[ The basicConstraints extension exists and the CA flag is false. This should not be validated. ] Certificate: Data: Version: 3 (0x2) Serial Number: 46 (0x2e) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=U.S. Government, OU=Dod, OU=Testing, CN=CA1-IC.02.01 Validity Not Before: Jan 1 12:01:00 1998 GMT Not After : Jan 1 12:01:00 2048 GMT Subject: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=User1-IC.02.01 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public Key: (1024 bit) Modulus (1024 bit): 00:d6:d3:55:e0:31:3a:26:c0:3b:72:86:ab:1c:58: dd:5a:8a:5c:3a:fd:b4:a2:4d:fa:28:29:29:be:30: 82:84:74:66:75:86:0e:eb:12:56:6e:29:be:77:99: f6:a7:e6:8b:c0:34:b0:cd:04:f7:5f:81:da:10:30: b1:4e:98:f5:1a:00:ee:73:ec:4e:41:58:8b:91:7e: 84:71:88:17:8e:8e:a7:af:1b:94:6a:d9:ad:a1:9f: f5:bb:16:5c:26:45:a0:ba:31:72:09:6d:c2:31:8f: 42:ac:99:e6:69:e7:9b:c7:31:51:bb:5a:5a:68:28: db:c3:0a:d7:20:47:fe:c4:b9 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Key Usage: critical Digital Signature, Non Repudiation, Key Encipherment X509v3 Certificate Policies: Policy: 2.16.840.1.101.3.1.48.1 X509v3 Subject Key Identifier: DE:09:01:36:8F:D2:21:23 X509v3 Authority Key Identifier: keyid:85:3F:46:8D:A6:87:8F:AF Signature Algorithm: sha1WithRSAEncryption 40:69:75:ee:e4:f6:c7:16:03:92:ce:87:a2:5a:d0:22:97:ac: 22:83:ea:12:26:7c:4e:48:b3:10:1b:8b:1b:7b:14:2a:c0:bb: 92:51:f0:cb:68:b2:56:f0:3a:9d:15:03:c1:ff:d7:cc:32:e9: 19:6f:c6:9f:42:93:5b:a6:58:21:7e:ac:9c:e0:b5:fb:b1:d7: e4:e2:60:95:0c:7c:b4:3a:43:bd:c0:20:ca:87:0a:f0:fb:c2: ac:77:ee:f6:8d:f7:27:8f:5a:49:e2:c0:56:9a:02:1f:09:de: b5:3b:49:c5:57:d3:32:68:d8:58:a7:83:6c:71:c7:8b:c6:b6: 61:32 -----BEGIN CERTIFICATE----- MIIChjCCAe+gAwIBAgIBLjANBgkqhkiG9w0BAQUFADBeMQswCQYDVQQGEwJVUzEY MBYGA1UEChMPVS5TLiBHb3Zlcm5tZW50MQwwCgYDVQQLEwNEb2QxEDAOBgNVBAsT B1Rlc3RpbmcxFTATBgNVBAMTDENBMS1JQy4wMi4wMTAeFw05ODAxMDExMjAxMDBa Fw00ODAxMDExMjAxMDBaMGAxCzAJBgNVBAYTAlVTMRgwFgYDVQQKEw9VLlMuIEdv dmVybm1lbnQxDDAKBgNVBAsTA0RvRDEQMA4GA1UECxMHVGVzdGluZzEXMBUGA1UE AxMOVXNlcjEtSUMuMDIuMDEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANbT VeAxOibAO3KGqxxY3VqKXDr9tKJN+igpKb4wgoR0ZnWGDusSVm4pvneZ9qfmi8A0 sM0E91+B2hAwsU6Y9RoA7nPsTkFYi5F+hHGIF46Op68blGrZraGf9bsWXCZFoLox cgltwjGPQqyZ5mnnm8cxUbtaWmgo28MK1yBH/sS5AgMBAAGjUjBQMA4GA1UdDwEB /wQEAwIF4DAWBgNVHSAEDzANMAsGCWCGSAFlAwEwATARBgNVHQ4ECgQI3gkBNo/S ISMwEwYDVR0jBAwwCoAIhT9GjaaHj68wDQYJKoZIhvcNAQEFBQADgYEAQGl17uT2 xxYDks6HolrQIpesIoPqEiZ8TkizEBuLG3sUKsC7klHwy2iyVvA6nRUDwf/XzDLp GW/Gn0KTW6ZYIX6snOC1+7HX5OJglQx8tDpDvcAgyocK8PvCrHfu9o33J49aSeLA VpoCHwnetTtJxVfTMmjYWKeDbHHHi8a2YTI= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 45 (0x2d) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=Trust Anchor Validity Not Before: Jan 1 12:01:00 1998 GMT Not After : Jan 1 12:01:00 2048 GMT Subject: C=US, O=U.S. Government, OU=Dod, OU=Testing, CN=CA1-IC.02.01 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public Key: (1024 bit) Modulus (1024 bit): 00:de:98:98:19:9c:ec:d7:3b:03:46:a9:10:37:5e: af:5a:32:b0:16:41:4e:28:16:e8:52:10:bb:04:61: f2:d9:18:ed:e7:b4:18:c9:2e:a0:a7:fa:bb:37:16: 34:7d:37:de:1c:bb:ad:d3:76:e3:80:82:a9:57:aa: b3:5b:bf:23:b5:f9:21:7d:9b:7e:49:5e:b7:aa:9f: f3:92:e8:aa:ca:e9:cf:16:d8:8a:43:01:62:5c:af: cf:67:1b:2c:82:5c:ca:09:79:a3:8e:b6:3f:26:d8: d8:d9:6e:59:82:66:fb:40:97:95:0c:39:ec:3b:dc: 61:3b:67:97:c4:fa:3b:40:db Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Certificate Policies: Policy: 2.16.840.1.101.3.1.48.1 X509v3 Subject Key Identifier: 85:3F:46:8D:A6:87:8F:AF X509v3 Authority Key Identifier: keyid:AB:9A:EB:F9:C2:E7:54:8F Signature Algorithm: sha1WithRSAEncryption 5a:12:89:52:e8:cb:6a:9c:69:cf:f0:e8:0f:fc:38:f0:73:33: 90:be:94:40:2c:50:3c:e0:23:c3:01:e2:71:7f:30:15:c2:a6: 72:b5:8b:54:17:55:0b:7d:3e:cb:0a:f3:32:b6:96:85:aa:be: 40:23:aa:b2:0b:71:0b:04:d9:ad:f5:31:6c:23:6a:84:a4:b4: 95:98:a3:08:c8:0d:37:82:61:b7:e3:c0:67:6d:ad:cc:4b:30: ee:70:b0:88:c3:36:9f:58:de:28:5f:f7:6e:da:03:11:4b:d9: 9f:d4:ae:ce:19:08:cb:1c:bb:43:c9:76:b5:b3:4e:b0:03:6a: a7:11 -----BEGIN CERTIFICATE----- MIICkjCCAfugAwIBAgIBLTANBgkqhkiG9w0BAQUFADBeMQswCQYDVQQGEwJVUzEY MBYGA1UEChMPVS5TLiBHb3Zlcm5tZW50MQwwCgYDVQQLEwNEb0QxEDAOBgNVBAsT B1Rlc3RpbmcxFTATBgNVBAMTDFRydXN0IEFuY2hvcjAeFw05ODAxMDExMjAxMDBa Fw00ODAxMDExMjAxMDBaMF4xCzAJBgNVBAYTAlVTMRgwFgYDVQQKEw9VLlMuIEdv dmVybm1lbnQxDDAKBgNVBAsTA0RvZDEQMA4GA1UECxMHVGVzdGluZzEVMBMGA1UE AxMMQ0ExLUlDLjAyLjAxMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDemJgZ nOzXOwNGqRA3Xq9aMrAWQU4oFuhSELsEYfLZGO3ntBjJLqCn+rs3FjR9N94cu63T duOAgqlXqrNbvyO1+SF9m35JXreqn/OS6KrK6c8W2IpDAWJcr89nGyyCXMoJeaOO tj8m2NjZblmCZvtAl5UMOew73GE7Z5fE+jtA2wIDAQABo2AwXjAMBgNVHRMBAf8E AjAAMA4GA1UdDwEB/wQEAwIBBjAWBgNVHSAEDzANMAsGCWCGSAFlAwEwATARBgNV HQ4ECgQIhT9GjaaHj68wEwYDVR0jBAwwCoAIq5rr+cLnVI8wDQYJKoZIhvcNAQEF BQADgYEAWhKJUujLapxpz/DoD/w48HMzkL6UQCxQPOAjwwHicX8wFcKmcrWLVBdV C30+ywrzMraWhaq+QCOqsgtxCwTZrfUxbCNqhKS0lZijCMgNN4Jht+PAZ22tzEsw 7nCwiMM2n1jeKF/3btoDEUvZn9SuzhkIyxy7Q8l2tbNOsANqpxE= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 99999 (0x1869f) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=Trust Anchor Validity Not Before: Jan 1 12:01:00 1999 GMT Not After : Jan 1 12:01:00 2048 GMT Subject: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=Trust Anchor Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public Key: (1024 bit) Modulus (1024 bit): 00:d3:f3:b9:c1:33:b7:3f:a7:27:f6:41:1d:5c:9c: 79:9d:aa:d2:95:10:b7:84:ce:da:a3:e5:58:0c:3e: 4e:8b:56:bf:3e:aa:21:2d:50:13:fe:f3:19:2e:7a: cb:11:cf:f3:d3:b8:5f:57:9f:9d:97:80:af:1d:95: 57:12:df:34:d4:bd:f3:ae:4d:e7:7c:a6:20:d4:04: 4e:da:63:61:3e:3d:2a:8d:37:cf:c5:3c:c9:f9:fa: f0:39:48:04:78:bd:b0:dd:f5:24:46:33:a1:46:9f: 17:9f:04:bb:cf:37:94:0c:13:43:aa:90:ac:91:78: 1d:ba:f3:18:84:2a:82:2b:47 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: AB:9A:EB:F9:C2:E7:54:8F X509v3 Basic Constraints: CA:TRUE X509v3 Authority Key Identifier: keyid:AB:9A:EB:F9:C2:E7:54:8F Signature Algorithm: sha1WithRSAEncryption 16:56:0f:61:ac:87:8b:4f:eb:64:12:1b:c3:85:59:4a:68:e1: 3b:a5:21:c1:59:2e:91:ac:68:fe:13:ff:63:6d:ee:55:d4:a0: 82:4c:37:bc:16:8e:a9:26:61:fe:7f:46:fa:38:1f:13:5c:8a: 6a:b7:12:47:98:72:b9:b5:56:80:ee:78:95:18:1a:f4:63:70: 26:39:9b:19:20:84:8d:bb:62:5f:df:2c:a1:3d:fc:1b:d0:3a: bb:d8:cc:1b:36:12:a2:ab:ad:3e:e6:e1:52:b4:75:13:11:ec: 27:95:a6:63:cf:d3:cc:f4:4e:d8:ba:b8:ad:ad:cc:1a:65:a7: 5a:45 -----BEGIN CERTIFICATE----- MIICbDCCAdWgAwIBAgIDAYafMA0GCSqGSIb3DQEBBQUAMF4xCzAJBgNVBAYTAlVT MRgwFgYDVQQKEw9VLlMuIEdvdmVybm1lbnQxDDAKBgNVBAsTA0RvRDEQMA4GA1UE CxMHVGVzdGluZzEVMBMGA1UEAxMMVHJ1c3QgQW5jaG9yMB4XDTk5MDEwMTEyMDEw MFoXDTQ4MDEwMTEyMDEwMFowXjELMAkGA1UEBhMCVVMxGDAWBgNVBAoTD1UuUy4g R292ZXJubWVudDEMMAoGA1UECxMDRG9EMRAwDgYDVQQLEwdUZXN0aW5nMRUwEwYD VQQDEwxUcnVzdCBBbmNob3IwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANPz ucEztz+nJ/ZBHVyceZ2q0pUQt4TO2qPlWAw+TotWvz6qIS1QE/7zGS56yxHP89O4 X1efnZeArx2VVxLfNNS9865N53ymINQETtpjYT49Ko03z8U8yfn68DlIBHi9sN31 JEYzoUafF58Eu883lAwTQ6qQrJF4HbrzGIQqgitHAgMBAAGjODA2MBEGA1UdDgQK BAirmuv5wudUjzAMBgNVHRMEBTADAQH/MBMGA1UdIwQMMAqACKua6/nC51SPMA0G CSqGSIb3DQEBBQUAA4GBABZWD2Gsh4tP62QSG8OFWUpo4TulIcFZLpGsaP4T/2Nt 7lXUoIJMN7wWjqkmYf5/Rvo4HxNcimq3EkeYcrm1VoDueJUYGvRjcCY5mxkghI27 Yl/fLKE9/BvQOrvYzBs2EqKrrT7m4VK0dRMR7CeVpmPP08z0Tti6uK2tzBplp1pF -----END CERTIFICATE-----