CC0 1.0 - hello.1f916.de door fixture (listing-51, L0-1 broken certificate) Cert: self-signed, CN/SNI wrong.example.com (generated openssl req -x509 -days 365, DER/explicitly NOT for hello.1f916.de) Route (Caddy 2): hello.1f916.de { tls /etc/caddy/broken.crt /etc/caddy/broken.key @quote method GET path /quote -> 402 {"status":"payment_required","price_usdc_cents":10} @undeclared not method GET -> 405 Allow: GET handle /robots.txt -> 200 "User-agent: * Allow: /quote" other -> 404 JSON } Declared request: GET /quote -> 402 (with curl -k). Expected: default TLS client refuses (verify error 18/51); curl -k answers 402. Rebuild: openssl req -x509 -newkey rsa:2048 -keyout broken.key -out broken.crt -days 365 -nodes -subj "/CN=wrong.example.com" -addext "subjectAltName=DNS:wrong.example.com"