standalone Self-Signed S/MIME Certificate


RSASSA-PSS dual-key certificate [C + S + E]


0. primary key, Certify [C]

X.509: ROOT/Issuer

Field/ExtensionContentOptional/Critical
VersionVersion: 3 (0x2)
Serial Numbercontaining at least 64 bits of output from a CSPRNG, e.g.0x79ca0c36078b2877
Signature Algorithm1.2.840.113549.1.1.10 RSASSA-PSS
Hash Algorithm:sha256
Mask Algorithm:mgf1 with sha256
ValidityNot Before...
Not After...
Issuer DN = Subject DNcommonName...
givenName
surname
pseudonym
serialNumber
emailAddress
title
streetAddress
localityName
stateOrProvinceName
postalCode
countryName
organizationName
organizationalUnitName
organizationIdentifier
Subject Public Key InfoPublic Key Algorithm and RSA Public-KeyrsaEncryption and 3072 bit
X509v3 extensionsBasic ConstraintsCA:TRUEcritical
Key UsagekeyCertSign, cRLSigncritical
Extended Key UsageclientAuth, emailProtection
Subject Key Identifier256-bit SHAKE-256 hash of the DER encoding of the subjectPublicKey (pin-shake256-hex)

1. subkey, Sign [S]

X.509: Subscriber/Subject

Field/ExtensionContentOptional/Critical
VersionVersion: 3 (0x2)
Serial Numbercontaining at least 64 bits of output from a CSPRNG, e.g.0x7012ccbbb18d3740
Signature Algorithm1.2.840.113549.1.1.10 RSASSA-PSS
Hash Algorithm:sha256
Mask Algorithm:mgf1 with sha256
Issuerbased on the Distinguished Name (Subject) in the issuer's certificate...
ValidityNot Before...
Not After...
Subject DNNULL SEQUENCE (NULL-DN)SEQUENCE {}
Subject Public Key InfoPublic Key Algorithm and RSA Public-KeyrsaEncryption and 2048 bit
X509v3 extensionsBasic ConstraintsCA:FALSEcritical
Key UsagedigitalSignaturecritical
Extended Key UsageclientAuth, emailProtection
Authority Key IdentifierkeyID: based on the subject key identifier in the issuer's certificate
Subject Key Identifier256-bit SHAKE-256 hash of the DER encoding of the subjectPublicKey (pin-shake256-hex)
Subject Alternative NameIA5String (rfc822Name) or/and UTF-8 (otherName)
test@example.com
critical

2. subkey, Encrypt [E]

X.509: Subscriber/Subject

Field/ExtensionContentOptional/Critical
VersionVersion: 3 (0x2)
Serial Numbercontaining at least 64 bits of output from a CSPRNG, e.g.0x50007342621b74f0
Signature Algorithm1.2.840.113549.1.1.10 RSASSA-PSS
Hash Algorithm:sha256
Mask Algorithm:mgf1 with sha256
Issuerbased on the Distinguished Name (Subject) in the issuer's certificate...
ValidityNot Before...
Not After...
Subject DNNULL SEQUENCE (NULL-DN)SEQUENCE {}
Subject Public Key InfoPublic Key Algorithm and RSA Public-KeyrsaEncryption and 2048 bit
X509v3 extensionsBasic ConstraintsCA:FALSEcritical
Key UsagekeyEnciphermentcritical
Extended Key UsageemailProtection
Authority Key IdentifierkeyID: based on the subject key identifier in the issuer's certificate
Subject Key Identifier256-bit SHAKE-256 hash of the DER encoding of the subjectPublicKey (pin-shake256-hex)
Subject Alternative NameIA5String (rfc822Name) or/and UTF-8 (otherName)
test@example.com
critical