blob: 575124052752ec21f48aec9041713b2a29de7f17 [file] [log] [blame]
[Created by: generate-chains.py]
Certificate chain where the intermediate has a policies extension (not
marked as critical) which contains an unknown policy qualifer (1.2.3.4).
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
31:6a:f9:bd:60:f3:6d:85:80:16:84:85:c0:6e:f2:0e:9a:01:52:0b
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:be:d9:c3:94:6a:c2:d7:1b:b4:33:1a:29:0d:ca:
48:e2:f1:94:93:27:36:71:c1:a2:dc:67:0e:5d:67:
b0:a9:08:9c:67:08:ba:d9:74:5f:01:62:5d:7f:2a:
bb:32:ed:0c:af:c8:5a:b5:02:24:45:6f:90:4c:83:
ab:0e:30:19:c2:df:bc:d5:25:99:b0:f3:5e:e1:27:
5b:06:2f:ca:3e:d6:49:fb:87:8d:d3:fd:b9:b9:27:
80:be:b5:88:72:3b:1b:20:3f:04:69:04:89:66:ee:
20:f7:c2:90:c1:27:aa:29:fa:88:ff:2f:10:3b:81:
cf:d0:b9:e9:a7:84:dc:f1:a7:d0:49:e0:6e:17:b2:
ba:09:ed:be:9c:a3:f2:66:37:dd:20:98:43:31:bd:
02:d1:55:63:88:f6:55:13:20:b7:b9:0b:c9:c9:fb:
a3:5b:0f:90:56:e8:8a:dc:a5:7a:92:bc:46:5d:82:
a4:e1:42:2c:7c:76:65:63:87:f4:e0:5a:cf:15:22:
13:49:1d:aa:0d:ea:25:08:7c:63:19:39:2f:1d:15:
2e:7c:9a:e7:d5:03:21:76:6c:22:1a:be:12:8b:72:
c5:cb:0f:41:ef:0f:d3:be:78:1d:12:e0:c2:29:eb:
d7:36:28:54:ad:8d:ce:c8:79:2f:4f:13:c1:2b:3b:
e4:ff
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
FE:3D:1B:76:A0:3D:EE:69:00:5B:D4:61:90:68:18:E3:29:EC:66:A3
X509v3 Authority Key Identifier:
keyid:49:F0:C4:09:BE:16:68:CF:0A:C1:E0:EF:8F:A6:34:1F:94:63:6F:E6
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
Signature Algorithm: sha256WithRSAEncryption
6f:3f:fa:25:c9:63:f2:c1:e6:27:f4:15:93:99:0b:ad:07:cd:
5b:e9:0e:73:79:9d:49:34:d8:0f:ae:b5:e3:c1:17:08:a4:d6:
6f:0f:c4:80:cb:1e:27:45:8c:df:17:dc:dc:22:60:8c:d6:da:
33:f9:39:a7:8e:79:1d:54:fc:6f:24:33:77:93:21:70:b1:18:
09:b1:c7:8c:7e:ee:6e:c6:77:fc:ba:f2:3a:82:64:d8:d4:72:
de:b6:ad:6a:bd:67:9c:bb:39:ec:f5:98:bc:26:4c:0f:f8:e3:
de:c5:9e:06:3c:69:42:43:c1:e4:91:ba:eb:d4:14:c2:9d:eb:
d2:16:92:e0:8b:5a:79:50:be:05:16:39:3f:42:ed:3e:b8:33:
8a:bf:09:0a:b0:fc:48:e0:54:b2:67:3a:d6:ea:fe:df:df:64:
4d:61:4b:09:e8:41:3a:44:b8:e8:38:c1:43:31:43:79:98:c2:
4c:a3:b0:50:de:6f:a8:fd:7d:50:b6:3f:c8:09:b9:08:17:8b:
4b:9d:ba:ad:12:24:b1:8e:04:e1:10:54:8b:e1:ea:3a:8a:12:
14:13:8c:a7:3c:82:70:97:05:0f:bf:3b:16:7d:bd:bb:6d:e8:
04:78:c6:aa:18:8f:2f:bd:29:97:4b:38:eb:f4:fc:45:11:dc:
41:5c:d5:2d
-----BEGIN CERTIFICATE-----
MIIDoDCCAoigAwIBAgIUMWr5vWDzbYWAFoSFwG7yDpoBUgswDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTE4MDMxMDEyMDAwMFoXDTIx
MDEwMTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAvtnDlGrC1xu0MxopDcpI4vGUkyc2ccGi3GcOXWewqQic
Zwi62XRfAWJdfyq7Mu0Mr8hatQIkRW+QTIOrDjAZwt+81SWZsPNe4SdbBi/KPtZJ
+4eN0/25uSeAvrWIcjsbID8EaQSJZu4g98KQwSeqKfqI/y8QO4HP0Lnpp4Tc8afQ
SeBuF7K6Ce2+nKPyZjfdIJhDMb0C0VVjiPZVEyC3uQvJyfujWw+QVuiK3KV6krxG
XYKk4UIsfHZlY4f04FrPFSITSR2qDeolCHxjGTkvHRUufJrn1QMhdmwiGr4Si3LF
yw9B7w/TvngdEuDCKevXNihUrY3OyHkvTxPBKzvk/wIDAQABo4HpMIHmMB0GA1Ud
DgQWBBT+PRt2oD3uaQBb1GGQaBjjKexmozAfBgNVHSMEGDAWgBRJ8MQJvhZozwrB
4O+PpjQflGNv5jA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZIhvcNAQELBQAD
ggEBAG8/+iXJY/LB5if0FZOZC60HzVvpDnN5nUk02A+utePBFwik1m8PxIDLHidF
jN8X3NwiYIzW2jP5OaeOeR1U/G8kM3eTIXCxGAmxx4x+7m7Gd/y68jqCZNjUct62
rWq9Z5y7Oez1mLwmTA/4497FngY8aUJDweSRuuvUFMKd69IWkuCLWnlQvgUWOT9C
7T64M4q/CQqw/EjgVLJnOtbq/t/fZE1hSwnoQTpEuOg4wUMxQ3mYwkyjsFDeb6j9
fVC2P8gJuQgXi0uduq0SJLGOBOEQVIvh6jqKEhQTjKc8gnCXBQ+/OxZ9vbtt6AR4
xqoYjy+9KZdLOOv0/EUR3EFc1S0=
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
1a:97:5a:9c:80:bc:38:51:fe:e9:06:6c:9c:24:16:bd:7b:49:b2:42
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:d9:74:6c:03:22:ab:05:1b:af:d1:34:43:ac:2a:
a3:bd:5d:dc:13:39:5f:df:ff:f4:bd:3c:bd:56:1e:
b5:e9:b2:19:1d:49:ff:9c:5a:31:9c:20:74:87:27:
81:22:50:a3:c2:90:da:48:da:c2:cd:4a:4d:dd:ec:
75:d7:61:5b:32:57:1e:1d:63:82:54:69:49:f1:ff:
3e:a5:67:46:b2:77:73:61:ce:30:9c:d5:f7:36:1f:
83:0e:12:f8:37:48:a9:36:e6:38:61:13:5a:1d:a7:
70:17:d2:0d:81:87:f0:cf:02:3c:13:56:fc:e9:79:
96:c0:6d:8a:5d:a7:ad:e7:c5:3f:09:28:aa:e9:a8:
6b:23:a3:78:fe:34:11:ba:d0:12:59:cf:b3:8a:68:
df:96:2f:44:b0:b9:72:54:cf:ba:1b:2c:8c:56:a4:
9d:db:b8:55:72:42:04:13:77:cc:75:04:3d:e9:b1:
fa:a4:19:1b:3d:6f:0a:c2:7a:48:37:8b:35:c6:e1:
cc:c6:50:b5:45:c0:f2:30:ca:ff:df:75:af:4b:c3:
c7:63:11:da:fb:54:bf:53:57:a0:ce:75:18:53:8e:
c7:49:c3:4a:79:88:a4:1d:34:a4:e0:d2:f4:63:ca:
5a:02:89:c3:94:a3:38:32:f6:3b:e1:06:e4:02:e4:
d0:25
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
49:F0:C4:09:BE:16:68:CF:0A:C1:E0:EF:8F:A6:34:1F:94:63:6F:E6
X509v3 Authority Key Identifier:
keyid:27:0D:D0:55:88:5D:DE:1C:37:96:A0:62:14:C2:19:3C:C6:A4:1F:D1
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Certificate Policies:
Policy: 1.2.3
Unknown Qualifier: 1.2.3.4
Signature Algorithm: sha256WithRSAEncryption
85:18:d1:0f:47:88:6e:c2:73:be:b3:46:b4:4e:7e:84:ee:c9:
04:fb:f8:ad:45:b6:10:16:0c:3c:ff:7c:14:98:55:f4:6e:22:
b1:57:34:40:92:94:24:3c:4c:5c:b8:ab:95:2c:74:c0:f3:e7:
f2:16:b1:00:28:f6:a8:41:c2:b9:85:84:27:c5:59:54:c9:3e:
1d:3a:f5:21:22:72:10:9d:5c:6d:68:f7:3c:11:69:c4:54:0d:
1c:83:47:4b:a2:a2:7d:68:c3:f9:18:85:93:41:8c:96:d5:59:
8a:42:10:d6:92:63:83:bf:78:00:16:85:ab:ce:8d:07:28:ff:
13:50:ba:d4:a7:b1:be:c3:25:99:93:0a:82:6c:24:02:61:29:
26:45:7c:8a:57:7c:1e:12:74:fd:cd:d2:07:30:74:cd:a1:45:
cd:6e:07:f2:bc:45:24:ba:24:05:4a:07:50:94:c3:21:91:67:
44:ad:63:a5:e5:fe:ab:a6:78:6a:f1:fb:50:2b:1a:86:f8:70:
6f:6b:7c:d2:78:29:ff:7b:81:5a:cd:51:ca:a2:62:00:12:03:
ee:9f:e3:2a:e5:62:2f:25:55:43:a8:16:db:a2:d8:f1:54:42:
40:a8:ea:b7:cf:ce:cb:b6:cc:7f:1e:aa:4e:84:6e:44:3f:c4:
0d:4a:c8:8c
-----BEGIN CERTIFICATE-----
MIIDnjCCAoagAwIBAgIUGpdanIC8OFH+6QZsnCQWvXtJskIwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBANl0bAMiqwUbr9E0Q6wqo71d3BM5X9//9L08vVYetemyGR1J
/5xaMZwgdIcngSJQo8KQ2kjaws1KTd3sdddhWzJXHh1jglRpSfH/PqVnRrJ3c2HO
MJzV9zYfgw4S+DdIqTbmOGETWh2ncBfSDYGH8M8CPBNW/Ol5lsBtil2nrefFPwko
qumoayOjeP40EbrQElnPs4po35YvRLC5clTPuhssjFakndu4VXJCBBN3zHUEPemx
+qQZGz1vCsJ6SDeLNcbhzMZQtUXA8jDK/991r0vDx2MR2vtUv1NXoM51GFOOx0nD
SnmIpB00pODS9GPKWgKJw5SjODL2O+EG5ALk0CUCAwEAAaOB6TCB5jAdBgNVHQ4E
FgQUSfDECb4WaM8KweDvj6Y0H5Rjb+YwHwYDVR0jBBgwFoAUJw3QVYhd3hw3lqBi
FMIZPMakH9EwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MBwGA1UdIAQVMBMwEQYCKgMwCzAJBgMqAwQMAmhpMA0GCSqGSIb3DQEBCwUAA4IB
AQCFGNEPR4huwnO+s0a0Tn6E7skE+/itRbYQFgw8/3wUmFX0biKxVzRAkpQkPExc
uKuVLHTA8+fyFrEAKPaoQcK5hYQnxVlUyT4dOvUhInIQnVxtaPc8EWnEVA0cg0dL
oqJ9aMP5GIWTQYyW1VmKQhDWkmODv3gAFoWrzo0HKP8TULrUp7G+wyWZkwqCbCQC
YSkmRXyKV3weEnT9zdIHMHTNoUXNbgfyvEUkuiQFSgdQlMMhkWdErWOl5f6rpnhq
8ftQKxqG+HBva3zSeCn/e4FazVHKomIAEgPun+Mq5WIvJVVDqBbbotjxVEJAqOq3
z87Ltsx/HqpOhG5EP8QNSsiM
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
1a:97:5a:9c:80:bc:38:51:fe:e9:06:6c:9c:24:16:bd:7b:49:b2:41
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:a0:f9:c1:fa:93:42:7b:bf:e5:1e:21:e2:f5:cd:
db:f7:61:04:6e:ea:06:4c:fc:d5:2e:9f:5e:6e:97:
b2:d4:c3:f1:4c:18:01:5e:3e:85:e2:c0:73:ce:56:
fb:cc:4c:4e:f0:37:b5:e0:c6:31:5c:c0:06:5a:90:
24:d8:5d:88:ab:e3:53:2b:12:90:0b:16:c6:db:19:
74:e7:29:63:53:d9:5b:f3:e7:80:8c:5e:86:ff:e8:
e3:72:6b:09:6c:64:6b:92:34:f2:9c:bd:f4:b7:c1:
31:6f:74:00:31:3a:45:70:9f:5d:a5:d3:9c:91:7f:
fb:87:95:ef:07:f3:8d:8e:c9:a5:cb:ed:cc:2d:23:
bf:e4:98:93:88:8d:be:bc:50:02:2c:3a:0d:52:53:
7e:9a:20:04:da:52:db:a4:e5:72:bc:d6:40:40:7f:
51:86:29:d7:f5:f7:db:85:b3:a0:7d:7a:c5:04:3e:
e9:73:ca:65:3c:13:91:46:a1:b4:fb:6b:8b:a0:5e:
7c:c9:9d:3c:5e:c5:f6:2a:99:df:2e:13:1e:7d:d8:
db:30:02:52:d7:94:16:93:b8:20:5d:77:4d:26:6e:
9c:c8:5e:0a:56:ad:ba:d9:26:c0:80:dd:66:aa:09:
09:18:41:fa:f2:5c:7f:ae:10:45:25:ba:cc:0d:5d:
d8:3b
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
27:0D:D0:55:88:5D:DE:1C:37:96:A0:62:14:C2:19:3C:C6:A4:1F:D1
X509v3 Authority Key Identifier:
keyid:27:0D:D0:55:88:5D:DE:1C:37:96:A0:62:14:C2:19:3C:C6:A4:1F:D1
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
23:c6:54:c3:ec:7a:07:fb:72:00:e2:7f:96:79:9c:d1:fb:7d:
b9:0b:99:a6:85:7d:1b:b4:12:6e:78:77:f9:c2:77:52:ab:b2:
cc:16:ce:d2:41:80:3b:48:95:8f:4e:dc:8b:75:72:11:90:b9:
15:6e:58:a6:4b:77:25:83:4e:46:82:21:af:14:81:a9:9c:66:
50:05:b1:d1:67:07:35:9e:7e:6d:5e:0e:bb:97:51:ad:89:87:
dd:26:d0:bf:3f:e1:32:96:e1:da:7b:bf:e7:8b:0c:2f:8a:db:
1e:94:d4:37:e5:67:bf:c2:65:50:60:ec:e1:6f:b8:1d:d9:f7:
31:3a:d4:cb:06:89:73:96:55:d0:4a:69:90:d8:e2:01:59:d7:
87:e5:1d:0b:4c:1e:78:d3:0a:39:fa:9a:ce:a5:91:b9:f4:38:
6a:f0:19:29:fd:4f:05:3b:61:4c:1e:ad:72:4e:86:b4:f6:bb:
b7:f9:92:c9:8f:51:7f:70:40:91:a4:ae:e6:28:29:35:6c:a4:
25:23:5a:3f:09:00:af:f7:cc:b9:fe:74:5d:e3:52:0e:80:db:
4a:d5:15:af:05:84:02:d5:a8:cf:3e:16:53:db:eb:3a:06:52:
3d:66:ac:6f:fd:42:8a:92:d9:5b:03:90:92:c3:2d:38:98:2b:
a5:5e:25:23
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUGpdanIC8OFH+6QZsnCQWvXtJskEwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQCg+cH6k0J7v+UeIeL1zdv3YQRu6gZM/NUun15ul7LUw/FMGAFePoXiwHPO
VvvMTE7wN7XgxjFcwAZakCTYXYir41MrEpALFsbbGXTnKWNT2Vvz54CMXob/6ONy
awlsZGuSNPKcvfS3wTFvdAAxOkVwn12l05yRf/uHle8H842OyaXL7cwtI7/kmJOI
jb68UAIsOg1SU36aIATaUtuk5XK81kBAf1GGKdf199uFs6B9esUEPulzymU8E5FG
obT7a4ugXnzJnTxexfYqmd8uEx592NswAlLXlBaTuCBdd00mbpzIXgpWrbrZJsCA
3WaqCQkYQfryXH+uEEUluswNXdg7AgMBAAGjgcswgcgwHQYDVR0OBBYEFCcN0FWI
Xd4cN5agYhTCGTzGpB/RMB8GA1UdIwQYMBaAFCcN0FWIXd4cN5agYhTCGTzGpB/R
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEAI8ZUw+x6B/tyAOJ/lnmc0ft9uQuZpoV9G7QSbnh3+cJ3Uquy
zBbO0kGAO0iVj07ci3VyEZC5FW5Ypkt3JYNORoIhrxSBqZxmUAWx0WcHNZ5+bV4O
u5dRrYmH3SbQvz/hMpbh2nu/54sML4rbHpTUN+Vnv8JlUGDs4W+4Hdn3MTrUywaJ
c5ZV0EppkNjiAVnXh+UdC0weeNMKOfqazqWRufQ4avAZKf1PBTthTB6tck6GtPa7
t/mSyY9Rf3BAkaSu5igpNWykJSNaPwkAr/fMuf50XeNSDoDbStUVrwWEAtWozz4W
U9vrOgZSPWasb/1CipLZWwOQksMtOJgrpV4lIw==
-----END CERTIFICATE-----