R2-ServerCA2A.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Intermediate Certificate, Expiring 2025-10-19) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/R2-ServerCA2A.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/R2-ServerCA2A.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7f:94:57:55:f1:87:a9:1f:81:63:f3:e6:24:62:01:77:ff:38
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
        Validity
            Not Before: Oct 22 00:00:00 2015 GMT
            Not After : Oct 19 00:00:00 2025 GMT
        Subject: C=US, O=Amazon, OU=Server CA 2A, CN=Amazon
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:b4:3f:c8:52:2d:ec:26:ad:9e:35:08:23:c1:43:
                    2b:59:b3:93:41:14:ca:b9:ce:d6:e7:31:ff:a4:65:
                    4a:7d:4b:6e:4b:3d:f8:cd:5b:7c:e0:0b:fe:84:a8:
                    24:d6:35:53:0c:1e:1a:bb:7b:3f:48:40:99:38:f2:
                    a6:df:05:32:e5:66:4b:8a:9d:45:9b:03:db:e8:c2:
                    b0:df:73:15:0d:d2:64:44:e0:1f:d3:25:bb:de:5f:
                    24:df:bc:4f:75:88:39:6a:0e:b1:11:79:c1:3d:0f:
                    cb:1d:8f:35:11:ae:d1:d3:a7:6e:e5:65:d4:64:5c:
                    5b:df:11:50:aa:e2:19:77:b0:79:33:8e:87:62:b1:
                    a4:2d:84:ba:75:80:bb:22:03:bb:ca:b7:ef:33:70:
                    be:00:7a:ae:76:53:26:1b:f2:be:3f:8d:d6:77:29:
                    a4:29:f0:ef:d3:e1:5c:03:09:12:a6:f1:ec:b7:92:
                    db:69:25:66:9f:95:c8:bb:79:1c:cd:8d:8e:e0:13:
                    73:4c:00:d5:57:09:e4:30:38:17:c7:d8:68:c8:34:
                    50:8e:6e:63:ec:aa:20:6e:a0:09:ec:bf:69:39:69:
                    02:cd:a1:4d:4e:66:4d:3c:0a:55:e6:98:46:76:ac:
                    8e:6a:65:44:d7:d4:7b:9e:7c:12:67:a4:c9:0f:ba:
                    01:42:c3:c6:9f:68:79:c1:d7:74:a4:2c:4e:f0:c5:
                    7f:12:65:17:43:21:ee:56:8b:0c:83:2f:5b:51:db:
                    ef:25:a7:3e:09:b0:ca:05:a2:91:e6:0f:71:9a:1f:
                    28:db:37:e8:64:3a:a1:e0:2e:5b:70:7b:03:ac:8b:
                    23:34:bb:70:99:a6:1c:a9:37:62:9e:0f:ed:45:2e:
                    39:d8:4e:07:48:01:dd:45:46:02:b6:65:70:c3:ac:
                    47:63:9e:c4:84:7d:28:4a:7f:49:78:98:53:d2:06:
                    cf:44:dd:4e:ac:2e:6b:9b:0d:15:ca:2c:b2:e9:6b:
                    f7:45:e1:e2:ae:2c:42:92:d5:b5:d8:4f:6f:22:33:
                    a0:f9:81:20:a7:ce:1a:39:1b:87:75:f2:34:03:fe:
                    c9:66:73:95:e6:46:8e:4f:8a:0d:11:c8:1c:03:68:
                    bb:b1:78:86:6e:88:9d:00:27:a6:05:85:f7:db:ac:
                    b6:05:e5:d1:10:97:47:14:fa:dd:d5:04:ae:6e:fe:
                    8d:56:91:65:ec:65:ac:14:d3:7f:25:5a:7f:c0:5d:
                    ea:e8:75:3f:e9:01:ca:ed:58:0e:04:35:01:0d:d3:
                    d5:84:28:c8:59:54:f8:6a:77:08:45:fc:6b:ac:af:
                    4e:26:42:d2:ad:ed:3d:af:e9:43:10:be:d5:60:96:
                    fe:44:ef
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                DA:43:4A:D0:FC:01:C0:4B:BF:58:27:8C:76:CD:0A:81:F3:94:2E:F4
            X509v3 Authority Key Identifier: 
                keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca2.amazontrust.com
                CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca2.amazontrust.com/rootca2.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

    Signature Algorithm: sha384WithRSAEncryption
         43:b9:5b:e8:85:c8:28:63:0f:2c:ab:9a:2c:05:ba:95:56:43:
         45:f2:d9:17:85:35:08:99:ab:b5:ca:54:7b:ec:2d:07:b4:d6:
         6a:12:2e:7c:5c:07:18:a8:38:f0:4a:b7:52:a4:64:ee:f0:19:
         c6:e6:91:ed:3e:ec:0c:4b:68:6f:c5:e4:d3:e7:cd:1b:4a:d7:
         fa:51:85:74:34:5d:d5:3c:a5:58:7f:d7:f8:78:1a:8a:91:95:
         9f:de:37:42:43:6a:b5:21:64:f9:15:91:2a:fd:e8:b5:18:0d:
         3c:5c:b0:08:9d:17:bc:e4:cd:67:e6:b5:c2:60:fc:0c:3c:9a:
         2d:78:c4:a5:44:6b:a6:95:c8:ab:b9:e1:cf:24:2a:47:65:b7:
         45:9a:8a:03:af:67:fc:58:87:1a:76:e0:07:e8:14:a6:88:ad:
         a0:cd:76:c0:fc:ab:63:7b:78:36:1e:37:85:86:2f:33:52:96:
         29:7e:88:58:f3:7e:52:3d:9a:ad:61:4e:e2:3f:64:d8:d5:ad:
         bb:e8:6f:a1:54:43:c0:9c:e7:6e:20:32:36:e9:64:23:6e:67:
         58:1f:5f:3c:30:84:6a:74:02:74:05:e8:22:6c:58:5f:6e:c0:
         fa:59:11:51:67:9e:77:e2:58:7d:cc:a2:ea:78:d4:4b:c1:86:
         a6:80:a8:e9:67:cb:4b:26:e6:92:3c:da:74:54:08:01:37:0c:
         b9:09:d7:e7:80:b5:d4:1a:61:b9:59:42:44:2b:47:24:ee:3e:
         62:44:9b:ee:72:43:07:43:57:0e:ae:1d:ce:4e:b1:28:ff:b7:
         28:61:f3:32:76:5e:ad:f3:82:1d:dd:30:e3:46:8c:91:32:b3:
         11:9a:0a:82:1b:fb:ad:4f:5b:03:32:d9:d2:1a:ad:5c:08:af:
         e7:3e:01:8f:b7:3e:b8:60:06:ca:4d:75:66:7c:ec:9c:cd:1e:
         28:bb:92:c7:63:51:25:46:4d:3c:b5:bc:65:e0:3d:8a:ef:d2:
         5a:74:20:c9:ca:69:93:f9:f3:18:b0:ac:3c:7b:b9:39:50:b8:
         f5:56:34:e6:6f:09:a4:f7:65:ca:31:4e:c3:4a:36:c7:08:51:
         ef:96:26:35:b1:e6:17:73:a6:ff:e8:92:c0:cf:63:99:6d:67:
         48:f7:86:50:d2:0f:e2:2d:93:de:7f:70:d2:55:44:cf:f4:1e:
         9c:48:d5:25:fd:31:36:6d:39:22:68:10:37:54:b4:ea:55:68:
         eb:81:02:f1:0a:e2:0b:d3:cd:db:74:af:92:fe:7e:e2:3a:a3:
         92:c0:b9:1a:3f:2c:ed:71:55:11:f8:f4:a1:51:a1:ac:e7:cd:
         4d:c2:87:df:a4:6c:f6:f7

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIGRzCCBC+gAwIBAgITBn+UV1Xxh6kfgWPz5iRiAXf/ODANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTE1MTAyMjAwMDAwMFoXDTI1MTAxOTAwMDAwMFowRjEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEVMBMGA1UECxMMU2VydmVyIENB
IDJBMQ8wDQYDVQQDEwZBbWF6b24wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIK
AoICAQC0P8hSLewmrZ41CCPBQytZs5NBFMq5ztbnMf+kZUp9S25LPfjNW3zgC/6E
qCTWNVMMHhq7ez9IQJk48qbfBTLlZkuKnUWbA9vowrDfcxUN0mRE4B/TJbveXyTf
vE91iDlqDrERecE9D8sdjzURrtHTp27lZdRkXFvfEVCq4hl3sHkzjodisaQthLp1
gLsiA7vKt+8zcL4Aeq52UyYb8r4/jdZ3KaQp8O/T4VwDCRKm8ey3kttpJWaflci7
eRzNjY7gE3NMANVXCeQwOBfH2GjINFCObmPsqiBuoAnsv2k5aQLNoU1OZk08ClXm
mEZ2rI5qZUTX1HuefBJnpMkPugFCw8afaHnB13SkLE7wxX8SZRdDIe5WiwyDL1tR
2+8lpz4JsMoFopHmD3GaHyjbN+hkOqHgLltwewOsiyM0u3CZphypN2KeD+1FLjnY
TgdIAd1FRgK2ZXDDrEdjnsSEfShKf0l4mFPSBs9E3U6sLmubDRXKLLLpa/dF4eKu
LEKS1bXYT28iM6D5gSCnzho5G4d18jQD/slmc5XmRo5Pig0RyBwDaLuxeIZuiJ0A
J6YFhffbrLYF5dEQl0cU+t3VBK5u/o1WkWXsZawU038lWn/AXerodT/pAcrtWA4E
NQEN09WEKMhZVPhqdwhF/Gusr04mQtKt7T2v6UMQvtVglv5E7wIDAQABo4IBOTCC
ATUwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYE
FNpDStD8AcBLv1gnjHbNCoHzlC70MB8GA1UdIwQYMBaAFLAM8Eww9AVYAkj9M+VS
r0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggrBgEFBQcwAYYjaHR0cDovL29jc3Au
cm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYIKwYBBQUHMAKGLmh0dHA6Ly9jcnQu
cm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9vdGNhMi5jZXIwPwYDVR0fBDgwNjA0
oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFtYXpvbnRydXN0LmNvbS9yb290Y2Ey
LmNybDARBgNVHSAECjAIMAYGBFUdIAAwDQYJKoZIhvcNAQEMBQADggIBAEO5W+iF
yChjDyyrmiwFupVWQ0Xy2ReFNQiZq7XKVHvsLQe01moSLnxcBxioOPBKt1KkZO7w
Gcbmke0+7AxLaG/F5NPnzRtK1/pRhXQ0XdU8pVh/1/h4GoqRlZ/eN0JDarUhZPkV
kSr96LUYDTxcsAidF7zkzWfmtcJg/Aw8mi14xKVEa6aVyKu54c8kKkdlt0WaigOv
Z/xYhxp24AfoFKaIraDNdsD8q2N7eDYeN4WGLzNSlil+iFjzflI9mq1hTuI/ZNjV
rbvob6FUQ8Cc524gMjbpZCNuZ1gfXzwwhGp0AnQF6CJsWF9uwPpZEVFnnnfiWH3M
oup41EvBhqaAqOlny0sm5pI82nRUCAE3DLkJ1+eAtdQaYblZQkQrRyTuPmJEm+5y
QwdDVw6uHc5OsSj/tyhh8zJ2Xq3zgh3dMONGjJEysxGaCoIb+61PWwMy2dIarVwI
r+c+AY+3PrhgBspNdWZ87JzNHii7ksdjUSVGTTy1vGXgPYrv0lp0IMnKaZP58xiw
rDx7uTlQuPVWNOZvCaT3ZcoxTsNKNscIUe+WJjWx5hdzpv/oksDPY5ltZ0j3hlDS
D+Itk95/cNJVRM/0HpxI1SX9MTZtOSJoEDdUtOpVaOuBAvEK4gvTzdt0r5L+fuI6
o5LAuRo/LO1xVRH49KFRoaznzU3Ch9+kbPb3
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06