blob: dc25c9adf3da395d470dc577fdcff7a0c7836916 [file] [log] [blame]
[Created by: ./generate-chains.py]
Chain where the leaf has two policies and the intermediate has anyPolicy.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
6b:e1:0f:c9:fa:59:38:73:f8:5d:58:01:76:a1:f9:07:db:92:01:5c
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:a7:fb:0c:b8:75:eb:c8:c2:7a:0c:72:ee:89:76:
8c:a8:0c:54:51:5a:2d:69:42:9f:78:ea:57:3f:c0:
c2:4f:6d:b9:92:cf:41:f5:83:70:56:02:06:80:f6:
0b:61:3d:ff:d6:2c:0e:9d:59:fc:91:a6:47:fe:f0:
36:07:48:1e:18:5b:d1:59:50:e9:07:a7:a6:3b:0c:
53:e3:31:53:e0:3b:c3:1d:02:c4:6d:ed:a7:9d:bc:
a4:f6:1a:1a:c8:c4:51:28:60:11:2d:3f:2c:93:60:
d5:4e:44:83:e3:2b:ea:47:98:7a:c4:6e:6d:67:32:
2c:29:28:3f:b0:73:c1:b2:ce:fc:f6:15:e3:16:d5:
00:11:b4:98:91:43:42:d6:0f:ed:82:95:2f:23:69:
60:0e:9a:09:1b:9a:67:c1:a0:83:d4:74:80:6f:de:
67:34:73:d9:79:bb:83:6b:90:0c:a7:59:05:5c:96:
9b:e2:7e:f2:d7:6b:57:09:81:8b:6a:54:d2:58:50:
22:49:3c:ca:44:a1:a9:c9:41:50:39:d4:ad:78:3c:
e0:4b:74:ff:d6:04:61:6a:e5:4d:eb:2d:45:11:78:
a7:30:bc:12:31:c5:1e:e6:f8:dc:81:60:6f:0b:01:
bc:50:a2:c1:e4:6c:eb:87:b4:b5:89:86:b3:cc:0a:
68:d1
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
9D:8B:D4:7E:BA:F1:1F:2F:2B:E6:6A:5E:E5:36:FD:A6:3E:F5:5F:B0
X509v3 Authority Key Identifier:
keyid:DE:60:17:6D:1C:07:19:9D:2A:ED:85:01:D1:5F:20:9F:30:B6:35:87
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Certificate Policies:
Policy: 1.2.3.4
Policy: 1.2.6.7
X509v3 Subject Alternative Name:
DNS:test.example
Signature Algorithm: sha256WithRSAEncryption
53:ff:95:b8:e6:43:0d:9b:ca:f0:ed:aa:90:0a:9b:17:b7:95:
ec:2e:e2:25:a6:49:bd:19:e4:98:c8:e7:3d:26:96:12:f7:77:
14:56:85:61:3c:a3:d7:86:fd:ac:8d:55:1b:aa:49:5d:ce:4b:
a0:1f:e6:f2:7b:8c:21:d3:4c:b8:72:c7:00:d2:ed:b7:25:39:
40:4d:d0:53:6e:b9:82:b8:f2:30:3f:2a:df:41:64:20:85:5a:
a9:2a:90:18:86:a1:23:7b:2c:b1:6a:22:87:80:a5:f6:2e:fb:
27:bf:61:cc:28:6e:c9:ab:da:35:5a:71:f6:89:c5:9c:fa:f7:
ab:d4:07:7e:58:e6:50:69:61:b3:b5:fa:a5:80:35:c1:b2:61:
91:09:c0:86:df:67:a0:ab:ee:8d:d4:f1:f0:6d:61:fe:5d:64:
5f:a5:06:37:3f:51:80:4c:4d:28:77:61:ef:e8:0e:dd:b8:8f:
5d:24:1e:45:18:76:10:5d:f6:5b:c9:65:72:c7:f9:b0:a4:1f:
04:ea:ff:16:b5:10:a5:2e:ea:cb:09:fd:c7:e3:38:40:93:4d:
5f:0c:78:9e:cc:6e:04:eb:4f:e0:94:ce:e2:0d:01:f7:9f:5f:
61:f9:c8:04:39:05:48:30:c2:5d:f8:cd:a8:be:8d:ea:7d:b4:
e1:99:4a:1f
-----BEGIN CERTIFICATE-----
MIID1DCCArygAwIBAgIUa+EPyfpZOHP4XVgBdqH5B9uSAVwwDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAp/sMuHXryMJ6DHLuiXaMqAxUUVotaUKfeOpXP8DCT225
ks9B9YNwVgIGgPYLYT3/1iwOnVn8kaZH/vA2B0geGFvRWVDpB6emOwxT4zFT4DvD
HQLEbe2nnbyk9hoayMRRKGARLT8sk2DVTkSD4yvqR5h6xG5tZzIsKSg/sHPBss78
9hXjFtUAEbSYkUNC1g/tgpUvI2lgDpoJG5pnwaCD1HSAb95nNHPZebuDa5AMp1kF
XJab4n7y12tXCYGLalTSWFAiSTzKRKGpyUFQOdSteDzgS3T/1gRhauVN6y1FEXin
MLwSMcUe5vjcgWBvCwG8UKLB5Gzrh7S1iYazzApo0QIDAQABo4IBHDCCARgwHQYD
VR0OBBYEFJ2L1H668R8vK+ZqXuU2/aY+9V+wMB8GA1UdIwQYMBaAFN5gF20cBxmd
Ku2FAdFfIJ8wtjWHMD8GCCsGAQUFBwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDov
L3VybC1mb3ItYWlhL0ludGVybWVkaWF0ZS5jZXIwNAYDVR0fBC0wKzApoCegJYYj
aHR0cDovL3VybC1mb3ItY3JsL0ludGVybWVkaWF0ZS5jcmwwDgYDVR0PAQH/BAQD
AgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAXBgNVHSAEEDAOMAUG
AyoDBDAFBgMqBgcwFwYDVR0RBBAwDoIMdGVzdC5leGFtcGxlMA0GCSqGSIb3DQEB
CwUAA4IBAQBT/5W45kMNm8rw7aqQCpsXt5XsLuIlpkm9GeSYyOc9JpYS93cUVoVh
PKPXhv2sjVUbqkldzkugH+bye4wh00y4cscA0u23JTlATdBTbrmCuPIwPyrfQWQg
hVqpKpAYhqEjeyyxaiKHgKX2Lvsnv2HMKG7Jq9o1WnH2icWc+ver1Ad+WOZQaWGz
tfqlgDXBsmGRCcCG32egq+6N1PHwbWH+XWRfpQY3P1GATE0od2Hv6A7duI9dJB5F
GHYQXfZbyWVyx/mwpB8E6v8WtRClLurLCf3H4zhAk01fDHiezG4E60/glM7iDQH3
n19h+cgEOQVIMMJd+M2ovo3qfbThmUof
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
76:42:db:45:76:7f:b8:53:d5:02:1e:c2:90:7e:60:72:5a:78:fc:c8
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:b2:2f:54:6d:cb:bc:2b:71:f5:87:7a:7d:5d:ab:
c3:0e:bd:15:b0:a5:47:e4:2b:2a:a0:a0:0d:0f:65:
fc:84:85:2c:b4:24:a7:cf:87:9e:89:d9:f3:cf:de:
89:61:c7:64:42:65:5f:39:13:89:92:48:54:9c:33:
6b:8e:dc:dc:c6:4d:79:f8:63:37:f4:41:0d:57:ee:
5b:0d:6d:2f:6a:d6:78:d3:d3:f7:29:d0:fa:89:ec:
72:ec:11:49:fe:78:8f:38:ac:69:27:e3:f9:19:3d:
58:18:2e:2d:f6:7c:a5:30:1f:1d:79:65:b5:b1:4d:
05:6a:4b:dd:01:2e:a7:64:d1:16:23:07:05:1a:09:
6a:67:73:d0:f3:d9:c3:81:9e:99:ac:ee:58:06:b5:
d6:ce:df:0d:c4:14:42:cb:44:e1:7b:2a:1f:e6:38:
e6:00:4b:39:d1:89:0c:27:d6:e3:61:16:7e:44:8f:
25:65:8d:a6:a4:95:85:3e:13:c5:d6:14:83:c1:e3:
69:cf:88:ed:f7:74:9e:2b:8e:a7:5f:ad:d2:84:98:
06:14:85:88:54:0a:b6:9c:8a:8f:0b:d1:c4:2c:5e:
06:96:55:4a:92:7b:14:bb:aa:bf:cd:d4:a5:a8:ae:
ef:eb:d8:97:75:7b:a0:7a:b6:69:1c:27:37:f2:f9:
e5:09
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
DE:60:17:6D:1C:07:19:9D:2A:ED:85:01:D1:5F:20:9F:30:B6:35:87
X509v3 Authority Key Identifier:
keyid:E3:1C:57:80:6D:50:B5:5E:E3:27:A5:3F:E5:CC:E0:A9:45:56:C1:9E
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Certificate Policies:
Policy: X509v3 Any Policy
Signature Algorithm: sha256WithRSAEncryption
65:99:b2:22:1c:ad:6d:5c:d5:ef:d5:53:70:84:2b:6a:54:e6:
55:e3:0a:9d:89:f3:dc:25:6c:ac:26:02:50:86:7d:25:4e:59:
ba:e5:54:5e:5f:b3:55:78:21:e1:63:02:3e:db:f3:ee:92:d4:
0b:13:e0:fd:db:83:4c:2a:50:a7:1b:f8:76:90:87:19:23:5a:
4d:73:8a:83:95:7b:13:9f:30:ae:df:03:11:56:5b:29:fe:8a:
22:80:f4:7c:05:5a:61:ba:83:e2:10:65:c2:69:33:45:bb:5c:
9b:a9:96:f2:bf:29:bc:72:76:85:6b:fc:51:fb:94:60:4a:5e:
ca:87:c8:ad:81:82:b8:14:09:68:dd:48:9e:93:3b:c9:84:ba:
4e:c5:8d:62:4a:32:52:5a:4f:58:b1:7c:ea:a8:f7:5f:50:13:
dd:46:35:2c:a0:df:4c:15:b9:6e:f9:74:e5:c4:f6:2f:02:2b:
1a:d8:9c:7d:fc:0c:22:d6:62:71:98:ad:5c:af:2c:70:d0:07:
fa:28:4c:4b:09:90:44:e4:85:b9:b2:8c:46:a4:b7:0d:55:71:
29:67:27:07:aa:11:b0:3d:e5:10:b7:28:58:d3:19:db:85:4c:
df:25:b7:82:38:21:f6:a2:4b:d1:af:68:4c:57:58:d2:b6:29:
79:ef:a2:f1
-----BEGIN CERTIFICATE-----
MIIDkzCCAnugAwIBAgIUdkLbRXZ/uFPVAh7CkH5gclp4/MgwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBALIvVG3LvCtx9Yd6fV2rww69FbClR+QrKqCgDQ9l/ISFLLQk
p8+HnonZ88/eiWHHZEJlXzkTiZJIVJwza47c3MZNefhjN/RBDVfuWw1tL2rWeNPT
9ynQ+onscuwRSf54jzisaSfj+Rk9WBguLfZ8pTAfHXlltbFNBWpL3QEup2TRFiMH
BRoJamdz0PPZw4GemazuWAa11s7fDcQUQstE4XsqH+Y45gBLOdGJDCfW42EWfkSP
JWWNpqSVhT4TxdYUg8Hjac+I7fd0niuOp1+t0oSYBhSFiFQKtpyKjwvRxCxeBpZV
SpJ7FLuqv83Upaiu7+vYl3V7oHq2aRwnN/L55QkCAwEAAaOB3jCB2zAdBgNVHQ4E
FgQU3mAXbRwHGZ0q7YUB0V8gnzC2NYcwHwYDVR0jBBgwFoAU4xxXgG1QtV7jJ6U/
5czgqUVWwZ4wNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MBEGA1UdIAQKMAgwBgYEVR0gADANBgkqhkiG9w0BAQsFAAOCAQEAZZmyIhytbVzV
79VTcIQralTmVeMKnYnz3CVsrCYCUIZ9JU5ZuuVUXl+zVXgh4WMCPtvz7pLUCxPg
/duDTCpQpxv4dpCHGSNaTXOKg5V7E58wrt8DEVZbKf6KIoD0fAVaYbqD4hBlwmkz
Rbtcm6mW8r8pvHJ2hWv8UfuUYEpeyofIrYGCuBQJaN1InpM7yYS6TsWNYkoyUlpP
WLF86qj3X1AT3UY1LKDfTBW5bvl05cT2LwIrGticffwMItZicZitXK8scNAH+ihM
SwmQROSFubKMRqS3DVVxKWcnB6oRsD3lELcoWNMZ24VM3yW3gjgh9qJL0a9oTFdY
0rYpee+i8Q==
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
76:42:db:45:76:7f:b8:53:d5:02:1e:c2:90:7e:60:72:5a:78:fc:c7
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:9a:8f:40:d0:8f:a9:e6:69:43:b2:9a:c5:a9:f9:
0f:20:56:10:59:91:36:08:26:d2:eb:0c:e6:82:de:
a5:90:ca:67:dc:f8:17:bc:71:91:9c:f3:46:eb:71:
65:f5:a5:e0:9c:5e:e5:09:2f:a2:9c:5d:49:29:20:
d0:bb:58:c3:ac:9d:4c:a4:df:8a:06:40:13:93:63:
1d:24:d8:5c:01:57:0c:34:ea:47:ae:31:1a:21:d7:
cf:29:73:44:96:97:01:c8:36:57:77:4c:1d:e0:bc:
5a:93:06:3b:d5:45:3f:98:09:8c:db:cc:f2:eb:90:
28:53:94:9f:8d:fd:97:75:ca:c7:fe:92:cf:58:1b:
93:66:37:12:c2:6b:bb:38:a2:43:24:dc:41:c3:b3:
3c:69:f9:a1:7b:ad:7d:92:b3:22:a5:31:df:34:86:
62:43:d8:11:3d:dd:7c:1b:24:9f:0d:2a:0f:c5:1c:
7d:c4:fe:55:4d:33:7a:0a:ef:98:55:64:3f:a7:c6:
40:d3:f7:e0:2d:68:f8:83:0f:c3:8d:c4:65:89:1c:
ab:c8:0d:30:6c:da:dd:8d:a2:8f:ac:96:d8:de:41:
e7:b8:3d:d4:5b:8f:c3:3d:87:6b:d6:7f:bb:4d:23:
d5:08:60:bc:d2:54:85:fe:4f:b4:49:cf:18:32:74:
a1:3f
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
E3:1C:57:80:6D:50:B5:5E:E3:27:A5:3F:E5:CC:E0:A9:45:56:C1:9E
X509v3 Authority Key Identifier:
keyid:E3:1C:57:80:6D:50:B5:5E:E3:27:A5:3F:E5:CC:E0:A9:45:56:C1:9E
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
29:37:4b:cd:43:0a:ff:3d:d9:d2:d8:8c:d0:0c:98:12:9f:a1:
d7:2c:02:d9:87:55:fe:bc:86:c2:e2:06:36:77:0a:d6:88:45:
78:52:63:57:77:ee:fd:76:95:4a:e2:bc:ce:58:fc:06:20:ac:
e7:66:e3:4b:bb:1d:69:dd:25:dd:e8:00:e7:d9:f9:5c:10:33:
0a:88:d7:fe:f0:cb:32:ec:8e:2d:c4:31:25:b7:8a:1f:a1:89:
b8:f1:58:d1:20:4b:ad:fe:da:2a:c1:f7:ef:c8:7b:d2:06:ee:
d0:4f:f7:0d:25:f1:d8:75:18:a5:82:90:9a:b1:b8:4a:b8:a3:
70:92:5f:d8:f3:ca:90:93:8b:4c:d6:66:a5:d5:2c:bf:ba:37:
08:0e:74:36:69:f1:02:43:90:da:bf:1a:d5:07:ef:24:74:0e:
cf:6e:cc:26:a0:b1:13:df:b5:6b:cb:b4:08:82:78:c8:81:a5:
d6:5d:48:76:fd:c9:0a:de:39:4b:87:ae:a9:ff:dd:30:89:d2:
64:14:83:df:a1:2a:23:f1:bc:5f:93:64:01:47:0e:a6:12:f5:
3e:89:0c:88:89:e3:3f:d9:44:27:fe:49:ee:85:4f:b7:a7:48:
74:4a:93:44:2e:4a:cf:e4:5a:44:cd:b4:7a:60:6e:28:70:3f:
f7:9e:04:4f
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUdkLbRXZ/uFPVAh7CkH5gclp4/McwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQCaj0DQj6nmaUOymsWp+Q8gVhBZkTYIJtLrDOaC3qWQymfc+Be8cZGc80br
cWX1peCcXuUJL6KcXUkpINC7WMOsnUyk34oGQBOTYx0k2FwBVww06keuMRoh188p
c0SWlwHINld3TB3gvFqTBjvVRT+YCYzbzPLrkChTlJ+N/Zd1ysf+ks9YG5NmNxLC
a7s4okMk3EHDszxp+aF7rX2SsyKlMd80hmJD2BE93XwbJJ8NKg/FHH3E/lVNM3oK
75hVZD+nxkDT9+AtaPiDD8ONxGWJHKvIDTBs2t2Noo+sltjeQee4PdRbj8M9h2vW
f7tNI9UIYLzSVIX+T7RJzxgydKE/AgMBAAGjgcswgcgwHQYDVR0OBBYEFOMcV4Bt
ULVe4yelP+XM4KlFVsGeMB8GA1UdIwQYMBaAFOMcV4BtULVe4yelP+XM4KlFVsGe
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEAKTdLzUMK/z3Z0tiM0AyYEp+h1ywC2YdV/ryGwuIGNncK1ohF
eFJjV3fu/XaVSuK8zlj8BiCs52bjS7sdad0l3egA59n5XBAzCojX/vDLMuyOLcQx
JbeKH6GJuPFY0SBLrf7aKsH378h70gbu0E/3DSXx2HUYpYKQmrG4SrijcJJf2PPK
kJOLTNZmpdUsv7o3CA50NmnxAkOQ2r8a1QfvJHQOz27MJqCxE9+1a8u0CIJ4yIGl
1l1Idv3JCt45S4euqf/dMInSZBSD36EqI/G8X5NkAUcOphL1PokMiInjP9lEJ/5J
7oVPt6dIdEqTRC5Kz+RaRM20emBuKHA/954ETw==
-----END CERTIFICATE-----