blob: e9bf4d0b083a081e67eb2fadd14c3564cafb7104 [file] [log] [blame]
[Created by: generate-chains.py]
Certificate chain where the leaf has a basic constraints extension with
CA=false, however specifies the optional pathlen.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
2d:58:fd:1c:9f:8b:f0:cb:61:00:36:cc:88:b7:31:82:91:15:f5:15
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:ba:80:5c:f0:d7:23:f0:69:d9:b7:8f:fc:c3:d4:
47:a2:41:29:77:01:50:3c:84:8f:52:f7:11:6d:c4:
75:04:84:48:98:8c:4e:bb:f6:4b:e2:cb:4d:be:01:
dc:b2:8e:48:b6:da:76:4d:b0:28:75:94:28:d7:44:
2c:0d:a5:70:fe:b8:ec:c3:d0:0d:8b:74:4a:18:b9:
13:bb:b1:99:80:09:d0:bd:00:a3:20:64:70:bb:18:
00:7c:61:1f:5d:d2:dc:23:6a:6a:e3:8a:6c:13:9b:
a3:c5:7b:dc:91:71:29:46:4e:1c:8e:82:2a:d6:bb:
f9:5a:91:be:f0:a7:a9:b2:d5:8c:df:a2:d2:eb:3a:
e4:49:30:8b:83:20:6d:fb:af:90:19:3e:44:b5:d3:
bb:05:a1:15:a1:0d:4c:61:82:63:5e:24:a5:94:df:
a9:35:5a:0f:56:eb:8c:1d:a5:0e:80:4a:16:d1:ef:
dd:cf:84:f6:45:55:65:55:b8:73:ae:ca:1c:f8:c7:
e2:67:e8:8a:42:5e:eb:f6:2c:bf:55:1c:18:39:51:
5b:15:16:1b:0a:06:ba:b0:ad:bc:45:2d:23:5c:3a:
ca:2b:04:c9:a2:4f:a6:80:ec:d2:b8:d7:98:44:69:
3c:3c:2e:ab:b4:44:e2:50:6a:b8:a6:59:db:d4:61:
54:fd
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
5B:3D:C4:92:95:A9:93:D8:29:1F:56:EB:DA:A0:3C:1A:C0:BD:5D:AB
X509v3 Authority Key Identifier:
keyid:FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE, pathlen:1
Signature Algorithm: sha256WithRSAEncryption
73:a8:63:41:82:ec:54:fb:89:62:65:5c:a4:d2:ef:a8:85:4f:
fe:41:aa:f3:dd:48:d4:48:53:b1:3e:04:2c:a9:35:60:bb:8d:
b7:7f:60:fa:94:7d:bd:4d:8b:41:90:9f:26:eb:84:d4:cd:eb:
ee:3d:59:4c:29:a5:47:ec:d4:58:07:14:b1:3e:c1:0f:f9:c3:
80:a7:91:8f:57:4b:80:f5:a6:a0:b8:65:36:d9:9e:86:67:8b:
81:72:cd:da:18:16:cd:0a:f1:0f:6c:f7:f6:b0:d0:59:57:d6:
31:13:27:97:cf:cc:63:45:9f:e8:20:27:98:8f:b4:8f:03:c4:
34:74:a9:0e:c8:18:dc:7f:49:0d:1f:19:50:78:c6:76:b2:aa:
a3:58:38:9c:c7:6b:61:98:45:6c:78:e2:f3:ff:2c:30:9e:34:
c1:82:29:ad:8f:ac:43:65:33:ac:0a:a6:24:6e:34:71:db:98:
6e:d6:9e:66:04:6d:79:ee:c9:50:04:6f:41:40:e1:1a:8e:32:
14:6a:19:cb:17:c7:3f:d7:a8:5d:50:da:20:6e:ca:18:01:e5:
1a:e3:92:ff:cb:20:b5:5a:78:c6:f4:dd:1f:88:92:93:d5:47:
01:b3:d3:3a:53:8a:4f:13:7b:d3:56:63:7b:0e:00:8d:11:37:
7f:be:2a:dd
-----BEGIN CERTIFICATE-----
MIIDsTCCApmgAwIBAgIULVj9HJ+L8MthADbMiLcxgpEV9RUwDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTE4MDMxMDEyMDAwMFoXDTIx
MDEwMTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAuoBc8Ncj8GnZt4/8w9RHokEpdwFQPISPUvcRbcR1BIRI
mIxOu/ZL4stNvgHcso5Ittp2TbAodZQo10QsDaVw/rjsw9ANi3RKGLkTu7GZgAnQ
vQCjIGRwuxgAfGEfXdLcI2pq44psE5ujxXvckXEpRk4cjoIq1rv5WpG+8KepstWM
36LS6zrkSTCLgyBt+6+QGT5EtdO7BaEVoQ1MYYJjXiSllN+pNVoPVuuMHaUOgEoW
0e/dz4T2RVVlVbhzrsoc+MfiZ+iKQl7r9iy/VRwYOVFbFRYbCga6sK28RS0jXDrK
KwTJok+mgOzSuNeYRGk8PC6rtETiUGq4plnb1GFU/QIDAQABo4H6MIH3MB0GA1Ud
DgQWBBRbPcSSlamT2CkfVuvaoDwawL1dqzAfBgNVHSMEGDAWgBT7OkOcukCJclu9
Joo7JXccwfAsfjA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwIB
ATANBgkqhkiG9w0BAQsFAAOCAQEAc6hjQYLsVPuJYmVcpNLvqIVP/kGq891I1EhT
sT4ELKk1YLuNt39g+pR9vU2LQZCfJuuE1M3r7j1ZTCmlR+zUWAcUsT7BD/nDgKeR
j1dLgPWmoLhlNtmehmeLgXLN2hgWzQrxD2z39rDQWVfWMRMnl8/MY0Wf6CAnmI+0
jwPENHSpDsgY3H9JDR8ZUHjGdrKqo1g4nMdrYZhFbHji8/8sMJ40wYIprY+sQ2Uz
rAqmJG40cduYbtaeZgRtee7JUARvQUDhGo4yFGoZyxfHP9eoXVDaIG7KGAHlGuOS
/8sgtVp4xvTdH4iSk9VHAbPTOlOKTxN701Zjew4AjRE3f74q3Q==
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fe
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b1:bb:78:97:4a:b5:56:42:fa:f9:6b:63:6c:f3:
0e:54:92:6c:84:d4:c7:53:48:24:c1:bd:6f:d0:83:
ad:f3:7a:5c:93:f1:74:38:ba:46:f1:19:db:0e:fb:
1b:b4:f2:9e:8b:c4:10:8e:97:b1:ff:f8:2d:03:cd:
36:91:8a:2c:e8:d8:da:a4:7e:58:8d:fb:ff:99:2b:
d5:e1:b3:63:7f:ec:2c:66:b5:0d:ca:ba:e1:74:5e:
b3:ad:bf:49:65:74:52:30:78:ed:ea:7c:08:26:32:
f1:d5:e3:ea:01:7e:3a:fc:0e:84:d6:17:aa:98:f8:
92:63:77:4d:5c:d3:13:61:af:e3:d8:35:0c:ff:1e:
39:91:0c:24:a9:ec:89:ab:28:97:97:56:eb:2a:73:
70:e7:46:17:89:1e:42:73:a5:f6:b6:de:5a:bc:24:
69:5d:41:09:31:f6:12:d3:57:2d:dc:96:9c:0a:4d:
64:f0:c4:24:44:8e:1d:66:37:a1:01:1a:d5:89:a8:
9c:81:82:00:d9:f5:56:e9:58:df:ea:5d:32:7e:fb:
2d:19:1b:39:b4:fb:77:2c:2e:e1:ae:f5:ea:b0:ad:
b7:d4:2e:35:86:26:9f:96:c6:e3:4c:27:7b:6a:7d:
a2:4e:bf:cb:59:33:85:6f:d1:98:e4:27:3c:95:3f:
fd:ad
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E
X509v3 Authority Key Identifier:
keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
43:39:2f:fe:4c:7f:eb:c6:65:73:5d:be:2a:a3:b0:c6:af:63:
28:ec:bf:29:88:07:0f:7d:5b:ec:b1:7b:43:76:10:3c:b7:dc:
a8:c6:ff:87:57:c5:84:4d:0f:3b:a4:1a:44:a7:69:ae:2f:fe:
4a:a7:ec:f8:26:4a:78:28:43:df:af:16:e4:29:06:79:be:06:
cc:13:91:b5:95:de:e3:01:e1:a2:97:b7:15:48:30:81:f9:b6:
1d:d6:42:62:62:62:d1:55:55:ca:0a:55:3c:e9:71:fe:1c:0f:
31:b3:c8:83:f0:c7:76:e4:72:81:38:52:c2:a1:4b:f7:66:07:
0e:98:31:d6:ea:6f:b1:bf:6a:60:a2:b0:86:00:97:9e:66:27:
7b:a1:a6:93:d1:3b:c6:0d:8f:2f:3a:e7:59:d9:92:b7:ac:7e:
da:c2:ed:aa:78:44:51:91:af:c1:74:74:7f:59:d4:e3:53:e6:
9d:03:04:0b:fa:70:90:6f:55:87:6b:fd:e7:12:ee:fe:b7:2d:
9c:de:14:89:57:22:0f:ff:a9:a3:e9:78:6e:0d:14:5a:8c:36:
86:08:1f:f1:3e:12:eb:89:51:6c:d3:af:47:62:7f:41:a3:0c:
6a:1b:25:a0:60:aa:7c:9b:80:88:ea:98:58:be:27:69:2d:ce:
09:4b:1e:21
-----BEGIN CERTIFICATE-----
MIIDgDCCAmigAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP4wDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBALG7eJdKtVZC+vlrY2zzDlSSbITUx1NIJMG9b9CDrfN6XJPx
dDi6RvEZ2w77G7TynovEEI6Xsf/4LQPNNpGKLOjY2qR+WI37/5kr1eGzY3/sLGa1
Dcq64XRes62/SWV0UjB47ep8CCYy8dXj6gF+OvwOhNYXqpj4kmN3TVzTE2Gv49g1
DP8eOZEMJKnsiasol5dW6ypzcOdGF4keQnOl9rbeWrwkaV1BCTH2EtNXLdyWnApN
ZPDEJESOHWY3oQEa1YmonIGCANn1VulY3+pdMn77LRkbObT7dywu4a716rCtt9Qu
NYYmn5bG40wne2p9ok6/y1kzhW/RmOQnPJU//a0CAwEAAaOByzCByDAdBgNVHQ4E
FgQU+zpDnLpAiXJbvSaKOyV3HMHwLH4wHwYDVR0jBBgwFoAUj05eeBmuKIJpL88z
lQTBzXXR9v8wNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MA0GCSqGSIb3DQEBCwUAA4IBAQBDOS/+TH/rxmVzXb4qo7DGr2Mo7L8piAcPfVvs
sXtDdhA8t9yoxv+HV8WETQ87pBpEp2muL/5Kp+z4Jkp4KEPfrxbkKQZ5vgbME5G1
ld7jAeGil7cVSDCB+bYd1kJiYmLRVVXKClU86XH+HA8xs8iD8Md25HKBOFLCoUv3
ZgcOmDHW6m+xv2pgorCGAJeeZid7oaaT0TvGDY8vOudZ2ZK3rH7awu2qeERRka/B
dHR/WdTjU+adAwQL+nCQb1WHa/3nEu7+ty2c3hSJVyIP/6mj6XhuDRRajDaGCB/x
PhLriVFs069HYn9BowxqGyWgYKp8m4CI6phYvidpLc4JSx4h
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fd
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b3:59:c0:d6:b0:f3:cb:31:46:9d:ef:de:63:f3:
1a:24:10:36:fb:e8:ee:05:76:21:51:51:fd:52:47:
97:12:13:46:42:bc:94:37:5e:e6:41:d2:d8:75:27:
2c:3d:04:bc:e1:ac:bc:a8:f6:d8:74:63:9a:be:a9:
7b:d2:1b:96:87:25:3b:ce:d1:ff:b4:dd:fa:29:64:
ae:df:4c:1b:b4:fb:9e:8a:9a:6c:74:ba:2a:76:45:
03:b7:91:7e:90:ba:04:3d:dc:0a:17:77:b3:5f:dc:
56:07:eb:63:5e:2b:54:c9:d7:b3:4b:f3:42:6b:9e:
2a:80:9c:71:52:5d:0f:6d:97:c6:d3:f6:c4:7a:7a:
ee:ea:22:4f:1c:e8:42:55:6e:b2:2a:56:cf:86:3c:
94:d1:e7:e0:7c:78:8c:94:05:05:b0:3f:b2:70:18:
da:92:d2:9a:ba:57:7c:fb:52:4b:0f:34:cb:dc:ab:
40:a0:76:4e:cc:11:b9:57:be:f2:e2:fa:2b:ba:20:
b0:c8:ee:8d:0a:11:a2:02:d4:f7:38:3d:f4:a8:49:
f4:b4:8a:08:ff:d0:c3:25:21:0e:dc:f0:17:22:f2:
bf:07:3d:e7:5f:4c:b2:cd:1a:18:f1:fd:3a:5a:42:
79:b3:82:47:ad:ad:e0:02:7f:0b:19:34:5d:3b:90:
81:23
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
X509v3 Authority Key Identifier:
keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
14:d5:0c:73:1a:59:37:e3:75:34:6f:ce:6f:01:d2:f8:94:28:
8c:0a:5e:db:ff:a7:5d:d9:d2:b7:e2:8d:73:36:c7:80:85:51:
c6:1c:39:af:8f:2c:74:1b:0d:fc:31:15:f6:a9:bd:0a:e3:6d:
05:33:ec:7f:da:14:9c:6c:34:d6:35:cd:3e:8f:dd:4f:6e:0c:
82:66:b7:00:5e:d7:1e:f4:86:d1:16:62:c4:ca:fd:bb:2d:8b:
b2:1b:ad:e6:eb:a3:ec:78:83:e3:90:a0:59:24:02:a0:8f:fe:
b7:86:64:43:4a:16:fd:c9:28:65:4e:bd:33:c4:2f:b9:cf:4c:
5b:4c:db:8f:fe:ed:1e:84:b7:77:ce:47:3d:e8:47:d7:2f:22:
34:b1:f5:d2:55:5d:d8:d9:1f:e5:d1:ef:87:75:56:43:60:f8:
d8:31:29:e1:34:85:72:c9:79:e8:ee:7d:3a:b9:ea:d1:eb:56:
dc:5a:2c:d0:ce:e5:41:d4:9a:81:da:dd:8d:1c:bc:2d:99:70:
63:09:5b:0f:53:d0:32:ee:1f:30:8d:73:ec:68:ac:d6:2b:71:
53:2a:68:a6:b1:d2:84:16:c5:73:fa:eb:be:7e:17:c8:c5:b3:
2a:08:d9:e7:23:92:2d:f8:0c:1e:94:e9:2c:2c:99:0a:de:51:
a0:b3:17:f4
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP0wDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQCzWcDWsPPLMUad795j8xokEDb76O4FdiFRUf1SR5cSE0ZCvJQ3XuZB0th1
Jyw9BLzhrLyo9th0Y5q+qXvSG5aHJTvO0f+03fopZK7fTBu0+56Kmmx0uip2RQO3
kX6QugQ93AoXd7Nf3FYH62NeK1TJ17NL80JrniqAnHFSXQ9tl8bT9sR6eu7qIk8c
6EJVbrIqVs+GPJTR5+B8eIyUBQWwP7JwGNqS0pq6V3z7UksPNMvcq0Cgdk7MEblX
vvLi+iu6ILDI7o0KEaIC1Pc4PfSoSfS0igj/0MMlIQ7c8Bci8r8HPedfTLLNGhjx
/TpaQnmzgketreACfwsZNF07kIEjAgMBAAGjgcswgcgwHQYDVR0OBBYEFI9OXngZ
riiCaS/PM5UEwc110fb/MB8GA1UdIwQYMBaAFI9OXngZriiCaS/PM5UEwc110fb/
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEAFNUMcxpZN+N1NG/ObwHS+JQojApe2/+nXdnSt+KNczbHgIVR
xhw5r48sdBsN/DEV9qm9CuNtBTPsf9oUnGw01jXNPo/dT24Mgma3AF7XHvSG0RZi
xMr9uy2Lshut5uuj7HiD45CgWSQCoI/+t4ZkQ0oW/ckoZU69M8Qvuc9MW0zbj/7t
HoS3d85HPehH1y8iNLH10lVd2Nkf5dHvh3VWQ2D42DEp4TSFcsl56O59Ornq0etW
3Fos0M7lQdSagdrdjRy8LZlwYwlbD1PQMu4fMI1z7Gis1itxUypoprHShBbFc/rr
vn4XyMWzKgjZ5yOSLfgMHpTpLCyZCt5RoLMX9A==
-----END CERTIFICATE-----