Certificates

Updated: April 4, 2026 1 min read

Open TSA uses a 4-tier CA hierarchy. Download the certificates once and store them alongside your archived timestamps.

Download URLs

CertificateURLValid until
open-ca.eu Root CAcerts/ca.crt2051
open-tsa.eu TSA Root CAcerts/tsa-root.crt2041
TSA Intermediate CAcerts/intermediate.crt2036
TSA Signing Certificatecerts/tsa.crt2028
Full Chain (all 3 CAs)certs/fullchain.pem

CA hierarchy

open-ca.eu Root CA (2026–2051 · 25 years · self-signed · OFFLINE) └── open-tsa.eu TSA Root CA (2026–2041 · 15 years · OFFLINE) └── open-tsa.eu TSA Intermediate CA (2026–2036 · 10 years) └── open-tsa.eu TSA Signing Certificate (2026–2028 · 2 years · EKU: timeStamping)

Which files do I need?

Use caseFiles needed
Verify a timestamp (openssl)ca.crt + fullchain.pem
Long-term archivalAll 4 certificates
Self-hosted verification toolfullchain.pem
Note: The open-ca.eu Root CA is not in any public trust store. You must supply it explicitly with -CAfile ca.crt when running openssl ts -verify.

Inspect a certificate

bash
curl -s https://open-tsa.eu/certs/ca.crt | openssl x509 -noout -text