SAMPLE Code Signing Certificate
A code-signing certificate (codeSigning EKU, digitalSignature only) issued by the SAMPLE intermediate. It signs nothing real — it exists so signature-verification tooling has an EKU-correct certificate to reason about.
-----BEGIN CERTIFICATE-----
MIIFADCCA2igAwIBAgIDcBAPMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaME8xCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMRwwGgYDVQQDDBNTQU1QTEUgQnVpbGQgU2ln
bmVyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvFQ+FKvpOhgmcptU
hCZk9Qi/Lc9ginBBdHVVfX7GBD1Lre3h2zBK0ZuqzKhrXjag+hMcyRVolyoPnfpC
Gmn+Jr2QtPAE0UjuG07wWf1I6dhg7dPHjkeWAEzDqT2tb244jnYKVPVzTj7X6L3B
UveZfFiKqzGZp2peQSJ56Coe13XSRdtDUtoG1VYu50Ps9QJR6oKv9b0ujuKc7dhL
/ea6vWrcgVLggKj02auQehLqZ8HOasmxPpr/LW0kcEwCShbHPc2qkgZ7YqNocxbS
B9AdO1Fn3GRVAcY1huI3nLPQ4xL7bzmiinyEac0nPRfcyzIrtZI/3LHaNrW7lSbM
WX+9twIDAQABo4IBUzCCAU8wDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUR1HSbgZv
IOtvLlwLfReh+R8Uqu8wDgYDVR0PAQH/BAQDAgeAMCMGA1UdEQQcMBqCGGJ1aWxk
LnBraS5zYW1wbGUuZXhhbXBsZTATBgNVHSUEDDAKBggrBgEFBQcDAzAfBgNVHSME
GDAWgBQPySRMD9x5tqq2szcZpU8DkN/Q+jBABgNVHR8EOTA3MDWgM6Axhi9odHRw
Oi8vY3JsLnBraS5zYW1wbGUuZXhhbXBsZS9pc3N1aW5nLWNhLWkyLmNybDBzBggr
BgEFBQcBAQRnMGUwKgYIKwYBBQUHMAGGHmh0dHA6Ly9vY3NwLnBraS5zYW1wbGUu
ZXhhbXBsZTA3BggrBgEFBQcwAoYraHR0cDovL3BraS5zYW1wbGUuZXhhbXBsZS9p
c3N1aW5nLWNhLWkyLmNydDANBgkqhkiG9w0BAQsFAAOCAYEATxfB22aN9XmfxJVB
CbAFVYrRSb0soCiafXEZEe/+C1Ik9De9/eczitlT5jIi/2TU0r0BxmIYqp0iyxOc
3J2rX3GsJeeFnr8G2kXUsvhSKCoW0HUg9qePEy3r1oHaABACIwS82DOe06f0+hpY
ENFx4Ih2y1RafPnd1pSpmHdg66+bMz31YEKEu6lI+MQJR8sWdLYEV5NjHNrYzSxC
Nlm575o6kDDe+rUumPnh+wFa3om7yJfkflFNdU3W2wdWeWFa84trfmAFm4lAz3sI
oDysu/w6kljhNSmVG0GGIob5aq33j1WLDGBErb5+7lyLyO0ov8Ghjkwj2C17suGX
FpPzNGdfTY0iA6jzng4JPDL1lTqX50iODBrOM5IGIrXYx6MMyQi3FQaIa+kb8HOp
KINIn48BPI05UiDgnHSoB0irTk5rwtQWvGFBsKF+8h5x1k/gCC/EaUWr2t1OJGBY
PIre9EOtapF3EKG4aHnNLmlUwzT9EpgGfc/8bkNgvKc2MW33
-----END CERTIFICATE-----
Specifications
- Eku
- codeSigning
- Issuer
- Novus Examples SAMPLE Issuing CA I2
- Serial
- 0x70100f
- Subject
- CN=SAMPLE Build Signer,O=Novus Examples SAMPLE PKI,C=ZZ
- Sample Only
- true
- Seed
- 70117
Testing contract
Expected to pass- Scenario
- Ask a signature verifier whether this certificate is acceptable for code signing and for TLS.
- Expected result
- It is accepted for code signing and rejected for TLS server authentication on EKU grounds.
What is a .pem file?
PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.
How to use this file
Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.
How to use this file for testing
“SAMPLE Code Signing Certificate” is a deterministic Novus Examples fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.
Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.
This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.
Related files
- jsonCRL Metadata JSON — SAMPLESAMPLE CRL metadata JSON (no binary CRL) for revocation-list UI and loader tests.

- keyEd25519 Private Key (PEM) — SAMPLEDeterministic SAMPLE Ed25519 private key for SSH/TLS tooling tests.

- keyEncrypted PKCS#8 RSA Key — SAMPLEPassword-encrypted SAMPLE PKCS#8 private key (password printed in specs) for decrypt-import tests.

- csrPKCS#10 CSR — Security SAMPLEPKCS#10 certificate signing request SAMPLE for CSR parsers and CA tooling smoke tests.

- p12PKCS#12 Bundle (.p12) — SAMPLESAMPLE PKCS#12 keystore (password `novus-sample-wg`) for keystore importer tests. Not byte-stable.

- keyRSA-2048 Private Key (PEM) — SAMPLEPublished SAMPLE RSA-2048 private key (PKCS#8 PEM). Never use for a real identity.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.