GeoTrustCNRSACAG1.crt: CN=GeoTrust CN RSA CA G1,OU=www.digicert.com,O=DigiCert Inc,C=US (Intermediate Certificate, Expiring 2029-06-20) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://crl.digicert-cn.com/GeoTrustCNRSACAG1.crt" --output cert.crt

Download certificate through wget:

wget -q "http://crl.digicert-cn.com/GeoTrustCNRSACAG1.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0a:04:70:d0:96:bc:8a:12:c8:90:a6:df:82:6e:ec:4b
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
        Validity
            Not Before: Jun 20 12:27:58 2019 GMT
            Not After : Jun 20 12:27:58 2029 GMT
        Subject: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=GeoTrust CN RSA CA G1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:b1:49:fa:3d:4a:79:95:46:e2:3c:e0:42:86:f6:
                    de:54:3c:3c:95:0d:85:8d:f5:b9:f6:62:86:e5:31:
                    85:87:3a:1d:25:38:2f:0d:1f:c5:f0:38:dd:af:43:
                    a4:99:7b:e0:cd:c4:e8:5d:59:44:13:9f:27:e7:56:
                    9d:a8:b2:60:3d:0f:c5:12:10:77:8c:09:8a:cb:62:
                    e1:46:9d:bf:3e:b5:21:86:3f:a1:0f:c4:97:19:3f:
                    5f:b1:85:0e:ab:98:bb:10:92:c8:17:47:b5:35:4c:
                    5c:2c:45:4a:f4:36:0b:fe:e3:59:91:43:7c:61:8a:
                    28:da:10:4a:22:72:c0:37:bc:8a:21:db:50:e6:a4:
                    2c:c9:97:98:e4:d9:c9:62:67:15:d4:7f:4c:7e:58:
                    35:38:8c:28:23:54:3c:70:25:78:6e:08:8a:01:b1:
                    0f:22:ff:81:bc:2b:74:33:62:6c:30:38:95:43:61:
                    0f:4c:4d:bc:f8:d0:f0:13:4a:aa:6e:47:58:3b:e2:
                    ad:4b:87:74:2f:b8:86:98:b4:18:93:b7:e0:ed:e2:
                    89:15:75:e9:89:96:4e:e5:45:35:ba:14:2c:36:74:
                    f8:f4:2d:72:d2:67:6a:da:6e:64:a3:c6:c8:a5:fa:
                    8c:2a:4f:bf:3c:cf:c3:f1:21:34:39:69:11:da:d8:
                    1d:93
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                91:9F:5E:31:15:AE:10:9F:AD:60:C1:F7:C1:CC:AA:48:34:2F:0C:26
            X509v3 Authority Key Identifier: 
                keyid:03:DE:50:35:56:D1:4C:BB:66:F0:A3:E2:1B:1B:C3:97:B2:3D:D1:55

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE
            Authority Information Access: 
                OCSP - URI:http://ocsp.dcocsp.cn

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.digicert-cn.com/DigiCertGlobalRootCA.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://www.digicert.com/CPS
                  User Notice:
                    Explicit Text: Any use of this Certificate constitutes acceptance of the Relying Party Agreement located at https://www.digicert.com/rpa-ua

    Signature Algorithm: sha256WithRSAEncryption
         17:e0:79:7a:f1:22:bb:65:8b:10:6f:f8:a3:03:7a:a2:b1:b4:
         d2:5b:66:22:c3:cc:90:64:18:27:78:1c:8e:b7:5f:97:92:e8:
         11:25:24:19:fa:98:8f:5e:61:5a:eb:ee:a3:8b:4e:9e:d6:88:
         ed:36:49:fd:58:ae:96:b3:fd:e3:d2:8d:9e:bc:e2:8f:3d:50:
         01:a9:c4:e7:db:81:54:8c:be:8f:da:d3:b9:ff:db:6d:23:51:
         62:f1:cd:a2:61:40:d2:ee:94:00:97:c3:05:ac:c5:87:fc:b7:
         03:fc:82:59:28:20:79:d4:50:d4:e5:86:cc:b2:97:56:73:bd:
         50:b8:6c:3a:48:e2:10:ba:42:42:46:ca:77:35:30:da:98:48:
         c8:fc:b5:96:e1:40:dc:37:1d:d4:a6:71:33:b4:35:cf:c9:fe:
         92:b6:55:97:3a:7c:56:ca:06:0b:29:9b:37:47:73:a8:cc:28:
         6d:ad:e2:58:ac:5c:4c:ac:4b:7c:0f:72:0d:1a:35:fa:f5:39:
         d9:79:fa:6c:a1:dc:c9:cc:2b:4f:1f:ea:94:d7:bd:db:8b:cf:
         e4:19:88:88:7c:21:82:fe:67:a4:16:81:36:7d:7b:68:e7:57:
         c8:ee:ba:65:f5:23:c1:9e:ed:c6:5d:b4:d9:d3:08:1f:21:15:
         fc:06:2d:40

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFGjCCBAKgAwIBAgIQCgRw0Ja8ihLIkKbfgm7sSzANBgkqhkiG9w0BAQsFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
QTAeFw0xOTA2MjAxMjI3NThaFw0yOTA2MjAxMjI3NThaMF8xCzAJBgNVBAYTAlVT
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xHjAcBgNVBAMTFUdlb1RydXN0IENOIFJTQSBDQSBHMTCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBALFJ+j1KeZVG4jzgQob23lQ8PJUNhY31ufZihuUx
hYc6HSU4Lw0fxfA43a9DpJl74M3E6F1ZRBOfJ+dWnaiyYD0PxRIQd4wJisti4Uad
vz61IYY/oQ/Elxk/X7GFDquYuxCSyBdHtTVMXCxFSvQ2C/7jWZFDfGGKKNoQSiJy
wDe8iiHbUOakLMmXmOTZyWJnFdR/TH5YNTiMKCNUPHAleG4IigGxDyL/gbwrdDNi
bDA4lUNhD0xNvPjQ8BNKqm5HWDvirUuHdC+4hpi0GJO34O3iiRV16YmWTuVFNboU
LDZ0+PQtctJnatpuZKPGyKX6jCpPvzzPw/EhNDlpEdrYHZMCAwEAAaOCAc4wggHK
MB0GA1UdDgQWBBSRn14xFa4Qn61gwffBzKpINC8MJjAfBgNVHSMEGDAWgBQD3lA1
VtFMu2bwo+IbG8OXsj3RVTAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYB
BQUHAwEGCCsGAQUFBwMCMA8GA1UdEwEB/wQFMAMBAf8wMQYIKwYBBQUHAQEEJTAj
MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5kY29jc3AuY24wRAYDVR0fBD0wOzA5
oDegNYYzaHR0cDovL2NybC5kaWdpY2VydC1jbi5jb20vRGlnaUNlcnRHbG9iYWxS
b290Q0EuY3JsMIHOBgNVHSAEgcYwgcMwgcAGBFUdIAAwgbcwKAYIKwYBBQUHAgEW
HGh0dHBzOi8vd3d3LmRpZ2ljZXJ0LmNvbS9DUFMwgYoGCCsGAQUFBwICMH4MfEFu
eSB1c2Ugb2YgdGhpcyBDZXJ0aWZpY2F0ZSBjb25zdGl0dXRlcyBhY2NlcHRhbmNl
IG9mIHRoZSBSZWx5aW5nIFBhcnR5IEFncmVlbWVudCBsb2NhdGVkIGF0IGh0dHBz
Oi8vd3d3LmRpZ2ljZXJ0LmNvbS9ycGEtdWEwDQYJKoZIhvcNAQELBQADggEBABfg
eXrxIrtlixBv+KMDeqKxtNJbZiLDzJBkGCd4HI63X5eS6BElJBn6mI9eYVrr7qOL
Tp7WiO02Sf1Yrpaz/ePSjZ684o89UAGpxOfbgVSMvo/a07n/220jUWLxzaJhQNLu
lACXwwWsxYf8twP8glkoIHnUUNTlhsyyl1ZzvVC4bDpI4hC6QkJGync1MNqYSMj8
tZbhQNw3HdSmcTO0Nc/J/pK2VZc6fFbKBgspmzdHc6jMKG2t4lisXEysS3wPcg0a
Nfr1Odl5+myh3MnMK08f6pTXvduLz+QZiIh8IYL+Z6QWgTZ9e2jnV8juumX1I8Ge
7cZdtNnTCB8hFfwGLUA=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06