Find answers to your technical questions and learn how to use our products
Search suggestions:
Find answers to your technical questions and learn how to use our products
Search suggestions:
|
Components
|
Description
|
|---|---|
|
Version
|
Usually V3 – indicating X.509 v3 format
|
|
Serial Number
|
A unique number used to uniquely identify the certificate. There is no requirement that the number is actually serialized, just that it is unique.
|
|
Signature Algorithm
|
The cryptographic algorithm used to create the signature. For example sha256RSA.
|
|
Issuer
|
Details of the certificate authority (CA) that issued the certificate. This consists of a number of sub-fields:
|
|
Subject
|
Details of the device or server to which the certificate belongs. This consists of the same sub-fields as the Subject above.
|
|
Issued By
|
Matches the common name ( CN) of the certificate Issuer.
|
|
Issued To
|
Matches the common name ( CN) of the certificate Subject.
|
|
Valid From
|
The UTC date and time from which the certificate is valid. All clients and servers using certificates require an accurate time source to validate certificates.
|
|
Valid To
|
The UTC date and time at which the certificate expires.
|
|
Subject Alternative Name(s)
|
The Subject Alternative Name(s) (
SAN) lists alternative names linked with the device identified by the certificate. Certificate recipients can use these to verify the source of the certificate.
|
|
Enhanced Key Usage
|
This setting is frequently also called Extended Key Usage and EKU. It indicates the purposes for which the Public Key can be used. For example: Server Authentication and Client Authentication.
|
|
Basic Constraints
|
This part of a certificate can contain the certificates Subject Type and Path Length Constraint as below.
|
|
Subject Type
|
Indicates the type of the certificate. For example:
|
|
Path Length Constraint
|
Sets the depth (number) of intermediate CA certificates allowed between a root certificate and end-entity certificate. For example:
|
|
Key Usage
|
The purposes for which you can use the certificate's public key, for example: certificate signing, encryption, authentication.
|
|
Subject Key Identifier
|
The certificate issuers digital signature, encrypted with their private key. This can be decrypted with the issuer's public key found in the issuer's certificate.
|
|
Public Key Algorithm
|
The public key type and size.
|
|
Public Key
|
The public key.
|