Microsoft Azure TLS Issuing CA 01 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 01,O=Microsoft Corporation,C=US (Intermediate Certificate, Expiring 2024-06-27) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2001%20-%20xsign.crt (in DER format )
- Serial Number : 14204314458671557774215927822652232471
- SHA-1 Fingerprint : 2f2877c5d778c31e0f29c7e371df5471bd673173
- SHA-1 Fingerprint : 2f:28:77:c5:d7:78:c3:1e:0f:29:c7:e3:71:df:54:71:bd:67:31:73
- SHA-256 Fingerprint : 24c7299864e0a2a6964f551c0e8df2461532fa8c48e4dbbb6080716691f190e5
- SHA-256 Fingerprint : 24:c7:29:98:64:e0:a2:a6:96:4f:55:1c:0e:8d:f2:46:15:32:fa:8c:48:e4:db:bb:60:80:71:66:91:f1:90:e5
- Signature Hash Algorithm : sha384
- Subject
: CN=Microsoft Azure TLS Issuing CA 01,O=Microsoft Corporation,C=US
- Country Name: US (United States of America)
- Organization: Microsoft Corporation
- Common Name: Microsoft Azure TLS Issuing CA 01
- Not Valid Before: 2020-07-29 12:30:00
- Not Valid After: 2024-06-27 23:59:59
- Issuer (Parent Certificate):
- Issuer Name: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.microsoft.com/pkiops/Docs/Content/policy/Microsoft_PKI_Services_CP_v3.1.6.pdf
- Certificate Practice Statement (CPS) URL: https://www.microsoft.com/pkiops/Docs/Content/policy/Microsoft_PKI_Services_CPS_v3.2.2.pdf
- Auditor: BDO International Limited
- Standard Audit URL: https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?attachmentid=fc6f34ea-9248-4ffe-a94b-9e870afae5b7
- Standard Audit Period Start Date: 2021.05.01
- Standard Audit Period End Date: 2022.04.30
- Standard Audit Statement Date: 2022.06.17
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: http://www.microsoft.com/pkiops/crl/Microsoft%20Azure%20TLS%20Issuing%20CA%2001.crl
- Check its issuer’s audit information: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US .
Download certificate through curl
:
curl -sSL "http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2001%20-%20xsign.crt" --output cert.crt
Download certificate through wget
:
wget -q "http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2001%20-%20xsign.crt" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
0a:af:a6:c5:ca:63:c4:51:41:ea:3b:e1:f7:c7:53:17
Signature Algorithm: sha384WithRSAEncryption
Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
Validity
Not Before: Jul 29 12:30:00 2020 GMT
Not After : Jun 27 23:59:59 2024 GMT
Subject: C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 01
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:c7:9d:70:3a:e4:5e:e7:cf:ee:9c:55:9b:51:47:
2c:33:40:f4:88:f0:1d:a3:28:69:8f:1a:ae:aa:99:
e0:67:df:e3:1c:ab:47:28:27:6a:f5:cb:ee:0d:76:
30:f0:31:f1:0e:83:77:d8:5f:07:3a:df:5b:19:05:
d0:1a:f6:c0:8b:e5:be:4c:d6:d3:59:da:35:54:a4:
1e:9f:8e:4b:78:4b:dd:6e:a7:97:f8:d8:bd:99:d5:
78:95:e3:b6:c2:98:71:72:1f:ff:a5:ad:b2:97:05:
e5:ac:25:43:d2:d9:25:c8:f0:68:7e:ca:a1:9b:8a:
f9:31:e9:5c:23:2d:cc:3f:17:35:57:66:19:6f:c9:
23:40:bf:ed:4f:c4:ed:eb:d7:9f:d5:c3:8a:8f:12:
62:41:92:33:ad:da:2c:ee:41:b4:b0:af:d3:dd:be:
d5:de:06:18:14:90:62:89:51:ab:ee:cf:77:59:11:
12:45:81:3e:6d:32:c1:9d:95:6f:c1:88:4b:90:cb:
ae:37:a5:12:40:67:28:2c:b2:dc:1d:32:42:e7:7d:
76:95:6c:89:47:84:ec:5e:6c:63:c3:1e:f7:a5:95:
c5:07:1b:3b:26:1d:11:8f:e3:ff:d5:29:0e:53:86:
fa:f0:3e:62:03:af:06:19:0a:12:38:aa:ca:05:69:
3f:c1:19:a0:c3:22:8d:ea:61:ce:0e:37:6f:94:22:
f6:be:54:ae:f6:28:a3:5f:68:47:ff:29:7f:81:c9:
34:33:c5:d3:f1:49:c0:55:4c:5b:c3:e6:08:12:c6:
b2:d8:a7:dc:d1:35:f8:d7:96:4e:41:ad:d1:3c:e9:
1e:38:0a:c9:f6:83:3f:6b:4e:e1:b0:a4:d4:6e:e9:
3f:69:03:15:3e:d2:61:f7:3c:c5:b8:02:90:54:36:
50:21:17:b1:a1:ff:7f:96:26:a4:b9:f8:60:f8:8d:
14:27:9e:22:27:5a:ef:19:df:4e:f7:38:ec:8c:72:
55:c7:07:1e:ad:45:cc:6c:a0:3a:a7:a6:af:11:04:
4c:a8:7c:86:f0:d1:e9:e0:5d:ac:1c:26:08:75:60:
66:b9:c0:aa:79:fd:dc:9b:46:c8:f2:e2:eb:e7:23:
58:65:46:b4:c6:47:c3:35:6f:5f:51:ef:48:51:bb:
ef:5b:2c:91:c1:23:27:18:90:35:00:d0:45:61:c4:
87:73:71:bc:d6:fb:90:59:40:5e:75:5d:46:49:2f:
86:3a:51:19:c8:45:85:30:33:aa:6c:25:b5:d5:a1:
58:31:32:08:c2:82:db:1f:e6:49:9b:d9:b6:56:46:
63:e8:37:ed:8e:f6:a8:7c:e2:77:0b:72:5b:ba:c1:
7a:d6:49
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
0F:20:5D:D7:A1:57:95:DB:92:CF:2B:D0:C7:C2:77:04:CE:72:80:76
X509v3 Authority Key Identifier:
keyid:4E:22:54:20:18:95:E6:E3:6E:E6:0F:FA:FA:B9:12:ED:06:17:8F:39
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
Authority Information Access:
OCSP - URI:http://ocsp.digicert.com
CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalRootG2.crt
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl3.digicert.com/DigiCertGlobalRootG2.crl
Full Name:
URI:http://crl4.digicert.com/DigiCertGlobalRootG2.crl
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 2.23.140.1.2.2
1.3.6.1.4.1.311.21.1:
...
Signature Algorithm: sha384WithRSAEncryption
25:16:f3:61:ed:08:17:54:b0:19:4a:c3:51:d9:74:66:22:7f:
62:4b:c3:87:14:20:40:5b:12:89:a2:2f:18:61:06:9f:a4:c4:
e4:32:a7:ae:ce:82:f7:1d:66:f5:a5:81:22:a6:c0:e4:86:23:
27:ae:97:de:61:91:00:ec:bc:fb:ca:a1:04:b5:f8:07:70:40:
6c:2b:d2:9c:4a:d4:06:19:94:5f:99:65:34:ee:13:d7:1e:71:
73:fb:98:13:5e:ac:c2:13:63:c1:32:54:60:55:46:09:88:0d:
b9:98:93:d7:7c:1d:34:80:3b:c6:86:d6:1a:fa:61:0d:c0:cf:
41:ab:50:7d:61:82:f2:2e:34:6d:53:3f:1c:c8:6b:1d:c9:32:
06:fd:b0:4c:fd:0f:63:71:5f:09:1a:a3:14:fd:48:c0:76:1d:
69:17:24:e7:9c:71:25:63:9f:4d:a6:2e:c5:f3:b6:6a:61:82:
44:1c:93:36:2c:60:fe:95:ef:15:b0:78:e0:79:65:f6:08:94:
24:a3:b9:25:5e:f7:22:ce:e6:6f:50:40:d3:8c:76:90:72:cd:
89:fa:43:e0:7f:23:08:39:8d:43:30:9d:b5:37:13:89:db:13:
d1:0b:fc:00:87:f8:73:48:14:55:b6:80:27:ca:ec:6d:91:9e:
15:8c:83:a1
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIF8zCCBNugAwIBAgIQCq+mxcpjxFFB6jvh98dTFzANBgkqhkiG9w0BAQwFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH
MjAeFw0yMDA3MjkxMjMwMDBaFw0yNDA2MjcyMzU5NTlaMFkxCzAJBgNVBAYTAlVT
MR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKjAoBgNVBAMTIU1pY3Jv
c29mdCBBenVyZSBUTFMgSXNzdWluZyBDQSAwMTCCAiIwDQYJKoZIhvcNAQEBBQAD
ggIPADCCAgoCggIBAMedcDrkXufP7pxVm1FHLDNA9IjwHaMoaY8arqqZ4Gff4xyr
RygnavXL7g12MPAx8Q6Dd9hfBzrfWxkF0Br2wIvlvkzW01naNVSkHp+OS3hL3W6n
l/jYvZnVeJXjtsKYcXIf/6WtspcF5awlQ9LZJcjwaH7KoZuK+THpXCMtzD8XNVdm
GW/JI0C/7U/E7evXn9XDio8SYkGSM63aLO5BtLCv092+1d4GGBSQYolRq+7Pd1kR
EkWBPm0ywZ2Vb8GIS5DLrjelEkBnKCyy3B0yQud9dpVsiUeE7F5sY8Me96WVxQcb
OyYdEY/j/9UpDlOG+vA+YgOvBhkKEjiqygVpP8EZoMMijephzg43b5Qi9r5UrvYo
o19oR/8pf4HJNDPF0/FJwFVMW8PmCBLGstin3NE1+NeWTkGt0TzpHjgKyfaDP2tO
4bCk1G7pP2kDFT7SYfc8xbgCkFQ2UCEXsaH/f5YmpLn4YPiNFCeeIida7xnfTvc4
7IxyVccHHq1FzGygOqemrxEETKh8hvDR6eBdrBwmCHVgZrnAqnn93JtGyPLi6+cj
WGVGtMZHwzVvX1HvSFG771sskcEjJxiQNQDQRWHEh3NxvNb7kFlAXnVdRkkvhjpR
GchFhTAzqmwltdWhWDEyCMKC2x/mSZvZtlZGY+g37Y72qHzidwtyW7rBetZJAgMB
AAGjggGtMIIBqTAdBgNVHQ4EFgQUDyBd16FXlduSzyvQx8J3BM5ygHYwHwYDVR0j
BBgwFoAUTiJUIBiV5uNu5g/6+rkS7QYXjzkwDgYDVR0PAQH/BAQDAgGGMB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH/AgEAMHYG
CCsGAQUFBwEBBGowaDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQu
Y29tMEAGCCsGAQUFBzAChjRodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGln
aUNlcnRHbG9iYWxSb290RzIuY3J0MHsGA1UdHwR0MHIwN6A1oDOGMWh0dHA6Ly9j
cmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5jcmwwN6A1oDOG
MWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5j
cmwwHQYDVR0gBBYwFDAIBgZngQwBAgEwCAYGZ4EMAQICMBAGCSsGAQQBgjcVAQQD
AgEAMA0GCSqGSIb3DQEBDAUAA4IBAQAlFvNh7QgXVLAZSsNR2XRmIn9iS8OHFCBA
WxKJoi8YYQafpMTkMqeuzoL3HWb1pYEipsDkhiMnrpfeYZEA7Lz7yqEEtfgHcEBs
K9KcStQGGZRfmWU07hPXHnFz+5gTXqzCE2PBMlRgVUYJiA25mJPXfB00gDvGhtYa
+mENwM9Bq1B9YYLyLjRtUz8cyGsdyTIG/bBM/Q9jcV8JGqMU/UjAdh1pFyTnnHEl
Y59Npi7F87ZqYYJEHJM2LGD+le8VsHjgeWX2CJQko7klXvcizuZvUEDTjHaQcs2J
+kPgfyMIOY1DMJ21NxOJ2xPRC/wAh/hzSBRVtoAnyuxtkZ4VjIOh
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Microsoft Azure TLS Issuing CA 02 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 02,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft Azure TLS Issuing CA 05 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 05,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft Azure TLS Issuing CA 06 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 06,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft ECC Product Root Certificate Authority 2018.crt: CN=Microsoft ECC Product Root Certificate Authority 2018,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2043-02-27)
- Microsoft ECC Root Certificate Authority 2017.crt: CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft ECC Root Certificate Authority 2017.crt: CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft ECC TS Root Certificate Authority 2018.crt: CN=Microsoft ECC TS Root Certificate Authority 2018,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2043-02-27)
- Microsoft EV ECC Root Certificate Authority 2017.crt: CN=Microsoft EV ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft EV ECC Root Certificate Authority 2017.crt: CN=Microsoft EV ECC Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft EV RSA Root Certificate Authority 2017.crt: CN=Microsoft EV RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft EV RSA Root Certificate Authority 2017.crt: CN=Microsoft EV RSA Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- microsoft identity verification root certificate authority 2020.crt: CN=Microsoft Identity Verification Root Certificate Authority 2020,O=Microsoft Corporation,C=US (Expiring: 2045-04-16)
- Microsoft Public RSA Timestamping CA 2020.crt: CN=Microsoft Public RSA Timestamping CA 2020,O=Microsoft Corporation,C=US (Expiring: 2035-11-19)
- Microsoft RSA Root Certificate Authority 2017.crt: CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft RSA Root Certificate Authority 2017.crt: CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft RSA TLS CA 01.crt: CN=Microsoft RSA TLS CA 01,O=Microsoft Corporation,C=US (Expiring: 2024-10-08)
- Microsoft RSA TLS CA 02.crt: CN=Microsoft RSA TLS CA 02,O=Microsoft Corporation,C=US (Expiring: 2024-10-08)
- MicRooCerAut_2010-06-23.crt: CN=Microsoft Root Certificate Authority 2010,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2035-06-23)
- MicRooCerAut2011_2011_03_22.crt: CN=Microsoft Root Certificate Authority 2011,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2036-03-22)
- Microsoft Time Stamp Root Certificate Authority 2014.crt: CN=Microsoft Time Stamp Root Certificate Authority 2014,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2039-10-22)