Microsoft Azure TLS Issuing CA 02 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 02,O=Microsoft Corporation,C=US (Intermediate Certificate, Expiring 2024-06-27) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2002%20-%20xsign.crt (in DER format )
- Serial Number : 16505855106165622982523337491647640084
- SHA-1 Fingerprint : e7eea674ca718e3befd90858e09f8372ad0ae2aa
- SHA-1 Fingerprint : e7:ee:a6:74:ca:71:8e:3b:ef:d9:08:58:e0:9f:83:72:ad:0a:e2:aa
- SHA-256 Fingerprint : 15a98761ebe011554da3a46d206b0812cb2eb69ae87aaa11a6dd4cb84ed5142a
- SHA-256 Fingerprint : 15:a9:87:61:eb:e0:11:55:4d:a3:a4:6d:20:6b:08:12:cb:2e:b6:9a:e8:7a:aa:11:a6:dd:4c:b8:4e:d5:14:2a
- Signature Hash Algorithm : sha384
- Subject
: CN=Microsoft Azure TLS Issuing CA 02,O=Microsoft Corporation,C=US
- Country Name: US (United States of America)
- Organization: Microsoft Corporation
- Common Name: Microsoft Azure TLS Issuing CA 02
- Not Valid Before: 2020-07-29 12:30:00
- Not Valid After: 2024-06-27 23:59:59
- Issuer (Parent Certificate):
- Issuer Name: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://www.microsoft.com/pkiops/Docs/Content/policy/Microsoft_PKI_Services_CP_v3.1.6.pdf
- Certificate Practice Statement (CPS) URL: https://www.microsoft.com/pkiops/Docs/Content/policy/Microsoft_PKI_Services_CPS_v3.2.2.pdf
- Auditor: BDO International Limited
- Standard Audit URL: https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?attachmentid=fc6f34ea-9248-4ffe-a94b-9e870afae5b7
- Standard Audit Period Start Date: 2021.05.01
- Standard Audit Period End Date: 2022.04.30
- Standard Audit Statement Date: 2022.06.17
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: http://www.microsoft.com/pkiops/crl/Microsoft%20Azure%20TLS%20Issuing%20CA%2002.crl
- Check its issuer’s audit information: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US .
Download certificate through curl
:
curl -sSL "http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2002%20-%20xsign.crt" --output cert.crt
Download certificate through wget
:
wget -q "http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%20Issuing%20CA%2002%20-%20xsign.crt" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
0c:6a:e9:7c:ce:d5:99:83:86:90:a0:0a:9e:a5:32:14
Signature Algorithm: sha384WithRSAEncryption
Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
Validity
Not Before: Jul 29 12:30:00 2020 GMT
Not After : Jun 27 23:59:59 2024 GMT
Subject: C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 02
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:e0:62:3b:52:ba:16:4e:1f:1c:8e:ad:de:62:64:
a6:0e:e5:c6:87:94:80:bf:2d:cf:dc:2e:23:6c:f4:
52:06:3c:bc:5a:da:dd:50:68:ed:0c:e7:0b:82:b7:
b3:d8:ea:29:61:32:21:06:35:d4:b7:b4:d7:4f:1b:
49:86:bf:4c:ad:1a:8a:83:ba:8a:da:46:8a:28:04:
1b:eb:c7:fe:2a:ad:41:73:d2:bb:a0:fc:d3:8a:e2:
d0:d1:59:d5:23:8f:f4:8c:e3:62:e4:22:2b:a0:16:
9e:d0:aa:3f:85:80:71:90:0f:b6:93:6b:34:b3:c1:
23:28:aa:9a:24:c3:4b:87:65:16:0d:5d:b2:43:2e:
56:94:f8:cf:43:29:80:43:26:c5:09:eb:49:9e:b5:
e6:b0:50:db:9b:e7:55:b0:4d:8a:0d:38:14:2b:21:
d5:5d:d2:f2:f7:b9:1b:38:74:f2:82:2b:2f:f8:39:
c6:af:79:a1:1a:e0:11:e3:81:21:e8:9e:81:0a:68:
2a:b2:d8:ca:8d:d1:d5:3b:78:f0:79:92:24:20:58:
43:9d:90:73:7e:11:83:14:1d:66:c2:d7:31:4a:d6:
b8:bd:49:2c:06:4f:eb:27:a8:e3:bc:92:4b:12:82:
8e:1a:b9:fc:05:16:bd:00:4f:dc:df:dc:3f:f8:89:
cc:a2:8a:c3:6d:ea:27:f9:24:56:b1:34:0d:25:43:
88:88:97:58:5d:1c:f5:a6:d2:1a:16:25:f5:23:e5:
f3:a2:07:70:80:08:cf:07:a5:27:84:8a:a4:7a:d5:
6e:1d:3f:c3:86:07:74:58:b9:41:b7:40:a7:b3:b9:
2b:17:f1:05:88:50:39:e1:f2:8a:cd:35:ce:4a:58:
9f:a4:aa:50:51:af:6c:af:1e:67:cc:bd:01:c9:6d:
f0:f2:14:7e:d3:06:ea:ae:41:85:d9:41:66:40:c3:
57:79:fb:d1:19:57:c1:8b:e5:97:37:d9:fe:75:7d:
e2:5f:a1:62:9f:86:2d:6e:e3:4a:6a:71:64:b1:bf:
5c:4c:f8:39:7b:53:b5:6c:0b:57:e2:24:20:e7:bf:
10:31:7b:f4:a0:9a:cd:6d:92:5c:e2:2f:54:89:cf:
a2:2d:4f:a8:de:13:b9:d3:6f:d0:6c:81:17:9b:51:
0b:f6:81:8d:4a:a9:97:2d:58:61:f7:8a:c2:04:55:
b3:cd:f3:e6:4b:a2:3a:27:26:74:66:4a:1f:d4:aa:
53:96:e7:2a:c7:bb:22:5c:9f:64:b8:3a:c8:0c:58:
c9:33:5e:ec:0f:5a:70:9d:ff:a4:69:82:22:42:7f:
f5:d7:cb:50:57:38:85:86:f7:63:22:08:60:69:aa:
9b:6f:f7
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
00:AB:91:FC:21:62:26:97:9A:A8:79:1B:61:41:90:60:A9:62:67:FD
X509v3 Authority Key Identifier:
keyid:4E:22:54:20:18:95:E6:E3:6E:E6:0F:FA:FA:B9:12:ED:06:17:8F:39
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
Authority Information Access:
OCSP - URI:http://ocsp.digicert.com
CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalRootG2.crt
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl3.digicert.com/DigiCertGlobalRootG2.crl
Full Name:
URI:http://crl4.digicert.com/DigiCertGlobalRootG2.crl
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 2.23.140.1.2.2
1.3.6.1.4.1.311.21.1:
...
Signature Algorithm: sha384WithRSAEncryption
33:a3:f2:9d:99:63:cf:4d:a6:0b:41:6e:c9:e4:3a:b1:12:20:
53:f5:0c:98:19:47:de:65:de:d3:47:5f:37:ec:7e:83:4a:41:
5a:fe:61:8c:d6:42:f0:8b:9c:bd:9a:26:4a:03:d9:3a:4f:d3:
b0:4f:1f:02:7e:57:2f:6c:d3:b6:52:41:56:d1:50:a5:74:41:
87:8b:2c:79:e3:6d:7e:1e:94:71:31:02:11:8e:58:a0:78:fb:
4e:b5:11:97:c1:a3:4e:43:bc:92:59:f2:61:46:12:9c:3c:a7:
b6:3c:61:47:40:8e:ff:de:7f:93:de:45:d0:fd:22:ee:da:59:
3d:42:ce:58:81:22:77:56:1c:41:53:39:d8:9f:52:95:28:95:
8f:13:4e:cc:e7:99:2e:52:00:aa:b8:05:74:3e:4b:19:8f:b1:
02:e2:72:ba:7b:f5:15:6c:fb:a6:96:3d:67:ca:39:71:86:f3:
6e:77:85:98:9a:be:27:b5:b0:5e:bf:a7:12:6c:ae:fc:76:92:
3f:dd:ca:fb:3f:f5:89:3d:82:6e:2f:41:2c:3b:73:20:8d:2d:
de:0c:25:fb:35:7a:79:ca:5b:9e:dd:37:29:41:f4:54:f0:12:
fe:c9:90:b5:c2:a5:fd:f1:1e:27:77:0e:d7:e2:a7:c6:68:4e:
d2:94:5e:c8
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIF8zCCBNugAwIBAgIQDGrpfM7VmYOGkKAKnqUyFDANBgkqhkiG9w0BAQwFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH
MjAeFw0yMDA3MjkxMjMwMDBaFw0yNDA2MjcyMzU5NTlaMFkxCzAJBgNVBAYTAlVT
MR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKjAoBgNVBAMTIU1pY3Jv
c29mdCBBenVyZSBUTFMgSXNzdWluZyBDQSAwMjCCAiIwDQYJKoZIhvcNAQEBBQAD
ggIPADCCAgoCggIBAOBiO1K6Fk4fHI6t3mJkpg7lxoeUgL8tz9wuI2z0UgY8vFra
3VBo7QznC4K3s9jqKWEyIQY11Le0108bSYa/TK0aioO6itpGiigEG+vH/iqtQXPS
u6D804ri0NFZ1SOP9IzjYuQiK6AWntCqP4WAcZAPtpNrNLPBIyiqmiTDS4dlFg1d
skMuVpT4z0MpgEMmxQnrSZ615rBQ25vnVbBNig04FCsh1V3S8ve5Gzh08oIrL/g5
xq95oRrgEeOBIeiegQpoKrLYyo3R1Tt48HmSJCBYQ52Qc34RgxQdZsLXMUrWuL1J
LAZP6yeo47ySSxKCjhq5/AUWvQBP3N/cP/iJzKKKw23qJ/kkVrE0DSVDiIiXWF0c
9abSGhYl9SPl86IHcIAIzwelJ4SKpHrVbh0/w4YHdFi5QbdAp7O5KxfxBYhQOeHy
is01zkpYn6SqUFGvbK8eZ8y9Aclt8PIUftMG6q5BhdlBZkDDV3n70RlXwYvllzfZ
/nV94l+hYp+GLW7jSmpxZLG/XEz4OXtTtWwLV+IkIOe/EDF79KCazW2SXOIvVInP
oi1PqN4TudNv0GyBF5tRC/aBjUqply1YYfeKwgRVs83z5kuiOicmdGZKH9SqU5bn
Kse7IlyfZLg6yAxYyTNe7A9acJ3/pGmCIkJ/9dfLUFc4hYb3YyIIYGmqm2/3AgMB
AAGjggGtMIIBqTAdBgNVHQ4EFgQUAKuR/CFiJpeaqHkbYUGQYKliZ/0wHwYDVR0j
BBgwFoAUTiJUIBiV5uNu5g/6+rkS7QYXjzkwDgYDVR0PAQH/BAQDAgGGMB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH/AgEAMHYG
CCsGAQUFBwEBBGowaDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQu
Y29tMEAGCCsGAQUFBzAChjRodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGln
aUNlcnRHbG9iYWxSb290RzIuY3J0MHsGA1UdHwR0MHIwN6A1oDOGMWh0dHA6Ly9j
cmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5jcmwwN6A1oDOG
MWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RHMi5j
cmwwHQYDVR0gBBYwFDAIBgZngQwBAgEwCAYGZ4EMAQICMBAGCSsGAQQBgjcVAQQD
AgEAMA0GCSqGSIb3DQEBDAUAA4IBAQAzo/KdmWPPTaYLQW7J5DqxEiBT9QyYGUfe
Zd7TR1837H6DSkFa/mGM1kLwi5y9miZKA9k6T9OwTx8CflcvbNO2UkFW0VCldEGH
iyx5421+HpRxMQIRjligePtOtRGXwaNOQ7ySWfJhRhKcPKe2PGFHQI7/3n+T3kXQ
/SLu2lk9Qs5YgSJ3VhxBUznYn1KVKJWPE07M55kuUgCquAV0PksZj7EC4nK6e/UV
bPumlj1nyjlxhvNud4WYmr4ntbBev6cSbK78dpI/3cr7P/WJPYJuL0EsO3MgjS3e
DCX7NXp5ylue3TcpQfRU8BL+yZC1wqX98R4ndw7X4qfGaE7SlF7I
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- Microsoft Azure TLS Issuing CA 01 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 01,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft Azure TLS Issuing CA 05 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 05,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft Azure TLS Issuing CA 06 - xsign.crt: CN=Microsoft Azure TLS Issuing CA 06,O=Microsoft Corporation,C=US (Expiring: 2024-06-27)
- Microsoft ECC Product Root Certificate Authority 2018.crt: CN=Microsoft ECC Product Root Certificate Authority 2018,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2043-02-27)
- Microsoft ECC Root Certificate Authority 2017.crt: CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft ECC Root Certificate Authority 2017.crt: CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft ECC TS Root Certificate Authority 2018.crt: CN=Microsoft ECC TS Root Certificate Authority 2018,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2043-02-27)
- Microsoft EV ECC Root Certificate Authority 2017.crt: CN=Microsoft EV ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft EV ECC Root Certificate Authority 2017.crt: CN=Microsoft EV ECC Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft EV RSA Root Certificate Authority 2017.crt: CN=Microsoft EV RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft EV RSA Root Certificate Authority 2017.crt: CN=Microsoft EV RSA Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- microsoft identity verification root certificate authority 2020.crt: CN=Microsoft Identity Verification Root Certificate Authority 2020,O=Microsoft Corporation,C=US (Expiring: 2045-04-16)
- Microsoft Public RSA Timestamping CA 2020.crt: CN=Microsoft Public RSA Timestamping CA 2020,O=Microsoft Corporation,C=US (Expiring: 2035-11-19)
- Microsoft RSA Root Certificate Authority 2017.crt: CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US (Expiring: 2042-07-18)
- Microsoft RSA Root Certificate Authority 2017.crt: CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2042-07-26)
- Microsoft RSA TLS CA 01.crt: CN=Microsoft RSA TLS CA 01,O=Microsoft Corporation,C=US (Expiring: 2024-10-08)
- Microsoft RSA TLS CA 02.crt: CN=Microsoft RSA TLS CA 02,O=Microsoft Corporation,C=US (Expiring: 2024-10-08)
- MicRooCerAut_2010-06-23.crt: CN=Microsoft Root Certificate Authority 2010,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2035-06-23)
- MicRooCerAut2011_2011_03_22.crt: CN=Microsoft Root Certificate Authority 2011,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2036-03-22)
- Microsoft Time Stamp Root Certificate Authority 2014.crt: CN=Microsoft Time Stamp Root Certificate Authority 2014,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Expiring: 2039-10-22)