← All DigiCert certificates
Intermediate Certificate

BT Class 2 CA - G3

DigiCertCCADBCA Organization name as it appears in the CA's CP, CPS, CP/CPS and audit statements.
⚠ This certificate has been revoked
Browser Trust
Apple
AppleCCADBCertificate status in Apple: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
CCADB status only
Chrome
ChromeCCADBCertificate status in Google Chrome: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
No direct match
Microsoft
MicrosoftCCADBCertificate status in Microsoft: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
No direct match
Mozilla
MozillaCCADBCertificate status in Mozilla: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Not Trusted
No direct match
Cross-Signing (1)
Other CCADB certificate records sharing this certificate's Subject Key Identifier — the same key pair issued more than once (cross-signed by a different root, or a prior/next root during a transition).
1 BT Class 2 CA - G3
SubjectComputed locallyThis related certificate's own distinguished name, parsed from its PEM. C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 ↗
IssuerComputed locallyThe distinguished name of the CA that signed this related certificate, parsed from its PEM. C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 2 Public Primary Certification Authority - G3 ↗
Intermediate Certificate · 2014-12-16 – 2024-12-15
AppleChromeMicrosoftMozilla
Certificate Details
Record TypeCCADBCCADB field: Certificate Record TypeOne of two values determined when certificate is added to the CCADB:
  • Intermediate Certificate
  • Root Certificate
Intermediate Certificate
Subject DNComputed locallyThe certificate's own distinguished name, parsed from its PEM. This identifies who the certificate was issued to.
C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3
Issuer DNComputed locallyThe distinguished name of the CA that signed this certificate, parsed from its PEM. This identifies who issued it.
C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 2 Public Primary Certification Authority - G3 ↗
SHA-256CCADBCCADB field: SHA-256 FingerprintA SHA-256 hash of the certificate generated by the CCADB when adding a certificate PEM.
AA257A6CE4A1EB7F6A508B5037D81DE2782C8D8AEA0127DE1E31150218BEDA75
Parent SHA-256CCADBCCADB field: Parent SHA-256 FingerprintA SHA-256 hash of the parent certificate, as generated by the CCADB when the parent certificate PEM was added.
92A9D9833FE1944DB366E8BFAE7A95B6480C2D6C6C2A1BE65D4236B608FCA1BB
Valid From (GMT)CCADBThe notBefore value extracted from the certificate PEM.
2014.12.16
Valid To (GMT)CCADBThe notAfter value extracted from the certificate PEM.
2024.12.15
AKICCADBCCADB field: Authority Key IdentifierThe authorityKeyIdentifier value extracted from the certificate PEM.
SKICCADBCCADB field: Subject Key IdentifierThe subjectKeyIdentifier value extracted from the certificate PEM.
6HzzrH/o3WQEh7tbZb6PkP1kGVs=
Operated ByCCADBCCADB field: Subordinate CA OwnerThis is the subordinate CA Owner's name as it appears in the provided audit statements. CA Owners MUST NOT leave this field blank unless both control of the private key and domain/IP control validation activities are performed by the organization listed in the audit statement of the parent certificate.
British Telecommunications plc
ConstrainedCCADBCCADB field: Technically ConstrainedA boolean value configured by the CCADB when the certificate PEM was added. Set to FALSE if the certificate does not contain an Extended Key Usage (EKU) extension. Set to TRUE if the EKU does not contain id-kp-serverAuth or anyExtendedKeyUsage. If the EKU contains id-kp-serverAuth, then set to TRUE if the certificate includes the Name Constraints X.509v3 extension with constraints on dNSName, iPAddress and DirectoryName. Otherwise set to FALSE.
False
RevocationCCADBCCADB field: Revocation StatusOnly applicable to the Intermediate Certificate record type, the revocation status for this certificate as configured by the CA Owner.
  • –None–
  • Not Revoked
  • Revoked
  • Parent Cert Revoked
✗ Revoked
Salesforce IDCCADBCCADB field: Salesforce Record IDAn internal unique ID for this certificate in the CCADB. This value is assigned by the CCADB.
0011J00001FudH8QAJ
Capabilities
EV OIDsCCADBCCADB field: EV OIDs for Root CertThis field is updated once daily by a batch program in the CCADB. It includes the union of all EV OIDs, as specified by Root Store Operators.
Status of RootCCADBCCADB field: Status of Root CertRoot Store inclusion status for the root certificate that this intermediate certificate chains up to in the CCADB. (Updated via hourly batch process)
Apple
Removed
Google Chrome
Not Included
Microsoft
Included
Mozilla
Removed
TLSCCADBCCADB field: TLS CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Server Authentication.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Server Authentication.
  • Otherwise set to FALSE.
TLS EVCCADBCCADB field: TLS EV CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Apple EV Enabled' is set to TRUE, or 'ExtendedValidation.cpp OIDs is not null, or 'Microsoft EV_SSL_Enabled is set to TRUE, or 'Google Chrome EV Enabled' is set to TRUE.
  • Set to TRUE for an intermediate certificate record if 'EV SSL Capable' is set to TRUE.
  • Otherwise set to FALSE.
Code SigningCCADBCCADB field: Code Signing CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Code Signing.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Code Signing.
  • Otherwise set to FALSE.
S/MIMECCADBCCADB field: S/MIME CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Secure Email.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Secure Email.
  • Otherwise set to FALSE.
VMCCCADBCCADB field: VMC CapableNot documented as a separate field in the CCADB data dictionary. Computed by CCADB using the same Trust Bits / Derived Trust Bits mechanism as the other capability flags, for Verified Mark Certificates.Document SigningCCADBCCADB field: Document Signing CapableNot documented as a separate field in the CCADB data dictionary. Computed by CCADB using the same Trust Bits / Derived Trust Bits mechanism as the other capability flags, for document signing EKU.
CAA IdentifiersCCADBCCADB field: AllCAAIdentifiersReportCSVV2A separate CCADB report, not part of the main certificate record (AllCertificateRecordsCSVFormatV5) used elsewhere on this page. CA Owners disclose the CAA issuer domain label(s) they use in DNS CAA records, tied to the specific intermediate certificate and Subject Key Identifier each declaration applies to.
Recognized CAA issuer identifiers published by CCADB for this CA certificate.
Not Applicable
Audit
Audit FirmCCADBCCADB field: AuditorA picklist value for the name of the Audit Firm that issued the audit statements, as selected by the CA Owner.
Firm LocationCCADBCCADB field: Audit Firm LocationNot documented as a separate field in the CCADB data dictionary. Disclosed alongside Auditor.
Same as ParentCCADBCCADB field: Audits Same as Parent?A boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if the current or next audit of the parent certificate includes this certificate. Otherwise set to FALSE, and all applicable audit fields must have values provided by the CA Owner.
false
Policy & Documentation
CP URLCCADBCCADB field: Certificate Policy (CP) URLThe URL to CP documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CP Same as Parent' is set to FALSE.
CP Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same Certificate Policy (CP) information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
CP EffectiveCCADBCCADB field: CP Effective DateThe date the CP documentation specific to this certificate became effective, as configured by the CA Owner. This value must be populated if 'CP Same as Parent' is set to FALSE.
CPS URLCCADBCCADB field: Certificate Practice Statement (CPS) URLThe URL to CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CPS Same as Parent' is set to FALSE.
CPS Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same Certification Practice Statement (CPS) information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
CPS EffectiveCCADBCCADB field: CPS Effective DateThe date the CPS documentation specific to this certificate became effective, as configured by the CA Owner. This value must be populated if 'CPS Same as Parent' is set to FALSE.
CP/CPS StatementCCADBCCADB field: Certificate Practice & Policy StatementThe URL to the combined CP/CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CP/CPS Same as Parent' is set to FALSE.
CP/CPS Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same combined CP/CPS information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
MD/AsciiDoc URLCCADBCCADB field: MD/AsciiDoc CP/CPS URLThe URL to the combined Markdown or AsciiDoc CP/CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'MD/AsciiDoc CP/CPS Same as Parent' is set to FALSE.
MD/AsciiDoc Same as ParentCCADBCCADB field: MD/AsciiDoc CP/CPS Same as ParentA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same combined Markdown or AsciiDoc CP/CPS information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
Infrastructure
CRL (Full)CCADBCCADB field: JSON Array of All Full CRL URLsNot the exact documented field (the data dictionary describes an older single-URL "Full CRL Issued By This CA" field); this is its JSON-array successor in the current V5 report, holding the full CRL URL(s) for certificates issued by this CA, as configured by the CA Owner.
CRL (Parts)CCADBCCADB field: JSON Array of Partitioned CRLsWhen there is no full CRL for certificates issued by this CA, the CA Owner can provide a JSON array whose elements are URLs of partitioned, DER-encoded CRLs that when combined are the equivalent of a full CRL for certificates issued by this CA. The JSON array may omit obsolete partitioned CRLs whose scopes only include expired certificates.
ACME DVCCADBCCADB field: DV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Domain Validated issuance, as configured by the CA Owner.
ACME OVCCADBCCADB field: OV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Organization Validated issuance, as configured by the CA Owner.
ACME EVCCADBCCADB field: EV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Extended Validation issuance, as configured by the CA Owner.
Test (Valid)CCADBCCADB field: Test Website URL - ValidThe URL to a website with a valid TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Test (Expired)CCADBCCADB field: Test Website URL - ExpiredThe URL to a website with an expired TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Test (Revoked)CCADBCCADB field: Test Website URL - RevokedThe URL to a website with a revoked TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Policy OIDs
Certificate X.509 certificatePolicies
2.16.840.1.113733.1.7.23.2
CCADB EV OIDs for Root Cert · administrative declaration
Declared on root: VeriSign Class 2 Public Primary Certification Authority - G3
No EV OIDs declared on the root
Comparison
Certificate declares policy OIDs not found in CCADB
Chain Validation
Certificate Lint (zlint, live)
pkimetal
Certificate (PEM)
crt.sh via Matador
By SPKI SHA-256 → All CT log entries sharing this public key, deduplicated — the broadest CT search for a CA
By SHA-256 → Look up this exact certificate by its fingerprint
By SKI → All certificates sharing this Subject Key Identifier
Issued Certificates → Resolve crt.sh issuer CA ID, then paginate all certificates issued by this CA
Mozilla OneCRL
StatusNameIssuerSerialBugModified
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 180A17ED270F7F1CFC6288853397AABE 2020-02-25
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 4803A931DA493CD982A1F5F9B30679A1 2019-09-12
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 0A419C690405F225236EB2B0AFA4FAF7 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 393DC768102C5D23B5100EF8F595716E 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 66DC537B23F7BA5FBBA86E0FB3AA7161 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 76B8BF3BD2D23CE7E4A0BF58A22ADE08 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 65A8D92980E4373BE52DCCAC0878C862 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 6BED58D4338489DED5D7851716B97900 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 6F29ADBDCA31642C4F581DE0F9E984E7 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 6FE46D83BA8D5C16985BE8D53F94D813 2019-05-09
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 5F8D3B9D6C980BBBBC942AC1AD6D9C44 1465399 2018-05-30
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 5BD2838D9BDA0DE5B03788D01BD4CEDF 1465399 2018-05-30
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 4561EC472CCFDCA1728E14CB3CEE053C 1465399 2018-05-30
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 25E92F7D59F7876F8E5FF57C11FEAFA6 1465399 2018-05-30
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 68AB19AD60E9B059552F4C644A16F6D8 1465399 2018-05-30
enabled C=GB, O=British Telecommunications plc, OU=Symantec Trust Network, CN=BT Class 2 CA - G3 485B85AC507B3199D9EADB2AC12E3BB7 1465399 2018-05-30

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action