cmca2.cer: CN=Cisco Manufacturing CA SHA2,O=Cisco (Intermediate Certificate, Expiring 2037-11-12) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.cisco.com/security/pki/certs/cmca2.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.cisco.com/security/pki/certs/cmca2.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 2 (0x2)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: O=Cisco, CN=Cisco Root CA M2
        Validity
            Not Before: Nov 12 13:50:58 2012 GMT
            Not After : Nov 12 13:00:17 2037 GMT
        Subject: O=Cisco, CN=Cisco Manufacturing CA SHA2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:f4:36:4b:42:02:32:67:de:49:3d:f2:15:3b:c1:
                    45:69:e9:09:4e:16:b9:48:b4:47:1e:e8:2a:5b:7d:
                    8a:5e:2d:d5:1e:65:db:80:a3:e4:b4:a2:dc:d3:94:
                    9c:12:d8:19:4c:85:9b:5a:72:ef:6f:52:97:e6:5b:
                    dc:3b:9d:0a:3d:cd:54:f7:7b:23:ee:84:5f:fa:ff:
                    d4:c4:75:50:67:ef:9c:db:e4:27:d5:f8:4e:a5:77:
                    e7:c7:9e:e3:e2:17:20:6e:f8:70:c3:25:17:77:ef:
                    73:a9:fb:de:7b:21:da:16:c8:fb:c3:f2:11:d1:d4:
                    72:46:14:9d:c9:24:a0:60:d1:44:9c:2f:82:42:c2:
                    57:ae:f7:c5:ea:ff:23:e5:02:a0:61:13:16:bb:6b:
                    6f:df:a9:29:99:03:4b:d9:20:6d:5b:05:f5:99:63:
                    c6:6d:49:e4:f1:2a:0d:de:5b:29:d5:fb:11:25:69:
                    b1:ea:4c:33:18:59:ff:b6:a1:bb:38:60:1e:65:20:
                    d4:db:62:01:f2:44:44:cf:e9:3f:17:af:a4:ed:0f:
                    48:77:eb:9e:0e:50:77:16:fb:59:9e:06:ef:e3:72:
                    d9:6e:30:aa:69:79:28:d5:b6:ba:1f:e6:fb:7e:a5:
                    b9:02:83:48:90:00:08:ec:2f:4a:9c:cd:3d:f2:68:
                    d5:ef
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.9.21.1.18.0
                  CPS: http://www.cisco.com/security/pki/policies/index.html

            X509v3 Subject Key Identifier: 
                7A:D7:79:95:CA:BB:48:2B:B8:55:14:FD:A3:C0:0F:BC:A7:0F:96:19
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://www.cisco.com/security/pki/crl/crcam2.crl

            Authority Information Access: 
                CA Issuers - URI:http://www.cisco.com/security/pki/certs/crcam2.cer
                OCSP - URI:https://tools.cisco.com/pki/ocsp

            X509v3 Authority Key Identifier: 
                keyid:C9:00:F9:1F:8A:1F:C2:66:BD:A5:D2:6D:65:0E:22:2E:34:C3:05:A0

    Signature Algorithm: sha256WithRSAEncryption
         73:59:36:ac:7e:98:4f:88:ee:17:1b:3d:ab:b3:9b:cd:f7:0a:
         6c:db:ce:c8:3b:1a:53:b6:af:e0:81:c5:5e:69:ff:27:17:e7:
         06:65:2f:63:10:08:d8:7c:77:c5:16:f4:2a:d1:b5:24:69:1f:
         7d:08:d5:02:d0:5b:a1:35:f2:9c:b6:90:b2:8f:e3:8f:8e:99:
         3a:e6:c8:17:cc:ba:1e:8d:e7:4c:0b:fb:43:a5:47:92:a4:82:
         75:90:a5:56:ef:75:cd:b1:d5:f4:51:58:43:32:71:8f:0d:50:
         80:1d:1a:e0:8b:52:e3:28:5d:9a:09:77:a0:33:44:71:bd:ed:
         ad:07:b3:ad:0d:ff:f3:9e:ff:21:2a:81:19:52:c4:6c:a1:ce:
         bb:c1:fa:cc:e2:e1:c4:08:19:d3:c6:9e:d6:84:10:40:9a:30:
         92:2d:08:6d:df:8b:44:b1:a8:be:d1:30:2e:0f:32:ca:a8:93:
         20:6b:de:ed:51:4b:da:c4:5a:f1:9d:eb:2b:db:65:c0:a5:47:
         da:4a:45:28:d0:1e:37:7a:df:28:5a:ab:d3:fc:1e:47:47:32:
         2a:99:8b:32:b4:81:4c:16:5c:c5:07:09:09:81:78:5f:a1:4e:
         ff:7d:8a:3a:a7:31:24:52:0e:28:65:48:52:3b:c0:be:2a:0e:
         aa:87:6e:73

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEZTCCA02gAwIBAgIBAjANBgkqhkiG9w0BAQsFADArMQ4wDAYDVQQKEwVDaXNj
bzEZMBcGA1UEAxMQQ2lzY28gUm9vdCBDQSBNMjAeFw0xMjExMTIxMzUwNThaFw0z
NzExMTIxMzAwMTdaMDYxDjAMBgNVBAoTBUNpc2NvMSQwIgYDVQQDExtDaXNjbyBN
YW51ZmFjdHVyaW5nIENBIFNIQTIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQD0NktCAjJn3kk98hU7wUVp6QlOFrlItEce6CpbfYpeLdUeZduAo+S0otzT
lJwS2BlMhZtacu9vUpfmW9w7nQo9zVT3eyPuhF/6/9TEdVBn75zb5CfV+E6ld+fH
nuPiFyBu+HDDJRd373Op+957IdoWyPvD8hHR1HJGFJ3JJKBg0UScL4JCwleu98Xq
/yPlAqBhExa7a2/fqSmZA0vZIG1bBfWZY8ZtSeTxKg3eWynV+xElabHqTDMYWf+2
obs4YB5lINTbYgHyRETP6T8Xr6TtD0h3654OUHcW+1meBu/jctluMKppeSjVtrof
5vt+pbkCg0iQAAjsL0qczT3yaNXvAgMBAAGjggGHMIIBgzAOBgNVHQ8BAf8EBAMC
AQYwEgYDVR0TAQH/BAgwBgEB/wIBADBcBgNVHSAEVTBTMFEGCisGAQQBCRUBEgAw
QzBBBggrBgEFBQcCARY1aHR0cDovL3d3dy5jaXNjby5jb20vc2VjdXJpdHkvcGtp
L3BvbGljaWVzL2luZGV4Lmh0bWwwHQYDVR0OBBYEFHrXeZXKu0gruFUU/aPAD7yn
D5YZMEEGA1UdHwQ6MDgwNqA0oDKGMGh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3Vy
aXR5L3BraS9jcmwvY3JjYW0yLmNybDB8BggrBgEFBQcBAQRwMG4wPgYIKwYBBQUH
MAKGMmh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3VyaXR5L3BraS9jZXJ0cy9jcmNh
bTIuY2VyMCwGCCsGAQUFBzABhiBodHRwczovL3Rvb2xzLmNpc2NvLmNvbS9wa2kv
b2NzcDAfBgNVHSMEGDAWgBTJAPkfih/CZr2l0m1lDiIuNMMFoDANBgkqhkiG9w0B
AQsFAAOCAQEAc1k2rH6YT4juFxs9q7ObzfcKbNvOyDsaU7av4IHFXmn/JxfnBmUv
YxAI2Hx3xRb0KtG1JGkffQjVAtBboTXynLaQso/jj46ZOubIF8y6Ho3nTAv7Q6VH
kqSCdZClVu91zbHV9FFYQzJxjw1QgB0a4ItS4yhdmgl3oDNEcb3trQezrQ3/857/
ISqBGVLEbKHOu8H6zOLhxAgZ08ae1oQQQJowki0Ibd+LRLGovtEwLg8yyqiTIGve
7VFL2sRa8Z3rK9tlwKVH2kpFKNAeN3rfKFqr0/weR0cyKpmLMrSBTBZcxQcJCYF4
X6FO/32KOqcxJFIOKGVIUjvAvioOqoducw==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06