The University of Iowa
Iowa City, Iowa


IT Certificate Repository

You can find policies here:
University IT Policies

The following internal UIowa CA certs are available:


(SHA2 - For SHA2 based certificates issued in 2016 and later)
Uiowa RSA Root CA certificate [PEM/Base 64]
Uiowa RSA Issuing CA1 certificate [PEM/Base 64]

The following UIowa Certificate Revocation Lists are available:
Uiowa RSA Root CA CRL
Uiowa RSA Issuing CA1 CRL


Incommon CA Certificates

For public facing services, the following Incommon related CA certs are available for trust:



Incommon CA Certificates until May 2026

  • On May 30, 2026 the AddTrust External CA Root certificate will expires.
  • Chains below no longer use the AddTrust External CA Root certificate or the UserTrust RSA Certification Authority cross-signed certificate.
For TLS certificates issued before May 4th, 2026
Base:
RSA:
InCommon RSA v2 Org Validation Server CA/Root Bundle [PEM/Base 64]
ECC:
InCommon ECC v2 Org Validation Server CA/Root Bundle [PEM/Base 64]

Incommon CA Certificates after May 2026 and before July 2026

For TLS Server Authentication certificates issued after May 4th, 2026; and before July 17th, 2026
  • On May 30, 2026 the AddTrust External CA Root certificate expired.
  • Chains below no longer use the AddTrust External CA Root certificate or the UserTrust RSA Certification Authority cross-signed certificate.
  • Sectigo is transitioning to a new certificate infrastructure, so new roots are used.
  • Cab-forum is beginning to phase out root certificates that are no longer compliant with the latest policy requirements.
  • April 15th, 2027 is the scheduled date for Chrome and Mozilla TLS Distrust date for the UserTrust RSA Certification Authority e.
  • June 15th, 2026 is the scheduled date for Chrome TLS SCTNotAfter date for the UserTrust RSA Certification Authority.
  • The new Sectigo roots are cross-signed by the UserTrust RSA Certification Authority, as shown here but this should be used only where still supported and needed.

Base: Legacy:
RSA:
InCommon RSA OV SSL CA 3/Root Bundle [PEM/Base 64]
RSA:
InCommon RSA OV SSL CA 3/Root Bundle [PEM/Base 64]
ECC:
InCommon ECC OV SSL CA 3/Root Bundle [PEM/Base 64]
ECC:
InCommon ECC OV SSL CA 3/Root Bundle [PEM/Base 64]

Sectigo CA Certificates after July 2026

For TLS Server Authentication certificates issued after July 17th, 2026
  • On July 17, 2026 InCommon is migrating to a new certificate infrastructure, moving away from Sectigo to Certinext.
  • We lose the ability to request new certificates from Sectigo through the old InCommon certificate portal.
  • Existing issued certificates from InCommon will continue to be valid and functional.
  • We are transitioning to using Sectigo through a new tenant, but it uses a seperate portal and API endpoints.
  • Essentially this means certificate chains will need to be updated to reflect the new infrastructure.

Organizational Validation: Domain Validation:
RSA:
Sectigo Public Server Authentication CA OV R36/Root Bundle [PEM/Base 64]
RSA:
Sectigo Public Server Authentication CA DV R36/Root Bundle [PEM/Base 64]
ECC:
Sectigo Public Server Authentication CA OV E36/Root Bundle [PEM/Base 64]
ECC:
Sectigo Public Server Authentication CA DV E36/Root Bundle [PEM/Base 64]