| [Created by: generate-chains.py] |
| |
| Certificate chain where the intermediate lacks a basic constraints |
| extension (yet is used to issue another certificate). |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 49:69:f3:be:c4:d1:47:b6:f9:34:d0:0a:22:12:e6:60:9c:51:8b:6e |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Intermediate |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Target |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:cd:97:c5:b2:49:20:8b:97:3c:5d:b5:01:5b:8d: |
| ac:af:2a:2a:b5:cf:1a:ba:d8:1c:2d:68:12:1f:1f: |
| 10:8c:50:4d:d6:75:72:cb:62:d5:5f:ff:6b:45:44: |
| a6:76:15:31:6e:7d:0e:21:2e:53:65:57:cf:7f:24: |
| ab:2d:05:db:7e:94:e7:7b:dc:ec:02:6d:58:3b:4e: |
| db:c0:95:02:bf:c4:ad:4c:26:20:49:11:a5:d1:b7: |
| 01:e9:27:15:85:ef:19:9a:7d:b9:32:6a:f8:0e:45: |
| 8b:ee:f4:31:ad:e6:ef:bf:be:d7:ac:44:2e:11:59: |
| 15:5b:82:81:37:88:46:58:98:96:5b:b4:33:c5:c3: |
| 14:11:7a:53:fc:e9:7a:c5:dd:61:ed:01:a4:83:fe: |
| 39:66:8d:34:8d:87:09:94:78:f4:fe:0c:0e:e8:ca: |
| f1:d0:7a:d6:d0:55:1d:4b:21:31:6c:54:39:ff:1d: |
| 38:c4:58:c0:10:02:78:ab:73:36:d3:2b:09:a4:62: |
| e9:e3:32:41:02:ea:d6:99:0a:0e:01:3c:df:68:3e: |
| 58:cb:7e:c2:61:84:c9:27:37:83:0b:5c:e8:60:5e: |
| 53:64:e6:50:cf:2a:22:cd:be:57:92:72:6c:6b:47: |
| 77:ee:bb:96:48:b0:4b:1b:eb:37:b8:0f:2b:c6:97: |
| 98:b3 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| A1:B6:F2:69:1D:9D:60:3D:20:03:B7:D6:19:26:AF:97:9F:7F:56:2A |
| X509v3 Authority Key Identifier: |
| keyid:45:32:A9:37:50:F0:A0:A1:8E:02:EB:8B:34:65:28:12:3F:FB:6A:18 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Intermediate.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Intermediate.crl |
| |
| X509v3 Key Usage: critical |
| Digital Signature, Key Encipherment |
| X509v3 Extended Key Usage: |
| TLS Web Server Authentication, TLS Web Client Authentication |
| Signature Algorithm: sha256WithRSAEncryption |
| c4:cc:e8:33:37:74:6f:57:73:3f:56:84:1c:30:4f:33:f9:d9: |
| 5b:d5:e3:24:b7:a1:09:58:3f:6a:c3:26:2a:7e:a7:94:12:21: |
| e1:1f:f8:01:51:23:5e:33:8d:b7:73:e1:da:f4:7e:3e:ca:e3: |
| c8:54:dd:5d:18:7e:84:17:38:b3:9d:61:2f:99:7a:73:17:97: |
| eb:4c:0c:1e:11:ce:1c:20:6b:8f:36:16:11:73:1e:28:16:27: |
| fb:98:8f:3e:35:b2:dc:12:e9:a0:3f:9a:8c:eb:87:12:35:ee: |
| b1:10:e2:17:ae:fa:91:d6:67:05:1e:ed:10:f5:0f:57:a9:b6: |
| 79:85:65:e6:77:c0:3d:3b:86:ac:f5:0d:de:db:32:9c:7b:f1: |
| 70:29:96:9a:7a:96:ba:cf:81:bc:6e:18:90:86:1a:59:f9:ad: |
| 11:5a:16:fa:c4:79:72:f2:72:fd:66:ff:4d:9d:53:66:92:38: |
| 39:46:5a:73:c9:39:7d:e0:f7:d3:40:e4:4a:28:ca:7e:4a:c8: |
| ed:0d:1a:93:a8:b0:30:9a:90:8d:27:94:b8:31:fe:40:c1:a1: |
| ae:df:9b:66:e4:0a:3e:11:d5:af:11:2e:41:f2:94:cf:6b:1f: |
| cf:c6:0e:af:9a:0f:8a:51:d1:8b:41:86:75:8a:83:31:13:20: |
| 3e:91:72:d6 |
| -----BEGIN CERTIFICATE----- |
| MIIDoDCCAoigAwIBAgIUSWnzvsTRR7b5NNAKIhLmYJxRi24wDQYJKoZIhvcNAQEL |
| BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTE4MDMxMDEyMDAwMFoXDTIx |
| MDEwMTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF |
| AAOCAQ8AMIIBCgKCAQEAzZfFskkgi5c8XbUBW42sryoqtc8autgcLWgSHx8QjFBN |
| 1nVyy2LVX/9rRUSmdhUxbn0OIS5TZVfPfySrLQXbfpTne9zsAm1YO07bwJUCv8St |
| TCYgSRGl0bcB6ScVhe8Zmn25Mmr4DkWL7vQxrebvv77XrEQuEVkVW4KBN4hGWJiW |
| W7QzxcMUEXpT/Ol6xd1h7QGkg/45Zo00jYcJlHj0/gwO6Mrx0HrW0FUdSyExbFQ5 |
| /x04xFjAEAJ4q3M20ysJpGLp4zJBAurWmQoOATzfaD5Yy37CYYTJJzeDC1zoYF5T |
| ZOZQzyoizb5XknJsa0d37ruWSLBLG+s3uA8rxpeYswIDAQABo4HpMIHmMB0GA1Ud |
| DgQWBBShtvJpHZ1gPSADt9YZJq+Xn39WKjAfBgNVHSMEGDAWgBRFMqk3UPCgoY4C |
| 64s0ZSgSP/tqGDA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 |
| cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 |
| dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF |
| oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZIhvcNAQELBQAD |
| ggEBAMTM6DM3dG9Xcz9WhBwwTzP52VvV4yS3oQlYP2rDJip+p5QSIeEf+AFRI14z |
| jbdz4dr0fj7K48hU3V0YfoQXOLOdYS+ZenMXl+tMDB4Rzhwga482FhFzHigWJ/uY |
| jz41stwS6aA/mozrhxI17rEQ4heu+pHWZwUe7RD1D1eptnmFZeZ3wD07hqz1Dd7b |
| Mpx78XAplpp6lrrPgbxuGJCGGln5rRFaFvrEeXLycv1m/02dU2aSODlGWnPJOX3g |
| 99NA5Eooyn5KyO0NGpOosDCakI0nlLgx/kDBoa7fm2bkCj4R1a8RLkHylM9rH8/G |
| Dq+aD4pR0YtBhnWKgzETID6RctY= |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 7c:71:83:7d:9a:71:3e:fb:f4:b1:79:2c:b6:6c:11:29:14:74:0b:74 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Intermediate |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:d4:d2:58:5a:24:b9:9d:c4:07:62:ed:0a:24:09: |
| 46:d4:97:a8:e1:e6:fa:c2:8d:ba:31:da:ea:95:6f: |
| ca:79:cc:10:08:cd:8e:5d:33:eb:04:40:94:7a:15: |
| 94:71:fe:50:73:ea:a0:41:e6:bf:93:aa:7f:60:c2: |
| e6:55:1a:24:ce:b5:f9:5f:ad:f7:90:b5:49:1c:30: |
| 45:ad:ed:12:d3:b0:9d:de:03:33:01:a6:c0:12:4e: |
| 96:13:d7:9f:b0:69:67:b9:cf:d5:a9:ce:9d:7c:4e: |
| 5f:0d:7b:d1:a4:65:93:12:22:42:e8:02:9f:18:0b: |
| 03:af:1f:3c:b1:e0:ac:a7:a7:87:b1:22:c1:c9:fe: |
| 1d:81:13:dd:e7:d9:21:68:86:6a:06:13:82:73:e5: |
| 78:78:e0:99:76:75:38:68:73:cb:8b:33:25:53:72: |
| d1:58:f0:40:64:36:03:32:1d:72:c3:8c:ef:de:76: |
| 07:df:9a:b7:b9:4c:10:94:fb:c8:7b:69:ba:d3:a9: |
| 1a:21:8c:f7:c5:b3:b1:1b:72:44:10:8c:dd:c3:76: |
| 36:e5:ce:a8:a0:29:1b:fa:47:0c:e3:89:f2:44:84: |
| cc:88:0f:48:09:c9:0e:1e:a9:ee:a7:55:ba:5a:6f: |
| 78:66:d8:bd:4d:9c:d5:52:95:83:b1:80:b5:af:ce: |
| f5:73 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| 45:32:A9:37:50:F0:A0:A1:8E:02:EB:8B:34:65:28:12:3F:FB:6A:18 |
| X509v3 Authority Key Identifier: |
| keyid:E5:37:1E:E2:93:2C:94:BA:7F:8B:6E:2F:75:D5:0D:D8:0A:D2:96:12 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| Signature Algorithm: sha256WithRSAEncryption |
| 5f:a1:16:28:be:28:96:31:37:b5:4f:9b:76:6d:71:2a:9c:f7: |
| a4:63:67:b4:2d:1e:59:8c:c5:27:8c:6b:13:dc:35:fb:bf:9f: |
| 2f:14:15:6b:a3:31:89:12:b2:3f:6d:3c:d9:69:4a:84:e2:58: |
| 42:bb:3e:3f:52:c7:6b:9b:90:87:64:bc:74:5c:10:35:05:88: |
| 42:24:71:76:ce:48:e8:40:a1:87:8d:28:52:d5:10:f6:ad:39: |
| 08:50:36:74:eb:18:08:bc:ab:9e:06:d1:58:fb:ab:99:c2:59: |
| 69:1c:b4:03:10:d7:94:d1:4f:d9:df:b4:2b:61:b3:d6:f8:47: |
| f1:94:fe:67:3e:73:d6:41:d7:9e:d5:70:02:7d:09:a6:cc:56: |
| a0:ba:f6:6e:7f:45:68:91:1f:95:61:01:82:31:ff:cd:f0:a4: |
| 1d:3e:ca:84:d8:d0:e9:fd:47:f5:b8:6f:c5:c2:1b:4b:d5:1c: |
| 29:65:9b:fe:12:97:0f:b4:a5:0b:7d:e0:40:d8:93:33:50:40: |
| 16:d4:e2:9c:8d:f6:90:de:6e:90:33:89:09:e0:5e:4c:f1:15: |
| bc:8c:89:73:23:6d:da:88:50:06:41:b7:38:e0:d9:3b:16:6e: |
| 42:7a:ba:41:a7:04:43:40:4c:52:0e:e9:56:23:b4:e4:ef:d7: |
| 92:a5:f0:5c |
| -----BEGIN CERTIFICATE----- |
| MIIDbzCCAlegAwIBAgIUfHGDfZpxPvv0sXkstmwRKRR0C3QwDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD |
| ggEPADCCAQoCggEBANTSWFokuZ3EB2LtCiQJRtSXqOHm+sKNujHa6pVvynnMEAjN |
| jl0z6wRAlHoVlHH+UHPqoEHmv5Oqf2DC5lUaJM61+V+t95C1SRwwRa3tEtOwnd4D |
| MwGmwBJOlhPXn7BpZ7nP1anOnXxOXw170aRlkxIiQugCnxgLA68fPLHgrKenh7Ei |
| wcn+HYET3efZIWiGagYTgnPleHjgmXZ1OGhzy4szJVNy0VjwQGQ2AzIdcsOM7952 |
| B9+at7lMEJT7yHtputOpGiGM98WzsRtyRBCM3cN2NuXOqKApG/pHDOOJ8kSEzIgP |
| SAnJDh6p7qdVulpveGbYvU2c1VKVg7GAta/O9XMCAwEAAaOBujCBtzAdBgNVHQ4E |
| FgQURTKpN1DwoKGOAuuLNGUoEj/7ahgwHwYDVR0jBBgwFoAU5Tce4pMslLp/i24v |
| ddUN2ArSlhIwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs |
| LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m |
| b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOC |
| AQEAX6EWKL4oljE3tU+bdm1xKpz3pGNntC0eWYzFJ4xrE9w1+7+fLxQVa6MxiRKy |
| P2082WlKhOJYQrs+P1LHa5uQh2S8dFwQNQWIQiRxds5I6EChh40oUtUQ9q05CFA2 |
| dOsYCLyrngbRWPurmcJZaRy0AxDXlNFP2d+0K2Gz1vhH8ZT+Zz5z1kHXntVwAn0J |
| psxWoLr2bn9FaJEflWEBgjH/zfCkHT7KhNjQ6f1H9bhvxcIbS9UcKWWb/hKXD7Sl |
| C33gQNiTM1BAFtTinI32kN5ukDOJCeBeTPEVvIyJcyNt2ohQBkG3OODZOxZuQnq6 |
| QacEQ0BMUg7pViO05O/XkqXwXA== |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 7c:71:83:7d:9a:71:3e:fb:f4:b1:79:2c:b6:6c:11:29:14:74:0b:73 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Mar 10 12:00:00 2018 GMT |
| Not After : Jan 1 12:00:00 2021 GMT |
| Subject: CN=Root |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:a9:f3:a8:48:50:46:fe:b1:fa:ee:af:1a:5c:c1: |
| f2:d0:e1:f9:d1:b4:8e:82:c7:91:d2:eb:1e:06:ba: |
| 27:e5:3e:d5:ae:c7:1c:3f:a6:b9:48:05:c4:90:57: |
| 23:ab:2a:01:cd:ca:7f:df:8c:b6:2e:6f:83:88:e9: |
| 8e:f3:b0:e8:97:9a:91:cd:ad:d0:ef:fb:4b:d7:61: |
| bd:f1:5d:00:97:70:5b:95:1e:6d:3c:a7:03:2b:ec: |
| 29:cc:b6:ed:b1:e2:9a:db:38:ce:73:02:19:3f:20: |
| 03:70:cd:88:29:f9:ad:40:f7:16:0b:b4:93:9b:ac: |
| 13:da:bb:39:e9:2f:2f:17:39:1a:27:47:75:cd:0a: |
| 81:a2:e5:a8:58:e7:08:15:a3:33:86:0e:b9:ba:90: |
| 23:3b:2a:2a:ed:04:d7:80:85:51:d8:dd:ba:d0:96: |
| 34:ef:8c:21:19:ce:cd:0a:9e:fc:ab:3d:ed:69:d1: |
| 4b:d2:2b:1f:77:5c:74:96:d7:25:ce:02:e0:49:ed: |
| 18:ee:c4:37:d1:e5:f5:a2:5c:ae:c9:fe:2b:cd:68: |
| a6:a5:31:9a:76:5e:a2:10:be:aa:14:ca:57:c3:31: |
| ac:92:bd:9b:53:df:69:8f:e2:26:85:36:20:27:f5: |
| 60:fb:66:6d:9b:a7:ec:f8:e4:1a:df:a2:38:ee:ef: |
| 3c:d1 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| E5:37:1E:E2:93:2C:94:BA:7F:8B:6E:2F:75:D5:0D:D8:0A:D2:96:12 |
| X509v3 Authority Key Identifier: |
| keyid:E5:37:1E:E2:93:2C:94:BA:7F:8B:6E:2F:75:D5:0D:D8:0A:D2:96:12 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| Signature Algorithm: sha256WithRSAEncryption |
| 1c:4f:b6:7d:05:1e:a9:94:32:36:2a:d8:21:f2:38:48:12:d1: |
| 5e:ee:10:67:54:7f:97:e7:9d:b1:95:dd:f1:5e:5c:29:42:58: |
| 76:b2:c9:6a:5e:e5:7f:a6:e4:e9:52:47:72:f8:cf:31:a3:d4: |
| bb:ff:1b:03:23:3f:4f:b0:fa:a0:2a:37:a8:de:be:29:4d:c0: |
| d3:db:2c:78:da:08:53:af:b1:8f:df:54:92:47:7b:ca:04:2c: |
| 93:74:30:b7:6b:6a:9c:b2:e4:24:67:df:c4:cf:7f:70:a4:dc: |
| 21:7d:1b:34:95:7e:9e:93:03:b1:1a:4c:3e:4b:09:d2:77:e8: |
| 52:63:57:40:ad:08:6d:0e:1f:27:d0:29:1e:dc:65:29:3f:8c: |
| f9:f4:77:02:c5:6b:a5:10:e6:59:d0:dd:46:46:76:b6:05:bd: |
| d0:e9:69:7d:24:84:c9:92:ca:88:c2:5d:5c:0b:92:53:0a:ee: |
| c9:5b:0a:83:04:0a:69:02:98:ec:3e:b2:23:8a:2e:b1:02:e2: |
| 92:d2:fc:4c:a5:77:9e:2e:65:bc:2e:d5:3d:81:dc:d3:9f:2c: |
| a4:23:93:4b:fc:08:24:a8:92:12:ab:22:b8:0e:bd:10:4e:7e: |
| 68:f1:64:45:ec:f6:cd:83:83:31:d7:54:59:0a:0a:19:c3:54: |
| a5:95:b7:1a |
| -----BEGIN CERTIFICATE----- |
| MIIDeDCCAmCgAwIBAgIUfHGDfZpxPvv0sXkstmwRKRR0C3MwDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0xODAzMTAxMjAwMDBaFw0yMTAxMDExMjAw |
| MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK |
| AoIBAQCp86hIUEb+sfrurxpcwfLQ4fnRtI6Cx5HS6x4GuiflPtWuxxw/prlIBcSQ |
| VyOrKgHNyn/fjLYub4OI6Y7zsOiXmpHNrdDv+0vXYb3xXQCXcFuVHm08pwMr7CnM |
| tu2x4prbOM5zAhk/IANwzYgp+a1A9xYLtJObrBPauznpLy8XORonR3XNCoGi5ahY |
| 5wgVozOGDrm6kCM7KirtBNeAhVHY3brQljTvjCEZzs0KnvyrPe1p0UvSKx93XHSW |
| 1yXOAuBJ7RjuxDfR5fWiXK7J/ivNaKalMZp2XqIQvqoUylfDMaySvZtT32mP4iaF |
| NiAn9WD7Zm2bp+z45Brfojju7zzRAgMBAAGjgcswgcgwHQYDVR0OBBYEFOU3HuKT |
| LJS6f4tuL3XVDdgK0pYSMB8GA1UdIwQYMBaAFOU3HuKTLJS6f4tuL3XVDdgK0pYS |
| MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh |
| L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S |
| b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG |
| 9w0BAQsFAAOCAQEAHE+2fQUeqZQyNirYIfI4SBLRXu4QZ1R/l+edsZXd8V5cKUJY |
| drLJal7lf6bk6VJHcvjPMaPUu/8bAyM/T7D6oCo3qN6+KU3A09sseNoIU6+xj99U |
| kkd7ygQsk3Qwt2tqnLLkJGffxM9/cKTcIX0bNJV+npMDsRpMPksJ0nfoUmNXQK0I |
| bQ4fJ9ApHtxlKT+M+fR3AsVrpRDmWdDdRkZ2tgW90OlpfSSEyZLKiMJdXAuSUwru |
| yVsKgwQKaQKY7D6yI4ousQLiktL8TKV3ni5lvC7VPYHc058spCOTS/wIJKiSEqsi |
| uA69EE5+aPFkRez2zYODMddUWQoKGcNUpZW3Gg== |
| -----END CERTIFICATE----- |