| [Created by: generate-chains.py] |
| |
| Certificate chain where the intermediate has a policies extension marked as |
| critical, and contains an unknown policy qualifer (1.2.3.4). |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 11:0a:fc:bd:a1:b1:c5:a4:95:da:e7:62:79:b3:82:f3:22:28:98:e5 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Intermediate |
| Validity |
| Not Before: Oct 5 12:00:00 2021 GMT |
| Not After : Oct 5 12:00:00 2022 GMT |
| Subject: CN=Target |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| RSA Public-Key: (2048 bit) |
| Modulus: |
| 00:c1:03:58:01:b1:2f:7b:fb:b2:71:dc:49:d0:cb: |
| 06:76:30:64:f7:61:bf:da:55:93:73:29:49:0f:cb: |
| 0a:33:bd:41:0b:28:03:45:35:72:a9:b4:4b:a7:ec: |
| 52:77:3a:8c:ba:cb:87:56:28:3b:39:8d:47:7b:70: |
| 7f:5a:8f:76:8c:7e:13:e8:61:17:19:1d:72:e3:6e: |
| 69:20:bc:83:f7:5b:11:85:6e:1a:b8:fb:7b:f8:fe: |
| 2b:e2:d2:bd:1a:0a:65:62:b0:84:a7:0a:ac:75:ea: |
| e6:74:c4:1d:2c:e8:04:62:76:4b:4d:04:b6:52:2f: |
| a6:ba:66:bb:fe:45:d6:6a:21:05:16:e5:f3:25:ae: |
| 94:fd:17:84:80:2f:ac:62:d9:83:e3:17:b0:03:1c: |
| 01:02:8b:47:7f:65:2e:f9:40:cf:ad:92:33:07:8a: |
| 14:44:5e:c2:ed:68:48:a4:d1:f0:7b:f9:67:91:28: |
| d9:9f:2c:f0:5e:12:92:52:92:97:27:7b:12:dd:c5: |
| d5:7f:32:8c:9b:26:05:eb:47:e1:26:99:ea:6a:a9: |
| 25:93:64:31:e5:6c:f4:cf:02:27:29:b3:9f:17:94: |
| 0d:38:9c:54:f1:80:ef:b9:b0:4b:6a:12:eb:ca:53: |
| 91:2a:95:ee:16:bf:12:9f:8a:32:a7:8a:81:dd:4c: |
| 02:91 |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| EF:56:67:1C:5E:24:60:78:3E:F2:35:40:2E:1A:58:65:4D:B3:4E:BE |
| X509v3 Authority Key Identifier: |
| keyid:47:8C:F1:C9:1E:F8:EC:25:A8:31:F3:1C:CE:BC:C5:70:9F:11:87:63 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Intermediate.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Intermediate.crl |
| |
| X509v3 Key Usage: critical |
| Digital Signature, Key Encipherment |
| X509v3 Extended Key Usage: |
| TLS Web Server Authentication, TLS Web Client Authentication |
| Signature Algorithm: sha256WithRSAEncryption |
| 07:fb:42:4a:92:11:ca:8f:d6:40:8b:92:3a:09:71:d7:28:a4: |
| a3:9b:6b:de:b0:c1:e5:17:17:66:bf:97:db:a8:5e:fd:af:4a: |
| 61:11:01:26:22:7b:dd:f7:e9:15:a4:68:91:c0:f8:34:e9:4a: |
| 56:e2:d1:94:e2:a1:37:ae:76:f8:e2:88:f8:13:2b:aa:58:aa: |
| cd:b9:d5:a8:1d:b8:04:ef:70:9e:36:c4:ee:1c:94:cd:f6:f0: |
| 4f:6a:db:89:59:7e:8f:69:41:92:47:41:7f:f5:5d:1e:a7:d9: |
| 76:d1:7c:e1:51:5d:af:53:ae:34:e6:36:47:e3:44:11:ac:12: |
| 23:1f:48:d2:87:68:91:9b:4d:3a:d7:f4:c2:b1:1d:aa:ba:17: |
| af:4f:a0:ad:4a:c8:7d:04:96:3c:82:7c:b7:86:63:90:d2:d1: |
| d7:fe:02:7f:11:a3:f1:d2:84:30:8a:d1:ed:ce:3c:51:ff:49: |
| ce:64:96:c1:77:0f:3b:f1:e5:82:bb:5c:57:2c:93:60:e7:b4: |
| ee:8a:d1:44:75:ac:b6:1b:c2:c6:59:40:76:e8:36:ea:18:54: |
| 2c:91:63:5b:0d:2e:ff:4a:13:1d:55:8d:f3:02:6e:f4:e8:f4: |
| a4:27:6a:88:2e:27:9a:f2:2b:4f:7c:49:3b:f2:fd:b8:53:18: |
| ea:17:41:d0 |
| -----BEGIN CERTIFICATE----- |
| MIIDoDCCAoigAwIBAgIUEQr8vaGxxaSV2udiebOC8yIomOUwDQYJKoZIhvcNAQEL |
| BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy |
| MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF |
| AAOCAQ8AMIIBCgKCAQEAwQNYAbEve/uycdxJ0MsGdjBk92G/2lWTcylJD8sKM71B |
| CygDRTVyqbRLp+xSdzqMusuHVig7OY1He3B/Wo92jH4T6GEXGR1y425pILyD91sR |
| hW4auPt7+P4r4tK9GgplYrCEpwqsdermdMQdLOgEYnZLTQS2Ui+muma7/kXWaiEF |
| FuXzJa6U/ReEgC+sYtmD4xewAxwBAotHf2Uu+UDPrZIzB4oURF7C7WhIpNHwe/ln |
| kSjZnyzwXhKSUpKXJ3sS3cXVfzKMmyYF60fhJpnqaqklk2Qx5Wz0zwInKbOfF5QN |
| OJxU8YDvubBLahLrylORKpXuFr8Sn4oyp4qB3UwCkQIDAQABo4HpMIHmMB0GA1Ud |
| DgQWBBTvVmccXiRgeD7yNUAuGlhlTbNOvjAfBgNVHSMEGDAWgBRHjPHJHvjsJagx |
| 8xzOvMVwnxGHYzA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 |
| cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 |
| dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF |
| oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZIhvcNAQELBQAD |
| ggEBAAf7QkqSEcqP1kCLkjoJcdcopKOba96wweUXF2a/l9uoXv2vSmERASYie933 |
| 6RWkaJHA+DTpSlbi0ZTioTeudvjiiPgTK6pYqs251agduATvcJ42xO4clM328E9q |
| 24lZfo9pQZJHQX/1XR6n2XbRfOFRXa9TrjTmNkfjRBGsEiMfSNKHaJGbTTrX9MKx |
| Haq6F69PoK1KyH0EljyCfLeGY5DS0df+An8Ro/HShDCK0e3OPFH/Sc5klsF3Dzvx |
| 5YK7XFcsk2DntO6K0UR1rLYbwsZZQHboNuoYVCyRY1sNLv9KEx1VjfMCbvTo9KQn |
| aoguJ5ryK098STvy/bhTGOoXQdA= |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 22:d5:d3:ab:e1:db:b6:4e:c6:30:5b:f4:c2:c2:ff:37:2e:43:2d:1a |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Oct 5 12:00:00 2021 GMT |
| Not After : Oct 5 12:00:00 2022 GMT |
| Subject: CN=Intermediate |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| RSA Public-Key: (2048 bit) |
| Modulus: |
| 00:ba:0f:08:80:56:6b:27:51:76:78:18:c5:92:b1: |
| b4:d1:7a:4f:8f:57:6a:6a:96:70:e3:ca:4a:68:9d: |
| 0b:5d:2e:fd:34:1b:2a:d7:f2:a0:e0:3d:98:f8:2c: |
| 88:d1:7e:25:5d:80:80:30:f0:1c:65:a5:e4:60:ed: |
| 7a:31:df:97:20:c3:0c:4e:d0:2a:d8:93:54:d2:21: |
| fe:9f:85:7d:fe:9d:45:fc:66:14:10:a5:6a:38:e7: |
| e0:1e:71:fa:fe:9a:c0:79:73:98:87:80:17:a8:e3: |
| c8:84:cb:9a:a8:db:d2:59:d5:26:40:cc:8b:29:03: |
| 8a:75:3d:05:01:ed:bf:05:57:27:94:e2:a3:7e:2e: |
| 06:95:8b:a2:99:8d:69:d3:3a:86:35:2b:23:19:cd: |
| 53:92:55:fe:7e:75:43:08:4c:05:51:db:1a:14:5d: |
| 6c:bb:4f:de:ef:7f:24:53:b1:e6:fc:90:a0:8a:39: |
| 22:f1:1d:1f:4a:3b:5b:c0:df:ca:a9:57:f2:c8:16: |
| f5:e0:f4:fa:79:77:9b:93:0d:b8:5a:9d:9b:48:98: |
| 69:75:11:0f:2d:b9:8e:cd:34:4c:06:62:f8:a2:de: |
| 07:d8:7e:a0:5a:88:b0:d1:72:0b:49:67:42:5c:08: |
| 3b:bc:10:60:01:c2:15:ab:f8:31:8f:5d:bb:a2:e6: |
| da:fb |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| 47:8C:F1:C9:1E:F8:EC:25:A8:31:F3:1C:CE:BC:C5:70:9F:11:87:63 |
| X509v3 Authority Key Identifier: |
| keyid:BD:1A:91:15:D9:48:10:F5:7E:D3:B8:CE:06:D8:29:10:AE:43:CE:42 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| X509v3 Certificate Policies: critical |
| Policy: 1.2.3 |
| Unknown Qualifier: 1.2.3.4 |
| |
| Signature Algorithm: sha256WithRSAEncryption |
| 49:0a:83:40:26:72:8f:2b:d7:44:4b:1e:62:27:3b:58:b3:8d: |
| 5d:ff:52:5b:1a:14:a5:e1:4b:79:98:ae:13:4a:0d:fd:ee:d1: |
| 8c:10:26:8b:a4:71:31:9d:c6:a5:16:10:c4:d4:ae:22:87:da: |
| 27:da:2e:ae:e0:9c:83:1e:c0:10:ac:7d:63:df:17:a7:be:27: |
| f1:e7:6f:6f:0a:53:25:7b:88:78:fe:2b:e9:b7:95:6d:f3:37: |
| 10:23:df:31:39:c9:cf:23:3f:76:1f:37:0f:21:27:8d:7e:19: |
| 84:89:14:c7:ac:06:97:c3:69:15:09:24:c3:b2:f7:b6:1c:0c: |
| ae:c0:c3:62:31:32:ca:f4:8d:4d:5a:3d:5c:7c:9f:af:1b:82: |
| 6c:ca:a9:65:9b:5e:3b:15:93:30:28:83:6e:11:fe:fd:23:96: |
| 20:d6:cc:df:f0:cf:a8:57:8f:52:6f:77:d2:ed:bc:64:65:54: |
| db:c1:aa:e0:43:0f:0f:07:4d:1f:7f:bd:a0:fc:0e:ea:8c:95: |
| e9:18:cc:b3:c8:25:a1:98:30:22:39:73:96:23:be:27:38:f8: |
| 27:7a:4d:82:d1:a3:92:ed:bd:50:6c:54:eb:55:76:f8:11:b1: |
| e1:02:c1:d8:a9:8c:ae:54:f6:00:8e:19:59:9f:88:c7:bc:30: |
| 45:58:b6:19 |
| -----BEGIN CERTIFICATE----- |
| MIIDoTCCAomgAwIBAgIUItXTq+Hbtk7GMFv0wsL/Ny5DLRowDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw |
| MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD |
| ggEPADCCAQoCggEBALoPCIBWaydRdngYxZKxtNF6T49XamqWcOPKSmidC10u/TQb |
| KtfyoOA9mPgsiNF+JV2AgDDwHGWl5GDtejHflyDDDE7QKtiTVNIh/p+Fff6dRfxm |
| FBClajjn4B5x+v6awHlzmIeAF6jjyITLmqjb0lnVJkDMiykDinU9BQHtvwVXJ5Ti |
| o34uBpWLopmNadM6hjUrIxnNU5JV/n51QwhMBVHbGhRdbLtP3u9/JFOx5vyQoIo5 |
| IvEdH0o7W8DfyqlX8sgW9eD0+nl3m5MNuFqdm0iYaXURDy25js00TAZi+KLeB9h+ |
| oFqIsNFyC0lnQlwIO7wQYAHCFav4MY9du6Lm2vsCAwEAAaOB7DCB6TAdBgNVHQ4E |
| FgQUR4zxyR747CWoMfMczrzFcJ8Rh2MwHwYDVR0jBBgwFoAUvRqRFdlIEPV+07jO |
| BtgpEK5DzkIwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs |
| LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m |
| b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ |
| MB8GA1UdIAEB/wQVMBMwEQYCKgMwCzAJBgMqAwQMAmhpMA0GCSqGSIb3DQEBCwUA |
| A4IBAQBJCoNAJnKPK9dESx5iJztYs41d/1JbGhSl4Ut5mK4TSg397tGMECaLpHEx |
| ncalFhDE1K4ih9on2i6u4JyDHsAQrH1j3xenvifx529vClMle4h4/ivpt5Vt8zcQ |
| I98xOcnPIz92HzcPISeNfhmEiRTHrAaXw2kVCSTDsve2HAyuwMNiMTLK9I1NWj1c |
| fJ+vG4Jsyqllm147FZMwKINuEf79I5Yg1szf8M+oV49Sb3fS7bxkZVTbwargQw8P |
| B00ff72g/A7qjJXpGMyzyCWhmDAiOXOWI74nOPgnek2C0aOS7b1QbFTrVXb4EbHh |
| AsHYqYyuVPYAjhlZn4jHvDBFWLYZ |
| -----END CERTIFICATE----- |
| |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: |
| 22:d5:d3:ab:e1:db:b6:4e:c6:30:5b:f4:c2:c2:ff:37:2e:43:2d:19 |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Root |
| Validity |
| Not Before: Oct 5 12:00:00 2021 GMT |
| Not After : Oct 5 12:00:00 2022 GMT |
| Subject: CN=Root |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| RSA Public-Key: (2048 bit) |
| Modulus: |
| 00:ba:3d:c2:46:f3:d5:1b:65:5e:43:a3:bc:db:43: |
| 94:e9:9c:20:e1:ea:84:98:c6:65:51:6d:1c:1d:5f: |
| 8d:f9:81:47:1a:06:18:d9:7c:57:8f:6c:55:5c:36: |
| 63:c2:c6:db:be:47:61:5c:35:46:30:ec:e1:e5:0e: |
| 10:4f:9d:d4:62:58:56:83:00:3a:63:f0:cb:b2:50: |
| e5:50:52:27:60:41:3e:db:07:61:92:db:d6:60:c2: |
| 66:f8:89:b6:aa:99:cb:5e:9d:74:db:cc:bc:3e:7d: |
| 0b:13:87:29:b8:fa:32:11:e9:fc:9a:e9:77:0d:7c: |
| 03:15:f7:7c:85:6c:f0:2c:2b:b0:32:5b:d9:6f:f8: |
| f0:82:71:9e:f4:63:5c:6d:98:c9:ea:12:ad:d3:66: |
| 22:da:67:26:3c:ae:b3:23:0e:68:91:b7:28:65:81: |
| b8:2c:04:34:92:bb:a0:00:39:51:06:53:14:c7:e9: |
| ae:31:ef:5a:d7:21:28:44:9f:ca:53:cf:ac:4f:60: |
| 56:a9:f4:92:20:ee:c0:db:46:da:83:bd:28:b4:dd: |
| d2:73:af:93:b5:31:84:55:e8:80:a0:6f:c5:f6:0c: |
| 54:50:dc:3d:b4:26:71:f9:fd:16:3f:62:b1:96:c9: |
| de:45:b4:28:86:8d:8e:34:ce:aa:41:7c:66:e4:04: |
| 72:bb |
| Exponent: 65537 (0x10001) |
| X509v3 extensions: |
| X509v3 Subject Key Identifier: |
| BD:1A:91:15:D9:48:10:F5:7E:D3:B8:CE:06:D8:29:10:AE:43:CE:42 |
| X509v3 Authority Key Identifier: |
| keyid:BD:1A:91:15:D9:48:10:F5:7E:D3:B8:CE:06:D8:29:10:AE:43:CE:42 |
| |
| Authority Information Access: |
| CA Issuers - URI:http://url-for-aia/Root.cer |
| |
| X509v3 CRL Distribution Points: |
| |
| Full Name: |
| URI:http://url-for-crl/Root.crl |
| |
| X509v3 Key Usage: critical |
| Certificate Sign, CRL Sign |
| X509v3 Basic Constraints: critical |
| CA:TRUE |
| Signature Algorithm: sha256WithRSAEncryption |
| 5b:e3:48:3a:63:d0:61:a7:99:8f:80:6a:42:fa:70:34:d6:69: |
| cb:fe:88:9f:a0:91:2d:3f:97:a1:a5:1f:e2:40:31:f3:2e:be: |
| f9:fb:6f:31:6e:6b:de:15:47:ac:c3:83:6c:d2:f9:30:dc:b6: |
| c2:26:b5:9c:c7:2b:e1:d7:bc:f5:98:54:3b:8c:c4:86:18:8f: |
| 70:99:31:46:d1:c6:a9:a0:38:dc:a0:55:fa:c9:5d:83:44:a8: |
| ae:a9:4f:b2:bd:e1:89:20:60:1c:07:b6:81:c3:d8:81:c7:dc: |
| 82:68:ae:43:e0:14:95:e3:c9:b4:fe:0d:fb:10:41:33:9b:bf: |
| 0b:32:35:3e:fa:c4:91:72:57:66:cd:77:1d:2c:0b:6b:6f:14: |
| e6:5e:a3:a5:f0:01:6b:5e:42:18:ba:e1:32:4b:25:4b:46:c8: |
| 2f:b1:4d:dc:b8:91:a1:15:b8:1b:09:5f:bc:a9:b6:ab:5e:14: |
| 1e:4a:c4:f2:b0:b1:1c:4e:ad:41:ba:c0:4a:3a:15:9b:6d:ba: |
| a9:95:3f:23:27:b7:20:d4:7c:48:81:2a:39:eb:ff:3e:24:cb: |
| 6d:27:3a:1e:f6:6c:59:2f:1e:50:64:aa:ee:9a:68:20:d6:8b: |
| 20:17:ec:51:13:3c:86:42:52:b6:e3:1a:b6:ef:e8:11:82:e9: |
| 06:49:30:1f |
| -----BEGIN CERTIFICATE----- |
| MIIDeDCCAmCgAwIBAgIUItXTq+Hbtk7GMFv0wsL/Ny5DLRkwDQYJKoZIhvcNAQEL |
| BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw |
| MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK |
| AoIBAQC6PcJG89UbZV5Do7zbQ5TpnCDh6oSYxmVRbRwdX435gUcaBhjZfFePbFVc |
| NmPCxtu+R2FcNUYw7OHlDhBPndRiWFaDADpj8MuyUOVQUidgQT7bB2GS29Zgwmb4 |
| ibaqmctenXTbzLw+fQsThym4+jIR6fya6XcNfAMV93yFbPAsK7AyW9lv+PCCcZ70 |
| Y1xtmMnqEq3TZiLaZyY8rrMjDmiRtyhlgbgsBDSSu6AAOVEGUxTH6a4x71rXIShE |
| n8pTz6xPYFap9JIg7sDbRtqDvSi03dJzr5O1MYRV6ICgb8X2DFRQ3D20JnH5/RY/ |
| YrGWyd5FtCiGjY40zqpBfGbkBHK7AgMBAAGjgcswgcgwHQYDVR0OBBYEFL0akRXZ |
| SBD1ftO4zgbYKRCuQ85CMB8GA1UdIwQYMBaAFL0akRXZSBD1ftO4zgbYKRCuQ85C |
| MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh |
| L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S |
| b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG |
| 9w0BAQsFAAOCAQEAW+NIOmPQYaeZj4BqQvpwNNZpy/6In6CRLT+XoaUf4kAx8y6+ |
| +ftvMW5r3hVHrMODbNL5MNy2wia1nMcr4de89ZhUO4zEhhiPcJkxRtHGqaA43KBV |
| +sldg0SorqlPsr3hiSBgHAe2gcPYgcfcgmiuQ+AUlePJtP4N+xBBM5u/CzI1PvrE |
| kXJXZs13HSwLa28U5l6jpfABa15CGLrhMkslS0bIL7FN3LiRoRW4GwlfvKm2q14U |
| HkrE8rCxHE6tQbrASjoVm226qZU/Iye3INR8SIEqOev/PiTLbSc6HvZsWS8eUGSq |
| 7ppoINaLIBfsURM8hkJStuMatu/oEYLpBkkwHw== |
| -----END CERTIFICATE----- |