R4-ServerCA4A.orig.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Intermediate Certificate, Expiring 2040-10-21) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/R4-ServerCA4A.orig.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/R4-ServerCA4A.orig.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7b:50:5a:50:15:3f:62:00:9a:61:28:38:20:f9:d4:8a:d6:02
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 4
        Validity
            Not Before: Oct 21 22:24:09 2015 GMT
            Not After : Oct 21 22:24:09 2040 GMT
        Subject: C=US, O=Amazon, OU=Server CA 4A, CN=Amazon
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:91:3f:49:08:5b:41:da:ef:e3:91:bc:45:61:21:
                    2e:60:22:09:07:eb:a5:f9:5b:db:c1:45:35:f5:e2:
                    81:bf:d5:e9:48:c8:8e:8b:6c:56:7e:13:92:80:b9:
                    f2:f4:5e:85:89:18:8d:56:6c:f4:66:1d:6d:b8:e8:
                    52:92:cc:5d:30:38:46:59:cb:11:11:3b:3e:ad:b9:
                    a5:6c:9d:74:47:44:4e:fa:ae:84:bf:5a:bd:3a:e2:
                    e2:69:28:7f:8b:bf:e4
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                A5:21:CD:DB:EB:53:21:99:AA:CA:D9:67:42:94:25:B2:7B:F4:C2:E3
            X509v3 Authority Key Identifier: 
                keyid:D3:EC:C7:3A:65:6E:CC:E1:DA:76:9A:56:FB:9C:F3:86:6D:57:E5:81

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca4.amazontrust.com
                CA Issuers - URI:http://crl.rootca4.amazontrust.com/rootca4.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca4.amazontrust.com/rootca4.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

    Signature Algorithm: ecdsa-with-SHA384
         30:66:02:31:00:80:25:97:a8:b8:92:2a:2a:cd:c7:f1:e1:9c:
         8e:fe:d4:fa:1a:5c:fb:c2:1c:b2:dc:30:95:4d:b7:1d:24:c9:
         ba:20:37:c5:4f:7f:c3:38:b6:25:d4:41:16:af:fb:6b:31:02:
         31:00:d2:1e:2f:64:8e:1c:f5:d0:ef:8b:c8:82:3d:90:46:96:
         b9:fb:27:3c:8f:52:df:80:12:f9:cc:a1:6d:f3:a6:54:53:65:
         0e:67:e3:d8:10:9c:e7:cb:cf:a0:d7:31:c0:84

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIC+TCCAn6gAwIBAgITBntQWlAVP2IAmmEoOCD51IrWAjAKBggqhkjOPQQDAzA5
MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6b24g
Um9vdCBDQSA0MB4XDTE1MTAyMTIyMjQwOVoXDTQwMTAyMTIyMjQwOVowRjELMAkG
A1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEVMBMGA1UECxMMU2VydmVyIENBIDRB
MQ8wDQYDVQQDEwZBbWF6b24wdjAQBgcqhkjOPQIBBgUrgQQAIgNiAASRP0kIW0Ha
7+ORvEVhIS5gIgkH66X5W9vBRTX14oG/1elIyI6LbFZ+E5KAufL0XoWJGI1WbPRm
HW246FKSzF0wOEZZyxEROz6tuaVsnXRHRE76roS/Wr064uJpKH+Lv+SjggE5MIIB
NTASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQU
pSHN2+tTIZmqytlnQpQlsnv0wuMwHwYDVR0jBBgwFoAU0+zHOmVuzOHadppW+5zz
hm1X5YEwewYIKwYBBQUHAQEEbzBtMC8GCCsGAQUFBzABhiNodHRwOi8vb2NzcC5y
b290Y2E0LmFtYXpvbnRydXN0LmNvbTA6BggrBgEFBQcwAoYuaHR0cDovL2NybC5y
b290Y2E0LmFtYXpvbnRydXN0LmNvbS9yb290Y2E0LmNlcjA/BgNVHR8EODA2MDSg
MqAwhi5odHRwOi8vY3JsLnJvb3RjYTQuYW1hem9udHJ1c3QuY29tL3Jvb3RjYTQu
Y3JsMBEGA1UdIAQKMAgwBgYEVR0gADAKBggqhkjOPQQDAwNpADBmAjEAgCWXqLiS
KirNx/HhnI7+1PoaXPvCHLLcMJVNtx0kybogN8VPf8M4tiXUQRav+2sxAjEA0h4v
ZI4c9dDvi8iCPZBGlrn7JzyPUt+AEvnMoW3zplRTZQ5n49gQnOfLz6DXMcCE
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06