AppleISTCA2G1.cer: C=US,O=Apple Inc.,OU=Certification Authority,CN=Apple IST CA 2 - G1 (Intermediate Certificate, Expiring 2025-05-07) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.apple.com/certificateauthority/AppleISTCA2G1.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.apple.com/certificateauthority/AppleISTCA2G1.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            71:b3:ba:d2:8d:8c:26:78:f8:38:8d:ec:6f:23:7a:d5:ce:2c:30:cc
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Apple Inc., OU=Apple Certification Authority, CN=Apple Root CA
        Validity
            Not Before: Apr 28 21:38:00 2022 GMT
            Not After : May  7 00:00:00 2025 GMT
        Subject: CN=Apple IST CA 2 - G1, OU=Certification Authority, O=Apple Inc., C=US
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:d0:93:a1:1d:47:43:20:16:b2:0b:6b:eb:c3:d5:
                    b4:e8:c7:98:cd:f3:de:bf:e8:4d:e9:e3:36:80:07:
                    fc:45:1b:6a:7c:45:86:ae:56:d3:a4:09:7f:61:0d:
                    6b:5d:7e:52:6b:7d:b4:c8:39:c4:f4:67:3a:f7:83:
                    ce:19:6f:86:2f:7e:45:7e:47:1c:67:52:ca:95:05:
                    5d:e2:36:51:85:c0:d4:67:80:35:6f:15:dd:3e:fd:
                    1d:d2:fd:8f:34:50:d8:ec:76:2a:be:e3:d3:da:e4:
                    fd:c8:eb:28:02:96:11:97:17:61:1c:e9:c4:59:3b:
                    42:dc:32:d1:09:1d:da:a6:d1:43:86:ff:5e:b2:bc:
                    8c:cf:66:db:01:8b:02:ae:94:48:f3:38:8f:fd:ea:
                    32:a8:08:ec:86:97:51:94:24:3e:49:49:96:53:e8:
                    79:a1:40:81:e9:05:bb:93:95:51:fc:e3:fd:7c:11:
                    4b:f7:9e:08:b3:15:49:15:07:f9:d1:37:a0:9b:4b:
                    32:f6:b5:c4:dc:6a:d1:fc:0a:ed:f6:e0:c5:29:a0:
                    a8:8b:71:fe:0d:92:bc:fe:54:70:18:0a:6d:c7:ed:
                    0c:fb:c9:2d:06:c3:8c:85:fc:cb:86:5c:d6:36:8e:
                    12:8b:09:7f:fb:19:1a:38:d5:f0:94:30:7a:0f:a6:
                    8c:f3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Authority Key Identifier: 
                keyid:2B:D0:69:47:94:76:09:FE:F4:6B:8D:2E:40:A6:F7:47:4D:7F:08:5E

            Authority Information Access: 
                OCSP - URI:http://ocsp.apple.com/ocsp03-applerootca

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

            X509v3 Extended Key Usage: 
                TLS Web Client Authentication, TLS Web Server Authentication
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.apple.com/root.crl

            X509v3 Subject Key Identifier: 
                D8:7A:94:44:7C:90:70:90:16:9E:DD:17:9C:01:44:03:86:D6:2A:29
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            1.2.840.113635.100.6.2.12: 
                ..
    Signature Algorithm: sha256WithRSAEncryption
         b4:18:bf:63:83:5c:5d:03:10:b5:1c:49:0a:28:ab:d6:2f:18:
         f8:7f:fb:96:1e:bd:74:30:44:2f:20:d2:81:2f:80:92:1d:78:
         54:b0:89:73:43:7b:c2:e0:75:08:77:cd:43:6b:a0:5e:72:50:
         00:57:2f:84:bd:a6:2e:c5:d2:e6:54:5f:b0:9e:f4:10:78:11:
         4f:74:df:32:06:02:34:c3:0a:88:bd:22:67:29:6a:29:c0:97:
         b3:3e:cf:43:ff:d0:48:8f:c7:28:7c:d1:0f:80:58:15:f7:2e:
         d3:0f:f9:f2:e3:fc:6b:60:af:cd:36:81:21:40:9b:1c:5f:c3:
         43:f1:b5:18:bf:bc:9b:b9:be:a4:64:6f:29:f1:ee:fb:4b:14:
         b0:7c:f5:56:27:8a:aa:3e:0f:78:a7:66:0d:50:55:7c:bd:1d:
         68:a9:72:6f:c4:cd:f8:4a:21:04:89:a2:b1:3a:0d:7e:87:3c:
         54:01:0f:f7:cc:4d:5b:3b:41:1f:94:f7:0f:3b:ac:da:1f:d3:
         f3:7b:22:6d:a2:0a:83:7c:d0:8c:6b:6d:ae:84:51:f1:70:d2:
         8a:2e:ae:26:34:33:e5:83:90:11:25:15:da:d9:6f:30:44:36:
         d1:f3:7f:f0:44:f1:b9:60:89:31:47:87:e4:2d:ce:ff:88:5c:
         bb:bd:9d:30

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEdjCCA16gAwIBAgIUcbO60o2MJnj4OI3sbyN61c4sMMwwDQYJKoZIhvcNAQEL
BQAwYjELMAkGA1UEBhMCVVMxEzARBgNVBAoTCkFwcGxlIEluYy4xJjAkBgNVBAsT
HUFwcGxlIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MRYwFAYDVQQDEw1BcHBsZSBS
b290IENBMB4XDTIyMDQyODIxMzgwMFoXDTI1MDUwNzAwMDAwMFowYjEcMBoGA1UE
AxMTQXBwbGUgSVNUIENBIDIgLSBHMTEgMB4GA1UECxMXQ2VydGlmaWNhdGlvbiBB
dXRob3JpdHkxEzARBgNVBAoTCkFwcGxlIEluYy4xCzAJBgNVBAYTAlVTMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0JOhHUdDIBayC2vrw9W06MeYzfPe
v+hN6eM2gAf8RRtqfEWGrlbTpAl/YQ1rXX5Sa320yDnE9Gc694POGW+GL35Ffkcc
Z1LKlQVd4jZRhcDUZ4A1bxXdPv0d0v2PNFDY7HYqvuPT2uT9yOsoApYRlxdhHOnE
WTtC3DLRCR3aptFDhv9esryMz2bbAYsCrpRI8ziP/eoyqAjshpdRlCQ+SUmWU+h5
oUCB6QW7k5VR/OP9fBFL954IsxVJFQf50Tegm0sy9rXE3GrR/Art9uDFKaCoi3H+
DZK8/lRwGAptx+0M+8ktBsOMhfzLhlzWNo4Siwl/+xkaONXwlDB6D6aM8wIDAQAB
o4IBIjCCAR4wEgYDVR0TAQH/BAgwBgEB/wIBADAfBgNVHSMEGDAWgBQr0GlHlHYJ
/vRrjS5ApvdHTX8IXjBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAGGKGh0dHA6
Ly9vY3NwLmFwcGxlLmNvbS9vY3NwMDMtYXBwbGVyb290Y2EwEQYDVR0gBAowCDAG
BgRVHSAAMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAuBgNVHR8EJzAl
MCOgIaAfhh1odHRwOi8vY3JsLmFwcGxlLmNvbS9yb290LmNybDAdBgNVHQ4EFgQU
2HqURHyQcJAWnt0XnAFEA4bWKikwDgYDVR0PAQH/BAQDAgEGMBAGCiqGSIb3Y2QG
AgwEAgUAMA0GCSqGSIb3DQEBCwUAA4IBAQC0GL9jg1xdAxC1HEkKKKvWLxj4f/uW
Hr10MEQvINKBL4CSHXhUsIlzQ3vC4HUId81Da6BeclAAVy+EvaYuxdLmVF+wnvQQ
eBFPdN8yBgI0wwqIvSJnKWopwJezPs9D/9BIj8cofNEPgFgV9y7TD/ny4/xrYK/N
NoEhQJscX8ND8bUYv7ybub6kZG8p8e77SxSwfPVWJ4qqPg94p2YNUFV8vR1oqXJv
xM34SiEEiaKxOg1+hzxUAQ/3zE1bO0EflPcPO6zaH9PzeyJtogqDfNCMa22uhFHx
cNKKLq4mNDPlg5ARJRXa2W8wRDbR83/wRPG5YIkxR4fkLc7/iFy7vZ0w
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06