Skip to content
Novus Examples
pem1.8 KB

SAMPLE Leaf Certificate — SAN/CN Mismatch

The certificate's CN is app.pki.sample.example but its only SAN is different.pki.sample.example. RFC 6125 clients must ignore the CN entirely, so this separates modern verifiers from ones still falling back to Common Name.

Preview — first 31 linespem
-----BEGIN CERTIFICATE-----
MIIFETCCA3mgAwIBAgIDcBAHMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaMFIxCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMR8wHQYDVQQDDBZhcHAucGtpLnNhbXBsZS5l
eGFtcGxlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvFQ+FKvpOhgm
cptUhCZk9Qi/Lc9ginBBdHVVfX7GBD1Lre3h2zBK0ZuqzKhrXjag+hMcyRVolyoP
nfpCGmn+Jr2QtPAE0UjuG07wWf1I6dhg7dPHjkeWAEzDqT2tb244jnYKVPVzTj7X
6L3BUveZfFiKqzGZp2peQSJ56Coe13XSRdtDUtoG1VYu50Ps9QJR6oKv9b0ujuKc
7dhL/ea6vWrcgVLggKj02auQehLqZ8HOasmxPpr/LW0kcEwCShbHPc2qkgZ7YqNo
cxbSB9AdO1Fn3GRVAcY1huI3nLPQ4xL7bzmiinyEac0nPRfcyzIrtZI/3LHaNrW7
lSbMWX+9twIDAQABo4IBYTCCAV0wDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUR1HS
bgZvIOtvLlwLfReh+R8Uqu8wDgYDVR0PAQH/BAQDAgWgMCcGA1UdEQQgMB6CHGRp
ZmZlcmVudC5wa2kuc2FtcGxlLmV4YW1wbGUwHQYDVR0lBBYwFAYIKwYBBQUHAwEG
CCsGAQUFBwMCMB8GA1UdIwQYMBaAFA/JJEwP3Hm2qrazNxmlTwOQ39D6MEAGA1Ud
HwQ5MDcwNaAzoDGGL2h0dHA6Ly9jcmwucGtpLnNhbXBsZS5leGFtcGxlL2lzc3Vp
bmctY2EtaTIuY3JsMHMGCCsGAQUFBwEBBGcwZTAqBggrBgEFBQcwAYYeaHR0cDov
L29jc3AucGtpLnNhbXBsZS5leGFtcGxlMDcGCCsGAQUFBzAChitodHRwOi8vcGtp
LnNhbXBsZS5leGFtcGxlL2lzc3VpbmctY2EtaTIuY3J0MA0GCSqGSIb3DQEBCwUA
A4IBgQBu7hrU4MYBO13tg0VmqVNv4/qXliPTU91EZ2MDbsx1YqJOXTPLR+cUcwwj
V7h142NPdFgLBBLCtpZ2Tux7Qiw/Yt4dIW8hc3OYh7hpIvV8HARa1D8kMVCm2FTn
Tvs8hb+Q1ujORJ+GylRYdKalVvAqrKdvt0UQGj8/ftsVPJCgwvyM2/mbqXYL2yrg
P/BbP0uUq9Ay8TocsZ9Fn6UXbMdkLHNVjmyt6YJn0ibu4a41KcnvFrGdwx0svIHl
ozAefs6LJpXKqlJyQu2wt2sYSACM9lTR8BlhHdN2AIO8VMyE2F7AY0Vp3778zk4v
BgXfdEVdq+xGkMOex+unGtZEV/q5lVRelD5A3wXhK/0mlBM7Ym8SkhCGBhXersjo
m/YJP7rkWuTxzXyy6uRMiXDGRY8yTyHnPCWiWslsW/rklqpy6xpllZAU+V12J/dL
lIiFoV8CaOLy7U29mI4rynIAs01c4xxbC0imwDUMFDdAt/T5dulBnsUMnacpsgD9
hd+QvX8=
-----END CERTIFICATE-----

Specifications

Cn
app.pki.sample.example
San
different.pki.sample.example
Issue
CN and SAN disagree; RFC 6125 clients ignore CN
Serial
0x701007
Sample Only
true
Seed
70117

Testing contract

Expected to fail
Scenario
Verify this certificate for hostname app.pki.sample.example.
Expected result
An RFC 6125-conformant client rejects it because no SAN matches; a client that still falls back to CN incorrectly accepts it.

What is a .pem file?

PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.

How to use this file

Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.

How to use this file for testing

“SAMPLE Leaf Certificate — SAN/CN Mismatch” is a deterministic Novus Examples fixture for Certificate & key testing, Error handling. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.