SFSRootCA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Intermediate Certificate, Expiring 2031-05-30) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/SFSRootCA-SFSRootCAG2.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/SFSRootCA-SFSRootCAG2.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 3202217 (0x30dca9)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
        Validity
            Not Before: Jan  1 07:00:00 2014 GMT
            Not After : May 30 07:00:00 2031 GMT
        Subject: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:d5:0c:3a:c4:2a:f9:4e:e2:f5:be:19:97:5f:8e:
                    88:53:b1:1f:3f:cb:cf:9f:20:13:6d:29:3a:c8:0f:
                    7d:3c:f7:6b:76:38:63:d9:36:60:a8:9b:5e:5c:00:
                    80:b2:2f:59:7f:f6:87:f9:25:43:86:e7:69:1b:52:
                    9a:90:e1:71:e3:d8:2d:0d:4e:6f:f6:c8:49:d9:b6:
                    f3:1a:56:ae:2b:b6:74:14:eb:cf:fb:26:e3:1a:ba:
                    1d:96:2e:6a:3b:58:94:89:47:56:ff:25:a0:93:70:
                    53:83:da:84:74:14:c3:67:9e:04:68:3a:df:8e:40:
                    5a:1d:4a:4e:cf:43:91:3b:e7:56:d6:00:70:cb:52:
                    ee:7b:7d:ae:3a:e7:bc:31:f9:45:f6:c2:60:cf:13:
                    59:02:2b:80:cc:34:47:df:b9:de:90:65:6d:02:cf:
                    2c:91:a6:a6:e7:de:85:18:49:7c:66:4e:a3:3a:6d:
                    a9:b5:ee:34:2e:ba:0d:03:b8:33:df:47:eb:b1:6b:
                    8d:25:d9:9b:ce:81:d1:45:46:32:96:70:87:de:02:
                    0e:49:43:85:b6:6c:73:bb:64:ea:61:41:ac:c9:d4:
                    54:df:87:2f:c7:22:b2:26:cc:9f:59:54:68:9f:fc:
                    be:2a:2f:c4:55:1c:75:40:60:17:85:02:55:39:8b:
                    7f:05
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                9C:5F:00:DF:AA:01:D7:30:2B:38:88:A2:B8:6D:4A:9C:F2:11:91:83
            X509v3 Authority Key Identifier: 
                keyid:B4:C6:7F:1A:43:CC:9B:75:5D:2F:C4:4B:F2:8B:98:10:E9:F1:51:10

            Authority Information Access: 
                OCSP - URI:http://ocsp.starfieldtech.com/

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.starfieldtech.com/sfsroot.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://certs.starfieldtech.com/repository/

    Signature Algorithm: sha256WithRSAEncryption
         1e:71:a0:8e:9c:5a:0e:42:da:b9:75:a8:6a:5e:2c:3c:fd:dd:
         29:ca:b1:0d:61:4d:3b:22:2c:4f:6e:b9:b6:62:af:12:2c:54:
         9e:75:d0:63:a9:23:d7:e6:b5:43:8d:95:f1:a0:86:a4:33:d0:
         7b:e4:5d:a1:63:2d:24:04:7c:8d:c9:31:11:24:dd:06:28:49:
         a3:85:7b:7c:9a:f6:0a:07:0f:ec:29:ff:d6:46:2c:b1:17:00:
         27:e6:80:a7:1d:24:1f:f0:a5:bc:26:26:f8:58:10:12:4a:ba:
         9f:9c:64:9f:2f:9e:90:0c:ab:21:fb:6f:0f:b8:b2:ce:b5:ac:
         71:cb:a9:98:82:ba:07:9e:36:97:da:94:ef:a0:a0:78:f7:b1:
         b1:97:eb:d8:6e:77:95:20:89:45:a3:15:dd:fe:5c:0a:c8:29:
         93:69:2b:b7:b0:ed:27:bd:12:1b:b6:e9:36:24:cd:bc:c5:b9:
         3b:11:2a:96:8b:5f:72:d6:27:9f:f9:a3:1d:fb:c6:c1:e1:99:
         63:b3:8b:17:c7:d2:fe:ca:c6:83:92:19:dd:10:07:05:21:4d:
         bd:e9:15:37:51:7b:33:13:37:d8:70:78:b2:28:9b:06:21:a6:
         d7:5b:e5:0f:3d:ac:ad:dd:f1:64:73:98:db:6d:4a:cc:41:ee:
         ce:5c:3e:aa

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFEjCCA/qgAwIBAgIDMNypMA0GCSqGSIb3DQEBCwUAMIHPMQswCQYDVQQGEwJV
UzEQMA4GA1UECBMHQXJpem9uYTETMBEGA1UEBxMKU2NvdHRzZGFsZTElMCMGA1UE
ChMcU3RhcmZpZWxkIFRlY2hub2xvZ2llcywgSW5jLjE6MDgGA1UECxMxaHR0cDov
L2NlcnRpZmljYXRlcy5zdGFyZmllbGR0ZWNoLmNvbS9yZXBvc2l0b3J5LzE2MDQG
A1UEAxMtU3RhcmZpZWxkIFNlcnZpY2VzIFJvb3QgQ2VydGlmaWNhdGUgQXV0aG9y
aXR5MB4XDTE0MDEwMTA3MDAwMFoXDTMxMDUzMDA3MDAwMFowgZgxCzAJBgNVBAYT
AlVTMRAwDgYDVQQIEwdBcml6b25hMRMwEQYDVQQHEwpTY290dHNkYWxlMSUwIwYD
VQQKExxTdGFyZmllbGQgVGVjaG5vbG9naWVzLCBJbmMuMTswOQYDVQQDEzJTdGFy
ZmllbGQgU2VydmljZXMgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgLSBHMjCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANUMOsQq+U7i9b4Zl1+OiFOx
Hz/Lz58gE20pOsgPfTz3a3Y4Y9k2YKibXlwAgLIvWX/2h/klQ4bnaRtSmpDhcePY
LQ1Ob/bISdm28xpWriu2dBTrz/sm4xq6HZYuajtYlIlHVv8loJNwU4PahHQUw2ee
BGg6345AWh1KTs9DkTvnVtYAcMtS7nt9rjrnvDH5RfbCYM8TWQIrgMw0R9+53pBl
bQLPLJGmpufehRhJfGZOozptqbXuNC66DQO4M99H67FrjSXZm86B0UVGMpZwh94C
DklDhbZsc7tk6mFBrMnUVN+HL8cisibMn1lUaJ/8viovxFUcdUBgF4UCVTmLfwUC
AwEAAaOCASowggEmMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0G
A1UdDgQWBBScXwDfqgHXMCs4iKK4bUqc8hGRgzAfBgNVHSMEGDAWgBS0xn8aQ8yb
dV0vxEvyi5gQ6fFREDA6BggrBgEFBQcBAQQuMCwwKgYIKwYBBQUHMAGGHmh0dHA6
Ly9vY3NwLnN0YXJmaWVsZHRlY2guY29tLzA5BgNVHR8EMjAwMC6gLKAqhihodHRw
Oi8vY3JsLnN0YXJmaWVsZHRlY2guY29tL3Nmc3Jvb3QuY3JsMEwGA1UdIARFMEMw
QQYEVR0gADA5MDcGCCsGAQUFBwIBFitodHRwczovL2NlcnRzLnN0YXJmaWVsZHRl
Y2guY29tL3JlcG9zaXRvcnkvMA0GCSqGSIb3DQEBCwUAA4IBAQAecaCOnFoOQtq5
dahqXiw8/d0pyrENYU07IixPbrm2Yq8SLFSeddBjqSPX5rVDjZXxoIakM9B75F2h
Yy0kBHyNyTERJN0GKEmjhXt8mvYKBw/sKf/WRiyxFwAn5oCnHSQf8KW8Jib4WBAS
SrqfnGSfL56QDKsh+28PuLLOtaxxy6mYgroHnjaX2pTvoKB497Gxl+vYbneVIIlF
oxXd/lwKyCmTaSu3sO0nvRIbtuk2JM28xbk7ESqWi19y1ief+aMd+8bB4Zljs4sX
x9L+ysaDkhndEAcFIU296RU3UXszEzfYcHiyKJsGIabXW+UPPayt3fFkc5jbbUrM
Qe7OXD6q
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06