zaur.it sample certificates - NOT TRUSTED

Test certificates from a test PKI of its own ("zaur.it Test Root CA - NOT TRUSTED").
Do not install the root in any trust store. The private keys were deleted after the
build: nothing here contains a key, and nothing here can be used on a real server.
Names and addresses are reserved for documentation and testing: example.com/.net/.org
(RFC 2606), .test (RFC 6761), 192.0.2.0/24 (RFC 5737), 2001:db8::/32 (RFC 3849).

Open any file in the decoder: https://zaur.it/tools/certificate-decoder/
Built with OpenSSL 3.5.7 9 Jun 2026 (Library: OpenSSL 3.5.7 9 Jun 2026). Checksums: SHA256SUMS next to this archive on the site.

  Valid    server-leaf                 Server certificate, RSA 2048. www.example.com and example.com. Only the "not in the paste" note for its issuer and the private-CA lifetime note.
  Valid    server-fullchain            Full chain: server + intermediate. Leaf first, then the issuing CA: the chain order check passes.
  Valid    wildcard                    Wildcard certificate. *.example.com plus example.com in the SAN.
  Valid    multi-san                   Several names and IP addresses. Four DNS names, an IPv4 and an IPv6 address in one certificate.
  Valid    ec-p256                     EC P-256 key. Elliptic curve key on P-256, signed by the RSA issuing CA.
  Valid    ec-p384                     EC P-384 key. Elliptic curve key on P-384.
  Valid    ed25519                     Ed25519 key. Edwards-curve key. Public CAs do not issue these.
  Valid    client-auth                 Client authentication. Client Authentication purpose and an email address, no host names.
  Valid    code-signing                Code signing. Code Signing purpose, RSA 3072.
  Valid    root-ca                     Root CA (self-signed). CA:TRUE, path length 1, RSA 4096. Shown as a CA certificate pasted alone.
  Valid    intermediate-ca             Intermediate (issuing) CA. CA:TRUE, path length 0, RSA 3072.
  Problems expired-leaf                Expired certificate. Expired on 1 March 2025.
  Problems not-yet-valid               Not yet valid. Starts on 1 January 2035.
  Problems no-san                      No subject alternative name. Common name only: browsers match no host name.
  Problems sha1-signed                 SHA-1 signature. Signed with SHA-1, rejected by browsers.
  Problems rsa-1024                    RSA 1024 key. Key too small for any public CA.
  Problems self-signed-server          Self-signed server certificate. As appliances ship them: trusted by nobody until installed.
  Problems chain-wrong-order           Chain in the wrong order. Intermediate first, then the leaf.
  Problems chain-missing-intermediate  Leaf without its intermediate. What a misconfigured server sends: the issuing CA is missing.
  CSRs     csr-with-san                CSR with two SAN names. RSA 2048, SHA-256, two DNS names requested.
  CSRs     csr-no-san                  CSR without SAN. Common name only: the decoder notes that no SAN is requested.
  CSRs     csr-ec-p256                 CSR with an EC P-256 key. Elliptic curve request with one SAN name.
