The Information System Authority announces that by the end of June 2026, we will be implementing Cloudflare’s security solutions to protect the SiVa validation service. As a result of this change, the IP addresses of the public endpoints for the SiVa demo and production environments will be replaced with those of Cloudflare. We ask all integrators and administrators to add the following IP addresses to their list of trusted addresses if necessary:
IPv4
- 141.101.90.16
- 141.101.90.17
IPv6
- 2a06:98c1:3200::6
- 2a06:98c1:3200::7
As a result of this change, the TLS certificate issuer will also change. If an application using the SiVa service trusts a minimal set of TLS certificates, these new certificates should be added to the existing ones to maintain the ability to quickly switch over in the event of a Cloudflare outage. If necessary, please add the following certificates to your list of trusted root certificates:
-
- GlobalSign R4 (https://pki.goog/repo/certs/gsr4.pem);
- GTS Root R1 (https://pki.goog/repo/certs/gtsr1.pem);
- GTS Root R2 (https://pki.goog/repo/certs/gtsr2.pem);
- GTS Root R3 (https://pki.goog/repo/certs/gtsr3.pem);
- GTS Root R4 (https://pki.goog/repo/certs/gtsr4.pem);
- ISRG Root X1 (https://letsencrypt.org/certs/isrgrootx1.pem);
- ISRG Root X2 (https://letsencrypt.org/certs/isrg-root-x2.pem).
-
- Amazon Root CA 1 (https://www.amazontrust.com/repository/AmazonRootCA1.pem);
- Amazon Root CA 2 (https://www.amazontrust.com/repository/AmazonRootCA2.pem);
- Amazon Root CA 3 (https://www.amazontrust.com/repository/AmazonRootCA3.pem);
- Amazon Root CA 4 (https://www.amazontrust.com/repository/AmazonRootCA4.pem).
-
- DigiCert Global G2 TLS RSA SHA256 2020 CA1 (https://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt.pem)
If you have any further questions, please contact us at [email protected].