SectigoECCDomainValidationSecureServerCA.crt: CN=Sectigo ECC Domain Validation Secure Server CA,O=Sectigo Limited,L=Salford,ST=Greater Manchester,C=GB

Page content

CA Certificate Basic Information

This certificate is intermediate certificate used for the issuance of other certificates.

  • Certificate download URL: http://crt.sectigo.com/SectigoECCDomainValidationSecureServerCA.crt (DER format)
  • Serial number: 323523223200994243259439853290236540189
  • SHA-1 Fingerprint: e84990cb9bf8e3ab0bcae8a649cb30fe4dc4d767
  • SHA-1 Fingerprint: e8:49:90:cb:9b:f8:e3:ab:0b:ca:e8:a6:49:cb:30:fe:4d:c4:d7:67
  • SHA-256 Fingerprint: 61e97375e9f6da982ff5c19e2f94e66c4e35b6837ce3b914d2245c7f5f65825f
  • SHA-256 Fingerprint: 61:e9:73:75:e9:f6:da:98:2f:f5:c1:9e:2f:94:e6:6c:4e:35:b6:83:7c:e3:b9:14:d2:24:5c:7f:5f:65:82:5f
  • Signature hash algorithm: sha384
  • Subject: CN=Sectigo ECC Domain Validation Secure Server CA,O=Sectigo Limited,L=Salford,ST=Greater Manchester,C=GB
  • Not valid before: 2018-11-02 00:00:00
  • Not valid after: 2030-12-31 23:59:59
  • Issuer:

Download certificate through curl:

curl -sSL http://crt.sectigo.com/SectigoECCDomainValidationSecureServerCA.crt --output cert.crt

Download certificate through wget:

wget -q http://crt.sectigo.com/SectigoECCDomainValidationSecureServerCA.crt --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            f3:64:4e:6b:6e:00:50:23:7e:09:46:bd:7b:e1:f5:1d
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
        Validity
            Not Before: Nov  2 00:00:00 2018 GMT
            Not After : Dec 31 23:59:59 2030 GMT
        Subject: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:79:18:93:ca:9f:6d:9e:6c:57:00:23:05:37:0b:
                    5f:0f:58:5a:c4:de:7f:55:a3:e9:1e:d6:d9:25:0a:
                    88:a0:20:4a:1d:7a:4f:05:30:8a:63:49:13:8c:64:
                    21:07:95:fd:3a:35:e1:4a:ce:90:f0:18:f7:3d:af:
                    68:a6:fb:d4:48
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:3A:E1:09:86:D4:CF:19:C2:96:76:74:49:76:DC:E0:35:C6:63:63:9A

            X509v3 Subject Key Identifier: 
                F6:85:0A:3B:11:86:E1:04:7D:0E:AA:0B:2C:D2:EE:CC:64:7B:7B:AE
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                Policy: 2.23.140.1.2.1

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.usertrust.com/USERTrustECCCertificationAuthority.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.usertrust.com/USERTrustECCAddTrustCA.crt
                OCSP - URI:http://ocsp.usertrust.com

    Signature Algorithm: ecdsa-with-SHA384
         30:65:02:30:4b:e7:c7:71:5c:b1:5c:09:6d:9a:42:60:5f:73:
         e9:f0:d6:26:d4:b5:51:54:6c:71:2d:1c:85:60:4d:28:f1:4d:
         a6:f0:ca:76:b7:4a:45:ef:a8:02:4a:f6:8d:4f:ae:6e:02:31:
         00:e0:e1:79:2a:f6:5e:17:00:ee:8c:fd:1e:67:9d:19:d3:21:
         96:b7:7d:e1:3a:0a:15:b6:65:fb:f3:a7:14:5c:ea:9e:f3:a1:
         72:31:ef:0a:51:02:11:07:0a:99:cf:1f:98

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDqDCCAy6gAwIBAgIRAPNkTmtuAFAjfglGvXvh9R0wCgYIKoZIzj0EAwMwgYgx
CzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpOZXcgSmVyc2V5MRQwEgYDVQQHEwtKZXJz
ZXkgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMS4wLAYDVQQD
EyVVU0VSVHJ1c3QgRUNDIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MTEw
MjAwMDAwMFoXDTMwMTIzMTIzNTk1OVowgY8xCzAJBgNVBAYTAkdCMRswGQYDVQQI
ExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZvcmQxGDAWBgNVBAoT
D1NlY3RpZ28gTGltaXRlZDE3MDUGA1UEAxMuU2VjdGlnbyBFQ0MgRG9tYWluIFZh
bGlkYXRpb24gU2VjdXJlIFNlcnZlciBDQTBZMBMGByqGSM49AgEGCCqGSM49AwEH
A0IABHkYk8qfbZ5sVwAjBTcLXw9YWsTef1Wj6R7W2SUKiKAgSh16TwUwimNJE4xk
IQeV/To14UrOkPAY9z2vaKb71EijggFuMIIBajAfBgNVHSMEGDAWgBQ64QmG1M8Z
wpZ2dEl23OA1xmNjmjAdBgNVHQ4EFgQU9oUKOxGG4QR9DqoLLNLuzGR7e64wDgYD
VR0PAQH/BAQDAgGGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0lBBYwFAYIKwYB
BQUHAwEGCCsGAQUFBwMCMBsGA1UdIAQUMBIwBgYEVR0gADAIBgZngQwBAgEwUAYD
VR0fBEkwRzBFoEOgQYY/aHR0cDovL2NybC51c2VydHJ1c3QuY29tL1VTRVJUcnVz
dEVDQ0NlcnRpZmljYXRpb25BdXRob3JpdHkuY3JsMHYGCCsGAQUFBwEBBGowaDA/
BggrBgEFBQcwAoYzaHR0cDovL2NydC51c2VydHJ1c3QuY29tL1VTRVJUcnVzdEVD
Q0FkZFRydXN0Q0EuY3J0MCUGCCsGAQUFBzABhhlodHRwOi8vb2NzcC51c2VydHJ1
c3QuY29tMAoGCCqGSM49BAMDA2gAMGUCMEvnx3FcsVwJbZpCYF9z6fDWJtS1UVRs
cS0chWBNKPFNpvDKdrdKRe+oAkr2jU+ubgIxAODheSr2XhcA7oz9HmedGdMhlrd9
4ToKFbZl+/OnFFzqnvOhcjHvClECEQcKmc8fmA==
-----END CERTIFICATE-----

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: a651bdd 2022-03-26