| OLD | NEW |
| (Empty) | |
| 1 [Created by: generate-intermediate-restricts-eku-fail.py] |
| 2 |
| 3 Certificate chain with 1 intermediate and a trusted root. The intermediate |
| 4 restricts the EKU to clientAuth, and the target has serverAuth + |
| 5 clientAuth. Verification is expected to fail when requesting serverAuth. |
| 6 |
| 7 Certificate: |
| 8 Data: |
| 9 Version: 3 (0x2) |
| 10 Serial Number: 1 (0x1) |
| 11 Signature Algorithm: sha256WithRSAEncryption |
| 12 Issuer: CN=Intermediate |
| 13 Validity |
| 14 Not Before: Jan 1 12:00:00 2015 GMT |
| 15 Not After : Jan 1 12:00:00 2016 GMT |
| 16 Subject: CN=Target |
| 17 Subject Public Key Info: |
| 18 Public Key Algorithm: rsaEncryption |
| 19 Public-Key: (2048 bit) |
| 20 Modulus: |
| 21 00:cf:f7:e3:6e:d2:f5:a5:82:0a:07:7e:24:03:7c: |
| 22 9b:9d:d8:c1:b2:be:05:f6:4d:aa:ca:f1:96:0f:b5: |
| 23 c2:ca:7a:15:d5:ee:85:9a:d8:fd:7c:c4:c8:82:79: |
| 24 29:c2:6c:a9:99:85:a3:d8:d1:8f:b9:48:c4:0f:0e: |
| 25 c7:09:26:3a:7c:26:df:44:12:5b:90:37:33:f4:18: |
| 26 f6:0c:6e:5f:88:68:fc:c7:a6:27:5e:74:ba:5c:f2: |
| 27 f7:d1:c2:10:cd:4f:cf:87:c8:cf:87:ca:78:81:65: |
| 28 76:29:a0:99:73:d7:7e:a7:f8:ce:a8:cc:36:d8:c7: |
| 29 ab:ed:d0:27:bb:ae:e5:8b:1e:0e:23:df:be:db:12: |
| 30 1b:f6:13:da:3e:e9:c4:2c:5d:8c:9c:05:ea:0e:fc: |
| 31 40:1f:f8:cd:d0:19:1e:6c:20:b2:23:cf:34:df:c6: |
| 32 de:50:76:36:3d:17:5b:97:83:78:69:12:e7:25:d3: |
| 33 6b:1a:93:f4:b3:2f:74:e2:a5:f4:eb:3d:94:93:39: |
| 34 e8:c8:3d:61:eb:dc:15:9c:c3:14:00:44:3a:40:5e: |
| 35 3e:5d:d7:26:0b:0b:4e:53:a5:06:7a:08:d4:72:50: |
| 36 bd:6b:19:0d:df:e8:0d:ff:4f:02:c8:7b:7f:4c:10: |
| 37 c3:27:f0:ba:87:5d:0c:b8:84:ce:01:6f:13:2c:36: |
| 38 57:79 |
| 39 Exponent: 65537 (0x10001) |
| 40 X509v3 extensions: |
| 41 X509v3 Subject Key Identifier: |
| 42 7C:9E:F1:64:89:5B:67:9E:D7:9D:C0:BD:DB:6E:5D:A9:B8:EE:DC:02 |
| 43 X509v3 Authority Key Identifier: |
| 44 keyid:24:2F:F9:FF:60:7F:92:42:26:05:1A:A0:3C:F7:68:69:14:93:17:F
2 |
| 45 |
| 46 Authority Information Access: |
| 47 CA Issuers - URI:http://url-for-aia/Intermediate.cer |
| 48 |
| 49 X509v3 CRL Distribution Points: |
| 50 |
| 51 Full Name: |
| 52 URI:http://url-for-crl/Intermediate.crl |
| 53 |
| 54 X509v3 Key Usage: critical |
| 55 Digital Signature, Key Encipherment |
| 56 X509v3 Extended Key Usage: |
| 57 TLS Web Server Authentication, TLS Web Client Authentication |
| 58 Signature Algorithm: sha256WithRSAEncryption |
| 59 57:46:35:53:66:08:34:e9:27:17:7e:2a:c8:35:fe:f4:37:fd: |
| 60 39:ec:22:cc:20:37:50:eb:41:09:54:e8:5a:9a:50:9f:e0:e2: |
| 61 6b:5b:bb:d0:78:75:42:64:db:b4:65:ab:bc:93:80:f6:0f:49: |
| 62 84:1f:1a:fd:65:51:b1:d6:25:13:27:0b:15:69:d1:60:52:bc: |
| 63 f2:cf:4a:ff:f0:eb:1a:0b:63:37:48:87:3f:53:c5:58:0a:2d: |
| 64 01:08:29:0e:e5:d9:92:87:7c:79:aa:d8:c2:1e:47:d3:74:d5: |
| 65 e1:78:9f:91:fa:b1:dd:7d:dd:77:8f:11:fc:74:26:ae:bd:1c: |
| 66 c2:a5:09:ad:42:d3:66:7b:14:6b:ff:5f:3c:a0:1d:b0:3e:a0: |
| 67 60:29:3e:0a:80:c3:d4:4b:32:4f:30:29:d4:4f:a7:e8:93:e8: |
| 68 3e:4c:6e:0e:0b:ed:b6:71:9f:93:0a:b6:06:38:2c:61:34:8f: |
| 69 be:1b:a3:5e:aa:f1:f9:76:71:6e:2a:ea:bd:48:76:58:5f:60: |
| 70 8b:31:93:cc:f9:35:6d:99:9d:5a:b8:4c:a5:78:0e:bb:87:8a: |
| 71 18:dc:ce:7c:50:06:aa:c6:3f:e1:0b:f9:0a:b3:f5:31:dd:ee: |
| 72 98:cd:63:e0:44:52:47:d6:60:53:6b:95:9e:89:de:59:e3:f0: |
| 73 2c:68:1a:5d |
| 74 -----BEGIN CERTIFICATE----- |
| 75 MIIDjTCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl |
| 76 cm1lZGlhdGUwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD |
| 77 VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDP9+Nu |
| 78 0vWlggoHfiQDfJud2MGyvgX2TarK8ZYPtcLKehXV7oWa2P18xMiCeSnCbKmZhaPY |
| 79 0Y+5SMQPDscJJjp8Jt9EEluQNzP0GPYMbl+IaPzHpidedLpc8vfRwhDNT8+HyM+H |
| 80 yniBZXYpoJlz136n+M6ozDbYx6vt0Ce7ruWLHg4j377bEhv2E9o+6cQsXYycBeoO |
| 81 /EAf+M3QGR5sILIjzzTfxt5QdjY9F1uXg3hpEucl02sak/SzL3TipfTrPZSTOejI |
| 82 PWHr3BWcwxQARDpAXj5d1yYLC05TpQZ6CNRyUL1rGQ3f6A3/TwLIe39MEMMn8LqH |
| 83 XQy4hM4BbxMsNld5AgMBAAGjgekwgeYwHQYDVR0OBBYEFHye8WSJW2ee153Avdtu |
| 84 Xam47twCMB8GA1UdIwQYMBaAFCQv+f9gf5JCJgUaoDz3aGkUkxfyMD8GCCsGAQUF |
| 85 BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk |
| 86 aWF0ZS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu |
| 87 dGVybWVkaWF0ZS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF |
| 88 BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAV0Y1U2YINOknF34qyDX+ |
| 89 9Df9OewizCA3UOtBCVToWppQn+Dia1u70Hh1QmTbtGWrvJOA9g9JhB8a/WVRsdYl |
| 90 EycLFWnRYFK88s9K//DrGgtjN0iHP1PFWAotAQgpDuXZkod8earYwh5H03TV4Xif |
| 91 kfqx3X3dd48R/HQmrr0cwqUJrULTZnsUa/9fPKAdsD6gYCk+CoDD1EsyTzAp1E+n |
| 92 6JPoPkxuDgvttnGfkwq2BjgsYTSPvhujXqrx+XZxbirqvUh2WF9gizGTzPk1bZmd |
| 93 WrhMpXgOu4eKGNzOfFAGqsY/4Qv5CrP1Md3umM1j4ERSR9ZgU2uVnoneWePwLGga |
| 94 XQ== |
| 95 -----END CERTIFICATE----- |
| 96 |
| 97 Certificate: |
| 98 Data: |
| 99 Version: 3 (0x2) |
| 100 Serial Number: 2 (0x2) |
| 101 Signature Algorithm: sha256WithRSAEncryption |
| 102 Issuer: CN=Root |
| 103 Validity |
| 104 Not Before: Jan 1 12:00:00 2015 GMT |
| 105 Not After : Jan 1 12:00:00 2016 GMT |
| 106 Subject: CN=Intermediate |
| 107 Subject Public Key Info: |
| 108 Public Key Algorithm: rsaEncryption |
| 109 Public-Key: (2048 bit) |
| 110 Modulus: |
| 111 00:cb:28:70:eb:a1:65:a2:22:db:5c:ba:86:17:54: |
| 112 58:48:b8:ba:2c:ac:a3:2d:b3:5d:18:f0:b6:69:04: |
| 113 c3:b8:67:15:d7:f9:94:df:b2:98:f6:32:fd:b1:d6: |
| 114 ab:0c:a1:8a:0a:b5:b7:d1:39:28:4f:ee:d5:f9:9a: |
| 115 ea:ab:5f:42:78:b2:5e:14:e1:23:dc:d4:3f:1d:d7: |
| 116 47:f3:77:f6:08:42:60:a9:98:5d:93:86:71:8c:17: |
| 117 e5:32:f7:c5:70:82:76:00:2d:72:d3:c3:a0:0e:c1: |
| 118 93:2d:3d:a4:79:08:61:66:9d:c4:d5:d6:01:4d:90: |
| 119 81:3e:b5:72:18:4b:66:ae:fc:e2:78:44:e7:ca:2f: |
| 120 d5:f1:77:d3:9f:35:f4:db:fa:f5:1c:1b:80:14:87: |
| 121 c3:76:25:01:12:bf:a7:47:e2:d8:30:59:95:4f:28: |
| 122 c4:14:c3:d3:4f:a0:f9:d6:7f:0d:ac:46:70:d7:23: |
| 123 0b:4c:3c:d2:a7:ab:39:3d:a5:65:db:ab:a6:79:f7: |
| 124 14:27:38:cf:85:c1:34:fd:f4:02:3e:0d:ff:27:61: |
| 125 49:99:9b:3f:2d:17:fd:6b:5e:3d:ba:bb:03:29:62: |
| 126 e1:07:56:cb:87:fc:17:76:de:79:94:fa:4f:c0:9a: |
| 127 c3:a5:a6:4e:13:8a:f3:45:e2:fe:a7:9c:c4:1c:83: |
| 128 22:cd |
| 129 Exponent: 65537 (0x10001) |
| 130 X509v3 extensions: |
| 131 X509v3 Subject Key Identifier: |
| 132 24:2F:F9:FF:60:7F:92:42:26:05:1A:A0:3C:F7:68:69:14:93:17:F2 |
| 133 X509v3 Authority Key Identifier: |
| 134 keyid:45:51:11:14:F9:18:AF:57:2D:C2:92:3F:57:C0:58:C0:D7:6C:C8:2
6 |
| 135 |
| 136 Authority Information Access: |
| 137 CA Issuers - URI:http://url-for-aia/Root.cer |
| 138 |
| 139 X509v3 CRL Distribution Points: |
| 140 |
| 141 Full Name: |
| 142 URI:http://url-for-crl/Root.crl |
| 143 |
| 144 X509v3 Key Usage: critical |
| 145 Certificate Sign, CRL Sign |
| 146 X509v3 Basic Constraints: critical |
| 147 CA:TRUE |
| 148 X509v3 Extended Key Usage: |
| 149 TLS Web Client Authentication |
| 150 Signature Algorithm: sha256WithRSAEncryption |
| 151 b2:e4:45:7d:5f:33:e5:cd:87:28:fe:e7:bb:17:d7:1d:bd:9c: |
| 152 1f:ee:7c:9c:da:3f:84:01:d3:f3:7c:71:03:4d:7b:00:c0:c7: |
| 153 c6:64:42:20:44:cc:17:3c:75:eb:a8:76:32:4f:80:7f:90:9a: |
| 154 c8:cf:0c:1c:e2:ac:7a:a2:89:51:cb:0d:23:f9:0d:d7:75:9a: |
| 155 7e:4e:04:ed:06:f5:c7:99:fc:c3:4d:f2:0f:b0:d8:09:1f:b1: |
| 156 27:86:ba:07:83:77:83:3e:72:34:50:a4:f3:6f:52:33:31:af: |
| 157 ff:cc:8e:af:05:da:e5:65:4d:d8:ac:98:eb:50:c8:02:81:9b: |
| 158 cf:2f:2d:83:e1:1e:c6:bc:eb:d0:d2:b0:55:19:b4:c5:f7:e4: |
| 159 cb:27:55:6d:16:d0:37:27:21:f1:29:1c:9b:2f:b2:6f:38:5d: |
| 160 c3:56:92:f5:e8:ee:82:07:b2:84:b0:8e:6c:8e:58:a1:24:97: |
| 161 3a:fd:5c:31:e3:fc:2c:b3:8e:2e:42:47:52:15:d7:06:4d:02: |
| 162 96:d0:08:81:9a:1c:f4:c4:84:2e:fd:24:2d:f9:52:52:94:6a: |
| 163 98:01:11:6c:65:62:fc:be:fc:fe:dc:12:df:9c:b1:3c:c5:cc: |
| 164 73:a2:eb:3b:4e:f9:3b:e5:5c:b4:59:88:7a:57:9d:54:95:ec: |
| 165 d5:8c:9c:2e |
| 166 -----BEGIN CERTIFICATE----- |
| 167 MIIDgjCCAmqgAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 |
| 168 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 |
| 169 ZXJtZWRpYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyyhw66Fl |
| 170 oiLbXLqGF1RYSLi6LKyjLbNdGPC2aQTDuGcV1/mU37KY9jL9sdarDKGKCrW30Tko |
| 171 T+7V+Zrqq19CeLJeFOEj3NQ/HddH83f2CEJgqZhdk4ZxjBflMvfFcIJ2AC1y08Og |
| 172 DsGTLT2keQhhZp3E1dYBTZCBPrVyGEtmrvzieETnyi/V8XfTnzX02/r1HBuAFIfD |
| 173 diUBEr+nR+LYMFmVTyjEFMPTT6D51n8NrEZw1yMLTDzSp6s5PaVl26umefcUJzjP |
| 174 hcE0/fQCPg3/J2FJmZs/LRf9a149ursDKWLhB1bLh/wXdt55lPpPwJrDpaZOE4rz |
| 175 ReL+p5zEHIMizQIDAQABo4HgMIHdMB0GA1UdDgQWBBQkL/n/YH+SQiYFGqA892hp |
| 176 FJMX8jAfBgNVHSMEGDAWgBRFUREU+RivVy3Ckj9XwFjA12zIJjA3BggrBgEFBQcB |
| 177 AQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwtZm9yLWFpYS9Sb290LmNlcjAs |
| 178 BgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZvci1jcmwvUm9vdC5jcmwwDgYD |
| 179 VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wEwYDVR0lBAwwCgYIKwYBBQUH |
| 180 AwIwDQYJKoZIhvcNAQELBQADggEBALLkRX1fM+XNhyj+57sX1x29nB/ufJzaP4QB |
| 181 0/N8cQNNewDAx8ZkQiBEzBc8deuodjJPgH+QmsjPDBzirHqiiVHLDSP5Ddd1mn5O |
| 182 BO0G9ceZ/MNN8g+w2AkfsSeGugeDd4M+cjRQpPNvUjMxr//Mjq8F2uVlTdismOtQ |
| 183 yAKBm88vLYPhHsa869DSsFUZtMX35MsnVW0W0DcnIfEpHJsvsm84XcNWkvXo7oIH |
| 184 soSwjmyOWKEklzr9XDHj/Cyzji5CR1IV1wZNApbQCIGaHPTEhC79JC35UlKUapgB |
| 185 EWxlYvy+/P7cEt+csTzFzHOi6ztO+TvlXLRZiHpXnVSV7NWMnC4= |
| 186 -----END CERTIFICATE----- |
| 187 |
| 188 Certificate: |
| 189 Data: |
| 190 Version: 3 (0x2) |
| 191 Serial Number: 1 (0x1) |
| 192 Signature Algorithm: sha256WithRSAEncryption |
| 193 Issuer: CN=Root |
| 194 Validity |
| 195 Not Before: Jan 1 12:00:00 2015 GMT |
| 196 Not After : Jan 1 12:00:00 2016 GMT |
| 197 Subject: CN=Root |
| 198 Subject Public Key Info: |
| 199 Public Key Algorithm: rsaEncryption |
| 200 Public-Key: (2048 bit) |
| 201 Modulus: |
| 202 00:bf:50:85:f3:70:3a:67:86:98:fd:8b:92:b9:e5: |
| 203 e8:7f:7c:45:65:ef:fd:72:f0:6c:dc:13:74:7e:f4: |
| 204 58:f7:b5:04:70:46:9f:63:6a:52:f9:cd:ea:37:01: |
| 205 e0:32:00:15:1b:90:bd:1f:4a:8c:22:8b:a9:ed:e0: |
| 206 ae:47:dd:fa:91:83:93:d0:ad:41:30:49:23:75:d4: |
| 207 76:75:19:3e:f3:c6:b5:d2:d3:a2:c2:45:4b:fb:07: |
| 208 fb:06:af:82:01:ec:b9:0b:99:db:eb:30:b8:4b:46: |
| 209 fd:60:a4:57:60:7b:9c:1e:3a:25:63:74:3e:4e:c3: |
| 210 88:82:02:69:50:94:70:8f:cf:c9:38:42:a4:16:e3: |
| 211 05:d5:46:21:21:fd:bb:42:98:da:8d:d0:a7:2b:5d: |
| 212 8f:96:cd:f8:8b:8e:d6:2e:a5:b0:0a:e4:d9:5c:dc: |
| 213 39:21:93:5f:1e:4a:fc:f4:3b:c1:14:27:27:09:05: |
| 214 80:0a:bb:3b:27:4c:e7:50:6b:a4:97:b6:5f:61:c7: |
| 215 68:be:3f:d3:ec:1a:e8:1c:30:e8:0a:c0:6b:3e:b4: |
| 216 0b:60:9d:bd:0c:c1:5e:5d:b1:43:ec:0b:c1:5d:5a: |
| 217 26:e1:02:40:3c:c2:60:7f:08:9f:32:eb:38:9d:53: |
| 218 15:21:cf:83:5e:52:1e:1c:a5:f5:33:d7:ab:f3:a9: |
| 219 d8:dd |
| 220 Exponent: 65537 (0x10001) |
| 221 X509v3 extensions: |
| 222 X509v3 Subject Key Identifier: |
| 223 45:51:11:14:F9:18:AF:57:2D:C2:92:3F:57:C0:58:C0:D7:6C:C8:26 |
| 224 X509v3 Authority Key Identifier: |
| 225 keyid:45:51:11:14:F9:18:AF:57:2D:C2:92:3F:57:C0:58:C0:D7:6C:C8:2
6 |
| 226 |
| 227 Authority Information Access: |
| 228 CA Issuers - URI:http://url-for-aia/Root.cer |
| 229 |
| 230 X509v3 CRL Distribution Points: |
| 231 |
| 232 Full Name: |
| 233 URI:http://url-for-crl/Root.crl |
| 234 |
| 235 X509v3 Key Usage: critical |
| 236 Certificate Sign, CRL Sign |
| 237 X509v3 Basic Constraints: critical |
| 238 CA:TRUE |
| 239 Signature Algorithm: sha256WithRSAEncryption |
| 240 68:e4:51:2c:81:e8:9b:fc:cf:05:6f:99:79:83:fa:0b:a4:c6: |
| 241 46:75:eb:b3:06:e0:7d:ec:88:bf:51:b7:90:58:15:1d:a1:7b: |
| 242 41:24:a5:48:34:d7:72:40:c2:c6:ec:22:c5:b7:c1:a6:5b:ec: |
| 243 ce:c3:8f:ce:f9:ef:b0:74:cd:0b:96:88:46:4b:32:a4:75:7a: |
| 244 34:88:4d:d4:f2:f5:6b:a1:3d:d7:61:2e:ac:fd:46:19:bb:7c: |
| 245 01:ec:d4:d0:be:b5:d9:ac:c9:0e:f0:d2:c2:b2:10:91:86:15: |
| 246 25:84:29:d5:60:91:fc:9d:c0:93:a6:69:8e:c5:df:50:4b:e5: |
| 247 32:97:fa:1e:ba:22:0a:1a:cf:f7:92:23:b7:53:0e:51:78:ad: |
| 248 21:64:d9:bb:3d:41:d2:90:33:33:a8:0c:98:17:7a:77:42:5a: |
| 249 f2:ff:a6:08:0e:49:88:f2:6c:74:4b:2b:5a:4f:2b:e2:84:6d: |
| 250 6b:b6:c5:ed:66:24:a6:97:0d:8f:bc:6d:8b:a3:0c:cd:f0:b6: |
| 251 7c:2a:bc:5f:2c:9f:47:f7:2b:db:bf:ef:51:79:8d:b2:05:30: |
| 252 46:f8:8d:c1:7c:a5:19:9b:42:82:4b:45:e5:4c:d4:a3:5e:33: |
| 253 db:88:81:12:7c:3f:81:ee:52:51:9d:44:c8:03:50:02:b7:1b: |
| 254 57:62:db:76 |
| 255 -----BEGIN TRUST_ANCHOR_UNCONSTRAINED----- |
| 256 MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 |
| 257 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v |
| 258 dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL9QhfNwOmeGmP2Lkrnl |
| 259 6H98RWXv/XLwbNwTdH70WPe1BHBGn2NqUvnN6jcB4DIAFRuQvR9KjCKLqe3grkfd |
| 260 +pGDk9CtQTBJI3XUdnUZPvPGtdLTosJFS/sH+wavggHsuQuZ2+swuEtG/WCkV2B7 |
| 261 nB46JWN0Pk7DiIICaVCUcI/PyThCpBbjBdVGISH9u0KY2o3Qpytdj5bN+IuO1i6l |
| 262 sArk2VzcOSGTXx5K/PQ7wRQnJwkFgAq7OydM51BrpJe2X2HHaL4/0+wa6Bww6ArA |
| 263 az60C2CdvQzBXl2xQ+wLwV1aJuECQDzCYH8InzLrOJ1TFSHPg15SHhyl9TPXq/Op |
| 264 2N0CAwEAAaOByzCByDAdBgNVHQ4EFgQURVERFPkYr1ctwpI/V8BYwNdsyCYwHwYD |
| 265 VR0jBBgwFoAURVERFPkYr1ctwpI/V8BYwNdsyCYwNwYIKwYBBQUHAQEEKzApMCcG |
| 266 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw |
| 267 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE |
| 268 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBo5FEsgeib |
| 269 /M8Fb5l5g/oLpMZGdeuzBuB97Ii/UbeQWBUdoXtBJKVINNdyQMLG7CLFt8GmW+zO |
| 270 w4/O+e+wdM0LlohGSzKkdXo0iE3U8vVroT3XYS6s/UYZu3wB7NTQvrXZrMkO8NLC |
| 271 shCRhhUlhCnVYJH8ncCTpmmOxd9QS+Uyl/oeuiIKGs/3kiO3Uw5ReK0hZNm7PUHS |
| 272 kDMzqAyYF3p3Qlry/6YIDkmI8mx0SytaTyvihG1rtsXtZiSmlw2PvG2LowzN8LZ8 |
| 273 KrxfLJ9H9yvbv+9ReY2yBTBG+I3BfKUZm0KCS0XlTNSjXjPbiIESfD+B7lJRnUTI |
| 274 A1ACtxtXYtt2 |
| 275 -----END TRUST_ANCHOR_UNCONSTRAINED----- |
| 276 |
| 277 150302120000Z |
| 278 -----BEGIN TIME----- |
| 279 MTUwMzAyMTIwMDAwWg== |
| 280 -----END TIME----- |
| 281 |
| 282 FAIL |
| 283 -----BEGIN VERIFY_RESULT----- |
| 284 RkFJTA== |
| 285 -----END VERIFY_RESULT----- |
| 286 |
| 287 serverAuth |
| 288 -----BEGIN KEY_PURPOSE----- |
| 289 c2VydmVyQXV0aA== |
| 290 -----END KEY_PURPOSE----- |
| 291 |
| 292 ----- Certificate i=1 (CN=Intermediate) ----- |
| 293 ERROR: The extended key usage does not include server auth |
| 294 |
| 295 |
| 296 -----BEGIN ERRORS----- |
| 297 LS0tLS0gQ2VydGlmaWNhdGUgaT0xIChDTj1JbnRlcm1lZGlhdGUpIC0tLS0tCkVSUk9SOiBUaGUgZXh0
ZW5kZWQga2V5IHVzYWdlIGRvZXMgbm90IGluY2x1ZGUgc2VydmVyIGF1dGgKCg== |
| 298 -----END ERRORS----- |
| OLD | NEW |