| OLD | NEW | 
|---|
| (Empty) |  | 
|  | 1 [Created by: generate-violates-basic-constraints-pathlen-0.py] | 
|  | 2 | 
|  | 3 Certificate chain with 2 intermediaries. The first | 
|  | 4 intermediary has a basic constraints path length of 0, so it is a violation for | 
|  | 5 it to have a subordinate intermediary. | 
|  | 6 | 
|  | 7 Certificate: | 
|  | 8     Data: | 
|  | 9         Version: 3 (0x2) | 
|  | 10         Serial Number: 1 (0x1) | 
|  | 11     Signature Algorithm: sha256WithRSAEncryption | 
|  | 12         Issuer: CN=Intermediary2 | 
|  | 13         Validity | 
|  | 14             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 15             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 16         Subject: CN=Target | 
|  | 17         Subject Public Key Info: | 
|  | 18             Public Key Algorithm: rsaEncryption | 
|  | 19                 Public-Key: (2048 bit) | 
|  | 20                 Modulus: | 
|  | 21                     00:aa:6b:96:7b:88:2a:26:42:33:eb:e5:1d:a6:22: | 
|  | 22                     fe:45:81:72:cc:a2:59:21:39:1f:08:f2:60:2d:9b: | 
|  | 23                     99:d6:a2:96:49:ce:4d:22:a3:57:6f:a6:54:15:11: | 
|  | 24                     55:48:33:69:c0:cf:82:60:07:70:d2:06:70:53:f9: | 
|  | 25                     e3:88:c8:25:c2:83:46:9b:c8:08:85:22:5b:16:b6: | 
|  | 26                     11:0d:e4:8d:37:5a:89:06:07:8c:d7:5e:b9:82:11: | 
|  | 27                     a8:34:3f:3b:b5:26:e2:93:1a:c9:f7:ee:52:eb:ba: | 
|  | 28                     01:6c:11:bb:5a:d9:26:e4:da:33:07:5f:6f:8e:2a: | 
|  | 29                     f1:e6:65:d8:3a:1f:ba:a7:45:9e:c5:e2:2b:c9:b1: | 
|  | 30                     0b:82:66:f8:9e:63:ca:55:b2:9b:69:a5:ed:b8:c6: | 
|  | 31                     00:dc:3d:9e:55:c2:06:d2:34:51:b1:c6:26:4c:8e: | 
|  | 32                     ee:1d:0d:d0:4b:3a:7a:8c:f9:b3:98:1e:98:4b:f8: | 
|  | 33                     e2:29:91:b8:6f:72:d2:f0:4a:fd:90:6c:9f:d2:d9: | 
|  | 34                     41:c9:6e:c7:65:e7:77:1f:18:5c:a4:22:34:cd:33: | 
|  | 35                     8a:57:fb:03:47:07:98:3e:86:2d:04:7e:5c:0e:40: | 
|  | 36                     54:45:12:e4:02:fc:80:1c:e0:50:78:12:5d:80:54: | 
|  | 37                     ac:19:ea:b3:df:39:d7:57:f0:75:17:6d:e0:db:a6: | 
|  | 38                     83:2d | 
|  | 39                 Exponent: 65537 (0x10001) | 
|  | 40         X509v3 extensions: | 
|  | 41             X509v3 Subject Key Identifier: | 
|  | 42                 09:1C:36:4F:EC:22:4C:B8:27:CB:BB:BF:61:EA:E9:B2:38:1B:33:39 | 
|  | 43             X509v3 Authority Key Identifier: | 
|  | 44                 keyid:5F:A2:FB:66:0B:2E:39:14:C8:43:2F:9A:DD:BF:CC:56:BA:FF:39:B
     8 | 
|  | 45 | 
|  | 46             Authority Information Access: | 
|  | 47                 CA Issuers - URI:http://url-for-aia/Intermediary2.cer | 
|  | 48 | 
|  | 49             X509v3 CRL Distribution Points: | 
|  | 50 | 
|  | 51                 Full Name: | 
|  | 52                   URI:http://url-for-crl/Intermediary2.crl | 
|  | 53 | 
|  | 54             X509v3 Key Usage: critical | 
|  | 55                 Digital Signature, Key Encipherment | 
|  | 56             X509v3 Extended Key Usage: | 
|  | 57                 TLS Web Server Authentication, TLS Web Client Authentication | 
|  | 58     Signature Algorithm: sha256WithRSAEncryption | 
|  | 59          18:28:02:69:68:9c:b0:68:8b:55:7d:bb:2c:6c:31:22:cd:14: | 
|  | 60          36:6f:e8:2f:38:a3:63:3c:4f:40:1d:9a:85:33:96:4c:45:2b: | 
|  | 61          6d:c3:cf:1b:c8:2f:07:14:24:f4:89:b5:c2:d7:88:fd:fa:8d: | 
|  | 62          43:92:96:d5:f7:54:c8:06:1a:c5:09:b0:1d:15:35:a7:37:a4: | 
|  | 63          3a:a8:26:fb:af:fb:dd:49:23:d1:60:0b:fc:54:98:c3:20:f2: | 
|  | 64          61:8a:6e:c1:3c:d4:bc:aa:f8:d8:8c:ba:26:01:15:53:9a:cf: | 
|  | 65          ad:e9:65:1c:6f:dd:e6:4e:db:2c:d3:05:1a:68:74:c6:cd:c2: | 
|  | 66          fe:7f:4c:ad:b8:a5:53:b7:8d:6e:61:24:24:f5:7e:2c:fe:2f: | 
|  | 67          16:83:b6:f7:43:b8:49:4f:c8:1d:4c:a9:2a:00:9b:45:d3:0f: | 
|  | 68          fb:9f:dd:37:44:f8:86:f9:09:45:b7:13:c4:ac:f2:61:26:09: | 
|  | 69          94:37:37:80:6c:d9:7e:1a:f5:02:2a:35:46:57:e1:0b:60:65: | 
|  | 70          f1:4d:97:83:e5:a2:f8:8b:79:13:c5:56:fe:01:71:bc:9d:0a: | 
|  | 71          1c:6a:b5:8c:89:3a:12:93:b8:41:48:cc:e2:bd:7a:4c:0c:c6: | 
|  | 72          64:35:43:8a:18:5e:a8:b1:27:10:6e:0f:27:f1:7c:07:af:06: | 
|  | 73          c1:e5:d9:b5 | 
|  | 74 -----BEGIN CERTIFICATE----- | 
|  | 75 MIIDkDCCAnigAwIBAgIBATANBgkqhkiG9w0BAQsFADAYMRYwFAYDVQQDDA1JbnRl | 
|  | 76 cm1lZGlhcnkyMB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowETEPMA0G | 
|  | 77 A1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqmuW | 
|  | 78 e4gqJkIz6+UdpiL+RYFyzKJZITkfCPJgLZuZ1qKWSc5NIqNXb6ZUFRFVSDNpwM+C | 
|  | 79 YAdw0gZwU/njiMglwoNGm8gIhSJbFrYRDeSNN1qJBgeM1165ghGoND87tSbikxrJ | 
|  | 80 9+5S67oBbBG7Wtkm5NozB19vjirx5mXYOh+6p0WexeIrybELgmb4nmPKVbKbaaXt | 
|  | 81 uMYA3D2eVcIG0jRRscYmTI7uHQ3QSzp6jPmzmB6YS/jiKZG4b3LS8Er9kGyf0tlB | 
|  | 82 yW7HZed3HxhcpCI0zTOKV/sDRweYPoYtBH5cDkBURRLkAvyAHOBQeBJdgFSsGeqz | 
|  | 83 3znXV/B1F23g26aDLQIDAQABo4HrMIHoMB0GA1UdDgQWBBQJHDZP7CJMuCfLu79h | 
|  | 84 6umyOBszOTAfBgNVHSMEGDAWgBRfovtmCy45FMhDL5rdv8xWuv85uDBABggrBgEF | 
|  | 85 BQcBAQQ0MDIwMAYIKwYBBQUHMAKGJGh0dHA6Ly91cmwtZm9yLWFpYS9JbnRlcm1l | 
|  | 86 ZGlhcnkyLmNlcjA1BgNVHR8ELjAsMCqgKKAmhiRodHRwOi8vdXJsLWZvci1jcmwv | 
|  | 87 SW50ZXJtZWRpYXJ5Mi5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsG | 
|  | 88 AQUFBwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAGCgCaWicsGiLVX27 | 
|  | 89 LGwxIs0UNm/oLzijYzxPQB2ahTOWTEUrbcPPG8gvBxQk9Im1wteI/fqNQ5KW1fdU | 
|  | 90 yAYaxQmwHRU1pzekOqgm+6/73Ukj0WAL/FSYwyDyYYpuwTzUvKr42Iy6JgEVU5rP | 
|  | 91 rellHG/d5k7bLNMFGmh0xs3C/n9MrbilU7eNbmEkJPV+LP4vFoO290O4SU/IHUyp | 
|  | 92 KgCbRdMP+5/dN0T4hvkJRbcTxKzyYSYJlDc3gGzZfhr1Aio1RlfhC2Bl8U2Xg+Wi | 
|  | 93 +It5E8VW/gFxvJ0KHGq1jIk6EpO4QUjM4r16TAzGZDVDihheqLEnEG4PJ/F8B68G | 
|  | 94 weXZtQ== | 
|  | 95 -----END CERTIFICATE----- | 
|  | 96 | 
|  | 97 Certificate: | 
|  | 98     Data: | 
|  | 99         Version: 3 (0x2) | 
|  | 100         Serial Number: 1 (0x1) | 
|  | 101     Signature Algorithm: sha256WithRSAEncryption | 
|  | 102         Issuer: CN=Intermediary1 | 
|  | 103         Validity | 
|  | 104             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 105             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 106         Subject: CN=Intermediary2 | 
|  | 107         Subject Public Key Info: | 
|  | 108             Public Key Algorithm: rsaEncryption | 
|  | 109                 Public-Key: (2048 bit) | 
|  | 110                 Modulus: | 
|  | 111                     00:c9:a3:fd:44:af:b5:fa:d3:9b:f2:fd:e4:9a:a6: | 
|  | 112                     39:0d:f1:3c:74:f8:c5:82:1a:32:5d:ab:a0:23:1f: | 
|  | 113                     ec:8a:5c:90:db:95:8f:64:74:ca:dd:81:b8:85:e5: | 
|  | 114                     cf:2e:44:55:5a:21:93:15:4c:f3:77:7b:bb:b9:56: | 
|  | 115                     f1:19:f9:e7:b0:76:37:96:19:88:90:54:9b:5a:9c: | 
|  | 116                     cd:fc:a2:ec:d7:e8:8b:3e:00:2e:ef:17:0f:f1:bc: | 
|  | 117                     1b:48:05:76:5d:ef:f5:f1:92:62:b3:79:88:07:5b: | 
|  | 118                     79:b5:99:b5:4e:7d:d2:13:4b:fc:31:b0:37:e6:08: | 
|  | 119                     37:cb:e2:46:b3:e2:dc:3d:8f:7e:26:e3:d7:b0:52: | 
|  | 120                     0e:1f:da:08:3f:43:17:e9:6b:d4:ae:6f:54:04:75: | 
|  | 121                     68:fb:c3:c8:6b:96:f6:35:ab:6c:c7:ab:ea:42:e0: | 
|  | 122                     5c:8c:b3:88:42:52:de:83:40:ab:57:76:55:92:ae: | 
|  | 123                     11:0c:dd:9a:32:09:c1:92:dd:05:6c:1b:19:51:1a: | 
|  | 124                     97:24:9d:37:fc:37:cc:e2:e8:b4:cd:eb:e6:29:56: | 
|  | 125                     69:b5:f8:84:b7:1d:3b:db:40:b8:f2:3c:9b:ad:2c: | 
|  | 126                     9a:a8:12:d3:3d:2c:1a:6e:b4:11:18:b5:39:c9:bc: | 
|  | 127                     80:9f:d2:7b:f2:69:1b:e4:21:ea:72:9e:eb:00:f7: | 
|  | 128                     87:87 | 
|  | 129                 Exponent: 65537 (0x10001) | 
|  | 130         X509v3 extensions: | 
|  | 131             X509v3 Subject Key Identifier: | 
|  | 132                 5F:A2:FB:66:0B:2E:39:14:C8:43:2F:9A:DD:BF:CC:56:BA:FF:39:B8 | 
|  | 133             X509v3 Authority Key Identifier: | 
|  | 134                 keyid:77:76:48:B2:B6:41:E7:F8:16:FB:DF:3E:6D:99:F4:9F:ED:FE:6F:7
     5 | 
|  | 135 | 
|  | 136             Authority Information Access: | 
|  | 137                 CA Issuers - URI:http://url-for-aia/Intermediary1.cer | 
|  | 138 | 
|  | 139             X509v3 CRL Distribution Points: | 
|  | 140 | 
|  | 141                 Full Name: | 
|  | 142                   URI:http://url-for-crl/Intermediary1.crl | 
|  | 143 | 
|  | 144             X509v3 Key Usage: critical | 
|  | 145                 Certificate Sign, CRL Sign | 
|  | 146             X509v3 Basic Constraints: critical | 
|  | 147                 CA:TRUE, pathlen:0 | 
|  | 148     Signature Algorithm: sha256WithRSAEncryption | 
|  | 149          64:29:65:04:5f:b1:30:26:83:84:67:8f:51:8c:d2:0f:6c:0c: | 
|  | 150          ab:50:99:c3:f0:e8:f0:88:f8:2e:c9:85:4f:43:d1:47:cc:43: | 
|  | 151          00:53:57:e5:dc:ae:53:fb:23:0d:fc:82:8c:cc:bf:72:ee:63: | 
|  | 152          3d:26:cd:53:19:4f:e6:c2:51:0f:ce:85:25:62:9d:85:80:f1: | 
|  | 153          3e:89:3a:3c:76:fd:bf:2a:7c:2e:d7:df:38:80:26:7c:9a:79: | 
|  | 154          e8:de:b7:1e:4a:4d:1a:5b:1e:34:8a:ae:af:0b:d6:6a:13:f2: | 
|  | 155          ca:dc:03:de:53:e7:54:02:96:55:c5:35:e8:33:60:5d:45:cb: | 
|  | 156          59:d3:a8:8b:72:92:e5:12:b3:23:b6:7a:0d:6e:f7:f7:fd:46: | 
|  | 157          dc:55:94:e5:40:cb:9c:b7:e1:95:54:7a:0a:7b:7e:f3:09:26: | 
|  | 158          8d:10:09:f2:e5:7f:a1:76:c9:c6:6d:d7:9d:24:af:a8:29:d0: | 
|  | 159          69:6f:0a:17:ec:5c:31:be:ff:e7:03:a5:0a:bb:5a:08:ff:d7: | 
|  | 160          d8:b2:ce:15:c9:71:a2:c9:ad:6d:42:25:37:22:70:58:60:b3: | 
|  | 161          e5:e4:72:c5:14:75:be:e7:9d:75:a5:4c:cf:6c:a5:29:39:11: | 
|  | 162          47:57:d9:04:9c:7e:27:84:ec:fa:a5:ce:fa:37:2b:79:35:d0: | 
|  | 163          88:04:6a:da | 
|  | 164 -----BEGIN CERTIFICATE----- | 
|  | 165 MIIDjDCCAnSgAwIBAgIBATANBgkqhkiG9w0BAQsFADAYMRYwFAYDVQQDDA1JbnRl | 
|  | 166 cm1lZGlhcnkxMB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowGDEWMBQG | 
|  | 167 A1UEAwwNSW50ZXJtZWRpYXJ5MjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC | 
|  | 168 ggEBAMmj/USvtfrTm/L95JqmOQ3xPHT4xYIaMl2roCMf7IpckNuVj2R0yt2BuIXl | 
|  | 169 zy5EVVohkxVM83d7u7lW8Rn557B2N5YZiJBUm1qczfyi7Nfoiz4ALu8XD/G8G0gF | 
|  | 170 dl3v9fGSYrN5iAdbebWZtU590hNL/DGwN+YIN8viRrPi3D2Pfibj17BSDh/aCD9D | 
|  | 171 F+lr1K5vVAR1aPvDyGuW9jWrbMer6kLgXIyziEJS3oNAq1d2VZKuEQzdmjIJwZLd | 
|  | 172 BWwbGVEalySdN/w3zOLotM3r5ilWabX4hLcdO9tAuPI8m60smqgS0z0sGm60ERi1 | 
|  | 173 Ocm8gJ/Se/JpG+Qh6nKe6wD3h4cCAwEAAaOB4DCB3TAdBgNVHQ4EFgQUX6L7Zgsu | 
|  | 174 ORTIQy+a3b/MVrr/ObgwHwYDVR0jBBgwFoAUd3ZIsrZB5/gW+98+bZn0n+3+b3Uw | 
|  | 175 QAYIKwYBBQUHAQEENDAyMDAGCCsGAQUFBzAChiRodHRwOi8vdXJsLWZvci1haWEv | 
|  | 176 SW50ZXJtZWRpYXJ5MS5jZXIwNQYDVR0fBC4wLDAqoCigJoYkaHR0cDovL3VybC1m | 
|  | 177 b3ItY3JsL0ludGVybWVkaWFyeTEuY3JsMA4GA1UdDwEB/wQEAwIBBjASBgNVHRMB | 
|  | 178 Af8ECDAGAQH/AgEAMA0GCSqGSIb3DQEBCwUAA4IBAQBkKWUEX7EwJoOEZ49RjNIP | 
|  | 179 bAyrUJnD8OjwiPguyYVPQ9FHzEMAU1fl3K5T+yMN/IKMzL9y7mM9Js1TGU/mwlEP | 
|  | 180 zoUlYp2FgPE+iTo8dv2/Knwu1984gCZ8mnno3rceSk0aWx40iq6vC9ZqE/LK3APe | 
|  | 181 U+dUApZVxTXoM2BdRctZ06iLcpLlErMjtnoNbvf3/UbcVZTlQMuct+GVVHoKe37z | 
|  | 182 CSaNEAny5X+hdsnGbdedJK+oKdBpbwoX7Fwxvv/nA6UKu1oI/9fYss4VyXGiya1t | 
|  | 183 QiU3InBYYLPl5HLFFHW+5511pUzPbKUpORFHV9kEnH4nhOz6pc76Nyt5NdCIBGra | 
|  | 184 -----END CERTIFICATE----- | 
|  | 185 | 
|  | 186 Certificate: | 
|  | 187     Data: | 
|  | 188         Version: 3 (0x2) | 
|  | 189         Serial Number: 2 (0x2) | 
|  | 190     Signature Algorithm: sha256WithRSAEncryption | 
|  | 191         Issuer: CN=Root | 
|  | 192         Validity | 
|  | 193             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 194             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 195         Subject: CN=Intermediary1 | 
|  | 196         Subject Public Key Info: | 
|  | 197             Public Key Algorithm: rsaEncryption | 
|  | 198                 Public-Key: (2048 bit) | 
|  | 199                 Modulus: | 
|  | 200                     00:b8:05:65:94:1f:e3:bc:28:11:c3:81:56:4b:02: | 
|  | 201                     ce:05:a1:c1:bd:68:dd:8f:c0:d0:69:17:98:60:1f: | 
|  | 202                     00:76:80:ae:a6:0b:d5:40:d3:c7:5d:8c:20:29:fe: | 
|  | 203                     a4:88:ae:ea:2c:e4:fa:1f:a3:48:cf:6a:17:8d:3e: | 
|  | 204                     d8:66:eb:39:fd:03:62:91:18:3d:12:25:1a:c3:4d: | 
|  | 205                     7b:4a:da:0a:bc:81:58:55:90:7f:39:41:0f:f4:2f: | 
|  | 206                     1c:32:40:b5:e4:b0:83:07:de:18:8e:0a:44:64:b3: | 
|  | 207                     64:43:19:a8:0b:79:89:fa:04:15:02:18:3e:42:72: | 
|  | 208                     f5:6c:fd:7c:43:20:20:6f:09:dd:75:c3:b3:41:cb: | 
|  | 209                     ea:d9:0f:0b:3a:3e:08:bd:a8:2e:55:f6:4b:01:35: | 
|  | 210                     68:78:9d:2b:dc:1b:be:a6:02:db:b9:1d:18:7b:29: | 
|  | 211                     02:e6:b7:27:3d:54:e3:49:b1:bb:58:49:ce:88:75: | 
|  | 212                     8d:54:22:41:0f:54:53:e4:7f:62:14:cb:c5:ba:61: | 
|  | 213                     02:73:05:51:8d:c0:ce:b5:11:51:88:c0:bd:05:ab: | 
|  | 214                     fa:23:d3:da:31:4e:06:82:72:b3:21:6b:46:d9:da: | 
|  | 215                     95:c1:82:8b:09:c9:20:51:51:81:27:19:1d:fb:d6: | 
|  | 216                     b8:21:71:37:9b:9e:66:2a:24:41:3a:cb:06:4c:7c: | 
|  | 217                     64:f9 | 
|  | 218                 Exponent: 65537 (0x10001) | 
|  | 219         X509v3 extensions: | 
|  | 220             X509v3 Subject Key Identifier: | 
|  | 221                 77:76:48:B2:B6:41:E7:F8:16:FB:DF:3E:6D:99:F4:9F:ED:FE:6F:75 | 
|  | 222             X509v3 Authority Key Identifier: | 
|  | 223                 keyid:F7:DF:89:AE:08:91:2A:16:2B:20:C1:5A:BA:34:2C:13:19:C1:C9:F
     9 | 
|  | 224 | 
|  | 225             Authority Information Access: | 
|  | 226                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 227 | 
|  | 228             X509v3 CRL Distribution Points: | 
|  | 229 | 
|  | 230                 Full Name: | 
|  | 231                   URI:http://url-for-crl/Root.crl | 
|  | 232 | 
|  | 233             X509v3 Key Usage: critical | 
|  | 234                 Certificate Sign, CRL Sign | 
|  | 235             X509v3 Basic Constraints: critical | 
|  | 236                 CA:TRUE, pathlen:0 | 
|  | 237     Signature Algorithm: sha256WithRSAEncryption | 
|  | 238          66:f8:8c:ea:42:57:10:51:25:2e:cb:ae:48:67:75:25:1a:5a: | 
|  | 239          d3:80:a6:02:9f:e8:40:f2:ac:5b:38:7f:98:09:46:ca:49:7e: | 
|  | 240          48:d5:67:8b:c4:2a:f8:fa:f0:31:fe:48:59:7e:18:16:a5:a7: | 
|  | 241          ea:56:fe:6b:e6:16:4e:f4:90:f6:89:ae:ab:e5:1c:10:32:cf: | 
|  | 242          58:f6:96:fc:78:98:6a:7e:6c:97:e0:e6:27:9c:ea:94:1c:f9: | 
|  | 243          48:60:fc:87:53:c9:9c:1c:f7:a1:6f:8f:c5:3b:aa:8c:c0:31: | 
|  | 244          94:eb:8d:db:7c:86:e5:18:1e:da:09:8e:30:70:d2:b7:1f:95: | 
|  | 245          95:9b:f4:07:02:e4:f4:66:0c:29:a1:ea:03:1d:fe:d0:5b:3b: | 
|  | 246          f9:6f:91:5d:ef:76:9c:f3:92:4e:58:4c:eb:8f:7c:01:c6:1d: | 
|  | 247          97:02:2e:ac:3d:91:e8:51:a8:3e:e1:82:02:d5:e8:6e:42:31: | 
|  | 248          e0:28:88:dd:62:50:a3:ab:1e:75:94:80:21:7f:a3:22:37:72: | 
|  | 249          81:4f:f1:68:cc:a7:b3:40:e8:98:19:97:fc:8c:cf:3e:43:bb: | 
|  | 250          17:ff:c7:35:aa:34:5e:d9:de:53:d8:80:8b:2e:2b:d5:8c:8c: | 
|  | 251          2e:05:b1:39:4f:d3:9c:cd:a4:a4:7c:f6:7d:5b:8e:0f:09:72: | 
|  | 252          f5:0c:b5:5c | 
|  | 253 -----BEGIN CERTIFICATE----- | 
|  | 254 MIIDcTCCAlmgAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 255 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowGDEWMBQGA1UEAwwNSW50 | 
|  | 256 ZXJtZWRpYXJ5MTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALgFZZQf | 
|  | 257 47woEcOBVksCzgWhwb1o3Y/A0GkXmGAfAHaArqYL1UDTx12MICn+pIiu6izk+h+j | 
|  | 258 SM9qF40+2GbrOf0DYpEYPRIlGsNNe0raCryBWFWQfzlBD/QvHDJAteSwgwfeGI4K | 
|  | 259 RGSzZEMZqAt5ifoEFQIYPkJy9Wz9fEMgIG8J3XXDs0HL6tkPCzo+CL2oLlX2SwE1 | 
|  | 260 aHidK9wbvqYC27kdGHspAua3Jz1U40mxu1hJzoh1jVQiQQ9UU+R/YhTLxbphAnMF | 
|  | 261 UY3AzrURUYjAvQWr+iPT2jFOBoJysyFrRtnalcGCiwnJIFFRgScZHfvWuCFxN5ue | 
|  | 262 ZiokQTrLBkx8ZPkCAwEAAaOBzjCByzAdBgNVHQ4EFgQUd3ZIsrZB5/gW+98+bZn0 | 
|  | 263 n+3+b3UwHwYDVR0jBBgwFoAU99+JrgiRKhYrIMFaujQsExnByfkwNwYIKwYBBQUH | 
|  | 264 AQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIw | 
|  | 265 LAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4G | 
|  | 266 A1UdDwEB/wQEAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEAMA0GCSqGSIb3DQEBCwUA | 
|  | 267 A4IBAQBm+IzqQlcQUSUuy65IZ3UlGlrTgKYCn+hA8qxbOH+YCUbKSX5I1WeLxCr4 | 
|  | 268 +vAx/khZfhgWpafqVv5r5hZO9JD2ia6r5RwQMs9Y9pb8eJhqfmyX4OYnnOqUHPlI | 
|  | 269 YPyHU8mcHPehb4/FO6qMwDGU643bfIblGB7aCY4wcNK3H5WVm/QHAuT0ZgwpoeoD | 
|  | 270 Hf7QWzv5b5Fd73ac85JOWEzrj3wBxh2XAi6sPZHoUag+4YIC1ehuQjHgKIjdYlCj | 
|  | 271 qx51lIAhf6MiN3KBT/FozKezQOiYGZf8jM8+Q7sX/8c1qjRe2d5T2ICLLivVjIwu | 
|  | 272 BbE5T9OczaSkfPZ9W44PCXL1DLVc | 
|  | 273 -----END CERTIFICATE----- | 
|  | 274 | 
|  | 275 Certificate: | 
|  | 276     Data: | 
|  | 277         Version: 3 (0x2) | 
|  | 278         Serial Number: 1 (0x1) | 
|  | 279     Signature Algorithm: sha256WithRSAEncryption | 
|  | 280         Issuer: CN=Root | 
|  | 281         Validity | 
|  | 282             Not Before: Jan  1 12:00:00 2015 GMT | 
|  | 283             Not After : Jan  1 12:00:00 2016 GMT | 
|  | 284         Subject: CN=Root | 
|  | 285         Subject Public Key Info: | 
|  | 286             Public Key Algorithm: rsaEncryption | 
|  | 287                 Public-Key: (2048 bit) | 
|  | 288                 Modulus: | 
|  | 289                     00:db:af:d1:cd:67:f8:54:6c:a4:f3:13:cd:6f:d6: | 
|  | 290                     9a:eb:b1:7b:b5:10:6a:40:85:f3:04:5c:54:77:f5: | 
|  | 291                     bc:1a:6b:96:90:c4:10:0c:34:74:2a:c4:14:27:5e: | 
|  | 292                     86:3a:5d:0c:8c:68:1b:41:53:0e:18:ad:bf:fe:33: | 
|  | 293                     44:a5:4a:b2:0d:54:6f:dd:ec:1a:99:5c:ec:43:58: | 
|  | 294                     60:20:fa:51:78:d6:57:1e:33:f7:8b:3f:27:0f:01: | 
|  | 295                     f8:60:46:6a:67:b1:12:b4:75:1c:26:26:7e:16:62: | 
|  | 296                     8c:5e:18:7d:98:8f:b0:92:2a:73:40:6e:44:da:a1: | 
|  | 297                     c8:95:ea:7d:5e:c1:37:40:30:0d:fe:9d:4b:0a:38: | 
|  | 298                     05:8a:44:47:4e:84:42:db:d0:63:87:9f:3f:7a:4b: | 
|  | 299                     a1:5c:2e:95:9f:5e:e5:4f:6a:55:1e:ca:05:c3:a9: | 
|  | 300                     ee:4e:2a:c1:f5:40:e6:9c:2e:e0:25:05:cc:1d:64: | 
|  | 301                     0d:e0:45:72:65:0d:31:49:7e:2c:ef:f3:26:39:ae: | 
|  | 302                     38:8e:4d:07:26:40:5a:6b:bb:6a:fb:be:d5:a0:35: | 
|  | 303                     9f:c0:b5:31:1a:20:28:84:a8:db:66:75:ba:f1:a1: | 
|  | 304                     b0:93:ff:97:da:6b:52:ce:37:b4:41:78:35:39:2d: | 
|  | 305                     e4:0c:c6:ef:1e:70:e7:df:c7:c4:0d:b2:20:98:5f: | 
|  | 306                     4c:25 | 
|  | 307                 Exponent: 65537 (0x10001) | 
|  | 308         X509v3 extensions: | 
|  | 309             X509v3 Subject Key Identifier: | 
|  | 310                 F7:DF:89:AE:08:91:2A:16:2B:20:C1:5A:BA:34:2C:13:19:C1:C9:F9 | 
|  | 311             X509v3 Authority Key Identifier: | 
|  | 312                 keyid:F7:DF:89:AE:08:91:2A:16:2B:20:C1:5A:BA:34:2C:13:19:C1:C9:F
     9 | 
|  | 313 | 
|  | 314             Authority Information Access: | 
|  | 315                 CA Issuers - URI:http://url-for-aia/Root.cer | 
|  | 316 | 
|  | 317             X509v3 CRL Distribution Points: | 
|  | 318 | 
|  | 319                 Full Name: | 
|  | 320                   URI:http://url-for-crl/Root.crl | 
|  | 321 | 
|  | 322             X509v3 Key Usage: critical | 
|  | 323                 Certificate Sign, CRL Sign | 
|  | 324             X509v3 Basic Constraints: critical | 
|  | 325                 CA:TRUE | 
|  | 326     Signature Algorithm: sha256WithRSAEncryption | 
|  | 327          01:73:db:a5:50:9e:35:50:41:28:2f:8f:c7:9b:f6:30:85:32: | 
|  | 328          84:b8:7f:55:90:6e:d2:40:b2:5f:54:39:d1:37:17:54:15:98: | 
|  | 329          ff:99:a6:03:07:2e:e0:0e:3f:ba:15:d0:27:57:b5:9d:bd:ad: | 
|  | 330          35:66:2a:93:73:65:5b:52:a7:fa:94:2d:91:00:41:dc:5b:ce: | 
|  | 331          e8:11:20:22:f3:91:c6:46:41:ea:d1:df:1c:5d:27:03:fd:ae: | 
|  | 332          5b:28:70:a8:fc:76:a1:db:9d:65:ee:a7:fb:dc:22:8c:e9:13: | 
|  | 333          79:3c:52:d5:d9:70:ea:6d:8d:a4:f8:97:b7:c4:9c:91:f3:13: | 
|  | 334          20:49:e0:f7:c2:43:5c:a2:dc:ad:f3:42:75:69:f2:68:0a:5e: | 
|  | 335          38:3e:e0:f7:40:b4:6a:f7:f8:a4:4a:a0:a9:8b:7d:52:49:4b: | 
|  | 336          e6:53:66:3b:fc:4b:27:20:19:56:57:63:a5:a2:61:b3:71:30: | 
|  | 337          33:3b:13:21:7c:f8:a4:57:c8:9b:2f:92:14:26:89:8a:e6:41: | 
|  | 338          87:03:8c:f5:b2:0b:32:d0:a3:fc:51:49:c9:a2:c1:72:fa:f0: | 
|  | 339          df:9f:3f:f8:9d:f5:4c:8c:0c:45:7c:4e:2c:f4:f8:05:d5:04: | 
|  | 340          75:9f:4e:1e:95:9c:41:4b:f4:09:8a:f2:b6:00:2f:cc:7b:1e: | 
|  | 341          7c:00:16:74 | 
|  | 342 -----BEGIN TRUSTED_CERTIFICATE----- | 
|  | 343 MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
|  | 344 MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v | 
|  | 345 dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANuv0c1n+FRspPMTzW/W | 
|  | 346 muuxe7UQakCF8wRcVHf1vBprlpDEEAw0dCrEFCdehjpdDIxoG0FTDhitv/4zRKVK | 
|  | 347 sg1Ub93sGplc7ENYYCD6UXjWVx4z94s/Jw8B+GBGamexErR1HCYmfhZijF4YfZiP | 
|  | 348 sJIqc0BuRNqhyJXqfV7BN0AwDf6dSwo4BYpER06EQtvQY4efP3pLoVwulZ9e5U9q | 
|  | 349 VR7KBcOp7k4qwfVA5pwu4CUFzB1kDeBFcmUNMUl+LO/zJjmuOI5NByZAWmu7avu+ | 
|  | 350 1aA1n8C1MRogKISo22Z1uvGhsJP/l9prUs43tEF4NTkt5AzG7x5w59/HxA2yIJhf | 
|  | 351 TCUCAwEAAaOByzCByDAdBgNVHQ4EFgQU99+JrgiRKhYrIMFaujQsExnByfkwHwYD | 
|  | 352 VR0jBBgwFoAU99+JrgiRKhYrIMFaujQsExnByfkwNwYIKwYBBQUHAQEEKzApMCcG | 
|  | 353 CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw | 
|  | 354 IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE | 
|  | 355 AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQABc9ulUJ41 | 
|  | 356 UEEoL4/Hm/YwhTKEuH9VkG7SQLJfVDnRNxdUFZj/maYDBy7gDj+6FdAnV7Wdva01 | 
|  | 357 ZiqTc2VbUqf6lC2RAEHcW87oESAi85HGRkHq0d8cXScD/a5bKHCo/Hah251l7qf7 | 
|  | 358 3CKM6RN5PFLV2XDqbY2k+Je3xJyR8xMgSeD3wkNcotyt80J1afJoCl44PuD3QLRq | 
|  | 359 9/ikSqCpi31SSUvmU2Y7/EsnIBlWV2OlomGzcTAzOxMhfPikV8ibL5IUJomK5kGH | 
|  | 360 A4z1sgsy0KP8UUnJosFy+vDfnz/4nfVMjAxFfE4s9PgF1QR1n04elZxBS/QJivK2 | 
|  | 361 AC/Mex58ABZ0 | 
|  | 362 -----END TRUSTED_CERTIFICATE----- | 
|  | 363 | 
|  | 364 -----BEGIN TIME----- | 
|  | 365 MTYwMzAyMTIwMDAwWg== | 
|  | 366 -----END TIME----- | 
|  | 367 | 
|  | 368 -----BEGIN VERIFY_RESULT----- | 
|  | 369 RkFJTA== | 
|  | 370 -----END VERIFY_RESULT----- | 
| OLD | NEW | 
|---|