SAMPLE PKCS#7 Certificate Bundle (PEM)
A degenerate (certificates-only) PKCS#7 structure holding all three SAMPLE certificates under BEGIN PKCS7 armour — the payload Windows and Java tools distribute as a .p7b. It carries no private key and no signature over any content.
-----BEGIN PKCS7-----
MIIP9gYJKoZIhvcNAQcCoIIP5zCCD+MCAQExADALBgkqhkiG9w0BBwGggg/LMIIF
HjCCAwagAwIBAgIDcAACMA0GCSqGSIb3DQEBCwUAMFwxCzAJBgNVBAYTAlpaMSIw
IAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSkwJwYDVQQDDCBOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUm9vdCBDQSBSMTAeFw0yNDAxMDEwMDAwMDBaFw0z
NDAxMDEwMDAwMDBaMF8xCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1cyBFeGFt
cGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNOb3Z1cyBFeGFtcGxlcyBTQU1QTEUg
SXNzdWluZyBDQSBJMjCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAMar
Om90SEq+1J9YSOlgjViGXmRY+52mrK5RMGjKSpJM6sIMr2tMtHIhUSak8ne0a4PD
mv55Yv1FybObPDzlG3F/tUn6+QIj10PFb/84HrtkoAwPWLsJQC0vpplayY1XmhYs
lZ9Hb34pHwzx1xmLChpU77hxrgSuDEZbb9GFNXeAGDTkKeGSx9BEXEiruvj+U79K
n7gViiJnrmCEPDNqvO0Mk5vhysGT/RYHVhWsr3sjpcrpNn0ZUTVIaTya55L0irqd
kSptRb/ElqNQyrJwVQbJtkMNTeV8PZ9zC4wsyxeFS8arWBPV83ykEMjCW7qJ97+H
+TcMroewrQfLSlgB0rB2a0o6YB61mH+T3LrRXhql1K3Q4pzHUzILMN7xf+qdGI4E
6y/HBpgDJNjCkwQfkiN0Q5Mgkb6CK5Dr7I1oI5/IQER/LHVbBMpKkcpreZaIgVDI
HtPX7vnAWewJBwVqsg125AD00Y6imJx+AIuhamPSildo3zWYhRh40eI/TORDpwID
AQABo2YwZDASBgNVHRMBAf8ECDAGAQH/AgEAMB0GA1UdDgQWBBQPySRMD9x5tqq2
szcZpU8DkN/Q+jAOBgNVHQ8BAf8EBAMCAYYwHwYDVR0jBBgwFoAUhWTpSaA3g2hV
FLw+1sbf95Gn3RswDQYJKoZIhvcNAQELBQADggIBACqcGae2JORx6VcZYrkiAXsY
bObv56q5kZbzG/1ysR+MgGCY6YcJDenUVpCCRvFnugnZ6P9eVOZeE4lt6CNLV5oK
AKlZE5lVASiGV970jmzbxn2/m5VnuJ83E0HcD0HhZHEdWheh+I7wsrlnn+hfoG3E
5v8jZuYo0d99YPY11w5yLmwePtbh1bmPquDebxvmkkU02fyzsuDVs5QVFFoRYJbt
m8dhYx5hfmqzae77sSbyBnd5aT8v/CLk6MNjuGPnTFy/V10VxqI+XLkE10uGGB2k
9rGX35CA3rhU8s6SObYFpxoR1HpCoB0RkkSc+7TYuIq8lvVb4nNypRIu9sM321m/
htlRHDwuz35R6tyZOpX2UvZ62gr4XEpLYRTBTdRlQiE7v+vClfuC82Zu3qFWvrwK
w5J6z2f0fi/mjjUWMjSXOJWFkujM80SI6sHf+ih3NtxI1fQ4yibZeXKDypuaZ/5T
fhPxwiFGLzq5JbikN2O4xkIWi8wt1zfrWqI9B5iZkc8NtwoUS2OYKti+Y/tOYKrM
UMOF6UF/z6jbWVVNfQPTscQxayVQDc/GiOgFpCBAbkTcj4vTWFMWA/fuwWaWmHcI
gC+rj8GqAknGvdzInyhlxlV2LCUaY4mxiy1CbxDBxiAu11qVBnSHqf8uC7uPbyRH
wkp8WN92cn85TxDn4SpIMIIFKjCCA5KgAwIBAgIDcBABMA0GCSqGSIb3DQEBCwUA
MF8xCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUg
UEtJMSwwKgYDVQQDDCNOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJ
MjAeFw0yNjAxMDEwMDAwMDBaFw0yNzAxMDEwMDAwMDBaMFMxCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSAwHgYDVQQDDBds
ZWFmLnBraS5zYW1wbGUuZXhhbXBsZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBALxUPhSr6ToYJnKbVIQmZPUIvy3PYIpwQXR1VX1+xgQ9S63t4dswStGb
qsyoa142oPoTHMkVaJcqD536Qhpp/ia9kLTwBNFI7htO8Fn9SOnYYO3Tx45HlgBM
w6k9rW9uOI52ClT1c04+1+i9wVL3mXxYiqsxmadqXkEieegqHtd10kXbQ1LaBtVW
LudD7PUCUeqCr/W9Lo7inO3YS/3mur1q3IFS4ICo9NmrkHoS6mfBzmrJsT6a/y1t
JHBMAkoWxz3NqpIGe2KjaHMW0gfQHTtRZ9xkVQHGNYbiN5yz0OMS+285oop8hGnN
Jz0X3MsyK7WSP9yx2ja1u5UmzFl/vbcCAwEAAaOCAXkwggF1MAwGA1UdEwEB/wQC
MAAwHQYDVR0OBBYEFEdR0m4GbyDrby5cC30XofkfFKrvMA4GA1UdDwEB/wQEAwIF
oDA/BgNVHREEODA2ghdsZWFmLnBraS5zYW1wbGUuZXhhbXBsZYIbd3d3LmxlYWYu
cGtpLnNhbXBsZS5leGFtcGxlMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcD
AjAfBgNVHSMEGDAWgBQPySRMD9x5tqq2szcZpU8DkN/Q+jBABgNVHR8EOTA3MDWg
M6Axhi9odHRwOi8vY3JsLnBraS5zYW1wbGUuZXhhbXBsZS9pc3N1aW5nLWNhLWky
LmNybDBzBggrBgEFBQcBAQRnMGUwKgYIKwYBBQUHMAGGHmh0dHA6Ly9vY3NwLnBr
aS5zYW1wbGUuZXhhbXBsZTA3BggrBgEFBQcwAoYraHR0cDovL3BraS5zYW1wbGUu
ZXhhbXBsZS9pc3N1aW5nLWNhLWkyLmNydDANBgkqhkiG9w0BAQsFAAOCAYEAwait
n0jderGdnw2GLR9NSTHdox70r4a+jR26GN7oJB2oJO9r6bkp/DRjwBFKwGj0tvHISpecifications
- Format
- PKCS#7 / CMS degenerate certs-only
- Armour
- BEGIN PKCS7
- Certs
- 3
- Contains
- leaf, intermediate, root
- Keys
- none
- Note
- the payload a .p7b file carries
- Sample Only
- true
- Seed
- 70117
Testing contract
Expected to pass- Scenario
- Import the bundle into a keystore tool and enumerate the certificates it contains.
- Expected result
- Three certificates are extracted — leaf, intermediate, and root — and no private key or signed content is reported.
What is a .pem file?
PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.
How to use this file
Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.
How to use this file for testing
“SAMPLE PKCS#7 Certificate Bundle (PEM)” is a deterministic Novus Examples fixture for Certificate & key testing, Conversion testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.
Documented properties for this file: seed 70117 · PKCS#7 / CMS degenerate certs-only. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.
This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.
Related files
- derSAMPLE Certificate Revocation List (DER)Binary DER twin of the SAMPLE CRL — the exact encoding a CRL distribution point serves over HTTP. Use it to test binary CRL fetching and caching paths that never see PEM armour.

- keySAMPLE EC P-256 Private Key — SEC 1The same P-256 scalar in the SEC 1 container (BEGIN EC PRIVATE KEY), which names the curve inline instead of through a PKCS#8 algorithm identifier. Some deployment tools accept only one of the two.

- derSAMPLE Intermediate CA Certificate (DER)Binary DER encoding of the SAMPLE intermediate CA certificate — the same bytes the PEM twin Base64-wraps. Feed it to ASN.1 decoders, Java keystores, and DER-to-PEM converters.

- derSAMPLE Leaf Certificate (DER)Binary DER encoding of the SAMPLE leaf certificate — the same bytes the PEM twin Base64-wraps. Feed it to ASN.1 decoders, Java keystores, and DER-to-PEM converters.

- derSAMPLE Root CA Certificate (DER)Binary DER encoding of the SAMPLE root CA certificate — the same bytes the PEM twin Base64-wraps. Feed it to ASN.1 decoders, Java keystores, and DER-to-PEM converters.

- keySAMPLE RSA Private Key — PKCS#1, UnencryptedThe identical key material wrapped in the legacy PKCS#1 container (BEGIN RSA PRIVATE KEY), which omits the algorithm OID that PKCS#8 carries. Diff it against its PKCS#8 twin to see exactly what a container migration changes.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.