| Index: net/data/verify_certificate_chain_unittest/violates-basic-constraints-pathlen-0.pem | 
| diff --git a/net/data/verify_certificate_chain_unittest/violates-basic-constraints-pathlen-0.pem b/net/data/verify_certificate_chain_unittest/violates-basic-constraints-pathlen-0.pem | 
| new file mode 100644 | 
| index 0000000000000000000000000000000000000000..9deca48ab3cb726d9a7bdd91882f5b1625f052fa | 
| --- /dev/null | 
| +++ b/net/data/verify_certificate_chain_unittest/violates-basic-constraints-pathlen-0.pem | 
| @@ -0,0 +1,370 @@ | 
| +[Created by: generate-violates-basic-constraints-pathlen-0.py] | 
| + | 
| +Certificate chain with 2 intermediaries. The first | 
| +intermediary has a basic constraints path length of 0, so it is a violation for | 
| +it to have a subordinate intermediary. | 
| + | 
| +Certificate: | 
| +    Data: | 
| +        Version: 3 (0x2) | 
| +        Serial Number: 1 (0x1) | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +        Issuer: CN=Intermediary2 | 
| +        Validity | 
| +            Not Before: Jan  1 12:00:00 2015 GMT | 
| +            Not After : Jan  1 12:00:00 2016 GMT | 
| +        Subject: CN=Target | 
| +        Subject Public Key Info: | 
| +            Public Key Algorithm: rsaEncryption | 
| +                Public-Key: (2048 bit) | 
| +                Modulus: | 
| +                    00:aa:6b:96:7b:88:2a:26:42:33:eb:e5:1d:a6:22: | 
| +                    fe:45:81:72:cc:a2:59:21:39:1f:08:f2:60:2d:9b: | 
| +                    99:d6:a2:96:49:ce:4d:22:a3:57:6f:a6:54:15:11: | 
| +                    55:48:33:69:c0:cf:82:60:07:70:d2:06:70:53:f9: | 
| +                    e3:88:c8:25:c2:83:46:9b:c8:08:85:22:5b:16:b6: | 
| +                    11:0d:e4:8d:37:5a:89:06:07:8c:d7:5e:b9:82:11: | 
| +                    a8:34:3f:3b:b5:26:e2:93:1a:c9:f7:ee:52:eb:ba: | 
| +                    01:6c:11:bb:5a:d9:26:e4:da:33:07:5f:6f:8e:2a: | 
| +                    f1:e6:65:d8:3a:1f:ba:a7:45:9e:c5:e2:2b:c9:b1: | 
| +                    0b:82:66:f8:9e:63:ca:55:b2:9b:69:a5:ed:b8:c6: | 
| +                    00:dc:3d:9e:55:c2:06:d2:34:51:b1:c6:26:4c:8e: | 
| +                    ee:1d:0d:d0:4b:3a:7a:8c:f9:b3:98:1e:98:4b:f8: | 
| +                    e2:29:91:b8:6f:72:d2:f0:4a:fd:90:6c:9f:d2:d9: | 
| +                    41:c9:6e:c7:65:e7:77:1f:18:5c:a4:22:34:cd:33: | 
| +                    8a:57:fb:03:47:07:98:3e:86:2d:04:7e:5c:0e:40: | 
| +                    54:45:12:e4:02:fc:80:1c:e0:50:78:12:5d:80:54: | 
| +                    ac:19:ea:b3:df:39:d7:57:f0:75:17:6d:e0:db:a6: | 
| +                    83:2d | 
| +                Exponent: 65537 (0x10001) | 
| +        X509v3 extensions: | 
| +            X509v3 Subject Key Identifier: | 
| +                09:1C:36:4F:EC:22:4C:B8:27:CB:BB:BF:61:EA:E9:B2:38:1B:33:39 | 
| +            X509v3 Authority Key Identifier: | 
| +                keyid:5F:A2:FB:66:0B:2E:39:14:C8:43:2F:9A:DD:BF:CC:56:BA:FF:39:B8 | 
| + | 
| +            Authority Information Access: | 
| +                CA Issuers - URI:http://url-for-aia/Intermediary2.cer | 
| + | 
| +            X509v3 CRL Distribution Points: | 
| + | 
| +                Full Name: | 
| +                  URI:http://url-for-crl/Intermediary2.crl | 
| + | 
| +            X509v3 Key Usage: critical | 
| +                Digital Signature, Key Encipherment | 
| +            X509v3 Extended Key Usage: | 
| +                TLS Web Server Authentication, TLS Web Client Authentication | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +         18:28:02:69:68:9c:b0:68:8b:55:7d:bb:2c:6c:31:22:cd:14: | 
| +         36:6f:e8:2f:38:a3:63:3c:4f:40:1d:9a:85:33:96:4c:45:2b: | 
| +         6d:c3:cf:1b:c8:2f:07:14:24:f4:89:b5:c2:d7:88:fd:fa:8d: | 
| +         43:92:96:d5:f7:54:c8:06:1a:c5:09:b0:1d:15:35:a7:37:a4: | 
| +         3a:a8:26:fb:af:fb:dd:49:23:d1:60:0b:fc:54:98:c3:20:f2: | 
| +         61:8a:6e:c1:3c:d4:bc:aa:f8:d8:8c:ba:26:01:15:53:9a:cf: | 
| +         ad:e9:65:1c:6f:dd:e6:4e:db:2c:d3:05:1a:68:74:c6:cd:c2: | 
| +         fe:7f:4c:ad:b8:a5:53:b7:8d:6e:61:24:24:f5:7e:2c:fe:2f: | 
| +         16:83:b6:f7:43:b8:49:4f:c8:1d:4c:a9:2a:00:9b:45:d3:0f: | 
| +         fb:9f:dd:37:44:f8:86:f9:09:45:b7:13:c4:ac:f2:61:26:09: | 
| +         94:37:37:80:6c:d9:7e:1a:f5:02:2a:35:46:57:e1:0b:60:65: | 
| +         f1:4d:97:83:e5:a2:f8:8b:79:13:c5:56:fe:01:71:bc:9d:0a: | 
| +         1c:6a:b5:8c:89:3a:12:93:b8:41:48:cc:e2:bd:7a:4c:0c:c6: | 
| +         64:35:43:8a:18:5e:a8:b1:27:10:6e:0f:27:f1:7c:07:af:06: | 
| +         c1:e5:d9:b5 | 
| +-----BEGIN CERTIFICATE----- | 
| +MIIDkDCCAnigAwIBAgIBATANBgkqhkiG9w0BAQsFADAYMRYwFAYDVQQDDA1JbnRl | 
| +cm1lZGlhcnkyMB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowETEPMA0G | 
| +A1UEAwwGVGFyZ2V0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqmuW | 
| +e4gqJkIz6+UdpiL+RYFyzKJZITkfCPJgLZuZ1qKWSc5NIqNXb6ZUFRFVSDNpwM+C | 
| +YAdw0gZwU/njiMglwoNGm8gIhSJbFrYRDeSNN1qJBgeM1165ghGoND87tSbikxrJ | 
| +9+5S67oBbBG7Wtkm5NozB19vjirx5mXYOh+6p0WexeIrybELgmb4nmPKVbKbaaXt | 
| +uMYA3D2eVcIG0jRRscYmTI7uHQ3QSzp6jPmzmB6YS/jiKZG4b3LS8Er9kGyf0tlB | 
| +yW7HZed3HxhcpCI0zTOKV/sDRweYPoYtBH5cDkBURRLkAvyAHOBQeBJdgFSsGeqz | 
| +3znXV/B1F23g26aDLQIDAQABo4HrMIHoMB0GA1UdDgQWBBQJHDZP7CJMuCfLu79h | 
| +6umyOBszOTAfBgNVHSMEGDAWgBRfovtmCy45FMhDL5rdv8xWuv85uDBABggrBgEF | 
| +BQcBAQQ0MDIwMAYIKwYBBQUHMAKGJGh0dHA6Ly91cmwtZm9yLWFpYS9JbnRlcm1l | 
| +ZGlhcnkyLmNlcjA1BgNVHR8ELjAsMCqgKKAmhiRodHRwOi8vdXJsLWZvci1jcmwv | 
| +SW50ZXJtZWRpYXJ5Mi5jcmwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsG | 
| +AQUFBwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAGCgCaWicsGiLVX27 | 
| +LGwxIs0UNm/oLzijYzxPQB2ahTOWTEUrbcPPG8gvBxQk9Im1wteI/fqNQ5KW1fdU | 
| +yAYaxQmwHRU1pzekOqgm+6/73Ukj0WAL/FSYwyDyYYpuwTzUvKr42Iy6JgEVU5rP | 
| +rellHG/d5k7bLNMFGmh0xs3C/n9MrbilU7eNbmEkJPV+LP4vFoO290O4SU/IHUyp | 
| +KgCbRdMP+5/dN0T4hvkJRbcTxKzyYSYJlDc3gGzZfhr1Aio1RlfhC2Bl8U2Xg+Wi | 
| ++It5E8VW/gFxvJ0KHGq1jIk6EpO4QUjM4r16TAzGZDVDihheqLEnEG4PJ/F8B68G | 
| +weXZtQ== | 
| +-----END CERTIFICATE----- | 
| + | 
| +Certificate: | 
| +    Data: | 
| +        Version: 3 (0x2) | 
| +        Serial Number: 1 (0x1) | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +        Issuer: CN=Intermediary1 | 
| +        Validity | 
| +            Not Before: Jan  1 12:00:00 2015 GMT | 
| +            Not After : Jan  1 12:00:00 2016 GMT | 
| +        Subject: CN=Intermediary2 | 
| +        Subject Public Key Info: | 
| +            Public Key Algorithm: rsaEncryption | 
| +                Public-Key: (2048 bit) | 
| +                Modulus: | 
| +                    00:c9:a3:fd:44:af:b5:fa:d3:9b:f2:fd:e4:9a:a6: | 
| +                    39:0d:f1:3c:74:f8:c5:82:1a:32:5d:ab:a0:23:1f: | 
| +                    ec:8a:5c:90:db:95:8f:64:74:ca:dd:81:b8:85:e5: | 
| +                    cf:2e:44:55:5a:21:93:15:4c:f3:77:7b:bb:b9:56: | 
| +                    f1:19:f9:e7:b0:76:37:96:19:88:90:54:9b:5a:9c: | 
| +                    cd:fc:a2:ec:d7:e8:8b:3e:00:2e:ef:17:0f:f1:bc: | 
| +                    1b:48:05:76:5d:ef:f5:f1:92:62:b3:79:88:07:5b: | 
| +                    79:b5:99:b5:4e:7d:d2:13:4b:fc:31:b0:37:e6:08: | 
| +                    37:cb:e2:46:b3:e2:dc:3d:8f:7e:26:e3:d7:b0:52: | 
| +                    0e:1f:da:08:3f:43:17:e9:6b:d4:ae:6f:54:04:75: | 
| +                    68:fb:c3:c8:6b:96:f6:35:ab:6c:c7:ab:ea:42:e0: | 
| +                    5c:8c:b3:88:42:52:de:83:40:ab:57:76:55:92:ae: | 
| +                    11:0c:dd:9a:32:09:c1:92:dd:05:6c:1b:19:51:1a: | 
| +                    97:24:9d:37:fc:37:cc:e2:e8:b4:cd:eb:e6:29:56: | 
| +                    69:b5:f8:84:b7:1d:3b:db:40:b8:f2:3c:9b:ad:2c: | 
| +                    9a:a8:12:d3:3d:2c:1a:6e:b4:11:18:b5:39:c9:bc: | 
| +                    80:9f:d2:7b:f2:69:1b:e4:21:ea:72:9e:eb:00:f7: | 
| +                    87:87 | 
| +                Exponent: 65537 (0x10001) | 
| +        X509v3 extensions: | 
| +            X509v3 Subject Key Identifier: | 
| +                5F:A2:FB:66:0B:2E:39:14:C8:43:2F:9A:DD:BF:CC:56:BA:FF:39:B8 | 
| +            X509v3 Authority Key Identifier: | 
| +                keyid:77:76:48:B2:B6:41:E7:F8:16:FB:DF:3E:6D:99:F4:9F:ED:FE:6F:75 | 
| + | 
| +            Authority Information Access: | 
| +                CA Issuers - URI:http://url-for-aia/Intermediary1.cer | 
| + | 
| +            X509v3 CRL Distribution Points: | 
| + | 
| +                Full Name: | 
| +                  URI:http://url-for-crl/Intermediary1.crl | 
| + | 
| +            X509v3 Key Usage: critical | 
| +                Certificate Sign, CRL Sign | 
| +            X509v3 Basic Constraints: critical | 
| +                CA:TRUE, pathlen:0 | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +         64:29:65:04:5f:b1:30:26:83:84:67:8f:51:8c:d2:0f:6c:0c: | 
| +         ab:50:99:c3:f0:e8:f0:88:f8:2e:c9:85:4f:43:d1:47:cc:43: | 
| +         00:53:57:e5:dc:ae:53:fb:23:0d:fc:82:8c:cc:bf:72:ee:63: | 
| +         3d:26:cd:53:19:4f:e6:c2:51:0f:ce:85:25:62:9d:85:80:f1: | 
| +         3e:89:3a:3c:76:fd:bf:2a:7c:2e:d7:df:38:80:26:7c:9a:79: | 
| +         e8:de:b7:1e:4a:4d:1a:5b:1e:34:8a:ae:af:0b:d6:6a:13:f2: | 
| +         ca:dc:03:de:53:e7:54:02:96:55:c5:35:e8:33:60:5d:45:cb: | 
| +         59:d3:a8:8b:72:92:e5:12:b3:23:b6:7a:0d:6e:f7:f7:fd:46: | 
| +         dc:55:94:e5:40:cb:9c:b7:e1:95:54:7a:0a:7b:7e:f3:09:26: | 
| +         8d:10:09:f2:e5:7f:a1:76:c9:c6:6d:d7:9d:24:af:a8:29:d0: | 
| +         69:6f:0a:17:ec:5c:31:be:ff:e7:03:a5:0a:bb:5a:08:ff:d7: | 
| +         d8:b2:ce:15:c9:71:a2:c9:ad:6d:42:25:37:22:70:58:60:b3: | 
| +         e5:e4:72:c5:14:75:be:e7:9d:75:a5:4c:cf:6c:a5:29:39:11: | 
| +         47:57:d9:04:9c:7e:27:84:ec:fa:a5:ce:fa:37:2b:79:35:d0: | 
| +         88:04:6a:da | 
| +-----BEGIN CERTIFICATE----- | 
| +MIIDjDCCAnSgAwIBAgIBATANBgkqhkiG9w0BAQsFADAYMRYwFAYDVQQDDA1JbnRl | 
| +cm1lZGlhcnkxMB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowGDEWMBQG | 
| +A1UEAwwNSW50ZXJtZWRpYXJ5MjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC | 
| +ggEBAMmj/USvtfrTm/L95JqmOQ3xPHT4xYIaMl2roCMf7IpckNuVj2R0yt2BuIXl | 
| +zy5EVVohkxVM83d7u7lW8Rn557B2N5YZiJBUm1qczfyi7Nfoiz4ALu8XD/G8G0gF | 
| +dl3v9fGSYrN5iAdbebWZtU590hNL/DGwN+YIN8viRrPi3D2Pfibj17BSDh/aCD9D | 
| +F+lr1K5vVAR1aPvDyGuW9jWrbMer6kLgXIyziEJS3oNAq1d2VZKuEQzdmjIJwZLd | 
| +BWwbGVEalySdN/w3zOLotM3r5ilWabX4hLcdO9tAuPI8m60smqgS0z0sGm60ERi1 | 
| +Ocm8gJ/Se/JpG+Qh6nKe6wD3h4cCAwEAAaOB4DCB3TAdBgNVHQ4EFgQUX6L7Zgsu | 
| +ORTIQy+a3b/MVrr/ObgwHwYDVR0jBBgwFoAUd3ZIsrZB5/gW+98+bZn0n+3+b3Uw | 
| +QAYIKwYBBQUHAQEENDAyMDAGCCsGAQUFBzAChiRodHRwOi8vdXJsLWZvci1haWEv | 
| +SW50ZXJtZWRpYXJ5MS5jZXIwNQYDVR0fBC4wLDAqoCigJoYkaHR0cDovL3VybC1m | 
| +b3ItY3JsL0ludGVybWVkaWFyeTEuY3JsMA4GA1UdDwEB/wQEAwIBBjASBgNVHRMB | 
| +Af8ECDAGAQH/AgEAMA0GCSqGSIb3DQEBCwUAA4IBAQBkKWUEX7EwJoOEZ49RjNIP | 
| +bAyrUJnD8OjwiPguyYVPQ9FHzEMAU1fl3K5T+yMN/IKMzL9y7mM9Js1TGU/mwlEP | 
| +zoUlYp2FgPE+iTo8dv2/Knwu1984gCZ8mnno3rceSk0aWx40iq6vC9ZqE/LK3APe | 
| +U+dUApZVxTXoM2BdRctZ06iLcpLlErMjtnoNbvf3/UbcVZTlQMuct+GVVHoKe37z | 
| +CSaNEAny5X+hdsnGbdedJK+oKdBpbwoX7Fwxvv/nA6UKu1oI/9fYss4VyXGiya1t | 
| +QiU3InBYYLPl5HLFFHW+5511pUzPbKUpORFHV9kEnH4nhOz6pc76Nyt5NdCIBGra | 
| +-----END CERTIFICATE----- | 
| + | 
| +Certificate: | 
| +    Data: | 
| +        Version: 3 (0x2) | 
| +        Serial Number: 2 (0x2) | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +        Issuer: CN=Root | 
| +        Validity | 
| +            Not Before: Jan  1 12:00:00 2015 GMT | 
| +            Not After : Jan  1 12:00:00 2016 GMT | 
| +        Subject: CN=Intermediary1 | 
| +        Subject Public Key Info: | 
| +            Public Key Algorithm: rsaEncryption | 
| +                Public-Key: (2048 bit) | 
| +                Modulus: | 
| +                    00:b8:05:65:94:1f:e3:bc:28:11:c3:81:56:4b:02: | 
| +                    ce:05:a1:c1:bd:68:dd:8f:c0:d0:69:17:98:60:1f: | 
| +                    00:76:80:ae:a6:0b:d5:40:d3:c7:5d:8c:20:29:fe: | 
| +                    a4:88:ae:ea:2c:e4:fa:1f:a3:48:cf:6a:17:8d:3e: | 
| +                    d8:66:eb:39:fd:03:62:91:18:3d:12:25:1a:c3:4d: | 
| +                    7b:4a:da:0a:bc:81:58:55:90:7f:39:41:0f:f4:2f: | 
| +                    1c:32:40:b5:e4:b0:83:07:de:18:8e:0a:44:64:b3: | 
| +                    64:43:19:a8:0b:79:89:fa:04:15:02:18:3e:42:72: | 
| +                    f5:6c:fd:7c:43:20:20:6f:09:dd:75:c3:b3:41:cb: | 
| +                    ea:d9:0f:0b:3a:3e:08:bd:a8:2e:55:f6:4b:01:35: | 
| +                    68:78:9d:2b:dc:1b:be:a6:02:db:b9:1d:18:7b:29: | 
| +                    02:e6:b7:27:3d:54:e3:49:b1:bb:58:49:ce:88:75: | 
| +                    8d:54:22:41:0f:54:53:e4:7f:62:14:cb:c5:ba:61: | 
| +                    02:73:05:51:8d:c0:ce:b5:11:51:88:c0:bd:05:ab: | 
| +                    fa:23:d3:da:31:4e:06:82:72:b3:21:6b:46:d9:da: | 
| +                    95:c1:82:8b:09:c9:20:51:51:81:27:19:1d:fb:d6: | 
| +                    b8:21:71:37:9b:9e:66:2a:24:41:3a:cb:06:4c:7c: | 
| +                    64:f9 | 
| +                Exponent: 65537 (0x10001) | 
| +        X509v3 extensions: | 
| +            X509v3 Subject Key Identifier: | 
| +                77:76:48:B2:B6:41:E7:F8:16:FB:DF:3E:6D:99:F4:9F:ED:FE:6F:75 | 
| +            X509v3 Authority Key Identifier: | 
| +                keyid:F7:DF:89:AE:08:91:2A:16:2B:20:C1:5A:BA:34:2C:13:19:C1:C9:F9 | 
| + | 
| +            Authority Information Access: | 
| +                CA Issuers - URI:http://url-for-aia/Root.cer | 
| + | 
| +            X509v3 CRL Distribution Points: | 
| + | 
| +                Full Name: | 
| +                  URI:http://url-for-crl/Root.crl | 
| + | 
| +            X509v3 Key Usage: critical | 
| +                Certificate Sign, CRL Sign | 
| +            X509v3 Basic Constraints: critical | 
| +                CA:TRUE, pathlen:0 | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +         66:f8:8c:ea:42:57:10:51:25:2e:cb:ae:48:67:75:25:1a:5a: | 
| +         d3:80:a6:02:9f:e8:40:f2:ac:5b:38:7f:98:09:46:ca:49:7e: | 
| +         48:d5:67:8b:c4:2a:f8:fa:f0:31:fe:48:59:7e:18:16:a5:a7: | 
| +         ea:56:fe:6b:e6:16:4e:f4:90:f6:89:ae:ab:e5:1c:10:32:cf: | 
| +         58:f6:96:fc:78:98:6a:7e:6c:97:e0:e6:27:9c:ea:94:1c:f9: | 
| +         48:60:fc:87:53:c9:9c:1c:f7:a1:6f:8f:c5:3b:aa:8c:c0:31: | 
| +         94:eb:8d:db:7c:86:e5:18:1e:da:09:8e:30:70:d2:b7:1f:95: | 
| +         95:9b:f4:07:02:e4:f4:66:0c:29:a1:ea:03:1d:fe:d0:5b:3b: | 
| +         f9:6f:91:5d:ef:76:9c:f3:92:4e:58:4c:eb:8f:7c:01:c6:1d: | 
| +         97:02:2e:ac:3d:91:e8:51:a8:3e:e1:82:02:d5:e8:6e:42:31: | 
| +         e0:28:88:dd:62:50:a3:ab:1e:75:94:80:21:7f:a3:22:37:72: | 
| +         81:4f:f1:68:cc:a7:b3:40:e8:98:19:97:fc:8c:cf:3e:43:bb: | 
| +         17:ff:c7:35:aa:34:5e:d9:de:53:d8:80:8b:2e:2b:d5:8c:8c: | 
| +         2e:05:b1:39:4f:d3:9c:cd:a4:a4:7c:f6:7d:5b:8e:0f:09:72: | 
| +         f5:0c:b5:5c | 
| +-----BEGIN CERTIFICATE----- | 
| +MIIDcTCCAlmgAwIBAgIBAjANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
| +MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowGDEWMBQGA1UEAwwNSW50 | 
| +ZXJtZWRpYXJ5MTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALgFZZQf | 
| +47woEcOBVksCzgWhwb1o3Y/A0GkXmGAfAHaArqYL1UDTx12MICn+pIiu6izk+h+j | 
| +SM9qF40+2GbrOf0DYpEYPRIlGsNNe0raCryBWFWQfzlBD/QvHDJAteSwgwfeGI4K | 
| +RGSzZEMZqAt5ifoEFQIYPkJy9Wz9fEMgIG8J3XXDs0HL6tkPCzo+CL2oLlX2SwE1 | 
| +aHidK9wbvqYC27kdGHspAua3Jz1U40mxu1hJzoh1jVQiQQ9UU+R/YhTLxbphAnMF | 
| +UY3AzrURUYjAvQWr+iPT2jFOBoJysyFrRtnalcGCiwnJIFFRgScZHfvWuCFxN5ue | 
| +ZiokQTrLBkx8ZPkCAwEAAaOBzjCByzAdBgNVHQ4EFgQUd3ZIsrZB5/gW+98+bZn0 | 
| +n+3+b3UwHwYDVR0jBBgwFoAU99+JrgiRKhYrIMFaujQsExnByfkwNwYIKwYBBQUH | 
| +AQEEKzApMCcGCCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIw | 
| +LAYDVR0fBCUwIzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4G | 
| +A1UdDwEB/wQEAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEAMA0GCSqGSIb3DQEBCwUA | 
| +A4IBAQBm+IzqQlcQUSUuy65IZ3UlGlrTgKYCn+hA8qxbOH+YCUbKSX5I1WeLxCr4 | 
| ++vAx/khZfhgWpafqVv5r5hZO9JD2ia6r5RwQMs9Y9pb8eJhqfmyX4OYnnOqUHPlI | 
| +YPyHU8mcHPehb4/FO6qMwDGU643bfIblGB7aCY4wcNK3H5WVm/QHAuT0ZgwpoeoD | 
| +Hf7QWzv5b5Fd73ac85JOWEzrj3wBxh2XAi6sPZHoUag+4YIC1ehuQjHgKIjdYlCj | 
| +qx51lIAhf6MiN3KBT/FozKezQOiYGZf8jM8+Q7sX/8c1qjRe2d5T2ICLLivVjIwu | 
| +BbE5T9OczaSkfPZ9W44PCXL1DLVc | 
| +-----END CERTIFICATE----- | 
| + | 
| +Certificate: | 
| +    Data: | 
| +        Version: 3 (0x2) | 
| +        Serial Number: 1 (0x1) | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +        Issuer: CN=Root | 
| +        Validity | 
| +            Not Before: Jan  1 12:00:00 2015 GMT | 
| +            Not After : Jan  1 12:00:00 2016 GMT | 
| +        Subject: CN=Root | 
| +        Subject Public Key Info: | 
| +            Public Key Algorithm: rsaEncryption | 
| +                Public-Key: (2048 bit) | 
| +                Modulus: | 
| +                    00:db:af:d1:cd:67:f8:54:6c:a4:f3:13:cd:6f:d6: | 
| +                    9a:eb:b1:7b:b5:10:6a:40:85:f3:04:5c:54:77:f5: | 
| +                    bc:1a:6b:96:90:c4:10:0c:34:74:2a:c4:14:27:5e: | 
| +                    86:3a:5d:0c:8c:68:1b:41:53:0e:18:ad:bf:fe:33: | 
| +                    44:a5:4a:b2:0d:54:6f:dd:ec:1a:99:5c:ec:43:58: | 
| +                    60:20:fa:51:78:d6:57:1e:33:f7:8b:3f:27:0f:01: | 
| +                    f8:60:46:6a:67:b1:12:b4:75:1c:26:26:7e:16:62: | 
| +                    8c:5e:18:7d:98:8f:b0:92:2a:73:40:6e:44:da:a1: | 
| +                    c8:95:ea:7d:5e:c1:37:40:30:0d:fe:9d:4b:0a:38: | 
| +                    05:8a:44:47:4e:84:42:db:d0:63:87:9f:3f:7a:4b: | 
| +                    a1:5c:2e:95:9f:5e:e5:4f:6a:55:1e:ca:05:c3:a9: | 
| +                    ee:4e:2a:c1:f5:40:e6:9c:2e:e0:25:05:cc:1d:64: | 
| +                    0d:e0:45:72:65:0d:31:49:7e:2c:ef:f3:26:39:ae: | 
| +                    38:8e:4d:07:26:40:5a:6b:bb:6a:fb:be:d5:a0:35: | 
| +                    9f:c0:b5:31:1a:20:28:84:a8:db:66:75:ba:f1:a1: | 
| +                    b0:93:ff:97:da:6b:52:ce:37:b4:41:78:35:39:2d: | 
| +                    e4:0c:c6:ef:1e:70:e7:df:c7:c4:0d:b2:20:98:5f: | 
| +                    4c:25 | 
| +                Exponent: 65537 (0x10001) | 
| +        X509v3 extensions: | 
| +            X509v3 Subject Key Identifier: | 
| +                F7:DF:89:AE:08:91:2A:16:2B:20:C1:5A:BA:34:2C:13:19:C1:C9:F9 | 
| +            X509v3 Authority Key Identifier: | 
| +                keyid:F7:DF:89:AE:08:91:2A:16:2B:20:C1:5A:BA:34:2C:13:19:C1:C9:F9 | 
| + | 
| +            Authority Information Access: | 
| +                CA Issuers - URI:http://url-for-aia/Root.cer | 
| + | 
| +            X509v3 CRL Distribution Points: | 
| + | 
| +                Full Name: | 
| +                  URI:http://url-for-crl/Root.crl | 
| + | 
| +            X509v3 Key Usage: critical | 
| +                Certificate Sign, CRL Sign | 
| +            X509v3 Basic Constraints: critical | 
| +                CA:TRUE | 
| +    Signature Algorithm: sha256WithRSAEncryption | 
| +         01:73:db:a5:50:9e:35:50:41:28:2f:8f:c7:9b:f6:30:85:32: | 
| +         84:b8:7f:55:90:6e:d2:40:b2:5f:54:39:d1:37:17:54:15:98: | 
| +         ff:99:a6:03:07:2e:e0:0e:3f:ba:15:d0:27:57:b5:9d:bd:ad: | 
| +         35:66:2a:93:73:65:5b:52:a7:fa:94:2d:91:00:41:dc:5b:ce: | 
| +         e8:11:20:22:f3:91:c6:46:41:ea:d1:df:1c:5d:27:03:fd:ae: | 
| +         5b:28:70:a8:fc:76:a1:db:9d:65:ee:a7:fb:dc:22:8c:e9:13: | 
| +         79:3c:52:d5:d9:70:ea:6d:8d:a4:f8:97:b7:c4:9c:91:f3:13: | 
| +         20:49:e0:f7:c2:43:5c:a2:dc:ad:f3:42:75:69:f2:68:0a:5e: | 
| +         38:3e:e0:f7:40:b4:6a:f7:f8:a4:4a:a0:a9:8b:7d:52:49:4b: | 
| +         e6:53:66:3b:fc:4b:27:20:19:56:57:63:a5:a2:61:b3:71:30: | 
| +         33:3b:13:21:7c:f8:a4:57:c8:9b:2f:92:14:26:89:8a:e6:41: | 
| +         87:03:8c:f5:b2:0b:32:d0:a3:fc:51:49:c9:a2:c1:72:fa:f0: | 
| +         df:9f:3f:f8:9d:f5:4c:8c:0c:45:7c:4e:2c:f4:f8:05:d5:04: | 
| +         75:9f:4e:1e:95:9c:41:4b:f4:09:8a:f2:b6:00:2f:cc:7b:1e: | 
| +         7c:00:16:74 | 
| +-----BEGIN TRUSTED_CERTIFICATE----- | 
| +MIIDZTCCAk2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAPMQ0wCwYDVQQDDARSb290 | 
| +MB4XDTE1MDEwMTEyMDAwMFoXDTE2MDEwMTEyMDAwMFowDzENMAsGA1UEAwwEUm9v | 
| +dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANuv0c1n+FRspPMTzW/W | 
| +muuxe7UQakCF8wRcVHf1vBprlpDEEAw0dCrEFCdehjpdDIxoG0FTDhitv/4zRKVK | 
| +sg1Ub93sGplc7ENYYCD6UXjWVx4z94s/Jw8B+GBGamexErR1HCYmfhZijF4YfZiP | 
| +sJIqc0BuRNqhyJXqfV7BN0AwDf6dSwo4BYpER06EQtvQY4efP3pLoVwulZ9e5U9q | 
| +VR7KBcOp7k4qwfVA5pwu4CUFzB1kDeBFcmUNMUl+LO/zJjmuOI5NByZAWmu7avu+ | 
| +1aA1n8C1MRogKISo22Z1uvGhsJP/l9prUs43tEF4NTkt5AzG7x5w59/HxA2yIJhf | 
| +TCUCAwEAAaOByzCByDAdBgNVHQ4EFgQU99+JrgiRKhYrIMFaujQsExnByfkwHwYD | 
| +VR0jBBgwFoAU99+JrgiRKhYrIMFaujQsExnByfkwNwYIKwYBBQUHAQEEKzApMCcG | 
| +CCsGAQUFBzAChhtodHRwOi8vdXJsLWZvci1haWEvUm9vdC5jZXIwLAYDVR0fBCUw | 
| +IzAhoB+gHYYbaHR0cDovL3VybC1mb3ItY3JsL1Jvb3QuY3JsMA4GA1UdDwEB/wQE | 
| +AwIBBjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQABc9ulUJ41 | 
| +UEEoL4/Hm/YwhTKEuH9VkG7SQLJfVDnRNxdUFZj/maYDBy7gDj+6FdAnV7Wdva01 | 
| +ZiqTc2VbUqf6lC2RAEHcW87oESAi85HGRkHq0d8cXScD/a5bKHCo/Hah251l7qf7 | 
| +3CKM6RN5PFLV2XDqbY2k+Je3xJyR8xMgSeD3wkNcotyt80J1afJoCl44PuD3QLRq | 
| +9/ikSqCpi31SSUvmU2Y7/EsnIBlWV2OlomGzcTAzOxMhfPikV8ibL5IUJomK5kGH | 
| +A4z1sgsy0KP8UUnJosFy+vDfnz/4nfVMjAxFfE4s9PgF1QR1n04elZxBS/QJivK2 | 
| +AC/Mex58ABZ0 | 
| +-----END TRUSTED_CERTIFICATE----- | 
| + | 
| +-----BEGIN TIME----- | 
| +MTYwMzAyMTIwMDAwWg== | 
| +-----END TIME----- | 
| + | 
| +-----BEGIN VERIFY_RESULT----- | 
| +RkFJTA== | 
| +-----END VERIFY_RESULT----- | 
|  |