D-Trust.HBA-CA5.crt: CN=D-Trust.HBA-CA5,OU=Heilberufsausweis-CA der Telematikinfrastruktur,O=D-TRUST GmbH,C=DE (Intermediate Certificate, Expiring 2029-03-08) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.d-trust.net/cgi-bin/D-Trust.HBA-CA5.crt" --output cert.crt

Download certificate through wget:

wget -q "https://www.d-trust.net/cgi-bin/D-Trust.HBA-CA5.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 11 (0xb)
    Signature Algorithm: ecdsa-with-SHA256
        Issuer: C=DE, O=gematik GmbH, OU=Zentrale Root-CA der Telematikinfrastruktur, CN=GEM.RCA4
        Validity
            Not Before: Mar 10 11:54:04 2021 GMT
            Not After : Mar  8 11:54:03 2029 GMT
        Subject: C=DE, O=D-TRUST GmbH, OU=Heilberufsausweis-CA der Telematikinfrastruktur, CN=D-Trust.HBA-CA5
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:02:89:0e:35:f9:17:cc:11:82:ae:e6:4e:c8:96:
                    f9:48:85:02:d4:97:c8:35:d6:78:fb:77:93:4c:79:
                    99:c6:3d:7a:40:59:58:89:55:86:30:8a:8a:35:a1:
                    da:7f:2f:f8:2d:64:14:c6:32:c5:e1:00:eb:25:c6:
                    97:a3:00:8a:cb
                ASN1 OID: brainpoolP256r1
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                67:2F:2E:09:F2:16:E0:DB:45:C0:75:E4:D3:58:32:01:43:5F:0C:07
            X509v3 Authority Key Identifier: 
                keyid:80:61:70:19:1C:38:ED:E2:6B:E4:A1:2E:AB:22:3E:75:C9:94:FE:7D

            Authority Information Access: 
                OCSP - URI:http://ocsp.root-ca.ti-dienste.de/ocsp

            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Certificate Policies: 
                Policy: 1.2.276.0.76.4.145

    Signature Algorithm: ecdsa-with-SHA256
         30:44:02:20:25:ac:11:47:9d:f5:51:4e:48:69:af:b0:98:3a:
         f4:9c:02:de:54:5b:e8:d4:4a:22:33:bf:12:31:ed:38:52:4c:
         02:20:66:63:6a:7e:49:26:c2:cc:37:0d:65:9b:5a:0d:3b:4b:
         13:24:01:10:cc:7b:e6:7a:ec:35:18:6f:01:e8:54:89

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIClzCCAj6gAwIBAgIBCzAKBggqhkjOPQQDAjBtMQswCQYDVQQGEwJERTEVMBMG
A1UECgwMZ2VtYXRpayBHbWJIMTQwMgYDVQQLDCtaZW50cmFsZSBSb290LUNBIGRl
ciBUZWxlbWF0aWtpbmZyYXN0cnVrdHVyMREwDwYDVQQDDAhHRU0uUkNBNDAeFw0y
MTAzMTAxMTU0MDRaFw0yOTAzMDgxMTU0MDNaMHgxCzAJBgNVBAYTAkRFMRUwEwYD
VQQKDAxELVRSVVNUIEdtYkgxODA2BgNVBAsML0hlaWxiZXJ1ZnNhdXN3ZWlzLUNB
IGRlciBUZWxlbWF0aWtpbmZyYXN0cnVrdHVyMRgwFgYDVQQDDA9ELVRydXN0LkhC
QS1DQTUwWjAUBgcqhkjOPQIBBgkrJAMDAggBAQcDQgAEAokONfkXzBGCruZOyJb5
SIUC1JfINdZ4+3eTTHmZxj16QFlYiVWGMIqKNaHafy/4LWQUxjLF4QDrJcaXowCK
y6OBwjCBvzAdBgNVHQ4EFgQUZy8uCfIW4NtFwHXk01gyAUNfDAcwHwYDVR0jBBgw
FoAUgGFwGRw47eJr5KEuqyI+dcmU/n0wQgYIKwYBBQUHAQEENjA0MDIGCCsGAQUF
BzABhiZodHRwOi8vb2NzcC5yb290LWNhLnRpLWRpZW5zdGUuZGUvb2NzcDASBgNV
HRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBBjAVBgNVHSAEDjAMMAoGCCqC
FABMBIERMAoGCCqGSM49BAMCA0cAMEQCICWsEUed9VFOSGmvsJg69JwC3lRb6NRK
IjO/EjHtOFJMAiBmY2p+SSbCzDcNZZtaDTtLEyQBEMx75nrsNRhvAehUiQ==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06