Amazon-RSA-2048-M01.cer: CN=Amazon RSA 2048 M01,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-2048-M01.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-RSA-2048-M01.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:38:0b:9d:66:88:a3:3b:1e:d9:bf:9c:cd:a6:8e:0e:0f
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 1
        Validity
            Not Before: Aug 23 22:21:28 2022 GMT
            Not After : Aug 23 22:21:28 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon RSA 2048 M01
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:eb:71:2c:a9:cb:1f:88:28:92:32:30:af:8a:57:
                    0f:78:b7:37:25:95:55:87:ac:67:5c:97:d3:22:c8:
                    da:a2:14:67:6b:7c:f0:67:da:e2:03:2a:b3:56:12:
                    5d:c6:b5:47:f9:67:08:a7:93:7a:95:92:18:0f:b4:
                    f9:f9:10:36:9a:7f:2f:80:b6:4f:ba:13:4e:c7:5d:
                    53:1e:e0:dd:96:33:07:20:d3:96:bc:12:e4:74:50:
                    42:a1:05:13:73:b5:4f:9b:44:24:fe:2d:7f:ed:bc:
                    22:85:ec:36:21:33:97:75:06:ce:27:18:82:dc:e3:
                    d9:c5:82:07:8d:5e:26:01:26:26:67:1f:d9:3f:13:
                    cf:32:ba:6b:ad:78:64:fc:aa:ff:0e:02:3c:07:df:
                    9c:05:78:72:8c:fd:ea:75:b7:03:28:84:da:e8:6e:
                    07:8c:d0:50:85:ef:81:54:b2:71:6e:ec:6d:62:ef:
                    8f:94:c3:5e:e9:c4:a4:d0:91:c0:2e:24:91:98:ca:
                    ee:ba:25:8e:d4:f6:71:b6:fb:5b:6b:38:06:48:37:
                    47:8d:86:dc:f2:ea:06:fb:76:37:7d:9e:ff:42:4e:
                    4d:58:82:93:cf:e2:71:c2:78:b1:7a:ab:4b:5b:94:
                    37:88:81:e4:d9:af:24:ae:f8:72:c5:65:fb:4b:b4:
                    51:e7
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                81:B8:0E:63:8A:89:12:18:E5:FA:3B:3B:50:95:9F:E6:E5:90:13:85
            X509v3 Authority Key Identifier: 
                keyid:84:18:CC:85:34:EC:BC:0C:94:94:2E:08:59:9C:C7:B2:10:4E:0A:08

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca1.amazontrust.com
                CA Issuers - URI:http://crt.rootca1.amazontrust.com/rootca1.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca1.amazontrust.com/rootca1.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha256WithRSAEncryption
         ad:00:de:02:05:23:2e:06:32:62:b4:6b:b1:94:16:e4:11:40:
         de:2b:fa:59:c1:35:ef:e0:aa:8f:2b:41:b9:d1:f3:87:39:00:
         1d:f2:3d:b5:a7:47:0c:06:06:c6:91:f3:07:57:02:d4:ed:bd:
         17:c1:90:9a:bf:48:75:a2:07:4f:30:dd:4a:6a:42:b5:0d:3d:
         15:c0:0f:fe:84:5b:c6:3c:99:cc:57:52:b1:d8:6e:12:d5:96:
         92:93:4b:94:e5:07:e8:89:82:08:6a:7a:34:d4:9e:64:e1:3d:
         87:6a:92:90:9a:63:a1:4b:f8:8f:b6:ea:34:d3:05:be:20:c2:
         de:06:e2:8c:9f:73:8b:9f:4d:39:85:ca:ce:19:36:9d:85:c9:
         9e:c9:f8:50:3f:b6:7e:88:a1:ef:ca:84:06:8b:50:b4:0a:5c:
         a6:1c:44:f1:fd:c8:61:40:60:f2:61:25:aa:07:f4:c7:c2:73:
         75:e4:0c:0b:42:8d:04:e5:5f:44:48:99:5b:7b:89:81:96:a7:
         88:9d:4b:0d:62:e8:04:c4:d7:fe:b4:e8:b2:6d:ca:ec:c0:1c:
         bc:38:5b:1d:df:85:ce:5b:7a:e3:49:4b:6c:b9:a7:dd:f4:05:
         b2:49:ad:e1:c5:14:6b:c2:cc:eb:cd:7f:d6:58:69:ba:c3:20:
         7e:7f:b0:b8

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEXjCCA0agAwIBAgITB3MSOAudZoijOx7Zv5zNpo4ODzANBgkqhkiG9w0BAQsF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAxMB4XDTIyMDgyMzIyMjEyOFoXDTMwMDgyMzIyMjEyOFowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSAyMDQ4IE0wMTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOtxLKnL
H4gokjIwr4pXD3i3NyWVVYesZ1yX0yLI2qIUZ2t88Gfa4gMqs1YSXca1R/lnCKeT
epWSGA+0+fkQNpp/L4C2T7oTTsddUx7g3ZYzByDTlrwS5HRQQqEFE3O1T5tEJP4t
f+28IoXsNiEzl3UGzicYgtzj2cWCB41eJgEmJmcf2T8TzzK6a614ZPyq/w4CPAff
nAV4coz96nW3AyiE2uhuB4zQUIXvgVSycW7sbWLvj5TDXunEpNCRwC4kkZjK7rol
jtT2cbb7W2s4Bkg3R42G3PLqBvt2N32e/0JOTViCk8/iccJ4sXqrS1uUN4iB5Nmv
JK74csVl+0u0UecCAwEAAaOCAVowggFWMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYD
VR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNV
HQ4EFgQUgbgOY4qJEhjl+js7UJWf5uWQE4UwHwYDVR0jBBgwFoAUhBjMhTTsvAyU
lC4IWZzHshBOCggwewYIKwYBBQUHAQEEbzBtMC8GCCsGAQUFBzABhiNodHRwOi8v
b2NzcC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbTA6BggrBgEFBQcwAoYuaHR0cDov
L2NydC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbS9yb290Y2ExLmNlcjA/BgNVHR8E
ODA2MDSgMqAwhi5odHRwOi8vY3JsLnJvb3RjYTEuYW1hem9udHJ1c3QuY29tL3Jv
b3RjYTEuY3JsMBMGA1UdIAQMMAowCAYGZ4EMAQIBMA0GCSqGSIb3DQEBCwUAA4IB
AQCtAN4CBSMuBjJitGuxlBbkEUDeK/pZwTXv4KqPK0G50fOHOQAd8j21p0cMBgbG
kfMHVwLU7b0XwZCav0h1ogdPMN1KakK1DT0VwA/+hFvGPJnMV1Kx2G4S1ZaSk0uU
5QfoiYIIano01J5k4T2HapKQmmOhS/iPtuo00wW+IMLeBuKMn3OLn005hcrOGTad
hcmeyfhQP7Z+iKHvyoQGi1C0ClymHETx/chhQGDyYSWqB/THwnN15AwLQo0E5V9E
SJlbe4mBlqeInUsNYugExNf+tOiybcrswBy8OFsd34XOW3rjSUtsuafd9AWySa3h
xRRrwszrzX/WWGm6wyB+f7C4
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06