Common CA Database

Home | Policy | For CAs | For Auditors | For Root Stores | Resources

Useful Resources

CCADB Support

  • For problems or questions when using the CCADB, please contact support [at] ccadb [dot] org.
  • You can record enhancements, bugs, and API access requests in the ‘Common CA Database’ component under the ‘CA Program’ product in Bugzilla.

CCADB Data

The CCADB Data Usage Terms applies to all data hosted in and by the CCADB.

Root Store Information

The Root Store Operators participating in the CCADB are described below, along with resources and reports that may be helpful to members of the community.

It is crucial to understand that each of these root stores is carefully managed for specific use cases and user communities. While the availability of root store reports and associated certificate bundles may seem convenient for re-use, re-purposing custom-built root stores for applications that do not perfectly align with their intended products, communities, or policies can introduce significant risks to security and interoperability. Such misuse can undermine the very protections these root stores are designed to provide.

In most cases, it’s far more appropriate and secure to curate a purpose-built root store tailored to satisfy the specific risk-based determinations of your corresponding user community. To assist user communities in considering and establishing their own root stores, several additional reports are provided in the Community Reports section of this page. These can help you determine the set of roots most appropriate for your PKI use case and community goals, leading to a more secure and interoperable outcome compared to simply reusing a root store that you do not control.

Apple

Policy: Apple Root Certificate Program

Additional Resources:

Contact: certificate-authority-program [at] apple [dot] com

Root Store Reports:

PKI Use Case Downloads Note
TLS Server Authentication CSV  
TLS Client Authentication CSV  
S/MIME CSV  
Timestamping CSV  


Cisco

Policy: Cisco PKI: Trusted Root Stores

Additional Resources:

Contact: trust-root-store [at] external [dot] cisco [dot] com

Root Store Reports:

  • See the bundles offered by Cisco.


Google Chrome

Policy: Chrome Root Program Policy

Additional Resources:

Contact: chrome-root-program [at] google [dot] com

Root Store Reports:

PKI Use Case Downloads Note
TLS Server Authentication CSV This download includes certificates that are constrained for various reasons.


Microsoft

Policy: Trusted Root Program Requirements

Additional Resources:

Contact: msroots [at] microsoft [dot] com

Root Store Reports:

PKI Use Case Downloads Note
TLS Server Authentication CSV  
TLS Client Authentication CSV  
S/MIME CSV  
Timestamping CSV  
Code Signing CSV  
Document Signing CSV  
Encrypting File System CSV  
IP Security End System CSV  
IP Security IKE Intermediate CSV  
IP Security Tunnel Termination CSV  
IP Security User CSV  


Mozilla

Policy: Mozilla Root Store Policy

Additional Resources:

Contact: certificates [at] mozilla [dot] org

Root Store Reports:

PKI Use Case Downloads Note
TLS Server Authentication CSV  
S/MIME CSV  


Community Reports

Use-case Specific Reports

The following reports contain any root Certification Authority (CA) certificate trusted for the given PKI use case by at least one CCADB Root Store Operator. The Trust Bits for Root Cert field is auto updated from a CCADB trigger that uses the collection of trust bits from all CCADB root stores. All “Apple Constrained”, “Google Chrome Constrained”, “Microsoft Constrained”, “Mozilla Constrained” values will be boolean depending on if any constraint information exists for that root program on that root certificate.

PKI Use Case Downloads Note
TLS Server Authentication CSV Trust Bits for Root Cert INCLUDES Server Authentication AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
TLS Client Authentication CSV Trust Bits for Root Cert INCLUDES Client Authentication AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
S/MIME CSV Trust Bits for Root Cert INCLUDES Secure Email AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
Timestamping CSV Trust Bits for Root Cert INCLUDES Time Stamping AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
Code Signing CSV Trust Bits for Root Cert INCLUDES Code Signing AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
Document Signing CSV Trust Bits for Root Cert INCLUDES Document Signing AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
Encrypting File System CSV Trust Bits for Root Cert INCLUDES Encrypting File System AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
IP Security End System CSV Trust Bits for Root Cert INCLUDES IP Security End System AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
IP Security IKE Intermediate CSV Trust Bits for Root Cert INCLUDES IP Security IKE Intermediate AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
IP Security Tunnel Termination CSV Trust Bits for Root Cert INCLUDES IP Security Tunnel Termination AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))
IP Security User CSV Trust Bits for Root Cert INCLUDES IP Security User AND ((Apple Status != Not Included OR Removed) OR (Google Chrome Status != Not Included OR Removed) OR (Microsoft Status != Not Included OR Pending OR Removed) OR (Mozilla Status != Not Yet Included OR Removed OR Obsolete))


Additional Reports

Description Downloads Note
AllCertificateRecords REST API N/A Description of report fields. This API intends to one day replace the All Certificate Information reports.
V5 All Certificate Information (root and intermediate) in the CCADB CSV Description of report fields.
V4 All Certificate Information (root and intermediate) in the CCADB CSV V4a (Records of CA certificates, excluding those that expired more than five years ago) V4b (Records of CA certificates expired over five years ago). These two reports–V4a and V4b–are mutually exclusive partitions of the full dataset for V4 and can be combined to reconstruct the complete list.
V3 All Certificate Information (root and intermediate) in the CCADB CSV Obsolete. This download will be removed on approximately October 1, 2026.
All Included Root Certificate Trust Bit Settings CSV  
List of CA problem reporting mechanisms (email, etc.) CSV / Custom Use this download to report a certificate problem directly to the CA.
List of CAA Identifiers CSV / Custom Obsolete. This download will be removed on approximately October 1, 2026.
List of CAA Identifiers CSV / Custom Used to restrict issuance of certificates to specific CAs via a DNS Certification Authority Authorization Resource Record.
Disclosed Domain Control Validation Practices CSV  
Accepted Roots for Production Certificate Transparency Logs CSV Includes CAs trusted by at least one of the CCADB root stores.
Accepted Roots for Test Certificate Transparency Logs CSV Includes CAs that have applied to at least one of the CCADB root stores.
All Certificate PEMs Year CSV Provides the certificate PEMs for which the CCADB record has a ‘Valid From (GMT)’ field that contains 1999. Change “1999” in the URL to a year of your choosing.
All Certificate PEMs Decade CSV Provides the certificate PEMs for which the CCADB record has a ‘Valid From (GMT)’ field that contains 2010. Change “2010” in the URL to a decade of your choosing.


Additional Resources