Directory "tmp" not found: creating -------------------------------------------------- TEST: security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5 TEST JDK: /home/yansendao/software/jdk/openjdk/jdk-binary ACTION: build -- Passed. Build successful REASON: User specified action: run build jtreg.SkippedException ValidatePathWithURL CAInterop TIME: 1.781 seconds messages: command: build jtreg.SkippedException ValidatePathWithURL CAInterop reason: User specified action: run build jtreg.SkippedException ValidatePathWithURL CAInterop started: Thu Jun 13 17:38:31 CST 2024 Library /test/lib: compile: jtreg.SkippedException Test directory: compile: ValidatePathWithURL, CAInterop finished: Thu Jun 13 17:38:33 CST 2024 elapsed time (seconds): 1.781 ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 0.72 seconds messages: command: compile /home/yansendao/git/jdk/test/lib/jtreg/SkippedException.java reason: .class file out of date or does not exist started: Thu Jun 13 17:38:31 CST 2024 Mode: othervm finished: Thu Jun 13 17:38:32 CST 2024 elapsed time (seconds): 0.72 configuration: javac compilation environment source path: /home/yansendao/git/jdk/test/lib class path: /home/yansendao/git/jdk/tmp/classes/test/lib rerun: cd /home/yansendao/git/jdk/tmp/scratch && \ DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \ DISPLAY=:7 \ HOME=/home/yansendao \ LANG=en_US.UTF-8 \ PATH=/bin:/usr/bin:/usr/sbin \ XDG_RUNTIME_DIR=/run/user/995 \ XDG_SESSION_ID=1273615 \ /home/yansendao/software/jdk/openjdk/jdk-binary/bin/javac \ -J-Dtest.vm.opts= \ -J-Dtest.tool.vm.opts= \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \ -J-Dcompile.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \ -J-Dtest.timeout.factor=1.0 \ -J-Dtest.root=/home/yansendao/git/jdk/test/jdk \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5 \ -J-Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \ -J-Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -J-Dtest.classes=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \ -J-Dtest.class.path=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib \ -d /home/yansendao/git/jdk/tmp/classes/test/lib \ -sourcepath /home/yansendao/git/jdk/test/lib \ -classpath /home/yansendao/git/jdk/tmp/classes/test/lib /home/yansendao/git/jdk/test/lib/jtreg/SkippedException.java STDOUT: STDERR: ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 1.055 seconds messages: command: compile /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java reason: .class file out of date or does not exist started: Thu Jun 13 17:38:32 CST 2024 Mode: othervm finished: Thu Jun 13 17:38:33 CST 2024 elapsed time (seconds): 1.055 configuration: javac compilation environment source path: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification /home/yansendao/git/jdk/test/lib class path: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification /home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d /home/yansendao/git/jdk/tmp/classes/test/lib rerun: cd /home/yansendao/git/jdk/tmp/scratch && \ DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \ DISPLAY=:7 \ HOME=/home/yansendao \ LANG=en_US.UTF-8 \ PATH=/bin:/usr/bin:/usr/sbin \ XDG_RUNTIME_DIR=/run/user/995 \ XDG_SESSION_ID=1273615 \ /home/yansendao/software/jdk/openjdk/jdk-binary/bin/javac \ -J-Dtest.vm.opts= \ -J-Dtest.tool.vm.opts= \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \ -J-Dcompile.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \ -J-Dtest.timeout.factor=1.0 \ -J-Dtest.root=/home/yansendao/git/jdk/test/jdk \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5 \ -J-Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \ -J-Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -J-Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -J-Dtest.classes=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \ -J-Dtest.class.path=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib \ -d /home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \ -sourcepath /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -classpath /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java STDOUT: STDERR: Note: /home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/ValidatePathWithURL.java uses or overrides a deprecated API. Note: Recompile with -Xlint:deprecation for details. ACTION: build -- Passed. All files up to date REASON: Named class compiled on demand TIME: 0.0 seconds messages: command: build CAInterop reason: Named class compiled on demand started: Thu Jun 13 17:38:33 CST 2024 finished: Thu Jun 13 17:38:33 CST 2024 elapsed time (seconds): 0.0 ACTION: main -- Failed. Execution failed: `main' threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com REASON: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp CAInterop digicerttlsrsarootg5 OCSP TIME: 2.811 seconds messages: command: main -Djava.security.debug=certpath,ocsp CAInterop digicerttlsrsarootg5 OCSP reason: User specified action: run main/othervm -Djava.security.debug=certpath,ocsp CAInterop digicerttlsrsarootg5 OCSP started: Thu Jun 13 17:38:33 CST 2024 Mode: othervm [/othervm specified] finished: Thu Jun 13 17:38:36 CST 2024 elapsed time (seconds): 2.811 configuration: STDOUT: ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, SHA1 usage SignedJAR & denyAfter 2019-01-01 com.sun.security.enableCRLDP :false ocsp.enable :true ===================================================== ===== Validate https://digicert-tls-rsa4096-root-g5.chain-demos.digicert.com===== Finding intermediate certificate issued by CA Checking: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Checking: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Found intermediate root CA: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US intermediate CA Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Verified: Intermediate CA signed by test root CA ======> SUCCESS ===== Validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com===== Finding intermediate certificate issued by CA Checking: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Checking: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Found intermediate root CA: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US intermediate CA Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Verified: Intermediate CA signed by test root CA STDERR: certpath: Constraints: 3DES_EDE_CBC certpath: Constraints: anon certpath: Constraints: DES certpath: Constraints: DH keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: DTLSv1.0 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: ECDH certpath: Constraints: MD5withRSA certpath: Constraints: NULL certpath: Constraints: RC4 certpath: Constraints: SSLv3 certpath: Constraints: TLSv1 certpath: Constraints: TLSv1.1 certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01 certpath: Constraints usage length is 1 certpath: Constraints set to denyAfter certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1 certpath: DenyAfterConstraint date set to: 2019-01-01 certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 01:00:20 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 0c:be Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: SHA1 usage SignedJAR & denyAfter 2019-01-01 certpath: Constraints usage length is 1 certpath: Constraints set to denyAfter certpath: DenyAfterConstraint read in as: year 2019, month = 1, day = 1 certpath: DenyAfterConstraint date set to: 2019-01-01 certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): RSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Key: RSA Date: Thu Jun 13 17:38:34 CST 2024 ] certpath: Constraints.permits(): SHA384withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Cert Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Cert Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Key: RSA Date: Thu Jun 13 17:38:34 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.2 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.3 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.2.3 CRIT: false EP: 2.23.140.1.2.3 (1) 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) 2.23.140.1.2.2 CRIT: false EP: 2.23.140.1.2.2 (1) 2.23.140.1.2.1 CRIT: false EP: 2.23.140.1.2.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Thu Jun 13 17:38:34 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US; subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; serial#: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58 Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US certpath: com.sun.security.ocsp.timeout set to 15000 milliseconds certpath: com.sun.security.ocsp.readtimeout set to 15000 milliseconds certpath: com.sun.security.ocsp.useget set to true certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 7E 63 ED 24 CF D5 32 DB 5D ........c.$..2.] 0020: 6E 66 AC EE 11 49 16 89 47 A2 0D 04 14 51 33 1C nf...I..G....Q3. 0030: ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E 23 3E B3 .6@...%.ih..N#>. 0040: 41 02 10 0E 64 58 E7 54 EC 9C C7 BA C8 32 31 D5 A...dX.T.....21. 0050: F9 4D 58 certpath: connecting to OCSP service at: http://ocsp.digicert.com certpath: OCSPResponse bytes... 0000: 30 82 02 D3 0A 01 00 A0 82 02 CC 30 82 02 C8 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 02 B9 30 82 .+.....0......0. 0020: 02 B5 30 81 9E A2 16 04 14 51 33 1C ED 36 40 AF ..0......Q3..6@. 0030: 17 D3 25 CD 69 68 F2 AF 4E 23 3E B3 41 18 0F 32 ..%.ih..N#>.A..2 0040: 30 32 34 30 36 31 32 31 38 33 39 34 33 5A 30 73 0240612183943Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 7E 63 ED 24 CF D5 32 DB 5D 6E 66 AC EE 11 49 ..c.$..2.]nf...I 0070: 16 89 47 A2 0D 04 14 51 33 1C ED 36 40 AF 17 D3 ..G....Q3..6@... 0080: 25 CD 69 68 F2 AF 4E 23 3E B3 41 02 10 0E 64 58 %.ih..N#>.A...dX 0090: E7 54 EC 9C C7 BA C8 32 31 D5 F9 4D 58 80 00 18 .T.....21..MX... 00A0: 0F 32 30 32 34 30 36 31 32 31 38 33 39 34 33 5A .20240612183943Z 00B0: A0 11 18 0F 32 30 32 34 30 36 31 39 31 38 33 39 ....202406191839 00C0: 34 33 5A 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0C 43Z0...*.H...... 00D0: 05 00 03 82 02 01 00 41 21 88 4E AD DE 59 78 47 .......A!.N..YxG 00E0: 4C 3C B9 56 33 50 D6 C2 56 3F BD A1 7B E8 99 35 L<.V3P..V?.....5 00F0: 4A E4 E9 DC 5A 43 A7 A3 E7 F2 46 C3 76 A5 60 96 J...ZC....F.v.`. 0100: 9C 0A 50 58 BA 15 44 29 2B 27 70 68 5D A9 E9 E7 ..PX..D)+'ph]... 0110: 57 06 36 A5 20 AA 52 D9 30 09 9C 12 93 60 97 26 W.6. .R.0....`.& 0120: C4 E2 C7 9B D1 91 FA CE 6E C4 5D 79 7A 07 C9 2E ........n.]yz... 0130: 10 63 B8 AA 21 87 4A 51 E7 60 72 3E 27 42 90 49 .c..!.JQ.`r>'B.I 0140: 76 82 99 A4 A7 F3 C5 D0 76 97 73 78 64 48 8B EE v.......v.sxdH.. 0150: AD 93 C7 98 57 0F AD 81 E2 22 FA 84 86 47 F3 66 ....W...."...G.f 0160: 57 53 5E F1 17 9B CD 43 B3 96 95 F6 30 39 B7 D7 WS^....C....09.. 0170: 2A 0C 7A 51 30 92 6A B5 D9 03 53 7D 34 D1 E1 54 *.zQ0.j...S.4..T 0180: CA 73 9D 0F 85 C0 E7 8F 28 0E 6D 6C 3E C0 48 C8 .s......(.ml>.H. 0190: 57 F3 6D 27 34 98 73 7F 9B 98 6C D4 68 C0 62 AB W.m'4.s...l.h.b. 01A0: 7A BC 91 D1 64 E7 00 BC 0C 17 DF 0D 37 0B D3 C6 z...d.......7... 01B0: EB 99 E9 95 E5 22 16 06 5E 4A 56 A4 36 90 BB C5 ....."..^JV.6... 01C0: AF E3 2B 3F 3E 06 2C 30 CA 69 CE CA C1 98 BD FC ..+?>.,0.i...... 01D0: A5 60 59 E3 61 8A 50 FA 78 FE 1D 4A D2 36 85 05 .`Y.a.P.x..J.6.. 01E0: 3A 1C 26 8D FA CB 00 6F 6F 78 58 87 54 CE 3E 27 :.&....ooxX.T.>' 01F0: 50 F1 7F 0A 4B C8 54 49 C3 18 ED EE 68 FE 75 2A P...K.TI....h.u* 0200: 3B FC E9 22 EE 79 A7 09 C4 D7 04 38 1B 67 0D 6B ;..".y.....8.g.k 0210: 90 86 ED 8C 09 A0 08 FF 5A 25 5C A5 84 0D 6E 2C ........Z%\...n, 0220: CC EB C3 1F 22 9F 5F 24 0C 69 C7 F3 6A D9 27 C1 ...."._$.i..j.'. 0230: 30 72 39 A4 BC FA 0F 94 DF BB 2B 8F BB D0 E2 A6 0r9.......+..... 0240: 6D AC A8 4E 29 F4 BC BA E4 51 8E AA 3D D1 4D AE m..N)....Q..=.M. 0250: A0 2C 34 76 04 BE D1 B2 61 53 94 EE 08 73 CE 69 .,4v....aS...s.i 0260: E6 46 7B D2 CA 7F CD 3D 64 97 59 4D F4 F9 4B 8E .F.....=d.YM..K. 0270: C3 75 58 DC 07 7C 1E A5 8E C1 BD 4C B7 9D 7E 7E .uX........L.... 0280: 13 B5 13 0A 33 74 3F 48 5D C2 8E 7E 65 22 13 03 ....3t?H]...e".. 0290: 6B 93 60 EC 12 A8 1B CF D5 F8 32 4D ED 5E 10 0B k.`.......2M.^.. 02A0: 11 14 23 E6 C9 B4 26 03 32 38 99 C1 9C 97 8E 47 ..#...&.28.....G 02B0: 55 55 13 5E 4F EB 22 FA 1A 5A 6E 1A 92 53 45 53 UU.^O."..Zn..SES 02C0: B8 C7 C4 43 96 30 35 C8 39 FD 77 8D 08 28 36 16 ...C.05.9.w..(6. 02D0: 41 5F 59 39 C6 A7 4D certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 51331CED3640AF17D325CD6968F2AF4E233EB341 certpath: OCSP response produced at: Thu Jun 13 02:39:43 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Thu Jun 13 02:39:43 CST 2024 certpath: nextUpdate: Thu Jun 20 02:39:43 CST 2024 certpath: Status of certificate (with serial number 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58) is: GOOD certpath: OCSP response is signed by the target's Issuing CA certpath: Constraints.permits(): SHA384withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Thu Jun 13 02:39:43 CST 2024 until Thu Jun 20 02:39:43 CST 2024 certpath: Checking validity of OCSP response on Thu Jun 13 17:38:34 CST 2024 with allowed interval between Thu Jun 13 17:23:34 CST 2024 and Thu Jun 13 17:53:34 CST 2024 certpath: -checker8 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA256withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Cert Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Cert Subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US Key: RSA Date: Thu Jun 13 17:38:34 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.2.3 CRIT: false EP: 2.23.140.1.2.3 (1) 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) 2.23.140.1.2.2 CRIT: false EP: 2.23.140.1.2.2 (1) 2.23.140.1.2.1 CRIT: false EP: 2.23.140.1.2.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (2) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Thu Jun 13 17:38:34 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US; serial#: 0e:4c:36:fb:15:ea:a8:e9:50:e4:8a:ed:57:6b:78:a2 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 0e:4c:36:fb:15:ea:a8:e9:50:e4:8a:ed:57:6b:78:a2 Subject: CN=digicert-tls-rsa4096-root-g5.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US certpath: Found cached OCSP response certpath: OCSPResponse bytes... 0000: 30 82 02 D3 0A 01 00 A0 82 02 CC 30 82 02 C8 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 02 B9 30 82 .+.....0......0. 0020: 02 B5 30 81 9E A2 16 04 14 AE BA 94 33 BA EF 37 ..0.........3..7 0030: 4D 0B D7 18 EF 4A E4 A1 0D BC 07 B6 73 18 0F 32 M....J......s..2 0040: 30 32 34 30 36 31 33 30 33 31 33 30 31 5A 30 73 0240613031301Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 F5 06 5C 39 EC FD 48 0E AD 99 8A 22 7A 1F E9 ...\9..H...."z.. 0070: C5 59 50 EA 18 04 14 AE BA 94 33 BA EF 37 4D 0B .YP.......3..7M. 0080: D7 18 EF 4A E4 A1 0D BC 07 B6 73 02 10 0E 4C 36 ...J......s...L6 0090: FB 15 EA A8 E9 50 E4 8A ED 57 6B 78 A2 80 00 18 .....P...Wkx.... 00A0: 0F 32 30 32 34 30 36 31 33 30 32 35 37 30 32 5A .20240613025702Z 00B0: A0 11 18 0F 32 30 32 34 30 36 32 30 30 31 35 37 ....202406200157 00C0: 30 32 5A 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0C 02Z0...*.H...... 00D0: 05 00 03 82 02 01 00 3E 6A 85 23 8F 9A CE FF 21 .......>j.#....! 00E0: 02 89 FC 30 7B 40 E1 38 D1 C6 D8 AF F1 43 D5 E4 ...0.@.8.....C.. 00F0: 1C F7 C1 A0 6D 98 7C D0 11 00 1A 84 16 AB 78 82 ....m.........x. 0100: 9B CB F0 B4 13 80 81 AD 93 AC B7 D1 12 0F 90 9D ................ 0110: 55 CA B5 17 D1 C5 F8 EA 4D 76 B1 41 DD 47 85 DB U.......Mv.A.G.. 0120: 2C 6E 31 8B 03 6F 52 BE 3E CA CE 45 24 28 1D 85 ,n1..oR.>..E$(.. 0130: F5 D1 D8 61 E7 07 CA 46 11 0F C7 E1 DA 01 93 BE ...a...F........ 0140: 2E 06 7F 22 AE 59 11 76 92 AD C3 FE E4 D3 B8 D7 ...".Y.v........ 0150: 69 52 97 EB D0 58 61 6E 87 F7 F7 6F 98 0F E7 18 iR...Xan...o.... 0160: 38 41 0C 3B C6 32 25 55 2C 7F AD 28 91 9A 96 B8 8A.;.2%U,..(.... 0170: E0 FC 16 C0 78 A4 64 27 9C 6A D8 E2 B3 AC DF 7E ....x.d'.j...... 0180: 7F C7 8B 6B E4 C0 A0 A8 8A 28 4D 2F 8A 04 9F 60 ...k.....(M/...` 0190: AB 00 98 96 DC D5 C7 0C 54 49 50 8F FA A9 FB EC ........TIP..... 01A0: EC 5D 31 BC FF 8A 17 B5 A0 1A DE BA 1B 3A 4C 57 .]1..........:LW 01B0: 68 0C DE BA 9E F4 58 C3 F1 26 C5 FF A9 8E 3A 2C h.....X..&....:, 01C0: 43 BA 05 BC 33 E3 F9 15 06 B4 46 72 4A DD 73 1B C...3.....FrJ.s. 01D0: 72 50 67 01 80 2F 44 90 7E 5B 9B 53 83 D3 1C A6 rPg../D..[.S.... 01E0: 06 EB 88 E9 3F 00 3D 4E 01 C3 C3 33 70 95 9B 6C ....?.=N...3p..l 01F0: 01 A6 C4 E3 5E C8 E2 CA FD 4D AA B3 8C 0B EF 04 ....^....M...... 0200: 2B 18 3C 6F 62 52 02 39 4A E5 B0 06 B4 95 E7 E6 +.<obR.9J....... 0210: 0F 27 50 B7 AD F3 0D 2B 27 AF 84 1E 8E 01 F6 70 .'P....+'......p 0220: 24 CD 89 59 BA DD 26 41 D3 B4 8A EA A5 D1 F6 88 $..Y..&A........ 0230: 7D 89 E5 48 CC 54 89 79 22 86 1C 6B 00 A5 A4 85 ...H.T.y"..k.... 0240: 70 1D 3A B7 70 B9 D8 A6 34 56 3D BE D1 91 DE 18 p.:.p...4V=..... 0250: EE 14 4E F9 86 51 AA 7E 52 E7 A1 B6 7A 3F 3E CE ..N..Q..R...z?>. 0260: 02 67 34 FF EB 4C 13 CC 3C 6B 0F EF 5A F4 BF 55 .g4..L..<k..Z..U 0270: B3 CB BC F6 56 D9 2F 74 63 48 3A 9B 44 CF 06 A6 ....V./tcH:.D... 0280: 7E B2 92 70 2F E9 22 8E 14 AA 48 77 08 BD 08 3D ...p/."...Hw...= 0290: 39 BE 9D 71 C8 B9 60 3F 96 49 28 8A 0B 65 80 A6 9..q..`?.I(..e.. 02A0: 8E 00 07 02 37 AD 25 78 CB 50 1A 4A 68 2C 81 AD ....7.%x.P.Jh,.. 02B0: 3B A3 57 1A 9B 68 DE 18 9C 96 41 A7 13 90 48 03 ;.W..h....A...H. 02C0: A0 EC 46 F3 08 26 77 5B 24 C0 7D 7E D1 9A 46 FE ..F..&w[$.....F. 02D0: EE D3 60 38 46 9E C3 certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: AEBA9433BAEF374D0BD718EF4AE4A10DBC07B673 certpath: OCSP response produced at: Thu Jun 13 11:13:01 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Thu Jun 13 10:57:02 CST 2024 certpath: nextUpdate: Thu Jun 20 09:57:02 CST 2024 certpath: Status of certificate (with serial number 0e:4c:36:fb:15:ea:a8:e9:50:e4:8a:ed:57:6b:78:a2) is: GOOD certpath: OCSP response is signed by the target's Issuing CA certpath: Constraints.permits(): SHA384withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Thu Jun 13 10:57:02 CST 2024 until Thu Jun 20 09:57:02 CST 2024 certpath: Checking validity of OCSP response on Thu Jun 13 17:38:34 CST 2024 with allowed interval between Thu Jun 13 17:23:34 CST 2024 and Thu Jun 13 17:53:34 CST 2024 certpath: -checker8 validation succeeded certpath: cert2 validation succeeded. certpath: Cert path validation succeeded. (PKIX validation algorithm) certpath: -------------------------------------------------------------- certpath: KeySizeConstraints.permits(): EC certpath: KeySizeConstraints.permits(): EC certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(Serial number: 01:00:20 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 0c:be Issuer: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW Subject: CN=TWCA Global Root CA, OU=Root CA, O=TAIWAN-CA, C=TW) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 00:9b:7e:06:49:a3:3e:62:b9:d5:ee:90:48:71:29:ef:57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(Serial number: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): RSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Key: RSA Date: Thu Jun 13 17:38:35 CST 2024 ] certpath: Constraints.permits(): SHA384withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Cert Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Cert Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Key: RSA Date: Thu Jun 13 17:38:35 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.2 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.2.3 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.2.1 CRIT: false EP: 2.23.140.1.2.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) 2.23.140.1.2.2 CRIT: false EP: 2.23.140.1.2.2 (1) 2.23.140.1.2.3 CRIT: false EP: 2.23.140.1.2.3 (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Thu Jun 13 17:38:35 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US; subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; serial#: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58 Subject: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US certpath: OCSPRequest bytes... 0000: 30 51 30 4F 30 4D 30 4B 30 49 30 09 06 05 2B 0E 0Q0O0M0K0I0...+. 0010: 03 02 1A 05 00 04 14 7E 63 ED 24 CF D5 32 DB 5D ........c.$..2.] 0020: 6E 66 AC EE 11 49 16 89 47 A2 0D 04 14 51 33 1C nf...I..G....Q3. 0030: ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E 23 3E B3 .6@...%.ih..N#>. 0040: 41 02 10 0E 64 58 E7 54 EC 9C C7 BA C8 32 31 D5 A...dX.T.....21. 0050: F9 4D 58 certpath: connecting to OCSP service at: http://ocsp.digicert.com certpath: OCSPResponse bytes... 0000: 30 82 02 D3 0A 01 00 A0 82 02 CC 30 82 02 C8 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 02 B9 30 82 .+.....0......0. 0020: 02 B5 30 81 9E A2 16 04 14 51 33 1C ED 36 40 AF ..0......Q3..6@. 0030: 17 D3 25 CD 69 68 F2 AF 4E 23 3E B3 41 18 0F 32 ..%.ih..N#>.A..2 0040: 30 32 34 30 36 31 32 31 38 33 39 34 33 5A 30 73 0240612183943Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 7E 63 ED 24 CF D5 32 DB 5D 6E 66 AC EE 11 49 ..c.$..2.]nf...I 0070: 16 89 47 A2 0D 04 14 51 33 1C ED 36 40 AF 17 D3 ..G....Q3..6@... 0080: 25 CD 69 68 F2 AF 4E 23 3E B3 41 02 10 0E 64 58 %.ih..N#>.A...dX 0090: E7 54 EC 9C C7 BA C8 32 31 D5 F9 4D 58 80 00 18 .T.....21..MX... 00A0: 0F 32 30 32 34 30 36 31 32 31 38 33 39 34 33 5A .20240612183943Z 00B0: A0 11 18 0F 32 30 32 34 30 36 31 39 31 38 33 39 ....202406191839 00C0: 34 33 5A 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0C 43Z0...*.H...... 00D0: 05 00 03 82 02 01 00 41 21 88 4E AD DE 59 78 47 .......A!.N..YxG 00E0: 4C 3C B9 56 33 50 D6 C2 56 3F BD A1 7B E8 99 35 L<.V3P..V?.....5 00F0: 4A E4 E9 DC 5A 43 A7 A3 E7 F2 46 C3 76 A5 60 96 J...ZC....F.v.`. 0100: 9C 0A 50 58 BA 15 44 29 2B 27 70 68 5D A9 E9 E7 ..PX..D)+'ph]... 0110: 57 06 36 A5 20 AA 52 D9 30 09 9C 12 93 60 97 26 W.6. .R.0....`.& 0120: C4 E2 C7 9B D1 91 FA CE 6E C4 5D 79 7A 07 C9 2E ........n.]yz... 0130: 10 63 B8 AA 21 87 4A 51 E7 60 72 3E 27 42 90 49 .c..!.JQ.`r>'B.I 0140: 76 82 99 A4 A7 F3 C5 D0 76 97 73 78 64 48 8B EE v.......v.sxdH.. 0150: AD 93 C7 98 57 0F AD 81 E2 22 FA 84 86 47 F3 66 ....W...."...G.f 0160: 57 53 5E F1 17 9B CD 43 B3 96 95 F6 30 39 B7 D7 WS^....C....09.. 0170: 2A 0C 7A 51 30 92 6A B5 D9 03 53 7D 34 D1 E1 54 *.zQ0.j...S.4..T 0180: CA 73 9D 0F 85 C0 E7 8F 28 0E 6D 6C 3E C0 48 C8 .s......(.ml>.H. 0190: 57 F3 6D 27 34 98 73 7F 9B 98 6C D4 68 C0 62 AB W.m'4.s...l.h.b. 01A0: 7A BC 91 D1 64 E7 00 BC 0C 17 DF 0D 37 0B D3 C6 z...d.......7... 01B0: EB 99 E9 95 E5 22 16 06 5E 4A 56 A4 36 90 BB C5 ....."..^JV.6... 01C0: AF E3 2B 3F 3E 06 2C 30 CA 69 CE CA C1 98 BD FC ..+?>.,0.i...... 01D0: A5 60 59 E3 61 8A 50 FA 78 FE 1D 4A D2 36 85 05 .`Y.a.P.x..J.6.. 01E0: 3A 1C 26 8D FA CB 00 6F 6F 78 58 87 54 CE 3E 27 :.&....ooxX.T.>' 01F0: 50 F1 7F 0A 4B C8 54 49 C3 18 ED EE 68 FE 75 2A P...K.TI....h.u* 0200: 3B FC E9 22 EE 79 A7 09 C4 D7 04 38 1B 67 0D 6B ;..".y.....8.g.k 0210: 90 86 ED 8C 09 A0 08 FF 5A 25 5C A5 84 0D 6E 2C ........Z%\...n, 0220: CC EB C3 1F 22 9F 5F 24 0C 69 C7 F3 6A D9 27 C1 ...."._$.i..j.'. 0230: 30 72 39 A4 BC FA 0F 94 DF BB 2B 8F BB D0 E2 A6 0r9.......+..... 0240: 6D AC A8 4E 29 F4 BC BA E4 51 8E AA 3D D1 4D AE m..N)....Q..=.M. 0250: A0 2C 34 76 04 BE D1 B2 61 53 94 EE 08 73 CE 69 .,4v....aS...s.i 0260: E6 46 7B D2 CA 7F CD 3D 64 97 59 4D F4 F9 4B 8E .F.....=d.YM..K. 0270: C3 75 58 DC 07 7C 1E A5 8E C1 BD 4C B7 9D 7E 7E .uX........L.... 0280: 13 B5 13 0A 33 74 3F 48 5D C2 8E 7E 65 22 13 03 ....3t?H]...e".. 0290: 6B 93 60 EC 12 A8 1B CF D5 F8 32 4D ED 5E 10 0B k.`.......2M.^.. 02A0: 11 14 23 E6 C9 B4 26 03 32 38 99 C1 9C 97 8E 47 ..#...&.28.....G 02B0: 55 55 13 5E 4F EB 22 FA 1A 5A 6E 1A 92 53 45 53 UU.^O."..Zn..SES 02C0: B8 C7 C4 43 96 30 35 C8 39 FD 77 8D 08 28 36 16 ...C.05.9.w..(6. 02D0: 41 5F 59 39 C6 A7 4D certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 51331CED3640AF17D325CD6968F2AF4E233EB341 certpath: OCSP response produced at: Thu Jun 13 02:39:43 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Thu Jun 13 02:39:43 CST 2024 certpath: nextUpdate: Thu Jun 20 02:39:43 CST 2024 certpath: Status of certificate (with serial number 0e:64:58:e7:54:ec:9c:c7:ba:c8:32:31:d5:f9:4d:58) is: GOOD certpath: OCSP response is signed by the target's Issuing CA certpath: Constraints.permits(): SHA384withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Thu Jun 13 02:39:43 CST 2024 until Thu Jun 20 02:39:43 CST 2024 certpath: Checking validity of OCSP response on Thu Jun 13 17:38:35 CST 2024 with allowed interval between Thu Jun 13 17:23:35 CST 2024 and Thu Jun 13 17:53:35 CST 2024 certpath: -checker8 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA256withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Cert Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US Cert Subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US Key: RSA Date: Thu Jun 13 17:38:35 CST 2024 ] certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.2.1 CRIT: false EP: 2.23.140.1.2.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) 2.23.140.1.2.2 CRIT: false EP: 2.23.140.1.2.2 (1) 2.23.140.1.2.3 CRIT: false EP: 2.23.140.1.2.3 (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.16.840.1.114412.2.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents() found parent: 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (1) 2.16.840.1.114412.2.1 CRIT: false EP: 2.16.840.1.114412.2.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Thu Jun 13 17:38:35 CST 2024... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US; subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US; serial#: 04:06:66:39:c3:4b:38:11:0d:87:ae:f9:78:f6:40:e4 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: -checker7 validation succeeded certpath: -Using checker8 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 04:06:66:39:c3:4b:38:11:0d:87:ae:f9:78:f6:40:e4 Subject: CN=digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com, O="DigiCert, Inc.", L=Lehi, ST=Utah, C=US, SERIALNUMBER=5299537-0142, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Utah, OID.1.3.6.1.4.1.311.60.2.1.3=US Issuer: CN=DigiCert G5 TLS RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US certpath: Found cached OCSP response certpath: OCSPResponse bytes... 0000: 30 82 02 D3 0A 01 00 A0 82 02 CC 30 82 02 C8 06 0..........0.... 0010: 09 2B 06 01 05 05 07 30 01 01 04 82 02 B9 30 82 .+.....0......0. 0020: 02 B5 30 81 9E A2 16 04 14 AE BA 94 33 BA EF 37 ..0.........3..7 0030: 4D 0B D7 18 EF 4A E4 A1 0D BC 07 B6 73 18 0F 32 M....J......s..2 0040: 30 32 34 30 36 31 31 30 30 30 30 30 30 5A 30 73 0240611000000Z0s 0050: 30 71 30 49 30 09 06 05 2B 0E 03 02 1A 05 00 04 0q0I0...+....... 0060: 14 F5 06 5C 39 EC FD 48 0E AD 99 8A 22 7A 1F E9 ...\9..H...."z.. 0070: C5 59 50 EA 18 04 14 AE BA 94 33 BA EF 37 4D 0B .YP.......3..7M. 0080: D7 18 EF 4A E4 A1 0D BC 07 B6 73 02 10 04 06 66 ...J......s....f 0090: 39 C3 4B 38 11 0D 87 AE F9 78 F6 40 E4 80 00 18 9.K8.....x.@.... 00A0: 0F 32 30 32 34 30 36 31 31 30 30 30 30 30 30 5A .20240611000000Z 00B0: A0 11 18 0F 32 30 32 34 30 36 31 37 32 33 30 30 ....202406172300 00C0: 30 30 5A 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0C 00Z0...*.H...... 00D0: 05 00 03 82 02 01 00 62 35 4E B9 30 00 5B 46 66 .......b5N.0.[Ff 00E0: EA C8 06 4E 4F AA 67 F9 AB AC 05 33 F7 D6 2E F0 ...NO.g....3.... 00F0: 86 51 34 0C 1F A2 03 10 85 64 F0 DF 1E 98 B7 7C .Q4......d...... 0100: EA 40 50 47 8B CD A3 F3 02 22 4E 30 5C 61 88 B6 .@PG....."N0\a.. 0110: 7D 71 E1 D6 F6 06 15 26 B7 5E 51 32 8A AE C3 76 .q.....&.^Q2...v 0120: 45 DC 02 92 D0 21 D4 FD B7 C1 2A 5F 20 9A 48 40 E....!....*_ .H@ 0130: AD 24 36 F9 69 29 9E 8A D5 CD 21 17 09 70 BC 6C .$6.i)....!..p.l 0140: 1F 74 35 9C 52 A5 7B D8 E1 A4 B8 0E 1A 6E 42 88 .t5.R........nB. 0150: 0F 2C 4E 1B A8 80 A3 F2 9A 55 A9 C1 FB 52 95 47 .,N......U...R.G 0160: 49 7A 44 61 6A A6 5B 60 F4 C4 4B 0C F7 CF E2 94 IzDaj.[`..K..... 0170: 90 C4 09 10 C8 26 90 96 53 C4 4B FE 61 C1 01 53 .....&..S.K.a..S 0180: F4 A6 4C 66 EC 15 B5 22 63 8A 9B AD 2F D2 67 F9 ..Lf..."c.../.g. 0190: DC 69 0A 61 12 51 20 6B A9 5D 04 D3 81 B2 BC A7 .i.a.Q k.]...... 01A0: 03 20 7E 6B 2D A8 85 19 A4 82 7C 1C B2 3E EA C2 . .k-........>.. 01B0: 71 26 19 5A 08 DA 0F 3A 86 73 A3 35 47 97 F4 BE q&.Z...:.s.5G... 01C0: 72 48 A3 A6 A7 47 94 9C FA 9F A4 29 EC 32 7D 1F rH...G.....).2.. 01D0: BD 3B 6C 35 65 96 65 22 C1 ED 71 40 2E 74 CC 71 .;l5e.e"..q@.t.q 01E0: 56 6C 61 13 62 B9 4A 7C F1 A1 C6 80 51 05 15 D4 Vla.b.J.....Q... 01F0: 71 98 BD DF 88 73 03 36 21 29 14 84 CE BB 4E A6 q....s.6!)....N. 0200: 6E A4 39 28 60 B0 64 1E CC 83 96 AC 8E 59 6E 6A n.9(`.d......Ynj 0210: 8B 67 96 5F 60 50 5F D9 08 3A 60 45 65 74 3B C6 .g._`P_..:`Eet;. 0220: A9 D8 8D 40 F5 6D 2E 94 7C 48 62 58 27 4C 10 7D ...@.m...HbX'L.. 0230: F1 CA C5 2F CA 83 EF 8D BA 1B B8 F8 2D CC 28 D6 .../........-.(. 0240: D5 AD C1 05 B5 FF E5 7B B7 83 1B 23 F9 43 DC 2F ...........#.C./ 0250: 46 23 30 27 4A 33 86 BF 0F 3E 6A DB 7A 2B 9A 42 F#0'J3...>j.z+.B 0260: 0B 2B 41 21 A0 63 7D F4 AE 9C FC 43 2A EF 06 C2 .+A!.c.....C*... 0270: FC 93 F7 FD 16 4F 6F 46 6F DB 1A 79 91 BE A9 47 .....OoFo..y...G 0280: 5F AD 54 AC C5 A0 1C D8 2D 3F 8B E3 D6 51 91 F3 _.T.....-?...Q.. 0290: 57 9B 38 7E 36 19 3B 07 09 8B F9 CE 01 C1 55 C7 W.8.6.;.......U. 02A0: 52 EB D7 16 DB 59 74 B7 4F 0F 84 0D 6E 99 73 10 R....Yt.O...n.s. 02B0: 61 1E 59 38 36 D8 14 3A A6 10 23 A6 DA 61 FB 74 a.Y86..:..#..a.t 02C0: 0E F6 E0 75 4F 23 D8 BB 4E C0 E8 58 4E A9 61 E0 ...uO#..N..XN.a. 02D0: F8 6E 88 31 69 37 B0 certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: AEBA9433BAEF374D0BD718EF4AE4A10DBC07B673 certpath: OCSP response produced at: Tue Jun 11 08:00:00 CST 2024 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Tue Jun 11 08:00:00 CST 2024 certpath: nextUpdate: Tue Jun 18 07:00:00 CST 2024 certpath: Status of certificate (with serial number 04:06:66:39:c3:4b:38:11:0d:87:ae:f9:78:f6:40:e4) is: GOOD certpath: OCSP response is signed by the target's Issuing CA certpath: Constraints.permits(): SHA384withRSA, [ Variant: tls server Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 733586237076682382075377630184371027754925465356716703522144818216188865358039478147774648515255495624235266827158884927780560818675083356101816237119300635341593161772723132494350330376433218224625311464908279180339997039935252629122549937390785916587439505910873845156220128607602674450142615557063840202758680378247609528416727375276770853877402235751674284430427207967930357491979612892143461058870682651738602448290245115842322487961395308871734147724417738877804112911892428027213654440512390624216061032438559552475038231310706694809209562538981126818140913707705729868710411855461031558217445609513940262545143552131197674006601157994543234269801766829937062206296556895887569684471682133119163319508979870483253619954549434429034313756892515411922479885748366009424483293950251210144822757852982561367349239167144553319554140884169717646605242702379595212319844277771947263703688230643885505848677309522195873670739239829224971043761889335614372216152390450991845082580266213849554091686669827916086554076054265593449079273620423234176670083808516375310298222060298242280368485512099428621485492338878823895705283909680485018597331655164054728457555493765846427310554016080662651967588284246438555271442652173482147685781483 public exponent: 65537 Validity: [From: Fri Jan 15 08:00:00 CST 2021, To: Mon Jan 15 07:59:59 CST 2046] Issuer: CN=DigiCert TLS RSA4096 Root G5, O="DigiCert, Inc.", C=US SerialNumber: 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen: no limit ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ DigitalSignature Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 51 33 1C ED 36 40 AF 17 D3 25 CD 69 68 F2 AF 4E Q3..6@...%.ih..N 0010: 23 3E B3 41 #>.A ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 60 A6 AF 5B 5F 57 DA 89 DB 4B 50 A9 C4 23 35 21 `..[_W...KP..#5! 0010: FF D0 61 30 84 91 B7 3F 10 CF 25 8E C9 BF 46 34 ..a0...?..%...F4 0020: D9 C1 21 26 1C 70 19 72 1E A3 C9 87 FE A9 43 64 ..!&.p.r......Cd 0030: 96 3A C8 53 04 0A B6 41 BB C4 47 00 D9 9F 18 18 .:.S...A..G..... 0040: 3B B2 0E F3 34 EA 24 F7 DD AF 20 60 AE 92 28 5F ;...4.$... `..(_ 0050: 36 E7 5D E4 DE C7 3C DB 50 39 AD BB 3D 28 4D 96 6.]...<.P9..=(M. 0060: 7C 76 C6 5B F4 C1 DB 14 A5 AB 19 62 07 18 40 5F .v.[.......b..@_ 0070: 97 91 DC 9C C7 AB B5 51 0D E6 69 53 55 CC 39 7D .......Q..iSU.9. 0080: DA C5 11 55 72 C5 3B 8B 89 F8 34 2D A4 17 E5 17 ...Ur.;...4-.... 0090: E6 99 7D 30 88 21 37 CD 30 17 3D B8 F2 BC A8 75 ...0.!7.0.=....u 00A0: A0 43 DC 3E 89 4B 90 AE 6D 03 E0 1C A3 A0 96 09 .C.>.K..m....... 00B0: BB 7D A3 B7 2A 10 44 4B 46 07 34 63 ED 31 B9 04 ....*.DKF.4c.1.. 00C0: EE A3 9B 9A AE E6 31 78 F4 EA 24 61 3B AB 58 64 ......1x..$a;.Xd 00D0: FF BB 87 27 62 25 81 DF DC A1 2F F6 ED A7 FF 7A ...'b%..../....z 00E0: 8F 51 2E 30 F8 A4 01 D2 85 39 5F 01 99 96 6F 5A .Q.0.....9_...oZ 00F0: 5B 70 19 46 FE 86 60 3E AD 80 10 09 DD 39 25 2F [p.F..`>.....9%/ 0100: 58 7F BB D2 74 F0 F7 46 1F 46 39 4A D8 53 D0 F3 X...t..F.F9J.S.. 0110: 2E 3B 71 A5 D4 6F FC F3 67 E4 07 8F DD 26 19 E1 .;q..o..g....&.. 0120: 8D 5B FA A3 93 11 9B E9 C8 3A C3 55 68 9A 92 E1 .[.......:.Uh... 0130: 52 76 38 E8 E1 BA BD FB 4F D5 EF B3 E7 48 83 31 Rv8.....O....H.1 0140: F0 82 21 E3 B6 BE A7 AB 6F EF 9F DF 4C CF 01 B8 ..!.....o...L... 0150: 62 6A 23 3D E7 09 4D 80 1B 7B 30 A4 C3 DD 07 7F bj#=..M...0..... 0160: 34 BE A4 26 B2 F6 41 E8 09 1D E3 20 98 AA 37 4F 4..&..A.... ..7O 0170: FF F7 F1 E2 29 70 31 47 3F 74 D0 14 16 FA 21 8A ....)p1G?t....!. 0180: 02 D5 8A 09 94 77 2E F2 59 28 8B 7C 50 92 0A 66 .....w..Y(..P..f 0190: 78 38 83 75 C4 B5 5A A8 11 C6 E5 C1 9D 66 55 CF x8.u..Z......fU. 01A0: 53 C4 AF D7 75 85 A9 42 13 56 EC 21 77 81 93 5A S...u..B.V.!w..Z 01B0: 0C EA 96 D9 49 CA A1 08 F2 97 3B 6D 9B 04 18 24 ....I.....;m...$ 01C0: 44 8E 7C 01 F2 DC 25 D8 5E 86 9A B1 39 DB F5 91 D.....%.^...9... 01D0: 32 6A D1 A6 70 8A A2 F7 DE A4 45 85 26 A8 1E 8C 2j..p.....E.&... 01E0: 5D 29 5B C8 4B D8 9A 6A 03 5E 70 F2 85 4F 6C 4B ])[.K..j.^p..OlK 01F0: 68 2F CA 54 F6 8C DA 32 FE C3 6B 83 3F 38 C6 7E h/.T...2..k.?8.. ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Tue Jun 11 08:00:00 CST 2024 until Tue Jun 18 07:00:00 CST 2024 certpath: Checking validity of OCSP response on Thu Jun 13 17:38:35 CST 2024 with allowed interval between Thu Jun 13 17:23:35 CST 2024 and Thu Jun 13 17:53:35 CST 2024 certpath: -checker8 validation succeeded certpath: cert2 validation succeeded. certpath: Cert path validation succeeded. (PKIX validation algorithm) certpath: -------------------------------------------------------------- certpath: KeySizeConstraints.permits(): EC certpath: KeySizeConstraints.permits(): EC java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com at ValidatePathWithURL.validateDomain(ValidatePathWithURL.java:129) at CAInterop.validate(CAInterop.java:788) at CAInterop.main(CAInterop.java:726) at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103) at java.base/java.lang.reflect.Method.invoke(Method.java:580) at com.sun.javatest.regtest.agent.MainWrapper$MainTask.run(MainWrapper.java:138) at java.base/java.lang.Thread.run(Thread.java:1575) JavaTest Message: Test threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com JavaTest Message: shutting down test STATUS:Failed.`main' threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com rerun: cd /home/yansendao/git/jdk/tmp/scratch && \ DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/995/bus \ DISPLAY=:7 \ HOME=/home/yansendao \ LANG=en_US.UTF-8 \ PATH=/bin:/usr/bin:/usr/sbin \ XDG_RUNTIME_DIR=/run/user/995 \ XDG_SESSION_ID=1273615 \ CLASSPATH=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/tmp/classes/test/lib:/home/yansendao/git/jdk/test/lib:/home/yansendao/software/jdk/jtreg-7/lib/javatest.jar:/home/yansendao/software/jdk/jtreg-7/lib/jtreg.jar \ /home/yansendao/software/jdk/openjdk/jdk-binary/bin/java \ -Dtest.vm.opts= \ -Dtest.tool.vm.opts= \ -Dtest.compiler.opts= \ -Dtest.java.opts= \ -Dtest.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \ -Dcompile.jdk=/home/yansendao/software/jdk/openjdk/jdk-binary \ -Dtest.timeout.factor=1.0 \ -Dtest.root=/home/yansendao/git/jdk/test/jdk \ -Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java#digicerttlsrsarootg5 \ -Dtest.file=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification/CAInterop.java \ -Dtest.src=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification \ -Dtest.src.path=/home/yansendao/git/jdk/test/jdk/security/infra/java/security/cert/CertPathValidator/certification:/home/yansendao/git/jdk/test/lib \ -Dtest.classes=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d \ -Dtest.class.path=/home/yansendao/git/jdk/tmp/classes/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d:/home/yansendao/git/jdk/tmp/classes/test/lib \ -Djava.security.debug=certpath,ocsp \ com.sun.javatest.regtest.agent.MainWrapper /home/yansendao/git/jdk/tmp/security/infra/java/security/cert/CertPathValidator/certification/CAInterop_digicerttlsrsarootg5.d/main.0.jta digicerttlsrsarootg5 OCSP TEST RESULT: Failed. Execution failed: `main' threw exception: java.lang.RuntimeException: Failed to validate https://digicert-tls-rsa4096-root-g5-revoked.chain-demos.digicert.com -------------------------------------------------- Test results: failed: 1 Results written to /home/yansendao/git/jdk/tmp Error: Some tests failed or other problems occurred.