NetflixPublicSHA2RSACA3.crt: CN=Netflix Public SHA2 RSA CA 3,O=Netflix, Inc.,C=US (Intermediate Certificate, Expiring 2030-10-20) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://cacerts.digicert.com/NetflixPublicSHA2RSACA3.crt" --output cert.crt

Download certificate through wget:

wget -q "http://cacerts.digicert.com/NetflixPublicSHA2RSACA3.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            35:93:5b:1e:e9:b4:60:89:68:cd:82:92:25:71:a2:0b
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
        Validity
            Not Before: Oct 21 00:00:00 2020 GMT
            Not After : Oct 20 23:59:59 2030 GMT
        Subject: C=US, O=Netflix, Inc., CN=Netflix Public SHA2 RSA CA 3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:cf:40:c6:3c:30:17:0c:d4:9e:df:d1:8c:8d:d8:
                    da:b7:ec:64:3f:b0:e2:66:e8:03:bf:01:ad:1d:91:
                    6d:be:9b:d1:a6:5c:85:e8:4b:f1:1d:7b:f8:aa:aa:
                    1e:41:e8:e8:8d:9f:fe:12:28:b7:ff:7e:9f:27:dc:
                    9a:b3:43:ce:8a:cc:2f:64:0a:32:54:56:11:b1:62:
                    9f:07:c5:66:05:d1:f1:2c:f9:8c:cf:a3:68:83:82:
                    9e:be:3d:81:39:ae:8d:da:4c:b6:1f:5c:92:b9:0e:
                    34:ac:85:4f:b6:43:17:7b:85:26:dd:05:02:3b:39:
                    a3:5c:df:59:49:8a:a8:ac:28:67:87:fb:dd:60:62:
                    2e:8c:d4:54:a1:7f:3b:1b:3b:68:b5:94:84:ff:87:
                    90:d6:26:47:57:37:50:aa:4a:f6:23:06:c7:35:da:
                    39:df:e5:e1:41:24:ae:98:cc:a4:ff:4f:03:1a:15:
                    05:f7:39:ad:6e:aa:27:d4:a3:cc:8f:76:48:d8:a0:
                    b4:9b:26:c9:b2:31:c2:f8:92:a0:7f:a4:10:9a:91:
                    b1:8f:8c:bb:16:e9:ef:67:7e:26:f4:54:f6:ad:ba:
                    78:f3:4f:16:ed:86:f4:45:3f:19:b3:62:02:2f:87:
                    97:6b:90:4b:a4:a5:1b:73:20:ff:aa:2b:a3:3c:35:
                    9b:8b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://s.symcb.com/pca3-g3.crl

            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            Authority Information Access: 
                OCSP - URI:http://s.symcd.com
                CA Issuers - URI:http://cacerts.digicert.com/pca3-g3.crt

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.1
                Policy: 2.23.140.1.2.1
                Policy: 2.23.140.1.2.2
                Policy: 2.23.140.1.2.3

            X509v3 Subject Key Identifier: 
                7D:D2:A8:9C:D6:11:07:3F:AC:7F:CE:92:B8:3F:27:3B:29:C1:04:BF
            X509v3 Authority Key Identifier: 
                keyid:F0:11:5C:20:AB:F0:D0:FE:3D:08:42:EF:95:71:E3:72:C1:1C:12:56

    Signature Algorithm: sha256WithRSAEncryption
         17:d7:51:20:b4:c1:f1:f1:77:1b:a7:70:d6:15:51:81:0e:d1:
         a9:78:e2:46:a9:76:d6:fa:4e:a0:88:f8:52:0c:bf:d8:9b:45:
         04:86:02:9d:c2:c0:84:76:a5:58:13:fe:1e:a0:92:05:f3:71:
         e1:3b:9b:30:e4:5d:c4:19:de:92:d1:f2:76:01:d3:e8:da:1d:
         14:bb:4e:8b:be:1d:c9:f2:58:0e:f4:f2:59:d9:6f:e3:1b:a1:
         cb:0f:7e:13:4e:28:43:9f:d2:0e:05:d1:70:2e:18:eb:6f:d3:
         f8:98:bc:87:10:35:e1:fb:39:c3:29:d1:6c:70:b7:80:d3:6d:
         27:d7:d4:9a:37:6b:d5:ff:4f:0d:38:80:03:f0:c0:29:05:64:
         1a:db:b7:89:ae:37:ac:fd:bd:9c:56:d8:68:ab:99:88:77:c2:
         a3:6e:b3:3e:f6:6c:4d:68:96:1a:48:4d:44:77:03:41:1a:d5:
         1c:b5:4e:b5:e4:09:c2:f1:84:9d:d5:ab:5b:60:c6:30:a5:37:
         7d:88:c9:d4:04:33:33:1e:8a:ea:dd:28:b2:24:6d:09:1b:60:
         9b:4e:34:17:ae:b2:28:2f:e0:05:9e:3f:d8:1c:3e:d8:d5:6c:
         72:a3:b3:f5:37:da:11:fc:4f:be:62:4c:04:92:62:3c:f4:a9:
         ae:b4:99:6b

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIE8jCCA9qgAwIBAgIQNZNbHum0YIlozYKSJXGiCzANBgkqhkiG9w0BAQsFADCB
yjELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMTk5OSBWZXJp
U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MUUwQwYDVQQDEzxW
ZXJpU2lnbiBDbGFzcyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0
aG9yaXR5IC0gRzMwHhcNMjAxMDIxMDAwMDAwWhcNMzAxMDIwMjM1OTU5WjBMMQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNTmV0ZmxpeCwgSW5jLjElMCMGA1UEAxMcTmV0
ZmxpeCBQdWJsaWMgU0hBMiBSU0EgQ0EgMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAM9AxjwwFwzUnt/RjI3Y2rfsZD+w4mboA78BrR2Rbb6b0aZchehL
8R17+KqqHkHo6I2f/hIot/9+nyfcmrNDzorML2QKMlRWEbFinwfFZgXR8Sz5jM+j
aIOCnr49gTmujdpMth9ckrkONKyFT7ZDF3uFJt0FAjs5o1zfWUmKqKwoZ4f73WBi
LozUVKF/Oxs7aLWUhP+HkNYmR1c3UKpK9iMGxzXaOd/l4UEkrpjMpP9PAxoVBfc5
rW6qJ9SjzI92SNigtJsmybIxwviSoH+kEJqRsY+Muxbp72d+JvRU9q26ePNPFu2G
9EU/GbNiAi+Hl2uQS6SlG3Mg/6orozw1m4sCAwEAAaOCAU8wggFLMBIGA1UdEwEB
/wQIMAYBAf8CAQAwLwYDVR0fBCgwJjAkoCKgIIYeaHR0cDovL3Muc3ltY2IuY29t
L3BjYTMtZzMuY3JsMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAOBgNV
HQ8BAf8EBAMCAYYwYwYIKwYBBQUHAQEEVzBVMB4GCCsGAQUFBzABhhJodHRwOi8v
cy5zeW1jZC5jb20wMwYIKwYBBQUHMAKGJ2h0dHA6Ly9jYWNlcnRzLmRpZ2ljZXJ0
LmNvbS9wY2EzLWczLmNydDAwBgNVHSAEKTAnMAcGBWeBDAEBMAgGBmeBDAECATAI
BgZngQwBAgIwCAYGZ4EMAQIDMB0GA1UdDgQWBBR90qic1hEHP6x/zpK4Pyc7KcEE
vzAfBgNVHSMEGDAWgBTwEVwgq/DQ/j0IQu+VceNywRwSVjANBgkqhkiG9w0BAQsF
AAOCAQEAF9dRILTB8fF3G6dw1hVRgQ7RqXjiRql21vpOoIj4Ugy/2JtFBIYCncLA
hHalWBP+HqCSBfNx4TubMORdxBnektHydgHT6NodFLtOi74dyfJYDvTyWdlv4xuh
yw9+E04oQ5/SDgXRcC4Y62/T+Ji8hxA14fs5wynRbHC3gNNtJ9fUmjdr1f9PDTiA
A/DAKQVkGtu3ia43rP29nFbYaKuZiHfCo26zPvZsTWiWGkhNRHcDQRrVHLVOteQJ
wvGEndWrW2DGMKU3fYjJ1AQzMx6K6t0osiRtCRtgm040F66yKC/gBZ4/2Bw+2NVs
cqOz9TfaEfxPvmJMBJJiPPSprrSZaw==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06