SectigoECCOrganizationValidationSecureServerCA.crt: CN=Sectigo ECC Organization Validation Secure Server CA,O=Sectigo Limited,L=Salford,ST=Greater Manchester,C=GB

Page content

CA Certificate Basic Information

This certificate is intermediate certificate used for the issuance of other certificates.

  • Certificate download URL: http://crt.sectigo.com/SectigoECCOrganizationValidationSecureServerCA.crt (DER format)
  • Serial number: 71437980826369674525412024444231136103
  • SHA-1 Fingerprint: c8af0b661078fa075b5b4e80ff37e0597bc8ce93
  • SHA-1 Fingerprint: c8:af:0b:66:10:78:fa:07:5b:5b:4e:80:ff:37:e0:59:7b:c8:ce:93
  • SHA-256 Fingerprint: 3457106752400212903a3545ca3b2ef384a456972bd951d8d840c1b0a379efa1
  • SHA-256 Fingerprint: 34:57:10:67:52:40:02:12:90:3a:35:45:ca:3b:2e:f3:84:a4:56:97:2b:d9:51:d8:d8:40:c1:b0:a3:79:ef:a1
  • Signature hash algorithm: sha384
  • Subject: CN=Sectigo ECC Organization Validation Secure Server CA,O=Sectigo Limited,L=Salford,ST=Greater Manchester,C=GB
  • Not valid before: 2018-11-02 00:00:00
  • Not valid after: 2030-12-31 23:59:59
  • Issuer:

Download certificate through curl:

curl -sSL http://crt.sectigo.com/SectigoECCOrganizationValidationSecureServerCA.crt --output cert.crt

Download certificate through wget:

wget -q http://crt.sectigo.com/SectigoECCOrganizationValidationSecureServerCA.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            35:be:74:63:8c:b3:e9:de:28:05:70:b7:97:80:b3:67
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
        Validity
            Not Before: Nov  2 00:00:00 2018 GMT
            Not After : Dec 31 23:59:59 2030 GMT
        Subject: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Organization Validation Secure Server CA
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:9c:8e:5c:0a:61:6f:a1:58:a3:d0:d5:ce:fa:fc:
                    44:f9:ff:ba:06:1e:7b:16:1a:72:1f:42:d3:0a:b2:
                    66:cd:fb:0f:49:72:21:4d:27:b1:af:dd:87:3a:5c:
                    fe:68:7a:a8:18:4d:2f:49:ef:c2:4b:02:c5:a1:67:
                    19:f1:6d:63:39
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:3A:E1:09:86:D4:CF:19:C2:96:76:74:49:76:DC:E0:35:C6:63:63:9A

            X509v3 Subject Key Identifier: 
                4D:4A:EF:C4:46:B3:12:AD:4F:4E:9A:B1:59:E2:51:AB:08:10:78:08
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                Policy: 2.23.140.1.2.2

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.usertrust.com/USERTrustECCCertificationAuthority.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.usertrust.com/USERTrustECCAddTrustCA.crt
                OCSP - URI:http://ocsp.usertrust.com

    Signature Algorithm: ecdsa-with-SHA384
         30:66:02:31:00:e9:3f:fe:ea:3b:8b:f3:28:78:a7:5c:c9:ea:
         af:8c:e5:ec:04:91:46:2c:8f:b5:8b:47:7e:4e:dc:bb:cc:49:
         e7:db:0e:03:35:2d:b5:4c:af:30:99:8d:ca:8e:6d:c4:99:02:
         31:00:f2:35:a8:73:3f:23:e3:92:fa:1c:74:39:98:46:7c:3a:
         0d:89:f4:de:fc:6c:60:59:9d:60:39:84:0a:ce:7e:a5:c0:fd:
         32:18:a9:6b:3f:ee:ef:ad:50:bc:21:cc:c9:e0

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDrjCCAzOgAwIBAgIQNb50Y4yz6d4oBXC3l4CzZzAKBggqhkjOPQQDAzCBiDEL
MAkGA1UEBhMCVVMxEzARBgNVBAgTCk5ldyBKZXJzZXkxFDASBgNVBAcTC0plcnNl
eSBDaXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5ldHdvcmsxLjAsBgNVBAMT
JVVTRVJUcnVzdCBFQ0MgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTgxMTAy
MDAwMDAwWhcNMzAxMjMxMjM1OTU5WjCBlTELMAkGA1UEBhMCR0IxGzAZBgNVBAgT
EkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9yZDEYMBYGA1UEChMP
U2VjdGlnbyBMaW1pdGVkMT0wOwYDVQQDEzRTZWN0aWdvIEVDQyBPcmdhbml6YXRp
b24gVmFsaWRhdGlvbiBTZWN1cmUgU2VydmVyIENBMFkwEwYHKoZIzj0CAQYIKoZI
zj0DAQcDQgAEnI5cCmFvoVij0NXO+vxE+f+6Bh57FhpyH0LTCrJmzfsPSXIhTSex
r92HOlz+aHqoGE0vSe/CSwLFoWcZ8W1jOaOCAW4wggFqMB8GA1UdIwQYMBaAFDrh
CYbUzxnClnZ0SXbc4DXGY2OaMB0GA1UdDgQWBBRNSu/ERrMSrU9OmrFZ4lGrCBB4
CDAOBgNVHQ8BAf8EBAMCAYYwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHSUEFjAU
BggrBgEFBQcDAQYIKwYBBQUHAwIwGwYDVR0gBBQwEjAGBgRVHSAAMAgGBmeBDAEC
AjBQBgNVHR8ESTBHMEWgQ6BBhj9odHRwOi8vY3JsLnVzZXJ0cnVzdC5jb20vVVNF
UlRydXN0RUNDQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcmwwdgYIKwYBBQUHAQEE
ajBoMD8GCCsGAQUFBzAChjNodHRwOi8vY3J0LnVzZXJ0cnVzdC5jb20vVVNFUlRy
dXN0RUNDQWRkVHJ1c3RDQS5jcnQwJQYIKwYBBQUHMAGGGWh0dHA6Ly9vY3NwLnVz
ZXJ0cnVzdC5jb20wCgYIKoZIzj0EAwMDaQAwZgIxAOk//uo7i/MoeKdcyeqvjOXs
BJFGLI+1i0d+Tty7zEnn2w4DNS21TK8wmY3Kjm3EmQIxAPI1qHM/I+OS+hx0OZhG
fDoNifTe/GxgWZ1gOYQKzn6lwP0yGKlrP+7vrVC8IczJ4A==
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26