1[Created by: generate-chains.py] 2 3Certificate chain where the target certificate sets the extended key usage 4to clientAuth. Neither the root nor the intermediate have an EKU. 5 6Certificate: 7 Data: 8 Version: 3 (0x2) 9 Serial Number: 10 51:d2:13:35:b6:8a:b2:3b:cd:22:15:03:93:0a:b2:a0:22:4d:e1:57 11 Signature Algorithm: sha256WithRSAEncryption 12 Issuer: CN=Intermediate 13 Validity 14 Not Before: Oct 5 12:00:00 2021 GMT 15 Not After : Oct 5 12:00:00 2022 GMT 16 Subject: CN=Target 17 Subject Public Key Info: 18 Public Key Algorithm: rsaEncryption 19 RSA Public-Key: (2048 bit) 20 Modulus: 21 00:c3:82:13:64:0e:35:33:0c:ac:44:be:6d:92:f5: 22 e4:97:d8:9a:bd:64:f1:b5:67:62:01:7b:0c:98:57: 23 4a:63:64:b0:9d:6a:7b:84:a2:91:fe:73:0b:4c:81: 24 ce:89:f9:8d:8d:8a:41:18:c8:d8:64:27:36:32:e6: 25 36:26:44:16:13:2e:a1:ad:38:06:0b:1b:39:62:6a: 26 94:ac:a0:59:be:52:cb:47:d7:4b:00:09:91:8e:14: 27 69:a9:62:df:49:d8:b6:79:73:de:60:d4:b8:76:89: 28 a4:53:8a:1d:4b:80:88:31:e8:05:46:81:1b:7b:5d: 29 52:d0:6b:3b:53:0d:25:3c:95:9b:2d:99:83:3c:03: 30 8c:b5:73:fb:43:6c:82:b3:48:57:38:3c:ff:b7:79: 31 d8:13:74:06:d0:17:78:a9:38:09:76:ca:f9:b7:5a: 32 a5:8a:6e:85:7f:27:34:79:82:ef:a2:01:93:ae:fa: 33 0b:18:47:d4:14:ff:67:78:2b:53:92:f6:ac:27:42: 34 c7:7f:8e:fd:06:4a:36:b9:7a:98:5e:0d:94:ef:1a: 35 fa:08:ad:8d:64:28:c7:c1:03:76:63:b9:33:5a:9f: 36 16:be:d3:e0:5c:e9:43:7b:9b:83:b3:90:31:e7:59: 37 2b:1c:d2:8c:73:15:a2:3a:94:35:03:80:97:f8:5d: 38 a3:13 39 Exponent: 65537 (0x10001) 40 X509v3 extensions: 41 X509v3 Subject Key Identifier: 42 5A:16:9C:06:85:B6:F4:77:AD:72:58:A2:4F:A1:FE:29:CF:97:8A:2B 43 X509v3 Authority Key Identifier: 44 keyid:24:B9:91:41:39:F1:30:5E:F8:C5:3B:C0:51:CC:11:58:A6:13:73:B3 45 46 Authority Information Access: 47 CA Issuers - URI:http://url-for-aia/Intermediate.cer 48 49 X509v3 CRL Distribution Points: 50 51 Full Name: 52 URI:http://url-for-crl/Intermediate.crl 53 54 X509v3 Key Usage: critical 55 Digital Signature, Key Encipherment 56 X509v3 Extended Key Usage: 57 TLS Web Client Authentication 58 Signature Algorithm: sha256WithRSAEncryption 59 1c:5f:11:a4:9a:79:cd:bf:20:c5:ac:53:19:8c:6c:19:57:0c: 60 58:fe:49:49:65:20:16:3d:04:32:e0:ec:32:92:cb:b2:15:2c: 61 d0:b0:3e:b9:72:bf:e5:4c:94:5e:29:04:36:f1:9e:af:5f:dc: 62 8f:da:e3:d4:c7:89:fc:e4:2b:d4:a4:e6:40:a5:db:61:c8:6c: 63 7a:4b:65:3c:31:d2:cd:08:92:2f:6c:47:95:e7:7e:b3:71:03: 64 5b:46:e7:bb:5a:79:37:e1:34:bb:d4:79:a1:58:fe:df:38:38: 65 21:ce:0d:85:5d:50:a0:1a:38:95:3c:63:bc:d0:71:af:89:29: 66 a0:be:1f:70:68:2f:f4:2c:4b:05:42:87:29:25:64:95:d1:40: 67 26:c5:51:4c:a5:29:79:fb:50:0e:11:48:c8:57:f5:9e:d8:69: 68 43:88:99:9a:e0:ef:71:38:60:8e:be:4d:59:f3:1f:64:6a:41: 69 20:68:ed:e4:e2:01:68:99:3d:8a:75:1b:bf:4a:ba:90:10:fb: 70 22:4a:4e:fc:d9:b9:98:f3:eb:a8:4e:13:c2:d1:87:8d:80:7e: 71 22:5e:fb:72:ff:ca:07:d6:31:76:60:c9:c2:4f:09:eb:ef:e8: 72 2b:e6:96:1e:87:08:0c:64:76:eb:af:d9:ca:b7:0f:d0:33:1c: 73 58:5f:53:aa 74-----BEGIN CERTIFICATE----- 75MIIDljCCAn6gAwIBAgIUUdITNbaKsjvNIhUDkwqyoCJN4VcwDQYJKoZIhvcNAQEL 76BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy 77MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF 78AAOCAQ8AMIIBCgKCAQEAw4ITZA41MwysRL5tkvXkl9iavWTxtWdiAXsMmFdKY2Sw 79nWp7hKKR/nMLTIHOifmNjYpBGMjYZCc2MuY2JkQWEy6hrTgGCxs5YmqUrKBZvlLL 80R9dLAAmRjhRpqWLfSdi2eXPeYNS4domkU4odS4CIMegFRoEbe11S0Gs7Uw0lPJWb 81LZmDPAOMtXP7Q2yCs0hXODz/t3nYE3QG0Bd4qTgJdsr5t1qlim6Ffyc0eYLvogGT 82rvoLGEfUFP9neCtTkvasJ0LHf479Bko2uXqYXg2U7xr6CK2NZCjHwQN2Y7kzWp8W 83vtPgXOlDe5uDs5Ax51krHNKMcxWiOpQ1A4CX+F2jEwIDAQABo4HfMIHcMB0GA1Ud 84DgQWBBRaFpwGhbb0d61yWKJPof4pz5eKKzAfBgNVHSMEGDAWgBQkuZFBOfEwXvjF 85O8BRzBFYphNzszA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91 86cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0 87dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF 88oDATBgNVHSUEDDAKBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAHF8RpJp5 89zb8gxaxTGYxsGVcMWP5JSWUgFj0EMuDsMpLLshUs0LA+uXK/5UyUXikENvGer1/c 90j9rj1MeJ/OQr1KTmQKXbYchsektlPDHSzQiSL2xHled+s3EDW0bnu1p5N+E0u9R5 91oVj+3zg4Ic4NhV1QoBo4lTxjvNBxr4kpoL4fcGgv9CxLBUKHKSVkldFAJsVRTKUp 92eftQDhFIyFf1nthpQ4iZmuDvcThgjr5NWfMfZGpBIGjt5OIBaJk9inUbv0q6kBD7 93IkpO/Nm5mPPrqE4TwtGHjYB+Il77cv/KB9YxdmDJwk8J6+/oK+aWHocIDGR266/Z 94yrcP0DMcWF9Tqg== 95-----END CERTIFICATE----- 96 97Certificate: 98 Data: 99 Version: 3 (0x2) 100 Serial Number: 101 21:b4:f1:0c:52:12:7e:ce:93:5e:dd:2d:2b:69:e9:bb:8c:4d:24:70 102 Signature Algorithm: sha256WithRSAEncryption 103 Issuer: CN=Root 104 Validity 105 Not Before: Oct 5 12:00:00 2021 GMT 106 Not After : Oct 5 12:00:00 2022 GMT 107 Subject: CN=Intermediate 108 Subject Public Key Info: 109 Public Key Algorithm: rsaEncryption 110 RSA Public-Key: (2048 bit) 111 Modulus: 112 00:ed:3b:bb:f2:8b:20:81:de:42:41:c6:24:63:1c: 113 4b:e5:63:b0:93:07:fd:22:64:50:7d:ef:8f:ed:65: 114 aa:ba:f4:d9:ad:0c:68:dd:50:b0:ea:0a:5e:18:9e: 115 df:48:88:ec:1f:fa:6b:4a:3e:db:ea:24:6e:b1:a3: 116 bb:0b:12:de:1d:49:d3:32:78:24:f9:e8:4f:aa:85: 117 90:21:a2:2c:8f:58:95:8c:70:80:8d:cd:99:68:03: 118 67:0f:48:eb:96:17:63:93:2b:8f:72:77:23:5f:97: 119 4f:86:bd:17:d2:70:5b:5c:18:f8:01:d6:11:d8:c0: 120 dc:32:b2:f4:bf:dd:da:65:fb:86:23:c0:a4:bd:ff: 121 c2:a4:b6:87:9e:10:98:d4:f4:09:cb:26:50:1d:56: 122 83:72:09:c6:c1:b7:cc:52:9c:61:09:04:bb:aa:2a: 123 63:66:a5:b1:02:60:85:bc:30:91:62:bb:6f:b0:24: 124 33:e8:b5:9a:13:1f:3a:73:95:d5:fb:bc:a9:48:dd: 125 14:a2:a4:62:e1:97:19:57:b1:1a:da:c1:79:93:fd: 126 74:cb:e1:ff:0c:49:c2:78:57:8e:ef:dc:df:60:96: 127 8e:e6:a2:97:60:b9:53:6b:17:8e:ae:f9:3d:be:31: 128 dd:46:18:bd:af:b6:a6:02:fa:48:2f:d8:c6:f0:1f: 129 bc:43 130 Exponent: 65537 (0x10001) 131 X509v3 extensions: 132 X509v3 Subject Key Identifier: 133 24:B9:91:41:39:F1:30:5E:F8:C5:3B:C0:51:CC:11:58:A6:13:73:B3 134 X509v3 Authority Key Identifier: 135 keyid:CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C 136 137 Authority Information Access: 138 CA Issuers - URI:http://url-for-aia/Root.cer 139 140 X509v3 CRL Distribution Points: 141 142 Full Name: 143 URI:http://url-for-crl/Root.crl 144 145 X509v3 Key Usage: critical 146 Certificate Sign, CRL Sign 147 X509v3 Basic Constraints: critical 148 CA:TRUE 149 Signature Algorithm: sha256WithRSAEncryption 150 40:30:80:b6:34:db:16:10:36:41:bd:52:25:3a:93:3b:2c:f9: 151 cd:54:5a:a0:4e:b7:49:aa:ab:54:c9:68:bd:dd:f2:8f:14:c6: 152 f1:8d:33:65:48:81:ef:8a:06:81:5d:be:8b:0d:6c:02:8d:a7: 153 7f:ab:5f:6f:67:78:7a:a4:85:f8:66:32:d7:6d:ae:7f:a9:3b: 154 61:37:01:cc:fd:f9:45:5a:21:2d:d8:2a:50:e7:d6:59:31:0d: 155 7b:4d:5e:fd:57:cc:ca:fd:77:48:3a:ac:cb:fe:41:8c:6c:9a: 156 3c:00:b3:63:8b:a0:56:bc:54:d8:de:50:c1:f7:0c:ea:3f:52: 157 11:ae:f3:c4:13:9c:99:52:02:3e:83:b9:38:c2:2c:a7:e5:85: 158 af:85:1f:b0:ff:2c:7c:85:14:d3:21:92:20:60:68:06:96:fb: 159 58:2e:f1:78:8d:a0:db:5a:4b:aa:27:0c:37:ef:28:46:35:28: 160 43:8c:88:99:36:68:ad:bc:b6:50:72:3c:f5:76:60:a6:df:70: 161 70:a3:80:d0:d0:1d:93:8c:ee:c1:c6:5a:51:ae:96:3d:88:dd: 162 ee:8e:35:0b:89:4e:0f:96:47:ff:b0:1e:8c:d5:11:e6:ba:3c: 163 0a:bc:bf:a4:8f:28:27:e6:44:d0:79:bc:b6:db:39:a5:96:90: 164 52:66:07:0e 165-----BEGIN CERTIFICATE----- 166MIIDgDCCAmigAwIBAgIUIbTxDFISfs6TXt0tK2npu4xNJHAwDQYJKoZIhvcNAQEL 167BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 168MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD 169ggEPADCCAQoCggEBAO07u/KLIIHeQkHGJGMcS+VjsJMH/SJkUH3vj+1lqrr02a0M 170aN1QsOoKXhie30iI7B/6a0o+2+okbrGjuwsS3h1J0zJ4JPnoT6qFkCGiLI9YlYxw 171gI3NmWgDZw9I65YXY5Mrj3J3I1+XT4a9F9JwW1wY+AHWEdjA3DKy9L/d2mX7hiPA 172pL3/wqS2h54QmNT0CcsmUB1Wg3IJxsG3zFKcYQkEu6oqY2alsQJghbwwkWK7b7Ak 173M+i1mhMfOnOV1fu8qUjdFKKkYuGXGVexGtrBeZP9dMvh/wxJwnhXju/c32CWjuai 174l2C5U2sXjq75Pb4x3UYYva+2pgL6SC/YxvAfvEMCAwEAAaOByzCByDAdBgNVHQ4E 175FgQUJLmRQTnxMF74xTvAUcwRWKYTc7MwHwYDVR0jBBgwFoAUzW9M/qp6OmNdEnlt 1769EywKop/+2wwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs 177LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m 178b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/ 179MA0GCSqGSIb3DQEBCwUAA4IBAQBAMIC2NNsWEDZBvVIlOpM7LPnNVFqgTrdJqqtU 180yWi93fKPFMbxjTNlSIHvigaBXb6LDWwCjad/q19vZ3h6pIX4ZjLXba5/qTthNwHM 181/flFWiEt2CpQ59ZZMQ17TV79V8zK/XdIOqzL/kGMbJo8ALNji6BWvFTY3lDB9wzq 182P1IRrvPEE5yZUgI+g7k4wiyn5YWvhR+w/yx8hRTTIZIgYGgGlvtYLvF4jaDbWkuq 183Jww37yhGNShDjIiZNmitvLZQcjz1dmCm33Bwo4DQ0B2TjO7BxlpRrpY9iN3ujjUL 184iU4Plkf/sB6M1RHmujwKvL+kjygn5kTQeby22zmllpBSZgcO 185-----END CERTIFICATE----- 186 187Certificate: 188 Data: 189 Version: 3 (0x2) 190 Serial Number: 191 21:b4:f1:0c:52:12:7e:ce:93:5e:dd:2d:2b:69:e9:bb:8c:4d:24:6f 192 Signature Algorithm: sha256WithRSAEncryption 193 Issuer: CN=Root 194 Validity 195 Not Before: Oct 5 12:00:00 2021 GMT 196 Not After : Oct 5 12:00:00 2022 GMT 197 Subject: CN=Root 198 Subject Public Key Info: 199 Public Key Algorithm: rsaEncryption 200 RSA Public-Key: (2048 bit) 201 Modulus: 202 00:e8:17:31:b6:0e:84:10:a4:9b:bf:9e:ae:9e:29: 203 b7:6f:81:ae:d7:df:45:89:d1:29:51:0e:1e:39:7a: 204 96:6b:7f:c0:78:df:88:cf:db:b3:ab:8d:49:0f:fb: 205 70:55:85:4f:93:9f:12:a1:a6:55:5c:a9:ae:8d:79: 206 4d:a6:3a:32:03:9c:bf:ad:95:c4:8b:49:1f:02:b5: 207 23:a0:9f:da:d3:45:c6:8c:fc:ec:97:46:57:dd:77: 208 56:c6:a2:46:78:da:a2:59:bb:22:ea:de:63:94:50: 209 19:91:1c:10:cd:67:e0:57:10:bd:e0:de:69:67:80: 210 6d:31:a8:43:bc:49:2c:8a:d6:4a:23:0f:a6:78:f4: 211 74:c7:4f:37:52:3a:af:9c:03:b2:b3:6c:26:ab:62: 212 61:12:6d:22:15:66:da:ec:d6:b8:1f:9b:14:b9:04: 213 9c:9b:5e:b5:cb:8b:62:95:67:6a:a1:57:44:02:77: 214 a2:81:3e:c7:20:52:a2:16:2e:ba:c2:29:a1:54:ed: 215 33:67:f2:2a:26:a3:b6:da:08:8d:63:6c:ca:4f:c6: 216 84:88:b9:60:08:cf:50:8e:5a:3e:75:d7:ec:d7:63: 217 c1:fe:18:3f:4e:fb:08:de:39:45:d2:81:34:8e:89: 218 5a:48:ce:49:bf:ca:84:cb:26:ac:c2:f7:1f:6b:3f: 219 0d:49 220 Exponent: 65537 (0x10001) 221 X509v3 extensions: 222 X509v3 Subject Key Identifier: 223 CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C 224 X509v3 Authority Key Identifier: 225 keyid:CD:6F:4C:FE:AA:7A:3A:63:5D:12:79:6D:F4:4C:B0:2A:8A:7F:FB:6C 226 227 Authority Information Access: 228 CA Issuers - URI:http://url-for-aia/Root.cer 229 230 X509v3 CRL Distribution Points: 231 232 Full Name: 233 URI:http://url-for-crl/Root.crl 234 235 X509v3 Key Usage: critical 236 Certificate Sign, CRL Sign 237 X509v3 Basic Constraints: critical 238 CA:TRUE 239 Signature Algorithm: sha256WithRSAEncryption 240 69:17:0f:f1:d9:f0:b5:69:62:e5:de:ca:bf:8d:84:d4:fa:1d: 241 f7:32:c2:b2:15:93:94:11:bf:af:de:72:63:43:61:b9:83:6d: 242 a4:ac:2a:68:b2:a5:c7:92:ed:69:96:8d:6d:9b:bf:5b:dc:1e: 243 6a:c4:e0:7b:00:35:7a:a7:44:74:95:16:92:72:2e:46:c7:fa: 244 25:e0:1b:46:dc:fd:53:e1:28:51:07:5e:01:9e:dc:03:a9:90: 245 d7:ed:25:f7:e6:82:1b:d2:32:3f:b7:d6:fa:75:62:d6:12:7d: 246 62:7f:d2:e6:fa:23:26:cd:a4:3c:bb:32:a0:2b:3f:15:3e:90: 247 57:21:04:9c:65:49:af:44:a8:44:8f:41:3d:92:b4:f8:80:39: 248 11:2e:1b:6a:a6:65:f3:31:5b:d1:cf:4f:6b:a9:39:56:8f:1d: 249 29:57:6c:d0:07:ae:4a:48:01:b7:2f:0e:ce:1b:49:46:72:2b: 250 28:70:34:ba:c0:88:01:11:0e:0f:85:65:b2:09:79:7b:d1:83: 251 94:65:d3:d2:ef:ac:58:af:0b:fb:f3:ad:e1:d9:9d:c8:48:42: 252 0b:8d:f4:40:d6:a7:12:82:cc:0c:34:a3:9e:d0:08:99:50:97: 253 51:65:d5:e1:ce:d4:a7:89:88:46:50:64:b1:d3:47:c6:0b:86: 254 65:d6:3b:18 255-----BEGIN CERTIFICATE----- 256MIIDeDCCAmCgAwIBAgIUIbTxDFISfs6TXt0tK2npu4xNJG8wDQYJKoZIhvcNAQEL 257BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw 258MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK 259AoIBAQDoFzG2DoQQpJu/nq6eKbdvga7X30WJ0SlRDh45epZrf8B434jP27OrjUkP 260+3BVhU+TnxKhplVcqa6NeU2mOjIDnL+tlcSLSR8CtSOgn9rTRcaM/OyXRlfdd1bG 261okZ42qJZuyLq3mOUUBmRHBDNZ+BXEL3g3mlngG0xqEO8SSyK1kojD6Z49HTHTzdS 262Oq+cA7KzbCarYmESbSIVZtrs1rgfmxS5BJybXrXLi2KVZ2qhV0QCd6KBPscgUqIW 263LrrCKaFU7TNn8iomo7baCI1jbMpPxoSIuWAIz1COWj511+zXY8H+GD9O+wjeOUXS 264gTSOiVpIzkm/yoTLJqzC9x9rPw1JAgMBAAGjgcswgcgwHQYDVR0OBBYEFM1vTP6q 265ejpjXRJ5bfRMsCqKf/tsMB8GA1UdIwQYMBaAFM1vTP6qejpjXRJ5bfRMsCqKf/ts 266MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh 267L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S 268b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG 2699w0BAQsFAAOCAQEAaRcP8dnwtWli5d7Kv42E1Pod9zLCshWTlBG/r95yY0NhuYNt 270pKwqaLKlx5LtaZaNbZu/W9weasTgewA1eqdEdJUWknIuRsf6JeAbRtz9U+EoUQde 271AZ7cA6mQ1+0l9+aCG9IyP7fW+nVi1hJ9Yn/S5vojJs2kPLsyoCs/FT6QVyEEnGVJ 272r0SoRI9BPZK0+IA5ES4baqZl8zFb0c9Pa6k5Vo8dKVds0AeuSkgBty8OzhtJRnIr 273KHA0usCIAREOD4Vlsgl5e9GDlGXT0u+sWK8L+/Ot4dmdyEhCC430QNanEoLMDDSj 274ntAImVCXUWXV4c7Up4mIRlBksdNHxguGZdY7GA== 275-----END CERTIFICATE----- 276