R2-ServerCA2A.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Intermediate Certificate, Expiring 2025-10-19) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: https://www.amazontrust.com/repository/R2-ServerCA2A.cer (in DER format )
- Serial Number : 144918209383901264186543282922762766780989240
- SHA-1 Fingerprint : 1cec96ae3d32914253df975f82aae83c9e8aa34d
- SHA-1 Fingerprint : 1c:ec:96:ae:3d:32:91:42:53:df:97:5f:82:aa:e8:3c:9e:8a:a3:4d
- SHA-256 Fingerprint : 72130e3b28900349214617f4d6f3fb85d08475ee78bf095c59458a14d1828866
- SHA-256 Fingerprint : 72:13:0e:3b:28:90:03:49:21:46:17:f4:d6:f3:fb:85:d0:84:75:ee:78:bf:09:5c:59:45:8a:14:d1:82:88:66
- Signature Hash Algorithm : sha384
- Subject
: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US
- Country Name: US (United States of America)
- Organization: Amazon
- Organization Unit: Server CA 2A
- Common Name: Amazon
- Not Valid Before: 2015-10-22 00:00:00
- Not Valid After: 2025-10-19 00:00:00
- Issuer (Parent Certificate):
- Issuer Name: CN=Amazon Root CA 2,O=Amazon,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: Unknown
- Certificate Practice Statement (CPS) URL: Unknown
- Auditor: BDO International Limited
- Standard Audit URL: https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?attachmentid=2c238883-a342-4762-8e2a-f506ad5660f8
- Standard Audit Period Start Date: 2021.01.16
- Standard Audit Period End Date: 2022.01.15
- Standard Audit Statement Date: 2022.04.08
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: Unknown
- Check its issuer’s audit information: CN=Amazon Root CA 2,O=Amazon,C=US .
Download certificate through curl
:
curl -sSL "https://www.amazontrust.com/repository/R2-ServerCA2A.cer" --output cert.crt
Download certificate through wget
:
wget -q "https://www.amazontrust.com/repository/R2-ServerCA2A.cer" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
06:7f:94:57:55:f1:87:a9:1f:81:63:f3:e6:24:62:01:77:ff:38
Signature Algorithm: sha384WithRSAEncryption
Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
Validity
Not Before: Oct 22 00:00:00 2015 GMT
Not After : Oct 19 00:00:00 2025 GMT
Subject: C=US, O=Amazon, OU=Server CA 2A, CN=Amazon
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:b4:3f:c8:52:2d:ec:26:ad:9e:35:08:23:c1:43:
2b:59:b3:93:41:14:ca:b9:ce:d6:e7:31:ff:a4:65:
4a:7d:4b:6e:4b:3d:f8:cd:5b:7c:e0:0b:fe:84:a8:
24:d6:35:53:0c:1e:1a:bb:7b:3f:48:40:99:38:f2:
a6:df:05:32:e5:66:4b:8a:9d:45:9b:03:db:e8:c2:
b0:df:73:15:0d:d2:64:44:e0:1f:d3:25:bb:de:5f:
24:df:bc:4f:75:88:39:6a:0e:b1:11:79:c1:3d:0f:
cb:1d:8f:35:11:ae:d1:d3:a7:6e:e5:65:d4:64:5c:
5b:df:11:50:aa:e2:19:77:b0:79:33:8e:87:62:b1:
a4:2d:84:ba:75:80:bb:22:03:bb:ca:b7:ef:33:70:
be:00:7a:ae:76:53:26:1b:f2:be:3f:8d:d6:77:29:
a4:29:f0:ef:d3:e1:5c:03:09:12:a6:f1:ec:b7:92:
db:69:25:66:9f:95:c8:bb:79:1c:cd:8d:8e:e0:13:
73:4c:00:d5:57:09:e4:30:38:17:c7:d8:68:c8:34:
50:8e:6e:63:ec:aa:20:6e:a0:09:ec:bf:69:39:69:
02:cd:a1:4d:4e:66:4d:3c:0a:55:e6:98:46:76:ac:
8e:6a:65:44:d7:d4:7b:9e:7c:12:67:a4:c9:0f:ba:
01:42:c3:c6:9f:68:79:c1:d7:74:a4:2c:4e:f0:c5:
7f:12:65:17:43:21:ee:56:8b:0c:83:2f:5b:51:db:
ef:25:a7:3e:09:b0:ca:05:a2:91:e6:0f:71:9a:1f:
28:db:37:e8:64:3a:a1:e0:2e:5b:70:7b:03:ac:8b:
23:34:bb:70:99:a6:1c:a9:37:62:9e:0f:ed:45:2e:
39:d8:4e:07:48:01:dd:45:46:02:b6:65:70:c3:ac:
47:63:9e:c4:84:7d:28:4a:7f:49:78:98:53:d2:06:
cf:44:dd:4e:ac:2e:6b:9b:0d:15:ca:2c:b2:e9:6b:
f7:45:e1:e2:ae:2c:42:92:d5:b5:d8:4f:6f:22:33:
a0:f9:81:20:a7:ce:1a:39:1b:87:75:f2:34:03:fe:
c9:66:73:95:e6:46:8e:4f:8a:0d:11:c8:1c:03:68:
bb:b1:78:86:6e:88:9d:00:27:a6:05:85:f7:db:ac:
b6:05:e5:d1:10:97:47:14:fa:dd:d5:04:ae:6e:fe:
8d:56:91:65:ec:65:ac:14:d3:7f:25:5a:7f:c0:5d:
ea:e8:75:3f:e9:01:ca:ed:58:0e:04:35:01:0d:d3:
d5:84:28:c8:59:54:f8:6a:77:08:45:fc:6b:ac:af:
4e:26:42:d2:ad:ed:3d:af:e9:43:10:be:d5:60:96:
fe:44:ef
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Subject Key Identifier:
DA:43:4A:D0:FC:01:C0:4B:BF:58:27:8C:76:CD:0A:81:F3:94:2E:F4
X509v3 Authority Key Identifier:
keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52
Authority Information Access:
OCSP - URI:http://ocsp.rootca2.amazontrust.com
CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.rootca2.amazontrust.com/rootca2.crl
X509v3 Certificate Policies:
Policy: X509v3 Any Policy
Signature Algorithm: sha384WithRSAEncryption
43:b9:5b:e8:85:c8:28:63:0f:2c:ab:9a:2c:05:ba:95:56:43:
45:f2:d9:17:85:35:08:99:ab:b5:ca:54:7b:ec:2d:07:b4:d6:
6a:12:2e:7c:5c:07:18:a8:38:f0:4a:b7:52:a4:64:ee:f0:19:
c6:e6:91:ed:3e:ec:0c:4b:68:6f:c5:e4:d3:e7:cd:1b:4a:d7:
fa:51:85:74:34:5d:d5:3c:a5:58:7f:d7:f8:78:1a:8a:91:95:
9f:de:37:42:43:6a:b5:21:64:f9:15:91:2a:fd:e8:b5:18:0d:
3c:5c:b0:08:9d:17:bc:e4:cd:67:e6:b5:c2:60:fc:0c:3c:9a:
2d:78:c4:a5:44:6b:a6:95:c8:ab:b9:e1:cf:24:2a:47:65:b7:
45:9a:8a:03:af:67:fc:58:87:1a:76:e0:07:e8:14:a6:88:ad:
a0:cd:76:c0:fc:ab:63:7b:78:36:1e:37:85:86:2f:33:52:96:
29:7e:88:58:f3:7e:52:3d:9a:ad:61:4e:e2:3f:64:d8:d5:ad:
bb:e8:6f:a1:54:43:c0:9c:e7:6e:20:32:36:e9:64:23:6e:67:
58:1f:5f:3c:30:84:6a:74:02:74:05:e8:22:6c:58:5f:6e:c0:
fa:59:11:51:67:9e:77:e2:58:7d:cc:a2:ea:78:d4:4b:c1:86:
a6:80:a8:e9:67:cb:4b:26:e6:92:3c:da:74:54:08:01:37:0c:
b9:09:d7:e7:80:b5:d4:1a:61:b9:59:42:44:2b:47:24:ee:3e:
62:44:9b:ee:72:43:07:43:57:0e:ae:1d:ce:4e:b1:28:ff:b7:
28:61:f3:32:76:5e:ad:f3:82:1d:dd:30:e3:46:8c:91:32:b3:
11:9a:0a:82:1b:fb:ad:4f:5b:03:32:d9:d2:1a:ad:5c:08:af:
e7:3e:01:8f:b7:3e:b8:60:06:ca:4d:75:66:7c:ec:9c:cd:1e:
28:bb:92:c7:63:51:25:46:4d:3c:b5:bc:65:e0:3d:8a:ef:d2:
5a:74:20:c9:ca:69:93:f9:f3:18:b0:ac:3c:7b:b9:39:50:b8:
f5:56:34:e6:6f:09:a4:f7:65:ca:31:4e:c3:4a:36:c7:08:51:
ef:96:26:35:b1:e6:17:73:a6:ff:e8:92:c0:cf:63:99:6d:67:
48:f7:86:50:d2:0f:e2:2d:93:de:7f:70:d2:55:44:cf:f4:1e:
9c:48:d5:25:fd:31:36:6d:39:22:68:10:37:54:b4:ea:55:68:
eb:81:02:f1:0a:e2:0b:d3:cd:db:74:af:92:fe:7e:e2:3a:a3:
92:c0:b9:1a:3f:2c:ed:71:55:11:f8:f4:a1:51:a1:ac:e7:cd:
4d:c2:87:df:a4:6c:f6:f7
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIGRzCCBC+gAwIBAgITBn+UV1Xxh6kfgWPz5iRiAXf/ODANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTE1MTAyMjAwMDAwMFoXDTI1MTAxOTAwMDAwMFowRjEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEVMBMGA1UECxMMU2VydmVyIENB
IDJBMQ8wDQYDVQQDEwZBbWF6b24wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIK
AoICAQC0P8hSLewmrZ41CCPBQytZs5NBFMq5ztbnMf+kZUp9S25LPfjNW3zgC/6E
qCTWNVMMHhq7ez9IQJk48qbfBTLlZkuKnUWbA9vowrDfcxUN0mRE4B/TJbveXyTf
vE91iDlqDrERecE9D8sdjzURrtHTp27lZdRkXFvfEVCq4hl3sHkzjodisaQthLp1
gLsiA7vKt+8zcL4Aeq52UyYb8r4/jdZ3KaQp8O/T4VwDCRKm8ey3kttpJWaflci7
eRzNjY7gE3NMANVXCeQwOBfH2GjINFCObmPsqiBuoAnsv2k5aQLNoU1OZk08ClXm
mEZ2rI5qZUTX1HuefBJnpMkPugFCw8afaHnB13SkLE7wxX8SZRdDIe5WiwyDL1tR
2+8lpz4JsMoFopHmD3GaHyjbN+hkOqHgLltwewOsiyM0u3CZphypN2KeD+1FLjnY
TgdIAd1FRgK2ZXDDrEdjnsSEfShKf0l4mFPSBs9E3U6sLmubDRXKLLLpa/dF4eKu
LEKS1bXYT28iM6D5gSCnzho5G4d18jQD/slmc5XmRo5Pig0RyBwDaLuxeIZuiJ0A
J6YFhffbrLYF5dEQl0cU+t3VBK5u/o1WkWXsZawU038lWn/AXerodT/pAcrtWA4E
NQEN09WEKMhZVPhqdwhF/Gusr04mQtKt7T2v6UMQvtVglv5E7wIDAQABo4IBOTCC
ATUwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYE
FNpDStD8AcBLv1gnjHbNCoHzlC70MB8GA1UdIwQYMBaAFLAM8Eww9AVYAkj9M+VS
r0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggrBgEFBQcwAYYjaHR0cDovL29jc3Au
cm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYIKwYBBQUHMAKGLmh0dHA6Ly9jcnQu
cm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9vdGNhMi5jZXIwPwYDVR0fBDgwNjA0
oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFtYXpvbnRydXN0LmNvbS9yb290Y2Ey
LmNybDARBgNVHSAECjAIMAYGBFUdIAAwDQYJKoZIhvcNAQEMBQADggIBAEO5W+iF
yChjDyyrmiwFupVWQ0Xy2ReFNQiZq7XKVHvsLQe01moSLnxcBxioOPBKt1KkZO7w
Gcbmke0+7AxLaG/F5NPnzRtK1/pRhXQ0XdU8pVh/1/h4GoqRlZ/eN0JDarUhZPkV
kSr96LUYDTxcsAidF7zkzWfmtcJg/Aw8mi14xKVEa6aVyKu54c8kKkdlt0WaigOv
Z/xYhxp24AfoFKaIraDNdsD8q2N7eDYeN4WGLzNSlil+iFjzflI9mq1hTuI/ZNjV
rbvob6FUQ8Cc524gMjbpZCNuZ1gfXzwwhGp0AnQF6CJsWF9uwPpZEVFnnnfiWH3M
oup41EvBhqaAqOlny0sm5pI82nRUCAE3DLkJ1+eAtdQaYblZQkQrRyTuPmJEm+5y
QwdDVw6uHc5OsSj/tyhh8zJ2Xq3zgh3dMONGjJEysxGaCoIb+61PWwMy2dIarVwI
r+c+AY+3PrhgBspNdWZ87JzNHii7ksdjUSVGTTy1vGXgPYrv0lp0IMnKaZP58xiw
rDx7uTlQuPVWNOZvCaT3ZcoxTsNKNscIUe+WJjWx5hdzpv/oksDPY5ltZ0j3hlDS
D+Itk95/cNJVRM/0HpxI1SX9MTZtOSJoEDdUtOpVaOuBAvEK4gvTzdt0r5L+fuI6
o5LAuRo/LO1xVRH49KFRoaznzU3Ch9+kbPb3
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Amazon-ECDSA-256-M01.cer: CN=Amazon ECDSA 256 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M02.cer: CN=Amazon ECDSA 256 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M03.cer: CN=Amazon ECDSA 256 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M04.cer: CN=Amazon ECDSA 256 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M01.cer: CN=Amazon ECDSA 384 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M02.cer: CN=Amazon ECDSA 384 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M03.cer: CN=Amazon ECDSA 384 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M04.cer: CN=Amazon ECDSA 384 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M01.cer: CN=Amazon RSA 2048 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M02.cer: CN=Amazon RSA 2048 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M03.cer: CN=Amazon RSA 2048 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M04.cer: CN=Amazon RSA 2048 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M01.cer: CN=Amazon RSA 4096 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M02.cer: CN=Amazon RSA 4096 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M03.cer: CN=Amazon RSA 4096 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M04.cer: CN=Amazon RSA 4096 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- rootca1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2038-01-17)
- G2-RootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA1.orig.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA2.orig.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA3.orig.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA4.orig.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-ServerCA0A.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2025-10-19)
- G2-ServerCA0A.orig.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2040-10-21)
- R1-ServerCA1A.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1A.orig.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2040-10-21)
- sca1b.crt: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.orig.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2040-10-21)
- R2-ServerCA2A.orig.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3A.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2025-10-19)
- R3-ServerCA3A.orig.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3B.cer: CN=Amazon,OU=Server CA 3B,O=Amazon,C=US (Expiring: 2028-07-16)
- R4-ServerCA4A.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2025-10-19)
- R4-ServerCA4A.orig.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2040-10-21)
- rootg2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.v2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFSRootCA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2031-05-30)
- SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2037-12-31)