Sunday, April 14, 2019

Checking the Certificate Information of a PEM Encoded SSL certificate

Customers can check the validity of PEM Encoded SSL certificate embedded on his Identity Provider metadata. A sample PEM certificate can be found as highlighted below:

SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAssertionsSigned="true"
       KeyDescriptor use="encryption"
            ds:KeyInfo xmlns:ds="
http://www.w3.org/2000/09/xmldsig#"
                ds:X509Data
                    ds:X509Certificate
MIIFbzCCBFegAwIBAgIHJ6RHKh7gLzANBgkqhkiG9w0BAQUFADCByjELMAkGA1UEBhMCVVMxEDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNjb3R0c2RhbGUxGjAYBgNVBAoTEUdvRGFkZHkuY29tLCBJbmMuMTMwMQYDVQQLEypodHRwOi8vY2VydGlmaWNhdGVzLmdvZGFkZHkuY29tL3JlcG9zaXRvcnkxMDAuBgNVBAMTJ0dvIERhZGR5IFNlY3VyZSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTERMA8GA1UEBRMIMDc5NjkyODcwHhcNMTIwNzMxMDAzMTQxWhcNMTMwNzMxMDAzMTQxWjBbMRowGAYDVQQKExFzYW1sLm5ldHN1aXRlLmNvbTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRowGAYDVQQDExFzYW1sLm5ldHN1aXRlLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALaJIZv3Eyz7r+hVG6nENCLxG0qC5YaTwlCrUbHovF82uIMtj7kf3tTtX4DRBW2ZXBo3MVclqi/PztaiBbGd64kAlCCPFdfxnsCfY8BrtyvvofHjbTwmXqcgbH8YRRKqgo46E/O+z81lIyEpDbf/ikfsZjiF01tB2O5Q7EzdityYRi5YPUk9mzvdHUqRn2ekQWn0qAqL9QZMtiUIdNrcmBMXI/0aHGYD7Cr5BnzBudqKXUGHADrjI5MwblXgAvndEZx0tZmsWwalBC5+NplgGNFdr9Zv+F4Vm+4rUDqPCllZkJyd+7wBG/Z3tKic20/0FWchP1wGSDykG+riL3N/iikCAwEAAaOCAcYwggHCMA8GA1UdEwEB/wQFMAMBAQAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA4GA1UdDwEB/wQEAwIFoDAzBgNVHR8ELDAqMCigJqAkhiJodHRwOi8vY3JsLmdvZGFkZHkuY29tL2dkczEtNzQuY3JsMFMGA1UdIARMMEowSAYLYIZIAYb9bQEHFwEwOTA3BggrBgEFBQcCARYraHR0cDovL2NlcnRpZmljYXRlcy5nb2RhZGR5LmNvbS9yZXBvc2l0b3J5LzCBgAYIKwYBBQUHAQEEdDByMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5nb2RhZGR5LmNvbS8wSgYIKwYBBQUHMAKGPmh0dHA6Ly9jZXJ0aWZpY2F0ZXMuZ29kYWRkeS5jb20vcmVwb3NpdG9yeS9nZF9pbnRlcm1lZGlhdGUuY3J0MB8GA1UdIwQYMBaAFP2sYTKTbEXW4u6FX5q653aZaMznMDMGA1UdEQQsMCqCEXNhbWwubmV0c3VpdGUuY29tghV3d3cuc2FtbC5uZXRzdWl0ZS5jb20wHQYDVR0OBBYEFHYpiqKKc+EdJnDDfmGryxbn/n2eMA0GCSqGSIb3DQEBBQUAA4IBAQCNz9tIF1Io6Mx23mSH+7AtBlnOlwBwRy9a58aQsz3DVxgJObKwUriNoO8+2tHfEPfmoZcPGpDDk/moaI1Cb5SHlKr/TIVxheDejSGD6s3LPctgHqRJHveKN2vbQpilnYeIEIOps/paFzhZWDFAiOJ0NGJN42mzMA8hzMALDSWmfDXawDC6Giq6HA/pC7aNWu+ypW85gTFGFkwItlN35DwFtkGOWaTYmOGrbf+AfhD/1qqTS7LSc4b+dzgsIzB2XEj0whRvTlrYhVsZ0GjJ5zLSBCREtfyvvcodQh6BsP032rFELzEzodkKIXotv8coDwUNc+8dFDaInCgo8b5hNNlC
                    ds:X509Certificate
                ds:X509Data

 
Customer can copy the certificate and paste it on the following URL:
http://www.sslshopper.com/certificate-decoder.html

Pasting the certificate would then show the essential certification as follows:

Common Name: test
Organization: Sun
Organization Unit: OpenSSO
Locality: Santa Clara
State: California
Country: US
Valid From: January 15, 2008
Valid To: January 12, 2018
Issuer: test, Sun
Key Size: 1024 bit
Serial Number: 1200424779 (0x478d074b)

No comments:

Post a Comment