1[Created by: generate_policies_tests.py] 2 3Cast certificate chain with the following policies: 4 5 Root: policies={} 6 Intermediate: policies={anyPolicy} 7 Leaf: policies={anyPolicy} 8 9Certificate: 10 Data: 11 Version: 3 (0x2) 12 Serial Number: 11 (0xb) 13 Signature Algorithm: sha256WithRSAEncryption 14 Issuer: CN=Intermediate 15 Validity 16 Not Before: Jan 1 12:00:00 2015 GMT 17 Not After : Jan 1 12:00:00 2018 GMT 18 Subject: CN=Leaf 19 Subject Public Key Info: 20 Public Key Algorithm: rsaEncryption 21 Public-Key: (2048 bit) 22 Modulus: 23 00:bc:42:b8:af:d7:ce:53:49:1d:f9:fd:41:b0:ce: 24 40:7a:c1:5d:79:db:a8:9d:6b:7b:f9:ef:8d:b8:f4: 25 22:e3:80:f9:5c:67:e1:91:a0:66:c2:d7:07:0a:ef: 26 ed:86:ab:c0:9e:d0:b1:95:cf:83:9b:ce:7b:0c:75: 27 05:8c:2f:44:e4:2f:ba:d8:17:04:ec:37:a2:6f:20: 28 66:d9:09:a9:20:e2:43:d8:d4:77:26:82:ec:a7:ca: 29 48:2b:19:73:73:fd:4b:d4:a6:38:e3:ea:6e:d7:02: 30 cd:18:e6:bd:c2:c6:9a:bf:ec:1f:ce:b0:e9:03:eb: 31 03:65:cd:e2:46:ad:a3:c1:4d:23:b3:d1:b1:52:e2: 32 5d:56:dc:bd:21:35:17:4b:65:e9:3b:e8:9a:f5:7b: 33 30:74:3f:da:e7:5a:8b:4e:74:53:56:db:f2:15:f6: 34 7d:bb:20:f0:fd:e5:bb:8b:a3:7d:10:f3:f2:d1:76: 35 d6:99:fc:0b:29:cb:bc:ec:dd:ed:85:54:01:a2:07: 36 96:ce:7e:24:ee:1b:12:2e:e0:65:8f:3d:de:e2:75: 37 64:a1:2f:1c:43:dd:d1:e9:6f:80:58:b0:11:d6:8a: 38 76:48:b5:60:38:7e:c0:52:7a:4a:6d:7d:b4:c2:4b: 39 d8:d2:f8:27:8a:88:54:f2:05:a0:65:12:ff:26:27: 40 bc:bb 41 Exponent: 65537 (0x10001) 42 X509v3 extensions: 43 X509v3 Subject Key Identifier: 44 63:5A:64:7F:7A:5B:13:1C:41:A8:00:23:5D:9E:D5:4E:86:22:FC:56 45 X509v3 Authority Key Identifier: 46 keyid:29:2B:35:96:F9:DF:46:CD:68:36:D9:20:F1:95:F7:40:FB:C6:58:33 47 48 Authority Information Access: 49 CA Issuers - URI:http://url-for-aia/Intermediate.cer 50 51 X509v3 CRL Distribution Points: 52 53 Full Name: 54 URI:http://url-for-crl/Intermediate.crl 55 56 X509v3 Key Usage: critical 57 Digital Signature, Key Encipherment 58 X509v3 Extended Key Usage: 59 TLS Web Client Authentication 60 X509v3 Certificate Policies: 61 Policy: X509v3 Any Policy 62 63 Signature Algorithm: sha256WithRSAEncryption 64 0c:f9:f7:0f:75:d6:67:f3:5b:a1:3a:3a:20:8b:d3:3a:f6:14: 65 f8:ac:89:22:2e:36:03:d3:7f:3f:bc:19:9f:2d:b7:c4:c9:99: 66 3d:85:10:a7:ca:d6:d5:97:56:8d:56:f1:98:d8:43:29:b2:87: 67 3c:6d:6f:52:00:8c:1d:3a:04:2b:f5:7b:75:40:7c:01:79:22: 68 00:10:48:a4:27:b6:30:b9:29:2b:14:de:cc:bf:f4:1e:cc:8c: 69 7f:6e:97:18:cf:03:f6:5d:ea:d1:47:2c:e8:78:73:31:e8:48: 70 c8:54:76:f6:b1:5b:a2:70:7e:8f:7f:12:2d:fa:2f:fd:d8:97: 71 34:90:fb:d4:2a:d3:3c:65:cc:25:1b:b0:d9:b9:8e:2e:e2:9a: 72 31:ce:4e:2f:df:7e:ee:0e:da:a0:3b:cd:12:8a:0d:6b:e0:10: 73 81:25:8e:25:25:a0:91:7a:e2:a5:ee:aa:d1:8f:cf:03:ca:d5: 74 45:1d:a2:14:67:7d:ac:cb:d9:1d:0a:af:e0:e9:b6:e9:53:27: 75 b7:63:bf:59:00:fb:8d:bc:17:00:fb:92:74:30:9c:f8:86:bf: 76 2f:94:73:32:af:95:a7:12:96:bf:37:6a:d7:9d:87:1e:17:27: 77 41:a7:6a:bc:9b:fa:ae:12:b3:ec:96:3c:5e:62:80:4f:3c:e7: 78 9f:a4:0a:ed 79-----BEGIN CERTIFICATE----- 80MIIDlDCCAnygAwIBAgIBCzANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl 81cm1lZGlhdGUwHhcNMTUwMTAxMTIwMDAwWhcNMTgwMTAxMTIwMDAwWjAPMQ0wCwYD 82VQQDDARMZWFmMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvEK4r9fO 83U0kd+f1BsM5AesFdeduonWt7+e+NuPQi44D5XGfhkaBmwtcHCu/thqvAntCxlc+D 84m857DHUFjC9E5C+62BcE7DeibyBm2QmpIOJD2NR3JoLsp8pIKxlzc/1L1KY44+pu 851wLNGOa9wsaav+wfzrDpA+sDZc3iRq2jwU0js9GxUuJdVty9ITUXS2XpO+ia9Xsw 86dD/a51qLTnRTVtvyFfZ9uyDw/eW7i6N9EPPy0XbWmfwLKcu87N3thVQBogeWzn4k 877hsSLuBljz3e4nVkoS8cQ93R6W+AWLAR1op2SLVgOH7AUnpKbX20wkvY0vgniohU 888gWgZRL/Jie8uwIDAQABo4HyMIHvMB0GA1UdDgQWBBRjWmR/elsTHEGoACNdntVO 89hiL8VjAfBgNVHSMEGDAWgBQpKzWW+d9GzWg22SDxlfdA+8ZYMzA/BggrBgEFBQcB 90AQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91cmwtZm9yLWFpYS9JbnRlcm1lZGlh 91dGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly91cmwtZm9yLWNybC9JbnRl 92cm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcD 93AjARBgNVHSAECjAIMAYGBFUdIAAwDQYJKoZIhvcNAQELBQADggEBAAz59w911mfz 94W6E6OiCL0zr2FPisiSIuNgPTfz+8GZ8tt8TJmT2FEKfK1tWXVo1W8ZjYQymyhzxt 95b1IAjB06BCv1e3VAfAF5IgAQSKQntjC5KSsU3sy/9B7MjH9ulxjPA/Zd6tFHLOh4 96czHoSMhUdvaxW6Jwfo9/Ei36L/3YlzSQ+9Qq0zxlzCUbsNm5ji7imjHOTi/ffu4O 972qA7zRKKDWvgEIEljiUloJF64qXuqtGPzwPK1UUdohRnfazL2R0Kr+DptulTJ7dj 98v1kA+428FwD7knQwnPiGvy+UczKvlacSlr83atedhx4XJ0Gnaryb+q4Ss+yWPF5i 99gE8855+kCu0= 100-----END CERTIFICATE----- 101 102Certificate: 103 Data: 104 Version: 3 (0x2) 105 Serial Number: 22 (0x16) 106 Signature Algorithm: sha256WithRSAEncryption 107 Issuer: CN=Root 108 Validity 109 Not Before: Jan 1 12:00:00 2015 GMT 110 Not After : Jan 1 12:00:00 2018 GMT 111 Subject: CN=Intermediate 112 Subject Public Key Info: 113 Public Key Algorithm: rsaEncryption 114 Public-Key: (2048 bit) 115 Modulus: 116 00:cc:f0:0a:27:5e:f1:ca:c1:d3:fd:33:14:dc:25: 117 7a:49:89:89:c5:67:fd:e4:56:aa:2b:1b:40:80:84: 118 b8:48:7e:ed:66:4c:23:82:99:5b:86:db:fc:82:35: 119 b3:56:01:bf:01:14:f6:46:5d:c7:96:5d:55:a7:a7: 120 e7:5c:8d:a7:c9:e9:a2:20:e4:ad:4c:8c:fe:2e:17: 121 59:56:8d:ed:7c:97:68:5a:0d:dd:b1:41:b7:24:44: 122 bc:77:84:f1:af:fe:87:1c:83:c7:10:72:8a:44:62: 123 99:a0:5c:78:f0:28:73:bf:2c:de:d1:8e:69:01:b6: 124 5a:39:20:2c:d9:fe:11:5f:09:27:5d:ff:2a:98:9a: 125 a8:6b:6a:e4:40:27:0d:b7:a7:2d:85:fa:7d:7a:08: 126 d4:bb:9f:ff:27:e8:3a:d4:f5:15:a0:40:4f:c1:11: 127 13:26:d7:1b:39:96:12:b7:19:aa:73:5c:4c:f7:ea: 128 d0:95:4d:14:a4:aa:73:63:58:8f:fe:e0:5a:83:31: 129 7f:34:aa:02:e1:d9:6c:ed:84:7b:7f:ec:6b:7e:d9: 130 3f:65:98:87:28:18:d5:aa:0f:d5:2f:ec:1a:86:19: 131 ed:3c:c6:a1:10:4a:fd:ac:60:6a:7a:ff:6a:66:c4: 132 99:49:67:7c:3f:37:32:eb:80:48:e5:0b:6a:1d:3d: 133 6a:47 134 Exponent: 65537 (0x10001) 135 X509v3 extensions: 136 X509v3 Subject Key Identifier: 137 29:2B:35:96:F9:DF:46:CD:68:36:D9:20:F1:95:F7:40:FB:C6:58:33 138 X509v3 Authority Key Identifier: 139 keyid:FF:6B:55:E3:48:07:3A:7D:A5:37:EE:4C:93:43:81:21:0E:CD:5F:D0 140 141 Authority Information Access: 142 CA Issuers - URI:http://url-for-aia/Root.cer 143 144 X509v3 CRL Distribution Points: 145 146 Full Name: 147 URI:http://url-for-crl/Root.crl 148 149 X509v3 Key Usage: critical 150 Certificate Sign, CRL Sign 151 X509v3 Basic Constraints: critical 152 CA:TRUE 153 X509v3 Certificate Policies: 154 Policy: X509v3 Any Policy 155 156 Signature Algorithm: sha256WithRSAEncryption 157 1a:0b:d3:2f:32:36:12:5e:be:00:85:07:03:11:d9:af:0e:54: 158 fe:c6:02:a0:f3:40:e3:4e:7d:52:b3:8b:24:75:c9:9e:de:0c: 159 a3:30:6e:8d:1f:e4:ea:cc:97:96:5e:b3:ad:78:34:99:05:d1: 160 69:99:09:fd:e3:3a:0c:ab:df:d0:7b:61:9d:af:da:71:96:8d: 161 6d:26:da:16:bd:54:f8:e9:12:7e:e6:1b:f6:d2:d3:69:a4:ba: 162 1f:4f:5c:8c:66:d7:2f:42:79:51:98:6e:55:4c:da:2a:d2:7d: 163 48:22:bc:33:65:d1:87:6b:df:f9:c7:7a:55:db:70:25:4f:14: 164 ef:15:07:aa:93:41:99:2c:f7:37:8f:e5:0f:73:41:05:18:d5: 165 f0:8a:e7:3e:4f:89:fa:a5:4d:86:16:12:63:6c:11:95:d0:a6: 166 81:d2:63:68:51:0a:ae:8b:2c:17:24:32:3a:44:57:fc:a8:0f: 167 d3:5f:95:ca:24:6e:ee:03:85:54:95:3d:42:4a:b0:ed:7e:4e: 168 d5:2c:e7:e0:73:90:72:aa:6b:b6:2a:9a:65:6b:ce:c1:1d:1e: 169 46:d0:a9:f5:7a:83:89:41:3c:e4:19:8b:b7:2a:93:23:d7:fb: 170 c5:a5:3f:4e:8d:7b:ec:d2:4f:b9:a9:4d:2b:f9:b5:7b:bb:a2: 171 66:51:a2:56 172-----BEGIN CERTIFICATE----- 173MIIDgDCCAmigAwIBAgIBFjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 174MB4XDTE1MDEwMTEyMDAwMFoXDTE4MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 175ZXJtZWRpYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzPAKJ17x 176ysHT/TMU3CV6SYmJxWf95FaqKxtAgIS4SH7tZkwjgplbhtv8gjWzVgG/ART2Rl3H 177ll1Vp6fnXI2nyemiIOStTIz+LhdZVo3tfJdoWg3dsUG3JES8d4Txr/6HHIPHEHKK 178RGKZoFx48Chzvyze0Y5pAbZaOSAs2f4RXwknXf8qmJqoa2rkQCcNt6cthfp9egjU 179u5//J+g61PUVoEBPwRETJtcbOZYStxmqc1xM9+rQlU0UpKpzY1iP/uBagzF/NKoC 1804dls7YR7f+xrftk/ZZiHKBjVqg/VL+wahhntPMahEEr9rGBqev9qZsSZSWd8Pzcy 18164BI5QtqHT1qRwIDAQABo4HeMIHbMB0GA1UdDgQWBBQpKzWW+d9GzWg22SDxlfdA 182+8ZYMzAfBgNVHSMEGDAWgBT/a1XjSAc6faU37kyTQ4EhDs1f0DA3BggrBgEFBQcB 183AQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwtZm9yLWFpYS9Sb290LmNlcjAs 184BgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZvci1jcmwvUm9vdC5jcmwwDgYD 185VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wEQYDVR0gBAowCDAGBgRVHSAA 186MA0GCSqGSIb3DQEBCwUAA4IBAQAaC9MvMjYSXr4AhQcDEdmvDlT+xgKg80DjTn1S 187s4skdcme3gyjMG6NH+TqzJeWXrOteDSZBdFpmQn94zoMq9/Qe2Gdr9pxlo1tJtoW 188vVT46RJ+5hv20tNppLofT1yMZtcvQnlRmG5VTNoq0n1IIrwzZdGHa9/5x3pV23Al 189TxTvFQeqk0GZLPc3j+UPc0EFGNXwiuc+T4n6pU2GFhJjbBGV0KaB0mNoUQquiywX 190JDI6RFf8qA/TX5XKJG7uA4VUlT1CSrDtfk7VLOfgc5Byqmu2Kppla87BHR5G0Kn1 191eoOJQTzkGYu3KpMj1/vFpT9OjXvs0k+5qU0r+bV7u6JmUaJW 192-----END CERTIFICATE----- 193 194Certificate: 195 Data: 196 Version: 3 (0x2) 197 Serial Number: 21 (0x15) 198 Signature Algorithm: sha256WithRSAEncryption 199 Issuer: CN=Root 200 Validity 201 Not Before: Jan 1 12:00:00 2015 GMT 202 Not After : Jan 1 12:00:00 2018 GMT 203 Subject: CN=Root 204 Subject Public Key Info: 205 Public Key Algorithm: rsaEncryption 206 Public-Key: (2048 bit) 207 Modulus: 208 00:be:a1:75:40:5a:14:73:94:76:9e:7d:38:ff:ed: 209 a8:db:dc:94:ad:5e:90:c1:fa:4f:c6:8f:5c:0d:17: 210 fd:08:d4:34:2d:4a:1d:b7:a3:bc:88:ae:f0:fc:7a: 211 bb:ea:fe:c8:e6:4f:5b:64:bc:0c:f8:64:01:cc:ae: 212 82:68:69:d5:b0:fb:a5:31:01:ba:5d:f9:6d:85:c2: 213 b1:c9:da:1c:84:01:24:dc:bb:de:52:54:f2:a2:a4: 214 0e:25:d8:c1:07:7f:e9:80:1a:1f:f8:7e:6b:d0:1f: 215 c3:6d:1e:69:0e:eb:dc:07:ad:e4:92:d8:34:7d:11: 216 19:27:ea:e1:ef:54:92:ae:2d:34:8e:80:06:84:2e: 217 3e:b3:63:06:63:c2:db:88:7b:2a:f2:67:63:e3:d3: 218 31:cb:4a:05:6f:c3:85:8c:00:4a:c1:1a:0b:cb:c4: 219 90:fa:db:1d:97:b2:33:5a:86:b4:81:9b:48:f1:ca: 220 59:88:cf:c7:05:fd:18:75:a9:c3:7f:20:7a:aa:25: 221 ec:a4:db:1f:ea:76:b2:f7:a5:2d:57:90:ab:e7:de: 222 fe:d1:d7:71:8e:2b:46:64:7c:e3:8c:ab:88:84:7d: 223 64:3e:39:0f:8a:ab:99:7d:5a:63:08:1d:28:49:45: 224 6e:99:4f:f6:b9:86:bb:d1:46:6c:97:ec:36:29:5a: 225 bc:15 226 Exponent: 65537 (0x10001) 227 X509v3 extensions: 228 X509v3 Subject Key Identifier: 229 FF:6B:55:E3:48:07:3A:7D:A5:37:EE:4C:93:43:81:21:0E:CD:5F:D0 230 X509v3 Authority Key Identifier: 231 keyid:FF:6B:55:E3:48:07:3A:7D:A5:37:EE:4C:93:43:81:21:0E:CD:5F:D0 232 233 Authority Information Access: 234 CA Issuers - URI:http://url-for-aia/Root.cer 235 236 X509v3 CRL Distribution Points: 237 238 Full Name: 239 URI:http://url-for-crl/Root.crl 240 241 X509v3 Key Usage: critical 242 Certificate Sign, CRL Sign 243 X509v3 Basic Constraints: critical 244 CA:TRUE 245 Signature Algorithm: sha256WithRSAEncryption 246 34:45:fc:7c:c8:38:e2:42:87:f6:de:f2:07:ad:9a:94:ce:af: 247 e7:09:2e:05:68:4f:25:01:1b:ae:0c:c9:55:21:42:55:02:42: 248 02:83:af:cf:72:44:96:28:e9:43:e2:bc:53:38:67:f9:20:44: 249 13:76:20:23:a5:3d:a1:8a:6d:bc:33:25:26:24:6f:ca:58:c6: 250 26:ac:ad:cb:69:79:44:3d:01:fb:2f:6f:23:47:da:89:af:0b: 251 22:1e:06:27:ea:08:b5:11:38:59:9d:87:19:b2:51:3c:22:ec: 252 c2:b1:e3:f4:6c:65:4a:ff:0d:a7:23:40:e7:d8:f3:3b:75:a1: 253 36:bb:e0:aa:88:5d:14:cd:a5:6e:47:4b:09:e7:fb:12:d4:4e: 254 31:e2:ff:58:ed:bd:06:2e:c2:27:8f:1e:bb:14:24:cf:23:9a: 255 63:97:f7:c4:0b:98:98:2c:c4:58:a1:00:d1:32:74:7f:17:4f: 256 f5:bd:93:c2:4a:db:06:d3:91:16:4a:1b:72:c2:80:3a:e3:8b: 257 ca:8f:d7:49:1c:7b:76:6d:42:cb:97:af:fa:36:74:b1:5f:0a: 258 0a:3a:c5:bd:6d:d7:2c:8a:d1:c8:cf:c2:b1:89:ed:0d:9a:6d: 259 a1:e8:d1:3b:1c:67:1b:26:10:3f:93:d2:1f:87:a4:69:1f:77: 260 40:08:74:eb 261-----BEGIN CERTIFICATE----- 262MIIDZTCCAk2gAwIBAgIBFTANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 263MB4XDTE1MDEwMTEyMDAwMFoXDTE4MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v 264dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL6hdUBaFHOUdp59OP/t 265qNvclK1ekMH6T8aPXA0X/QjUNC1KHbejvIiu8Px6u+r+yOZPW2S8DPhkAcyugmhp 2661bD7pTEBul35bYXCscnaHIQBJNy73lJU8qKkDiXYwQd/6YAaH/h+a9Afw20eaQ7r 2673Aet5JLYNH0RGSfq4e9Ukq4tNI6ABoQuPrNjBmPC24h7KvJnY+PTMctKBW/DhYwA 268SsEaC8vEkPrbHZeyM1qGtIGbSPHKWYjPxwX9GHWpw38geqol7KTbH+p2svelLVeQ 269q+fe/tHXcY4rRmR844yriIR9ZD45D4qrmX1aYwgdKElFbplP9rmGu9FGbJfsNila 270vBUCAwEAAaOByzCByDAdBgNVHQ4EFgQU/2tV40gHOn2lN+5Mk0OBIQ7NX9AwHwYD 271VR0jBBgwFoAU/2tV40gHOn2lN+5Mk0OBIQ7NX9AwNwYIKwYBBQUHAQEEKzApMCcG 272CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw 273IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE 274AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQA0Rfx8yDji 275Qof23vIHrZqUzq/nCS4FaE8lARuuDMlVIUJVAkICg6/PckSWKOlD4rxTOGf5IEQT 276diAjpT2him28MyUmJG/KWMYmrK3LaXlEPQH7L28jR9qJrwsiHgYn6gi1EThZnYcZ 277slE8IuzCseP0bGVK/w2nI0Dn2PM7daE2u+CqiF0UzaVuR0sJ5/sS1E4x4v9Y7b0G 278LsInjx67FCTPI5pjl/fEC5iYLMRYoQDRMnR/F0/1vZPCStsG05EWShtywoA644vK 279j9dJHHt2bULLl6/6NnSxXwoKOsW9bdcsitHIz8Kxie0Nmm2h6NE7HGcbJhA/k9If 280h6RpH3dACHTr 281-----END CERTIFICATE----- 282