1[Created by: generate-chains.py] 2 3Certificate chain where the target was signed by a different 4certificate with a different key. The target lacks an 5authorityKeyIdentifier extension as some verifiers will not try verifying with 6the bogus intermediate if the authorityKeyIdentifier does not match the 7intermediate's subjectKeyIdentifier. 8 9 10Certificate: 11 Data: 12 Version: 3 (0x2) 13 Serial Number: 14 2c:6b:f0:a5:aa:60:49:5e:d6:8b:7f:f5:b2:89:be:f7:78:1d:89:d2 15 Signature Algorithm: sha256WithRSAEncryption 16 Issuer: CN=Intermediate 17 Validity 18 Not Before: Oct 5 12:00:00 2021 GMT 19 Not After : Oct 5 12:00:00 2022 GMT 20 Subject: CN=Target 21 Subject Public Key Info: 22 Public Key Algorithm: rsaEncryption 23 RSA Public-Key: (2048 bit) 24 Modulus: 25 00:b6:34:1b:30:e4:7d:b9:40:ec:8c:d8:b7:d5:4d: 26 a0:0c:85:66:25:a7:bf:16:c2:d8:4e:6a:b5:d1:3c: 27 c1:63:a8:ff:96:24:87:59:14:9b:e0:00:8b:75:7a: 28 52:5d:7d:a5:1d:fc:1d:f8:4b:eb:e3:74:b5:8d:e8: 29 43:8d:dc:b9:3d:d5:47:86:fb:c7:d8:56:b6:91:03: 30 76:56:ba:f9:35:6b:b6:71:44:51:a2:7c:24:02:e5: 31 f0:7c:67:34:21:e0:10:31:54:f9:6d:96:43:33:a6: 32 bb:ca:4c:f8:31:a4:16:93:6d:15:50:0a:5e:43:77: 33 ab:2d:4b:ce:79:80:ec:95:0c:a2:9b:7a:72:7d:f5: 34 a6:4a:28:14:a3:b8:eb:8f:88:84:08:e5:00:86:30: 35 aa:53:6f:b2:9e:5f:85:85:29:dd:94:aa:94:28:8a: 36 ca:50:13:f9:ac:08:64:8c:b9:80:65:ff:65:c1:a6: 37 48:75:df:b0:9a:8c:0b:c8:d0:07:a9:8b:9f:16:69: 38 51:81:c9:8a:33:81:3f:04:57:2c:06:53:c6:2e:c7: 39 4c:99:6d:65:2b:a4:c0:b6:6a:ca:37:05:38:2a:64: 40 b0:7f:e5:ad:3b:90:77:bd:86:53:34:18:00:46:6a: 41 37:0f:85:39:c5:95:96:ab:bd:a3:81:09:69:40:22: 42 09:b7 43 Exponent: 65537 (0x10001) 44 X509v3 extensions: 45 X509v3 Subject Key Identifier: 46 7A:1C:A0:65:5A:CD:B7:F6:57:2D:AA:6C:C2:A7:B0:AE:60:FE:61:02 47 Authority Information Access: 48 CA Issuers - URI:http://url-for-aia/Intermediate.cer 49 50 X509v3 CRL Distribution Points: 51 52 Full Name: 53 URI:http://url-for-crl/Intermediate.crl 54 55 X509v3 Key Usage: critical 56 Digital Signature, Key Encipherment 57 X509v3 Extended Key Usage: 58 TLS Web Server Authentication, TLS Web Client Authentication 59 X509v3 Subject Alternative Name: 60 DNS:test.example 61 Signature Algorithm: sha256WithRSAEncryption 62 42:20:d3:44:c7:c2:bf:44:3f:d3:c7:df:6f:15:17:34:04:40: 63 4d:c6:d4:a9:2c:06:b1:41:78:4a:57:00:f3:65:22:17:ed:42: 64 5a:e9:5d:a6:22:25:c0:9a:e0:1d:0b:5c:c6:fd:0e:05:6c:11: 65 b8:ae:cd:ad:91:bf:b9:4e:bb:81:28:a7:7e:47:01:0b:e4:73: 66 29:4b:9a:6e:cd:01:0e:e6:3e:f0:19:49:24:1d:8e:04:5e:4d: 67 1f:64:ad:5a:90:d8:22:18:7a:66:10:cd:4d:6a:2c:f4:31:82: 68 f0:31:e4:c5:2e:a5:1e:3c:52:77:de:c5:02:fc:0f:68:ee:8c: 69 1c:24:4a:da:41:ba:ed:bc:4d:c0:f7:f0:27:7b:44:8f:ac:be: 70 e0:d5:49:89:c1:98:53:6c:7e:f3:27:82:70:a5:03:01:0e:39: 71 82:b0:53:6e:26:5d:5e:a7:e6:8a:bf:8c:4e:00:38:1c:65:42: 72 c0:ff:8c:36:4f:fe:2f:1a:fd:3c:6a:75:3d:05:19:88:23:f3: 73 84:eb:fd:53:2c:f4:98:c1:38:bb:a5:fb:a8:f7:b5:9d:1d:d1: 74 20:33:2d:b1:68:f8:55:8b:63:df:20:f4:3b:88:0d:03:e0:4a: 75 75:b4:b3:0b:c5:03:49:1d:18:78:65:93:bc:b0:66:61:e5:64: 76 b4:0a:e0:e6 77-----BEGIN CERTIFICATE----- 78MIIDmDCCAoCgAwIBAgIULGvwpapgSV7Wi3/1som+93gdidIwDQYJKoZIhvcNAQEL 79BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy 80MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF 81AAOCAQ8AMIIBCgKCAQEAtjQbMOR9uUDsjNi31U2gDIVmJae/FsLYTmq10TzBY6j/ 82liSHWRSb4ACLdXpSXX2lHfwd+Evr43S1jehDjdy5PdVHhvvH2Fa2kQN2Vrr5NWu2 83cURRonwkAuXwfGc0IeAQMVT5bZZDM6a7ykz4MaQWk20VUApeQ3erLUvOeYDslQyi 84m3pyffWmSigUo7jrj4iECOUAhjCqU2+ynl+FhSndlKqUKIrKUBP5rAhkjLmAZf9l 85waZIdd+wmowLyNAHqYufFmlRgcmKM4E/BFcsBlPGLsdMmW1lK6TAtmrKNwU4KmSw 86f+WtO5B3vYZTNBgARmo3D4U5xZWWq72jgQlpQCIJtwIDAQABo4HhMIHeMB0GA1Ud 87DgQWBBR6HKBlWs239lctqmzCp7CuYP5hAjA/BggrBgEFBQcBAQQzMDEwLwYIKwYB 88BQUHMAKGI2h0dHA6Ly91cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1Ud 89HwQtMCswKaAnoCWGI2h0dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3Js 90MA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIw 91FwYDVR0RBBAwDoIMdGVzdC5leGFtcGxlMA0GCSqGSIb3DQEBCwUAA4IBAQBCINNE 92x8K/RD/Tx99vFRc0BEBNxtSpLAaxQXhKVwDzZSIX7UJa6V2mIiXAmuAdC1zG/Q4F 93bBG4rs2tkb+5TruBKKd+RwEL5HMpS5puzQEO5j7wGUkkHY4EXk0fZK1akNgiGHpm 94EM1Naiz0MYLwMeTFLqUePFJ33sUC/A9o7owcJEraQbrtvE3A9/Ane0SPrL7g1UmJ 95wZhTbH7zJ4JwpQMBDjmCsFNuJl1ep+aKv4xOADgcZULA/4w2T/4vGv08anU9BRmI 96I/OE6/1TLPSYwTi7pfuo97WdHdEgMy2xaPhVi2PfIPQ7iA0D4Ep1tLMLxQNJHRh4 97ZZO8sGZh5WS0CuDm 98-----END CERTIFICATE----- 99 100Certificate: 101 Data: 102 Version: 3 (0x2) 103 Serial Number: 104 7d:8c:81:7c:3f:7c:cd:c0:85:4b:99:ee:b9:df:b6:b1:07:4e:88:46 105 Signature Algorithm: sha256WithRSAEncryption 106 Issuer: CN=Root 107 Validity 108 Not Before: Oct 5 12:00:00 2021 GMT 109 Not After : Oct 5 12:00:00 2022 GMT 110 Subject: CN=Intermediate 111 Subject Public Key Info: 112 Public Key Algorithm: rsaEncryption 113 RSA Public-Key: (2048 bit) 114 Modulus: 115 00:b4:e3:56:b9:b0:39:df:ba:72:ab:22:55:10:91: 116 0b:ac:73:32:70:19:51:96:6b:17:ba:78:a2:c8:77: 117 cc:d2:b2:0e:9d:de:b5:3f:6b:8a:49:80:b9:a6:23: 118 9e:96:82:ff:41:65:bd:86:e3:bd:a4:bf:b9:19:85: 119 f2:0a:c8:3a:b7:87:d5:d6:6f:2e:c3:72:35:36:46: 120 98:ec:d9:fd:0e:61:cb:0a:d4:65:c5:5d:a7:e0:cd: 121 6f:ed:92:40:03:62:1b:00:c6:c2:02:1a:de:f1:67: 122 d5:f6:0b:82:aa:7f:dc:72:08:5e:be:81:57:1d:66: 123 9a:82:bb:d5:b1:78:de:f7:6f:b2:d7:26:5c:b5:47: 124 65:32:91:41:70:0f:3e:23:89:70:e3:0a:be:aa:a9: 125 dd:0e:e2:6e:8d:49:30:af:bb:ad:bb:3e:4d:0f:6d: 126 43:c2:3c:41:20:26:68:af:a7:ec:83:6c:2e:2d:43: 127 7e:16:5b:93:8e:b4:6c:ba:e7:26:8c:d1:60:93:4b: 128 78:10:e6:a6:cb:97:b9:4f:fb:fc:3f:f0:68:a1:22: 129 f0:20:bf:5f:21:89:a8:5b:8b:fb:7d:a9:b2:ed:13: 130 a3:3c:d1:4c:c7:e5:ba:8c:ca:8c:76:f6:89:aa:8f: 131 6d:44:0a:a4:d1:18:66:65:e5:04:25:b1:86:84:e4: 132 2a:73 133 Exponent: 65537 (0x10001) 134 X509v3 extensions: 135 X509v3 Subject Key Identifier: 136 51:9D:BA:B2:87:A5:E9:E6:E3:E1:DB:F3:1B:0C:67:CB:6C:D1:C5:A8 137 X509v3 Authority Key Identifier: 138 keyid:FA:79:49:F6:69:64:80:41:9B:1E:E6:2C:39:F8:36:2C:0F:F4:82:66 139 140 Authority Information Access: 141 CA Issuers - URI:http://url-for-aia/Root.cer 142 143 X509v3 CRL Distribution Points: 144 145 Full Name: 146 URI:http://url-for-crl/Root.crl 147 148 X509v3 Key Usage: critical 149 Certificate Sign, CRL Sign 150 X509v3 Basic Constraints: critical 151 CA:TRUE 152 Signature Algorithm: sha256WithRSAEncryption 153 99:68:59:0b:1e:31:c3:e6:9a:27:95:89:cc:0a:79:cf:95:39: 154 77:83:21:22:e3:65:77:26:19:ab:f2:5f:14:7d:50:cb:82:1c: 155 92:06:d0:6d:c2:dd:34:17:69:fe:a4:34:8a:fe:b4:5d:e5:29: 156 6f:f4:88:82:4f:2c:3d:97:a7:b6:7a:2d:df:23:89:50:a8:21: 157 da:70:78:d7:c3:c3:3e:c0:1e:29:53:97:d0:5e:cd:c5:9e:7d: 158 05:20:be:7a:29:8d:5e:31:84:4c:de:57:6b:55:91:30:06:60: 159 b2:73:94:99:98:8c:cb:6f:aa:81:00:49:99:48:a5:04:cb:cf: 160 bf:af:9f:0c:d8:43:16:7d:d9:a0:42:37:b8:3d:ec:f9:81:2d: 161 4a:09:ce:69:14:99:95:92:69:ba:4f:9f:04:05:af:a7:7c:4b: 162 93:44:90:fb:00:73:1f:0e:87:1c:53:1f:db:48:c7:b3:8f:94: 163 a2:06:e2:66:8d:35:16:3f:6f:53:f9:4d:3f:43:ac:0b:7f:d9: 164 41:85:b3:7c:6e:33:b6:31:99:fc:ce:dd:c4:22:2d:65:dc:97: 165 e8:56:20:a8:80:d2:1e:b6:2a:19:e7:cb:fb:ff:26:f6:53:37: 166 2f:23:52:eb:d7:89:e7:78:22:f7:e6:8e:fb:cb:15:25:4f:4e: 167 79:81:72:6c 168-----BEGIN CERTIFICATE----- 169MIIDgDCCAmigAwIBAgIUfYyBfD98zcCFS5nuud+2sQdOiEYwDQYJKoZIhvcNAQEL 170BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 171MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD 172ggEPADCCAQoCggEBALTjVrmwOd+6cqsiVRCRC6xzMnAZUZZrF7p4osh3zNKyDp3e 173tT9rikmAuaYjnpaC/0FlvYbjvaS/uRmF8grIOreH1dZvLsNyNTZGmOzZ/Q5hywrU 174ZcVdp+DNb+2SQANiGwDGwgIa3vFn1fYLgqp/3HIIXr6BVx1mmoK71bF43vdvstcm 175XLVHZTKRQXAPPiOJcOMKvqqp3Q7ibo1JMK+7rbs+TQ9tQ8I8QSAmaK+n7INsLi1D 176fhZbk460bLrnJozRYJNLeBDmpsuXuU/7/D/waKEi8CC/XyGJqFuL+32psu0TozzR 177TMfluozKjHb2iaqPbUQKpNEYZmXlBCWxhoTkKnMCAwEAAaOByzCByDAdBgNVHQ4E 178FgQUUZ26soel6ebj4dvzGwxny2zRxagwHwYDVR0jBBgwFoAU+nlJ9mlkgEGbHuYs 179Ofg2LA/0gmYwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs 180LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m 181b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ 182MA0GCSqGSIb3DQEBCwUAA4IBAQCZaFkLHjHD5ponlYnMCnnPlTl3gyEi42V3Jhmr 1838l8UfVDLghySBtBtwt00F2n+pDSK/rRd5Slv9IiCTyw9l6e2ei3fI4lQqCHacHjX 184w8M+wB4pU5fQXs3Fnn0FIL56KY1eMYRM3ldrVZEwBmCyc5SZmIzLb6qBAEmZSKUE 185y8+/r58M2EMWfdmgQje4Pez5gS1KCc5pFJmVkmm6T58EBa+nfEuTRJD7AHMfDocc 186Ux/bSMezj5SiBuJmjTUWP29T+U0/Q6wLf9lBhbN8bjO2MZn8zt3EIi1l3JfoViCo 187gNIetioZ58v7/yb2UzcvI1Lr14nneCL35o77yxUlT055gXJs 188-----END CERTIFICATE----- 189 190Certificate: 191 Data: 192 Version: 3 (0x2) 193 Serial Number: 194 7d:8c:81:7c:3f:7c:cd:c0:85:4b:99:ee:b9:df:b6:b1:07:4e:88:44 195 Signature Algorithm: sha256WithRSAEncryption 196 Issuer: CN=Root 197 Validity 198 Not Before: Oct 5 12:00:00 2021 GMT 199 Not After : Oct 5 12:00:00 2022 GMT 200 Subject: CN=Root 201 Subject Public Key Info: 202 Public Key Algorithm: rsaEncryption 203 RSA Public-Key: (2048 bit) 204 Modulus: 205 00:ba:f9:00:80:eb:0d:65:6c:30:78:a7:66:72:14: 206 df:06:ab:f7:a6:30:bc:62:50:81:94:e1:45:f7:47: 207 38:1f:35:99:9a:b9:26:e5:7b:32:a3:71:df:02:84: 208 22:a0:09:32:13:6b:05:5a:8c:3b:2a:59:1a:89:0e: 209 08:58:d0:a5:74:bf:96:7a:16:67:00:22:23:7c:07: 210 37:f8:da:e3:7c:8e:a2:d6:81:18:fb:51:b1:f5:e5: 211 0d:c5:28:4f:17:59:25:42:08:e8:f0:14:1d:8d:03: 212 d7:1c:48:94:f3:2f:70:2d:c4:03:7c:06:c5:ca:dd: 213 15:d3:1b:d4:c8:e4:af:e7:c0:a9:90:f9:a4:c6:d3: 214 e6:28:0f:b0:34:a4:aa:7b:a6:df:45:2e:8f:cc:ba: 215 e1:86:e6:98:74:22:07:cd:33:a3:8e:d3:79:5a:28: 216 a1:d4:a1:e6:b2:7d:c3:6d:9c:61:67:ce:ca:74:b6: 217 6f:d7:32:4c:c9:f8:d8:f2:f0:60:97:3d:2b:e2:b4: 218 67:6c:69:08:23:bd:8a:71:65:a9:3e:62:7f:15:76: 219 08:0e:cb:a9:b2:68:51:5e:5c:19:b0:83:8f:41:98: 220 d8:b1:0e:ef:26:ac:c5:f7:e6:34:8d:71:5f:1e:bd: 221 d4:db:c5:69:47:47:7c:91:88:d0:8b:c4:e1:7a:61: 222 a4:45 223 Exponent: 65537 (0x10001) 224 X509v3 extensions: 225 X509v3 Subject Key Identifier: 226 FA:79:49:F6:69:64:80:41:9B:1E:E6:2C:39:F8:36:2C:0F:F4:82:66 227 X509v3 Authority Key Identifier: 228 keyid:FA:79:49:F6:69:64:80:41:9B:1E:E6:2C:39:F8:36:2C:0F:F4:82:66 229 230 Authority Information Access: 231 CA Issuers - URI:http://url-for-aia/Root.cer 232 233 X509v3 CRL Distribution Points: 234 235 Full Name: 236 URI:http://url-for-crl/Root.crl 237 238 X509v3 Key Usage: critical 239 Certificate Sign, CRL Sign 240 X509v3 Basic Constraints: critical 241 CA:TRUE 242 Signature Algorithm: sha256WithRSAEncryption 243 56:35:08:8f:8b:5e:ea:62:f3:6f:49:49:c3:45:54:12:cd:de: 244 ba:f2:66:12:99:c3:1f:01:bd:ac:08:3a:5e:12:3e:63:c5:b9: 245 1f:05:81:3a:05:90:9b:d1:52:4a:bc:d2:61:2b:88:03:9b:03: 246 5b:4c:da:04:c2:57:6a:e9:d9:ef:a4:50:d0:ae:af:99:0b:4a: 247 98:e9:91:9a:4b:0c:3f:34:bb:c6:dd:c0:31:ba:28:1b:32:e9: 248 12:48:90:3a:ec:cf:e1:82:95:34:93:02:69:c1:75:ba:57:3f: 249 22:e2:76:f1:fa:8d:dd:d1:e2:ed:74:f4:69:c4:2c:79:ba:a7: 250 86:e2:5c:fb:ab:2f:e6:67:b8:46:01:ab:23:d3:77:3b:1f:47: 251 7b:a1:e0:66:7a:1f:c8:d8:b8:f1:91:94:70:4d:9a:c7:f6:ec: 252 a8:c5:b5:87:f6:df:5e:b0:6f:8f:6c:c8:18:6c:62:13:8a:ee: 253 81:ff:7b:02:54:ab:e4:19:58:f5:57:e7:74:00:9b:e1:45:ac: 254 1b:ef:89:c2:f9:e2:73:20:ba:ab:48:36:a3:d5:a4:a1:9e:1a: 255 22:82:08:b0:9e:0d:46:dc:d2:4c:06:e2:80:b5:40:ef:c1:23: 256 99:f7:79:62:5f:19:5b:1c:01:3c:70:0a:5f:d3:c4:43:ee:21: 257 8a:dc:d3:ba 258-----BEGIN CERTIFICATE----- 259MIIDeDCCAmCgAwIBAgIUfYyBfD98zcCFS5nuud+2sQdOiEQwDQYJKoZIhvcNAQEL 260BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 261MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK 262AoIBAQC6+QCA6w1lbDB4p2ZyFN8Gq/emMLxiUIGU4UX3RzgfNZmauSblezKjcd8C 263hCKgCTITawVajDsqWRqJDghY0KV0v5Z6FmcAIiN8Bzf42uN8jqLWgRj7UbH15Q3F 264KE8XWSVCCOjwFB2NA9ccSJTzL3AtxAN8BsXK3RXTG9TI5K/nwKmQ+aTG0+YoD7A0 265pKp7pt9FLo/MuuGG5ph0IgfNM6OO03laKKHUoeayfcNtnGFnzsp0tm/XMkzJ+Njy 2668GCXPSvitGdsaQgjvYpxZak+Yn8VdggOy6myaFFeXBmwg49BmNixDu8mrMX35jSN 267cV8evdTbxWlHR3yRiNCLxOF6YaRFAgMBAAGjgcswgcgwHQYDVR0OBBYEFPp5SfZp 268ZIBBmx7mLDn4NiwP9IJmMB8GA1UdIwQYMBaAFPp5SfZpZIBBmx7mLDn4NiwP9IJm 269MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh 270L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S 271b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG 2729w0BAQsFAAOCAQEAVjUIj4te6mLzb0lJw0VUEs3euvJmEpnDHwG9rAg6XhI+Y8W5 273HwWBOgWQm9FSSrzSYSuIA5sDW0zaBMJXaunZ76RQ0K6vmQtKmOmRmksMPzS7xt3A 274MbooGzLpEkiQOuzP4YKVNJMCacF1ulc/IuJ28fqN3dHi7XT0acQsebqnhuJc+6sv 2755me4RgGrI9N3Ox9He6HgZnofyNi48ZGUcE2ax/bsqMW1h/bfXrBvj2zIGGxiE4ru 276gf97AlSr5BlY9VfndACb4UWsG++JwvnicyC6q0g2o9WkoZ4aIoIIsJ4NRtzSTAbi 277gLVA78Ejmfd5Yl8ZWxwBPHAKX9PEQ+4hitzTug== 278-----END CERTIFICATE----- 279