Smile certificate authority

If you saw a security warning just before visiting this web page, stop reading now, and ask a system administrator for help.

Ever seen this ?

ieerror.jpg
firefoxerror.jpg
chromeerror.jpg

You are NEVER supposed to see these messages when accessing a Smile URL. DO NOT FORCE YOUR WEB BROWSER TO CONTINUE

There is a way to fix those errors permanently for all Smile websites (Intranet, Wiki, etc.)

How do I fix it

Renewed in September 2026

The root certificate was re-signed on 2026-09-17 with the same key: it now expires on 2029-12-30 instead of 2026-10-04. If you installed the previous file before that date, install this one again; it replaces the old entry. Verify the download with its SHA-256 fingerprint:

FC:E0:92:73:9A:2D:FA:C7:7E:89:D2:28:A6:68:C7:F6:A9:3C:E5:54:A0:27:C9:97:6C:A2:F0:A8:31:70:20:7B

More information on the wiki

Follow those instructions :

Chrome (Windows)

windowsadd1.jpg
windowsadd2.jpg
windowsadd3.jpg
windowsadd4.jpg
windowsadd5.jpg
windowsadd6.jpg
windowsadd7.jpg
windowsadd8.jpg
windowsadd9.jpg

Close and reopen your web browser

Firefox

firefoxadd1.jpg

Chrome (Linux)

Download the smile2016.crt file to your home directory


Go to the SSL settings (chrome://settings/certificates)


chromeadd1.jpg
chromeadd2.jpg

Select the smile2016.crt file you just downloaded


chromeadd3.jpg

For system administrators

Servers need the root in their trust store and, for their own certificate, the issuing intermediate.

FileWhat it is
smile-root-ca-g2.crtSmile Root CA G2, trust anchor, valid to 2029-12-30. Named after the key generation, not the year: the 2026 renewal kept the key, so the file identity did not change.
smile2016.crt / ca2016.pemSame root under its historical names. Kept because ca2016.pem is the AIA URL inside every issued certificate and smile2016.crt is the path on existing servers.
smile-ssl-ca-g3.crtSmile SSL CA G3, the issuing CA since September 2026 (OpenBao, ACME), valid to 2029-09-16
smile-chain-g3.pemG3 intermediate + root, ready for ssl_trusted_certificate / SSLCertificateChainFile
smile-ssl-ca-g2.crt (also smile-ssl.crt)Smile SSL CA G2, the previous issuing CA; certificates it signed stay valid until 2027-07-19
SHA256SUMSchecksums of the files above

Debian / Ubuntu:

curl -fsSLo /usr/local/share/ca-certificates/smile2016.crt https://pki.smile.fr/smile2016.crt
update-ca-certificates

Windows (elevated prompt):

certutil -addstore -f Root smile2016.crt

New server certificates are issued automatically over ACME from the internal CA; ask the DSI team for the directory URL and the role for your DNS zone. Intermediate G3 fingerprint (SHA-256):

52:2B:3C:AC:9B:C4:E0:8F:EA:E1:5E:98:FE:93:30:C7:4E:6D:99:93:CC:E4:EB:51:F3:36:7C:63:B3:AA:FB:C7