Microsoft Azure TLS Issuing CA 05 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 05,O=Microsoft Corporation,C=US

Page content

CA Certificate Basic Information

This certificate is intermediate certificate used for the issuance of other certificates.

  • Certificate download URL: http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2005%20-%20xsign.crt (DER format)
  • Serial number: 17923441888884453276882086283662137533
  • SHA-1 Fingerprint: 6c3af02e7f269aa73afd0eff2a88a4a1f04ed1e5
  • SHA-1 Fingerprint: 6c:3a:f0:2e:7f:26:9a:a7:3a:fd:0e:ff:2a:88:a4:a1:f0:4e:d1:e5
  • SHA-256 Fingerprint: d6831ba43607f5ac19778d627531562af55145f191cab5efafa0e0005442b302
  • SHA-256 Fingerprint: d6:83:1b:a4:36:07:f5:ac:19:77:8d:62:75:31:56:2a:f5:51:45:f1:91:ca:b5:ef:af:a0:e0:00:54:42:b3:02
  • Signature hash algorithm: sha384
  • Subject: CN=Microsoft Azure TLS Issuing CA 05,O=Microsoft Corporation,C=US
  • Not valid before: 2020-07-29 12:30:00
  • Not valid after: 2024-06-27 23:59:59
  • Issuer:

Download certificate through curl:

curl -sSL http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2005%20-%20xsign.crt --output cert.crt

Download certificate through wget:

wget -q http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2005%20-%20xsign.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0d:7b:ed:e9:7d:82:09:96:7a:52:63:1b:8b:dd:18:bd
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
        Validity
            Not Before: Jul 29 12:30:00 2020 GMT
            Not After : Jun 27 23:59:59 2024 GMT
        Subject: C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 05
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Modulus:
                    00:aa:65:0d:39:90:f5:a7:f0:54:f4:1e:94:3b:ae:
                    f8:d9:31:34:9d:3c:e0:23:4a:9e:b6:76:d4:00:5e:
                    c0:4f:94:53:81:8a:0e:7c:32:81:97:4a:e9:a8:0d:
                    48:cb:39:52:87:21:50:40:f3:cf:d0:a9:75:5e:6d:
                    74:fc:cb:d7:83:bf:19:e1:36:80:ee:7f:69:41:53:
                    50:c1:bd:73:a9:de:cb:19:39:b6:ad:56:74:ab:0f:
                    92:2b:4f:c2:ce:95:f0:c5:9a:e5:dd:4b:ff:2e:11:
                    16:16:47:52:c8:31:c5:4c:92:95:89:46:a4:d7:07:
                    86:1b:32:af:b1:2f:15:e7:19:18:0d:4c:7e:c8:ad:
                    01:65:69:ea:18:96:00:d9:16:28:83:5f:45:c7:6d:
                    dd:9d:80:db:78:66:30:7f:4c:45:21:81:71:c1:e2:
                    3e:ec:f0:ad:5b:12:98:bc:2f:b7:75:a5:44:38:0e:
                    6c:99:04:e3:4b:45:62:f2:7a:19:70:10:89:a1:87:
                    08:85:92:54:e6:e0:3b:7c:e3:eb:19:1d:6c:41:4c:
                    98:9f:f3:af:65:9e:b7:92:84:71:40:ed:50:18:40:
                    e1:d5:14:a1:a3:d5:cf:af:6e:e3:a5:79:e9:5b:1c:
                    cb:79:57:bb:56:25:b2:4f:38:8f:99:54:3c:b7:6c:
                    03:1b:6e:96:d3:f8:38:f4:28:39:3a:67:63:c9:31:
                    5a:41:fa:92:03:b9:81:32:84:dc:74:6f:a1:52:23:
                    53:8c:49:d0:94:3b:e3:ac:f2:ff:c1:9d:40:0d:fa:
                    49:a3:62:cf:85:37:bb:5d:33:15:98:36:46:4b:f6:
                    74:bd:4b:bf:9f:04:5c:bd:36:af:9a:b9:07:f9:e1:
                    54:7f:cc:d6:3a:13:be:94:6f:69:e1:29:00:98:64:
                    20:0f:4d:92:9b:db:18:4a:52:75:c0:34:3a:bb:4e:
                    39:e1:ad:ae:c8:8e:c8:c0:58:92:3a:41:e6:7c:34:
                    70:96:35:40:73:ab:de:72:2f:27:63:a7:63:e3:8a:
                    25:b0:d2:ae:11:6a:5a:c9:3c:ff:5a:ba:67:55:8d:
                    bc:e3:73:ee:d7:b5:a4:0b:47:7a:b7:4f:8b:9a:42:
                    1d:e8:97:08:da:6f:f9:f6:9d:c0:fd:24:f1:cc:da:
                    7f:65:6c:d7:d9:d8:b2:05:a7:e6:e2:32:2d:02:fc:
                    11:e8:5d:07:30:9b:38:a2:72:f6:c9:7c:e9:2e:05:
                    a9:ee:07:1b:20:2d:9a:a1:a5:69:63:ac:ab:60:3a:
                    3b:fa:5a:32:2d:c1:4a:65:93:0d:b8:0f:2c:23:c1:
                    6c:fb:5e:fd:bb:2e:00:41:78:6a:39:0f:10:44:b7:
                    18:73:fd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                C7:B2:9C:7F:1C:E3:B8:5A:EF:E9:68:1A:A8:5D:94:C1:26:52:6A:68
            X509v3 Authority Key Identifier: 
                keyid:4E:22:54:20:18:95:E6:E3:6E:E6:0F:FA:FA:B9:12:ED:06:17:8F:39

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com
                CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalRootG2.crt

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl3.digicert.com/DigiCertGlobalRootG2.crl

                Full Name:
                  URI:http://crl4.digicert.com/DigiCertGlobalRootG2.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
                Policy: 2.23.140.1.2.2

            1.3.6.1.4.1.311.21.1: 
                ...
    Signature Algorithm: sha384WithRSAEncryption
         1e:f8:6f:86:d9:11:5d:5a:d6:31:2c:82:8c:47:91:ff:69:53:
         45:8c:d3:fb:25:d7:ae:fa:86:5a:29:a2:2e:ed:4d:cd:89:dc:
         a4:16:bf:7d:e2:34:b1:30:13:15:ef:af:2e:90:9e:7f:84:b4:
         8a:b2:e8:ff:48:b8:e6:01:fc:11:01:9f:b0:d1:11:aa:8b:f9:
         0e:bc:f6:14:94:1a:ff:b0:a3:b0:af:7b:55:92:0f:5c:71:90:
         5e:6e:70:55:1b:e0:cb:29:3a:76:3b:1d:3e:8d:80:42:3f:19:
         5a:e4:53:b6:e7:6a:a9:93:bf:fa:c2:df:12:66:4d:dd:89:25:
         35:d8:99:bb:89:ff:e3:8e:48:64:18:1f:de:f1:47:5f:ac:aa:
         0b:ca:d0:ef:a9:57:a2:c0:f0:39:14:fc:ea:2a:84:aa:37:be:
         5b:c8:b8:ec:20:a2:44:74:d8:b4:ed:26:38:e6:13:7f:45:49:
         ec:98:8a:00:7f:dd:ea:95:a1:d1:fd:22:56:55:18:6b:5a:dd:
         c9:99:ea:01:27:64:43:2b:8f:76:cc:5e:93:1a:ed:66:a2:1e:
         1a:13:a7:b4:d1:89:30:4c:f5:ab:7a:ec:2f:68:b0:76:db:4b:
         d6:9a:d8:19:3e:cf:83:48:86:f6:77:d8:4f:05:d0:89:82:f7:
         21:a3:57:3b

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIF8zCCBNugAwIBAgIQDXvt6X2CCZZ6UmMbi90YvTANBgkqhkiG9w0BAQwFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH
MjAeFw0yMDA3MjkxMjMwMDBaFw0yNDA2MjcyMzU5NTlaMFkxCzAJBgNVBAYTAlVT
MR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKjAoBgNVBAMTIU1pY3Jv
c29mdCBBenVyZSBUTFMgSXNzdWluZyBDQSAwNTCCAiIwDQYJKoZIhvcNAQEBBQAD
ggIPADCCAgoCggIBAKplDTmQ9afwVPQelDuu+NkxNJ084CNKnrZ21ABewE+UU4GK
DnwygZdK6agNSMs5UochUEDzz9CpdV5tdPzL14O/GeE2gO5/aUFTUMG9c6neyxk5
tq1WdKsPkitPws6V8MWa5d1L/y4RFhZHUsgxxUySlYlGpNcHhhsyr7EvFecZGA1M
fsitAWVp6hiWANkWKINfRcdt3Z2A23hmMH9MRSGBccHiPuzwrVsSmLwvt3WlRDgO
bJkE40tFYvJ6GXAQiaGHCIWSVObgO3zj6xkdbEFMmJ/zr2Wet5KEcUDtUBhA4dUU
oaPVz69u46V56Vscy3lXu1Ylsk84j5lUPLdsAxtultP4OPQoOTpnY8kxWkH6kgO5
gTKE3HRvoVIjU4xJ0JQ746zy/8GdQA36SaNiz4U3u10zFZg2Rkv2dL1Lv58EXL02
r5q5B/nhVH/M1joTvpRvaeEpAJhkIA9NkpvbGEpSdcA0OrtOOeGtrsiOyMBYkjpB
5nw0cJY1QHOr3nIvJ2OnY+OKJbDSrhFqWsk8/1q6Z1WNvONz7te1pAtHerdPi5pC
HeiXCNpv+fadwP0k8czaf2Vs19nYsgWn5uIyLQL8EehdBzCbOKJy9sl86S4Fqe4H
GyAtmqGlaWOsq2A6O/paMi3BSmWTDbgPLCPBbPte/bsuAEF4ajkPEES3GHP9AgMB
AAGjggGtMIIBqTAdBgNVHQ4EFgQUx7KcfxzjuFrv6WgaqF2UwSZSamgwHwYDVR0j
BBgwFoAUTiJUIBiV5uNu5g/6+rkS7QYXjzkwDgYDVR0PAQH/BAQDAgGGMB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH/AgEAMHYG
CCsGAQUFBwEBBGowaDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQu
Y29tMEAGCCsGAQUFBzAChjRodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGln
aUNlcnRHbG9iYWxSb290RzIuY3J0MHsGA1UdHwR0MHIwN6A1oDOGMWh0dHA6Ly9j
cmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5jcmwwN6A1oDOG
MWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5j
cmwwHQYDVR0gBBYwFDAIBgZngQwBAgEwCAYGZ4EMAQICMBAGCSsGAQQBgjcVAQQD
AgEAMA0GCSqGSIb3DQEBDAUAA4IBAQAe+G+G2RFdWtYxLIKMR5H/aVNFjNP7Jdeu
+oZaKaIu7U3NidykFr994jSxMBMV768ukJ5/hLSKsuj/SLjmAfwRAZ+w0RGqi/kO
vPYUlBr/sKOwr3tVkg9ccZBebnBVG+DLKTp2Ox0+jYBCPxla5FO252qpk7/6wt8S
Zk3diSU12Jm7if/jjkhkGB/e8UdfrKoLytDvqVeiwPA5FPzqKoSqN75byLjsIKJE
dNi07SY45hN/RUnsmIoAf93qlaHR/SJWVRhrWt3JmeoBJ2RDK492zF6TGu1moh4a
E6e00YkwTPWreuwvaLB220vWmtgZPs+DSIb2d9hPBdCJgvcho1c7
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26