SlideShare a Scribd company logo
1 of 2
InCommon SSL Chain 
Comodo AddTrust External CA: InCommon Intermediate Server CA: 
Subscriber SSL Certificates 
InCommon Server CA 
Version: V3 cert required 
Serial Number: unique integer (relative to issuer) 
Signature Algorithm: sha1WithRSAEncryption 
Validity: 10 years (min 8 years = 3 years of program + 5 years to issue 
user certs on last day) 
Issuer: C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, 
CN=AddTrust External CA Root 
Subject: C=US, O=Internet2, OU=InCommon, CN=InCommon Server CA 
Public Key: 2048-bit 
basicConstraints (critical): ca:true pathLenConstraint:0 
keyUsage: (critical) keyCertSign (2.5.29.15.5), cRLSign (2.5.29.15.6) 
cRLDistributionPoints (non-critical): 
URI:http://crl.usertrust.com/AddTrustExternalCARoot.crl 
certificatePolicies (non-critical): 
policyID: anyPolicy (2.5.29.32.0) 
authorityInfoAccess (non-critical): 
CA Issuer – URI: 
http://crt.usertrust.com/AddTrustExternalCARoot.p7c 
OCSP - URI: http://ocsp.usertrust.com 
authorityKeyIdentifier (non-critical): keyID: 
keyid:AD:BD:98:7A:34:B4:26:F7:FA:C4:26:54:EF:03:BD:E0:24:CB:54:1A 
subjectKeyIdentifier (non-critical): keyID: 
CE:A6:57:E6:EE:BF:47:3D:12:76:4E:02:88:92:6F:43:BA:DD:C0:F2 
InCommon SSL/TLS Certificates 
Version: V3 certs required 
Serial Number: unique integer (relative to issuer) 
Signature Algorithm: sha1WithRSAEncryption / optional: 
sha256WithRSAEncryption (to follow) 
Validity: 1 / 2 / 3 years 
Issuer: C=US, O=Internet2, OU=InCommon, CN=InCommon Server CA 
Subject: 
C required 
ST optional 
L optional 
O required (campus defined, InCommon approved) 
OU optional 
CN required (dNSName, wildcard is supported, private/local names 
are supported) 
Public Key: 2048-bit min 
basicConstraints (critical): ca:false (no pathLenConstraint) 
keyUsage: (critical) digitalSignature (2.5.29.15.0), keyEncipherment 
(2.5.29.15.2) 
extendedKeyUsage (non-critical): id-kp-serverAuth (1.3.6.1.5.5.7.3.1), 
id-kp-clientAuth (1.3.6.1.5.5.7.3.2) 
subjectAltName (non-critical): required, dNSName (min 1, max 100 names) 
or private/local names / optional rfc822Name (email for admin – must be 
validated if included) 
cRLDistributionPoints (non-critical): 
URI:http://crl.incommon.org/InCommonServerCA.crl 
certificatePolicies (non-critical): 
policyID: id-pki-InCommon-SSL (1.3.6.1.4.1.5923.1.4.3.1.1) 
cpsURI: https://www.incommon.org/cert/repository/cps_ssl.pdf 
authorityInfoAccess (non-critical): 
CA Issuer – URI: http://cert.incommon.org/InCommonServerCA.crt
OCSP - URI: http://ocsp.incommon.org 
authorityKeyIdentifier (non-critical): keyID: 
CE:A6:57:E6:EE:BF:47:3D:12:76:4E:02:88:92:6F:43:BA:DD:C0:F2 
subjectKeyIdentifier (non-critical): keyID:...

More Related Content

Similar to Cert profile ssl

A 5 security x line platform
A 5 security x line platformA 5 security x line platform
A 5 security x line platformLINE Corporation
 
#MoreCrypto : Introduction to TLS
#MoreCrypto : Introduction to TLS#MoreCrypto : Introduction to TLS
#MoreCrypto : Introduction to TLSOlle E Johansson
 
Enteprise Sync IT Data Sheets
Enteprise Sync IT Data SheetsEnteprise Sync IT Data Sheets
Enteprise Sync IT Data SheetsMarcus Grimaldo
 
03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...
03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...
03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...ghorilemin
 
this is ppt this is ppt this is ppt this is ppt
this is ppt this is ppt this is ppt this is pptthis is ppt this is ppt this is ppt this is ppt
this is ppt this is ppt this is ppt this is pptghorilemin
 
Best Practices for IoT Security in the Cloud
Best Practices for IoT Security in the CloudBest Practices for IoT Security in the Cloud
Best Practices for IoT Security in the CloudAmazon Web Services
 
HashiTLS Demystifying Security Certs
HashiTLS Demystifying Security CertsHashiTLS Demystifying Security Certs
HashiTLS Demystifying Security CertsMitchell Pronschinske
 
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...CODE BLUE
 
Detecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DC
Detecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DCDetecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DC
Detecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DCKhaled Al-Hassanieh
 
Steam Learn: HTTPS and certificates explained
Steam Learn: HTTPS and certificates explainedSteam Learn: HTTPS and certificates explained
Steam Learn: HTTPS and certificates explainedinovia
 
Cisco Connect Ottawa 2018 secure on prem
Cisco Connect Ottawa 2018 secure on premCisco Connect Ottawa 2018 secure on prem
Cisco Connect Ottawa 2018 secure on premCisco Canada
 
Cisco iso based CA (certificate authority)
Cisco iso based CA (certificate authority)Cisco iso based CA (certificate authority)
Cisco iso based CA (certificate authority)Netwax Lab
 
IMS Authentication with AKAv1 and AKAv2
IMS Authentication with AKAv1 and AKAv2 IMS Authentication with AKAv1 and AKAv2
IMS Authentication with AKAv1 and AKAv2 mohammad norozzudegan
 
Kerberos survival guide SPS Kansas City
Kerberos survival guide SPS Kansas CityKerberos survival guide SPS Kansas City
Kerberos survival guide SPS Kansas CityJ.D. Wade
 
LAS16-306: Exploring the Open Trusted Protocol
LAS16-306: Exploring the Open Trusted ProtocolLAS16-306: Exploring the Open Trusted Protocol
LAS16-306: Exploring the Open Trusted ProtocolLinaro
 
Security in Large Networks by Raja Velampalli
Security in Large Networks by Raja VelampalliSecurity in Large Networks by Raja Velampalli
Security in Large Networks by Raja VelampalliRaja Velampalli
 
Django SEM
Django SEMDjango SEM
Django SEMGandi24
 

Similar to Cert profile ssl (20)

A 5 security x line platform
A 5 security x line platformA 5 security x line platform
A 5 security x line platform
 
#MoreCrypto : Introduction to TLS
#MoreCrypto : Introduction to TLS#MoreCrypto : Introduction to TLS
#MoreCrypto : Introduction to TLS
 
Enteprise Sync IT Data Sheets
Enteprise Sync IT Data SheetsEnteprise Sync IT Data Sheets
Enteprise Sync IT Data Sheets
 
03-SSL (1).ppt
03-SSL (1).ppt03-SSL (1).ppt
03-SSL (1).ppt
 
03-SSL (2).ppt
03-SSL (2).ppt03-SSL (2).ppt
03-SSL (2).ppt
 
03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...
03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...
03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL (1).ppt03-SSL ...
 
this is ppt this is ppt this is ppt this is ppt
this is ppt this is ppt this is ppt this is pptthis is ppt this is ppt this is ppt this is ppt
this is ppt this is ppt this is ppt this is ppt
 
Best Practices for IoT Security in the Cloud
Best Practices for IoT Security in the CloudBest Practices for IoT Security in the Cloud
Best Practices for IoT Security in the Cloud
 
HashiTLS Demystifying Security Certs
HashiTLS Demystifying Security CertsHashiTLS Demystifying Security Certs
HashiTLS Demystifying Security Certs
 
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
[cb22] Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulat...
 
Detecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DC
Detecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DCDetecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DC
Detecting Malicious SSL Certificates Using Machine Learning - 2017 B-Sides DC
 
Steam Learn: HTTPS and certificates explained
Steam Learn: HTTPS and certificates explainedSteam Learn: HTTPS and certificates explained
Steam Learn: HTTPS and certificates explained
 
Cisco Connect Ottawa 2018 secure on prem
Cisco Connect Ottawa 2018 secure on premCisco Connect Ottawa 2018 secure on prem
Cisco Connect Ottawa 2018 secure on prem
 
Cisco iso based CA (certificate authority)
Cisco iso based CA (certificate authority)Cisco iso based CA (certificate authority)
Cisco iso based CA (certificate authority)
 
IMS Authentication with AKAv1 and AKAv2
IMS Authentication with AKAv1 and AKAv2 IMS Authentication with AKAv1 and AKAv2
IMS Authentication with AKAv1 and AKAv2
 
Kerberos survival guide SPS Kansas City
Kerberos survival guide SPS Kansas CityKerberos survival guide SPS Kansas City
Kerberos survival guide SPS Kansas City
 
LAS16-306: Exploring the Open Trusted Protocol
LAS16-306: Exploring the Open Trusted ProtocolLAS16-306: Exploring the Open Trusted Protocol
LAS16-306: Exploring the Open Trusted Protocol
 
Security in Large Networks by Raja Velampalli
Security in Large Networks by Raja VelampalliSecurity in Large Networks by Raja Velampalli
Security in Large Networks by Raja Velampalli
 
Django SEM
Django SEMDjango SEM
Django SEM
 
Web Security
Web SecurityWeb Security
Web Security
 

More from Haris Ahmadilapa

Adobe acrobat-405-for-macintosh-readme1239
Adobe acrobat-405-for-macintosh-readme1239Adobe acrobat-405-for-macintosh-readme1239
Adobe acrobat-405-for-macintosh-readme1239Haris Ahmadilapa
 
21tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp01
21tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp0121tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp01
21tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp01Haris Ahmadilapa
 
Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)
Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)
Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)Haris Ahmadilapa
 
Fonts licensed for_editable_embedding_5.15.14
Fonts licensed for_editable_embedding_5.15.14Fonts licensed for_editable_embedding_5.15.14
Fonts licensed for_editable_embedding_5.15.14Haris Ahmadilapa
 
Eula5seat intl english07.11.11
Eula5seat intl english07.11.11Eula5seat intl english07.11.11
Eula5seat intl english07.11.11Haris Ahmadilapa
 
Acrobat reader xi_3rd_party_read_me_ver_1
Acrobat reader xi_3rd_party_read_me_ver_1Acrobat reader xi_3rd_party_read_me_ver_1
Acrobat reader xi_3rd_party_read_me_ver_1Haris Ahmadilapa
 

More from Haris Ahmadilapa (16)

2.1.16 cookheaders.patch
2.1.16 cookheaders.patch2.1.16 cookheaders.patch
2.1.16 cookheaders.patch
 
2.1.16 cookheaders.patch
2.1.16 cookheaders.patch2.1.16 cookheaders.patch
2.1.16 cookheaders.patch
 
2.1.16 cookheaders.patch
2.1.16 cookheaders.patch2.1.16 cookheaders.patch
2.1.16 cookheaders.patch
 
2.1.16 cookheaders.patch
2.1.16 cookheaders.patch2.1.16 cookheaders.patch
2.1.16 cookheaders.patch
 
2.1.16 cookheaders.patch
2.1.16 cookheaders.patch2.1.16 cookheaders.patch
2.1.16 cookheaders.patch
 
Adobe acrobat-405-for-macintosh-readme1239
Adobe acrobat-405-for-macintosh-readme1239Adobe acrobat-405-for-macintosh-readme1239
Adobe acrobat-405-for-macintosh-readme1239
 
21tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp01
21tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp0121tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp01
21tacticstoacquirecustomers referralcandyslideshare-140908124745-phpapp01
 
Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)
Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)
Q3prodwebcastcorpaug26emea 140827162133-phpapp01 (1)
 
Fonts licensed for_editable_embedding_5.15.14
Fonts licensed for_editable_embedding_5.15.14Fonts licensed for_editable_embedding_5.15.14
Fonts licensed for_editable_embedding_5.15.14
 
Mozilla petition
Mozilla petitionMozilla petition
Mozilla petition
 
Apache 2.0-license
Apache 2.0-licenseApache 2.0-license
Apache 2.0-license
 
Eula5seat intl english07.11.11
Eula5seat intl english07.11.11Eula5seat intl english07.11.11
Eula5seat intl english07.11.11
 
Adobe products eula(2)
Adobe products eula(2)Adobe products eula(2)
Adobe products eula(2)
 
Adobe products eula(1)
Adobe products eula(1)Adobe products eula(1)
Adobe products eula(1)
 
Adobe products eula
Adobe products eulaAdobe products eula
Adobe products eula
 
Acrobat reader xi_3rd_party_read_me_ver_1
Acrobat reader xi_3rd_party_read_me_ver_1Acrobat reader xi_3rd_party_read_me_ver_1
Acrobat reader xi_3rd_party_read_me_ver_1
 

Cert profile ssl

  • 1. InCommon SSL Chain Comodo AddTrust External CA: InCommon Intermediate Server CA: Subscriber SSL Certificates InCommon Server CA Version: V3 cert required Serial Number: unique integer (relative to issuer) Signature Algorithm: sha1WithRSAEncryption Validity: 10 years (min 8 years = 3 years of program + 5 years to issue user certs on last day) Issuer: C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root Subject: C=US, O=Internet2, OU=InCommon, CN=InCommon Server CA Public Key: 2048-bit basicConstraints (critical): ca:true pathLenConstraint:0 keyUsage: (critical) keyCertSign (2.5.29.15.5), cRLSign (2.5.29.15.6) cRLDistributionPoints (non-critical): URI:http://crl.usertrust.com/AddTrustExternalCARoot.crl certificatePolicies (non-critical): policyID: anyPolicy (2.5.29.32.0) authorityInfoAccess (non-critical): CA Issuer – URI: http://crt.usertrust.com/AddTrustExternalCARoot.p7c OCSP - URI: http://ocsp.usertrust.com authorityKeyIdentifier (non-critical): keyID: keyid:AD:BD:98:7A:34:B4:26:F7:FA:C4:26:54:EF:03:BD:E0:24:CB:54:1A subjectKeyIdentifier (non-critical): keyID: CE:A6:57:E6:EE:BF:47:3D:12:76:4E:02:88:92:6F:43:BA:DD:C0:F2 InCommon SSL/TLS Certificates Version: V3 certs required Serial Number: unique integer (relative to issuer) Signature Algorithm: sha1WithRSAEncryption / optional: sha256WithRSAEncryption (to follow) Validity: 1 / 2 / 3 years Issuer: C=US, O=Internet2, OU=InCommon, CN=InCommon Server CA Subject: C required ST optional L optional O required (campus defined, InCommon approved) OU optional CN required (dNSName, wildcard is supported, private/local names are supported) Public Key: 2048-bit min basicConstraints (critical): ca:false (no pathLenConstraint) keyUsage: (critical) digitalSignature (2.5.29.15.0), keyEncipherment (2.5.29.15.2) extendedKeyUsage (non-critical): id-kp-serverAuth (1.3.6.1.5.5.7.3.1), id-kp-clientAuth (1.3.6.1.5.5.7.3.2) subjectAltName (non-critical): required, dNSName (min 1, max 100 names) or private/local names / optional rfc822Name (email for admin – must be validated if included) cRLDistributionPoints (non-critical): URI:http://crl.incommon.org/InCommonServerCA.crl certificatePolicies (non-critical): policyID: id-pki-InCommon-SSL (1.3.6.1.4.1.5923.1.4.3.1.1) cpsURI: https://www.incommon.org/cert/repository/cps_ssl.pdf authorityInfoAccess (non-critical): CA Issuer – URI: http://cert.incommon.org/InCommonServerCA.crt
  • 2. OCSP - URI: http://ocsp.incommon.org authorityKeyIdentifier (non-critical): keyID: CE:A6:57:E6:EE:BF:47:3D:12:76:4E:02:88:92:6F:43:BA:DD:C0:F2 subjectKeyIdentifier (non-critical): keyID:...