blob: 385494f0de208aaa62127d8bbb358fb2f5f4217b [file] [log] [blame]
[Created by: generate-chains.py]
Certificate chain where the target certificate contains an unknown X.509v3
extension (OID=1.2.3.4) that is marked as critical.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
4e:9a:ac:ff:32:38:c0:2f:b6:e5:63:63:94:45:6d:aa:aa:c4:b6:e5
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:bd:05:ea:3a:1c:14:a1:db:ad:2c:18:3d:25:9c:
dc:1c:0f:2b:1e:42:df:c2:7c:b4:39:e6:4b:45:eb:
d3:a2:1c:2b:dc:f2:8c:08:f5:81:df:bd:fa:a2:1a:
1c:5c:99:cb:00:c7:31:02:c8:44:5f:31:cf:9c:82:
6d:3c:0c:5d:f7:d6:cc:91:fe:f3:e7:7a:08:17:85:
d5:75:61:ee:dd:66:55:3c:e2:68:98:36:19:20:e4:
9b:cd:24:6c:a3:5d:89:84:80:2e:c7:11:4e:c1:82:
b2:80:ce:0f:e9:6a:42:54:10:fb:c0:0a:53:be:19:
01:38:ba:06:c5:93:93:1c:84:aa:25:c7:c5:9a:4d:
32:2e:a4:13:5e:6d:07:d6:9d:e5:b0:29:63:da:14:
b7:62:51:63:93:dc:28:ae:4a:bc:35:ac:c0:06:ea:
ea:0b:d5:70:61:3b:05:78:e4:d3:ad:c3:ad:95:f1:
48:e5:79:a6:dc:12:1f:14:4f:21:9f:ca:6f:7a:dd:
d6:45:c8:8a:60:96:1c:02:06:16:18:80:21:58:6a:
f6:83:3e:1a:98:b8:b2:a9:22:44:c2:25:e9:dc:a9:
aa:bf:1d:2e:3f:2e:a1:78:08:93:04:4c:c4:1f:f9:
b3:34:9f:a7:78:5b:02:a6:ca:d3:1f:fa:ba:4d:34:
a2:bb
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
D6:55:4E:AC:07:84:35:A9:0D:9A:63:45:82:73:4E:A4:CC:53:B0:02
X509v3 Authority Key Identifier:
keyid:8A:E3:E6:F6:58:6F:1C:90:B4:67:A5:14:D8:64:E7:F7:00:77:61:01
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
1.2.3.4: critical
....
Signature Algorithm: sha256WithRSAEncryption
a8:13:5e:72:31:d7:35:54:3e:a3:b3:ad:16:98:43:4d:ac:22:
4d:42:9e:1d:f2:98:3e:ff:cd:ab:be:a8:6e:18:0a:12:76:2a:
ac:f6:63:da:09:9c:a3:78:66:19:14:eb:f5:aa:83:bc:0f:f6:
af:54:41:43:f1:4e:68:65:b3:ca:73:aa:e0:e3:b6:16:5b:cf:
0d:eb:37:76:c7:18:af:3c:92:db:c5:6a:64:d2:30:94:bb:59:
cf:95:06:3b:94:81:e9:1e:6e:6b:ff:53:97:d3:ed:99:42:5e:
1e:82:2c:ac:20:cc:39:90:88:d0:44:07:14:df:8f:66:0d:7a:
d9:5a:9b:78:6b:5c:dd:f6:29:ea:77:ff:86:63:4e:60:45:63:
d8:c3:3c:33:d0:e5:ca:e9:af:a5:0f:f1:f9:aa:5f:65:fe:1d:
3b:e2:a9:94:27:25:a9:64:0b:a0:52:91:d7:1e:63:77:a1:d3:
4c:d2:b3:65:99:3a:5a:f2:7b:92:c6:f6:f0:21:9d:ea:23:90:
f0:36:72:af:ce:d3:93:ab:06:29:9a:e7:9f:ed:67:64:f2:61:
2c:9e:12:da:0e:f0:fc:1f:7b:11:3c:0e:d4:60:e6:7b:30:1f:
51:eb:8c:55:68:84:23:87:6f:c0:36:c3:a1:26:10:a8:16:b9:
30:75:dd:f8
-----BEGIN CERTIFICATE-----
MIIDsDCCApigAwIBAgIUTpqs/zI4wC+25WNjlEVtqqrEtuUwDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTE4MDMxMDEyMDAwMFoXDTIx
MDEwMTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAvQXqOhwUodutLBg9JZzcHA8rHkLfwny0OeZLRevTohwr
3PKMCPWB3736ohocXJnLAMcxAshEXzHPnIJtPAxd99bMkf7z53oIF4XVdWHu3WZV
POJomDYZIOSbzSRso12JhIAuxxFOwYKygM4P6WpCVBD7wApTvhkBOLoGxZOTHISq
JcfFmk0yLqQTXm0H1p3lsClj2hS3YlFjk9workq8NazABurqC9VwYTsFeOTTrcOt
lfFI5Xmm3BIfFE8hn8pvet3WRciKYJYcAgYWGIAhWGr2gz4amLiyqSJEwiXp3Kmq
vx0uPy6heAiTBEzEH/mzNJ+neFsCpsrTH/q6TTSiuwIDAQABo4H5MIH2MB0GA1Ud
DgQWBBTWVU6sB4Q1qQ2aY0WCc06kzFOwAjAfBgNVHSMEGDAWgBSK4+b2WG8ckLRn
pRTYZOf3AHdhATA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDgYDKgMEAQH/BAQBAgME
MA0GCSqGSIb3DQEBCwUAA4IBAQCoE15yMdc1VD6js60WmENNrCJNQp4d8pg+/82r
vqhuGAoSdiqs9mPaCZyjeGYZFOv1qoO8D/avVEFD8U5oZbPKc6rg47YWW88N6zd2
xxivPJLbxWpk0jCUu1nPlQY7lIHpHm5r/1OX0+2ZQl4egiysIMw5kIjQRAcU349m
DXrZWpt4a1zd9inqd/+GY05gRWPYwzwz0OXK6a+lD/H5ql9l/h074qmUJyWpZAug
UpHXHmN3odNM0rNlmTpa8nuSxvbwIZ3qI5DwNnKvztOTqwYpmuef7Wdk8mEsnhLa
DvD8H3sRPA7UYOZ7MB9R64xVaIQjh2/ANsOhJhCoFrkwdd34
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
06:66:51:84:c2:7e:fc:0c:cf:05:27:4c:bc:d3:55:23:ed:cb:19:f9
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b8:cf:91:dd:b5:74:07:ba:8a:93:3c:ca:0c:11:
5d:36:29:ec:53:1e:32:8b:90:ae:f9:c0:db:d2:7e:
78:ea:3c:58:57:5f:70:4a:96:9a:93:58:d3:7e:42:
60:bd:78:07:38:6b:e4:16:8f:32:17:30:b1:76:95:
56:6d:7e:e5:9e:f9:0f:f8:5a:99:ee:80:e1:e6:fc:
d6:af:33:61:aa:da:19:98:7f:da:27:2f:80:bc:96:
2e:51:81:f8:1a:63:27:0b:ce:ee:02:16:55:4a:96:
0a:c5:c1:7e:99:95:e8:70:e7:4d:2b:2f:bf:d3:d2:
2d:25:7d:0f:b2:50:96:36:95:e5:2c:ca:0e:59:b5:
d4:7c:31:57:96:fa:be:c6:d5:9a:83:b5:96:f2:1c:
4a:20:cf:be:0e:7f:42:4f:a7:b4:5b:e2:01:f4:ed:
59:c4:6e:51:a1:a5:aa:a7:1f:04:ce:e0:d2:2c:ff:
a3:74:c7:e4:2a:a8:d2:7f:cd:f1:56:86:67:fe:75:
22:05:f7:2d:3b:3b:ce:5c:b9:95:4e:e5:ca:d8:89:
f6:b3:12:27:b4:22:6b:fb:83:f9:0e:de:a8:be:38:
5b:15:66:81:3b:62:d7:50:12:29:69:5b:c5:5a:99:
97:aa:51:c3:36:88:97:c9:c1:90:53:4f:b3:ec:99:
3c:f3
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
8A:E3:E6:F6:58:6F:1C:90:B4:67:A5:14:D8:64:E7:F7:00:77:61:01
X509v3 Authority Key Identifier:
keyid:52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
5d:ea:42:56:51:61:2a:81:f5:b3:93:03:dc:91:88:3e:7c:22:
8b:b0:13:e3:e2:b8:67:3b:ec:47:5b:d3:c6:c0:38:b1:bf:9a:
21:ac:8b:d1:73:8c:14:ec:33:8d:53:23:4a:f0:82:7f:52:9c:
05:2e:93:a3:3a:43:f1:43:03:24:2b:98:61:fd:05:03:ae:41:
32:50:c7:cf:cb:9a:a9:b0:b6:0b:7d:cc:6a:63:67:39:03:0a:
4f:b2:e9:7f:ac:8b:3b:ed:cb:22:31:8d:c3:9e:da:b2:84:e5:
2f:a7:13:08:c7:d2:3b:cd:f8:04:76:57:d0:bc:42:9b:51:e7:
90:e5:c9:8a:d1:2f:3d:14:71:fc:0c:cf:55:de:0b:02:b9:e1:
cb:7a:df:d6:e2:1d:9c:d5:a4:f8:d4:c4:5a:f3:8a:f3:1f:db:
c9:7e:eb:17:c3:d5:18:07:6e:4f:cd:4b:33:91:b9:45:a9:6a:
c1:dd:80:8c:ce:55:49:cf:5a:2a:fc:ac:48:3e:04:a7:a6:77:
96:5b:d7:30:bf:24:1c:40:93:5b:99:bb:40:c1:76:16:32:47:
5b:91:f8:e9:ae:a2:4f:81:d8:40:76:ed:ec:38:a2:ac:8e:5a:
66:35:ce:be:89:fd:c8:dc:89:fb:38:ca:48:84:a6:2c:57:11:
78:d3:69:73
-----BEGIN CERTIFICATE-----
MIIDgDCCAmigAwIBAgIUBmZRhMJ+/AzPBSdMvNNVI+3LGfkwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBALjPkd21dAe6ipM8ygwRXTYp7FMeMouQrvnA29J+eOo8WFdf
cEqWmpNY035CYL14Bzhr5BaPMhcwsXaVVm1+5Z75D/hame6A4eb81q8zYaraGZh/
2icvgLyWLlGB+BpjJwvO7gIWVUqWCsXBfpmV6HDnTSsvv9PSLSV9D7JQljaV5SzK
Dlm11HwxV5b6vsbVmoO1lvIcSiDPvg5/Qk+ntFviAfTtWcRuUaGlqqcfBM7g0iz/
o3TH5Cqo0n/N8VaGZ/51IgX3LTs7zly5lU7lytiJ9rMSJ7Qia/uD+Q7eqL44WxVm
gTti11ASKWlbxVqZl6pRwzaIl8nBkFNPs+yZPPMCAwEAAaOByzCByDAdBgNVHQ4E
FgQUiuPm9lhvHJC0Z6UU2GTn9wB3YQEwHwYDVR0jBBgwFoAUUgCkvotfI2NeMQWH
9GtQpwFwY9owNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MA0GCSqGSIb3DQEBCwUAA4IBAQBd6kJWUWEqgfWzkwPckYg+fCKLsBPj4rhnO+xH
W9PGwDixv5ohrIvRc4wU7DONUyNK8IJ/UpwFLpOjOkPxQwMkK5hh/QUDrkEyUMfP
y5qpsLYLfcxqY2c5AwpPsul/rIs77csiMY3DntqyhOUvpxMIx9I7zfgEdlfQvEKb
UeeQ5cmK0S89FHH8DM9V3gsCueHLet/W4h2c1aT41MRa84rzH9vJfusXw9UYB25P
zUszkblFqWrB3YCMzlVJz1oq/KxIPgSnpneWW9cwvyQcQJNbmbtAwXYWMkdbkfjp
rqJPgdhAdu3sOKKsjlpmNc6+if3I3In7OMpIhKYsVxF402lz
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
06:66:51:84:c2:7e:fc:0c:cf:05:27:4c:bc:d3:55:23:ed:cb:19:f8
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Mar 10 12:00:00 2018 GMT
Not After : Jan 1 12:00:00 2021 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:c0:8e:83:7c:7e:0c:6a:e8:93:2c:f8:e6:80:17:
e6:2a:91:f2:1d:1a:b1:51:6e:3e:4d:96:bd:a1:29:
f3:bd:ce:46:17:dc:5f:ed:b7:33:d8:17:31:80:b1:
12:f3:bb:86:1d:4a:a7:61:dd:51:15:a8:9d:50:25:
4f:93:5b:8c:a6:43:30:a5:46:7e:80:74:51:17:66:
61:ba:c0:9d:f5:53:e4:4d:02:58:a4:27:ac:ef:35:
eb:01:e6:0d:0f:a2:67:b3:95:1d:33:d3:70:55:6d:
73:80:dd:c7:dc:21:c6:58:9a:7d:cb:e6:9d:e2:af:
7f:14:02:7c:f8:45:ff:5c:74:7a:7d:b1:35:1f:74:
0f:e7:0d:97:51:58:15:41:07:fa:12:99:2a:84:92:
48:9b:08:ee:ad:26:37:15:3e:7e:7b:b6:1e:94:36:
be:b9:d8:b6:6f:27:71:13:d1:3e:b7:9e:9d:d6:1e:
e1:cb:7b:2b:ab:20:46:e0:08:9c:54:5b:c6:db:c2:
57:d3:67:ee:00:cf:d2:cb:0b:64:31:a7:9c:97:f5:
4b:37:db:7d:d5:dd:91:a7:ed:dc:0c:2f:9c:04:42:
50:46:8a:59:d2:9c:10:d7:0c:25:d9:79:de:e1:4c:
3d:4a:5a:3f:2c:6c:20:a1:60:9f:24:69:1a:0a:f9:
6e:79
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
X509v3 Authority Key Identifier:
keyid:52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
b1:46:a2:be:75:4e:8a:30:07:5b:fb:11:58:65:69:82:59:f5:
c9:f6:c4:96:b9:0a:f7:ab:e4:20:33:85:1e:7b:67:ca:b2:f8:
fa:ef:33:2a:4b:b9:34:d2:3a:6b:c0:b2:f2:49:7c:a9:92:c9:
67:16:de:5c:f9:71:cb:2f:24:af:41:0e:c8:9c:72:fc:c0:52:
2f:aa:ca:25:2f:39:86:b7:48:f1:bb:c0:9a:e5:0a:c6:31:46:
48:ae:e6:2b:3c:3f:82:ca:81:7d:c3:e3:7a:66:05:ac:90:86:
1d:a2:60:64:18:f0:94:90:93:f9:ae:f0:cf:9c:fd:af:59:20:
12:ae:c9:f7:cf:d4:68:eb:66:cf:24:1b:82:d6:61:ed:f5:48:
cf:88:3c:24:b4:39:b2:69:da:44:5c:92:11:13:d7:79:9d:ec:
e6:7b:79:89:cf:09:47:e9:51:5a:b9:f3:47:0e:d3:6c:65:9e:
70:1f:78:c8:ce:63:9c:aa:2f:81:04:93:3a:22:1d:a2:a2:03:
4d:96:37:1b:8f:fc:df:e8:03:79:f2:57:6f:5b:26:e2:3c:4c:
ae:ba:46:2a:2a:6b:fd:aa:d2:c9:a6:be:59:db:ef:91:60:f3:
35:e7:de:b4:bd:e3:00:f4:3f:3b:d6:a3:32:66:9b:05:8f:06:
44:da:90:36
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUBmZRhMJ+/AzPBSdMvNNVI+3LGfgwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDAjoN8fgxq6JMs+OaAF+YqkfIdGrFRbj5Nlr2hKfO9zkYX3F/ttzPYFzGA
sRLzu4YdSqdh3VEVqJ1QJU+TW4ymQzClRn6AdFEXZmG6wJ31U+RNAlikJ6zvNesB
5g0PomezlR0z03BVbXOA3cfcIcZYmn3L5p3ir38UAnz4Rf9cdHp9sTUfdA/nDZdR
WBVBB/oSmSqEkkibCO6tJjcVPn57th6UNr652LZvJ3ET0T63np3WHuHLeyurIEbg
CJxUW8bbwlfTZ+4Az9LLC2Qxp5yX9Us3233V3ZGn7dwML5wEQlBGilnSnBDXDCXZ
ed7hTD1KWj8sbCChYJ8kaRoK+W55AgMBAAGjgcswgcgwHQYDVR0OBBYEFFIApL6L
XyNjXjEFh/RrUKcBcGPaMB8GA1UdIwQYMBaAFFIApL6LXyNjXjEFh/RrUKcBcGPa
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEAsUaivnVOijAHW/sRWGVpgln1yfbElrkK96vkIDOFHntnyrL4
+u8zKku5NNI6a8Cy8kl8qZLJZxbeXPlxyy8kr0EOyJxy/MBSL6rKJS85hrdI8bvA
muUKxjFGSK7mKzw/gsqBfcPjemYFrJCGHaJgZBjwlJCT+a7wz5z9r1kgEq7J98/U
aOtmzyQbgtZh7fVIz4g8JLQ5smnaRFySERPXeZ3s5nt5ic8JR+lRWrnzRw7TbGWe
cB94yM5jnKovgQSTOiIdoqIDTZY3G4/83+gDefJXb1sm4jxMrrpGKipr/arSyaa+
WdvvkWDzNefetL3jAPQ/O9ajMmabBY8GRNqQNg==
-----END CERTIFICATE-----