blob: 44ab7c5103843eca402f2d36101a0f8dc4bafa35 [file] [log] [blame]
[Created by: generate-chains.py]
Certificate chain where the leaf has a basic constraints extension with
CA=false, however specifies the optional pathlen.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
2d:58:fd:1c:9f:8b:f0:cb:61:00:36:cc:88:b7:31:82:91:15:f5:15
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:ba:80:5c:f0:d7:23:f0:69:d9:b7:8f:fc:c3:d4:
47:a2:41:29:77:01:50:3c:84:8f:52:f7:11:6d:c4:
75:04:84:48:98:8c:4e:bb:f6:4b:e2:cb:4d:be:01:
dc:b2:8e:48:b6:da:76:4d:b0:28:75:94:28:d7:44:
2c:0d:a5:70:fe:b8:ec:c3:d0:0d:8b:74:4a:18:b9:
13:bb:b1:99:80:09:d0:bd:00:a3:20:64:70:bb:18:
00:7c:61:1f:5d:d2:dc:23:6a:6a:e3:8a:6c:13:9b:
a3:c5:7b:dc:91:71:29:46:4e:1c:8e:82:2a:d6:bb:
f9:5a:91:be:f0:a7:a9:b2:d5:8c:df:a2:d2:eb:3a:
e4:49:30:8b:83:20:6d:fb:af:90:19:3e:44:b5:d3:
bb:05:a1:15:a1:0d:4c:61:82:63:5e:24:a5:94:df:
a9:35:5a:0f:56:eb:8c:1d:a5:0e:80:4a:16:d1:ef:
dd:cf:84:f6:45:55:65:55:b8:73:ae:ca:1c:f8:c7:
e2:67:e8:8a:42:5e:eb:f6:2c:bf:55:1c:18:39:51:
5b:15:16:1b:0a:06:ba:b0:ad:bc:45:2d:23:5c:3a:
ca:2b:04:c9:a2:4f:a6:80:ec:d2:b8:d7:98:44:69:
3c:3c:2e:ab:b4:44:e2:50:6a:b8:a6:59:db:d4:61:
54:fd
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
5B:3D:C4:92:95:A9:93:D8:29:1F:56:EB:DA:A0:3C:1A:C0:BD:5D:AB
X509v3 Authority Key Identifier:
keyid:FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE, pathlen:1
Signature Algorithm: sha256WithRSAEncryption
18:c7:ef:53:96:6c:fc:7d:06:87:5a:b7:cc:77:67:82:54:10:
eb:8e:21:a6:57:f3:83:cf:ee:ba:c0:59:cc:95:d3:1b:2a:92:
19:86:20:ee:7a:62:5c:cb:27:b9:71:22:a8:bb:f2:26:f6:15:
a7:5a:57:79:d1:d0:4a:06:17:4f:95:f9:37:ab:13:6e:dd:57:
3c:87:5e:dd:69:be:53:3a:51:3e:fc:7c:38:75:e3:20:cd:34:
0f:23:d1:35:c2:00:03:9e:64:51:00:1d:e1:56:04:9a:6c:73:
bd:fb:e3:f0:63:f3:11:04:59:83:42:19:7e:1d:a5:25:25:e0:
12:9c:60:87:07:6d:a7:99:3d:24:1f:dd:a6:c7:f7:dd:34:d9:
be:96:9c:e7:5a:21:f8:6b:8e:1b:77:7c:d8:04:6d:e4:7c:7a:
fd:ba:44:4a:13:1d:8c:c0:64:59:de:95:5d:50:3c:13:9d:26:
ee:36:08:d0:d0:fc:79:72:e1:af:d1:71:9c:7b:16:14:4b:2d:
eb:e7:c2:6d:0a:cd:cd:ff:02:95:ff:60:af:32:42:58:69:8f:
08:b1:a3:d6:37:80:6f:ce:93:83:c9:c5:52:8d:60:c3:6c:8c:
62:20:7f:75:64:03:10:30:24:34:7b:20:b9:dc:21:83:fc:fa:
b9:b5:11:03
-----BEGIN CERTIFICATE-----
MIIDsTCCApmgAwIBAgIULVj9HJ+L8MthADbMiLcxgpEV9RUwDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAuoBc8Ncj8GnZt4/8w9RHokEpdwFQPISPUvcRbcR1BIRI
mIxOu/ZL4stNvgHcso5Ittp2TbAodZQo10QsDaVw/rjsw9ANi3RKGLkTu7GZgAnQ
vQCjIGRwuxgAfGEfXdLcI2pq44psE5ujxXvckXEpRk4cjoIq1rv5WpG+8KepstWM
36LS6zrkSTCLgyBt+6+QGT5EtdO7BaEVoQ1MYYJjXiSllN+pNVoPVuuMHaUOgEoW
0e/dz4T2RVVlVbhzrsoc+MfiZ+iKQl7r9iy/VRwYOVFbFRYbCga6sK28RS0jXDrK
KwTJok+mgOzSuNeYRGk8PC6rtETiUGq4plnb1GFU/QIDAQABo4H6MIH3MB0GA1Ud
DgQWBBRbPcSSlamT2CkfVuvaoDwawL1dqzAfBgNVHSMEGDAWgBT7OkOcukCJclu9
Joo7JXccwfAsfjA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwIB
ATANBgkqhkiG9w0BAQsFAAOCAQEAGMfvU5Zs/H0Gh1q3zHdnglQQ644hplfzg8/u
usBZzJXTGyqSGYYg7npiXMsnuXEiqLvyJvYVp1pXedHQSgYXT5X5N6sTbt1XPIde
3Wm+UzpRPvx8OHXjIM00DyPRNcIAA55kUQAd4VYEmmxzvfvj8GPzEQRZg0IZfh2l
JSXgEpxghwdtp5k9JB/dpsf33TTZvpac51oh+GuOG3d82ARt5Hx6/bpEShMdjMBk
Wd6VXVA8E50m7jYI0ND8eXLhr9FxnHsWFEst6+fCbQrNzf8Clf9grzJCWGmPCLGj
1jeAb86Tg8nFUo1gw2yMYiB/dWQDEDAkNHsgudwhg/z6ubURAw==
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fe
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:b1:bb:78:97:4a:b5:56:42:fa:f9:6b:63:6c:f3:
0e:54:92:6c:84:d4:c7:53:48:24:c1:bd:6f:d0:83:
ad:f3:7a:5c:93:f1:74:38:ba:46:f1:19:db:0e:fb:
1b:b4:f2:9e:8b:c4:10:8e:97:b1:ff:f8:2d:03:cd:
36:91:8a:2c:e8:d8:da:a4:7e:58:8d:fb:ff:99:2b:
d5:e1:b3:63:7f:ec:2c:66:b5:0d:ca:ba:e1:74:5e:
b3:ad:bf:49:65:74:52:30:78:ed:ea:7c:08:26:32:
f1:d5:e3:ea:01:7e:3a:fc:0e:84:d6:17:aa:98:f8:
92:63:77:4d:5c:d3:13:61:af:e3:d8:35:0c:ff:1e:
39:91:0c:24:a9:ec:89:ab:28:97:97:56:eb:2a:73:
70:e7:46:17:89:1e:42:73:a5:f6:b6:de:5a:bc:24:
69:5d:41:09:31:f6:12:d3:57:2d:dc:96:9c:0a:4d:
64:f0:c4:24:44:8e:1d:66:37:a1:01:1a:d5:89:a8:
9c:81:82:00:d9:f5:56:e9:58:df:ea:5d:32:7e:fb:
2d:19:1b:39:b4:fb:77:2c:2e:e1:ae:f5:ea:b0:ad:
b7:d4:2e:35:86:26:9f:96:c6:e3:4c:27:7b:6a:7d:
a2:4e:bf:cb:59:33:85:6f:d1:98:e4:27:3c:95:3f:
fd:ad
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E
X509v3 Authority Key Identifier:
keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
a9:df:02:10:a3:f8:14:af:a4:b2:3d:bf:3a:5e:e1:0f:9e:fa:
e1:d0:5a:be:e8:a4:f4:db:b7:a6:1c:40:7a:06:0a:77:39:6f:
f5:b9:7f:3b:5d:61:05:fc:0f:2e:de:40:89:2e:1b:11:12:35:
96:44:a8:be:0b:35:f9:73:2f:81:bc:47:5c:01:b2:b8:22:7e:
ca:c9:56:54:68:1a:4a:98:ac:6f:43:06:4b:a5:12:4f:05:ec:
23:36:a5:5e:8e:a0:36:6b:35:12:e1:76:ad:84:77:af:eb:b6:
b8:f6:4b:21:98:53:c2:32:74:03:ff:7f:67:bf:0d:31:58:6b:
b5:bd:e7:c5:dc:e3:c4:04:1d:e0:c5:84:d9:6d:74:a3:21:66:
5e:99:af:18:9e:db:49:8d:83:92:34:00:a2:e7:89:d2:4b:f5:
6a:5e:02:a9:ab:3b:3d:23:01:34:c7:ee:99:3f:0e:75:55:ed:
99:c1:28:b1:39:da:2e:25:03:59:82:ed:7a:e8:32:8a:9a:fc:
fa:2a:e6:d1:13:0b:2b:9b:d7:a7:3e:23:e2:45:1a:a1:c1:e5:
4d:fb:a5:3c:a0:5e:ef:c0:d4:9a:d6:53:e7:4a:48:6c:31:8a:
92:60:7d:e8:d4:60:4a:6a:96:b0:f5:c2:a8:83:22:42:e0:1c:
aa:15:1b:af
-----BEGIN CERTIFICATE-----
MIIDgDCCAmigAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP4wDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBALG7eJdKtVZC+vlrY2zzDlSSbITUx1NIJMG9b9CDrfN6XJPx
dDi6RvEZ2w77G7TynovEEI6Xsf/4LQPNNpGKLOjY2qR+WI37/5kr1eGzY3/sLGa1
Dcq64XRes62/SWV0UjB47ep8CCYy8dXj6gF+OvwOhNYXqpj4kmN3TVzTE2Gv49g1
DP8eOZEMJKnsiasol5dW6ypzcOdGF4keQnOl9rbeWrwkaV1BCTH2EtNXLdyWnApN
ZPDEJESOHWY3oQEa1YmonIGCANn1VulY3+pdMn77LRkbObT7dywu4a716rCtt9Qu
NYYmn5bG40wne2p9ok6/y1kzhW/RmOQnPJU//a0CAwEAAaOByzCByDAdBgNVHQ4E
FgQU+zpDnLpAiXJbvSaKOyV3HMHwLH4wHwYDVR0jBBgwFoAUj05eeBmuKIJpL88z
lQTBzXXR9v8wNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MA0GCSqGSIb3DQEBCwUAA4IBAQCp3wIQo/gUr6SyPb86XuEPnvrh0Fq+6KT027em
HEB6Bgp3OW/1uX87XWEF/A8u3kCJLhsREjWWRKi+CzX5cy+BvEdcAbK4In7KyVZU
aBpKmKxvQwZLpRJPBewjNqVejqA2azUS4XathHev67a49kshmFPCMnQD/39nvw0x
WGu1vefF3OPEBB3gxYTZbXSjIWZema8YnttJjYOSNACi54nSS/VqXgKpqzs9IwE0
x+6ZPw51Ve2ZwSixOdouJQNZgu166DKKmvz6KubREwsrm9enPiPiRRqhweVN+6U8
oF7vwNSa1lPnSkhsMYqSYH3o1GBKapaw9cKogyJC4ByqFRuv
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fd
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:b3:59:c0:d6:b0:f3:cb:31:46:9d:ef:de:63:f3:
1a:24:10:36:fb:e8:ee:05:76:21:51:51:fd:52:47:
97:12:13:46:42:bc:94:37:5e:e6:41:d2:d8:75:27:
2c:3d:04:bc:e1:ac:bc:a8:f6:d8:74:63:9a:be:a9:
7b:d2:1b:96:87:25:3b:ce:d1:ff:b4:dd:fa:29:64:
ae:df:4c:1b:b4:fb:9e:8a:9a:6c:74:ba:2a:76:45:
03:b7:91:7e:90:ba:04:3d:dc:0a:17:77:b3:5f:dc:
56:07:eb:63:5e:2b:54:c9:d7:b3:4b:f3:42:6b:9e:
2a:80:9c:71:52:5d:0f:6d:97:c6:d3:f6:c4:7a:7a:
ee:ea:22:4f:1c:e8:42:55:6e:b2:2a:56:cf:86:3c:
94:d1:e7:e0:7c:78:8c:94:05:05:b0:3f:b2:70:18:
da:92:d2:9a:ba:57:7c:fb:52:4b:0f:34:cb:dc:ab:
40:a0:76:4e:cc:11:b9:57:be:f2:e2:fa:2b:ba:20:
b0:c8:ee:8d:0a:11:a2:02:d4:f7:38:3d:f4:a8:49:
f4:b4:8a:08:ff:d0:c3:25:21:0e:dc:f0:17:22:f2:
bf:07:3d:e7:5f:4c:b2:cd:1a:18:f1:fd:3a:5a:42:
79:b3:82:47:ad:ad:e0:02:7f:0b:19:34:5d:3b:90:
81:23
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
X509v3 Authority Key Identifier:
keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
70:f6:5a:6d:fe:7b:04:4d:4f:e1:d2:c5:92:07:20:6d:68:d3:
86:51:6c:60:3a:07:0a:1b:27:7d:99:88:db:01:a6:0e:f0:3a:
3d:a2:37:0e:bd:32:48:e1:36:3c:ac:a3:89:2f:33:d0:ab:ba:
7a:90:db:28:61:3d:7b:b5:4b:cd:df:3d:20:c6:a1:fb:81:ec:
69:2a:f8:c3:4c:c6:48:87:39:34:84:3e:4d:2d:eb:c9:dd:26:
70:8b:71:23:8c:0d:d1:fd:5b:0e:0e:58:86:20:0c:4e:aa:a1:
d1:b0:e9:56:bf:9f:9a:4d:a8:0d:76:6a:48:a2:dd:19:92:25:
93:7f:90:8f:a2:c0:ac:1d:d3:63:17:d6:a5:07:98:27:cb:a7:
44:60:17:aa:f2:22:0f:0d:c9:7d:58:1c:00:54:e6:99:84:d3:
a0:6e:e9:fb:8d:97:21:24:79:c4:b8:23:81:2c:65:da:cc:0e:
09:9c:82:8a:23:74:54:10:56:e4:a2:f0:e8:ce:8f:d5:cf:03:
d9:0e:37:f3:86:66:e0:4e:c0:55:fc:e1:1b:7b:cc:8a:ad:41:
2f:7b:02:4a:42:f1:e4:b9:4e:86:f3:30:bb:8a:bf:f2:79:c7:
5d:68:02:b5:fb:40:cf:3f:5d:55:55:58:05:ef:95:34:ee:ea:
3e:6e:91:59
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP0wDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQCzWcDWsPPLMUad795j8xokEDb76O4FdiFRUf1SR5cSE0ZCvJQ3XuZB0th1
Jyw9BLzhrLyo9th0Y5q+qXvSG5aHJTvO0f+03fopZK7fTBu0+56Kmmx0uip2RQO3
kX6QugQ93AoXd7Nf3FYH62NeK1TJ17NL80JrniqAnHFSXQ9tl8bT9sR6eu7qIk8c
6EJVbrIqVs+GPJTR5+B8eIyUBQWwP7JwGNqS0pq6V3z7UksPNMvcq0Cgdk7MEblX
vvLi+iu6ILDI7o0KEaIC1Pc4PfSoSfS0igj/0MMlIQ7c8Bci8r8HPedfTLLNGhjx
/TpaQnmzgketreACfwsZNF07kIEjAgMBAAGjgcswgcgwHQYDVR0OBBYEFI9OXngZ
riiCaS/PM5UEwc110fb/MB8GA1UdIwQYMBaAFI9OXngZriiCaS/PM5UEwc110fb/
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEAcPZabf57BE1P4dLFkgcgbWjThlFsYDoHChsnfZmI2wGmDvA6
PaI3Dr0ySOE2PKyjiS8z0Ku6epDbKGE9e7VLzd89IMah+4HsaSr4w0zGSIc5NIQ+
TS3ryd0mcItxI4wN0f1bDg5YhiAMTqqh0bDpVr+fmk2oDXZqSKLdGZIlk3+Qj6LA
rB3TYxfWpQeYJ8unRGAXqvIiDw3JfVgcAFTmmYTToG7p+42XISR5xLgjgSxl2swO
CZyCiiN0VBBW5KLw6M6P1c8D2Q4384Zm4E7AVfzhG3vMiq1BL3sCSkLx5LlOhvMw
u4q/8nnHXWgCtftAzz9dVVVYBe+VNO7qPm6RWQ==
-----END CERTIFICATE-----