DigiCertBasicRSACNCAG2.crt: CN=DigiCert Basic RSA CN CA G2,O=DigiCert Inc,C=US (Intermediate Certificate, Expiring 2030-03-04) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://cacerts.digicert.cn/DigiCertBasicRSACNCAG2.crt" --output cert.crt

Download certificate through wget:

wget -q "http://cacerts.digicert.cn/DigiCertBasicRSACNCAG2.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            02:f7:e1:f9:82:ba:d0:09:af:f4:7d:c9:57:41:b2:f6
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
        Validity
            Not Before: Mar  4 12:04:07 2020 GMT
            Not After : Mar  4 12:04:07 2030 GMT
        Subject: C=US, O=DigiCert Inc, CN=DigiCert Basic RSA CN CA G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:be:3d:f6:fa:65:3d:85:f8:aa:33:63:50:8e:50:
                    4f:a5:20:71:cf:11:8e:45:89:15:d7:02:da:13:30:
                    bc:f6:cd:43:a4:4b:6e:39:af:10:11:87:8a:79:c3:
                    96:90:70:6f:c1:59:90:11:96:56:ff:83:8e:77:de:
                    f7:cd:b9:84:1c:04:1f:68:9a:23:40:fa:42:98:c4:
                    77:a4:5b:e4:48:47:54:68:c8:4b:82:1c:ba:6a:4a:
                    91:dd:d0:f6:d4:1a:58:f7:1e:58:1f:13:c8:2e:07:
                    e5:75:cf:15:14:d1:e3:6b:76:2b:7a:9a:65:b7:46:
                    3d:1a:78:3c:6d:eb:b0:92:d7:80:21:bc:33:57:03:
                    56:68:bb:70:3f:70:32:68:e2:e2:48:b2:d2:22:f9:
                    ff:c5:56:6a:39:b4:f5:21:eb:1c:2d:06:16:4e:70:
                    c2:21:8e:ee:78:f2:26:a4:d4:dd:a7:d8:69:fe:68:
                    5e:1d:5e:05:ad:62:2b:41:5e:1d:a6:fb:0a:e8:f1:
                    13:56:9f:8f:fe:bd:bf:cd:86:0a:28:2b:50:7c:b1:
                    36:a9:e6:ca:9c:69:1b:3d:ef:43:be:c7:09:8f:e3:
                    2a:f6:d8:24:ab:24:a9:27:01:17:f4:46:0c:4f:92:
                    2a:ec:73:c3:ff:8d:d8:4e:36:23:2f:ff:41:3f:1b:
                    8c:b3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                06:BD:A6:9B:60:79:50:31:BE:D5:A9:02:4A:A0:D0:95:53:8B:2F:34
            X509v3 Authority Key Identifier: 
                keyid:03:DE:50:35:56:D1:4C:BB:66:F0:A3:E2:1B:1B:C3:97:B2:3D:D1:55

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.cn

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.digicert.cn/DigiCertGlobalRootCA.crl

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.114412.1.1
                  CPS: https://www.digicert.com/CPS
                  User Notice:
                    Explicit Text: Any use of this Certificate constitutes acceptance of the Relying Party Agreement located at https://www.digicert.com/rpa-ua
                Policy: 2.23.140.1.2.2

    Signature Algorithm: sha256WithRSAEncryption
         0d:64:22:57:06:5e:94:07:62:12:52:c8:1f:9c:47:3b:76:02:
         d0:33:95:fc:bc:03:aa:d7:19:4e:e6:9d:9d:ef:42:35:4c:27:
         67:18:cf:fe:44:0b:2b:94:7b:d0:1f:98:72:1e:af:bb:ca:a2:
         78:62:c9:e9:bc:cf:06:1e:7f:b6:58:85:d5:80:5c:de:51:ff:
         68:d2:07:08:37:58:79:49:60:e8:a0:c5:c6:8d:d4:b8:d8:c5:
         28:b2:e0:2c:4c:7d:ab:79:e0:6e:34:be:14:30:32:68:4f:0e:
         66:23:04:d1:1b:64:22:df:3e:f8:55:54:c9:bd:74:4f:25:82:
         4b:f9:2a:d8:f4:77:51:1f:7f:36:60:40:17:2b:98:28:e1:a4:
         4c:6a:ab:d7:63:f3:9b:4d:f1:88:2f:4b:4a:2f:2d:4c:83:9a:
         1a:59:ad:52:94:d4:e0:99:aa:fe:80:4b:12:18:bb:81:f0:b6:
         35:c9:1e:ef:22:92:cc:09:b2:44:17:cd:d3:9c:27:2a:c3:c8:
         40:35:12:62:1a:15:45:c9:10:7b:e5:40:ee:48:74:22:e6:bb:
         de:66:ea:5f:cd:f0:1f:e8:e6:b2:00:49:39:36:37:a6:8c:eb:
         83:e4:08:1e:5e:f9:f2:97:cd:eb:3c:e2:77:c0:0c:75:71:73:
         03:c5:c2:d4

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFFTCCA/2gAwIBAgIQAvfh+YK60Amv9H3JV0Gy9jANBgkqhkiG9w0BAQsFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
QTAeFw0yMDAzMDQxMjA0MDdaFw0zMDAzMDQxMjA0MDdaMEoxCzAJBgNVBAYTAlVT
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxJDAiBgNVBAMTG0RpZ2lDZXJ0IEJhc2lj
IFJTQSBDTiBDQSBHMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL49
9vplPYX4qjNjUI5QT6Ugcc8RjkWJFdcC2hMwvPbNQ6RLbjmvEBGHinnDlpBwb8FZ
kBGWVv+Djnfe9825hBwEH2iaI0D6QpjEd6Rb5EhHVGjIS4IcumpKkd3Q9tQaWPce
WB8TyC4H5XXPFRTR42t2K3qaZbdGPRp4PG3rsJLXgCG8M1cDVmi7cD9wMmji4kiy
0iL5/8VWajm09SHrHC0GFk5wwiGO7njyJqTU3afYaf5oXh1eBa1iK0FeHab7Cujx
E1afj/69v82GCigrUHyxNqnmypxpGz3vQ77HCY/jKvbYJKskqScBF/RGDE+SKuxz
w/+N2E42Iy//QT8bjLMCAwEAAaOCAd4wggHaMB0GA1UdDgQWBBQGvaabYHlQMb7V
qQJKoNCVU4svNDAfBgNVHSMEGDAWgBQD3lA1VtFMu2bwo+IbG8OXsj3RVTAOBgNV
HQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwMwYIKwYBBQUHAQEEJzAlMCMGCCsGAQUFBzABhhdodHRw
Oi8vb2NzcC5kaWdpY2VydC5jbjBABgNVHR8EOTA3MDWgM6Axhi9odHRwOi8vY3Js
LmRpZ2ljZXJ0LmNuL0RpZ2lDZXJ0R2xvYmFsUm9vdENBLmNybDCB3QYDVR0gBIHV
MIHSMIHFBglghkgBhv1sAQEwgbcwKAYIKwYBBQUHAgEWHGh0dHBzOi8vd3d3LmRp
Z2ljZXJ0LmNvbS9DUFMwgYoGCCsGAQUFBwICMH4MfEFueSB1c2Ugb2YgdGhpcyBD
ZXJ0aWZpY2F0ZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSZWx5aW5n
IFBhcnR5IEFncmVlbWVudCBsb2NhdGVkIGF0IGh0dHBzOi8vd3d3LmRpZ2ljZXJ0
LmNvbS9ycGEtdWEwCAYGZ4EMAQICMA0GCSqGSIb3DQEBCwUAA4IBAQANZCJXBl6U
B2ISUsgfnEc7dgLQM5X8vAOq1xlO5p2d70I1TCdnGM/+RAsrlHvQH5hyHq+7yqJ4
YsnpvM8GHn+2WIXVgFzeUf9o0gcIN1h5SWDooMXGjdS42MUosuAsTH2reeBuNL4U
MDJoTw5mIwTRG2Qi3z74VVTJvXRPJYJL+SrY9HdRH382YEAXK5go4aRMaqvXY/Ob
TfGIL0tKLy1Mg5oaWa1SlNTgmar+gEsSGLuB8LY1yR7vIpLMCbJEF83TnCcqw8hA
NRJiGhVFyRB75UDuSHQi5rveZupfzfAf6OayAEk5NjemjOuD5AgeXvnyl83rPOJ3
wAx1cXMDxcLU
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06