crl.cvshealth.com

Certificate Revocation & Trust Distribution

Certificate Authority Trust Anchors

Root and intermediate CA certificates for CVS Health and Aetna certificate chains. Install the appropriate trust anchors for your environment before deploying enterprise certificates.

Active Chains 4 chains published
Page Last Updated September 1, 2026
CRL Refresh Cadence Every 24 hours
Certificate Help Open a ServiceNow ticket ↗
i

Why HTTP and not HTTPS? CRL distribution points intentionally use HTTP per RFC 5280 §4.2.1.13 to avoid a circular trust dependency — an HTTPS CRL endpoint would require the very certificate it is helping to validate. This is by design, not a misconfiguration. Security scanners flagging this endpoint as "Not Secure" are expected and can be safely acknowledged.

CVS Health Private Chain — Internal Server & Client Active

For internal TLS, server auth, and client auth on corp.cvscaremark.com endpoints. Required for private chain adoption.

Root CA
CVSHealthRoot
RSA 4096 SHA-256 Expires 2044 5F:2C:82:D4:83:32:...
Intermediate CA
CVSHealthICA_Servers_01
RSA 4096 SHA-256 Expires 2034 5E:8F:E5:FF:5D:CB:...
CVS Health Private Chain — Retail Active

For internal TLS, server auth, and client auth on Retail endpoints. Required for private chain adoption.

Root CA
CVSHealthRoot
RSA 4096 SHA-256 Expires 2044 5F:2C:82:D4:83:32:...
Intermediate CA
CVSHealthICA_Retail_01
RSA 4096 SHA-512 Expires 2034 16:86:DE:55:6C:C1:...
CVS Health Private Chain — HCD Active

For internal TLS, server auth, and client auth on HCD endpoints. Required for private chain adoption.

Root CA
CVSHealthRoot
RSA 4096 SHA-256 Expires 2044 5F:2C:82:D4:83:32:...
Intermediate CA
HCDICA_Multi_01
RSA 4096 SHA-512 Expires 2035 3B:D8:A6:7F:F1:BD:4F:6F:AB:F2:21:2F:5E:EB:78:E0:FD:E8:81:06
CVS Health Private Chain — Users Active

For internal TLS, server auth, and client auth on User endpoints. Required for private chain adoption.

Root CA
CVSHealthRoot
RSA 4096 SHA-256 Expires 2044 5F:2C:82:D4:83:32:...
Intermediate CA
CVSHealthICA_Users_01
RSA 4096 SHA-512 Expires 2034 4C:14:80:02:88:41:18:FD:E8:13:EE:03:20:4D:97:A3:5C:25:CC:EC
Public OV — Standard Internet (2030) Active

CVS Health and Aetna Organization Validation certificates. Anchor: DigiCert Global Root G2.

Root CA
DigiCert Global Root G2
RSA 2048 SHA-256 Expires 2038 DF:3C:24:F9:BF:D6:66:76:1B:26:80:73:FE:06:D1:CC:8D:4F:82:A4
Intermediate CA
DigiCert Global G2 TLS RSA SHA256 2020 CA1
RSA 2048 SHA-256 Expires 2031 E7:A2:38:E0:03:5C:1D:77:B0:24:45:F3:1E:5C:B3:67:F3:07:30:CB
Public EV — Premium Extended Validation G2 Active

CVS Health and Aetna Extended Validation certificates. Anchor: DigiCert Global Root G2.

Root CA
DigiCert Global Root G2
RSA 2048 SHA-256 Expires 2038 DF:3C:24:F9:BF:D6:66:76:1B:26:80:73:FE:06:D1:CC:8D:4F:82:A4
Intermediate CA
DigiCert EV RSA CA G2
RSA 2048 SHA-256 Expires 2031 60:7C:4C:20:24:5B:5C:5C:B3:42:AA:E3:AB:4B:B5:D5:3C:9E:A5:F5
X9 Financial — Third-Party Client Authentication Active Restricted use

For financial institution mutual TLS. Contact PKI Engineering before installing this chain.

Restricted chain. The X9 Financial chain is for financial institution partners requiring mutual TLS client authentication only. Do not install in general-purpose trust stores. Open a ServiceNow ticket before deployment.
Root CA
X9FinancialPKI-RSA4096Root
RSA 4096 SHA-256 Expires 2032 B8:1D:44:A2:33:F8:...
Intermediate CA
X9FinancialPKI-RSA4096ICA
RSA 4096 SHA-256 Expires 2029 C3:7F:22:9A:66:B4:...