G2-RootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Intermediate Certificate, Expiring 2037-12-31) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/G2-RootCA2.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/G2-RootCA2.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7f:94:4a:2f:99:53:9d:50:5a:ed:f2:de:3e:d8:57:01:e6:ca
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2
        Validity
            Not Before: May 25 12:00:00 2015 GMT
            Not After : Dec 31 01:00:00 2037 GMT
        Subject: C=US, O=Amazon, CN=Amazon Root CA 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:ad:96:9f:2d:9c:4a:4c:4a:81:79:51:99:ec:8a:
                    cb:6b:60:51:13:bc:4d:6d:06:fc:b0:08:8d:dd:19:
                    10:6a:c7:26:0c:35:d8:c0:6f:20:84:e9:94:b1:9b:
                    85:03:c3:5b:db:4a:e8:c8:f8:90:76:d9:5b:4f:e3:
                    4c:e8:06:36:4d:cc:9a:ac:3d:0c:90:2b:92:d4:06:
                    19:60:ac:37:44:79:85:81:82:ad:5a:37:e0:0d:cc:
                    9d:a6:4c:52:76:ea:43:9d:b7:04:d1:50:f6:55:e0:
                    d5:d2:a6:49:85:e9:37:e9:ca:7e:ae:5c:95:4d:48:
                    9a:3f:ae:20:5a:6d:88:95:d9:34:b8:52:1a:43:90:
                    b0:bf:6c:05:b9:b6:78:b7:ea:d0:e4:3a:3c:12:53:
                    62:ff:4a:f2:7b:be:35:05:a9:12:34:e3:f3:64:74:
                    62:2c:3d:00:49:5a:28:fe:32:44:bb:87:dd:65:27:
                    02:71:3b:da:4a:f7:1f:da:cd:f7:21:55:90:4f:0f:
                    ec:ae:82:e1:9f:6b:d9:45:d3:bb:f0:5f:87:ed:3c:
                    2c:39:86:da:3f:de:ec:72:55:eb:79:a3:ad:db:dd:
                    7c:b0:ba:1c:ce:fc:de:4f:35:76:cf:0f:f8:78:1f:
                    6a:36:51:46:27:61:5b:e9:9e:cf:f0:a2:55:7d:7c:
                    25:8a:6f:2f:b4:c5:cf:84:2e:2b:fd:0d:51:10:6c:
                    fb:5f:1b:bc:1b:7e:c5:ae:3b:98:01:31:92:ff:0b:
                    57:f4:9a:b2:b9:57:e9:ab:ef:0d:76:d1:f0:ee:f4:
                    ce:86:a7:e0:6e:e9:b4:69:a1:df:69:f6:33:c6:69:
                    2e:97:13:9e:a5:87:b0:57:10:81:37:c9:53:b3:bb:
                    7f:f6:92:d1:9c:d0:18:f4:92:6e:da:83:4f:a6:63:
                    99:4c:a5:fb:5e:ef:21:64:7a:20:5f:6c:64:85:15:
                    cb:37:e9:62:0c:0b:2a:16:dc:01:2e:32:da:3e:4b:
                    f5:9e:3a:f6:17:40:94:ef:9e:91:08:86:fa:be:63:
                    a8:5a:33:ec:cb:74:43:95:f9:6c:69:52:36:c7:29:
                    6f:fc:55:03:5c:1f:fb:9f:bd:47:eb:e7:49:47:95:
                    0b:4e:89:22:09:49:e0:f5:61:1e:f1:bf:2e:8a:72:
                    6e:80:59:ff:57:3a:f9:75:32:a3:4e:5f:ec:ed:28:
                    62:d9:4d:73:f2:cc:81:17:60:ed:cd:eb:dc:db:a7:
                    ca:c5:7e:02:bd:f2:54:08:54:fd:b4:2d:09:2c:17:
                    54:4a:98:d1:54:e1:51:67:08:d2:ed:6e:7e:6f:3f:
                    d2:2d:81:59:29:66:cb:90:39:95:11:1e:74:27:fe:
                    dd:eb:af
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52
            X509v3 Authority Key Identifier: 
                keyid:9C:5F:00:DF:AA:01:D7:30:2B:38:88:A2:B8:6D:4A:9C:F2:11:91:83

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootg2.amazontrust.com
                CA Issuers - URI:http://crt.rootg2.amazontrust.com/rootg2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootg2.amazontrust.com/rootg2.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

    Signature Algorithm: sha256WithRSAEncryption
         40:18:8c:a6:a1:0b:9f:b5:5a:d4:ae:69:de:9b:c6:bd:22:a3:
         3b:88:23:7e:55:d7:6a:f4:d0:3e:7d:72:6f:f3:58:62:c7:4a:
         ca:0e:72:7e:4d:2b:5b:cc:fb:4c:e9:52:8d:a7:a5:00:06:e4:
         eb:e6:b0:12:ad:05:00:19:56:a2:21:51:d0:c5:5b:4e:82:42:
         1a:ff:3c:44:71:70:5c:22:35:ad:c5:ce:32:74:79:2d:77:ea:
         9b:f4:18:c2:ca:0e:63:17:76:98:d6:35:40:1c:44:53:1b:80:
         79:4d:34:18:e8:4b:14:cd:f5:27:5b:0f:e9:2b:59:68:c0:c3:
         5c:2c:0d:fa:7c:07:d9:59:15:f3:86:5f:83:a9:f4:5d:56:99:
         8f:34:a3:e2:b8:81:38:d7:14:4a:b2:08:37:eb:be:b1:f7:f8:
         fe:9d:23:6b:68:fc:b4:c1:74:07:b3:5e:0d:37:dc:4b:4b:53:
         0e:bd:6a:d0:8b:b5:df:2b:f1:32:0c:00:4d:88:18:5b:79:ac:
         78:38:b0:41:ba:35:83:d7:90:ea:d0:aa:ce:89:2d:a1:71:89:
         b2:aa:eb:af:53:7c:19:5c:96:81:8b:73:cd:1d:1b:de:ab:ca:
         3a:4d:23:31:14:b5:3e:44:c9:ce:8a:22:5d:59:fc:8d:3d:88:
         1c:44:59:03

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFkjCCBHqgAwIBAgITBn+USi+ZU51QWu3y3j7YVwHmyjANBgkqhkiG9w0BAQsF
ADCBmDELMAkGA1UEBhMCVVMxEDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNj
b3R0c2RhbGUxJTAjBgNVBAoTHFN0YXJmaWVsZCBUZWNobm9sb2dpZXMsIEluYy4x
OzA5BgNVBAMTMlN0YXJmaWVsZCBTZXJ2aWNlcyBSb290IENlcnRpZmljYXRlIEF1
dGhvcml0eSAtIEcyMB4XDTE1MDUyNTEyMDAwMFoXDTM3MTIzMTAxMDAwMFowOTEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEZMBcGA1UEAxMQQW1hem9uIFJv
b3QgQ0EgMjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAK2Wny2cSkxK
gXlRmeyKy2tgURO8TW0G/LAIjd0ZEGrHJgw12MBvIITplLGbhQPDW9tK6Mj4kHbZ
W0/jTOgGNk3Mmqw9DJArktQGGWCsN0R5hYGCrVo34A3MnaZMUnbqQ523BNFQ9lXg
1dKmSYXpN+nKfq5clU1Imj+uIFptiJXZNLhSGkOQsL9sBbm2eLfq0OQ6PBJTYv9K
8nu+NQWpEjTj82R0Yiw9AElaKP4yRLuH3WUnAnE72kr3H9rN9yFVkE8P7K6C4Z9r
2UXTu/Bfh+08LDmG2j/e7HJV63mjrdvdfLC6HM783k81ds8P+HgfajZRRidhW+me
z/CiVX18JYpvL7TFz4QuK/0NURBs+18bvBt+xa47mAExkv8LV/SasrlX6avvDXbR
8O70zoan4G7ptGmh32n2M8ZpLpcTnqWHsFcQgTfJU7O7f/aS0ZzQGPSSbtqDT6Zj
mUyl+17vIWR6IF9sZIUVyzfpYgwLKhbcAS4y2j5L9Z469hdAlO+ekQiG+r5jqFoz
7Mt0Q5X5bGlSNscpb/xVA1wf+5+9R+vnSUeVC06JIglJ4PVhHvG/LopyboBZ/1c6
+XUyo05f7O0oYtlNc/LMgRdg7c3r3NunysV+Ar3yVAhU/bQtCSwXVEqY0VThUWcI
0u1ufm8/0i2BWSlmy5A5lREedCf+3euvAgMBAAGjggExMIIBLTAPBgNVHRMBAf8E
BTADAQH/MA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQUsAzwTDD0BVgCSP0z5VKv
S4TjZlIwHwYDVR0jBBgwFoAUnF8A36oB1zArOIiiuG1KnPIRkYMweAYIKwYBBQUH
AQEEbDBqMC4GCCsGAQUFBzABhiJodHRwOi8vb2NzcC5yb290ZzIuYW1hem9udHJ1
c3QuY29tMDgGCCsGAQUFBzAChixodHRwOi8vY3J0LnJvb3RnMi5hbWF6b250cnVz
dC5jb20vcm9vdGcyLmNlcjA9BgNVHR8ENjA0MDKgMKAuhixodHRwOi8vY3JsLnJv
b3RnMi5hbWF6b250cnVzdC5jb20vcm9vdGcyLmNybDARBgNVHSAECjAIMAYGBFUd
IAAwDQYJKoZIhvcNAQELBQADggEBAEAYjKahC5+1WtSuad6bxr0iozuII35V12r0
0D59cm/zWGLHSsoOcn5NK1vM+0zpUo2npQAG5OvmsBKtBQAZVqIhUdDFW06CQhr/
PERxcFwiNa3FzjJ0eS136pv0GMLKDmMXdpjWNUAcRFMbgHlNNBjoSxTN9SdbD+kr
WWjAw1wsDfp8B9lZFfOGX4Op9F1WmY80o+K4gTjXFEqyCDfrvrH3+P6dI2to/LTB
dAezXg033EtLUw69atCLtd8r8TIMAE2IGFt5rHg4sEG6NYPXkOrQqs6JLaFxibKq
669TfBlcloGLc80dG96ryjpNIzEUtT5Eyc6KIl1Z/I09iBxEWQM=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06