Amazon-ECDSA-384-M02.cer: CN=Amazon ECDSA 384 M02,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-ECDSA-384-M02.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-ECDSA-384-M02.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:7d:fa:a6:b9:e2:b9:55:38:aa:76:dd:e4:30:7f:17:c4
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 4
        Validity
            Not Before: Aug 23 22:36:58 2022 GMT
            Not After : Aug 23 22:36:58 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon ECDSA 384 M02
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:cd:63:35:90:0d:75:74:36:83:66:47:48:49:3f:
                    02:6a:86:36:0e:39:2f:73:d0:1d:99:ec:c4:2e:77:
                    18:39:c7:75:6c:89:be:8d:fa:d2:64:ab:c7:65:8d:
                    1a:b9:a3:a2:b4:6d:b8:7f:91:15:5f:a2:2f:70:7c:
                    a8:41:d3:76:33:82:47:ab:af:04:42:1f:b6:7d:81:
                    4e:67:6c:16:3e:63:9f:84:b4:89:aa:e3:23:81:d2:
                    7e:c9:42:04:31:59:e9
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                A6:D9:AB:3B:87:99:33:FF:E8:68:F8:8B:61:83:6C:D0:B2:BA:AF:BD
            X509v3 Authority Key Identifier: 
                keyid:D3:EC:C7:3A:65:6E:CC:E1:DA:76:9A:56:FB:9C:F3:86:6D:57:E5:81

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca4.amazontrust.com
                CA Issuers - URI:http://crt.rootca4.amazontrust.com/rootca4.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca4.amazontrust.com/rootca4.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: ecdsa-with-SHA384
         30:66:02:31:00:db:30:86:eb:1d:31:32:58:12:5d:61:06:2c:
         df:3e:d5:73:7e:38:26:05:e6:f8:f4:67:58:ed:57:2f:80:a5:
         d2:e5:ce:ec:4d:b7:d1:c1:5a:7d:e1:be:ab:ce:d9:6f:0a:02:
         31:00:a4:d7:6c:64:e0:a6:93:9b:99:05:88:ae:09:20:67:0c:
         7d:e3:c8:a8:4d:e9:d5:b2:ba:e1:d6:f5:68:fb:4b:12:a7:39:
         4e:7e:c1:85:99:03:40:50:02:fd:4a:4f:ad:a2

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDETCCApagAwIBAgITB3MSffqmueK5VTiqdt3kMH8XxDAKBggqhkjOPQQDAzA5
MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6b24g
Um9vdCBDQSA0MB4XDTIyMDgyMzIyMzY1OFoXDTMwMDgyMzIyMzY1OFowPTELMAkG
A1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEdMBsGA1UEAxMUQW1hem9uIEVDRFNB
IDM4NCBNMDIwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAATNYzWQDXV0NoNmR0hJPwJq
hjYOOS9z0B2Z7MQudxg5x3Vsib6N+tJkq8dljRq5o6K0bbh/kRVfoi9wfKhB03Yz
gkerrwRCH7Z9gU5nbBY+Y5+EtImq4yOB0n7JQgQxWemjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFKbZqzuHmTP/6Gj4i2GDbNCyuq+9MB8GA1Ud
IwQYMBaAFNPsxzplbszh2naaVvuc84ZtV+WBMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhNC5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhNC5hbWF6b250cnVzdC5jb20vcm9v
dGNhNC5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2E0LmFt
YXpvbnRydXN0LmNvbS9yb290Y2E0LmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAK
BggqhkjOPQQDAwNpADBmAjEA2zCG6x0xMlgSXWEGLN8+1XN+OCYF5vj0Z1jtVy+A
pdLlzuxNt9HBWn3hvqvO2W8KAjEApNdsZOCmk5uZBYiuCSBnDH3jyKhN6dWyuuHW
9Wj7SxKnOU5+wYWZA0BQAv1KT62i
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06