Directory "tmp-jtreg-CAInterop.java_globalsigne46/index-10800" not found: creating -------------------------------------------------- TEST: security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#globalsigne46 TEST JDK: /home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk ACTION: build -- Passed. Build successful REASON: User specified action: run build jtreg.SkippedException ValidatePathWithURL CAInterop TIME: 4.117 seconds messages: command: build jtreg.SkippedException ValidatePathWithURL CAInterop reason: User specified action: run build jtreg.SkippedException ValidatePathWithURL CAInterop started: Sat May 18 18:06:33 CST 2024 Library /test/lib: compile: jtreg.SkippedException Test directory: compile: ValidatePathWithURL, CAInterop finished: Sat May 18 18:06:37 CST 2024 elapsed time (seconds): 4.117 ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 1.614 seconds messages: command: compile /home/yansendao/git/jdk/test/lib/jtreg/SkippedException.java reason: .class file out of date or does not exist started: Sat May 18 18:06:33 CST 2024 Mode: othervm finished: Sat May 18 18:06:34 CST 2024 elapsed time (seconds): 1.614 configuration: javac compilation environment source path: /home/yansendao/git/jdk/test/lib class path: /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib rerun: cd /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/scratch && \ DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \ DISPLAY=:7 \ HOME=/home/yansendao \ LANG=en_US.UTF-8 \ PATH=/bin:/usr/bin:/usr/sbin \ XDG_RUNTIME_DIR=/run/user/995 \ XDG_SESSION_ID=282 \ /home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk/bin/javac \ -J-ea \ -J-esa \ -J-Dtest.vm.opts='-ea -esa' \ -J-Dtest.tool.vm.opts='-J-ea -J-esa' \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -J-Dcompile.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -J-Dtest.timeout.factor=4.0 \ -J-Dtest.root=/home/yansendao/git/jdk/test/jdk \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#globalsigne46 \ -J-Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \ -J-Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -J-Dtest.classes=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d \ -J-Dtest.class.path=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib \ -d /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib \ -sourcepath /home/yansendao/git/jdk/test/lib \ -classpath /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib /home/yansendao/git/jdk/test/lib/jtreg/SkippedException.java STDOUT: STDERR: ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 2.497 seconds messages: command: compile /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java reason: .class file out of date or does not exist started: Sat May 18 18:06:34 CST 2024 Mode: othervm finished: Sat May 18 18:06:37 CST 2024 elapsed time (seconds): 2.497 configuration: javac compilation environment source path: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification /home/yansendao/git/jdk/test/lib class path: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib rerun: cd /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/scratch && \ DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \ DISPLAY=:7 \ HOME=/home/yansendao \ LANG=en_US.UTF-8 \ PATH=/bin:/usr/bin:/usr/sbin \ XDG_RUNTIME_DIR=/run/user/995 \ XDG_SESSION_ID=282 \ /home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk/bin/javac \ -J-ea \ -J-esa \ -J-Dtest.vm.opts='-ea -esa' \ -J-Dtest.tool.vm.opts='-J-ea -J-esa' \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -J-Dcompile.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -J-Dtest.timeout.factor=4.0 \ -J-Dtest.root=/home/yansendao/git/jdk/test/jdk \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#globalsigne46 \ -J-Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \ -J-Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -J-Dtest.classes=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d \ -J-Dtest.class.path=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib \ -d /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d \ -sourcepath /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -classpath /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java STDOUT: STDERR: Note: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java uses or overrides a deprecated API. Note: Recompile with -Xlint:deprecation for details. ACTION: build -- Passed. All files up to date REASON: Named class compiled on demand TIME: 0.0 seconds messages: command: build CAInterop reason: Named class compiled on demand started: Sat May 18 18:06:37 CST 2024 finished: Sat May 18 18:06:37 CST 2024 elapsed time (seconds): 0.0 ACTION: main -- Passed. Execution successful REASON: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp CAInterop globalsigne46 OCSP TIME: 3.262 seconds messages: command: main -Djava.security.debug=certpath,ocsp CAInterop globalsigne46 OCSP reason: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp CAInterop globalsigne46 OCSP started: Sat May 18 18:06:37 CST 2024 Mode: othervm [/othervm specified] finished: Sat May 18 18:06:40 CST 2024 elapsed time (seconds): 3.262 configuration: STDOUT: ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, SHA1 usage SignedJAR & denyAfter 2019-01-01 com.sun.security.enableCRLDP :false ocsp.enable :true ===================================================== ===== Validate https://valid.e46.roots.globalsign.com===== Finding intermediate certificate issued by CA Checking: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Checking: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Found intermediate root CA: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE intermediate CA Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Verified: Intermediate CA signed by test root CA ======> SUCCESS ===== Validate https://revoked.e46.roots.globalsign.com===== SSLHandshakeException: (certificate_revoked) PKIX path validation failed: java.security.cert.CertPathValidatorException: Certificate has been revoked, reason: UNSPECIFIED, revocation date: Mon Oct 23 20:29:02 CST 2023, authority: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4 - OCSP Responder, O=GlobalSign nv-sa, C=BE, extension OIDs: [] Certificate is revoked Finding intermediate certificate issued by CA Checking: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=revoked.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Checking: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Found intermediate root CA: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE intermediate CA Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Verified: Intermediate CA signed by test root CA ======> SUCCESS STDERR: certpath: Constraints: 3DES_EDE_CBC certpath: Constraints: anon certpath: Constraints: DES certpath: Constraints: DH keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: DTLSv1.0 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: ECDH certpath: Constraints: MD5withRSA certpath: Constraints: NULL certpath: Constraints: RC4 certpath: Constraints: SSLv3 certpath: Constraints: TLSv1 certpath: Constraints: TLSv1.1 certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01 certpath: Constraints usage length is 1 certpath: Constraints set to denyAfter certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1 certpath: DenyAfterConstraint date set to: 2019-01-01 certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 0c:be Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01 certpath: Constraints usage length is 1 certpath: Constraints set to denyAfter certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1 certpath: DenyAfterConstraint date set to: 2019-01-01 certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC Date: Sat May 18 18:06:39 CST 2024 ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Key: EC Date: Sat May 18 18:06:39 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.10.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Sat May 18 18:06:39 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE; subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE; serial#: 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE certpath: com.sun.security.ocsp.timeout set to 15000 milliseconds certpath: com.sun.security.ocsp.readtimeout set to 15000 milliseconds certpath: com.sun.security.ocsp.useget set to true certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 DE 1D 43 C4 7A F5 F1 BC 86 .........C.z.... 0020: AB 36 43 7E 02 17 03 F8 9C CF 5C 04 14 31 0A 90 .6C.......\..1.. 0030: 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 12 4F 1B .....DK.......O. 0040: 95 02 10 7F 1F 2C 88 FD 17 29 03 A3 20 2B 07 62 .....,...).. +.b 0050: D9 76 9C certpath: connecting to OCSP service at: http://ocsp.globalsign.com/roote46 certpath: OCSPResponse bytes... 0000: 30 82 04 F1 0A 01 00 A0 82 04 EA 30 82 04 E6 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 04 D7 30 82 .+.....0......0. 0020: 04 D3 30 81 9E A2 16 04 14 43 C5 86 1F 37 F3 52 ..0......C...7.R 0030: 2A CC 49 A4 15 FE 55 B4 34 DD 8D 3D EF 18 0F 32 *.I...U.4..=...2 0040: 30 32 34 30 35 31 38 30 38 34 30 35 32 5A 30 73 0240518084052Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 DE 1D 43 C4 7A F5 F1 BC 86 AB 36 43 7E 02 17 ...C.z.....6C... 0070: 03 F8 9C CF 5C 04 14 31 0A 90 8F B6 C6 9D D2 44 ....\..1.......D 0080: 4B 80 B5 A2 E6 1F B1 12 4F 1B 95 02 10 7F 1F 2C K.......O......, 0090: 88 FD 17 29 03 A3 20 2B 07 62 D9 76 9C 80 00 18 ...).. +.b.v.... 00A0: 0F 32 30 32 34 30 35 31 38 30 38 34 30 35 32 5A .20240518084052Z 00B0: A0 11 18 0F 32 30 32 34 30 35 32 32 30 38 34 30 ....202405220840 00C0: 35 31 5A 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0B 51Z0...*.H...... 00D0: 05 00 03 82 01 01 00 72 F2 98 5F 0A A6 89 5E F9 .......r.._...^. 00E0: C6 76 15 8D 37 AA 9A 37 80 E5 3E 9F DE BD 34 10 .v..7..7..>...4. 00F0: 26 AD 50 75 B5 AC 24 C2 25 12 DB 01 86 D4 5F B1 &.Pu..$.%....._. 0100: 7F 32 2C 7B 53 B9 8D A1 79 A4 F8 5B 53 8B 94 9B .2,.S...y..[S... 0110: 70 49 62 93 9E 2A 5D 6A 99 79 19 DC C2 6A 03 A0 pIb..*]j.y...j.. 0120: 24 DC C7 31 17 46 AA 7D 42 25 05 F3 A1 9A A4 CC $..1.F..B%...... 0130: 0B 4E D7 F3 6A CA 16 0F AD 84 B3 03 5B 92 6C 26 .N..j.......[.l& 0140: 77 8A C8 54 36 89 EF 38 95 90 08 91 D3 07 D6 2A w..T6..8.......* 0150: 22 4A C3 8D AD 3E DA 28 18 AF 78 B2 83 99 11 8D "J...>.(..x..... 0160: BC 7E 72 3A 90 5A 94 29 36 9E 46 47 6A 17 AA 3C ..r:.Z.)6.FGj..< 0170: 13 E5 AB B3 4A 36 1C 1B 57 6A 4D EF 7F A8 F1 A4 ....J6..WjM..... 0180: B9 28 3E 0A BF A2 79 C3 F2 91 47 C1 77 B3 D2 E6 .(>...y...G.w... 0190: 5B 54 38 59 07 78 5E 6C 64 FC 18 D2 33 36 EB 0E [T8Y.x^ld...36.. 01A0: D4 0A 13 D0 51 20 AD 0C C8 BE BE 86 26 19 88 DE ....Q ......&... 01B0: D1 62 36 AB A5 A0 0A 5A D3 D9 7F 34 54 B2 EC 3A .b6....Z...4T..: 01C0: 97 07 19 82 54 4F 4E F5 67 CB D2 7E 84 3E 83 E9 ....TON.g....>.. 01D0: 7A 9B BF 63 8D 8C 0E A0 82 03 1A 30 82 03 16 30 z..c.......0...0 01E0: 82 03 12 30 82 02 98 A0 03 02 01 02 02 11 00 80 ...0............ 01F0: 4E 02 61 EA D7 14 3F BB D7 C1 F9 97 3D FC 92 30 N.a...?.....=..0 0200: 0A 06 08 2A 86 48 CE 3D 04 03 03 30 46 31 0B 30 ...*.H.=...0F1.0 0210: 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 ...U....BE1.0... 0220: 55 04 0A 13 10 47 6C 6F 62 61 6C 53 69 67 6E 20 U....GlobalSign 0230: 6E 76 2D 73 61 31 1C 30 1A 06 03 55 04 03 13 13 nv-sa1.0...U.... 0240: 47 6C 6F 62 61 6C 53 69 67 6E 20 52 6F 6F 74 20 GlobalSign Root 0250: 45 34 36 30 1E 17 0D 32 34 30 31 31 37 30 33 33 E460...240117033 0260: 31 34 39 5A 17 0D 32 34 30 38 31 35 30 30 30 30 149Z..2408150000 0270: 30 30 5A 30 5A 31 0B 30 09 06 03 55 04 06 13 02 00Z0Z1.0...U.... 0280: 42 45 31 19 30 17 06 03 55 04 0A 13 10 47 6C 6F BE1.0...U....Glo 0290: 62 61 6C 53 69 67 6E 20 6E 76 2D 73 61 31 30 30 balSign nv-sa100 02A0: 2E 06 03 55 04 03 13 27 47 6C 6F 62 61 6C 53 69 ...U...'GlobalSi 02B0: 67 6E 20 52 6F 6F 74 20 45 34 36 20 2D 20 4F 43 gn Root E46 - OC 02C0: 53 50 20 31 2E 32 20 32 30 32 34 30 35 30 37 30 SP 1.2 202405070 02D0: 82 01 22 30 0D 06 09 2A 86 48 86 F7 0D 01 01 01 .."0...*.H...... 02E0: 05 00 03 82 01 0F 00 30 82 01 0A 02 82 01 01 00 .......0........ 02F0: 94 E6 7A 6D DF 9F 17 54 B6 D4 7F CC 95 DF AD 3E ..zm...T.......> 0300: AC 8E 43 2C EB C2 9E ED 9B 9B 1C E2 63 2F FE E3 ..C,........c/.. 0310: E1 76 D8 5E 29 55 D0 0B D3 DF 30 6A 1A A2 34 3E .v.^)U....0j..4> 0320: B6 97 9B F5 33 8F EF E2 8F 4D 41 95 C1 52 B8 19 ....3....MA..R.. 0330: 0D D9 2A F6 C6 BC 51 E0 69 82 8F 1B C0 7F D4 41 ..*...Q.i......A 0340: 66 D7 75 13 86 17 D6 7E 60 1B D1 61 FC E9 08 0B f.u.....`..a.... 0350: 85 22 30 EE FC 82 11 86 5F CB 30 A2 DC 7D B7 DB ."0....._.0..... 0360: 6F AB 96 DE 23 10 4D E2 98 2C 08 EE AE 7C 1E 23 o...#.M..,.....# 0370: 2F D4 B8 10 35 70 F7 97 AE 89 FA 9F 8E 07 E1 AD /...5p.......... 0380: FA A1 3A 94 09 2E 5C 66 23 44 36 60 A2 1A EA 9B ..:...\f#D6`.... 0390: 91 92 DA F6 07 C6 89 40 ED E2 C9 E0 71 F3 D6 91 .......@....q... 03A0: 2E 54 8C CC 21 0A 48 FF 06 5A 76 02 95 61 75 27 .T..!.H..Zv..au' 03B0: A4 B0 80 EC 69 0B 85 BE 35 02 AB C6 F5 27 76 A4 ....i...5....'v. 03C0: 76 E8 B1 BC F1 D4 49 61 89 AC 91 EB 1C 2E 23 09 v.....Ia......#. 03D0: C8 68 15 7D E5 64 BB BE 4E 02 4E 08 F5 44 AB 65 .h...d..N.N..D.e 03E0: A7 67 E2 40 D7 4A CB 32 3E A8 2B E6 19 BA A0 83 .g.@.J.2>.+..... 03F0: 02 03 01 00 01 A3 81 87 30 81 84 30 0E 06 03 55 ........0..0...U 0400: 1D 0F 01 01 FF 04 04 03 02 07 80 30 13 06 03 55 ...........0...U 0410: 1D 25 04 0C 30 0A 06 08 2B 06 01 05 05 07 03 09 .%..0...+....... 0420: 30 0C 06 03 55 1D 13 01 01 FF 04 02 30 00 30 1D 0...U.......0.0. 0430: 06 03 55 1D 0E 04 16 04 14 43 C5 86 1F 37 F3 52 ..U......C...7.R 0440: 2A CC 49 A4 15 FE 55 B4 34 DD 8D 3D EF 30 1F 06 *.I...U.4..=.0.. 0450: 03 55 1D 23 04 18 30 16 80 14 31 0A 90 8F B6 C6 .U.#..0...1..... 0460: 9D D2 44 4B 80 B5 A2 E6 1F B1 12 4F 1B 95 30 0F ..DK.......O..0. 0470: 06 09 2B 06 01 05 05 07 30 01 05 04 02 05 00 30 ..+.....0......0 0480: 0A 06 08 2A 86 48 CE 3D 04 03 03 03 68 00 30 65 ...*.H.=....h.0e 0490: 02 31 00 93 B6 DE DA 9D 04 5D CE C7 AD CB D5 7C .1.......]...... 04A0: 60 6F 30 C1 B5 18 6B 6E 6D 21 28 65 E1 D1 3B 95 `o0...knm!(e..;. 04B0: C7 EA 60 92 07 F9 3B C6 4F DE 66 6A CF F2 B9 0B ..`...;.O.fj.... 04C0: 0A 96 B3 02 30 4B 14 DA 07 02 BE D7 1B 28 02 70 ....0K.......(.p 04D0: 4D 81 EE C4 B4 E3 D3 32 1A 53 44 2C B6 71 E2 9D M......2.SD,.q.. 04E0: 0C 45 A7 DF 5A 63 4E 87 D0 41 4A 88 62 CC 70 5A .E..ZcN..AJ.b.pZ 04F0: 77 9B 24 86 4C certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 43C5861F37F3522ACC49A415FE55B434DD8D3DEF certpath: OCSP response produced at: Sat May 18 16:40:52 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sat May 18 16:40:52 CST 2024 certpath: nextUpdate: Wed May 22 16:40:51 CST 2024 certpath: OCSP response cert #1: CN=GlobalSign Root E46 - OCSP 1.2 20240507, O=GlobalSign nv-sa, C=BE certpath: Status of certificate (with serial number 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c) is: GOOD certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Root E46 - OCSP 1.2 20240507, O=GlobalSign nv-sa, C=BE Key: RSA ] certpath: Responder's certificate includes the extension id-pkix-ocsp-nocheck. certpath: OCSP response is signed by an Authorized Responder certpath: Constraints.permits(): SHA256withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sat May 18 16:40:52 CST 2024 until Wed May 22 16:40:51 CST 2024 certpath: Checking validity of OCSP response on Sat May 18 18:06:39 CST 2024 with allowed interval between Sat May 18 17:51:39 CST 2024 and Sat May 18 18:21:39 CST 2024 certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: KeySizeConstraints.permits(): EC certpath: -checker8 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Cert Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Key: EC Date: Sat May 18 18:06:39 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.10.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (2) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Sat May 18 18:06:39 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE; subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB; serial#: 01:c7:71:fd:da:a6:99:85:e4:b6:61:75:f2:65:c5:8a certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 01:c7:71:fd:da:a6:99:85:e4:b6:61:75:f2:65:c5:8a Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 06 C6 A3 12 8E E7 80 BF 64 ...............d 0020: AC 73 89 54 16 FA EB C8 B1 6A AA 04 14 5E C4 F2 .s.T.....j...^.. 0030: F2 F8 D0 CF 0D 79 A3 4F 69 21 F1 41 71 7D 53 65 .....y.Oi!.Aq.Se 0040: 60 02 10 01 C7 71 FD DA A6 99 85 E4 B6 61 75 F2 `....q.......au. 0050: 65 C5 8A certpath: connecting to OCSP service at: http://ocsp.globalsign.com/ca/gsatlase46evtlsca2023q4 certpath: OCSPResponse bytes... 0000: 30 82 03 8A 0A 01 00 A0 82 03 83 30 82 03 7F 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 03 70 30 82 .+.....0.....p0. 0020: 03 6C 30 81 9E A2 16 04 14 33 A9 AB 48 EC B6 BD .l0......3..H... 0030: 0E 42 CF EF CE FB A2 AE D1 7C C3 07 79 18 0F 32 .B..........y..2 0040: 30 32 34 30 35 31 38 30 39 34 30 30 30 5A 30 73 0240518094000Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 06 C6 A3 12 8E E7 80 BF 64 AC 73 89 54 16 FA .........d.s.T.. 0070: EB C8 B1 6A AA 04 14 5E C4 F2 F2 F8 D0 CF 0D 79 ...j...^.......y 0080: A3 4F 69 21 F1 41 71 7D 53 65 60 02 10 01 C7 71 .Oi!.Aq.Se`....q 0090: FD DA A6 99 85 E4 B6 61 75 F2 65 C5 8A 80 00 18 .......au.e..... 00A0: 0F 32 30 32 34 30 35 31 38 30 39 30 30 30 30 5A .20240518090000Z 00B0: A0 11 18 0F 32 30 32 34 30 35 31 38 32 31 30 30 ....202405182100 00C0: 30 30 5A 30 0A 06 08 2A 86 48 CE 3D 04 03 02 03 00Z0...*.H.=.... 00D0: 48 00 30 45 02 21 00 E8 E1 8E 24 C2 22 98 2C 6A H.0E.!....$.".,j 00E0: F7 DD F5 F0 B3 1D E5 3D 3A DE EF 6A A9 DA C7 85 .......=:..j.... 00F0: 64 42 13 98 8E 2E 0F 02 20 1F 09 33 F4 58 0A 52 dB...... ..3.X.R 0100: 96 85 5B F0 3F 37 6A 44 33 D3 4E C7 C3 26 BF EC ..[.?7jD3.N..&.. 0110: E5 F2 8C 8A C3 A3 E6 0F 42 A0 82 02 71 30 82 02 ........B...q0.. 0120: 6D 30 82 02 69 30 82 01 EF A0 03 02 01 02 02 10 m0..i0.......... 0130: 01 9A C4 75 15 74 A6 35 76 E5 EF F1 E6 12 4A 04 ...u.t.5v.....J. 0140: 30 0A 06 08 2A 86 48 CE 3D 04 03 03 30 59 31 0B 0...*.H.=...0Y1. 0150: 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 0...U....BE1.0.. 0160: 03 55 04 0A 13 10 47 6C 6F 62 61 6C 53 69 67 6E .U....GlobalSign 0170: 20 6E 76 2D 73 61 31 2F 30 2D 06 03 55 04 03 13 nv-sa1/0-..U... 0180: 26 47 6C 6F 62 61 6C 53 69 67 6E 20 41 74 6C 61 &GlobalSign Atla 0190: 73 20 45 34 36 20 45 56 20 54 4C 53 20 43 41 20 s E46 EV TLS CA 01A0: 32 30 32 33 20 51 34 30 1E 17 0D 32 34 30 35 31 2023 Q40...24051 01B0: 38 30 35 32 35 35 36 5A 17 0D 32 34 30 35 32 35 8052556Z..240525 01C0: 30 35 32 35 35 36 5A 30 6A 31 0B 30 09 06 03 55 052556Z0j1.0...U 01D0: 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0A 0C ....BE1.0...U... 01E0: 10 47 6C 6F 62 61 6C 53 69 67 6E 20 6E 76 2D 73 .GlobalSign nv-s 01F0: 61 31 40 30 3E 06 03 55 04 03 0C 37 47 6C 6F 62 a1@0>..U...7Glob 0200: 61 6C 53 69 67 6E 20 41 74 6C 61 73 20 45 34 36 alSign Atlas E46 0210: 20 45 56 20 54 4C 53 20 43 41 20 32 30 32 33 20 EV TLS CA 2023 0220: 51 34 20 2D 20 4F 43 53 50 20 52 65 73 70 6F 6E Q4 - OCSP Respon 0230: 64 65 72 30 59 30 13 06 07 2A 86 48 CE 3D 02 01 der0Y0...*.H.=.. 0240: 06 08 2A 86 48 CE 3D 03 01 07 03 42 00 04 62 15 ..*.H.=....B..b. 0250: 07 7C 96 DF 4F D5 E4 79 67 4B 54 18 6D 72 9C 11 ....O..ygKT.mr.. 0260: 77 73 02 A0 62 A0 30 32 CA B3 8E 20 23 1A 37 05 ws..b.02... #.7. 0270: 36 0B 16 97 C5 58 63 C7 38 85 CE 75 D0 F6 E4 6A 6....Xc.8..u...j 0280: 52 9D 62 B2 CC BC 93 F8 86 36 8A 93 BE B8 A3 81 R.b......6...... 0290: 87 30 81 84 30 0F 06 09 2B 06 01 05 05 07 30 01 .0..0...+.....0. 02A0: 05 04 02 05 00 30 0E 06 03 55 1D 0F 01 01 FF 04 .....0...U...... 02B0: 04 03 02 07 80 30 13 06 03 55 1D 25 04 0C 30 0A .....0...U.%..0. 02C0: 06 08 2B 06 01 05 05 07 03 09 30 1D 06 03 55 1D ..+.......0...U. 02D0: 0E 04 16 04 14 33 A9 AB 48 EC B6 BD 0E 42 CF EF .....3..H....B.. 02E0: CE FB A2 AE D1 7C C3 07 79 30 0C 06 03 55 1D 13 ........y0...U.. 02F0: 01 01 FF 04 02 30 00 30 1F 06 03 55 1D 23 04 18 .....0.0...U.#.. 0300: 30 16 80 14 5E C4 F2 F2 F8 D0 CF 0D 79 A3 4F 69 0...^.......y.Oi 0310: 21 F1 41 71 7D 53 65 60 30 0A 06 08 2A 86 48 CE !.Aq.Se`0...*.H. 0320: 3D 04 03 03 03 68 00 30 65 02 31 00 EC CA 11 E7 =....h.0e.1..... 0330: 1E 45 E6 AB 29 6D 47 01 04 B5 8A 8A 38 D9 1E 4A .E..)mG.....8..J 0340: 03 01 C7 CA 81 A3 AD F6 4E 0A 21 84 6D 6C C2 3C ........N.!.ml.< 0350: D0 80 D8 E2 A7 C6 2B BC 17 93 07 D6 02 30 3D 7E ......+......0=. 0360: 6E DD DC D0 57 85 13 44 A6 E7 58 D4 CE ED BD 03 n...W..D..X..... 0370: 9B 2C 0F BD 9A EE DE C0 2D A5 F2 B5 03 37 B4 62 .,......-....7.b 0380: 17 6E 4E 99 D7 BA 6A 22 93 61 71 D0 D5 D2 certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 33A9AB48ECB6BD0E42CFEFCEFBA2AED17CC30779 certpath: OCSP response produced at: Sat May 18 17:40:00 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sat May 18 17:00:00 CST 2024 certpath: nextUpdate: Sun May 19 05:00:00 CST 2024 certpath: OCSP response cert #1: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4 - OCSP Responder, O=GlobalSign nv-sa, C=BE certpath: Status of certificate (with serial number 01:c7:71:fd:da:a6:99:85:e4:b6:61:75:f2:65:c5:8a) is: GOOD certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4 - OCSP Responder, O=GlobalSign nv-sa, C=BE Key: EC ] certpath: Responder's certificate includes the extension id-pkix-ocsp-nocheck. certpath: OCSP response is signed by an Authorized Responder certpath: Constraints.permits(): SHA256withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sat May 18 17:00:00 CST 2024 until Sun May 19 05:00:00 CST 2024 certpath: Checking validity of OCSP response on Sat May 18 18:06:39 CST 2024 with allowed interval between Sat May 18 17:51:39 CST 2024 and Sat May 18 18:21:39 CST 2024 certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: KeySizeConstraints.permits(): EC certpath: KeySizeConstraints.permits(): EC certpath: -checker8 validation succeeded certpath: cert2 validation succeeded. certpath: Cert path validation succeeded. (PKIX validation algorithm) certpath: -------------------------------------------------------------- certpath: KeySizeConstraints.permits(): EC certpath: KeySizeConstraints.permits(): EC certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 0c:be Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC Date: Sat May 18 18:06:40 CST 2024 ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Key: EC Date: Sat May 18 18:06:40 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.10.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Sat May 18 18:06:40 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE; subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE; serial#: 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 DE 1D 43 C4 7A F5 F1 BC 86 .........C.z.... 0020: AB 36 43 7E 02 17 03 F8 9C CF 5C 04 14 31 0A 90 .6C.......\..1.. 0030: 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 12 4F 1B .....DK.......O. 0040: 95 02 10 7F 1F 2C 88 FD 17 29 03 A3 20 2B 07 62 .....,...).. +.b 0050: D9 76 9C certpath: connecting to OCSP service at: http://ocsp.globalsign.com/roote46 certpath: OCSPResponse bytes... 0000: 30 82 04 F1 0A 01 00 A0 82 04 EA 30 82 04 E6 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 04 D7 30 82 .+.....0......0. 0020: 04 D3 30 81 9E A2 16 04 14 43 C5 86 1F 37 F3 52 ..0......C...7.R 0030: 2A CC 49 A4 15 FE 55 B4 34 DD 8D 3D EF 18 0F 32 *.I...U.4..=...2 0040: 30 32 34 30 35 31 38 30 38 34 30 35 32 5A 30 73 0240518084052Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 DE 1D 43 C4 7A F5 F1 BC 86 AB 36 43 7E 02 17 ...C.z.....6C... 0070: 03 F8 9C CF 5C 04 14 31 0A 90 8F B6 C6 9D D2 44 ....\..1.......D 0080: 4B 80 B5 A2 E6 1F B1 12 4F 1B 95 02 10 7F 1F 2C K.......O......, 0090: 88 FD 17 29 03 A3 20 2B 07 62 D9 76 9C 80 00 18 ...).. +.b.v.... 00A0: 0F 32 30 32 34 30 35 31 38 30 38 34 30 35 32 5A .20240518084052Z 00B0: A0 11 18 0F 32 30 32 34 30 35 32 32 30 38 34 30 ....202405220840 00C0: 35 31 5A 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0B 51Z0...*.H...... 00D0: 05 00 03 82 01 01 00 72 F2 98 5F 0A A6 89 5E F9 .......r.._...^. 00E0: C6 76 15 8D 37 AA 9A 37 80 E5 3E 9F DE BD 34 10 .v..7..7..>...4. 00F0: 26 AD 50 75 B5 AC 24 C2 25 12 DB 01 86 D4 5F B1 &.Pu..$.%....._. 0100: 7F 32 2C 7B 53 B9 8D A1 79 A4 F8 5B 53 8B 94 9B .2,.S...y..[S... 0110: 70 49 62 93 9E 2A 5D 6A 99 79 19 DC C2 6A 03 A0 pIb..*]j.y...j.. 0120: 24 DC C7 31 17 46 AA 7D 42 25 05 F3 A1 9A A4 CC $..1.F..B%...... 0130: 0B 4E D7 F3 6A CA 16 0F AD 84 B3 03 5B 92 6C 26 .N..j.......[.l& 0140: 77 8A C8 54 36 89 EF 38 95 90 08 91 D3 07 D6 2A w..T6..8.......* 0150: 22 4A C3 8D AD 3E DA 28 18 AF 78 B2 83 99 11 8D "J...>.(..x..... 0160: BC 7E 72 3A 90 5A 94 29 36 9E 46 47 6A 17 AA 3C ..r:.Z.)6.FGj..< 0170: 13 E5 AB B3 4A 36 1C 1B 57 6A 4D EF 7F A8 F1 A4 ....J6..WjM..... 0180: B9 28 3E 0A BF A2 79 C3 F2 91 47 C1 77 B3 D2 E6 .(>...y...G.w... 0190: 5B 54 38 59 07 78 5E 6C 64 FC 18 D2 33 36 EB 0E [T8Y.x^ld...36.. 01A0: D4 0A 13 D0 51 20 AD 0C C8 BE BE 86 26 19 88 DE ....Q ......&... 01B0: D1 62 36 AB A5 A0 0A 5A D3 D9 7F 34 54 B2 EC 3A .b6....Z...4T..: 01C0: 97 07 19 82 54 4F 4E F5 67 CB D2 7E 84 3E 83 E9 ....TON.g....>.. 01D0: 7A 9B BF 63 8D 8C 0E A0 82 03 1A 30 82 03 16 30 z..c.......0...0 01E0: 82 03 12 30 82 02 98 A0 03 02 01 02 02 11 00 80 ...0............ 01F0: 4E 02 61 EA D7 14 3F BB D7 C1 F9 97 3D FC 92 30 N.a...?.....=..0 0200: 0A 06 08 2A 86 48 CE 3D 04 03 03 30 46 31 0B 30 ...*.H.=...0F1.0 0210: 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 ...U....BE1.0... 0220: 55 04 0A 13 10 47 6C 6F 62 61 6C 53 69 67 6E 20 U....GlobalSign 0230: 6E 76 2D 73 61 31 1C 30 1A 06 03 55 04 03 13 13 nv-sa1.0...U.... 0240: 47 6C 6F 62 61 6C 53 69 67 6E 20 52 6F 6F 74 20 GlobalSign Root 0250: 45 34 36 30 1E 17 0D 32 34 30 31 31 37 30 33 33 E460...240117033 0260: 31 34 39 5A 17 0D 32 34 30 38 31 35 30 30 30 30 149Z..2408150000 0270: 30 30 5A 30 5A 31 0B 30 09 06 03 55 04 06 13 02 00Z0Z1.0...U.... 0280: 42 45 31 19 30 17 06 03 55 04 0A 13 10 47 6C 6F BE1.0...U....Glo 0290: 62 61 6C 53 69 67 6E 20 6E 76 2D 73 61 31 30 30 balSign nv-sa100 02A0: 2E 06 03 55 04 03 13 27 47 6C 6F 62 61 6C 53 69 ...U...'GlobalSi 02B0: 67 6E 20 52 6F 6F 74 20 45 34 36 20 2D 20 4F 43 gn Root E46 - OC 02C0: 53 50 20 31 2E 32 20 32 30 32 34 30 35 30 37 30 SP 1.2 202405070 02D0: 82 01 22 30 0D 06 09 2A 86 48 86 F7 0D 01 01 01 .."0...*.H...... 02E0: 05 00 03 82 01 0F 00 30 82 01 0A 02 82 01 01 00 .......0........ 02F0: 94 E6 7A 6D DF 9F 17 54 B6 D4 7F CC 95 DF AD 3E ..zm...T.......> 0300: AC 8E 43 2C EB C2 9E ED 9B 9B 1C E2 63 2F FE E3 ..C,........c/.. 0310: E1 76 D8 5E 29 55 D0 0B D3 DF 30 6A 1A A2 34 3E .v.^)U....0j..4> 0320: B6 97 9B F5 33 8F EF E2 8F 4D 41 95 C1 52 B8 19 ....3....MA..R.. 0330: 0D D9 2A F6 C6 BC 51 E0 69 82 8F 1B C0 7F D4 41 ..*...Q.i......A 0340: 66 D7 75 13 86 17 D6 7E 60 1B D1 61 FC E9 08 0B f.u.....`..a.... 0350: 85 22 30 EE FC 82 11 86 5F CB 30 A2 DC 7D B7 DB ."0....._.0..... 0360: 6F AB 96 DE 23 10 4D E2 98 2C 08 EE AE 7C 1E 23 o...#.M..,.....# 0370: 2F D4 B8 10 35 70 F7 97 AE 89 FA 9F 8E 07 E1 AD /...5p.......... 0380: FA A1 3A 94 09 2E 5C 66 23 44 36 60 A2 1A EA 9B ..:...\f#D6`.... 0390: 91 92 DA F6 07 C6 89 40 ED E2 C9 E0 71 F3 D6 91 .......@....q... 03A0: 2E 54 8C CC 21 0A 48 FF 06 5A 76 02 95 61 75 27 .T..!.H..Zv..au' 03B0: A4 B0 80 EC 69 0B 85 BE 35 02 AB C6 F5 27 76 A4 ....i...5....'v. 03C0: 76 E8 B1 BC F1 D4 49 61 89 AC 91 EB 1C 2E 23 09 v.....Ia......#. 03D0: C8 68 15 7D E5 64 BB BE 4E 02 4E 08 F5 44 AB 65 .h...d..N.N..D.e 03E0: A7 67 E2 40 D7 4A CB 32 3E A8 2B E6 19 BA A0 83 .g.@.J.2>.+..... 03F0: 02 03 01 00 01 A3 81 87 30 81 84 30 0E 06 03 55 ........0..0...U 0400: 1D 0F 01 01 FF 04 04 03 02 07 80 30 13 06 03 55 ...........0...U 0410: 1D 25 04 0C 30 0A 06 08 2B 06 01 05 05 07 03 09 .%..0...+....... 0420: 30 0C 06 03 55 1D 13 01 01 FF 04 02 30 00 30 1D 0...U.......0.0. 0430: 06 03 55 1D 0E 04 16 04 14 43 C5 86 1F 37 F3 52 ..U......C...7.R 0440: 2A CC 49 A4 15 FE 55 B4 34 DD 8D 3D EF 30 1F 06 *.I...U.4..=.0.. 0450: 03 55 1D 23 04 18 30 16 80 14 31 0A 90 8F B6 C6 .U.#..0...1..... 0460: 9D D2 44 4B 80 B5 A2 E6 1F B1 12 4F 1B 95 30 0F ..DK.......O..0. 0470: 06 09 2B 06 01 05 05 07 30 01 05 04 02 05 00 30 ..+.....0......0 0480: 0A 06 08 2A 86 48 CE 3D 04 03 03 03 68 00 30 65 ...*.H.=....h.0e 0490: 02 31 00 93 B6 DE DA 9D 04 5D CE C7 AD CB D5 7C .1.......]...... 04A0: 60 6F 30 C1 B5 18 6B 6E 6D 21 28 65 E1 D1 3B 95 `o0...knm!(e..;. 04B0: C7 EA 60 92 07 F9 3B C6 4F DE 66 6A CF F2 B9 0B ..`...;.O.fj.... 04C0: 0A 96 B3 02 30 4B 14 DA 07 02 BE D7 1B 28 02 70 ....0K.......(.p 04D0: 4D 81 EE C4 B4 E3 D3 32 1A 53 44 2C B6 71 E2 9D M......2.SD,.q.. 04E0: 0C 45 A7 DF 5A 63 4E 87 D0 41 4A 88 62 CC 70 5A .E..ZcN..AJ.b.pZ 04F0: 77 9B 24 86 4C certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 43C5861F37F3522ACC49A415FE55B434DD8D3DEF certpath: OCSP response produced at: Sat May 18 16:40:52 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sat May 18 16:40:52 CST 2024 certpath: nextUpdate: Wed May 22 16:40:51 CST 2024 certpath: OCSP response cert #1: CN=GlobalSign Root E46 - OCSP 1.2 20240507, O=GlobalSign nv-sa, C=BE certpath: Status of certificate (with serial number 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c) is: GOOD certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Root E46 - OCSP 1.2 20240507, O=GlobalSign nv-sa, C=BE Key: RSA ] certpath: Responder's certificate includes the extension id-pkix-ocsp-nocheck. certpath: OCSP response is signed by an Authorized Responder certpath: Constraints.permits(): SHA256withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sat May 18 16:40:52 CST 2024 until Wed May 22 16:40:51 CST 2024 certpath: Checking validity of OCSP response on Sat May 18 18:06:40 CST 2024 with allowed interval between Sat May 18 17:51:40 CST 2024 and Sat May 18 18:21:40 CST 2024 certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: KeySizeConstraints.permits(): EC certpath: -checker8 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=revoked.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Cert Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=revoked.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Key: EC Date: Sat May 18 18:06:40 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.10.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (2) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (2) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Sat May 18 18:06:40 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE; subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=revoked.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB; serial#: 01:e5:27:75:02:54:d2:e0:ad:1e:f2:a3:92:c7:3a:20 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 01:e5:27:75:02:54:d2:e0:ad:1e:f2:a3:92:c7:3a:20 Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=revoked.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 06 C6 A3 12 8E E7 80 BF 64 ...............d 0020: AC 73 89 54 16 FA EB C8 B1 6A AA 04 14 5E C4 F2 .s.T.....j...^.. 0030: F2 F8 D0 CF 0D 79 A3 4F 69 21 F1 41 71 7D 53 65 .....y.Oi!.Aq.Se 0040: 60 02 10 01 E5 27 75 02 54 D2 E0 AD 1E F2 A3 92 `....'u.T....... 0050: C7 3A 20 certpath: connecting to OCSP service at: http://ocsp.globalsign.com/ca/gsatlase46evtlsca2023q4 certpath: OCSPResponse bytes... 0000: 30 82 03 9E 0A 01 00 A0 82 03 97 30 82 03 93 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 03 84 30 82 .+.....0......0. 0020: 03 80 30 81 B1 A2 16 04 14 33 A9 AB 48 EC B6 BD ..0......3..H... 0030: 0E 42 CF EF CE FB A2 AE D1 7C C3 07 79 18 0F 32 .B..........y..2 0040: 30 32 34 30 35 31 38 30 39 34 30 30 30 5A 30 81 0240518094000Z0. 0050: 85 30 81 82 30 49 30 09 06 05 2B 0E 03 02 1A 05 .0..0I0...+..... 0060: 00 04 14 06 C6 A3 12 8E E7 80 BF 64 AC 73 89 54 ...........d.s.T 0070: 16 FA EB C8 B1 6A AA 04 14 5E C4 F2 F2 F8 D0 CF .....j...^...... 0080: 0D 79 A3 4F 69 21 F1 41 71 7D 53 65 60 02 10 01 .y.Oi!.Aq.Se`... 0090: E5 27 75 02 54 D2 E0 AD 1E F2 A3 92 C7 3A 20 A1 .'u.T........: . 00A0: 11 18 0F 32 30 32 33 31 30 32 33 31 32 32 39 30 ...2023102312290 00B0: 32 5A 18 0F 32 30 32 34 30 35 31 38 30 39 30 30 2Z..202405180900 00C0: 30 30 5A A0 11 18 0F 32 30 32 34 30 35 31 38 32 00Z....202405182 00D0: 31 30 30 30 30 5A 30 0A 06 08 2A 86 48 CE 3D 04 10000Z0...*.H.=. 00E0: 03 02 03 49 00 30 46 02 21 00 EF 1C 5E 7E D5 C9 ...I.0F.!...^... 00F0: BE 1F 0A 78 96 90 68 60 CB 7F 5A 03 BE DC B4 9D ...x..h`..Z..... 0100: AC D4 C3 EB 61 E7 72 22 5D 07 02 21 00 AA 86 60 ....a.r"]..!...` 0110: 35 0C 7A 24 F0 DA 7F 1B 9B 0C 9B 3E BB 53 75 EE 5.z$.......>.Su. 0120: C8 65 FD A8 51 D6 39 32 7C B5 93 1B AD A0 82 02 .e..Q.92........ 0130: 71 30 82 02 6D 30 82 02 69 30 82 01 EF A0 03 02 q0..m0..i0...... 0140: 01 02 02 10 01 9A C4 75 15 74 A6 35 76 E5 EF F1 .......u.t.5v... 0150: E6 12 4A 04 30 0A 06 08 2A 86 48 CE 3D 04 03 03 ..J.0...*.H.=... 0160: 30 59 31 0B 30 09 06 03 55 04 06 13 02 42 45 31 0Y1.0...U....BE1 0170: 19 30 17 06 03 55 04 0A 13 10 47 6C 6F 62 61 6C .0...U....Global 0180: 53 69 67 6E 20 6E 76 2D 73 61 31 2F 30 2D 06 03 Sign nv-sa1/0-.. 0190: 55 04 03 13 26 47 6C 6F 62 61 6C 53 69 67 6E 20 U...&GlobalSign 01A0: 41 74 6C 61 73 20 45 34 36 20 45 56 20 54 4C 53 Atlas E46 EV TLS 01B0: 20 43 41 20 32 30 32 33 20 51 34 30 1E 17 0D 32 CA 2023 Q40...2 01C0: 34 30 35 31 38 30 35 32 35 35 36 5A 17 0D 32 34 40518052556Z..24 01D0: 30 35 32 35 30 35 32 35 35 36 5A 30 6A 31 0B 30 0525052556Z0j1.0 01E0: 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 ...U....BE1.0... 01F0: 55 04 0A 0C 10 47 6C 6F 62 61 6C 53 69 67 6E 20 U....GlobalSign 0200: 6E 76 2D 73 61 31 40 30 3E 06 03 55 04 03 0C 37 nv-sa1@0>..U...7 0210: 47 6C 6F 62 61 6C 53 69 67 6E 20 41 74 6C 61 73 GlobalSign Atlas 0220: 20 45 34 36 20 45 56 20 54 4C 53 20 43 41 20 32 E46 EV TLS CA 2 0230: 30 32 33 20 51 34 20 2D 20 4F 43 53 50 20 52 65 023 Q4 - OCSP Re 0240: 73 70 6F 6E 64 65 72 30 59 30 13 06 07 2A 86 48 sponder0Y0...*.H 0250: CE 3D 02 01 06 08 2A 86 48 CE 3D 03 01 07 03 42 .=....*.H.=....B 0260: 00 04 62 15 07 7C 96 DF 4F D5 E4 79 67 4B 54 18 ..b.....O..ygKT. 0270: 6D 72 9C 11 77 73 02 A0 62 A0 30 32 CA B3 8E 20 mr..ws..b.02... 0280: 23 1A 37 05 36 0B 16 97 C5 58 63 C7 38 85 CE 75 #.7.6....Xc.8..u 0290: D0 F6 E4 6A 52 9D 62 B2 CC BC 93 F8 86 36 8A 93 ...jR.b......6.. 02A0: BE B8 A3 81 87 30 81 84 30 0F 06 09 2B 06 01 05 .....0..0...+... 02B0: 05 07 30 01 05 04 02 05 00 30 0E 06 03 55 1D 0F ..0......0...U.. 02C0: 01 01 FF 04 04 03 02 07 80 30 13 06 03 55 1D 25 .........0...U.% 02D0: 04 0C 30 0A 06 08 2B 06 01 05 05 07 03 09 30 1D ..0...+.......0. 02E0: 06 03 55 1D 0E 04 16 04 14 33 A9 AB 48 EC B6 BD ..U......3..H... 02F0: 0E 42 CF EF CE FB A2 AE D1 7C C3 07 79 30 0C 06 .B..........y0.. 0300: 03 55 1D 13 01 01 FF 04 02 30 00 30 1F 06 03 55 .U.......0.0...U 0310: 1D 23 04 18 30 16 80 14 5E C4 F2 F2 F8 D0 CF 0D .#..0...^....... 0320: 79 A3 4F 69 21 F1 41 71 7D 53 65 60 30 0A 06 08 y.Oi!.Aq.Se`0... 0330: 2A 86 48 CE 3D 04 03 03 03 68 00 30 65 02 31 00 *.H.=....h.0e.1. 0340: EC CA 11 E7 1E 45 E6 AB 29 6D 47 01 04 B5 8A 8A .....E..)mG..... 0350: 38 D9 1E 4A 03 01 C7 CA 81 A3 AD F6 4E 0A 21 84 8..J........N.!. 0360: 6D 6C C2 3C D0 80 D8 E2 A7 C6 2B BC 17 93 07 D6 ml.<......+..... 0370: 02 30 3D 7E 6E DD DC D0 57 85 13 44 A6 E7 58 D4 .0=.n...W..D..X. 0380: CE ED BD 03 9B 2C 0F BD 9A EE DE C0 2D A5 F2 B5 .....,......-... 0390: 03 37 B4 62 17 6E 4E 99 D7 BA 6A 22 93 61 71 D0 .7.b.nN...j".aq. 03A0: D5 D2 certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 33A9AB48ECB6BD0E42CFEFCEFBA2AED17CC30779 certpath: OCSP response produced at: Sat May 18 17:40:00 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: Revocation time: Mon Oct 23 20:29:02 CST 2023 certpath: Revocation reason: UNSPECIFIED certpath: thisUpdate: Sat May 18 17:00:00 CST 2024 certpath: nextUpdate: Sun May 19 05:00:00 CST 2024 certpath: OCSP response cert #1: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4 - OCSP Responder, O=GlobalSign nv-sa, C=BE certpath: Status of certificate (with serial number 01:e5:27:75:02:54:d2:e0:ad:1e:f2:a3:92:c7:3a:20) is: REVOKED certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4 - OCSP Responder, O=GlobalSign nv-sa, C=BE Key: EC ] certpath: Responder's certificate includes the extension id-pkix-ocsp-nocheck. certpath: OCSP response is signed by an Authorized Responder certpath: Constraints.permits(): SHA256withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sat May 18 17:00:00 CST 2024 until Sun May 19 05:00:00 CST 2024 certpath: Checking validity of OCSP response on Sat May 18 18:06:40 CST 2024 with allowed interval between Sat May 18 17:51:40 CST 2024 and Sat May 18 18:21:40 CST 2024 certpath: X509CertSelector.match(Serial number: 01:00:20 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match STATUS:Passed. rerun: cd /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/scratch && \ DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \ DISPLAY=:7 \ HOME=/home/yansendao \ LANG=en_US.UTF-8 \ PATH=/bin:/usr/bin:/usr/sbin \ XDG_RUNTIME_DIR=/run/user/995 \ XDG_SESSION_ID=282 \ CLASSPATH=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d:/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib:/home/yansendao/git/jdk/test/lib:/home/yansendao/software/jdk/jtreg-7/lib/javatest.jar:/home/yansendao/software/jdk/jtreg-7/lib/jtreg.jar \ /home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk/bin/java \ -Dtest.vm.opts='-ea -esa' \ -Dtest.tool.vm.opts='-J-ea -J-esa' \ -Dtest.compiler.opts= \ -Dtest.java.opts= \ -Dtest.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -Dcompile.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -Dtest.timeout.factor=4.0 \ -Dtest.root=/home/yansendao/git/jdk/test/jdk \ -Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#globalsigne46 \ -Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \ -Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -Dtest.classes=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d \ -Dtest.class.path=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib \ -ea \ -esa \ -Djava.security.debug=certpath,ocsp \ com.sun.javatest.regtest.agent.MainWrapper /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d/main.0.jta globalsigne46 OCSP ACTION: build -- Passed. All files up to date REASON: Named class compiled on demand TIME: 0.0 seconds messages: command: build CAInterop reason: Named class compiled on demand started: Sat May 18 18:06:40 CST 2024 finished: Sat May 18 18:06:40 CST 2024 elapsed time (seconds): 0.0 ACTION: main -- Failed. Execution failed: `main' threw exception: java.lang.RuntimeException: Unhandled exception REASON: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp -Dcom.sun.security.ocsp.useget=false CAInterop globalsigne46 OCSP TIME: 19.674 seconds messages: command: main -Djava.security.debug=certpath,ocsp -Dcom.sun.security.ocsp.useget=false CAInterop globalsigne46 OCSP reason: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp -Dcom.sun.security.ocsp.useget=false CAInterop globalsigne46 OCSP started: Sat May 18 18:06:40 CST 2024 Mode: othervm [/othervm specified] finished: Sat May 18 18:07:00 CST 2024 elapsed time (seconds): 19.674 configuration: STDOUT: ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, SHA1 usage SignedJAR & denyAfter 2019-01-01 com.sun.security.enableCRLDP :false ocsp.enable :true ===================================================== ===== Validate https://valid.e46.roots.globalsign.com===== SSLHandshakeException: Remote host terminated the handshake STDERR: certpath: Constraints: 3DES_EDE_CBC certpath: Constraints: anon certpath: Constraints: DES certpath: Constraints: DH keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: DTLSv1.0 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: ECDH certpath: Constraints: MD5withRSA certpath: Constraints: NULL certpath: Constraints: RC4 certpath: Constraints: SSLv3 certpath: Constraints: TLSv1 certpath: Constraints: TLSv1.1 certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01 certpath: Constraints usage length is 1 certpath: Constraints set to denyAfter certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1 certpath: DenyAfterConstraint date set to: 2019-01-01 certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 01:00:20 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01 certpath: Constraints usage length is 1 certpath: Constraints set to denyAfter certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1 certpath: DenyAfterConstraint date set to: 2019-01-01 certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC Date: Sat May 18 18:07:00 CST 2024 ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Key: EC Date: Sat May 18 18:07:00 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.10.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Sat May 18 18:07:00 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE; subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE; serial#: 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE certpath: com.sun.security.ocsp.timeout set to 15000 milliseconds certpath: com.sun.security.ocsp.readtimeout set to 15000 milliseconds certpath: com.sun.security.ocsp.useget set to false certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 DE 1D 43 C4 7A F5 F1 BC 86 .........C.z.... 0020: AB 36 43 7E 02 17 03 F8 9C CF 5C 04 14 31 0A 90 .6C.......\..1.. 0030: 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 12 4F 1B .....DK.......O. 0040: 95 02 10 7F 1F 2C 88 FD 17 29 03 A3 20 2B 07 62 .....,...).. +.b 0050: D9 76 9C certpath: connecting to OCSP service at: http://ocsp.globalsign.com/roote46 certpath: OCSPResponse bytes... 0000: 30 82 04 F1 0A 01 00 A0 82 04 EA 30 82 04 E6 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 04 D7 30 82 .+.....0......0. 0020: 04 D3 30 81 9E A2 16 04 14 43 C5 86 1F 37 F3 52 ..0......C...7.R 0030: 2A CC 49 A4 15 FE 55 B4 34 DD 8D 3D EF 18 0F 32 *.I...U.4..=...2 0040: 30 32 34 30 35 31 38 30 38 34 30 35 32 5A 30 73 0240518084052Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 DE 1D 43 C4 7A F5 F1 BC 86 AB 36 43 7E 02 17 ...C.z.....6C... 0070: 03 F8 9C CF 5C 04 14 31 0A 90 8F B6 C6 9D D2 44 ....\..1.......D 0080: 4B 80 B5 A2 E6 1F B1 12 4F 1B 95 02 10 7F 1F 2C K.......O......, 0090: 88 FD 17 29 03 A3 20 2B 07 62 D9 76 9C 80 00 18 ...).. +.b.v.... 00A0: 0F 32 30 32 34 30 35 31 38 30 38 34 30 35 32 5A .20240518084052Z 00B0: A0 11 18 0F 32 30 32 34 30 35 32 32 30 38 34 30 ....202405220840 00C0: 35 31 5A 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0B 51Z0...*.H...... 00D0: 05 00 03 82 01 01 00 72 F2 98 5F 0A A6 89 5E F9 .......r.._...^. 00E0: C6 76 15 8D 37 AA 9A 37 80 E5 3E 9F DE BD 34 10 .v..7..7..>...4. 00F0: 26 AD 50 75 B5 AC 24 C2 25 12 DB 01 86 D4 5F B1 &.Pu..$.%....._. 0100: 7F 32 2C 7B 53 B9 8D A1 79 A4 F8 5B 53 8B 94 9B .2,.S...y..[S... 0110: 70 49 62 93 9E 2A 5D 6A 99 79 19 DC C2 6A 03 A0 pIb..*]j.y...j.. 0120: 24 DC C7 31 17 46 AA 7D 42 25 05 F3 A1 9A A4 CC $..1.F..B%...... 0130: 0B 4E D7 F3 6A CA 16 0F AD 84 B3 03 5B 92 6C 26 .N..j.......[.l& 0140: 77 8A C8 54 36 89 EF 38 95 90 08 91 D3 07 D6 2A w..T6..8.......* 0150: 22 4A C3 8D AD 3E DA 28 18 AF 78 B2 83 99 11 8D "J...>.(..x..... 0160: BC 7E 72 3A 90 5A 94 29 36 9E 46 47 6A 17 AA 3C ..r:.Z.)6.FGj..< 0170: 13 E5 AB B3 4A 36 1C 1B 57 6A 4D EF 7F A8 F1 A4 ....J6..WjM..... 0180: B9 28 3E 0A BF A2 79 C3 F2 91 47 C1 77 B3 D2 E6 .(>...y...G.w... 0190: 5B 54 38 59 07 78 5E 6C 64 FC 18 D2 33 36 EB 0E [T8Y.x^ld...36.. 01A0: D4 0A 13 D0 51 20 AD 0C C8 BE BE 86 26 19 88 DE ....Q ......&... 01B0: D1 62 36 AB A5 A0 0A 5A D3 D9 7F 34 54 B2 EC 3A .b6....Z...4T..: 01C0: 97 07 19 82 54 4F 4E F5 67 CB D2 7E 84 3E 83 E9 ....TON.g....>.. 01D0: 7A 9B BF 63 8D 8C 0E A0 82 03 1A 30 82 03 16 30 z..c.......0...0 01E0: 82 03 12 30 82 02 98 A0 03 02 01 02 02 11 00 80 ...0............ 01F0: 4E 02 61 EA D7 14 3F BB D7 C1 F9 97 3D FC 92 30 N.a...?.....=..0 0200: 0A 06 08 2A 86 48 CE 3D 04 03 03 30 46 31 0B 30 ...*.H.=...0F1.0 0210: 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 ...U....BE1.0... 0220: 55 04 0A 13 10 47 6C 6F 62 61 6C 53 69 67 6E 20 U....GlobalSign 0230: 6E 76 2D 73 61 31 1C 30 1A 06 03 55 04 03 13 13 nv-sa1.0...U.... 0240: 47 6C 6F 62 61 6C 53 69 67 6E 20 52 6F 6F 74 20 GlobalSign Root 0250: 45 34 36 30 1E 17 0D 32 34 30 31 31 37 30 33 33 E460...240117033 0260: 31 34 39 5A 17 0D 32 34 30 38 31 35 30 30 30 30 149Z..2408150000 0270: 30 30 5A 30 5A 31 0B 30 09 06 03 55 04 06 13 02 00Z0Z1.0...U.... 0280: 42 45 31 19 30 17 06 03 55 04 0A 13 10 47 6C 6F BE1.0...U....Glo 0290: 62 61 6C 53 69 67 6E 20 6E 76 2D 73 61 31 30 30 balSign nv-sa100 02A0: 2E 06 03 55 04 03 13 27 47 6C 6F 62 61 6C 53 69 ...U...'GlobalSi 02B0: 67 6E 20 52 6F 6F 74 20 45 34 36 20 2D 20 4F 43 gn Root E46 - OC 02C0: 53 50 20 31 2E 32 20 32 30 32 34 30 35 30 37 30 SP 1.2 202405070 02D0: 82 01 22 30 0D 06 09 2A 86 48 86 F7 0D 01 01 01 .."0...*.H...... 02E0: 05 00 03 82 01 0F 00 30 82 01 0A 02 82 01 01 00 .......0........ 02F0: 94 E6 7A 6D DF 9F 17 54 B6 D4 7F CC 95 DF AD 3E ..zm...T.......> 0300: AC 8E 43 2C EB C2 9E ED 9B 9B 1C E2 63 2F FE E3 ..C,........c/.. 0310: E1 76 D8 5E 29 55 D0 0B D3 DF 30 6A 1A A2 34 3E .v.^)U....0j..4> 0320: B6 97 9B F5 33 8F EF E2 8F 4D 41 95 C1 52 B8 19 ....3....MA..R.. 0330: 0D D9 2A F6 C6 BC 51 E0 69 82 8F 1B C0 7F D4 41 ..*...Q.i......A 0340: 66 D7 75 13 86 17 D6 7E 60 1B D1 61 FC E9 08 0B f.u.....`..a.... 0350: 85 22 30 EE FC 82 11 86 5F CB 30 A2 DC 7D B7 DB ."0....._.0..... 0360: 6F AB 96 DE 23 10 4D E2 98 2C 08 EE AE 7C 1E 23 o...#.M..,.....# 0370: 2F D4 B8 10 35 70 F7 97 AE 89 FA 9F 8E 07 E1 AD /...5p.......... 0380: FA A1 3A 94 09 2E 5C 66 23 44 36 60 A2 1A EA 9B ..:...\f#D6`.... 0390: 91 92 DA F6 07 C6 89 40 ED E2 C9 E0 71 F3 D6 91 .......@....q... 03A0: 2E 54 8C CC 21 0A 48 FF 06 5A 76 02 95 61 75 27 .T..!.H..Zv..au' 03B0: A4 B0 80 EC 69 0B 85 BE 35 02 AB C6 F5 27 76 A4 ....i...5....'v. 03C0: 76 E8 B1 BC F1 D4 49 61 89 AC 91 EB 1C 2E 23 09 v.....Ia......#. 03D0: C8 68 15 7D E5 64 BB BE 4E 02 4E 08 F5 44 AB 65 .h...d..N.N..D.e 03E0: A7 67 E2 40 D7 4A CB 32 3E A8 2B E6 19 BA A0 83 .g.@.J.2>.+..... 03F0: 02 03 01 00 01 A3 81 87 30 81 84 30 0E 06 03 55 ........0..0...U 0400: 1D 0F 01 01 FF 04 04 03 02 07 80 30 13 06 03 55 ...........0...U 0410: 1D 25 04 0C 30 0A 06 08 2B 06 01 05 05 07 03 09 .%..0...+....... 0420: 30 0C 06 03 55 1D 13 01 01 FF 04 02 30 00 30 1D 0...U.......0.0. 0430: 06 03 55 1D 0E 04 16 04 14 43 C5 86 1F 37 F3 52 ..U......C...7.R 0440: 2A CC 49 A4 15 FE 55 B4 34 DD 8D 3D EF 30 1F 06 *.I...U.4..=.0.. 0450: 03 55 1D 23 04 18 30 16 80 14 31 0A 90 8F B6 C6 .U.#..0...1..... 0460: 9D D2 44 4B 80 B5 A2 E6 1F B1 12 4F 1B 95 30 0F ..DK.......O..0. 0470: 06 09 2B 06 01 05 05 07 30 01 05 04 02 05 00 30 ..+.....0......0 0480: 0A 06 08 2A 86 48 CE 3D 04 03 03 03 68 00 30 65 ...*.H.=....h.0e 0490: 02 31 00 93 B6 DE DA 9D 04 5D CE C7 AD CB D5 7C .1.......]...... 04A0: 60 6F 30 C1 B5 18 6B 6E 6D 21 28 65 E1 D1 3B 95 `o0...knm!(e..;. 04B0: C7 EA 60 92 07 F9 3B C6 4F DE 66 6A CF F2 B9 0B ..`...;.O.fj.... 04C0: 0A 96 B3 02 30 4B 14 DA 07 02 BE D7 1B 28 02 70 ....0K.......(.p 04D0: 4D 81 EE C4 B4 E3 D3 32 1A 53 44 2C B6 71 E2 9D M......2.SD,.q.. 04E0: 0C 45 A7 DF 5A 63 4E 87 D0 41 4A 88 62 CC 70 5A .E..ZcN..AJ.b.pZ 04F0: 77 9B 24 86 4C certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 43C5861F37F3522ACC49A415FE55B434DD8D3DEF certpath: OCSP response produced at: Sat May 18 16:40:52 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sat May 18 16:40:52 CST 2024 certpath: nextUpdate: Wed May 22 16:40:51 CST 2024 certpath: OCSP response cert #1: CN=GlobalSign Root E46 - OCSP 1.2 20240507, O=GlobalSign nv-sa, C=BE certpath: Status of certificate (with serial number 7f:1f:2c:88:fd:17:29:03:a3:20:2b:07:62:d9:76:9c) is: GOOD certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Root E46 - OCSP 1.2 20240507, O=GlobalSign nv-sa, C=BE Key: RSA ] certpath: Responder's certificate includes the extension id-pkix-ocsp-nocheck. certpath: OCSP response is signed by an Authorized Responder certpath: Constraints.permits(): SHA256withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sat May 18 16:40:52 CST 2024 until Wed May 22 16:40:51 CST 2024 certpath: Checking validity of OCSP response on Sat May 18 18:07:00 CST 2024 with allowed interval between Sat May 18 17:52:00 CST 2024 and Sat May 18 18:22:00 CST 2024 certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: KeySizeConstraints.permits(): EC certpath: -checker8 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Cert Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Key: EC Date: Sat May 18 18:07:00 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4146.10.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (1) 1.3.6.1.4.1.4146.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.1.1 (2) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (1) 1.3.6.1.4.1.4146.10.1.1 CRIT: false EP: 1.3.6.1.4.1.4146.10.1.1 (2) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Sat May 18 18:07:00 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE; subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB; serial#: 01:c7:71:fd:da:a6:99:85:e4:b6:61:75:f2:65:c5:8a certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 01:c7:71:fd:da:a6:99:85:e4:b6:61:75:f2:65:c5:8a Subject: SERIALNUMBER=04705639, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, CN=valid.e46.roots.globalsign.com, O=GMO GlobalSign LTD, STREET="Springfield House, Sandling Road", OID.2.5.4.17=ME14 2LP, L=Maidstone, ST=Kent, C=GB Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 06 C6 A3 12 8E E7 80 BF 64 ...............d 0020: AC 73 89 54 16 FA EB C8 B1 6A AA 04 14 5E C4 F2 .s.T.....j...^.. 0030: F2 F8 D0 CF 0D 79 A3 4F 69 21 F1 41 71 7D 53 65 .....y.Oi!.Aq.Se 0040: 60 02 10 01 C7 71 FD DA A6 99 85 E4 B6 61 75 F2 `....q.......au. 0050: 65 C5 8A certpath: connecting to OCSP service at: http://ocsp.globalsign.com/ca/gsatlase46evtlsca2023q4 certpath: OCSPResponse bytes... 0000: 30 82 03 8A 0A 01 00 A0 82 03 83 30 82 03 7F 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 03 70 30 82 .+.....0.....p0. 0020: 03 6C 30 81 9E A2 16 04 14 33 A9 AB 48 EC B6 BD .l0......3..H... 0030: 0E 42 CF EF CE FB A2 AE D1 7C C3 07 79 18 0F 32 .B..........y..2 0040: 30 32 34 30 35 31 38 30 39 34 30 30 30 5A 30 73 0240518094000Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 06 C6 A3 12 8E E7 80 BF 64 AC 73 89 54 16 FA .........d.s.T.. 0070: EB C8 B1 6A AA 04 14 5E C4 F2 F2 F8 D0 CF 0D 79 ...j...^.......y 0080: A3 4F 69 21 F1 41 71 7D 53 65 60 02 10 01 C7 71 .Oi!.Aq.Se`....q 0090: FD DA A6 99 85 E4 B6 61 75 F2 65 C5 8A 80 00 18 .......au.e..... 00A0: 0F 32 30 32 34 30 35 31 38 30 39 30 30 30 30 5A .20240518090000Z 00B0: A0 11 18 0F 32 30 32 34 30 35 31 38 32 31 30 30 ....202405182100 00C0: 30 30 5A 30 0A 06 08 2A 86 48 CE 3D 04 03 02 03 00Z0...*.H.=.... 00D0: 48 00 30 45 02 21 00 E8 E1 8E 24 C2 22 98 2C 6A H.0E.!....$.".,j 00E0: F7 DD F5 F0 B3 1D E5 3D 3A DE EF 6A A9 DA C7 85 .......=:..j.... 00F0: 64 42 13 98 8E 2E 0F 02 20 1F 09 33 F4 58 0A 52 dB...... ..3.X.R 0100: 96 85 5B F0 3F 37 6A 44 33 D3 4E C7 C3 26 BF EC ..[.?7jD3.N..&.. 0110: E5 F2 8C 8A C3 A3 E6 0F 42 A0 82 02 71 30 82 02 ........B...q0.. 0120: 6D 30 82 02 69 30 82 01 EF A0 03 02 01 02 02 10 m0..i0.......... 0130: 01 9A C4 75 15 74 A6 35 76 E5 EF F1 E6 12 4A 04 ...u.t.5v.....J. 0140: 30 0A 06 08 2A 86 48 CE 3D 04 03 03 30 59 31 0B 0...*.H.=...0Y1. 0150: 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 0...U....BE1.0.. 0160: 03 55 04 0A 13 10 47 6C 6F 62 61 6C 53 69 67 6E .U....GlobalSign 0170: 20 6E 76 2D 73 61 31 2F 30 2D 06 03 55 04 03 13 nv-sa1/0-..U... 0180: 26 47 6C 6F 62 61 6C 53 69 67 6E 20 41 74 6C 61 &GlobalSign Atla 0190: 73 20 45 34 36 20 45 56 20 54 4C 53 20 43 41 20 s E46 EV TLS CA 01A0: 32 30 32 33 20 51 34 30 1E 17 0D 32 34 30 35 31 2023 Q40...24051 01B0: 38 30 35 32 35 35 36 5A 17 0D 32 34 30 35 32 35 8052556Z..240525 01C0: 30 35 32 35 35 36 5A 30 6A 31 0B 30 09 06 03 55 052556Z0j1.0...U 01D0: 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0A 0C ....BE1.0...U... 01E0: 10 47 6C 6F 62 61 6C 53 69 67 6E 20 6E 76 2D 73 .GlobalSign nv-s 01F0: 61 31 40 30 3E 06 03 55 04 03 0C 37 47 6C 6F 62 a1@0>..U...7Glob 0200: 61 6C 53 69 67 6E 20 41 74 6C 61 73 20 45 34 36 alSign Atlas E46 0210: 20 45 56 20 54 4C 53 20 43 41 20 32 30 32 33 20 EV TLS CA 2023 0220: 51 34 20 2D 20 4F 43 53 50 20 52 65 73 70 6F 6E Q4 - OCSP Respon 0230: 64 65 72 30 59 30 13 06 07 2A 86 48 CE 3D 02 01 der0Y0...*.H.=.. 0240: 06 08 2A 86 48 CE 3D 03 01 07 03 42 00 04 62 15 ..*.H.=....B..b. 0250: 07 7C 96 DF 4F D5 E4 79 67 4B 54 18 6D 72 9C 11 ....O..ygKT.mr.. 0260: 77 73 02 A0 62 A0 30 32 CA B3 8E 20 23 1A 37 05 ws..b.02... #.7. 0270: 36 0B 16 97 C5 58 63 C7 38 85 CE 75 D0 F6 E4 6A 6....Xc.8..u...j 0280: 52 9D 62 B2 CC BC 93 F8 86 36 8A 93 BE B8 A3 81 R.b......6...... 0290: 87 30 81 84 30 0F 06 09 2B 06 01 05 05 07 30 01 .0..0...+.....0. 02A0: 05 04 02 05 00 30 0E 06 03 55 1D 0F 01 01 FF 04 .....0...U...... 02B0: 04 03 02 07 80 30 13 06 03 55 1D 25 04 0C 30 0A .....0...U.%..0. 02C0: 06 08 2B 06 01 05 05 07 03 09 30 1D 06 03 55 1D ..+.......0...U. 02D0: 0E 04 16 04 14 33 A9 AB 48 EC B6 BD 0E 42 CF EF .....3..H....B.. 02E0: CE FB A2 AE D1 7C C3 07 79 30 0C 06 03 55 1D 13 ........y0...U.. 02F0: 01 01 FF 04 02 30 00 30 1F 06 03 55 1D 23 04 18 .....0.0...U.#.. 0300: 30 16 80 14 5E C4 F2 F2 F8 D0 CF 0D 79 A3 4F 69 0...^.......y.Oi 0310: 21 F1 41 71 7D 53 65 60 30 0A 06 08 2A 86 48 CE !.Aq.Se`0...*.H. 0320: 3D 04 03 03 03 68 00 30 65 02 31 00 EC CA 11 E7 =....h.0e.1..... 0330: 1E 45 E6 AB 29 6D 47 01 04 B5 8A 8A 38 D9 1E 4A .E..)mG.....8..J 0340: 03 01 C7 CA 81 A3 AD F6 4E 0A 21 84 6D 6C C2 3C ........N.!.ml.< 0350: D0 80 D8 E2 A7 C6 2B BC 17 93 07 D6 02 30 3D 7E ......+......0=. 0360: 6E DD DC D0 57 85 13 44 A6 E7 58 D4 CE ED BD 03 n...W..D..X..... 0370: 9B 2C 0F BD 9A EE DE C0 2D A5 F2 B5 03 37 B4 62 .,......-....7.b 0380: 17 6E 4E 99 D7 BA 6A 22 93 61 71 D0 D5 D2 certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 33A9AB48ECB6BD0E42CFEFCEFBA2AED17CC30779 certpath: OCSP response produced at: Sat May 18 17:40:00 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sat May 18 17:00:00 CST 2024 certpath: nextUpdate: Sun May 19 05:00:00 CST 2024 certpath: OCSP response cert #1: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4 - OCSP Responder, O=GlobalSign nv-sa, C=BE certpath: Status of certificate (with serial number 01:c7:71:fd:da:a6:99:85:e4:b6:61:75:f2:65:c5:8a) is: GOOD certpath: Constraints.permits(): EC, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Cert Issuer: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4, O=GlobalSign nv-sa, C=BE Cert Subject: CN=GlobalSign Atlas E46 EV TLS CA 2023 Q4 - OCSP Responder, O=GlobalSign nv-sa, C=BE Key: EC ] certpath: Responder's certificate includes the extension id-pkix-ocsp-nocheck. certpath: OCSP response is signed by an Authorized Responder certpath: Constraints.permits(): SHA256withECDSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 24019432300189087672941319075455521479694611637571214575722013324283564684998168122961977598895087693950505975722624 public y coord: 6742149443231861379623016579368542169821401513454099743947791365305396240395805831645430329030075773173056934067232 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Wed Mar 20 08:00:00 CST 2019, To: Tue Mar 20 08:00:00 CST 2046] Issuer: CN=GlobalSign Root E46, O=GlobalSign nv-sa, C=BE SerialNumber: 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43 Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 31 0A 90 8F B6 C6 9D D2 44 4B 80 B5 A2 E6 1F B1 1.......DK...... 0010: 12 4F 1B 95 .O.. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 31 00 DF 54 90 ED 9B EF 8B 94 02 93 17 0e.1..T......... 0010: 82 99 BE B3 9E 2C F6 0B 91 8C 9F 4A 14 B1 F6 64 .....,.....J...d 0020: BC BB 68 51 13 0C 03 F7 15 8B 84 60 B9 8B FF 52 ..hQ.......`...R 0030: 8E E7 8C BC 1C 02 30 3C F9 11 D4 8C 4E C0 C1 61 ......0<....N..a 0040: C2 15 4C AA AB 1D 0B 31 5F 3B 1C E2 00 97 44 31 ..L....1_;....D1 0050: E6 FE 73 96 2F DA 96 D3 FE 08 07 B3 34 89 BC 05 ..s./.......4... 0060: 9F F7 1E 86 EE 8B 70 ......p ] Key: EC ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sat May 18 17:00:00 CST 2024 until Sun May 19 05:00:00 CST 2024 certpath: Checking validity of OCSP response on Sat May 18 18:07:00 CST 2024 with allowed interval between Sat May 18 17:52:00 CST 2024 and Sat May 18 18:22:00 CST 2024 certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: KeySizeConstraints.permits(): EC certpath: KeySizeConstraints.permits(): EC certpath: -checker8 validation succeeded certpath: cert2 validation succeeded. certpath: Cert path validation succeeded. (PKIX validation algorithm) certpath: -------------------------------------------------------------- certpath: KeySizeConstraints.permits(): EC certpath: KeySizeConstraints.permits(): EC java.lang.RuntimeException: Unhandled exception at ValidatePathWithURL.validateDomainCertChain(ValidatePathWithURL.java:176) at ValidatePathWithURL.validateDomain(ValidatePathWithURL.java:128) at CAInterop.validate(CAInterop.java:784) at CAInterop.main(CAInterop.java:726) at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103) at java.base/java.lang.reflect.Method.invoke(Method.java:580) at com.sun.javatest.regtest.agent.MainWrapper$MainTask.run(MainWrapper.java:138) at java.base/java.lang.Thread.run(Thread.java:1575) Caused by: javax.net.ssl.SSLHandshakeException: Remote host terminated the handshake at java.base/sun.security.ssl.SSLSocketImpl.handleEOF(SSLSocketImpl.java:1715) at java.base/sun.security.ssl.SSLSocketImpl.decode(SSLSocketImpl.java:1515) at java.base/sun.security.ssl.SSLSocketImpl.readHandshakeRecord(SSLSocketImpl.java:1422) at java.base/sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:455) at java.base/sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:426) at java.base/sun.net.www.protocol.https.HttpsClient.afterConnect(HttpsClient.java:586) at java.base/sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:187) at java.base/sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(HttpsURLConnectionImpl.java:141) at ValidatePathWithURL.validateDomainCertChain(ValidatePathWithURL.java:142) ... 7 more Caused by: java.io.EOFException: SSL peer shut down incorrectly at java.base/sun.security.ssl.SSLSocketInputRecord.read(SSLSocketInputRecord.java:494) at java.base/sun.security.ssl.SSLSocketInputRecord.readHeader(SSLSocketInputRecord.java:483) at java.base/sun.security.ssl.SSLSocketInputRecord.decode(SSLSocketInputRecord.java:160) at java.base/sun.security.ssl.SSLTransport.decode(SSLTransport.java:111) at java.base/sun.security.ssl.SSLSocketImpl.decode(SSLSocketImpl.java:1507) ... 14 more JavaTest Message: Test threw exception: java.lang.RuntimeException: Unhandled exception JavaTest Message: shutting down test STATUS:Failed.`main' threw exception: java.lang.RuntimeException: Unhandled exception rerun: cd /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/scratch && \ DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \ DISPLAY=:7 \ HOME=/home/yansendao \ LANG=en_US.UTF-8 \ PATH=/bin:/usr/bin:/usr/sbin \ XDG_RUNTIME_DIR=/run/user/995 \ XDG_SESSION_ID=282 \ CLASSPATH=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d:/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib:/home/yansendao/git/jdk/test/lib:/home/yansendao/software/jdk/jtreg-7/lib/javatest.jar:/home/yansendao/software/jdk/jtreg-7/lib/jtreg.jar \ /home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk/bin/java \ -Dtest.vm.opts='-ea -esa' \ -Dtest.tool.vm.opts='-J-ea -J-esa' \ -Dtest.compiler.opts= \ -Dtest.java.opts= \ -Dtest.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -Dcompile.jdk=/home/yansendao/git/jdk/build/linux-x86_64-server-release/images/jdk \ -Dtest.timeout.factor=4.0 \ -Dtest.root=/home/yansendao/git/jdk/test/jdk \ -Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#globalsigne46 \ -Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \ -Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -Dtest.classes=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d \ -Dtest.class.path=/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d:/home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/classes/test/lib \ -ea \ -esa \ -Djava.security.debug=certpath,ocsp \ -Dcom.sun.security.ocsp.useget=false \ com.sun.javatest.regtest.agent.MainWrapper /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_globalsigne46.d/main.1.jta globalsigne46 OCSP TEST RESULT: Failed. Execution failed: `main' threw exception: java.lang.RuntimeException: Unhandled exception -------------------------------------------------- Test results: failed: 1 Results written to /home/yansendao/git/jdk/tmp-jtreg-CAInterop.java_globalsigne46/index-10800 Error: Some tests failed or other problems occurred.