1[Created by: generate-chains.py] 2 3Certificate chain where the root certificate holds an RSA key, intermediate 4certificate holds an EC key, and target certificate holds an RSA key. The 5target certificate has a valid signature using ECDSA. 6 7Certificate: 8 Data: 9 Version: 3 (0x2) 10 Serial Number: 11 41:40:39:26:f7:3c:b3:a7:c4:58:60:3a:f3:20:9a:3a:ee:e3:c5:56 12 Signature Algorithm: ecdsa-with-SHA256 13 Issuer: CN=Intermediate 14 Validity 15 Not Before: Oct 5 12:00:00 2021 GMT 16 Not After : Oct 5 12:00:00 2022 GMT 17 Subject: CN=Target 18 Subject Public Key Info: 19 Public Key Algorithm: rsaEncryption 20 RSA Public-Key: (2048 bit) 21 Modulus: 22 00:e6:90:14:d7:6c:5e:85:24:21:17:7a:ce:f2:8a: 23 3e:83:20:e4:3e:eb:cf:4c:06:bb:0a:d5:21:d9:2b: 24 e1:2e:14:8a:20:16:c8:c9:4b:55:ed:e9:ea:48:ed: 25 ef:03:2b:de:25:dd:41:9b:0c:0b:bd:f8:58:e2:a0: 26 ba:92:3f:03:de:ca:e6:35:42:be:ab:e1:33:17:ac: 27 3e:bc:fc:90:2a:d2:c7:76:1f:51:d2:ca:e9:80:e0: 28 76:39:ab:88:65:b4:e3:ea:05:dd:c5:8e:fe:4c:86: 29 c3:06:49:0c:ab:69:a5:4f:14:cc:82:1f:b1:3d:f6: 30 f9:d5:d4:61:41:35:e5:d4:f7:4f:1a:af:fb:a8:ff: 31 ef:7b:38:95:40:c5:56:32:a5:cf:8f:d6:04:df:23: 32 eb:5b:f7:32:a3:d7:a1:df:cb:67:35:25:d6:63:92: 33 d7:da:d9:83:20:52:58:1d:ef:6e:3c:88:91:14:08: 34 c7:70:85:b7:b3:93:c1:9a:51:57:d8:d5:4c:81:83: 35 96:91:b6:5a:b9:b5:7e:fb:90:bd:71:2e:09:04:6e: 36 f9:0b:ff:51:43:d4:20:77:ee:31:34:98:f8:e8:8f: 37 5a:2e:75:f1:0f:bf:64:35:a5:00:cb:4a:00:6e:45: 38 a3:01:d7:97:46:49:55:c1:df:2d:31:c4:98:ae:25: 39 b2:b3 40 Exponent: 65537 (0x10001) 41 X509v3 extensions: 42 X509v3 Subject Key Identifier: 43 A0:D4:34:B4:BC:27:68:8C:38:A0:8F:3A:CF:6E:58:5F:57:97:44:B8 44 X509v3 Authority Key Identifier: 45 keyid:B1:0E:68:94:5F:A9:F7:F8:4B:09:42:7D:AE:5A:7A:05:BF:E4:A1:F1 46 47 Authority Information Access: 48 CA Issuers - URI:http://url-for-aia/Intermediate.cer 49 50 X509v3 CRL Distribution Points: 51 52 Full Name: 53 URI:http://url-for-crl/Intermediate.crl 54 55 X509v3 Key Usage: critical 56 Digital Signature, Key Encipherment 57 X509v3 Extended Key Usage: 58 TLS Web Server Authentication, TLS Web Client Authentication 59 Signature Algorithm: ecdsa-with-SHA256 60 30:66:02:31:00:bf:ee:04:f4:3a:0a:2c:ba:41:33:77:1e:dc: 61 e3:ae:85:f0:ac:29:06:88:ab:a1:58:98:eb:1f:e4:8e:66:9f: 62 dd:1c:6e:96:7f:57:ba:27:4f:f5:21:a0:ad:5a:1f:38:93:02: 63 31:00:c0:58:7d:64:1d:a0:43:1d:04:26:68:14:08:41:bf:a9: 64 7d:56:78:a6:95:74:a4:d3:db:88:6b:64:4c:e7:ee:b5:a0:49: 65 71:00:39:63:19:31:b0:8f:86:7b:c1:b5:dd:f4 66-----BEGIN CERTIFICATE----- 67MIIDADCCAoWgAwIBAgIUQUA5Jvc8s6fEWGA68yCaOu7jxVYwCgYIKoZIzj0EAwIw 68FzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIyMTAw 69NTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEFAAOC 70AQ8AMIIBCgKCAQEA5pAU12xehSQhF3rO8oo+gyDkPuvPTAa7CtUh2SvhLhSKIBbI 71yUtV7enqSO3vAyveJd1BmwwLvfhY4qC6kj8D3srmNUK+q+EzF6w+vPyQKtLHdh9R 720srpgOB2OauIZbTj6gXdxY7+TIbDBkkMq2mlTxTMgh+xPfb51dRhQTXl1PdPGq/7 73qP/veziVQMVWMqXPj9YE3yPrW/cyo9eh38tnNSXWY5LX2tmDIFJYHe9uPIiRFAjH 74cIW3s5PBmlFX2NVMgYOWkbZaubV++5C9cS4JBG75C/9RQ9Qgd+4xNJj46I9aLnXx 75D79kNaUAy0oAbkWjAdeXRklVwd8tMcSYriWyswIDAQABo4HpMIHmMB0GA1UdDgQW 76BBSg1DS0vCdojDigjzrPblhfV5dEuDAfBgNVHSMEGDAWgBSxDmiUX6n3+EsJQn2u 77WnoFv+Sh8TA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91cmwt 78Zm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6 79Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIFoDAd 80BgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwCgYIKoZIzj0EAwIDaQAwZgIx 81AL/uBPQ6Ciy6QTN3HtzjroXwrCkGiKuhWJjrH+SOZp/dHG6Wf1e6J0/1IaCtWh84 82kwIxAMBYfWQdoEMdBCZoFAhBv6l9VnimlXSk09uIa2RM5+61oElxADljGTGwj4Z7 83wbXd9A== 84-----END CERTIFICATE----- 85 86Certificate: 87 Data: 88 Version: 3 (0x2) 89 Serial Number: 90 62:20:1f:53:92:38:2c:47:67:4d:1d:04:41:2d:53:ab:1e:d4:5c:aa 91 Signature Algorithm: sha256WithRSAEncryption 92 Issuer: CN=Root 93 Validity 94 Not Before: Oct 5 12:00:00 2021 GMT 95 Not After : Oct 5 12:00:00 2022 GMT 96 Subject: CN=Intermediate 97 Subject Public Key Info: 98 Public Key Algorithm: id-ecPublicKey 99 Public-Key: (384 bit) 100 pub: 101 04:f3:8f:d7:88:9f:98:67:05:36:a9:16:7c:85:b2: 102 cf:8e:02:72:19:eb:ab:48:14:1e:6f:6a:13:93:3e: 103 80:b9:aa:7f:53:9c:91:91:9e:b1:79:76:ec:31:ef: 104 97:46:30:d8:f4:ad:9c:60:c0:a6:00:88:62:5a:68: 105 9e:3e:00:f3:6c:b4:1a:10:0b:78:12:f3:fe:5f:47: 106 40:14:e7:2d:c0:82:cc:cf:df:93:fb:21:8e:ed:59: 107 b2:70:1e:7b:70:0c:e5 108 ASN1 OID: secp384r1 109 NIST CURVE: P-384 110 X509v3 extensions: 111 X509v3 Subject Key Identifier: 112 B1:0E:68:94:5F:A9:F7:F8:4B:09:42:7D:AE:5A:7A:05:BF:E4:A1:F1 113 X509v3 Authority Key Identifier: 114 keyid:43:E7:CC:3C:45:3E:58:A7:6D:D2:90:56:8F:16:93:9E:2F:F3:06:2E 115 116 Authority Information Access: 117 CA Issuers - URI:http://url-for-aia/Root.cer 118 119 X509v3 CRL Distribution Points: 120 121 Full Name: 122 URI:http://url-for-crl/Root.crl 123 124 X509v3 Key Usage: critical 125 Certificate Sign, CRL Sign 126 X509v3 Basic Constraints: critical 127 CA:TRUE 128 Signature Algorithm: sha256WithRSAEncryption 129 8d:18:e4:44:8c:d8:6b:90:61:40:38:87:fb:85:bf:25:b8:c6: 130 a6:8b:6a:95:28:46:a9:19:3a:59:83:df:1a:d1:73:b0:20:7d: 131 96:41:bc:0e:77:0c:b9:65:8d:54:f4:0b:a5:69:b1:5a:9a:49: 132 21:f0:92:fe:88:00:79:01:57:47:4a:d4:a7:06:ca:49:69:fc: 133 c7:e9:40:90:58:0f:d6:3b:66:a7:39:f5:11:d8:de:5e:bf:3d: 134 04:08:92:c2:ba:c1:d1:9b:c3:63:08:22:48:a4:9b:23:12:86: 135 95:cf:b3:9f:7e:94:01:6d:3b:e7:fa:4f:b5:29:43:5d:34:98: 136 01:f5:26:96:7e:c6:46:77:8f:41:7c:74:ad:e1:f7:60:5a:bd: 137 fa:28:f6:c1:d9:5c:e2:0d:a3:9c:f3:72:69:c0:7e:ca:b6:5d: 138 e3:19:0f:90:c6:e8:08:64:b7:38:17:56:9d:16:ac:49:17:d9: 139 18:08:1c:eb:02:e5:11:5d:22:92:e2:7f:28:ec:cf:73:c5:25: 140 d5:13:17:b3:d1:88:e2:4b:5d:e7:b1:39:73:9b:52:9c:3e:6d: 141 02:d2:f1:be:ac:6a:20:f1:93:9e:51:60:e4:50:da:c9:b4:99: 142 79:85:cf:de:19:81:0c:8d:fa:2a:28:c9:da:51:db:66:51:da: 143 1e:c0:90:54 144-----BEGIN CERTIFICATE----- 145MIIC0jCCAbqgAwIBAgIUYiAfU5I4LEdnTR0EQS1Tqx7UXKowDQYJKoZIhvcNAQEL 146BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 147MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTB2MBAGByqGSM49AgEGBSuBBAAi 148A2IABPOP14ifmGcFNqkWfIWyz44Cchnrq0gUHm9qE5M+gLmqf1OckZGesXl27DHv 149l0Yw2PStnGDApgCIYlponj4A82y0GhALeBLz/l9HQBTnLcCCzM/fk/shju1ZsnAe 150e3AM5aOByzCByDAdBgNVHQ4EFgQUsQ5olF+p9/hLCUJ9rlp6Bb/kofEwHwYDVR0j 151BBgwFoAUQ+fMPEU+WKdt0pBWjxaTni/zBi4wNwYIKwYBBQUHAQEEKzApMCcGCCsG 152AQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAh 153oB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIB 154BjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCNGOREjNhrkGFA 155OIf7hb8luMami2qVKEapGTpZg98a0XOwIH2WQbwOdwy5ZY1U9AulabFamkkh8JL+ 156iAB5AVdHStSnBspJafzH6UCQWA/WO2anOfUR2N5evz0ECJLCusHRm8NjCCJIpJsj 157EoaVz7OffpQBbTvn+k+1KUNdNJgB9SaWfsZGd49BfHSt4fdgWr36KPbB2VziDaOc 15883JpwH7Ktl3jGQ+QxugIZLc4F1adFqxJF9kYCBzrAuURXSKS4n8o7M9zxSXVExez 1590YjiS13nsTlzm1KcPm0C0vG+rGog8ZOeUWDkUNrJtJl5hc/eGYEMjfoqKMnaUdtm 160UdoewJBU 161-----END CERTIFICATE----- 162 163Certificate: 164 Data: 165 Version: 3 (0x2) 166 Serial Number: 167 62:20:1f:53:92:38:2c:47:67:4d:1d:04:41:2d:53:ab:1e:d4:5c:a9 168 Signature Algorithm: sha256WithRSAEncryption 169 Issuer: CN=Root 170 Validity 171 Not Before: Oct 5 12:00:00 2021 GMT 172 Not After : Oct 5 12:00:00 2022 GMT 173 Subject: CN=Root 174 Subject Public Key Info: 175 Public Key Algorithm: rsaEncryption 176 RSA Public-Key: (2048 bit) 177 Modulus: 178 00:f5:c6:4e:ee:3f:f0:7c:64:c3:5d:09:15:02:1c: 179 1b:f3:43:19:a5:c1:a9:a0:fb:f9:98:ee:e4:af:7c: 180 e2:ad:51:6d:c5:74:03:4d:db:f1:e0:69:ed:9a:23: 181 d8:cd:34:0b:83:6a:32:4e:1d:c0:91:fc:88:17:02: 182 0d:bd:6d:d9:b9:92:71:6b:8f:23:40:f9:48:fe:16: 183 59:af:f4:9c:33:7d:3f:08:65:ff:f1:e5:9c:4d:e8: 184 e8:7b:4a:c3:16:6d:53:9d:92:d7:86:9b:95:fb:5d: 185 86:6d:af:00:dd:6f:25:0d:53:70:7e:b6:36:11:94: 186 d1:90:b5:f1:6d:a8:b0:e8:2d:0d:c5:85:b5:50:4b: 187 7e:b0:57:8d:82:6d:bb:e0:82:64:3b:a4:d6:c4:d7: 188 0a:2c:89:61:47:99:67:5e:71:1f:5c:66:14:08:fa: 189 29:88:09:3b:38:60:4d:01:67:53:fe:16:85:70:54: 190 bf:e1:5e:76:b8:33:e3:9c:17:08:a4:0f:f2:c5:e1: 191 ac:99:94:7e:10:47:7d:51:43:42:85:df:e2:9a:53: 192 07:c4:2f:c8:bf:56:da:0b:7f:41:6d:8f:76:42:b0: 193 25:3c:fb:0a:f4:d0:d0:b3:79:72:70:0d:07:95:97: 194 c1:11:82:ff:c4:13:ec:0f:cf:bb:4e:b8:4a:ed:ca: 195 3c:a3 196 Exponent: 65537 (0x10001) 197 X509v3 extensions: 198 X509v3 Subject Key Identifier: 199 43:E7:CC:3C:45:3E:58:A7:6D:D2:90:56:8F:16:93:9E:2F:F3:06:2E 200 X509v3 Authority Key Identifier: 201 keyid:43:E7:CC:3C:45:3E:58:A7:6D:D2:90:56:8F:16:93:9E:2F:F3:06:2E 202 203 Authority Information Access: 204 CA Issuers - URI:http://url-for-aia/Root.cer 205 206 X509v3 CRL Distribution Points: 207 208 Full Name: 209 URI:http://url-for-crl/Root.crl 210 211 X509v3 Key Usage: critical 212 Certificate Sign, CRL Sign 213 X509v3 Basic Constraints: critical 214 CA:TRUE 215 Signature Algorithm: sha256WithRSAEncryption 216 d2:50:10:c9:a0:28:ad:dc:18:87:68:2b:7c:a7:6c:e8:1a:07: 217 38:9f:f0:dc:45:7a:75:f4:24:47:16:ce:4a:60:76:c0:0e:2a: 218 61:f0:b1:55:42:23:08:f9:b1:f4:4f:9a:0e:ad:9a:4f:b9:bb: 219 42:d4:98:13:87:ce:1e:55:f3:1b:25:cf:fa:a4:f5:5b:d6:d2: 220 cb:28:ca:86:aa:f8:e2:8b:d2:8b:e3:0c:0e:d9:e3:9f:ee:27: 221 03:c6:13:e8:9d:a5:b1:64:c8:a2:e5:c0:f0:07:03:58:a1:20: 222 0c:7b:47:a2:db:67:86:e9:68:25:04:ad:c9:1f:dc:2d:b1:0e: 223 52:a8:6f:de:6c:29:02:17:58:30:df:0c:7c:f3:1f:e6:9e:d7: 224 bd:40:0d:e3:eb:af:49:1f:d8:e9:3f:0b:ee:54:97:b1:93:1e: 225 77:f2:26:51:6a:5a:be:e4:82:ff:5f:fc:b5:23:74:dd:82:45: 226 ea:f5:7a:31:7d:9d:fd:62:4a:2d:99:67:4b:ba:62:5e:47:cb: 227 4a:63:d9:b4:6e:ea:39:ac:d6:3e:6c:53:92:d1:9a:ae:a1:1f: 228 6f:f2:ff:75:07:26:24:53:76:1e:e0:d7:2a:3b:59:74:45:54: 229 94:b6:7e:45:aa:26:b3:96:22:c0:ca:c5:d0:e2:5d:a4:f6:74: 230 b7:3a:66:d1 231-----BEGIN CERTIFICATE----- 232MIIDeDCCAmCgAwIBAgIUYiAfU5I4LEdnTR0EQS1Tqx7UXKkwDQYJKoZIhvcNAQEL 233BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 234MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK 235AoIBAQD1xk7uP/B8ZMNdCRUCHBvzQxmlwamg+/mY7uSvfOKtUW3FdANN2/Hgae2a 236I9jNNAuDajJOHcCR/IgXAg29bdm5knFrjyNA+Uj+Flmv9JwzfT8IZf/x5ZxN6Oh7 237SsMWbVOdkteGm5X7XYZtrwDdbyUNU3B+tjYRlNGQtfFtqLDoLQ3FhbVQS36wV42C 238bbvggmQ7pNbE1wosiWFHmWdecR9cZhQI+imICTs4YE0BZ1P+FoVwVL/hXna4M+Oc 239FwikD/LF4ayZlH4QR31RQ0KF3+KaUwfEL8i/VtoLf0Ftj3ZCsCU8+wr00NCzeXJw 240DQeVl8ERgv/EE+wPz7tOuErtyjyjAgMBAAGjgcswgcgwHQYDVR0OBBYEFEPnzDxF 241PlinbdKQVo8Wk54v8wYuMB8GA1UdIwQYMBaAFEPnzDxFPlinbdKQVo8Wk54v8wYu 242MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh 243L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S 244b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG 2459w0BAQsFAAOCAQEA0lAQyaAordwYh2grfKds6BoHOJ/w3EV6dfQkRxbOSmB2wA4q 246YfCxVUIjCPmx9E+aDq2aT7m7QtSYE4fOHlXzGyXP+qT1W9bSyyjKhqr44ovSi+MM 247Dtnjn+4nA8YT6J2lsWTIouXA8AcDWKEgDHtHottnhuloJQStyR/cLbEOUqhv3mwp 248AhdYMN8MfPMf5p7XvUAN4+uvSR/Y6T8L7lSXsZMed/ImUWpavuSC/1/8tSN03YJF 2496vV6MX2d/WJKLZlnS7piXkfLSmPZtG7qOazWPmxTktGarqEfb/L/dQcmJFN2HuDX 250KjtZdEVUlLZ+Raoms5YiwMrF0OJdpPZ0tzpm0Q== 251-----END CERTIFICATE----- 252