aftdv1ca.crt: CN=AffirmTrust Certificate Authority - DV1,OU=See www.affirmtrust.com/repository,O=AffirmTrust,C=CA

Page content

CA Certificate Basic Information

This certificate is root certificate used for the issuance of other certificates.

  • Certificate download URL: http://aia.affirmtrust.com/aftdv1ca.crt (DER format)
  • Serial number: 131202930761082976608027773910440693654
  • SHA-1 Fingerprint: bdf562e8410556855d901795f34c2809189f818b
  • SHA-1 Fingerprint: bd:f5:62:e8:41:05:56:85:5d:90:17:95:f3:4c:28:09:18:9f:81:8b
  • SHA-256 Fingerprint: 4563b936e35ab97576f5aef1935d9bc7e9977841f0573bd2e16bcac9534a6af9
  • SHA-256 Fingerprint: 45:63:b9:36:e3:5a:b9:75:76:f5:ae:f1:93:5d:9b:c7:e9:97:78:41:f0:57:3b:d2:e1:6b:ca:c9:53:4a:6a:f9
  • Signature hash algorithm: sha256
  • Subject: CN=AffirmTrust Certificate Authority - DV1,OU=See www.affirmtrust.com/repository,O=AffirmTrust,C=CA
  • Not valid before: 2019-03-21 20:21:37
  • Not valid after: 2030-12-02 04:00:00
  • Issuer:
    • Issuer name: CN=AffirmTrust Commercial,O=AffirmTrust,C=US
    • Issuer certificate URL: None

Download certificate through curl:

curl -sSL http://aia.affirmtrust.com/aftdv1ca.crt --output cert.crt

Download certificate through wget:

wget -q http://aia.affirmtrust.com/aftdv1ca.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            62:b4:c3:eb:a5:39:18:17:7f:12:7a:83:7b:57:4f:96
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=AffirmTrust, CN=AffirmTrust Commercial
        Validity
            Not Before: Mar 21 20:21:37 2019 GMT
            Not After : Dec  2 04:00:00 2030 GMT
        Subject: C=CA, O=AffirmTrust, OU=See www.affirmtrust.com/repository, CN=AffirmTrust Certificate Authority - DV1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d9:2d:3d:83:89:d6:ec:c2:57:be:38:38:08:3c:
                    76:ff:0d:79:cc:64:37:dd:a4:ea:2d:50:86:d8:1c:
                    c8:56:d4:78:80:87:b1:a4:0f:53:20:ad:32:35:03:
                    33:fa:96:3e:83:31:3c:62:55:48:b8:37:c3:8a:f4:
                    42:38:5d:97:4c:8b:7b:16:ab:93:a9:90:1a:15:e3:
                    d9:66:9e:e4:85:fc:b8:b9:76:7c:9a:b3:62:2d:b8:
                    11:66:ce:a8:84:93:18:f8:dc:56:ac:eb:6e:ea:21:
                    63:f0:5f:83:07:c8:33:7c:d7:82:b9:e2:99:94:fe:
                    88:40:82:51:07:eb:ae:5b:fb:50:2b:0f:3d:6f:c4:
                    41:29:14:44:7a:23:c2:ff:7d:35:d8:04:6b:3f:c0:
                    22:48:57:95:e7:04:a5:e3:90:e9:7d:e8:b4:7f:44:
                    35:6a:93:e9:15:e9:cf:44:e3:f4:e1:b3:82:15:61:
                    e2:e2:cc:5b:a4:7b:b7:cd:a2:26:72:bd:64:3e:1f:
                    fb:54:21:95:86:a3:2a:99:d9:90:88:5e:93:ca:34:
                    8e:a4:b7:9a:05:2c:95:df:1d:cb:bb:94:34:0c:e5:
                    4c:63:56:5c:d5:0d:b2:45:79:30:f9:2c:71:c3:ed:
                    4c:25:44:40:89:63:c1:82:df:d7:50:d7:09:35:24:
                    e2:85
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            Authority Information Access: 
                OCSP - URI:http://ocsp.affirmtrust.com

            X509v3 Subject Key Identifier: 
                33:DF:7A:3E:02:79:96:EB:B6:0C:C0:63:FA:75:BF:92:22:CD:91:FA
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Authority Key Identifier: 
                keyid:9D:93:C6:53:8B:5E:CA:AF:3F:9F:1E:0F:E5:99:95:BC:24:F6:94:8F

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://www.affirmtrust.com/repository

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.affirmtrust.com/crl/AffirmTrustCommercial.crl

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
    Signature Algorithm: sha256WithRSAEncryption
         91:7c:ab:f9:25:a3:e5:bc:87:1a:41:4c:17:50:f7:80:bb:ea:
         8e:fa:d4:dd:4f:3d:51:b5:1d:49:8b:fa:1b:d5:87:0f:bf:0f:
         2d:68:1b:dc:68:09:5b:f0:45:98:35:ad:71:16:a0:21:8f:d6:
         83:19:d4:3c:76:f9:83:2a:bb:fe:f7:4d:62:75:57:2f:a2:75:
         ef:95:41:d3:7b:9b:e2:97:33:ff:f0:d2:9f:ff:60:5a:21:40:
         58:82:9e:7b:b1:fe:8f:91:81:bd:3c:39:5f:dc:51:d6:a7:d0:
         73:ce:1b:71:84:d5:03:ea:31:69:1a:52:7b:51:9c:97:d4:07:
         8d:79:93:85:70:d3:ca:0f:05:bc:d2:bb:7b:08:d0:d6:ab:84:
         f1:a7:8b:b9:4f:42:a2:ad:96:9f:fc:07:2e:0f:18:9a:c1:df:
         db:f1:e6:16:8d:9b:f0:bb:ac:fd:ac:38:50:89:92:16:1c:00:
         3b:52:aa:68:d2:a2:2c:d9:18:41:10:86:38:7a:e6:3e:f6:69:
         c7:75:ec:b5:35:c2:ba:8d:36:89:a0:7e:bb:66:cc:3d:76:01:
         a5:20:33:a8:37:36:8f:27:e2:7b:ea:77:8b:6c:1e:24:85:29:
         6e:32:cf:95:53:eb:e8:15:40:01:c8:7f:9a:b8:63:5d:c7:dd:
         23:3b:3c:63

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEpzCCA4+gAwIBAgIQYrTD66U5GBd/EnqDe1dPljANBgkqhkiG9w0BAQsFADBE
MQswCQYDVQQGEwJVUzEUMBIGA1UECgwLQWZmaXJtVHJ1c3QxHzAdBgNVBAMMFkFm
ZmlybVRydXN0IENvbW1lcmNpYWwwHhcNMTkwMzIxMjAyMTM3WhcNMzAxMjAyMDQw
MDAwWjCBgjELMAkGA1UEBhMCQ0ExFDASBgNVBAoTC0FmZmlybVRydXN0MSswKQYD
VQQLEyJTZWUgd3d3LmFmZmlybXRydXN0LmNvbS9yZXBvc2l0b3J5MTAwLgYDVQQD
EydBZmZpcm1UcnVzdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgLSBEVjEwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDZLT2Didbswle+ODgIPHb/DXnMZDfd
pOotUIbYHMhW1HiAh7GkD1MgrTI1AzP6lj6DMTxiVUi4N8OK9EI4XZdMi3sWq5Op
kBoV49lmnuSF/Li5dnyas2ItuBFmzqiEkxj43Fas627qIWPwX4MHyDN814K54pmU
/ohAglEH665b+1ArDz1vxEEpFER6I8L/fTXYBGs/wCJIV5XnBKXjkOl96LR/RDVq
k+kV6c9E4/Ths4IVYeLizFuke7fNoiZyvWQ+H/tUIZWGoyqZ2ZCIXpPKNI6kt5oF
LJXfHcu7lDQM5UxjVlzVDbJFeTD5LHHD7UwlRECJY8GC39dQ1wk1JOKFAgMBAAGj
ggFUMIIBUDA3BggrBgEFBQcBAQQrMCkwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vY3Nw
LmFmZmlybXRydXN0LmNvbTAdBgNVHQ4EFgQUM996PgJ5luu2DMBj+nW/kiLNkfow
EgYDVR0TAQH/BAgwBgEB/wIBADAfBgNVHSMEGDAWgBSdk8ZTi17Krz+fHg/lmZW8
JPaUjzBHBgNVHSAEQDA+MDwGBFUdIAAwNDAyBggrBgEFBQcCARYmaHR0cHM6Ly93
d3cuYWZmaXJtdHJ1c3QuY29tL3JlcG9zaXRvcnkwSQYDVR0fBEIwQDA+oDygOoY4
aHR0cDovL2NybC5hZmZpcm10cnVzdC5jb20vY3JsL0FmZmlybVRydXN0Q29tbWVy
Y2lhbC5jcmwwDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggr
BgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAkXyr+SWj5byHGkFMF1D3gLvqjvrU
3U89UbUdSYv6G9WHD78PLWgb3GgJW/BFmDWtcRagIY/WgxnUPHb5gyq7/vdNYnVX
L6J175VB03ub4pcz//DSn/9gWiFAWIKee7H+j5GBvTw5X9xR1qfQc84bcYTVA+ox
aRpSe1Gcl9QHjXmThXDTyg8FvNK7ewjQ1quE8aeLuU9Coq2Wn/wHLg8YmsHf2/Hm
Fo2b8Lus/aw4UImSFhwAO1KqaNKiLNkYQRCGOHrmPvZpx3XstTXCuo02iaB+u2bM
PXYBpSAzqDc2jyfie+p3i2weJIUpbjLPlVPr6BVAAch/mrhjXcfdIzs8Yw==
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26