[Created by: generate-chains.py] Certificate chain where the intermediate lacks a basic constraints extension (yet is used to issue another certificate). Certificate: Data: Version: 3 (0x2) Serial Number: 49:69:f3:be:c4:d1:47:b6:f9:34:d0:0a:22:12:e6:60:9c:51:8b:6e Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Intermediate Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Target Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:cd:97:c5:b2:49:20:8b:97:3c:5d:b5:01:5b:8d: ac:af:2a:2a:b5:cf:1a:ba:d8:1c:2d:68:12:1f:1f: 10:8c:50:4d:d6:75:72:cb:62:d5:5f:ff:6b:45:44: a6:76:15:31:6e:7d:0e:21:2e:53:65:57:cf:7f:24: ab:2d:05:db:7e:94:e7:7b:dc:ec:02:6d:58:3b:4e: db:c0:95:02:bf:c4:ad:4c:26:20:49:11:a5:d1:b7: 01:e9:27:15:85:ef:19:9a:7d:b9:32:6a:f8:0e:45: 8b:ee:f4:31:ad:e6:ef:bf:be:d7:ac:44:2e:11:59: 15:5b:82:81:37:88:46:58:98:96:5b:b4:33:c5:c3: 14:11:7a:53:fc:e9:7a:c5:dd:61:ed:01:a4:83:fe: 39:66:8d:34:8d:87:09:94:78:f4:fe:0c:0e:e8:ca: f1:d0:7a:d6:d0:55:1d:4b:21:31:6c:54:39:ff:1d: 38:c4:58:c0:10:02:78:ab:73:36:d3:2b:09:a4:62: e9:e3:32:41:02:ea:d6:99:0a:0e:01:3c:df:68:3e: 58:cb:7e:c2:61:84:c9:27:37:83:0b:5c:e8:60:5e: 53:64:e6:50:cf:2a:22:cd:be:57:92:72:6c:6b:47: 77:ee:bb:96:48:b0:4b:1b:eb:37:b8:0f:2b:c6:97: 98:b3 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: A1:B6:F2:69:1D:9D:60:3D:20:03:B7:D6:19:26:AF:97:9F:7F:56:2A X509v3 Authority Key Identifier: keyid:45:32:A9:37:50:F0:A0:A1:8E:02:EB:8B:34:65:28:12:3F:FB:6A:18 Authority Information Access: CA Issuers - URI:http://url-for-aia/Intermediate.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Intermediate.crl X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication Signature Algorithm: sha256WithRSAEncryption ce:53:84:d8:c1:2d:3d:aa:6b:47:32:92:12:9a:77:80:e6:76: 22:c5:6c:5c:d9:53:39:41:18:7a:e5:9d:54:9e:8e:3c:93:23: f9:47:dd:f8:e1:83:90:9c:47:52:31:99:ec:d2:0d:96:0c:c7: b4:4d:62:f6:0e:0b:7d:38:d8:3c:0e:06:ba:d9:d8:6e:e5:e7: 33:08:eb:e7:e8:f5:72:cc:9e:13:34:64:8f:17:ee:cd:b8:fe: db:80:14:ae:e3:ea:f5:45:01:4f:ac:14:7a:41:9f:ca:3d:2e: 7b:bb:66:fa:e9:2c:f5:94:8b:ce:c5:34:0a:9e:bf:91:70:13: a7:e7:cf:ff:71:8d:22:c9:22:de:ea:7a:27:51:08:80:00:f1: 9b:82:04:7d:c4:c9:75:4a:f3:49:4f:2b:9a:40:1d:7d:2b:d3: 76:de:da:99:9e:b6:5f:90:03:9c:25:8f:46:eb:b7:fb:26:b6: dd:8c:66:12:df:c9:c3:9f:09:6f:10:88:45:37:8c:75:1c:bc: a0:04:52:fd:77:23:fc:00:95:51:a0:4b:37:66:37:64:37:e5: ed:09:67:51:30:5e:c2:63:c5:52:f1:88:2e:0b:51:3f:08:5f: 76:6d:12:79:e5:a1:f4:e9:d3:55:1f:91:d0:43:3e:40:01:dc: b3:8f:d2:ac -----BEGIN CERTIFICATE----- MIIDoDCCAoigAwIBAgIUSWnzvsTRR7b5NNAKIhLmYJxRi24wDQYJKoZIhvcNAQEL BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEAzZfFskkgi5c8XbUBW42sryoqtc8autgcLWgSHx8QjFBN 1nVyy2LVX/9rRUSmdhUxbn0OIS5TZVfPfySrLQXbfpTne9zsAm1YO07bwJUCv8St TCYgSRGl0bcB6ScVhe8Zmn25Mmr4DkWL7vQxrebvv77XrEQuEVkVW4KBN4hGWJiW W7QzxcMUEXpT/Ol6xd1h7QGkg/45Zo00jYcJlHj0/gwO6Mrx0HrW0FUdSyExbFQ5 /x04xFjAEAJ4q3M20ysJpGLp4zJBAurWmQoOATzfaD5Yy37CYYTJJzeDC1zoYF5T ZOZQzyoizb5XknJsa0d37ruWSLBLG+s3uA8rxpeYswIDAQABo4HpMIHmMB0GA1Ud DgQWBBShtvJpHZ1gPSADt9YZJq+Xn39WKjAfBgNVHSMEGDAWgBRFMqk3UPCgoY4C 64s0ZSgSP/tqGDA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZIhvcNAQELBQAD ggEBAM5ThNjBLT2qa0cykhKad4DmdiLFbFzZUzlBGHrlnVSejjyTI/lH3fjhg5Cc R1IxmezSDZYMx7RNYvYOC3042DwOBrrZ2G7l5zMI6+fo9XLMnhM0ZI8X7s24/tuA FK7j6vVFAU+sFHpBn8o9Lnu7ZvrpLPWUi87FNAqev5FwE6fnz/9xjSLJIt7qeidR CIAA8ZuCBH3EyXVK80lPK5pAHX0r03be2pmetl+QA5wlj0brt/smtt2MZhLfycOf CW8QiEU3jHUcvKAEUv13I/wAlVGgSzdmN2Q35e0JZ1EwXsJjxVLxiC4LUT8IX3Zt EnnlofTp01UfkdBDPkAB3LOP0qw= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 7c:71:83:7d:9a:71:3e:fb:f4:b1:79:2c:b6:6c:11:29:14:74:0b:74 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Intermediate Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:d4:d2:58:5a:24:b9:9d:c4:07:62:ed:0a:24:09: 46:d4:97:a8:e1:e6:fa:c2:8d:ba:31:da:ea:95:6f: ca:79:cc:10:08:cd:8e:5d:33:eb:04:40:94:7a:15: 94:71:fe:50:73:ea:a0:41:e6:bf:93:aa:7f:60:c2: e6:55:1a:24:ce:b5:f9:5f:ad:f7:90:b5:49:1c:30: 45:ad:ed:12:d3:b0:9d:de:03:33:01:a6:c0:12:4e: 96:13:d7:9f:b0:69:67:b9:cf:d5:a9:ce:9d:7c:4e: 5f:0d:7b:d1:a4:65:93:12:22:42:e8:02:9f:18:0b: 03:af:1f:3c:b1:e0:ac:a7:a7:87:b1:22:c1:c9:fe: 1d:81:13:dd:e7:d9:21:68:86:6a:06:13:82:73:e5: 78:78:e0:99:76:75:38:68:73:cb:8b:33:25:53:72: d1:58:f0:40:64:36:03:32:1d:72:c3:8c:ef:de:76: 07:df:9a:b7:b9:4c:10:94:fb:c8:7b:69:ba:d3:a9: 1a:21:8c:f7:c5:b3:b1:1b:72:44:10:8c:dd:c3:76: 36:e5:ce:a8:a0:29:1b:fa:47:0c:e3:89:f2:44:84: cc:88:0f:48:09:c9:0e:1e:a9:ee:a7:55:ba:5a:6f: 78:66:d8:bd:4d:9c:d5:52:95:83:b1:80:b5:af:ce: f5:73 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 45:32:A9:37:50:F0:A0:A1:8E:02:EB:8B:34:65:28:12:3F:FB:6A:18 X509v3 Authority Key Identifier: keyid:E5:37:1E:E2:93:2C:94:BA:7F:8B:6E:2F:75:D5:0D:D8:0A:D2:96:12 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign Signature Algorithm: sha256WithRSAEncryption 75:42:84:61:76:99:df:4f:c9:9c:e5:a2:98:7e:95:fc:c3:d5: 30:41:a8:99:80:99:4a:ac:e7:17:24:58:57:65:52:6a:ef:15: 35:0e:1c:83:22:54:f0:10:27:ba:3f:cf:e7:bb:21:e3:6d:c5: e4:09:ea:a6:5a:0a:40:28:b2:cd:96:78:db:28:0c:9c:86:97: 3f:e9:31:91:60:89:ba:1a:03:6f:ce:eb:10:cb:17:4a:a4:98: ae:c3:80:0a:ec:00:92:6a:2a:77:45:22:13:da:92:9e:29:65: ec:a9:1a:8e:b4:ec:e4:b2:b8:40:6a:b6:c7:56:25:e5:80:c3: 48:d3:99:af:49:c1:17:7e:8c:3a:48:63:7a:6f:dd:33:1d:7b: 6b:43:8e:05:53:8c:04:14:3d:b4:04:bd:80:d6:f9:a8:c3:35: a9:0f:5b:60:68:c6:10:93:1e:89:75:70:e4:55:f0:c1:b7:b0: 5e:c2:41:3c:d2:e1:1a:07:86:94:18:d5:33:0f:fe:ce:13:b8: 84:82:1f:51:aa:be:de:7a:06:a5:33:88:ef:01:cf:46:a0:11: 85:2b:e2:8e:36:d8:f0:ed:cb:d7:03:45:9c:26:b1:2e:e6:41: 10:bf:02:29:f6:18:d7:ed:1b:32:69:16:93:91:a3:aa:7d:e8: 2e:24:60:04 -----BEGIN CERTIFICATE----- MIIDbzCCAlegAwIBAgIUfHGDfZpxPvv0sXkstmwRKRR0C3QwDQYJKoZIhvcNAQEL BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBANTSWFokuZ3EB2LtCiQJRtSXqOHm+sKNujHa6pVvynnMEAjN jl0z6wRAlHoVlHH+UHPqoEHmv5Oqf2DC5lUaJM61+V+t95C1SRwwRa3tEtOwnd4D MwGmwBJOlhPXn7BpZ7nP1anOnXxOXw170aRlkxIiQugCnxgLA68fPLHgrKenh7Ei wcn+HYET3efZIWiGagYTgnPleHjgmXZ1OGhzy4szJVNy0VjwQGQ2AzIdcsOM7952 B9+at7lMEJT7yHtputOpGiGM98WzsRtyRBCM3cN2NuXOqKApG/pHDOOJ8kSEzIgP SAnJDh6p7qdVulpveGbYvU2c1VKVg7GAta/O9XMCAwEAAaOBujCBtzAdBgNVHQ4E FgQURTKpN1DwoKGOAuuLNGUoEj/7ahgwHwYDVR0jBBgwFoAU5Tce4pMslLp/i24v ddUN2ArSlhIwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOC AQEAdUKEYXaZ30/JnOWimH6V/MPVMEGomYCZSqznFyRYV2VSau8VNQ4cgyJU8BAn uj/P57sh423F5AnqploKQCiyzZZ42ygMnIaXP+kxkWCJuhoDb87rEMsXSqSYrsOA CuwAkmoqd0UiE9qSnill7KkajrTs5LK4QGq2x1Yl5YDDSNOZr0nBF36MOkhjem/d Mx17a0OOBVOMBBQ9tAS9gNb5qMM1qQ9bYGjGEJMeiXVw5FXwwbewXsJBPNLhGgeG lBjVMw/+zhO4hIIfUaq+3noGpTOI7wHPRqARhSvijjbY8O3L1wNFnCaxLuZBEL8C KfYY1+0bMmkWk5Gjqn3oLiRgBA== -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 7c:71:83:7d:9a:71:3e:fb:f4:b1:79:2c:b6:6c:11:29:14:74:0b:73 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Root Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:a9:f3:a8:48:50:46:fe:b1:fa:ee:af:1a:5c:c1: f2:d0:e1:f9:d1:b4:8e:82:c7:91:d2:eb:1e:06:ba: 27:e5:3e:d5:ae:c7:1c:3f:a6:b9:48:05:c4:90:57: 23:ab:2a:01:cd:ca:7f:df:8c:b6:2e:6f:83:88:e9: 8e:f3:b0:e8:97:9a:91:cd:ad:d0:ef:fb:4b:d7:61: bd:f1:5d:00:97:70:5b:95:1e:6d:3c:a7:03:2b:ec: 29:cc:b6:ed:b1:e2:9a:db:38:ce:73:02:19:3f:20: 03:70:cd:88:29:f9:ad:40:f7:16:0b:b4:93:9b:ac: 13:da:bb:39:e9:2f:2f:17:39:1a:27:47:75:cd:0a: 81:a2:e5:a8:58:e7:08:15:a3:33:86:0e:b9:ba:90: 23:3b:2a:2a:ed:04:d7:80:85:51:d8:dd:ba:d0:96: 34:ef:8c:21:19:ce:cd:0a:9e:fc:ab:3d:ed:69:d1: 4b:d2:2b:1f:77:5c:74:96:d7:25:ce:02:e0:49:ed: 18:ee:c4:37:d1:e5:f5:a2:5c:ae:c9:fe:2b:cd:68: a6:a5:31:9a:76:5e:a2:10:be:aa:14:ca:57:c3:31: ac:92:bd:9b:53:df:69:8f:e2:26:85:36:20:27:f5: 60:fb:66:6d:9b:a7:ec:f8:e4:1a:df:a2:38:ee:ef: 3c:d1 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: E5:37:1E:E2:93:2C:94:BA:7F:8B:6E:2F:75:D5:0D:D8:0A:D2:96:12 X509v3 Authority Key Identifier: keyid:E5:37:1E:E2:93:2C:94:BA:7F:8B:6E:2F:75:D5:0D:D8:0A:D2:96:12 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption 42:40:02:30:8f:45:00:28:39:8b:4e:d1:cf:70:53:b1:76:34: 02:16:01:3e:8f:96:71:44:c4:85:be:44:16:c6:8e:77:0b:19: cc:62:a7:56:e0:4c:94:85:6a:85:81:58:6c:24:93:9f:6e:ea: b2:a6:3c:b3:c3:70:38:ea:2d:b5:f5:52:16:00:90:7c:2e:b4: 59:67:57:46:8a:48:7d:93:15:d7:4e:2d:c6:15:4d:36:e1:b0: 5b:7b:3d:19:fc:8c:b0:2e:b3:30:45:c3:70:99:5e:6b:b0:b3: 1d:28:ca:61:97:f1:82:43:a4:73:e2:95:27:48:8d:49:4c:ad: 18:a0:76:3e:9d:3a:26:25:bb:7a:af:c5:2a:5e:96:5e:aa:cc: 08:38:c2:e5:3a:64:5a:7e:0e:4c:f7:80:fd:26:98:31:97:0d: 9a:7a:fa:68:b9:79:aa:e6:b2:fd:2f:90:b8:db:b9:b6:f7:c8: 77:b4:13:1a:ae:b8:0f:68:4a:d3:10:d7:5b:cb:7f:a3:c6:68: 2d:05:40:a0:84:e0:69:7e:1c:55:8f:6a:47:dd:2b:67:e4:6b: bc:a6:af:04:d9:d6:e3:e6:10:af:aa:98:20:3f:51:b8:31:04: 70:99:dd:95:5a:7d:9b:cb:71:a6:05:cd:f2:7c:57:19:43:00: 9a:c5:2c:97 -----BEGIN CERTIFICATE----- MIIDeDCCAmCgAwIBAgIUfHGDfZpxPvv0sXkstmwRKRR0C3MwDQYJKoZIhvcNAQEL BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQCp86hIUEb+sfrurxpcwfLQ4fnRtI6Cx5HS6x4GuiflPtWuxxw/prlIBcSQ VyOrKgHNyn/fjLYub4OI6Y7zsOiXmpHNrdDv+0vXYb3xXQCXcFuVHm08pwMr7CnM tu2x4prbOM5zAhk/IANwzYgp+a1A9xYLtJObrBPauznpLy8XORonR3XNCoGi5ahY 5wgVozOGDrm6kCM7KirtBNeAhVHY3brQljTvjCEZzs0KnvyrPe1p0UvSKx93XHSW 1yXOAuBJ7RjuxDfR5fWiXK7J/ivNaKalMZp2XqIQvqoUylfDMaySvZtT32mP4iaF NiAn9WD7Zm2bp+z45Brfojju7zzRAgMBAAGjgcswgcgwHQYDVR0OBBYEFOU3HuKT LJS6f4tuL3XVDdgK0pYSMB8GA1UdIwQYMBaAFOU3HuKTLJS6f4tuL3XVDdgK0pYS MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG 9w0BAQsFAAOCAQEAQkACMI9FACg5i07Rz3BTsXY0AhYBPo+WcUTEhb5EFsaOdwsZ zGKnVuBMlIVqhYFYbCSTn27qsqY8s8NwOOottfVSFgCQfC60WWdXRopIfZMV104t xhVNNuGwW3s9GfyMsC6zMEXDcJlea7CzHSjKYZfxgkOkc+KVJ0iNSUytGKB2Pp06 JiW7eq/FKl6WXqrMCDjC5TpkWn4OTPeA/SaYMZcNmnr6aLl5quay/S+QuNu5tvfI d7QTGq64D2hK0xDXW8t/o8ZoLQVAoITgaX4cVY9qR90rZ+RrvKavBNnW4+YQr6qY ID9RuDEEcJndlVp9m8txpgXN8nxXGUMAmsUslw== -----END CERTIFICATE-----