Category II: Non-Federal Agency PKIs cross certified with the FBCA or PKIs from other PKI Bridges that are cross certified with the FBCA
Note: Possession of a valid approved partner PKI certificate, as demonstrated by successful PKI authentication, provides assured identification of the user. A separate authorization decision verifying that the identified user should have access to the requested content should be made before providing access to DoD information systems.
See the DoD PKI External Interoperability FAQ for more information on DoD approved partner PKI credentials.
DigiCert NFI PKI (Formerly Symantec NFI PKI, VeriSign NFI PKI)
Current Certification Authorities (CAs) Details | See Section 4.3.11 of DoD Approved External PKIs Master Document |
Current CA Certificates | See DigiCert_NFI folder in DoD Approved External PKI Certificate Trust Chains zip |
Approved Certificate Assurance Levels* | See Section 5.22 of DoD Approved External PKIs Master Document |
Certificate Revocation List (CRL) Distribution Points** | See DigiCert NFI section of DoD Approved External CRL Distribution Points (CRLDPs) |
Online Certificate Status Protocol (OCSP) Responder URL(s)** | See DigiCert NFI section of DoD Approved External OCSP URLs |
Performs CA Rekeys? | No |
*As represented by OIDs listed in the Certificate Policies extension of the partner certificate; a certificate must assert at least one approved assurance level to be acceptable for use.
**Note: These lists are developed and maintained by DoD PKE based on CRLDP and AIA OCSP values asserted in sample certificates provided to DoD by the partner PKI for testing; they are provided for ease of reference and may not be exhaustive in all cases. Any CRL URL asserted in a CRLDP extension or OCSP URL asserted in an AIA extension of an approved certificate is approved for use by DoD relying parties.