Amazon-RSA-2048-M04.cer: CN=Amazon RSA 2048 M04,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-2048-M04.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-RSA-2048-M04.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:4f:2a:95:2e:3e:d1:8a:58:bd:b8:5d:1b:c0:ce:5f:27
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 1
        Validity
            Not Before: Aug 23 22:26:35 2022 GMT
            Not After : Aug 23 22:26:35 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon RSA 2048 M04
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:cd:e9:55:1e:80:95:03:a9:e3:17:bb:ef:a1:5d:
                    78:f5:f2:7a:38:00:df:c9:98:c7:5a:2e:f7:f8:eb:
                    a5:5e:92:7e:7f:bf:a2:a0:4a:83:08:58:e9:e3:ec:
                    40:71:d0:6b:25:81:25:d0:67:bf:85:b3:df:ad:ea:
                    44:8e:17:52:1f:6c:c0:11:49:d7:54:e7:67:72:ea:
                    38:cb:c7:99:6a:b6:fa:5a:00:d1:03:ed:39:f5:dd:
                    27:67:c7:04:ba:c1:ae:78:2d:27:f1:81:d2:9e:68:
                    94:05:58:ad:26:60:bd:01:8f:d7:a4:5f:f1:d7:6d:
                    37:2c:44:12:16:26:dc:7b:a1:98:d8:be:bd:27:80:
                    ab:5b:4b:60:93:c0:bd:10:97:a2:74:e9:59:d4:83:
                    c5:8e:a1:bd:d9:b1:96:a4:d8:8b:cd:80:b4:15:d2:
                    7e:91:90:e7:c1:c7:33:48:70:d0:2e:9a:41:a9:20:
                    86:bc:16:8b:97:c6:b2:52:ce:ab:3a:62:98:d3:08:
                    b1:3e:dc:a9:ad:06:27:1e:89:7c:aa:89:aa:64:10:
                    36:99:4e:da:1f:27:f5:9b:05:26:00:68:c2:87:f4:
                    d6:9a:5d:a0:b0:16:83:a7:1a:30:e3:34:a2:6f:d5:
                    20:b2:9a:6b:7d:05:f5:6f:eb:f1:08:da:87:b9:6d:
                    19:59
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                1F:52:92:61:56:82:54:7F:81:66:D8:1D:3D:0A:AA:32:5C:87:DD:08
            X509v3 Authority Key Identifier: 
                keyid:84:18:CC:85:34:EC:BC:0C:94:94:2E:08:59:9C:C7:B2:10:4E:0A:08

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca1.amazontrust.com
                CA Issuers - URI:http://crt.rootca1.amazontrust.com/rootca1.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca1.amazontrust.com/rootca1.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha256WithRSAEncryption
         3e:d4:ee:54:b0:06:8d:b9:6d:e5:1f:32:6d:a4:d1:b0:06:76:
         5d:f5:01:18:16:dc:69:88:09:c8:69:5e:2a:02:99:c6:4b:d3:
         82:c3:96:4f:c2:27:bb:61:29:43:64:5e:72:c8:53:ec:16:15:
         02:d9:0f:6e:24:76:3f:09:15:75:6f:98:48:88:61:f4:fb:af:
         b0:e4:f8:0a:89:8d:4c:5a:e5:93:f1:50:1a:26:31:71:be:e8:
         4c:ed:af:de:7c:dd:93:23:0d:56:77:a5:82:97:a6:11:8a:cb:
         a7:8d:03:ab:48:ff:ae:9e:a0:bc:03:9e:34:24:dc:99:d4:93:
         84:de:35:6a:6a:dd:ce:64:11:a0:32:f8:a1:76:3d:b0:63:6d:
         c4:a7:07:ac:ac:a8:90:ce:41:f3:9a:f4:87:eb:b3:d5:5b:8c:
         9c:6c:fc:b4:f0:75:59:9c:1c:59:e4:da:e5:18:6f:5b:c1:74:
         77:7c:d4:da:cf:e7:3e:12:3e:9c:e4:09:f0:23:7a:a4:38:58:
         12:92:0d:d8:ef:97:1d:17:3e:a9:3b:fa:25:2b:e7:b7:02:ac:
         a0:01:cb:f4:5a:3c:e6:90:33:ee:06:3b:2c:b9:98:c2:1c:c0:
         b9:ea:81:f7:18:99:15:db:d0:e2:da:3e:69:ac:72:5b:c1:98:
         c6:d6:29:d4

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEXjCCA0agAwIBAgITB3MSTyqVLj7Rili9uF0bwM5fJzANBgkqhkiG9w0BAQsF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAxMB4XDTIyMDgyMzIyMjYzNVoXDTMwMDgyMzIyMjYzNVowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSAyMDQ4IE0wNDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM3pVR6A
lQOp4xe776FdePXyejgA38mYx1ou9/jrpV6Sfn+/oqBKgwhY6ePsQHHQayWBJdBn
v4Wz363qRI4XUh9swBFJ11TnZ3LqOMvHmWq2+loA0QPtOfXdJ2fHBLrBrngtJ/GB
0p5olAVYrSZgvQGP16Rf8ddtNyxEEhYm3HuhmNi+vSeAq1tLYJPAvRCXonTpWdSD
xY6hvdmxlqTYi82AtBXSfpGQ58HHM0hw0C6aQakghrwWi5fGslLOqzpimNMIsT7c
qa0GJx6JfKqJqmQQNplO2h8n9ZsFJgBowof01ppdoLAWg6caMOM0om/VILKaa30F
9W/r8Qjah7ltGVkCAwEAAaOCAVowggFWMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYD
VR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNV
HQ4EFgQUH1KSYVaCVH+BZtgdPQqqMlyH3QgwHwYDVR0jBBgwFoAUhBjMhTTsvAyU
lC4IWZzHshBOCggwewYIKwYBBQUHAQEEbzBtMC8GCCsGAQUFBzABhiNodHRwOi8v
b2NzcC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbTA6BggrBgEFBQcwAoYuaHR0cDov
L2NydC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbS9yb290Y2ExLmNlcjA/BgNVHR8E
ODA2MDSgMqAwhi5odHRwOi8vY3JsLnJvb3RjYTEuYW1hem9udHJ1c3QuY29tL3Jv
b3RjYTEuY3JsMBMGA1UdIAQMMAowCAYGZ4EMAQIBMA0GCSqGSIb3DQEBCwUAA4IB
AQA+1O5UsAaNuW3lHzJtpNGwBnZd9QEYFtxpiAnIaV4qApnGS9OCw5ZPwie7YSlD
ZF5yyFPsFhUC2Q9uJHY/CRV1b5hIiGH0+6+w5PgKiY1MWuWT8VAaJjFxvuhM7a/e
fN2TIw1Wd6WCl6YRisunjQOrSP+unqC8A540JNyZ1JOE3jVqat3OZBGgMvihdj2w
Y23EpwesrKiQzkHzmvSH67PVW4ycbPy08HVZnBxZ5NrlGG9bwXR3fNTaz+c+Ej6c
5AnwI3qkOFgSkg3Y75cdFz6pO/olK+e3AqygAcv0WjzmkDPuBjssuZjCHMC56oH3
GJkV29Di2j5prHJbwZjG1inU
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06