cacert.crt: CN=DFN-Verein Certification Authority 2,OU=DFN-PKI,O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.,C=DE (Intermediate Certificate, Expiring 2031-02-22) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is intermediate certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://cdp1.pca.dfn.de/global-root-g2-ca/pub/cacert/cacert.crt" --output cert.crt

Download certificate through wget:

wget -q "http://cdp1.pca.dfn.de/global-root-g2-ca/pub/cacert/cacert.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            e3:0b:d5:f8:af:25:d9:81
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 2
        Validity
            Not Before: Feb 22 13:38:22 2016 GMT
            Not After : Feb 22 23:59:59 2031 GMT
        Subject: C=DE, O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V., OU=DFN-PKI, CN=DFN-Verein Certification Authority 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:cb:60:d7:ff:66:a1:41:cd:d2:fa:87:97:8a:73:
                    ab:99:4d:ea:67:39:5a:a1:60:80:47:15:4e:8c:95:
                    b2:e5:cf:ce:d3:57:4b:8d:ce:f8:56:6c:15:55:76:
                    07:ea:46:fd:c8:03:45:63:3e:70:d4:ab:54:80:b1:
                    23:9c:be:37:28:a9:09:ff:05:5d:18:0f:c4:98:99:
                    37:b3:20:f6:66:78:17:87:c2:9d:0e:cc:4a:32:e7:
                    16:9d:ae:0e:8d:29:79:07:00:20:54:dc:15:5f:4a:
                    96:d7:78:b6:34:d3:c1:74:b5:9d:e9:bf:c0:77:4d:
                    ea:bd:59:07:e0:5a:2f:6c:3c:a5:00:dc:35:bd:65:
                    0d:8f:7f:32:6d:f2:5a:6a:4b:62:01:ee:ac:38:34:
                    59:45:36:49:05:da:78:ca:6a:6d:5b:c0:81:6b:11:
                    cc:d2:3c:a8:8b:f8:71:1a:ca:3b:e2:80:dd:16:b4:
                    67:7a:8b:36:ea:4e:91:29:3d:b3:51:5c:ad:a8:0c:
                    be:9d:34:e3:d1:0d:17:83:75:c4:39:1e:b0:94:0b:
                    12:f1:d5:69:8e:25:f4:b8:3d:2b:bf:c0:8e:c3:1e:
                    3b:a5:bf:55:10:ab:2a:ae:17:97:5e:33:ce:c8:f3:
                    f4:09:07:e3:02:86:31:46:6b:01:c5:10:0c:11:c7:
                    59:e9
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Subject Key Identifier: 
                93:E3:D8:32:26:DA:D5:F1:4A:A5:91:4A:E0:EA:4B:E2:A2:0C:CF:E1
            X509v3 Authority Key Identifier: 
                keyid:BF:59:20:36:00:79:A0:A0:22:6B:8C:D5:F2:61:D2:B8:2C:CB:82:4A

            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:2
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.22177.300.1.1.4
                Policy: 1.3.6.1.4.1.22177.300.30
                Policy: 2.23.140.1.2.2

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://pki0336.telesec.de/rl/TeleSec_GlobalRoot_Class_2.crl

            Authority Information Access: 
                OCSP - URI:http://ocsp0336.telesec.de/ocspr
                CA Issuers - URI:http://pki0336.telesec.de/crt/TeleSec_GlobalRoot_Class_2.cer

    Signature Algorithm: sha256WithRSAEncryption
         87:0b:ff:3e:02:9b:65:c8:56:2d:d6:3b:9a:98:8b:71:4f:da:
         ba:29:aa:21:f9:46:2e:f5:b2:a4:0f:ae:11:38:79:38:b3:0e:
         74:ba:76:5d:9e:e8:18:82:96:62:db:4c:33:e8:dd:f9:6a:df:
         32:bd:2c:4c:47:60:55:7f:e7:74:6b:b4:2c:83:d8:79:6b:b6:
         b7:4d:50:0b:66:07:b5:ed:b3:97:ad:ea:ee:7f:30:e6:99:fd:
         22:e2:72:4d:3e:84:5b:ee:f9:cf:99:ea:7f:d7:52:39:2e:ac:
         98:00:44:7e:69:3b:bf:75:ee:d0:0b:3b:1a:cd:e5:f7:0f:22:
         6c:47:84:f6:a5:47:a0:fd:d0:1a:34:7d:ad:d2:3d:77:b3:ee:
         f4:d7:4d:ff:c3:e8:e5:92:4f:59:3e:90:47:10:4a:b0:85:58:
         c0:6f:7f:f8:ae:ed:08:42:9e:1e:d4:df:14:2e:4d:8f:bc:9e:
         94:c3:e7:ed:f6:18:f8:3c:49:e7:26:a8:a7:36:d8:2c:de:22:
         cd:8b:82:d8:d9:78:e2:55:12:a3:3b:87:44:b6:11:0b:d5:0c:
         52:af:69:8c:0f:06:df:d0:a2:53:8b:57:98:7b:cf:fd:07:24:
         f4:fc:bd:c3:fd:4a:92:02:97:1b:f2:b7:b6:cf:65:8a:1a:a2:
         b5:72:19:39

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIFEjCCA/qgAwIBAgIJAOML1fivJdmBMA0GCSqGSIb3DQEBCwUAMIGCMQswCQYD
VQQGEwJERTErMCkGA1UECgwiVC1TeXN0ZW1zIEVudGVycHJpc2UgU2VydmljZXMg
R21iSDEfMB0GA1UECwwWVC1TeXN0ZW1zIFRydXN0IENlbnRlcjElMCMGA1UEAwwc
VC1UZWxlU2VjIEdsb2JhbFJvb3QgQ2xhc3MgMjAeFw0xNjAyMjIxMzM4MjJaFw0z
MTAyMjIyMzU5NTlaMIGVMQswCQYDVQQGEwJERTFFMEMGA1UEChM8VmVyZWluIHp1
ciBGb2VyZGVydW5nIGVpbmVzIERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUu
IFYuMRAwDgYDVQQLEwdERk4tUEtJMS0wKwYDVQQDEyRERk4tVmVyZWluIENlcnRp
ZmljYXRpb24gQXV0aG9yaXR5IDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDLYNf/ZqFBzdL6h5eKc6uZTepnOVqhYIBHFU6MlbLlz87TV0uNzvhWbBVV
dgfqRv3IA0VjPnDUq1SAsSOcvjcoqQn/BV0YD8SYmTezIPZmeBeHwp0OzEoy5xad
rg6NKXkHACBU3BVfSpbXeLY008F0tZ3pv8B3Teq9WQfgWi9sPKUA3DW9ZQ2PfzJt
8lpqS2IB7qw4NFlFNkkF2njKam1bwIFrEczSPKiL+HEayjvigN0WtGd6izbqTpEp
PbNRXK2oDL6dNOPRDReDdcQ5HrCUCxLx1WmOJfS4PSu/wI7DHjulv1UQqyquF5de
M87I8/QJB+MChjFGawHFEAwRx1npAgMBAAGjggF0MIIBcDAOBgNVHQ8BAf8EBAMC
AQYwHQYDVR0OBBYEFJPj2DIm2tXxSqWRSuDqS+KiDM/hMB8GA1UdIwQYMBaAFL9Z
IDYAeaCgImuM1fJh0rgsy4JKMBIGA1UdEwEB/wQIMAYBAf8CAQIwMwYDVR0gBCww
KjAPBg0rBgEEAYGtIYIsAQEEMA0GCysGAQQBga0hgiweMAgGBmeBDAECAjBMBgNV
HR8ERTBDMEGgP6A9hjtodHRwOi8vcGtpMDMzNi50ZWxlc2VjLmRlL3JsL1RlbGVT
ZWNfR2xvYmFsUm9vdF9DbGFzc18yLmNybDCBhgYIKwYBBQUHAQEEejB4MCwGCCsG
AQUFBzABhiBodHRwOi8vb2NzcDAzMzYudGVsZXNlYy5kZS9vY3NwcjBIBggrBgEF
BQcwAoY8aHR0cDovL3BraTAzMzYudGVsZXNlYy5kZS9jcnQvVGVsZVNlY19HbG9i
YWxSb290X0NsYXNzXzIuY2VyMA0GCSqGSIb3DQEBCwUAA4IBAQCHC/8+AptlyFYt
1juamItxT9q6Kaoh+UYu9bKkD64ROHk4sw50unZdnugYgpZi20wz6N35at8yvSxM
R2BVf+d0a7Qsg9h5a7a3TVALZge17bOXrerufzDmmf0i4nJNPoRb7vnPmep/11I5
LqyYAER+aTu/de7QCzsazeX3DyJsR4T2pUeg/dAaNH2t0j13s+70103/w+jlkk9Z
PpBHEEqwhVjAb3/4ru0IQp4e1N8ULk2PvJ6Uw+ft9hj4PEnnJqinNtgs3iLNi4LY
2XjiVRKjO4dEthEL1QxSr2mMDwbf0KJTi1eYe8/9ByT0/L3D/UqSApcb8re2z2WK
GqK1chk5
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06