Glossary term · C
Root certificate and trust chain
Definition
A root certificate is the apex of the PKI: self-signed by the root certification authority, it anchors the trust of the entire chain. When verifying an electronic signature, the verifier traverses the certificate chain (End Entity → Intermediate(s) → Root) and verifies that each link is valid, not revoked (OCSP / CRL) and compliant with its usage policy. Browsers and operating systems embed trusted root stores (Mozilla NSS, Microsoft Root Store, Apple Root Certificate Program). For eIDAS qualified signatures, the chain must trace back to a QTSP listed on the EU trust list. A certificate whose root is not in the verifier''s store will be rejected even if the cryptographic signature is technically correct.
Related guides
Related terms
Ready to put these concepts into practice?
Certyneo allows you to create signature envelopes compliant with eIDAS in just a few clicks, without installation.