Stop 03 of 08 · Certificates

What is a contract certificate?

About 6 min · 3 questions ·

Friday
The situation

The car presents a contract certificate and a contract ID. The charger has a certificate of its own, which it showed the car a moment earlier.

Both trust the other because they trust the same root.

The questionWhat exactly is in the car, and why should the charger believe it?

Three kinds of certificateWho holds what in a session
Held byProves
Contract certificatewith the contract ID (eMAID)carthe contract
Charger certificatefor the TLS connectionchargerthe charger
Root certificatestrust anchorsbothwhom to trust

In the OCA application note, the car sends its contract certificate and eMAID; the charger obtains its own certificate and its root certificates through the backend.

A contract that can prove itself

A binds a , the eMAID, to a key that only the car holds. When the car presents it, the charger or its backend can check two things: that the certificate was issued within a trusted chain, and that it is still valid.

  • Online, the backend checks the certificate's status, for example with an OCSP request.
  • Offline, the charger can validate the certificate itself if it has the root and the operator has enabled offline validation, and then use its local list for the eMAID.

Trust in both directions

The car does not simply trust any charger. Before it presents its contract, the charger proves its own identity in the TLS connection with its certificate. Both sides check the other's certificate against root certificates they already trust. Where those roots come from is the subject of stop 04.

Check your understanding

3 questions. Answer all of them to complete this stop. Each answer explains itself.

01Question 1 of 3

What does the contract certificate prove?

02Question 2 of 3

How can a backend check whether a contract certificate is still valid?

03Question 3 of 3

Why does the charger show its own certificate first?

  1. Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.
  2. Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.
  3. Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.
  4. Open Charge Alliance: Using ISO 15118 Plug & Charge with OCPP 1.6, application note v1.0, 2020. https://openchargealliance.org/wp-content/uploads/2025/05/ocpp_1_6_ISO_15118_v10-3.pdf. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.
Was this helpful?