TelephonyBrowser onlyLive · STI-PA roots and CRL, refreshed daily

STIR/SHAKEN Certificate Test

Paste the certificate URL from a signed call. We download it the way a verifier would, time every step, read the signing SPID, and check the whole chain against the STI-PA’s trusted roots and CRL.

Test a certificate URL

The x5u from the call’s Identity header, as it appears there.

19 trusted STI-CA roots·verified 10h 10m ago·CRL 22 entries, issued 1d 9h ago· the CRL is past its next update
Where to find it: the x5u in the PASSporT header, or info=<...> on the Identity header

STI-PA trusted roots

The root certificates of every STI-CA the STI-PA has approved, downloaded from the STI-PA once a day. Each list is only loaded after its STI-PA signature checks out.

Comcast
Comcast SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2040-03-12 · 4,906 days
CTIA
SHAKEN Root CA
STI-CA EC P-384
Verified 10h 10m ago
Expires 2048-06-14 · 7,922 days
GBSDTech
GBSDTech SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-04-30 · 5,321 days
Martini Security, LLC
Martini Security SHAKEN R1
STI-CA EC P-256
Verified 10h 10m ago
Expires 2047-05-03 · 7,515 days
Martini Security, LLC
Martini Security SHAKEN ROOT R2
STI-CA EC P-256
Verified 10h 10m ago
Expires 2048-07-24 · 7,963 days
NetNumber Inc
NetNumber SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-07-07 · 5,389 days
NetNumber Inc
NetNumber SHAKEN Root CA 1
STI-CA EC P-521
Verified 10h 10m ago
Expires 2046-09-21 · 7,291 days
Neustar Information Services Inc
Neustar Certified Caller ID Root CA
STI-CA RSA 2048
Verified 10h 10m ago
Expires 2039-09-23 · 4,735 days
Neustar Information Services Inc
Neustar Certified Caller ID SHAKEN Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-08-17 · 5,430 days
Peeringhub Inc
Peeringhub Inc Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2040-12-12 · 5,182 days
Ribbon Communications
SHAKEN Ribbon Root CA
STI-CA EC P-256
Verified 10h 10m ago
Expires 2046-05-12 · 7,159 days
Sansay Corporation
SHAKEN Sansay Root CA US
STI-CA EC P-256
Verified 10h 10m ago
Expires 2040-08-16 · 5,063 days
SOMOS
SHAKEN ROOT - somos.com
STI-CA EC P-256
Verified 10h 10m ago
Expires 2049-01-11 · 8,133 days
Telonium
Telonium STI-CA Root1
STI-CA EC P-256
Verified 10h 10m ago
Expires 2035-03-05 · 3,073 days
Telonium
Telonium STI-CA Root2
STI-CA EC P-256
Verified 10h 10m ago
Expires 2038-03-07 · 4,171 days
Telonium Communications LLC
Telonium SHAKEN ROOT G1
STI-CA EC P-256
Verified 10h 10m ago
Expires 2035-07-21 · 3,210 days
TMOBILE-USA
TMOBILE-PROD-ROOT-STIRSHAKEN-EC
STI-CA EC P-256
Verified 10h 10m ago
Expires 2044-09-18 · 6,558 days
Transaction Network Services Inc.
TNS STI-CA SHAKEN Root
STI-CA EC P-256
Verified 10h 10m ago
Expires 2041-07-29 · 5,411 days
TransNexus, Inc.
TransNexus, Inc. SHAKEN Root CA2
STI-CA EC P-256
Verified 10h 10m ago
Expires 2042-10-23 · 5,862 days

How this test works

What it checks, where the trust comes from, and why the timing matters.

Which URL do I paste?
The x5u from the call’s Identity header: the https:// address in the PASSporT’s header (it is also the info= parameter on the Identity header) where verifiers download the signing certificate. Paste it as it is; quotes or angle brackets around it are ignored.
What does the test check?
The signing certificate: whether it is valid right now, its names (O and CN), its key, and the SPC in its TNAuthList extension. The intermediate: the STI-CA certificate that signed it, its names and expiry, and whether it is allowed to issue certificates. The root: whether the chain ends at a root on the STI-PA’s trusted list. Then revocation, against the STI-PA CRL and any CRL the chain names, and how long the certificate took to fetch.
What is the signing SPID?
The Service Provider Code (SPC) in the signing certificate’s TNAuthList extension (1.3.6.1.5.5.7.1.26). It identifies the provider the STI-PA issued the SPC token to, usually by its OCN, and it is how a verifier knows who signed the call. A certificate without one is not a SHAKEN signing certificate.
Where do the trusted roots come from?
From the STI-PA, the Policy Administrator (run by iconectiv). Once a day we download its trusted STI-CA list, its Cross Border Trust List and its CRL, check the STI-PA’s signature on each, and only then load them. The roots are listed above with when each was last verified and when it expires. A root that drops off the STI-PA’s list stops being trusted here the same day.
Why does the fetch time matter?
Verification happens while the call is being set up. A verifier that has not cached the certificate downloads it during that window, and a repository that takes more than a second to answer can make it time out and pass the call on as unverified. The test times the DNS lookup, connect, TLS handshake, the server’s response and the download separately, and warns about anything over one second.
Is it safe to test a URL I do not trust?
Yes. The tool only fetches from public addresses, follows at most three redirects and checks each one, stops after 64 KB or a few seconds, and asks for no compression. What comes back is only ever read as certificate data. Nothing from it is run, saved as a file, or shown without escaping. If the file holds a private key, the test says so, and never shows it.