root4096.crt: CN=TWCA Global Root CA,OU=Root CA,O=TAIWAN-CA,C=TW (Intermediate Certificate, Expiring 2030-10-28) detail info and audit record
Page content
CA Certificate Information and Audit Record
This certificate is intermediate certificate used for the issuance of other certificates.
- Certificate Download URL: http://sslserver.twca.com.tw/cacert/root4096.crt (in DER format )
- Serial Number : 85076825076483007851870499652419525481
- SHA-1 Fingerprint : fd54e4643b49705a2aaae50653c4f56c2df8083d
- SHA-1 Fingerprint : fd:54:e4:64:3b:49:70:5a:2a:aa:e5:06:53:c4:f5:6c:2d:f8:08:3d
- SHA-256 Fingerprint : 8ad47f6d70a44fa80af0f931125ffe3a76876ffad219a4d40a13c038dc85e69e
- SHA-256 Fingerprint : 8a:d4:7f:6d:70:a4:4f:a8:0a:f0:f9:31:12:5f:fe:3a:76:87:6f:fa:d2:19:a4:d4:0a:13:c0:38:dc:85:e6:9e
- Signature Hash Algorithm : sha256
- Subject
: CN=TWCA Global Root CA,OU=Root CA,O=TAIWAN-CA,C=TW
- Country Name: TW (Taiwan (Province of China))
- Organization: TAIWAN-CA
- Organization Unit: Root CA
- Common Name: TWCA Global Root CA
- Not Valid Before: 2014-10-28 07:38:31
- Not Valid After: 2030-10-28 15:59:59
- Issuer (Parent Certificate):
- Issuer Name: CN=TWCA Root Certification Authority,OU=Root CA,O=TAIWAN-CA,C=TW
- Issuer Certificate URL: NA
- Audit Record:
- Revocation Status: Not Revoked
- Certificate Policy (CP) URL: Unknown
- Certificate Practice Statement (CPS) URL: Unknown
- Auditor: KPMG
- Standard Audit URL: Unknown
- Standard Audit Period Start Date: Unknown
- Standard Audit Period End Date: Unknown
- Standard Audit Statement Date: Unknown
- Standard Audit Type: Unknown
- Full CRL Issued By This CA: http://RootCA.twca.com.tw/TWCARCA/global_revoke_4096.crl
- Check its issuer’s audit information: CN=TWCA Root Certification Authority,OU=Root CA,O=TAIWAN-CA,C=TW .
Download certificate through curl
:
curl -sSL "http://sslserver.twca.com.tw/cacert/root4096.crt" --output cert.crt
Download certificate through wget
:
wget -q "http://sslserver.twca.com.tw/cacert/root4096.crt" --output-document=cert.crt
CA Certificate Detail Information
Use openssl x509
to decode DER certificate to get detail information:
openssl x509 -in cert.crt -inform der -text -noout
Use openssl x509
to decode PEM certificate to get detail information:
openssl x509 -in cert.crt -inform pem -text -noout
Decoded detail certificate information:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
40:01:33:53:e4:00:00:00:00:00:00:0c:ca:5d:1b:69
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
Validity
Not Before: Oct 28 07:38:31 2014 GMT
Not After : Oct 28 15:59:59 2030 GMT
Subject: C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Global Root CA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (4096 bit)
Modulus:
00:b0:05:db:c8:eb:8c:c4:6e:8a:21:ef:8e:4d:9c:
71:0a:1f:52:70:ed:6d:82:9c:97:c5:d7:4c:4e:45:
49:cb:40:42:b5:12:34:6c:19:c2:74:a4:31:5f:85:
02:97:ec:43:33:0a:53:d2:9c:8c:8e:b7:b8:79:db:
2b:d5:6a:f2:8e:66:c4:ee:2b:01:07:92:d4:b3:d0:
02:df:50:f6:55:af:66:0e:cb:e0:47:60:2f:2b:32:
39:35:52:3a:28:83:f8:7b:16:c6:18:b8:62:d6:47:
25:91:ce:f0:19:12:4d:ad:63:f5:d3:3f:75:5f:29:
f0:a1:30:1c:2a:a0:98:a6:15:bd:ee:fd:19:36:f0:
e2:91:43:8f:fa:ca:d6:10:27:49:4c:ef:dd:c1:f1:
85:70:9b:ca:ea:a8:5a:43:fc:6d:86:6f:73:e9:37:
45:a9:f0:36:c7:cc:88:75:1e:bb:6c:06:ff:9b:6b:
3e:17:ec:61:aa:71:7c:c6:1d:a2:f7:49:e9:15:b5:
3c:d6:a1:61:f5:11:f7:05:6f:1d:fd:11:be:d0:30:
07:c2:29:b0:09:4e:26:dc:e3:a2:a8:91:6a:1f:c2:
91:45:88:5c:e5:98:b8:71:a5:15:19:c9:7c:75:11:
cc:70:74:4f:2d:9b:1d:91:44:fd:56:28:a0:fe:bb:
86:6a:c8:fa:5c:0b:58:dc:c6:4b:76:c8:ab:22:d9:
73:0f:a5:f4:5a:02:89:3f:4f:9e:22:82:ee:a2:74:
53:2a:3d:53:27:69:1d:6c:8e:32:2c:64:00:26:63:
61:36:4e:a3:46:b7:3f:7d:b3:2d:ac:6d:90:a2:95:
a2:ce:cf:da:82:e7:07:34:19:96:e9:b8:21:aa:29:
7e:a6:38:be:8e:29:4a:21:66:79:1f:b3:c3:b5:09:
67:de:d6:d4:07:46:f3:2a:da:e6:22:37:60:cb:81:
b6:0f:a0:0f:e9:c8:95:7f:bf:55:91:05:7a:cf:3d:
15:c0:6f:de:09:94:01:83:d7:34:1b:cc:40:a5:f0:
b8:9b:67:d5:98:91:3b:a7:84:78:95:26:a4:5a:08:
f8:2b:74:b4:00:04:3c:df:b8:14:8e:e8:df:a9:8d:
6c:67:92:33:1d:c0:b7:d2:ec:92:c8:be:09:bf:2c:
29:05:6f:02:6b:9e:ef:bc:bf:2a:bc:5b:c0:50:8f:
41:70:71:87:b2:4d:b7:04:a9:84:a3:32:af:ae:ee:
6b:17:8b:b2:b1:fe:6c:e1:90:8c:88:a8:97:48:ce:
c8:4d:cb:f3:06:cf:5f:6a:0a:42:b1:1e:1e:77:2f:
8e:a0:e6:92:0e:06:fc:05:22:d2:26:e1:31:51:7d:
32:dc:0f
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
keyid:6A:38:5B:26:8D:DE:8B:5A:F2:4F:7A:54:83:19:18:E3:08:35:A6:BA
X509v3 Subject Key Identifier:
48:DB:CD:DE:8E:E9:49:72:5A:88:E8:B1:D8:3D:07:B3:B9:6B:66:50
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Certificate Policies:
Policy: X509v3 Any Policy
CPS: http://www.twca.com.tw/
X509v3 CRL Distribution Points:
Full Name:
URI:http://RootCA.twca.com.tw/TWCARCA/revoke_2048.crl
X509v3 Basic Constraints: critical
CA:TRUE
Authority Information Access:
OCSP - URI:http://rootocsp.twca.com.tw/
Signature Algorithm: sha256WithRSAEncryption
29:0b:6e:c4:94:dc:62:59:93:7a:5a:4c:5d:dc:99:3e:8e:a8:
fb:f9:a0:8f:1b:d9:27:70:6d:f8:2e:5e:48:69:61:17:40:10:
89:aa:03:b8:1c:cb:df:bc:6c:28:54:1f:c5:21:f5:4b:96:bf:
fc:4c:47:ca:0b:77:c3:cc:66:7b:6f:b9:36:08:69:f9:c1:91:
ed:8f:d6:9e:a2:22:e8:82:b7:89:c8:aa:d0:20:e7:4a:ac:23:
2b:2f:4f:f6:4f:14:6b:f1:7a:45:a1:87:c8:71:e7:a7:a4:b9:
80:6b:c9:ce:cd:8a:25:9c:cd:d3:09:a5:32:fa:24:d1:51:7f:
3c:31:99:47:ea:1f:a7:6f:6e:84:cd:ae:d8:ae:35:6a:d6:cb:
e0:be:13:c1:a2:31:cb:ee:1f:e9:26:df:b7:06:c6:0d:45:0a:
e7:ab:45:57:1e:b7:01:9b:31:f5:f2:05:40:45:86:d8:02:1b:
d0:4b:21:db:20:82:e3:22:e9:4f:e3:5d:2b:c4:39:12:17:28:
c6:b9:67:b1:7d:e1:b2:7c:76:e5:36:84:da:74:5e:ac:38:b6:
6b:f8:ee:a1:03:c4:b0:c4:5c:12:4c:6f:06:da:3a:44:65:b6:
36:97:0c:18:79:d0:46:97:33:1f:ab:52:a8:ce:de:57:b4:28:
13:38:b7:ac
CA Certificate in PEM Format
Use openssl x509
to convert certificate from DER
format to PEM
format:
openssl x509 -in cert.crt -inform der
Converted PEM
format certificate:
-----BEGIN CERTIFICATE-----
MIIFWTCCBEGgAwIBAgIQQAEzU+QAAAAAAAAMyl0baTANBgkqhkiG9w0BAQsFADBf
MQswCQYDVQQGEwJUVzESMBAGA1UECgwJVEFJV0FOLUNBMRAwDgYDVQQLDAdSb290
IENBMSowKAYDVQQDDCFUV0NBIFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkw
HhcNMTQxMDI4MDczODMxWhcNMzAxMDI4MTU1OTU5WjBRMQswCQYDVQQGEwJUVzES
MBAGA1UEChMJVEFJV0FOLUNBMRAwDgYDVQQLEwdSb290IENBMRwwGgYDVQQDExNU
V0NBIEdsb2JhbCBSb290IENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKC
AgEAsAXbyOuMxG6KIe+OTZxxCh9ScO1tgpyXxddMTkVJy0BCtRI0bBnCdKQxX4UC
l+xDMwpT0pyMjre4edsr1WryjmbE7isBB5LUs9AC31D2Va9mDsvgR2AvKzI5NVI6
KIP4exbGGLhi1kclkc7wGRJNrWP10z91XynwoTAcKqCYphW97v0ZNvDikUOP+srW
ECdJTO/dwfGFcJvK6qhaQ/xthm9z6TdFqfA2x8yIdR67bAb/m2s+F+xhqnF8xh2i
90npFbU81qFh9RH3BW8d/RG+0DAHwimwCU4m3OOiqJFqH8KRRYhc5Zi4caUVGcl8
dRHMcHRPLZsdkUT9Viig/ruGasj6XAtY3MZLdsirItlzD6X0WgKJP0+eIoLuonRT
Kj1TJ2kdbI4yLGQAJmNhNk6jRrc/fbMtrG2QopWizs/agucHNBmW6bghqil+pji+
jilKIWZ5H7PDtQln3tbUB0bzKtrmIjdgy4G2D6AP6ciVf79VkQV6zz0VwG/eCZQB
g9c0G8xApfC4m2fVmJE7p4R4lSakWgj4K3S0AAQ837gUjujfqY1sZ5IzHcC30uyS
yL4JvywpBW8Ca57vvL8qvFvAUI9BcHGHsk23BKmEozKvru5rF4uysf5s4ZCMiKiX
SM7ITcvzBs9fagpCsR4edy+OoOaSDgb8BSLSJuExUX0y3A8CAwEAAaOCAR0wggEZ
MB8GA1UdIwQYMBaAFGo4WyaN3ota8k96VIMZGOMINaa6MB0GA1UdDgQWBBRI283e
julJclqI6LHYPQezuWtmUDAOBgNVHQ8BAf8EBAMCAQYwOAYDVR0gBDEwLzAtBgRV
HSAAMCUwIwYIKwYBBQUHAgEWF2h0dHA6Ly93d3cudHdjYS5jb20udHcvMEIGA1Ud
HwQ7MDkwN6A1oDOGMWh0dHA6Ly9Sb290Q0EudHdjYS5jb20udHcvVFdDQVJDQS9y
ZXZva2VfMjA0OC5jcmwwDwYDVR0TAQH/BAUwAwEB/zA4BggrBgEFBQcBAQQsMCow
KAYIKwYBBQUHMAGGHGh0dHA6Ly9yb290b2NzcC50d2NhLmNvbS50dy8wDQYJKoZI
hvcNAQELBQADggEBACkLbsSU3GJZk3paTF3cmT6OqPv5oI8b2SdwbfguXkhpYRdA
EImqA7gcy9+8bChUH8Uh9UuWv/xMR8oLd8PMZntvuTYIafnBke2P1p6iIuiCt4nI
qtAg50qsIysvT/ZPFGvxekWhh8hx56ekuYBryc7NiiWczdMJpTL6JNFRfzwxmUfq
H6dvboTNrtiuNWrWy+C+E8GiMcvuH+km37cGxg1FCuerRVcetwGbMfXyBUBFhtgC
G9BLIdsgguMi6U/jXSvEORIXKMa5Z7F94bJ8duU2hNp0Xqw4tmv47qEDxLDEXBJM
bwbaOkRltjaXDBh50EaXMx+rUqjO3le0KBM4t6w=
-----END CERTIFICATE-----
Also see Top 1 Millions Domains CA Certificate List