cloudflare-dns.com


证书 ASN.1 原始内容


-----BEGIN CERTIFICATE-----
MIIGozCCBYugAwIBAgIQAn3IxeFylK7J7T9nco6KCDANBgkqhkiG9w0BAQsFADBZ
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMTMwMQYDVQQDEypE
aWdpQ2VydCBHbG9iYWwgRzIgVExTIFJTQSBTSEEyNTYgMjAyMCBDQTEwHhcNMjUw
MTAyMDAwMDAwWhcNMjYwMTIxMjM1OTU5WjByMQswCQYDVQQGEwJVUzETMBEGA1UE
CBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEZMBcGA1UEChMQ
Q2xvdWRmbGFyZSwgSW5jLjEbMBkGA1UEAxMSY2xvdWRmbGFyZS1kbnMuY29tMFkw
EwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEgIDx3suTAqNAfpWyuepPf8ujMsY8MuNg
AnqCjTcmBwdrQC5OCZsWlzY/o/KV7gKb1KG0tYyULpFGeYzqW4bKhqOCBBcwggQT
MB8GA1UdIwQYMBaAFHSFgMBmx9833s+9KTeqAx2+7c0XMB0GA1UdDgQWBBQrL4SD
o+Zp6VTA5bC2nx/NthivqDCBpgYDVR0RBIGeMIGbghJjbG91ZGZsYXJlLWRucy5j
b22CFCouY2xvdWRmbGFyZS1kbnMuY29tgg9vbmUub25lLm9uZS5vbmWHBAEAAAGH
BAEBAQGHBKKfJAGHBKKfLgGHECYGRwBHAAAAAAAAAAAAEAGHECYGRwBHAAAAAAAA
AAAAERGHECYGRwBHAAAAAAAAAAAAAGSHECYGRwBHAAAAAAAAAAAAZAAwPgYDVR0g
BDcwNTAzBgZngQwBAgIwKTAnBggrBgEFBQcCARYbaHR0cDovL3d3dy5kaWdpY2Vy
dC5jb20vQ1BTMA4GA1UdDwEB/wQEAwIDiDAdBgNVHSUEFjAUBggrBgEFBQcDAQYI
KwYBBQUHAwIwgZ8GA1UdHwSBlzCBlDBIoEagRIZCaHR0cDovL2NybDMuZGlnaWNl
cnQuY29tL0RpZ2lDZXJ0R2xvYmFsRzJUTFNSU0FTSEEyNTYyMDIwQ0ExLTEuY3Js
MEigRqBEhkJodHRwOi8vY3JsNC5kaWdpY2VydC5jb20vRGlnaUNlcnRHbG9iYWxH
MlRMU1JTQVNIQTI1NjIwMjBDQTEtMS5jcmwwgYcGCCsGAQUFBwEBBHsweTAkBggr
BgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQuY29tMFEGCCsGAQUFBzAChkVo
dHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGlnaUNlcnRHbG9iYWxHMlRMU1JT
QVNIQTI1NjIwMjBDQTEtMS5jcnQwDAYDVR0TAQH/BAIwADCCAX0GCisGAQQB1nkC
BAIEggFtBIIBaQFnAHUADleUvPOuqT4zGyyZB7P3kN+bwj1xMiXdIaklrGHFTiEA
AAGUKVlm1gAABAMARjBEAiBDu8Jtj839F3/yqeYqHAuX/QgQqJt8erZr7Dznzik3
bwIgL9ZqNIIgrnluYOTYrwa2iM4S0eDPilETVJtidHeWhlQAdgBkEcRspBLsp4kc
ogIuALyrTygH1B41J6vq/tUDyX3N8AAAAZQpWWaBAAAEAwBHMEUCIQDZZeS1rC2H
TJcC7RSFNd1B+MgTpRuR4GBl3HuakEBylgIgAXN1hDwDEGW76y/CX69p2T+37ynk
5Echmou2KGABSioAdgBJnJtp3h187Pw23s2HZKa4W68Kh4AZ0VVS++nrKd34wwAA
AZQpWWaSAAAEAwBHMEUCIQDhCdnSDU+zRPZX45GbZZEV8RrEpGs2cbTBoMqC2W5s
fgIgdMtZlrh33Tu1P5SIpdz7t4R4hsxPVpIaTLWJqw+QL4MwDQYJKoZIhvcNAQEL
BQADggEBAJw2xIAXRfEnrUY1o6eMgJRd6j/h7sDf4J4a0cYYIyquBDsRUOaX12QQ
WcmoovD/paaOCjsEZOiYx3uu28/n0aPeSx9dc+tTwTsnnk6yw7bQ12d5wm2obnVO
l512YW6Yo3wd+9hZKltR+HTpieALI6vyYFSilPRuWzP8jdDFZPPTY2xMyohGfF5L
1eThceOjvGJ+S1zP+kDNmR9gfCy5e4rS/eazo6jrJ+JBsulEFzWEOMX5633VZGwZ
1z2IXx4dPWvrnsQivoqrWkzxqclruP1H3CKmnDFvUSZvl2s6CIZzE2r0SMjNclQU
Jxhfg2tICXdV4LYjx24laEzZVxoCE+Y=
-----END CERTIFICATE-----

ASN.1 Viewer


使用 certutil 工具


certutil -dump cloudflare-dns.com.crt
X509 Certificate:
Version: 3
Serial Number: 027dc8c5e17294aec9ed3f67728e8a08
Signature Algorithm:
Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
Algorithm Parameters:
05 00
Issuer:
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
O=DigiCert Inc
C=US
Name Hash(sha1): a7c4b8b3dc5bb5581ea7d7f13ac569f56f48d789
Name Hash(md5): f0ab2dd3946de51b1b4465c10611da9a
NotBefore: 1/2/2025 8:00 AM
NotAfter: 1/22/2026 7:59 AM
Subject:
CN=cloudflare-dns.com
O=Cloudflare, Inc.
L=San Francisco
S=California
C=US
Name Hash(sha1): b0a25b5db248d95b419dd444e4782f6d84e50349
Name Hash(md5): 2f8aa899d6cac8bd5bf3e4e69d592c82
Public Key Algorithm:
Algorithm ObjectId: 1.2.840.10045.2.1 ECC
Algorithm Parameters:
06 08 2a 86 48 ce 3d 03 01 07
1.2.840.10045.3.1.7 ECDH_P256
Public Key Length: 256 bits
Public Key: UnusedBits = 0
0000 04 80 80 f1 de cb 93 02 a3 40 7e 95 b2 b9 ea 4f
0010 7f cb a3 32 c6 3c 32 e3 60 02 7a 82 8d 37 26 07
0020 07 6b 40 2e 4e 09 9b 16 97 36 3f a3 f2 95 ee 02
0030 9b d4 a1 b4 b5 8c 94 2e 91 46 79 8c ea 5b 86 ca
0040 86
Certificate Extensions: 10
2.5.29.35: Flags = 0, Length = 18
Authority Key Identifier
KeyID=748580c066c7df37decfbd2937aa031dbeedcd17
2.5.29.14: Flags = 0, Length = 16
Subject Key Identifier
2b2f8483a3e669e954c0e5b0b69f1fcdb618afa8
2.5.29.17: Flags = 0, Length = 9e
Subject Alternative Name
DNS Name=cloudflare-dns.com
DNS Name=*.cloudflare-dns.com
DNS Name=one.one.one.one
IP Address=1.0.0.1
IP Address=1.1.1.1
IP Address=162.159.36.1
IP Address=162.159.46.1
IP Address=2606:4700:4700:0000:0000:0000:0000:1001
IP Address=2606:4700:4700:0000:0000:0000:0000:1111
IP Address=2606:4700:4700:0000:0000:0000:0000:0064
IP Address=2606:4700:4700:0000:0000:0000:0000:6400
2.5.29.32: Flags = 0, Length = 37
Certificate Policies
[1]Certificate Policy:
Policy Identifier=2.23.140.1.2.2
[1,1]Policy Qualifier Info:
Policy Qualifier Id=CPS
Qualifier:
http://www.digicert.com/CPS
2.5.29.15: Flags = 1(Critical), Length = 4
Key Usage
Digital Signature, Key Agreement (88)
2.5.29.37: Flags = 0, Length = 16
Enhanced Key Usage
Server Authentication (1.3.6.1.5.5.7.3.1)
Client Authentication (1.3.6.1.5.5.7.3.2)
2.5.29.31: Flags = 0, Length = 97
CRL Distribution Points
[1]CRL Distribution Point
Distribution Point Name:
Full Name:
URL=http://crl3.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl
[2]CRL Distribution Point
Distribution Point Name:
Full Name:
URL=http://crl4.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl
1.3.6.1.5.5.7.1.1: Flags = 0, Length = 7b
Authority Information Access
[1]Authority Info Access
Access Method=On-line Certificate Status Protocol (1.3.6.1.5.5.7.48.1)
Alternative Name:
URL=http://ocsp.digicert.com
[2]Authority Info Access
Access Method=Certification Authority Issuer (1.3.6.1.5.5.7.48.2)
Alternative Name:
URL=http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt
2.5.29.19: Flags = 1(Critical), Length = 2
Basic Constraints
Subject Type=End Entity
Path Length Constraint=None
1.3.6.1.4.1.11129.2.4.2: Flags = 0, Length = 16d
SCT List
v1
0e5794bcf3aea93e331b2c9907b3f790df9bc23d713225dd21a925ac61c54e21
Friday, January 3, 2025 7:28:32 AM
SHA256
ECDSA
3044022043bbc26d8fcdfd177ff2a9e62a1c0b97fd0810a89b7c7ab66bec3ce7ce29376f02202fd66a348220ae796e60e4d8af06b688ce12d1e0cf8a5113549b627477968654
v1
6411c46ca412eca7891ca2022e00bcab4f2807d41e3527abeafed503c97dcdf0
Friday, January 3, 2025 7:28:32 AM
SHA256
ECDSA
3045022100d965e4b5ac2d874c9702ed148535dd41f8c813a51b91e06065dc7b9a904072960220017375843c031065bbeb2fc25faf69d93fb7ef29e4e447219a8bb62860014a2a
v1
499c9b69de1d7cecfc36decd8764a6b85baf0a878019d15552fbe9eb29ddf8c3
Friday, January 3, 2025 7:28:32 AM
SHA256
ECDSA
3045022100e109d9d20d4fb344f657e3919b659115f11ac4a46b3671b4c1a0ca82d96e6c7e022074cb5996b877dd3bb53f9488a5dcfbb7847886cc4f56921a4cb589ab0f902f83
CT[0]:
Version: 1
Key Id Hash(log-sha256): DleUvPOuqT4zGyyZB7P3kN+bwj1xMiXdIaklrGHFTiE=
Key Id Hash(log-sha256-hex): 0e5794bcf3aea93e331b2c9907b3f790df9bc23d713225dd21a925ac61c54e21
Signing Time: 1/3/2025 7:28 AM
Extensions: 0000
Hash Algorithm: 4 (SHA256)
Signature Algorithm: 3 (ECDSA)
Length: 0046
0000: 30 44 ; SEQUENCE (44 Bytes)
0002: 02 20 ; INTEGER (20 Bytes)
0004: | 43 bb c2 6d 8f cd fd 17 7f f2 a9 e6 2a 1c 0b 97
0014: | fd 08 10 a8 9b 7c 7a b6 6b ec 3c e7 ce 29 37 6f
0024: 02 20 ; INTEGER (20 Bytes)
0026: 2f d6 6a 34 82 20 ae 79 6e 60 e4 d8 af 06 b6 88
0036: ce 12 d1 e0 cf 8a 51 13 54 9b 62 74 77 96 86 54
Not found: DleUvPOuqT4zGyyZB7P3kN+bwj1xMiXdIaklrGHFTiE=
CT[1]:
Version: 1
Key Id Hash(log-sha256): ZBHEbKQS7KeJHKICLgC8q08oB9QeNSer6v7VA8l9zfA=
Key Id Hash(log-sha256-hex): 6411c46ca412eca7891ca2022e00bcab4f2807d41e3527abeafed503c97dcdf0
Signing Time: 1/3/2025 7:28 AM
Extensions: 0000
Hash Algorithm: 4 (SHA256)
Signature Algorithm: 3 (ECDSA)
Length: 0047
0000: 30 45 ; SEQUENCE (45 Bytes)
0002: 02 21 ; INTEGER (21 Bytes)
0004: | 00
0005: | d9 65 e4 b5 ac 2d 87 4c 97 02 ed 14 85 35 dd 41
0015: | f8 c8 13 a5 1b 91 e0 60 65 dc 7b 9a 90 40 72 96
0025: 02 20 ; INTEGER (20 Bytes)
0027: 01 73 75 84 3c 03 10 65 bb eb 2f c2 5f af 69 d9
0037: 3f b7 ef 29 e4 e4 47 21 9a 8b b6 28 60 01 4a 2a
Not found: ZBHEbKQS7KeJHKICLgC8q08oB9QeNSer6v7VA8l9zfA=
CT[2]:
Version: 1
Key Id Hash(log-sha256): SZybad4dfOz8Nt7Nh2SmuFuvCoeAGdFVUvvp6ynd+MM=
Key Id Hash(log-sha256-hex): 499c9b69de1d7cecfc36decd8764a6b85baf0a878019d15552fbe9eb29ddf8c3
Signing Time: 1/3/2025 7:28 AM
Extensions: 0000
Hash Algorithm: 4 (SHA256)
Signature Algorithm: 3 (ECDSA)
Length: 0047
0000: 30 45 ; SEQUENCE (45 Bytes)
0002: 02 21 ; INTEGER (21 Bytes)
0004: | 00
0005: | e1 09 d9 d2 0d 4f b3 44 f6 57 e3 91 9b 65 91 15
0015: | f1 1a c4 a4 6b 36 71 b4 c1 a0 ca 82 d9 6e 6c 7e
0025: 02 20 ; INTEGER (20 Bytes)
0027: 74 cb 59 96 b8 77 dd 3b b5 3f 94 88 a5 dc fb b7
0037: 84 78 86 cc 4f 56 92 1a 4c b5 89 ab 0f 90 2f 83
Not found: SZybad4dfOz8Nt7Nh2SmuFuvCoeAGdFVUvvp6ynd+MM=
Signature Algorithm:
Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
Algorithm Parameters:
05 00
Signature: UnusedBits=0
0000 e6 13 02 1a 57 d9 4c 68 25 6e c7 23 b6 e0 55 77
0010 09 48 6b 83 5f 18 27 14 54 72 cd c8 48 f4 6a 13
0020 73 86 08 3a 6b 97 6f 26 51 6f 31 9c a6 22 dc 47
0030 fd b8 6b c9 a9 f1 4c 5a ab 8a be 22 c4 9e eb 6b
0040 3d 1d 1e 5f 88 3d d7 19 6c 64 d5 7d eb f9 c5 38
0050 84 35 17 44 e9 b2 41 e2 27 eb a8 a3 b3 e6 fd d2
0060 8a 7b b9 2c 7c 60 1f 99 cd 40 fa cf 5c 4b 7e 62
0070 bc a3 e3 71 e1 e4 d5 4b 5e 7c 46 88 ca 4c 6c 63
0080 d3 f3 64 c5 d0 8d fc 33 5b 6e f4 94 a2 54 60 f2
0090 ab 23 0b e0 89 e9 74 f8 51 5b 2a 59 d8 fb 1d 7c
00a0 a3 98 6e 61 76 9d 97 4e 75 6e a8 6d c2 79 67 d7
00b0 d0 b6 c3 b2 4e 9e 27 3b c1 53 eb 73 5d 1f 4b de
00c0 a3 d1 e7 cf db ae 7b c7 98 e8 64 04 3b 0a 8e a6
00d0 a5 ff f0 a2 a8 c9 59 10 64 d7 97 e6 50 11 3b 04
00e0 ae 2a 23 18 c6 d1 1a 9e e0 df c0 ee e1 3f ea 5d
00f0 94 80 8c a7 a3 35 46 ad 27 f1 45 17 80 c4 36 9c
Non-root Certificate
Key Id Hash(rfc-sha1): 2b2f8483a3e669e954c0e5b0b69f1fcdb618afa8
Key Id Hash(sha1): 767bb0163e7120d303303a0815f75aab23ff7b44
Key Id Hash(bcrypt-sha1): 4c113383a2bff683471b048eab5851ecfb299004
Key Id Hash(bcrypt-sha256): 87ce2e9a9e5bba66052beff21ac3a8ba88ab81f82339e5c19ffaaef3e5daddbe
Key Id Hash(md5): 41a44a31d6aae2da58fecf28736f5c05
Key Id Hash(sha256): ddbd240f8b91c700b10e6b814bd640157e0aad257f0764b514aebb2dce6470f5
Key Id Hash(pin-sha256): SPfg6FluPIlUc6a5h313BDCxQYNGX+THTy7ig5X3+VA=
Key Id Hash(pin-sha256-hex): 48f7e0e8596e3c895473a6b9877d770430b14183465fe4c74f2ee28395f7f950
Cert Hash(md5): 956f4b8a30ec423d4bbec9ec60df71df
Cert Hash(sha1): 3ba7e9f806eb30d2f4e3f905e53f07e9acf08e1e
Cert Hash(sha256): 73b8ed5becf1ba6493d2e2215a42dfdc7877e91e311ff5e59fb43d094871e699
Signature Hash: 936a1147bfb4843ef8072e995d3f7487c3d190c65b639a42f063bd27b10af3b5