[Created by: generate-expired-intermediary.py] Certificate chain with 1 intermediary, where the intermediary is expired (violates validity.notAfter). Verification is expected to fail. Certificate: Data: Version: 3 (0x2) Serial Number: 1 (0x1) Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Intermediary Validity Not Before: Jan 1 12:00:00 2015 GMT Not After : Jan 1 12:00:00 2016 GMT Subject: CN=Target Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:b4:33:49:77:46:22:00:7b:a3:98:45:15:f7:e4: 40:bc:c7:d1:86:bf:05:3b:c7:57:d7:12:e4:b0:aa: 58:38:e7:bb:2f:1a:54:91:a8:78:39:d1:bd:67:5c: c6:d5:08:44:d0:98:7e:7f:69:03:2a:5d:cd:f9:51: 13:44:50:62:c4:ca:44:3e:1d:ea:bc:fd:eb:21:57: e2:cd:85:3d:fe:70:e1:e8:92:c4:5f:68:67:4e:53: 96:6b:02:59:39:31:c9:8b:fe:71:17:b3:b7:14:77: 1b:89:b4:f8:ec:c5:b1:53:dd:42:ca:40:cd:14:c0: 8a:b7:f6:32:72:16:d0:37:72:de:62:9f:49:e5:c3: 2e:22:bc:a0:04:a7:d5:11:56:54:9f:7f:0e:92:f3: 7a:88:bb:74:2e:19:3f:02:9e:69:fa:b4:bd:57:38: 3d:19:99:48:f4:c1:07:57:91:52:db:63:dc:8b:0c: ca:74:85:1a:cd:f1:8c:3f:b9:9f:61:44:31:f8:86: ef:c1:ff:31:e7:fb:cd:7a:59:30:b2:8b:9c:5e:71: 41:04:11:96:e4:8a:a7:8e:0e:58:76:ac:0f:1c:eb: 1e:dc:0f:01:4f:ad:4e:29:ba:9b:40:7f:f5:c8:51: 0c:8b:a9:19:01:51:c3:23:71:25:19:be:0c:10:ea: 46:75 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 77:E8:2F:D7:FB:5C:C4:E2:A0:B9:44:4F:B4:A7:15:35:41:B6:C8:C3 X509v3 Authority Key Identifier: keyid:8C:5E:B2:DE:2B:9F:31:B1:26:55:4D:45:E8:E7:23:87:58:5B:83:D1 Authority Information Access: CA Issuers - URI:http://url-for-aia/Intermediary.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Intermediary.crl X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication Signature Algorithm: sha256WithRSAEncryption 96:9d:3f:9e:85:d1:f5:b1:b8:42:a6:13:92:77:ea:af:0a:3e: f1:2e:73:e5:db:55:e5:08:d9:54:35:67:ed:0c:7a:ec:b4:a6: 3b:6e:7b:db:44:82:36:84:65:6e:f0:95:bc:a2:10:f3:73:39: 41:ae:3d:2b:dc:de:3f:9b:8a:bc:67:83:75:83:dd:67:b1:96: fc:79:0f:ca:89:73:7f:48:83:55:f5:e5:dd:b3:fd:8d:8c:1c: c1:7f:41:fd:db:ac:59:33:58:0e:01:cb:8d:d9:c0:7d:bd:e0: a1:1e:ce:cb:eb:a1:c8:97:05:4d:4d:28:26:f6:eb:1a:7d:20: 3a:d5:a9:9c:12:2d:b4:56:42:ab:fa:4d:f4:50:68:62:e5:94: 2c:9c:e7:83:25:db:d7:8b:40:2d:d7:ba:b8:f4:fe:f4:88:76: 5d:b9:a0:6d:ee:ba:82:a1:33:42:3a:e4:10:77:30:9b:60:c2: c7:8b:cd:9e:29:00:0c:2d:01:a1:eb:1b:ce:41:6a:c7:91:79: ff:64:f4:fe:2e:20:34:c6:6e:8a:4b:82:be:09:6b:17:94:aa: cb:75:82:3a:b4:03:16:8a:52:4e:3a:92:a3:85:fd:db:a2:e8: e7:a3:8c:bf:85:7e:6b:2d:7a:53:1d:db:49:1e:30:d0:8d:99: 06:f8:95:3a -----BEGIN CERTIFICATE----- MIIDjTCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl cm1lZGlhcnkwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC0M0l3 RiIAe6OYRRX35EC8x9GGvwU7x1fXEuSwqlg457svGlSRqHg50b1nXMbVCETQmH5/ aQMqXc35URNEUGLEykQ+Heq8/eshV+LNhT3+cOHoksRfaGdOU5ZrAlk5McmL/nEX s7cUdxuJtPjsxbFT3ULKQM0UwIq39jJyFtA3ct5in0nlwy4ivKAEp9URVlSffw6S 83qIu3QuGT8Cnmn6tL1XOD0ZmUj0wQdXkVLbY9yLDMp0hRrN8Yw/uZ9hRDH4hu/B /zHn+816WTCyi5xecUEEEZbkiqeODlh2rA8c6x7cDwFPrU4puptAf/XIUQyLqRkB UcMjcSUZvgwQ6kZ1AgMBAAGjgekwgeYwHQYDVR0OBBYEFHfoL9f7XMTioLlET7Sn FTVBtsjDMB8GA1UdIwQYMBaAFIxest4rnzGxJlVNRejnI4dYW4PRMD8GCCsGAQUF BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk aWFyeS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu dGVybWVkaWFyeS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAlp0/noXR9bG4QqYTknfq rwo+8S5z5dtV5QjZVDVn7Qx67LSmO25720SCNoRlbvCVvKIQ83M5Qa49K9zeP5uK vGeDdYPdZ7GW/HkPyolzf0iDVfXl3bP9jYwcwX9B/dusWTNYDgHLjdnAfb3goR7O y+uhyJcFTU0oJvbrGn0gOtWpnBIttFZCq/pN9FBoYuWULJzngyXb14tALde6uPT+ 9Ih2Xbmgbe66gqEzQjrkEHcwm2DCx4vNnikADC0BoesbzkFqx5F5/2T0/i4gNMZu ikuCvglrF5Sqy3WCOrQDFopSTjqSo4X926Lo56OMv4V+ay16Ux3bSR4w0I2ZBviV Og== -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 2 (0x2) Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Jan 1 12:00:00 2015 GMT Not After : Jan 1 12:00:00 2016 GMT Subject: CN=Intermediary Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ab:a7:65:bb:25:26:49:f5:55:58:4e:25:97:97: 19:be:89:c0:d7:29:77:db:32:59:71:e5:92:4c:6e: c3:9c:29:73:65:a7:60:ba:a6:59:06:25:28:df:90: ec:d7:fb:b9:fd:67:f4:0a:e2:2f:9c:e6:0d:77:77: 12:60:e7:57:71:08:ba:87:50:30:a0:5f:d6:02:0c: 9a:64:6c:fb:cf:f7:6b:12:ce:09:98:27:d9:15:46: 00:14:58:63:08:e1:58:7f:98:5d:86:09:6b:59:78: 69:c1:74:5b:6e:a4:fc:b0:d7:64:30:e6:50:7a:3a: 98:fd:48:ed:b9:d3:b2:04:5a:f6:67:c8:50:f2:bb: 2a:49:4c:82:2c:9c:1a:ab:5c:e8:0d:7b:ae:2b:5f: 4f:77:90:4a:c9:63:cd:0f:07:1d:63:23:7f:e6:6b: 16:f8:70:f1:43:ac:4c:e0:72:05:36:0e:3f:62:ed: 71:61:8f:e1:7c:8b:16:7d:9c:99:e1:18:d4:8e:52: 14:07:3b:49:7e:5d:06:ac:6b:34:63:6c:86:c5:8a: fb:f0:e5:a3:aa:40:4f:35:da:4b:31:c6:a0:7e:49: c1:47:22:19:5b:2d:c3:07:ac:25:fe:e8:97:4c:e1: 59:59:2c:6b:bd:96:ee:b5:67:ca:03:1d:a7:e1:8e: 19:a3 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 8C:5E:B2:DE:2B:9F:31:B1:26:55:4D:45:E8:E7:23:87:58:5B:83:D1 X509v3 Authority Key Identifier: keyid:15:EB:EA:C0:58:73:9E:53:97:FB:86:13:F2:7A:4E:1C:E1:91:7C:C5 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption 0e:32:41:5f:b0:5f:c7:3e:3e:d7:54:43:2c:7d:d5:49:a0:2f: 90:d6:70:2e:f4:d6:a7:13:15:83:3b:44:a0:c2:d8:d8:01:0b: b0:37:ec:14:39:e5:85:99:de:80:f6:da:11:b4:31:5a:66:86: f0:e8:ac:ad:d6:ac:4a:eb:49:4f:af:59:cc:c5:ca:e7:09:8c: 98:e1:b7:86:c1:46:c3:85:34:7a:89:72:0b:0a:f5:e7:41:ac: 6d:9c:78:ff:d6:ba:fc:86:f3:39:b9:77:44:f4:2f:f4:c0:5e: b2:93:01:9e:85:8d:a8:58:dc:cd:77:37:40:28:0c:d7:42:19: f5:bc:a0:e9:ea:f6:a1:42:6a:1f:d3:d6:01:b0:8e:ef:49:97: 7a:d5:8b:37:28:96:95:00:dd:4c:6c:05:5a:59:fd:14:bd:69: ae:03:c3:8b:47:ea:8e:48:92:4c:c9:bc:9c:b7:07:bd:e4:5e: 6c:d3:e1:51:57:45:b2:79:bf:7e:22:c1:d5:65:a8:50:db:51: 13:28:8e:02:2c:d2:19:09:69:16:6d:60:40:23:44:5b:38:4a: a4:a1:61:27:ec:36:95:81:2e:5c:ac:f1:13:39:f5:d0:d5:3a: 94:82:8f:c8:41:da:e8:a4:0e:19:a8:6d:19:6c:fb:29:39:74: af:48:01:e2 -----BEGIN CERTIFICATE----- MIIDbTCCAlWgAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 ZXJtZWRpYXJ5MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq6dluyUm SfVVWE4ll5cZvonA1yl32zJZceWSTG7DnClzZadguqZZBiUo35Ds1/u5/Wf0CuIv nOYNd3cSYOdXcQi6h1AwoF/WAgyaZGz7z/drEs4JmCfZFUYAFFhjCOFYf5hdhglr WXhpwXRbbqT8sNdkMOZQejqY/UjtudOyBFr2Z8hQ8rsqSUyCLJwaq1zoDXuuK19P d5BKyWPNDwcdYyN/5msW+HDxQ6xM4HIFNg4/Yu1xYY/hfIsWfZyZ4RjUjlIUBztJ fl0GrGs0Y2yGxYr78OWjqkBPNdpLMcagfknBRyIZWy3DB6wl/uiXTOFZWSxrvZbu tWfKAx2n4Y4ZowIDAQABo4HLMIHIMB0GA1UdDgQWBBSMXrLeK58xsSZVTUXo5yOH WFuD0TAfBgNVHSMEGDAWgBQV6+rAWHOeU5f7hhPyek4c4ZF8xTA3BggrBgEFBQcB AQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwtZm9yLWFpYS9Sb290LmNlcjAs BgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZvci1jcmwvUm9vdC5jcmwwDgYD VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEB AA4yQV+wX8c+PtdUQyx91UmgL5DWcC701qcTFYM7RKDC2NgBC7A37BQ55YWZ3oD2 2hG0MVpmhvDorK3WrErrSU+vWczFyucJjJjht4bBRsOFNHqJcgsK9edBrG2ceP/W uvyG8zm5d0T0L/TAXrKTAZ6FjahY3M13N0AoDNdCGfW8oOnq9qFCah/T1gGwju9J l3rVizcolpUA3UxsBVpZ/RS9aa4Dw4tH6o5IkkzJvJy3B73kXmzT4VFXRbJ5v34i wdVlqFDbURMojgIs0hkJaRZtYEAjRFs4SqShYSfsNpWBLlys8RM59dDVOpSCj8hB 2uikDhmobRls+yk5dK9IAeI= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 1 (0x1) Signature Algorithm: sha256WithRSAEncryption Issuer: CN=Root Validity Not Before: Jan 1 12:00:00 2015 GMT Not After : Jan 1 12:00:00 2016 GMT Subject: CN=Root Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ca:63:ce:f6:f5:87:1c:17:7d:20:6c:eb:25:52: 83:6a:00:1b:c4:76:25:c4:5e:e0:0e:eb:dc:c2:86: 9f:84:9a:b2:da:cd:05:7f:5b:ad:e0:11:3a:f9:c5: a9:97:96:77:9c:4a:3c:3d:e8:c2:fe:f0:e5:f4:1f: c2:bd:cb:33:89:fa:a0:61:c2:85:c1:ea:8b:ec:97: f4:5d:dc:cf:bd:45:c8:5d:a9:0d:8e:7a:b0:53:67: 8b:37:bd:67:20:f0:e3:fd:20:5d:7e:e8:df:90:ba: 0a:59:b3:08:fb:42:45:ae:83:89:b8:50:93:09:66: ac:a3:7a:fe:b3:ee:ad:0c:fd:c3:a0:ab:3b:1a:49: 4f:bb:2e:8a:0a:61:ae:99:40:15:79:9a:63:a9:f3: e0:50:98:eb:11:7d:06:56:85:43:50:8d:9c:1f:a5: c3:6e:17:6b:f3:07:3a:8a:ce:c2:4f:71:84:eb:c3: ca:91:1c:71:96:57:14:93:15:f7:93:b6:39:4e:9e: 99:8e:2b:e0:47:ad:86:ff:d4:7f:a4:b1:5b:3f:08: 03:84:95:8f:2a:ff:0c:33:22:28:3e:e8:12:53:5d: 10:3b:86:24:61:1b:85:a8:97:ad:b1:2f:d2:a0:5a: 5f:51:49:7c:ab:4f:4b:4a:43:da:2f:4a:46:6a:c9: 12:d5 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 15:EB:EA:C0:58:73:9E:53:97:FB:86:13:F2:7A:4E:1C:E1:91:7C:C5 X509v3 Authority Key Identifier: keyid:15:EB:EA:C0:58:73:9E:53:97:FB:86:13:F2:7A:4E:1C:E1:91:7C:C5 Authority Information Access: CA Issuers - URI:http://url-for-aia/Root.cer X509v3 CRL Distribution Points: Full Name: URI:http://url-for-crl/Root.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption 35:78:42:b8:84:7a:f4:0a:9d:ab:2f:a2:95:a7:6a:f5:14:ee: b7:5a:f4:36:43:22:ef:f7:39:c4:85:ff:eb:e4:24:47:c2:04: ac:af:25:a5:04:68:64:a3:41:23:fe:a6:99:d2:2a:95:51:60: 2a:97:31:31:01:a0:83:2c:d8:fe:81:5f:dc:2d:3f:5a:5c:6f: 2f:df:43:57:61:35:a2:e3:d9:56:f0:26:7d:74:15:3f:24:07: 1a:cd:49:d9:d0:2f:94:5b:d8:ae:da:f4:93:fa:7a:34:25:20: a1:d0:ef:d2:1e:c3:eb:b5:63:49:c6:4c:a1:2f:11:d6:5b:88: a8:89:b0:e6:22:92:3f:d2:a9:26:ad:32:85:e4:98:14:3c:9e: 4d:9e:49:62:f9:88:25:bd:e0:0d:72:d0:dc:cc:55:b7:bc:38: 58:70:6b:cb:e0:ce:6b:1a:f8:3a:b6:33:0f:21:0d:d1:80:e1: 5f:2a:ca:b0:29:e0:e0:17:af:4a:39:bb:cc:29:97:30:08:64: 26:d9:ba:0b:1f:17:a3:41:e3:0f:a2:d1:cd:21:a1:4e:40:ee: 3d:c3:20:4a:6d:c4:35:3c:10:f1:f8:76:f8:04:da:7f:17:22: 6a:de:fe:59:24:04:06:e8:57:f1:6b:f8:4d:63:17:c3:0e:dc: 3b:26:f3:e2 -----BEGIN TRUSTED_CERTIFICATE----- MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMpjzvb1hxwXfSBs6yVS g2oAG8R2JcRe4A7r3MKGn4SastrNBX9breAROvnFqZeWd5xKPD3owv7w5fQfwr3L M4n6oGHChcHqi+yX9F3cz71FyF2pDY56sFNnize9ZyDw4/0gXX7o35C6ClmzCPtC Ra6DibhQkwlmrKN6/rPurQz9w6CrOxpJT7suigphrplAFXmaY6nz4FCY6xF9BlaF Q1CNnB+lw24Xa/MHOorOwk9xhOvDypEccZZXFJMV95O2OU6emY4r4Eethv/Uf6Sx Wz8IA4SVjyr/DDMiKD7oElNdEDuGJGEbhaiXrbEv0qBaX1FJfKtPS0pD2i9KRmrJ EtUCAwEAAaOByzCByDAdBgNVHQ4EFgQUFevqwFhznlOX+4YT8npOHOGRfMUwHwYD VR0jBBgwFoAUFevqwFhznlOX+4YT8npOHOGRfMUwNwYIKwYBBQUHAQEEKzApMCcG CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQA1eEK4hHr0 Cp2rL6KVp2r1FO63WvQ2QyLv9znEhf/r5CRHwgSsryWlBGhko0Ej/qaZ0iqVUWAq lzExAaCDLNj+gV/cLT9aXG8v30NXYTWi49lW8CZ9dBU/JAcazUnZ0C+UW9iu2vST +no0JSCh0O/SHsPrtWNJxkyhLxHWW4ioibDmIpI/0qkmrTKF5JgUPJ5Nnkli+Ygl veANctDczFW3vDhYcGvL4M5rGvg6tjMPIQ3RgOFfKsqwKeDgF69KObvMKZcwCGQm 2boLHxejQeMPotHNIaFOQO49wyBKbcQ1PBDx+Hb4BNp/FyJq3v5ZJAQG6Ffxa/hN YxfDDtw7JvPi -----END TRUSTED_CERTIFICATE----- -----BEGIN TIME----- MTYwMzAyMTIwMDAwWg== -----END TIME----- -----BEGIN VERIFY_RESULT----- RkFJTA== -----END VERIFY_RESULT-----