G2-RootCA2.orig.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Intermediate Certificate, Expiring 2037-12-31) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/G2-RootCA2.orig.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/G2-RootCA2.orig.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7b:50:4b:b1:d5:26:85:bf:73:e3:07:0b:01:ba:fe:b2:74:43
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2
        Validity
            Not Before: Oct 21 22:20:55 2015 GMT
            Not After : Dec 31 00:00:00 2037 GMT
        Subject: C=US, O=Amazon, CN=Amazon Root CA 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:ad:96:9f:2d:9c:4a:4c:4a:81:79:51:99:ec:8a:
                    cb:6b:60:51:13:bc:4d:6d:06:fc:b0:08:8d:dd:19:
                    10:6a:c7:26:0c:35:d8:c0:6f:20:84:e9:94:b1:9b:
                    85:03:c3:5b:db:4a:e8:c8:f8:90:76:d9:5b:4f:e3:
                    4c:e8:06:36:4d:cc:9a:ac:3d:0c:90:2b:92:d4:06:
                    19:60:ac:37:44:79:85:81:82:ad:5a:37:e0:0d:cc:
                    9d:a6:4c:52:76:ea:43:9d:b7:04:d1:50:f6:55:e0:
                    d5:d2:a6:49:85:e9:37:e9:ca:7e:ae:5c:95:4d:48:
                    9a:3f:ae:20:5a:6d:88:95:d9:34:b8:52:1a:43:90:
                    b0:bf:6c:05:b9:b6:78:b7:ea:d0:e4:3a:3c:12:53:
                    62:ff:4a:f2:7b:be:35:05:a9:12:34:e3:f3:64:74:
                    62:2c:3d:00:49:5a:28:fe:32:44:bb:87:dd:65:27:
                    02:71:3b:da:4a:f7:1f:da:cd:f7:21:55:90:4f:0f:
                    ec:ae:82:e1:9f:6b:d9:45:d3:bb:f0:5f:87:ed:3c:
                    2c:39:86:da:3f:de:ec:72:55:eb:79:a3:ad:db:dd:
                    7c:b0:ba:1c:ce:fc:de:4f:35:76:cf:0f:f8:78:1f:
                    6a:36:51:46:27:61:5b:e9:9e:cf:f0:a2:55:7d:7c:
                    25:8a:6f:2f:b4:c5:cf:84:2e:2b:fd:0d:51:10:6c:
                    fb:5f:1b:bc:1b:7e:c5:ae:3b:98:01:31:92:ff:0b:
                    57:f4:9a:b2:b9:57:e9:ab:ef:0d:76:d1:f0:ee:f4:
                    ce:86:a7:e0:6e:e9:b4:69:a1:df:69:f6:33:c6:69:
                    2e:97:13:9e:a5:87:b0:57:10:81:37:c9:53:b3:bb:
                    7f:f6:92:d1:9c:d0:18:f4:92:6e:da:83:4f:a6:63:
                    99:4c:a5:fb:5e:ef:21:64:7a:20:5f:6c:64:85:15:
                    cb:37:e9:62:0c:0b:2a:16:dc:01:2e:32:da:3e:4b:
                    f5:9e:3a:f6:17:40:94:ef:9e:91:08:86:fa:be:63:
                    a8:5a:33:ec:cb:74:43:95:f9:6c:69:52:36:c7:29:
                    6f:fc:55:03:5c:1f:fb:9f:bd:47:eb:e7:49:47:95:
                    0b:4e:89:22:09:49:e0:f5:61:1e:f1:bf:2e:8a:72:
                    6e:80:59:ff:57:3a:f9:75:32:a3:4e:5f:ec:ed:28:
                    62:d9:4d:73:f2:cc:81:17:60:ed:cd:eb:dc:db:a7:
                    ca:c5:7e:02:bd:f2:54:08:54:fd:b4:2d:09:2c:17:
                    54:4a:98:d1:54:e1:51:67:08:d2:ed:6e:7e:6f:3f:
                    d2:2d:81:59:29:66:cb:90:39:95:11:1e:74:27:fe:
                    dd:eb:af
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52
            X509v3 Authority Key Identifier: 
                keyid:9C:5F:00:DF:AA:01:D7:30:2B:38:88:A2:B8:6D:4A:9C:F2:11:91:83

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootg2.amazontrust.com
                CA Issuers - URI:http://crl.rootg2.amazontrust.com/rootg2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootg2.amazontrust.com/rootg2.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

    Signature Algorithm: sha256WithRSAEncryption
         68:15:72:5c:60:44:c4:1a:13:7d:26:be:93:d4:ce:3e:d1:80:
         52:5a:17:94:81:d6:5f:35:aa:56:25:88:2d:ad:25:87:d3:c1:
         75:10:7f:7f:8c:bc:8f:71:4f:ac:33:4d:5b:79:e2:00:fe:b0:
         4b:b9:c1:cd:b2:3c:80:29:8b:ce:78:09:97:1c:9b:56:1a:cb:
         72:47:0d:41:40:6f:b6:d7:2d:00:4e:bc:54:ad:96:41:65:f3:
         fb:b8:0c:a1:3d:e8:58:1b:b0:55:a9:8e:17:fa:b6:57:cb:87:
         b8:60:29:b2:02:44:bd:53:6d:06:b8:57:36:dd:0e:e6:75:f6:
         73:e1:56:1b:59:fc:a1:66:0b:14:f6:36:aa:61:ff:86:58:d9:
         53:56:82:6a:22:ed:f1:96:ee:6a:83:88:1d:8d:85:99:42:69:
         a0:eb:d3:4a:e0:8b:c8:08:ea:94:f0:08:4a:79:7d:f6:ef:d6:
         cd:e6:28:f5:aa:32:5f:e3:00:96:bd:d3:19:3f:19:c1:0f:eb:
         8c:28:e9:d1:a0:26:70:6c:9e:08:72:c1:0b:e7:9e:0a:e6:12:
         97:66:f0:84:e2:20:97:ca:94:1b:33:45:8b:1c:bc:f3:bb:64:
         0c:0c:51:55:23:3b:46:c6:29:6e:50:2d:b3:a9:35:33:7f:6d:
         db:e3:aa:3a

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFkjCCBHqgAwIBAgITBntQS7HVJoW/c+MHCwG6/rJ0QzANBgkqhkiG9w0BAQsF
ADCBmDELMAkGA1UEBhMCVVMxEDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNj
b3R0c2RhbGUxJTAjBgNVBAoTHFN0YXJmaWVsZCBUZWNobm9sb2dpZXMsIEluYy4x
OzA5BgNVBAMTMlN0YXJmaWVsZCBTZXJ2aWNlcyBSb290IENlcnRpZmljYXRlIEF1
dGhvcml0eSAtIEcyMB4XDTE1MTAyMTIyMjA1NVoXDTM3MTIzMTAwMDAwMFowOTEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEZMBcGA1UEAxMQQW1hem9uIFJv
b3QgQ0EgMjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAK2Wny2cSkxK
gXlRmeyKy2tgURO8TW0G/LAIjd0ZEGrHJgw12MBvIITplLGbhQPDW9tK6Mj4kHbZ
W0/jTOgGNk3Mmqw9DJArktQGGWCsN0R5hYGCrVo34A3MnaZMUnbqQ523BNFQ9lXg
1dKmSYXpN+nKfq5clU1Imj+uIFptiJXZNLhSGkOQsL9sBbm2eLfq0OQ6PBJTYv9K
8nu+NQWpEjTj82R0Yiw9AElaKP4yRLuH3WUnAnE72kr3H9rN9yFVkE8P7K6C4Z9r
2UXTu/Bfh+08LDmG2j/e7HJV63mjrdvdfLC6HM783k81ds8P+HgfajZRRidhW+me
z/CiVX18JYpvL7TFz4QuK/0NURBs+18bvBt+xa47mAExkv8LV/SasrlX6avvDXbR
8O70zoan4G7ptGmh32n2M8ZpLpcTnqWHsFcQgTfJU7O7f/aS0ZzQGPSSbtqDT6Zj
mUyl+17vIWR6IF9sZIUVyzfpYgwLKhbcAS4y2j5L9Z469hdAlO+ekQiG+r5jqFoz
7Mt0Q5X5bGlSNscpb/xVA1wf+5+9R+vnSUeVC06JIglJ4PVhHvG/LopyboBZ/1c6
+XUyo05f7O0oYtlNc/LMgRdg7c3r3NunysV+Ar3yVAhU/bQtCSwXVEqY0VThUWcI
0u1ufm8/0i2BWSlmy5A5lREedCf+3euvAgMBAAGjggExMIIBLTAPBgNVHRMBAf8E
BTADAQH/MA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQUsAzwTDD0BVgCSP0z5VKv
S4TjZlIwHwYDVR0jBBgwFoAUnF8A36oB1zArOIiiuG1KnPIRkYMweAYIKwYBBQUH
AQEEbDBqMC4GCCsGAQUFBzABhiJodHRwOi8vb2NzcC5yb290ZzIuYW1hem9udHJ1
c3QuY29tMDgGCCsGAQUFBzAChixodHRwOi8vY3JsLnJvb3RnMi5hbWF6b250cnVz
dC5jb20vcm9vdGcyLmNlcjA9BgNVHR8ENjA0MDKgMKAuhixodHRwOi8vY3JsLnJv
b3RnMi5hbWF6b250cnVzdC5jb20vcm9vdGcyLmNybDARBgNVHSAECjAIMAYGBFUd
IAAwDQYJKoZIhvcNAQELBQADggEBAGgVclxgRMQaE30mvpPUzj7RgFJaF5SB1l81
qlYliC2tJYfTwXUQf3+MvI9xT6wzTVt54gD+sEu5wc2yPIApi854CZccm1Yay3JH
DUFAb7bXLQBOvFStlkFl8/u4DKE96FgbsFWpjhf6tlfLh7hgKbICRL1TbQa4Vzbd
DuZ19nPhVhtZ/KFmCxT2Nqph/4ZY2VNWgmoi7fGW7mqDiB2NhZlCaaDr00rgi8gI
6pTwCEp5ffbv1s3mKPWqMl/jAJa90xk/GcEP64wo6dGgJnBsnghywQvnngrmEpdm
8ITiIJfKlBszRYscvPO7ZAwMUVUjO0bGKW5QLbOpNTN/bdvjqjo=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06