1[Created by: ./generate-chains.py]
2
3Certificate chain with policies and requireExplicitPolicy.
4
5Certificate:
6    Data:
7        Version: 3 (0x2)
8        Serial Number:
9            76:08:4d:78:c1:3f:07:cd:a3:c6:78:9f:04:0f:8d:7f:53:59:b2:73
10        Signature Algorithm: sha256WithRSAEncryption
11        Issuer: CN=Intermediate
12        Validity
13            Not Before: Oct  5 12:00:00 2021 GMT
14            Not After : Oct  5 12:00:00 2022 GMT
15        Subject: CN=Target
16        Subject Public Key Info:
17            Public Key Algorithm: rsaEncryption
18                Public-Key: (2048 bit)
19                Modulus:
20                    00:c1:4e:54:b8:f3:a9:51:97:5a:ab:40:dd:8f:a8:
21                    4d:1c:3e:e2:4a:bc:ea:eb:f4:11:44:51:30:8c:9c:
22                    b0:60:16:37:98:47:4a:c3:b8:b1:2e:b3:bd:c8:05:
23                    3f:70:4c:b8:2d:57:43:3b:6f:da:9b:72:57:f6:45:
24                    db:8d:e1:c8:08:80:d6:10:94:c9:2a:58:92:e9:a4:
25                    2d:ce:a7:5b:64:bd:99:fc:16:ee:8e:87:fb:fc:05:
26                    e8:06:13:b0:01:b7:c7:53:6f:20:34:40:c5:d4:0b:
27                    e9:72:54:88:f8:38:2c:dc:6c:21:e0:9b:c5:d1:95:
28                    79:f3:f2:3a:38:8e:54:0b:af:d6:74:98:37:28:86:
29                    96:33:7c:63:e5:38:03:f2:7d:16:fe:fb:16:57:5b:
30                    59:81:f1:83:86:11:4f:4a:96:17:80:e1:22:00:e4:
31                    e0:7f:6c:b6:4e:ad:22:10:90:fb:2c:61:9c:4e:25:
32                    23:c3:04:69:69:45:66:6a:e6:fc:0a:31:98:59:0f:
33                    df:e5:45:37:68:d4:2d:b8:c4:20:16:f2:c0:db:c2:
34                    7e:93:5b:0b:e2:26:46:ba:78:e5:fa:b7:e1:b3:86:
35                    7a:72:85:26:ae:1c:c6:a6:e9:57:fd:c1:c7:6d:4e:
36                    5f:59:3a:7a:76:f8:d9:f6:1b:e5:e9:c6:96:c4:14:
37                    ce:9d
38                Exponent: 65537 (0x10001)
39        X509v3 extensions:
40            X509v3 Subject Key Identifier:
41                3F:54:44:D9:08:0D:47:C0:7F:78:3F:FE:2A:09:5F:9A:11:8F:B3:5D
42            X509v3 Authority Key Identifier:
43                3D:93:4F:05:1D:3B:34:80:2F:A2:A7:1F:CA:9C:28:DC:C1:55:E2:67
44            Authority Information Access:
45                CA Issuers - URI:http://url-for-aia/Intermediate.cer
46            X509v3 CRL Distribution Points:
47                Full Name:
48                  URI:http://url-for-crl/Intermediate.crl
49            X509v3 Key Usage: critical
50                Digital Signature, Key Encipherment
51            X509v3 Extended Key Usage:
52                TLS Web Server Authentication, TLS Web Client Authentication
53            X509v3 Certificate Policies: critical
54                Policy: 1.2.3.4
55    Signature Algorithm: sha256WithRSAEncryption
56    Signature Value:
57        63:69:e9:e2:b0:09:40:6b:26:74:bb:fa:01:d5:fb:c7:b7:aa:
58        d1:bd:69:0d:ac:f0:94:56:21:8b:32:7e:4b:12:e9:a5:eb:ce:
59        14:41:2a:23:17:eb:5f:df:dd:e0:e7:1a:9d:1e:cf:17:9f:26:
60        81:9b:b4:b0:c3:28:67:5b:65:c9:d7:9f:21:9b:9c:01:97:a8:
61        ec:44:8d:04:7d:fc:72:01:93:aa:92:84:59:42:d2:da:49:08:
62        35:8e:d6:7d:89:a0:c3:70:6d:05:f7:eb:30:08:6e:66:2c:90:
63        7c:33:e7:b8:81:d9:04:cb:12:db:a2:34:1a:c9:fa:d6:ef:af:
64        98:84:bc:c9:a9:af:4a:d6:23:ff:b3:6d:d4:3c:0f:d8:f8:bc:
65        10:1e:c6:29:06:6c:7c:5b:b2:f3:4f:96:95:79:69:7b:00:c0:
66        65:04:84:0f:2e:28:e9:b2:a2:98:2d:b8:35:8c:09:c3:d4:f1:
67        69:f6:31:d7:37:85:5a:72:46:07:11:56:fc:48:79:b7:02:ed:
68        ba:a8:bd:4b:38:95:71:e8:e0:e0:99:2c:f9:19:bc:1e:61:f8:
69        a3:26:61:31:c8:af:07:d2:1b:58:96:82:42:b0:f3:f0:6c:4f:
70        54:0a:bb:fa:44:a2:92:89:90:c5:fc:1d:31:e3:08:4d:fe:97:
71        b0:8e:b0:cc
72-----BEGIN CERTIFICATE-----
73MIIDtTCCAp2gAwIBAgIUdghNeME/B82jxnifBA+Nf1NZsnMwDQYJKoZIhvcNAQEL
74BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
75MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
76AAOCAQ8AMIIBCgKCAQEAwU5UuPOpUZdaq0Ddj6hNHD7iSrzq6/QRRFEwjJywYBY3
77mEdKw7ixLrO9yAU/cEy4LVdDO2/am3JX9kXbjeHICIDWEJTJKliS6aQtzqdbZL2Z
78/Bbujof7/AXoBhOwAbfHU28gNEDF1AvpclSI+Dgs3Gwh4JvF0ZV58/I6OI5UC6/W
79dJg3KIaWM3xj5TgD8n0W/vsWV1tZgfGDhhFPSpYXgOEiAOTgf2y2Tq0iEJD7LGGc
80TiUjwwRpaUVmaub8CjGYWQ/f5UU3aNQtuMQgFvLA28J+k1sL4iZGunjl+rfhs4Z6
81coUmrhzGpulX/cHHbU5fWTp6dvjZ9hvl6caWxBTOnQIDAQABo4H+MIH7MB0GA1Ud
82DgQWBBQ/VETZCA1HwH94P/4qCV+aEY+zXTAfBgNVHSMEGDAWgBQ9k08FHTs0gC+i
83px/KnCjcwVXiZzA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
84cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
85dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
86oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEwYDVR0gAQH/BAkwBzAF
87BgMqAwQwDQYJKoZIhvcNAQELBQADggEBAGNp6eKwCUBrJnS7+gHV+8e3qtG9aQ2s
888JRWIYsyfksS6aXrzhRBKiMX61/f3eDnGp0ezxefJoGbtLDDKGdbZcnXnyGbnAGX
89qOxEjQR9/HIBk6qShFlC0tpJCDWO1n2JoMNwbQX36zAIbmYskHwz57iB2QTLEtui
90NBrJ+tbvr5iEvMmpr0rWI/+zbdQ8D9j4vBAexikGbHxbsvNPlpV5aXsAwGUEhA8u
91KOmyopgtuDWMCcPU8Wn2Mdc3hVpyRgcRVvxIebcC7bqovUs4lXHo4OCZLPkZvB5h
92+KMmYTHIrwfSG1iWgkKw8/BsT1QKu/pEopKJkMX8HTHjCE3+l7COsMw=
93-----END CERTIFICATE-----
94
95Certificate:
96    Data:
97        Version: 3 (0x2)
98        Serial Number:
99            6d:e0:57:1a:f3:9a:80:02:b6:c9:bd:be:0c:a5:21:0f:8b:78:67:70
100        Signature Algorithm: sha256WithRSAEncryption
101        Issuer: CN=Root
102        Validity
103            Not Before: Oct  5 12:00:00 2021 GMT
104            Not After : Oct  5 12:00:00 2022 GMT
105        Subject: CN=Intermediate
106        Subject Public Key Info:
107            Public Key Algorithm: rsaEncryption
108                Public-Key: (2048 bit)
109                Modulus:
110                    00:d4:36:ce:68:1f:c4:5f:a3:21:5a:43:7d:5e:54:
111                    8e:a7:77:c3:5e:48:80:e7:05:4a:05:a2:c4:36:30:
112                    2c:e2:0b:d9:8e:0c:df:98:4f:f0:6d:2b:12:ae:6c:
113                    ae:3c:d9:d7:a8:c1:3c:0e:40:14:81:90:f9:ed:cf:
114                    3f:e4:93:f4:5a:dc:89:57:f4:4f:ca:0d:c7:8c:32:
115                    a0:b0:7b:d1:d0:b1:45:e6:5a:2a:32:c9:dc:db:7f:
116                    af:46:e6:5b:1a:02:72:46:be:66:3b:98:67:e2:33:
117                    c8:05:60:05:2a:7b:03:42:14:ba:62:f0:62:c0:7b:
118                    75:58:06:c0:b4:b8:81:ad:23:e7:60:33:53:55:7e:
119                    7c:78:7c:97:a5:09:fc:97:2c:49:51:77:48:49:39:
120                    5f:fb:6f:b1:3f:eb:b0:6d:c4:d6:a5:9f:97:ba:8e:
121                    19:5f:fe:d9:71:ee:8a:6a:0d:08:6e:5c:09:54:6f:
122                    8c:f3:a1:74:08:6f:dc:36:69:00:e8:6a:40:82:6f:
123                    de:ba:87:dd:32:f2:c8:60:f0:3f:5f:87:a3:e5:4c:
124                    76:7f:77:75:46:47:c0:fa:c0:03:ce:3f:57:dc:9a:
125                    ee:0c:3e:27:65:39:4b:5c:fc:dd:09:c9:80:d8:6c:
126                    9c:ee:6c:8b:e7:99:43:b3:21:b5:10:9f:4a:aa:8e:
127                    0b:97
128                Exponent: 65537 (0x10001)
129        X509v3 extensions:
130            X509v3 Subject Key Identifier:
131                3D:93:4F:05:1D:3B:34:80:2F:A2:A7:1F:CA:9C:28:DC:C1:55:E2:67
132            X509v3 Authority Key Identifier:
133                B2:69:86:08:36:14:3E:66:79:B7:98:70:BE:30:9D:0B:73:00:6F:0E
134            Authority Information Access:
135                CA Issuers - URI:http://url-for-aia/Root.cer
136            X509v3 CRL Distribution Points:
137                Full Name:
138                  URI:http://url-for-crl/Root.crl
139            X509v3 Key Usage: critical
140                Certificate Sign, CRL Sign
141            X509v3 Basic Constraints: critical
142                CA:TRUE
143            X509v3 Certificate Policies: critical
144                Policy: 1.2.3.4
145            X509v3 Policy Constraints: critical
146                Require Explicit Policy:0
147    Signature Algorithm: sha256WithRSAEncryption
148    Signature Value:
149        28:a1:4e:4e:d5:82:36:24:6f:69:b8:2d:ab:a2:a6:64:32:48:
150        7d:cd:18:0d:6a:d8:43:79:c1:6b:b9:f1:6b:70:ab:64:e3:b3:
151        46:1f:06:61:99:92:21:ef:9e:18:38:4a:c0:3d:a2:b6:32:79:
152        5d:c9:68:04:84:ba:a6:1a:a6:8c:f1:51:3e:ab:01:83:57:78:
153        f8:38:80:e9:38:d8:db:40:ac:9e:94:e1:da:13:d9:33:4c:20:
154        98:3d:da:6b:95:d0:64:6f:fd:6c:37:f1:fe:1c:ea:a5:71:49:
155        9e:b1:24:94:0a:84:ff:60:b0:b0:8d:2a:54:2c:25:74:0d:18:
156        1c:7e:9a:67:d8:82:ec:af:fc:88:2a:fb:9c:29:ba:a6:a9:1a:
157        cc:cd:c0:71:b3:02:f3:d8:58:f2:d3:4f:0f:5a:19:da:28:3b:
158        f3:5a:38:b5:5a:40:1a:05:13:16:9c:0c:d7:df:ef:0b:2f:2b:
159        81:7b:01:30:d7:88:2d:8d:e5:b6:89:b8:98:4b:40:aa:0f:46:
160        65:15:09:40:49:8f:93:0c:10:5e:b2:34:1a:e0:8f:7b:7d:90:
161        35:df:64:1c:ce:08:0e:38:fa:cb:cf:f0:e4:62:a6:e7:15:dd:
162        07:a5:b5:42:3b:d8:77:e7:8b:d1:1c:2a:3c:6f:c2:33:2c:f2:
163        7c:14:59:5f
164-----BEGIN CERTIFICATE-----
165MIIDpjCCAo6gAwIBAgIUbeBXGvOagAK2yb2+DKUhD4t4Z3AwDQYJKoZIhvcNAQEL
166BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
167MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
168ggEPADCCAQoCggEBANQ2zmgfxF+jIVpDfV5Ujqd3w15IgOcFSgWixDYwLOIL2Y4M
16935hP8G0rEq5srjzZ16jBPA5AFIGQ+e3PP+ST9FrciVf0T8oNx4wyoLB70dCxReZa
170KjLJ3Nt/r0bmWxoCcka+ZjuYZ+IzyAVgBSp7A0IUumLwYsB7dVgGwLS4ga0j52Az
171U1V+fHh8l6UJ/JcsSVF3SEk5X/tvsT/rsG3E1qWfl7qOGV/+2XHuimoNCG5cCVRv
172jPOhdAhv3DZpAOhqQIJv3rqH3TLyyGDwP1+Ho+VMdn93dUZHwPrAA84/V9ya7gw+
173J2U5S1z83QnJgNhsnO5si+eZQ7MhtRCfSqqOC5cCAwEAAaOB8TCB7jAdBgNVHQ4E
174FgQUPZNPBR07NIAvoqcfypwo3MFV4mcwHwYDVR0jBBgwFoAUsmmGCDYUPmZ5t5hw
175vjCdC3MAbw4wNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
176LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
177b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
178MBMGA1UdIAEB/wQJMAcwBQYDKgMEMA8GA1UdJAEB/wQFMAOAAQAwDQYJKoZIhvcN
179AQELBQADggEBACihTk7VgjYkb2m4LauipmQySH3NGA1q2EN5wWu58Wtwq2Tjs0Yf
180BmGZkiHvnhg4SsA9orYyeV3JaASEuqYapozxUT6rAYNXePg4gOk42NtArJ6U4doT
1812TNMIJg92muV0GRv/Ww38f4c6qVxSZ6xJJQKhP9gsLCNKlQsJXQNGBx+mmfYguyv
182/Igq+5wpuqapGszNwHGzAvPYWPLTTw9aGdooO/NaOLVaQBoFExacDNff7wsvK4F7
183ATDXiC2N5baJuJhLQKoPRmUVCUBJj5MMEF6yNBrgj3t9kDXfZBzOCA44+svP8ORi
184pucV3QeltUI72Hfni9EcKjxvwjMs8nwUWV8=
185-----END CERTIFICATE-----
186
187Certificate:
188    Data:
189        Version: 3 (0x2)
190        Serial Number:
191            6d:e0:57:1a:f3:9a:80:02:b6:c9:bd:be:0c:a5:21:0f:8b:78:67:6f
192        Signature Algorithm: sha256WithRSAEncryption
193        Issuer: CN=Root
194        Validity
195            Not Before: Oct  5 12:00:00 2021 GMT
196            Not After : Oct  5 12:00:00 2022 GMT
197        Subject: CN=Root
198        Subject Public Key Info:
199            Public Key Algorithm: rsaEncryption
200                Public-Key: (2048 bit)
201                Modulus:
202                    00:b7:3b:ea:17:07:2b:f0:3b:dd:d2:24:53:f6:fa:
203                    9f:47:c2:a7:6e:fa:04:f1:b2:fe:74:ef:ec:24:75:
204                    07:fd:f3:7b:29:9c:17:1c:e5:41:df:34:4a:1c:2b:
205                    4a:5f:8d:36:44:1a:5f:67:92:7a:2a:a8:85:7b:49:
206                    b7:83:1d:c7:7f:44:c3:a7:09:3a:75:5e:00:43:db:
207                    dd:91:41:28:a1:cd:13:11:35:3b:7a:92:fc:ad:98:
208                    3c:ac:cb:85:77:a4:d0:3f:57:ed:67:69:9c:40:3b:
209                    c4:0c:a3:32:3a:01:73:0c:ed:55:21:a8:be:b4:41:
210                    ee:f3:6e:e9:04:10:9b:2c:7b:c5:2a:d2:87:52:ef:
211                    12:84:87:82:5e:40:e3:bf:6a:47:33:60:22:1a:42:
212                    63:45:ac:28:be:79:59:37:48:45:65:6b:13:89:bb:
213                    58:6e:d8:4e:8d:b3:26:30:d2:c0:3e:d6:16:f2:08:
214                    31:bf:2c:b1:c9:b7:c4:58:09:89:ee:52:21:fb:ab:
215                    7a:f1:4e:b3:7f:a1:20:c3:99:9b:74:0d:d3:c4:c3:
216                    3d:53:aa:cb:32:48:0e:8a:66:2b:07:09:8c:73:38:
217                    ff:81:15:30:c9:12:39:d5:ec:44:32:81:df:ec:85:
218                    c1:d3:45:d1:eb:82:61:f2:86:ad:1a:e1:a3:ee:a1:
219                    a0:29
220                Exponent: 65537 (0x10001)
221        X509v3 extensions:
222            X509v3 Subject Key Identifier:
223                B2:69:86:08:36:14:3E:66:79:B7:98:70:BE:30:9D:0B:73:00:6F:0E
224            X509v3 Authority Key Identifier:
225                B2:69:86:08:36:14:3E:66:79:B7:98:70:BE:30:9D:0B:73:00:6F:0E
226            Authority Information Access:
227                CA Issuers - URI:http://url-for-aia/Root.cer
228            X509v3 CRL Distribution Points:
229                Full Name:
230                  URI:http://url-for-crl/Root.crl
231            X509v3 Key Usage: critical
232                Certificate Sign, CRL Sign
233            X509v3 Basic Constraints: critical
234                CA:TRUE
235    Signature Algorithm: sha256WithRSAEncryption
236    Signature Value:
237        55:ce:69:0a:bf:08:3a:d2:a3:2d:00:b0:5f:b4:f9:e1:26:3b:
238        3b:28:e5:45:c5:e4:8f:46:f0:1a:a2:ae:d4:e7:a9:dd:39:08:
239        dd:d4:80:52:75:4d:35:95:50:b6:44:49:c0:48:c1:3f:c4:19:
240        1b:b1:71:73:65:9b:78:a1:1d:79:01:09:d8:46:e8:b0:6b:e3:
241        77:b3:a0:4e:6b:ff:1a:e1:63:12:56:b7:df:4d:d9:f4:ab:fc:
242        5f:a5:e7:e1:38:28:80:a6:cb:fd:b1:ba:32:34:2e:c9:90:9f:
243        9a:8f:c2:40:ab:04:42:8c:ea:b4:55:79:e3:e5:7d:73:e6:0f:
244        63:95:76:49:94:44:16:57:7f:4f:2b:6a:28:16:ff:01:e4:1c:
245        ad:b8:14:10:d2:10:17:df:65:36:f7:08:98:c3:c3:f2:6c:c4:
246        70:dc:8f:e1:67:f0:62:eb:19:21:8c:c0:a6:53:20:ff:4d:b8:
247        80:a8:3d:6d:15:6b:23:5d:06:70:fa:2a:87:ec:ff:20:96:f8:
248        31:1c:23:93:f5:a4:03:e9:11:c5:0b:da:cf:7e:60:86:a8:da:
249        c5:fe:5c:eb:dd:b8:67:72:5c:d9:16:c4:af:a8:41:aa:38:c4:
250        40:0a:17:fd:06:89:b5:c4:7a:2a:1b:0d:49:23:9e:ed:55:e3:
251        c5:ec:48:3d
252-----BEGIN CERTIFICATE-----
253MIIDeDCCAmCgAwIBAgIUbeBXGvOagAK2yb2+DKUhD4t4Z28wDQYJKoZIhvcNAQEL
254BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
255MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
256AoIBAQC3O+oXByvwO93SJFP2+p9Hwqdu+gTxsv507+wkdQf983spnBcc5UHfNEoc
257K0pfjTZEGl9nknoqqIV7SbeDHcd/RMOnCTp1XgBD292RQSihzRMRNTt6kvytmDys
258y4V3pNA/V+1naZxAO8QMozI6AXMM7VUhqL60Qe7zbukEEJsse8Uq0odS7xKEh4Je
259QOO/akczYCIaQmNFrCi+eVk3SEVlaxOJu1hu2E6NsyYw0sA+1hbyCDG/LLHJt8RY
260CYnuUiH7q3rxTrN/oSDDmZt0DdPEwz1TqssySA6KZisHCYxzOP+BFTDJEjnV7EQy
261gd/shcHTRdHrgmHyhq0a4aPuoaApAgMBAAGjgcswgcgwHQYDVR0OBBYEFLJphgg2
262FD5mebeYcL4wnQtzAG8OMB8GA1UdIwQYMBaAFLJphgg2FD5mebeYcL4wnQtzAG8O
263MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
264L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
265b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
2669w0BAQsFAAOCAQEAVc5pCr8IOtKjLQCwX7T54SY7OyjlRcXkj0bwGqKu1Oep3TkI
2673dSAUnVNNZVQtkRJwEjBP8QZG7Fxc2WbeKEdeQEJ2EbosGvjd7OgTmv/GuFjEla3
268303Z9Kv8X6Xn4TgogKbL/bG6MjQuyZCfmo/CQKsEQozqtFV54+V9c+YPY5V2SZRE
269Fld/TytqKBb/AeQcrbgUENIQF99lNvcImMPD8mzEcNyP4WfwYusZIYzAplMg/024
270gKg9bRVrI10GcPoqh+z/IJb4MRwjk/WkA+kRxQvaz35ghqjaxf5c6924Z3Jc2RbE
271r6hBqjjEQAoX/QaJtcR6KhsNSSOe7VXjxexIPQ==
272-----END CERTIFICATE-----
273