blob: 799d78cb120836f8cebb49ef35cc967f4bcf5508 [file] [log] [blame]
Bob Beckbc97b7a2023-04-18 08:35:15 -06001[Created by: generate-chains.py]
2
3Certificate chain where the intermediate restricts the extended key usage to
4clientAuth, and the target asserts serverAuth + clientAuth.
5
6Certificate:
7 Data:
8 Version: 3 (0x2)
9 Serial Number:
10 56:4a:78:5b:dc:c1:19:20:fe:f3:13:be:99:46:f9:53:d1:a4:40:a1
11 Signature Algorithm: sha256WithRSAEncryption
12 Issuer: CN=Intermediate
13 Validity
14 Not Before: Oct 5 12:00:00 2021 GMT
15 Not After : Oct 5 12:00:00 2022 GMT
16 Subject: CN=Target
17 Subject Public Key Info:
18 Public Key Algorithm: rsaEncryption
19 RSA Public-Key: (2048 bit)
20 Modulus:
21 00:bb:d3:3c:f5:4c:df:73:61:c9:d0:be:56:b8:7f:
22 e6:52:56:9c:3b:84:83:23:d8:ea:30:cb:cc:01:ba:
23 1d:36:70:d3:4c:58:62:74:2f:96:57:7c:e5:b0:27:
24 6f:fa:72:c0:5b:0b:0c:f6:ec:1e:3b:c7:04:45:b8:
25 89:97:be:fa:49:27:b6:c2:0a:29:b8:98:cd:a4:a4:
26 54:29:ce:55:c5:91:ff:89:d3:51:87:88:d0:c3:ef:
27 0c:de:43:b0:e0:b9:d9:23:92:f0:04:42:b6:50:06:
28 2b:1a:7b:97:3e:67:a4:ed:77:23:e5:83:76:76:63:
29 09:6d:be:05:6e:fc:aa:a0:c8:91:97:97:2d:85:02:
30 95:c2:fc:dd:dc:f4:4b:08:c3:be:3b:43:76:96:cc:
31 ec:55:7a:0f:00:fe:29:4b:87:ca:df:50:ba:5c:60:
32 e5:6f:8c:f0:56:7b:5b:20:3d:87:fd:81:7f:61:51:
33 6c:44:61:55:3a:52:28:cf:49:4d:72:3f:34:b0:a3:
34 04:18:e6:47:50:c7:f0:e1:a5:4f:8c:59:e3:73:ca:
35 b6:a6:0d:34:a3:40:fb:41:97:8c:66:93:64:29:20:
36 13:1b:f5:ab:69:74:11:88:13:8d:dc:15:c8:22:a2:
37 2b:16:74:f2:f1:8b:27:c1:5a:9c:c5:0e:95:78:ba:
38 fe:9f
39 Exponent: 65537 (0x10001)
40 X509v3 extensions:
41 X509v3 Subject Key Identifier:
42 6D:1B:79:D9:7C:01:F2:1D:99:D4:DD:54:90:BF:32:03:0F:28:4D:38
43 X509v3 Authority Key Identifier:
44 keyid:3A:B9:4C:96:D7:3D:14:A8:24:C8:DE:55:0A:54:05:5D:5C:A2:C9:99
45
46 Authority Information Access:
47 CA Issuers - URI:http://url-for-aia/Intermediate.cer
48
49 X509v3 CRL Distribution Points:
50
51 Full Name:
52 URI:http://url-for-crl/Intermediate.crl
53
54 X509v3 Key Usage: critical
55 Digital Signature, Key Encipherment
56 X509v3 Extended Key Usage:
57 TLS Web Server Authentication, TLS Web Client Authentication
58 Signature Algorithm: sha256WithRSAEncryption
59 b5:18:18:ce:72:38:e6:68:49:dd:96:86:a6:9e:d1:d3:2d:95:
60 1e:05:13:c8:ed:bf:b9:a0:e6:78:7e:dd:01:26:d2:fb:28:3a:
61 fa:30:f0:7f:0e:cc:e5:83:a5:fc:5f:bb:3d:23:c5:f2:b4:b3:
62 07:b3:4c:ec:5e:14:67:9d:09:5c:2b:1e:54:b2:03:29:6b:21:
63 3a:9e:cf:95:be:b7:1e:4f:ae:f3:99:15:5c:7b:48:42:fd:c8:
64 4a:ba:8e:34:81:3f:c7:cb:a2:d0:b0:c0:fb:6f:7a:3f:45:f1:
65 1b:1c:b1:3b:22:83:ce:10:05:5c:99:aa:5b:88:b2:cc:f8:f0:
66 bb:a6:48:d8:a5:a3:d0:90:00:66:25:73:5e:6d:80:ca:ec:97:
67 36:1c:aa:70:90:41:58:b0:8e:23:77:33:d7:ab:ba:d7:65:47:
68 c5:be:62:ea:42:8a:c9:45:3d:a8:50:54:f3:f6:3b:9e:30:62:
69 55:f1:66:f8:93:51:ad:5a:1a:70:26:ec:27:25:cf:37:6c:77:
70 70:25:34:63:94:41:4c:d1:4c:69:0f:b9:3c:88:95:5c:92:6f:
71 5f:a5:14:15:78:34:03:58:a8:0d:10:46:20:1d:83:a8:83:95:
72 b5:3d:94:62:40:c2:7f:d2:d4:49:a6:f9:e4:cc:42:f6:48:40:
73 dc:20:48:6d
74-----BEGIN CERTIFICATE-----
75MIIDoDCCAoigAwIBAgIUVkp4W9zBGSD+8xO+mUb5U9GkQKEwDQYJKoZIhvcNAQEL
76BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
77MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
78AAOCAQ8AMIIBCgKCAQEAu9M89Uzfc2HJ0L5WuH/mUlacO4SDI9jqMMvMAbodNnDT
79TFhidC+WV3zlsCdv+nLAWwsM9uweO8cERbiJl776SSe2wgopuJjNpKRUKc5VxZH/
80idNRh4jQw+8M3kOw4LnZI5LwBEK2UAYrGnuXPmek7Xcj5YN2dmMJbb4FbvyqoMiR
81l5cthQKVwvzd3PRLCMO+O0N2lszsVXoPAP4pS4fK31C6XGDlb4zwVntbID2H/YF/
82YVFsRGFVOlIoz0lNcj80sKMEGOZHUMfw4aVPjFnjc8q2pg00o0D7QZeMZpNkKSAT
83G/WraXQRiBON3BXIIqIrFnTy8YsnwVqcxQ6VeLr+nwIDAQABo4HpMIHmMB0GA1Ud
84DgQWBBRtG3nZfAHyHZnU3VSQvzIDDyhNODAfBgNVHSMEGDAWgBQ6uUyW1z0UqCTI
853lUKVAVdXKLJmTA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
86cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
87dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
88oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZIhvcNAQELBQAD
89ggEBALUYGM5yOOZoSd2Whqae0dMtlR4FE8jtv7mg5nh+3QEm0vsoOvow8H8OzOWD
90pfxfuz0jxfK0swezTOxeFGedCVwrHlSyAylrITqez5W+tx5PrvOZFVx7SEL9yEq6
91jjSBP8fLotCwwPtvej9F8RscsTsig84QBVyZqluIssz48LumSNilo9CQAGYlc15t
92gMrslzYcqnCQQViwjiN3M9erutdlR8W+YupCislFPahQVPP2O54wYlXxZviTUa1a
93GnAm7Cclzzdsd3AlNGOUQUzRTGkPuTyIlVySb1+lFBV4NANYqA0QRiAdg6iDlbU9
94lGJAwn/S1Emm+eTMQvZIQNwgSG0=
95-----END CERTIFICATE-----
96
97Certificate:
98 Data:
99 Version: 3 (0x2)
100 Serial Number:
101 6b:b7:9e:0a:83:55:83:77:1b:db:10:18:94:12:3f:c4:67:6e:66:e1
102 Signature Algorithm: sha256WithRSAEncryption
103 Issuer: CN=Root
104 Validity
105 Not Before: Oct 5 12:00:00 2021 GMT
106 Not After : Oct 5 12:00:00 2022 GMT
107 Subject: CN=Intermediate
108 Subject Public Key Info:
109 Public Key Algorithm: rsaEncryption
110 RSA Public-Key: (2048 bit)
111 Modulus:
112 00:bd:9a:08:67:72:a5:4d:ba:39:c4:0a:d5:a9:42:
113 46:7a:a0:f3:f2:2b:1f:83:91:58:a7:00:3b:b3:17:
114 51:e5:1f:83:13:44:10:14:7f:84:6d:97:57:de:32:
115 00:bd:15:18:e4:c7:89:8b:6e:5b:41:51:ad:d3:c9:
116 f7:3e:75:51:74:5c:71:40:2e:9b:95:be:8f:3b:17:
117 33:a5:3a:33:17:97:05:d7:30:0c:40:94:c1:8d:e7:
118 80:5f:f3:d4:3e:e4:46:8c:e3:80:ec:95:91:87:e0:
119 a0:a3:32:73:6c:44:c2:9c:12:a5:d3:6b:91:e0:60:
120 3d:a1:61:9d:09:6f:5f:7b:b1:c5:98:6a:3a:cc:85:
121 76:45:f2:44:0e:3f:cf:b9:56:5a:23:55:68:31:4b:
122 17:30:ad:a0:e2:b1:85:3f:6e:2e:7e:a7:38:b9:dd:
123 cd:3d:fb:74:1a:83:87:c2:ec:ec:6a:63:0b:5e:c8:
124 75:07:b5:4f:3f:93:58:a5:fe:3e:76:18:ee:16:df:
125 b1:52:b8:1a:f0:77:65:a3:b7:2d:16:a3:e6:c8:11:
126 67:e1:20:ea:2f:ed:0b:93:e6:c8:2a:a0:fc:34:b7:
127 fa:4b:21:33:60:02:86:cf:b4:bd:f0:c7:ec:f5:7a:
128 b4:ff:84:18:f4:73:a1:28:7a:31:de:08:b6:fd:be:
129 0a:7d
130 Exponent: 65537 (0x10001)
131 X509v3 extensions:
132 X509v3 Subject Key Identifier:
133 3A:B9:4C:96:D7:3D:14:A8:24:C8:DE:55:0A:54:05:5D:5C:A2:C9:99
134 X509v3 Authority Key Identifier:
135 keyid:AE:89:01:94:41:77:67:BD:EF:7F:98:4F:29:E7:1B:3A:18:B9:DD:51
136
137 Authority Information Access:
138 CA Issuers - URI:http://url-for-aia/Root.cer
139
140 X509v3 CRL Distribution Points:
141
142 Full Name:
143 URI:http://url-for-crl/Root.crl
144
145 X509v3 Key Usage: critical
146 Certificate Sign, CRL Sign
147 X509v3 Basic Constraints: critical
148 CA:TRUE
149 X509v3 Extended Key Usage:
150 TLS Web Client Authentication
151 Signature Algorithm: sha256WithRSAEncryption
152 24:78:e2:54:e9:1e:cb:af:11:8d:ec:44:39:bc:37:d8:2a:40:
153 d2:8d:11:c2:c8:5b:ca:43:07:4f:f0:14:33:15:be:8f:bd:7c:
154 23:e1:f7:e7:38:0f:a8:f9:73:3d:52:90:4f:56:80:62:20:93:
155 c1:e5:10:6c:98:b6:0f:80:30:ae:38:66:6e:78:80:cb:3e:0b:
156 44:f1:b7:d6:f2:f6:5c:1a:73:c6:ad:0a:fb:5f:61:59:e6:20:
157 b6:c4:8a:18:7b:cd:a7:37:b2:b9:1e:9c:77:dc:e9:93:4e:6d:
158 53:65:80:fc:d4:53:44:d3:f1:49:7f:a1:f7:94:35:d1:ce:78:
159 15:9b:c9:dd:23:63:9a:9e:bd:61:76:ce:00:2d:5e:81:53:12:
160 bb:75:2b:25:44:9d:d1:91:82:ac:ff:6e:7c:1f:6b:06:d5:0f:
161 a1:16:5c:f4:f0:5b:f4:b8:09:c3:d3:81:d6:03:7b:9d:71:78:
162 fb:c4:8b:99:61:f1:60:6c:ff:e7:74:3c:5b:ed:45:e0:3d:c0:
163 75:80:b5:a4:35:af:a9:5e:dc:a7:ee:63:ff:9d:67:26:da:aa:
164 8d:79:7d:d9:ac:56:ae:9c:2d:1d:0f:ca:66:3e:96:e9:0c:81:
165 62:dc:1e:4e:84:dc:0a:1b:c0:25:19:7f:d5:21:a2:06:24:ab:
166 b2:a4:24:c9
167-----BEGIN CERTIFICATE-----
168MIIDlTCCAn2gAwIBAgIUa7eeCoNVg3cb2xAYlBI/xGduZuEwDQYJKoZIhvcNAQEL
169BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
170MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
171ggEPADCCAQoCggEBAL2aCGdypU26OcQK1alCRnqg8/IrH4ORWKcAO7MXUeUfgxNE
172EBR/hG2XV94yAL0VGOTHiYtuW0FRrdPJ9z51UXRccUAum5W+jzsXM6U6MxeXBdcw
173DECUwY3ngF/z1D7kRozjgOyVkYfgoKMyc2xEwpwSpdNrkeBgPaFhnQlvX3uxxZhq
174OsyFdkXyRA4/z7lWWiNVaDFLFzCtoOKxhT9uLn6nOLndzT37dBqDh8Ls7GpjC17I
175dQe1Tz+TWKX+PnYY7hbfsVK4GvB3ZaO3LRaj5sgRZ+Eg6i/tC5PmyCqg/DS3+ksh
176M2AChs+0vfDH7PV6tP+EGPRzoSh6Md4Itv2+Cn0CAwEAAaOB4DCB3TAdBgNVHQ4E
177FgQUOrlMltc9FKgkyN5VClQFXVyiyZkwHwYDVR0jBBgwFoAUrokBlEF3Z73vf5hP
178KecbOhi53VEwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
179LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
180b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
181MBMGA1UdJQQMMAoGCCsGAQUFBwMCMA0GCSqGSIb3DQEBCwUAA4IBAQAkeOJU6R7L
182rxGN7EQ5vDfYKkDSjRHCyFvKQwdP8BQzFb6PvXwj4ffnOA+o+XM9UpBPVoBiIJPB
1835RBsmLYPgDCuOGZueIDLPgtE8bfW8vZcGnPGrQr7X2FZ5iC2xIoYe82nN7K5Hpx3
1843OmTTm1TZYD81FNE0/FJf6H3lDXRzngVm8ndI2Oanr1hds4ALV6BUxK7dSslRJ3R
185kYKs/258H2sG1Q+hFlz08Fv0uAnD04HWA3udcXj7xIuZYfFgbP/ndDxb7UXgPcB1
186gLWkNa+pXtyn7mP/nWcm2qqNeX3ZrFaunC0dD8pmPpbpDIFi3B5OhNwKG8AlGX/V
187IaIGJKuypCTJ
188-----END CERTIFICATE-----
189
190Certificate:
191 Data:
192 Version: 3 (0x2)
193 Serial Number:
194 6b:b7:9e:0a:83:55:83:77:1b:db:10:18:94:12:3f:c4:67:6e:66:e0
195 Signature Algorithm: sha256WithRSAEncryption
196 Issuer: CN=Root
197 Validity
198 Not Before: Oct 5 12:00:00 2021 GMT
199 Not After : Oct 5 12:00:00 2022 GMT
200 Subject: CN=Root
201 Subject Public Key Info:
202 Public Key Algorithm: rsaEncryption
203 RSA Public-Key: (2048 bit)
204 Modulus:
205 00:b6:30:63:d8:b0:11:71:5f:03:38:e5:24:a7:88:
206 9c:fe:f5:a6:2a:59:63:7b:18:39:d5:34:2f:27:4c:
207 fe:18:27:eb:7e:71:25:4d:af:71:97:7f:f0:18:b0:
208 19:a7:fd:ab:52:d9:01:aa:13:ff:3f:c9:c8:d4:87:
209 fa:69:53:28:b7:52:4f:91:ac:55:cb:38:7f:61:32:
210 b6:d9:20:f4:58:6f:c3:4c:4f:64:d7:14:34:8c:d3:
211 ac:f5:97:8a:9d:f6:d0:0b:64:b4:3a:55:71:0b:92:
212 b1:8e:df:2e:77:8a:fe:36:f6:0f:be:49:03:3d:42:
213 fc:4c:e4:50:f6:3e:86:d0:e4:0b:15:cd:27:49:ae:
214 7a:be:d7:05:28:68:f7:e7:35:1b:fc:2a:50:c1:66:
215 f3:31:11:f3:f9:40:80:51:3a:60:9a:87:47:fc:46:
216 99:e3:1a:c9:5c:76:d9:34:45:b0:82:d6:06:d7:ea:
217 5d:13:ce:ca:4e:9d:2e:80:cd:b3:5c:47:11:dd:f1:
218 8a:97:c7:8d:37:6a:1a:c7:97:13:ad:bf:9c:85:32:
219 df:20:0a:a9:27:3b:e6:26:c6:9d:98:d3:d1:d7:a0:
220 16:4d:b1:a3:3b:1f:19:c3:c5:81:dd:35:25:3c:86:
221 8e:8b:76:69:f2:e5:35:5e:3c:6c:3f:7e:47:57:7f:
222 eb:0d
223 Exponent: 65537 (0x10001)
224 X509v3 extensions:
225 X509v3 Subject Key Identifier:
226 AE:89:01:94:41:77:67:BD:EF:7F:98:4F:29:E7:1B:3A:18:B9:DD:51
227 X509v3 Authority Key Identifier:
228 keyid:AE:89:01:94:41:77:67:BD:EF:7F:98:4F:29:E7:1B:3A:18:B9:DD:51
229
230 Authority Information Access:
231 CA Issuers - URI:http://url-for-aia/Root.cer
232
233 X509v3 CRL Distribution Points:
234
235 Full Name:
236 URI:http://url-for-crl/Root.crl
237
238 X509v3 Key Usage: critical
239 Certificate Sign, CRL Sign
240 X509v3 Basic Constraints: critical
241 CA:TRUE
242 Signature Algorithm: sha256WithRSAEncryption
243 8b:5d:0a:24:04:16:0f:a6:8c:bc:d2:d2:f4:b6:a1:b5:34:39:
244 d1:be:3d:0f:d1:84:38:84:34:09:29:a9:f2:5f:3c:14:61:cb:
245 45:cf:73:19:63:95:b6:59:0f:7f:17:20:f1:a9:1d:4a:92:f9:
246 3e:99:ae:54:98:75:f0:3f:39:b6:79:ae:5b:91:19:e0:34:6d:
247 02:0e:80:1e:42:2c:5d:e0:68:94:c1:45:f0:fa:f0:ae:f2:7a:
248 4c:5a:a1:2b:35:c7:5e:d7:ed:ab:16:e5:7d:e5:65:9a:0f:87:
249 74:42:a6:9e:89:9f:df:54:da:68:58:6f:dc:c4:c1:62:23:8c:
250 e1:d8:4e:64:43:5b:4e:02:86:4b:58:6d:91:02:d2:94:9c:84:
251 3f:39:61:60:32:ea:56:60:f7:1d:b0:24:c7:62:f4:7e:59:32:
252 fa:5b:d4:dc:7f:6b:60:44:df:6d:d5:f9:29:3e:69:40:a0:8e:
253 a1:de:03:db:f2:86:83:75:8c:38:97:df:70:24:6e:d5:00:82:
254 61:96:c8:3d:d8:c9:a9:88:b7:3b:6b:32:eb:78:8c:de:7b:e8:
255 2f:d5:7a:1c:d2:99:2a:7e:dd:c1:cf:de:6c:11:5d:61:bc:59:
256 cf:18:a2:fc:14:1b:ff:57:dc:b5:9c:b6:9f:63:ae:88:ff:78:
257 6e:46:40:3b
258-----BEGIN CERTIFICATE-----
259MIIDeDCCAmCgAwIBAgIUa7eeCoNVg3cb2xAYlBI/xGduZuAwDQYJKoZIhvcNAQEL
260BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
261MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
262AoIBAQC2MGPYsBFxXwM45SSniJz+9aYqWWN7GDnVNC8nTP4YJ+t+cSVNr3GXf/AY
263sBmn/atS2QGqE/8/ycjUh/ppUyi3Uk+RrFXLOH9hMrbZIPRYb8NMT2TXFDSM06z1
264l4qd9tALZLQ6VXELkrGO3y53iv429g++SQM9QvxM5FD2PobQ5AsVzSdJrnq+1wUo
265aPfnNRv8KlDBZvMxEfP5QIBROmCah0f8RpnjGslcdtk0RbCC1gbX6l0TzspOnS6A
266zbNcRxHd8YqXx403ahrHlxOtv5yFMt8gCqknO+Ymxp2Y09HXoBZNsaM7HxnDxYHd
267NSU8ho6Ldmny5TVePGw/fkdXf+sNAgMBAAGjgcswgcgwHQYDVR0OBBYEFK6JAZRB
268d2e973+YTynnGzoYud1RMB8GA1UdIwQYMBaAFK6JAZRBd2e973+YTynnGzoYud1R
269MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
270L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
271b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
2729w0BAQsFAAOCAQEAi10KJAQWD6aMvNLS9LahtTQ50b49D9GEOIQ0CSmp8l88FGHL
273Rc9zGWOVtlkPfxcg8akdSpL5PpmuVJh18D85tnmuW5EZ4DRtAg6AHkIsXeBolMFF
2748PrwrvJ6TFqhKzXHXtftqxblfeVlmg+HdEKmnomf31TaaFhv3MTBYiOM4dhOZENb
275TgKGS1htkQLSlJyEPzlhYDLqVmD3HbAkx2L0flky+lvU3H9rYETfbdX5KT5pQKCO
276od4D2/KGg3WMOJffcCRu1QCCYZbIPdjJqYi3O2sy63iM3nvoL9V6HNKZKn7dwc/e
277bBFdYbxZzxii/BQb/1fctZy2n2OuiP94bkZAOw==
278-----END CERTIFICATE-----