Modules / PRU / M11

Solo & Team plansPublic overview - no login to view

PKI & Certificate Chain

Module M11 · Passenger RU journey · 5 scenario questions

Set up the certificate chain for secure exchange.

Assessment scope

Step 11 - PKI & Certificate Chain. Secure message exchange via the Common Interface rests on a certification chain that ERA TD-106 articulates on three levels: the organisation root CA certificate (ORCAC), issued for your organisation by a certification authority listed in ERA's common central repository; an operational issuing CA certificate; and the leaf certificates. Any full chain contains at least three certificates, though an internal issuing CA is at the organisation's discretion. TD-106 Table 3 names the leaf types - among them the Operator Non-safety Communication Certificate (ONCC) for RU/IM and RU/RU communication, the Operator Safety Communication Certificate (OSCC), the Operator ticketing Certificate (OTC) for ticketing security elements, and the Operator database access certificate (ODTAC) for reference-database access. TEL TSI Art. 7(2) and TD-106 define four distinct use cases - keeping certificates separated per use case limits the blast radius of any single compromise. Certificate expiry must be actively managed.

Governing articles & annex points

The 5 questions in this module are judged against these provisions of Commission Implementing Regulation (EU) 2026/253. Each reference opens the official text in the EU Official Journal on EUR-Lex.

Source transparency: inside the assessment, every verdict cites its exact article or annex point - the references above are extracted from this module’s question set, not written for marketing.

TSI Solution GmbH checked this content against the Official Journal text on .