cacert.crt: CN=DFN-Verein Certification Authority 2,OU=DFN-PKI,O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.,C=DE (Intermediate Certificate, Expiring 2031-02-22) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: http://cdp1.pca.dfn.de/global-root-g2-ca/pub/cacert/cacert.crt (in DER format )
- Serial Number : 16360405335420557697
- SHA-1 Fingerprint : e224bef6d786220d262bb807ab6dacf9d3a89a93
- SHA-1 Fingerprint : e2:24:be:f6:d7:86:22:0d:26:2b:b8:07:ab:6d:ac:f9:d3:a8:9a:93
- SHA-256 Fingerprint : f660b0c256481cb2bfc67661c1ea8feee395b7141bcac36c36e04d08cd9e1582
- SHA-256 Fingerprint : f6:60:b0:c2:56:48:1c:b2:bf:c6:76:61:c1:ea:8f:ee:e3:95:b7:14:1b:ca:c3:6c:36:e0:4d:08:cd:9e:15:82
- Signature Hash Algorithm : sha256
- Subject
: CN=DFN-Verein Certification Authority 2,OU=DFN-PKI,O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.,C=DE
- Country Name: DE (Germany)
- Organization: Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.
- Organization Unit: DFN-PKI
- Common Name: DFN-Verein Certification Authority 2
- Not Valid Before: 2016-02-22 13:38:22
- Not Valid After: 2031-02-22 23:59:59
- Issuer (Parent Certificate):
- Issuer Name: CN=T-TeleSec GlobalRoot Class 2,OU=T-Systems Trust Center,O=T-Systems Enterprise Services GmbH,C=DE
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.pki.dfn.de/fileadmin/PKI/DFN-PKI_CP-EN.pdf
- Certificate Practice Statement (CPS) URL: https://www.pki.dfn.de/fileadmin/PKI/DFN-PKI_CPS-EN.pdf
- Auditor: TÜViT - TÜV Informationstechnik GmbH
- Standard Audit URL: https://www.tuvit.de/fileadmin/Content/TUV_IT/zertifikate/de/AA2022112101_DFN-Verein_Certification_Authority_2_V1.0.pdf
- Standard Audit Period Start Date: 2021.09.02
- Standard Audit Period End Date: 2022.09.01
- Standard Audit Statement Date: 2022.11.21
- Standard Audit Type: ETSI EN 319 411
- Full CRL Issued By This CA: http://cdp1.pca.dfn.de/global-root-g2-ca/pub/crl/cacrl.crl
- Check its issuer’s audit information: CN=T-TeleSec GlobalRoot Class 2,OU=T-Systems Trust Center,O=T-Systems Enterprise Services GmbH,C=DE .
Download certificate through curl
:
curl -sSL "http://cdp1.pca.dfn.de/global-root-g2-ca/pub/cacert/cacert.crt" --output cert.crt
Download certificate through wget
:
wget -q "http://cdp1.pca.dfn.de/global-root-g2-ca/pub/cacert/cacert.crt" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
e3:0b:d5:f8:af:25:d9:81
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 2
Validity
Not Before: Feb 22 13:38:22 2016 GMT
Not After : Feb 22 23:59:59 2031 GMT
Subject: C=DE, O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V., OU=DFN-PKI, CN=DFN-Verein Certification Authority 2
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:cb:60:d7:ff:66:a1:41:cd:d2:fa:87:97:8a:73:
ab:99:4d:ea:67:39:5a:a1:60:80:47:15:4e:8c:95:
b2:e5:cf:ce:d3:57:4b:8d:ce:f8:56:6c:15:55:76:
07:ea:46:fd:c8:03:45:63:3e:70:d4:ab:54:80:b1:
23:9c:be:37:28:a9:09:ff:05:5d:18:0f:c4:98:99:
37:b3:20:f6:66:78:17:87:c2:9d:0e:cc:4a:32:e7:
16:9d:ae:0e:8d:29:79:07:00:20:54:dc:15:5f:4a:
96:d7:78:b6:34:d3:c1:74:b5:9d:e9:bf:c0:77:4d:
ea:bd:59:07:e0:5a:2f:6c:3c:a5:00:dc:35:bd:65:
0d:8f:7f:32:6d:f2:5a:6a:4b:62:01:ee:ac:38:34:
59:45:36:49:05:da:78:ca:6a:6d:5b:c0:81:6b:11:
cc:d2:3c:a8:8b:f8:71:1a:ca:3b:e2:80:dd:16:b4:
67:7a:8b:36:ea:4e:91:29:3d:b3:51:5c:ad:a8:0c:
be:9d:34:e3:d1:0d:17:83:75:c4:39:1e:b0:94:0b:
12:f1:d5:69:8e:25:f4:b8:3d:2b:bf:c0:8e:c3:1e:
3b:a5:bf:55:10:ab:2a:ae:17:97:5e:33:ce:c8:f3:
f4:09:07:e3:02:86:31:46:6b:01:c5:10:0c:11:c7:
59:e9
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Subject Key Identifier:
93:E3:D8:32:26:DA:D5:F1:4A:A5:91:4A:E0:EA:4B:E2:A2:0C:CF:E1
X509v3 Authority Key Identifier:
keyid:BF:59:20:36:00:79:A0:A0:22:6B:8C:D5:F2:61:D2:B8:2C:CB:82:4A
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:2
X509v3 Certificate Policies:
Policy: 1.3.6.1.4.1.22177.300.1.1.4
Policy: 1.3.6.1.4.1.22177.300.30
Policy: 2.23.140.1.2.2
X509v3 CRL Distribution Points:
Full Name:
URI:http://pki0336.telesec.de/rl/TeleSec_GlobalRoot_Class_2.crl
Authority Information Access:
OCSP - URI:http://ocsp0336.telesec.de/ocspr
CA Issuers - URI:http://pki0336.telesec.de/crt/TeleSec_GlobalRoot_Class_2.cer
Signature Algorithm: sha256WithRSAEncryption
87:0b:ff:3e:02:9b:65:c8:56:2d:d6:3b:9a:98:8b:71:4f:da:
ba:29:aa:21:f9:46:2e:f5:b2:a4:0f:ae:11:38:79:38:b3:0e:
74:ba:76:5d:9e:e8:18:82:96:62:db:4c:33:e8:dd:f9:6a:df:
32:bd:2c:4c:47:60:55:7f:e7:74:6b:b4:2c:83:d8:79:6b:b6:
b7:4d:50:0b:66:07:b5:ed:b3:97:ad:ea:ee:7f:30:e6:99:fd:
22:e2:72:4d:3e:84:5b:ee:f9:cf:99:ea:7f:d7:52:39:2e:ac:
98:00:44:7e:69:3b:bf:75:ee:d0:0b:3b:1a:cd:e5:f7:0f:22:
6c:47:84:f6:a5:47:a0:fd:d0:1a:34:7d:ad:d2:3d:77:b3:ee:
f4:d7:4d:ff:c3:e8:e5:92:4f:59:3e:90:47:10:4a:b0:85:58:
c0:6f:7f:f8:ae:ed:08:42:9e:1e:d4:df:14:2e:4d:8f:bc:9e:
94:c3:e7:ed:f6:18:f8:3c:49:e7:26:a8:a7:36:d8:2c:de:22:
cd:8b:82:d8:d9:78:e2:55:12:a3:3b:87:44:b6:11:0b:d5:0c:
52:af:69:8c:0f:06:df:d0:a2:53:8b:57:98:7b:cf:fd:07:24:
f4:fc:bd:c3:fd:4a:92:02:97:1b:f2:b7:b6:cf:65:8a:1a:a2:
b5:72:19:39
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIFEjCCA/qgAwIBAgIJAOML1fivJdmBMA0GCSqGSIb3DQEBCwUAMIGCMQswCQYD
VQQGEwJERTErMCkGA1UECgwiVC1TeXN0ZW1zIEVudGVycHJpc2UgU2VydmljZXMg
R21iSDEfMB0GA1UECwwWVC1TeXN0ZW1zIFRydXN0IENlbnRlcjElMCMGA1UEAwwc
VC1UZWxlU2VjIEdsb2JhbFJvb3QgQ2xhc3MgMjAeFw0xNjAyMjIxMzM4MjJaFw0z
MTAyMjIyMzU5NTlaMIGVMQswCQYDVQQGEwJERTFFMEMGA1UEChM8VmVyZWluIHp1
ciBGb2VyZGVydW5nIGVpbmVzIERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUu
IFYuMRAwDgYDVQQLEwdERk4tUEtJMS0wKwYDVQQDEyRERk4tVmVyZWluIENlcnRp
ZmljYXRpb24gQXV0aG9yaXR5IDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDLYNf/ZqFBzdL6h5eKc6uZTepnOVqhYIBHFU6MlbLlz87TV0uNzvhWbBVV
dgfqRv3IA0VjPnDUq1SAsSOcvjcoqQn/BV0YD8SYmTezIPZmeBeHwp0OzEoy5xad
rg6NKXkHACBU3BVfSpbXeLY008F0tZ3pv8B3Teq9WQfgWi9sPKUA3DW9ZQ2PfzJt
8lpqS2IB7qw4NFlFNkkF2njKam1bwIFrEczSPKiL+HEayjvigN0WtGd6izbqTpEp
PbNRXK2oDL6dNOPRDReDdcQ5HrCUCxLx1WmOJfS4PSu/wI7DHjulv1UQqyquF5de
M87I8/QJB+MChjFGawHFEAwRx1npAgMBAAGjggF0MIIBcDAOBgNVHQ8BAf8EBAMC
AQYwHQYDVR0OBBYEFJPj2DIm2tXxSqWRSuDqS+KiDM/hMB8GA1UdIwQYMBaAFL9Z
IDYAeaCgImuM1fJh0rgsy4JKMBIGA1UdEwEB/wQIMAYBAf8CAQIwMwYDVR0gBCww
KjAPBg0rBgEEAYGtIYIsAQEEMA0GCysGAQQBga0hgiweMAgGBmeBDAECAjBMBgNV
HR8ERTBDMEGgP6A9hjtodHRwOi8vcGtpMDMzNi50ZWxlc2VjLmRlL3JsL1RlbGVT
ZWNfR2xvYmFsUm9vdF9DbGFzc18yLmNybDCBhgYIKwYBBQUHAQEEejB4MCwGCCsG
AQUFBzABhiBodHRwOi8vb2NzcDAzMzYudGVsZXNlYy5kZS9vY3NwcjBIBggrBgEF
BQcwAoY8aHR0cDovL3BraTAzMzYudGVsZXNlYy5kZS9jcnQvVGVsZVNlY19HbG9i
YWxSb290X0NsYXNzXzIuY2VyMA0GCSqGSIb3DQEBCwUAA4IBAQCHC/8+AptlyFYt
1juamItxT9q6Kaoh+UYu9bKkD64ROHk4sw50unZdnugYgpZi20wz6N35at8yvSxM
R2BVf+d0a7Qsg9h5a7a3TVALZge17bOXrerufzDmmf0i4nJNPoRb7vnPmep/11I5
LqyYAER+aTu/de7QCzsazeX3DyJsR4T2pUeg/dAaNH2t0j13s+70103/w+jlkk9Z
PpBHEEqwhVjAb3/4ru0IQp4e1N8ULk2PvJ6Uw+ft9hj4PEnnJqinNtgs3iLNi4LY
2XjiVRKjO4dEthEL1QxSr2mMDwbf0KJTi1eYe8/9ByT0/L3D/UqSApcb8re2z2WK
GqK1chk5
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- cacert.crt: CN=DFN-Verein Global Issuing CA,OU=DFN-PKI,O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.,C=DE (Expiring: 2031-02-22)
- cacert.crt: CN=Fraunhofer Service CA - G02,OU=Fraunhofer Corporate PKI,O=Fraunhofer,L=Muenchen,ST=Bayern,C=DE (Expiring: 2031-02-22)
- cacert.crt: CN=MPG CA - G02,O=Max-Planck-Gesellschaft,L=Muenchen,ST=Bayern,C=DE (Expiring: 2031-02-22)
- cacert.crt: CN=TU Dresden CA,O=Technische Universitaet Dresden,L=Dresden,ST=Sachsen,C=DE (Expiring: 2031-02-22)
- cacert.crt: CN=TU Ilmenau CA G2,O=Technische Universitaet Ilmenau,C=DE (Expiring: 2031-02-22)