blob: 410612b16b635c7e1d73a9d3fa58c6d0bdc99ba9 [file] [log] [blame]
[Created by: ./generate-chains.py]
Certificate chain with inhibitAnyPolicy=1 on the root, and an intermediate
that uses anyPolicy. Should succeed since anyPolicy is still allowed for
intermediate.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
1f:68:8f:ee:fd:60:39:09:33:64:83:cf:6f:a4:7c:43:a0:48:dd:fb
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Intermediate
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:ae:0d:42:e9:f2:fa:b9:8c:97:53:ed:60:ed:92:
0f:08:11:8d:65:ea:98:d7:d4:84:8f:53:b6:58:60:
72:d6:c2:1d:76:c0:6c:93:27:32:58:1a:88:23:93:
5a:a0:d8:6e:f5:5a:2c:1e:ba:5f:4d:e3:30:93:4c:
bd:04:0f:7b:b9:4b:17:b0:0d:22:a0:ca:ff:f7:9e:
f6:ff:08:d3:9d:ab:52:03:a1:f8:5c:14:de:6e:8d:
cc:16:8e:5d:fa:2b:40:d6:fb:9b:fa:a0:c1:08:10:
80:c2:ea:68:ec:a1:52:a8:0b:97:5f:e0:17:6a:bc:
0b:1e:43:1f:f6:ee:4f:c2:75:a1:9e:76:88:9b:06:
b2:3f:5e:3f:f0:a1:e9:e8:2e:af:70:ed:17:a6:39:
e3:74:82:b7:ff:94:9a:47:9e:e7:7b:75:1c:4d:7d:
83:a6:0b:df:e5:fd:af:12:3d:33:b5:a0:83:91:21:
d7:02:82:47:cb:b5:5a:f6:5e:0c:96:1c:36:a5:f3:
8a:a7:31:c5:8f:c5:b5:11:a3:af:1f:af:ba:46:a3:
89:98:73:96:91:ee:34:83:22:f5:a2:e5:5f:e9:9a:
97:12:36:0e:f4:11:8d:a4:10:2e:81:12:3d:44:a0:
33:80:ff:a0:5a:95:81:f8:9f:32:80:f0:d4:44:62:
40:25
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
84:09:4F:4B:7E:C1:B5:A8:C6:F1:92:14:50:B2:A2:82:63:56:F2:EB
X509v3 Authority Key Identifier:
44:9B:0F:5D:73:05:AB:7F:5A:A4:88:72:CE:78:3F:D4:5F:1B:F7:5B
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Certificate Policies: critical
Policy: 1.2.3.5
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
5e:38:2c:b0:f6:9b:52:fd:b9:00:87:8b:cb:59:05:a7:bd:d8:
63:06:2c:21:14:1a:55:30:37:9b:30:3f:33:00:00:7c:89:01:
55:26:81:89:82:5c:cf:43:90:b7:a9:62:29:56:60:a6:ff:6f:
8c:5f:fb:01:56:79:49:63:40:dd:06:16:99:e5:6d:d5:2d:fc:
33:28:cc:85:87:e9:eb:0c:5b:ca:48:c3:72:4b:68:91:01:6a:
e5:25:80:0b:e4:c4:71:0d:c6:c8:72:b9:16:8f:1c:9c:1d:94:
34:29:b0:68:89:a4:ef:a8:cf:b6:90:6b:65:82:72:06:af:86:
26:10:c6:dd:43:48:18:3c:b1:2a:e4:2f:47:d4:41:e9:1a:70:
bd:fe:35:48:9a:f9:06:49:c2:7e:9a:b4:aa:0d:a3:10:8a:1e:
b3:fb:66:41:2e:2d:c8:1f:65:74:e2:cf:7b:f8:59:85:01:ec:
78:84:ee:3b:d8:9f:db:5c:54:5e:0c:b2:9d:4d:af:0a:5b:5a:
9b:52:f6:2f:30:10:9b:58:64:73:71:5a:c7:c8:0b:57:d0:4a:
21:60:1c:02:51:a9:03:63:ea:b0:92:82:d8:20:73:30:84:a9:
33:95:0f:9f:42:84:61:c1:89:17:d2:42:03:77:ef:9d:04:2d:
92:13:95:aa
-----BEGIN CERTIFICATE-----
MIIDtTCCAp2gAwIBAgIUH2iP7v1gOQkzZIPPb6R8Q6BI3fswDQYJKoZIhvcNAQEL
BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEArg1C6fL6uYyXU+1g7ZIPCBGNZeqY19SEj1O2WGBy1sId
dsBskycyWBqII5NaoNhu9VosHrpfTeMwk0y9BA97uUsXsA0ioMr/9572/wjTnatS
A6H4XBTebo3MFo5d+itA1vub+qDBCBCAwupo7KFSqAuXX+AXarwLHkMf9u5PwnWh
nnaImwayP14/8KHp6C6vcO0XpjnjdIK3/5SaR57ne3UcTX2Dpgvf5f2vEj0ztaCD
kSHXAoJHy7Va9l4Mlhw2pfOKpzHFj8W1EaOvH6+6RqOJmHOWke40gyL1ouVf6ZqX
EjYO9BGNpBAugRI9RKAzgP+gWpWB+J8ygPDURGJAJQIDAQABo4H+MIH7MB0GA1Ud
DgQWBBSECU9LfsG1qMbxkhRQsqKCY1by6zAfBgNVHSMEGDAWgBREmw9dcwWrf1qk
iHLOeD/UXxv3WzA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEwYDVR0gAQH/BAkwBzAF
BgMqAwUwDQYJKoZIhvcNAQELBQADggEBAF44LLD2m1L9uQCHi8tZBae92GMGLCEU
GlUwN5swPzMAAHyJAVUmgYmCXM9DkLepYilWYKb/b4xf+wFWeUljQN0GFpnlbdUt
/DMozIWH6esMW8pIw3JLaJEBauUlgAvkxHENxshyuRaPHJwdlDQpsGiJpO+oz7aQ
a2WCcgavhiYQxt1DSBg8sSrkL0fUQekacL3+NUia+QZJwn6atKoNoxCKHrP7ZkEu
LcgfZXTiz3v4WYUB7HiE7jvYn9tcVF4Msp1NrwpbWptS9i8wEJtYZHNxWsfIC1fQ
SiFgHAJRqQNj6rCSgtggczCEqTOVD59ChGHBiRfSQgN3750ELZITlao=
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
70:09:64:da:50:cc:c6:d4:9d:ae:e5:e6:0a:57:94:4b:37:e5:92:ff
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:89:26:5d:b6:91:69:ea:ce:b4:ed:b5:36:0b:7c:
c3:7e:e4:68:84:e8:9e:bb:52:76:dc:a5:f2:9e:76:
26:51:b7:d2:db:9f:5f:f1:ae:9f:72:f3:16:e4:f1:
aa:b7:f6:d6:c9:1e:da:ef:d2:d5:f7:a2:b0:f9:e2:
7b:01:01:33:40:2b:03:85:de:10:e4:e9:ff:5e:d4:
c3:72:f8:ee:51:1b:aa:ff:1e:c1:1d:83:ff:d6:c5:
54:8e:b8:60:73:b1:bf:6f:bf:3f:02:b9:fb:7a:bd:
c9:c4:71:d1:d7:de:b0:c0:3b:69:cf:dd:2b:9f:88:
81:12:b0:3b:61:bc:3c:29:56:71:2d:04:c1:1f:9f:
74:77:de:d5:a5:ac:00:e9:d5:fd:a8:e1:76:0b:e8:
8f:f2:a8:64:a6:59:6f:33:42:e6:e8:15:64:10:b2:
8d:db:51:23:73:01:0e:bf:d3:ad:17:65:cc:b2:c2:
a0:06:f6:ba:16:9a:80:0d:ac:3c:9c:15:73:0f:15:
64:dd:f6:99:55:70:b5:91:78:08:93:79:57:fb:83:
89:e3:cd:b4:5a:b0:56:eb:00:6b:cc:7c:c0:02:e4:
ae:0a:84:63:e2:5f:c0:f3:a9:a1:16:cb:bb:f1:ef:
56:75:95:d9:b8:bc:55:7d:61:45:73:32:e5:a5:87:
56:bb
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
44:9B:0F:5D:73:05:AB:7F:5A:A4:88:72:CE:78:3F:D4:5F:1B:F7:5B
X509v3 Authority Key Identifier:
FB:09:9A:AA:11:65:B8:7C:67:A5:6E:C4:AB:74:FE:5F:54:0A:A2:A7
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Policy Constraints: critical
Require Explicit Policy:0
X509v3 Certificate Policies: critical
Policy: X509v3 Any Policy
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
da:6c:b3:22:9a:bf:00:10:72:85:11:8b:3e:23:63:52:f4:a2:
63:ee:85:73:02:c0:61:da:8e:92:5d:8c:43:f5:a9:02:32:9d:
f2:10:0f:5c:df:1c:22:fd:dd:cf:23:4b:9f:1a:f3:b5:07:ea:
81:00:06:a7:58:d4:f7:b1:12:ca:3a:67:2b:82:84:ed:38:da:
e5:c6:bf:0c:d0:af:dc:7a:17:b1:c9:33:9a:81:96:2f:61:9e:
c8:58:cb:96:35:e3:84:60:93:8b:a6:da:56:b4:63:f1:55:c7:
19:c0:28:7e:05:df:1b:36:0b:52:31:bd:d1:3e:e5:7d:f7:bf:
d4:47:fa:08:d3:92:de:33:33:00:84:8c:1f:b2:bb:45:63:a5:
fb:9d:6b:d2:ee:ea:0b:c1:58:ae:de:31:d3:de:0e:6f:8e:cb:
05:7a:75:6d:38:c3:b6:a9:5b:08:3c:93:35:0f:94:ca:ea:bc:
b2:1e:a5:70:04:65:4e:4b:99:5e:e3:09:a7:b6:de:6a:f9:a1:
48:37:ae:24:20:45:88:ea:78:81:25:8b:57:90:3e:8c:0f:8d:
ec:00:e3:3e:c7:43:d1:e3:ca:6a:81:5f:e1:c8:c7:7f:23:55:
e3:e2:8c:8a:b7:4d:9c:e9:47:93:2d:60:ca:6e:f8:7f:7d:46:
3f:14:d1:d9
-----BEGIN CERTIFICATE-----
MIIDpzCCAo+gAwIBAgIUcAlk2lDMxtSdruXmCleUSzflkv8wDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBAIkmXbaRaerOtO21Ngt8w37kaITonrtSdtyl8p52JlG30tuf
X/Gun3LzFuTxqrf21ske2u/S1feisPniewEBM0ArA4XeEOTp/17Uw3L47lEbqv8e
wR2D/9bFVI64YHOxv2+/PwK5+3q9ycRx0dfesMA7ac/dK5+IgRKwO2G8PClWcS0E
wR+fdHfe1aWsAOnV/ajhdgvoj/KoZKZZbzNC5ugVZBCyjdtRI3MBDr/TrRdlzLLC
oAb2uhaagA2sPJwVcw8VZN32mVVwtZF4CJN5V/uDiePNtFqwVusAa8x8wALkrgqE
Y+JfwPOpoRbLu/HvVnWV2bi8VX1hRXMy5aWHVrsCAwEAAaOB8jCB7zAdBgNVHQ4E
FgQURJsPXXMFq39apIhyzng/1F8b91swHwYDVR0jBBgwFoAU+wmaqhFluHxnpW7E
q3T+X1QKoqcwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
MA8GA1UdJAEB/wQFMAOAAQAwFAYDVR0gAQH/BAowCDAGBgRVHSAAMA0GCSqGSIb3
DQEBCwUAA4IBAQDabLMimr8AEHKFEYs+I2NS9KJj7oVzAsBh2o6SXYxD9akCMp3y
EA9c3xwi/d3PI0ufGvO1B+qBAAanWNT3sRLKOmcrgoTtONrlxr8M0K/cehexyTOa
gZYvYZ7IWMuWNeOEYJOLptpWtGPxVccZwCh+Bd8bNgtSMb3RPuV997/UR/oI05Le
MzMAhIwfsrtFY6X7nWvS7uoLwViu3jHT3g5vjssFenVtOMO2qVsIPJM1D5TK6ryy
HqVwBGVOS5le4wmntt5q+aFIN64kIEWI6niBJYtXkD6MD43sAOM+x0PR48pqgV/h
yMd/I1Xj4oyKt02c6UeTLWDKbvh/fUY/FNHZ
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
70:09:64:da:50:cc:c6:d4:9d:ae:e5:e6:0a:57:94:4b:37:e5:92:fe
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:da:86:a0:3a:dc:6f:58:98:e5:86:57:9e:07:6c:
f1:8c:87:54:d3:9b:7b:2c:aa:95:29:d5:86:b0:16:
b2:78:62:12:a4:09:3e:1a:38:7c:1f:32:be:bd:59:
55:58:3a:8a:2e:9b:28:54:09:0c:ec:d7:e8:e5:ee:
94:62:7f:f0:b7:cb:d1:36:d9:fc:71:bb:f5:74:bf:
d0:58:8e:bd:fc:1d:0e:ae:08:58:cc:17:cd:21:69:
1c:db:1f:7a:ee:6b:40:ed:4b:6d:8f:43:32:f8:14:
58:ac:94:dc:97:cc:35:04:e5:6f:17:66:53:c8:21:
ae:0e:8b:a8:bd:3b:41:66:af:fa:f6:b2:af:0c:a0:
c8:17:ea:d7:5c:cc:84:9b:9a:5b:cc:23:73:f7:b6:
a8:d3:05:27:b7:2a:95:ac:c8:1f:dd:5e:52:e3:6a:
38:73:31:f6:f3:3a:ca:7d:57:d1:ff:a6:59:4e:9a:
29:68:be:b5:8b:9a:b1:2f:d1:41:c2:fd:f7:fb:aa:
bc:07:34:56:a9:ea:8b:b3:87:54:c7:8b:15:41:2a:
56:aa:42:00:27:5d:2c:36:68:1e:d3:02:76:3e:00:
1f:90:4a:a6:f5:d9:9e:b2:aa:10:85:ba:73:65:09:
d1:fb:51:58:9f:a9:f0:d0:1f:a0:7d:56:d6:e9:ed:
f3:a5
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
FB:09:9A:AA:11:65:B8:7C:67:A5:6E:C4:AB:74:FE:5F:54:0A:A2:A7
X509v3 Authority Key Identifier:
FB:09:9A:AA:11:65:B8:7C:67:A5:6E:C4:AB:74:FE:5F:54:0A:A2:A7
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Inhibit Any Policy: critical
1
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
06:70:58:59:b1:7c:e9:8f:75:42:27:f0:eb:e9:bd:b9:c1:11:
47:12:18:e7:a7:11:c7:fe:6c:08:c2:40:5a:d7:90:8d:53:12:
b4:01:93:69:87:ec:dc:40:69:2e:d1:b1:04:1d:36:d4:ae:6f:
bd:22:d7:8d:9e:cf:ff:c7:14:f2:36:43:e6:a3:0c:54:0c:52:
3f:65:ff:8e:4c:34:1b:83:6b:12:01:09:87:cd:f0:1a:67:89:
e0:2d:24:a9:85:af:25:7a:3b:d0:2a:d0:a5:8e:ee:9c:cf:fa:
81:8a:db:1a:33:74:2f:e8:b4:73:67:26:20:c4:86:75:ae:2a:
ef:f6:6b:f8:3c:3f:d8:a2:be:b3:82:70:74:8b:d4:b8:cb:6b:
31:de:29:77:22:22:85:46:8a:3f:7a:f4:8a:8b:40:77:3b:92:
7a:59:57:ab:4d:84:84:c9:19:35:a6:45:95:65:41:3c:f1:4e:
a1:d3:c0:bd:c2:d4:bb:fe:32:26:1c:fc:25:3c:87:3b:c4:29:
ce:1b:1b:dd:9c:3f:1c:bf:b6:5b:9e:d4:46:79:ea:94:70:0b:
fb:5a:d0:9c:2e:be:0e:a8:fd:38:fc:2a:65:31:5b:a4:1d:52:
e0:e0:9f:07:76:72:e7:41:e9:95:6f:04:42:9e:88:a6:3c:d6:
ad:7d:6a:48
-----BEGIN CERTIFICATE-----
MIIDhzCCAm+gAwIBAgIUcAlk2lDMxtSdruXmCleUSzflkv4wDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDahqA63G9YmOWGV54HbPGMh1TTm3ssqpUp1YawFrJ4YhKkCT4aOHwfMr69
WVVYOooumyhUCQzs1+jl7pRif/C3y9E22fxxu/V0v9BYjr38HQ6uCFjMF80haRzb
H3rua0DtS22PQzL4FFislNyXzDUE5W8XZlPIIa4Oi6i9O0Fmr/r2sq8MoMgX6tdc
zISbmlvMI3P3tqjTBSe3KpWsyB/dXlLjajhzMfbzOsp9V9H/pllOmilovrWLmrEv
0UHC/ff7qrwHNFap6ouzh1THixVBKlaqQgAnXSw2aB7TAnY+AB+QSqb12Z6yqhCF
unNlCdH7UVifqfDQH6B9Vtbp7fOlAgMBAAGjgdowgdcwHQYDVR0OBBYEFPsJmqoR
Zbh8Z6VuxKt0/l9UCqKnMB8GA1UdIwQYMBaAFPsJmqoRZbh8Z6VuxKt0/l9UCqKn
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgNVHTYB
Af8EAwIBATANBgkqhkiG9w0BAQsFAAOCAQEABnBYWbF86Y91Qifw6+m9ucERRxIY
56cRx/5sCMJAWteQjVMStAGTaYfs3EBpLtGxBB021K5vvSLXjZ7P/8cU8jZD5qMM
VAxSP2X/jkw0G4NrEgEJh83wGmeJ4C0kqYWvJXo70CrQpY7unM/6gYrbGjN0L+i0
c2cmIMSGda4q7/Zr+Dw/2KK+s4JwdIvUuMtrMd4pdyIihUaKP3r0iotAdzuSellX
q02EhMkZNaZFlWVBPPFOodPAvcLUu/4yJhz8JTyHO8Qpzhsb3Zw/HL+2W57URnnq
lHAL+1rQnC6+Dqj9OPwqZTFbpB1S4OCfB3Zy50HplW8EQp6IpjzWrX1qSA==
-----END CERTIFICATE-----