GandiStandardSSLCA2.crt: CN=Gandi Standard SSL CA 2,O=Gandi,L=Paris,ST=Paris,C=FR (Intermediate Certificate, Expiring 2024-09-11) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://crt.usertrust.com/GandiStandardSSLCA2.crt" --output cert.crt

Download certificate through wget:

wget -q "http://crt.usertrust.com/GandiStandardSSLCA2.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            05:e4:dc:3b:94:38:ab:3b:85:97:cb:a6:a1:98:50:e3
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
        Validity
            Not Before: Sep 12 00:00:00 2014 GMT
            Not After : Sep 11 23:59:59 2024 GMT
        Subject: C=FR, ST=Paris, L=Paris, O=Gandi, CN=Gandi Standard SSL CA 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:94:04:2d:a6:79:95:74:ff:d5:00:3c:f5:ae:d8:
                    94:b1:29:7c:c0:8f:0b:0b:89:b9:82:83:97:6e:37:
                    28:f5:a2:1a:cf:d2:92:0b:9b:a8:d3:87:94:73:84:
                    10:9f:dc:35:cb:c2:2d:92:ac:21:b9:cb:3b:fc:40:
                    c1:c1:83:21:f0:bf:f8:f6:9c:fa:9c:82:10:c0:d0:
                    8e:4e:e5:0d:4c:b0:91:5c:90:b4:a4:40:51:16:da:
                    e4:84:12:2d:05:5c:a1:1f:17:19:24:51:aa:7a:ea:
                    e1:07:1b:86:8d:01:72:f2:e7:d4:83:23:39:9e:e0:
                    e1:4c:1f:6b:22:a3:b4:10:66:b0:ed:82:96:d7:6e:
                    6a:b4:f2:3f:b5:42:fc:dd:8a:b5:ab:ba:2d:1d:3a:
                    75:9b:31:dc:3e:9d:ac:5b:d3:41:0d:6c:b0:1b:f5:
                    3a:f5:79:ea:21:a2:f8:f4:33:52:4b:24:2d:1e:a4:
                    99:b1:6d:48:bc:b8:12:fe:72:70:7c:f7:fb:02:75:
                    f4:8d:de:d6:da:c0:a0:32:1a:52:df:38:6b:2e:45:
                    38:3f:3f:04:96:00:fd:a1:f4:a2:bb:d5:17:d6:27:
                    7c:1b:58:59:95:5e:8a:12:fd:9c:ab:81:3e:52:28:
                    48:51:85:6b:f3:91:b2:86:3f:29:b5:6e:03:62:ee:
                    d6:05
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:53:79:BF:5A:AA:2B:4A:CF:54:80:E1:D8:9B:C0:9D:F2:B2:03:66:CB

            X509v3 Subject Key Identifier: 
                B3:90:A7:D8:C9:AF:4E:CD:61:3C:9F:7C:AD:5D:7F:41:FD:69:30:EA
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.6449.1.2.2.26
                Policy: 2.23.140.1.2.1

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt
                OCSP - URI:http://ocsp.usertrust.com

    Signature Algorithm: sha384WithRSAEncryption
         58:67:fd:72:b2:6a:d7:7c:61:96:19:7e:d9:43:46:d1:26:7d:
         c8:53:fa:66:b0:6b:2d:a7:d3:aa:56:f7:3a:88:d0:3b:72:c9:
         50:fd:f7:59:b2:aa:68:f5:8c:73:03:bb:95:65:17:ce:2f:1c:
         dd:98:13:a2:91:c9:ee:a1:40:6e:3c:98:d6:5c:f3:b2:22:3c:
         2d:ee:1b:a4:e1:de:20:24:16:f2:8c:11:73:91:3a:f6:fa:ce:
         24:02:87:ca:93:ec:b4:b6:c8:16:17:c5:72:fc:27:40:f6:13:
         fe:93:a6:9d:51:ef:3c:2b:d8:77:57:9b:8c:65:3a:35:25:36:
         b7:b5:8a:63:6f:07:27:93:b1:60:8d:80:db:96:d4:7a:8f:2d:
         ab:1c:88:c9:6e:7e:d6:65:1f:af:5d:ca:16:3f:28:46:dc:a0:
         35:e5:f9:e9:e5:d5:96:88:0c:4f:c6:b7:77:67:48:84:27:b6:
         1f:b0:68:db:ac:bf:77:b0:90:b8:a2:c9:1c:32:5d:02:ba:25:
         43:81:42:47:bb:d8:e1:8f:0c:0c:46:5f:ee:46:33:6b:03:14:
         82:d3:7e:cd:8f:af:90:d6:8e:24:7d:40:42:b4:6a:6a:17:c6:
         95:97:e1:f2:38:cd:a7:ed:b4:27:40:93:df:72:a9:b8:c6:66:
         63:37:38:64:22:30:a2:3b:f1:b9:c8:7b:c8:fb:29:3a:ab:1a:
         72:d2:06:12:4e:f6:82:d4:23:6f:3e:c3:93:e5:d8:b6:c0:de:
         dc:23:16:d6:13:30:b7:a0:9a:0e:2c:55:06:00:70:01:cf:ea:
         39:1d:80:db:88:f7:a5:20:b8:5b:fd:31:26:69:8f:2d:0a:61:
         83:3a:47:a6:13:54:2c:1e:e3:ed:44:ca:bc:6a:1f:28:0e:51:
         d9:de:0e:9f:75:cd:0e:03:95:ca:f9:c5:a9:2a:2d:fe:41:a4:
         a1:47:ae:0d:c2:f9:39:66:33:4a:5b:e1:84:28:59:6c:7d:94:
         17:76:e4:45:82:ad:70:20:fd:d2:6f:63:a8:d7:fa:a0:33:fa:
         37:cb:f7:b2:65:9e:da:50:6f:3f:e4:a7:f3:8e:5d:58:32:97:
         70:23:2e:e7:fd:c4:15:9b:9c:27:8f:32:ed:17:ad:58:81:31:
         29:11:1a:9b:d4:fc:6c:95:28:c7:4e:05:07:a6:fd:1d:bc:19:
         e2:e8:b7:b9:11:8a:2d:70:12:52:85:8d:8c:33:4a:0f:fc:99:
         92:e0:63:70:da:a5:94:47:63:07:e7:58:c7:31:5f:05:3d:36:
         55:fe:83:b2:e8:a6:ad:d7:e9:e6:02:74:88:74:5c:da:34:db:
         90:d2:6d:51:0a:23:d6:23

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIF6TCCA9GgAwIBAgIQBeTcO5Q4qzuFl8umoZhQ4zANBgkqhkiG9w0BAQwFADCB
iDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCk5ldyBKZXJzZXkxFDASBgNVBAcTC0pl
cnNleSBDaXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5ldHdvcmsxLjAsBgNV
BAMTJVVTRVJUcnVzdCBSU0EgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTQw
OTEyMDAwMDAwWhcNMjQwOTExMjM1OTU5WjBfMQswCQYDVQQGEwJGUjEOMAwGA1UE
CBMFUGFyaXMxDjAMBgNVBAcTBVBhcmlzMQ4wDAYDVQQKEwVHYW5kaTEgMB4GA1UE
AxMXR2FuZGkgU3RhbmRhcmQgU1NMIENBIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQCUBC2meZV0/9UAPPWu2JSxKXzAjwsLibmCg5duNyj1ohrP0pIL
m6jTh5RzhBCf3DXLwi2SrCG5yzv8QMHBgyHwv/j2nPqcghDA0I5O5Q1MsJFckLSk
QFEW2uSEEi0FXKEfFxkkUap66uEHG4aNAXLy59SDIzme4OFMH2sio7QQZrDtgpbX
bmq08j+1QvzdirWrui0dOnWbMdw+naxb00ENbLAb9Tr1eeohovj0M1JLJC0epJmx
bUi8uBL+cnB89/sCdfSN3tbawKAyGlLfOGsuRTg/PwSWAP2h9KK71RfWJ3wbWFmV
XooS/ZyrgT5SKEhRhWvzkbKGPym1bgNi7tYFAgMBAAGjggF1MIIBcTAfBgNVHSME
GDAWgBRTeb9aqitKz1SA4dibwJ3ysgNmyzAdBgNVHQ4EFgQUs5Cn2MmvTs1hPJ98
rV1/Qf1pMOowDgYDVR0PAQH/BAQDAgGGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYD
VR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMCIGA1UdIAQbMBkwDQYLKwYBBAGy
MQECAhowCAYGZ4EMAQIBMFAGA1UdHwRJMEcwRaBDoEGGP2h0dHA6Ly9jcmwudXNl
cnRydXN0LmNvbS9VU0VSVHJ1c3RSU0FDZXJ0aWZpY2F0aW9uQXV0aG9yaXR5LmNy
bDB2BggrBgEFBQcBAQRqMGgwPwYIKwYBBQUHMAKGM2h0dHA6Ly9jcnQudXNlcnRy
dXN0LmNvbS9VU0VSVHJ1c3RSU0FBZGRUcnVzdENBLmNydDAlBggrBgEFBQcwAYYZ
aHR0cDovL29jc3AudXNlcnRydXN0LmNvbTANBgkqhkiG9w0BAQwFAAOCAgEAWGf9
crJq13xhlhl+2UNG0SZ9yFP6ZrBrLafTqlb3OojQO3LJUP33WbKqaPWMcwO7lWUX
zi8c3ZgTopHJ7qFAbjyY1lzzsiI8Le4bpOHeICQW8owRc5E69vrOJAKHypPstLbI
FhfFcvwnQPYT/pOmnVHvPCvYd1ebjGU6NSU2t7WKY28HJ5OxYI2A25bUeo8tqxyI
yW5+1mUfr13KFj8oRtygNeX56eXVlogMT8a3d2dIhCe2H7Bo26y/d7CQuKLJHDJd
ArolQ4FCR7vY4Y8MDEZf7kYzawMUgtN+zY+vkNaOJH1AQrRqahfGlZfh8jjNp+20
J0CT33KpuMZmYzc4ZCIwojvxuch7yPspOqsactIGEk72gtQjbz7Dk+XYtsDe3CMW
1hMwt6CaDixVBgBwAc/qOR2A24j3pSC4W/0xJmmPLQphgzpHphNULB7j7UTKvGof
KA5R2d4On3XNDgOVyvnFqSot/kGkoUeuDcL5OWYzSlvhhChZbH2UF3bkRYKtcCD9
0m9jqNf6oDP6N8v3smWe2lBvP+Sn845dWDKXcCMu5/3EFZucJ48y7RetWIExKREa
m9T8bJUox04FB6b9HbwZ4ui3uRGKLXASUoWNjDNKD/yZkuBjcNqllEdjB+dYxzFf
BT02Vf6Dsuimrdfp5gJ0iHRc2jTbkNJtUQoj1iM=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06