Skip to content
Novus Examples
pem1.8 KB

SAMPLE Leaf Certificate — Wrong Common Name

A valid, correctly chained certificate for the wrong host: both CN and SAN say wrong-host.pki.sample.example. Serve it for leaf.pki.sample.example to exercise the hostname-verification path on its own.

Preview — first 31 linespem
-----BEGIN CERTIFICATE-----
MIIFGTCCA4GgAwIBAgIDcBAGMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaMFkxCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSYwJAYDVQQDDB13cm9uZy1ob3N0LnBraS5z
YW1wbGUuZXhhbXBsZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALxU
PhSr6ToYJnKbVIQmZPUIvy3PYIpwQXR1VX1+xgQ9S63t4dswStGbqsyoa142oPoT
HMkVaJcqD536Qhpp/ia9kLTwBNFI7htO8Fn9SOnYYO3Tx45HlgBMw6k9rW9uOI52
ClT1c04+1+i9wVL3mXxYiqsxmadqXkEieegqHtd10kXbQ1LaBtVWLudD7PUCUeqC
r/W9Lo7inO3YS/3mur1q3IFS4ICo9NmrkHoS6mfBzmrJsT6a/y1tJHBMAkoWxz3N
qpIGe2KjaHMW0gfQHTtRZ9xkVQHGNYbiN5yz0OMS+285oop8hGnNJz0X3MsyK7WS
P9yx2ja1u5UmzFl/vbcCAwEAAaOCAWIwggFeMAwGA1UdEwEB/wQCMAAwHQYDVR0O
BBYEFEdR0m4GbyDrby5cC30XofkfFKrvMA4GA1UdDwEB/wQEAwIFoDAoBgNVHREE
ITAfgh13cm9uZy1ob3N0LnBraS5zYW1wbGUuZXhhbXBsZTAdBgNVHSUEFjAUBggr
BgEFBQcDAQYIKwYBBQUHAwIwHwYDVR0jBBgwFoAUD8kkTA/cebaqtrM3GaVPA5Df
0PowQAYDVR0fBDkwNzA1oDOgMYYvaHR0cDovL2NybC5wa2kuc2FtcGxlLmV4YW1w
bGUvaXNzdWluZy1jYS1pMi5jcmwwcwYIKwYBBQUHAQEEZzBlMCoGCCsGAQUFBzAB
hh5odHRwOi8vb2NzcC5wa2kuc2FtcGxlLmV4YW1wbGUwNwYIKwYBBQUHMAKGK2h0
dHA6Ly9wa2kuc2FtcGxlLmV4YW1wbGUvaXNzdWluZy1jYS1pMi5jcnQwDQYJKoZI
hvcNAQELBQADggGBAKpZAkD7Notbj4XtpnJLDOjuaSrMas0os1FLLSFfHnoxtpnd
Oik1laeZZfsRKHXNlA/wf3dDcRtLsAM6oQzIughuI+hEju8+pwvXlzi7XNUWzcv2
hShCZIaVTlYUk9aiuivJEt5DsTIcH2TvCebTlqfzupczOejOX84mfPYAoYHiLrEk
N3Sb7+12fEkLx7zTUCicnzueXNux6RAm1o4sZtpeQTg/I7yp7B9a8UeoMy+x/UWC
jLbU043NYzGBgAZmaMQ2eTiuYfWFt4iQeGhTToIAVtPAq5enjusY5WzbvD5HSvgL
yPw0bcpigNY7aAKmsAsU33iOkv6qL0PNoOUUcTLpA8JB1liXKBzvb3Ha0D221D6P
ydDeJAK59X8Thul56wvVAHsKRQrol8UVPuGepTbb3JfykGuligNbhsN0qnSq1r8C
d0e3fNKn0evbQFEYJlF+5vUKoFpOWAYMkDEYQilASo2i736LOFm3N/b4ujiuWzmM
L7onw7CwmjuwsDKfww==
-----END CERTIFICATE-----

Specifications

Cn
wrong-host.pki.sample.example
San
wrong-host.pki.sample.example
Presented For
leaf.pki.sample.example
Serial
0x701006
Sample Only
true
Seed
70117

Testing contract

Expected to fail
Scenario
Verify the chain for hostname leaf.pki.sample.example using this certificate.
Expected result
Chain building succeeds but hostname verification fails, naming wrong-host.pki.sample.example as the presented identity.

What is a .pem file?

PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.

How to use this file

Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.

How to use this file for testing

“SAMPLE Leaf Certificate — Wrong Common Name” is a deterministic Novus Examples fixture for Certificate & key testing, Error handling. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.