Created November 7, 2016 14:24
One-line Bash script to fetch the issuer CA certificate of an x509-specified certificate via id-ad-caIssuers of x509.v3 Authority Information Access extension.
# Maintainer: Gowe Wang<>
# Reference:
# Notice: Just available in most cases.
curl -s $(openssl x509 -in $1 -noout -text | grep -Po "((?<=CA Issuers - URI:)http://.*)$") | openssl x509 -inform DER -outform PEM
Gowee commented Nov 7, 2016

Usage: /path/to/your/cert/in/PEM
Known issues:
Does not work in some cases where id-ad-caIssuers or even AIA is not available or id-ad-caIssuers is not distributed via HTTP or in DER format.(Won't fix.)

