G2-ServerCA0A.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Intermediate Certificate, Expiring 2025-10-19) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/G2-ServerCA0A.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/G2-ServerCA0A.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7f:94:57:4b:b7:07:5d:3e:48:96:5c:78:32:24:aa:75:4f:ed
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2
        Validity
            Not Before: Oct 22 00:00:00 2015 GMT
            Not After : Oct 19 00:00:00 2025 GMT
        Subject: C=US, O=Amazon, OU=Server CA 0A, CN=Amazon
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:a1:85:31:dc:31:7f:96:71:22:a2:a3:fd:95:27:
                    c3:74:70:2a:5d:ad:47:f8:a0:1f:55:f9:fc:76:74:
                    5c:54:f9:78:11:be:cc:e1:81:e3:dc:34:ab:f9:77:
                    b6:b4:a8:e5:85:f6:e2:e6:62:2c:74:04:fd:f8:c5:
                    8b:a3:35:ed:13:4c:60:63:39:d8:c2:5a:64:cb:8b:
                    d9:9b:e6:03:bc:43:17:b7:79:a3:d9:14:75:f6:25:
                    b0:3e:19:ea:b2:2e:4b:f7:fc:3b:78:4a:48:20:01:
                    95:f5:3e:fa:1a:3e:50:b2:b4:70:96:ee:a0:dd:a3:
                    ec:9c:ba:ac:2b:ad:f9:74:7d:87:c9:ac:40:3e:3b:
                    9c:7c:bf:eb:87:52:60:b9:00:f1:79:bd:81:3c:5d:
                    d1:a1:1a:b6:b9:25:1a:2d:d9:36:37:3f:e2:a1:d4:
                    07:ee:25:63:cb:05:18:26:99:b3:ec:72:ff:35:cd:
                    57:65:f8:bc:d9:74:61:4f:74:29:c2:c0:4f:4e:29:
                    de:2c:b4:a3:64:3b:6b:d3:c1:d2:72:90:b8:28:bd:
                    c1:7c:f3:d2:d0:75:b3:df:0b:1e:d4:68:37:87:74:
                    07:09:2f:23:5c:4b:48:b9:16:b1:c3:ee:13:5f:c3:
                    37:e9:38:e4:45:d3:ed:70:17:a1:dd:13:f1:81:50:
                    90:49
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                97:EA:C4:22:D2:06:18:ED:85:04:FF:DC:52:C2:6E:DB:0E:06:E1:3F
            X509v3 Authority Key Identifier: 
                keyid:9C:5F:00:DF:AA:01:D7:30:2B:38:88:A2:B8:6D:4A:9C:F2:11:91:83

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootg2.amazontrust.com
                CA Issuers - URI:http://crt.rootg2.amazontrust.com/rootg2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootg2.amazontrust.com/rootg2.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

    Signature Algorithm: sha256WithRSAEncryption
         af:c6:27:d3:4d:95:5a:1f:ff:8e:49:a3:da:a8:bb:15:7b:f5:
         f8:b2:38:d8:f0:e4:ac:a6:9d:9a:64:a3:6e:ce:d9:34:30:9d:
         23:78:c6:0b:a1:47:da:8f:08:b2:45:7f:3c:69:c9:b8:d9:2b:
         9d:be:6e:93:69:5d:b5:8e:a1:92:84:b1:72:05:c5:28:68:71:
         79:b1:c5:8d:e3:a5:04:43:8a:32:2a:c8:1d:70:10:46:15:ff:
         44:b8:27:a7:46:b5:dc:7d:c5:bf:ed:d4:be:bf:e7:7a:20:14:
         f6:b5:ee:ff:9d:16:12:50:d1:6c:08:cd:f4:d6:47:f5:68:c7:
         96:6b:27:fb:20:04:88:32:94:42:56:b0:45:17:d2:17:3e:43:
         0a:f2:78:65:3d:62:5b:f6:5c:87:26:00:dc:e8:1f:6b:50:9c:
         7b:35:bf:c1:86:dc:56:18:45:9e:05:7a:83:c4:4f:35:df:29:
         df:7c:cb:49:7d:bf:a9:71:da:0b:90:e2:13:40:de:f0:98:0c:
         c1:7e:c3:fd:93:71:55:ba:60:f5:4c:8c:49:2e:44:dd:a1:ca:
         97:18:b8:d9:9a:a9:a3:00:d0:ad:19:0f:b9:d0:39:e7:57:71:
         e3:51:7e:bf:86:ae:e1:d1:76:e8:76:11:92:34:80:cc:5f:3a:
         9c:1f:9f:df

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEojCCA4qgAwIBAgITBn+UV0u3B10+SJZceDIkqnVP7TANBgkqhkiG9w0BAQsF
ADCBmDELMAkGA1UEBhMCVVMxEDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNj
b3R0c2RhbGUxJTAjBgNVBAoTHFN0YXJmaWVsZCBUZWNobm9sb2dpZXMsIEluYy4x
OzA5BgNVBAMTMlN0YXJmaWVsZCBTZXJ2aWNlcyBSb290IENlcnRpZmljYXRlIEF1
dGhvcml0eSAtIEcyMB4XDTE1MTAyMjAwMDAwMFoXDTI1MTAxOTAwMDAwMFowRjEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEVMBMGA1UECxMMU2VydmVyIENB
IDBBMQ8wDQYDVQQDEwZBbWF6b24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQChhTHcMX+WcSKio/2VJ8N0cCpdrUf4oB9V+fx2dFxU+XgRvszhgePcNKv5
d7a0qOWF9uLmYix0BP34xYujNe0TTGBjOdjCWmTLi9mb5gO8Qxe3eaPZFHX2JbA+
GeqyLkv3/Dt4SkggAZX1PvoaPlCytHCW7qDdo+ycuqwrrfl0fYfJrEA+O5x8v+uH
UmC5APF5vYE8XdGhGra5JRot2TY3P+Kh1AfuJWPLBRgmmbPscv81zVdl+LzZdGFP
dCnCwE9OKd4stKNkO2vTwdJykLgovcF889LQdbPfCx7UaDeHdAcJLyNcS0i5FrHD
7hNfwzfpOORF0+1wF6HdE/GBUJBJAgMBAAGjggE0MIIBMDASBgNVHRMBAf8ECDAG
AQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQUl+rEItIGGO2FBP/cUsJu
2w4G4T8wHwYDVR0jBBgwFoAUnF8A36oB1zArOIiiuG1KnPIRkYMweAYIKwYBBQUH
AQEEbDBqMC4GCCsGAQUFBzABhiJodHRwOi8vb2NzcC5yb290ZzIuYW1hem9udHJ1
c3QuY29tMDgGCCsGAQUFBzAChixodHRwOi8vY3J0LnJvb3RnMi5hbWF6b250cnVz
dC5jb20vcm9vdGcyLmNlcjA9BgNVHR8ENjA0MDKgMKAuhixodHRwOi8vY3JsLnJv
b3RnMi5hbWF6b250cnVzdC5jb20vcm9vdGcyLmNybDARBgNVHSAECjAIMAYGBFUd
IAAwDQYJKoZIhvcNAQELBQADggEBAK/GJ9NNlVof/45Jo9qouxV79fiyONjw5Kym
nZpko27O2TQwnSN4xguhR9qPCLJFfzxpybjZK52+bpNpXbWOoZKEsXIFxShocXmx
xY3jpQRDijIqyB1wEEYV/0S4J6dGtdx9xb/t1L6/53ogFPa17v+dFhJQ0WwIzfTW
R/Vox5ZrJ/sgBIgylEJWsEUX0hc+QwryeGU9Ylv2XIcmANzoH2tQnHs1v8GG3FYY
RZ4FeoPETzXfKd98y0l9v6lx2guQ4hNA3vCYDMF+w/2TcVW6YPVMjEkuRN2hypcY
uNmaqaMA0K0ZD7nQOedXceNRfr+GruHRduh2EZI0gMxfOpwfn98=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06