apsecc12g1.der: C=US,ST=California,O=Apple Inc.,CN=Apple Public Server ECC CA 12 - G1

Page content

CA Certificate Basic Information

This certificate is root certificate used for the issuance of other certificates.

  • Certificate download URL: http://certs.apple.com/apsecc12g1.der (DER format)
  • Serial number: 152062101864786254270275607527185217712
  • SHA-1 Fingerprint: cf040baae6f7c4caf6b0ba88d7d5d001f4fa0cfd
  • SHA-1 Fingerprint: cf:04:0b:aa:e6:f7:c4:ca:f6:b0:ba:88:d7:d5:d0:01:f4:fa:0c:fd
  • SHA-256 Fingerprint: 70db9ded944dd35d474ea15ff2aa4e25f393a893ecda54359d305bc319649817
  • SHA-256 Fingerprint: 70:db:9d:ed:94:4d:d3:5d:47:4e:a1:5f:f2:aa:4e:25:f3:93:a8:93:ec:da:54:35:9d:30:5b:c3:19:64:98:17
  • Signature hash algorithm: sha256
  • Subject: C=US,ST=California,O=Apple Inc.,CN=Apple Public Server ECC CA 12 - G1
  • Not valid before: 2019-06-19 00:00:00
  • Not valid after: 2028-12-06 23:59:59
  • Issuer:
    • Issuer name: CN=AAA Certificate Services,O=Comodo CA Limited,L=Salford,ST=Greater Manchester,C=GB
    • Issuer certificate URL: None

Download certificate through curl:

curl -sSL http://certs.apple.com/apsecc12g1.der --output cert.crt

Download certificate through wget:

wget -q http://certs.apple.com/apsecc12g1.der --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            72:66:18:75:3a:d6:c9:22:c5:6c:9d:e1:f3:84:78:b0
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
        Validity
            Not Before: Jun 19 00:00:00 2019 GMT
            Not After : Dec  6 23:59:59 2028 GMT
        Subject: CN=Apple Public Server ECC CA 12 - G1, O=Apple Inc., ST=California, C=US
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:97:79:71:27:f1:cf:44:d9:8c:ff:c1:19:b5:87:
                    59:ee:d1:b5:cb:78:91:39:8c:4d:4a:a1:18:3d:10:
                    ca:6a:bc:0a:7f:74:95:e4:b7:9e:4f:32:c8:62:ac:
                    96:35:d5:5d:9e:f2:7e:85:12:86:f8:1a:48:58:9f:
                    31:46:6e:b0:30
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:A0:11:0A:23:3E:96:F1:07:EC:E2:AF:29:EF:82:A5:7F:D0:30:A4:B4

            X509v3 Subject Key Identifier: 
                5F:E3:2E:8A:94:97:DE:D3:5C:E1:B7:D4:BC:98:8E:31:29:C9:90:3A
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Certificate Policies: 
                Policy: 1.2.840.113635.100.5.11.4
                Policy: 2.23.140.1.2.2

            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.comodoca.com/AAACertificateServices.crl

            Authority Information Access: 
                OCSP - URI:http://ocsp.comodoca.com

    Signature Algorithm: sha256WithRSAEncryption
         a3:dc:6d:e8:d1:49:58:d8:c8:5e:8f:7a:1d:76:f5:67:ba:27:
         8c:d7:d8:da:84:15:74:38:14:c0:e1:63:c4:a9:6c:b2:70:4b:
         9b:9b:cf:ac:f7:35:b3:00:b3:ea:61:d9:d0:53:7f:c3:58:24:
         b4:3d:49:71:b0:4d:7a:37:b5:55:e0:2f:64:62:47:43:21:fc:
         99:cd:6c:cf:a0:4b:ae:08:de:2c:e6:80:d4:43:45:26:5f:32:
         4f:bd:fb:89:5f:ce:c7:67:12:e2:06:dc:e4:1d:01:e8:c2:c5:
         ea:86:41:66:7d:22:1a:76:13:96:eb:54:3f:c4:38:9a:fc:b5:
         8d:3c:89:27:70:1e:d7:b3:cf:93:4c:23:21:7f:ca:28:ad:f3:
         38:3f:d8:6a:48:bc:db:3e:ae:27:27:ed:64:59:a3:44:3c:22:
         0f:0b:7c:dc:cc:19:7d:8e:80:7c:58:35:c1:e9:fb:96:c9:a7:
         40:24:8d:25:56:a0:7f:8c:00:e1:41:8b:bf:a8:91:a8:e6:db:
         10:fb:aa:af:83:b5:fa:64:65:d0:a7:83:ba:83:e9:8b:71:0d:
         81:29:17:aa:cd:9b:50:50:81:a9:5c:21:58:34:77:62:f0:0f:
         3d:73:c4:2a:3c:a7:9a:cd:ca:c1:ae:a1:fd:cf:a5:fc:00:cb:
         a7:c0:59:58

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDxTCCAq2gAwIBAgIQcmYYdTrWySLFbJ3h84R4sDANBgkqhkiG9w0BAQsFADB7
MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYD
VQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEhMB8GA1UE
AwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTE5MDYxOTAwMDAwMFoXDTI4
MTIwNjIzNTk1OVowZDErMCkGA1UEAxMiQXBwbGUgUHVibGljIFNlcnZlciBFQ0Mg
Q0EgMTIgLSBHMTETMBEGA1UEChMKQXBwbGUgSW5jLjETMBEGA1UECBMKQ2FsaWZv
cm5pYTELMAkGA1UEBhMCVVMwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAASXeXEn
8c9E2Yz/wRm1h1nu0bXLeJE5jE1KoRg9EMpqvAp/dJXkt55PMshirJY11V2e8n6F
Eob4GkhYnzFGbrAwo4IBJTCCASEwHwYDVR0jBBgwFoAUoBEKIz6W8Qfs4q8p74Kl
f9AwpLQwHQYDVR0OBBYEFF/jLoqUl97TXOG31LyYjjEpyZA6MA4GA1UdDwEB/wQE
AwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwIQYDVR0gBBowGDAM
BgoqhkiG92NkBQsEMAgGBmeBDAECAjASBgNVHRMBAf8ECDAGAQH/AgEAMEMGA1Ud
HwQ8MDowOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29tL0FBQUNlcnRpZmlj
YXRlU2VydmljZXMuY3JsMDQGCCsGAQUFBwEBBCgwJjAkBggrBgEFBQcwAYYYaHR0
cDovL29jc3AuY29tb2RvY2EuY29tMA0GCSqGSIb3DQEBCwUAA4IBAQCj3G3o0UlY
2Mhej3oddvVnuieM19jahBV0OBTA4WPEqWyycEubm8+s9zWzALPqYdnQU3/DWCS0
PUlxsE16N7VV4C9kYkdDIfyZzWzPoEuuCN4s5oDUQ0UmXzJPvfuJX87HZxLiBtzk
HQHowsXqhkFmfSIadhOW61Q/xDia/LWNPIkncB7Xs8+TTCMhf8oorfM4P9hqSLzb
Pq4nJ+1kWaNEPCIPC3zczBl9joB8WDXB6fuWyadAJI0lVqB/jADhQYu/qJGo5tsQ
+6qvg7X6ZGXQp4O6g+mLcQ2BKReqzZtQUIGpXCFYNHdi8A89c8QqPKeazcrBrqH9
z6X8AMunwFlY
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26