Amazon-ECDSA-256-M03.cer: CN=Amazon ECDSA 256 M03,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-ECDSA-256-M03.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-ECDSA-256-M03.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:70:3d:79:51:fd:4e:b2:d7:3c:ab:82:6a:fb:aa:08:0d
    Signature Algorithm: ecdsa-with-SHA256
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 3
        Validity
            Not Before: Aug 23 22:33:55 2022 GMT
            Not After : Aug 23 22:33:55 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon ECDSA 256 M03
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:1b:f7:23:7f:7e:eb:35:59:1b:49:5a:1c:75:45:
                    ea:90:67:9f:d9:29:0a:26:73:e8:02:55:e0:5a:56:
                    cf:61:d1:b8:6e:16:a9:95:de:a3:56:15:26:d0:51:
                    49:d8:15:04:55:03:b7:f7:e9:60:e8:a6:b1:12:c6:
                    f1:75:63:fc:40
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                CB:23:C3:F3:02:73:6F:BA:C1:A4:AD:F8:71:C6:10:28:16:DF:EC:BF
            X509v3 Authority Key Identifier: 
                keyid:AB:B6:DB:D7:06:9E:37:AC:30:86:07:91:70:C7:9C:C4:19:B1:78:C0

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca3.amazontrust.com
                CA Issuers - URI:http://crt.rootca3.amazontrust.com/rootca3.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca3.amazontrust.com/rootca3.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: ecdsa-with-SHA256
         30:46:02:21:00:c0:63:8f:a9:ed:a7:c5:b7:6d:63:08:89:86:
         5e:24:00:28:9f:ec:a2:fe:e5:c3:f0:d7:fc:eb:55:de:92:8a:
         c2:02:21:00:c5:d7:a8:0b:98:ac:e3:1d:75:a1:f5:92:4d:6d:
         8a:fa:ab:60:4b:0d:ec:27:d0:5f:02:9b:0a:43:96:34:83:d6

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIC1DCCAnmgAwIBAgITB3MScD15Uf1Ostc8q4Jq+6oIDTAKBggqhkjOPQQDAjA5
MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6b24g
Um9vdCBDQSAzMB4XDTIyMDgyMzIyMzM1NVoXDTMwMDgyMzIyMzM1NVowPTELMAkG
A1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEdMBsGA1UEAxMUQW1hem9uIEVDRFNB
IDI1NiBNMDMwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQb9yN/fus1WRtJWhx1
ReqQZ5/ZKQomc+gCVeBaVs9h0bhuFqmV3qNWFSbQUUnYFQRVA7f36WDoprESxvF1
Y/xAo4IBWjCCAVYwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAYYw
HQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTLI8PzAnNv
usGkrfhxxhAoFt/svzAfBgNVHSMEGDAWgBSrttvXBp43rDCGB5Fwx5zEGbF4wDB7
BggrBgEFBQcBAQRvMG0wLwYIKwYBBQUHMAGGI2h0dHA6Ly9vY3NwLnJvb3RjYTMu
YW1hem9udHJ1c3QuY29tMDoGCCsGAQUFBzAChi5odHRwOi8vY3J0LnJvb3RjYTMu
YW1hem9udHJ1c3QuY29tL3Jvb3RjYTMuY2VyMD8GA1UdHwQ4MDYwNKAyoDCGLmh0
dHA6Ly9jcmwucm9vdGNhMy5hbWF6b250cnVzdC5jb20vcm9vdGNhMy5jcmwwEwYD
VR0gBAwwCjAIBgZngQwBAgEwCgYIKoZIzj0EAwIDSQAwRgIhAMBjj6ntp8W3bWMI
iYZeJAAon+yi/uXD8Nf861XekorCAiEAxdeoC5is4x11ofWSTW2K+qtgSw3sJ9Bf
ApsKQ5Y0g9Y=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06