Prior to mid-2011, GlobalSign issued the following
OrganizationSSL Intermediate Root Certificate.
As server certificates are renewed, they must be changed to use the new OrganizationSSL certificate (technically, whatever certificate they chained to; but this certificate is likely to be used for a while yet). Currently no problems are known to arise if the old certificate is also left in the server's keychain. Servers still using old certificates must have that old certificate available.
Search: organizationSSLOld
Here is the actual old certificate.
Complete with comment expansion such as openssl x509 -text
would
provide.
Note that where this one says
Certificate: Data: Version: 3 (0x2) Serial Number: 04:00:00:00:00:01:1e:44:a5:f5:2a Signature Algorithm: sha1WithRSAEncryption Issuer: C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA Validity Not Before: Apr 11 12:00:00 2007 GMT Not After : Apr 11 12:00:00 2017 GMT Subject: OU=Organization Validation CA, O=GlobalSign, CN=GlobalSign Organization Validation CA Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public Key: (2048 bit) Modulus (2048 bit): 00:a1:2f:c4:bc:ce:87:03:e9:67:c1:89:c8:e5:93: fc:7d:b4:ad:9e:f6:63:4e:6a:e8:9c:2c:73:89:a2: 01:f4:8f:21:f8:fd:25:9d:58:16:6d:86:f6:ee:49: 57:75:7e:75:ea:22:11:7e:3d:fb:c7:42:41:dc:fc: c5:0c:91:55:80:7b:eb:64:33:1d:9b:f9:ca:38:e9: ab:c6:25:43:51:25:40:f4:e4:7e:18:55:6a:a9:8f: 10:3a:40:1e:d6:57:83:ef:7f:2f:34:2f:2d:d2:f6: 53:c2:19:0d:b7:ed:c9:81:f5:46:2c:b4:23:42:5e: 9d:13:03:75:ec:ea:6a:fc:57:7c:c9:36:97:3b:98: dc:13:13:ec:ec:41:fa:5d:34:ea:b9:93:e7:10:16: 65:cc:9c:92:fd:f5:c5:9d:3e:4a:b9:09:fc:e4:5f: 1e:69:5f:4d:f4:56:72:44:b1:1d:23:03:c8:36:f6: 65:88:c8:bf:39:16:45:8e:1e:26:6c:51:16:c5:2a: 00:38:c5:a4:13:69:95:7d:ab:01:3b:a8:c4:14:b4: 80:da:ac:1a:44:20:d5:fe:a9:06:7b:14:27:af:e0: 30:21:dd:90:f4:a9:d5:23:19:2e:1e:03:e6:c1:df: 95:29:e4:c1:94:43:dd:3e:90:aa:cb:4b:c9:be:8a: d3:39 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 X509v3 Subject Key Identifier: 7D:6D:2A:EC:66:AB:A7:51:36:AB:02:69:F1:70:8F:C4:59:0B:9A:1F X509v3 Certificate Policies: Policy: 1.3.6.1.4.1.4146.1.20 CPS: http://www.globalsign.net/repository/ X509v3 CRL Distribution Points: URI:http://crl.globalsign.net/root.crl Netscape Cert Type: SSL CA X509v3 Extended Key Usage: Microsoft Server Gated Crypto, Netscape Server Gated Crypto X509v3 Authority Key Identifier: keyid:60:7B:66:1A:45:0D:97:CA:89:50:2F:7D:04:CD:34:A8:FF:FC:FD:4B Signature Algorithm: sha1WithRSAEncryption 79:47:fc:15:d7:4c:79:df:0f:7a:9e:ce:d4:7c:4b:63:c9:89: b5:7b:3f:99:12:e8:9c:8c:9a:49:2f:e0:4e:95:4a:ed:c7:bc: be:f1:a2:db:8e:93:1d:ba:71:54:aa:4b:d9:89:22:24:87:c5: 04:a8:ac:82:52:a0:52:f8:b8:e1:4f:a1:27:66:63:21:4a:39: e7:c7:c5:4e:5f:b2:d6:1d:13:6d:30:e9:ce:d7:a2:1c:bc:29: 0a:73:3c:5b:23:49:fe:d6:ff:ca:b0:4f:f5:f2:67:98:c0:47: 11:f8:b7:48:a6:90:09:d6:42:be:ea:b1:b9:53:42:c3:9c:20: c9:fb:a1:5b:b5:56:6d:87:81:c8:60:ac:c4:b9:72:27:0a:8e: 1e:a8:b1:2e:cd:32:a2:78:57:b0:9c:f8:95:bb:43:8e:8c:31: 86:6e:53:0d:c6:12:05:ba:41:6e:a8:35:30:09:18:1d:02:61: ff:fd:ee:35:de:6a:c3:3b:d0:4d:4b:4e:50:b2:56:36:0c:44: 5d:da:1a:65:2a:e6:98:56:a9:63:33:2e:04:e7:ae:e8:f4:8e: b7:b2:da:7d:c0:c8:e2:ae:a6:28:2f:e3:c9:73:bd:fc:07:41: 34:b7:aa:6e:ee:a7:db:d1:93:3c:ed:90:ec:32:92:88:d9:c8: 23:6c:74:21 -----BEGIN CERTIFICATE----- MIIEZzCCA0+gAwIBAgILBAAAAAABHkSl9SowDQYJKoZIhvcNAQEFBQAwVzELMAkG A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw0wNzA0MTExMjAw MDBaFw0xNzA0MTExMjAwMDBaMGoxIzAhBgNVBAsTGk9yZ2FuaXphdGlvbiBWYWxp ZGF0aW9uIENBMRMwEQYDVQQKEwpHbG9iYWxTaWduMS4wLAYDVQQDEyVHbG9iYWxT aWduIE9yZ2FuaXphdGlvbiBWYWxpZGF0aW9uIENBMIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEAoS/EvM6HA+lnwYnI5ZP8fbStnvZjTmronCxziaIB9I8h +P0lnVgWbYb27klXdX516iIRfj37x0JB3PzFDJFVgHvrZDMdm/nKOOmrxiVDUSVA 9OR+GFVqqY8QOkAe1leD738vNC8t0vZTwhkNt+3JgfVGLLQjQl6dEwN17Opq/Fd8 yTaXO5jcExPs7EH6XTTquZPnEBZlzJyS/fXFnT5KuQn85F8eaV9N9FZyRLEdIwPI NvZliMi/ORZFjh4mbFEWxSoAOMWkE2mVfasBO6jEFLSA2qwaRCDV/qkGexQnr+Aw Id2Q9KnVIxkuHgPmwd+VKeTBlEPdPpCqy0vJvorTOQIDAQABo4IBHzCCARswDgYD VR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFH1tKuxm q6dRNqsCafFwj8RZC5ofMEsGA1UdIAREMEIwQAYJKwYBBAGgMgEUMDMwMQYIKwYB BQUHAgEWJWh0dHA6Ly93d3cuZ2xvYmFsc2lnbi5uZXQvcmVwb3NpdG9yeS8wMwYD VR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5nbG9iYWxzaWduLm5ldC9yb290LmNy bDARBglghkgBhvhCAQEEBAMCAgQwIAYDVR0lBBkwFwYKKwYBBAGCNwoDAwYJYIZI AYb4QgQBMB8GA1UdIwQYMBaAFGB7ZhpFDZfKiVAvfQTNNKj//P1LMA0GCSqGSIb3 DQEBBQUAA4IBAQB5R/wV10x53w96ns7UfEtjyYm1ez+ZEuicjJpJL+BOlUrtx7y+ 8aLbjpMdunFUqkvZiSIkh8UEqKyCUqBS+LjhT6EnZmMhSjnnx8VOX7LWHRNtMOnO 16IcvCkKczxbI0n+1v/KsE/18meYwEcR+LdIppAJ1kK+6rG5U0LDnCDJ+6FbtVZt h4HIYKzEuXInCo4eqLEuzTKieFewnPiVu0OOjDGGblMNxhIFukFuqDUwCRgdAmH/ /e413mrDO9BNS05QslY2DERd2hplKuaYVqljMy4E567o9I63stp9wMjirqYoL+PJ c738B0E0t6pu7qfb0ZM87ZDsMpKI2cgjbHQh -----END CERTIFICATE-----
-- AdrianPepper - 22 Jul 2011