• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1[Created by: generate-chains.py]
2
3Certificate chain where the leaf has a basic constraints extension with
4CA=false, however specifies the optional pathlen.
5
6Certificate:
7    Data:
8        Version: 3 (0x2)
9        Serial Number:
10            2d:58:fd:1c:9f:8b:f0:cb:61:00:36:cc:88:b7:31:82:91:15:f5:15
11        Signature Algorithm: sha256WithRSAEncryption
12        Issuer: CN=Intermediate
13        Validity
14            Not Before: Oct  5 12:00:00 2021 GMT
15            Not After : Oct  5 12:00:00 2022 GMT
16        Subject: CN=Target
17        Subject Public Key Info:
18            Public Key Algorithm: rsaEncryption
19                RSA Public-Key: (2048 bit)
20                Modulus:
21                    00:ba:80:5c:f0:d7:23:f0:69:d9:b7:8f:fc:c3:d4:
22                    47:a2:41:29:77:01:50:3c:84:8f:52:f7:11:6d:c4:
23                    75:04:84:48:98:8c:4e:bb:f6:4b:e2:cb:4d:be:01:
24                    dc:b2:8e:48:b6:da:76:4d:b0:28:75:94:28:d7:44:
25                    2c:0d:a5:70:fe:b8:ec:c3:d0:0d:8b:74:4a:18:b9:
26                    13:bb:b1:99:80:09:d0:bd:00:a3:20:64:70:bb:18:
27                    00:7c:61:1f:5d:d2:dc:23:6a:6a:e3:8a:6c:13:9b:
28                    a3:c5:7b:dc:91:71:29:46:4e:1c:8e:82:2a:d6:bb:
29                    f9:5a:91:be:f0:a7:a9:b2:d5:8c:df:a2:d2:eb:3a:
30                    e4:49:30:8b:83:20:6d:fb:af:90:19:3e:44:b5:d3:
31                    bb:05:a1:15:a1:0d:4c:61:82:63:5e:24:a5:94:df:
32                    a9:35:5a:0f:56:eb:8c:1d:a5:0e:80:4a:16:d1:ef:
33                    dd:cf:84:f6:45:55:65:55:b8:73:ae:ca:1c:f8:c7:
34                    e2:67:e8:8a:42:5e:eb:f6:2c:bf:55:1c:18:39:51:
35                    5b:15:16:1b:0a:06:ba:b0:ad:bc:45:2d:23:5c:3a:
36                    ca:2b:04:c9:a2:4f:a6:80:ec:d2:b8:d7:98:44:69:
37                    3c:3c:2e:ab:b4:44:e2:50:6a:b8:a6:59:db:d4:61:
38                    54:fd
39                Exponent: 65537 (0x10001)
40        X509v3 extensions:
41            X509v3 Subject Key Identifier:
42                5B:3D:C4:92:95:A9:93:D8:29:1F:56:EB:DA:A0:3C:1A:C0:BD:5D:AB
43            X509v3 Authority Key Identifier:
44                keyid:FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E
45
46            Authority Information Access:
47                CA Issuers - URI:http://url-for-aia/Intermediate.cer
48
49            X509v3 CRL Distribution Points:
50
51                Full Name:
52                  URI:http://url-for-crl/Intermediate.crl
53
54            X509v3 Key Usage: critical
55                Digital Signature, Key Encipherment
56            X509v3 Extended Key Usage:
57                TLS Web Server Authentication, TLS Web Client Authentication
58            X509v3 Basic Constraints: critical
59                CA:FALSE, pathlen:1
60    Signature Algorithm: sha256WithRSAEncryption
61         18:c7:ef:53:96:6c:fc:7d:06:87:5a:b7:cc:77:67:82:54:10:
62         eb:8e:21:a6:57:f3:83:cf:ee:ba:c0:59:cc:95:d3:1b:2a:92:
63         19:86:20:ee:7a:62:5c:cb:27:b9:71:22:a8:bb:f2:26:f6:15:
64         a7:5a:57:79:d1:d0:4a:06:17:4f:95:f9:37:ab:13:6e:dd:57:
65         3c:87:5e:dd:69:be:53:3a:51:3e:fc:7c:38:75:e3:20:cd:34:
66         0f:23:d1:35:c2:00:03:9e:64:51:00:1d:e1:56:04:9a:6c:73:
67         bd:fb:e3:f0:63:f3:11:04:59:83:42:19:7e:1d:a5:25:25:e0:
68         12:9c:60:87:07:6d:a7:99:3d:24:1f:dd:a6:c7:f7:dd:34:d9:
69         be:96:9c:e7:5a:21:f8:6b:8e:1b:77:7c:d8:04:6d:e4:7c:7a:
70         fd:ba:44:4a:13:1d:8c:c0:64:59:de:95:5d:50:3c:13:9d:26:
71         ee:36:08:d0:d0:fc:79:72:e1:af:d1:71:9c:7b:16:14:4b:2d:
72         eb:e7:c2:6d:0a:cd:cd:ff:02:95:ff:60:af:32:42:58:69:8f:
73         08:b1:a3:d6:37:80:6f:ce:93:83:c9:c5:52:8d:60:c3:6c:8c:
74         62:20:7f:75:64:03:10:30:24:34:7b:20:b9:dc:21:83:fc:fa:
75         b9:b5:11:03
76-----BEGIN CERTIFICATE-----
77MIIDsTCCApmgAwIBAgIULVj9HJ+L8MthADbMiLcxgpEV9RUwDQYJKoZIhvcNAQEL
78BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
79MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
80AAOCAQ8AMIIBCgKCAQEAuoBc8Ncj8GnZt4/8w9RHokEpdwFQPISPUvcRbcR1BIRI
81mIxOu/ZL4stNvgHcso5Ittp2TbAodZQo10QsDaVw/rjsw9ANi3RKGLkTu7GZgAnQ
82vQCjIGRwuxgAfGEfXdLcI2pq44psE5ujxXvckXEpRk4cjoIq1rv5WpG+8KepstWM
8336LS6zrkSTCLgyBt+6+QGT5EtdO7BaEVoQ1MYYJjXiSllN+pNVoPVuuMHaUOgEoW
840e/dz4T2RVVlVbhzrsoc+MfiZ+iKQl7r9iy/VRwYOVFbFRYbCga6sK28RS0jXDrK
85KwTJok+mgOzSuNeYRGk8PC6rtETiUGq4plnb1GFU/QIDAQABo4H6MIH3MB0GA1Ud
86DgQWBBRbPcSSlamT2CkfVuvaoDwawL1dqzAfBgNVHSMEGDAWgBT7OkOcukCJclu9
87Joo7JXccwfAsfjA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
88cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
89dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
90oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwIB
91ATANBgkqhkiG9w0BAQsFAAOCAQEAGMfvU5Zs/H0Gh1q3zHdnglQQ644hplfzg8/u
92usBZzJXTGyqSGYYg7npiXMsnuXEiqLvyJvYVp1pXedHQSgYXT5X5N6sTbt1XPIde
933Wm+UzpRPvx8OHXjIM00DyPRNcIAA55kUQAd4VYEmmxzvfvj8GPzEQRZg0IZfh2l
94JSXgEpxghwdtp5k9JB/dpsf33TTZvpac51oh+GuOG3d82ARt5Hx6/bpEShMdjMBk
95Wd6VXVA8E50m7jYI0ND8eXLhr9FxnHsWFEst6+fCbQrNzf8Clf9grzJCWGmPCLGj
961jeAb86Tg8nFUo1gw2yMYiB/dWQDEDAkNHsgudwhg/z6ubURAw==
97-----END CERTIFICATE-----
98
99Certificate:
100    Data:
101        Version: 3 (0x2)
102        Serial Number:
103            7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fe
104        Signature Algorithm: sha256WithRSAEncryption
105        Issuer: CN=Root
106        Validity
107            Not Before: Oct  5 12:00:00 2021 GMT
108            Not After : Oct  5 12:00:00 2022 GMT
109        Subject: CN=Intermediate
110        Subject Public Key Info:
111            Public Key Algorithm: rsaEncryption
112                RSA Public-Key: (2048 bit)
113                Modulus:
114                    00:b1:bb:78:97:4a:b5:56:42:fa:f9:6b:63:6c:f3:
115                    0e:54:92:6c:84:d4:c7:53:48:24:c1:bd:6f:d0:83:
116                    ad:f3:7a:5c:93:f1:74:38:ba:46:f1:19:db:0e:fb:
117                    1b:b4:f2:9e:8b:c4:10:8e:97:b1:ff:f8:2d:03:cd:
118                    36:91:8a:2c:e8:d8:da:a4:7e:58:8d:fb:ff:99:2b:
119                    d5:e1:b3:63:7f:ec:2c:66:b5:0d:ca:ba:e1:74:5e:
120                    b3:ad:bf:49:65:74:52:30:78:ed:ea:7c:08:26:32:
121                    f1:d5:e3:ea:01:7e:3a:fc:0e:84:d6:17:aa:98:f8:
122                    92:63:77:4d:5c:d3:13:61:af:e3:d8:35:0c:ff:1e:
123                    39:91:0c:24:a9:ec:89:ab:28:97:97:56:eb:2a:73:
124                    70:e7:46:17:89:1e:42:73:a5:f6:b6:de:5a:bc:24:
125                    69:5d:41:09:31:f6:12:d3:57:2d:dc:96:9c:0a:4d:
126                    64:f0:c4:24:44:8e:1d:66:37:a1:01:1a:d5:89:a8:
127                    9c:81:82:00:d9:f5:56:e9:58:df:ea:5d:32:7e:fb:
128                    2d:19:1b:39:b4:fb:77:2c:2e:e1:ae:f5:ea:b0:ad:
129                    b7:d4:2e:35:86:26:9f:96:c6:e3:4c:27:7b:6a:7d:
130                    a2:4e:bf:cb:59:33:85:6f:d1:98:e4:27:3c:95:3f:
131                    fd:ad
132                Exponent: 65537 (0x10001)
133        X509v3 extensions:
134            X509v3 Subject Key Identifier:
135                FB:3A:43:9C:BA:40:89:72:5B:BD:26:8A:3B:25:77:1C:C1:F0:2C:7E
136            X509v3 Authority Key Identifier:
137                keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
138
139            Authority Information Access:
140                CA Issuers - URI:http://url-for-aia/Root.cer
141
142            X509v3 CRL Distribution Points:
143
144                Full Name:
145                  URI:http://url-for-crl/Root.crl
146
147            X509v3 Key Usage: critical
148                Certificate Sign, CRL Sign
149            X509v3 Basic Constraints: critical
150                CA:TRUE
151    Signature Algorithm: sha256WithRSAEncryption
152         a9:df:02:10:a3:f8:14:af:a4:b2:3d:bf:3a:5e:e1:0f:9e:fa:
153         e1:d0:5a:be:e8:a4:f4:db:b7:a6:1c:40:7a:06:0a:77:39:6f:
154         f5:b9:7f:3b:5d:61:05:fc:0f:2e:de:40:89:2e:1b:11:12:35:
155         96:44:a8:be:0b:35:f9:73:2f:81:bc:47:5c:01:b2:b8:22:7e:
156         ca:c9:56:54:68:1a:4a:98:ac:6f:43:06:4b:a5:12:4f:05:ec:
157         23:36:a5:5e:8e:a0:36:6b:35:12:e1:76:ad:84:77:af:eb:b6:
158         b8:f6:4b:21:98:53:c2:32:74:03:ff:7f:67:bf:0d:31:58:6b:
159         b5:bd:e7:c5:dc:e3:c4:04:1d:e0:c5:84:d9:6d:74:a3:21:66:
160         5e:99:af:18:9e:db:49:8d:83:92:34:00:a2:e7:89:d2:4b:f5:
161         6a:5e:02:a9:ab:3b:3d:23:01:34:c7:ee:99:3f:0e:75:55:ed:
162         99:c1:28:b1:39:da:2e:25:03:59:82:ed:7a:e8:32:8a:9a:fc:
163         fa:2a:e6:d1:13:0b:2b:9b:d7:a7:3e:23:e2:45:1a:a1:c1:e5:
164         4d:fb:a5:3c:a0:5e:ef:c0:d4:9a:d6:53:e7:4a:48:6c:31:8a:
165         92:60:7d:e8:d4:60:4a:6a:96:b0:f5:c2:a8:83:22:42:e0:1c:
166         aa:15:1b:af
167-----BEGIN CERTIFICATE-----
168MIIDgDCCAmigAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP4wDQYJKoZIhvcNAQEL
169BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
170MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
171ggEPADCCAQoCggEBALG7eJdKtVZC+vlrY2zzDlSSbITUx1NIJMG9b9CDrfN6XJPx
172dDi6RvEZ2w77G7TynovEEI6Xsf/4LQPNNpGKLOjY2qR+WI37/5kr1eGzY3/sLGa1
173Dcq64XRes62/SWV0UjB47ep8CCYy8dXj6gF+OvwOhNYXqpj4kmN3TVzTE2Gv49g1
174DP8eOZEMJKnsiasol5dW6ypzcOdGF4keQnOl9rbeWrwkaV1BCTH2EtNXLdyWnApN
175ZPDEJESOHWY3oQEa1YmonIGCANn1VulY3+pdMn77LRkbObT7dywu4a716rCtt9Qu
176NYYmn5bG40wne2p9ok6/y1kzhW/RmOQnPJU//a0CAwEAAaOByzCByDAdBgNVHQ4E
177FgQU+zpDnLpAiXJbvSaKOyV3HMHwLH4wHwYDVR0jBBgwFoAUj05eeBmuKIJpL88z
178lQTBzXXR9v8wNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
179LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
180b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
181MA0GCSqGSIb3DQEBCwUAA4IBAQCp3wIQo/gUr6SyPb86XuEPnvrh0Fq+6KT027em
182HEB6Bgp3OW/1uX87XWEF/A8u3kCJLhsREjWWRKi+CzX5cy+BvEdcAbK4In7KyVZU
183aBpKmKxvQwZLpRJPBewjNqVejqA2azUS4XathHev67a49kshmFPCMnQD/39nvw0x
184WGu1vefF3OPEBB3gxYTZbXSjIWZema8YnttJjYOSNACi54nSS/VqXgKpqzs9IwE0
185x+6ZPw51Ve2ZwSixOdouJQNZgu166DKKmvz6KubREwsrm9enPiPiRRqhweVN+6U8
186oF7vwNSa1lPnSkhsMYqSYH3o1GBKapaw9cKogyJC4ByqFRuv
187-----END CERTIFICATE-----
188
189Certificate:
190    Data:
191        Version: 3 (0x2)
192        Serial Number:
193            7c:eb:63:f0:f3:c9:2c:8c:45:ed:1d:f4:86:49:1e:61:f3:54:68:fd
194        Signature Algorithm: sha256WithRSAEncryption
195        Issuer: CN=Root
196        Validity
197            Not Before: Oct  5 12:00:00 2021 GMT
198            Not After : Oct  5 12:00:00 2022 GMT
199        Subject: CN=Root
200        Subject Public Key Info:
201            Public Key Algorithm: rsaEncryption
202                RSA Public-Key: (2048 bit)
203                Modulus:
204                    00:b3:59:c0:d6:b0:f3:cb:31:46:9d:ef:de:63:f3:
205                    1a:24:10:36:fb:e8:ee:05:76:21:51:51:fd:52:47:
206                    97:12:13:46:42:bc:94:37:5e:e6:41:d2:d8:75:27:
207                    2c:3d:04:bc:e1:ac:bc:a8:f6:d8:74:63:9a:be:a9:
208                    7b:d2:1b:96:87:25:3b:ce:d1:ff:b4:dd:fa:29:64:
209                    ae:df:4c:1b:b4:fb:9e:8a:9a:6c:74:ba:2a:76:45:
210                    03:b7:91:7e:90:ba:04:3d:dc:0a:17:77:b3:5f:dc:
211                    56:07:eb:63:5e:2b:54:c9:d7:b3:4b:f3:42:6b:9e:
212                    2a:80:9c:71:52:5d:0f:6d:97:c6:d3:f6:c4:7a:7a:
213                    ee:ea:22:4f:1c:e8:42:55:6e:b2:2a:56:cf:86:3c:
214                    94:d1:e7:e0:7c:78:8c:94:05:05:b0:3f:b2:70:18:
215                    da:92:d2:9a:ba:57:7c:fb:52:4b:0f:34:cb:dc:ab:
216                    40:a0:76:4e:cc:11:b9:57:be:f2:e2:fa:2b:ba:20:
217                    b0:c8:ee:8d:0a:11:a2:02:d4:f7:38:3d:f4:a8:49:
218                    f4:b4:8a:08:ff:d0:c3:25:21:0e:dc:f0:17:22:f2:
219                    bf:07:3d:e7:5f:4c:b2:cd:1a:18:f1:fd:3a:5a:42:
220                    79:b3:82:47:ad:ad:e0:02:7f:0b:19:34:5d:3b:90:
221                    81:23
222                Exponent: 65537 (0x10001)
223        X509v3 extensions:
224            X509v3 Subject Key Identifier:
225                8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
226            X509v3 Authority Key Identifier:
227                keyid:8F:4E:5E:78:19:AE:28:82:69:2F:CF:33:95:04:C1:CD:75:D1:F6:FF
228
229            Authority Information Access:
230                CA Issuers - URI:http://url-for-aia/Root.cer
231
232            X509v3 CRL Distribution Points:
233
234                Full Name:
235                  URI:http://url-for-crl/Root.crl
236
237            X509v3 Key Usage: critical
238                Certificate Sign, CRL Sign
239            X509v3 Basic Constraints: critical
240                CA:TRUE
241    Signature Algorithm: sha256WithRSAEncryption
242         70:f6:5a:6d:fe:7b:04:4d:4f:e1:d2:c5:92:07:20:6d:68:d3:
243         86:51:6c:60:3a:07:0a:1b:27:7d:99:88:db:01:a6:0e:f0:3a:
244         3d:a2:37:0e:bd:32:48:e1:36:3c:ac:a3:89:2f:33:d0:ab:ba:
245         7a:90:db:28:61:3d:7b:b5:4b:cd:df:3d:20:c6:a1:fb:81:ec:
246         69:2a:f8:c3:4c:c6:48:87:39:34:84:3e:4d:2d:eb:c9:dd:26:
247         70:8b:71:23:8c:0d:d1:fd:5b:0e:0e:58:86:20:0c:4e:aa:a1:
248         d1:b0:e9:56:bf:9f:9a:4d:a8:0d:76:6a:48:a2:dd:19:92:25:
249         93:7f:90:8f:a2:c0:ac:1d:d3:63:17:d6:a5:07:98:27:cb:a7:
250         44:60:17:aa:f2:22:0f:0d:c9:7d:58:1c:00:54:e6:99:84:d3:
251         a0:6e:e9:fb:8d:97:21:24:79:c4:b8:23:81:2c:65:da:cc:0e:
252         09:9c:82:8a:23:74:54:10:56:e4:a2:f0:e8:ce:8f:d5:cf:03:
253         d9:0e:37:f3:86:66:e0:4e:c0:55:fc:e1:1b:7b:cc:8a:ad:41:
254         2f:7b:02:4a:42:f1:e4:b9:4e:86:f3:30:bb:8a:bf:f2:79:c7:
255         5d:68:02:b5:fb:40:cf:3f:5d:55:55:58:05:ef:95:34:ee:ea:
256         3e:6e:91:59
257-----BEGIN CERTIFICATE-----
258MIIDeDCCAmCgAwIBAgIUfOtj8PPJLIxF7R30hkkeYfNUaP0wDQYJKoZIhvcNAQEL
259BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
260MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
261AoIBAQCzWcDWsPPLMUad795j8xokEDb76O4FdiFRUf1SR5cSE0ZCvJQ3XuZB0th1
262Jyw9BLzhrLyo9th0Y5q+qXvSG5aHJTvO0f+03fopZK7fTBu0+56Kmmx0uip2RQO3
263kX6QugQ93AoXd7Nf3FYH62NeK1TJ17NL80JrniqAnHFSXQ9tl8bT9sR6eu7qIk8c
2646EJVbrIqVs+GPJTR5+B8eIyUBQWwP7JwGNqS0pq6V3z7UksPNMvcq0Cgdk7MEblX
265vvLi+iu6ILDI7o0KEaIC1Pc4PfSoSfS0igj/0MMlIQ7c8Bci8r8HPedfTLLNGhjx
266/TpaQnmzgketreACfwsZNF07kIEjAgMBAAGjgcswgcgwHQYDVR0OBBYEFI9OXngZ
267riiCaS/PM5UEwc110fb/MB8GA1UdIwQYMBaAFI9OXngZriiCaS/PM5UEwc110fb/
268MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
269L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
270b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
2719w0BAQsFAAOCAQEAcPZabf57BE1P4dLFkgcgbWjThlFsYDoHChsnfZmI2wGmDvA6
272PaI3Dr0ySOE2PKyjiS8z0Ku6epDbKGE9e7VLzd89IMah+4HsaSr4w0zGSIc5NIQ+
273TS3ryd0mcItxI4wN0f1bDg5YhiAMTqqh0bDpVr+fmk2oDXZqSKLdGZIlk3+Qj6LA
274rB3TYxfWpQeYJ8unRGAXqvIiDw3JfVgcAFTmmYTToG7p+42XISR5xLgjgSxl2swO
275CZyCiiN0VBBW5KLw6M6P1c8D2Q4384Zm4E7AVfzhG3vMiq1BL3sCSkLx5LlOhvMw
276u4q/8nnHXWgCtftAzz9dVVVYBe+VNO7qPm6RWQ==
277-----END CERTIFICATE-----
278