Output formats | Specifications | Real-Time SSL Certificate Chain Streaming | WhoisXML API

Output format

There are two types of text messages you can receive from the endpoint:

  • Error message: this message is a plain text and begins with "err:". After this message, the server closes the connection.
  • Data message: this message contains one or several domain records in the format defined below. Records are separated from each other by the newline character (“\n”). One message contains from 1 to 1000 records.
...
{
    "auditCreated": "2022-02-14 10:30:52 UTC",
    "domain": "nationaltoolbox.vg",
    "ip": "88.198.29.97",
    "port": 443,
    "certificates": [
        {
            "chainHierarchy": "end-user",
            "validationType": "self-signed-ca",
            "validFrom": "2016-03-17 07:37:40 UTC",
            "validTo": "2017-03-17 07:37:40 UTC",
            "serialNumber": "",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "LU",
                "organization": "domainerschoice",
                "organizationalUnit": "tech",
                "locality": "luxemburg",
                "province": "luxemburg",
                "commonName": "tc138.traffic.club"
            },
            "issuer": {
                "country": "LU",
                "organization": "domainerschoice",
                "organizationalUnit": "tech",
                "locality": "luxemburg",
                "province": "luxemburg",
                "commonName": "tc138.traffic.club"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIECTCCAvGgAwIBAgIBADANBgkqhkiG9w0BAQsFADCBnjEbMBkGA1UEAwwSdGMx\nMzgudHJhZmZpYy5jbHViMQswCQYDVQQGEwJMVTESMBAGA1UECAwJbHV4ZW1idXJn\nMRIwEAYDVQQHDAlsdXhlbWJ1cmcxGDAWBgNVBAoMD2RvbWFpbmVyc2Nob2ljZTEN\nMAsGA1UECwwEdGVjaDEhMB8GCSqGSIb3DQEJARYSdGMxMzhAdHJhZmZpYy5jbHVi\nMB4XDTE2MDMxNzA3Mzc0MFoXDTE3MDMxNzA3Mzc0MFowgZ4xGzAZBgNVBAMMEnRj\nMTM4LnRyYWZmaWMuY2x1YjELMAkGA1UEBhMCTFUxEjAQBgNVBAgMCWx1eGVtYnVy\nZzESMBAGA1UEBwwJbHV4ZW1idXJnMRgwFgYDVQQKDA9kb21haW5lcnNjaG9pY2Ux\nDTALBgNVBAsMBHRlY2gxITAfBgkqhkiG9w0BCQEWEnRjMTM4QHRyYWZmaWMuY2x1\nYjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMmwyz/RMLbTvgF1IQh9\nMYzYxdZCb/aRcDc1bpPrEkM2jNna6LquJe52xJey1o8zXk1DY4w/umJsPZk4NRxy\numYcCSt7nlM8dJ7Lyr6QUYiAGvVehgIrLd1Sr08GC5o/Wl4o6LNdUBrsrjMgFQSb\n0XULOckH9PUb4IXSRQhdlhGxwP9DozL91u1ffirgtBcZA1BS+yFyQ7xWC2I4p9Ez\nvMbecR3qTKN+ZR7Ww5kaFoxvcwOs8OpSZG20i87BxiZYlNgQXI0Ff1sjxVJHYqIf\nFUitzjsKqmnTRM0Zpc+Xu0Ld0lwPSsKKxyKcYI+sGVyHcQI7le4rzkgokxkpN1iV\n3tUCAwEAAaNQME4wHQYDVR0OBBYEFKLINE9tCtheFu3uhFwyvIro/iieMB8GA1Ud\nIwQYMBaAFKLINE9tCtheFu3uhFwyvIro/iieMAwGA1UdEwQFMAMBAf8wDQYJKoZI\nhvcNAQELBQADggEBAHefvRNpyT8IwGugAjfNkIURslD4jmv2q28gqkKRWsycP7i2\nE+HR73Qe3yyq4NME2bMzCcUxXoV3g601LF0oz6R58NArt7PxsgZSqMPwS7kyq1u7\nkUJsk4qnMMwW/mfvbUZ4EfxCVPe3KtUqILR7UVPJxPvyp1IEgXgp/E6ta304bSUj\nH3eaTX74sOnxghbE441Ptz6uo+p2Bws08xOn8Lw/8krb6Bb6f+Fq2I2n/m3KkFNF\n/9x77MSQi6F7XJopjYQLe4yctoEd4zJT4TDnyyV+FcNFzZwofIM8mDypCJHhdX77\nRYIUkG2I+TRe1cvOFfqIClia8YNF4jieidIqwA8=\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "A2:C8:34:4F:6D:0A:D8:5E:16:ED:EE:84:5C:32:BC:8A:E8:FE:28:9E",
                "subjectKeyIdentifier": "A2:C8:34:4F:6D:0A:D8:5E:16:ED:EE:84:5C:32:BC:8A:E8:FE:28:9E"
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAybDLP9EwttO+AXUhCH0x\njNjF1kJv9pFwNzVuk+sSQzaM2drouq4l7nbEl7LWjzNeTUNjjD+6Ymw9mTg1HHK6\nZhwJK3ueUzx0nsvKvpBRiIAa9V6GAist3VKvTwYLmj9aXijos11QGuyuMyAVBJvR\ndQs5yQf09RvghdJFCF2WEbHA/0OjMv3W7V9+KuC0FxkDUFL7IXJDvFYLYjin0TO8\nxt5xHepMo35lHtbDmRoWjG9zA6zw6lJkbbSLzsHGJliU2BBcjQV/WyPFUkdioh8V\nSK3OOwqqadNEzRmlz5e7Qt3SXA9KworHIpxgj6wZXIdxAjuV7ivOSCiTGSk3WJXe\n1QIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2010-02-18 00:00:00 UTC",
            "validTo": "2020-02-17 23:59:59 UTC",
            "serialNumber": "76:10:12:8A:17:B6:82:BB:3A:1F:9D:1A:9A:35:C0:92",
            "signatureAlgorithm": "SHA1-RSA",
            "subject": {
                "country": "US",
                "organization": "Thawte, Inc.",
                "organizationalUnit": "Domain Validated SSL",
                "commonName": "Thawte DV SSL CA"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIEjzCCA3egAwIBAgIQdhASihe2grs6H50amjXAkjANBgkqhkiG9w0BAQUFADCB\nqTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDYgdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxHzAdBgNV\nBAMTFnRoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EwHhcNMTAwMjE4MDAwMDAwWhcNMjAw\nMjE3MjM1OTU5WjBeMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMVGhhd3RlLCBJbmMu\nMR0wGwYDVQQLExREb21haW4gVmFsaWRhdGVkIFNTTDEZMBcGA1UEAxMQVGhhd3Rl\nIERWIFNTTCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMuYyTY/\n0pzYFgfUSWP5g7DoAi3MXFp0l6YT7xMT3gV8p+bKACPaOfnvE89Sxa+a48q+84LZ\niz2q4cyuiFBmoy3sYRR1SasOJPGsRFsLKKIzIHYeBmBqZwVxi7pmYhZ6s20Nx9CU\nQMaMPR6SDGI0DUSJ1feJ/intGI/2mysI92qr2EiXWvSf7Qx1UiL31V6EAJ/ASg0x\nd0xk0BLmDzrwocDVXB3nXy3C99Y2GNmVbkROyVgUTbaOu83eYh76W7W9GCuYrKyT\nP1Ba9RQLos+2855PWs1awzYj2hqvsE3WSiIDj0MCGb3qrN3EejUyFPFyLghVQAz0\nB0FBrzg3hClCslUCAwEAAaOB/DCB+TAyBggrBgEFBQcBAQQmMCQwIgYIKwYBBQUH\nMAGGFmh0dHA6Ly9vY3NwLnRoYXd0ZS5jb20wEgYDVR0TAQH/BAgwBgEB/wIBADA0\nBgNVHR8ELTArMCmgJ6AlhiNodHRwOi8vY3JsLnRoYXd0ZS5jb20vVGhhd3RlUENB\nLmNybDAOBgNVHQ8BAf8EBAMCAQYwKQYDVR0RBCIwIKQeMBwxGjAYBgNVBAMTEVZl\ncmlTaWduTVBLSS0yLTExMB0GA1UdDgQWBBSrRORd7IPH2cCFn/fhxpeQsIw/mDAf\nBgNVHSMEGDAWgBR7W0XPr87Lev0xkhpqtvNG61dIUDANBgkqhkiG9w0BAQUFAAOC\nAQEABLr7rLv8S1QRoy2Iszy9AG2KGraNxMGD+MdTKsEybjqBoVR92ho/OkVPNudC\nsApChZegrPvlh6eDT+ixt5tYZW4mgAuSTUdVuWEWUWXpK/Fo2Vi4A4HRt2Yc07zF\npntfPsU4RnbndbSgDEvOosKpwcw2c3v7uSQkoF6n9vq7DChDnh3wTvA/2CSwIdxt\nLe6/Wjv6iJx0bK8h3ZLswxXvlHUmRtamP79mSKod790n5rdRiTh9E4QMQPzQtfHg\n2/lPL0ActI5HImG4TJbe8F8Rfk8R2exQRyIOxR3iZEnnaGNFOorZcfRe8W63FE0+\nbxQe3FL+vN8MvSk/dvsRX2hoFQ==\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50",
                "subjectKeyIdentifier": "AB:44:E4:5D:EC:83:C7:D9:C0:85:9F:F7:E1:C6:97:90:B0:8C:3F:98",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://crl.thawte.com/ThawtePCA.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://ocsp.thawte.com"
                    ]
                }
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAy5jJNj/SnNgWB9RJY/mD\nsOgCLcxcWnSXphPvExPeBXyn5soAI9o5+e8Tz1LFr5rjyr7zgtmLParhzK6IUGaj\nLexhFHVJqw4k8axEWwsoojMgdh4GYGpnBXGLumZiFnqzbQ3H0JRAxow9HpIMYjQN\nRInV94n+Ke0Yj/abKwj3aqvYSJda9J/tDHVSIvfVXoQAn8BKDTF3TGTQEuYPOvCh\nwNVcHedfLcL31jYY2ZVuRE7JWBRNto67zd5iHvpbtb0YK5isrJM/UFr1FAuiz7bz\nnk9azVrDNiPaGq+wTdZKIgOPQwIZveqs3cR6NTIU8XIuCFVADPQHQUGvODeEKUKy\nVQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2013-10-31 00:00:00 UTC",
            "validTo": "2023-10-30 23:59:59 UTC",
            "serialNumber": "05:23:71:50:E6:7B:DD:38:F3:3E:F5:3C:D2:11:31:3F",
            "signatureAlgorithm": "SHA1-RSA",
            "subject": {
                "country": "US",
                "organization": "thawte, Inc.",
                "commonName": "thawte EV SSL CA - G2"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIErzCCA5egAwIBAgIQBSNxUOZ73TjzPvU80hExPzANBgkqhkiG9w0BAQUFADCB\nqTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDYgdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxHzAdBgNV\nBAMTFnRoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EwHhcNMTMxMDMxMDAwMDAwWhcNMjMx\nMDMwMjM1OTU5WjBEMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMdGhhd3RlLCBJbmMu\nMR4wHAYDVQQDExV0aGF3dGUgRVYgU1NMIENBIC0gRzIwggEiMA0GCSqGSIb3DQEB\nAQUAA4IBDwAwggEKAoIBAQC0OdfRaYVQLcLryGKXMjAXBPTxgJ42N0UuRJhZvWjc\nZaHMo4Q2+bopTFkef3zLozYK1Da8nWbuDeC0SeGgtuL2P4xph3HNNCR84gl7QH0X\nTx07r+2Inhz7AcoWJjoZxFp7MmTscPt2jMmiXx4vEo3SAAtnF/vcQXefw8rTLEQp\ndA0SVB4BqvsEhI4jxALF9R1x+99EwUkfiYL23J9SQlfKDiRv+f3guiGXNRp3vF1k\nCNkTDLpHe3PcZ9tqWNTboFpYsPStSGX+dJqPzWtfS04oQGSYZpKxz3LYxXYL3LzZ\nDr06D7ygFnKLjKOxAwKW9ilCkOrBwwtNvsJ9lFx5x/EhAgMBAAGjggE1MIIBMTAS\nBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBBjAvBggrBgEFBQcBAQQj\nMCEwHwYIKwYBBQUHMAGGE2h0dHA6Ly90Mi5zeW1jYi5jb20wOwYDVR0gBDQwMjAw\nBgRVHSAAMCgwJgYIKwYBBQUHAgEWGmh0dHBzOi8vd3d3LnRoYXd0ZS5jb20vY3Bz\nMDIGA1UdHwQrMCkwJ6AloCOGIWh0dHA6Ly90MS5zeW1jYi5jb20vVGhhd3RlUENB\nLmNybDApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRU3ltYW50ZWNQS0ktMS01MzUw\nHQYDVR0OBBYEFC40Iw1fwXqy30AvXuVWMOSapGyEMB8GA1UdIwQYMBaAFHtbRc+v\nzst6/TGSGmq280brV0hQMA0GCSqGSIb3DQEBBQUAA4IBAQCQB3H7nhipCm+K4gcT\n7XNGnYDGt4FNKRPF4SenZuZsnu9TcJRaQJOJdYZk5tuDLK7CF8t3nCJof7hdP9vW\nIyYJ/xYTSA+qQaGIP8DdyG0Ch/ysJ+LAK4Y6djQxXQS6rrqL2twRCw0SLz/tWoaH\nwlE2gkoMSeirqHgYBXEBJeoM4aljXLClHbM+GOJBqhSVgBnq0Kgfx1HAp/E3WZu8\nH+r0LaHtfmO+bHOotBGlRlTigl2WMPb0dKe2pr2a8Cb8YwbnHBqhpAztRr7G/QKo\naQKQ+m00ioV0ZuS8l3COYKYdDMTmqBOVQxrqFOE0nGr65yTPPJ7jBtE5YEoesvKU\ni4Ah\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50",
                "subjectKeyIdentifier": "2E:34:23:0D:5F:C1:7A:B2:DF:40:2F:5E:E5:56:30:E4:9A:A4:6C:84",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://t1.symcb.com/ThawtePCA.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://t2.symcb.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.5.29.32.0",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.thawte.com/cps"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtDnX0WmFUC3C68hilzIw\nFwT08YCeNjdFLkSYWb1o3GWhzKOENvm6KUxZHn98y6M2CtQ2vJ1m7g3gtEnhoLbi\n9j+MaYdxzTQkfOIJe0B9F08dO6/tiJ4c+wHKFiY6GcRaezJk7HD7dozJol8eLxKN\n0gALZxf73EF3n8PK0yxEKXQNElQeAar7BISOI8QCxfUdcfvfRMFJH4mC9tyfUkJX\nyg4kb/n94LohlzUad7xdZAjZEwy6R3tz3GfbaljU26BaWLD0rUhl/nSaj81rX0tO\nKEBkmGaSsc9y2MV2C9y82Q69Og+8oBZyi4yjsQMClvYpQpDqwcMLTb7CfZRcecfx\nIQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2010-02-08 00:00:00 UTC",
            "validTo": "2020-02-07 23:59:59 UTC",
            "serialNumber": "4D:5F:2C:34:08:B2:4C:20:CD:6D:50:7E:24:4D:C9:EC",
            "signatureAlgorithm": "SHA1-RSA",
            "subject": {
                "country": "US",
                "organization": "Thawte, Inc.",
                "commonName": "Thawte SSL CA"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIEbDCCA1SgAwIBAgIQTV8sNAiyTCDNbVB+JE3J7DANBgkqhkiG9w0BAQUFADCB\nqTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDYgdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxHzAdBgNV\nBAMTFnRoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EwHhcNMTAwMjA4MDAwMDAwWhcNMjAw\nMjA3MjM1OTU5WjA8MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMVGhhd3RlLCBJbmMu\nMRYwFAYDVQQDEw1UaGF3dGUgU1NMIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A\nMIIBCgKCAQEAmeSFW3ZJfS8F2MWsyMip09yY5tc0pi8M8iIm2KPJFEyPBaRF6BQM\nWJAFGrfFwQalgK+7HUlrUjSIw1nn72vEJ0GMK2Yd0OCjl5gZNEtB1ZjVxwWtouTX\n7QytT8G1sCH9PlBTssSQ0NQwZ2ya8Q50xMLciuiX/8mSrgGKVgqYMrAAI+yQGmDD\n7bs6yw9jnw1EyVLhJZa/7VCViX9WFLG3YR0cB4w6LPf/gN45RdWvGtF42MdxaqMZ\npzJQIenyDqHGEwNESNFmqFJX1xG0k4vlmZ9d53hR5U32t1m0drUJN00GOBN6HAiY\nXMRISstSoKn4sZ2Oe3mwIC88lqgRYke7EQIDAQABo4H7MIH4MDIGCCsGAQUFBwEB\nBCYwJDAiBggrBgEFBQcwAYYWaHR0cDovL29jc3AudGhhd3RlLmNvbTASBgNVHRMB\nAf8ECDAGAQH/AgEAMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwudGhhd3Rl\nLmNvbS9UaGF3dGVQQ0EuY3JsMA4GA1UdDwEB/wQEAwIBBjAoBgNVHREEITAfpB0w\nGzEZMBcGA1UEAxMQVmVyaVNpZ25NUEtJLTItOTAdBgNVHQ4EFgQUp6KDuzRFQD38\n1TBPErk+oQGf9tswHwYDVR0jBBgwFoAUe1tFz6/Oy3r9MZIaarbzRutXSFAwDQYJ\nKoZIhvcNAQEFBQADggEBAIAigOBsyJUW11cmh/NyNNvGclYnPtOW9i4lkaU+M5en\nS+Uv+yV9Lwdh+m+DdExMU3IgpHrPUVFWgYiwbR82LMgrsYiZwf5Eq0hRfNjyRGQq\n2HGn+xov+RmNNLIjv8RMVR2OROiqXZrdn/0Dx7okQ40tR0Tb9tiYyLL52u/tKVxp\nEvrRI5YPv5wN8nlFUzeaVi/oVxBw9u6JDEmJmsEj9cIqzEHPIqtlbreUgm0vQF9Y\n3uuVK6ZyaFIZkSqudZ1OkubK3lTqGKslPOZkpnkfJn1h7X3S5XFV2JMXfBQ4MDzf\nhuNMrUnjl1nOG5srztxl1Asoa06ERlFE9zMILViXIa4=\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50",
                "subjectKeyIdentifier": "A7:A2:83:BB:34:45:40:3D:FC:D5:30:4F:12:B9:3E:A1:01:9F:F6:DB",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://crl.thawte.com/ThawtePCA.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://ocsp.thawte.com"
                    ]
                }
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmeSFW3ZJfS8F2MWsyMip\n09yY5tc0pi8M8iIm2KPJFEyPBaRF6BQMWJAFGrfFwQalgK+7HUlrUjSIw1nn72vE\nJ0GMK2Yd0OCjl5gZNEtB1ZjVxwWtouTX7QytT8G1sCH9PlBTssSQ0NQwZ2ya8Q50\nxMLciuiX/8mSrgGKVgqYMrAAI+yQGmDD7bs6yw9jnw1EyVLhJZa/7VCViX9WFLG3\nYR0cB4w6LPf/gN45RdWvGtF42MdxaqMZpzJQIenyDqHGEwNESNFmqFJX1xG0k4vl\nmZ9d53hR5U32t1m0drUJN00GOBN6HAiYXMRISstSoKn4sZ2Oe3mwIC88lqgRYke7\nEQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2010-02-08 00:00:00 UTC",
            "validTo": "2020-02-07 23:59:59 UTC",
            "serialNumber": "47:97:4D:78:73:A5:BC:AB:0D:2F:B3:70:19:2F:CE:5E",
            "signatureAlgorithm": "SHA1-RSA",
            "subject": {
                "country": "US",
                "organization": "Thawte, Inc.",
                "commonName": "Thawte Code Signing CA - G2"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIEnDCCA4SgAwIBAgIQR5dNeHOlvKsNL7NwGS/OXjANBgkqhkiG9w0BAQUFADCB\nqTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDYgdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxHzAdBgNV\nBAMTFnRoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EwHhcNMTAwMjA4MDAwMDAwWhcNMjAw\nMjA3MjM1OTU5WjBKMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMVGhhd3RlLCBJbmMu\nMSQwIgYDVQQDExtUaGF3dGUgQ29kZSBTaWduaW5nIENBIC0gRzIwggEiMA0GCSqG\nSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC3i891W58l2n45sJPbONOpI9CC+ukkflwL\njoP45npZ5qPFmKeZ0kT/AKalOQSK2imI6tui8xyZFSbCsfT84QxHqQkRBgogkrnH\noASMXJQZq1slLB1ifnANzmFs3SuCyc5dSF/3wr68QSMeTyld10+89MUq/GPmfCZO\nmad5QZ4QSnp5ycaG94aV0ibOPBgq1nzOr82tu/eCLHAmN0XlD0cixgEovS6DXGqk\nR8Hn0NhrgUY/IRf1B8VDWqZnLLh7YBG1g+71dApycUQ9WP7oGqs4w1nbf244fXbH\ncmmYNpZX02Yc0lSRBC5UGbDcPbUiXobVKn4g313merFl/sUCTjEtAgMBAAGjggEc\nMIIBGDASBgNVHRMBAf8ECDAGAQH/AgEAMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6\nLy9jcmwudGhhd3RlLmNvbS9UaGF3dGVQQ0EuY3JsMA4GA1UdDwEB/wQEAwIBBjAy\nBggrBgEFBQcBAQQmMCQwIgYIKwYBBQUHMAGGFmh0dHA6Ly9vY3NwLnRoYXd0ZS5j\nb20wHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMDMCkGA1UdEQQiMCCkHjAc\nMRowGAYDVQQDExFWZXJpU2lnbk1QS0ktMi0xMDAdBgNVHQ4EFgQU1A1lP3q9NMb+\nR+dMDcC98t4Vq3EwHwYDVR0jBBgwFoAUe1tFz6/Oy3r9MZIaarbzRutXSFAwDQYJ\nKoZIhvcNAQEFBQADggEBAFb+U1zhx568p+1+U21qFEtRjEBegF+qpOgv7zjIBMnK\nPs/fOlhOsNS2Y8UpV/oCBZpFTWjbKhvUND2fAMNay5VJpW7hsMX8QU1BSm/Td8jX\nOI3kGd4Y8x8VZYNtRQxT+QqaLqVdv28ygRiSGWpVAK1jHFIGflXZKWiuSnwYmnmI\nayMj2Cc4KimHdsr7x7ZiIx/telZM3ZwyW/U9DEYYlTsqI2iDZEHZAG0PGSQVaHK9\nxXFnbqxM25DrUaUaYgfQvmoARzxyL+xPYT5zhc5aCre6wBwTdeMiOSjdbR0JRp1P\nuuhAgZHGpM6UchsBzypuFWeVia59t7fN+Qo9dbZrPCU=\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50",
                "subjectKeyIdentifier": "D4:0D:65:3F:7A:BD:34:C6:FE:47:E7:4C:0D:C0:BD:F2:DE:15:AB:71",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "extendedKeyUsage": [
                    "Client Authentication",
                    "Code Signing"
                ],
                "crlDistributionPoints": [
                    "http://crl.thawte.com/ThawtePCA.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://ocsp.thawte.com"
                    ]
                }
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt4vPdVufJdp+ObCT2zjT\nqSPQgvrpJH5cC46D+OZ6WeajxZinmdJE/wCmpTkEitopiOrbovMcmRUmwrH0/OEM\nR6kJEQYKIJK5x6AEjFyUGatbJSwdYn5wDc5hbN0rgsnOXUhf98K+vEEjHk8pXddP\nvPTFKvxj5nwmTpmneUGeEEp6ecnGhveGldImzjwYKtZ8zq/Nrbv3gixwJjdF5Q9H\nIsYBKL0ug1xqpEfB59DYa4FGPyEX9QfFQ1qmZyy4e2ARtYPu9XQKcnFEPVj+6Bqr\nOMNZ239uOH12x3JpmDaWV9NmHNJUkQQuVBmw3D21Il6G1Sp+IN9d5nqxZf7FAk4x\nLQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2014-06-10 00:00:00 UTC",
            "validTo": "2024-06-09 23:59:59 UTC",
            "serialNumber": "2C:69:E1:2F:6A:67:0B:D9:9D:D2:0F:91:9E:F0:9E:51",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Domain Validated SSL",
                "commonName": "thawte DV SSL CA - G2"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIE0jCCA7qgAwIBAgIQLGnhL2pnC9md0g+RnvCeUTANBgkqhkiG9w0BAQsFADCB\nqTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDYgdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxHzAdBgNV\nBAMTFnRoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EwHhcNMTQwNjEwMDAwMDAwWhcNMjQw\nNjA5MjM1OTU5WjBjMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMdGhhd3RlLCBJbmMu\nMR0wGwYDVQQLExREb21haW4gVmFsaWRhdGVkIFNTTDEeMBwGA1UEAxMVdGhhd3Rl\nIERWIFNTTCBDQSAtIEcyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA\n6pQHhchBLPaDEmySX6sfANSWb3TNLhHpbA85AblIkEA5TcSiyHlqpZq9kURld1St\n/yVf7kL7swIP6l163RpUntdzQpvMeV/FTfS3Cxg5IHrdUAFdNEVfTBEO9YcmJrSw\n835xoDFxUIloWmOKFGLljDoWVQ0+66qAHXF644cHq72idM3aCAGdG8wniIxH1Gkl\nQta7UG2FUNBIgg0In+kj40LGPJi4u27FcBPfGR0B/dK1TuZi9Af6a30Rd8RiT0BO\npXiXqyxNDKd8w8RQMp/QcJsP//91WTSFrUnVNe5PW9TUNpWgfujFoRy9E0597mNq\nlhmZyKcqAOZRjUbrMFjoLQIDAQABo4IBOTCCATUwEgYDVR0TAQH/BAgwBgEB/wIB\nADBBBgNVHSAEOjA4MDYGCmCGSAGG+EUBBzYwKDAmBggrBgEFBQcCARYaaHR0cHM6\nLy93d3cudGhhd3RlLmNvbS9jcHMwDgYDVR0PAQH/BAQDAgEGMC4GCCsGAQUFBwEB\nBCIwIDAeBggrBgEFBQcwAYYSaHR0cDovL3Quc3ltY2QuY29tMDEGA1UdHwQqMCgw\nJqAkoCKGIGh0dHA6Ly90LnN5bWNiLmNvbS9UaGF3dGVQQ0EuY3JsMCkGA1UdEQQi\nMCCkHjAcMRowGAYDVQQDExFTeW1hbnRlY1BLSS0xLTY5ODAdBgNVHQ4EFgQUn7jB\nqWzy9cAiKpTtXJms1OzXxgcwHwYDVR0jBBgwFoAUe1tFz6/Oy3r9MZIaarbzRutX\nSFAwDQYJKoZIhvcNAQELBQADggEBAFNU8keoAtfvqjV4vkoIDZAYS22eKlMr6VQX\nd3QpftA3BwW45Pq4tGOYRNzGT4EGjDq+xzBXxnD81pMZn8NV1z4fcoqdMFo1lzLL\nY+TGct/7aMppL9vNUDg+K7urO4LH/UubvXxBmO8BU9g1jyXJAwbmnFfBUQ+e9n2T\nTfh2yDpr9MSPMzJ/nSGENNmn+ZL6QZFhhAWdo3lGzmfngfJerEy8qKtqbRXinE5a\n2WOAvPdC65pExoxrBja0izKJ3sLxqCaqqaz/6nGm54xB+hc1u7OHMamTwshY4QpO\nlYOcue07pe8I4HT5wxvmB6PuB9dCInkhoKHUHSbT0NamXStBwHk=\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50",
                "subjectKeyIdentifier": "9F:B8:C1:A9:6C:F2:F5:C0:22:2A:94:ED:5C:99:AC:D4:EC:D7:C6:07",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://t.symcb.com/ThawtePCA.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://t.symcd.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.16.840.1.113733.1.7.54",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.thawte.com/cps"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6pQHhchBLPaDEmySX6sf\nANSWb3TNLhHpbA85AblIkEA5TcSiyHlqpZq9kURld1St/yVf7kL7swIP6l163RpU\nntdzQpvMeV/FTfS3Cxg5IHrdUAFdNEVfTBEO9YcmJrSw835xoDFxUIloWmOKFGLl\njDoWVQ0+66qAHXF644cHq72idM3aCAGdG8wniIxH1GklQta7UG2FUNBIgg0In+kj\n40LGPJi4u27FcBPfGR0B/dK1TuZi9Af6a30Rd8RiT0BOpXiXqyxNDKd8w8RQMp/Q\ncJsP//91WTSFrUnVNe5PW9TUNpWgfujFoRy9E0597mNqlhmZyKcqAOZRjUbrMFjo\nLQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2013-10-31 00:00:00 UTC",
            "validTo": "2023-10-30 23:59:59 UTC",
            "serialNumber": "5D:72:FB:33:76:20:F6:4C:72:80:DB:E9:12:81:FF:6A",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "thawte, Inc.",
                "commonName": "thawte EV SSL CA - G3"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIErzCCA5egAwIBAgIQXXL7M3Yg9kxygNvpEoH/ajANBgkqhkiG9w0BAQsFADCB\nqTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDYgdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxHzAdBgNV\nBAMTFnRoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EwHhcNMTMxMDMxMDAwMDAwWhcNMjMx\nMDMwMjM1OTU5WjBEMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMdGhhd3RlLCBJbmMu\nMR4wHAYDVQQDExV0aGF3dGUgRVYgU1NMIENBIC0gRzMwggEiMA0GCSqGSIb3DQEB\nAQUAA4IBDwAwggEKAoIBAQDE3dqUHjKyLqCDwKZ9X2Ut/Se4cw74C6nUViZpmGc1\nOWRYzoJvmJTRj+CQ1u1VS5hL1xBZNAIb51ExUcQ4wrzbA1zK4XzcT1mX6gd/D4U+\nkuqqp9m+AUHkYlZHNr1XkeYh0/hBC9i66O2BrXDAi27ziW4nnqamc1m7cQDUT0tI\n6dXJJzacfBwCqqy9O9FTg2of5ghHM6exnwK+m0ftMwTcHIAn0UozoIzrAUehMpBk\ne8TghMky6d00H4poZ/OtEGPr7oqasSobJnShKrCP/lKYRpfPo1Ycb26Zl40mDqns\nwlNw/HqlGUm9tReCVd6X4F1ihIHwcKg0U08U/T1dPW+5AgMBAAGjggE1MIIBMTAS\nBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBBjAvBggrBgEFBQcBAQQj\nMCEwHwYIKwYBBQUHMAGGE2h0dHA6Ly90Mi5zeW1jYi5jb20wOwYDVR0gBDQwMjAw\nBgRVHSAAMCgwJgYIKwYBBQUHAgEWGmh0dHBzOi8vd3d3LnRoYXd0ZS5jb20vY3Bz\nMDIGA1UdHwQrMCkwJ6AloCOGIWh0dHA6Ly90MS5zeW1jYi5jb20vVGhhd3RlUENB\nLmNybDApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRU3ltYW50ZWNQS0ktMS01MzYw\nHQYDVR0OBBYEFPBwUdrTKpFPUnfXhnd0D85xGmwiMB8GA1UdIwQYMBaAFHtbRc+v\nzst6/TGSGmq280brV0hQMA0GCSqGSIb3DQEBCwUAA4IBAQChLpQ+mxb0WBpvwfrB\nfkOTssP3iesTYl3dzGETKx1OiHkRYhQ3MEb/iWIQhSqHHvjir/6TApPK8ulGA2uh\nGqzV8IAbmG+4OlD4VHEGA+eEzI5h0l9NDJcCZbWMJrwFmPTcxq/kV3/j3KHXJ0cq\n4Cw/CXTcWuW1fPqCmhX6dCuELmus7zWmMPpHSqo2RPZakQfT5E6XP6ZT2CkzMm+L\nPbWlDeXkiuj1wPqv2DcoJ8PtNDHZfKavTRJP0CuSnGmV8iim/qjG4CxNNusRNNbh\ngZmdQfLnxVcFDhnKr0I5H6cnXuAKF7iuR6uS8YoE3zDgu0+K+RuITwO0JXp43i59\nKdEx\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50",
                "subjectKeyIdentifier": "F0:70:51:DA:D3:2A:91:4F:52:77:D7:86:77:74:0F:CE:71:1A:6C:22",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://t1.symcb.com/ThawtePCA.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://t2.symcb.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.5.29.32.0",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.thawte.com/cps"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxN3alB4ysi6gg8CmfV9l\nLf0nuHMO+Aup1FYmaZhnNTlkWM6Cb5iU0Y/gkNbtVUuYS9cQWTQCG+dRMVHEOMK8\n2wNcyuF83E9Zl+oHfw+FPpLqqqfZvgFB5GJWRza9V5HmIdP4QQvYuujtga1wwItu\n84luJ56mpnNZu3EA1E9LSOnVySc2nHwcAqqsvTvRU4NqH+YIRzOnsZ8CvptH7TME\n3ByAJ9FKM6CM6wFHoTKQZHvE4ITJMundNB+KaGfzrRBj6+6KmrEqGyZ0oSqwj/5S\nmEaXz6NWHG9umZeNJg6p7MJTcPx6pRlJvbUXglXel+BdYoSB8HCoNFNPFP09XT1v\nuQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2013-10-31 00:00:00 UTC",
            "validTo": "2023-10-30 23:59:59 UTC",
            "serialNumber": "16:87:D6:88:6D:E2:30:06:85:23:3D:BF:11:BF:65:97",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "thawte, Inc.",
                "commonName": "thawte SSL CA - G2"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIEsjCCA5qgAwIBAgIQFofWiG3iMAaFIz2/Eb9llzANBgkqhkiG9w0BAQsFADCB\nqTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDYgdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxHzAdBgNV\nBAMTFnRoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EwHhcNMTMxMDMxMDAwMDAwWhcNMjMx\nMDMwMjM1OTU5WjBBMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMdGhhd3RlLCBJbmMu\nMRswGQYDVQQDExJ0aGF3dGUgU1NMIENBIC0gRzIwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEKAoIBAQCy/Ab7BJPS6lkgO0SFl1I55xDweuCwlEDaRvgMKLu5zmA4\nP9LYEUIbka1J7o/H3mzeN2/9iyA8bed009zVJIhBgInuNr7E1b6NUxOq5KW4kwq+\n7NrNPNQyVu/QTqC4l7s5UB5uZcP9ss7gWalICcb+vq78PjuBIJeLj0bfYGQHdbsb\nhjifR3s0zqHRl6122J+3Jtt5gDZI8sU3+NkyrnykU4HHmaFUOC9PdaC7WqW7zawC\nWxkC1RMYp86sdFUSBYubopVGZHI4zVobOhanvnGZjFQDuJZsAdM+Bpg/IYE7An4A\nR1MBHg5GQ/tLLdwLGugvmPh+0ZmrE2ykF95v9hX1AgMBAAGjggE7MIIBNzASBgNV\nHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBBjAyBgNVHR8EKzApMCegJaAj\nhiFodHRwOi8vdDEuc3ltY2IuY29tL1RoYXd0ZVBDQS5jcmwwLwYIKwYBBQUHAQEE\nIzAhMB8GCCsGAQUFBzABhhNodHRwOi8vdDIuc3ltY2IuY29tMEEGA1UdIAQ6MDgw\nNgYKYIZIAYb4RQEHNjAoMCYGCCsGAQUFBwIBFhpodHRwczovL3d3dy50aGF3dGUu\nY29tL2NwczApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRU3ltYW50ZWNQS0ktMS01\nMzcwHQYDVR0OBBYEFMJPSFf80U+awF04fQ4F29kutVJgMB8GA1UdIwQYMBaAFHtb\nRc+vzst6/TGSGmq280brV0hQMA0GCSqGSIb3DQEBCwUAA4IBAQCNBt5DyXYCytkj\nl17zY9d9RMIPawr1B+WLuPrgo/prgJK1AyzFN+DC5ZW1knAYKEKU7kt3agEPiyPs\nVk30AGnlhMji6t5bPvY8BzqUymwnscyDGmBxJ9K/AvUeRNNI1abTdiEAnPqYZOsX\nNj/rGzw+prHZWAYOctlovvGnINdS5KR3H3FwnVU1hTfhHU2UwnB/lUBuS32ytCkq\nA3nIuUxnYQSgiyf/WQDrVX/GtzM1LV5OrLjqEsXo97mrvnSSLLfZTcqELxzC8HJ8\nsjFuz4DliAc2UXu6Ya9tjSNbNKOVvKIxf/L157fo78S1JzLp955pxyvovrsMqufq\nYBLqJop4\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50",
                "subjectKeyIdentifier": "C2:4F:48:57:FC:D1:4F:9A:C0:5D:38:7D:0E:05:DB:D9:2E:B5:52:60",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://t1.symcb.com/ThawtePCA.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://t2.symcb.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.16.840.1.113733.1.7.54",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.thawte.com/cps"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsvwG+wST0upZIDtEhZdS\nOecQ8HrgsJRA2kb4DCi7uc5gOD/S2BFCG5GtSe6Px95s3jdv/YsgPG3ndNPc1SSI\nQYCJ7ja+xNW+jVMTquSluJMKvuzazTzUMlbv0E6guJe7OVAebmXD/bLO4FmpSAnG\n/r6u/D47gSCXi49G32BkB3W7G4Y4n0d7NM6h0ZetdtiftybbeYA2SPLFN/jZMq58\npFOBx5mhVDgvT3Wgu1qlu82sAlsZAtUTGKfOrHRVEgWLm6KVRmRyOM1aGzoWp75x\nmYxUA7iWbAHTPgaYPyGBOwJ+AEdTAR4ORkP7Sy3cCxroL5j4ftGZqxNspBfeb/YV\n9QIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2014-06-10 00:00:00 UTC",
            "validTo": "2024-06-09 23:59:59 UTC",
            "serialNumber": "3E:23:34:5A:ED:2C:0A:51:7B:26:DE:D4:80:1D:10:AA",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Domain Validated SSL",
                "commonName": "thawte DV SSL SHA256 CA"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA - G3"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIE3DCCA8SgAwIBAgIQPiM0Wu0sClF7Jt7UgB0QqjANBgkqhkiG9w0BAQsFADCB\nrjELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDggdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxJDAiBgNV\nBAMTG3RoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EgLSBHMzAeFw0xNDA2MTAwMDAwMDBa\nFw0yNDA2MDkyMzU5NTlaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwx0aGF3dGUs\nIEluYy4xHTAbBgNVBAsTFERvbWFpbiBWYWxpZGF0ZWQgU1NMMSAwHgYDVQQDExd0\naGF3dGUgRFYgU1NMIFNIQTI1NiBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC\nAQoCggEBALOsDX+tuxNNlF9nQmrQiXGp7XQEkyTITVah8JGWhNmEas9SIeMasVRM\n5saenks4qZZUHfWz7ZIE0G5UkG4v6X2YtIotEqO0Qkcdf19A4fx/kaYB3FWkUHgq\nYz+EfizIKyG2xg5evLix1BuYs8b44ego7TJEG8t/9+SxEevGCLBb7qjC7Eaqjynf\nubekA6A1elg/iylHwdIi+izGx2zN0/dYMpOU0W+pKpwPCiiSqxQKtt/tQHpkB1TO\n6nWXMrmWoHXJdzECdK9Ud0+ZooFLeVm4kj/5B+pCdFcuNexVivxhPD5XcZI7q+TB\n4RcsZDYAhLV8Gn2wQTN8I/ZOd1oswUsCAwEAAaOCATwwggE4MC4GCCsGAQUFBwEB\nBCIwIDAeBggrBgEFBQcwAYYSaHR0cDovL3Quc3ltY2QuY29tMBIGA1UdEwEB/wQI\nMAYBAf8CAQAwQQYDVR0gBDowODA2BgpghkgBhvhFAQc2MCgwJgYIKwYBBQUHAgEW\nGmh0dHBzOi8vd3d3LnRoYXd0ZS5jb20vY3BzMDQGA1UdHwQtMCswKaAnoCWGI2h0\ndHA6Ly90LnN5bWNiLmNvbS9UaGF3dGVQQ0EtRzMuY3JsMA4GA1UdDwEB/wQEAwIB\nBjApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRU3ltYW50ZWNQS0ktMS02OTUwHQYD\nVR0OBBYEFH0pMS/BHm6uMQVqs+sczandroCaMB8GA1UdIwQYMBaAFK1sqpRgnO3k\n//o+CnQrYwP3tlm/MA0GCSqGSIb3DQEBCwUAA4IBAQA2/6LxHH65UXuU01p7SCXT\nN6KCKi1fOB6HZ+zJMavXkjO4vTXKsYBwBIJ8iMw3LhZ0bpNAY8qNe/8HKOb5M6vw\nYY09yoPFUNi9aTkfrry37hXFjQQGIDMoBJnFnBH1AQ9HXtiJmaXOwoD+Rvrvthuo\nkbKDs+JXDRrkltW8971tA/hifuv4Qgn+CWSkyVy40jkLeQKeFTkdwNnNHF9odo3z\nHi36v6dJog2X9ZbC6WzUzUcLi4oBi9v6z5J1Lt4+p3O1/gNRp0LDx0JrqW++9iDh\njr+fCY7lCOiSk3c+SUScf+l5nf9Lr+A4VzQNXxEyEpKpYYiBpR74oPBFWoZxIIWF\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "AD:6C:AA:94:60:9C:ED:E4:FF:FA:3E:0A:74:2B:63:03:F7:B6:59:BF",
                "subjectKeyIdentifier": "7D:29:31:2F:C1:1E:6E:AE:31:05:6A:B3:EB:1C:CD:A9:DD:AE:80:9A",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://t.symcb.com/ThawtePCA-G3.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://t.symcd.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.16.840.1.113733.1.7.54",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.thawte.com/cps"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs6wNf627E02UX2dCatCJ\ncantdASTJMhNVqHwkZaE2YRqz1Ih4xqxVEzmxp6eSzipllQd9bPtkgTQblSQbi/p\nfZi0ii0So7RCRx1/X0Dh/H+RpgHcVaRQeCpjP4R+LMgrIbbGDl68uLHUG5izxvjh\n6CjtMkQby3/35LER68YIsFvuqMLsRqqPKd+5t6QDoDV6WD+LKUfB0iL6LMbHbM3T\n91gyk5TRb6kqnA8KKJKrFAq23+1AemQHVM7qdZcyuZagdcl3MQJ0r1R3T5migUt5\nWbiSP/kH6kJ0Vy417FWK/GE8Pldxkjur5MHhFyxkNgCEtXwafbBBM3wj9k53WizB\nSwIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2013-04-09 00:00:00 UTC",
            "validTo": "2023-04-08 23:59:59 UTC",
            "serialNumber": "0A:48:9E:88:53:7E:8A:A6:45:4D:6E:2C:4B:2A:EB:20",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "thawte, Inc.",
                "commonName": "thawte Extended Validation SHA256 SSL CA"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA - G3"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIE0DCCA7igAwIBAgIQCkieiFN+iqZFTW4sSyrrIDANBgkqhkiG9w0BAQsFADCB\nrjELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDggdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxJDAiBgNV\nBAMTG3RoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EgLSBHMzAeFw0xMzA0MDkwMDAwMDBa\nFw0yMzA0MDgyMzU5NTlaMFcxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwx0aGF3dGUs\nIEluYy4xMTAvBgNVBAMTKHRoYXd0ZSBFeHRlbmRlZCBWYWxpZGF0aW9uIFNIQTI1\nNiBTU0wgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDyxLx06CX2\nAGIo40zouN8Tn4sHN+9iSvFXCfaC6HXwCqknz5M77DaJpW4d1lTzuASXcrRpJczR\nQg5b1Rx/omBusVIa25MvuwsNZFMWyxwJJJUpIrSKGACJ/vcfcsjoXC8aG6IYuO8Y\nXMu12zpO2w+u38R54x6qXKOk5axhmzeFj0h1G7nVaJbpJ3lwVyMau2yTkMdF1xfS\nNyp2s82CqU/AA3vhPXp+W7iF8vUV+3CpvfVQZRad47ZrYW6hep7oDRz3Ko5pfkMw\njnjO7mUeO5uHHkkc+DJGXShGeSpOJ10XWKg3/qgTqWkV3zYiiXW6ygFALu2d1wyq\nMc4nrlfV0lH7AgMBAAGjggE+MIIBOjASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1Ud\nDwEB/wQEAwIBBjAyBggrBgEFBQcBAQQmMCQwIgYIKwYBBQUHMAGGFmh0dHA6Ly9v\nY3NwLnRoYXd0ZS5jb20wOwYDVR0gBDQwMjAwBgRVHSAAMCgwJgYIKwYBBQUHAgEW\nGmh0dHBzOi8vd3d3LnRoYXd0ZS5jb20vY3BzMDcGA1UdHwQwMC4wLKAqoCiGJmh0\ndHA6Ly9jcmwudGhhd3RlLmNvbS9UaGF3dGVQQ0EtRzMuY3JsMCoGA1UdEQQjMCGk\nHzAdMRswGQYDVQQDExJWZXJpU2lnbk1QS0ktMi0zNzQwHQYDVR0OBBYEFDskyDGg\nt1rQarjSygd0zB4k1MTcMB8GA1UdIwQYMBaAFK1sqpRgnO3k//o+CnQrYwP3tlm/\nMA0GCSqGSIb3DQEBCwUAA4IBAQBomCaq1DPJunVw1J9JrdbBVNzuqlYfeKfwoaTu\nC/kSr9+muO7DyzUTalkq+MnpTC+8sbwrwgIw4cO+wvCBjJl3iVgAo8x/owJMU7Ju\nNk/+34d2sz/sWmJQtgBFWPKHrHfm0CBQY8XksnAVGJAFe3uvK0a+a04fU/yEJ66D\n0o1HU6cOH2O1utsW2GoJJVV9jz1KwYP5s7mnBFrI8xEEkVMw2VKHyzkAnOxTwwIJ\nfqc2jnIhLyO7TMZHpaHuZ8QvXDpHOGHiwx43kp7IL2v679LDzSmNmPhSF+21Uzzf\nr8kbYq3fAu5dNPZBS8vDVa+xy9qcc9UCqC2nrPzh5QfQUeg1\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "AD:6C:AA:94:60:9C:ED:E4:FF:FA:3E:0A:74:2B:63:03:F7:B6:59:BF",
                "subjectKeyIdentifier": "3B:24:C8:31:A0:B7:5A:D0:6A:B8:D2:CA:07:74:CC:1E:24:D4:C4:DC",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://crl.thawte.com/ThawtePCA-G3.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://ocsp.thawte.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.5.29.32.0",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.thawte.com/cps"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8sS8dOgl9gBiKONM6Ljf\nE5+LBzfvYkrxVwn2guh18AqpJ8+TO+w2iaVuHdZU87gEl3K0aSXM0UIOW9Ucf6Jg\nbrFSGtuTL7sLDWRTFsscCSSVKSK0ihgAif73H3LI6FwvGhuiGLjvGFzLtds6TtsP\nrt/EeeMeqlyjpOWsYZs3hY9IdRu51WiW6Sd5cFcjGrtsk5DHRdcX0jcqdrPNgqlP\nwAN74T16flu4hfL1Fftwqb31UGUWneO2a2FuoXqe6A0c9yqOaX5DMI54zu5lHjub\nhx5JHPgyRl0oRnkqTiddF1ioN/6oE6lpFd82Iol1usoBQC7tndcMqjHOJ65X1dJR\n+wIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2013-05-23 00:00:00 UTC",
            "validTo": "2023-05-22 23:59:59 UTC",
            "serialNumber": "36:34:9E:18:C9:9C:26:69:B6:56:2E:6C:E5:AD:71:32",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "thawte, Inc.",
                "commonName": "thawte SHA256 SSL CA"
            },
            "issuer": {
                "country": "US",
                "organization": "thawte, Inc.",
                "organizationalUnit": "Certification Services Division",
                "commonName": "thawte Primary Root CA - G3"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIEwjCCA6qgAwIBAgIQNjSeGMmcJmm2Vi5s5a1xMjANBgkqhkiG9w0BAQsFADCB\nrjELMAkGA1UEBhMCVVMxFTATBgNVBAoTDHRoYXd0ZSwgSW5jLjEoMCYGA1UECxMf\nQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjE4MDYGA1UECxMvKGMpIDIw\nMDggdGhhd3RlLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxJDAiBgNV\nBAMTG3RoYXd0ZSBQcmltYXJ5IFJvb3QgQ0EgLSBHMzAeFw0xMzA1MjMwMDAwMDBa\nFw0yMzA1MjIyMzU5NTlaMEMxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwx0aGF3dGUs\nIEluYy4xHTAbBgNVBAMTFHRoYXd0ZSBTSEEyNTYgU1NMIENBMIIBIjANBgkqhkiG\n9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo2Mr1LpdOK6wz7lMON8gffErR3Edi2jzVvmc\n2qrlhCbepXEwvPMxI53oO4DIZld1tlcO25P1Jo5wumRSZooqiFxEGE2oony9VmEy\nkBL5NYdIYLBukGdEAY3nyQ1jaHJyq2M8hrgffa2IJadqiCn7WcZ4cV8suonm04D9\nV+y5UV9DMy5+JTukBNFgjLNEM5MMrSq2RKIZO6/EkG97BYeGmyxqnStsd8kAn8nP\nrO0+G/fD89n4bNSgV8T7KDKqM/Dmupjf5cJOnHS/ikjC8hvwd0BBBwSyOtVMxCmp\nEUA/AkbwkdXSgYOGE7Mx7UarqId2qZl9vM0xUPSltdylMrOLiwIDAQABo4IBRDCC\nAUAwMgYIKwYBBQUHAQEEJjAkMCIGCCsGAQUFBzABhhZodHRwOi8vb2NzcC50aGF3\ndGUuY29tMBIGA1UdEwEB/wQIMAYBAf8CAQAwQQYDVR0gBDowODA2BgpghkgBhvhF\nAQc2MCgwJgYIKwYBBQUHAgEWGmh0dHBzOi8vd3d3LnRoYXd0ZS5jb20vY3BzMDcG\nA1UdHwQwMC4wLKAqoCiGJmh0dHA6Ly9jcmwudGhhd3RlLmNvbS9UaGF3dGVQQ0Et\nRzMuY3JsMA4GA1UdDwEB/wQEAwIBBjAqBgNVHREEIzAhpB8wHTEbMBkGA1UEAxMS\nVmVyaVNpZ25NUEtJLTItNDE1MB0GA1UdDgQWBBQrmjWuARg4MOFwegXgEXajzr2Q\nFDAfBgNVHSMEGDAWgBStbKqUYJzt5P/6Pgp0K2MD97ZZvzANBgkqhkiG9w0BAQsF\nAAOCAQEAdKZW6K+Tlhn7JvkNsESlzel6SAN0AWwTcbfggpCZYiPj1pmv8McenqgY\nIdu0lD80VhuZVS+O8EUzMrdywRNbNNP1YOUuGNFcxWrBqodQDBydZCv/G9zVLmEL\n57m2kVOG2QMq0T17StorB74p8mBCqZEaDi480X2lExQC+u6LjbbIuD5WgVchJD9l\nw7TJzlyNRqxT8/lVdMgr/dJ4cPX4EeX0p60g9Z3x7HD2E6zmjI3bP8byeQ6rUvLM\nG3knzxaz1vPGNoBD7MWU8N2QjfjGUkZW63RHvqbzGa5xTMDh59TP7dQGKCoRPLrZ\nQW4A54E3k+TaYsYdZ29jtBSG2aZi8A==\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "AD:6C:AA:94:60:9C:ED:E4:FF:FA:3E:0A:74:2B:63:03:F7:B6:59:BF",
                "subjectKeyIdentifier": "2B:9A:35:AE:01:18:38:30:E1:70:7A:05:E0:11:76:A3:CE:BD:90:14",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign"
                ],
                "crlDistributionPoints": [
                    "http://crl.thawte.com/ThawtePCA-G3.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://ocsp.thawte.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.16.840.1.113733.1.7.54",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.thawte.com/cps"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo2Mr1LpdOK6wz7lMON8g\nffErR3Edi2jzVvmc2qrlhCbepXEwvPMxI53oO4DIZld1tlcO25P1Jo5wumRSZooq\niFxEGE2oony9VmEykBL5NYdIYLBukGdEAY3nyQ1jaHJyq2M8hrgffa2IJadqiCn7\nWcZ4cV8suonm04D9V+y5UV9DMy5+JTukBNFgjLNEM5MMrSq2RKIZO6/EkG97BYeG\nmyxqnStsd8kAn8nPrO0+G/fD89n4bNSgV8T7KDKqM/Dmupjf5cJOnHS/ikjC8hvw\nd0BBBwSyOtVMxCmpEUA/AkbwkdXSgYOGE7Mx7UarqId2qZl9vM0xUPSltdylMrOL\niwIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "intermediate",
            "validationType": "organization",
            "validFrom": "2017-11-02 12:24:25 UTC",
            "validTo": "2027-11-02 12:24:25 UTC",
            "serialNumber": "09:0E:E8:C5:DE:5B:FA:62:D2:AE:2F:F7:09:7C:48:57",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "DigiCert Inc",
                "organizationalUnit": "www.digicert.com",
                "commonName": "Thawte TLS RSA CA G1"
            },
            "issuer": {
                "country": "US",
                "organization": "DigiCert Inc",
                "organizationalUnit": "www.digicert.com",
                "commonName": "DigiCert Global Root G2"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIEizCCA3OgAwIBAgIQCQ7oxd5b+mLSri/3CXxIVzANBgkqhkiG9w0BAQsFADBh\nMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3\nd3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH\nMjAeFw0xNzExMDIxMjI0MjVaFw0yNzExMDIxMjI0MjVaMF4xCzAJBgNVBAYTAlVT\nMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j\nb20xHTAbBgNVBAMTFFRoYXd0ZSBUTFMgUlNBIENBIEcxMIIBIjANBgkqhkiG9w0B\nAQEFAAOCAQ8AMIIBCgKCAQEAxjngmPhVetC0b/ozbYJdzOBUA1sMog47030cAP+P\n23ANUN8grXECL8NhDEF4F1R9tL0wY0mczHaR0a7lYanlxtwWo1s2uGnnyDs6mOCs\n66ew2w3YETr6Tb14xgjpu1gGFtAeewaikO9Fud8hxGJTSwn8xeNkfKVWpD2L4vFN\n36FNgxeilK6aE4ykgGAzNlokTp6hNOLAYpDySdLAPKzuJSQ7JCEZ6O+SDKywIdXL\noMTnpxuBKGSG88NWTo3CHCOGmQECia2yqdPDjgLqnEiYNjwQL8uMqj8rOvlMgviB\ncHA7xty+7/uYLN6ZS7Vq1/F/lVhVOf5ej6jZdmB85szFbQIDAQABo4IBQDCCATww\nHQYDVR0OBBYEFKWM/jLM6w8s1BnGCLgAJIhdw8W3MB8GA1UdIwQYMBaAFE4iVCAY\nlebjbuYP+vq5Eu0GF485MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEF\nBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADA0BggrBgEFBQcBAQQo\nMCYwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTBCBgNVHR8E\nOzA5MDegNaAzhjFodHRwOi8vY3JsMy5kaWdpY2VydC5jb20vRGlnaUNlcnRHbG9i\nYWxSb290RzIuY3JsMD0GA1UdIAQ2MDQwMgYEVR0gADAqMCgGCCsGAQUFBwIBFhxo\ndHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMA0GCSqGSIb3DQEBCwUAA4IBAQC6\nkm0KA4sTb2VYpEBm/uL2HL/pZX9B7L/hbJ4NcoBe7V56oCnt7aeIo8sMjCRWTCWZ\nD1dY0+2KZOC1dKj8d1VXXAtnjytDDuPPf6/iow0mYQTO/GAg/MLyL6CDm3FzDB8V\ntsH/aeMgP6pgD1XQqz+haDnfnJTKBuxhcpnx3Adbleue/QnPf1hHYa8L+Rv8Pi5U\nh4V9FwHOfphdMXOxi14OqmsiTbc5cOs9/uukH+YVsuFdWTna6IVw1qh+tEtyH16R\nvmi7pkqyZYULOPMIE7avrljVVBZuikwARtY8tCVV6Pp9l3VeagBqb2ffgqNJt3C0\nTYNYQI+BXG1R1cABlold\n-----END CERTIFICATE-----\n",
            "extensions": {
                "authorityKeyIdentifier": "4E:22:54:20:18:95:E6:E3:6E:E6:0F:FA:FA:B9:12:ED:06:17:8F:39",
                "subjectKeyIdentifier": "A5:8C:FE:32:CC:EB:0F:2C:D4:19:C6:08:B8:00:24:88:5D:C3:C5:B7",
                "keyUsage": [
                    "Digital Signature",
                    "Cert Sign",
                    "CRL Sign"
                ],
                "extendedKeyUsage": [
                    "Server Authentication",
                    "Client Authentication"
                ],
                "crlDistributionPoints": [
                    "http://crl3.digicert.com/DigiCertGlobalRootG2.crl"
                ],
                "authorityInfoAccess": {
                    "ocsp": [
                        "http://ocsp.digicert.com"
                    ]
                },
                "certificatePolicies": [
                    {
                        "policyIdentifier": "2.5.29.32.0",
                        "policyQualifiers": [
                            {
                                "policyQualifierId": "1.3.6.1.5.5.7.2.1",
                                "cpsUri": "https://www.digicert.com/CPS"
                            }
                        ]
                    }
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxjngmPhVetC0b/ozbYJd\nzOBUA1sMog47030cAP+P23ANUN8grXECL8NhDEF4F1R9tL0wY0mczHaR0a7lYanl\nxtwWo1s2uGnnyDs6mOCs66ew2w3YETr6Tb14xgjpu1gGFtAeewaikO9Fud8hxGJT\nSwn8xeNkfKVWpD2L4vFN36FNgxeilK6aE4ykgGAzNlokTp6hNOLAYpDySdLAPKzu\nJSQ7JCEZ6O+SDKywIdXLoMTnpxuBKGSG88NWTo3CHCOGmQECia2yqdPDjgLqnEiY\nNjwQL8uMqj8rOvlMgviBcHA7xty+7/uYLN6ZS7Vq1/F/lVhVOf5ej6jZdmB85szF\nbQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        },
        {
            "chainHierarchy": "root",
            "validationType": "self-signed-ca",
            "validFrom": "2013-08-01 12:00:00 UTC",
            "validTo": "2038-01-15 12:00:00 UTC",
            "serialNumber": "03:3A:F1:E6:A7:11:A9:A0:BB:28:64:B1:1D:09:FA:E5",
            "signatureAlgorithm": "SHA256-RSA",
            "subject": {
                "country": "US",
                "organization": "DigiCert Inc",
                "organizationalUnit": "www.digicert.com",
                "commonName": "DigiCert Global Root G2"
            },
            "issuer": {
                "country": "US",
                "organization": "DigiCert Inc",
                "organizationalUnit": "www.digicert.com",
                "commonName": "DigiCert Global Root G2"
            },
            "pem": "-----BEGIN CERTIFICATE-----\nMIIDjjCCAnagAwIBAgIQAzrx5qcRqaC7KGSxHQn65TANBgkqhkiG9w0BAQsFADBh\nMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3\nd3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH\nMjAeFw0xMzA4MDExMjAwMDBaFw0zODAxMTUxMjAwMDBaMGExCzAJBgNVBAYTAlVT\nMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j\nb20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IEcyMIIBIjANBgkqhkiG\n9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuzfNNNx7a8myaJCtSnX/RrohCgiN9RlUyfuI\n2/Ou8jqJkTx65qsGGmvPrC3oXgkkRLpimn7Wo6h+4FR1IAWsULecYxpsMNzaHxmx\n1x7e/dfgy5SDN67sH0NO3Xss0r0upS/kqbitOtSZpLYl6ZtrAGCSYP9PIUkY92eQ\nq2EGnI/yuum06ZIya7XzV+hdG82MHauVBJVJ8zUtluNJbd134/tJS7SsVQepj5Wz\ntCO7TG1F8PapspUwtP1MVYwnSlcUfIKdzXOS0xZKBgyMUNGPHgm+F6HmIcr9g+UQ\nvIOlCsRnKPZzFBQ9RnbDhxSJITRNrw9FDKZJobq7nMWxM4MphQIDAQABo0IwQDAP\nBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQUTiJUIBiV\n5uNu5g/6+rkS7QYXjzkwDQYJKoZIhvcNAQELBQADggEBAGBnKJRvDkhj6zHd6mcY\n1Yl9PMWLSn/pvtsrF9+wX3N3KjITOYFnQoQj8kVnNeyIv/iPsGEMNKSuIEyExtv4\nNeF22d+mQrvHRAiGfzZ0JFrabA0UWTW98kndth/Jsw1HKj2ZL7tcu7XUIOGZX1NG\nFdtom/DzMNU+MeKNhJ7jitralj41E6Vf8PlwUHBHQRFXGU7Aj64GxJUTFy8bJZ91\n8rGOmaFvE7FBcf6IKshPECBV1/MUReXgRPTqh5Uykw7+U0b6LJ3/iyK5S9kJRaTe\npLiaWN0bfVKfjllDiIGknibVb63dDcY3fe0Dkhvld1927jyNxF1WW6LZZm6zNTfl\nMrY=\n-----END CERTIFICATE-----\n",
            "extensions": {
                "subjectKeyIdentifier": "4E:22:54:20:18:95:E6:E3:6E:E6:0F:FA:FA:B9:12:ED:06:17:8F:39",
                "keyUsage": [
                    "Cert Sign",
                    "CRL Sign",
                    "Digital Signature"
                ]
            },
            "publicKey": {
                "type": "RSA",
                "bits": 2048,
                "pem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuzfNNNx7a8myaJCtSnX/\nRrohCgiN9RlUyfuI2/Ou8jqJkTx65qsGGmvPrC3oXgkkRLpimn7Wo6h+4FR1IAWs\nULecYxpsMNzaHxmx1x7e/dfgy5SDN67sH0NO3Xss0r0upS/kqbitOtSZpLYl6Ztr\nAGCSYP9PIUkY92eQq2EGnI/yuum06ZIya7XzV+hdG82MHauVBJVJ8zUtluNJbd13\n4/tJS7SsVQepj5WztCO7TG1F8PapspUwtP1MVYwnSlcUfIKdzXOS0xZKBgyMUNGP\nHgm+F6HmIcr9g+UQvIOlCsRnKPZzFBQ9RnbDhxSJITRNrw9FDKZJobq7nMWxM4Mp\nhQIDAQAB\n-----END PUBLIC KEY-----\n"
            }
        }
    ],
    "status": "discovered"
}
...

Output field description

auditCreated
The date (UTC) when the certificate was collected from the server.
domain
The domain name the certificate chain is returned for.
ip
The IP address to which the SSL connection was established.
port
The port on which the SSL connection was established.
status

The status of the certificate chain from the domain name’s perspective:

  • discovered - the certificate is returned but the previous certificate is unknown;
  • added - the certificate was missing but now it’s present;
  • dropped - the certificate was present but now it’s missing;
  • updated - the previous and the current certificates' hashes don’t match thus the certificate was re-issued or re-configured;
certificates
Array of SSL certificates collected for the domain name. The certificates are sorted from the end-user to the root one.
certificates[0].chainHierarchy
Position in the certificates chain: End-user, Intermediate or Root.
certificates[0].validationType

The certificate's validation type:

  • domain - Domain validation
  • organization - Organization validation
  • extended - Extended validation
  • individual - Individual validation
  • self-signed - Self-signed certificate
  • self-signed-ca - Self-signed CA certificate (typically, it’s the root certificate in the chain)
certificates[0].validFrom
The date and time (UTC) the certificate is valid from.
certificates[0].validTo
The date and time (UTC) the certificate expires.
certificates[0].serialNumber
Uniquely identifies the certificate within Certificate Authority (CA) systems to track revocation information..
certificates[0].signatureAlgorithm
The algorithm used to sign the public key certificate.
certificates[0].subject
The object that contains a distinguished name (DN) of the certificate’s subject (i.e. who the certificate was issued to). Some fields might be omitted since usually DN objects don’t contain all the available fields.
certificates[0].issuer
The object that contains a distinguished name (DN) of the certificate’s issuer (i.e. the one who issued the certificate.).
certificates[0].[issuer|subject].country
(optional) (C) Country
certificates[0].[issuer|subject].organization
(optional) (O) Organization
certificates[0].[issuer|subject].organizationUnit
(optional) Organization unit (OU)
certificates[0].[issuer|subject].locality
(optional) (L) City
certificates[0].[issuer|subject].province
(optional) (S) Province/State
certificates[0].[issuer|subject].streetAddress
(optional) (STREET) Street
certificates[0].[issuer|subject].postalCode
(optional) (PC) Postal code or ZIP-code
certificates[0].[issuer|subject].serialNumber
(optional) (SERIALNUMBER) Certificate serial number
certificates[0].[issuer|subject].commonName
(optional) (CN) Certificate's common name
certificates[0].pem
The PEM-encoded certificate’s raw data
certificates[0].extensions
Available certificate extensions. (RFC 5280
certificates[0].extensions.authorityKeyIdentifier
(optional) The authority key identifier extension provides a means of identifying the public key corresponding to the private key used to sign a certificate.
certificates[0].extensions.subjectKeyIdentifier
(optional) The subject key identifier extension provides a means of identifying certificates that contain a particular public key.
certificates[0].extensions.keyUsage
(optional) The purposes of the key contained in the certificate.
certificates[0].extensions.extendedKeyUsage
(optional) Additional purposes of the key contained in the certificate.
certificates[0].extensions.crlDistributionPoints
(optional) The array of CRL (Certificate revocation list) distribution endpoints for the SSL certificate.
certificates[0].extensions.authorityInfoAccess
(optional) The extensions contains the information regarding the certificate issuers.
certificates[0].extensions.authorityInfo.issuers
(optional) Issuer's resources location.
certificates[0].extensions.authorityInfo.ocsp
(optional) OCSP (Online Certificate Status Protocol) endpoints.
certificates[0].extensions.subjectAlternativeNames
(optional) Alternatives names bound into the certificate.
certificates[0].extensions.subjectAlternativeNames.dnsNames
(optional) Alternative DNS names.
certificates[0].extensions.subjectAlternativeNames.emailAddresses
(optional) Alternative email addresses.
certificates[0].extensions.subjectAlternativeNames.ipAddresses
(optional) Alternative IP addresses.
certificates[0].extensions.subjectAlternativeNames.uris
(optional) Alternative URIs.
certificates[0].extensions.certificatePolicies
(optional) The information regarding the policies under which the certificate was issued and the purposes for which the certificate can be used.
certificates[0].extensions.certificatePolicies[0].policyIdentifier
The OID (object identifier) of the policy.
certificates[0].extensions.certificatePolicies[0].policyQualifiers
(optional) Policy qualifiers.
certificates[0].extensions.certificatePolicies[0].policyQualifiers[0].policyQualifierId
The OID of the policy’s qualifier.
certificates[0].extensions.certificatePolicies[0].policyQualifiers[0].cpsUri
(optional) Certification Practice Statement's URI.
certificates[0].extensions.certificatePolicies[0].policyQualifiers[0].userNotice
(optional) User notice related to the certificate. It may be provided either in the form of notice reference or in the form of the explicit text.
certificates[0].extensions.certificatePolicies[0].policyQualifiers[0].userNotice.noticeRef
(optional) Contains the reference to the textual statement related to the certificate.
certificates[0].extensions.certificatePolicies[0].policyQualifiers[0].userNotice.noticeRef.organization
Organization which prepared the notice.
certificates[0].extensions.certificatePolicies[0].policyQualifiers[0].userNotice.noticeRef.noticeNumbers
The identifier of the particular textual statement prepared by the organization.
certificates[0].extensions.certificatePolicies[0].policyQualifiers[0].userNotice.explicitText
The explicit textual statement in the certificate.
certificates[0].publicKey
The certificate’s public key information.
certificates[0].publicKey.type
The public key algorithm.
certificates[0].publicKey.bits
The public key length (bits).
certificates[0].publicKey.pem
The PEM-encoded public key’s raw data.