G2-RootCA4.orig.cer: CN=Amazon Root CA 4,O=Amazon,C=US (Intermediate Certificate, Expiring 2037-12-31) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/G2-RootCA4.orig.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/G2-RootCA4.orig.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            06:7b:50:4d:83:d3:cb:28:e8:8c:fa:48:bd:96:37:a8:61:ef:92
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2
        Validity
            Not Before: Oct 21 22:21:19 2015 GMT
            Not After : Dec 31 00:00:00 2037 GMT
        Subject: C=US, O=Amazon, CN=Amazon Root CA 4
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:d2:ab:8a:37:4f:a3:53:0d:fe:c1:8a:7b:4b:a8:
                    7b:46:4b:63:b0:62:f6:2d:1b:db:08:71:21:d2:00:
                    e8:63:bd:9a:27:fb:f0:39:6e:5d:ea:3d:a5:c9:81:
                    aa:a3:5b:20:98:45:5d:16:db:fd:e8:10:6d:e3:9c:
                    e0:e3:bd:5f:84:62:f3:70:64:33:a0:cb:24:2f:70:
                    ba:88:a1:2a:a0:75:f8:81:ae:62:06:c4:81:db:39:
                    6e:29:b0:1e:fa:2e:5c
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                D3:EC:C7:3A:65:6E:CC:E1:DA:76:9A:56:FB:9C:F3:86:6D:57:E5:81
            X509v3 Authority Key Identifier: 
                keyid:9C:5F:00:DF:AA:01:D7:30:2B:38:88:A2:B8:6D:4A:9C:F2:11:91:83

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootg2.amazontrust.com
                CA Issuers - URI:http://crl.rootg2.amazontrust.com/rootg2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootg2.amazontrust.com/rootg2.crl

            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

    Signature Algorithm: sha256WithRSAEncryption
         17:79:ad:e3:61:e0:c2:6a:2d:b0:91:5e:be:97:69:80:83:b0:
         fd:87:51:3e:b4:57:9e:b5:81:bd:ff:8f:a3:2a:99:e6:8c:9b:
         d4:8f:76:85:31:d2:4f:83:23:d6:3b:91:c3:9a:32:98:19:b1:
         ff:71:c0:f0:81:02:21:01:be:b8:24:2f:de:a7:53:9b:cc:64:
         36:df:5c:56:df:07:d7:0e:12:97:a1:0f:95:3d:1b:fd:9c:b8:
         ce:a3:5d:37:af:3d:c8:0c:53:ef:3f:46:4a:db:20:4b:77:86:
         5d:0a:ba:2e:bb:00:05:50:d9:f7:27:af:50:cf:44:a0:59:f1:
         39:fc:22:c7:58:63:1d:a6:94:c3:e9:b9:ce:9a:f0:01:ac:1a:
         9e:f4:c7:83:91:6f:d0:d4:35:5d:92:6a:87:5a:d8:fb:e8:b6:
         b1:a1:db:bb:b9:8b:00:d1:ba:9b:81:75:69:47:29:29:8e:56:
         cc:e8:8a:7a:c6:9d:19:6a:ac:37:2d:a7:d9:97:dc:78:4a:17:
         44:f1:69:03:c9:5d:42:4b:4d:06:22:fb:30:ed:92:12:68:fc:
         62:df:f9:1c:dd:9e:12:57:52:1a:c8:95:3c:ed:75:fa:a8:16:
         6a:a6:07:91:1e:26:cd:f6:b2:65:96:c1:a7:6a:43:90:29:0b:
         a3:6f:0b:0b

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIID5DCCAsygAwIBAgITBntQTYPTyyjojPpIvZY3qGHvkjANBgkqhkiG9w0BAQsF
ADCBmDELMAkGA1UEBhMCVVMxEDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNj
b3R0c2RhbGUxJTAjBgNVBAoTHFN0YXJmaWVsZCBUZWNobm9sb2dpZXMsIEluYy4x
OzA5BgNVBAMTMlN0YXJmaWVsZCBTZXJ2aWNlcyBSb290IENlcnRpZmljYXRlIEF1
dGhvcml0eSAtIEcyMB4XDTE1MTAyMTIyMjExOVoXDTM3MTIzMTAwMDAwMFowOTEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEZMBcGA1UEAxMQQW1hem9uIFJv
b3QgQ0EgNDB2MBAGByqGSM49AgEGBSuBBAAiA2IABNKrijdPo1MN/sGKe0uoe0ZL
Y7Bi9i0b2whxIdIA6GO9mif78DluXeo9pcmBqqNbIJhFXRbb/egQbeOc4OO9X4Ri
83BkM6DLJC9wuoihKqB1+IGuYgbEgds5bimwHvouXKOCATEwggEtMA8GA1UdEwEB
/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgGGMB0GA1UdDgQWBBTT7Mc6ZW7M4dp2mlb7
nPOGbVflgTAfBgNVHSMEGDAWgBScXwDfqgHXMCs4iKK4bUqc8hGRgzB4BggrBgEF
BQcBAQRsMGowLgYIKwYBBQUHMAGGImh0dHA6Ly9vY3NwLnJvb3RnMi5hbWF6b250
cnVzdC5jb20wOAYIKwYBBQUHMAKGLGh0dHA6Ly9jcmwucm9vdGcyLmFtYXpvbnRy
dXN0LmNvbS9yb290ZzIuY2VyMD0GA1UdHwQ2MDQwMqAwoC6GLGh0dHA6Ly9jcmwu
cm9vdGcyLmFtYXpvbnRydXN0LmNvbS9yb290ZzIuY3JsMBEGA1UdIAQKMAgwBgYE
VR0gADANBgkqhkiG9w0BAQsFAAOCAQEAF3mt42HgwmotsJFevpdpgIOw/YdRPrRX
nrWBvf+PoyqZ5oyb1I92hTHST4Mj1juRw5oymBmx/3HA8IECIQG+uCQv3qdTm8xk
Nt9cVt8H1w4Sl6EPlT0b/Zy4zqNdN689yAxT7z9GStsgS3eGXQq6LrsABVDZ9yev
UM9EoFnxOfwix1hjHaaUw+m5zprwAawanvTHg5Fv0NQ1XZJqh1rY++i2saHbu7mL
ANG6m4F1aUcpKY5WzOiKesadGWqsNy2n2ZfceEoXRPFpA8ldQktNBiL7MO2SEmj8
Yt/5HN2eEldSGsiVPO11+qgWaqYHkR4mzfayZZbBp2pDkCkLo28LCw==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06