DomeinServerCA2020.cer: CN=Staat der Nederlanden Domein Server CA 2020,O=Staat der Nederlanden,C=NL (Intermediate Certificate, Expiring 2022-12-06) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: http://cert.pkioverheid.nl/DomeinServerCA2020.cer (in DER format )
- Serial Number : 525441290765089516486887856618729111225828668600
- SHA-1 Fingerprint : a2af8fb631de777d4dda9b0b6634ec5a96c52b7c
- SHA-1 Fingerprint : a2:af:8f:b6:31:de:77:7d:4d:da:9b:0b:66:34:ec:5a:96:c5:2b:7c
- SHA-256 Fingerprint : 0da914fb7125f6e644eb7aa261de9eb809dc7f925b6b2a7d8a7edd8736398b5b
- SHA-256 Fingerprint : 0d:a9:14:fb:71:25:f6:e6:44:eb:7a:a2:61:de:9e:b8:09:dc:7f:92:5b:6b:2a:7d:8a:7e:dd:87:36:39:8b:5b
- Signature Hash Algorithm : sha256
- Subject
: CN=Staat der Nederlanden Domein Server CA 2020,O=Staat der Nederlanden,C=NL
- Country Name: NL (Netherlands)
- Organization: Staat der Nederlanden
- Common Name: Staat der Nederlanden Domein Server CA 2020
- Not Valid Before: 2020-07-29 17:26:24
- Not Valid After: 2022-12-06 00:00:00
- Issuer (Parent Certificate):
- Issuer Name: CN=Staat der Nederlanden EV Root CA,O=Staat der Nederlanden,C=NL
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: Unknown
- Certificate Practice Statement (CPS) URL: Unknown
- Auditor: KPMG
- Standard Audit URL: Unknown
- Standard Audit Period Start Date: Unknown
- Standard Audit Period End Date: Unknown
- Standard Audit Statement Date: Unknown
- Standard Audit Type: Unknown
- Full CRL Issued By This CA: http://crl.pkioverheid.nl/DomeinServerCA2020LatestCRL.crl
- Check its issuer’s audit information: CN=Staat der Nederlanden EV Root CA,O=Staat der Nederlanden,C=NL .
Download certificate through curl
:
curl -sSL "http://cert.pkioverheid.nl/DomeinServerCA2020.cer" --output cert.crt
Download certificate through wget
:
wget -q "http://cert.pkioverheid.nl/DomeinServerCA2020.cer" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
5c:09:9a:34:75:34:a0:ab:11:49:3b:19:d5:5a:53:8a:c6:ac:74:b8
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=NL, O=Staat der Nederlanden, CN=Staat der Nederlanden EV Root CA
Validity
Not Before: Jul 29 17:26:24 2020 GMT
Not After : Dec 6 00:00:00 2022 GMT
Subject: C=NL, O=Staat der Nederlanden, CN=Staat der Nederlanden Domein Server CA 2020
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:d9:f3:8b:55:a0:c2:3a:ff:bf:ee:6e:b3:7e:93:
a9:1a:b2:a5:56:0a:40:b8:db:c8:f7:b0:e3:72:39:
1d:fe:ba:9c:2a:70:8a:98:25:ff:6d:af:8b:6a:d6:
ef:02:40:53:40:1f:0a:1c:a9:14:b7:21:43:b3:fb:
6e:90:b6:38:64:53:f1:cd:43:a7:6f:e2:ac:58:4d:
86:0f:21:af:a1:b0:bb:e8:20:de:22:11:55:eb:4c:
31:c0:ba:26:69:e5:dd:c9:be:dd:16:0c:70:c5:40:
6b:58:60:9d:ff:a4:89:6c:d7:de:f8:fd:22:49:04:
1e:b1:8d:a8:bf:52:77:8f:f5:bc:f6:b4:66:e7:f7:
91:c1:82:39:f8:2f:00:0a:c2:1b:90:3f:9d:0a:4f:
ff:84:3e:09:55:01:49:2a:b3:5f:2d:83:9c:e3:5d:
26:8f:9d:81:41:00:81:02:a8:41:f1:90:3a:3c:56:
8a:0a:34:8e:2e:05:99:3a:55:9e:a7:d3:a3:ef:a3:
c3:9d:f0:1e:7d:99:f9:c1:2a:75:7c:2e:21:64:57:
6c:12:3f:1e:e1:4f:89:9c:26:d4:e2:3c:64:70:9f:
50:7d:46:38:91:31:87:1c:87:e5:ae:75:02:0b:ab:
39:2a:d6:e8:b3:73:83:4f:b5:83:db:a9:7d:69:02:
2b:42:39:5c:26:1a:96:4d:5b:97:24:e9:db:59:7f:
a5:b8:29:0b:1f:d9:f3:de:df:74:2b:fe:ea:13:8a:
9a:83:2a:11:4d:b9:95:a2:1b:82:35:24:19:8c:95:
35:66:2b:6c:fc:4d:81:59:dd:ac:6e:6b:05:50:b2:
f6:9d:a1:fd:47:03:09:34:a2:a7:26:16:5f:c8:bf:
74:7e:11:fa:12:0e:92:a6:bd:51:d6:41:78:ce:78:
e5:6a:d7:17:c5:71:bb:3c:d7:de:b1:44:80:89:47:
67:de:57:4e:89:47:86:0d:38:2a:f5:2b:73:8a:be:
30:20:83:e9:5d:2f:fc:39:14:7d:4f:8a:b3:8e:da:
21:95:65:93:cc:3a:42:0c:92:5b:dd:ec:63:79:88:
30:da:ef:ab:ed:6e:fb:59:7c:2d:75:1d:4d:d4:32:
14:4f:9a:bf:57:57:51:7e:49:41:c7:b6:de:ca:32:
6b:b1:78:25:63:25:b7:82:7d:5a:93:25:ca:dc:1b:
b1:fd:12:d4:39:ea:f2:70:3d:a2:18:5d:4e:3c:de:
3b:85:5c:f9:89:2f:19:0e:68:40:8e:a3:88:57:5e:
9f:57:80:b8:c2:7a:5f:25:07:4d:47:8e:b6:0a:94:
5b:bc:e1:b3:70:f9:3f:cb:18:f2:85:a9:10:69:7b:
7f:5e:0d
Exponent: 65537 (0x10001)
X509v3 extensions:
Authority Information Access:
CA Issuers - URI:http://cert.pkioverheid.nl/EVRootCA.cer
OCSP - URI:http://evrootocsp.pkioverheid.nl
X509v3 Subject Key Identifier:
5A:5D:34:25:C1:88:91:73:F9:DE:E1:0C:D5:F4:EA:18:BF:30:34:6E
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Authority Key Identifier:
keyid:FE:AB:00:90:98:9E:24:FC:A9:CC:1A:8A:FB:27:B8:BF:30:6E:A8:3B
X509v3 Certificate Policies:
Policy: 2.16.528.1.1003.1.2.5.8
Policy: 2.16.528.1.1003.1.2.5.9
CPS: https://cps.pkioverheid.nl
Policy: 2.23.140.1.2.2
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.pkioverheid.nl/EVRootLatestCRL.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Client Authentication, TLS Web Server Authentication
Signature Algorithm: sha256WithRSAEncryption
02:6b:65:8d:3b:61:74:64:64:2b:5f:c1:33:04:ef:04:8b:40:
aa:f2:06:66:0a:3b:18:bc:97:76:e4:7e:c4:09:4a:e4:d3:e5:
bc:67:1f:24:be:ae:f2:61:0c:67:f3:9a:22:ee:b5:07:03:f5:
c9:d4:53:33:8f:9a:42:b3:ed:56:00:03:63:bf:e6:9a:f4:e3:
d4:ab:a8:2c:86:5b:62:06:bd:1b:6a:ff:33:86:ca:fe:e4:8d:
11:5b:ab:fa:fb:ed:5b:ce:b0:e9:5e:92:66:f2:66:bc:c8:5e:
a1:b8:51:df:0b:7d:77:8e:e4:ef:75:62:a0:ba:09:85:0e:f8:
5a:1b:27:27:92:64:65:fa:e2:8e:0f:c8:f8:87:dd:7c:20:60:
e7:0a:89:00:59:83:db:a5:80:84:1d:1c:34:a7:46:f6:b9:d1:
98:23:76:b4:66:40:35:4f:ae:b3:75:6b:d6:fa:b6:ef:56:c5:
9f:59:5e:94:13:55:cf:8f:a2:3c:73:0a:e3:f3:65:ea:f5:ef:
c8:61:14:8e:4e:88:9c:1b:43:6e:6c:ac:7b:56:74:d7:dc:3e:
e7:c9:7f:18:e1:06:69:2b:d2:da:05:f4:59:75:dc:66:16:e5:
0a:5c:c2:d8:f0:7d:1f:e4:6b:d3:8a:7b:65:60:d9:36:f1:a2:
3f:44:f3:00:65:5d:a1:2d:87:ca:ee:bf:de:7e:89:cf:48:f2:
44:b4:12:0c:f5:8a:a2:3b:34:08:3c:cc:ff:35:bc:74:c0:b2:
aa:00:44:11:b5:c4:d9:20:37:fb:86:2d:96:28:12:18:19:cd:
9c:40:94:f2:11:0c:06:71:a6:24:49:b8:b6:12:67:9a:fb:69:
2c:68:c7:5a:02:32:84:25:ef:91:b0:ec:65:2f:ea:15:c8:e9:
82:87:b8:27:00:95:e2:b8:d9:ce:a8:21:81:95:96:9c:b2:69:
21:d0:91:ac:9a:35:2a:8a:6f:2c:2f:77:49:e4:14:d2:1f:35:
84:2c:7b:76:49:74:b7:e9:73:6c:d3:ba:6f:53:3e:03:33:81:
19:62:61:1c:cb:0e:49:e2:ff:86:dc:e2:bd:27:21:08:bb:08:
f7:4d:7a:ec:54:07:dc:58:39:30:3f:94:c0:d2:cf:8c:ce:ce:
b9:f1:d7:c0:aa:29:c3:aa:de:1c:7f:00:88:50:03:88:8c:48:
01:1c:ba:89:32:7d:d1:3e:64:b4:d8:a8:d5:f0:3e:ea:71:ae:
e0:dd:bb:62:2c:e4:81:ab:91:c0:e2:be:b7:18:48:6f:82:d1:
e2:bb:fe:67:51:fc:d9:27:55:8b:72:a1:f0:2c:d4:cf:94:0a:
e5:5e:70:ea:ab:40:ff:ab
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIG3TCCBMWgAwIBAgIUXAmaNHU0oKsRSTsZ1VpTisasdLgwDQYJKoZIhvcNAQEL
BQAwWDELMAkGA1UEBhMCTkwxHjAcBgNVBAoMFVN0YWF0IGRlciBOZWRlcmxhbmRl
bjEpMCcGA1UEAwwgU3RhYXQgZGVyIE5lZGVybGFuZGVuIEVWIFJvb3QgQ0EwHhcN
MjAwNzI5MTcyNjI0WhcNMjIxMjA2MDAwMDAwWjBjMQswCQYDVQQGEwJOTDEeMBwG
A1UECgwVU3RhYXQgZGVyIE5lZGVybGFuZGVuMTQwMgYDVQQDDCtTdGFhdCBkZXIg
TmVkZXJsYW5kZW4gRG9tZWluIFNlcnZlciBDQSAyMDIwMIICIjANBgkqhkiG9w0B
AQEFAAOCAg8AMIICCgKCAgEA2fOLVaDCOv+/7m6zfpOpGrKlVgpAuNvI97Djcjkd
/rqcKnCKmCX/ba+LatbvAkBTQB8KHKkUtyFDs/tukLY4ZFPxzUOnb+KsWE2GDyGv
obC76CDeIhFV60wxwLomaeXdyb7dFgxwxUBrWGCd/6SJbNfe+P0iSQQesY2ov1J3
j/W89rRm5/eRwYI5+C8ACsIbkD+dCk//hD4JVQFJKrNfLYOc410mj52BQQCBAqhB
8ZA6PFaKCjSOLgWZOlWep9Oj76PDnfAefZn5wSp1fC4hZFdsEj8e4U+JnCbU4jxk
cJ9QfUY4kTGHHIflrnUCC6s5Ktbos3ODT7WD26l9aQIrQjlcJhqWTVuXJOnbWX+l
uCkLH9nz3t90K/7qE4qagyoRTbmVohuCNSQZjJU1Zits/E2BWd2sbmsFULL2naH9
RwMJNKKnJhZfyL90fhH6Eg6Spr1R1kF4znjlatcXxXG7PNfesUSAiUdn3ldOiUeG
DTgq9Stzir4wIIPpXS/8ORR9T4qzjtohlWWTzDpCDJJb3exjeYgw2u+r7W77WXwt
dR1N1DIUT5q/V1dRfklBx7beyjJrsXglYyW3gn1akyXK3Bux/RLUOerycD2iGF1O
PN47hVz5iS8ZDmhAjqOIV16fV4C4wnpfJQdNR462CpRbvOGzcPk/yxjyhakQaXt/
Xg0CAwEAAaOCAZIwggGOMHEGCCsGAQUFBwEBBGUwYzAzBggrBgEFBQcwAoYnaHR0
cDovL2NlcnQucGtpb3ZlcmhlaWQubmwvRVZSb290Q0EuY2VyMCwGCCsGAQUFBzAB
hiBodHRwOi8vZXZyb290b2NzcC5wa2lvdmVyaGVpZC5ubDAdBgNVHQ4EFgQUWl00
JcGIkXP53uEM1fTqGL8wNG4wDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBT+
qwCQmJ4k/KnMGor7J7i/MG6oOzBZBgNVHSAEUjBQMAwGCmCEEAGHawECBQgwNgYK
YIQQAYdrAQIFCTAoMCYGCCsGAQUFBwIBFhpodHRwczovL2Nwcy5wa2lvdmVyaGVp
ZC5ubDAIBgZngQwBAgIwPgYDVR0fBDcwNTAzoDGgL4YtaHR0cDovL2NybC5wa2lv
dmVyaGVpZC5ubC9FVlJvb3RMYXRlc3RDUkwuY3JsMA4GA1UdDwEB/wQEAwIBBjAd
BgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwDQYJKoZIhvcNAQELBQADggIB
AAJrZY07YXRkZCtfwTME7wSLQKryBmYKOxi8l3bkfsQJSuTT5bxnHyS+rvJhDGfz
miLutQcD9cnUUzOPmkKz7VYAA2O/5pr049SrqCyGW2IGvRtq/zOGyv7kjRFbq/r7
7VvOsOlekmbyZrzIXqG4Ud8LfXeO5O91YqC6CYUO+FobJyeSZGX64o4PyPiH3Xwg
YOcKiQBZg9ulgIQdHDSnRva50ZgjdrRmQDVPrrN1a9b6tu9WxZ9ZXpQTVc+Pojxz
CuPzZer178hhFI5OiJwbQ25srHtWdNfcPufJfxjhBmkr0toF9Fl13GYW5Qpcwtjw
fR/ka9OKe2Vg2Tbxoj9E8wBlXaEth8ruv95+ic9I8kS0Egz1iqI7NAg8zP81vHTA
sqoARBG1xNkgN/uGLZYoEhgZzZxAlPIRDAZxpiRJuLYSZ5r7aSxox1oCMoQl75Gw
7GUv6hXI6YKHuCcAleK42c6oIYGVlpyyaSHQkayaNSqKbywvd0nkFNIfNYQse3ZJ
dLfpc2zTum9TPgMzgRliYRzLDkni/4bc4r0nIQi7CPdNeuxUB9xYOTA/lMDSz4zO
zrnx18CqKcOq3hx/AIhQA4iMSAEcuokyfdE+ZLTYqNXwPupxruDdu2Is5IGrkcDi
vrcYSG+C0eK7/mdR/NknVYtyofAs1M+UCuVecOqrQP+r
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List