GDCA_Generic_SM2_CA.cer: CN=GDCA Generic SM2 CA,O=Global Digital Cybersecurity Authority Co., Ltd.,C=CN (Intermediate Certificate, Expiring 2035-11-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.gdca.com.cn/certdownload/caCertDownLoadServlet?filename=GDCA_Generic_SM2_CA.cer&cn=GDCA%20Generic%20SM2%20CA&name=/GDCA_Generic_SM2_CA.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.gdca.com.cn/certdownload/caCertDownLoadServlet?filename=GDCA_Generic_SM2_CA.cer&cn=GDCA%20Generic%20SM2%20CA&name=/GDCA_Generic_SM2_CA.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            40:6e:7e:92:7f:1a:a1:0f:7d:27:5a:70:94:8b:42:34
    Signature Algorithm: 1.2.156.10197.1.501
        Issuer: C=CN, O=Global Digital Cybersecurity Authority Co., Ltd., CN=GDCA GM SM2 ROOT
        Validity
            Not Before: Nov 26 06:49:48 2020 GMT
            Not After : Nov 23 06:49:48 2035 GMT
        Subject: C=CN, O=Global Digital Cybersecurity Authority Co., Ltd., CN=GDCA Generic SM2 CA
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
            Unable to load Public Key
140704467711616:error:10FFF010:elliptic curve routines:CRYPTO_internal:EC lib:/AppleInternal/Library/BuildRoots/9e200cfa-7d96-11ed-886f-a23c4f261b56/Library/Caches/com.apple.xbs/Sources/libressl/libressl-3.3/crypto/ec/ec_ameth.c:207:
140704467711616:error:0BFFF07D:x509 certificate routines:CRYPTO_internal:public key decode error:/AppleInternal/Library/BuildRoots/9e200cfa-7d96-11ed-886f-a23c4f261b56/Library/Caches/com.apple.xbs/Sources/libressl/libressl-3.3/crypto/asn1/x_pubkey.c:203:
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Authority Key Identifier: 
                keyid:E8:E9:D4:44:6A:73:FE:9B:77:5A:81:C3:D8:50:97:E1:CD:50:7A:D0

            Authority Information Access: 
                CA Issuers - URI:http://gm.gdca.com.cn/cert/GDCA_GM_SM2_ROOT.der
                OCSP - URI:http://gmocsp2.gdca.com.cn/ocsp

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://www.gdca.com.cn/cps/gmcps

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://gmcrl.gdca.com.cn/crl/GDCA_GM_SM2_ROOT.crl

            X509v3 Subject Key Identifier: 
                52:4C:90:27:33:9F:27:0A:C7:AF:C1:3C:D1:AB:41:99:22:0F:A1:DF
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: 1.2.156.10197.1.501
         30:44:02:20:48:7e:3e:92:f7:dd:16:52:4e:fa:a4:df:79:b4:
         24:a3:83:96:66:02:5d:4b:c1:f1:f6:51:62:fb:dd:3e:a4:26:
         02:20:47:ab:a3:c0:a1:fc:eb:23:4d:64:e4:c7:e7:81:31:b2:
         e3:ef:d4:a8:0b:be:c7:42:2f:60:a5:d2:34:b7:7f:9f

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDMjCCAtmgAwIBAgIQQG5+kn8aoQ99J1pwlItCNDAKBggqgRzPVQGDdTBjMQsw
CQYDVQQGEwJDTjE5MDcGA1UECgwwR2xvYmFsIERpZ2l0YWwgQ3liZXJzZWN1cml0
eSBBdXRob3JpdHkgQ28uLCBMdGQuMRkwFwYDVQQDDBBHRENBIEdNIFNNMiBST09U
MB4XDTIwMTEyNjA2NDk0OFoXDTM1MTEyMzA2NDk0OFowZjELMAkGA1UEBhMCQ04x
OTA3BgNVBAoMMEdsb2JhbCBEaWdpdGFsIEN5YmVyc2VjdXJpdHkgQXV0aG9yaXR5
IENvLiwgTHRkLjEcMBoGA1UEAwwTR0RDQSBHZW5lcmljIFNNMiBDQTBZMBMGByqG
SM49AgEGCCqBHM9VAYItA0IABHT4xRzPt1FVmlgTerJBjC1hcbFX8i2tEH8Wdqzd
1I7jWYEv4afFVE+YyAK60nIFSCP/zLJ5Se4B6fCA8tRJo/ijggFqMIIBZjASBgNV
HRMBAf8ECDAGAQH/AgEAMB8GA1UdIwQYMBaAFOjp1ERqc/6bd1qBw9hQl+HNUHrQ
MHgGCCsGAQUFBwEBBGwwajA7BggrBgEFBQcwAoYvaHR0cDovL2dtLmdkY2EuY29t
LmNuL2NlcnQvR0RDQV9HTV9TTTJfUk9PVC5kZXIwKwYIKwYBBQUHMAGGH2h0dHA6
Ly9nbW9jc3AyLmdkY2EuY29tLmNuL29jc3AwQgYDVR0gBDswOTA3BgRVHSAAMC8w
LQYIKwYBBQUHAgEWIWh0dHBzOi8vd3d3LmdkY2EuY29tLmNuL2Nwcy9nbWNwczBC
BgNVHR8EOzA5MDegNaAzhjFodHRwOi8vZ21jcmwuZ2RjYS5jb20uY24vY3JsL0dE
Q0FfR01fU00yX1JPT1QuY3JsMB0GA1UdDgQWBBRSTJAnM58nCsevwTzRq0GZIg+h
3zAOBgNVHQ8BAf8EBAMCAQYwCgYIKoEcz1UBg3UDRwAwRAIgSH4+kvfdFlJO+qTf
ebQko4OWZgJdS8Hx9lFi+90+pCYCIEero8Ch/OsjTWTkx+eBMbLj79SoC77HQi9g
pdI0t3+f
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06