This is certificate chain where the issuer of the second certificate is not byte-for-byte equal to the subject of the third certificate. The names are equal when applying the comparison rules given in RFC 5280. The difference in byte values is due to encoding some components as UTF8String which were encoded in the other version as PrintableString. The verification should succeed. This certificate chain was obtained from the certificate transparency database. Certificate: Data: Version: 3 (0x2) Serial Number: 966709257826132928 (0xd6a70f2b9cee3c0) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=Trend Micro Inc, CN=Trend Micro CA Validity Not Before: May 20 15:18:33 2013 GMT Not After : May 21 15:18:33 2015 GMT Subject: businessCategory=Business Entity/1.3.6.1.4.1.311.60.2.1.3=US/1.3.6.1.4.1.311.60.2.1.2=California/serialNumber=C1919248, C=US, ST=California, L=Cupertino, O=Trend Micro, Inc., CN=community.trendmicro.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:bf:84:0a:28:77:d4:40:6b:62:00:de:5f:a7:da: de:c0:83:bb:81:56:f1:a5:1f:7b:ea:23:e2:f0:53: 96:b4:e4:c9:dd:68:06:5b:f4:d6:c8:de:d5:a8:21: e5:c3:b5:fc:a7:04:7c:ef:1f:ac:1b:06:6d:f3:e5: 36:2f:a8:ea:7c:2b:c9:cf:43:a7:f6:5f:15:be:7b: cb:d8:35:14:39:6a:47:f2:9b:e8:c7:07:48:97:a3: 02:67:8c:bf:97:f8:51:ec:8f:fd:3a:74:05:01:f9: 7c:1b:85:25:e4:f2:66:8d:11:de:d5:f0:12:97:3f: a1:8f:23:36:b3:71:bd:ac:1e:e7:8f:fb:89:11:36: a7:bd:32:7f:44:9a:e9:8d:54:f2:85:06:d2:4f:d1: 3f:4a:a0:e2:0f:35:16:5f:ac:7b:2e:7e:da:d5:77: 72:64:88:ea:2e:1f:c1:f2:eb:81:17:b5:89:2f:22: e7:fc:c1:2b:22:6f:b8:ac:29:e6:61:95:3f:3b:4d: b4:03:5a:f5:44:cb:00:e3:1a:16:36:53:eb:33:7a: 88:73:51:22:3a:03:c9:a6:01:bc:1e:07:a5:0f:d4: a3:57:5f:ce:3d:19:59:e6:97:60:e5:5b:8d:0e:66: 6d:e2:5e:6f:39:48:d4:69:77:5b:c2:08:bc:c9:55: 82:09 Exponent: 65537 (0x10001) X509v3 extensions: Authority Information Access: CA Issuers - URI:http://ocsp.trendmicro.com/tmca.crt OCSP - URI:http://ocsp.trendmicro.com/tmca X509v3 Subject Key Identifier: 58:E3:2D:66:53:0F:E5:F0:00:2C:A6:5E:CF:AD:D1:64:2D:1E:77:21 X509v3 Basic Constraints: critical CA:FALSE X509v3 Authority Key Identifier: keyid:AD:31:C7:FA:02:CE:67:F7:65:1C:FB:BA:5F:C0:BB:C5:50:4C:67:C8 X509v3 Certificate Policies: Policy: 1.3.6.1.4.1.34697.2.2 Policy: 2.16.756.1.89.1.2.1.1 Policy: 1.3.6.1.4.1.34697.1.1 CPS: http://ssl.trendmicro.com/resources/ X509v3 CRL Distribution Points: Full Name: URI:http://crl.trendmicro.com/crl/trendmicroca.crl X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Subject Alternative Name: DNS:community.trendmicro.com Signature Algorithm: sha1WithRSAEncryption a7:ec:1b:48:20:53:62:a8:6b:e5:b0:ae:7c:c5:5b:37:ec:59: de:39:b7:ef:e0:64:26:85:94:2f:22:91:d3:91:c6:07:93:8e: 23:ea:41:84:5b:90:c5:d2:32:1c:8b:d4:83:8c:0c:c9:7a:b2: de:a8:b6:e9:de:06:50:5c:ef:f7:73:d1:5f:66:31:53:e0:80: 14:c8:1c:dc:81:e4:fe:05:f1:88:b5:ff:24:58:48:c5:4c:f5: 4f:1a:a6:dd:1a:43:b1:91:74:75:99:7a:c9:22:04:12:9d:6c: ef:b2:05:60:f5:ec:15:84:81:aa:ee:0b:d9:ba:75:74:4f:f6: fb:d0:a9:99:d8:d4:11:d6:a6:c6:79:64:cd:de:19:6e:92:89: f4:85:d0:b3:dc:94:00:93:27:29:b5:dd:30:71:67:e7:c3:e2: cb:9a:d1:d7:da:56:7b:f7:33:4b:2b:6c:52:ca:1b:7b:51:9c: 6b:7a:d2:2f:38:a0:d2:e5:7c:cf:f4:34:f8:1c:d7:4b:80:bd: 8a:c0:e9:7d:dd:85:86:5d:12:05:60:19:0d:ff:72:15:30:ba: cf:c0:2e:a4:1a:a1:7f:73:85:9f:4a:4e:2c:a6:98:47:20:e5: fc:29:09:ed:21:97:28:49:5d:a3:cc:03:f0:ca:e3:c6:e3:56: 9b:22:fd:36 -----BEGIN CERTIFICATE----- MIIFVjCCBD6gAwIBAgIIDWpw8rnO48AwDQYJKoZIhvcNAQEFBQAwQDELMAkGA1UEBhMCVVMxGDA WBgNVBAoMD1RyZW5kIE1pY3JvIEluYzEXMBUGA1UEAwwOVHJlbmQgTWljcm8gQ0EwHhcNMTMwNT IwMTUxODMzWhcNMTUwNTIxMTUxODMzWjCB1DEYMBYGA1UEDwwPQnVzaW5lc3MgRW50aXR5MRMwE QYLKwYBBAGCNzwCAQMMAlVTMRswGQYLKwYBBAGCNzwCAQIMCkNhbGlmb3JuaWExETAPBgNVBAUT CEMxOTE5MjQ4MQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTESMBAGA1UEBwwJQ3V wZXJ0aW5vMRowGAYDVQQKDBFUcmVuZCBNaWNybywgSW5jLjEhMB8GA1UEAwwYY29tbXVuaXR5Ln RyZW5kbWljcm8uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv4QKKHfUQGtiA N5fp9rewIO7gVbxpR976iPi8FOWtOTJ3WgGW/TWyN7VqCHlw7X8pwR87x+sGwZt8+U2L6jqfCvJ z0On9l8VvnvL2DUUOWpH8pvoxwdIl6MCZ4y/l/hR7I/9OnQFAfl8G4Ul5PJmjRHe1fASlz+hjyM 2s3G9rB7nj/uJETanvTJ/RJrpjVTyhQbST9E/SqDiDzUWX6x7Ln7a1XdyZIjqLh/B8uuBF7WJLy Ln/MErIm+4rCnmYZU/O020A1r1RMsA4xoWNlPrM3qIc1EiOgPJpgG8HgelD9SjV1/OPRlZ5pdg5 VuNDmZt4l5vOUjUaXdbwgi8yVWCCQIDAQABo4IBvTCCAbkwbAYIKwYBBQUHAQEEYDBeMC8GCCsG AQUFBzAChiNodHRwOi8vb2NzcC50cmVuZG1pY3JvLmNvbS90bWNhLmNydDArBggrBgEFBQcwAYY faHR0cDovL29jc3AudHJlbmRtaWNyby5jb20vdG1jYTAdBgNVHQ4EFgQUWOMtZlMP5fAALKZez6 3RZC0edyEwDAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBStMcf6As5n92Uc+7pfwLvFUExnyDBmB gNVHSAEXzBdMAwGCisGAQQBgo8JAgIwCwYJYIV0AVkBAgEBMEAGCisGAQQBgo8JAQEwMjAwBggr BgEFBQcCARYkaHR0cDovL3NzbC50cmVuZG1pY3JvLmNvbS9yZXNvdXJjZXMvMD8GA1UdHwQ4MDY wNKAyoDCGLmh0dHA6Ly9jcmwudHJlbmRtaWNyby5jb20vY3JsL3RyZW5kbWljcm9jYS5jcmwwDg YDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAjBgNVHREEHDAag hhjb21tdW5pdHkudHJlbmRtaWNyby5jb20wDQYJKoZIhvcNAQEFBQADggEBAKfsG0ggU2Koa+Ww rnzFWzfsWd45t+/gZCaFlC8ikdORxgeTjiPqQYRbkMXSMhyL1IOMDMl6st6otuneBlBc7/dz0V9 mMVPggBTIHNyB5P4F8Yi1/yRYSMVM9U8apt0aQ7GRdHWZeskiBBKdbO+yBWD17BWEgaruC9m6dX RP9vvQqZnY1BHWpsZ5ZM3eGW6SifSF0LPclACTJym13TBxZ+fD4sua0dfaVnv3M0srbFLKG3tRn Gt60i84oNLlfM/0NPgc10uAvYrA6X3dhYZdEgVgGQ3/chUwus/ALqQaoX9zhZ9KTiymmEcg5fwp Ce0hlyhJXaPMA/DK48bjVpsi/TY= -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 6555005306879019608 (0x5af80e98c1530a58) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=AffirmTrust, CN=AffirmTrust Networking Validity Not Before: Oct 22 19:14:42 2011 GMT Not After : Dec 31 14:08:24 2030 GMT Subject: C=US, O=Trend Micro Inc, CN=Trend Micro CA Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:c2:b7:3e:ea:50:16:fa:d4:31:c5:60:36:d1:8f: af:67:8a:49:3f:e2:c6:d0:e7:73:67:3d:2a:ce:04: 91:17:dc:4e:7d:30:03:e8:10:ef:db:89:8c:e8:30: 5e:00:dd:47:41:2f:36:6c:46:9e:12:60:96:74:5b: 26:f2:bd:a1:31:b3:d1:47:10:27:e9:71:7a:21:38: 23:e4:1b:bb:b5:44:2e:04:b5:48:0c:8f:0d:e5:36: fb:b7:80:3b:f2:8b:9b:ad:71:d2:88:e2:e3:b0:22: 48:43:f2:86:e3:2a:ec:d2:95:4e:08:69:48:ec:4d: a7:88:44:e2:90:1e:db:64:0c:cc:3b:77:c1:e1:39: 1c:b7:42:74:d2:20:29:59:de:18:16:0c:96:59:1c: ec:84:db:18:46:85:dc:86:fc:a7:cd:97:0f:ee:5e: d2:7d:03:9f:d8:50:f1:e9:e1:d0:df:ad:05:76:3d: 4a:fe:75:38:2c:dc:12:21:f6:be:dd:46:78:25:6b: 80:6a:6e:f3:5a:1f:c6:30:dd:f1:49:f0:3a:98:d7: 5f:09:1f:91:92:43:74:50:c0:7a:73:d9:fd:f8:9f: 4c:b6:3d:34:8c:2d:09:4c:50:2d:a2:44:13:9d:f1: d8:56:25:ee:51:19:b2:9f:bd:e1:d7:0d:f0:60:a9: d0:41 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: AD:31:C7:FA:02:CE:67:F7:65:1C:FB:BA:5F:C0:BB:C5:50:4C:67:C8 X509v3 Basic Constraints: critical CA:TRUE X509v3 Authority Key Identifier: keyid:07:1F:D2:E7:9C:DA:C2:6E:A2:40:B4:B0:7A:50:10:50:74:C4:C8:BD X509v3 Certificate Policies: Policy: X509v3 Any Policy CPS: http://www.affirmtrust.com/resources/cps X509v3 CRL Distribution Points: Full Name: URI:http://crl.affirmtrust.com/crl/AffirmTrustNetworking.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign Signature Algorithm: sha1WithRSAEncryption b3:f0:b1:7c:b3:8b:9e:a1:a6:68:bf:4f:df:85:53:c9:96:6f: 1f:97:22:1a:ff:3c:4a:c5:1e:cf:2b:6e:8b:5c:96:d5:ed:9e: 02:2f:fe:d7:b6:9d:33:56:dc:c0:78:58:6e:0f:5d:58:4a:41: ba:04:eb:c1:0e:fa:33:b7:8a:c7:94:bb:8e:8f:f4:7e:20:8d: 74:b0:11:b8:47:76:75:89:45:1e:5d:52:c8:e5:ee:0b:d1:12: fc:bd:bd:4f:34:18:21:51:61:7b:fb:75:b8:19:ef:c2:7c:78: e7:a3:55:79:23:6f:77:93:ce:68:b6:98:e0:ab:43:20:26:ca: f5:ea:87:bd:be:38:ce:91:74:99:68:6d:7e:35:7b:21:c1:aa: 85:6c:31:48:ef:43:91:08:fd:07:98:a0:03:3c:01:a6:fb:eb: 25:ea:15:62:b3:52:3d:7d:6a:3d:72:89:ec:89:84:53:1e:cd: 9a:73:47:ff:6c:0b:b9:97:20:df:dc:e4:84:b5:c6:98:9a:f3: 2e:cf:02:38:05:9e:f1:4e:63:db:c7:4a:45:37:e7:64:a5:2f: 15:d9:53:b5:6c:84:eb:90:a0:64:5b:a2:ea:95:5c:83:63:c6: a5:ed:0e:1e:6b:2f:21:48:52:5b:44:13:73:c8:f8:fe:a1:aa: d9:eb:d1:df -----BEGIN CERTIFICATE----- MIIEATCCAumgAwIBAgIIWvgOmMFTClgwDQYJKoZIhvcNAQEFBQAwRDELMAkGA1UEBhMCVVMxFDA SBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZpcm1UcnVzdCBOZXR3b3JraW5nMB4XDT ExMTAyMjE5MTQ0MloXDTMwMTIzMTE0MDgyNFowQDELMAkGA1UEBhMCVVMxGDAWBgNVBAoMD1RyZ W5kIE1pY3JvIEluYzEXMBUGA1UEAwwOVHJlbmQgTWljcm8gQ0EwggEiMA0GCSqGSIb3DQEBAQUA A4IBDwAwggEKAoIBAQDCtz7qUBb61DHFYDbRj69nikk/4sbQ53NnPSrOBJEX3E59MAPoEO/biYz oMF4A3UdBLzZsRp4SYJZ0WybyvaExs9FHECfpcXohOCPkG7u1RC4EtUgMjw3lNvu3gDvyi5utcd KI4uOwIkhD8objKuzSlU4IaUjsTaeIROKQHttkDMw7d8HhORy3QnTSIClZ3hgWDJZZHOyE2xhGh dyG/KfNlw/uXtJ9A5/YUPHp4dDfrQV2PUr+dTgs3BIh9r7dRngla4BqbvNaH8Yw3fFJ8DqY118J H5GSQ3RQwHpz2f34n0y2PTSMLQlMUC2iRBOd8dhWJe5RGbKfveHXDfBgqdBBAgMBAAGjgfowgfc wHQYDVR0OBBYEFK0xx/oCzmf3ZRz7ul/Au8VQTGfIMA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBB gwFoAUBx/S55zawm6iQLSwelAQUHTEyL0wSQYDVR0gBEIwQDA+BgRVHSAAMDYwNAYIKwYBBQUHA gEWKGh0dHA6Ly93d3cuYWZmaXJtdHJ1c3QuY29tL3Jlc291cmNlcy9jcHMwSQYDVR0fBEIwQDA+ oDygOoY4aHR0cDovL2NybC5hZmZpcm10cnVzdC5jb20vY3JsL0FmZmlybVRydXN0TmV0d29ya2l uZy5jcmwwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBBQUAA4IBAQCz8LF8s4ueoaZov0/fhV PJlm8flyIa/zxKxR7PK26LXJbV7Z4CL/7Xtp0zVtzAeFhuD11YSkG6BOvBDvozt4rHlLuOj/R+I I10sBG4R3Z1iUUeXVLI5e4L0RL8vb1PNBghUWF7+3W4Ge/CfHjno1V5I293k85otpjgq0MgJsr1 6oe9vjjOkXSZaG1+NXshwaqFbDFI70ORCP0HmKADPAGm++sl6hVis1I9fWo9consiYRTHs2ac0f /bAu5lyDf3OSEtcaYmvMuzwI4BZ7xTmPbx0pFN+dkpS8V2VO1bITrkKBkW6LqlVyDY8al7Q4eay 8hSFJbRBNzyPj+oarZ69Hf -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 84:3c:74:b1:aa:34:86:b1:c4:c7:a0:df:55:b5:e9 Signature Algorithm: sha1WithRSAEncryption Issuer: C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 Validity Not Before: Dec 1 12:00:00 2009 GMT Not After : Nov 1 12:00:00 2019 GMT Subject: C=US, O=AffirmTrust, CN=AffirmTrust Networking Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:b4:84:cc:33:17:2e:6b:94:6c:6b:61:52:a0:eb: a3:cf:79:94:4c:e5:94:80:99:cb:55:64:44:65:8f: 67:64:e2:06:e3:5c:37:49:f6:2f:9b:84:84:1e:2d: f2:60:9d:30:4e:cc:84:85:e2:2c:cf:1e:9e:fe:36: ab:33:77:35:44:d8:35:96:1a:3d:36:e8:7a:0e:d8: d5:47:a1:6a:69:8b:d9:fc:bb:3a:ae:79:5a:d5:f4: d6:71:bb:9a:90:23:6b:9a:b7:88:74:87:0c:1e:5f: b9:9e:2d:fa:ab:53:2b:dc:bb:76:3e:93:4c:08:08: 8c:1e:a2:23:1c:d4:6a:ad:22:ba:99:01:2e:6d:65: cb:be:24:66:55:24:4b:40:44:b1:1b:d7:e1:c2:85: c0:de:10:3f:3d:ed:b8:fc:f1:f1:23:53:dc:bf:65: 97:6f:d9:f9:40:71:8d:7d:bd:95:d4:ce:be:a0:5e: 27:23:de:fd:a6:d0:26:0e:00:29:eb:3c:46:f0:3d: 60:bf:3f:50:d2:dc:26:41:51:9e:14:37:42:04:a3: 70:57:a8:1b:87:ed:2d:fa:7b:ee:8c:0a:e3:a9:66: 89:19:cb:41:f9:dd:44:36:61:cf:e2:77:46:c8:7d: f6:f4:92:81:36:fd:db:34:f1:72:7e:f3:0c:16:bd: b4:15 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:TRUE X509v3 Subject Key Identifier: 07:1F:D2:E7:9C:DA:C2:6E:A2:40:B4:B0:7A:50:10:50:74:C4:C8:BD X509v3 Authority Key Identifier: keyid:5B:25:7B:96:A4:65:51:7E:B8:39:F3:C0:78:66:5E:E8:3A:E7:F0:EE X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 CRL Distribution Points: Full Name: URI:http://crl.swisssign.net/5B257B96A465517EB839F3C078665EE83AE7F0EE Full Name: URI:ldap://directory.swisssign.net/CN=5B257B96A465517EB839F3C078665EE83AE7F0EE%2CO=SwissSign%2CC=CH?certificateRevocationList?base?objectClass=cRLDistributionPoint X509v3 Certificate Policies: Policy: X509v3 Any Policy CPS: http://www.affirmtrust.com/resources/cps Signature Algorithm: sha1WithRSAEncryption 72:7a:80:2b:d3:9b:96:58:44:bb:91:8c:ed:b8:af:cc:0f:4d: 8b:a9:52:c0:99:85:ce:e7:a4:9f:67:45:00:df:91:4a:ff:67: 00:ff:88:de:06:6b:26:ce:ff:65:aa:8e:c2:e1:b5:d7:c4:3e: 4e:a2:2e:2c:85:32:52:be:f1:0c:2e:e6:e3:10:b3:a4:99:3c: 4d:8d:64:89:a6:c6:d3:61:b8:91:61:2a:e1:1a:f4:94:34:8b: dd:39:cd:db:a3:cf:93:c2:27:58:13:2c:8d:98:64:d1:6f:6c: 7d:4c:40:19:5c:9a:7e:21:9f:bb:68:de:bb:46:52:a4:52:ad: c1:83:50:06:0f:06:50:56:53:13:ec:06:c2:81:ed:bf:e9:72: 5b:e6:04:83:5b:2c:48:90:1a:8c:08:c3:93:9d:18:b7:28:5d: 0d:68:eb:32:c8:4b:81:2a:4b:dd:76:56:ce:2f:f7:85:38:29: 27:ac:68:9b:89:2f:8b:92:7e:8e:7f:e1:72:9e:5f:f1:15:73: c2:70:a0:60:a1:3d:77:d5:5d:6e:78:20:48:66:4a:e8:bb:89: 6f:0d:aa:49:e5:ce:31:e3:63:c1:ec:42:97:16:bc:c0:55:dc: 6c:dd:c7:de:59:5a:52:a8:92:e7:13:75:67:7a:8e:ef:65:60: 4c:44:73:1e:d5:c4:12:da:52:c6:e2:ae:84:af:67:ff:e7:9c: 66:b8:bc:ca:b4:b2:f6:b8:07:14:fb:b4:c3:a6:a2:9b:52:f8: b1:48:70:64:a4:65:ca:e5:17:fa:7a:56:ea:57:3f:72:02:da: ca:64:3a:4f:dd:a0:b0:5d:50:14:35:14:70:4f:55:d8:c9:9f: f5:b2:63:65:81:42:dc:ad:f1:e5:60:bd:56:f2:2c:e9:eb:49: 1a:7d:de:f3:14:ff:cf:c7:bd:94:90:99:0a:3a:17:a7:5c:aa: 06:21:4b:9b:cc:25:77:99:37:91:d3:7a:7b:15:e1:da:1f:84: ae:35:23:ef:f0:f5:aa:95:09:84:38:e6:97:da:b1:c9:3d:a3: d4:3b:42:0d:14:71:4f:b2:d7:b7:3e:13:5c:85:36:73:88:2d: d0:a3:1f:4c:3c:11:bd:3b:10:95:da:2b:c4:b0:19:a3:cd:20: 66:e6:62:c9:4d:ff:96:bd:93:76:dd:2f:86:4a:70:3d:f9:46: 32:27:3e:d8:c4:25:e8:55:22:37:76:75:2c:cc:d1:12:06:39: 02:5a:bb:ec:40:67:41:1f:8d:39:7d:f5:ed:64:1c:bc:89:96: 29:d8:d4:13:b1:d1:42:88:8d:7b:79:ea:17:4d:5d:3e:ad:fd: 8f:02:fa:d3:f1:4d:3d:23 -----BEGIN CERTIFICATE----- MIIFxzCCA6+gAwIBAgIQAIQ8dLGqNIaxxMeg31W16TANBgkqhkiG9w0BAQUFADBFMQswCQYDVQQ GEwJDSDEVMBMGA1UEChMMU3dpc3NTaWduIEFHMR8wHQYDVQQDExZTd2lzc1NpZ24gR29sZCBDQS AtIEcyMB4XDTA5MTIwMTEyMDAwMFoXDTE5MTEwMTEyMDAwMFowRDELMAkGA1UEBhMCVVMxFDASB gNVBAoTC0FmZmlybVRydXN0MR8wHQYDVQQDExZBZmZpcm1UcnVzdCBOZXR3b3JraW5nMIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtITMMxcua5Rsa2FSoOujz3mUTOWUgJnLVWREZY9 nZOIG41w3SfYvm4SEHi3yYJ0wTsyEheIszx6e/jarM3c1RNg1lho9Nuh6DtjVR6FqaYvZ/Ls6rn la1fTWcbuakCNrmreIdIcMHl+5ni36q1Mr3Lt2PpNMCAiMHqIjHNRqrSK6mQEubWXLviRmVSRLQ ESxG9fhwoXA3hA/Pe24/PHxI1Pcv2WXb9n5QHGNfb2V1M6+oF4nI979ptAmDgAp6zxG8D1gvz9Q 0twmQVGeFDdCBKNwV6gbh+0t+nvujArjqWaJGctB+d1ENmHP4ndGyH329JKBNv3bNPFyfvMMFr2 0FQIDAQABo4IBsjCCAa4wDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUBx/S55zawm6iQLSwel AQUHTEyL0wHwYDVR0jBBgwFoAUWyV7lqRlUX64OfPAeGZe6Drn8O4wDgYDVR0PAQH/BAQDAgEGM IH/BgNVHR8EgfcwgfQwR6BFoEOGQWh0dHA6Ly9jcmwuc3dpc3NzaWduLm5ldC81QjI1N0I5NkE0 NjU1MTdFQjgzOUYzQzA3ODY2NUVFODNBRTdGMEVFMIGooIGloIGihoGfbGRhcDovL2RpcmVjdG9 yeS5zd2lzc3NpZ24ubmV0L0NOPTVCMjU3Qjk2QTQ2NTUxN0VCODM5RjNDMDc4NjY1RUU4M0FFN0 YwRUUlMkNPPVN3aXNzU2lnbiUyQ0M9Q0g/Y2VydGlmaWNhdGVSZXZvY2F0aW9uTGlzdD9iYXNlP 29iamVjdENsYXNzPWNSTERpc3RyaWJ1dGlvblBvaW50MEkGA1UdIARCMEAwPgYEVR0gADA2MDQG CCsGAQUFBwIBFihodHRwOi8vd3d3LmFmZmlybXRydXN0LmNvbS9yZXNvdXJjZXMvY3BzMA0GCSq GSIb3DQEBBQUAA4ICAQByeoAr05uWWES7kYztuK/MD02LqVLAmYXO56SfZ0UA35FK/2cA/4jeBm smzv9lqo7C4bXXxD5Ooi4shTJSvvEMLubjELOkmTxNjWSJpsbTYbiRYSrhGvSUNIvdOc3bo8+Tw idYEyyNmGTRb2x9TEAZXJp+IZ+7aN67RlKkUq3Bg1AGDwZQVlMT7AbCge2/6XJb5gSDWyxIkBqM CMOTnRi3KF0NaOsyyEuBKkvddlbOL/eFOCknrGibiS+Lkn6Of+Fynl/xFXPCcKBgoT131V1ueCB IZkrou4lvDapJ5c4x42PB7EKXFrzAVdxs3cfeWVpSqJLnE3Vneo7vZWBMRHMe1cQS2lLG4q6Er2 f/55xmuLzKtLL2uAcU+7TDpqKbUvixSHBkpGXK5Rf6elbqVz9yAtrKZDpP3aCwXVAUNRRwT1XYy Z/1smNlgULcrfHlYL1W8izp60kafd7zFP/Px72UkJkKOhenXKoGIUubzCV3mTeR03p7FeHaH4Su NSPv8PWqlQmEOOaX2rHJPaPUO0INFHFPste3PhNchTZziC3Qox9MPBG9OxCV2ivEsBmjzSBm5mL JTf+WvZN23S+GSnA9+UYyJz7YxCXoVSI3dnUszNESBjkCWrvsQGdBH405ffXtZBy8iZYp2NQTsd FCiI17eeoXTV0+rf2PAvrT8U09Iw== -----END CERTIFICATE----- Certificate: Data: Version: 3 (0x2) Serial Number: 13492815561806991280 (0xbb401c43f55e4fb0) Signature Algorithm: sha1WithRSAEncryption Issuer: C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 Validity Not Before: Oct 25 08:30:35 2006 GMT Not After : Oct 25 08:30:35 2036 GMT Subject: C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (4096 bit) Modulus: 00:af:e4:ee:7e:8b:24:0e:12:6e:a9:50:2d:16:44: 3b:92:92:5c:ca:b8:5d:84:92:42:13:2a:bc:65:57: 82:40:3e:57:24:cd:50:8b:25:2a:b7:6f:fc:ef:a2: d0:c0:1f:02:24:4a:13:96:8f:23:13:e6:28:58:00: a3:47:c7:06:a7:84:23:2b:bb:bd:96:2b:7f:55:cc: 8b:c1:57:1f:0e:62:65:0f:dd:3d:56:8a:73:da:ae: 7e:6d:ba:81:1c:7e:42:8c:20:35:d9:43:4d:84:fa: 84:db:52:2c:f3:0e:27:77:0b:6b:bf:11:2f:72:78: 9f:2e:d8:3e:e6:18:37:5a:2a:72:f9:da:62:90:92: 95:ca:1f:9c:e9:b3:3c:2b:cb:f3:01:13:bf:5a:cf: c1:b5:0a:60:bd:dd:b5:99:64:53:b8:a0:96:b3:6f: e2:26:77:91:8c:e0:62:10:02:9f:34:0f:a4:d5:92: 33:51:de:be:8d:ba:84:7a:60:3c:6a:db:9f:2b:ec: de:de:01:3f:6e:4d:e5:50:86:cb:b4:af:ed:44:40: c5:ca:5a:8c:da:d2:2b:7c:a8:ee:be:a6:e5:0a:aa: 0e:a5:df:05:52:b7:55:c7:22:5d:32:6a:97:97:63: 13:db:c9:db:79:36:7b:85:3a:4a:c5:52:89:f9:24: e7:9d:77:a9:82:ff:55:1c:a5:71:69:2b:d1:02:24: f2:b3:26:d4:6b:da:04:55:e5:c1:0a:c7:6d:30:37: 90:2a:e4:9e:14:33:5e:16:17:55:c5:5b:b5:cb:34: 89:92:f1:9d:26:8f:a1:07:d4:c6:b2:78:50:db:0c: 0c:0b:7c:0b:8c:41:d7:b9:e9:dd:8c:88:f7:a3:4d: b2:32:cc:d8:17:da:cd:b7:ce:66:9d:d4:fd:5e:ff: bd:97:3e:29:75:e7:7e:a7:62:58:af:25:34:a5:41: c7:3d:bc:0d:50:ca:03:03:0f:08:5a:1f:95:73:78: 62:bf:af:72:14:69:0e:a5:e5:03:0e:78:8e:26:28: 42:f0:07:0b:62:20:10:67:39:46:fa:a9:03:cc:04: 38:7a:66:ef:20:83:b5:8c:4a:56:8e:91:00:fc:8e: 5c:82:de:88:a0:c3:e2:68:6e:7d:8d:ef:3c:dd:65: f4:5d:ac:51:ef:24:80:ae:aa:56:97:6f:f9:ad:7d: da:61:3f:98:77:3c:a5:91:b6:1c:8c:26:da:65:a2: 09:6d:c1:e2:54:e3:b9:ca:4c:4c:80:8f:77:7b:60: 9a:1e:df:b6:f2:48:1e:0e:ba:4e:54:6d:98:e0:e1: a2:1a:a2:77:50:cf:c4:63:92:ec:47:19:9d:eb:e6: 6b:ce:c1 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE X509v3 Subject Key Identifier: 5B:25:7B:96:A4:65:51:7E:B8:39:F3:C0:78:66:5E:E8:3A:E7:F0:EE X509v3 Authority Key Identifier: keyid:5B:25:7B:96:A4:65:51:7E:B8:39:F3:C0:78:66:5E:E8:3A:E7:F0:EE X509v3 Certificate Policies: Policy: 2.16.756.1.89.1.2.1.1 CPS: http://repository.swisssign.com/ Signature Algorithm: sha1WithRSAEncryption 27:ba:e3:94:7c:f1:ae:c0:de:17:e6:e5:d8:d5:f5:54:b0:83: f4:bb:cd:5e:05:7b:4f:9f:75:66:af:3c:e8:56:7e:fc:72:78: 38:03:d9:2b:62:1b:00:b9:f8:e9:60:cd:cc:ce:51:8a:c7:50: 31:6e:e1:4a:7e:18:2f:69:59:b6:3d:64:81:2b:e3:83:84:e6: 22:87:8e:7d:e0:ee:02:99:61:b8:1e:f4:b8:2b:88:12:16:84: c2:31:93:38:96:31:a6:b9:3b:53:3f:c3:24:93:56:5b:69:92: ec:c5:c1:bb:38:00:e3:ec:17:a9:b8:dc:c7:7c:01:83:9f:32: 47:ba:52:22:34:1d:32:7a:09:56:a7:7c:25:36:a9:3d:4b:da: c0:82:6f:0a:bb:12:c8:87:4b:27:11:f9:1e:2d:c7:93:3f:9e: db:5f:26:6b:52:d9:2e:8a:f1:14:c6:44:8d:15:a9:b7:bf:bd: de:a6:1a:ee:ae:2d:fb:48:77:17:fe:bb:ec:af:18:f5:2a:51: f0:39:84:97:95:6c:6e:1b:c3:2b:c4:74:60:79:25:b0:0a:27: df:df:5e:d2:39:cf:45:7d:42:4b:df:b3:2c:1e:c5:c6:5d:ca: 55:3a:a0:9c:69:9a:8f:da:ef:b2:b0:3c:9f:87:6c:12:2b:65: 70:15:52:31:1a:24:cf:6f:31:23:50:1f:8c:4f:8f:23:c3:74: 41:63:1c:55:a8:14:dd:3e:e0:51:50:cf:f1:1b:30:56:0e:92: b0:82:85:d8:83:cb:22:64:bc:2d:b8:25:d5:54:a2:b8:06:ea: ad:92:a4:24:a0:c1:86:b5:4a:13:6a:47:cf:2e:0b:56:95:54: cb:ce:9a:db:6a:b4:a6:b2:db:41:08:86:27:77:f7:6a:a0:42: 6c:0b:38:ce:d7:75:50:32:92:c2:df:2b:30:22:48:d0:d5:41: 38:25:5d:a4:e9:5d:9f:c6:94:75:d0:45:fd:30:97:43:8f:90: ab:0a:c7:86:73:60:4a:69:2d:de:a5:78:d7:06:da:6a:9e:4b: 3e:77:3a:20:13:22:01:d0:bf:68:9e:63:60:6b:35:4d:0b:6d: ba:a1:3d:c0:93:e0:7f:23:b3:55:ad:72:25:4e:46:f9:d2:16: ef:b0:64:c1:01:9e:e9:ca:a0:6a:98:0e:cf:d8:60:f2:2f:49: b8:e4:42:e1:38:35:16:f4:c8:6e:4f:f7:81:56:e8:ba:a3:be: 23:af:ae:fd:6f:03:e0:02:3b:30:76:fa:1b:6d:41:cf:01:b1: e9:b8:c9:66:f4:db:26:f3:3a:a4:74:f2:49:24:5b:c9:b0:d0: 57:c1:fa:3e:7a:e1:97:c9 -----BEGIN TRUSTED_CERTIFICATE----- MIIFujCCA6KgAwIBAgIJALtAHEP1Xk+wMA0GCSqGSIb3DQEBBQUAMEUxCzAJBgNVBAYTAkNIMRU wEwYDVQQKEwxTd2lzc1NpZ24gQUcxHzAdBgNVBAMTFlN3aXNzU2lnbiBHb2xkIENBIC0gRzIwHh cNMDYxMDI1MDgzMDM1WhcNMzYxMDI1MDgzMDM1WjBFMQswCQYDVQQGEwJDSDEVMBMGA1UEChMMU 3dpc3NTaWduIEFHMR8wHQYDVQQDExZTd2lzc1NpZ24gR29sZCBDQSAtIEcyMIICIjANBgkqhkiG 9w0BAQEFAAOCAg8AMIICCgKCAgEAr+TufoskDhJuqVAtFkQ7kpJcyrhdhJJCEyq8ZVeCQD5XJM1 QiyUqt2/876LQwB8CJEoTlo8jE+YoWACjR8cGp4QjK7u9lit/VcyLwVcfDmJlD909Vopz2q5+bb qBHH5CjCA12UNNhPqE21Is8w4ndwtrvxEvcnifLtg+5hg3Wipy+dpikJKVyh+c6bM8K8vzARO/W s/BtQpgvd21mWRTuKCWs2/iJneRjOBiEAKfNA+k1ZIzUd6+jbqEemA8atufK+ze3gE/bk3lUIbL tK/tREDFylqM2tIrfKjuvqblCqoOpd8FUrdVxyJdMmqXl2MT28nbeTZ7hTpKxVKJ+STnnXepgv9 VHKVxaSvRAiTysybUa9oEVeXBCsdtMDeQKuSeFDNeFhdVxVu1yzSJkvGdJo+hB9TGsnhQ2wwMC3 wLjEHXuendjIj3o02yMszYF9rNt85mndT9Xv+9lz4pded+p2JYryU0pUHHPbwNUMoDAw8IWh+Vc 3hiv69yFGkOpeUDDniOJihC8AcLYiAQZzlG+qkDzAQ4embvIIO1jEpWjpEA/I5cgt6IoMPiaG59 je883WX0XaxR7ySArqpWl2/5rX3aYT+YdzylkbYcjCbaZaIJbcHiVOO5ykxMgI93e2CaHt+28kg eDrpOVG2Y4OGiGqJ3UM/EY5LsRxmd6+ZrzsECAwEAAaOBrDCBqTAOBgNVHQ8BAf8EBAMCAQYwDw YDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUWyV7lqRlUX64OfPAeGZe6Drn8O4wHwYDVR0jBBgwF oAUWyV7lqRlUX64OfPAeGZe6Drn8O4wRgYDVR0gBD8wPTA7BglghXQBWQECAQEwLjAsBggrBgEF BQcCARYgaHR0cDovL3JlcG9zaXRvcnkuc3dpc3NzaWduLmNvbS8wDQYJKoZIhvcNAQEFBQADggI BACe645R88a7A3hfm5djV9VSwg/S7zV4Fe0+fdWavPOhWfvxyeDgD2StiGwC5+OlgzczOUYrHUD Fu4Up+GC9pWbY9ZIEr44OE5iKHjn3g7gKZYbge9LgriBIWhMIxkziWMaa5O1M/wySTVltpkuzFw bs4AOPsF6m43Md8AYOfMke6UiI0HTJ6CVanfCU2qT1L2sCCbwq7EsiHSycR+R4tx5M/nttfJmtS 2S6K8RTGRI0Vqbe/vd6mGu6uLftIdxf+u+yvGPUqUfA5hJeVbG4bwyvEdGB5JbAKJ9/fXtI5z0V 9QkvfsywexcZdylU6oJxpmo/a77KwPJ+HbBIrZXAVUjEaJM9vMSNQH4xPjyPDdEFjHFWoFN0+4F FQz/EbMFYOkrCChdiDyyJkvC24JdVUorgG6q2SpCSgwYa1ShNqR88uC1aVVMvOmttqtKay20EIh id392qgQmwLOM7XdVAyksLfKzAiSNDVQTglXaTpXZ/GlHXQRf0wl0OPkKsKx4ZzYEppLd6leNcG 2mqeSz53OiATIgHQv2ieY2BrNU0LbbqhPcCT4H8js1WtciVORvnSFu+wZMEBnunKoGqYDs/YYPI vSbjkQuE4NRb0yG5P94FW6LqjviOvrv1vA+ACOzB2+httQc8Bsem4yWb02ybzOqR08kkkW8mw0F fB+j564ZfJ -----END TRUSTED_CERTIFICATE----- -----BEGIN TIME----- MTMwNTIwMTUxODMzWg== -----END TIME----- -----BEGIN VERIFY_RESULT----- U1VDQ0VTUw== -----END VERIFY_RESULT-----