vrkrootc.crt: CN=VRK Gov. Root CA,OU=Varmennepalvelut,OU=Certification Authority Services,O=Vaestorekisterikeskus CA,ST=Finland,C=FI (Root Certificate, Expiring 2023-12-18) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is root certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://dvv.fineid.fi/api/v1/cas/701/certificate?name=/vrkrootc.crt" --output cert.crt

Download certificate through wget:

wget -q "https://dvv.fineid.fi/api/v1/cas/701/certificate?name=/vrkrootc.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 100000 (0x186a0)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=FI, ST=Finland, O=Vaestorekisterikeskus CA, OU=Certification Authority Services, OU=Varmennepalvelut, CN=VRK Gov. Root CA
        Validity
            Not Before: Dec 18 13:53:00 2002 GMT
            Not After : Dec 18 13:51:08 2023 GMT
        Subject: C=FI, ST=Finland, O=Vaestorekisterikeskus CA, OU=Certification Authority Services, OU=Varmennepalvelut, CN=VRK Gov. Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:b0:85:15:da:c8:03:37:d0:a3:46:37:6c:1b:1e:
                    96:30:c2:5a:85:12:67:23:f2:bb:9f:e7:8a:81:60:
                    27:f8:13:a9:3c:bc:f7:86:aa:aa:f4:f3:25:29:b4:
                    fe:75:ae:1e:81:86:8a:05:b2:1d:65:b2:38:e8:b4:
                    cc:28:9a:fb:17:36:f1:93:d5:79:ce:c1:83:8b:21:
                    4f:c3:0d:ad:41:df:78:9d:48:e3:1f:42:44:fc:3c:
                    6d:21:20:6b:ad:22:84:24:42:8f:17:4d:c2:50:1f:
                    64:cd:2d:39:22:56:88:fd:b2:63:9d:54:da:42:69:
                    c0:c8:4f:d7:18:e2:3e:c8:69:84:94:3d:2c:80:c6:
                    7c:ce:bd:d7:53:1f:eb:88:b9:a6:cb:bb:85:57:ef:
                    57:76:5d:0c:8b:d3:5e:12:41:9f:21:c0:39:f4:26:
                    6d:08:fa:38:b3:a1:77:b1:ee:16:d8:d0:68:da:b4:
                    98:a5:a0:65:46:4a:6b:8d:7e:aa:4d:60:b8:f8:c8:
                    0d:fc:71:3e:ee:39:87:81:b4:d9:f8:6e:90:ee:3f:
                    0e:61:d7:1d:2b:68:e6:2e:e1:42:44:26:78:2c:58:
                    f2:7d:16:7f:61:c0:49:24:2a:89:87:b6:5d:2f:29:
                    19:f8:a6:e7:8e:52:9e:41:4b:5a:0e:aa:b8:c2:66:
                    42:53
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            Netscape Cert Type: 
                SSL CA, S/MIME CA, Object Signing CA
            X509v3 Key Usage: critical
                Digital Signature, Non Repudiation, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                DB:E9:E1:9B:D2:D1:24:0B:FC:AB:E3:A0:67:EA:AE:9C:4B:77:F4:B0
    Signature Algorithm: sha1WithRSAEncryption
         ad:7d:48:0f:54:11:9e:58:ee:af:0d:9b:12:2f:21:a4:cd:9b:
         ba:84:47:e6:c9:25:55:23:e3:df:18:58:2a:2c:db:5e:f7:cd:
         54:f5:51:24:7b:62:67:e1:b1:1f:49:af:34:d0:eb:b1:cc:d9:
         a2:0d:52:7f:42:4b:88:60:97:cf:25:72:b7:4f:29:2d:62:9f:
         4f:a1:c0:55:57:56:0e:c4:68:97:91:1f:9c:64:c2:29:32:01:
         e9:d4:c8:da:b8:81:98:28:2e:18:c7:2c:fc:eb:9b:52:96:df:
         f4:c8:90:19:2d:23:f3:f1:bb:71:da:9e:85:23:bd:1a:ef:2e:
         e4:7a:79:b7:c3:9d:86:49:2d:63:b9:2d:74:cf:65:0f:32:66:
         89:df:3b:21:ee:29:6f:39:63:d9:15:c1:6e:f6:df:80:3e:50:
         78:19:8a:dd:03:a3:14:a5:37:a7:b5:2c:7c:b6:11:87:e7:05:
         f2:bc:b6:de:d4:ff:97:81:28:84:fe:fe:6c:46:85:10:41:9f:
         4d:75:8c:07:d4:99:67:6f:75:8a:6f:e4:50:92:f6:99:d5:10:
         b8:c4:a9:7b:f7:17:8d:4b:bf:d7:95:9f:09:dc:44:0f:1e:32:
         c3:c0:cf:d3:79:0d:e4:c7:3b:87:f0:90:34:88:21:62:49:92:
         04:04:1f:bc

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEGjCCAwKgAwIBAgIDAYagMA0GCSqGSIb3DQEBBQUAMIGjMQswCQYDVQQGEwJG
STEQMA4GA1UECBMHRmlubGFuZDEhMB8GA1UEChMYVmFlc3RvcmVraXN0ZXJpa2Vz
a3VzIENBMSkwJwYDVQQLEyBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSBTZXJ2aWNl
czEZMBcGA1UECxMQVmFybWVubmVwYWx2ZWx1dDEZMBcGA1UEAxMQVlJLIEdvdi4g
Um9vdCBDQTAeFw0wMjEyMTgxMzUzMDBaFw0yMzEyMTgxMzUxMDhaMIGjMQswCQYD
VQQGEwJGSTEQMA4GA1UECBMHRmlubGFuZDEhMB8GA1UEChMYVmFlc3RvcmVraXN0
ZXJpa2Vza3VzIENBMSkwJwYDVQQLEyBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSBT
ZXJ2aWNlczEZMBcGA1UECxMQVmFybWVubmVwYWx2ZWx1dDEZMBcGA1UEAxMQVlJL
IEdvdi4gUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALCF
FdrIAzfQo0Y3bBseljDCWoUSZyPyu5/nioFgJ/gTqTy894aqqvTzJSm0/nWuHoGG
igWyHWWyOOi0zCia+xc28ZPVec7Bg4shT8MNrUHfeJ1I4x9CRPw8bSEga60ihCRC
jxdNwlAfZM0tOSJWiP2yY51U2kJpwMhP1xjiPshphJQ9LIDGfM6911Mf64i5psu7
hVfvV3ZdDIvTXhJBnyHAOfQmbQj6OLOhd7HuFtjQaNq0mKWgZUZKa41+qk1guPjI
DfxxPu45h4G02fhukO4/DmHXHSto5i7hQkQmeCxY8n0Wf2HASSQqiYe2XS8pGfim
545SnkFLWg6quMJmQlMCAwEAAaNVMFMwDwYDVR0TAQH/BAUwAwEB/zARBglghkgB
hvhCAQEEBAMCAAcwDgYDVR0PAQH/BAQDAgHGMB0GA1UdDgQWBBTb6eGb0tEkC/yr
46Bn6q6cS3f0sDANBgkqhkiG9w0BAQUFAAOCAQEArX1ID1QRnljurw2bEi8hpM2b
uoRH5sklVSPj3xhYKizbXvfNVPVRJHtiZ+GxH0mvNNDrsczZog1Sf0JLiGCXzyVy
t08pLWKfT6HAVVdWDsRol5EfnGTCKTIB6dTI2riBmCguGMcs/OubUpbf9MiQGS0j
8/G7cdqehSO9Gu8u5Hp5t8OdhkktY7ktdM9lDzJmid87Ie4pbzlj2RXBbvbfgD5Q
eBmK3QOjFKU3p7UsfLYRh+cF8ry23tT/l4EohP7+bEaFEEGfTXWMB9SZZ291im/k
UJL2mdUQuMSpe/cXjUu/15WfCdxEDx4yw8DP03kN5Mc7h/CQNIghYkmSBAQfvA==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06