apevsrsa2g1.der: CN=Apple Public EV Server RSA CA 2 - G1,O=Apple Inc.,C=US (Intermediate Certificate, Expiring 2030-04-10) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://certs.apple.com/apevsrsa2g1.der" --output cert.crt

Download certificate through wget:

wget -q "http://certs.apple.com/apevsrsa2g1.der" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:17:79:11:00:5d:22:67:f6:88:92:f6:8f:8b:50:58
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
        Validity
            Not Before: Apr 29 12:54:50 2020 GMT
            Not After : Apr 10 23:59:59 2030 GMT
        Subject: C=US, O=Apple Inc., CN=Apple Public EV Server RSA CA 2 - G1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:e2:00:fd:a5:df:5f:b9:38:71:49:eb:ba:93:d8:
                    c3:4d:33:dc:5c:14:ea:70:2f:c1:ea:53:3b:cb:9e:
                    51:c0:54:b2:64:06:a6:97:31:e4:17:84:ca:78:2f:
                    67:c3:d2:89:e1:f4:18:71:ca:ed:19:c7:6e:02:c2:
                    87:2a:27:d8:7f:44:a6:06:28:ec:d4:35:ca:b7:02:
                    e5:31:ef:a3:75:6b:94:03:fa:53:be:3a:39:14:83:
                    c5:46:db:bf:8c:f5:e6:40:2c:ca:f0:01:50:21:62:
                    f1:2e:c8:5e:4c:c3:22:38:4e:20:23:6b:03:c7:d7:
                    52:95:0a:6c:87:1c:23:62:6f:33:3e:d1:bf:0e:46:
                    78:6e:dc:69:ad:ae:fa:f4:88:dd:39:81:9f:03:1c:
                    8d:5a:a5:b1:27:2a:63:ab:5b:13:f8:e2:ec:2f:d7:
                    0f:0e:f0:52:93:07:c9:a4:0c:54:63:ce:ee:62:5f:
                    8b:4f:d0:6e:25:0f:5b:09:c2:24:f6:00:a8:fa:6f:
                    05:58:de:06:1d:1a:bd:40:86:68:fd:99:b5:97:36:
                    26:7b:35:0b:c8:7d:79:b2:46:f9:9d:da:c1:d8:01:
                    a9:03:d8:0f:62:3e:7f:2f:da:06:d9:d3:3a:48:67:
                    04:9b:62:f2:3c:61:d5:38:4d:57:ae:52:f5:2b:9c:
                    65:e7
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                50:55:AB:43:A1:AF:A9:48:2B:5A:C1:A2:87:89:04:E4:7A:0E:CA:DA
            X509v3 Authority Key Identifier: 
                keyid:B1:3E:C3:69:03:F8:BF:47:01:D4:98:26:1A:08:02:EF:63:64:2B:C3

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.114412.2.1
                  CPS: https://www.digicert.com/CPS
                  User Notice:
                    Explicit Text: Any use of this Certificate constitutes acceptance of the Relying Party Agreement located at https://www.digicert.com/rpa-ua
                Policy: 2.23.140.1.1

    Signature Algorithm: sha256WithRSAEncryption
         a6:5e:6c:50:b6:65:5c:2b:4e:3f:ae:ea:70:e8:dc:ed:37:7b:
         4f:e0:fe:13:7e:e9:4e:62:03:b5:fd:74:11:a6:43:1d:c2:ec:
         d9:0f:34:05:74:99:4a:1a:92:5b:1c:78:80:48:43:f6:c2:ee:
         eb:5d:83:09:d2:29:39:e6:e4:77:55:8a:90:12:c8:b9:68:53:
         b4:cf:da:30:2d:0d:07:40:c4:16:af:98:b9:c5:c1:cc:17:06:
         9e:a7:d7:bb:8b:a7:eb:8f:53:80:d9:82:e6:cc:f7:a2:f2:51:
         08:a5:52:56:04:45:b8:2e:eb:aa:c2:2b:5f:23:46:6a:1b:0e:
         f1:53:f0:4e:f5:a1:4d:77:a3:53:9e:ff:55:94:1c:56:d3:ca:
         74:64:29:6e:f7:24:37:76:ad:9d:b5:3e:29:bb:2c:42:55:63:
         73:9c:46:6b:58:34:76:8c:fe:5b:a7:63:1d:59:43:ed:1f:c3:
         b1:dc:e4:9f:f1:47:bb:e5:46:2b:b2:3f:e7:c9:f6:e7:2e:0d:
         8b:a9:2e:0d:f7:dc:38:b9:47:b2:59:21:f9:d7:e3:67:9c:5f:
         40:dd:d3:02:1e:b8:58:f4:1c:18:c7:e9:cd:b9:15:4a:2f:fc:
         56:b9:66:3a:f4:54:f8:e6:9a:03:7a:3e:7a:0c:02:b5:19:5c:
         39:10:7b:73

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFMjCCBBqgAwIBAgIQBxd5EQBdImf2iJL2j4tQWDANBgkqhkiG9w0BAQsFADBs
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5j
ZSBFViBSb290IENBMB4XDTIwMDQyOTEyNTQ1MFoXDTMwMDQxMDIzNTk1OVowUTEL
MAkGA1UEBhMCVVMxEzARBgNVBAoTCkFwcGxlIEluYy4xLTArBgNVBAMTJEFwcGxl
IFB1YmxpYyBFViBTZXJ2ZXIgUlNBIENBIDIgLSBHMTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAOIA/aXfX7k4cUnrupPYw00z3FwU6nAvwepTO8ueUcBU
smQGppcx5BeEyngvZ8PSieH0GHHK7RnHbgLChyon2H9EpgYo7NQ1yrcC5THvo3Vr
lAP6U746ORSDxUbbv4z15kAsyvABUCFi8S7IXkzDIjhOICNrA8fXUpUKbIccI2Jv
Mz7Rvw5GeG7caa2u+vSI3TmBnwMcjVqlsScqY6tbE/ji7C/XDw7wUpMHyaQMVGPO
7mJfi0/QbiUPWwnCJPYAqPpvBVjeBh0avUCGaP2ZtZc2Jns1C8h9ebJG+Z3awdgB
qQPYD2I+fy/aBtnTOkhnBJti8jxh1ThNV65S9SucZecCAwEAAaOCAekwggHlMB0G
A1UdDgQWBBRQVatDoa+pSCtawaKHiQTkeg7K2jAfBgNVHSMEGDAWgBSxPsNpA/i/
RwHUmCYaCALvY2QrwzAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYBBQUH
AwEGCCsGAQUFBwMCMBIGA1UdEwEB/wQIMAYBAf8CAQAwNAYIKwYBBQUHAQEEKDAm
MCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdpY2VydC5jb20wSwYDVR0fBEQw
QjBAoD6gPIY6aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0SGlnaEFz
c3VyYW5jZUVWUm9vdENBLmNybDCB3AYDVR0gBIHUMIHRMIHFBglghkgBhv1sAgEw
gbcwKAYIKwYBBQUHAgEWHGh0dHBzOi8vd3d3LmRpZ2ljZXJ0LmNvbS9DUFMwgYoG
CCsGAQUFBwICMH4MfEFueSB1c2Ugb2YgdGhpcyBDZXJ0aWZpY2F0ZSBjb25zdGl0
dXRlcyBhY2NlcHRhbmNlIG9mIHRoZSBSZWx5aW5nIFBhcnR5IEFncmVlbWVudCBs
b2NhdGVkIGF0IGh0dHBzOi8vd3d3LmRpZ2ljZXJ0LmNvbS9ycGEtdWEwBwYFZ4EM
AQEwDQYJKoZIhvcNAQELBQADggEBAKZebFC2ZVwrTj+u6nDo3O03e0/g/hN+6U5i
A7X9dBGmQx3C7NkPNAV0mUoaklsceIBIQ/bC7utdgwnSKTnm5HdVipASyLloU7TP
2jAtDQdAxBavmLnFwcwXBp6n17uLp+uPU4DZgubM96LyUQilUlYERbgu66rCK18j
RmobDvFT8E71oU13o1Oe/1WUHFbTynRkKW73JDd2rZ21Pim7LEJVY3OcRmtYNHaM
/lunYx1ZQ+0fw7Hc5J/xR7vlRiuyP+fJ9ucuDYupLg333Di5R7JZIfnX42ecX0Dd
0wIeuFj0HBjH6c25FUov/Fa5Zjr0VPjmmgN6PnoMArUZXDkQe3M=
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06