blob: 7c68d004abfebb20a21a63112f99eca36f6a7e07 [file] [log] [blame]
[Created by: ./generate-chains.py]
Certificate chain where the target certificate contains an unknown X.509v3
extension (OID=1.2.3.4) that is marked as critical.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
4e:9a:ac:ff:32:38:c0:2f:b6:e5:63:63:94:45:6d:aa:aa:c4:b6:e5
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:bd:05:ea:3a:1c:14:a1:db:ad:2c:18:3d:25:9c:
dc:1c:0f:2b:1e:42:df:c2:7c:b4:39:e6:4b:45:eb:
d3:a2:1c:2b:dc:f2:8c:08:f5:81:df:bd:fa:a2:1a:
1c:5c:99:cb:00:c7:31:02:c8:44:5f:31:cf:9c:82:
6d:3c:0c:5d:f7:d6:cc:91:fe:f3:e7:7a:08:17:85:
d5:75:61:ee:dd:66:55:3c:e2:68:98:36:19:20:e4:
9b:cd:24:6c:a3:5d:89:84:80:2e:c7:11:4e:c1:82:
b2:80:ce:0f:e9:6a:42:54:10:fb:c0:0a:53:be:19:
01:38:ba:06:c5:93:93:1c:84:aa:25:c7:c5:9a:4d:
32:2e:a4:13:5e:6d:07:d6:9d:e5:b0:29:63:da:14:
b7:62:51:63:93:dc:28:ae:4a:bc:35:ac:c0:06:ea:
ea:0b:d5:70:61:3b:05:78:e4:d3:ad:c3:ad:95:f1:
48:e5:79:a6:dc:12:1f:14:4f:21:9f:ca:6f:7a:dd:
d6:45:c8:8a:60:96:1c:02:06:16:18:80:21:58:6a:
f6:83:3e:1a:98:b8:b2:a9:22:44:c2:25:e9:dc:a9:
aa:bf:1d:2e:3f:2e:a1:78:08:93:04:4c:c4:1f:f9:
b3:34:9f:a7:78:5b:02:a6:ca:d3:1f:fa:ba:4d:34:
a2:bb
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
D6:55:4E:AC:07:84:35:A9:0D:9A:63:45:82:73:4E:A4:CC:53:B0:02
X509v3 Authority Key Identifier:
8A:E3:E6:F6:58:6F:1C:90:B4:67:A5:14:D8:64:E7:F7:00:77:61:01
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
1.2.3.4: critical
....
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
2d:da:b3:73:a9:3c:2f:ac:6f:a6:db:80:c2:82:ea:0f:6e:bd:
58:35:f5:d5:69:3f:73:26:e6:80:cd:39:d1:cf:38:f8:19:dd:
f7:cf:57:70:44:3b:83:5a:8d:91:7b:02:a9:e8:ef:06:1e:b6:
4b:97:ff:0e:96:ee:fe:85:ea:b4:93:ba:0e:b1:15:ef:ff:f6:
be:0d:f2:2a:d6:2d:df:43:a9:e8:a0:e3:50:bb:56:af:51:05:
1d:50:f3:58:f4:41:f0:ea:b4:1e:34:99:ac:d5:b8:34:78:96:
73:2e:62:e5:7e:b5:1d:e4:08:52:b4:8f:28:bf:b7:75:23:71:
f2:31:b2:ad:eb:4c:94:ec:79:09:0c:8b:94:38:a8:c8:82:e8:
42:e4:72:50:bc:4b:8e:0d:e8:c0:77:a7:94:8e:d4:35:36:73:
d4:1e:32:8f:19:14:8e:eb:26:61:bb:c9:9c:b5:71:08:40:61:
52:8f:1e:a3:3d:01:2c:c8:a5:b5:c7:ac:42:ee:75:2b:a2:e7:
77:65:98:1d:02:1c:95:d3:8a:1d:17:71:82:86:5c:f3:a9:44:
e0:54:c5:51:84:b4:3c:c9:f1:bd:25:2d:cb:23:f2:72:d2:8c:
f9:2d:c5:2a:4b:14:f5:df:65:53:e5:fb:2e:71:02:03:c5:6e:
6f:0a:68:69
-----BEGIN CERTIFICATE-----
MIIDsDCCApigAwIBAgIUTpqs/zI4wC+25WNjlEVtqqrEtuUwDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAvQXqOhwUodutLBg9JZzcHA8rHkLfwny0OeZLRevTohwr
3PKMCPWB3736ohocXJnLAMcxAshEXzHPnIJtPAxd99bMkf7z53oIF4XVdWHu3WZV
POJomDYZIOSbzSRso12JhIAuxxFOwYKygM4P6WpCVBD7wApTvhkBOLoGxZOTHISq
JcfFmk0yLqQTXm0H1p3lsClj2hS3YlFjk9workq8NazABurqC9VwYTsFeOTTrcOt
lfFI5Xmm3BIfFE8hn8pvet3WRciKYJYcAgYWGIAhWGr2gz4amLiyqSJEwiXp3Kmq
vx0uPy6heAiTBEzEH/mzNJ+neFsCpsrTH/q6TTSiuwIDAQABo4H5MIH2MB0GA1Ud
DgQWBBTWVU6sB4Q1qQ2aY0WCc06kzFOwAjAfBgNVHSMEGDAWgBSK4+b2WG8ckLRn
pRTYZOf3AHdhATA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDgYDKgMEAQH/BAQBAgME
MA0GCSqGSIb3DQEBCwUAA4IBAQAt2rNzqTwvrG+m24DCguoPbr1YNfXVaT9zJuaA
zTnRzzj4Gd33z1dwRDuDWo2RewKp6O8GHrZLl/8Olu7+heq0k7oOsRXv//a+DfIq
1i3fQ6nooONQu1avUQUdUPNY9EHw6rQeNJms1bg0eJZzLmLlfrUd5AhStI8ov7d1
I3HyMbKt60yU7HkJDIuUOKjIguhC5HJQvEuODejAd6eUjtQ1NnPUHjKPGRSO6yZh
u8mctXEIQGFSjx6jPQEsyKW1x6xC7nUroud3ZZgdAhyV04odF3GChlzzqUTgVMVR
hLQ8yfG9JS3LI/Jy0oz5LcUqSxT132VT5fsucQIDxW5vCmhp
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
06:66:51:84:c2:7e:fc:0c:cf:05:27:4c:bc:d3:55:23:ed:cb:19:f9
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b8:cf:91:dd:b5:74:07:ba:8a:93:3c:ca:0c:11:
5d:36:29:ec:53:1e:32:8b:90:ae:f9:c0:db:d2:7e:
78:ea:3c:58:57:5f:70:4a:96:9a:93:58:d3:7e:42:
60:bd:78:07:38:6b:e4:16:8f:32:17:30:b1:76:95:
56:6d:7e:e5:9e:f9:0f:f8:5a:99:ee:80:e1:e6:fc:
d6:af:33:61:aa:da:19:98:7f:da:27:2f:80:bc:96:
2e:51:81:f8:1a:63:27:0b:ce:ee:02:16:55:4a:96:
0a:c5:c1:7e:99:95:e8:70:e7:4d:2b:2f:bf:d3:d2:
2d:25:7d:0f:b2:50:96:36:95:e5:2c:ca:0e:59:b5:
d4:7c:31:57:96:fa:be:c6:d5:9a:83:b5:96:f2:1c:
4a:20:cf:be:0e:7f:42:4f:a7:b4:5b:e2:01:f4:ed:
59:c4:6e:51:a1:a5:aa:a7:1f:04:ce:e0:d2:2c:ff:
a3:74:c7:e4:2a:a8:d2:7f:cd:f1:56:86:67:fe:75:
22:05:f7:2d:3b:3b:ce:5c:b9:95:4e:e5:ca:d8:89:
f6:b3:12:27:b4:22:6b:fb:83:f9:0e:de:a8:be:38:
5b:15:66:81:3b:62:d7:50:12:29:69:5b:c5:5a:99:
97:aa:51:c3:36:88:97:c9:c1:90:53:4f:b3:ec:99:
3c:f3
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
8A:E3:E6:F6:58:6F:1C:90:B4:67:A5:14:D8:64:E7:F7:00:77:61:01
X509v3 Authority Key Identifier:
52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
03:01:bd:9d:2d:b0:21:65:4d:11:4b:8d:72:4a:45:c5:cf:0a:
b3:df:9c:a4:0a:2c:c0:10:61:ce:91:c2:79:ef:f8:90:9e:66:
aa:ba:b0:2a:05:bf:76:8d:4d:1b:43:ff:cd:24:d7:79:f9:49:
73:25:6b:47:d8:3a:59:ab:fa:da:11:5e:7e:ce:bb:07:21:e4:
ea:30:b5:14:b6:34:36:f9:b4:94:ec:31:ae:1f:f2:02:96:68:
6b:d2:3c:ce:29:7f:0d:af:35:c5:a7:c3:1c:75:b3:c8:04:96:
7b:3e:b7:10:fa:25:00:8e:f4:f3:65:46:fc:09:5c:19:c4:69:
56:44:49:1f:db:04:09:04:0b:3e:72:fb:f8:ac:d6:23:31:ec:
37:70:fa:8b:db:d1:80:25:1f:44:68:ff:48:e0:c2:c0:8e:9d:
02:ee:ff:e3:b6:ac:22:1f:7e:c4:59:94:f7:06:05:19:23:ff:
4a:c9:16:99:94:3e:2e:ba:86:6c:01:31:01:1d:17:2c:f7:0b:
5c:02:8a:2d:28:73:a7:81:b9:8f:91:f7:a3:0b:2a:16:98:e7:
8d:5c:31:95:48:59:ce:1b:7e:2b:8c:79:1e:c1:27:11:20:07:
83:ad:b5:1c:aa:77:57:7e:bb:13:19:52:6a:13:6b:5d:32:bf:
2a:26:5b:5c
-----BEGIN CERTIFICATE-----
MIIDgDCCAmigAwIBAgIUBmZRhMJ+/AzPBSdMvNNVI+3LGfkwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBALjPkd21dAe6ipM8ygwRXTYp7FMeMouQrvnA29J+eOo8WFdf
cEqWmpNY035CYL14Bzhr5BaPMhcwsXaVVm1+5Z75D/hame6A4eb81q8zYaraGZh/
2icvgLyWLlGB+BpjJwvO7gIWVUqWCsXBfpmV6HDnTSsvv9PSLSV9D7JQljaV5SzK
Dlm11HwxV5b6vsbVmoO1lvIcSiDPvg5/Qk+ntFviAfTtWcRuUaGlqqcfBM7g0iz/
o3TH5Cqo0n/N8VaGZ/51IgX3LTs7zly5lU7lytiJ9rMSJ7Qia/uD+Q7eqL44WxVm
gTti11ASKWlbxVqZl6pRwzaIl8nBkFNPs+yZPPMCAwEAAaOByzCByDAdBgNVHQ4E
FgQUiuPm9lhvHJC0Z6UU2GTn9wB3YQEwHwYDVR0jBBgwFoAUUgCkvotfI2NeMQWH
9GtQpwFwY9owNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MA0GCSqGSIb3DQEBCwUAA4IBAQADAb2dLbAhZU0RS41ySkXFzwqz35ykCizAEGHO
kcJ57/iQnmaqurAqBb92jU0bQ//NJNd5+UlzJWtH2DpZq/raEV5+zrsHIeTqMLUU
tjQ2+bSU7DGuH/IClmhr0jzOKX8NrzXFp8McdbPIBJZ7PrcQ+iUAjvTzZUb8CVwZ
xGlWREkf2wQJBAs+cvv4rNYjMew3cPqL29GAJR9EaP9I4MLAjp0C7v/jtqwiH37E
WZT3BgUZI/9KyRaZlD4uuoZsATEBHRcs9wtcAootKHOngbmPkfejCyoWmOeNXDGV
SFnOG34rjHkewScRIAeDrbUcqndXfrsTGVJqE2tdMr8qJltc
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
06:66:51:84:c2:7e:fc:0c:cf:05:27:4c:bc:d3:55:23:ed:cb:19:f8
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:c0:8e:83:7c:7e:0c:6a:e8:93:2c:f8:e6:80:17:
e6:2a:91:f2:1d:1a:b1:51:6e:3e:4d:96:bd:a1:29:
f3:bd:ce:46:17:dc:5f:ed:b7:33:d8:17:31:80:b1:
12:f3:bb:86:1d:4a:a7:61:dd:51:15:a8:9d:50:25:
4f:93:5b:8c:a6:43:30:a5:46:7e:80:74:51:17:66:
61:ba:c0:9d:f5:53:e4:4d:02:58:a4:27:ac:ef:35:
eb:01:e6:0d:0f:a2:67:b3:95:1d:33:d3:70:55:6d:
73:80:dd:c7:dc:21:c6:58:9a:7d:cb:e6:9d:e2:af:
7f:14:02:7c:f8:45:ff:5c:74:7a:7d:b1:35:1f:74:
0f:e7:0d:97:51:58:15:41:07:fa:12:99:2a:84:92:
48:9b:08:ee:ad:26:37:15:3e:7e:7b:b6:1e:94:36:
be:b9:d8:b6:6f:27:71:13:d1:3e:b7:9e:9d:d6:1e:
e1:cb:7b:2b:ab:20:46:e0:08:9c:54:5b:c6:db:c2:
57:d3:67:ee:00:cf:d2:cb:0b:64:31:a7:9c:97:f5:
4b:37:db:7d:d5:dd:91:a7:ed:dc:0c:2f:9c:04:42:
50:46:8a:59:d2:9c:10:d7:0c:25:d9:79:de:e1:4c:
3d:4a:5a:3f:2c:6c:20:a1:60:9f:24:69:1a:0a:f9:
6e:79
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
X509v3 Authority Key Identifier:
52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
8c:cc:8d:39:d4:a7:3f:73:9f:db:20:71:ed:d6:e0:94:76:4f:
ce:d3:05:24:82:bf:31:94:30:bd:7a:77:88:09:95:0e:79:79:
20:48:59:6a:3c:a6:a0:f3:3b:54:f0:3c:af:83:3d:22:a1:07:
7a:5b:f0:16:97:b8:ee:a4:d5:5a:f4:1e:89:e5:d3:fb:d0:b2:
cc:81:13:65:57:0f:2c:52:cc:b2:8b:a6:2d:b0:eb:e6:4e:12:
ae:31:e4:5a:5c:c4:65:33:8d:3b:fe:55:c5:65:74:80:92:25:
ef:e3:25:92:f1:b2:90:3f:59:c0:94:0b:fb:26:d8:4e:2f:21:
b2:69:7c:37:fd:28:36:b5:10:c8:04:46:28:3e:ff:5e:39:74:
50:4d:59:ab:a2:75:bf:ad:78:3a:b2:b6:0c:37:21:78:0f:8c:
73:b8:cc:36:02:ba:5f:1c:eb:c5:7b:77:c5:50:9e:3b:7e:17:
ce:17:73:50:d0:4c:46:86:f8:0c:d9:d1:eb:bb:3f:e7:f3:6e:
09:27:49:0b:8f:70:2e:64:8b:15:2e:f2:16:a2:fe:0f:01:87:
45:b8:2d:a3:a9:e2:5b:0c:f0:e8:79:db:cd:30:45:86:4e:49:
e7:37:38:b8:71:28:92:3a:0e:ac:1c:81:25:d7:d3:1a:c8:e5:
1d:47:8d:5b
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUBmZRhMJ+/AzPBSdMvNNVI+3LGfgwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDAjoN8fgxq6JMs+OaAF+YqkfIdGrFRbj5Nlr2hKfO9zkYX3F/ttzPYFzGA
sRLzu4YdSqdh3VEVqJ1QJU+TW4ymQzClRn6AdFEXZmG6wJ31U+RNAlikJ6zvNesB
5g0PomezlR0z03BVbXOA3cfcIcZYmn3L5p3ir38UAnz4Rf9cdHp9sTUfdA/nDZdR
WBVBB/oSmSqEkkibCO6tJjcVPn57th6UNr652LZvJ3ET0T63np3WHuHLeyurIEbg
CJxUW8bbwlfTZ+4Az9LLC2Qxp5yX9Us3233V3ZGn7dwML5wEQlBGilnSnBDXDCXZ
ed7hTD1KWj8sbCChYJ8kaRoK+W55AgMBAAGjgcswgcgwHQYDVR0OBBYEFFIApL6L
XyNjXjEFh/RrUKcBcGPaMB8GA1UdIwQYMBaAFFIApL6LXyNjXjEFh/RrUKcBcGPa
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEAjMyNOdSnP3Of2yBx7dbglHZPztMFJIK/MZQwvXp3iAmVDnl5
IEhZajymoPM7VPA8r4M9IqEHelvwFpe47qTVWvQeieXT+9CyzIETZVcPLFLMsoum
LbDr5k4SrjHkWlzEZTONO/5VxWV0gJIl7+MlkvGykD9ZwJQL+ybYTi8hsml8N/0o
NrUQyARGKD7/Xjl0UE1Zq6J1v614OrK2DDcheA+Mc7jMNgK6XxzrxXt3xVCeO34X
zhdzUNBMRob4DNnR67s/5/NuCSdJC49wLmSLFS7yFqL+DwGHRbgto6niWwzw6Hnb
zTBFhk5J5zc4uHEokjoOrByBJdfTGsjlHUeNWw==
-----END CERTIFICATE-----