NZRS CA Chain (used for both Legacy SRS and the IRS)

Our Legacy SRS, EPP and Rest API services and also the new IRS EPP and TBR make use of the internal NZRS CA chain, which you will need installed if you intend to validate your SSL/TLS connection to SRS.

If you are attempting to connect to us via the EPP protocol then you will need a client certificate signed by this certificate authority, please contact registry@internetnz.net.nz with your CSR.

CA Installation

The following instructions are for a Ubuntu/Debian box:

  • Copy the root cert in PEM format to: /usr/local/share/ca-certificates/srs_ca_root.crt

  • Run update-ca-certificates