Amazon-ECDSA-384-M04.cer: CN=Amazon ECDSA 384 M04,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: https://www.amazontrust.com/repository/Amazon-ECDSA-384-M04.cer (in DER format )
 - Serial Number : 166129428113730841837293432839745856477380212
 - SHA-1 Fingerprint : 5b07240ad433140b3d14dd5d3434656813f4f34d
 - SHA-1 Fingerprint : 5b:07:24:0a:d4:33:14:0b:3d:14:dd:5d:34:34:65:68:13:f4:f3:4d
 - SHA-256 Fingerprint : 47fd11ad552ab264d7f272770d3b5590aae145412f4ad6081bdc485298d8e000
 - SHA-256 Fingerprint : 47:fd:11:ad:55:2a:b2:64:d7:f2:72:77:0d:3b:55:90:aa:e1:45:41:2f:4a:d6:08:1b:dc:48:52:98:d8:e0:00
 - Signature Hash Algorithm : sha384
 - Subject
: CN=Amazon ECDSA 384 M04,O=Amazon,C=US
- Country Name: US (United States of America)
 - Organization: Amazon
 - Common Name: Amazon ECDSA 384 M04
 
 - Not Valid Before: 2022-08-23 22:38:01
 - Not Valid After: 2030-08-23 22:38:01
 - Issuer (Parent Certificate):
- Issuer Name: CN=Amazon Root CA 4,O=Amazon,C=US
 - Issuer Certificate URL: NA
 
 - Audit Record:
- Revocation Status: Not Revoked
 - Certificate Policy (CP) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cp-v5-12-Final.pdf
 - Certificate Practice Statement (CPS) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cps-v5-12-Final.pdf
 - Auditor: BDO International Limited
 - Standard Audit URL: https://bugzilla.mozilla.org/attachment.cgi?id=9309728
 - Standard Audit Period Start Date: 2021.10.01
 - Standard Audit Period End Date: 2022.09.30
 - Standard Audit Statement Date: 2022.12.22
 - Standard Audit Type: WebTrust
 - Full CRL Issued By This CA: http://crl.e3m04.amazontrust.com/e3m04.crl
 - Check its issuer’s audit information: CN=Amazon Root CA 4,O=Amazon,C=US .
 
 
Download certificate through curl:
curl -sSL "https://www.amazontrust.com/repository/Amazon-ECDSA-384-M04.cer" --output cert.crt
Download certificate through wget:
wget -q "https://www.amazontrust.com/repository/Amazon-ECDSA-384-M04.cer" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509 to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509 to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:82:b8:d0:eb:83:b7:b3:74:00:58:da:b4:97:d0:be:74
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 4
        Validity
            Not Before: Aug 23 22:38:01 2022 GMT
            Not After : Aug 23 22:38:01 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon ECDSA 384 M04
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:2b:5f:5f:7d:27:77:62:8b:e2:f9:0c:4e:cd:5a:
                    ae:4b:d6:a8:9a:dc:9c:ef:1b:0f:5e:51:0b:05:61:
                    b9:9b:1c:2c:07:c8:dc:7b:83:c0:85:47:6b:cc:d9:
                    bd:ba:62:41:48:47:3d:c0:32:3f:4f:e0:4c:39:34:
                    06:11:36:ae:9c:a2:13:d0:16:7e:07:af:10:10:0e:
                    f6:42:0f:47:ee:0b:5b:1a:2b:ae:42:e0:7a:a9:d5:
                    63:cc:b2:d8:d9:f2:f2
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                52:F0:D2:50:80:3C:D4:19:11:C8:83:6F:0E:02:BE:A8:4A:17:4D:C7
            X509v3 Authority Key Identifier: 
                keyid:D3:EC:C7:3A:65:6E:CC:E1:DA:76:9A:56:FB:9C:F3:86:6D:57:E5:81
            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca4.amazontrust.com
                CA Issuers - URI:http://crt.rootca4.amazontrust.com/rootca4.cer
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://crl.rootca4.amazontrust.com/rootca4.crl
            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
    Signature Algorithm: ecdsa-with-SHA384
         30:65:02:30:60:d5:94:37:9d:7e:7a:8b:e2:8b:4c:45:2f:3c:
         0b:91:ee:d4:7d:5c:d1:fd:12:78:3d:a1:d7:24:b6:33:ed:3d:
         f0:8c:ba:c4:c8:d7:95:14:f2:15:b3:b2:57:2d:9a:4b:02:31:
         00:e5:48:a6:63:f4:76:6f:3f:53:03:f9:ae:2e:d6:c0:62:33:
         a3:87:6f:04:13:c5:cd:87:69:10:13:25:34:3a:14:e1:b3:fd:
         43:05:c4:a4:b7:8b:4a:09:e7:ad:41:04:9a
CA Certificate in PEM Format
Use openssl x509 to convert certificate from DER format to PEM format:
openssl x509 -in cert.crt -inform der
Converted PEM format certificate:
-----BEGIN CERTIFICATE-----
MIIDEDCCApagAwIBAgITB3MSgrjQ64O3s3QAWNq0l9C+dDAKBggqhkjOPQQDAzA5
MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6b24g
Um9vdCBDQSA0MB4XDTIyMDgyMzIyMzgwMVoXDTMwMDgyMzIyMzgwMVowPTELMAkG
A1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEdMBsGA1UEAxMUQW1hem9uIEVDRFNB
IDM4NCBNMDQwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQrX199J3dii+L5DE7NWq5L
1qia3JzvGw9eUQsFYbmbHCwHyNx7g8CFR2vM2b26YkFIRz3AMj9P4Ew5NAYRNq6c
ohPQFn4HrxAQDvZCD0fuC1saK65C4Hqp1WPMstjZ8vKjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFFLw0lCAPNQZEciDbw4CvqhKF03HMB8GA1Ud
IwQYMBaAFNPsxzplbszh2naaVvuc84ZtV+WBMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhNC5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhNC5hbWF6b250cnVzdC5jb20vcm9v
dGNhNC5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2E0LmFt
YXpvbnRydXN0LmNvbS9yb290Y2E0LmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAK
BggqhkjOPQQDAwNoADBlAjBg1ZQ3nX56i+KLTEUvPAuR7tR9XNH9Eng9odcktjPt
PfCMusTI15UU8hWzslctmksCMQDlSKZj9HZvP1MD+a4u1sBiM6OHbwQTxc2HaRAT
JTQ6FOGz/UMFxKS3i0oJ561BBJo=
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Amazon-ECDSA-256-M01.cer: CN=Amazon ECDSA 256 M01,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-ECDSA-256-M02.cer: CN=Amazon ECDSA 256 M02,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-ECDSA-256-M03.cer: CN=Amazon ECDSA 256 M03,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-ECDSA-256-M04.cer: CN=Amazon ECDSA 256 M04,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-ECDSA-384-M01.cer: CN=Amazon ECDSA 384 M01,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-ECDSA-384-M02.cer: CN=Amazon ECDSA 384 M02,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-ECDSA-384-M03.cer: CN=Amazon ECDSA 384 M03,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-2048-M01.cer: CN=Amazon RSA 2048 M01,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-2048-M02.cer: CN=Amazon RSA 2048 M02,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-2048-M03.cer: CN=Amazon RSA 2048 M03,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-2048-M04.cer: CN=Amazon RSA 2048 M04,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-4096-M01.cer: CN=Amazon RSA 4096 M01,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-4096-M02.cer: CN=Amazon RSA 4096 M02,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-4096-M03.cer: CN=Amazon RSA 4096 M03,O=Amazon,C=US (Expiring: 2030-08-23)
 - Amazon-RSA-4096-M04.cer: CN=Amazon RSA 4096 M04,O=Amazon,C=US (Expiring: 2030-08-23)
 - rootca1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
 - AmazonRootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2038-01-17)
 - G2-RootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
 - G2-RootCA1.orig.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
 - AmazonRootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2040-05-26)
 - G2-RootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
 - G2-RootCA2.orig.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
 - AmazonRootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2040-05-26)
 - G2-RootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
 - G2-RootCA3.orig.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
 - AmazonRootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2040-05-26)
 - G2-RootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
 - G2-RootCA4.orig.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
 - G2-ServerCA0A.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2025-10-19)
 - G2-ServerCA0A.orig.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2040-10-21)
 - R1-ServerCA1A.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2025-10-19)
 - R1-ServerCA1A.orig.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2040-10-21)
 - sca1b.crt: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
 - R1-ServerCA1B.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
 - R1-ServerCA1B.orig.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2040-10-21)
 - R2-ServerCA2A.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2025-10-19)
 - R2-ServerCA2A.orig.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2040-10-21)
 - R3-ServerCA3A.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2025-10-19)
 - R3-ServerCA3A.orig.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2040-10-21)
 - R3-ServerCA3B.cer: CN=Amazon,OU=Server CA 3B,O=Amazon,C=US (Expiring: 2028-07-16)
 - R4-ServerCA4A.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2025-10-19)
 - R4-ServerCA4A.orig.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2040-10-21)
 - rootg2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
 - SFC2CA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
 - SFC2CA-SFSRootCAG2.v2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
 - SFSRootCA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2031-05-30)
 - SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2037-12-31)