Our SRS, EPP and Rest API services make use of the internal NZRS CA chain, which you will need installed if you intend to validate your SSL/TLS connection to SRS.

If you are attempting to connect to us via the EPP protocol then you will need a client certificate signed by this certificate authority, please contact with your CSR.

CA Installation

The following instructions are for a Ubuntu/Debian box:

  • Copy the root cert in PEM format to: /usr/local/share/ca-certificates/srs_ca_root.crt
  • Run update-ca-certificates


NZRS Root CA (2012)


The root CA listed above should be all that is necessary to validate certificates signed by the NZRS CA, and the issuing CAs listed below are for reference only.