For the complete documentation index, see llms.txt. This page is also available as Markdown.

TLS Certificates

What should I do to prevent service disruptions due to Corppass certificate rotation?

To avoid disruptions:

  • Do NOT pin Corppass TLS leaf certificates. These certificates are rotated periodically without prior notice.

  • Ensure your system trusts AWS root CA certificates. The trusted certificate chain can be found in the AWS Trust Repository.

By following these steps, your system will remain compatible with Corppass certificate updates.


How should I handle certificate validation for Corppass?

It is recommended for Relying Parties to trust all certificates issued by established Certificate Authorities (CAs). Amazon Web Services (AWS) is Corppass's issuing CA.

Add AWS root certificates to your trust store, available at the AWS Trust Repository, to ensure uninterrupted service.


Pinning TLS leaf certificates is not recommended because Corppass certificates are regularly rotated or re-issued. If your system relies on pinned certificates, this will result in a service disruption.

Corppass rotates its certificates as a routine maintenance activity without prior notification. As such, we highly recommend Relying Parties not to pin our leaf certificates.

Last updated