| [Created by: generate-chains.py] |
| |
| Certificate chain where the leaf has a basic constraints extension with |
| CA=false, however specifies the optional pathlen. |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 2d:58:fd:1c:9f:8b:f0:cb:61:00:36:cc:88:b7:31:82:91:15:f5:15 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Intermediate |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Target |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:ba:80:5c:f0:d7:23:f0:69:d9:b7:8f:fc:c3:d4: |
| 47:a2:41:29:77:01:50:3c:84:8f:52:f7:11:6d:c4: |
| 75:04:84:48:98:8c:4e:bb:f6:4b:e2:cb:4d:be:01: |
| dc:b2:8e:48:b6:da:76:4d:b0:28:75:94:28:d7:44: |
| 2c:0d:a5:70:fe:b8:ec:c3:d0:0d:8b:74:4a:18:b9: |
| 13:bb:b1:99:80:09:d0:bd:00:a3:20:64:70:bb:18: |
| 00:7c:61:1f:5d:d2:dc:23:6a:6a:e3:8a:6c:13:9b: |
| a3:c5:7b:dc:91:71:29:46:4e:1c:8e:82:2a:d6:bb: |
| f9:5a:91:be:f0:a7:a9:b2:d5:8c:df:a2:d2:eb:3a: |
| e4:49:30:8b:83:20:6d:fb:af:90:19:3e:44:b5:d3: |
| bb:05:a1:15:a1:0d:4c:61:82:63:5e:24:a5:94:df: |
| a9:35:5a:0f:56:eb:8c:1d:a5:0e:80:4a:16:d1:ef: |
| dd:cf:84:f6:45:55:65:55:b8:73:ae:ca:1c:f8:c7: |
| e2:67:e8:8a:42:5e:eb:f6:2c:bf:55:1c:18:39:51: |
| 5b:15:16:1b:0a:06:ba:b0:ad:bc:45:2d:23:5c:3a: |
| ca:2b:04:c9:a2:4f:a6:80:ec:d2:b8:d7:98:44:69: |
| 3c:3c:2e:ab:b4:44:e2:50:6a:b8:a6:59:db:d4:61: |
| 54:fd |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| 5B:3D:C4:92:95:A9:93:D8:29:1F:56:EB:DA:A0:3C:1A:C0:BD:5D:AB |
| X509v3 Authority Key Identifier: |
| keyid:FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Intermediate.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Intermediate.crl |
| |
| X509v3 Key Usage: critical |
| Digital Signature, Key Encipherment |
| X509v3 Extended Key Usage: |
| TLS Web Server Authentication, TLS Web Client Authentication |
| X509v3 Basic Constraints: critical |
| CA:FALSE, pathlen:1 |
| Signature Algorithm: sha256WithRSAEncryption |
| 73:a8:63:41:82:ec:54:fb:89:62:65:5c:a4:d2:ef:a8:85:4f: |
| fe:41:aa:f3:dd:48:d4:48:53:b1:3e:04:2c:a9:35:60:bb:8d: |
| b7:7f:60:fa:94:7d:bd:4d:8b:41:90:9f:26:eb:84:d4:cd:eb: |
| ee:3d:59:4c:29:a5:47:ec:d4:58:07:14:b1:3e:c1:0f:f9:c3: |
| 80:a7:91:8f:57:4b:80:f5:a6:a0:b8:65:36:d9:9e:86:67:8b: |
| 81:72:cd:da:18:16:cd:0a:f1:0f:6c:f7:f6:b0:d0:59:57:d6: |
| 31:13:27:97:cf:cc:63:45:9f:e8:20:27:98:8f:b4:8f:03:c4: |
| 34:74:a9:0e:c8:18:dc:7f:49:0d:1f:19:50:78:c6:76:b2:aa: |
| a3:58:38:9c:c7:6b:61:98:45:6c:78:e2:f3:ff:2c:30:9e:34: |
| c1:82:29:ad:8f:ac:43:65:33:ac:0a:a6:24:6e:34:71:db:98: |
| 6e:d6:9e:66:04:6d:79:ee:c9:50:04:6f:41:40:e1:1a:8e:32: |
| 14:6a:19:cb:17:c7:3f:d7:a8:5d:50:da:20:6e:ca:18:01:e5: |
| 1a:e3:92:ff:cb:20:b5:5a:78:c6:f4:dd:1f:88:92:93:d5:47: |
| 01:b3:d3:3a:53:8a:4f:13:7b:d3:56:63:7b:0e:00:8d:11:37: |
| 7f:be:2a:dd |
| -----BEGIN CERTIFICATE----- |
| MIIDsTCCApmgAwIBAgIULVj9HJ+L8MthADbMiLcxgpEV9RUwDQYJKoZIhvcNAQEL |
| BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTE4MDMxMDEyMDAwMFoXDTIx |
| MDEwMTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF |
| AAOCAQ8AMIIBCgKCAQEAuoBc8Ncj8GnZt4/8w9RHokEpdwFQPISPUvcRbcR1BIRI |
| mIxOu/ZL4stNvgHcso5Ittp2TbAodZQo10QsDaVw/rjsw9ANi3RKGLkTu7GZgAnQ |
| vQCjIGRwuxgAfGEfXdLcI2pq44psE5ujxXvckXEpRk4cjoIq1rv5WpG+8KepstWM |
| 36LS6zrkSTCLgyBt+6+QGT5EtdO7BaEVoQ1MYYJjXiSllN+pNVoPVuuMHaUOgEoW |
| 0e/dz4T2RVVlVbhzrsoc+MfiZ+iKQl7r9iy/VRwYOVFbFRYbCga6sK28RS0jXDrK |
| KwTJok+mgOzSuNeYRGk8PC6rtETiUGq4plnb1GFU/QIDAQABo4H6MIH3MB0GA1Ud |
| DgQWBBRbPcSSlamT2CkfVuvaoDwawL1dqzAfBgNVHSMEGDAWgBT7OkOcukCJclu9 |
| Joo7JXccwfAsfjA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 |
| cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 |
| dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF |
| oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwIB |
| ATANBgkqhkiG9w0BAQsFAAOCAQEAc6hjQYLsVPuJYmVcpNLvqIVP/kGq891I1EhT |
| sT4ELKk1YLuNt39g+pR9vU2LQZCfJuuE1M3r7j1ZTCmlR+zUWAcUsT7BD/nDgKeR |
| j1dLgPWmoLhlNtmehmeLgXLN2hgWzQrxD2z39rDQWVfWMRMnl8/MY0Wf6CAnmI+0 |
| jwPENHSpDsgY3H9JDR8ZUHjGdrKqo1g4nMdrYZhFbHji8/8sMJ40wYIprY+sQ2Uz |
| rAqmJG40cduYbtaeZgRtee7JUARvQUDhGo4yFGoZyxfHP9eoXVDaIG7KGAHlGuOS |
| /8sgtVp4xvTdH4iSk9VHAbPTOlOKTxN701Zjew4AjRE3f74q3Q== |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fe |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Intermediate |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:b1:bb:78:97:4a:b5:56:42:fa:f9:6b:63:6c:f3: |
| 0e:54:92:6c:84:d4:c7:53:48:24:c1:bd:6f:d0:83: |
| ad:f3:7a:5c:93:f1:74:38:ba:46:f1:19:db:0e:fb: |
| 1b:b4:f2:9e:8b:c4:10:8e:97:b1:ff:f8:2d:03:cd: |
| 36:91:8a:2c:e8:d8:da:a4:7e:58:8d:fb:ff:99:2b: |
| d5:e1:b3:63:7f:ec:2c:66:b5:0d:ca:ba:e1:74:5e: |
| b3:ad:bf:49:65:74:52:30:78:ed:ea:7c:08:26:32: |
| f1:d5:e3:ea:01:7e:3a:fc:0e:84:d6:17:aa:98:f8: |
| 92:63:77:4d:5c:d3:13:61:af:e3:d8:35:0c:ff:1e: |
| 39:91:0c:24:a9:ec:89:ab:28:97:97:56:eb:2a:73: |
| 70:e7:46:17:89:1e:42:73:a5:f6:b6:de:5a:bc:24: |
| 69:5d:41:09:31:f6:12:d3:57:2d:dc:96:9c:0a:4d: |
| 64:f0:c4:24:44:8e:1d:66:37:a1:01:1a:d5:89:a8: |
| 9c:81:82:00:d9:f5:56:e9:58:df:ea:5d:32:7e:fb: |
| 2d:19:1b:39:b4:fb:77:2c:2e:e1:ae:f5:ea:b0:ad: |
| b7:d4:2e:35:86:26:9f:96:c6:e3:4c:27:7b:6a:7d: |
| a2:4e:bf:cb:59:33:85:6f:d1:98:e4:27:3c:95:3f: |
| fd:ad |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E |
| X509v3 Authority Key Identifier: |
| keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| Signature Algorithm: sha256WithRSAEncryption |
| 43:39:2f:fe:4c:7f:eb:c6:65:73:5d:be:2a:a3:b0:c6:af:63: |
| 28:ec:bf:29:88:07:0f:7d:5b:ec:b1:7b:43:76:10:3c:b7:dc: |
| a8:c6:ff:87:57:c5:84:4d:0f:3b:a4:1a:44:a7:69:ae:2f:fe: |
| 4a:a7:ec:f8:26:4a:78:28:43:df:af:16:e4:29:06:79:be:06: |
| cc:13:91:b5:95:de:e3:01:e1:a2:97:b7:15:48:30:81:f9:b6: |
| 1d:d6:42:62:62:62:d1:55:55:ca:0a:55:3c:e9:71:fe:1c:0f: |
| 31:b3:c8:83:f0:c7:76:e4:72:81:38:52:c2:a1:4b:f7:66:07: |
| 0e:98:31:d6:ea:6f:b1:bf:6a:60:a2:b0:86:00:97:9e:66:27: |
| 7b:a1:a6:93:d1:3b:c6:0d:8f:2f:3a:e7:59:d9:92:b7:ac:7e: |
| da:c2:ed:aa:78:44:51:91:af:c1:74:74:7f:59:d4:e3:53:e6: |
| 9d:03:04:0b:fa:70:90:6f:55:87:6b:fd:e7:12:ee:fe:b7:2d: |
| 9c:de:14:89:57:22:0f:ff:a9:a3:e9:78:6e:0d:14:5a:8c:36: |
| 86:08:1f:f1:3e:12:eb:89:51:6c:d3:af:47:62:7f:41:a3:0c: |
| 6a:1b:25:a0:60:aa:7c:9b:80:88:ea:98:58:be:27:69:2d:ce: |
| 09:4b:1e:21 |
| -----BEGIN CERTIFICATE----- |
| MIIDgDCCAmigAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP4wDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD |
| ggEPADCCAQoCggEBALG7eJdKtVZC+vlrY2zzDlSSbITUx1NIJMG9b9CDrfN6XJPx |
| dDi6RvEZ2w77G7TynovEEI6Xsf/4LQPNNpGKLOjY2qR+WI37/5kr1eGzY3/sLGa1 |
| Dcq64XRes62/SWV0UjB47ep8CCYy8dXj6gF+OvwOhNYXqpj4kmN3TVzTE2Gv49g1 |
| DP8eOZEMJKnsiasol5dW6ypzcOdGF4keQnOl9rbeWrwkaV1BCTH2EtNXLdyWnApN |
| ZPDEJESOHWY3oQEa1YmonIGCANn1VulY3+pdMn77LRkbObT7dywu4a716rCtt9Qu |
| NYYmn5bG40wne2p9ok6/y1kzhW/RmOQnPJU//a0CAwEAAaOByzCByDAdBgNVHQ4E |
| FgQU+zpDnLpAiXJbvSaKOyV3HMHwLH4wHwYDVR0jBBgwFoAUj05eeBmuKIJpL88z |
| lQTBzXXR9v8wNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs |
| LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m |
| b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ |
| MA0GCSqGSIb3DQEBCwUAA4IBAQBDOS/+TH/rxmVzXb4qo7DGr2Mo7L8piAcPfVvs |
| sXtDdhA8t9yoxv+HV8WETQ87pBpEp2muL/5Kp+z4Jkp4KEPfrxbkKQZ5vgbME5G1 |
| ld7jAeGil7cVSDCB+bYd1kJiYmLRVVXKClU86XH+HA8xs8iD8Md25HKBOFLCoUv3 |
| ZgcOmDHW6m+xv2pgorCGAJeeZid7oaaT0TvGDY8vOudZ2ZK3rH7awu2qeERRka/B |
| dHR/WdTjU+adAwQL+nCQb1WHa/3nEu7+ty2c3hSJVyIP/6mj6XhuDRRajDaGCB/x |
| PhLriVFs069HYn9BowxqGyWgYKp8m4CI6phYvidpLc4JSx4h |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fd |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Root |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:b3:59:c0:d6:b0:f3:cb:31:46:9d:ef:de:63:f3: |
| 1a:24:10:36:fb:e8:ee:05:76:21:51:51:fd:52:47: |
| 97:12:13:46:42:bc:94:37:5e:e6:41:d2:d8:75:27: |
| 2c:3d:04:bc:e1:ac:bc:a8:f6:d8:74:63:9a:be:a9: |
| 7b:d2:1b:96:87:25:3b:ce:d1:ff:b4:dd:fa:29:64: |
| ae:df:4c:1b:b4:fb:9e:8a:9a:6c:74:ba:2a:76:45: |
| 03:b7:91:7e:90:ba:04:3d:dc:0a:17:77:b3:5f:dc: |
| 56:07:eb:63:5e:2b:54:c9:d7:b3:4b:f3:42:6b:9e: |
| 2a:80:9c:71:52:5d:0f:6d:97:c6:d3:f6:c4:7a:7a: |
| ee:ea:22:4f:1c:e8:42:55:6e:b2:2a:56:cf:86:3c: |
| 94:d1:e7:e0:7c:78:8c:94:05:05:b0:3f:b2:70:18: |
| da:92:d2:9a:ba:57:7c:fb:52:4b:0f:34:cb:dc:ab: |
| 40:a0:76:4e:cc:11:b9:57:be:f2:e2:fa:2b:ba:20: |
| b0:c8:ee:8d:0a:11:a2:02:d4:f7:38:3d:f4:a8:49: |
| f4:b4:8a:08:ff:d0:c3:25:21:0e:dc:f0:17:22:f2: |
| bf:07:3d:e7:5f:4c:b2:cd:1a:18:f1:fd:3a:5a:42: |
| 79:b3:82:47:ad:ad:e0:02:7f:0b:19:34:5d:3b:90: |
| 81:23 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| 8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF |
| X509v3 Authority Key Identifier: |
| keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| Signature Algorithm: sha256WithRSAEncryption |
| 14:d5:0c:73:1a:59:37:e3:75:34:6f:ce:6f:01:d2:f8:94:28: |
| 8c:0a:5e:db:ff:a7:5d:d9:d2:b7:e2:8d:73:36:c7:80:85:51: |
| c6:1c:39:af:8f:2c:74:1b:0d:fc:31:15:f6:a9:bd:0a:e3:6d: |
| 05:33:ec:7f:da:14:9c:6c:34:d6:35:cd:3e:8f:dd:4f:6e:0c: |
| 82:66:b7:00:5e:d7:1e:f4:86:d1:16:62:c4:ca:fd:bb:2d:8b: |
| b2:1b:ad:e6:eb:a3:ec:78:83:e3:90:a0:59:24:02:a0:8f:fe: |
| b7:86:64:43:4a:16:fd:c9:28:65:4e:bd:33:c4:2f:b9:cf:4c: |
| 5b:4c:db:8f:fe:ed:1e:84:b7:77:ce:47:3d:e8:47:d7:2f:22: |
| 34:b1:f5:d2:55:5d:d8:d9:1f:e5:d1:ef:87:75:56:43:60:f8: |
| d8:31:29:e1:34:85:72:c9:79:e8:ee:7d:3a:b9:ea:d1:eb:56: |
| dc:5a:2c:d0:ce:e5:41:d4:9a:81:da:dd:8d:1c:bc:2d:99:70: |
| 63:09:5b:0f:53:d0:32:ee:1f:30:8d:73:ec:68:ac:d6:2b:71: |
| 53:2a:68:a6:b1:d2:84:16:c5:73:fa:eb:be:7e:17:c8:c5:b3: |
| 2a:08:d9:e7:23:92:2d:f8:0c:1e:94:e9:2c:2c:99:0a:de:51: |
| a0:b3:17:f4 |
| -----BEGIN CERTIFICATE----- |
| MIIDeDCCAmCgAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP0wDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK |
| AoIBAQCzWcDWsPPLMUad795j8xokEDb76O4FdiFRUf1SR5cSE0ZCvJQ3XuZB0th1 |
| Jyw9BLzhrLyo9th0Y5q+qXvSG5aHJTvO0f+03fopZK7fTBu0+56Kmmx0uip2RQO3 |
| kX6QugQ93AoXd7Nf3FYH62NeK1TJ17NL80JrniqAnHFSXQ9tl8bT9sR6eu7qIk8c |
| 6EJVbrIqVs+GPJTR5+B8eIyUBQWwP7JwGNqS0pq6V3z7UksPNMvcq0Cgdk7MEblX |
| vvLi+iu6ILDI7o0KEaIC1Pc4PfSoSfS0igj/0MMlIQ7c8Bci8r8HPedfTLLNGhjx |
| /TpaQnmzgketreACfwsZNF07kIEjAgMBAAGjgcswgcgwHQYDVR0OBBYEFI9OXngZ |
| riiCaS/PM5UEwc110fb/MB8GA1UdIwQYMBaAFI9OXngZriiCaS/PM5UEwc110fb/ |
| MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh |
| L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S |
| b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG |
| 9w0BAQsFAAOCAQEAFNUMcxpZN+N1NG/ObwHS+JQojApe2/+nXdnSt+KNczbHgIVR |
| xhw5r48sdBsN/DEV9qm9CuNtBTPsf9oUnGw01jXNPo/dT24Mgma3AF7XHvSG0RZi |
| xMr9uy2Lshut5uuj7HiD45CgWSQCoI/+t4ZkQ0oW/ckoZU69M8Qvuc9MW0zbj/7t |
| HoS3d85HPehH1y8iNLH10lVd2Nkf5dHvh3VWQ2D42DEp4TSFcsl56O59Ornq0etW |
| 3Fos0M7lQdSagdrdjRy8LZlwYwlbD1PQMu4fMI1z7Gis1itxUypoprHShBbFc/rr |
| vn4XyMWzKgjZ5yOSLfgMHpTpLCyZCt5RoLMX9A== |
| -----END CERTIFICATE----- |