Skip to content
Novus Examples
pem1.5 KB

SAMPLE Leaf Certificate — EC P-256

The elliptic-curve twin of the reference leaf: identical subject, SANs, EKU and issuer, but a P-256 subject public key instead of RSA-2048. Diff the two to isolate exactly what changes when a deployment migrates key types.

Preview — first 27 linespem
-----BEGIN CERTIFICATE-----
MIIEXzCCAsegAwIBAgIDcBACMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaMFMxCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSAwHgYDVQQDDBdsZWFmLnBraS5zYW1wbGUu
ZXhhbXBsZTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFvg0bZA8+Cnw4FJPHg9
MXW/lK0a5f3IoklsCdO7l+yJ9IE+5maLT4yN/XTTwuR2AEjeuENKSTwGqGGqhmQl
i+GjggF5MIIBdTAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBRc5IoYcZQQDnKWpUCD
tYrf3NNqjjAOBgNVHQ8BAf8EBAMCBaAwPwYDVR0RBDgwNoIXbGVhZi5wa2kuc2Ft
cGxlLmV4YW1wbGWCG3d3dy5sZWFmLnBraS5zYW1wbGUuZXhhbXBsZTAdBgNVHSUE
FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHwYDVR0jBBgwFoAUD8kkTA/cebaqtrM3
GaVPA5Df0PowQAYDVR0fBDkwNzA1oDOgMYYvaHR0cDovL2NybC5wa2kuc2FtcGxl
LmV4YW1wbGUvaXNzdWluZy1jYS1pMi5jcmwwcwYIKwYBBQUHAQEEZzBlMCoGCCsG
AQUFBzABhh5odHRwOi8vb2NzcC5wa2kuc2FtcGxlLmV4YW1wbGUwNwYIKwYBBQUH
MAKGK2h0dHA6Ly9wa2kuc2FtcGxlLmV4YW1wbGUvaXNzdWluZy1jYS1pMi5jcnQw
DQYJKoZIhvcNAQELBQADggGBACKvDFpqQ1Zq/jaTjFnMH1ODy01CZC92wgXMrjDC
5icMI43Ljd1BpwcgAoH8ns/BmeoqbLnYA4DGwgyQcmyaWFICiqRja4l96WG0hOPs
9b7BIYqbdlL16k+FL80Owlz86RxzKHnuH0Q3LU7AP2Zn1awr1LORVAlCgqOW4NXx
g7bo+N6UzlyWpi4vb9bmIvGZJj+ZpDoPb0bZxNBQQdrFCHirzz3eMqL+AyhncX69
dxhJY3BGxYO9YmIR1yqMfF0t3Hx6m/SAck3kb+pRpItOWudBrKzvi9HK74lUuREq
DKf/VSfp0GuIdgCzjCN9u7+i0nWIxtixGI670WbBx9BFikW7JslVVvGoJqwG+f1Q
czLIW6lEcJEw+6hCVvwU5AVJeGOa7v9/F9HOGSSaL4AAboBkKQhDM6ioOE/dLVOU
M8S5HpamlEKq2gyUaYdqbAUn9QuAuNJR7nV78IsVykLuQ7V0D2FEusc+8B2Bw8G+
b2WMKDQnOHmaE6aIXK0+pqvQcA==
-----END CERTIFICATE-----

Specifications

Subject Key
EC P-256 (prime256v1)
Issuer
Novus Examples SAMPLE Issuing CA I2
Signature
sha256WithRSAEncryption
Note
EC subject key, RSA issuer signature (keeps the bytes deterministic)
Serial
0x701002
Sample Only
true
Seed
70117

Testing contract

Expected to pass
Scenario
Verify the EC leaf against the same chain as its RSA twin and compare the parsed SubjectPublicKeyInfo of both.
Expected result
Both certificates validate identically; only the SubjectPublicKeyInfo algorithm (id-ecPublicKey vs rsaEncryption) and key size differ.

What is a .pem file?

PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.

How to use this file

Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.

How to use this file for testing

“SAMPLE Leaf Certificate — EC P-256” is a deterministic Novus Examples fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.