Cybertrust Japan iTrust SSL/TLS Server Certificate Policy/ Certification Practice Statement Version 3.1 Cybertrust Japan Co., Ltd. March 13, 2026 **■ Copyright and distribution conditions of this document** This document is available under Attribution-NoDerivs (CC-BY-ND) 4.0 (or later version) of the Creative Commons license. © 2019 Cybertrust Japan Co., Ltd. Version 3.1 Creation/revision date: March 13, 2026 This document can be copied and distributed in whole or in part free of charge if the following conditions are satisfied. - Display the copyright notice, Version, and revision date on the top of pages of a whole or a part of this copies. - Set forth that full text can be obtained at https://www.cybertrust.ne.jp/ssl/repository/ if only a part of this document is distributed. - Specify the citation source appropriately when using part of this document as excerpts and citations in other documents. - Cybertrust Japan shall not be liable for any dispute or damage related to copying and distribution of this CP/CPS. - In addition, Cybertrust Japan prohibits alteration and modification in any case. For inquiries about the copyright and distribution conditions of this document, please contact us as described in 1.5.2 “Contact person” of this document. ------------------- # Revision History
| Version | Date | Reason for Revision |
|---|---|---|
| 1.0 | September 27, 2019 | Formulation of initial version |
| 1.1 | April 20, 2020 |
|
| 1.2 | April 1, 2021 |
|
| 1.3 | May 13, 2022 |
|
| 1.4 | September 5, 2022 |
|
| 1.5 | August 4, 2023 |
|
| 1.6 | August 31, 2023 |
|
| 1.7 | December 18,2023 |
|
| 1.8 | January 25, 2024 |
|
| 1.9 | June 28, 2024 |
|
| 1.10 | September 13, 2024 |
|
| 1.11 | December 23, 2024 |
|
| 1.12 | June 1, 2025 |
|
| 2.0 | July 15, 2025 |
|
| 2.1 | September 17, 2025 |
|
| 2.2 | October 31, 2025 |
|
| 3.0 | December 22, 2025 |
|
| 3.1 | March 13, 2026 |
|
| Contact Information | ||||||
|---|---|---|---|---|---|---|
General contact in Cybertrust Japan Co., Ltd. Address: 13F SE Sapporo Bldg., 1-1-2 Kita 7-jo Nishi, Kita-ku, Sapporo-shi 060-0807 Tel: 0120-957-975 or +81-11-708-5283 Business Days: Monday to Friday (excluding National Holidays, and the designated days addressed on Cybertrust’s website including Year-End and New Year) Business Hours: 9:00 to 18:00 Inquiries and complaints: As indicated below
|
| Term | Definition |
|---|---|
| Archive | As used herein, the term "archive" refers to the process of storing expired certificates for a predetermined period. |
| Application Software Supplier | A supplier of software or other relying-party application software that displays or uses the Certificates, incorporates Root Certificates, and adopts the CA/Browser Forum’s Requirements as all or part of its requirements for participation in a root store program. |
| Cryptographic Module | Software, hardware, or a device configured from the combination of such software and hardware that is used for ensuring security in the generation, storage and use of private keys. |
| Suspension | Measure for temporarily invalidating a certificate during the effective period of that certificate. |
| Key Size | A bit number that represents the key size (number of digits), which is also a factor in deciding the cryptographic strength. |
| Key Pair | A public key and a private key in public key cryptography. The two keys are unique in that one key cannot be derived from the other key. |
| Activation | To cause a system or device to be usable. Activation requires activation data, and specifically includes a PIN and pass phrase. |
| Subscriber Agreement | An agreement to be accepted by a subscriber to apply for and use a certificate. This CP/CPS constitute a part of the subscriber agreement. |
| Compromise | A state where the confidentiality or integrity of information that is incidental to the private key and the private key is lost. |
| Public Key | One key of the key pair in public key cryptography that is notified to and used by the other party (communication partner, etc.). |
| Sole Proprietor | A person who meets all the following conditions.
|
| Mixed characters | String that contains two or more types of characters, such as alphanumeric characters and symbols. |
| Revocation | Measure for invalidating a certificate even during the effective period of that certificate. |
| Certificate Management System | A system used by a CA or Delegated Third Party to process, approve issuance of, or store certificates or certificate status information, including the database, database server, and storage. |
| Certificate Revocation List | Abbreviated as "CRL" in this CP/CPS. CRL is a list of revoked certificates. A Certification Authority publishes CRL so that the relying parties can verify the validity of certificates. |
| Certificate Systems | The system used by a CA or Delegated Third Party in providing identity verification, registration and enrollment, certificate approval, issuance, validity status, support, and other PKI‐related services. |
| Certification Operations | Series of operations that are performed during the life cycle controls of certificates. Including, but not limited to, operations of accepting issuance/revocation requests, screening operations, issuance/revocation/discarding operations, operations of responding to inquiries, billing operations, and system maintenance and management operations of Certification Authorities. |
| Backup Site | A facility that is separate from the main site for storing important assets of Certification Authorities required for certificate issuance and revocation to ensure business continuity during disasters. |
| Private Key | One key of the key pair in public key cryptography that is kept private from third parties other than a subscriber. |
| Main Site | A facility equipped with assets of Certification Authorities required for certificate issuance and revocation. |
| Escrow | As used herein, the term "escrow" refers to the processing of registering and storing a private key or a public key at a third party. |
| Repository | A website or system for posting public information such as this CP/CPS and CRL. |
| Linting | A process in which the content of digitally signed data such as a Precertificate, Certificates, CRL, or OCSP Response, or data-to-be-signed object such as a `tbsCertificate` (as described in RFC 5280, Section 4.1.1.1) is checked for conformance with the profiles and requirements defined in the BR. |
| Root CA | A certification authority above the Certification Authority. It issues certificates of the Certification Authority. |
| ACME | Abbreviation for "Automated Certificate Management Environment" and it is a standard protocol for automating the processes of domain names verification, installation, and management for X.509 certificates. |
| ALPN | Abbreviation for "Application-Layer Protocol Negotiation" and it is an extended function of TLS. |
| Apple Root Certificate Program | The requirements which Apple imposes certification authorities to have their certificates trusted and included in Apple Root Program. |
| Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates (BR) | Requirements for issuing publicly-trusted SSL/TLS Server certificates which were formulated by the CA/Browser Forum. |
| CA/Browser Forum | Organization that consists of the Certification Authorities that issue publicly trusted certificates for SSL/TLS communications and the companies that develop applications such as browsers. It creates standards for the certificates. The website of the organization is https://cabforum.org/. |
| Certificate Transparency | A scheme standardized in RFC6962 for promptly discovering and detecting fraudulent certificates. |
| Chrome Root Program Policy | The requirements which Google imposes certification authorities to have their certificates trusted and included in Google Root Program. |
| DBA/Tradename | Indicates a common name, trade name, shop name, trademark, etc. other than the legal name of an organization. |
| Distinguished Name | An identifier set forth in the X.500 recommendation formulated by ITU-T. Configured from attribute information such as a common name, organization name, and country name. |
| DNS CAA Email Contact | The email address defined in APPENDIX A.1.1 of BR. |
| DNS CAA Phone Contact | The phone number defined in APPENDIX A.1.2 of BR. |
| DNS Certification Authority Authorization Resource Record (CAA Record) | One of the DNS records defined in RFC8659 which aims to clarify the certification authority to issue the server certificate to a domain name and prevent the issuance of unintended certificates. |
| DNS TXT Record Email Contact | The email address defined in APPENDIX A.2.1 of BR. |
| DNS TXT Record Phone Contact | The phone number defined in APPENDIX A.2.2 of BR. |
| Extended Validation Certificate (EV Certificate) | EV certificates that are issued based on the "Guidelines For The Issuance And Management Of Extended Validation Certificates" set forth by the CA/Browser Forum and are used for the authentication of servers in SSL/TLS communication. |
| FIPS 140-2 | FIPS (Federal Information Processing Standards Publication 140) is a U.S. federal standard that prescribes the specifications of security requirements in a cryptographic module, and the latest version of this standard is 2. With this standard, the security requirements are classified as the levels of 1 (lowest) to 4 (highest). |
| Fully-Qualified Domain Name (FQDN) | A domain name to which a subdomain name and a host name are added and is included in a certificate. |
| Guidelines for the Issuance and Management of Extended Validation Certificates (EV Guidelines) | Requirements for issuing EV certificates, which were formulated by the CA/Browser Forum. |
| IETF PKIX Working Group | Internet Engineering Task Force (IETF) is an organization that standardizes technologies used for the Internet, and the PKIX Working Group of IETF set forth in RFC 3647. |
| IP Address | 32-bit or 128-bit label that is assigned to a device that uses the Internet Protocol for communications. |
| IP Address Contact | A person or organization authorized to control the method of using one or more IP addresses that are registered in an IP address registration authority. |
| IP Address Registration Authority | Internet Assigned Numbers Authority (IANA) or Regional Internet Registry (RIPE, APNIC, ARIN, AfriNIC, LACNIC). |
| ITU-T | Telecommunications Standardization Sector of the International Telecommunication Union. |
| Program Requirements - Microsoft Trusted Root Program | The requirements which Microsoft imposes certification authorities to have their certificates trusted and included in Microsoft Root Program. |
| Mozilla Root Store Policy | The requirements which Mozilla imposes certification authorities to have their certificates trusted and included in Mozilla Root Program. |
| Multi-Perspective Issuance Corroboration | Refers to the process of obtaining same validation results as a domain validation and/or CAA check, confirmed using multiple Network Perspectives before Certificate issuance. This process can protect against Border Gateway Protocol (BGP) attacks or hijacks and improve the reliability of the validation results. Network Perspective refers to a system that operates on a network to obtain the information necessary for some validations. The Network Perspective used as the primary system is called the Primary Network Perspective, while the Network Perspective operating from a remote location is referred to as the remote Network Perspective. |
| Name Constraints | Registration of the Key Usage and Name Constraint extensions in a certificate of a certification authority to restrict the issue of a certificate. |
| Network and Certificate System Security Requirements | The requirements developed by CA/Browser Forum for the security on network of publicly trusted certificate and the security of CA systems. |
| OCSP | Abbreviation of "Online Certificate Status Protocol" and is a communication protocol for providing certificate revocation information. A Certification Authority operates an OCSP Responder, in addition to publicly disclosing the CRL, so that a relying party can verify the validity of a certificate. |
| Organizational Validation Certificates (OV Certificate) | OV certificates that are issued based on the “Baseline Requirements for the Issuance and Management of Publicly Trusted TLS Server Certificates” as set forth by the CA/Browser Forum and are used for the authentication of servers in SSL/TLS communication. |
| Punycode | Punycode is a method, defined in RFC 3492, designed to encode an Internationalized Domain Names (IDN). The value transformed its Unicode string into an ASCII characters with ACE prefix "xn--" added in accordance with Punycode encoding method shall be called "A-label". |
| Precertificate | Certificates explained in RFC6962 which is a document on Certificate Transparency. |
| RSA | Public key cryptography developed by Rivest, Shamir, and Adelman. |
| RFC7231 | The document named "Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content" defining semantics of HTTP/1.1 message which is set forth by the IETF PKIX Working Group. |
| RFC7538 | The document named "The Hypertext Transfer Protocol Status Code 308 (Permanent Redirect)" defining the additional Hypertext Transfer Protocol (HTTP) status code 308 (Permanent Redirect) which is set forth by the IETF PKIX Working Group. |
| SHA1/SHA2 | A hash function used in digital signatures, etc. A hash function is used for reducing data into a given length based on mathematical operations, and makes it infeasible to calculate the same output value from two different input values. It is also infeasible to inverse the input value from the output value. |
| SSL/TLS | A protocol for encrypting and sending/receiving information on the Internet which was developed by Netscape Communications. TLS is an improvement of SSL 3.0. |
| WebTrust Principles and Criteria | Audit standards established by CPA Canada to evaluate the appropriateness and effectiveness of certification authority operations. |
| X.500 | International standard of distribution directory services to be provided on a network standardized by ITU-T. |
| X.509 | International standard of digital certificates standardized by ITU-T. |
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
46157929531853354100488418937468587687 (0x22b9b1a12d91f181ad7a7b6dbeb38ea7) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
SECOM Trust Systems CO.,LTD. | |
| organizationalUnitName | Organizational unit name attribute of certificate issuer | |
|
type |
Object ID for organizational unit name | |
|
type:OID |
2.5.4.11 | |
|
value |
Value of organizational unit name | |
|
type:PrintableString |
Security Communication RootCA2 | |
| validity | value | |
| Validity | Validity period of the certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
231213062845Z (December 13, 2023 15:28:45 JST) |
|
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
290529050039Z (May 29, 2029 14:00:39 JST) |
|
| subject | value | |
| countryName | Country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer EV CA G3 | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*Public key of 2048 bit size | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Information of Subject Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
82:6C:75:5D:53:F5:45:69:BC:25:2D:A4:4C:89:E6:B2:B7:41:87:A3 | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
| type:OCTET STRING | 0A:85:A9:77:65:05:98:7C:40:81:F8:0F:97:2C:38:F1:0A:EC:3C:CF | |
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
|
type:BOOLEAN |
TRUE | |
|
pathLenConstraint |
Path length constraint | |
|
type:INTEGER |
0 | |
| keyUsage (extnId :== 2.5.29.15, critical :== TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
00000110 (0x06) (keyCertSign, cRLSign) |
|
| cRLDistributionPoints (extnId :== 2.5.29.31, critical :== FALSE) | value | |
| CRLDistributionPoints | CRL Distribution Point | |
|
DistributionPoint |
CRL Distribution Point | |
|
uniformResourceIdentifier |
URI of CRL Distribution Point | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2CRL.crl | |
| certificatePolicies (extnId :== 2.5.29.32, critical :== FALSE) | value | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
2.23.140.1.1 | |
|
PolicyInformation |
Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
1.2.392.200091.100.721.1 | |
|
policyQualifiers |
Information of the policy qualifiers | |
|
PolicyQualifierID |
Classification of the policy qualifiers | |
|
type:OID |
1.3.6.1.5.5.7.2.1 (CPSuri) | |
|
Qualifier |
URI of CPS is published | |
|
type:IA5String |
https://repository.secomtrust.net/SC-Root2/ | |
| authorityInfoAccess (extnId :== 1.3.6.1.5.5.7.1.1, critical :== FALSE) | value | |
| AuthorityInfoAccess | Authority Information Access | |
|
AccessDescription |
Online Certificate Status Protocol | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.1 (ocsp) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://scrootca2.ocsp.secomtrust.net | |
|
AccessDescription |
Issuer of the Authority | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.2 (caIssuers) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2ca.cer | |
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.1 (serverAuth) 1.3.6.1.5.5.7.3.2 (clientAuth) |
|
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
640569885012466767356 (0x22b9b16488bce695fc) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
SECOM Trust Systems CO.,LTD. | |
| organizationalUnitName | Organizational unit name attribute of certificate issuer | |
|
type |
Object ID for organizational unit name | |
|
type:OID |
2.5.4.11 | |
|
value |
Value of organizational unit name | |
|
type:PrintableString |
Security Communication RootCA2 | |
| validity | value | |
| Validity | Validity period of the certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
190927020420Z (September 27, 2019 11:04:20 JST) |
|
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
290529050039Z (May 29, 2029 14:00:39 JST) |
|
| subject | value | |
| countryName | Country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer EV CA G3 | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*Public key of 2048 bit size | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Information of Subject Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
82:6C:75:5D:53:F5:45:69:BC:25:2D:A4:4C:89:E6:B2:B7:41:87:A3 | |
| certificatePolicies (extnId :== 2.5.29.32, critical :== FALSE) | value | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
| type:OID | 1.2.392.200091.100.721.1 | |
|
policyQualifiers |
Information of the policy qualifiers | |
|
PolicyQualifierID |
Classification of the policy qualifiers | |
|
type:OID |
1.3.6.1.5.5.7.2.1 (CPSuri) | |
|
Qualifier |
URI of CPS is published | |
|
type:IA5String |
https://repository.secomtrust.net/SC-Root2/ | |
| cRLDistributionPoints (extnId :== 2.5.29.31, critical :== FALSE) | value | |
| CRLDistributionPoints | CRL Distribution Point | |
|
DistributionPoint |
CRL Distribution Point | |
|
uniformResourceIdentifier |
URI of CRL Distribution Point | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2CRL.crl | |
| authorityInfoAccess (extnId :== 1.3.6.1.5.5.7.1.1, critical :== FALSE) | value | |
| AuthorityInfoAccess | Authority Information Access | |
|
AccessDescription |
Online Certificate Status Protocol | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.1 (ocsp) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://scrootca2.ocsp.secomtrust.net | |
|
AccessDescription |
Issuer of the Authority | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.2 (caIssuers) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2ca.cer | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
0A:85:A9:77:65:05:98:7C:40:81:F8:0F:97:2C:38:F1:0A:EC:3C:CF | |
| keyUsage (extnId :== 2.5.29.15, critical :== TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
00000110 (0x06) (keyCertSign, cRLSign) |
|
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.1 (serverAuth) 1.3.6.1.5.5.7.3.2 (clientAuth) |
|
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
|
type:BOOLEAN |
TRUE | |
|
pathLenConstraint |
Path length constraint | |
|
type:INTEGER |
0 | |
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
46157929474543200098709732507498232300 (0x22b9b1a074641857f7a01332db42b9ec) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
SECOM Trust Systems CO.,LTD. | |
| organizationalUnitName | Organizational unit name attribute of certificate issuer | |
|
type |
Object ID for organizational unit name | |
|
type:OID |
2.5.4.11 | |
|
value |
Value of organizational unit name | |
|
type:PrintableString |
Security Communication RootCA2 | |
| validity | value | |
| Validity | Validity period of the certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
231213055730Z (December 13, 2023 14:57:30 JST) |
|
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
290529050039Z (May 29, 2029 14:00:39 JST) |
|
| subject | value | |
| countryName | Country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer CA G4 | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*Public key of 2048 bit size | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Information of Subject Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
62:A7:D2:DA:DE:85:B6:92:F1:85:BC:F6:E8:95:9D:75:A0:FA:4E:1F | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
| type:OCTET STRING | 0A:85:A9:77:65:05:98:7C:40:81:F8:0F:97:2C:38:F1:0A:EC:3C:CF | |
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
| type:BOOLEAN | TRUE | |
|
pathLenConstraint |
Path length constraint | |
|
type:INTEGER |
0 | |
| keyUsage (extnId :== 2.5.29.15, critical :== TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
00000110 (0x06) (keyCertSign, cRLSign) |
|
| cRLDistributionPoints (extnId :== 2.5.29.31, critical :== FALSE) | value | |
| CRLDistributionPoints | CRL Distribution Point | |
|
DistributionPoint |
CRL Distribution Point | |
|
uniformResourceIdentifier |
URI of CRL Distribution Point | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2CRL.crl | |
| certificatePolicies (extnId :== 2.5.29.32, critical :== FALSE) | value | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
2.23.140.1.2.2 | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
1.2.392.200091.100.901.4 | |
|
policyQualifiers |
Information of the policy qualifiers | |
|
PolicyQualifierID |
Classification of the policy qualifiers | |
|
type:OID |
1.3.6.1.5.5.7.2.1 (CPSuri) | |
|
Qualifier |
URI of CPS is published | |
|
type:IA5String |
https://repository.secomtrust.net/SC-Root2/ | |
| authorityInfoAccess (extnId :== 1.3.6.1.5.5.7.1.1, critical :== FALSE) | value | |
| AuthorityInfoAccess | Authority Information Access | |
|
AccessDescription |
Online Certificate Status Protocol | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.1 (ocsp) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://scrootca2.ocsp.secomtrust.net | |
|
AccessDescription |
Issuer of the Authority | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.2 (caIssuers) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2ca.cer | |
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.1 (serverAuth) 1.3.6.1.5.5.7.3.2 (clientAuth) |
|
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
640569883381181201454 (0x22b9b1630cecb43c2e) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
SECOM Trust Systems CO.,LTD. | |
| organizationalUnitName | Organizational unit name attribute of certificate issuer | |
|
type |
Object ID for organizational unit name | |
|
type:OID |
2.5.4.11 | |
|
value |
Value of organizational unit name | |
|
type:PrintableString |
Security Communication RootCA2 | |
| validity | value | |
| Validity | Validity period of the certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
190927015423Z (September 27, 2019 10:54:23 JST) |
|
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
290529050039Z (May 29, 2029 14:00:39 JST) |
|
| subject | value | |
| countryName | Country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer CA G4 | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*Public key of 2048 bit size | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Information of Subject Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
62:A7:D2:DA:DE:85:B6:92:F1:85:BC:F6:E8:95:9D:75:A0:FA:4E:1F | |
| certificatePolicies (extnId :== 2.5.29.32, critical :== FALSE) | value | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
| type:OID | 1.2.392.200091.100.901.4 | |
|
policyQualifiers |
Information of the policy qualifiers | |
|
PolicyQualifierID |
Classification of the policy qualifiers | |
|
type:OID |
1.3.6.1.5.5.7.2.1 (CPSuri) | |
|
Qualifier |
URI of CPS is published | |
|
type:IA5String |
https://repository.secomtrust.net/SC-Root2/ | |
| cRLDistributionPoints (extnId :== 2.5.29.31, critical :== FALSE) | value | |
| CRLDistributionPoints | CRL Distribution Point | |
|
DistributionPoint |
CRL Distribution Point | |
|
uniformResourceIdentifier |
URI of CRL Distribution Point | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2CRL.crl | |
| authorityInfoAccess (extnId :== 1.3.6.1.5.5.7.1.1, critical :== FALSE) | value | |
| AuthorityInfoAccess | Authority Information Access | |
|
AccessDescription |
Online Certificate Status Protocol | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.1 (ocsp) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://scrootca2.ocsp.secomtrust.net | |
|
AccessDescription |
Issuer of the Authority | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.2 (caIssuers) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://repository.secomtrust.net/SC-Root2/SCRoot2ca.cer | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
0A:85:A9:77:65:05:98:7C:40:81:F8:0F:97:2C:38:F1:0A:EC:3C:CF | |
| keyUsage (extnId :== 2.5.29.15, critical :== TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
00000110 (0x06) (keyCertSign, cRLSign) |
|
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.1 (serverAuth) 1.3.6.1.5.5.7.3.2 (clientAuth) |
|
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
|
type:BOOLEAN |
TRUE | |
|
pathLenConstraint |
Path length constraint | |
|
type:INTEGER |
0 | |
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
*Serial number of certificate (unique positive integer) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate issuer | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer EV CA G3 | |
| validity | value | |
| Validity | Validity period of certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
*The date on which the certificate validity period begins | |
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
*The date on which the certificate validity period ends | |
| subject | value | |
| jurisdictionOfIncorporationCountryName | Jurisdiction of incorporation country name attribute of certificate subject | |
|
type |
Object ID for the jurisdiction of incorporation state or province name | |
|
type:OID |
1.3.6.1.4.1.311.60.2.1.3 | |
|
value |
Value of jurisdiction of incorporation state or province name | |
|
type:PrintableString |
JP (Fixed value) | |
| jurisdictionOfIncorporationStateOrProvinceName | Jurisdiction of incorporation state or province name attribute of certificate subject | *Only valid when business category of the applicant is government entity (municipality or other) |
|
type |
Object ID for the jurisdiction of incorporation state or province name | |
|
type:OID |
1.3.6.1.4.1.311.60.2.1.2 | |
|
value |
Value of jurisdiction of incorporation state or province name | |
|
type:PrintableString |
*Jurisdiction of incorporation state or province name | |
| jurisdictionOfIncorporationLocalityName | Jurisdiction of incorporation locality name attribute of certificate subject | *Only valid when business category of the applicant is government entity (other) |
|
type |
Object ID for the jurisdiction of incorporation locality name | |
|
type:OID |
1.3.6.1.4.1.311.60.2.1.1 | |
|
value |
Value of jurisdiction of incorporation locality name | |
|
type:PrintableString |
*Jurisdiction of incorporation locality name | |
| serialNumber | Registration number attribute of certificate subject | |
|
type |
Object ID for the registration number | |
|
type:OID |
2.5.4.5 | |
|
value |
Value of registration number | |
|
type:PrintableString |
*Registration number attribute of certificate subject *When business category of the applicant is private organization, it is required registration number. When business category of the applicant is government entity, it is required "The Subject is Government Entity". |
|
| businessCategory | Business category attribute of certificate subject | |
|
type |
Object ID for the business category | |
|
type:OID |
2.5.4.15 | |
|
value |
Value of business category | |
|
type:PrintableString |
*Business category attribute of certificate subject Private: Private Organization Government (central government ministries /the administrative divisions of Japan / municipality): Government Entity Government(others) : Government Entity |
|
| countryName | Validated country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
*Validated country name attribute of certificate subject | |
| stateOrProvinceName | Validated state or Province name attribute of certificate subject | |
|
type |
Object ID for the state or province name | |
|
type:OID |
2.5.4.8 | |
|
value |
Value of state or province name | |
|
type:PrintableString / UTF8String |
*Validated state or province name attribute of certificate subject | |
| localityName | Validated locality name attribute of certificate subject | |
|
type |
Object ID for the locality name | |
|
type:OID |
2.5.4.7 | |
|
value |
Value of locality name | |
|
type:PrintableString / UTF8String |
*Validated locality name attribute of certificate subject | |
| organizationName | Formal organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString / UTF8String |
*Formal organization name attribute of certificate subject | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
*FQDN of the SSL/TLS server | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*The key size depends on application *The key size must be at least 2048 bit |
|
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
|
type:BOOLEAN |
FALSE | |
| certificatePolicies (extnId :== 2.5.29.32, critical :== FALSE) | value | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
2.23.140.1.1 (extended-validation) | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
1.2.392.200081.1.22.1 | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
1.2.392.200091.100.721.1 | |
|
policyQualifiers |
Information of the policy qualifiers | |
|
PolicyQualifierID |
Classification of the policy qualifiers | |
|
type:OID |
1.3.6.1.5.5.7.2.1 (CPSuri) | |
|
Qualifier |
URI of CPS is published | |
|
type:IA5String |
https://www.cybertrust.ne.jp/ssl/repository/index.html | |
| authorityInfoAccess (extnId :== 1.3.6.1.5.5.7.1.1, critical :== FALSE) | value | |
| AuthorityInfoAccess | Authority Information Access | |
|
AccessDescription |
Online Certificate Status Protocol | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.1 (ocsp) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://evocsp.cybertrust.ne.jp/OcspServer | |
|
AccessDescription |
Issuer of the Authority | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.2 (caIssuers) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://crl.cybertrust.ne.jp/SureServer/evcag3/evcag3.crt | |
| subjectAltName (extnId :== 2.5.29.17, critical :== FALSE) | value | |
| SubjectAltName | Subject Alternative Name | |
|
dNSName |
DNSName | |
|
type:IA5String |
*FQDN of the SSL/TLS server | |
| keyUsage (extnId :== 2.5.29.15, critical :==TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
10100000 (0xA0) (digitalSignature, keyEncipherment) |
|
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.1 (serverAuth) 1.3.6.1.5.5.7.3.2 (clientAuth) |
|
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
82:6C:75:5D:53:F5:45:69:BC:25:2D:A4:4C:89:E6:B2:B7:41:87:A3 | |
| cRLDistributionPoints (extnId :== 2.5.29.31, critical :== FALSE) | value | |
| CRLDistributionPoints | CRL Distribution Point | |
|
DistributionPoint |
CRL Distribution Point | |
|
uniformResourceIdentifier |
URI of CRL Distribution Point | |
|
type:IA5String |
http://crl.cybertrust.ne.jp/SureServer/evcag3/cdp.crl | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Subject Key Identifier(Based on RFC 5280, Section 4.2.1.2) | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
*Hash value of the BIT STRING subjectPublicKey | |
| signedCertificateTimestampList (extnId :== 1.3.6.1.4.1.11129.2.4.2, critical :== FALSE) | value | |
| SignedCertificateTimestampList | Timestamp list for Certificate Transparency | |
|
SignedCertificateTimestamp |
Timestamp of Certificate Transparency type:OCTET STRING |
*Signed CertificateTimestamp List |
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
*Serial number of certificate (unique positive integer) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate issuer | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer CA G4 | |
| validity | value | |
| Validity | Validity period of certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
*The date on which the certificate validity period begins | |
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
*The date on which the certificate validity period ends | |
| subject | value | |
| countryName | Validated country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
*Validated country name attribute of certificate subject | |
| stateOrProvinceName | Validated state or Province name attribute of certificate subject | |
|
type |
Object ID for the state or province name | |
|
type:OID |
2.5.4.8 | |
|
value |
Value of state or province name | |
|
type:PrintableString / UTF8String |
*Validated state or province name attribute of certificate subject | |
| localityName | Validated locality name attribute of certificate subject | |
|
type |
Object ID for the locality name | |
|
type:OID |
2.5.4.7 | |
|
value |
Value of locality name | |
|
type:PrintableString / UTF8String |
*Validated locality name attribute of certificate subject | |
| organizationName | Formal organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString / UTF8String |
* Formal organization name attribute of certificate subject | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
*FQDN of the SSL/TLS server | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*The key size depends on application *The key size must be at least 2048 bit |
|
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
|
type:BOOLEAN |
FALSE | |
| certificatePolicies (extnId :== 2.5.29.32, critical :== FALSE) | value | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
2.23.140.1.2.2 (organization-validated) | |
| PolicyInformation | Information of the Policy | |
|
policyIdentifier |
Object ID for the Policy | |
|
type:OID |
1.2.392.200081.1.23.1 | |
|
policyQualifiers |
Information of the policy qualifiers | |
|
PolicyQualifierID |
Classification of the policy qualifiers | |
|
type:OID |
1.3.6.1.5.5.7.2.1 (CPSuri) | |
|
Qualifier |
URI of CPS is published | |
|
type:IA5String |
https://www.cybertrust.ne.jp/ssl/repository/index.html | |
| subjectAltName (extnId :== 2.5.29.17, critical :== FALSE) | value | |
| SubjectAltName | Subject Alternative Name | |
|
dNSName or iPAddress |
DNS Name or iPAddress | |
|
type:IA5String (DNS Name) type: OCTET STRING (iPAddress) |
*FQDN or IP address of the SSL/TLS server | |
| authorityInfoAccess (extnId :== 1.3.6.1.5.5.7.1.1, critical :== FALSE) | value | |
| Authority Information Access | Authority Information Access | |
|
AccessDescription |
Online Certificate Status Protocol | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.1 (ocsp) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://ssocsp.cybertrust.ne.jp/OcspServer | |
|
AccessDescription |
Issuer of the Authority | |
|
accessMethod |
Access method | |
|
type:OID |
1.3.6.1.5.5.7.48.2 (caIssuers) | |
|
accessLocation |
Access location | |
|
type:IA5String |
http://crl.cybertrust.ne.jp/SureServer/ovcag4/ovcag4.crt | |
| keyUsage (extnId :== 2.5.29.15, critical :==TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
10100000 (0xA0) (digitalSignature, keyEncipherment) |
|
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.1 (serverAuth) 1.3.6.1.5.5.7.3.2 (clientAuth) |
|
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
62:A7:D2:DA:DE:85:B6:92:F1:85:BC:F6:E8:95:9D:75:A0:FA:4E:1F | |
| cRLDistributionPoints (extnId :== 2.5.29.31, critical :== FALSE) | value | |
| CRLDistributionPoints | CRL Distribution Point | |
|
DistributionPoint |
CRL Distribution Point | |
|
uniformResourceIdentifier |
URI of CRL Distribution Point | |
|
type:IA5String |
http://crl.cybertrust.ne.jp/SureServer/ovcag4/cdp.crl | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Subject Key Identifier (Generated according to RFC5280, Section 4.2.1.2) | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
*Hash value of the BIT STRING subjectPublicKey | |
| signedCertificateTimestampList (extnId :== 1.3.6.1.4.1.11129.2.4.2, critical :== FALSE) | value | |
| SignedCertificateTimestampList | Timestamp list for Certificate Transparency | |
|
SignedCertificateTimestamp |
Timestamp of Certificate Transparency type:OCTET STRING |
*Signed CertificateTimestamp List |
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
*Serial number of certificate (unique positive integer) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate issuer | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer EV CA G3 | |
| validity | value | |
| Validity | Validity period of certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
*The date on which the certificate validity period begins | |
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
*The date on which the certificate validity period ends | |
| subject | value | |
| countryName | Country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer EV CA G3 OCSP Responder | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*Public key of 2048 bit size | |
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
|
type:BOOLEAN |
FALSE | |
| ocspNoCheck (extnId :== 1.3.6.1.5.5.7.48.1.5, critical :== FALSE) | value | |
| OCSPNoCheck | Revocation checking of signer certificates | |
| Do not check revocation | NULL | |
| keyUsage (extnId :== 2.5.29.15, critical :== TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
10000000 (0x80) (digitalSignature) |
|
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.9 (OCSPSigning) | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
82:6C:75:5D:53:F5:45:69:BC:25:2D:A4:4C:89:E6:B2:B7:41:87:A3 | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Subject Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
*Hash value of the BIT STRING subjectPublicKey | |
| version | value | |
| Version | Version of the encoded certificate | |
|
type:INTEGER |
2 (Ver.3) | |
| serialNumber | value | |
| CertificateSerialNumber | Serial number of certificate | |
|
type:INTEGER |
*Serial number of certificate (unique positive integer) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CA to sign this certificate | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country-name attribute of certificate issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate issuer | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer CA G4 | |
| validity | value | |
| Validity | Validity period of certificate | |
|
notBefore |
The date on which the certificate validity period begins | |
|
type:UTCTime |
*The date on which the certificate validity period begins | |
|
notAfter |
The date on which the certificate validity period ends | |
|
type:UTCTime |
*The date on which the certificate validity period ends | |
| subject | value | |
| countryName | Country name attribute of certificate subject | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of certificate subject | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of certificate subject | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer CA G4 OCSP Responder | |
| subjectPublicKeyInfo | value | |
| SubjectPublicKeyInfo | Subject’s public key information | |
|
AlgorithmIdentifier |
The identifier for cryptographic algorithm | |
|
algorithm |
Object ID for the cryptographic algorithm | |
|
type:OID |
1.2.840.113549.1.1.1 (rsaEncryption) | |
|
parameters |
Parameters of cryptographic algorithm | |
|
type:NULL |
NULL | |
|
subjectPublicKey |
Value of public key | |
|
type:BIT STRING |
*Public key of 2048 bit size | |
| basicConstraints (extnId :== 2.5.29.19, critical :== TRUE) | value | |
| BasicConstraints | Basic Constraints | |
|
cA |
The flag to determine whether the supplied certificate is associated with a CA or an end entity | |
|
type:BOOLEAN |
FALSE | |
| ocspNoCheck (extnId :== 1.3.6.1.5.5.7.48.1.5, critical :== FALSE) | value | |
| OCSPNoCheck | Revocation checking of signer certificates | |
| Do not check revocation | NULL | |
| keyUsage (extnId :== 2.5.29.15, critical :== TRUE) | value | |
| KeyUsage | Key Usage | |
|
type:BIT STRING |
10000000 (0x80) (digitalSignature) |
|
| extKeyUsage (extnId :== 2.5.29.37, critical :== FALSE) | value | |
| ExtKeyUsage | Extended Key Usage | |
|
KeyPurposeId |
The purpose of the key contained in the certificate | |
|
type:OID |
1.3.6.1.5.5.7.3.9 (OCSPSigning) | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
62:A7:D2:DA:DE:85:B6:92:F1:85:BC:F6:E8:95:9D:75:A0:FA:4E:1F | |
| subjectKeyIdentifier (extnId :== 2.5.29.14, critical :== FALSE) | value | |
| SubjectKeyIdentifier | Subject Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
| type:OCTET STRING | *Hash value of the BIT STRING subjectPublicKey | |
| version | value | |
| Version | Version of the CRL (Revocation list) | |
|
type:INTEGER |
1 (Ver.2) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CRL issuer to sign the CertificateList | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of CRL issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of CRL issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of CRL issuer | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer EV CA G3 | |
| thisUpdate | value | |
| thisUpdate | The issue date of this CRL | |
|
type:UTCTime |
*The date on which the certificate validity period begins | |
| nextUpdate | value | |
| nextUpdate | The date by which the next CRL is issued | |
|
type:UTCTime |
*The date by which the next CRL is issued | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
82:6C:75:5D:53:F5:45:69:BC:25:2D:A4:4C:89:E6:B2:B7:41:87:A3 | |
| cRLNumber (extnId :== 2.5.29.20, critical :== FALSE) | value | |
| cRLNumber | CRL Number | |
|
type:INTEGER |
*Serial number of CRL | |
| revokedCertificates | value | |
| CertificateSerialNumber | Serial number of revoked certificate | |
|
type:INTEGER |
*Serial number of revoked certificate | |
| revocationDate | The date on which the revocation occurred | |
|
type:UTCTime |
*The date on which the revocation occurred | |
| invalidityDate (extnId :== 2.5.29.24, critical :== FALSE) | value | |
| invalidityDate | The date on which it is known or suspected That the certificate became invalid | |
|
type:GeneralizedTime |
*The date on which the revocation occurred of the certificate | |
| cRLReason (extnId :== 2.5.29.21, critical :== FALSE) | value | |
| CRLReason | The reason code for the certificate revocation | |
|
type:ENUMERATED |
*Value of reason code for the revocation | |
| version | value | |
| Version | Version of the CRL(Revocation list) | |
|
type:INTEGER |
1 (Ver.2) | |
| signature | value | |
| AlgorithmIdentifier | The identifier for the signature algorithm used by the CRL issuer to sign the CertificateList | |
|
algorithm |
Object ID for the signature algorithm | |
|
type:OID |
1.2.840.113549.1.1.11 (sha256WithRSAEncryption) | |
|
parameters |
Parameters of signature algorithm | |
|
type:NULL |
NULL | |
| issuer | value | |
| countryName | Country name attribute of CRL issuer | |
|
type |
Object ID for the country name | |
|
type:OID |
2.5.4.6 | |
|
value |
Value of country name | |
|
type:PrintableString |
JP | |
| organizationName | Organization name attribute of CRL issuer | |
|
type |
Object ID for organization name | |
|
type:OID |
2.5.4.10 | |
|
value |
Value of organization name | |
|
type:PrintableString |
Cybertrust Japan Co., Ltd. | |
| commonName | Common name attribute of CRL issuer | |
|
type |
Object ID for common name | |
|
type:OID |
2.5.4.3 | |
|
value |
Value of common name | |
|
type:PrintableString |
Cybertrust Japan SureServer CA G4 | |
| thisUpdate | value | |
| thisUpdate | The issue date of this CRL | |
|
type:UTCTime |
*The issue date of this CRL | |
| nextUpdate | value | |
| nextUpdate | The date by which the next CRL is issued | |
|
type:UTCTime |
*The date by which the next CRL is issued | |
| authorityKeyIdentifier (extnId :== 2.5.29.35, critical :== FALSE) | value | |
| AuthorityKeyIdentifier | Authority Key Identifier | |
|
KeyIdentifier |
The identifier for public key | |
|
type:OCTET STRING |
62:A7:D2:DA:DE:85:B6:92:F1:85:BC:F6:E8:95:9D:75:A0:FA:4E:1F | |
| cRLNumber (extnId :== 2.5.29.20, critical :== FALSE) | value | |
| cRLNumber | CRL Number | |
|
type:INTEGER |
*Serial number of CRL | |
| revokedCertificates | value | |
| CertificateSerialNumber | Serial number of revoked certificate | |
|
type:INTEGER |
*Serial number of revoked certificate | |
| revocationDate | The date on which the revocation occurred | |
|
type:UTCTime |
*The date on which the revocation occurred | |
| invalidityDate (extnId :== 2.5.29.24, critical :== FALSE) | value | |
| invalidityDate | The date on which it is known or suspected that the certificate became invalid | |
|
type:GeneralizedTime |
*The date on which the revocation occurred of the certificate | |
| cRLReason (extnId :== 2.5.29.21, critical :== FALSE) | value | |
| CRLReason | The reason code for the certificate revocation | |
|
type:ENUMERATED |
*Value of reason code for the revocation | |