Amazon-ECDSA-384-M01.cer: CN=Amazon ECDSA 384 M01,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-ECDSA-384-M01.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-ECDSA-384-M01.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:75:7e:f4:c3:66:0f:08:af:24:03:d3:e5:54:35:d4:0b
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 4
        Validity
            Not Before: Aug 23 22:35:05 2022 GMT
            Not After : Aug 23 22:35:05 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon ECDSA 384 M01
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:39:6e:64:e2:66:cd:66:2f:46:3b:a2:3d:ce:f8:
                    66:d9:c1:94:ea:35:e0:ac:30:72:f1:e2:6b:b7:e4:
                    9f:ad:ba:f6:69:93:ad:e1:90:9f:fa:fd:4d:91:d8:
                    22:ee:62:78:68:ea:74:06:ff:b5:de:cc:db:fa:b3:
                    08:92:3b:4f:a3:d1:3e:12:43:fc:f6:5d:eb:ae:99:
                    f9:a9:78:52:c2:fe:b9:fa:2b:1f:89:69:2f:de:bc:
                    f7:bd:4d:42:1c:b7:4e
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                03:E4:A4:04:8E:05:7F:9A:12:97:84:04:FF:11:77:30:8C:BA:2A:A7
            X509v3 Authority Key Identifier: 
                keyid:D3:EC:C7:3A:65:6E:CC:E1:DA:76:9A:56:FB:9C:F3:86:6D:57:E5:81

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca4.amazontrust.com
                CA Issuers - URI:http://crt.rootca4.amazontrust.com/rootca4.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca4.amazontrust.com/rootca4.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: ecdsa-with-SHA384
         30:65:02:31:00:84:cb:f5:3a:f0:95:e0:63:1d:3d:e8:2e:75:
         12:70:91:a2:fd:6a:8d:a0:5a:a7:83:79:4e:58:10:ff:16:b8:
         07:17:e6:c0:79:a4:df:67:62:f5:2d:11:57:70:d3:d1:1a:02:
         30:61:1e:79:59:91:3f:ec:6b:a6:c8:93:48:23:8c:92:ca:8e:
         6d:a3:ce:27:4e:b8:53:f7:b7:ce:c3:35:74:a7:e9:22:b3:56:
         e6:18:11:aa:e0:da:86:04:2d:f1:76:d4:19

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDEDCCApagAwIBAgITB3MSdX70w2YPCK8kA9PlVDXUCzAKBggqhkjOPQQDAzA5
MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6b24g
Um9vdCBDQSA0MB4XDTIyMDgyMzIyMzUwNVoXDTMwMDgyMzIyMzUwNVowPTELMAkG
A1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEdMBsGA1UEAxMUQW1hem9uIEVDRFNB
IDM4NCBNMDEwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQ5bmTiZs1mL0Y7oj3O+GbZ
wZTqNeCsMHLx4mu35J+tuvZpk63hkJ/6/U2R2CLuYnho6nQG/7XezNv6swiSO0+j
0T4SQ/z2XeuumfmpeFLC/rn6Kx+JaS/evPe9TUIct06jggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFAPkpASOBX+aEpeEBP8RdzCMuiqnMB8GA1Ud
IwQYMBaAFNPsxzplbszh2naaVvuc84ZtV+WBMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhNC5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhNC5hbWF6b250cnVzdC5jb20vcm9v
dGNhNC5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2E0LmFt
YXpvbnRydXN0LmNvbS9yb290Y2E0LmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAK
BggqhkjOPQQDAwNoADBlAjEAhMv1OvCV4GMdPegudRJwkaL9ao2gWqeDeU5YEP8W
uAcX5sB5pN9nYvUtEVdw09EaAjBhHnlZkT/sa6bIk0gjjJLKjm2jzidOuFP3t87D
NXSn6SKzVuYYEarg2oYELfF21Bk=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06