| OLD | NEW |
| (Empty) | |
| 1 [Created by: generate-target-signed-by-512bit-rsa.py] |
| 2 |
| 3 Certificate chain with 1 intermediary. The target certificate |
| 4 is signed using a weak RSA key (512-bit modulus) |
| 5 |
| 6 Certificate: |
| 7 Data: |
| 8 Version: 3 (0x2) |
| 9 Serial Number: 1 (0x1) |
| 10 Signature Algorithm: sha256WithRSAEncryption |
| 11 Issuer: CN=Intermediary |
| 12 Validity |
| 13 Not Before: Jan 1 12:00:00 2015 GMT |
| 14 Not After : Jan 1 12:00:00 2016 GMT |
| 15 Subject: CN=Target |
| 16 Subject Public Key Info: |
| 17 Public Key Algorithm: rsaEncryption |
| 18 Public-Key: (2048 bit) |
| 19 Modulus: |
| 20 00:ca:10:3e:cf:ee:e8:57:a8:4a:4b:80:03:ff:b0: |
| 21 70:c3:03:80:ec:a9:15:d6:94:6c:b6:f0:02:31:1a: |
| 22 52:49:95:14:ba:10:52:36:8a:cd:36:37:8f:3f:2a: |
| 23 74:5f:ac:38:a5:d2:dd:35:2e:ee:e4:47:7f:5d:f7: |
| 24 6a:26:4e:a0:33:ca:46:ba:18:71:76:94:22:ba:ae: |
| 25 b0:ea:62:ca:36:63:d9:4e:5e:18:e0:fc:1a:9d:e6: |
| 26 04:52:75:71:b2:7e:24:91:81:be:74:c9:4f:e6:ca: |
| 27 d4:77:cf:28:29:07:73:1b:3b:55:83:d5:73:10:fb: |
| 28 96:ec:12:46:b1:26:fb:06:5f:b2:84:16:de:04:36: |
| 29 30:be:99:af:23:e3:6f:be:63:6c:fd:0c:62:6d:8c: |
| 30 29:43:9b:79:26:0d:7c:f0:38:e8:19:1b:4d:57:63: |
| 31 0e:2e:6b:e6:f7:61:d7:6b:cc:3a:f1:76:b0:da:8b: |
| 32 21:f2:a3:97:78:f9:d8:76:97:80:b9:34:8e:1c:27: |
| 33 ef:48:22:c5:ac:a3:ac:b3:cc:3b:54:dc:67:c6:e8: |
| 34 18:7b:8c:f0:8c:e3:e8:6b:9e:5f:17:eb:bc:3c:79: |
| 35 03:5e:c3:17:d2:26:49:97:3f:ba:6c:64:f5:9e:8e: |
| 36 98:25:2d:98:05:1a:6f:f1:5c:5e:8e:d1:04:50:41: |
| 37 8f:e9 |
| 38 Exponent: 65537 (0x10001) |
| 39 X509v3 extensions: |
| 40 X509v3 Subject Key Identifier: |
| 41 80:48:02:46:1D:D2:6B:B6:90:3A:D9:CA:9A:51:6E:B8:EA:06:9D:23 |
| 42 X509v3 Authority Key Identifier: |
| 43 keyid:4E:20:FE:20:6A:E4:2E:EE:8D:23:B4:13:86:17:6D:9A:66:47:4B:8
1 |
| 44 |
| 45 Authority Information Access: |
| 46 CA Issuers - URI:http://url-for-aia/Intermediary.cer |
| 47 |
| 48 X509v3 CRL Distribution Points: |
| 49 |
| 50 Full Name: |
| 51 URI:http://url-for-crl/Intermediary.crl |
| 52 |
| 53 X509v3 Key Usage: critical |
| 54 Digital Signature, Key Encipherment |
| 55 X509v3 Extended Key Usage: |
| 56 TLS Web Server Authentication, TLS Web Client Authentication |
| 57 Signature Algorithm: sha256WithRSAEncryption |
| 58 a9:8b:48:ed:b6:51:5c:5c:36:b7:8b:ff:64:76:94:f1:8f:b4: |
| 59 8a:a0:96:47:76:5d:dc:84:11:0c:ae:1b:29:d7:de:58:85:46: |
| 60 d9:bd:10:91:0f:bb:c0:99:bc:ef:9f:7f:65:31:21:a4:f5:e0: |
| 61 db:e9:5c:3e:fa:71:8d:24:3d:e9 |
| 62 -----BEGIN CERTIFICATE----- |
| 63 MIICyzCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl |
| 64 cm1lZGlhcnkwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD |
| 65 VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDKED7P |
| 66 7uhXqEpLgAP/sHDDA4DsqRXWlGy28AIxGlJJlRS6EFI2is02N48/KnRfrDil0t01 |
| 67 Lu7kR39d92omTqAzyka6GHF2lCK6rrDqYso2Y9lOXhjg/Bqd5gRSdXGyfiSRgb50 |
| 68 yU/mytR3zygpB3MbO1WD1XMQ+5bsEkaxJvsGX7KEFt4ENjC+ma8j42++Y2z9DGJt |
| 69 jClDm3kmDXzwOOgZG01XYw4ua+b3YddrzDrxdrDaiyHyo5d4+dh2l4C5NI4cJ+9I |
| 70 IsWso6yzzDtU3GfG6Bh7jPCM4+hrnl8X67w8eQNewxfSJkmXP7psZPWejpglLZgF |
| 71 Gm/xXF6O0QRQQY/pAgMBAAGjgekwgeYwHQYDVR0OBBYEFIBIAkYd0mu2kDrZyppR |
| 72 brjqBp0jMB8GA1UdIwQYMBaAFE4g/iBq5C7ujSO0E4YXbZpmR0uBMD8GCCsGAQUF |
| 73 BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk |
| 74 aWFyeS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu |
| 75 dGVybWVkaWFyeS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF |
| 76 BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAANBAKmLSO22UVxcNreL/2R2lPGP |
| 77 tIqglkd2XdyEEQyuGynX3liFRtm9EJEPu8CZvO+ff2UxIaT14NvpXD76cY0kPek= |
| 78 -----END CERTIFICATE----- |
| 79 |
| 80 Certificate: |
| 81 Data: |
| 82 Version: 3 (0x2) |
| 83 Serial Number: 2 (0x2) |
| 84 Signature Algorithm: sha256WithRSAEncryption |
| 85 Issuer: CN=Root |
| 86 Validity |
| 87 Not Before: Jan 1 12:00:00 2015 GMT |
| 88 Not After : Jan 1 12:00:00 2016 GMT |
| 89 Subject: CN=Intermediary |
| 90 Subject Public Key Info: |
| 91 Public Key Algorithm: rsaEncryption |
| 92 Public-Key: (512 bit) |
| 93 Modulus: |
| 94 00:b6:6f:fa:f8:27:9c:43:68:d0:dd:c9:6e:cd:56: |
| 95 2b:34:4c:fe:89:3e:8a:76:ed:0a:53:2a:a2:ff:85: |
| 96 ec:9c:88:72:b7:8c:64:31:31:d6:30:cc:f3:e1:1a: |
| 97 f3:ba:e2:f2:80:4c:2c:e2:16:24:e3:2c:2c:9b:4c: |
| 98 f5:82:86:35:db |
| 99 Exponent: 65537 (0x10001) |
| 100 X509v3 extensions: |
| 101 X509v3 Subject Key Identifier: |
| 102 4E:20:FE:20:6A:E4:2E:EE:8D:23:B4:13:86:17:6D:9A:66:47:4B:81 |
| 103 X509v3 Authority Key Identifier: |
| 104 keyid:16:B5:C9:50:1F:6E:98:6B:7D:33:56:2F:52:20:33:1E:C9:44:C0:E
8 |
| 105 |
| 106 Authority Information Access: |
| 107 CA Issuers - URI:http://url-for-aia/Root.cer |
| 108 |
| 109 X509v3 CRL Distribution Points: |
| 110 |
| 111 Full Name: |
| 112 URI:http://url-for-crl/Root.crl |
| 113 |
| 114 X509v3 Key Usage: critical |
| 115 Certificate Sign, CRL Sign |
| 116 X509v3 Basic Constraints: critical |
| 117 CA:TRUE |
| 118 Signature Algorithm: sha256WithRSAEncryption |
| 119 9e:13:bf:0b:f8:09:17:18:22:f3:09:44:8a:41:71:23:46:cc: |
| 120 72:ac:ba:96:9a:2c:70:80:7a:ca:e0:66:11:77:92:bb:63:05: |
| 121 c7:95:c5:2d:ad:1b:f3:c6:7c:14:5a:e0:25:06:a3:ad:c8:41: |
| 122 cf:23:69:61:bb:b6:2c:eb:80:f6:01:af:e2:81:16:0c:2b:c2: |
| 123 b7:e9:6e:f9:b4:01:a9:72:61:76:9f:91:96:1e:ce:85:ae:31: |
| 124 0f:59:9d:2f:ef:11:c2:e0:79:b3:dd:17:e8:3f:3f:78:2f:9a: |
| 125 2a:cd:b7:c9:06:f7:03:93:c6:26:2d:44:36:3b:71:17:88:3c: |
| 126 c5:3c:d5:b1:5e:05:e7:ca:be:e9:bc:98:fb:e0:92:41:82:9a: |
| 127 7a:df:49:4e:b4:25:bf:e3:9c:4a:d8:0a:4f:bc:2a:bc:4b:5d: |
| 128 50:91:ad:be:a5:6f:78:3a:6a:fa:67:6b:91:3f:30:21:05:50: |
| 129 28:fe:71:db:3a:19:25:80:66:fa:af:dc:12:eb:fe:bb:03:22: |
| 130 59:88:34:b4:3a:5a:6c:37:0c:91:f7:5f:10:83:e9:f4:04:ad: |
| 131 43:1b:32:29:24:11:48:fe:e6:c1:3f:11:8e:b5:a6:93:cc:af: |
| 132 ee:87:7f:24:58:b6:a4:37:ae:57:73:c5:34:74:66:44:ca:90: |
| 133 9f:b8:83:03 |
| 134 -----BEGIN CERTIFICATE----- |
| 135 MIICpTCCAY2gAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 |
| 136 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 |
| 137 ZXJtZWRpYXJ5MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBALZv+vgnnENo0N3Jbs1W |
| 138 KzRM/ok+inbtClMqov+F7JyIcreMZDEx1jDM8+Ea87ri8oBMLOIWJOMsLJtM9YKG |
| 139 NdsCAwEAAaOByzCByDAdBgNVHQ4EFgQUTiD+IGrkLu6NI7QThhdtmmZHS4EwHwYD |
| 140 VR0jBBgwFoAUFrXJUB9umGt9M1YvUiAzHslEwOgwNwYIKwYBBQUHAQEEKzApMCcG |
| 141 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw |
| 142 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE |
| 143 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCeE78L+AkX |
| 144 GCLzCUSKQXEjRsxyrLqWmixwgHrK4GYRd5K7YwXHlcUtrRvzxnwUWuAlBqOtyEHP |
| 145 I2lhu7Ys64D2Aa/igRYMK8K36W75tAGpcmF2n5GWHs6FrjEPWZ0v7xHC4Hmz3Rfo |
| 146 Pz94L5oqzbfJBvcDk8YmLUQ2O3EXiDzFPNWxXgXnyr7pvJj74JJBgpp630lOtCW/ |
| 147 45xK2ApPvCq8S11Qka2+pW94Omr6Z2uRPzAhBVAo/nHbOhklgGb6r9wS6/67AyJZ |
| 148 iDS0OlpsNwyR918Qg+n0BK1DGzIpJBFI/ubBPxGOtaaTzK/uh38kWLakN65Xc8U0 |
| 149 dGZEypCfuIMD |
| 150 -----END CERTIFICATE----- |
| 151 |
| 152 Certificate: |
| 153 Data: |
| 154 Version: 3 (0x2) |
| 155 Serial Number: 1 (0x1) |
| 156 Signature Algorithm: sha256WithRSAEncryption |
| 157 Issuer: CN=Root |
| 158 Validity |
| 159 Not Before: Jan 1 12:00:00 2015 GMT |
| 160 Not After : Jan 1 12:00:00 2016 GMT |
| 161 Subject: CN=Root |
| 162 Subject Public Key Info: |
| 163 Public Key Algorithm: rsaEncryption |
| 164 Public-Key: (2048 bit) |
| 165 Modulus: |
| 166 00:c7:27:b9:d2:57:ee:3d:8e:4b:ab:23:c4:f7:1a: |
| 167 4d:bf:98:79:d9:3c:f1:68:f8:e0:b9:65:c5:ae:60: |
| 168 a2:16:c1:31:a2:e1:d7:a7:fc:57:be:13:e1:d2:d7: |
| 169 c2:48:1c:0a:a0:6a:bc:ac:84:ed:75:ab:ea:68:33: |
| 170 fb:30:0c:05:ad:ee:12:d2:b1:6f:16:f9:81:30:aa: |
| 171 0f:96:3d:98:96:09:b4:06:2c:fa:8f:6d:68:be:1d: |
| 172 f8:a7:74:8a:9b:1e:91:e3:20:b2:d5:d5:49:9c:bd: |
| 173 7d:09:7e:71:eb:08:61:ec:25:9d:eb:a7:4a:46:3d: |
| 174 92:28:57:94:29:62:d7:a0:bc:28:90:e8:ac:54:2a: |
| 175 96:73:2a:e3:d1:4b:9e:f0:cf:8b:de:47:fc:55:c0: |
| 176 78:e0:8e:f6:c1:9f:c8:b2:78:4c:93:32:b6:e4:bf: |
| 177 54:dc:ea:90:69:96:12:e0:f4:a0:41:7a:80:28:6b: |
| 178 ed:39:51:35:64:08:51:9d:40:72:5c:f2:5b:4d:97: |
| 179 fb:aa:ff:d1:26:82:32:1e:72:9e:c0:b7:ec:94:45: |
| 180 f5:cb:91:fe:ed:bc:83:46:c2:b9:a5:4a:9c:c9:76: |
| 181 9b:8a:02:89:1b:66:6e:21:a3:53:e2:e1:3b:03:13: |
| 182 32:9b:26:09:27:c2:bf:9b:89:bc:41:83:ae:58:90: |
| 183 f3:bf |
| 184 Exponent: 65537 (0x10001) |
| 185 X509v3 extensions: |
| 186 X509v3 Subject Key Identifier: |
| 187 16:B5:C9:50:1F:6E:98:6B:7D:33:56:2F:52:20:33:1E:C9:44:C0:E8 |
| 188 X509v3 Authority Key Identifier: |
| 189 keyid:16:B5:C9:50:1F:6E:98:6B:7D:33:56:2F:52:20:33:1E:C9:44:C0:E
8 |
| 190 |
| 191 Authority Information Access: |
| 192 CA Issuers - URI:http://url-for-aia/Root.cer |
| 193 |
| 194 X509v3 CRL Distribution Points: |
| 195 |
| 196 Full Name: |
| 197 URI:http://url-for-crl/Root.crl |
| 198 |
| 199 X509v3 Key Usage: critical |
| 200 Certificate Sign, CRL Sign |
| 201 X509v3 Basic Constraints: critical |
| 202 CA:TRUE |
| 203 Signature Algorithm: sha256WithRSAEncryption |
| 204 42:1d:03:ac:af:b1:8e:ae:50:c5:7f:b7:7f:03:2c:8e:4b:3c: |
| 205 5a:24:07:7a:fd:f4:49:5f:e6:07:d8:cc:69:1c:c3:62:95:86: |
| 206 ad:d3:70:7a:ec:d0:4e:59:55:80:d6:c2:e8:f8:5d:be:52:81: |
| 207 68:5f:47:b2:60:5a:ee:9e:5a:42:9f:37:dc:2c:7b:4b:7f:b9: |
| 208 d5:68:e0:fe:35:af:71:9d:a3:30:c6:40:47:31:e8:de:48:89: |
| 209 fc:cf:0f:0c:7e:48:09:9c:e1:cf:93:85:0a:04:3f:f0:50:b9: |
| 210 8f:ff:5e:05:da:c0:41:a1:e5:0e:90:89:e3:cd:11:34:8a:d7: |
| 211 a2:06:fb:0f:ac:b7:2c:97:43:49:4f:23:9f:a2:b6:dd:28:83: |
| 212 22:9c:61:5f:3f:ad:af:02:ab:59:03:66:4e:ac:eb:41:d0:5c: |
| 213 cb:9b:65:72:50:9f:cc:13:e2:d4:a3:5c:41:50:90:b3:4f:16: |
| 214 2d:ac:8b:1b:52:f3:29:f3:c2:f6:e8:e1:be:bc:b4:12:08:d9: |
| 215 6d:e1:11:7b:89:7e:7c:8e:16:42:f3:d0:3c:40:5c:cb:4f:79: |
| 216 5a:cf:8f:ca:58:1a:f1:66:7e:9e:b6:b4:df:32:77:a9:90:57: |
| 217 d0:0a:08:5d:98:1d:5d:4a:b1:40:2a:bd:29:ea:6f:ba:ad:a7: |
| 218 b1:c0:ee:49 |
| 219 -----BEGIN TRUSTED_CERTIFICATE----- |
| 220 MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 |
| 221 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v |
| 222 dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMcnudJX7j2OS6sjxPca |
| 223 Tb+Yedk88Wj44Lllxa5gohbBMaLh16f8V74T4dLXwkgcCqBqvKyE7XWr6mgz+zAM |
| 224 Ba3uEtKxbxb5gTCqD5Y9mJYJtAYs+o9taL4d+Kd0ipsekeMgstXVSZy9fQl+cesI |
| 225 YewlneunSkY9kihXlCli16C8KJDorFQqlnMq49FLnvDPi95H/FXAeOCO9sGfyLJ4 |
| 226 TJMytuS/VNzqkGmWEuD0oEF6gChr7TlRNWQIUZ1AclzyW02X+6r/0SaCMh5ynsC3 |
| 227 7JRF9cuR/u28g0bCuaVKnMl2m4oCiRtmbiGjU+LhOwMTMpsmCSfCv5uJvEGDrliQ |
| 228 878CAwEAAaOByzCByDAdBgNVHQ4EFgQUFrXJUB9umGt9M1YvUiAzHslEwOgwHwYD |
| 229 VR0jBBgwFoAUFrXJUB9umGt9M1YvUiAzHslEwOgwNwYIKwYBBQUHAQEEKzApMCcG |
| 230 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw |
| 231 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE |
| 232 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBCHQOsr7GO |
| 233 rlDFf7d/AyyOSzxaJAd6/fRJX+YH2MxpHMNilYat03B67NBOWVWA1sLo+F2+UoFo |
| 234 X0eyYFrunlpCnzfcLHtLf7nVaOD+Na9xnaMwxkBHMejeSIn8zw8MfkgJnOHPk4UK |
| 235 BD/wULmP/14F2sBBoeUOkInjzRE0iteiBvsPrLcsl0NJTyOforbdKIMinGFfP62v |
| 236 AqtZA2ZOrOtB0FzLm2VyUJ/ME+LUo1xBUJCzTxYtrIsbUvMp88L26OG+vLQSCNlt |
| 237 4RF7iX58jhZC89A8QFzLT3laz4/KWBrxZn6etrTfMnepkFfQCghdmB1dSrFAKr0p |
| 238 6m+6raexwO5J |
| 239 -----END TRUSTED_CERTIFICATE----- |
| 240 |
| 241 -----BEGIN TIME----- |
| 242 MTYwMzAyMTIwMDAwWg== |
| 243 -----END TIME----- |
| 244 |
| 245 -----BEGIN VERIFY_RESULT----- |
| 246 RkFJTA== |
| 247 -----END VERIFY_RESULT----- |
| OLD | NEW |