DigiCertGlobalG3TLSECCSHA3842020CA1.crt: CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1,O=DigiCert Inc,C=US

Page content

CA Certificate Basic Information

This certificate is intermediate certificate used for the issuance of other certificates.

  • Certificate download URL: http://cacerts.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1.crt (DER format)
  • Serial number: 17560596793023370858630914980245971165
  • SHA-1 Fingerprint: 427bc3298045e99e093eeca667ae955f099cd1cd
  • SHA-1 Fingerprint: 42:7b:c3:29:80:45:e9:9e:09:3e:ec:a6:67:ae:95:5f:09:9c:d1:cd
  • SHA-256 Fingerprint: 338edb04fb8beaf07a10749e7f4e538de0715dafb6478d58063fb7c8bdb0c30d
  • SHA-256 Fingerprint: 33:8e:db:04:fb:8b:ea:f0:7a:10:74:9e:7f:4e:53:8d:e0:71:5d:af:b6:47:8d:58:06:3f:b7:c8:bd:b0:c3:0d
  • Signature hash algorithm: sha384
  • Subject: CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1,O=DigiCert Inc,C=US
  • Not valid before: 2020-09-24 00:00:00
  • Not valid after: 2030-09-23 23:59:59
  • Issuer:

Download certificate through curl:

curl -sSL http://cacerts.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1.crt --output cert.crt

Download certificate through wget:

wget -q http://cacerts.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0d:36:0c:44:84:91:ce:24:ed:0b:35:40:d8:70:a0:dd
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
        Validity
            Not Before: Sep 24 00:00:00 2020 GMT
            Not After : Sep 23 23:59:59 2030 GMT
        Subject: C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:78:a9:9c:75:ae:88:5d:63:a4:ad:5d:86:d8:10:
                    49:d6:af:92:59:63:43:23:85:f4:48:65:30:cd:4a:
                    34:95:a6:0e:3e:d9:7c:08:d7:57:05:28:48:9e:0b:
                    ab:eb:c2:d3:96:9e:ed:45:d2:8b:8a:ce:01:4b:17:
                    43:e1:73:cf:6d:73:48:34:dc:00:46:09:b5:56:54:
                    c9:5f:7a:c7:13:07:d0:6c:18:17:6c:ca:db:c7:0b:
                    26:56:2e:8d:07:f5:67
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                8A:23:EB:9E:6B:D7:F9:37:5D:F9:6D:21:39:76:9A:A1:67:DE:10:A8
            X509v3 Authority Key Identifier: 
                keyid:B3:DB:48:A4:F9:A1:C5:D8:AE:36:41:CC:11:63:69:62:29:BC:4B:C6

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com
                CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalRootG3.crt

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl3.digicert.com/DigiCertGlobalRootG3.crl

                Full Name:
                  URI:http://crl4.digicert.com/DigiCertGlobalRootG3.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.1
                Policy: 2.23.140.1.2.1
                Policy: 2.23.140.1.2.2
                Policy: 2.23.140.1.2.3

    Signature Algorithm: ecdsa-with-SHA384
         30:66:02:31:00:93:50:63:a8:3b:e1:b0:34:71:a3:8f:ff:4c:
         f4:27:f5:a2:56:d7:a9:0f:a7:dc:40:c3:e0:34:10:9d:ba:75:
         db:d9:d9:71:b3:54:a9:b1:33:93:16:73:cf:e2:dd:56:2f:02:
         31:00:85:97:b5:67:3d:74:b0:62:c1:ef:6d:a2:25:68:1e:c9:
         1b:a1:22:93:17:18:ec:b5:f7:e4:25:7e:ca:9b:95:4d:b2:99:
         92:30:13:4e:f4:4e:82:62:f9:02:04:db:b0:08

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDpjCCAyugAwIBAgIQDTYMRISRziTtCzVA2HCg3TAKBggqhkjOPQQDAzBhMQsw
CQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cu
ZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBHMzAe
Fw0yMDA5MjQwMDAwMDBaFw0zMDA5MjMyMzU5NTlaMFkxCzAJBgNVBAYTAlVTMRUw
EwYDVQQKEwxEaWdpQ2VydCBJbmMxMzAxBgNVBAMTKkRpZ2lDZXJ0IEdsb2JhbCBH
MyBUTFMgRUNDIFNIQTM4NCAyMDIwIENBMTB2MBAGByqGSM49AgEGBSuBBAAiA2IA
BHipnHWuiF1jpK1dhtgQSdavklljQyOF9EhlMM1KNJWmDj7ZfAjXVwUoSJ4Lq+vC
05ae7UXSi4rOAUsXQ+Fzz21zSDTcAEYJtVZUyV96xxMH0GwYF2zK28cLJlYujQf1
Z6OCAa4wggGqMB0GA1UdDgQWBBSKI+uea9f5N135bSE5dpqhZ94QqDAfBgNVHSME
GDAWgBSz20ik+aHF2K42QcwRY2liKbxLxjAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0l
BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBIGA1UdEwEB/wQIMAYBAf8CAQAwdgYI
KwYBBQUHAQEEajBoMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdpY2VydC5j
b20wQAYIKwYBBQUHMAKGNGh0dHA6Ly9jYWNlcnRzLmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEdsb2JhbFJvb3RHMy5jcnQwewYDVR0fBHQwcjA3oDWgM4YxaHR0cDovL2Ny
bDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0R2xvYmFsUm9vdEczLmNybDA3oDWgM4Yx
aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0R2xvYmFsUm9vdEczLmNy
bDAwBgNVHSAEKTAnMAcGBWeBDAEBMAgGBmeBDAECATAIBgZngQwBAgIwCAYGZ4EM
AQIDMAoGCCqGSM49BAMDA2kAMGYCMQCTUGOoO+GwNHGjj/9M9Cf1olbXqQ+n3EDD
4DQQnbp129nZcbNUqbEzkxZzz+LdVi8CMQCFl7VnPXSwYsHvbaIlaB7JG6EikxcY
7LX35CV+ypuVTbKZkjATTvROgmL5AgTbsAg=
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26