STIR/SHAKEN Certificate Test
Paste the certificate URL from a signed call. We download it the way a verifier would, time every step, read the signing SPID, and check the whole chain against the STI-PA’s trusted roots and CRL.
Live Test
Test a certificate URL
The x5u from the call’s Identity header, as it appears there.
19 trusted STI-CA roots·verified 10h 10m ago·CRL 22 entries, issued 1d 9h ago· the CRL is past its next update
Trust anchors
STI-PA trusted roots
The root certificates of every STI-CA the STI-PA has approved, downloaded from the STI-PA once a day. Each list is only loaded after its STI-PA signature checks out.
Comcast
Comcast SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2040-03-12 · 4,906 days
CTIA
SHAKEN Root CA
STI-CA EC P-384
Verified 10h 10m ago
Expires 2048-06-14 · 7,922 days
GBSDTech
GBSDTech SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-04-30 · 5,321 days
Martini Security, LLC
Martini Security SHAKEN R1
STI-CA EC P-256
Verified 10h 10m ago
Expires 2047-05-03 · 7,515 days
Martini Security, LLC
Martini Security SHAKEN ROOT R2
STI-CA EC P-256
Verified 10h 10m ago
Expires 2048-07-24 · 7,963 days
NetNumber Inc
NetNumber SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-07-07 · 5,389 days
NetNumber Inc
NetNumber SHAKEN Root CA 1
STI-CA EC P-521
Verified 10h 10m ago
Expires 2046-09-21 · 7,291 days
Neustar Information Services Inc
Neustar Certified Caller ID Root CA
STI-CA RSA 2048
Verified 10h 10m ago
Expires 2039-09-23 · 4,735 days
Neustar Information Services Inc
Neustar Certified Caller ID SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-08-17 · 5,430 days
Peeringhub Inc
Peeringhub Inc Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2040-12-12 · 5,182 days
Ribbon Communications
SHAKEN Ribbon Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2046-05-12 · 7,159 days
Sansay Corporation
SHAKEN Sansay Root CA US
STI-CA EC P-256
Verified 10h 10m ago
Expires 2040-08-16 · 5,063 days
SOMOS
SHAKEN ROOT - somos.com
STI-CA EC P-256
Verified 10h 10m ago
Expires 2049-01-11 · 8,133 days
Telonium
Telonium STI-CA Root1
STI-CA EC P-256
Verified 10h 10m ago
Expires 2035-03-05 · 3,073 days
Telonium
Telonium STI-CA Root2
STI-CA EC P-256
Verified 10h 10m ago
Expires 2038-03-07 · 4,171 days
Telonium Communications LLC
Telonium SHAKEN ROOT G1
STI-CA EC P-256
Verified 10h 10m ago
Expires 2035-07-21 · 3,210 days
TMOBILE-USA
TMOBILE-PROD-ROOT-STIRSHAKEN-EC
STI-CA EC P-256
Verified 10h 10m ago
Expires 2044-09-18 · 6,558 days
Transaction Network Services Inc.
TNS STI-CA SHAKEN Root
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-07-29 · 5,411 days
TransNexus, Inc.
TransNexus, Inc. SHAKEN Root CA2
STI-CA EC P-256
Verified 10h 10m ago
Expires 2042-10-23 · 5,862 days
Notes
How this test works
What it checks, where the trust comes from, and why the timing matters.
Which URL do I paste?
The
x5u from the call’s Identity header: the https:// address in the
PASSporT’s header (it is also the info= parameter on the Identity header) where verifiers
download the signing certificate. Paste it as it is; quotes or angle brackets around it are ignored.
What does the test check?
The signing certificate: whether it is valid right now, its names (
O and
CN), its key, and the SPC in its TNAuthList extension. The
intermediate: the STI-CA certificate that signed it, its names and expiry, and whether it is
allowed to issue certificates. The root: whether the chain ends at a root on the STI-PA’s
trusted list. Then revocation, against the STI-PA CRL and any CRL the chain names, and how long
the certificate took to fetch.
What is the signing SPID?
The Service Provider Code (SPC) in the signing certificate’s TNAuthList extension
(
1.3.6.1.5.5.7.1.26). It identifies the provider the STI-PA issued the SPC token to, usually by its
OCN, and it is how a verifier knows who signed the call. A certificate without one is not a SHAKEN signing
certificate.
Where do the trusted roots come from?
From the STI-PA, the Policy Administrator (run by iconectiv). Once a day we download its
trusted STI-CA list, its Cross Border Trust List and its CRL, check the STI-PA’s signature on each, and
only then load them. The roots are listed above with when each was last verified and when it expires. A root
that drops off the STI-PA’s list stops being trusted here the same day.
Why does the fetch time matter?
Verification happens while the call is being set up. A verifier that has not cached the certificate downloads
it during that window, and a repository that takes more than a second to answer can make it time out and pass
the call on as unverified. The test times the DNS lookup, connect, TLS handshake, the server’s response and
the download separately, and warns about anything over one second.
Is it safe to test a URL I do not trust?
Yes. The tool only fetches from public addresses, follows at most three redirects and checks each one, stops
after 64 KB or a few seconds, and asks for no compression. What comes back is only ever read as
certificate data. Nothing from it is run, saved as a file, or shown without escaping. If the file holds a
private key, the test says so, and never shows it.