aftov1ca.crt: CN=AffirmTrust Certificate Authority - OV1,OU=See www.affirmtrust.com/repository,O=AffirmTrust,C=CA

Page content

CA Certificate Basic Information

This certificate is root certificate used for the issuance of other certificates.

  • Certificate download URL: http://aia.affirmtrust.com/aftov1ca.crt (DER format)
  • Serial number: 111606596907061919512666864307668197892
  • SHA-1 Fingerprint: cec97e9230e72482ef3c4e3f81a660dc9f1c9911
  • SHA-1 Fingerprint: ce:c9:7e:92:30:e7:24:82:ef:3c:4e:3f:81:a6:60:dc:9f:1c:99:11
  • SHA-256 Fingerprint: b5fd6f800334f565036b0999f8310b5b0bd7268395d8b267005697af7301c5e8
  • SHA-256 Fingerprint: b5:fd:6f:80:03:34:f5:65:03:6b:09:99:f8:31:0b:5b:0b:d7:26:83:95:d8:b2:67:00:56:97:af:73:01:c5:e8
  • Signature hash algorithm: sha256
  • Subject: CN=AffirmTrust Certificate Authority - OV1,OU=See www.affirmtrust.com/repository,O=AffirmTrust,C=CA
  • Not valid before: 2019-03-21 20:25:32
  • Not valid after: 2030-12-02 04:00:00
  • Issuer:
    • Issuer name: CN=AffirmTrust Commercial,O=AffirmTrust,C=US
    • Issuer certificate URL: None

Download certificate through curl:

curl -sSL http://aia.affirmtrust.com/aftov1ca.crt --output cert.crt

Download certificate through wget:

wget -q http://aia.affirmtrust.com/aftov1ca.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            53:f6:a6:11:09:2e:52:8e:d9:63:f1:91:49:53:22:04
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=AffirmTrust, CN=AffirmTrust Commercial
        Validity
            Not Before: Mar 21 20:25:32 2019 GMT
            Not After : Dec  2 04:00:00 2030 GMT
        Subject: C=CA, O=AffirmTrust, OU=See www.affirmtrust.com/repository, CN=AffirmTrust Certificate Authority - OV1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:c2:bd:ca:3b:0d:e7:9b:fe:9f:2f:1a:f6:be:02:
                    25:c3:f9:8f:82:bb:41:e2:03:86:a9:27:81:90:34:
                    d6:cb:48:59:10:f4:f7:68:36:f8:c5:94:23:c7:f6:
                    02:15:25:f7:36:f0:9a:ed:f3:bd:5d:e0:83:e1:af:
                    1a:30:7b:2d:ea:6b:e1:cf:1c:c9:8d:a2:2c:00:72:
                    35:f1:8a:cb:02:06:ae:cd:ad:98:24:49:74:4c:86:
                    26:ba:16:ed:cd:bc:58:05:a9:93:65:ef:36:f5:19:
                    3a:42:4a:29:58:88:72:04:fd:6f:ed:1e:d6:dc:96:
                    7d:5b:9c:b2:24:ec:03:32:d9:94:b6:12:0b:26:27:
                    25:3b:c9:56:e6:12:8f:18:db:47:f7:03:75:83:21:
                    c6:55:ce:33:90:18:96:fc:75:8c:61:70:1b:35:31:
                    6c:03:7a:88:5a:bc:18:4c:08:58:b6:20:35:df:05:
                    98:db:0f:60:7a:06:2a:bb:fa:36:49:b4:fa:34:eb:
                    2c:83:b0:2d:9f:78:be:7f:7a:5e:f3:d4:3e:a0:4d:
                    47:28:08:19:53:e5:8e:b3:3e:7b:01:07:dd:15:d6:
                    f5:47:55:37:a8:a5:d9:e1:3f:8b:9c:72:a5:65:9f:
                    8d:08:80:00:0a:b1:ad:f9:71:0b:2d:c6:a6:61:2c:
                    d8:49
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            Authority Information Access: 
                OCSP - URI:http://ocsp.affirmtrust.com

            X509v3 Subject Key Identifier: 
                FE:60:C3:0D:A4:A2:9D:21:4F:7A:78:4C:62:C5:DB:14:FC:39:78:C4
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Authority Key Identifier: 
                keyid:9D:93:C6:53:8B:5E:CA:AF:3F:9F:1E:0F:E5:99:95:BC:24:F6:94:8F

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://www.affirmtrust.com/repository

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.affirmtrust.com/crl/AffirmTrustCommercial.crl

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
    Signature Algorithm: sha256WithRSAEncryption
         3a:4e:78:a8:73:cc:78:9c:0e:b4:fb:7f:28:fd:2f:19:9d:4a:
         c7:f1:bb:ce:47:ef:63:d7:d1:c3:ed:40:4c:67:8b:ca:e0:6f:
         0c:f1:43:18:2e:d9:1d:77:a0:cb:d7:07:e6:dc:47:26:9c:d8:
         b7:63:6c:e6:5f:74:4f:0a:8a:48:b0:dc:81:61:ed:7d:e8:2d:
         5a:7c:d8:44:e1:e5:ef:0d:e5:94:ba:cc:4b:2f:8c:8e:18:d4:
         94:7e:e1:4d:34:6b:93:a5:5d:d0:7a:dc:af:3e:28:07:d7:9b:
         1e:61:bf:50:51:56:a0:3e:21:b2:0e:ca:02:0a:93:8e:d9:52:
         d5:5b:37:65:60:a7:51:a2:c0:84:e7:1f:e8:9e:7a:21:1a:35:
         00:64:df:3a:1f:c3:f3:3a:1d:83:94:07:b6:16:62:f9:47:25:
         e2:4c:03:f3:3c:d4:75:77:73:71:89:2d:b9:5c:2c:ff:96:4d:
         a7:53:6f:d8:5b:d2:9a:63:4a:9e:95:85:7e:42:75:39:35:46:
         30:a9:eb:c1:4f:c5:f0:ab:04:ee:d8:48:51:fc:f5:c7:f0:4b:
         fe:43:51:a7:b3:cc:89:74:4a:8b:83:7b:28:48:a2:40:f9:5e:
         77:d1:0c:dc:57:85:ec:ed:2a:d9:f6:e7:e5:2e:19:e7:27:6e:
         08:46:2b:aa

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEpzCCA4+gAwIBAgIQU/amEQkuUo7ZY/GRSVMiBDANBgkqhkiG9w0BAQsFADBE
MQswCQYDVQQGEwJVUzEUMBIGA1UECgwLQWZmaXJtVHJ1c3QxHzAdBgNVBAMMFkFm
ZmlybVRydXN0IENvbW1lcmNpYWwwHhcNMTkwMzIxMjAyNTMyWhcNMzAxMjAyMDQw
MDAwWjCBgjELMAkGA1UEBhMCQ0ExFDASBgNVBAoTC0FmZmlybVRydXN0MSswKQYD
VQQLEyJTZWUgd3d3LmFmZmlybXRydXN0LmNvbS9yZXBvc2l0b3J5MTAwLgYDVQQD
EydBZmZpcm1UcnVzdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgLSBPVjEwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDCvco7Deeb/p8vGva+AiXD+Y+Cu0Hi
A4apJ4GQNNbLSFkQ9PdoNvjFlCPH9gIVJfc28Jrt871d4IPhrxowey3qa+HPHMmN
oiwAcjXxissCBq7NrZgkSXRMhia6Fu3NvFgFqZNl7zb1GTpCSilYiHIE/W/tHtbc
ln1bnLIk7AMy2ZS2EgsmJyU7yVbmEo8Y20f3A3WDIcZVzjOQGJb8dYxhcBs1MWwD
eohavBhMCFi2IDXfBZjbD2B6Biq7+jZJtPo06yyDsC2feL5/el7z1D6gTUcoCBlT
5Y6zPnsBB90V1vVHVTeopdnhP4uccqVln40IgAAKsa35cQstxqZhLNhJAgMBAAGj
ggFUMIIBUDA3BggrBgEFBQcBAQQrMCkwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vY3Nw
LmFmZmlybXRydXN0LmNvbTAdBgNVHQ4EFgQU/mDDDaSinSFPenhMYsXbFPw5eMQw
EgYDVR0TAQH/BAgwBgEB/wIBADAfBgNVHSMEGDAWgBSdk8ZTi17Krz+fHg/lmZW8
JPaUjzBHBgNVHSAEQDA+MDwGBFUdIAAwNDAyBggrBgEFBQcCARYmaHR0cHM6Ly93
d3cuYWZmaXJtdHJ1c3QuY29tL3JlcG9zaXRvcnkwSQYDVR0fBEIwQDA+oDygOoY4
aHR0cDovL2NybC5hZmZpcm10cnVzdC5jb20vY3JsL0FmZmlybVRydXN0Q29tbWVy
Y2lhbC5jcmwwDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggr
BgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAOk54qHPMeJwOtPt/KP0vGZ1Kx/G7
zkfvY9fRw+1ATGeLyuBvDPFDGC7ZHXegy9cH5txHJpzYt2Ns5l90TwqKSLDcgWHt
fegtWnzYROHl7w3llLrMSy+MjhjUlH7hTTRrk6Vd0Hrcrz4oB9ebHmG/UFFWoD4h
sg7KAgqTjtlS1Vs3ZWCnUaLAhOcf6J56IRo1AGTfOh/D8zodg5QHthZi+Ucl4kwD
8zzUdXdzcYktuVws/5ZNp1Nv2FvSmmNKnpWFfkJ1OTVGMKnrwU/F8KsE7thIUfz1
x/BL/kNRp7PMiXRKi4N7KEiiQPled9EM3FeF7O0q2fbn5S4Z5yduCEYrqg==
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26