| Field | Subordinate CA Value |
| Version | V3 (2) |
| Serial Number | Must be unique |
| Issuer Signature Algorithm |
sha-1WithRSAEncryption {1 2 840 113549 1 1 5} |
| Issuer Distinguished Name |
cn=ECA Root CA, ou=ECA, o=U.S. Government, c=US |
| Validity Period | 6 years from date of issue in UTCT format |
| Subject Distinguished Name |
cn=ORC ECA, ou=Certification Authorities, ou=ECA, o=U.S. Government, c=US |
| Subject Public Key Information |
1024 bit RSA key modulus, rsaEncryption {1 2 840 113549 1 1 1} |
| Issuer Unique Identifier | Not Present |
| Subject Unique Identifier | Not Present |
| Issuer’s Signature | sha-1WithRSAEncryption {1 2 840 113549 1 1 5} |
| Extensions | |
| Authority Key Identifier | Octet String (20 byte SHA-1 hash of the binary DER encoding of the ECA Root CA’s public key information) |
| Subject Key Identifier | Octet String (20 byte SHA-1 hash of the binary DER encoding of the ECA public key information) |
| Key Usage | c=yes; digitalSignature, keyCertSign, cRLSign |
| Extended Key Usage |
Not Present |
| Private Key Usage Period |
Not Present |
| Certificate Policies | c=no; {2 16 840 1 101 3 2 1 12 1}, {2 16 840 1 101 3 2 1 12 2} |
| Policy Mapping | Not Present |
| Subject Alternative Name |
Not Present |
| Issuer Alternative Name |
Not Present |
| Subject Directory Attributes |
Not Present |
| Basic Constraints | c=yes; cA=True; path length constraint = 0 |
| Name Constraints | C=no; permitted subtrees: ou=ORC, ou=ECA, o=U.S. Government, c=US |
| Policy Constraints | Not Present |
| Authority Information Access |
Not Present |
| CRL Distribution Points |
c = no; always present, ldap://eca-ds.orc.com/cn=ECA Root CA, ou=ECA, o=U.S. Government,c=US?certificaterevocationlist;binary |