gtsy2.der: CN=GTS Y2,O=Google Trust Services LLC,C=US (Intermediate Certificate, Expiring 2028-11-01) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://pki.goog/repo/certs/gtsy2.der" --output cert.crt

Download certificate through wget:

wget -q "https://pki.goog/repo/certs/gtsy2.der" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            01:f0:9c:5b:0e:a2:29:37:cf:9e:e4:41:6c
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Google Trust Services LLC, CN=GTS Root R2
        Validity
            Not Before: Nov  1 00:00:42 2018 GMT
            Not After : Nov  1 00:00:42 2028 GMT
        Subject: C=US, O=Google Trust Services LLC, CN=GTS Y2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:a8:1f:57:6c:73:2a:e2:ca:10:99:1a:4e:54:5f:
                    42:b2:72:0f:0b:6b:99:dc:84:d1:d1:04:51:78:12:
                    e1:39:8d:ec:5b:08:de:05:cb:6a:a8:c7:28:70:dd:
                    33:83:ed:f4:73:8f:94:54:07:0e:74:0c:47:8c:4a:
                    55:6a:46:eb:b5:ca:9f:17:bd:70:ae:16:ae:f2:8e:
                    ac:9f:ec:bc:32:b7:58:02:da:c6:ad:8c:e7:b3:6e:
                    8a:11:35:fc:34:8c:f1:27:2f:ef:df:5c:09:39:09:
                    d6:fd:66:44:8b:37:ac:e0:97:ce:ff:53:28:de:a5:
                    80:89:aa:1c:b6:c8:87:98:be:4f:1b:cc:50:91:d3:
                    a1:3c:d7:47:bb:a2:9c:80:ed:08:b0:9f:41:08:2b:
                    9f:77:d4:e9:24:c6:f4:12:73:b5:58:ad:d6:64:b4:
                    1d:82:65:67:cb:91:64:12:aa:74:17:3e:53:81:02:
                    9e:90:7c:9a:8e:76:ee:8d:fd:53:d3:d0:06:cd:34:
                    20:3b:40:6d:cf:5e:56:2f:da:64:30:00:cc:58:ac:
                    18:b5:b1:2e:ac:96:87:ac:08:1e:8c:c1:d6:0b:b2:
                    a3:6a:a1:f7:5e:55:66:14:c2:6c:de:b0:c3:21:0c:
                    72:4d:12:c1:3e:a4:4b:6a:25:24:cf:1b:c1:06:79:
                    ab:97
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Subject Key Identifier: 
                6D:65:A2:D7:F3:50:8F:09:78:65:B1:62:A2:BE:3C:ED:BB:46:3A:35
            X509v3 Authority Key Identifier: 
                keyid:BB:FF:CA:8E:23:9F:4F:99:CA:DB:E2:68:A6:A5:15:27:17:1E:D9:0E

            Authority Information Access: 
                OCSP - URI:http://ocsp.pki.goog/gtsr2
                CA Issuers - URI:http://pki.goog/gtsr2/gtsr2.crt

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.pki.goog/gtsr2/gtsr2.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
                Policy: 2.23.140.1.2.2

    Signature Algorithm: sha256WithRSAEncryption
         10:61:c1:1c:8e:76:02:33:d9:68:6c:21:23:64:b5:6a:a0:fe:
         04:dd:de:e2:42:b9:ca:06:1d:5f:87:ac:93:61:72:b7:70:bd:
         e9:56:d6:1a:e3:1a:3f:99:db:6f:ca:1c:fb:a5:e5:28:17:f2:
         3b:68:9a:e5:8d:b1:a5:92:a2:27:59:db:cc:3b:c5:b7:15:4d:
         63:bd:95:0e:91:04:74:03:41:78:e6:cd:a2:fa:85:c6:76:60:
         ec:6e:27:ee:b4:bd:ac:5e:14:05:c0:77:22:bf:a2:26:2d:c6:
         d6:91:22:bf:58:c9:1d:49:40:3e:d1:0f:b0:d3:8e:0f:22:a9:
         9b:7a:a1:c3:7c:db:60:47:eb:f3:e9:ad:0a:9f:63:cd:c4:dc:
         07:93:6a:2c:45:1f:7d:8f:60:86:22:89:a5:0e:1e:b9:11:54:
         64:1c:65:7d:d7:0d:8f:59:2f:c9:02:da:1c:0c:f6:ca:0c:1d:
         ad:df:4e:c4:c1:de:ca:ea:7a:7e:45:eb:95:e6:67:7c:27:d4:
         e5:82:63:57:17:8b:ee:47:4e:e4:07:b2:cd:5b:80:06:4a:cc:
         06:dc:22:62:1c:58:05:b0:d5:4f:70:2b:dd:e9:b3:d9:23:cc:
         57:4d:53:0b:c9:97:10:dc:82:08:a7:99:8f:29:08:a1:9b:23:
         06:43:7b:d5:cd:f4:9c:7a:0b:95:e7:e5:13:39:d1:c9:6b:ca:
         e8:1a:4e:92:aa:5e:92:0d:08:f0:f0:ee:2a:0d:c6:28:06:ef:
         43:44:90:75:b0:d8:c0:71:dc:d7:69:04:e9:f3:b0:0f:11:e7:
         da:08:0e:fb:b7:9f:2c:ed:08:78:6b:da:e1:9a:56:c7:a4:fc:
         5c:d1:4d:14:9f:f6:6a:4c:0e:23:c4:ad:e3:39:4d:12:66:6b:
         eb:70:d0:d9:53:f9:a5:0f:5c:e1:f4:d7:8b:ab:3d:93:65:3c:
         eb:21:e6:4e:a1:64:e5:43:86:1e:9d:d6:f1:52:b8:f7:59:d9:
         c0:ca:b8:ba:66:c0:a5:9f:ca:86:5a:35:5b:99:09:73:1e:4e:
         f7:c1:5f:9c:d1:b3:26:9f:24:75:30:9d:19:34:26:08:fb:14:
         f9:41:33:8e:8b:0d:c3:a3:49:16:15:23:66:5b:08:de:b4:30:
         7b:a5:be:57:01:34:f4:ce:89:6f:34:30:6b:cc:8c:be:f7:68:
         cb:e6:d4:9c:40:b4:d0:c1:67:ae:3f:04:ac:9c:1c:8e:e2:e7:
         15:32:6e:65:57:d4:95:9c:3e:9e:b6:ee:4a:36:a3:47:75:eb:
         1f:af:c5:c4:80:ca:e2:67:89:ca:be:28:ea:78:2c:fe:75:1a:
         79:17:de:1b:d5:d2:c7:9a

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFUzCCAzugAwIBAgINAfCcWw6iKTfPnuRBbDANBgkqhkiG9w0BAQsFADBHMQsw
CQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEU
MBIGA1UEAxMLR1RTIFJvb3QgUjIwHhcNMTgxMTAxMDAwMDQyWhcNMjgxMTAxMDAw
MDQyWjBCMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZp
Y2VzIExMQzEPMA0GA1UEAxMGR1RTIFkyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEAqB9XbHMq4soQmRpOVF9CsnIPC2uZ3ITR0QRReBLhOY3sWwjeBctq
qMcocN0zg+30c4+UVAcOdAxHjEpVakbrtcqfF71wrhau8o6sn+y8MrdYAtrGrYzn
s26KETX8NIzxJy/v31wJOQnW/WZEizes4JfO/1Mo3qWAiaoctsiHmL5PG8xQkdOh
PNdHu6KcgO0IsJ9BCCufd9TpJMb0EnO1WK3WZLQdgmVny5FkEqp0Fz5TgQKekHya
jnbujf1T09AGzTQgO0Btz15WL9pkMADMWKwYtbEurJaHrAgejMHWC7KjaqH3XlVm
FMJs3rDDIQxyTRLBPqRLaiUkzxvBBnmrlwIDAQABo4IBQTCCAT0wDgYDVR0PAQH/
BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8E
CDAGAQH/AgEAMB0GA1UdDgQWBBRtZaLX81CPCXhlsWKivjztu0Y6NTAfBgNVHSME
GDAWgBS7/8qOI59Pmcrb4mimpRUnFx7ZDjBjBggrBgEFBQcBAQRXMFUwJgYIKwYB
BQUHMAGGGmh0dHA6Ly9vY3NwLnBraS5nb29nL2d0c3IyMCsGCCsGAQUFBzAChh9o
dHRwOi8vcGtpLmdvb2cvZ3RzcjIvZ3RzcjIuY3J0MDQGA1UdHwQtMCswKaAnoCWG
I2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjIvZ3RzcjIuY3JsMB0GA1UdIAQWMBQw
CAYGZ4EMAQIBMAgGBmeBDAECAjANBgkqhkiG9w0BAQsFAAOCAgEAEGHBHI52AjPZ
aGwhI2S1aqD+BN3e4kK5ygYdX4esk2Fyt3C96VbWGuMaP5nbb8oc+6XlKBfyO2ia
5Y2xpZKiJ1nbzDvFtxVNY72VDpEEdANBeObNovqFxnZg7G4n7rS9rF4UBcB3Ir+i
Ji3G1pEiv1jJHUlAPtEPsNOODyKpm3qhw3zbYEfr8+mtCp9jzcTcB5NqLEUffY9g
hiKJpQ4euRFUZBxlfdcNj1kvyQLaHAz2ygwdrd9OxMHeyup6fkXrleZnfCfU5YJj
VxeL7kdO5AeyzVuABkrMBtwiYhxYBbDVT3Ar3emz2SPMV01TC8mXENyCCKeZjykI
oZsjBkN71c30nHoLleflEznRyWvK6BpOkqpekg0I8PDuKg3GKAbvQ0SQdbDYwHHc
12kE6fOwDxHn2ggO+7efLO0IeGva4ZpWx6T8XNFNFJ/2akwOI8St4zlNEmZr63DQ
2VP5pQ9c4fTXi6s9k2U86yHmTqFk5UOGHp3W8VK491nZwMq4umbApZ/Khlo1W5kJ
cx5O98FfnNGzJp8kdTCdGTQmCPsU+UEzjosNw6NJFhUjZlsI3rQwe6W+VwE09M6J
bzQwa8yMvvdoy+bUnEC00MFnrj8ErJwcjuLnFTJuZVfUlZw+nrbuSjajR3XrH6/F
xIDK4meJyr4o6ngs/nUaeRfeG9XSx5o=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06