Amazon-RSA-4096-M02.cer: CN=Amazon RSA 4096 M02,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-4096-M02.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-RSA-4096-M02.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:5b:0c:34:c3:c9:40:29:9a:9f:04:a3:9e:5a:52:cc:d9
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
        Validity
            Not Before: Aug 23 22:29:13 2022 GMT
            Not After : Aug 23 22:29:13 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon RSA 4096 M02
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:c1:8c:97:fa:59:d4:eb:31:1d:8f:60:c3:f6:1f:
                    74:e3:78:9a:6a:c0:36:43:f0:8b:bc:f6:76:31:c0:
                    e4:42:ed:fe:f4:48:dd:2b:b4:95:ee:8e:a2:2a:4b:
                    7f:4d:e2:ca:80:a7:63:2e:18:ae:97:d3:6e:1c:83:
                    ae:21:3c:34:9a:69:b3:63:83:27:95:b5:87:4a:f3:
                    e8:53:35:43:92:6d:df:9c:1f:93:ee:02:11:f0:13:
                    05:37:a0:1d:59:54:27:4a:c9:83:32:b9:62:5f:e3:
                    ae:4d:76:66:c0:b8:65:e4:67:e7:8b:21:b3:37:0a:
                    e9:b1:e3:e0:b6:48:1d:78:6b:60:82:1f:7a:d0:4c:
                    30:3f:15:ee:19:61:77:9e:00:72:51:16:ba:d5:15:
                    78:11:23:91:20:b3:0d:29:3e:a5:02:88:8c:22:f4:
                    72:ba:af:45:23:ef:50:da:f2:fc:15:7a:e7:37:c6:
                    99:c7:92:63:1a:5c:2e:65:7b:93:b4:a9:c2:9a:3e:
                    d7:3f:30:f8:e7:5f:9f:1d:af:b2:6e:e8:94:f9:5d:
                    7d:a4:e1:aa:4e:9f:5c:1b:48:9c:e4:65:e0:47:f7:
                    db:11:77:54:34:f5:dd:47:97:b5:03:e8:94:58:67:
                    a7:c5:0e:72:2e:b8:6d:6f:91:f2:d6:ed:1a:95:17:
                    20:0f:03:86:bf:12:81:83:c7:e8:d5:b8:8e:15:03:
                    e3:e0:06:f3:27:ab:f1:cb:40:d4:79:7d:b6:af:ba:
                    b5:8a:f6:ea:ad:f2:b8:22:ee:e6:bc:09:75:f3:06:
                    eb:7e:1f:58:84:57:4a:3f:86:26:2f:12:7c:07:46:
                    b4:fc:97:c2:ee:7b:f7:d3:56:7a:c5:78:bd:49:2b:
                    91:25:dd:20:12:b8:4d:00:ae:2b:e8:f1:68:9e:58:
                    f9:9a:36:97:71:85:b1:6c:8c:3c:d3:91:2e:3a:10:
                    5d:b8:c5:e8:a0:32:8d:3c:88:08:ba:bd:57:3a:10:
                    2a:1c:b1:e0:b9:76:08:da:d0:bf:c0:b1:aa:d0:c2:
                    1a:f5:e2:f6:44:44:25:80:05:ea:5b:1c:38:1d:31:
                    82:50:00:17:99:67:75:c6:8d:91:51:c4:54:e3:1d:
                    83:d6:59:b5:d2:72:c0:75:a6:f1:07:9d:d5:6b:72:
                    da:aa:fe:86:60:3b:6e:8a:16:40:d4:44:d7:69:d6:
                    d6:78:82:e4:3e:1c:3f:6c:a4:3c:af:47:4a:06:fb:
                    c5:67:54:17:7d:95:89:d5:1c:f6:d3:4a:33:ac:4a:
                    8d:27:7f:47:fb:4f:a7:e5:c0:c9:b3:52:c0:4a:28:
                    3e:dd:ff:3a:fc:a1:a5:54:63:2e:e5:a8:aa:a6:c2:
                    95:32:9d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                9E:71:1F:1A:1D:93:A9:D9:2D:8E:CC:48:53:3F:03:54:F3:9E:E6:66
            X509v3 Authority Key Identifier: 
                keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca2.amazontrust.com
                CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca2.amazontrust.com/rootca2.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha384WithRSAEncryption
         97:51:a0:29:73:a7:d2:3d:4c:59:3d:4a:25:54:9e:c1:0d:bc:
         48:66:e2:7b:75:30:66:3d:5d:32:c8:c9:6a:60:ab:40:f9:f6:
         9e:04:8d:6c:b9:bd:fa:e9:45:88:10:d4:f3:12:91:f5:9c:77:
         b5:9a:6c:e7:92:14:29:62:d4:3e:47:cc:0b:eb:e4:57:b6:ac:
         0c:1a:aa:cf:31:34:17:f3:24:7a:48:0f:7c:e8:f1:d5:5f:52:
         e9:67:e0:de:c4:a0:fb:d2:9c:96:eb:ab:5c:51:25:ae:ea:8a:
         7c:e9:b8:72:a9:a4:57:be:fa:5f:51:be:01:a6:90:ee:69:54:
         82:20:98:8b:a3:6a:45:04:b2:86:7f:33:ac:a9:0d:9d:b3:ba:
         40:be:5a:f4:80:82:e3:b9:22:65:84:40:47:f8:51:bd:93:ad:
         d7:54:14:2b:9b:42:31:72:57:a3:48:8e:e1:72:a4:32:ef:a3:
         76:77:a1:3f:59:21:e3:1b:99:85:8c:e7:22:02:8a:e8:c2:48:
         21:31:48:fc:98:fc:f5:4e:12:38:f9:dc:ca:e4:bd:e2:c5:2e:
         13:61:2a:be:f3:bf:b7:cd:6a:7a:87:b2:eb:04:e1:cf:98:91:
         6d:4f:f4:0a:f0:c5:9d:33:20:79:b5:86:51:9d:94:64:9f:9a:
         cf:fa:db:dc:a6:17:19:f5:56:6a:c2:c8:a2:79:2f:61:3e:f3:
         bc:73:86:34:00:3d:a1:0f:13:4e:03:ce:98:f7:d2:57:27:e9:
         a6:52:ad:3b:f6:b2:6d:6a:79:41:21:f6:72:c2:30:ba:fc:39:
         76:49:a9:91:ce:36:88:3e:7b:5c:7a:1b:e4:b6:cc:26:0f:7d:
         cf:7b:d0:06:6a:1d:fe:2a:66:3a:93:43:f7:9f:c1:78:0d:a6:
         96:50:59:81:9e:77:4b:49:ef:0d:70:f3:6f:34:7d:15:df:35:
         3c:0c:fd:42:bb:a8:74:e2:4a:70:3e:a9:94:a4:23:66:39:0b:
         cc:d8:75:bf:f4:68:08:53:bc:92:22:46:13:85:01:31:33:3c:
         15:49:34:0d:71:f8:6c:02:c8:23:8c:30:98:37:a5:ad:25:2e:
         94:ab:c3:4c:3c:59:bc:f1:78:75:b1:17:20:23:4f:77:9d:44:
         30:63:e0:11:3c:70:6e:83:95:f9:bc:d6:15:52:34:21:64:3c:
         3e:16:76:56:e3:0f:0e:4d:ad:68:e3:29:36:cb:8b:b6:56:1c:
         da:dc:0f:6f:da:ff:1e:f8:2f:ec:6e:be:22:da:41:1d:9c:0e:
         56:dd:68:23:7a:47:6e:33:29:ec:fd:e9:39:94:8f:af:a1:b5:
         5a:43:72:f6:65:fc:ad:57

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIGXjCCBEagAwIBAgITB3MSWww0w8lAKZqfBKOeWlLM2TANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTIyMDgyMzIyMjkxM1oXDTMwMDgyMzIyMjkxM1owPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSA0MDk2IE0wMjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAMGMl/pZ
1OsxHY9gw/YfdON4mmrANkPwi7z2djHA5ELt/vRI3Su0le6OoipLf03iyoCnYy4Y
rpfTbhyDriE8NJpps2ODJ5W1h0rz6FM1Q5Jt35wfk+4CEfATBTegHVlUJ0rJgzK5
Yl/jrk12ZsC4ZeRn54shszcK6bHj4LZIHXhrYIIfetBMMD8V7hlhd54AclEWutUV
eBEjkSCzDSk+pQKIjCL0crqvRSPvUNry/BV65zfGmceSYxpcLmV7k7Spwpo+1z8w
+Odfnx2vsm7olPldfaThqk6fXBtInORl4Ef32xF3VDT13UeXtQPolFhnp8UOci64
bW+R8tbtGpUXIA8Dhr8SgYPH6NW4jhUD4+AG8yer8ctA1Hl9tq+6tYr26q3yuCLu
5rwJdfMG634fWIRXSj+GJi8SfAdGtPyXwu5799NWesV4vUkrkSXdIBK4TQCuK+jx
aJ5Y+Zo2l3GFsWyMPNORLjoQXbjF6KAyjTyICLq9VzoQKhyx4Ll2CNrQv8CxqtDC
GvXi9kREJYAF6lscOB0xglAAF5lndcaNkVHEVOMdg9ZZtdJywHWm8Qed1Wty2qr+
hmA7booWQNRE12nW1niC5D4cP2ykPK9HSgb7xWdUF32VidUc9tNKM6xKjSd/R/tP
p+XAybNSwEooPt3/OvyhpVRjLuWoqqbClTKdAgMBAAGjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFJ5xHxodk6nZLY7MSFM/A1TznuZmMB8GA1Ud
IwQYMBaAFLAM8Eww9AVYAkj9M+VSr0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9v
dGNhMi5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFt
YXpvbnRydXN0LmNvbS9yb290Y2EyLmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAN
BgkqhkiG9w0BAQwFAAOCAgEAl1GgKXOn0j1MWT1KJVSewQ28SGbie3UwZj1dMsjJ
amCrQPn2ngSNbLm9+ulFiBDU8xKR9Zx3tZps55IUKWLUPkfMC+vkV7asDBqqzzE0
F/MkekgPfOjx1V9S6Wfg3sSg+9KcluurXFElruqKfOm4cqmkV776X1G+AaaQ7mlU
giCYi6NqRQSyhn8zrKkNnbO6QL5a9ICC47kiZYRAR/hRvZOt11QUK5tCMXJXo0iO
4XKkMu+jdnehP1kh4xuZhYznIgKK6MJIITFI/Jj89U4SOPncyuS94sUuE2EqvvO/
t81qeoey6wThz5iRbU/0CvDFnTMgebWGUZ2UZJ+az/rb3KYXGfVWasLIonkvYT7z
vHOGNAA9oQ8TTgPOmPfSVyfpplKtO/aybWp5QSH2csIwuvw5dkmpkc42iD57XHob
5LbMJg99z3vQBmod/ipmOpND95/BeA2mllBZgZ53S0nvDXDzbzR9Fd81PAz9Qruo
dOJKcD6plKQjZjkLzNh1v/RoCFO8kiJGE4UBMTM8FUk0DXH4bALII4wwmDelrSUu
lKvDTDxZvPF4dbEXICNPd51EMGPgETxwboOV+bzWFVI0IWQ8PhZ2VuMPDk2taOMp
NsuLtlYc2twPb9r/Hvgv7G6+ItpBHZwOVt1oI3pHbjMp7P3pOZSPr6G1WkNy9mX8
rVc=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06