apevsecc1g1.der: CN=Apple Public EV Server ECC CA 1 - G1,O=Apple Inc.,C=US

Page content

CA Certificate Basic Information

This certificate is root certificate used for the issuance of other certificates.

  • Certificate download URL: http://certs.apple.com/apevsecc1g1.der (DER format)
  • Serial number: 16842083344538996361179333927479884023
  • SHA-1 Fingerprint: 222902acfb934c606d45bdc31c603daaf8b13e4f
  • SHA-1 Fingerprint: 22:29:02:ac:fb:93:4c:60:6d:45:bd:c3:1c:60:3d:aa:f8:b1:3e:4f
  • SHA-256 Fingerprint: 2585928d2c5bfd952e025bd12e27c6776224cf752ec362d3031cdd49351844d4
  • SHA-256 Fingerprint: 25:85:92:8d:2c:5b:fd:95:2e:02:5b:d1:2e:27:c6:77:62:24:cf:75:2e:c3:62:d3:03:1c:dd:49:35:18:44:d4
  • Signature hash algorithm: sha384
  • Subject: CN=Apple Public EV Server ECC CA 1 - G1,O=Apple Inc.,C=US
  • Not valid before: 2020-04-29 12:34:52
  • Not valid after: 2030-04-10 23:59:59
  • Issuer:
    • Issuer name: CN=DigiCert Global Root G3,OU=www.digicert.com,O=DigiCert Inc,C=US
    • Issuer certificate URL: None

Download certificate through curl:

curl -sSL http://certs.apple.com/apevsecc1g1.der --output cert.crt

Download certificate through wget:

wget -q http://certs.apple.com/apevsecc1g1.der --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0c:ab:aa:d1:ce:c4:e9:7c:c2:66:58:81:d0:21:38:f7
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
        Validity
            Not Before: Apr 29 12:34:52 2020 GMT
            Not After : Apr 10 23:59:59 2030 GMT
        Subject: C=US, O=Apple Inc., CN=Apple Public EV Server ECC CA 1 - G1
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:29:f8:e1:5a:b9:87:44:04:98:ff:16:90:86:f9:
                    e0:e1:42:65:5f:86:fd:03:18:fc:c6:cf:8d:13:5b:
                    c0:5e:5b:18:a9:61:33:9a:e0:52:e2:78:06:28:53:
                    ed:ed:da:d8:3d:15:92:ad:03:80:43:4c:ee:37:62:
                    9a:cb:66:6e:b3
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                E0:85:48:7D:13:A6:D3:10:19:9F:5C:CB:6B:78:24:92:F8:AE:1B:AE
            X509v3 Authority Key Identifier: 
                keyid:B3:DB:48:A4:F9:A1:C5:D8:AE:36:41:CC:11:63:69:62:29:BC:4B:C6

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl3.digicert.com/DigiCertGlobalRootG3.crl

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.114412.2.1
                  CPS: https://www.digicert.com/CPS
                  User Notice:
                    Explicit Text: Any use of this Certificate constitutes acceptance of the Relying Party Agreement located at https://www.digicert.com/rpa-ua
                Policy: 2.23.140.1.1

    Signature Algorithm: ecdsa-with-SHA384
         30:65:02:31:00:c8:72:c0:4f:fe:22:06:ec:62:e3:f3:47:85:
         97:5e:e0:f6:4e:f0:29:c6:db:f0:37:a0:63:b4:36:c8:e9:a1:
         ed:92:57:de:07:af:e2:69:60:7a:c1:cd:3f:21:c9:e2:92:02:
         30:67:45:7c:91:69:cf:6c:33:c2:8d:15:d8:37:fb:b2:d6:22:
         25:bd:b1:48:ed:24:2e:a4:1a:64:72:1a:6e:af:57:8a:00:84:
         40:dd:f6:37:64:e2:af:bb:6f:9c:e5:89:de

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDsjCCAzigAwIBAgIQDKuq0c7E6XzCZliB0CE49zAKBggqhkjOPQQDAzBhMQsw
CQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cu
ZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBHMzAe
Fw0yMDA0MjkxMjM0NTJaFw0zMDA0MTAyMzU5NTlaMFExCzAJBgNVBAYTAlVTMRMw
EQYDVQQKEwpBcHBsZSBJbmMuMS0wKwYDVQQDEyRBcHBsZSBQdWJsaWMgRVYgU2Vy
dmVyIEVDQyBDQSAxIC0gRzEwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQp+OFa
uYdEBJj/FpCG+eDhQmVfhv0DGPzGz40TW8BeWxipYTOa4FLieAYoU+3t2tg9FZKt
A4BDTO43YprLZm6zo4IB4DCCAdwwHQYDVR0OBBYEFOCFSH0TptMQGZ9cy2t4JJL4
rhuuMB8GA1UdIwQYMBaAFLPbSKT5ocXYrjZBzBFjaWIpvEvGMA4GA1UdDwEB/wQE
AwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgw
BgEB/wIBADA0BggrBgEFBQcBAQQoMCYwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBCBgNVHR8EOzA5MDegNaAzhjFodHRwOi8vY3JsMy5kaWdp
Y2VydC5jb20vRGlnaUNlcnRHbG9iYWxSb290RzMuY3JsMIHcBgNVHSAEgdQwgdEw
gcUGCWCGSAGG/WwCATCBtzAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cuZGlnaWNl
cnQuY29tL0NQUzCBigYIKwYBBQUHAgIwfgx8QW55IHVzZSBvZiB0aGlzIENlcnRp
ZmljYXRlIGNvbnN0aXR1dGVzIGFjY2VwdGFuY2Ugb2YgdGhlIFJlbHlpbmcgUGFy
dHkgQWdyZWVtZW50IGxvY2F0ZWQgYXQgaHR0cHM6Ly93d3cuZGlnaWNlcnQuY29t
L3JwYS11YTAHBgVngQwBATAKBggqhkjOPQQDAwNoADBlAjEAyHLAT/4iBuxi4/NH
hZde4PZO8CnG2/A3oGO0Nsjpoe2SV94Hr+JpYHrBzT8hyeKSAjBnRXyRac9sM8KN
Fdg3+7LWIiW9sUjtJC6kGmRyGm6vV4oAhEDd9jdk4q+7b5zlid4=
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26