Skip to content
Novus Examples
pem1.5 KB

SAMPLE Client Authentication Certificate

A mutual-TLS client certificate: EC P-256 subject key, clientAuth EKU only, and an OU naming the fictional access group. Present it to an mTLS endpoint to test client-certificate parsing and EKU enforcement.

Preview — first 27 linespem
-----BEGIN CERTIFICATE-----
MIIEZTCCAs2gAwIBAgIDcBANMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaMHkxCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMR0wGwYDVQQLDBRTQU1QTEUgQ2xpZW50IEFj
Y2VzczEnMCUGA1UEAwweY2xpZW50LTAwMDEucGtpLnNhbXBsZS5leGFtcGxlMFkw
EwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEW+DRtkDz4KfDgUk8eD0xdb+UrRrl/cii
SWwJ07uX7In0gT7mZotPjI39dNPC5HYASN64Q0pJPAaoYaqGZCWL4aOCAVkwggFV
MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFFzkihhxlBAOcpalQIO1it/c02qOMA4G
A1UdDwEB/wQEAwIHgDApBgNVHREEIjAggh5jbGllbnQtMDAwMS5wa2kuc2FtcGxl
LmV4YW1wbGUwEwYDVR0lBAwwCgYIKwYBBQUHAwIwHwYDVR0jBBgwFoAUD8kkTA/c
ebaqtrM3GaVPA5Df0PowQAYDVR0fBDkwNzA1oDOgMYYvaHR0cDovL2NybC5wa2ku
c2FtcGxlLmV4YW1wbGUvaXNzdWluZy1jYS1pMi5jcmwwcwYIKwYBBQUHAQEEZzBl
MCoGCCsGAQUFBzABhh5odHRwOi8vb2NzcC5wa2kuc2FtcGxlLmV4YW1wbGUwNwYI
KwYBBQUHMAKGK2h0dHA6Ly9wa2kuc2FtcGxlLmV4YW1wbGUvaXNzdWluZy1jYS1p
Mi5jcnQwDQYJKoZIhvcNAQELBQADggGBAH1i3HuJFNTMkSP/tM6Y+0JF08F39VXH
QO8P1KOlZRtULXN41E+QwMkeUepAWrMg7lWkMQm7N//nHrYmAsXQOWoSJjQJWhmg
4gAtX+Csb2X4UUXjPgFcFLR+5Y3q0yMQqLeuAm9Od1fiXpOhfNIfm9J8bFVI/819
m05G3VT2LmC0wRfdq4dt+O2FSHtMVPcVfecCNnJ8YsQu/8PLiYkxxIfoVGI++L8w
vA0TjzfzAwV2siFiYwAQ80XbtIbEXQJaZarEK7uBK5FCUhbqooh86hegOr3OcW1E
SoEepsX0ZBUMXQWQyg1brfWBq/LlZcezLQb8biQWy16EG0X5BLd5C9C0h9YHgIWO
5XUNupoiW5WMqyEZVByT6tIoL8XY4aaNuM7lGzoNZXNjYdlbyPmDhP1xc6+Ca7QS
EOqnDAUiPqcQSiaEYQX4wBYSzlEhV2PKGawM365kCHGzNknIYgxyiytkn0pkMwHK
YcQGE3ZYCF10OMarsxcuiikWp1Yu7B+PhA==
-----END CERTIFICATE-----

Specifications

Eku
clientAuth
Issuer
Novus Examples SAMPLE Issuing CA I2
Serial
0x70100d
Subject
CN=client-0001.pki.sample.example,OU=SAMPLE Client Access,O=Novus Examples SAMPLE PKI,C=ZZ
Sample Only
true
Seed
70117

Testing contract

Expected to pass
Scenario
Present this certificate to a server that requires clientAuth, then to one that requires serverAuth.
Expected result
The mTLS handshake accepts it; the serverAuth endpoint rejects it for an unsuitable extended key usage.

What is a .pem file?

PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.

How to use this file

Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.

How to use this file for testing

“SAMPLE Client Authentication Certificate” is a deterministic Novus Examples fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.