Skip to content
Novus Examples
crt1.9 KB

SAMPLE Root CA Certificate (PEM)

The self-signed root of the Novus Examples SAMPLE certificate hierarchy (RSA-4096, CA:TRUE, no path-length limit). Install it as the only trust anchor to make the rest of this wave's chains verifiable in a sandbox. Fictional issuer — never a real identity.

Preview — first 33 linescrt
-----BEGIN CERTIFICATE-----
MIIFdzCCA1+gAwIBAgIDcAABMA0GCSqGSIb3DQEBCwUAMFwxCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSkwJwYDVQQDDCBO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgUm9vdCBDQSBSMTAeFw0yMDAxMDEwMDAwMDBa
Fw00MDAxMDEwMDAwMDBaMFwxCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1cyBF
eGFtcGxlcyBTQU1QTEUgUEtJMSkwJwYDVQQDDCBOb3Z1cyBFeGFtcGxlcyBTQU1Q
TEUgUm9vdCBDQSBSMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAOHk
4ei9BVbSA7LszYI4uhZ50ejUuVDg27BrAMQKjjV6GVDfyYQiQ1On9t5dEb0k2bfU
FTfhUcPjTMJ4DgX95+UWG1vs5zkcYjYvEvEESp1JZLVc+UwY3+5eY3cDnl8BAyFa
3QyC+qWJSNRanDpV1t6/14v7OnAu2e8jVPQ387eawmvoLEvoKtzwElwpoz5+Nu4z
xQCktfleQC3pfvQOqbv4s7U0bUqKOBMEUjaVl2cVRAy4utpvlIKcJpq7jcIMdK84
YjvyqCij9urJK6QDj+X/MSrm9IDz/hL+qaSJkEsJkd5hx86DOOoeW1GEZo2KerWj
1zZB/Ar7WX5duKij1gAUo1xdQY8FDCr02+hhngR5/Li60fESMHxXzOi+Dzmd0Dhs
3M1VHpMHTXbIGeJ3Wa//RZdtfXGc98MusuViBV4D/Zz5iEN+K7NrWNPcqp6EZDMa
K+DoXjziFGYujBuQ39YHDEFd7tobsbqbf24DrvIN5boPUBmcnMMDHu/0uEHlbiQw
v//XI8dTKBTxe+pNd4UJeK1jt7W39DGoHcHgJc1Ke5ndTWOzatJGLigs8YGoM7ys
7UktDErNHb1WE76PG1X+4edwR3r+M04vTUq0Kv4T0ujPYL294cPInJDUZHsXTj1P
MdGY8iRVLfvWJiPNyc0vCsUz0NpHgLFiYZKjD+9FAgMBAAGjQjBAMA8GA1UdEwEB
/wQFMAMBAf8wHQYDVR0OBBYEFIVk6UmgN4NoVRS8PtbG3/eRp90bMA4GA1UdDwEB
/wQEAwIBhjANBgkqhkiG9w0BAQsFAAOCAgEA39qSNEKOVaQpbNtQJdiO3uiuA7CJ
VJu33MMxryy2IUVC9UNbhrLGkd1xui06j1UZGd+/P6iQ12dvk7BVCfa0tv+7nX8S
Ct5hhb/8GseOI3Gg0ho5Ppf23bFngfdQzEVFmIcd5SlTt2AAaclfgYRrPNQNkuR/
oZiV4dUfXlB6z3KN4X/Y6twNLFyWIH6MgJKFO8erjw9PtPT41ig4sdsHOvEtA5R7
crS/XdMBABxzV8W9cgeYt3RtgfSfjfLQOHRbJa+MRBbfyJJ8IL/ToH+4BIrMWBrd
OLPWWa5KD+H4Sy9asl9OgYFJ8r1VepHCL3b2Q/L3akABsFuVDupL7tLyDQBvky0a
UJfC7L4TKlAgjiySdFUgIwIsgqbKqsOzPizM2vqrBTleMdY5zCgv/60LPQAVGrv2
icLhOxGsN6wPndWTpsznaxJYJNmzPfYDsKUwA4pzVeMTUz64ES/lK0YwOzvhyZ1W
niHC2/PAmb+MTUgK1ueO1OD+MIxda/5tQSHQ4mOExnKDSiZdvxTEXT2muUQSuasW
hfCD0A1NxjX+ZAUTEfqinrplg+67CbSIUanLvrZVr+Ee9COB4xS3IQdlAe17KGhJ
YnhqYokNT2jgVp5qFTVTNO7pKRrD6hFU5iPJXGvzGSkokiWD3rR8zruhDi1fbZHg
G2JlrMMH22NaxO0=
-----END CERTIFICATE-----

Specifications

Role
root CA
Key
RSA-4096
Self Signed
true
Basic Constraints
CA:TRUE
Path Len
none
Validity
2020-01-01 to 2040-01-01
Serial
0x700001
Signature
sha256WithRSAEncryption
Sample Only
true
Seed
70117

Testing contract

Reference control
Scenario
Load the certificate into a test trust store and build a path from any p7 leaf.
Expected result
Parses as an X.509 v3 CA certificate; chain building to any p7 leaf succeeds with this as the only anchor.

What is a .crt file?

A .crt file holds an X.509 certificate, most often PEM-encoded (Base64 text) though sometimes DER binary. The extension is a convention for the public certificate half of a TLS identity, as opposed to the private .key file. It carries the subject, issuer, validity window, public key, and signature.

How to use this file

Use an example .crt to test certificate parsers, trust-store importers, and TLS tooling, or as input for .crt-to-.pem/.der conversion. Sample material only, self-signed and clearly labelled.

How to use this file for testing

“SAMPLE Root CA Certificate (PEM)” is a deterministic Novus Examples fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117 · root CA. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.