| [Created by: generate-chains.py] |
| |
| Certificate chain where the target certificate sets the extended key usage |
| to clientAuth. Neither the root nor the intermediate have an EKU. |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 51:d2:13:35:b6:8a:b2:3b:cd:22:15:03:93:0a:b2:a0:22:4d:e1:57 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Intermediate |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Target |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:c3:82:13:64:0e:35:33:0c:ac:44:be:6d:92:f5: |
| e4:97:d8:9a:bd:64:f1:b5:67:62:01:7b:0c:98:57: |
| 4a:63:64:b0:9d:6a:7b:84:a2:91:fe:73:0b:4c:81: |
| ce:89:f9:8d:8d:8a:41:18:c8:d8:64:27:36:32:e6: |
| 36:26:44:16:13:2e:a1:ad:38:06:0b:1b:39:62:6a: |
| 94:ac:a0:59:be:52:cb:47:d7:4b:00:09:91:8e:14: |
| 69:a9:62:df:49:d8:b6:79:73:de:60:d4:b8:76:89: |
| a4:53:8a:1d:4b:80:88:31:e8:05:46:81:1b:7b:5d: |
| 52:d0:6b:3b:53:0d:25:3c:95:9b:2d:99:83:3c:03: |
| 8c:b5:73:fb:43:6c:82:b3:48:57:38:3c:ff:b7:79: |
| d8:13:74:06:d0:17:78:a9:38:09:76:ca:f9:b7:5a: |
| a5:8a:6e:85:7f:27:34:79:82:ef:a2:01:93:ae:fa: |
| 0b:18:47:d4:14:ff:67:78:2b:53:92:f6:ac:27:42: |
| c7:7f:8e:fd:06:4a:36:b9:7a:98:5e:0d:94:ef:1a: |
| fa:08:ad:8d:64:28:c7:c1:03:76:63:b9:33:5a:9f: |
| 16:be:d3:e0:5c:e9:43:7b:9b:83:b3:90:31:e7:59: |
| 2b:1c:d2:8c:73:15:a2:3a:94:35:03:80:97:f8:5d: |
| a3:13 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| 5A:16:9C:06:85:B6:F4:77:AD:72:58:A2:4F:A1:FE:29:CF:97:8A:2B |
| X509v3 Authority Key Identifier: |
| keyid:24:B9:91:41:39:F1:30:5E:F8:C5:3B:C0:51:CC:11:58:A6:13:73:B3 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Intermediate.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Intermediate.crl |
| |
| X509v3 Key Usage: critical |
| Digital Signature, Key Encipherment |
| X509v3 Extended Key Usage: |
| TLS Web Client Authentication |
| Signature Algorithm: sha256WithRSAEncryption |
| 65:00:f1:76:67:91:72:f9:ac:7a:e0:1e:c6:17:fb:ea:22:56: |
| 38:5d:62:96:0e:43:c5:b9:95:af:52:22:10:34:11:7d:03:23: |
| 8e:82:40:12:4a:4e:e1:b9:52:30:3c:d1:8e:bd:4f:71:dc:a0: |
| 81:10:ef:c3:03:d8:a7:d8:28:18:de:e5:41:8e:98:54:99:05: |
| 05:ef:02:01:e1:e2:39:d0:8a:94:da:47:40:01:f5:f2:97:00: |
| b7:06:51:72:e9:af:ea:91:3b:d2:f2:c9:7e:0c:06:eb:d2:e2: |
| 12:ca:86:43:2a:dc:c4:2a:e2:40:d4:d5:4b:ed:66:80:3d:de: |
| 5d:ad:f5:92:fa:a5:4e:8c:95:9b:ed:5b:19:ce:83:dd:26:00: |
| 68:2d:4a:7b:29:13:df:18:ff:b4:d6:2a:88:52:14:5c:d7:42: |
| 70:1b:4c:4b:12:f5:83:d6:8c:fa:69:ce:d5:c8:87:5f:e4:ea: |
| c4:de:d0:eb:38:06:27:e1:77:55:c1:67:4a:00:85:71:85:5a: |
| 88:c1:dc:46:b9:39:a8:0c:34:f1:8f:99:80:06:6e:5d:ad:88: |
| f4:27:0b:61:0d:10:cf:57:ed:3a:35:9e:36:12:99:b1:2d:d0: |
| 49:16:76:26:33:3b:1e:29:80:fb:58:6d:29:31:f9:59:86:58: |
| a3:57:de:d5 |
| -----BEGIN CERTIFICATE----- |
| MIIDljCCAn6gAwIBAgIUUdITNbaKsjvNIhUDkwqyoCJN4VcwDQYJKoZIhvcNAQEL |
| BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTE4MDMxMDEyMDAwMFoXDTIx |
| MDEwMTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF |
| AAOCAQ8AMIIBCgKCAQEAw4ITZA41MwysRL5tkvXkl9iavWTxtWdiAXsMmFdKY2Sw |
| nWp7hKKR/nMLTIHOifmNjYpBGMjYZCc2MuY2JkQWEy6hrTgGCxs5YmqUrKBZvlLL |
| R9dLAAmRjhRpqWLfSdi2eXPeYNS4domkU4odS4CIMegFRoEbe11S0Gs7Uw0lPJWb |
| LZmDPAOMtXP7Q2yCs0hXODz/t3nYE3QG0Bd4qTgJdsr5t1qlim6Ffyc0eYLvogGT |
| rvoLGEfUFP9neCtTkvasJ0LHf479Bko2uXqYXg2U7xr6CK2NZCjHwQN2Y7kzWp8W |
| vtPgXOlDe5uDs5Ax51krHNKMcxWiOpQ1A4CX+F2jEwIDAQABo4HfMIHcMB0GA1Ud |
| DgQWBBRaFpwGhbb0d61yWKJPof4pz5eKKzAfBgNVHSMEGDAWgBQkuZFBOfEwXvjF |
| O8BRzBFYphNzszA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 |
| cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 |
| dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF |
| oDATBgNVHSUEDDAKBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAZQDxdmeR |
| cvmseuAexhf76iJWOF1ilg5DxbmVr1IiEDQRfQMjjoJAEkpO4blSMDzRjr1Pcdyg |
| gRDvwwPYp9goGN7lQY6YVJkFBe8CAeHiOdCKlNpHQAH18pcAtwZRcumv6pE70vLJ |
| fgwG69LiEsqGQyrcxCriQNTVS+1mgD3eXa31kvqlToyVm+1bGc6D3SYAaC1KeykT |
| 3xj/tNYqiFIUXNdCcBtMSxL1g9aM+mnO1ciHX+TqxN7Q6zgGJ+F3VcFnSgCFcYVa |
| iMHcRrk5qAw08Y+ZgAZuXa2I9CcLYQ0Qz1ftOjWeNhKZsS3QSRZ2JjM7HimA+1ht |
| KTH5WYZYo1fe1Q== |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 21:b4:f1:0c:52:12:7e:ce:93:5e:dd:2d:2b:69:e9:bb:8c:4d:24:70 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Intermediate |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:ed:3b:bb:f2:8b:20:81:de:42:41:c6:24:63:1c: |
| 4b:e5:63:b0:93:07:fd:22:64:50:7d:ef:8f:ed:65: |
| aa:ba:f4:d9:ad:0c:68:dd:50:b0:ea:0a:5e:18:9e: |
| df:48:88:ec:1f:fa:6b:4a:3e:db:ea:24:6e:b1:a3: |
| bb:0b:12:de:1d:49:d3:32:78:24:f9:e8:4f:aa:85: |
| 90:21:a2:2c:8f:58:95:8c:70:80:8d:cd:99:68:03: |
| 67:0f:48:eb:96:17:63:93:2b:8f:72:77:23:5f:97: |
| 4f:86:bd:17:d2:70:5b:5c:18:f8:01:d6:11:d8:c0: |
| dc:32:b2:f4:bf:dd:da:65:fb:86:23:c0:a4:bd:ff: |
| c2:a4:b6:87:9e:10:98:d4:f4:09:cb:26:50:1d:56: |
| 83:72:09:c6:c1:b7:cc:52:9c:61:09:04:bb:aa:2a: |
| 63:66:a5:b1:02:60:85:bc:30:91:62:bb:6f:b0:24: |
| 33:e8:b5:9a:13:1f:3a:73:95:d5:fb:bc:a9:48:dd: |
| 14:a2:a4:62:e1:97:19:57:b1:1a:da:c1:79:93:fd: |
| 74:cb:e1:ff:0c:49:c2:78:57:8e:ef:dc:df:60:96: |
| 8e:e6:a2:97:60:b9:53:6b:17:8e:ae:f9:3d:be:31: |
| dd:46:18:bd:af:b6:a6:02:fa:48:2f:d8:c6:f0:1f: |
| bc:43 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| 24:B9:91:41:39:F1:30:5E:F8:C5:3B:C0:51:CC:11:58:A6:13:73:B3 |
| X509v3 Authority Key Identifier: |
| keyid:CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| Signature Algorithm: sha256WithRSAEncryption |
| 9c:db:e3:e1:00:2a:ae:1f:72:8f:3d:39:13:b8:b1:47:b2:24: |
| b9:8d:3d:10:dc:dc:1c:e9:1e:71:d2:39:99:89:86:8c:8a:6d: |
| b6:87:a5:06:cf:75:a2:d2:ea:7a:7f:ac:ba:a7:83:85:22:d8: |
| f7:79:1c:3e:6d:b1:02:27:dd:d7:03:0b:49:e0:58:fd:39:eb: |
| b5:22:22:1b:b3:0d:53:ed:81:60:87:1f:c4:a6:cc:c8:3d:76: |
| 31:87:d5:a9:3c:74:36:0b:9b:92:2f:7a:0d:64:97:85:3d:d9: |
| f7:8a:dc:0a:28:0b:83:f1:8d:7f:3c:56:de:10:26:c6:ea:d3: |
| 85:cc:e2:58:67:45:9d:b6:10:96:8f:31:d0:85:65:48:8a:0b: |
| 90:35:46:a3:3c:72:65:c0:ce:25:5f:eb:8b:79:88:61:ab:25: |
| 6d:35:cd:bd:33:c8:ac:9e:c5:ca:f5:cf:43:9e:55:ee:49:d7: |
| 89:62:9e:4f:b3:8a:11:50:4b:1e:57:76:ef:89:a5:d1:bd:57: |
| c0:80:9c:ec:ef:3f:20:bd:cd:0e:45:04:2f:79:c5:50:58:81: |
| c5:54:37:f5:40:d6:cf:66:ce:5d:cc:a2:ef:ed:16:e7:60:a7: |
| 82:3a:17:de:df:02:a2:57:f3:a9:9e:36:a6:27:40:a5:c1:72: |
| e5:1c:b6:bd |
| -----BEGIN CERTIFICATE----- |
| MIIDgDCCAmigAwIBAgIUIbTxDFISfs6TXt0tK2npu4xNJHAwDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD |
| ggEPADCCAQoCggEBAO07u/KLIIHeQkHGJGMcS+VjsJMH/SJkUH3vj+1lqrr02a0M |
| aN1QsOoKXhie30iI7B/6a0o+2+okbrGjuwsS3h1J0zJ4JPnoT6qFkCGiLI9YlYxw |
| gI3NmWgDZw9I65YXY5Mrj3J3I1+XT4a9F9JwW1wY+AHWEdjA3DKy9L/d2mX7hiPA |
| pL3/wqS2h54QmNT0CcsmUB1Wg3IJxsG3zFKcYQkEu6oqY2alsQJghbwwkWK7b7Ak |
| M+i1mhMfOnOV1fu8qUjdFKKkYuGXGVexGtrBeZP9dMvh/wxJwnhXju/c32CWjuai |
| l2C5U2sXjq75Pb4x3UYYva+2pgL6SC/YxvAfvEMCAwEAAaOByzCByDAdBgNVHQ4E |
| FgQUJLmRQTnxMF74xTvAUcwRWKYTc7MwHwYDVR0jBBgwFoAUzW9M/qp6OmNdEnlt |
| 9EywKop/+2wwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs |
| LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m |
| b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ |
| MA0GCSqGSIb3DQEBCwUAA4IBAQCc2+PhACquH3KPPTkTuLFHsiS5jT0Q3Nwc6R5x |
| 0jmZiYaMim22h6UGz3Wi0up6f6y6p4OFItj3eRw+bbECJ93XAwtJ4Fj9Oeu1IiIb |
| sw1T7YFghx/EpszIPXYxh9WpPHQ2C5uSL3oNZJeFPdn3itwKKAuD8Y1/PFbeECbG |
| 6tOFzOJYZ0WdthCWjzHQhWVIiguQNUajPHJlwM4lX+uLeYhhqyVtNc29M8isnsXK |
| 9c9DnlXuSdeJYp5Ps4oRUEseV3bviaXRvVfAgJzs7z8gvc0ORQQvecVQWIHFVDf1 |
| QNbPZs5dzKLv7RbnYKeCOhfe3wKiV/OpnjamJ0ClwXLlHLa9 |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 21:b4:f1:0c:52:12:7e:ce:93:5e:dd:2d:2b:69:e9:bb:8c:4d:24:6f |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Root |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:e8:17:31:b6:0e:84:10:a4:9b:bf:9e:ae:9e:29: |
| b7:6f:81:ae:d7:df:45:89:d1:29:51:0e:1e:39:7a: |
| 96:6b:7f:c0:78:df:88:cf:db:b3:ab:8d:49:0f:fb: |
| 70:55:85:4f:93:9f:12:a1:a6:55:5c:a9:ae:8d:79: |
| 4d:a6:3a:32:03:9c:bf:ad:95:c4:8b:49:1f:02:b5: |
| 23:a0:9f:da:d3:45:c6:8c:fc:ec:97:46:57:dd:77: |
| 56:c6:a2:46:78:da:a2:59:bb:22:ea:de:63:94:50: |
| 19:91:1c:10:cd:67:e0:57:10:bd:e0:de:69:67:80: |
| 6d:31:a8:43:bc:49:2c:8a:d6:4a:23:0f:a6:78:f4: |
| 74:c7:4f:37:52:3a:af:9c:03:b2:b3:6c:26:ab:62: |
| 61:12:6d:22:15:66:da:ec:d6:b8:1f:9b:14:b9:04: |
| 9c:9b:5e:b5:cb:8b:62:95:67:6a:a1:57:44:02:77: |
| a2:81:3e:c7:20:52:a2:16:2e:ba:c2:29:a1:54:ed: |
| 33:67:f2:2a:26:a3:b6:da:08:8d:63:6c:ca:4f:c6: |
| 84:88:b9:60:08:cf:50:8e:5a:3e:75:d7:ec:d7:63: |
| c1:fe:18:3f:4e:fb:08:de:39:45:d2:81:34:8e:89: |
| 5a:48:ce:49:bf:ca:84:cb:26:ac:c2:f7:1f:6b:3f: |
| 0d:49 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C |
| X509v3 Authority Key Identifier: |
| keyid:CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| Signature Algorithm: sha256WithRSAEncryption |
| 33:85:9f:ab:29:fc:7f:ee:57:cb:82:f2:49:33:f8:40:df:a8: |
| 7d:f3:7e:78:a0:51:80:87:ab:70:d5:71:e2:ab:76:b1:72:4f: |
| 49:c0:06:f8:4e:30:60:30:cf:3a:05:74:65:60:3f:f1:d4:3e: |
| 2b:8a:ce:f5:bc:38:a7:17:20:0d:41:80:75:46:47:45:e5:29: |
| 1c:35:76:b9:54:68:15:ed:34:e4:27:b0:26:9e:ae:b6:20:74: |
| 04:e1:25:a2:20:a6:6e:8f:2b:1d:99:04:75:50:62:7e:a0:5b: |
| 6e:a9:49:e2:66:5d:db:40:01:92:b4:5e:88:41:52:9a:62:ac: |
| ad:b9:f3:82:67:c4:5c:97:ea:24:fc:bb:d6:1a:a6:f4:9a:01: |
| 25:12:c5:cb:c2:79:52:34:26:78:84:da:45:3e:cd:90:a4:a7: |
| e5:05:6d:5c:51:69:1e:c5:fd:75:b8:29:4b:77:c1:1f:39:22: |
| d3:de:60:37:ed:e7:47:f2:24:26:da:89:74:7b:65:71:a7:d8: |
| 6d:f6:9f:4d:1a:97:d6:09:ae:23:54:ef:26:88:4b:62:d8:b0: |
| 29:db:d0:25:c0:ee:d5:f9:4b:34:8a:7a:2b:79:90:7d:da:56: |
| 54:81:e3:75:48:76:6e:12:57:02:47:57:84:18:ba:05:50:99: |
| ce:5f:b0:97 |
| -----BEGIN CERTIFICATE----- |
| MIIDeDCCAmCgAwIBAgIUIbTxDFISfs6TXt0tK2npu4xNJG8wDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK |
| AoIBAQDoFzG2DoQQpJu/nq6eKbdvga7X30WJ0SlRDh45epZrf8B434jP27OrjUkP |
| +3BVhU+TnxKhplVcqa6NeU2mOjIDnL+tlcSLSR8CtSOgn9rTRcaM/OyXRlfdd1bG |
| okZ42qJZuyLq3mOUUBmRHBDNZ+BXEL3g3mlngG0xqEO8SSyK1kojD6Z49HTHTzdS |
| Oq+cA7KzbCarYmESbSIVZtrs1rgfmxS5BJybXrXLi2KVZ2qhV0QCd6KBPscgUqIW |
| LrrCKaFU7TNn8iomo7baCI1jbMpPxoSIuWAIz1COWj511+zXY8H+GD9O+wjeOUXS |
| gTSOiVpIzkm/yoTLJqzC9x9rPw1JAgMBAAGjgcswgcgwHQYDVR0OBBYEFM1vTP6q |
| ejpjXRJ5bfRMsCqKf/tsMB8GA1UdIwQYMBaAFM1vTP6qejpjXRJ5bfRMsCqKf/ts |
| MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh |
| L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S |
| b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG |
| 9w0BAQsFAAOCAQEAM4Wfqyn8f+5Xy4LySTP4QN+offN+eKBRgIercNVx4qt2sXJP |
| ScAG+E4wYDDPOgV0ZWA/8dQ+K4rO9bw4pxcgDUGAdUZHReUpHDV2uVRoFe005Cew |
| Jp6utiB0BOEloiCmbo8rHZkEdVBifqBbbqlJ4mZd20ABkrReiEFSmmKsrbnzgmfE |
| XJfqJPy71hqm9JoBJRLFy8J5UjQmeITaRT7NkKSn5QVtXFFpHsX9dbgpS3fBHzki |
| 095gN+3nR/IkJtqJdHtlcafYbfafTRqX1gmuI1TvJohLYtiwKdvQJcDu1flLNIp6 |
| K3mQfdpWVIHjdUh2bhJXAkdXhBi6BVCZzl+wlw== |
| -----END CERTIFICATE----- |