PKCS#12 Bundle (.p12)
A PKCS#12 (.p12/PFX) bundle packaging the sample RSA key and certificate together, protected with the sample password 'novus-sample', for testing keystore importers and PKCS#12 parsers. (The PKCS#12 MAC salt is random, so this file is intentionally not byte-stable.)
| Field | Value |
|---|---|
| Type | PKCS#12 / PFX bundle (binary) |
| Contains | RSA 2048 private key + X.509 certificate |
| Friendly name | novus-sample |
| Password | novus-sample (sample-only) |
| Encryption | PBE (per-file random salt) |
Specifications
- Format
- PKCS#12 (PFX)
- Contains
- RSA key + certificate
- Password
- novus-sample
- Byte Stable
- false
- Sample Only
- true
Testing contract
Expected to pass- Scenario
- Exercise PKCS#12 Bundle (.p12) in its security workflow. A PKCS#12 (.p12/PFX) bundle packaging the sample RSA key and certificate together, protected with the sample password 'novus-sample', for testing keystore importers and PKCS#12 parsers.
- Expected result
- private key present=True; leaf certificate present=True; additional certificates=0; certificate subject=CN=sample.example,O=Novus Examples (Sample),C=US. Declared feature checks: contains=RSA key + certificate; password=novus-sample; byteStable=False.
What is a .p12 file?
A .p12 file is a PKCS#12 (PFX) bundle: a password-protected binary archive that packages a certificate together with its private key (and optionally a chain) in one importable file. It is the standard way to move a complete TLS or client identity between systems.
How to use this file
Use an example .p12 to test PKCS#12 parsers and importers, keystore tooling, and password-protected bundle handling. The sample password is documented on the file's page; this is published sample material, not a real identity.
How to use this file for testing
“PKCS#12 Bundle (.p12)” is a deterministic Testaroo fixture for Certificate & key testing. Self-signed X.509 certificates (PEM, CRT, DER), a CSR, RSA and Ed25519 keys, an SSH public key, a PKCS#12 bundle, and an htpasswd file, all published sample-only material, for testing certificate parsers, TLS tooling, keystore importers, and PEM/DER decoders.
Documented properties for this file: PKCS#12 (PFX). Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such, expect parsers to fail loudly rather than silently accept them.
Data fixtures document their exact quirks (delimiters, encodings, null handling, schema, and row counts) in the spec table. Point your parser or importer at the file and assert it handles the documented edge cases; clean and deliberately-messy siblings make before/after diffs straightforward.
This is a published, sample-only certificate/key. Parse it, verify the chain or signature, and test PEM↔DER conversion, never deploy it anywhere real.
Generated by generation/pki_security.py. Free for any use, no attribution required, license.
Related files
- csrCertificate Signing Request (CSR)A PKCS#10 certificate signing request (PEM) with the subject and SAN, self-signed by the RSA key to prove key possession, for testing CSR parsers and certificate-authority intake flows.

- keyEd25519 Private Key (PEM)An Ed25519 private key in PKCS#8 PEM, derived from a fixed seed: a published, sample-only modern elliptic-curve key for testing PEM parsers and Ed25519 tooling. Never use it for real.

- htpasswdhtpasswd (HTTP Basic Auth)An Apache/nginx .htpasswd file with two users hashed using the {SHA} scheme (Base64 SHA-1): the sample passwords are documented in the file, for testing Basic-Auth credential parsers and hash identification.

- keyRSA 2048 Private Key (PEM)A 2048-bit RSA private key in unencrypted PKCS#8 PEM: a deliberately PUBLISHED, sample-only key for testing PEM key parsers and PKCS#8 decoders. Never use it for anything real.

- pubSSH Public Key (Ed25519)An OpenSSH-format Ed25519 public key (the shareable half of the key pair): a single line of algorithm, Base64 key blob, and comment, for testing SSH public-key parsers and authorized_keys tooling.

- crtX.509 Certificate (.crt)The same self-signed certificate under the conventional .crt extension (PEM-encoded), for testing trust-store importers and tools that key off the .crt extension. Sample only.
