Trust Anchors

alle Verbindungen werden aufgezeichnet — all connections are logged!

Files on this page are published verbatim from their canonical sources. Fetch them with certificate verification on — this site is served with a publicly trusted certificate, so a machine straight from an OS installer can verify it.

Current root CA

Consumers should pin the public key, not the certificate, so that a reissue with the same key does not invalidate them (SPKI SHA-256 pin):

sha256/fnzvI5YJmEmVHGPuGcfqTf8ltRACMec6jP4vM8UvMAo=

RPM package signing key (public half)

05828C73 E4EEDD5A 48278B04 D758CBC4 7BB58666

During a key rotation this directory holds both the current key and its successor; import all of them.

Legacy certificates

Kept downloadable at their historical URLs. Machines provisioned today need the current root CA above, not these.

Using them

# Fedora / RHEL
curl -fSLo /etc/pki/ca-trust/source/anchors/beso-root-ca.crt \
    https://ca.bestsolution.at/ca/bestsolution-root-ca-2026.crt
update-ca-trust

# Debian / Ubuntu
curl -fSLo /usr/local/share/ca-certificates/beso-root-ca.crt \
    https://ca.bestsolution.at/ca/bestsolution-root-ca-2026.crt
update-ca-certificates

# RPM signing key
curl -fSLo /tmp/RPM-GPG-KEY-beso \
    https://ca.bestsolution.at/rpm-gpg/RPM-GPG-KEY-beso
gpg --show-keys --with-colons /tmp/RPM-GPG-KEY-beso   # check the fingerprint above
rpm --import /tmp/RPM-GPG-KEY-beso