GeoTrustRSACNCAG2.crt: CN=GeoTrust RSA CN CA G2,O=DigiCert Inc,C=US (Intermediate Certificate, Expiring 2030-03-04) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://cacerts.digicert.cn/GeoTrustRSACNCAG2.crt" --output cert.crt

Download certificate through wget:

wget -q "http://cacerts.digicert.cn/GeoTrustRSACNCAG2.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0b:13:62:b6:ee:6a:9d:3e:96:89:30:f1:6e:20:7d:39
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
        Validity
            Not Before: Mar  4 12:04:40 2020 GMT
            Not After : Mar  4 12:04:40 2030 GMT
        Subject: C=US, O=DigiCert Inc, CN=GeoTrust RSA CN CA G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:d0:35:39:92:49:b5:95:08:ef:38:f8:a8:51:d3:
                    ef:d8:3e:3a:d9:2c:e1:31:1f:99:41:03:86:b3:4a:
                    04:41:23:6f:f8:b6:f4:60:5f:9e:9b:c5:75:3d:fa:
                    6b:30:a0:d9:53:83:25:14:a3:23:31:67:e2:a0:03:
                    71:cf:38:12:67:ca:88:31:0c:f7:b1:c5:b1:03:e9:
                    f5:14:64:ab:11:f9:70:1e:75:11:4d:9e:04:4f:54:
                    6b:de:71:fb:04:29:fc:a4:9d:0a:a2:13:09:0f:ef:
                    ca:f9:b7:27:85:29:8e:5d:30:95:6f:30:44:23:c2:
                    59:c6:30:de:92:82:94:64:64:37:35:6d:23:52:97:
                    9d:fa:67:ed:f1:b7:37:ce:27:ef:09:41:6f:d2:06:
                    28:91:5a:73:fe:be:87:1b:d9:c7:6a:a7:7c:bb:31:
                    74:82:91:d1:0f:db:88:6a:14:e9:9f:08:cb:f4:7f:
                    a7:b1:a8:3c:ef:2f:6a:65:74:f7:4f:90:1c:42:f9:
                    01:d4:b3:2a:d1:21:53:db:dd:bd:cb:96:8e:32:f1:
                    56:76:89:2d:f8:ff:e9:6a:06:66:3f:14:5a:7d:f3:
                    15:b1:28:4d:56:80:7e:9d:b1:a9:dc:d6:ef:24:6f:
                    8b:6a:f5:e3:c9:bd:7a:fe:e5:8c:3a:87:a3:c5:17:
                    eb:db
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                24:6F:91:3F:89:87:87:0E:32:C2:40:18:DF:C5:4C:EB:4F:C8:49:32
            X509v3 Authority Key Identifier: 
                keyid:03:DE:50:35:56:D1:4C:BB:66:F0:A3:E2:1B:1B:C3:97:B2:3D:D1:55

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.cn

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.digicert.cn/DigiCertGlobalRootCA.crl

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.114412.1.1
                  CPS: https://www.digicert.com/CPS
                  User Notice:
                    Explicit Text: Any use of this Certificate constitutes acceptance of the Relying Party Agreement located at https://www.digicert.com/rpa-ua
                Policy: 2.23.140.1.2.2

    Signature Algorithm: sha256WithRSAEncryption
         b3:91:c5:ea:d1:33:74:a1:29:f8:51:e5:e9:14:15:bb:53:cc:
         eb:1c:12:21:1f:d3:17:1c:d0:69:f9:8c:bf:c8:dd:7d:d7:7d:
         d4:63:4e:6e:b8:75:c7:69:4d:94:bf:48:71:79:f7:24:8c:f7:
         64:69:7e:c0:46:ca:3e:3b:70:2b:ea:77:fb:61:f0:70:0a:a4:
         a9:aa:c3:5c:90:a4:fb:28:ab:5f:dc:eb:7d:e7:06:05:a4:a0:
         da:eb:88:dc:45:47:f1:cd:15:a7:9a:ad:76:21:5c:dc:ce:a1:
         c8:b0:8b:d4:65:02:0d:c3:f5:07:49:07:16:7a:47:54:9c:c8:
         39:f1:b4:12:1f:24:e3:c2:48:fd:8d:c5:f6:45:44:71:69:56:
         64:af:5e:70:c6:8f:d9:dd:87:68:d8:f5:4a:dd:a7:c4:af:4f:
         ef:72:e1:6f:13:b4:1e:19:78:88:d8:32:5d:56:dd:c9:79:f6:
         ad:67:7a:e3:e1:54:d6:d9:a5:19:c0:71:94:89:65:88:52:e7:
         41:7d:02:91:d0:91:29:94:9f:0c:15:a2:83:87:8f:c0:d9:51:
         09:9d:72:0b:bb:58:b0:bd:cd:66:de:30:9a:3e:ec:d9:29:da:
         07:33:fd:76:df:86:f3:9c:92:36:68:07:e1:7c:88:68:1f:0f:
         74:b4:f3:be

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFDzCCA/egAwIBAgIQCxNitu5qnT6WiTDxbiB9OTANBgkqhkiG9w0BAQsFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
QTAeFw0yMDAzMDQxMjA0NDBaFw0zMDAzMDQxMjA0NDBaMEQxCzAJBgNVBAYTAlVT
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxHjAcBgNVBAMTFUdlb1RydXN0IFJTQSBD
TiBDQSBHMjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANA1OZJJtZUI
7zj4qFHT79g+Otks4TEfmUEDhrNKBEEjb/i29GBfnpvFdT36azCg2VODJRSjIzFn
4qADcc84EmfKiDEM97HFsQPp9RRkqxH5cB51EU2eBE9Ua95x+wQp/KSdCqITCQ/v
yvm3J4Upjl0wlW8wRCPCWcYw3pKClGRkNzVtI1KXnfpn7fG3N84n7wlBb9IGKJFa
c/6+hxvZx2qnfLsxdIKR0Q/biGoU6Z8Iy/R/p7GoPO8vamV090+QHEL5AdSzKtEh
U9vdvcuWjjLxVnaJLfj/6WoGZj8UWn3zFbEoTVaAfp2xqdzW7yRvi2r148m9ev7l
jDqHo8UX69sCAwEAAaOCAd4wggHaMB0GA1UdDgQWBBQkb5E/iYeHDjLCQBjfxUzr
T8hJMjAfBgNVHSMEGDAWgBQD3lA1VtFMu2bwo+IbG8OXsj3RVTAOBgNVHQ8BAf8E
BAMCAYYwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBIGA1UdEwEB/wQI
MAYBAf8CAQAwMwYIKwYBBQUHAQEEJzAlMCMGCCsGAQUFBzABhhdodHRwOi8vb2Nz
cC5kaWdpY2VydC5jbjBABgNVHR8EOTA3MDWgM6Axhi9odHRwOi8vY3JsLmRpZ2lj
ZXJ0LmNuL0RpZ2lDZXJ0R2xvYmFsUm9vdENBLmNybDCB3QYDVR0gBIHVMIHSMIHF
BglghkgBhv1sAQEwgbcwKAYIKwYBBQUHAgEWHGh0dHBzOi8vd3d3LmRpZ2ljZXJ0
LmNvbS9DUFMwgYoGCCsGAQUFBwICMH4MfEFueSB1c2Ugb2YgdGhpcyBDZXJ0aWZp
Y2F0ZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSZWx5aW5nIFBhcnR5
IEFncmVlbWVudCBsb2NhdGVkIGF0IGh0dHBzOi8vd3d3LmRpZ2ljZXJ0LmNvbS9y
cGEtdWEwCAYGZ4EMAQICMA0GCSqGSIb3DQEBCwUAA4IBAQCzkcXq0TN0oSn4UeXp
FBW7U8zrHBIhH9MXHNBp+Yy/yN19133UY05uuHXHaU2Uv0hxefckjPdkaX7ARso+
O3Ar6nf7YfBwCqSpqsNckKT7KKtf3Ot95wYFpKDa64jcRUfxzRWnmq12IVzczqHI
sIvUZQINw/UHSQcWekdUnMg58bQSHyTjwkj9jcX2RURxaVZkr15wxo/Z3Ydo2PVK
3afEr0/vcuFvE7QeGXiI2DJdVt3JefatZ3rj4VTW2aUZwHGUiWWIUudBfQKR0JEp
lJ8MFaKDh4/A2VEJnXILu1iwvc1m3jCaPuzZKdoHM/1234bznJI2aAfhfIhoHw90
tPO+
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06