lets-encrypt-r4-cross-signed.der: CN=R4,O=Let's Encrypt,C=US (Intermediate Certificate, Expiring 2021-09-29) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://letsencrypt.org/certs/lets-encrypt-r4-cross-signed.der" --output cert.crt

Download certificate through wget:

wget -q "https://letsencrypt.org/certs/lets-encrypt-r4-cross-signed.der" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            40:01:75:04:83:25:3b:e4:64:b7:77:b1:23:d0:8a:82
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: O=Digital Signature Trust Co., CN=DST Root CA X3
        Validity
            Not Before: Oct  7 19:21:45 2020 GMT
            Not After : Sep 29 19:21:45 2021 GMT
        Subject: C=US, O=Let's Encrypt, CN=R4
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:b3:28:dc:77:29:d3:e7:91:be:f3:b7:0a:00:c7:
                    fb:f2:55:0b:25:22:63:53:36:af:e9:08:20:df:0d:
                    af:28:3e:cd:c6:ab:57:b6:9d:a4:25:19:a5:d2:32:
                    6d:49:a6:08:b9:c7:2f:a1:9b:93:c5:20:40:6b:84:
                    31:20:a2:8e:30:60:25:60:ef:d9:1a:89:3f:1f:69:
                    71:b2:da:ea:3f:73:41:c4:90:6f:66:fd:7d:9e:58:
                    d8:77:cf:cd:59:75:44:c9:a1:0a:7b:9f:3f:1b:0e:
                    3a:66:6f:b6:75:cf:8b:cb:af:9d:c0:70:c5:ff:d2:
                    82:0a:af:5d:cd:e2:e8:9c:85:94:a4:e6:00:35:e8:
                    7e:4e:39:81:c7:21:89:60:77:ea:1d:96:f2:8b:83:
                    7b:47:c4:6d:32:c0:52:7e:23:1e:45:b5:71:ee:a3:
                    ef:17:c2:03:a9:93:89:dd:f5:9f:db:ba:f1:da:e0:
                    7e:97:87:71:81:1e:1a:82:56:e4:3e:7c:18:a2:08:
                    e5:16:5f:a8:fa:a8:e0:48:51:4d:18:14:a0:0c:a3:
                    e5:b6:ca:b3:b5:55:12:6b:72:c7:5a:7f:3b:8c:f9:
                    e7:d9:d1:8e:12:4d:33:33:03:2a:f1:13:e1:42:3c:
                    c2:2e:59:60:2e:6d:e0:07:47:33:65:df:d2:67:ca:
                    4d:85
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            Authority Information Access: 
                CA Issuers - URI:http://apps.identrust.com/roots/dstrootcax3.p7c

            X509v3 Authority Key Identifier: 
                keyid:C4:A7:B1:A4:7B:2C:71:FA:DB:E1:4B:90:75:FF:C4:15:60:85:89:10

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
                Policy: 1.3.6.1.4.1.44947.1.1.1
                  CPS: http://cps.root-x1.letsencrypt.org

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.identrust.com/DSTROOTCAX3CRL.crl

            X509v3 Subject Key Identifier: 
                36:9D:3E:E0:B1:40:F6:27:2C:7C:BF:8D:9D:31:8A:F6:54:A6:46:26
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
    Signature Algorithm: sha256WithRSAEncryption
         37:80:a9:80:f9:8a:d8:2e:69:ab:f4:5d:57:d8:04:75:67:2f:
         3e:73:df:4f:d4:e8:b9:ca:c0:31:37:27:ff:fc:32:58:15:85:
         db:01:b8:86:f3:c1:43:1c:6e:a8:f1:02:66:c8:b8:9c:b4:38:
         e5:52:69:c8:2d:4d:0d:dd:06:a8:64:08:32:a3:5d:0b:83:78:
         4c:b0:ed:77:b6:21:cb:cb:f9:26:c7:c4:31:46:db:eb:15:b8:
         b0:a7:9e:78:ac:b7:69:f3:a4:7a:5e:b4:5e:0d:7f:ee:77:52:
         9a:9a:62:1e:a7:61:f9:37:49:30:bd:61:a6:d4:60:77:11:a2:
         07:c2:cc:a4:7b:96:fe:83:3c:6a:47:f2:b7:84:e4:06:10:3c:
         f9:6b:bc:30:ce:9d:94:9c:89:ee:71:c1:56:71:14:15:0e:0d:
         8b:e1:b3:34:2f:e9:41:22:f6:f9:8f:4c:ab:81:c7:22:4d:99:
         17:2d:16:07:c2:ac:57:07:5e:36:b1:11:3c:bf:8b:8e:18:4b:
         75:ed:44:b7:46:8b:f6:79:6f:e0:2a:b0:5c:73:0b:d8:b3:e0:
         93:7f:23:fd:69:65:6d:0f:fc:1d:17:76:56:90:7e:25:6e:99:
         f0:93:61:72:7b:81:c0:04:c7:30:27:89:54:21:5a:a6:86:6c:
         3d:f4:10:e9

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEZTCCA02gAwIBAgIQQAF1BIMlO+Rkt3exI9CKgjANBgkqhkiG9w0BAQsFADA/
MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
DkRTVCBSb290IENBIFgzMB4XDTIwMTAwNzE5MjE0NVoXDTIxMDkyOTE5MjE0NVow
MjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUxldCdzIEVuY3J5cHQxCzAJBgNVBAMT
AlI0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsyjcdynT55G+87cK
AMf78lULJSJjUzav6Qgg3w2vKD7NxqtXtp2kJRml0jJtSaYIuccvoZuTxSBAa4Qx
IKKOMGAlYO/ZGok/H2lxstrqP3NBxJBvZv19nljYd8/NWXVEyaEKe58/Gw46Zm+2
dc+Ly6+dwHDF/9KCCq9dzeLonIWUpOYANeh+TjmBxyGJYHfqHZbyi4N7R8RtMsBS
fiMeRbVx7qPvF8IDqZOJ3fWf27rx2uB+l4dxgR4aglbkPnwYogjlFl+o+qjgSFFN
GBSgDKPltsqztVUSa3LHWn87jPnn2dGOEk0zMwMq8RPhQjzCLllgLm3gB0czZd/S
Z8pNhQIDAQABo4IBaDCCAWQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8E
BAMCAYYwSwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5p
ZGVudHJ1c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTE
p7Gkeyxx+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEE
AYLfEwEBATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2Vu
Y3J5cHQub3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0
LmNvbS9EU1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFDadPuCxQPYnLHy/jZ0x
ivZUpkYmMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjANBgkqhkiG9w0B
AQsFAAOCAQEAN4CpgPmK2C5pq/RdV9gEdWcvPnPfT9ToucrAMTcn//wyWBWF2wG4
hvPBQxxuqPECZsi4nLQ45VJpyC1NDd0GqGQIMqNdC4N4TLDtd7Yhy8v5JsfEMUbb
6xW4sKeeeKy3afOkel60Xg1/7ndSmppiHqdh+TdJML1hptRgdxGiB8LMpHuW/oM8
akfyt4TkBhA8+Wu8MM6dlJyJ7nHBVnEUFQ4Ni+GzNC/pQSL2+Y9Mq4HHIk2ZFy0W
B8KsVwdeNrERPL+LjhhLde1Et0aL9nlv4CqwXHML2LPgk38j/WllbQ/8HRd2VpB+
JW6Z8JNhcnuBwATHMCeJVCFapoZsPfQQ6Q==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06