1[Created by: ./generate-chains.py] 2 3Certificate chain where the leaf has a basic constraints extension with 4CA=true 5 6Certificate: 7 Data: 8 Version: 3 (0x2) 9 Serial Number: 10 08:bc:87:56:5b:c5:c0:7d:88:48:cc:cc:ca:97:dd:d6:7e:b8:ae:e7 11 Signature Algorithm: sha256WithRSAEncryption 12 Issuer: CN=Intermediate 13 Validity 14 Not Before: Oct 5 12:00:00 2021 GMT 15 Not After : Oct 5 12:00:00 2022 GMT 16 Subject: CN=Target 17 Subject Public Key Info: 18 Public Key Algorithm: rsaEncryption 19 Public-Key: (2048 bit) 20 Modulus: 21 00:be:16:a4:92:0f:af:f6:da:90:19:3e:26:29:a9: 22 04:35:24:67:db:93:b7:89:61:5c:c2:84:07:ff:db: 23 83:9a:1b:5c:9d:2f:ac:f6:20:87:74:fd:5a:f7:96: 24 da:aa:8b:77:d0:7d:cb:87:cf:96:37:2d:04:ef:19: 25 f7:09:6d:aa:73:74:16:b9:1c:f1:7b:15:9f:50:a9: 26 be:33:08:86:9f:88:9e:0c:b4:3b:2a:98:06:43:0f: 27 bb:14:ac:65:27:0f:c1:6c:58:d0:54:ce:62:89:ed: 28 03:99:3c:c7:f0:2e:ab:c5:f3:f0:5a:b6:91:68:6f: 29 aa:4b:37:e9:d8:dd:63:0f:6c:a2:0b:f7:72:0e:6f: 30 a3:ee:b9:7e:c7:4b:a4:cd:69:6c:b8:a3:66:14:14: 31 46:96:95:ca:60:64:af:58:93:0b:a2:d8:17:04:5c: 32 cd:ec:48:85:7a:4b:5b:c2:84:00:52:fa:8f:25:7b: 33 ce:0b:9b:14:a6:21:cc:48:f6:14:d5:c1:1b:3a:8b: 34 ba:ae:ef:15:55:0d:63:4d:f6:ea:f1:ca:1c:11:04: 35 3a:c9:f8:87:13:c2:8f:cb:f1:1d:18:79:2f:66:1d: 36 10:45:2d:4c:55:49:4c:3b:68:28:25:4a:8b:99:a9: 37 8d:27:66:86:71:4a:6d:f1:f8:fb:58:7e:db:3b:2d: 38 9e:8b 39 Exponent: 65537 (0x10001) 40 X509v3 extensions: 41 X509v3 Subject Key Identifier: 42 F8:96:4F:23:BA:6B:B3:8F:4B:07:6E:24:86:07:55:F1:E9:8E:6E:02 43 X509v3 Authority Key Identifier: 44 0D:33:4F:98:F6:3C:94:C8:20:5B:51:C9:BD:ED:09:3B:F0:B4:F3:D6 45 Authority Information Access: 46 CA Issuers - URI:http://url-for-aia/Intermediate.cer 47 X509v3 CRL Distribution Points: 48 Full Name: 49 URI:http://url-for-crl/Intermediate.crl 50 X509v3 Key Usage: critical 51 Digital Signature, Key Encipherment 52 X509v3 Extended Key Usage: 53 TLS Web Server Authentication, TLS Web Client Authentication 54 X509v3 Basic Constraints: critical 55 CA:TRUE 56 Signature Algorithm: sha256WithRSAEncryption 57 Signature Value: 58 2f:f3:3e:5f:9a:ed:43:1c:58:2e:15:aa:94:d8:d7:37:87:83: 59 79:ff:a8:7d:d2:bf:3d:4d:3c:99:91:78:93:84:7b:ce:1e:07: 60 55:f8:bd:5d:d1:e6:82:c4:a9:c0:6b:bf:e4:73:df:d0:b6:38: 61 09:66:84:23:50:e3:16:37:15:88:89:78:08:31:7d:52:e0:56: 62 a2:2d:ef:a6:75:5a:a3:44:c5:ae:23:a3:fc:92:81:b6:cf:3f: 63 bc:ba:a1:4d:da:6d:0a:18:04:95:7a:4f:b3:74:e7:1b:19:97: 64 fd:c3:32:c3:77:17:15:7a:d5:9b:6c:54:9c:16:1b:3f:37:3e: 65 b9:ed:97:69:f9:da:3d:cf:e4:aa:2a:39:45:28:2b:2e:4e:d7: 66 60:bb:fd:cb:3d:c2:19:85:e0:f6:1d:1e:bb:21:4c:f4:ee:a1: 67 cf:dc:c9:24:53:cb:80:44:5f:d3:cf:83:09:90:17:1c:32:a8: 68 c5:49:c1:c9:e6:28:f0:88:7d:36:d1:fe:0b:dc:a9:3f:79:ae: 69 c9:89:4c:04:ec:49:ac:6d:58:24:67:20:d3:8f:29:c1:87:84: 70 2f:69:4f:da:18:7d:f6:a0:88:92:ea:db:47:8d:f0:b3:a3:c9: 71 15:6a:c8:e5:84:79:74:cd:e1:ee:fa:02:79:05:1f:5c:76:4a: 72 71:ae:58:b8 73-----BEGIN CERTIFICATE----- 74MIIDsTCCApmgAwIBAgIUCLyHVlvFwH2ISMzMypfd1n64rucwDQYJKoZIhvcNAQEL 75BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy 76MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF 77AAOCAQ8AMIIBCgKCAQEAvhakkg+v9tqQGT4mKakENSRn25O3iWFcwoQH/9uDmhtc 78nS+s9iCHdP1a95baqot30H3Lh8+WNy0E7xn3CW2qc3QWuRzxexWfUKm+MwiGn4ie 79DLQ7KpgGQw+7FKxlJw/BbFjQVM5iie0DmTzH8C6rxfPwWraRaG+qSzfp2N1jD2yi 80C/dyDm+j7rl+x0ukzWlsuKNmFBRGlpXKYGSvWJMLotgXBFzN7EiFektbwoQAUvqP 81JXvOC5sUpiHMSPYU1cEbOou6ru8VVQ1jTfbq8cocEQQ6yfiHE8KPy/EdGHkvZh0Q 82RS1MVUlMO2goJUqLmamNJ2aGcUpt8fj7WH7bOy2eiwIDAQABo4H6MIH3MB0GA1Ud 83DgQWBBT4lk8jumuzj0sHbiSGB1Xx6Y5uAjAfBgNVHSMEGDAWgBQNM0+Y9jyUyCBb 84Ucm97Qk78LTz1jA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 85cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 86dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF 87oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwEB 88/zANBgkqhkiG9w0BAQsFAAOCAQEAL/M+X5rtQxxYLhWqlNjXN4eDef+ofdK/PU08 89mZF4k4R7zh4HVfi9XdHmgsSpwGu/5HPf0LY4CWaEI1DjFjcViIl4CDF9UuBWoi3v 90pnVao0TFriOj/JKBts8/vLqhTdptChgElXpPs3TnGxmX/cMyw3cXFXrVm2xUnBYb 91Pzc+ue2XafnaPc/kqio5RSgrLk7XYLv9yz3CGYXg9h0euyFM9O6hz9zJJFPLgERf 9208+DCZAXHDKoxUnByeYo8Ih9NtH+C9ypP3muyYlMBOxJrG1YJGcg048pwYeEL2lP 932hh99qCIkurbR43ws6PJFWrI5YR5dM3h7voCeQUfXHZKca5YuA== 94-----END CERTIFICATE----- 95 96Certificate: 97 Data: 98 Version: 3 (0x2) 99 Serial Number: 100 02:6e:e9:d7:f8:5d:44:ad:34:05:15:23:70:65:9e:cc:e0:a7:66:53 101 Signature Algorithm: sha256WithRSAEncryption 102 Issuer: CN=Root 103 Validity 104 Not Before: Oct 5 12:00:00 2021 GMT 105 Not After : Oct 5 12:00:00 2022 GMT 106 Subject: CN=Intermediate 107 Subject Public Key Info: 108 Public Key Algorithm: rsaEncryption 109 Public-Key: (2048 bit) 110 Modulus: 111 00:c5:8c:3e:44:f5:7d:89:d5:8d:77:86:f9:d5:a0: 112 8b:dc:1d:0f:3e:d0:f8:d1:72:c4:5b:d0:83:56:b5: 113 98:0c:4e:0c:3d:48:f7:db:06:e8:c2:eb:5c:fc:f4: 114 2f:b0:23:74:fc:95:23:0c:7d:3d:be:29:89:6f:d5: 115 97:d3:8b:6f:bf:36:4d:99:4e:c9:fe:59:a2:9a:56: 116 df:3c:a6:e0:f4:8e:2b:20:00:4a:4d:6e:15:c9:7f: 117 c0:35:8f:5a:48:08:0b:41:d1:cf:84:c0:fd:99:71: 118 26:96:7b:b5:6f:1d:ce:db:74:b1:d3:1d:39:37:70: 119 d0:e1:53:d5:44:72:e2:80:c2:bb:c7:71:93:4e:02: 120 40:ac:a0:af:33:72:a1:6d:9a:44:9b:45:ad:22:74: 121 fc:18:74:e0:84:34:00:00:76:46:2a:77:f9:ff:a8: 122 af:71:b9:e6:e6:32:9a:d4:d2:a7:dd:71:f9:2a:49: 123 2a:fe:c2:8e:cf:9c:77:f7:39:7d:d3:99:09:b1:49: 124 30:35:e5:8d:3a:c3:3e:6c:1d:d6:b7:26:bb:90:e4: 125 3b:c3:2e:aa:37:18:bb:28:f3:79:d2:69:9c:87:7f: 126 78:5f:c5:97:d1:d8:45:14:17:38:6d:66:23:2e:90: 127 dd:25:c1:60:3c:7c:f5:9a:d2:16:05:c0:7f:89:3e: 128 10:87 129 Exponent: 65537 (0x10001) 130 X509v3 extensions: 131 X509v3 Subject Key Identifier: 132 0D:33:4F:98:F6:3C:94:C8:20:5B:51:C9:BD:ED:09:3B:F0:B4:F3:D6 133 X509v3 Authority Key Identifier: 134 7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8 135 Authority Information Access: 136 CA Issuers - URI:http://url-for-aia/Root.cer 137 X509v3 CRL Distribution Points: 138 Full Name: 139 URI:http://url-for-crl/Root.crl 140 X509v3 Key Usage: critical 141 Certificate Sign, CRL Sign 142 X509v3 Basic Constraints: critical 143 CA:TRUE 144 Signature Algorithm: sha256WithRSAEncryption 145 Signature Value: 146 76:1d:d7:22:f9:e8:d8:a6:ec:b0:bf:06:92:7c:2a:82:cd:8a: 147 7b:13:bd:c6:d9:da:4b:b3:94:12:82:59:a8:16:76:c1:05:c0: 148 7e:7d:19:b4:8f:35:c7:58:73:ff:7d:9e:8c:55:6f:0b:b3:e3: 149 5f:d0:e8:57:c0:92:6c:47:a7:55:84:77:90:19:c1:67:1f:8a: 150 32:70:0c:3e:de:01:6f:c6:79:1e:a0:10:15:a2:ec:f6:1a:19: 151 10:ac:aa:bf:63:0b:52:88:3d:61:5e:e9:6b:76:4d:b1:f5:16: 152 a7:09:4f:68:67:1b:47:b5:62:37:b2:6b:66:e0:e7:51:86:50: 153 32:54:b7:b7:e8:77:5c:d8:ff:8d:3b:6e:49:ac:5c:ce:33:38: 154 52:0f:41:80:1d:b0:fd:35:8d:37:23:06:e3:1c:89:f4:d3:6c: 155 73:d0:d3:8f:72:db:9a:7a:34:40:54:77:97:ae:9f:5b:4d:d8: 156 94:99:a7:89:11:04:bb:52:06:ba:32:fd:f9:16:b7:ee:a6:03: 157 55:39:31:4f:89:3b:9c:9b:d3:61:4b:a0:f2:ab:24:ad:95:46: 158 2e:5e:27:be:03:f2:e0:4d:70:27:63:9a:c1:f9:1b:00:ab:6b: 159 de:e7:f1:04:a7:b5:bd:85:31:a6:32:4b:0e:e8:a5:ab:8d:c1: 160 52:19:f2:b6 161-----BEGIN CERTIFICATE----- 162MIIDgDCCAmigAwIBAgIUAm7p1/hdRK00BRUjcGWezOCnZlMwDQYJKoZIhvcNAQEL 163BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 164MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD 165ggEPADCCAQoCggEBAMWMPkT1fYnVjXeG+dWgi9wdDz7Q+NFyxFvQg1a1mAxODD1I 16699sG6MLrXPz0L7AjdPyVIwx9Pb4piW/Vl9OLb782TZlOyf5ZoppW3zym4PSOKyAA 167Sk1uFcl/wDWPWkgIC0HRz4TA/ZlxJpZ7tW8dztt0sdMdOTdw0OFT1URy4oDCu8dx 168k04CQKygrzNyoW2aRJtFrSJ0/Bh04IQ0AAB2Rip3+f+or3G55uYymtTSp91x+SpJ 169Kv7Cjs+cd/c5fdOZCbFJMDXljTrDPmwd1rcmu5DkO8MuqjcYuyjzedJpnId/eF/F 170l9HYRRQXOG1mIy6Q3SXBYDx89ZrSFgXAf4k+EIcCAwEAAaOByzCByDAdBgNVHQ4E 171FgQUDTNPmPY8lMggW1HJve0JO/C089YwHwYDVR0jBBgwFoAUepipP7qA3WgbHIdX 172LkI/X7NQXagwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs 173LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m 174b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ 175MA0GCSqGSIb3DQEBCwUAA4IBAQB2Hdci+ejYpuywvwaSfCqCzYp7E73G2dpLs5QS 176glmoFnbBBcB+fRm0jzXHWHP/fZ6MVW8Ls+Nf0OhXwJJsR6dVhHeQGcFnH4oycAw+ 1773gFvxnkeoBAVouz2GhkQrKq/YwtSiD1hXulrdk2x9RanCU9oZxtHtWI3smtm4OdR 178hlAyVLe36Hdc2P+NO25JrFzOMzhSD0GAHbD9NY03IwbjHIn002xz0NOPctuaejRA 179VHeXrp9bTdiUmaeJEQS7Uga6Mv35FrfupgNVOTFPiTucm9NhS6DyqyStlUYuXie+ 180A/LgTXAnY5rB+RsAq2ve5/EEp7W9hTGmMksO6KWrjcFSGfK2 181-----END CERTIFICATE----- 182 183Certificate: 184 Data: 185 Version: 3 (0x2) 186 Serial Number: 187 02:6e:e9:d7:f8:5d:44:ad:34:05:15:23:70:65:9e:cc:e0:a7:66:52 188 Signature Algorithm: sha256WithRSAEncryption 189 Issuer: CN=Root 190 Validity 191 Not Before: Oct 5 12:00:00 2021 GMT 192 Not After : Oct 5 12:00:00 2022 GMT 193 Subject: CN=Root 194 Subject Public Key Info: 195 Public Key Algorithm: rsaEncryption 196 Public-Key: (2048 bit) 197 Modulus: 198 00:af:0c:3f:db:02:4b:9e:87:03:a5:64:a7:18:9a: 199 c1:4c:c8:bf:1b:e7:5a:04:52:70:6c:a2:bc:19:99: 200 33:44:f9:9a:6b:30:d8:57:5b:be:a0:dc:8c:97:91: 201 20:97:f8:04:ef:21:1d:b1:c7:a3:1b:57:02:c9:bd: 202 53:54:f8:58:96:f3:c2:d7:5e:ae:61:c1:d5:08:ff: 203 88:bf:80:c1:ef:c8:6d:99:ac:8e:55:f6:e0:da:8f: 204 f3:31:f1:e5:02:82:2c:f9:42:cb:7c:4c:2b:ba:97: 205 eb:ef:cd:b0:d5:31:a1:09:f8:5e:62:74:4e:29:02: 206 9b:7e:de:0b:31:36:b6:fd:36:e5:a6:a8:ac:05:1f: 207 5f:32:e6:60:f7:5f:8f:f3:a5:6e:3d:c4:ec:dd:23: 208 ac:4b:69:ab:df:41:65:2b:bd:f2:ed:51:e0:94:e4: 209 5f:35:6c:be:c8:be:2a:10:27:55:92:6b:82:ac:72: 210 b7:c4:de:47:04:03:6c:57:fd:de:f1:17:3b:16:0c: 211 d7:cd:26:28:84:b2:df:19:e7:2f:45:87:2f:91:82: 212 d5:21:4b:0a:49:77:a0:46:39:2d:fc:ab:63:1f:76: 213 2d:c1:4a:03:1c:d8:e0:dc:a3:4d:c8:56:aa:41:1c: 214 e9:11:63:10:c6:55:03:4e:c8:be:53:7e:3c:a9:d7: 215 13:af 216 Exponent: 65537 (0x10001) 217 X509v3 extensions: 218 X509v3 Subject Key Identifier: 219 7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8 220 X509v3 Authority Key Identifier: 221 7A:98:A9:3F:BA:80:DD:68:1B:1C:87:57:2E:42:3F:5F:B3:50:5D:A8 222 Authority Information Access: 223 CA Issuers - URI:http://url-for-aia/Root.cer 224 X509v3 CRL Distribution Points: 225 Full Name: 226 URI:http://url-for-crl/Root.crl 227 X509v3 Key Usage: critical 228 Certificate Sign, CRL Sign 229 X509v3 Basic Constraints: critical 230 CA:TRUE 231 Signature Algorithm: sha256WithRSAEncryption 232 Signature Value: 233 07:9d:ea:d3:5a:05:0f:1d:14:12:d4:a3:1f:1e:29:e7:5b:8c: 234 8f:9f:3e:b9:f3:85:d2:5e:73:9c:41:7c:81:bf:75:fe:61:49: 235 dd:d9:69:95:43:4c:46:8d:b7:49:1b:b8:4e:a0:e8:f7:ab:dc: 236 c1:6c:85:43:4b:f1:94:a0:3c:b6:06:db:20:70:fe:cb:b4:a3: 237 ee:d3:12:93:70:c1:c1:97:30:8e:78:7a:7e:31:f6:35:d4:b6: 238 e8:f4:9e:1c:11:c9:5b:51:8b:18:da:c3:65:48:d8:0c:9d:7e: 239 73:27:26:b1:3c:25:b2:9c:12:79:a8:3e:37:18:14:ca:a9:33: 240 78:17:03:12:bd:42:48:6f:78:0a:4f:8d:b5:c0:88:c4:d2:a5: 241 99:84:2b:a5:d9:40:85:65:67:aa:12:74:4f:c9:b6:0a:64:17: 242 d7:af:51:3b:13:08:70:ce:65:af:36:59:46:32:b3:40:45:c3: 243 1a:8b:56:3e:2b:81:5d:81:48:a6:f9:8e:5b:26:c2:1a:1a:68: 244 57:a1:22:8a:42:2e:9a:51:8c:18:f8:fe:d6:a4:89:b5:7d:64: 245 14:5b:b1:5d:26:92:f1:17:54:8a:bb:e6:d7:97:82:6c:e1:b4: 246 39:42:68:d1:69:64:a9:21:1c:28:e1:ae:bd:eb:09:78:76:c9: 247 7f:cd:79:90 248-----BEGIN CERTIFICATE----- 249MIIDeDCCAmCgAwIBAgIUAm7p1/hdRK00BRUjcGWezOCnZlIwDQYJKoZIhvcNAQEL 250BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 251MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK 252AoIBAQCvDD/bAkuehwOlZKcYmsFMyL8b51oEUnBsorwZmTNE+ZprMNhXW76g3IyX 253kSCX+ATvIR2xx6MbVwLJvVNU+FiW88LXXq5hwdUI/4i/gMHvyG2ZrI5V9uDaj/Mx 2548eUCgiz5Qst8TCu6l+vvzbDVMaEJ+F5idE4pApt+3gsxNrb9NuWmqKwFH18y5mD3 255X4/zpW49xOzdI6xLaavfQWUrvfLtUeCU5F81bL7IvioQJ1WSa4KscrfE3kcEA2xX 256/d7xFzsWDNfNJiiEst8Z5y9Fhy+RgtUhSwpJd6BGOS38q2Mfdi3BSgMc2ODco03I 257VqpBHOkRYxDGVQNOyL5Tfjyp1xOvAgMBAAGjgcswgcgwHQYDVR0OBBYEFHqYqT+6 258gN1oGxyHVy5CP1+zUF2oMB8GA1UdIwQYMBaAFHqYqT+6gN1oGxyHVy5CP1+zUF2o 259MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh 260L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S 261b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG 2629w0BAQsFAAOCAQEAB53q01oFDx0UEtSjHx4p51uMj58+ufOF0l5znEF8gb91/mFJ 2633dlplUNMRo23SRu4TqDo96vcwWyFQ0vxlKA8tgbbIHD+y7Sj7tMSk3DBwZcwjnh6 264fjH2NdS26PSeHBHJW1GLGNrDZUjYDJ1+cycmsTwlspwSeag+NxgUyqkzeBcDEr1C 265SG94Ck+NtcCIxNKlmYQrpdlAhWVnqhJ0T8m2CmQX169ROxMIcM5lrzZZRjKzQEXD 266GotWPiuBXYFIpvmOWybCGhpoV6EiikIumlGMGPj+1qSJtX1kFFuxXSaS8RdUirvm 26715eCbOG0OUJo0WlkqSEcKOGuvesJeHbJf815kA== 268-----END CERTIFICATE----- 269