Certificates

These are the currently in-use SSL/TLS certificates.

IMPORTANT: ADMIN-ONLY. Regular end-users should NOT have to change any settings regarding certificates. Use a modern browser.

WARNING: It's recommended to trust your browser vendor's root certificates.
Only trust specific certificates if there's no altenative (eg, if you have to manage your own trust store).
Even in this scenario, please trust the root certificates in preference to endpoint certificates.

Please keep browsers, trust stores, and operating system updated according to the vendors recommended update policy.

Environment Implementation Type URL base Endpoint Certificate Root certificate Extra
Production 12/10/2026 Web, end-user www.me.com.br Sertigo cert Sertigo ca SSLLabs A-
Production 12/10/2026 Integration, webservices, MEConnect api.me.com.br Sertigo cert Sertigo ca SSLLabs A-
Staging 21/09/2026 Web, end-user, webservices, MEConnect stg.me.com.br Sectigo cert Sectigo ca SSLLabs A-
UAT 21/09/2026 Web, end-user, webservices, MEConnect uat.me.com.br Sectigo cert Sectigo ca SSLLabs A-

Official References for Let's Encrypt Certificates

URL: api.mercadoe.com

Root certificate (required)::
- ISRG Root X1
https://letsencrypt.org/certs/isrgrootx1.pem

Intermediate certificates (recommended)::
- Intermediario YR2
https://letsencrypt.org/certs/gen-y/int-yr2.pem
- Root YR assinado pelo ISRG Root X1
https://letsencrypt.org/certs/gen-y/root-yr-by-x1.pem

IMPORTANT: The CA/Browser Forum, together with major browser vendors (Apple, Google, Microsoft and Mozilla), has approved a phased reduction in the maximum validity period of publicly trusted TLS/SSL certificates.

Effective Date Maximum Certificate Validity
Until March 14, 2026 398 days
From March 15, 2026 200 days
From March 15, 2027 100 days
From March 15, 2029 47 days

Organizations are strongly encouraged to implement automated certificate lifecycle management and renewal processes to avoid service disruptions caused by certificate expiration.

IMPORTANT: SSLv3 (and DH1024), TLS 1.0 and TLS 1.1 are no longer supported since 01/06/2020.