The DoD sponsored External Certification Authority (ECA) program was established to support the issuance of DoD-approved certificates to industry partners and other external entities. Prior to the 2008 DoD CIO memorandum “Approval of External Public Key Infrastructures” the ECA PKI was the only means for DoD partners to interoperate with DoD users and servers. The ECA program is managed by the DoD PKI PMO.
ECA certificates are included in InstallRoot and the PKCS#7 Certificate Bundle for ECA PKI. The Global Directory Service (GDS) hosts ECA information including CA certificates, cross-certificate content, and Certificate Revocation Lists (CRLs). The DoD Robust Certificate Validation Service (RCVS) also provides Online Certificate Status Protocol (OCSP) responses for ECA CA certificates, while individual ECA vendors provide OCSP responses for ECA end entity certificates. More information can be found on the ECA homepage.
Note: Possession of a valid ECA PKI certificate, as demonstrated by successful PKI authentication, provides assured identification of the user. A separate authorization decision verifying that the identified user should have access to the requested content should be made before providing access to DoD information systems.
IdenTrust ECA
Current Certification Authorities (CAs) Details | See Section 3.2.1 of DoD Approved External PKIs Master Document |
Current CA Certificates | See _ECA folder in DoD Approved External PKI Certificate Trust Chains zip |
Approved Certificate Assurance Levels* | See Section 5.2 of DoD Approved External PKIs Master Document |
Certificate Revocation List (CRL) Distribution Points** | See ECA PKI section of DoD and ECA CRL Distribution Points |
Online Certificate Status Protocol (OCSP) Responder URL(s)** | See the DoD ECA Program section of DoD Approved External OCSP URLs |
WidePoint (formerly ORC) ECA
Current Certification Authorities (CAs) Details | See Section 3.2.1 of DoD Approved External PKIs Master Document |
Current CA Certificates | See _ECA folder in DoD Approved External PKI Certificate Trust Chains zip |
Approved Certificate Assurance Levels* | See Section 5.2 of DoD Approved External PKIs Master Document |
Certificate Revocation List (CRL) Distribution Points** | See ECA PKI section of DoD and ECA CRL Distribution Points |
Online Certificate Status Protocol (OCSP) Responder URL(s)** | See the DoD ECA Program section of DoD Approved External OCSP URLs |
*As represented by OIDs listed in the Certificate Policies extension of the partner certificate; a certificate must assert at least one approved assurance level to be acceptable for use.
**Note: These lists are developed and maintained by DoD PKE based on CRLDP and AIA OCSP values asserted in sample certificates provided to DoD by the partner PKI for testing; they are provided for ease of reference and may not be exhaustive in all cases. Any CRL URL asserted in a CRLDP extension or OCSP URL asserted in an AIA extension of an approved certificate is approved for use by DoD relying parties.