Microsoft Azure TLS Issuing CA 01 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 01,O=Microsoft Corporation,C=US

Page content

CA Certificate Basic Information

This certificate is intermediate certificate used for the issuance of other certificates.

  • Certificate download URL: http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2001%20-%20xsign.crt (DER format)
  • Serial number: 14204314458671557774215927822652232471
  • SHA-1 Fingerprint: 2f2877c5d778c31e0f29c7e371df5471bd673173
  • SHA-1 Fingerprint: 2f:28:77:c5:d7:78:c3:1e:0f:29:c7:e3:71:df:54:71:bd:67:31:73
  • SHA-256 Fingerprint: 24c7299864e0a2a6964f551c0e8df2461532fa8c48e4dbbb6080716691f190e5
  • SHA-256 Fingerprint: 24:c7:29:98:64:e0:a2:a6:96:4f:55:1c:0e:8d:f2:46:15:32:fa:8c:48:e4:db:bb:60:80:71:66:91:f1:90:e5
  • Signature hash algorithm: sha384
  • Subject: CN=Microsoft Azure TLS Issuing CA 01,O=Microsoft Corporation,C=US
  • Not valid before: 2020-07-29 12:30:00
  • Not valid after: 2024-06-27 23:59:59
  • Issuer:

Download certificate through curl:

curl -sSL http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2001%20-%20xsign.crt --output cert.crt

Download certificate through wget:

wget -q http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2001%20-%20xsign.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0a:af:a6:c5:ca:63:c4:51:41:ea:3b:e1:f7:c7:53:17
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
        Validity
            Not Before: Jul 29 12:30:00 2020 GMT
            Not After : Jun 27 23:59:59 2024 GMT
        Subject: C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 01
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Modulus:
                    00:c7:9d:70:3a:e4:5e:e7:cf:ee:9c:55:9b:51:47:
                    2c:33:40:f4:88:f0:1d:a3:28:69:8f:1a:ae:aa:99:
                    e0:67:df:e3:1c:ab:47:28:27:6a:f5:cb:ee:0d:76:
                    30:f0:31:f1:0e:83:77:d8:5f:07:3a:df:5b:19:05:
                    d0:1a:f6:c0:8b:e5:be:4c:d6:d3:59:da:35:54:a4:
                    1e:9f:8e:4b:78:4b:dd:6e:a7:97:f8:d8:bd:99:d5:
                    78:95:e3:b6:c2:98:71:72:1f:ff:a5:ad:b2:97:05:
                    e5:ac:25:43:d2:d9:25:c8:f0:68:7e:ca:a1:9b:8a:
                    f9:31:e9:5c:23:2d:cc:3f:17:35:57:66:19:6f:c9:
                    23:40:bf:ed:4f:c4:ed:eb:d7:9f:d5:c3:8a:8f:12:
                    62:41:92:33:ad:da:2c:ee:41:b4:b0:af:d3:dd:be:
                    d5:de:06:18:14:90:62:89:51:ab:ee:cf:77:59:11:
                    12:45:81:3e:6d:32:c1:9d:95:6f:c1:88:4b:90:cb:
                    ae:37:a5:12:40:67:28:2c:b2:dc:1d:32:42:e7:7d:
                    76:95:6c:89:47:84:ec:5e:6c:63:c3:1e:f7:a5:95:
                    c5:07:1b:3b:26:1d:11:8f:e3:ff:d5:29:0e:53:86:
                    fa:f0:3e:62:03:af:06:19:0a:12:38:aa:ca:05:69:
                    3f:c1:19:a0:c3:22:8d:ea:61:ce:0e:37:6f:94:22:
                    f6:be:54:ae:f6:28:a3:5f:68:47:ff:29:7f:81:c9:
                    34:33:c5:d3:f1:49:c0:55:4c:5b:c3:e6:08:12:c6:
                    b2:d8:a7:dc:d1:35:f8:d7:96:4e:41:ad:d1:3c:e9:
                    1e:38:0a:c9:f6:83:3f:6b:4e:e1:b0:a4:d4:6e:e9:
                    3f:69:03:15:3e:d2:61:f7:3c:c5:b8:02:90:54:36:
                    50:21:17:b1:a1:ff:7f:96:26:a4:b9:f8:60:f8:8d:
                    14:27:9e:22:27:5a:ef:19:df:4e:f7:38:ec:8c:72:
                    55:c7:07:1e:ad:45:cc:6c:a0:3a:a7:a6:af:11:04:
                    4c:a8:7c:86:f0:d1:e9:e0:5d:ac:1c:26:08:75:60:
                    66:b9:c0:aa:79:fd:dc:9b:46:c8:f2:e2:eb:e7:23:
                    58:65:46:b4:c6:47:c3:35:6f:5f:51:ef:48:51:bb:
                    ef:5b:2c:91:c1:23:27:18:90:35:00:d0:45:61:c4:
                    87:73:71:bc:d6:fb:90:59:40:5e:75:5d:46:49:2f:
                    86:3a:51:19:c8:45:85:30:33:aa:6c:25:b5:d5:a1:
                    58:31:32:08:c2:82:db:1f:e6:49:9b:d9:b6:56:46:
                    63:e8:37:ed:8e:f6:a8:7c:e2:77:0b:72:5b:ba:c1:
                    7a:d6:49
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                0F:20:5D:D7:A1:57:95:DB:92:CF:2B:D0:C7:C2:77:04:CE:72:80:76
            X509v3 Authority Key Identifier: 
                keyid:4E:22:54:20:18:95:E6:E3:6E:E6:0F:FA:FA:B9:12:ED:06:17:8F:39

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com
                CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalRootG2.crt

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl3.digicert.com/DigiCertGlobalRootG2.crl

                Full Name:
                  URI:http://crl4.digicert.com/DigiCertGlobalRootG2.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
                Policy: 2.23.140.1.2.2

            1.3.6.1.4.1.311.21.1: 
                ...
    Signature Algorithm: sha384WithRSAEncryption
         25:16:f3:61:ed:08:17:54:b0:19:4a:c3:51:d9:74:66:22:7f:
         62:4b:c3:87:14:20:40:5b:12:89:a2:2f:18:61:06:9f:a4:c4:
         e4:32:a7:ae:ce:82:f7:1d:66:f5:a5:81:22:a6:c0:e4:86:23:
         27:ae:97:de:61:91:00:ec:bc:fb:ca:a1:04:b5:f8:07:70:40:
         6c:2b:d2:9c:4a:d4:06:19:94:5f:99:65:34:ee:13:d7:1e:71:
         73:fb:98:13:5e:ac:c2:13:63:c1:32:54:60:55:46:09:88:0d:
         b9:98:93:d7:7c:1d:34:80:3b:c6:86:d6:1a:fa:61:0d:c0:cf:
         41:ab:50:7d:61:82:f2:2e:34:6d:53:3f:1c:c8:6b:1d:c9:32:
         06:fd:b0:4c:fd:0f:63:71:5f:09:1a:a3:14:fd:48:c0:76:1d:
         69:17:24:e7:9c:71:25:63:9f:4d:a6:2e:c5:f3:b6:6a:61:82:
         44:1c:93:36:2c:60:fe:95:ef:15:b0:78:e0:79:65:f6:08:94:
         24:a3:b9:25:5e:f7:22:ce:e6:6f:50:40:d3:8c:76:90:72:cd:
         89:fa:43:e0:7f:23:08:39:8d:43:30:9d:b5:37:13:89:db:13:
         d1:0b:fc:00:87:f8:73:48:14:55:b6:80:27:ca:ec:6d:91:9e:
         15:8c:83:a1

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIF8zCCBNugAwIBAgIQCq+mxcpjxFFB6jvh98dTFzANBgkqhkiG9w0BAQwFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH
MjAeFw0yMDA3MjkxMjMwMDBaFw0yNDA2MjcyMzU5NTlaMFkxCzAJBgNVBAYTAlVT
MR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKjAoBgNVBAMTIU1pY3Jv
c29mdCBBenVyZSBUTFMgSXNzdWluZyBDQSAwMTCCAiIwDQYJKoZIhvcNAQEBBQAD
ggIPADCCAgoCggIBAMedcDrkXufP7pxVm1FHLDNA9IjwHaMoaY8arqqZ4Gff4xyr
RygnavXL7g12MPAx8Q6Dd9hfBzrfWxkF0Br2wIvlvkzW01naNVSkHp+OS3hL3W6n
l/jYvZnVeJXjtsKYcXIf/6WtspcF5awlQ9LZJcjwaH7KoZuK+THpXCMtzD8XNVdm
GW/JI0C/7U/E7evXn9XDio8SYkGSM63aLO5BtLCv092+1d4GGBSQYolRq+7Pd1kR
EkWBPm0ywZ2Vb8GIS5DLrjelEkBnKCyy3B0yQud9dpVsiUeE7F5sY8Me96WVxQcb
OyYdEY/j/9UpDlOG+vA+YgOvBhkKEjiqygVpP8EZoMMijephzg43b5Qi9r5UrvYo
o19oR/8pf4HJNDPF0/FJwFVMW8PmCBLGstin3NE1+NeWTkGt0TzpHjgKyfaDP2tO
4bCk1G7pP2kDFT7SYfc8xbgCkFQ2UCEXsaH/f5YmpLn4YPiNFCeeIida7xnfTvc4
7IxyVccHHq1FzGygOqemrxEETKh8hvDR6eBdrBwmCHVgZrnAqnn93JtGyPLi6+cj
WGVGtMZHwzVvX1HvSFG771sskcEjJxiQNQDQRWHEh3NxvNb7kFlAXnVdRkkvhjpR
GchFhTAzqmwltdWhWDEyCMKC2x/mSZvZtlZGY+g37Y72qHzidwtyW7rBetZJAgMB
AAGjggGtMIIBqTAdBgNVHQ4EFgQUDyBd16FXlduSzyvQx8J3BM5ygHYwHwYDVR0j
BBgwFoAUTiJUIBiV5uNu5g/6+rkS7QYXjzkwDgYDVR0PAQH/BAQDAgGGMB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH/AgEAMHYG
CCsGAQUFBwEBBGowaDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQu
Y29tMEAGCCsGAQUFBzAChjRodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGln
aUNlcnRHbG9iYWxSb290RzIuY3J0MHsGA1UdHwR0MHIwN6A1oDOGMWh0dHA6Ly9j
cmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5jcmwwN6A1oDOG
MWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5j
cmwwHQYDVR0gBBYwFDAIBgZngQwBAgEwCAYGZ4EMAQICMBAGCSsGAQQBgjcVAQQD
AgEAMA0GCSqGSIb3DQEBDAUAA4IBAQAlFvNh7QgXVLAZSsNR2XRmIn9iS8OHFCBA
WxKJoi8YYQafpMTkMqeuzoL3HWb1pYEipsDkhiMnrpfeYZEA7Lz7yqEEtfgHcEBs
K9KcStQGGZRfmWU07hPXHnFz+5gTXqzCE2PBMlRgVUYJiA25mJPXfB00gDvGhtYa
+mENwM9Bq1B9YYLyLjRtUz8cyGsdyTIG/bBM/Q9jcV8JGqMU/UjAdh1pFyTnnHEl
Y59Npi7F87ZqYYJEHJM2LGD+le8VsHjgeWX2CJQko7klXvcizuZvUEDTjHaQcs2J
+kPgfyMIOY1DMJ21NxOJ2xPRC/wAh/hzSBRVtoAnyuxtkZ4VjIOh
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26