[gnutls-devel] gnutls 2.12.23 - chainverify testsuite failure on amd64

Andreas Metzler ametzler at bebt.de
Sun Apr 27 17:09:28 CEST 2014


Hello,

gnutls 2.12.23 has recently started failing the chainverify test on
amd64 (i386 works):

------------------------
(sid-AMD64)ametzler at argenau:/tmp/GNUTLS/gnutls-2.12.23$ ./tests/chainverify ; echo $?
chain[cacertrsamd5 ok]: verify_status: 1026 expected: 0
1
------------------------

Any idea? --verbose attached.

cu Andreas
-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'
-------------- next part --------------
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: verify.c:306
|<2>| ASSERT: verify.c:356
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
Chain 'CVE-2008-4989' (0)...
	Certificate 0: subject `C=DE,O=GNU TLS Attack,CN=server', issuer `C=DE,O=GNU TLS Attack,CN=intermediate', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-11-03 12:05:04 UTC', expires `2008-12-03 12:05:04 UTC', SHA-1 fingerprint `0cc65ee009e1345dbc0458545ffaaacbaf11c6ef'
	Certificate 1: subject `C=DE,O=GNU TLS Attack,CN=intermediate', issuer `C=DE,O=GNU TLS Attack,CN=root', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-11-03 12:04:45 UTC', expires `2008-12-03 12:04:45 UTC', SHA-1 fingerprint `6d20189cb569bd77b7775a41171781dfa49f6211'
	Certificate 2: subject `C=US,O=thawte\, Inc.,OU=Certification Services Division,OU=(c) 2006 thawte\, Inc. - For authorized use only,CN=thawte Primary Root CA', issuer `C=US,O=thawte\, Inc.,OU=Certification Services Division,OU=(c) 2006 thawte\, Inc. - For authorized use only,CN=thawte Primary Root CA', RSA key 2048 bits, signed using RSA-SHA1, activated `2006-11-17 00:00:00 UTC', expires `2036-07-16 23:59:59 UTC', SHA-1 fingerprint `91c6d6ee3e8ac86384e548c299295c756c817b81'
	CA Certificate: subject `C=US,O=thawte\, Inc.,OU=Certification Services Division,OU=(c) 2006 thawte\, Inc. - For authorized use only,CN=thawte Primary Root CA', issuer `C=US,O=thawte\, Inc.,OU=Certification Services Division,OU=(c) 2006 thawte\, Inc. - For authorized use only,CN=thawte Primary Root CA', RSA key 2048 bits, signed using RSA-SHA1, activated `2006-11-17 00:00:00 UTC', expires `2036-07-16 23:59:59 UTC', SHA-1 fingerprint `91c6d6ee3e8ac86384e548c299295c756c817b81'
	Verifying...done
	Cleanup...done


Chain 'verisign.com v1 fail' (1)...
	Certificate 0: subject `serialNumber=2497886,jurisdictionOfIncorporationCountryName=US,jurisdictionOfIncorporationStateOrProvinceName=Delaware,C=US,postalCode=94043,ST=California,L=Mountain View,STREET=487 East Middlefield Road,O=VeriSign\, Inc.,OU=Production Security Services,OU=Terms of use at www.verisign.com/rpa (c)06,CN=www.verisign.com', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)06,CN=VeriSign Class 3 Extended Validation SSL SGC CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2007-05-09 00:00:00 UTC', expires `2009-05-08 23:59:59 UTC', SHA-1 fingerprint `c6750e8da95f5a65bb046d6079d4fc87402e0381'
	Certificate 1: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)06,CN=VeriSign Class 3 Extended Validation SSL SGC CA', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=(c) 2006 VeriSign\, Inc. - For authorized use only,CN=VeriSign Class 3 Public Primary Certification Authority - G5', RSA key 2048 bits, signed using RSA-SHA1, activated `2006-11-08 00:00:00 UTC', expires `2016-11-07 23:59:59 UTC', SHA-1 fingerprint `4a8a2a0e276ff33b5dd88a362146010f2a8b6aee'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=(c) 2006 VeriSign\, Inc. - For authorized use only,CN=VeriSign Class 3 Public Primary Certification Authority - G5', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 2048 bits, signed using RSA-SHA1, activated `2006-11-08 00:00:00 UTC', expires `2021-11-07 23:59:59 UTC', SHA-1 fingerprint `7e7e026f71bfe7bbc7e7e5c591b1915cb6684e6c'
	Certificate 3: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'verisign.com v1 ok' (2)|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
...
	Certificate 0: subject `serialNumber=2497886,jurisdictionOfIncorporationCountryName=US,jurisdictionOfIncorporationStateOrProvinceName=Delaware,C=US,postalCode=94043,ST=California,L=Mountain View,STREET=487 East Middlefield Road,O=VeriSign\, Inc.,OU=Production Security Services,OU=Terms of use at www.verisign.com/rpa (c)06,CN=www.verisign.com', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)06,CN=VeriSign Class 3 Extended Validation SSL SGC CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2007-05-09 00:00:00 UTC', expires `2009-05-08 23:59:59 UTC', SHA-1 fingerprint `c6750e8da95f5a65bb046d6079d4fc87402e0381'
	Certificate 1: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)06,CN=VeriSign Class 3 Extended Validation SSL SGC CA', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=(c) 2006 VeriSign\, Inc. - For authorized use only,CN=VeriSign Class 3 Public Primary Certification Authority - G5', RSA key 2048 bits, signed using RSA-SHA1, activated `2006-11-08 00:00:00 UTC', expires `2016-11-07 23:59:59 UTC', SHA-1 fingerprint `4a8a2a0e276ff33b5dd88a362146010f2a8b6aee'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=(c) 2006 VeriSign\, Inc. - For authorized use only,CN=VeriSign Class 3 Public Primary Certification Authority - G5', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 2048 bits, signed using RSA-SHA1, activated `2006-11-08 00:00:00 UTC', expires `2021-11-07 23:59:59 UTC', SHA-1 fingerprint `7e7e026f71bfe7bbc7e7e5c591b1915cb6684e6c'
	Certificate 3: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'citibank.com v1 fail' (3)...
	Certificate 0: subject `C=US,ST=New Jersey,L=Weehawken,O=Citigroup,OU=whg-oak6,CN=www.citibank.com', issuer `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-08-29 00:00:00 UTC', expires `2010-08-29 23:59:59 UTC', SHA-1 fingerprint `8b410d9cf13f191596a65f1f77580ddfa37aba49'
	Certificate 1: subject `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-SHA1, activated `1997-04-17 00:00:00 UTC', expires `2011-10-24 23:59:59 UTC', SHA-1 fingerprint `c2f0087d01e686053a4d633e7e70d4ef65c2cc4f'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53|<2>| ASSERT: verify.c:207
|<2>| ASSERT: verify.c:376
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: verify.c:207
|<2>| ASSERT: verify.c:376
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: verify.c:207
|<2>| ASSERT: verify.c:376
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
e6174e2'
	Verifying...done
	Cleanup...done


Chain 'expired self signed' (4)...
	Certificate 0: subject `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', issuer `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', RSA key 2048 bits, signed using RSA-SHA1, activated `2008-05-30 19:53:43 UTC', expires `2008-11-26 19:53:43 UTC', SHA-1 fingerprint `87a0285ef6fa364664a50034a631c10a7279a77f'
	CA Certificate: subject `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', issuer `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', RSA key 2048 bits, signed using RSA-SHA1, activated `2008-05-30 19:53:43 UTC', expires `2008-11-26 19:53:43 UTC', SHA-1 fingerprint `87a0285ef6fa364664a50034a631c10a7279a77f'
	Verifying...done
	Cleanup...done


Chain 'self signed' (5)...
	Certificate 0: subject `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', issuer `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', RSA key 2048 bits, signed using RSA-SHA1, activated `2008-05-30 19:53:43 UTC', expires `2008-11-26 19:53:43 UTC', SHA-1 fingerprint `87a0285ef6fa364664a50034a631c10a7279a77f'
	CA Certificate: subject `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', issuer `C=BR,O=Minas Livre,CN=Thadeu Lima de Souza Cascardo', RSA key 2048 bits, signed using RSA-SHA1, activated `2008-05-30 19:53:43 UTC', expires `2008-11-26 19:53:43 UTC', SHA-1 fingerprint `87a0285ef6fa364664a50034a631c10a7279a77f'
	Verifying...done
	Cleanup...done


Chain 'ca=false' (6)...
	Certificate 0: subject `C=DE,ST=RLP,L=Kaiserslautern,O=Technische Universitaet,OU=Fachbereich Physik,CN=thea.physik.uni-kl.de', issuer `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-09-11 10:52:07 UTC', expires `2018-09-09 10:52:07 UTC', SHA-1 fingerprint `2fbe7e0f2266f7247b06cd41e63a3e1a104e4fd5'
	Certificate 1: subject `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', issuer `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-09-11 10:47:44 UTC', expires `2018-09-09 10:47:44 UTC', SHA-1 fingerprint `5c3a6e72781972580071abeefe730d1b85f6d167'
	CA Certificate: subject `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', issuer `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-09-11 10:47:44 UTC', expires `2018-09-09 10:47:44 UTC', SHA-1 fingerprint `5c3a6e72781972580071abeefe730d1b85f6d167'
	Verifying...done
	Cleanup...done


Chain 'ca=false2' (7)...
	Certificate 0: subject `C=DE,ST=RLP,L=Kaiserslautern,O=Technische Universitaet,OU=Fachbereich Physik,CN=thea.physik.uni-kl.de', issuer `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-09-11 10:52:07 UTC', expires `2018-09-09 10:52:07 UTC', SHA-1 fingerprint `2fbe7e0f2266f7247b06cd41e63a3e1a104e4fd5'
	Certificate 1: subject `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', issuer `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-09-11 10:47:44 UTC', expires `2018-09-09 10:47:44 UTC', SHA-1 fingerprint `5c3a6e72781972580071abeefe730d1b85f6d167'
	CA Certificate: subject `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', issuer `C=DE,ST=RLP,O=Technische Universitaet,OU=Fachbereich Physik,CN=CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-09-11 10:47:44 UTC', expires `2018-09-09 10:47:44 UTC', SHA-1 fingerprint `5c3a6e72781972580071abeefe730d1b85f6d167'
	Verifying...done
	Cleanup...done


Chain 'hbci v1 fail' (8)...
	Certificate 0: subject `C=DE,ST=Hessen,L=Frankfurt am Main,O=Sparkassen Informatik GmbH & Co. KG,OU=Terms of use at www.verisign.com,CN=hbci-pintan-rp.s-hbci.de', issuer `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', RSA key 1024 bits, signed using |<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: verify.c:207
|<2>| ASSERT: verify.c:376
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
RSA-SHA1, activated `2008-06-10 00:00:00 UTC', expires `2009-07-30 23:59:59 UTC', SHA-1 fingerprint `a648bde8c1d773504947bc581ac730ea0bdb4df6'
	Certificate 1: subject `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-SHA1, activated `1997-04-17 00:00:00 UTC', expires `2011-10-24 23:59:59 UTC', SHA-1 fingerprint `c2f0087d01e686053a4d633e7e70d4ef65c2cc4f'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'hbci v1 ok expired' (9)...
	Certificate 0: subject `C=DE,ST=Hessen,L=Frankfurt am Main,O=Sparkassen Informatik GmbH & Co. KG,OU=Terms of use at www.verisign.com,CN=hbci-pintan-rp.s-hbci.de', issuer `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-06-10 00:00:00 UTC', expires `2009-07-30 23:59:59 UTC', SHA-1 fingerprint `a648bde8c1d773504947bc581ac730ea0bdb4df6'
	Certificate 1: subject `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-SHA1, activated `1997-04-17 00:00:00 UTC', expires `2011-10-24 23:59:59 UTC', SHA-1 fingerprint `c2f0087d01e686053a4d633e7e70d4ef65c2cc4f'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'hbci v1 ok' (10)...
	Certificate 0: subject `C=DE,ST=Hessen,L=Frankfurt am Main,O=Sparkassen Informatik GmbH & Co. KG,OU=Terms of use at www.verisign.com,CN=hbci-pintan-rp.s-hbci.de', issuer `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-06-10 00:00:00 UTC', expires `2009-07-30 23:59:59 UTC', SHA-1 fingerprint `a648bde8c1d773504947bc581ac730ea0bdb4df6'
	Certificate 1: subject `O=VeriSign Trust Network,OU=VeriSign\, Inc.,OU=VeriSign International Server CA - Class 3,OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-SHA1, activated `1997-04-17 00:00:00 UTC', expires `2011-10-24 23:59:59 UTC', SHA-1 fingerprint `c2f0087d01e686053a4d633e7e70d4ef65c2cc4f'
	Certif|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
icate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'rsa-md5 fail' (11)...
	Certificate 0: subject `C=US,O=support.mayfirst.org,OU=GT69079880,OU=See www.rapidssl.com/resources/cps (c)07,OU=Domain Control Validated - RapidSSL(R),CN=support.mayfirst.org', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `2008-05-19 05:29:19 UTC', expires `2009-10-19 05:29:19 UTC', SHA-1 fingerprint `be7755879c78be4a19c16f789f752c4394a85395'
	Certificate 1: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	CA Certificate: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	Verifying...done
	Cleanup...done


Chain 'rsa-md5 not ok' (12)...
	Certificate 0: subject `C=US,O=support.mayfirst.org,OU=GT69079880,OU=See www.rapidssl.com/resources/cps (c)07,OU=Domain Control Validated - RapidSSL(R),CN=support.mayfirst.org', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `2008-05-19 05:29:19 UTC', expires `2009-10-19 05:29:19 UTC', SHA-1 fingerprint `be7755879c78be4a19c16f789f752c4394a85395'
	Certificate 1: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	CA Certificate: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	Verifying...done
	Cleanup...done


Chain 'rsa-md5 not ok2' (13)...
	Certificate 0: subject `C=US,O=support.mayfirst.org,OU=GT69079880,OU=See www.rapidssl.com/resources/cps (c)07,OU=Domain Control Validated - RapidSSL(R),CN=support.mayfirst.org', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `2008-05-19 05:29:19 UTC', expires `2009-10-19 05:29:19 UTC', SHA-1 fingerprint `be7755879c78be4a19c16f789f752c4394a85395'
	Certificate 1: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	CA Certificate: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure |<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: verify.c:207
|<2>| ASSERT: verify.c:376
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	Verifying...done
	Cleanup...done


Chain 'rsa-md5 ok' (14)...
	Certificate 0: subject `C=US,O=support.mayfirst.org,OU=GT69079880,OU=See www.rapidssl.com/resources/cps (c)07,OU=Domain Control Validated - RapidSSL(R),CN=support.mayfirst.org', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `2008-05-19 05:29:19 UTC', expires `2009-10-19 05:29:19 UTC', SHA-1 fingerprint `be7755879c78be4a19c16f789f752c4394a85395'
	Certificate 1: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	CA Certificate: subject `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', issuer `C=US,O=Equifax Secure Inc.,CN=Equifax Secure Global eBusiness CA-1', RSA key 1024 bits, signed using RSA-MD5 (broken!), activated `1999-06-21 04:00:00 UTC', expires `2020-06-21 04:00:00 UTC', SHA-1 fingerprint `7e784a101c8265cc2de1f16d47b440cad90a1945'
	Verifying...done
	Cleanup...done


Chain 'v1ca fail' (15)...
	Certificate 0: subject `C=US,ST=Illinois,L=Du Page,O=Argonne National Laboratory,CN=auth2.it.anl.gov', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-05-05 00:00:00 UTC', expires `2009-05-22 23:59:59 UTC', SHA-1 fingerprint `687c93b7db0cc9b9d899aa2e9633e18db0ba7925'
	Certificate 1: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 2048 bits, signed using RSA-SHA1, activated `2005-01-19 00:00:00 UTC', expires `2015-01-18 23:59:59 UTC', SHA-1 fingerprint `188590e94878478e33b6194e59fbbb28ff0888d5'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'v1ca expired' (16)...
	Certificate 0: subject `C=US,ST=Illinois,L=Du Page,O=Argonne National Laboratory,CN=auth2.it.anl.gov', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-05-05 00:00:00 UTC', expires `2009-05-22 23:59:59 UTC', SHA-1 fingerprint `687c93b7db0cc9b9d899aa2e9633e18db0ba7925'
	Certificate 1: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 2048 bits, signed using RSA-SHA1, activated `2005-01-19 00:00:00 UTC', expires `2015-01-18 23:59:59 UTC', SHA-1 fingerprint `188590e94878478e33b6194e59fbbb28ff0888d5'
	Certificate 2: subject `C=|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'v1ca ok' (17)...
	Certificate 0: subject `C=US,ST=Illinois,L=Du Page,O=Argonne National Laboratory,CN=auth2.it.anl.gov', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-05-05 00:00:00 UTC', expires `2009-05-22 23:59:59 UTC', SHA-1 fingerprint `687c93b7db0cc9b9d899aa2e9633e18db0ba7925'
	Certificate 1: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 2048 bits, signed using RSA-SHA1, activated `2005-01-19 00:00:00 UTC', expires `2015-01-18 23:59:59 UTC', SHA-1 fingerprint `188590e94878478e33b6194e59fbbb28ff0888d5'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'v1ca2 expired' (18)...
	Certificate 0: subject `C=US,ST=Illinois,L=Du Page,O=Argonne National Laboratory,CN=auth2.it.anl.gov', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-05-05 00:00:00 UTC', expires `2009-05-22 23:59:59 UTC', SHA-1 fingerprint `687c93b7db0cc9b9d899aa2e9633e18db0ba7925'
	Certificate 1: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 2048 bits, signed using RSA-SHA1, activated `2005-01-19 00:00:00 UTC', expires `2015-01-18 23:59:59 UTC', SHA-1 fingerprint `188590e94878478e33b6194e59fbbb28ff0888d5'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'v1ca2 ok' (19)...
	Certificate 0: subject|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
 `C=US,ST=Illinois,L=Du Page,O=Argonne National Laboratory,CN=auth2.it.anl.gov', issuer `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', RSA key 1024 bits, signed using RSA-SHA1, activated `2008-05-05 00:00:00 UTC', expires `2009-05-22 23:59:59 UTC', SHA-1 fingerprint `687c93b7db0cc9b9d899aa2e9633e18db0ba7925'
	Certificate 1: subject `C=US,O=VeriSign\, Inc.,OU=VeriSign Trust Network,OU=Terms of use at https://www.verisign.com/rpa (c)05,CN=VeriSign Class 3 Secure Server CA', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 2048 bits, signed using RSA-SHA1, activated `2005-01-19 00:00:00 UTC', expires `2015-01-18 23:59:59 UTC', SHA-1 fingerprint `188590e94878478e33b6194e59fbbb28ff0888d5'
	Certificate 2: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	CA Certificate: subject `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', issuer `C=US,O=VeriSign\, Inc.,OU=Class 3 Public Primary Certification Authority', RSA key 1024 bits, signed using RSA-MD2 (broken!), activated `1996-01-29 00:00:00 UTC', expires `2028-08-01 23:59:59 UTC', SHA-1 fingerprint `742c3192e607e424eb4549542be1bbc53e6174e2'
	Verifying...done
	Cleanup...done


Chain 'cacertrsamd5 fail' (20)...
	Certificate 0: subject `CN=fry.serverama.de', issuer `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', RSA key 1024 bits, signed using RSA-SHA1, activated `2009-01-16 22:29:47 UTC', expires `2011-01-16 22:29:47 UTC', SHA-1 fingerprint `7d18c5e1f1fc350458b499ee5d95bbf41274597d'
	Certificate 1: subject `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2005-10-14 07:36:55 UTC', expires `2033-03-28 07:36:55 UTC', SHA-1 fingerprint `db4c4269073fe9c2a37d890a5c1b18c4184e2a2d'
	Certificate 2: subject `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2003-03-30 12:29:49 UTC', expires `2033-03-29 12:29:49 UTC', SHA-1 fingerprint `135cec36f49cb8e93b1ab270cd80884676ce8f33'
	CA Certificate: subject `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2003-03-30 12:29:49 UTC', expires `2033-03-29 12:29:49 UTC', SHA-1 fingerprint `135cec36f49cb8e93b1ab270cd80884676ce8f33'
	Verifying...done
	Cleanup...done


Chain 'cacertrsamd5 ok' (21)...
	Certificate 0: subject `CN=fry.serverama.de', issuer `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', RSA key 1024 bits, signed using RSA-SHA1, activated `2009-01-16 22:29:47 UTC', expires `2011-01-16 22:29:47 UTC', SHA-1 fingerprint `7d18c5e1f1fc350458b499ee5d95bbf41274597d'
	Certificate 1: subject `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2005-10-14 07:36:55 UTC', expires `2033-03-28 07:36:55 UTC', SHA-1 fingerprint `db4c4269073fe9c2a37d890a5c1b18c4184e2a2d'
	Certificate 2: subject `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broke|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
chain[cacertrsamd5 ok]: verify_status: 1026 expected: 0
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:1209
|<2>| ASSERT: verify.c:306
|<2>| ASSERT: verify.c:356
|<2>| ASSERT: verify.c:588
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: dn.c:305
|<2>| ASSERT: mpi.c:609
|<2>| ASSERT: dn.c:1209
chain[cacertrsamd5 short-cut ok]: verify_status: 1026 expected: 0
n!), activated `2003-03-30 12:29:49 UTC', expires `2033-03-29 12:29:49 UTC', SHA-1 fingerprint `135cec36f49cb8e93b1ab270cd80884676ce8f33'
	CA Certificate: subject `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2003-03-30 12:29:49 UTC', expires `2033-03-29 12:29:49 UTC', SHA-1 fingerprint `135cec36f49cb8e93b1ab270cd80884676ce8f33'
	Verifying...	Cleanup...done


Chain 'cacertrsamd5 short-cut not ok' (22)...
	Certificate 0: subject `CN=fry.serverama.de', issuer `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', RSA key 1024 bits, signed using RSA-SHA1, activated `2009-01-16 22:29:47 UTC', expires `2011-01-16 22:29:47 UTC', SHA-1 fingerprint `7d18c5e1f1fc350458b499ee5d95bbf41274597d'
	Certificate 1: subject `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2005-10-14 07:36:55 UTC', expires `2033-03-28 07:36:55 UTC', SHA-1 fingerprint `db4c4269073fe9c2a37d890a5c1b18c4184e2a2d'
	Certificate 2: subject `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2003-03-30 12:29:49 UTC', expires `2033-03-29 12:29:49 UTC', SHA-1 fingerprint `135cec36f49cb8e93b1ab270cd80884676ce8f33'
	CA Certificate: subject `CN=fry.serverama.de', issuer `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', RSA key 1024 bits, signed using RSA-SHA1, activated `2009-01-16 22:29:47 UTC', expires `2011-01-16 22:29:47 UTC', SHA-1 fingerprint `7d18c5e1f1fc350458b499ee5d95bbf41274597d'
	Verifying...done
	Cleanup...done


Chain 'cacertrsamd5 short-cut ok' (23)...
	Certificate 0: subject `CN=fry.serverama.de', issuer `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', RSA key 1024 bits, signed using RSA-SHA1, activated `2009-01-16 22:29:47 UTC', expires `2011-01-16 22:29:47 UTC', SHA-1 fingerprint `7d18c5e1f1fc350458b499ee5d95bbf41274597d'
	Certificate 1: subject `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2005-10-14 07:36:55 UTC', expires `2033-03-28 07:36:55 UTC', SHA-1 fingerprint `db4c4269073fe9c2a37d890a5c1b18c4184e2a2d'
	Certificate 2: subject `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2003-03-30 12:29:49 UTC', expires `2033-03-29 12:29:49 UTC', SHA-1 fingerprint `135cec36f49cb8e93b1ab270cd80884676ce8f33'
	CA Certificate: subject `O=CAcert Inc.,OU=http://www.CAcert.org,CN=CAcert Class 3 Root', issuer `O=Root CA,OU=http://www.cacert.org,CN=CA Cert Signing Authority,EMAIL=support at cacert.org', RSA key 4096 bits, signed using RSA-MD5 (broken!), activated `2005-10-14 07:36:55 UTC', expires `2033-03-28 07:36:55 UTC', SHA-1 fingerprint `db4c4269073fe9c2a37d890a5c1b18c4184e2a2d'
	Verifying...	Cleanup...done


Exit status...0
0


More information about the Gnutls-devel mailing list