Amazon-RSA-4096-M04.cer: CN=Amazon RSA 4096 M04,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-4096-M04.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-RSA-4096-M04.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:63:af:8f:9f:c1:63:88:a2:a2:e2:cf:a3:56:73:03:52
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
        Validity
            Not Before: Aug 23 22:31:08 2022 GMT
            Not After : Aug 23 22:31:08 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon RSA 4096 M04
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:9e:dc:16:13:49:26:60:f4:12:63:92:db:f4:0c:
                    c0:2b:87:67:3f:10:97:62:23:74:1f:3a:2e:56:96:
                    41:65:53:90:56:c0:8e:87:fb:3d:54:3d:97:c6:0d:
                    cc:95:87:fa:78:f4:dc:78:c9:6f:60:4a:df:ff:f4:
                    8c:db:00:13:b2:1d:9b:e1:25:93:7e:62:45:a8:12:
                    b7:13:d5:f2:62:e4:6d:22:14:9a:e7:d9:8a:72:39:
                    42:56:f9:f8:37:e0:ba:3e:32:f1:6a:a8:27:01:a6:
                    e6:b9:03:59:46:88:ed:ed:44:f0:b3:53:c5:4c:04:
                    59:80:43:c1:54:85:83:a2:73:2e:6b:21:f2:22:56:
                    b7:5e:a7:0a:4d:5c:cc:2f:e6:fd:a3:8c:b9:98:74:
                    60:de:f3:eb:3a:55:6a:8d:0b:38:33:14:3d:12:3c:
                    54:dc:e1:3e:2e:1f:8e:b3:a6:44:32:ae:9e:a4:63:
                    49:d8:d7:7b:70:bf:13:67:11:10:2b:ab:cc:66:34:
                    41:f3:93:69:30:04:c1:c4:23:34:07:eb:01:9b:de:
                    c7:7b:ae:f3:16:41:e1:ea:47:48:47:1c:57:b1:06:
                    5f:18:d8:fa:99:2f:88:da:96:08:68:d1:95:8f:e6:
                    ca:11:2f:ed:f0:35:37:9f:aa:81:21:c2:26:65:3a:
                    ee:d4:58:62:49:7c:75:00:2d:dc:48:d8:89:87:2d:
                    82:3f:b3:3c:3a:d6:5c:4e:5d:e8:d1:6a:35:28:65:
                    96:ae:a8:dc:3a:fd:08:d4:88:ba:d8:04:2c:b6:d4:
                    74:e6:b0:60:fb:c9:65:da:04:be:b7:65:d9:75:ae:
                    0f:d4:30:e5:83:ce:51:53:0c:de:5a:30:13:d9:0d:
                    82:d8:a2:04:c0:90:d3:db:17:5a:68:16:e0:00:fa:
                    fb:13:13:1b:8b:47:5c:56:41:00:bb:27:ce:c2:b8:
                    d3:e8:42:c4:e6:9b:20:a7:c5:df:ba:a5:df:bf:bb:
                    97:77:21:4a:d4:2b:b1:17:e6:d2:42:63:28:39:d4:
                    b7:44:0b:1b:33:a3:7e:6d:fa:40:6b:e4:38:d0:12:
                    bd:c8:86:81:d7:96:f8:49:7b:a2:14:6d:1a:15:38:
                    4e:34:c2:55:65:0e:fd:71:05:8d:d9:6d:48:5c:9d:
                    d1:1c:41:14:14:48:34:71:59:39:b7:f9:f3:86:fb:
                    b4:10:25:c8:52:84:be:7a:6c:85:55:21:76:36:f0:
                    eb:54:13:87:f9:b0:8e:da:75:32:b5:56:70:12:20:
                    93:e0:e5:25:ef:b1:8d:1a:a5:90:1f:7a:7d:d0:3b:
                    ec:91:fc:08:ad:04:2c:2d:61:30:54:ec:e0:88:c8:
                    e9:d9:9d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                46:33:08:90:85:B9:B5:20:F6:82:8E:A4:CC:6A:E4:D5:D1:92:02:CC
            X509v3 Authority Key Identifier: 
                keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca2.amazontrust.com
                CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca2.amazontrust.com/rootca2.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha384WithRSAEncryption
         40:38:c3:ab:c4:b9:db:3d:74:c5:e8:04:3a:03:13:a1:c7:29:
         01:ea:41:c8:a8:65:72:54:f8:dc:53:7d:f3:9c:ed:79:bc:b8:
         a7:fc:70:70:43:c1:4d:ef:70:ae:be:b5:ab:91:7b:4f:b1:a1:
         ca:eb:06:2d:59:5e:54:4f:6f:f5:9e:6c:18:01:a5:66:e8:76:
         fb:4c:53:4f:e3:ac:3e:ae:d0:1b:58:c3:9e:88:b2:bb:02:a3:
         b1:4e:b6:af:94:1c:37:ad:12:7a:06:39:99:2a:4c:85:e0:58:
         e4:7e:cf:f8:38:ac:26:81:0f:7b:90:bc:bd:6b:13:74:bc:c4:
         0b:27:79:d8:94:34:20:66:ab:81:90:f3:b4:6d:0a:95:40:6e:
         9f:c2:9e:7a:d7:fc:65:68:3a:30:28:a0:1f:66:db:b9:31:89:
         7a:27:22:94:6c:d4:e8:12:aa:bc:6e:41:b8:fe:2f:98:4b:09:
         aa:e8:60:5e:f2:13:6b:d6:cb:6c:c2:63:36:cc:28:07:41:33:
         1d:d9:cb:0d:e4:f2:63:73:38:76:6e:ac:e5:ff:c0:de:16:7a:
         1b:70:ca:f0:fd:d6:b2:60:75:1a:fe:c5:20:fe:45:75:0e:fb:
         1c:a7:a4:c2:3a:d4:bd:38:12:11:e9:a5:1d:a1:00:c4:30:e8:
         56:f3:88:c4:a5:3f:21:f2:52:88:9d:44:3b:5c:ab:40:12:0d:
         53:83:4a:05:23:aa:1b:cb:85:ca:45:71:f6:d4:2a:99:6c:eb:
         9a:b8:1f:1e:87:26:d6:e6:60:07:ab:32:46:4d:97:69:e2:9c:
         e1:73:bc:3d:4b:8c:a6:83:a9:ce:f8:a9:06:01:02:c3:35:b9:
         2e:f3:56:77:6d:0c:39:f9:b3:c7:e8:de:92:20:b8:e0:92:d1:
         44:45:50:18:b3:9e:ce:2b:6c:90:b8:f7:7b:68:a8:7a:51:c4:
         77:61:13:02:27:06:62:c8:bd:89:6f:49:49:15:da:fd:3f:f3:
         62:0c:d3:38:02:9e:f3:68:3c:e3:b6:2f:aa:8e:2d:99:f7:63:
         3d:7a:91:5f:77:98:a1:95:1c:cd:5c:9d:c9:f7:bb:d1:c8:d9:
         0b:8a:93:f0:44:0a:92:42:84:83:a9:5b:7d:1e:8c:92:8e:ed:
         31:6e:fe:0d:60:02:a6:f2:9b:e9:22:6d:27:6d:2a:97:dd:e7:
         9c:73:84:7a:e8:af:93:6e:68:90:b5:45:3f:02:61:5a:d6:70:
         45:55:f8:18:f7:da:c6:c9:29:84:75:d9:ff:30:16:ab:5b:6d:
         7c:ad:27:ee:c2:a4:7e:87:ae:67:6d:b7:e5:10:46:3f:35:a3:
         c2:6d:5b:50:a5:00:72:07

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIGXjCCBEagAwIBAgITB3MSY6+Pn8FjiKKi4s+jVnMDUjANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTIyMDgyMzIyMzEwOFoXDTMwMDgyMzIyMzEwOFowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSA0MDk2IE0wNDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAJ7cFhNJ
JmD0EmOS2/QMwCuHZz8Ql2IjdB86LlaWQWVTkFbAjof7PVQ9l8YNzJWH+nj03HjJ
b2BK3//0jNsAE7Idm+Elk35iRagStxPV8mLkbSIUmufZinI5Qlb5+Dfguj4y8Wqo
JwGm5rkDWUaI7e1E8LNTxUwEWYBDwVSFg6JzLmsh8iJWt16nCk1czC/m/aOMuZh0
YN7z6zpVao0LODMUPRI8VNzhPi4fjrOmRDKunqRjSdjXe3C/E2cRECurzGY0QfOT
aTAEwcQjNAfrAZvex3uu8xZB4epHSEccV7EGXxjY+pkviNqWCGjRlY/myhEv7fA1
N5+qgSHCJmU67tRYYkl8dQAt3EjYiYctgj+zPDrWXE5d6NFqNShllq6o3Dr9CNSI
utgELLbUdOawYPvJZdoEvrdl2XWuD9Qw5YPOUVMM3lowE9kNgtiiBMCQ09sXWmgW
4AD6+xMTG4tHXFZBALsnzsK40+hCxOabIKfF37ql37+7l3chStQrsRfm0kJjKDnU
t0QLGzOjfm36QGvkONASvciGgdeW+El7ohRtGhU4TjTCVWUO/XEFjdltSFyd0RxB
FBRINHFZObf584b7tBAlyFKEvnpshVUhdjbw61QTh/mwjtp1MrVWcBIgk+DlJe+x
jRqlkB96fdA77JH8CK0ELC1hMFTs4IjI6dmdAgMBAAGjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFEYzCJCFubUg9oKOpMxq5NXRkgLMMB8GA1Ud
IwQYMBaAFLAM8Eww9AVYAkj9M+VSr0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9v
dGNhMi5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFt
YXpvbnRydXN0LmNvbS9yb290Y2EyLmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAN
BgkqhkiG9w0BAQwFAAOCAgEAQDjDq8S52z10xegEOgMToccpAepByKhlclT43FN9
85zteby4p/xwcEPBTe9wrr61q5F7T7GhyusGLVleVE9v9Z5sGAGlZuh2+0xTT+Os
Pq7QG1jDnoiyuwKjsU62r5QcN60SegY5mSpMheBY5H7P+DisJoEPe5C8vWsTdLzE
Cyd52JQ0IGargZDztG0KlUBun8Keetf8ZWg6MCigH2bbuTGJeicilGzU6BKqvG5B
uP4vmEsJquhgXvITa9bLbMJjNswoB0EzHdnLDeTyY3M4dm6s5f/A3hZ6G3DK8P3W
smB1Gv7FIP5FdQ77HKekwjrUvTgSEemlHaEAxDDoVvOIxKU/IfJSiJ1EO1yrQBIN
U4NKBSOqG8uFykVx9tQqmWzrmrgfHocm1uZgB6syRk2XaeKc4XO8PUuMpoOpzvip
BgECwzW5LvNWd20MOfmzx+jekiC44JLRREVQGLOezitskLj3e2ioelHEd2ETAicG
Ysi9iW9JSRXa/T/zYgzTOAKe82g847Yvqo4tmfdjPXqRX3eYoZUczVydyfe70cjZ
C4qT8EQKkkKEg6lbfR6Mko7tMW7+DWACpvKb6SJtJ20ql93nnHOEeuivk25okLVF
PwJhWtZwRVX4GPfaxskphHXZ/zAWq1ttfK0n7sKkfoeuZ2235RBGPzWjwm1bUKUA
cgc=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06