Meraki Authentication Server Certificate Rotation - July 2025
Overview
As part of a standard yearly server certificate rotation to maintain Meraki Cloud Radius authentication security, Meraki rotates the RADIUS server certificate used for Meraki Cloud Authentication. The certificate in question is called Cisco Meraki Radius {year} with the common name radius.meraki.com. Clients must trust this certificate for Meraki Cloud Authentication. The following is the expected impact and remediation steps of this yearly rotation.
The common name of the certificate will remain radius.meraki.com between rotations. If clients can remain trusting this service certificate common name there should be no impact from this certificate transition.
Recommended Remediation Actions for Various Deployment Scenarios
Meraki Authentication with Sentry Wi-Fi
Devices with Meraki Authentication with Systems Manager Sentry Wi-Fi that were online sometime after July 1, 2025 and before July 22, 2025, 01:30 UTC will have no impact.
For users with devices that were not online during this period, such devices will need to associate with an SSID which will allow them to check in with the dashboard for long enough to allow a check-in cycle to complete (~2 minutes) and receive the updated payload, and resume normal operation. Users can verify the payload is working by attempting to connect to the original Meraki Sentry Wi-Fi enabled SSID.
Note: Windows 10 and 11 users may need to select the appropriate certificate during the rotation process. Select the appropriate "SCEP Wi-Fi Certificate for {device_id}" and click OK.
Meraki Authentication without Sentry Wi-Fi
Users of Meraki Authentication via certificate-based authentication without Sentry Wi-Fi will need to 'trust' the new certificate with the below information upon associating to the Meraki Authentication SSID.
Host: radius.meraki.com
Issued: DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires: Jul 29 23:59:59 2025 GMT
Note: Some devices may require the SSID to be "forgotten" before they will be prompted to accept the new certificate.
Note: See the Meraki Authentication Radius Certificate below for the new certificate.
Trusted Access
Users of a Trusted Access configuration to an SSID will need to re-download their device's Trusted Access configuration from portal.meraki.com on or after the rotation date.
FAQs
1. What is changing?
Due to an approaching certificate expiration, Meraki will be rotating the RADIUS certificate for Meraki Cloud Authentication on July 22, 2025. This rotation is a standard yearly action taken to maintain Meraki Authentication security.
In some Systems Manager (SM) deployments, devices will automatically receive the new certificate and no further action will likely be required. However, there are certain deployment scenarios that may require action to be taken.
2. How can an affected network be identified?
Any services relying on Meraki Cloud Authentication via certificates will be affected. This includes Sentry Wi-Fi, Trusted Access Wi-Fi, and any manual authentication relying on Meraki Cloud Authentication via certificates.
3. Which network deployment scenarios require action to be taken?
Only SSIDs with Meraki Cloud Authentication using the RADIUS certificate for authentication will be affected.
If you are using this certificate for Meraki Cloud Authentication and have a network with any of the following deployment scenarios, your action may be required to manually accept the new certificate:
-
If you have non-Systems Manager (SM) deployment networks
-
If you utilize Meraki Authentication with Sentry Wi-Fi, but had devices offline before the rotation date
-
If you utilize a Trusted Access configuration to an SSID
Please refer to our documentation (above) for further network identification details and next steps.
4. Is there an action needed to maintain connectivity?
If your network is affected, you need to accept the new certificate for your devices before July 22, 2025, 01:30 UTC to maintain connectivity. Please refer to our documentation above for more information.
5. What happens if no action is taken by the certificate rotation date?
If devices are still using the outdated RADIUS certificate after July 22, 2025, they will not be able to connect back to the Meraki Cloud Authentication SSID until the new certificate is accepted. Please see our documentation (above) for more details and a list of recommended actions for avoiding impact on device connectivity.
6. Will this affect username or password authentication with Meraki Authentication?
If you are using Meraki Cloud Authentication with username/ password authentication (such as PEAP) will be prompted to 'trust' the new radius.meraki.com server certificate after the rotation date.
If you are using certificate-based authentication (such as EAP-TLS) where this RADIUS Meraki Cloud Authentication certificate is used, you will need to accept the new certificate before July 22, 2025, 01:30 UTC.
7. Where can I go if I need additional assistance?
If you have additional questions or need assistance, please contact Meraki Technical Support.
Open a case via:
-
Call your localized support line, which can be found at the bottom of the Meraki Technical Support webpage.
Certificate Details
Below is a copy of the certificate which users will be required to accept, as well as the plaintext output from reading the certificate with openssl:
openssl x509 -noout -text -in radius.meraki.com.2025.cert Certificate: Data: Version: 3 (0x2) Serial Number: 04:b6:2d:b9:c4:0b:75:9d:8d:24:a3:03:86:fa:75:f8 Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 Validity Not Before: Jul 1 00:00:00 2025 GMT Not After : Aug 1 23:59:59 2026 GMT Subject: C=US, ST=California, L=San Francisco, O=Meraki LLC, CN=radius.meraki.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (4096 bit) Modulus: 00:da:7d:f4:b4:ae:72:d8:cd:6b:5f:04:78:41:ab: e9:14:97:a3:d0:77:af:c1:ef:f1:24:ab:cc:41:a2: e6:44:fc:9a:4d:54:5c:26:45:a1:b6:aa:19:f2:dd: 1b:cd:8e:a0:2c:21:2c:bd:77:93:ea:86:7a:8e:85: a0:e4:15:c9:37:2c:3d:fa:0a:9f:c2:3a:69:b2:42: a1:45:57:fc:f4:16:5c:06:3f:66:25:4d:4c:f2:28: a0:9d:b2:e8:f5:c1:53:a0:c2:b1:ee:06:94:e5:c3: d8:1c:b2:bb:36:bc:e4:2e:31:31:ef:dc:16:c6:28: b5:d2:31:86:be:6e:7f:93:c6:f6:2e:62:7e:69:84: 7c:5d:f4:4a:47:d5:e6:72:a2:b0:d4:c6:54:a7:83: cf:87:08:40:7a:2c:7d:89:98:72:a4:b0:c3:ee:13: 09:5f:19:90:f2:78:2e:dd:60:5c:0b:29:4a:2f:9c: 02:4b:3e:33:20:61:0f:f7:40:fe:f0:36:2f:e9:8f: 99:aa:49:c2:32:e5:b6:df:75:f9:66:c8:dc:1a:8e: 63:f6:9a:c1:fb:68:62:e8:2f:ac:22:01:f7:73:9f: 2b:11:a3:3b:78:86:27:85:f4:a3:d3:cd:b6:87:64: 78:2c:00:ba:4b:36:0f:b0:4f:6e:1e:af:e5:8d:7e: 3d:ed:b4:5c:df:4e:d3:bd:4b:83:48:13:d2:c5:e6: 97:21:8b:46:53:04:79:04:c9:d8:79:c3:c0:5e:1f: fb:f8:41:f9:c4:e1:bd:07:17:8b:87:d9:20:34:6d: c1:14:35:55:df:7a:ef:ef:7e:58:a4:c2:d8:76:27: 17:93:44:74:c0:8d:66:23:92:52:74:53:d3:23:8c: b9:45:27:7a:44:85:94:9a:01:70:6c:ce:86:6b:4c: 2e:fe:23:77:76:3b:50:8f:1e:c3:f7:f3:5e:6a:89: 54:c5:92:1d:c9:a2:79:ce:47:13:49:78:3f:61:01: 3a:8c:86:60:ff:e0:14:dd:49:e8:8d:b3:32:36:f5: 28:f9:e2:58:38:b4:26:44:47:70:3c:9a:70:ef:11: 6c:33:49:ba:10:19:ee:35:79:e3:35:c9:6a:ff:10: 90:41:d7:87:46:37:79:2b:f0:b9:a6:71:ad:7e:cf: ba:ec:3c:59:ea:c2:33:2b:cc:72:8c:6d:c2:e1:7f: a9:b9:80:7c:16:31:ca:e5:4d:90:c3:04:05:74:ca: c6:81:54:dd:66:4f:21:36:06:fb:72:26:b1:34:c7: 24:c1:83:66:1f:fb:a0:a1:d8:36:72:7e:db:4c:4e: 2b:79:9a:f0:fc:89:d9:e1:7c:9d:6e:5e:b7:63:0a: c4:3d:13 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: 74:85:80:C0:66:C7:DF:37:DE:CF:BD:29:37:AA:03:1D:BE:ED:CD:17 X509v3 Subject Key Identifier: 0F:7F:02:89:0A:8C:F4:7C:5A:FD:25:E1:DF:0F:53:29:1B:0A:CE:61 X509v3 Subject Alternative Name: DNS:radius.meraki.com X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CPS: http://www.digicert.com/CPS X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 CRL Distribution Points: Full Name: URI:http://crl3.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl Full Name: URI:http://crl4.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl Authority Information Access: OCSP - URI:http://ocsp.digicert.com CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt X509v3 Basic Constraints: critical CA:FALSE CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9: 82:C9:33:5A:65:E1:D0:B3:01:73:17:C0:C8:C5:69:77 Timestamp : Jul 1 17:52:41.241 2025 GMT Extensions: none Signature : ecdsa-with-SHA256 30:44:02:20:25:48:82:3E:E0:B9:60:A9:D3:39:4C:6C: 25:58:70:D1:9E:86:94:7D:B4:FC:29:82:C9:B6:7C:09: 04:91:28:9D:02:20:28:72:DF:FC:B2:68:FA:E2:56:B0: 2E:70:12:7B:61:A3:9D:11:F7:BB:11:CB:FF:EC:3A:44: 78:7A:1D:DA:FC:91 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB: C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD Timestamp : Jul 1 17:52:41.303 2025 GMT Extensions: none Signature : ecdsa-with-SHA256 30:44:02:20:50:DF:AA:E1:82:2D:C1:25:96:78:08:68: 62:43:39:36:AE:CD:FD:DB:2F:E8:B2:83:75:FD:78:63: D9:46:54:BA:02:20:2D:9C:F3:B7:5C:5E:31:22:D4:D7: 95:56:04:63:94:32:7A:3A:F9:48:92:9B:CB:82:85:BB: 38:73:B8:E6:B7:6D Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65: 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8 Timestamp : Jul 1 17:52:41.320 2025 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:6D:3B:A8:20:5A:B9:38:DC:7E:98:C5:EC: A7:14:C6:53:F0:81:C1:01:5C:23:2D:0D:C8:54:1D:CB: 03:2C:FB:FA:02:21:00:F9:C6:9D:0A:01:A8:3B:FE:B1: C5:97:52:78:40:28:3C:E4:0D:1D:FF:C7:F9:6A:9A:09: 64:D6:EB:C0:CA:23:6E Signature Algorithm: sha256WithRSAEncryption Signature Value: 7b:4b:23:f1:8a:f0:98:9a:8d:fb:f0:d5:c3:09:c1:16:1b:75: da:f4:13:fa:7a:2b:09:7f:57:db:13:f2:57:2f:32:c4:bb:1a: 8d:ef:28:6d:ab:36:44:cc:20:30:1d:b2:00:3f:e5:19:b1:20: 08:09:8c:b0:e5:14:57:c9:01:38:68:b2:ea:0d:96:d2:9a:bf: cf:2f:bd:1d:0d:47:69:d5:7c:57:4e:ec:12:5d:8c:8f:f4:a7: de:b9:96:0b:bc:33:01:d6:45:d3:05:9b:80:21:ed:26:c2:25: 53:3e:94:67:2e:86:5f:eb:4d:0f:77:6a:0e:5d:33:6a:44:90: a5:10:cf:20:eb:a8:73:c1:e9:09:4c:6b:d2:f3:c4:96:2d:64: 42:f8:7d:d5:cc:63:00:53:9a:68:96:c5:4e:5f:86:09:29:36: de:12:6f:9b:19:1d:fe:bc:c4:4f:52:55:f7:a6:09:38:ac:e1: 4f:22:da:76:f2:28:54:70:c0:6a:48:10:74:13:08:ae:e5:9b: 31:70:17:45:6b:3e:10:9b:90:e5:b2:6f:c1:57:14:15:ef:4a: 21:1e:57:e4:1e:79:0f:b0:5c:78:ef:7e:8f:c7:fb:3b:c0:ad: 90:e7:4d:05:70:2a:7d:9a:26:5b:0c:38:75:05:21:5d:c2:2f: b3:dd:11:07
#Meraki Authentication Radius Certificate-----BEGIN CERTIFICATE----- MIIH2zCCBsOgAwIBAgIQBLYtucQLdZ2NJKMDhvp1+DANBgkqhkiG9w0BAQsFADBZ MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMTMwMQYDVQQDEypE aWdpQ2VydCBHbG9iYWwgRzIgVExTIFJTQSBTSEEyNTYgMjAyMCBDQTEwHhcNMjUw NzAxMDAwMDAwWhcNMjYwODAxMjM1OTU5WjBrMQswCQYDVQQGEwJVUzETMBEGA1UE CBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzETMBEGA1UEChMK TWVyYWtpIExMQzEaMBgGA1UEAxMRcmFkaXVzLm1lcmFraS5jb20wggIiMA0GCSqG SIb3DQEBAQUAA4ICDwAwggIKAoICAQDaffS0rnLYzWtfBHhBq+kUl6PQd6/B7/Ek q8xBouZE/JpNVFwmRaG2qhny3RvNjqAsISy9d5PqhnqOhaDkFck3LD36Cp/COmmy QqFFV/z0FlwGP2YlTUzyKKCdsuj1wVOgwrHuBpTlw9gcsrs2vOQuMTHv3BbGKLXS MYa+bn+TxvYuYn5phHxd9EpH1eZyorDUxlSng8+HCEB6LH2JmHKksMPuEwlfGZDy eC7dYFwLKUovnAJLPjMgYQ/3QP7wNi/pj5mqScIy5bbfdflmyNwajmP2msH7aGLo L6wiAfdznysRozt4hieF9KPTzbaHZHgsALpLNg+wT24er+WNfj3ttFzfTtO9S4NI E9LF5pchi0ZTBHkEydh5w8BeH/v4QfnE4b0HF4uH2SA0bcEUNVXfeu/vflikwth2 JxeTRHTAjWYjklJ0U9MjjLlFJ3pEhZSaAXBszoZrTC7+I3d2O1CPHsP3815qiVTF kh3JonnORxNJeD9hATqMhmD/4BTdSeiNszI29Sj54lg4tCZER3A8mnDvEWwzSboQ Ge41eeM1yWr/EJBB14dGN3kr8Lmmca1+z7rsPFnqwjMrzHKMbcLhf6m5gHwWMcrl TZDDBAV0ysaBVN1mTyE2BvtyJrE0xyTBg2Yf+6Ch2DZyfttMTit5mvD8idnhfJ1u XrdjCsQ9EwIDAQABo4IDizCCA4cwHwYDVR0jBBgwFoAUdIWAwGbH3zfez70pN6oD Hb7tzRcwHQYDVR0OBBYEFA9/AokKjPR8Wv0l4d8PUykbCs5hMBwGA1UdEQQVMBOC EXJhZGl1cy5tZXJha2kuY29tMD4GA1UdIAQ3MDUwMwYGZ4EMAQICMCkwJwYIKwYB BQUHAgEWG2h0dHA6Ly93d3cuZGlnaWNlcnQuY29tL0NQUzAOBgNVHQ8BAf8EBAMC BaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMIGfBgNVHR8EgZcwgZQw SKBGoESGQmh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbEcy VExTUlNBU0hBMjU2MjAyMENBMS0xLmNybDBIoEagRIZCaHR0cDovL2NybDQuZGln aWNlcnQuY29tL0RpZ2lDZXJ0R2xvYmFsRzJUTFNSU0FTSEEyNTYyMDIwQ0ExLTEu Y3JsMIGHBggrBgEFBQcBAQR7MHkwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRp Z2ljZXJ0LmNvbTBRBggrBgEFBQcwAoZFaHR0cDovL2NhY2VydHMuZGlnaWNlcnQu Y29tL0RpZ2lDZXJ0R2xvYmFsRzJUTFNSU0FTSEEyNTYyMDIwQ0ExLTEuY3J0MAwG A1UdEwEB/wQCMAAwggF8BgorBgEEAdZ5AgQCBIIBbASCAWgBZgB1ANdtfRDRp/V3 wsfpX9cAv/mCyTNaZeHQswFzF8DIxWl3AAABl8cemxkAAAQDAEYwRAIgJUiCPuC5 YKnTOUxsJVhw0Z6GlH20/CmCybZ8CQSRKJ0CIChy3/yyaPriVrAucBJ7YaOdEfe7 Ecv/7DpEeHod2vyRAHUAwjF+V0UZo0XufzjespBB68fCIVoiv3/Vta12mtkOUs0A AAGXxx6bVwAABAMARjBEAiBQ36rhgi3BJZZ4CGhiQzk2rs392y/osoN1/Xhj2UZU ugIgLZzzt1xeMSLU15VWBGOUMno6+UiSm8uChbs4c7jmt20AdgCUTkOH+uzB74Hz GSQmqBhlAcfTXzgCAT9yZ31VNy4Z2AAAAZfHHptoAAAEAwBHMEUCIG07qCBauTjc fpjF7KcUxlPwgcEBXCMtDchUHcsDLPv6AiEA+cadCgGoO/6xxZdSeEAoPOQNHf/H +WqaCWTW68DKI24wDQYJKoZIhvcNAQELBQADggEBAHtLI/GK8Jiajfvw1cMJwRYb ddr0E/p6Kwl/V9sT8lcvMsS7Go3vKG2rNkTMIDAdsgA/5RmxIAgJjLDlFFfJATho suoNltKav88vvR0NR2nVfFdO7BJdjI/0p965lgu8MwHWRdMFm4Ah7SbCJVM+lGcu hl/rTQ93ag5dM2pEkKUQzyDrqHPB6QlMa9LzxJYtZEL4fdXMYwBTmmiWxU5fhgkp Nt4Sb5sZHf68xE9SVfemCTis4U8i2nbyKFRwwGpIEHQTCK7lmzFwF0VrPhCbkOWy b8FXFBXvSiEeV+QeeQ+wXHjvfo/H+zvArZDnTQVwKn2aJlsMOHUFIV3CL7PdEQc= -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIIEyDCCA7CgAwIBAgIQDPW9BitWAvR6uFAsI8zwZjANBgkqhkiG9w0BAQsFADBh MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3 d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH MjAeFw0yMTAzMzAwMDAwMDBaFw0zMTAzMjkyMzU5NTlaMFkxCzAJBgNVBAYTAlVT MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxMzAxBgNVBAMTKkRpZ2lDZXJ0IEdsb2Jh bCBHMiBUTFMgUlNBIFNIQTI1NiAyMDIwIENBMTCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBAMz3EGJPprtjb+2QUlbFbSd7ehJWivH0+dbn4Y+9lavyYEEV cNsSAPonCrVXOFt9slGTcZUOakGUWzUb+nv6u8W+JDD+Vu/E832X4xT1FE3LpxDy FuqrIvAxIhFhaZAmunjZlx/jfWardUSVc8is/+9dCopZQ+GssjoP80j812s3wWPc 3kbW20X+fSP9kOhRBx5Ro1/tSUZUfyyIxfQTnJcVPAPooTncaQwywa8WV0yUR0J8 osicfebUTVSvQpmowQTCd5zWSOTOEeAqgJnwQ3DPP3Zr0UxJqyRewg2C/Uaoq2yT zGJSQnWS+Jr6Xl6ysGHlHx+5fwmY6D36g39HaaECAwEAAaOCAYIwggF+MBIGA1Ud EwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFHSFgMBmx9833s+9KTeqAx2+7c0XMB8G A1UdIwQYMBaAFE4iVCAYlebjbuYP+vq5Eu0GF485MA4GA1UdDwEB/wQEAwIBhjAd BgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwdgYIKwYBBQUHAQEEajBoMCQG CCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdpY2VydC5jb20wQAYIKwYBBQUHMAKG NGh0dHA6Ly9jYWNlcnRzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RH Mi5jcnQwQgYDVR0fBDswOTA3oDWgM4YxaHR0cDovL2NybDMuZGlnaWNlcnQuY29t L0RpZ2lDZXJ0R2xvYmFsUm9vdEcyLmNybDA9BgNVHSAENjA0MAsGCWCGSAGG/WwC ATAHBgVngQwBATAIBgZngQwBAgEwCAYGZ4EMAQICMAgGBmeBDAECAzANBgkqhkiG 9w0BAQsFAAOCAQEAkPFwyyiXaZd8dP3A+iZ7U6utzWX9upwGnIrXWkOH7U1MVl+t wcW1BSAuWdH/SvWgKtiwla3JLko716f2b4gp/DA/JIS7w7d7kwcsr4drdjPtAFVS slme5LnQ89/nD/7d+MS5EHKBCQRfz5eeLjJ1js+aWNJXMX43AYGyZm0pGrFmCW3R bpD0ufovARTFXFZkAdl9h6g4U5+LXUZtXMYnhIHUfoyMo5tS58aI7Dd8KvvwVVo4 chDYABPPTHPbqjc1qCmBaZx2vN4Ye5DUys/vZwP9BFohFrH/6j/f3IL16/RZkiMN JCqVJUzKoZHm1Lesh3Sz8W2jmdv51b2EQJ8HmA== -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIIDjjCCAnagAwIBAgIQAzrx5qcRqaC7KGSxHQn65TANBgkqhkiG9w0BAQsFADBh MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3 d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH MjAeFw0xMzA4MDExMjAwMDBaFw0zODAxMTUxMjAwMDBaMGExCzAJBgNVBAYTAlVT MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j b20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IEcyMIIBIjANBgkqhkiG 9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuzfNNNx7a8myaJCtSnX/RrohCgiN9RlUyfuI 2/Ou8jqJkTx65qsGGmvPrC3oXgkkRLpimn7Wo6h+4FR1IAWsULecYxpsMNzaHxmx 1x7e/dfgy5SDN67sH0NO3Xss0r0upS/kqbitOtSZpLYl6ZtrAGCSYP9PIUkY92eQ q2EGnI/yuum06ZIya7XzV+hdG82MHauVBJVJ8zUtluNJbd134/tJS7SsVQepj5Wz tCO7TG1F8PapspUwtP1MVYwnSlcUfIKdzXOS0xZKBgyMUNGPHgm+F6HmIcr9g+UQ vIOlCsRnKPZzFBQ9RnbDhxSJITRNrw9FDKZJobq7nMWxM4MphQIDAQABo0IwQDAP BgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQUTiJUIBiV 5uNu5g/6+rkS7QYXjzkwDQYJKoZIhvcNAQELBQADggEBAGBnKJRvDkhj6zHd6mcY 1Yl9PMWLSn/pvtsrF9+wX3N3KjITOYFnQoQj8kVnNeyIv/iPsGEMNKSuIEyExtv4 NeF22d+mQrvHRAiGfzZ0JFrabA0UWTW98kndth/Jsw1HKj2ZL7tcu7XUIOGZX1NG Fdtom/DzMNU+MeKNhJ7jitralj41E6Vf8PlwUHBHQRFXGU7Aj64GxJUTFy8bJZ91 8rGOmaFvE7FBcf6IKshPECBV1/MUReXgRPTqh5Uykw7+U0b6LJ3/iyK5S9kJRaTe pLiaWN0bfVKfjllDiIGknibVb63dDcY3fe0Dkhvld1927jyNxF1WW6LZZm6zNTfl MrY= -----END CERTIFICATE-----