Public Key Infrastructure (PKI)
CORDIFESA - Certification Center
Introduction
CORDIFESA, since 21 September 2006, is part of the national Certifiers accredited by the Agency for Digital Italy (AGID) and is included in the List of Certifiers Accredited published by the same Agency. With the entry into force of EU Regulation no. 910/2014 (eIDAS), CORDIFESA has also become a Qualified Trust Service Provider (QTSP) at European level and has been registered in the list of European QTSPs (EU/EEA Trusted List).
CORDIFESA, making use of a technical body called the Certification Centre, offers the public key certification service and is responsible for issuing and managing qualified certificates digital signature and CNS authentication pursuant to the Legislative Decree. n.82 of 7 March 2005 (CAD) and the technical rules referred to in the Decree of the President of the Council of Ministers of 22 February 2013. Furthermore it provides a Certified Timestamping service for the temporal validation of digitally signed documents.
In order to provide military and civilian Defense personnel with the necessary tools for signing documents and for network authentication, CORDIFESA installs these qualified certificates inside the chip of the Multiservice Card of the Defense (CMD) also called ATe Model. The ATe Model is a smartcard pre-printed with of anti-counterfeiting and non-replicability requirements
The ATe Model is the identification card for public administration personnel.
The criteria rules and procedures (of an organisational, operational and technical nature) implemented by the Certification Authority are illustrated in the Operational Manual.
STATO MAGGIORE DELLA DIFESA
COMANDO PER LE OPERAZIONI IN RETE
Via Stresa, 31 B
00135 ROME
ITALY
STATO MAGGIORE DELLA DIFESA
COMANDO PER LE OPERAZIONI IN RETE
Centro di Certificazione
Via Stresa, 31 B
00135 ROME
ITALY
email: info_pkiff@smd.difesa.it
Software Applications
QTSP Difesa provides its users with a software application for digital signature, time stamping and verification digitally signed documents It also provides all the software needed to use the CMD/Mod smartcard.
Signature Kit 5.5.2.4
Software application made available to its users for signature and verification of documents
Signature Kit Manual
User manual of the Signature Kit
Smart Card API (CMD API) 3.87 (Windows)
Application software for use of CMD/Modello ATe smart card on the Microsoft Windows operating systems
ATTENZIONE: Installation of Smart Card APIs (CMD APIs) requires administration privileges (Inform the IT Referrer of the Department/Command). Follow instructions inside the manual.
CryptoWebToolkit 5.08 (Windows)
Software application for use from digital signature on CMD/ATE model smart cards through bowser
Smart Card API for sistemi MAC OS version 12 or later
Software application for the use of CMD/Model ATe smart card on the MAC OS version 12 or later operating systems
Smart Card API (CMD API) Manual
User manual of the application software for use of CMD/Modello ATe smart card on the Microsoft Windows operating systems
Verification Tool
Software application made available solely for the purpose of verifying signed documents in the various formats
Verification Tool Manual
User manual of the Verificatin Tool
Digital Signature
PKI Difesa issues and manages Digital certificates according to the ETSI QCP-n-qscd, i.e. policy for qualified EU certificates issued to natural persons with the private key and the related certificate installed on board a device for the creation of qualified electronicn signatures seals, and QCP-l-qscd, i.e. policy for qualified EU certificates to legal persons with the private key and the related certificate installed on board a device for the creation of qualified electronic signatures seals All the details relating to the documentation, the procedures and, in general, the information on the service provided, are explained in the documentation, produced pursuant to Regulation (EU) No. 910/2014 (eIDAS), reported below.
Click on the link to download the corresponding item.Signature Services.
PKI Disclosure Statement (PDS)
Document that summarizes the most important points of the Certificate Practice Statement (CPS)
Terms and Conditions (T&C)
Document indicating what is considered as acceptance of the Digital Signature Certificate
Certification Practice Statement (CPS)
Document describing the practices and procedures for issuing and managing Digital Signature Certificates
Certificate Policy (CP)
Document indicating the different actors of Digital Signature PKI
PKI Difesa Operative Manual
A document describing all the features of the services offered by PKI Difesa. Only in Italian language.
PKI Difesa Operative Manual 2007-2014
A document describing all the features of the services offered by PKI Difesa. Only in Italian language from 2007 to 2014.
Appendix to the PKI Difesa Operative Manual - Remote signature SMD-COR v1.4 (not currently available)
Appendix to the PKI Difesa Operative Manual with extra information about Remote Signature located at Stato Maggiore Difesa - Comando per le Operazioni in Rete (SMD-COR). Only in Italian language.
Appendix to the PKI Difesa Operative Manual - SGD v1.6
Appendix to the PKI Difesa Operative Manual with extra information about Automatic Signature located at Segretariato Generale della Difesa (SGD). Only in Italian language.
Appendix to the PKI Difesa Operative Manual - Automatic signature and seal SMD-COR v1.1
Appendix to the PKI Difesa Operative Manual with extra information dedicated to the seal at Stato Maggiore Difesa - Comando per le Operazioni in Rete (SMD-COR). Only in Italian language.
Digital Signature (eIDAS) CA Certificate
Distinguished Name: CN = Ministero della Difesa - CA di Firma Digitale, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 56 be 97 77 09 18 b1 cf 24 f4 4d 34 28 c7 c0 f0 60 42 55 f8
IT Trusted List (XML)
Public List of Italian Certifiers, in accordance with eIDAS Regulation and produced by AgID
EU Trusted List (XML)
Public List of the addresses where the various national lists are published, in accordance with the eIDAS Regulation and produced by the European Commission
Time Stamping
PKI Difesa offers a Time Stamping service for its users. The Time Stamping service conforms to the policy BSTP "best practices policy for time-stamp" issued by ETSI. For all details regarding the practices, the procedures and general information about the service provided, refer to the documentation produced under Regulation (EU) n. 910/2014 (also known as eIDAS) and Italian law whose links are available below.
PKI Disclosure Statement (PDS)
Document that summarizes the most important points of the Certificate Practice Statement (CPS) of the Time Stamping service
Terms and Conditions (T&C)
Document indicating what is considered as acceptance of the Time Stamping service
Certification Practice Statement (CPS)
Document describing the practices and procedures for managing the Time Stamping service
Certificate Policy (CP)
Document indicating the different actors of the Time Stamping service
PKI Difesa Operative Manual
A document describing all the features of the services offered by PKI Difesa. Only in Italian language.
eIDAS Time Stamp Authority CA Certificate
Distinguished Name: CN = Ministero della Difesa - Time Stamp Authority eIDAS, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): f9 c2 a3 8b 20 f2 a2 ef 39 ff c1 eb 95 56 b4 a4 12 c7 8f 80
Time Stamp Authority CA Certificate
Distinguished Name: CN = Ministero della Difesa - Time Stamp Authority, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 5e 2f 59 e6 ac d8 a5 0e 12 02 88 55 69 54 bd 8a 12 53 2e d6
IT Trusted List (XML)
Public List of Italian Certifiers, in accordance with eIDAS Regulation and produced by AgID
EU Trusted List (XML)
Public List of the addresses where the various national lists are published, in accordance with the eIDAS Regulation and produced by the European Commission
CNS IT Authentication
PKI Difesa issues and manages CNS IT Authentication certificates necessary for online authentication on IT public administration sites All the details relating to the documentation, the procedures and, in general, the information on the service provided, are explained in the documentation, produced pursuant to the Legislative Decree. n.82 of 7 March 2005 (CAD), reported below.
Click on the link to download the corresponding item.
PKI Difesa Operative Manual
A document describing all the features of the services offered by PKI Difesa. Only in Italian language.
CNS Authentication CA Certificate
Distinguished Name: CN = Ministero della Difesa - CA di Autenticazione CNS, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 23 a3 b1 54 54 d6 98 f9 e6 4c c0 6d 68 a1 d3 87 dc 12 d2 8a
Browser Configuration
Document that describes the configuration procedure of the Microsoft Internet Explorer and Mozilla Firefox 33.1.1 browsers. Only in Italian language.
IT Trusted List (XML)
Public List of Italian Certifiers, in accordance with eIDAS Regulation and produced by AgID
EU Trusted List (XML)
Public List of the addresses where the various national lists are published, in accordance with the eIDAS Regulation and produced by the European Commission
CA Certificates/Certificate Revocation List (CRLs)
Below are the CA/TSA certificates and the related CRLs managed by PKI Difesa.
Certification Authority | Certificate | CRL |
CA Digital Sign (eIDAS)
Distinguished Name: CN = Ministero della Difesa - CA Digital Sign, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
CA IT CNS Authentication (CMD-2/Modello ATe)
Distinguished Name: CN = Ministero della Difesa - CA IT CNS Authentication, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
CA CypherDecypher (CMD-2/Modello ATe)
Distinguished Name: E = info_pkiff@smd.difesa.it, CN = Ministero della Difesa - CA CypherDecypher, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
CA Internal
Distinguished Name: E = info_pkiff@smd.difesa.it, CN = Ministero della Difesa - CA Internal, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
CA Internal Edition 2022
Distinguished Name: E = info_pkiff@smd.difesa.it, CN = Ministero della Difesa - CA Internal Edition 2022, OU = S.M.D. - COR Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
Time Stamping Authority
Distinguished Name: CN = Ministero della Difesa - Time Stamp Authority, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
Time Stamping Authority (eIDAS)
Distinguished Name: CN = Ministero della Difesa - Time Stamp Authority eIDAS, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
CA SmartCard Logon (CMD-2/Modello ATe)
Distinguished Name: CN = Ministero della Difesa - CA SmartCard Logon, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
|
DER | PEM | DER |
SGSI
Information Security Management System