Amazon-RSA-4096-M03.cer: CN=Amazon RSA 4096 M03,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-4096-M03.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-RSA-4096-M03.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:5e:aa:47:cf:e4:cc:ff:3c:1a:a3:7f:be:b0:29:72:f7
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
        Validity
            Not Before: Aug 23 22:30:01 2022 GMT
            Not After : Aug 23 22:30:01 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon RSA 4096 M03
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:b7:58:49:d0:7c:7e:0d:47:a6:13:d1:28:1d:27:
                    d8:13:09:f6:2f:4a:8b:cd:c0:53:ee:c8:97:4f:f0:
                    51:56:3d:4f:6e:40:1c:4a:72:09:b6:67:c3:fd:50:
                    cc:1e:91:25:ce:67:8d:78:57:fe:56:50:c9:8d:df:
                    97:ec:a5:82:2e:57:74:7a:fd:97:4e:6d:5a:6f:0e:
                    ef:95:a1:73:39:d2:98:d6:3d:5b:c9:bd:2d:6d:2d:
                    f3:30:c3:36:64:1b:cd:e0:d7:fe:9a:49:62:a6:3f:
                    af:bd:0a:c7:ec:93:22:0b:46:1c:96:40:dc:ac:8e:
                    b2:9c:c6:ef:a9:d5:cc:11:6c:a2:6c:c9:e9:95:b0:
                    0c:7b:6c:46:eb:b9:52:34:b8:8c:06:69:8c:09:6d:
                    38:d2:09:19:c7:52:d3:7e:02:e3:eb:d3:e1:82:81:
                    3e:78:a2:77:39:0e:da:0a:f8:93:c9:11:af:79:83:
                    c8:74:e5:09:ce:15:df:bc:c7:40:1c:4c:e5:17:ab:
                    f7:d4:3e:92:79:bd:b9:e2:77:ab:5e:f0:62:00:15:
                    93:cd:28:88:cb:03:1a:4a:2c:8e:88:0e:17:a1:f1:
                    07:bd:d9:24:da:73:ee:9c:13:88:3b:4e:15:be:08:
                    e1:dc:7b:8e:b6:2c:d9:18:9b:57:bb:17:57:fe:69:
                    ed:d6:fb:f7:06:99:b2:f6:4f:1f:7b:92:bd:6d:1f:
                    dd:ea:5e:e8:c4:40:46:d0:84:79:04:d7:09:43:e1:
                    fa:8b:2b:17:d3:17:06:df:8d:84:be:24:54:55:65:
                    8c:29:07:fb:b7:cf:79:5c:f0:ac:7d:ff:7d:9d:70:
                    10:0f:3b:8b:2c:b1:4d:e3:6b:8b:e6:da:51:d2:0f:
                    5e:32:bd:ed:bd:6a:e6:36:67:40:0e:f7:cb:d7:ad:
                    ed:9d:55:21:99:c3:8d:42:e0:40:2d:7f:0d:35:95:
                    a5:01:7d:35:c5:6c:d4:1f:5e:0a:bd:92:bb:ba:98:
                    ad:47:11:d7:0b:cd:44:65:e5:5e:11:01:0a:ec:56:
                    fa:47:89:da:51:da:0b:5b:f6:6a:32:db:58:10:46:
                    33:e6:a4:81:b3:73:33:d3:f7:a3:5e:29:a2:0e:34:
                    b7:2d:d4:36:17:58:40:d2:51:e7:1b:58:f1:f6:de:
                    c3:8d:18:52:21:a0:61:0f:76:29:c3:3c:a4:53:28:
                    c5:b6:0a:36:3a:a6:d5:68:c8:c9:f6:d0:f0:52:09:
                    10:f5:8d:49:fe:7f:e3:b3:ad:e4:30:03:b8:dd:7b:
                    a1:32:f3:c5:a9:21:b1:97:fe:40:70:1c:75:ac:2f:
                    7e:da:be:0f:ce:64:6b:5b:85:32:8b:a5:6b:07:66:
                    e2:f6:29
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                10:14:01:BB:00:D3:BD:B4:86:FA:7B:EF:B1:EE:96:BF:4A:44:E5:02
            X509v3 Authority Key Identifier: 
                keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca2.amazontrust.com
                CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca2.amazontrust.com/rootca2.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha384WithRSAEncryption
         41:ca:52:6d:ce:2a:51:85:88:18:a0:9b:15:70:26:6c:3b:cc:
         8a:8c:8d:d4:2c:f7:a3:95:28:9f:e9:e2:31:b8:bf:08:f8:3b:
         85:9e:a0:49:70:69:d2:0c:c4:fa:3e:2e:83:93:db:f1:d1:c3:
         32:1c:61:88:cb:9f:50:93:fa:0f:17:4c:25:50:68:2d:6d:3f:
         d7:cd:eb:60:24:cb:e9:0a:80:d9:6e:90:49:37:23:26:a5:3c:
         db:f9:d7:0c:77:30:50:bc:32:10:8b:12:f4:7f:c4:49:39:73:
         e2:94:40:12:79:b6:57:25:e0:cc:1e:06:b0:e6:97:39:c5:3e:
         5f:7a:50:ad:d0:ea:b9:4a:64:02:87:4c:67:2e:0e:e1:4b:38:
         55:b5:ed:8f:52:23:ed:e4:ed:d7:73:85:04:46:b7:76:51:18:
         3e:56:67:58:e2:e5:65:ab:8c:ea:e0:66:bd:19:54:42:2a:7e:
         e6:a1:fb:55:f2:f7:93:23:f3:ca:72:47:1d:f3:58:15:f3:8a:
         9c:b1:fd:8f:c8:a1:c7:fc:f3:d0:09:a9:93:1e:e8:3b:2b:84:
         d9:aa:62:97:36:e0:77:8d:18:10:76:3d:95:e1:d3:5c:bd:29:
         92:f4:23:0b:53:1d:df:76:61:b8:0a:56:cf:ea:98:8e:e5:7f:
         f7:f2:82:2a:12:6e:e7:a7:26:59:eb:66:30:b1:6e:ed:63:19:
         3c:0b:98:e3:dd:c9:8b:e7:80:84:d7:94:6c:6e:82:e3:38:22:
         4b:3a:bd:bc:e2:cf:20:96:33:97:db:35:22:da:23:94:67:c0:
         7a:e0:ea:8b:e3:15:7a:58:a8:a9:15:06:29:c9:3d:45:41:3e:
         29:e3:bb:53:05:5d:94:2c:2c:89:ab:18:a6:0d:6c:e2:f9:bf:
         b1:a6:52:b3:b0:19:31:83:a4:96:29:fd:7d:4c:5d:19:35:98:
         4c:a2:00:9a:30:18:44:96:8b:ce:67:59:81:f2:cd:ec:98:7c:
         ef:8e:fb:a9:f7:0e:f6:d7:fa:dc:43:76:6e:87:e2:9c:86:51:
         53:60:f7:06:9d:93:1d:ad:bd:c0:6c:57:4c:5c:3d:c3:92:41:
         5d:a9:0b:a5:a9:99:ea:43:49:ec:1f:91:4f:9f:34:cf:7d:2d:
         75:ef:3a:b5:c7:86:d3:e9:9e:ec:d8:4b:69:e8:e1:8c:c3:fe:
         37:fd:02:ab:c1:f9:16:10:44:3d:97:d3:05:55:f7:b4:a9:91:
         15:79:4d:1e:3a:0b:32:9b:28:3b:14:e1:8b:ba:9f:d3:a4:22:
         f2:11:a3:22:fd:20:fb:e9:f4:ab:6f:1f:bd:20:fb:ab:26:e0:
         a9:bc:3d:06:3f:1d:eb:8b

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIGXjCCBEagAwIBAgITB3MSXqpHz+TM/zwao3++sCly9zANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTIyMDgyMzIyMzAwMVoXDTMwMDgyMzIyMzAwMVowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSA0MDk2IE0wMzCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBALdYSdB8
fg1HphPRKB0n2BMJ9i9Ki83AU+7Il0/wUVY9T25AHEpyCbZnw/1QzB6RJc5njXhX
/lZQyY3fl+ylgi5XdHr9l05tWm8O75WhcznSmNY9W8m9LW0t8zDDNmQbzeDX/ppJ
YqY/r70Kx+yTIgtGHJZA3KyOspzG76nVzBFsomzJ6ZWwDHtsRuu5UjS4jAZpjAlt
ONIJGcdS034C4+vT4YKBPniidzkO2gr4k8kRr3mDyHTlCc4V37zHQBxM5Rer99Q+
knm9ueJ3q17wYgAVk80oiMsDGkosjogOF6HxB73ZJNpz7pwTiDtOFb4I4dx7jrYs
2RibV7sXV/5p7db79waZsvZPH3uSvW0f3epe6MRARtCEeQTXCUPh+osrF9MXBt+N
hL4kVFVljCkH+7fPeVzwrH3/fZ1wEA87iyyxTeNri+baUdIPXjK97b1q5jZnQA73
y9et7Z1VIZnDjULgQC1/DTWVpQF9NcVs1B9eCr2Su7qYrUcR1wvNRGXlXhEBCuxW
+keJ2lHaC1v2ajLbWBBGM+akgbNzM9P3o14pog40ty3UNhdYQNJR5xtY8fbew40Y
UiGgYQ92KcM8pFMoxbYKNjqm1WjIyfbQ8FIJEPWNSf5/47Ot5DADuN17oTLzxakh
sZf+QHAcdawvftq+D85ka1uFMoulawdm4vYpAgMBAAGjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFBAUAbsA0720hvp777Hulr9KROUCMB8GA1Ud
IwQYMBaAFLAM8Eww9AVYAkj9M+VSr0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9v
dGNhMi5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFt
YXpvbnRydXN0LmNvbS9yb290Y2EyLmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAN
BgkqhkiG9w0BAQwFAAOCAgEAQcpSbc4qUYWIGKCbFXAmbDvMioyN1Cz3o5Uon+ni
Mbi/CPg7hZ6gSXBp0gzE+j4ug5Pb8dHDMhxhiMufUJP6DxdMJVBoLW0/183rYCTL
6QqA2W6QSTcjJqU82/nXDHcwULwyEIsS9H/ESTlz4pRAEnm2VyXgzB4GsOaXOcU+
X3pQrdDquUpkAodMZy4O4Us4VbXtj1Ij7eTt13OFBEa3dlEYPlZnWOLlZauM6uBm
vRlUQip+5qH7VfL3kyPzynJHHfNYFfOKnLH9j8ihx/zz0Ampkx7oOyuE2apilzbg
d40YEHY9leHTXL0pkvQjC1Md33ZhuApWz+qYjuV/9/KCKhJu56cmWetmMLFu7WMZ
PAuY493Ji+eAhNeUbG6C4zgiSzq9vOLPIJYzl9s1ItojlGfAeuDqi+MVelioqRUG
Kck9RUE+KeO7UwVdlCwsiasYpg1s4vm/saZSs7AZMYOklin9fUxdGTWYTKIAmjAY
RJaLzmdZgfLN7Jh87477qfcO9tf63EN2bofinIZRU2D3Bp2THa29wGxXTFw9w5JB
XakLpamZ6kNJ7B+RT580z30tde86tceG0+me7NhLaejhjMP+N/0Cq8H5FhBEPZfT
BVX3tKmRFXlNHjoLMpsoOxThi7qf06Qi8hGjIv0g++n0q28fvSD7qybgqbw9Bj8d
64s=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06