lets-encrypt-x2-cross-signed.der: CN=Let's Encrypt Authority X2,O=Let's Encrypt,C=US (Intermediate Certificate, Expiring 2020-10-19) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://letsencrypt.org/certs/lets-encrypt-x2-cross-signed.der" --output cert.crt

Download certificate through wget:

wget -q "https://letsencrypt.org/certs/lets-encrypt-x2-cross-signed.der" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            c3:83:4c:98:c0:bd:6b:25:2c:a3:79:b6:6f:a5:2b:0e
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: O=Digital Signature Trust Co., CN=DST Root CA X3
        Validity
            Not Before: Oct 19 22:35:01 2015 GMT
            Not After : Oct 19 22:35:01 2020 GMT
        Subject: C=US, O=Let's Encrypt, CN=Let's Encrypt Authority X2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:e1:24:74:42:7b:b7:91:31:d9:73:ff:38:aa:d8:
                    ce:44:5c:b7:39:0a:dc:44:ae:0d:bd:45:b9:97:37:
                    67:af:bd:50:4f:5f:d3:10:54:6b:f7:41:da:8e:63:
                    e6:6d:5b:c0:e8:40:a9:8c:41:fc:d1:03:89:ff:62:
                    61:09:60:d6:07:05:78:9a:90:bd:1a:64:3e:4f:dc:
                    cf:77:2f:89:6b:cb:67:af:41:4d:c5:8d:00:c0:6b:
                    fe:8d:84:dc:b5:f2:95:31:a8:e8:f6:90:a0:43:4a:
                    93:74:5c:b3:3e:43:69:4b:89:22:47:74:51:3e:99:
                    64:c3:cd:24:01:f9:84:2f:28:77:17:22:a7:dd:c3:
                    6c:08:4c:66:2f:37:74:c5:6f:93:8e:b0:46:37:16:
                    61:d1:50:98:c8:b0:0f:4f:58:53:7c:ac:f6:da:2d:
                    96:61:50:ad:43:dc:0a:a6:4f:9e:b5:52:b9:9c:8e:
                    ef:4e:df:46:b3:31:dc:20:fc:69:c2:a3:20:75:3e:
                    ec:38:1b:36:4e:66:66:d2:df:f5:66:a4:93:2f:7b:
                    a6:0e:94:3e:60:3d:4a:4b:1c:6f:ba:b4:4d:1c:3c:
                    91:58:6e:2f:4d:c4:da:70:db:ed:01:39:76:c0:49:
                    e7:e9:35:b5:14:06:90:c1:e5:92:e2:10:fd:6b:b9:
                    b4:85
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            Authority Information Access: 
                OCSP - URI:http://isrg.trustid.ocsp.identrust.com
                CA Issuers - URI:http://apps.identrust.com/roots/dstrootcax3.p7c

            X509v3 Authority Key Identifier: 
                keyid:C4:A7:B1:A4:7B:2C:71:FA:DB:E1:4B:90:75:FF:C4:15:60:85:89:10

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
                Policy: 1.3.6.1.4.1.44947.1.1.1
                  CPS: http://cps.root-x1.letsencrypt.org

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.identrust.com/DSTROOTCAX3CRL.crl

            X509v3 Name Constraints: 
                Excluded:
                  DNS:.mil

            X509v3 Subject Key Identifier: 
                C5:B1:AB:4E:4C:B1:CD:64:30:93:7E:C1:84:99:05:AB:E6:03:E2:25
    Signature Algorithm: sha256WithRSAEncryption
         07:12:02:16:84:ee:bb:c7:c7:25:27:86:09:04:a4:c4:79:ea:
         8d:88:20:7f:a6:97:0e:64:92:78:e1:02:eb:da:04:80:0c:e7:
         d3:19:90:56:c5:83:90:ab:35:6b:7c:2b:e1:b7:52:8c:49:80:
         5c:2f:ec:7b:c9:27:1a:b0:80:fa:4d:81:70:bf:b9:3d:e9:ae:
         4b:f0:b7:ed:a5:bf:32:89:29:ba:9d:1f:e9:68:e3:43:fc:12:
         e4:b2:c8:93:b3:da:18:eb:47:33:4c:1d:b2:47:60:34:bd:3a:
         11:79:58:2e:4b:39:04:1a:c9:d8:0b:67:f2:47:c5:78:09:ca:
         91:19:a9:c9:95:81:0f:b2:60:1b:34:5c:fc:17:8c:4e:ce:13:
         cb:db:c7:94:44:c2:ee:e0:4e:83:08:a8:0a:16:46:85:96:d8:
         cc:52:83:6f:11:18:f5:67:1f:31:e4:d9:75:75:9d:91:b2:f5:
         3f:8d:61:0f:75:bd:65:89:af:5a:73:34:41:59:d1:c9:c0:db:
         11:b0:4d:e2:7e:cd:9d:d4:44:27:f0:dd:9d:54:f9:80:0b:dd:
         85:26:ae:f7:68:44:19:40:48:e4:e6:34:99:97:4a:8f:6a:bc:
         c6:0f:6b:70:c4:a2:60:0f:a0:54:05:66:ab:12:37:a9:2e:a8:
         31:08:a8:c0

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEqDCCA5CgAwIBAgIRAMODTJjAvWslLKN5tm+lKw4wDQYJKoZIhvcNAQELBQAw
PzEkMCIGA1UEChMbRGlnaXRhbCBTaWduYXR1cmUgVHJ1c3QgQ28uMRcwFQYDVQQD
Ew5EU1QgUm9vdCBDQSBYMzAeFw0xNTEwMTkyMjM1MDFaFw0yMDEwMTkyMjM1MDFa
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMjCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBAOEkdEJ7t5Ex2XP/OKrYzkRctzkK3ESuDb1FuZc3Z6+9UE9f
0xBUa/dB2o5j5m1bwOhAqYxB/NEDif9iYQlg1gcFeJqQvRpkPk/cz3cviWvLZ69B
TcWNAMBr/o2E3LXylTGo6PaQoENKk3Rcsz5DaUuJIkd0UT6ZZMPNJAH5hC8odxci
p93DbAhMZi83dMVvk46wRjcWYdFQmMiwD09YU3ys9totlmFQrUPcCqZPnrVSuZyO
707fRrMx3CD8acKjIHU+7DgbNk5mZtLf9Wakky97pg6UPmA9Skscb7q0TRw8kVhu
L03E2nDb7QE5dsBJ5+k1tRQGkMHlkuIQ/Wu5tIUCAwEAAaOCAZIwggGOMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwDgYDVR0PAQH/BAQDAgGGMH8GCCsGAQUFBwEBBHMwcTAy
BggrBgEFBQcwAYYmaHR0cDovL2lzcmcudHJ1c3RpZC5vY3NwLmlkZW50cnVzdC5j
b20wOwYIKwYBBQUHMAKGL2h0dHA6Ly9hcHBzLmlkZW50cnVzdC5jb20vcm9vdHMv
ZHN0cm9vdGNheDMucDdjMB8GA1UdIwQYMBaAFMSnsaR7LHH62+FLkHX/xBVghYkQ
MFQGA1UdIARNMEswCAYGZ4EMAQIBMD8GCysGAQQBgt8TAQEBMDAwLgYIKwYBBQUH
AgEWImh0dHA6Ly9jcHMucm9vdC14MS5sZXRzZW5jcnlwdC5vcmcwPAYDVR0fBDUw
MzAxoC+gLYYraHR0cDovL2NybC5pZGVudHJ1c3QuY29tL0RTVFJPT1RDQVgzQ1JM
LmNybDATBgNVHR4EDDAKoQgwBoIELm1pbDAdBgNVHQ4EFgQUxbGrTkyxzWQwk37B
hJkFq+YD4iUwDQYJKoZIhvcNAQELBQADggEBAAcSAhaE7rvHxyUnhgkEpMR56o2I
IH+mlw5kknjhAuvaBIAM59MZkFbFg5CrNWt8K+G3UoxJgFwv7HvJJxqwgPpNgXC/
uT3prkvwt+2lvzKJKbqdH+lo40P8EuSyyJOz2hjrRzNMHbJHYDS9OhF5WC5LOQQa
ydgLZ/JHxXgJypEZqcmVgQ+yYBs0XPwXjE7OE8vbx5REwu7gToMIqAoWRoWW2MxS
g28RGPVnHzHk2XV1nZGy9T+NYQ91vWWJr1pzNEFZ0cnA2xGwTeJ+zZ3URCfw3Z1U
+YAL3YUmrvdoRBlASOTmNJmXSo9qvMYPa3DEomAPoFQFZqsSN6kuqDEIqMA=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06