1Signed through an intermediate without the correct key usage
2
3$ openssl ocsp -resp_text -respin <([OCSP RESPONSE])
4OCSP Response Data:
5    OCSP Response Status: successful (0x0)
6    Response Type: Basic OCSP Response
7    Version: 1 (0x0)
8    Responder Id: CN = Test False OCSP Signer
9    Produced At: Mar  2 00:00:00 2017 GMT
10    Responses:
11    Certificate ID:
12      Hash Algorithm: sha1
13      Issuer Name Hash: 449B1C5B31C6E9990966523E49C3F773C024190A
14      Issuer Key Hash: 7F765910653BB5704124C41E94AEFCF940431A66
15      Serial Number: 04
16    Cert Status: good
17    This Update: Mar  1 00:00:00 2017 GMT
18
19    Signature Algorithm: sha1WithRSAEncryption
20         99:5b:54:5b:da:7b:f5:e1:1d:50:73:1d:0c:5b:d8:f2:2c:e2:
21         da:91:7d:c6:16:fb:0d:aa:cd:cf:c1:94:7e:1e:42:38:49:5f:
22         d5:26:7c:9a:30:b7:4e:5f:fb:14:2e:a8:f3:67:03:17:5f:c1:
23         c2:ca:af:6b:bf:2a:32:99:3b:51:50:5f:6d:b0:ad:e3:e7:b5:
24         c5:e4:41:73:11:7f:ef:85:35:78:24:91:a3:2c:c0:4e:41:fe:
25         bc:4c:c6:ef:05:ac:22:81:9a:bd:93:89:9f:c5:54:94:db:08:
26         0f:55:8f:88:13:f9:7d:ac:ae:e8:56:0b:ea:d9:04:25:db:de:
27         4c:96
28Certificate:
29    Data:
30        Version: 3 (0x2)
31        Serial Number: 3 (0x3)
32        Signature Algorithm: sha1WithRSAEncryption
33        Issuer: CN=Test Intermediate CA
34        Validity
35            Not Before: Jan  1 00:00:00 2017 GMT
36            Not After : Jan  1 00:00:00 2018 GMT
37        Subject: CN=Test False OCSP Signer
38        Subject Public Key Info:
39            Public Key Algorithm: rsaEncryption
40                RSA Public-Key: (1024 bit)
41                Modulus:
42                    00:9d:a4:70:41:77:2a:fa:11:c5:10:ea:13:ef:e4:
43                    1d:9f:7a:ff:89:38:6a:79:61:21:ba:87:65:95:27:
44                    8a:cc:6e:d8:56:e6:a1:e2:2f:61:2f:d1:d0:da:1d:
45                    b7:c0:ac:83:b1:a5:e0:45:30:eb:0d:50:ea:55:21:
46                    a6:ac:cc:6b:e0:b1:5d:3a:d8:55:b3:fe:4b:a1:2a:
47                    19:c0:e6:b5:24:93:7c:8d:8f:fc:60:4b:fc:90:4c:
48                    40:47:67:51:3d:9f:a5:9d:74:89:40:c7:6a:ec:16:
49                    49:bd:77:71:64:db:40:d2:3b:e3:6f:86:90:33:d1:
50                    60:98:12:29:e1:07:5f:d0:03
51                Exponent: 65537 (0x10001)
52    Signature Algorithm: sha1WithRSAEncryption
53         60:5d:f1:ba:17:d5:98:98:99:54:ca:d3:57:b6:2f:01:32:aa:
54         e5:dc:5a:43:1a:48:b6:9c:26:cb:fd:b1:b5:bb:01:17:c5:2e:
55         62:c1:98:f5:b3:19:8f:5e:1c:b6:7e:d0:d4:f2:d5:6d:75:5c:
56         b1:bb:c1:36:ae:be:37:73:58:72:30:3e:62:96:aa:cf:f1:bc:
57         3a:12:bf:6c:d8:dc:49:24:80:8a:7c:f0:67:0a:c3:e1:cc:24:
58         60:92:21:59:3b:7e:ab:87:ba:83:b8:0e:31:e9:23:4c:a4:23:
59         41:5c:b5:78:60:d5:72:f5:e7:4d:f5:f3:0f:bf:01:ab:1e:83:
60         86:41
61~~~~~BEGIN CERTIFICATE~~~~~
62MIIBuDCCASGgAwIBAgIBAzANBgkqhkiG9w0BAQUFADAfMR0wGwYDVQQDDBRUZXN0
63IEludGVybWVkaWF0ZSBDQTAiGA8yMDE3MDEwMTAwMDAwMFoYDzIwMTgwMTAxMDAw
64MDAwWjAhMR8wHQYDVQQDDBZUZXN0IEZhbHNlIE9DU1AgU2lnbmVyMIGfMA0GCSqG
65SIb3DQEBAQUAA4GNADCBiQKBgQCdpHBBdyr6EcUQ6hPv5B2fev+JOGp5YSG6h2WV
66J4rMbthW5qHiL2Ev0dDaHbfArIOxpeBFMOsNUOpVIaaszGvgsV062FWz/kuhKhnA
675rUkk3yNj/xgS/yQTEBHZ1E9n6WddIlAx2rsFkm9d3Fk20DSO+NvhpAz0WCYEinh
68B1/QAwIDAQABMA0GCSqGSIb3DQEBBQUAA4GBAGBd8boX1ZiYmVTK01e2LwEyquXc
69WkMaSLacJsv9sbW7ARfFLmLBmPWzGY9eHLZ+0NTy1W11XLG7wTauvjdzWHIwPmKW
70qs/xvDoSv2zY3EkkgIp88GcKw+HMJGCSIVk7fquHuoO4DjHpI0ykI0FctXhg1XL1
7150318w+/Aaseg4ZB
72~~~~~END CERTIFICATE~~~~~
73-----BEGIN OCSP RESPONSE-----
74MIIC/QoBAKCCAvYwggLyBgkrBgEFBQcwAQEEggLjMIIC3zCBh6EjMCExHzAdBgNVBAMMFlRlc3Q
75gRmFsc2UgT0NTUCBTaWduZXIYDzIwMTcwMzAyMDAwMDAwWjBPME0wODAHBgUrDgMCGgQURJscWz
76HG6ZkJZlI+ScP3c8AkGQoEFH92WRBlO7VwQSTEHpSu/PlAQxpmAgEEgAAYDzIwMTcwMzAxMDAwM
77DAwWjALBgkqhkiG9w0BAQUDgYEAmVtUW9p79eEdUHMdDFvY8izi2pF9xhb7DarNz8GUfh5COElf
781SZ8mjC3Tl/7FC6o82cDF1/Bwsqva78qMpk7UVBfbbCt4+e1xeRBcxF/74U1eCSRoyzATkH+vEz
79G7wWsIoGavZOJn8VUlNsID1WPiBP5fayu6FYL6tkEJdveTJagggHAMIIBvDCCAbgwggEhoAMCAQ
80ICAQMwDQYJKoZIhvcNAQEFBQAwHzEdMBsGA1UEAwwUVGVzdCBJbnRlcm1lZGlhdGUgQ0EwIhgPM
81jAxNzAxMDEwMDAwMDBaGA8yMDE4MDEwMTAwMDAwMFowITEfMB0GA1UEAwwWVGVzdCBGYWxzZSBP
82Q1NQIFNpZ25lcjCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAnaRwQXcq+hHFEOoT7+Qdn3r
83/iThqeWEhuodllSeKzG7YVuah4i9hL9HQ2h23wKyDsaXgRTDrDVDqVSGmrMxr4LFdOthVs/5LoS
84oZwOa1JJN8jY/8YEv8kExAR2dRPZ+lnXSJQMdq7BZJvXdxZNtA0jvjb4aQM9FgmBIp4Qdf0AMCA
85wEAATANBgkqhkiG9w0BAQUFAAOBgQBgXfG6F9WYmJlUytNXti8BMqrl3FpDGki2nCbL/bG1uwEX
86xS5iwZj1sxmPXhy2ftDU8tVtdVyxu8E2rr43c1hyMD5ilqrP8bw6Er9s2NxJJICKfPBnCsPhzCR
87gkiFZO36rh7qDuA4x6SNMpCNBXLV4YNVy9edN9fMPvwGrHoOGQQ==
88-----END OCSP RESPONSE-----
89
90$ openssl x509 -text < [CA CERTIFICATE]
91Certificate:
92    Data:
93        Version: 3 (0x2)
94        Serial Number: 1 (0x1)
95        Signature Algorithm: sha1WithRSAEncryption
96        Issuer: CN = Test CA
97        Validity
98            Not Before: Jan  1 00:00:00 2017 GMT
99            Not After : Jan  1 00:00:00 2018 GMT
100        Subject: CN = Test Intermediate CA
101        Subject Public Key Info:
102            Public Key Algorithm: rsaEncryption
103                RSA Public-Key: (1024 bit)
104                Modulus:
105                    00:c5:fb:81:a7:1b:6a:61:38:1c:6a:de:dd:db:22:
106                    61:64:7a:22:a3:3b:1d:e5:92:54:17:ad:39:2e:fe:
107                    81:ff:46:0a:70:d6:84:a5:d5:bd:05:d3:f2:a5:98:
108                    90:fd:e4:ff:d8:d2:cf:7c:d1:f2:78:0d:4a:a1:80:
109                    c8:6a:70:75:84:04:c1:c2:4b:af:17:9b:a2:29:2b:
110                    a7:be:f1:f9:19:80:f3:6a:d4:10:28:51:38:26:97:
111                    ed:ad:06:96:85:a7:b7:7c:78:38:90:44:df:d7:10:
112                    e4:52:a2:49:22:6c:98:71:51:f5:b2:13:6a:7f:08:
113                    34:7c:d0:c6:99:6f:79:98:f9
114                Exponent: 65537 (0x10001)
115    Signature Algorithm: sha1WithRSAEncryption
116         7d:67:0f:39:4e:7c:e3:ba:f2:63:b9:ed:6e:ec:61:f2:8a:4f:
117         1e:82:e2:4b:44:04:f8:a5:a1:5a:bc:8c:72:91:6d:bf:03:27:
118         21:10:9e:5c:8a:cf:4b:87:83:e0:c2:d7:72:55:d5:42:d3:d1:
119         2b:76:b3:42:84:e0:e8:3b:80:b2:5f:55:e7:e0:f6:b6:21:c6:
120         fd:91:b5:c9:ba:fa:d8:ba:5c:8b:e1:f6:de:5d:cf:39:e6:92:
121         22:85:31:1f:c3:ed:19:db:0a:0b:f9:ef:a7:36:4d:e1:54:af:
122         8e:c0:59:25:43:e5:69:47:c4:e0:00:1e:21:eb:e6:b4:13:8f:
123         30:01
124-----BEGIN CA CERTIFICATE-----
125MIIBqTCCARKgAwIBAgIBATANBgkqhkiG9w0BAQUFADASMRAwDgYDVQQDDAdUZXN0IENBMCIYDzI
126wMTcwMTAxMDAwMDAwWhgPMjAxODAxMDEwMDAwMDBaMB8xHTAbBgNVBAMMFFRlc3QgSW50ZXJtZW
127RpYXRlIENBMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDF+4GnG2phOBxq3t3bImFkeiKjO
128x3lklQXrTku/oH/Rgpw1oSl1b0F0/KlmJD95P/Y0s980fJ4DUqhgMhqcHWEBMHCS68Xm6IpK6e+
1298fkZgPNq1BAoUTgml+2tBpaFp7d8eDiQRN/XEORSokkibJhxUfWyE2p/CDR80MaZb3mY+QIDAQA
130BMA0GCSqGSIb3DQEBBQUAA4GBAH1nDzlOfOO68mO57W7sYfKKTx6C4ktEBPiloVq8jHKRbb8DJy
131EQnlyKz0uHg+DC13JV1ULT0St2s0KE4Og7gLJfVefg9rYhxv2Rtcm6+ti6XIvh9t5dzznmkiKFM
132R/D7RnbCgv576c2TeFUr47AWSVD5WlHxOAAHiHr5rQTjzAB
133-----END CA CERTIFICATE-----
134
135$ openssl x509 -text < [CERTIFICATE]
136Certificate:
137    Data:
138        Version: 3 (0x2)
139        Serial Number: 4 (0x4)
140        Signature Algorithm: sha1WithRSAEncryption
141        Issuer: CN = Test Intermediate CA
142        Validity
143            Not Before: Jan  1 00:00:00 2017 GMT
144            Not After : Jan  1 00:00:00 2018 GMT
145        Subject: CN = Test Cert
146        Subject Public Key Info:
147            Public Key Algorithm: rsaEncryption
148                RSA Public-Key: (1024 bit)
149                Modulus:
150                    00:d1:d2:a7:fd:5f:56:b8:4a:4a:00:c4:f0:36:48:
151                    0d:99:1e:ba:ca:8d:8c:0e:e9:5a:f4:31:94:26:f4:
152                    24:77:0c:2d:76:39:fe:1e:51:9c:b1:3a:b2:61:ae:
153                    f6:2b:41:46:92:81:b4:1e:35:73:bb:df:53:d6:63:
154                    a4:07:58:e9:0a:40:7a:b7:71:a3:fd:7d:6a:3f:23:
155                    ee:5e:76:90:3f:60:ea:85:6b:74:1b:1f:6a:40:27:
156                    37:7f:ac:6e:97:ee:13:f7:cb:81:44:26:f3:25:48:
157                    56:40:ef:33:84:c8:d7:52:66:8a:40:35:ed:ec:67:
158                    95:c1:35:46:9e:db:9b:ce:9b
159                Exponent: 65537 (0x10001)
160    Signature Algorithm: sha1WithRSAEncryption
161         8e:94:5a:91:44:aa:ab:e4:bf:c4:ca:a3:ee:10:67:2d:3e:d5:
162         ac:b8:90:8b:4e:7f:3e:bc:83:bb:b2:c9:0c:a2:ae:fb:6c:b3:
163         5d:b7:40:20:9f:9b:7c:3d:5f:67:bc:0e:f9:20:bc:24:67:27:
164         a9:2e:81:08:e5:3f:ad:e9:b7:eb:a9:c5:58:55:55:f3:26:17:
165         26:46:5f:ef:20:38:c9:f2:81:ba:39:d9:28:4b:e8:83:ff:d7:
166         2e:87:72:36:77:0f:46:9b:a1:fe:d8:d8:20:50:68:c1:7b:66:
167         82:5d:62:94:90:98:71:8b:b9:83:69:a8:65:a4:58:5d:ce:90:
168         0a:53
169-----BEGIN CERTIFICATE-----
170MIIBqzCCARSgAwIBAgIBBDANBgkqhkiG9w0BAQUFADAfMR0wGwYDVQQDDBRUZXN0IEludGVybWV
171kaWF0ZSBDQTAiGA8yMDE3MDEwMTAwMDAwMFoYDzIwMTgwMTAxMDAwMDAwWjAUMRIwEAYDVQQDDA
172lUZXN0IENlcnQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANHSp/1fVrhKSgDE8DZIDZkeu
173sqNjA7pWvQxlCb0JHcMLXY5/h5RnLE6smGu9itBRpKBtB41c7vfU9ZjpAdY6QpAerdxo/19aj8j
1747l52kD9g6oVrdBsfakAnN3+sbpfuE/fLgUQm8yVIVkDvM4TI11JmikA17exnlcE1Rp7bm86bAgM
175BAAEwDQYJKoZIhvcNAQEFBQADgYEAjpRakUSqq+S/xMqj7hBnLT7VrLiQi05/PryDu7LJDKKu+2
176yzXbdAIJ+bfD1fZ7wO+SC8JGcnqS6BCOU/rem366nFWFVV8yYXJkZf7yA4yfKBujnZKEvog//XL
177odyNncPRpuh/tjYIFBowXtmgl1ilJCYcYu5g2moZaRYXc6QClM=
178-----END CERTIFICATE-----
179
180$ openssl asn1parse -i < [OCSP REQUEST]
181    0:d=0  hl=2 l=  66 cons: SEQUENCE
182    2:d=1  hl=2 l=  64 cons:  SEQUENCE
183    4:d=2  hl=2 l=  62 cons:   SEQUENCE
184    6:d=3  hl=2 l=  60 cons:    SEQUENCE
185    8:d=4  hl=2 l=  58 cons:     SEQUENCE
186   10:d=5  hl=2 l=   9 cons:      SEQUENCE
187   12:d=6  hl=2 l=   5 prim:       OBJECT            :sha1
188   19:d=6  hl=2 l=   0 prim:       NULL
189   21:d=5  hl=2 l=  20 prim:      OCTET STRING      [HEX DUMP]:449B1C5B31C6E9990966523E49C3F773C024190A
190   43:d=5  hl=2 l=  20 prim:      OCTET STRING      [HEX DUMP]:7F765910653BB5704124C41E94AEFCF940431A66
191   65:d=5  hl=2 l=   1 prim:      INTEGER           :04
192-----BEGIN OCSP REQUEST-----
193MEIwQDA+MDwwOjAJBgUrDgMCGgUABBREmxxbMcbpmQlmUj5Jw/dzwCQZCgQUf3ZZEGU7tXBBJMQ
194elK78+UBDGmYCAQQ=
195-----END OCSP REQUEST-----
196