Amazon-RSA-2048-M03.cer: CN=Amazon RSA 2048 M03,O=Amazon,C=US (Intermediate Certificate, Expiring 2030-08-23) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "https://www.amazontrust.com/repository/Amazon-RSA-2048-M03.cer" --output cert.crt

Download certificate through wget:

wget -q "https://www.amazontrust.com/repository/Amazon-RSA-2048-M03.cer" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:73:12:4c:d4:06:d2:67:c0:99:1c:dd:29:9a:9f:38:31:79:85
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Amazon, CN=Amazon Root CA 1
        Validity
            Not Before: Aug 23 22:26:04 2022 GMT
            Not After : Aug 23 22:26:04 2030 GMT
        Subject: C=US, O=Amazon, CN=Amazon RSA 2048 M03
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:b7:7f:a5:59:28:f2:fb:8c:e3:be:53:7f:8e:47:
                    57:70:5b:0a:5f:c1:f4:9c:bc:f4:6d:42:46:41:63:
                    70:f6:34:e9:60:3d:95:2f:bb:75:66:d4:03:b1:ad:
                    59:42:a8:92:ca:fa:f6:12:8c:c1:c3:2c:36:9c:65:
                    c3:b6:f7:8d:e5:c5:83:10:74:f7:f9:e6:6a:57:00:
                    5a:d9:cb:cc:5f:8b:68:32:84:03:90:d0:9a:f2:b3:
                    ba:1d:67:7c:87:ea:12:22:82:41:29:97:5e:1d:3d:
                    5e:cf:9d:3b:b7:26:e6:a6:da:2f:68:61:34:90:92:
                    01:e8:dc:8b:07:2f:38:58:05:36:01:0c:47:8d:b0:
                    9b:a2:88:14:7b:10:5b:6f:23:84:0f:b5:bb:f3:34:
                    a7:a7:d5:c1:17:ae:12:06:5f:2d:f7:71:f3:63:f1:
                    d0:b2:5c:93:79:52:4f:71:01:fc:97:db:76:c7:4e:
                    cf:3c:e0:e5:89:18:d5:d7:ee:a9:ff:32:e5:f5:1e:
                    67:b0:b3:59:76:d3:8e:e8:f0:5f:f4:e8:be:67:96:
                    28:0d:fa:54:b0:b3:ef:96:b3:5b:ab:43:36:e0:e7:
                    eb:a1:4e:a4:00:d9:67:da:26:55:a1:7a:06:a3:49:
                    88:b3:15:97:a3:f7:fd:cd:0e:89:43:02:e9:9e:4e:
                    7c:a7
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Subject Key Identifier: 
                55:D9:18:5F:D2:1C:CC:01:E1:58:B4:BE:AB:D9:55:42:01:D7:2E:02
            X509v3 Authority Key Identifier: 
                keyid:84:18:CC:85:34:EC:BC:0C:94:94:2E:08:59:9C:C7:B2:10:4E:0A:08

            Authority Information Access: 
                OCSP - URI:http://ocsp.rootca1.amazontrust.com
                CA Issuers - URI:http://crt.rootca1.amazontrust.com/rootca1.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.rootca1.amazontrust.com/rootca1.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1

    Signature Algorithm: sha256WithRSAEncryption
         06:8d:e5:a6:d9:c0:be:df:3d:8c:cd:20:a7:b5:ee:3a:ff:b2:
         59:be:3d:e2:41:90:d8:ec:4b:ce:0c:d7:59:17:8d:67:ef:52:
         eb:93:d9:1b:7c:dc:1e:ac:ad:1d:54:dc:d6:df:a5:9e:7e:be:
         e3:ed:94:b0:05:58:39:d1:6e:5a:cb:ae:63:35:23:7b:e1:34:
         d0:57:5c:ad:e1:69:d2:6d:5b:cd:e8:a9:4c:b3:58:62:c8:e6:
         5d:a0:72:ac:28:35:76:50:63:71:6d:da:01:60:24:0d:6b:61:
         98:17:c1:50:21:62:ee:80:da:77:e5:a4:8e:a4:cc:ba:70:59:
         72:98:54:28:98:8a:e7:39:01:f0:2b:59:ef:55:8e:2a:c4:34:
         89:31:4f:e0:34:9c:f5:ec:3f:00:ac:f3:77:9e:09:f2:67:64:
         f0:7a:92:74:b8:12:0d:cf:71:b9:b5:ed:ab:74:55:05:e2:2e:
         18:dc:16:fb:15:49:47:0d:89:b8:bb:c6:88:44:6a:64:d9:9a:
         5f:5e:6c:5a:a3:19:db:20:16:51:bc:62:cf:49:4b:8f:c2:7c:
         28:50:e3:2c:27:c8:e2:ac:8e:6f:b3:67:6f:72:13:db:ec:cb:
         48:d6:b9:5e:8b:4d:9f:da:2b:c7:da:fc:64:8c:32:e5:b5:2a:
         5e:d9:f8:82

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIEXjCCA0agAwIBAgITB3MSTNQG0mfAmRzdKZqfODF5hTANBgkqhkiG9w0BAQsF
ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
b24gUm9vdCBDQSAxMB4XDTIyMDgyMzIyMjYwNFoXDTMwMDgyMzIyMjYwNFowPDEL
MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEcMBoGA1UEAxMTQW1hem9uIFJT
QSAyMDQ4IE0wMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALd/pVko
8vuM475Tf45HV3BbCl/B9Jy89G1CRkFjcPY06WA9lS+7dWbUA7GtWUKoksr69hKM
wcMsNpxlw7b3jeXFgxB09/nmalcAWtnLzF+LaDKEA5DQmvKzuh1nfIfqEiKCQSmX
Xh09Xs+dO7cm5qbaL2hhNJCSAejciwcvOFgFNgEMR42wm6KIFHsQW28jhA+1u/M0
p6fVwReuEgZfLfdx82Px0LJck3lST3EB/JfbdsdOzzzg5YkY1dfuqf8y5fUeZ7Cz
WXbTjujwX/TovmeWKA36VLCz75azW6tDNuDn66FOpADZZ9omVaF6BqNJiLMVl6P3
/c0OiUMC6Z5OfKcCAwEAAaOCAVowggFWMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYD
VR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNV
HQ4EFgQUVdkYX9IczAHhWLS+q9lVQgHXLgIwHwYDVR0jBBgwFoAUhBjMhTTsvAyU
lC4IWZzHshBOCggwewYIKwYBBQUHAQEEbzBtMC8GCCsGAQUFBzABhiNodHRwOi8v
b2NzcC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbTA6BggrBgEFBQcwAoYuaHR0cDov
L2NydC5yb290Y2ExLmFtYXpvbnRydXN0LmNvbS9yb290Y2ExLmNlcjA/BgNVHR8E
ODA2MDSgMqAwhi5odHRwOi8vY3JsLnJvb3RjYTEuYW1hem9udHJ1c3QuY29tL3Jv
b3RjYTEuY3JsMBMGA1UdIAQMMAowCAYGZ4EMAQIBMA0GCSqGSIb3DQEBCwUAA4IB
AQAGjeWm2cC+3z2MzSCnte46/7JZvj3iQZDY7EvODNdZF41n71Lrk9kbfNwerK0d
VNzW36Wefr7j7ZSwBVg50W5ay65jNSN74TTQV1yt4WnSbVvN6KlMs1hiyOZdoHKs
KDV2UGNxbdoBYCQNa2GYF8FQIWLugNp35aSOpMy6cFlymFQomIrnOQHwK1nvVY4q
xDSJMU/gNJz17D8ArPN3ngnyZ2TwepJ0uBINz3G5te2rdFUF4i4Y3Bb7FUlHDYm4
u8aIRGpk2ZpfXmxaoxnbIBZRvGLPSUuPwnwoUOMsJ8jirI5vs2dvchPb7MtI1rle
i02f2ivH2vxkjDLltSpe2fiC
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06