Useful Resources
CCADB Support
- For problems or questions when using the CCADB, please contact support [at] ccadb [dot] org.
- You can record enhancements, bugs, and API access requests in the ‘Common CA Database’ component under the ‘CA Program’ product in Bugzilla.
CCADB Data
The CCADB Data Usage Terms applies to all data hosted in and by the CCADB.
Root Store Information
The Root Store Operators participating in the CCADB are described below, along with resources and reports that may be helpful to members of the community.
It is crucial to understand that each of these root stores is carefully managed for specific use cases and user communities. While the availability of root store reports and associated certificate bundles may seem convenient for re-use, re-purposing custom-built root stores for applications that do not perfectly align with their intended products, communities, or policies can introduce significant risks to security and interoperability. Such misuse can undermine the very protections these root stores are designed to provide.
In most cases, it’s far more appropriate and secure to curate a purpose-built root store tailored to satisfy the specific risk-based determinations of your corresponding user community. To assist user communities in considering and establishing their own root stores, several additional reports are provided in the Community Reports section of this page. These can help you determine the set of roots most appropriate for your PKI use case and community goals, leading to a more secure and interoperable outcome compared to simply reusing a root store that you do not control.
Apple
Policy: Apple Root Certificate Program
Additional Resources:
Contact: certificate-authority-program [at] apple [dot] com
Root Store Reports:
| PKI Use Case | Downloads | Note |
|---|---|---|
| TLS Server Authentication | CSV | |
| TLS Client Authentication | CSV | |
| S/MIME | CSV | |
| Timestamping | CSV |
Cisco
Policy: Cisco PKI: Trusted Root Stores
Additional Resources:
Contact: trust-root-store [at] external [dot] cisco [dot] com
Root Store Reports:
- See the bundles offered by Cisco.
Google Chrome
Policy: Chrome Root Program Policy
Additional Resources:
Contact: chrome-root-program [at] google [dot] com
Root Store Reports:
| PKI Use Case | Downloads | Note |
|---|---|---|
| TLS Server Authentication | CSV | This download includes certificates that are constrained for various reasons. |
Microsoft
Policy: Trusted Root Program Requirements
Additional Resources:
Contact: msroots [at] microsoft [dot] com
Root Store Reports:
| PKI Use Case | Downloads | Note |
|---|---|---|
| TLS Server Authentication | CSV | |
| TLS Client Authentication | CSV | |
| S/MIME | CSV | |
| Timestamping | CSV | |
| Code Signing | CSV | |
| Document Signing | CSV | |
| Encrypting File System | CSV | |
| IP Security End System | CSV | |
| IP Security IKE Intermediate | CSV | |
| IP Security Tunnel Termination | CSV | |
| IP Security User | CSV |
Mozilla
Policy: Mozilla Root Store Policy
Additional Resources:
Contact: certificates [at] mozilla [dot] org
Root Store Reports:
| PKI Use Case | Downloads | Note |
|---|---|---|
| TLS Server Authentication | CSV | |
| S/MIME | CSV |
Community Reports
Use-case Specific Reports
The following reports contain any root Certification Authority (CA) certificate trusted for the given PKI use case by at least one CCADB Root Store Operator. The Trust Bits for Root Cert field is auto updated from a CCADB trigger that uses the collection of trust bits from all CCADB root stores. All “Apple Constrained”, “Google Chrome Constrained”, “Microsoft Constrained”, “Mozilla Constrained” values will be boolean depending on if any constraint information exists for that root program on that root certificate.
| PKI Use Case | Downloads | Note |
|---|---|---|
| TLS Server Authentication | CSV | Trust Bits for Root Cert INCLUDES Server Authentication AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| TLS Client Authentication | CSV | Trust Bits for Root Cert INCLUDES Client Authentication AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| S/MIME | CSV | Trust Bits for Root Cert INCLUDES Secure Email AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| Timestamping | CSV | Trust Bits for Root Cert INCLUDES Time Stamping AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| Code Signing | CSV | Trust Bits for Root Cert INCLUDES Code Signing AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| Document Signing | CSV | Trust Bits for Root Cert INCLUDES Document Signing AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| Encrypting File System | CSV | Trust Bits for Root Cert INCLUDES Encrypting File System AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| IP Security End System | CSV | Trust Bits for Root Cert INCLUDES IP Security End System AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| IP Security IKE Intermediate | CSV | Trust Bits for Root Cert INCLUDES IP Security IKE Intermediate AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| IP Security Tunnel Termination | CSV | Trust Bits for Root Cert INCLUDES IP Security Tunnel Termination AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
| IP Security User | CSV | Trust Bits for Root Cert INCLUDES IP Security User AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete)) |
Additional Reports
| Description | Downloads | Note |
|---|---|---|
| AllCertificateRecords REST API | N/A | Description of report fields. This API intends to one day replace the All Certificate Information reports. |
| V5 All Certificate Information (root and intermediate) in the CCADB | CSV | Description of report fields. |
| V4 All Certificate Information (root and intermediate) in the CCADB | CSV | V4a (Records of CA certificates, excluding those that expired more than five years ago) V4b (Records of CA certificates expired over five years ago). These two reports–V4a and V4b–are mutually exclusive partitions of the full dataset for V4 and can be combined to reconstruct the complete list. |
| V3 All Certificate Information (root and intermediate) in the CCADB | CSV | Obsolete. This download will be removed on approximately October 1, 2026. |
| All Included Root Certificate Trust Bit Settings | CSV | |
| List of CA problem reporting mechanisms (email, etc.) | CSV / Custom | Use this download to report a certificate problem directly to the CA. |
| List of CAA Identifiers | CSV / Custom | Obsolete. This download will be removed on approximately October 1, 2026. |
| List of CAA Identifiers | CSV / Custom | Used to restrict issuance of certificates to specific CAs via a DNS Certification Authority Authorization Resource Record. |
| Disclosed Domain Control Validation Practices | CSV | |
| Accepted Roots for Production Certificate Transparency Logs | CSV | Includes CAs trusted by at least one of the CCADB root stores. |
| Accepted Roots for Test Certificate Transparency Logs | CSV | Includes CAs that have applied to at least one of the CCADB root stores. |
| All Certificate PEMs Year | CSV | Provides the certificate PEMs for which the CCADB record has a ‘Valid From (GMT)’ field that contains 1999. Change “1999” in the URL to a year of your choosing. |
| All Certificate PEMs Decade | CSV | Provides the certificate PEMs for which the CCADB record has a ‘Valid From (GMT)’ field that contains 2010. Change “2010” in the URL to a decade of your choosing. |