lets-encrypt-r4-cross-signed.der: CN=R4,O=Let's Encrypt,C=US (Intermediate Certificate, Expiring 2021-09-29) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: https://letsencrypt.org/certs/lets-encrypt-r4-cross-signed.der (in DER format )
- Serial Number : 85078157426516977370628618881327991426
- SHA-1 Fingerprint : f99abe21cdb1823c54c272e2b4904d263e8a8bff
- SHA-1 Fingerprint : f9:9a:be:21:cd:b1:82:3c:54:c2:72:e2:b4:90:4d:26:3e:8a:8b:ff
- SHA-256 Fingerprint : 5a8f16fda448d783481cca57a2428d174dad8c60943ceb28f661ae31fd39a5fa
- SHA-256 Fingerprint : 5a:8f:16:fd:a4:48:d7:83:48:1c:ca:57:a2:42:8d:17:4d:ad:8c:60:94:3c:eb:28:f6:61:ae:31:fd:39:a5:fa
- Signature Hash Algorithm : sha256
- Subject
: CN=R4,O=Let’s Encrypt,C=US
- Country Name: US (United States of America)
- Organization: Let’s Encrypt
- Common Name: R4
- Not Valid Before: 2020-10-07 19:21:45
- Not Valid After: 2021-09-29 19:21:45
- Issuer (Parent Certificate):
- Issuer Name: CN=DST Root CA X3,O=Digital Signature Trust Co.
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: https://letsencrypt.org/documents/isrg-cp-v2.4/
- Certificate Practice Statement (CPS) URL: https://letsencrypt.org/documents/isrg-cps-v2.9/ https://letsencrypt.org/documents/isrg-cps-v2.7/
- Auditor: Schellman & Company, LLC.
- Standard Audit URL: https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?attachmentid=c70581de-e331-4411-8be9-7c182502c042
- Standard Audit Period Start Date: 2019.09.01
- Standard Audit Period End Date: 2020.08.31
- Standard Audit Statement Date: 2020.10.02
- Standard Audit Type: WebTrust
- Full CRL Issued By This CA: Unknown
- Check its issuer’s audit information: CN=DST Root CA X3,O=Digital Signature Trust Co. .
Download certificate through curl
:
curl -sSL "https://letsencrypt.org/certs/lets-encrypt-r4-cross-signed.der" --output cert.crt
Download certificate through wget
:
wget -q "https://letsencrypt.org/certs/lets-encrypt-r4-cross-signed.der" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
40:01:75:04:83:25:3b:e4:64:b7:77:b1:23:d0:8a:82
Signature Algorithm: sha256WithRSAEncryption
Issuer: O=Digital Signature Trust Co., CN=DST Root CA X3
Validity
Not Before: Oct 7 19:21:45 2020 GMT
Not After : Sep 29 19:21:45 2021 GMT
Subject: C=US, O=Let's Encrypt, CN=R4
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:b3:28:dc:77:29:d3:e7:91:be:f3:b7:0a:00:c7:
fb:f2:55:0b:25:22:63:53:36:af:e9:08:20:df:0d:
af:28:3e:cd:c6:ab:57:b6:9d:a4:25:19:a5:d2:32:
6d:49:a6:08:b9:c7:2f:a1:9b:93:c5:20:40:6b:84:
31:20:a2:8e:30:60:25:60:ef:d9:1a:89:3f:1f:69:
71:b2:da:ea:3f:73:41:c4:90:6f:66:fd:7d:9e:58:
d8:77:cf:cd:59:75:44:c9:a1:0a:7b:9f:3f:1b:0e:
3a:66:6f:b6:75:cf:8b:cb:af:9d:c0:70:c5:ff:d2:
82:0a:af:5d:cd:e2:e8:9c:85:94:a4:e6:00:35:e8:
7e:4e:39:81:c7:21:89:60:77:ea:1d:96:f2:8b:83:
7b:47:c4:6d:32:c0:52:7e:23:1e:45:b5:71:ee:a3:
ef:17:c2:03:a9:93:89:dd:f5:9f:db:ba:f1:da:e0:
7e:97:87:71:81:1e:1a:82:56:e4:3e:7c:18:a2:08:
e5:16:5f:a8:fa:a8:e0:48:51:4d:18:14:a0:0c:a3:
e5:b6:ca:b3:b5:55:12:6b:72:c7:5a:7f:3b:8c:f9:
e7:d9:d1:8e:12:4d:33:33:03:2a:f1:13:e1:42:3c:
c2:2e:59:60:2e:6d:e0:07:47:33:65:df:d2:67:ca:
4d:85
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
Authority Information Access:
CA Issuers - URI:http://apps.identrust.com/roots/dstrootcax3.p7c
X509v3 Authority Key Identifier:
keyid:C4:A7:B1:A4:7B:2C:71:FA:DB:E1:4B:90:75:FF:C4:15:60:85:89:10
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 1.3.6.1.4.1.44947.1.1.1
CPS: http://cps.root-x1.letsencrypt.org
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.identrust.com/DSTROOTCAX3CRL.crl
X509v3 Subject Key Identifier:
36:9D:3E:E0:B1:40:F6:27:2C:7C:BF:8D:9D:31:8A:F6:54:A6:46:26
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
Signature Algorithm: sha256WithRSAEncryption
37:80:a9:80:f9:8a:d8:2e:69:ab:f4:5d:57:d8:04:75:67:2f:
3e:73:df:4f:d4:e8:b9:ca:c0:31:37:27:ff:fc:32:58:15:85:
db:01:b8:86:f3:c1:43:1c:6e:a8:f1:02:66:c8:b8:9c:b4:38:
e5:52:69:c8:2d:4d:0d:dd:06:a8:64:08:32:a3:5d:0b:83:78:
4c:b0:ed:77:b6:21:cb:cb:f9:26:c7:c4:31:46:db:eb:15:b8:
b0:a7:9e:78:ac:b7:69:f3:a4:7a:5e:b4:5e:0d:7f:ee:77:52:
9a:9a:62:1e:a7:61:f9:37:49:30:bd:61:a6:d4:60:77:11:a2:
07:c2:cc:a4:7b:96:fe:83:3c:6a:47:f2:b7:84:e4:06:10:3c:
f9:6b:bc:30:ce:9d:94:9c:89:ee:71:c1:56:71:14:15:0e:0d:
8b:e1:b3:34:2f:e9:41:22:f6:f9:8f:4c:ab:81:c7:22:4d:99:
17:2d:16:07:c2:ac:57:07:5e:36:b1:11:3c:bf:8b:8e:18:4b:
75:ed:44:b7:46:8b:f6:79:6f:e0:2a:b0:5c:73:0b:d8:b3:e0:
93:7f:23:fd:69:65:6d:0f:fc:1d:17:76:56:90:7e:25:6e:99:
f0:93:61:72:7b:81:c0:04:c7:30:27:89:54:21:5a:a6:86:6c:
3d:f4:10:e9
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIEZTCCA02gAwIBAgIQQAF1BIMlO+Rkt3exI9CKgjANBgkqhkiG9w0BAQsFADA/
MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
DkRTVCBSb290IENBIFgzMB4XDTIwMTAwNzE5MjE0NVoXDTIxMDkyOTE5MjE0NVow
MjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUxldCdzIEVuY3J5cHQxCzAJBgNVBAMT
AlI0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsyjcdynT55G+87cK
AMf78lULJSJjUzav6Qgg3w2vKD7NxqtXtp2kJRml0jJtSaYIuccvoZuTxSBAa4Qx
IKKOMGAlYO/ZGok/H2lxstrqP3NBxJBvZv19nljYd8/NWXVEyaEKe58/Gw46Zm+2
dc+Ly6+dwHDF/9KCCq9dzeLonIWUpOYANeh+TjmBxyGJYHfqHZbyi4N7R8RtMsBS
fiMeRbVx7qPvF8IDqZOJ3fWf27rx2uB+l4dxgR4aglbkPnwYogjlFl+o+qjgSFFN
GBSgDKPltsqztVUSa3LHWn87jPnn2dGOEk0zMwMq8RPhQjzCLllgLm3gB0czZd/S
Z8pNhQIDAQABo4IBaDCCAWQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8E
BAMCAYYwSwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5p
ZGVudHJ1c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTE
p7Gkeyxx+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEE
AYLfEwEBATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2Vu
Y3J5cHQub3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0
LmNvbS9EU1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFDadPuCxQPYnLHy/jZ0x
ivZUpkYmMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjANBgkqhkiG9w0B
AQsFAAOCAQEAN4CpgPmK2C5pq/RdV9gEdWcvPnPfT9ToucrAMTcn//wyWBWF2wG4
hvPBQxxuqPECZsi4nLQ45VJpyC1NDd0GqGQIMqNdC4N4TLDtd7Yhy8v5JsfEMUbb
6xW4sKeeeKy3afOkel60Xg1/7ndSmppiHqdh+TdJML1hptRgdxGiB8LMpHuW/oM8
akfyt4TkBhA8+Wu8MM6dlJyJ7nHBVnEUFQ4Ni+GzNC/pQSL2+Y9Mq4HHIk2ZFy0W
B8KsVwdeNrERPL+LjhhLde1Et0aL9nlv4CqwXHML2LPgk38j/WllbQ/8HRd2VpB+
JW6Z8JNhcnuBwATHMCeJVCFapoZsPfQQ6Q==
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List
Related Certificates
- lets-encrypt-e1.der: CN=E1,O=Let’s Encrypt,C=US (Expiring: 2025-09-15)
- lets-encrypt-e2.der: CN=E2,O=Let’s Encrypt,C=US (Expiring: 2025-09-15)
- isrg-root-ocsp-x1.der: CN=ISRG Root OCSP X1,O=Internet Security Research Group,C=US (Expiring: 2025-06-10)
- isrg-root-x1-cross-signed.der: CN=ISRG Root X1,O=Internet Security Research Group,C=US (Expiring: 2024-09-30)
- isrgrootx1.der: CN=ISRG Root X1,O=Internet Security Research Group,C=US (Expiring: 2035-06-04)
- isrg-root-x2-cross-signed.der: CN=ISRG Root X2,O=Internet Security Research Group,C=US (Expiring: 2025-09-15)
- isrg-root-x2.der: CN=ISRG Root X2,O=Internet Security Research Group,C=US (Expiring: 2040-09-17)
- lets-encrypt-x1-cross-signed.der: CN=Let’s Encrypt Authority X1,O=Let’s Encrypt,C=US (Expiring: 2020-10-19)
- letsencryptauthorityx1.der: CN=Let’s Encrypt Authority X1,O=Let’s Encrypt,C=US (Expiring: 2020-06-04)
- lets-encrypt-x2-cross-signed.der: CN=Let’s Encrypt Authority X2,O=Let’s Encrypt,C=US (Expiring: 2020-10-19)
- letsencryptauthorityx2.der: CN=Let’s Encrypt Authority X2,O=Let’s Encrypt,C=US (Expiring: 2020-06-04)
- http://cert.int-x3.letsencrypt.org/: CN=Let’s Encrypt Authority X3,O=Let’s Encrypt,C=US (Expiring: 2021-03-17)
- lets-encrypt-x3-cross-signed.der: CN=Let’s Encrypt Authority X3,O=Let’s Encrypt,C=US (Expiring: 2021-03-17)
- letsencryptauthorityx3.der: CN=Let’s Encrypt Authority X3,O=Let’s Encrypt,C=US (Expiring: 2021-10-06)
- lets-encrypt-x4-cross-signed.der: CN=Let’s Encrypt Authority X4,O=Let’s Encrypt,C=US (Expiring: 2021-03-17)
- letsencryptauthorityx4.der: CN=Let’s Encrypt Authority X4,O=Let’s Encrypt,C=US (Expiring: 2021-10-06)
- lets-encrypt-r3-cross-signed.der: CN=R3,O=Let’s Encrypt,C=US (Expiring: 2021-09-29)
- lets-encrypt-r3.der: CN=R3,O=Let’s Encrypt,C=US (Expiring: 2025-09-15)
- lets-encrypt-r4.der: CN=R4,O=Let’s Encrypt,C=US (Expiring: 2025-09-15)