ZeroSSLECCDomainSecureSiteCA.crt: CN=ZeroSSL ECC Domain Secure Site CA,O=ZeroSSL,C=AT

Page content

CA Certificate Basic Information

This certificate is intermediate certificate used for the issuance of other certificates.

  • Certificate download URL: http://zerossl.crt.sectigo.com/ZeroSSLECCDomainSecureSiteCA.crt (DER format)
  • Serial number: 47475399004980497348775734540896789736
  • SHA-1 Fingerprint: 7f95276d4951499fd756df344aa24fb38ceaf678
  • SHA-1 Fingerprint: 7f:95:27:6d:49:51:49:9f:d7:56:df:34:4a:a2:4f:b3:8c:ea:f6:78
  • SHA-256 Fingerprint: 5dd661d3cb33b5005cbed045a223ddc4445aaa41d1acb5df700884cad9ba4195
  • SHA-256 Fingerprint: 5d:d6:61:d3:cb:33:b5:00:5c:be:d0:45:a2:23:dd:c4:44:5a:aa:41:d1:ac:b5:df:70:08:84:ca:d9:ba:41:95
  • Signature hash algorithm: sha384
  • Subject: CN=ZeroSSL ECC Domain Secure Site CA,O=ZeroSSL,C=AT
  • Not valid before: 2020-01-30 00:00:00
  • Not valid after: 2030-01-29 23:59:59
  • Issuer:

Download certificate through curl:

curl -sSL http://zerossl.crt.sectigo.com/ZeroSSLECCDomainSecureSiteCA.crt --output cert.crt

Download certificate through wget:

wget -q http://zerossl.crt.sectigo.com/ZeroSSLECCDomainSecureSiteCA.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            23:b7:6d:e3:c1:bb:2b:1a:51:96:1e:08:ea:b7:64:e8
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
        Validity
            Not Before: Jan 30 00:00:00 2020 GMT
            Not After : Jan 29 23:59:59 2030 GMT
        Subject: C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:36:41:61:17:2b:53:25:ed:aa:ca:94:e4:d6:da:
                    48:57:ef:50:ba:84:64:82:d7:bb:05:1b:d6:1f:06:
                    24:f6:a5:33:9d:8c:e7:f1:0b:55:68:63:82:30:10:
                    5f:8d:65:ec:aa:a8:af:97:ca:b5:86:ce:30:01:89:
                    74:de:e3:4e:5e:01:6e:ee:26:7b:cc:53:fa:23:a4:
                    f7:44:1d:3e:4d:1e:5f:66:a6:ad:85:f6:f2:e3:bc:
                    8e:09:98:80:24:8e:20
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:3A:E1:09:86:D4:CF:19:C2:96:76:74:49:76:DC:E0:35:C6:63:63:9A

            X509v3 Subject Key Identifier: 
                0F:6B:E6:4B:CE:39:47:AE:F6:7E:90:1E:79:F0:30:91:92:C8:5F:A3
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.6449.1.2.2.78
                Policy: 2.23.140.1.2.1

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.usertrust.com/USERTrustECCCertificationAuthority.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.usertrust.com/USERTrustECCAddTrustCA.crt
                OCSP - URI:http://ocsp.usertrust.com

    Signature Algorithm: ecdsa-with-SHA384
         30:64:02:30:24:70:54:0f:01:c9:40:dd:c8:54:d9:6d:54:ca:
         c8:08:ca:98:43:74:d8:3f:f4:d7:a9:5f:6d:f2:61:b9:70:0a:
         26:1b:63:30:a8:8b:31:9c:bf:77:ec:67:b0:7f:a5:88:02:30:
         25:ad:ab:a4:b0:ee:8d:52:e0:dd:0d:7c:9d:df:7d:1d:ae:e2:
         5c:64:9c:74:f8:7e:63:e5:c1:4e:60:16:86:b0:a7:5e:19:6e:
         ec:08:c6:91:d8:fb:03:14:a1:a5:95:ab

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDhTCCAwygAwIBAgIQI7dt48G7KxpRlh4I6rdk6DAKBggqhkjOPQQDAzCBiDEL
MAkGA1UEBhMCVVMxEzARBgNVBAgTCk5ldyBKZXJzZXkxFDASBgNVBAcTC0plcnNl
eSBDaXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5ldHdvcmsxLjAsBgNVBAMT
JVVTRVJUcnVzdCBFQ0MgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMjAwMTMw
MDAwMDAwWhcNMzAwMTI5MjM1OTU5WjBLMQswCQYDVQQGEwJBVDEQMA4GA1UEChMH
WmVyb1NTTDEqMCgGA1UEAxMhWmVyb1NTTCBFQ0MgRG9tYWluIFNlY3VyZSBTaXRl
IENBMHYwEAYHKoZIzj0CAQYFK4EEACIDYgAENkFhFytTJe2qypTk1tpIV+9QuoRk
gte7BRvWHwYk9qUznYzn8QtVaGOCMBBfjWXsqqivl8q1hs4wAYl03uNOXgFu7iZ7
zFP6I6T3RB0+TR5fZqathfby47yOCZiAJI4go4IBdTCCAXEwHwYDVR0jBBgwFoAU
OuEJhtTPGcKWdnRJdtzgNcZjY5owHQYDVR0OBBYEFA9r5kvOOUeu9n6QHnnwMJGS
yF+jMA4GA1UdDwEB/wQEAwIBhjASBgNVHRMBAf8ECDAGAQH/AgEAMB0GA1UdJQQW
MBQGCCsGAQUFBwMBBggrBgEFBQcDAjAiBgNVHSAEGzAZMA0GCysGAQQBsjEBAgJO
MAgGBmeBDAECATBQBgNVHR8ESTBHMEWgQ6BBhj9odHRwOi8vY3JsLnVzZXJ0cnVz
dC5jb20vVVNFUlRydXN0RUNDQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcmwwdgYI
KwYBBQUHAQEEajBoMD8GCCsGAQUFBzAChjNodHRwOi8vY3J0LnVzZXJ0cnVzdC5j
b20vVVNFUlRydXN0RUNDQWRkVHJ1c3RDQS5jcnQwJQYIKwYBBQUHMAGGGWh0dHA6
Ly9vY3NwLnVzZXJ0cnVzdC5jb20wCgYIKoZIzj0EAwMDZwAwZAIwJHBUDwHJQN3I
VNltVMrICMqYQ3TYP/TXqV9t8mG5cAomG2MwqIsxnL937Gewf6WIAjAlrauksO6N
UuDdDXyd330druJcZJx0+H5j5cFOYBaGsKdeGW7sCMaR2PsDFKGllas=
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26