1[Created by: ./generate-chains.py]
2
3Certificate chain where the leaf has a basic constraints extension with
4CA=true
5
6Certificate:
7    Data:
8        Version: 3 (0x2)
9        Serial Number:
10            08:bc:87:56:5b:c5:c0:7d:88:48:cc:cc:ca:97:dd:d6:7e:b8:ae:e7
11        Signature Algorithm: sha256WithRSAEncryption
12        Issuer: CN=Intermediate
13        Validity
14            Not Before: Oct  5 12:00:00 2021 GMT
15            Not After : Oct  5 12:00:00 2022 GMT
16        Subject: CN=Target
17        Subject Public Key Info:
18            Public Key Algorithm: rsaEncryption
19                Public-Key: (2048 bit)
20                Modulus:
21                    00:be:16:a4:92:0f:af:f6:da:90:19:3e:26:29:a9:
22                    04:35:24:67:db:93:b7:89:61:5c:c2:84:07:ff:db:
23                    83:9a:1b:5c:9d:2f:ac:f6:20:87:74:fd:5a:f7:96:
24                    da:aa:8b:77:d0:7d:cb:87:cf:96:37:2d:04:ef:19:
25                    f7:09:6d:aa:73:74:16:b9:1c:f1:7b:15:9f:50:a9:
26                    be:33:08:86:9f:88:9e:0c:b4:3b:2a:98:06:43:0f:
27                    bb:14:ac:65:27:0f:c1:6c:58:d0:54:ce:62:89:ed:
28                    03:99:3c:c7:f0:2e:ab:c5:f3:f0:5a:b6:91:68:6f:
29                    aa:4b:37:e9:d8:dd:63:0f:6c:a2:0b:f7:72:0e:6f:
30                    a3:ee:b9:7e:c7:4b:a4:cd:69:6c:b8:a3:66:14:14:
31                    46:96:95:ca:60:64:af:58:93:0b:a2:d8:17:04:5c:
32                    cd:ec:48:85:7a:4b:5b:c2:84:00:52:fa:8f:25:7b:
33                    ce:0b:9b:14:a6:21:cc:48:f6:14:d5:c1:1b:3a:8b:
34                    ba:ae:ef:15:55:0d:63:4d:f6:ea:f1:ca:1c:11:04:
35                    3a:c9:f8:87:13:c2:8f:cb:f1:1d:18:79:2f:66:1d:
36                    10:45:2d:4c:55:49:4c:3b:68:28:25:4a:8b:99:a9:
37                    8d:27:66:86:71:4a:6d:f1:f8:fb:58:7e:db:3b:2d:
38                    9e:8b
39                Exponent: 65537 (0x10001)
40        X509v3 extensions:
41            X509v3 Subject Key Identifier:
42                F8:96:4F:23:BA:6B:B3:8F:4B:07:6E:24:86:07:55:F1:E9:8E:6E:02
43            X509v3 Authority Key Identifier:
44                0D:33:4F:98:F6:3C:94:C8:20:5B:51:C9:BD:ED:09:3B:F0:B4:F3:D6
45            Authority Information Access:
46                CA Issuers - URI:http://url-for-aia/Intermediate.cer
47            X509v3 CRL Distribution Points:
48                Full Name:
49                  URI:http://url-for-crl/Intermediate.crl
50            X509v3 Key Usage: critical
51                Digital Signature, Key Encipherment
52            X509v3 Extended Key Usage:
53                TLS Web Server Authentication, TLS Web Client Authentication
54            X509v3 Basic Constraints: critical
55                CA:TRUE
56    Signature Algorithm: sha256WithRSAEncryption
57    Signature Value:
58        2f:f3:3e:5f:9a:ed:43:1c:58:2e:15:aa:94:d8:d7:37:87:83:
59        79:ff:a8:7d:d2:bf:3d:4d:3c:99:91:78:93:84:7b:ce:1e:07:
60        55:f8:bd:5d:d1:e6:82:c4:a9:c0:6b:bf:e4:73:df:d0:b6:38:
61        09:66:84:23:50:e3:16:37:15:88:89:78:08:31:7d:52:e0:56:
62        a2:2d:ef:a6:75:5a:a3:44:c5:ae:23:a3:fc:92:81:b6:cf:3f:
63        bc:ba:a1:4d:da:6d:0a:18:04:95:7a:4f:b3:74:e7:1b:19:97:
64        fd:c3:32:c3:77:17:15:7a:d5:9b:6c:54:9c:16:1b:3f:37:3e:
65        b9:ed:97:69:f9:da:3d:cf:e4:aa:2a:39:45:28:2b:2e:4e:d7:
66        60:bb:fd:cb:3d:c2:19:85:e0:f6:1d:1e:bb:21:4c:f4:ee:a1:
67        cf:dc:c9:24:53:cb:80:44:5f:d3:cf:83:09:90:17:1c:32:a8:
68        c5:49:c1:c9:e6:28:f0:88:7d:36:d1:fe:0b:dc:a9:3f:79:ae:
69        c9:89:4c:04:ec:49:ac:6d:58:24:67:20:d3:8f:29:c1:87:84:
70        2f:69:4f:da:18:7d:f6:a0:88:92:ea:db:47:8d:f0:b3:a3:c9:
71        15:6a:c8:e5:84:79:74:cd:e1:ee:fa:02:79:05:1f:5c:76:4a:
72        71:ae:58:b8
73-----BEGIN CERTIFICATE-----
74MIIDsTCCApmgAwIBAgIUCLyHVlvFwH2ISMzMypfd1n64rucwDQYJKoZIhvcNAQEL
75BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
76MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
77AAOCAQ8AMIIBCgKCAQEAvhakkg+v9tqQGT4mKakENSRn25O3iWFcwoQH/9uDmhtc
78nS+s9iCHdP1a95baqot30H3Lh8+WNy0E7xn3CW2qc3QWuRzxexWfUKm+MwiGn4ie
79DLQ7KpgGQw+7FKxlJw/BbFjQVM5iie0DmTzH8C6rxfPwWraRaG+qSzfp2N1jD2yi
80C/dyDm+j7rl+x0ukzWlsuKNmFBRGlpXKYGSvWJMLotgXBFzN7EiFektbwoQAUvqP
81JXvOC5sUpiHMSPYU1cEbOou6ru8VVQ1jTfbq8cocEQQ6yfiHE8KPy/EdGHkvZh0Q
82RS1MVUlMO2goJUqLmamNJ2aGcUpt8fj7WH7bOy2eiwIDAQABo4H6MIH3MB0GA1Ud
83DgQWBBT4lk8jumuzj0sHbiSGB1Xx6Y5uAjAfBgNVHSMEGDAWgBQNM0+Y9jyUyCBb
84Ucm97Qk78LTz1jA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
85cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
86dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
87oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwEB
88/zANBgkqhkiG9w0BAQsFAAOCAQEAL/M+X5rtQxxYLhWqlNjXN4eDef+ofdK/PU08
89mZF4k4R7zh4HVfi9XdHmgsSpwGu/5HPf0LY4CWaEI1DjFjcViIl4CDF9UuBWoi3v
90pnVao0TFriOj/JKBts8/vLqhTdptChgElXpPs3TnGxmX/cMyw3cXFXrVm2xUnBYb
91Pzc+ue2XafnaPc/kqio5RSgrLk7XYLv9yz3CGYXg9h0euyFM9O6hz9zJJFPLgERf
9208+DCZAXHDKoxUnByeYo8Ih9NtH+C9ypP3muyYlMBOxJrG1YJGcg048pwYeEL2lP
932hh99qCIkurbR43ws6PJFWrI5YR5dM3h7voCeQUfXHZKca5YuA==
94-----END CERTIFICATE-----
95
96Certificate:
97    Data:
98        Version: 3 (0x2)
99        Serial Number:
100            02:6e:e9:d7:f8:5d:44:ad:34:05:15:23:70:65:9e:cc:e0:a7:66:53
101        Signature Algorithm: sha256WithRSAEncryption
102        Issuer: CN=Root
103        Validity
104            Not Before: Oct  5 12:00:00 2021 GMT
105            Not After : Oct  5 12:00:00 2022 GMT
106        Subject: CN=Intermediate
107        Subject Public Key Info:
108            Public Key Algorithm: rsaEncryption
109                Public-Key: (2048 bit)
110                Modulus:
111                    00:c5:8c:3e:44:f5:7d:89:d5:8d:77:86:f9:d5:a0:
112                    8b:dc:1d:0f:3e:d0:f8:d1:72:c4:5b:d0:83:56:b5:
113                    98:0c:4e:0c:3d:48:f7:db:06:e8:c2:eb:5c:fc:f4:
114                    2f:b0:23:74:fc:95:23:0c:7d:3d:be:29:89:6f:d5:
115                    97:d3:8b:6f:bf:36:4d:99:4e:c9:fe:59:a2:9a:56:
116                    df:3c:a6:e0:f4:8e:2b:20:00:4a:4d:6e:15:c9:7f:
117                    c0:35:8f:5a:48:08:0b:41:d1:cf:84:c0:fd:99:71:
118                    26:96:7b:b5:6f:1d:ce:db:74:b1:d3:1d:39:37:70:
119                    d0:e1:53:d5:44:72:e2:80:c2:bb:c7:71:93:4e:02:
120                    40:ac:a0:af:33:72:a1:6d:9a:44:9b:45:ad:22:74:
121                    fc:18:74:e0:84:34:00:00:76:46:2a:77:f9:ff:a8:
122                    af:71:b9:e6:e6:32:9a:d4:d2:a7:dd:71:f9:2a:49:
123                    2a:fe:c2:8e:cf:9c:77:f7:39:7d:d3:99:09:b1:49:
124                    30:35:e5:8d:3a:c3:3e:6c:1d:d6:b7:26:bb:90:e4:
125                    3b:c3:2e:aa:37:18:bb:28:f3:79:d2:69:9c:87:7f:
126                    78:5f:c5:97:d1:d8:45:14:17:38:6d:66:23:2e:90:
127                    dd:25:c1:60:3c:7c:f5:9a:d2:16:05:c0:7f:89:3e:
128                    10:87
129                Exponent: 65537 (0x10001)
130        X509v3 extensions:
131            X509v3 Subject Key Identifier:
132                0D:33:4F:98:F6:3C:94:C8:20:5B:51:C9:BD:ED:09:3B:F0:B4:F3:D6
133            X509v3 Authority Key Identifier:
134                7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8
135            Authority Information Access:
136                CA Issuers - URI:http://url-for-aia/Root.cer
137            X509v3 CRL Distribution Points:
138                Full Name:
139                  URI:http://url-for-crl/Root.crl
140            X509v3 Key Usage: critical
141                Certificate Sign, CRL Sign
142            X509v3 Basic Constraints: critical
143                CA:TRUE
144    Signature Algorithm: sha256WithRSAEncryption
145    Signature Value:
146        76:1d:d7:22:f9:e8:d8:a6:ec:b0:bf:06:92:7c:2a:82:cd:8a:
147        7b:13:bd:c6:d9:da:4b:b3:94:12:82:59:a8:16:76:c1:05:c0:
148        7e:7d:19:b4:8f:35:c7:58:73:ff:7d:9e:8c:55:6f:0b:b3:e3:
149        5f:d0:e8:57:c0:92:6c:47:a7:55:84:77:90:19:c1:67:1f:8a:
150        32:70:0c:3e:de:01:6f:c6:79:1e:a0:10:15:a2:ec:f6:1a:19:
151        10:ac:aa:bf:63:0b:52:88:3d:61:5e:e9:6b:76:4d:b1:f5:16:
152        a7:09:4f:68:67:1b:47:b5:62:37:b2:6b:66:e0:e7:51:86:50:
153        32:54:b7:b7:e8:77:5c:d8:ff:8d:3b:6e:49:ac:5c:ce:33:38:
154        52:0f:41:80:1d:b0:fd:35:8d:37:23:06:e3:1c:89:f4:d3:6c:
155        73:d0:d3:8f:72:db:9a:7a:34:40:54:77:97:ae:9f:5b:4d:d8:
156        94:99:a7:89:11:04:bb:52:06:ba:32:fd:f9:16:b7:ee:a6:03:
157        55:39:31:4f:89:3b:9c:9b:d3:61:4b:a0:f2:ab:24:ad:95:46:
158        2e:5e:27:be:03:f2:e0:4d:70:27:63:9a:c1:f9:1b:00:ab:6b:
159        de:e7:f1:04:a7:b5:bd:85:31:a6:32:4b:0e:e8:a5:ab:8d:c1:
160        52:19:f2:b6
161-----BEGIN CERTIFICATE-----
162MIIDgDCCAmigAwIBAgIUAm7p1/hdRK00BRUjcGWezOCnZlMwDQYJKoZIhvcNAQEL
163BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
164MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
165ggEPADCCAQoCggEBAMWMPkT1fYnVjXeG+dWgi9wdDz7Q+NFyxFvQg1a1mAxODD1I
16699sG6MLrXPz0L7AjdPyVIwx9Pb4piW/Vl9OLb782TZlOyf5ZoppW3zym4PSOKyAA
167Sk1uFcl/wDWPWkgIC0HRz4TA/ZlxJpZ7tW8dztt0sdMdOTdw0OFT1URy4oDCu8dx
168k04CQKygrzNyoW2aRJtFrSJ0/Bh04IQ0AAB2Rip3+f+or3G55uYymtTSp91x+SpJ
169Kv7Cjs+cd/c5fdOZCbFJMDXljTrDPmwd1rcmu5DkO8MuqjcYuyjzedJpnId/eF/F
170l9HYRRQXOG1mIy6Q3SXBYDx89ZrSFgXAf4k+EIcCAwEAAaOByzCByDAdBgNVHQ4E
171FgQUDTNPmPY8lMggW1HJve0JO/C089YwHwYDVR0jBBgwFoAUepipP7qA3WgbHIdX
172LkI/X7NQXagwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
173LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
174b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
175MA0GCSqGSIb3DQEBCwUAA4IBAQB2Hdci+ejYpuywvwaSfCqCzYp7E73G2dpLs5QS
176glmoFnbBBcB+fRm0jzXHWHP/fZ6MVW8Ls+Nf0OhXwJJsR6dVhHeQGcFnH4oycAw+
1773gFvxnkeoBAVouz2GhkQrKq/YwtSiD1hXulrdk2x9RanCU9oZxtHtWI3smtm4OdR
178hlAyVLe36Hdc2P+NO25JrFzOMzhSD0GAHbD9NY03IwbjHIn002xz0NOPctuaejRA
179VHeXrp9bTdiUmaeJEQS7Uga6Mv35FrfupgNVOTFPiTucm9NhS6DyqyStlUYuXie+
180A/LgTXAnY5rB+RsAq2ve5/EEp7W9hTGmMksO6KWrjcFSGfK2
181-----END CERTIFICATE-----
182
183Certificate:
184    Data:
185        Version: 3 (0x2)
186        Serial Number:
187            02:6e:e9:d7:f8:5d:44:ad:34:05:15:23:70:65:9e:cc:e0:a7:66:52
188        Signature Algorithm: sha256WithRSAEncryption
189        Issuer: CN=Root
190        Validity
191            Not Before: Oct  5 12:00:00 2021 GMT
192            Not After : Oct  5 12:00:00 2022 GMT
193        Subject: CN=Root
194        Subject Public Key Info:
195            Public Key Algorithm: rsaEncryption
196                Public-Key: (2048 bit)
197                Modulus:
198                    00:af:0c:3f:db:02:4b:9e:87:03:a5:64:a7:18:9a:
199                    c1:4c:c8:bf:1b:e7:5a:04:52:70:6c:a2:bc:19:99:
200                    33:44:f9:9a:6b:30:d8:57:5b:be:a0:dc:8c:97:91:
201                    20:97:f8:04:ef:21:1d:b1:c7:a3:1b:57:02:c9:bd:
202                    53:54:f8:58:96:f3:c2:d7:5e:ae:61:c1:d5:08:ff:
203                    88:bf:80:c1:ef:c8:6d:99:ac:8e:55:f6:e0:da:8f:
204                    f3:31:f1:e5:02:82:2c:f9:42:cb:7c:4c:2b:ba:97:
205                    eb:ef:cd:b0:d5:31:a1:09:f8:5e:62:74:4e:29:02:
206                    9b:7e:de:0b:31:36:b6:fd:36:e5:a6:a8:ac:05:1f:
207                    5f:32:e6:60:f7:5f:8f:f3:a5:6e:3d:c4:ec:dd:23:
208                    ac:4b:69:ab:df:41:65:2b:bd:f2:ed:51:e0:94:e4:
209                    5f:35:6c:be:c8:be:2a:10:27:55:92:6b:82:ac:72:
210                    b7:c4:de:47:04:03:6c:57:fd:de:f1:17:3b:16:0c:
211                    d7:cd:26:28:84:b2:df:19:e7:2f:45:87:2f:91:82:
212                    d5:21:4b:0a:49:77:a0:46:39:2d:fc:ab:63:1f:76:
213                    2d:c1:4a:03:1c:d8:e0:dc:a3:4d:c8:56:aa:41:1c:
214                    e9:11:63:10:c6:55:03:4e:c8:be:53:7e:3c:a9:d7:
215                    13:af
216                Exponent: 65537 (0x10001)
217        X509v3 extensions:
218            X509v3 Subject Key Identifier:
219                7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8
220            X509v3 Authority Key Identifier:
221                7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8
222            Authority Information Access:
223                CA Issuers - URI:http://url-for-aia/Root.cer
224            X509v3 CRL Distribution Points:
225                Full Name:
226                  URI:http://url-for-crl/Root.crl
227            X509v3 Key Usage: critical
228                Certificate Sign, CRL Sign
229            X509v3 Basic Constraints: critical
230                CA:TRUE
231    Signature Algorithm: sha256WithRSAEncryption
232    Signature Value:
233        07:9d:ea:d3:5a:05:0f:1d:14:12:d4:a3:1f:1e:29:e7:5b:8c:
234        8f:9f:3e:b9:f3:85:d2:5e:73:9c:41:7c:81:bf:75:fe:61:49:
235        dd:d9:69:95:43:4c:46:8d:b7:49:1b:b8:4e:a0:e8:f7:ab:dc:
236        c1:6c:85:43:4b:f1:94:a0:3c:b6:06:db:20:70:fe:cb:b4:a3:
237        ee:d3:12:93:70:c1:c1:97:30:8e:78:7a:7e:31:f6:35:d4:b6:
238        e8:f4:9e:1c:11:c9:5b:51:8b:18:da:c3:65:48:d8:0c:9d:7e:
239        73:27:26:b1:3c:25:b2:9c:12:79:a8:3e:37:18:14:ca:a9:33:
240        78:17:03:12:bd:42:48:6f:78:0a:4f:8d:b5:c0:88:c4:d2:a5:
241        99:84:2b:a5:d9:40:85:65:67:aa:12:74:4f:c9:b6:0a:64:17:
242        d7:af:51:3b:13:08:70:ce:65:af:36:59:46:32:b3:40:45:c3:
243        1a:8b:56:3e:2b:81:5d:81:48:a6:f9:8e:5b:26:c2:1a:1a:68:
244        57:a1:22:8a:42:2e:9a:51:8c:18:f8:fe:d6:a4:89:b5:7d:64:
245        14:5b:b1:5d:26:92:f1:17:54:8a:bb:e6:d7:97:82:6c:e1:b4:
246        39:42:68:d1:69:64:a9:21:1c:28:e1:ae:bd:eb:09:78:76:c9:
247        7f:cd:79:90
248-----BEGIN CERTIFICATE-----
249MIIDeDCCAmCgAwIBAgIUAm7p1/hdRK00BRUjcGWezOCnZlIwDQYJKoZIhvcNAQEL
250BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
251MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
252AoIBAQCvDD/bAkuehwOlZKcYmsFMyL8b51oEUnBsorwZmTNE+ZprMNhXW76g3IyX
253kSCX+ATvIR2xx6MbVwLJvVNU+FiW88LXXq5hwdUI/4i/gMHvyG2ZrI5V9uDaj/Mx
2548eUCgiz5Qst8TCu6l+vvzbDVMaEJ+F5idE4pApt+3gsxNrb9NuWmqKwFH18y5mD3
255X4/zpW49xOzdI6xLaavfQWUrvfLtUeCU5F81bL7IvioQJ1WSa4KscrfE3kcEA2xX
256/d7xFzsWDNfNJiiEst8Z5y9Fhy+RgtUhSwpJd6BGOS38q2Mfdi3BSgMc2ODco03I
257VqpBHOkRYxDGVQNOyL5Tfjyp1xOvAgMBAAGjgcswgcgwHQYDVR0OBBYEFHqYqT+6
258gN1oGxyHVy5CP1+zUF2oMB8GA1UdIwQYMBaAFHqYqT+6gN1oGxyHVy5CP1+zUF2o
259MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
260L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
261b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
2629w0BAQsFAAOCAQEAB53q01oFDx0UEtSjHx4p51uMj58+ufOF0l5znEF8gb91/mFJ
2633dlplUNMRo23SRu4TqDo96vcwWyFQ0vxlKA8tgbbIHD+y7Sj7tMSk3DBwZcwjnh6
264fjH2NdS26PSeHBHJW1GLGNrDZUjYDJ1+cycmsTwlspwSeag+NxgUyqkzeBcDEr1C
265SG94Ck+NtcCIxNKlmYQrpdlAhWVnqhJ0T8m2CmQX169ROxMIcM5lrzZZRjKzQEXD
266GotWPiuBXYFIpvmOWybCGhpoV6EiikIumlGMGPj+1qSJtX1kFFuxXSaS8RdUirvm
26715eCbOG0OUJo0WlkqSEcKOGuvesJeHbJf815kA==
268-----END CERTIFICATE-----
269