Public Key Infrastructure (PKI)

CORDIFESA - Certification Center

Introduction

CORDIFESA, since 21 September 2006, is part of the national Certifiers accredited by the Agency for Digital Italy (AGID) and is included in the List of Certifiers Accredited published by the same Agency. With the entry into force of EU Regulation no. 910/2014 (eIDAS), CORDIFESA has also become a Qualified Trust Service Provider (QTSP) at European level and has been registered in the list of European QTSPs (EU/EEA Trusted List).

CORDIFESA, making use of a technical body called the Certification Centre, offers the public key certification service and is responsible for issuing and managing qualified certificates digital signature and CNS authentication pursuant to the Legislative Decree. n.82 of 7 March 2005 (CAD) and the technical rules referred to in the Decree of the President of the Council of Ministers of 22 February 2013. Furthermore it provides a Certified Timestamping service for the temporal validation of digitally signed documents.

In order to provide military and civilian Defense personnel with the necessary tools for signing documents and for network authentication, CORDIFESA installs these qualified certificates inside the chip of the Multiservice Card of the Defense (CMD) also called ATe Model. The ATe Model is a smartcard pre-printed with of anti-counterfeiting and non-replicability requirements

The ATe Model is the identification card for public administration personnel.

The criteria rules and procedures (of an organisational, operational and technical nature) implemented by the Certification Authority are illustrated in the Operational Manual.

Qualified Trust Service Provider Identification Data:
STATO MAGGIORE DELLA DIFESA
COMANDO PER LE OPERAZIONI IN RETE
Via Stresa, 31 B
00135 ROME
ITALY
Certification Center Identification Data:
STATO MAGGIORE DELLA DIFESA
COMANDO PER LE OPERAZIONI IN RETE
Centro di Certificazione
Via Stresa, 31 B
00135 ROME
ITALY
email: info_pkiff@smd.difesa.it

Software Applications

QTSP Difesa provides its users with a software application for digital signature, time stamping and verification digitally signed documents It also provides all the software needed to use the CMD/Mod smartcard.

Digital Signature

PKI Difesa issues and manages Digital certificates according to the ETSI QCP-n-qscd, i.e. policy for qualified EU certificates issued to natural persons with the private key and the related certificate installed on board a device for the creation of qualified electronicn signatures seals, and QCP-l-qscd, i.e. policy for qualified EU certificates to legal persons with the private key and the related certificate installed on board a device for the creation of qualified electronic signatures seals All the details relating to the documentation, the procedures and, in general, the information on the service provided, are explained in the documentation, produced pursuant to Regulation (EU) No. 910/2014 (eIDAS), reported below.

Click on the link to download the corresponding item.Signature Services.

PKI Disclosure Statement (PDS)

Document that summarizes the most important points of the Certificate Practice Statement (CPS)

Terms and Conditions (T&C)

Document indicating what is considered as acceptance of the Digital Signature Certificate

Certification Practice Statement (CPS)

Document describing the practices and procedures for issuing and managing Digital Signature Certificates

Certificate Policy (CP)

Document indicating the different actors of Digital Signature PKI

PKI Difesa Operative Manual

A document describing all the features of the services offered by PKI Difesa. Only in Italian language.

PKI Difesa Operative Manual 2007-2014

A document describing all the features of the services offered by PKI Difesa. Only in Italian language from 2007 to 2014.

Appendix to the PKI Difesa Operative Manual - Remote signature SMD-COR v1.4

Appendix to the PKI Difesa Operative Manual with extra information about Remote Signature located at Stato Maggiore Difesa - Comando per le Operazioni in Rete (SMD-COR). Only in Italian language.

Appendix to the PKI Difesa Operative Manual - SGD v1.6

Appendix to the PKI Difesa Operative Manual with extra information about Automatic Signature located at Segretariato Generale della Difesa (SGD). Only in Italian language.

Appendix to the PKI Difesa Operative Manual - Automatic signature and seal SMD-COR v1.1

Appendix to the PKI Difesa Operative Manual with extra information dedicated to the seal at Stato Maggiore Difesa - Comando per le Operazioni in Rete (SMD-COR). Only in Italian language.

Digital Signature (eIDAS) CA Certificate

Distinguished Name: CN = Ministero della Difesa - CA di Firma Digitale, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 56 be 97 77 09 18 b1 cf 24 f4 4d 34 28 c7 c0 f0 60 42 55 f8

IT Trusted List (XML)

Public List of Italian Certifiers, in accordance with eIDAS Regulation and produced by AgID

EU Trusted List (XML)

Public List of the addresses where the various national lists are published, in accordance with the eIDAS Regulation and produced by the European Commission

Time Stamping

PKI Difesa offers a Time Stamping service for its users. The Time Stamping service conforms to the policy BSTP "best practices policy for time-stamp" issued by ETSI. For all details regarding the practices, the procedures and general information about the service provided, refer to the documentation produced under Regulation (EU) n. 910/2014 (also known as eIDAS) and Italian law whose links are available below.

CNS IT Authentication

PKI Difesa issues and manages CNS IT Authentication certificates necessary for online authentication on IT public administration sites All the details relating to the documentation, the procedures and, in general, the information on the service provided, are explained in the documentation, produced pursuant to the Legislative Decree. n.82 of 7 March 2005 (CAD), reported below.

Click on the link to download the corresponding item.

CA Certificates/Certificate Revocation List (CRLs)

Below are the CA/TSA certificates and the related CRLs managed by PKI Difesa.

Certification Authority Certificate CRL
CA Digital Sign (eIDAS)

Distinguished Name: CN = Ministero della Difesa - CA Digital Sign, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 56 be 97 77 09 18 b1 cf 24 f4 4d 34 28 c7 c0 f0 60 42 55 f8

DER | PEM DER
CA IT CNS Authentication (CMD-2/Modello ATe)

Distinguished Name: CN = Ministero della Difesa - CA IT CNS Authentication, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 23 a3 b1 54 54 d6 98 f9 e6 4c c0 6d 68 a1 d3 87 dc 12 d2 8a

DER | PEM DER
CA CypherDecypher (CMD-2/Modello ATe)

Distinguished Name: E = info_pkiff@smd.difesa.it, CN = Ministero della Difesa - CA CypherDecypher, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 94 53 e1 0b 3a 57 95 4c 35 0b 26 7a 97 7c b7 cc f7 5b 30 12

DER | PEM DER
CA Internal

Distinguished Name: E = info_pkiff@smd.difesa.it, CN = Ministero della Difesa - CA Internal, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 18 aa 44 f1 fe 6d 67 07 9e a7 f4 86 bc f6 2b 97 e4 0a 6a b7

DER | PEM DER
CA Internal Edition 2022

Distinguished Name: E = info_pkiff@smd.difesa.it, CN = Ministero della Difesa - CA Internal Edition 2022, OU = S.M.D. - COR Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 69 5f a6 4d 14 15 7d e1 c3 66 6f be 3d b6 67 e2 df 85 eb 16

DER | PEM DER
Time Stamping Authority

Distinguished Name: CN = Ministero della Difesa - Time Stamp Authority, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 5e 2f 59 e6 ac d8 a5 0e 12 02 88 55 69 54 bd 8a 12 53 2e d6

DER | PEM DER
Time Stamping Authority (eIDAS)

Distinguished Name: CN = Ministero della Difesa - Time Stamp Authority eIDAS, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): f9 c2 a3 8b 20 f2 a2 ef 39 ff c1 eb 95 56 b4 a4 12 c7 8f 80

DER | PEM DER
CA SmartCard Logon (CMD-2/Modello ATe)

Distinguished Name: CN = Ministero della Difesa - CA SmartCard Logon, SERIALNUMBER = 97355240587, OU = S.M.D. - C.do C4 Difesa, O = Ministero della Difesa, C = IT
Digest (SHA-1): 9f b4 1c 7e ac 40 a8 d6 5c 9f 39 77 4c 0b 4e cf 5b 11 66 42

DER | PEM DER