| OLD | NEW | 
|---|
| (Empty) |  | 
|  | 1 [Created by: generate-basic-constraints-pathlen-0-self-issued.py] | 
|  | 2 | 
|  | 3 Certificate chain with 2 intermediaries. The first | 
|  | 4 intermediary has a basic constraints path length of 0. The second one is | 
|  | 5 self-issued so does not count against the path length. | 
|  | 6 | 
|  | 7 Certificate: | 
|  | 8     Data: | 
|  | 9         Version: 3 (0x2) | 
|  | 10         Serial Number: 1 (0x1) | 
|  | 11     Signature Algorithm: sha256WithRSAEncryption | 
|  | 12         Issuer: CN=Intermediary | 
|  | 13         Validity | 
|  | 14             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 15             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 16         Subject: CN=Target | 
|  | 17         Subject Public Key Info: | 
|  | 18             Public Key Algorithm: rsaEncryption | 
|  | 19                 Public-Key: (2048 bit) | 
|  | 20                 Modulus: | 
|  | 21                     00:da:6c:52:80:62:b4:74:cb:b7:65:77:76:7a:84: | 
|  | 22                     8c:ef:40:61:40:9e:48:db:29:0e:ff:d0:3d:a1:0a: | 
|  | 23                     53:26:27:5c:34:b6:6b:50:f8:b8:f2:5c:13:40:db: | 
|  | 24                     18:fd:8d:98:ec:7f:5c:b0:6a:f6:f6:42:cf:03:fc: | 
|  | 25                     a1:b9:cf:55:b3:d0:47:5a:e3:0e:22:bb:c0:27:0c: | 
|  | 26                     4e:da:76:72:c6:61:a7:81:08:31:80:19:27:fc:51: | 
|  | 27                     a9:97:2b:44:7d:24:20:c2:af:a8:6d:56:26:0c:f8: | 
|  | 28                     05:0a:e5:db:8d:48:93:85:74:f5:a9:83:50:fe:df: | 
|  | 29                     dd:9c:f1:a0:01:c4:dd:1d:52:1c:24:82:1b:10:b8: | 
|  | 30                     08:38:78:ab:fe:da:3c:bf:a4:36:d3:65:9a:5b:66: | 
|  | 31                     5e:c7:2c:b9:88:53:00:24:81:8d:f0:57:20:26:52: | 
|  | 32                     f4:e8:78:40:49:04:b2:c0:4b:8a:d3:f6:e1:81:d3: | 
|  | 33                     2a:de:64:11:b0:c2:f8:e2:d9:87:04:21:96:0c:0f: | 
|  | 34                     4d:4d:5e:03:85:bd:df:a2:20:2c:37:06:ae:c1:5b: | 
|  | 35                     41:a7:14:0c:ed:1d:b8:1f:94:40:0c:8e:71:c5:a5: | 
|  | 36                     fc:91:45:ae:67:c1:46:40:15:ed:1a:6a:e9:02:89: | 
|  | 37                     59:56:92:66:98:17:15:a1:35:2e:ee:f6:e3:3b:8e: | 
|  | 38                     b3:4f | 
|  | 39                 Exponent: 65537 (0x10001) | 
|  | 40         X509v3 extensions: | 
|  | 41             X509v3 Subject Key Identifier: | 
|  | 42                 3B:FE:2D:7C:1A:5F:A7:91:69:60:95:1A:EF:BC:B0:6D:DB:FE:19:BC | 
|  | 43             X509v3 Authority Key Identifier: | 
|  | 44                 keyid:2E:EC:8B:44:F0:5A:89:96:73:61:9B:4F:4E:2C:B0:53:52:9F:7B:1
     E | 
|  | 45 | 
|  | 46             Authority Information Access: | 
|  | 47                 CA Issuers - URI:http://url-for-aia/Intermediary.cer | 
|  | 48 | 
|  | 49             X509v3 CRL Distribution Points: | 
|  | 50 | 
|  | 51                 Full Name: | 
|  | 52                   URI:http://url-for-crl/Intermediary.crl | 
|  | 53 | 
|  | 54             X509v3 Key Usage: critical | 
|  | 55                 Digital Signature, Key Encipherment | 
|  | 56             X509v3 Extended Key Usage: | 
|  | 57                 TLS Web Server Authentication, TLS Web Client Authentication | 
|  | 58     Signature Algorithm: sha256WithRSAEncryption | 
|  | 59          5f:28:0d:4a:a7:79:e4:f8:ce:36:34:e8:a6:1b:22:e9:dd:0a: | 
|  | 60          33:ca:4a:ad:1c:df:63:26:89:24:50:73:be:38:d8:3e:1a:f4: | 
|  | 61          3d:0f:07:a9:b8:c9:ab:00:6f:e6:b2:21:6a:67:70:30:a2:d2: | 
|  | 62          e6:9b:da:8a:ea:f8:ce:3d:fe:b2:db:57:9e:b5:8f:01:39:a0: | 
|  | 63          80:41:19:c1:ba:f5:50:35:8d:77:ff:8c:59:1b:10:89:4a:e5: | 
|  | 64          50:9e:e4:38:04:b3:78:b2:25:0f:e5:69:37:d9:9f:49:a8:a3: | 
|  | 65          b0:1b:d9:a5:46:73:9a:9e:17:e2:b8:49:7f:a1:bf:fa:22:2b: | 
|  | 66          ff:28:dd:58:5c:51:dc:57:1e:78:c1:45:73:84:dc:1e:94:25: | 
|  | 67          7e:8a:56:e3:14:97:9f:f8:81:54:2f:67:4c:f7:77:60:50:23: | 
|  | 68          cc:62:c0:69:32:68:81:d1:c4:09:09:05:2e:69:b9:35:a0:10: | 
|  | 69          ff:3e:81:61:0d:0b:f5:05:3d:ca:14:96:b7:c6:a8:d1:eb:ed: | 
|  | 70          d7:96:f2:2f:5d:58:1a:fd:13:93:b5:78:95:fc:9a:b8:d7:e3: | 
|  | 71          ae:72:34:9e:d5:c3:8c:90:af:99:55:aa:37:6d:ee:bf:7f:66: | 
|  | 72          10:48:af:34:5a:0f:6e:d7:80:69:b0:a5:11:95:a2:e4:47:30: | 
|  | 73          02:f7:02:cb | 
|  | 74 -----BEGIN CERTIFICATE----- | 
|  | 75 MIIDjTCCAnWgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl | 
|  | 76 cm1lZGlhcnkwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjARMQ8wDQYD | 
|  | 77 VQQDDAZUYXJnZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDabFKA | 
|  | 78 YrR0y7dld3Z6hIzvQGFAnkjbKQ7/0D2hClMmJ1w0tmtQ+LjyXBNA2xj9jZjsf1yw | 
|  | 79 avb2Qs8D/KG5z1Wz0Eda4w4iu8AnDE7adnLGYaeBCDGAGSf8UamXK0R9JCDCr6ht | 
|  | 80 ViYM+AUK5duNSJOFdPWpg1D+392c8aABxN0dUhwkghsQuAg4eKv+2jy/pDbTZZpb | 
|  | 81 Zl7HLLmIUwAkgY3wVyAmUvToeEBJBLLAS4rT9uGB0yreZBGwwvji2YcEIZYMD01N | 
|  | 82 XgOFvd+iICw3Bq7BW0GnFAztHbgflEAMjnHFpfyRRa5nwUZAFe0aaukCiVlWkmaY | 
|  | 83 FxWhNS7u9uM7jrNPAgMBAAGjgekwgeYwHQYDVR0OBBYEFDv+LXwaX6eRaWCVGu+8 | 
|  | 84 sG3b/hm8MB8GA1UdIwQYMBaAFC7si0TwWomWc2GbT04ssFNSn3seMD8GCCsGAQUF | 
|  | 85 BwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0ludGVybWVk | 
|  | 86 aWFyeS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3ItY3JsL0lu | 
|  | 87 dGVybWVkaWFyeS5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUF | 
|  | 88 BwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAXygNSqd55PjONjTophsi | 
|  | 89 6d0KM8pKrRzfYyaJJFBzvjjYPhr0PQ8HqbjJqwBv5rIhamdwMKLS5pvaiur4zj3+ | 
|  | 90 sttXnrWPATmggEEZwbr1UDWNd/+MWRsQiUrlUJ7kOASzeLIlD+VpN9mfSaijsBvZ | 
|  | 91 pUZzmp4X4rhJf6G/+iIr/yjdWFxR3FceeMFFc4TcHpQlfopW4xSXn/iBVC9nTPd3 | 
|  | 92 YFAjzGLAaTJogdHECQkFLmm5NaAQ/z6BYQ0L9QU9yhSWt8ao0evt15byL11YGv0T | 
|  | 93 k7V4lfyauNfjrnI0ntXDjJCvmVWqN23uv39mEEivNFoPbteAabClEZWi5EcwAvcC | 
|  | 94 yw== | 
|  | 95 -----END CERTIFICATE----- | 
|  | 96 | 
|  | 97 Certificate: | 
|  | 98     Data: | 
|  | 99         Version: 3 (0x2) | 
|  | 100         Serial Number: 1 (0x1) | 
|  | 101     Signature Algorithm: sha256WithRSAEncryption | 
|  | 102         Issuer: CN=Intermediary | 
|  | 103         Validity | 
|  | 104             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 105             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 106         Subject: CN=Intermediary | 
|  | 107         Subject Public Key Info: | 
|  | 108             Public Key Algorithm: rsaEncryption | 
|  | 109                 Public-Key: (2048 bit) | 
|  | 110                 Modulus: | 
|  | 111                     00:b9:8f:42:56:6a:0d:21:9b:3d:61:79:3d:21:85: | 
|  | 112                     45:69:3f:00:9a:32:59:2f:01:70:be:ea:c1:af:8a: | 
|  | 113                     6c:21:59:1a:eb:a0:4e:1a:cc:e4:57:2b:3c:57:34: | 
|  | 114                     20:9e:6c:13:a2:60:39:6e:94:ee:3f:a3:32:25:13: | 
|  | 115                     16:dc:1c:6e:8d:a0:f2:29:3f:31:a3:ba:7c:e7:58: | 
|  | 116                     04:62:38:27:ae:51:b0:b8:d2:e3:a9:d2:4d:bf:0e: | 
|  | 117                     7b:bb:e7:70:bf:18:5c:70:cd:7f:5e:13:df:8a:e6: | 
|  | 118                     df:56:e9:ad:9e:79:b2:2f:cd:60:f7:d8:56:92:4d: | 
|  | 119                     a0:a8:61:65:0a:7b:99:af:53:b1:14:75:ef:7a:d6: | 
|  | 120                     23:30:a2:c0:05:d7:60:a7:59:50:78:37:9a:90:e2: | 
|  | 121                     a1:37:31:bf:3a:e0:26:b1:78:19:8c:36:ee:fb:4d: | 
|  | 122                     8b:e6:11:c9:cd:94:92:ab:a2:33:4f:b4:79:2c:26: | 
|  | 123                     be:11:57:c2:47:e1:05:d2:65:45:44:5b:da:7b:fe: | 
|  | 124                     89:23:eb:3a:0e:2f:27:ae:30:4a:b1:5c:a3:a4:f7: | 
|  | 125                     ec:5c:09:89:18:69:21:9e:8d:6b:18:49:7a:49:d2: | 
|  | 126                     b8:cd:3e:ac:fb:ba:52:13:8a:37:45:12:5e:26:47: | 
|  | 127                     1d:5e:9d:b7:92:ac:20:33:2c:79:ba:79:74:24:e5: | 
|  | 128                     80:bb | 
|  | 129                 Exponent: 65537 (0x10001) | 
|  | 130         X509v3 extensions: | 
|  | 131             X509v3 Subject Key Identifier: | 
|  | 132                 2E:EC:8B:44:F0:5A:89:96:73:61:9B:4F:4E:2C:B0:53:52:9F:7B:1E | 
|  | 133             X509v3 Authority Key Identifier: | 
|  | 134                 keyid:7A:49:1B:4B:85:12:41:CE:AF:BE:2E:18:2D:1D:3B:C5:F3:0A:A8:7
     B | 
|  | 135 | 
|  | 136             Authority Information Access: | 
|  | 137                 CA Issuers - URI:http://url-for-aia/Intermediary.cer | 
|  | 138 | 
|  | 139             X509v3 CRL Distribution Points: | 
|  | 140 | 
|  | 141                 Full Name: | 
|  | 142                   URI:http://url-for-crl/Intermediary.crl | 
|  | 143 | 
|  | 144             X509v3 Key Usage: critical | 
|  | 145                 Certificate Sign, CRL Sign | 
|  | 146             X509v3 Basic Constraints: critical | 
|  | 147                 CA:TRUE, pathlen:0 | 
|  | 148     Signature Algorithm: sha256WithRSAEncryption | 
|  | 149          2e:dc:27:2d:5f:0a:52:89:3c:4e:92:3d:1c:cc:29:47:48:4d: | 
|  | 150          a8:8f:34:a3:4c:40:cf:1c:76:d5:a1:5f:c1:3e:01:68:b1:eb: | 
|  | 151          d2:d6:00:57:6f:77:2c:1a:4c:d3:a4:d8:26:1e:2b:ca:66:11: | 
|  | 152          8c:64:78:d0:91:83:39:68:68:91:38:15:c4:36:41:3a:90:60: | 
|  | 153          a1:f8:85:7e:2a:bc:90:a4:1b:53:64:d5:24:58:85:e4:c9:98: | 
|  | 154          35:0b:cf:32:f0:e8:f6:87:ac:fa:7e:a1:53:94:a9:73:c1:66: | 
|  | 155          c0:b2:09:6d:22:74:84:05:69:99:64:d6:8f:ce:0c:66:67:be: | 
|  | 156          ac:18:16:e5:6a:34:87:fd:88:cb:a5:a1:4f:6e:33:b0:96:08: | 
|  | 157          02:65:75:26:f8:d5:e6:91:1c:2d:a0:f3:3b:f5:01:ca:42:64: | 
|  | 158          5f:41:90:30:77:74:26:36:3a:bd:95:80:c3:ec:80:9a:60:09: | 
|  | 159          b7:25:a7:5d:30:40:72:33:ee:19:75:8e:0d:93:d4:9c:1a:71: | 
|  | 160          b6:ff:34:dc:83:9a:7d:5e:4e:a4:aa:81:30:38:a3:a8:8b:e2: | 
|  | 161          85:ad:e7:a0:17:c6:0f:0c:f7:df:26:3d:83:42:8a:95:8a:45: | 
|  | 162          56:2f:fd:e7:97:cd:60:ad:96:ef:7b:b6:e4:65:b3:4c:0b:04: | 
|  | 163          43:e4:3a:c7 | 
|  | 164 -----BEGIN CERTIFICATE----- | 
|  | 165 MIIDiDCCAnCgAwIBAgIBATANBgkqhkiG9w0BAQsFADAXMRUwEwYDVQQDDAxJbnRl | 
|  | 166 cm1lZGlhcnkwHhcNMTUwMTAxMTIwMDAwWhcNMTYwMTAxMTIwMDAwWjAXMRUwEwYD | 
|  | 167 VQQDDAxJbnRlcm1lZGlhcnkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB | 
|  | 168 AQC5j0JWag0hmz1heT0hhUVpPwCaMlkvAXC+6sGvimwhWRrroE4azORXKzxXNCCe | 
|  | 169 bBOiYDlulO4/ozIlExbcHG6NoPIpPzGjunznWARiOCeuUbC40uOp0k2/Dnu753C/ | 
|  | 170 GFxwzX9eE9+K5t9W6a2eebIvzWD32FaSTaCoYWUKe5mvU7EUde961iMwosAF12Cn | 
|  | 171 WVB4N5qQ4qE3Mb864CaxeBmMNu77TYvmEcnNlJKrojNPtHksJr4RV8JH4QXSZUVE | 
|  | 172 W9p7/okj6zoOLyeuMEqxXKOk9+xcCYkYaSGejWsYSXpJ0rjNPqz7ulITijdFEl4m | 
|  | 173 Rx1enbeSrCAzLHm6eXQk5YC7AgMBAAGjgd4wgdswHQYDVR0OBBYEFC7si0TwWomW | 
|  | 174 c2GbT04ssFNSn3seMB8GA1UdIwQYMBaAFHpJG0uFEkHOr74uGC0dO8XzCqh7MD8G | 
|  | 175 CCsGAQUFBwEBBDMwMTAvBggrBgEFBQcwAoYjaHR0cDovL3VybC1mb3ItYWlhL0lu | 
|  | 176 dGVybWVkaWFyeS5jZXIwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL3VybC1mb3It | 
|  | 177 Y3JsL0ludGVybWVkaWFyeS5jcmwwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQI | 
|  | 178 MAYBAf8CAQAwDQYJKoZIhvcNAQELBQADggEBAC7cJy1fClKJPE6SPRzMKUdITaiP | 
|  | 179 NKNMQM8cdtWhX8E+AWix69LWAFdvdywaTNOk2CYeK8pmEYxkeNCRgzloaJE4FcQ2 | 
|  | 180 QTqQYKH4hX4qvJCkG1Nk1SRYheTJmDULzzLw6PaHrPp+oVOUqXPBZsCyCW0idIQF | 
|  | 181 aZlk1o/ODGZnvqwYFuVqNIf9iMuloU9uM7CWCAJldSb41eaRHC2g8zv1AcpCZF9B | 
|  | 182 kDB3dCY2Or2VgMPsgJpgCbclp10wQHIz7hl1jg2T1Jwacbb/NNyDmn1eTqSqgTA4 | 
|  | 183 o6iL4oWt56AXxg8M998mPYNCipWKRVYv/eeXzWCtlu97tuRls0wLBEPkOsc= | 
|  | 184 -----END CERTIFICATE----- | 
|  | 185 | 
|  | 186 Certificate: | 
|  | 187     Data: | 
|  | 188         Version: 3 (0x2) | 
|  | 189         Serial Number: 2 (0x2) | 
|  | 190     Signature Algorithm: sha256WithRSAEncryption | 
|  | 191         Issuer: CN=Root | 
|  | 192         Validity | 
|  | 193             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 194             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 195         Subject: CN=Intermediary | 
|  | 196         Subject Public Key Info: | 
|  | 197             Public Key Algorithm: rsaEncryption | 
|  | 198                 Public-Key: (2048 bit) | 
|  | 199                 Modulus: | 
|  | 200                     00:98:c5:55:48:f8:f5:69:8e:47:2c:68:85:0d:3d: | 
|  | 201                     7e:1d:3e:c1:4b:ee:5b:57:9e:0d:6b:69:e6:a6:a2: | 
|  | 202                     08:f5:d5:67:28:d9:72:ac:a7:bc:d7:f3:2d:5b:8d: | 
|  | 203                     60:0e:e9:72:a3:9c:a7:33:69:69:32:4c:83:93:af: | 
|  | 204                     37:e4:c9:7e:c5:69:f8:ec:21:6a:77:7b:33:7d:55: | 
|  | 205                     d2:aa:a0:8e:03:c9:60:1e:01:fc:fe:38:3a:c2:07: | 
|  | 206                     3b:e3:f5:65:6b:98:d3:09:f1:d0:df:e7:e8:08:57: | 
|  | 207                     d5:c1:9b:11:4d:f4:58:07:ec:13:6a:7d:46:92:95: | 
|  | 208                     80:2c:c8:c0:e7:21:8d:8e:48:df:f5:92:97:90:9d: | 
|  | 209                     03:8c:e1:2a:4f:48:ba:91:06:17:44:08:5d:ba:cf: | 
|  | 210                     d5:92:3a:32:8d:45:49:6a:5f:a7:eb:a0:07:0c:68: | 
|  | 211                     f5:84:6a:5f:06:e2:90:a3:af:57:b5:3d:1d:ae:00: | 
|  | 212                     1f:9a:39:7a:e7:b6:e9:13:12:ed:af:26:b1:06:09: | 
|  | 213                     bb:9e:e8:8a:e3:ee:a6:bc:d8:7f:a9:a6:bf:33:07: | 
|  | 214                     92:7b:11:e8:3a:dc:58:6a:d8:3f:7d:90:cf:a3:6f: | 
|  | 215                     05:1d:35:d4:9f:14:b1:9f:02:a9:39:af:20:c2:d3: | 
|  | 216                     8d:b7:8e:05:f6:46:40:7e:85:e0:53:8a:37:73:a9: | 
|  | 217                     a2:49 | 
|  | 218                 Exponent: 65537 (0x10001) | 
|  | 219         X509v3 extensions: | 
|  | 220             X509v3 Subject Key Identifier: | 
|  | 221                 7A:49:1B:4B:85:12:41:CE:AF:BE:2E:18:2D:1D:3B:C5:F3:0A:A8:7B | 
|  | 222             X509v3 Authority Key Identifier: | 
|  | 223                 keyid:6F:5A:FA:01:4A:FE:9C:0F:11:77:68:8A:B5:6A:68:B3:99:42:3B:7
     A | 
|  | 224 | 
|  | 225             Authority Information Access: | 
|  | 226                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 227 | 
|  | 228             X509v3 CRL Distribution Points: | 
|  | 229 | 
|  | 230                 Full Name: | 
|  | 231                   URI:http://url-for-crl/Root.crl | 
|  | 232 | 
|  | 233             X509v3 Key Usage: critical | 
|  | 234                 Certificate Sign, CRL Sign | 
|  | 235             X509v3 Basic Constraints: critical | 
|  | 236                 CA:TRUE, pathlen:0 | 
|  | 237     Signature Algorithm: sha256WithRSAEncryption | 
|  | 238          83:b0:8e:2f:51:0b:de:1f:e1:c7:b5:f4:f6:26:88:1b:43:39: | 
|  | 239          0b:62:07:f7:c6:d9:83:dd:82:7c:a8:18:df:27:f5:0f:62:c6: | 
|  | 240          6c:91:24:a8:ad:33:98:29:c0:1a:a8:01:bd:75:be:0d:13:d8: | 
|  | 241          21:0f:ff:2f:1f:6e:5e:29:52:b1:e1:a9:09:f6:d1:48:2d:d5: | 
|  | 242          50:a5:10:f1:c0:8d:cf:0b:83:c4:ee:62:80:cb:62:92:2b:27: | 
|  | 243          0e:11:b7:a1:24:28:30:28:b0:a7:bb:35:3f:f1:09:e0:da:7f: | 
|  | 244          69:ad:e5:7f:04:72:01:c8:8d:51:8c:a2:40:f5:a1:dc:83:6e: | 
|  | 245          50:02:16:34:cb:d2:11:86:35:2e:49:2b:3c:68:7d:c1:1a:e6: | 
|  | 246          fa:9e:7e:bd:07:1c:62:3c:92:34:a0:ed:fb:bd:c3:02:1e:45: | 
|  | 247          59:aa:87:9c:11:7e:f3:f1:ef:b8:84:b1:00:a0:38:8e:27:c0: | 
|  | 248          b5:35:25:23:d0:07:5e:75:ff:96:c5:91:e7:71:43:60:ff:1e: | 
|  | 249          5b:a3:04:c2:2e:4e:26:c5:ca:d4:b8:e6:aa:16:47:9f:05:cb: | 
|  | 250          f1:ae:8d:45:0f:f9:50:b0:6b:48:03:ff:84:59:2c:ac:4f:bf: | 
|  | 251          9d:e4:22:4c:4b:43:1c:10:a5:b5:8c:3a:ab:5d:94:78:1e:f3: | 
|  | 252          5f:09:7f:03 | 
|  | 253 -----BEGIN CERTIFICATE----- | 
|  | 254 MIIDcDCCAligAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 255 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowFzEVMBMGA1UEAwwMSW50 | 
|  | 256 ZXJtZWRpYXJ5MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmMVVSPj1 | 
|  | 257 aY5HLGiFDT1+HT7BS+5bV54Na2nmpqII9dVnKNlyrKe81/MtW41gDulyo5ynM2lp | 
|  | 258 MkyDk6835Ml+xWn47CFqd3szfVXSqqCOA8lgHgH8/jg6wgc74/Vla5jTCfHQ3+fo | 
|  | 259 CFfVwZsRTfRYB+wTan1GkpWALMjA5yGNjkjf9ZKXkJ0DjOEqT0i6kQYXRAhdus/V | 
|  | 260 kjoyjUVJal+n66AHDGj1hGpfBuKQo69XtT0drgAfmjl657bpExLtryaxBgm7nuiK | 
|  | 261 4+6mvNh/qaa/MweSexHoOtxYatg/fZDPo28FHTXUnxSxnwKpOa8gwtONt44F9kZA | 
|  | 262 foXgU4o3c6miSQIDAQABo4HOMIHLMB0GA1UdDgQWBBR6SRtLhRJBzq++LhgtHTvF | 
|  | 263 8wqoezAfBgNVHSMEGDAWgBRvWvoBSv6cDxF3aIq1amizmUI7ejA3BggrBgEFBQcB | 
|  | 264 AQQrMCkwJwYIKwYBBQUHMAKGG2h0dHA6Ly91cmwtZm9yLWFpYS9Sb290LmNlcjAs | 
|  | 265 BgNVHR8EJTAjMCGgH6AdhhtodHRwOi8vdXJsLWZvci1jcmwvUm9vdC5jcmwwDgYD | 
|  | 266 VR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwDQYJKoZIhvcNAQELBQAD | 
|  | 267 ggEBAIOwji9RC94f4ce19PYmiBtDOQtiB/fG2YPdgnyoGN8n9Q9ixmyRJKitM5gp | 
|  | 268 wBqoAb11vg0T2CEP/y8fbl4pUrHhqQn20Ugt1VClEPHAjc8Lg8TuYoDLYpIrJw4R | 
|  | 269 t6EkKDAosKe7NT/xCeDaf2mt5X8EcgHIjVGMokD1odyDblACFjTL0hGGNS5JKzxo | 
|  | 270 fcEa5vqefr0HHGI8kjSg7fu9wwIeRVmqh5wRfvPx77iEsQCgOI4nwLU1JSPQB151 | 
|  | 271 /5bFkedxQ2D/HlujBMIuTibFytS45qoWR58Fy/GujUUP+VCwa0gD/4RZLKxPv53k | 
|  | 272 IkxLQxwQpbWMOqtdlHge818JfwM= | 
|  | 273 -----END CERTIFICATE----- | 
|  | 274 | 
|  | 275 Certificate: | 
|  | 276     Data: | 
|  | 277         Version: 3 (0x2) | 
|  | 278         Serial Number: 1 (0x1) | 
|  | 279     Signature Algorithm: sha256WithRSAEncryption | 
|  | 280         Issuer: CN=Root | 
|  | 281         Validity | 
|  | 282             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 283             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 284         Subject: CN=Root | 
|  | 285         Subject Public Key Info: | 
|  | 286             Public Key Algorithm: rsaEncryption | 
|  | 287                 Public-Key: (2048 bit) | 
|  | 288                 Modulus: | 
|  | 289                     00:e3:80:0e:0e:47:e0:a4:2e:75:74:86:96:44:42: | 
|  | 290                     9e:c6:02:56:04:73:18:9b:ff:0c:fc:fc:bd:26:64: | 
|  | 291                     f4:15:55:f2:94:0c:92:e2:4d:26:df:27:ca:24:fc: | 
|  | 292                     a2:ff:a2:0e:a2:0d:95:e8:09:6b:de:24:4a:ae:43: | 
|  | 293                     49:c5:2b:c7:4d:10:63:1d:44:da:40:f4:77:d3:8b: | 
|  | 294                     c6:b8:e4:79:8e:db:57:51:22:4e:8b:01:b9:b9:1a: | 
|  | 295                     76:9f:1f:f9:cc:07:71:e8:a5:a6:ba:a1:bf:2d:32: | 
|  | 296                     a2:7c:75:35:18:0a:c5:6c:28:af:d8:05:e3:81:4f: | 
|  | 297                     0e:e8:63:7d:3c:5b:eb:c5:71:3f:38:b2:a8:32:f3: | 
|  | 298                     1d:83:13:ed:47:f9:34:06:4d:c4:e6:9c:16:02:4b: | 
|  | 299                     a9:43:0c:c4:ce:17:8d:6f:69:a8:41:c5:a6:3f:65: | 
|  | 300                     d8:bb:ce:2a:be:66:12:40:b0:9e:31:02:57:2b:d2: | 
|  | 301                     f3:0c:06:16:48:6c:76:a9:29:ac:68:b3:5f:51:81: | 
|  | 302                     c5:86:62:03:f7:35:33:68:a4:f9:b3:8b:49:2d:25: | 
|  | 303                     c8:e9:91:83:37:b2:7a:8e:6a:25:50:b8:54:c3:41: | 
|  | 304                     e5:bf:c1:7d:80:2f:07:e2:7c:b3:cb:e6:61:69:87: | 
|  | 305                     22:49:83:a2:ec:4f:d7:57:fe:ad:c3:f0:76:71:af: | 
|  | 306                     40:c5 | 
|  | 307                 Exponent: 65537 (0x10001) | 
|  | 308         X509v3 extensions: | 
|  | 309             X509v3 Subject Key Identifier: | 
|  | 310                 6F:5A:FA:01:4A:FE:9C:0F:11:77:68:8A:B5:6A:68:B3:99:42:3B:7A | 
|  | 311             X509v3 Authority Key Identifier: | 
|  | 312                 keyid:6F:5A:FA:01:4A:FE:9C:0F:11:77:68:8A:B5:6A:68:B3:99:42:3B:7
     A | 
|  | 313 | 
|  | 314             Authority Information Access: | 
|  | 315                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 316 | 
|  | 317             X509v3 CRL Distribution Points: | 
|  | 318 | 
|  | 319                 Full Name: | 
|  | 320                   URI:http://url-for-crl/Root.crl | 
|  | 321 | 
|  | 322             X509v3 Key Usage: critical | 
|  | 323                 Certificate Sign, CRL Sign | 
|  | 324             X509v3 Basic Constraints: critical | 
|  | 325                 CA:TRUE | 
|  | 326     Signature Algorithm: sha256WithRSAEncryption | 
|  | 327          6a:e2:ca:2f:f2:f1:77:ba:e0:70:7b:cc:e8:38:75:6c:07:a1: | 
|  | 328          49:be:d2:4e:0d:b3:f9:c0:ec:f0:a0:62:b8:b9:38:f3:4c:aa: | 
|  | 329          4e:ef:d4:54:db:7c:33:c0:28:fe:30:f0:16:f6:17:29:08:b6: | 
|  | 330          5c:ef:28:02:c1:95:48:53:99:77:22:69:a9:00:d3:c9:b5:20: | 
|  | 331          b6:41:c0:9a:9e:1d:63:37:54:ae:cc:d3:bb:69:bd:e6:76:9b: | 
|  | 332          72:a1:62:84:67:8d:0e:c3:45:66:78:fa:4f:33:de:c7:44:5b: | 
|  | 333          25:84:f6:6a:d0:c7:35:b5:75:af:88:f3:b6:b9:a9:bd:2d:86: | 
|  | 334          cc:65:15:a5:13:75:c0:28:97:0c:a4:f7:23:b1:e3:6a:13:65: | 
|  | 335          89:9d:a4:13:35:bf:f5:bf:86:8f:46:e9:01:c6:a3:35:f3:2f: | 
|  | 336          51:48:d7:a1:79:c5:41:70:4c:39:c6:13:34:25:c3:bd:10:c8: | 
|  | 337          d9:08:62:5c:e5:8d:cc:fb:b9:0a:1f:83:9f:d1:63:6b:42:e6: | 
|  | 338          02:fd:22:47:e0:43:5a:16:54:cf:8c:dc:c0:d3:51:c6:55:2b: | 
|  | 339          63:b7:71:87:1e:26:82:40:37:48:03:0c:e8:85:be:fc:4e:db: | 
|  | 340          a6:53:8b:52:13:d7:06:73:a2:72:c2:7d:04:c1:31:cc:bb:bc: | 
|  | 341          ee:b9:c3:7c | 
|  | 342 -----BEGIN TRUSTED_CERTIFICATE----- | 
|  | 343 MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 344 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v | 
|  | 345 dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOOADg5H4KQudXSGlkRC | 
|  | 346 nsYCVgRzGJv/DPz8vSZk9BVV8pQMkuJNJt8nyiT8ov+iDqINlegJa94kSq5DScUr | 
|  | 347 x00QYx1E2kD0d9OLxrjkeY7bV1EiTosBubkadp8f+cwHceilprqhvy0yonx1NRgK | 
|  | 348 xWwor9gF44FPDuhjfTxb68VxPziyqDLzHYMT7Uf5NAZNxOacFgJLqUMMxM4XjW9p | 
|  | 349 qEHFpj9l2LvOKr5mEkCwnjECVyvS8wwGFkhsdqkprGizX1GBxYZiA/c1M2ik+bOL | 
|  | 350 SS0lyOmRgzeyeo5qJVC4VMNB5b/BfYAvB+J8s8vmYWmHIkmDouxP11f+rcPwdnGv | 
|  | 351 QMUCAwEAAaOByzCByDAdBgNVHQ4EFgQUb1r6AUr+nA8Rd2iKtWpos5lCO3owHwYD | 
|  | 352 VR0jBBgwFoAUb1r6AUr+nA8Rd2iKtWpos5lCO3owNwYIKwYBBQUHAQEEKzApMCcG | 
|  | 353 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw | 
|  | 354 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE | 
|  | 355 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBq4sov8vF3 | 
|  | 356 uuBwe8zoOHVsB6FJvtJODbP5wOzwoGK4uTjzTKpO79RU23wzwCj+MPAW9hcpCLZc | 
|  | 357 7ygCwZVIU5l3ImmpANPJtSC2QcCanh1jN1SuzNO7ab3mdptyoWKEZ40Ow0VmePpP | 
|  | 358 M97HRFslhPZq0Mc1tXWviPO2uam9LYbMZRWlE3XAKJcMpPcjseNqE2WJnaQTNb/1 | 
|  | 359 v4aPRukBxqM18y9RSNehecVBcEw5xhM0JcO9EMjZCGJc5Y3M+7kKH4Of0WNrQuYC | 
|  | 360 /SJH4ENaFlTPjNzA01HGVStjt3GHHiaCQDdIAwzohb78TtumU4tSE9cGc6Jywn0E | 
|  | 361 wTHMu7zuucN8 | 
|  | 362 -----END TRUSTED_CERTIFICATE----- | 
|  | 363 | 
|  | 364 -----BEGIN TIME----- | 
|  | 365 MTYwMzAyMTIwMDAwWg== | 
|  | 366 -----END TIME----- | 
|  | 367 | 
|  | 368 -----BEGIN VERIFY_RESULT----- | 
|  | 369 U1VDQ0VTUw== | 
|  | 370 -----END VERIFY_RESULT----- | 
| OLD | NEW | 
|---|