1A real world extensions sequence (taken from Google's GAI2). 2 3#-----BEGIN EXTENSIONS----- 4SEQUENCE { 5 SEQUENCE { 6 # authorityKeyIdentifier 7 OBJECT_IDENTIFIER { 2.5.29.35 } 8 OCTET_STRING { 9 SEQUENCE { 10 [0 PRIMITIVE] { `c07a98688d89fbab05640c117daa7d65b8cacc4e` } 11 } 12 } 13 } 14 SEQUENCE { 15 # subjectKeyIdentifier 16 OBJECT_IDENTIFIER { 2.5.29.14 } 17 OCTET_STRING { 18 OCTET_STRING { `4add06161bbcf668b576f581b6bb621aba5a812f` } 19 } 20 } 21 SEQUENCE { 22 # keyUsage 23 OBJECT_IDENTIFIER { 2.5.29.15 } 24 BOOLEAN { `ff` } 25 OCTET_STRING { 26 BIT_STRING { `0106` } 27 } 28 } 29 SEQUENCE { 30 # authorityInfoAccess 31 OBJECT_IDENTIFIER { 1.3.6.1.5.5.7.1.1 } 32 OCTET_STRING { 33 SEQUENCE { 34 SEQUENCE { 35 # ocsp 36 OBJECT_IDENTIFIER { 1.3.6.1.5.5.7.48.1 } 37 [6 PRIMITIVE] { "http://g.symcd.com" } 38 } 39 } 40 } 41 } 42 SEQUENCE { 43 # basicConstraints 44 OBJECT_IDENTIFIER { 2.5.29.19 } 45 BOOLEAN { `ff` } 46 OCTET_STRING { 47 SEQUENCE { 48 BOOLEAN { `ff` } 49 INTEGER { 0 } 50 } 51 } 52 } 53 SEQUENCE { 54 # cRLDistributionPoints 55 OBJECT_IDENTIFIER { 2.5.29.31 } 56 OCTET_STRING { 57 SEQUENCE { 58 SEQUENCE { 59 [0] { 60 [0] { 61 [6 PRIMITIVE] { "http://g.symcb.com/crls/gtglobal.crl" } 62 } 63 } 64 } 65 } 66 } 67 } 68 SEQUENCE { 69 # certificatePolicies 70 OBJECT_IDENTIFIER { 2.5.29.32 } 71 OCTET_STRING { 72 SEQUENCE { 73 SEQUENCE { 74 OBJECT_IDENTIFIER { 1.3.6.1.4.1.11129.2.5.1 } 75 } 76 } 77 } 78 } 79} 80#-----END EXTENSIONS----- 81 82 83-----BEGIN CERTIFICATE----- 84MIIC8DCCAlmgAwIBAgIJAPuwTC6rEJsMMA0GCSqGSIb3DQEBBQUAMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwHhcNMTQwNDIzMjA1MDQwWhcNMTcwNDIyMjA1MDQwWjBFMQswCQYDVQQGEwJBVTETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDYK8imMuRi/03z0K1Zi0WnvfFHvwlYeyK9Na6XJYaUoIDAtB92kWdGMdAQhLciHnAjkXLI6W15OoV3gA/ElRZ1xUpxTMhjP6PyY5wqT5r6y8FxbiiFKKAnHmUcrgfVW28tQ+0rkLGMryRtrukXOgXBv7gcrmU7G1jC2a7WqmeI8QIDAQABo4HnMIHkMB8GA1UdIwQYMBaAFMB6mGiNifurBWQMEX2qfWW4ysxOMB0GA1UdDgQWBBRK3QYWG7z2aLV29YG2u2IaulqBLzAOBgNVHQ8BAf8EBAMCAQYwLgYIKwYBBQUHAQEEIjAgMB4GCCsGAQUFBzABhhJodHRwOi8vZy5zeW1jZC5jb20wEgYDVR0TAQH/BAgwBgEB/wIBADA1BgNVHR8ELjAsMCqgKKAmhiRodHRwOi8vZy5zeW1jYi5jb20vY3Jscy9ndGdsb2JhbC5jcmwwFwYDVR0gBBAwDjAMBgorBgEEAdZ5AgUBMA0GCSqGSIb3DQEBBQUAA4GBADvoeG2V1j1q9xMZLBvCiK4iq/SNMvV8cWfPLdEcwsOH4um+iVzkNKtIkcI/la4rR54leGtPmhCkcv3P9wIMsAoIpFri5XR+ER05YGrJH2nzLmMm3J7va3oK4VRXmKpykXgEfh+PZU0fCxKsnCQPhBQaVS0fu/CdCbIIXFkyZYAm 85-----END CERTIFICATE----- 86