What is a contract certificate?
The car presents a contract certificate and a contract ID. The charger has a certificate of its own, which it showed the car a moment earlier.
Both trust the other because they trust the same root.
The questionWhat exactly is in the car, and why should the charger believe it?
| Held by | Proves | |
|---|---|---|
| Contract certificatewith the contract ID (eMAID) | car | the contract |
| Charger certificatefor the TLS connection | charger | the charger |
| Root certificatestrust anchors | both | whom to trust |
In the OCA application note, the car sends its contract certificate and eMAID; the charger obtains its own certificate and its root certificates through the backend.
A contract that can prove itself
A binds a , the eMAID, to a key that only the car holds. When the car presents it, the charger or its backend can check two things: that the certificate was issued within a trusted chain, and that it is still valid.
- Online, the backend checks the certificate's status, for example with an OCSP request.
- Offline, the charger can validate the certificate itself if it has the root and the operator has enabled offline validation, and then use its local list for the eMAID.
Trust in both directions
The car does not simply trust any charger. Before it presents its contract, the charger proves its own identity in the TLS connection with its certificate. Both sides check the other's certificate against root certificates they already trust. Where those roots come from is the subject of stop 04.
Check your understanding
3 questions. Answer all of them to complete this stop. Each answer explains itself.
What does the contract certificate prove?
It binds the contract ID to the car; the charger's own certificate proves the charger.
How can a backend check whether a contract certificate is still valid?
The OCA application note describes OCSP requests to check the certificate status.
Why does the charger show its own certificate first?
Trust runs both ways: the car checks the charger before it presents its contract.
- Contract certificate A certificate in the car that binds the driver's contract ID to a key only the car holds, used for Plug & Charge. Glossary
- eMAID The contract ID of an e-mobility contract, carried in the contract certificate for Plug & Charge. Glossary
- Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.
- Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.
- Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.
- Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.