[Created by: generate-chains.py] Certificate chain where the root certificate lacks a basic constraints extension. Certificate: Data: Version: 3 (0x2) Serial Number: 6f:30:93:e0:af:42:20:f7:92:d9:8d:63:e4:7e:ee:e3:df:49:cd:56 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Intermediate Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Target Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:e0:2c:39:1a:67:64:64:af:b8:19:4f:41:9e:78: a6:a8:fc:a4:43:70:a7:7c:23:f9:27:a0:7f:98:37: e7:ee:fe:be:2d:82:65:9e:46:15:1e:fc:3d:70:36: 96:47:69:6a:c0:51:c5:f1:59:2a:d7:1e:3f:b3:2e: df:ac:af:89:16:45:ed:71:ae:38:04:4d:5e:e7:b8: d9:a1:45:14:a5:f9:a4:f7:e3:e7:e4:e9:ac:7e:82: 95:e6:5c:8e:ac:da:14:d5:2f:04:ed:48:f7:56:4b: 5a:98:72:0f:07:66:ca:17:a5:0e:b7:05:64:3b:6a: 97:ad:b1:7e:4d:b3:8c:d4:2b:23:3d:88:bb:c9:80: 04:d9:5b:1a:36:37:ab:d2:c7:06:a8:81:6f:62:b7: c1:74:74:8e:ee:f6:6b:c0:15:28:44:50:85:dc:8d: 3b:e7:0b:82:9d:bd:db:20:69:1a:55:68:48:0e:84: 2a:25:26:ca:01:ad:16:7f:3c:30:d4:5b:47:9a:86: fe:fc:90:b5:d0:bb:d3:ee:af:9a:80:3c:4c:da:46: c8:db:36:68:89:51:fe:76:78:cf:22:eb:ce:62:d4: 2c:2b:c7:7c:24:48:64:ca:9b:91:b2:90:fc:c9:29: 65:70:83:60:05:1a:32:70:ca:12:f3:70:52:dd:3e: 82:b1 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 98:FA:6D:F3:B3:9E:A3:B9:81:22:1C:C5:19:24:06:BC:D9:D6:92:ED X509v3 Authority Key Identifier: keyid:C1:E9:0B:DE:AA:27:20:FA:0B:FF:DB:77:09:96:1E:9B:2C:0D:F7:70 Authority Information Access: CA Issuers - URI:http://url-for-aia/Intermediate.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Intermediate.crl X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication Signature Algorithm: sha256WithRSAEncryption b4:37:d0:b2:e6:04:26:d5:cf:ea:f2:91:5c:aa:03:17:35:07: 21:bd:67:52:60:9c:c2:9e:79:6e:ef:5f:a2:05:74:6c:b4:75: 7e:f1:3b:0f:2e:62:85:b2:33:3b:23:68:7c:67:e1:b6:e1:c4: b0:af:50:29:a7:73:fc:aa:b9:e0:f2:fb:7e:f3:f5:27:07:e6: 26:c0:b8:51:06:7c:42:9d:59:b5:b3:2f:ae:ea:f4:e5:0b:9c: 63:00:34:2c:46:cd:df:22:55:21:3b:78:23:b0:8e:0d:69:8d: 66:92:16:90:83:fd:ad:46:60:7f:5f:87:61:7f:2f:0f:c2:8c: 0f:7a:dc:b4:6e:cc:a7:80:88:3b:49:17:ef:fb:95:48:9b:80: b6:f4:32:95:e0:e8:e6:1a:97:2f:fe:c6:a7:ad:02:b8:ef:a7: 25:42:cd:ea:bd:c1:64:6b:b0:89:6c:bb:fb:e6:9c:43:b8:51: 03:0c:ed:03:01:44:5b:ef:ad:8e:59:aa:29:cd:2d:c4:c8:1f: 55:66:c6:26:d8:6c:2d:07:ca:91:10:2e:04:54:5d:e1:ee:87: 1b:22:ff:2a:b9:7a:e2:be:be:d7:51:d2:7f:3e:ee:e0:80:c8: 58:fc:f1:7e:66:ca:6f:24:1a:bc:c0:98:a0:75:88:27:2e:28: 59:30:f4:05 -----BEGIN CERTIFICATE----- MIIDoDCCAoigAwIBAgIUbzCT4K9CIPeS2Y1j5H7u499JzVYwDQYJKoZIhvcNAQEL BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEA4Cw5GmdkZK+4GU9BnnimqPykQ3CnfCP5J6B/mDfn7v6+ LYJlnkYVHvw9cDaWR2lqwFHF8Vkq1x4/sy7frK+JFkXtca44BE1e57jZoUUUpfmk 9+Pn5OmsfoKV5lyOrNoU1S8E7Uj3VktamHIPB2bKF6UOtwVkO2qXrbF+TbOM1Csj PYi7yYAE2VsaNjer0scGqIFvYrfBdHSO7vZrwBUoRFCF3I075wuCnb3bIGkaVWhI DoQqJSbKAa0Wfzww1FtHmob+/JC10LvT7q+agDxM2kbI2zZoiVH+dnjPIuvOYtQs K8d8JEhkypuRspD8ySllcINgBRoycMoS83BS3T6CsQIDAQABo4HpMIHmMB0GA1Ud DgQWBBSY+m3zs56juYEiHMUZJAa82daS7TAfBgNVHSMEGDAWgBTB6Qveqicg+gv/ 23cJlh6bLA33cDA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZIhvcNAQELBQAD ggEBALQ30LLmBCbVz+rykVyqAxc1ByG9Z1JgnMKeeW7vX6IFdGy0dX7xOw8uYoWy MzsjaHxn4bbhxLCvUCmnc/yqueDy+37z9ScH5ibAuFEGfEKdWbWzL67q9OULnGMA NCxGzd8iVSE7eCOwjg1pjWaSFpCD/a1GYH9fh2F/Lw/CjA963LRuzKeAiDtJF+/7 lUibgLb0MpXg6OYaly/+xqetArjvpyVCzeq9wWRrsIlsu/vmnEO4UQMM7QMBRFvv rY5ZqinNLcTIH1VmxibYbC0HypEQLgRUXeHuhxsi/yq5euK+vtdR0n8+7uCAyFj8 8X5mym8kGrzAmKB1iCcuKFkw9AU= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 08:55:78:34:50:50:34:15:fe:10:58:e3:0b:cb:6b:c3:c6:56:3d:16 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Intermediate Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:de:e6:c0:76:c5:4c:d0:8e:b3:87:07:91:66:aa: f1:ae:93:8f:a2:83:2d:d5:05:91:b8:52:f6:2d:a5: ff:fd:95:ee:85:0f:85:c3:eb:d7:8e:f7:6f:2a:c0: 15:de:ae:1e:62:62:12:64:c3:f7:c1:0f:05:a4:0f: b7:33:69:92:66:57:93:4f:4e:04:43:bb:23:bb:c3: c6:29:0b:42:68:1f:26:81:77:2d:91:f6:62:b8:e3: 9a:2c:78:2d:7c:1f:3a:f5:ce:f2:c2:75:39:5a:b7: c2:23:f5:f5:ee:7e:a5:7a:45:c4:d4:1e:12:c8:a6: 40:44:64:07:ff:33:a8:ce:41:df:77:c4:01:f5:c5: 41:6b:4e:a0:ee:9d:36:63:5a:b0:e8:38:bb:bd:fb: a5:7f:6e:5c:6d:c6:62:dd:05:2f:90:d4:fb:5b:18: 71:84:57:e2:c9:d3:cc:c8:36:5f:d1:78:20:4c:68: 83:1f:df:64:a3:11:9f:e8:bd:d4:bb:8e:04:63:0d: 3d:6d:a9:43:30:5d:f0:ca:e3:62:8f:11:9e:8b:8f: de:9a:6e:6d:03:e5:8c:0f:6f:00:6e:1a:72:2c:13: e0:a1:78:93:ef:2c:6d:2c:0a:8a:5c:02:65:50:36: fa:da:07:ba:36:b9:21:eb:01:14:97:ab:19:60:be: 97:6b Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: C1:E9:0B:DE:AA:27:20:FA:0B:FF:DB:77:09:96:1E:9B:2C:0D:F7:70 X509v3 Authority Key Identifier: keyid:96:9F:CB:9C:5C:0D:06:9D:F1:3A:21:D5:22:F7:4B:75:2C:7D:D3:D3 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption 0a:11:c3:21:b5:94:3d:5f:ae:33:72:18:c4:74:c0:cb:15:b0: 22:74:39:5d:76:7b:77:a9:91:0d:02:7c:1b:0c:fa:d1:dc:94: f2:d3:38:01:f3:64:42:53:5b:0e:a7:a3:7e:8d:8d:0b:6f:1a: 93:ab:17:3a:02:43:23:c6:c2:8c:40:32:fe:e9:e4:42:31:c2: 4f:96:87:da:54:70:f0:85:31:7c:a3:a2:96:af:c6:a3:0a:26: 68:3c:db:1b:dc:be:58:c6:c2:ef:62:a1:87:3e:01:4a:3c:c0: aa:fa:f5:30:d7:7d:35:3c:3b:f0:ef:7b:e9:f8:67:5a:f7:75: 5f:0f:ae:63:a6:61:98:5a:21:8a:36:ca:59:40:75:60:4b:6b: cd:0e:99:d7:2f:fc:85:1d:81:4c:50:e0:66:1b:fe:8f:83:e4: bf:00:07:48:3c:ea:16:c4:43:8d:53:3a:44:bf:64:99:58:1e: 72:38:f9:ec:63:ad:4e:e3:5a:7b:b3:22:0a:54:d8:49:41:e7: 4f:f6:ad:df:3b:f2:c2:3d:d5:e1:62:30:4a:61:30:09:ea:2a: 66:98:1e:a7:51:e1:cc:08:c2:32:5e:c7:77:2c:93:c0:6b:77: 89:99:e3:f5:89:bb:62:6b:3e:96:25:ac:a1:79:2e:82:9b:e3: 1b:4b:28:96 -----BEGIN CERTIFICATE----- MIIDgDCCAmigAwIBAgIUCFV4NFBQNBX+EFjjC8trw8ZWPRYwDQYJKoZIhvcNAQEL BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBAN7mwHbFTNCOs4cHkWaq8a6Tj6KDLdUFkbhS9i2l//2V7oUP hcPr1473byrAFd6uHmJiEmTD98EPBaQPtzNpkmZXk09OBEO7I7vDxikLQmgfJoF3 LZH2Yrjjmix4LXwfOvXO8sJ1OVq3wiP19e5+pXpFxNQeEsimQERkB/8zqM5B33fE AfXFQWtOoO6dNmNasOg4u737pX9uXG3GYt0FL5DU+1sYcYRX4snTzMg2X9F4IExo gx/fZKMRn+i91LuOBGMNPW2pQzBd8MrjYo8RnouP3ppubQPljA9vAG4aciwT4KF4 k+8sbSwKilwCZVA2+toHuja5IesBFJerGWC+l2sCAwEAAaOByzCByDAdBgNVHQ4E FgQUwekL3qonIPoL/9t3CZYemywN93AwHwYDVR0jBBgwFoAUlp/LnFwNBp3xOiHV IvdLdSx909MwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ MA0GCSqGSIb3DQEBCwUAA4IBAQAKEcMhtZQ9X64zchjEdMDLFbAidDlddnt3qZEN AnwbDPrR3JTy0zgB82RCU1sOp6N+jY0LbxqTqxc6AkMjxsKMQDL+6eRCMcJPlofa VHDwhTF8o6KWr8ajCiZoPNsb3L5YxsLvYqGHPgFKPMCq+vUw1301PDvw73vp+Gda 93VfD65jpmGYWiGKNspZQHVgS2vNDpnXL/yFHYFMUOBmG/6Pg+S/AAdIPOoWxEON UzpEv2SZWB5yOPnsY61O41p7syIKVNhJQedP9q3fO/LCPdXhYjBKYTAJ6ipmmB6n UeHMCMIyXsd3LJPAa3eJmeP1ibtiaz6WJayheS6Cm+MbSyiW -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 08:55:78:34:50:50:34:15:fe:10:58:e3:0b:cb:6b:c3:c6:56:3d:15 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Root Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:b7:0e:0c:2e:e1:46:5f:9d:dc:3a:16:51:56:2f: 4c:5c:f7:92:93:2a:a1:bf:d1:bd:15:cd:8a:f8:e3: 8a:a4:41:fa:9f:de:85:84:ff:cd:5b:7d:13:33:ca: b8:8b:34:f6:85:73:a5:23:ef:ba:61:ca:18:9f:08: ea:39:17:18:69:dd:3a:21:57:a5:6d:b2:63:a7:42: ba:b6:8a:4e:e2:1f:ab:88:4f:ae:ca:1a:66:b8:79: d2:94:73:b9:46:c4:be:89:31:53:c1:d8:b4:cc:1c: 6b:d9:0c:a3:5a:e3:a5:20:7c:a0:bd:d4:14:7a:14: 29:0c:b7:40:da:f5:fc:af:c3:91:65:78:b3:41:ee: f5:9f:0b:22:0b:c1:f5:12:94:89:25:13:1b:dd:a3: a3:44:7a:57:7c:40:17:e0:66:33:a9:27:7c:2e:6f: 9f:38:d3:fa:4d:67:80:39:33:36:e5:41:fd:ac:6b: 37:d0:84:75:e2:84:93:3b:8d:ce:8c:22:98:4e:05: 64:7f:df:fb:96:85:c5:ea:0e:11:24:f9:84:bd:17: ce:15:30:86:ad:c6:de:2c:48:84:d0:45:d4:0b:1f: 13:e9:a4:ca:e7:69:c0:24:a1:23:5e:6b:4e:76:b4: bd:d7:0d:96:94:b6:d9:8e:25:9b:1e:c9:a2:00:10: 47:77 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 96:9F:CB:9C:5C:0D:06:9D:F1:3A:21:D5:22:F7:4B:75:2C:7D:D3:D3 X509v3 Authority Key Identifier: keyid:96:9F:CB:9C:5C:0D:06:9D:F1:3A:21:D5:22:F7:4B:75:2C:7D:D3:D3 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign Signature Algorithm: sha256WithRSAEncryption a0:63:51:25:66:b7:9a:52:c8:f3:a5:18:a4:76:b5:02:e8:a1: 12:0e:f7:e0:92:32:6f:85:2a:d3:95:ae:c1:5d:11:11:53:c2: bb:85:55:a5:5c:71:f5:65:c6:f2:88:8a:a5:10:66:b6:bb:36: d6:d5:c3:c1:87:be:bc:5f:c6:47:87:63:de:ef:6a:d6:46:db: ca:b6:09:17:07:39:76:6d:3a:ef:69:37:05:0d:c8:24:51:1f: 24:a7:c0:bc:44:a4:a3:57:28:f3:4f:ca:52:3b:1c:1a:3c:18: 07:17:26:8c:ed:22:d0:0a:41:05:ae:cc:2c:b9:24:80:d5:22: 1e:c0:eb:a7:48:fd:3a:c3:ee:89:95:6d:25:0b:45:86:70:11: 69:da:11:38:c9:7a:3a:c1:b0:a7:f3:df:15:85:d1:66:ae:8f: 2d:52:38:2d:db:32:c5:12:ba:e2:fd:b1:77:8a:ef:1b:8d:cd: 99:85:33:e3:82:bb:42:f2:f7:92:56:4d:5d:4e:8d:82:54:23: e8:90:3b:32:d2:9e:24:a7:4b:58:86:ed:fe:bf:b5:8d:e5:a5: c3:af:d8:fa:92:df:bb:ae:8b:00:8c:64:e0:6c:53:5e:d9:14: bd:30:78:40:80:f4:58:cd:b1:92:50:c9:87:59:91:39:18:a9: ea:18:44:e7 -----BEGIN CERTIFICATE----- MIIDZzCCAk+gAwIBAgIUCFV4NFBQNBX+EFjjC8trw8ZWPRUwDQYJKoZIhvcNAQEL BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQC3Dgwu4UZfndw6FlFWL0xc95KTKqG/0b0VzYr444qkQfqf3oWE/81bfRMz yriLNPaFc6Uj77phyhifCOo5Fxhp3TohV6VtsmOnQrq2ik7iH6uIT67KGma4edKU c7lGxL6JMVPB2LTMHGvZDKNa46UgfKC91BR6FCkMt0Da9fyvw5FleLNB7vWfCyIL wfUSlIklExvdo6NEeld8QBfgZjOpJ3wub5840/pNZ4A5MzblQf2sazfQhHXihJM7 jc6MIphOBWR/3/uWhcXqDhEk+YS9F84VMIatxt4sSITQRdQLHxPppMrnacAkoSNe a052tL3XDZaUttmOJZseyaIAEEd3AgMBAAGjgbowgbcwHQYDVR0OBBYEFJafy5xc DQad8Toh1SL3S3UsfdPTMB8GA1UdIwQYMBaAFJafy5xcDQad8Toh1SL3S3UsfdPT MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADggEBAKBjUSVm t5pSyPOlGKR2tQLooRIO9+CSMm+FKtOVrsFdERFTwruFVaVccfVlxvKIiqUQZra7 NtbVw8GHvrxfxkeHY97vatZG28q2CRcHOXZtOu9pNwUNyCRRHySnwLxEpKNXKPNP ylI7HBo8GAcXJoztItAKQQWuzCy5JIDVIh7A66dI/TrD7omVbSULRYZwEWnaETjJ ejrBsKfz3xWF0Waujy1SOC3bMsUSuuL9sXeK7xuNzZmFM+OCu0Ly95JWTV1OjYJU I+iQOzLSniSnS1iG7f6/tY3lpcOv2PqS37uuiwCMZOBsU17ZFL0weECA9FjNsZJQ yYdZkTkYqeoYROc= -----END CERTIFICATE-----