Amazon-RSA-4096-M02.cer: CN=Amazon RSA 4096 M02,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: https://www.amazontrust.com/repository/Amazon-RSA-4096-M02.cer (in DER format )
- Serial Number : 166129375377596743052351347119491338153938137
- SHA-1 Fingerprint : 5de786fa3f380100584a61487a78a3d15099b648
- SHA-1 Fingerprint : 5d:e7:86:fa:3f:38:01:00:58:4a:61:48:7a:78:a3:d1:50:99:b6:48
- SHA-256 Fingerprint : 2cc39f6789b967b0282aeaca4548f602a1b274e90d260773e9e7b0f7c0f13432
- SHA-256 Fingerprint : 2c:c3:9f:67:89:b9:67:b0:28:2a:ea:ca:45:48:f6:02:a1:b2:74:e9:0d:26:07:73:e9:e7:b0:f7:c0:f1:34:32
- Signature Hash Algorithm : sha384
- Subject
: CN=Amazon RSA 4096 M02,O=Amazon,C=US
- Country Name: US (United States of America)
- Organization: Amazon
- Common Name: Amazon RSA 4096 M02
- Not Valid Before: 2022-08-23 22:29:13
- Not Valid After: 2030-08-23 22:29:13
- Issuer (Parent Certificate):
- Issuer Name: CN=Amazon Root CA 2,O=Amazon,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cp-v5-12-Final.pdf
- Certificate Practice Statement (CPS) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cps-v5-12-Final.pdf
- Auditor: BDO International Limited
- Standard Audit URL: https://bugzilla.mozilla.org/attachment.cgi?id=9309728
- Standard Audit Period Start Date: 2021.10.01
- Standard Audit Period End Date: 2022.09.30
- Standard Audit Statement Date: 2022.12.22
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: http://crl.r4m02.amazontrust.com/r4m02.crl
- Check its issuer’s audit information: CN=Amazon Root CA 2,O=Amazon,C=US .
Download certificate through curl
:
curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-4096-M02.cer" --output cert.crt
Download certificate through wget
:
wget -q "https://www.amazontrust.com/repository/Amazon-RSA-4096-M02.cer" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
07:73:12:5b:0c:34:c3:c9:40:29:9a:9f:04:a3:9e:5a:52:cc:d9
Signature Algorithm: sha384WithRSAEncryption
Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
Validity
Not Before: Aug 23 22:29:13 2022 GMT
Not After : Aug 23 22:29:13 2030 GMT
Subject: C=US, O=Amazon, CN=Amazon RSA 4096 M02
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:c1:8c:97:fa:59:d4:eb:31:1d:8f:60:c3:f6:1f:
74:e3:78:9a:6a:c0:36:43:f0:8b:bc:f6:76:31:c0:
e4:42:ed:fe:f4:48:dd:2b:b4:95:ee:8e:a2:2a:4b:
7f:4d:e2:ca:80:a7:63:2e:18:ae:97:d3:6e:1c:83:
ae:21:3c:34:9a:69:b3:63:83:27:95:b5:87:4a:f3:
e8:53:35:43:92:6d:df:9c:1f:93:ee:02:11:f0:13:
05:37:a0:1d:59:54:27:4a:c9:83:32:b9:62:5f:e3:
ae:4d:76:66:c0:b8:65:e4:67:e7:8b:21:b3:37:0a:
e9:b1:e3:e0:b6:48:1d:78:6b:60:82:1f:7a:d0:4c:
30:3f:15:ee:19:61:77:9e:00:72:51:16:ba:d5:15:
78:11:23:91:20:b3:0d:29:3e:a5:02:88:8c:22:f4:
72:ba:af:45:23:ef:50:da:f2:fc:15:7a:e7:37:c6:
99:c7:92:63:1a:5c:2e:65:7b:93:b4:a9:c2:9a:3e:
d7:3f:30:f8:e7:5f:9f:1d:af:b2:6e:e8:94:f9:5d:
7d:a4:e1:aa:4e:9f:5c:1b:48:9c:e4:65:e0:47:f7:
db:11:77:54:34:f5:dd:47:97:b5:03:e8:94:58:67:
a7:c5:0e:72:2e:b8:6d:6f:91:f2:d6:ed:1a:95:17:
20:0f:03:86:bf:12:81:83:c7:e8:d5:b8:8e:15:03:
e3:e0:06:f3:27:ab:f1:cb:40:d4:79:7d:b6:af:ba:
b5:8a:f6:ea:ad:f2:b8:22:ee:e6:bc:09:75:f3:06:
eb:7e:1f:58:84:57:4a:3f:86:26:2f:12:7c:07:46:
b4:fc:97:c2:ee:7b:f7:d3:56:7a:c5:78:bd:49:2b:
91:25:dd:20:12:b8:4d:00:ae:2b:e8:f1:68:9e:58:
f9:9a:36:97:71:85:b1:6c:8c:3c:d3:91:2e:3a:10:
5d:b8:c5:e8:a0:32:8d:3c:88:08:ba:bd:57:3a:10:
2a:1c:b1:e0:b9:76:08:da:d0:bf:c0:b1:aa:d0:c2:
1a:f5:e2:f6:44:44:25:80:05:ea:5b:1c:38:1d:31:
82:50:00:17:99:67:75:c6:8d:91:51:c4:54:e3:1d:
83:d6:59:b5:d2:72:c0:75:a6:f1:07:9d:d5:6b:72:
da:aa:fe:86:60:3b:6e:8a:16:40:d4:44:d7:69:d6:
d6:78:82:e4:3e:1c:3f:6c:a4:3c:af:47:4a:06:fb:
c5:67:54:17:7d:95:89:d5:1c:f6:d3:4a:33:ac:4a:
8d:27:7f:47:fb:4f:a7:e5:c0:c9:b3:52:c0:4a:28:
3e:dd:ff:3a:fc:a1:a5:54:63:2e:e5:a8:aa:a6:c2:
95:32:9d
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Subject Key Identifier:
9E:71:1F:1A:1D:93:A9:D9:2D:8E:CC:48:53:3F:03:54:F3:9E:E6:66
X509v3 Authority Key Identifier:
keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52
Authority Information Access:
OCSP - URI:http://ocsp.rootca2.amazontrust.com
CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.rootca2.amazontrust.com/rootca2.crl
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Signature Algorithm: sha384WithRSAEncryption
97:51:a0:29:73:a7:d2:3d:4c:59:3d:4a:25:54:9e:c1:0d:bc:
48:66:e2:7b:75:30:66:3d:5d:32:c8:c9:6a:60:ab:40:f9:f6:
9e:04:8d:6c:b9:bd:fa:e9:45:88:10:d4:f3:12:91:f5:9c:77:
b5:9a:6c:e7:92:14:29:62:d4:3e:47:cc:0b:eb:e4:57:b6:ac:
0c:1a:aa:cf:31:34:17:f3:24:7a:48:0f:7c:e8:f1:d5:5f:52:
e9:67:e0:de:c4:a0:fb:d2:9c:96:eb:ab:5c:51:25:ae:ea:8a:
7c:e9:b8:72:a9:a4:57:be:fa:5f:51:be:01:a6:90:ee:69:54:
82:20:98:8b:a3:6a:45:04:b2:86:7f:33:ac:a9:0d:9d:b3:ba:
40:be:5a:f4:80:82:e3:b9:22:65:84:40:47:f8:51:bd:93:ad:
d7:54:14:2b:9b:42:31:72:57:a3:48:8e:e1:72:a4:32:ef:a3:
76:77:a1:3f:59:21:e3:1b:99:85:8c:e7:22:02:8a:e8:c2:48:
21:31:48:fc:98:fc:f5:4e:12:38:f9:dc:ca:e4:bd:e2:c5:2e:
13:61:2a:be:f3:bf:b7:cd:6a:7a:87:b2:eb:04:e1:cf:98:91:
6d:4f:f4:0a:f0:c5:9d:33:20:79:b5:86:51:9d:94:64:9f:9a:
cf:fa:db:dc:a6:17:19:f5:56:6a:c2:c8:a2:79:2f:61:3e:f3:
bc:73:86:34:00:3d:a1:0f:13:4e:03:ce:98:f7:d2:57:27:e9:
a6:52:ad:3b:f6:b2:6d:6a:79:41:21:f6:72:c2:30:ba:fc:39:
76:49:a9:91:ce:36:88:3e:7b:5c:7a:1b:e4:b6:cc:26:0f:7d:
cf:7b:d0:06:6a:1d:fe:2a:66:3a:93:43:f7:9f:c1:78:0d:a6:
96:50:59:81:9e:77:4b:49:ef:0d:70:f3:6f:34:7d:15:df:35:
3c:0c:fd:42:bb:a8:74:e2:4a:70:3e:a9:94:a4:23:66:39:0b:
cc:d8:75:bf:f4:68:08:53:bc:92:22:46:13:85:01:31:33:3c:
15:49:34:0d:71:f8:6c:02:c8:23:8c:30:98:37:a5:ad:25:2e:
94:ab:c3:4c:3c:59:bc:f1:78:75:b1:17:20:23:4f:77:9d:44:
30:63:e0:11:3c:70:6e:83:95:f9:bc:d6:15:52:34:21:64:3c:
3e:16:76:56:e3:0f:0e:4d:ad:68:e3:29:36:cb:8b:b6:56:1c:
da:dc:0f:6f:da:ff:1e:f8:2f:ec:6e:be:22:da:41:1d:9c:0e:
56:dd:68:23:7a:47:6e:33:29:ec:fd:e9:39:94:8f:af:a1:b5:
5a:43:72:f6:65:fc:ad:57
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIGXjCCBEagAwIBAgITB3MSWww0w8lAKZqfBKOeWlLM2TANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTIyMDgyMzIyMjkxM1oXDTMwMDgyMzIyMjkxM1owPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSA0MDk2IE0wMjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAMGMl/pZ
1OsxHY9gw/YfdON4mmrANkPwi7z2djHA5ELt/vRI3Su0le6OoipLf03iyoCnYy4Y
rpfTbhyDriE8NJpps2ODJ5W1h0rz6FM1Q5Jt35wfk+4CEfATBTegHVlUJ0rJgzK5
Yl/jrk12ZsC4ZeRn54shszcK6bHj4LZIHXhrYIIfetBMMD8V7hlhd54AclEWutUV
eBEjkSCzDSk+pQKIjCL0crqvRSPvUNry/BV65zfGmceSYxpcLmV7k7Spwpo+1z8w
+Odfnx2vsm7olPldfaThqk6fXBtInORl4Ef32xF3VDT13UeXtQPolFhnp8UOci64
bW+R8tbtGpUXIA8Dhr8SgYPH6NW4jhUD4+AG8yer8ctA1Hl9tq+6tYr26q3yuCLu
5rwJdfMG634fWIRXSj+GJi8SfAdGtPyXwu5799NWesV4vUkrkSXdIBK4TQCuK+jx
aJ5Y+Zo2l3GFsWyMPNORLjoQXbjF6KAyjTyICLq9VzoQKhyx4Ll2CNrQv8CxqtDC
GvXi9kREJYAF6lscOB0xglAAF5lndcaNkVHEVOMdg9ZZtdJywHWm8Qed1Wty2qr+
hmA7booWQNRE12nW1niC5D4cP2ykPK9HSgb7xWdUF32VidUc9tNKM6xKjSd/R/tP
p+XAybNSwEooPt3/OvyhpVRjLuWoqqbClTKdAgMBAAGjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFJ5xHxodk6nZLY7MSFM/A1TznuZmMB8GA1Ud
IwQYMBaAFLAM8Eww9AVYAkj9M+VSr0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9v
dGNhMi5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFt
YXpvbnRydXN0LmNvbS9yb290Y2EyLmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAN
BgkqhkiG9w0BAQwFAAOCAgEAl1GgKXOn0j1MWT1KJVSewQ28SGbie3UwZj1dMsjJ
amCrQPn2ngSNbLm9+ulFiBDU8xKR9Zx3tZps55IUKWLUPkfMC+vkV7asDBqqzzE0
F/MkekgPfOjx1V9S6Wfg3sSg+9KcluurXFElruqKfOm4cqmkV776X1G+AaaQ7mlU
giCYi6NqRQSyhn8zrKkNnbO6QL5a9ICC47kiZYRAR/hRvZOt11QUK5tCMXJXo0iO
4XKkMu+jdnehP1kh4xuZhYznIgKK6MJIITFI/Jj89U4SOPncyuS94sUuE2EqvvO/
t81qeoey6wThz5iRbU/0CvDFnTMgebWGUZ2UZJ+az/rb3KYXGfVWasLIonkvYT7z
vHOGNAA9oQ8TTgPOmPfSVyfpplKtO/aybWp5QSH2csIwuvw5dkmpkc42iD57XHob
5LbMJg99z3vQBmod/ipmOpND95/BeA2mllBZgZ53S0nvDXDzbzR9Fd81PAz9Qruo
dOJKcD6plKQjZjkLzNh1v/RoCFO8kiJGE4UBMTM8FUk0DXH4bALII4wwmDelrSUu
lKvDTDxZvPF4dbEXICNPd51EMGPgETxwboOV+bzWFVI0IWQ8PhZ2VuMPDk2taOMp
NsuLtlYc2twPb9r/Hvgv7G6+ItpBHZwOVt1oI3pHbjMp7P3pOZSPr6G1WkNy9mX8
rVc=
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Amazon-ECDSA-256-M01.cer: CN=Amazon ECDSA 256 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M02.cer: CN=Amazon ECDSA 256 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M03.cer: CN=Amazon ECDSA 256 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M04.cer: CN=Amazon ECDSA 256 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M01.cer: CN=Amazon ECDSA 384 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M02.cer: CN=Amazon ECDSA 384 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M03.cer: CN=Amazon ECDSA 384 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M04.cer: CN=Amazon ECDSA 384 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M01.cer: CN=Amazon RSA 2048 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M02.cer: CN=Amazon RSA 2048 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M03.cer: CN=Amazon RSA 2048 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M04.cer: CN=Amazon RSA 2048 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M01.cer: CN=Amazon RSA 4096 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M03.cer: CN=Amazon RSA 4096 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M04.cer: CN=Amazon RSA 4096 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- rootca1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2038-01-17)
- G2-RootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA1.orig.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA2.orig.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA3.orig.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA4.orig.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-ServerCA0A.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2025-10-19)
- G2-ServerCA0A.orig.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2040-10-21)
- R1-ServerCA1A.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1A.orig.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2040-10-21)
- sca1b.crt: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.orig.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2040-10-21)
- R2-ServerCA2A.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2025-10-19)
- R2-ServerCA2A.orig.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3A.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2025-10-19)
- R3-ServerCA3A.orig.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3B.cer: CN=Amazon,OU=Server CA 3B,O=Amazon,C=US (Expiring: 2028-07-16)
- R4-ServerCA4A.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2025-10-19)
- R4-ServerCA4A.orig.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2040-10-21)
- rootg2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.v2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFSRootCA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2031-05-30)
- SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2037-12-31)