1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251
|
[Created by: generate-chains.py]
Certificate chain where the root certificate holds an RSA key, intermediate
certificate holds an EC key, and target certificate holds an RSA key. The
target certificate has a valid signature using ECDSA.
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
41:40:39:26:f7:3c:b3:a7:c4:58:60:3a:f3:20:9a:3a:ee:e3:c5:56
Signature Algorithm: ecdsa-with-SHA256
Issuer: CN=Intermediate
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Target
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:e6:90:14:d7:6c:5e:85:24:21:17:7a:ce:f2:8a:
3e:83:20:e4:3e:eb:cf:4c:06:bb:0a:d5:21:d9:2b:
e1:2e:14:8a:20:16:c8:c9:4b:55:ed:e9:ea:48:ed:
ef:03:2b:de:25:dd:41:9b:0c:0b:bd:f8:58:e2:a0:
ba:92:3f:03:de:ca:e6:35:42:be:ab:e1:33:17:ac:
3e:bc:fc:90:2a:d2:c7:76:1f:51:d2:ca:e9:80:e0:
76:39:ab:88:65:b4:e3:ea:05:dd:c5:8e:fe:4c:86:
c3:06:49:0c:ab:69:a5:4f:14:cc:82:1f:b1:3d:f6:
f9:d5:d4:61:41:35:e5:d4:f7:4f:1a:af:fb:a8:ff:
ef:7b:38:95:40:c5:56:32:a5:cf:8f:d6:04:df:23:
eb:5b:f7:32:a3:d7:a1:df:cb:67:35:25:d6:63:92:
d7:da:d9:83:20:52:58:1d:ef:6e:3c:88:91:14:08:
c7:70:85:b7:b3:93:c1:9a:51:57:d8:d5:4c:81:83:
96:91:b6:5a:b9:b5:7e:fb:90:bd:71:2e:09:04:6e:
f9:0b:ff:51:43:d4:20:77:ee:31:34:98:f8:e8:8f:
5a:2e:75:f1:0f:bf:64:35:a5:00:cb:4a:00:6e:45:
a3:01:d7:97:46:49:55:c1:df:2d:31:c4:98:ae:25:
b2:b3
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
A0:D4:34:B4:BC:27:68:8C:38:A0:8F:3A:CF:6E:58:5F:57:97:44:B8
X509v3 Authority Key Identifier:
keyid:B1:0E:68:94:5F:A9:F7:F8:4B:09:42:7D:AE:5A:7A:05:BF:E4:A1:F1
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Intermediate.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Intermediate.crl
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
Signature Algorithm: ecdsa-with-SHA256
30:66:02:31:00:bf:ee:04:f4:3a:0a:2c:ba:41:33:77:1e:dc:
e3:ae:85:f0:ac:29:06:88:ab:a1:58:98:eb:1f:e4:8e:66:9f:
dd:1c:6e:96:7f:57:ba:27:4f:f5:21:a0:ad:5a:1f:38:93:02:
31:00:c0:58:7d:64:1d:a0:43:1d:04:26:68:14:08:41:bf:a9:
7d:56:78:a6:95:74:a4:d3:db:88:6b:64:4c:e7:ee:b5:a0:49:
71:00:39:63:19:31:b0:8f:86:7b:c1:b5:dd:f4
-----BEGIN CERTIFICATE-----
MIIDADCCAoWgAwIBAgIUQUA5Jvc8s6fEWGA68yCaOu7jxVYwCgYIKoZIzj0EAwIw
FzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIyMTAw
NTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEA5pAU12xehSQhF3rO8oo+gyDkPuvPTAa7CtUh2SvhLhSKIBbI
yUtV7enqSO3vAyveJd1BmwwLvfhY4qC6kj8D3srmNUK+q+EzF6w+vPyQKtLHdh9R
0srpgOB2OauIZbTj6gXdxY7+TIbDBkkMq2mlTxTMgh+xPfb51dRhQTXl1PdPGq/7
qP/veziVQMVWMqXPj9YE3yPrW/cyo9eh38tnNSXWY5LX2tmDIFJYHe9uPIiRFAjH
cIW3s5PBmlFX2NVMgYOWkbZaubV++5C9cS4JBG75C/9RQ9Qgd+4xNJj46I9aLnXx
D79kNaUAy0oAbkWjAdeXRklVwd8tMcSYriWyswIDAQABo4HpMIHmMB0GA1UdDgQW
BBSg1DS0vCdojDigjzrPblhfV5dEuDAfBgNVHSMEGDAWgBSxDmiUX6n3+EsJQn2u
WnoFv+Sh8TA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91cmwt
Zm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6
Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIFoDAd
BgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwCgYIKoZIzj0EAwIDaQAwZgIx
AL/uBPQ6Ciy6QTN3HtzjroXwrCkGiKuhWJjrH+SOZp/dHG6Wf1e6J0/1IaCtWh84
kwIxAMBYfWQdoEMdBCZoFAhBv6l9VnimlXSk09uIa2RM5+61oElxADljGTGwj4Z7
wbXd9A==
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
62:20:1f:53:92:38:2c:47:67:4d:1d:04:41:2d:53:ab:1e:d4:5c:aa
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Intermediate
Subject Public Key Info:
Public Key Algorithm: id-ecPublicKey
Public-Key: (384 bit)
pub:
04:f3:8f:d7:88:9f:98:67:05:36:a9:16:7c:85:b2:
cf:8e:02:72:19:eb:ab:48:14:1e:6f:6a:13:93:3e:
80:b9:aa:7f:53:9c:91:91:9e:b1:79:76:ec:31:ef:
97:46:30:d8:f4:ad:9c:60:c0:a6:00:88:62:5a:68:
9e:3e:00:f3:6c:b4:1a:10:0b:78:12:f3:fe:5f:47:
40:14:e7:2d:c0:82:cc:cf:df:93:fb:21:8e:ed:59:
b2:70:1e:7b:70:0c:e5
ASN1 OID: secp384r1
NIST CURVE: P-384
X509v3 extensions:
X509v3 Subject Key Identifier:
B1:0E:68:94:5F:A9:F7:F8:4B:09:42:7D:AE:5A:7A:05:BF:E4:A1:F1
X509v3 Authority Key Identifier:
keyid:43:E7:CC:3C:45:3E:58:A7:6D:D2:90:56:8F:16:93:9E:2F:F3:06:2E
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
8d:18:e4:44:8c:d8:6b:90:61:40:38:87:fb:85:bf:25:b8:c6:
a6:8b:6a:95:28:46:a9:19:3a:59:83:df:1a:d1:73:b0:20:7d:
96:41:bc:0e:77:0c:b9:65:8d:54:f4:0b:a5:69:b1:5a:9a:49:
21:f0:92:fe:88:00:79:01:57:47:4a:d4:a7:06:ca:49:69:fc:
c7:e9:40:90:58:0f:d6:3b:66:a7:39:f5:11:d8:de:5e:bf:3d:
04:08:92:c2:ba:c1:d1:9b:c3:63:08:22:48:a4:9b:23:12:86:
95:cf:b3:9f:7e:94:01:6d:3b:e7:fa:4f:b5:29:43:5d:34:98:
01:f5:26:96:7e:c6:46:77:8f:41:7c:74:ad:e1:f7:60:5a:bd:
fa:28:f6:c1:d9:5c:e2:0d:a3:9c:f3:72:69:c0:7e:ca:b6:5d:
e3:19:0f:90:c6:e8:08:64:b7:38:17:56:9d:16:ac:49:17:d9:
18:08:1c:eb:02:e5:11:5d:22:92:e2:7f:28:ec:cf:73:c5:25:
d5:13:17:b3:d1:88:e2:4b:5d:e7:b1:39:73:9b:52:9c:3e:6d:
02:d2:f1:be:ac:6a:20:f1:93:9e:51:60:e4:50:da:c9:b4:99:
79:85:cf:de:19:81:0c:8d:fa:2a:28:c9:da:51:db:66:51:da:
1e:c0:90:54
-----BEGIN CERTIFICATE-----
MIIC0jCCAbqgAwIBAgIUYiAfU5I4LEdnTR0EQS1Tqx7UXKowDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTB2MBAGByqGSM49AgEGBSuBBAAi
A2IABPOP14ifmGcFNqkWfIWyz44Cchnrq0gUHm9qE5M+gLmqf1OckZGesXl27DHv
l0Yw2PStnGDApgCIYlponj4A82y0GhALeBLz/l9HQBTnLcCCzM/fk/shju1ZsnAe
e3AM5aOByzCByDAdBgNVHQ4EFgQUsQ5olF+p9/hLCUJ9rlp6Bb/kofEwHwYDVR0j
BBgwFoAUQ+fMPEU+WKdt0pBWjxaTni/zBi4wNwYIKwYBBQUHAQEEKzApMCcGCCsG
AQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAh
oB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIB
BjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCNGOREjNhrkGFA
OIf7hb8luMami2qVKEapGTpZg98a0XOwIH2WQbwOdwy5ZY1U9AulabFamkkh8JL+
iAB5AVdHStSnBspJafzH6UCQWA/WO2anOfUR2N5evz0ECJLCusHRm8NjCCJIpJsj
EoaVz7OffpQBbTvn+k+1KUNdNJgB9SaWfsZGd49BfHSt4fdgWr36KPbB2VziDaOc
83JpwH7Ktl3jGQ+QxugIZLc4F1adFqxJF9kYCBzrAuURXSKS4n8o7M9zxSXVExez
0YjiS13nsTlzm1KcPm0C0vG+rGog8ZOeUWDkUNrJtJl5hc/eGYEMjfoqKMnaUdtm
UdoewJBU
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
62:20:1f:53:92:38:2c:47:67:4d:1d:04:41:2d:53:ab:1e:d4:5c:a9
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Root
Validity
Not Before: Oct 5 12:00:00 2021 GMT
Not After : Oct 5 12:00:00 2022 GMT
Subject: CN=Root
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:f5:c6:4e:ee:3f:f0:7c:64:c3:5d:09:15:02:1c:
1b:f3:43:19:a5:c1:a9:a0:fb:f9:98:ee:e4:af:7c:
e2:ad:51:6d:c5:74:03:4d:db:f1:e0:69:ed:9a:23:
d8:cd:34:0b:83:6a:32:4e:1d:c0:91:fc:88:17:02:
0d:bd:6d:d9:b9:92:71:6b:8f:23:40:f9:48:fe:16:
59:af:f4:9c:33:7d:3f:08:65:ff:f1:e5:9c:4d:e8:
e8:7b:4a:c3:16:6d:53:9d:92:d7:86:9b:95:fb:5d:
86:6d:af:00:dd:6f:25:0d:53:70:7e:b6:36:11:94:
d1:90:b5:f1:6d:a8:b0:e8:2d:0d:c5:85:b5:50:4b:
7e:b0:57:8d:82:6d:bb:e0:82:64:3b:a4:d6:c4:d7:
0a:2c:89:61:47:99:67:5e:71:1f:5c:66:14:08:fa:
29:88:09:3b:38:60:4d:01:67:53:fe:16:85:70:54:
bf:e1:5e:76:b8:33:e3:9c:17:08:a4:0f:f2:c5:e1:
ac:99:94:7e:10:47:7d:51:43:42:85:df:e2:9a:53:
07:c4:2f:c8:bf:56:da:0b:7f:41:6d:8f:76:42:b0:
25:3c:fb:0a:f4:d0:d0:b3:79:72:70:0d:07:95:97:
c1:11:82:ff:c4:13:ec:0f:cf:bb:4e:b8:4a:ed:ca:
3c:a3
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
43:E7:CC:3C:45:3E:58:A7:6D:D2:90:56:8F:16:93:9E:2F:F3:06:2E
X509v3 Authority Key Identifier:
keyid:43:E7:CC:3C:45:3E:58:A7:6D:D2:90:56:8F:16:93:9E:2F:F3:06:2E
Authority Information Access:
CA Issuers - URI:http://url-for-aia/Root.cer
X509v3 CRL Distribution Points:
Full Name:
URI:http://url-for-crl/Root.crl
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
d2:50:10:c9:a0:28:ad:dc:18:87:68:2b:7c:a7:6c:e8:1a:07:
38:9f:f0:dc:45:7a:75:f4:24:47:16:ce:4a:60:76:c0:0e:2a:
61:f0:b1:55:42:23:08:f9:b1:f4:4f:9a:0e:ad:9a:4f:b9:bb:
42:d4:98:13:87:ce:1e:55:f3:1b:25:cf:fa:a4:f5:5b:d6:d2:
cb:28:ca:86:aa:f8:e2:8b:d2:8b:e3:0c:0e:d9:e3:9f:ee:27:
03:c6:13:e8:9d:a5:b1:64:c8:a2:e5:c0:f0:07:03:58:a1:20:
0c:7b:47:a2:db:67:86:e9:68:25:04:ad:c9:1f:dc:2d:b1:0e:
52:a8:6f:de:6c:29:02:17:58:30:df:0c:7c:f3:1f:e6:9e:d7:
bd:40:0d:e3:eb:af:49:1f:d8:e9:3f:0b:ee:54:97:b1:93:1e:
77:f2:26:51:6a:5a:be:e4:82:ff:5f:fc:b5:23:74:dd:82:45:
ea:f5:7a:31:7d:9d:fd:62:4a:2d:99:67:4b:ba:62:5e:47:cb:
4a:63:d9:b4:6e:ea:39:ac:d6:3e:6c:53:92:d1:9a:ae:a1:1f:
6f:f2:ff:75:07:26:24:53:76:1e:e0:d7:2a:3b:59:74:45:54:
94:b6:7e:45:aa:26:b3:96:22:c0:ca:c5:d0:e2:5d:a4:f6:74:
b7:3a:66:d1
-----BEGIN CERTIFICATE-----
MIIDeDCCAmCgAwIBAgIUYiAfU5I4LEdnTR0EQS1Tqx7UXKkwDQYJKoZIhvcNAQEL
BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQD1xk7uP/B8ZMNdCRUCHBvzQxmlwamg+/mY7uSvfOKtUW3FdANN2/Hgae2a
I9jNNAuDajJOHcCR/IgXAg29bdm5knFrjyNA+Uj+Flmv9JwzfT8IZf/x5ZxN6Oh7
SsMWbVOdkteGm5X7XYZtrwDdbyUNU3B+tjYRlNGQtfFtqLDoLQ3FhbVQS36wV42C
bbvggmQ7pNbE1wosiWFHmWdecR9cZhQI+imICTs4YE0BZ1P+FoVwVL/hXna4M+Oc
FwikD/LF4ayZlH4QR31RQ0KF3+KaUwfEL8i/VtoLf0Ftj3ZCsCU8+wr00NCzeXJw
DQeVl8ERgv/EE+wPz7tOuErtyjyjAgMBAAGjgcswgcgwHQYDVR0OBBYEFEPnzDxF
PlinbdKQVo8Wk54v8wYuMB8GA1UdIwQYMBaAFEPnzDxFPlinbdKQVo8Wk54v8wYu
MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQsFAAOCAQEA0lAQyaAordwYh2grfKds6BoHOJ/w3EV6dfQkRxbOSmB2wA4q
YfCxVUIjCPmx9E+aDq2aT7m7QtSYE4fOHlXzGyXP+qT1W9bSyyjKhqr44ovSi+MM
Dtnjn+4nA8YT6J2lsWTIouXA8AcDWKEgDHtHottnhuloJQStyR/cLbEOUqhv3mwp
AhdYMN8MfPMf5p7XvUAN4+uvSR/Y6T8L7lSXsZMed/ImUWpavuSC/1/8tSN03YJF
6vV6MX2d/WJKLZlnS7piXkfLSmPZtG7qOazWPmxTktGarqEfb/L/dQcmJFN2HuDX
KjtZdEVUlLZ+Raoms5YiwMrF0OJdpPZ0tzpm0Q==
-----END CERTIFICATE-----
|