Peppol PKI Migration 2025 – From MPKI8 to DOTL
The Peppol community is entering a major transition in 2025 H2, as every Peppol Service Provider must migrate from:
๐ DigiCert Managed PKI v8 (MPKI8) CA chain → to DigiCert One Trust Lifecycle (DOTL) CA chain
โ
โWhat This Means
๐All existing MPKI8 certificates must be replaced with DOTL certificates.
๐OpenPeppol will issue production certificates under DOTL only after Service Providers:
โ
Obtain a test certificate from DOTL
โ
Successfully demonstrate dual-capability (MPKI8 & DOTL) conformance in the Peppol Testbed
โ
โKey Migration Timelines
๐ T0 (11 Aug 2025 onward)
โ
DOTL CA chain available
โ
Service Providers can obtain DOTL test certificates
๐ T1 (11 Feb 2026 - 6-months transition period)
โ
Mandatory dual capability (support both MPKI8 & DOTL)
๐ T2 (1 Apr 2026)
โ
MPKI8 certificates revoked
โ
DOTL becomes the only trusted CA chain
โโ
โ
Oxalis Support
โ๏ธ Oxalis-NG v1.2.0 → Dual-capability (MPKI8 & DOTL)
๐ More details in Oxalis-NG WIKI: https://github.com/OxalisCommunity/oxalis-ng/wiki/Peppol-PKI-2025-%E2%80%90-MPKI8-to-DOTL
โโ
โ๏ธ Oxalis 7.2.0 and Oxalis-AS4 7.2.0 → Dual-capability (MPKI8 & DOTL)
๐ More details in Oxalis WIKI: https://github.com/OxalisCommunity/oxalis/wiki/Peppol-PKI-2025-%E2%80%90-MPKI8-to-DOTL
References & Guidance
๐ Peppol PKI 2025 – Parent Page – Peppol PKI 2025 - 1. OpenPEPPOL Members Area - Confluence
๐ Dedicated Migration Guideline – Peppol PKI 2025 - Dedicated Migration Guideline - 1. OpenPEPPOL Members Area - Confluence
๐ Certificate Authority Migration Plan – Peppol PKI 2025 - Certificate Authority Migration Plan - 1. OpenPEPPOL Members Area - Confluence
๐ Certificate Authorities – Peppol PKI 2025 - Certificate Authorities - 1. OpenPEPPOL Members Area - Confluence
๐ Issuing & Enrolment Process – Peppol PKI 2025 - Issuing and Enrolment Process - 1. OpenPEPPOL Members Area - Confluence
๐ฅ Webinar: Peppol PKI 2025 – Peppol PKI 2025 - Webinar - 1. OpenPEPPOL Members Area - Confluence
โก This migration is time critical. Service Providers should plan ahead, enable dual capability early, and ensure seamless conformance testing before production rollout.
โ
โ
