| OLD | NEW | 
|---|
| (Empty) |  | 
|  | 1 [Created by: generate-target-signed-using-ecdsa.py] | 
|  | 2 | 
|  | 3 Simple certificate where the intermediary has an EC key, but | 
|  | 4 the root and target contain RSA keys. | 
|  | 5 | 
|  | 6 Certificate: | 
|  | 7     Data: | 
|  | 8         Version: 3 (0x2) | 
|  | 9         Serial Number: 1 (0x1) | 
|  | 10     Signature Algorithm: ecdsa-with-SHA256 | 
|  | 11         Issuer: CN=Intermediary | 
|  | 12         Validity | 
|  | 13             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 14             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 15         Subject: CN=Target | 
|  | 16         Subject Public Key Info: | 
|  | 17             Public Key Algorithm: rsaEncryption | 
|  | 18                 Public-Key: (2048 bit) | 
|  | 19                 Modulus: | 
|  | 20                     00:cd:af:55:50:df:8c:d9:ff:fa:4c:ea:84:a3:36: | 
|  | 21                     d1:9d:01:04:7d:bd:65:4b:ec:dc:af:c6:67:cc:99: | 
|  | 22                     49:b9:3e:11:53:61:7d:3f:ba:9f:99:7b:70:37:bd: | 
|  | 23                     c5:a0:82:10:8e:51:51:26:1e:a6:26:3a:b6:e8:c9: | 
|  | 24                     2d:cb:58:6e:4f:fe:16:9a:77:66:ae:80:9d:5a:14: | 
|  | 25                     c7:27:40:4b:26:86:3d:96:01:e9:84:66:90:d7:86: | 
|  | 26                     07:0d:c7:fc:9c:66:b2:f8:a2:68:e4:49:55:df:35: | 
|  | 27                     7a:29:9f:fb:a5:30:58:0f:ae:b5:7c:8f:fa:4d:5e: | 
|  | 28                     0a:0f:a9:fb:b1:74:da:0f:71:99:f7:13:99:4d:56: | 
|  | 29                     16:01:de:d2:c5:29:b6:4d:42:7c:d6:87:28:2f:43: | 
|  | 30                     f0:97:c6:4d:4e:ca:7d:32:aa:90:fd:99:a1:70:0c: | 
|  | 31                     d8:96:b6:08:bf:20:5f:0f:84:9d:b4:7b:c6:8c:a1: | 
|  | 32                     9a:bb:da:c3:44:74:c5:95:2d:61:bb:a0:12:a3:6b: | 
|  | 33                     7d:e1:d6:c1:d5:76:f9:9e:d2:f5:45:b1:54:86:65: | 
|  | 34                     e0:16:50:fe:92:69:a3:9e:a7:ac:eb:0a:7e:d3:f8: | 
|  | 35                     e6:a0:85:bc:da:d2:3f:e4:bb:49:18:a8:a4:e0:6e: | 
|  | 36                     63:8a:9e:8a:52:c2:9a:13:4f:3b:b6:04:76:09:1d: | 
|  | 37                     b8:69 | 
|  | 38                 Exponent: 65537 (0x10001) | 
|  | 39         X509v3 extensions: | 
|  | 40             X509v3 Subject Key Identifier: | 
|  | 41                 06:A7:D1:14:26:E1:C5:87:D7:08:C8:98:58:D0:51:80:C2:68:E5:74 | 
|  | 42             X509v3 Authority Key Identifier: | 
|  | 43                 keyid:C0:4E:97:5B:44:FB:CD:F0:8C:9C:BC:3D:8B:EF:31:60:85:5D:93:C
     B | 
|  | 44 | 
|  | 45             Authority Information Access: | 
|  | 46                 CA Issuers - URI:http://url-for-aia/Intermediary.cer | 
|  | 47 | 
|  | 48             X509v3 CRL Distribution Points: | 
|  | 49 | 
|  | 50                 Full Name: | 
|  | 51                   URI:http://url-for-crl/Intermediary.crl | 
|  | 52 | 
|  | 53             X509v3 Key Usage: critical | 
|  | 54                 Digital Signature, Key Encipherment | 
|  | 55             X509v3 Extended Key Usage: | 
|  | 56                 TLS Web Server Authentication, TLS Web Client Authentication | 
|  | 57     Signature Algorithm: ecdsa-with-SHA256 | 
|  | 58          30:64:02:30:76:35:ba:d7:c7:36:0d:00:98:08:8c:1e:4b:91: | 
|  | 59          26:ab:0d:e7:57:5b:a8:44:a5:b4:43:cf:c4:7d:ea:e5:4a:c0: | 
|  | 60          80:c2:73:55:93:b0:28:b6:ed:ff:76:a1:6a:02:28:db:02:30: | 
|  | 61          23:ee:c8:fa:8c:82:c3:c2:91:d4:a6:f9:3c:57:e3:1a:16:6b: | 
|  | 62          31:22:d9:e9:9c:4e:99:29:c2:aa:69:47:a2:45:bf:82:f1:a2: | 
|  | 63          4d:2e:53:09:2e:c4:c9:43:75:af:7d:08 | 
|  | 64 -----BEGIN CERTIFICATE----- | 
|  | 65 MIIC6zCCAnKgAwIBAgIBATAKBggqhkjOPQQDAjAXMRUwEwYDVQQDDAxJbnRlcm1l | 
|  | 66 ZGlhcnkwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYDVQQD | 
|  | 67 DAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDNr1VQ34zZ | 
|  | 68 //pM6oSjNtGdAQR9vWVL7NyvxmfMmUm5PhFTYX0/up+Ze3A3vcWgghCOUVEmHqYm | 
|  | 69 OrboyS3LWG5P/haad2augJ1aFMcnQEsmhj2WAemEZpDXhgcNx/ycZrL4omjkSVXf | 
|  | 70 NXopn/ulMFgPrrV8j/pNXgoPqfuxdNoPcZn3E5lNVhYB3tLFKbZNQnzWhygvQ/CX | 
|  | 71 xk1Oyn0yqpD9maFwDNiWtgi/IF8PhJ20e8aMoZq72sNEdMWVLWG7oBKja33h1sHV | 
|  | 72 dvme0vVFsVSGZeAWUP6SaaOep6zrCn7T+Oaghbza0j/ku0kYqKTgbmOKnopSwpoT | 
|  | 73 Tzu2BHYJHbhpAgMBAAGjgekwgeYwHQYDVR0OBBYEFAan0RQm4cWH1wjImFjQUYDC | 
|  | 74 aOV0MB8GA1UdIwQYMBaAFMBOl1tE+83wjJy8PYvvMWCFXZPLMD8GCCsGAQUFBwEB | 
|  | 75 BDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVkaWFy | 
|  | 76 eS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0ludGVy | 
|  | 77 bWVkaWFyeS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMB | 
|  | 78 BggrBgEFBQcDAjAKBggqhkjOPQQDAgNnADBkAjB2NbrXxzYNAJgIjB5LkSarDedX | 
|  | 79 W6hEpbRDz8R96uVKwIDCc1WTsCi27f92oWoCKNsCMCPuyPqMgsPCkdSm+TxX4xoW | 
|  | 80 azEi2emcTpkpwqppR6JFv4Lxok0uUwkuxMlDda99CA== | 
|  | 81 -----END CERTIFICATE----- | 
|  | 82 | 
|  | 83 Certificate: | 
|  | 84     Data: | 
|  | 85         Version: 3 (0x2) | 
|  | 86         Serial Number: 2 (0x2) | 
|  | 87     Signature Algorithm: sha256WithRSAEncryption | 
|  | 88         Issuer: CN=Root | 
|  | 89         Validity | 
|  | 90             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 91             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 92         Subject: CN=Intermediary | 
|  | 93         Subject Public Key Info: | 
|  | 94             Public Key Algorithm: id-ecPublicKey | 
|  | 95                 Public-Key: (384 bit) | 
|  | 96                 pub: | 
|  | 97                     04:5c:ae:63:42:56:1e:4f:ac:f1:f1:23:4b:5f:ad: | 
|  | 98                     54:0e:88:26:73:9e:71:3c:e4:75:9b:23:88:cd:76: | 
|  | 99                     83:4b:5d:5c:01:c2:f7:0d:29:27:78:d2:58:c7:c0: | 
|  | 100                     c5:25:8e:19:60:20:35:fe:85:6a:37:e9:02:87:2d: | 
|  | 101                     93:5c:ee:54:79:de:61:7e:f6:ae:9a:81:c6:2b:2b: | 
|  | 102                     af:5d:fd:b6:98:a9:22:3c:91:3a:74:04:19:63:b7: | 
|  | 103                     5a:48:06:dc:ff:26:20 | 
|  | 104                 ASN1 OID: secp384r1 | 
|  | 105         X509v3 extensions: | 
|  | 106             X509v3 Subject Key Identifier: | 
|  | 107                 C0:4E:97:5B:44:FB:CD:F0:8C:9C:BC:3D:8B:EF:31:60:85:5D:93:CB | 
|  | 108             X509v3 Authority Key Identifier: | 
|  | 109                 keyid:7F:47:C4:8B:61:FB:9B:52:F8:ED:91:43:F7:F6:97:C5:7B:5A:7B:9
     1 | 
|  | 110 | 
|  | 111             Authority Information Access: | 
|  | 112                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 113 | 
|  | 114             X509v3 CRL Distribution Points: | 
|  | 115 | 
|  | 116                 Full Name: | 
|  | 117                   URI:http://url-for-crl/Root.crl | 
|  | 118 | 
|  | 119             X509v3 Key Usage: critical | 
|  | 120                 Certificate Sign, CRL Sign | 
|  | 121             X509v3 Basic Constraints: critical | 
|  | 122                 CA:TRUE | 
|  | 123     Signature Algorithm: sha256WithRSAEncryption | 
|  | 124          31:2b:0c:29:b6:ef:68:6f:c5:57:71:67:0b:3a:a0:e5:cd:f5: | 
|  | 125          db:d9:a1:46:f0:1d:cd:f7:98:c7:6f:9f:00:57:dd:92:24:27: | 
|  | 126          12:f4:be:c4:1c:91:6a:f6:9e:b9:80:aa:f3:63:27:15:9a:ed: | 
|  | 127          4b:13:41:a9:c4:87:24:8f:57:d9:c0:9c:50:1a:09:b9:ce:db: | 
|  | 128          58:00:bf:de:be:98:2d:ed:ab:53:5f:5f:af:1b:c3:0e:40:a4: | 
|  | 129          1b:2a:66:fb:80:3c:a0:42:6f:ee:4c:da:de:5c:d8:fd:16:32: | 
|  | 130          9d:3e:25:76:91:a1:f3:88:b1:2d:d3:41:3d:49:f4:2f:59:68: | 
|  | 131          a9:b9:f5:d0:e6:cd:a9:a6:30:dc:25:14:14:84:02:e8:83:e0: | 
|  | 132          ac:6e:b3:e2:d2:70:fb:6f:dc:b8:3e:9b:85:77:d6:58:1e:bc: | 
|  | 133          0d:d2:d5:e2:77:9b:76:f6:1c:82:a1:f7:7a:0e:12:53:f9:de: | 
|  | 134          6e:8b:23:f2:ea:27:48:ff:a2:50:80:53:38:fe:cd:7a:e7:8a: | 
|  | 135          71:66:63:8c:5c:56:a8:87:93:1a:5f:35:ae:9c:18:71:04:99: | 
|  | 136          21:12:19:b3:ea:e1:a1:be:91:80:09:6c:39:03:ab:a9:91:e3: | 
|  | 137          39:06:74:55:e2:c5:f9:e1:7e:a0:1e:05:d2:c1:c1:ad:b0:15: | 
|  | 138          02:65:47:ff | 
|  | 139 -----BEGIN CERTIFICATE----- | 
|  | 140 MIICvzCCAaegAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 141 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 | 
|  | 142 ZXJtZWRpYXJ5MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEXK5jQlYeT6zx8SNLX61U | 
|  | 143 Dogmc55xPOR1myOIzXaDS11cAcL3DSkneNJYx8DFJY4ZYCA1/oVqN+kChy2TXO5U | 
|  | 144 ed5hfvaumoHGKyuvXf22mKkiPJE6dAQZY7daSAbc/yYgo4HLMIHIMB0GA1UdDgQW | 
|  | 145 BBTATpdbRPvN8IycvD2L7zFghV2TyzAfBgNVHSMEGDAWgBR/R8SLYfubUvjtkUP3 | 
|  | 146 9pfFe1p7kTA3BggrBgEFBQcBAQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwt | 
|  | 147 Zm9yLWFpYS9Sb290LmNlcjAsBgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZv | 
|  | 148 ci1jcmwvUm9vdC5jcmwwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8w | 
|  | 149 DQYJKoZIhvcNAQELBQADggEBADErDCm272hvxVdxZws6oOXN9dvZoUbwHc33mMdv | 
|  | 150 nwBX3ZIkJxL0vsQckWr2nrmAqvNjJxWa7UsTQanEhySPV9nAnFAaCbnO21gAv96+ | 
|  | 151 mC3tq1NfX68bww5ApBsqZvuAPKBCb+5M2t5c2P0WMp0+JXaRofOIsS3TQT1J9C9Z | 
|  | 152 aKm59dDmzammMNwlFBSEAuiD4Kxus+LScPtv3Lg+m4V31lgevA3S1eJ3m3b2HIKh | 
|  | 153 93oOElP53m6LI/LqJ0j/olCAUzj+zXrninFmY4xcVqiHkxpfNa6cGHEEmSESGbPq | 
|  | 154 4aG+kYAJbDkDq6mR4zkGdFXixfnhfqAeBdLBwa2wFQJlR/8= | 
|  | 155 -----END CERTIFICATE----- | 
|  | 156 | 
|  | 157 Certificate: | 
|  | 158     Data: | 
|  | 159         Version: 3 (0x2) | 
|  | 160         Serial Number: 1 (0x1) | 
|  | 161     Signature Algorithm: sha256WithRSAEncryption | 
|  | 162         Issuer: CN=Root | 
|  | 163         Validity | 
|  | 164             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 165             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 166         Subject: CN=Root | 
|  | 167         Subject Public Key Info: | 
|  | 168             Public Key Algorithm: rsaEncryption | 
|  | 169                 Public-Key: (2048 bit) | 
|  | 170                 Modulus: | 
|  | 171                     00:ba:62:02:ed:28:d0:81:6a:0a:43:cf:60:08:65: | 
|  | 172                     64:1e:0d:5d:04:5b:8f:84:e7:9e:22:aa:11:5c:b5: | 
|  | 173                     9f:d7:06:ed:95:55:35:dc:cf:d4:e3:11:4a:f7:ca: | 
|  | 174                     fa:8d:c8:ea:74:57:74:d9:92:48:a8:9a:b7:55:09: | 
|  | 175                     6d:8e:52:2b:8b:86:2a:63:7e:f6:f3:96:d8:df:0e: | 
|  | 176                     21:b2:e1:ba:dc:2f:9c:d3:35:7f:d8:7f:47:6b:e5: | 
|  | 177                     e5:d6:8c:42:4e:11:ac:9d:bd:5a:18:2b:40:0f:6c: | 
|  | 178                     c9:e6:21:66:8c:b1:9b:f9:ae:29:91:f0:24:de:e7: | 
|  | 179                     6f:7a:ce:2b:d3:f7:85:4a:a8:eb:86:55:79:38:33: | 
|  | 180                     68:d1:7e:ef:60:a5:d1:23:6e:49:18:12:df:58:62: | 
|  | 181                     2e:00:73:24:64:10:67:53:fb:61:74:0e:9d:17:ff: | 
|  | 182                     3b:69:30:96:32:bb:ba:d4:24:88:7d:4a:98:55:e7: | 
|  | 183                     ea:9f:3c:88:14:ce:8a:94:25:de:66:3c:86:0a:a3: | 
|  | 184                     16:fc:e9:f3:16:0f:d5:bc:e0:3c:bf:18:14:d2:28: | 
|  | 185                     6a:d6:1e:b4:3d:92:e1:e8:dd:48:f9:02:c6:67:ba: | 
|  | 186                     4b:a5:c9:80:b4:d4:ae:31:20:3a:4c:ba:29:f2:ff: | 
|  | 187                     b5:a1:d5:72:c2:62:f2:17:e8:5c:09:e4:21:8c:58: | 
|  | 188                     e3:b7 | 
|  | 189                 Exponent: 65537 (0x10001) | 
|  | 190         X509v3 extensions: | 
|  | 191             X509v3 Subject Key Identifier: | 
|  | 192                 7F:47:C4:8B:61:FB:9B:52:F8:ED:91:43:F7:F6:97:C5:7B:5A:7B:91 | 
|  | 193             X509v3 Authority Key Identifier: | 
|  | 194                 keyid:7F:47:C4:8B:61:FB:9B:52:F8:ED:91:43:F7:F6:97:C5:7B:5A:7B:9
     1 | 
|  | 195 | 
|  | 196             Authority Information Access: | 
|  | 197                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 198 | 
|  | 199             X509v3 CRL Distribution Points: | 
|  | 200 | 
|  | 201                 Full Name: | 
|  | 202                   URI:http://url-for-crl/Root.crl | 
|  | 203 | 
|  | 204             X509v3 Key Usage: critical | 
|  | 205                 Certificate Sign, CRL Sign | 
|  | 206             X509v3 Basic Constraints: critical | 
|  | 207                 CA:TRUE | 
|  | 208     Signature Algorithm: sha256WithRSAEncryption | 
|  | 209          98:1e:d9:01:bc:84:49:b2:5d:c8:4b:88:93:c0:ae:ba:d8:6b: | 
|  | 210          ad:3b:4f:2e:a0:09:10:d8:95:de:71:b9:7c:da:70:a0:2d:48: | 
|  | 211          91:6c:76:03:3a:28:ff:bb:25:a7:1f:bd:1f:48:22:67:34:de: | 
|  | 212          0b:ba:9a:cb:14:81:6d:27:c7:7e:b5:a6:72:8a:f2:aa:f6:8e: | 
|  | 213          51:b2:2f:03:ff:5d:36:de:89:96:40:b9:88:9e:07:2c:15:66: | 
|  | 214          50:17:47:f8:50:b5:77:0d:c9:e8:70:89:c5:59:8d:8a:2e:d3: | 
|  | 215          c5:e9:cc:28:ed:88:ac:69:53:a0:71:54:c6:3d:b1:a9:ad:0c: | 
|  | 216          a2:c7:8c:4d:b9:e7:4a:a1:14:d4:45:e4:1e:c0:95:4a:41:87: | 
|  | 217          bb:85:16:ce:a9:84:7a:7b:fa:2e:4e:e8:11:fa:2a:86:98:ba: | 
|  | 218          38:c6:97:15:84:68:cb:36:4c:08:19:e3:92:37:08:97:58:5e: | 
|  | 219          46:4c:04:56:2e:22:e9:62:84:a7:5e:5e:7e:67:d3:01:ea:fd: | 
|  | 220          1f:92:13:0a:64:b6:4b:ad:9e:ae:63:d0:bc:8e:f9:3e:52:d5: | 
|  | 221          61:25:a1:09:bf:f9:cb:4a:52:be:d5:e3:6f:19:0c:dc:13:4d: | 
|  | 222          1f:a7:b2:0e:d2:02:99:87:cb:f1:4e:e6:be:74:49:fe:e7:b8: | 
|  | 223          e8:74:41:03 | 
|  | 224 -----BEGIN TRUSTED_CERTIFICATE----- | 
|  | 225 MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 226 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v | 
|  | 227 dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALpiAu0o0IFqCkPPYAhl | 
|  | 228 ZB4NXQRbj4TnniKqEVy1n9cG7ZVVNdzP1OMRSvfK+o3I6nRXdNmSSKiat1UJbY5S | 
|  | 229 K4uGKmN+9vOW2N8OIbLhutwvnNM1f9h/R2vl5daMQk4RrJ29WhgrQA9syeYhZoyx | 
|  | 230 m/muKZHwJN7nb3rOK9P3hUqo64ZVeTgzaNF+72Cl0SNuSRgS31hiLgBzJGQQZ1P7 | 
|  | 231 YXQOnRf/O2kwljK7utQkiH1KmFXn6p88iBTOipQl3mY8hgqjFvzp8xYP1bzgPL8Y | 
|  | 232 FNIoatYetD2S4ejdSPkCxme6S6XJgLTUrjEgOky6KfL/taHVcsJi8hfoXAnkIYxY | 
|  | 233 47cCAwEAAaOByzCByDAdBgNVHQ4EFgQUf0fEi2H7m1L47ZFD9/aXxXtae5EwHwYD | 
|  | 234 VR0jBBgwFoAUf0fEi2H7m1L47ZFD9/aXxXtae5EwNwYIKwYBBQUHAQEEKzApMCcG | 
|  | 235 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw | 
|  | 236 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE | 
|  | 237 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCYHtkBvIRJ | 
|  | 238 sl3IS4iTwK662GutO08uoAkQ2JXecbl82nCgLUiRbHYDOij/uyWnH70fSCJnNN4L | 
|  | 239 uprLFIFtJ8d+taZyivKq9o5Rsi8D/1023omWQLmIngcsFWZQF0f4ULV3DcnocInF | 
|  | 240 WY2KLtPF6cwo7YisaVOgcVTGPbGprQyix4xNuedKoRTUReQewJVKQYe7hRbOqYR6 | 
|  | 241 e/ouTugR+iqGmLo4xpcVhGjLNkwIGeOSNwiXWF5GTARWLiLpYoSnXl5+Z9MB6v0f | 
|  | 242 khMKZLZLrZ6uY9C8jvk+UtVhJaEJv/nLSlK+1eNvGQzcE00fp7IO0gKZh8vxTua+ | 
|  | 243 dEn+57jodEED | 
|  | 244 -----END TRUSTED_CERTIFICATE----- | 
|  | 245 | 
|  | 246 -----BEGIN TIME----- | 
|  | 247 MTYwMzAyMTIwMDAwWg== | 
|  | 248 -----END TIME----- | 
|  | 249 | 
|  | 250 -----BEGIN VERIFY_RESULT----- | 
|  | 251 U1VDQ0VTUw== | 
|  | 252 -----END VERIFY_RESULT----- | 
| OLD | NEW | 
|---|