Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 410 (0x19a)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Dec  9 19:55:24 2010 GMT
            Not After : Dec  9 19:49:04 2020 GMT
        Subject: C=US, O=Betrusted US Inc, OU=SSP, OU=Betrusted Production SSP CA A1, CN=Betrusted Production SSP CA A1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:9f:68:0f:4c:40:4a:b6:fa:3b:26:76:8e:5c:4e:
                    c5:60:79:4f:60:ee:6a:5c:25:63:6e:a7:bd:2d:e7:
                    62:2e:8d:de:7d:98:2c:98:51:0a:e2:8b:65:2f:a9:
                    54:0b:d3:c9:02:e2:2d:79:ea:e2:2e:43:af:f7:e9:
                    a8:9a:ed:3c:c5:7d:45:c8:97:58:01:69:bf:9a:86:
                    11:2d:55:0c:88:2b:83:80:95:4b:a7:0e:c5:82:64:
                    21:ec:50:41:01:6e:c8:1d:e0:6f:09:8c:d4:53:83:
                    b3:87:d5:5d:62:ec:4a:91:c0:39:b3:3f:47:80:52:
                    fb:45:4c:9b:94:c0:0f:7a:5e:fd:24:1a:4e:74:bb:
                    d8:12:00:40:f8:ed:b9:fd:55:4b:c9:ea:83:db:00:
                    90:86:45:a4:10:8b:16:14:31:b5:8b:a1:63:75:52:
                    bf:8b:5a:2d:e2:45:23:f2:71:d2:fe:8f:6e:88:87:
                    9b:60:af:bc:94:f8:34:94:ad:23:1e:12:33:a3:17:
                    93:18:3c:7d:c2:25:66:91:9f:c0:dc:54:6d:ad:a9:
                    8c:10:f4:10:68:bd:9d:ff:f9:18:e2:d2:26:99:75:
                    b9:e3:58:40:9f:d4:96:cb:d5:2b:e7:6d:ed:3b:10:
                    e9:b0:d1:35:55:a3:7e:ed:15:38:62:de:02:c5:fe:
                    97:af
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c
                CA Issuers - URI:ldap://ldap.fpki.gov/cn=Federal%20Common%20Policy%20CA,ou=FPKI,o=U.S.%20Government,c=US?cACertificate;binary,crossCertificatePair;binary

            Subject Information Access: 
                CA Repository - URI:http://sia1.ssp-strong-id.net/CA/SSP-CA-A1-SIA.p7c
                CA Repository - URI:ldap://dir1.ssp-strong-id.net/cn=Betrusted%20Production%20SSP%20CA%20A1,ou=Betrusted%20Production%20SSP%20CA%20A1,ou=SSP,o=Betrusted%20US%20Inc,c=US?cACertificate;binary,crossCertificatePair;binary

            X509v3 Key Usage: critical
                Digital Signature, Non Repudiation, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

                Full Name:
                  URI:ldap://ldap.fpki.gov/cn%3dFederal%20Common%20Policy%20CA,ou%3dFPKI,o%3dU.S.%20Government,c%3dUS?certificateRevocationList

            X509v3 Subject Key Identifier: 
                BB:A4:E9:B9:83:0B:32:72:1A:21:0E:AA:CF:45:1D:B7:16:23:C8:0D
    Signature Algorithm: sha256WithRSAEncryption
         af:a4:93:ed:5b:b0:9b:95:b2:97:c0:fa:5b:77:70:9f:65:f0:
         02:22:f1:16:b8:ac:40:89:d8:da:95:75:1f:4a:e1:07:5f:34:
         e9:a0:d3:30:16:db:26:e9:bc:9d:d9:0f:cc:bb:bd:5c:e4:cd:
         d9:17:c0:9b:06:31:93:0b:29:82:bd:dd:de:08:fd:38:ec:33:
         26:4c:40:54:96:a3:d7:d5:4f:19:fd:12:5f:62:bc:87:73:3b:
         e4:76:ee:d6:0a:f0:b2:0a:84:a4:8e:d1:0d:48:ea:4c:ad:cd:
         e5:e2:59:3c:29:5c:71:f4:61:25:05:a4:b3:4e:af:7d:20:65:
         4b:2e:a1:68:69:83:fb:1b:ed:57:d0:b3:e4:f6:7c:dc:d7:45:
         1c:37:9a:ac:1b:a9:07:31:dd:67:dd:7c:b9:9f:c0:26:42:e2:
         07:22:af:0d:4d:d1:27:e8:d8:6a:a0:21:cd:7f:3b:31:0b:f7:
         7b:49:87:6d:12:5c:fc:09:2e:41:76:58:de:24:1d:49:91:d4:
         c4:04:d1:7f:32:43:e5:98:b7:a8:25:e7:5a:96:28:d5:e8:40:
         c9:be:4d:3d:96:dd:8f:2d:10:e4:06:5d:df:a7:94:21:e2:c0:
         a4:32:ac:f0:8b:94:bf:84:98:5a:b2:20:df:a5:96:db:e6:03:
         11:fa:93:53
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 5705 (0x1649)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=SHA-1 Federal Root CA
        Validity
            Not Before: Dec 19 17:52:17 2013 GMT
            Not After : Dec 19 17:52:06 2016 GMT
        Subject: C=US, O=CertiPath LLC, OU=Certification Authorities, CN=CertiPath Bridge CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:cf:89:98:b8:ee:d1:f2:7e:7b:84:44:02:af:5d:
                    2d:85:58:9f:dc:a5:ac:a1:f7:58:df:ee:ec:59:6e:
                    00:3f:57:18:11:c7:8c:d1:98:c3:36:a0:fa:24:19:
                    d5:03:1c:34:04:aa:d9:c8:f2:a0:d6:3c:a3:9e:27:
                    7c:08:c7:cf:74:b1:15:53:ef:03:cd:7e:c6:45:78:
                    94:fe:41:36:83:d1:7d:1e:3e:a3:a5:c3:64:6b:8e:
                    67:d2:99:6a:4f:bf:03:12:51:cf:ab:07:26:c6:80:
                    82:79:16:83:bc:a3:92:68:c4:7c:6e:68:d4:d9:43:
                    cc:98:b3:84:69:8a:7a:b2:36:8c:3c:6c:8c:ee:60:
                    33:91:d3:11:b1:e0:b2:e7:0c:2e:da:db:82:82:08:
                    f1:c7:de:2c:92:c9:40:b3:47:76:bb:0c:12:65:37:
                    4d:50:e9:b5:bf:69:00:94:13:83:59:9a:2a:9c:91:
                    e8:75:ad:99:37:8a:84:d0:26:5a:cc:97:63:7a:6a:
                    d3:5d:49:8b:1a:8c:a5:46:cb:45:88:4b:09:0c:56:
                    97:62:b0:21:5c:bd:f9:a0:dc:8b:7c:23:52:0a:9b:
                    2f:65:ae:a1:f3:39:5d:74:10:12:a4:fe:76:89:75:
                    a2:38:f0:b0:8e:34:6f:2d:34:1e:28:2c:94:38:bc:
                    09:9d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/sha1frca/caCertsIssuedTosha1frca.p7c

            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.3.24:1.3.6.1.4.1.24019.1.1.1.18, 2.16.840.1.101.3.2.1.3.23:1.3.6.1.4.1.24019.1.1.1.17, 2.16.840.1.101.3.2.1.3.22:1.3.6.1.4.1.24019.1.1.1.21, 2.16.840.1.101.3.2.1.3.21:1.3.6.1.4.1.24019.1.1.1.20, 2.16.840.1.101.3.2.1.3.24:1.3.6.1.4.1.24019.1.1.1.19, 2.16.840.1.101.3.2.1.3.25:1.3.6.1.4.1.24019.1.1.1.17
            X509v3 Name Constraints: critical
                Excluded:
                  DirName: C = US, O = U.S. Government
                  DirName: DC = mil
                  DirName: DC = gov

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.23
                Policy: 2.16.840.1.101.3.2.1.3.24
                Policy: 2.16.840.1.101.3.2.1.3.25
                Policy: 2.16.840.1.101.3.2.1.3.21
                Policy: 2.16.840.1.101.3.2.1.3.22

            Subject Information Access: 
                CA Repository - URI:http://certipath-sia.symauth.com/IssuedBy-CertiPathBridgeRootCA.p7c

            X509v3 Policy Constraints: critical
                Inhibit Policy Mapping:1
            X509v3 Inhibit Any Policy: critical
                0
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:86:9A:5C:62:FF:73:93:D5:E1:8A:7F:4A:C6:88:2E:9F:6E:A0:AE:12

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/sha1frca/sha1frca.crl

            X509v3 Subject Key Identifier: 
                35:1F:41:EA:BF:91:76:C1:67:A0:06:19:1B:80:F4:06:D1:39:93:DC
    Signature Algorithm: sha1WithRSAEncryption
         5a:67:53:c2:fa:d0:ae:e9:db:7f:a4:5b:14:37:24:f9:4e:c9:
         f6:93:05:83:6b:aa:1a:69:20:f5:eb:ad:73:15:0c:ad:42:19:
         64:c5:e4:dd:ba:37:dd:64:42:94:f9:fc:aa:e4:f9:84:56:c1:
         e7:a7:88:63:e7:61:1f:e6:ac:05:da:74:15:b9:06:74:ef:5c:
         79:12:78:a7:41:f2:57:bb:02:45:c4:ef:d4:12:55:78:a9:e7:
         86:ef:e8:d1:50:c6:c3:81:80:04:18:ff:10:5b:66:98:7b:4e:
         0d:39:00:3d:ef:55:d5:bc:56:fc:7d:d5:58:4a:65:17:98:1f:
         a0:b2:17:06:82:e4:59:55:b5:ac:ec:17:3d:14:1f:71:25:0d:
         6a:38:2f:55:9a:8d:e9:f3:6a:d0:53:cf:4b:51:e5:f7:38:5c:
         cd:78:ea:10:6e:d5:da:49:8e:06:c9:ba:ec:fd:d7:e9:cd:34:
         77:b3:25:68:19:73:75:77:f8:c1:21:8e:63:e9:fe:7d:03:6f:
         65:c5:a8:93:cc:c9:08:53:d8:2c:b7:32:ff:4c:b8:ae:07:cc:
         9e:a1:57:85:58:0b:ac:0c:ef:57:30:c3:68:0e:00:56:ea:32:
         7a:10:e4:3a:3d:13:49:12:6a:04:ee:aa:ab:22:83:1a:0e:41:
         ee:56:bd:f0
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 9 (0x9)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan  2 16:24:45 2006 GMT
            Not After : Jan  1 16:24:45 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-11
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:be:88:3a:69:98:56:b7:02:fd:61:43:20:ea:c6:
                    6e:87:2e:1f:f9:b5:c4:7a:07:91:e3:a0:35:06:92:
                    74:0e:ac:e5:12:2b:d4:75:a6:b9:ae:6d:8f:41:41:
                    b7:27:80:4c:b5:fb:23:d9:26:e7:2c:b8:74:ca:3c:
                    ad:01:32:eb:bb:79:2a:f0:eb:11:5f:c7:0c:c9:f6:
                    dd:0e:90:5e:16:6e:5c:5f:6a:e8:a8:21:fb:ba:df:
                    8b:a8:7d:89:63:2b:1c:b4:b1:79:bf:c9:27:40:33:
                    b1:2f:06:c9:d2:13:f4:b0:a2:15:d4:af:04:b3:67:
                    3f:68:27:c6:ee:79:cd:bb:5f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                53:22:DF:BC:C6:18:33:83:89:C2:AD:AE:26:4E:44:F7:24:0E:15:BB
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         4e:49:2a:d0:37:2b:5d:2b:d7:a8:49:fe:6b:53:03:54:47:ae:
         de:11:ad:3e:e7:e6:08:8a:f1:18:69:e0:f8:67:20:00:3c:b3:
         4f:4f:67:1d:4e:c3:59:8c:ee:06:0a:d0:83:2b:e2:54:b1:ae:
         6e:8c:fd:73:ea:ac:54:a1:57:68:73:4d:6c:0c:1d:98:d9:16:
         3d:e2:10:6a:fc:d3:38:d9:49:69:8f:bc:86:f2:80:a3:69:1d:
         fa:e9:ad:81:cd:68:a2:6d:16:64:9a:76:04:80:a2:99:d6:cf:
         9e:df:d5:b5:04:04:c4:56:d7:06:b3:0d:31:79:0c:c6:bd:22:
         01:82:25:29:8a:3d:86:ca:44:67:64:3f:7d:0c:c9:54:4a:1e:
         dd:1c:8a:6c:b9:0d:0d:b4:e0:24:ea:07:ea:73:cb:0f:a7:7a:
         18:e6:f3:5b:27:06:3b:74:08:36:34:60:53:d6:2b:ad:59:7b:
         3a:bc:41:f9:9b:df:b8:05:c9:05:9b:c1:a3:90:7d:ca:c8:c7:
         2c:ec:32:9b:fe:d7:70:9c:cc:ba:c6:51:f2:dc:86:1c:cd:bf:
         ab:8d:ae:a2:ec:3b:21:50:76:2a:e4:9c:09:47:0f:e8:4d:88:
         4c:2e:9e:28:35:a1:59:89:d1:85:fb:45:a3:0f:d2:fe:ba:58:
         42:54:b8:0f
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 11 (0xb)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan  9 13:47:27 2006 GMT
            Not After : Jan  8 13:47:27 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-12
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:d5:1f:40:a1:77:b4:ee:7b:98:a0:c8:7d:e4:d3:
                    83:e8:2b:70:d5:22:93:6a:bd:65:73:79:0d:aa:36:
                    cc:09:8f:b1:34:9f:a9:b6:6a:b6:f1:62:3b:bd:3e:
                    b9:e4:46:f2:1b:c7:03:b0:36:8b:13:48:3d:4b:85:
                    cf:bf:35:68:34:10:ca:df:d7:ce:b2:29:5a:ac:94:
                    3e:a2:a4:3c:26:39:54:38:86:58:e0:fd:6b:d2:10:
                    f6:09:36:21:56:0c:88:a9:ea:ac:34:14:2b:35:11:
                    29:88:c1:09:c2:a5:88:23:0d:40:34:1a:e6:5c:4a:
                    1e:1f:17:8d:bb:a5:46:c1:97
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                AA:97:45:80:89:01:D2:BE:2C:98:07:72:1C:58:D3:EB:BF:CB:8E:68
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         a4:3c:db:1d:fa:d5:5c:f5:70:e9:b6:10:f7:9e:c9:f7:20:13:
         26:a7:6a:5a:81:4d:56:6b:66:a8:36:a3:64:97:4e:c7:17:0d:
         ba:80:f1:01:05:06:49:59:f2:c9:5d:7e:75:e7:8b:22:3d:e9:
         dd:38:ed:77:a3:f0:40:1b:dc:aa:b2:1a:53:49:d1:45:61:e1:
         c4:df:fa:e1:1e:0a:3c:da:7f:5c:b0:39:6f:69:0f:c1:6b:0c:
         2f:3a:d0:11:56:12:f9:8f:cf:1d:f0:51:57:98:be:9b:64:7a:
         9c:a4:02:9e:6f:8e:a0:40:93:82:ae:46:e7:2f:43:a3:33:19:
         0a:4c:ab:a7:db:8c:3e:20:bd:74:76:b6:a2:5f:03:dc:3d:b2:
         e0:bc:6a:2a:17:bf:2b:44:53:cc:38:99:d8:e3:2d:ee:c5:2d:
         11:39:68:14:f7:e2:c9:53:7a:b0:8e:fe:82:5c:8f:78:ba:3b:
         b2:dd:5d:db:1d:c0:5f:98:59:ac:26:36:f0:05:4b:b8:ab:35:
         22:20:0b:44:d7:1e:d3:ee:72:73:fa:c1:aa:79:e7:a6:0f:8c:
         59:d7:29:45:e5:4b:43:f3:8f:be:46:94:4c:fe:88:50:5f:fb:
         a1:d7:b5:b3:19:ff:f7:ce:19:59:b4:fa:f8:09:82:76:e9:7b:
         7e:d2:c9:26
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 23 (0x17)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 23 16:49:24 2006 GMT
            Not After : Jan 22 16:49:24 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-13
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:d2:34:f5:7c:b6:90:d9:ec:09:44:a5:ac:de:3d:
                    ac:d1:b2:ff:41:da:73:f5:ba:8e:28:99:41:d5:51:
                    92:f6:8c:00:c8:71:4d:25:3f:b8:2e:0f:5a:ef:9b:
                    4b:81:6c:ce:72:1a:9a:43:b3:b7:61:d7:c0:d4:8a:
                    c2:43:12:4d:ce:ad:b4:e3:82:73:3a:f0:35:ee:50:
                    fd:16:ba:e0:95:6b:61:62:39:a6:44:a8:ea:4d:26:
                    f4:97:5e:69:30:35:47:da:b0:d8:28:fa:51:6f:14:
                    bc:9a:83:38:21:89:33:66:29:8e:0e:e1:e5:53:3b:
                    94:2e:e3:ff:6c:13:48:12:dd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                64:64:43:25:A4:6C:E7:0D:22:1D:65:AC:C0:E4:75:37:CC:04:DA:DA
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         2f:b6:63:a2:72:24:92:db:78:a6:47:77:c8:3c:43:4d:52:1f:
         03:a5:a6:7f:72:b8:a3:3f:2e:a1:de:83:3b:53:04:f9:db:2a:
         36:c0:a8:8e:3c:5d:f3:73:b7:b8:e8:ae:78:f7:07:ea:c4:30:
         a3:e9:09:4b:82:f6:12:ed:a8:b5:cf:70:54:42:4a:a1:18:85:
         8b:6f:83:7b:9e:a5:79:f3:2b:60:58:d8:4e:fe:ff:c3:c2:ee:
         2e:ee:0f:a1:78:bd:e4:bc:60:13:30:bd:5d:32:f5:4c:fd:75:
         1a:10:bd:29:2f:5e:75:96:64:30:06:ed:19:3e:d1:22:77:0a:
         3e:70:56:f0:ba:4b:a2:05:46:94:0d:03:02:9b:a6:6d:2a:40:
         90:03:6b:34:18:f8:01:87:ee:d6:bc:63:b6:ad:c4:89:fa:82:
         7c:61:4e:96:43:c8:d0:88:97:bd:ac:15:a6:be:4d:99:42:fd:
         a0:9d:aa:d7:94:6b:aa:1b:5d:75:1a:30:26:e0:ad:bf:77:ae:
         48:9a:fe:e7:ee:78:24:4d:0b:71:55:bd:26:ff:ff:9b:f2:1e:
         da:48:48:7b:c4:e4:de:3c:70:7b:a0:ad:5c:82:66:2c:45:13:
         e8:5c:57:18:b7:1e:95:c2:fd:95:18:1c:06:07:ae:0d:40:3c:
         09:c7:14:6e
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 13 (0xd)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan  9 13:57:30 2006 GMT
            Not After : Jan  8 13:57:30 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-14
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:bf:c8:63:3a:27:04:38:f0:e0:fe:c5:03:d9:5f:
                    43:4f:2a:e7:f5:2d:86:0e:80:03:50:7e:c6:e0:ef:
                    7e:e2:7c:22:29:f6:d2:d4:e4:7b:77:93:91:e8:19:
                    68:7d:91:0a:f5:7b:04:c7:b0:76:28:db:a7:1a:05:
                    c1:bf:7d:33:f7:88:86:22:71:e2:27:6c:26:b0:8a:
                    d7:d8:6a:57:f5:90:85:07:96:41:f5:e1:63:20:8c:
                    13:3f:6e:d7:d1:fa:57:50:d8:76:14:8c:a9:c9:c9:
                    0d:31:bc:d5:3c:19:8b:43:e0:aa:30:c1:b6:ce:2c:
                    ba:15:78:d1:65:1c:8c:09:37
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                E1:55:BD:E7:4B:E7:9C:C8:27:E4:BB:B5:17:B8:66:50:A4:52:F3:39
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         12:c2:66:ec:5b:9a:1d:10:b6:a0:a3:3d:4b:f1:51:32:22:9a:
         e0:6e:3b:0f:39:b0:f2:27:ae:f7:07:01:c7:cc:3a:a0:f0:ef:
         c7:42:e6:e2:f7:62:f9:ff:5b:7d:33:ab:10:aa:82:c8:07:a7:
         e3:53:fa:bc:d7:46:04:0c:fe:ad:a2:23:7f:29:63:50:1c:05:
         01:23:91:57:00:1b:bd:5b:23:5d:44:e3:df:82:5a:fc:8a:22:
         a1:5d:28:f0:dd:bf:6c:33:cc:de:8e:c8:93:1d:96:05:8d:c2:
         31:92:ca:3f:00:4c:fd:15:7d:14:7b:b3:b9:c7:52:f9:58:59:
         25:e3:ca:7b:51:89:de:5e:6d:d8:be:ae:37:e6:52:3c:41:55:
         d4:3b:75:7d:be:1b:8e:09:f5:42:9b:98:12:57:63:34:6a:54:
         46:b4:b6:3a:3b:e0:bb:1c:dd:7c:b1:f7:90:8c:e5:73:b1:10:
         c4:51:5b:06:60:1b:e3:26:93:0c:b2:a5:42:dc:22:15:79:3f:
         b3:fb:e0:8c:57:44:69:80:e7:34:ae:67:46:f9:64:27:a7:db:
         d5:c4:4c:c3:1f:7f:15:ae:91:96:16:61:cb:b9:d9:d7:07:7a:
         2b:d3:fc:ee:64:70:42:24:5b:7e:96:ac:b6:3d:7c:d5:85:45:
         e8:d0:54:5c
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 26 (0x1a)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 15:22:16 2006 GMT
            Not After : Jun 13 23:00:00 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-15
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ca:21:1c:98:f0:7e:96:ed:fd:5c:1c:d0:cd:7a:
                    1e:e5:50:78:5b:0d:b0:19:71:d7:c8:fc:7f:c1:39:
                    41:88:09:07:7b:79:8d:49:d5:d5:e3:22:96:46:49:
                    ef:45:4e:58:b4:0a:3a:f1:b6:0f:e1:df:5e:08:ab:
                    3b:d6:6d:4b:07:4b:60:40:d4:c5:9e:1c:7b:c6:57:
                    d8:37:20:55:ed:36:8d:60:63:82:99:c8:56:7d:53:
                    ab:46:a9:65:f3:bd:d7:d7:2d:ef:b5:92:7d:e6:d2:
                    e6:fe:31:35:5a:1d:09:49:40:b0:df:62:bd:76:6c:
                    50:0f:11:c5:2e:ce:95:3b:e1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                68:80:11:78:19:0D:EE:ED:F3:65:49:8E:00:22:EC:52:8E:BA:04:CE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         15:79:5b:99:7d:f1:40:0c:77:c3:fd:9b:f1:f0:5e:fa:cf:22:
         d6:bf:f7:f7:82:03:54:42:ce:9c:49:89:f5:02:0d:06:f9:fb:
         67:40:e8:39:73:cd:0b:a7:b0:62:f5:4a:be:ee:6b:bf:7b:9c:
         18:3c:fe:e0:f0:1c:9f:4e:e5:d4:47:be:31:17:0c:b9:cd:98:
         98:d1:a6:9e:5f:6e:d3:69:32:d7:3e:a5:c4:8c:94:df:8b:33:
         1f:68:da:68:dd:a3:d0:4d:fc:60:1c:f3:22:3e:1b:91:66:73:
         2d:29:b5:7b:d7:a2:84:1a:80:7f:65:f7:24:13:04:a6:32:74:
         8b:ba:35:c0:35:35:12:31:6f:66:6f:3c:77:da:3b:dc:7d:38:
         d0:e8:eb:a3:90:8a:55:dd:57:47:a7:dd:86:64:2d:d6:14:7a:
         98:09:f9:4c:0f:e1:59:82:5d:10:90:f7:db:34:4b:52:4c:cd:
         87:ab:42:4a:7b:b8:08:c3:2e:e6:c9:55:03:8a:15:3a:d7:23:
         51:14:bf:c3:1e:39:cb:ea:81:55:95:6a:47:c6:32:25:3f:52:
         77:7c:dc:b7:94:1c:75:c5:c9:a7:7f:00:73:79:94:cc:d0:27:
         9c:1b:0b:42:e6:44:c8:cc:22:dc:a5:f4:d5:44:e5:99:3e:6d:
         8e:b0:b5:b8
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 28 (0x1c)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 16:58:04 2006 GMT
            Not After : Jun 14 15:58:04 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-16
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:db:a6:44:62:ec:8c:77:a8:2d:da:3d:98:4c:e7:
                    95:98:42:5e:d9:1a:e3:85:f5:9d:22:ae:6e:1b:84:
                    82:50:87:9f:98:28:1d:ab:1a:a9:95:b0:5c:6f:29:
                    b9:90:6f:ac:7e:3d:e5:29:1d:14:86:d9:67:1c:8d:
                    0f:05:81:44:39:42:e4:90:d0:c6:f3:fd:54:d4:35:
                    e9:9e:46:d0:b2:11:8f:ae:f5:fd:2d:98:9b:51:73:
                    88:47:04:fd:2c:ac:60:88:bf:bc:80:e0:62:e0:3b:
                    ff:c2:f9:e8:cf:e3:e1:f6:73:41:99:42:47:c9:2a:
                    2c:d1:d5:bc:b3:a2:ed:5f:1f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                50:6B:CE:58:B9:C0:FB:6A:23:0B:0A:C9:8F:41:9E:9C:05:62:E7:69
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         25:b4:e9:ce:14:6a:7e:97:d4:5d:d2:73:54:65:b7:18:7e:fd:
         93:33:e2:b3:fe:c0:d1:f6:c7:b0:a4:2d:b2:ac:a9:ec:1f:df:
         01:89:ee:46:e7:86:6f:c0:fd:18:98:0f:b0:16:3f:75:a2:05:
         64:66:09:c8:1c:fc:b9:99:98:1f:92:d3:40:2b:dd:e1:90:90:
         43:56:24:be:31:3c:f0:11:10:d3:1d:89:3b:cf:6e:91:09:5f:
         92:57:3a:16:0e:52:2b:05:b6:b7:2f:53:87:44:01:66:2a:22:
         82:ec:3e:eb:45:47:50:13:e3:3c:e4:39:0b:75:c4:6d:11:93:
         de:18:cd:69:37:5c:6e:dc:36:0c:53:0f:19:c9:33:b6:b7:45:
         be:02:83:2b:4c:6b:c4:29:87:5c:ff:01:d1:d4:fe:83:a5:69:
         87:c4:18:97:a3:9d:f8:b0:7d:c3:37:36:01:5e:a1:14:70:90:
         23:df:a4:87:cd:97:e7:41:7b:69:ba:0b:b5:4d:65:11:8a:1b:
         00:5c:cd:1b:76:c7:9a:99:23:41:f2:2c:e7:dc:e7:4f:24:36:
         d3:e1:ee:9b:f2:65:eb:5e:cb:5c:d7:11:26:f2:5a:d3:f6:fd:
         b5:70:b3:a4:a5:ad:79:66:e3:4d:9d:3a:9f:e8:d9:d7:83:98:
         2f:36:78:e3
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 30 (0x1e)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 17:09:32 2006 GMT
            Not After : Jun 14 16:09:32 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-17
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:b3:44:f9:60:40:d1:09:62:a9:32:28:ca:01:37:
                    81:c8:50:d9:6e:17:51:bb:ec:6c:37:dc:3d:1e:46:
                    b2:89:5e:c7:1d:1a:fc:12:3b:54:63:e6:d3:f3:10:
                    28:fb:74:01:6c:35:e9:48:d2:91:24:30:0a:58:39:
                    d7:95:e3:09:ff:f9:68:03:d7:28:8c:f1:c8:bc:a4:
                    ed:33:f2:1e:9b:37:53:1c:6b:b1:da:cc:26:c9:07:
                    e8:07:d0:b8:92:7f:85:f4:6d:61:f8:01:82:ff:b2:
                    21:36:4e:a7:15:b7:39:db:91:11:02:f2:7b:7b:07:
                    24:e1:2c:f5:08:13:99:b5:13
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                9D:D5:F7:A5:B6:4C:61:C2:A2:12:6D:7B:F2:74:EA:7C:76:24:25:3B
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         73:57:9a:b6:a6:ae:51:fc:97:7d:b3:1d:22:c0:9d:ce:7e:17:
         76:ec:8c:de:df:4e:bc:79:60:f7:d7:87:47:e3:34:8f:cc:53:
         fc:91:95:59:55:44:74:0e:71:63:64:ee:36:1b:a1:7b:bc:94:
         c7:54:47:e7:f4:b3:2d:7d:9c:9d:af:78:92:13:44:1a:89:1c:
         91:38:f9:e3:6e:a2:ea:a6:9b:cd:36:df:a7:68:ec:13:b1:0b:
         ca:6a:4a:60:b9:07:63:96:9f:7a:e6:e4:be:ae:85:ee:5d:97:
         1c:7a:dd:d3:c1:b8:e1:2c:35:a9:73:26:e8:eb:ed:8d:a2:07:
         48:ba:c5:6d:d5:8b:fc:cc:46:cf:10:e4:10:e0:11:b4:35:5b:
         92:a0:64:b2:3c:17:d5:6c:a5:ec:f1:71:5b:67:dc:e7:05:df:
         7a:7c:aa:90:d9:57:35:e2:e6:f9:01:3e:dd:cc:ae:bc:6e:2d:
         40:81:38:0a:bf:56:32:26:6c:f7:cf:5d:b5:97:f0:13:0c:a7:
         01:cd:6f:12:1c:33:38:b0:d1:87:5f:7d:9d:ad:35:6a:9d:76:
         61:b5:c8:86:a4:56:a9:64:52:a9:10:a4:df:3e:b5:56:41:0e:
         9a:45:72:38:e3:39:7c:ef:72:05:61:4f:d8:cc:85:a2:7f:7a:
         bf:d4:23:35
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 32 (0x20)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 17:16:32 2006 GMT
            Not After : Jun 14 16:16:32 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-18
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:d0:a0:7d:2f:e6:71:4d:b7:ee:59:ab:50:71:40:
                    d8:5c:9d:11:0d:48:29:9f:ab:67:10:5e:7c:c5:18:
                    a6:69:88:17:ca:dd:ef:90:9e:e7:6d:35:a2:d3:af:
                    4b:2c:4a:0f:1b:f5:0c:77:6d:80:49:72:5d:07:bc:
                    17:90:1d:83:10:33:0b:be:a5:44:cb:d8:cd:c6:ef:
                    39:ed:b9:e6:35:77:68:3e:93:7d:71:9d:9a:ae:7f:
                    f7:dd:03:30:ba:4a:f2:ca:64:7e:e9:36:fb:32:53:
                    ca:49:0f:67:b8:a9:ef:2b:d9:3f:3e:86:4b:69:57:
                    da:88:c4:8b:d9:44:3e:4a:b9
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                32:A1:C9:09:AB:5E:7F:17:79:4A:2A:14:EE:FD:62:7C:A1:01:E5:B9
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         30:fb:ec:6e:a5:d9:fb:a3:e9:c3:6e:2f:9c:1e:ef:2d:98:d1:
         24:da:25:ab:05:63:b8:5f:3b:b9:1b:c8:27:3d:96:ad:24:9b:
         e7:3c:8f:73:3c:f7:69:04:80:8c:02:2f:e4:1a:eb:d1:7c:12:
         4b:7e:0d:d7:ba:1b:c5:4c:b0:68:88:33:de:64:a5:e5:88:cf:
         64:06:12:04:20:65:00:bc:c5:fe:b6:4e:5b:5c:28:64:89:39:
         35:a1:03:8e:56:ee:86:b6:1b:5a:8f:a6:95:42:3e:91:e4:a4:
         e3:98:7b:56:e2:8a:7f:47:79:53:8b:71:61:8e:bd:0b:59:30:
         13:06:fc:b5:ec:b5:95:ad:54:5f:6c:e6:c4:05:76:b9:25:63:
         35:48:74:a0:d9:99:b5:d9:c7:ac:f1:c5:33:ce:47:09:a0:86:
         bf:4f:13:80:7d:85:d9:e1:36:e4:31:4a:22:51:81:61:cb:f4:
         61:d9:ca:cc:75:3f:e1:6c:85:b7:da:12:a0:ef:f7:bf:c6:ba:
         a9:b0:13:6f:b1:1f:7c:44:57:03:0b:85:98:22:11:d7:eb:23:
         cd:60:fa:fd:6d:e6:b6:c4:ec:da:88:74:cb:63:68:31:b1:94:
         66:53:dc:db:0a:ed:3d:de:47:a1:3e:09:28:1f:8d:f0:40:3d:
         3d:bc:e0:71
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 40 (0x28)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Apr 23 20:57:30 2008 GMT
            Not After : Apr 23 19:57:30 2014 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-19
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d6:03:90:43:cb:44:ae:09:ed:c3:d2:46:2b:5a:
                    f4:f0:3e:7a:e3:c4:23:48:df:90:f8:89:47:4f:86:
                    07:57:17:50:03:7a:cf:f7:83:39:a0:66:40:5a:44:
                    d4:a8:cd:96:c0:48:d3:9e:89:91:49:60:a5:21:93:
                    d3:eb:92:b1:f4:45:fc:1c:28:d7:eb:8c:28:0a:e3:
                    38:5f:4d:01:3a:46:b6:c8:54:9e:33:a7:95:fd:97:
                    28:a1:35:0e:98:63:db:f2:11:ba:c4:8c:34:a7:cf:
                    cd:87:42:d3:3f:95:ff:db:26:5a:f0:34:8f:17:2d:
                    80:cd:54:aa:4e:94:b5:32:e8:fe:bb:d7:11:04:c9:
                    f4:74:42:e3:f0:e5:90:db:d4:c1:70:50:d0:c7:ea:
                    28:67:16:f5:b9:69:df:5e:af:f9:31:b4:3b:84:df:
                    3e:b4:57:61:59:33:66:b4:62:ea:3f:01:2e:d9:97:
                    e1:8d:5a:c5:30:84:75:57:db:c1:d2:87:f4:7a:30:
                    b2:81:72:ec:5c:5f:9b:53:f6:01:f5:a9:3a:a5:b8:
                    b9:af:3c:33:ca:40:89:ce:ee:fe:8f:fb:42:82:c2:
                    43:9d:f0:e4:83:2d:8e:2e:36:d4:7f:99:33:d7:43:
                    d8:5e:b3:15:6d:4d:4c:d3:5f:1c:30:18:4e:9a:d4:
                    de:03
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                80:FD:72:CB:16:6C:F5:8D:6F:EB:40:1C:61:64:3C:E3:61:3B:BB:92
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         a5:27:3b:6b:61:75:82:8c:d3:1c:37:bd:c0:f5:00:bd:81:38:
         70:59:87:33:57:c1:72:ae:51:66:c9:d4:c5:1c:0f:a7:0a:1c:
         ba:71:ed:2a:66:fc:8d:a8:59:3c:cc:c3:60:da:39:8a:be:f2:
         08:81:c9:92:ae:19:42:69:89:05:84:34:44:23:0d:8c:04:1c:
         b5:c5:c3:3c:d9:1b:1c:e6:c2:9d:6b:cf:8b:3a:0e:97:16:27:
         74:a2:5d:fd:c5:28:da:ef:bf:f4:8b:19:c9:69:5d:e3:58:a6:
         32:ee:a8:2c:90:d0:09:bf:36:1e:40:f3:02:44:f8:a9:ee:e7:
         63:41:ea:2f:98:b5:8a:ae:9a:ff:e5:45:6e:6b:63:36:fa:d8:
         af:a1:d0:24:f8:5a:24:93:7e:80:f5:f1:18:a5:10:ec:62:fb:
         21:3b:40:8f:4c:82:d6:6f:4b:d4:ec:a6:c9:5a:b6:5b:a9:8f:
         06:e9:49:b1:44:46:70:3e:8f:fa:c8:48:32:73:40:22:7c:4a:
         70:89:e2:7d:77:19:48:98:c5:eb:05:9e:44:5e:6b:84:3e:81:
         0a:ea:17:8e:09:08:e4:7c:4e:50:b3:2a:5a:e5:41:7d:7c:43:
         d2:aa:88:64:33:d3:6f:9c:a5:80:79:b6:e6:f2:c0:67:9c:33:
         ba:57:d2:3d
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 42 (0x2a)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Apr 23 21:05:37 2008 GMT
            Not After : Apr 23 20:05:37 2014 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-20
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:c8:c9:0b:2b:a3:65:3b:7b:d3:90:6f:17:78:ef:
                    e8:2e:01:0c:bb:f0:da:cd:29:45:af:9d:dd:33:a5:
                    a2:36:fe:6c:20:f8:13:f3:25:03:ab:8a:56:8a:25:
                    e8:c3:75:29:4b:6e:64:f2:6c:1f:12:d1:de:f1:b6:
                    0a:64:c0:b8:50:a1:7f:c8:02:a2:80:0f:0b:e2:00:
                    c2:d3:1c:aa:90:97:64:6c:a5:7f:4c:64:5d:74:d0:
                    7f:9e:cd:50:c2:82:80:a0:3c:56:4d:24:4f:71:f1:
                    31:dd:c9:0c:0c:59:3b:0b:bf:51:e0:c3:ee:11:e5:
                    a2:ef:bf:3d:e0:82:2f:88:9b:39:47:a7:0c:32:fd:
                    e3:3b:f0:aa:50:aa:d1:a8:78:66:ff:c1:aa:72:f0:
                    ad:40:2b:cc:b1:b3:62:40:e1:94:71:48:8a:e1:ba:
                    98:51:60:62:3d:88:88:5e:84:49:d6:0c:83:42:2b:
                    b9:63:38:85:c4:d3:be:0b:c3:83:34:0e:d8:19:69:
                    43:dd:a3:cd:85:03:09:c7:e3:9f:91:f2:ef:d5:84:
                    3f:dc:57:1c:6f:4d:ff:5d:8d:a6:ab:bf:25:07:03:
                    7d:c7:b3:3f:dd:cc:ae:8a:b7:d1:b7:09:7f:00:ce:
                    7d:04:44:b0:e5:6c:86:61:02:d2:65:e6:74:52:6f:
                    67:ed
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                1C:F1:82:35:D5:98:D2:AC:43:D6:B2:B9:57:78:89:15:8F:57:F1:77
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         33:b8:22:88:ef:22:85:39:c2:42:ec:78:49:54:34:3f:f0:fe:
         5e:e9:50:c3:56:9f:00:99:45:6b:72:f9:77:1f:ba:b2:e3:16:
         2f:84:35:d4:ff:b4:8f:82:55:a8:4a:c3:ae:4a:2a:08:52:3a:
         85:ae:63:80:a9:d0:9f:7c:49:3c:38:11:c5:0e:d7:cb:1f:8b:
         69:11:b7:99:d6:cb:15:ff:7f:52:8f:3a:80:9f:7c:5e:db:ad:
         f5:2a:ac:22:08:c3:4d:b5:8d:cb:eb:b3:fa:68:d8:f5:dd:53:
         40:04:a1:92:8b:1c:b1:df:16:57:f6:62:9e:8e:5f:9b:67:8b:
         88:9a:ae:25:f3:be:d3:5d:10:16:8b:ac:5a:e5:79:f0:b3:37:
         72:aa:f1:b7:4c:0f:be:a7:5b:80:03:37:b9:bc:cf:90:86:93:
         85:ac:aa:70:37:30:d5:73:f9:d0:d1:46:50:d8:c3:d8:4f:a0:
         fb:ab:a2:22:ed:30:67:e0:2e:17:28:a8:3e:95:80:8a:1c:9d:
         84:26:97:87:03:72:16:27:7a:15:0f:24:c8:08:68:c6:ab:84:
         a5:38:3c:7c:ed:04:47:8c:4e:1b:11:4a:76:84:cc:0f:e5:4e:
         d1:e1:8a:d5:b0:30:a7:6c:70:d0:3a:dd:c2:f8:ff:7f:5d:9d:
         2a:43:ee:58
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 76 (0x4c)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 16:35:03 2009 GMT
            Not After : Jan 25 16:35:03 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-21
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:dd:94:49:64:9d:b2:eb:f5:35:59:e6:14:e3:23:
                    9c:c6:0b:58:a7:5f:49:c1:c6:08:a4:37:29:7b:23:
                    14:79:08:fe:1a:2e:da:71:14:62:80:2f:63:52:96:
                    7b:84:97:f6:c0:48:79:b1:a3:49:08:87:d3:af:b7:
                    8f:69:4d:10:22:e2:fe:70:5d:3c:93:0a:9c:58:5e:
                    6f:2a:5d:81:fe:1d:62:39:2e:bb:99:0e:03:5a:9f:
                    c6:e5:77:2d:88:0d:60:cc:b4:8a:77:4c:5f:9b:e6:
                    a5:3f:a6:af:04:e9:cc:52:9e:ac:80:64:83:a5:69:
                    15:f3:54:4d:f4:a8:02:3a:73:9c:16:c4:42:85:2b:
                    41:37:09:40:c4:58:23:4f:a7:4b:27:c7:07:43:e5:
                    38:2c:0c:7f:d8:03:95:82:09:7f:b6:99:68:56:86:
                    88:03:e1:d2:54:2a:75:17:4b:65:ca:f3:12:45:cb:
                    96:10:ec:13:cc:1b:be:9b:04:54:fb:3c:51:9b:34:
                    7e:77:8e:7d:f9:31:bd:34:9f:7c:e8:1e:37:cb:52:
                    4e:88:3d:e7:09:bd:58:23:00:96:f2:bc:a7:03:b4:
                    35:e6:0c:76:6f:68:23:22:72:ad:8b:b7:f7:ff:26:
                    ed:2d:1e:b5:59:40:0d:a8:fd:ad:27:1f:51:e4:b9:
                    ed:41
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                09:99:13:E2:A3:D5:E7:74:D8:F6:3F:B5:DC:FB:D4:B5:16:ED:4C:D3
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         25:ee:7c:eb:82:a5:d0:51:99:2a:23:dc:f3:ad:27:25:c0:69:
         79:48:00:32:26:d2:ee:6c:1c:1c:bb:f0:c0:0c:d3:d8:2c:74:
         58:a5:55:09:43:a2:5a:f9:27:fe:d8:5a:e8:e0:a8:a4:bd:bd:
         05:a5:0b:95:26:1c:0e:08:88:0e:e4:f9:1f:7b:7e:98:41:0c:
         33:a0:8e:44:c2:f1:ac:de:84:01:86:ec:35:ec:ff:81:bb:60:
         7d:8e:b7:56:f2:4c:90:02:1f:d3:88:3c:e9:21:6e:8c:2b:bc:
         6f:1b:40:19:62:b2:e3:14:70:bf:d1:80:4b:a4:71:3f:14:ee:
         e0:f4:e9:1e:f5:05:81:12:3d:d4:fc:00:83:b2:1f:c2:05:2c:
         63:20:09:c2:47:9d:5b:1e:93:77:a6:23:0b:16:63:70:5a:e4:
         cd:de:25:26:dc:ad:57:08:31:23:66:9b:9f:9c:09:1a:54:fc:
         89:58:6b:83:fa:df:62:70:1c:7a:f9:32:35:fb:c3:e8:cf:06:
         6a:d2:d9:39:ba:3d:8f:ae:60:7b:2a:66:00:39:c5:50:a9:5e:
         43:4d:a1:bc:0a:b2:24:fb:12:36:57:cd:f8:ca:3b:5f:7e:cb:
         c5:11:2a:d5:04:05:fb:5f:58:e7:54:07:67:a9:49:07:8e:4a:
         56:13:66:4b
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 72 (0x48)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 20:18:59 2009 GMT
            Not After : Jan 25 20:18:59 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-22
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:9b:fc:e1:ab:1f:f1:70:34:45:05:5f:09:fc:1c:
                    d7:d5:26:93:d2:90:69:b3:1e:ce:d8:12:53:70:94:
                    42:0c:fc:a5:2e:ce:7f:be:68:84:83:84:2c:8f:1d:
                    e2:df:a7:db:05:d5:23:f3:a1:87:78:d4:2a:be:31:
                    75:48:c2:f7:30:6b:4b:15:25:3c:98:0b:c7:10:2d:
                    55:cf:28:76:b3:bb:43:20:72:a2:c3:01:61:12:de:
                    ea:ae:bd:d2:e4:96:0e:7a:ed:94:61:24:fb:ad:99:
                    da:e2:66:15:cd:d5:bb:77:ef:81:4f:61:2d:cf:a9:
                    ab:55:18:e8:5a:bf:89:8d:29:ce:20:5b:40:13:31:
                    56:92:60:41:06:cb:0a:a1:33:fe:6e:4b:8f:5b:1d:
                    5e:29:97:e3:81:f4:bd:e9:04:3d:d1:32:c6:a0:6d:
                    c0:93:87:01:17:41:87:01:c2:23:2d:b1:fe:b0:69:
                    07:c8:c2:9f:13:ca:84:6d:d1:fd:72:bf:be:9a:bd:
                    6a:60:73:56:88:3a:c6:ad:1b:c4:17:bd:0d:1b:e3:
                    52:63:fc:af:c1:fb:cc:2f:6e:35:d2:dd:3a:d8:10:
                    d1:c4:28:b7:b6:6c:ff:93:e0:f6:72:f0:29:13:67:
                    0b:38:3c:19:28:8d:6c:19:93:49:3d:5b:3d:97:84:
                    d7:1d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                28:30:1F:51:51:8E:D5:DD:AD:A1:CB:20:C2:58:15:46:30:A6:44:4F
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         a7:de:56:35:63:ce:f9:b4:fe:d8:ff:b9:2c:0d:ee:9e:b6:a8:
         56:d5:41:fd:26:7e:67:fc:b2:90:8d:ab:d9:38:e6:77:55:cd:
         37:a8:5e:b9:d7:bc:63:24:87:91:ce:bb:97:bd:98:e8:e5:38:
         57:ce:fb:0e:33:6d:b4:94:99:ef:b9:41:d8:a5:18:16:01:ee:
         ff:e6:bc:ec:f8:06:d1:d4:c1:6a:00:f6:ed:b8:6f:de:e3:0b:
         98:54:1b:80:01:9d:cd:a1:47:cf:0e:33:cf:28:89:b2:49:fa:
         7b:86:fc:9e:e2:c9:96:9e:38:b1:1f:24:b3:cc:14:05:b2:63:
         38:51:6b:39:68:49:bf:99:82:73:59:13:e1:dd:46:d2:2a:f3:
         ba:64:09:51:9f:96:ba:ba:66:b3:b8:e1:9c:13:f4:86:e4:41:
         0b:28:7a:dd:95:da:75:37:b0:af:f8:67:be:f1:ac:3c:47:ec:
         62:f0:d3:36:09:73:45:17:f8:be:2a:16:9b:bc:7e:87:45:1c:
         c3:d9:c9:eb:4b:27:cd:46:ad:57:b6:be:c0:35:a8:12:fa:11:
         48:db:c4:da:f1:ea:ea:f4:0f:40:fc:6e:d7:9e:57:75:77:bc:
         ac:0c:97:ec:52:0e:be:a7:98:b5:78:7e:7c:d6:c5:9f:3d:7c:
         23:a7:ff:25
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 75 (0x4b)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 16:38:45 2009 GMT
            Not After : Jan 25 16:38:45 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-23
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d6:a7:86:23:1c:6d:02:d8:98:9a:24:7f:a5:ff:
                    5b:a3:98:9a:eb:b5:d4:7f:1d:ab:7a:49:4a:ed:61:
                    9f:f9:c8:16:61:b8:8f:f1:fe:69:71:2e:c5:4e:62:
                    a5:28:96:0b:fa:3b:55:66:c6:47:01:d8:f7:23:77:
                    3a:6b:b3:df:b0:36:32:f3:5e:14:59:d1:e6:1f:d3:
                    dc:1b:d1:2f:10:26:c5:a6:15:c1:9a:f4:18:7b:31:
                    8b:97:64:eb:30:c5:b0:02:69:3b:da:5f:87:b1:ef:
                    8a:f8:8e:fe:5f:86:ea:fe:84:5a:ae:7f:a1:17:26:
                    b4:02:91:53:9b:7d:a8:55:42:4d:fe:4f:ec:8e:cd:
                    92:f5:e3:fd:0e:34:94:52:a0:cb:14:57:77:65:a0:
                    15:fc:48:d1:0a:06:92:89:ca:ed:eb:b2:71:c7:b7:
                    28:e0:20:97:fd:07:53:fb:3a:ff:3c:9a:b9:1c:5c:
                    a5:4f:3e:59:59:a3:8b:70:d7:9d:6a:f0:bd:fb:d5:
                    d2:fc:9f:bd:8f:a7:c8:cc:c4:a1:a5:81:2a:ca:2e:
                    92:90:50:c4:88:43:f3:aa:94:ee:54:ed:a6:b2:88:
                    59:ed:c3:91:10:94:6d:0f:64:34:c4:da:0e:cd:73:
                    51:60:0d:87:c6:99:19:4b:51:94:ad:65:02:ef:0d:
                    8d:c5
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                AA:41:F7:12:A3:1C:83:0D:2B:D7:8A:3C:3D:C5:FC:6C:52:4F:CD:58
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         50:41:da:23:d3:8e:1e:02:5d:48:7e:d4:31:5e:66:80:a3:f1:
         cb:f5:b0:4a:be:ea:0f:6c:61:a4:72:46:39:48:99:5c:43:e8:
         93:59:39:df:b5:18:01:5c:32:4b:50:9c:3f:d4:ca:43:fd:60:
         32:4b:96:bd:98:5f:0c:70:9d:d0:dc:33:2e:3e:4d:ed:95:52:
         ae:e2:38:9e:63:7f:cd:6c:14:78:00:76:7f:6a:70:6c:9e:e4:
         ab:58:42:0c:1e:2c:07:53:de:c9:a4:2f:8d:8e:c7:bd:6c:de:
         b3:8a:81:db:48:e3:c3:e2:ad:94:4b:df:ca:79:93:38:69:38:
         a8:7c:36:cc:73:b7:db:4f:19:1b:47:83:e9:8b:9a:3c:aa:5b:
         0f:87:eb:1d:f9:a9:03:cd:a4:7e:6f:a4:a3:8b:1a:4a:7a:ae:
         96:d7:b0:26:64:9a:c9:7e:f0:17:17:ba:24:6f:8d:a7:95:02:
         ce:fd:72:f0:99:b5:1f:f4:82:06:63:f6:50:d4:73:fa:c8:7b:
         3e:24:02:90:8a:4d:1f:a6:43:15:55:59:15:08:7a:0e:cf:86:
         58:ea:81:10:2f:92:ce:b9:54:be:d8:94:13:f1:ce:6a:81:47:
         ba:c0:4e:84:32:d4:71:1e:85:ea:24:89:15:97:6d:aa:4d:af:
         2b:0c:8e:79
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 71 (0x47)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 20:23:11 2009 GMT
            Not After : Jan 25 20:23:11 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-24
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:c2:20:ae:49:25:7c:fb:7c:3b:d2:26:de:8b:e1:
                    48:96:1a:3f:68:bb:72:5e:60:d9:36:ee:74:84:3d:
                    16:3c:fc:07:d9:d7:0f:e5:30:b8:ed:4c:19:f8:9c:
                    15:0a:35:67:a5:fa:d8:66:d3:22:51:d4:6e:c1:e4:
                    60:58:02:f1:f7:7b:87:67:e9:41:0d:74:07:5d:08:
                    57:1f:5b:3d:62:ab:04:33:35:0c:46:38:fa:9c:ba:
                    fa:3a:bf:f9:41:c1:67:d7:b2:7a:50:eb:67:be:e5:
                    36:1a:f3:51:3e:7c:fc:fc:ff:f9:ff:ed:d8:4a:a0:
                    6f:36:3c:df:27:ec:f2:fa:16:61:73:ee:1c:55:54:
                    97:44:6d:f6:e6:54:07:45:4b:46:6b:03:e7:cc:cb:
                    46:2b:72:1f:13:24:b5:4d:bf:a6:e4:66:d5:fb:3a:
                    cd:1a:31:ef:65:2c:92:32:c9:33:35:6c:8c:41:04:
                    41:ef:36:83:bd:ef:37:4d:d1:80:9d:f2:d1:e2:ce:
                    39:6a:3d:fa:5c:49:c6:34:6b:5e:e1:dd:ea:3d:2e:
                    65:a9:09:31:ba:f2:12:4a:d8:b6:c4:32:ee:27:04:
                    ca:54:b2:8f:93:18:bb:26:99:09:ec:3c:77:a0:08:
                    b8:ef:94:d1:a8:c5:da:da:1c:17:80:77:15:a5:06:
                    ae:01
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                16:50:17:75:CE:3B:8A:AE:B5:08:45:A4:A5:70:E0:F6:37:B6:BE:4F
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         b1:ca:b7:4e:cb:c0:53:8b:2c:09:11:9b:13:31:15:f6:3d:b9:
         2f:62:46:76:2a:ac:4b:55:eb:0c:d7:ce:28:6b:0b:95:ab:0a:
         38:16:cb:d7:ae:cc:87:b1:55:ba:26:25:9a:55:a9:33:d9:e3:
         89:ea:8e:53:07:01:20:e4:e1:6c:3c:79:d6:5d:5b:01:e0:6a:
         3a:cc:81:53:d5:c6:15:4e:89:e4:c3:16:a4:05:42:8c:67:e3:
         c6:7c:f7:46:9e:14:3d:cc:bc:6b:e2:64:4b:73:60:6b:8c:5f:
         bc:9b:62:2a:15:48:3d:0c:53:9e:80:39:e8:c4:aa:1a:70:12:
         62:c6:c2:ed:6a:79:43:2f:a4:9a:63:1a:4b:64:37:c2:51:6f:
         ca:3a:96:1e:3f:4b:79:20:2f:84:5f:74:33:14:e5:ce:ef:d7:
         55:2e:b0:91:1e:e4:a1:97:bb:3a:db:d9:5a:a1:00:72:19:c2:
         e1:f2:a5:6f:dc:75:75:59:43:f2:d6:f0:ca:99:74:b4:6d:45:
         24:b1:9f:80:90:3c:d7:6f:58:a1:35:cb:c3:48:53:3f:a3:36:
         5e:34:ed:28:ae:38:4d:86:7e:cb:31:b5:b2:6d:8d:5e:2a:a8:
         ff:92:c3:64:f7:14:93:48:77:dc:a7:57:80:bb:f8:64:7f:d5:
         6c:9a:26:a6
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 78 (0x4e)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 14 17:33:12 2010 GMT
            Not After : Jan 14 17:33:12 2016 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-25
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:e1:e2:60:b7:ce:51:b7:66:8e:48:60:fb:0b:a8:
                    ba:5a:51:d4:d8:2a:65:f4:d2:96:ed:a3:58:99:a2:
                    89:a8:55:86:85:61:ad:08:ff:b3:12:16:75:d2:38:
                    fa:1c:ee:9a:a0:62:5a:91:e1:cc:e1:c9:0d:35:7e:
                    17:5f:7f:14:ac:01:75:e4:5f:4a:5f:2d:22:cb:49:
                    d4:82:b1:19:17:ae:6d:32:38:29:72:97:0b:9b:6e:
                    15:d0:23:08:7b:2d:4b:44:bb:a1:15:c9:96:6e:a6:
                    d9:14:02:88:9c:5e:df:f9:82:31:14:46:a8:8b:01:
                    3e:e4:ae:ae:fa:53:50:37:54:ba:64:53:68:a1:a2:
                    8f:7c:80:97:f9:3b:f2:8f:e5:f2:ff:46:f8:8a:ec:
                    58:25:80:77:46:60:61:ba:6e:60:3e:1f:7a:3c:a4:
                    d7:17:0e:57:9f:a3:2e:b7:40:8a:80:b6:e3:d7:d7:
                    cf:6d:01:13:f2:80:93:47:f3:b9:69:9b:0b:56:7d:
                    f7:8b:40:a8:70:c2:4e:8d:04:19:7e:8b:39:54:23:
                    0f:bb:8a:f0:7c:77:d5:e9:84:56:cc:05:b7:43:72:
                    fe:ef:62:42:07:85:48:4f:44:e9:82:f4:10:96:b4:
                    b1:23:c5:e8:1f:7b:ea:9b:93:0b:ff:cb:ee:84:cc:
                    32:07
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                2E:0B:65:F9:D6:65:DE:4B:A3:25:75:A4:A1:2E:85:21:40:73:B9:0A
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         96:0b:c8:16:bb:92:62:e8:12:8d:60:25:e6:12:ac:77:b1:93:
         96:a5:aa:58:f8:1f:80:33:d5:cc:7e:2d:2c:b1:84:4e:2b:d6:
         45:0f:0d:38:b5:3a:a6:88:9d:59:ae:f0:ce:a5:7a:c5:f8:ee:
         9d:79:e3:a7:73:5e:6c:bb:b8:ab:64:48:bc:3b:ba:5a:1a:5d:
         55:53:98:f4:68:54:8e:35:b8:23:07:b6:a4:7c:75:c5:14:a3:
         22:9e:9f:11:b6:16:30:91:2c:d8:9e:a0:02:ac:a2:e1:c7:83:
         41:e1:c1:cd:62:84:58:37:91:03:5c:38:58:30:1c:11:61:d2:
         01:49:84:6a:e0:71:04:74:bb:94:70:7a:f9:f0:cf:3b:16:e9:
         79:b5:0b:a2:05:c2:72:03:e5:df:60:3a:64:72:b3:03:06:40:
         12:d1:d3:0b:a3:0b:9e:42:6d:b0:eb:95:47:9a:36:46:82:24:
         65:53:d5:bc:16:08:5f:20:ee:57:5c:02:24:d9:c7:d4:16:bc:
         4b:88:18:3a:cc:0c:2a:23:71:7d:08:c1:7f:f6:b2:f1:13:a7:
         ed:82:4e:ec:0b:e1:13:ae:c2:35:81:40:d5:0e:9e:d7:79:18:
         dd:3e:67:0f:43:b0:76:d2:a8:ce:7a:6d:77:fa:27:c9:58:ad:
         b1:69:da:17
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 80 (0x50)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 14 17:38:05 2010 GMT
            Not After : Jan 14 17:38:05 2016 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-26
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:c2:e4:71:ba:ff:44:1f:a5:11:e5:8e:58:1a:35:
                    7e:04:42:7c:fb:54:e1:ce:5e:25:a3:f0:03:c0:ab:
                    6c:2b:3e:00:8b:1f:ca:8d:46:13:11:17:4d:15:e9:
                    90:e6:e9:9d:d7:d3:d2:8d:e6:97:56:bc:5c:68:ae:
                    ff:1f:e9:4c:2e:46:41:06:b6:8d:0d:31:ec:73:41:
                    22:07:77:ee:44:be:3b:60:b3:42:94:64:47:ef:24:
                    5f:c5:ba:b6:dc:43:31:04:cf:c1:da:5f:23:bd:70:
                    95:5c:3f:a6:58:2b:5e:18:ac:d1:90:d3:d6:ad:56:
                    10:5b:27:40:eb:90:c2:4c:7c:ab:17:66:c2:29:96:
                    23:75:7f:0c:0b:00:e7:e7:0b:f9:28:f2:95:d3:a9:
                    6f:9d:28:4f:62:ea:69:ce:8c:06:48:7f:ca:1c:29:
                    44:35:73:36:4a:e8:9e:7b:d4:37:cf:9a:93:3c:53:
                    54:e6:1c:93:b5:ef:79:69:74:44:08:6a:4d:ef:12:
                    d8:2f:63:af:99:cb:45:3b:8a:09:74:14:2f:cd:fb:
                    5e:26:60:68:61:20:82:57:71:14:6f:25:3c:3d:af:
                    0f:da:37:9a:6d:fc:a6:45:8c:be:b5:db:e2:94:0b:
                    d0:47:c2:b6:54:a3:32:9a:69:fa:22:37:d4:da:3b:
                    38:99
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                6A:5F:B9:F4:7A:36:2C:E2:75:F0:BB:64:32:C1:F1:B4:4C:A5:2C:FD
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         7a:3e:6c:ac:06:cf:f2:6e:cb:fd:ed:b0:68:d2:c2:96:f4:e3:
         3c:37:10:2d:66:95:a7:1d:56:69:1d:4a:26:29:a5:2f:55:e6:
         3f:d3:b0:32:45:8d:14:a1:db:75:a4:6d:98:fc:6e:f5:ca:7e:
         d8:ca:ce:52:a4:85:01:98:9d:19:22:60:5a:ca:c2:2e:f5:22:
         13:0b:18:ad:6b:c6:1c:f2:d9:a6:92:b4:fb:90:07:18:af:42:
         9b:2b:50:2a:c5:2d:03:e8:06:2c:9f:f6:79:1e:89:4d:2d:39:
         76:20:5f:c8:98:a8:de:0e:61:0a:2c:be:0a:04:5e:36:75:cf:
         6d:6b:05:ed:2a:5e:a3:0c:72:90:cc:98:ce:2c:f9:a9:97:1b:
         c5:fc:df:c0:2c:a5:90:39:ac:a0:af:63:dc:63:86:aa:cc:1d:
         3f:e7:db:62:da:12:0b:63:3c:43:49:f8:05:39:55:2d:c6:80:
         96:51:01:64:51:5c:cb:26:7a:ea:b6:a8:29:80:e2:77:c2:e8:
         8c:16:72:85:7d:6f:8e:34:a5:5f:50:bd:c3:4e:8d:f5:7a:7d:
         c8:d6:61:ae:dc:fa:48:12:54:12:1d:48:5e:96:f0:e5:fb:a8:
         a1:75:61:4c:56:82:2d:88:d7:18:b9:09:55:bf:b1:7e:59:94:
         c2:2c:60:93
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 434 (0x1b2)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 15:50:25 2011 GMT
            Not After : Sep  8 15:50:25 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-27
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:96:84:08:fd:7a:ba:b6:94:83:d0:9d:3b:19:0b:
                    cf:04:df:88:2a:9e:b8:1a:58:eb:87:22:2a:63:3a:
                    7f:39:c3:6b:6b:e7:bc:1a:a8:11:02:f5:61:cd:01:
                    a4:98:75:73:c6:17:8c:89:3c:42:c7:e2:8e:c9:89:
                    b1:a8:ff:9f:9e:0a:bb:68:de:ba:de:b6:11:01:94:
                    43:74:9c:bd:cf:e1:be:e0:ce:1c:6d:6a:7c:7c:7f:
                    62:e8:5e:da:36:ea:94:c5:06:8b:46:88:e2:c0:c2:
                    24:09:05:50:7f:f3:d9:e5:12:05:5e:d2:d7:ce:35:
                    c2:7b:47:35:18:15:57:cd:c5:9c:f7:e9:31:7a:2a:
                    8c:39:f1:35:8e:2e:a1:50:91:40:37:a2:8e:92:ce:
                    8c:56:b7:fc:ec:2f:76:3c:82:de:c0:c8:bb:47:d6:
                    7e:f7:a9:28:5c:29:1e:96:00:ad:27:86:74:84:b4:
                    04:ba:a7:55:16:69:0e:93:d4:bc:8c:62:4d:4f:56:
                    82:b6:c7:b4:78:2f:7d:d9:d3:43:ed:73:26:f1:53:
                    ee:ff:b3:d5:b0:e4:6e:b6:be:2d:1b:68:0d:77:58:
                    84:57:42:cf:40:70:8c:bc:ca:c0:39:75:4e:f7:19:
                    88:7c:6b:ec:29:c6:64:1d:e8:53:50:bd:94:aa:e4:
                    83:dd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                1B:04:04:40:45:5E:7D:2B:5E:0B:CC:99:65:4D:F3:A4:DE:90:77:17
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         40:c0:0c:4b:9f:8d:23:a6:31:d1:34:ae:9e:91:5c:5f:84:dd:
         9c:04:95:61:cd:80:14:1f:6e:de:88:97:7c:e9:af:a5:f5:f7:
         70:27:e1:10:44:93:0a:31:a4:09:a6:9f:70:4b:22:90:4e:bf:
         16:ff:62:4f:d7:f4:82:35:42:17:07:ee:b5:a6:cb:6b:84:b7:
         1a:6e:17:1c:45:17:4c:d1:cd:cf:e5:dc:0c:d7:c5:f6:c6:ba:
         2e:9c:b3:3b:6f:5c:16:5e:43:6c:25:4a:9c:f5:b0:ef:f9:aa:
         13:ce:ba:a6:3d:b2:50:dc:74:2c:b8:14:15:79:bd:e6:1d:91:
         1d:68:1a:3e:15:b5:07:77:51:d1:5f:03:ac:01:a6:d2:66:e8:
         0a:d7:af:33:a1:33:95:08:6d:fc:88:92:92:f5:72:fa:2e:8f:
         93:31:a4:bf:29:23:a3:21:53:ba:3e:b0:75:20:e4:15:40:3a:
         58:c8:c8:1e:dd:cb:75:10:b5:41:01:e6:16:5a:68:f7:37:39:
         d6:11:b6:30:25:fb:b4:7e:c8:12:c6:d8:9f:63:a9:d9:6d:86:
         d2:36:47:a1:73:29:22:fe:02:f4:63:2b:29:20:97:ae:b5:34:
         bc:58:e6:60:b6:11:d7:82:a6:e7:e2:37:7e:3b:7b:06:78:26:
         6f:6c:45:73
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 435 (0x1b3)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 15:57:01 2011 GMT
            Not After : Sep  8 15:57:01 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-28
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:ab:4b:55:9a:d1:83:c6:45:3d:d0:03:2f:ab:f1:
                    98:ab:34:c3:61:cb:e4:cf:ff:33:4d:0c:16:de:8c:
                    7b:a4:23:c6:04:c8:d3:d7:d2:98:2e:c2:7c:3d:79:
                    df:ec:f3:45:14:4f:f0:a9:15:33:e1:d1:a6:3c:16:
                    84:99:3c:2e:94:78:67:77:31:12:cf:a6:c1:78:19:
                    d3:c4:cc:fc:b6:f9:1c:55:4f:1f:94:a7:cf:b2:1b:
                    27:59:6f:a7:e7:78:19:c9:3e:78:4d:52:48:d2:21:
                    18:e7:1d:22:68:bb:fe:78:3d:b5:0a:2f:b0:ec:7a:
                    82:e9:d8:65:fd:f0:db:3d:a4:f3:5e:38:fd:4d:eb:
                    37:fa:02:00:2c:54:ff:79:b5:cb:9e:30:ee:d7:41:
                    3c:f1:3d:3e:f6:12:1a:35:04:53:4d:34:17:71:ff:
                    64:b9:38:14:d6:77:47:57:2d:b7:ac:cf:e1:37:50:
                    24:ee:d1:ca:3f:44:d7:e9:fa:d2:e0:43:35:69:8d:
                    e6:50:95:df:f1:48:6f:24:5c:ac:55:47:d2:e3:75:
                    b3:35:51:0a:22:b6:f2:83:8f:a2:71:be:40:b9:ba:
                    f4:4b:7a:73:7a:f9:f3:40:ad:5f:db:98:1d:e6:13:
                    7f:df:da:24:51:6b:d8:d0:8b:d2:9f:85:61:a1:f6:
                    d2:3f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                26:B4:AE:AA:2D:8E:E9:8D:8A:6F:B6:B5:5B:9D:EA:4E:AE:B1:9C:69
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         68:b3:d1:49:11:ab:5b:dd:bd:b4:1d:ea:5a:de:a7:b8:cf:87:
         da:a8:90:c5:23:49:d0:49:27:bd:ea:00:2b:fc:7e:1d:8b:e7:
         98:ee:5e:b2:e3:cf:83:e1:88:83:b1:4b:27:61:44:d5:a4:5b:
         ff:07:c5:c8:42:d4:76:3c:70:e0:38:21:0c:8d:13:cb:ef:17:
         3b:23:d2:1f:dd:4d:84:36:8c:a6:87:59:04:fb:d9:2e:1e:69:
         9e:56:74:48:b4:c6:52:b1:0a:7d:2e:10:5c:65:82:fc:0c:86:
         61:70:a9:c5:3a:46:60:5f:6d:be:81:88:66:df:b3:c4:8e:99:
         9b:b0:fc:3d:de:c1:da:8c:1b:44:20:d4:a3:7a:c0:00:10:47:
         70:89:44:15:6c:8b:57:ea:7e:b5:8f:78:d0:14:73:cc:3f:95:
         91:ec:5b:ad:53:70:4c:79:f5:81:21:98:d1:7e:af:38:b1:38:
         87:ce:70:de:23:23:10:25:f8:1a:8a:d1:46:6a:a5:4e:c6:77:
         f5:e8:02:83:eb:dc:3f:32:59:52:26:6c:00:69:64:25:90:15:
         09:96:e3:de:64:b1:7c:a0:9c:c0:d3:fe:eb:e9:8c:7b:a5:8c:
         94:b1:01:04:67:33:04:79:49:58:6a:a6:41:e9:58:27:56:95:
         98:03:f7:ee
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 436 (0x1b4)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 15:58:26 2011 GMT
            Not After : Sep  8 15:58:26 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-29
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:bb:4a:10:76:19:34:40:1e:72:2b:61:90:32:88:
                    f0:3b:75:1c:3e:3d:6a:77:3a:97:79:0b:ec:e8:51:
                    0f:7e:6a:00:43:98:c4:e6:a1:e0:45:5b:2d:03:fa:
                    66:68:a5:a3:d0:e0:92:81:3d:f4:77:6d:03:db:db:
                    25:e6:76:60:94:3f:f6:5f:df:5a:18:41:e2:f3:37:
                    48:f1:97:fe:2a:ad:44:e7:fc:31:e3:16:f8:bc:9a:
                    75:a5:fd:2f:56:9a:82:49:3a:cd:4d:4f:70:cd:3f:
                    7f:00:11:16:83:0a:ae:57:7d:69:04:83:a0:f3:77:
                    ca:05:c1:ff:fb:85:df:98:38:f4:fb:80:13:3d:38:
                    77:6f:ce:0c:9b:18:53:bc:d8:f4:24:ff:3c:ba:9b:
                    b0:2b:c7:e2:90:d1:fd:03:f3:38:ef:cc:52:c3:7e:
                    e3:7a:6c:a1:48:11:68:ee:00:38:4d:ca:38:7c:30:
                    3d:87:8d:ee:20:24:06:04:5f:5c:20:d1:05:c6:80:
                    bf:09:49:e0:6b:9a:c4:0b:2d:ab:61:76:5e:1c:70:
                    d9:82:c8:8b:0e:33:83:19:70:2e:2a:f1:7e:e9:19:
                    4a:fb:08:1e:93:cd:f3:57:77:b8:17:e5:73:9f:35:
                    a3:34:5e:55:88:75:27:60:d0:15:a6:05:c3:16:f6:
                    4b:a5
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                9B:C5:94:3F:EF:61:61:57:A8:E1:FE:59:AE:E2:69:18:DB:18:57:DE
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         2e:7a:47:cf:b4:b7:b9:a3:56:8a:5e:32:eb:a5:d8:d6:54:c3:
         e3:3a:6f:c2:c5:88:14:ad:b8:08:f5:05:a8:4d:57:38:bc:45:
         e4:86:0f:83:1c:7b:48:86:3e:82:06:f3:88:db:54:28:c9:34:
         85:e9:9f:03:bc:ad:4c:0f:9e:06:55:f6:df:13:02:dd:65:ad:
         09:38:01:e8:62:30:ab:99:de:83:51:67:ed:68:ab:ba:00:64:
         3d:f7:da:59:3e:0d:13:5f:de:dc:29:7b:df:cc:23:5b:9c:02:
         4d:6a:99:b0:39:71:83:a4:2b:71:2c:d3:c6:84:e1:15:08:63:
         17:d8:05:4d:54:3e:4f:2d:e7:2d:9a:23:36:08:52:69:5b:6f:
         0e:71:ef:a8:90:2f:31:3e:73:ae:f4:7a:d2:99:df:24:84:07:
         f3:71:6f:c7:f8:3a:7a:5c:9a:5c:11:5a:f7:c8:3f:3a:6f:43:
         b5:88:37:7a:41:aa:1a:df:18:14:f0:af:90:fe:a2:45:61:b2:
         ea:89:37:34:ab:0d:3c:e8:c0:d0:08:89:83:55:a5:47:0b:4b:
         4c:37:f5:29:a9:a0:6f:1e:75:a9:46:b5:72:fc:6c:9e:2c:fa:
         3f:de:8e:95:4d:3d:bb:88:1f:07:48:42:d1:10:be:02:8b:8d:
         30:30:08:7c
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 437 (0x1b5)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 15:59:24 2011 GMT
            Not After : Sep  8 15:59:24 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CA-30
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:cd:3c:93:67:26:0f:1e:e6:81:5e:ee:9f:ce:f9:
                    50:1e:dd:62:a2:15:84:25:e5:77:56:c2:53:c7:a0:
                    e0:c9:42:53:2a:e6:4e:67:52:3e:70:5d:c6:68:b8:
                    15:65:c8:dd:76:d0:b2:d5:9a:c9:aa:2c:e3:c4:09:
                    22:04:f7:7d:89:a4:88:d9:c2:83:ec:59:7b:49:10:
                    ef:9a:8d:c8:86:f9:73:dd:f2:0e:60:7a:9c:d9:8f:
                    4f:77:83:78:0c:4b:4c:2d:de:ed:9f:b1:af:1c:43:
                    32:ac:b0:d0:38:3a:54:9e:26:0f:14:4b:8d:c1:6e:
                    f5:26:95:24:37:87:ed:ed:e0:c3:d5:ef:c0:f0:0d:
                    75:f5:6f:9a:be:fd:64:3c:2a:22:af:38:12:2b:73:
                    2d:0d:09:7e:11:ea:fc:6b:32:73:4d:5c:c4:59:17:
                    da:c4:59:81:06:04:b6:0b:02:d0:67:b3:96:9c:79:
                    13:43:15:24:5e:c4:95:fd:50:d1:5e:08:9e:1f:b4:
                    a1:96:92:39:2b:68:ac:bd:8c:3e:86:89:2e:3e:b6:
                    eb:45:e0:bc:1c:9b:2b:0b:78:ef:6d:f1:1a:60:dd:
                    e6:47:f8:75:f4:f2:ca:44:a8:fb:80:59:e0:51:63:
                    85:0b:b6:fb:16:2c:e3:f3:ff:6f:f7:6a:be:9b:cd:
                    35:81
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                08:4E:D5:A4:3C:2A:04:9B:93:1B:B7:04:08:8E:74:B9:06:7C:0D:A3
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         99:f7:d7:ac:b1:25:bb:af:1f:03:35:bf:56:7b:f5:a1:60:a6:
         da:94:ee:8f:dd:cc:32:d1:35:0d:9f:e5:5e:a6:74:12:7f:01:
         2a:5a:33:21:c0:d7:06:ca:bf:dd:1b:66:54:4f:02:55:fc:a6:
         df:68:17:d2:bf:f4:5d:6b:8e:f9:c8:73:db:5b:54:3a:dd:bd:
         e1:69:d9:fa:91:db:2a:5a:0f:c7:8e:88:35:08:23:ab:64:67:
         db:df:1f:6b:fc:8e:5f:72:9f:97:81:87:81:e5:a5:21:7d:d8:
         4f:fe:31:9b:a1:79:a4:26:54:41:f0:45:90:af:5f:42:c1:1e:
         96:87:f9:cf:c7:a4:1a:44:53:91:11:34:d0:80:64:b4:d9:13:
         d6:2d:0e:88:c7:a9:b1:20:24:56:7c:07:fb:c4:7b:f4:f9:9c:
         7a:b5:0e:44:b7:32:57:3a:4d:83:91:c4:75:18:94:96:cf:5f:
         f6:6f:36:2b:ae:73:19:f8:e0:fc:69:ce:86:7f:ff:42:21:3e:
         f9:38:c3:5e:7a:99:28:de:98:2c:b0:9c:88:10:b2:34:1e:aa:
         08:0a:cb:4e:01:c5:64:eb:4d:a5:a7:f3:08:3d:0b:7a:75:3a:
         96:4a:f7:fd:cf:1c:af:72:4c:71:42:d9:fe:23:b9:5a:b4:ad:
         57:05:fd:24
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 39 (0x27)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jun 10 09:52:41 2003 GMT
            Not After : Jun  8 09:52:41 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-10
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:89:77:8e:79:1f:c8:54:b0:0c:29:7e:96:48:6c:
                    00:b7:cc:93:b8:97:b3:14:8f:b5:47:34:b5:da:af:
                    7f:79:60:96:7a:57:1d:65:7f:de:44:8c:4c:dc:16:
                    5c:72:74:f5:22:be:67:0d:3e:93:6f:61:d2:c5:64:
                    59:1d:36:0a:64:e3:6a:ed:6c:65:18:61:db:e9:b9:
                    9d:a0:00:c8:77:60:20:e7:9b:01:81:df:7f:90:49:
                    9f:37:57:4a:78:65:27:e9:23:69:07:21:19:ee:a0:
                    4d:52:95:52:bd:72:1b:9a:1c:1c:05:0e:9e:08:60:
                    16:43:d9:f1:15:b9:3d:69:53
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                35:27:1A:30:8C:1E:4D:A6:60:7B:B7:2D:3A:46:2E:4B:A9:2F:2B:30
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         a6:9b:50:92:23:73:ed:17:41:0d:36:27:53:d6:73:86:e8:a4:
         d5:aa:1d:f7:e3:41:aa:56:eb:2a:c2:6c:00:fe:05:14:d0:dc:
         bb:82:67:f8:68:ca:b4:d8:d8:97:e4:4e:e1:fc:24:eb:49:a2:
         c8:d4:47:0a:c2:80:dd:c2:83:cb:39:67:74:86:e4:94:2e:1a:
         ca:1b:11:d3:b0:cd:c0:c5:1f:0e:71:d3:86:3b:c7:55:6d:b3:
         49:bf:68:8f:d2:23:5b:ed:56:97:bc:9d:d7:49:01:1b:97:7b:
         0f:54:fe:86:cb:c4:65:f5:39:85:16:b8:68:ec:fd:15:fb:b3:
         ad:69
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 17 (0x11)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jul  5 13:00:29 2000 GMT
            Not After : Jul  4 13:00:29 2006 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ca:36:08:72:3e:52:8d:46:8e:c6:cb:6e:3a:14:
                    a4:c8:5a:e2:82:37:6e:82:df:e0:4c:e9:97:cb:c2:
                    63:81:9a:1b:a8:b4:8f:84:f2:0c:c1:01:a0:a4:8e:
                    83:b5:a4:56:f7:f5:95:b7:15:7e:ff:11:e9:e4:ee:
                    e7:31:87:0e:d7:49:6f:3d:f8:56:d6:a2:f7:f5:81:
                    58:36:e6:36:79:9b:bb:4d:86:38:ea:da:5d:1e:d1:
                    19:07:1c:ba:bd:c8:48:5e:de:46:24:60:ed:ac:0f:
                    16:c9:75:1b:ef:f5:74:52:83:d6:04:ad:c1:95:e8:
                    8a:d6:f7:27:be:36:06:d8:41
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                07:E1:41:C6:81:0B:61:48:34:8F:4A:7C:32:8A:70:7B:52:00:F8:33
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         3a:e1:7c:86:32:5c:2a:2f:20:f4:08:75:bb:52:32:97:de:b0:
         eb:ce:f6:e9:d1:f5:aa:79:1e:a5:fc:bf:c8:2e:49:c1:51:0c:
         38:64:f6:d6:85:8d:6f:89:aa:de:59:39:e7:4b:00:31:de:ff:
         a7:75:4b:f5:fc:b6:e2:aa:53:02:c0:37:e6:ad:9e:a6:5f:d9:
         07:9a:91:d2:34:60:a5:0f:55:98:5c:6f:73:cb:36:69:67:1c:
         2c:28:63:1b:63:e4:c4:b1:45:a1:4c:e1:f9:20:3e:22:a6:b7:
         f9:18:48:c6:80:54:1c:38:09:c0:a7:94:44:7f:4a:c5:9e:c2:
         6b:f7
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 15 (0xf)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jul  5 12:55:43 2000 GMT
            Not After : Jul  4 12:55:43 2006 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-4
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:e0:05:e2:d1:bf:b6:07:4e:61:de:4f:42:38:d6:
                    fc:a9:bf:5f:f7:39:3b:b7:99:97:58:ed:8d:06:10:
                    88:82:f0:eb:c9:5d:14:83:53:46:9a:30:d4:19:da:
                    94:b2:b4:4d:47:2a:2b:f9:83:02:fc:23:d4:a4:02:
                    13:30:f2:7e:11:11:9b:b0:90:3c:81:b2:22:b6:72:
                    b5:8f:c1:a1:47:b3:ae:a0:a4:f3:ac:02:91:82:6b:
                    b5:6e:bf:22:b0:99:e1:30:67:79:e6:e0:da:2a:2f:
                    44:ba:75:5d:24:c1:49:da:f6:98:e6:45:b9:80:5a:
                    00:d2:58:ed:23:d7:78:93:97
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                15:A2:A3:35:DE:71:32:35:2F:BF:F1:FD:E7:55:D1:9F:D8:F6:2A:5F
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         b3:b7:00:85:68:37:d2:b0:ef:d3:51:81:73:e6:52:97:a6:1a:
         94:7b:84:3d:c8:c0:78:ad:e3:3a:b2:89:9b:0b:e8:6f:38:28:
         12:fc:ac:3c:b9:25:87:c7:5d:43:1d:bb:a4:52:21:a0:24:8a:
         95:b5:82:89:ae:5c:65:d9:26:06:c9:bc:cc:14:63:6d:81:7e:
         36:80:71:6b:e7:1d:b9:38:fa:eb:01:64:af:08:08:24:61:f3:
         f1:dc:90:a1:5f:c9:a5:30:f2:5f:aa:a7:fb:1c:94:d0:56:92:
         28:1b:76:d6:64:36:32:a8:83:1a:1d:75:08:67:30:b1:6b:4b:
         7d:32
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 31 (0x1f)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Mar 20 15:00:13 2003 GMT
            Not After : Mar 18 15:00:13 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-5
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:de:24:b5:55:78:3e:e4:0a:3e:3e:ac:07:32:bb:
                    3a:97:6e:0f:98:0f:4f:f8:84:ad:04:71:46:e1:28:
                    ba:06:44:0c:d2:96:11:b5:d1:94:93:0e:12:cb:4c:
                    88:28:fe:4e:31:8b:08:71:f4:34:1a:4a:86:af:db:
                    c3:95:10:f4:50:04:de:cc:2b:a6:cf:97:55:a4:68:
                    5c:f0:11:79:5d:ec:b4:1a:45:03:24:17:a0:ac:58:
                    2e:8a:c8:97:a6:05:de:28:45:cd:dd:74:9b:28:b5:
                    78:bc:f6:c4:9b:91:b9:45:94:0e:e3:2f:45:bf:eb:
                    be:0a:5d:74:9c:03:18:13:29
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                AF:CA:84:6B:F3:CA:E1:EA:FF:88:F4:A3:49:A5:38:D0:AA:34:AC:A9
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         ae:c3:29:18:38:e4:8b:90:63:0b:7e:b7:a6:5a:f9:f8:ab:3b:
         5e:a9:5b:6b:4a:e4:a3:36:8e:4d:e5:b6:44:ea:69:88:44:3a:
         b5:46:01:43:71:52:71:6e:f0:e4:ae:e3:05:f7:ae:9f:82:a2:
         4c:5a:8a:f7:59:89:86:49:6e:07:68:52:0e:59:39:e2:b8:38:
         ca:71:5c:09:df:24:17:c9:91:72:a1:cf:d8:b7:8b:cb:e8:26:
         69:33:bd:80:48:3b:82:c0:0e:9b:04:35:4b:0f:5e:19:38:9d:
         68:cf:d5:3a:59:59:31:6f:e5:8f:aa:d5:71:85:9f:ef:e9:64:
         78:48
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 33 (0x21)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Apr  9 14:06:27 2003 GMT
            Not After : Apr  7 14:06:27 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-6
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:b8:e7:74:c6:4a:d7:70:30:0c:e1:e5:4c:62:3d:
                    d4:4f:a7:fc:fb:bd:ff:f9:79:0d:cd:24:5c:0c:73:
                    a0:5c:cd:e4:c6:ca:1f:4f:1d:89:8b:5b:4e:cc:8c:
                    bb:69:fb:36:8b:54:af:9d:a7:e8:b1:bc:b5:5b:cd:
                    66:06:6b:e9:64:4a:34:52:46:c3:70:98:15:eb:12:
                    b9:e2:00:43:55:1c:b9:d0:0e:87:48:9c:27:7c:2c:
                    75:f5:48:08:e4:f6:f8:c2:a1:7d:84:7b:64:02:3d:
                    89:b2:4a:de:79:aa:40:ee:d4:8a:43:f7:d8:1d:ba:
                    0a:9b:2f:cd:51:d6:57:e4:d1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                31:71:87:1F:F0:21:90:7A:FF:C4:63:33:41:C3:F9:86:AF:37:BE:C9
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         a3:9e:9b:19:56:aa:3e:bb:50:17:16:a6:bd:59:64:78:17:cd:
         c7:9f:dd:c8:ec:c9:9f:b2:97:b0:2a:09:c4:60:fd:42:27:2f:
         5a:79:dc:03:37:c4:d8:8e:33:8e:ed:84:c7:9d:fa:26:34:0a:
         9c:b1:b5:f2:7e:28:93:37:cb:54:e1:0c:b4:b9:89:9e:fe:64:
         5a:a2:b7:6e:5c:bd:8b:0e:fc:58:ca:ad:97:26:10:11:99:d2:
         20:79:1a:da:c1:90:f0:34:3e:53:69:07:02:46:aa:d5:72:14:
         60:cc:3e:6b:bc:ca:ce:a3:48:a2:07:0b:39:71:3c:dc:b2:eb:
         ab:a3
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 36 (0x24)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jun  4 10:12:06 2003 GMT
            Not After : Jun  2 10:12:06 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-7
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:bc:04:a4:24:4f:af:ca:b8:3c:a8:b8:af:27:ec:
                    09:40:ca:f6:72:d4:a0:28:99:dd:dc:97:ff:67:76:
                    67:a1:3a:88:3e:fa:a5:ce:ec:57:5f:23:8f:8a:dc:
                    c5:2a:9b:a4:c5:0b:f3:96:a6:db:ed:0f:01:81:b3:
                    f2:ca:a1:ad:0b:8d:a2:03:2f:0c:a0:8c:6f:e4:39:
                    04:6b:cc:77:0a:c6:7a:68:96:e9:96:24:cd:9e:54:
                    96:40:4f:87:5f:21:45:37:2d:f5:96:3e:89:9a:26:
                    07:c0:55:46:07:33:86:f2:a1:71:ed:3f:56:09:28:
                    2d:06:cc:57:82:49:97:0e:d5
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                02:C5:1F:43:11:73:60:32:37:3E:E6:47:86:29:DE:21:B6:72:66:23
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         b4:ea:8c:4c:69:79:99:d2:f7:56:9d:84:a0:89:8b:aa:f1:d3:
         a4:5d:a7:3a:a9:cc:16:7c:78:4f:cc:e2:8d:71:fc:8f:4f:db:
         1c:8d:34:00:86:d8:25:e5:60:cb:d6:32:2f:3d:d7:b3:11:19:
         5a:f7:32:c1:34:6a:d1:79:0b:b3:c1:2d:ca:07:44:ea:56:4d:
         24:0d:cf:c7:71:67:3e:60:53:c1:a5:d3:0d:a1:80:eb:de:5c:
         7a:6a:7a:ec:bf:39:6e:fc:66:d8:85:57:9e:bf:75:8b:a9:25:
         55:cc:d8:f7:43:29:71:60:54:c0:17:8a:f2:9c:4f:76:c7:2a:
         d9:89
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 44 (0x2c)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Sep 17 09:35:20 2003 GMT
            Not After : Sep 15 09:35:20 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-8
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:c7:d6:55:24:75:d0:8c:fd:ff:2a:fc:7c:ec:0c:
                    2b:90:d5:71:3b:49:a8:a5:7c:6f:b4:a8:7e:bf:23:
                    a5:b0:7f:3a:28:c7:7b:00:e0:2c:f9:7d:af:69:d5:
                    6a:dd:1d:b3:5c:0f:3c:94:77:7b:cd:5c:43:fd:c3:
                    f8:da:5d:3a:46:76:68:26:24:23:e2:44:69:60:87:
                    ac:dd:31:fc:63:1e:7d:51:b7:a2:e4:ce:ac:71:84:
                    87:ac:48:d9:0c:5b:f0:8b:13:07:b6:5e:08:28:24:
                    2c:29:62:78:d6:e2:69:b6:d7:08:6c:5a:f6:02:a8:
                    5c:7f:94:ce:17:cc:b3:84:cb
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                99:45:C7:10:F8:B6:90:19:29:23:D9:3C:7F:41:59:75:82:9D:0E:DA
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         43:6c:4b:bb:64:f6:75:db:8f:1a:6b:b0:e2:7f:99:a3:17:87:
         49:5c:c4:f2:b3:ed:4e:92:bf:bd:66:cc:ee:c9:4d:5a:de:4b:
         5d:77:f0:20:32:15:9a:19:8e:8e:33:a5:5a:7d:b0:6c:38:4b:
         cb:55:2f:58:36:4d:af:dc:4d:4d:15:13:3d:46:a1:8e:c5:9d:
         64:18:89:a9:64:07:68:1a:ab:02:bb:35:7d:9c:ac:fb:2b:f6:
         1f:96:28:5c:0f:f9:26:a0:06:3f:43:b0:73:8f:3d:d5:52:a2:
         92:95:ce:df:e5:b5:b6:80:4a:18:d7:79:ef:1b:b0:4d:99:fe:
         47:bc
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 42 (0x2a)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jun 10 10:20:47 2003 GMT
            Not After : Jun  8 10:20:47 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CA-9
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:cf:d0:e3:16:62:4d:5e:a3:d0:f0:ef:b2:bd:cb:
                    65:0b:9e:ed:d6:53:6a:27:90:e3:27:2d:47:67:5e:
                    c8:b9:65:0f:dc:0c:fd:0a:17:4f:06:4b:8d:91:2a:
                    42:99:9a:a0:1b:f5:b5:76:fa:d5:4a:60:17:c9:71:
                    15:96:34:ac:ce:d3:58:a6:af:25:48:a5:85:45:1b:
                    df:69:b2:70:ba:90:2e:57:8e:40:1d:b2:62:c7:5e:
                    92:21:f3:20:aa:a3:d0:1c:b4:65:7b:41:3a:5b:a2:
                    57:01:be:dd:b8:81:fa:b6:e5:03:5a:05:43:c7:e8:
                    7a:67:d6:82:6e:8f:ce:cf:33
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                7E:70:56:29:D7:90:1A:17:D6:BC:5C:65:D3:CD:47:5D:1D:CE:10:B7
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         3b:34:4a:e2:a7:1d:aa:29:89:3c:28:b5:a5:ed:72:fc:af:8d:
         58:3c:eb:ee:65:f6:4e:8f:cc:87:53:6d:f5:8a:35:ab:29:c2:
         93:c4:3e:1d:21:f8:db:bb:b1:55:45:f4:36:44:0e:2e:0e:43:
         50:de:ec:ba:5e:d1:23:15:a2:af:43:26:4b:83:e0:40:a5:c7:
         19:6b:06:f0:33:e6:6a:8e:63:27:1a:64:4c:a5:45:36:42:0c:
         ec:d3:7c:97:50:c1:87:bb:4b:d5:ea:8d:a4:04:93:8a:28:ec:
         71:00:02:38:c1:0b:26:31:15:c0:93:c6:f1:82:09:33:5a:b1:
         44:94
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 20 (0x14)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Sep 27 11:37:28 2000 GMT
            Not After : Sep 26 11:37:28 2006 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CAC CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:97:12:02:97:35:9a:24:22:55:3d:98:25:ff:2a:
                    b1:26:02:51:4d:b4:5d:7d:9a:0f:6c:4b:f3:d6:9d:
                    2f:22:b0:60:92:cf:4b:76:60:c8:a2:91:36:f2:79:
                    8d:2a:7f:a4:6e:c5:15:72:aa:82:6b:4f:dc:17:d8:
                    91:61:b1:a8:3c:e9:6e:4d:d4:89:dc:d2:b5:d3:7f:
                    e9:cd:c3:dc:4f:eb:1f:08:19:d4:90:56:e6:a6:bc:
                    bd:49:b7:82:f9:e6:7a:8c:bb:44:13:6a:56:30:c5:
                    db:8d:94:6a:e4:29:54:7b:4a:0e:59:05:30:fd:36:
                    15:87:75:ae:9e:26:99:24:79
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                A7:22:39:30:7B:50:3C:51:B0:9F:07:0E:C9:A7:0D:01:1E:CE:CB:CF
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         81:1f:ac:e0:d5:4f:2d:d9:44:9e:79:f6:1d:1a:ff:8f:9d:b6:
         1f:ea:cc:98:35:72:de:2e:2e:c5:f9:35:70:00:88:fb:a5:6b:
         4b:9e:cf:fe:78:d5:c7:df:43:fe:ae:eb:56:4c:e8:ec:cc:c8:
         98:55:92:ea:f8:2f:ad:a6:5c:26:4b:c7:e6:a5:de:85:1e:16:
         da:0d:96:05:31:a1:00:73:9a:19:55:a3:d5:7f:10:b1:be:89:
         4a:68:26:e0:fb:34:ca:cf:85:bd:da:2e:ba:da:4e:2d:8f:99:
         78:ef:b2:f7:96:61:05:76:47:e8:3f:ad:1c:12:f9:7b:c8:9a:
         00:81
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 21 (0x15)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Sep 27 11:45:53 2000 GMT
            Not After : Sep 26 11:45:53 2006 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 CAC EMAIL CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ca:01:2c:75:19:49:1a:e7:19:df:48:fe:b8:d9:
                    96:ec:76:df:a3:0f:b3:f7:0e:d7:43:d9:36:41:69:
                    dc:60:75:7a:2a:3c:5f:1c:55:35:a1:e1:fc:b5:d7:
                    84:cb:b5:3a:79:85:99:fe:27:5c:1e:1c:ee:14:ad:
                    1e:ee:11:f7:71:67:72:db:51:ce:37:cb:40:13:d1:
                    13:b6:fb:d0:03:e9:c2:24:ec:04:ff:ab:7f:46:64:
                    f8:fe:27:f4:87:d5:e2:8d:33:d3:b7:b1:ce:1e:a6:
                    c0:9e:da:2d:b9:2e:ee:49:7c:71:8c:00:3d:a0:cd:
                    9f:19:76:95:84:f0:25:e9:5b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                CD:24:39:A6:0B:49:1D:DB:E3:E5:F8:0C:6E:0A:04:63:B2:09:6D:B8
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         62:8e:6e:09:58:a7:31:56:03:8d:97:09:05:9e:d5:a9:f4:0c:
         cc:b2:c5:7f:d6:4c:9e:0a:13:12:c5:80:dd:fa:b5:fd:48:2f:
         0c:dc:6b:d8:23:a2:cb:25:18:fb:04:8c:92:95:a2:31:cd:33:
         70:0d:6f:96:1f:ea:d2:88:9f:3d:73:95:07:b3:6b:56:4b:b0:
         ce:cc:59:36:03:5c:d8:37:3a:b5:fc:cb:1c:6c:9a:9b:c8:8c:
         96:aa:d8:60:ca:2a:28:f1:f4:c2:a9:f4:70:a5:14:01:0a:cc:
         a2:cf:0c:f6:0e:82:55:c5:55:aa:e5:48:0e:2b:8d:27:a7:38:
         54:2b
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 40 (0x28)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jun 10 09:55:01 2003 GMT
            Not After : Jun  8 09:55:01 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-10
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:d4:21:7b:6a:55:aa:ac:30:b5:89:0b:5e:93:e5:
                    24:1c:51:dd:f8:a9:e5:23:18:75:11:5f:db:92:66:
                    51:1b:7c:65:bd:7e:2a:13:3a:08:23:96:c4:19:8f:
                    26:0d:c4:47:f2:f9:ac:fb:52:44:5b:ae:72:8e:8c:
                    fa:54:87:0d:f2:a7:44:a7:a9:24:50:54:7d:28:9e:
                    1c:f7:81:0a:db:e1:df:93:d2:be:30:ca:5c:44:0c:
                    7f:91:be:7e:63:1c:60:bf:c7:6c:76:c3:3e:b2:b1:
                    50:7c:79:4a:9a:e4:c6:a4:0a:a2:52:d7:a4:b7:2f:
                    6e:a9:43:bb:ce:7a:e6:f0:69
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                6F:37:23:A4:D3:20:EB:F4:0C:3F:60:9F:79:4C:0B:72:10:D2:3C:97
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         a7:65:59:a7:99:b2:72:b8:a4:99:a5:35:0a:c2:9e:e0:08:b7:
         b7:6a:48:f6:db:93:d0:3a:b8:47:c7:48:2d:eb:82:c7:d9:fb:
         c3:13:08:42:ae:21:ce:f2:34:46:23:20:dd:44:24:22:0e:93:
         de:f6:ed:98:ff:12:bf:c2:f2:14:58:35:01:3c:c2:ff:9b:e3:
         b0:18:e0:e2:b9:31:7c:d4:df:1e:80:1e:ce:b4:6f:a2:ab:6b:
         1a:da:85:3e:f7:ba:22:d6:b6:08:16:3e:1d:8d:99:ef:5b:3e:
         3d:14:6f:6a:e4:54:e8:75:f0:f5:62:98:5d:de:17:c9:e9:8f:
         83:09
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 19 (0x13)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Aug 11 17:45:29 2000 GMT
            Not After : Aug 10 17:45:29 2006 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ef:7c:bd:c8:6b:eb:f1:2e:37:85:70:da:1d:68:
                    bf:38:88:07:33:a6:97:cf:0b:2a:d8:8d:43:13:05:
                    37:4e:c9:57:4e:09:15:1d:a4:66:db:8e:c6:50:9c:
                    bc:d9:cb:d9:f5:ef:f6:54:46:e2:d7:a2:c2:a0:65:
                    76:dd:fa:7a:45:58:ff:52:c3:91:6e:b1:0d:e7:2f:
                    1e:74:b8:06:e2:61:40:f9:e6:31:d9:ee:1c:5e:3b:
                    4f:02:bb:3b:f6:f1:bd:eb:c0:2a:92:9e:4b:5f:ec:
                    c3:5c:2e:c8:a2:4d:f4:18:bb:8d:ec:c7:df:a8:18:
                    f8:27:53:f5:5c:1f:3f:84:09
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                EC:13:5B:BC:21:8C:66:9B:0A:8B:7F:07:5F:25:B0:14:F9:10:F5:9B
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         26:a5:8d:35:38:76:6b:fe:f4:41:26:c8:31:19:45:fb:76:21:
         ac:08:6a:f3:60:cd:42:d1:f8:6b:26:49:c7:e0:be:cb:9b:ad:
         4d:b7:56:d2:67:8f:e8:6c:78:e5:43:10:50:c8:3c:7d:a2:f2:
         12:04:08:bf:fd:35:54:77:55:0a:6d:da:8d:5b:b2:27:b2:8d:
         9e:9e:62:bd:6d:e1:bd:78:ae:4c:d1:97:c4:76:3d:d2:d1:4c:
         66:24:08:11:5d:28:15:b2:71:3b:c7:33:f7:b9:9d:7f:98:9c:
         7e:fa:04:b0:72:97:7e:fc:d3:c1:54:93:63:14:93:df:f1:1b:
         cb:e0
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 14 (0xe)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jul  5 12:50:51 2000 GMT
            Not After : Jul  4 12:50:51 2006 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-4
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:bf:76:cb:dd:56:7a:e7:a6:d2:1a:7e:4d:88:81:
                    2b:4a:9e:60:12:8a:3b:63:1c:27:d4:79:e9:66:fa:
                    3c:6e:55:f4:47:2b:0e:3e:fd:b0:96:87:cd:ee:e0:
                    0d:4a:d2:a6:b2:50:c4:ee:61:f6:4c:58:1f:2d:9d:
                    5d:9e:e9:2b:72:75:43:52:4d:2d:81:65:03:73:c3:
                    99:62:2f:ee:ff:04:31:a6:76:f5:87:84:11:41:15:
                    3f:5b:5b:41:1a:d5:f7:52:eb:41:2b:08:09:f5:60:
                    3d:10:63:ef:9d:5b:90:26:a1:d1:ac:ab:b9:be:99:
                    c4:cd:8b:14:87:a0:00:c8:6f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                D5:B6:23:C9:45:82:39:96:44:E8:18:09:A7:D6:8A:61:FD:8C:65:C4
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         11:f6:8c:a6:b0:5f:bd:f1:0e:45:17:aa:a6:ee:5f:f8:40:47:
         64:3b:83:3f:35:8c:b0:eb:b8:7f:7b:ff:1b:0d:f2:62:ef:ce:
         2e:f3:bf:ad:ce:0b:27:40:cc:6b:a8:98:bf:a7:5b:68:4e:e8:
         e8:2c:30:a8:82:23:9e:b8:78:c3:32:94:22:c1:28:66:b4:18:
         ce:f2:17:ad:2d:2c:3c:0f:47:94:e5:03:aa:23:29:b1:88:b6:
         fe:40:8d:f2:a2:3c:5b:c1:c3:5a:d0:4c:63:3b:f7:23:73:94:
         4a:05:d4:30:02:13:55:fa:50:0e:1f:18:27:58:c8:96:22:bd:
         a7:08
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 32 (0x20)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Mar 20 15:02:53 2003 GMT
            Not After : Mar 18 15:02:53 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-5
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ae:cf:46:1b:c1:58:11:50:48:cc:24:dd:e8:10:
                    ff:f8:5c:8f:4d:bf:9a:1f:e7:1f:75:84:ec:84:cd:
                    52:24:d8:6e:c6:32:0a:16:bf:12:7a:4b:f8:db:67:
                    98:8a:05:ff:97:2e:f5:a1:2b:3d:6f:5e:e3:16:1c:
                    42:61:63:60:40:16:60:f6:9b:53:8d:d2:72:e8:c9:
                    82:b8:14:79:0f:d2:3c:ce:59:25:1a:07:c1:25:06:
                    92:be:cb:3b:1c:15:60:4e:69:6e:6d:f6:82:b6:08:
                    77:5a:18:bc:62:c7:b3:81:29:e1:75:52:db:07:1a:
                    40:3b:f2:74:a9:1e:65:da:c3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                FC:10:FA:B9:6A:61:2E:4F:B3:D7:74:C6:28:1E:69:E0:2F:CE:54:E8
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         ab:c7:f8:47:e1:24:ec:cf:9b:3f:c6:f9:34:f8:30:a3:92:cf:
         07:86:f7:b0:92:f8:be:2d:c9:7f:e7:b4:5e:3b:14:8c:fb:a4:
         67:c5:03:c9:95:58:7b:56:ca:0c:9e:f3:58:c6:e5:99:25:3b:
         4f:e0:5c:3d:d5:46:20:ec:71:44:e2:e1:83:9f:87:9c:9a:06:
         f1:68:d3:80:fd:4a:ad:9b:20:0c:73:3c:ba:86:e1:bf:bc:73:
         20:ef:95:da:19:65:2e:1a:95:ae:a3:7c:37:91:7b:68:28:f7:
         e7:e8:9a:82:eb:4e:1e:1e:b9:3f:de:be:93:e5:8e:4e:18:c9:
         79:63
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 34 (0x22)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Apr  9 14:08:23 2003 GMT
            Not After : Apr  7 14:08:23 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-6
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:aa:d3:fa:6a:4b:d6:7e:8a:dd:9a:70:f0:07:72:
                    a6:72:ca:63:8f:71:4b:bf:f4:90:b0:53:99:c4:ae:
                    e7:7d:72:59:5f:56:02:65:59:22:10:a5:d4:81:f9:
                    4b:f4:91:d3:46:61:8e:6c:a4:12:a8:b1:0a:e7:cd:
                    05:1a:0f:3f:a1:0f:00:97:2f:b8:71:28:30:63:64:
                    52:46:42:25:67:ec:bf:04:44:a7:bd:a9:17:41:f6:
                    c4:db:4d:6c:93:cd:23:07:fd:bb:9b:5e:c7:8c:9c:
                    b0:d9:12:96:45:7b:61:cd:d8:55:40:d6:15:d4:39:
                    95:68:d9:fd:a1:27:c6:c9:b7
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                E8:AB:23:35:7A:5B:20:5A:14:29:F5:4A:C9:F0:96:16:80:38:62:B6
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         70:0e:ac:9c:4d:cb:00:85:6a:17:1e:95:be:f6:e1:e4:f5:ae:
         43:ff:b7:2c:bd:0d:5a:6c:66:73:34:c8:90:4c:23:e3:e4:55:
         df:d6:b7:85:b6:d7:e2:c8:60:fc:80:79:17:20:76:85:e7:88:
         69:3a:2b:c0:0e:e2:db:47:13:71:86:bd:8b:23:82:70:b4:f2:
         02:9b:ad:85:be:b2:2c:5e:32:bc:87:65:8f:a1:ac:b9:1c:3b:
         1b:ab:31:e7:84:aa:70:45:ca:b0:43:af:c3:d0:6e:b8:94:04:
         5d:8b:fa:e0:3e:d6:ac:b3:77:b6:14:dc:1d:bf:13:e1:db:a8:
         50:17
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 41 (0x29)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jun 10 10:11:58 2003 GMT
            Not After : Jun  8 10:11:58 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-7
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:d3:b0:a8:e5:6d:b6:f4:3b:f1:b3:fd:86:e5:6f:
                    14:4e:29:26:c8:e7:43:a8:9a:b7:af:fe:8b:c2:11:
                    f5:ce:3a:a4:f6:5e:e3:c9:db:80:99:65:ba:0c:bc:
                    fe:e7:05:fd:c8:0e:bb:5f:98:c5:e4:a5:8a:0b:c2:
                    40:9f:31:2b:a0:bb:4e:6e:67:77:8d:d9:e0:13:e8:
                    bc:a4:e7:42:99:42:55:98:0d:72:a4:7e:72:39:b1:
                    fd:1f:1f:5c:a6:5a:0f:77:4d:75:b0:5e:f6:9a:72:
                    b4:f4:f9:2d:57:6b:d3:5e:56:a3:8f:37:56:8c:dc:
                    e6:c6:f3:f5:56:64:1e:68:79
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                5F:B7:8D:95:96:8A:58:68:0F:8D:D8:E1:5C:7B:C6:E7:76:D1:A1:59
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         16:82:6d:9c:f7:fa:97:c7:77:3a:7b:dd:78:d3:23:b6:fc:15:
         79:d0:df:fe:22:bc:73:a2:07:1f:94:38:88:32:24:c4:0a:3b:
         70:11:14:22:ed:07:80:d1:32:e8:de:6f:7d:a2:7e:c8:e9:74:
         3b:9b:be:9a:15:9c:98:f9:a4:a8:56:0c:16:e5:32:ef:45:97:
         42:e8:c7:34:86:22:97:ba:a8:09:e1:c4:c9:e9:d3:08:81:22:
         80:31:47:11:38:b2:67:b7:af:57:d0:d2:ff:ab:20:8b:b4:0f:
         2e:36:ae:d2:5a:e2:b9:01:3d:f3:13:dc:4c:be:60:c4:c2:4d:
         ba:8d
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 45 (0x2d)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Sep 17 09:37:18 2003 GMT
            Not After : Sep 15 09:37:18 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-8
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:e0:4c:84:93:18:e6:34:e2:7e:f0:5d:4d:e7:7a:
                    86:03:50:c9:0d:65:b6:d5:fe:84:cb:6c:8b:c1:7e:
                    50:be:8e:9d:3c:ca:99:c2:19:83:ff:10:f3:21:8f:
                    8b:d3:47:84:09:1b:98:ed:30:82:b0:9d:2f:4c:21:
                    54:57:32:8b:ca:21:84:3b:1b:9f:f2:3c:ef:9a:78:
                    56:33:35:f3:1d:9e:bb:7b:1f:c3:3b:ba:41:57:f5:
                    79:b7:5a:f1:16:78:38:7a:2c:35:11:41:3e:08:4a:
                    4b:a8:e9:cc:db:43:6f:d5:94:24:8a:ef:c5:de:32:
                    5f:61:5f:e4:14:2d:c5:32:2f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                88:67:29:78:A3:B6:13:1C:70:17:7F:42:93:28:92:14:70:96:73:E5
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         63:0e:92:dc:b8:c2:97:c0:0f:5f:2b:e5:fb:a3:bb:3d:ce:79:
         65:b4:c2:2a:95:a6:76:77:ef:5d:2b:a6:55:2c:fa:35:b2:97:
         08:96:a4:01:17:4d:ba:f5:02:78:be:09:70:20:88:b6:38:a0:
         c1:f0:99:cd:e0:ce:fa:41:4f:bd:78:79:48:31:5f:fa:4b:60:
         95:fd:ba:e2:71:2e:60:14:a2:11:9f:f4:72:4e:d0:54:b9:1f:
         c2:dc:be:93:45:08:ab:41:c0:5a:45:bc:43:62:32:6c:a4:91:
         11:22:bb:38:48:6a:e6:57:7b:c2:3b:f3:4e:04:75:2c:2b:22:
         64:51
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 43 (0x2b)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: Jun 10 10:22:21 2003 GMT
            Not After : Jun  8 10:22:21 2009 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD CLASS 3 EMAIL CA-9
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:92:81:e1:87:97:79:fb:37:4a:b6:45:a6:e4:0b:
                    94:64:5d:03:5e:c8:76:d7:f6:7c:c0:db:91:d7:56:
                    a0:32:0b:f8:79:eb:06:c5:22:88:93:bd:e2:ec:d4:
                    f7:95:10:33:1a:58:36:e9:12:2d:9c:6e:e1:b8:6c:
                    7f:85:d3:3e:d2:89:24:65:21:55:ff:44:6f:e8:84:
                    03:31:5e:9c:2c:ce:44:6d:b0:c7:7e:bc:78:e6:e3:
                    39:d6:69:f3:05:10:03:c2:3f:67:ae:c9:c7:14:a8:
                    8c:48:a5:b2:bb:36:f3:0e:ac:37:2f:1d:60:75:c1:
                    4a:8e:2a:bd:be:05:bf:b1:91
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                AA:D2:53:ED:BF:3E:E0:F4:16:B4:32:D5:DE:44:2A:DA:25:62:97:BF
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Authority Key Identifier: 
                keyid:6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 Issuer Alternative Name: 
                URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://ds-3.c3pki.chamb.disa.mil/cn%3dDoD%20CLASS%203%20Root%20CA%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         96:18:83:14:55:e1:1b:54:9f:11:f2:42:fc:4b:55:57:25:c3:
         4f:5d:33:8d:24:b6:a4:9f:33:4b:a4:36:a8:e6:ab:b2:14:7f:
         31:75:7e:5e:c2:2f:a4:f0:0e:a1:a3:c7:08:80:1c:ec:d8:12:
         ea:ad:7d:e3:a5:c6:48:36:38:0f:42:3a:4e:f4:b7:87:ee:4e:
         8f:01:ce:14:55:c7:4a:ae:1e:3e:75:32:a0:5d:4c:56:87:ea:
         7f:14:7f:75:b6:19:6f:5f:de:db:22:7e:6c:1a:6b:f0:40:88:
         fc:ba:a8:d9:71:5b:36:c4:9d:7e:44:58:b6:18:a0:bc:c4:38:
         c7:d9
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 10 (0xa)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan  2 16:45:55 2006 GMT
            Not After : Jan  1 16:45:55 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-11
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:9b:7f:4b:9d:ee:f9:f4:05:4d:95:42:56:c7:0d:
                    a0:6d:cf:12:f3:8f:75:0f:5e:b0:f1:ff:f9:06:07:
                    a1:3d:83:e9:ec:a5:f2:1f:cf:fd:70:dc:9f:53:a5:
                    e3:83:2e:1a:23:b2:25:2a:90:bb:8f:b3:d4:94:d4:
                    96:be:1f:22:a1:48:a9:bd:99:3c:7e:d3:bc:b8:53:
                    54:15:41:9b:ee:f6:08:43:fe:19:0d:0f:74:f5:4f:
                    8a:61:21:0a:46:de:98:a1:0e:96:5d:04:0e:b0:20:
                    94:f8:2b:da:ff:f6:52:aa:56:1a:b6:97:dc:5f:5e:
                    9a:b7:76:82:81:b9:b8:b6:f3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                53:15:03:45:EE:74:A1:34:5D:6C:86:AF:72:66:81:6F:E9:AD:7F:12
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         15:5b:55:b9:49:6f:74:8d:79:d1:05:59:59:5b:82:2d:e5:e6:
         16:46:85:4b:36:cf:1e:10:33:03:12:2f:18:8e:ee:66:4c:16:
         17:9a:ce:39:2d:81:ea:14:e4:20:30:83:a2:bc:34:3a:2c:9b:
         9c:5b:e7:22:4f:bf:4b:89:0a:a4:4a:78:3c:14:58:16:08:c0:
         16:51:3f:64:e4:76:52:bc:67:ef:e2:f0:71:5b:b2:19:8e:bd:
         82:be:8e:32:11:40:8a:f7:b8:61:db:8a:11:36:5f:bc:27:5d:
         00:48:83:20:3a:34:4a:91:d5:6e:92:1f:ca:99:36:e2:21:d4:
         b0:98:18:3f:59:04:5c:8f:50:3d:0b:9f:63:d8:84:db:f0:df:
         3f:51:43:c6:a6:96:8c:ac:c5:75:4d:65:f5:4f:30:24:19:c9:
         e0:eb:f7:56:51:83:83:7d:ef:2f:0a:6e:36:b2:c9:19:29:ec:
         3f:9d:d2:10:83:de:f1:e8:5e:e8:e4:fb:ed:c2:b4:90:b0:9f:
         c3:c5:72:5d:4e:e6:71:f5:2c:46:4c:26:2a:2e:09:32:c9:a1:
         9d:e7:02:c1:dc:f3:7d:56:ab:d1:71:a6:f6:87:d2:fe:64:dd:
         a3:b8:09:0f:c6:a2:6f:f3:c7:19:da:92:99:85:36:23:95:ca:
         6e:9c:81:d2
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 12 (0xc)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan  9 13:54:45 2006 GMT
            Not After : Jan  8 13:54:45 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-12
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:e3:22:a6:ee:8a:a2:a4:d1:01:46:7b:52:43:56:
                    a6:7b:14:f0:b4:ea:81:53:54:cf:2b:6c:6a:2d:7e:
                    c4:8e:2a:b8:b2:cb:63:46:a9:8b:c9:29:ff:0b:79:
                    5d:f2:4e:d9:ca:e4:5a:b3:40:40:dd:ff:45:d4:1c:
                    d4:4e:5a:8b:22:da:f3:12:7f:93:b8:e9:69:87:37:
                    a2:aa:ac:43:10:99:98:6a:5a:51:fc:9a:eb:52:e5:
                    4d:b1:99:f5:5d:f7:da:bc:56:e5:8e:9d:1d:62:92:
                    5a:21:b7:4b:d7:16:82:62:95:d5:86:95:ca:f0:1c:
                    90:40:74:5a:5f:46:bc:6d:03
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                D5:C3:29:8C:A0:77:DC:1C:28:08:4E:77:4F:FF:E9:13:11:63:41:33
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         2a:1f:0a:9d:77:0e:e5:9b:fa:e4:91:cd:6d:a8:5d:9e:9e:0d:
         16:3f:cd:d0:a1:4f:54:6d:be:6b:96:ee:21:8d:5f:13:b3:34:
         44:62:80:10:c2:de:b4:0c:87:1c:30:46:99:be:78:bd:61:48:
         72:e8:26:50:9b:66:93:1e:e8:22:13:f1:4b:ff:2d:eb:e5:9f:
         3f:88:a5:2f:dd:7b:57:b6:60:b2:06:7c:67:0b:7f:5d:ce:a7:
         1b:38:d4:a8:e4:de:c6:3d:b2:92:97:07:f7:04:6a:c5:58:97:
         52:e1:a8:8d:b5:b2:15:14:47:80:78:32:c3:05:3b:fa:2c:40:
         a2:49:72:df:65:bb:f5:ac:96:6d:18:05:da:92:8a:33:47:03:
         d1:49:88:4e:c4:d7:38:0b:a4:08:f5:ee:90:7f:61:4a:de:99:
         c1:d2:f6:86:de:88:dd:e4:80:07:d4:f8:4f:a4:3c:28:ae:03:
         17:de:46:33:49:43:43:ad:06:90:27:a6:8f:41:b7:9e:66:e8:
         6f:24:e1:2d:ba:b9:61:9d:dc:43:7c:0e:2d:f2:43:7a:54:f3:
         73:8a:a1:9f:32:dc:29:57:1e:2e:5b:9f:73:5a:82:f4:63:1d:
         eb:1d:63:10:ce:66:40:e4:29:df:d7:8a:de:67:7a:bf:9c:8d:
         d0:c7:b7:e8
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 24 (0x18)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 23 16:54:07 2006 GMT
            Not After : Jan 22 16:54:07 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-13
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:f0:45:16:66:ad:67:b6:20:f4:1a:47:72:9d:69:
                    89:cf:88:f7:d5:f7:60:04:a5:48:61:ea:84:ca:22:
                    3e:a1:4e:c8:66:7f:76:2c:8a:29:8f:57:9a:e3:40:
                    f8:92:fb:bf:15:c2:e8:78:2e:99:12:e6:56:41:8f:
                    f6:bc:bc:32:ac:08:12:75:33:73:a5:28:77:44:c7:
                    50:6f:d2:47:91:31:8d:c6:b9:6a:7b:d2:fa:a3:47:
                    2f:73:a8:ba:0d:3a:de:fd:bf:f9:ac:d6:d9:69:c0:
                    fb:a4:cd:14:43:d5:e7:d3:0e:5b:4d:33:a0:6a:af:
                    77:62:62:f4:60:09:0b:fd:e3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                A1:18:E6:0A:90:82:0F:FC:BB:D6:87:89:2C:56:C5:F7:CF:68:C7:3D
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         89:6b:41:54:8d:fc:9a:5c:91:12:6f:28:ee:fb:1d:49:92:4f:
         26:3e:a5:af:86:0a:57:ec:90:4c:30:1b:58:2d:47:61:46:6a:
         07:10:12:7b:84:7d:9b:80:1b:d7:02:12:40:2a:4d:69:2a:36:
         f0:30:f1:26:03:3b:bf:ed:93:b4:29:41:49:39:e2:3c:36:fc:
         2b:a1:b1:d2:5d:0c:b2:c1:26:bf:5b:58:33:3b:bc:cc:fd:7a:
         ae:e3:3f:46:8f:b5:f2:9f:88:91:e3:fd:b5:10:50:8d:d5:3f:
         93:29:34:ec:51:68:73:b8:a0:7b:2b:0a:45:53:55:0c:4d:5a:
         19:0b:20:9d:e3:17:7a:30:56:da:5f:32:3c:0d:f5:06:77:a6:
         df:1c:a9:6b:98:2c:a4:85:a0:c6:a9:12:a4:8c:1c:36:49:7c:
         4c:20:1e:51:6d:05:49:b7:02:39:2c:6e:41:44:35:cc:51:f8:
         59:d6:fe:07:52:99:86:d4:4c:c0:2f:67:9b:6a:0e:15:6e:a9:
         6b:69:3f:7c:b6:65:7f:0d:ca:31:a6:8c:d5:86:03:e4:50:bd:
         3a:1e:37:c3:4a:2d:74:e0:e6:a1:87:5c:24:fa:38:94:4d:81:
         c8:5e:a2:31:fd:54:f9:65:7c:cb:7f:55:f2:4c:27:e7:81:86:
         a6:5c:10:ef
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 14 (0xe)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan  9 14:00:06 2006 GMT
            Not After : Jan  8 14:00:06 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-14
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ce:cb:ba:bf:35:fb:4f:74:48:26:4b:a5:d1:c7:
                    82:60:f1:b0:bf:42:0f:1b:da:dd:93:2e:38:5b:58:
                    6e:eb:8d:d8:18:49:6b:a6:cd:5f:c9:2d:7f:96:4e:
                    8f:58:6a:02:0c:18:ee:2f:9f:f1:3c:8d:48:90:5d:
                    2f:94:fb:db:de:96:66:39:f5:e4:95:db:44:58:a4:
                    6c:1e:7b:15:b7:03:d1:7c:24:23:b2:ed:57:49:b6:
                    aa:2b:38:27:be:81:29:20:49:77:00:42:46:06:f8:
                    51:ea:4f:ac:c2:b3:2b:22:9c:ad:4c:72:20:72:56:
                    b3:eb:c2:8b:53:64:e5:c0:ab
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                07:AD:F7:C7:EA:E0:A8:72:BC:09:EA:C1:4C:8C:18:08:8C:00:DD:5E
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS%3fcertificaterevocationlist%3bbinary

    Signature Algorithm: sha1WithRSAEncryption
         ad:67:7d:bf:26:c0:79:4d:85:7d:32:ab:50:a5:d0:21:be:a2:
         82:88:15:14:29:b7:62:6a:94:a2:59:2b:96:80:17:44:64:29:
         17:34:e5:d5:ef:70:30:a0:59:ab:16:a0:7a:bf:d3:80:08:c7:
         9d:6f:e4:77:3a:da:d4:8b:33:04:31:ae:f8:c0:f7:0f:8b:ac:
         22:c2:7f:9b:d1:7c:2b:0f:56:29:db:c7:6b:72:1c:b6:4d:2b:
         fd:38:31:04:92:fb:9a:65:da:b9:97:bf:81:b9:f1:5c:54:48:
         c3:03:67:58:15:74:f4:ee:7f:23:c6:dc:94:e1:0c:46:07:78:
         15:4c:c9:ac:ad:f8:db:c4:35:d5:13:9d:c5:ac:ae:d1:72:3d:
         a1:c5:48:ff:56:89:e3:62:9c:bf:a2:71:b1:a5:ac:82:87:20:
         46:06:50:d2:74:70:9a:6c:7d:a3:f9:21:d8:5d:70:4b:83:fa:
         29:d3:8d:f0:d0:24:4a:20:6f:88:69:fd:58:47:a5:a0:5a:12:
         25:0c:62:69:05:35:65:85:35:ae:58:a2:55:c4:05:d2:34:8a:
         3d:80:3f:71:56:9e:b9:25:f4:15:3a:87:c3:1c:ce:09:a9:18:
         e5:3d:e1:40:19:07:74:c1:e1:b8:92:c2:ed:7a:6b:ca:22:3a:
         98:1c:01:57
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 27 (0x1b)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 16:38:45 2006 GMT
            Not After : Jun 14 15:38:45 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-15
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:b5:69:95:9f:a5:b6:e4:9f:3c:f3:9f:00:d5:9a:
                    15:07:fc:d6:39:ae:d9:d6:bc:56:76:c0:26:e0:3b:
                    8f:81:a9:69:66:8a:4a:2b:c2:b5:4a:62:51:5e:d7:
                    fb:7a:80:e3:41:16:9a:c3:66:f3:e1:fc:84:8a:7c:
                    87:fd:cb:bb:c8:2a:a6:bd:d6:17:73:55:19:97:90:
                    7b:44:84:fc:bf:68:6e:8a:75:6a:04:ce:48:19:d3:
                    aa:c2:b9:00:1e:64:54:88:5f:3b:e4:9b:f0:c8:47:
                    15:52:df:2b:c4:ca:65:a0:c1:6c:03:af:4b:6c:83:
                    d6:b6:e9:38:65:16:a5:10:83
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                95:B5:8C:78:AB:9D:56:33:3C:F4:48:A3:9C:58:ED:B1:64:8A:8A:9E
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         8a:f9:ad:5c:a7:17:bc:c8:4c:99:a5:2a:9f:6a:db:2c:89:ea:
         be:73:f9:93:b6:ab:04:d3:fb:64:d0:a2:c5:6a:85:c7:c8:1e:
         0f:2b:17:29:fd:a7:1a:a8:39:ea:3f:7c:a4:93:ab:bb:7d:b4:
         20:63:79:7f:01:46:24:8a:a8:a9:5e:2e:32:4c:51:86:d9:8f:
         f4:c2:5f:dc:92:d2:df:4f:93:08:c9:b9:a0:c5:72:5c:78:cb:
         96:07:6e:c9:0b:00:78:17:be:f9:e6:f9:b5:a5:88:7e:81:ed:
         47:8f:a8:8b:fe:fa:9b:45:82:2b:42:5b:f8:21:a5:55:12:d6:
         16:b4:f3:cd:6a:9b:86:d8:ac:33:25:14:0e:15:39:91:36:4c:
         c0:dd:08:b1:b8:58:76:3e:7b:83:63:1a:17:d9:46:0b:9d:43:
         f1:ce:d5:67:33:11:98:54:c2:78:51:27:54:8d:2b:37:9b:09:
         3b:3d:4a:bf:07:2a:a6:7b:14:f8:1c:e3:1e:fd:1d:d8:62:67:
         99:aa:e2:0f:cc:a6:86:cd:2a:7d:a7:7a:bd:97:13:e4:af:f7:
         f1:89:70:ed:1d:c3:27:41:b6:08:45:70:30:89:e2:d7:a2:0e:
         d6:69:dd:d5:c4:42:d5:be:b2:cb:b6:76:c1:6b:99:04:5e:be:
         99:f0:f5:ac
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 29 (0x1d)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 17:04:03 2006 GMT
            Not After : Jun 14 16:04:03 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-16
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:c3:84:bc:1d:92:3b:1b:c8:e6:c0:cb:5c:45:48:
                    83:79:f0:57:ee:e5:4b:ed:f0:5b:e7:7f:fd:a4:5b:
                    6e:e9:8c:69:12:9e:4a:0e:1f:46:34:ff:12:45:25:
                    c4:b9:6c:30:db:ff:f9:33:dd:ea:23:0e:58:67:f7:
                    4e:9f:55:c7:01:ba:86:7b:99:62:e9:b7:25:dc:3d:
                    12:1f:14:3c:dd:ca:4a:2b:59:c7:47:9f:cf:84:29:
                    20:fc:d3:29:57:9e:c8:f1:54:fa:45:9b:aa:a2:a3:
                    d1:af:1c:52:bc:71:e3:17:19:b9:d7:04:39:6b:0d:
                    93:22:20:24:25:9b:ce:24:4f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                47:93:C7:A3:23:3C:B4:31:EE:CC:42:7C:DD:68:13:CB:01:9A:8F:2D
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         06:61:84:ac:28:11:3a:f2:ae:66:cc:88:98:fa:4e:be:97:c5:
         a7:5b:23:8d:82:2d:01:27:91:30:ea:c6:22:c9:57:34:3a:87:
         f9:f8:06:5b:fa:66:6d:b1:89:ed:d3:9b:43:62:80:04:a5:2a:
         53:68:58:d4:6b:56:88:cb:6a:14:a2:4e:7d:74:1b:67:3a:8b:
         07:b5:2c:e4:a0:20:27:bf:48:67:e8:f3:e9:c9:69:9f:7f:01:
         48:61:fb:c1:27:77:7b:8f:be:ae:d2:42:d1:0c:31:24:26:9d:
         d7:1a:91:f3:8d:ac:fe:6f:93:2d:e0:1e:4f:c7:39:04:7f:71:
         1f:2e:a7:c9:e7:3f:e8:71:de:2a:b7:d0:ac:11:0b:6e:ea:8b:
         35:a3:75:95:3d:ae:67:08:17:dd:86:18:fa:48:92:1b:00:2e:
         61:17:a9:6c:54:44:69:49:20:17:2d:59:0a:9b:01:ea:43:44:
         a0:e7:57:d2:54:84:17:13:e3:4d:24:00:d8:ae:7a:20:d7:e3:
         4a:8f:37:c4:7f:bc:b1:a1:83:21:7e:73:71:37:68:91:db:45:
         e2:ff:d8:1a:ed:10:60:5a:b9:61:cc:c0:00:3c:a5:6d:cc:b9:
         9c:fe:c6:9d:c7:1a:9e:c0:70:4d:82:c1:39:f8:86:ca:c1:a0:
         0f:d0:f9:e9
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 31 (0x1f)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 17:13:18 2006 GMT
            Not After : Jun 14 16:13:18 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-17
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:c8:5c:86:36:bd:ee:cc:f1:1d:5f:c3:99:16:1c:
                    7f:e9:ca:ab:f6:d4:b4:a6:89:bd:10:ae:b7:b3:4a:
                    4d:81:19:76:b3:06:ec:c8:5f:9e:35:11:78:dd:17:
                    a8:22:12:2b:fb:27:b0:59:98:8a:1e:c5:a3:24:6e:
                    3c:8c:e2:64:b9:b0:09:0e:ab:c8:3c:c0:73:bc:fd:
                    9c:0b:70:4e:e2:73:a1:51:49:e0:a2:7b:93:b2:11:
                    b6:56:92:0b:8d:9a:c3:da:48:6a:24:04:b0:83:c5:
                    b4:c9:db:8f:e3:07:23:a0:11:1e:75:79:17:77:0f:
                    14:b8:bb:f7:4a:c7:38:44:35
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                26:24:46:AB:7C:65:55:52:4F:2C:8E:5B:37:A0:1D:F2:11:4C:8B:20
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         a8:88:05:2f:ea:ee:3f:22:62:36:a1:16:9a:9d:8a:f9:f6:a4:
         1c:aa:b2:eb:d4:94:bf:9a:85:c8:f6:aa:b9:db:23:c2:cb:95:
         c2:5e:63:89:73:d0:f6:39:15:1e:99:fd:26:cc:26:8c:51:fd:
         b8:c1:22:34:6c:06:08:62:4b:7f:1a:41:dd:c9:90:bd:da:3b:
         c1:12:02:f3:8f:f0:d2:b7:df:68:8c:ff:a5:3b:6d:f0:34:69:
         44:ae:b4:96:b1:b9:9e:2f:35:52:4c:03:ce:05:1e:be:8a:7a:
         30:65:e2:38:c2:f4:0c:eb:f5:b1:9a:5a:f8:78:9f:cc:ce:08:
         ba:55:1e:a4:0c:a1:6a:4f:38:58:06:36:0a:a8:e6:8d:85:4e:
         12:f0:01:37:62:7c:e1:2c:90:13:3a:41:66:3a:4b:e5:bc:3f:
         19:b9:6c:f9:25:6c:f0:cd:54:49:4b:af:06:e1:b1:d7:ff:cd:
         1e:4f:80:03:6c:e7:6d:9c:f6:d3:1c:2c:0d:34:1c:84:06:ce:
         66:cb:39:23:b3:7c:0b:37:83:9c:d4:fc:8b:dc:7e:51:e6:bf:
         30:45:d3:f6:6c:88:94:06:d3:77:b6:62:c1:7d:e6:5e:eb:3a:
         bb:96:2b:70:a2:50:eb:d3:63:6a:5d:15:fd:d3:63:94:39:c5:
         17:7e:54:8c
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 33 (0x21)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jun 14 17:20:29 2006 GMT
            Not After : Jun 14 16:20:29 2012 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-18
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ad:38:f4:bb:83:93:d7:9f:d5:37:9c:a5:18:25:
                    a6:60:de:63:09:fe:16:24:6e:24:ab:ea:d5:05:44:
                    75:a8:a5:58:84:b2:8a:01:a9:7b:e2:59:a2:3e:c3:
                    9f:24:9e:a1:6b:58:64:8c:f5:9f:eb:d0:76:35:22:
                    b6:da:9b:24:e9:5a:cf:8c:f5:ad:b2:e5:ce:f9:46:
                    c5:ad:44:60:e3:99:7a:4b:1d:25:29:14:ea:f3:c8:
                    e7:08:33:1c:1f:e0:81:70:12:97:05:be:64:51:c3:
                    75:b4:af:cb:0d:7f:66:ea:0b:dd:18:e8:2f:e0:84:
                    2b:27:9c:a5:d7:d7:b5:f5:21
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                C5:4D:F6:66:55:5A:49:5D:D7:3D:F5:3C:88:82:CF:06:9A:C9:10:A4
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.gds.disa.mil/getcrl?DoD%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         80:7b:ba:77:5c:c8:94:cd:71:8b:4d:9e:ba:ce:d9:33:ac:9a:
         47:15:25:d2:6e:4e:8a:3d:ba:71:8b:dc:70:35:89:3d:4c:fc:
         4f:e2:c0:17:92:07:ad:97:36:73:7a:d7:cd:c3:e6:f9:1f:d2:
         c8:cf:66:29:85:33:63:47:d4:cb:35:8d:ea:09:d5:66:f4:d7:
         eb:22:96:bb:ea:23:15:71:2f:b2:61:da:44:03:ad:f4:bd:a8:
         61:c5:45:56:5b:29:21:28:a7:e6:d5:59:1c:26:00:9f:d7:9c:
         a0:5c:6e:ce:29:c8:24:7f:2f:6a:b3:1f:4e:65:1e:9e:f8:e4:
         fa:77:2c:9d:b5:83:c0:2c:23:b7:e1:af:6c:44:a4:cb:e4:f7:
         bf:67:07:d7:0d:3e:e1:b7:c7:8f:38:c0:c4:3e:4b:81:92:c5:
         12:93:66:54:25:a5:47:08:a7:7b:9f:b5:18:cc:07:f4:35:df:
         87:96:de:3d:c9:f7:77:49:ed:19:32:a3:54:42:f6:94:d5:2a:
         06:85:d4:27:19:0a:86:61:0b:4d:04:f1:c5:f7:cc:de:3b:6d:
         5e:80:5e:1d:c9:59:cf:a4:72:c4:71:28:1e:ce:3b:b3:42:db:
         ab:a5:10:e1:8b:97:db:e3:21:fc:8a:df:a8:7c:8e:a4:b5:7e:
         46:d1:83:b8
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 41 (0x29)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Apr 23 21:03:06 2008 GMT
            Not After : Apr 23 20:03:06 2014 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-19
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:aa:b9:a7:5e:06:10:a6:33:d6:4b:4b:a3:a7:d3:
                    6c:2d:79:f9:d7:1c:78:7c:da:3c:3c:2d:5b:26:73:
                    41:16:4d:64:29:fa:6d:2f:f5:15:0b:48:51:0e:06:
                    cc:f4:e4:8b:c9:29:51:f7:3f:bc:27:77:fa:95:ea:
                    92:24:f3:b0:a7:0e:d4:69:af:f2:b9:37:87:a0:fc:
                    27:88:1a:20:e5:e0:4b:4f:f2:81:55:02:14:7f:4d:
                    3b:a4:e1:ed:a0:a2:54:b9:e2:14:08:01:f4:5c:5c:
                    88:77:5f:5c:46:42:a4:7c:1c:54:73:17:44:96:ea:
                    d8:53:54:ff:bf:c7:7d:b7:69:79:72:a3:64:d5:fe:
                    e8:e1:84:80:b3:1a:c2:48:9e:4d:cf:bd:97:3c:c0:
                    81:55:28:c3:48:64:49:30:80:11:21:a4:ea:d5:5e:
                    5f:58:89:b4:57:ee:c6:9b:f5:83:6b:58:97:db:9b:
                    ab:7d:e0:37:be:bd:68:d8:dd:48:22:96:ff:78:b6:
                    7b:de:9f:72:e6:71:74:82:3a:b5:0c:fe:2c:9d:fd:
                    ed:2a:66:b2:34:df:a1:ca:2c:20:bb:9d:24:4b:ef:
                    95:95:bc:28:9c:c2:57:9b:11:82:f5:9d:a7:4c:dd:
                    a9:f2:13:c1:af:02:1c:e9:17:56:16:f0:ae:a8:6e:
                    0b:1b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                03:6D:7D:B9:C0:41:EF:F6:47:AF:24:1D:3B:98:1C:74:0E:8C:64:DB
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         6e:59:06:8b:ee:6b:91:ff:97:b7:af:5e:fa:c0:b2:02:80:5e:
         ab:43:0d:b6:65:15:4b:7e:ae:56:90:31:57:58:fc:57:c1:8e:
         29:8f:ac:70:30:9a:51:3a:61:75:16:18:fd:76:ec:9f:00:08:
         98:ff:64:a2:60:f7:9e:5d:d0:db:f2:90:18:85:b4:c9:b1:07:
         4a:67:72:ed:ed:e4:0b:bc:db:bf:22:e2:07:cc:4d:b8:7e:4a:
         c1:cb:89:e4:8d:04:78:af:21:9e:c1:68:ea:9b:9b:a5:c7:8d:
         f5:32:ac:d8:0a:8c:7a:d0:72:3e:20:67:10:39:ba:89:23:a7:
         d4:99:a5:68:4e:84:05:e9:21:10:7c:e3:b1:92:59:05:7a:e8:
         84:8e:5e:d7:6a:d4:f9:7b:25:c6:42:78:bc:8d:b2:8b:54:ad:
         d1:b7:bb:c1:4d:36:a1:68:67:f7:11:0e:f9:ae:75:23:37:ac:
         e8:b3:cc:4a:2d:b7:66:18:73:63:4d:9c:f0:f8:e1:97:36:cd:
         26:1c:59:08:50:b3:e5:03:71:75:80:5c:1c:12:3b:4d:e2:57:
         28:64:ba:57:6d:b7:d3:51:96:a8:00:0e:f1:7a:0b:c9:f7:2f:
         c2:7c:d0:c3:34:be:ff:35:f8:8b:02:07:eb:50:02:29:6b:8a:
         74:49:97:25
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 43 (0x2b)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Apr 23 21:08:56 2008 GMT
            Not After : Apr 23 20:08:56 2014 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-20
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:b7:1a:90:89:1c:80:0b:db:a1:ba:25:ec:2e:a3:
                    f6:2d:01:88:55:e6:16:d1:4f:9d:c9:53:9c:a6:29:
                    f9:88:41:f1:dd:9d:32:26:9f:07:33:21:b6:47:41:
                    02:20:3c:a5:d2:4a:cb:bb:cb:81:4f:61:41:d0:f6:
                    c8:ee:68:a6:c6:f7:78:7a:b4:2c:50:1d:fe:8b:32:
                    b6:5a:32:79:91:30:51:f0:21:4a:98:a9:12:d3:2e:
                    74:99:4f:e6:fa:d5:b8:27:88:f8:c9:21:a0:c5:b3:
                    7d:b7:56:aa:7b:97:43:9c:20:34:4e:81:89:3a:8e:
                    3c:16:12:8c:bb:a8:b3:8c:60:d7:79:bc:ef:e1:2b:
                    b4:7c:91:04:27:8e:73:4e:48:34:02:e5:fb:ae:b4:
                    ce:83:9d:d8:95:e4:14:f8:33:df:36:ac:4e:f8:e9:
                    52:39:d7:56:e4:32:c2:4d:6e:48:37:6f:f5:e5:46:
                    37:12:63:32:49:c2:4f:8b:fe:34:99:c8:ec:f8:e6:
                    df:ae:86:a0:7f:3d:48:20:63:a4:49:2d:41:3e:fe:
                    9d:42:7c:81:46:e6:1d:92:e3:74:d2:02:08:54:88:
                    60:2b:65:31:a9:73:80:fa:97:f8:6a:36:d4:83:2b:
                    64:f0:cd:61:61:e1:c2:58:94:b6:ca:e2:31:b2:d9:
                    1a:61
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                B2:BF:6E:00:6D:B9:40:49:2F:60:0A:F4:78:D5:79:84:25:A9:31:BA
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         6d:05:65:3f:c1:d9:d5:f1:b2:06:d6:08:cd:8e:e5:8b:a0:e6:
         46:02:7d:a5:a6:64:9b:2f:13:12:b4:01:98:a1:f5:8c:3a:81:
         4b:05:23:a6:ed:cd:eb:b0:05:2b:44:31:4e:04:d7:6d:43:1d:
         da:29:51:ab:f9:c1:af:96:74:e1:68:1e:48:4f:4e:5c:bc:ca:
         b0:24:43:a2:ec:40:2b:11:02:db:08:23:5c:95:bc:35:76:35:
         d0:62:b1:76:f2:d9:39:ff:c0:b5:d8:a8:db:ae:a1:69:fa:a5:
         fe:5d:f4:3e:05:b5:0c:85:f7:cc:3e:d0:c2:b0:44:5b:09:c3:
         e6:83:5c:ce:2e:4b:75:28:a9:f8:ed:58:2c:96:4b:9d:26:06:
         bd:76:86:8d:37:24:24:54:1d:cf:cc:17:51:08:f0:86:92:7c:
         47:bf:b7:ed:fb:38:5d:14:6e:2e:ea:53:d3:aa:e1:ae:fb:26:
         90:f4:fa:f4:ef:59:6b:75:6f:2f:28:59:9b:1f:1e:be:d7:9d:
         de:ae:55:5d:2b:14:9f:16:9a:0b:70:86:f3:91:42:d3:23:68:
         a2:f2:bf:36:37:af:14:ba:80:6f:61:47:32:be:87:4c:77:79:
         6e:a8:59:cc:c4:17:14:39:23:bd:ae:21:9c:fd:b9:ba:f8:73:
         dc:e0:a7:1a
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 74 (0x4a)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 16:41:13 2009 GMT
            Not After : Jan 25 16:41:13 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-21
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:9a:ed:08:dc:23:a0:44:47:9b:f5:c3:9e:c9:3b:
                    d8:6e:cf:eb:f9:c6:83:62:7a:0c:83:f9:8f:38:7e:
                    82:c0:8d:9c:d1:42:2c:cb:88:0e:62:51:22:a9:80:
                    17:58:41:7a:0c:46:9b:3e:25:a8:6a:28:a9:bb:12:
                    fd:fc:85:2b:ef:b3:5b:31:4f:ca:15:c5:d3:b7:98:
                    45:66:05:72:f6:09:9a:72:e9:26:ff:bd:90:26:35:
                    0a:25:bd:bb:ac:bf:d0:d6:38:87:79:61:2c:7b:d1:
                    0e:d3:2a:f5:12:3f:40:e4:98:73:68:c2:49:ac:8f:
                    d4:8c:0a:17:af:3e:4a:44:a9:3f:39:0d:69:bb:16:
                    0d:86:8e:0e:e9:be:53:76:79:83:1f:5d:6e:8a:e7:
                    71:d6:45:c1:a4:cf:32:72:48:e0:e7:10:f9:b1:0b:
                    b5:f3:74:f0:64:1a:13:40:94:d2:13:6d:b2:09:21:
                    57:e1:dd:a9:07:57:a6:bd:c0:a4:84:57:be:b9:1d:
                    51:49:1f:7c:5b:c6:e6:d2:23:fd:36:55:57:88:c8:
                    79:45:db:63:cf:4b:6a:3b:31:ec:b5:3d:5d:67:bc:
                    b2:57:a5:2d:d5:ed:fc:4c:d8:3b:87:d1:47:73:18:
                    74:6f:70:53:42:86:6e:2f:c0:78:16:c1:b9:b6:32:
                    87:25
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                51:67:84:1C:FF:AB:A7:B1:9D:1D:84:64:84:99:5D:D0:0B:D7:BD:5B
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         72:c4:71:17:4e:53:41:ca:ee:fa:93:c5:34:12:fa:44:15:da:
         e0:63:49:d6:b2:1b:5e:a3:9e:1f:21:6f:78:a2:0f:0a:c2:da:
         d4:ba:66:c7:22:6c:93:4d:09:4b:29:67:14:8d:99:0e:05:06:
         f7:ad:dc:47:dc:0e:99:08:0a:2e:f2:09:97:e8:f5:21:85:ce:
         f2:0d:34:ff:9a:43:5f:93:76:4a:a3:0c:d8:2a:21:8b:0d:60:
         4e:76:1e:ad:0a:ef:13:bb:34:2e:0c:15:56:3b:b6:31:7b:36:
         9f:39:88:8b:cb:48:b3:d9:04:4f:9f:11:58:e5:d9:ad:99:c0:
         12:28:23:98:70:fa:9d:48:03:6b:bc:a0:d8:4e:3d:b6:91:a9:
         a2:88:68:86:c2:b1:48:13:52:d8:c0:80:90:f8:6c:e8:21:21:
         27:e3:7a:3e:d1:b2:9c:64:9e:18:82:68:30:57:84:07:b1:75:
         5a:99:38:92:29:6b:fd:1b:31:06:b7:97:fa:e5:eb:3a:82:64:
         d5:4e:79:b7:76:07:b7:34:6e:a6:49:ca:42:c6:22:3b:83:b0:
         a4:38:db:34:a6:b0:95:24:1f:cb:f1:1f:b6:c0:ff:7b:a6:dc:
         0f:f8:fd:25:b6:b2:32:d6:76:99:24:4b:77:ea:fd:2d:c4:61:
         b9:b1:ff:2e
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 70 (0x46)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 20:25:07 2009 GMT
            Not After : Jan 25 20:25:07 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-22
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a6:00:06:25:23:80:f9:f5:60:c4:06:06:28:05:
                    47:2e:1b:67:1f:be:b4:45:e5:1c:34:c6:f4:c5:ba:
                    d2:4c:68:9d:53:24:d7:97:bf:d8:e8:07:cf:78:ce:
                    9a:e8:64:c5:10:79:d3:6f:c7:1d:33:9b:88:c3:00:
                    f1:f0:29:f8:53:fd:e0:a5:31:28:68:c9:2e:8c:38:
                    07:92:45:b4:3f:08:02:cb:f7:ee:01:81:2d:5f:4b:
                    15:b1:dd:80:f2:b9:c0:ff:a9:ed:a0:f5:27:9b:79:
                    ec:7b:25:2b:25:11:29:ab:fd:5f:11:3c:62:93:97:
                    42:79:48:c0:9d:06:d1:b7:23:25:99:57:de:06:55:
                    ca:1e:87:93:14:f7:12:43:31:d1:26:0e:6d:d2:45:
                    4c:38:e2:d2:9a:e7:12:af:c9:4c:5d:e3:c8:7f:1f:
                    c7:ca:09:39:f1:09:4f:c6:a2:e7:61:81:79:99:0b:
                    d2:8c:0b:65:7a:b9:3c:18:15:ce:10:bb:2f:c0:64:
                    1a:32:08:d1:b0:a0:12:8c:10:cb:b3:6c:a4:70:40:
                    ac:bd:56:0b:54:a5:d4:f1:46:33:dc:ec:f6:51:52:
                    af:27:27:2e:9d:55:a4:1d:f7:5d:5a:f8:64:68:41:
                    89:58:bd:2f:77:9d:28:de:0d:78:5f:88:67:fc:1c:
                    bc:b1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                85:2F:0D:0A:AF:35:08:50:09:8D:9B:1C:70:AC:A8:FE:89:77:94:5A
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         38:54:f5:4b:89:31:e3:f3:f5:17:17:a5:74:9f:cb:3f:89:53:
         ef:41:ea:57:51:c5:e4:e2:ce:ba:fa:40:1f:98:4c:6e:43:6b:
         2d:cf:c0:19:6e:f4:17:47:dd:96:90:46:a6:73:2f:ed:f1:27:
         78:87:4f:b7:ed:01:34:6e:79:68:bf:85:c9:5c:65:6c:b9:7b:
         98:2a:8a:9e:5d:61:40:26:bc:e4:87:35:9f:03:ea:ce:c9:79:
         0c:06:7e:68:de:9d:55:c3:d1:0a:08:7f:d8:e6:e7:3a:83:56:
         97:e3:e1:c3:b2:6f:3b:44:76:b8:73:6c:ea:f0:c7:20:4c:8f:
         31:55:80:86:5d:1e:e6:39:44:99:8e:34:a1:69:f9:6d:5f:72:
         0e:05:47:69:9a:08:ec:65:d9:29:80:9f:e0:af:7e:01:03:b8:
         0b:e9:13:f7:58:21:d6:30:fe:a0:ee:72:7b:81:79:81:0d:95:
         60:84:3d:ca:48:b6:0c:7b:89:73:5f:98:5d:7b:1e:0f:69:aa:
         04:26:7c:6a:91:70:fd:f3:62:d8:50:4f:79:76:ba:69:56:fa:
         be:6e:bb:8c:57:6f:b1:c7:fe:2e:df:85:65:c2:b2:17:14:19:
         1c:16:13:fd:7e:1d:6f:b2:27:d6:13:1c:0c:59:90:70:bd:56:
         bc:ae:02:86
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 73 (0x49)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 16:43:25 2009 GMT
            Not After : Jan 25 16:43:25 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-23
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:bd:f4:29:4d:57:93:44:03:07:8d:06:1f:ae:fa:
                    3c:34:56:34:40:e7:b1:18:7f:6c:25:6e:17:85:05:
                    05:23:e9:f6:c5:50:25:4f:81:e4:23:30:42:71:69:
                    ea:f7:b8:9e:f7:6f:ac:de:5d:aa:fc:d6:e0:8d:bc:
                    6b:ee:7d:99:95:22:3b:b3:58:c6:b1:52:1c:b2:a8:
                    bf:31:40:22:06:fe:8d:28:d2:a9:50:55:6a:1e:07:
                    70:f8:a6:48:c9:6d:fd:ae:ec:be:80:6c:3d:cf:90:
                    d4:07:a2:4e:91:14:03:bf:57:59:12:f5:74:de:43:
                    96:5a:5a:b9:cf:b9:47:e8:7f:d0:8e:b0:f8:d8:e9:
                    4b:34:5e:cc:4b:17:8e:02:f0:12:bf:f2:04:6c:1d:
                    13:bf:ab:1c:de:0d:09:ec:cb:9b:56:ed:d9:90:e7:
                    96:a5:7f:26:65:61:c1:c4:9b:68:24:a5:cd:d2:79:
                    23:6f:c3:3c:c1:85:1e:48:f9:3e:50:71:62:a0:41:
                    ba:72:44:a5:43:e3:a5:72:6e:cd:ce:ab:da:cb:84:
                    d2:1a:bf:1f:6e:72:11:3f:2d:99:1f:6d:b0:fb:05:
                    30:ce:e6:ec:23:2a:65:47:1f:78:9c:0d:9f:4c:24:
                    75:6c:76:d2:d5:3b:17:44:16:b2:8a:28:48:d7:b9:
                    0d:af
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                5B:96:2D:31:A5:E1:F6:9A:6A:5C:5E:81:51:36:61:1E:96:24:19:D1
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         3e:f6:f6:e4:0f:d4:57:cd:be:ed:e9:c4:45:52:da:45:5b:18:
         a6:36:39:30:0a:b6:7e:eb:f6:89:fc:a7:62:2e:b3:3f:83:7d:
         e1:12:1a:86:d3:63:94:f4:74:f4:ce:71:97:ea:fb:c4:6a:3a:
         5d:e2:99:a7:ac:c3:e2:36:f8:e8:78:f4:d8:c4:50:ee:8a:81:
         55:fa:8a:83:65:0c:c5:f2:4d:cc:e9:1f:8f:7b:46:dd:03:0a:
         9c:ea:e2:ac:63:77:07:cb:32:54:db:08:55:b2:58:00:7d:5c:
         a6:b9:16:3c:5f:65:6d:2f:05:ce:5a:3f:9a:db:49:cb:92:a3:
         a1:d9:6f:51:d4:f5:c0:08:c1:a3:39:5b:d0:41:63:81:c4:94:
         65:64:63:29:4c:5d:f0:5f:71:87:6a:9d:96:92:e5:c7:82:fd:
         2d:74:d7:02:6c:ca:e2:db:a0:b3:db:71:d5:0e:86:3e:3e:17:
         89:bd:6e:42:17:1b:b4:f6:39:f9:1a:bd:e6:2e:2c:9b:0e:37:
         3b:10:5f:44:fe:7b:b5:94:58:d6:71:25:e5:39:d1:23:ba:34:
         00:c1:43:6d:b8:f4:0e:97:ab:b2:30:f6:88:a7:8e:8e:8a:10:
         03:84:74:dc:ae:4d:f9:e5:99:74:1a:a9:a2:0a:6d:0b:07:15:
         94:c5:3f:63
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 69 (0x45)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 26 20:26:15 2009 GMT
            Not After : Jan 25 20:26:15 2015 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-24
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a5:2e:58:7a:a1:de:e6:9a:5b:f6:02:f1:d5:d4:
                    dc:35:23:9a:7b:6e:28:64:74:1a:70:3c:96:1d:cc:
                    c2:9f:74:04:3c:0c:39:92:21:08:0d:12:4e:a0:d7:
                    37:a8:d2:c9:c6:27:9d:28:fa:55:d7:b2:17:04:19:
                    ce:32:bc:f0:79:9e:f5:68:ab:2e:cc:cf:37:04:b2:
                    f8:0a:65:9a:49:20:14:25:c1:bc:12:6a:a0:42:6d:
                    1b:08:b4:87:a1:42:22:ab:13:99:da:02:01:39:1f:
                    5e:08:57:6b:60:de:13:7e:68:6a:7e:41:f5:89:80:
                    38:7a:fd:97:b2:d2:e2:96:4b:36:80:62:b6:ec:25:
                    bb:d0:0f:a7:a3:cd:51:a8:f7:d2:79:55:90:34:26:
                    a3:e4:5c:cd:bb:68:26:74:09:37:a1:e6:af:cd:e4:
                    3e:99:47:ff:7f:c2:47:bc:65:84:ba:32:29:a3:0e:
                    f0:c2:a2:5b:7a:ea:b2:4a:7d:0b:c6:c3:6e:ac:bd:
                    10:7f:4f:a9:76:3a:3d:02:01:2c:2a:30:b4:f7:c8:
                    a0:d2:98:3a:7c:08:d0:5a:89:0f:b5:8a:82:fa:0d:
                    30:1e:7e:d6:d1:c7:b6:43:27:b1:28:a9:0c:e3:b3:
                    07:78:df:62:64:9a:45:8c:4e:cd:af:0e:ae:9c:58:
                    36:df
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                54:AA:73:2A:C7:B3:77:EA:CD:22:40:79:48:7B:11:FB:A7:99:22:82
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         72:16:dc:39:73:63:4d:93:e9:37:1c:cf:b2:ed:9c:d8:4d:f7:
         0c:32:4a:89:9e:b3:ca:ba:f3:04:ac:71:66:31:a6:2a:bd:ba:
         7d:54:d8:2f:09:63:4a:88:08:e8:6c:13:a1:ec:5e:7b:56:17:
         30:2d:c8:d2:ed:d7:8d:47:44:69:cf:11:6f:cb:d8:e7:52:75:
         b5:51:c8:aa:1d:69:f0:19:1f:30:f0:07:c7:36:bd:ce:0c:de:
         3b:76:fd:0a:ce:cb:b6:13:ba:d6:85:8b:f1:5c:12:91:ca:af:
         e8:7f:12:a8:ac:2d:8b:d6:76:50:94:ec:36:fa:a3:0f:df:c6:
         32:ea:c7:73:46:fc:84:1a:9a:2f:c4:e8:27:1c:48:c2:46:36:
         f6:17:ec:ed:67:32:0f:b8:a2:e0:b7:d2:5e:90:06:13:94:21:
         61:43:6c:7d:f3:3b:6b:65:ed:e3:db:a8:ff:c5:9b:b2:92:e7:
         eb:5f:ee:ef:bf:f3:39:8c:b3:f5:17:d2:86:d5:c3:6c:4a:3a:
         6c:3f:9e:af:e8:5b:1d:36:5b:a6:26:15:46:0b:46:6b:c7:d4:
         80:aa:e7:ae:1c:b8:2b:4e:fa:21:72:9f:5f:9f:81:af:b4:ee:
         5b:c9:97:29:89:7c:e9:dc:78:e2:4e:e0:74:9f:d2:86:78:66:
         a2:c7:98:a8
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 79 (0x4f)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 14 17:36:32 2010 GMT
            Not After : Jan 14 17:36:32 2016 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-25
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a2:47:73:df:40:a0:15:a6:a7:ed:a0:e9:c8:7f:
                    fb:d2:8e:4f:09:e5:c5:8d:5c:64:1a:43:7e:e1:73:
                    b9:af:10:45:7d:33:2d:ea:60:26:73:62:21:8b:2f:
                    ae:9c:17:cc:d5:e6:38:a1:2d:ee:02:b3:f0:b9:de:
                    a6:8b:88:d1:b4:63:3d:c8:88:88:1c:7f:5e:42:eb:
                    1d:93:f3:ab:78:e9:94:1d:03:3d:4d:3e:19:17:7c:
                    ef:09:22:82:fe:c3:e4:9f:9e:cd:d9:bd:82:84:39:
                    0c:52:b7:7d:bb:41:7f:f5:8d:a4:2a:f6:d0:5c:62:
                    31:c8:e3:ea:b7:b7:78:d6:9b:4e:62:5e:b5:12:db:
                    ca:74:5d:b8:6a:11:43:49:15:83:b9:69:63:8f:4d:
                    62:c2:f2:04:77:59:04:ab:05:ce:ac:14:5e:99:7d:
                    1f:4e:8b:d4:c9:a2:97:ba:ce:d0:9c:e3:9d:36:fe:
                    8c:81:fc:68:39:4d:9e:23:e2:83:b3:d3:ab:e0:d9:
                    df:99:64:0a:c8:34:f2:ac:e2:f5:50:9e:5e:6d:d1:
                    0f:45:b2:52:eb:4e:92:6f:1f:69:c8:a1:37:18:6d:
                    61:c8:86:aa:cf:c4:b7:cc:37:49:fa:7c:1b:66:72:
                    81:4a:46:8c:41:4a:ab:20:0a:76:f7:ce:12:d4:d0:
                    06:55
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                26:DB:EB:B1:45:2E:D8:12:90:4D:F5:12:41:F5:C3:F0:1E:CC:E0:CE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         69:90:0d:6e:22:e9:bb:05:b6:e6:cf:38:24:a8:90:33:79:9a:
         e2:d9:60:11:22:d5:ec:28:47:90:20:37:e2:84:84:b2:68:f6:
         7d:fe:8b:4b:11:b9:1d:bf:db:cc:dc:e9:72:7e:46:c9:8c:48:
         a9:36:86:60:90:99:da:f8:58:db:72:d0:a9:8e:6e:60:c8:bc:
         60:eb:04:d0:0e:f8:71:85:e7:5b:e9:c1:fb:ec:92:95:aa:03:
         69:fd:c8:34:05:65:d5:02:4f:4f:99:83:1a:c8:46:5c:3b:fe:
         f8:71:d8:7c:3b:3d:5c:d1:cd:82:4c:43:8d:f5:1a:a6:a8:2f:
         4b:02:74:d7:28:d6:91:46:d0:4d:63:8d:ad:f4:94:88:98:23:
         23:8b:b6:ed:8e:40:4e:86:f4:d9:e9:d1:36:4a:d4:53:c0:4b:
         96:f0:b1:b8:6e:40:9c:6a:32:7c:65:6d:b6:60:ed:81:4a:50:
         57:53:63:66:e8:77:c7:79:dc:77:23:0b:3d:63:4a:6d:bb:e8:
         4f:43:24:cf:6d:98:5c:11:e8:2f:88:a5:3a:e5:4e:c4:d8:d0:
         fe:9c:98:e4:32:ad:8e:27:14:55:ab:da:c8:b7:76:42:fb:59:
         18:92:b8:0a:2b:9a:66:cc:30:fb:c4:63:6a:26:b7:b7:91:1d:
         18:a2:3e:9c
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 81 (0x51)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Jan 14 17:39:27 2010 GMT
            Not After : Jan 14 17:39:27 2016 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-26
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:ac:5f:10:5b:3d:2a:07:fd:ee:cf:4e:c6:b0:4e:
                    3d:5a:a0:00:60:50:79:c2:02:45:66:4f:38:34:81:
                    5c:1c:bf:27:60:6a:79:cc:a6:97:0b:d6:89:e6:d8:
                    db:95:7c:57:3a:07:ee:46:e5:64:2a:13:17:8f:1d:
                    30:fc:2d:fa:36:7f:37:61:24:e5:14:a2:fd:22:57:
                    1c:61:ae:4d:2e:03:50:66:55:46:dd:6a:27:f8:a9:
                    79:ab:5c:2a:e5:25:5d:5c:1b:fb:71:0f:b5:b8:15:
                    8f:5f:94:7b:03:cf:ee:ab:92:08:0a:e4:bd:a3:a1:
                    5d:83:d7:3d:c7:9f:d4:44:10:3a:a2:5f:5f:e4:86:
                    94:6f:03:a0:35:f3:83:d8:e1:b8:19:9f:7a:ba:75:
                    cf:00:05:d0:db:23:a4:6a:25:d7:69:70:45:c6:5d:
                    78:8b:07:5f:45:ac:9d:d6:a3:4b:5d:18:cf:8f:4c:
                    0a:11:a1:d9:11:db:f9:9c:a5:d5:8f:9c:ea:0f:47:
                    bd:25:82:94:f9:60:92:4a:14:f8:ba:9b:a9:6c:df:
                    ca:15:11:a1:8b:39:be:fa:19:4d:bc:bb:14:6f:dd:
                    60:7d:b2:9c:90:07:7c:80:47:b9:85:8c:b8:3e:a3:
                    75:b9:ae:5e:77:91:73:c1:75:89:55:ba:4d:86:e4:
                    ad:bb
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                32:DF:C8:6D:F3:FF:3E:29:FD:E9:0C:97:29:50:F0:A2:10:2C:6E:2F
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         6a:c0:50:29:84:f8:dc:67:13:b1:96:ee:ba:5c:d4:e5:92:f9:
         cd:64:65:33:85:28:0b:a0:1a:ab:53:1d:8c:40:17:91:ba:66:
         da:6b:6b:bc:ac:8e:61:01:c3:67:35:11:59:52:85:70:5d:a1:
         86:e7:7a:c1:1c:c3:d8:5e:cb:77:bb:cc:5c:dc:1a:dd:04:5f:
         fa:88:ed:b3:6e:b5:b4:44:cb:3a:35:9d:a0:4e:1c:c0:45:b5:
         f6:d4:cd:06:79:d2:1a:39:ec:25:26:71:9c:d9:b8:6f:93:6c:
         d6:3b:34:3b:67:99:aa:5f:a5:b8:6d:4c:c7:09:ea:c9:c0:74:
         99:d9:59:8b:29:89:90:2b:81:95:d9:87:fd:55:f8:58:75:52:
         a6:7f:22:68:6d:85:d6:7d:ae:8a:0d:2f:34:bf:d7:28:6c:c6:
         5b:ad:bc:ff:1b:3a:c6:64:85:a4:9c:7d:84:95:9f:a8:03:65:
         e4:7f:4d:cc:0c:75:7a:4a:05:44:58:80:8b:39:34:4f:33:3f:
         2b:44:f1:d6:74:ef:ef:7c:9a:d8:dc:0b:18:3d:f2:e5:9d:50:
         3b:23:29:e5:f4:cf:60:ea:60:4f:1c:60:c1:1a:b2:9c:5a:02:
         04:b0:7c:c1:c9:15:6a:db:2a:af:0b:08:bb:3e:71:7a:a6:3c:
         e5:1d:44:22
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 438 (0x1b6)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 16:00:18 2011 GMT
            Not After : Sep  8 16:00:18 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-27
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d3:9d:c2:07:b0:f5:7e:cc:ee:ae:b8:ab:aa:33:
                    ea:a7:92:6e:13:56:40:68:e5:1f:c6:21:bc:c0:81:
                    97:61:2c:70:d1:5a:15:17:fe:9c:a3:ef:48:69:89:
                    b7:5b:52:f9:ac:e0:3a:9c:a6:43:56:20:28:82:6c:
                    cd:f5:96:fe:80:9d:d9:8d:f1:d1:ee:81:9a:bc:ec:
                    f0:85:35:16:41:b9:26:89:0c:26:7a:40:6e:d0:09:
                    80:51:c0:02:d8:ee:84:6f:cc:2c:82:22:aa:35:85:
                    5e:a4:5e:85:04:d1:09:99:a4:b8:7d:52:b1:21:7a:
                    4d:d8:21:a7:bc:44:4f:ca:15:a2:8c:31:2e:89:d6:
                    39:2f:40:56:37:78:eb:2e:5d:2e:d1:18:47:16:ed:
                    ac:a0:84:d4:0b:82:98:bd:03:18:70:b0:19:5d:8c:
                    6b:de:35:24:62:5a:c8:fb:0f:ba:7a:ec:c8:40:49:
                    72:56:9e:1a:4d:54:c0:4e:e5:10:34:4f:61:d1:d2:
                    ed:4d:df:d1:59:b0:eb:02:42:2f:0c:1b:52:0c:15:
                    a0:f2:ee:ba:36:57:fb:cc:ac:11:f1:9a:2d:4c:8b:
                    29:18:f1:f0:70:92:68:d6:41:26:cc:5b:7c:75:76:
                    d8:05:60:52:d3:09:fc:ad:c0:40:1c:a4:46:d6:30:
                    2d:7b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                BF:C8:ED:44:0E:BB:33:E6:C7:CA:41:2C:A5:31:B9:C9:60:61:89:2E
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         11:7d:f2:4e:5d:a8:d6:46:1a:e7:d9:d4:66:b1:51:c6:81:e0:
         e6:7f:3d:71:ae:46:a7:70:0b:83:b4:bd:c0:40:33:50:9b:87:
         43:94:87:05:69:74:be:67:6d:dd:2a:ec:0a:31:04:bf:78:95:
         6f:d8:b1:ec:43:27:0a:cf:00:80:01:16:3c:7d:97:37:85:98:
         5b:a6:80:73:0c:b3:77:fe:c9:70:33:52:8b:7a:75:b7:b9:2e:
         fe:bc:2d:25:46:96:fa:45:6d:78:28:cd:db:9b:99:4c:07:9e:
         2c:62:0d:8a:db:7f:78:55:05:47:12:1b:db:99:02:37:f9:67:
         1f:04:31:ef:28:81:77:76:5a:2e:94:8b:75:78:3d:89:cc:78:
         d0:4b:05:98:a2:c0:70:16:87:70:ff:8b:7c:09:d2:e1:2d:32:
         ed:03:ed:61:2b:8d:da:ce:cd:d2:3c:e3:e6:8f:f6:71:e3:ba:
         2f:5c:84:82:6e:88:a6:5d:3a:ab:c1:6d:fe:67:f9:e9:ab:e5:
         38:44:ef:43:1b:e5:2a:b1:30:fb:f4:fb:6f:7d:a4:20:00:54:
         60:22:3e:5d:33:64:bb:94:ea:5a:76:95:9f:c8:8f:06:6b:3a:
         60:e8:c2:46:26:53:ab:ba:e6:28:cb:f9:5b:8e:bd:43:ad:f1:
         c7:68:32:be
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 439 (0x1b7)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 16:01:19 2011 GMT
            Not After : Sep  8 16:01:19 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-28
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a0:be:92:ce:0a:98:d3:08:e1:c5:f7:ee:5d:82:
                    4a:db:cf:ca:66:f4:bd:70:6e:93:1b:ca:9b:39:01:
                    50:18:c0:d3:56:7a:cb:58:67:dd:05:a4:d4:2b:31:
                    41:62:7a:0a:fd:c2:fb:1e:85:2c:8a:f9:eb:a9:b3:
                    9f:b3:ca:5a:a4:78:56:55:17:41:97:89:f5:cd:c7:
                    30:c6:de:c8:a5:16:ea:d8:e0:86:28:11:0c:78:0d:
                    9d:37:ee:18:f9:16:2d:5f:ae:84:6e:34:8b:ba:46:
                    3b:f4:3d:7a:a3:3f:e3:ae:9b:a9:87:76:7d:c3:b7:
                    e0:b2:2d:82:3a:41:7f:b9:69:e1:50:22:b1:bf:4c:
                    51:6a:4a:f9:03:0e:14:b7:32:a9:5f:8d:1b:ef:51:
                    57:bc:87:29:5b:65:26:3f:f9:f3:a1:92:38:a8:d9:
                    31:c7:18:11:b7:eb:8a:18:d3:90:a5:cd:09:b2:b5:
                    2c:ef:09:69:9e:c8:a5:d7:62:22:0f:da:85:e0:1a:
                    a3:34:b4:18:8c:a9:75:49:c6:c7:6e:84:8d:a9:a4:
                    90:5f:ad:5b:ae:13:97:5d:a9:5f:60:0f:dc:c4:91:
                    92:36:03:7b:fd:69:59:c9:d6:fa:e7:dc:e0:fe:5a:
                    3d:5c:3f:f4:3f:00:1b:58:5f:d3:09:47:ef:50:72:
                    c8:31
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                59:88:30:48:E6:6D:FE:61:27:A6:C4:D5:85:8D:5B:73:9E:EF:C1:CD
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         1d:6b:de:17:1c:3a:e9:7d:2a:64:7d:74:03:20:76:64:4d:9f:
         a0:1e:d9:5b:45:4a:77:31:cc:65:2b:5a:e9:b6:5f:5e:ee:36:
         88:10:14:db:b7:7c:00:4c:b1:6d:39:09:19:78:8c:32:69:77:
         aa:64:9e:7c:71:d7:49:b1:2c:a0:df:27:31:52:2a:99:82:f4:
         d6:53:46:4a:cc:c0:f3:be:98:1f:60:13:8b:e2:8a:07:64:7e:
         85:4c:b1:09:b1:e9:58:8a:cd:99:7e:12:c2:93:4b:d7:f5:a4:
         14:3e:c4:7b:08:30:43:c8:26:7e:17:f6:53:49:bf:6a:ee:b6:
         03:92:c3:00:04:c9:49:07:89:f0:41:ad:d7:df:cc:d7:f3:26:
         84:62:50:b2:14:36:ca:0b:06:3a:29:80:f9:83:ab:a5:44:86:
         e2:81:2c:ed:20:03:4b:44:af:0f:98:41:54:c5:c0:18:87:21:
         cb:d5:83:4c:66:91:7b:16:13:57:91:97:74:92:bd:01:95:28:
         7b:4e:e2:da:d6:56:20:36:d2:cb:46:7d:74:ca:8a:e3:f9:d6:
         c0:42:27:49:03:ce:3f:05:0f:aa:d8:a5:bf:33:2e:16:0f:ae:
         1d:b1:ff:c9:4b:d8:71:6b:93:c5:a1:ff:6a:3b:55:5e:19:37:
         5e:5b:23:c9
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 440 (0x1b8)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 16:02:14 2011 GMT
            Not After : Sep  8 16:02:14 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-29
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:92:62:2f:41:c2:20:00:16:06:55:64:9f:bd:a7:
                    88:15:6e:82:9b:48:c1:85:77:bd:02:ab:0c:d9:f1:
                    2b:60:81:01:ba:3e:75:70:8e:12:a6:a7:38:84:90:
                    b3:e9:40:80:12:dc:6a:ca:51:cd:ad:2d:86:10:cc:
                    44:bc:0e:c5:58:38:19:b2:14:32:25:41:54:58:5c:
                    43:0e:c8:6c:73:0f:c3:0c:18:18:16:04:9a:52:3d:
                    81:a2:71:ce:3c:32:00:9f:71:55:ba:f8:ce:36:77:
                    1e:21:b7:28:94:e7:3d:3e:a6:f6:c0:7a:31:60:91:
                    28:97:77:22:50:f2:c6:93:6e:b2:1b:c5:41:c6:f9:
                    a1:37:fb:10:bf:da:56:a6:fb:52:4d:5f:bf:ef:c4:
                    96:77:28:e5:32:ff:e8:e1:18:cc:43:52:18:ac:8d:
                    77:9a:72:4c:e8:9d:03:5e:b0:a2:ef:e4:dd:d2:e7:
                    e6:a7:a6:52:ad:e1:98:08:96:4a:43:cc:73:3d:4b:
                    a2:8d:89:ef:dc:82:4c:b8:4a:80:24:65:2b:1e:91:
                    82:f5:04:f6:72:1f:57:18:40:17:f0:39:51:b6:8f:
                    f3:89:3b:67:f7:58:4e:4a:bc:da:f9:0e:c1:c0:0c:
                    bd:f3:08:71:f8:83:0f:c9:2e:80:95:f4:85:0e:ce:
                    ae:a9
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                B8:43:83:64:21:7A:EE:70:81:DE:A5:DE:0C:60:28:87:78:AE:5E:78
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         2c:6b:2c:79:35:db:f0:1e:1c:87:7b:ab:e1:e8:69:6a:37:8b:
         db:7a:4f:55:60:69:95:2f:53:9d:c6:ca:43:b6:d4:37:91:d6:
         03:5d:7e:5a:b1:b8:1d:f7:9e:81:d3:ae:50:54:30:a4:6f:4b:
         2e:bb:14:1b:17:aa:5c:10:d3:94:7a:31:39:96:a4:54:79:f5:
         e9:56:2e:55:c3:1b:16:ea:aa:02:c8:cf:51:f7:32:81:22:c6:
         34:3a:a9:cd:9a:aa:48:93:c7:e9:fb:1e:32:7e:71:c4:76:f0:
         45:54:12:1d:55:ea:bd:5c:32:87:3a:ae:93:9a:6e:99:22:5f:
         a8:51:35:ee:b2:53:60:5f:f6:4f:45:b8:16:84:1d:65:55:cd:
         15:ca:10:01:1f:a9:d2:9c:a7:57:91:a3:d7:e7:b0:86:3d:2d:
         f4:89:3a:d8:c9:77:70:50:c6:6c:ef:f2:eb:98:f8:10:aa:3d:
         da:c8:5c:29:ad:ce:b8:73:49:4c:a1:92:bb:e6:ed:cd:ba:82:
         1a:63:21:19:65:f4:06:19:bf:83:aa:73:e5:d3:1b:b1:98:ff:
         45:df:fb:49:cc:73:e8:e2:e7:07:96:00:31:e9:7f:d9:24:08:
         e7:ca:44:7a:48:06:c3:42:d8:3f:f9:79:87:a5:37:92:16:a9:
         84:20:92:63
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 441 (0x1b9)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Sep  8 16:03:08 2011 GMT
            Not After : Sep  8 16:03:08 2017 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DOD EMAIL CA-30
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:e6:29:22:d4:14:26:d1:98:1a:52:5e:c5:84:83:
                    73:7e:c1:60:b3:b3:d0:94:be:fd:1c:94:55:bf:f6:
                    84:2c:9b:c9:c0:74:73:ef:cc:c2:99:f2:99:c9:6d:
                    ca:14:d3:74:ff:be:10:f2:f7:2d:bf:cb:bb:06:a3:
                    ee:98:50:41:65:01:e1:57:2c:b6:cb:e4:ca:1c:ac:
                    7e:52:34:0e:b1:8e:07:26:3e:32:35:af:a3:61:0a:
                    c5:e5:08:b6:12:79:8c:54:c1:7a:e9:f1:50:1f:5d:
                    83:3a:67:30:b3:29:db:1d:3a:4c:39:21:50:d8:18:
                    2c:8d:06:75:ee:63:72:78:68:ad:62:9c:75:a4:94:
                    06:d3:32:6b:12:af:06:07:29:be:13:a0:c0:a7:f0:
                    25:4f:b7:fe:1f:b7:57:e0:18:12:8d:21:6a:15:b9:
                    5a:54:fb:77:65:d8:4c:3f:f5:ba:3c:c0:37:e1:06:
                    7e:c2:be:9e:23:8c:28:d1:9a:d7:c6:67:38:d7:73:
                    c9:bd:07:1d:85:6f:d5:95:0a:9a:dc:da:3a:4e:28:
                    f0:a5:eb:09:df:e5:db:0b:cd:47:af:8a:cd:bb:6f:
                    94:40:e3:59:9c:50:9f:c9:0e:a9:71:02:b9:dc:e9:
                    69:80:3a:89:3b:45:05:22:18:05:84:b5:12:f0:3c:
                    c0:81
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                35:61:66:28:09:BC:56:25:5B:8B:CC:BF:81:5E:61:2C:30:39:D3:21
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.17
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.3.2.1.3.26
                Policy: 2.16.840.1.101.3.2.1.3.27

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/crl/DODROOTCA2.crl

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/issuedto/DODROOTCA2_IT.p7c
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         0a:88:56:1c:a5:57:26:5a:62:cb:75:d0:dd:86:c5:52:e2:2f:
         f3:bc:11:64:3f:8c:2f:3e:11:fc:98:60:40:f2:80:0d:28:82:
         9a:68:fe:e0:48:4b:27:d3:3a:0a:7b:95:f6:03:0c:81:14:91:
         42:3a:60:6c:e2:2b:53:2d:ec:df:11:ae:f5:54:17:f0:01:f9:
         97:07:a7:9b:ab:0b:db:ac:97:89:09:c6:ef:f9:07:34:16:00:
         a8:7e:11:53:9e:7c:2f:a1:38:a2:99:79:39:34:41:6e:7d:b8:
         58:30:56:88:9e:e4:aa:64:45:d9:a0:44:62:3a:b7:e5:31:d3:
         91:80:f1:1b:10:b2:67:70:d5:5b:ab:59:b4:5a:48:16:42:c4:
         02:4c:da:6c:68:ca:50:1d:31:be:37:99:c7:cf:53:cc:42:29:
         56:c3:9d:17:ca:03:e7:10:5a:f1:39:3c:1c:cc:fb:1b:97:0a:
         26:f3:31:df:e0:ab:5c:24:9d:9e:de:38:7d:02:51:67:46:f9:
         93:70:85:ed:0a:55:c2:f4:c1:68:5a:9f:08:c9:1d:7b:9b:76:
         dc:54:ef:39:8c:18:e5:0c:44:ee:f7:06:b2:1f:f5:cb:e6:0e:
         bd:d4:a1:ff:d4:f9:91:07:22:52:79:b7:c0:fd:ec:b2:f8:85:
         f4:44:fb:5c
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 4 (0x4)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Validity
            Not Before: May 19 13:13:00 2000 GMT
            Not After : May 14 13:13:00 2020 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD CLASS 3 Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:b5:30:fe:64:be:ea:cc:6d:ed:81:2c:f7:7f:e9:
                    19:ba:0e:69:6a:28:e1:a9:a9:cb:95:58:1f:f1:e6:
                    9a:69:53:e0:88:3f:91:c5:51:b9:63:97:a8:e6:21:
                    8c:13:5e:36:3c:a8:57:fa:f8:70:2c:4c:6a:cb:bf:
                    30:a7:4c:16:e4:32:5c:f8:12:b0:51:f8:16:57:8d:
                    2f:b4:4d:fa:2e:a8:94:e8:2a:61:d4:57:0d:47:ce:
                    6e:2c:2f:7e:98:67:cc:00:08:ab:b6:96:16:35:c2:
                    85:91:e5:5b:a0:0a:c7:66:52:62:f3:61:75:95:17:
                    ae:bc:2a:56:29:a5:e0:2b:53
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                6C:9C:A5:F0:5C:8F:6D:41:8D:C4:17:3B:90:57:C2:0F:A3:CD:6D:FE
            X509v3 Basic Constraints: 
                CA:TRUE
    Signature Algorithm: sha1WithRSAEncryption
         af:71:44:f9:97:23:cc:68:69:8c:43:07:41:ba:88:20:b3:22:
         00:41:c8:98:a0:55:1c:cd:3f:6e:b1:93:5c:ad:fa:18:9a:bb:
         1c:73:6f:fd:24:42:8f:87:9f:51:cf:be:86:9f:e9:d7:8a:48:
         4f:08:d9:69:94:ac:3f:e6:0f:2d:97:0f:28:93:76:4f:62:df:
         ff:a0:cd:61:f8:a6:86:0c:31:34:20:dc:7f:2f:a8:fb:39:be:
         95:ee:38:59:02:62:c1:de:6c:15:4f:e0:df:9d:bb:e4:79:73:
         24:fd:63:64:95:f7:4a:a8:99:1f:48:65:95:c7:7b:bf:78:32:
         e7:7a
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 44 (0x2c)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Feb  5 15:36:43 2008 GMT
            Not After : Feb  4 14:36:43 2018 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Intermediate CA-1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:99:5c:9e:21:37:15:b6:75:37:29:09:ce:cf:aa:
                    a7:22:4e:09:e5:98:fd:0b:44:03:17:fe:b2:bc:26:
                    0b:e4:df:6b:7a:b4:b4:13:bf:63:d6:99:71:b8:76:
                    25:cf:a0:5b:78:50:1d:c9:52:0e:4f:89:87:dc:0b:
                    ae:17:e8:aa:a4:30:a6:c9:78:7a:f9:bc:b6:85:95:
                    5c:9c:8d:68:08:99:b4:3a:3e:70:2b:ef:f3:58:35:
                    97:70:32:d6:4f:af:64:9f:3f:74:a3:1c:22:4f:a7:
                    74:8c:2b:a1:ab:bc:23:0f:d0:41:4b:a2:91:0a:60:
                    b3:3b:8b:4f:f2:ef:b4:83:34:d7:a9:5f:90:ba:88:
                    07:15:02:35:e1:d6:00:79:8d:19:f1:41:7c:92:56:
                    cc:75:b5:e8:eb:8f:c1:b7:a7:dc:31:3e:8c:3b:93:
                    ec:e0:d1:ee:dd:61:ab:95:32:bf:7b:18:a3:95:2c:
                    f7:ea:7f:29:9a:e9:de:6f:cd:de:e0:8b:1e:d7:94:
                    77:5e:82:d7:04:79:22:72:be:22:61:f2:93:f2:65:
                    73:fa:1b:43:d9:3c:ef:e9:cc:74:c2:39:5b:79:43:
                    ae:54:e1:c1:3e:90:b5:b9:07:ce:b4:b3:ec:9c:6b:
                    e6:dd:8f:1d:7c:c9:db:9a:ab:b0:6f:24:6b:02:17:
                    7d:69
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                D3:D4:72:CE:A5:97:6C:3A:FA:9A:D4:D2:83:FF:73:03:DB:53:4D:A3
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:1
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         80:91:d8:4f:fb:6d:12:07:57:9d:7b:6f:7b:56:00:50:8b:af:
         e1:79:9e:e8:75:fd:c1:37:b0:71:df:aa:91:49:56:8d:94:fe:
         c9:e3:c1:d9:85:00:17:64:4f:96:4d:34:44:4b:29:6f:d7:11:
         fc:1b:be:ef:b8:0b:60:e5:8e:a7:c3:21:e3:68:ca:ae:25:be:
         80:d0:2d:b9:0a:11:ac:32:08:57:5b:c4:e5:ea:64:6b:5b:39:
         4b:f3:47:fa:e7:92:19:32:ed:69:a3:a4:7e:96:3a:85:52:1d:
         86:2a:b8:5c:7d:69:bd:46:1b:ae:a0:70:26:87:b9:ce:64:64:
         eb:ea:e0:7b:80:f1:24:b0:fe:e7:bc:8c:61:a0:6e:ad:b7:fe:
         04:97:a7:21:03:f4:47:00:41:9b:cb:8d:f1:56:1b:48:9d:4c:
         a1:5f:df:0a:6a:39:22:b3:06:84:21:97:d9:c1:88:99:58:7f:
         fb:81:1c:3e:43:ea:ee:68:8f:0b:86:cb:1c:76:51:07:70:f7:
         f8:ec:91:c1:d0:87:78:3f:6f:30:aa:00:0b:a7:f8:06:6c:39:
         1b:e5:16:bf:2b:b7:2c:a5:b1:f9:a6:b5:97:19:e9:40:c5:68:
         94:2e:b3:fb:f3:f0:ee:6f:16:81:94:b8:20:24:2d:62:8d:bf:
         67:ad:2e:94
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 45 (0x2d)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: May  7 14:44:51 2008 GMT
            Not After : May  7 13:44:51 2018 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Intermediate CA-2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:99:50:69:c5:ef:60:b5:6d:b9:ab:5b:ce:15:fe:
                    ef:cd:eb:71:8e:34:d2:43:3b:c4:47:cb:49:69:6b:
                    a1:3d:b5:75:a3:f8:26:42:2d:5f:3f:a4:7f:11:90:
                    f8:e6:4e:e9:24:dc:eb:79:b7:07:55:5a:b1:49:64:
                    5f:b6:97:af:76:50:7a:22:8f:ef:94:35:83:7c:4f:
                    80:21:df:f7:84:bf:f9:0a:0e:2d:be:f5:9c:c0:04:
                    d1:d1:9a:27:1d:8d:7a:a1:98:8a:7a:8e:5f:c9:38:
                    2d:31:a1:18:6b:f4:c0:d5:2c:ad:63:d6:6f:91:da:
                    e0:26:00:e8:20:8f:cc:ed:5b:6e:20:ce:55:a6:08:
                    e9:ac:3a:92:be:f4:10:43:14:49:66:10:9c:a8:90:
                    18:94:08:b7:fa:d8:15:14:a0:ee:22:e7:c8:71:03:
                    05:a9:b0:84:9f:78:a3:6e:3b:8d:96:b8:09:81:71:
                    4e:02:c7:2a:26:36:a6:18:61:30:ff:cf:5c:1d:79:
                    80:6f:75:37:e4:6e:a2:4b:5d:0f:fc:54:9a:53:29:
                    e9:0d:8f:b7:3a:03:32:a0:a7:d5:cf:d8:8f:e6:4a:
                    a7:ba:08:75:cd:c1:c1:97:3f:3c:2d:ac:91:92:f0:
                    1e:c1:5d:81:fa:6f:48:9e:84:96:0f:a3:0e:15:64:
                    7e:a7
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96

            X509v3 Subject Key Identifier: 
                4B:1C:D6:8E:0D:08:E5:CC:AD:A0:02:C3:78:90:C3:23:63:AE:11:AE
            X509v3 Policy Constraints: 
                Require Explicit Policy:0
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:1
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.2.1.11.5
                Policy: 2.16.840.1.101.2.1.11.9
                Policy: 2.16.840.1.101.2.1.11.10
                Policy: 2.16.840.1.101.2.1.11.18
                Policy: 2.16.840.1.101.2.1.11.19
                Policy: 2.16.840.1.101.2.1.11.20

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?DoD%20Root%20CA%202

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?DoD%20Root%20CA%202
                OCSP - URI:http://ocsp.disa.mil
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dDoD%20Root%20CA%202%2cou%3dPKI%2cou%3dDoD%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         4c:92:eb:5f:20:3b:32:50:32:41:3b:6e:22:ba:73:02:eb:c5:
         1a:06:f0:0c:5a:a3:4a:2a:d8:bb:d7:6f:41:70:3d:9e:15:e4:
         1d:5c:a7:0e:42:cc:28:0d:2c:d0:71:f5:9a:c8:82:c2:89:3e:
         a9:41:54:ea:da:fa:e4:2d:8e:a2:35:95:0e:33:ce:18:59:2d:
         7c:d9:d1:9c:76:fd:69:62:c0:c3:6b:03:94:bb:5d:fa:f7:a9:
         91:f4:d9:e3:20:35:ab:f6:78:28:0f:db:af:60:a1:ba:70:75:
         71:40:42:24:4f:43:e9:fc:a8:fc:e6:1b:1f:b2:95:fa:de:de:
         7c:2c:6c:74:b3:a5:e3:aa:73:cc:dd:34:d0:2e:83:b5:bc:d4:
         a0:47:8d:11:ff:e6:14:81:6a:b6:de:89:d0:16:87:50:e8:95:
         e7:d1:57:70:d1:45:09:c8:63:a8:8b:d2:54:d1:6f:62:b0:70:
         84:e6:4c:b1:9e:f3:c3:f3:05:d1:7d:8f:09:96:bf:12:6a:47:
         93:94:90:3b:ad:fa:bd:04:e1:83:9c:d5:82:f4:91:4f:5f:28:
         94:16:bd:5f:6f:c4:97:a6:da:69:0f:c8:7d:25:09:6c:95:5c:
         d0:56:3f:73:94:e8:be:72:dc:bf:d9:84:bb:2d:e3:fa:e2:ff:
         7b:12:2c:b5
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 5525 (0x1595)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=SHA-1 Federal Root CA
        Validity
            Not Before: Dec  3 16:04:32 2013 GMT
            Not After : Dec  3 16:02:48 2016 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Interoperability Root CA 1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:9c:7d:b2:f6:cd:5a:1a:5b:b7:30:f5:32:2f:0b:
                    9e:9a:c3:1c:a8:42:32:6b:6c:59:57:70:42:3c:4a:
                    a9:a9:b1:dd:42:e0:59:be:78:96:c0:ff:7b:b9:23:
                    bf:5e:49:32:f1:1b:69:73:eb:c6:72:47:d7:7f:29:
                    bf:6d:d6:93:e7:b4:61:e4:a4:7c:1c:f0:56:cd:d0:
                    b3:99:24:c4:c1:7d:d5:ee:d2:83:8d:68:68:8c:8e:
                    98:e5:5d:29:38:c8:a6:b3:e7:ed:21:2b:58:ba:83:
                    5b:bc:f4:03:90:3f:60:ee:2b:2f:96:d4:2e:37:8f:
                    ab:2c:b4:1b:a2:80:0d:35:89:47:63:44:46:c4:aa:
                    45:43:7b:c1:3c:d2:21:43:8a:02:76:13:6d:7b:57:
                    19:bf:a7:38:79:9b:5f:fa:6f:df:fa:61:8c:07:d9:
                    4d:f2:26:ef:f2:90:35:1f:d7:fd:74:72:90:29:36:
                    f1:6e:74:c4:dc:f7:b5:1b:d7:85:78:21:af:20:c9:
                    7a:a5:7d:0e:74:e1:8f:24:6c:43:d3:09:f4:83:a5:
                    39:12:2e:4f:d4:94:fa:b3:5f:07:db:17:83:27:9e:
                    07:a6:ca:07:de:af:4a:13:ee:37:2e:37:ac:91:e8:
                    2d:6c:82:52:bd:02:08:ae:1f:09:bc:0a:23:a0:59:
                    fc:dd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/sha1frca/caCertsIssuedTosha1frca.p7c

            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.3.23:2.16.840.1.101.2.1.11.18, 2.16.840.1.101.3.2.1.3.24:2.16.840.1.101.2.1.11.19, 2.16.840.1.101.3.2.1.3.25:2.16.840.1.101.2.1.11.17, 2.16.840.1.101.3.2.1.3.25:2.16.840.1.101.3.2.1.12.1, 2.16.840.1.101.3.2.1.3.23:2.16.840.1.101.3.2.1.12.1, 2.16.840.1.101.3.2.1.3.24:2.16.840.1.101.3.2.1.12.2, 2.16.840.1.101.3.2.1.3.24:2.16.840.1.101.3.2.1.12.3
            X509v3 Name Constraints: critical
                Permitted:
                  DirName: C = US, O = U.S. Government, OU = DoD
                  DirName: DC = mil
                  DirName: C = US, O = U.S. Government, OU = ECA

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.23
                Policy: 2.16.840.1.101.3.2.1.3.24
                Policy: 2.16.840.1.101.3.2.1.3.25

            Subject Information Access: 
                CA Repository - URI:http://crl.disa.mil/issuedby/DODINTEROPERABILITYROOTCA1_IB.p7c

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:86:9A:5C:62:FF:73:93:D5:E1:8A:7F:4A:C6:88:2E:9F:6E:A0:AE:12

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/sha1frca/sha1frca.crl

            X509v3 Subject Key Identifier: 
                76:86:1E:DF:ED:00:C9:7E:14:31:7C:5B:94:82:21:49:57:BE:70:07
    Signature Algorithm: sha1WithRSAEncryption
         35:c2:f1:40:23:9d:d1:61:b5:b7:c4:d7:d8:38:62:f2:f1:20:
         29:ba:dd:87:84:a6:cb:87:4a:3d:97:7d:78:2c:d6:24:ba:ce:
         81:2c:e4:c9:c4:43:c0:b8:6e:93:f4:ed:e4:2e:3e:0a:82:0c:
         62:90:de:e6:f7:ab:03:d1:b3:07:c1:cb:a9:55:9e:5f:29:48:
         0a:18:f1:fa:17:7c:34:88:e9:b3:c2:09:4d:d4:17:eb:00:a5:
         ba:62:61:ac:37:5a:15:c4:0f:5b:0a:00:ca:95:dd:cc:b4:5e:
         c2:81:b2:20:39:6a:84:a3:bd:53:48:e9:2d:02:93:5a:6d:e0:
         71:f7:a5:77:a3:ab:22:1f:11:0a:05:0f:3c:5c:33:72:e8:d6:
         fb:2a:8c:57:6f:5d:43:52:59:a5:5f:52:4c:99:4b:88:5c:6a:
         35:4b:72:5a:55:6d:c4:f9:73:6a:37:18:0a:1c:24:1b:47:ce:
         94:4f:8a:3a:95:e0:54:26:93:2e:05:98:10:34:cb:ac:84:96:
         d2:e6:ed:cd:e6:06:0a:e0:8d:47:7a:ee:81:aa:da:5d:d5:e9:
         45:ff:c7:e6:99:87:12:f8:24:fe:71:ed:9b:69:43:d9:78:dd:
         85:73:ee:a7:c4:e2:ea:ae:49:b8:0a:e5:39:9d:0f:f4:4f:f6:
         2b:b1:31:d2
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 5 (0x5)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Validity
            Not Before: Dec 13 15:00:10 2004 GMT
            Not After : Dec  5 15:00:10 2029 GMT
        Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:c0:2c:c1:f6:8d:3b:ac:ff:3f:3c:d6:71:be:b8:
                    74:22:07:ec:70:41:15:fc:ab:40:e3:07:aa:c1:c3:
                    d8:9f:fe:da:4c:3a:bf:3f:c8:d8:28:7b:4b:36:01:
                    c0:ac:45:25:c3:d2:0e:0a:8f:85:18:64:10:3d:1a:
                    13:70:2a:6f:8e:d7:dc:8d:93:b3:41:0f:38:21:cd:
                    ad:ab:c2:3d:2a:05:d3:57:11:37:0d:cd:8c:51:f9:
                    93:e3:cc:46:49:21:8e:14:b4:cd:cb:14:3e:38:cd:
                    72:31:ee:ab:12:f2:65:ea:34:2e:56:5d:ff:ee:63:
                    75:cb:6d:ba:91:34:fc:9e:f3:f4:2d:1c:be:50:c4:
                    42:df:59:88:ff:6a:b3:fa:a8:6c:3d:cb:56:71:71:
                    05:96:bb:9f:80:e5:80:45:59:67:41:b0:eb:c3:ad:
                    60:a4:80:75:06:17:9c:0e:f4:43:e0:99:0e:1b:fb:
                    7f:f5:b3:cc:b2:81:82:b1:fd:32:c1:b8:be:41:a4:
                    64:b5:60:3a:5a:51:30:8c:ce:de:41:2c:19:47:5c:
                    49:10:64:b9:74:a9:87:41:af:7d:6e:ba:c1:b8:a1:
                    bf:65:31:3a:04:67:f9:b5:bb:8e:92:8a:00:63:b8:
                    b1:e6:8c:38:5f:83:ff:50:d5:3b:a2:5d:6b:b2:10:
                    cc:63
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                49:74:BB:0C:5E:BA:7A:FE:02:54:EF:7B:A0:C6:95:C6:09:80:70:96
            X509v3 Key Usage: 
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
    Signature Algorithm: sha1WithRSAEncryption
         98:91:8d:3f:89:c8:bb:f5:c0:69:73:29:3b:35:ac:ba:b3:08:
         76:3d:70:09:92:e9:84:44:21:01:7d:14:76:1b:ee:51:6c:1d:
         8d:15:37:2d:7b:31:69:f4:9a:44:b8:af:46:cc:34:fa:23:cb:
         03:27:19:d2:83:21:75:2b:e7:e0:1b:99:26:dc:84:40:95:e8:
         a8:d2:cc:f6:58:5c:66:ef:3f:4a:97:10:82:1d:ba:0a:a2:dd:
         5b:06:2b:9d:a7:64:4e:eb:2e:01:35:a4:b4:3f:13:ad:55:e4:
         d5:73:a8:69:9b:11:f1:98:f2:31:1e:6f:40:d4:f8:78:9f:8e:
         91:a0:6f:70:04:90:66:aa:06:2b:ce:e1:7a:92:b5:7d:e1:e0:
         d1:96:e7:a1:3a:2d:cc:b1:9d:1f:05:44:ed:87:99:d3:4d:1a:
         70:39:c1:04:0c:e5:7e:d9:f1:af:d7:20:0e:f1:22:7a:25:a4:
         73:99:cc:3f:a4:07:27:96:a8:a2:95:ed:82:b9:16:d3:9e:0b:
         87:c2:c1:f2:88:f5:62:df:68:df:c7:bc:69:51:ed:b1:5c:dc:
         54:54:29:0f:09:39:9a:ac:03:c1:db:0c:4d:ae:6f:0a:7a:16:
         49:f1:bf:91:d2:38:94:d3:f6:95:2c:b7:6c:c9:42:b6:8d:ca:
         90:8d:85:d9
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 14 (0xe)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA
        Validity
            Not Before: Jun 14 10:20:09 2004 GMT
            Not After : Jun 14 10:20:09 2040 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ae:4a:f6:79:72:12:ea:80:0a:22:90:e4:3a:57:
                    10:65:d3:06:76:77:28:ca:00:84:21:4f:a4:b6:a6:
                    37:a1:fe:52:55:55:d4:ef:f8:ad:ee:42:75:11:4c:
                    d1:e2:28:b6:be:d8:50:b5:bc:30:f5:a0:27:a5:0c:
                    5c:12:65:d9:93:c7:84:ca:21:84:3f:2f:9c:09:03:
                    25:94:16:3e:79:f3:ad:2a:08:db:40:d0:d9:de:50:
                    7d:d7:da:b3:50:9c:01:97:60:4c:c6:c9:54:d5:7b:
                    09:43:0f:52:2b:5d:25:3d:b4:26:e1:ab:1a:f0:4f:
                    1e:e7:34:d4:92:76:41:5a:71
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:F6:B8:04:27:0E:56:16:D9:B9:63:D9:FD:A1:54:65:41:A0:08:48:2F

            X509v3 Subject Key Identifier: 
                F6:B8:04:27:0E:56:16:D9:B9:63:D9:FD:A1:54:65:41:A0:08:48:2F
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                Policy: 2.16.840.1.101.3.2.1.12.2

    Signature Algorithm: sha1WithRSAEncryption
         1e:1d:04:41:8d:9c:67:6d:3d:68:16:f9:ab:4c:16:d4:44:74:
         75:ce:0e:1b:3b:0b:ca:a8:c7:7d:a4:38:4c:46:8c:99:4c:0b:
         00:94:6d:6b:f7:38:29:55:8b:8b:06:ce:0e:cb:e0:26:4f:82:
         69:69:92:2f:4d:e0:45:6f:dc:89:56:ff:a8:35:7b:aa:1f:4f:
         c9:dd:5c:3a:56:a7:65:30:27:3e:88:36:8b:cd:b2:2f:78:b6:
         7c:af:43:08:2f:38:ba:8c:44:41:b8:2a:2b:68:f1:f5:b2:23:
         15:3c:25:02:a2:13:93:d7:c6:02:6e:66:75:3f:38:20:4c:2a:
         d4:6c
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 5 (0x5)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA 2
        Validity
            Not Before: Apr  4 14:24:49 2008 GMT
            Not After : Mar 30 14:24:49 2028 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:b3:90:d8:1e:ef:9a:ed:6e:47:b1:46:61:46:8d:
                    a3:56:08:9c:4a:32:c7:45:f2:d2:a4:a4:66:be:7e:
                    3d:97:80:ef:e9:d7:6b:e9:e0:c0:3b:8d:e2:f8:12:
                    fa:13:35:a4:cd:5a:86:8b:b0:d0:2f:34:8c:f7:05:
                    ed:87:6f:a7:30:17:d0:16:c6:58:46:bd:95:f9:56:
                    1a:88:d4:4e:1e:7e:58:1f:1b:a2:73:15:9d:5e:8b:
                    06:24:13:76:3c:9f:60:62:ad:b0:b5:f4:e0:24:c1:
                    53:f7:d9:1c:37:1d:e6:3c:f0:fa:d3:f1:f9:a1:98:
                    f1:37:85:d8:cf:02:60:f0:a0:38:94:4b:51:28:09:
                    c2:17:fc:40:a4:61:79:0e:b4:8c:1b:20:82:62:f5:
                    e4:9a:d6:29:8a:36:fa:1f:81:c0:a1:11:31:4b:fe:
                    56:fd:d8:bf:51:93:27:59:da:f5:83:3e:44:a4:df:
                    d5:20:67:eb:9f:00:a7:fb:de:31:b6:63:31:1c:3d:
                    f7:1c:6c:09:8d:7f:f4:ba:9c:a8:7c:1f:01:c6:80:
                    6d:01:01:d8:37:a8:fe:2d:7d:2b:c2:cb:d6:e9:9c:
                    ba:94:8d:76:16:de:cc:81:75:04:7b:41:77:15:65:
                    15:c9:ac:00:b6:bf:eb:1c:dc:b9:8d:64:2d:ff:35:
                    db:c5
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                ED:E4:87:D0:27:C4:50:E6:84:3A:F7:CC:F7:EB:3A:49:FC:52:4E:21
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            Subject Information Access: 
                CA Repository - URI:http://crl.gds.disa.mil/getIssuedBy?ECA%20Root%20CA%202
                CA Repository - URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         4a:cc:1b:e7:85:88:93:23:d9:b9:be:cf:ba:f1:35:94:c1:4b:
         3c:13:70:5d:83:2e:4e:7e:c1:56:0f:2d:c1:7e:1f:0d:e9:dd:
         fe:02:99:7c:60:e3:86:aa:b9:86:23:c3:17:7e:c7:11:0f:e3:
         d0:42:56:a3:1c:f3:70:8f:b1:88:91:b5:bc:0e:89:25:66:c8:
         3f:5f:36:2a:0e:3e:b6:67:40:8c:3d:40:df:a7:62:e0:38:18:
         fa:24:6d:2d:23:d3:c0:b8:74:5e:95:44:54:7a:21:97:0f:5a:
         cd:c3:fc:95:3d:22:22:15:dd:18:60:5d:85:37:a9:4d:f7:81:
         fc:bd:4a:a6:58:8c:4f:bf:c7:65:a1:ff:e2:d3:34:48:1a:17:
         01:32:f2:84:f3:de:05:b2:64:49:98:37:cd:21:f5:a8:81:5b:
         64:c5:da:7c:58:b0:61:61:1f:ad:c0:ad:ed:34:b6:94:ab:c7:
         9c:ec:65:97:29:85:94:94:33:c4:35:24:8b:3d:cd:fc:37:2a:
         bb:fa:a4:b6:1b:90:f2:95:57:17:48:e0:ef:a9:9d:ad:00:e2:
         b1:64:d9:67:79:11:83:b9:9a:e8:0b:32:36:ce:20:67:e3:7a:
         6d:4b:ea:5e:53:e5:2f:30:41:dd:f8:e5:54:9d:a9:d7:69:c6:
         75:d9:45:47
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 11814 (0x2e26)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Jul 30 13:18:52 2015 GMT
            Not After : Jul 30 13:12:42 2025 GMT
        Subject: C=US, O=Entrust, OU=Certification Authorities, OU=Entrust Managed Services Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:98:a8:a3:7a:28:dc:38:cd:82:ca:82:2e:98:3a:
                    88:ae:c3:a2:bf:f5:ef:db:9f:b0:f6:80:d9:40:43:
                    13:d9:b4:6b:e6:be:1c:c8:3b:1d:94:78:70:f0:86:
                    61:64:8a:f3:72:d9:f8:08:af:ce:7f:6e:b4:1f:2a:
                    0b:a4:5a:0a:5c:11:2f:43:97:61:a9:72:c9:ce:5c:
                    34:a6:f9:c0:2d:18:9a:c4:57:af:c4:72:fe:a8:fb:
                    3d:aa:9b:46:11:38:33:44:68:c1:78:00:d2:e5:fc:
                    7f:79:c9:f4:78:97:9e:1a:23:e3:17:ea:bc:73:4e:
                    74:ef:fa:3f:d0:a6:d2:f7:67:22:5e:f0:b9:d0:a1:
                    e2:07:af:af:49:a3:6d:5e:e9:e9:06:46:d9:58:27:
                    d2:fc:af:9a:a7:ee:cf:db:17:d2:99:fd:a9:2c:59:
                    e0:76:d5:dd:70:72:2d:dd:20:8a:4d:e5:b3:3c:af:
                    96:27:40:b1:23:8f:38:37:e5:2b:1b:a8:11:1f:b7:
                    5f:d0:be:0c:43:6c:45:93:5b:df:c8:22:3e:61:5a:
                    ba:72:05:57:b6:de:92:70:36:d1:16:96:eb:c5:c6:
                    1c:d0:cf:7c:49:d1:4d:59:05:14:17:c9:25:47:6f:
                    1d:24:d1:2c:91:96:18:45:bf:aa:e2:72:8a:04:4e:
                    1b:49
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.36
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17
                Policy: 2.16.840.1.101.3.2.1.3.39
                Policy: 2.16.840.1.101.3.2.1.3.40
                Policy: 2.16.840.1.101.3.2.1.3.41

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c

            Subject Information Access: 
                CA Repository - URI:http://rootweb.managed.entrust.com/SIA/CertsIssuedByEMSRootCA.p7c
                CA Repository - URI:ldap://rootdir.managed.entrust.com/ou=Entrust%20Managed%20Services%20Root%20CA,ou=Certification%20Authorities,o=Entrust,c=US?cACertificate;binary,crossCertificatePair;binary

            X509v3 Inhibit Any Policy: critical
                0
            X509v3 Policy Constraints: critical
                Inhibit Policy Mapping:0
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

            X509v3 Subject Key Identifier: 
                A9:53:BE:64:84:83:4B:5D:26:C6:27:3E:2E:D1:84:68:55:3C:D0:75
    Signature Algorithm: sha256WithRSAEncryption
         3c:54:c7:6a:d6:3c:c8:8f:b5:95:14:30:42:6f:9c:2d:3e:a9:
         de:b3:8f:d8:fb:10:76:9a:fc:7b:65:dc:49:86:45:b1:50:84:
         7c:bf:4c:e6:15:a6:4e:0b:12:33:02:4d:ea:fd:69:74:70:15:
         20:05:3d:21:00:b7:71:16:b5:7a:17:0d:c3:4c:00:6a:bb:db:
         bd:41:d9:c1:f6:4e:88:0b:d5:aa:7a:cc:b9:20:8b:3a:c3:be:
         6b:d7:af:ef:f2:da:da:40:1a:e0:b7:a5:3b:e5:28:9d:11:e5:
         0f:21:19:5d:aa:0e:97:f0:fb:74:2e:21:2d:ee:61:71:b1:95:
         a5:0d:76:d1:76:8f:d8:00:00:d0:4a:de:36:e8:45:b0:eb:01:
         2d:fa:81:bb:16:8e:db:89:cd:18:ac:c7:e8:f6:f3:40:7a:9d:
         c1:bf:3b:51:f5:b0:89:5d:04:d3:78:34:84:3e:dd:ff:44:a3:
         ac:e8:47:0f:8c:3b:96:5e:14:59:a0:24:09:d3:84:71:20:a3:
         eb:4d:8c:ba:61:c7:ff:5a:f0:3b:8d:68:52:c9:97:16:5c:b6:
         e5:14:be:f1:2a:91:02:0f:2a:ed:d0:40:cd:75:be:70:c6:ca:
         96:7d:be:f4:ec:22:8d:e2:14:53:2f:86:8f:b1:f8:41:95:0b:
         0c:5d:f5:9a
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 11424 (0x2ca0)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Jun 24 15:45:07 2015 GMT
            Not After : Jun 24 15:45:07 2018 GMT
        Subject: C=US, O=U.S. Government, OU=FPKI, CN=Federal Bridge CA 2013
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:9c:e8:17:25:c2:59:ef:34:a5:c5:44:3b:00:35:
                    ec:31:40:a5:7a:02:d2:3e:19:14:9b:25:89:cd:4a:
                    8c:3b:e6:5e:6a:da:1c:6b:dd:0c:03:2a:45:84:29:
                    9d:4f:2e:ff:b0:a0:6c:02:c6:5a:a7:78:67:a5:77:
                    bb:c6:98:f8:b1:7e:e2:94:bb:fa:11:4f:63:38:1c:
                    1e:7c:08:0c:9e:f6:2a:15:63:22:62:14:12:e7:9f:
                    d4:ea:50:2e:d4:7e:3e:64:25:e4:2e:1c:1b:b8:ed:
                    5f:65:b4:f3:00:15:4f:0d:24:92:2c:71:50:22:3c:
                    eb:11:69:b3:2c:38:f3:e0:73:a1:98:26:75:a6:2d:
                    56:a9:05:af:9b:c9:38:8c:66:c0:c8:08:3b:43:3c:
                    83:dd:2a:52:ab:08:21:7e:cd:4f:ef:45:69:70:0c:
                    7c:b5:fe:1b:51:4e:09:28:2c:07:2b:4a:79:8c:41:
                    45:c4:53:0b:cd:e5:d4:a6:bb:93:33:d8:37:96:c3:
                    b0:2b:5b:c5:c5:e6:49:5c:41:5b:75:a3:02:db:15:
                    9e:73:d0:a6:cc:e4:c8:9a:1a:c7:01:07:93:b0:df:
                    eb:b8:fd:7f:dc:ab:18:94:92:8b:8d:f4:0c:29:09:
                    50:4f:5b:71:e1:da:50:5e:a3:bf:df:dc:a4:8a:f0:
                    07:4b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c

            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.3.6:2.16.840.1.101.3.2.1.3.3, 2.16.840.1.101.3.2.1.3.7:2.16.840.1.101.3.2.1.3.12, 2.16.840.1.101.3.2.1.3.8:2.16.840.1.101.3.2.1.3.37, 2.16.840.1.101.3.2.1.3.16:2.16.840.1.101.3.2.1.3.4, 2.16.840.1.101.3.2.1.3.36:2.16.840.1.101.3.2.1.3.38
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.1
                Policy: 2.16.840.1.101.3.2.1.3.2
                Policy: 2.16.840.1.101.3.2.1.3.3
                Policy: 2.16.840.1.101.3.2.1.3.12
                Policy: 2.16.840.1.101.3.2.1.3.14
                Policy: 2.16.840.1.101.3.2.1.3.15
                Policy: 2.16.840.1.101.3.2.1.3.37
                Policy: 2.16.840.1.101.3.2.1.3.38
                Policy: 2.16.840.1.101.3.2.1.3.4
                Policy: 2.16.840.1.101.3.2.1.3.18
                Policy: 2.16.840.1.101.3.2.1.3.19
                Policy: 2.16.840.1.101.3.2.1.3.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.36
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.16
                Policy: 2.16.840.1.101.3.2.1.3.17
                Policy: 2.16.840.1.101.3.2.1.3.40
                Policy: 2.16.840.1.101.3.2.1.3.41
                Policy: 2.16.840.1.101.3.2.1.3.39

            Subject Information Access: 
                CA Repository - URI:http://http.fpki.gov/bridge/caCertsIssuedByfbca2013.p7c

            X509v3 Policy Constraints: critical
                Inhibit Policy Mapping:2
            X509v3 Inhibit Any Policy: critical
                0
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

            X509v3 Subject Key Identifier: 
                BB:CE:74:71:83:34:4E:59:32:45:15:5F:40:60:60:DC:2B:B0:B4:E4
    Signature Algorithm: sha256WithRSAEncryption
         c0:1e:6d:27:f0:79:47:52:46:84:c8:88:5d:2e:9c:a6:76:fd:
         fc:f9:85:d2:79:3c:06:21:fb:cc:fd:27:39:bc:a3:1a:91:64:
         57:a8:5e:80:71:b0:43:66:9d:2a:f8:11:47:ba:0c:7e:58:5f:
         b7:51:8f:23:b9:dd:13:ef:18:f2:89:f4:51:37:59:81:4a:c4:
         70:ad:47:ec:8b:1a:53:71:e7:2f:49:66:c6:ef:84:1b:2c:f3:
         43:5d:3c:11:7b:41:20:5b:8e:5a:72:d5:01:84:f6:32:f5:01:
         f1:3a:c8:7e:8f:f4:fa:d0:c5:78:d6:bf:a3:84:1c:18:66:c8:
         4d:bc:33:fd:df:4d:ce:78:b2:52:1b:46:88:72:67:4d:6d:72:
         5b:bb:e1:57:2d:cf:3e:0a:4d:07:37:70:94:b2:23:bb:da:d5:
         be:6f:87:52:f6:57:53:a8:6b:33:3b:60:d9:b0:84:0e:b0:4a:
         59:4f:6b:ac:b7:4c:95:be:37:b1:d3:39:83:c8:b3:8d:eb:dc:
         38:65:cf:16:33:66:ae:72:92:8f:0d:68:e4:d2:5d:72:73:30:
         08:a5:4c:74:5a:dc:1f:9b:4b:71:60:9c:d3:5e:50:bf:2e:6d:
         ce:b2:5b:e6:c6:ed:c9:7c:8b:01:d1:db:b1:cd:a7:a1:62:6e:
         d4:67:5e:31
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 1312391187 (0x4e398013)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=Department of the Treasury, OU=Certification Authorities, OU=US Treasury Root CA
        Validity
            Not Before: Dec 19 20:12:57 2013 GMT
            Not After : Dec 19 20:42:57 2016 GMT
        Subject: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d8:75:fb:35:16:34:5a:41:bf:5a:af:5c:30:04:
                    14:1c:ad:78:44:b5:ea:26:ea:75:61:c7:cd:36:79:
                    f8:7c:d8:bd:29:51:66:59:21:e3:79:ab:d4:78:be:
                    b0:2d:b0:a1:d5:b2:35:16:23:d0:cc:1e:be:0e:e8:
                    ab:dc:c3:c9:d6:12:d7:a7:72:68:18:31:b8:17:22:
                    b2:3e:7e:ba:08:6d:c6:fd:d1:58:2c:69:a0:03:f0:
                    2a:a3:f6:3f:21:25:3d:df:b7:32:c5:8e:27:b3:23:
                    a5:e0:52:b3:5d:96:e9:b0:b8:c5:c5:9f:bb:c5:a0:
                    6e:82:40:bb:c5:27:05:36:49:d6:26:27:69:0c:34:
                    8f:cf:27:7a:2a:0a:a3:41:5f:8d:1d:03:86:83:15:
                    e0:55:c1:c5:98:2c:9e:ec:1a:72:dc:48:c1:3e:f9:
                    84:d2:84:82:c1:1b:c3:74:36:b7:b9:c7:36:32:7a:
                    f8:32:b6:d0:36:ae:22:18:31:8c:50:73:21:9e:fe:
                    83:3b:30:88:24:e3:e9:c1:7e:de:ed:98:c7:1f:92:
                    10:8a:9f:5b:62:2f:9d:a4:bc:d5:85:6f:3a:fd:c9:
                    53:a7:20:4b:aa:db:20:ab:21:4e:1d:0d:4e:e6:98:
                    85:e5:ab:11:47:5d:9d:3f:c4:23:c0:e3:14:06:6e:
                    fe:9d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.5.2:2.16.840.1.101.3.2.1.3.1, 2.16.840.1.101.3.2.1.5.3:2.16.840.1.101.3.2.1.3.2, 2.16.840.1.101.3.2.1.5.7:2.16.840.1.101.3.2.1.3.6, 2.16.840.1.101.3.2.1.5.4:2.16.840.1.101.3.2.1.3.7, 2.16.840.1.101.3.2.1.5.5:2.16.840.1.101.3.2.1.3.16
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.5.2
                Policy: 2.16.840.1.101.3.2.1.5.3
                Policy: 2.16.840.1.101.3.2.1.5.7
                Policy: 2.16.840.1.101.3.2.1.5.4
                Policy: 2.16.840.1.101.3.2.1.5.5

            Authority Information Access: 
                CA Issuers - URI:http://pki.treas.gov/cpca_aia.p7c

            Subject Information Access: 
                CA Repository - URI:http://http.fpki.gov/fcpca/caCertsIssuedByfcpca.p7c

            X509v3 Subject Key Identifier: 
                AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC
            X509v3 CRL Distribution Points: 

                Full Name:
                  DirName: C = US, O = U.S. Government, OU = Department of the Treasury, OU = Certification Authorities, OU = US Treasury Root CA, CN = CRL1

                Full Name:
                  URI:http://pki.treas.gov/US_Treasury_Root_CA.crl

            X509v3 Authority Key Identifier: 
                keyid:68:84:15:48:8C:54:70:7F:2D:12:58:0E:EC:1C:78:EF:3C:2E:59:64

            1.2.840.113533.7.65.0: 
                0
..V7.1....
    Signature Algorithm: sha256WithRSAEncryption
         c5:db:1c:af:35:9f:fd:26:97:5a:a2:90:14:44:3b:18:28:02:
         12:10:80:fb:bd:fa:84:c9:ca:fc:68:04:b5:57:25:e9:7d:60:
         18:09:cc:00:14:24:d4:53:1f:16:c8:a4:70:36:6a:74:6e:85:
         47:e7:4c:78:95:50:6b:a6:09:28:fa:cc:61:13:fc:9f:a0:28:
         1b:ae:3c:4d:a3:4b:46:b1:bb:7d:4b:2d:a5:19:a8:51:5f:0d:
         d2:55:e5:e1:44:97:16:31:ec:3e:8b:d2:6b:e5:f8:4e:fc:c8:
         5a:98:f1:d3:25:39:80:43:ed:e4:da:63:0f:90:54:43:74:60:
         d0:57:21:57:2a:74:d3:98:2a:ca:63:0f:1f:8f:66:4c:dc:77:
         b0:0b:2c:e8:5e:a3:48:53:96:b2:20:36:e6:0a:7a:61:d0:09:
         80:e8:bf:a5:b7:a0:ca:05:0d:c0:5c:10:db:8d:ad:bd:4e:20:
         36:11:27:a4:b4:df:e8:22:8f:04:92:46:b7:74:86:08:b1:b0:
         d0:a4:61:3a:10:3c:ba:41:8b:66:92:74:ea:39:0d:37:6a:c0:
         6f:05:7e:33:0b:a4:5f:b5:89:b2:ed:e6:3a:bb:17:6a:a1:f6:
         ca:29:e8:1c:fb:06:8b:a8:ec:ee:fb:01:82:3f:c4:08:a6:90:
         a5:28:d6:7a
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 1370474143 (0x51afc69f)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: DC=sbu, DC=state, CN=Configuration, CN=Services, CN=Public Key Services, CN=AIA, CN=U.S. Department of State AD Root CA
        Validity
            Not Before: Jan 31 22:34:26 2014 GMT
            Not After : Jan 31 23:04:26 2017 GMT
        Subject: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d8:75:fb:35:16:34:5a:41:bf:5a:af:5c:30:04:
                    14:1c:ad:78:44:b5:ea:26:ea:75:61:c7:cd:36:79:
                    f8:7c:d8:bd:29:51:66:59:21:e3:79:ab:d4:78:be:
                    b0:2d:b0:a1:d5:b2:35:16:23:d0:cc:1e:be:0e:e8:
                    ab:dc:c3:c9:d6:12:d7:a7:72:68:18:31:b8:17:22:
                    b2:3e:7e:ba:08:6d:c6:fd:d1:58:2c:69:a0:03:f0:
                    2a:a3:f6:3f:21:25:3d:df:b7:32:c5:8e:27:b3:23:
                    a5:e0:52:b3:5d:96:e9:b0:b8:c5:c5:9f:bb:c5:a0:
                    6e:82:40:bb:c5:27:05:36:49:d6:26:27:69:0c:34:
                    8f:cf:27:7a:2a:0a:a3:41:5f:8d:1d:03:86:83:15:
                    e0:55:c1:c5:98:2c:9e:ec:1a:72:dc:48:c1:3e:f9:
                    84:d2:84:82:c1:1b:c3:74:36:b7:b9:c7:36:32:7a:
                    f8:32:b6:d0:36:ae:22:18:31:8c:50:73:21:9e:fe:
                    83:3b:30:88:24:e3:e9:c1:7e:de:ed:98:c7:1f:92:
                    10:8a:9f:5b:62:2f:9d:a4:bc:d5:85:6f:3a:fd:c9:
                    53:a7:20:4b:aa:db:20:ab:21:4e:1d:0d:4e:e6:98:
                    85:e5:ab:11:47:5d:9d:3f:c4:23:c0:e3:14:06:6e:
                    fe:9d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Name Constraints: critical
                Excluded:
                  DirName: DC = gov, DC = state
                  DirName: DC = sbu, DC = state
                  DirName: C = US, O = U.S. Government, OU = Department of State

            X509v3 Inhibit Any Policy: 
                0
            Authority Information Access: 
                CA Issuers - URI:http://crls.pki.state.gov/AIA/CertsIssuedToDoSADRootCA.p7c
                CA Issuers - URI:ldap://certrep.pki.state.gov/cn=U.S.%20Department%20of%20State%20AD%20Root%20CA,cn=AIA,cn=Public%20Key%20Services,cn=Services,cn=Configuration,dc=state,dc=sbu?cACertificate;binary,crossCertificatePair;binary

            Subject Information Access: 
                CA Repository - URI:http://http.fpki.gov/fcpca/caCertsIssuedByfcpca.p7c

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.6.1
                Policy: 2.16.840.1.101.3.2.1.6.2
                Policy: 2.16.840.1.101.3.2.1.6.3
                Policy: 2.16.840.1.101.3.2.1.6.4
                Policy: 2.16.840.1.101.3.2.1.6.12

            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.6.1:2.16.840.1.101.3.2.1.3.1, 2.16.840.1.101.3.2.1.6.2:2.16.840.1.101.3.2.1.3.2, 2.16.840.1.101.3.2.1.6.3:2.16.840.1.101.3.2.1.3.6, 2.16.840.1.101.3.2.1.6.4:2.16.840.1.101.3.2.1.3.16, 2.16.840.1.101.3.2.1.6.12:2.16.840.1.101.3.2.1.3.7
            X509v3 Subject Key Identifier: 
                AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crls.pki.state.gov/crls/DoSADPKIRootCA.crl
                  URI:ldap://certrep.pki.state.gov/cn=U.S.%20Department%20of%20State%20AD%20Root%20CA,cn=AIA,cn=Public%20Key%20Services,cn=Services,cn=Configuration,dc=state,dc=sbu?certificateRevocationList

                Full Name:
                  DirName: DC = sbu, DC = state, CN = Configuration, CN = Services, CN = Public Key Services, CN = AIA, CN = U.S. Department of State AD Root CA, CN = CRL1

            X509v3 Authority Key Identifier: 
                keyid:6F:83:FE:82:50:64:65:77:3E:FD:DF:03:9A:CE:29:D1:2F:30:CC:EC

    Signature Algorithm: sha256WithRSAEncryption
         53:53:6f:7d:c8:18:01:ff:51:e2:d8:4a:a5:63:90:23:c7:e7:
         f1:b9:6b:09:db:08:11:90:92:c6:40:67:3e:71:fa:e8:a9:1d:
         51:c6:92:9d:10:93:c9:32:46:36:59:cb:cd:9d:93:91:7b:bc:
         28:25:db:cc:5b:41:86:b2:93:d5:95:c9:81:26:da:b8:3d:62:
         1f:cf:a0:90:b7:4e:e2:f1:96:89:c6:3b:33:a1:59:00:63:89:
         5c:d5:67:d9:ab:6f:e7:17:b5:ad:b7:1f:7d:c4:d9:41:bf:20:
         b0:f2:63:39:7e:57:5c:17:f8:aa:58:3a:3e:6b:91:1c:f5:0b:
         6a:fb:5d:08:91:10:50:48:ff:94:11:e4:1b:d3:6e:a2:b1:00:
         ff:d4:cb:3b:ff:c5:83:52:b8:f1:27:91:0f:46:ef:ea:fc:8f:
         3f:08:cf:5b:6a:9e:dc:b5:ab:4a:f3:15:9e:54:29:dc:00:55:
         65:ff:fb:b7:2f:a9:f0:80:d9:59:f6:76:10:c5:62:6b:47:06:
         91:5b:00:5f:29:d6:95:32:f6:c4:26:30:f0:59:b2:03:ec:e4:
         c4:cb:eb:be:df:66:15:42:07:03:05:2d:21:73:bc:09:0c:f4:
         b4:4e:c6:25:bd:df:93:2d:cb:c6:87:3a:9c:3b:72:f5:3d:86:
         ab:5d:26:ba
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 5724 (0x165c)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Bridge CA 2013
        Validity
            Not Before: Jun 24 15:52:07 2015 GMT
            Not After : Jun 24 15:52:07 2018 GMT
        Subject: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d8:75:fb:35:16:34:5a:41:bf:5a:af:5c:30:04:
                    14:1c:ad:78:44:b5:ea:26:ea:75:61:c7:cd:36:79:
                    f8:7c:d8:bd:29:51:66:59:21:e3:79:ab:d4:78:be:
                    b0:2d:b0:a1:d5:b2:35:16:23:d0:cc:1e:be:0e:e8:
                    ab:dc:c3:c9:d6:12:d7:a7:72:68:18:31:b8:17:22:
                    b2:3e:7e:ba:08:6d:c6:fd:d1:58:2c:69:a0:03:f0:
                    2a:a3:f6:3f:21:25:3d:df:b7:32:c5:8e:27:b3:23:
                    a5:e0:52:b3:5d:96:e9:b0:b8:c5:c5:9f:bb:c5:a0:
                    6e:82:40:bb:c5:27:05:36:49:d6:26:27:69:0c:34:
                    8f:cf:27:7a:2a:0a:a3:41:5f:8d:1d:03:86:83:15:
                    e0:55:c1:c5:98:2c:9e:ec:1a:72:dc:48:c1:3e:f9:
                    84:d2:84:82:c1:1b:c3:74:36:b7:b9:c7:36:32:7a:
                    f8:32:b6:d0:36:ae:22:18:31:8c:50:73:21:9e:fe:
                    83:3b:30:88:24:e3:e9:c1:7e:de:ed:98:c7:1f:92:
                    10:8a:9f:5b:62:2f:9d:a4:bc:d5:85:6f:3a:fd:c9:
                    53:a7:20:4b:aa:db:20:ab:21:4e:1d:0d:4e:e6:98:
                    85:e5:ab:11:47:5d:9d:3f:c4:23:c0:e3:14:06:6e:
                    fe:9d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/bridge/caCertsIssuedTofbca2013.p7c

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.1
                Policy: 2.16.840.1.101.3.2.1.3.2
                Policy: 2.16.840.1.101.3.2.1.3.3
                Policy: 2.16.840.1.101.3.2.1.3.12
                Policy: 2.16.840.1.101.3.2.1.3.14
                Policy: 2.16.840.1.101.3.2.1.3.15
                Policy: 2.16.840.1.101.3.2.1.3.37
                Policy: 2.16.840.1.101.3.2.1.3.38
                Policy: 2.16.840.1.101.3.2.1.3.4
                Policy: 2.16.840.1.101.3.2.1.3.18
                Policy: 2.16.840.1.101.3.2.1.3.19
                Policy: 2.16.840.1.101.3.2.1.3.20
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.36
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.16
                Policy: 2.16.840.1.101.3.2.1.3.17
                Policy: 2.16.840.1.101.3.2.1.3.40
                Policy: 2.16.840.1.101.3.2.1.3.41
                Policy: 2.16.840.1.101.3.2.1.3.39

            Subject Information Access: 
                CA Repository - URI:http://http.fpki.gov/fcpca/caCertsIssuedByfcpca.p7c

            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.3.3:2.16.840.1.101.3.2.1.3.6, 2.16.840.1.101.3.2.1.3.4:2.16.840.1.101.3.2.1.3.16, 2.16.840.1.101.3.2.1.3.12:2.16.840.1.101.3.2.1.3.7, 2.16.840.1.101.3.2.1.3.37:2.16.840.1.101.3.2.1.3.8, 2.16.840.1.101.3.2.1.3.38:2.16.840.1.101.3.2.1.3.36
            X509v3 Inhibit Any Policy: critical
                0
            X509v3 Policy Constraints: critical
                Inhibit Policy Mapping:1
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:BB:CE:74:71:83:34:4E:59:32:45:15:5F:40:60:60:DC:2B:B0:B4:E4

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/bridge/fbca2013.crl

            X509v3 Subject Key Identifier: 
                AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC
    Signature Algorithm: sha256WithRSAEncryption
         7d:ca:6e:2b:56:3a:f7:f9:93:a8:c0:49:ed:15:76:ac:d7:d3:
         13:17:b1:21:d5:3a:ee:7c:1a:76:94:f6:8b:3c:8d:e2:a5:0a:
         17:20:8d:de:35:e5:d4:fd:f6:a5:25:2b:d4:ca:33:32:5e:cd:
         38:0e:68:1d:16:02:f3:c2:35:0f:96:ae:0b:29:82:5b:9e:6c:
         3a:de:5f:b3:d4:00:6c:d6:cc:f6:7c:21:6f:2a:ba:44:e3:03:
         1f:af:23:e2:75:7a:b1:bd:83:83:bb:25:60:f6:df:e5:46:da:
         70:29:aa:20:6c:e3:1a:99:2c:df:8f:42:a6:2d:ff:d8:a7:75:
         6e:bc:f1:e3:fd:77:b6:29:cd:94:2f:55:a1:cb:35:47:20:83:
         79:c0:bb:34:93:68:13:a9:c0:a6:ae:37:9b:73:6c:e7:df:04:
         63:a6:95:95:71:e9:09:60:3d:d7:70:3e:c9:41:b8:1f:ba:e6:
         9b:87:eb:fb:93:2b:5d:3e:fd:8f:c8:aa:4c:b4:77:65:b1:3e:
         31:82:9a:74:cb:17:84:59:29:72:9d:89:e2:12:8f:b2:8c:9c:
         bd:15:de:83:2d:34:e3:5d:59:2e:45:1c:9f:8f:07:6b:c0:dd:
         0c:94:a4:b5:44:20:26:89:59:21:e4:8f:22:8f:3a:5a:f2:44:
         c0:00:15:86
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 36 (0x24)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA
        Validity
            Not Before: Jul 25 14:35:05 2007 GMT
            Not After : Jul 26 13:35:05 2013 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=IdenTrust ECA 1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:d4:21:67:0e:7f:6f:0d:15:2a:0a:8a:c9:4a:76:
                    48:7e:17:9d:e8:40:a0:20:81:be:46:be:37:14:b8:
                    cb:d3:bf:a6:85:2f:23:bf:7b:09:fd:3b:ed:59:4d:
                    64:27:22:b1:3f:c0:e9:65:9e:bd:2c:f2:21:e3:b8:
                    f8:b9:61:45:88:db:59:20:6a:4b:f8:80:8e:10:e6:
                    f4:e2:23:ac:df:15:63:1c:0b:0a:99:bc:18:71:bd:
                    db:67:3a:72:f2:44:df:ca:d1:89:ac:d7:9a:36:d6:
                    3b:6e:67:e6:e9:69:13:70:f0:72:2f:93:53:0b:70:
                    0e:76:5b:49:9b:30:ba:06:97
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:F6:B8:04:27:0E:56:16:D9:B9:63:D9:FD:A1:54:65:41:A0:08:48:2F

            X509v3 Subject Key Identifier: 
                F7:33:60:4C:C0:D1:E4:80:34:15:ED:14:72:15:05:EA:86:77:78:C0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                Policy: 2.16.840.1.101.3.2.1.12.2

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

                Full Name:
                  URI:http://crl.chamb.disa.mil/getcrl?ECA%20ROOT%20CA

            Authority Information Access: 
                CA Issuers - URI:ldap://crl.chamb.disa.mil/cn%3DECA%20Root%20CA%2Cou%3DECA%2Co%3DU.S.%20Government%2Cc%3DUS?cACertificate;binary

    Signature Algorithm: sha1WithRSAEncryption
         18:17:9d:ee:b8:b9:a2:ed:a2:61:4b:14:77:62:a8:87:7c:25:
         b2:58:52:c5:60:2e:e2:dc:47:42:6c:03:f6:24:88:26:0a:1b:
         38:a0:5d:6a:97:91:5f:b9:ac:e9:96:33:0a:4e:0f:9d:9b:77:
         f6:9a:a8:87:43:ac:6a:7e:9b:4a:ef:16:ca:d1:ec:36:0d:dd:
         f7:43:d3:e2:a6:9b:10:6d:98:86:43:ef:c6:2c:de:9f:91:ee:
         e6:40:5d:dc:11:c6:62:4d:79:d1:ec:58:45:49:1c:e9:6f:3a:
         ce:c6:5a:de:e7:f3:61:52:1b:c5:ce:c8:6a:72:26:a6:d0:b7:
         76:73
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 6 (0x6)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA 2
        Validity
            Not Before: May  7 15:43:06 2008 GMT
            Not After : May  6 15:43:06 2014 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=IdenTrust ECA 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a9:d5:0f:af:2a:fe:ca:63:55:4c:10:6e:74:4f:
                    60:c9:ed:6b:d7:25:a3:69:8c:a8:11:f7:2a:3b:d5:
                    0b:1f:b4:69:05:5c:04:b1:3f:e3:29:17:d6:ef:c9:
                    14:5b:94:c0:12:25:31:60:18:09:30:17:3e:67:cd:
                    85:c7:49:70:77:4e:c1:f9:a9:e3:65:a4:3b:fe:62:
                    63:65:1c:f4:47:22:9a:42:89:6f:dd:d3:99:68:74:
                    36:8d:76:cd:14:07:55:b9:7b:c0:6a:4b:ce:7c:b6:
                    17:72:62:35:93:30:13:0a:e0:5d:84:3e:5f:b2:57:
                    87:fb:d3:ba:a1:c3:60:13:ad:74:fa:e5:ad:ff:11:
                    c1:79:1d:0b:1d:83:ba:04:47:fb:2a:90:f2:f9:6e:
                    b0:e7:6c:60:4d:1d:ab:54:c7:d3:de:aa:6a:71:8a:
                    f0:7a:2e:0d:0a:4b:93:8e:4a:6f:68:05:03:2c:96:
                    72:b8:95:3f:a7:69:37:fa:d8:e3:70:37:43:c6:5a:
                    6c:35:80:78:20:27:58:17:b4:9c:77:bb:4c:cf:5c:
                    43:c4:c9:4e:22:08:df:ef:26:7e:a1:28:ef:b0:55:
                    d2:a8:ff:35:ca:da:ac:6f:66:df:ef:5d:42:82:fd:
                    4d:c3:99:34:43:2e:17:c6:ca:99:9b:a1:38:bc:a9:
                    55:0b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                5C:4E:73:E2:4A:BE:DC:80:21:F7:5F:92:CA:0E:BF:D6:D9:4D:63:FD
            X509v3 Authority Key Identifier: 
                keyid:ED:E4:87:D0:27:C4:50:E6:84:3A:F7:CC:F7:EB:3A:49:FC:52:4E:21

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                Policy: 2.16.840.1.101.3.2.1.12.2
                Policy: 2.16.840.1.101.3.2.1.12.3

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?ECA%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?certificateRevocationList;binary

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?ECA%20Root%20CA%202
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary,crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         77:ff:93:2c:08:4f:05:11:56:ef:42:64:84:b5:9b:db:4b:7b:
         21:27:8c:78:69:09:f6:25:86:74:8b:85:7a:97:23:63:70:61:
         06:3d:31:46:0d:b7:7d:07:84:3f:9a:c6:49:8f:23:7b:90:67:
         4c:60:1a:64:a3:48:aa:ec:88:bc:f4:1a:14:eb:a7:f4:ff:fd:
         96:95:70:39:cf:8c:d0:4b:76:a4:86:50:dd:ee:70:89:56:1d:
         52:7f:19:af:a1:ba:1d:a8:99:67:71:cb:4a:b4:a6:45:32:88:
         f6:ed:a2:e5:0a:3f:d8:60:83:81:61:d1:0a:13:5e:e2:5f:1f:
         6a:08:9b:6c:6b:fb:ad:a3:12:83:6d:1e:fe:eb:2c:dc:2f:e2:
         e0:3c:d7:d5:ee:00:bf:22:31:c5:f6:3f:3a:84:6e:65:35:71:
         de:20:b5:6f:2b:0d:6c:d9:fa:99:5a:3a:24:d9:be:b8:71:65:
         99:74:f0:dd:e4:2c:ff:84:9f:9e:d9:b1:59:91:52:0f:d7:c3:
         fa:07:90:86:83:93:90:50:ea:8b:63:a2:5e:f7:4b:5c:71:35:
         da:a3:56:4b:9f:b9:e6:a2:9c:f7:20:cd:e1:f2:ae:0a:57:f1:
         86:c8:3f:be:63:94:b3:3a:c6:f2:fe:0b:af:b5:e7:8b:69:a9:
         5d:ac:e1:a1
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 26 (0x1a)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA
        Validity
            Not Before: Jun 14 13:04:51 2004 GMT
            Not After : Jun 15 12:04:51 2010 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=ORC ECA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:87:e6:de:6a:8c:58:bc:ea:52:13:d5:c0:23:e7:
                    30:cb:60:f0:56:f0:0a:0a:f4:82:e6:44:02:65:9d:
                    6f:e7:08:99:04:0b:fb:22:70:3a:f0:42:cf:fd:76:
                    5a:5e:69:b7:32:7d:5d:c4:58:5a:52:02:9c:7c:60:
                    29:b8:0c:d4:c7:69:2e:fb:1f:d6:e4:b9:7e:e2:09:
                    79:37:65:1e:f6:06:64:9d:b1:b6:f4:18:e1:6f:97:
                    c6:51:75:ae:32:67:17:b1:84:5c:cd:12:2c:ec:c5:
                    45:23:ec:8a:b8:f2:7e:f8:e8:a5:ba:c2:b0:77:cf:
                    1e:b1:8f:9a:b0:23:af:3f:cd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:F6:B8:04:27:0E:56:16:D9:B9:63:D9:FD:A1:54:65:41:A0:08:48:2F

            X509v3 Subject Key Identifier: 
                AC:F7:4B:B6:D6:D2:36:69:F3:BB:A2:03:67:97:19:87:33:65:2E:A5
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                Policy: 2.16.840.1.101.3.2.1.12.2

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

                Full Name:
                  URI:ldap://eca-ds.orc.com/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

            Authority Information Access: 
                CA Issuers - URI:http://eca.orc.com/certs/ecarootca.p7c

    Signature Algorithm: sha1WithRSAEncryption
         0c:ec:cc:19:26:17:d8:1e:ad:ec:d8:05:0e:2b:76:42:2c:3e:
         32:16:f5:ac:19:a7:84:94:72:18:b7:cf:1c:9f:ce:7b:55:43:
         10:d6:5c:45:ae:73:36:b2:d2:ce:f3:b4:38:d0:2b:e4:c7:b8:
         cc:db:11:84:b6:53:3f:29:c5:c6:2c:3a:c8:e1:c0:4c:04:25:
         13:7a:61:3b:4a:b8:72:28:85:79:4c:6e:f4:a5:0a:dc:ac:83:
         8f:87:ad:02:b5:8e:a2:bd:c2:2a:1e:7c:70:aa:a4:8c:f6:25:
         4b:6a:fd:9a:08:76:cd:44:0f:d9:af:3d:a0:ee:ad:15:e5:1a:
         b4:d2
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 34 (0x22)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA
        Validity
            Not Before: Jun 21 13:00:23 2007 GMT
            Not After : Jun 22 12:00:23 2013 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=ORC ECA 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:f2:88:3c:bb:3e:af:85:9d:6a:a5:e0:99:54:6f:
                    d8:49:17:94:6b:c9:ee:28:ef:0f:bb:91:2a:11:3b:
                    9b:1c:88:36:92:dc:81:3e:8a:b3:cb:91:0f:78:f4:
                    a1:88:69:db:6f:24:ee:08:44:b2:6e:79:bd:a5:aa:
                    4e:ba:4d:f1:dc:e8:77:1c:d9:0d:49:b9:24:5d:44:
                    9f:3b:39:b3:6f:c5:e1:14:8e:5b:9f:63:d9:02:64:
                    a3:c9:8a:fd:ed:91:7e:c6:12:dd:fb:12:49:6a:70:
                    a6:b4:ab:22:f4:32:6f:c6:9f:27:a1:2d:0c:66:b2:
                    c4:45:28:a9:07:a9:dc:4e:b3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:F6:B8:04:27:0E:56:16:D9:B9:63:D9:FD:A1:54:65:41:A0:08:48:2F

            X509v3 Subject Key Identifier: 
                AA:E4:E7:63:72:DD:5D:AE:81:ED:BB:51:50:5D:F1:35:71:7D:FD:9C
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

                Full Name:
                  URI:ldap://eca-ds.orc.com/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

            Authority Information Access: 
                CA Issuers - URI:http://eca.orc.com/certs/ecarootca.p7c

    Signature Algorithm: sha1WithRSAEncryption
         15:29:71:b6:75:b6:95:5c:01:0e:3a:15:bd:0d:27:17:45:ce:
         43:ff:8f:d7:e7:22:4d:cf:d5:6d:20:f8:c4:52:02:c6:44:97:
         db:f0:99:19:36:b8:11:f0:9f:2d:09:c7:21:32:09:6b:00:f6:
         eb:db:1f:ee:45:84:be:d0:f3:03:72:92:c2:b4:5d:39:be:c7:
         90:fd:f3:1a:34:01:8b:09:48:d5:96:87:40:87:8d:b8:37:44:
         b6:bb:ad:97:7a:a8:63:0b:ab:18:92:6e:1d:51:90:22:3b:8f:
         11:77:81:5f:83:5b:0a:96:f6:94:3d:38:a3:2f:80:40:d2:ae:
         45:55
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 35 (0x23)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA
        Validity
            Not Before: Jun 29 11:33:36 2007 GMT
            Not After : Jun 30 10:33:36 2013 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=ORC ECA Foreign Nationals CA 1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:c0:94:5a:c3:3e:4b:98:82:bd:68:6c:87:b4:d6:
                    07:e2:dc:7c:60:59:22:6a:fd:3d:cc:20:d2:8d:70:
                    5e:12:05:cf:22:a4:09:18:4d:62:85:a4:90:64:32:
                    1c:17:a0:e5:d4:bc:c7:9a:46:bf:b2:62:a5:0e:70:
                    b4:47:7d:5a:da:e2:64:08:bf:c0:77:f4:69:47:34:
                    6f:cd:4b:61:00:ca:31:3b:12:b5:57:f2:d9:a5:c7:
                    ec:49:31:3b:f4:e8:d2:f5:b8:e4:88:47:8c:33:ae:
                    2e:5c:39:5a:7a:66:73:61:53:8e:6b:d0:b9:c9:d3:
                    e2:a2:4e:c1:3f:0b:07:7a:11
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:F6:B8:04:27:0E:56:16:D9:B9:63:D9:FD:A1:54:65:41:A0:08:48:2F

            X509v3 Subject Key Identifier: 
                9A:98:A4:0E:B1:FE:95:2D:3F:F5:F4:23:86:60:A3:C4:CB:E4:4B:52
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

                Full Name:
                  URI:ldap://eca-ds.orc.com/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

            Authority Information Access: 
                CA Issuers - URI:http://eca.orc.com/certs/ecarootca.p7c

    Signature Algorithm: sha1WithRSAEncryption
         89:e1:db:10:64:c6:f6:8a:b0:81:a4:5c:ce:0b:17:ff:b3:8d:
         46:da:86:3f:13:ce:60:20:6c:d2:6e:72:76:d5:b1:45:70:03:
         9d:23:4d:3e:9d:2a:b8:f8:0f:55:3f:bd:5f:d5:0b:6a:4e:95:
         41:a5:10:00:7b:f7:f8:7f:15:f5:75:37:26:96:b1:74:e2:58:
         df:7b:b5:2a:3f:cf:d1:18:e1:fe:e9:dc:34:bc:df:e1:e5:7e:
         4e:ee:3f:71:f6:bb:0b:14:f5:1f:42:eb:e2:cf:ee:03:66:82:
         0b:59:d9:79:46:25:ec:39:61:8e:f1:14:42:8d:e7:de:76:d1:
         56:d5
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 8 (0x8)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA 2
        Validity
            Not Before: Jun 11 13:43:46 2008 GMT
            Not After : Jun 10 13:43:46 2014 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=ORC ECA HW 3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a1:04:a1:55:2b:21:00:65:89:24:03:ea:47:95:
                    33:d2:24:ac:b4:c5:35:87:3e:ab:32:50:81:2c:5c:
                    85:b9:28:8f:02:64:de:b5:b3:f4:27:32:65:03:ec:
                    d0:81:56:fb:eb:5b:be:66:96:70:d9:d3:24:16:fa:
                    6b:8c:7f:9c:6c:05:f2:7e:3b:10:5a:cc:70:12:44:
                    6f:34:f4:78:5f:52:0f:9d:87:d2:2e:3b:d7:51:cf:
                    a3:9c:a4:90:28:bf:fd:02:e4:51:5a:35:35:91:98:
                    18:61:89:63:fe:97:d2:0c:99:c2:4c:9a:3b:97:11:
                    ee:7c:b8:6b:90:16:a8:59:21:17:53:0a:36:94:6a:
                    ae:1e:f1:25:46:a0:b7:39:8c:d0:93:0d:d7:b4:0d:
                    86:40:ae:a0:ee:7b:55:31:ee:26:62:fc:8c:fa:70:
                    5c:7c:da:92:45:3a:b6:da:05:f8:20:11:ce:6d:03:
                    6f:9b:f7:8e:b7:60:80:15:00:7e:cc:20:63:78:e4:
                    a1:e6:59:3d:ad:d3:cc:0d:44:a1:a8:6d:83:3d:b3:
                    95:3f:2a:74:85:a8:89:39:7f:91:79:5a:c3:6e:c2:
                    af:20:06:ca:e5:34:3e:24:df:41:da:43:c5:3b:4d:
                    c2:fb:dd:af:3d:90:e8:71:b9:57:85:0b:29:d0:42:
                    08:49
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                35:00:98:42:DD:ED:E7:1E:0F:C7:C0:C7:6E:68:A6:C6:85:FB:7D:07
            X509v3 Authority Key Identifier: 
                keyid:ED:E4:87:D0:27:C4:50:E6:84:3A:F7:CC:F7:EB:3A:49:FC:52:4E:21

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                Policy: 2.16.840.1.101.3.2.1.12.2
                Policy: 2.16.840.1.101.3.2.1.12.3

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?ECA%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?certificateRevocationList;binary

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?ECA%20Root%20CA%202
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary,crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         91:44:01:a7:a9:f3:d6:e1:da:9f:d0:8d:f6:73:c0:bd:0e:ff:
         78:f5:8c:20:e0:24:06:8b:4c:00:67:1f:df:2d:37:d7:9f:65:
         2e:64:bf:35:f7:38:e4:d0:80:b9:b6:be:9b:b9:a2:d8:f9:39:
         9e:ed:e4:28:f5:20:1e:94:9a:26:59:75:1b:ce:e5:12:ca:fa:
         3e:c8:b9:7a:62:b2:01:e3:59:35:2b:44:bc:01:60:98:0e:38:
         19:0c:78:d7:bb:35:8c:82:55:25:95:a3:4b:f7:a6:46:4c:0d:
         8d:05:d4:b8:28:51:ba:05:dc:ad:e1:e2:6d:1c:6d:18:53:4e:
         ab:2f:26:9f:d6:f4:6f:a3:01:30:54:07:e8:84:9f:2b:b1:93:
         9b:89:40:b6:95:ab:cf:df:ca:0a:69:6b:a8:bc:30:a8:00:2c:
         a1:02:00:87:d6:30:a3:72:df:fb:fb:6b:cd:6e:a2:4f:19:c5:
         24:53:52:11:d3:96:c4:50:a1:60:e0:d5:0b:75:97:39:b7:44:
         04:8c:69:5b:96:31:f0:99:f5:79:8c:5d:f3:98:42:8d:e8:40:
         79:b0:f3:f3:4d:f1:3b:a4:40:e8:a2:6a:44:6b:0f:5f:c9:41:
         85:0d:08:43:d5:61:d0:e5:ea:ea:ba:31:78:58:2f:02:dd:56:
         a4:08:a8:50
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 7 (0x7)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA 2
        Validity
            Not Before: Jun 11 13:37:30 2008 GMT
            Not After : Jun 10 13:37:30 2014 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=ORC ECA SW 3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d0:34:fc:5e:d8:bb:97:00:6b:69:9c:dc:54:ba:
                    c1:c8:c7:c0:ca:32:7b:7b:6c:64:5c:58:2e:66:16:
                    fe:0e:d3:b0:7d:ee:66:f2:26:c4:da:f6:ae:ce:88:
                    04:f5:7a:c6:6a:01:0f:61:a1:f1:3e:db:17:93:3c:
                    14:df:30:82:ad:ae:65:4a:f0:68:6a:2a:29:89:22:
                    d9:36:42:fd:7c:35:ca:2b:16:06:f7:29:2d:e7:c5:
                    26:c5:b9:6d:f9:73:73:c6:b8:37:ed:be:bc:16:e7:
                    32:0c:b5:55:13:1d:a3:3a:02:cd:f5:d7:07:d9:bf:
                    12:60:29:d4:b6:ad:83:63:88:3a:05:a7:70:c4:63:
                    3c:4a:d3:01:c6:66:a0:9b:e8:ed:6b:de:13:00:04:
                    b7:99:b3:be:86:8b:ad:de:4e:4b:10:1f:34:fc:0e:
                    f3:53:ba:4a:c3:f1:20:a0:6f:b2:50:72:01:56:18:
                    b6:82:7c:2f:4f:19:58:2a:9a:a7:96:a5:a5:b9:65:
                    c7:30:b4:3c:57:5d:5d:2d:b1:2c:ff:74:c0:8f:5e:
                    20:4e:ea:64:94:58:43:55:68:52:40:cc:2b:e9:2c:
                    c6:a5:08:cb:87:27:30:3b:60:6f:ea:01:df:9f:09:
                    65:9a:2f:9c:56:4f:73:51:1f:80:e1:3e:91:5f:22:
                    cc:81
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                EA:64:28:CF:BA:C7:D0:80:B8:29:20:8E:BB:DE:D8:39:85:36:10:5F
            X509v3 Authority Key Identifier: 
                keyid:ED:E4:87:D0:27:C4:50:E6:84:3A:F7:CC:F7:EB:3A:49:FC:52:4E:21

            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                Policy: 2.16.840.1.101.3.2.1.12.2
                Policy: 2.16.840.1.101.3.2.1.12.3

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?ECA%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?certificateRevocationList;binary

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?ECA%20Root%20CA%202
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary,crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         5d:8d:4e:88:08:a8:fc:b8:02:02:be:16:1b:5b:3e:98:cd:88:
         84:9d:61:41:a9:ee:b1:ca:43:a9:c5:9b:ad:8c:a7:48:f6:75:
         84:ff:a8:9f:eb:86:e9:30:6e:ba:42:89:3e:06:7f:34:02:d8:
         67:4e:96:d5:29:2d:7d:92:a5:ca:27:03:b1:0e:5d:8f:f0:ca:
         81:2c:3e:5b:a9:10:d8:ef:c6:01:28:58:31:64:36:14:99:86:
         69:7d:a4:2e:ba:2b:ed:c7:de:26:43:22:c1:a5:de:cc:fb:7a:
         24:86:de:6e:0c:33:0f:c9:7b:b1:46:14:d6:4b:42:77:c7:87:
         85:ac:d8:1b:93:7d:9c:88:ac:eb:a9:fe:ce:89:27:d6:b0:a2:
         01:8f:ee:f5:4d:8c:80:fb:5e:c5:3f:43:70:b1:89:7c:58:29:
         0b:74:1a:fd:6b:27:97:03:61:83:34:62:ec:0d:b8:12:96:38:
         9a:6a:09:9b:b4:32:a0:40:5d:1b:3e:af:80:63:ec:09:b5:95:
         f9:36:d4:fc:e8:73:b7:c0:ee:0a:5d:a7:ff:32:df:cc:58:bb:
         22:c6:62:ba:1d:6a:9a:6f:ce:a1:08:1a:5f:2c:be:b4:2c:5f:
         ac:37:2d:05:70:58:cf:12:54:7e:56:b0:70:2e:1e:22:c6:6b:
         20:12:87:2d
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 706 (0x2c2)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Jan 12 00:54:57 2011 GMT
            Not After : Jan 12 00:52:59 2021 GMT
        Subject: C=US, O=ORC PKI, CN=ORC SSP 3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a7:96:c1:d9:92:15:da:8a:b2:46:f8:32:3a:1b:
                    17:b7:96:dd:62:81:e1:74:00:f7:74:19:a2:d0:79:
                    d4:4a:49:77:01:d9:2a:25:4c:59:76:64:f5:f2:d6:
                    a5:37:db:f7:40:46:9d:94:fd:81:cd:7f:7b:ea:95:
                    84:14:6c:00:d1:b1:0c:c4:cb:49:65:f6:6a:e0:8f:
                    00:b7:cf:47:fb:98:4f:4b:af:ac:ef:1a:9f:61:ea:
                    83:58:d8:42:15:11:03:97:98:0c:19:40:5e:96:9c:
                    0d:22:f2:c8:db:b5:3c:0f:9b:45:6e:d3:c1:84:16:
                    dc:d3:4c:ea:c9:00:85:a5:0f:76:22:16:c2:e7:b3:
                    45:ec:ad:bd:ff:77:19:13:c8:be:54:67:c2:d8:f6:
                    31:91:67:bf:bd:af:a0:ee:ae:6e:ac:42:14:82:01:
                    9f:eb:1b:74:d3:8b:80:b6:4e:ca:fb:66:78:dc:c2:
                    8b:78:8c:97:21:cb:97:1f:f6:d2:e7:4a:2c:d8:42:
                    16:eb:69:30:32:4b:8a:4c:cd:97:38:9f:56:ed:2b:
                    ca:6d:f1:9a:3b:fb:50:c7:2b:04:ae:27:fe:31:7d:
                    c5:8f:2c:dd:3b:c9:f6:ec:14:7b:9b:0d:79:66:70:
                    49:2f:19:ec:63:46:5c:f1:06:e9:5d:01:be:32:58:
                    ed:c3
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c
                CA Issuers - URI:ldap://ldap.fpki.gov/cn=Federal%20Common%20Policy%20CA,ou=FPKI,o=U.S.%20Government,c=US?cACertificate;binary,crossCertificatePair;binary

            Subject Information Access: 
                CA Repository - URI:http://crlserver.orc.com/caCerts/ORCSSP3.p7c
                CA Repository - URI:ldap://orc-ds.orc.com/cn%3dORC%20SSP%203%2cO%3dORC%20PKI%2cC%3dUS?cACertificate;binary,crossCertificatePair;binary

            X509v3 Key Usage: critical
                Digital Signature, Non Repudiation, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

                Full Name:
                  URI:ldap://ldap.fpki.gov/cn%3dFederal%20Common%20Policy%20CA,ou%3dFPKI,o%3dU.S.%20Government,c%3dUS?certificateRevocationList

            X509v3 Subject Key Identifier: 
                6A:88:6D:52:FC:B1:44:9E:30:AE:33:18:4D:C0:39:9D:96:6B:24:B0
    Signature Algorithm: sha256WithRSAEncryption
         38:04:4d:28:fa:c5:bd:93:b1:9c:71:61:b9:eb:12:c3:5d:3a:
         cd:fd:a2:dc:82:1d:b0:1d:54:11:19:4d:d1:1b:22:05:bc:29:
         a8:ea:10:7a:68:55:03:d5:a5:eb:e2:92:8f:b2:04:09:55:ba:
         54:cb:bb:82:ce:45:f7:e0:e8:6a:27:50:cd:ab:ff:99:09:90:
         95:38:b6:8b:c4:18:9c:fa:c2:2a:7f:e4:61:ea:6c:e5:d9:f2:
         68:f6:cf:c9:33:4c:45:0a:09:b1:de:07:bc:e9:2d:44:65:84:
         78:34:2b:c3:f0:79:3e:da:2f:90:2a:47:2e:41:bf:db:21:6e:
         93:47:91:83:45:d1:66:e2:32:38:28:df:84:bd:68:a0:04:2e:
         a9:b5:ad:37:15:36:dd:7c:97:d4:64:80:c1:da:3e:e7:04:66:
         dc:e4:18:86:03:ce:98:46:ce:64:20:58:76:a3:3f:69:da:04:
         c7:3a:82:4a:a7:14:42:7d:83:50:c1:1d:a2:74:1c:22:b7:5d:
         8c:8e:03:64:1d:a8:0a:ee:71:cd:fb:0f:c6:1f:81:d1:10:65:
         c7:07:30:ab:89:0f:d9:9b:8d:b0:c4:4e:e0:8a:d8:67:51:be:
         a0:4b:4e:d9:da:c5:f1:ed:31:73:bb:8e:b7:97:c5:23:52:ff:
         26:75:e4:54
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 12025 (0x2ef9)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Aug 31 15:14:29 2015 GMT
            Not After : Jan 21 16:36:50 2024 GMT
        Subject: C=US, O=ORC PKI, CN=ORC SSP 4
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:af:bc:56:7e:95:09:60:71:95:1b:4a:c4:7b:38:
                    b7:ac:5a:7a:05:28:8e:a7:71:d8:b7:0f:da:31:a9:
                    b3:53:99:9e:7a:0d:b1:db:1c:4e:c8:8b:19:df:8d:
                    a1:d1:de:17:ef:5d:f0:41:f9:ee:9c:cf:0d:e2:44:
                    04:fe:df:5a:55:8e:7e:ac:4f:6e:b0:cb:13:e0:a3:
                    95:7c:42:69:fc:50:7e:e2:75:19:4b:15:41:df:f9:
                    62:d6:04:dc:0f:9f:4e:58:00:9e:99:4b:4f:9d:fa:
                    30:18:85:d0:4f:55:8f:ab:3d:30:9e:57:9f:85:df:
                    49:a5:fc:ca:04:eb:f9:ea:27:43:9d:1f:7e:83:9b:
                    ca:80:79:a6:03:71:6d:b8:c2:c6:3a:14:2a:01:31:
                    4d:bf:02:60:c6:36:76:55:fc:e8:0e:0a:f5:9f:89:
                    36:94:59:0a:69:c1:37:8e:24:35:a3:de:aa:5a:fa:
                    ef:32:49:32:33:c2:98:f2:de:99:67:77:da:c6:95:
                    45:70:38:03:c7:d5:0c:b1:74:6f:ed:a7:2a:05:15:
                    c6:07:97:24:0a:a6:8f:b5:ed:62:b8:c5:ef:de:39:
                    9a:78:7f:57:bd:05:57:1e:8b:b5:d3:14:66:1e:97:
                    e9:2c:0a:c9:c0:dd:96:ab:cc:14:cf:f1:5d:53:b7:
                    72:39
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.36
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17
                Policy: 2.16.840.1.101.3.2.1.3.39

            Subject Information Access: 
                CA Repository - URI:http://crlserver.orc.com/caCerts/ORCSSP4.p7c

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c

            X509v3 Policy Constraints: critical
                Inhibit Policy Mapping:0
            X509v3 Inhibit Any Policy: critical
                0
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

            X509v3 Subject Key Identifier: 
                14:0B:99:1F:98:1F:64:8C:6F:C3:FF:7A:D5:FF:F5:F8:4E:49:9C:21
    Signature Algorithm: sha256WithRSAEncryption
         03:71:e0:18:9f:9f:a9:9e:55:af:14:11:21:43:23:3e:39:0b:
         c4:1e:a0:86:8c:af:96:96:a6:ee:bb:9a:72:ee:07:ac:34:95:
         46:2c:af:90:bb:7f:de:f2:af:d9:16:cb:38:b8:69:6a:2f:4b:
         91:a1:8a:c5:fc:fb:25:e1:d3:0a:22:01:69:4a:29:b9:a6:de:
         9c:9f:0b:7f:7a:94:78:f6:36:4d:17:9a:c3:06:f0:ab:21:1f:
         e4:f8:0a:c9:7c:de:75:f9:92:5c:3c:b8:7f:f8:40:47:e4:cc:
         05:b0:ea:8e:08:1f:d0:03:4d:cf:75:b3:f4:4b:60:93:be:c0:
         61:dc:c0:23:aa:23:51:70:ac:ec:b0:25:08:e9:bb:bf:5f:9f:
         7d:c2:30:ed:52:34:52:c7:63:e3:7a:6a:fe:05:c5:68:fb:ae:
         0d:58:7e:99:ef:7c:9e:96:05:12:4f:93:d1:e5:dd:a5:ab:a4:
         06:42:7f:9f:29:8d:af:1b:70:2d:95:30:44:53:48:19:28:97:
         b3:38:6f:d6:e0:50:e7:c0:18:bb:fc:53:88:a2:cd:2b:93:f7:
         bf:79:9a:a3:e9:50:f5:29:1d:a9:d1:ad:fc:04:02:7f:4d:04:
         fd:68:ef:b7:a3:f1:69:21:c2:a3:57:01:9c:44:6c:0b:93:ff:
         f0:75:35:32
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 5915 (0x171b)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Dec  3 17:37:18 2013 GMT
            Not After : May  2 16:36:28 2017 GMT
        Subject: C=US, O=U.S. Government, OU=FPKI, CN=SHA-1 Federal Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a7:07:9e:05:3a:5c:7e:b1:ff:b0:99:12:ba:65:
                    72:3e:c3:32:3e:8f:8a:05:4c:32:f8:31:15:ba:80:
                    39:f3:66:60:78:ae:b7:e8:8e:fe:6a:f5:60:53:64:
                    33:2e:e6:33:40:c9:21:23:df:6a:b1:33:4e:71:4e:
                    f1:fc:72:e4:ae:91:99:2a:c1:29:9a:8d:74:ff:b1:
                    32:39:02:72:09:9b:65:c8:07:11:af:b2:38:b5:c6:
                    8e:fd:b0:18:c1:ea:11:9d:29:64:8f:28:30:38:e9:
                    48:14:76:1c:47:93:ec:96:40:c1:ca:59:85:51:0c:
                    57:3f:bb:e1:c2:c4:7a:3b:0a:19:fb:60:96:8b:65:
                    6e:e5:29:3d:c0:39:57:b7:00:ae:11:ae:a9:07:85:
                    e3:72:38:e9:ba:6e:33:01:50:cb:d4:bf:a7:41:c4:
                    3f:9b:78:fc:01:98:91:f3:e8:2c:88:22:68:22:cf:
                    94:4a:14:58:79:43:95:ea:40:9a:90:84:7a:dd:67:
                    13:00:95:49:30:94:b2:85:29:90:a7:68:bd:7e:f6:
                    36:68:d3:c7:f9:94:31:53:fb:22:d2:2b:1c:92:ae:
                    d7:da:2f:15:7e:0c:63:a0:dd:db:a5:4c:78:82:e3:
                    43:dd:58:83:1c:c3:fe:6e:6f:81:f2:0b:b3:65:54:
                    90:4f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.21
                Policy: 2.16.840.1.101.3.2.1.3.22
                Policy: 2.16.840.1.101.3.2.1.3.23
                Policy: 2.16.840.1.101.3.2.1.3.24
                Policy: 2.16.840.1.101.3.2.1.3.25

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c

            Subject Information Access: 
                CA Repository - URI:http://http.fpki.gov/sha1frca/caCertsIssuedBysha1frca.p7c

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

            X509v3 Subject Key Identifier: 
                86:9A:5C:62:FF:73:93:D5:E1:8A:7F:4A:C6:88:2E:9F:6E:A0:AE:12
    Signature Algorithm: sha256WithRSAEncryption
         bd:b9:83:66:9d:1b:61:f3:e5:e0:09:59:33:d8:a7:53:33:60:
         c5:df:95:d6:84:2c:88:b4:1a:b0:96:f9:ab:84:9a:17:00:1f:
         48:cc:52:98:bd:50:07:10:43:b4:74:66:41:5a:77:0e:39:9b:
         4f:19:1d:04:69:96:94:3c:af:9f:e6:3d:bc:74:8c:de:07:9d:
         77:9f:79:cb:f2:6d:9a:fc:fb:91:2d:62:94:f9:0a:76:43:3f:
         23:a1:06:75:3a:a7:8d:ef:40:2e:81:76:ba:62:4c:ca:a1:39:
         c2:a5:5f:c1:ef:ac:5e:70:65:ec:b5:76:cf:f1:9c:a3:68:ca:
         a4:84:a1:72:ce:a8:31:8d:c0:e0:67:a5:7f:ba:8d:f8:6f:09:
         55:ce:70:16:2a:85:73:a1:2c:9f:15:89:9b:60:2e:d0:cc:ac:
         51:97:13:08:74:17:50:17:75:cb:d4:cc:b5:7d:15:f2:5c:86:
         7b:d5:4d:8d:27:ae:5f:eb:44:4e:4f:98:f6:05:1e:ad:6f:4c:
         54:54:db:ff:2d:cb:6a:68:0e:5e:e4:b2:6b:bf:a6:44:3a:54:
         c8:ab:ce:ae:c2:76:de:bc:56:b3:83:d9:7a:7f:96:ce:f0:3e:
         0b:7a:fa:5a:54:39:f6:db:13:7e:2c:83:b2:db:ae:9c:5c:c4:
         d1:cc:e5:2b
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 9604 (0x2584)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Nov 10 17:57:10 2014 GMT
            Not After : Nov 10 17:55:35 2024 GMT
        Subject: C=US, O=Symantec Corporation, CN=Symantec SSP Intermediate CA - G4
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:df:ec:06:91:c8:7c:ed:40:da:50:47:28:0d:06:
                    ee:cc:8a:f2:af:34:3f:9e:96:66:2e:03:a9:b5:05:
                    95:11:38:45:32:ed:8e:c1:7d:0a:36:5e:37:b4:09:
                    92:92:1c:e7:5f:99:89:66:e8:6c:53:28:56:48:ce:
                    35:52:02:bb:5d:db:0c:0e:59:3f:6f:cf:af:a1:d8:
                    68:cc:13:f5:1d:18:2a:4e:22:61:dd:f4:45:e4:ce:
                    87:e2:82:8a:48:f4:fb:58:99:d0:c7:ff:a2:85:7c:
                    8d:65:57:a3:a3:ad:83:ca:ea:a3:14:db:e1:d1:39:
                    7e:e6:c7:34:1b:21:5a:ef:f4:4d:1d:69:25:53:83:
                    35:2e:13:c2:b5:5d:7c:6b:87:88:8a:80:bd:0d:66:
                    b6:ce:53:84:a5:2e:8b:e1:36:99:a6:43:66:f3:e6:
                    65:98:8a:f9:31:b2:b7:4c:ff:83:7b:d9:cf:7a:b4:
                    c8:1f:55:17:8c:64:ad:b8:20:0b:29:3d:f6:61:e9:
                    b9:7f:95:6e:f7:51:2a:82:23:75:54:09:a3:9d:f3:
                    9e:d3:19:09:90:cd:34:5b:40:bb:bf:19:f3:ad:93:
                    9b:92:f5:3b:79:7c:9e:db:09:7d:26:71:6f:47:fb:
                    9c:91:77:0c:dd:af:a1:91:1c:9e:10:e9:ea:a6:cf:
                    47:1b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.36
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17
                Policy: 2.16.840.1.101.3.2.1.3.39
                Policy: 2.16.840.1.101.3.2.1.3.16

            Subject Information Access: 
                CA Repository - URI:http://ssp-sia.symauth.com/SSP/Certs_issued_by_SYMCSSPCAG4.p7c

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c

            X509v3 Policy Constraints: 
                Inhibit Policy Mapping:0
            X509v3 Inhibit Any Policy: 
                0
            X509v3 Subject Alternative Name: 
                DirName:/CN=SymantecPKI-1-762
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

            X509v3 Subject Key Identifier: 
                FF:CC:34:D1:DB:4A:E1:E1:C2:0B:D2:DB:EB:80:7C:73:0C:75:5F:66
    Signature Algorithm: sha256WithRSAEncryption
         9b:62:37:a7:60:25:11:40:95:49:c9:20:9e:21:5b:8e:15:9b:
         3b:e2:4f:fd:24:ae:fb:96:6f:6e:5b:f5:98:ee:c0:e3:6b:f3:
         cb:ab:34:12:9e:dd:39:ba:99:e5:51:fe:fb:8d:22:97:8a:aa:
         f7:b2:3f:f2:35:98:e0:f9:b1:b2:74:54:b9:4a:f3:bc:f8:a7:
         c6:d9:9c:9f:5a:f6:9d:86:75:8d:fa:f7:7d:d9:69:4b:da:49:
         e6:63:b1:fc:b6:7b:79:95:e8:bb:7d:df:f9:4c:dd:e4:28:bd:
         11:7a:e6:10:f1:cb:4f:54:ca:4d:97:f1:24:d1:16:63:cd:0a:
         d7:45:20:4a:a5:5f:5e:77:5a:bc:09:cb:ac:bf:a9:6e:6a:78:
         7d:ec:b1:15:1b:cb:b2:c9:4a:71:8f:dc:a9:8b:f8:49:81:6f:
         d1:e2:f9:54:0a:90:38:5d:a5:c2:e2:6c:c3:bf:a4:2b:71:88:
         fa:cd:6f:0d:10:99:6b:79:6b:43:9c:0d:13:ac:ca:0f:53:30:
         48:66:df:e2:da:d6:a1:82:7f:8f:b3:64:8e:3a:d7:25:89:fc:
         30:54:7b:3d:82:a5:76:f3:68:0a:28:1e:b1:d5:84:fe:bf:71:
         b7:1b:5c:fd:44:60:8d:6b:d9:01:dd:c7:77:2f:6c:e4:78:e4:
         6d:9d:53:95
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 6104 (0x17d8)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Dec 23 11:16:51 2013 GMT
            Not After : Dec 23 11:16:51 2016 GMT
        Subject: C=US, O=U.S. Government, OU=Department of the Treasury, OU=Certification Authorities, OU=US Treasury Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:e8:24:04:59:cc:98:c7:7c:64:b1:6a:d7:3b:29:
                    48:c7:bb:58:ea:df:a2:c4:2a:93:d1:68:d6:8b:83:
                    c2:2a:40:e6:6a:ec:6e:1a:df:e9:23:ef:54:61:da:
                    e5:a2:ed:76:00:69:04:d5:4c:f2:bf:c4:1b:68:85:
                    51:ae:07:a7:38:d9:0a:b3:52:11:36:9f:22:81:de:
                    04:48:77:be:a8:af:b2:f1:78:2e:ac:c4:58:87:50:
                    86:02:0c:7b:37:68:08:9d:62:4d:b5:09:b7:f1:16:
                    73:db:04:e8:46:e9:88:93:25:c8:da:6d:a3:a8:8c:
                    21:df:c6:d7:36:58:20:db:ad:f6:8c:12:80:22:97:
                    58:f4:e3:42:8b:7d:d1:f4:7e:b9:7f:56:ef:ba:31:
                    bc:49:ec:12:af:08:80:b9:e2:97:62:60:7f:ef:83:
                    f9:63:de:eb:70:6e:ab:c4:4f:0f:34:12:a6:cb:ad:
                    26:43:cb:8f:03:c6:f3:9e:24:1e:2a:83:b0:6a:e6:
                    29:ff:57:1e:b1:6e:5f:4f:40:d5:42:b5:aa:d5:b4:
                    51:e4:b2:7b:5b:06:fc:82:a2:cc:b1:16:bf:3e:44:
                    c7:a3:64:b7:82:f6:68:72:db:e6:fe:7b:61:db:fe:
                    ae:75:76:cc:dc:6c:52:d9:bc:07:a8:39:66:eb:8f:
                    9a:cb
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.1
                Policy: 2.16.840.1.101.3.2.1.3.2
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.17
                Policy: 2.16.840.1.101.3.2.1.3.16
                Policy: 2.16.840.1.101.3.2.1.3.36
                Policy: 2.16.840.1.101.3.2.1.3.39

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c

            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.3.1:2.16.840.1.101.3.2.1.5.2, 2.16.840.1.101.3.2.1.3.2:2.16.840.1.101.3.2.1.5.3, 2.16.840.1.101.3.2.1.3.6:2.16.840.1.101.3.2.1.5.7, 2.16.840.1.101.3.2.1.3.7:2.16.840.1.101.3.2.1.5.4, 2.16.840.1.101.3.2.1.3.16:2.16.840.1.101.3.2.1.5.5
            Subject Information Access: 
                CA Repository - URI:http://pki.treas.gov/root_sia.p7c

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

            X509v3 Subject Key Identifier: 
                68:84:15:48:8C:54:70:7F:2D:12:58:0E:EC:1C:78:EF:3C:2E:59:64
    Signature Algorithm: sha256WithRSAEncryption
         48:f5:4a:ee:fb:ce:75:30:86:32:6c:21:a4:57:a8:28:29:e9:
         08:aa:76:cb:cf:ac:bd:b4:00:2a:78:a1:f0:e7:b1:cf:2e:12:
         5d:0a:1b:b5:7f:b0:a7:d8:d7:62:6f:88:bd:bb:6e:dc:92:5a:
         d9:c6:ca:04:d7:e5:79:f8:fd:84:e3:b6:01:00:a9:e9:80:1c:
         ca:b4:79:e7:32:91:a1:4a:ff:92:70:96:85:00:50:bf:5a:74:
         c2:10:91:dd:b1:4f:f7:46:dc:30:39:bc:29:14:05:ce:cd:a1:
         ac:b5:82:88:fe:de:39:91:29:f2:00:bf:e7:ad:66:c0:12:0a:
         83:8f:79:c9:f0:0f:79:cd:d9:f2:6d:d9:46:96:6e:8b:c7:be:
         76:43:9a:de:6a:b1:db:06:db:20:9b:20:5e:34:62:f1:66:01:
         d0:04:79:a1:19:6d:15:e7:3b:83:7a:18:8c:74:fe:4b:73:00:
         b8:47:4a:b4:2b:d0:12:34:03:23:3d:6b:3c:21:bd:cc:cd:ea:
         89:48:cd:28:e5:2b:87:21:88:e0:9f:08:f5:81:af:1b:92:c4:
         4f:ab:86:92:c6:b1:13:c2:87:6e:ef:6d:91:9a:c6:54:74:5a:
         2d:87:2f:28:b6:7d:5c:69:44:fc:c8:1d:1c:d3:b5:39:f0:36:
         ad:0a:a8:76
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 8504 (0x2138)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Aug 11 14:25:02 2014 GMT
            Not After : Aug 11 14:23:59 2017 GMT
        Subject: DC=sbu, DC=state, CN=Configuration, CN=Services, CN=Public Key Services, CN=AIA, CN=U.S. Department of State AD Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:b9:36:5f:b3:b1:05:da:4a:e2:6b:c3:97:7f:4a:
                    5c:10:d9:0a:29:af:d9:6f:9a:55:af:a5:19:6e:b4:
                    f4:a5:ed:7e:43:83:95:92:c9:4d:95:d2:ef:be:24:
                    4d:2e:a6:b3:a1:b3:e6:48:f5:64:b6:ec:c2:be:6b:
                    7d:8e:98:cc:d3:83:a1:d5:ce:93:b7:72:ea:d1:88:
                    cf:e1:e5:f2:6b:00:40:58:15:e5:e8:ba:bd:28:50:
                    76:05:c1:67:02:86:2d:64:d2:66:64:32:b6:f8:58:
                    ef:7e:5a:9a:53:16:52:2f:f5:be:cc:4a:06:8e:a0:
                    7e:54:4d:43:44:e4:70:0c:30:38:0f:55:01:a7:22:
                    cc:72:95:fb:45:ee:29:02:ca:57:78:e4:de:fa:e0:
                    70:cb:76:57:f3:c3:68:f4:44:79:f5:9e:d1:30:da:
                    ad:29:a7:ab:c6:6c:13:7d:fd:13:e1:f7:ba:ce:a8:
                    9a:ca:22:bd:e2:78:4e:01:cf:0d:db:fa:00:05:e3:
                    29:a3:70:a3:a2:82:5d:a5:8a:1f:0f:24:6e:59:a6:
                    e1:a6:3f:03:a6:59:78:7e:ae:6c:27:cc:03:3a:a5:
                    09:87:a7:fc:57:0c:83:ea:27:1e:61:bd:37:e8:38:
                    ab:09:84:18:9e:3e:0c:10:39:cd:1b:95:88:2c:5c:
                    ce:e7
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.2
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.1
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.16

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c

            X509v3 Policy Mappings: 
                2.16.840.1.101.3.2.1.3.1:2.16.840.1.101.3.2.1.6.1, 2.16.840.1.101.3.2.1.3.2:2.16.840.1.101.3.2.1.6.2, 2.16.840.1.101.3.2.1.3.6:2.16.840.1.101.3.2.1.6.3, 2.16.840.1.101.3.2.1.3.7:2.16.840.1.101.3.2.1.6.12, 2.16.840.1.101.3.2.1.3.16:2.16.840.1.101.3.2.1.6.4
            Subject Information Access: 
                CA Repository - URI:http://crls.pki.state.gov/SIA/CertsIssuedByADRootCA.p7c
                CA Repository - URI:ldap://certrep.pki.state.gov/cn=U.S.%20Department%20of%20State%20AD%20Root%20CA,cn=AIA,cn=Public%20Key%20Services,cn=Services,cn=Configuration,dc=state,dc=sbu?cACertificate;binary,crossCertificatePair;binary

            X509v3 Name Constraints: critical
                Excluded:
                  DirName: DC = mil

            X509v3 Policy Constraints: critical
                Inhibit Policy Mapping:0
            X509v3 Inhibit Any Policy: critical
                0
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

            X509v3 Subject Key Identifier: 
                6F:83:FE:82:50:64:65:77:3E:FD:DF:03:9A:CE:29:D1:2F:30:CC:EC
    Signature Algorithm: sha256WithRSAEncryption
         58:9c:5d:3e:70:2b:f9:29:ba:9a:7e:49:fc:85:d9:63:b9:49:
         e1:08:31:ca:55:52:fb:83:2b:26:65:40:ac:21:ea:f3:ce:49:
         4f:59:a0:ab:5a:04:ce:fb:24:73:20:0e:e8:1d:7e:27:a3:db:
         0b:56:9a:ee:f1:eb:d0:2f:92:10:55:85:02:9c:72:28:09:63:
         d6:f4:b2:2f:b7:b7:8a:24:78:b4:29:d4:e5:6c:ae:49:4c:de:
         92:36:8d:4c:56:7d:73:d4:bf:83:d7:99:d4:86:ea:ac:dd:be:
         45:5b:10:a5:f4:06:ce:d1:5e:6d:b2:20:08:ab:a7:4d:ae:17:
         5f:85:42:48:38:bc:c3:7d:f3:36:e0:73:82:df:02:03:11:10:
         1f:66:23:c2:2e:c2:b4:9c:e1:e2:c5:6f:1d:35:0f:17:b1:3e:
         99:54:9e:31:87:12:7d:cd:6d:8e:db:0a:7f:b1:62:61:9f:31:
         94:61:de:37:21:81:f4:02:b8:87:94:1c:98:27:71:1f:bd:6b:
         6e:ef:8c:a9:88:8f:42:e7:18:27:cd:6f:ab:ab:37:b8:0f:11:
         b7:f3:e4:02:d1:5e:24:20:1e:5a:74:68:21:44:3f:ea:74:f1:
         25:c3:88:4c:0b:36:db:64:61:ac:f8:e2:46:a1:fa:e2:87:3b:
         74:1b:23:4c
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 20 (0x14)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA
        Validity
            Not Before: Jun 28 16:39:03 2005 GMT
            Not After : Jun 29 15:39:03 2011 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=VeriSign Client External Certification Authority
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:ae:b9:af:a2:f7:ad:56:cc:44:11:8f:7e:2b:40:
                    22:24:5a:0d:a7:2d:a6:35:b2:d6:e7:4c:a5:ad:f9:
                    00:0c:29:a8:2e:a1:af:a1:d7:b8:aa:fc:f9:e6:b2:
                    62:0b:32:9d:bb:84:72:b9:5f:e2:26:d5:fe:58:2c:
                    22:cf:c8:f6:0d:51:c5:d1:11:09:ea:76:2e:d0:c0:
                    f9:85:28:9b:0f:40:e2:aa:dd:ed:c0:f3:e5:3d:e2:
                    d9:84:a7:f7:4e:59:2b:84:f4:78:18:39:08:e7:b8:
                    aa:47:10:f0:d8:8b:78:19:d9:a1:29:eb:84:ce:ab:
                    5a:d9:2b:bf:ef:50:a6:5b:71
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Alternative Name: 
                DirName:/CN=PrivateLabel2-210
            X509v3 Authority Key Identifier: 
                keyid:F6:B8:04:27:0E:56:16:D9:B9:63:D9:FD:A1:54:65:41:A0:08:48:2F

            X509v3 Subject Key Identifier: 
                0D:C0:D8:3D:BF:FB:65:93:C8:37:66:26:E2:8A:12:5F:BB:C2:80:F5
            X509v3 Name Constraints: 
                Permitted:
                  DirName: C = US, O = U.S. Government, OU = ECA, OU = "VeriSign, Inc."
                  email:

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                  CPS: https://www.verisign.com/repository/eca/cps
                Policy: 2.16.840.1.101.3.2.1.12.2
                  CPS: https://www.verisign.com/repository/eca/cps

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:ldap://crl.chamb.disa.mil/cn%3DECA%20Root%20CA%2C%20ou%3DECA%2C%20o%3DU.S.%20Government%2C%20c%3DUS?certificaterevocationlist;binary

    Signature Algorithm: sha1WithRSAEncryption
         a2:1d:79:15:58:eb:c1:6d:2e:29:3a:39:8c:8f:00:46:71:d6:
         d7:76:48:2a:71:58:02:43:ed:36:96:6f:6b:e2:ba:55:56:25:
         80:2d:c8:df:46:37:b4:4b:54:3a:c0:92:48:d3:12:75:65:0a:
         1c:42:ec:f6:ca:2b:11:4e:4c:40:dd:83:3d:43:5e:ff:9d:6b:
         63:6e:4b:92:9d:b4:17:b1:84:9c:04:28:d8:7e:80:48:35:54:
         78:77:c8:8f:8b:36:df:b6:56:76:41:ee:67:92:d0:2c:ac:73:
         6c:11:5b:1d:26:3f:65:1d:83:b4:36:fe:4a:d1:7a:26:f9:6c:
         d6:4e
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 10 (0xa)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=ECA, CN=ECA Root CA 2
        Validity
            Not Before: Jul  2 14:41:18 2008 GMT
            Not After : Jul  1 14:41:18 2014 GMT
        Subject: C=US, O=U.S. Government, OU=ECA, OU=Certification Authorities, CN=VeriSign Client External Certification Authority - G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:bc:0b:9e:eb:8d:f2:86:68:0d:80:24:38:ce:e6:
                    21:78:5e:87:60:1d:b0:5f:da:0d:70:8e:62:e2:8b:
                    bc:8c:06:8c:42:2b:26:ca:93:d3:a8:b5:9c:89:07:
                    15:fe:f1:18:fe:0f:83:db:54:a0:53:ba:a0:88:49:
                    8e:a9:13:74:24:4e:e6:e3:a1:3c:df:14:10:f1:66:
                    63:5f:a9:23:41:f1:8f:3f:e2:88:0f:34:73:90:1d:
                    73:67:cc:1e:68:ee:7a:37:18:16:5f:d4:8e:13:23:
                    14:cb:99:c4:2e:5e:ea:7b:7f:3e:6a:8c:2d:1c:05:
                    d2:c1:31:94:b8:84:8b:aa:47:76:04:f3:b7:5e:89:
                    f7:30:92:9f:71:f7:7c:2c:76:1f:73:f1:7e:92:2c:
                    f3:c2:b1:a9:fd:ad:3f:47:92:3f:75:48:23:80:b3:
                    a4:24:b0:02:aa:a5:8c:b7:56:45:c7:9f:7c:02:02:
                    81:b1:71:e9:0a:4f:b3:23:2d:bf:2b:b9:25:19:89:
                    61:b6:21:f6:e9:89:2f:0d:6f:90:c1:06:97:61:8b:
                    6c:3d:bc:cf:23:8a:7a:4d:30:bd:7a:a9:7a:0b:5a:
                    63:2c:2f:18:0e:4f:4b:1d:4c:a8:08:f1:76:40:20:
                    8c:55:36:07:b7:69:35:e9:d4:a7:96:fc:af:b5:d9:
                    d9:17
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Subject Alternative Name: 
                DirName:/CN=PrivateLabel4-2048-81
            X509v3 Subject Key Identifier: 
                0D:4F:C2:C5:DA:13:90:22:17:DD:50:5C:0A:F4:21:4B:FC:72:28:1A
            X509v3 Authority Key Identifier: 
                keyid:ED:E4:87:D0:27:C4:50:E6:84:3A:F7:CC:F7:EB:3A:49:FC:52:4E:21

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.12.1
                Policy: 2.16.840.1.101.3.2.1.12.2
                Policy: 2.16.840.1.101.3.2.1.12.3

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.disa.mil/getcrl?ECA%20Root%20CA%202

                Full Name:
                  URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?certificateRevocationList;binary

            Authority Information Access: 
                CA Issuers - URI:http://crl.disa.mil/getIssuedTo?ECA%20Root%20CA%202
                CA Issuers - URI:ldap://crl.gds.disa.mil/cn%3dECA%20Root%20CA%202%2cou%3dECA%2co%3dU.S.%20Government%2cc%3dUS?cACertificate;binary,crossCertificatePair;binary

    Signature Algorithm: sha1WithRSAEncryption
         b2:5e:40:ce:0b:64:47:3c:83:61:05:6a:7a:71:82:26:29:a3:
         99:6b:a2:c0:c6:6c:37:1c:6c:f5:e2:ce:e6:d6:ab:e0:2c:45:
         dc:28:99:15:5f:c4:b3:8c:2f:26:99:51:6b:36:c3:60:09:bf:
         bc:8b:df:96:cd:08:e2:96:74:00:93:8f:77:d7:53:c9:21:56:
         d5:79:06:c0:8d:49:e0:4f:d7:36:af:7f:b8:63:42:95:58:91:
         e8:e9:98:21:bc:0c:c6:c6:ac:9e:e6:0b:a9:9a:92:a9:9d:fd:
         2f:d5:2a:31:d5:ce:6f:e2:0d:7d:cc:2a:12:12:ea:c8:e8:48:
         48:14:d8:a8:4c:e5:22:85:27:4b:7c:7a:86:75:07:99:29:96:
         77:c6:af:5c:80:9d:85:ca:3c:94:d0:56:75:9e:9e:ee:ef:34:
         12:bd:bb:42:c2:d5:77:6c:7e:6a:30:26:d7:0b:86:25:3c:7f:
         8d:d7:b2:9f:ff:be:ed:d2:ff:d4:e0:fd:31:ca:d8:b3:2d:47:
         b0:18:0d:21:60:3f:6f:98:6b:03:ea:43:f1:25:48:86:68:1d:
         42:50:7d:b4:ca:02:fb:23:5f:5e:7c:91:7b:27:63:6c:2f:1f:
         65:9d:30:ca:47:9a:3e:c6:be:29:08:c3:fb:4f:ff:bc:3d:fe:
         ec:1e:ea:61
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 406 (0x196)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
        Validity
            Not Before: Dec  9 19:11:52 2010 GMT
            Not After : Dec  9 19:10:21 2020 GMT
        Subject: C=US, O=VeriSign, Inc., CN=VeriSign SSP Intermediate CA - G3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:af:0d:2d:1a:27:cb:58:5a:b2:49:97:83:34:d3:
                    08:1f:82:bf:e9:e0:96:e4:4b:88:3c:2c:1e:75:6b:
                    3e:4b:f0:18:52:f8:a5:fc:ba:36:01:c5:13:e6:84:
                    14:88:ec:27:4d:3c:82:35:9b:9c:0a:d1:a6:4f:dc:
                    c7:3b:08:f8:e3:8c:73:e8:51:c2:f1:3e:2f:16:00:
                    3b:e8:0b:7e:54:8c:98:3b:88:55:1a:d3:7f:48:61:
                    11:8c:16:5b:bd:6f:17:6b:fe:47:ce:84:64:4f:b8:
                    30:b0:80:c7:aa:67:82:03:fe:9c:2d:84:a2:a1:d5:
                    b4:1b:26:4d:71:67:c8:0a:e1:7b:f7:06:db:84:3f:
                    cf:d0:be:a6:9c:37:f8:b9:8b:7e:79:9c:de:04:86:
                    a2:d3:ef:b3:68:90:6c:f6:45:54:1d:c6:46:2b:ba:
                    72:0c:9b:6e:24:79:d1:c3:57:66:b4:b4:5d:39:72:
                    d3:2d:92:c3:15:ea:d5:15:95:a9:ca:05:ff:38:bb:
                    94:be:72:a1:77:4f:62:98:c0:7c:48:66:5f:94:55:
                    bf:d3:48:79:cc:6e:8c:ad:3c:cb:ad:1a:f4:92:e2:
                    da:8f:5e:c6:7e:40:9e:54:c6:04:fd:7b:83:7a:2b:
                    16:7f:99:8e:48:98:30:0a:8f:92:bc:1d:b5:6f:dc:
                    10:bd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.101.3.2.1.3.6
                Policy: 2.16.840.1.101.3.2.1.3.7
                Policy: 2.16.840.1.101.3.2.1.3.8
                Policy: 2.16.840.1.101.3.2.1.3.13
                Policy: 2.16.840.1.101.3.2.1.3.16
                Policy: 2.16.840.1.101.3.2.1.3.17

            Authority Information Access: 
                CA Issuers - URI:http://http.fpki.gov/fcpca/caCertsIssuedTofcpca.p7c
                CA Issuers - URI:ldap://ldap.fpki.gov/cn=Federal%20Common%20Policy%20CA,ou=FPKI,o=U.S.%20Government,c=US?cACertificate;binary,crossCertificatePair;binary

            Subject Information Access: 
                CA Repository - URI:http://ssp-sia.verisign.com/SSP/Certs_issued_by_VRSNSSPCAG3.p7c
                CA Repository - URI:ldap://ssp-sia-ldap.verisign.com/CN=VeriSign%20SSP%20Intermediate%20CA%20-%20G3,O=%22VeriSign,%20Inc.%22,C=US?cACertificate;binary,crossCertificatePair;binary

            X509v3 Subject Alternative Name: 
                DirName:/CN=VeriSignMPKI-2-26
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier: 
                keyid:AD:0C:7A:75:5C:E5:F3:98:C4:79:98:0E:AC:28:FD:97:F4:E7:02:FC

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://http.fpki.gov/fcpca/fcpca.crl

                Full Name:
                  URI:ldap://ldap.fpki.gov/cn%3dFederal%20Common%20Policy%20CA,ou%3dFPKI,o%3dU.S.%20Government,c%3dUS?certificateRevocationList

            X509v3 Subject Key Identifier: 
                64:61:B6:22:D8:56:30:E2:A1:AA:CC:A2:F8:79:33:1F:B1:CA:E9:98
    Signature Algorithm: sha256WithRSAEncryption
         4b:57:35:92:51:42:41:e7:66:31:33:5b:9b:0c:d7:95:bb:2b:
         50:0f:b7:7d:e0:1a:13:ff:18:63:23:99:73:d7:83:06:5d:b2:
         59:ac:eb:ed:b6:1e:9d:03:19:08:6c:04:6b:3b:cb:bb:78:0e:
         c9:6e:1b:16:e1:72:c7:dc:3e:de:75:84:c0:50:76:7a:73:a9:
         40:9c:da:eb:02:5c:bc:c6:45:8e:be:f3:ca:69:3c:07:57:33:
         dd:f3:85:f6:b5:ab:c6:e0:62:c0:2d:68:43:86:27:c7:15:57:
         e3:2e:71:c0:36:e4:9d:e9:05:ae:59:11:c3:b5:45:66:ec:6d:
         8b:49:ff:42:e2:3b:89:1f:8f:de:c4:f4:88:8b:9a:45:5e:99:
         fd:b1:34:50:22:57:b9:44:8e:4a:07:f5:c4:eb:4f:a7:7d:e7:
         c5:79:d5:20:a5:ba:fd:cb:39:e5:61:8f:af:90:42:e8:c7:e3:
         6b:97:48:99:63:be:3a:2e:f8:72:cc:27:d1:e1:3c:86:3f:a3:
         51:98:12:d8:b5:6f:62:cb:b6:ba:97:96:27:fc:f9:c4:06:39:
         ab:19:92:68:ed:9a:1d:23:f2:1b:87:fb:2f:1e:6d:9e:e0:9d:
         c1:f7:8a:1d:7d:4e:20:f8:1f:ce:1d:d5:6c:8b:c0:0f:50:78:
         f2:11:1f:7a
