Directory "tmp" not found: creating
--------------------------------------------------
TEST: security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5
TEST JDK: /home/yansendao/software/jdk/openjdk/jdk-binary

ACTION: build -- Passed. Build successful
REASON: User specified action: run build jtreg.SkippedException ValidatePathWithURL CAInterop 
TIME:   1.781 seconds
messages:
command: build jtreg.SkippedException ValidatePathWithURL CAInterop
reason: User specified action: run build jtreg.SkippedException ValidatePathWithURL CAInterop 
started: Thu Jun 13 17:38:31 CST 2024
Library /test/lib:
  compile: jtreg.SkippedException
Test directory:
  compile: ValidatePathWithURL, CAInterop
finished: Thu Jun 13 17:38:33 CST 2024
elapsed time (seconds): 1.781

ACTION: compile -- Passed. Compilation successful
REASON: .class file out of date or does not exist
TIME:   0.72 seconds
messages:
command: compile /home/yansendao/git/jdk/test/lib/jtreg/SkippedException.java
reason: .class file out of date or does not exist
started: Thu Jun 13 17:38:31 CST 2024
Mode: othervm
finished: Thu Jun 13 17:38:32 CST 2024
elapsed time (seconds): 0.72
configuration:
javac compilation environment
  source path: /home/yansendao/git/jdk/test/lib
  class path:  /home/yansendao/git/jdk/tmp/classes/test/lib

rerun:
cd /home/yansendao/git/jdk/tmp/scratch && \
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \
DISPLAY=:7 \
HOME=/home/yansendao \
LANG=en_US.UTF-8 \
PATH=/bin:/usr/bin:/usr/sbin \
XDG_RUNTIME_DIR=/run/user/995 \
XDG_SESSION_ID=1273615 \
    /home/yansendao/software/jdk/openjdk/jdk-binary/bin/javac \
        -J-Dtest.vm.opts= \
        -J-Dtest.tool.vm.opts= \
        -J-Dtest.compiler.opts= \
        -J-Dtest.java.opts= \
        -J-Dtest.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \
        -J-Dcompile.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \
        -J-Dtest.timeout.factor=1.0 \
        -J-Dtest.root=/home/yansendao/git/jdk/test/jdk \
        -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5 \
        -J-Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \
        -J-Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \
        -J-Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \
        -J-Dtest.classes=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \
        -J-Dtest.class.path=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib \
        -d /home/yansendao/git/jdk/tmp/classes/test/lib \
        -sourcepath /home/yansendao/git/jdk/test/lib \
        -classpath /home/yansendao/git/jdk/tmp/classes/test/lib /home/yansendao/git/jdk/test/lib/jtreg/SkippedException.java
STDOUT:
STDERR:

ACTION: compile -- Passed. Compilation successful
REASON: .class file out of date or does not exist
TIME:   1.055 seconds
messages:
command: compile /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java
reason: .class file out of date or does not exist
started: Thu Jun 13 17:38:32 CST 2024
Mode: othervm
finished: Thu Jun 13 17:38:33 CST 2024
elapsed time (seconds): 1.055
configuration:
javac compilation environment
  source path: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification
               /home/yansendao/git/jdk/test/lib
  class path:  /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification
               /home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d
               /home/yansendao/git/jdk/tmp/classes/test/lib

rerun:
cd /home/yansendao/git/jdk/tmp/scratch && \
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \
DISPLAY=:7 \
HOME=/home/yansendao \
LANG=en_US.UTF-8 \
PATH=/bin:/usr/bin:/usr/sbin \
XDG_RUNTIME_DIR=/run/user/995 \
XDG_SESSION_ID=1273615 \
    /home/yansendao/software/jdk/openjdk/jdk-binary/bin/javac \
        -J-Dtest.vm.opts= \
        -J-Dtest.tool.vm.opts= \
        -J-Dtest.compiler.opts= \
        -J-Dtest.java.opts= \
        -J-Dtest.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \
        -J-Dcompile.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \
        -J-Dtest.timeout.factor=1.0 \
        -J-Dtest.root=/home/yansendao/git/jdk/test/jdk \
        -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5 \
        -J-Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \
        -J-Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \
        -J-Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \
        -J-Dtest.classes=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \
        -J-Dtest.class.path=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib \
        -d /home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \
        -sourcepath /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \
        -classpath /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java
STDOUT:
STDERR:
Note: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java uses or overrides a deprecated API.
Note: Recompile with -Xlint:deprecation for details.

ACTION: build -- Passed. All files up to date
REASON: Named class compiled on demand
TIME:   0.0 seconds
messages:
command: build CAInterop
reason: Named class compiled on demand
started: Thu Jun 13 17:38:33 CST 2024
finished: Thu Jun 13 17:38:33 CST 2024
elapsed time (seconds): 0.0

ACTION: main -- Failed. Execution failed: `main' threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com
REASON: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp CAInterop digicerttlsrsarootg5 OCSP 
TIME:   2.811 seconds
messages:
command: main -Djava.security.debug=certpath,ocsp CAInterop digicerttlsrsarootg5 OCSP
reason: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp CAInterop digicerttlsrsarootg5 OCSP 
started: Thu Jun 13 17:38:33 CST 2024
Mode: othervm [/othervm specified]
finished: Thu Jun 13 17:38:36 CST 2024
elapsed time (seconds): 2.811
configuration:
STDOUT:
=====================================================
CONFIGURATION
=====================================================
http.proxyHost :null
http.proxyPort :null
https.proxyHost :null
https.proxyPort :null
https.socksProxyHost :null
https.socksProxyPort :null
jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, SHA1 usage SignedJAR & denyAfter 2019-01-01
com.sun.security.enableCRLDP :false
ocsp.enable :true
=====================================================

===== Validate https://digicert-tls-rsa4096-root-g5.chain-demos.digicert.com=====
Finding intermediate certificate issued by CA
Checking: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
Checking: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
Found intermediate root CA: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
intermediate CA Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
Verified: Intermediate CA signed by test root CA
======> SUCCESS

===== Validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com=====
Finding intermediate certificate issued by CA
Checking: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
Checking: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
Found intermediate root CA: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
intermediate CA Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
Verified: Intermediate CA signed by test root CA
STDERR:
certpath: Constraints: 3DES_EDE_CBC
certpath: Constraints: anon
certpath: Constraints: DES
certpath: Constraints: DH keySize < 1024
certpath: Constraints set to keySize: keySize < 1024
certpath: Constraints: DTLSv1.0
certpath: Constraints: EC keySize < 224
certpath: Constraints set to keySize: keySize < 224
certpath: Constraints: ECDH
certpath: Constraints: MD5withRSA
certpath: Constraints: NULL
certpath: Constraints: RC4
certpath: Constraints: SSLv3
certpath: Constraints: TLSv1
certpath: Constraints: TLSv1.1
certpath: Constraints: DSA keySize < 1024
certpath: Constraints set to keySize: keySize < 1024
certpath: Constraints: EC keySize < 224
certpath: Constraints set to keySize: keySize < 224
certpath: Constraints: MD2
certpath: Constraints: MD5
certpath: Constraints: RSA keySize < 1024
certpath: Constraints set to keySize: keySize < 1024
certpath: Constraints: SHA1 jdkCA & usage TLSServer
certpath: Constraints set to jdkCA.
certpath: Constraints usage length is 1
certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01
certpath: Constraints usage length is 1
certpath: Constraints set to denyAfter
certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1
certpath: DenyAfterConstraint date set to: 2019-01-01
certpath: PKIXCertPathValidator.engineValidate()...
certpath: X509CertSelector.match(Serial number: 01:00:20
  Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL
  Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL)
certpath: X509CertSelector.match: subject DNs don't match
certpath: X509CertSelector.match(Serial number: 0c:be
  Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW
  Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW)
certpath: X509CertSelector.match: subject DNs don't match
certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57
  Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
  Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US)
certpath: X509CertSelector.match: subject DNs don't match
certpath: X509CertSelector.match(Serial number: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US)
certpath: X509CertSelector.match returning: true
certpath: YES - try this trustedCert
certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
certpath: Constraints: DSA keySize < 1024
certpath: Constraints set to keySize: keySize < 1024
certpath: Constraints: EC keySize < 224
certpath: Constraints set to keySize: keySize < 224
certpath: Constraints: MD2
certpath: Constraints: MD5
certpath: Constraints: RSA keySize < 1024
certpath: Constraints set to keySize: keySize < 1024
certpath: Constraints: SHA1 jdkCA & usage TLSServer
certpath: Constraints set to jdkCA.
certpath: Constraints usage length is 1
certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01
certpath: Constraints usage length is 1
certpath: Constraints set to denyAfter
certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1
certpath: DenyAfterConstraint date set to: 2019-01-01
certpath: --------------------------------------------------------------
certpath: Executing PKIX certification path validation algorithm.
certpath: Checking cert1 - Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19}
certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker]
certpath: -checker1 validation succeeded
certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: Constraints.permits(): RSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Key: RSA
  Date: Thu Jun 13 17:38:34 CST 2024
]
certpath: Constraints.permits(): SHA384withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Cert Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Cert Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
  Key: RSA
  Date: Thu Jun 13 17:38:34 CST 2024
]
certpath: -checker2 validation succeeded
certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker]
certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage...
certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified.
certpath: -checker3 validation succeeded
certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker]
certpath: ---checking basic constraints...
certpath: i = 1, maxPathLength = 2
certpath: after processing, maxPathLength = 0
certpath: basic constraints verified.
certpath: ---checking name constraints...
certpath: prevNC = null, newNC = null
certpath: mergedNC = null
certpath: name constraints verified.
certpath: -checker4 validation succeeded
certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker]
certpath: PolicyChecker.checkPolicy() ---checking certificate policies...
certpath: PolicyChecker.checkPolicy() certIndex = 1
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() policiesCritical = false
certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true
certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.2
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.3
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy  ROOT
  2.23.140.1.2.3  CRIT: false  EP: 2.23.140.1.2.3  (1)
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)
  2.23.140.1.2.2  CRIT: false  EP: 2.23.140.1.2.2  (1)
  2.23.140.1.2.1  CRIT: false  EP: 2.23.140.1.2.1  (1)
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)

certpath: PolicyChecker.checkPolicy() certificate policies verified
certpath: -checker5 validation succeeded
certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker]
certpath: ---checking validity:Thu Jun 13 17:38:34 CST 2024...
certpath: validity verified.
certpath: ---checking subject/issuer name chaining...
certpath: subject/issuer name chaining verified.
certpath: ---checking signature...
certpath: signature verified.
certpath: BasicChecker.updateState issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US; subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; serial#: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58
certpath: -checker6 validation succeeded
certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: -checker7 validation succeeded
certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker]
certpath: RevocationChecker.check: checking cert
  SN: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58
  Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
certpath: com.sun.security.ocsp.timeout set to 15000 milliseconds
certpath: com.sun.security.ocsp.readtimeout set to 15000 milliseconds
certpath: com.sun.security.ocsp.useget set to true
certpath: OCSPRequest bytes...

0000: 30 51 30 4F 30 4D 30 4B   30 49 30 09 06 05 2B 0E  0Q0O0M0K0I0...+.
0010: 03 02 1A 05 00 04 14 7E   63 ED 24 CF D5 32 DB 5D  ........c.$..2.]
0020: 6E 66 AC EE 11 49 16 89   47 A2 0D 04 14 51 33 1C  nf...I..G....Q3.
0030: ED 36 40 AF 17 D3 25 CD   69 68 F2 AF 4E 23 3E B3  .6@...%.ih..N#>.
0040: 41 02 10 0E 64 58 E7 54   EC 9C C7 BA C8 32 31 D5  A...dX.T.....21.
0050: F9 4D 58 

certpath: connecting to OCSP service at: http://ocsp.digicert.com
certpath: OCSPResponse bytes...

0000: 30 82 02 D3 0A 01 00 A0   82 02 CC 30 82 02 C8 06  0..........0....
0010: 09 2B 06 01 05 05 07 30   01 01 04 82 02 B9 30 82  .+.....0......0.
0020: 02 B5 30 81 9E A2 16 04   14 51 33 1C ED 36 40 AF  ..0......Q3..6@.
0030: 17 D3 25 CD 69 68 F2 AF   4E 23 3E B3 41 18 0F 32  ..%.ih..N#>.A..2
0040: 30 32 34 30 36 31 32 31   38 33 39 34 33 5A 30 73  0240612183943Z0s
0050: 30 71 30 49 30 09 06 05   2B 0E 03 02 1A 05 00 04  0q0I0...+.......
0060: 14 7E 63 ED 24 CF D5 32   DB 5D 6E 66 AC EE 11 49  ..c.$..2.]nf...I
0070: 16 89 47 A2 0D 04 14 51   33 1C ED 36 40 AF 17 D3  ..G....Q3..6@...
0080: 25 CD 69 68 F2 AF 4E 23   3E B3 41 02 10 0E 64 58  %.ih..N#>.A...dX
0090: E7 54 EC 9C C7 BA C8 32   31 D5 F9 4D 58 80 00 18  .T.....21..MX...
00A0: 0F 32 30 32 34 30 36 31   32 31 38 33 39 34 33 5A  .20240612183943Z
00B0: A0 11 18 0F 32 30 32 34   30 36 31 39 31 38 33 39  ....202406191839
00C0: 34 33 5A 30 0D 06 09 2A   86 48 86 F7 0D 01 01 0C  43Z0...*.H......
00D0: 05 00 03 82 02 01 00 41   21 88 4E AD DE 59 78 47  .......A!.N..YxG
00E0: 4C 3C B9 56 33 50 D6 C2   56 3F BD A1 7B E8 99 35  L<.V3P..V?.....5
00F0: 4A E4 E9 DC 5A 43 A7 A3   E7 F2 46 C3 76 A5 60 96  J...ZC....F.v.`.
0100: 9C 0A 50 58 BA 15 44 29   2B 27 70 68 5D A9 E9 E7  ..PX..D)+'ph]...
0110: 57 06 36 A5 20 AA 52 D9   30 09 9C 12 93 60 97 26  W.6. .R.0....`.&
0120: C4 E2 C7 9B D1 91 FA CE   6E C4 5D 79 7A 07 C9 2E  ........n.]yz...
0130: 10 63 B8 AA 21 87 4A 51   E7 60 72 3E 27 42 90 49  .c..!.JQ.`r>'B.I
0140: 76 82 99 A4 A7 F3 C5 D0   76 97 73 78 64 48 8B EE  v.......v.sxdH..
0150: AD 93 C7 98 57 0F AD 81   E2 22 FA 84 86 47 F3 66  ....W...."...G.f
0160: 57 53 5E F1 17 9B CD 43   B3 96 95 F6 30 39 B7 D7  WS^....C....09..
0170: 2A 0C 7A 51 30 92 6A B5   D9 03 53 7D 34 D1 E1 54  *.zQ0.j...S.4..T
0180: CA 73 9D 0F 85 C0 E7 8F   28 0E 6D 6C 3E C0 48 C8  .s......(.ml>.H.
0190: 57 F3 6D 27 34 98 73 7F   9B 98 6C D4 68 C0 62 AB  W.m'4.s...l.h.b.
01A0: 7A BC 91 D1 64 E7 00 BC   0C 17 DF 0D 37 0B D3 C6  z...d.......7...
01B0: EB 99 E9 95 E5 22 16 06   5E 4A 56 A4 36 90 BB C5  ....."..^JV.6...
01C0: AF E3 2B 3F 3E 06 2C 30   CA 69 CE CA C1 98 BD FC  ..+?>.,0.i......
01D0: A5 60 59 E3 61 8A 50 FA   78 FE 1D 4A D2 36 85 05  .`Y.a.P.x..J.6..
01E0: 3A 1C 26 8D FA CB 00 6F   6F 78 58 87 54 CE 3E 27  :.&....ooxX.T.>'
01F0: 50 F1 7F 0A 4B C8 54 49   C3 18 ED EE 68 FE 75 2A  P...K.TI....h.u*
0200: 3B FC E9 22 EE 79 A7 09   C4 D7 04 38 1B 67 0D 6B  ;..".y.....8.g.k
0210: 90 86 ED 8C 09 A0 08 FF   5A 25 5C A5 84 0D 6E 2C  ........Z%\...n,
0220: CC EB C3 1F 22 9F 5F 24   0C 69 C7 F3 6A D9 27 C1  ...."._$.i..j.'.
0230: 30 72 39 A4 BC FA 0F 94   DF BB 2B 8F BB D0 E2 A6  0r9.......+.....
0240: 6D AC A8 4E 29 F4 BC BA   E4 51 8E AA 3D D1 4D AE  m..N)....Q..=.M.
0250: A0 2C 34 76 04 BE D1 B2   61 53 94 EE 08 73 CE 69  .,4v....aS...s.i
0260: E6 46 7B D2 CA 7F CD 3D   64 97 59 4D F4 F9 4B 8E  .F.....=d.YM..K.
0270: C3 75 58 DC 07 7C 1E A5   8E C1 BD 4C B7 9D 7E 7E  .uX........L....
0280: 13 B5 13 0A 33 74 3F 48   5D C2 8E 7E 65 22 13 03  ....3t?H]...e"..
0290: 6B 93 60 EC 12 A8 1B CF   D5 F8 32 4D ED 5E 10 0B  k.`.......2M.^..
02A0: 11 14 23 E6 C9 B4 26 03   32 38 99 C1 9C 97 8E 47  ..#...&.28.....G
02B0: 55 55 13 5E 4F EB 22 FA   1A 5A 6E 1A 92 53 45 53  UU.^O."..Zn..SES
02C0: B8 C7 C4 43 96 30 35 C8   39 FD 77 8D 08 28 36 16  ...C.05.9.w..(6.
02D0: 41 5F 59 39 C6 A7 4D 

certpath: OCSP response status: SUCCESSFUL
certpath: OCSP response type: basic
certpath: Responder ID: byKey: 51331CED3640AF17D325CD6968F2AF4E233EB341
certpath: OCSP response produced at: Thu Jun 13 02:39:43 CST 2024
certpath: OCSP number of SingleResponses: 1
certpath: thisUpdate: Thu Jun 13 02:39:43 CST 2024
certpath: nextUpdate: Thu Jun 20 02:39:43 CST 2024
certpath: Status of certificate (with serial number 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58) is: GOOD
certpath: OCSP response is signed by the target's Issuing CA
certpath: Constraints.permits(): SHA384withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Key: RSA
]
certpath: Verified signature of OCSP Response
certpath: OCSP response validity interval is from Thu Jun 13 02:39:43 CST 2024 until Thu Jun 20 02:39:43 CST 2024
certpath: Checking validity of OCSP response on Thu Jun 13 17:38:34 CST 2024 with allowed interval between Thu Jun 13 17:23:34 CST 2024 and Thu Jun 13 17:53:34 CST 2024
certpath: -checker8 validation succeeded
certpath: 
cert1 validation succeeded.

certpath: Checking cert2 - Subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19}
certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker]
certpath: -checker1 validation succeeded
certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: Constraints.permits(): SHA256withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Cert Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
  Cert Subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
  Key: RSA
  Date: Thu Jun 13 17:38:34 CST 2024
]
certpath: -checker2 validation succeeded
certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker]
certpath: -checker3 validation succeeded
certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker]
certpath: ---checking basic constraints...
certpath: i = 2, maxPathLength = 0
certpath: after processing, maxPathLength = 0
certpath: basic constraints verified.
certpath: ---checking name constraints...
certpath: prevNC = null, newNC = null
certpath: mergedNC = null
certpath: name constraints verified.
certpath: -checker4 validation succeeded
certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker]
certpath: PolicyChecker.checkPolicy() ---checking certificate policies...
certpath: PolicyChecker.checkPolicy() certIndex = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy  ROOT
  2.23.140.1.2.3  CRIT: false  EP: 2.23.140.1.2.3  (1)
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)
  2.23.140.1.2.2  CRIT: false  EP: 2.23.140.1.2.2  (1)
  2.23.140.1.2.1  CRIT: false  EP: 2.23.140.1.2.1  (1)
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)

certpath: PolicyChecker.processPolicies() policiesCritical = false
certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true
certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents() found parent:
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents() found parent:
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)

certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy  ROOT
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)
    2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (2)
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)
    2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (2)

certpath: PolicyChecker.checkPolicy() certificate policies verified
certpath: -checker5 validation succeeded
certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker]
certpath: ---checking validity:Thu Jun 13 17:38:34 CST 2024...
certpath: validity verified.
certpath: ---checking subject/issuer name chaining...
certpath: subject/issuer name chaining verified.
certpath: ---checking signature...
certpath: signature verified.
certpath: BasicChecker.updateState issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US; serial#: 0e:4c:36:fb:15:ea:a8:e9:50:e4:8a:ed:57:6b:78:a2
certpath: -checker6 validation succeeded
certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: -checker7 validation succeeded
certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker]
certpath: RevocationChecker.check: checking cert
  SN: 0e:4c:36:fb:15:ea:a8:e9:50:e4:8a:ed:57:6b:78:a2
  Subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
  Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
certpath: Found cached OCSP response
certpath: OCSPResponse bytes...

0000: 30 82 02 D3 0A 01 00 A0   82 02 CC 30 82 02 C8 06  0..........0....
0010: 09 2B 06 01 05 05 07 30   01 01 04 82 02 B9 30 82  .+.....0......0.
0020: 02 B5 30 81 9E A2 16 04   14 AE BA 94 33 BA EF 37  ..0.........3..7
0030: 4D 0B D7 18 EF 4A E4 A1   0D BC 07 B6 73 18 0F 32  M....J......s..2
0040: 30 32 34 30 36 31 33 30   33 31 33 30 31 5A 30 73  0240613031301Z0s
0050: 30 71 30 49 30 09 06 05   2B 0E 03 02 1A 05 00 04  0q0I0...+.......
0060: 14 F5 06 5C 39 EC FD 48   0E AD 99 8A 22 7A 1F E9  ...\9..H...."z..
0070: C5 59 50 EA 18 04 14 AE   BA 94 33 BA EF 37 4D 0B  .YP.......3..7M.
0080: D7 18 EF 4A E4 A1 0D BC   07 B6 73 02 10 0E 4C 36  ...J......s...L6
0090: FB 15 EA A8 E9 50 E4 8A   ED 57 6B 78 A2 80 00 18  .....P...Wkx....
00A0: 0F 32 30 32 34 30 36 31   33 30 32 35 37 30 32 5A  .20240613025702Z
00B0: A0 11 18 0F 32 30 32 34   30 36 32 30 30 31 35 37  ....202406200157
00C0: 30 32 5A 30 0D 06 09 2A   86 48 86 F7 0D 01 01 0C  02Z0...*.H......
00D0: 05 00 03 82 02 01 00 3E   6A 85 23 8F 9A CE FF 21  .......>j.#....!
00E0: 02 89 FC 30 7B 40 E1 38   D1 C6 D8 AF F1 43 D5 E4  ...0.@.8.....C..
00F0: 1C F7 C1 A0 6D 98 7C D0   11 00 1A 84 16 AB 78 82  ....m.........x.
0100: 9B CB F0 B4 13 80 81 AD   93 AC B7 D1 12 0F 90 9D  ................
0110: 55 CA B5 17 D1 C5 F8 EA   4D 76 B1 41 DD 47 85 DB  U.......Mv.A.G..
0120: 2C 6E 31 8B 03 6F 52 BE   3E CA CE 45 24 28 1D 85  ,n1..oR.>..E$(..
0130: F5 D1 D8 61 E7 07 CA 46   11 0F C7 E1 DA 01 93 BE  ...a...F........
0140: 2E 06 7F 22 AE 59 11 76   92 AD C3 FE E4 D3 B8 D7  ...".Y.v........
0150: 69 52 97 EB D0 58 61 6E   87 F7 F7 6F 98 0F E7 18  iR...Xan...o....
0160: 38 41 0C 3B C6 32 25 55   2C 7F AD 28 91 9A 96 B8  8A.;.2%U,..(....
0170: E0 FC 16 C0 78 A4 64 27   9C 6A D8 E2 B3 AC DF 7E  ....x.d'.j......
0180: 7F C7 8B 6B E4 C0 A0 A8   8A 28 4D 2F 8A 04 9F 60  ...k.....(M/...`
0190: AB 00 98 96 DC D5 C7 0C   54 49 50 8F FA A9 FB EC  ........TIP.....
01A0: EC 5D 31 BC FF 8A 17 B5   A0 1A DE BA 1B 3A 4C 57  .]1..........:LW
01B0: 68 0C DE BA 9E F4 58 C3   F1 26 C5 FF A9 8E 3A 2C  h.....X..&....:,
01C0: 43 BA 05 BC 33 E3 F9 15   06 B4 46 72 4A DD 73 1B  C...3.....FrJ.s.
01D0: 72 50 67 01 80 2F 44 90   7E 5B 9B 53 83 D3 1C A6  rPg../D..[.S....
01E0: 06 EB 88 E9 3F 00 3D 4E   01 C3 C3 33 70 95 9B 6C  ....?.=N...3p..l
01F0: 01 A6 C4 E3 5E C8 E2 CA   FD 4D AA B3 8C 0B EF 04  ....^....M......
0200: 2B 18 3C 6F 62 52 02 39   4A E5 B0 06 B4 95 E7 E6  +.<obR.9J.......
0210: 0F 27 50 B7 AD F3 0D 2B   27 AF 84 1E 8E 01 F6 70  .'P....+'......p
0220: 24 CD 89 59 BA DD 26 41   D3 B4 8A EA A5 D1 F6 88  $..Y..&A........
0230: 7D 89 E5 48 CC 54 89 79   22 86 1C 6B 00 A5 A4 85  ...H.T.y"..k....
0240: 70 1D 3A B7 70 B9 D8 A6   34 56 3D BE D1 91 DE 18  p.:.p...4V=.....
0250: EE 14 4E F9 86 51 AA 7E   52 E7 A1 B6 7A 3F 3E CE  ..N..Q..R...z?>.
0260: 02 67 34 FF EB 4C 13 CC   3C 6B 0F EF 5A F4 BF 55  .g4..L..<k..Z..U
0270: B3 CB BC F6 56 D9 2F 74   63 48 3A 9B 44 CF 06 A6  ....V./tcH:.D...
0280: 7E B2 92 70 2F E9 22 8E   14 AA 48 77 08 BD 08 3D  ...p/."...Hw...=
0290: 39 BE 9D 71 C8 B9 60 3F   96 49 28 8A 0B 65 80 A6  9..q..`?.I(..e..
02A0: 8E 00 07 02 37 AD 25 78   CB 50 1A 4A 68 2C 81 AD  ....7.%x.P.Jh,..
02B0: 3B A3 57 1A 9B 68 DE 18   9C 96 41 A7 13 90 48 03  ;.W..h....A...H.
02C0: A0 EC 46 F3 08 26 77 5B   24 C0 7D 7E D1 9A 46 FE  ..F..&w[$.....F.
02D0: EE D3 60 38 46 9E C3 

certpath: OCSP response status: SUCCESSFUL
certpath: OCSP response type: basic
certpath: Responder ID: byKey: AEBA9433BAEF374D0BD718EF4AE4A10DBC07B673
certpath: OCSP response produced at: Thu Jun 13 11:13:01 CST 2024
certpath: OCSP number of SingleResponses: 1
certpath: thisUpdate: Thu Jun 13 10:57:02 CST 2024
certpath: nextUpdate: Thu Jun 20 09:57:02 CST 2024
certpath: Status of certificate (with serial number 0e:4c:36:fb:15:ea:a8:e9:50:e4:8a:ed:57:6b:78:a2) is: GOOD
certpath: OCSP response is signed by the target's Issuing CA
certpath: Constraints.permits(): SHA384withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Key: RSA
]
certpath: Verified signature of OCSP Response
certpath: OCSP response validity interval is from Thu Jun 13 10:57:02 CST 2024 until Thu Jun 20 09:57:02 CST 2024
certpath: Checking validity of OCSP response on Thu Jun 13 17:38:34 CST 2024 with allowed interval between Thu Jun 13 17:23:34 CST 2024 and Thu Jun 13 17:53:34 CST 2024
certpath: -checker8 validation succeeded
certpath: 
cert2 validation succeeded.

certpath: Cert path validation succeeded. (PKIX validation algorithm)
certpath: --------------------------------------------------------------
certpath: KeySizeConstraints.permits(): EC
certpath: KeySizeConstraints.permits(): EC
certpath: PKIXCertPathValidator.engineValidate()...
certpath: X509CertSelector.match(Serial number: 01:00:20
  Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL
  Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL)
certpath: X509CertSelector.match: subject DNs don't match
certpath: X509CertSelector.match(Serial number: 0c:be
  Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW
  Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW)
certpath: X509CertSelector.match: subject DNs don't match
certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57
  Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
  Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US)
certpath: X509CertSelector.match: subject DNs don't match
certpath: X509CertSelector.match(Serial number: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US)
certpath: X509CertSelector.match returning: true
certpath: YES - try this trustedCert
certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
certpath: --------------------------------------------------------------
certpath: Executing PKIX certification path validation algorithm.
certpath: Checking cert1 - Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19}
certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker]
certpath: -checker1 validation succeeded
certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: Constraints.permits(): RSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Key: RSA
  Date: Thu Jun 13 17:38:35 CST 2024
]
certpath: Constraints.permits(): SHA384withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Cert Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Cert Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
  Key: RSA
  Date: Thu Jun 13 17:38:35 CST 2024
]
certpath: -checker2 validation succeeded
certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker]
certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage...
certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified.
certpath: -checker3 validation succeeded
certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker]
certpath: ---checking basic constraints...
certpath: i = 1, maxPathLength = 2
certpath: after processing, maxPathLength = 0
certpath: basic constraints verified.
certpath: ---checking name constraints...
certpath: prevNC = null, newNC = null
certpath: mergedNC = null
certpath: name constraints verified.
certpath: -checker4 validation succeeded
certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker]
certpath: PolicyChecker.checkPolicy() ---checking certificate policies...
certpath: PolicyChecker.checkPolicy() certIndex = 1
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() policiesCritical = false
certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true
certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.2
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.3
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents(): matchAny = true
certpath: PolicyChecker.processParents() found parent:
anyPolicy  ROOT

certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy  ROOT
  2.23.140.1.2.1  CRIT: false  EP: 2.23.140.1.2.1  (1)
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)
  2.23.140.1.2.2  CRIT: false  EP: 2.23.140.1.2.2  (1)
  2.23.140.1.2.3  CRIT: false  EP: 2.23.140.1.2.3  (1)

certpath: PolicyChecker.checkPolicy() certificate policies verified
certpath: -checker5 validation succeeded
certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker]
certpath: ---checking validity:Thu Jun 13 17:38:35 CST 2024...
certpath: validity verified.
certpath: ---checking subject/issuer name chaining...
certpath: subject/issuer name chaining verified.
certpath: ---checking signature...
certpath: signature verified.
certpath: BasicChecker.updateState issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US; subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; serial#: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58
certpath: -checker6 validation succeeded
certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: -checker7 validation succeeded
certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker]
certpath: RevocationChecker.check: checking cert
  SN: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58
  Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
certpath: OCSPRequest bytes...

0000: 30 51 30 4F 30 4D 30 4B   30 49 30 09 06 05 2B 0E  0Q0O0M0K0I0...+.
0010: 03 02 1A 05 00 04 14 7E   63 ED 24 CF D5 32 DB 5D  ........c.$..2.]
0020: 6E 66 AC EE 11 49 16 89   47 A2 0D 04 14 51 33 1C  nf...I..G....Q3.
0030: ED 36 40 AF 17 D3 25 CD   69 68 F2 AF 4E 23 3E B3  .6@...%.ih..N#>.
0040: 41 02 10 0E 64 58 E7 54   EC 9C C7 BA C8 32 31 D5  A...dX.T.....21.
0050: F9 4D 58 

certpath: connecting to OCSP service at: http://ocsp.digicert.com
certpath: OCSPResponse bytes...

0000: 30 82 02 D3 0A 01 00 A0   82 02 CC 30 82 02 C8 06  0..........0....
0010: 09 2B 06 01 05 05 07 30   01 01 04 82 02 B9 30 82  .+.....0......0.
0020: 02 B5 30 81 9E A2 16 04   14 51 33 1C ED 36 40 AF  ..0......Q3..6@.
0030: 17 D3 25 CD 69 68 F2 AF   4E 23 3E B3 41 18 0F 32  ..%.ih..N#>.A..2
0040: 30 32 34 30 36 31 32 31   38 33 39 34 33 5A 30 73  0240612183943Z0s
0050: 30 71 30 49 30 09 06 05   2B 0E 03 02 1A 05 00 04  0q0I0...+.......
0060: 14 7E 63 ED 24 CF D5 32   DB 5D 6E 66 AC EE 11 49  ..c.$..2.]nf...I
0070: 16 89 47 A2 0D 04 14 51   33 1C ED 36 40 AF 17 D3  ..G....Q3..6@...
0080: 25 CD 69 68 F2 AF 4E 23   3E B3 41 02 10 0E 64 58  %.ih..N#>.A...dX
0090: E7 54 EC 9C C7 BA C8 32   31 D5 F9 4D 58 80 00 18  .T.....21..MX...
00A0: 0F 32 30 32 34 30 36 31   32 31 38 33 39 34 33 5A  .20240612183943Z
00B0: A0 11 18 0F 32 30 32 34   30 36 31 39 31 38 33 39  ....202406191839
00C0: 34 33 5A 30 0D 06 09 2A   86 48 86 F7 0D 01 01 0C  43Z0...*.H......
00D0: 05 00 03 82 02 01 00 41   21 88 4E AD DE 59 78 47  .......A!.N..YxG
00E0: 4C 3C B9 56 33 50 D6 C2   56 3F BD A1 7B E8 99 35  L<.V3P..V?.....5
00F0: 4A E4 E9 DC 5A 43 A7 A3   E7 F2 46 C3 76 A5 60 96  J...ZC....F.v.`.
0100: 9C 0A 50 58 BA 15 44 29   2B 27 70 68 5D A9 E9 E7  ..PX..D)+'ph]...
0110: 57 06 36 A5 20 AA 52 D9   30 09 9C 12 93 60 97 26  W.6. .R.0....`.&
0120: C4 E2 C7 9B D1 91 FA CE   6E C4 5D 79 7A 07 C9 2E  ........n.]yz...
0130: 10 63 B8 AA 21 87 4A 51   E7 60 72 3E 27 42 90 49  .c..!.JQ.`r>'B.I
0140: 76 82 99 A4 A7 F3 C5 D0   76 97 73 78 64 48 8B EE  v.......v.sxdH..
0150: AD 93 C7 98 57 0F AD 81   E2 22 FA 84 86 47 F3 66  ....W...."...G.f
0160: 57 53 5E F1 17 9B CD 43   B3 96 95 F6 30 39 B7 D7  WS^....C....09..
0170: 2A 0C 7A 51 30 92 6A B5   D9 03 53 7D 34 D1 E1 54  *.zQ0.j...S.4..T
0180: CA 73 9D 0F 85 C0 E7 8F   28 0E 6D 6C 3E C0 48 C8  .s......(.ml>.H.
0190: 57 F3 6D 27 34 98 73 7F   9B 98 6C D4 68 C0 62 AB  W.m'4.s...l.h.b.
01A0: 7A BC 91 D1 64 E7 00 BC   0C 17 DF 0D 37 0B D3 C6  z...d.......7...
01B0: EB 99 E9 95 E5 22 16 06   5E 4A 56 A4 36 90 BB C5  ....."..^JV.6...
01C0: AF E3 2B 3F 3E 06 2C 30   CA 69 CE CA C1 98 BD FC  ..+?>.,0.i......
01D0: A5 60 59 E3 61 8A 50 FA   78 FE 1D 4A D2 36 85 05  .`Y.a.P.x..J.6..
01E0: 3A 1C 26 8D FA CB 00 6F   6F 78 58 87 54 CE 3E 27  :.&....ooxX.T.>'
01F0: 50 F1 7F 0A 4B C8 54 49   C3 18 ED EE 68 FE 75 2A  P...K.TI....h.u*
0200: 3B FC E9 22 EE 79 A7 09   C4 D7 04 38 1B 67 0D 6B  ;..".y.....8.g.k
0210: 90 86 ED 8C 09 A0 08 FF   5A 25 5C A5 84 0D 6E 2C  ........Z%\...n,
0220: CC EB C3 1F 22 9F 5F 24   0C 69 C7 F3 6A D9 27 C1  ...."._$.i..j.'.
0230: 30 72 39 A4 BC FA 0F 94   DF BB 2B 8F BB D0 E2 A6  0r9.......+.....
0240: 6D AC A8 4E 29 F4 BC BA   E4 51 8E AA 3D D1 4D AE  m..N)....Q..=.M.
0250: A0 2C 34 76 04 BE D1 B2   61 53 94 EE 08 73 CE 69  .,4v....aS...s.i
0260: E6 46 7B D2 CA 7F CD 3D   64 97 59 4D F4 F9 4B 8E  .F.....=d.YM..K.
0270: C3 75 58 DC 07 7C 1E A5   8E C1 BD 4C B7 9D 7E 7E  .uX........L....
0280: 13 B5 13 0A 33 74 3F 48   5D C2 8E 7E 65 22 13 03  ....3t?H]...e"..
0290: 6B 93 60 EC 12 A8 1B CF   D5 F8 32 4D ED 5E 10 0B  k.`.......2M.^..
02A0: 11 14 23 E6 C9 B4 26 03   32 38 99 C1 9C 97 8E 47  ..#...&.28.....G
02B0: 55 55 13 5E 4F EB 22 FA   1A 5A 6E 1A 92 53 45 53  UU.^O."..Zn..SES
02C0: B8 C7 C4 43 96 30 35 C8   39 FD 77 8D 08 28 36 16  ...C.05.9.w..(6.
02D0: 41 5F 59 39 C6 A7 4D 

certpath: OCSP response status: SUCCESSFUL
certpath: OCSP response type: basic
certpath: Responder ID: byKey: 51331CED3640AF17D325CD6968F2AF4E233EB341
certpath: OCSP response produced at: Thu Jun 13 02:39:43 CST 2024
certpath: OCSP number of SingleResponses: 1
certpath: thisUpdate: Thu Jun 13 02:39:43 CST 2024
certpath: nextUpdate: Thu Jun 20 02:39:43 CST 2024
certpath: Status of certificate (with serial number 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58) is: GOOD
certpath: OCSP response is signed by the target's Issuing CA
certpath: Constraints.permits(): SHA384withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Key: RSA
]
certpath: Verified signature of OCSP Response
certpath: OCSP response validity interval is from Thu Jun 13 02:39:43 CST 2024 until Thu Jun 20 02:39:43 CST 2024
certpath: Checking validity of OCSP response on Thu Jun 13 17:38:35 CST 2024 with allowed interval between Thu Jun 13 17:23:35 CST 2024 and Thu Jun 13 17:53:35 CST 2024
certpath: -checker8 validation succeeded
certpath: 
cert1 validation succeeded.

certpath: Checking cert2 - Subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19}
certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker]
certpath: -checker1 validation succeeded
certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: Constraints.permits(): SHA256withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Cert Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
  Cert Subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
  Key: RSA
  Date: Thu Jun 13 17:38:35 CST 2024
]
certpath: -checker2 validation succeeded
certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker]
certpath: -checker3 validation succeeded
certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker]
certpath: ---checking basic constraints...
certpath: i = 2, maxPathLength = 0
certpath: after processing, maxPathLength = 0
certpath: basic constraints verified.
certpath: ---checking name constraints...
certpath: prevNC = null, newNC = null
certpath: mergedNC = null
certpath: name constraints verified.
certpath: -checker4 validation succeeded
certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker]
certpath: PolicyChecker.checkPolicy() ---checking certificate policies...
certpath: PolicyChecker.checkPolicy() certIndex = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2
certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy  ROOT
  2.23.140.1.2.1  CRIT: false  EP: 2.23.140.1.2.1  (1)
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)
  2.23.140.1.2.2  CRIT: false  EP: 2.23.140.1.2.2  (1)
  2.23.140.1.2.3  CRIT: false  EP: 2.23.140.1.2.3  (1)

certpath: PolicyChecker.processPolicies() policiesCritical = false
certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true
certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents() found parent:
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)

certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1
certpath: PolicyChecker.processParents(): matchAny = false
certpath: PolicyChecker.processParents() found parent:
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)

certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2
certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy  ROOT
  2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (1)
    2.23.140.1.1  CRIT: false  EP: 2.23.140.1.1  (2)
  2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (1)
    2.16.840.1.114412.2.1  CRIT: false  EP: 2.16.840.1.114412.2.1  (2)

certpath: PolicyChecker.checkPolicy() certificate policies verified
certpath: -checker5 validation succeeded
certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker]
certpath: ---checking validity:Thu Jun 13 17:38:35 CST 2024...
certpath: validity verified.
certpath: ---checking subject/issuer name chaining...
certpath: subject/issuer name chaining verified.
certpath: ---checking signature...
certpath: signature verified.
certpath: BasicChecker.updateState issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US; serial#: 04:06:66:39:c3:4b:38:11:0d:87:ae:f9:78:f6:40:e4
certpath: -checker6 validation succeeded
certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker]
certpath: -checker7 validation succeeded
certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker]
certpath: RevocationChecker.check: checking cert
  SN: 04:06:66:39:c3:4b:38:11:0d:87:ae:f9:78:f6:40:e4
  Subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US
  Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
certpath: Found cached OCSP response
certpath: OCSPResponse bytes...

0000: 30 82 02 D3 0A 01 00 A0   82 02 CC 30 82 02 C8 06  0..........0....
0010: 09 2B 06 01 05 05 07 30   01 01 04 82 02 B9 30 82  .+.....0......0.
0020: 02 B5 30 81 9E A2 16 04   14 AE BA 94 33 BA EF 37  ..0.........3..7
0030: 4D 0B D7 18 EF 4A E4 A1   0D BC 07 B6 73 18 0F 32  M....J......s..2
0040: 30 32 34 30 36 31 31 30   30 30 30 30 30 5A 30 73  0240611000000Z0s
0050: 30 71 30 49 30 09 06 05   2B 0E 03 02 1A 05 00 04  0q0I0...+.......
0060: 14 F5 06 5C 39 EC FD 48   0E AD 99 8A 22 7A 1F E9  ...\9..H...."z..
0070: C5 59 50 EA 18 04 14 AE   BA 94 33 BA EF 37 4D 0B  .YP.......3..7M.
0080: D7 18 EF 4A E4 A1 0D BC   07 B6 73 02 10 04 06 66  ...J......s....f
0090: 39 C3 4B 38 11 0D 87 AE   F9 78 F6 40 E4 80 00 18  9.K8.....x.@....
00A0: 0F 32 30 32 34 30 36 31   31 30 30 30 30 30 30 5A  .20240611000000Z
00B0: A0 11 18 0F 32 30 32 34   30 36 31 37 32 33 30 30  ....202406172300
00C0: 30 30 5A 30 0D 06 09 2A   86 48 86 F7 0D 01 01 0C  00Z0...*.H......
00D0: 05 00 03 82 02 01 00 62   35 4E B9 30 00 5B 46 66  .......b5N.0.[Ff
00E0: EA C8 06 4E 4F AA 67 F9   AB AC 05 33 F7 D6 2E F0  ...NO.g....3....
00F0: 86 51 34 0C 1F A2 03 10   85 64 F0 DF 1E 98 B7 7C  .Q4......d......
0100: EA 40 50 47 8B CD A3 F3   02 22 4E 30 5C 61 88 B6  .@PG....."N0\a..
0110: 7D 71 E1 D6 F6 06 15 26   B7 5E 51 32 8A AE C3 76  .q.....&.^Q2...v
0120: 45 DC 02 92 D0 21 D4 FD   B7 C1 2A 5F 20 9A 48 40  E....!....*_ .H@
0130: AD 24 36 F9 69 29 9E 8A   D5 CD 21 17 09 70 BC 6C  .$6.i)....!..p.l
0140: 1F 74 35 9C 52 A5 7B D8   E1 A4 B8 0E 1A 6E 42 88  .t5.R........nB.
0150: 0F 2C 4E 1B A8 80 A3 F2   9A 55 A9 C1 FB 52 95 47  .,N......U...R.G
0160: 49 7A 44 61 6A A6 5B 60   F4 C4 4B 0C F7 CF E2 94  IzDaj.[`..K.....
0170: 90 C4 09 10 C8 26 90 96   53 C4 4B FE 61 C1 01 53  .....&..S.K.a..S
0180: F4 A6 4C 66 EC 15 B5 22   63 8A 9B AD 2F D2 67 F9  ..Lf..."c.../.g.
0190: DC 69 0A 61 12 51 20 6B   A9 5D 04 D3 81 B2 BC A7  .i.a.Q k.]......
01A0: 03 20 7E 6B 2D A8 85 19   A4 82 7C 1C B2 3E EA C2  . .k-........>..
01B0: 71 26 19 5A 08 DA 0F 3A   86 73 A3 35 47 97 F4 BE  q&.Z...:.s.5G...
01C0: 72 48 A3 A6 A7 47 94 9C   FA 9F A4 29 EC 32 7D 1F  rH...G.....).2..
01D0: BD 3B 6C 35 65 96 65 22   C1 ED 71 40 2E 74 CC 71  .;l5e.e"..q@.t.q
01E0: 56 6C 61 13 62 B9 4A 7C   F1 A1 C6 80 51 05 15 D4  Vla.b.J.....Q...
01F0: 71 98 BD DF 88 73 03 36   21 29 14 84 CE BB 4E A6  q....s.6!)....N.
0200: 6E A4 39 28 60 B0 64 1E   CC 83 96 AC 8E 59 6E 6A  n.9(`.d......Ynj
0210: 8B 67 96 5F 60 50 5F D9   08 3A 60 45 65 74 3B C6  .g._`P_..:`Eet;.
0220: A9 D8 8D 40 F5 6D 2E 94   7C 48 62 58 27 4C 10 7D  ...@.m...HbX'L..
0230: F1 CA C5 2F CA 83 EF 8D   BA 1B B8 F8 2D CC 28 D6  .../........-.(.
0240: D5 AD C1 05 B5 FF E5 7B   B7 83 1B 23 F9 43 DC 2F  ...........#.C./
0250: 46 23 30 27 4A 33 86 BF   0F 3E 6A DB 7A 2B 9A 42  F#0'J3...>j.z+.B
0260: 0B 2B 41 21 A0 63 7D F4   AE 9C FC 43 2A EF 06 C2  .+A!.c.....C*...
0270: FC 93 F7 FD 16 4F 6F 46   6F DB 1A 79 91 BE A9 47  .....OoFo..y...G
0280: 5F AD 54 AC C5 A0 1C D8   2D 3F 8B E3 D6 51 91 F3  _.T.....-?...Q..
0290: 57 9B 38 7E 36 19 3B 07   09 8B F9 CE 01 C1 55 C7  W.8.6.;.......U.
02A0: 52 EB D7 16 DB 59 74 B7   4F 0F 84 0D 6E 99 73 10  R....Yt.O...n.s.
02B0: 61 1E 59 38 36 D8 14 3A   A6 10 23 A6 DA 61 FB 74  a.Y86..:..#..a.t
02C0: 0E F6 E0 75 4F 23 D8 BB   4E C0 E8 58 4E A9 61 E0  ...uO#..N..XN.a.
02D0: F8 6E 88 31 69 37 B0 

certpath: OCSP response status: SUCCESSFUL
certpath: OCSP response type: basic
certpath: Responder ID: byKey: AEBA9433BAEF374D0BD718EF4AE4A10DBC07B673
certpath: OCSP response produced at: Tue Jun 11 08:00:00 CST 2024
certpath: OCSP number of SingleResponses: 1
certpath: thisUpdate: Tue Jun 11 08:00:00 CST 2024
certpath: nextUpdate: Tue Jun 18 07:00:00 CST 2024
certpath: Status of certificate (with serial number 04:06:66:39:c3:4b:38:11:0d:87:ae:f9:78:f6:40:e4) is: GOOD
certpath: OCSP response is signed by the target's Issuing CA
certpath: Constraints.permits(): SHA384withRSA, [
  Variant: tls server
  Anchor: [
  Trusted CA cert: [
[
  Version: V3
  Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12

  Key:  Sun RSA public key, 4096 bits
  params: null
  modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483
  public exponent: 65537
  Validity: [From: Fri Jan 15 08:00:00 CST 2021,
               To: Mon Jan 15 07:59:59 CST 2046]
  Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US
  SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a

Certificate Extensions: 3
[1]: ObjectId: 2.5.29.19 Criticality=true
BasicConstraints:[
  CA:true
  PathLen: no limit
]

[2]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Key_CertSign
  Crl_Sign
]

[3]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 51 33 1C ED 36 40 AF 17   D3 25 CD 69 68 F2 AF 4E  Q3..6@...%.ih..N
0010: 23 3E B3 41                                        #>.A
]
]

]
  Algorithm: [SHA384withRSA]
  Signature:
0000: 60 A6 AF 5B 5F 57 DA 89   DB 4B 50 A9 C4 23 35 21  `..[_W...KP..#5!
0010: FF D0 61 30 84 91 B7 3F   10 CF 25 8E C9 BF 46 34  ..a0...?..%...F4
0020: D9 C1 21 26 1C 70 19 72   1E A3 C9 87 FE A9 43 64  ..!&.p.r......Cd
0030: 96 3A C8 53 04 0A B6 41   BB C4 47 00 D9 9F 18 18  .:.S...A..G.....
0040: 3B B2 0E F3 34 EA 24 F7   DD AF 20 60 AE 92 28 5F  ;...4.$... `..(_
0050: 36 E7 5D E4 DE C7 3C DB   50 39 AD BB 3D 28 4D 96  6.]...<.P9..=(M.
0060: 7C 76 C6 5B F4 C1 DB 14   A5 AB 19 62 07 18 40 5F  .v.[.......b..@_
0070: 97 91 DC 9C C7 AB B5 51   0D E6 69 53 55 CC 39 7D  .......Q..iSU.9.
0080: DA C5 11 55 72 C5 3B 8B   89 F8 34 2D A4 17 E5 17  ...Ur.;...4-....
0090: E6 99 7D 30 88 21 37 CD   30 17 3D B8 F2 BC A8 75  ...0.!7.0.=....u
00A0: A0 43 DC 3E 89 4B 90 AE   6D 03 E0 1C A3 A0 96 09  .C.>.K..m.......
00B0: BB 7D A3 B7 2A 10 44 4B   46 07 34 63 ED 31 B9 04  ....*.DKF.4c.1..
00C0: EE A3 9B 9A AE E6 31 78   F4 EA 24 61 3B AB 58 64  ......1x..$a;.Xd
00D0: FF BB 87 27 62 25 81 DF   DC A1 2F F6 ED A7 FF 7A  ...'b%..../....z
00E0: 8F 51 2E 30 F8 A4 01 D2   85 39 5F 01 99 96 6F 5A  .Q.0.....9_...oZ
00F0: 5B 70 19 46 FE 86 60 3E   AD 80 10 09 DD 39 25 2F  [p.F..`>.....9%/
0100: 58 7F BB D2 74 F0 F7 46   1F 46 39 4A D8 53 D0 F3  X...t..F.F9J.S..
0110: 2E 3B 71 A5 D4 6F FC F3   67 E4 07 8F DD 26 19 E1  .;q..o..g....&..
0120: 8D 5B FA A3 93 11 9B E9   C8 3A C3 55 68 9A 92 E1  .[.......:.Uh...
0130: 52 76 38 E8 E1 BA BD FB   4F D5 EF B3 E7 48 83 31  Rv8.....O....H.1
0140: F0 82 21 E3 B6 BE A7 AB   6F EF 9F DF 4C CF 01 B8  ..!.....o...L...
0150: 62 6A 23 3D E7 09 4D 80   1B 7B 30 A4 C3 DD 07 7F  bj#=..M...0.....
0160: 34 BE A4 26 B2 F6 41 E8   09 1D E3 20 98 AA 37 4F  4..&..A.... ..7O
0170: FF F7 F1 E2 29 70 31 47   3F 74 D0 14 16 FA 21 8A  ....)p1G?t....!.
0180: 02 D5 8A 09 94 77 2E F2   59 28 8B 7C 50 92 0A 66  .....w..Y(..P..f
0190: 78 38 83 75 C4 B5 5A A8   11 C6 E5 C1 9D 66 55 CF  x8.u..Z......fU.
01A0: 53 C4 AF D7 75 85 A9 42   13 56 EC 21 77 81 93 5A  S...u..B.V.!w..Z
01B0: 0C EA 96 D9 49 CA A1 08   F2 97 3B 6D 9B 04 18 24  ....I.....;m...$
01C0: 44 8E 7C 01 F2 DC 25 D8   5E 86 9A B1 39 DB F5 91  D.....%.^...9...
01D0: 32 6A D1 A6 70 8A A2 F7   DE A4 45 85 26 A8 1E 8C  2j..p.....E.&...
01E0: 5D 29 5B C8 4B D8 9A 6A   03 5E 70 F2 85 4F 6C 4B  ])[.K..j.^p..OlK
01F0: 68 2F CA 54 F6 8C DA 32   FE C3 6B 83 3F 38 C6 7E  h/.T...2..k.?8..

]

  Key: RSA
]
certpath: Verified signature of OCSP Response
certpath: OCSP response validity interval is from Tue Jun 11 08:00:00 CST 2024 until Tue Jun 18 07:00:00 CST 2024
certpath: Checking validity of OCSP response on Thu Jun 13 17:38:35 CST 2024 with allowed interval between Thu Jun 13 17:23:35 CST 2024 and Thu Jun 13 17:53:35 CST 2024
certpath: -checker8 validation succeeded
certpath: 
cert2 validation succeeded.

certpath: Cert path validation succeeded. (PKIX validation algorithm)
certpath: --------------------------------------------------------------
certpath: KeySizeConstraints.permits(): EC
certpath: KeySizeConstraints.permits(): EC
java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com
	at ValidatePathWithURL.validateDomain(ValidatePathWithURL.java:129)
	at CAInterop.validate(CAInterop.java:788)
	at CAInterop.main(CAInterop.java:726)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at com.sun.javatest.regtest.agent.MainWrapper$MainTask.run(MainWrapper.java:138)
	at java.base/java.lang.Thread.run(Thread.java:1575)

JavaTest Message: Test threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com
JavaTest Message: shutting down test

STATUS:Failed.`main' threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com
rerun:
cd /home/yansendao/git/jdk/tmp/scratch && \
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \
DISPLAY=:7 \
HOME=/home/yansendao \
LANG=en_US.UTF-8 \
PATH=/bin:/usr/bin:/usr/sbin \
XDG_RUNTIME_DIR=/run/user/995 \
XDG_SESSION_ID=1273615 \
CLASSPATH=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/tmp/classes/test/lib:/home/yansendao/git/jdk/test/lib:/home/yansendao/software/jdk/jtreg-7/lib/javatest.jar:/home/yansendao/software/jdk/jtreg-7/lib/jtreg.jar \
    /home/yansendao/software/jdk/openjdk/jdk-binary/bin/java \
        -Dtest.vm.opts= \
        -Dtest.tool.vm.opts= \
        -Dtest.compiler.opts= \
        -Dtest.java.opts= \
        -Dtest.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \
        -Dcompile.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \
        -Dtest.timeout.factor=1.0 \
        -Dtest.root=/home/yansendao/git/jdk/test/jdk \
        -Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5 \
        -Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \
        -Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \
        -Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \
        -Dtest.classes=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \
        -Dtest.class.path=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib \
        -Djava.security.debug=certpath,ocsp \
        com.sun.javatest.regtest.agent.MainWrapper /home/yansendao/git/jdk/tmp/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d/main.0.jta digicerttlsrsarootg5 OCSP

TEST RESULT: Failed. Execution failed: `main' threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com
--------------------------------------------------
Test results: failed: 1
Results written to /home/yansendao/git/jdk/tmp
Error: Some tests failed or other problems occurred.