Amazon-RSA-2048-M02.cer: CN=Amazon RSA 2048 M02,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-2048-M02.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-RSA-2048-M02.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:4a:4b:cb:d4:4e:c7:b5:3b:ea:f1:94:84:2d:3a:0f:a1
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 1
        Validity
            Not Before: Aug 23 22:25:30 2022 GMT
            Not After : Aug 23 22:25:30 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon RSA 2048 M02
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:bb:43:18:c6:5a:a8:79:de:29:e8:b5:6f:2e:be:
                    a5:43:cf:2e:58:d3:07:5e:37:4a:2e:95:a4:45:8f:
                    73:a9:92:90:58:59:6f:fe:aa:ae:46:72:a0:79:50:
                    2d:b0:d8:9c:8d:83:ee:10:f4:b1:dc:c4:a9:f9:ee:
                    02:32:2c:b9:74:0b:1b:70:3c:4e:f5:fa:57:7a:05:
                    34:11:55:7b:c3:65:2c:91:ef:06:c7:8a:63:cf:2c:
                    68:bc:2e:7f:19:19:57:09:3b:e2:0e:27:5a:53:4c:
                    5f:39:5a:f5:8e:45:df:0c:11:1f:03:15:1f:8e:37:
                    c4:6c:fa:52:d1:92:65:2a:90:f7:87:85:c7:95:fb:
                    4e:5a:ad:f3:08:62:f2:a0:9a:29:d6:79:ac:d6:a4:
                    fa:bf:67:51:38:4e:78:29:6a:15:de:28:5f:27:21:
                    ff:f4:5c:ed:8d:1e:5f:52:8d:58:76:12:23:53:64:
                    df:59:98:82:22:b7:26:f1:f4:eb:78:3e:2b:db:47:
                    03:ad:d9:79:38:0a:82:77:65:87:e5:88:fb:3b:fb:
                    8b:8e:07:7a:94:59:8c:0d:45:63:06:19:f5:5b:ff:
                    f5:49:02:e5:8c:fc:ff:25:3a:e5:f8:23:68:4f:b0:
                    54:73:38:7b:f6:32:0b:6a:2c:ac:f5:84:ee:02:7e:
                    75:73
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                C0:31:52:CD:5A:50:C3:82:7C:74:71:CE:CB:E9:9C:F9:7A:EB:82:E2
            X509v3 Authority Key Identifier: 
                keyid:84:18:CC:85:34:EC:BC:0C:94:94:2E:08:59:9C:C7:B2:10:4E:0A:08

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca1.amazontrust.com
                CA Issuers - URI:http://crt.rootca1.amazontrust.com/rootca1.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca1.amazontrust.com/rootca1.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha256WithRSAEncryption
         2d:4e:2e:85:b3:40:33:7e:2f:a2:c2:6e:e3:af:3f:82:4b:11:
         c7:fa:e1:e5:ec:b6:b0:dc:c4:12:5d:5b:51:f1:15:79:dc:fb:
         51:ea:bf:fa:80:da:6a:97:37:68:66:ae:05:29:b0:03:8b:5b:
         fd:06:e9:fc:45:8f:03:e7:5b:9e:75:17:e3:b1:b7:a8:76:2c:
         de:04:1f:27:5e:67:b2:0f:7d:c4:a7:b5:40:4e:3e:28:cd:c7:
         77:d5:81:55:7e:04:61:bd:34:b1:36:ba:d3:94:da:56:91:49:
         34:9b:70:4c:3e:ff:2c:83:7f:35:1e:10:3a:b8:46:28:90:4e:
         6a:f6:ec:2c:ff:76:24:2a:a4:62:13:3d:d3:b1:a5:a6:26:a2:
         11:66:13:1b:80:07:e9:ec:ee:c5:53:01:48:6f:b5:08:b2:9a:
         20:65:22:b1:3c:85:89:a7:18:8f:a3:74:dc:05:a9:9b:6d:5b:
         50:39:c3:51:5b:3e:6a:09:07:43:b2:52:36:c9:ac:aa:d2:7d:
         93:5e:81:f2:34:22:c4:1f:ca:e9:b0:94:55:20:b1:6c:83:48:
         dc:ec:16:85:ac:c9:c5:e3:ad:be:6a:34:9e:86:08:f5:d8:88:
         9d:35:e4:4d:e3:39:7e:12:83:5a:59:da:67:5a:77:6f:4a:90:
         04:92:ad:8f

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEXjCCA0agAwIBAgITB3MSSkvL1E7HtTvq8ZSELToPoTANBgkqhkiG9w0BAQsF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAxMB4XDTIyMDgyMzIyMjUzMFoXDTMwMDgyMzIyMjUzMFowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSAyMDQ4IE0wMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALtDGMZa
qHneKei1by6+pUPPLljTB143Si6VpEWPc6mSkFhZb/6qrkZyoHlQLbDYnI2D7hD0
sdzEqfnuAjIsuXQLG3A8TvX6V3oFNBFVe8NlLJHvBseKY88saLwufxkZVwk74g4n
WlNMXzla9Y5F3wwRHwMVH443xGz6UtGSZSqQ94eFx5X7Tlqt8whi8qCaKdZ5rNak
+r9nUThOeClqFd4oXych//Rc7Y0eX1KNWHYSI1Nk31mYgiK3JvH063g+K9tHA63Z
eTgKgndlh+WI+zv7i44HepRZjA1FYwYZ9Vv/9UkC5Yz8/yU65fgjaE+wVHM4e/Yy
C2osrPWE7gJ+dXMCAwEAAaOCAVowggFWMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYD
VR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNV
HQ4EFgQUwDFSzVpQw4J8dHHOy+mc+XrrguIwHwYDVR0jBBgwFoAUhBjMhTTsvAyU
lC4IWZzHshBOCggwewYIKwYBBQUHAQEEbzBtMC8GCCsGAQUFBzABhiNodHRwOi8v
b2NzcC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbTA6BggrBgEFBQcwAoYuaHR0cDov
L2NydC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbS9yb290Y2ExLmNlcjA/BgNVHR8E
ODA2MDSgMqAwhi5odHRwOi8vY3JsLnJvb3RjYTEuYW1hem9udHJ1c3QuY29tL3Jv
b3RjYTEuY3JsMBMGA1UdIAQMMAowCAYGZ4EMAQIBMA0GCSqGSIb3DQEBCwUAA4IB
AQAtTi6Fs0Azfi+iwm7jrz+CSxHH+uHl7Law3MQSXVtR8RV53PtR6r/6gNpqlzdo
Zq4FKbADi1v9Bun8RY8D51uedRfjsbeodizeBB8nXmeyD33Ep7VATj4ozcd31YFV
fgRhvTSxNrrTlNpWkUk0m3BMPv8sg381HhA6uEYokE5q9uws/3YkKqRiEz3TsaWm
JqIRZhMbgAfp7O7FUwFIb7UIspogZSKxPIWJpxiPo3TcBambbVtQOcNRWz5qCQdD
slI2yayq0n2TXoHyNCLEH8rpsJRVILFsg0jc7BaFrMnF462+ajSehgj12IidNeRN
4zl+EoNaWdpnWndvSpAEkq2P
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06