DigiCertCNRSACAG1.crt: CN=DigiCert CN RSA CA G1,OU=www.digicert.com,O=DigiCert Inc,C=US (Intermediate Certificate, Expiring 2029-06-20) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://crl.digicert-cn.com/DigiCertCNRSACAG1.crt" --output cert.crt

Download certificate through wget:

wget -q "http://crl.digicert-cn.com/DigiCertCNRSACAG1.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0b:50:fe:69:4c:83:c9:5c:e2:24:15:c6:09:5c:fe:40
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
        Validity
            Not Before: Jun 20 12:27:34 2019 GMT
            Not After : Jun 20 12:27:34 2029 GMT
        Subject: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert CN RSA CA G1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:bb:f8:98:5e:ab:39:15:14:5d:9b:b0:83:f1:51:
                    f5:81:4e:33:9b:59:8f:74:44:e4:94:cc:15:6a:c3:
                    75:aa:db:be:7c:5d:82:ee:41:1e:a9:8f:ca:df:d0:
                    ef:13:52:ef:03:b2:1d:12:78:79:1a:58:87:48:49:
                    3d:16:ed:55:02:3f:d1:58:20:8d:5a:57:2d:d3:61:
                    c6:95:5d:fd:18:50:e3:8a:de:8f:9f:d8:55:25:24:
                    81:23:da:80:ce:73:a6:97:42:a3:a9:52:04:86:b7:
                    a7:39:f3:5d:35:6c:1e:01:3a:ba:6b:7a:47:36:b1:
                    09:0b:34:46:b5:35:4a:da:8c:13:d6:25:44:73:b6:
                    71:8d:2c:93:20:39:79:86:1b:c6:b9:6b:e7:12:59:
                    e2:6d:63:f3:da:f7:3b:21:d8:33:43:1c:e3:2d:1b:
                    8a:8e:e0:52:15:8f:66:5d:7b:06:f0:ee:19:b9:3d:
                    0d:70:f1:a3:07:7e:e6:f9:e9:2a:93:74:e7:52:ed:
                    9b:ce:0d:e8:11:02:cd:e1:3f:bd:b1:ce:2c:65:54:
                    e9:c6:34:d5:5e:f9:d3:30:c9:ed:24:e9:74:dc:fc:
                    16:b5:74:08:c3:fa:2b:da:df:04:64:55:61:81:32:
                    eb:ea:cc:48:eb:cb:b6:13:fe:46:a2:1d:dd:bf:c8:
                    6e:79
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                EF:45:0B:78:15:91:A5:B6:D1:73:A4:92:6F:63:5A:59:D3:5F:3E:9D
            X509v3 Authority Key Identifier: 
                keyid:03:DE:50:35:56:D1:4C:BB:66:F0:A3:E2:1B:1B:C3:97:B2:3D:D1:55

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE
            Authority Information Access: 
                OCSP - URI:http://ocsp.dcocsp.cn

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.digicert-cn.com/DigiCertGlobalRootCA.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://www.digicert.com/CPS
                  User Notice:
                    Explicit Text: Any use of this Certificate constitutes acceptance of the Relying Party Agreement located at https://www.digicert.com/rpa-ua

    Signature Algorithm: sha256WithRSAEncryption
         bf:5c:f2:59:9a:16:40:66:3b:47:21:eb:0e:66:8b:54:4a:4b:
         b7:3b:53:7a:6a:df:05:8e:5f:35:05:28:a2:59:0a:7c:89:60:
         77:0c:50:8c:8d:08:38:3b:d5:c9:42:17:3e:05:b7:fc:98:2e:
         85:e4:ce:a3:54:2c:06:84:52:d6:79:8a:47:f8:23:c8:49:1e:
         fe:b4:92:0d:b9:18:b0:ac:7e:6d:8e:d6:2b:1b:13:45:b1:a5:
         e6:f8:a9:fe:ce:18:f2:8a:30:b0:a6:99:c7:5b:66:4b:8e:f8:
         0c:77:f2:3a:3c:fc:13:b8:4e:75:68:79:bf:9b:60:a8:13:ba:
         f7:af:eb:01:82:4d:ec:c8:0c:d1:81:e7:ef:e9:0f:63:57:c2:
         99:2a:72:05:f8:a1:f2:0a:e0:27:4a:94:3d:47:8b:99:f0:25:
         b2:98:38:b4:69:36:b5:e9:f3:79:f9:a1:a7:31:95:ec:f1:a7:
         88:a4:b7:ae:04:84:3b:06:d6:65:9a:40:3d:2d:a8:27:01:a4:
         61:db:6f:c1:92:c8:1b:36:2a:88:42:a7:f9:5c:ca:c4:d5:2d:
         9b:54:66:46:46:b4:80:5d:f8:d9:62:de:35:4f:a6:e6:63:94:
         68:b9:d4:fd:f4:4d:17:89:ae:01:f8:f9:e3:d3:ce:60:f1:9d:
         84:a4:52:12

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFGjCCBAKgAwIBAgIQC1D+aUyDyVziJBXGCVz+QDANBgkqhkiG9w0BAQsFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
QTAeFw0xOTA2MjAxMjI3MzRaFw0yOTA2MjAxMjI3MzRaMF8xCzAJBgNVBAYTAlVT
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xHjAcBgNVBAMTFURpZ2lDZXJ0IENOIFJTQSBDQSBHMTCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBALv4mF6rORUUXZuwg/FR9YFOM5tZj3RE5JTMFWrD
darbvnxdgu5BHqmPyt/Q7xNS7wOyHRJ4eRpYh0hJPRbtVQI/0VggjVpXLdNhxpVd
/RhQ44rej5/YVSUkgSPagM5zppdCo6lSBIa3pznzXTVsHgE6umt6RzaxCQs0RrU1
StqME9YlRHO2cY0skyA5eYYbxrlr5xJZ4m1j89r3OyHYM0Mc4y0bio7gUhWPZl17
BvDuGbk9DXDxowd+5vnpKpN051Ltm84N6BECzeE/vbHOLGVU6cY01V750zDJ7STp
dNz8FrV0CMP6K9rfBGRVYYEy6+rMSOvLthP+RqId3b/IbnkCAwEAAaOCAc4wggHK
MB0GA1UdDgQWBBTvRQt4FZGlttFzpJJvY1pZ018+nTAfBgNVHSMEGDAWgBQD3lA1
VtFMu2bwo+IbG8OXsj3RVTAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYB
BQUHAwEGCCsGAQUFBwMCMA8GA1UdEwEB/wQFMAMBAf8wMQYIKwYBBQUHAQEEJTAj
MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5kY29jc3AuY24wRAYDVR0fBD0wOzA5
oDegNYYzaHR0cDovL2NybC5kaWdpY2VydC1jbi5jb20vRGlnaUNlcnRHbG9iYWxS
b290Q0EuY3JsMIHOBgNVHSAEgcYwgcMwgcAGBFUdIAAwgbcwKAYIKwYBBQUHAgEW
HGh0dHBzOi8vd3d3LmRpZ2ljZXJ0LmNvbS9DUFMwgYoGCCsGAQUFBwICMH4MfEFu
eSB1c2Ugb2YgdGhpcyBDZXJ0aWZpY2F0ZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNl
IG9mIHRoZSBSZWx5aW5nIFBhcnR5IEFncmVlbWVudCBsb2NhdGVkIGF0IGh0dHBz
Oi8vd3d3LmRpZ2ljZXJ0LmNvbS9ycGEtdWEwDQYJKoZIhvcNAQELBQADggEBAL9c
8lmaFkBmO0ch6w5mi1RKS7c7U3pq3wWOXzUFKKJZCnyJYHcMUIyNCDg71clCFz4F
t/yYLoXkzqNULAaEUtZ5ikf4I8hJHv60kg25GLCsfm2O1isbE0Wxpeb4qf7OGPKK
MLCmmcdbZkuO+Ax38jo8/BO4TnVoeb+bYKgTuvev6wGCTezIDNGB5+/pD2NXwpkq
cgX4ofIK4CdKlD1Hi5nwJbKYOLRpNrXp83n5oacxlezxp4ikt64EhDsG1mWaQD0t
qCcBpGHbb8GSyBs2KohCp/lcysTVLZtUZkZGtIBd+Nli3jVPpuZjlGi51P30TReJ
rgH4+ePTzmDxnYSkUhI=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06