cmca.cer: CN=Cisco Manufacturing CA,O=Cisco Systems (Intermediate Certificate, Expiring 2029-05-14) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.cisco.com/security/pki/certs/cmca.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.cisco.com/security/pki/certs/cmca.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            6a:69:67:b3:00:00:00:00:00:03
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: O=Cisco Systems, CN=Cisco Root CA 2048
        Validity
            Not Before: Jun 10 22:16:01 2005 GMT
            Not After : May 14 20:25:42 2029 GMT
        Subject: O=Cisco Systems, CN=Cisco Manufacturing CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:a0:c5:f7:dc:96:94:35:15:f1:f4:99:4e:bb:9b:
                    41:e1:7d:db:79:16:91:bb:f3:54:f2:41:4a:94:32:
                    62:62:c9:23:f7:9a:e7:bb:9b:79:e8:07:29:4e:30:
                    f5:ae:1b:c5:21:56:46:b0:f8:f4:e6:8e:81:b8:16:
                    cc:a8:9b:85:d2:42:81:db:7c:cb:94:a9:11:61:12:
                    1c:5c:ea:33:20:1c:9a:16:a7:7d:db:99:06:6a:e2:
                    36:af:ec:f8:0a:ff:98:67:07:f4:30:ee:a5:f8:88:
                    1a:aa:e8:c7:3c:1c:ce:ee:48:fd:cd:5c:37:f1:86:
                    93:9e:3d:71:75:7d:34:ee:4b:14:a9:c0:29:7b:05:
                    10:ef:87:9e:69:31:30:f5:48:36:3f:d8:ab:ce:15:
                    e2:e8:58:9f:3e:62:71:04:87:26:a4:15:62:01:25:
                    aa:d5:df:c9:c9:5b:b8:c9:a1:07:7b:be:68:92:93:
                    93:20:a8:6c:bd:15:75:d3:44:5d:45:4b:ec:a8:da:
                    60:c7:d8:c8:d5:c8:ed:41:e1:f5:5f:57:8e:53:32:
                    93:49:d5:d9:0f:f8:36:aa:07:c4:32:41:c5:a7:af:
                    1d:19:ff:f6:73:99:39:5a:73:67:62:13:34:0d:1f:
                    5e:95:70:52:64:17:06:ec:53:5c:5c:db:6a:ea:35:
                    00:41
                Exponent: 3 (0x3)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Subject Key Identifier: 
                D0:C5:22:26:AB:4F:46:60:EC:AE:05:91:C7:DC:5A:D1:B0:47:F7:6C
            X509v3 Key Usage: 
                Digital Signature, Certificate Sign, CRL Sign
            1.3.6.1.4.1.311.21.1: 
                ...
            1.3.6.1.4.1.311.20.2: 
                .
.S.u.b.C.A
            X509v3 Authority Key Identifier: 
                keyid:27:F3:C8:15:1E:6E:9A:02:09:16:AD:2B:A0:89:60:5F:DA:7B:2F:AA

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://www.cisco.com/security/pki/crl/crca2048.crl

            Authority Information Access: 
                CA Issuers - URI:http://www.cisco.com/security/pki/certs/crca2048.cer

            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.9.21.1.2.0
                  CPS: http://www.cisco.com/security/pki/policies/index.html

            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication, IPSec End System, IPSec Tunnel, IPSec User, Microsoft Trust List Signing, 1.3.6.1.4.1.311.20.2.1, 1.3.6.1.4.1.311.21.6
    Signature Algorithm: sha1WithRSAEncryption
         30:f3:30:2d:8c:f2:ca:37:4a:64:99:24:29:0a:f2:86:aa:42:
         d5:23:e8:a2:ea:2b:6f:69:23:7a:82:8e:1c:4c:09:cf:a4:4f:
         ab:84:2f:37:e9:65:60:d1:9a:c6:d8:f3:0b:f5:de:d0:27:00:
         5c:6f:1d:91:bd:d1:4e:58:51:1d:c9:e3:f7:38:e7:d3:0b:d1:
         68:be:8e:22:a5:4b:06:e1:e6:a4:aa:33:7d:1a:75:ba:26:f3:
         70:c6:61:00:a5:c3:79:26:5b:a7:19:d1:93:8d:ab:9b:10:11:
         29:1f:a1:82:fd:fd:3c:4b:6e:65:dc:93:45:05:e9:af:33:6b:
         67:23:07:06:86:22:da:eb:dc:87:cf:59:21:42:1a:e9:cf:70:
         75:88:e0:24:3d:5d:7d:4e:96:38:80:97:d5:6f:f0:9b:71:d8:
         ba:60:19:a5:b0:61:86:ad:dd:65:66:f6:b9:27:a2:ee:2f:61:
         9b:ba:a1:30:61:fd:be:ac:35:14:f9:b8:2d:97:06:af:c3:ef:
         6d:cc:3d:3c:eb:95:e9:81:d3:8a:5e:b6:ce:fa:79:a4:6b:d7:
         a2:57:64:c4:3f:4c:c9:db:e8:82:ec:01:66:d4:10:88:a2:56:
         e5:3c:57:ed:e9:02:a8:48:91:63:07:ab:61:26:4b:1a:13:9f:
         e4:dc:da:5f

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIE2TCCA8GgAwIBAgIKamlnswAAAAAAAzANBgkqhkiG9w0BAQUFADA1MRYwFAYD
VQQKEw1DaXNjbyBTeXN0ZW1zMRswGQYDVQQDExJDaXNjbyBSb290IENBIDIwNDgw
HhcNMDUwNjEwMjIxNjAxWhcNMjkwNTE0MjAyNTQyWjA5MRYwFAYDVQQKEw1DaXNj
byBTeXN0ZW1zMR8wHQYDVQQDExZDaXNjbyBNYW51ZmFjdHVyaW5nIENBMIIBIDAN
BgkqhkiG9w0BAQEFAAOCAQ0AMIIBCAKCAQEAoMX33JaUNRXx9JlOu5tB4X3beRaR
u/NU8kFKlDJiYskj95rnu5t56AcpTjD1rhvFIVZGsPj05o6BuBbMqJuF0kKB23zL
lKkRYRIcXOozIByaFqd925kGauI2r+z4Cv+YZwf0MO6l+IgaqujHPBzO7kj9zVw3
8YaTnj1xdX007ksUqcApewUQ74eeaTEw9Ug2P9irzhXi6FifPmJxBIcmpBViASWq
1d/JyVu4yaEHe75okpOTIKhsvRV100RdRUvsqNpgx9jI1cjtQeH1X1eOUzKTSdXZ
D/g2qgfEMkHFp68dGf/2c5k5WnNnYhM0DR9elXBSZBcG7FNcXNtq6jUAQQIBA6OC
AecwggHjMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFNDFIiarT0Zg7K4F
kcfcWtGwR/dsMAsGA1UdDwQEAwIBhjAQBgkrBgEEAYI3FQEEAwIBADAZBgkrBgEE
AYI3FAIEDB4KAFMAdQBiAEMAQTAfBgNVHSMEGDAWgBQn88gVHm6aAgkWrSugiWBf
2nsvqjBDBgNVHR8EPDA6MDigNqA0hjJodHRwOi8vd3d3LmNpc2NvLmNvbS9zZWN1
cml0eS9wa2kvY3JsL2NyY2EyMDQ4LmNybDBQBggrBgEFBQcBAQREMEIwQAYIKwYB
BQUHMAKGNGh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3VyaXR5L3BraS9jZXJ0cy9j
cmNhMjA0OC5jZXIwXAYDVR0gBFUwUzBRBgorBgEEAQkVAQIAMEMwQQYIKwYBBQUH
AgEWNWh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3VyaXR5L3BraS9wb2xpY2llcy9p
bmRleC5odG1sMF4GA1UdJQRXMFUGCCsGAQUFBwMBBggrBgEFBQcDAgYIKwYBBQUH
AwUGCCsGAQUFBwMGBggrBgEFBQcDBwYKKwYBBAGCNwoDAQYKKwYBBAGCNxQCAQYJ
KwYBBAGCNxUGMA0GCSqGSIb3DQEBBQUAA4IBAQAw8zAtjPLKN0pkmSQpCvKGqkLV
I+ii6itvaSN6go4cTAnPpE+rhC836WVg0ZrG2PML9d7QJwBcbx2RvdFOWFEdyeP3
OOfTC9Fovo4ipUsG4eakqjN9GnW6JvNwxmEApcN5JlunGdGTjaubEBEpH6GC/f08
S25l3JNFBemvM2tnIwcGhiLa69yHz1khQhrpz3B1iOAkPV19TpY4gJfVb/Cbcdi6
YBmlsGGGrd1lZva5J6LuL2GbuqEwYf2+rDUU+bgtlwavw+9tzD0865XpgdOKXrbO
+nmka9eiV2TEP0zJ2+iC7AFm1BCIolblPFft6QKoSJFjB6thJksaE5/k3Npf
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06