[ This chain should be validated. The basicConstraints in the intermediate certificate is there and the CA is set to true ] Certificate: Data: Version: 3 (0x2) Serial Number: 48 (0x30) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=U.S. Government, OU=Dod, OU=Testing, CN=CA1-IC.02.02 Validity Not Before: Jan 1 12:01:00 1998 GMT Not After : Jan 1 12:01:00 2048 GMT Subject: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=User1-IC.02.02 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public Key: (1024 bit) Modulus (1024 bit): 00:aa:20:a9:61:b1:f4:4a:49:ff:41:bb:39:1a:29: c8:84:38:21:95:d8:28:a4:c4:e3:c5:aa:38:96:ee: 9c:b0:f7:b7:11:a3:31:46:f9:5d:e7:e5:fd:0c:93: 7d:de:89:ef:9f:1d:74:6c:cf:88:ab:35:cd:63:ba: ae:27:df:24:b2:01:a0:e1:43:9a:df:2d:72:13:c1: 26:e2:0c:de:02:a0:5d:e5:5c:64:cc:85:e6:67:9b: 9b:9f:c6:65:e9:0c:3a:36:ec:f0:ff:f3:6c:b7:6b: 96:ed:43:f4:26:56:64:c5:ce:35:88:ad:76:5b:92: 83:69:a8:30:66:de:c1:2d:8d Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Key Usage: critical Digital Signature, Non Repudiation, Key Encipherment X509v3 Certificate Policies: Policy: 2.16.840.1.101.3.1.48.1 X509v3 Subject Key Identifier: 3F:C3:7B:3A:63:46:B2:11 X509v3 Authority Key Identifier: keyid:2B:1E:18:6F:3B:B6:3D:A6 Signature Algorithm: sha1WithRSAEncryption c2:4a:45:8f:a2:af:f8:e7:0a:ad:4b:4e:82:71:fd:41:d7:41: d0:48:f4:a1:4e:81:e7:fe:47:86:17:f7:96:20:0f:2a:d9:65: 0c:79:e1:52:3e:a7:a9:f8:78:00:f3:6a:fe:2a:98:14:e9:0a: 31:14:54:66:86:a3:ea:46:a4:24:d4:8e:96:0b:d1:22:24:1f: b8:52:20:bf:70:aa:2d:99:e1:af:ce:58:15:19:ca:82:89:6e: 64:4d:69:ab:74:ef:ba:7a:22:2b:22:5b:0a:36:e6:c8:2a:2c: 45:dd:f6:81:57:09:ab:4d:b8:c6:f6:36:79:50:53:97:ab:5f: 9f:90 -----BEGIN CERTIFICATE----- MIIChjCCAe+gAwIBAgIBMDANBgkqhkiG9w0BAQUFADBeMQswCQYDVQQGEwJVUzEY MBYGA1UEChMPVS5TLiBHb3Zlcm5tZW50MQwwCgYDVQQLEwNEb2QxEDAOBgNVBAsT B1Rlc3RpbmcxFTATBgNVBAMTDENBMS1JQy4wMi4wMjAeFw05ODAxMDExMjAxMDBa Fw00ODAxMDExMjAxMDBaMGAxCzAJBgNVBAYTAlVTMRgwFgYDVQQKEw9VLlMuIEdv dmVybm1lbnQxDDAKBgNVBAsTA0RvRDEQMA4GA1UECxMHVGVzdGluZzEXMBUGA1UE AxMOVXNlcjEtSUMuMDIuMDIwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKog qWGx9EpJ/0G7ORopyIQ4IZXYKKTE48WqOJbunLD3txGjMUb5Xefl/QyTfd6J758d dGzPiKs1zWO6riffJLIBoOFDmt8tchPBJuIM3gKgXeVcZMyF5mebm5/GZekMOjbs 8P/zbLdrlu1D9CZWZMXONYitdluSg2moMGbewS2NAgMBAAGjUjBQMA4GA1UdDwEB /wQEAwIF4DAWBgNVHSAEDzANMAsGCWCGSAFlAwEwATARBgNVHQ4ECgQIP8N7OmNG shEwEwYDVR0jBAwwCoAIKx4Ybzu2PaYwDQYJKoZIhvcNAQEFBQADgYEAwkpFj6Kv +OcKrUtOgnH9QddB0Ej0oU6B5/5Hhhf3liAPKtllDHnhUj6nqfh4APNq/iqYFOkK MRRUZoaj6kakJNSOlgvRIiQfuFIgv3CqLZnhr85YFRnKgoluZE1pq3TvunoiKyJb CjbmyCosRd32gVcJq024xvY2eVBTl6tfn5A= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 47 (0x2f) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=Trust Anchor Validity Not Before: Jan 1 12:01:00 1998 GMT Not After : Jan 1 12:01:00 2048 GMT Subject: C=US, O=U.S. Government, OU=Dod, OU=Testing, CN=CA1-IC.02.02 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public Key: (1024 bit) Modulus (1024 bit): 00:e8:78:0d:f6:04:fc:20:ab:ca:4b:26:84:7f:b5: b3:92:8c:7b:40:cf:a7:e6:ce:fc:c9:ae:12:4c:be: 5e:b8:71:c5:6e:23:31:b1:cc:e9:de:62:c3:bf:65: 85:b2:dd:91:ad:94:2a:0c:64:94:67:4b:cd:ed:c3: 48:a4:53:db:d0:53:00:70:ec:31:1c:7d:19:4b:29: 89:18:eb:ca:e9:db:93:75:57:92:44:8e:79:47:c3: e4:6f:b9:b7:46:92:89:d6:cd:43:49:15:b6:35:18: 0d:b8:27:79:e8:d8:66:47:88:b3:e0:5a:61:9b:d6: 3b:00:f0:08:37:d8:c5:2b:09 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:TRUE X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Certificate Policies: Policy: 2.16.840.1.101.3.1.48.1 X509v3 Subject Key Identifier: 2B:1E:18:6F:3B:B6:3D:A6 X509v3 Authority Key Identifier: keyid:AB:9A:EB:F9:C2:E7:54:8F Signature Algorithm: sha1WithRSAEncryption a2:d1:9e:34:5c:e6:92:db:dc:c6:90:91:72:9b:80:44:79:2f: d6:55:be:2d:e8:2f:6c:30:67:48:fb:c6:9e:bd:7e:0a:7f:6b: 65:cb:8b:ba:9b:bc:7b:1e:95:27:b2:96:b6:05:81:b7:37:4e: 7a:57:ab:3b:ac:ad:7d:64:3a:ee:e3:69:4c:eb:9c:d1:20:dd: 93:f7:f7:b4:26:a0:77:1e:38:2c:15:50:cb:0b:aa:fc:a8:f9: ed:9b:8d:8e:97:b8:27:c5:0f:65:20:45:14:af:8f:de:04:d7: dd:2f:e5:20:ab:03:8b:ac:63:46:7a:85:2d:24:18:19:7d:97: 88:81 -----BEGIN CERTIFICATE----- MIIClTCCAf6gAwIBAgIBLzANBgkqhkiG9w0BAQUFADBeMQswCQYDVQQGEwJVUzEY MBYGA1UEChMPVS5TLiBHb3Zlcm5tZW50MQwwCgYDVQQLEwNEb0QxEDAOBgNVBAsT B1Rlc3RpbmcxFTATBgNVBAMTDFRydXN0IEFuY2hvcjAeFw05ODAxMDExMjAxMDBa Fw00ODAxMDExMjAxMDBaMF4xCzAJBgNVBAYTAlVTMRgwFgYDVQQKEw9VLlMuIEdv dmVybm1lbnQxDDAKBgNVBAsTA0RvZDEQMA4GA1UECxMHVGVzdGluZzEVMBMGA1UE AxMMQ0ExLUlDLjAyLjAyMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoeA32 BPwgq8pLJoR/tbOSjHtAz6fmzvzJrhJMvl64ccVuIzGxzOneYsO/ZYWy3ZGtlCoM ZJRnS83tw0ikU9vQUwBw7DEcfRlLKYkY68rp25N1V5JEjnlHw+RvubdGkonWzUNJ FbY1GA24J3no2GZHiLPgWmGb1jsA8Ag32MUrCQIDAQABo2MwYTAPBgNVHRMBAf8E BTADAQH/MA4GA1UdDwEB/wQEAwIBBjAWBgNVHSAEDzANMAsGCWCGSAFlAwEwATAR BgNVHQ4ECgQIKx4Ybzu2PaYwEwYDVR0jBAwwCoAIq5rr+cLnVI8wDQYJKoZIhvcN AQEFBQADgYEAotGeNFzmktvcxpCRcpuARHkv1lW+LegvbDBnSPvGnr1+Cn9rZcuL upu8ex6VJ7KWtgWBtzdOelerO6ytfWQ67uNpTOuc0SDdk/f3tCagdx44LBVQywuq /Kj57ZuNjpe4J8UPZSBFFK+P3gTX3S/lIKsDi6xjRnqFLSQYGX2XiIE= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 99999 (0x1869f) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=Trust Anchor Validity Not Before: Jan 1 12:01:00 1999 GMT Not After : Jan 1 12:01:00 2048 GMT Subject: C=US, O=U.S. Government, OU=DoD, OU=Testing, CN=Trust Anchor Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public Key: (1024 bit) Modulus (1024 bit): 00:d3:f3:b9:c1:33:b7:3f:a7:27:f6:41:1d:5c:9c: 79:9d:aa:d2:95:10:b7:84:ce:da:a3:e5:58:0c:3e: 4e:8b:56:bf:3e:aa:21:2d:50:13:fe:f3:19:2e:7a: cb:11:cf:f3:d3:b8:5f:57:9f:9d:97:80:af:1d:95: 57:12:df:34:d4:bd:f3:ae:4d:e7:7c:a6:20:d4:04: 4e:da:63:61:3e:3d:2a:8d:37:cf:c5:3c:c9:f9:fa: f0:39:48:04:78:bd:b0:dd:f5:24:46:33:a1:46:9f: 17:9f:04:bb:cf:37:94:0c:13:43:aa:90:ac:91:78: 1d:ba:f3:18:84:2a:82:2b:47 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: AB:9A:EB:F9:C2:E7:54:8F X509v3 Basic Constraints: CA:TRUE X509v3 Authority Key Identifier: keyid:AB:9A:EB:F9:C2:E7:54:8F Signature Algorithm: sha1WithRSAEncryption 16:56:0f:61:ac:87:8b:4f:eb:64:12:1b:c3:85:59:4a:68:e1: 3b:a5:21:c1:59:2e:91:ac:68:fe:13:ff:63:6d:ee:55:d4:a0: 82:4c:37:bc:16:8e:a9:26:61:fe:7f:46:fa:38:1f:13:5c:8a: 6a:b7:12:47:98:72:b9:b5:56:80:ee:78:95:18:1a:f4:63:70: 26:39:9b:19:20:84:8d:bb:62:5f:df:2c:a1:3d:fc:1b:d0:3a: bb:d8:cc:1b:36:12:a2:ab:ad:3e:e6:e1:52:b4:75:13:11:ec: 27:95:a6:63:cf:d3:cc:f4:4e:d8:ba:b8:ad:ad:cc:1a:65:a7: 5a:45 -----BEGIN CERTIFICATE----- MIICbDCCAdWgAwIBAgIDAYafMA0GCSqGSIb3DQEBBQUAMF4xCzAJBgNVBAYTAlVT MRgwFgYDVQQKEw9VLlMuIEdvdmVybm1lbnQxDDAKBgNVBAsTA0RvRDEQMA4GA1UE CxMHVGVzdGluZzEVMBMGA1UEAxMMVHJ1c3QgQW5jaG9yMB4XDTk5MDEwMTEyMDEw MFoXDTQ4MDEwMTEyMDEwMFowXjELMAkGA1UEBhMCVVMxGDAWBgNVBAoTD1UuUy4g R292ZXJubWVudDEMMAoGA1UECxMDRG9EMRAwDgYDVQQLEwdUZXN0aW5nMRUwEwYD VQQDEwxUcnVzdCBBbmNob3IwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANPz ucEztz+nJ/ZBHVyceZ2q0pUQt4TO2qPlWAw+TotWvz6qIS1QE/7zGS56yxHP89O4 X1efnZeArx2VVxLfNNS9865N53ymINQETtpjYT49Ko03z8U8yfn68DlIBHi9sN31 JEYzoUafF58Eu883lAwTQ6qQrJF4HbrzGIQqgitHAgMBAAGjODA2MBEGA1UdDgQK BAirmuv5wudUjzAMBgNVHRMEBTADAQH/MBMGA1UdIwQMMAqACKua6/nC51SPMA0G CSqGSIb3DQEBBQUAA4GBABZWD2Gsh4tP62QSG8OFWUpo4TulIcFZLpGsaP4T/2Nt 7lXUoIJMN7wWjqkmYf5/Rvo4HxNcimq3EkeYcrm1VoDueJUYGvRjcCY5mxkghI27 Yl/fLKE9/BvQOrvYzBs2EqKrrT7m4VK0dRMR7CeVpmPP08z0Tti6uK2tzBplp1pF -----END CERTIFICATE-----