Registration authority (RA)

Registration Authority (RA): the PKI party that verifies applicant identity and attributes, then passes verified data to the CA for certificate issuance.

A Registration Authority is the party in a PKI that establishes and verifies the identity of an applicant before a certificate is issued. It carries out identity verification, checks supporting documents, and confirms that the applicant is entitled to the attributes claimed, such as a name or organisational role. Under eIDAS and ETSI standards such as ETSI TS 119 461 (v2.1.1 since February 2025), this identity proofing can be done through methods including face-to-face verification, use of an existing eID means, or remote identity verification. The standard lets the trust service provider do it itself or leave it to a specialised identity proofing service provider (IPSP) working as its subcontractor, which is the term the ETSI text uses for that party. The RA then passes its findings to the Certificate Authority (CA), which issues the certificate based on that confirmed identity.

Frequently asked questions

Back to glossary