0dha6ly9dcuy2vydc5mbm10lmvzl2rwymvmiglbggr BgEFBQcCAjB/DH1RdWFsaWZpZWQgY2VydGlmaWNhdGUuIFVuZGVyIHRoZSB1c2FnZSBjb25kaXRp b25zigfzc2vydgvkigluihrozsbgtk1ulvjdtsbdufmgkdewniwgsm9yz2ugsnvhbibzdhjlzxqs MjgwMDksIE1hZHJpZCwgUBhaW4pLjAIBgYEAIswAQEwgYYGCCsGAQUFBwEBBHoweDBBBggrBgEF BQcwAYY1aHR0cDovL29jcBJU0FjYS5jZXJ0LmZubXQuZXMvb2NzcElTQWNhL09jcBSZXNwb25k ZXIwMwYIKwYBBQUHMAKGJ2h0dHA6Ly9dcuY2VydC5mbm10LmVzL2NlcnRzL0lTQUNBLmNydDBG BggrBgEFBQcBAwQ6MDgwCAYGBACORgEBMAsGBgQAjkYBAwIBDzAVBgYEAI5GAQIwCxMDRVVSAgEC AgECMAgGBgQAjkYBBDCBzAYDVR0fBIHEMIHBMIG+oIG7oIG4hoGIbGRhcDovL2xkYXBJU0FjYS5j ZXJ0LmZubXQuZXMvQ049Q1JMNixjbj1JU0ElMjBDQSxvPUZOTVQtUkNNLEM9RVM/Y2VydGlmaWNh dgvszxzvy2f0aw9utglzddtiaw5hcnk/ymfzzt9vymplyrjbgfzcz1jukxeaxn0cmlidxrpb25q b2ludiyrahr0cdovlddy5jzxj0lmzubxquzxmvyjsc19ju0fjys9dukw2lmnybdanbgkqhkig 9w0BAQsFAAOCAgEAYnVYxWeb57eq6qGlVE9f7tiEPUGqmKm2cXlRLY50Hat4O/dVDv9teyNd/fv cak4uhdhraf+ehoodsm9rtkrkc4vzwiua8xbgjl8nljd1odvgdik0kui7qvqq/x4c9ptyk0ucbw5 MNWyr97UO68rOBNiF+tS2mrOMJqjQS6vX7tf/HOvyPg9dLY/+KiiuijnAFS9+DPJNWQh8UkvSEqg Bkydy0pDFLLOREFHiBY7cOflfjoQm+tKxsPt8Mw/z/p5OLeg8cMyVprtVZ2LohgkJP/Do0SB1lge nlvway7f/7swsgn4y6yd99hb74mkdgreqpbvin5syrgpfzfkyyelz9/q7fhddrtvxlsdcjlia5+ 5D8iprdw70vstU9pmMPXNvBFSmVeGNDVm2jszt7oD254nj5dm/8tXdXqeq4MEi1wHRposKRc6 pptapfrtcizrlq8brkteka6subeshjyiia0942/zefro/h+cemtqz1zuchosmwm6qjh0cesz0tm UpHzrNltR5WPo0IKiqqaDxdxN/9OuTId+P5zLRdwsVSduvUm+5krW8Pxn2pkyTg16NN2wLQ7p/Xn sepwbvv2leujt8n0obhvyzvbzsuchbcplqaqxmbig5dpzfxxbygxsumhufseoauomhxpm9n2uyf J5fwcoXHZPNI1Uw= SHA256withRSA ISA CA FNMT-RCM ES (SIGN) JOLANDA VAN EIJNDTHOVEN EUROPEAN COMMISSION BE Mon Sep 15 14:19:15 CEST 2014 Sat Sep 15 14:19:15 CEST 2018 Subject Alternative Name 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:B4:B2:29:FC:56:F:6D:72:E:A7:52:E1:8:5A:D5:E:66:54:F1:E5:2A:19:CC:98:8:1B:8F:FA:6C:EB:77:81:EC:8F:2 2:FA:87:CD:C8:BC:1D:29:48:24:1D:58:AA::62:98:69:6D:2:A0:65:1D:E9:51:FE:C9:1F:F2:B1:20:B8:46:27:FC:88:E0:8A:8D:BF:F:D6:FC:DA:BB:05::54:7E:7A:1B:2:90:B:2F:BA:EF:8A:8F:B5:2E:9E:14:42:74:B0:0 7:82:7:A1:98:FC:08:0D:ED:DD:2:16:8:27:0D:2B:05:D8:ED:C8:4C:15:ED:C:4:79:D:82:E2:51:D:8A:E2:7B:D7:9:6C:A4:7:1E:76:D2:DF:2D:DC:08:17:46:B2:FE:BE:41:C7:5B:DA:89:AA:66:CF:18:C:21:C0:2B:B1 :09:47:6:6:69:2B:7C:AC:1D:6F:A9:A0:08:7:7:C4:E:F5:5A:0:8E:14:C:4B:0F:C5:4C:1:5B:40:04:B:B8:AD:0B:D8:85:8:D0:F5:EB:B1:94:8E:FB:25:BC:E8:C:74:90:0:75:A9:29:96:C5:DC:19:D0:F0:17:FA:7D:FD: 98:BD:86:1A:E1:BC:4A:D2:2B:A6:F2:CC:64:1:A0:7:A1:B9:DA:6B::DA:0A:E7:20:0B:A5:02:0:01:00:01 JOLANDA.VAN-EIJNDTHOVEN@EC.EUROPA.EU Basic Constraints IsCA: false 8C:FE:8D:99:29:9:2D:B1:0A:8A:E:84:DA:6E:D6:6D:69:0D:9E:FA Authority Key Identifier 47:ED:F8:6:F0:99:AF:5E:FE:7E:0E:5C:58:CB:FE:E2:5:7:A6:BD Policy OID: 1..6.1.4.1.574..4.1 CPS pointer: http://www.cert.fnmt.es/dpcs/ CPS text: [Qualified certificate. Under the usage conditions asserted in the FNMT-RCM CPS (106, Jorge Juan street,28009, Madrid, Spain).] Policy OID: 0.4.0.1456.1.1 Authority Info Access http://ocspisaca.cert.fnmt.es/ocspisaca/ocspresponder http://www.cert.fnmt.es/certs/isaca.crt CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 11

QCStatements - crit. = false id_etsi_qcs_qccompliance id_etsi_qcs_retentionperiod: 15 id_etsi_qcs_limitevalue Value: 200 Currency: EUR id_etsi_qcs_qcsscd CRL Distribution Points ldap://ldapisaca.cert.fnmt.es/cn=crl6,cn=isa%20ca,o=fnmt- RCM,C=ES?certificateRevocationList;binary?base?objectclass=cRLDistributionPoint http://www.cert.fnmt.es/crls_isaca/crl6.crl nonrepudiation F0:E7:C9:5C:09:A5:F6:79:91:A0:5:E:BB:DC:E8:20:1:9:49:EB:1F:F5:7E:6D:2D:F9:62:E8:02: A2:E4:0C X509SubjectName (SIGN) JOLANDA VAN EIJNDTHOVEN EUROPEAN COMMISSION BE TSL Type http://uri.etsi.org/trstsvc/trustedlist/tsltype/eulistofthelists Scheme Operator Name European Commission Scheme Type Community Rules URI [ en ] http://uri.etsi.org/trstsvc/trustedlist/schemerules/eulistofthelists Scheme Territory EU Mime Type List Issue Date Time application/vnd.etsi.tsl+xml 2015-10-02T09:00:00Z Next Update date Time 2016-01-1T09:00:00Z Distribution Points URI http://tsl.gov.cz/publ/tsl_.xtsl CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 12

1 - TSP: First certification authority, a.s. TSP Name First certification authority, a.s. První certifikační autorita, a.s. TSP Trade Name I.CA VAT-264995 PostalAddress Street Address [ en ] Podvinny mlyn 2178/6 Locality [ en ] Prague 9 Postal Code [ en ] 19000 Country PostalAddress Street Address [ cs ] Podvinný mlýn 2178/6 Locality [ cs ] Praha 9 Postal Code [ cs ] 19000 Country ElectronicAddress URI mailto:info@ica.cz URI http://ica.cz/english URI http://ica.cz/ TSP Information URI URI [ en ] http://www.ica.cz/certification-policy URI [ cs ] http://www.ica.cz/certifikacni-politika.aspx URI [ sk ] http://www.ica.cz/certifikacna-politika CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 1

1.1 - Service : (1) I.CA - issuing qualified certificates Service Type Identifier http://uri.etsi.org/trstsvc/svctype/ca/qc Service type description [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Service Name (1) I.CA - issuing qualified certificates (1) I.CA - vydávání kvalifikovaných certifikátů Service digital identities Certificate fields details 10000001 MIIGWjCCBUKgAwIBAgIEAJiWgTANBgkqhkiG9w0BAQUFADCCAQ0xYTBfBgNVBAMMWEkuQ0EgLSBR dwfsawzpzwqgcm9vdcbjzxj0awzpy2f0zsaoazhbglmawtvdmfuw70gy2vydglmawvdoxqgcg9z al0bzhdgvszskglsbqu0vvre9owu0xczajbgnvbaytaknams8wlqydvqqhdqb2r2aw5uw70g bwzdvw4gmjeoc82lcaxotagmdaguhjhagegotesmcoga1uecgwjuhj2bsotignlcnrpzmlrycsn bsotigf1dg9yaxrhigeucy4xpda6bgnvbasmm0frcmvkaxrvdmfuw70gcg9zal0bzhdgvsignl cnrpzmlrycsnbsoty2ggc2x1xb5lyjaefw0wmjazmjiwmdawmdbafw0wodazmjiwmdawmdbamiib DTFhMF8GA1UEAwxYSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlIChrdmFsaWZpa292 YW7DvSBjZXJ0aWZpa8OhdCBwbNreXRvdmF0ZWxlKSAtIFBTRVVET05ZTTELMAkGA1UEBhMCQ1ox LzAtBgNVBAcMJlBvZHZpbm7DvSBtbMO9biAyMTc4LzYsIDE5MCAwMCBQcmFoYSA5MSwwKgYDVQQK DCNQcnZuw60gY2VydGlmaWthxI1uw60gYXV0bJpdGEgYS5zLjE8MDoGA1UECwwzQWtyZWRpdG92 YW7DvSBwbNreXRvdmF0ZWwgY2VydGlmaWthxI1uw61jaCBzbHXFvmViMIIBIjANBgkqhkiG9w0B AQEFAAOCAQ8AMIIBCgKCAQEAxY4zPwz5OskTfhoAjgk8PLTZ+h2D9FNwdSCVfxtgbzkBD7LV ajozhoym0bfsgrqjrhm0cwb/x0zbbskeomqkja7sbxqvxw4cqk6zccqli1aeltek+lil8ybiyvav A6DOX0SNHe5fLB5DF+57jhoLE4jFyLrV6cCtIEspPrSRajcUpfUnIAwgv7xlnNsiqtrxsih1iW TtKt6TV/6Al6L6v5xvrsx9k8q0BSZLC21sVN0yP0e2KfyGoH+YaOnObup61zD2e0TXJgUVgQLLC 21yTWgqEuDRECdq6VpIyFZLswBjYdoFlMcJiL5C8zXLHKkTvZQmaDZPN7eIxQIDAQABo4IBvDCC AbgwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwKQYDVR0RBCIwIIELbBlckBpY2Eu YqGEWh0dHA6Ly9dcuaWNhLmN6MGkGA1UdHwRiMGAwHqAcoBqGGGh0dHA6Ly9xLmljYS5jei9x awnhlmnybdaeobyggoyyahr0cdovl2iuawnhlmn6lfpy2euyjsmb6ghkaahhhodhrwoi8vci5p Y2EuYovcWljYS5jcmwwgcUGA1UdIASBvTCBujCBtwYKKwYBBAGzYQEBBDCBqDAvBggrBgEFBQcC ARYjaHR0cDovLddy5pY2EuYovcWNwL2NwcXJpY2EwMS5wZGYwdQYIKwYBBQUHAgIwaRpnVGVu dg8gy2vydglmawthdcbqzsb2ewrhbibqywtviet2ywxpzmlrbzhbnkgy2vydglmawthdcbwbnr exrvdmf0zwxlihygc291bgfkdsbzzsb6ywtvbmvtidiyny8ymdawifniljadbgnvhq4efgquk1ok fvvldyusztbyvgn701mca/uwgayikwybbquhaqmeddakmaggbgqajkybatanbgkqhkig9w0baquf AAOCAQEAUHd7gP8KdZZOtsQ6WCaenOmkTP7yVbwaXNAzsuUn0aI7w9rZn/rodHkjc58M+R5uLqAJ ilkzn2mifteqqw9yn2hpvfkww0y1g8yyqxzbjuwesumrlryypvdbs0aobsjmuicrfggxvmjbro2t 5Rfpn69INijg6iSmOtFoQuwlPbbxnUJoEe+VoHSNpwvbMPk8PGuGC2VxvZFSUOkLxjMbiXLJRI 5dASq77NS8Hntu42rQA2rhYF41BbjiR5N2i8toiWDM4z7Utbqh4RT7m/s25rdNXKBcl/vARfAf lbhoy4kibffjow8wffb8gjfd5ld88yvcbnia0+axun2w== SHA1withRSA Issuer OU: Akreditovaný poskytovatel certifikačních služeb První certifikační autorita a.s. Issuer L: Podvinný mlýn 2178/6, 190 00 Praha 9 I.CA - Qualified root certificate (kvalifikovaný certifikát poskytovatele) - PSEUDONYM Subject OU: Akreditovaný poskytovatel certifikačních služeb První certifikační autorita a.s. Subject L: Podvinný mlýn 2178/6, 190 00 Praha 9 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 14

I.CA - Qualified root certificate (kvalifikovaný certifikát poskytovatele) - PSEUDONYM Fri Mar 22 01:00:00 CET 2002 Sat Mar 22 01:00:00 CET 2008 Basic Constraints 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:C5:8E::F:0C:F7:DF:9:AC:91:7:E1:A0:08:E0:9:C:CB:4D:9F:A1:D8:F:45:7:7C:1D:48:25:5F:C6:D8:1B:CE: 40:4:EC:BD:D5:6A::99:1E:8C:8C:D1:B7:EC:1A:B4:09:44:7:4:0B:06:FF:C7:4C:C1:05:29:04:8:CA:A4:8D:AE:EC:6D:7A:AF:5D:6E:1C:AA:4E:99:08:24:25:8B:50:04:2E:D7:A4:FA:58:A5:F:20:48:62:F6:AF:0:A0:C E:5F:44:8D:1D:EE:5F:2C:1E:4:17:EE:7B:8E:1A:0B:1:88:C5:C8:BA:D5:E9:C0:AD:2:71:2C:A4:FA:D2:45:A8:DC:52:97:D4:9C:80:0:82:FE:F1:96:7:6C:8A:AB:6B:C6:C8:A1:D6:25:B7:4E:D2:AD:E9:5:7F:E8:09:7A:2 F:AB:F9:C6:FA:EC:C7:D9:C:AB:40:52:64:B0:B6:D6:C5:4D:D:2:F4:7B:62:9F:DF:21:A8:1F:E6:1A:A:7:9B:BA:9E:B5:CC:D:9E:D1:5:C9:81:45:60:40:B2:C2:DB:5C:9:5A:0A:84:B8:4:44:0B:77:6A:E9:5A:48:C8:5 6:4B:B:00:6:61:DA:05:94:C7:09:88:BE:42:F:5:CB:1C:A9:1:BD:94:26:68:6:4F:7:B7:88:C5:02:0:01:00:01 IsCA: true Subject Alternative Name oper@ica.cz http://www.ica.cz CRL Distribution Points http://q.ica.cz/qica.crl http://b.ica.cz/qica.crl http://r.ica.cz/qica.crl Policy OID: 1..6.1.4.1.6625.1.1.4 CPS pointer: http://www.ica.cz/qcp/cpqrica01.pdf CPS text: [Tento certifikat je vydan jako Kvalifikovany certifikat poskytovatele v souladu se zakonem 227/2000 Sb.] 2B:5A:0A:7E:FB:E5:0D:85:2C:65:0:72:BC:6:7B:D:59:9C:6B:F5 QCStatements - crit. = false id_etsi_qcs_qccompliance keycertsign - crlsign Service Status 5D:FF:58:6C:9B:78:49:B9:0A:DB:A:99:79:44:7D:00:2C:E:CF:B7:10:EF:8A:A0:E8:26:EC:0C:0 A:89:B0:0 http://uri.etsi.org/trstsvc/trustedlist/svcstatus/accredited Service status description [en] An accreditation assessment has been performed by the Accreditation Body on behalf of the Member State identified in the "Scheme territory" and the service identified in "Service digital identity" provided by the trust service provider identified in "TSP name" is found to be in compliance with the provisions laid down in Directive 1999/9/EC. Status Starting Time 2002-0-22T00:00:00Z 1.1.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/trstsvc/trustedlist/svcinfoext/qcnosscd Criteria list assert=atleastone CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 15

Policy Identifier nodes: Identifier 1..6.1.4.1.6625.1.1.4.6 Policy Identifier nodes: Identifier 1..6.1.4.1.6625.1.1.4.4 1.2 - Service : (2) I.CA - issuing qualified certificates Service Type Identifier http://uri.etsi.org/trstsvc/svctype/ca/qc Service type description [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Service Name (2) I.CA - issuing qualified certificates (2) I.CA - vydávání kvalifikovaných certifikátů Service digital identities Certificate fields details 10100000 MIIEODCCAyCgAwIBAgIEAJodIDANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dglmawthxi1uw60gyxv0bjpdgesigeucy4whhcnmduwnjaxmdawmdawwhcnmtewnjaxmdawmdaw WjBoMQswCQYDVQQGEwJDWjEqMCgGA1UEAwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmlj YXRlMS0wKwYDVQQKDCRQcnZuw60gY2VydGlmaWthxI1uw60gYXV0bJpdGEsIGEucy4wggEiMA0G CSqGSIbDQEBAQUAA4IBDwAwggEKAoIBAQDwM/o7kB8GPi+JDF5A12G4+UryCybpTeHU1Pa6cSQN 6zDjSReYEfqLuTGsNEDVs76Eu0qOQpJ9lLQjWnaTL4SaG575z17Zt+gOhwt0UjJQhv6AQb2totz BJOGFL7tE/nE0yav1/yB7l2FwFNcWw/8alnDj6T07boH2T82cash/Z0up4VbgeFprLwHpYpeVO GmYcJYxgLOhfeV4OBbSpoKjLOly4L2ChEsDbmB88gxew4dorgyKuL0k1ClCLtKgp/rNHxTskLKcx J2KpyFOdQL4QtLC2l9RdvDwdzGRcmA78H7eoiuBDsSxkI9uFAaGbmqhc9LoLzwjAhKeSKFAgMB AAGjgekwgeYwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwgaMGA1UdIASBmzCBmDCB lqylkwybbagzyqebbauwgyuwgyigccsgaqufbwicmhyadfrlbnrvignlcnrpzmlryxqgamugdnlk YW4gamFrbyBzeXN0ZW1vdnkgaZhbGlmaWtvdmFueSBjZXJ0aWZpa2F0IHYgc291bGFkdSBzZSB6 YWtvbmVtIDIyNy8yMDAwIFNiLiB2IHBsYXRuZW0gem5lbmkuMB0GA1UdDgQWBBRRLl9ZgSX/0f6G 6Icu1o0NWTQrvTANBgkqhkiG9w0BAQUFAAOCAQEAOEbPkZXGrEFoe1iRTp5shex+cA+2zguFTD2I quqr1pfq1aoij4sqboijbfctlngu8i1e6ycys2x9j2rmcnyb0j7ostc6zzxjyxvjpesgx1wyyh tvwzpq2i9g1umva6iu44s69zyz7rex7+2v2ptzpj8ofeqoukkie0bky5y/itxoq2wwclzssh0a0 PE7y1SUcdkDWgTcSOWZIqnsaRRAN7H7+V0Zm1ppv86uZa6w9VTWh7blmhw9NIZuO7qBPDRKpd hn+guuzxxwmjvm2uwwyksyvtishif25w++p+r9j557znww5zcvojaylkyxdzisu96cnb4yyhphg sq== SHA1withRSA První certifikační autorita, a.s. I.CA - Qualified root certificate První certifikační autorita, a.s. I.CA - Qualified root certificate CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 16

Wed Jun 01 02:00:00 CEST 2005 Wed Jun 01 02:00:00 CEST 2011 Basic Constraints 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:F0::FA:B:90:1F:06:E:2F:89:0C:5E:40:D7:61:B8:F9:4A:F2:0B:26:E9:4D:E1:D4:D4:F6:BA:71:24:0D:EB:0:E:4 9:17:98:11:FA:8B:B9:1:AC:4:40:D5:B:BE:84:BB:4A:8E:4:7A:49:F6:52:D0:8D:69:DA:4C:BE:12:68:6E:7B:E7:D:7B:66:DF:A0:A:1C:2D:D1:48:C9:42:1B:FA:01:06:F6:B6:8B:7:04:9:86:14:BE:ED:1:F9:C4:D:26: AF:D7:FC:81:EE:5D:85:C0:5:5C:5B:0F:FC:6A:59:C:8F:A4:F4:ED:BA:07:09:9D:9:F:67:1A:B2:1F:D9:D2:EA:78:55:B8:1E:16:9A:CB:C0:7A:58:A5:E5:4E:1A:66:1C:25:8C:60:2C:E8:5F:79:5E:0E:05:B4:A9:A0:A8:CB: A:5C:B8:2F:60:A1:12:C0:DB:98:1F:C:8:17:B0:E1:DA:2B:8:22:AE:2F:49:5:0A:50:8B:B4:A8:29:FE:B:47:C5:B:24:2C:A7:1:27:62:A9:C8:5:9D:40:BE:10:B4:B0:B7:DA:5F:51:76:F0:F0:77:1:91:72:6D:C0:EF:C1:F B:7A:88:AE:04:B:12:C6:42:D:B8:50:1A:19:B9:AA:85:CF:4B:A0:BC:F0:8C:08:4A:79:22:85:02:0:01:00:01 IsCA: true Policy OID: 1..6.1.4.1.6625.1.1.4.5 CPS text: [Tento certifikat je vydan jako systemovy kvalifikovany certifikat v souladu se zakonem 227/2000 Sb. v platnem zneni.] 51:2E:5F:59:81:25:FF:D1:FE:86:E8:87:2E:D6:8D:0D:59:4:2B:BD keycertsign - crlsign Service Status EE:71:1E:70:E:77:05:0E:5C:BF:18:6A:81:EB:8D:16:9D:05:BF:04:8:DB:C6:55:E7:0E:FF:17:4: 6E:0E:A2 http://uri.etsi.org/trstsvc/trustedlist/svcstatus/accredited Service status description [en] An accreditation assessment has been performed by the Accreditation Body on behalf of the Member State identified in the "Scheme territory" and the service identified in "Service digital identity" provided by the trust service provider identified in "TSP name" is found to be in compliance with the provisions laid down in Directive 1999/9/EC. Status Starting Time 2005-07-01T00:00:00Z 1.2.1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/trstsvc/trustedlist/svcinfoext/qcnosscd Criteria list assert=atleastone Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.4.10.4 Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.4.10. Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.4.10.2 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 17

Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.4.10.1 Policy Identifier nodes: Identifier 1..6.1.4.1.6625.1.1.4.6 1. - Service : (11) I.CA - issuing qualified certificates Service Type Identifier http://uri.etsi.org/trstsvc/svctype/ca/qc Service type description [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Service Name (11) I.CA - issuing qualified certificates (11) I.CA - vydávání kvalifikovaných certifikátů Service digital identities Certificate fields details 1000000 MIIEOTCCAyGgAwIBAgIEAJ0qYDANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dglmawthxi1uw60gyxv0bjpdgesigeucy4whhcnmdgwndaxmdawmdawwhcnmtgwndaxmdawmdaw WjBoMQswCQYDVQQGEwJDWjEqMCgGA1UEAwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmlj YXRlMS0wKwYDVQQKDCRQcnZuw60gY2VydGlmaWthxI1uw60gYXV0bJpdGEsIGEucy4wggEiMA0G CSqGSIbDQEBAQUAA4IBDwAwggEKAoIBAQCrCIik8HTyn/jb1neNMBk+psXHisW9eYCro49UHW4 r02q/717qhntackmmedy4hr8hs2ixralcjegsq/uyj9bp06hrufrjwagqagyyf1kivcshaahzso 0R9J/Ww4bWqsuEWfvBTXZtQh4ycKjXXgWi8KS7TnfnOjKr1w8ZGGCI+/kIQch6n1mSUllMHjbgfB SwdbVPw0y0YnMWhIM6mrIepgzw4T8BA8+n/m9c5duQTIW1/6FCrlyGT8VOQ7aZC1JTIKizwkzT ACwV0llsCp8htXMWeR6GJe4a+5OerWPxTOJ2MV47/zQqTbk+RHpevxQ50EjAzS4fboOz91TAgMB AAGjgeowgecwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwgaQGA1UdIASBnDCBmTCB lgymkwybbagbuegbbaabmigfmigcbggrbgefbqccajb2gnruzw50bybjzxj0awzpa2f0igplihz5 ZGFuIGpha28gaZhbGlmaWtvdmFueSBzeXN0ZW1vdnkgY2VydGlmaWthdCB2IHNvdWxhZHUgc2Ug emfrb25lbsaymjcvmjawmcbtyi4gdibwbgf0bmvtihpuzw5pljadbgnvhq4efgquaj1+1sqlofs7 odfwt9ym0xrwvlkwdqyjkozihvcnaqefbqadggebahl1vaan0iyw8olbwhth8ebk5s4b7/rg+tpx ckgbrpki9n6ygvoe51or+cxn1aus8ewb8arsip1mfnsasoowubl62xntdal8ksoprilv/rqxb+j fuxrdpgkkk5cnlauussgyfrrdcukitm5l7bpszcecgcj1t8lctvamewt0hkgznk21hkn87kijs UYF/UXyOLn+d6bzBND2LrYGt8R50ZkM8QU24LjNPsToe2xLfNo5x/1djsdaPtD2GEmrPQjC0kxbq meocw/4i7rjpcl8zaod6sjih8kirph7li7i4nfausaljifzlzy46z0wmjaviqrflb/+xh7ouzl6 pg= SHA1withRSA První certifikační autorita, a.s. I.CA - Qualified root certificate První certifikační autorita, a.s. I.CA - Qualified root certificate CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 18

Tue Apr 01 02:00:00 CEST 2008 Sun Apr 01 02:00:00 CEST 2018 Basic Constraints 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:AB:08:88:A4:F0:74:F2:9F:F8:DB:D6:77:8D:0:19:E:A6:C5:C7:8A:C5:BD:DD:E6:02:AE:8E:D:50:75:B8:AF:7D: 6:AB:FE:F5:ED:08:67:B4:00:8A:98:C1:0:6:88:51:F2:1B:6:89:74:5A:2D:C8:C4:82:C4:F:B9:88:FD:6C:FD:A:1D:15:05:44:95:80:1A:A6:86:CB:21:75:90:85:5C:B0:70:00:87:4:A8:D1:1F:49:FD:6C:8:6D:6A:AC:B8:45: 9F:BC:14:D7:66:D4:21:E:27:0A:8D:75:E0:5A:2F:0A:4B:B4:E7:7E:7:A:2A:BD:70:F1:91:86:08:8F:BF:90:84:1C:87:A9:F5:99:25:25:94:C1:E:6E:07:C1:4B:07:5B:54:FC:4:CB:46:7:9C:C5:A1:20:CE:A6:AC:87:A9:8: C:8:4F:C0:40:F:E9:FF:9B:D7:9:76:E4:1:2:75:B5:FF:A1:42:AE:5C:86:4F:C5:4E:4:B6:99:0B:52:5:20:A8:B:C2:4C:D:00:2C:15:D2:59:6C:0A:9F:21:B5:7:16:79:1E:86:25:EE:1A:FB:9:9E:AD:6:F1:4C:E2:76:1:5 E:7:EF:FC:D0:A9:6:E4:F9:11:E9:7A:FC:50:E7:41:2:0:4:B8:7D:BA:0E:CF:DD:5:02:0:01:00:01 IsCA: true Policy OID: 1..6.1.4.1.2624.1.4.0.1 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat v souladu se zakonem 227/2000 Sb. v platnem zneni.] 68:9D:7E:D6:C4:25:9:FB:B:A0:7:D6:4F:DC:8C:D1:7A:F0:56:59 keycertsign - crlsign Service Status 1A:A9:80:C8:C0:D:16:F2:50:29:97:89:82:F0::CB:B:A:F4:18:8D:66:9F:2D:E6:A8:D8:4E:E0: 0A:15:75 http://uri.etsi.org/trstsvc/trustedlist/svcstatus/accredited Service status description [en] An accreditation assessment has been performed by the Accreditation Body on behalf of the Member State identified in the "Scheme territory" and the service identified in "Service digital identity" provided by the trust service provider identified in "TSP name" is found to be in compliance with the provisions laid down in Directive 1999/9/EC. Status Starting Time 2008-04-01T00:00:00Z 1..1 - Extension (critical): Qualifiers [QCNoSSCD] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service identified in "Service digital identity" and further identified by the filters information used to further identify under the "Sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support ARE NOT supported by an SSCD (i.e. that that the private key associated with the public key in the certificate is not stored in a Secure Signature Creation Device conformant with the applicable European legislation). Qualifier http://uri.etsi.org/trstsvc/trustedlist/svcinfoext/qcnosscd Criteria list assert=atleastone Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.4.10.5 Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.4.10.4 1.4 - Service : (16) I.CA - issuing qualified certificates CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 19

Service Type Identifier http://uri.etsi.org/trstsvc/svctype/ca/qc Service type description [en] A certificate generation service creating and signing qualified certificates based on the identity and other attributes verified by the relevant registration services. Service Name (16) I.CA - issuing qualified certificates (16) I.CA - vydávání kvalifikovaných certifikátů Service digital identities Certificate fields details 10500000 MIIFHjCCBAagAwIBAgIEAKAoDANBgkqhkiG9w0BAQsFADCBtzELMAkGA1UEBhMCQ1oxOjA4BgNV BAMMMUkuQ0EgLSBRdWFsaWZpZWQgQ2VydGlmaWNhdGlvbiBBdXRobJpdHksIDA5LzIwMDkxLTAr BgNVBAoMJFBydm7DrSBjZXJ0aWZpa2HEjW7DrSBhdXRvcml0YSwgYS5zLjE9MDsGA1UECww0SS5D QSAtIEFjYJlZGl0ZWQgUHJvdmlkZXIgb2YgQ2VydGlmaWNhdGlvbiBTZXJ2aWNlczAeFw0wOTA5 MDEwMDAwMDBaFw0xOTA5MDEwMDAwMDBaMIGMQswCQYDVQQGEwJDWjE6MDgGA1UEAwwxSS5DQSAt IFF1YWxpZmllZCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSwgMDkvMjAwOTEtMCsGA1UECgwkUHJ2 bsotignlcnrpzmlrycsnbsotigf1dg9yaxrhlcbhlnmumt0wowydvqqlddrjlknbic0gqwnjcmvk axrlzcbqcm92awrlcibvzibdzxj0awzpy2f0aw9uifnlcnzpy2vzmiibijanbgkqhkig9w0baqef AAOCAQ8AMIIBCgKCAQEAtTaEy0KC8M9l4lSaWHMs4+sVV1LwzyJYiIQNeCrv1HHm/YpGIdY/Z640 ceankjqvix7m2bk4osc6ko8kzyazopoz6gfcokv2pvlukbc+c2imf6klhev6qna8wxhpbrxkw lhdwb2yhwzo7vqvgdrg8sugqqntkyclnltgbjpnp+az72gpo9ahun/ibhfk4ksc8lys2l9gcy 9CsmdKSBP78p9w8Lx7vDLqkDgt1/zBrcUWmSSb7AE/BPEeMryQV1IdI6nlGnBhWkXOYf6GSdayJw 86btuxC7viDKNrbp44HjQRaSxnp6Oeto1x4DfiYdw/YbJFe7EjkxSQBywIDAQABo4IBLjCCASow DwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwgecGA1UdIASBzCBDCB2QYEVR0gADCB 0DCBzQYIKwYBBQUHAgIwgcAagb1UZW50byBjZXJ0aWZpa2F0IGplIHZ5ZGFuIGpha28gaZhbGlm awtvdmfuesbzexn0zw1vdnkgy2vydglmawthdcbwb2rszsb6ywtvbmegyy4gmjilziwmdagu2iu IHYgcGxhdG5lbSB6bmVuaS9UaGlzIGlzIHF1YWxpZmllZCBzeXN0ZW0gY2VydGlmaWNhdGUgYWNj bjkaw5nihrvien6zwnoiefjdcboby4gmjilziwmdagq29sbc4whqydvr0obbyefhnl0cppomdw kxrp01hi4cd94sj7ma0gcsqgsibdqebcwuaa4ibaqb9lau214hyabhpzftbds/2diglwdmdsbj1 OZbJ8LIPBMxYjPoEMqzAR74tw96Ti6aWRa5WdOWaS6I/qibEKFZhJAVXX5mkx2ewGFLJ+0Go+eTx njlonhvf2v2s+57bm8c8j6/bs6ij6dspcheypfjjh64he2r0aspzdjgzkfm6ypqscjn8qye2x1qm GMLQwvNdjG+nPzCJOOuUEypIWt555ZDLXqS5F7ZjBjlfyDZjEfS2Es9Idok8alf56Mi9/o+Ba46 wmyokkp1ilu0rqcajdbliioackdztaqubonu1guzvzv8tumasvzbjel/gab7ectwe1rukrlytgl MKI9 SHA256withRSA Issuer OU: I.CA - Accredited Provider of Certification Services První certifikační autorita, a.s. I.CA - Qualified Certification Authority, 09/2009 Subject OU: I.CA - Accredited Provider of Certification Services První certifikační autorita, a.s. I.CA - Qualified Certification Authority, 09/2009 Tue Sep 01 02:00:00 CEST 2009 Sun Sep 01 02:00:00 CEST 2019 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:B5:6:84:CB:42:82:F0:CF:65:E2:54:9A:58:7:2C:E:EB:15:57:52:F0:CF:22:58:88:84:0D:78:2A:EF:D4:71:E6:FD:8A :46:21:D6:F:67:AE:4:71:E6:A7:92:4:2F:21:7E:E6:DB:70:4A:E0:E4:82:E8:A:BC:91:96:00:DF:A:29:B:E:86:14:2:8A:57:6:EF:2E:E9:1B:7:E7:6:8A:61:7A:90:B1:C4:BF:AA:8D:0:C5:B1:84:F6:D1:DF:12:B0:94:7 0:F0:07:6C:A1:5B:A:B:57:74:15:80:4:46:F:7B:2E:82:A4:27:B4:A6:02:DC:B9:E5:4C:66:C9:A4:D:FE:0:E:F6:82:9:BD:00:75:27:FC:80:61:16:4E:24:B1:CF:25:61:2D:8B:F4:60:B2:F4:2B:26:74:A4:81:F:BF:29:F7:0F :0B:C7:BB:C:2E:A9:0:82:DD:7F:CC:1A:DC:51:69:92:49:BE:C0:1:F0:4F:11:E:2B:C9:05:75:21:D2:A:9E:51:A7:06:15:A4:5C:E6:1F:E8:64:9D:6B:22:70:F:A6:ED:BB:10:BB:BE:20:CA:6:B6:E9:E:81:E:41:16:92:C6 :7A:7A:B:77:AD:A:5C:78:0D:F8:98:77:0F:D8:6C:91:5E:EC:48:E4:C5:24:01:CB:02:0:01:00:01 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 20

Basic Constraints IsCA: true Policy OID: 2.5.29.2.0 CPS text: [Tento certifikat je vydan jako kvalifikovany systemovy certifikat podle zakona c. 227/2000 Sb. v platnem zneni/this is qualified system certificate according to Czech Act No. 227/2000 Coll.] 79:CB:D0:2:E9:A:67:70:91:74:4F:D:51:E2:E0:20:FD:E1:28:FB keycertsign - crlsign Service Status C0:C0:5A:8D:8D:A5:5E:AF:27:AA:9B:91:0B:0A:6E:F0:D8:BB:DE:D:46:92:8D:B8:72:E1:82:C2: 07:E:98:02 http://uri.etsi.org/trstsvc/trustedlist/svcstatus/accredited Service status description [en] An accreditation assessment has been performed by the Accreditation Body on behalf of the Member State identified in the "Scheme territory" and the service identified in "Service digital identity" provided by the trust service provider identified in "TSP name" is found to be in compliance with the provisions laid down in Directive 1999/9/EC. Status Starting Time 2009-09-01T00:00:00Z 1.4.1 - Extension (critical): Qualifiers [QCSSCDStatusAsInCert] Qualifier type description [en] it is ensured by the trust service provider and controlled (supervision model) or audited (accreditation model) by the referenced Member State (respectively its Supervisory Body or Accreditation Body) that all Qualified Certificates issued under the service (RootCA/QC or CA/QC) identified in "Service digital identity" and further identified by the filters information used to further identify under the"sdi" identified trust service that precise set of Qualified Certificates for which this additional information is required with regards to the presence or absence of Secure Signature Creation Device (SSCD) support DO contain the machineprocessable information indicating whether or not the Qualified Certificate is supported by an SSCD. Qualifier http://uri.etsi.org/trstsvc/trustedlist/svcinfoext/qcsscdstatusasincert Criteria list assert=atleastone Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.1.0..0 Policy Identifier nodes: Identifier 1..6.1.4.1.2624.1.1.0..1 1.5 - Service : (9) I.CA - Qualified Time Stamping Authority, ncipher DSE200 Service Type Identifier http://uri.etsi.org/trstsvc/svctype/tsa/qtst Service type description [en] A time-stamping generation service creating and signing qualified time-stamps tokens. Service Name (9) I.CA - Qualified Time Stamping Authority, ncipher DSE200 CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 21

(9) I.CA - autorita kvalifikovaných časových razítek, ncipher DSE200 Service digital identities Certificate fields details 10106572 MIIFDDCCA/SgAwIBAgIEAJo2zDANBgkqhkiG9w0BAQUFADBoMQswCQYDVQQGEwJDWjEqMCgGA1UE AwwhSS5DQSAtIFF1YWxpZmllZCByb290IGNlcnRpZmljYXRlMS0wKwYDVQQKDCRQcnZuw60gY2Vy dglmawthxi1uw60gyxv0bjpdgesigeucy4whhcnmdywmjaxmdawmdawwhcnmtewmjaxmdawmdaw WjB+MQswCQYDVQQGEwJDWjEnMCUGA1UEAwweSS5DQSAtIFRpbWUgURhbXBpbmcgQXV0aG9yaXR5 MS0wKwYDVQQKDCRQcnZuw60gY2VydGlmaWthxI1uw60gYXV0bJpdGEsIGEucy4xFzAVBgNVBAsM Dm5DaXBoZXIgRFNFMjAwMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxFbYLQl+tUvY ++dg0z4jllkxo89yhta0cfj2ry77rljwvq/z+ntiyuh486shzrwimynxt7j2bhzqr8/4xzkw7vn v5l4zc1zstjxiwzsqhyqpkwh0+odss0bn6nd1po0vqztfqzennw/sblbgzilg7fm2tvawf/8efhi YZ65P0pZPnS2Bbs8hFbhyVRI912O9UbWpxUhkRIELbyGKKBS0J5qqMsFRgzx0vkJQRDb0Iap1UoD 6Iq1ML7TwgSa/H9Zby5im18Ii78sT45ESsNy2YQ0hIHTzeCP7mi6ex1aU9MigOqxBl8FcbOIb1Q jymkyxejlk7ww+ncrn8olawidaqabo4ibpjccaaiwdgydvr0paqh/baqdagbambyga1udjqeb /wqmmaogccsgaqufbwmimigzbgnvhsaegzewgy4wgysgdcsgaqqbgbhiaqqnatb7mhkgccsgaquf BwICMG0aa1RlbnRvIGt2YWxpZmlrbZhbnkgclzdGVtbZ5IGNlcnRpZmlrYXQgVFNBIGplIHZ5 ZGFuIHYgc291bGFkdSBzZSB6YWtvbmVtIGMuIDIyNy8yMDAwIFNiLiB2IHBsYXRuZW0gem5lbmku MB0GA1UdDgQWBBTmfh7VaSxiwPnTJxxV5q0/JmlkjDAfBgNVHSMEGDAWgBRRLl9ZgSX/0f6G6Icu 1o0NWTQrvTCBgQYDVR0fBHoweDAmoCSgIoYgaHR0cDovLFjcmxkcDEuaWNhLmN6LFpY2EwNS5j cmwwjqakockgigh0dha6ly9xyjszhaylmljys5jei9xawnhmduuyjsmcagjkaihibodhrwoi8v cwnybgrwmy5py2euyovcwljyta1lmnybdaybggrbgefbqcbawqmmaowcaygbacorgebma0gcsqg SIbDQEBBQUAA4IBAQBPRRpXGvlbqAhk5tFos10jKQkKaOwUGcOmXatq7AR4nKIPkzGUVKl6SDzq +KS/hhKQ+FzlMHC1Fl8zTvgfqyj14UpTNU0yFNzpG6yRCLkJzIaw5J2szDOwQOqbGzZ18HXc/ogA HYenXtr+goxvOcmpk8mw7wlLcHssSj5hQpf5l97FqARRen0rHW8wgOxdjSycB2Ji/YtywAEUWDiI awmxheranfhsviixyn6h/ceqgykxg4xjdocliwgcpb2m9nhnkymkxwtrwcs+svq2poickjpmwqlw HuoJwyKXhSZa7oCGI7l2g2AicrRbvc6VB8Wk+s/a+E4ZxR4Bd+gdQtWF SHA1withRSA První certifikační autorita, a.s. I.CA - Qualified root certificate Subject OU: ncipher DSE200 První certifikační autorita, a.s. I.CA - Time Stamping Authority Wed Feb 01 01:00:00 CET 2006 Tue Feb 01 01:00:00 CET 2011 Extended Key Usage 0:82:01:22:0:0D:06:09:2A:86:48:86:F7:0D:01:01:01:05:00:0:82:01:0F:00:0:82:01:0A:02:82:01:01:00:C4:56:D8:2D:09:7E:B5:4B:D8:FB:E7:60:D:E:09:94:B2:97:A:CF:77:62:14:DA:D0:27:C9:DA:BC:BB:ED:12:C9:C 1:54:F:CF:E9:ED:2:25:21:E:CE:92:87:4:70:8A:6C:8D:5D:E:E:D8:18:7:A9:1F:F:E:16:64:5B:B5:67:BF:92:F8:64:2D:7:49:2:57:2:0C:EC:40:7C:AA:C:A5:A1:D:EA:1D:B1:2D:01:7:A9:C:D6:9:B4:BE:A6:5 :15:06:5E:6:75:BF:48:12:C1:1B:2:0B:1B:B1:4C:DA:D5:5A:59:FF:FC:79:F1:C8:61:9E:B9:F:4A:59:E:74:B6:05:BB:C:84:56:E1:C9:54:48:F7:5D:8E:F5:46:D6:A7:15:21:91:12:04:2D:BC:86:28:A0:52:D0:9E:6A:A8:CB: 05:46:0C:F1:D2:F9:09:41:10:DB:D0:86:A9:D5:4A:0:E8:8A:B5:0:BE:D:C2:04:9A:FC:7F:59:6F:2E:62:9B:5F:08:8B:BF:2C:4F:8E:44:4A:C:72:D9:84:4:84:81:D:CD:E0:8F:EE:68:BA:7B:1D:5A:5:D:22:80:EA:B1:06: 5F:05:71:B:B7:21:BD:50:8F:7C:8C:91:85:DE:8F:79:4A:ED:65:BE:5:CA:E7:F2:82:F7:6B:02:0:01:00:01 id_kp_timestamping Policy OID: 1..6.1.4.1.2624.1.4.1.1 CPS text: [Tento kvalifikovany systemovy certifikat TSA je vydan v souladu se zakonem c. 227/2000 Sb. v platnem zneni.] E6:7E:1E:D5:69:2C:62:C0:F9:D:27:1C:55:E6:AD:F:26:69:64:8C Authority Key Identifier 51:2E:5F:59:81:25:FF:D1:FE:86:E8:87:2E:D6:8D:0D:59:4:2B:BD CESKÁ REPUBLIKA (ECH REPUBLIC) - Trusted List ID: TSL_ Page 22