| OLD | NEW |
| (Empty) | |
| 1 [Created by: generate-intermediate-restricts-eku-fail.py] |
| 2 |
| 3 Certificate chain with 1 intermediate and a trusted root. The intermediate |
| 4 restricts the EKU to clientAuth, and the target has serverAuth + |
| 5 clientAuth. Verification is expected to fail when requesting serverAuth. |
| 6 |
| 7 Certificate: |
| 8 Data: |
| 9 Version: 3 (0x2) |
| 10 Serial Number: 1 (0x1) |
| 11 Signature Algorithm: sha256WithRSAEncryption |
| 12 Issuer: CN=Intermediate |
| 13 Validity |
| 14 Not Before: Jan 1 12:00:00 2015 GMT |
| 15 Not After : Jan 1 12:00:00 2016 GMT |
| 16 Subject: CN=Target |
| 17 Subject Public Key Info: |
| 18 Public Key Algorithm: rsaEncryption |
| 19 Public-Key: (2048 bit) |
| 20 Modulus: |
| 21 00:bb:d3:3c:f5:4c:df:73:61:c9:d0:be:56:b8:7f: |
| 22 e6:52:56:9c:3b:84:83:23:d8:ea:30:cb:cc:01:ba: |
| 23 1d:36:70:d3:4c:58:62:74:2f:96:57:7c:e5:b0:27: |
| 24 6f:fa:72:c0:5b:0b:0c:f6:ec:1e:3b:c7:04:45:b8: |
| 25 89:97:be:fa:49:27:b6:c2:0a:29:b8:98:cd:a4:a4: |
| 26 54:29:ce:55:c5:91:ff:89:d3:51:87:88:d0:c3:ef: |
| 27 0c:de:43:b0:e0:b9:d9:23:92:f0:04:42:b6:50:06: |
| 28 2b:1a:7b:97:3e:67:a4:ed:77:23:e5:83:76:76:63: |
| 29 09:6d:be:05:6e:fc:aa:a0:c8:91:97:97:2d:85:02: |
| 30 95:c2:fc:dd:dc:f4:4b:08:c3:be:3b:43:76:96:cc: |
| 31 ec:55:7a:0f:00:fe:29:4b:87:ca:df:50:ba:5c:60: |
| 32 e5:6f:8c:f0:56:7b:5b:20:3d:87:fd:81:7f:61:51: |
| 33 6c:44:61:55:3a:52:28:cf:49:4d:72:3f:34:b0:a3: |
| 34 04:18:e6:47:50:c7:f0:e1:a5:4f:8c:59:e3:73:ca: |
| 35 b6:a6:0d:34:a3:40:fb:41:97:8c:66:93:64:29:20: |
| 36 13:1b:f5:ab:69:74:11:88:13:8d:dc:15:c8:22:a2: |
| 37 2b:16:74:f2:f1:8b:27:c1:5a:9c:c5:0e:95:78:ba: |
| 38 fe:9f |
| 39 Exponent: 65537 (0x10001) |
| 40 X509v3 extensions: |
| 41 X509v3 Subject Key Identifier: |
| 42 6D:1B:79:D9:7C:01:F2:1D:99:D4:DD:54:90:BF:32:03:0F:28:4D:38 |
| 43 X509v3 Authority Key Identifier: |
| 44 keyid:3A:B9:4C:96:D7:3D:14:A8:24:C8:DE:55:0A:54:05:5D:5C:A2:C9:9
9 |
| 45 |
| 46 Authority Information Access: |
| 47 CA Issuers - URI:http://url-for-aia/Intermediate.cer |
| 48 |
| 49 X509v3 CRL Distribution Points: |
| 50 |
| 51 Full Name: |
| 52 URI:http://url-for-crl/Intermediate.crl |
| 53 |
| 54 X509v3 Key Usage: critical |
| 55 Digital Signature, Key Encipherment |
| 56 X509v3 Extended Key Usage: |
| 57 TLS Web Server Authentication, TLS Web Client Authentication |
| 58 Signature Algorithm: sha256WithRSAEncryption |
| 59 03:b3:7d:3a:ad:31:3c:23:cd:8f:44:99:81:8c:1a:72:a7:c9: |
| 60 da:24:74:8c:cf:00:59:8b:d6:38:d1:b0:64:e6:9b:bb:40:9a: |
| 61 d0:d0:ba:22:58:4d:a1:4d:16:7e:a9:dd:27:11:b5:69:31:5d: |
| 62 7d:cb:8d:26:16:76:3f:fc:f4:15:72:c0:50:32:88:2c:83:02: |
| 63 b6:6f:c3:e7:a0:93:53:f6:e5:e9:6b:bc:91:9c:18:3a:ae:4f: |
| 64 86:5b:b3:88:bd:1b:1e:29:cf:13:76:f8:5c:93:50:32:c5:a1: |
| 65 96:0a:fb:b9:66:53:a4:5a:e6:e8:fe:75:90:02:68:18:82:cf: |
| 66 0e:1f:37:6c:47:43:5d:4b:10:68:16:89:4a:59:f4:2a:62:1e: |
| 67 7c:7a:35:a2:5b:0e:72:f1:7b:62:d8:84:bd:ad:8c:1e:4d:71: |
| 68 d3:45:aa:2f:0c:46:bd:06:0f:88:38:14:11:d5:c6:e8:d8:82: |
| 69 f1:c0:b6:0a:f6:c7:d0:71:89:1c:4f:11:d2:ae:cc:ee:b6:39: |
| 70 01:69:46:69:8b:73:4f:d3:ad:2a:a8:be:49:7c:01:22:58:b9: |
| 71 d1:63:10:5f:19:d9:51:22:45:13:24:48:91:8a:00:9a:70:54: |
| 72 91:3a:ab:65:ef:63:b8:ce:48:1c:b7:9d:1a:a3:9c:9a:96:ce: |
| 73 51:3f:88:8e |
| 74 -----BEGIN CERTIFICATE----- |
| 75 MIIDjTCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl |
| 76 cm1lZGlhdGUwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD |
| 77 VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC70zz1 |
| 78 TN9zYcnQvla4f+ZSVpw7hIMj2Oowy8wBuh02cNNMWGJ0L5ZXfOWwJ2/6csBbCwz2 |
| 79 7B47xwRFuImXvvpJJ7bCCim4mM2kpFQpzlXFkf+J01GHiNDD7wzeQ7DgudkjkvAE |
| 80 QrZQBisae5c+Z6TtdyPlg3Z2YwltvgVu/KqgyJGXly2FApXC/N3c9EsIw747Q3aW |
| 81 zOxVeg8A/ilLh8rfULpcYOVvjPBWe1sgPYf9gX9hUWxEYVU6UijPSU1yPzSwowQY |
| 82 5kdQx/DhpU+MWeNzyramDTSjQPtBl4xmk2QpIBMb9atpdBGIE43cFcgioisWdPLx |
| 83 iyfBWpzFDpV4uv6fAgMBAAGjgekwgeYwHQYDVR0OBBYEFG0bedl8AfIdmdTdVJC/ |
| 84 MgMPKE04MB8GA1UdIwQYMBaAFDq5TJbXPRSoJMjeVQpUBV1cosmZMD8GCCsGAQUF |
| 85 BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk |
| 86 aWF0ZS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu |
| 87 dGVybWVkaWF0ZS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF |
| 88 BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAA7N9Oq0xPCPNj0SZgYwa |
| 89 cqfJ2iR0jM8AWYvWONGwZOabu0Ca0NC6IlhNoU0WfqndJxG1aTFdfcuNJhZ2P/z0 |
| 90 FXLAUDKILIMCtm/D56CTU/bl6Wu8kZwYOq5PhluziL0bHinPE3b4XJNQMsWhlgr7 |
| 91 uWZTpFrm6P51kAJoGILPDh83bEdDXUsQaBaJSln0KmIefHo1olsOcvF7YtiEva2M |
| 92 Hk1x00WqLwxGvQYPiDgUEdXG6NiC8cC2CvbH0HGJHE8R0q7M7rY5AWlGaYtzT9Ot |
| 93 Kqi+SXwBIli50WMQXxnZUSJFEyRIkYoAmnBUkTqrZe9juM5IHLedGqOcmpbOUT+I |
| 94 jg== |
| 95 -----END CERTIFICATE----- |
| 96 |
| 97 Certificate: |
| 98 Data: |
| 99 Version: 3 (0x2) |
| 100 Serial Number: 2 (0x2) |
| 101 Signature Algorithm: sha256WithRSAEncryption |
| 102 Issuer: CN=Root |
| 103 Validity |
| 104 Not Before: Jan 1 12:00:00 2015 GMT |
| 105 Not After : Jan 1 12:00:00 2016 GMT |
| 106 Subject: CN=Intermediate |
| 107 Subject Public Key Info: |
| 108 Public Key Algorithm: rsaEncryption |
| 109 Public-Key: (2048 bit) |
| 110 Modulus: |
| 111 00:bd:9a:08:67:72:a5:4d:ba:39:c4:0a:d5:a9:42: |
| 112 46:7a:a0:f3:f2:2b:1f:83:91:58:a7:00:3b:b3:17: |
| 113 51:e5:1f:83:13:44:10:14:7f:84:6d:97:57:de:32: |
| 114 00:bd:15:18:e4:c7:89:8b:6e:5b:41:51:ad:d3:c9: |
| 115 f7:3e:75:51:74:5c:71:40:2e:9b:95:be:8f:3b:17: |
| 116 33:a5:3a:33:17:97:05:d7:30:0c:40:94:c1:8d:e7: |
| 117 80:5f:f3:d4:3e:e4:46:8c:e3:80:ec:95:91:87:e0: |
| 118 a0:a3:32:73:6c:44:c2:9c:12:a5:d3:6b:91:e0:60: |
| 119 3d:a1:61:9d:09:6f:5f:7b:b1:c5:98:6a:3a:cc:85: |
| 120 76:45:f2:44:0e:3f:cf:b9:56:5a:23:55:68:31:4b: |
| 121 17:30:ad:a0:e2:b1:85:3f:6e:2e:7e:a7:38:b9:dd: |
| 122 cd:3d:fb:74:1a:83:87:c2:ec:ec:6a:63:0b:5e:c8: |
| 123 75:07:b5:4f:3f:93:58:a5:fe:3e:76:18:ee:16:df: |
| 124 b1:52:b8:1a:f0:77:65:a3:b7:2d:16:a3:e6:c8:11: |
| 125 67:e1:20:ea:2f:ed:0b:93:e6:c8:2a:a0:fc:34:b7: |
| 126 fa:4b:21:33:60:02:86:cf:b4:bd:f0:c7:ec:f5:7a: |
| 127 b4:ff:84:18:f4:73:a1:28:7a:31:de:08:b6:fd:be: |
| 128 0a:7d |
| 129 Exponent: 65537 (0x10001) |
| 130 X509v3 extensions: |
| 131 X509v3 Subject Key Identifier: |
| 132 3A:B9:4C:96:D7:3D:14:A8:24:C8:DE:55:0A:54:05:5D:5C:A2:C9:99 |
| 133 X509v3 Authority Key Identifier: |
| 134 keyid:AE:89:01:94:41:77:67:BD:EF:7F:98:4F:29:E7:1B:3A:18:B9:DD:5
1 |
| 135 |
| 136 Authority Information Access: |
| 137 CA Issuers - URI:http://url-for-aia/Root.cer |
| 138 |
| 139 X509v3 CRL Distribution Points: |
| 140 |
| 141 Full Name: |
| 142 URI:http://url-for-crl/Root.crl |
| 143 |
| 144 X509v3 Key Usage: critical |
| 145 Certificate Sign, CRL Sign |
| 146 X509v3 Basic Constraints: critical |
| 147 CA:TRUE |
| 148 X509v3 Extended Key Usage: |
| 149 TLS Web Client Authentication |
| 150 Signature Algorithm: sha256WithRSAEncryption |
| 151 48:57:46:43:a9:be:bb:bb:5c:b1:c1:42:cd:72:22:1e:34:98: |
| 152 8f:ae:c5:8f:88:72:3e:01:f4:9f:d0:2a:ed:6b:3a:32:22:e0: |
| 153 9e:be:2c:7d:5c:b8:01:98:d8:41:97:58:88:69:a1:1c:2d:c3: |
| 154 97:00:71:47:b8:f9:91:5d:66:b2:cd:e9:ec:3c:1a:70:b5:7a: |
| 155 ee:8e:88:d3:d6:c3:32:e7:11:c2:a5:8d:b4:01:2c:87:06:a5: |
| 156 c8:85:07:29:6c:1a:20:ee:5e:ca:6e:42:f0:89:f3:e9:d1:e8: |
| 157 cd:d6:4b:ef:b4:fc:10:be:ae:b8:4c:0d:b0:af:3d:72:4a:17: |
| 158 03:72:d5:aa:a4:30:bf:8d:6f:66:9f:19:fa:e0:c7:e4:fe:5c: |
| 159 30:53:95:8e:6a:87:59:bb:14:62:3a:1a:2f:24:87:c3:0c:8e: |
| 160 09:e7:e4:f1:3c:e3:03:e7:29:28:5d:b4:fd:a1:f7:8c:00:c5: |
| 161 8f:33:56:09:df:48:f8:d3:1e:cd:4a:b8:69:ac:81:65:3d:20: |
| 162 f3:d2:52:dd:44:e7:fa:f8:22:b4:fb:ec:8e:b9:27:a8:d9:12: |
| 163 69:bc:d0:6d:b6:45:41:c5:d6:fc:16:d0:47:da:b4:a3:75:f0: |
| 164 e2:fa:49:9d:5f:9c:64:ee:17:1d:1a:83:26:5d:e0:ad:fb:a8: |
| 165 74:70:30:08 |
| 166 -----BEGIN CERTIFICATE----- |
| 167 MIIDgjCCAmqgAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 |
| 168 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 |
| 169 ZXJtZWRpYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvZoIZ3Kl |
| 170 Tbo5xArVqUJGeqDz8isfg5FYpwA7sxdR5R+DE0QQFH+EbZdX3jIAvRUY5MeJi25b |
| 171 QVGt08n3PnVRdFxxQC6blb6POxczpTozF5cF1zAMQJTBjeeAX/PUPuRGjOOA7JWR |
| 172 h+CgozJzbETCnBKl02uR4GA9oWGdCW9fe7HFmGo6zIV2RfJEDj/PuVZaI1VoMUsX |
| 173 MK2g4rGFP24ufqc4ud3NPft0GoOHwuzsamMLXsh1B7VPP5NYpf4+dhjuFt+xUrga |
| 174 8Hdlo7ctFqPmyBFn4SDqL+0Lk+bIKqD8NLf6SyEzYAKGz7S98Mfs9Xq0/4QY9HOh |
| 175 KHox3gi2/b4KfQIDAQABo4HgMIHdMB0GA1UdDgQWBBQ6uUyW1z0UqCTI3lUKVAVd |
| 176 XKLJmTAfBgNVHSMEGDAWgBSuiQGUQXdnve9/mE8p5xs6GLndUTA3BggrBgEFBQcB |
| 177 AQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwtZm9yLWFpYS9Sb290LmNlcjAs |
| 178 BgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZvci1jcmwvUm9vdC5jcmwwDgYD |
| 179 VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wEwYDVR0lBAwwCgYIKwYBBQUH |
| 180 AwIwDQYJKoZIhvcNAQELBQADggEBAEhXRkOpvru7XLHBQs1yIh40mI+uxY+Icj4B |
| 181 9J/QKu1rOjIi4J6+LH1cuAGY2EGXWIhpoRwtw5cAcUe4+ZFdZrLN6ew8GnC1eu6O |
| 182 iNPWwzLnEcKljbQBLIcGpciFBylsGiDuXspuQvCJ8+nR6M3WS++0/BC+rrhMDbCv |
| 183 PXJKFwNy1aqkML+Nb2afGfrgx+T+XDBTlY5qh1m7FGI6Gi8kh8MMjgnn5PE84wPn |
| 184 KShdtP2h94wAxY8zVgnfSPjTHs1KuGmsgWU9IPPSUt1E5/r4IrT77I65J6jZEmm8 |
| 185 0G22RUHF1vwW0EfatKN18OL6SZ1fnGTuFx0agyZd4K37qHRwMAg= |
| 186 -----END CERTIFICATE----- |
| 187 |
| 188 Certificate: |
| 189 Data: |
| 190 Version: 3 (0x2) |
| 191 Serial Number: 1 (0x1) |
| 192 Signature Algorithm: sha256WithRSAEncryption |
| 193 Issuer: CN=Root |
| 194 Validity |
| 195 Not Before: Jan 1 12:00:00 2015 GMT |
| 196 Not After : Jan 1 12:00:00 2016 GMT |
| 197 Subject: CN=Root |
| 198 Subject Public Key Info: |
| 199 Public Key Algorithm: rsaEncryption |
| 200 Public-Key: (2048 bit) |
| 201 Modulus: |
| 202 00:b6:30:63:d8:b0:11:71:5f:03:38:e5:24:a7:88: |
| 203 9c:fe:f5:a6:2a:59:63:7b:18:39:d5:34:2f:27:4c: |
| 204 fe:18:27:eb:7e:71:25:4d:af:71:97:7f:f0:18:b0: |
| 205 19:a7:fd:ab:52:d9:01:aa:13:ff:3f:c9:c8:d4:87: |
| 206 fa:69:53:28:b7:52:4f:91:ac:55:cb:38:7f:61:32: |
| 207 b6:d9:20:f4:58:6f:c3:4c:4f:64:d7:14:34:8c:d3: |
| 208 ac:f5:97:8a:9d:f6:d0:0b:64:b4:3a:55:71:0b:92: |
| 209 b1:8e:df:2e:77:8a:fe:36:f6:0f:be:49:03:3d:42: |
| 210 fc:4c:e4:50:f6:3e:86:d0:e4:0b:15:cd:27:49:ae: |
| 211 7a:be:d7:05:28:68:f7:e7:35:1b:fc:2a:50:c1:66: |
| 212 f3:31:11:f3:f9:40:80:51:3a:60:9a:87:47:fc:46: |
| 213 99:e3:1a:c9:5c:76:d9:34:45:b0:82:d6:06:d7:ea: |
| 214 5d:13:ce:ca:4e:9d:2e:80:cd:b3:5c:47:11:dd:f1: |
| 215 8a:97:c7:8d:37:6a:1a:c7:97:13:ad:bf:9c:85:32: |
| 216 df:20:0a:a9:27:3b:e6:26:c6:9d:98:d3:d1:d7:a0: |
| 217 16:4d:b1:a3:3b:1f:19:c3:c5:81:dd:35:25:3c:86: |
| 218 8e:8b:76:69:f2:e5:35:5e:3c:6c:3f:7e:47:57:7f: |
| 219 eb:0d |
| 220 Exponent: 65537 (0x10001) |
| 221 X509v3 extensions: |
| 222 X509v3 Subject Key Identifier: |
| 223 AE:89:01:94:41:77:67:BD:EF:7F:98:4F:29:E7:1B:3A:18:B9:DD:51 |
| 224 X509v3 Authority Key Identifier: |
| 225 keyid:AE:89:01:94:41:77:67:BD:EF:7F:98:4F:29:E7:1B:3A:18:B9:DD:5
1 |
| 226 |
| 227 Authority Information Access: |
| 228 CA Issuers - URI:http://url-for-aia/Root.cer |
| 229 |
| 230 X509v3 CRL Distribution Points: |
| 231 |
| 232 Full Name: |
| 233 URI:http://url-for-crl/Root.crl |
| 234 |
| 235 X509v3 Key Usage: critical |
| 236 Certificate Sign, CRL Sign |
| 237 X509v3 Basic Constraints: critical |
| 238 CA:TRUE |
| 239 Signature Algorithm: sha256WithRSAEncryption |
| 240 3e:0f:33:42:25:43:7e:e0:36:64:99:cc:4d:38:94:6e:26:40: |
| 241 50:7d:78:af:88:41:6b:44:4c:55:db:3e:11:2d:d3:67:94:79: |
| 242 d6:7e:bc:e1:23:9b:2a:a4:a7:ad:3d:a9:fe:86:3e:3d:81:98: |
| 243 7c:0f:21:60:a4:65:13:83:a3:c4:4d:12:d8:d5:52:3f:ad:de: |
| 244 29:f5:ee:dc:31:ef:56:85:ce:7a:b4:05:f4:95:6e:ba:ce:ac: |
| 245 09:19:49:eb:8e:ea:c6:dd:13:dd:15:b7:53:7b:44:67:ab:4d: |
| 246 b7:41:c6:4e:de:f7:ca:bb:cc:7a:fb:84:ec:31:f6:ac:9e:26: |
| 247 83:74:cf:4f:a9:6a:dd:dd:68:28:f7:13:2e:54:42:ea:39:8d: |
| 248 44:51:3d:2e:05:11:63:81:0b:a8:82:96:72:ff:bb:45:a6:e7: |
| 249 9b:f3:03:24:d0:21:e4:67:2b:a8:d9:61:aa:ab:9b:b9:f0:3f: |
| 250 b7:16:fc:7b:32:dc:4a:33:e8:a3:d3:79:f5:fc:16:6e:95:23: |
| 251 a5:ec:a7:75:76:ff:ff:8f:6b:c4:32:d2:4d:e7:45:2c:1d:7e: |
| 252 8a:76:28:dd:e6:01:e1:f0:f9:45:5b:91:7c:0a:92:90:be:1b: |
| 253 9c:0c:1f:b9:24:df:d2:f7:f5:fa:8c:76:cd:00:01:73:35:04: |
| 254 a7:08:6a:dd |
| 255 -----BEGIN TRUST_ANCHOR_UNCONSTRAINED----- |
| 256 MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 |
| 257 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v |
| 258 dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALYwY9iwEXFfAzjlJKeI |
| 259 nP71pipZY3sYOdU0LydM/hgn635xJU2vcZd/8BiwGaf9q1LZAaoT/z/JyNSH+mlT |
| 260 KLdST5GsVcs4f2Eyttkg9Fhvw0xPZNcUNIzTrPWXip320AtktDpVcQuSsY7fLneK |
| 261 /jb2D75JAz1C/EzkUPY+htDkCxXNJ0muer7XBSho9+c1G/wqUMFm8zER8/lAgFE6 |
| 262 YJqHR/xGmeMayVx22TRFsILWBtfqXRPOyk6dLoDNs1xHEd3xipfHjTdqGseXE62/ |
| 263 nIUy3yAKqSc75ibGnZjT0degFk2xozsfGcPFgd01JTyGjot2afLlNV48bD9+R1d/ |
| 264 6w0CAwEAAaOByzCByDAdBgNVHQ4EFgQUrokBlEF3Z73vf5hPKecbOhi53VEwHwYD |
| 265 VR0jBBgwFoAUrokBlEF3Z73vf5hPKecbOhi53VEwNwYIKwYBBQUHAQEEKzApMCcG |
| 266 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw |
| 267 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE |
| 268 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQA+DzNCJUN+ |
| 269 4DZkmcxNOJRuJkBQfXiviEFrRExV2z4RLdNnlHnWfrzhI5sqpKetPan+hj49gZh8 |
| 270 DyFgpGUTg6PETRLY1VI/rd4p9e7cMe9Whc56tAX0lW66zqwJGUnrjurG3RPdFbdT |
| 271 e0Rnq023QcZO3vfKu8x6+4TsMfasniaDdM9PqWrd3Wgo9xMuVELqOY1EUT0uBRFj |
| 272 gQuogpZy/7tFpueb8wMk0CHkZyuo2WGqq5u58D+3Fvx7MtxKM+ij03n1/BZulSOl |
| 273 7Kd1dv//j2vEMtJN50UsHX6Kdijd5gHh8PlFW5F8CpKQvhucDB+5JN/S9/X6jHbN |
| 274 AAFzNQSnCGrd |
| 275 -----END TRUST_ANCHOR_UNCONSTRAINED----- |
| 276 |
| 277 150302120000Z |
| 278 -----BEGIN TIME----- |
| 279 MTUwMzAyMTIwMDAwWg== |
| 280 -----END TIME----- |
| 281 |
| 282 FAIL |
| 283 -----BEGIN VERIFY_RESULT----- |
| 284 RkFJTA== |
| 285 -----END VERIFY_RESULT----- |
| 286 |
| 287 serverAuth |
| 288 -----BEGIN KEY_PURPOSE----- |
| 289 c2VydmVyQXV0aA== |
| 290 -----END KEY_PURPOSE----- |
| 291 |
| 292 ----- Certificate i=1 (CN=Intermediate) ----- |
| 293 ERROR: The extended key usage does not include server auth |
| 294 |
| 295 |
| 296 -----BEGIN ERRORS----- |
| 297 LS0tLS0gQ2VydGlmaWNhdGUgaT0xIChDTj1JbnRlcm1lZGlhdGUpIC0tLS0tCkVSUk9SOiBUaGUgZXh0
ZW5kZWQga2V5IHVzYWdlIGRvZXMgbm90IGluY2x1ZGUgc2VydmVyIGF1dGgKCg== |
| 298 -----END ERRORS----- |
| OLD | NEW |