blob: c943710238e14a5fd0214de18d4503e4b8c50856 [file] [log] [blame]
[Created by: ./generate-chains.py]
Certificate chain where the target certificate sets the extended key usage
to clientAuth. Neither the root nor the intermediate have an EKU.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
3f:1d:2b:1d:12:7e:34:b6:2b:61:b2:78:f2:74:66:9a:dc:66:ad:cc
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:c3:82:13:64:0e:35:33:0c:ac:44:be:6d:92:f5:
e4:97:d8:9a:bd:64:f1:b5:67:62:01:7b:0c:98:57:
4a:63:64:b0:9d:6a:7b:84:a2:91:fe:73:0b:4c:81:
ce:89:f9:8d:8d:8a:41:18:c8:d8:64:27:36:32:e6:
36:26:44:16:13:2e:a1:ad:38:06:0b:1b:39:62:6a:
94:ac:a0:59:be:52:cb:47:d7:4b:00:09:91:8e:14:
69:a9:62:df:49:d8:b6:79:73:de:60:d4:b8:76:89:
a4:53:8a:1d:4b:80:88:31:e8:05:46:81:1b:7b:5d:
52:d0:6b:3b:53:0d:25:3c:95:9b:2d:99:83:3c:03:
8c:b5:73:fb:43:6c:82:b3:48:57:38:3c:ff:b7:79:
d8:13:74:06:d0:17:78:a9:38:09:76:ca:f9:b7:5a:
a5:8a:6e:85:7f:27:34:79:82:ef:a2:01:93:ae:fa:
0b:18:47:d4:14:ff:67:78:2b:53:92:f6:ac:27:42:
c7:7f:8e:fd:06:4a:36:b9:7a:98:5e:0d:94:ef:1a:
fa:08:ad:8d:64:28:c7:c1:03:76:63:b9:33:5a:9f:
16:be:d3:e0:5c:e9:43:7b:9b:83:b3:90:31:e7:59:
2b:1c:d2:8c:73:15:a2:3a:94:35:03:80:97:f8:5d:
a3:13
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
5A:16:9C:06:85:B6:F4:77:AD:72:58:A2:4F:A1:FE:29:CF:97:8A:2B
X509v3 Authority Key Identifier:
keyid:24:B9:91:41:39:F1:30:5E:F8:C5:3B:C0:51:CC:11:58:A6:13:73:B3
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Client Authentication, TLS Web Server Authentication, Code Signing, OCSP Signing, Time Stamping
Signature Algorithm: sha256WithRSAEncryption
4a:f1:10:7d:eb:77:f7:e9:8a:1a:e4:1a:2d:84:9c:1d:91:67:
f8:c2:d9:a7:f4:e9:97:5e:74:fe:d8:a3:8f:21:3d:51:bc:af:
eb:2a:e5:dd:76:61:de:31:4c:1b:ca:91:1c:79:5e:2c:5d:7b:
41:b8:04:47:e0:92:ac:cd:39:c2:86:b3:e0:24:5b:62:c7:ef:
79:8d:f5:09:60:29:74:16:80:94:ed:8c:93:15:32:ee:66:bb:
31:db:6a:eb:00:b4:60:6e:ed:61:f6:1e:f9:e7:fd:de:2f:a2:
4f:f1:3d:50:7e:86:04:8b:e0:a9:94:ee:83:fc:23:16:a5:3c:
07:87:1b:b8:71:f2:22:2e:5b:cf:8d:86:be:ae:45:5d:81:8a:
33:6e:36:32:8a:28:04:cb:39:f2:78:b0:e4:cf:21:fd:72:06:
76:c1:83:06:6e:36:0c:69:5a:4c:90:42:60:64:56:db:b6:c8:
29:56:d8:48:77:6b:2b:5b:2a:33:37:fd:6a:78:ae:a2:0a:29:
8c:2b:5e:10:d7:04:ef:b7:19:6f:e5:82:1e:03:d1:8e:73:b0:
1b:dd:4c:8a:ce:40:de:a5:02:29:8a:e3:ff:5a:bb:a9:8c:34:
87:b0:6b:44:6b:ee:c3:dc:d0:51:d3:af:e8:ee:37:4f:b7:c1:
0f:7e:5a:2c
-----BEGIN CERTIFICATE-----
MIIDwDCCAqigAwIBAgIUPx0rHRJ+NLYrYbJ48nRmmtxmrcwwDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAw4ITZA41MwysRL5tkvXkl9iavWTxtWdiAXsMmFdKY2Sw
nWp7hKKR/nMLTIHOifmNjYpBGMjYZCc2MuY2JkQWEy6hrTgGCxs5YmqUrKBZvlLL
R9dLAAmRjhRpqWLfSdi2eXPeYNS4domkU4odS4CIMegFRoEbe11S0Gs7Uw0lPJWb
LZmDPAOMtXP7Q2yCs0hXODz/t3nYE3QG0Bd4qTgJdsr5t1qlim6Ffyc0eYLvogGT
rvoLGEfUFP9neCtTkvasJ0LHf479Bko2uXqYXg2U7xr6CK2NZCjHwQN2Y7kzWp8W
vtPgXOlDe5uDs5Ax51krHNKMcxWiOpQ1A4CX+F2jEwIDAQABo4IBCDCCAQQwHQYD
VR0OBBYEFFoWnAaFtvR3rXJYok+h/inPl4orMB8GA1UdIwQYMBaAFCS5kUE58TBe
+MU7wFHMEVimE3OzMD8GCCsGAQUFBwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDov
L3VybC1mb3ItYWlhL0ludGVybWVkaWF0ZS5jZXIwNAYDVR0fBC0wKzApoCegJYYj
aHR0cDovL3VybC1mb3ItY3JsL0ludGVybWVkaWF0ZS5jcmwwDgYDVR0PAQH/BAQD
AgWgMDsGA1UdJQQ0MDIGCCsGAQUFBwMCBggrBgEFBQcDAQYIKwYBBQUHAwMGCCsG
AQUFBwMJBggrBgEFBQcDCDANBgkqhkiG9w0BAQsFAAOCAQEASvEQfet39+mKGuQa
LYScHZFn+MLZp/Tpl150/tijjyE9Ubyv6yrl3XZh3jFMG8qRHHleLF17QbgER+CS
rM05woaz4CRbYsfveY31CWApdBaAlO2MkxUy7ma7Mdtq6wC0YG7tYfYe+ef93i+i
T/E9UH6GBIvgqZTug/wjFqU8B4cbuHHyIi5bz42Gvq5FXYGKM242MoooBMs58niw
5M8h/XIGdsGDBm42DGlaTJBCYGRW27bIKVbYSHdrK1sqMzf9aniuogopjCteENcE
77cZb+WCHgPRjnOwG91Mis5A3qUCKYrj/1q7qYw0h7BrRGvuw9zQUdOv6O43T7fB
D35aLA==
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
71:f4:9e:e7:b5:f7:36:30:c9:84:5e:a5:b8:39:8b:58:f3:23:7b:19
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:ed:3b:bb:f2:8b:20:81:de:42:41:c6:24:63:1c:
4b:e5:63:b0:93:07:fd:22:64:50:7d:ef:8f:ed:65:
aa:ba:f4:d9:ad:0c:68:dd:50:b0:ea:0a:5e:18:9e:
df:48:88:ec:1f:fa:6b:4a:3e:db:ea:24:6e:b1:a3:
bb:0b:12:de:1d:49:d3:32:78:24:f9:e8:4f:aa:85:
90:21:a2:2c:8f:58:95:8c:70:80:8d:cd:99:68:03:
67:0f:48:eb:96:17:63:93:2b:8f:72:77:23:5f:97:
4f:86:bd:17:d2:70:5b:5c:18:f8:01:d6:11:d8:c0:
dc:32:b2:f4:bf:dd:da:65:fb:86:23:c0:a4:bd:ff:
c2:a4:b6:87:9e:10:98:d4:f4:09:cb:26:50:1d:56:
83:72:09:c6:c1:b7:cc:52:9c:61:09:04:bb:aa:2a:
63:66:a5:b1:02:60:85:bc:30:91:62:bb:6f:b0:24:
33:e8:b5:9a:13:1f:3a:73:95:d5:fb:bc:a9:48:dd:
14:a2:a4:62:e1:97:19:57:b1:1a:da:c1:79:93:fd:
74:cb:e1:ff:0c:49:c2:78:57:8e:ef:dc:df:60:96:
8e:e6:a2:97:60:b9:53:6b:17:8e:ae:f9:3d:be:31:
dd:46:18:bd:af:b6:a6:02:fa:48:2f:d8:c6:f0:1f:
bc:43
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
24:B9:91:41:39:F1:30:5E:F8:C5:3B:C0:51:CC:11:58:A6:13:73:B3
X509v3 Authority Key Identifier:
keyid:CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
b5:72:33:3e:f7:8f:e4:b8:bb:1c:6d:25:34:ec:3f:2b:03:19:
c8:50:bd:f0:17:e8:5a:eb:43:6d:57:b0:e5:5e:90:18:c9:5d:
96:e4:27:d3:09:35:ba:22:c7:5f:c3:b2:b0:2f:be:dc:50:57:
b3:1a:7b:60:fa:ba:99:85:d9:8b:cb:08:67:c5:4b:28:a7:f2:
21:91:44:ac:aa:c2:d0:4e:15:59:1f:c0:91:06:fa:f8:09:b5:
39:3f:6d:be:80:7b:10:72:fd:2c:fe:27:69:3a:36:63:e3:14:
30:11:a0:77:83:f3:14:d2:fa:76:0c:c3:88:1a:3c:fa:f0:50:
ba:d4:69:4b:80:93:6d:01:38:2e:3e:81:e4:e5:f7:02:1c:bf:
ad:e7:be:6e:dd:a3:1d:3c:7c:df:58:7b:ea:06:56:2c:8e:e1:
00:14:79:c3:a9:aa:b5:25:8d:fb:62:e2:18:75:27:d3:f4:09:
3b:fa:49:f7:9e:fd:28:22:57:e4:fe:f4:b6:3e:17:91:46:2c:
6d:b0:5a:36:b4:f1:47:fb:dd:28:2a:b4:c3:43:7e:dd:05:a5:
35:05:60:8c:fc:1e:76:8d:28:a7:42:f0:6b:b3:4b:5c:77:ae:
ec:be:c3:9e:a6:50:be:5b:46:f4:b3:2d:e4:a5:f5:a1:4e:94:
0a:09:e4:2e
-----BEGIN CERTIFICATE-----
MIIDgDCCAmigAwIBAgIUcfSe57X3NjDJhF6luDmLWPMjexkwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBAO07u/KLIIHeQkHGJGMcS+VjsJMH/SJkUH3vj+1lqrr02a0M
aN1QsOoKXhie30iI7B/6a0o+2+okbrGjuwsS3h1J0zJ4JPnoT6qFkCGiLI9YlYxw
gI3NmWgDZw9I65YXY5Mrj3J3I1+XT4a9F9JwW1wY+AHWEdjA3DKy9L/d2mX7hiPA
pL3/wqS2h54QmNT0CcsmUB1Wg3IJxsG3zFKcYQkEu6oqY2alsQJghbwwkWK7b7Ak
M+i1mhMfOnOV1fu8qUjdFKKkYuGXGVexGtrBeZP9dMvh/wxJwnhXju/c32CWjuai
l2C5U2sXjq75Pb4x3UYYva+2pgL6SC/YxvAfvEMCAwEAAaOByzCByDAdBgNVHQ4E
FgQUJLmRQTnxMF74xTvAUcwRWKYTc7MwHwYDVR0jBBgwFoAUzW9M/qp6OmNdEnlt
9EywKop/+2wwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MA0GCSqGSIb3DQEBCwUAA4IBAQC1cjM+94/kuLscbSU07D8rAxnIUL3wF+ha60Nt
V7DlXpAYyV2W5CfTCTW6Isdfw7KwL77cUFezGntg+rqZhdmLywhnxUsop/IhkUSs
qsLQThVZH8CRBvr4CbU5P22+gHsQcv0s/idpOjZj4xQwEaB3g/MU0vp2DMOIGjz6
8FC61GlLgJNtATguPoHk5fcCHL+t575u3aMdPHzfWHvqBlYsjuEAFHnDqaq1JY37
YuIYdSfT9Ak7+kn3nv0oIlfk/vS2PheRRixtsFo2tPFH+90oKrTDQ37dBaU1BWCM
/B52jSinQvBrs0tcd67svsOeplC+W0b0sy3kpfWhTpQKCeQu
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
71:f4:9e:e7:b5:f7:36:30:c9:84:5e:a5:b8:39:8b:58:f3:23:7b:18
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:e8:17:31:b6:0e:84:10:a4:9b:bf:9e:ae:9e:29:
b7:6f:81:ae:d7:df:45:89:d1:29:51:0e:1e:39:7a:
96:6b:7f:c0:78:df:88:cf:db:b3:ab:8d:49:0f:fb:
70:55:85:4f:93:9f:12:a1:a6:55:5c:a9:ae:8d:79:
4d:a6:3a:32:03:9c:bf:ad:95:c4:8b:49:1f:02:b5:
23:a0:9f:da:d3:45:c6:8c:fc:ec:97:46:57:dd:77:
56:c6:a2:46:78:da:a2:59:bb:22:ea:de:63:94:50:
19:91:1c:10:cd:67:e0:57:10:bd:e0:de:69:67:80:
6d:31:a8:43:bc:49:2c:8a:d6:4a:23:0f:a6:78:f4:
74:c7:4f:37:52:3a:af:9c:03:b2:b3:6c:26:ab:62:
61:12:6d:22:15:66:da:ec:d6:b8:1f:9b:14:b9:04:
9c:9b:5e:b5:cb:8b:62:95:67:6a:a1:57:44:02:77:
a2:81:3e:c7:20:52:a2:16:2e:ba:c2:29:a1:54:ed:
33:67:f2:2a:26:a3:b6:da:08:8d:63:6c:ca:4f:c6:
84:88:b9:60:08:cf:50:8e:5a:3e:75:d7:ec:d7:63:
c1:fe:18:3f:4e:fb:08:de:39:45:d2:81:34:8e:89:
5a:48:ce:49:bf:ca:84:cb:26:ac:c2:f7:1f:6b:3f:
0d:49
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C
X509v3 Authority Key Identifier:
keyid:CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
2e:3a:98:e7:b2:5c:e7:8d:50:e4:04:4d:82:34:86:f0:13:6b:
02:e6:cd:c9:ae:cc:6c:0b:79:da:1f:9a:5e:9d:59:12:f2:c8:
aa:56:32:28:2a:ea:64:68:15:a1:9f:27:e6:26:b7:66:15:9c:
65:3c:37:af:f9:27:78:63:42:cc:bb:d4:ea:49:e2:7d:31:6b:
94:7e:d0:41:24:bc:f9:e1:b3:34:a7:60:35:d7:4a:05:ef:53:
5f:9f:a7:9a:e8:25:40:35:94:3e:c0:2e:3a:3a:5e:00:f9:ec:
45:16:e3:11:2c:29:8e:86:70:ae:8f:0e:f6:7a:3d:c3:01:ef:
b2:35:e7:00:3d:1a:4a:0c:8e:a8:fe:bb:11:b9:05:71:60:d4:
a6:94:4c:ee:1b:a1:88:68:13:87:e0:1d:25:ba:e3:71:fd:7a:
ee:3e:c1:8c:4e:a5:c9:c2:26:a4:c6:dc:de:73:7c:14:e9:a1:
2d:a6:0a:82:09:8a:1a:bb:08:54:01:50:3b:fa:e9:1e:ca:96:
fd:93:6f:a6:9e:4c:02:18:0f:71:86:0b:14:92:a8:43:09:39:
19:96:d1:5f:96:12:08:18:bd:46:53:28:df:19:37:1d:17:48:
97:4d:57:4d:90:7b:d2:1e:be:32:cd:e6:4c:98:bd:15:c8:26:
cc:7f:8a:ff
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUcfSe57X3NjDJhF6luDmLWPMjexgwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDoFzG2DoQQpJu/nq6eKbdvga7X30WJ0SlRDh45epZrf8B434jP27OrjUkP
+3BVhU+TnxKhplVcqa6NeU2mOjIDnL+tlcSLSR8CtSOgn9rTRcaM/OyXRlfdd1bG
okZ42qJZuyLq3mOUUBmRHBDNZ+BXEL3g3mlngG0xqEO8SSyK1kojD6Z49HTHTzdS
Oq+cA7KzbCarYmESbSIVZtrs1rgfmxS5BJybXrXLi2KVZ2qhV0QCd6KBPscgUqIW
LrrCKaFU7TNn8iomo7baCI1jbMpPxoSIuWAIz1COWj511+zXY8H+GD9O+wjeOUXS
gTSOiVpIzkm/yoTLJqzC9x9rPw1JAgMBAAGjgcswgcgwHQYDVR0OBBYEFM1vTP6q
ejpjXRJ5bfRMsCqKf/tsMB8GA1UdIwQYMBaAFM1vTP6qejpjXRJ5bfRMsCqKf/ts
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEALjqY57Jc541Q5ARNgjSG8BNrAubNya7MbAt52h+aXp1ZEvLI
qlYyKCrqZGgVoZ8n5ia3ZhWcZTw3r/kneGNCzLvU6knifTFrlH7QQSS8+eGzNKdg
NddKBe9TX5+nmuglQDWUPsAuOjpeAPnsRRbjESwpjoZwro8O9no9wwHvsjXnAD0a
SgyOqP67EbkFcWDUppRM7huhiGgTh+AdJbrjcf167j7BjE6lycImpMbc3nN8FOmh
LaYKggmKGrsIVAFQO/rpHsqW/ZNvpp5MAhgPcYYLFJKoQwk5GZbRX5YSCBi9RlMo
3xk3HRdIl01XTZB70h6+Ms3mTJi9FcgmzH+K/w==
-----END CERTIFICATE-----