l1f-ec1.cer: CN=Entrust Certification Authority - L1F,OU=(c) 2016 Entrust, Inc. - for authorized use only,OU=See www.entrust.net/legal-terms,O=Entrust, Inc.,C=US

Page content

CA Certificate Basic Information

This certificate is root certificate used for the issuance of other certificates.

  • Certificate download URL: http://aia.entrust.net/l1f-ec1.cer (DER format)
  • Serial number: 241927633353286396679576221569636418038
  • SHA-1 Fingerprint: 6312cf0da9102f5263d3840f074a76abf0301ebe
  • SHA-1 Fingerprint: 63:12:cf:0d:a9:10:2f:52:63:d3:84:0f:07:4a:76:ab:f0:30:1e:be
  • SHA-256 Fingerprint: 1835b0e482ea65536fc010e4bc13c060f65668165fba97e2f542ce96ca6dfefc
  • SHA-256 Fingerprint: 18:35:b0:e4:82:ea:65:53:6f:c0:10:e4:bc:13:c0:60:f6:56:68:16:5f:ba:97:e2:f5:42:ce:96:ca:6d:fe:fc
  • Signature hash algorithm: sha384
  • Subject: CN=Entrust Certification Authority - L1F,OU=(c) 2016 Entrust, Inc. - for authorized use only,OU=See www.entrust.net/legal-terms,O=Entrust , Inc.,C=US
  • Not valid before: 2016-04-05 20:17:29
  • Not valid after: 2037-10-05 20:47:29
  • Issuer:
    • Issuer name: CN=Entrust Root Certification Authority - EC1,OU=(c) 2012 Entrust, Inc. - for authorized use only,OU=See www.entrust.net/legal-terms,O=Entrust , Inc.,C=US
    • Issuer certificate URL: None

Download certificate through curl:

curl -sSL http://aia.entrust.net/l1f-ec1.cer --output cert.crt

Download certificate through wget:

wget -q http://aia.entrust.net/l1f-ec1.cer --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            b6:01:91:3d:85:53:ba:fa:00:00:00:00:51:d4:c1:f6
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - EC1
        Validity
            Not Before: Apr  5 20:17:29 2016 GMT
            Not After : Oct  5 20:47:29 2037 GMT
        Subject: C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2016 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1F
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:44:7d:f4:c7:28:a8:f9:82:9d:d1:24:04:aa:c2:
                    a1:2a:55:9e:02:43:58:05:41:ab:05:2d:a4:48:9f:
                    31:87:d6:9e:88:d0:0d:68:09:8f:44:27:01:ce:fa:
                    62:b3:3a:8b:87:ad:c1:b7:a5:a5:78:46:fb:6c:9c:
                    ed:73:29:20:69:b6:10:c4:56:af:00:f8:20:5a:07:
                    86:cd:5c:6a:d9:fd:3b:b7:97:5a:29:5a:15:e9:d6:
                    67:1e:a6:a0:d7:e7:82
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.entrust.net

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.entrust.net/ec1root.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: http://www.entrust.net/rpa

            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                2E:62:F0:14:EE:87:CD:B3:35:03:3D:EF:E4:B9:9E:FD:3B:B8:A3:C9
            X509v3 Authority Key Identifier: 
                keyid:B7:63:E7:1A:DD:8D:E9:08:A6:55:83:A4:E0:6A:50:41:65:11:42:49

    Signature Algorithm: ecdsa-with-SHA384
         30:64:02:30:52:25:89:35:b9:8d:f6:1d:f9:e9:86:28:0c:a2:
         6f:df:ce:ff:33:2d:ce:0e:0f:3c:1c:2e:e4:8c:cd:f6:a6:3f:
         3f:ef:13:7f:19:42:90:5a:be:0e:7f:fe:d4:97:28:42:02:30:
         19:20:b2:a8:73:3d:5f:ca:b9:57:d6:cb:6e:18:d9:83:91:a8:
         00:53:e0:76:1b:c8:97:10:9a:ab:82:2a:57:a3:24:c6:37:d3:
         28:3e:6c:2a:c4:6a:1e:d8:30:60:5c:eb

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIID5jCCA22gAwIBAgIRALYBkT2FU7r6AAAAAFHUwfYwCgYIKoZIzj0EAwMwgb8x
CzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9T
ZWUgd3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAx
MiBFbnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxMzAxBgNV
BAMTKkVudHJ1c3QgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEVDMTAe
Fw0xNjA0MDUyMDE3MjlaFw0zNzEwMDUyMDQ3MjlaMIG6MQswCQYDVQQGEwJVUzEW
MBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0
Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTYgRW50cnVzdCwgSW5j
LiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENl
cnRpZmljYXRpb24gQXV0aG9yaXR5IC0gTDFGMHYwEAYHKoZIzj0CAQYFK4EEACID
YgAERH30xyio+YKd0SQEqsKhKlWeAkNYBUGrBS2kSJ8xh9aeiNANaAmPRCcBzvpi
szqLh63Bt6WleEb7bJztcykgabYQxFavAPggWgeGzVxq2f07t5daKVoV6dZnHqag
1+eCo4IBLjCCASowDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAw
MwYIKwYBBQUHAQEEJzAlMCMGCCsGAQUFBzABhhdodHRwOi8vb2NzcC5lbnRydXN0
Lm5ldDAzBgNVHR8ELDAqMCigJqAkhiJodHRwOi8vY3JsLmVudHJ1c3QubmV0L2Vj
MXJvb3QuY3JsMDsGA1UdIAQ0MDIwMAYEVR0gADAoMCYGCCsGAQUFBwIBFhpodHRw
Oi8vd3d3LmVudHJ1c3QubmV0L3JwYTAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYB
BQUHAwIwHQYDVR0OBBYEFC5i8BTuh82zNQM97+S5nv07uKPJMB8GA1UdIwQYMBaA
FLdj5xrdjekIplWDpOBqUEFlEUJJMAoGCCqGSM49BAMDA2cAMGQCMFIliTW5jfYd
+emGKAyib9/O/zMtzg4PPBwu5IzN9qY/P+8TfxlCkFq+Dn/+1JcoQgIwGSCyqHM9
X8q5V9bLbhjZg5GoAFPgdhvIlxCaq4IqV6MkxjfTKD5sKsRqHtgwYFzr
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26