R2-ServerCA2A.orig.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Intermediate Certificate, Expiring 2040-10-21) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/R2-ServerCA2A.orig.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/R2-ServerCA2A.orig.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7b:50:58:e2:64:2c:1a:92:84:8b:ac:0d:b1:af:00:a0:e2:20
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
        Validity
            Not Before: Oct 21 22:23:50 2015 GMT
            Not After : Oct 21 22:23:50 2040 GMT
        Subject: C=US, O=Amazon, OU=Server CA 2A, CN=Amazon
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:b4:3f:c8:52:2d:ec:26:ad:9e:35:08:23:c1:43:
                    2b:59:b3:93:41:14:ca:b9:ce:d6:e7:31:ff:a4:65:
                    4a:7d:4b:6e:4b:3d:f8:cd:5b:7c:e0:0b:fe:84:a8:
                    24:d6:35:53:0c:1e:1a:bb:7b:3f:48:40:99:38:f2:
                    a6:df:05:32:e5:66:4b:8a:9d:45:9b:03:db:e8:c2:
                    b0:df:73:15:0d:d2:64:44:e0:1f:d3:25:bb:de:5f:
                    24:df:bc:4f:75:88:39:6a:0e:b1:11:79:c1:3d:0f:
                    cb:1d:8f:35:11:ae:d1:d3:a7:6e:e5:65:d4:64:5c:
                    5b:df:11:50:aa:e2:19:77:b0:79:33:8e:87:62:b1:
                    a4:2d:84:ba:75:80:bb:22:03:bb:ca:b7:ef:33:70:
                    be:00:7a:ae:76:53:26:1b:f2:be:3f:8d:d6:77:29:
                    a4:29:f0:ef:d3:e1:5c:03:09:12:a6:f1:ec:b7:92:
                    db:69:25:66:9f:95:c8:bb:79:1c:cd:8d:8e:e0:13:
                    73:4c:00:d5:57:09:e4:30:38:17:c7:d8:68:c8:34:
                    50:8e:6e:63:ec:aa:20:6e:a0:09:ec:bf:69:39:69:
                    02:cd:a1:4d:4e:66:4d:3c:0a:55:e6:98:46:76:ac:
                    8e:6a:65:44:d7:d4:7b:9e:7c:12:67:a4:c9:0f:ba:
                    01:42:c3:c6:9f:68:79:c1:d7:74:a4:2c:4e:f0:c5:
                    7f:12:65:17:43:21:ee:56:8b:0c:83:2f:5b:51:db:
                    ef:25:a7:3e:09:b0:ca:05:a2:91:e6:0f:71:9a:1f:
                    28:db:37:e8:64:3a:a1:e0:2e:5b:70:7b:03:ac:8b:
                    23:34:bb:70:99:a6:1c:a9:37:62:9e:0f:ed:45:2e:
                    39:d8:4e:07:48:01:dd:45:46:02:b6:65:70:c3:ac:
                    47:63:9e:c4:84:7d:28:4a:7f:49:78:98:53:d2:06:
                    cf:44:dd:4e:ac:2e:6b:9b:0d:15:ca:2c:b2:e9:6b:
                    f7:45:e1:e2:ae:2c:42:92:d5:b5:d8:4f:6f:22:33:
                    a0:f9:81:20:a7:ce:1a:39:1b:87:75:f2:34:03:fe:
                    c9:66:73:95:e6:46:8e:4f:8a:0d:11:c8:1c:03:68:
                    bb:b1:78:86:6e:88:9d:00:27:a6:05:85:f7:db:ac:
                    b6:05:e5:d1:10:97:47:14:fa:dd:d5:04:ae:6e:fe:
                    8d:56:91:65:ec:65:ac:14:d3:7f:25:5a:7f:c0:5d:
                    ea:e8:75:3f:e9:01:ca:ed:58:0e:04:35:01:0d:d3:
                    d5:84:28:c8:59:54:f8:6a:77:08:45:fc:6b:ac:af:
                    4e:26:42:d2:ad:ed:3d:af:e9:43:10:be:d5:60:96:
                    fe:44:ef
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                DA:43:4A:D0:FC:01:C0:4B:BF:58:27:8C:76:CD:0A:81:F3:94:2E:F4
            X509v3 Authority Key Identifier: 
                keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca2.amazontrust.com
                CA Issuers - URI:http://crl.rootca2.amazontrust.com/rootca2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca2.amazontrust.com/rootca2.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

    Signature Algorithm: sha384WithRSAEncryption
         98:a4:09:20:af:18:94:8d:28:0f:af:94:70:4f:0e:b3:ba:62:
         78:3a:b2:23:a9:1c:23:25:7f:2b:f4:09:9d:51:e3:82:b5:fa:
         9f:eb:b7:46:c6:a3:82:d5:a7:18:61:1c:05:bb:1f:39:cc:7e:
         88:58:9f:f7:c4:2f:e2:e8:26:32:d0:62:e6:73:46:ac:0e:14:
         11:8f:a7:b5:21:c3:64:8c:c2:d4:c0:a4:01:cf:e2:55:b3:20:
         f1:58:4a:66:46:26:94:a5:8f:cb:17:15:b2:c0:97:4c:c5:64:
         3f:6b:8a:f6:df:4b:45:1e:d5:cf:49:86:d3:7f:7e:2f:1f:b7:
         d1:c3:f7:76:62:a4:50:f7:32:51:02:4e:73:d0:d3:6a:ba:be:
         b4:2c:58:da:73:5b:5c:ff:d4:1a:bb:81:ab:46:df:1e:4e:cb:
         06:27:88:00:37:0c:67:a3:95:e5:f0:63:b6:61:82:cc:8a:d6:
         b1:12:a0:71:ec:ae:5c:36:fe:1b:52:50:54:db:95:3a:88:24:
         bf:96:ed:72:b3:45:ea:1c:c2:b1:1a:86:36:be:ec:27:84:75:
         e6:03:1d:d8:87:d8:41:b7:15:b3:81:d0:17:12:8b:64:69:d2:
         c8:c4:91:00:d8:cc:3a:8b:e6:e4:a7:41:26:d7:91:cf:77:6c:
         87:fd:6f:2a:37:19:bc:26:fd:33:67:b7:85:3d:6d:3b:92:91:
         4d:52:2c:f2:69:3e:fc:59:07:82:0e:a3:bb:40:52:e7:36:8b:
         87:4d:d3:41:f9:c3:15:03:49:87:d2:85:26:3e:9c:f7:6f:72:
         a8:ef:96:aa:5f:1a:a8:3c:f0:04:5e:f9:6a:4f:4c:e3:cd:26:
         f0:e0:1d:b0:27:8b:ff:8d:b6:84:1d:68:7f:59:d1:87:a5:88:
         c1:9a:bb:fb:4d:95:58:fb:55:cd:44:80:4c:91:8c:97:41:7b:
         d8:01:40:86:db:e0:e6:6a:b3:81:9d:9d:2d:b2:d2:9c:ee:50:
         56:34:99:f8:66:26:07:1a:8e:7c:31:1a:8e:36:5e:40:7b:33:
         12:e3:af:ad:2f:9c:58:56:37:e6:a5:8a:3a:39:48:27:21:05:
         a3:a0:cf:0d:ac:a3:40:1e:55:51:55:13:c9:4f:e7:a1:2d:70:
         d1:aa:99:4a:74:c0:db:1e:48:6d:23:08:27:17:28:4f:0e:a2:
         b3:f6:ea:1f:5b:9a:c1:8c:0a:e7:42:23:2b:2e:77:84:49:62:
         3a:42:37:b2:9b:fe:23:d0:51:b6:d7:32:7e:61:ea:30:f0:73:
         43:51:21:66:13:fd:ad:02:8b:64:93:2e:a0:0e:1a:f7:fd:3c:
         48:05:5e:85:b1:9e:a3:76

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIGRzCCBC+gAwIBAgITBntQWOJkLBqShIusDbGvAKDiIDANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTE1MTAyMTIyMjM1MFoXDTQwMTAyMTIyMjM1MFowRjEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEVMBMGA1UECxMMU2VydmVyIENB
IDJBMQ8wDQYDVQQDEwZBbWF6b24wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIK
AoICAQC0P8hSLewmrZ41CCPBQytZs5NBFMq5ztbnMf+kZUp9S25LPfjNW3zgC/6E
qCTWNVMMHhq7ez9IQJk48qbfBTLlZkuKnUWbA9vowrDfcxUN0mRE4B/TJbveXyTf
vE91iDlqDrERecE9D8sdjzURrtHTp27lZdRkXFvfEVCq4hl3sHkzjodisaQthLp1
gLsiA7vKt+8zcL4Aeq52UyYb8r4/jdZ3KaQp8O/T4VwDCRKm8ey3kttpJWaflci7
eRzNjY7gE3NMANVXCeQwOBfH2GjINFCObmPsqiBuoAnsv2k5aQLNoU1OZk08ClXm
mEZ2rI5qZUTX1HuefBJnpMkPugFCw8afaHnB13SkLE7wxX8SZRdDIe5WiwyDL1tR
2+8lpz4JsMoFopHmD3GaHyjbN+hkOqHgLltwewOsiyM0u3CZphypN2KeD+1FLjnY
TgdIAd1FRgK2ZXDDrEdjnsSEfShKf0l4mFPSBs9E3U6sLmubDRXKLLLpa/dF4eKu
LEKS1bXYT28iM6D5gSCnzho5G4d18jQD/slmc5XmRo5Pig0RyBwDaLuxeIZuiJ0A
J6YFhffbrLYF5dEQl0cU+t3VBK5u/o1WkWXsZawU038lWn/AXerodT/pAcrtWA4E
NQEN09WEKMhZVPhqdwhF/Gusr04mQtKt7T2v6UMQvtVglv5E7wIDAQABo4IBOTCC
ATUwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYE
FNpDStD8AcBLv1gnjHbNCoHzlC70MB8GA1UdIwQYMBaAFLAM8Eww9AVYAkj9M+VS
r0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggrBgEFBQcwAYYjaHR0cDovL29jc3Au
cm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYIKwYBBQUHMAKGLmh0dHA6Ly9jcmwu
cm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9vdGNhMi5jZXIwPwYDVR0fBDgwNjA0
oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFtYXpvbnRydXN0LmNvbS9yb290Y2Ey
LmNybDARBgNVHSAECjAIMAYGBFUdIAAwDQYJKoZIhvcNAQEMBQADggIBAJikCSCv
GJSNKA+vlHBPDrO6Yng6siOpHCMlfyv0CZ1R44K1+p/rt0bGo4LVpxhhHAW7HznM
fohYn/fEL+LoJjLQYuZzRqwOFBGPp7Uhw2SMwtTApAHP4lWzIPFYSmZGJpSlj8sX
FbLAl0zFZD9rivbfS0Ue1c9JhtN/fi8ft9HD93ZipFD3MlECTnPQ02q6vrQsWNpz
W1z/1Bq7gatG3x5OywYniAA3DGejleXwY7ZhgsyK1rESoHHsrlw2/htSUFTblTqI
JL+W7XKzReocwrEahja+7CeEdeYDHdiH2EG3FbOB0BcSi2Rp0sjEkQDYzDqL5uSn
QSbXkc93bIf9byo3Gbwm/TNnt4U9bTuSkU1SLPJpPvxZB4IOo7tAUuc2i4dN00H5
wxUDSYfShSY+nPdvcqjvlqpfGqg88ARe+WpPTOPNJvDgHbAni/+NtoQdaH9Z0Yel
iMGau/tNlVj7Vc1EgEyRjJdBe9gBQIbb4OZqs4GdnS2y0pzuUFY0mfhmJgcajnwx
Go42XkB7MxLjr60vnFhWN+alijo5SCchBaOgzw2so0AeVVFVE8lP56EtcNGqmUp0
wNseSG0jCCcXKE8OorP26h9bmsGMCudCIysud4RJYjpCN7Kb/iPQUbbXMn5h6jDw
c0NRIWYT/a0Ci2STLqAOGvf9PEgFXoWxnqN2
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06