Amazon-RSA-4096-M01.cer: CN=Amazon RSA 4096 M01,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: https://www.amazontrust.com/repository/Amazon-RSA-4096-M01.cer (in DER format )
- Serial Number : 166129363228890173703490318234751053526455749
- SHA-1 Fingerprint : a3e5db3a3049cffdf074e88935485fb993c0ebdc
- SHA-1 Fingerprint : a3:e5:db:3a:30:49:cf:fd:f0:74:e8:89:35:48:5f:b9:93:c0:eb:dc
- SHA-256 Fingerprint : 40fe28dc925d1a8a6b8f861863eb57cd30c6776416ab8a99920bac7c925a4174
- SHA-256 Fingerprint : 40:fe:28:dc:92:5d:1a:8a:6b:8f:86:18:63:eb:57:cd:30:c6:77:64:16:ab:8a:99:92:0b:ac:7c:92:5a:41:74
- Signature Hash Algorithm : sha384
- Subject
: CN=Amazon RSA 4096 M01,O=Amazon,C=US
- Country Name: US (United States of America)
- Organization: Amazon
- Common Name: Amazon RSA 4096 M01
- Not Valid Before: 2022-08-23 22:27:12
- Not Valid After: 2030-08-23 22:27:12
- Issuer (Parent Certificate):
- Issuer Name: CN=Amazon Root CA 2,O=Amazon,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cp-v5-12-Final.pdf
- Certificate Practice Statement (CPS) URL: https://www.digicert.com/content/dam/digicert/pdfs/legal/digicert-cps-v5-12-Final.pdf
- Auditor: BDO International Limited
- Standard Audit URL: https://bugzilla.mozilla.org/attachment.cgi?id=9309728
- Standard Audit Period Start Date: 2021.10.01
- Standard Audit Period End Date: 2022.09.30
- Standard Audit Statement Date: 2022.12.22
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: http://crl.r4m01.amazontrust.com/r4m01.crl
- Check its issuer’s audit information: CN=Amazon Root CA 2,O=Amazon,C=US .
Download certificate through curl
:
curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-4096-M01.cer" --output cert.crt
Download certificate through wget
:
wget -q "https://www.amazontrust.com/repository/Amazon-RSA-4096-M01.cer" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
07:73:12:51:e8:73:49:33:7f:2e:25:9d:84:29:ed:57:8f:d5:c5
Signature Algorithm: sha384WithRSAEncryption
Issuer: C=US, O=Amazon, CN=Amazon Root CA 2
Validity
Not Before: Aug 23 22:27:12 2022 GMT
Not After : Aug 23 22:27:12 2030 GMT
Subject: C=US, O=Amazon, CN=Amazon RSA 4096 M01
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:e3:46:ed:86:fb:c6:a8:d3:84:ef:a3:38:d2:aa:
cb:d6:5b:03:ef:9e:b3:a5:ef:5a:a8:e4:af:14:0f:
7b:dd:65:7a:5b:c0:1b:96:9c:c1:a2:05:cc:1f:3f:
2a:3a:10:b5:29:63:58:7b:c4:6d:d4:2f:53:52:fa:
41:e6:b0:c2:d7:3c:80:a5:70:a6:7e:6b:34:ac:95:
4c:4b:3a:02:7d:96:b7:83:01:4d:e0:a3:c7:27:ec:
c0:46:e5:8a:71:40:e1:13:73:96:75:d0:ab:46:57:
d5:e6:cf:ef:d4:c9:d0:ed:32:6d:25:26:a9:2d:1d:
61:53:2c:61:e5:8a:85:20:ff:95:0c:74:17:55:90:
8b:04:d9:ce:07:49:3c:4a:65:4d:2c:f0:dc:a9:6e:
6f:42:cc:a5:cc:53:79:f8:7d:17:e2:bc:d8:42:f6:
66:d7:7d:f7:53:a9:ca:b8:1d:a4:c4:b6:86:43:09:
20:2c:b3:cc:96:03:bd:35:10:43:f3:91:56:7a:09:
24:d5:5a:c7:e9:29:df:c4:4e:1c:bc:21:85:d7:ae:
4a:78:ba:c8:e8:bb:c2:f8:bd:2e:d4:49:7d:23:33:
a4:48:62:78:88:dd:92:8a:7b:29:1f:a6:df:8c:5f:
db:74:af:65:f2:cf:66:a4:d0:ec:b4:01:16:54:50:
89:02:b7:38:9e:69:f7:59:5c:8a:c6:a0:18:2f:b6:
e2:04:00:ab:d6:fd:dc:58:d2:9c:f6:3d:65:c3:ce:
e2:18:3a:7a:b4:41:b2:12:19:91:69:24:fa:8e:d7:
4c:08:6a:a9:47:8c:ba:71:b0:d9:6e:d3:e2:90:70:
e8:c0:57:ed:09:29:3e:3c:d6:b7:86:60:66:92:e5:
b0:b3:cd:43:ce:03:cb:ff:28:10:1a:8e:74:25:84:
c1:58:2f:57:40:3a:05:b7:0c:fe:5f:53:94:e7:bb:
02:49:86:2f:de:ad:ba:07:08:6b:24:48:3a:90:ec:
7b:98:98:5c:37:3d:3a:07:48:69:a5:12:bc:65:5e:
2c:f0:5f:48:15:8b:df:f9:bf:18:5e:fb:8d:91:7c:
99:1c:e1:d0:49:c3:30:f8:3b:35:73:be:df:91:a8:
5b:d4:09:59:61:11:c7:46:0a:75:4d:0c:45:5d:a6:
88:a8:0f:5d:2e:b9:57:f1:fb:77:cd:dc:5d:0c:66:
ea:f7:c0:ac:70:e5:dd:97:ad:8f:d3:f8:c2:fd:d2:
7f:62:62:45:bd:97:6b:3f:12:9e:51:d0:0c:2b:2a:
7e:25:bd:18:a2:ae:94:da:1a:21:e8:28:0a:5b:ee:
f7:37:e3:21:4b:dd:43:a9:12:97:26:cc:c6:56:ef:
bc:ba:a3
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Subject Key Identifier:
27:3B:B8:44:76:93:F1:3C:17:C3:4D:B3:BD:21:1D:64:99:67:7E:BC
X509v3 Authority Key Identifier:
keyid:B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52
Authority Information Access:
OCSP - URI:http://ocsp.rootca2.amazontrust.com
CA Issuers - URI:http://crt.rootca2.amazontrust.com/rootca2.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.rootca2.amazontrust.com/rootca2.crl
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Signature Algorithm: sha384WithRSAEncryption
02:42:1b:df:a5:3f:89:5c:41:38:86:dd:30:7c:fa:ce:80:0d:
e0:82:d8:18:e4:ef:71:1f:c7:77:24:06:e1:bf:bc:72:00:e3:
c6:46:27:ae:4f:e0:28:e6:5f:a9:db:c4:7a:b9:88:fe:67:d5:
5d:c5:a3:4c:95:6a:66:46:95:3e:9f:71:f6:cb:e9:a5:95:8e:
3f:10:1a:23:eb:44:01:17:95:3d:e2:24:54:d9:df:7e:37:c8:
c3:94:67:34:ce:a1:4a:63:bd:dc:48:48:83:59:c3:e7:b7:59:
4c:07:b0:19:86:74:da:9b:9a:f0:85:56:65:31:ca:9f:59:05:
e1:42:89:da:3f:b8:6b:51:51:dc:a4:41:98:c6:dc:5e:f6:d0:
d1:7f:c0:7d:45:3c:6d:fc:9e:a3:55:7c:ee:97:e5:e1:c3:62:
03:cf:ab:a2:96:af:8b:da:97:b1:e0:16:8c:ec:92:87:62:d1:
0c:27:6d:d5:95:28:62:e9:e1:5f:7c:3b:23:e5:b1:20:a4:0e:
14:37:25:25:10:69:2c:44:a1:bb:fc:5d:8b:72:5b:87:65:0d:
d7:81:3e:42:ca:4b:d3:7b:1a:fd:33:ea:a7:f8:35:34:90:6d:
77:55:4e:56:cd:6b:e7:02:be:e8:95:3a:5d:b4:1a:f1:2b:4d:
99:60:50:ff:17:6c:a9:8d:78:88:84:9e:c3:69:63:5b:16:6a:
98:12:c3:d1:70:ed:a8:56:e3:79:2a:7e:40:f5:88:07:f3:70:
ed:6d:a4:7c:8a:fe:95:6f:87:64:39:7b:dd:b9:ba:c6:5f:9a:
b8:a2:3e:fc:3f:0b:81:49:0e:c9:3e:80:89:d7:6c:ac:d9:c2:
66:bb:ee:99:3e:19:2b:a6:0e:a1:f5:ff:6b:46:eb:dc:57:06:
8c:08:03:48:c1:ea:45:57:59:a0:18:3d:7d:61:c6:29:e8:4d:
c2:55:d5:cc:fa:cc:4d:b4:44:7d:b0:96:44:42:03:be:ca:f6:
c0:32:bf:91:34:27:ac:f2:23:a1:4d:f4:e5:ba:47:87:9a:3c:
dd:bf:66:de:58:bb:82:13:d3:16:ce:fd:47:fc:2c:09:e6:91:
12:dc:21:4c:97:fc:ac:b6:9d:c2:c4:d4:cc:cb:ae:bc:e0:48:
d8:15:5e:25:ba:68:9f:5f:71:47:af:00:f3:de:21:c6:e1:ff:
65:d8:38:32:b7:af:17:cc:e9:92:80:5f:a0:b3:df:04:a9:ee:
e7:46:5a:80:3f:98:29:f8:65:1a:53:3a:f2:14:2a:82:92:53:
52:23:44:54:01:d7:f4:ce:9f:ba:76:86:a9:d9:ce:ab:5e:1d:
c8:a3:73:94:d8:98:b0:b6
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIGXjCCBEagAwIBAgITB3MSUehzSTN/LiWdhCntV4/VxTANBgkqhkiG9w0BAQwF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAyMB4XDTIyMDgyMzIyMjcxMloXDTMwMDgyMzIyMjcxMlowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSA0MDk2IE0wMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAONG7Yb7
xqjThO+jONKqy9ZbA++es6XvWqjkrxQPe91lelvAG5acwaIFzB8/KjoQtSljWHvE
bdQvU1L6Qeawwtc8gKVwpn5rNKyVTEs6An2Wt4MBTeCjxyfswEblinFA4RNzlnXQ
q0ZX1ebP79TJ0O0ybSUmqS0dYVMsYeWKhSD/lQx0F1WQiwTZzgdJPEplTSzw3Klu
b0LMpcxTefh9F+K82EL2Ztd991OpyrgdpMS2hkMJICyzzJYDvTUQQ/ORVnoJJNVa
x+kp38ROHLwhhdeuSni6yOi7wvi9LtRJfSMzpEhieIjdkop7KR+m34xf23SvZfLP
ZqTQ7LQBFlRQiQK3OJ5p91lcisagGC+24gQAq9b93FjSnPY9ZcPO4hg6erRBshIZ
kWkk+o7XTAhqqUeMunGw2W7T4pBw6MBX7QkpPjzWt4ZgZpLlsLPNQ84Dy/8oEBqO
dCWEwVgvV0A6BbcM/l9TlOe7AkmGL96tugcIayRIOpDse5iYXDc9OgdIaaUSvGVe
LPBfSBWL3/m/GF77jZF8mRzh0EnDMPg7NXO+35GoW9QJWWERx0YKdU0MRV2miKgP
XS65V/H7d83cXQxm6vfArHDl3Zetj9P4wv3Sf2JiRb2Xaz8SnlHQDCsqfiW9GKKu
lNoaIegoClvu9zfjIUvdQ6kSlybMxlbvvLqjAgMBAAGjggFaMIIBVjASBgNVHRMB
Af8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwHQYDVR0OBBYEFCc7uER2k/E8F8NNs70hHWSZZ368MB8GA1Ud
IwQYMBaAFLAM8Eww9AVYAkj9M+VSr0uE42ZSMHsGCCsGAQUFBwEBBG8wbTAvBggr
BgEFBQcwAYYjaHR0cDovL29jc3Aucm9vdGNhMi5hbWF6b250cnVzdC5jb20wOgYI
KwYBBQUHMAKGLmh0dHA6Ly9jcnQucm9vdGNhMi5hbWF6b250cnVzdC5jb20vcm9v
dGNhMi5jZXIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2NybC5yb290Y2EyLmFt
YXpvbnRydXN0LmNvbS9yb290Y2EyLmNybDATBgNVHSAEDDAKMAgGBmeBDAECATAN
BgkqhkiG9w0BAQwFAAOCAgEAAkIb36U/iVxBOIbdMHz6zoAN4ILYGOTvcR/HdyQG
4b+8cgDjxkYnrk/gKOZfqdvEermI/mfVXcWjTJVqZkaVPp9x9svppZWOPxAaI+tE
AReVPeIkVNnffjfIw5RnNM6hSmO93EhIg1nD57dZTAewGYZ02pua8IVWZTHKn1kF
4UKJ2j+4a1FR3KRBmMbcXvbQ0X/AfUU8bfyeo1V87pfl4cNiA8+ropavi9qXseAW
jOySh2LRDCdt1ZUoYunhX3w7I+WxIKQOFDclJRBpLEShu/xdi3Jbh2UN14E+QspL
03sa/TPqp/g1NJBtd1VOVs1r5wK+6JU6XbQa8StNmWBQ/xdsqY14iISew2ljWxZq
mBLD0XDtqFbjeSp+QPWIB/Nw7W2kfIr+lW+HZDl73bm6xl+auKI+/D8LgUkOyT6A
iddsrNnCZrvumT4ZK6YOofX/a0br3FcGjAgDSMHqRVdZoBg9fWHGKehNwlXVzPrM
TbREfbCWREIDvsr2wDK/kTQnrPIjoU305bpHh5o83b9m3li7ghPTFs79R/wsCeaR
EtwhTJf8rLadwsTUzMuuvOBI2BVeJbpon19xR68A894hxuH/Zdg4MrevF8zpkoBf
oLPfBKnu50ZagD+YKfhlGlM68hQqgpJTUiNEVAHX9M6funaGqdnOq14dyKNzlNiY
sLY=
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Amazon-ECDSA-256-M01.cer: CN=Amazon ECDSA 256 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M02.cer: CN=Amazon ECDSA 256 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M03.cer: CN=Amazon ECDSA 256 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-256-M04.cer: CN=Amazon ECDSA 256 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M01.cer: CN=Amazon ECDSA 384 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M02.cer: CN=Amazon ECDSA 384 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M03.cer: CN=Amazon ECDSA 384 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-ECDSA-384-M04.cer: CN=Amazon ECDSA 384 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M01.cer: CN=Amazon RSA 2048 M01,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M02.cer: CN=Amazon RSA 2048 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M03.cer: CN=Amazon RSA 2048 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-2048-M04.cer: CN=Amazon RSA 2048 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M02.cer: CN=Amazon RSA 4096 M02,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M03.cer: CN=Amazon RSA 4096 M03,O=Amazon,C=US (Expiring: 2030-08-23)
- Amazon-RSA-4096-M04.cer: CN=Amazon RSA 4096 M04,O=Amazon,C=US (Expiring: 2030-08-23)
- rootca1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2038-01-17)
- G2-RootCA1.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA1.orig.cer: CN=Amazon Root CA 1,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA2.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA2.orig.cer: CN=Amazon Root CA 2,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA3.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA3.orig.cer: CN=Amazon Root CA 3,O=Amazon,C=US (Expiring: 2037-12-31)
- AmazonRootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2040-05-26)
- G2-RootCA4.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-RootCA4.orig.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Expiring: 2037-12-31)
- G2-ServerCA0A.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2025-10-19)
- G2-ServerCA0A.orig.cer: CN=Amazon,OU=Server CA 0A,O=Amazon,C=US (Expiring: 2040-10-21)
- R1-ServerCA1A.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1A.orig.cer: CN=Amazon,OU=Server CA 1A,O=Amazon,C=US (Expiring: 2040-10-21)
- sca1b.crt: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2025-10-19)
- R1-ServerCA1B.orig.cer: CN=Amazon,OU=Server CA 1B,O=Amazon,C=US (Expiring: 2040-10-21)
- R2-ServerCA2A.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2025-10-19)
- R2-ServerCA2A.orig.cer: CN=Amazon,OU=Server CA 2A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3A.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2025-10-19)
- R3-ServerCA3A.orig.cer: CN=Amazon,OU=Server CA 3A,O=Amazon,C=US (Expiring: 2040-10-21)
- R3-ServerCA3B.cer: CN=Amazon,OU=Server CA 3B,O=Amazon,C=US (Expiring: 2028-07-16)
- R4-ServerCA4A.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2025-10-19)
- R4-ServerCA4A.orig.cer: CN=Amazon,OU=Server CA 4A,O=Amazon,C=US (Expiring: 2040-10-21)
- rootg2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFC2CA-SFSRootCAG2.v2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2034-06-28)
- SFSRootCA-SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2031-05-30)
- SFSRootCAG2.cer: CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies, Inc.,L=Scottsdale,ST=Arizona,C=US (Expiring: 2037-12-31)