Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(71)

Unified Diff: net/data/verify_certificate_chain_unittest/intermediate-restricts-eku-fail.pem

Issue 2800993002: Add a key purpose parameter to Certificate PathBuilder. (Closed)
Patch Set: add datafiles for ios build Created 3 years, 8 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: net/data/verify_certificate_chain_unittest/intermediate-restricts-eku-fail.pem
diff --git a/net/data/verify_certificate_chain_unittest/intermediate-restricts-eku-fail.pem b/net/data/verify_certificate_chain_unittest/intermediate-restricts-eku-fail.pem
new file mode 100644
index 0000000000000000000000000000000000000000..7b603a6eacfaa81c9afbad533c0fd19f46399245
--- /dev/null
+++ b/net/data/verify_certificate_chain_unittest/intermediate-restricts-eku-fail.pem
@@ -0,0 +1,298 @@
+[Created by: generate-intermediate-restricts-eku-fail.py]
+
+Certificate chain with 1 intermediate and a trusted root. The intermediate
+restricts the EKU to clientAuth, and the target has serverAuth +
+clientAuth. Verification is expected to fail when requesting serverAuth.
+
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 1 (0x1)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=Intermediate
+ Validity
+ Not Before: Jan 1 12:00:00 2015 GMT
+ Not After : Jan 1 12:00:00 2016 GMT
+ Subject: CN=Target
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ Public-Key: (2048 bit)
+ Modulus:
+ 00:cf:f7:e3:6e:d2:f5:a5:82:0a:07:7e:24:03:7c:
+ 9b:9d:d8:c1:b2:be:05:f6:4d:aa:ca:f1:96:0f:b5:
+ c2:ca:7a:15:d5:ee:85:9a:d8:fd:7c:c4:c8:82:79:
+ 29:c2:6c:a9:99:85:a3:d8:d1:8f:b9:48:c4:0f:0e:
+ c7:09:26:3a:7c:26:df:44:12:5b:90:37:33:f4:18:
+ f6:0c:6e:5f:88:68:fc:c7:a6:27:5e:74:ba:5c:f2:
+ f7:d1:c2:10:cd:4f:cf:87:c8:cf:87:ca:78:81:65:
+ 76:29:a0:99:73:d7:7e:a7:f8:ce:a8:cc:36:d8:c7:
+ ab:ed:d0:27:bb:ae:e5:8b:1e:0e:23:df:be:db:12:
+ 1b:f6:13:da:3e:e9:c4:2c:5d:8c:9c:05:ea:0e:fc:
+ 40:1f:f8:cd:d0:19:1e:6c:20:b2:23:cf:34:df:c6:
+ de:50:76:36:3d:17:5b:97:83:78:69:12:e7:25:d3:
+ 6b:1a:93:f4:b3:2f:74:e2:a5:f4:eb:3d:94:93:39:
+ e8:c8:3d:61:eb:dc:15:9c:c3:14:00:44:3a:40:5e:
+ 3e:5d:d7:26:0b:0b:4e:53:a5:06:7a:08:d4:72:50:
+ bd:6b:19:0d:df:e8:0d:ff:4f:02:c8:7b:7f:4c:10:
+ c3:27:f0:ba:87:5d:0c:b8:84:ce:01:6f:13:2c:36:
+ 57:79
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 7C:9E:F1:64:89:5B:67:9E:D7:9D:C0:BD:DB:6E:5D:A9:B8:EE:DC:02
+ X509v3 Authority Key Identifier:
+ keyid:24:2F:F9:FF:60:7F:92:42:26:05:1A:A0:3C:F7:68:69:14:93:17:F2
+
+ Authority Information Access:
+ CA Issuers - URI:http://url-for-aia/Intermediate.cer
+
+ X509v3 CRL Distribution Points:
+
+ Full Name:
+ URI:http://url-for-crl/Intermediate.crl
+
+ X509v3 Key Usage: critical
+ Digital Signature, Key Encipherment
+ X509v3 Extended Key Usage:
+ TLS Web Server Authentication, TLS Web Client Authentication
+ Signature Algorithm: sha256WithRSAEncryption
+ 57:46:35:53:66:08:34:e9:27:17:7e:2a:c8:35:fe:f4:37:fd:
+ 39:ec:22:cc:20:37:50:eb:41:09:54:e8:5a:9a:50:9f:e0:e2:
+ 6b:5b:bb:d0:78:75:42:64:db:b4:65:ab:bc:93:80:f6:0f:49:
+ 84:1f:1a:fd:65:51:b1:d6:25:13:27:0b:15:69:d1:60:52:bc:
+ f2:cf:4a:ff:f0:eb:1a:0b:63:37:48:87:3f:53:c5:58:0a:2d:
+ 01:08:29:0e:e5:d9:92:87:7c:79:aa:d8:c2:1e:47:d3:74:d5:
+ e1:78:9f:91:fa:b1:dd:7d:dd:77:8f:11:fc:74:26:ae:bd:1c:
+ c2:a5:09:ad:42:d3:66:7b:14:6b:ff:5f:3c:a0:1d:b0:3e:a0:
+ 60:29:3e:0a:80:c3:d4:4b:32:4f:30:29:d4:4f:a7:e8:93:e8:
+ 3e:4c:6e:0e:0b:ed:b6:71:9f:93:0a:b6:06:38:2c:61:34:8f:
+ be:1b:a3:5e:aa:f1:f9:76:71:6e:2a:ea:bd:48:76:58:5f:60:
+ 8b:31:93:cc:f9:35:6d:99:9d:5a:b8:4c:a5:78:0e:bb:87:8a:
+ 18:dc:ce:7c:50:06:aa:c6:3f:e1:0b:f9:0a:b3:f5:31:dd:ee:
+ 98:cd:63:e0:44:52:47:d6:60:53:6b:95:9e:89:de:59:e3:f0:
+ 2c:68:1a:5d
+-----BEGIN CERTIFICATE-----
+MIIDjTCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl
+cm1lZGlhdGUwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD
+VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDP9+Nu
+0vWlggoHfiQDfJud2MGyvgX2TarK8ZYPtcLKehXV7oWa2P18xMiCeSnCbKmZhaPY
+0Y+5SMQPDscJJjp8Jt9EEluQNzP0GPYMbl+IaPzHpidedLpc8vfRwhDNT8+HyM+H
+yniBZXYpoJlz136n+M6ozDbYx6vt0Ce7ruWLHg4j377bEhv2E9o+6cQsXYycBeoO
+/EAf+M3QGR5sILIjzzTfxt5QdjY9F1uXg3hpEucl02sak/SzL3TipfTrPZSTOejI
+PWHr3BWcwxQARDpAXj5d1yYLC05TpQZ6CNRyUL1rGQ3f6A3/TwLIe39MEMMn8LqH
+XQy4hM4BbxMsNld5AgMBAAGjgekwgeYwHQYDVR0OBBYEFHye8WSJW2ee153Avdtu
+Xam47twCMB8GA1UdIwQYMBaAFCQv+f9gf5JCJgUaoDz3aGkUkxfyMD8GCCsGAQUF
+BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk
+aWF0ZS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu
+dGVybWVkaWF0ZS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF
+BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAV0Y1U2YINOknF34qyDX+
+9Df9OewizCA3UOtBCVToWppQn+Dia1u70Hh1QmTbtGWrvJOA9g9JhB8a/WVRsdYl
+EycLFWnRYFK88s9K//DrGgtjN0iHP1PFWAotAQgpDuXZkod8earYwh5H03TV4Xif
+kfqx3X3dd48R/HQmrr0cwqUJrULTZnsUa/9fPKAdsD6gYCk+CoDD1EsyTzAp1E+n
+6JPoPkxuDgvttnGfkwq2BjgsYTSPvhujXqrx+XZxbirqvUh2WF9gizGTzPk1bZmd
+WrhMpXgOu4eKGNzOfFAGqsY/4Qv5CrP1Md3umM1j4ERSR9ZgU2uVnoneWePwLGga
+XQ==
+-----END CERTIFICATE-----
+
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 2 (0x2)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=Root
+ Validity
+ Not Before: Jan 1 12:00:00 2015 GMT
+ Not After : Jan 1 12:00:00 2016 GMT
+ Subject: CN=Intermediate
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ Public-Key: (2048 bit)
+ Modulus:
+ 00:cb:28:70:eb:a1:65:a2:22:db:5c:ba:86:17:54:
+ 58:48:b8:ba:2c:ac:a3:2d:b3:5d:18:f0:b6:69:04:
+ c3:b8:67:15:d7:f9:94:df:b2:98:f6:32:fd:b1:d6:
+ ab:0c:a1:8a:0a:b5:b7:d1:39:28:4f:ee:d5:f9:9a:
+ ea:ab:5f:42:78:b2:5e:14:e1:23:dc:d4:3f:1d:d7:
+ 47:f3:77:f6:08:42:60:a9:98:5d:93:86:71:8c:17:
+ e5:32:f7:c5:70:82:76:00:2d:72:d3:c3:a0:0e:c1:
+ 93:2d:3d:a4:79:08:61:66:9d:c4:d5:d6:01:4d:90:
+ 81:3e:b5:72:18:4b:66:ae:fc:e2:78:44:e7:ca:2f:
+ d5:f1:77:d3:9f:35:f4:db:fa:f5:1c:1b:80:14:87:
+ c3:76:25:01:12:bf:a7:47:e2:d8:30:59:95:4f:28:
+ c4:14:c3:d3:4f:a0:f9:d6:7f:0d:ac:46:70:d7:23:
+ 0b:4c:3c:d2:a7:ab:39:3d:a5:65:db:ab:a6:79:f7:
+ 14:27:38:cf:85:c1:34:fd:f4:02:3e:0d:ff:27:61:
+ 49:99:9b:3f:2d:17:fd:6b:5e:3d:ba:bb:03:29:62:
+ e1:07:56:cb:87:fc:17:76:de:79:94:fa:4f:c0:9a:
+ c3:a5:a6:4e:13:8a:f3:45:e2:fe:a7:9c:c4:1c:83:
+ 22:cd
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 24:2F:F9:FF:60:7F:92:42:26:05:1A:A0:3C:F7:68:69:14:93:17:F2
+ X509v3 Authority Key Identifier:
+ keyid:45:51:11:14:F9:18:AF:57:2D:C2:92:3F:57:C0:58:C0:D7:6C:C8:26
+
+ Authority Information Access:
+ CA Issuers - URI:http://url-for-aia/Root.cer
+
+ X509v3 CRL Distribution Points:
+
+ Full Name:
+ URI:http://url-for-crl/Root.crl
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Extended Key Usage:
+ TLS Web Client Authentication
+ Signature Algorithm: sha256WithRSAEncryption
+ b2:e4:45:7d:5f:33:e5:cd:87:28:fe:e7:bb:17:d7:1d:bd:9c:
+ 1f:ee:7c:9c:da:3f:84:01:d3:f3:7c:71:03:4d:7b:00:c0:c7:
+ c6:64:42:20:44:cc:17:3c:75:eb:a8:76:32:4f:80:7f:90:9a:
+ c8:cf:0c:1c:e2:ac:7a:a2:89:51:cb:0d:23:f9:0d:d7:75:9a:
+ 7e:4e:04:ed:06:f5:c7:99:fc:c3:4d:f2:0f:b0:d8:09:1f:b1:
+ 27:86:ba:07:83:77:83:3e:72:34:50:a4:f3:6f:52:33:31:af:
+ ff:cc:8e:af:05:da:e5:65:4d:d8:ac:98:eb:50:c8:02:81:9b:
+ cf:2f:2d:83:e1:1e:c6:bc:eb:d0:d2:b0:55:19:b4:c5:f7:e4:
+ cb:27:55:6d:16:d0:37:27:21:f1:29:1c:9b:2f:b2:6f:38:5d:
+ c3:56:92:f5:e8:ee:82:07:b2:84:b0:8e:6c:8e:58:a1:24:97:
+ 3a:fd:5c:31:e3:fc:2c:b3:8e:2e:42:47:52:15:d7:06:4d:02:
+ 96:d0:08:81:9a:1c:f4:c4:84:2e:fd:24:2d:f9:52:52:94:6a:
+ 98:01:11:6c:65:62:fc:be:fc:fe:dc:12:df:9c:b1:3c:c5:cc:
+ 73:a2:eb:3b:4e:f9:3b:e5:5c:b4:59:88:7a:57:9d:54:95:ec:
+ d5:8c:9c:2e
+-----BEGIN CERTIFICATE-----
+MIIDgjCCAmqgAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290
+MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50
+ZXJtZWRpYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyyhw66Fl
+oiLbXLqGF1RYSLi6LKyjLbNdGPC2aQTDuGcV1/mU37KY9jL9sdarDKGKCrW30Tko
+T+7V+Zrqq19CeLJeFOEj3NQ/HddH83f2CEJgqZhdk4ZxjBflMvfFcIJ2AC1y08Og
+DsGTLT2keQhhZp3E1dYBTZCBPrVyGEtmrvzieETnyi/V8XfTnzX02/r1HBuAFIfD
+diUBEr+nR+LYMFmVTyjEFMPTT6D51n8NrEZw1yMLTDzSp6s5PaVl26umefcUJzjP
+hcE0/fQCPg3/J2FJmZs/LRf9a149ursDKWLhB1bLh/wXdt55lPpPwJrDpaZOE4rz
+ReL+p5zEHIMizQIDAQABo4HgMIHdMB0GA1UdDgQWBBQkL/n/YH+SQiYFGqA892hp
+FJMX8jAfBgNVHSMEGDAWgBRFUREU+RivVy3Ckj9XwFjA12zIJjA3BggrBgEFBQcB
+AQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwtZm9yLWFpYS9Sb290LmNlcjAs
+BgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZvci1jcmwvUm9vdC5jcmwwDgYD
+VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wEwYDVR0lBAwwCgYIKwYBBQUH
+AwIwDQYJKoZIhvcNAQELBQADggEBALLkRX1fM+XNhyj+57sX1x29nB/ufJzaP4QB
+0/N8cQNNewDAx8ZkQiBEzBc8deuodjJPgH+QmsjPDBzirHqiiVHLDSP5Ddd1mn5O
+BO0G9ceZ/MNN8g+w2AkfsSeGugeDd4M+cjRQpPNvUjMxr//Mjq8F2uVlTdismOtQ
+yAKBm88vLYPhHsa869DSsFUZtMX35MsnVW0W0DcnIfEpHJsvsm84XcNWkvXo7oIH
+soSwjmyOWKEklzr9XDHj/Cyzji5CR1IV1wZNApbQCIGaHPTEhC79JC35UlKUapgB
+EWxlYvy+/P7cEt+csTzFzHOi6ztO+TvlXLRZiHpXnVSV7NWMnC4=
+-----END CERTIFICATE-----
+
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 1 (0x1)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=Root
+ Validity
+ Not Before: Jan 1 12:00:00 2015 GMT
+ Not After : Jan 1 12:00:00 2016 GMT
+ Subject: CN=Root
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ Public-Key: (2048 bit)
+ Modulus:
+ 00:bf:50:85:f3:70:3a:67:86:98:fd:8b:92:b9:e5:
+ e8:7f:7c:45:65:ef:fd:72:f0:6c:dc:13:74:7e:f4:
+ 58:f7:b5:04:70:46:9f:63:6a:52:f9:cd:ea:37:01:
+ e0:32:00:15:1b:90:bd:1f:4a:8c:22:8b:a9:ed:e0:
+ ae:47:dd:fa:91:83:93:d0:ad:41:30:49:23:75:d4:
+ 76:75:19:3e:f3:c6:b5:d2:d3:a2:c2:45:4b:fb:07:
+ fb:06:af:82:01:ec:b9:0b:99:db:eb:30:b8:4b:46:
+ fd:60:a4:57:60:7b:9c:1e:3a:25:63:74:3e:4e:c3:
+ 88:82:02:69:50:94:70:8f:cf:c9:38:42:a4:16:e3:
+ 05:d5:46:21:21:fd:bb:42:98:da:8d:d0:a7:2b:5d:
+ 8f:96:cd:f8:8b:8e:d6:2e:a5:b0:0a:e4:d9:5c:dc:
+ 39:21:93:5f:1e:4a:fc:f4:3b:c1:14:27:27:09:05:
+ 80:0a:bb:3b:27:4c:e7:50:6b:a4:97:b6:5f:61:c7:
+ 68:be:3f:d3:ec:1a:e8:1c:30:e8:0a:c0:6b:3e:b4:
+ 0b:60:9d:bd:0c:c1:5e:5d:b1:43:ec:0b:c1:5d:5a:
+ 26:e1:02:40:3c:c2:60:7f:08:9f:32:eb:38:9d:53:
+ 15:21:cf:83:5e:52:1e:1c:a5:f5:33:d7:ab:f3:a9:
+ d8:dd
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 45:51:11:14:F9:18:AF:57:2D:C2:92:3F:57:C0:58:C0:D7:6C:C8:26
+ X509v3 Authority Key Identifier:
+ keyid:45:51:11:14:F9:18:AF:57:2D:C2:92:3F:57:C0:58:C0:D7:6C:C8:26
+
+ Authority Information Access:
+ CA Issuers - URI:http://url-for-aia/Root.cer
+
+ X509v3 CRL Distribution Points:
+
+ Full Name:
+ URI:http://url-for-crl/Root.crl
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ Signature Algorithm: sha256WithRSAEncryption
+ 68:e4:51:2c:81:e8:9b:fc:cf:05:6f:99:79:83:fa:0b:a4:c6:
+ 46:75:eb:b3:06:e0:7d:ec:88:bf:51:b7:90:58:15:1d:a1:7b:
+ 41:24:a5:48:34:d7:72:40:c2:c6:ec:22:c5:b7:c1:a6:5b:ec:
+ ce:c3:8f:ce:f9:ef:b0:74:cd:0b:96:88:46:4b:32:a4:75:7a:
+ 34:88:4d:d4:f2:f5:6b:a1:3d:d7:61:2e:ac:fd:46:19:bb:7c:
+ 01:ec:d4:d0:be:b5:d9:ac:c9:0e:f0:d2:c2:b2:10:91:86:15:
+ 25:84:29:d5:60:91:fc:9d:c0:93:a6:69:8e:c5:df:50:4b:e5:
+ 32:97:fa:1e:ba:22:0a:1a:cf:f7:92:23:b7:53:0e:51:78:ad:
+ 21:64:d9:bb:3d:41:d2:90:33:33:a8:0c:98:17:7a:77:42:5a:
+ f2:ff:a6:08:0e:49:88:f2:6c:74:4b:2b:5a:4f:2b:e2:84:6d:
+ 6b:b6:c5:ed:66:24:a6:97:0d:8f:bc:6d:8b:a3:0c:cd:f0:b6:
+ 7c:2a:bc:5f:2c:9f:47:f7:2b:db:bf:ef:51:79:8d:b2:05:30:
+ 46:f8:8d:c1:7c:a5:19:9b:42:82:4b:45:e5:4c:d4:a3:5e:33:
+ db:88:81:12:7c:3f:81:ee:52:51:9d:44:c8:03:50:02:b7:1b:
+ 57:62:db:76
+-----BEGIN TRUST_ANCHOR_UNCONSTRAINED-----
+MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290
+MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v
+dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL9QhfNwOmeGmP2Lkrnl
+6H98RWXv/XLwbNwTdH70WPe1BHBGn2NqUvnN6jcB4DIAFRuQvR9KjCKLqe3grkfd
++pGDk9CtQTBJI3XUdnUZPvPGtdLTosJFS/sH+wavggHsuQuZ2+swuEtG/WCkV2B7
+nB46JWN0Pk7DiIICaVCUcI/PyThCpBbjBdVGISH9u0KY2o3Qpytdj5bN+IuO1i6l
+sArk2VzcOSGTXx5K/PQ7wRQnJwkFgAq7OydM51BrpJe2X2HHaL4/0+wa6Bww6ArA
+az60C2CdvQzBXl2xQ+wLwV1aJuECQDzCYH8InzLrOJ1TFSHPg15SHhyl9TPXq/Op
+2N0CAwEAAaOByzCByDAdBgNVHQ4EFgQURVERFPkYr1ctwpI/V8BYwNdsyCYwHwYD
+VR0jBBgwFoAURVERFPkYr1ctwpI/V8BYwNdsyCYwNwYIKwYBBQUHAQEEKzApMCcG
+CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw
+IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE
+AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBo5FEsgeib
+/M8Fb5l5g/oLpMZGdeuzBuB97Ii/UbeQWBUdoXtBJKVINNdyQMLG7CLFt8GmW+zO
+w4/O+e+wdM0LlohGSzKkdXo0iE3U8vVroT3XYS6s/UYZu3wB7NTQvrXZrMkO8NLC
+shCRhhUlhCnVYJH8ncCTpmmOxd9QS+Uyl/oeuiIKGs/3kiO3Uw5ReK0hZNm7PUHS
+kDMzqAyYF3p3Qlry/6YIDkmI8mx0SytaTyvihG1rtsXtZiSmlw2PvG2LowzN8LZ8
+KrxfLJ9H9yvbv+9ReY2yBTBG+I3BfKUZm0KCS0XlTNSjXjPbiIESfD+B7lJRnUTI
+A1ACtxtXYtt2
+-----END TRUST_ANCHOR_UNCONSTRAINED-----
+
+150302120000Z
+-----BEGIN TIME-----
+MTUwMzAyMTIwMDAwWg==
+-----END TIME-----
+
+FAIL
+-----BEGIN VERIFY_RESULT-----
+RkFJTA==
+-----END VERIFY_RESULT-----
+
+serverAuth
+-----BEGIN KEY_PURPOSE-----
+c2VydmVyQXV0aA==
+-----END KEY_PURPOSE-----
+
+----- Certificate i=1 (CN=Intermediate) -----
+ERROR: The extended key usage does not include server auth
+
+
+-----BEGIN ERRORS-----
+LS0tLS0gQ2VydGlmaWNhdGUgaT0xIChDTj1JbnRlcm1lZGlhdGUpIC0tLS0tCkVSUk9SOiBUaGUgZXh0ZW5kZWQga2V5IHVzYWdlIGRvZXMgbm90IGluY2x1ZGUgc2VydmVyIGF1dGgKCg==
+-----END ERRORS-----

Powered by Google App Engine
This is Rietveld 408576698