Set up the certificate chain for secure exchange.
Assessment scope
Step 11 - PKI & Certificate Chain. Secure message exchange via the Common Interface rests on a certification chain that ERA TD-106 articulates on three levels: the organisation root CA certificate (ORCAC), issued for your organisation by a certification authority listed in ERA's common central repository; an operational issuing CA certificate; and the leaf certificates. Any full chain contains at least three certificates, though an internal issuing CA is at the organisation's discretion. TD-106 Table 3 names the leaf types - among them the Operator Non-safety Communication Certificate (ONCC) for RU/IM and RU/RU communication, the Operator Safety Communication Certificate (OSCC), the Operator ticketing Certificate (OTC) for ticketing security elements, and the Operator database access certificate (ODTAC) for reference-database access. TEL TSI Art. 7(2) and TD-106 define four distinct use cases - keeping certificates separated per use case limits the blast radius of any single compromise. Certificate expiry must be actively managed.
Governing articles & annex points
The 5 questions in this module are judged against these provisions of Commission Implementing Regulation (EU) 2026/253. Each reference opens the official text in the EU Official Journal on EUR-Lex.
Source transparency: inside the assessment, every verdict cites its exact article or annex point - the references above are extracted from this module’s question set, not written for marketing.