| OLD | NEW | 
|---|
| (Empty) |  | 
|  | 1 [Created by: generate-target-signed-by-512bit-rsa.py] | 
|  | 2 | 
|  | 3 Certificate chain with 1 intermediary. The target certificate | 
|  | 4 is signed using a weak RSA key (512-bit modulus) | 
|  | 5 | 
|  | 6 Certificate: | 
|  | 7     Data: | 
|  | 8         Version: 3 (0x2) | 
|  | 9         Serial Number: 1 (0x1) | 
|  | 10     Signature Algorithm: sha256WithRSAEncryption | 
|  | 11         Issuer: CN=Intermediary | 
|  | 12         Validity | 
|  | 13             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 14             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 15         Subject: CN=Target | 
|  | 16         Subject Public Key Info: | 
|  | 17             Public Key Algorithm: rsaEncryption | 
|  | 18                 Public-Key: (2048 bit) | 
|  | 19                 Modulus: | 
|  | 20                     00:ca:10:3e:cf:ee:e8:57:a8:4a:4b:80:03:ff:b0: | 
|  | 21                     70:c3:03:80:ec:a9:15:d6:94:6c:b6:f0:02:31:1a: | 
|  | 22                     52:49:95:14:ba:10:52:36:8a:cd:36:37:8f:3f:2a: | 
|  | 23                     74:5f:ac:38:a5:d2:dd:35:2e:ee:e4:47:7f:5d:f7: | 
|  | 24                     6a:26:4e:a0:33:ca:46:ba:18:71:76:94:22:ba:ae: | 
|  | 25                     b0:ea:62:ca:36:63:d9:4e:5e:18:e0:fc:1a:9d:e6: | 
|  | 26                     04:52:75:71:b2:7e:24:91:81:be:74:c9:4f:e6:ca: | 
|  | 27                     d4:77:cf:28:29:07:73:1b:3b:55:83:d5:73:10:fb: | 
|  | 28                     96:ec:12:46:b1:26:fb:06:5f:b2:84:16:de:04:36: | 
|  | 29                     30:be:99:af:23:e3:6f:be:63:6c:fd:0c:62:6d:8c: | 
|  | 30                     29:43:9b:79:26:0d:7c:f0:38:e8:19:1b:4d:57:63: | 
|  | 31                     0e:2e:6b:e6:f7:61:d7:6b:cc:3a:f1:76:b0:da:8b: | 
|  | 32                     21:f2:a3:97:78:f9:d8:76:97:80:b9:34:8e:1c:27: | 
|  | 33                     ef:48:22:c5:ac:a3:ac:b3:cc:3b:54:dc:67:c6:e8: | 
|  | 34                     18:7b:8c:f0:8c:e3:e8:6b:9e:5f:17:eb:bc:3c:79: | 
|  | 35                     03:5e:c3:17:d2:26:49:97:3f:ba:6c:64:f5:9e:8e: | 
|  | 36                     98:25:2d:98:05:1a:6f:f1:5c:5e:8e:d1:04:50:41: | 
|  | 37                     8f:e9 | 
|  | 38                 Exponent: 65537 (0x10001) | 
|  | 39         X509v3 extensions: | 
|  | 40             X509v3 Subject Key Identifier: | 
|  | 41                 80:48:02:46:1D:D2:6B:B6:90:3A:D9:CA:9A:51:6E:B8:EA:06:9D:23 | 
|  | 42             X509v3 Authority Key Identifier: | 
|  | 43                 keyid:4E:20:FE:20:6A:E4:2E:EE:8D:23:B4:13:86:17:6D:9A:66:47:4B:8
     1 | 
|  | 44 | 
|  | 45             Authority Information Access: | 
|  | 46                 CA Issuers - URI:http://url-for-aia/Intermediary.cer | 
|  | 47 | 
|  | 48             X509v3 CRL Distribution Points: | 
|  | 49 | 
|  | 50                 Full Name: | 
|  | 51                   URI:http://url-for-crl/Intermediary.crl | 
|  | 52 | 
|  | 53             X509v3 Key Usage: critical | 
|  | 54                 Digital Signature, Key Encipherment | 
|  | 55             X509v3 Extended Key Usage: | 
|  | 56                 TLS Web Server Authentication, TLS Web Client Authentication | 
|  | 57     Signature Algorithm: sha256WithRSAEncryption | 
|  | 58          a9:8b:48:ed:b6:51:5c:5c:36:b7:8b:ff:64:76:94:f1:8f:b4: | 
|  | 59          8a:a0:96:47:76:5d:dc:84:11:0c:ae:1b:29:d7:de:58:85:46: | 
|  | 60          d9:bd:10:91:0f:bb:c0:99:bc:ef:9f:7f:65:31:21:a4:f5:e0: | 
|  | 61          db:e9:5c:3e:fa:71:8d:24:3d:e9 | 
|  | 62 -----BEGIN CERTIFICATE----- | 
|  | 63 MIICyzCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl | 
|  | 64 cm1lZGlhcnkwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD | 
|  | 65 VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDKED7P | 
|  | 66 7uhXqEpLgAP/sHDDA4DsqRXWlGy28AIxGlJJlRS6EFI2is02N48/KnRfrDil0t01 | 
|  | 67 Lu7kR39d92omTqAzyka6GHF2lCK6rrDqYso2Y9lOXhjg/Bqd5gRSdXGyfiSRgb50 | 
|  | 68 yU/mytR3zygpB3MbO1WD1XMQ+5bsEkaxJvsGX7KEFt4ENjC+ma8j42++Y2z9DGJt | 
|  | 69 jClDm3kmDXzwOOgZG01XYw4ua+b3YddrzDrxdrDaiyHyo5d4+dh2l4C5NI4cJ+9I | 
|  | 70 IsWso6yzzDtU3GfG6Bh7jPCM4+hrnl8X67w8eQNewxfSJkmXP7psZPWejpglLZgF | 
|  | 71 Gm/xXF6O0QRQQY/pAgMBAAGjgekwgeYwHQYDVR0OBBYEFIBIAkYd0mu2kDrZyppR | 
|  | 72 brjqBp0jMB8GA1UdIwQYMBaAFE4g/iBq5C7ujSO0E4YXbZpmR0uBMD8GCCsGAQUF | 
|  | 73 BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk | 
|  | 74 aWFyeS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu | 
|  | 75 dGVybWVkaWFyeS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF | 
|  | 76 BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAANBAKmLSO22UVxcNreL/2R2lPGP | 
|  | 77 tIqglkd2XdyEEQyuGynX3liFRtm9EJEPu8CZvO+ff2UxIaT14NvpXD76cY0kPek= | 
|  | 78 -----END CERTIFICATE----- | 
|  | 79 | 
|  | 80 Certificate: | 
|  | 81     Data: | 
|  | 82         Version: 3 (0x2) | 
|  | 83         Serial Number: 2 (0x2) | 
|  | 84     Signature Algorithm: sha256WithRSAEncryption | 
|  | 85         Issuer: CN=Root | 
|  | 86         Validity | 
|  | 87             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 88             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 89         Subject: CN=Intermediary | 
|  | 90         Subject Public Key Info: | 
|  | 91             Public Key Algorithm: rsaEncryption | 
|  | 92                 Public-Key: (512 bit) | 
|  | 93                 Modulus: | 
|  | 94                     00:b6:6f:fa:f8:27:9c:43:68:d0:dd:c9:6e:cd:56: | 
|  | 95                     2b:34:4c:fe:89:3e:8a:76:ed:0a:53:2a:a2:ff:85: | 
|  | 96                     ec:9c:88:72:b7:8c:64:31:31:d6:30:cc:f3:e1:1a: | 
|  | 97                     f3:ba:e2:f2:80:4c:2c:e2:16:24:e3:2c:2c:9b:4c: | 
|  | 98                     f5:82:86:35:db | 
|  | 99                 Exponent: 65537 (0x10001) | 
|  | 100         X509v3 extensions: | 
|  | 101             X509v3 Subject Key Identifier: | 
|  | 102                 4E:20:FE:20:6A:E4:2E:EE:8D:23:B4:13:86:17:6D:9A:66:47:4B:81 | 
|  | 103             X509v3 Authority Key Identifier: | 
|  | 104                 keyid:16:B5:C9:50:1F:6E:98:6B:7D:33:56:2F:52:20:33:1E:C9:44:C0:E
     8 | 
|  | 105 | 
|  | 106             Authority Information Access: | 
|  | 107                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 108 | 
|  | 109             X509v3 CRL Distribution Points: | 
|  | 110 | 
|  | 111                 Full Name: | 
|  | 112                   URI:http://url-for-crl/Root.crl | 
|  | 113 | 
|  | 114             X509v3 Key Usage: critical | 
|  | 115                 Certificate Sign, CRL Sign | 
|  | 116             X509v3 Basic Constraints: critical | 
|  | 117                 CA:TRUE | 
|  | 118     Signature Algorithm: sha256WithRSAEncryption | 
|  | 119          9e:13:bf:0b:f8:09:17:18:22:f3:09:44:8a:41:71:23:46:cc: | 
|  | 120          72:ac:ba:96:9a:2c:70:80:7a:ca:e0:66:11:77:92:bb:63:05: | 
|  | 121          c7:95:c5:2d:ad:1b:f3:c6:7c:14:5a:e0:25:06:a3:ad:c8:41: | 
|  | 122          cf:23:69:61:bb:b6:2c:eb:80:f6:01:af:e2:81:16:0c:2b:c2: | 
|  | 123          b7:e9:6e:f9:b4:01:a9:72:61:76:9f:91:96:1e:ce:85:ae:31: | 
|  | 124          0f:59:9d:2f:ef:11:c2:e0:79:b3:dd:17:e8:3f:3f:78:2f:9a: | 
|  | 125          2a:cd:b7:c9:06:f7:03:93:c6:26:2d:44:36:3b:71:17:88:3c: | 
|  | 126          c5:3c:d5:b1:5e:05:e7:ca:be:e9:bc:98:fb:e0:92:41:82:9a: | 
|  | 127          7a:df:49:4e:b4:25:bf:e3:9c:4a:d8:0a:4f:bc:2a:bc:4b:5d: | 
|  | 128          50:91:ad:be:a5:6f:78:3a:6a:fa:67:6b:91:3f:30:21:05:50: | 
|  | 129          28:fe:71:db:3a:19:25:80:66:fa:af:dc:12:eb:fe:bb:03:22: | 
|  | 130          59:88:34:b4:3a:5a:6c:37:0c:91:f7:5f:10:83:e9:f4:04:ad: | 
|  | 131          43:1b:32:29:24:11:48:fe:e6:c1:3f:11:8e:b5:a6:93:cc:af: | 
|  | 132          ee:87:7f:24:58:b6:a4:37:ae:57:73:c5:34:74:66:44:ca:90: | 
|  | 133          9f:b8:83:03 | 
|  | 134 -----BEGIN CERTIFICATE----- | 
|  | 135 MIICpTCCAY2gAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 136 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 | 
|  | 137 ZXJtZWRpYXJ5MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBALZv+vgnnENo0N3Jbs1W | 
|  | 138 KzRM/ok+inbtClMqov+F7JyIcreMZDEx1jDM8+Ea87ri8oBMLOIWJOMsLJtM9YKG | 
|  | 139 NdsCAwEAAaOByzCByDAdBgNVHQ4EFgQUTiD+IGrkLu6NI7QThhdtmmZHS4EwHwYD | 
|  | 140 VR0jBBgwFoAUFrXJUB9umGt9M1YvUiAzHslEwOgwNwYIKwYBBQUHAQEEKzApMCcG | 
|  | 141 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw | 
|  | 142 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE | 
|  | 143 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCeE78L+AkX | 
|  | 144 GCLzCUSKQXEjRsxyrLqWmixwgHrK4GYRd5K7YwXHlcUtrRvzxnwUWuAlBqOtyEHP | 
|  | 145 I2lhu7Ys64D2Aa/igRYMK8K36W75tAGpcmF2n5GWHs6FrjEPWZ0v7xHC4Hmz3Rfo | 
|  | 146 Pz94L5oqzbfJBvcDk8YmLUQ2O3EXiDzFPNWxXgXnyr7pvJj74JJBgpp630lOtCW/ | 
|  | 147 45xK2ApPvCq8S11Qka2+pW94Omr6Z2uRPzAhBVAo/nHbOhklgGb6r9wS6/67AyJZ | 
|  | 148 iDS0OlpsNwyR918Qg+n0BK1DGzIpJBFI/ubBPxGOtaaTzK/uh38kWLakN65Xc8U0 | 
|  | 149 dGZEypCfuIMD | 
|  | 150 -----END CERTIFICATE----- | 
|  | 151 | 
|  | 152 Certificate: | 
|  | 153     Data: | 
|  | 154         Version: 3 (0x2) | 
|  | 155         Serial Number: 1 (0x1) | 
|  | 156     Signature Algorithm: sha256WithRSAEncryption | 
|  | 157         Issuer: CN=Root | 
|  | 158         Validity | 
|  | 159             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 160             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 161         Subject: CN=Root | 
|  | 162         Subject Public Key Info: | 
|  | 163             Public Key Algorithm: rsaEncryption | 
|  | 164                 Public-Key: (2048 bit) | 
|  | 165                 Modulus: | 
|  | 166                     00:c7:27:b9:d2:57:ee:3d:8e:4b:ab:23:c4:f7:1a: | 
|  | 167                     4d:bf:98:79:d9:3c:f1:68:f8:e0:b9:65:c5:ae:60: | 
|  | 168                     a2:16:c1:31:a2:e1:d7:a7:fc:57:be:13:e1:d2:d7: | 
|  | 169                     c2:48:1c:0a:a0:6a:bc:ac:84:ed:75:ab:ea:68:33: | 
|  | 170                     fb:30:0c:05:ad:ee:12:d2:b1:6f:16:f9:81:30:aa: | 
|  | 171                     0f:96:3d:98:96:09:b4:06:2c:fa:8f:6d:68:be:1d: | 
|  | 172                     f8:a7:74:8a:9b:1e:91:e3:20:b2:d5:d5:49:9c:bd: | 
|  | 173                     7d:09:7e:71:eb:08:61:ec:25:9d:eb:a7:4a:46:3d: | 
|  | 174                     92:28:57:94:29:62:d7:a0:bc:28:90:e8:ac:54:2a: | 
|  | 175                     96:73:2a:e3:d1:4b:9e:f0:cf:8b:de:47:fc:55:c0: | 
|  | 176                     78:e0:8e:f6:c1:9f:c8:b2:78:4c:93:32:b6:e4:bf: | 
|  | 177                     54:dc:ea:90:69:96:12:e0:f4:a0:41:7a:80:28:6b: | 
|  | 178                     ed:39:51:35:64:08:51:9d:40:72:5c:f2:5b:4d:97: | 
|  | 179                     fb:aa:ff:d1:26:82:32:1e:72:9e:c0:b7:ec:94:45: | 
|  | 180                     f5:cb:91:fe:ed:bc:83:46:c2:b9:a5:4a:9c:c9:76: | 
|  | 181                     9b:8a:02:89:1b:66:6e:21:a3:53:e2:e1:3b:03:13: | 
|  | 182                     32:9b:26:09:27:c2:bf:9b:89:bc:41:83:ae:58:90: | 
|  | 183                     f3:bf | 
|  | 184                 Exponent: 65537 (0x10001) | 
|  | 185         X509v3 extensions: | 
|  | 186             X509v3 Subject Key Identifier: | 
|  | 187                 16:B5:C9:50:1F:6E:98:6B:7D:33:56:2F:52:20:33:1E:C9:44:C0:E8 | 
|  | 188             X509v3 Authority Key Identifier: | 
|  | 189                 keyid:16:B5:C9:50:1F:6E:98:6B:7D:33:56:2F:52:20:33:1E:C9:44:C0:E
     8 | 
|  | 190 | 
|  | 191             Authority Information Access: | 
|  | 192                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 193 | 
|  | 194             X509v3 CRL Distribution Points: | 
|  | 195 | 
|  | 196                 Full Name: | 
|  | 197                   URI:http://url-for-crl/Root.crl | 
|  | 198 | 
|  | 199             X509v3 Key Usage: critical | 
|  | 200                 Certificate Sign, CRL Sign | 
|  | 201             X509v3 Basic Constraints: critical | 
|  | 202                 CA:TRUE | 
|  | 203     Signature Algorithm: sha256WithRSAEncryption | 
|  | 204          42:1d:03:ac:af:b1:8e:ae:50:c5:7f:b7:7f:03:2c:8e:4b:3c: | 
|  | 205          5a:24:07:7a:fd:f4:49:5f:e6:07:d8:cc:69:1c:c3:62:95:86: | 
|  | 206          ad:d3:70:7a:ec:d0:4e:59:55:80:d6:c2:e8:f8:5d:be:52:81: | 
|  | 207          68:5f:47:b2:60:5a:ee:9e:5a:42:9f:37:dc:2c:7b:4b:7f:b9: | 
|  | 208          d5:68:e0:fe:35:af:71:9d:a3:30:c6:40:47:31:e8:de:48:89: | 
|  | 209          fc:cf:0f:0c:7e:48:09:9c:e1:cf:93:85:0a:04:3f:f0:50:b9: | 
|  | 210          8f:ff:5e:05:da:c0:41:a1:e5:0e:90:89:e3:cd:11:34:8a:d7: | 
|  | 211          a2:06:fb:0f:ac:b7:2c:97:43:49:4f:23:9f:a2:b6:dd:28:83: | 
|  | 212          22:9c:61:5f:3f:ad:af:02:ab:59:03:66:4e:ac:eb:41:d0:5c: | 
|  | 213          cb:9b:65:72:50:9f:cc:13:e2:d4:a3:5c:41:50:90:b3:4f:16: | 
|  | 214          2d:ac:8b:1b:52:f3:29:f3:c2:f6:e8:e1:be:bc:b4:12:08:d9: | 
|  | 215          6d:e1:11:7b:89:7e:7c:8e:16:42:f3:d0:3c:40:5c:cb:4f:79: | 
|  | 216          5a:cf:8f:ca:58:1a:f1:66:7e:9e:b6:b4:df:32:77:a9:90:57: | 
|  | 217          d0:0a:08:5d:98:1d:5d:4a:b1:40:2a:bd:29:ea:6f:ba:ad:a7: | 
|  | 218          b1:c0:ee:49 | 
|  | 219 -----BEGIN TRUSTED_CERTIFICATE----- | 
|  | 220 MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 221 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v | 
|  | 222 dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMcnudJX7j2OS6sjxPca | 
|  | 223 Tb+Yedk88Wj44Lllxa5gohbBMaLh16f8V74T4dLXwkgcCqBqvKyE7XWr6mgz+zAM | 
|  | 224 Ba3uEtKxbxb5gTCqD5Y9mJYJtAYs+o9taL4d+Kd0ipsekeMgstXVSZy9fQl+cesI | 
|  | 225 YewlneunSkY9kihXlCli16C8KJDorFQqlnMq49FLnvDPi95H/FXAeOCO9sGfyLJ4 | 
|  | 226 TJMytuS/VNzqkGmWEuD0oEF6gChr7TlRNWQIUZ1AclzyW02X+6r/0SaCMh5ynsC3 | 
|  | 227 7JRF9cuR/u28g0bCuaVKnMl2m4oCiRtmbiGjU+LhOwMTMpsmCSfCv5uJvEGDrliQ | 
|  | 228 878CAwEAAaOByzCByDAdBgNVHQ4EFgQUFrXJUB9umGt9M1YvUiAzHslEwOgwHwYD | 
|  | 229 VR0jBBgwFoAUFrXJUB9umGt9M1YvUiAzHslEwOgwNwYIKwYBBQUHAQEEKzApMCcG | 
|  | 230 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw | 
|  | 231 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE | 
|  | 232 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBCHQOsr7GO | 
|  | 233 rlDFf7d/AyyOSzxaJAd6/fRJX+YH2MxpHMNilYat03B67NBOWVWA1sLo+F2+UoFo | 
|  | 234 X0eyYFrunlpCnzfcLHtLf7nVaOD+Na9xnaMwxkBHMejeSIn8zw8MfkgJnOHPk4UK | 
|  | 235 BD/wULmP/14F2sBBoeUOkInjzRE0iteiBvsPrLcsl0NJTyOforbdKIMinGFfP62v | 
|  | 236 AqtZA2ZOrOtB0FzLm2VyUJ/ME+LUo1xBUJCzTxYtrIsbUvMp88L26OG+vLQSCNlt | 
|  | 237 4RF7iX58jhZC89A8QFzLT3laz4/KWBrxZn6etrTfMnepkFfQCghdmB1dSrFAKr0p | 
|  | 238 6m+6raexwO5J | 
|  | 239 -----END TRUSTED_CERTIFICATE----- | 
|  | 240 | 
|  | 241 -----BEGIN TIME----- | 
|  | 242 MTYwMzAyMTIwMDAwWg== | 
|  | 243 -----END TIME----- | 
|  | 244 | 
|  | 245 -----BEGIN VERIFY_RESULT----- | 
|  | 246 RkFJTA== | 
|  | 247 -----END VERIFY_RESULT----- | 
| OLD | NEW | 
|---|