1[Created by: ./generate-chains.py]
2
3Certificate chain where the target certificate contains an unknown X.509v3
4extension (OID=1.2.3.4) that is marked as critical.
5
6Certificate:
7    Data:
8        Version: 3 (0x2)
9        Serial Number:
10            4e:9a:ac:ff:32:38:c0:2f:b6:e5:63:63:94:45:6d:aa:aa:c4:b6:e5
11        Signature Algorithm: sha256WithRSAEncryption
12        Issuer: CN=Intermediate
13        Validity
14            Not Before: Oct  5 12:00:00 2021 GMT
15            Not After : Oct  5 12:00:00 2022 GMT
16        Subject: CN=Target
17        Subject Public Key Info:
18            Public Key Algorithm: rsaEncryption
19                Public-Key: (2048 bit)
20                Modulus:
21                    00:bd:05:ea:3a:1c:14:a1:db:ad:2c:18:3d:25:9c:
22                    dc:1c:0f:2b:1e:42:df:c2:7c:b4:39:e6:4b:45:eb:
23                    d3:a2:1c:2b:dc:f2:8c:08:f5:81:df:bd:fa:a2:1a:
24                    1c:5c:99:cb:00:c7:31:02:c8:44:5f:31:cf:9c:82:
25                    6d:3c:0c:5d:f7:d6:cc:91:fe:f3:e7:7a:08:17:85:
26                    d5:75:61:ee:dd:66:55:3c:e2:68:98:36:19:20:e4:
27                    9b:cd:24:6c:a3:5d:89:84:80:2e:c7:11:4e:c1:82:
28                    b2:80:ce:0f:e9:6a:42:54:10:fb:c0:0a:53:be:19:
29                    01:38:ba:06:c5:93:93:1c:84:aa:25:c7:c5:9a:4d:
30                    32:2e:a4:13:5e:6d:07:d6:9d:e5:b0:29:63:da:14:
31                    b7:62:51:63:93:dc:28:ae:4a:bc:35:ac:c0:06:ea:
32                    ea:0b:d5:70:61:3b:05:78:e4:d3:ad:c3:ad:95:f1:
33                    48:e5:79:a6:dc:12:1f:14:4f:21:9f:ca:6f:7a:dd:
34                    d6:45:c8:8a:60:96:1c:02:06:16:18:80:21:58:6a:
35                    f6:83:3e:1a:98:b8:b2:a9:22:44:c2:25:e9:dc:a9:
36                    aa:bf:1d:2e:3f:2e:a1:78:08:93:04:4c:c4:1f:f9:
37                    b3:34:9f:a7:78:5b:02:a6:ca:d3:1f:fa:ba:4d:34:
38                    a2:bb
39                Exponent: 65537 (0x10001)
40        X509v3 extensions:
41            X509v3 Subject Key Identifier:
42                D6:55:4E:AC:07:84:35:A9:0D:9A:63:45:82:73:4E:A4:CC:53:B0:02
43            X509v3 Authority Key Identifier:
44                8A:E3:E6:F6:58:6F:1C:90:B4:67:A5:14:D8:64:E7:F7:00:77:61:01
45            Authority Information Access:
46                CA Issuers - URI:http://url-for-aia/Intermediate.cer
47            X509v3 CRL Distribution Points:
48                Full Name:
49                  URI:http://url-for-crl/Intermediate.crl
50            X509v3 Key Usage: critical
51                Digital Signature, Key Encipherment
52            X509v3 Extended Key Usage:
53                TLS Web Server Authentication, TLS Web Client Authentication
54            1.2.3.4: critical
55                ....
56    Signature Algorithm: sha256WithRSAEncryption
57    Signature Value:
58        2d:da:b3:73:a9:3c:2f:ac:6f:a6:db:80:c2:82:ea:0f:6e:bd:
59        58:35:f5:d5:69:3f:73:26:e6:80:cd:39:d1:cf:38:f8:19:dd:
60        f7:cf:57:70:44:3b:83:5a:8d:91:7b:02:a9:e8:ef:06:1e:b6:
61        4b:97:ff:0e:96:ee:fe:85:ea:b4:93:ba:0e:b1:15:ef:ff:f6:
62        be:0d:f2:2a:d6:2d:df:43:a9:e8:a0:e3:50:bb:56:af:51:05:
63        1d:50:f3:58:f4:41:f0:ea:b4:1e:34:99:ac:d5:b8:34:78:96:
64        73:2e:62:e5:7e:b5:1d:e4:08:52:b4:8f:28:bf:b7:75:23:71:
65        f2:31:b2:ad:eb:4c:94:ec:79:09:0c:8b:94:38:a8:c8:82:e8:
66        42:e4:72:50:bc:4b:8e:0d:e8:c0:77:a7:94:8e:d4:35:36:73:
67        d4:1e:32:8f:19:14:8e:eb:26:61:bb:c9:9c:b5:71:08:40:61:
68        52:8f:1e:a3:3d:01:2c:c8:a5:b5:c7:ac:42:ee:75:2b:a2:e7:
69        77:65:98:1d:02:1c:95:d3:8a:1d:17:71:82:86:5c:f3:a9:44:
70        e0:54:c5:51:84:b4:3c:c9:f1:bd:25:2d:cb:23:f2:72:d2:8c:
71        f9:2d:c5:2a:4b:14:f5:df:65:53:e5:fb:2e:71:02:03:c5:6e:
72        6f:0a:68:69
73-----BEGIN CERTIFICATE-----
74MIIDsDCCApigAwIBAgIUTpqs/zI4wC+25WNjlEVtqqrEtuUwDQYJKoZIhvcNAQEL
75BQAwFzEVMBMGA1UEAwwMSW50ZXJtZWRpYXRlMB4XDTIxMTAwNTEyMDAwMFoXDTIy
76MTAwNTEyMDAwMFowETEPMA0GA1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEF
77AAOCAQ8AMIIBCgKCAQEAvQXqOhwUodutLBg9JZzcHA8rHkLfwny0OeZLRevTohwr
783PKMCPWB3736ohocXJnLAMcxAshEXzHPnIJtPAxd99bMkf7z53oIF4XVdWHu3WZV
79POJomDYZIOSbzSRso12JhIAuxxFOwYKygM4P6WpCVBD7wApTvhkBOLoGxZOTHISq
80JcfFmk0yLqQTXm0H1p3lsClj2hS3YlFjk9workq8NazABurqC9VwYTsFeOTTrcOt
81lfFI5Xmm3BIfFE8hn8pvet3WRciKYJYcAgYWGIAhWGr2gz4amLiyqSJEwiXp3Kmq
82vx0uPy6heAiTBEzEH/mzNJ+neFsCpsrTH/q6TTSiuwIDAQABo4H5MIH2MB0GA1Ud
83DgQWBBTWVU6sB4Q1qQ2aY0WCc06kzFOwAjAfBgNVHSMEGDAWgBSK4+b2WG8ckLRn
84pRTYZOf3AHdhATA/BggrBgEFBQcBAQQzMDEwLwYIKwYBBQUHMAKGI2h0dHA6Ly91
85cmwtZm9yLWFpYS9JbnRlcm1lZGlhdGUuY2VyMDQGA1UdHwQtMCswKaAnoCWGI2h0
86dHA6Ly91cmwtZm9yLWNybC9JbnRlcm1lZGlhdGUuY3JsMA4GA1UdDwEB/wQEAwIF
87oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDgYDKgMEAQH/BAQBAgME
88MA0GCSqGSIb3DQEBCwUAA4IBAQAt2rNzqTwvrG+m24DCguoPbr1YNfXVaT9zJuaA
89zTnRzzj4Gd33z1dwRDuDWo2RewKp6O8GHrZLl/8Olu7+heq0k7oOsRXv//a+DfIq
901i3fQ6nooONQu1avUQUdUPNY9EHw6rQeNJms1bg0eJZzLmLlfrUd5AhStI8ov7d1
91I3HyMbKt60yU7HkJDIuUOKjIguhC5HJQvEuODejAd6eUjtQ1NnPUHjKPGRSO6yZh
92u8mctXEIQGFSjx6jPQEsyKW1x6xC7nUroud3ZZgdAhyV04odF3GChlzzqUTgVMVR
93hLQ8yfG9JS3LI/Jy0oz5LcUqSxT132VT5fsucQIDxW5vCmhp
94-----END CERTIFICATE-----
95
96Certificate:
97    Data:
98        Version: 3 (0x2)
99        Serial Number:
100            06:66:51:84:c2:7e:fc:0c:cf:05:27:4c:bc:d3:55:23:ed:cb:19:f9
101        Signature Algorithm: sha256WithRSAEncryption
102        Issuer: CN=Root
103        Validity
104            Not Before: Oct  5 12:00:00 2021 GMT
105            Not After : Oct  5 12:00:00 2022 GMT
106        Subject: CN=Intermediate
107        Subject Public Key Info:
108            Public Key Algorithm: rsaEncryption
109                Public-Key: (2048 bit)
110                Modulus:
111                    00:b8:cf:91:dd:b5:74:07:ba:8a:93:3c:ca:0c:11:
112                    5d:36:29:ec:53:1e:32:8b:90:ae:f9:c0:db:d2:7e:
113                    78:ea:3c:58:57:5f:70:4a:96:9a:93:58:d3:7e:42:
114                    60:bd:78:07:38:6b:e4:16:8f:32:17:30:b1:76:95:
115                    56:6d:7e:e5:9e:f9:0f:f8:5a:99:ee:80:e1:e6:fc:
116                    d6:af:33:61:aa:da:19:98:7f:da:27:2f:80:bc:96:
117                    2e:51:81:f8:1a:63:27:0b:ce:ee:02:16:55:4a:96:
118                    0a:c5:c1:7e:99:95:e8:70:e7:4d:2b:2f:bf:d3:d2:
119                    2d:25:7d:0f:b2:50:96:36:95:e5:2c:ca:0e:59:b5:
120                    d4:7c:31:57:96:fa:be:c6:d5:9a:83:b5:96:f2:1c:
121                    4a:20:cf:be:0e:7f:42:4f:a7:b4:5b:e2:01:f4:ed:
122                    59:c4:6e:51:a1:a5:aa:a7:1f:04:ce:e0:d2:2c:ff:
123                    a3:74:c7:e4:2a:a8:d2:7f:cd:f1:56:86:67:fe:75:
124                    22:05:f7:2d:3b:3b:ce:5c:b9:95:4e:e5:ca:d8:89:
125                    f6:b3:12:27:b4:22:6b:fb:83:f9:0e:de:a8:be:38:
126                    5b:15:66:81:3b:62:d7:50:12:29:69:5b:c5:5a:99:
127                    97:aa:51:c3:36:88:97:c9:c1:90:53:4f:b3:ec:99:
128                    3c:f3
129                Exponent: 65537 (0x10001)
130        X509v3 extensions:
131            X509v3 Subject Key Identifier:
132                8A:E3:E6:F6:58:6F:1C:90:B4:67:A5:14:D8:64:E7:F7:00:77:61:01
133            X509v3 Authority Key Identifier:
134                52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
135            Authority Information Access:
136                CA Issuers - URI:http://url-for-aia/Root.cer
137            X509v3 CRL Distribution Points:
138                Full Name:
139                  URI:http://url-for-crl/Root.crl
140            X509v3 Key Usage: critical
141                Certificate Sign, CRL Sign
142            X509v3 Basic Constraints: critical
143                CA:TRUE
144    Signature Algorithm: sha256WithRSAEncryption
145    Signature Value:
146        03:01:bd:9d:2d:b0:21:65:4d:11:4b:8d:72:4a:45:c5:cf:0a:
147        b3:df:9c:a4:0a:2c:c0:10:61:ce:91:c2:79:ef:f8:90:9e:66:
148        aa:ba:b0:2a:05:bf:76:8d:4d:1b:43:ff:cd:24:d7:79:f9:49:
149        73:25:6b:47:d8:3a:59:ab:fa:da:11:5e:7e:ce:bb:07:21:e4:
150        ea:30:b5:14:b6:34:36:f9:b4:94:ec:31:ae:1f:f2:02:96:68:
151        6b:d2:3c:ce:29:7f:0d:af:35:c5:a7:c3:1c:75:b3:c8:04:96:
152        7b:3e:b7:10:fa:25:00:8e:f4:f3:65:46:fc:09:5c:19:c4:69:
153        56:44:49:1f:db:04:09:04:0b:3e:72:fb:f8:ac:d6:23:31:ec:
154        37:70:fa:8b:db:d1:80:25:1f:44:68:ff:48:e0:c2:c0:8e:9d:
155        02:ee:ff:e3:b6:ac:22:1f:7e:c4:59:94:f7:06:05:19:23:ff:
156        4a:c9:16:99:94:3e:2e:ba:86:6c:01:31:01:1d:17:2c:f7:0b:
157        5c:02:8a:2d:28:73:a7:81:b9:8f:91:f7:a3:0b:2a:16:98:e7:
158        8d:5c:31:95:48:59:ce:1b:7e:2b:8c:79:1e:c1:27:11:20:07:
159        83:ad:b5:1c:aa:77:57:7e:bb:13:19:52:6a:13:6b:5d:32:bf:
160        2a:26:5b:5c
161-----BEGIN CERTIFICATE-----
162MIIDgDCCAmigAwIBAgIUBmZRhMJ+/AzPBSdMvNNVI+3LGfkwDQYJKoZIhvcNAQEL
163BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
164MDBaMBcxFTATBgNVBAMMDEludGVybWVkaWF0ZTCCASIwDQYJKoZIhvcNAQEBBQAD
165ggEPADCCAQoCggEBALjPkd21dAe6ipM8ygwRXTYp7FMeMouQrvnA29J+eOo8WFdf
166cEqWmpNY035CYL14Bzhr5BaPMhcwsXaVVm1+5Z75D/hame6A4eb81q8zYaraGZh/
1672icvgLyWLlGB+BpjJwvO7gIWVUqWCsXBfpmV6HDnTSsvv9PSLSV9D7JQljaV5SzK
168Dlm11HwxV5b6vsbVmoO1lvIcSiDPvg5/Qk+ntFviAfTtWcRuUaGlqqcfBM7g0iz/
169o3TH5Cqo0n/N8VaGZ/51IgX3LTs7zly5lU7lytiJ9rMSJ7Qia/uD+Q7eqL44WxVm
170gTti11ASKWlbxVqZl6pRwzaIl8nBkFNPs+yZPPMCAwEAAaOByzCByDAdBgNVHQ4E
171FgQUiuPm9lhvHJC0Z6UU2GTn9wB3YQEwHwYDVR0jBBgwFoAUUgCkvotfI2NeMQWH
1729GtQpwFwY9owNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJs
173LWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1m
174b3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/
175MA0GCSqGSIb3DQEBCwUAA4IBAQADAb2dLbAhZU0RS41ySkXFzwqz35ykCizAEGHO
176kcJ57/iQnmaqurAqBb92jU0bQ//NJNd5+UlzJWtH2DpZq/raEV5+zrsHIeTqMLUU
177tjQ2+bSU7DGuH/IClmhr0jzOKX8NrzXFp8McdbPIBJZ7PrcQ+iUAjvTzZUb8CVwZ
178xGlWREkf2wQJBAs+cvv4rNYjMew3cPqL29GAJR9EaP9I4MLAjp0C7v/jtqwiH37E
179WZT3BgUZI/9KyRaZlD4uuoZsATEBHRcs9wtcAootKHOngbmPkfejCyoWmOeNXDGV
180SFnOG34rjHkewScRIAeDrbUcqndXfrsTGVJqE2tdMr8qJltc
181-----END CERTIFICATE-----
182
183Certificate:
184    Data:
185        Version: 3 (0x2)
186        Serial Number:
187            06:66:51:84:c2:7e:fc:0c:cf:05:27:4c:bc:d3:55:23:ed:cb:19:f8
188        Signature Algorithm: sha256WithRSAEncryption
189        Issuer: CN=Root
190        Validity
191            Not Before: Oct  5 12:00:00 2021 GMT
192            Not After : Oct  5 12:00:00 2022 GMT
193        Subject: CN=Root
194        Subject Public Key Info:
195            Public Key Algorithm: rsaEncryption
196                Public-Key: (2048 bit)
197                Modulus:
198                    00:c0:8e:83:7c:7e:0c:6a:e8:93:2c:f8:e6:80:17:
199                    e6:2a:91:f2:1d:1a:b1:51:6e:3e:4d:96:bd:a1:29:
200                    f3:bd:ce:46:17:dc:5f:ed:b7:33:d8:17:31:80:b1:
201                    12:f3:bb:86:1d:4a:a7:61:dd:51:15:a8:9d:50:25:
202                    4f:93:5b:8c:a6:43:30:a5:46:7e:80:74:51:17:66:
203                    61:ba:c0:9d:f5:53:e4:4d:02:58:a4:27:ac:ef:35:
204                    eb:01:e6:0d:0f:a2:67:b3:95:1d:33:d3:70:55:6d:
205                    73:80:dd:c7:dc:21:c6:58:9a:7d:cb:e6:9d:e2:af:
206                    7f:14:02:7c:f8:45:ff:5c:74:7a:7d:b1:35:1f:74:
207                    0f:e7:0d:97:51:58:15:41:07:fa:12:99:2a:84:92:
208                    48:9b:08:ee:ad:26:37:15:3e:7e:7b:b6:1e:94:36:
209                    be:b9:d8:b6:6f:27:71:13:d1:3e:b7:9e:9d:d6:1e:
210                    e1:cb:7b:2b:ab:20:46:e0:08:9c:54:5b:c6:db:c2:
211                    57:d3:67:ee:00:cf:d2:cb:0b:64:31:a7:9c:97:f5:
212                    4b:37:db:7d:d5:dd:91:a7:ed:dc:0c:2f:9c:04:42:
213                    50:46:8a:59:d2:9c:10:d7:0c:25:d9:79:de:e1:4c:
214                    3d:4a:5a:3f:2c:6c:20:a1:60:9f:24:69:1a:0a:f9:
215                    6e:79
216                Exponent: 65537 (0x10001)
217        X509v3 extensions:
218            X509v3 Subject Key Identifier:
219                52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
220            X509v3 Authority Key Identifier:
221                52:00:A4:BE:8B:5F:23:63:5E:31:05:87:F4:6B:50:A7:01:70:63:DA
222            Authority Information Access:
223                CA Issuers - URI:http://url-for-aia/Root.cer
224            X509v3 CRL Distribution Points:
225                Full Name:
226                  URI:http://url-for-crl/Root.crl
227            X509v3 Key Usage: critical
228                Certificate Sign, CRL Sign
229            X509v3 Basic Constraints: critical
230                CA:TRUE
231    Signature Algorithm: sha256WithRSAEncryption
232    Signature Value:
233        8c:cc:8d:39:d4:a7:3f:73:9f:db:20:71:ed:d6:e0:94:76:4f:
234        ce:d3:05:24:82:bf:31:94:30:bd:7a:77:88:09:95:0e:79:79:
235        20:48:59:6a:3c:a6:a0:f3:3b:54:f0:3c:af:83:3d:22:a1:07:
236        7a:5b:f0:16:97:b8:ee:a4:d5:5a:f4:1e:89:e5:d3:fb:d0:b2:
237        cc:81:13:65:57:0f:2c:52:cc:b2:8b:a6:2d:b0:eb:e6:4e:12:
238        ae:31:e4:5a:5c:c4:65:33:8d:3b:fe:55:c5:65:74:80:92:25:
239        ef:e3:25:92:f1:b2:90:3f:59:c0:94:0b:fb:26:d8:4e:2f:21:
240        b2:69:7c:37:fd:28:36:b5:10:c8:04:46:28:3e:ff:5e:39:74:
241        50:4d:59:ab:a2:75:bf:ad:78:3a:b2:b6:0c:37:21:78:0f:8c:
242        73:b8:cc:36:02:ba:5f:1c:eb:c5:7b:77:c5:50:9e:3b:7e:17:
243        ce:17:73:50:d0:4c:46:86:f8:0c:d9:d1:eb:bb:3f:e7:f3:6e:
244        09:27:49:0b:8f:70:2e:64:8b:15:2e:f2:16:a2:fe:0f:01:87:
245        45:b8:2d:a3:a9:e2:5b:0c:f0:e8:79:db:cd:30:45:86:4e:49:
246        e7:37:38:b8:71:28:92:3a:0e:ac:1c:81:25:d7:d3:1a:c8:e5:
247        1d:47:8d:5b
248-----BEGIN CERTIFICATE-----
249MIIDeDCCAmCgAwIBAgIUBmZRhMJ+/AzPBSdMvNNVI+3LGfgwDQYJKoZIhvcNAQEL
250BQAwDzENMAsGA1UEAwwEUm9vdDAeFw0yMTEwMDUxMjAwMDBaFw0yMjEwMDUxMjAw
251MDBaMA8xDTALBgNVBAMMBFJvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
252AoIBAQDAjoN8fgxq6JMs+OaAF+YqkfIdGrFRbj5Nlr2hKfO9zkYX3F/ttzPYFzGA
253sRLzu4YdSqdh3VEVqJ1QJU+TW4ymQzClRn6AdFEXZmG6wJ31U+RNAlikJ6zvNesB
2545g0PomezlR0z03BVbXOA3cfcIcZYmn3L5p3ir38UAnz4Rf9cdHp9sTUfdA/nDZdR
255WBVBB/oSmSqEkkibCO6tJjcVPn57th6UNr652LZvJ3ET0T63np3WHuHLeyurIEbg
256CJxUW8bbwlfTZ+4Az9LLC2Qxp5yX9Us3233V3ZGn7dwML5wEQlBGilnSnBDXDCXZ
257ed7hTD1KWj8sbCChYJ8kaRoK+W55AgMBAAGjgcswgcgwHQYDVR0OBBYEFFIApL6L
258XyNjXjEFh/RrUKcBcGPaMB8GA1UdIwQYMBaAFFIApL6LXyNjXjEFh/RrUKcBcGPa
259MDcGCCsGAQUFBwEBBCswKTAnBggrBgEFBQcwAoYbaHR0cDovL3VybC1mb3ItYWlh
260L1Jvb3QuY2VyMCwGA1UdHwQlMCMwIaAfoB2GG2h0dHA6Ly91cmwtZm9yLWNybC9S
261b290LmNybDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
2629w0BAQsFAAOCAQEAjMyNOdSnP3Of2yBx7dbglHZPztMFJIK/MZQwvXp3iAmVDnl5
263IEhZajymoPM7VPA8r4M9IqEHelvwFpe47qTVWvQeieXT+9CyzIETZVcPLFLMsoum
264LbDr5k4SrjHkWlzEZTONO/5VxWV0gJIl7+MlkvGykD9ZwJQL+ybYTi8hsml8N/0o
265NrUQyARGKD7/Xjl0UE1Zq6J1v614OrK2DDcheA+Mc7jMNgK6XxzrxXt3xVCeO34X
266zhdzUNBMRob4DNnR67s/5/NuCSdJC49wLmSLFS7yFqL+DwGHRbgto6niWwzw6Hnb
267zTBFhk5J5zc4uHEokjoOrByBJdfTGsjlHUeNWw==
268-----END CERTIFICATE-----
269