GlobalSign OrganizationSSL Certificate (Obsolescent Version)

GlobalSign OrganizationSSL Intermediate Root Certificate (Obsolescent Version)

Prior to mid-2011, GlobalSign issued the following OrganizationSSL Intermediate Root Certificate.

As server certificates are renewed, they must be changed to use the new OrganizationSSL certificate (technically, whatever certificate they chained to; but this certificate is likely to be used for a while yet). Currently no problems are known to arise if the old certificate is also left in the server's keychain. Servers still using old certificates must have that old certificate available.


Perhaps See

Search: organizationSSLOld


Here is the actual old certificate. Complete with comment expansion such as openssl x509 -text would provide.

Note that where this one says

  • Subject: OU=Organization Validation CA, O=GlobalSign, CN=GlobalSign Organization Validation CA
the correct nww replacement (currently) says
  • Subject: C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - G2

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            04:00:00:00:00:01:1e:44:a5:f5:2a
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
        Validity
            Not Before: Apr 11 12:00:00 2007 GMT
            Not After : Apr 11 12:00:00 2017 GMT
        Subject: OU=Organization Validation CA, O=GlobalSign, CN=GlobalSign Organization Validation CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:a1:2f:c4:bc:ce:87:03:e9:67:c1:89:c8:e5:93:
                    fc:7d:b4:ad:9e:f6:63:4e:6a:e8:9c:2c:73:89:a2:
                    01:f4:8f:21:f8:fd:25:9d:58:16:6d:86:f6:ee:49:
                    57:75:7e:75:ea:22:11:7e:3d:fb:c7:42:41:dc:fc:
                    c5:0c:91:55:80:7b:eb:64:33:1d:9b:f9:ca:38:e9:
                    ab:c6:25:43:51:25:40:f4:e4:7e:18:55:6a:a9:8f:
                    10:3a:40:1e:d6:57:83:ef:7f:2f:34:2f:2d:d2:f6:
                    53:c2:19:0d:b7:ed:c9:81:f5:46:2c:b4:23:42:5e:
                    9d:13:03:75:ec:ea:6a:fc:57:7c:c9:36:97:3b:98:
                    dc:13:13:ec:ec:41:fa:5d:34:ea:b9:93:e7:10:16:
                    65:cc:9c:92:fd:f5:c5:9d:3e:4a:b9:09:fc:e4:5f:
                    1e:69:5f:4d:f4:56:72:44:b1:1d:23:03:c8:36:f6:
                    65:88:c8:bf:39:16:45:8e:1e:26:6c:51:16:c5:2a:
                    00:38:c5:a4:13:69:95:7d:ab:01:3b:a8:c4:14:b4:
                    80:da:ac:1a:44:20:d5:fe:a9:06:7b:14:27:af:e0:
                    30:21:dd:90:f4:a9:d5:23:19:2e:1e:03:e6:c1:df:
                    95:29:e4:c1:94:43:dd:3e:90:aa:cb:4b:c9:be:8a:
                    d3:39
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Subject Key Identifier: 
                7D:6D:2A:EC:66:AB:A7:51:36:AB:02:69:F1:70:8F:C4:59:0B:9A:1F
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.4146.1.20
                  CPS: http://www.globalsign.net/repository/

            X509v3 CRL Distribution Points: 
                URI:http://crl.globalsign.net/root.crl

            Netscape Cert Type: 
                SSL CA
            X509v3 Extended Key Usage: 
                Microsoft Server Gated Crypto, Netscape Server Gated Crypto
            X509v3 Authority Key Identifier: 
                keyid:60:7B:66:1A:45:0D:97:CA:89:50:2F:7D:04:CD:34:A8:FF:FC:FD:4B

    Signature Algorithm: sha1WithRSAEncryption
        79:47:fc:15:d7:4c:79:df:0f:7a:9e:ce:d4:7c:4b:63:c9:89:
        b5:7b:3f:99:12:e8:9c:8c:9a:49:2f:e0:4e:95:4a:ed:c7:bc:
        be:f1:a2:db:8e:93:1d:ba:71:54:aa:4b:d9:89:22:24:87:c5:
        04:a8:ac:82:52:a0:52:f8:b8:e1:4f:a1:27:66:63:21:4a:39:
        e7:c7:c5:4e:5f:b2:d6:1d:13:6d:30:e9:ce:d7:a2:1c:bc:29:
        0a:73:3c:5b:23:49:fe:d6:ff:ca:b0:4f:f5:f2:67:98:c0:47:
        11:f8:b7:48:a6:90:09:d6:42:be:ea:b1:b9:53:42:c3:9c:20:
        c9:fb:a1:5b:b5:56:6d:87:81:c8:60:ac:c4:b9:72:27:0a:8e:
        1e:a8:b1:2e:cd:32:a2:78:57:b0:9c:f8:95:bb:43:8e:8c:31:
        86:6e:53:0d:c6:12:05:ba:41:6e:a8:35:30:09:18:1d:02:61:
        ff:fd:ee:35:de:6a:c3:3b:d0:4d:4b:4e:50:b2:56:36:0c:44:
        5d:da:1a:65:2a:e6:98:56:a9:63:33:2e:04:e7:ae:e8:f4:8e:
        b7:b2:da:7d:c0:c8:e2:ae:a6:28:2f:e3:c9:73:bd:fc:07:41:
        34:b7:aa:6e:ee:a7:db:d1:93:3c:ed:90:ec:32:92:88:d9:c8:
        23:6c:74:21
-----BEGIN CERTIFICATE-----
MIIEZzCCA0+gAwIBAgILBAAAAAABHkSl9SowDQYJKoZIhvcNAQEFBQAwVzELMAkG
A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv
b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw0wNzA0MTExMjAw
MDBaFw0xNzA0MTExMjAwMDBaMGoxIzAhBgNVBAsTGk9yZ2FuaXphdGlvbiBWYWxp
ZGF0aW9uIENBMRMwEQYDVQQKEwpHbG9iYWxTaWduMS4wLAYDVQQDEyVHbG9iYWxT
aWduIE9yZ2FuaXphdGlvbiBWYWxpZGF0aW9uIENBMIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAoS/EvM6HA+lnwYnI5ZP8fbStnvZjTmronCxziaIB9I8h
+P0lnVgWbYb27klXdX516iIRfj37x0JB3PzFDJFVgHvrZDMdm/nKOOmrxiVDUSVA
9OR+GFVqqY8QOkAe1leD738vNC8t0vZTwhkNt+3JgfVGLLQjQl6dEwN17Opq/Fd8
yTaXO5jcExPs7EH6XTTquZPnEBZlzJyS/fXFnT5KuQn85F8eaV9N9FZyRLEdIwPI
NvZliMi/ORZFjh4mbFEWxSoAOMWkE2mVfasBO6jEFLSA2qwaRCDV/qkGexQnr+Aw
Id2Q9KnVIxkuHgPmwd+VKeTBlEPdPpCqy0vJvorTOQIDAQABo4IBHzCCARswDgYD
VR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFH1tKuxm
q6dRNqsCafFwj8RZC5ofMEsGA1UdIAREMEIwQAYJKwYBBAGgMgEUMDMwMQYIKwYB
BQUHAgEWJWh0dHA6Ly93d3cuZ2xvYmFsc2lnbi5uZXQvcmVwb3NpdG9yeS8wMwYD
VR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5nbG9iYWxzaWduLm5ldC9yb290LmNy
bDARBglghkgBhvhCAQEEBAMCAgQwIAYDVR0lBBkwFwYKKwYBBAGCNwoDAwYJYIZI
AYb4QgQBMB8GA1UdIwQYMBaAFGB7ZhpFDZfKiVAvfQTNNKj//P1LMA0GCSqGSIb3
DQEBBQUAA4IBAQB5R/wV10x53w96ns7UfEtjyYm1ez+ZEuicjJpJL+BOlUrtx7y+
8aLbjpMdunFUqkvZiSIkh8UEqKyCUqBS+LjhT6EnZmMhSjnnx8VOX7LWHRNtMOnO
16IcvCkKczxbI0n+1v/KsE/18meYwEcR+LdIppAJ1kK+6rG5U0LDnCDJ+6FbtVZt
h4HIYKzEuXInCo4eqLEuzTKieFewnPiVu0OOjDGGblMNxhIFukFuqDUwCRgdAmH/
/e413mrDO9BNS05QslY2DERd2hplKuaYVqljMy4E567o9I63stp9wMjirqYoL+PJ
c738B0E0t6pu7qfb0ZM87ZDsMpKI2cgjbHQh
-----END CERTIFICATE-----


-- AdrianPepper - 22 Jul 2011

Edit | Attach | Watch | Print version | History: r1 | Backlinks | Raw View | WYSIWYG | More topic actions
Topic revision: r1 - 2011-07-22 - AdrianPepper
 
This site is powered by the TWiki collaboration platform Powered by PerlCopyright © 2008-2024 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback