Skip to content

Instantly share code, notes, and snippets.

@schlarpc
Created September 16, 2025 03:21
Show Gist options
  • Save schlarpc/2c9612eae7a6f3c2f3ae1692a2f4a8d0 to your computer and use it in GitHub Desktop.
Save schlarpc/2c9612eae7a6f3c2f3ae1692a2f4a8d0 to your computer and use it in GitHub Desktop.
Netscape Navigator 2.0 root CAs

Netscape Navigator 2.0 root CAs

These are ripped out of Netscape Navigator 2.0 for Windows.

CERT.DB in the installed program is a Berkley DB 1.85 file. Its entries consist of a 7 byte header, a DER-encoded CA certificate, followed by a null terminated friendly name.

I have extracted these certificates and they are presented below.

RSA Secure Server CA

-----BEGIN CERTIFICATE-----
MIICKTCCAZYCBQJBAAABMA0GCSqGSIb3DQEBAgUAMF8xCzAJBgNVBAYTAlVTMSAw
HgYDVQQKExdSU0EgRGF0YSBTZWN1cml0eSwgSW5jLjEuMCwGA1UECxMlU2VjdXJl
IFNlcnZlciBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw05NDExMDkyMzU0MTda
Fw05OTEyMzEyMzU0MTdaMF8xCzAJBgNVBAYTAlVTMSAwHgYDVQQKExdSU0EgRGF0
YSBTZWN1cml0eSwgSW5jLjEuMCwGA1UECxMlU2VjdXJlIFNlcnZlciBDZXJ0aWZp
Y2F0aW9uIEF1dGhvcml0eTCBmzANBgkqhkiG9w0BAQEFAAOBiQAwgYUCfgCSznrB
roM+WqqJg1esJQF2DK2ujiw3zus1eGRUA+WEQFHJv48I4oqCCNIWhjdV6bEhAq12
aIGaBaJLyUslZiJWbIgHj/eBWW2EB2VwE3F2Ppt3TONQiVaYSLkdpykaEy5KEVmc
HhXVSVQsczppgrGXOZxtcGdI5d0t1sgeewIDAQABMA0GCSqGSIb3DQEBAgUAA34A
iNHReSHO4ovo+MF9NFM/YYPZtgs4F7boviGNjwC4i1N+RGceIr2XJ+CchcxK9oU7
suK+ktPlDemvXA4MRpX/oRxePug2WHpzpgr4IhFrwwk4fia7c+8AvQKk8xQNMD9h
cHsg/jKjn7P0Z1LctO6EjJY2IN6BCINxIYoPnqk=
-----END CERTIFICATE-----

Subject/Issuer

  • Subject: OU=Secure Server Certification Authority,O=RSA Data Security, Inc.,C=US
  • Issuer: OU=Secure Server Certification Authority,O=RSA Data Security, Inc.,C=US
  • Serial: 0x241000001

Validity

  • Not Before: 1994-11-09T23:54:17
  • Not After: 1999-12-31T23:54:17

Algorithms

  • Signature OID: 1.2.840.113549.1.1.2 (md2WithRSAEncryption)
  • Public Key: RSA, 1000 bits

Fingerprints

  • MD5: 115632b0c42739458d5cf441895f1c72
  • SHA-1: 0d974461703713cb74932d2a75acbc714b281266
  • SHA-256: b6e5b9fa1c5fd742328e7d3ef5fdc5b5e4c112ae6b366ab2d00df272bbc4bca1

ATT CA

-----BEGIN CERTIFICATE-----
MIIB7zCCAVgCBQJqAAABMA0GCSqGSIb3DQEBAgUAMD4xCzAJBgNVBAYTAlVTMQ0w
CwYDVQQKFARBVCZUMSAwHgYDVQQLExdDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAe
Fw05NTA0MTgwMDAwMDBaFw05NjA0MTcyMzU5NTlaMD4xCzAJBgNVBAYTAlVTMQ0w
CwYDVQQKFARBVCZUMSAwHgYDVQQLExdDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTCB
nzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAw9WxrKED4s16flgydYS1U08jf80x
KjiEaaZMoV1zQxP6rZ6MS296Jj6XGGHuK0tr+Z6dDGe2GP8c+RXX+yd+WuXFiXH1
igVlHYqIduoEN6cG6iKHN4F6jRrrXIJwjCddHsEtpnJLzlmXW3lWwIwFJ/irbL9V
tzRHDHg2ajcjRi8CAwEAATANBgkqhkiG9w0BAQIFAAOBgQB/kDiOn3vNKrKj9bGa
CIlZn6CS+i/0GEXl/j/vpAIfnZn889YGcY1DEPFC9PDj8Eidqhn3qgkZROiaPX43
gllhPBRXPe+7Kh/ziG5VolB1nyLInnu16vUpblF27kL3g1I0L9HS9syv0jd0nZfw
C8/gXQnN/Z4YOax1PPZLvY134g==
-----END CERTIFICATE-----

Subject/Issuer

  • Subject: OU=Certification Authority,O=AT&T,C=US
  • Issuer: OU=Certification Authority,O=AT&T,C=US
  • Serial: 0x26a000001

Validity

  • Not Before: 1995-04-18T00:00:00
  • Not After: 1996-04-17T23:59:59

Algorithms

  • Signature OID: 1.2.840.113549.1.1.2 (md2WithRSAEncryption)
  • Public Key: RSA, 1024 bits

Fingerprints

  • MD5: 4ee4fdf4c0c94ffff8e2304bce3d39a0
  • SHA-1: 716adf4b8ff8132307dfbfce5f3a22d850816f90
  • SHA-256: 10091f84a726e53b5cbf3e1fce9b69cac6495ff432b2a057196d2a5685b309f7

RSA Commercial CA

-----BEGIN CERTIFICATE-----
MIICIzCCAZACBQJBAAAWMA0GCSqGSIb3DQEBAgUAMFwxCzAJBgNVBAYTAlVTMSAw
HgYDVQQKExdSU0EgRGF0YSBTZWN1cml0eSwgSW5jLjErMCkGA1UECxMiQ29tbWVy
Y2lhbCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw05NDExMDQxODU4MzRaFw05
OTExMDMxODU4MzRaMFwxCzAJBgNVBAYTAlVTMSAwHgYDVQQKExdSU0EgRGF0YSBT
ZWN1cml0eSwgSW5jLjErMCkGA1UECxMiQ29tbWVyY2lhbCBDZXJ0aWZpY2F0aW9u
IEF1dGhvcml0eTCBmzANBgkqhkiG9w0BAQEFAAOBiQAwgYUCfgCk+4Fie84QJ93o
975sbsZwmdu41QUDaSiCnHJ/lj+O7Kwpkj+KFPhCdr69XQO5kNTQvAayUTNfxMK/
touPmbZiImDd298ggrTKoi8tUO2UMt7gVY3UaOLgTNLNBRYulWZcYVI4HlGogqHE
7yXpCuaLK44xZtn42f29O2nZ6wIDAQABMA0GCSqGSIb3DQEBAgUAA34AdrW2EP4j
9/dZYkuwX5zBaLxJu7NJbyFHXSudVMQAKD+YufKKg5tgf+tQx6sFEC097TgCwaVI
0v5loMC86qYjFmZsGySp8+x5NRhPJsjjr1BKx6cxa9B8GJ1Qv6km+iYrRpwUqbtb
MJhCKLVLU7tDCZJAuqiqWqTGtotXTcU=
-----END CERTIFICATE-----

Subject/Issuer

  • Subject: OU=Commercial Certification Authority,O=RSA Data Security, Inc.,C=US
  • Issuer: OU=Commercial Certification Authority,O=RSA Data Security, Inc.,C=US
  • Serial: 0x241000016

Validity

  • Not Before: 1994-11-04T18:58:34
  • Not After: 1999-11-03T18:58:34

Algorithms

  • Signature OID: 1.2.840.113549.1.1.2 (md2WithRSAEncryption)
  • Public Key: RSA, 1000 bits

Fingerprints

  • MD5: 5a0bdd429eb2b46297327f7f0aaa9a39
  • SHA-1: 90807053a0099ffd1d732540e5593ec7662897ed
  • SHA-256: 349b88d9806fb23e3b340d230878c37db1ff891e69087fff6039471f37af33de

ATT Research CA

-----BEGIN CERTIFICATE-----
MIICCDCCAXECAQAwDQYJKoZIhvcNAQEEBQAwTjELMAkGA1UEBhMCVVMxHzAdBgNV
BAoUFkFUJlQgQmVsbCBMYWJvcmF0b3JpZXMxHjAcBgNVBAsUFVByb3RvdHlwZSBS
ZXNlYXJjaCBDQTAeFw05NTA0MTMyMTA2NTZaFw05NzA0MTIyMTA2NTZaME4xCzAJ
BgNVBAYTAlVTMR8wHQYDVQQKFBZBVCZUIEJlbGwgTGFib3JhdG9yaWVzMR4wHAYD
VQQLFBVQcm90b3R5cGUgUmVzZWFyY2ggQ0EwgZwwDQYJKoZIhvcNAQEBBQADgYoA
MIGGAoGAebOmgtSCl+wCYZc86UGYeTLY8cjmW2P0FN8ToT/u2pECCoFdrlycX0OR
3wt0ZhpFXLVNeDnHwEE9veNUih7pCL2ZBFqoIoQkB1lZmXRiVtjGonz8BLm/qrFM
YHb0lme/Ol+s118mwKVxnn6bSAeI/OXKhLaVdYZWk+aEaxEDkVkCAQ8wDQYJKoZI
hvcNAQEEBQADgYEAAZMG14lZmZ8bahkaHaTV9dQf4p2FZiQTFwHP9ZyGsXPC+LT5
dG5iTaRmyjNIJdPWohZDl97kAci79aBndvuEvRKOjLHs3WRGBIwERnAcnY9Mz8u/
zIHK23PjYVxGGaZd669OJwD0CYyqH22HH9nFUGaoJdsv39ChW0NRdLE9+y8=
-----END CERTIFICATE-----

Subject/Issuer

  • Subject: OU=Prototype Research CA,O=AT&T Bell Laboratories,C=US
  • Issuer: OU=Prototype Research CA,O=AT&T Bell Laboratories,C=US
  • Serial: 0x0

Validity

  • Not Before: 1995-04-13T21:06:56
  • Not After: 1997-04-12T21:06:56

Algorithms

  • Signature OID: 1.2.840.113549.1.1.4 (md5WithRSAEncryption)
  • Public Key: RSA, 1023 bits

Fingerprints

  • MD5: 79642da5b3d04df47fae8165e5ce6f98
  • SHA-1: 4bc8fe4a244d46ef6640fb3cd6e5dc9cd754e463
  • SHA-256: 7de7df5473050391609563c9e2f3f6932f41fd70b26f571525c5256869a426f5

Netscape Test CA

-----BEGIN CERTIFICATE-----
MIIB/DCCAWUCAgIaMA0GCSqGSIb3DQEBBAUAMEcxCzAJBgNVBAYTAlVTMRAwDgYD
VQQLEwdUZXN0IENBMSYwJAYDVQQKEx1OZXRzY2FwZSBDb21tdW5pY2F0aW9ucyBD
b3JwLjAeFw05NTA5MjIyMjEzMzVaFw05NTExMjEyMjEzMzVaMEcxCzAJBgNVBAYT
AlVTMRAwDgYDVQQLEwdUZXN0IENBMSYwJAYDVQQKEx1OZXRzY2FwZSBDb21tdW5p
Y2F0aW9ucyBDb3JwLjCBnTANBgkqhkiG9w0BAQEFAAOBiwAwgYcCgYEAtGyK7LoY
e3KhPMvpgRUt35uyglsTUAIq/nxRB+YUw2CtFVbe8KcywaA0laNqTr8hSEpKIX1r
NxJZirjJZf+nRaAWt+G4y1IOFr3gFt3dpzZnPgm52zO9dPzeWJTPKLOW1Y4zYR/L
QD8qKS0LaIcVaP0JAOB3TtJAGj5fnNPMFmMCAQMwDQYJKoZIhvcNAQEEBQADgYEA
CksO14NPeYXC9zSVj9v2m6qysD8saWxeB2WXVqRA/Z+w3WMsEC9lDRBNvwpD7pWR
lq8OS/FjWDpUAYW46YC3zOULI1cwHs8sMqlabm9FrN65cKaOeQRfUAvEpy6AXUjm
kYCS9iXuYqRlvM1pNG1Hryd4RBvWkKX083FBtwaNur0=
-----END CERTIFICATE-----

Subject/Issuer

  • Subject: O=Netscape Communications Corp.,OU=Test CA,C=US
  • Issuer: O=Netscape Communications Corp.,OU=Test CA,C=US
  • Serial: 0x21a

Validity

  • Not Before: 1995-09-22T22:13:35
  • Not After: 1995-11-21T22:13:35

Algorithms

  • Signature OID: 1.2.840.113549.1.1.4 (md5WithRSAEncryption)
  • Public Key: RSA, 1024 bits

Fingerprints

  • MD5: 74f25520ce0406a8e34c5fe63c7932ed
  • SHA-1: acfecb429e9dcaf1611093d30ac30ad9fe015030
  • SHA-256: 3b871457345da9fd002c8a94d062c7b4a624d6fcc0e521788c2de2f6f71fc61b

MCI Mall CA

This one won't parse in either OpenSSL or Python's cryptography library. Instead, here's the hex-encoded DER and an ASN.1 tree.

308201ee308201570205026e000001300d06092a864886f70d0101020500303f
310b3009060355040613025553310c300a060355040a13034d43493114301206
0355040b130b696e7465726e65744d4349310c300a060355040b130350434130
1a170b393431313232323030305a170b393631313231323335395a3040310b30
09060355040613025553310c300a060355040a13034d43493114301206035504
0b130b696e7465726e65744d4349310d300b060355040b13044d414c4c30819f
300d06092a864886f70d010101050003818d0030818902818100e321235f51a8
2dc08fae10f06fce4880f2945e8883fce43f0d371e34f0080c924da3fbcba506
e99ed636300627cc4988dfc59f5f936c1fa941eca0d4d29876556fc5a3a54249
86f725c61ec8433191fb49e6df4e36cc6dd5e0fe188c43f2eb13399527d42bac
98eba90f2d219b5c9b5bcf1c441926816e88ed9a63bb5676516f020301000130
0d06092a864886f70d01010205000381810081fe5a56aec2719166c9f3932e1e
50ac4b1906e571ccafb7188bf9224f2c6a62c365177a40393346e355aff392ba
154e75926af3696b4795100ba012848e433255ce3038436679c8ea4736a6aff3
e088b779411f92e8fa850a6df2b9ceb768f42f62f72de85626c3c4429f0484a6
96c3bf532c63615035a50316706d5b7adcd6
SEQUENCE
  SEQUENCE
    INTEGER 026e000001
    SEQUENCE
      ObjectIdentifier MD2withRSA (1 2 840 113549 1 1 2)
      NULL
    SEQUENCE
      SET
        SEQUENCE
          ObjectIdentifier countryName (2 5 4 6)
          PrintableString 'US'
      SET
        SEQUENCE
          ObjectIdentifier organizationName (2 5 4 10)
          PrintableString 'MCI'
      SET
        SEQUENCE
          ObjectIdentifier organizationalUnitName (2 5 4 11)
          PrintableString 'internetMCI'
      SET
        SEQUENCE
          ObjectIdentifier organizationalUnitName (2 5 4 11)
          PrintableString 'PCA'
    SEQUENCE
      UTCTime 9411222000Z
      UTCTime 9611212359Z
    SEQUENCE
      SET
        SEQUENCE
          ObjectIdentifier countryName (2 5 4 6)
          PrintableString 'US'
      SET
        SEQUENCE
          ObjectIdentifier organizationName (2 5 4 10)
          PrintableString 'MCI'
      SET
        SEQUENCE
          ObjectIdentifier organizationalUnitName (2 5 4 11)
          PrintableString 'internetMCI'
      SET
        SEQUENCE
          ObjectIdentifier organizationalUnitName (2 5 4 11)
          PrintableString 'MALL'
    SEQUENCE
      SEQUENCE
        ObjectIdentifier rsaEncryption (1 2 840 113549 1 1 1)
        NULL
      BITSTRING, encapsulates
        SEQUENCE
          INTEGER 00e321235f51a82dc08fae10f06fce48..(total 129bytes)..cf1c441926816e88ed9a63bb5676516f
          INTEGER 010001
  SEQUENCE
    ObjectIdentifier MD2withRSA (1 2 840 113549 1 1 2)
    NULL
  BITSTRING 0081fe5a56aec2719166c9f3932e1e50..(total 129bytes)..bf532c63615035a50316706d5b7adcd6

CommerceNet CA

-----BEGIN CERTIFICATE-----
MIIB/zCCAWwCBQJBAAAeMA0GCSqGSIb3DQEBAgUAMF8xCzAJBgNVBAYTAlVTMSAw
HgYDVQQKExdSU0EgRGF0YSBTZWN1cml0eSwgSW5jLjEuMCwGA1UECxMlU2VjdXJl
IFNlcnZlciBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw05NTAzMTMxODM4NDZa
Fw05NjAzMTIxODM4NDZaMGExCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9y
bmlhMRQwEgYDVQQKEwtDb21tZXJjZU5ldDEnMCUGA1UECxMeU2VydmVyIENlcnRp
ZmljYXRpb24gQXV0aG9yaXR5MHAwDQYJKoZIhvcNAQEBBQADXwAwXAJVLVjpv/Ax
zXkGUFrVng4s5sL3+dLOVWSFsZCakrM2wbzqyCO3qzqnZGN3X4QijuW2Rd1Grgrd
AMIfutmtwHVi+JWCooCxgmn64a9/vH3ifHbVvCqA+wIDAQABMA0GCSqGSIb3DQEB
AgUAA34ABaVlnZPviJfGrcqjA9HF7z6d/Eyyr4pWS9CbsVyHPzc3GvrcAXPYBgKs
IB5KSEPB8ZdJ4nHstCgtMmOK9u7oOgUYlpZz5pRWFN520P2LeJ9EQBhqu7dG/dyG
2nps2lujEOYa7CAHv/1qkwfCHjgujO8P1IH0qkiqKqjvAv8=
-----END CERTIFICATE-----

Subject/Issuer

  • Subject: OU=Server Certification Authority,O=CommerceNet,ST=California,C=US
  • Issuer: OU=Secure Server Certification Authority,O=RSA Data Security, Inc.,C=US
  • Serial: 0x24100001e

Validity

  • Not Before: 1995-03-13T18:38:46
  • Not After: 1996-03-12T18:38:46

Algorithms

  • Signature OID: 1.2.840.113549.1.1.2 (md2WithRSAEncryption)
  • Public Key: RSA, 678 bits

Fingerprints

  • MD5: daccb0043f0bd613f202a3cfe00613ae
  • SHA-1: 225d1518773bc6174d99bcd2370b45ee75335f90
  • SHA-256: 729d845bc2af81b194a633e906430917608441230a0cbd080cd699c8f246a135
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment