DIGITAL CERTIFICATE ISSUANCE SERVICE
Security Document Library
Home to all your cable certificate needs
CableLabs manages specifications that require embedding digital certificates into devices at the time of manufacture. The certificates provide the basis for data confidentiality, content integrity, and hardware authentication. The Digital Certificate Issuance Service provides easy to use, web-based accounts to help vendors obtain bulk certificate orders for their cable devices.
For any questions, please contact the PKI Operations Team at: [email protected]
DOCSIS® PKI Certificates and Where They Are Used
DOCSIS PKI certificates are used throughout the network to secure communications between network components and customer premise equipment (CPE). Use this document to help your team to identify where and how to deploy DOCSIS PKI certificates on various network devices and to determine the price for the certificates you need.
Security Documents
Common PKI Documents
User Guides
- CommScope PKI Works User Guide
- Digicert ONE User Guide – IOT | Digicert ONE User Guide – DTM
- Sectigo User Guide
Agreements
Digital Certificate Authorization Agreement –If you are a new customer, complete this form in addition to only the necessary naming document(s) listed below.
Naming Documents
If you are a new or existing customer, complete a naming document for each account type requested. Click on the icon to download the correct form for your provider. For more details on the certificate types, see the Onboarding and Delivery Process document (noted above) and/or contact [email protected].
Test Certificates
- TEST DOCSIS 3.0 or Earlier (1st Gen PKI) – TEST CA and steps to issue TEST device certs
- TEST DOCSIS 3.1 (2nd Gen PKI) – TEST CA and steps to issue TEST device certs
- TEST DOCSIS 4.0 (2nd Gen PKI) – TEST CA and steps to issue TEST device certs
- TEST Remote PHY (2nd Gen PKI) – TEST CA and steps to issue TEST device certs
- TEST EuroDOCSIS – TEST CA and steps to issue TEST device certs
Production CA Certificates
(Root CAs included in all packages)
DOCSIS 3.0 of Earlier CA Certificates (1st Gen PKI)
- CA01 – DigiCert (DCS)
- CA03 V2 EXT – DigiCert (DigiCertOne) – 2049 expiration
- CA03 – DigiCert (Magnum, DigiCert One)
- CA04 – Sectigo
- CA04 V2 EXT – Sectigo – 2049 expiration
- CA05 V2 EXT – CommScope – 2049 expiration
DOCSIS 3.1 & Remote PHY CA Certificates (2nd Gen PKI)
DOCSIS 4.0 CA Certificates (2nd Gen PKI)
DOCSIS CVC CA Certificates (2nd Gen PKI)
DOCSIS Service Provider CA
CableLabs Certificate Policies
- CableLabs 2nd Gen PKI Certificate Policy 2025 v8.0
- CableLabs 2nd Gen PKI Certificate Policy 2024 V7.0
- CableLabs 2nd Gen PKI Certificate Policy 2022 V6.3
- CableLabs 2nd Gen PKI Certificate Policy 2022 V6.2
- CableLabs 2nd Gen PKI Certificate Policy 2022 V6.1
- CableLabs 2nd Gen PKI Certificate Policy 2022 V6.0
- CableLabs 2nd Gen PKI Certificate Policy 2021 V5.1
- CableLabs 2nd Gen PKI Certificate Policy 2021 V5.0
- CableLabs 2nd Gen PKI Certificate Policy 2020 V4.0
- CableLabs 2nd Gen PKI Certificate Policy 2019 V3.0
- CableLabs 2nd Gen PKI Certificate Policy 2019 V2.1
- CableLabs 2nd Gen PKI Certificate Policy 2018 V2.0
- CableLabs 2nd Gen PKI Certificate Policy 2018 V1.5
- CableLabs 2nd Gen PKI Certificate Policy 2017 V1.4
- CableLabs 2nd Gen PKI Certificate Policy 2017 V1.3
- CableLabs 2nd Gen PKI Certificate Policy 2017 V1.2
- CableLabs 2nd Gen PKI Certificate Policy 2017 V1.1
- CableLabs 2nd Gen PKI Certificate Policy 2017 V1.0
Trust Infrastructure (DOCSIS® 2nd Gen PKI – Certificate Profiles)
- CableLabs 2nd Gen PKI Trust Infrastructure (TI) v1.6
- CableLabs 2nd Gen PKI Trust Infrastructure (TI) V1.5 (Amended and Restated)
- CableLabs 2nd Gen PKI Trust Infrastructure (TI) V1.4
- CableLabs 2nd Gen PKI Trust Infrastructure (TI) V1.3
- CableLabs 2nd Gen PKI Trust Infrastructure (TI) V1.2
- CableLabs 2nd Gen PKI Trust Infrastructure (TI) V1.1
Production CRLs
Test Certificates
Production Certificates
- CableLabs Service Provider Root CA
- Shared-01 CableLabs Service Provider CA
- PacketCable™ MTA Root CA
- PacketCable™ Centralized MTA CA (only used by vendors receiving certificates from the centralized CA on the DCS Portal)
- PacketCable™ Centralized MTA CA – G2 (only used by vendors receiving certificates from the centralized CA on the Magnum Portal)
- Legacy CA Certificates with Extended Validity
- Issued off the Sectigo IoT Portal
Test Certificates
Production Certificates
- DPoE™ CA00008(issues DPoE™ device certificates on the DCS Portal)
- DPoE™ CA00008 – G2(issues DPoE™ device certificates on the Magnum Portal)
- CableLabs Manufacturer Root CA
- CableLabs CVC Root CA
- CableLabs CVC CA (issues DPoE™ CVC Certificates – 2032 expiration)
- CableLabs CVC CA – G2 (issues DPoE™ CVC Certificates – 2042 expiration)
- Legacy CA Certificates with Extended Validity
VIDEO
Agreement
Get information on licensing by contacting us.
Test Certificates
Production Certificates
- CableLabs Manufacturer Root CA
- CableLabs CVC Root CA
- CableLabs CVC CA (issues OCAP CVC Certificates)
- CableLabs Application CVC CA (issues OCAP Application CVC Certificates)
- CableLabs OCUR CVC CA (Issues OCUR CVC Certificates)
- OpenCable™ CA00001 (issues CableCARD™ Device Certificates on the DCS Portal)
- OpenCable™ CA00001 – G2 (issues CableCARD™ Device Certificates on the DCS Portal)
- OpenCable™ CA00001 – G3 (issues CableCARD™ Device Certificates on the Magnum Portal)
- OpenCable™ CA00002 (issues OpenCable Host Device Certificates)
- OpenCable™ CA00004 (issues UDCP Host Device Certificates on the DCS Portal)
- OpenCable™ CA00004 – G2 (issues UDCP Host Device Certificates on the Magnum Portal)
- OpenCable™ CA00006 (issues OpenCable Host Device Certificates on the DCS Portal)
- OpenCable™ CA00006 – G2 (issues OpenCable Host Device Certificates on the DCS Portal)
- OpenCable™ CA00006 – G3 (issues OpenCable Host Device Certificates on the Magnum Portal)
- OpenCable™ CA00007 (DCS Portal)
- OpenCable™ CA00007 – G2 (Magnum Portal)
- Legacy CA Certificates with Extended Validity
- Issued off the Sectigo IoT Portal

