R3-ServerCA3B.cer: CN=Amazon,OU=Server CA 3B,O=Amazon,C=US (Intermediate Certificate, Expiring 2028-07-16) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: https://www.amazontrust.com/repository/R3-ServerCA3B.cer (in DER format )
- Serial Number : 153177878782232859375223032513834700059899758
- SHA-1 Fingerprint : 6c787156ae214cf4b04483ac4f45522c6ea504c1
- SHA-1 Fingerprint : 6c:78:71:56:ae:21:4c:f4:b0:44:83:ac:4f:45:52:2c:6e:a5:04:c1
- SHA-256 Fingerprint : ecc295b6ddcd084ba7179fb53bdd1d422cb6c0a8d94f154d4a5b17780b7279ed
- SHA-256 Fingerprint : ec:c2:95:b6:dd:cd:08:4b:a7:17:9f:b5:3b:dd:1d:42:2c:b6:c0:a8:d9:4f:15:4d:4a:5b:17:78:0b:72:79:ed
- Signature Hash Algorithm : sha256
- Subject
: CN=Amazon,OU=Server CA 3B,O=Amazon,C=US
- Country Name: US (United States of America)
- Organization: Amazon
- Organization Unit: Server CA 3B
- Common Name: Amazon
- Not Valid Before: 2018-07-16 22:06:27
- Not Valid After: 2028-07-16 22:06:27
- Issuer (Parent Certificate):
- Issuer Name: CN=Amazon Root CA 3,O=Amazon,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cp-v5-12-Final.pdf
- Certificate Practice Statement (CPS) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cps-v5-12-Final.pdf
- Auditor: BDO International Limited
- Standard Audit URL: https://bugzilla.mozilla.org/attachment.cgi?id=9309728
- Standard Audit Period Start Date: 2021.10.01
- Standard Audit Period End Date: 2022.09.30
- Standard Audit Statement Date: 2022.12.22
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: http://crl.sca3b.amazontrust.com/sca3b.crl
- Check its issuer’s audit information: CN=Amazon Root CA 3,O=Amazon,C=US .
Download certificate through curl
:
curl -sSL "https://www.amazontrust.com/repository/R3-ServerCA3B.cer" --output cert.crt
Download certificate through wget
:
wget -q "https://www.amazontrust.com/repository/R3-ServerCA3B.cer" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
06:de:65:53:f4:71:2a:18:31:2d:fd:a2:b4:84:6d:1b:36:f7:6e
Signature Algorithm: ecdsa-with-SHA256
Issuer: C=US, O=Amazon, CN=Amazon Root CA 3
Validity
Not Before: Jul 16 22:06:27 2018 GMT
Not After : Jul 16 22:06:27 2028 GMT
Subject: C=US, O=Amazon, OU=Server CA 3B, CN=Amazon
Subject Public Key Info:
Public Key Algorithm: id-ecPublicKey
Public-Key: (256 bit)
pub:
04:f9:e3:ee:6c:0d:51:53:27:55:62:66:68:f8:43:
a6:19:34:3b:53:5b:d5:e7:32:8e:c6:b9:1d:b7:4c:
48:16:71:45:a7:a9:c8:42:d6:d2:76:bd:41:0c:25:
4f:52:24:7d:f2:59:67:8d:a7:ca:f1:8a:21:1a:89:
44:63:db:bf:ef
ASN1 OID: prime256v1
NIST CURVE: P-256
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Subject Key Identifier:
AE:5C:80:FF:42:97:C9:C3:A0:9B:65:0B:04:CE:9E:71:7F:3E:CE:5A
X509v3 Authority Key Identifier:
keyid:AB:B6:DB:D7:06:9E:37:AC:30:86:07:91:70:C7:9C:C4:19:B1:78:C0
Authority Information Access:
OCSP - URI:http://ocsp.rootca3.amazontrust.com
CA Issuers - URI:http://crt.rootca3.amazontrust.com/rootca3.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.rootca3.amazontrust.com/rootca3.crl
X509v3 Certificate Policies:
Policy: X509v3 Any Policy
Signature Algorithm: ecdsa-with-SHA256
30:45:02:21:00:b8:73:ae:68:a7:25:07:85:34:43:86:0b:d2:
4b:5b:39:72:9d:3f:b7:b8:17:7a:7e:5a:fe:a0:2f:86:88:1f:
7b:02:20:2f:d9:0b:10:8f:13:a2:b0:db:7b:fa:2d:c3:5a:b3:
d6:67:9a:8a:71:a7:73:85:42:29:6a:9e:58:9c:69:91:72
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIICuzCCAmGgAwIBAgITBt5lU/RxKhgxLf2itIRtGzb3bjAKBggqhkjOPQQDAjA5
MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6b24g
Um9vdCBDQSAzMB4XDTE4MDcxNjIyMDYyN1oXDTI4MDcxNjIyMDYyN1owRjELMAkG
A1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEVMBMGA1UECxMMU2VydmVyIENBIDNC
MQ8wDQYDVQQDEwZBbWF6b24wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAT54+5s
DVFTJ1ViZmj4Q6YZNDtTW9XnMo7GuR23TEgWcUWnqchC1tJ2vUEMJU9SJH3yWWeN
p8rxiiEaiURj27/vo4IBOTCCATUwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8B
Af8EBAMCAYYwHQYDVR0OBBYEFK5cgP9Cl8nDoJtlCwTOnnF/Ps5aMB8GA1UdIwQY
MBaAFKu229cGnjesMIYHkXDHnMQZsXjAMHsGCCsGAQUFBwEBBG8wbTAvBggrBgEF
BQcwAYYjaHR0cDovL29jc3Aucm9vdGNhMy5hbWF6b250cnVzdC5jb20wOgYIKwYB
BQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhMy5hbWF6b250cnVzdC5jb20vcm9vdGNh
My5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2EzLmFtYXpv
bnRydXN0LmNvbS9yb290Y2EzLmNybDARBgNVHSAECjAIMAYGBFUdIAAwCgYIKoZI
zj0EAwIDSAAwRQIhALhzrminJQeFNEOGC9JLWzlynT+3uBd6flr+oC+GiB97AiAv
2QsQjxOisNt7+i3DWrPWZ5qKcadzhUIpap5YnGmRcg==
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Amazon-ECDSA-256-M01.cer: CN=Amazon ECDSA 256 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M02.cer: CN=Amazon ECDSA 256 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M03.cer: CN=Amazon ECDSA 256 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M04.cer: CN=Amazon ECDSA 256 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M01.cer: CN=Amazon ECDSA 384 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M02.cer: CN=Amazon ECDSA 384 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M03.cer: CN=Amazon ECDSA 384 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M04.cer: CN=Amazon ECDSA 384 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M01.cer: CN=Amazon RSA 2048 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M02.cer: CN=Amazon RSA 2048 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M03.cer: CN=Amazon RSA 2048 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M04.cer: CN=Amazon RSA 2048 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M01.cer: CN=Amazon RSA 4096 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M02.cer: CN=Amazon RSA 4096 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M03.cer: CN=Amazon RSA 4096 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M04.cer: CN=Amazon RSA 4096 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- rootca1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2038-01-17)
- G2-RootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA1.orig.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA2.orig.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA3.orig.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA4.orig.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-ServerCA0A.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2025-10-19)
- G2-ServerCA0A.orig.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2040-10-21)
- R1-ServerCA1A.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1A.orig.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2040-10-21)
- sca1b.crt: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.orig.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2040-10-21)
- R2-ServerCA2A.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2025-10-19)
- R2-ServerCA2A.orig.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3A.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2025-10-19)
- R3-ServerCA3A.orig.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2040-10-21)
- R4-ServerCA4A.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2025-10-19)
- R4-ServerCA4A.orig.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2040-10-21)
- rootg2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.v2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFSRootCA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2031-05-30)
- SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2037-12-31)