TEST: security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.java TEST JDK: /var/tmp/tone/run/jtreg/jdk-repo/build/linux-x86_64-server-release/images/jdk ACTION: build -- Passed. Build successful REASON: User specified action: run build ValidatePathWithParams TIME: 2.218 seconds messages: command: build ValidatePathWithParams reason: User specified action: run build ValidatePathWithParams started: Wed Jun 12 22:02:11 CST 2024 Test directory: compile: ValidatePathWithParams finished: Wed Jun 12 22:02:14 CST 2024 elapsed time (seconds): 2.218 ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 2.218 seconds messages: command: compile /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithParams.java reason: .class file out of date or does not exist started: Wed Jun 12 22:02:11 CST 2024 Mode: othervm finished: Wed Jun 12 22:02:14 CST 2024 elapsed time (seconds): 2.218 configuration: javac compilation environment source path: /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification class path: /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification /var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d rerun: cd /var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA && \ DISPLAY=:7 \ HOME=/home/testUserForTone \ JTREG_VERSION=jtreg-7.3.1.1 \ LANG=C \ LC_CTYPE=C.UTF-8 \ LD_LIBRARY_PATH=/var/tmp/tone/run/jtreg/jdk-repo/build/tools/lib \ PATH=/bin:/usr/bin:/usr/sbin \ TEST_IMAGE_DIR=/var/tmp/tone/run/jtreg/test-images \ /var/tmp/tone/run/jtreg/jdk-repo/build/linux-x86_64-server-release/images/jdk/bin/javac \ -J-Djdk.lang.processReaperUseDefaultStackSize=true \ -J-Dtest.wisp.socketAddress=www.alibabacloud.com \ -J-Xcomp \ -J-XX:TieredStopAtLevel=1 \ -J-ea \ -J-esa \ -J-Dtest.vm.opts='-Djdk.lang.processReaperUseDefaultStackSize=true -Dtest.wisp.socketAddress=www.alibabacloud.com -Xcomp -XX:TieredStopAtLevel=1 -ea -esa' \ -J-Dtest.tool.vm.opts='-J-Djdk.lang.processReaperUseDefaultStackSize=true -J-Dtest.wisp.socketAddress=www.alibabacloud.com -J-Xcomp -J-XX:TieredStopAtLevel=1 -J-ea -J-esa' \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk=/var/tmp/tone/run/jtreg/jdk-repo/build/linux-x86_64-server-release/images/jdk \ -J-Dcompile.jdk=/var/tmp/tone/run/jtreg/jdk-repo/build/linux-x86_64-server-release/images/jdk \ -J-Dtest.timeout.factor=4.0 \ -J-Dtest.nativepath=/var/tmp/tone/run/jtreg/test-images/hotspot/jtreg/native \ -J-Dtest.root=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.java \ -J-Dtest.file=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.java \ -J-Dtest.src=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.src.path=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.classes=/var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d \ -J-Dtest.class.path=/var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d \ -d /var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d \ -sourcepath /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -classpath /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithParams.java STDOUT: STDERR: ACTION: build -- Passed. Build successful REASON: Named class compiled on demand TIME: 1.901 seconds messages: command: build DTrustCA reason: Named class compiled on demand started: Wed Jun 12 22:02:14 CST 2024 Test directory: compile: DTrustCA finished: Wed Jun 12 22:02:16 CST 2024 elapsed time (seconds): 1.901 ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 1.901 seconds messages: command: compile /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.java reason: .class file out of date or does not exist started: Wed Jun 12 22:02:14 CST 2024 Mode: othervm finished: Wed Jun 12 22:02:16 CST 2024 elapsed time (seconds): 1.901 configuration: javac compilation environment source path: /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification class path: /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification /var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d rerun: cd /var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA && \ DISPLAY=:7 \ HOME=/home/testUserForTone \ JTREG_VERSION=jtreg-7.3.1.1 \ LANG=C \ LC_CTYPE=C.UTF-8 \ LD_LIBRARY_PATH=/var/tmp/tone/run/jtreg/jdk-repo/build/tools/lib \ PATH=/bin:/usr/bin:/usr/sbin \ TEST_IMAGE_DIR=/var/tmp/tone/run/jtreg/test-images \ /var/tmp/tone/run/jtreg/jdk-repo/build/linux-x86_64-server-release/images/jdk/bin/javac \ -J-Djdk.lang.processReaperUseDefaultStackSize=true \ -J-Dtest.wisp.socketAddress=www.alibabacloud.com \ -J-Xcomp \ -J-XX:TieredStopAtLevel=1 \ -J-ea \ -J-esa \ -J-Dtest.vm.opts='-Djdk.lang.processReaperUseDefaultStackSize=true -Dtest.wisp.socketAddress=www.alibabacloud.com -Xcomp -XX:TieredStopAtLevel=1 -ea -esa' \ -J-Dtest.tool.vm.opts='-J-Djdk.lang.processReaperUseDefaultStackSize=true -J-Dtest.wisp.socketAddress=www.alibabacloud.com -J-Xcomp -J-XX:TieredStopAtLevel=1 -J-ea -J-esa' \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk=/var/tmp/tone/run/jtreg/jdk-repo/build/linux-x86_64-server-release/images/jdk \ -J-Dcompile.jdk=/var/tmp/tone/run/jtreg/jdk-repo/build/linux-x86_64-server-release/images/jdk \ -J-Dtest.timeout.factor=4.0 \ -J-Dtest.nativepath=/var/tmp/tone/run/jtreg/test-images/hotspot/jtreg/native \ -J-Dtest.root=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.java \ -J-Dtest.file=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.java \ -J-Dtest.src=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.src.path=/var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.classes=/var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d \ -J-Dtest.class.path=/var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d \ -d /var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d \ -sourcepath /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -classpath /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/var/tmp/tone/run/jtreg/jt-work/jtreg/test_jdk/classes/47/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.d /var/tmp/tone/run/jtreg/jdk-repo/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/DTrustCA.java STDOUT: STDERR: ACTION: main -- Failed. Execution failed: `main' threw exception: java.lang.RuntimeException: TEST FAILED: couldn't determine EE certificate status REASON: User specified action: run main/othervm -Djava.security.debug=certpath DTrustCA OCSP TIME: 5.424 seconds messages: command: main -Djava.security.debug=certpath DTrustCA OCSP reason: User specified action: run main/othervm -Djava.security.debug=certpath DTrustCA OCSP started: Wed Jun 12 22:02:16 CST 2024 Mode: othervm [/othervm specified] finished: Wed Jun 12 22:02:21 CST 2024 elapsed time (seconds): 5.424 configuration: STDOUT: ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, SHA1 usage SignedJAR & denyAfter 2019-01-01 Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, SHA1 usage SignedJAR & denyAfter 2019-01-01 Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Validation Date:Thu Jan 01 00:00:00 CST 2015 Expected EE Status:REVOKED Expected EE Revocation Date:Fri Jun 27 00:28:39 CST 2014 ===================================================== Received exception: java.security.cert.CertPathValidatorException: Certificate has been revoked, reason: UNSPECIFIED, revocation date: Fri Jun 27 00:28:39 CST 2014, authority: CN=D-TRUST OCSP 23 SSL Class 3 CA 1 2009, O=D-Trust GmbH, C=DE, extension OIDs: [1.3.6.1.5.5.7.48.1.6, 1.3.36.8.3.13] Expected Certificate status: REVOKED Certificate status after validation: REVOKED Certificate revocation date:Fri Jun 27 00:28:39 CST 2014 Expected revocation date:Fri Jun 27 00:28:39 CST 2014 ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, SHA1 usage SignedJAR & denyAfter 2019-01-01 Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Validation Date:Thu Jan 01 00:00:00 CST 2015 Expected EE Status:REVOKED Expected EE Revocation Date:Fri Jun 27 00:45:14 CST 2014 ===================================================== Received exception: java.security.cert.CertPathValidatorException: OCSP response error: TRY_LATER STDERR: certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 01:00:20 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 09:83:f3 Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01 certpath: Constraints usage length is 1 certpath: Constraints set to denyAfter certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1 certpath: DenyAfterConstraint date set to: 2019-01-01 certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=D-TRUST SSL Class 3 CA 1 2009, O=D-Trust GmbH, C=DE certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): RSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 26724201522434137289335270507166949197415921890249746323790367115462157300731373392766371674690657277775154741031722470766632219347900642251563827102182870641779439502280345401382089423093169588721456236799899161402202223998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB 20 15 ...0.p1..i..p. . 0030: 86 D0 0D F0 BE AC 01 75 84 CE 7E 9F 4D BF B7 60 .......u....M..` 0040: 3B 9C F3 CA 1D E2 5E 68 D8 A3 9D 97 E5 40 60 D2 ;.....^h.....@`. 0050: 36 21 FE D0 B4 B8 17 DA 74 A3 7F D4 DF B0 98 02 6!......t....... 0060: AC 6F 6B 6B 2C 25 24 72 A1 65 EE 25 5A E5 E6 32 .okk,%$r.e.%Z..2 0070: E7 F2 DF AB 49 FA F3 90 69 23 DB 04 D9 E7 5C 58 ....I...i#....\X 0080: FC 65 D4 97 BE CC FC 2E 0A CC 25 2A 35 04 F8 60 .e........%*5..` 0090: 91 15 75 3D 41 FF 23 1F 19 C8 6C EB 82 53 04 A6 ..u=A.#...l..S.. 00A0: E4 4C 22 4D 8D 8C BA CE 5B 73 EC 64 54 50 6D D1 .L"M....[s.dTPm. 00B0: 9C 55 FB 69 C3 36 C3 8C BC 3C 85 A6 6B 0A 26 0D .U.i.6...<..k.&. 00C0: E0 93 98 60 AE 7E C6 24 97 8A 61 5F 91 8E 66 92 ...`...$..a_..f. 00D0: 09 87 36 CD 8B 9B 2D 3E F6 51 D4 50 D4 59 28 BD ..6...->.Q.P.Y(. 00E0: 83 F2 CC 28 7B 53 86 6D D8 26 88 70 D7 EA 91 CD ...(.S.m.&.p.... 00F0: 3E B9 CA C0 90 6E 5A C6 5E 74 65 D7 5C FE A3 E2 >....nZ.^te.\... ] Key: RSA Date: Wed Jun 12 22:02:16 CST 2024 ] certpath: Constraints.permits(): SHA256withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 26724201522434137289335270507166949197415921890249746323790367115462157300731373392766371674690657277775154741031722470766632219347900642251563827102182870641779439502280345401382089423093169588721456236799899161402202223998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB 20 15 ...0.p1..i..p. . 0030: 86 D0 0D F0 BE AC 01 75 84 CE 7E 9F 4D BF B7 60 .......u....M..` 0040: 3B 9C F3 CA 1D E2 5E 68 D8 A3 9D 97 E5 40 60 D2 ;.....^h.....@`. 0050: 36 21 FE D0 B4 B8 17 DA 74 A3 7F D4 DF B0 98 02 6!......t....... 0060: AC 6F 6B 6B 2C 25 24 72 A1 65 EE 25 5A E5 E6 32 .okk,%$r.e.%Z..2 0070: E7 F2 DF AB 49 FA F3 90 69 23 DB 04 D9 E7 5C 58 ....I...i#....\X 0080: FC 65 D4 97 BE CC FC 2E 0A CC 25 2A 35 04 F8 60 .e........%*5..` 0090: 91 15 75 3D 41 FF 23 1F 19 C8 6C EB 82 53 04 A6 ..u=A.#...l..S.. 00A0: E4 4C 22 4D 8D 8C BA CE 5B 73 EC 64 54 50 6D D1 .L"M....[s.dTPm. 00B0: 9C 55 FB 69 C3 36 C3 8C BC 3C 85 A6 6B 0A 26 0D .U.i.6...<..k.&. 00C0: E0 93 98 60 AE 7E C6 24 97 8A 61 5F 91 8E 66 92 ...`...$..a_..f. 00D0: 09 87 36 CD 8B 9B 2D 3E F6 51 D4 50 D4 59 28 BD ..6...->.Q.P.Y(. 00E0: 83 F2 CC 28 7B 53 86 6D D8 26 88 70 D7 EA 91 CD ...(.S.m.&.p.... 00F0: 3E B9 CA C0 90 6E 5A C6 5E 74 65 D7 5C FE A3 E2 >....nZ.^te.\... ] Cert Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Cert Subject: CN=D-TRUST SSL Class 3 CA 1 2009, O=D-Trust GmbH, C=DE Key: RSA Date: Wed Jun 12 22:02:16 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.5.29.32.0 certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Wed Jun 12 22:02:16 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE; subject: CN=D-TRUST SSL Class 3 CA 1 2009, O=D-Trust GmbH, C=DE; serial#: 09:90:63 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 09:90:63 Subject: CN=D-TRUST SSL Class 3 CA 1 2009, O=D-Trust GmbH, C=DE Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE certpath: com.sun.security.ocsp.timeout set to 15000 milliseconds certpath: com.sun.security.ocsp.readtimeout set to 15000 milliseconds certpath: com.sun.security.ocsp.useget set to true certpath: connecting to OCSP service at: http://root-c3-ca2-2009.ocsp.d-trust.net certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byName: CN=D-TRUST OCSP 23 Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE certpath: OCSP response produced at: Wed Jun 12 22:01:58 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Wed Jun 12 22:01:58 CST 2024 certpath: nextUpdate: Thu Jun 13 22:01:58 CST 2024 certpath: Extension: ObjectId: 1.3.36.8.3.13 Criticality=false certpath: Extension: ObjectId: 1.3.6.1.5.5.7.48.1.6 Criticality=false certpath: singleExtension: ObjectId: 1.3.6.1.5.5.7.48.1.6 Criticality=false certpath: singleExtension: ObjectId: 1.3.36.8.3.13 Criticality=false certpath: OCSP response cert #1: CN=D-TRUST OCSP 23 Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE certpath: OCSP response cert #2: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE certpath: Status of certificate (with serial number 09:90:63) is: GOOD certpath: Constraints.permits(): RSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 26724201522434137289335270507166949197415921890249746323790367115462157300731373392766371674690657277775154741031722470766632219347900642251563827102182870641779439502280345401382089423093169588721456236799899161402202223998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB 20 15 ...0.p1..i..p. . 0030: 86 D0 0D F0 BE AC 01 75 84 CE 7E 9F 4D BF B7 60 .......u....M..` 0040: 3B 9C F3 CA 1D E2 5E 68 D8 A3 9D 97 E5 40 60 D2 ;.....^h.....@`. 0050: 36 21 FE D0 B4 B8 17 DA 74 A3 7F D4 DF B0 98 02 6!......t....... 0060: AC 6F 6B 6B 2C 25 24 72 A1 65 EE 25 5A E5 E6 32 .okk,%$r.e.%Z..2 0070: E7 F2 DF AB 49 FA F3 90 69 23 DB 04 D9 E7 5C 58 ....I...i#....\X 0080: FC 65 D4 97 BE CC FC 2E 0A CC 25 2A 35 04 F8 60 .e........%*5..` 0090: 91 15 75 3D 41 FF 23 1F 19 C8 6C EB 82 53 04 A6 ..u=A.#...l..S.. 00A0: E4 4C 22 4D 8D 8C BA CE 5B 73 EC 64 54 50 6D D1 .L"M....[s.dTPm. 00B0: 9C 55 FB 69 C3 36 C3 8C BC 3C 85 A6 6B 0A 26 0D .U.i.6...<..k.&. 00C0: E0 93 98 60 AE 7E C6 24 97 8A 61 5F 91 8E 66 92 ...`...$..a_..f. 00D0: 09 87 36 CD 8B 9B 2D 3E F6 51 D4 50 D4 59 28 BD ..6...->.Q.P.Y(. 00E0: 83 F2 CC 28 7B 53 86 6D D8 26 88 70 D7 EA 91 CD ...(.S.m.&.p.... 00F0: 3E B9 CA C0 90 6E 5A C6 5E 74 65 D7 5C FE A3 E2 >....nZ.^te.\... ] Key: RSA ] certpath: Constraints.permits(): SHA256withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 26724201522434137289335270507166949197415921890249746323790367115462157300731373392766371674690657277775154741031722470766632219347900642251563827102182870641779439502280345401382089423093169588721456236799899161402202223998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB 20 15 ...0.p1..i..p. . 0030: 86 D0 0D F0 BE AC 01 75 84 CE 7E 9F 4D BF B7 60 .......u....M..` 0040: 3B 9C F3 CA 1D E2 5E 68 D8 A3 9D 97 E5 40 60 D2 ;.....^h.....@`. 0050: 36 21 FE D0 B4 B8 17 DA 74 A3 7F D4 DF B0 98 02 6!......t....... 0060: AC 6F 6B 6B 2C 25 24 72 A1 65 EE 25 5A E5 E6 32 .okk,%$r.e.%Z..2 0070: E7 F2 DF AB 49 FA F3 90 69 23 DB 04 D9 E7 5C 58 ....I...i#....\X 0080: FC 65 D4 97 BE CC FC 2E 0A CC 25 2A 35 04 F8 60 .e........%*5..` 0090: 91 15 75 3D 41 FF 23 1F 19 C8 6C EB 82 53 04 A6 ..u=A.#...l..S.. 00A0: E4 4C 22 4D 8D 8C BA CE 5B 73 EC 64 54 50 6D D1 .L"M....[s.dTPm. 00B0: 9C 55 FB 69 C3 36 C3 8C BC 3C 85 A6 6B 0A 26 0D .U.i.6...<..k.&. 00C0: E0 93 98 60 AE 7E C6 24 97 8A 61 5F 91 8E 66 92 ...`...$..a_..f. 00D0: 09 87 36 CD 8B 9B 2D 3E F6 51 D4 50 D4 59 28 BD ..6...->.Q.P.Y(. 00E0: 83 F2 CC 28 7B 53 86 6D D8 26 88 70 D7 EA 91 CD ...(.S.m.&.p.... 00F0: 3E B9 CA C0 90 6E 5A C6 5E 74 65 D7 5C FE A3 E2 >....nZ.^te.\... ] Cert Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Cert Subject: CN=D-TRUST OCSP 23 Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Key: RSA ] certpath: Responder's certificate includes the extension id-pkix-ocsp-nocheck. certpath: OCSP response is signed by an Authorized Responder certpath: Constraints.permits(): SHA256withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 26724201522434137289335270507166949197415921890249746323790367115462157300731373392766371674690657277775154741031722470766632219347900642251563827102182870641779439502280345401382089423093169588721456236799899161402202223998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB 20 15 ...0.p1..i..p. . 0030: 86 D0 0D F0 BE AC 01 75 84 CE 7E 9F 4D BF B7 60 .......u....M..` 0040: 3B 9C F3 CA 1D E2 5E 68 D8 A3 9D 97 E5 40 60 D2 ;.....^h.....@`. 0050: 36 21 FE D0 B4 B8 17 DA 74 A3 7F D4 DF B0 98 02 6!......t....... 0060: AC 6F 6B 6B 2C 25 24 72 A1 65 EE 25 5A E5 E6 32 .okk,%$r.e.%Z..2 0070: E7 F2 DF AB 49 FA F3 90 69 23 DB 04 D9 E7 5C 58 ....I...i#....\X 0080: FC 65 D4 97 BE CC FC 2E 0A CC 25 2A 35 04 F8 60 .e........%*5..` 0090: 91 15 75 3D 41 FF 23 1F 19 C8 6C EB 82 53 04 A6 ..u=A.#...l..S.. 00A0: E4 4C 22 4D 8D 8C BA CE 5B 73 EC 64 54 50 6D D1 .L"M....[s.dTPm. 00B0: 9C 55 FB 69 C3 36 C3 8C BC 3C 85 A6 6B 0A 26 0D .U.i.6...<..k.&. 00C0: E0 93 98 60 AE 7E C6 24 97 8A 61 5F 91 8E 66 92 ...`...$..a_..f. 00D0: 09 87 36 CD 8B 9B 2D 3E F6 51 D4 50 D4 59 28 BD ..6...->.Q.P.Y(. 00E0: 83 F2 CC 28 7B 53 86 6D D8 26 88 70 D7 EA 91 CD ...(.S.m.&.p.... 00F0: 3E B9 CA C0 90 6E 5A C6 5E 74 65 D7 5C FE A3 E2 >....nZ.^te.\... ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Wed Jun 12 22:01:58 CST 2024 until Thu Jun 13 22:01:58 CST 2024 certpath: Checking validity of OCSP response on Wed Jun 12 22:02:17 CST 2024 with allowed interval between Wed Jun 12 21:47:17 CST 2024 and Wed Jun 12 22:17:17 CST 2024 certpath: -checker7 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: CN=certdemo-ov-valid.ssl.d-trust.net, O=D-Trust GmbH, OU=IT, L=Berlin, ST=Berlin, C=DE, SERIALNUMBER=DTRWS354803406304201, DNQ=7223150018 certpath: Set of critical extensions: {2.5.29.15} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA256withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 26724201522434137289335270507166949197415921890249746323790367115462157300731373392766371674690657277775154741031722470766632219347900642251563827102182870641779439502280345401382089423093169588721456236799899161402202223998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB 20 15 ...0.p1..i..p. . 0030: 86 D0 0D F0 BE AC 01 75 84 CE 7E 9F 4D BF B7 60 .......u....M..` 0040: 3B 9C F3 CA 1D E2 5E 68 D8 A3 9D 97 E5 40 60 D2 ;.....^h.....@`. 0050: 36 21 FE D0 B4 B8 17 DA 74 A3 7F D4 DF B0 98 02 6!......t....... 0060: AC 6F 6B 6B 2C 25 24 72 A1 65 EE 25 5A E5 E6 32 .okk,%$r.e.%Z..2 0070: E7 F2 DF AB 49 FA F3 90 69 23 DB 04 D9 E7 5C 58 ....I...i#....\X 0080: FC 65 D4 97 BE CC FC 2E 0A CC 25 2A 35 04 F8 60 .e........%*5..` 0090: 91 15 75 3D 41 FF 23 1F 19 C8 6C EB 82 53 04 A6 ..u=A.#...l..S.. 00A0: E4 4C 22 4D 8D 8C BA CE 5B 73 EC 64 54 50 6D D1 .L"M....[s.dTPm. 00B0: 9C 55 FB 69 C3 36 C3 8C BC 3C 85 A6 6B 0A 26 0D .U.i.6...<..k.&. 00C0: E0 93 98 60 AE 7E C6 24 97 8A 61 5F 91 8E 66 92 ...`...$..a_..f. 00D0: 09 87 36 CD 8B 9B 2D 3E F6 51 D4 50 D4 59 28 BD ..6...->.Q.P.Y(. 00E0: 83 F2 CC 28 7B 53 86 6D D8 26 88 70 D7 EA 91 CD ...(.S.m.&.p.... 00F0: 3E B9 CA C0 90 6E 5A C6 5E 74 65 D7 5C FE A3 E2 >....nZ.^te.\... ] Cert Issuer: CN=D-TRUST SSL Class 3 CA 1 2009, O=D-Trust GmbH, C=DE Cert Subject: CN=certdemo-ov-valid.ssl.d-trust.net, O=D-Trust GmbH, OU=IT, L=Berlin, ST=Berlin, C=DE, SERIALNUMBER=DTRWS354803406304201, DNQ=7223150018 Key: RSA Date: Wed Jun 12 22:02:16 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.4788.2.200.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) 1.3.6.1.4.1.4788.2.200.1 CRIT: false EP: 1.3.6.1.4.1.4788.2.200.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Wed Jun 12 22:02:16 CST 2024... certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 0c:be Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW) certpath: X509CertSelector.match: subject DNs don't match certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 0c:be Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 09:83:f3 Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=D-TRUST SSL Class 3 CA 1 2009, O=D-Trust GmbH, C=DE certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): RSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 26724201522434137289335270507166949197415921890249746323790367115462157300731373392766371674690657277775154741031722470766632219347900642251563827102182870641779439502280345401382089423093169588721456236799899161402202223998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB ... Output overflow: JT Harness has limited the test output to the text at the beginning and the end, so that you can see how the test began, and how it completed. If you need to see more of the output from the test, set the system property javatest.maxOutputSize to a higher value. The current value is 100000 ... 3998937256231175704692880742029055390031468823489456520136747517890586160110220479842231796558781326902325444481557078451532294948037027720108897561290597573027298906576835874315779324585800977183424782123900623397828902039804064653423500283877618238150178222951038922132483686951491872057489428707443422592700947403027966897077753708830178987452525361751323537892221113692591631438484370801823173 public exponent: 65537 Validity: [From: Thu Nov 05 16:35:58 CST 2009, To: Mon Nov 05 16:35:58 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f3 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: FD DA 14 C4 9F 30 DE 21 BD 1E 42 39 FC AB 63 23 .....0.!..B9..c# 0010: 49 E0 F1 84 I... ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 7F 97 DB 30 C8 DF A4 9C 7D 21 7A 80 70 CE 14 12 ...0.....!z.p... 0010: 69 88 14 95 60 44 01 AC B2 E9 30 4F 9B 50 C2 66 i...`D....0O.P.f 0020: D8 7E 8D 30 B5 70 31 E9 E2 69 C7 F3 70 DB 20 15 ...0.p1..i..p. . 0030: 86 D0 0D F0 BE AC 01 75 84 CE 7E 9F 4D BF B7 60 .......u....M..` 0040: 3B 9C F3 CA 1D E2 5E 68 D8 A3 9D 97 E5 40 60 D2 ;.....^h.....@`. 0050: 36 21 FE D0 B4 B8 17 DA 74 A3 7F D4 DF B0 98 02 6!......t....... 0060: AC 6F 6B 6B 2C 25 24 72 A1 65 EE 25 5A E5 E6 32 .okk,%$r.e.%Z..2 0070: E7 F2 DF AB 49 FA F3 90 69 23 DB 04 D9 E7 5C 58 ....I...i#....\X 0080: FC 65 D4 97 BE CC FC 2E 0A CC 25 2A 35 04 F8 60 .e........%*5..` 0090: 91 15 75 3D 41 FF 23 1F 19 C8 6C EB 82 53 04 A6 ..u=A.#...l..S.. 00A0: E4 4C 22 4D 8D 8C BA CE 5B 73 EC 64 54 50 6D D1 .L"M....[s.dTPm. 00B0: 9C 55 FB 69 C3 36 C3 8C BC 3C 85 A6 6B 0A 26 0D .U.i.6...<..k.&. 00C0: E0 93 98 60 AE 7E C6 24 97 8A 61 5F 91 8E 66 92 ...`...$..a_..f. 00D0: 09 87 36 CD 8B 9B 2D 3E F6 51 D4 50 D4 59 28 BD ..6...->.Q.P.Y(. 00E0: 83 F2 CC 28 7B 53 86 6D D8 26 88 70 D7 EA 91 CD ...(.S.m.&.p.... 00F0: 3E B9 CA C0 90 6E 5A C6 5E 74 65 D7 5C FE A3 E2 >....nZ.^te.\... ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Wed Jun 12 22:02:18 CST 2024 until Thu Jun 13 22:02:18 CST 2024 certpath: Checking validity of OCSP response on Wed Jun 12 22:02:18 CST 2024 with allowed interval between Wed Jun 12 21:47:18 CST 2024 and Wed Jun 12 22:17:18 CST 2024 certpath: X509CertSelector.match(Serial number: 01:00:20 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 0c:be Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 01:00:20 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 09:83:f4 Issuer: CN=D-TRUST Root Class 3 CA 2 EV 2009, O=D-Trust GmbH, C=DE Subject: CN=D-TRUST Root Class 3 CA 2 EV 2009, O=D-Trust GmbH, C=DE) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=D-TRUST Root Class 3 CA 2 EV 2009, O=D-Trust GmbH, C=DE certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=D-TRUST SSL Class 3 CA 1 EV 2009, O=D-Trust GmbH, C=DE certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): RSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=D-TRUST Root Class 3 CA 2 EV 2009, O=D-Trust GmbH, C=DE Signature Algorithm: SHA256withRSA, OID = 1.2.840.113549.1.1.11 Key: Sun RSA public key, 2048 bits params: null modulus: 19433556847837019840606200191248436601054120485771157601288645519736173618047465011741481487651021384493549955989498982475980813761289359053152837346417920823756875200691648424961484623093435712979383064241900489852345879275457329691108610236732795083196866237553320151717334440851150683643572544795711598985752083358023655872389888412184301674329827459219268339852829936243363099017072357722762563204287131800596545661582660699955630082534810484020660655829480662422319473060709494923323266729571374792293205970154391229787824063468849360943765308592527255872838061874599503071289267222755399270040829047112029662117 public exponent: 65537 Validity: [From: Thu Nov 05 16:50:46 CST 2009, To: Mon Nov 05 16:50:46 CST 2029] Issuer: CN=D-TRUST Root Class 3 CA 2 EV 2009, O=D-Trust GmbH, C=DE SerialNumber: 09:83:f4 Certificate Extensions: 4 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.31 Criticality=false CRLDistributionPoints [ [DistributionPoint: [URIName: ldap://directory.d-trust.net/CN=D-TRUST%20Root%20Class%203%20CA%202%20EV%202009,O=D-Trust%20GmbH,C=DE?certificaterevocationlist] , DistributionPoint: [URIName: http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_ev_2009.crl] ]] [3]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [4]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: D3 94 8A 4C 62 13 2A 19 2E CC AF 72 8A 7D 36 D7 ...Lb.*....r..6. 0010: 9A 1C DC 67 ...g ] ] ] Algorithm: [SHA256withRSA] Signature: 0000: 34 ED 7B 5A 3C A4 94 88 EF 1A 11 75 07 2F B3 FE 4..Z<......u./.. 0010: 3C FA 1E 51 26 EB 87 F6 29 DE E0 F1 D4 C6 24 09 <..Q&...).....$. 0020: E9 C1 CF 55 1B B4 30 D9 CE 1A FE 06 51 A6 15 A4 ...U..0.....Q... 0030: 2D EF B2 4B BF 20 28 25 49 D1 A6 36 77 34 E8 64 -..K. (%I..6w4.d 0040: DF 52 B1 11 C7 73 7A CD 39 9E C2 AD 8C 71 21 F2 .R...sz.9....q!. 0050: 5A 6B AF DF 3C 4E 55 AF B2 84 65 14 89 B9 77 CB Zk..