Amazon-RSA-4096-M04.cer: CN=Amazon RSA 4096 M04,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: https://www.amazontrust.com/repository/Amazon-RSA-4096-M04.cer (in DER format )
- Serial Number : 166129386859607941899818120077129858497577810
- SHA-1 Fingerprint : 0ee958f54b6f6d990ae948a362b4f7a81e3653ce
- SHA-1 Fingerprint : 0e:e9:58:f5:4b:6f:6d:99:0a:e9:48:a3:62:b4:f7:a8:1e:36:53:ce
- SHA-256 Fingerprint : 3b6fab0ab11c14eef9031969e0adb037c8fcc3366728a6567623d3c26b3632cb
- SHA-256 Fingerprint : 3b:6f:ab:0a:b1:1c:14:ee:f9:03:19:69:e0:ad:b0:37:c8:fc:c3:36:67:28:a6:56:76:23:d3:c2:6b:36:32:cb
- Signature Hash Algorithm : sha384
- Subject
: CN=Amazon RSA 4096 M04,O=Amazon,C=US
- Country Name: US (United States of America)
- Organization: Amazon
- Common Name: Amazon RSA 4096 M04
- Not Valid Before: 2022-08-23 22:31:08
- Not Valid After: 2030-08-23 22:31:08
- Issuer (Parent Certificate):
- Issuer Name: CN=Amazon Root CA 2,O=Amazon,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cp-v5-12-Final.pdf
- Certificate Practice Statement (CPS) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cps-v5-12-Final.pdf
- Auditor: BDO International Limited
- Standard Audit URL: https://bugzilla.mozilla.org/attachment.cgi?id=9309728
- Standard Audit Period Start Date: 2021.10.01
- Standard Audit Period End Date: 2022.09.30
- Standard Audit Statement Date: 2022.12.22
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: http://crl.r4m04.amazontrust.com/r4m04.crl
- Check its issuer’s audit information: CN=Amazon Root CA 2,O=Amazon,C=US .
Download certificate through curl
:
curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-4096-M04.cer" --output cert.crt
Download certificate through wget
:
wget -q "https://www.amazontrust.com/repository/Amazon-RSA-4096-M04.cer" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
07:73:12:63:af:8f:9f:c1:63:88:a2:a2:e2:cf:a3:56:73:03:52
Signature Algorithm: sha384WithRSAEncryption
Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
Validity
Not Before: Aug 23 22:31:08 2022 GMT
Not After : Aug 23 22:31:08 2030 GMT
Subject: C=US, O=Amazon, CN=Amazon RSA 4096 M04
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:9e:dc:16:13:49:26:60:f4:12:63:92:db:f4:0c:
c0:2b:87:67:3f:10:97:62:23:74:1f:3a:2e:56:96:
41:65:53:90:56:c0:8e:87:fb:3d:54:3d:97:c6:0d:
cc:95:87:fa:78:f4:dc:78:c9:6f:60:4a:df:ff:f4:
8c:db:00:13:b2:1d:9b:e1:25:93:7e:62:45:a8:12:
b7:13:d5:f2:62:e4:6d:22:14:9a:e7:d9:8a:72:39:
42:56:f9:f8:37:e0:ba:3e:32:f1:6a:a8:27:01:a6:
e6:b9:03:59:46:88:ed:ed:44:f0:b3:53:c5:4c:04:
59:80:43:c1:54:85:83:a2:73:2e:6b:21:f2:22:56:
b7:5e:a7:0a:4d:5c:cc:2f:e6:fd:a3:8c:b9:98:74:
60:de:f3:eb:3a:55:6a:8d:0b:38:33:14:3d:12:3c:
54:dc:e1:3e:2e:1f:8e:b3:a6:44:32:ae:9e:a4:63:
49:d8:d7:7b:70:bf:13:67:11:10:2b:ab:cc:66:34:
41:f3:93:69:30:04:c1:c4:23:34:07:eb:01:9b:de:
c7:7b:ae:f3:16:41:e1:ea:47:48:47:1c:57:b1:06:
5f:18:d8:fa:99:2f:88:da:96:08:68:d1:95:8f:e6:
ca:11:2f:ed:f0:35:37:9f:aa:81:21:c2:26:65:3a:
ee:d4:58:62:49:7c:75:00:2d:dc:48:d8:89:87:2d:
82:3f:b3:3c:3a:d6:5c:4e:5d:e8:d1:6a:35:28:65:
96:ae:a8:dc:3a:fd:08:d4:88:ba:d8:04:2c:b6:d4:
74:e6:b0:60:fb:c9:65:da:04:be:b7:65:d9:75:ae:
0f:d4:30:e5:83:ce:51:53:0c:de:5a:30:13:d9:0d:
82:d8:a2:04:c0:90:d3:db:17:5a:68:16:e0:00:fa:
fb:13:13:1b:8b:47:5c:56:41:00:bb:27:ce:c2:b8:
d3:e8:42:c4:e6:9b:20:a7:c5:df:ba:a5:df:bf:bb:
97:77:21:4a:d4:2b:b1:17:e6:d2:42:63:28:39:d4:
b7:44:0b:1b:33:a3:7e:6d:fa:40:6b:e4:38:d0:12:
bd:c8:86:81:d7:96:f8:49:7b:a2:14:6d:1a:15:38:
4e:34:c2:55:65:0e:fd:71:05:8d:d9:6d:48:5c:9d:
d1:1c:41:14:14:48:34:71:59:39:b7:f9:f3:86:fb:
b4:10:25:c8:52:84:be:7a:6c:85:55:21:76:36:f0:
eb:54:13:87:f9:b0:8e:da:75:32:b5:56:70:12:20:
93:e0:e5:25:ef:b1:8d:1a:a5:90:1f:7a:7d:d0:3b:
ec:91:fc:08:ad:04:2c:2d:61:30:54:ec:e0:88:c8:
e9:d9:9d
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Subject Key Identifier:
46:33:08:90:85:B9:B5:20:F6:82:8E:A4:CC:6A:E4:D5:D1:92:02:CC
X509v3 Authority Key Identifier:
keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52
Authority Information Access:
OCSP - URI:http://ocsp.rootca2.amazontrust.com
CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.rootca2.amazontrust.com/rootca2.crl
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Signature Algorithm: sha384WithRSAEncryption
40:38:c3:ab:c4:b9:db:3d:74:c5:e8:04:3a:03:13:a1:c7:29:
01:ea:41:c8:a8:65:72:54:f8:dc:53:7d:f3:9c:ed:79:bc:b8:
a7:fc:70:70:43:c1:4d:ef:70:ae:be:b5:ab:91:7b:4f:b1:a1:
ca:eb:06:2d:59:5e:54:4f:6f:f5:9e:6c:18:01:a5:66:e8:76:
fb:4c:53:4f:e3:ac:3e:ae:d0:1b:58:c3:9e:88:b2:bb:02:a3:
b1:4e:b6:af:94:1c:37:ad:12:7a:06:39:99:2a:4c:85:e0:58:
e4:7e:cf:f8:38:ac:26:81:0f:7b:90:bc:bd:6b:13:74:bc:c4:
0b:27:79:d8:94:34:20:66:ab:81:90:f3:b4:6d:0a:95:40:6e:
9f:c2:9e:7a:d7:fc:65:68:3a:30:28:a0:1f:66:db:b9:31:89:
7a:27:22:94:6c:d4:e8:12:aa:bc:6e:41:b8:fe:2f:98:4b:09:
aa:e8:60:5e:f2:13:6b:d6:cb:6c:c2:63:36:cc:28:07:41:33:
1d:d9:cb:0d:e4:f2:63:73:38:76:6e:ac:e5:ff:c0:de:16:7a:
1b:70:ca:f0:fd:d6:b2:60:75:1a:fe:c5:20:fe:45:75:0e:fb:
1c:a7:a4:c2:3a:d4:bd:38:12:11:e9:a5:1d:a1:00:c4:30:e8:
56:f3:88:c4:a5:3f:21:f2:52:88:9d:44:3b:5c:ab:40:12:0d:
53:83:4a:05:23:aa:1b:cb:85:ca:45:71:f6:d4:2a:99:6c:eb:
9a:b8:1f:1e:87:26:d6:e6:60:07:ab:32:46:4d:97:69:e2:9c:
e1:73:bc:3d:4b:8c:a6:83:a9:ce:f8:a9:06:01:02:c3:35:b9:
2e:f3:56:77:6d:0c:39:f9:b3:c7:e8:de:92:20:b8:e0:92:d1:
44:45:50:18:b3:9e:ce:2b:6c:90:b8:f7:7b:68:a8:7a:51:c4:
77:61:13:02:27:06:62:c8:bd:89:6f:49:49:15:da:fd:3f:f3:
62:0c:d3:38:02:9e:f3:68:3c:e3:b6:2f:aa:8e:2d:99:f7:63:
3d:7a:91:5f:77:98:a1:95:1c:cd:5c:9d:c9:f7:bb:d1:c8:d9:
0b:8a:93:f0:44:0a:92:42:84:83:a9:5b:7d:1e:8c:92:8e:ed:
31:6e:fe:0d:60:02:a6:f2:9b:e9:22:6d:27:6d:2a:97:dd:e7:
9c:73:84:7a:e8:af:93:6e:68:90:b5:45:3f:02:61:5a:d6:70:
45:55:f8:18:f7:da:c6:c9:29:84:75:d9:ff:30:16:ab:5b:6d:
7c:ad:27:ee:c2:a4:7e:87:ae:67:6d:b7:e5:10:46:3f:35:a3:
c2:6d:5b:50:a5:00:72:07
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIGXjCCBEagAwIBAgITB3MSY6+Pn8FjiKKi4s+jVnMDUjANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTIyMDgyMzIyMzEwOFoXDTMwMDgyMzIyMzEwOFowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSA0MDk2IE0wNDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAJ7cFhNJ
JmD0EmOS2/QMwCuHZz8Ql2IjdB86LlaWQWVTkFbAjof7PVQ9l8YNzJWH+nj03HjJ
b2BK3//0jNsAE7Idm+Elk35iRagStxPV8mLkbSIUmufZinI5Qlb5+Dfguj4y8Wqo
JwGm5rkDWUaI7e1E8LNTxUwEWYBDwVSFg6JzLmsh8iJWt16nCk1czC/m/aOMuZh0
YN7z6zpVao0LODMUPRI8VNzhPi4fjrOmRDKunqRjSdjXe3C/E2cRECurzGY0QfOT
aTAEwcQjNAfrAZvex3uu8xZB4epHSEccV7EGXxjY+pkviNqWCGjRlY/myhEv7fA1
N5+qgSHCJmU67tRYYkl8dQAt3EjYiYctgj+zPDrWXE5d6NFqNShllq6o3Dr9CNSI
utgELLbUdOawYPvJZdoEvrdl2XWuD9Qw5YPOUVMM3lowE9kNgtiiBMCQ09sXWmgW
4AD6+xMTG4tHXFZBALsnzsK40+hCxOabIKfF37ql37+7l3chStQrsRfm0kJjKDnU
t0QLGzOjfm36QGvkONASvciGgdeW+El7ohRtGhU4TjTCVWUO/XEFjdltSFyd0RxB
FBRINHFZObf584b7tBAlyFKEvnpshVUhdjbw61QTh/mwjtp1MrVWcBIgk+DlJe+x
jRqlkB96fdA77JH8CK0ELC1hMFTs4IjI6dmdAgMBAAGjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFEYzCJCFubUg9oKOpMxq5NXRkgLMMB8GA1Ud
IwQYMBaAFLAM8Eww9AVYAkj9M+VSr0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9v
dGNhMi5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFt
YXpvbnRydXN0LmNvbS9yb290Y2EyLmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAN
BgkqhkiG9w0BAQwFAAOCAgEAQDjDq8S52z10xegEOgMToccpAepByKhlclT43FN9
85zteby4p/xwcEPBTe9wrr61q5F7T7GhyusGLVleVE9v9Z5sGAGlZuh2+0xTT+Os
Pq7QG1jDnoiyuwKjsU62r5QcN60SegY5mSpMheBY5H7P+DisJoEPe5C8vWsTdLzE
Cyd52JQ0IGargZDztG0KlUBun8Keetf8ZWg6MCigH2bbuTGJeicilGzU6BKqvG5B
uP4vmEsJquhgXvITa9bLbMJjNswoB0EzHdnLDeTyY3M4dm6s5f/A3hZ6G3DK8P3W
smB1Gv7FIP5FdQ77HKekwjrUvTgSEemlHaEAxDDoVvOIxKU/IfJSiJ1EO1yrQBIN
U4NKBSOqG8uFykVx9tQqmWzrmrgfHocm1uZgB6syRk2XaeKc4XO8PUuMpoOpzvip
BgECwzW5LvNWd20MOfmzx+jekiC44JLRREVQGLOezitskLj3e2ioelHEd2ETAicG
Ysi9iW9JSRXa/T/zYgzTOAKe82g847Yvqo4tmfdjPXqRX3eYoZUczVydyfe70cjZ
C4qT8EQKkkKEg6lbfR6Mko7tMW7+DWACpvKb6SJtJ20ql93nnHOEeuivk25okLVF
PwJhWtZwRVX4GPfaxskphHXZ/zAWq1ttfK0n7sKkfoeuZ2235RBGPzWjwm1bUKUA
cgc=
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Amazon-ECDSA-256-M01.cer: CN=Amazon ECDSA 256 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M02.cer: CN=Amazon ECDSA 256 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M03.cer: CN=Amazon ECDSA 256 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M04.cer: CN=Amazon ECDSA 256 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M01.cer: CN=Amazon ECDSA 384 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M02.cer: CN=Amazon ECDSA 384 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M03.cer: CN=Amazon ECDSA 384 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M04.cer: CN=Amazon ECDSA 384 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M01.cer: CN=Amazon RSA 2048 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M02.cer: CN=Amazon RSA 2048 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M03.cer: CN=Amazon RSA 2048 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M04.cer: CN=Amazon RSA 2048 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M01.cer: CN=Amazon RSA 4096 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M02.cer: CN=Amazon RSA 4096 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M03.cer: CN=Amazon RSA 4096 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- rootca1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2038-01-17)
- G2-RootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA1.orig.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA2.orig.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA3.orig.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA4.orig.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-ServerCA0A.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2025-10-19)
- G2-ServerCA0A.orig.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2040-10-21)
- R1-ServerCA1A.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1A.orig.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2040-10-21)
- sca1b.crt: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.orig.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2040-10-21)
- R2-ServerCA2A.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2025-10-19)
- R2-ServerCA2A.orig.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3A.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2025-10-19)
- R3-ServerCA3A.orig.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3B.cer: CN=Amazon,OU=Server CA 3B,O=Amazon,C=US (Expiring: 2028-07-16)
- R4-ServerCA4A.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2025-10-19)
- R4-ServerCA4A.orig.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2040-10-21)
- rootg2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.v2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFSRootCA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2031-05-30)
- SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2037-12-31)