| OLD | NEW |
| (Empty) | |
| 1 [Created by: generate-unknown-root.py] |
| 2 |
| 3 Certificate chain with 1 intermediary, but the root is not in trust store. |
| 4 Verification is expected to fail because the final intermediary (Intermediary) |
| 5 does not chain to a known root. |
| 6 |
| 7 Certificate: |
| 8 Data: |
| 9 Version: 3 (0x2) |
| 10 Serial Number: 1 (0x1) |
| 11 Signature Algorithm: sha256WithRSAEncryption |
| 12 Issuer: CN=Intermediary |
| 13 Validity |
| 14 Not Before: Jan 1 12:00:00 2015 GMT |
| 15 Not After : Jan 1 12:00:00 2016 GMT |
| 16 Subject: CN=Target |
| 17 Subject Public Key Info: |
| 18 Public Key Algorithm: rsaEncryption |
| 19 Public-Key: (2048 bit) |
| 20 Modulus: |
| 21 00:f3:f6:f4:c5:f5:4f:a3:17:ee:19:45:0e:97:90: |
| 22 31:60:2a:a5:31:0d:e4:c7:f4:fa:4d:e4:99:f5:3c: |
| 23 db:ad:6b:2d:f2:8d:07:4f:dc:c1:e3:3f:53:b6:48: |
| 24 31:8e:8e:a6:b3:d6:a4:3c:fb:21:00:01:a6:35:79: |
| 25 50:a6:d0:43:10:8d:13:1b:6f:a9:4b:a3:9b:77:11: |
| 26 af:0f:7c:f9:f0:e6:03:c5:b5:b4:49:7a:9d:8f:a1: |
| 27 42:89:a5:41:5d:c7:e1:7d:4a:e5:af:8f:66:ad:93: |
| 28 b0:f6:60:52:f4:0c:2d:d1:60:ca:a4:4c:fa:0d:55: |
| 29 0d:46:60:69:10:a7:8e:06:bd:ad:28:65:63:a5:63: |
| 30 36:d8:eb:8e:e1:cc:fd:53:76:80:d3:1d:e2:b8:46: |
| 31 f9:24:e7:3a:86:30:f9:14:34:a2:42:81:b7:2b:a4: |
| 32 41:14:7a:9c:77:83:51:cb:b9:08:31:29:a2:b0:25: |
| 33 92:1e:7f:43:90:1c:6a:43:ca:64:04:37:c8:26:b7: |
| 34 7b:ae:cb:8b:2e:e7:6f:09:c4:3e:87:0d:b1:ef:70: |
| 35 58:cd:b5:d7:c7:6b:dd:7b:3c:46:0c:4d:5f:21:1d: |
| 36 78:b9:cf:46:5e:f8:35:48:7d:14:0b:3e:a4:2a:1c: |
| 37 4e:78:6d:27:76:61:e5:c5:74:16:fb:f1:77:9c:f3: |
| 38 51:7f |
| 39 Exponent: 65537 (0x10001) |
| 40 X509v3 extensions: |
| 41 X509v3 Subject Key Identifier: |
| 42 F8:48:56:E7:65:49:C4:48:98:8E:F0:F5:EA:01:C4:01:C8:4D:56:D9 |
| 43 X509v3 Authority Key Identifier: |
| 44 keyid:41:D3:BE:10:2F:EE:43:B6:25:B0:04:4E:39:CF:78:F9:0E:ED:E1:9
D |
| 45 |
| 46 Authority Information Access: |
| 47 CA Issuers - URI:http://url-for-aia/Intermediary.cer |
| 48 |
| 49 X509v3 CRL Distribution Points: |
| 50 |
| 51 Full Name: |
| 52 URI:http://url-for-crl/Intermediary.crl |
| 53 |
| 54 X509v3 Key Usage: critical |
| 55 Digital Signature, Key Encipherment |
| 56 X509v3 Extended Key Usage: |
| 57 TLS Web Server Authentication, TLS Web Client Authentication |
| 58 Signature Algorithm: sha256WithRSAEncryption |
| 59 48:65:f4:55:86:82:85:93:a0:4d:b0:ce:b8:b2:21:f5:bf:56: |
| 60 66:ef:e3:f5:24:52:da:a5:15:21:f7:b4:a1:7c:2f:69:de:1e: |
| 61 6a:90:8d:98:e9:38:29:b8:51:44:7b:43:68:92:95:e4:50:7c: |
| 62 32:94:72:6c:96:4a:77:07:ce:0c:55:df:19:50:29:e5:ee:ff: |
| 63 c4:54:c9:75:2d:c2:fd:f1:41:5c:c4:28:3c:15:df:1a:12:73: |
| 64 aa:a6:af:2a:3e:f5:a6:17:68:5b:80:d8:6d:fa:6d:37:26:a1: |
| 65 01:0e:0a:c1:a8:ed:ef:2b:65:1c:43:4d:dd:aa:7b:e1:6d:a6: |
| 66 a6:23:66:11:58:73:f0:e2:98:d2:ba:db:94:ed:c9:fc:41:6f: |
| 67 4b:99:7c:be:2e:e9:57:e2:c6:26:24:db:2a:02:4e:3c:7e:8b: |
| 68 d8:96:27:43:7b:b4:1e:25:2f:19:c0:e4:05:b9:5e:0e:57:29: |
| 69 9e:81:9c:1e:d8:48:4b:d0:c8:ff:1a:a7:7f:71:4a:9f:51:0d: |
| 70 8a:11:6e:74:86:8e:89:d8:fd:a4:69:bb:67:78:2d:2d:44:75: |
| 71 9b:63:31:ef:b1:3e:38:11:ce:01:ae:b0:fa:a4:3f:b0:df:be: |
| 72 13:9a:5e:11:f6:bb:eb:8e:3a:7d:09:be:76:9b:e5:d4:91:f3: |
| 73 dc:e5:23:df |
| 74 -----BEGIN CERTIFICATE----- |
| 75 MIIDjTCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl |
| 76 cm1lZGlhcnkwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD |
| 77 VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDz9vTF |
| 78 9U+jF+4ZRQ6XkDFgKqUxDeTH9PpN5Jn1PNutay3yjQdP3MHjP1O2SDGOjqaz1qQ8 |
| 79 +yEAAaY1eVCm0EMQjRMbb6lLo5t3Ea8PfPnw5gPFtbRJep2PoUKJpUFdx+F9SuWv |
| 80 j2atk7D2YFL0DC3RYMqkTPoNVQ1GYGkQp44Gva0oZWOlYzbY647hzP1TdoDTHeK4 |
| 81 Rvkk5zqGMPkUNKJCgbcrpEEUepx3g1HLuQgxKaKwJZIef0OQHGpDymQEN8gmt3uu |
| 82 y4su528JxD6HDbHvcFjNtdfHa917PEYMTV8hHXi5z0Ze+DVIfRQLPqQqHE54bSd2 |
| 83 YeXFdBb78Xec81F/AgMBAAGjgekwgeYwHQYDVR0OBBYEFPhIVudlScRImI7w9eoB |
| 84 xAHITVbZMB8GA1UdIwQYMBaAFEHTvhAv7kO2JbAETjnPePkO7eGdMD8GCCsGAQUF |
| 85 BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk |
| 86 aWFyeS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu |
| 87 dGVybWVkaWFyeS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF |
| 88 BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEASGX0VYaChZOgTbDOuLIh |
| 89 9b9WZu/j9SRS2qUVIfe0oXwvad4eapCNmOk4KbhRRHtDaJKV5FB8MpRybJZKdwfO |
| 90 DFXfGVAp5e7/xFTJdS3C/fFBXMQoPBXfGhJzqqavKj71phdoW4DYbfptNyahAQ4K |
| 91 wajt7ytlHENN3ap74W2mpiNmEVhz8OKY0rrblO3J/EFvS5l8vi7pV+LGJiTbKgJO |
| 92 PH6L2JYnQ3u0HiUvGcDkBbleDlcpnoGcHthIS9DI/xqnf3FKn1ENihFudIaOidj9 |
| 93 pGm7Z3gtLUR1m2Mx77E+OBHOAa6w+qQ/sN++E5peEfa76446fQm+dpvl1JHz3OUj |
| 94 3w== |
| 95 -----END CERTIFICATE----- |
| 96 |
| 97 Certificate: |
| 98 Data: |
| 99 Version: 3 (0x2) |
| 100 Serial Number: 2 (0x2) |
| 101 Signature Algorithm: sha256WithRSAEncryption |
| 102 Issuer: CN=Root |
| 103 Validity |
| 104 Not Before: Jan 1 12:00:00 2015 GMT |
| 105 Not After : Jan 1 12:00:00 2016 GMT |
| 106 Subject: CN=Intermediary |
| 107 Subject Public Key Info: |
| 108 Public Key Algorithm: rsaEncryption |
| 109 Public-Key: (2048 bit) |
| 110 Modulus: |
| 111 00:cd:6f:e8:b3:ea:d4:9e:d9:23:03:8a:4a:f3:6c: |
| 112 84:cd:0c:28:7c:c2:07:60:89:c5:9a:9f:74:b8:d0: |
| 113 ac:e4:30:f1:4b:1c:c5:7f:9d:d2:0f:4e:e0:e5:45: |
| 114 4a:cc:93:70:a0:df:3c:4c:fc:0c:a5:d5:c9:86:fd: |
| 115 ba:4e:67:c0:af:c3:04:98:cb:bb:f6:25:a6:af:7f: |
| 116 7b:a3:29:b9:86:60:87:80:67:90:ab:e7:64:86:ec: |
| 117 e6:30:f6:dd:5b:3a:69:4f:b1:58:f8:4b:15:ae:13: |
| 118 c8:84:24:bf:9a:a0:6c:8a:b3:36:31:84:2f:a4:3e: |
| 119 4a:f2:9f:07:91:a4:8b:dc:fa:5b:65:3c:4e:93:19: |
| 120 02:a5:3a:78:5d:f2:51:bd:d7:96:16:6e:c5:8b:17: |
| 121 d0:21:77:2f:96:4a:44:c8:17:2d:73:d5:da:24:40: |
| 122 d1:a4:b7:f2:c4:b2:e2:16:6a:19:9b:72:cb:58:62: |
| 123 eb:30:2f:2f:c5:35:1c:74:2f:ba:e6:93:7e:dc:78: |
| 124 bc:ad:e3:89:c9:72:9a:f5:01:95:61:02:9f:82:40: |
| 125 f9:c1:c8:6e:36:b7:14:4a:13:36:bb:d0:1b:25:bd: |
| 126 d6:5e:11:e7:d9:ea:a7:db:6d:d3:92:98:b1:2a:c1: |
| 127 cf:00:52:c1:78:c9:0a:30:41:30:09:c8:90:0a:04: |
| 128 8f:0d |
| 129 Exponent: 65537 (0x10001) |
| 130 X509v3 extensions: |
| 131 X509v3 Subject Key Identifier: |
| 132 41:D3:BE:10:2F:EE:43:B6:25:B0:04:4E:39:CF:78:F9:0E:ED:E1:9D |
| 133 X509v3 Authority Key Identifier: |
| 134 keyid:A7:80:43:01:58:B0:DD:7A:AD:7C:38:10:73:02:DE:2C:E6:E4:9E:A
9 |
| 135 |
| 136 Authority Information Access: |
| 137 CA Issuers - URI:http://url-for-aia/Root.cer |
| 138 |
| 139 X509v3 CRL Distribution Points: |
| 140 |
| 141 Full Name: |
| 142 URI:http://url-for-crl/Root.crl |
| 143 |
| 144 X509v3 Key Usage: critical |
| 145 Certificate Sign, CRL Sign |
| 146 X509v3 Basic Constraints: critical |
| 147 CA:TRUE |
| 148 Signature Algorithm: sha256WithRSAEncryption |
| 149 90:b6:a5:85:fe:d4:51:b9:f7:92:ae:60:80:ab:54:09:3d:63: |
| 150 43:fd:ce:e0:ea:e3:f2:c0:db:f5:1b:a7:db:f1:b3:21:d0:e4: |
| 151 7f:63:c1:75:13:ca:3d:6b:70:76:55:23:cc:c8:74:80:b8:82: |
| 152 c0:cd:63:41:77:4c:27:8a:32:34:f7:9d:8d:0e:9f:15:ee:22: |
| 153 4f:ed:d7:32:f2:c9:95:bd:35:87:d8:c5:58:19:ba:06:58:a4: |
| 154 96:bc:2d:4e:1b:ed:2f:23:ac:b1:2f:b7:e0:88:a9:fc:68:c0: |
| 155 8d:8a:41:e6:d3:ba:b9:88:77:54:37:5a:e5:a9:b3:f2:85:7b: |
| 156 b4:7d:69:83:37:81:12:54:21:4c:d1:69:98:a2:fd:ef:a3:65: |
| 157 e9:32:f6:63:1e:54:ce:a9:75:74:53:61:b4:f0:78:72:c4:f0: |
| 158 04:f0:f3:a8:70:93:f6:35:89:0f:6f:49:7a:0e:57:e0:af:33: |
| 159 35:89:b6:cd:ef:81:aa:8c:10:11:e9:57:a1:66:4c:30:9c:11: |
| 160 6a:c6:85:4b:d1:94:88:6e:aa:5f:8e:fb:d2:31:3d:ee:19:19: |
| 161 01:3c:4a:05:72:9c:aa:ae:ef:af:b0:f1:9f:e0:ae:d6:8e:09: |
| 162 d1:05:ee:6b:77:08:11:52:8c:91:a0:2f:9b:ac:88:98:14:14: |
| 163 a4:08:b5:7d |
| 164 -----BEGIN CERTIFICATE----- |
| 165 MIIDbTCCAlWgAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 |
| 166 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 |
| 167 ZXJtZWRpYXJ5MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzW/os+rU |
| 168 ntkjA4pK82yEzQwofMIHYInFmp90uNCs5DDxSxzFf53SD07g5UVKzJNwoN88TPwM |
| 169 pdXJhv26TmfAr8MEmMu79iWmr397oym5hmCHgGeQq+dkhuzmMPbdWzppT7FY+EsV |
| 170 rhPIhCS/mqBsirM2MYQvpD5K8p8HkaSL3PpbZTxOkxkCpTp4XfJRvdeWFm7FixfQ |
| 171 IXcvlkpEyBctc9XaJEDRpLfyxLLiFmoZm3LLWGLrMC8vxTUcdC+65pN+3Hi8reOJ |
| 172 yXKa9QGVYQKfgkD5wchuNrcUShM2u9AbJb3WXhHn2eqn223TkpixKsHPAFLBeMkK |
| 173 MEEwCciQCgSPDQIDAQABo4HLMIHIMB0GA1UdDgQWBBRB074QL+5DtiWwBE45z3j5 |
| 174 Du3hnTAfBgNVHSMEGDAWgBSngEMBWLDdeq18OBBzAt4s5uSeqTA3BggrBgEFBQcB |
| 175 AQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwtZm9yLWFpYS9Sb290LmNlcjAs |
| 176 BgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZvci1jcmwvUm9vdC5jcmwwDgYD |
| 177 VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEB |
| 178 AJC2pYX+1FG595KuYICrVAk9Y0P9zuDq4/LA2/Ubp9vxsyHQ5H9jwXUTyj1rcHZV |
| 179 I8zIdIC4gsDNY0F3TCeKMjT3nY0OnxXuIk/t1zLyyZW9NYfYxVgZugZYpJa8LU4b |
| 180 7S8jrLEvt+CIqfxowI2KQebTurmId1Q3WuWps/KFe7R9aYM3gRJUIUzRaZii/e+j |
| 181 Zeky9mMeVM6pdXRTYbTweHLE8ATw86hwk/Y1iQ9vSXoOV+CvMzWJts3vgaqMEBHp |
| 182 V6FmTDCcEWrGhUvRlIhuql+O+9IxPe4ZGQE8SgVynKqu76+w8Z/grtaOCdEF7mt3 |
| 183 CBFSjJGgL5usiJgUFKQItX0= |
| 184 -----END CERTIFICATE----- |
| 185 |
| 186 -----BEGIN TIME----- |
| 187 MTUwMzAyMTIwMDAwWg== |
| 188 -----END TIME----- |
| 189 |
| 190 -----BEGIN VERIFY_RESULT----- |
| 191 RkFJTA== |
| 192 -----END VERIFY_RESULT----- |
| OLD | NEW |