Category I: U.S. Federal Agency PKIs

Note: Possession of a valid approved partner PKI certificate, as demonstrated by successful PKI authentication, provides assured identification of the user.  A separate authorization decision verifying that the identified user should have access to the requested content should be made before providing access to DoD information systems.

See the DoD PKI External Interoperability FAQ for more information on DoD approved partner PKI credentials.

U.S. Treasury SSP PKI

Current Certification Authorities (CAs) DetailsSee Section 4.2.4 of DoD Approved External PKIs Master Document
Current CA CertificatesSee US_Treasury_SSP folder in DoD Approved External PKI Certificate Trust Chains zip
Approved Certificate Assurance Levels*See Section 5.7 of DoD Approved External PKIs Master Document
Certificate Revocation List (CRL) Distribution Points**See US Treasury SSP section of DoD Approved External CRL Distribution Points (CRLDPs)
Online Certificate Status Protocol (OCSP) Responder URL(s)**See US Treasury SSP section of DoD Approved External OCSP URLs
Agencies SupportedSee agencies with a Federal PKI Shared Service Provider of US Treasury SSP at https://playbooks.idmanagement.gov/fpki/pivcas-and-agencies/
Performs CA Rekeys?Yes

*As represented by OIDs listed in the Certificate Policies extension of the partner certificate; a certificate must assert at least one approved assurance level to be acceptable for use.

**Note:  These lists are developed and maintained by DoD PKE based on CRLDP and AIA OCSP values asserted in sample certificates provided to DoD by the partner PKI for testing; they are provided for ease of reference and may not be exhaustive in all cases.  Any CRL URL asserted in a CRLDP extension or OCSP URL asserted in an AIA extension of an approved certificate is approved for use by DoD relying parties.

  Title Size Updated
DoD Approved External CRL Distribution Points (CRLDPs) - Version 1.18 DoD Approved External CRL Distribution Points (CRLDPs) - Version 1.18
6.05 KB 2024 01 11
DoD Approved External OCSP URLs - Version 1.17 DoD Approved External OCSP URLs - Version 1.17
3.12 KB 2024 01 11
  DoD Approved External PKIs Master Document - Version 10.2 DoD Approved External PKIs Master Document - Version 10.2
This document provides Certification Authority (CA) certificate trust chain and assurance level information for all Department of Defense (DoD) approved Public Key Infrastructures (PKIs).
1.21 MB 2024 01 11
DoD Approved External PKIs Category 2 Certificate Trust Chains (Non Federal Issuers) - Version 1.16 DoD Approved External PKIs Category 2 Certificate Trust Chains (Non Federal Issuers) - Version 1.16
82.6 KB 2024 01 11
  DoD Approved External PKI Certificate Trust Chains - Version 10.2 DoD Approved External PKI Certificate Trust Chains - Version 10.2
This zip file contains certificate trust chains for DoD Approved External PKIs.
234.33 KB 2024 01 11
DoD Approved External PKIs Category 1 Certificate Trust Chains (Federal Agencies) - Version 1.11 DoD Approved External PKIs Category 1 Certificate Trust Chains (Federal Agencies) - Version 1.11
58.19 KB 2023 09 27
DoD Approved External PKIs Category 3 Certificate Trust Chains (Foreign, Allied, Coalition Partner and Other PKIs) - Version 1.4 DoD Approved External PKIs Category 3 Certificate Trust Chains (Foreign, Allied, Coalition Partner and Other PKIs) - Version 1.4
26.84 KB 2023 09 27
DoD Approved Assurance Levels from External Partner PKIs - Version 1.16 DoD Approved Assurance Levels from External Partner PKIs - Version 1.16
12.1 KB 2023 09 27