standalone Self-Signed S/MIME Certificate


RSA single-key certificate [C + SE]


0. primary key, Certify [C]

X.509: ROOT/Issuer

Field/ExtensionContentOptional/Critical
VersionVersion: 3 (0x2)
Serial Numbercontaining at least 64 bits of output from a CSPRNG, e.g.0x483542be07fe1736
Signature Algorithmsha256WithRSAEncryption
ValidityNot Before...
Not After...
Issuer DN = Subject DNcommonName...
givenName
surname
pseudonym
serialNumber
emailAddress
title
streetAddress
localityName
stateOrProvinceName
postalCode
countryName
organizationName
organizationalUnitName
organizationIdentifier
Subject Public Key InfoPublic Key Algorithm and RSA Public-KeyrsaEncryption and 3072 bit
X509v3 extensionsBasic ConstraintsCA:TRUEcritical
Key UsagekeyCertSign, cRLSigncritical
Extended Key UsageclientAuth, emailProtection
Subject Key Identifier256-bit SHAKE-256 hash of the DER encoding of the subjectPublicKey (pin-shake256-hex)

1. subkey, Sign+Encrypt [SE]

X.509: Subscriber/Subject

Field/ExtensionContentOptional/Critical
VersionVersion: 3 (0x2)
Serial Numbercontaining at least 64 bits of output from a CSPRNG, e.g.0x13cc47fb48a2859c
Signature Algorithmsha256WithRSAEncryption
Issuerbased on the Distinguished Name (Subject) in the issuer's certificate...
ValidityNot Before...
Not After...
Subject DNNULL SEQUENCE (NULL-DN)SEQUENCE {}
Subject Public Key InfoPublic Key Algorithm and RSA Public-KeyrsaEncryption and 2048 bit
X509v3 extensionsBasic ConstraintsCA:FALSEcritical
Key UsagedigitalSignature, keyEnciphermentcritical
Extended Key UsageclientAuth, emailProtection
Authority Key IdentifierkeyID: based on the subject key identifier in the issuer's certificate
Subject Key Identifier256-bit SHAKE-256 hash of the DER encoding of the subjectPublicKey (pin-shake256-hex)
Subject Alternative NameIA5String (rfc822Name) or/and UTF-8 (otherName)
test@example.com
critical