1.
| 1.
| CN=*.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.12.2025
| 09.12.2026 expires in 123 days | *.spotify.com, spotify.com - 2 entries
|
1.
| 1.
| CN=*.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.12.2025
09.12.2026 expires in 123 days |
|
| *.spotify.com, spotify.com - 2 entries
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 04A7B6CCEC54B36CF146C0E8D8CC3839
| | Thumbprint: | BF967ACEE4F690B656416372FB6409A51C55D578
| | SHA256 / Certificate: | 0lnAcbIu6EUj57JW5LATr/PHtPJe7bGutagrk1iNY8Y=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 3c36abf09c89a64177011018700f8439923be80ded5ee4cd69e8082698fff385
| | SHA256 hex / Subject Public Key Information (SPKI): | 3c36abf09c89a64177011018700f8439923be80ded5ee4cd69e8082698fff385 (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 2.
| CN=*.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.12.2025
| 09.12.2026 expires in 123 days | *.spotify.com, spotify.com - 2 entries
|
| 2.
| CN=*.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.12.2025
09.12.2026 expires in 123 days |
|
| *.spotify.com, spotify.com - 2 entries
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 04A7B6CCEC54B36CF146C0E8D8CC3839
| | Thumbprint: | BF967ACEE4F690B656416372FB6409A51C55D578
| | SHA256 / Certificate: | 0lnAcbIu6EUj57JW5LATr/PHtPJe7bGutagrk1iNY8Y=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 3c36abf09c89a64177011018700f8439923be80ded5ee4cd69e8082698fff385
| | SHA256 hex / Subject Public Key Information (SPKI): | 3c36abf09c89a64177011018700f8439923be80ded5ee4cd69e8082698fff385 (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 3.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
| 30.03.2031 expires in 1695 days |
|
| 3.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
30.03.2031 expires in 1695 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0CF5BD062B5602F47AB8502C23CCF066
| | Thumbprint: | 1B511ABEAD59C6CE207077C0BF0E0043B1382612
| | SHA256 / Certificate: | yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)
|
|
|
|
| 4.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
| 30.03.2031 expires in 1695 days |
|
| 4.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
30.03.2031 expires in 1695 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0CF5BD062B5602F47AB8502C23CCF066
| | Thumbprint: | 1B511ABEAD59C6CE207077C0BF0E0043B1382612
| | SHA256 / Certificate: | yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)
|
|
|
|
| 5.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 29.10.2024
| 09.11.2031 expires in 1919 days |
|
| 5.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 29.10.2024
09.11.2031 expires in 1919 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0E7D75235CA83761577F4CCD24CD6D1D
| | Thumbprint: | B7402517EEAAC80AB04681186E8247BD7851CD0A
| | SHA256 / Certificate: | oNYJp+PENOh4qaHBvQZbjc8zqn7+4bEbx1zOXloEIIA=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: | http://ocsp.digicert.cn
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
| 6.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 01.08.2013
| 15.01.2038 expires in 4178 days |
|
| 6.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 01.08.2013
15.01.2038 expires in 4178 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 033AF1E6A711A9A0BB2864B11D09FAE5
| | Thumbprint: | DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
| | SHA256 / Certificate: | yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
| | SHA256 hex / Cert (DANE * 0 1): | cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
| | SHA256 hex / PublicKey (DANE * 1 1): | 8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
| | SHA256 hex / Subject Public Key Information (SPKI): | 8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|
| 7.
| CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
| 10.11.2006
| 10.11.2031 expires in 1920 days |
|
| 7.
| CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
| 10.11.2006
10.11.2031 expires in 1920 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA-1 with RSA Encryption
| | Serial Number: | 02AC5C266A0B409B8F0B79F2AE462577
| | Thumbprint: | 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
| | SHA256 / Certificate: | dDHl9MPBzkaQd08LYeBUQIg7qaAe0Aumq9eAbtOxGM8=
| | SHA256 hex / Cert (DANE * 0 1): | 7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf
| | SHA256 hex / PublicKey (DANE * 1 1): | 5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
| | SHA256 hex / Subject Public Key Information (SPKI): | 5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|
2.
| 1.
| CN=www.spotify.com
| 03.06.2026
| 01.09.2026 expires in 24 days | www.spotify.com - 1 entry
|
2.
| 1.
| CN=www.spotify.com
| 03.06.2026
01.09.2026 expires in 24 days |
|
| www.spotify.com - 1 entry
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 05AE3B8EDF465D185DD208E94DDDE24B59E6
| | Thumbprint: | A0972DC52FA996663A912A803C590699890057A4
| | SHA256 / Certificate: | L0wKncCTPAG4sMaJi28DzQSURFgOKKL1GoMbuNDgYY0=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 29bdbbe0c4e977cd2e7e6350173814dfc39e3c3c255ffe532bced0407a0c5278
| | SHA256 hex / Subject Public Key Information (SPKI): | 29bdbbe0c4e977cd2e7e6350173814dfc39e3c3c255ffe532bced0407a0c5278 (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 2.
| CN=www.spotify.com
| 03.06.2026
| 01.09.2026 expires in 24 days | www.spotify.com - 1 entry
|
| 2.
| CN=www.spotify.com
| 03.06.2026
01.09.2026 expires in 24 days |
|
| www.spotify.com - 1 entry
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 05AE3B8EDF465D185DD208E94DDDE24B59E6
| | Thumbprint: | A0972DC52FA996663A912A803C590699890057A4
| | SHA256 / Certificate: | L0wKncCTPAG4sMaJi28DzQSURFgOKKL1GoMbuNDgYY0=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 29bdbbe0c4e977cd2e7e6350173814dfc39e3c3c255ffe532bced0407a0c5278
| | SHA256 hex / Subject Public Key Information (SPKI): | 29bdbbe0c4e977cd2e7e6350173814dfc39e3c3c255ffe532bced0407a0c5278 (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 3.
| CN=YR1, O=Let's Encrypt, C=US
| 03.09.2025
| 03.09.2028 expires in 757 days |
|
| 3.
| CN=YR1, O=Let's Encrypt, C=US
| 03.09.2025
03.09.2028 expires in 757 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 00A20253F15F2691C05DC1CE13B9BCCA4E
| | Thumbprint: | CBCFD09CE3CD22D99D94E58F92E9898FBEE51A5E
| | SHA256 / Certificate: | E5SWNNmc1v1qqAvANP76zOsZaf7vmGWGcT7NuwV1jT8=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 2e8307068b6db620e4a39d068b5dee5d6ef5788cbb2c0b6d23ead84fcc17178c
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 4.
| CN=YR1, O=Let's Encrypt, C=US
| 03.09.2025
| 03.09.2028 expires in 757 days |
|
| 4.
| CN=YR1, O=Let's Encrypt, C=US
| 03.09.2025
03.09.2028 expires in 757 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 00A20253F15F2691C05DC1CE13B9BCCA4E
| | Thumbprint: | CBCFD09CE3CD22D99D94E58F92E9898FBEE51A5E
| | SHA256 / Certificate: | E5SWNNmc1v1qqAvANP76zOsZaf7vmGWGcT7NuwV1jT8=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 2e8307068b6db620e4a39d068b5dee5d6ef5788cbb2c0b6d23ead84fcc17178c
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 5.
| CN=Root YR, O=ISRG, C=US
| 03.09.2025
| 03.09.2032 expires in 2218 days |
|
| 5.
| CN=Root YR, O=ISRG, C=US
| 03.09.2025
03.09.2032 expires in 2218 days |
|
|
|
| | Keyalgorithm | RSA encryption (4096 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 00FAA6275DC258431D9766EC3045EF24AC
| | Thumbprint: | 18F47BAE342367CBBF120681E6721D6AADC386C7
| | SHA256 / Certificate: | JwxktroarpSwdW6D2NsHMvW1NLzcVF1E4zTV3U0Q/sA=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 7e4e8838a8add6295de7ae3b047d3aba3488ab95db0a0aa56d897a00d8618bcf
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
| 6.
| CN=Root YR, O=ISRG, C=US
| 13.05.2026
| 03.09.2032 expires in 2218 days |
|
| 6.
| CN=Root YR, O=ISRG, C=US
| 13.05.2026
03.09.2032 expires in 2218 days |
|
|
|
| | Keyalgorithm | RSA encryption (4096 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 00F24B6D17F9D9AD7CB1C9FEA78782699F
| | Thumbprint: | AB9D0263244DD0326EB67015705A667E79CFE998
| | SHA256 / Certificate: | ByY50LFA1b/64WrZw/bMYIYEBiH1HuYabUaokVwHz3Y=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 7e4e8838a8add6295de7ae3b047d3aba3488ab95db0a0aa56d897a00d8618bcf
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 7.
| CN=ISRG Root X1, O=Internet Security Research Group, C=US
| 04.06.2015
| 04.06.2035 expires in 3222 days |
|
| 7.
| CN=ISRG Root X1, O=Internet Security Research Group, C=US
| 04.06.2015
04.06.2035 expires in 3222 days |
|
|
|
| | Keyalgorithm | RSA encryption (4096 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 008210CFB0D240E3594463E0BB63828B00
| | Thumbprint: | CABD2A79A1076A31F21D253635CB039D4329A5E8
| | SHA256 / Certificate: | lrzsBiZJdvN0YHeazyjFp8/oo8Cq4RqP/O4FwL3fCMY=
| | SHA256 hex / Cert (DANE * 0 1): | 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
| | SHA256 hex / PublicKey (DANE * 1 1): | 0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
| | SHA256 hex / Subject Public Key Information (SPKI): | 0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|
| 8.
| CN=ISRG Root X1, O=Internet Security Research Group, C=US
| 04.06.2015
| 04.06.2035 expires in 3222 days |
|
| 8.
| CN=ISRG Root X1, O=Internet Security Research Group, C=US
| 04.06.2015
04.06.2035 expires in 3222 days |
|
|
|
| | Keyalgorithm | RSA encryption (4096 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 008210CFB0D240E3594463E0BB63828B00
| | Thumbprint: | CABD2A79A1076A31F21D253635CB039D4329A5E8
| | SHA256 / Certificate: | lrzsBiZJdvN0YHeazyjFp8/oo8Cq4RqP/O4FwL3fCMY=
| | SHA256 hex / Cert (DANE * 0 1): | 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
| | SHA256 hex / PublicKey (DANE * 1 1): | 0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
| | SHA256 hex / Subject Public Key Information (SPKI): | 0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|
3.
| 1.
| CN=canary-certificate-for-noop.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.06.2026
| 15.07.2026 24 days expired | canary-certificate-for-noop.spotify.com - 1 entry
|
3.
| 1.
| CN=canary-certificate-for-noop.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.06.2026
15.07.2026 24 days expired |
|
| canary-certificate-for-noop.spotify.com - 1 entry
|
| | Keyalgorithm | EC Public Key (256 bit, prime256v1) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0111F27164ED6798D5FB156692F9B2DD
| | Thumbprint: | 29AA40F110BA8E965F7AC5E0688A1C1CB95E73E3
| | SHA256 / Certificate: | Flnbk4EOAt4VXKdccatGMuJpnhsFPKax/gqnCFJbrJ4=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 3fc2b54fa58005691a5ca6d0627b56b30ae7cd39134912a83109ab3fc7f717fd
| | SHA256 hex / Subject Public Key Information (SPKI): | 3fc2b54fa58005691a5ca6d0627b56b30ae7cd39134912a83109ab3fc7f717fd (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 2.
| CN=canary-certificate-for-noop.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.06.2026
| 15.07.2026 24 days expired | canary-certificate-for-noop.spotify.com - 1 entry
|
| 2.
| CN=canary-certificate-for-noop.spotify.com, O=Spotify AB, L=Stockholm, C=SE
| 08.06.2026
15.07.2026 24 days expired |
|
| canary-certificate-for-noop.spotify.com - 1 entry
|
| | Keyalgorithm | EC Public Key (256 bit, prime256v1) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0111F27164ED6798D5FB156692F9B2DD
| | Thumbprint: | 29AA40F110BA8E965F7AC5E0688A1C1CB95E73E3
| | SHA256 / Certificate: | Flnbk4EOAt4VXKdccatGMuJpnhsFPKax/gqnCFJbrJ4=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 3fc2b54fa58005691a5ca6d0627b56b30ae7cd39134912a83109ab3fc7f717fd
| | SHA256 hex / Subject Public Key Information (SPKI): | 3fc2b54fa58005691a5ca6d0627b56b30ae7cd39134912a83109ab3fc7f717fd (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 3.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
| 30.03.2031 expires in 1695 days |
|
| 3.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
30.03.2031 expires in 1695 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0CF5BD062B5602F47AB8502C23CCF066
| | Thumbprint: | 1B511ABEAD59C6CE207077C0BF0E0043B1382612
| | SHA256 / Certificate: | yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)
|
|
|
|
| 4.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
| 30.03.2031 expires in 1695 days |
|
| 4.
| CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
| 30.03.2021
30.03.2031 expires in 1695 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0CF5BD062B5602F47AB8502C23CCF066
| | Thumbprint: | 1B511ABEAD59C6CE207077C0BF0E0043B1382612
| | SHA256 / Certificate: | yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: | http://ocsp.digicert.com
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)
|
|
|
|
| 5.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 01.08.2013
| 15.01.2038 expires in 4178 days |
|
| 5.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 01.08.2013
15.01.2038 expires in 4178 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 033AF1E6A711A9A0BB2864B11D09FAE5
| | Thumbprint: | DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
| | SHA256 / Certificate: | yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
| | SHA256 hex / Cert (DANE * 0 1): | cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
| | SHA256 hex / PublicKey (DANE * 1 1): | 8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
| | SHA256 hex / Subject Public Key Information (SPKI): | 8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|
| 6.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 29.10.2024
| 09.11.2031 expires in 1919 days |
|
| 6.
| CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
| 29.10.2024
09.11.2031 expires in 1919 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 0E7D75235CA83761577F4CCD24CD6D1D
| | Thumbprint: | B7402517EEAAC80AB04681186E8247BD7851CD0A
| | SHA256 / Certificate: | oNYJp+PENOh4qaHBvQZbjc8zqn7+4bEbx1zOXloEIIA=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: | http://ocsp.digicert.cn
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
| 7.
| CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
| 10.11.2006
| 10.11.2031 expires in 1920 days |
|
| 7.
| CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
| 10.11.2006
10.11.2031 expires in 1920 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA-1 with RSA Encryption
| | Serial Number: | 02AC5C266A0B409B8F0B79F2AE462577
| | Thumbprint: | 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
| | SHA256 / Certificate: | dDHl9MPBzkaQd08LYeBUQIg7qaAe0Aumq9eAbtOxGM8=
| | SHA256 hex / Cert (DANE * 0 1): | 7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf
| | SHA256 hex / PublicKey (DANE * 1 1): | 5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
| | SHA256 hex / Subject Public Key Information (SPKI): | 5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|
4.
| 1.
| CN=s.sni-810-default.ssl.fastly.net
| 11.06.2026
| 11.07.2026 28 days expired | s.sni-810-default.ssl.fastly.net - 1 entry
|
4.
| 1.
| CN=s.sni-810-default.ssl.fastly.net
| 11.06.2026
11.07.2026 28 days expired |
|
| s.sni-810-default.ssl.fastly.net - 1 entry
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 78675DF43A1C7B8289EBF0787A863888C9FA
| | Thumbprint: | 97B68E95C3BFC5C534DCE12D3AB882C0BDDFDC0C
| | SHA256 / Certificate: | wnwX0FMpTkLkdXiuTaQkjmW20S0SN5pdLLlx2+cZeUg=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | cf389b613dc87737646952da7d4d91c9465a866fbcace34117988c07c4cda552
| | SHA256 hex / Subject Public Key Information (SPKI): | cf389b613dc87737646952da7d4d91c9465a866fbcace34117988c07c4cda552 (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 2.
| CN=Certainly Intermediate R1, O=Certainly, C=US
| 22.06.2022
| 22.06.2032 expires in 2145 days |
|
| 2.
| CN=Certainly Intermediate R1, O=Certainly, C=US
| 22.06.2022
22.06.2032 expires in 2145 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 11831CDE4CB573E5
| | Thumbprint: | FEDEA3AA3B69BF9B84DB1FBE46855AF990EDBDB1
| | SHA256 / Certificate: | /sQeMsp1wpWmJA+mOdOr47+1yxMdZpDiMxoXa+0uW9I=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | a16eec98284c251727cd339b17b2be1f322745e00f4f107f2f587a7994e6c3d4
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)
|
|
|
|
| 3.
| CN=Starfield Root Certificate Authority - G2, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US
| 01.09.2009
| 01.01.2038 expires in 4164 days |
|
| 3.
| CN=Starfield Root Certificate Authority - G2, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US
| 01.09.2009
01.01.2038 expires in 4164 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 00
| | Thumbprint: | B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E
| | SHA256 / Certificate: | LOHLC/nS+eECmT++IVFSw7LdDKveHGjlMZuDkVTbt/U=
| | SHA256 hex / Cert (DANE * 0 1): | 2ce1cb0bf9d2f9e102993fbe215152c3b2dd0cabde1c68e5319b839154dbb7f5
| | SHA256 hex / PublicKey (DANE * 1 1): | 808d68b3fab4884a5f971ace7d10550d7a95a163774f3ec36afffb213fbe4c74
| | SHA256 hex / Subject Public Key Information (SPKI): | 808d68b3fab4884a5f971ace7d10550d7a95a163774f3ec36afffb213fbe4c74
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|
5.
| 1.
| CN=open.spotify.com
| 31.05.2026
| 30.06.2026 39 days expired | open.spotify.com - 1 entry
|
5.
| 1.
| CN=open.spotify.com
| 31.05.2026
30.06.2026 39 days expired |
|
| open.spotify.com - 1 entry
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 787B1B0E9371D613649B25EFAF84DF455D88
| | Thumbprint: | 609854AB3587FB87ABA7A328EB73C489435D4CD0
| | SHA256 / Certificate: | KX0wAdthm9OeB193oN42QQg7u8eQRqJh7wvmO5mdDyQ=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | 29bdbbe0c4e977cd2e7e6350173814dfc39e3c3c255ffe532bced0407a0c5278
| | SHA256 hex / Subject Public Key Information (SPKI): | 29bdbbe0c4e977cd2e7e6350173814dfc39e3c3c255ffe532bced0407a0c5278 (is buggy, ignore the result)
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | yes
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1)
|
|
|
|
| 2.
| CN=Certainly Intermediate R1, O=Certainly, C=US
| 22.06.2022
| 22.06.2032 expires in 2145 days |
|
| 2.
| CN=Certainly Intermediate R1, O=Certainly, C=US
| 22.06.2022
22.06.2032 expires in 2145 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 11831CDE4CB573E5
| | Thumbprint: | FEDEA3AA3B69BF9B84DB1FBE46855AF990EDBDB1
| | SHA256 / Certificate: | /sQeMsp1wpWmJA+mOdOr47+1yxMdZpDiMxoXa+0uW9I=
| | SHA256 hex / Cert (DANE * 0 1): | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
| | SHA256 hex / PublicKey (DANE * 1 1): | a16eec98284c251727cd339b17b2be1f322745e00f4f107f2f587a7994e6c3d4
| | SHA256 hex / Subject Public Key Information (SPKI): |
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Check unknown. No result 404 / 200
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: | Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)
|
|
|
|
| 3.
| CN=Starfield Root Certificate Authority - G2, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US
| 01.09.2009
| 01.01.2038 expires in 4164 days |
|
| 3.
| CN=Starfield Root Certificate Authority - G2, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US
| 01.09.2009
01.01.2038 expires in 4164 days |
|
|
|
| | Keyalgorithm | RSA encryption (2048 bit) | | Signatur: | SHA256 With RSA-Encryption
| | Serial Number: | 00
| | Thumbprint: | B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E
| | SHA256 / Certificate: | LOHLC/nS+eECmT++IVFSw7LdDKveHGjlMZuDkVTbt/U=
| | SHA256 hex / Cert (DANE * 0 1): | 2ce1cb0bf9d2f9e102993fbe215152c3b2dd0cabde1c68e5319b839154dbb7f5
| | SHA256 hex / PublicKey (DANE * 1 1): | 808d68b3fab4884a5f971ace7d10550d7a95a163774f3ec36afffb213fbe4c74
| | SHA256 hex / Subject Public Key Information (SPKI): | 808d68b3fab4884a5f971ace7d10550d7a95a163774f3ec36afffb213fbe4c74
| | SPKI checked via https://v1.pwnedkeys.com/spki-hash: | Good: Key isn't compromised
| | OCSP - Url: |
| | OCSP - must staple: | no
| | Certificate Transparency: | no
| | Enhanced Key Usage: |
|
|
|
|
|