Skip to content
Novus Examples
pem1.8 KB

SAMPLE S/MIME Email Certificate

An S/MIME-shaped certificate whose SAN is an rfc822Name rather than a DNS name, with the emailProtection EKU and a non-repudiation key usage. Useful for testing address extraction from certificates.

Preview — first 30 linespem
-----BEGIN CERTIFICATE-----
MIIFATCCA2mgAwIBAgIDcBAOMA0GCSqGSIb3DQEBCwUAMF8xCzAJBgNVBAYTAlpa
MSIwIAYDVQQKDBlOb3Z1cyBFeGFtcGxlcyBTQU1QTEUgUEtJMSwwKgYDVQQDDCNO
b3Z1cyBFeGFtcGxlcyBTQU1QTEUgSXNzdWluZyBDQSBJMjAeFw0yNjAxMDEwMDAw
MDBaFw0yNzAxMDEwMDAwMDBaME8xCzAJBgNVBAYTAlpaMSIwIAYDVQQKDBlOb3Z1
cyBFeGFtcGxlcyBTQU1QTEUgUEtJMRwwGgYDVQQDDBNTYW0gUml2ZXJhIChTQU1Q
TEUpMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvFQ+FKvpOhgmcptU
hCZk9Qi/Lc9ginBBdHVVfX7GBD1Lre3h2zBK0ZuqzKhrXjag+hMcyRVolyoPnfpC
Gmn+Jr2QtPAE0UjuG07wWf1I6dhg7dPHjkeWAEzDqT2tb244jnYKVPVzTj7X6L3B
UveZfFiKqzGZp2peQSJ56Coe13XSRdtDUtoG1VYu50Ps9QJR6oKv9b0ujuKc7dhL
/ea6vWrcgVLggKj02auQehLqZ8HOasmxPpr/LW0kcEwCShbHPc2qkgZ7YqNocxbS
B9AdO1Fn3GRVAcY1huI3nLPQ4xL7bzmiinyEac0nPRfcyzIrtZI/3LHaNrW7lSbM
WX+9twIDAQABo4IBVDCCAVAwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUR1HSbgZv
IOtvLlwLfReh+R8Uqu8wDgYDVR0PAQH/BAQDAgXgMCQGA1UdEQQdMBuBGXNhbS5y
aXZlcmFAc2FtcGxlLmV4YW1wbGUwEwYDVR0lBAwwCgYIKwYBBQUHAwQwHwYDVR0j
BBgwFoAUD8kkTA/cebaqtrM3GaVPA5Df0PowQAYDVR0fBDkwNzA1oDOgMYYvaHR0
cDovL2NybC5wa2kuc2FtcGxlLmV4YW1wbGUvaXNzdWluZy1jYS1pMi5jcmwwcwYI
KwYBBQUHAQEEZzBlMCoGCCsGAQUFBzABhh5odHRwOi8vb2NzcC5wa2kuc2FtcGxl
LmV4YW1wbGUwNwYIKwYBBQUHMAKGK2h0dHA6Ly9wa2kuc2FtcGxlLmV4YW1wbGUv
aXNzdWluZy1jYS1pMi5jcnQwDQYJKoZIhvcNAQELBQADggGBALAMFsmc/rbAYude
VlA7x7iB6Ttn3EtQG9MesDtFJN7LeHqWbxyNfWzYcMnFh0/7NIJwCQDh0JjUUbUR
0ZsE5miBAMc2nu2lAMy7XsRnWVGi2Sp1J+b0rZDGJHoBH+C28WYt99X1I760xn+o
mm28XEIcf9Tdve/JChNCVgaromzOL+fOds69HNINTknHnGUnbGj3bs3I9uv6rc2q
vr35MffOrswB24vUgI3rGesvw2bX+70zTJ95jlphYJmiOmB43c+ibaerxsVNLNhc
nIneLRJSZ5JCNS+E1nv6I3GTq0mu7YyPpTrkQUc3eDkMUz7tNpMq2H04H7zbRQPj
WpQIaROmgxIrRLi76YGPf3gomjoShVHpkHK+4i/o+AiuKmYUXC0VgWyQP1v/Yv0H
rCZKEksS69UQ4jfzLqk6pkF+yhZSZcIAG8Do6thYfJ+CXICVuRs0KgoYBOyiMy9K
mWDcgPfaHEDfh/+b7q6t4MG3cwA53bv0zwxvHL1omfjiiwIiNA==
-----END CERTIFICATE-----

Specifications

Eku
emailProtection
Issuer
Novus Examples SAMPLE Issuing CA I2
Serial
0x70100e
Subject
CN=Sam Rivera (SAMPLE),O=Novus Examples SAMPLE PKI,C=ZZ
Sample Only
true
Seed
70117

Testing contract

Expected to pass
Scenario
Extract the signing identity from the certificate for an S/MIME verification flow.
Expected result
The rfc822Name SAN sam.rivera@sample.example is returned as the identity, and the emailProtection EKU is reported.

What is a .pem file?

PEM (Privacy-Enhanced Mail) is a text container that Base64-encodes DER binary data between BEGIN/END header lines, used to hold X.509 certificates, certificate requests, and keys. A single .pem file may contain a certificate, a chain, or a private key, which makes it the most common format for TLS material.

How to use this file

Use an example .pem certificate to test X.509 and TLS parsers, PEM decoders, certificate-chain validators, and PEM-to-DER converters. This is published sample material — never a real production key.

How to use this file for testing

“SAMPLE S/MIME Email Certificate” is a deterministic Novus Examples fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file — all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion — never deploy it anywhere real.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.