Skip to content
Novus Examples
pem1.8 KB

SAMPLE Leaf Certificate — RSA-2048

The reference end-entity certificate for this wave: RSA-2048 subject key, two DNS SANs, serverAuth/clientAuth EKU, and AIA/CRL pointers to the fictional SAMPLE responder. Everything else in the p7 PKI is a deviation from this one.

Preview — first 31 linespem
-----BEGIN CERTIFICATE-----
MIIFKjCCA5KgAwIBAgIDcBABMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaMFMxCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSAwHgYDVQQDDBdsZWFmLnBraS5zYW1wbGUu
ZXhhbXBsZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALxUPhSr6ToY
JnKbVIQmZPUIvy3PYIpwQXR1VX1+xgQ9S63t4dswStGbqsyoa142oPoTHMkVaJcq
D536Qhpp/ia9kLTwBNFI7htO8Fn9SOnYYO3Tx45HlgBMw6k9rW9uOI52ClT1c04+
1+i9wVL3mXxYiqsxmadqXkEieegqHtd10kXbQ1LaBtVWLudD7PUCUeqCr/W9Lo7i
nO3YS/3mur1q3IFS4ICo9NmrkHoS6mfBzmrJsT6a/y1tJHBMAkoWxz3NqpIGe2Kj
aHMW0gfQHTtRZ9xkVQHGNYbiN5yz0OMS+285oop8hGnNJz0X3MsyK7WSP9yx2ja1
u5UmzFl/vbcCAwEAAaOCAXkwggF1MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFEdR
0m4GbyDrby5cC30XofkfFKrvMA4GA1UdDwEB/wQEAwIFoDA/BgNVHREEODA2ghds
ZWFmLnBraS5zYW1wbGUuZXhhbXBsZYIbd3d3LmxlYWYucGtpLnNhbXBsZS5leGFt
cGxlMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAfBgNVHSMEGDAWgBQP
ySRMD9x5tqq2szcZpU8DkN/Q+jBABgNVHR8EOTA3MDWgM6Axhi9odHRwOi8vY3Js
LnBraS5zYW1wbGUuZXhhbXBsZS9pc3N1aW5nLWNhLWkyLmNybDBzBggrBgEFBQcB
AQRnMGUwKgYIKwYBBQUHMAGGHmh0dHA6Ly9vY3NwLnBraS5zYW1wbGUuZXhhbXBs
ZTA3BggrBgEFBQcwAoYraHR0cDovL3BraS5zYW1wbGUuZXhhbXBsZS9pc3N1aW5n
LWNhLWkyLmNydDANBgkqhkiG9w0BAQsFAAOCAYEAwaitn0jderGdnw2GLR9NSTHd
ox70r4a+jR26GN7oJB2oJO9r6bkp/DRjwBFKwGj0tvHIkPZoPdH8Q/v6GfdvYVtH
Jt7zYQQ2tZgBnplZsVgRZ9xKFm4Ir7R4nDbCD2K/7GqcKI+S1IxSfboQUYWYPbQk
1Q+ii/1syxGIIxGUIhcsY3dbmTZ4zTNrIG+aU3BjJbbfqgqTwVDzF8H9PgDem3IM
bzpgYQDPokyxl1vHfir9R6hhQKe4LCpKtPDlJfRBn2dWAWmzOtSDWknx9eDOO/Ye
sGeaRV2tjdC4MYJ0JaG5ChLZ9Obv5U4KktZSOGDZmHp3PQTZVkr8mJxNF+buY18k
NW/PDmFx9CEDJaghQm2kTDzY1fk8Czk1pRFsLUNwACqZekC0owkTUkDbnrolZ5oR
SCmG6bugfj+siJFm1mW7vrJyZXs73AryLLs8iL4hNxzxyXHSjlZ+SXPjS8xAoP5n
/LWOun/bLEpecPWRhtVK+STXzF/e1RdgbqWs00qB
-----END CERTIFICATE-----

Specifications

Subject Key
RSA-2048
Issuer
Novus Examples SAMPLE Issuing CA I2
San
leaf.pki.sample.example, www.leaf.pki.sample.example
Eku
serverAuth, clientAuth
Crl Distribution Point
http://crl.pki.sample.example/issuing-ca-i2.crl
Ocsp
http://ocsp.pki.sample.example
Validity
2026-01-01 to 2027-01-01
Serial
0x701001
Sample Only
true
Seed
70117

Testing contract

Expected to pass
Scenario
Verify the leaf against the SAMPLE intermediate and root with hostname leaf.pki.sample.example at a clock inside 2026.
Expected result
Path building succeeds, the hostname matches a DNS SAN, and no policy or validity error is raised.

What is a .pem file?

PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.

How to use this file

Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.

How to use this file for testing

“SAMPLE Leaf Certificate — RSA-2048” is a deterministic Novus Examples fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.