Sophie

Sophie

distrib > Mageia > 6 > armv7hl > media > core-updates-src > by-pkgid > c5e60b5ea944c639550e89727e4d4c54 > files > 1

qdigidoc4-4.2.0-2.mga6.src.rpm

<?xml version="1.0" encoding="UTF-8"?><TrustServiceStatusList xmlns="http://uri.etsi.org/02231/v2#" xmlns:ns2="http://www.w3.org/2000/09/xmldsig#" xmlns:ns3="http://uri.etsi.org/02231/v2/additionaltypes#" xmlns:ns4="http://uri.etsi.org/01903/v1.3.2#" xmlns:ns5="http://uri.etsi.org/TrstSvc/SvcInfoExt/eSigDir-1999-93-EC-TrustedList/#" xmlns:ns6="http://uri.etsi.org/01903/v1.4.1#" Id="EE0001" TSLTag="http://uri.etsi.org/19612/TSLTag">
    <SchemeInformation>
        <TSLVersionIdentifier>5</TSLVersionIdentifier>
        <TSLSequenceNumber>45</TSLSequenceNumber>
        <TSLType>http://uri.etsi.org/TrstSvc/TrustedList/TSLType/EUgeneric</TSLType>
        <SchemeOperatorName>
            <Name xml:lang="en">Estonian Technical Regulatory Authority</Name>
            <Name xml:lang="et">Tehnilise Järelevalve Amet</Name>
        </SchemeOperatorName>
        <SchemeOperatorAddress>
            <PostalAddresses>
                <PostalAddress xml:lang="en">
                    <StreetAddress>23A Sõle St</StreetAddress>
                    <Locality>Tallinn</Locality>
                    <PostalCode>10614</PostalCode>
                    <CountryName>EE</CountryName>
                </PostalAddress>
            </PostalAddresses>
            <ElectronicAddress>
                <URI xml:lang="en">mailto:info@tja.ee</URI>
                <URI xml:lang="en">https://sr.riik.ee/en.html</URI>
            </ElectronicAddress>
        </SchemeOperatorAddress>
        <SchemeName>
            <Name xml:lang="en">EE:Trusted list including information related to the qualified trust service providers which are supervised by the issuing Member State, together with information related to the qualified trust services provided by them, in accordance with the relevant provisions laid down in Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC.</Name>
        </SchemeName>
        <SchemeInformationURI>
            <URI xml:lang="en">https://sr.riik.ee/en/tl.html</URI>
            <URI xml:lang="en">http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32014R0910&amp;from=EN</URI>
            <URI xml:lang="et">https://sr.riik.ee/et/tl.html</URI>
            <URI xml:lang="et">http://eur-lex.europa.eu/legal-content/ET/TXT/PDF/?uri=CELEX:32014R0910&amp;from=EN</URI>
        </SchemeInformationURI>
        <StatusDeterminationApproach>http://uri.etsi.org/TrstSvc/TrustedList/StatusDetn/EUappropriate</StatusDeterminationApproach>
        <SchemeTypeCommunityRules>
            <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/schemerules/EUcommon</URI>
            <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/schemerules/EE</URI>
        </SchemeTypeCommunityRules>
        <SchemeTerritory>EE</SchemeTerritory>
        <PolicyOrLegalNotice>
            <TSLLegalNotice xml:lang="en">The applicable legal framework for the present trusted list is Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC.</TSLLegalNotice>
            <TSLLegalNotice xml:lang="et">Käesoleva usaldusnimekirja suhtes kohaldatav õigusraamistik on Euroopa Parlamendi ja nõukogu 23. juuli 2014. aasta määrus (EL) nr 910/2014 e-identimise ja e-tehingute jaoks vajalike usaldusteenuste kohta siseturul ja millega tunnistatakse kehtetuks direktiiv 1999/93/EÜ.</TSLLegalNotice>
        </PolicyOrLegalNotice>
        <HistoricalInformationPeriod>65535</HistoricalInformationPeriod>
        <PointersToOtherTSL>
            <OtherTSLPointer>
                <ServiceDigitalIdentities>
                    <ServiceDigitalIdentity>
                        <DigitalId>
                            <X509Certificate>MIID/DCCAuSgAwIBAgIQEAAAAAAAWgS4SGkJJUcHdzANBgkqhkiG9w0BAQUFADAzMQswCQYDVQQGEwJCRTETMBEGA1UEAxMKQ2l0aXplbiBDQTEPMA0GA1UEBRMGMjAxMzA2MB4XDTEzMDcxNzE3NDQwOFoXDTE4MDcxMzIzNTk1OVowbjELMAkGA1UEBhMCQkUxITAfBgNVBAMTGFBpZXJyZSBEYW1hcyAoU2lnbmF0dXJlKTEOMAwGA1UEBBMFRGFtYXMxFjAUBgNVBCoMDVBpZXJyZSBBbmRyw6kxFDASBgNVBAUTCzYwMDIxMjExOTE5MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCMv+7DvhzLwG3prirUDGaYRS2+jBZtN2cYXuloKSqAc5Q58FEmk0gsZRF+/4dkt8hgCvbBcpmG6FcvTfNxQbxPX88yYwpBYsWnJ3aD5P4QrN2+fZxwxfXxRRcX+t30IBpr+WYFv/GhJhoFo0LWUehC4eyvnMfP4J/MR4TGlQRrcwIDAQABo4IBUzCCAU8wHwYDVR0jBBgwFoAUww/Dck0/3rI43jkuR2RQ//KP88cwbgYIKwYBBQUHAQEEYjBgMDYGCCsGAQUFBzAChipodHRwOi8vY2VydHMuZWlkLmJlbGdpdW0uYmUvYmVsZ2l1bXJzMi5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3NwLmVpZC5iZWxnaXVtLmJlMEQGA1UdIAQ9MDswOQYHYDgJAQECATAuMCwGCCsGAQUFBwIBFiBodHRwOi8vcmVwb3NpdG9yeS5laWQuYmVsZ2l1bS5iZTA5BgNVHR8EMjAwMC6gLKAqhihodHRwOi8vY3JsLmVpZC5iZWxnaXVtLmJlL2VpZGMyMDEzMDYuY3JsMA4GA1UdDwEB/wQEAwIGQDARBglghkgBhvhCAQEEBAMCBSAwGAYIKwYBBQUHAQMEDDAKMAgGBgQAjkYBATANBgkqhkiG9w0BAQUFAAOCAQEAEE3KGmLX5XXqArQwIZQmQEE6orKSu3a1z8ey1txsZC4rMk1vpvC6MtsfDaU4N6ooprhcM/WAlcIGOPCNhvxV+xcY7gUBwa6myiClnK0CMSiGYHqWcJG8ns13B9f0+5PJqsoziPoksXb2A9VXkr5aEdEmBYLjh7wG7GwAuDgDT0v87qtphN02/MAlJcNqT3JUUAotD7yfEybmK245jKo+pTYeCHGh7r1HzVWhbUDcQ/e1PpQXjVqBmr4k1ACtuu4H19t6K1P5kf7ta5JFEJPFgy3Hxt6YqzoY07WTVEpS4gJqtleIdX1Fhse7jq83ltcCzlfysBRqY/okUzipo1rbQw==</X509Certificate>
                        </DigitalId>
                    </ServiceDigitalIdentity>
                    <ServiceDigitalIdentity>
                        <DigitalId>
                            <X509Certificate>MIID/TCCAuWgAwIBAgIQEAAAAAAAWcxEUPr16SDrtzANBgkqhkiG9w0BAQUFADAzMQswCQYDVQQGEwJCRTETMBEGA1UEAxMKQ2l0aXplbiBDQTEPMA0GA1UEBRMGMjAxMzExMB4XDTEzMDcyNDAxNDUzMVoXDTE4MDcxODIzNTk1OVowbzELMAkGA1UEBhMCQkUxIjAgBgNVBAMTGU1hYXJ0ZW4gT3R0b3kgKFNpZ25hdHVyZSkxDjAMBgNVBAQTBU90dG95MRYwFAYDVQQqEw1NYWFydGVuIEpvcmlzMRQwEgYDVQQFEws4MzEyMTQyNDEwMjCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAjbr1T8USYkuh4X+Yi+coykq7mbF8PjgyjWQ28uODqRCkynuqJz468tCIYxsM/+/QdqEFq4Z5Z1YDbBYb5KsxfBmkzr9D+Gt49iWVt9Ig+FhngbOexwCW108t6Q/+NAo6gwl6IKkzv2wpEJIwtc51VFzvM+WkE1mNmclphYRTL5UCAwEAAaOCAVMwggFPMB8GA1UdIwQYMBaAFLws1Y0dT3YXfAzva5To9R51FmNhMG4GCCsGAQUFBwEBBGIwYDA2BggrBgEFBQcwAoYqaHR0cDovL2NlcnRzLmVpZC5iZWxnaXVtLmJlL2JlbGdpdW1yczIuY3J0MCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5laWQuYmVsZ2l1bS5iZTBEBgNVHSAEPTA7MDkGB2A4CQEBAgEwLjAsBggrBgEFBQcCARYgaHR0cDovL3JlcG9zaXRvcnkuZWlkLmJlbGdpdW0uYmUwOQYDVR0fBDIwMDAuoCygKoYoaHR0cDovL2NybC5laWQuYmVsZ2l1bS5iZS9laWRjMjAxMzExLmNybDAOBgNVHQ8BAf8EBAMCBkAwEQYJYIZIAYb4QgEBBAQDAgUgMBgGCCsGAQUFBwEDBAwwCjAIBgYEAI5GAQEwDQYJKoZIhvcNAQEFBQADggEBAHNRipzOD4aXB7Oo4FgfBbWgPkmUGTqkz2jK9U2tEWUbyQrhirgqhxK6YMAHBvzL+7BHouMEAuxycZG3ozAfEDRZiznFWyqS8QlnHUe0ThaAvs8v5wYOUO7lJ6vnaNLLvQj7W3L5kCnEva5h0Jh9wMytlNp89dd02l7MD4BsidXoMN21AE8su39tBmNayLF6YrFLe3Zob4fQCuIEbx/pj3kYIVC4WM7uuDx+QpEJdNBtB41o2q2JJFqusRP7W0phkxX7sPtYkot6RXLdgaZNoB4YIRwGozIvcegydRVqpcYrvFSoppNHQqd8ZNzswjGzqBhlWYPsxdjjsxJiUyk7T1c=</X509Certificate>
                        </DigitalId>
                    </ServiceDigitalIdentity>
                    <ServiceDigitalIdentity>
                        <DigitalId>
                            <X509Certificate>MIIHATCCBOmgAwIBAgIDGpmWMA0GCSqGSIb3DQEBCwUAME4xCzAJBgNVBAYTAkxVMRYwFAYDVQQKDA1MdXhUcnVzdCBTLkEuMScwJQYDVQQDDB5MdXhUcnVzdCBHbG9iYWwgUXVhbGlmaWVkIENBIDMwHhcNMTYwOTE1MDkwMDEyWhcNMTkwOTE1MDkwMDEyWjCB/TELMAkGA1UEBhMCQkUxCzAJBgNVBAcTAkJFMRwwGgYDVQQKExNFdXJvcGVhbiBDb21taXNzaW9uMRUwEwYDVQQLEwwwOTQ5LjM4My4zNDIxHDAaBgNVBAMTE01hYXJ0ZW4gSm9yaXMgT3R0b3kxDjAMBgNVBAQTBU90dG95MRYwFAYDVQQqEw1NYWFydGVuIEpvcmlzMR0wGwYDVQQFExQxMDMwNDQ0NDExMDA4MDgzNzU5MjEpMCcGCSqGSIb3DQEJARYabWFhcnRlbi5vdHRveUBlYy5ldXJvcGEuZXUxHDAaBgNVBAwTE1Byb2Zlc3Npb25hbCBQZXJzb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCyUn5NvdLXpWSAPF7S+tOy/M6uY8Un5sNt2cHIOs/OHvcfY+ghBXwz91EffNXku2RKqwgw3+dyRBI1eOq2l7r0z9dgNd40zB7a/p9M10SsDT41MJB5iQRYE4kQ73FGA61oXD530fYNzxCA9dWXzQ40L+wdpPbrVtfgi+pRTZSXocZF2VHpuiPEVexHPHt68rX/G8pYHg7zmYOEBPLsjjQAwbrVZIKb9Ypgkwb4ziaFg6UZemMfRtl7S08UWjjhOUUjZ+216ie9V6cMSXzg+5Co9HVSXPdqooNhMrOShTI7IzDja3rXAcw6TkvPDgZEpCJZ73HCxz+DWnW7D2JuXMelAgMBAAGjggI2MIICMjAMBgNVHRMBAf8EAjAAMGYGCCsGAQUFBwEBBFowWDAnBggrBgEFBQcwAYYbaHR0cDovL3FjYS5vY3NwLmx1eHRydXN0Lmx1MC0GCCsGAQUFBzAChiFodHRwOi8vY2EubHV4dHJ1c3QubHUvTFRHUUNBMy5jcnQwggEeBgNVHSAEggEVMIIBETCCAQMGCCuBKwEBCgMBMIH2MIHHBggrBgEFBQcCAjCBuhqBt0x1eFRydXN0IFF1YWxpZmllZCBDZXJ0aWZpY2F0ZSBvbiBTU0NEIGNvbXBsaWFudCB3aXRoIEVUU0kgVFMgMTAxIDQ1NiBRQ1ArIGNlcnRpZmljYXRlIHBvbGljeS4gS2V5IEdlbmVyYXRpb24gYnkgQ1NQLiBTb2xlIEF1dGhvcmlzZWQgVXNhZ2U6IFN1cHBvcnQgb2YgUXVhbGlmaWVkIEVsZWN0cm9uaWMgU2lnbmF0dXJlLjAqBggrBgEFBQcCARYeaHR0cHM6Ly9yZXBvc2l0b3J5Lmx1eHRydXN0Lmx1MAgGBgQAizABATAiBggrBgEFBQcBAwQWMBQwCAYGBACORgEBMAgGBgQAjkYBBDALBgNVHQ8EBAMCBkAwHwYDVR0jBBgwFoAUY4/CiwOxq47YU0eWHZmoffasqHUwMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5sdXh0cnVzdC5sdS9MVEdRQ0EzLmNybDARBgNVHQ4ECgQIR8OxCQGxgiswDQYJKoZIhvcNAQELBQADggIBACWb5+Xt6sOaxE8bpakXFo2BoWYphyq5XAXRM6e7QDS57CaHW8Ly6ep0I23EZ3KcI3mpqg2UDaEZhGhvnE/SVEyh4go6E8Hljv9iyrdGccc+RgTM87rbkoUi6sZ+BcLlG7WNo2c5BqRyElch5o1/9AEnft3inLK4R47BHtbRkf/FkptiQWjSVzJ6LEHIi8EF215Qg5X/yaUQdxIfMPcQ580rGujGN/Dl2H9rxBUdPUCO0i7zbPeJtfah1zSXxYjy9V4x2Q+cVbcMpa5fSys9c/YQA6XAkA5oKrkSsjCGBULDi2APC3FMehp6BcI/5k202iwebq3xgDWFvuD+swgZ8P0YxS4dZMcjtseYvzGCArFEcoI7buZb30A/Z7K3qx3D895NHupfz20dskujjCV7PVgxx0PCXJPBquuPFV+aYgDCLr7XQMmU8wo0HGKZ/mXThY2F2POLF0uKgY6F5mZBIhRYU5IgybGrayqEpaEcr8LMBKzr2DRpLzDojU5k9apmVnoQJ2cSfTrQ87ZXOaG+6h/Md6cVaUI0J8iOpFLinKRGRBEkwE+pxFE2tOoyaK9iLKurRYdfd8WETatEsEyi4o4CFPD//bthgwvSl0Cfrkj8V5lIR13140D+NQtX0vSx/PHq5ySOKq9ZPUo42r8ihX/ZP0Z+Vrg5ATqpSCcqn01Z</X509Certificate>
                        </DigitalId>
                    </ServiceDigitalIdentity>
                    <ServiceDigitalIdentity>
                        <DigitalId>
                            <X509Certificate>MIIHDjCCBPagAwIBAgIDHiEoMA0GCSqGSIb3DQEBCwUAME4xCzAJBgNVBAYTAkxVMRYwFAYDVQQKDA1MdXhUcnVzdCBTLkEuMScwJQYDVQQDDB5MdXhUcnVzdCBHbG9iYWwgUXVhbGlmaWVkIENBIDMwHhcNMTcwNTExMTAyNzI1WhcNMjAwNTExMTAyNzI1WjCCAQkxCzAJBgNVBAYTAk5MMQswCQYDVQQHEwJCRTEcMBoGA1UEChMTRXVyb3BlYW4gQ29tbWlzc2lvbjEVMBMGA1UECxMMMDk0OS4zODMuMzQyMSEwHwYDVQQDExhNaWNoYWVsIFRoZW9kb29yIGRlIEJvZXIxEDAOBgNVBAQTB2RlIEJvZXIxGTAXBgNVBCoTEE1pY2hhZWwgVGhlb2Rvb3IxHTAbBgNVBAUTFDEwMzAzOTY5NDUwMDg1MDQ2NDI0MSswKQYJKoZIhvcNAQkBFhxtaWNoYWVsLmRlLWJvZXJAZWMuZXVyb3BhLmV1MRwwGgYDVQQMExNQcm9mZXNzaW9uYWwgUGVyc29uMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq2G70g/Tsyt8nyI1PXYHgIm6a6DawB2ATZMsMxkS1flXjkPNMd/e1Go/G1+IFsqA6iBlfxmFhABJa9FbFallOMBrE3Ao0SdHpT4UbrhVyWx5iV/DjInxPMCzx3Przus3CVy7YhKHO9Jt/qPruWeLCf3YFMV8N02lig904Vbc6pxjx5yqKij7skHSiMyAzdgw/VIQZjJF8PiA10eguvwgS/BU6ip5M03DoGOZPBvIt3q/Av4YHtd7LaOFTYl/zRcn2f12FqO4JMiNR5LxfByRbMmUJQe8sjtC0/ho7cG3BWuusLUe/LtQIGCT/uXXdF9qKuOiPDQ3OpfhJIhElaJPpwIDAQABo4ICNjCCAjIwDAYDVR0TAQH/BAIwADBmBggrBgEFBQcBAQRaMFgwJwYIKwYBBQUHMAGGG2h0dHA6Ly9xY2Eub2NzcC5sdXh0cnVzdC5sdTAtBggrBgEFBQcwAoYhaHR0cDovL2NhLmx1eHRydXN0Lmx1L0xUR1FDQTMuY3J0MIIBHgYDVR0gBIIBFTCCAREwggEDBggrgSsBAQoDATCB9jCBxwYIKwYBBQUHAgIwgboagbdMdXhUcnVzdCBRdWFsaWZpZWQgQ2VydGlmaWNhdGUgb24gU1NDRCBjb21wbGlhbnQgd2l0aCBFVFNJIFRTIDEwMSA0NTYgUUNQKyBjZXJ0aWZpY2F0ZSBwb2xpY3kuIEtleSBHZW5lcmF0aW9uIGJ5IENTUC4gU29sZSBBdXRob3Jpc2VkIFVzYWdlOiBTdXBwb3J0IG9mIFF1YWxpZmllZCBFbGVjdHJvbmljIFNpZ25hdHVyZS4wKgYIKwYBBQUHAgEWHmh0dHBzOi8vcmVwb3NpdG9yeS5sdXh0cnVzdC5sdTAIBgYEAIswAQEwIgYIKwYBBQUHAQMEFjAUMAgGBgQAjkYBATAIBgYEAI5GAQQwCwYDVR0PBAQDAgZAMB8GA1UdIwQYMBaAFGOPwosDsauO2FNHlh2ZqH32rKh1MDMGA1UdHwQsMCowKKAmoCSGImh0dHA6Ly9jcmwubHV4dHJ1c3QubHUvTFRHUUNBMy5jcmwwEQYDVR0OBAoECED2Gny4nY/ZMA0GCSqGSIb3DQEBCwUAA4ICAQBvdAp4qOITVgjyiZkdUMoQC5HPDvptyJrF+j4aZmCIYbg8UEy5RqurLv5icKUWjp0nYO8Qq4drrMGHbOMlWiVZ6yUiy8oXv62gv/hiSGGrwDKekfZcJ3K9wUT50TaM3sROmY0BzbYqatsDOoHb2BwhNMooFwo+sUZ+5Qt1Lv+FMLKHxeO9rM4ezXPO8Vsfh6d5zddGl29WrxbBZj7bp3cfSBHJa1t6NIIr5+sU9Xu+GvTSXuSSht3kmVU9ofctXetQ8Qq+mxPwPhNTyNu8IaQgQQBnWTMb6PQgtIaWOJak9mpRhvvlH9+sdIjNvGO46BCNykUPu4Mdgi0Zq5rsoCJUp5EpUWrAmdM5yMufMMKXqW8XHqU0KsTGyBcIkoElmhvtCQBBTfE5vh7yOS6hYpzTop9fLTJ+uQJI14DTOu+iVSmw5Oh8AYTPKh5wzKkEWTiq5Z0KiwmmOIxo8T9Ytlhsae/7aO1nC3WxFKaqWAFQx5UPIs4bQ0rRW39n1T6PovJxkKTPEW6TPmYrYjR2DYlsSnIbR9ebHUbRB/v/o9Pvqx6dArlpVuhDWWDjuAT1bW3ej+/jIJGyQtwKqL9fnDcmuUqzoBa9fXJuB1e8m3+tI1H5e9F/JH3kdkPsrV9DMS13+MYIeQJgAK3ofJcuKCKYQ5uUEZaU2CKiR6TzvzzGqQ==</X509Certificate>
                        </DigitalId>
                    </ServiceDigitalIdentity>
                    <ServiceDigitalIdentity>
                        <DigitalId>
                            <X509Certificate>MIIGZzCCBE+gAwIBAgIQEAAAAAAAH6yPXvnVxqcEcDANBgkqhkiG9w0BAQUFADAzMQswCQYDVQQGEwJCRTETMBEGA1UEAxMKQ2l0aXplbiBDQTEPMA0GA1UEBRMGMjAxNTA4MB4XDTE1MDUwMTE4NTQ1NFoXDTI1MDQyNTIzNTk1OVowczELMAkGA1UEBhMCQkUxJzAlBgNVBAMTHkplYW4tTWFyYyBWZXJiZXJndCAoU2lnbmF0dXJlKTERMA8GA1UEBBMIVmVyYmVyZ3QxEjAQBgNVBCoTCUplYW4tTWFyYzEUMBIGA1UEBRMLNjcwMjIzMzAzNDAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCwbnf998lxC5nc7YZUhnMIQ+n3VAjrFU2IOIzmHHSJ6aMASYOMYOlLx7XDrjbmh/MyhlpGYmNsF0iLwEYWXNwF4ChmfHqvoI/P29aqNkcojV2cFpZj+ocgnyf+f2cwn3z/kGh9kI6x4eS5IroFpABvzxWi0WD3W7wSJKyeRoMaGOtw07iA43S4fjDzjkKTYGor6PIOv6UtCfrZqPjTg+822kFhERz/3KiqSn2Hx324IIN/mZCSDd5ixKl0tdCsX+bPbXJI4tOyE0RDUl5/+iMAQWjli45opKj8eTMx2kmSycw9Du4zkFzgnp81XGDqEHZp53wSg8uZ5QR8EUjU3xNbAgMBAAGjggI1MIICMTAfBgNVHSMEGDAWgBRqb1HlzCddZQnuqBsSlAPwQKAI8jBwBggrBgEFBQcBAQRkMGIwNgYIKwYBBQUHMAKGKmh0dHA6Ly9jZXJ0cy5laWQuYmVsZ2l1bS5iZS9iZWxnaXVtcnMzLmNydDAoBggrBgEFBQcwAYYcaHR0cDovL29jc3AuZWlkLmJlbGdpdW0uYmUvMjCCARgGA1UdIASCAQ8wggELMIIBBwYHYDgKAQECATCB+zAsBggrBgEFBQcCARYgaHR0cDovL3JlcG9zaXRvcnkuZWlkLmJlbGdpdW0uYmUwgcoGCCsGAQUFBwICMIG9GoG6R2VicnVpayBvbmRlcndvcnBlbiBhYW4gYWFuc3ByYWtlbGlqa2hlaWRzYmVwZXJraW5nZW4sIHppZSBDUFMgLSBVc2FnZSBzb3VtaXMgw6AgZGVzIGxpbWl0YXRpb25zIGRlIHJlc3BvbnNhYmlsaXTDqSwgdm9pciBDUFMgLSBWZXJ3ZW5kdW5nIHVudGVybGllZ3QgSGFmdHVuZ3NiZXNjaHLDpG5rdW5nZW4sIGdlbcOkc3MgQ1BTMDkGA1UdHwQyMDAwLqAsoCqGKGh0dHA6Ly9jcmwuZWlkLmJlbGdpdW0uYmUvZWlkYzIwMTUwOC5jcmwwDgYDVR0PAQH/BAQDAgZAMBEGCWCGSAGG+EIBAQQEAwIFIDAiBggrBgEFBQcBAwQWMBQwCAYGBACORgEBMAgGBgQAjkYBBDANBgkqhkiG9w0BAQUFAAOCAgEAJ9OdfZ1C/G+mWS/MaTIK80oGEjapyYgZnXxJ5sFuUGv4oKev2Tq9FwzeKTpo+ufb6chMSWDguX+HkkwBlCj8Dt3ND4FFDzAsgoGnorKuWkO54Pa8KpXEb7OjsWvMnJhz2iG/rEnm7b2QjN/jxbS7ZzCJhW6mXuQ1K9FUnO6VzBV59N3KdoIUEEXZlPMVYhlQEJPG3PsmMXUwcQthDQgRpgbyiPPtzUJdS86dZu0eRds2xjAAzl7EVnHvSVcBFwaikB9YuECb7NfjD9yU+WshStCjvZb1aW9qGQXb5RrWP2kdKe6VMKsQh9dwpXPZ0cFABK9IJxAJB0vhV0JKD9FtcCJ4GA8oxX5Ul57oHGeFBVazT+OKaaNwNM/1zpowv6QwYowX4Y9NZJ/CYRkMNeNwCuB88mvDvIZY/a/IZTzVwqX2KuGZeFTJInN8esUu1uROd3jRkguSs93R/6Ch8xOS6uyeNY7IyrlW9IbSJ6Sza9viZRN8FhQARNa0sLPwXeX2zHUQ1xLSU2+E0E7ruBtMT0o5jTbViDmrmSb0PPmbSRnBlLsjf8PcgKkRzrGUDWfhoGnqu4dJs3uipwsPPVaoInZ26DIPgEDlneLmYi9Kt3T+yxG57lOq8E9Ip6HzBeiTXKGB+C5o484w32E97mtnP6dvMLL7VsoyegfJhO/3/lU=</X509Certificate>
                        </DigitalId>
                    </ServiceDigitalIdentity>
                </ServiceDigitalIdentities>
                <TSLLocation>https://ec.europa.eu/information_society/policy/esignature/trusted-list/tl-mp.xml</TSLLocation>
                <AdditionalInformation>
                    <OtherInformation>
                        <TSLType>http://uri.etsi.org/TrstSvc/TrustedList/TSLType/EUlistofthelists</TSLType>
                    </OtherInformation>
                    <OtherInformation>
                        <SchemeTerritory>EU</SchemeTerritory>
                    </OtherInformation>
                    <OtherInformation>
                        <ns3:MimeType>application/vnd.etsi.tsl+xml</ns3:MimeType>
                    </OtherInformation>
                    <OtherInformation>
                        <SchemeOperatorName>
                            <Name xml:lang="en">European Commission</Name>
                        </SchemeOperatorName>
                    </OtherInformation>
                    <OtherInformation>
                        <SchemeTypeCommunityRules>
                            <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/schemerules/EUlistofthelists</URI>
                        </SchemeTypeCommunityRules>
                    </OtherInformation>
                </AdditionalInformation>
            </OtherTSLPointer>
        </PointersToOtherTSL>
        <ListIssueDateTime>2018-11-09T13:00:00Z</ListIssueDateTime>
        <NextUpdate>
            <dateTime>2019-05-09T12:00:00Z</dateTime>
        </NextUpdate>
        <DistributionPoints>
            <URI>https://sr.riik.ee/tsl/estonian-tsl.xml</URI>
        </DistributionPoints>
    </SchemeInformation>
    <TrustServiceProviderList>
        <TrustServiceProvider>
            <TSPInformation>
                <TSPName>
                    <Name xml:lang="en">SK ID Solutions AS</Name>
                </TSPName>
                <TSPTradeName>
                    <Name xml:lang="en">VATEE-100687640</Name>
                    <Name xml:lang="en">SK ID Solutions AS</Name>
                    <Name xml:lang="en">AS Sertifitseerimiskeskus</Name>
                    <Name xml:lang="en">ESTEID</Name>
                    <Name xml:lang="en">SK</Name>
                </TSPTradeName>
                <TSPAddress>
                    <PostalAddresses>
                        <PostalAddress xml:lang="en">
                            <StreetAddress>Pärnu mnt 141</StreetAddress>
                            <Locality>Tallinn</Locality>
                            <PostalCode>11314</PostalCode>
                            <CountryName>EE</CountryName>
                        </PostalAddress>
                    </PostalAddresses>
                    <ElectronicAddress>
                        <URI xml:lang="en">mailto:info@sk.ee</URI>
                        <URI xml:lang="en">https://www.sk.ee/en</URI>
                    </ElectronicAddress>
                </TSPAddress>
                <TSPInformationURI>
                    <URI xml:lang="en">https://www.sk.ee/en/repository/</URI>
                    <URI xml:lang="et">https://www.sk.ee/repositoorium/</URI>
                </TSPInformationURI>
            </TSPInformation>
            <TSPServices>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID-SK</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIFAjCCA+qgAwIBAgIEPERcgjANBgkqhkiG9w0BAQUFADBdMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMRAwDgYDVQQDEwdKdXVyLVNLMB4XDTAyMDExNTE2NDQ1MFoXDTEyMDExMzE2NDQ1MFowfDEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEPMA0GA1UECxMGRVNURUlEMQowCAYDVQQEEwExMRIwEAYDVQQDEwlFU1RFSUQtU0swggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCLeZO5NVo3zbwA8eFVCrrbeZQKvPDB7LUDPvzCqw7U2sC+IwEOdjjpJRF4lxFs+f8yC1bP+rqtWzrKhhJ2owfSAlIZMbly/OFjfLqOcyyi7qdfA/66u+69u/DY9tW5fqW93D73v5WNcNoIemCTydh9IFkQvMihWKH7LblBzCHa4W6qUcBZ7QsBgYpQS9n9fGJt5D2wCDeq0pF1Zy72G3CQFrpuR/aPG28tv9r+C7oqncapbiJ7xIOa77Fm3o07M/9aarq/m1oHEp9CxYiH9nmD3kyMe8yxw5v02MTMmAcxOm83z5O4oXSDTALG5gDfZNPjJaNPno7J8FuGrI3vV8z3AgMBAAGjggGpMIIBpTAMBgNVHRMEBTADAQH/MA4GA1UdDwEB/wQEAwIB5jCCARYGA1UdIASCAQ0wggEJMIIBBQYKKwYBBAHOHwEBATCB9jCB0AYIKwYBBQUHAgIwgcMegcAAUwBlAGUAIABzAGUAcgB0AGkAZgBpAGsAYQBhAHQAIABvAG4AIAB2AOQAbABqAGEAcwB0AGEAdAB1AGQAIABBAFMALQBpAHMAIABTAGUAcgB0AGkAZgBpAHQAcwBlAGUAcgBpAG0AaQBzAGsAZQBzAGsAdQBzACAAYQBsAGEAbQAtAFMASwAgAHMAZQByAHQAaQBmAGkAawBhAGEAdABpAGQAZQAgAGsAaQBuAG4AaQB0AGEAbQBpAHMAZQBrAHMwIQYIKwYBBQUHAgEWFWh0dHA6Ly93d3cuc2suZWUvY3BzLzArBgNVHR8EJDAiMCCgHqAchhpodHRwOi8vd3d3LnNrLmVlL2p1dXIvY3JsLzAfBgNVHSMEGDAWgBQEqnpHo+SJrxrPCkCnGD9v7+l9vjAdBgNVHQ4EFgQUeBe1BfmzWM1ZjN5nXkQGTHWGaV0wDQYJKoZIhvcNAQEFBQADggEBAFIsMHaq4Ffkrxmzw38rHYh5Ia5JGxjtWfPpag9pBtQNZHzY8j97xfPI15haE9Ah3u1WC+bsU2SndVSUGaZ0gKafMxDOy2DUw3B84ymbNRiAFSWty+aKrMCjtdlPktbSQmxNSJAX9vVtM4Y2ory+dtAQ7g11GKHJ+l8BDUpOJA+l8hvS2l4K5whWDHCSqlplMiHPIKgBVArFRNzAq6dquMY+kS3e2PL+PM4GdDW5lRHR/6KUy0BHP2gX/BO4mYQ3BH2BHImUclNras0HISnV/pt6hIkgd1PsFt3rtEolAWP4DWBmc4zAYQJ5t0cEwFM329zCXSGIQIm3a1cMugF5Q/k=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=ESTEID-SK, SURNAME=1, OU=ESTEID, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2017-06-30T22:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=ESTEID-SK, SURNAME=1, OU=ESTEID, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>eBe1BfmzWM1ZjN5nXkQGTHWGaV0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK: Qualified certificates for Estonian ID-card</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=ESTEID-SK, SURNAME=1, OU=ESTEID, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>eBe1BfmzWM1ZjN5nXkQGTHWGaV0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2002-01-15T17:44:50Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description> This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an SSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID-SK 2007</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIID0zCCArugAwIBAgIERZugDTANBgkqhkiG9w0BAQUFADBdMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMRAwDgYDVQQDEwdKdXVyLVNLMB4XDTA3MDEwMzEyMjIzN1oXDTE2MDgyNjE0MjMwMVowWzELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxDzANBgNVBAsTBkVTVEVJRDEXMBUGA1UEAxMORVNURUlELVNLIDIwMDcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDtWp2jLCsA7K9AxoPDOL0geM1GoR0Q6wSUICCJYyFkUMboEMxpSzFB6tlb0ySlHEU6Fs+tjA4QrSqwaw0uNk4BXv1lkoOr6DUc+20+AQd5jB6A0atrltZ1XG5IvDEep3DJPykkk2MPxUz7dZx7XUEr/kdUWI9cDIkFWic7y9oTBY9JaV6lxm08kweZ/qTw5PU8/bTvZCE0ygvBXU4TDS2FpUJ/+jTzM2ocWa3QjFQv2Sir6LBvgNY3du/m+WLABq0dgN18R4nhFtmaVepqAeUuEi8eRBl6yLTSmMwYCY46LsK5CdjTCZSZv934FtNuyY6Ph9nCXJAgNAY+GfNJfdMXAgMBAAGjgZwwgZkwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAf4wMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL3d3dy5zay5lZS9jcmxzL2p1dXIvY3JsLmNybDAfBgNVHSMEGDAWgBQEqnpHo+SJrxrPCkCnGD9v7+l9vjAdBgNVHQ4EFgQUSAbevoyHV5WAeGP6nCMrK6A6GHUwDQYJKoZIhvcNAQEFBQADggEBACO6SJrjN5WZuiLSMy/tSmT/w3dd/KPErSAdUIJYkC7hOIauW7jZ3VNgNUMHSIkUoP8AviEMjGA4lkT61YScpJAdmgl8Y80HFdZV5CsThhddoIdZ3cZjSI4NZmTVkSduTjoySALxKL3ZEIPrepQDvNEeV1WSpI5+u/vMekUWJSPc8BK9O2av1e9ResKyPJidqrIksHFjNS+Yt8Ouw7F10MHaPPzMiwoa0DYTVsIKJncPTQmvdJG8M0DDToiiNPQuUy5d1CA75Wtjs+yILGZXpOfbdoQhE7G4pbZaF1s69jKp+zc0ZT4g2OoKfI2TiIX9qeGJMxkOENcd1DDqYVfePmo=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=ESTEID-SK 2007, OU=ESTEID, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2017-06-30T22:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2007</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=ESTEID-SK 2007, OU=ESTEID, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>SAbevoyHV5WAeGP6nCMrK6A6GHU=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2007: Qualified certificates for Estonian ID-card, the residence permit card, the digital identity card, the digital identity card in form of the Mobile-ID</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=ESTEID-SK 2007, OU=ESTEID, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>SAbevoyHV5WAeGP6nCMrK6A6GHU=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2007-01-03T13:22:37Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description> This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an SSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID qualified certificates for electronic signatures (ESTEID-SK 2011)</Name>
                            <Name xml:lang="et">ESTEID kvalifitseeritud e-allkirjastamise sertifikaatide väljastamise teenus (ESTEID-SK 2011)</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIFBTCCA+2gAwIBAgIQKVKTqv2MxtRNgzCjwmRRDTANBgkqhkiG9w0BAQUFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMB4XDTExMDMxODEwMTQ1OVoXDTI0MDMxODEwMTQ1OVowZDELMAkGA1UEBhMCRUUxIjAgBgNVBAoMGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxFzAVBgNVBAMMDkVTVEVJRC1TSyAyMDExMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCz6XxsZh6r/aXcNe3kSpNMOqmQoAXUpzzcr4ZSaGZh/7JHIiplvNi6tbW/lK7sAiRsb65KzMWROEauld66ggbDPga6kU97C+AXGu7+DROXstjUOv6VlrHZVAnLmIOkycpWaxjM+EfQPZuDxEbkw96B3/fG69Zbp3s9y6WEhwU5Y9IiQl8YTkGnNUxidQbON1BGQm+HVEsgTf22J6r6G3FsE07rnMNskNC3DjuLSCUKF4kH0rVGVK9BdiCdFaZjHEykjwjIGzqnyxyRKe4YbJ6B9ABm95eSFgMBHtZEYU+q0VUIQGhAGAurOTXjWi1TssA42mnLGQZEI5GXMXtabp51AgMBAAGjggGgMIIBnDASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBBjCB9gYDVR0gBIHuMIHrMIHoBgsrBgEEAc4fZAEBATCB2DCBsgYIKwYBBQUHAgIwgaUegaIASwBhAHMAdQB0AGEAdABhAGsAcwBlACAAaQBzAGkAawB1AHQAdAD1AGUAbgBkAGEAdgBhAGwAZQAgAGQAbwBrAHUAbQBlAG4AZABpAGwAZQAgAGsAYQBuAHQAYQB2AGEAdABlACAAcwBlAHIAdABpAGYAaQBrAGEAYQB0AGkAZABlACAAdgDkAGwAagBhAHMAdABhAG0AaQBzAGUAawBzAC4wIQYIKwYBBQUHAgEWFWh0dHBzOi8vd3d3LnNrLmVlL0NQUzAdBgNVHQ4EFgQUe2ryVVBcuNl6CIdBrvqiKz1bV3YwHwYDVR0jBBgwFoAUEvJaPupWHL/NBqzx8SXJqUvUFJkwPQYDVR0fBDYwNDAyoDCgLoYsaHR0cDovL3d3dy5zay5lZS9yZXBvc2l0b3J5L2NybHMvZWVjY3JjYS5jcmwwDQYJKoZIhvcNAQEFBQADggEBAKC4IN3FC2gVDIH05TNMgFrQOCGSnXhzoJclRLoQ81BCOXTZI4qn7N74FHEnrAy6uNG7SS5qANqSaPIL8dp63jg/L4qn4iWaB5q5GGJOV07SnTHS7gUrqChGClnUeHxiZbL13PkP37Lnc+TKl1SKfgtn5FbH5cqrhvbA/VF3Yzlimu+L7EVohW9HKxZ//z8kDn6ieiPFfZdTOov/0eXVLlxqklybUuS6LYRRDiqQupgBKQBTwNbC8x0UHX00HokW+dCVcQvsUbv4xLhRq/MvyTthE+RdbkrV0JuzbfZvADfj75nA3+ZAzFYS5ZpMOjZ9p4rQVKpzQTklrF0m6mkdcEo=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2011, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2018-11-02T14:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.1</ns4:Identifier>
                    <ns4:Description>Certificate Policy for ID card and Digi-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.3</ns4:Identifier>
                    <ns4:Description>Certificate Policy for the digital identity card in form of the Mobile-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.1</ns4:Identifier>
                    <ns4:Description>Certificate Policy for ID card and Digi-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.3</ns4:Identifier>
                    <ns4:Description>Certificate Policy for the digital identity card in form of the Mobile-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2011 qualified certificates for electronic signatures</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2011, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>e2ryVVBcuNl6CIdBrvqiKz1bV3Y=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2011: Qualified certificates for Estonian ID-card, the residence permit card, the digital identity card, the digital identity card in form of the Mobile-ID</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2011, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>e2ryVVBcuNl6CIdBrvqiKz1bV3Y=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2011-03-18T11:14:59Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description> This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an SSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID qualified certificates for electronic signatures (ESTEID-SK 2015)</Name>
                            <Name xml:lang="et">ESTEID kvalifitseeritud e-allkirjastamise sertifikaatide väljastamise teenus (ESTEID-SK 2015)</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIGcDCCBVigAwIBAgIQRUgJC4ec7yFWcqzT3mwbWzANBgkqhkiG9w0BAQwFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMCAXDTE1MTIxNzEyMzg0M1oYDzIwMzAxMjE3MjM1OTU5WjBjMQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEXMBUGA1UEYQwOTlRSRUUtMTA3NDcwMTMxFzAVBgNVBAMMDkVTVEVJRC1TSyAyMDE1MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA0oH61NDxbdW9k8nLA1qGaL4B7vydod2Ewp/STBZB3wEtIJCLdkpEsS8pXfFiRqwDVsgGGbu+Q99trlb5LI7yi7rIkRov5NftBdSNPSU5rAhYPQhvZZQgOwRaHa5Ey+BaLJHmLqYQS9hQvQsCYyws+xVvNFUpK0pGD64iycqdMuBl/nWq3fLuZppwBh0VFltm4nhr/1S0R9TRJpqFUGbGr4OK/DwebQ5PjhdS40gCUNwmC7fPQ4vIH+x+TCk2aG+u3MoAz0IrpVWqiwzG/vxreuPPAkgXeFCeYf6fXLsGz4WivsZFbph2pMjELu6sltlBXfAG3fGv43t91VXicyzR/eT5dsB+zFsW1sHV+1ONPr+qzgDxCH2cmuqoZNfIIq+buob3eA8ee+XpJKJQr+1qGrmhggjvAhc7m6cU4x/QfxwRYhIVNhJf+sKVThkQhbJ9XxuKk3c18wymwL1mpDD0PIGJqlssMeiuJ4IzagFbgESGNDUd4icm0hQT8CmQeUm1GbWeBYseqPhMQX97QFBLXJLVy2SCyoAz7Bq1qA43++EcibN+yBc1nQs2Zoq8ck9MK0bCxDMeUkQUz6VeQGp69ImOQrsw46qTz0mtdQrMSbnkXCuLan5dPm284J9HmaqiYi6j6KLcZ2NkUnDQFesBVlMEm+fHa2iR6lnAFYZ06UECAwEAAaOCAgowggIGMB8GA1UdIwQYMBaAFBLyWj7qVhy/zQas8fElyalL1BSZMB0GA1UdDgQWBBSzq4i8mdVipIUqCM20HXI7g3JHUTAOBgNVHQ8BAf8EBAMCAQYwdwYDVR0gBHAwbjAIBgYEAI96AQIwCQYHBACL7EABAjAwBgkrBgEEAc4fAQEwIzAhBggrBgEFBQcCARYVaHR0cHM6Ly93d3cuc2suZWUvQ1BTMAsGCSsGAQQBzh8BAjALBgkrBgEEAc4fAQMwCwYJKwYBBAHOHwEEMBIGA1UdEwEB/wQIMAYBAf8CAQAwQQYDVR0eBDowOKE2MASCAiIiMAqHCAAAAAAAAAAAMCKHIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMCcGA1UdJQQgMB4GCCsGAQUFBwMJBggrBgEFBQcDAgYIKwYBBQUHAwQwfAYIKwYBBQUHAQEEcDBuMCAGCCsGAQUFBzABhhRodHRwOi8vb2NzcC5zay5lZS9DQTBKBggrBgEFBQcwAoY+aHR0cDovL3d3dy5zay5lZS9jZXJ0cy9FRV9DZXJ0aWZpY2F0aW9uX0NlbnRyZV9Sb290X0NBLmRlci5jcnQwPQYDVR0fBDYwNDAyoDCgLoYsaHR0cDovL3d3dy5zay5lZS9yZXBvc2l0b3J5L2NybHMvZWVjY3JjYS5jcmwwDQYJKoZIhvcNAQEMBQADggEBAHRWDGI3P00r2sOnlvLHKk9eE7X93eT+4e5TeaQsOpE5zQRUTtshxN8Bnx2ToQ9rgi18q+MwXm2f0mrGakYYG0bix7ZgDQvCMD/kuRYmwLGdfsTXwh8KuL6uSHF+U/ZTss6qG7mxCHG9YvebkN5Yj/rYRvZ9/uJ9rieByxw4wo7b19p22PXkAkXP5y3+qK/Oet98lqwI97kJhiS2zxFYRk+dXbazmoVHnozYKmsZaSUvoYNNH19tpS7BLdsgi9KpbvQLb5ywIMq9ut3+b2Xvzq8yzmHMFtLIJ6Afu1jJpqD82BUAFcvi5vhnP8M7b974R18WCOpgNQvXDI+2/8ZINeU=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=ESTEID-SK 2015, OID.2.5.4.97=NTREE-10747013, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2018-11-02T14:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.1</ns4:Identifier>
                    <ns4:Description>Certificate Policy for ID card and Digi-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.3</ns4:Identifier>
                    <ns4:Description>Certificate Policy for the digital identity card in form of the Mobile-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.1</ns4:Identifier>
                    <ns4:Description>Certificate Policy for ID card and Digi-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.1.3</ns4:Identifier>
                    <ns4:Description>Certificate Policy for the digital identity card in form of the Mobile-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2015 qualified certificates for electronic signatures</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=ESTEID-SK 2015, OID.2.5.4.97=NTREE-10747013, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>s6uIvJnVYqSFKgjNtB1yO4NyR1E=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2015: Qualified certificates for Estonian ID-card, the residence permit card, the digital identity card, the digital identity card in form of the Mobile-ID</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=ESTEID-SK 2015, OID.2.5.4.97=NTREE-10747013, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>s6uIvJnVYqSFKgjNtB1yO4NyR1E=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2015-12-17T12:38:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description> This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an SSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID qualified certificates for electronic signatures (ESTEID2018)</Name>
                            <Name xml:lang="et">ESTEID kvalifitseeritud e-allkirjastamise sertifikaatide väljastamise teenus (ESTEID2018)</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIFVzCCBLigAwIBAgIQdUf6rBR0S4tbo2bU/mZV7TAKBggqhkjOPQQDBDBaMQswCQYDVQQGEwJFRTEbMBkGA1UECgwSU0sgSUQgU29sdXRpb25zIEFTMRcwFQYDVQRhDA5OVFJFRS0xMDc0NzAxMzEVMBMGA1UEAwwMRUUtR292Q0EyMDE4MB4XDTE4MDkyMDA5MjIyOFoXDTMzMDkwNTA5MTEwM1owWDELMAkGA1UEBhMCRUUxGzAZBgNVBAoMElNLIElEIFNvbHV0aW9ucyBBUzEXMBUGA1UEYQwOTlRSRUUtMTA3NDcwMTMxEzARBgNVBAMMCkVTVEVJRDIwMTgwgZswEAYHKoZIzj0CAQYFK4EEACMDgYYABAHHOBlv7UrRPYP1yHhOb7RA/YBDbtgynSVMqYdxnFrKHUXh6tFkghvHuA1k2DSom1hE5kqhB5VspDembwWDJBOQWQGOI/0t3EtccLYjeM7F9xOPdzUbZaIbpNRHpQgVBpFX0xpLTgW27MpIMhU8DHBWFpeAaNX3eUpD4gC5cvhsK0RFEqOCAx0wggMZMB8GA1UdIwQYMBaAFH4pVuc0knhOd+FvLjMqmHHB/TSfMB0GA1UdDgQWBBTZrHDbX36+lPig5L5HotA0rZoqEjAOBgNVHQ8BAf8EBAMCAQYwEgYDVR0TAQH/BAgwBgEB/wIBADCCAc0GA1UdIASCAcQwggHAMAgGBgQAj3oBAjAJBgcEAIvsQAECMDIGCysGAQQBg5EhAQEBMCMwIQYIKwYBBQUHAgEWFWh0dHBzOi8vd3d3LnNrLmVlL0NQUzANBgsrBgEEAYORIQEBAjANBgsrBgEEAYORfwEBATANBgsrBgEEAYORIQEBBTANBgsrBgEEAYORIQEBBjANBgsrBgEEAYORIQEBBzANBgsrBgEEAYORIQEBAzANBgsrBgEEAYORIQEBBDANBgsrBgEEAYORIQEBCDANBgsrBgEEAYORIQEBCTANBgsrBgEEAYORIQEBCjANBgsrBgEEAYORIQEBCzANBgsrBgEEAYORIQEBDDANBgsrBgEEAYORIQEBDTANBgsrBgEEAYORIQEBDjANBgsrBgEEAYORIQEBDzANBgsrBgEEAYORIQEBEDANBgsrBgEEAYORIQEBETANBgsrBgEEAYORIQEBEjANBgsrBgEEAYORIQEBEzANBgsrBgEEAYORIQEBFDANBgsrBgEEAYORfwEBAjANBgsrBgEEAYORfwEBAzANBgsrBgEEAYORfwEBBDANBgsrBgEEAYORfwEBBTANBgsrBgEEAYORfwEBBjAqBgNVHSUBAf8EIDAeBggrBgEFBQcDCQYIKwYBBQUHAwIGCCsGAQUFBwMEMGoGCCsGAQUFBwEBBF4wXDApBggrBgEFBQcwAYYdaHR0cDovL2FpYS5zay5lZS9lZS1nb3ZjYTIwMTgwLwYIKwYBBQUHMAKGI2h0dHA6Ly9jLnNrLmVlL0VFLUdvdkNBMjAxOC5kZXIuY3J0MBgGCCsGAQUFBwEDBAwwCjAIBgYEAI5GAQEwMAYDVR0fBCkwJzAloCOgIYYfaHR0cDovL2Muc2suZWUvRUUtR292Q0EyMDE4LmNybDAKBggqhkjOPQQDBAOBjAAwgYgCQgDeuUY4HczUbFKS002HZ88gclgYdztHqglENyTMtXE6dMBRnCbgUmhBCAA0mJSHbyFJ8W9ikLiSyurmkJM0hDE9KgJCASOqA405Ia5nKjTJPNsHQlMi7KZsIcTHOoBccx+54N8ZX1MgBozJmT59rZY/2/OeE163BAwD0UdUQAnMPP6+W3Vd</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=ESTEID2018, OID.2.5.4.97=NTREE-10747013, O=SK ID Solutions AS, C=EE</X509SubjectName>
                            </DigitalId>
                            <DigitalId>
<X509SKI>2axw219+vpT4oOS+R6LQNK2aKhI=</X509SKI>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2018-11-02T14:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.51361.1</ns4:Identifier>
                    <ns4:Description>Certificate Policy for ID-card, Digi-ID, RP-card and Diplomatic-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://www.id.ee/?id=30500</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.51361.1</ns4:Identifier>
                    <ns4:Description>Certificate Policy for ID-card, Digi-ID, RP-card and Diplomatic-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://www.id.ee/?id=30500</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">EID-SK 2007</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIID4jCCAsqgAwIBAgIERZ4nqjANBgkqhkiG9w0BAQUFADBdMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMRAwDgYDVQQDEwdKdXVyLVNLMB4XDTA3MDEwNTEwMjU0NloXDTE2MDgyNjE0MjMwMVowajELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsTGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDEUMBIGA1UEAxMLRUlELVNLIDIwMDcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDifhEdyvuhk/3TJEGMJ1tEZOskE81yMqPGGXaPHXACJ7fncn1D1uQFt+RG8/ckh7zDquHV1m4HQk7dchaP00rvgsvRlYC9GPcFt6TW8w3t+BkxY1RNbmONgH3qzikljk7m6Nb8UGtL9hOmZdw5k5t9Ht8fgHTnoBkFrxYgsv9d4CCkBTSprNUK+vy/NTak4iAYinWtK6tRHHb1fxRsLUXiDLSO42Kz+rehhslANX+9Y5/h0wlh3pcmxLB1JWAP0O9fV6N1LUQ3Ym7wMp/lBXuPvl52yJuSZDWUF7GkIp+vUifOSefF6CeGh8K9BXDvuOqg+5c/6gkfEQxpRgdu+q5FAgMBAAGjgZwwgZkwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAf4wMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL3d3dy5zay5lZS9jcmxzL2p1dXIvY3JsLmNybDAfBgNVHSMEGDAWgBQEqnpHo+SJrxrPCkCnGD9v7+l9vjAdBgNVHQ4EFgQUHAf0nL+kJWyztJ4iHx+USBtYeo0wDQYJKoZIhvcNAQEFBQADggEBABaiEXv415Oh7AgHODwKRyNFqPcSSOgpLCy1XJB3hl3fi21fslccWuBhfzqHQCiQi0fewh109IJiHq8n1PeKoHBCUVq6NFpxkVsUlUPBr0Qsya1O3SQjuOsBLzUWBvY25dtBuAkBMCo0V1Erf7iTeOzuL4LLbCoeOfeQT3HPmEfSqP5f8V10ST8erbiTVPJwzr66vXaT9YKxy8NyAQc2iaOHuYmGKxs8dgDQRkG6b2a/f5q21YEQKDhvz7VvM6tH+F+rohA2wAvVz4tcPtyw5WEYcavr1KHgz4eZVWsqh2OsHUK9qMas5m/44O1/hXrjpMy5IQsiB4ASXDuXvdOTVbU=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=EID-SK 2007, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2017-06-30T22:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">EID-SK 2007</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=EID-SK 2007, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>HAf0nL+kJWyztJ4iHx+USBtYeo0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">EID-SK 2007: Qualified certificates for Mobile-ID</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=EID-SK 2007, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>HAf0nL+kJWyztJ4iHx+USBtYeo0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2007-01-05T11:25:46Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description> This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an SSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">EID-SK 2011 qualified certificates for electronic signatures</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIFADCCA+igAwIBAgIQQyvUTmJDa0ZNgy+/fS0vWjANBgkqhkiG9w0BAQUFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMB4XDTExMDMxODEwMTExMVoXDTI0MDMxODEwMTExMVowYTELMAkGA1UEBhMCRUUxIjAgBgNVBAoMGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxFDASBgNVBAMMC0VJRC1TSyAyMDExMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC2Q1zKMt7DytbntSLoYAAVkEwV+5djSr0vSIG/Zm9seKyx+2PY8sVzXRoUD1CMIYnstDhBSKMjn2/+HpA7pOipAIAMrk6uKnpSTTdFbQ+0fzJVPokBgsdsQ6R5TZFPB1nu5zgRRlQmWIFxOpDiNHTt0LObUhWLXzUb31vc1Wmao2IYcDx1TCs/1E9+camiCl2B5lXrPEU3wBq4waD54izS20DK05+6+hHRg+TqoIg5YSmwbjStEyd/8AQeokwVloyyH49bnpeluADcZJgxxE9ZUvVWHoxYfmg1IeRU72jHTcIjNf1cQN2+9/FtHQMnGzDBgmAPpghwWr3JtW0JWvMXAgMBAAGjggGeMIIBmjASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBBjCB9AYDVR0gBIHsMIHpMIHmBgsrBgEEAc4fZAEBATCB1jCBsAYIKwYBBQUHAgIwgaMegaAASwBhAHMAdQB0AGEAdABhAGsAcwBlACAAZgD8APwAcwBpAGwAaQBzAHQAZQBsAGUAIABpAHMAaQBrAHUAdABlAGwAZQAgAHMAZQByAHQAaQBmAGkAawBhAGEAdABpAGQAZQAgAHYA5ABsAGoAYQBzAHQAYQBtAGkAcwBlAGsAcwAgAGsAbwBtAG0AZQByAHQAcwBhAGwAdQBzAGUAbAAuMCEGCCsGAQUFBwIBFhVodHRwczovL3d3dy5zay5lZS9DUFMwHQYDVR0OBBYEFLEQlwL63YbGeEGkwzKI+/4f58AFMB8GA1UdIwQYMBaAFBLyWj7qVhy/zQas8fElyalL1BSZMD0GA1UdHwQ2MDQwMqAwoC6GLGh0dHA6Ly93d3cuc2suZWUvcmVwb3NpdG9yeS9jcmxzL2VlY2NyY2EuY3JsMA0GCSqGSIb3DQEBBQUAA4IBAQAxau3ohdFkpvaiVUR7arNovQUZRCG9Ge3udqHYemovyU7N60Hgomc/ZG+uunScATTUhBcv9a5zkQxb1dQ1LYDRfNr9CqI0QvSEE4t9Sfu3fOhyLrlmb3s8xhhYLJBJ325uDvtO/qFeXLlcRXMF5nU8FE2IyaZP1CHYKVh5QNPPQiGZGSox5oOkCvmt4lUl4lZUwVie75us/WtrD6DJeREBTEDHORIfg8E9RA1y/7t2gT9vrU8tabeSZlD03qwXe0nJ9RscI/P0HT8vuo1PGzCfbH9xFqfoZ2jdJ0HzxrFM8VsL/AtCw0dmrxRHLlZzqSw0G7b0W40mwOQauO2gbMfn</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2011, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an QSCD</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">EID-SK 2011: Qualified certificates for Mobile-ID, organisation cards for natural persons</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2011, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>sRCXAvrdhsZ4QaTDMoj7/h/nwAU=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2011-03-18T11:11:11Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="digitalSignature">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description> This service issues qualified certificates for e-signing and e-authentication within the same process. The Relying Party shall make distinction by inspection of keyUsage field contents - e-signature certificates have nonRepudation bit set exclusively. Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) and that has either its nR or its dS bit set is to be considered as supported by an SSCD</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">EID-SK 2016 qualified certificates for electronic signatures</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIG4jCCBcqgAwIBAgIQO4A6a2nBKoxXxVAFMRvE2jANBgkqhkiG9w0BAQwFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMCAXDTE2MDgzMDA5MjEwOVoYDzIwMzAxMjE3MjM1OTU5WjBgMQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEXMBUGA1UEYQwOTlRSRUUtMTA3NDcwMTMxFDASBgNVBAMMC0VJRC1TSyAyMDE2MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAr7XWFN0j1CFoGIuVe9xRezEnA0Tk3vmvIpvURX+y7Z5DJsfub2mtpSLtbhXjAeynq9QV78zjgQ73pNVGh+GQ6oPG7HF8KIlZuIYsf1+gBxPxNiLa0+sCWxa6p4HQbgdgYRVGod4IQbib9KbOki3wjCG5WiWh1SP9qcuTZVY+9zawkSMf65Px/Y4ChjtNFtY66MEvsPChlHHfsBNiUbtZ68jJNYCECjtkm0vxz2iiSXB2WRIv3/hTrRgMJ2CNMyFjRQoGQlpH010+fcisObKeyPwA8kI22Oto9MzLw7KsY524OD3B1L5MExYxHD916XIEHT/9gBP2Zn8qZu/BllKdSIapOIJW9ZEw+3w5UOU6LT3tTSbAzeQAnD3eCABPifYwHYC0lmKsPpQJqtx0Q3Jbm3BGReYiZ9KuK36nF/G78YjhM+yioERr2B/cKf31j0W/GuGvyHakbokwy7nsbL30sTuRLR70Oqi5UBMy4e8J2CduR3R3NJw5UqpScJIchngsLAx+WsyC0w38AmMewMBcnlp/QbakKo52HrsYRR1m+NhCVDBy45Lzl8I0/OGd9Ikdg1h7T7SIguZVpyzys8E0yfrcS5YMEd9hMqVPr7rszXCzbxyw0tVIk8QLMw/lI+XE1Oi7SkgzA2i5Vpa6i2K0ard6GPHzRqGPTkjc5Z4DzZMCAwEAAaOCAn8wggJ7MB8GA1UdIwQYMBaAFBLyWj7qVhy/zQas8fElyalL1BSZMB0GA1UdDgQWBBScCagHhww9rC6H/KCu0vtlSYgo+zAOBgNVHQ8BAf8EBAMCAQYwgcQGA1UdIASBvDCBuTA8BgcEAIvsQAECMDEwLwYIKwYBBQUHAgEWI2h0dHBzOi8vd3d3LnNrLmVlL3JlcG9zaXRvb3JpdW0vQ1BTMDwGBwQAi+xAAQAwMTAvBggrBgEFBQcCARYjaHR0cHM6Ly93d3cuc2suZWUvcmVwb3NpdG9vcml1bS9DUFMwOwYGBACPegECMDEwLwYIKwYBBQUHAgEWI2h0dHBzOi8vd3d3LnNrLmVlL3JlcG9zaXRvb3JpdW0vQ1BTMBIGA1UdEwEB/wQIMAYBAf8CAQAwJwYDVR0lBCAwHgYIKwYBBQUHAwkGCCsGAQUFBwMCBggrBgEFBQcDBDB8BggrBgEFBQcBAQRwMG4wIAYIKwYBBQUHMAGGFGh0dHA6Ly9vY3NwLnNrLmVlL0NBMEoGCCsGAQUFBzAChj5odHRwOi8vd3d3LnNrLmVlL2NlcnRzL0VFX0NlcnRpZmljYXRpb25fQ2VudHJlX1Jvb3RfQ0EuZGVyLmNydDBBBgNVHR4EOjA4oTYwBIICIiIwCocIAAAAAAAAAAAwIocgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwJQYIKwYBBQUHAQMEGTAXMBUGCCsGAQUFBwsCMAkGBwQAi+xJAQEwPQYDVR0fBDYwNDAyoDCgLoYsaHR0cDovL3d3dy5zay5lZS9yZXBvc2l0b3J5L2NybHMvZWVjY3JjYS5jcmwwDQYJKoZIhvcNAQEMBQADggEBAKSIoud5DSfhDU6yp+VrXYL40wi5zFTf19ha/kO/zzLxZ1hf45VJmSyukMWaWXEqhaLWBZuw5kP78mQ0HyaRUennN0hom/pEiBz6cuz9oc+xlmPAZM25ZoaLqa4upP2/+NCWoRTzYkIdc9MEECs5RMBUmyT1G4s8J6n8L2M2yYadBMvPGJS3yXxYdc/b3a2foiw3kKa/q1tXAHXZCsuxFVYxXdZt3AwInYHemCVKjZg8BaRpvIEXd3AgJwt+9bpV/x0/MouRPNRv0jjWIx1sAlL94hO74WZDMFbZVaV6gpG77X2P3dPHKFIRWzjtSQJX4C5n1uvQBxO4ABoMswq0lq0=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=EID-SK 2016, OID.2.5.4.97=NTREE-10747013, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                            <DigitalId>
<X509SKI>nAmoB4cMPawuh/ygrtL7ZUmIKPs=</X509SKI>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2016-12-21T10:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>1.3.6.1.4.1.10015.17.2</ns4:Identifier>
                    <ns4:Description>Certificate Policy for Qualified Smart-ID</ns4:Description>
                    <ns4:DocumentationReferences>
                        <ns4:DocumentationReference>https://sk.ee/en/repository/CP/</ns4:DocumentationReference>
                    </ns4:DocumentationReferences>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">KLASS3-SK</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIEBDCCAuygAwIBAgIEPNkU9TANBgkqhkiG9w0BAQUFADBdMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMRAwDgYDVQQDEwdKdXVyLVNLMB4XDTAyMDUwODEyMDcxN1oXDTEyMDUwNTExMDcxN1owgY4xGDAWBgkqhkiG9w0BCQEWCXBraUBzay5lZTELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsTGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDEKMAgGA1UEBRMBMTESMBAGA1UEAxMJS0xBU1MzLVNLMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvIIeK3GJxoPCXVwan+HjJwYGaH3nb/rTPEqg5v9e1c7dnTDBdD2Yteg+lUdHBZDHLj1Tz+J/W9Foc0dzEr96S8+6nMXoonK2x0854JNH2UVbS/+YOGUM6iWSxkHw525tvn5tFaIQoaeh46aQFp9Dngcnv4Gatd0/7NCkLggjFrKmnNTPINpLAG9VoCpVyIMvcVCyTNvSQ+n33ToPO5vtULNYOtCF9MDVND+uNRE2o0tWIG0l84owYPA47tJOLgCpAxLNFR5Ys0nB/ofBYcO+YiCri0yc6t7ZPs/vcfbR6czIwW0GMjyHmVPLB+/WHS3P1sk29DdgIC42RTMthJS6ZQIDAQABo4GZMIGWMA8GA1UdEwQIMAYBAf8CAQAwDgYDVR0PAQH/BAQDAgHmMDMGA1UdHwQsMCowKKAmoCSGImh0dHA6Ly93d3cuc2suZWUvY3Jscy9qdXVyL2NybC5jcmwwHwYDVR0jBBgwFoAUBKp6R6Pkia8azwpApxg/b+/pfb4wHQYDVR0OBBYEFOU/DJ1xPW+8Gb+a9G6/Cf5A652WMA0GCSqGSIb3DQEBBQUAA4IBAQASvWB+YrgN23EMLW7C5/XUwQLNN1RMDhr6UzOo5XHZ3pxUXq2Erk5ggiS+UJIxkQaSg4OHRru8KTchoJDvS2neeYHOz05zJcAIwoy2GGkHq1iVN+QZaprDaDNYR5GGKgJb3FZrMtyX4dNwnrZzMFzd6t5YibCW+BDPAmqGJvNHzJ5YYdA7I3WT9Baan1ncKd4FtUVb54fppd19NkbCKKSUd7qRYDduNYqVs1C/C0qqLq4TrxoxoxSo+WNLiD01896sIRiPIy8qDOAXJU67382J5XXETe9wZO6o7+NaG0CrpzVY1OaaD2O6Wv/vSpxE2ugqaf0WsP35+coFCWdM2uHZ</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=KLASS3-SK, SERIALNUMBER=1, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:01Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>Any certificate that is issued under the CA/QC Sdi certificate and that is issued as a QC (i.e. containing a QcCompliance statement) and having its non-repudation bit set exclusively, is to be considered as  supported by an SSCD. They are issued for digital stamping according to Estonian Digital Signature Act</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/NotQualified"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">false</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) is to be considered as issued to a Legal Person</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=KLASS3-SK, SERIALNUMBER=1, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>5T8MnXE9b7wZv5r0br8J/kDrnZY=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate that is issued under the CA/QC Sdi certificate and that is issued as a QC (i.e. containing a QcCompliance statement) and having its non-repudation bit set exclusively, is to be considered as  supported by an SSCD. They are issued for digital stamping according to Estonian Digital Signature Act</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/NotQualified"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">false</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) is to be considered as issued to a Legal Person</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK: Qualified electronic seals</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=KLASS3-SK, SERIALNUMBER=1, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>5T8MnXE9b7wZv5r0br8J/kDrnZY=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2002-05-08T12:07:17Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForLegalPerson"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">false</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) is to be considered as issued to a Legal Person</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate that is issued under the CA/QC Sdi certificate and that is issued as a QC (i.e. containing a QcCompliance statement) and having its non-repudation bit set exclusively, is to be considered as  supported by an SSCD. They are issued for digital stamping according to Estonian Digital Signature Act</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">Klass3-SK 2010 qualified certificate for electronic seal</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIID5TCCAs2gAwIBAgIES7MTKDANBgkqhkiG9w0BAQUFADBdMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMRAwDgYDVQQDEwdKdXVyLVNLMB4XDTEwMDMzMTA5MTcyOFoXDTE2MDgyNjE0MjMwMVowbTELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsTGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDEXMBUGA1UEAxMOS0xBU1MzLVNLIDIwMTAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrlaYRX2v89k8Hd0ADaOfnUcIn7iM6aOXkAR+jp5827ZhDqDyNddF9ZUoBgPghGNIrkHbH7qwex39YnI0ka24lCjcwEMvQMPbyPnX/a4RyJ+wEZttmjBl++FfrZK54L+vD7Dyy4YYB0Og9ktB4qptsDBj+giiv/MGPeGeNs3TacJdNb7+3splTPtPKlDfrufvq4H6jNOv9S9bC+j2VVY9uCFXUro8AA3hoOEKJdSjlpYCa51N8KGLVJYRuc/K81xqi054Jz+Cy/HY/AcXkk2JkxlpJoEXmcuTkxjO/QE/Xbd+mRJHnq6+HurOiKcxKwZCPAa+d+dvRPkbyq9ohMXH9AgMBAAGjgZwwgZkwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAcYwMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL3d3dy5zay5lZS9jcmxzL2p1dXIvY3JsLmNybDAfBgNVHSMEGDAWgBQEqnpHo+SJrxrPCkCnGD9v7+l9vjAdBgNVHQ4EFgQUXXUUEYz0pY5Cj3uyQESj7tZ6O3IwDQYJKoZIhvcNAQEFBQADggEBADFuAGtSoO8PsWRw/QxFzc5EZtbq2KXC9yZ8YQPWBLY4Mh3OVLFJqWyKC+8JHy9D5tJTG49F5UHyDJPufD/XvC2rjRlkqvS/W7sy3MqGh7e+6bg+aD4mo+98Oalnqi12UD+ki+N8JKPXjHNJ31AvH6E/xDsCsvtzubylxI+FU8R0XODIUFbBqRtatRI1/zVaKRhD6LNGPt3rz/3IJKmuEv6b29mzL+p4oNULqpPr6aTmheZme8ZHuEIh3Zp5kdoX3i2D4hsmgClpevZifo196zeKRLk0Qs6nmRjoMxyk6jYIric3/VnV81oyhXSBY1GZnbM4qP1w2S5kSA2bb1pkwFo=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509Certificate>MIIErDCCA5SgAwIBAgIQAznVp1LayatNgy6bN8f9QjANBgkqhkiG9w0BAQUFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMB4XDTExMDMxODEwMDYxOFoXDTI0MDMxODEwMDYxOFowbTELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsTGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDEXMBUGA1UEAxMOS0xBU1MzLVNLIDIwMTAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrlaYRX2v89k8Hd0ADaOfnUcIn7iM6aOXkAR+jp5827ZhDqDyNddF9ZUoBgPghGNIrkHbH7qwex39YnI0ka24lCjcwEMvQMPbyPnX/a4RyJ+wEZttmjBl++FfrZK54L+vD7Dyy4YYB0Og9ktB4qptsDBj+giiv/MGPeGeNs3TacJdNb7+3splTPtPKlDfrufvq4H6jNOv9S9bC+j2VVY9uCFXUro8AA3hoOEKJdSjlpYCa51N8KGLVJYRuc/K81xqi054Jz+Cy/HY/AcXkk2JkxlpJoEXmcuTkxjO/QE/Xbd+mRJHnq6+HurOiKcxKwZCPAa+d+dvRPkbyq9ohMXH9AgMBAAGjggE+MIIBOjASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBxjCBlAYDVR0gBIGMMIGJMIGGBgsrBgEEAc4fZAEBATB3MCEGCCsGAQUFBwIBFhVodHRwczovL3d3dy5zay5lZS9jcHMwUgYIKwYBBQUHAgIwRh5EAEEAcwB1AHQAdQBzAGUAIABzAGUAcgB0AGkAZgBpAGsAYQBhAHQALgAgAEMAbwByAHAAbwByAGEAdABlACAASQBEAC4wHQYDVR0OBBYEFF11FBGM9KWOQo97skBEo+7WejtyMB8GA1UdIwQYMBaAFBLyWj7qVhy/zQas8fElyalL1BSZMD0GA1UdHwQ2MDQwMqAwoC6GLGh0dHA6Ly93d3cuc2suZWUvcmVwb3NpdG9yeS9jcmxzL2VlY2NyY2EuY3JsMA0GCSqGSIb3DQEBBQUAA4IBAQC3qNBgY2I9Wqm4LZYKAjCYkc2Nltm1RS9frMvQJ4aEE4Y4TtW2LPcQp2lenOf9aYdEB8G/E9CytZSPlFuvDdsdknj6fg1XCeu6ITR2wIkxJeAeLQvrFEfb1mcAa5tU9RNalZhYc7MFMFQTjQP+GBNxz+KIjNDVASFdv7TCe7GBjsW8Dfes9lQGHaWsBRkHCyuPGIHfH+cmMuhLtWqa4Qlg4f54kcsGO7s4buKtk6XqEj8Cj2ITdfk/aUs9QoxxkYWGwSUlCueTamzufXEJo9yz5Jp6IFdGjotmjb/EBUCf2sFfI83a4Cm1D3L3/KYb5g3cYlDEpPWNqbNuA1XosIqK</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509Certificate>MIIFKjCCBBKgAwIBAgIQChm34x8ah3BVcFedls2c2jANBgkqhkiG9w0BAQwFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMB4XDTE1MDYwNDEzNTAyMVoXDTI0MDMxNzIyMDAwMFowbTELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsTGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDEXMBUGA1UEAxMOS0xBU1MzLVNLIDIwMTAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrlaYRX2v89k8Hd0ADaOfnUcIn7iM6aOXkAR+jp5827ZhDqDyNddF9ZUoBgPghGNIrkHbH7qwex39YnI0ka24lCjcwEMvQMPbyPnX/a4RyJ+wEZttmjBl++FfrZK54L+vD7Dyy4YYB0Og9ktB4qptsDBj+giiv/MGPeGeNs3TacJdNb7+3splTPtPKlDfrufvq4H6jNOv9S9bC+j2VVY9uCFXUro8AA3hoOEKJdSjlpYCa51N8KGLVJYRuc/K81xqi054Jz+Cy/HY/AcXkk2JkxlpJoEXmcuTkxjO/QE/Xbd+mRJHnq6+HurOiKcxKwZCPAa+d+dvRPkbyq9ohMXH9AgMBAAGjggG8MIIBuDASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBxjCBlAYDVR0gBIGMMIGJMIGGBgsrBgEEAc4fZAEBATB3MCEGCCsGAQUFBwIBFhVodHRwczovL3d3dy5zay5lZS9jcHMwUgYIKwYBBQUHAgIwRh5EAEEAcwB1AHQAdQBzAGUAIABzAGUAcgB0AGkAZgBpAGsAYQBhAHQALgAgAEMAbwByAHAAbwByAGEAdABlACAASQBEAC4wHQYDVR0OBBYEFF11FBGM9KWOQo97skBEo+7WejtyMB8GA1UdIwQYMBaAFBLyWj7qVhy/zQas8fElyalL1BSZMHwGCCsGAQUFBwEBBHAwbjAgBggrBgEFBQcwAYYUaHR0cDovL29jc3Auc2suZWUvQ0EwSgYIKwYBBQUHMAKGPmh0dHA6Ly93d3cuc2suZWUvY2VydHMvRUVfQ2VydGlmaWNhdGlvbl9DZW50cmVfUm9vdF9DQS5kZXIuY3J0MD0GA1UdHwQ2MDQwMqAwoC6GLGh0dHA6Ly93d3cuc2suZWUvcmVwb3NpdG9yeS9jcmxzL2VlY2NyY2EuY3JsMA0GCSqGSIb3DQEBDAUAA4IBAQB4/0TLXdtMTnzl8Z810lR3pESCq6ueQRvGPPl2isGe3ldA9PhKZ7j6323ifI2ldOdMeU12gd4pzuHXieFC1YhswqXCR1huLNu1KA8PRhgxdOBQ1etRSkZTIftMhBgpxot2Tu4G2xKQ7wfetdqnrUQ/u++BuAhuHA2xsma236eQ7z3izoxCOSc+FMpQT/SY9NvKtZlmFEPycxZxu0uWCQtBbx+b/MAYKgq2/vMvLO4lyRqkeSRuLMZT4AA42HgggUwL7hWiwedyEqvwq0Sg3e92F2wBff+Xah/WeZBioxul1TRtzFcge6BTfF2S0RdbaaOWeXsbNaA/azZ4WrNj1CTv</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=KLASS3-SK 2010, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>0.4.0.194112.1.3</ns4:Identifier>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>Any certificate that is issued under the CA/QC Sdi certificate and that is issued as a QC (i.e. containing a QcCompliance statement) and having its Certificate Policy PolicyIdentifier OID set as 0.4.0.194112.1.3, is to be considered as supported by a QSCD. They are issued for digital stamping according to eIDAS regulation</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForLegalPerson"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">false</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) is to be considered as issued to a Legal Person</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESeal"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description/>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK 2010</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=KLASS3-SK 2010, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>XXUUEYz0pY5Cj3uyQESj7tZ6O3I=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate that is issued under the CA/QC Sdi certificate and that is issued as a QC (i.e. containing a QcCompliance statement) and having its Certificate Policy PolicyIdentifier OID set as 0.4.0.194112.1.3, is to be considered as supported by a QSCD. They are issued for digital stamping according to eIDAS regulation</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/NotQualified"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">false</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) is to be considered as issued to a Legal Person</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK 2010: Qualified electronic seals</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=KLASS3-SK 2010, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>XXUUEYz0pY5Cj3uyQESj7tZ6O3I=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2010-03-31T09:17:28Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <ns5:Qualifications>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForLegalPerson"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="atLeastOne">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">false</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) is to be considered as issued to a Legal Person</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>Any certificate that is issued under the CA/QC Sdi certificate and that is issued as a QC (i.e. containing a QcCompliance statement) and having its non-repudation bit set exclusively, is to be considered as  supported by an SSCD. They are issued for digital stamping according to Estonian Digital Signature Act</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
        <ns5:QualificationElement>
            <ns5:Qualifiers>
                <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
            </ns5:Qualifiers>
            <ns5:CriteriaList assert="all">
                <ns5:KeyUsage>
                    <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
                </ns5:KeyUsage>
                <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
            </ns5:CriteriaList>
        </ns5:QualificationElement>
    </ns5:Qualifications>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/CA/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">Klass3-SK 2016 qualified certificate for electronic seal</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIGgTCCBWmgAwIBAgIQXlM7EyVgNCtYSVcwizB43DANBgkqhkiG9w0BAQwFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMCAXDTE2MTIwODEyNTA1NloYDzIwMzAxMjE3MjM1OTU5WjCBhjELMAkGA1UEBhMCRUUxIjAgBgNVBAoMGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsMGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDEXMBUGA1UEYQwOTlRSRUUtMTA3NDcwMTMxFzAVBgNVBAMMDktMQVNTMy1TSyAyMDE2MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAlkOLeKQPKK1U8VK7z2Dzt2SX2KblGqrBmOXfzlImzXHxGVopSeji2/4MdR5Ok6NJqXxanbyufXXRTeuE5nQ8Olzr5+9U21DPmVUADFNWnDLy6NWyqE3CvrYp7tVOHbfTb9Mf3ECvQNt8YM0HGwdSfc8kGXuX8d4oixxeG4AD+wrj1+LJ0ioaQFlS6Tbcwq3xEO0WVv1hMrJOoMmPpaqrvRLcoikpmjnPm/Gtfx64FcyXiMmNxFDnROVMgr1OQKbxAdlX3Iu32fcXjXesCTcACLlNRMi5Sb1wowjGEpqL2H53+JDIrdE7hM0uUqX4aaT5etaUh0o2hxOBHg3m6WRAZmBPqO1BqIBN6PRMWYgab7BBtJMUKXE+FUaNy9Lb8jraX85t3IwN/hbbMx3wUAqZvoQVIaJu2tsP8eTGJUd6jES9q9rH788LNf2w9o16blr1cM0AkzfbPf1ktClERcQd+iEhAPluSjKwMHIehRQGwGGuo7db4QXKhXDXPGK5YRw6Q56mp+BpSqJJqpdlQCieEXbHm9sHsoP5yaQygZI8nJpd0nlpdcTq91aEjrWuuksQTNDG9++8NSAql2G/BVCesWx/zR0KtcWecMPUVfe7qEEFurWsewpLgZFsk5RLtNGwyTEgHHBfJqAJC8l2VMfbbsEW+tcjdMqb6BHgT6hNCx8CAwEAAaOCAfcwggHzMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYDVR0PAQH/BAQDAgHGMIHTBgNVHSAEgcswgcgwgYQGCSsGAQQBzh8HAzB3MCEGCCsGAQUFBwIBFhVodHRwczovL3d3dy5zay5lZS9jcHMwUgYIKwYBBQUHAgIwRh5EAEEAcwB1AHQAdQBzAGUAIABzAGUAcgB0AGkAZgBpAGsAYQBhAHQALgAgAEMAbwByAHAAbwByAGEAdABlACAASQBEAC4wCAYGZ4EMAQICMAsGCSsGAQQBzh8HAjAIBgYEAI96AQEwCQYHBACL7EABATAIBgYEAI96AQcwCQYHBACL7EABAzAdBgNVHQ4EFgQUrl5Y9fLy2cGO2e9OB9t1ylDihwAwHwYDVR0jBBgwFoAUEvJaPupWHL/NBqzx8SXJqUvUFJkweAYIKwYBBQUHAQEEbDBqMCAGCCsGAQUFBzABhhRodHRwOi8vb2NzcC5zay5lZS9DQTBGBggrBgEFBQcwAoY6aHR0cDovL3NrLmVlL2NlcnRzL0VFX0NlcnRpZmljYXRpb25fQ2VudHJlX1Jvb3RfQ0EuZGVyLmNydDA9BgNVHR8ENjA0MDKgMKAuhixodHRwOi8vd3d3LnNrLmVlL3JlcG9zaXRvcnkvY3Jscy9lZWNjcmNhLmNybDANBgkqhkiG9w0BAQwFAAOCAQEAah2vGqi+Pe5+CPtarh0vCQWOm233nl5Y9qL+JqG5PccowQ41kzf4qknmP6BHfisYGQsRc75K07A+/BdlFrLMbP3fFsuTi7+HAmAjXYEq35G49GAQg52+HvZiBe+RtbR8yOOar5fAKnzS1yNy9M1z7g7yMcEouk3TUebe2aanMvzabc7qgV3HGDfZkzhL9PlcjmFl0LQEflef/6sdMhy6C0HiditdLSUZYfSySJpb6lvJBGdN4Vrbo2fNtL3qIc+vX1Jvh/qLFIFmFXuC6lIjFJFtpIbCIQMtHoMXdI1A5JzzkmrTLPTSYDAQXXn9RPnzsRz2GnlYRV4xGayDGbUyow==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=KLASS3-SK 2016, OID.2.5.4.97=NTREE-10747013, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                            <DigitalId>
<X509SKI>rl5Y9fLy2cGO2e9OB9t1ylDihwA=</X509SKI>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2017-06-03T06:00:00Z</StatusStartingTime>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<ns5:Qualifications>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:PolicySet>
                <ns5:PolicyIdentifier>
                    <ns4:Identifier>0.4.0.194112.1.3</ns4:Identifier>
                </ns5:PolicyIdentifier>
            </ns5:PolicySet>
            <ns5:Description>Any certificate that is issued under the CA/QC Sdi certificate and that is issued as a QC (i.e. containing a QcCompliance statement) and having its Certificate Policy PolicyIdentifier OID set as 0.4.0.194112.1.3, is to be considered as supported by a QSCD. They are issued for digital stamping according to eIDAS regulation</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForLegalPerson"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="atLeastOne">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">false</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>Any certificate issued under the CA/QC Sdi certificate and is issued as a QC (i.e. containing a QcCompliance statement) is to be considered as issued to a Legal Person</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description>All certificates issued under this CA/QC service that have nonRepudiation bit set exclusively are issued as qualified certificates</ns5:Description>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
    <ns5:QualificationElement>
        <ns5:Qualifiers>
            <ns5:Qualifier uri="http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESeal"/>
        </ns5:Qualifiers>
        <ns5:CriteriaList assert="all">
            <ns5:KeyUsage>
                <ns5:KeyUsageBit name="nonRepudiation">true</ns5:KeyUsageBit>
            </ns5:KeyUsage>
            <ns5:Description/>
        </ns5:CriteriaList>
    </ns5:QualificationElement>
</ns5:Qualifications>
                            </Extension>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID-SK OCSP RESPONDER 2005</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIDPDCCAiSgAwIBAgIEQi2iwTANBgkqhkiG9w0BAQUFADB8MRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMQ8wDQYDVQQLEwZFU1RFSUQxCjAIBgNVBAQTATExEjAQBgNVBAMTCUVTVEVJRC1TSzAeFw0wNTAzMDgxMzA0MDFaFw0xMjAxMTIxMzA0MDFaMG8xCzAJBgNVBAYTAkVFMQ8wDQYDVQQKEwZFU1RFSUQxDTALBgNVBAsTBE9DU1AxJjAkBgNVBAMTHUVTVEVJRC1TSyBPQ1NQIFJFU1BPTkRFUiAyMDA1MRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAI8mLeLkRHLxMNCB5Pz8R5DnvPdVxBS91PoHboLnbhjlp1ecByVosjwGpXCGu8tUPuv81Azgqq97AsSugM1J7Pu0gj4bg0Mf6O/9XyoT7RI7H0BuEn4KJQlFcw7tXizI5KUWFFZ4Qg8kfg0xwrDrLIjusBtRbeRARG3DhH8dgZBpAgMBAAGjVzBVMBMGA1UdJQQMMAoGCCsGAQUFBwMJMB8GA1UdIwQYMBaAFHgXtQX5s1jNWYzeZ15EBkx1hmldMB0GA1UdDgQWBBRM+GJhloJeOPpJDgvA0clxQXdnVTANBgkqhkiG9w0BAQUFAAOCAQEAfD8dP+swtSeigLxL3uUXV/tmQkjre7Ww39Uey71LdtxQ6zC7MDjcsLW13JaU0pRuu/p/eGe6h4/w46tSMsBx/U+D1WnHeCj1ED9SFWwfNQFVz9FkM5JEkPDm7lw5hHoxIghRHAC3NMbR3sCrVQA2YELf2WypslROoz8XlRT1LN4pwVehpBeWO7xbQPUtoaxKrSCGumtxtxA3KRJ7POHPTAH4cvipxaZhS1ZcXbKtxsesGW+7KLZirpTBT17ICXEA1CFXDWmJ8MHRhbeNWK3G1PERgTiGtBQV7Z00CzmJPHmb1yfcT27+WZ1W9tRQsjhGEWyMVkNnZooWHIjLpNucQA==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK OCSP RESPONDER 2005, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK OCSP RESPONDER 2005</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK OCSP RESPONDER 2005, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>TPhiYZaCXjj6SQ4LwNHJcUF3Z1U=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, ESTEID-SK OCSP RESPONDER 2005</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK OCSP RESPONDER 2005, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>TPhiYZaCXjj6SQ4LwNHJcUF3Z1U=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2005-03-08T14:04:01Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID-SK 2007 OCSP RESPONDER</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIDnDCCAoSgAwIBAgIERZ0acjANBgkqhkiG9w0BAQUFADBbMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEPMA0GA1UECxMGRVNURUlEMRcwFQYDVQQDEw5FU1RFSUQtU0sgMjAwNzAeFw0wNzAxMDQxNTE3MDZaFw0xMDAxMDgxNTE3MDZaMG8xCzAJBgNVBAYTAkVFMQ8wDQYDVQQKEwZFU1RFSUQxDTALBgNVBAsTBE9DU1AxJjAkBgNVBAMTHUVTVEVJRC1TSyAyMDA3IE9DU1AgUkVTUE9OREVSMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAJmoB3SJCpPzcoHNqK1J0tRNQjgr5iuB27uE1VacIbITjD/Nc1AefKz5ydNPIaBNehm4yKxBYGxEeWOSJHVXyhJMg53EAUOw/45c46gvznXupHuJ6TEiGjh1pxaXTeLSnTqzNDZDAGQsOTgIbwGLa5U5ad8rXYu2YkJKsAfo6jT5AgMBAAGjgdcwgdQwEwYDVR0lBAwwCgYIKwYBBQUHAwkwEgYJKwYEBQUHMAEFBAUwAwQBMDCBiQYDVR0jBIGBMH+AFEgG3r6Mh1eVgHhj+pwjKyugOhh1oWGkXzBdMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMRAwDgYDVQQDEwdKdXVyLVNLggRFm6ANMB0GA1UdDgQWBBRJ/snw1GDL3fUH9n9Cpn8yhXiC7DANBgkqhkiG9w0BAQUFAAOCAQEAYzGkZD/uaXlWPeye1z5IiI83nmAjiJyvoj/r3BB9ZFWMX+ZY4Fz6/V/fzD0xXoeDpWbBKxcuctPXzXYxEH17n0/3yGOz8jhdJNBUCwRmd+96oHsU9aWSf+D2tiq1jPw6HVCiUYOhC/OWjg/+JpFlWsBV4gTW8/2PSGig85XlEsWLK7i7tIe60nnw/rWnfbCckMRcbrAF1L/JIlnUYUdkGOGQ9KPVqwR/MyWrwFIcSy2QIbcIaWMuiUc1nt8bmIXKoFZxbLzXYC00zba9cY7lSC4WPuhBtrQJ9JWb4OeoXd5j6O45UaH6XbarfrhER1GHL06cTyksT18p2L2GrMuEJg==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2007 OCSP RESPONDER, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2007 OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2007 OCSP RESPONDER, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>Sf7J8NRgy931B/Z/QqZ/MoV4guw=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, ESTEID-SK 2007 OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2007 OCSP RESPONDER, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>Sf7J8NRgy931B/Z/QqZ/MoV4guw=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2007-01-04T16:17:06Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID-SK 2007 OCSP RESPONDER 2010</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIEkjCCA3qgAwIBAgIESxUPmTANBgkqhkiG9w0BAQUFADBbMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEPMA0GA1UECxMGRVNURUlEMRcwFQYDVQQDEw5FU1RFSUQtU0sgMjAwNzAeFw0wOTEyMDExMjQ1MDBaFw0xNjA4MjYxMzIzMDBaMIGHMQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czENMAsGA1UECwwET0NTUDErMCkGA1UEAwwiRVNURUlELVNLIDIwMDcgT0NTUCBSRVNQT05ERVIgMjAxMDEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA48pyM/QfeiU1Kbu4AdcAUKXBiwbYbBl4gCltZHC5fZ77fKj2mqfPX2/XW1EqzbVvG0PYIkapkQzBr3R1S6Uaxh1DLC2Cc8BRnqmhXoE03o8En7N9xpN9dGGDBHp2aElBcVVZnAvF4jgbPDCNFAeo3cvpjIx18n0URiVOZFEdxDvF8PFo/exKXtjRM+jk3K6+9doHYvSXn9klFbT8Wge87Qdll3gQzZE3L8QMXF0z4xbBH1lyTmVLt5yZ0fxoE0jNlZFvn2w2EDnU4CKfId8w6Zjd5kdxomcwDzGuuLzdiJllPt05USJcY4FHn9YAVKWmofYY/o6xOUzU8fAz6yA1tQIDAQABo4IBLzCCASswEwYDVR0lBAwwCgYIKwYBBQUHAwkwaQYDVR0gBGIwYDBeBgorBgEEAc4fBAECMFAwJQYIKwYBBQUHAgIwGRoXU0sgdGltZSBzdGFtcGluZyBwb2xpY3kwJwYIKwYBBQUHAgEWG2h0dHA6Ly93d3cuc2suZWUvYWphdGVtcGVsLzCBiQYDVR0jBIGBMH+AFEgG3r6Mh1eVgHhj+pwjKyugOhh1oWGkXzBdMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMRAwDgYDVQQDEwdKdXVyLVNLggRFm6ANMB0GA1UdDgQWBBQ4AhAwumZ6EXROIl5wZQXedXpOFDANBgkqhkiG9w0BAQUFAAOCAQEAJ/LvPUevNRcBp+J78fZRofhk/ifKNLxCUoh8T3MjtU9u5R0KojRlye+1NU8MqH/zrKhr6TPxuXD0cRrFQ9Hy60II7IzzaegrQVNgq7UgQINvCuNxWZcGtEa3ba9M7tBpQeFxqp3CpBytGeVuXn65hqOBKdp/zYEiMUUkYNAT5A6SSPYLAOgARCI/ydBx+cw0l0fwYvw72FKZa2Mlt5DmXBccCtrQ4l/sb95xfANCNe5n5sBvBhY4F+sIWZUVJ8fTVh7iGaVPSayQfeAAei0m/4/ksiXBwfx6qhzyB3yqcnSk489oBrrCegua/t+3LizfHpNZvDphKMPuAZ4uheLfQA==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2007 OCSP RESPONDER 2010, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK 2007 OCSP RESPONDER 2010</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2007 OCSP RESPONDER 2010, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>OAIQMLpmehF0TiJecGUF3nV6ThQ=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, ESTEID-SK 2007 OCSP RESPONDER 2010</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK 2007 OCSP RESPONDER 2010, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>OAIQMLpmehF0TiJecGUF3nV6ThQ=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2009-12-01T13:45:00Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">EID-SK 2007 OCSP RESPONDER</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIDOjCCAiKgAwIBAgIERh9YjTANBgkqhkiG9w0BAQUFADBqMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEhMB8GA1UECxMYU2VydGlmaXRzZWVyaW1pc3RlZW51c2VkMRQwEgYDVQQDEwtFSUQtU0sgMjAwNzAeFw0wNzA0MTMxMDE2NDVaFw0xMDA0MTcwOTE2NDVaMH8xCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMQ0wCwYDVQQLEwRPQ1NQMSMwIQYDVQQDExpFSUQtU0sgMjAwNyBPQ1NQIFJFU1BPTkRFUjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD+Z0LZ6TjBzx4x+UshExea1nIMsS86xAN6u/amLV8XQE+vodEld8iqtRsrvFiQ74isYOys1JKqiq+1ryic6j2FnMDZueLiXZl51QWyuhWu+aT4BwEaA8rUxMgKJ94zWksrqSf9cjoaap+9DlDhEsrDa+/89CPl2rlZIB5lqeHLQQIDAQABo1cwVTATBgNVHSUEDDAKBggrBgEFBQcDCTAfBgNVHSMEGDAWgBQcB/Scv6QlbLO0niIfH5RIG1h6jTAdBgNVHQ4EFgQUMsMzikmZqG6CcdgnD5VAXfQeCrgwDQYJKoZIhvcNAQEFBQADggEBAH0eUFQ7LznD4R8XWj/6rsNhe0fme3Os7cyZGNkx1EWenkgdMHCV/gN3SyIfrjW7sEJM62sS1X+8Ke2J+6b5YH0TcSmSDqYICn6zVbsq5MLtHW5wmwKucBJ5xFgoC3NNCEp8wVrzuQmm6xCvFWQVQ6uNhjuxCQxcDKgLwpL7iEcBEMmTTKkvqEtqrvu/LZ/a2OHytkEoXGheN8KlEcIv7AJBPVL8OCv4UpgyUOrVnmIeX2F/KG3wmo4U3kVupuF9kaPrOeOGYG3ZzK2HNwfRNkZ/Ej7AuPazkumAHdsJBbpTdBYq8d8er8XZKai24Ra/e5eEmcMye+O8IpxAA4ExY+I=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2007 OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">EID-SK 2007 OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2007 OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>MsMzikmZqG6CcdgnD5VAXfQeCrg=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, EID-SK 2007 OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2007 OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>MsMzikmZqG6CcdgnD5VAXfQeCrg=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2007-04-13T10:16:45Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">EID-SK 2007 OCSP RESPONDER 2010</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIEMTCCAxmgAwIBAgIESxUA8TANBgkqhkiG9w0BAQUFADBqMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEhMB8GA1UECxMYU2VydGlmaXRzZWVyaW1pc3RlZW51c2VkMRQwEgYDVQQDEwtFSUQtU0sgMjAwNzAeFw0wOTEyMDExMTQxMzBaFw0xNjA4MjYxMzIzMDBaMIGEMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czENMAsGA1UECxMET0NTUDEoMCYGA1UEAxMfRUlELVNLIDIwMDcgT0NTUCBSRVNQT05ERVIgMjAxMDEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAso91KG7EHsjAxMairaCKUHSOyXp5rzxRq5Y9LfDyplVbHfh34fbB7M5G+wnu5CZgJsfJ7DF3MjpA7nlAHd5alAynIUl/CNXejf+XnJ/vyF1eQvAoWvnjBPVIS0mbaABgF54ybAGE2E7UKeZVOAj7RoQVAMHQcYVjxZW5OWz3yJX9KdaDZPOzqlGtRYKUASHiwAFwExKcqfaHOj0qO8+KdSvEBaVlpe5kunEVEvn+kgNKBtzdH2XFMjVFa4im31KW+iq7mNQwUiZDSe9ho6T6UrWu7g8yTQowx3SYLTqVxR0YVgcYNCx7nn1AVGNxK3oeonrHHqcBp6qSAIYXeQNfiQIDAQABo4HDMIHAMBMGA1UdJQQMMAoGCCsGAQUFBwMJMGkGA1UdIARiMGAwXgYKKwYBBAHOHwQBAjBQMCUGCCsGAQUFBwICMBkaF1NLIHRpbWUgc3RhbXBpbmcgcG9saWN5MCcGCCsGAQUFBwIBFhtodHRwOi8vd3d3LnNrLmVlL2FqYXRlbXBlbC8wHwYDVR0jBBgwFoAUHAf0nL+kJWyztJ4iHx+USBtYeo0wHQYDVR0OBBYEFPBOCDPMR+kfp7Ozk5U68E68/AseMA0GCSqGSIb3DQEBBQUAA4IBAQCRaqmxZgJiJ+MLamb/P4vyS6azr6/tj8dZCK++V/3GnecRm7CiZpR47EnW0NyDzCecGyTWSkVlnZPnNvXRx700Nn0M4Inia5pNhSuVmWS3p5eV70vCbsfRD26+6CZhkHWnL/J2xpqeacULtgPPz9gBTyC2ybQr17dv7W5Qc+3UFywmE5N8ozQuEJroGz7P+yCbBEssWcmIUNDNdO0xs6aQZ1f+DV4FUB0lajuILYFz4xM+81akYFVqaGPCVwbQgFSWRKmamj8FxfWjA4DCrgkHVR1rA3tZyirfCBK9cfWpTCLr8zq9Ur0jTAeGrHRzHlUrB9mYZwyr0kNOyl9293xh</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2007 OCSP RESPONDER 2010, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">EID-SK 2007 OCSP RESPONDER 2010</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2007 OCSP RESPONDER 2010, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>8E4IM8xH6R+ns7OTlTrwTrz8Cx4=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, EID-SK 2007 OCSP RESPONDER 2010</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=EID-SK 2007 OCSP RESPONDER 2010, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>8E4IM8xH6R+ns7OTlTrwTrz8Cx4=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2009-12-01T12:41:30Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">KLASS3-SK OCSP RESPONDER 2009</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIDzzCCAregAwIBAgIEScskSjANBgkqhkiG9w0BAQUFADCBjjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEhMB8GA1UECxMYU2VydGlmaXRzZWVyaW1pc3RlZW51c2VkMQowCAYDVQQFEwExMRIwEAYDVQQDEwlLTEFTUzMtU0swHhcNMDkwMzI2MDY0NDI2WhcNMTIwNTA0MDU0NDI2WjCBgjELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxDTALBgNVBAsTBE9DU1AxJjAkBgNVBAMTHUtMQVNTMy1TSyBPQ1NQIFJFU1BPTkRFUiAyMDA5MRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKi6weNl7Wj7sL6JD4YUNt/JXQ79KL53x5m4QGRsijGJaV5YggE5rJyVZGlsX4FSd9JFIV597ypAUGDbLPf0nDdlSIGteP7zamyETI3GI6bKfkeUuIE707r7uC+8FFe9iHOOL20+pi7WFzwnyXT9yuWs0eCoKdjQvLpMiq0MBIm9AgMBAAGjgcIwgb8wEwYDVR0lBAwwCgYIKwYBBQUHAwkwaAYDVR0gBGEwXzBdBgorBgEEAc4fBAECME8wJQYIKwYBBQUHAgIwGRoXU0sgdGltZSBzdGFtcGluZyBwb2xpY3kwJgYIKwYBBQUHAgEWGmh0dHA6Ly93d3cuc2suZWUvYWphdGVtcGVsMB8GA1UdIwQYMBaAFOU/DJ1xPW+8Gb+a9G6/Cf5A652WMB0GA1UdDgQWBBT59PTkSIzYXNBxQQnAhqH3BtED0TANBgkqhkiG9w0BAQUFAAOCAQEAhyl3H6fo1bz3mD0JcD4eY1slcwec92Qgkn6i9TsO5TlDQCJxiC/80zlh+H5dgIMcNQ6gNbr1cWsUw7xAanv2hGlg20IWq7uCyy5LDghFpO2BWDzTJjmiVTXzyVEvqST0W6efDiwi1tA8H7b+aAzc9ItWm7pYlucGvneKJq07t/UvU9ONSDUfVLPNMr8slwCMOexVDZ+eiBlvrLL3N7NouPs7UpFh/+m5JsERmeLbbrNYimHUUn2PJ/trJ3kBEVFToO+nFdBElfzC3bjSlbPXFxSOL+AqSgvRIaB4CEWUxa33wzoZNaVpCh5AupxQOGdr4u7ajw5hkV8Y9VZ7OFej6A==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER 2009, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK OCSP RESPONDER 2009</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER 2009, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>+fT05EiM2FzQcUEJwIah9wbRA9E=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK OCSP RESPONDER 2009</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER 2009, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>+fT05EiM2FzQcUEJwIah9wbRA9E=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, KLASS3-SK OCSP RESPONDER 2009</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER 2009, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>+fT05EiM2FzQcUEJwIah9wbRA9E=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2009-03-26T07:44:26Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">KLASS3-SK 2010 OCSP RESPONDER</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIELzCCAxegAwIBAgICAMswDQYJKoZIhvcNAQEFBQAwbTELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsTGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDEXMBUGA1UEAxMOS0xBU1MzLVNLIDIwMTAwHhcNMTAwNDA4MDgwMTMxWhcNMTYwODI1MjIwMDAwWjCBgjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czENMAsGA1UECxMET0NTUDEmMCQGA1UEAxMdS0xBU1MzLVNLIDIwMTAgT0NTUCBSRVNQT05ERVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDhWwGpngF0sdGCgOgiyT12A/Vdm9sMPr/cUwZhU7DA5C8rU1yJhbrh28fMpv0eas6/+IC1oDxI24zjfWIKfHwpBmhUTFsmvmKRIu4a1F6VwNwYEdoAZrQDpzZSve6H6R/+0Uy0BAolebdhPUK22pKd8V1CBY3de886Ray8uUJu09MAU8j+xsoUNOzyxiWdAVp1YTXRhhUt+EQVYJ22RBZ6+b9fPQvgb9aWgE/WwqUh7OrgTnrGZVzgO46prfE7zkALG0FYZCzQTCMH8aIqqte0E3HwSVlKh9qwbRPB9WTDCtCqajh4qgGRTXvWT4vATlHvx8GpJ3roZkp5AlQno3hTAgMBAAGjgcIwgb8waAYDVR0gBGEwXzBdBgorBgEEAc4fBAECME8wJQYIKwYBBQUHAgIwGRoXU0sgdGltZSBzdGFtcGluZyBwb2xpY3kwJgYIKwYBBQUHAgEWGmh0dHA6Ly93d3cuc2suZWUvYWphdGVtcGVsMBMGA1UdJQQMMAoGCCsGAQUFBwMJMB8GA1UdIwQYMBaAFF11FBGM9KWOQo97skBEo+7WejtyMB0GA1UdDgQWBBQ3MJkXG2Go/6j4bem465aue3P5qjANBgkqhkiG9w0BAQUFAAOCAQEAKhoVTII1ECecFkyt9Ogr0XW3WEFprrqTDE4IycMlx+LNjWk30aknMldEtzIC5nCDX27NCWkpbN1o/3ddBv0cKMa05ZK8sHQxU6A5Oev8DCp72/LFEChq5IDqgqW2BiHhyfPfr93JIuV03b/Wgq3fpRyBd21VE9254W4A90xeNxDvdpqxlrD2Lonzm/V/oomzEHsp4kKxXkPmRU4vGtTnxxAnxYp9OuLkvpUCLNoAWMbYqb4cbYzaZ9tQIkBy3nJ352Rs5obYDb3R/ZVWuYLLSocWL7b2QwlDP7LA8VNDqmQvioHt8GcyKXQ5/eWMvj2ePt58waVhwfSdd4nANKtq1g==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>CN=KLASS3-SK 2010 OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK 2010 OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=KLASS3-SK 2010 OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>NzCZFxthqP+o+G3puOuWrntz+ao=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK 2010 OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=KLASS3-SK 2010 OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>NzCZFxthqP+o+G3puOuWrntz+ao=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, KLASS3-SK 2010 OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=KLASS3-SK 2010 OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE, EMAILADDRESS=pki@sk.ee</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>NzCZFxthqP+o+G3puOuWrntz+ao=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2010-04-08T08:01:31Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">SK OCSP RESPONDER 2011</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIEvDCCA6SgAwIBAgIQcpyVmdruRVxNgzI3N/NZQTANBgkqhkiG9w0BAQUFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMB4XDTExMDMxODEwMjE0M1oXDTI0MDMxODEwMjE0M1owgZ0xCzAJBgNVBAYTAkVFMQ4wDAYDVQQIEwVIYXJqdTEQMA4GA1UEBxMHVGFsbGlubjEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czENMAsGA1UECxMET0NTUDEfMB0GA1UEAxMWU0sgT0NTUCBSRVNQT05ERVIgMjAxMTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAihvGyhMVrgReHluKln1za6gvCE/mlSREmWjJFpL9llvuEUZoPFIypYA8g5u1VfgkeW5gDq25jAOq4FyXeDGIa+pJn2h0o2Wc2aeppVG/emfGm/jA8jjeyMrwH8fAJrqVQ7c9X2xSwJEch/P2d8CfMZt5YF6gqLtPvG1b+n6otBZA5wjIFfJ/inJBMUvqHSz3+PLfxO2/T3Wyk/c8M9HIMqTelqyiMGRgWehiU1OsL9armv3dQrHs1wm6vHaxfpfWB9YAFpeo9aYqhPCxVt/zo2NQB6vxyZS0hsOrXL7SxRToOJaqsnvlbf0erPPFtRHUvbojYYgl+fzlz0Jt6QJoNwIDAQABo4IBHTCCARkwEwYDVR0lBAwwCgYIKwYBBQUHAwkwHQYDVR0OBBYEFKWhSGFt537NmJ50nCm7vYrecgxZMIGCBgNVHSAEezB5MHcGCisGAQQBzh8EAQIwaTA+BggrBgEFBQcCAjAyHjAAUwBLACAAdABpAG0AZQAgAHMAdABhAG0AcABpAG4AZwAgAHAAbwBsAGkAYwB5AC4wJwYIKwYBBQUHAgEWG2h0dHBzOi8vd3d3LnNrLmVlL2FqYXRlbXBlbDAfBgNVHSMEGDAWgBQS8lo+6lYcv80GrPHxJcmpS9QUmTA9BgNVHR8ENjA0MDKgMKAuhixodHRwOi8vd3d3LnNrLmVlL3JlcG9zaXRvcnkvY3Jscy9lZWNjcmNhLmNybDANBgkqhkiG9w0BAQUFAAOCAQEAw2sKwvTHtYGtD8Jw9mNUuj/mWiBSBEBeY2LhW8V6tjBPAPp3s6iWOh0FbVR2LUyrqRwgT3fyWiGsiDm/6cIqM+IblLp/8ztfRQjquhW6XCD9SK02OQ9ZSdBwcmoAApZLGXQC34wdgmV/hLTTNxONnDACBKz9U+Dy9a4ZT4tpNkbH8jq/BMne8FzbvRt1bjpXBP7gjLX+zdx8/hp0Wq4tD+f9NVX0+vm9ahEKuzx4QzPnSB7hhWM9OnLZT7noRQa+KWk5c+e5VoR5R2t7MjVl8Cd+2llxiSxqMSbU5/23BzAKgN+NQdrBZAzpZ7lfaAuLFaICP+bAm6uW2JUrM6abOw==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=SK OCSP RESPONDER 2011, OU=OCSP, O=AS Sertifitseerimiskeskus, L=Tallinn, ST=Harju, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, SK OCSP RESPONDER 2011</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=SK OCSP RESPONDER 2011, OU=OCSP, O=AS Sertifitseerimiskeskus, L=Tallinn, ST=Harju, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>paFIYW3nfs2YnnScKbu9it5yDFk=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2011-03-18T11:21:43Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">SK Proxy OCSP Responder 2009</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIEUjCCAzqgAwIBAgIESg1N9TANBgkqhkiG9w0BAQUFADCBjjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEhMB8GA1UECxMYU2VydGlmaXRzZWVyaW1pc3RlZW51c2VkMQowCAYDVQQFEwExMRIwEAYDVQQDEwlLTEFTUzMtU0swHhcNMDkwNTE1MTExMTQ5WhcNMTIwNTA1MTEwNzE3WjCBgTELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxDTALBgNVBAsTBE9DU1AxJTAjBgNVBAMTHFNLIFByb3h5IE9DU1AgUmVzcG9uZGVyIDIwMDkxGDAWBgkqhkiG9w0BCQEWCXBraUBzay5lZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJ6rr1AZFPunWKMJAse70wx9Utc57qgbrJdk8iiOrcUN2FApNal2wFnRIw9rsF8u9KPu3g47ZSuKKYkpdVVupTwt6gK+brQczfQShO3xOCj7cubcl5+6jDPXSh47zma10hh4tJ5VECOiCDBhIRfA/UJfMYj6BYgEhFuRQxEBgAF5yyEJX1X8Sco/GQcha4Er5SyEhHvXu/vvg0OVfLRqH/7gGBBRLPMOsDImmXf+C0UYKs7ywFBf+M0VnWH9u0p7E8XzA8s3m2ivTdU/JYIU5Zy7NFeV9NJgZw3iaLCO1dbV2gBIWpgGvqlwQ3coKHMs3tMBT25+WWmKVMsHFi254ysCAwEAAaOBwjCBvzATBgNVHSUEDDAKBggrBgEFBQcDCTBoBgNVHSAEYTBfMF0GCisGAQQBzh8EAQIwTzAlBggrBgEFBQcCAjAZGhdTSyB0aW1lIHN0YW1waW5nIHBvbGljeTAmBggrBgEFBQcCARYaaHR0cDovL3d3dy5zay5lZS9hamF0ZW1wZWwwHwYDVR0jBBgwFoAU5T8MnXE9b7wZv5r0br8J/kDrnZYwHQYDVR0OBBYEFCRXW4FmpJ/GGw3/AXu5czpgogbJMA0GCSqGSIb3DQEBBQUAA4IBAQB9U7sG/M/w7eXBQh5tDOZ7XLCRmhrmGk9+1RdAP54SmMzc1nnglmfgl13ncaizPleu0p8541a51XCYqQMJbry47YkEnq48ImiAjEpkbaCZsZhX06uUpA9DlstEW/wBZzSCUoGsklbBolwTWAP97B7trizPe102hNvD5IMaXrMqaH9hQcoYmKyJHBQnxW2bXxYjeXvIDcAQvevLP8IIOLqdib029GFcM7U889FaBcO4cPxx4kITXC2hAvdiZwGuDVAz15Byl8RAfNWrlmv+IBRSQpAecnLYozJYyRNcFPrYLd9aXbej6p6sRCHgC452czoM0VbMmisrK8pm6yZ0J1r+</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=SK Proxy OCSP Responder 2009, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">SK Proxy OCSP Responder 2009</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=SK Proxy OCSP Responder 2009, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>JFdbgWakn8YbDf8Be7lzOmCiBsk=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, SK Proxy OCSP Responder 2009</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=SK Proxy OCSP Responder 2009, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>JFdbgWakn8YbDf8Be7lzOmCiBsk=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2009-05-15T11:11:49Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">ESTEID-SK OCSP RESPONDER</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIDuDCCAqCgAwIBAgIEPJilyDANBgkqhkiG9w0BAQUFADB8MRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKExlBUyBTZXJ0aWZpdHNlZXJpbWlza2Vza3VzMQ8wDQYDVQQLEwZFU1RFSUQxCjAIBgNVBAQTATExEjAQBgNVBAMTCUVTVEVJRC1TSzAeFw0wMjAzMjAxNTA3NTJaFw0wNTAzMjQxNTA3NTJaMGoxCzAJBgNVBAYTAkVFMQ8wDQYDVQQKEwZFU1RFSUQxDTALBgNVBAsTBE9DU1AxITAfBgNVBAMTGEVTVEVJRC1TSyBPQ1NQIFJFU1BPTkRFUjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC10BeCObXZZWcDX298Wqfd16hpi9tuSbT4L+kowTj+aWz7PDsFpKQWqhxCdlicu67xCT0zAAjaK6x9cwasiIdre++IkscRi00w20G5nTPocxpwGTHqwHx4ED7cceK4t4pbj/zB8FluVNVii8ouG9ZEhH76j/Icx0X27Sq5AS0CwwIDAQABo4HXMIHUMBMGA1UdJQQMMAoGCCsGAQUFBwMJMBIGCSsGBAUFBzABBQQFMAMEATAwgYkGA1UdIwSBgTB/gBR4F7UF+bNYzVmM3mdeRAZMdYZpXaFhpF8wXTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEQMA4GA1UEAxMHSnV1ci1TS4IEPERcgjAdBgNVHQ4EFgQUzpYj2gwlDYK9ahyGyKa0AkK5ys0wDQYJKoZIhvcNAQEFBQADggEBADrq0tGkwsrddEqUbsOpXi75Xs4GVkOyseysNqZZCvLqCF7qTSMiC+fzRxQbXQDhuOT7QQvi3JAoA5zTIm2RvIO1fmrVnJ6CsObjxxvXtcSLI+bICG4uQYgEA+duDRgICpmtCCjtmxb+2/cSJLGioaKiwn0YwgeEowOgjDMh2o4otm6FjtyT1GZsZm56U7WkFa7tSwkHKw427iZUWVrED6W9AfATY14rNnAk8Jqz06w4rPnGE4kYjO+UqMLmFU2KImdrTp1O7h4YLCVlxH/e/He8r7FSgzXSG4EqlD/TMEdCLu7DSWR3SEgJPvKWCpNWzv2DRldHp+kQO3k+R/f2c80=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, C=EE, O=ESTEID, OU=OCSP, CN=ESTEID-SK OCSP RESPONDER</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">ESTEID-SK OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK OCSP RESPONDER, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>zpYj2gwlDYK9ahyGyKa0AkK5ys0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, ESTEID-SK OCSP RESPONDER</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=ESTEID-SK OCSP RESPONDER, OU=OCSP, O=ESTEID, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>zpYj2gwlDYK9ahyGyKa0AkK5ys0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2002-03-20T16:07:52Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">KLASS3-SK OCSP RESPONDER (2003)</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIDXTCCAkWgAwIBAgIEPolzuzANBgkqhkiG9w0BAQUFADCBjjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEhMB8GA1UECxMYU2VydGlmaXRzZWVyaW1pc3RlZW51c2VkMQowCAYDVQQFEwExMRIwEAYDVQQDEwlLTEFTUzMtU0swHhcNMDMwNDAxMTExMDUxWhcNMDYwNDA1MTAxMDUxWjB9MQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czENMAsGA1UECxMET0NTUDEhMB8GA1UEAxMYS0xBU1MzLVNLIE9DU1AgUkVTUE9OREVSMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALXQF4I5tdllZwNfb3xap93XqGmL225JtPgv6SjBOP5pbPs8OwWkpBaqHEJ2WJy7rvEJPTMACNorrH1zBqyIh2t774iSxxGLTTDbQbmdM+hzGnAZMerAfHgQPtxx4ri3iluP/MHwWW5U1WKLyi4b1kSEfvqP8hzHRfbtKrkBLQLDAgMBAAGjVzBVMBMGA1UdJQQMMAoGCCsGAQUFBwMJMB8GA1UdIwQYMBaAFOU/DJ1xPW+8Gb+a9G6/Cf5A652WMB0GA1UdDgQWBBTOliPaDCUNgr1qHIbIprQCQrnKzTANBgkqhkiG9w0BAQUFAAOCAQEAd/8FCyPC9zXxcAZN67KCNU4+XNJ8e+LmG602lBe+lS7Pw4pOgMKebgULKh1fEBHQ2K7FSUWMZdPWkDHaKVRh646yVbFZbfEmKNq4LhRf13/hoUdrG5uRVmCsV03WSfgfUVfb1cZf8tDMIwCmsNXu22k9wykeHallpUmGUfbVZygqfKE2NVQpm2FULiKWBFKXqbMtW5R3xmDS3bjrAIAdUdYhxhfdCHCphsQf/FJlxb8UFOUa8SeRNr5eL7s8znLnrC5pKPpWGbUNSlrhLJZHIeXfwbOamae6UVvjto6bMqRe2sxCsMA0dGz+tMiglfmTVInxpEKBkyvF/on/2qwtVw==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, C=EE, O=AS Sertifitseerimiskeskus, OU=OCSP, CN=KLASS3-SK OCSP RESPONDER</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/deprecatedatnationallevel</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK OCSP RESPONDER (2003)</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>zpYj2gwlDYK9ahyGyKa0AkK5ys0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/recognisedatnationallevel</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK OCSP RESPONDER (2003)</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>zpYj2gwlDYK9ahyGyKa0AkK5ys0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/recognisedatnationallevel</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, KLASS3-SK OCSP RESPONDER (2003)</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>zpYj2gwlDYK9ahyGyKa0AkK5ys0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2003-04-01T11:10:51Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">KLASS3-SK OCSP RESPONDER (2006)</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIDXTCCAkWgAwIBAgIERCKLGDANBgkqhkiG9w0BAQUFADCBjjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEhMB8GA1UECxMYU2VydGlmaXRzZWVyaW1pc3RlZW51c2VkMQowCAYDVQQFEwExMRIwEAYDVQQDEwlLTEFTUzMtU0swHhcNMDYwMzIzMTE0ODQwWhcNMDkwMzI3MTE0ODQwWjB9MQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czENMAsGA1UECxMET0NTUDEhMB8GA1UEAxMYS0xBU1MzLVNLIE9DU1AgUkVTUE9OREVSMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKKTI8Aex0Gva9eeeBkM3fGTiNOEvjj2McN3tOJBMAEvG/G7Npu0/2fAEKFFUv4NnPyH3MiC7s6R8PtPMhV5GBG6kWVztL/gQnlIjAbo1l654+jApIQjT3vdVZDIYyS6lKlYoAdG40CgLlVtRihargQ77azlfORkyRfhKZcSQe8tAgMBAAGjVzBVMBMGA1UdJQQMMAoGCCsGAQUFBwMJMB8GA1UdIwQYMBaAFOU/DJ1xPW+8Gb+a9G6/Cf5A652WMB0GA1UdDgQWBBQUQsudE6pYaIJSuWurylGItfy52DANBgkqhkiG9w0BAQUFAAOCAQEAV+Vu+qzrHe7HDjMHq9DdOQTz833QcMRY0huSgphMOgqNjqjPqTNpHPgNvE6HKGdQ0+VWr8IyRWcxnPMZNihmaCGMpFMpYuH0fx9nsjXDbjat8MfGuX2m1EADGOwjtjMuoYTEGEUe3MBeFkmPFDIYpeuS+I4Qv34tOsGvFOpsDkobSATq4EFw/5hI9WfWaEMYkmBXdeokoVjbNpt+gtdGKNBU42AlxLrcc+YzAE1hj5qH99/hl0X6r63pTjUb1ZMRjGQg7ELwmddms7wB5LKKi5kbfmag5hBtDKGs2s0xW1be4ylNOrT9lqUYuPn9lwcHNg1IS42mYVChV97Tlt/5vw==</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, C=EE, O=AS Sertifitseerimiskeskus, OU=OCSP,CN=KLASS3-SK OCSP RESPONDER</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK OCSP RESPONDER (2006)</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>FELLnROqWGiCUrlrq8pRiLX8udg=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">KLASS3-SK OCSP RESPONDER (2006)</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>FELLnROqWGiCUrlrq8pRiLX8udg=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP/QC</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, KLASS3-SK OCSP RESPONDER (2006)</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=KLASS3-SK OCSP RESPONDER, OU=OCSP, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>FELLnROqWGiCUrlrq8pRiLX8udg=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2006-03-23T12:48:40Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">SK Proxy OCSP Responder 2008</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIEgTCCA2mgAwIBAgIESQbcTzANBgkqhkiG9w0BAQUFADCBjjEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMQswCQYDVQQGEwJFRTEiMCAGA1UEChMZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEhMB8GA1UECxMYU2VydGlmaXRzZWVyaW1pc3RlZW51c2VkMQowCAYDVQQFEwExMRIwEAYDVQQDEwlLTEFTUzMtU0swHhcNMDgxMDI4MDkzMzAzWhcNMTExMTAyMDgzMzAzWjCBlTELMAkGA1UEBhMCRUUxIjAgBgNVBAoTGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxITAfBgNVBAsTGFNlcnRpZml0c2VlcmltaXN0ZWVudXNlZDElMCMGA1UEAxMcU0sgUHJveHkgT0NTUCBSZXNwb25kZXIgMjAwODEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnquvUBkU+6dYowkCx7vTDH1S1znuqBusl2TyKI6txQ3YUCk1qXbAWdEjD2uwXy70o+7eDjtlK4opiSl1VW6lPC3qAr5utBzN9BKE7fE4KPty5tyXn7qMM9dKHjvOZrXSGHi0nlUQI6IIMGEhF8D9Ql8xiPoFiASEW5FDEQGAAXnLIQlfVfxJyj8ZByFrgSvlLISEe9e7+++DQ5V8tGof/uAYEFEs8w6wMiaZd/4LRRgqzvLAUF/4zRWdYf27SnsTxfMDyzebaK9N1T8lghTlnLs0V5X00mBnDeJosI7V1tXaAEhamAa+qXBDdygocyze0wFPbn5ZaYpUywcWLbnjKwIDAQABo4HdMIHaMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDCTBoBgNVHSAEYTBfMF0GCisGAQQBzh8EAQIwTzAlBggrBgEFBQcCAjAZGhdTSyB0aW1lIHN0YW1waW5nIHBvbGljeTAmBggrBgEFBQcCARYaaHR0cDovL3d3dy5zay5lZS9hamF0ZW1wZWwwHwYDVR0jBBgwFoAU5T8MnXE9b7wZv5r0br8J/kDrnZYwHQYDVR0OBBYEFCRXW4FmpJ/GGw3/AXu5czpgogbJMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQEFBQADggEBALnuqrbcM13+ISq6lzIbwaHr6Om2zAialZcAAU0i++lqs1lLTSA/cXoRuUIcjJ54Csh9pVPt3tJ76193H57ICkeKE+YhpHKFTdD3tPtgAU0prOlwiVq7Gh5MR+sMNX2TKaWTj0qd8Vgeui4MB5uWSUWYCNlKnmgoZbV+Zt0AyBHQVG9oRbqcEfK1iPUJw/sjkDUdghUHNUTcXpXfIPWCEvhQz+BX3TRNkR4NREvAwT/tHVtweJi+mr7RPrbtvdYBjdTppFwZVZDpGC34AM6KtL+mpVeGkK73h5V/pDvQ1rmLQn2L2GJe6n9ztghE/BB5zYJ1hWACaoJh5lEm+6xNPyU=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>EMAILADDRESS=pki@sk.ee, C=EE, O=AS Sertifitseerimiskeskus, OU=Sertifitseerimisteenused, CN=SK Proxy OCSP Responder 2008</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/deprecatedatnationallevel</ServiceStatus>
                        <StatusStartingTime>2018-03-20T07:00:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://ocsp.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <ServiceInformationExtensions>
                            <Extension Critical="true">
<AdditionalServiceInformation>
    <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
</AdditionalServiceInformation>
                            </Extension>
                        </ServiceInformationExtensions>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">SK Proxy OCSP Responder 2008</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=SK Proxy OCSP Responder 2008, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>JFdbgWakn8YbDf8Be7lzOmCiBsk=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/recognisedatnationallevel</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                            <ServiceInformationExtensions>
<Extension Critical="true">
    <AdditionalServiceInformation>
        <URI xml:lang="en">http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures</URI>
    </AdditionalServiceInformation>
</Extension>
                            </ServiceInformationExtensions>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/Certstatus/OCSP</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">OCSP, SK Proxy OCSP Responder 2008</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>EMAILADDRESS=pki@sk.ee, CN=SK Proxy OCSP Responder 2008, OU=Sertifitseerimisteenused, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>JFdbgWakn8YbDf8Be7lzOmCiBsk=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2008-10-28T10:33:03Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">SK Time-Stamping Authority for qualified electronic time stamps</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIIEDTCCAvWgAwIBAgIQJK/s6xJo0AJUF/eG7W8BWTANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYGCSqGSIb3DQEJARYJcGtpQHNrLmVlMB4XDTE0MDkxNjA4NDAzOFoXDTE5MDkxNjA4NDAzOFowYzELMAkGA1UEBhMCRUUxIjAgBgNVBAoMGUFTIFNlcnRpZml0c2VlcmltaXNrZXNrdXMxDDAKBgNVBAsMA1RTQTEiMCAGA1UEAwwZU0sgVElNRVNUQU1QSU5HIEFVVEhPUklUWTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJPa/dQKemSKCNSwlMUp9YKQY6zQOfs9vgUnbzTRHCRBRdsabZYknxTI4DqQ5+JPqw8MTkDvb6nfDZGd15t4oY4tHXXoCfRrbMjJ9+DV+M7bd+vrBI8vi7DBCM59/VAjxBAuZ9P7Tsg8o8BrVqqB9c0ezlSCtFg8X0x2ET3ZBtZ49UARh/XP07I7eRk/DtSLYauxJDPzXVEZmSJCIybclox93u8F5/o8GySbD5GYMhffOJgXmul/Vz7eR0d5SxCMvJIRrP7WfiJYaUjLYqL2wjFQe/nUltcGCn2KtqGCyH7vl+Xzefea6Xjc8ebTgan2FJ0UH0mHv98lWADKuTI2fXcCAwEAAaOBqjCBpzAOBgNVHQ8BAf8EBAMCBsAwFgYDVR0lAQH/BAwwCgYIKwYBBQUHAwgwHQYDVR0OBBYEFLGwvffmoGkWbCDlUftc9DBic1cnMB8GA1UdIwQYMBaAFBLyWj7qVhy/zQas8fElyalL1BSZMD0GA1UdHwQ2MDQwMqAwoC6GLGh0dHA6Ly93d3cuc2suZWUvcmVwb3NpdG9yeS9jcmxzL2VlY2NyY2EuY3JsMA0GCSqGSIb3DQEBCwUAA4IBAQCopcU932wVPD6eed+sDBht4zt+kMPPFXv1pIX0RgbizaKvHWU4oHpRH8zcgo/gpotRLlLhZbHtu94pLFN6enpiyHNwevkmUyvrBWylONR1Yhwb4dLS8pBGGFR6eRdhGzoKAUF4B4dIoXOj4p26q1yYULF5ZkZHxhQFNi5uxak9tgCFlGtzXumjL5jBmtWeDTGE4YSa34pzDXjz8VAjPJ9sVuOmK2E0gyWxUTLXF9YevrWzRLzVFqw+qewBV2I4of/6miZOOT2wlA/meL7zr3hnfo7KSJQmMNUjZ6lh6RBIVvYI0t+A/fpTKiZfviz/Xn2e4PC6i57wmH5EgOOav0UK</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>C=EE, O=AS Sertifitseerimiskeskus, OU=TSA, CN=SK TIMESTAMPING AUTHORITY</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:01:00Z</StatusStartingTime>
                        <ServiceSupplyPoints>
                            <ServiceSupplyPoint>http://tsa.sk.ee</ServiceSupplyPoint>
                        </ServiceSupplyPoints>
                        <TSPServiceDefinitionURI>
                            <URI xml:lang="en">https://sk.ee/en/repository/</URI>
                            <URI xml:lang="et">https://sk.ee/repositoorium/</URI>
                        </TSPServiceDefinitionURI>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">SK TIMESTAMPING AUTHORITY</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=SK TIMESTAMPING AUTHORITY, OU=TSA, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>sbC99+agaRZsIOVR+1z0MGJzVyc=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                            <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">SK TIMESTAMPING AUTHORITY</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>CN=SK TIMESTAMPING AUTHORITY, OU=TSA, O=AS Sertifitseerimiskeskus, C=EE</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>sbC99+agaRZsIOVR+1z0MGJzVyc=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2014-09-16T08:40:38Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
            </TSPServices>
        </TrustServiceProvider>
        <TrustServiceProvider>
            <TSPInformation>
                <TSPName>
                    <Name xml:lang="en">GuardTime AS</Name>
                </TSPName>
                <TSPTradeName>
                    <Name xml:lang="en">VATEE-101114112</Name>
                    <Name xml:lang="en">GuardTime AS</Name>
                    <Name xml:lang="en">Guardtime</Name>
                </TSPTradeName>
                <TSPAddress>
                    <PostalAddresses>
                        <PostalAddress xml:lang="en">
                            <StreetAddress>Tammsaare tee 60</StreetAddress>
                            <Locality>Tallinn</Locality>
                            <PostalCode>11316</PostalCode>
                            <CountryName>EE</CountryName>
                        </PostalAddress>
                    </PostalAddresses>
                    <ElectronicAddress>
                        <URI xml:lang="en">mailto:info@guardtime.com</URI>
                        <URI xml:lang="en">https://www.guardtime.com</URI>
                    </ElectronicAddress>
                </TSPAddress>
                <TSPInformationURI>
                    <URI xml:lang="en">https://sr.riik.ee/sites/default/files/GuardTime_Timestamping_Policy_200803.pdf</URI>
                </TSPInformationURI>
            </TSPInformation>
            <TSPServices>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA0</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQELBQAwJjENMAsGA1UEAxMEVFNBMDEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTExMDQyOTA5MTUxNVoXDTEyMDUyOTA5MTUxNVowJjENMAsGA1UEAxMEVFNBMDEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2WKqpwAceqQ1DNnsIvmj7AsSFgFR4g0U3ot8aLmIVT3cJ0rVN8PaQ4zuCIGf0xTM6mp1nQRqvtEScYkijZ9lSW44KDs4P71rC/8MYuX0NL/AwDlevmjCEkvHvqCQw7SAJ5gFkObc6FGjMcOzzVDTLc/0g9txSaFy6A2kTQYWY2a7DhqRDVBJphGhW8ir28DmH+AGRxj5I3vs6V8W/x1xy90yWunh8b/DNbS+29YKQ04phwPl0Ks59qvsgm1wPppix0xf/mp9HGC574q0zq2Ee7v4PAhu2FwY2t6Hj887KTWeVDUaRsVtwKqqDWJdmJBG/Pa96H/k9v1t5Lln8NlxHQIDAMm9MA0GCSqGSIb3DQEBCwUAA4IBAQBit30I5IzoldRcKYbWRLPrii5nNcmdLFfOVbjjfh/BcQV4G9cIaNtimuaw75Kq0eVuMaD1GBzn3gNSA7UFpCURt5xtEt/TNdO4ht+SLkVuFeW7AgRSlsJ/M1LiNrQei7qkPRTYrJwT4TGFbycy6oQVkHsFx0WSntG1TECDxNfutS4oKJQVp9pCwt99CVpt2M1sniIRFIsCgeYgwP6EqB0fwHpAZGZeX42VMmvLUFdkuijBgW8phGP5yxDWGWHkY/l+XDTZB2SlBbYcgDpQuS1k0lhGRZScIDSUr4g2ig1LBrbPlMakNXg/EWh74KkDeDDE8NSZFnh/cr2azvcXqt1G</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA0</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA0</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA0</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>FYIbyUnpkQO13KX4X2hiUVTAjj8=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2011-04-29T12:15:15Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA1</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQELBQAwJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTExMDQyOTExMDMzOFoXDTEyMDUyOTExMDMzOFowJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3IeYUjkf9LPKTkMUrjeOofT57NjJd+5WUmrsTRDGJsW6CWN/rM405B4EbXdrxeKR5TXqvTc8uKB8vb7QdQTBYAEiy8y49jL0wApQ40B2wnAj7kpyeWHwvMLwqeVyAxFxcR+gytsUxdRXl601g7GvwlXpCqi8Alj4vKykx99SBgsrya0CnR63v+Rgwv+0tc3A24b5SiE395Dzh1R9N1pgXWYNOPqn98A1cYWGA0bwayHzpcqw+e4YcR6qQ1gykULsPNlnIGCkakiOshblezzB1WrSziT6lNAjNSev+M7Uo4j6bCB3sFRrv1NXJWM7AqLxn+zC1xVqihB+N9m0YmNkjQIDAPHnMA0GCSqGSIb3DQEBCwUAA4IBAQDUXshmA1Kx+fPyMrbQkOim5FrSoTuLw4Jaxhhcw5wQLTnI0H25IwciqGisi7ou4fYffaQISbLfbXEpGG2aaZ9DPGGeG//5NPvtLoxLYw3igmaCYi4QEQ+O8Q5bH/YgxJWIZha8qtDXYjBVq7giX+1Kkb4O87BcBm9yGWXnDbu/Cbjvv+lnbhLff3N9AGlhEVZW4y/WNgd4RjRANYuKHLsNdBBT2jnxTirGzHRbcQ3QwxJUcTO+z8f/WUJfq6b/VayReUnWrrmYG6btzU2iwUUusb+eZ2uvNNAjuIJS+ngc8g9FLlty5ZcTR+SadzU1H36mdCE1uGHVDl3L07SlHNja</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA1</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>45sv4BLKD1el+RtP/81SVdyGgmc=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2011-04-29T14:03:38Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA1</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQELBQAwJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTEwMDQwOTA5MzMzNFoXDTExMDUwOTA5MzMzNFowJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx77CtLsrKHF3SswUv5uBEilPF3hJS6J+W54dKIFj4fE0xkxl7J7yMlDMf3Gk2tunTpZolsOKDPCbsl/9SsV8dY7y+yCT7bRT467yfi2zqTrFybHjXduYGSlvagNpYVw260he6gVH27D/IdpQv2eWOOScGAWcBOZTr6pZxEuX7b24luq7sSci8hv4ARpJamWBTLQX6sdxfiPhjnyMIacEGOQuEQgUjPKxAxo45ApwSHWESD7lAm2PQNacSZJg8+pkxrOq0s/7FrsgfJzQxlDhyF9BA7u28ilsCL60WdVbxqshmQBp91yyuX3ZHAkJ8Wp0kT8EwVfVnLutFWxzXp/4gwIDAOHjMA0GCSqGSIb3DQEBCwUAA4IBAQAAYwPUlEPIzB88xdz9WTaC8/QNF/DbfYOYKOD5439rGPhWjJ0YBe6SliohQf3lK0tfBrnaCj+Nw8EwzJ7fUD6+9xJ4FLSSQPSsH3pxZliAdiLXKWXUNou6jiPTh9gSDBkkjHvWCMhHj7GNDdIEABbwfqsSlejzNsQZGUVu9Z7vP0+flTGvqC3qIJqschhpQWZqaD4YR73K06H+JEFn6vnGQ6UVsWM/KDaktvLStQui/OwIqK8kyEm2cpCQOdkVPJZ7vTcGDgonWvbwaxf78xPJUqHSNkuWIHveV6dFlS949v1eJYEwvcsv6DyVD6UI8A2efjnQmjA4KbXucmWzm0KY</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA1</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>nsIInN9NggJuait7/oodYeuYG8E=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2010-04-09T12:33:34Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA2</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQELBQAwJjENMAsGA1UEAxMEVFNBMjEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTEwMDQxMjA3NTIyOVoXDTExMDUxMjA3NTIyOVowJjENMAsGA1UEAxMEVFNBMjEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp430lCKJvdyzzdK95iX4IlSE3MyVDkiPcQWKdvM/O0K/skXMKxK9308G01VVPz4Q0Fe/zm9Hd/b0tF6lNehGpi+CUfS13eq32JZvfyI7UsGNZCiU0nnkuGUUfLCXqlEMVsqfxXu9RAhwaJE3Zw0GZLc4jSF9xJy1HRSSryUkgp09pOl/PP5l0IgBeUESM0U3ALPvS5xjgMpYJAOshZCIS+rsyO1Cp83ymVNyGAw2jUCgjHGHu/l+wbTw8b6C2pUnqcUacaemjctKhtf6hNs+5+uTPBW2q9oA8k2c0SQii7+V04H8L8rvSdLaeVuNDgjEjzqPIJV7oS62APrWlWOf3wIDAKlzMA0GCSqGSIb3DQEBCwUAA4IBAQCCHTCmS6YOLlnhSEMpOq6F6ZUPq7B4BIEVJPlZOkrPuGRnwXY3CP1CM01mM2FcNc7OMYwEVyJNt11Aj12kB2yoCGCqABdYij78P2n4MzQykakymH/IQhTiP6rZ1glB1stye5yboAvezm5Cor9IbdGSf9QEv7DPGYqqyEwDAqCIhIgyKWBDTixcKkRFlP7hvDWCzYaDaCzaxcxN0Cjv0KTMoTDzK97IZJ2+qrBcgP/9AEsZIfPOlvzObbrRpnmwowwgNvYT3p3il7irrIwHryQh8H1kU4AwxmHtuMDcVKvQQrxpCQuEITPlBlelY2MdXKRoCcu4q//X5lq9YYP1XIjH</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA2</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA2</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA2</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>aj+TWPM7OpTB+vFnEQk4DETK8Hk=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2010-04-12T10:52:29Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA1</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQELBQAwJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTEyMDUwMzA4NDEwM1oXDTEzMDYwMzA4NDEwM1owJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0AjnC81sjs87Vv9e8XDGWcKaj7kJTxuaeWpC+WULglfyU2YSawqwb1PZbM9AT0Oi4Dz44tCG1o0Kcaeik+vWFe7AU3GSSC9K4Y3+jrhKZEOhySn1yI1DMdnl+Iv844R/IqS+XEKvP0c2LLnT0Bnmz6l8GIUh2c9MJWXIXfNyfgymldyT3ssw/RabL/IksTdqMsa9B7ar81vtmEG2rzsUjCl6I8U6N7Etv3hseALX/mcdWplpWn8uxAGUl8KqskF1itQ04BOU3P6Qk0WsLFBNCeQ2Rj+HcHPEdxtkT1eM0IbmOT71FuS7YZjC5fqza+CoiSPKBMJioU+28KG1qOFC1QIDAOwjMA0GCSqGSIb3DQEBCwUAA4IBAQBftgbUf5jzWS5EwcLmi7OgQ4ejPme6ZO5M+SX4OJh8cTViXOpqrF6JmIaFl7auqTKa4KNtgWmeGzjaqD3U9WamJ2aU3xmtf+t9rHWns9dBE+JRVdwNIjvOyEt+foSCENaFxtPRDqpaphx/fYC+jdCdNh+JHuKxqf1tW9ktBFNxG7qxmSeBa4eC+RosAXtt0gbmHBVMOQJOApGKIlQzruJ3c5YrCRzza/+D9jSkyp196VO+aYmt2epLMTK5CvJlgIjvF/vyuJuEXAnqd1Si6qUbfLxchWHgJ/dxUf7DxeqpPzJ8s+V0CD0fXYTIHa3p9Kz7/gLqpZMcuY8OH0nVnYOn</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA1</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>QdnoWaDRXvOdBJZ4GSjbfUW5bjs=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-05-28T07:45:00Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA2</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQELBQAwJjENMAsGA1UEAxMEVFNBMjEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTEyMDUwMjEyMTM1M1oXDTEzMDYwMjEyMTM1M1owJjENMAsGA1UEAxMEVFNBMjEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuWgbOYOThEhCRi61lnP3GSdD+V4sjuQCehCt9MJ+yyFvrEcJewvGhMaCBq7mUJul0yV5pCNoSH7gLDaO8XByJ4acmV8DxKAH1KlLSH/tashAjxQLMbReolA9c/qKiwO1oK12z5OCN7rA9C7PBO8gk/sCLFacOwgYtDCz7faY5l94AEaniIA62hT3PZ7Sd0IkcL5Gp9goJ2tZdQ+G58GBZawF+pfS2dzWSkKxWiV/lMzZahRdaXUF7vCGsXDsVHqS3AhL7ZblGCRVX0Thg+RCyRBqE12iPea8HWcVMxSJFHLhvSvKHTpj3iA6WVIOCJGUlhcz7h373WCKtgwGx7U+tQIDAMRFMA0GCSqGSIb3DQEBCwUAA4IBAQC4F/SnPubK6gaCyw5/7+sMTMILecuEGZ3W3ScAWLY4KP04pS7ViqlJxCvH3brl52dc9gUG0h602hRlEhdcXpk96tcd108er0mv666mGp97CT92vIL2E46mnz6QUG8uWyNfs+7K5SCgfkAflU7+lypM0NjOLXfDgCDRK2x3S7EAJh1mlqYSRHL9mst1sBLxjUMzi2xzOEGh5SaijIb0xelm2bp2J3JZrCvyjvGGA+95xRwHrGL9sMFdksrY6u66gG9zea8qurkSzRYBv0OGNUHwQWpw95QPZ47IITq9ipqC+J67FIEZheHTUtgPfvx1ch19IS8GiSM72M6rAeS8Kq19</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA2</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA2</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA2</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>wDEee81dyoI53eLTZ4ElUd6o/QE=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-05-28T07:45:00Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA1</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQELBQAwJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTEyMTAxOTE3MzE0M1oXDTEzMTAxOTE3MzE0M1owJjENMAsGA1UEAxMEVFNBMTEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+OA6jsb8QE/mLd3RPZFW40+l9RiGhpVWtaPSNgJAu1emrld4SFmLpOWM5BPsK6tVj2waLNucmEuRtG3r6H91E7EEgjsiBDxJaaREHytXMgpatMkt26X6Cg73Eb0pvD+5eBIh6VpksIWHtRrtq6ahde2wpb9CUmF8nb9IjfJqEsd3L9+EfsF4/EppRzOs4GDzKG+NGmBz95IEMGiIf0yh9Ot05b0Wj4xdOT7sJONbF0lC5qpQiPoXMKeLzsWWj6RfctjjhJZ9s2xEyLfwM89Yb4/vdwVVaa9Rk36ZkCvuoJeP1e+FKDXAJmNRGp2knEC1lQBZvXLG027bKmDdU0+WGwIDAKKPMA0GCSqGSIb3DQEBCwUAA4IBAQCR63M7Z45TV0MW2eA1bYO1vmRSryLbBK7fC4+2T8BqCXC8PYVxRtdMrQMdLUvXolibDY8bUDIC3GI4LLMDu1ivVcAcRJOCO4ii5KHxmK+mlmInif8v7YTZIlXAqPxbxJlYmpRNaEHFcDS7fciYzvohPzpbxRCKb4Nu9rfA0YqJv2s0vZmkZPTQ7W1vwHQw/+7KeRL3v/oY6/ANP0eKcNURwdhV3es2kya3RyEXH6sJuv3iUGOIPTAp5h8T7RV0xjlDxnz6BcRMSxxpFhyaUJHaA8ELKQXqHx1jjz0Ycri/AdIM21F3wc5Uq6855rm1STGythhxYFkrgx/dgLU7JeXc</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA1</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA1</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>u4+kp6DnUM0luSdwJVgTsm7g84Y=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-10-19T16:31:00Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">TSA2</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICwDCCAagCAQEwDQYJKoZIhvcNAQEFBQAwJjENMAsGA1UEAxMEVFNBMjEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMB4XDTEzMDUxNTEyNDA1MVoXDTE0MDUxNTEyNDA1MVowJjENMAsGA1UEAxMEVFNBMjEVMBMGA1UEChMMR3VhcmRUaW1lIEFTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmbkBqCyj5DTDvCRFqy9AubKiWtz1NczYGFG4Uu1YrtNpY7hOrutp2SxjBZGMwcXDXdzIceE28FCvuPjhTF1MsSmWA3wRqEFfdoKtwJ3hYM4N8NKB8GHgDKRYKw5nY++1anjt+KoxhpZsRbaAvPZSkbONr6trgSe9DUXE1WJ632LAvC0PGdd4LnUERxnernnhs5N/mQwv4BJmMPHcZ2lpiMfBCgJ2/v7r9UbodVRkGr/EHMzp9RdehneT3IQpMDV+7oL1niOyXi6KVdlbqaLzmL8QTpQuopfhaA6uKaAegWkkEaYOo50BK3xYKZjCUHwL+yH6Sw7ddgGNtBId7vtdpwIDALyRMA0GCSqGSIb3DQEBBQUAA4IBAQAjlFih75+4WvKgcTr7CHVgftiGLaSCa93uq57kmebap1raFqigOkCYpqg3Jx5DDhdGcx93VjdqTt6qC8IAvx2VJAywQXOisTtIrfiXK5hXUJMWlXzqT6q6Kv1q3Ac8603QySfStmVg5vehW504bg2UnjjL2oY0+X9e/D8nQRpeI8zVNAYYk2elAr3nNDrcR/kRtEfughvlK2F4fS5R4UrNO2P7xTaiNdQwRuq3CJZEkA2HjPRXE3kiJoL80p7aWU6DKOOHZr6VQjcOHJiK5T/ZUHeOT10tM3BCPHzmmHAs1ziMkFFfItOmAXooOXBsw8L3cOX5BiopaTnMzMw7Pwfo</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=GuardTime AS, CN=TSA2</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">TSA2</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=GuardTime AS, CN=TSA2</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>D3QyCl0LQEFZ0QcjGfxJDWFGZyY=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2013-05-15T11:40:51Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H1</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDExEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xMjExMjYxMjI1MDhaFw0xNDEyMjYxMjI1MDhaMCExCzAJBgNVBAMTAkgxMRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC6jdPpv5oA0BNHcFTVZpB8CEjGZvWix4KWgbAVbJiQaiLx2TgmRrimtAi7ogQ2qWPpJJbxgnKQUvpL/913tMH1blL2PXYk2fR6xU/jF3DoBvQBA7TrX39OlcTn+GO/noh9/hz3/a5ebyp452AyFow/g7IzvECf/kT8G+OcIj4aWK/M7qbmrj98eB/j6t5kuBF26llyLzExJr4iJOTSuCaR7BT3yWuLC3rAUtXJaG0XiQxkmTd6Ibt5GK8pSBtsQfKeJv9iTUS6I093rqZ8dSiP9/k2satrk9/hy464niGyXiKWfiEwWBeEe6okg7FwtZZ7ZHL42IATqLBRmbI9qvbXAgMBc7MwDQYJKoZIhvcNAQELBQADggEBAEbHvn6BZArTuTDE+opwN0NZ6FdtQ102tR1qWMcNGgKKICc1dvQpTCsUD5X4RL26pE0aNy9lB6HFa2vNlS4ZOz7LAbxKWn9DwSTHZVCBmDz7cThAop6YaVd+f2cYk6aP4FnIWr0dfSTTqxIWyFURip5TLC4vgu2FvJRuQU3LTBcpdbi5WwVSxxgS5VCzpEc5qUC7kZFGBV/aze6CAxUoE2nWrK3udj/8RUOSpUyaeF+f4oEAkR/xMKvd1xuWjl09rRyOD71h7WhfmNAJDHYZVRVthl6XBJbv+DMOkjpltfeFUHyvZm9eXEZnUh+KS8VpJ4O62VA+rNwV6e2QgaaVu7M=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime, CN=H1</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H1</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H1</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>zQ97Xa7ocnzmMZDaA9ZAuQVArp0=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-11-26T12:25:08Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H2</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDIxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xMjExMjYxMjQwNDZaFw0xNDEyMjYxMjQwNDZaMCExCzAJBgNVBAMTAkgyMRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDGUFzXDI8KWQj8/UcZLf1BecHHG3+YYoA3FwfZfdNjlbRepRdwypQx8p0RNbvcZC5eP7TnOLz8tCA95jBclLXOOMEKLeIdbcEuERrVNNZ6MplCsLBfxf0rSZzPcgjUA8vnREZj+rLqYkUwt6P2qt3uwCT/Ymm6D25UG373TX/058+7+8YlftspEowUPZt1E23ZzpTrObervZSiqvy4V1+efOPQZq0B/h71hkmw0+/zuWJ9vjTUhS3sde86AqDf8s3q6G1FbVEH9ilnJ8XZipam95fZx+kRCeBQ/Yitw+lYeLcGFQKOJ0uZuqMo3HnFcJfNkd27uA1Ymi938SVOCypfAgMBbiswDQYJKoZIhvcNAQELBQADggEBAHR1TVGVIuBLeTtrflzXP4bnsczEudLu36D0dTKcwTvBeGB4YEnaBp69vKT2/boNbdeZ0Pm6ft7PQYRzQg5v8NVlqmYwq8pAxNhrywGOICOynoW7mnRbooDKVQ25Ct4vdJwdf/pcrJ0l9F1WX3MZ5rNgKTPW6sXrMReXojfFf/2YwAvdwPhATjtRvnXYhkkN0aeXvkgPiPMctEP0lEiZelwWm+DjVFHOy8l1d4+38rvh25tuChxxcl/p45/H7xpAndHO1qpKEu9DJy6q5eWBcNgvHVf7UTXSDtIuRCOcS6g0Q2yz72sdW1Z/m1W/67ToYjofQwvhc14CrhQkD05pRAA=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime, CN=H2</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H2</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H2</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>4wZ8Qgdniap0mVcJ7mqsZKvwOjA=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-11-26T12:40:46Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H3</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDMxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xMjExMjYxMzAwMTZaFw0xNDEyMjYxMzAwMTZaMCExCzAJBgNVBAMTAkgzMRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDVkmSzH2Au23FOAGkCMTdCZUoHCcOHV7EPqVxFmwea01gS0nDfAjzFUcudvgYRtaw6r6r4ZPLC+pqBI0W7FjeVpRQAuKypYGhie2IEd2FAQLDB4gnJl68Z7K9B+Njc8rvwKbrqix+N3ReqFz9IENbwtGrXj90SMFBoCofkmUCe+fy5H/YYjhud7wnZUhYPw7DsYU+5eqAh9dNXNSD4gxOLDoZgID49G953fS2pkgdZKIWpZl+/hftiTDLD92NB0HYwoqEJZZGSM+RUKMxPeRiHz6goGcqoXp/WjeXyd5uiP4TQX8KsvAQQDTBrBs8DFbFlL7MOEzM+vvV2PdFdU0bRAgMBDskwDQYJKoZIhvcNAQELBQADggEBAL/Invma9hUUj7tcZAKKNlZm2bktd6jguW+eFUbf7m1zfSLw3sq85mwFkl8hSDlV/d4pasJJCd8KmGLki5T9BM/TAjvzf1g2orBGMArhZkYNnYkuJTHcxetLFqtyBxdMKGiObmhfTI1YNAckomnvsausJ8ejsKKFxFTcWQ1TOeL3v3N/sZ/c/pwVd80ZbTIo/k/dFwbRVkhuj3Q+DDi/8tlcGXSAppBVX+uFqDGudu3TZ8XQY7VX7ZSH/2rIO5SZm0CbgAOFYQitDLKLIXEBS6R4W4n559L+dXIaStAR3U8Jmx8WXWMSsa1FJVynyiVLUMMw07mVgQGUs2IK81ghXsY=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime, CN=H3</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H3</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H3</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>d8R/lqslVchhyESZTyjfFalKaYM=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-11-26T13:00:16Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H4</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDQxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xMjExMjYxMzA3NDdaFw0xNDEyMjYxMzA3NDdaMCExCzAJBgNVBAMTAkg0MRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDNVtvh71sZgFYcsv6a/zRU3/iby6KWNztiEjzuLl2oaqsUEVHq4kpAAj6/Hl+UPpIEwPEckB6rpGRgeN/+K+4bWJTrxh/7S/k3sQiHozTAYIOf6TIC4xAK5rjkfRyJNWZMbKU5ShXGC+DMh5sn5ZLtxOLshP4bVjCDrKUb+bNJCxYE/UT4N3bSPj3j45CgYnwqANWu2MFYcuuwSI6M+BiLWRA9HNLwHF3nVibCCJtyo17gN4oa236h61/+hehqICa9xePBBRh9gao35dtFNOEUgEN+qjqXGkUBrcFst6SG0nGh67AGJcQeku3QKU8Z81qocY9NhUKeXordC1C/XPsfAgMBWGEwDQYJKoZIhvcNAQELBQADggEBAGAdaaN8Zy/BWVBH+hLT+LXFJLKmFxaqRKRiyPtuerCRHmKjlHw8JqlVjB1UDUy4BN1LL04k6iwcpZX/ahuvlG0cwrdfi2/ld++ngyMQ8ecFEvjvli5u9kqiWSFxwDtA7fU5rsTm+Qni5hklPA60VMQHkuylx5oHejoyvPoBEft/tQnQ3QL+re7Cs06in8hkBtWndYK9jyot7G99wWfR5TEYzYQkze1L0oTjmySW/+EkrsT66XmRWHQuYLgo5tL5D+oO6H2tfeiKQ5PO0+zDLwQJJYjvvITCVKudR7/sH1v6/B4nXuvch82gaAzlfHK3EP6TQ7CBC3cw+uZ7qkggdIY=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime, CN=H4</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H4</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H4</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>g4Rp4hbka/wb/X12o1eSDeWB078=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-11-26T13:07:47Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H5</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDUxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xMjExMjYxMjUzMjJaFw0xNDEyMjYxMjUzMjJaMCExCzAJBgNVBAMTAkg1MRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCzNmmpHjZG/rb8xYUBH5TgSkSE9tkVl+JgtkeokY0BLZvrJhM9TZ/XX3AbN5aagJWnMgxPDBCyTYcA7XzsW6lRlQK7gym+zbLi9bmLEcpQzEYdeQs4Bi39Hb4vtlHYOFQjdck5H0CCaiLoJVJxX4b5y1dczJjXN5n7pkBl/YXXuIt4h/41bdZKw25j/KxEGWU/CmlZdrrDPzYW85aYk++dbO+uKspRkkIQZV+impSUpbwjOoN0VjfrmbJ7s+iyvB94j6qvvSTl537uFY6TOK//W3O4OrtEd8ze3aiePC517yTM8IQaUOrNy/pojan7FkhvLcVi1duQILuAcDu7gaQjAgMBMMcwDQYJKoZIhvcNAQELBQADggEBADndrk/PCTqGVmbrtjFWmYIjLyFgbUihSoHHf2+kw66Mzi77LFkDc+CYSz5M1pIjsXQe+a+Kkrvpc9YKkvxnT81ttiSduRujCNw2ISrYfFVP91Hzxh6hl2mnRSF6LOLsNbZCaSJjkH4JPuFdnY7wUiozKFmt/6T/5qu4B7osH5o+sLuCJKcgk0fXgssx41JM+ZUWf5JhS/QUUaPiW18s4SOZmNmO5w1IYVVG70bUOXsoGsVmrBNuuQeikPPdE30OAf+4ODB82rudUZok/ZrSW69p+eiAbkLKqlVfd1Lx05xeLf/EBgIvlSXRUECHV2LDmTbwJq1wDjHh5NHN7Z8I22I=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime, CN=H5</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H5</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H5</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>1y2GEphAgI0iKD3RaFtEI/53Aoo=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2012-11-26T12:53:22Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H1</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDExEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xNDEyMDkwODQ1NDNaFw0xNzAxMDkwODQ1NDNaMCExCzAJBgNVBAMTAkgxMRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDLKt3SYJHx+Y0zQypj433j9k23BtR7VxLy+FDL54GkqmAiCmaknWz/nRy19FM+kDfciM92OySnneN+nOyykfoblJ0uL2CIhN5vYITV9QvHxNNsij0urOiWu5eXui6N6T+lZPOl938EmNeorJbgzG7FeDJid5W4kRBE9apiRBPp3YFehl0crycBgLY6kHlvvoH33AgwsW9Zbp2B7jWU92GdH1D3aBw5JwhEhSI01sqjcI7Odbh7PZaygsXpoVRyW1T5PzDDR1+qoWHoak/oN9J0NXMEAVyswpytQ0rckOIbnXhfA7va2WLQ8+GuIm7wKwquS2wtqgBPbyvO7rP4L/AfAgMB4EEwDQYJKoZIhvcNAQELBQADggEBAI52GHcEe75qB8Sps07G3TVA+XXh+PGFZYSMrH5bsn1uJvaDNDb1fl1dQCK+YibtoxzVM0pdyBVlHFWsex1wTpdmstsmZYP8Xaj9ezabN6nPSCz6pdzhFUKM2XG0kuny6JLAFuNjqsh13SxsATARL6yZv7L2PI5VclXHbcpRhNaqiTeTKxLfXqfTgSX1f1RGNJI/r4SoiTBT+PFJ2TcJfc5GTuRunaTeGVIe+QGIrv0fWXAlZylGTFszgq2e2hh/1i9KFlxD7gS1IPvSRrxHVWdTEjM9BHSjMd/y6L6jQ9Ti9qW+UYz2CRo8sOYgfB7axA1mVmv/W60TQr2pkCl7GDM=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime,CN=H1</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H1</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H1</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>Eh8iaw0jrxBJx9MGEmtlnpGmxyM=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2014-12-09T09:45:43Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H2</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDIxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xNDEyMDMxMjIwMDZaFw0xNzAxMDMxMjIwMDZaMCExCzAJBgNVBAMTAkgyMRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC8ojFnaqso7obLfS6sDn8Mj22s/ZcmY2NbwfGy12xX+1FpEjgwrwea8Uq6YS55Mvux/oRcBh2UsgFxnn0IlzSLgrmRx0t42PVuufygcXVGy+voYjxsOJUkP8uFqdv+QhLPUHTyVzMKHIYvVEa434dHKiSK2nwWkpFVqEQ2hITU/uSv3ZAX64F+7iJuIlraefdZ0QC6ucdOsxAFwC3FEH+HfPpV2rb6nhsBu8hxIGWOqDHoCcd3y0H2+7n/BE1pmOCkuT0j1tKU2NwUrEvWfRna2xyx+zNff9PmcNRrlT0yytr4ghCuQJbcGpA7+EGf5jGKfGjL1xL6GXwnb3W23SPDAgMBHWMwDQYJKoZIhvcNAQELBQADggEBALxmxs0QzRhDIlCmedBngmOGYIBd9sJ3TtWXak+4cJemPttrKPetWlDnSHyW2leuO6neIUtvKSXVETrIqbX0Y2bn37qPseBu3284qWLi2fAYhhOKfz2PEuUmck0+p3wKH6iDgsXgjmQuu6wO9m1+Y8qB/K+mSwi8gpxjBU38aPCgQrPZnIAbBPpju2NBb241ep+aOlonKQRO+KcsPMwYzLt0xEmkjopq4dRl0i+Nl/m3EVc1JCIslvSD37tUBQIbEpvv7OrXbv37xvY9Cr4JRWrrjrRO6n1d2NSxdagHjwobdBgPCQXGqroMxUNL0EprVmlbRNvWkxmj4wd6PYKfnaQ=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime,CN=H2</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H2</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H2</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>EYQKyMAHRbdf0QdxvZ2qxd7XipQ=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2014-12-03T13:20:06Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H3</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDMxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xNDEyMDQwOTI4MTFaFw0xNzAxMDQwOTI4MTFaMCExCzAJBgNVBAMTAkgzMRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC15sVKLBcJ6NRMFmMZxyBy/kKCcBr8zwozbZ+3cyuKeRk8s2+9IEH0xklpE9MxCmDaW65rpk24aX01A9LvYaM/Jn8bzE9H955wuRTWZbUpW22iljLxjq3x6bM2mwMB/BRkWPK/0BZ8mO1XOXFGh6eRD5OqLXDen3AXno3LgxpibK7jHekfX1aT2G35c2zDcZmif86bQiFSxPxI/xJXiJcswX3Xl1CoEdoyiOhyYIl1756QKzNL/yzXy4W7Fczk5gjax+ke9snndPg/ZnPzKLHJowNyPzobhG0R7W7eG/S7BpxMTEG3alA3BZvV2gmVDw8Bp8t6mNNtxgbWL6fqKQdrAgMBb5cwDQYJKoZIhvcNAQELBQADggEBACyCZSs4DiVR9FvRRUCeXAU4zpvlO2+nlAqL/SnK657aHNbnnQKqtBdoW4N/Gf6Pxz27B7PB1c1p1qgmKzvVewKfwh+37XoCIxqenoLzwALGN0wPne3dVB1Jf8DMEMtECB5ktZMd/BI8fgc6VlYBDnDXa+qu13hbTHYuWV0dIokseNOoNU9twcABn14E0AsEwfalZpXps9LQgjVx609pZwDFRQo3igzY4qKxpivUD0xyrjjsh5UebldLj2K7gtFubrenuQuRerVFIJ82VmNsAdFFzyVsCXdUdULO+wxcnIjCUlAY2l8CEM70z/UXmuCCqnoqPmmXk/oEIdqPLZQqR3c=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime,CN=H3</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H3</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H3</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>QirOC5zp/hiyOrBnqKibCdrnyZ4=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2014-12-04T10:28:11Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H4</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDQxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xNDEyMDUwOTQwMzVaFw0xNzAxMDUwOTQwMzVaMCExCzAJBgNVBAMTAkg0MRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCgdoH5rbrx9r/CkW7gdHjEGtJlVYP9/sF26W0yMVvyEApwXJk9ccM5FNeJlnHO94DQ4jQIYGU8MnFu0Xs8FlrRI47vPikjsdI/HfGW8zQFvPq/CGR2JWtoTW/OS3TLlhuKsgZ4ynsIZs7VrU9H1bk/OyAgtvK3sbdyELF6JYIy0t2mN5kXHPgFYs3PCifQteLEDsYLdxKKtwnEpR8Vyptw/9iNHPsvnqwpa/U5UL0Q/0dF4fxpYNwVdgTKL5bpjaI6I2NmYBdhI8L9aTdEXsP+kSA/+pB5iqNGZ9vlrfweRLsqb8fIILjgIheJwgOKMMTdfIsxfN8nJPr6ICAjd37DAgMBmHswDQYJKoZIhvcNAQELBQADggEBAHh80N8rHNR29mMguKbYl5b6Enhls0VWx/F3oDe+gfZ3p+ASXHPqZG8+e0BwDZh0QykZ3g8etSBL4yOEUi5PEhilECuny++NqFItHheyUXFFJih5qCqP8w+qiseVignIlRH/oumNXMt0HZUeWvh0G43Nc/6OdW2g2OtjUKjQ3WtbNP9Znx+okruUAzOrWpYN0V5PqE5FXrrsslykYb6ou3xThvmkowHddyl3x/koUd1nfra5YUAY9hzfFfUC8SdRg805OSy+EwI+dE006j91dR1EyNKZhqEg1Q5Wb2BGGRXbAYDOGeuX6NE9X+V2gKqD+kauxfz+t2f6lzWEueaexo8=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime,CN=H4</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H4</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H4</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>2zNKmjgO3GbRjbtLb/2gxC95Ydg=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2014-12-05T10:40:35Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
                <TSPService>
                    <ServiceInformation>
                        <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                        <ServiceName>
                            <Name xml:lang="en">H5</Name>
                        </ServiceName>
                        <ServiceDigitalIdentity>
                            <DigitalId>
<X509Certificate>MIICtjCCAZ4CAQEwDQYJKoZIhvcNAQELBQAwITELMAkGA1UEAxMCSDUxEjAQBgNVBAoTCUd1YXJkdGltZTAeFw0xNDEyMDgwOTAzNDdaFw0xNzAxMDgwOTAzNDdaMCExCzAJBgNVBAMTAkg1MRIwEAYDVQQKEwlHdWFyZHRpbWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC60wohNDbrmyAL/7WupGYRFg8sBizryJup1HDV/YJvhVAo7jt63nrzuxqnADeqlzeek2GuYugh5LbYRR8EeBtxE3ssIablc5TLKPZj1hzJ+Tsw39BrbYebQUwusxU+BUclQ9TpxgSAM6eXa5w2pi9o8eiHVMxzXQ5c5BE0XGSSH4IRRoej/xnealXgxNIFvEm14sFvkAg04WQQwD9ZTmWMY80WHeYDFr+v7N520r19GMyTc8YoR8DfWI0lLBYrcG1yDXu6gZlaLD+Xrb633Qn7WRgWD0ejCh9taWbEDBwoc6aM8yZDLfBsExYQSn8RMCcVXZjDZv5k7+IQaozgj0q7AgMBarkwDQYJKoZIhvcNAQELBQADggEBALnzytGvxyDEf8fDaErxIVaZpUcZrWSifiBc3jK3h3PvFTuaY98DT9keY2X1vM9mSeMBusRdMbIkFROA6+uUUNEXlp7lQEoZ9/N1H4vCGscvZWBOua668qw2PrUCQoD5pP1SDH/0JpK4wX+Xk8bdi+Q6cHu2p606r4PBtJVv2oR5y+LaghTC10pT+4+EQ8rDPmseiatvSa9dJdz3RM/bIR+Ki9OO5nBYpPBQJuvDTJ1rfWSfr7JD0ejDOVeG9OfN0j26L/sChV5uZxRMs/mvIlRibHqXU0+oeOGCCsZGb6YN27nLFh5TUdqtGRbJuu3f/8tYNLa7Gb/iI6afpO8nRXc=</X509Certificate>
                            </DigitalId>
                            <DigitalId>
<X509SubjectName>O=Guardtime,CN=H5</X509SubjectName>
                            </DigitalId>
                        </ServiceDigitalIdentity>
                        <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/withdrawn</ServiceStatus>
                        <StatusStartingTime>2016-06-30T22:00:00Z</StatusStartingTime>
                    </ServiceInformation>
                    <ServiceHistory>
                        <ServiceHistoryInstance>
                            <ServiceTypeIdentifier>http://uri.etsi.org/TrstSvc/Svctype/TSA/QTST</ServiceTypeIdentifier>
                            <ServiceName>
<Name xml:lang="en">H5</Name>
                            </ServiceName>
                            <ServiceDigitalIdentity>
<DigitalId>
    <X509SubjectName>O=Guardtime, CN=H5</X509SubjectName>
</DigitalId>
<DigitalId>
    <X509SKI>i8kh3VDj6mI46TJ0BxYTItfimzM=</X509SKI>
</DigitalId>
                            </ServiceDigitalIdentity>
                            <ServiceStatus>http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision</ServiceStatus>
                            <StatusStartingTime>2014-12-08T10:03:47Z</StatusStartingTime>
                        </ServiceHistoryInstance>
                    </ServiceHistory>
                </TSPService>
            </TSPServices>
        </TrustServiceProvider>
    </TrustServiceProviderList>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#" Id="id-16754d1212e0af5f20a8055e453ca217"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><ds:Reference Id="xml_ref_id" Type="" URI=""><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>Ut07j0ml3JoEiQPs5E3wX1barCmLYqT3WyfZTQYIQBQ=</ds:DigestValue></ds:Reference><ds:Reference Type="http://uri.etsi.org/01903#SignedProperties" URI="#xades-id-16754d1212e0af5f20a8055e453ca217"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>InlyS0wbUaKsBp3Ohnh7Z9k3qQxQi9JmxG5Kmdp/Rtk=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue Id="value-id-16754d1212e0af5f20a8055e453ca217">EDldxhimC6fsFROz25QUVXufkiGIz0JKVk/bVBarjR4WE5nHpG4D6M0q5i5kbRC+N8bfdW7nT3IMIwouMFxO7n3hbxVV4YQP4rms9xaWBK+Zfkjrn//Sxh8blTWTJI78XXm3/KMmcaXudqB+nbtKagZqDLNV/CZDKvZhTA/Ch602adQI32VDdTUoAbLD31Aj97MpvImp01n3AMRAy4pXpIPYLv7BVrTtjY5aYe3JJSesCcd3O1/GTuGkS4ueQ0rUyHUPQ8lHUkBI5lHujVuObg33hshlINLBuhfwZVeMo4/IYd4tMTXOHT+ZWNa17thsQXV4R8IEMibez6aRVKgnHw==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIIDsDCCApigAwIBAgIJALEKWhHxTIoZMA0GCSqGSIb3DQEBDQUAMG8xLjAsBgNVBAMMJUVzdG9uaWFuIFRydXN0ZWQgTGlzdCBTY2hlbWUgT3BlcmF0b3IxCzAJBgNVBAYTAkVFMTAwLgYDVQQKDCdFc3RvbmlhbiBUZWNobmljYWwgUmVndWxhdG9yeSBBdXRob3JpdHkwHhcNMTcxMjA0MTEzMTM5WhcNMjcwNjAzMTEzMTM5WjBvMS4wLAYDVQQDDCVFc3RvbmlhbiBUcnVzdGVkIExpc3QgU2NoZW1lIE9wZXJhdG9yMQswCQYDVQQGEwJFRTEwMC4GA1UECgwnRXN0b25pYW4gVGVjaG5pY2FsIFJlZ3VsYXRvcnkgQXV0aG9yaXR5MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzIn9cZEzFbdPY9fWMH1Fla+oc195JcUbKcrTMSX/mi9lgOTKVPxtE9maKwFRtsdrBpAxeJC0QLbBUHmoOc4rwoBi0Z5eo0aIhvOJZWRAjgG3CCPoyVnTyU4N+JT6Z9QLWkg/2jlX3A210bDrEb0o4pzch6PeUXDmU3tWf/H/JvxQSB3BpnleLEjz5gNfeQJc+1WLFj5gS+U4RcIRPAa2Ji3dkb/LL9W6qt0jUTYHgQcnZlolDMaFklJHugB4nO4YfOvuzSc0KEIhOh62J9eKQ/FtZq+7j+1nrhKc2Kmj9mWk0wKV17ZRiAz7BeLrUk3A/cTpaTLTn4uRRiFqXf1JfwIDAQABo08wTTAMBgNVHRMEBTADAgEAMAsGA1UdDwQEAwIHgDAdBgNVHQ4EFgQUZcjaQmAh8bjQ7HL1m4MWZl8fYxYwEQYDVR0lBAowCAYGBACRNwMAMA0GCSqGSIb3DQEBDQUAA4IBAQBom/cEP5HvY7k4hwZYkA+rxI+TcpqmOX8l4cRiYtvLDsy3AnSv9lTZQRBjf3wPq38pnY1sYXNHcJHcWnbSJe45YsCyXojXFhkVm8UtrDdkq3uE4K3TqP/Ep+7xPNm8srJ5B8pmU13/T5cYTkeHVyH2SwGUS6pW8VYj/kZ1V17GQHtDKR7iQHfiS/ltOWcdIm+Sq3/D5its5wTQPPxExNg6MvdUMB5xZJId+cfPvz4sXXBCqQmfnkEC1xbOSC1+pU0PjWnyzZDPe8wYfIrYblNk57nF+GgWlDIeMWZqNszaBqaxebZSIPZKs+Cq8q+yElE6qUst4f2CPCHl2dtKag9D</ds:X509Certificate></ds:X509Data></ds:KeyInfo><ds:Object><xades:QualifyingProperties xmlns:xades="http://uri.etsi.org/01903/v1.3.2#" Target="#id-16754d1212e0af5f20a8055e453ca217"><xades:SignedProperties Id="xades-id-16754d1212e0af5f20a8055e453ca217"><xades:SignedSignatureProperties><xades:SigningTime>2018-11-09T13:01:46Z</xades:SigningTime><xades:SigningCertificate><xades:Cert><xades:CertDigest><ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><ds:DigestValue>hIS1stdSbJLpfk7FG/vyN3HkyPg=</ds:DigestValue></xades:CertDigest><xades:IssuerSerial><ds:X509IssuerName>O=Estonian Technical Regulatory Authority,C=EE,CN=Estonian Trusted List Scheme Operator</ds:X509IssuerName><ds:X509SerialNumber>12757107927589620249</ds:X509SerialNumber></xades:IssuerSerial></xades:Cert></xades:SigningCertificate></xades:SignedSignatureProperties><xades:SignedDataObjectProperties><xades:DataObjectFormat ObjectReference="#xml_ref_id"><xades:MimeType>text/xml</xades:MimeType></xades:DataObjectFormat></xades:SignedDataObjectProperties></xades:SignedProperties></xades:QualifyingProperties></ds:Object></ds:Signature></TrustServiceStatusList>