| [Created by: generate-chains.py] |
| |
| Certificate chain where the intermediate has a policies extension marked as |
| critical, and contains an unknown policy qualifer (1.2.3.4). |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 11:0a:fc:bd:a1:b1:c5:a4:95:da:e7:62:79:b3:82:f3:22:28:98:e5 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Intermediate |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Target |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:c1:03:58:01:b1:2f:7b:fb:b2:71:dc:49:d0:cb: |
| 06:76:30:64:f7:61:bf:da:55:93:73:29:49:0f:cb: |
| 0a:33:bd:41:0b:28:03:45:35:72:a9:b4:4b:a7:ec: |
| 52:77:3a:8c:ba:cb:87:56:28:3b:39:8d:47:7b:70: |
| 7f:5a:8f:76:8c:7e:13:e8:61:17:19:1d:72:e3:6e: |
| 69:20:bc:83:f7:5b:11:85:6e:1a:b8:fb:7b:f8:fe: |
| 2b:e2:d2:bd:1a:0a:65:62:b0:84:a7:0a:ac:75:ea: |
| e6:74:c4:1d:2c:e8:04:62:76:4b:4d:04:b6:52:2f: |
| a6:ba:66:bb:fe:45:d6:6a:21:05:16:e5:f3:25:ae: |
| 94:fd:17:84:80:2f:ac:62:d9:83:e3:17:b0:03:1c: |
| 01:02:8b:47:7f:65:2e:f9:40:cf:ad:92:33:07:8a: |
| 14:44:5e:c2:ed:68:48:a4:d1:f0:7b:f9:67:91:28: |
| d9:9f:2c:f0:5e:12:92:52:92:97:27:7b:12:dd:c5: |
| d5:7f:32:8c:9b:26:05:eb:47:e1:26:99:ea:6a:a9: |
| 25:93:64:31:e5:6c:f4:cf:02:27:29:b3:9f:17:94: |
| 0d:38:9c:54:f1:80:ef:b9:b0:4b:6a:12:eb:ca:53: |
| 91:2a:95:ee:16:bf:12:9f:8a:32:a7:8a:81:dd:4c: |
| 02:91 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| EF:56:67:1C:5E:24:60:78:3E:F2:35:40:2E:1A:58:65:4D:B3:4E:BE |
| X509v3 Authority Key Identifier: |
| keyid:47:8C:F1:C9:1E:F8:EC:25:A8:31:F3:1C:CE:BC:C5:70:9F:11:87:63 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Intermediate.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Intermediate.crl |
| |
| X509v3 Key Usage: critical |
| Digital Signature, Key Encipherment |
| X509v3 Extended Key Usage: |
| TLS Web Server Authentication, TLS Web Client Authentication |
| Signature Algorithm: sha256WithRSAEncryption |
| 9f:04:58:29:ad:9b:ae:88:48:2b:df:91:67:c8:7a:d9:8e:82: |
| b4:9b:12:14:fb:87:e8:c6:f2:16:87:d3:4d:1b:da:fa:d3:8b: |
| 2d:2a:c1:06:9f:b4:28:9c:dc:e6:16:85:a4:e2:0e:b8:76:84: |
| a0:f3:00:09:e1:54:5d:4d:2d:34:8b:fe:98:36:7f:16:5a:38: |
| 96:e5:0c:67:c9:e2:77:c2:d3:52:26:6f:60:58:b6:78:26:8a: |
| b9:8f:0e:38:93:24:50:18:d2:85:62:9f:88:26:4a:ce:38:25: |
| 9d:ad:30:b9:f6:0b:ee:f8:73:8f:6b:b6:0e:0c:d0:6f:a4:4f: |
| 3b:f1:d7:d7:99:77:59:d1:c4:29:15:f5:1e:d8:6b:b4:a8:b1: |
| 44:6f:7f:ec:63:06:24:9a:be:8e:e9:34:c8:8f:6d:d8:bb:d0: |
| 86:37:ff:57:53:2b:e7:67:7d:e6:3a:85:c0:76:f3:ba:40:d3: |
| 16:7b:d8:5c:e1:7f:92:d8:7e:ed:53:11:89:e0:17:44:68:3f: |
| ad:64:63:e3:18:df:84:66:05:17:84:09:88:d5:3f:d8:03:d1: |
| ed:3a:6b:15:9a:bc:68:55:bd:e6:21:f9:6d:f2:c0:c9:54:2e: |
| 36:b8:2d:2b:1d:de:b5:7e:ba:33:22:69:6f:b1:1d:b1:8b:fb: |
| 98:5e:e7:de |
| -----BEGIN CERTIFICATE----- |
| MIIDoDCCAoigAwIBAgIUEQr8vaGxxaSV2udiebOC8yIomOUwDQYJKoZIhvcNAQEL |
| BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTE4MDMxMDEyMDAwMFoXDTIx |
| MDEwMTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF |
| AAOCAQ8AMIIBCgKCAQEAwQNYAbEve/uycdxJ0MsGdjBk92G/2lWTcylJD8sKM71B |
| CygDRTVyqbRLp+xSdzqMusuHVig7OY1He3B/Wo92jH4T6GEXGR1y425pILyD91sR |
| hW4auPt7+P4r4tK9GgplYrCEpwqsdermdMQdLOgEYnZLTQS2Ui+muma7/kXWaiEF |
| FuXzJa6U/ReEgC+sYtmD4xewAxwBAotHf2Uu+UDPrZIzB4oURF7C7WhIpNHwe/ln |
| kSjZnyzwXhKSUpKXJ3sS3cXVfzKMmyYF60fhJpnqaqklk2Qx5Wz0zwInKbOfF5QN |
| OJxU8YDvubBLahLrylORKpXuFr8Sn4oyp4qB3UwCkQIDAQABo4HpMIHmMB0GA1Ud |
| DgQWBBTvVmccXiRgeD7yNUAuGlhlTbNOvjAfBgNVHSMEGDAWgBRHjPHJHvjsJagx |
| 8xzOvMVwnxGHYzA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 |
| cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 |
| dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF |
| oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZIhvcNAQELBQAD |
| ggEBAJ8EWCmtm66ISCvfkWfIetmOgrSbEhT7h+jG8haH000b2vrTiy0qwQaftCic |
| 3OYWhaTiDrh2hKDzAAnhVF1NLTSL/pg2fxZaOJblDGfJ4nfC01Imb2BYtngmirmP |
| DjiTJFAY0oVin4gmSs44JZ2tMLn2C+74c49rtg4M0G+kTzvx19eZd1nRxCkV9R7Y |
| a7SosURvf+xjBiSavo7pNMiPbdi70IY3/1dTK+dnfeY6hcB287pA0xZ72Fzhf5LY |
| fu1TEYngF0RoP61kY+MY34RmBReECYjVP9gD0e06axWavGhVveYh+W3ywMlULja4 |
| LSsd3rV+ujMiaW+xHbGL+5he594= |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 22:d5:d3:ab:e1:db:b6:4e:c6:30:5b:f4:c2:c2:ff:37:2e:43:2d:1a |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Intermediate |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:ba:0f:08:80:56:6b:27:51:76:78:18:c5:92:b1: |
| b4:d1:7a:4f:8f:57:6a:6a:96:70:e3:ca:4a:68:9d: |
| 0b:5d:2e:fd:34:1b:2a:d7:f2:a0:e0:3d:98:f8:2c: |
| 88:d1:7e:25:5d:80:80:30:f0:1c:65:a5:e4:60:ed: |
| 7a:31:df:97:20:c3:0c:4e:d0:2a:d8:93:54:d2:21: |
| fe:9f:85:7d:fe:9d:45:fc:66:14:10:a5:6a:38:e7: |
| e0:1e:71:fa:fe:9a:c0:79:73:98:87:80:17:a8:e3: |
| c8:84:cb:9a:a8:db:d2:59:d5:26:40:cc:8b:29:03: |
| 8a:75:3d:05:01:ed:bf:05:57:27:94:e2:a3:7e:2e: |
| 06:95:8b:a2:99:8d:69:d3:3a:86:35:2b:23:19:cd: |
| 53:92:55:fe:7e:75:43:08:4c:05:51:db:1a:14:5d: |
| 6c:bb:4f:de:ef:7f:24:53:b1:e6:fc:90:a0:8a:39: |
| 22:f1:1d:1f:4a:3b:5b:c0:df:ca:a9:57:f2:c8:16: |
| f5:e0:f4:fa:79:77:9b:93:0d:b8:5a:9d:9b:48:98: |
| 69:75:11:0f:2d:b9:8e:cd:34:4c:06:62:f8:a2:de: |
| 07:d8:7e:a0:5a:88:b0:d1:72:0b:49:67:42:5c:08: |
| 3b:bc:10:60:01:c2:15:ab:f8:31:8f:5d:bb:a2:e6: |
| da:fb |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| 47:8C:F1:C9:1E:F8:EC:25:A8:31:F3:1C:CE:BC:C5:70:9F:11:87:63 |
| X509v3 Authority Key Identifier: |
| keyid:BD:1A:91:15:D9:48:10:F5:7E:D3:B8:CE:06:D8:29:10:AE:43:CE:42 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| X509v3 Certificate Policies: critical |
| Policy: 1.2.3 |
| Unknown Qualifier: 1.2.3.4 |
| |
| Signature Algorithm: sha256WithRSAEncryption |
| 31:a1:e5:55:45:37:a8:5c:4f:99:ef:8f:d3:09:9a:93:e5:c8: |
| ae:e5:2a:c9:17:a7:45:36:c5:b8:b1:ad:84:1f:4c:8b:ea:fc: |
| 29:53:f5:e7:a9:c5:74:07:e1:46:c4:a2:d6:ae:6c:6f:2d:84: |
| d4:40:7b:a7:1b:ab:4d:3f:69:90:15:4b:ba:af:fe:74:8d:f5: |
| 96:99:35:23:a6:cf:d6:c0:9a:bc:58:ce:5b:3c:98:94:3c:f2: |
| c3:28:ee:7a:85:bc:fa:6d:54:08:2a:9d:10:39:5a:09:98:82: |
| 13:6b:17:c4:38:15:78:46:9d:af:f1:b7:6c:97:57:fb:50:1a: |
| 6b:2d:dd:a2:4c:a9:f0:65:64:57:90:f1:92:1d:e8:0a:10:72: |
| a0:62:f2:62:3c:72:c7:d0:c0:87:db:0d:80:1d:bf:de:1d:d2: |
| 8a:94:d9:ed:44:3f:22:e1:85:d7:26:f2:66:b1:c5:35:be:c1: |
| 1b:c8:50:1e:1f:38:e6:f7:d6:72:c2:f3:a2:9a:e9:a1:25:7a: |
| 97:f8:b5:37:11:cc:8b:09:c5:a2:8f:65:57:4f:e7:fd:4f:e0: |
| c1:6a:f6:cf:d1:c7:be:f7:b5:3e:69:08:af:2d:37:72:26:11: |
| c2:b3:28:f0:61:1e:c2:58:59:fc:ed:62:8b:9e:0d:c5:f8:ee: |
| 35:23:bd:5d |
| -----BEGIN CERTIFICATE----- |
| MIIDoTCCAomgAwIBAgIUItXTq+Hbtk7GMFv0wsL/Ny5DLRowDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD |
| ggEPADCCAQoCggEBALoPCIBWaydRdngYxZKxtNF6T49XamqWcOPKSmidC10u/TQb |
| KtfyoOA9mPgsiNF+JV2AgDDwHGWl5GDtejHflyDDDE7QKtiTVNIh/p+Fff6dRfxm |
| FBClajjn4B5x+v6awHlzmIeAF6jjyITLmqjb0lnVJkDMiykDinU9BQHtvwVXJ5Ti |
| o34uBpWLopmNadM6hjUrIxnNU5JV/n51QwhMBVHbGhRdbLtP3u9/JFOx5vyQoIo5 |
| IvEdH0o7W8DfyqlX8sgW9eD0+nl3m5MNuFqdm0iYaXURDy25js00TAZi+KLeB9h+ |
| oFqIsNFyC0lnQlwIO7wQYAHCFav4MY9du6Lm2vsCAwEAAaOB7DCB6TAdBgNVHQ4E |
| FgQUR4zxyR747CWoMfMczrzFcJ8Rh2MwHwYDVR0jBBgwFoAUvRqRFdlIEPV+07jO |
| BtgpEK5DzkIwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs |
| LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m |
| b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ |
| MB8GA1UdIAEB/wQVMBMwEQYCKgMwCzAJBgMqAwQMAmhpMA0GCSqGSIb3DQEBCwUA |
| A4IBAQAxoeVVRTeoXE+Z74/TCZqT5ciu5SrJF6dFNsW4sa2EH0yL6vwpU/XnqcV0 |
| B+FGxKLWrmxvLYTUQHunG6tNP2mQFUu6r/50jfWWmTUjps/WwJq8WM5bPJiUPPLD |
| KO56hbz6bVQIKp0QOVoJmIITaxfEOBV4Rp2v8bdsl1f7UBprLd2iTKnwZWRXkPGS |
| HegKEHKgYvJiPHLH0MCH2w2AHb/eHdKKlNntRD8i4YXXJvJmscU1vsEbyFAeHzjm |
| 99ZywvOimumhJXqX+LU3EcyLCcWij2VXT+f9T+DBavbP0ce+97U+aQivLTdyJhHC |
| syjwYR7CWFn87WKLng3F+O41I71d |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 22:d5:d3:ab:e1:db:b6:4e:c6:30:5b:f4:c2:c2:ff:37:2e:43:2d:19 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Root |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:ba:3d:c2:46:f3:d5:1b:65:5e:43:a3:bc:db:43: |
| 94:e9:9c:20:e1:ea:84:98:c6:65:51:6d:1c:1d:5f: |
| 8d:f9:81:47:1a:06:18:d9:7c:57:8f:6c:55:5c:36: |
| 63:c2:c6:db:be:47:61:5c:35:46:30:ec:e1:e5:0e: |
| 10:4f:9d:d4:62:58:56:83:00:3a:63:f0:cb:b2:50: |
| e5:50:52:27:60:41:3e:db:07:61:92:db:d6:60:c2: |
| 66:f8:89:b6:aa:99:cb:5e:9d:74:db:cc:bc:3e:7d: |
| 0b:13:87:29:b8:fa:32:11:e9:fc:9a:e9:77:0d:7c: |
| 03:15:f7:7c:85:6c:f0:2c:2b:b0:32:5b:d9:6f:f8: |
| f0:82:71:9e:f4:63:5c:6d:98:c9:ea:12:ad:d3:66: |
| 22:da:67:26:3c:ae:b3:23:0e:68:91:b7:28:65:81: |
| b8:2c:04:34:92:bb:a0:00:39:51:06:53:14:c7:e9: |
| ae:31:ef:5a:d7:21:28:44:9f:ca:53:cf:ac:4f:60: |
| 56:a9:f4:92:20:ee:c0:db:46:da:83:bd:28:b4:dd: |
| d2:73:af:93:b5:31:84:55:e8:80:a0:6f:c5:f6:0c: |
| 54:50:dc:3d:b4:26:71:f9:fd:16:3f:62:b1:96:c9: |
| de:45:b4:28:86:8d:8e:34:ce:aa:41:7c:66:e4:04: |
| 72:bb |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| BD:1A:91:15:D9:48:10:F5:7E:D3:B8:CE:06:D8:29:10:AE:43:CE:42 |
| X509v3 Authority Key Identifier: |
| keyid:BD:1A:91:15:D9:48:10:F5:7E:D3:B8:CE:06:D8:29:10:AE:43:CE:42 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| Signature Algorithm: sha256WithRSAEncryption |
| 10:bf:74:ba:31:31:9b:8e:aa:8c:67:08:56:79:bc:e2:50:65: |
| 6e:2e:a9:9d:9d:63:64:23:95:6f:04:4f:24:df:a2:a1:f1:75: |
| d6:d2:a9:06:05:bf:64:19:bd:d9:94:14:cd:bc:19:0d:56:14: |
| b4:e9:b0:78:99:dc:e1:d6:ac:99:86:90:5d:ae:54:66:b6:ec: |
| d6:6f:26:3f:2e:a6:63:25:14:48:b4:19:0f:c6:de:3d:be:1d: |
| 0b:4a:a7:01:2c:be:8a:ee:e4:98:9d:62:fd:f4:5f:08:f9:43: |
| b1:0f:ae:6d:3e:9c:30:6c:61:37:28:d0:cb:56:51:e4:56:4a: |
| 92:69:15:9e:3b:6c:0c:b4:c7:47:46:89:2b:b3:29:1a:2c:c7: |
| be:ea:b4:b4:88:a8:5c:30:5d:b4:ef:d8:1d:bc:e5:aa:b4:06: |
| 55:42:3c:1d:27:1a:68:64:d4:1b:e8:e3:f6:d2:2e:61:23:05: |
| a6:ed:f4:a7:e8:ae:ac:17:8e:ed:26:fc:92:f3:c6:13:9a:7b: |
| ed:42:ed:95:7a:f6:b7:53:83:fd:a6:c3:3a:73:14:a6:18:6b: |
| 3e:4d:bc:06:5e:dc:e9:81:25:5b:cf:cb:73:e5:49:57:5a:fb: |
| 28:dc:b8:06:cb:6c:bb:a6:81:3f:93:a6:a8:b4:2a:27:db:59: |
| 09:59:94:96 |
| -----BEGIN CERTIFICATE----- |
| MIIDeDCCAmCgAwIBAgIUItXTq+Hbtk7GMFv0wsL/Ny5DLRkwDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK |
| AoIBAQC6PcJG89UbZV5Do7zbQ5TpnCDh6oSYxmVRbRwdX435gUcaBhjZfFePbFVc |
| NmPCxtu+R2FcNUYw7OHlDhBPndRiWFaDADpj8MuyUOVQUidgQT7bB2GS29Zgwmb4 |
| ibaqmctenXTbzLw+fQsThym4+jIR6fya6XcNfAMV93yFbPAsK7AyW9lv+PCCcZ70 |
| Y1xtmMnqEq3TZiLaZyY8rrMjDmiRtyhlgbgsBDSSu6AAOVEGUxTH6a4x71rXIShE |
| n8pTz6xPYFap9JIg7sDbRtqDvSi03dJzr5O1MYRV6ICgb8X2DFRQ3D20JnH5/RY/ |
| YrGWyd5FtCiGjY40zqpBfGbkBHK7AgMBAAGjgcswgcgwHQYDVR0OBBYEFL0akRXZ |
| SBD1ftO4zgbYKRCuQ85CMB8GA1UdIwQYMBaAFL0akRXZSBD1ftO4zgbYKRCuQ85C |
| MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh |
| L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S |
| b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG |
| 9w0BAQsFAAOCAQEAEL90ujExm46qjGcIVnm84lBlbi6pnZ1jZCOVbwRPJN+iofF1 |
| 1tKpBgW/ZBm92ZQUzbwZDVYUtOmweJnc4dasmYaQXa5UZrbs1m8mPy6mYyUUSLQZ |
| D8bePb4dC0qnASy+iu7kmJ1i/fRfCPlDsQ+ubT6cMGxhNyjQy1ZR5FZKkmkVnjts |
| DLTHR0aJK7MpGizHvuq0tIioXDBdtO/YHbzlqrQGVUI8HScaaGTUG+jj9tIuYSMF |
| pu30p+iurBeO7Sb8kvPGE5p77ULtlXr2t1OD/abDOnMUphhrPk28Bl7c6YElW8/L |
| c+VJV1r7KNy4Bstsu6aBP5OmqLQqJ9tZCVmUlg== |
| -----END CERTIFICATE----- |