SSHCHICAGO.ORG Certificate Authority (CA)

From sshcWiki
Revision as of 16:38, 9 December 2016 by Cswingler (talk | contribs) (grumble grumble wiki formatting)
Jump to navigation Jump to search

Certificate Authority

We operate our own internal Certificate Authority.

You can get the CA cert from either of these links (these are stored on different servers, and should serve the exact same certificate):

https://auth.sshchicago.org/ipa/config/ca.crt

http://sshchicago.org/ssl/sshchicago-ca.cer

Or, if you'd rather just have it in the clear:

-----BEGIN CERTIFICATE-----
MIIDlTCCAn2gAwIBAgIBATANBgkqhkiG9w0BAQsFADA5MRcwFQYDVQQKEw5TU0hD
SElDQUdPLk9SRzEeMBwGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE0
MDMxNjE5MDQwNVoXDTM0MDMxNjE5MDQwNVowOTEXMBUGA1UEChMOU1NIQ0hJQ0FH
Ty5PUkcxHjAcBgNVBAMTFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAKhPpe9okF3y1f7+Mpg9pRKOexH7KevOdkQN
V2rNBZ7s2SXxg/r6vfcXNEKAfzdvTe6eycAlA9ENyaELzkqGBNs6z2y4Wewn2H+7
1F233wfkvhwgm1sAHAeVFwjbbFGEk1I37uV6N5K7nOxwCeN5n/XDKtkHSeTkXBNI
ctfIiJNgvqhyqrp/R9eqyZiAQN0bsSF8ZFV224Gn7qgvurn2Fza4MNGDzRvuiuw2
+oFV2beXENKvDlZib/w6lRYU6UwovEBV2S3ko3argqqKANvwobmyX6MS51z5nPtw
jism4g1Ue3DXVGsjt/JdpZx/Afom1v1g/1RD8NGpEFBeRho9xLkCAwEAAaOBpzCB
pDAfBgNVHSMEGDAWgBTw8F+DwnCWenAkJAFNHRkgbWoW+jAPBgNVHRMBAf8EBTAD
AQH/MA4GA1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQU8PBfg8JwlnpwJCQBTR0ZIG1q
FvowQQYIKwYBBQUHAQEENTAzMDEGCCsGAQUFBzABhiVodHRwOi8vYXV0aC5zc2hj
aGljYWdvLm9yZzo4MC9jYS9vY3NwMA0GCSqGSIb3DQEBCwUAA4IBAQA9lCgce4d1
XkGnXw+ldNsNAn6OX3ZWHlGLVECunbbVqRDbOU7pHMZG2nr3QoUkO3FABJN80A9C
a0aX15pYkA8T6JC/h4Fw78G0hAKGnm+6nxIDo9wDXarT452osSSyts3TLinDSDt7
D+g3c04ivMx03gRpoZWnRsfVb3P3LDvx/2566ejHpv8W4REav6kmhWzxGMubO11J
AgBuAVNNHACuGbSFIrK0zTeMCAtaCbojsQ1IhJBEtSUoqtEJATjencp2dkkVRB6N
2KQsacZhzR9s6e1YvqcvYO35aJaXSWLf6wCsn4MjPwQfeTbiYrk5qi7i2xVpN5Il
vQ+AHNlQsD2e
-----END CERTIFICATE-----

Decoded:

Certificate:
   Data:
       Version: 3 (0x2)
       Serial Number: 1 (0x1)
       Signature Algorithm: sha256WithRSAEncryption
       Issuer: O=SSHCHICAGO.ORG, CN=Certificate Authority
       Validity
           Not Before: Mar 16 19:04:05 2014 GMT
           Not After : Mar 16 19:04:05 2034 GMT
       Subject: O=SSHCHICAGO.ORG, CN=Certificate Authority
       Subject Public Key Info:
           Public Key Algorithm: rsaEncryption
           RSA Public Key: (2048 bit)
               Modulus (2048 bit):
                   00:a8:4f:a5:ef:68:90:5d:f2:d5:fe:fe:32:98:3d:
                   a5:12:8e:7b:11:fb:29:eb:ce:76:44:0d:57:6a:cd:
                   05:9e:ec:d9:25:f1:83:fa:fa:bd:f7:17:34:42:80:
                   7f:37:6f:4d:ee:9e:c9:c0:25:03:d1:0d:c9:a1:0b:
                   ce:4a:86:04:db:3a:cf:6c:b8:59:ec:27:d8:7f:bb:
                   d4:5d:b7:df:07:e4:be:1c:20:9b:5b:00:1c:07:95:
                   17:08:db:6c:51:84:93:52:37:ee:e5:7a:37:92:bb:
                   9c:ec:70:09:e3:79:9f:f5:c3:2a:d9:07:49:e4:e4:
                   5c:13:48:72:d7:c8:88:93:60:be:a8:72:aa:ba:7f:
                   47:d7:aa:c9:98:80:40:dd:1b:b1:21:7c:64:55:76:
                   db:81:a7:ee:a8:2f:ba:b9:f6:17:36:b8:30:d1:83:
                   cd:1b:ee:8a:ec:36:fa:81:55:d9:b7:97:10:d2:af:
                   0e:56:62:6f:fc:3a:95:16:14:e9:4c:28:bc:40:55:
                   d9:2d:e4:a3:76:ab:82:aa:8a:00:db:f0:a1:b9:b2:
                   5f:a3:12:e7:5c:f9:9c:fb:70:8e:2b:26:e2:0d:54:
                   7b:70:d7:54:6b:23:b7:f2:5d:a5:9c:7f:01:fa:26:
                   d6:fd:60:ff:54:43:f0:d1:a9:10:50:5e:46:1a:3d:
                   c4:b9
               Exponent: 65537 (0x10001)
       X509v3 extensions:
           X509v3 Authority Key Identifier: 
               keyid:F0:F0:5F:83:C2:70:96:7A:70:24:24:01:4D:1D:19:20:6D:6A:16:FA

           X509v3 Basic Constraints: critical
               CA:TRUE
           X509v3 Key Usage: critical
               Digital Signature, Non Repudiation, Certificate Sign, CRL Sign
           X509v3 Subject Key Identifier: 
               F0:F0:5F:83:C2:70:96:7A:70:24:24:01:4D:1D:19:20:6D:6A:16:FA
           Authority Information Access: 
               OCSP - URI:http://auth.sshchicago.org:80/ca/ocsp

   Signature Algorithm: sha256WithRSAEncryption
       3d:94:28:1c:7b:87:75:5e:41:a7:5f:0f:a5:74:db:0d:02:7e:
       8e:5f:76:56:1e:51:8b:54:40:ae:9d:b6:d5:a9:10:db:39:4e:
       e9:1c:c6:46:da:7a:f7:42:85:24:3b:71:40:04:93:7c:d0:0f:
       42:6b:46:97:d7:9a:58:90:0f:13:e8:90:bf:87:81:70:ef:c1:
       b4:84:02:86:9e:6f:ba:9f:12:03:a3:dc:03:5d:aa:d3:e3:9d:
       a8:b1:24:b2:b6:cd:d3:2e:29:c3:48:3b:7b:0f:e8:37:73:4e:
       22:bc:cc:74:de:04:69:a1:95:a7:46:c7:d5:6f:73:f7:2c:3b:
       f1:ff:6e:7a:e9:e8:c7:a6:ff:16:e1:11:1a:bf:a9:26:85:6c:
       f1:18:cb:9b:3b:5d:49:02:00:6e:01:53:4d:1c:00:ae:19:b4:
       85:22:b2:b4:cd:37:8c:08:0b:5a:09:ba:23:b1:0d:48:84:90:
       44:b5:25:28:aa:d1:09:01:38:de:9d:ca:76:76:49:15:44:1e:
       8d:d8:a4:2c:69:c6:61:cd:1f:6c:e9:ed:58:be:a7:2f:60:ed:
       f9:68:96:97:49:62:df:eb:00:ac:9f:83:23:3f:04:1f:79:36:
       e2:62:b9:39:aa:2e:e2:db:15:69:37:92:25:bd:0f:80:1c:d9:
       50:b0:3d:9e