9F22

Certification Authority Public Key Index (PK Index) – Terminal

Certification Authority Public Key Index - Terminal is exactly what 8F is on the card side, but reported by the terminal instead: which CA root key, by RID, the terminal itself actually used to verify the issuer's certificate during this transaction. Because a terminal can carry multiple generations of CA keys for the same RID (keys expire and get replaced over time), 9F22 lets a downstream log or an issuer's own records confirm precisely which key generation was live in the field at the moment of a specific transaction, which the card's own 8F alone can't tell you - 8F says which key the card expects; 9F22 says which key the terminal actually reached for. A mismatch between what a terminal reports in 9F22 across otherwise-identical transactions from the same period is a strong signal of a CA key rotation happening mid-fleet, worth correlating with any offline-authentication failure spike from the same window before assuming the fault lies with specific cards rather than a key rollout. See EMV 4.4 Book 3.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (1): 01

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 01

Related tags

Properties

Tag9F22
NameCertification Authority Public Key Index (PK Index) – Terminal
FormatBinary
Length1 bytes
SourceTerminal
Templates
BooksEMV 4.4 Book 3

Frequently asked questions

What is EMV tag 9F22?
Certification Authority Public Key Index - Terminal is exactly what 8F is on the card side, but reported by the terminal instead: which CA root key, by RID, the terminal itself actually used to verify the issuer's certificate during this transaction. Because a terminal can carry multiple generations of CA keys for the same RID (keys expire and get replaced over time), 9F22 lets a downstream log or an issuer's own records confirm precisely which key generation was live in the field at the moment of a specific transaction, which the card's own 8F alone can't tell you - 8F says which key the card expects; 9F22 says which key the terminal actually reached for. A mismatch between what a terminal reports in 9F22 across otherwise-identical transactions from the same period is a strong signal of a CA key rotation happening mid-fleet, worth correlating with any offline-authentication failure spike from the same window before assuming the fault lies with specific cards rather than a key rollout. See EMV 4.4 Book 3.
What format and length does EMV tag 9F22 use?
Tag 9F22 uses the Binary format and is normally 1 bytes long.
Is tag 9F22 provided by the card or the terminal?
Tag 9F22 (Certification Authority Public Key Index (PK Index) – Terminal) is provided by the Terminal.

Sources

  • EMV_v4.4_Book_3_Application_Specification, p. 143

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.