R1-ServerCA1B.orig.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Intermediate Certificate, Expiring 2040-10-21) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/R1-ServerCA1B.orig.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/R1-ServerCA1B.orig.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7b:50:5c:2a:65:27:bc:1e:be:2d:a2:d1:99:98:ed:b8:9b:2c
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 1
        Validity
            Not Before: Oct 21 22:24:34 2015 GMT
            Not After : Oct 21 22:24:34 2040 GMT
        Subject: C=US, O=Amazon, OU=Server CA 1B, CN=Amazon
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:c2:4e:16:67:dd:ce:bc:6a:c8:37:5a:ec:3a:30:
                    b0:1d:e6:d1:12:e8:12:28:48:cc:e8:29:c1:b9:6e:
                    53:d5:a3:eb:03:39:1a:cc:77:87:f6:01:b9:d9:70:
                    cc:cf:6b:8d:e3:e3:03:71:86:99:6d:cb:a6:94:2a:
                    4e:13:d6:a7:bd:04:ec:0a:16:3c:0a:eb:39:b1:c4:
                    b5:58:a3:b6:c7:56:25:ec:3e:52:7a:a8:e3:29:16:
                    07:b9:6e:50:cf:fb:5f:31:f8:1d:ba:03:4a:62:89:
                    03:ae:3e:47:f2:0f:27:91:e3:14:20:85:f8:fa:e9:
                    8a:35:f5:5f:9e:99:4d:e7:6b:37:ef:a4:50:3e:44:
                    ec:fa:5a:85:66:07:9c:7e:17:6a:55:f3:17:8a:35:
                    1e:ee:e9:ac:c3:75:4e:58:55:7d:53:6b:0a:6b:9b:
                    14:42:d7:e5:ac:01:89:b3:ea:a3:fe:cf:c0:2b:0c:
                    84:c2:d8:53:15:cb:67:f0:d0:88:ca:3a:d1:17:73:
                    f5:5f:9a:d4:c5:72:1e:7e:01:f1:98:30:63:2a:aa:
                    f2:7a:2d:c5:e2:02:1a:86:e5:32:3e:0e:bd:11:b4:
                    cf:3c:93:ef:17:50:10:9e:43:c2:06:2a:e0:0d:68:
                    be:d3:88:8b:4a:65:8c:4a:d4:c3:2e:4c:9b:55:f4:
                    86:e5
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                59:A4:66:06:52:A0:7B:95:92:3C:A3:94:07:27:96:74:5B:F9:3D:D0
            X509v3 Authority Key Identifier: 
                keyid:84:18:CC:85:34:EC:BC:0C:94:94:2E:08:59:9C:C7:B2:10:4E:0A:08

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca1.amazontrust.com
                CA Issuers - URI:http://crl.rootca1.amazontrust.com/rootca1.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca1.amazontrust.com/rootca1.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha256WithRSAEncryption
         1f:b1:a1:0a:c2:7d:7b:0e:30:1b:8b:f0:e2:7b:47:ad:9f:e3:
         c4:81:f6:3f:23:ab:3c:34:b5:a4:c4:60:0e:51:f5:b6:a3:eb:
         d5:a3:03:40:45:15:63:68:81:9d:ae:10:1f:79:61:e4:64:8e:
         aa:da:92:34:c7:f2:09:62:6c:a6:99:c5:9a:65:a5:bf:d9:1e:
         c3:bd:00:ed:c4:29:05:91:56:b1:51:e1:ef:10:d9:ba:23:2a:
         95:85:fe:90:e6:83:75:da:40:d2:ac:9a:33:cf:1e:c8:ee:d1:
         e3:84:12:bb:57:95:e8:4f:24:b8:35:4e:04:85:2c:b3:1a:08:
         f6:c7:a6:b1:0d:dd:61:1d:18:db:94:4a:49:f3:42:e8:89:79:
         66:50:3c:e9:ba:d0:57:c8:ee:66:91:ca:e9:95:c5:6f:94:82:
         62:5a:62:a3:ac:39:f6:cf:32:b1:0d:7e:67:c2:f9:2c:92:92:
         23:62:52:5c:ad:0b:b8:88:25:f5:fd:8c:19:d7:23:6a:17:d2:
         eb:ca:39:62:96:98:47:08:00:a2:1d:b8:48:46:71:9f:37:c8:
         fc:28:b0:d5:99:6c:93:60:c9:3c:57:ee:a3:d0:b2:38:fb:8c:
         c5:87:6b:a9:a8:63:10:1c:bd:d5:15:51:56:05:e9:3a:bc:20:
         d6:84:1f:db

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIESTCCAzGgAwIBAgITBntQXCplJ7wevi2i0ZmY7bibLDANBgkqhkiG9w0BAQsF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAxMB4XDTE1MTAyMTIyMjQzNFoXDTQwMTAyMTIyMjQzNFowRjEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEVMBMGA1UECxMMU2VydmVyIENB
IDFCMQ8wDQYDVQQDEwZBbWF6b24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDCThZn3c68asg3Wuw6MLAd5tES6BIoSMzoKcG5blPVo+sDORrMd4f2AbnZ
cMzPa43j4wNxhplty6aUKk4T1qe9BOwKFjwK6zmxxLVYo7bHViXsPlJ6qOMpFge5
blDP+18x+B26A0piiQOuPkfyDyeR4xQghfj66Yo19V+emU3nazfvpFA+ROz6WoVm
B5x+F2pV8xeKNR7u6azDdU5YVX1TawprmxRC1+WsAYmz6qP+z8ArDITC2FMVy2fw
0IjKOtEXc/VfmtTFch5+AfGYMGMqqvJ6LcXiAhqG5TI+Dr0RtM88k+8XUBCeQ8IG
KuANaL7TiItKZYxK1MMuTJtV9IblAgMBAAGjggE7MIIBNzASBgNVHRMBAf8ECDAG
AQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQUWaRmBlKge5WSPKOUByeW
dFv5PdAwHwYDVR0jBBgwFoAUhBjMhTTsvAyUlC4IWZzHshBOCggwewYIKwYBBQUH
AQEEbzBtMC8GCCsGAQUFBzABhiNodHRwOi8vb2NzcC5yb290Y2ExLmFtYXpvbnRy
dXN0LmNvbTA6BggrBgEFBQcwAoYuaHR0cDovL2NybC5yb290Y2ExLmFtYXpvbnRy
dXN0LmNvbS9yb290Y2ExLmNlcjA/BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vY3Js
LnJvb3RjYTEuYW1hem9udHJ1c3QuY29tL3Jvb3RjYTEuY3JsMBMGA1UdIAQMMAow
CAYGZ4EMAQIBMA0GCSqGSIb3DQEBCwUAA4IBAQAfsaEKwn17DjAbi/Die0etn+PE
gfY/I6s8NLWkxGAOUfW2o+vVowNARRVjaIGdrhAfeWHkZI6q2pI0x/IJYmymmcWa
ZaW/2R7DvQDtxCkFkVaxUeHvENm6IyqVhf6Q5oN12kDSrJozzx7I7tHjhBK7V5Xo
TyS4NU4EhSyzGgj2x6axDd1hHRjblEpJ80LoiXlmUDzputBXyO5mkcrplcVvlIJi
WmKjrDn2zzKxDX5nwvkskpIjYlJcrQu4iCX1/YwZ1yNqF9LryjlilphHCACiHbhI
RnGfN8j8KLDVmWyTYMk8V+6j0LI4+4zFh2upqGMQHL3VFVFWBek6vCDWhB/b
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06