Thawte Intermediate CA Certificates for CodeSign 
Thawte Intermediate CA Certificates for SSL 123 
Thawte Intermediate CA Certificates for SGC Supercerts 
Thawte Intermediate CA Certificates for SSL WebServer 
Thawte Intermediate CA Certificates for SSL WebServer Wildcard 
Thawte Intermediate CA Certificates for SSL WebServer EV 
All Thawte CA Certificates 
Thawte Root Certificates 
Thawte CA Certificates Official link 
Thawte Root Certificates Official link 
Converter SSL 
Thawte Root Certificates
ALL ROOT CERTIFICATES ARE PROVIDED "AS IS" WITHOUT ANY WARRANTY WHATSOEVER. SYMANTEC HEREBY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WITHOUT LIMITATION, ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT OF THIRD PARTY RIGHTS. SYMANTEC FURTHER DISCLAIMS ANY WARRANTY FOR ANY OUTDATED ROOTS THAT ARE REPLACED BY UPDATED ROOTS MADE AVAILABLE BY SYMANTEC.
Download a root package with all the Thawte roots.
This root CA is the root used for Thawte Extended Validation Certificates and should be included in root stores.
After June, 2010 this root will also be the primary root used for all Thawte SSL and Code Signing certificates.
Country = US
Organization = thawte, Inc.
Organizational Unit = Certification Services Division
Organizational Unit = (c) 2006 thawte, Inc. - For authorized use only
Common Name = thawte Primary Root CA
Validity Start: November 17, 2006
Validity End: July 16, 2036
Key Size: RSA (2048 bits)
Signature Algorithm: SHA1 With RSA
Serial Number: 34 4e d5 57 20 d5 ed ec 49 f4 2f ce 37 db 2b 6d
Certificate SHA1 fingerprint: 91 c6 d6 ee 3e 8a c8 63 84 e5 48 c2 99 29 5c 75 6c 81 7b 81
Test Site: https://ssltest7.bbtest.net
|
Select
|
This root CA is the root currently used for Thawte Web Server Certificates and Code Signing Certificates.
It is intended to be the primary root used for these products until mid 2010 when Thawte transitions to using
a 2048 bit root. . After that transition this root will be used as part of a cross certification to ensure legacy
applications continue to trust Thawte certificates and must continue to be included in root stores by vendors.
Vendors should not plan on removing support for this root until officially advised that the root is no longer
needed to support certificates or CRL validation.
Country = ZA
Organization = Thawte Consulting cc
Organizational Unit = Class 3 Public Primary Certification Authority - G2
Organizational Unit = Certification Services Division
Common name = Thawte Premium Server CA
Serial Number: 36 12 22 96 c5 e3 38 a5 20 a1 d2 5f 4c d7 09 54
Valid From: Wednesday, July 31, 1996
Valid to: Friday, January 01, 2021
Certificate SHA1 Fingerprint: e0 ab 05 94 20 72 54 93 05 60 62 02 36 70 f7 cd 2e fc 66 66
Key Size: RSA(1024 Bits)
Signature Algorithm: sha1RSA
Test Site: https://ssltest28.bbtest.net
|
Select
|
This root CA is the root used for SSL123 It is intended to be the primary root used for these products until mid 2010
when VeriSign transitions to using a 2048 bit root. Vendors should not plan on removing support for this root until
officially advised that the root is no longer needed to support certificates or CRL validation.
Country = ZA
Organization = Thawte Consulting cc
Organizational Unit = Class 3 Public Primary Certification Authority - G2
Organizational Unit = Certification Services Division
Common name = Thawte Server CA
Serial Number: 01
Valid From: Wednesday, July 31, 1996
Valid to: Thursday, December 31, 2020
Certificate SHA1 Thumbprint: 23 e5 94 94 51 95 f2 41 48 03 b4 d5 64 d2 a3 a3 f5 d8 8b 8c
Key Size: RSA(1024 Bits)
Signature Algorithm: MD5RSA
Test Site: https://ssltest29.bbtest.net
|
Select
|
This root CA is not used today. It is intended for use in the future for SSL and Code Signing services needing an
ECC encryption algorithm. This root should be included in root stores.
Country = US
Organization = thawte, Inc.
Organizational Unit = (c) 2007 thawte, Inc. - For authorized use only
Common Name = thawte Primary Root CA - G2
Serial Number: 35 fc 26 5c d9 84 4f c9 3d 26 3d 57 9b ae d7 56
Valid From: Sunday, November 04, 2007 5:00:00 PM
Valid to: Monday, January 18, 2038 4:59:59 PM
Certificate SHA1 Fingerprint: aa db bc 22 23 8f c4 01 a1 27 bb 38 dd f4 1d db 08 9e f0 12
Signature Algorithm: SHA384 With ECC
|
Select
|
This root is not being used today. It is intended for use in the future for SSL nd Code Signing certificates requiring SHA 256
encryption algorithm. This root should be included in root stores.
Country = US
Organization = thawte, Inc.
Organizational Unit = Certification Services Division
Organizational Unit = (c) 2008 thawte, Inc. - For authorized use only
Common Name = thawte Primary Root CA - G3
Serial Number: 60 01 97 b7 46 a7 ea b4 b4 9a d6 4b 2f f7 90 fb
Valid From: Tuesday, April 01, 2008 5:00:00 PM
Valid to: Tuesday, December 01, 2037 4:59:59 PM
Certificate SHA1 Fingerprint: f1 8b 53 8d 1b e9 03 b6 a6 f0 56 43 5b 17 15 89 ca f3 6b f2
Signature Algorithm: SHA256 With RSA
|
Select
|
thawte is a commercial CA with worldwide operations and customer base; it is a subsidiary of VeriSign, Inc.
Audit:WebTrust/WebTrust EV, performed by KPMG:Audit Report and Management's Assertions
thawte Primary Root CA - G2
This CA will be used to sign certificates for SSL-enabled servers, and may in the future be used to sign certificates for
digitally-signed executable code objects. thawte is not yet actively issuing certificates from this root, so they have not
yet published a CRL. All subordinated CAs for this root will be internally operated.
thawte Primary Root CA - G3
This CA will be used to sign certificates for SSL-enabled servers, and may in the future be used to sign certificates for
digitally-signed executable code objects. thawte is not yet actively issuing certificates from this root, so they have not
yet published a CRL. All subordinated CAs for this root will be internally operated.
thawte Primary Root CA
This CA issues a CA certificate to the subordinate CAs thawte Extended Validation SSL CA and thawte Extended
Validation SSL SGC CA, which in turn issue Extended Validation certificates for SSL-enabled servers.
| Link | Download/Install |
| SHA1 | 91:C6:D6:EE:3E:8A:C8:63:84:E5:48:C2:99:29:5C:75:6C:81:7B:81 |
| Version | 3 |
| Modulus (key length) | 2048 |
| Valid From | 2006-11-17 |
| Valid To | 2036-07-16 |
| Revocation | CRL, OCSP |
| Type | EV (policy OID 2.16.840.1.113733.1.7.48.1) |
| Document | thawte Certification Practice Statement, Version 3.5 (January 2008) |
| Requested Trust Bits | |
| Bugs | Authorisation (407163), Inclusion (424152), EV (424154) |
| Comments | Note that for compatibility reasons thawte has implemented a cross-signing scheme involving this CA. In this scheme, if applications not supporting EV functionality (e.g., Firefox 2 and earlier) encounter thawte EV certificates then they will end up treating this CA as a subordinate CA under the existing Thawte Premium Server CA root. |
|