appleistca2g1_bc.cer: C=US,O=Apple Inc.,OU=Certification Authority,CN=Apple IST CA 2 - G1 (Intermediate Certificate, Expiring 2025-05-07) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://certs.apple.com/appleistca2g1_bc.cer" --output cert.crt

Download certificate through wget:

wget -q "http://certs.apple.com/appleistca2g1_bc.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            05:52:c7:ef:fe:ec:29:2b:a9:f1:38:7b:07:af:92:9f
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
        Validity
            Not Before: Dec 12 12:00:00 2018 GMT
            Not After : May  7 12:00:00 2025 GMT
        Subject: CN=Apple IST CA 2 - G1, OU=Certification Authority, O=Apple Inc., C=US
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:d0:93:a1:1d:47:43:20:16:b2:0b:6b:eb:c3:d5:
                    b4:e8:c7:98:cd:f3:de:bf:e8:4d:e9:e3:36:80:07:
                    fc:45:1b:6a:7c:45:86:ae:56:d3:a4:09:7f:61:0d:
                    6b:5d:7e:52:6b:7d:b4:c8:39:c4:f4:67:3a:f7:83:
                    ce:19:6f:86:2f:7e:45:7e:47:1c:67:52:ca:95:05:
                    5d:e2:36:51:85:c0:d4:67:80:35:6f:15:dd:3e:fd:
                    1d:d2:fd:8f:34:50:d8:ec:76:2a:be:e3:d3:da:e4:
                    fd:c8:eb:28:02:96:11:97:17:61:1c:e9:c4:59:3b:
                    42:dc:32:d1:09:1d:da:a6:d1:43:86:ff:5e:b2:bc:
                    8c:cf:66:db:01:8b:02:ae:94:48:f3:38:8f:fd:ea:
                    32:a8:08:ec:86:97:51:94:24:3e:49:49:96:53:e8:
                    79:a1:40:81:e9:05:bb:93:95:51:fc:e3:fd:7c:11:
                    4b:f7:9e:08:b3:15:49:15:07:f9:d1:37:a0:9b:4b:
                    32:f6:b5:c4:dc:6a:d1:fc:0a:ed:f6:e0:c5:29:a0:
                    a8:8b:71:fe:0d:92:bc:fe:54:70:18:0a:6d:c7:ed:
                    0c:fb:c9:2d:06:c3:8c:85:fc:cb:86:5c:d6:36:8e:
                    12:8b:09:7f:fb:19:1a:38:d5:f0:94:30:7a:0f:a6:
                    8c:f3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                D8:7A:94:44:7C:90:70:90:16:9E:DD:17:9C:01:44:03:86:D6:2A:29
            X509v3 Authority Key Identifier: 
                keyid:E5:9D:59:30:82:47:58:CC:AC:FA:08:54:36:86:7B:3A:B5:04:4D:F0

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl3.digicert.com/Omniroot2025.crl

            X509v3 Certificate Policies: 
                Policy: 1.2.840.113635.100.5.11.4
                Policy: 2.23.140.1.2.2
                Policy: 2.16.840.1.114412.0.2.4
                  CPS: https://www.digicert.com/CPS

    Signature Algorithm: sha256WithRSAEncryption
         5a:00:e8:6d:a6:78:0e:af:33:48:e7:72:5a:f0:9a:f9:36:9d:
         eb:43:88:c0:4f:6a:93:3d:a8:df:72:85:09:c0:0c:fc:2b:f1:
         5e:b7:17:4d:36:28:f5:52:47:9e:29:c4:f8:6f:52:82:e2:1d:
         ba:49:03:0c:03:87:31:3f:16:be:ca:a8:9b:27:4c:5e:49:d0:
         25:56:d1:10:e0:17:29:42:a0:4b:9a:b4:ff:da:2e:f4:dd:45:
         8c:9b:e4:84:f1:85:cc:06:ee:2e:74:89:b4:ba:26:7c:93:f1:
         1d:6e:21:de:5e:9b:76:58:90:a1:d5:50:5d:dd:f1:51:b5:d1:
         a9:32:8d:51:b1:7d:6c:88:78:eb:4d:7e:2a:1c:99:2f:4b:b4:
         07:f7:93:a6:97:ff:d4:ee:52:fa:a1:40:c9:10:03:af:59:6f:
         7c:87:8d:1d:9b:f5:d6:2c:9f:e2:ee:de:b8:b0:6c:5e:3c:93:
         de:f3:f0:c6:b8:a1:a4:0c:01:e6:9b:bf:0e:12:56:87:88:af:
         ef:44:3b:a5:cb:c0:69:14:5f:88:98:0c:8f:70:34:7c:58:2f:
         aa:f1:9b:5b:d8:e6:b7:4e:3e:0a:bf:cf:8e:95:9e:30:5b:77:
         28:a8:f7:0d:18:78:8c:92:a3:25:41:ad:f8:9c:5d:18:62:78:
         b4:21:b2:0b

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEnjCCA4agAwIBAgIQBVLH7/7sKSup8Th7B6+SnzANBgkqhkiG9w0BAQsFADBa
MQswCQYDVQQGEwJJRTESMBAGA1UEChMJQmFsdGltb3JlMRMwEQYDVQQLEwpDeWJl
clRydXN0MSIwIAYDVQQDExlCYWx0aW1vcmUgQ3liZXJUcnVzdCBSb290MB4XDTE4
MTIxMjEyMDAwMFoXDTI1MDUwNzEyMDAwMFowYjEcMBoGA1UEAxMTQXBwbGUgSVNU
IENBIDIgLSBHMTEgMB4GA1UECxMXQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxEzAR
BgNVBAoTCkFwcGxlIEluYy4xCzAJBgNVBAYTAlVTMIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEA0JOhHUdDIBayC2vrw9W06MeYzfPev+hN6eM2gAf8RRtq
fEWGrlbTpAl/YQ1rXX5Sa320yDnE9Gc694POGW+GL35FfkccZ1LKlQVd4jZRhcDU
Z4A1bxXdPv0d0v2PNFDY7HYqvuPT2uT9yOsoApYRlxdhHOnEWTtC3DLRCR3aptFD
hv9esryMz2bbAYsCrpRI8ziP/eoyqAjshpdRlCQ+SUmWU+h5oUCB6QW7k5VR/OP9
fBFL954IsxVJFQf50Tegm0sy9rXE3GrR/Art9uDFKaCoi3H+DZK8/lRwGAptx+0M
+8ktBsOMhfzLhlzWNo4Siwl/+xkaONXwlDB6D6aM8wIDAQABo4IBVjCCAVIwHQYD
VR0OBBYEFNh6lER8kHCQFp7dF5wBRAOG1iopMB8GA1UdIwQYMBaAFOWdWTCCR1jM
rPoIVDaGezq1BE3wMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADA0BggrBgEFBQcBAQQoMCYw
JAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTA6BgNVHR8EMzAx
MC+gLaArhilodHRwOi8vY3JsMy5kaWdpY2VydC5jb20vT21uaXJvb3QyMDI1LmNy
bDBbBgNVHSAEVDBSMAwGCiqGSIb3Y2QFCwQwCAYGZ4EMAQICMDgGCmCGSAGG/WwA
AgQwKjAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cuZGlnaWNlcnQuY29tL0NQUzAN
BgkqhkiG9w0BAQsFAAOCAQEAWgDobaZ4Dq8zSOdyWvCa+Tad60OIwE9qkz2o33KF
CcAM/CvxXrcXTTYo9VJHninE+G9SguIdukkDDAOHMT8WvsqomydMXknQJVbREOAX
KUKgS5q0/9ou9N1FjJvkhPGFzAbuLnSJtLomfJPxHW4h3l6bdliQodVQXd3xUbXR
qTKNUbF9bIh4601+KhyZL0u0B/eTppf/1O5S+qFAyRADr1lvfIeNHZv11iyf4u7e
uLBsXjyT3vPwxrihpAwB5pu/DhJWh4iv70Q7pcvAaRRfiJgMj3A0fFgvqvGbW9jm
t04+Cr/PjpWeMFt3KKj3DRh4jJKjJUGt+JxdGGJ4tCGyCw==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06