giag4ecc.der: CN=GIAG4 ECC,O=Google Trust Services LLC,C=US (Intermediate Certificate, Expiring 2028-11-01) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://pki.goog/repo/certs/giag4ecc.der" --output cert.crt

Download certificate through wget:

wget -q "https://pki.goog/repo/certs/giag4ecc.der" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            01:f0:9c:57:8a:e0:e9:fc:18:55:86:7c:64
    Signature Algorithm: ecdsa-with-SHA256
        Issuer: OU=GlobalSign ECC Root CA - R4, O=GlobalSign, CN=GlobalSign
        Validity
            Not Before: Nov  1 00:00:42 2018 GMT
            Not After : Nov  1 00:00:42 2028 GMT
        Subject: C=US, O=Google Trust Services LLC, CN=GIAG4 ECC
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:5a:00:f1:0e:c4:cf:ec:e7:7d:ac:1f:13:3d:49:
                    6d:31:a7:18:08:76:08:36:d8:5c:0e:39:4f:bb:7c:
                    0f:d0:2b:26:cb:a0:eb:8a:dd:e0:86:a6:93:a8:57:
                    9c:a9:c8:24:b3:94:70:70:a4:24:4f:da:db:63:77:
                    bc:94:7b:ae:03
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Subject Key Identifier: 
                80:8C:FC:16:0A:C8:F3:99:CE:5C:93:BF:63:E3:4A:96:CB:9C:99:B4
            X509v3 Authority Key Identifier: 
                keyid:54:B0:7B:AD:45:B8:E2:40:7F:FB:0A:6E:FB:BE:33:C9:3C:A3:84:D5

            Authority Information Access: 
                OCSP - URI:http://ocsp.pki.goog/gsr4
                CA Issuers - URI:http://pki.goog/gsr4/gsr4.crt

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.pki.goog/gsr4/gsr4.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
                Policy: 2.23.140.1.2.2

    Signature Algorithm: ecdsa-with-SHA256
         30:44:02:20:77:9f:72:0b:d4:6a:09:73:82:74:d6:98:36:25:
         d4:25:9e:5f:71:97:7f:46:c2:f7:32:83:a5:70:d7:41:2b:fe:
         02:20:78:b8:df:06:d0:e6:8c:7d:ce:8b:41:77:20:dc:40:46:
         5f:fd:c4:47:b9:23:e9:67:4f:72:df:c9:19:bb:77:83

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIICzTCCAnSgAwIBAgINAfCcV4rg6fwYVYZ8ZDAKBggqhkjOPQQDAjBQMSQwIgYD
VQQLExtHbG9iYWxTaWduIEVDQyBSb290IENBIC0gUjQxEzARBgNVBAoTCkdsb2Jh
bFNpZ24xEzARBgNVBAMTCkdsb2JhbFNpZ24wHhcNMTgxMTAxMDAwMDQyWhcNMjgx
MTAxMDAwMDQyWjBFMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0
IFNlcnZpY2VzIExMQzESMBAGA1UEAxMJR0lBRzQgRUNDMFkwEwYHKoZIzj0CAQYI
KoZIzj0DAQcDQgAEWgDxDsTP7Od9rB8TPUltMacYCHYINthcDjlPu3wP0Csmy6Dr
it3ghqaTqFecqcgks5RwcKQkT9rbY3e8lHuuA6OCATwwggE4MA4GA1UdDwEB/wQE
AwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgw
BgEB/wIBADAdBgNVHQ4EFgQUgIz8FgrI85nOXJO/Y+NKlsucmbQwHwYDVR0jBBgw
FoAUVLB7rUW44kB/+wpu+74zyTyjhNUwYAYIKwYBBQUHAQEEVDBSMCUGCCsGAQUF
BzABhhlodHRwOi8vb2NzcC5wa2kuZ29vZy9nc3I0MCkGCCsGAQUFBzAChh1odHRw
Oi8vcGtpLmdvb2cvZ3NyNC9nc3I0LmNydDAyBgNVHR8EKzApMCegJaAjhiFodHRw
Oi8vY3JsLnBraS5nb29nL2dzcjQvZ3NyNC5jcmwwHQYDVR0gBBYwFDAIBgZngQwB
AgEwCAYGZ4EMAQICMAoGCCqGSM49BAMCA0cAMEQCIHefcgvUaglzgnTWmDYl1CWe
X3GXf0bC9zKDpXDXQSv+AiB4uN8G0OaMfc6LQXcg3EBGX/3ER7kj6WdPct/JGbt3
gw==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06