[Created by: ./generate-chains.py] Certificate chain where the leaf has a basic constraints extension with CA=true Certificate: Data: Version: 3 (0x2) Serial Number: 08:bc:87:56:5b:c5:c0:7d:88:48:cc:cc:ca:97:dd:d6:7e:b8:ae:e7 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Intermediate Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Target Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:be:16:a4:92:0f:af:f6:da:90:19:3e:26:29:a9: 04:35:24:67:db:93:b7:89:61:5c:c2:84:07:ff:db: 83:9a:1b:5c:9d:2f:ac:f6:20:87:74:fd:5a:f7:96: da:aa:8b:77:d0:7d:cb:87:cf:96:37:2d:04:ef:19: f7:09:6d:aa:73:74:16:b9:1c:f1:7b:15:9f:50:a9: be:33:08:86:9f:88:9e:0c:b4:3b:2a:98:06:43:0f: bb:14:ac:65:27:0f:c1:6c:58:d0:54:ce:62:89:ed: 03:99:3c:c7:f0:2e:ab:c5:f3:f0:5a:b6:91:68:6f: aa:4b:37:e9:d8:dd:63:0f:6c:a2:0b:f7:72:0e:6f: a3:ee:b9:7e:c7:4b:a4:cd:69:6c:b8:a3:66:14:14: 46:96:95:ca:60:64:af:58:93:0b:a2:d8:17:04:5c: cd:ec:48:85:7a:4b:5b:c2:84:00:52:fa:8f:25:7b: ce:0b:9b:14:a6:21:cc:48:f6:14:d5:c1:1b:3a:8b: ba:ae:ef:15:55:0d:63:4d:f6:ea:f1:ca:1c:11:04: 3a:c9:f8:87:13:c2:8f:cb:f1:1d:18:79:2f:66:1d: 10:45:2d:4c:55:49:4c:3b:68:28:25:4a:8b:99:a9: 8d:27:66:86:71:4a:6d:f1:f8:fb:58:7e:db:3b:2d: 9e:8b Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: F8:96:4F:23:BA:6B:B3:8F:4B:07:6E:24:86:07:55:F1:E9:8E:6E:02 X509v3 Authority Key Identifier: 0D:33:4F:98:F6:3C:94:C8:20:5B:51:C9:BD:ED:09:3B:F0:B4:F3:D6 Authority Information Access: CA Issuers - URI:http://url-for-aia/Intermediate.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Intermediate.crl X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption Signature Value: 2f:f3:3e:5f:9a:ed:43:1c:58:2e:15:aa:94:d8:d7:37:87:83: 79:ff:a8:7d:d2:bf:3d:4d:3c:99:91:78:93:84:7b:ce:1e:07: 55:f8:bd:5d:d1:e6:82:c4:a9:c0:6b:bf:e4:73:df:d0:b6:38: 09:66:84:23:50:e3:16:37:15:88:89:78:08:31:7d:52:e0:56: a2:2d:ef:a6:75:5a:a3:44:c5:ae:23:a3:fc:92:81:b6:cf:3f: bc:ba:a1:4d:da:6d:0a:18:04:95:7a:4f:b3:74:e7:1b:19:97: fd:c3:32:c3:77:17:15:7a:d5:9b:6c:54:9c:16:1b:3f:37:3e: b9:ed:97:69:f9:da:3d:cf:e4:aa:2a:39:45:28:2b:2e:4e:d7: 60:bb:fd:cb:3d:c2:19:85:e0:f6:1d:1e:bb:21:4c:f4:ee:a1: cf:dc:c9:24:53:cb:80:44:5f:d3:cf:83:09:90:17:1c:32:a8: c5:49:c1:c9:e6:28:f0:88:7d:36:d1:fe:0b:dc:a9:3f:79:ae: c9:89:4c:04:ec:49:ac:6d:58:24:67:20:d3:8f:29:c1:87:84: 2f:69:4f:da:18:7d:f6:a0:88:92:ea:db:47:8d:f0:b3:a3:c9: 15:6a:c8:e5:84:79:74:cd:e1:ee:fa:02:79:05:1f:5c:76:4a: 71:ae:58:b8 -----BEGIN CERTIFICATE----- MIIDsTCCApmgAwIBAgIUCLyHVlvFwH2ISMzMypfd1n64rucwDQYJKoZIhvcNAQEL BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEAvhakkg+v9tqQGT4mKakENSRn25O3iWFcwoQH/9uDmhtc nS+s9iCHdP1a95baqot30H3Lh8+WNy0E7xn3CW2qc3QWuRzxexWfUKm+MwiGn4ie DLQ7KpgGQw+7FKxlJw/BbFjQVM5iie0DmTzH8C6rxfPwWraRaG+qSzfp2N1jD2yi C/dyDm+j7rl+x0ukzWlsuKNmFBRGlpXKYGSvWJMLotgXBFzN7EiFektbwoQAUvqP JXvOC5sUpiHMSPYU1cEbOou6ru8VVQ1jTfbq8cocEQQ6yfiHE8KPy/EdGHkvZh0Q RS1MVUlMO2goJUqLmamNJ2aGcUpt8fj7WH7bOy2eiwIDAQABo4H6MIH3MB0GA1Ud DgQWBBT4lk8jumuzj0sHbiSGB1Xx6Y5uAjAfBgNVHSMEGDAWgBQNM0+Y9jyUyCBb Ucm97Qk78LTz1jA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwEB /zANBgkqhkiG9w0BAQsFAAOCAQEAL/M+X5rtQxxYLhWqlNjXN4eDef+ofdK/PU08 mZF4k4R7zh4HVfi9XdHmgsSpwGu/5HPf0LY4CWaEI1DjFjcViIl4CDF9UuBWoi3v pnVao0TFriOj/JKBts8/vLqhTdptChgElXpPs3TnGxmX/cMyw3cXFXrVm2xUnBYb Pzc+ue2XafnaPc/kqio5RSgrLk7XYLv9yz3CGYXg9h0euyFM9O6hz9zJJFPLgERf 08+DCZAXHDKoxUnByeYo8Ih9NtH+C9ypP3muyYlMBOxJrG1YJGcg048pwYeEL2lP 2hh99qCIkurbR43ws6PJFWrI5YR5dM3h7voCeQUfXHZKca5YuA== -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 02:6e:e9:d7:f8:5d:44:ad:34:05:15:23:70:65:9e:cc:e0:a7:66:53 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Intermediate Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:c5:8c:3e:44:f5:7d:89:d5:8d:77:86:f9:d5:a0: 8b:dc:1d:0f:3e:d0:f8:d1:72:c4:5b:d0:83:56:b5: 98:0c:4e:0c:3d:48:f7:db:06:e8:c2:eb:5c:fc:f4: 2f:b0:23:74:fc:95:23:0c:7d:3d:be:29:89:6f:d5: 97:d3:8b:6f:bf:36:4d:99:4e:c9:fe:59:a2:9a:56: df:3c:a6:e0:f4:8e:2b:20:00:4a:4d:6e:15:c9:7f: c0:35:8f:5a:48:08:0b:41:d1:cf:84:c0:fd:99:71: 26:96:7b:b5:6f:1d:ce:db:74:b1:d3:1d:39:37:70: d0:e1:53:d5:44:72:e2:80:c2:bb:c7:71:93:4e:02: 40:ac:a0:af:33:72:a1:6d:9a:44:9b:45:ad:22:74: fc:18:74:e0:84:34:00:00:76:46:2a:77:f9:ff:a8: af:71:b9:e6:e6:32:9a:d4:d2:a7:dd:71:f9:2a:49: 2a:fe:c2:8e:cf:9c:77:f7:39:7d:d3:99:09:b1:49: 30:35:e5:8d:3a:c3:3e:6c:1d:d6:b7:26:bb:90:e4: 3b:c3:2e:aa:37:18:bb:28:f3:79:d2:69:9c:87:7f: 78:5f:c5:97:d1:d8:45:14:17:38:6d:66:23:2e:90: dd:25:c1:60:3c:7c:f5:9a:d2:16:05:c0:7f:89:3e: 10:87 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 0D:33:4F:98:F6:3C:94:C8:20:5B:51:C9:BD:ED:09:3B:F0:B4:F3:D6 X509v3 Authority Key Identifier: 7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption Signature Value: 76:1d:d7:22:f9:e8:d8:a6:ec:b0:bf:06:92:7c:2a:82:cd:8a: 7b:13:bd:c6:d9:da:4b:b3:94:12:82:59:a8:16:76:c1:05:c0: 7e:7d:19:b4:8f:35:c7:58:73:ff:7d:9e:8c:55:6f:0b:b3:e3: 5f:d0:e8:57:c0:92:6c:47:a7:55:84:77:90:19:c1:67:1f:8a: 32:70:0c:3e:de:01:6f:c6:79:1e:a0:10:15:a2:ec:f6:1a:19: 10:ac:aa:bf:63:0b:52:88:3d:61:5e:e9:6b:76:4d:b1:f5:16: a7:09:4f:68:67:1b:47:b5:62:37:b2:6b:66:e0:e7:51:86:50: 32:54:b7:b7:e8:77:5c:d8:ff:8d:3b:6e:49:ac:5c:ce:33:38: 52:0f:41:80:1d:b0:fd:35:8d:37:23:06:e3:1c:89:f4:d3:6c: 73:d0:d3:8f:72:db:9a:7a:34:40:54:77:97:ae:9f:5b:4d:d8: 94:99:a7:89:11:04:bb:52:06:ba:32:fd:f9:16:b7:ee:a6:03: 55:39:31:4f:89:3b:9c:9b:d3:61:4b:a0:f2:ab:24:ad:95:46: 2e:5e:27:be:03:f2:e0:4d:70:27:63:9a:c1:f9:1b:00:ab:6b: de:e7:f1:04:a7:b5:bd:85:31:a6:32:4b:0e:e8:a5:ab:8d:c1: 52:19:f2:b6 -----BEGIN CERTIFICATE----- MIIDgDCCAmigAwIBAgIUAm7p1/hdRK00BRUjcGWezOCnZlMwDQYJKoZIhvcNAQEL BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBAMWMPkT1fYnVjXeG+dWgi9wdDz7Q+NFyxFvQg1a1mAxODD1I 99sG6MLrXPz0L7AjdPyVIwx9Pb4piW/Vl9OLb782TZlOyf5ZoppW3zym4PSOKyAA Sk1uFcl/wDWPWkgIC0HRz4TA/ZlxJpZ7tW8dztt0sdMdOTdw0OFT1URy4oDCu8dx k04CQKygrzNyoW2aRJtFrSJ0/Bh04IQ0AAB2Rip3+f+or3G55uYymtTSp91x+SpJ Kv7Cjs+cd/c5fdOZCbFJMDXljTrDPmwd1rcmu5DkO8MuqjcYuyjzedJpnId/eF/F l9HYRRQXOG1mIy6Q3SXBYDx89ZrSFgXAf4k+EIcCAwEAAaOByzCByDAdBgNVHQ4E FgQUDTNPmPY8lMggW1HJve0JO/C089YwHwYDVR0jBBgwFoAUepipP7qA3WgbHIdX LkI/X7NQXagwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ MA0GCSqGSIb3DQEBCwUAA4IBAQB2Hdci+ejYpuywvwaSfCqCzYp7E73G2dpLs5QS glmoFnbBBcB+fRm0jzXHWHP/fZ6MVW8Ls+Nf0OhXwJJsR6dVhHeQGcFnH4oycAw+ 3gFvxnkeoBAVouz2GhkQrKq/YwtSiD1hXulrdk2x9RanCU9oZxtHtWI3smtm4OdR hlAyVLe36Hdc2P+NO25JrFzOMzhSD0GAHbD9NY03IwbjHIn002xz0NOPctuaejRA VHeXrp9bTdiUmaeJEQS7Uga6Mv35FrfupgNVOTFPiTucm9NhS6DyqyStlUYuXie+ A/LgTXAnY5rB+RsAq2ve5/EEp7W9hTGmMksO6KWrjcFSGfK2 -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 02:6e:e9:d7:f8:5d:44:ad:34:05:15:23:70:65:9e:cc:e0:a7:66:52 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Oct 5 12:00:00 2021 GMT Not After : Oct 5 12:00:00 2022 GMT Subject: CN=Root Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:af:0c:3f:db:02:4b:9e:87:03:a5:64:a7:18:9a: c1:4c:c8:bf:1b:e7:5a:04:52:70:6c:a2:bc:19:99: 33:44:f9:9a:6b:30:d8:57:5b:be:a0:dc:8c:97:91: 20:97:f8:04:ef:21:1d:b1:c7:a3:1b:57:02:c9:bd: 53:54:f8:58:96:f3:c2:d7:5e:ae:61:c1:d5:08:ff: 88:bf:80:c1:ef:c8:6d:99:ac:8e:55:f6:e0:da:8f: f3:31:f1:e5:02:82:2c:f9:42:cb:7c:4c:2b:ba:97: eb:ef:cd:b0:d5:31:a1:09:f8:5e:62:74:4e:29:02: 9b:7e:de:0b:31:36:b6:fd:36:e5:a6:a8:ac:05:1f: 5f:32:e6:60:f7:5f:8f:f3:a5:6e:3d:c4:ec:dd:23: ac:4b:69:ab:df:41:65:2b:bd:f2:ed:51:e0:94:e4: 5f:35:6c:be:c8:be:2a:10:27:55:92:6b:82:ac:72: b7:c4:de:47:04:03:6c:57:fd:de:f1:17:3b:16:0c: d7:cd:26:28:84:b2:df:19:e7:2f:45:87:2f:91:82: d5:21:4b:0a:49:77:a0:46:39:2d:fc:ab:63:1f:76: 2d:c1:4a:03:1c:d8:e0:dc:a3:4d:c8:56:aa:41:1c: e9:11:63:10:c6:55:03:4e:c8:be:53:7e:3c:a9:d7: 13:af Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8 X509v3 Authority Key Identifier: 7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption Signature Value: 07:9d:ea:d3:5a:05:0f:1d:14:12:d4:a3:1f:1e:29:e7:5b:8c: 8f:9f:3e:b9:f3:85:d2:5e:73:9c:41:7c:81:bf:75:fe:61:49: dd:d9:69:95:43:4c:46:8d:b7:49:1b:b8:4e:a0:e8:f7:ab:dc: c1:6c:85:43:4b:f1:94:a0:3c:b6:06:db:20:70:fe:cb:b4:a3: ee:d3:12:93:70:c1:c1:97:30:8e:78:7a:7e:31:f6:35:d4:b6: e8:f4:9e:1c:11:c9:5b:51:8b:18:da:c3:65:48:d8:0c:9d:7e: 73:27:26:b1:3c:25:b2:9c:12:79:a8:3e:37:18:14:ca:a9:33: 78:17:03:12:bd:42:48:6f:78:0a:4f:8d:b5:c0:88:c4:d2:a5: 99:84:2b:a5:d9:40:85:65:67:aa:12:74:4f:c9:b6:0a:64:17: d7:af:51:3b:13:08:70:ce:65:af:36:59:46:32:b3:40:45:c3: 1a:8b:56:3e:2b:81:5d:81:48:a6:f9:8e:5b:26:c2:1a:1a:68: 57:a1:22:8a:42:2e:9a:51:8c:18:f8:fe:d6:a4:89:b5:7d:64: 14:5b:b1:5d:26:92:f1:17:54:8a:bb:e6:d7:97:82:6c:e1:b4: 39:42:68:d1:69:64:a9:21:1c:28:e1:ae:bd:eb:09:78:76:c9: 7f:cd:79:90 -----BEGIN CERTIFICATE----- MIIDeDCCAmCgAwIBAgIUAm7p1/hdRK00BRUjcGWezOCnZlIwDQYJKoZIhvcNAQEL BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQCvDD/bAkuehwOlZKcYmsFMyL8b51oEUnBsorwZmTNE+ZprMNhXW76g3IyX kSCX+ATvIR2xx6MbVwLJvVNU+FiW88LXXq5hwdUI/4i/gMHvyG2ZrI5V9uDaj/Mx 8eUCgiz5Qst8TCu6l+vvzbDVMaEJ+F5idE4pApt+3gsxNrb9NuWmqKwFH18y5mD3 X4/zpW49xOzdI6xLaavfQWUrvfLtUeCU5F81bL7IvioQJ1WSa4KscrfE3kcEA2xX /d7xFzsWDNfNJiiEst8Z5y9Fhy+RgtUhSwpJd6BGOS38q2Mfdi3BSgMc2ODco03I VqpBHOkRYxDGVQNOyL5Tfjyp1xOvAgMBAAGjgcswgcgwHQYDVR0OBBYEFHqYqT+6 gN1oGxyHVy5CP1+zUF2oMB8GA1UdIwQYMBaAFHqYqT+6gN1oGxyHVy5CP1+zUF2o MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG 9w0BAQsFAAOCAQEAB53q01oFDx0UEtSjHx4p51uMj58+ufOF0l5znEF8gb91/mFJ 3dlplUNMRo23SRu4TqDo96vcwWyFQ0vxlKA8tgbbIHD+y7Sj7tMSk3DBwZcwjnh6 fjH2NdS26PSeHBHJW1GLGNrDZUjYDJ1+cycmsTwlspwSeag+NxgUyqkzeBcDEr1C SG94Ck+NtcCIxNKlmYQrpdlAhWVnqhJ0T8m2CmQX169ROxMIcM5lrzZZRjKzQEXD GotWPiuBXYFIpvmOWybCGhpoV6EiikIumlGMGPj+1qSJtX1kFFuxXSaS8RdUirvm 15eCbOG0OUJo0WlkqSEcKOGuvesJeHbJf815kA== -----END CERTIFICATE-----