Directory "JTwork" not found: creating Directory "JTreport" not found: creating -------------------------------------------------- TEST: security/infra/java/security/cert/CertPathValidator/certification/ComodoCA.java TEST JDK: c:\Users\PRAJWALK\software\jdks\jdk-11.0.12 ACTION: build -- Passed. Build successful REASON: User specified action: run build ValidatePathWithParams TIME: 1.03 seconds messages: command: build ValidatePathWithParams reason: User specified action: run build ValidatePathWithParams Test directory: compile: ValidatePathWithParams elapsed time (seconds): 1.03 ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 1.011 seconds messages: command: compile C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification\ValidatePathWithParams.java reason: .class file out of date or does not exist Mode: othervm elapsed time (seconds): 1.011 configuration: javac compilation environment source path: C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification class path: C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d rerun: cd 'C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\scratch' && \ PATH='C:\cygwin64\usr\local\bin;C:\cygwin64\bin;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0;C:\WINDOWS\System32\OpenSSH;C:\Users\PRAJWALK\Documents\SRs\11u8_ssl\instantclient_19_8;C:\Users\PRAJWALK\Documents\SRs\11u8_ssl\instantclient_19_8;C:\Program Files\TortoiseHg;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\Tools;C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\Bin\NETFX 4.0 Tools;C:\Program Files\Git\cmd;C:\Program Files\PuTTY;C:\Users\PRAJWALK\AppData\Local\Microsoft\WindowsApps;C:\Users\PRAJWALK\software\apache-maven-3.6.3-bin\apache-maven-3.6.3\bin;C:\Users\PRAJWALK\software\apache-cassandra-3.11.9\bin;C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\bin\amd64;C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\crt\src;C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\Lib\x64;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\Tools;C:\Users\PRAJWALK\software\jdks\jdk-16\bin' \ SystemDrive=C: \ SystemRoot='C:\WINDOWS' \ TEMP='C:\cygwin64\tmp' \ TMP='C:\cygwin64\tmp' \ TZ=Asia/Kolkata \ windir='C:\WINDOWS' \ 'c:\Users\PRAJWALK\software\jdks\jdk-11.0.12\bin\javac' \ -J-Dtest.vm.opts= \ -J-Dtest.tool.vm.opts= \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk='c:\Users\PRAJWALK\software\jdks\jdk-11.0.12' \ -J-Dcompile.jdk='c:\Users\PRAJWALK\software\jdks\jdk-11.0.12' \ -J-Dtest.timeout.factor=2.0 \ -J-Dtest.root='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk' \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/ComodoCA.java \ -J-Dtest.file='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.java' \ -J-Dtest.src='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -J-Dtest.src.path='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -J-Dtest.classes='C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -J-Dtest.class.path='C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -d 'C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -sourcepath 'C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -classpath 'C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification;C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' 'C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification\ValidatePathWithParams.java' STDOUT: STDERR: ACTION: build -- Passed. Build successful REASON: Named class compiled on demand TIME: 1.262 seconds messages: command: build ComodoCA reason: Named class compiled on demand Test directory: compile: ComodoCA elapsed time (seconds): 1.262 ACTION: compile -- Passed. Compilation successful REASON: .class file out of date or does not exist TIME: 1.261 seconds messages: command: compile C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.java reason: .class file out of date or does not exist Mode: othervm elapsed time (seconds): 1.261 configuration: javac compilation environment source path: C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification class path: C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d rerun: cd 'C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\scratch' && \ PATH='C:\cygwin64\usr\local\bin;C:\cygwin64\bin;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0;C:\WINDOWS\System32\OpenSSH;C:\Users\PRAJWALK\Documents\SRs\11u8_ssl\instantclient_19_8;C:\Users\PRAJWALK\Documents\SRs\11u8_ssl\instantclient_19_8;C:\Program Files\TortoiseHg;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\Tools;C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\Bin\NETFX 4.0 Tools;C:\Program Files\Git\cmd;C:\Program Files\PuTTY;C:\Users\PRAJWALK\AppData\Local\Microsoft\WindowsApps;C:\Users\PRAJWALK\software\apache-maven-3.6.3-bin\apache-maven-3.6.3\bin;C:\Users\PRAJWALK\software\apache-cassandra-3.11.9\bin;C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\bin\amd64;C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\crt\src;C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\Lib\x64;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\Tools;C:\Users\PRAJWALK\software\jdks\jdk-16\bin' \ SystemDrive=C: \ SystemRoot='C:\WINDOWS' \ TEMP='C:\cygwin64\tmp' \ TMP='C:\cygwin64\tmp' \ TZ=Asia/Kolkata \ windir='C:\WINDOWS' \ 'c:\Users\PRAJWALK\software\jdks\jdk-11.0.12\bin\javac' \ -J-Dtest.vm.opts= \ -J-Dtest.tool.vm.opts= \ -J-Dtest.compiler.opts= \ -J-Dtest.java.opts= \ -J-Dtest.jdk='c:\Users\PRAJWALK\software\jdks\jdk-11.0.12' \ -J-Dcompile.jdk='c:\Users\PRAJWALK\software\jdks\jdk-11.0.12' \ -J-Dtest.timeout.factor=2.0 \ -J-Dtest.root='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk' \ -J-Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/ComodoCA.java \ -J-Dtest.file='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.java' \ -J-Dtest.src='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -J-Dtest.src.path='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -J-Dtest.classes='C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -J-Dtest.class.path='C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -d 'C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -sourcepath 'C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -classpath 'C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification;C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' 'C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.java' STDOUT: STDERR: ACTION: main -- Passed. Execution successful REASON: User specified action: run main/othervm -Djava.security.debug=certpath ComodoCA OCSP TIME: 2.495 seconds messages: command: main -Djava.security.debug=certpath ComodoCA OCSP reason: User specified action: run main/othervm -Djava.security.debug=certpath ComodoCA OCSP Mode: othervm [/othervm specified] elapsed time (seconds): 2.495 configuration: STDOUT: ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Thu Nov 29 22:11:09 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Thu Nov 29 21:42:02 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Fri Nov 30 00:28:13 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Thu Nov 29 23:36:00 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test STDERR: certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(SN: 9b7e0649a33e62b9d5ee90487129ef57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(SN: 4caaf9cadb636fe01ff74ed85b03869d Issuer: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB Subject: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: secp112r1 certpath: Constraints: secp112r2 certpath: Constraints: secp128r1 certpath: Constraints: secp128r2 certpath: Constraints: secp160k1 certpath: Constraints: secp160r1 certpath: Constraints: secp160r2 certpath: Constraints: secp192k1 certpath: Constraints: secp192r1 certpath: Constraints: secp224k1 certpath: Constraints: secp224r1 certpath: Constraints: secp256k1 certpath: Constraints: sect113r1 certpath: Constraints: sect113r2 certpath: Constraints: sect131r1 certpath: Constraints: sect131r2 certpath: Constraints: sect163k1 certpath: Constraints: sect163r1 certpath: Constraints: sect163r2 certpath: Constraints: sect193r1 certpath: Constraints: sect193r2 certpath: Constraints: sect233k1 certpath: Constraints: sect233r1 certpath: Constraints: sect239k1 certpath: Constraints: sect283k1 certpath: Constraints: sect283r1 certpath: Constraints: sect409k1 certpath: Constraints: sect409r1 certpath: Constraints: sect571k1 certpath: Constraints: sect571r1 certpath: Constraints: X9.62 c2tnb191v1 certpath: Constraints: X9.62 c2tnb191v2 certpath: Constraints: X9.62 c2tnb191v3 certpath: Constraints: X9.62 c2tnb239v1 certpath: Constraints: X9.62 c2tnb239v2 certpath: Constraints: X9.62 c2tnb239v3 certpath: Constraints: X9.62 c2tnb359v1 certpath: Constraints: X9.62 c2tnb431r1 certpath: Constraints: X9.62 prime192v2 certpath: Constraints: X9.62 prime192v3 certpath: Constraints: X9.62 prime239v1 certpath: Constraints: X9.62 prime239v2 certpath: Constraints: X9.62 prime239v3 certpath: Constraints: brainpoolP256r1 certpath: Constraints: brainpoolP320r1 certpath: Constraints: brainpoolP384r1 certpath: Constraints: brainpoolP512r1 certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=COMODO RSA Extended Validation Secure Server CA, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 595250832037245141724642107398533641144111340640849154810839512193646804439589382557795096048235159392412856809181253983148280442751106836828767077478502910675291715965426418324395462826337195608826159904332409833532414343087397304684051488024083060971973988667565926401713702437407307790551210783180012029671811979458976709742365579736599681150756374332129237698142054260771585540729412505699671993111094681722253786369180597052805125225748672266569013967025850135765598233721214965171040686884703517711864518647963618102322884373894861238464186441528415873877499307554355231373646804211013770034465627350166153734933786011622475019872581027516832913754790596939102532587063612068091625752995700206528059096165261547017202283116886060219954285939324476288744352486373249118864714420341870384243932900936553074796547571643358129426474424573956572670213304441994994142333208766235762328926816055054634905252931414737971249889745696283503174642385591131856834241724878687870772321902051261453524679758731747154638983677185705464969589189761598154153383380395065347776922242683529305823609958629983678843126221186204478003285765580771286537570893899006127941280337699169761047271395591258462580922460487748761665926731923248227868312659 public exponent: 65537 Validity: [From: Tue Jan 19 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB SerialNumber: [ 4caaf9ca db636fe0 1ff74ed8 5b03869d] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: BB AF 7E 02 3D FA A6 F1 3C 84 8E AD EE 38 98 EC ....=...<....8.. 0010: D9 32 32 D4 .22. ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 0A F1 D5 46 84 B7 AE 51 BB 6C B2 4D 41 14 00 93 ...F...Q.l.MA... 0010: 4C 9C CB E5 C0 54 CF A0 25 8E 02 F9 FD B0 A2 0D L....T..%....... 0020: F5 20 98 3C 13 2D AC 56 A2 B0 D6 7E 11 92 E9 2E . .<.-.V........ 0030: BA 9E 2E 9A 72 B1 BD 19 44 6C 61 35 A2 9A B4 16 ....r...Dla5.... 0040: 12 69 5A 8C E1 D7 3E A4 1A E8 2F 03 F4 AE 61 1D .iZ...>.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i..@(.....]." 01E0: F5 52 E6 58 C5 1F 88 31 43 EE 88 1D D7 C6 8E 3C .R.X...1C......< 01F0: 43 6A 1D A7 18 DE 7D 3D 16 F1 62 F9 CA 90 A8 FD Cj.....=..b..... ] Cert Issuer: CN=USERTrust RSA Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Cert Subject: CN=usertrustrsacertificationauthority-ev.comodoca.com, OU=COMODO EV SGC SSL, O=Sectigo Limited, STREET="3rd Floor, 26 Office Village", STREET=Exchange Quay, STREET=Trafford Road, L=Salford, ST=Greater Manchester, OID.2.5.4.17=M5 3EQ, C=GB, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, SERIALNUMBER=04058690 Key: RSA Date: Mon Jun 28 21:22:45 IST 2021 ] certpath: KeySizeConstraints.permits(): RSA certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.6449.1.2.1.5.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) 1.3.6.1.4.1.6449.1.2.1.5.1 CRIT: false EP: 1.3.6.1.4.1.6449.1.2.1.5.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Mon Jun 28 21:22:45 IST 2021... certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(SN: 1fd6d30fca3ca51a81bbc640e35032d Issuer: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Subject: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=USERTrust RSA Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 522487583617525075342463885337225473046087723081156730587063215030496109729932253265799265766294932028686353264919061580385049464836356954829105402248183391733854684450211900139329107087047502332675235340095978056484941150490991882497576839367560163275257272036049422473305642441793498160967907038120493294785868862142444988597324986519765187124452830375519261844367396077186284797811937481089746704868620023056657703518830114050467515432464700561931699003833397734285032347494370276582779046272750546463559965522756516229404690045766706787524020435412948721306424393993169229289467834493533160413056397476973792368174460238110091615871730381483443293300931137331198904539782455960886494693833561140472387578208844296917484075205019671738707845074905611668239406330644414805698779400987201310909725918270612084339872279020908867861033880814315358914565703236337174308524328436716608021785644764836810087074012339936543228255034168864046688601575503801789648707560351240165066165280965007233076211669633638389449522443357879549163908594012762321622514340998051396106368358204746516265702776221449060497686599696175189532242983987568916433102740386532378470836364707455134729548367373189550921756904777340153719441907345834660183638543 public exponent: 65537 Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 01fd6d30 fca3ca51 a81bbc64 0e35032d] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 53 79 BF 5A AA 2B 4A CF 54 80 E1 D8 9B C0 9D F2 Sy.Z.+J.T....... 0010: B2 03 66 CB ..f. ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 5C D4 7C 0D CF F7 01 7D 41 99 65 0C 73 C5 52 9F \.......A.e.s.R. 0010: CB F8 CF 99 06 7F 1B DA 43 15 9F 9E 02 55 57 96 ........C....UW. 0020: 14 F1 52 3C 27 87 94 28 ED 1F 3A 01 37 A2 76 FC ..R<'..(..:.7.v. 0030: 53 50 C0 84 9B C6 6B 4E BA 8C 21 4F A2 8E 55 62 SP....kN..!O..Ub 0040: 91 F3 69 15 D8 BC 88 E3 C4 AA 0B FD EF A8 E9 4B ..i............K 0050: 55 2A 06 20 6D 55 78 29 19 EE 5F 30 5C 4B 24 11 U*. mUx).._0\K$. 0060: 55 FF 24 9A 6E 5E 2A 2B EE 0B 4D 9F 7F F7 01 38 U.$.n^*+..M....8 0070: 94 14 95 43 07 09 FB 60 A9 EE 1C AB 12 8C A0 9A ...C...`........ 0080: 5E A7 98 6A 59 6D 8B 3F 08 FB C8 D1 45 AF 18 15 ^..jYm.?....E... 0090: 64 90 12 0F 73 28 2E C5 E2 24 4E FC 58 EC F0 F4 d...s(...$N.X... 00A0: 45 FE 22 B3 EB 2F 8E D2 D9 45 61 05 C1 97 6F A8 E."../...Ea...o. 00B0: 76 72 8F 8B 8C 36 AF BF 0D 05 CE 71 8D E6 A6 6F vr...6.....q...o 00C0: 1F 6C A6 71 62 C5 D8 D0 83 72 0C F1 67 11 89 0C .l.qb....r..g... 00D0: 9C 13 4C 72 34 DF BC D5 71 DF AA 71 DD E1 B9 6C ..Lr4...q..q...l 00E0: 8C 3C 12 5D 65 DA BD 57 12 B6 43 6B FF E5 DE 4D .<.]e..W..Ck...M 00F0: 66 11 51 CF 99 AE EC 17 B6 E8 71 91 8C DE 49 FE f.Q.......q...I. 0100: DD 35 71 A2 15 27 94 1C CF 61 E3 26 BB 6F A3 67 .5q..'...a.&.o.g 0110: 25 21 5D E6 DD 1D 0B 2E 68 1B 3B 82 AF EC 83 67 %!].....h.;....g 0120: 85 D4 98 51 74 B1 B9 99 80 89 FF 7F 78 19 5C 79 ...Qt.......x.\y 0130: 4A 60 2E 92 40 AE 4C 37 2A 2C C9 C7 62 C8 0E 5D J`..@.L7*,..b..] 0140: F7 36 5B CA E0 25 25 01 B4 DD 1A 07 9C 77 00 3F .6[..%%......w.? 0150: D0 DC D5 EC 3D D4 FA BB 3F CC 85 D6 6F 7F A9 2D ....=...?...o..- 0160: DF B9 02 F7 F5 97 9A B5 35 DA C3 67 B0 87 4A A9 ........5..g..J. 0170: 28 9E 23 8E FF 5C 27 6B E1 B0 4F F3 07 EE 00 2E (.#..\'k..O..... 0180: D4 59 87 CB 52 41 95 EA F4 47 D7 EE 64 41 55 7C .Y..RA...G..dAU. 0190: 8D 59 02 95 DD 62 9D C2 B9 EE 5A 28 74 84 A5 9B .Y...b....Z(t... 01A0: B7 90 C7 0C 07 DF F5 89 36 74 32 D6 28 C1 B0 B0 ........6t2.(... 01B0: 0B E0 9C 4C C3 1C D6 FC E3 69 B5 47 46 81 2F A2 ...L.....i.GF./. 01C0: 82 AB D3 63 44 70 C4 8D FF 2D 33 BA AD 8F 7B B5 ...cDp...-3..... 01D0: 70 88 AE 3E 19 CF 40 28 D8 FC C8 90 BB 5D 99 22 p..>..@(.....]." 01E0: F5 52 E6 58 C5 1F 88 31 43 EE 88 1D D7 C6 8E 3C .R.X...1C......< 01F0: 43 6A 1D A7 18 DE 7D 3D 16 F1 62 F9 CA 90 A8 FD Cj.....=..b..... ] Cert Issuer: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Cert Subject: CN=USERTrust RSA Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Key: RSA Date: Mon Jun 28 21:22:45 IST 2021 ] certpath: KeySizeConstraints.permits(): RSA certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.5.29.32.0 certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Mon Jun 28 21:22:45 IST 2021... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US; subject: CN=USERTrust RSA Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US; serial#: 20497713873245400500623124166461312899 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 0f6bb751 efa7d2e8 368e6064 07334f83 Subject: CN=USERTrust RSA Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Issuer: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: connecting to OCSP service at: http://ocsp.usertrust.com certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 5379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB certpath: OCSP response produced at: Sun Jun 27 04:22:18 IST 2021 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sun Jun 27 04:22:18 IST 2021 certpath: nextUpdate: Sun Jul 04 04:22:18 IST 2021 certpath: Status of certificate (with serial number 20497713873245400500623124166461312899) is: GOOD certpath: OCSP response is signed by the target's Issuing CA certpath: Constraints.permits(): SHA384withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 522487583617525075342463885337225473046087723081156730587063215030496109729932253265799265766294932028686353264919061580385049464836356954829105402248183391733854684450211900139329107087047502332675235340095978056484941150490991882497576839367560163275257272036049422473305642441793498160967907038120493294785868862142444988597324986519765187124452830375519261844367396077186284797811937481089746704868620023056657703518830114050467515432464700561931699003833397734285032347494370276582779046272750546463559965522756516229404690045766706787524020435412948721306424393993169229289467834493533160413056397476973792368174460238110091615871730381483443293300931137331198904539782455960886494693833561140472387578208844296917484075205019671738707845074905611668239406330644414805698779400987201310909725918270612084339872279020908867861033880814315358914565703236337174308524328436716608021785644764836810087074012339936543228255034168864046688601575503801789648707560351240165066165280965007233076211669633638389449522443357879549163908594012762321622514340998051396106368358204746516265702776221449060497686599696175189532242983987568916433102740386532378470836364707455134729548367373189550921756904777340153719441907345834660183638543 public exponent: 65537 Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 01fd6d30 fca3ca51 a81bbc64 0e35032d] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 53 79 BF 5A AA 2B 4A CF 54 80 E1 D8 9B C0 9D F2 Sy.Z.+J.T....... 0010: B2 03 66 CB ..f. ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 5C D4 7C 0D CF F7 01 7D 41 99 65 0C 73 C5 52 9F \.......A.e.s.R. 0010: CB F8 CF 99 06 7F 1B DA 43 15 9F 9E 02 55 57 96 ........C....UW. 0020: 14 F1 52 3C 27 87 94 28 ED 1F 3A 01 37 A2 76 FC ..R<'..(..:.7.v. 0030: 53 50 C0 84 9B C6 6B 4E BA 8C 21 4F A2 8E 55 62 SP....kN..!O..Ub 0040: 91 F3 69 15 D8 BC 88 E3 C4 AA 0B FD EF A8 E9 4B ..i............K 0050: 55 2A 06 20 6D 55 78 29 19 EE 5F 30 5C 4B 24 11 U*. mUx).._0\K$. 0060: 55 FF 24 9A 6E 5E 2A 2B EE 0B 4D 9F 7F F7 01 38 U.$.n^*+..M....8 0070: 94 14 95 43 07 09 FB 60 A9 EE 1C AB 12 8C A0 9A ...C...`........ 0080: 5E A7 98 6A 59 6D 8B 3F 08 FB C8 D1 45 AF 18 15 ^..jYm.?....E... 0090: 64 90 12 0F 73 28 2E C5 E2 24 4E FC 58 EC F0 F4 d...s(...$N.X... 00A0: 45 FE 22 B3 EB 2F 8E D2 D9 45 61 05 C1 97 6F A8 E."../...Ea...o. 00B0: 76 72 8F 8B 8C 36 AF BF 0D 05 CE 71 8D E6 A6 6F vr...6.....q...o 00C0: 1F 6C A6 71 62 C5 D8 D0 83 72 0C F1 67 11 89 0C .l.qb....r..g... 00D0: 9C 13 4C 72 34 DF BC D5 71 DF AA 71 DD E1 B9 6C ..Lr4...q..q...l 00E0: 8C 3C 12 5D 65 DA BD 57 12 B6 43 6B FF E5 DE 4D .<.]e..W..Ck...M 00F0: 66 11 51 CF 99 AE EC 17 B6 E8 71 91 8C DE 49 FE f.Q.......q...I. 0100: DD 35 71 A2 15 27 94 1C CF 61 E3 26 BB 6F A3 67 .5q..'...a.&.o.g 0110: 25 21 5D E6 DD 1D 0B 2E 68 1B 3B 82 AF EC 83 67 %!].....h.;....g 0120: 85 D4 98 51 74 B1 B9 99 80 89 FF 7F 78 19 5C 79 ...Qt.......x.\y 0130: 4A 60 2E 92 40 AE 4C 37 2A 2C C9 C7 62 C8 0E 5D J`..@.L7*,..b..] 0140: F7 36 5B CA E0 25 25 01 B4 DD 1A 07 9C 77 00 3F .6[..%%......w.? 0150: D0 DC D5 EC 3D D4 FA BB 3F CC 85 D6 6F 7F A9 2D ....=...?...o..- 0160: DF B9 02 F7 F5 97 9A B5 35 DA C3 67 B0 87 4A A9 ........5..g..J. 0170: 28 9E 23 8E FF 5C 27 6B E1 B0 4F F3 07 EE 00 2E (.#..\'k..O..... 0180: D4 59 87 CB 52 41 95 EA F4 47 D7 EE 64 41 55 7C .Y..RA...G..dAU. 0190: 8D 59 02 95 DD 62 9D C2 B9 EE 5A 28 74 84 A5 9B .Y...b....Z(t... 01A0: B7 90 C7 0C 07 DF F5 89 36 74 32 D6 28 C1 B0 B0 ........6t2.(... 01B0: 0B E0 9C 4C C3 1C D6 FC E3 69 B5 47 46 81 2F A2 ...L.....i.GF./. 01C0: 82 AB D3 63 44 70 C4 8D FF 2D 33 BA AD 8F 7B B5 ...cDp...-3..... 01D0: 70 88 AE 3E 19 CF 40 28 D8 FC C8 90 BB 5D 99 22 p..>..@(.....]." 01E0: F5 52 E6 58 C5 1F 88 31 43 EE 88 1D D7 C6 8E 3C .R.X...1C......< 01F0: 43 6A 1D A7 18 DE 7D 3D 16 F1 62 F9 CA 90 A8 FD Cj.....=..b..... ] Key: RSA ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sun Jun 27 04:22:18 IST 2021 until Sun Jul 04 04:22:18 IST 2021 certpath: Checking validity of OCSP response on: Mon Jun 28 21:22:45 IST 2021 certpath: -checker7 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: CN=usertrustrsacertificationauthority-ev.comodoca.com, OU=COMODO EV SGC SSL, O=COMODO CA Limited, STREET="3rd Floor, 26 Office Village", STREET=Exchange Quay, STREET=Trafford Road, L=Salford, ST=Greater Manchester, OID.2.5.4.17=M5 3EQ, C=GB, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, SERIALNUMBER=04058690 certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA256withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 522487583617525075342463885337225473046087723081156730587063215030496109729932253265799265766294932028686353264919061580385049464836356954829105402248183391733854684450211900139329107087047502332675235340095978056484941150490991882497576839367560163275257272036049422473305642441793498160967907038120493294785868862142444988597324986519765187124452830375519261844367396077186284797811937481089746704868620023056657703518830114050467515432464700561931699003833397734285032347494370276582779046272750546463559965522756516229404690045766706787524020435412948721306424393993169229289467834493533160413056397476973792368174460238110091615871730381483443293300931137331198904539782455960886494693833561140472387578208844296917484075205019671738707845074905611668239406330644414805698779400987201310909725918270612084339872279020908867861033880814315358914565703236337174308524328436716608021785644764836810087074012339936543228255034168864046688601575503801789648707560351240165066165280965007233076211669633638389449522443357879549163908594012762321622514340998051396106368358204746516265702776221449060497686599696175189532242983987568916433102740386532378470836364707455134729548367373189550921756904777340153719441907345834660183638543 public exponent: 65537 Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 01fd6d30 fca3ca51 a81bbc64 0e35032d] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 53 79 BF 5A AA 2B 4A CF 54 80 E1 D8 9B C0 9D F2 Sy.Z.+J.T....... 0010: B2 03 66 CB ..f. ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 5C D4 7C 0D CF F7 01 7D 41 99 65 0C 73 C5 52 9F \.......A.e.s.R. 0010: CB F8 CF 99 06 7F 1B DA 43 15 9F 9E 02 55 57 96 ........C....UW. 0020: 14 F1 52 3C 27 87 94 28 ED 1F 3A 01 37 A2 76 FC ..R<'..(..:.7.v. 0030: 53 50 C0 84 9B C6 6B 4E BA 8C 21 4F A2 8E 55 62 SP....kN..!O..Ub 0040: 91 F3 69 15 D8 BC 88 E3 C4 AA 0B FD EF A8 E9 4B ..i............K 0050: 55 2A 06 20 6D 55 78 29 19 EE 5F 30 5C 4B 24 11 U*. mUx).._0\K$. 0060: 55 FF 24 9A 6E 5E 2A 2B EE 0B 4D 9F 7F F7 01 38 U.$.n^*+..M....8 0070: 94 14 95 43 07 09 FB 60 A9 EE 1C AB 12 8C A0 9A ...C...`........ 0080: 5E A7 98 6A 59 6D 8B 3F 08 FB C8 D1 45 AF 18 15 ^..jYm.?....E... 0090: 64 90 12 0F 73 28 2E C5 E2 24 4E FC 58 EC F0 F4 d...s(...$N.X... 00A0: 45 FE 22 B3 EB 2F 8E D2 D9 45 61 05 C1 97 6F A8 E."../...Ea...o. 00B0: 76 72 8F 8B 8C 36 AF BF 0D 05 CE 71 8D E6 A6 6F vr...6.....q...o 00C0: 1F 6C A6 71 62 C5 D8 D0 83 72 0C F1 67 11 89 0C .l.qb....r..g... 00D0: 9C 13 4C 72 34 DF BC D5 71 DF AA 71 DD E1 B9 6C ..Lr4...q..q...l 00E0: 8C 3C 12 5D 65 DA BD 57 12 B6 43 6B FF E5 DE 4D .<.]e..W..Ck...M 00F0: 66 11 51 CF 99 AE EC 17 B6 E8 71 91 8C DE 49 FE f.Q.......q...I. 0100: DD 35 71 A2 15 27 94 1C CF 61 E3 26 BB 6F A3 67 .5q..'...a.&.o.g 0110: 25 21 5D E6 DD 1D 0B 2E 68 1B 3B 82 AF EC 83 67 %!].....h.;....g 0120: 85 D4 98 51 74 B1 B9 99 80 89 FF 7F 78 19 5C 79 ...Qt.......x.\y 0130: 4A 60 2E 92 40 AE 4C 37 2A 2C C9 C7 62 C8 0E 5D J`..@.L7*,..b..] 0140: F7 36 5B CA E0 25 25 01 B4 DD 1A 07 9C 77 00 3F .6[..%%......w.? 0150: D0 DC D5 EC 3D D4 FA BB 3F CC 85 D6 6F 7F A9 2D ....=...?...o..- 0160: DF B9 02 F7 F5 97 9A B5 35 DA C3 67 B0 87 4A A9 ........5..g..J. 0170: 28 9E 23 8E FF 5C 27 6B E1 B0 4F F3 07 EE 00 2E (.#..\'k..O..... 0180: D4 59 87 CB 52 41 95 EA F4 47 D7 EE 64 41 55 7C .Y..RA...G..dAU. 0190: 8D 59 02 95 DD 62 9D C2 B9 EE 5A 28 74 84 A5 9B .Y...b....Z(t... 01A0: B7 90 C7 0C 07 DF F5 89 36 74 32 D6 28 C1 B0 B0 ........6t2.(... 01B0: 0B E0 9C 4C C3 1C D6 FC E3 69 B5 47 46 81 2F A2 ...L.....i.GF./. 01C0: 82 AB D3 63 44 70 C4 8D FF 2D 33 BA AD 8F 7B B5 ...cDp...-3..... 01D0: 70 88 AE 3E 19 CF 40 28 D8 FC C8 90 BB 5D 99 22 p..>..@(.....]." 01E0: F5 52 E6 58 C5 1F 88 31 43 EE 88 1D D7 C6 8E 3C .R.X...1C......< 01F0: 43 6A 1D A7 18 DE 7D 3D 16 F1 62 F9 CA 90 A8 FD Cj.....=..b..... ] Cert Issuer: CN=USERTrust RSA Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Cert Subject: CN=usertrustrsacertificationauthority-ev.comodoca.com, OU=COMODO EV SGC SSL, O=COMODO CA Limited, STREET="3rd Floor, 26 Office Village", STREET=Exchange Quay, STREET=Trafford Road, L=Salford, ST=Greater Manchester, OID.2.5.4.17=M5 3EQ, C=GB, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, SERIALNUMBER=04058690 Key: RSA Date: Mon Jun 28 21:22:45 IST 2021 ] certpath: KeySizeConstraints.permits(): RSA certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.6449.1.2.1.5.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) 1.3.6.1.4.1.6449.1.2.1.5.1 CRIT: false EP: 1.3.6.1.4.1.6449.1.2.1.5.1 (2) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Mon Jun 28 21:22:45 IST 2021... certpath: X509CertSelector.match(SN: 10020 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(SN: 9b7e0649a33e62b9d5ee90487129ef57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(SN: 10020 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(SN: 9b7e0649a33e62b9d5ee90487129ef57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(SN: 5c8b99c55a94c5d27156decd8980cc26 Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 4105375390653649233713119777321734233266869078187987018407577420645365974521940631581724628993333063239514030334497 public y coord: 27675056301647551922849568396717635354139598802203471838229080227718009101673931134993105203564358052385576850782585 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 5c8b99c5 5a94c5d2 7156decd 8980cc26] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 3A E1 09 86 D4 CF 19 C2 96 76 74 49 76 DC E0 35 :........vtIv..5 0010: C6 63 63 9A .cc. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 30 36 67 A1 16 08 DC E4 97 00 41 1D 4E 0e.06g.......A.N 0010: BE E1 63 01 CF 3B AA 42 11 64 A0 9D 94 39 02 11 ..c..;.B.d...9.. 0020: 79 5C 7B 1D FA 64 B9 EE 16 42 B3 BF 8A C2 09 C4 y\...d...B...... 0030: EC E4 B1 4D 02 31 00 E9 2A 61 47 8C 52 4A 4B 4E ...M.1..*aG.RJKN 0040: 18 70 F6 D6 44 D6 6E F5 83 BA 6D 58 BD 24 D9 56 .p..D.n...mX.$.V 0050: 48 EA EF C4 A2 46 81 88 6A 3A 46 D1 A9 9B 4D C9 H....F..j:F...M. 0060: 61 DA D1 5D 57 6A 18 a..]Wj. ] Cert Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Cert Subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Key: EC Date: Mon Jun 28 21:22:45 IST 2021 ] certpath: KeySizeConstraints.permits(): EC certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.5.29.32.0 certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Mon Jun 28 21:22:45 IST 2021... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US; subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US; serial#: 81133254971024055075643788472352877138 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 3d09b24f 5c08a7ce 8eb85a51 d3c1aa52 Subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: connecting to OCSP service at: http://ocsp.trust-provider.com certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 3AE10986D4CF19C29676744976DCE035C663639A certpath: OCSP response produced at: Sun Jun 27 04:22:18 IST 2021 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sun Jun 27 04:22:18 IST 2021 certpath: nextUpdate: Sun Jul 04 04:22:18 IST 2021 certpath: Status of certificate (with serial number 81133254971024055075643788472352877138) is: GOOD certpath: OCSP response is signed by the target's Issuing CA certpath: Constraints.permits(): SHA384withECDSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 4105375390653649233713119777321734233266869078187987018407577420645365974521940631581724628993333063239514030334497 public y coord: 27675056301647551922849568396717635354139598802203471838229080227718009101673931134993105203564358052385576850782585 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 5c8b99c5 5a94c5d2 7156decd 8980cc26] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 3A E1 09 86 D4 CF 19 C2 96 76 74 49 76 DC E0 35 :........vtIv..5 0010: C6 63 63 9A .cc. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 30 36 67 A1 16 08 DC E4 97 00 41 1D 4E 0e.06g.......A.N 0010: BE E1 63 01 CF 3B AA 42 11 64 A0 9D 94 39 02 11 ..c..;.B.d...9.. 0020: 79 5C 7B 1D FA 64 B9 EE 16 42 B3 BF 8A C2 09 C4 y\...d...B...... 0030: EC E4 B1 4D 02 31 00 E9 2A 61 47 8C 52 4A 4B 4E ...M.1..*aG.RJKN 0040: 18 70 F6 D6 44 D6 6E F5 83 BA 6D 58 BD 24 D9 56 .p..D.n...mX.$.V 0050: 48 EA EF C4 A2 46 81 88 6A 3A 46 D1 A9 9B 4D C9 H....F..j:F...M. 0060: 61 DA D1 5D 57 6A 18 a..]Wj. ] Key: EC ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sun Jun 27 04:22:18 IST 2021 until Sun Jul 04 04:22:18 IST 2021 certpath: Checking validity of OCSP response on: Mon Jun 28 21:22:46 IST 2021 certpath: -checker7 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: CN=usertrustecccertificationauthority-ev.comodoca.com, OU=COMODO EV SGC SSL, O=Sectigo Limited, STREET="3rd Floor, 26 Office Village", STREET=Exchange Quay, STREET=Trafford Road, L=Salford, ST=Greater Manchester, OID.2.5.4.17=M5 3EQ, C=GB, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, SERIALNUMBER=04058690 certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA256withECDSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 4105375390653649233713119777321734233266869078187987018407577420645365974521940631581724628993333063239514030334497 public y coord: 27675056301647551922849568396717635354139598802203471838229080227718009101673931134993105203564358052385576850782585 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 5c8b99c5 5a94c5d2 7156decd 8980cc26] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 3A E1 09 86 D4 CF 19 C2 96 76 74 49 76 DC E0 35 :........vtIv..5 0010: C6 63 63 9A .cc. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 30 36 67 A1 16 08 DC E4 97 00 41 1D 4E 0e.06g.......A.N 0010: BE E1 63 01 CF 3B AA 42 11 64 A0 9D 94 39 02 11 ..c..;.B.d...9.. 0020: 79 5C 7B 1D FA 64 B9 EE 16 42 B3 BF 8A C2 09 C4 y\...d...B...... 0030: EC E4 B1 4D 02 31 00 E9 2A 61 47 8C 52 4A 4B 4E ...M.1..*aG.RJKN 0040: 18 70 F6 D6 44 D6 6E F5 83 BA 6D 58 BD 24 D9 56 .p..D.n...mX.$.V 0050: 48 EA EF C4 A2 46 81 88 6A 3A 46 D1 A9 9B 4D C9 H....F..j:F...M. 0060: 61 DA D1 5D 57 6A 18 a..]Wj. ] Cert Issuer: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Cert Subject: CN=usertrustecccertificationauthority-ev.comodoca.com, OU=COMODO EV SGC SSL, O=Sectigo Limited, STREET="3rd Floor, 26 Office Village", STREET=Exchange Quay, STREET=Trafford Road, L=Salford, ST=Greater Manchester, OID.2.5.4.17=M5 3EQ, C=GB, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, SERIALNUMBER=04058690 Key: EC Date: Mon Jun 28 21:22:45 IST 2021 ] certpath: KeySizeConstraints.permits(): EC certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.6449.1.2.1.5.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) 1.3.6.1.4.1.6449.1.2.1.5.1 CRIT: false EP: 1.3.6.1.4.1.6449.1.2.1.5.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Mon Jun 28 21:22:45 IST 2021... certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(SN: 10020 Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(SN: 5c8b99c55a94c5d27156decd8980cc26 Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withECDSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 4105375390653649233713119777321734233266869078187987018407577420645365974521940631581724628993333063239514030334497 public y coord: 27675056301647551922849568396717635354139598802203471838229080227718009101673931134993105203564358052385576850782585 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 5c8b99c5 5a94c5d2 7156decd 8980cc26] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 3A E1 09 86 D4 CF 19 C2 96 76 74 49 76 DC E0 35 :........vtIv..5 0010: C6 63 63 9A .cc. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 30 36 67 A1 16 08 DC E4 97 00 41 1D 4E 0e.06g.......A.N 0010: BE E1 63 01 CF 3B AA 42 11 64 A0 9D 94 39 02 11 ..c..;.B.d...9.. 0020: 79 5C 7B 1D FA 64 B9 EE 16 42 B3 BF 8A C2 09 C4 y\...d...B...... 0030: EC E4 B1 4D 02 31 00 E9 2A 61 47 8C 52 4A 4B 4E ...M.1..*aG.RJKN 0040: 18 70 F6 D6 44 D6 6E F5 83 BA 6D 58 BD 24 D9 56 .p..D.n...mX.$.V 0050: 48 EA EF C4 A2 46 81 88 6A 3A 46 D1 A9 9B 4D C9 H....F..j:F...M. 0060: 61 DA D1 5D 57 6A 18 a..]Wj. ] Cert Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Cert Subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Key: EC Date: Mon Jun 28 21:22:46 IST 2021 ] certpath: KeySizeConstraints.permits(): EC certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: KeyChecker.verifyCAKeyUsage() ---checking CA key usage... certpath: KeyChecker.verifyCAKeyUsage() CA key usage verified. certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 1, maxPathLength = 2 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 1 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 3 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 2.5.29.32.0 certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy ROOT certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Mon Jun 28 21:22:46 IST 2021... certpath: validity verified. certpath: ---checking subject/issuer name chaining... certpath: subject/issuer name chaining verified. certpath: ---checking signature... certpath: signature verified. certpath: BasicChecker.updateState issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US; subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US; serial#: 81133254971024055075643788472352877138 certpath: -checker6 validation succeeded certpath: -Using checker7 ... [sun.security.provider.certpath.RevocationChecker] certpath: RevocationChecker.check: checking cert SN: 3d09b24f 5c08a7ce 8eb85a51 d3c1aa52 Subject: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US certpath: connecting to OCSP service at: http://ocsp.trust-provider.com certpath: OCSP response status: SUCCESSFUL certpath: OCSP response type: basic certpath: Responder ID: byKey: 3AE10986D4CF19C29676744976DCE035C663639A certpath: OCSP response produced at: Sun Jun 27 04:22:18 IST 2021 certpath: OCSP number of SingleResponses: 1 certpath: thisUpdate: Sun Jun 27 04:22:18 IST 2021 certpath: nextUpdate: Sun Jul 04 04:22:18 IST 2021 certpath: Status of certificate (with serial number 81133254971024055075643788472352877138) is: GOOD certpath: OCSP response is signed by the target's Issuing CA certpath: Constraints.permits(): SHA384withECDSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 4105375390653649233713119777321734233266869078187987018407577420645365974521940631581724628993333063239514030334497 public y coord: 27675056301647551922849568396717635354139598802203471838229080227718009101673931134993105203564358052385576850782585 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 5c8b99c5 5a94c5d2 7156decd 8980cc26] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 3A E1 09 86 D4 CF 19 C2 96 76 74 49 76 DC E0 35 :........vtIv..5 0010: C6 63 63 9A .cc. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 30 36 67 A1 16 08 DC E4 97 00 41 1D 4E 0e.06g.......A.N 0010: BE E1 63 01 CF 3B AA 42 11 64 A0 9D 94 39 02 11 ..c..;.B.d...9.. 0020: 79 5C 7B 1D FA 64 B9 EE 16 42 B3 BF 8A C2 09 C4 y\...d...B...... 0030: EC E4 B1 4D 02 31 00 E9 2A 61 47 8C 52 4A 4B 4E ...M.1..*aG.RJKN 0040: 18 70 F6 D6 44 D6 6E F5 83 BA 6D 58 BD 24 D9 56 .p..D.n...mX.$.V 0050: 48 EA EF C4 A2 46 81 88 6A 3A 46 D1 A9 9B 4D C9 H....F..j:F...M. 0060: 61 DA D1 5D 57 6A 18 a..]Wj. ] Key: EC ] certpath: Verified signature of OCSP Response certpath: OCSP response validity interval is from Sun Jun 27 04:22:18 IST 2021 until Sun Jul 04 04:22:18 IST 2021 certpath: Checking validity of OCSP response on: Mon Jun 28 21:22:46 IST 2021 certpath: -checker7 validation succeeded certpath: cert1 validation succeeded. certpath: Checking cert2 - Subject: CN=usertrustecccertificationauthority-ev.comodoca.com, OU=COMODO EV SGC SSL, O=COMODO CA Limited, STREET="3rd Floor, 26 Office Village", STREET=Exchange Quay, STREET=Trafford Road, L=Salford, ST=Greater Manchester, OID.2.5.4.17=M5 3EQ, C=GB, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, SERIALNUMBER=04058690 certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA256withECDSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 4105375390653649233713119777321734233266869078187987018407577420645365974521940631581724628993333063239514030334497 public y coord: 27675056301647551922849568396717635354139598802203471838229080227718009101673931134993105203564358052385576850782585 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Mon Feb 01 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US SerialNumber: [ 5c8b99c5 5a94c5d2 7156decd 8980cc26] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: 3A E1 09 86 D4 CF 19 C2 96 76 74 49 76 DC E0 35 :........vtIv..5 0010: C6 63 63 9A .cc. ] ] ] Algorithm: [SHA384withECDSA] Signature: 0000: 30 65 02 30 36 67 A1 16 08 DC E4 97 00 41 1D 4E 0e.06g.......A.N 0010: BE E1 63 01 CF 3B AA 42 11 64 A0 9D 94 39 02 11 ..c..;.B.d...9.. 0020: 79 5C 7B 1D FA 64 B9 EE 16 42 B3 BF 8A C2 09 C4 y\...d...B...... 0030: EC E4 B1 4D 02 31 00 E9 2A 61 47 8C 52 4A 4B 4E ...M.1..*aG.RJKN 0040: 18 70 F6 D6 44 D6 6E F5 83 BA 6D 58 BD 24 D9 56 .p..D.n...mX.$.V 0050: 48 EA EF C4 A2 46 81 88 6A 3A 46 D1 A9 9B 4D C9 H....F..j:F...M. 0060: 61 DA D1 5D 57 6A 18 a..]Wj. ] Cert Issuer: CN=USERTrust ECC Extended Validation Secure Server CA, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US Cert Subject: CN=usertrustecccertificationauthority-ev.comodoca.com, OU=COMODO EV SGC SSL, O=COMODO CA Limited, STREET="3rd Floor, 26 Office Village", STREET=Exchange Quay, STREET=Trafford Road, L=Salford, ST=Greater Manchester, OID.2.5.4.17=M5 3EQ, C=GB, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB, SERIALNUMBER=04058690 Key: EC Date: Mon Jun 28 21:22:46 IST 2021 ] certpath: KeySizeConstraints.permits(): EC certpath: -checker2 validation succeeded certpath: -Using checker3 ... [sun.security.provider.certpath.KeyChecker] certpath: -checker3 validation succeeded certpath: -Using checker4 ... [sun.security.provider.certpath.ConstraintsChecker] certpath: ---checking basic constraints... certpath: i = 2, maxPathLength = 0 certpath: after processing, maxPathLength = 0 certpath: basic constraints verified. certpath: ---checking name constraints... certpath: prevNC = null, newNC = null certpath: mergedNC = null certpath: name constraints verified. certpath: -checker4 validation succeeded certpath: -Using checker5 ... [sun.security.provider.certpath.PolicyChecker] certpath: PolicyChecker.checkPolicy() ---checking certificate policies... certpath: PolicyChecker.checkPolicy() certIndex = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() BEFORE PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() policiesCritical = false certpath: PolicyChecker.processPolicies() rejectPolicyQualifiers = true certpath: PolicyChecker.processPolicies() processing policy: 1.3.6.1.4.1.6449.1.2.1.5.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.processPolicies() processing policy: 2.23.140.1.1 certpath: PolicyChecker.processParents(): matchAny = false certpath: PolicyChecker.processParents(): matchAny = true certpath: PolicyChecker.processParents() found parent: anyPolicy CRIT: false EP: anyPolicy (1) certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: explicitPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyMapping = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: inhibitAnyPolicy = 2 certpath: PolicyChecker.checkPolicy() AFTER PROCESSING: policyTree = anyPolicy ROOT anyPolicy CRIT: false EP: anyPolicy (1) 2.23.140.1.1 CRIT: false EP: 2.23.140.1.1 (2) 1.3.6.1.4.1.6449.1.2.1.5.1 CRIT: false EP: 1.3.6.1.4.1.6449.1.2.1.5.1 (2) certpath: PolicyChecker.checkPolicy() certificate policies verified certpath: -checker5 validation succeeded certpath: -Using checker6 ... [sun.security.provider.certpath.BasicChecker] certpath: ---checking validity:Mon Jun 28 21:22:46 IST 2021... certpath: X509CertSelector.match(SN: 9b7e0649a33e62b9d5ee90487129ef57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match STATUS:Passed. rerun: cd 'C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\scratch' && \ PATH='C:\cygwin64\usr\local\bin;C:\cygwin64\bin;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0;C:\WINDOWS\System32\OpenSSH;C:\Users\PRAJWALK\Documents\SRs\11u8_ssl\instantclient_19_8;C:\Users\PRAJWALK\Documents\SRs\11u8_ssl\instantclient_19_8;C:\Program Files\TortoiseHg;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\Tools;C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\Bin\NETFX 4.0 Tools;C:\Program Files\Git\cmd;C:\Program Files\PuTTY;C:\Users\PRAJWALK\AppData\Local\Microsoft\WindowsApps;C:\Users\PRAJWALK\software\apache-maven-3.6.3-bin\apache-maven-3.6.3\bin;C:\Users\PRAJWALK\software\apache-cassandra-3.11.9\bin;C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\bin\amd64;C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\crt\src;C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\Lib\x64;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\Tools;C:\Users\PRAJWALK\software\jdks\jdk-16\bin' \ SystemDrive=C: \ SystemRoot='C:\WINDOWS' \ TEMP='C:\cygwin64\tmp' \ TMP='C:\cygwin64\tmp' \ TZ=Asia/Kolkata \ windir='C:\WINDOWS' \ CLASSPATH='C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d;C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification;C:\Users\PRAJWALK\software\jtreg51\lib\javatest.jar;C:\Users\PRAJWALK\software\jtreg51\lib\jtreg.jar' \ 'c:\Users\PRAJWALK\software\jdks\jdk-11.0.12\bin\java' \ -Dtest.vm.opts= \ -Dtest.tool.vm.opts= \ -Dtest.compiler.opts= \ -Dtest.java.opts= \ -Dtest.jdk='c:\Users\PRAJWALK\software\jdks\jdk-11.0.12' \ -Dcompile.jdk='c:\Users\PRAJWALK\software\jdks\jdk-11.0.12' \ -Dtest.timeout.factor=2.0 \ -Dtest.root='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk' \ -Dtest.name=security/infra/java/security/cert/CertPathValidator/certification/ComodoCA.java \ -Dtest.file='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.java' \ -Dtest.src='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -Dtest.src.path='C:\cygwin64\home\PRAJWALK\repos\jdk11u-cpu\open\test\jdk\security\infra\java\security\cert\CertPathValidator\certification' \ -Dtest.classes='C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -Dtest.class.path='C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\classes\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d' \ -Djava.security.debug=certpath \ com.sun.javatest.regtest.agent.MainWrapper 'C:\Users\PRAJWALK\software\jtreg51\bin\JTwork\security\infra\java\security\cert\CertPathValidator\certification\ComodoCA.d\main.0.jta' OCSP ACTION: build -- Passed. All files up to date REASON: Named class compiled on demand TIME: 0.003 seconds messages: command: build ComodoCA reason: Named class compiled on demand elapsed time (seconds): 0.003 ACTION: main -- Passed. Execution successful REASON: User specified action: run main/othervm -Djava.security.debug=certpath ComodoCA CRL TIME: 2.773 seconds messages: command: main -Djava.security.debug=certpath ComodoCA CRL reason: User specified action: run main/othervm -Djava.security.debug=certpath ComodoCA CRL Mode: othervm [/othervm specified] elapsed time (seconds): 2.773 configuration: STDOUT: ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Thu Nov 29 22:11:09 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Thu Nov 29 21:42:02 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Fri Nov 30 00:28:13 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:GOOD ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: GOOD Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test ===================================================== CONFIGURATION ===================================================== http.proxyHost :null http.proxyPort :null https.proxyHost :null https.proxyPort :null https.socksProxyHost :null https.socksProxyPort :null jdk.certpath.disabledAlgorithms :MD2, MD5, SHA1 jdkCA & usage TLSServer, RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, include jdk.disabled.namedCurves Revocation options :[NO_FALLBACK, PREFER_CRLS] OCSP responder set :null Trusted root set: false Expected EE Status:REVOKED Expected EE Revocation Date:Thu Nov 29 23:36:00 IST 2018 ===================================================== Received exception: java.security.cert.CertPathValidatorException: validity check failed Expected Certificate status: REVOKED Certificate status after validation: EXPIRED WARNING: Certificate expired, skip the test STDERR: certpath: PKIXCertPathValidator.engineValidate()... certpath: X509CertSelector.match(SN: 9b7e0649a33e62b9d5ee90487129ef57 Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US) certpath: X509CertSelector.match: subject DNs don't match certpath: X509CertSelector.match(SN: 4caaf9cadb636fe01ff74ed85b03869d Issuer: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB Subject: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB) certpath: X509CertSelector.match returning: true certpath: YES - try this trustedCert certpath: anchor.getTrustedCert().getSubjectX500Principal() = CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB certpath: Constraints: MD2 certpath: Constraints: MD5 certpath: Constraints: SHA1 jdkCA & usage TLSServer certpath: Constraints set to jdkCA. certpath: Constraints usage length is 1 certpath: Constraints: RSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: DSA keySize < 1024 certpath: Constraints set to keySize: keySize < 1024 certpath: Constraints: EC keySize < 224 certpath: Constraints set to keySize: keySize < 224 certpath: Constraints: secp112r1 certpath: Constraints: secp112r2 certpath: Constraints: secp128r1 certpath: Constraints: secp128r2 certpath: Constraints: secp160k1 certpath: Constraints: secp160r1 certpath: Constraints: secp160r2 certpath: Constraints: secp192k1 certpath: Constraints: secp192r1 certpath: Constraints: secp224k1 certpath: Constraints: secp224r1 certpath: Constraints: secp256k1 certpath: Constraints: sect113r1 certpath: Constraints: sect113r2 certpath: Constraints: sect131r1 certpath: Constraints: sect131r2 certpath: Constraints: sect163k1 certpath: Constraints: sect163r1 certpath: Constraints: sect163r2 certpath: Constraints: sect193r1 certpath: Constraints: sect193r2 certpath: Constraints: sect233k1 certpath: Constraints: sect233r1 certpath: Constraints: sect239k1 certpath: Constraints: sect283k1 certpath: Constraints: sect283r1 certpath: Constraints: sect409k1 certpath: Constraints: sect409r1 certpath: Constraints: sect571k1 certpath: Constraints: sect571r1 certpath: Constraints: X9.62 c2tnb191v1 certpath: Constraints: X9.62 c2tnb191v2 certpath: Constraints: X9.62 c2tnb191v3 certpath: Constraints: X9.62 c2tnb239v1 certpath: Constraints: X9.62 c2tnb239v2 certpath: Constraints: X9.62 c2tnb239v3 certpath: Constraints: X9.62 c2tnb359v1 certpath: Constraints: X9.62 c2tnb431r1 certpath: Constraints: X9.62 prime192v2 certpath: Constraints: X9.62 prime192v3 certpath: Constraints: X9.62 prime239v1 certpath: Constraints: X9.62 prime239v2 certpath: Constraints: X9.62 prime239v3 certpath: Constraints: brainpoolP256r1 certpath: Constraints: brainpoolP320r1 certpath: Constraints: brainpoolP384r1 certpath: Constraints: brainpoolP512r1 certpath: -------------------------------------------------------------- certpath: Executing PKIX certification path validation algorithm. certpath: Checking cert1 - Subject: CN=COMODO RSA Extended Validation Secure Server CA, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB certpath: Set of critical extensions: {2.5.29.15, 2.5.29.19} certpath: -Using checker1 ... [sun.security.provider.certpath.UntrustedChecker] certpath: -checker1 validation succeeded certpath: -Using checker2 ... [sun.security.provider.certpath.AlgorithmChecker] certpath: Constraints.permits(): SHA384withRSA, [ Variant: generic Anchor: [ Trusted CA cert: [ [ Version: V3 Subject: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB Signature Algorithm: SHA384withRSA, OID = 1.2.840.113549.1.1.12 Key: Sun RSA public key, 4096 bits params: null modulus: 595250832037245141724642107398533641144111340640849154810839512193646804439589382557795096048235159392412856809181253983148280442751106836828767077478502910675291715965426418324395462826337195608826159904332409833532414343087397304684051488024083060971973988667565926401713702437407307790551210783180012029671811979458976709742365579736599681150756374332129237698142054260771585540729412505699671993111094681722253786369180597052805125225748672266569013967025850135765598233721214965171040686884703517711864518647963618102322884373894861238464186441528415873877499307554355231373646804211013770034465627350166153734933786011622475019872581027516832913754790596939102532587063612068091625752995700206528059096165261547017202283116886060219954285939324476288744352486373249118864714420341870384243932900936553074796547571643358129426474424573956572670213304441994994142333208766235762328926816055054634905252931414737971249889745696283503174642385591131856834241724878687870772321902051261453524679758731747154638983677185705464969589189761598154153383380395065347776922242683529305823609958629983678843126221186204478003285765580771286537570893899006127941280337699169761047271395591258462580922460487748761665926731923248227868312659 public exponent: 65537 Validity: [From: Tue Jan 19 05:30:00 IST 2010, To: Tue Jan 19 05:29:59 IST 2038] Issuer: CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB SerialNumber: [ 4caaf9ca db636fe0 1ff74ed8 5b03869d] Certificate Extensions: 3 [1]: ObjectId: 2.5.29.19 Criticality=true BasicConstraints:[ CA:true PathLen:2147483647 ] [2]: ObjectId: 2.5.29.15 Criticality=true KeyUsage [ Key_CertSign Crl_Sign ] [3]: ObjectId: 2.5.29.14 Criticality=false SubjectKeyIdentifier [ KeyIdentifier [ 0000: BB AF 7E 02 3D FA A6 F1 3C 84 8E AD EE 38 98 EC ....=...<....8.. 0010: D9 32 32 D4 .22. ] ] ] Algorithm: [SHA384withRSA] Signature: 0000: 0A F1 D5 46 84 B7 AE 51 BB 6C B2 4D 41 14 00 93 ...F...Q.l.MA... 0010: 4C 9C CB E5 C0 54 CF A0 25 8E 02 F9 FD B0 A2 0D L....T..%....... 0020: F5 20 98 3C 13 2D AC 56 A2 B0 D6 7E 11 92 E9 2E . .<.-.V........ 0030: BA 9E 2E 9A 72 B1 BD 19 44 6C 61 35 A2 9A B4 16 ....r...Dla5.... 0040: 12 69 5A 8C E1 D7 3E A4 1A E8 2F 03 F4 AE 61 1D .iZ...>.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i.../...a. 0050: 10 1B 2A A4 8B 7A C5 FE 05 A6 E1 C0 D6 C8 FE 9E ..*..z.......... 0060: AE 8F 2B BA 3D 99 F8 D8 73 09 58 46 6E A6 9C F4 ..+.=...s.XFn... 0070: D7 27 D3 95 DA 37 83 72 1C D3 73 E0 A2 47 99 03 .'...7.r..s..G.. 0080: 38 5D D5 49 79 00 29 1C C7 EC 9B 20 1C 07 24 69 8].Iy.).... ..$i 0090: 57 78 B2 39 FC 3A 84 A0 B5 9C 7C 8D BF 2E 93 62 Wx.9.:.........b 00A0: 27 B7 39 DA 17 18 AE BD 3C 09 68 FF 84 9B 3C D5 '.9.....<.h...<. 00B0: D6 0B 03 E3 57 9E 14 F7 D1 EB 4F C8 BD 87 23 B7 ....W.....O...#. 00C0: B6 49 43 79 85 5C BA EB 92 0B A1 C6 E8 68 A8 4C .ICy.\.......h.L 00D0: 16 B1 1A 99 0A E8 53 2C 92 BB A1 09 18 75 0C 65 ......S,.....u.e 00E0: A8 7B CB 23 B7 1A C2 28 85 C3 1B FF D0 2B 62 EF ...#...(.....+b. 00F0: A4 7B 09 91 98 67 8C 14 01 CD 68 06 6A 63 21 75 .....g....h.jc!u 0100: 03 80 88 8A 6E 81 C6 85 F2 A9 A4 2D E7 F4 A5 24 ....n......-...$ 0110: 10 47 83 CA CD F4 8D 79 58 B1 06 9B E7 1A 2A D9 .G.....yX.....*. 0120: 9D 01 D7 94 7D ED 03 4A CA F0 DB E8 A9 01 3E F5 .......J......>. 0130: 56 99 C9 1E 8E 49 3D BB E5 09 B9 E0 4F 49 92 3D V....I=.....OI.= 0140: 16 82 40 CC CC 59 C6 E6 3A ED 12 2E 69 3C 6C 95 ..@..Y..:...i