This page lists every field whose value can be searched within the Certificates dataset.

The difference between a keyword and a text field is that searches on keyword fields will only return exact matches, while searches on text fields will return fuzzy matches.

Certificates

Path Type Repeated Docs
ct Subrecord No
ct.akamai_ct Subrecord No
ct.akamai_ct.added_to_ct_at Date No
ct.akamai_ct.censys_to_ct_at Date No
ct.akamai_ct.ct_to_censys_at Date No
ct.akamai_ct.index Long No
ct.akamai_ct.sct String No
ct.behind_the_sofa Subrecord No
ct.behind_the_sofa.added_to_ct_at Date No
ct.behind_the_sofa.censys_to_ct_at Date No
ct.behind_the_sofa.ct_to_censys_at Date No
ct.behind_the_sofa.index Long No
ct.behind_the_sofa.sct String No
ct.certificatetransparency_cn_ct Subrecord No
ct.certificatetransparency_cn_ct.added_to_ct_at Date No
ct.certificatetransparency_cn_ct.censys_to_ct_at Date No
ct.certificatetransparency_cn_ct.ct_to_censys_at Date No
ct.certificatetransparency_cn_ct.index Long No
ct.certificatetransparency_cn_ct.sct String No
ct.certly_log Subrecord No
ct.certly_log.added_to_ct_at Date No
ct.certly_log.censys_to_ct_at Date No
ct.certly_log.ct_to_censys_at Date No
ct.certly_log.index Long No
ct.certly_log.sct String No
ct.cloudflare_nimbus_2017 Subrecord No
ct.cloudflare_nimbus_2017.added_to_ct_at Date No
ct.cloudflare_nimbus_2017.censys_to_ct_at Date No
ct.cloudflare_nimbus_2017.ct_to_censys_at Date No
ct.cloudflare_nimbus_2017.index Long No
ct.cloudflare_nimbus_2017.sct String No
ct.cloudflare_nimbus_2018 Subrecord No
ct.cloudflare_nimbus_2018.added_to_ct_at Date No
ct.cloudflare_nimbus_2018.censys_to_ct_at Date No
ct.cloudflare_nimbus_2018.ct_to_censys_at Date No
ct.cloudflare_nimbus_2018.index Long No
ct.cloudflare_nimbus_2018.sct String No
ct.cloudflare_nimbus_2019 Subrecord No
ct.cloudflare_nimbus_2019.added_to_ct_at Date No
ct.cloudflare_nimbus_2019.censys_to_ct_at Date No
ct.cloudflare_nimbus_2019.ct_to_censys_at Date No
ct.cloudflare_nimbus_2019.index Long No
ct.cloudflare_nimbus_2019.sct String No
ct.cloudflare_nimbus_2020 Subrecord No
ct.cloudflare_nimbus_2020.added_to_ct_at Date No
ct.cloudflare_nimbus_2020.censys_to_ct_at Date No
ct.cloudflare_nimbus_2020.ct_to_censys_at Date No
ct.cloudflare_nimbus_2020.index Long No
ct.cloudflare_nimbus_2020.sct String No
ct.cloudflare_nimbus_2021 Subrecord No
ct.cloudflare_nimbus_2021.added_to_ct_at Date No
ct.cloudflare_nimbus_2021.censys_to_ct_at Date No
ct.cloudflare_nimbus_2021.ct_to_censys_at Date No
ct.cloudflare_nimbus_2021.index Long No
ct.cloudflare_nimbus_2021.sct String No
ct.cloudflare_nimbus_2022 Subrecord No
ct.cloudflare_nimbus_2022.added_to_ct_at Date No
ct.cloudflare_nimbus_2022.censys_to_ct_at Date No
ct.cloudflare_nimbus_2022.ct_to_censys_at Date No
ct.cloudflare_nimbus_2022.index Long No
ct.cloudflare_nimbus_2022.sct String No
ct.cloudflare_nimbus_2023 Subrecord No
ct.cloudflare_nimbus_2023.added_to_ct_at Date No
ct.cloudflare_nimbus_2023.censys_to_ct_at Date No
ct.cloudflare_nimbus_2023.ct_to_censys_at Date No
ct.cloudflare_nimbus_2023.index Long No
ct.cloudflare_nimbus_2023.sct String No
ct.cnnic_ctserver Subrecord No
ct.cnnic_ctserver.added_to_ct_at Date No
ct.cnnic_ctserver.censys_to_ct_at Date No
ct.cnnic_ctserver.ct_to_censys_at Date No
ct.cnnic_ctserver.index Long No
ct.cnnic_ctserver.sct String No
ct.comodo_dodo Subrecord No
ct.comodo_dodo.added_to_ct_at Date No
ct.comodo_dodo.censys_to_ct_at Date No
ct.comodo_dodo.ct_to_censys_at Date No
ct.comodo_dodo.index Long No
ct.comodo_dodo.sct String No
ct.comodo_mammoth Subrecord No
ct.comodo_mammoth.added_to_ct_at Date No
ct.comodo_mammoth.censys_to_ct_at Date No
ct.comodo_mammoth.ct_to_censys_at Date No
ct.comodo_mammoth.index Long No
ct.comodo_mammoth.sct String No
ct.comodo_sabre Subrecord No
ct.comodo_sabre.added_to_ct_at Date No
ct.comodo_sabre.censys_to_ct_at Date No
ct.comodo_sabre.ct_to_censys_at Date No
ct.comodo_sabre.index Long No
ct.comodo_sabre.sct String No
ct.ctlogs_alpha Subrecord No
ct.ctlogs_alpha.added_to_ct_at Date No
ct.ctlogs_alpha.censys_to_ct_at Date No
ct.ctlogs_alpha.ct_to_censys_at Date No
ct.ctlogs_alpha.index Long No
ct.ctlogs_alpha.sct String No
ct.digicert_ct1 Subrecord No
ct.digicert_ct1.added_to_ct_at Date No
ct.digicert_ct1.censys_to_ct_at Date No
ct.digicert_ct1.ct_to_censys_at Date No
ct.digicert_ct1.index Long No
ct.digicert_ct1.sct String No
ct.digicert_ct2 Subrecord No
ct.digicert_ct2.added_to_ct_at Date No
ct.digicert_ct2.censys_to_ct_at Date No
ct.digicert_ct2.ct_to_censys_at Date No
ct.digicert_ct2.index Long No
ct.digicert_ct2.sct String No
ct.digicert_golem Subrecord No
ct.digicert_golem.added_to_ct_at Date No
ct.digicert_golem.censys_to_ct_at Date No
ct.digicert_golem.ct_to_censys_at Date No
ct.digicert_golem.index Long No
ct.digicert_golem.sct String No
ct.digicert_nessie_2018 Subrecord No
ct.digicert_nessie_2018.added_to_ct_at Date No
ct.digicert_nessie_2018.censys_to_ct_at Date No
ct.digicert_nessie_2018.ct_to_censys_at Date No
ct.digicert_nessie_2018.index Long No
ct.digicert_nessie_2018.sct String No
ct.digicert_nessie_2019 Subrecord No
ct.digicert_nessie_2019.added_to_ct_at Date No
ct.digicert_nessie_2019.censys_to_ct_at Date No
ct.digicert_nessie_2019.ct_to_censys_at Date No
ct.digicert_nessie_2019.index Long No
ct.digicert_nessie_2019.sct String No
ct.digicert_nessie_2020 Subrecord No
ct.digicert_nessie_2020.added_to_ct_at Date No
ct.digicert_nessie_2020.censys_to_ct_at Date No
ct.digicert_nessie_2020.ct_to_censys_at Date No
ct.digicert_nessie_2020.index Long No
ct.digicert_nessie_2020.sct String No
ct.digicert_nessie_2021 Subrecord No
ct.digicert_nessie_2021.added_to_ct_at Date No
ct.digicert_nessie_2021.censys_to_ct_at Date No
ct.digicert_nessie_2021.ct_to_censys_at Date No
ct.digicert_nessie_2021.index Long No
ct.digicert_nessie_2021.sct String No
ct.digicert_nessie_2022 Subrecord No
ct.digicert_nessie_2022.added_to_ct_at Date No
ct.digicert_nessie_2022.censys_to_ct_at Date No
ct.digicert_nessie_2022.ct_to_censys_at Date No
ct.digicert_nessie_2022.index Long No
ct.digicert_nessie_2022.sct String No
ct.digicert_nessie_2023 Subrecord No
ct.digicert_nessie_2023.added_to_ct_at Date No
ct.digicert_nessie_2023.censys_to_ct_at Date No
ct.digicert_nessie_2023.ct_to_censys_at Date No
ct.digicert_nessie_2023.index Long No
ct.digicert_nessie_2023.sct String No
ct.digicert_yeti_2018 Subrecord No
ct.digicert_yeti_2018.added_to_ct_at Date No
ct.digicert_yeti_2018.censys_to_ct_at Date No
ct.digicert_yeti_2018.ct_to_censys_at Date No
ct.digicert_yeti_2018.index Long No
ct.digicert_yeti_2018.sct String No
ct.digicert_yeti_2019 Subrecord No
ct.digicert_yeti_2019.added_to_ct_at Date No
ct.digicert_yeti_2019.censys_to_ct_at Date No
ct.digicert_yeti_2019.ct_to_censys_at Date No
ct.digicert_yeti_2019.index Long No
ct.digicert_yeti_2019.sct String No
ct.digicert_yeti_2020 Subrecord No
ct.digicert_yeti_2020.added_to_ct_at Date No
ct.digicert_yeti_2020.censys_to_ct_at Date No
ct.digicert_yeti_2020.ct_to_censys_at Date No
ct.digicert_yeti_2020.index Long No
ct.digicert_yeti_2020.sct String No
ct.digicert_yeti_2021 Subrecord No
ct.digicert_yeti_2021.added_to_ct_at Date No
ct.digicert_yeti_2021.censys_to_ct_at Date No
ct.digicert_yeti_2021.ct_to_censys_at Date No
ct.digicert_yeti_2021.index Long No
ct.digicert_yeti_2021.sct String No
ct.digicert_yeti_2022 Subrecord No
ct.digicert_yeti_2022.added_to_ct_at Date No
ct.digicert_yeti_2022.censys_to_ct_at Date No
ct.digicert_yeti_2022.ct_to_censys_at Date No
ct.digicert_yeti_2022.index Long No
ct.digicert_yeti_2022.sct String No
ct.digicert_yeti_2023 Subrecord No
ct.digicert_yeti_2023.added_to_ct_at Date No
ct.digicert_yeti_2023.censys_to_ct_at Date No
ct.digicert_yeti_2023.ct_to_censys_at Date No
ct.digicert_yeti_2023.index Long No
ct.digicert_yeti_2023.sct String No
ct.gdca_ct Subrecord No
ct.gdca_ct.added_to_ct_at Date No
ct.gdca_ct.censys_to_ct_at Date No
ct.gdca_ct.ct_to_censys_at Date No
ct.gdca_ct.index Long No
ct.gdca_ct.sct String No
ct.gdca_ctlog Subrecord No
ct.gdca_ctlog.added_to_ct_at Date No
ct.gdca_ctlog.censys_to_ct_at Date No
ct.gdca_ctlog.ct_to_censys_at Date No
ct.gdca_ctlog.index Long No
ct.gdca_ctlog.sct String No
ct.gdca_log Subrecord No
ct.gdca_log.added_to_ct_at Date No
ct.gdca_log.censys_to_ct_at Date No
ct.gdca_log.ct_to_censys_at Date No
ct.gdca_log.index Long No
ct.gdca_log.sct String No
ct.gdca_log2 Subrecord No
ct.gdca_log2.added_to_ct_at Date No
ct.gdca_log2.censys_to_ct_at Date No
ct.gdca_log2.ct_to_censys_at Date No
ct.gdca_log2.index Long No
ct.gdca_log2.sct String No
ct.google_argon_2017 Subrecord No
ct.google_argon_2017.added_to_ct_at Date No
ct.google_argon_2017.censys_to_ct_at Date No
ct.google_argon_2017.ct_to_censys_at Date No
ct.google_argon_2017.index Long No
ct.google_argon_2017.sct String No
ct.google_argon_2018 Subrecord No
ct.google_argon_2018.added_to_ct_at Date No
ct.google_argon_2018.censys_to_ct_at Date No
ct.google_argon_2018.ct_to_censys_at Date No
ct.google_argon_2018.index Long No
ct.google_argon_2018.sct String No
ct.google_argon_2019 Subrecord No
ct.google_argon_2019.added_to_ct_at Date No
ct.google_argon_2019.censys_to_ct_at Date No
ct.google_argon_2019.ct_to_censys_at Date No
ct.google_argon_2019.index Long No
ct.google_argon_2019.sct String No
ct.google_argon_2020 Subrecord No
ct.google_argon_2020.added_to_ct_at Date No
ct.google_argon_2020.censys_to_ct_at Date No
ct.google_argon_2020.ct_to_censys_at Date No
ct.google_argon_2020.index Long No
ct.google_argon_2020.sct String No
ct.google_argon_2021 Subrecord No
ct.google_argon_2021.added_to_ct_at Date No
ct.google_argon_2021.censys_to_ct_at Date No
ct.google_argon_2021.ct_to_censys_at Date No
ct.google_argon_2021.index Long No
ct.google_argon_2021.sct String No
ct.google_argon_2022 Subrecord No
ct.google_argon_2022.added_to_ct_at Date No
ct.google_argon_2022.censys_to_ct_at Date No
ct.google_argon_2022.ct_to_censys_at Date No
ct.google_argon_2022.index Long No
ct.google_argon_2022.sct String No
ct.google_argon_2023 Subrecord No
ct.google_argon_2023.added_to_ct_at Date No
ct.google_argon_2023.censys_to_ct_at Date No
ct.google_argon_2023.ct_to_censys_at Date No
ct.google_argon_2023.index Long No
ct.google_argon_2023.sct String No
ct.google_aviator Subrecord No
ct.google_aviator.added_to_ct_at Date No
ct.google_aviator.censys_to_ct_at Date No
ct.google_aviator.ct_to_censys_at Date No
ct.google_aviator.index Long No
ct.google_aviator.sct String No
ct.google_daedalus Subrecord No
ct.google_daedalus.added_to_ct_at Date No
ct.google_daedalus.censys_to_ct_at Date No
ct.google_daedalus.ct_to_censys_at Date No
ct.google_daedalus.index Long No
ct.google_daedalus.sct String No
ct.google_icarus Subrecord No
ct.google_icarus.added_to_ct_at Date No
ct.google_icarus.censys_to_ct_at Date No
ct.google_icarus.ct_to_censys_at Date No
ct.google_icarus.index Long No
ct.google_icarus.sct String No
ct.google_pilot Subrecord No
ct.google_pilot.added_to_ct_at Date No
ct.google_pilot.censys_to_ct_at Date No
ct.google_pilot.ct_to_censys_at Date No
ct.google_pilot.index Long No
ct.google_pilot.sct String No
ct.google_rocketeer Subrecord No
ct.google_rocketeer.added_to_ct_at Date No
ct.google_rocketeer.censys_to_ct_at Date No
ct.google_rocketeer.ct_to_censys_at Date No
ct.google_rocketeer.index Long No
ct.google_rocketeer.sct String No
ct.google_skydiver Subrecord No
ct.google_skydiver.added_to_ct_at Date No
ct.google_skydiver.censys_to_ct_at Date No
ct.google_skydiver.ct_to_censys_at Date No
ct.google_skydiver.index Long No
ct.google_skydiver.sct String No
ct.google_submariner Subrecord No
ct.google_submariner.added_to_ct_at Date No
ct.google_submariner.censys_to_ct_at Date No
ct.google_submariner.ct_to_censys_at Date No
ct.google_submariner.index Long No
ct.google_submariner.sct String No
ct.google_testtube Subrecord No
ct.google_testtube.added_to_ct_at Date No
ct.google_testtube.censys_to_ct_at Date No
ct.google_testtube.ct_to_censys_at Date No
ct.google_testtube.index Long No
ct.google_testtube.sct String No
ct.google_xenon_2018 Subrecord No
ct.google_xenon_2018.added_to_ct_at Date No
ct.google_xenon_2018.censys_to_ct_at Date No
ct.google_xenon_2018.ct_to_censys_at Date No
ct.google_xenon_2018.index Long No
ct.google_xenon_2018.sct String No
ct.google_xenon_2019 Subrecord No
ct.google_xenon_2019.added_to_ct_at Date No
ct.google_xenon_2019.censys_to_ct_at Date No
ct.google_xenon_2019.ct_to_censys_at Date No
ct.google_xenon_2019.index Long No
ct.google_xenon_2019.sct String No
ct.google_xenon_2020 Subrecord No
ct.google_xenon_2020.added_to_ct_at Date No
ct.google_xenon_2020.censys_to_ct_at Date No
ct.google_xenon_2020.ct_to_censys_at Date No
ct.google_xenon_2020.index Long No
ct.google_xenon_2020.sct String No
ct.google_xenon_2021 Subrecord No
ct.google_xenon_2021.added_to_ct_at Date No
ct.google_xenon_2021.censys_to_ct_at Date No
ct.google_xenon_2021.ct_to_censys_at Date No
ct.google_xenon_2021.index Long No
ct.google_xenon_2021.sct String No
ct.google_xenon_2022 Subrecord No
ct.google_xenon_2022.added_to_ct_at Date No
ct.google_xenon_2022.censys_to_ct_at Date No
ct.google_xenon_2022.ct_to_censys_at Date No
ct.google_xenon_2022.index Long No
ct.google_xenon_2022.sct String No
ct.google_xenon_2023 Subrecord No
ct.google_xenon_2023.added_to_ct_at Date No
ct.google_xenon_2023.censys_to_ct_at Date No
ct.google_xenon_2023.ct_to_censys_at Date No
ct.google_xenon_2023.index Long No
ct.google_xenon_2023.sct String No
ct.izenpe_com_ct Subrecord No
ct.izenpe_com_ct.added_to_ct_at Date No
ct.izenpe_com_ct.censys_to_ct_at Date No
ct.izenpe_com_ct.ct_to_censys_at Date No
ct.izenpe_com_ct.index Long No
ct.izenpe_com_ct.sct String No
ct.izenpe_com_pilot Subrecord No
ct.izenpe_com_pilot.added_to_ct_at Date No
ct.izenpe_com_pilot.censys_to_ct_at Date No
ct.izenpe_com_pilot.ct_to_censys_at Date No
ct.izenpe_com_pilot.index Long No
ct.izenpe_com_pilot.sct String No
ct.izenpe_eus_ct Subrecord No
ct.izenpe_eus_ct.added_to_ct_at Date No
ct.izenpe_eus_ct.censys_to_ct_at Date No
ct.izenpe_eus_ct.ct_to_censys_at Date No
ct.izenpe_eus_ct.index Long No
ct.izenpe_eus_ct.sct String No
ct.letsencrypt_ct_birch Subrecord No
ct.letsencrypt_ct_birch.added_to_ct_at Date No
ct.letsencrypt_ct_birch.censys_to_ct_at Date No
ct.letsencrypt_ct_birch.ct_to_censys_at Date No
ct.letsencrypt_ct_birch.index Long No
ct.letsencrypt_ct_birch.sct String No
ct.letsencrypt_ct_clicky Subrecord No
ct.letsencrypt_ct_clicky.added_to_ct_at Date No
ct.letsencrypt_ct_clicky.censys_to_ct_at Date No
ct.letsencrypt_ct_clicky.ct_to_censys_at Date No
ct.letsencrypt_ct_clicky.index Long No
ct.letsencrypt_ct_clicky.sct String No
ct.letsencrypt_ct_faux Subrecord No
ct.letsencrypt_ct_faux.added_to_ct_at Date No
ct.letsencrypt_ct_faux.censys_to_ct_at Date No
ct.letsencrypt_ct_faux.ct_to_censys_at Date No
ct.letsencrypt_ct_faux.index Long No
ct.letsencrypt_ct_faux.sct String No
ct.letsencrypt_ct_oak Subrecord No
ct.letsencrypt_ct_oak.added_to_ct_at Date No
ct.letsencrypt_ct_oak.censys_to_ct_at Date No
ct.letsencrypt_ct_oak.ct_to_censys_at Date No
ct.letsencrypt_ct_oak.index Long No
ct.letsencrypt_ct_oak.sct String No
ct.letsencrypt_ct_oak_2019 Subrecord No
ct.letsencrypt_ct_oak_2019.added_to_ct_at Date No
ct.letsencrypt_ct_oak_2019.censys_to_ct_at Date No
ct.letsencrypt_ct_oak_2019.ct_to_censys_at Date No
ct.letsencrypt_ct_oak_2019.index Long No
ct.letsencrypt_ct_oak_2019.sct String No
ct.letsencrypt_ct_oak_2020 Subrecord No
ct.letsencrypt_ct_oak_2020.added_to_ct_at Date No
ct.letsencrypt_ct_oak_2020.censys_to_ct_at Date No
ct.letsencrypt_ct_oak_2020.ct_to_censys_at Date No
ct.letsencrypt_ct_oak_2020.index Long No
ct.letsencrypt_ct_oak_2020.sct String No
ct.letsencrypt_ct_oak_2021 Subrecord No
ct.letsencrypt_ct_oak_2021.added_to_ct_at Date No
ct.letsencrypt_ct_oak_2021.censys_to_ct_at Date No
ct.letsencrypt_ct_oak_2021.ct_to_censys_at Date No
ct.letsencrypt_ct_oak_2021.index Long No
ct.letsencrypt_ct_oak_2021.sct String No
ct.letsencrypt_ct_oak_2022 Subrecord No
ct.letsencrypt_ct_oak_2022.added_to_ct_at Date No
ct.letsencrypt_ct_oak_2022.censys_to_ct_at Date No
ct.letsencrypt_ct_oak_2022.ct_to_censys_at Date No
ct.letsencrypt_ct_oak_2022.index Long No
ct.letsencrypt_ct_oak_2022.sct String No
ct.letsencrypt_ct_oak_2023 Subrecord No
ct.letsencrypt_ct_oak_2023.added_to_ct_at Date No
ct.letsencrypt_ct_oak_2023.censys_to_ct_at Date No
ct.letsencrypt_ct_oak_2023.ct_to_censys_at Date No
ct.letsencrypt_ct_oak_2023.index Long No
ct.letsencrypt_ct_oak_2023.sct String No
ct.nordu_ct_flimsy Subrecord No
ct.nordu_ct_flimsy.added_to_ct_at Date No
ct.nordu_ct_flimsy.censys_to_ct_at Date No
ct.nordu_ct_flimsy.ct_to_censys_at Date No
ct.nordu_ct_flimsy.index Long No
ct.nordu_ct_flimsy.sct String No
ct.nordu_ct_plausible Subrecord No
ct.nordu_ct_plausible.added_to_ct_at Date No
ct.nordu_ct_plausible.censys_to_ct_at Date No
ct.nordu_ct_plausible.ct_to_censys_at Date No
ct.nordu_ct_plausible.index Long No
ct.nordu_ct_plausible.sct String No
ct.sheca_ct Subrecord No
ct.sheca_ct.added_to_ct_at Date No
ct.sheca_ct.censys_to_ct_at Date No
ct.sheca_ct.ct_to_censys_at Date No
ct.sheca_ct.index Long No
ct.sheca_ct.sct String No
ct.sheca_ctlog Subrecord No
ct.sheca_ctlog.added_to_ct_at Date No
ct.sheca_ctlog.censys_to_ct_at Date No
ct.sheca_ctlog.ct_to_censys_at Date No
ct.sheca_ctlog.index Long No
ct.sheca_ctlog.sct String No
ct.startssl_ct Subrecord No
ct.startssl_ct.added_to_ct_at Date No
ct.startssl_ct.censys_to_ct_at Date No
ct.startssl_ct.ct_to_censys_at Date No
ct.startssl_ct.index Long No
ct.startssl_ct.sct String No
ct.symantec_ws_ct Subrecord No
ct.symantec_ws_ct.added_to_ct_at Date No
ct.symantec_ws_ct.censys_to_ct_at Date No
ct.symantec_ws_ct.ct_to_censys_at Date No
ct.symantec_ws_ct.index Long No
ct.symantec_ws_ct.sct String No
ct.symantec_ws_deneb Subrecord No
ct.symantec_ws_deneb.added_to_ct_at Date No
ct.symantec_ws_deneb.censys_to_ct_at Date No
ct.symantec_ws_deneb.ct_to_censys_at Date No
ct.symantec_ws_deneb.index Long No
ct.symantec_ws_deneb.sct String No
ct.symantec_ws_sirius Subrecord No
ct.symantec_ws_sirius.added_to_ct_at Date No
ct.symantec_ws_sirius.censys_to_ct_at Date No
ct.symantec_ws_sirius.ct_to_censys_at Date No
ct.symantec_ws_sirius.index Long No
ct.symantec_ws_sirius.sct String No
ct.symantec_ws_vega Subrecord No
ct.symantec_ws_vega.added_to_ct_at Date No
ct.symantec_ws_vega.censys_to_ct_at Date No
ct.symantec_ws_vega.ct_to_censys_at Date No
ct.symantec_ws_vega.index Long No
ct.symantec_ws_vega.sct String No
ct.venafi_api_ctlog Subrecord No
ct.venafi_api_ctlog.added_to_ct_at Date No
ct.venafi_api_ctlog.censys_to_ct_at Date No
ct.venafi_api_ctlog.ct_to_censys_at Date No
ct.venafi_api_ctlog.index Long No
ct.venafi_api_ctlog.sct String No
ct.venafi_api_ctlog_gen2 Subrecord No
ct.venafi_api_ctlog_gen2.added_to_ct_at Date No
ct.venafi_api_ctlog_gen2.censys_to_ct_at Date No
ct.venafi_api_ctlog_gen2.ct_to_censys_at Date No
ct.venafi_api_ctlog_gen2.index Long No
ct.venafi_api_ctlog_gen2.sct String No
ct.wosign_ct Subrecord No
ct.wosign_ct.added_to_ct_at Date No
ct.wosign_ct.censys_to_ct_at Date No
ct.wosign_ct.ct_to_censys_at Date No
ct.wosign_ct.index Long No
ct.wosign_ct.sct String No
ct.wosign_ctlog Subrecord No
ct.wosign_ctlog.added_to_ct_at Date No
ct.wosign_ctlog.censys_to_ct_at Date No
ct.wosign_ctlog.ct_to_censys_at Date No
ct.wosign_ctlog.index Long No
ct.wosign_ctlog.sct String No
ct.wosign_ctlog2 Subrecord No
ct.wosign_ctlog2.added_to_ct_at Date No
ct.wosign_ctlog2.censys_to_ct_at Date No
ct.wosign_ctlog2.ct_to_censys_at Date No
ct.wosign_ctlog2.index Long No
ct.wosign_ctlog2.sct String No
ct.wosign_ctlog3 Subrecord No
ct.wosign_ctlog3.added_to_ct_at Date No
ct.wosign_ctlog3.censys_to_ct_at Date No
ct.wosign_ctlog3.ct_to_censys_at Date No
ct.wosign_ctlog3.index Long No
ct.wosign_ctlog3.sct String No
ct.wotrus_ctlog Subrecord No
ct.wotrus_ctlog.added_to_ct_at Date No
ct.wotrus_ctlog.censys_to_ct_at Date No
ct.wotrus_ctlog.ct_to_censys_at Date No
ct.wotrus_ctlog.index Long No
ct.wotrus_ctlog.sct String No
ct.wotrus_ctlog3 Subrecord No
ct.wotrus_ctlog3.added_to_ct_at Date No
ct.wotrus_ctlog3.censys_to_ct_at Date No
ct.wotrus_ctlog3.ct_to_censys_at Date No
ct.wotrus_ctlog3.index Long No
ct.wotrus_ctlog3.sct String No
metadata Subrecord No
metadata.added_at Date No
metadata.parse_error Text No
metadata.parse_status Keyword No
metadata.parse_version Integer No
metadata.post_processed Boolean No
metadata.post_processed_at Date No
metadata.seen_in_scan Boolean No
metadata.source Keyword No
metadata.updated_at Date No
parsed Subrecord No
parsed.__expanded_names Keyword Yes
parsed.extensions Subrecord No
parsed.extensions.authority_info_access Subrecord No The parsed id-pe-authorityInfoAccess extension (1.3.6.1.5.7.1.1). Only id-ad-caIssuers and id-ad-ocsp accessMethods are supported; others are omitted.
parsed.extensions.authority_info_access.issuer_urls Text Yes URLs of accessLocations with accessMethod of id-ad-caIssuers, pointing to locations where this certificate's issuers can be downloaded. Only uniformResourceIdentifier accessLocations are supported; others are omitted.
parsed.extensions.authority_info_access.ocsp_urls Text Yes URLs of accessLocations with accessMethod of id-ad-ocsp, pointing to OCSP servers that can be used to check this certificate's revocation status. Only uniformResourceIdentifier accessLocations are supported; others are omitted.
parsed.extensions.authority_key_id Keyword No A key identifier, usually a digest of the DER encoding of a SubjectPublicKeyInfo. This is the hex encoding of the OCTET STRING value.
parsed.extensions.basic_constraints Subrecord No The parsed id-ce-basicConstraints extension (2.5.29.19); see RFC 5280.
parsed.extensions.basic_constraints.is_ca Boolean No Indicates that the certificate is permitted to sign other certificates.
parsed.extensions.basic_constraints.max_path_len Integer No When present, gives the maximum number of non-self-issued intermediate certificates that may follow this certificate in a valid certification path.
parsed.extensions.cabf_organization_id Subrecordtype No The CA/BF organization ID extensions (2.23.140.3.1)
parsed.extensions.cabf_organization_id.country Text No
parsed.extensions.cabf_organization_id.reference Text No
parsed.extensions.cabf_organization_id.scheme Text No
parsed.extensions.cabf_organization_id.state Text No
parsed.extensions.certificate_policies Subrecordtype Yes The parsed id-ce-certificatePolicies extension (2.5.29.32).
parsed.extensions.certificate_policies.cps Text Yes List of URIs to the policies
parsed.extensions.certificate_policies.id Keyword No The OBJECT IDENTIFIER identifying the policy.
parsed.extensions.certificate_policies.user_notice Subrecordtype Yes List of textual notices to display relying parties.
parsed.extensions.certificate_policies.user_notice.explicit_text Text No Textual statement with a maximum size of 200 characters. Should be a UTF8String or IA5String.
parsed.extensions.certificate_policies.user_notice.notice_reference Subrecordtype Yes Names an organization and identifies, by number, a particular textual statement prepared by that organization.
parsed.extensions.certificate_policies.user_notice.notice_reference.notice_numbers Integer Yes The numeric identifier(s) of the notice.
parsed.extensions.certificate_policies.user_notice.notice_reference.organization Text No The organization that prepared the notice.
parsed.extensions.crl_distribution_points Text Yes The parsed id-ce-cRLDistributionPoints extension (2.5.29.31). Contents are a list of distributionPoint URLs (other distributionPoint types are omitted).
parsed.extensions.ct_poison Boolean No This is true if the certificate possesses the Certificate Transparency Precertificate Poison extension (1.3.6.1.4.1.11129.2.4.3).
parsed.extensions.extended_key_usage Subrecordtype No The parsed id-ce-extKeyUsage (2.5.29.37) extension.
parsed.extensions.extended_key_usage.any Boolean No Extension has extended key usage ANY (OBJECT IDENTIFIER = 2.5.29.37.0)
parsed.extensions.extended_key_usage.apple_code_signing Boolean No Extension has extended key usage APPLE_CODE_SIGNING (OBJECT IDENTIFIER = 1.2.840.113635.100.4.1)
parsed.extensions.extended_key_usage.apple_code_signing_development Boolean No Extension has extended key usage APPLE_CODE_SIGNING_DEVELOPMENT (OBJECT IDENTIFIER = 1.2.840.113635.100.4.1.1)
parsed.extensions.extended_key_usage.apple_code_signing_third_party Boolean No Extension has extended key usage APPLE_CODE_SIGNING_THIRD_PARTY (OBJECT IDENTIFIER = 1.2.840.113635.100.4.1.3)
parsed.extensions.extended_key_usage.apple_crypto_development_env Boolean No Extension has extended key usage APPLE_CRYPTO_DEVELOPMENT_ENV (OBJECT IDENTIFIER = 1.2.840.113635.100.4.5.4)
parsed.extensions.extended_key_usage.apple_crypto_env Boolean No Extension has extended key usage APPLE_CRYPTO_ENV (OBJECT IDENTIFIER = 1.2.840.113635.100.4.5)
parsed.extensions.extended_key_usage.apple_crypto_maintenance_env Boolean No Extension has extended key usage APPLE_CRYPTO_MAINTENANCE_ENV (OBJECT IDENTIFIER = 1.2.840.113635.100.4.5.2)
parsed.extensions.extended_key_usage.apple_crypto_production_env Boolean No Extension has extended key usage APPLE_CRYPTO_PRODUCTION_ENV (OBJECT IDENTIFIER = 1.2.840.113635.100.4.5.1)
parsed.extensions.extended_key_usage.apple_crypto_qos Boolean No Extension has extended key usage APPLE_CRYPTO_QOS (OBJECT IDENTIFIER = 1.2.840.113635.100.4.6)
parsed.extensions.extended_key_usage.apple_crypto_test_env Boolean No Extension has extended key usage APPLE_CRYPTO_TEST_ENV (OBJECT IDENTIFIER = 1.2.840.113635.100.4.5.3)
parsed.extensions.extended_key_usage.apple_crypto_tier0_qos Boolean No Extension has extended key usage APPLE_CRYPTO_TIER0_QOS (OBJECT IDENTIFIER = 1.2.840.113635.100.4.6.1)
parsed.extensions.extended_key_usage.apple_crypto_tier1_qos Boolean No Extension has extended key usage APPLE_CRYPTO_TIER1_QOS (OBJECT IDENTIFIER = 1.2.840.113635.100.4.6.2)
parsed.extensions.extended_key_usage.apple_crypto_tier2_qos Boolean No Extension has extended key usage APPLE_CRYPTO_TIER2_QOS (OBJECT IDENTIFIER = 1.2.840.113635.100.4.6.3)
parsed.extensions.extended_key_usage.apple_crypto_tier3_qos Boolean No Extension has extended key usage APPLE_CRYPTO_TIER3_QOS (OBJECT IDENTIFIER = 1.2.840.113635.100.4.6.4)
parsed.extensions.extended_key_usage.apple_ichat_encryption Boolean No Extension has extended key usage APPLE_ICHAT_ENCRYPTION (OBJECT IDENTIFIER = 1.2.840.113635.100.4.3)
parsed.extensions.extended_key_usage.apple_ichat_signing Boolean No Extension has extended key usage APPLE_ICHAT_SIGNING (OBJECT IDENTIFIER = 1.2.840.113635.100.4.2)
parsed.extensions.extended_key_usage.apple_resource_signing Boolean No Extension has extended key usage APPLE_RESOURCE_SIGNING (OBJECT IDENTIFIER = 1.2.840.113635.100.4.1.4)
parsed.extensions.extended_key_usage.apple_software_update_signing Boolean No Extension has extended key usage APPLE_SOFTWARE_UPDATE_SIGNING (OBJECT IDENTIFIER = 1.2.840.113635.100.4.1.2)
parsed.extensions.extended_key_usage.apple_system_identity Boolean No Extension has extended key usage APPLE_SYSTEM_IDENTITY (OBJECT IDENTIFIER = 1.2.840.113635.100.4.4)
parsed.extensions.extended_key_usage.client_auth Boolean No Extension has extended key usage CLIENT_AUTH (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.2)
parsed.extensions.extended_key_usage.code_signing Boolean No Extension has extended key usage CODE_SIGNING (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.3)
parsed.extensions.extended_key_usage.dvcs Boolean No Extension has extended key usage DVCS (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.10)
parsed.extensions.extended_key_usage.eap_over_lan Boolean No Extension has extended key usage EAP_OVER_LAN (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.14)
parsed.extensions.extended_key_usage.eap_over_ppp Boolean No Extension has extended key usage EAP_OVER_PPP (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.13)
parsed.extensions.extended_key_usage.email_protection Boolean No Extension has extended key usage EMAIL_PROTECTION (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.4)
parsed.extensions.extended_key_usage.ipsec_end_system Boolean No Extension has extended key usage IPSEC_END_SYSTEM (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.5)
parsed.extensions.extended_key_usage.ipsec_tunnel Boolean No Extension has extended key usage IPSEC_TUNNEL (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.6)
parsed.extensions.extended_key_usage.ipsec_user Boolean No Extension has extended key usage IPSEC_USER (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.7)
parsed.extensions.extended_key_usage.microsoft_ca_exchange Boolean No Extension has extended key usage MICROSOFT_CA_EXCHANGE (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.21.5)
parsed.extensions.extended_key_usage.microsoft_cert_trust_list_signing Boolean No Extension has extended key usage MICROSOFT_CERT_TRUST_LIST_SIGNING (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.1)
parsed.extensions.extended_key_usage.microsoft_csp_signature Boolean No Extension has extended key usage MICROSOFT_CSP_SIGNATURE (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.16)
parsed.extensions.extended_key_usage.microsoft_document_signing Boolean No Extension has extended key usage MICROSOFT_DOCUMENT_SIGNING (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.12)
parsed.extensions.extended_key_usage.microsoft_drm Boolean No Extension has extended key usage MICROSOFT_DRM (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.5.1)
parsed.extensions.extended_key_usage.microsoft_drm_individualization Boolean No Extension has extended key usage MICROSOFT_DRM_INDIVIDUALIZATION (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.5.2)
parsed.extensions.extended_key_usage.microsoft_efs_recovery Boolean No Extension has extended key usage MICROSOFT_EFS_RECOVERY (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.4.1)
parsed.extensions.extended_key_usage.microsoft_embedded_nt_crypto Boolean No Extension has extended key usage MICROSOFT_EMBEDDED_NT_CRYPTO (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.8)
parsed.extensions.extended_key_usage.microsoft_encrypted_file_system Boolean No Extension has extended key usage MICROSOFT_ENCRYPTED_FILE_SYSTEM (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.4)
parsed.extensions.extended_key_usage.microsoft_enrollment_agent Boolean No Extension has extended key usage MICROSOFT_ENROLLMENT_AGENT (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.20.2.1)
parsed.extensions.extended_key_usage.microsoft_kernel_mode_code_signing Boolean No Extension has extended key usage MICROSOFT_KERNEL_MODE_CODE_SIGNING (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.61.1.1)
parsed.extensions.extended_key_usage.microsoft_key_recovery_21 Boolean No Extension has extended key usage MICROSOFT_KEY_RECOVERY_21 (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.21.6)
parsed.extensions.extended_key_usage.microsoft_key_recovery_3 Boolean No Extension has extended key usage MICROSOFT_KEY_RECOVERY_3 (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.11)
parsed.extensions.extended_key_usage.microsoft_license_server Boolean No Extension has extended key usage MICROSOFT_LICENSE_SERVER (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.5.4)
parsed.extensions.extended_key_usage.microsoft_licenses Boolean No Extension has extended key usage MICROSOFT_LICENSES (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.5.3)
parsed.extensions.extended_key_usage.microsoft_lifetime_signing Boolean No Extension has extended key usage MICROSOFT_LIFETIME_SIGNING (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.13)
parsed.extensions.extended_key_usage.microsoft_mobile_device_software Boolean No Extension has extended key usage MICROSOFT_MOBILE_DEVICE_SOFTWARE (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.14)
parsed.extensions.extended_key_usage.microsoft_nt5_crypto Boolean No Extension has extended key usage MICROSOFT_NT5_CRYPTO (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.6)
parsed.extensions.extended_key_usage.microsoft_oem_whql_crypto Boolean No Extension has extended key usage MICROSOFT_OEM_WHQL_CRYPTO (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.7)
parsed.extensions.extended_key_usage.microsoft_qualified_subordinate Boolean No Extension has extended key usage MICROSOFT_QUALIFIED_SUBORDINATE (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.10)
parsed.extensions.extended_key_usage.microsoft_root_list_signer Boolean No Extension has extended key usage MICROSOFT_ROOT_LIST_SIGNER (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.9)
parsed.extensions.extended_key_usage.microsoft_server_gated_crypto Boolean No Extension has extended key usage MICROSOFT_SERVER_GATED_CRYPTO (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.3)
parsed.extensions.extended_key_usage.microsoft_sgc_serialized Boolean No Extension has extended key usage MICROSOFT_SGC_SERIALIZED (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.3.1)
parsed.extensions.extended_key_usage.microsoft_smart_display Boolean No Extension has extended key usage MICROSOFT_SMART_DISPLAY (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.15)
parsed.extensions.extended_key_usage.microsoft_smartcard_logon Boolean No Extension has extended key usage MICROSOFT_SMARTCARD_LOGON (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.20.2.2)
parsed.extensions.extended_key_usage.microsoft_system_health Boolean No Extension has extended key usage MICROSOFT_SYSTEM_HEALTH (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.47.1.1)
parsed.extensions.extended_key_usage.microsoft_system_health_loophole Boolean No Extension has extended key usage MICROSOFT_SYSTEM_HEALTH_LOOPHOLE (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.47.1.3)
parsed.extensions.extended_key_usage.microsoft_timestamp_signing Boolean No Extension has extended key usage MICROSOFT_TIMESTAMP_SIGNING (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.2)
parsed.extensions.extended_key_usage.microsoft_whql_crypto Boolean No Extension has extended key usage MICROSOFT_WHQL_CRYPTO (OBJECT IDENTIFIER = 1.3.6.1.4.1.311.10.3.5)
parsed.extensions.extended_key_usage.netscape_server_gated_crypto Boolean No Extension has extended key usage NETSCAPE_SERVER_GATED_CRYPTO (OBJECT IDENTIFIER = 2.16.840.1.113730.4.1)
parsed.extensions.extended_key_usage.ocsp_signing Boolean No Extension has extended key usage OCSP_SIGNING (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.9)
parsed.extensions.extended_key_usage.sbgp_cert_aa_service_auth Boolean No Extension has extended key usage SBGP_CERT_AA_SERVICE_AUTH (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.11)
parsed.extensions.extended_key_usage.server_auth Boolean No Extension has extended key usage SERVER_AUTH (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.1)
parsed.extensions.extended_key_usage.time_stamping Boolean No Extension has extended key usage TIME_STAMPING (OBJECT IDENTIFIER = 1.3.6.1.5.5.7.3.8)
parsed.extensions.extended_key_usage.unknown Keyword Yes A list of the raw OBJECT IDENTIFIERs of any EKUs not recognized by the application.
parsed.extensions.extended_key_usage.value Integer Yes
parsed.extensions.issuer_alt_name Subrecordtype No The parsed Issuer Alternative Name extension (id-ce-issuerAltName, 2.5.29.18).
parsed.extensions.issuer_alt_name.directory_names Subrecordtype Yes Parsed directoryName entries in the GeneralName (CHOICE tag 4).
parsed.extensions.issuer_alt_name.directory_names.common_name Text Yes commonName (CN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.3)
parsed.extensions.issuer_alt_name.directory_names.country Text Yes countryName (C) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.6)
parsed.extensions.issuer_alt_name.directory_names.domain_component Text Yes domainComponent (DC) elements of the distinguished name (OBJECT IDENTIFIER 0.9.2342.19200300.100.1.25)
parsed.extensions.issuer_alt_name.directory_names.email_address Text Yes emailAddress (E) elements of the distinguished name (OBJECT IDENTIFIER 1.2.840.113549.1.9.1)
parsed.extensions.issuer_alt_name.directory_names.given_name Text Yes givenName (G) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.42)
parsed.extensions.issuer_alt_name.directory_names.jurisdiction_country Text Yes jurisdictionCountry elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.3)
parsed.extensions.issuer_alt_name.directory_names.jurisdiction_locality Text Yes jurisdictionLocality elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.1)
parsed.extensions.issuer_alt_name.directory_names.jurisdiction_province Text Yes jurisdictionStateOrProvice elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.2)
parsed.extensions.issuer_alt_name.directory_names.locality Text Yes localityName (L) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.7)
parsed.extensions.issuer_alt_name.directory_names.organization Text Yes organizationName (O) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.10)
parsed.extensions.issuer_alt_name.directory_names.organization_id Text Yes organizationId elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.97)
parsed.extensions.issuer_alt_name.directory_names.organizational_unit Text Yes organizationalUnit (OU) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.11)
parsed.extensions.issuer_alt_name.directory_names.postal_code Keyword Yes postalCode elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.17)
parsed.extensions.issuer_alt_name.directory_names.province Text Yes stateOrProviceName (ST) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.8)
parsed.extensions.issuer_alt_name.directory_names.serial_number Keyword Yes serialNumber elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.5)
parsed.extensions.issuer_alt_name.directory_names.street_address Text Yes streetAddress (STREET) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.9)
parsed.extensions.issuer_alt_name.directory_names.surname Text Yes surname (SN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.4)
parsed.extensions.issuer_alt_name.dns_names Text Yes dNSName entries in the GeneralName (IA5String, CHOICE tag 2).
parsed.extensions.issuer_alt_name.edi_party_names Subrecordtype Yes Parsed eDIPartyName entries in the GeneralName (CHOICE tag 5)
parsed.extensions.issuer_alt_name.edi_party_names.name_assigner Text No The nameAssigner (a DirectoryString)
parsed.extensions.issuer_alt_name.edi_party_names.party_name Text No The partyName (a DirectoryString)
parsed.extensions.issuer_alt_name.email_addresses Text Yes rfc822Name entries in the GeneralName (IA5String, CHOICE tag 1).
parsed.extensions.issuer_alt_name.ip_addresses Ip Yes iPAddress entries in the GeneralName (CHOICE tag 7).
parsed.extensions.issuer_alt_name.other_names Subrecordtype Yes otherName entries in the GeneralName (CHOICE tag 0). An arbitrary binary value identified by an OBJECT IDENTIFIER.
parsed.extensions.issuer_alt_name.other_names.id Keyword No The OBJECT IDENTIFIER identifying the syntax of the otherName value.
parsed.extensions.issuer_alt_name.other_names.value String No The raw otherName value.
parsed.extensions.issuer_alt_name.registered_ids Keyword Yes registeredID entries in the GeneralName (OBJECT IDENTIFIER, CHOICE tag 8). Stored in dotted-decimal format.
parsed.extensions.issuer_alt_name.uniform_resource_identifiers Text Yes uniformResourceIdentifier entries in the GeneralName (CHOICE tag 6).
parsed.extensions.key_usage Subrecord No The parsed id-ce-keyUsage extension (2.5.29.15); see RFC 5280.
parsed.extensions.key_usage.certificate_sign Boolean No Indicates if the keyCertSign bit(5) is set.
parsed.extensions.key_usage.content_commitment Boolean No Indicates if the contentCommitment bit(1) (formerly called nonRepudiation) is set.
parsed.extensions.key_usage.crl_sign Boolean No Indicates if the cRLSign bit(6) is set.
parsed.extensions.key_usage.data_encipherment Boolean No Indicates if the dataEncipherment bit(3) is set.
parsed.extensions.key_usage.decipher_only Boolean No Indicates if the encipherOnly bit(7) is set.
parsed.extensions.key_usage.digital_signature Boolean No Indicates if the digitalSignature bit(0) is set.
parsed.extensions.key_usage.encipher_only Boolean No Indicates if the decipherOnly bit(8) is set.
parsed.extensions.key_usage.key_agreement Boolean No Indicates if the keyAgreement bit(4) is set.
parsed.extensions.key_usage.key_encipherment Boolean No Indicates if the keyEncipherment bit(2) is set.
parsed.extensions.key_usage.value Integer No Integer value of the bitmask in the extension
parsed.extensions.name_constraints Subrecord No The parsed id-ce-nameConstraints extension (2.5.29.30). Specifies a name space within which all child certificates' subject names MUST be located.
parsed.extensions.name_constraints.critical Boolean No If set, clients unable to understand this extension must reject this certificate.
parsed.extensions.name_constraints.excluded_directory_names Subrecordtype Yes Excluded names of type directoryName.
parsed.extensions.name_constraints.excluded_directory_names.common_name Text Yes commonName (CN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.3)
parsed.extensions.name_constraints.excluded_directory_names.country Text Yes countryName (C) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.6)
parsed.extensions.name_constraints.excluded_directory_names.domain_component Text Yes domainComponent (DC) elements of the distinguished name (OBJECT IDENTIFIER 0.9.2342.19200300.100.1.25)
parsed.extensions.name_constraints.excluded_directory_names.email_address Text Yes emailAddress (E) elements of the distinguished name (OBJECT IDENTIFIER 1.2.840.113549.1.9.1)
parsed.extensions.name_constraints.excluded_directory_names.given_name Text Yes givenName (G) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.42)
parsed.extensions.name_constraints.excluded_directory_names.jurisdiction_country Text Yes jurisdictionCountry elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.3)
parsed.extensions.name_constraints.excluded_directory_names.jurisdiction_locality Text Yes jurisdictionLocality elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.1)
parsed.extensions.name_constraints.excluded_directory_names.jurisdiction_province Text Yes jurisdictionStateOrProvice elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.2)
parsed.extensions.name_constraints.excluded_directory_names.locality Text Yes localityName (L) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.7)
parsed.extensions.name_constraints.excluded_directory_names.organization Text Yes organizationName (O) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.10)
parsed.extensions.name_constraints.excluded_directory_names.organization_id Text Yes organizationId elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.97)
parsed.extensions.name_constraints.excluded_directory_names.organizational_unit Text Yes organizationalUnit (OU) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.11)
parsed.extensions.name_constraints.excluded_directory_names.postal_code Keyword Yes postalCode elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.17)
parsed.extensions.name_constraints.excluded_directory_names.province Text Yes stateOrProviceName (ST) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.8)
parsed.extensions.name_constraints.excluded_directory_names.serial_number Keyword Yes serialNumber elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.5)
parsed.extensions.name_constraints.excluded_directory_names.street_address Text Yes streetAddress (STREET) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.9)
parsed.extensions.name_constraints.excluded_directory_names.surname Text Yes surname (SN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.4)
parsed.extensions.name_constraints.excluded_edi_party_names Subrecordtype Yes Excluded names of type ediPartyName.
parsed.extensions.name_constraints.excluded_edi_party_names.name_assigner Text No The nameAssigner (a DirectoryString)
parsed.extensions.name_constraints.excluded_edi_party_names.party_name Text No The partyName (a DirectoryString)
parsed.extensions.name_constraints.excluded_email_addresses Text Yes Excluded names of type rfc822Name.
parsed.extensions.name_constraints.excluded_ip_addresses Subrecordtype Yes Range of excluded names of type iPAddress.
parsed.extensions.name_constraints.excluded_ip_addresses.begin Ip No The first IP in the range.
parsed.extensions.name_constraints.excluded_ip_addresses.cidr Keyword No The CIDR specifying the subtree.
parsed.extensions.name_constraints.excluded_ip_addresses.end Ip No The last IP in the range.
parsed.extensions.name_constraints.excluded_ip_addresses.mask Ip No The mask IP.
parsed.extensions.name_constraints.excluded_names Text Yes Excluded names of type dNSName.
parsed.extensions.name_constraints.excluded_registered_ids Keyword Yes Excluded names of type registeredID.
parsed.extensions.name_constraints.permitted_directory_names Subrecordtype Yes Permitted names of type directoryName.
parsed.extensions.name_constraints.permitted_directory_names.common_name Text Yes commonName (CN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.3)
parsed.extensions.name_constraints.permitted_directory_names.country Text Yes countryName (C) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.6)
parsed.extensions.name_constraints.permitted_directory_names.domain_component Text Yes domainComponent (DC) elements of the distinguished name (OBJECT IDENTIFIER 0.9.2342.19200300.100.1.25)
parsed.extensions.name_constraints.permitted_directory_names.email_address Text Yes emailAddress (E) elements of the distinguished name (OBJECT IDENTIFIER 1.2.840.113549.1.9.1)
parsed.extensions.name_constraints.permitted_directory_names.given_name Text Yes givenName (G) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.42)
parsed.extensions.name_constraints.permitted_directory_names.jurisdiction_country Text Yes jurisdictionCountry elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.3)
parsed.extensions.name_constraints.permitted_directory_names.jurisdiction_locality Text Yes jurisdictionLocality elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.1)
parsed.extensions.name_constraints.permitted_directory_names.jurisdiction_province Text Yes jurisdictionStateOrProvice elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.2)
parsed.extensions.name_constraints.permitted_directory_names.locality Text Yes localityName (L) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.7)
parsed.extensions.name_constraints.permitted_directory_names.organization Text Yes organizationName (O) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.10)
parsed.extensions.name_constraints.permitted_directory_names.organization_id Text Yes organizationId elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.97)
parsed.extensions.name_constraints.permitted_directory_names.organizational_unit Text Yes organizationalUnit (OU) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.11)
parsed.extensions.name_constraints.permitted_directory_names.postal_code Keyword Yes postalCode elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.17)
parsed.extensions.name_constraints.permitted_directory_names.province Text Yes stateOrProviceName (ST) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.8)
parsed.extensions.name_constraints.permitted_directory_names.serial_number Keyword Yes serialNumber elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.5)
parsed.extensions.name_constraints.permitted_directory_names.street_address Text Yes streetAddress (STREET) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.9)
parsed.extensions.name_constraints.permitted_directory_names.surname Text Yes surname (SN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.4)
parsed.extensions.name_constraints.permitted_edi_party_names Subrecordtype Yes Permitted names of type ediPartyName
parsed.extensions.name_constraints.permitted_edi_party_names.name_assigner Text No The nameAssigner (a DirectoryString)
parsed.extensions.name_constraints.permitted_edi_party_names.party_name Text No The partyName (a DirectoryString)
parsed.extensions.name_constraints.permitted_email_addresses Text Yes Permitted names of type rfc822Name.
parsed.extensions.name_constraints.permitted_ip_addresses Subrecordtype Yes Range of permitted names of type iPAddress.
parsed.extensions.name_constraints.permitted_ip_addresses.begin Ip No The first IP in the range.
parsed.extensions.name_constraints.permitted_ip_addresses.cidr Keyword No The CIDR specifying the subtree.
parsed.extensions.name_constraints.permitted_ip_addresses.end Ip No The last IP in the range.
parsed.extensions.name_constraints.permitted_ip_addresses.mask Ip No The mask IP.
parsed.extensions.name_constraints.permitted_names Text Yes Permitted names of type dNSName.
parsed.extensions.name_constraints.permitted_registered_ids Keyword Yes Permitted names of type registeredID.
parsed.extensions.qc_statements Subrecordtype No IDs and parsed statements for qualified certificates (1.3.6.1.5.5.7.1.3)
parsed.extensions.qc_statements.ids Keyword Yes All included statement OIDs
parsed.extensions.qc_statements.parsed Subrecord No Contains known QCStatements. Each field is repeated to handle the case where a single statement appears more than once.
parsed.extensions.qc_statements.parsed.etsi_compliance Boolean Yes True if present (Statement ID 0.4.0.1862.1.1)
parsed.extensions.qc_statements.parsed.legislation Subrecordtype Yes Statement ID 0.4.0.1862.1.7
parsed.extensions.qc_statements.parsed.legislation.country_codes Keyword Yes Country codes for the set of countries where this certificate issued as a qualified certificate
parsed.extensions.qc_statements.parsed.limit Subrecordtype Yes Statement ID 0.4.0.1862.1.2
parsed.extensions.qc_statements.parsed.limit.amount Long No Value in currency
parsed.extensions.qc_statements.parsed.limit.currency Keyword No Currency, if provided as a string
parsed.extensions.qc_statements.parsed.limit.currency_number Long No Currency, if provided as an integer
parsed.extensions.qc_statements.parsed.limit.exponent Long No Total is amount times 10 raised to the exponent
parsed.extensions.qc_statements.parsed.pds_locations Subrecordtype Yes Statement ID 0.4.0.1862.1.5
parsed.extensions.qc_statements.parsed.pds_locations.locations Subrecordtype Yes Included PDS locations
parsed.extensions.qc_statements.parsed.pds_locations.locations.language Keyword No Locale code
parsed.extensions.qc_statements.parsed.pds_locations.locations.url Text No Location of the PDS
parsed.extensions.qc_statements.parsed.retention_period Long Yes Statement ID 0.4.0.1862.1.3
parsed.extensions.qc_statements.parsed.sscd Boolean Yes True if present (Statement ID 0.4.0.1862.1.4
parsed.extensions.qc_statements.parsed.types Subrecordtype Yes Statement ID 0.4.0.1862.1.6
parsed.extensions.qc_statements.parsed.types.ids Keyword Yes Included QC type OIDs
parsed.extensions.signed_certificate_timestamps Subrecordtype Yes The parsed Certificate Transparency SignedCertificateTimestampsList extension (1.3.6.1.4.1.11129.2.4.2); see RFC 6962.
parsed.extensions.signed_certificate_timestamps.extensions Binary No For future extensions to the protocol.
parsed.extensions.signed_certificate_timestamps.log_id String No The SHA-256 hash of the log's public key, calculated over the DER encoding of the key's SubjectPublicKeyInfo.
parsed.extensions.signed_certificate_timestamps.signature Binary No The log's signature for this SCT.
parsed.extensions.signed_certificate_timestamps.timestamp Date No Time at which the SCT was issued (in seconds since the Unix epoch).
parsed.extensions.signed_certificate_timestamps.version Short No Version of the protocol to which the SCT conforms.
parsed.extensions.subject_alt_name Subrecordtype No The parsed Subject Alternative Name extension (id-ce-subjectAltName, 2.5.29.17).
parsed.extensions.subject_alt_name.directory_names Subrecordtype Yes Parsed directoryName entries in the GeneralName (CHOICE tag 4).
parsed.extensions.subject_alt_name.directory_names.common_name Text Yes commonName (CN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.3)
parsed.extensions.subject_alt_name.directory_names.country Text Yes countryName (C) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.6)
parsed.extensions.subject_alt_name.directory_names.domain_component Text Yes domainComponent (DC) elements of the distinguished name (OBJECT IDENTIFIER 0.9.2342.19200300.100.1.25)
parsed.extensions.subject_alt_name.directory_names.email_address Text Yes emailAddress (E) elements of the distinguished name (OBJECT IDENTIFIER 1.2.840.113549.1.9.1)
parsed.extensions.subject_alt_name.directory_names.given_name Text Yes givenName (G) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.42)
parsed.extensions.subject_alt_name.directory_names.jurisdiction_country Text Yes jurisdictionCountry elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.3)
parsed.extensions.subject_alt_name.directory_names.jurisdiction_locality Text Yes jurisdictionLocality elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.1)
parsed.extensions.subject_alt_name.directory_names.jurisdiction_province Text Yes jurisdictionStateOrProvice elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.2)
parsed.extensions.subject_alt_name.directory_names.locality Text Yes localityName (L) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.7)
parsed.extensions.subject_alt_name.directory_names.organization Text Yes organizationName (O) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.10)
parsed.extensions.subject_alt_name.directory_names.organization_id Text Yes organizationId elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.97)
parsed.extensions.subject_alt_name.directory_names.organizational_unit Text Yes organizationalUnit (OU) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.11)
parsed.extensions.subject_alt_name.directory_names.postal_code Keyword Yes postalCode elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.17)
parsed.extensions.subject_alt_name.directory_names.province Text Yes stateOrProviceName (ST) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.8)
parsed.extensions.subject_alt_name.directory_names.serial_number Keyword Yes serialNumber elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.5)
parsed.extensions.subject_alt_name.directory_names.street_address Text Yes streetAddress (STREET) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.9)
parsed.extensions.subject_alt_name.directory_names.surname Text Yes surname (SN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.4)
parsed.extensions.subject_alt_name.dns_names Text Yes dNSName entries in the GeneralName (IA5String, CHOICE tag 2).
parsed.extensions.subject_alt_name.edi_party_names Subrecordtype Yes Parsed eDIPartyName entries in the GeneralName (CHOICE tag 5)
parsed.extensions.subject_alt_name.edi_party_names.name_assigner Text No The nameAssigner (a DirectoryString)
parsed.extensions.subject_alt_name.edi_party_names.party_name Text No The partyName (a DirectoryString)
parsed.extensions.subject_alt_name.email_addresses Text Yes rfc822Name entries in the GeneralName (IA5String, CHOICE tag 1).
parsed.extensions.subject_alt_name.ip_addresses Ip Yes iPAddress entries in the GeneralName (CHOICE tag 7).
parsed.extensions.subject_alt_name.other_names Subrecordtype Yes otherName entries in the GeneralName (CHOICE tag 0). An arbitrary binary value identified by an OBJECT IDENTIFIER.
parsed.extensions.subject_alt_name.other_names.id Keyword No The OBJECT IDENTIFIER identifying the syntax of the otherName value.
parsed.extensions.subject_alt_name.other_names.value String No The raw otherName value.
parsed.extensions.subject_alt_name.registered_ids Keyword Yes registeredID entries in the GeneralName (OBJECT IDENTIFIER, CHOICE tag 8). Stored in dotted-decimal format.
parsed.extensions.subject_alt_name.uniform_resource_identifiers Text Yes uniformResourceIdentifier entries in the GeneralName (CHOICE tag 6).
parsed.extensions.subject_key_id Keyword No A key identifier, usually a digest of the DER encoding of a SubjectPublicKeyInfo. This is the hex encoding of the OCTET STRING value.
parsed.fingerprint_md5 Keyword No The MD5 digest over the DER encoding of the certificate, as a hexadecimal string.
parsed.fingerprint_sha1 Keyword No The SHA1 digest over the DER encoding of the certificate, as a hexadecimal string.
parsed.fingerprint_sha256 Keyword No The SHA2-256 digest over the DER encoding of the certificate, as a hexadecimal string.
parsed.issuer Subrecordtype No The parsed issuer name.
parsed.issuer.common_name Text Yes commonName (CN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.3)
parsed.issuer.country Text Yes countryName (C) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.6)
parsed.issuer.domain_component Text Yes domainComponent (DC) elements of the distinguished name (OBJECT IDENTIFIER 0.9.2342.19200300.100.1.25)
parsed.issuer.email_address Text Yes emailAddress (E) elements of the distinguished name (OBJECT IDENTIFIER 1.2.840.113549.1.9.1)
parsed.issuer.given_name Text Yes givenName (G) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.42)
parsed.issuer.jurisdiction_country Text Yes jurisdictionCountry elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.3)
parsed.issuer.jurisdiction_locality Text Yes jurisdictionLocality elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.1)
parsed.issuer.jurisdiction_province Text Yes jurisdictionStateOrProvice elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.2)
parsed.issuer.locality Text Yes localityName (L) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.7)
parsed.issuer.organization Text Yes organizationName (O) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.10)
parsed.issuer.organization_id Text Yes organizationId elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.97)
parsed.issuer.organizational_unit Text Yes organizationalUnit (OU) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.11)
parsed.issuer.postal_code Keyword Yes postalCode elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.17)
parsed.issuer.province Text Yes stateOrProviceName (ST) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.8)
parsed.issuer.serial_number Keyword Yes serialNumber elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.5)
parsed.issuer.street_address Text Yes streetAddress (STREET) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.9)
parsed.issuer.surname Text Yes surname (SN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.4)
parsed.issuer_dn Text No A canonical string representation of the issuer name.
parsed.names Text Yes A list of subject names in the certificate, including the Subject CommonName and SubjectAltName DNSNames, IPAddresses and URIs.
parsed.redacted Boolean No This is set if any of the certificate's names contain redacted fields.
parsed.serial_number Keyword No Serial number as an signed decimal integer. Stored as string to support >uint lengths. Negative values are allowed.
parsed.signature Subrecord No
parsed.signature.self_signed Boolean No Indicates whether the subject key was also used to sign the certificate.
parsed.signature.signature_algorithm Subrecordtype No
parsed.signature.signature_algorithm.name Keyword No Name of signature algorithm, e.g., SHA1-RSA or ECDSA-SHA512. Unknown algorithms get an integer id.
parsed.signature.signature_algorithm.oid Keyword No The OBJECT IDENTIFIER of the signature algorithm, in dotted-decimal notation.
parsed.signature.valid Boolean No
parsed.signature.value Binary No Contents of the signature BIT STRING.
parsed.signature_algorithm Subrecordtype No Identifies the algorithm used by the CA to sign the certificate.
parsed.signature_algorithm.name Keyword No Name of signature algorithm, e.g., SHA1-RSA or ECDSA-SHA512. Unknown algorithms get an integer id.
parsed.signature_algorithm.oid Keyword No The OBJECT IDENTIFIER of the signature algorithm, in dotted-decimal notation.
parsed.spki_subject_fingerprint Keyword No The SHA2-256 digest over the DER encoding of the certificate's SubjectPublicKeyInfo, as a hexadecimal string.
parsed.subject Subrecordtype No The parsed subject name.
parsed.subject.common_name Text Yes commonName (CN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.3)
parsed.subject.country Text Yes countryName (C) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.6)
parsed.subject.domain_component Text Yes domainComponent (DC) elements of the distinguished name (OBJECT IDENTIFIER 0.9.2342.19200300.100.1.25)
parsed.subject.email_address Text Yes emailAddress (E) elements of the distinguished name (OBJECT IDENTIFIER 1.2.840.113549.1.9.1)
parsed.subject.given_name Text Yes givenName (G) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.42)
parsed.subject.jurisdiction_country Text Yes jurisdictionCountry elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.3)
parsed.subject.jurisdiction_locality Text Yes jurisdictionLocality elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.1)
parsed.subject.jurisdiction_province Text Yes jurisdictionStateOrProvice elements of the distinguished name (OBJECT IDENTIFIER 1.3.6.1.4.1.311.60.2.1.2)
parsed.subject.locality Text Yes localityName (L) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.7)
parsed.subject.organization Text Yes organizationName (O) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.10)
parsed.subject.organization_id Text Yes organizationId elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.97)
parsed.subject.organizational_unit Text Yes organizationalUnit (OU) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.11)
parsed.subject.postal_code Keyword Yes postalCode elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.17)
parsed.subject.province Text Yes stateOrProviceName (ST) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.8)
parsed.subject.serial_number Keyword Yes serialNumber elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.5)
parsed.subject.street_address Text Yes streetAddress (STREET) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.9)
parsed.subject.surname Text Yes surname (SN) elements of the distinguished name (OBJECT IDENTIFIER 2.5.4.4)
parsed.subject_dn Text No A canonical string representation of the subject name.
parsed.subject_key_info Subrecord No The certificate's public key. Only one of the *_public_key fields will be set.
parsed.subject_key_info.dsa_public_key Subrecordtype No The public portion of a DSA asymmetric key.
parsed.subject_key_info.dsa_public_key.g String No
parsed.subject_key_info.dsa_public_key.p String No
parsed.subject_key_info.dsa_public_key.q String No
parsed.subject_key_info.dsa_public_key.y String No
parsed.subject_key_info.ecdsa_public_key Subrecordtype No The public portion of an ECDSA asymmetric key.
parsed.subject_key_info.ecdsa_public_key.b String No
parsed.subject_key_info.ecdsa_public_key.curve Keyword No
parsed.subject_key_info.ecdsa_public_key.gx String No
parsed.subject_key_info.ecdsa_public_key.gy String No
parsed.subject_key_info.ecdsa_public_key.length Integer No
parsed.subject_key_info.ecdsa_public_key.n String No
parsed.subject_key_info.ecdsa_public_key.p String No
parsed.subject_key_info.ecdsa_public_key.pub String No
parsed.subject_key_info.ecdsa_public_key.x String No
parsed.subject_key_info.ecdsa_public_key.y String No
parsed.subject_key_info.fingerprint_sha256 Keyword No The SHA2-256 digest calculated over the certificate's DER-encoded SubjectPublicKeyInfo field.
parsed.subject_key_info.key_algorithm Subrecordtype No Identifies the type of key and any relevant parameters.
parsed.subject_key_info.key_algorithm.name Keyword No Name of public key type, e.g., RSA or ECDSA. More information is available the named SubRecord (e.g., RSAPublicKey()).
parsed.subject_key_info.key_algorithm.oid Keyword No OID of the public key on the certificate. This is helpful when an unknown type is present. This field is reserved and not currently populated.
parsed.subject_key_info.rsa_public_key Subrecordtype No Container for the public portion (modulus and exponent) of an RSA asymmetric key.
parsed.subject_key_info.rsa_public_key.exponent Long No The RSA key's public exponent (e).
parsed.subject_key_info.rsa_public_key.length Integer No Bit-length of modulus.
parsed.subject_key_info.rsa_public_key.modulus String No The RSA key's modulus (n) in big-endian encoding.
parsed.tbs_fingerprint Keyword No The SHA2-256 digest over the DER encoding of the certificate's TBSCertificate, as a hexadecimal string.
parsed.tbs_noct_fingerprint Keyword No The SHA2-256 digest over the DER encoding of the certificate's TBSCertificate, *with any CT extensions omitted*, as a hexadecimal string.
parsed.unknown_extensions Subrecordtype Yes List of raw extensions that were not recognized by the application.
parsed.unknown_extensions.critical Boolean No Certificates should be rejected if they have critical extensions the validator does not recognize.
parsed.unknown_extensions.id Keyword No The OBJECT IDENTIFIER identifying the extension.
parsed.unknown_extensions.value String No The raw value of the extnValue OCTET STREAM.
parsed.validation_level Keyword No How the certificate is validated -- Domain validated (DV), Organization Validated (OV), Extended Validation (EV), or unknown.
parsed.validity Subrecord No
parsed.validity.end Date No Timestamp of when certificate expires. Timezone is UTC.
parsed.validity.length Long No The length of time, in seconds, that the certificate is valid.
parsed.validity.start Date No Timestamp of when certificate is first valid. Timezone is UTC.
parsed.version Short No The x.509 certificate version number.
validation Subrecord No
validation.apple Subrecord No
validation.apple.blacklisted Boolean No True if the certificate is explicitly blacklisted by some method than OneCRL/CRLSet. For example, a set of certificates revoked by Cloudflare are blacklisted by SPKI hash in Chrome.
validation.apple.had_trusted_path Boolean No True if now or at some point in the past there existed a path from the certificate to the root store.
validation.apple.in_revocation_set Boolean No True if the certificate is in the revocation set (e.g. OneCRL) associated with this root store.
validation.apple.parents Keyword Yes SHA256 fingerprints of immediate parents.
validation.apple.paths Keyword Yes
validation.apple.trusted_path Boolean No True if there exists a path from the certificate to the root store.
validation.apple.type Keyword No Indicates if the certificate is a root, intermediate, or leaf.
validation.apple.valid Boolean No ((has_trusted_path && !revoked && !blacklisted) || whitelisted) && !expired
validation.apple.was_valid Boolean No True if the certificate is valid now or was ever valid in the past.
validation.apple.whitelisted Boolean No True if the certificate is explicitly whitelisted, e.g. the set of trusted WoSign certificates Apple uses.
validation.crl_error Keyword No
validation.crl_revocation Subrecord No Indicates that the certificate has been revoked.
validation.crl_revocation.next_update Date No
validation.crl_revocation.reason Keyword No
validation.crl_revocation.revoked Boolean No
validation.google_ct_primary Subrecord No
validation.google_ct_primary.blacklisted Boolean No True if the certificate is explicitly blacklisted by some method than OneCRL/CRLSet. For example, a set of certificates revoked by Cloudflare are blacklisted by SPKI hash in Chrome.
validation.google_ct_primary.had_trusted_path Boolean No True if now or at some point in the past there existed a path from the certificate to the root store.
validation.google_ct_primary.in_revocation_set Boolean No True if the certificate is in the revocation set (e.g. OneCRL) associated with this root store.
validation.google_ct_primary.parents Keyword Yes SHA256 fingerprints of immediate parents.
validation.google_ct_primary.paths Keyword Yes
validation.google_ct_primary.trusted_path Boolean No True if there exists a path from the certificate to the root store.
validation.google_ct_primary.type Keyword No Indicates if the certificate is a root, intermediate, or leaf.
validation.google_ct_primary.valid Boolean No ((has_trusted_path && !revoked && !blacklisted) || whitelisted) && !expired
validation.google_ct_primary.was_valid Boolean No True if the certificate is valid now or was ever valid in the past.
validation.google_ct_primary.whitelisted Boolean No True if the certificate is explicitly whitelisted, e.g. the set of trusted WoSign certificates Apple uses.
validation.microsoft Subrecord No
validation.microsoft.blacklisted Boolean No True if the certificate is explicitly blacklisted by some method than OneCRL/CRLSet. For example, a set of certificates revoked by Cloudflare are blacklisted by SPKI hash in Chrome.
validation.microsoft.had_trusted_path Boolean No True if now or at some point in the past there existed a path from the certificate to the root store.
validation.microsoft.in_revocation_set Boolean No True if the certificate is in the revocation set (e.g. OneCRL) associated with this root store.
validation.microsoft.parents Keyword Yes SHA256 fingerprints of immediate parents.
validation.microsoft.paths Keyword Yes
validation.microsoft.trusted_path Boolean No True if there exists a path from the certificate to the root store.
validation.microsoft.type Keyword No Indicates if the certificate is a root, intermediate, or leaf.
validation.microsoft.valid Boolean No ((has_trusted_path && !revoked && !blacklisted) || whitelisted) && !expired
validation.microsoft.was_valid Boolean No True if the certificate is valid now or was ever valid in the past.
validation.microsoft.whitelisted Boolean No True if the certificate is explicitly whitelisted, e.g. the set of trusted WoSign certificates Apple uses.
validation.nss Subrecord No
validation.nss.blacklisted Boolean No True if the certificate is explicitly blacklisted by some method than OneCRL/CRLSet. For example, a set of certificates revoked by Cloudflare are blacklisted by SPKI hash in Chrome.
validation.nss.had_trusted_path Boolean No True if now or at some point in the past there existed a path from the certificate to the root store.
validation.nss.in_revocation_set Boolean No True if the certificate is in the revocation set (e.g. OneCRL) associated with this root store.
validation.nss.parents Keyword Yes SHA256 fingerprints of immediate parents.
validation.nss.paths Keyword Yes
validation.nss.trusted_path Boolean No True if there exists a path from the certificate to the root store.
validation.nss.type Keyword No Indicates if the certificate is a root, intermediate, or leaf.
validation.nss.valid Boolean No ((has_trusted_path && !revoked && !blacklisted) || whitelisted) && !expired
validation.nss.was_valid Boolean No True if the certificate is valid now or was ever valid in the past.
validation.nss.whitelisted Boolean No True if the certificate is explicitly whitelisted, e.g. the set of trusted WoSign certificates Apple uses.
validation.ocsp_error Keyword No
validation.ocsp_revocation Subrecord No Indicates that the certificate has been revoked.
validation.ocsp_revocation.next_update Date No
validation.ocsp_revocation.reason Keyword No
validation.ocsp_revocation.revoked Boolean No
validation.revoked Boolean No
zlint Subrecord No
zlint.errors_present Boolean No
zlint.fatals_present Boolean No
zlint.lints Subrecord No
zlint.lints.e_basic_constraints_not_critical Boolean No
zlint.lints.e_ca_common_name_missing Boolean No
zlint.lints.e_ca_country_name_invalid Boolean No
zlint.lints.e_ca_country_name_missing Boolean No
zlint.lints.e_ca_crl_sign_not_set Boolean No
zlint.lints.e_ca_is_ca Boolean No
zlint.lints.e_ca_key_cert_sign_not_set Boolean No
zlint.lints.e_ca_key_usage_missing Boolean No
zlint.lints.e_ca_key_usage_not_critical Boolean No
zlint.lints.e_ca_organization_name_missing Boolean No
zlint.lints.e_ca_subject_field_empty Boolean No
zlint.lints.e_cab_dv_conflicts_with_locality Boolean No
zlint.lints.e_cab_dv_conflicts_with_org Boolean No
zlint.lints.e_cab_dv_conflicts_with_postal Boolean No
zlint.lints.e_cab_dv_conflicts_with_province Boolean No
zlint.lints.e_cab_dv_conflicts_with_street Boolean No
zlint.lints.e_cab_iv_requires_personal_name Boolean No
zlint.lints.e_cab_ov_requires_org Boolean No
zlint.lints.e_cert_contains_unique_identifier Boolean No
zlint.lints.e_cert_extensions_version_not_3 Boolean No
zlint.lints.e_cert_policy_iv_requires_country Boolean No
zlint.lints.e_cert_policy_iv_requires_province_or_locality Boolean No
zlint.lints.e_cert_policy_ov_requires_country Boolean No
zlint.lints.e_cert_policy_ov_requires_province_or_locality Boolean No
zlint.lints.e_cert_unique_identifier_version_not_2_or_3 Boolean No
zlint.lints.e_distribution_point_incomplete Boolean No
zlint.lints.e_dnsname_bad_character_in_label Boolean No
zlint.lints.e_dnsname_contains_bare_iana_suffix Boolean No
zlint.lints.e_dnsname_empty_label Boolean No
zlint.lints.e_dnsname_hyphen_in_sld Boolean No
zlint.lints.e_dnsname_label_too_long Boolean No
zlint.lints.e_dnsname_left_label_wildcard_correct Boolean No
zlint.lints.e_dnsname_not_valid_tld Boolean No
zlint.lints.e_dnsname_underscore_in_sld Boolean No
zlint.lints.e_dnsname_wildcard_only_in_left_label Boolean No
zlint.lints.e_dsa_correct_order_in_subgroup Boolean No
zlint.lints.e_dsa_improper_modulus_or_divisor_size Boolean No
zlint.lints.e_dsa_params_missing Boolean No
zlint.lints.e_dsa_shorter_than_2048_bits Boolean No
zlint.lints.e_dsa_unique_correct_representation Boolean No
zlint.lints.e_ec_improper_curves Boolean No
zlint.lints.e_ev_business_category_missing Boolean No
zlint.lints.e_ev_country_name_missing Boolean No
zlint.lints.e_ev_locality_name_missing Boolean No
zlint.lints.e_ev_organization_name_missing Boolean No
zlint.lints.e_ev_serial_number_missing Boolean No
zlint.lints.e_ev_valid_time_too_long Boolean No
zlint.lints.e_ext_aia_marked_critical Boolean No
zlint.lints.e_ext_authority_key_identifier_critical Boolean No
zlint.lints.e_ext_authority_key_identifier_missing Boolean No
zlint.lints.e_ext_authority_key_identifier_no_key_identifier Boolean No
zlint.lints.e_ext_cert_policy_disallowed_any_policy_qualifier Boolean No
zlint.lints.e_ext_cert_policy_duplicate Boolean No
zlint.lints.e_ext_cert_policy_explicit_text_ia5_string Boolean No
zlint.lints.e_ext_cert_policy_explicit_text_too_long Boolean No
zlint.lints.e_ext_duplicate_extension Boolean No
zlint.lints.e_ext_freshest_crl_marked_critical Boolean No
zlint.lints.e_ext_ian_dns_not_ia5_string Boolean No
zlint.lints.e_ext_ian_empty_name Boolean No
zlint.lints.e_ext_ian_no_entries Boolean No
zlint.lints.e_ext_ian_rfc822_format_invalid Boolean No
zlint.lints.e_ext_ian_space_dns_name Boolean No
zlint.lints.e_ext_ian_uri_format_invalid Boolean No
zlint.lints.e_ext_ian_uri_host_not_fqdn_or_ip Boolean No
zlint.lints.e_ext_ian_uri_not_ia5 Boolean No
zlint.lints.e_ext_ian_uri_relative Boolean No
zlint.lints.e_ext_key_usage_cert_sign_without_ca Boolean No
zlint.lints.e_ext_key_usage_without_bits Boolean No
zlint.lints.e_ext_name_constraints_not_critical Boolean No
zlint.lints.e_ext_name_constraints_not_in_ca Boolean No
zlint.lints.e_ext_policy_constraints_empty Boolean No
zlint.lints.e_ext_policy_constraints_not_critical Boolean No
zlint.lints.e_ext_policy_map_any_policy Boolean No
zlint.lints.e_ext_san_contains_reserved_ip Boolean No
zlint.lints.e_ext_san_directory_name_present Boolean No
zlint.lints.e_ext_san_dns_name_too_long Boolean No
zlint.lints.e_ext_san_dns_not_ia5_string Boolean No
zlint.lints.e_ext_san_edi_party_name_present Boolean No
zlint.lints.e_ext_san_empty_name Boolean No
zlint.lints.e_ext_san_missing Boolean No
zlint.lints.e_ext_san_no_entries Boolean No
zlint.lints.e_ext_san_not_critical_without_subject Boolean No
zlint.lints.e_ext_san_other_name_present Boolean No
zlint.lints.e_ext_san_registered_id_present Boolean No
zlint.lints.e_ext_san_rfc822_format_invalid Boolean No
zlint.lints.e_ext_san_rfc822_name_present Boolean No
zlint.lints.e_ext_san_space_dns_name Boolean No
zlint.lints.e_ext_san_uniform_resource_identifier_present Boolean No
zlint.lints.e_ext_san_uri_format_invalid Boolean No
zlint.lints.e_ext_san_uri_host_not_fqdn_or_ip Boolean No
zlint.lints.e_ext_san_uri_not_ia5 Boolean No
zlint.lints.e_ext_san_uri_relative Boolean No
zlint.lints.e_ext_subject_directory_attr_critical Boolean No
zlint.lints.e_ext_subject_key_identifier_critical Boolean No
zlint.lints.e_ext_subject_key_identifier_missing_ca Boolean No
zlint.lints.e_generalized_time_does_not_include_seconds Boolean No
zlint.lints.e_generalized_time_includes_fraction_seconds Boolean No
zlint.lints.e_generalized_time_not_in_zulu Boolean No
zlint.lints.e_ian_bare_wildcard Boolean No
zlint.lints.e_ian_dns_name_includes_null_char Boolean No
zlint.lints.e_ian_dns_name_starts_with_period Boolean No
zlint.lints.e_ian_wildcard_not_first Boolean No
zlint.lints.e_inhibit_any_policy_not_critical Boolean No
zlint.lints.e_international_dns_name_not_nfkc Boolean No
zlint.lints.e_international_dns_name_not_unicode Boolean No
zlint.lints.e_invalid_certificate_version Boolean No
zlint.lints.e_issuer_field_empty Boolean No
zlint.lints.e_name_constraint_empty Boolean No
zlint.lints.e_name_constraint_maximum_not_absent Boolean No
zlint.lints.e_name_constraint_minimum_non_zero Boolean No
zlint.lints.e_old_root_ca_rsa_mod_less_than_2048_bits Boolean No
zlint.lints.e_old_sub_ca_rsa_mod_less_than_1024_bits Boolean No
zlint.lints.e_old_sub_cert_rsa_mod_less_than_1024_bits Boolean No
zlint.lints.e_path_len_constraint_improperly_included Boolean No
zlint.lints.e_path_len_constraint_zero_or_less Boolean No
zlint.lints.e_public_key_type_not_allowed Boolean No
zlint.lints.e_root_ca_extended_key_usage_present Boolean No
zlint.lints.e_root_ca_key_usage_must_be_critical Boolean No
zlint.lints.e_root_ca_key_usage_present Boolean No
zlint.lints.e_rsa_exp_negative Boolean No
zlint.lints.e_rsa_mod_less_than_2048_bits Boolean No
zlint.lints.e_rsa_no_public_key Boolean No
zlint.lints.e_rsa_public_exponent_not_odd Boolean No
zlint.lints.e_rsa_public_exponent_too_small Boolean No
zlint.lints.e_san_bare_wildcard Boolean No
zlint.lints.e_san_dns_name_includes_null_char Boolean No
zlint.lints.e_san_dns_name_starts_with_period Boolean No
zlint.lints.e_san_wildcard_not_first Boolean No
zlint.lints.e_serial_number_longer_than_20_octets Boolean No
zlint.lints.e_serial_number_not_positive Boolean No
zlint.lints.e_signature_algorithm_not_supported Boolean No
zlint.lints.e_sub_ca_aia_does_not_contain_ocsp_url Boolean No
zlint.lints.e_sub_ca_aia_marked_critical Boolean No
zlint.lints.e_sub_ca_aia_missing Boolean No
zlint.lints.e_sub_ca_certificate_policies_missing Boolean No
zlint.lints.e_sub_ca_crl_distribution_points_does_not_contain_url Boolean No
zlint.lints.e_sub_ca_crl_distribution_points_marked_critical Boolean No
zlint.lints.e_sub_ca_crl_distribution_points_missing Boolean No
zlint.lints.e_sub_ca_eku_missing Boolean No
zlint.lints.e_sub_ca_eku_name_constraints Boolean No
zlint.lints.e_sub_ca_must_not_contain_any_policy Boolean No
zlint.lints.e_sub_cert_aia_does_not_contain_ocsp_url Boolean No
zlint.lints.e_sub_cert_aia_marked_critical Boolean No
zlint.lints.e_sub_cert_aia_missing Boolean No
zlint.lints.e_sub_cert_cert_policy_empty Boolean No
zlint.lints.e_sub_cert_certificate_policies_missing Boolean No
zlint.lints.e_sub_cert_country_name_must_appear Boolean No
zlint.lints.e_sub_cert_crl_distribution_points_does_not_contain_url Boolean No
zlint.lints.e_sub_cert_crl_distribution_points_marked_critical Boolean No
zlint.lints.e_sub_cert_eku_missing Boolean No
zlint.lints.e_sub_cert_eku_server_auth_client_auth_missing Boolean No
zlint.lints.e_sub_cert_given_name_surname_contains_correct_policy Boolean No
zlint.lints.e_sub_cert_key_usage_cert_sign_bit_set Boolean No
zlint.lints.e_sub_cert_key_usage_crl_sign_bit_set Boolean No
zlint.lints.e_sub_cert_locality_name_must_appear Boolean No
zlint.lints.e_sub_cert_locality_name_must_not_appear Boolean No
zlint.lints.e_sub_cert_not_is_ca Boolean No
zlint.lints.e_sub_cert_or_sub_ca_using_sha1 Boolean No
zlint.lints.e_sub_cert_postal_code_must_not_appear Boolean No
zlint.lints.e_sub_cert_province_must_appear Boolean No
zlint.lints.e_sub_cert_province_must_not_appear Boolean No
zlint.lints.e_sub_cert_street_address_should_not_exist Boolean No
zlint.lints.e_sub_cert_valid_time_too_long Boolean No
zlint.lints.e_subject_common_name_max_length Boolean No
zlint.lints.e_subject_common_name_not_from_san Boolean No
zlint.lints.e_subject_contains_noninformational_value Boolean No
zlint.lints.e_subject_contains_reserved_ip Boolean No
zlint.lints.e_subject_country_not_iso Boolean No
zlint.lints.e_subject_empty_without_san Boolean No
zlint.lints.e_subject_info_access_marked_critical Boolean No
zlint.lints.e_subject_locality_name_max_length Boolean No
zlint.lints.e_subject_not_dn Boolean No
zlint.lints.e_subject_organization_name_max_length Boolean No
zlint.lints.e_subject_organizational_unit_name_max_length Boolean No
zlint.lints.e_subject_state_name_max_length Boolean No
zlint.lints.e_utc_time_does_not_include_seconds Boolean No
zlint.lints.e_utc_time_not_in_zulu Boolean No
zlint.lints.e_validity_time_not_positive Boolean No
zlint.lints.e_wrong_time_format_pre2050 Boolean No
zlint.lints.n_ca_digital_signature_not_set Boolean No
zlint.lints.n_contains_redacted_dnsname Boolean No
zlint.lints.n_sub_ca_eku_not_technically_constrained Boolean No
zlint.lints.n_subject_common_name_included Boolean No
zlint.lints.w_distribution_point_missing_ldap_or_uri Boolean No
zlint.lints.w_dnsname_underscore_in_trd Boolean No
zlint.lints.w_dnsname_wildcard_left_of_public_suffix Boolean No
zlint.lints.w_eku_critical_improperly Boolean No
zlint.lints.w_ext_aia_access_location_missing Boolean No
zlint.lints.w_ext_cert_policy_contains_noticeref Boolean No
zlint.lints.w_ext_cert_policy_explicit_text_includes_control Boolean No
zlint.lints.w_ext_cert_policy_explicit_text_not_nfc Boolean No
zlint.lints.w_ext_cert_policy_explicit_text_not_utf8 Boolean No
zlint.lints.w_ext_crl_distribution_marked_critical Boolean No
zlint.lints.w_ext_ian_critical Boolean No
zlint.lints.w_ext_key_usage_not_critical Boolean No
zlint.lints.w_ext_policy_map_not_critical Boolean No
zlint.lints.w_ext_policy_map_not_in_cert_policy Boolean No
zlint.lints.w_ext_san_critical_with_subject_dn Boolean No
zlint.lints.w_ext_subject_key_identifier_missing_sub_cert Boolean No
zlint.lints.w_ian_iana_pub_suffix_empty Boolean No
zlint.lints.w_issuer_dn_leading_whitespace Boolean No
zlint.lints.w_issuer_dn_trailing_whitespace Boolean No
zlint.lints.w_multiple_issuer_rdn Boolean No
zlint.lints.w_multiple_subject_rdn Boolean No
zlint.lints.w_name_constraint_on_edi_party_name Boolean No
zlint.lints.w_name_constraint_on_registered_id Boolean No
zlint.lints.w_name_constraint_on_x400 Boolean No
zlint.lints.w_root_ca_basic_constraints_path_len_constraint_field_present Boolean No
zlint.lints.w_root_ca_contains_cert_policy Boolean No
zlint.lints.w_rsa_mod_factors_smaller_than_752 Boolean No
zlint.lints.w_rsa_mod_not_odd Boolean No
zlint.lints.w_rsa_public_exponent_not_in_range Boolean No
zlint.lints.w_san_iana_pub_suffix_empty Boolean No
zlint.lints.w_serial_number_low_entropy Boolean No
zlint.lints.w_sub_ca_aia_does_not_contain_issuing_ca_url Boolean No
zlint.lints.w_sub_ca_certificate_policies_marked_critical Boolean No
zlint.lints.w_sub_ca_eku_critical Boolean No
zlint.lints.w_sub_ca_name_constraints_not_critical Boolean No
zlint.lints.w_sub_cert_aia_does_not_contain_issuing_ca_url Boolean No
zlint.lints.w_sub_cert_certificate_policies_marked_critical Boolean No
zlint.lints.w_sub_cert_eku_extra_values Boolean No
zlint.lints.w_sub_cert_sha1_expiration_too_long Boolean No
zlint.lints.w_subject_dn_leading_whitespace Boolean No
zlint.lints.w_subject_dn_trailing_whitespace Boolean No
zlint.notices_present Boolean No
zlint.version Integer No
zlint.warnings_present Boolean No