D-TRUST_CA_3-2_2016.crt: 2.5.4.97=NTRDE-HRB74346,CN=D-TRUST CA 3-2 2016,O=D-Trust GmbH,C=DE (Intermediate Certificate, Expiring 2031-10-26) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.d-trust.net/cgi-bin/D-TRUST_CA_3-2_2016.crt" --output cert.crt

Download certificate through wget:

wget -q "https://www.d-trust.net/cgi-bin/D-TRUST_CA_3-2_2016.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 1041527 (0xfe477)
    Signature Algorithm: rsassaPss         
         Hash Algorithm: sha512
         Mask Algorithm: mgf1 with sha512
          Salt Length: 0x40
         Trailer Field: 0xBC (default)
        Issuer: C=DE, O=D-Trust GmbH, CN=D-TRUST Root CA 3 2016/2.5.4.97=NTRDE-HRB74346
        Validity
            Not Before: Oct 26 08:45:17 2016 GMT
            Not After : Oct 26 08:36:50 2031 GMT
        Subject: C=DE, O=D-Trust GmbH, CN=D-TRUST CA 3-2 2016/2.5.4.97=NTRDE-HRB74346
        Subject Public Key Info:
            Public Key Algorithm: rsassaPss
                RSA-PSS Public-Key: (4096 bit)
                Modulus:
                    00:f5:5c:89:68:5c:e1:9a:38:bc:a4:c0:03:f8:44:
                    35:c5:03:c9:db:1e:ae:49:40:dc:1d:ec:1c:41:b4:
                    b1:f9:88:b7:13:4f:2e:99:49:cd:4c:dd:42:79:4c:
                    1f:80:9c:07:0c:bc:c6:8c:be:e8:f5:58:6e:a9:49:
                    9a:df:a0:7f:d9:2f:b8:3f:bb:93:a9:98:c5:ac:fd:
                    79:c7:e7:54:9c:21:9d:27:b8:18:9a:cb:ec:17:8a:
                    ef:af:4d:e3:55:2a:51:66:bf:4c:2b:29:dd:51:6e:
                    34:09:53:4f:70:ae:ae:dc:72:b6:93:7f:ad:84:c9:
                    75:29:fd:31:5c:7b:aa:e8:3c:7a:7d:d1:56:bc:64:
                    63:fd:d4:ac:67:c7:03:cb:50:35:38:f0:72:17:76:
                    d7:02:27:b8:4f:96:3d:1e:6b:22:d5:4d:2a:41:09:
                    49:94:e2:48:a1:d8:c3:94:a3:4a:e5:1f:9e:a8:8f:
                    ef:ab:f3:91:81:56:d6:01:25:4a:18:a9:ac:bd:86:
                    0e:52:68:17:0c:fb:7a:f7:c2:87:ea:3d:3e:2f:21:
                    13:0b:15:63:25:5d:6d:80:35:b2:56:4d:4c:d7:10:
                    a6:55:ab:33:d1:d4:e4:c5:61:14:a7:8f:a9:c5:5e:
                    67:e9:32:00:f0:3c:4a:66:f7:94:01:39:4a:82:a1:
                    65:cd:6e:fc:03:61:b3:69:67:98:44:4b:3f:ed:8f:
                    22:0b:e6:18:f3:36:49:28:4a:18:fb:7e:45:41:53:
                    ff:c8:5d:49:3c:69:40:ac:99:d6:90:cf:be:db:c4:
                    94:b5:4b:59:66:db:9e:56:09:f7:e2:3a:05:5c:92:
                    8f:36:f0:89:c2:ed:34:5b:ef:92:16:cb:61:10:d5:
                    4c:f5:f2:5f:6e:a3:67:5c:d8:b1:95:de:c4:7e:78:
                    20:55:d9:d4:a8:f1:72:bf:d3:7b:75:4a:b0:41:cd:
                    4e:af:87:ca:eb:26:97:47:8f:f2:0d:53:d9:07:ae:
                    e1:36:7c:fb:39:87:9c:24:60:61:7e:ff:c1:de:5f:
                    3b:67:f1:33:28:e2:a3:d3:ad:41:e8:f8:a9:50:02:
                    60:c4:b0:93:e8:70:1b:60:1d:1d:01:fe:b3:6e:72:
                    57:d9:cb:e6:b4:b7:18:94:2c:15:4d:1a:4d:96:29:
                    a3:f1:b5:7a:bb:b8:cf:fd:7b:e0:58:44:b8:bd:8c:
                    31:16:14:eb:40:b8:83:92:0d:b9:41:fa:d8:1d:b0:
                    3d:20:76:d1:c0:73:d0:8e:40:71:97:db:aa:c6:c2:
                    1b:c1:c8:eb:0d:54:a1:c5:ae:b4:67:e1:05:f9:db:
                    f5:97:64:43:21:52:97:cc:55:80:33:ad:da:71:0c:
                    11:ae:fd
                Exponent: 65537 (0x10001)
                No PSS parameter restrictions
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:DC:C0:12:BD:88:3D:63:13:8C:34:AB:DB:CE:8B:32:C4:11:4E:5D:E7

            Authority Information Access: 
                OCSP - URI:http://root-ca-3-2016.ocsp.d-trust.net
                CA Issuers - URI:http://www.d-trust.net/cgi-bin/D-TRUST_Root_CA_3_2016.crt

            X509v3 Certificate Policies: 
                Policy: 0.4.0.194112.1.3
                Policy: 1.3.6.1.4.1.4788.2.150.2
                  CPS: http://www.d-trust.net/internet/files/D-TRUST_Root_PKI_CPS.pdf

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://directory.d-trust.net/CN=D-TRUST%20Root%20CA%203%202016,O=D-Trust%20GmbH,C=DE?certificaterevocationlist

                Full Name:
                  URI:http://crl.d-trust.net/crl/d-trust_root_ca_3_2016.crl

            X509v3 Subject Key Identifier: 
                6B:61:63:00:43:6B:04:37:A7:6C:06:A0:7F:95:A9:FE:45:E0:B3:14
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
    Signature Algorithm: rsassaPss         
         Hash Algorithm: sha512
         Mask Algorithm: mgf1 with sha512
          Salt Length: 0x40
         Trailer Field: 0xBC (default)

         86:40:b3:1b:b8:19:46:58:32:7e:9e:fc:f4:60:ce:18:03:49:
         aa:d9:cf:24:c9:ea:97:2e:8c:f3:ef:ca:6e:7b:8e:45:e7:5f:
         c8:89:84:16:91:46:1c:7a:1b:b6:28:6a:e4:6d:d8:bb:03:2c:
         d6:e2:fc:5f:f8:18:a8:1b:dd:69:05:98:55:6a:c7:7f:36:f0:
         5e:bc:e9:6f:3f:3a:59:2a:a1:30:1b:29:7f:cb:02:68:65:b5:
         12:b9:3f:d1:6b:39:3f:48:0b:a1:aa:84:95:6c:a6:18:a6:10:
         39:00:ce:d9:65:2c:90:f8:32:3f:c7:0f:0e:cc:0a:7c:97:61:
         b3:b9:11:bb:51:d0:27:22:ad:b1:12:a9:2a:c3:fa:5c:b5:06:
         89:56:f8:33:95:e7:f1:59:e2:f0:91:ad:a3:c1:a2:07:9e:fa:
         c6:d5:8a:46:85:21:83:74:e9:1b:1f:50:b2:62:56:a7:3a:6b:
         f5:a4:b1:3e:6d:81:57:7a:54:ea:a4:03:20:5a:c8:81:68:53:
         0e:99:0b:2c:15:58:dc:ee:bd:7a:31:b8:d8:bb:e7:02:b1:35:
         ca:8b:d0:30:90:17:2f:70:d7:a9:92:2a:c7:6c:cd:fc:bf:d3:
         34:85:3c:c0:30:15:69:50:9f:9a:f3:f5:8d:87:99:c2:50:f3:
         7c:12:65:1d:da:91:84:98:f0:5b:01:45:cc:48:73:b0:6c:6a:
         a8:fb:71:56:d6:83:28:bb:9e:a3:bf:5c:98:bd:e6:80:73:c2:
         ff:39:9a:4d:7e:12:be:e8:0b:cb:8c:4c:56:7c:3a:ec:a9:24:
         56:fb:c2:69:09:c0:8f:50:be:92:a6:46:9d:3c:ba:8f:8b:a8:
         03:6f:25:e5:a9:b0:d8:30:3c:79:19:d1:8b:c4:19:9e:c6:bc:
         b5:ef:96:47:30:5e:cd:a3:fe:2b:0d:61:ef:89:3f:31:c4:2d:
         68:78:59:bb:9b:a2:b0:1d:12:28:79:7a:fe:9f:c5:ea:62:55:
         6d:26:a6:0c:cc:46:d1:1c:a9:2a:ba:76:b2:d1:8c:03:2b:cd:
         c7:2a:eb:1b:4c:48:ed:db:4b:55:5b:2c:17:cb:83:ef:6f:23:
         36:08:56:0f:76:b7:22:f4:45:11:01:a3:82:d6:e2:56:0a:30:
         23:56:b7:3a:27:1f:6b:e5:54:bf:e0:4c:1d:ed:fa:1a:53:92:
         53:80:36:be:58:66:68:00:19:ea:05:fa:dc:a1:b7:f7:d2:7f:
         42:26:9c:db:7f:da:3a:59:27:a5:b1:b5:17:0e:17:8d:f0:0d:
         1c:31:21:5d:77:f7:a9:be:7a:36:19:99:8e:14:6a:5b:76:f4:
         29:1b:4e:73:99:64:03:38

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIHvjCCBXagAwIBAgIDD+R3MD0GCSqGSIb3DQEBCjAwoA0wCwYJYIZIAWUDBAID
oRowGAYJKoZIhvcNAQEIMAsGCWCGSAFlAwQCA6IDAgFAMF4xCzAJBgNVBAYTAkRF
MRUwEwYDVQQKEwxELVRydXN0IEdtYkgxHzAdBgNVBAMTFkQtVFJVU1QgUm9vdCBD
QSAzIDIwMTYxFzAVBgNVBGETDk5UUkRFLUhSQjc0MzQ2MB4XDTE2MTAyNjA4NDUx
N1oXDTMxMTAyNjA4MzY1MFowWzELMAkGA1UEBhMCREUxFTATBgNVBAoTDEQtVHJ1
c3QgR21iSDEcMBoGA1UEAxMTRC1UUlVTVCBDQSAzLTIgMjAxNjEXMBUGA1UEYRMO
TlRSREUtSFJCNzQzNDYwggIgMAsGCSqGSIb3DQEBCgOCAg8AMIICCgKCAgEA9VyJ
aFzhmji8pMAD+EQ1xQPJ2x6uSUDcHewcQbSx+Yi3E08umUnNTN1CeUwfgJwHDLzG
jL7o9VhuqUma36B/2S+4P7uTqZjFrP15x+dUnCGdJ7gYmsvsF4rvr03jVSpRZr9M
KyndUW40CVNPcK6u3HK2k3+thMl1Kf0xXHuq6Dx6fdFWvGRj/dSsZ8cDy1A1OPBy
F3bXAie4T5Y9Hmsi1U0qQQlJlOJIodjDlKNK5R+eqI/vq/ORgVbWASVKGKmsvYYO
UmgXDPt698KH6j0+LyETCxVjJV1tgDWyVk1M1xCmVasz0dTkxWEUp4+pxV5n6TIA
8DxKZveUATlKgqFlzW78A2GzaWeYREs/7Y8iC+YY8zZJKEoY+35FQVP/yF1JPGlA
rJnWkM++28SUtUtZZtueVgn34joFXJKPNvCJwu00W++SFsthENVM9fJfbqNnXNix
ld7EfnggVdnUqPFyv9N7dUqwQc1Or4fK6yaXR4/yDVPZB67hNnz7OYecJGBhfv/B
3l87Z/EzKOKj061B6PipUAJgxLCT6HAbYB0dAf6zbnJX2cvmtLcYlCwVTRpNlimj
8bV6u7jP/XvgWES4vYwxFhTrQLiDkg25QfrYHbA9IHbRwHPQjkBxl9uqxsIbwcjr
DVShxa60Z+EF+dv1l2RDIVKXzFWAM63acQwRrv0CAwEAAaOCAigwggIkMB8GA1Ud
IwQYMBaAFNzAEr2IPWMTjDSr286LMsQRTl3nMIGJBggrBgEFBQcBAQR9MHswMgYI
KwYBBQUHMAGGJmh0dHA6Ly9yb290LWNhLTMtMjAxNi5vY3NwLmQtdHJ1c3QubmV0
MEUGCCsGAQUFBzAChjlodHRwOi8vd3d3LmQtdHJ1c3QubmV0L2NnaS1iaW4vRC1U
UlVTVF9Sb290X0NBXzNfMjAxNi5jcnQwcQYDVR0gBGowaDAJBgcEAIvsQAEDMFsG
CysGAQQBpTQCgRYCMEwwSgYIKwYBBQUHAgEWPmh0dHA6Ly93d3cuZC10cnVzdC5u
ZXQvaW50ZXJuZXQvZmlsZXMvRC1UUlVTVF9Sb290X1BLSV9DUFMucGRmMIG+BgNV
HR8EgbYwgbMwdKByoHCGbmxkYXA6Ly9kaXJlY3RvcnkuZC10cnVzdC5uZXQvQ049
RC1UUlVTVCUyMFJvb3QlMjBDQSUyMDMlMjAyMDE2LE89RC1UcnVzdCUyMEdtYkgs
Qz1ERT9jZXJ0aWZpY2F0ZXJldm9jYXRpb25saXN0MDugOaA3hjVodHRwOi8vY3Js
LmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X3Jvb3RfY2FfM18yMDE2LmNybDAdBgNV
HQ4EFgQUa2FjAENrBDenbAagf5Wp/kXgsxQwDgYDVR0PAQH/BAQDAgEGMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwPQYJKoZIhvcNAQEKMDCgDTALBglghkgBZQMEAgOhGjAY
BgkqhkiG9w0BAQgwCwYJYIZIAWUDBAIDogMCAUADggIBAIZAsxu4GUZYMn6e/PRg
zhgDSarZzyTJ6pcujPPvym57jkXnX8iJhBaRRhx6G7YoauRt2LsDLNbi/F/4GKgb
3WkFmFVqx3828F686W8/OlkqoTAbKX/LAmhltRK5P9FrOT9IC6GqhJVsphimEDkA
ztllLJD4Mj/HDw7MCnyXYbO5EbtR0CcirbESqSrD+ly1BolW+DOV5/FZ4vCRraPB
ogee+sbVikaFIYN06RsfULJiVqc6a/WksT5tgVd6VOqkAyBayIFoUw6ZCywVWNzu
vXoxuNi75wKxNcqL0DCQFy9w16mSKsdszfy/0zSFPMAwFWlQn5rz9Y2HmcJQ83wS
ZR3akYSY8FsBRcxIc7Bsaqj7cVbWgyi7nqO/XJi95oBzwv85mk1+Er7oC8uMTFZ8
OuypJFb7wmkJwI9QvpKmRp08uo+LqANvJeWpsNgwPHkZ0YvEGZ7GvLXvlkcwXs2j
/isNYe+JPzHELWh4WbuborAdEih5ev6fxepiVW0mpgzMRtEcqSq6drLRjAMrzccq
6xtMSO3bS1VbLBfLg+9vIzYIVg92tyL0RREBo4LW4lYKMCNWtzonH2vlVL/gTB3t
+hpTklOANr5YZmgAGeoF+tyht/fSf0ImnNt/2jpZJ6WxtRcOF43wDRwxIV1396m+
ejYZmY4Ualt29CkbTnOZZAM4
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06