Skip to content
Novus Examples
pem1.8 KB

SAMPLE Leaf Certificate — Wildcard SAN

A wildcard certificate covering *.wild.pki.sample.example plus the bare apex. Use it to check that a matcher accepts exactly one label and refuses to stretch the wildcard across a dot.

Preview — first 31 linespem
-----BEGIN CERTIFICATE-----
MIIFKjCCA5KgAwIBAgIDcBAJMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaMFUxCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSIwIAYDVQQDDBkqLndpbGQucGtpLnNhbXBs
ZS5leGFtcGxlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvFQ+FKvp
OhgmcptUhCZk9Qi/Lc9ginBBdHVVfX7GBD1Lre3h2zBK0ZuqzKhrXjag+hMcyRVo
lyoPnfpCGmn+Jr2QtPAE0UjuG07wWf1I6dhg7dPHjkeWAEzDqT2tb244jnYKVPVz
Tj7X6L3BUveZfFiKqzGZp2peQSJ56Coe13XSRdtDUtoG1VYu50Ps9QJR6oKv9b0u
juKc7dhL/ea6vWrcgVLggKj02auQehLqZ8HOasmxPpr/LW0kcEwCShbHPc2qkgZ7
YqNocxbSB9AdO1Fn3GRVAcY1huI3nLPQ4xL7bzmiinyEac0nPRfcyzIrtZI/3LHa
NrW7lSbMWX+9twIDAQABo4IBdzCCAXMwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQU
R1HSbgZvIOtvLlwLfReh+R8Uqu8wDgYDVR0PAQH/BAQDAgWgMD0GA1UdEQQ2MDSC
GSoud2lsZC5wa2kuc2FtcGxlLmV4YW1wbGWCF3dpbGQucGtpLnNhbXBsZS5leGFt
cGxlMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAfBgNVHSMEGDAWgBQP
ySRMD9x5tqq2szcZpU8DkN/Q+jBABgNVHR8EOTA3MDWgM6Axhi9odHRwOi8vY3Js
LnBraS5zYW1wbGUuZXhhbXBsZS9pc3N1aW5nLWNhLWkyLmNybDBzBggrBgEFBQcB
AQRnMGUwKgYIKwYBBQUHMAGGHmh0dHA6Ly9vY3NwLnBraS5zYW1wbGUuZXhhbXBs
ZTA3BggrBgEFBQcwAoYraHR0cDovL3BraS5zYW1wbGUuZXhhbXBsZS9pc3N1aW5n
LWNhLWkyLmNydDANBgkqhkiG9w0BAQsFAAOCAYEACNJa16OawELdU7x0+/Axc8S2
XgnuxhKL1YG2n6krKnXd5aFiUHbIpOQcwu2ZpGpPrwUWY7Pth1Tr1pynsxVcJygC
6kdT2EO11G/h0tktFND/f848BrqJFrYZ59s/s05Q6pN2eIuL+7o8+eeG43U6naxm
sxEwPPrSvzahzL5m46ROOQAjKIuW6j6wUxydzOjRrtFie/PEq3T93aQrti6ugAJE
mcQwYoyq52zXsLY861bn0EsikYzfQEUZ6ewtLpvCThLM9LshkMm4QMVOSwcVELzg
jRCIkdxS1Zv3VkdXNyj4XDMRFAV56vWdvxF9NqqErP/DeW3YiUNumQ8TP9aqyeB9
4ZUEUep+tJ4GWeOlGnJY9oj5aN+kEey4vPA6GS41gpOmlCE1TPVWLktRDUTYvpaJ
dzoOm3D+R/HKB91SN24hCOKd8tOBFw7M4rP0jPAVkPWEHANazcj/nIzdC/79dIxY
qNjEC+/NENl5dq/j6MhSqWDv4vbyTq46q6gCZ53u
-----END CERTIFICATE-----

Specifications

San
*.wild.pki.sample.example, wild.pki.sample.example
Matches
one label only
Serial
0x701009
Sample Only
true
Seed
70117

Testing contract

Expected to pass
Scenario
Match a.wild.pki.sample.example, wild.pki.sample.example, and a.b.wild.pki.sample.example against this certificate.
Expected result
The first two match; the two-label a.b.wild.pki.sample.example is rejected because a wildcard covers a single label.

What is a .pem file?

PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.

How to use this file

Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.

How to use this file for testing

“SAMPLE Leaf Certificate — Wildcard SAN” is a deterministic Novus Examples fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.