Microsoft Azure TLS Issuing CA 05 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 05,O=Microsoft Corporation,C=US (Intermediate Certificate, Expiring 2024-06-27) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2005%20-%20xsign.crt (in DER format )
- Serial Number : 17923441888884453276882086283662137533
- SHA-1 Fingerprint : 6c3af02e7f269aa73afd0eff2a88a4a1f04ed1e5
- SHA-1 Fingerprint : 6c:3a:f0:2e:7f:26:9a:a7:3a:fd:0e:ff:2a:88:a4:a1:f0:4e:d1:e5
- SHA-256 Fingerprint : d6831ba43607f5ac19778d627531562af55145f191cab5efafa0e0005442b302
- SHA-256 Fingerprint : d6:83:1b:a4:36:07:f5:ac:19:77:8d:62:75:31:56:2a:f5:51:45:f1:91:ca:b5:ef:af:a0:e0:00:54:42:b3:02
- Signature Hash Algorithm : sha384
- Subject
: CN=Microsoft Azure TLS Issuing CA 05,O=Microsoft Corporation,C=US
- Country Name: US (United States of America)
- Organization: Microsoft Corporation
- Common Name: Microsoft Azure TLS Issuing CA 05
- Not Valid Before: 2020-07-29 12:30:00
- Not Valid After: 2024-06-27 23:59:59
- Issuer (Parent Certificate):
- Issuer Name: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.microsoft.com/pkiops/Docs/Content/policy/Microsoft_PKI_Services_CP_v3.1.6.pdf
- Certificate Practice Statement (CPS) URL: https://www.microsoft.com/pkiops/Docs/Content/policy/Microsoft_PKI_Services_CPS_v3.2.2.pdf
- Auditor: BDO International Limited
- Standard Audit URL: https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?attachmentid=fc6f34ea-9248-4ffe-a94b-9e870afae5b7
- Standard Audit Period Start Date: 2021.05.01
- Standard Audit Period End Date: 2022.04.30
- Standard Audit Statement Date: 2022.06.17
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: http://www.microsoft.com/pkiops/crl/Microsoft%20Azure%20TLS%20Issuing%20CA%2005.crl
- Check its issuer’s audit information: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US .
Download certificate through curl
:
curl -sSL "http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2005%20-%20xsign.crt" --output cert.crt
Download certificate through wget
:
wget -q "http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2005%20-%20xsign.crt" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
0d:7b:ed:e9:7d:82:09:96:7a:52:63:1b:8b:dd:18:bd
Signature Algorithm: sha384WithRSAEncryption
Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
Validity
Not Before: Jul 29 12:30:00 2020 GMT
Not After : Jun 27 23:59:59 2024 GMT
Subject: C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 05
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:aa:65:0d:39:90:f5:a7:f0:54:f4:1e:94:3b:ae:
f8:d9:31:34:9d:3c:e0:23:4a:9e:b6:76:d4:00:5e:
c0:4f:94:53:81:8a:0e:7c:32:81:97:4a:e9:a8:0d:
48:cb:39:52:87:21:50:40:f3:cf:d0:a9:75:5e:6d:
74:fc:cb:d7:83:bf:19:e1:36:80:ee:7f:69:41:53:
50:c1:bd:73:a9:de:cb:19:39:b6:ad:56:74:ab:0f:
92:2b:4f:c2:ce:95:f0:c5:9a:e5:dd:4b:ff:2e:11:
16:16:47:52:c8:31:c5:4c:92:95:89:46:a4:d7:07:
86:1b:32:af:b1:2f:15:e7:19:18:0d:4c:7e:c8:ad:
01:65:69:ea:18:96:00:d9:16:28:83:5f:45:c7:6d:
dd:9d:80:db:78:66:30:7f:4c:45:21:81:71:c1:e2:
3e:ec:f0:ad:5b:12:98:bc:2f:b7:75:a5:44:38:0e:
6c:99:04:e3:4b:45:62:f2:7a:19:70:10:89:a1:87:
08:85:92:54:e6:e0:3b:7c:e3:eb:19:1d:6c:41:4c:
98:9f:f3:af:65:9e:b7:92:84:71:40:ed:50:18:40:
e1:d5:14:a1:a3:d5:cf:af:6e:e3:a5:79:e9:5b:1c:
cb:79:57:bb:56:25:b2:4f:38:8f:99:54:3c:b7:6c:
03:1b:6e:96:d3:f8:38:f4:28:39:3a:67:63:c9:31:
5a:41:fa:92:03:b9:81:32:84:dc:74:6f:a1:52:23:
53:8c:49:d0:94:3b:e3:ac:f2:ff:c1:9d:40:0d:fa:
49:a3:62:cf:85:37:bb:5d:33:15:98:36:46:4b:f6:
74:bd:4b:bf:9f:04:5c:bd:36:af:9a:b9:07:f9:e1:
54:7f:cc:d6:3a:13:be:94:6f:69:e1:29:00:98:64:
20:0f:4d:92:9b:db:18:4a:52:75:c0:34:3a:bb:4e:
39:e1:ad:ae:c8:8e:c8:c0:58:92:3a:41:e6:7c:34:
70:96:35:40:73:ab:de:72:2f:27:63:a7:63:e3:8a:
25:b0:d2:ae:11:6a:5a:c9:3c:ff:5a:ba:67:55:8d:
bc:e3:73:ee:d7:b5:a4:0b:47:7a:b7:4f:8b:9a:42:
1d:e8:97:08:da:6f:f9:f6:9d:c0:fd:24:f1:cc:da:
7f:65:6c:d7:d9:d8:b2:05:a7:e6:e2:32:2d:02:fc:
11:e8:5d:07:30:9b:38:a2:72:f6:c9:7c:e9:2e:05:
a9:ee:07:1b:20:2d:9a:a1:a5:69:63:ac:ab:60:3a:
3b:fa:5a:32:2d:c1:4a:65:93:0d:b8:0f:2c:23:c1:
6c:fb:5e:fd:bb:2e:00:41:78:6a:39:0f:10:44:b7:
18:73:fd
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
C7:B2:9C:7F:1C:E3:B8:5A:EF:E9:68:1A:A8:5D:94:C1:26:52:6A:68
X509v3 Authority Key Identifier:
keyid:4E:22:54:20:18:95:E6:E3:6E:E6:0F:FA:FA:B9:12:ED:06:17:8F:39
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
Authority Information Access:
OCSP - URI:http://ocsp.digicert.com
CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalRootG2.crt
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl3.digicert.com/DigiCertGlobalRootG2.crl
Full Name:
URI:http://crl4.digicert.com/DigiCertGlobalRootG2.crl
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 2.23.140.1.2.2
1.3.6.1.4.1.311.21.1:
...
Signature Algorithm: sha384WithRSAEncryption
1e:f8:6f:86:d9:11:5d:5a:d6:31:2c:82:8c:47:91:ff:69:53:
45:8c:d3:fb:25:d7:ae:fa:86:5a:29:a2:2e:ed:4d:cd:89:dc:
a4:16:bf:7d:e2:34:b1:30:13:15:ef:af:2e:90:9e:7f:84:b4:
8a:b2:e8:ff:48:b8:e6:01:fc:11:01:9f:b0:d1:11:aa:8b:f9:
0e:bc:f6:14:94:1a:ff:b0:a3:b0:af:7b:55:92:0f:5c:71:90:
5e:6e:70:55:1b:e0:cb:29:3a:76:3b:1d:3e:8d:80:42:3f:19:
5a:e4:53:b6:e7:6a:a9:93:bf:fa:c2:df:12:66:4d:dd:89:25:
35:d8:99:bb:89:ff:e3:8e:48:64:18:1f:de:f1:47:5f:ac:aa:
0b:ca:d0:ef:a9:57:a2:c0:f0:39:14:fc:ea:2a:84:aa:37:be:
5b:c8:b8:ec:20:a2:44:74:d8:b4:ed:26:38:e6:13:7f:45:49:
ec:98:8a:00:7f:dd:ea:95:a1:d1:fd:22:56:55:18:6b:5a:dd:
c9:99:ea:01:27:64:43:2b:8f:76:cc:5e:93:1a:ed:66:a2:1e:
1a:13:a7:b4:d1:89:30:4c:f5:ab:7a:ec:2f:68:b0:76:db:4b:
d6:9a:d8:19:3e:cf:83:48:86:f6:77:d8:4f:05:d0:89:82:f7:
21:a3:57:3b
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIF8zCCBNugAwIBAgIQDXvt6X2CCZZ6UmMbi90YvTANBgkqhkiG9w0BAQwFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH
MjAeFw0yMDA3MjkxMjMwMDBaFw0yNDA2MjcyMzU5NTlaMFkxCzAJBgNVBAYTAlVT
MR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKjAoBgNVBAMTIU1pY3Jv
c29mdCBBenVyZSBUTFMgSXNzdWluZyBDQSAwNTCCAiIwDQYJKoZIhvcNAQEBBQAD
ggIPADCCAgoCggIBAKplDTmQ9afwVPQelDuu+NkxNJ084CNKnrZ21ABewE+UU4GK
DnwygZdK6agNSMs5UochUEDzz9CpdV5tdPzL14O/GeE2gO5/aUFTUMG9c6neyxk5
tq1WdKsPkitPws6V8MWa5d1L/y4RFhZHUsgxxUySlYlGpNcHhhsyr7EvFecZGA1M
fsitAWVp6hiWANkWKINfRcdt3Z2A23hmMH9MRSGBccHiPuzwrVsSmLwvt3WlRDgO
bJkE40tFYvJ6GXAQiaGHCIWSVObgO3zj6xkdbEFMmJ/zr2Wet5KEcUDtUBhA4dUU
oaPVz69u46V56Vscy3lXu1Ylsk84j5lUPLdsAxtultP4OPQoOTpnY8kxWkH6kgO5
gTKE3HRvoVIjU4xJ0JQ746zy/8GdQA36SaNiz4U3u10zFZg2Rkv2dL1Lv58EXL02
r5q5B/nhVH/M1joTvpRvaeEpAJhkIA9NkpvbGEpSdcA0OrtOOeGtrsiOyMBYkjpB
5nw0cJY1QHOr3nIvJ2OnY+OKJbDSrhFqWsk8/1q6Z1WNvONz7te1pAtHerdPi5pC
HeiXCNpv+fadwP0k8czaf2Vs19nYsgWn5uIyLQL8EehdBzCbOKJy9sl86S4Fqe4H
GyAtmqGlaWOsq2A6O/paMi3BSmWTDbgPLCPBbPte/bsuAEF4ajkPEES3GHP9AgMB
AAGjggGtMIIBqTAdBgNVHQ4EFgQUx7KcfxzjuFrv6WgaqF2UwSZSamgwHwYDVR0j
BBgwFoAUTiJUIBiV5uNu5g/6+rkS7QYXjzkwDgYDVR0PAQH/BAQDAgGGMB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH/AgEAMHYG
CCsGAQUFBwEBBGowaDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQu
Y29tMEAGCCsGAQUFBzAChjRodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGln
aUNlcnRHbG9iYWxSb290RzIuY3J0MHsGA1UdHwR0MHIwN6A1oDOGMWh0dHA6Ly9j
cmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5jcmwwN6A1oDOG
MWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5j
cmwwHQYDVR0gBBYwFDAIBgZngQwBAgEwCAYGZ4EMAQICMBAGCSsGAQQBgjcVAQQD
AgEAMA0GCSqGSIb3DQEBDAUAA4IBAQAe+G+G2RFdWtYxLIKMR5H/aVNFjNP7Jdeu
+oZaKaIu7U3NidykFr994jSxMBMV768ukJ5/hLSKsuj/SLjmAfwRAZ+w0RGqi/kO
vPYUlBr/sKOwr3tVkg9ccZBebnBVG+DLKTp2Ox0+jYBCPxla5FO252qpk7/6wt8S
Zk3diSU12Jm7if/jjkhkGB/e8UdfrKoLytDvqVeiwPA5FPzqKoSqN75byLjsIKJE
dNi07SY45hN/RUnsmIoAf93qlaHR/SJWVRhrWt3JmeoBJ2RDK492zF6TGu1moh4a
E6e00YkwTPWreuwvaLB220vWmtgZPs+DSIb2d9hPBdCJgvcho1c7
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Microsoft Azure TLS Issuing CA 01 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 01,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft Azure TLS Issuing CA 02 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 02,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft Azure TLS Issuing CA 06 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 06,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft ECC Product Root Certificate Authority 2018.crt: CN=Microsoft ECC Product Root Certificate Authority 2018,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2043-02-27)
- Microsoft ECC Root Certificate Authority 2017.crt: CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft ECC Root Certificate Authority 2017.crt: CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft ECC TS Root Certificate Authority 2018.crt: CN=Microsoft ECC TS Root Certificate Authority 2018,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2043-02-27)
- Microsoft EV ECC Root Certificate Authority 2017.crt: CN=Microsoft EV ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft EV ECC Root Certificate Authority 2017.crt: CN=Microsoft EV ECC Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft EV RSA Root Certificate Authority 2017.crt: CN=Microsoft EV RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft EV RSA Root Certificate Authority 2017.crt: CN=Microsoft EV RSA Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- microsoft identity verification root certificate authority 2020.crt: CN=Microsoft Identity Verification Root Certificate Authority 2020,O=Microsoft Corporation,C=US (Expiring: 2045-04-16)
- Microsoft Public RSA Timestamping CA 2020.crt: CN=Microsoft Public RSA Timestamping CA 2020,O=Microsoft Corporation,C=US (Expiring: 2035-11-19)
- Microsoft RSA Root Certificate Authority 2017.crt: CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft RSA Root Certificate Authority 2017.crt: CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft RSA TLS CA 01.crt: CN=Microsoft RSA TLS CA 01,O=Microsoft Corporation,C=US (Expiring: 2024-10-08)
- Microsoft RSA TLS CA 02.crt: CN=Microsoft RSA TLS CA 02,O=Microsoft Corporation,C=US (Expiring: 2024-10-08)
- MicRooCerAut_2010-06-23.crt: CN=Microsoft Root Certificate Authority 2010,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2035-06-23)
- MicRooCerAut2011_2011_03_22.crt: CN=Microsoft Root Certificate Authority 2011,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2036-03-22)
- Microsoft Time Stamp Root Certificate Authority 2014.crt: CN=Microsoft Time Stamp Root Certificate Authority 2014,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2039-10-22)