diff --git a/website/data/security/errata.toml b/website/data/security/errata.toml
index 4cc5b7ccfa..c74f581696 100644
--- a/website/data/security/errata.toml
+++ b/website/data/security/errata.toml
@@ -1,703 +1,719 @@
# Sort errata notices by year, month and day
# $FreeBSD$
+[[notices]]
+name = "FreeBSD-EN-21:29.tzdata"
+date = "2021-11-03"
+
+[[notices]]
+name = "FreeBSD-EN-21:28.vmci"
+date = "2021-11-03"
+
+[[notices]]
+name = "FreeBSD-EN-21:27.caroot"
+date = "2021-11-03"
+
+[[notices]]
+name = "FreeBSD-EN-21:26.libevent"
+date = "2021-11-03"
+
[[notices]]
name = "FreeBSD-EN-21:25.bhyve"
date = "2021-08-24"
[[notices]]
name = "FreeBSD-EN-21:24.libcrypto"
date = "2021-08-24"
[[notices]]
name = "FreeBSD-EN-21:23.virtio_blk"
date = "2021-08-24"
[[notices]]
name = "FreeBSD-EN-21:22.linux_futex"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:21.ipfw"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:20.vlan"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:19.libcasper"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:18.libc++"
date = "2021-06-29"
[[notices]]
name = "FreeBSD-EN-21:17.libradius"
date = "2021-06-01"
[[notices]]
name = "FreeBSD-EN-21:16.bc"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:15.virtio"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:14.pms"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:13.mpt"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:12.divert"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:11.aesni"
date = "2021-05-26"
[[notices]]
name = "FreeBSD-EN-21:10.lldb"
date = "2021-04-06"
[[notices]]
name = "FreeBSD-EN-21:09.pf"
date = "2021-04-06"
[[notices]]
name = "FreeBSD-EN-21:08.freebsd-update"
date = "2021-02-24"
[[notices]]
name = "FreeBSD-EN-21:07.caroot"
date = "2021-02-24"
[[notices]]
name = "FreeBSD-EN-21:06.microcode"
date = "2021-02-24"
[[notices]]
name = "FreeBSD-EN-21:05.libatomic"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:04.zfs"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:03.vnet"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:02.extattr"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-21:01.tzdata"
date = "2021-01-29"
[[notices]]
name = "FreeBSD-EN-20:22.callout"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:21.ipfw"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:20.tzdata"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:19.audit"
date = "2020-12-01"
[[notices]]
name = "FreeBSD-EN-20:18.getfsstat"
date = "2020-09-02"
[[notices]]
name = "FreeBSD-EN-20:17.linuxthread"
date = "2020-09-02"
[[notices]]
name = "FreeBSD-EN-20:16.vmx"
date = "2020-08-05"
[[notices]]
name = "FreeBSD-EN-20:15.mps"
date = "2020-07-08"
[[notices]]
name = "FreeBSD-EN-20:14.linuxkpi"
date = "2020-07-08"
[[notices]]
name = "FreeBSD-EN-20:13.bhyve"
date = "2020-07-08"
[[notices]]
name = "FreeBSD-EN-20:12.iflib"
date = "2020-06-09"
[[notices]]
name = "FreeBSD-EN-20:11.ena"
date = "2020-06-09"
[[notices]]
name = "FreeBSD-EN-20:10.build"
date = "2020-05-12"
[[notices]]
name = "FreeBSD-EN-20:09.igb"
date = "2020-05-12"
[[notices]]
name = "FreeBSD-EN-20:08.tzdata"
date = "2020-05-12"
[[notices]]
name = "FreeBSD-EN-20:07.quotad"
date = "2020-04-21"
[[notices]]
name = "FreeBSD-EN-20:06.ipv6"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:05.mlx5en"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:04.pfctl"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:03.sshd"
date = "2020-03-19"
[[notices]]
name = "FreeBSD-EN-20:02.nmount"
date = "2020-01-28"
[[notices]]
name = "FreeBSD-EN-20:01.ssp"
date = "2020-01-28"
[[notices]]
name = "FreeBSD-EN-19:19.loader"
date = "2019-11-12"
[[notices]]
name = "FreeBSD-EN-19:18.tzdata"
date = "2019-10-23"
[[notices]]
name = "FreeBSD-EN-19:17.ipfw"
date = "2019-08-20"
[[notices]]
name = "FreeBSD-EN-19:16.bhyve"
date = "2019-08-20"
[[notices]]
name = "FreeBSD-EN-19:15.libunwind"
date = "2019-08-06"
[[notices]]
name = "FreeBSD-EN-19:14.epoch"
date = "2019-08-06"
[[notices]]
name = "FreeBSD-EN-19:13.mds"
date = "2019-07-24"
[[notices]]
name = "FreeBSD-EN-19:12.tzdata"
date = "2019-07-02"
[[notices]]
name = "FreeBSD-EN-19:11.net"
date = "2019-06-19"
[[notices]]
name = "FreeBSD-EN-19:10.scp"
date = "2019-05-14"
[[notices]]
name = "FreeBSD-EN-19:09.xinstall"
date = "2019-05-14"
[[notices]]
name = "FreeBSD-EN-19:08.tzdata"
date = "2019-05-14"
[[notices]]
name = "FreeBSD-EN-19:07.lle"
date = "2019-02-05"
[[notices]]
name = "FreeBSD-EN-19:06.dtrace"
date = "2019-02-05"
[[notices]]
name = "FreeBSD-EN-19:05.kqueue"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:04.tzdata"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:03.sqlite"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:02.tcp"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-19:01.cc_cubic"
date = "2019-01-09"
[[notices]]
name = "FreeBSD-EN-18:18.zfs"
date = "2018-12-19"
[[notices]]
name = "FreeBSD-EN-18:17.vm"
date = "2018-12-19"
[[notices]]
name = "FreeBSD-EN-18:16.ptrace"
date = "2018-12-19"
[[notices]]
name = "FreeBSD-EN-18:15.loader"
date = "2018-11-27"
[[notices]]
name = "FreeBSD-EN-18:14.tzdata"
date = "2018-11-27"
[[notices]]
name = "FreeBSD-EN-18:13.icmp"
date = "2018-11-27"
[[notices]]
name = "FreeBSD-EN-18:12.mem"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:11.listen"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:10.syscall"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:09.ip"
date = "2018-09-27"
[[notices]]
name = "FreeBSD-EN-18:08.lazyfpu"
date = "2018-09-12"
[[notices]]
name = "FreeBSD-EN-18:07.pmap"
date = "2018-06-21"
[[notices]]
name = "FreeBSD-EN-18:06.tzdata"
date = "2018-05-08"
[[notices]]
name = "FreeBSD-EN-18:05.mem"
date = "2018-05-08"
[[notices]]
name = "FreeBSD-EN-18:04.mem"
date = "2018-04-04"
[[notices]]
name = "FreeBSD-EN-18:03.tzdata"
date = "2018-04-04"
[[notices]]
name = "FreeBSD-EN-18:02.file"
date = "2018-03-07"
[[notices]]
name = "FreeBSD-EN-18:01.tzdata"
date = "2018-03-07"
[[notices]]
name = "FreeBSD-EN-17:09.tzdata"
date = "2017-11-02"
[[notices]]
name = "FreeBSD-EN-17:08.pf"
date = "2017-08-10"
[[notices]]
name = "FreeBSD-EN-17:07.vnet"
date = "2017-08-10"
[[notices]]
name = "FreeBSD-EN-17:06.hyperv"
date = "2017-07-12"
[[notices]]
name = "FreeBSD-EN-17:05.xen"
date = "2017-04-12"
[[notices]]
name = "FreeBSD-EN-17:04.mandoc"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-17:03.hyperv"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-17:02.yp"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-17:01.pcie"
date = "2017-02-23"
[[notices]]
name = "FreeBSD-EN-16:21.localedef"
date = "2016-12-06"
[[notices]]
name = "FreeBSD-EN-16:20.tzdata"
date = "2016-12-06"
[[notices]]
name = "FreeBSD-EN-16:19.tzcode"
date = "2016-12-06"
[[notices]]
name = "FreeBSD-EN-16:18.loader"
date = "2016-10-25"
[[notices]]
name = "FreeBSD-EN-16:17.vm"
date = "2016-10-25"
[[notices]]
name = "FreeBSD-EN-16:16.hv_storvsc"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:15.vmbus"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:14.hv_storvsc"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:13.vmbus"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:12.hv_storvsc"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:11.vmbus"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:10.dhclient"
date = "2016-08-12"
[[notices]]
name = "FreeBSD-EN-16:09.freebsd-update"
date = "2016-07-25"
[[notices]]
name = "FreeBSD-EN-16:08.zfs"
date = "2016-05-04"
[[notices]]
name = "FreeBSD-EN-16:07.ipi"
date = "2016-05-04"
[[notices]]
name = "FreeBSD-EN-16:06.libc"
date = "2016-05-04"
[[notices]]
name = "FreeBSD-EN-16:05.hv_netvsc"
date = "2016-03-16"
[[notices]]
name = "FreeBSD-EN-16:04.hyperv"
date = "2016-03-16"
[[notices]]
name = "FreeBSD-EN-16:03.yplib"
date = "2016-01-14"
[[notices]]
name = "FreeBSD-EN-16:02.pf"
date = "2016-01-14"
[[notices]]
name = "FreeBSD-EN-16:01.filemon"
date = "2016-01-14"
[[notices]]
name = "FreeBSD-EN-15:20.vm"
date = "2015-11-04"
[[notices]]
name = "FreeBSD-EN-15:19.kqueue"
date = "2015-11-04"
[[notices]]
name = "FreeBSD-EN-15:18.pkg"
date = "2015-09-16"
[[notices]]
name = "FreeBSD-EN-15:17.libc"
date = "2015-09-16"
[[notices]]
name = "FreeBSD-EN-15:16.pw"
date = "2015-09-16"
[[notices]]
name = "FreeBSD-EN-15:15.pkg"
date = "2015-08-25"
[[notices]]
name = "FreeBSD-EN-15:14.ixgbe"
date = "2015-08-25"
[[notices]]
name = "FreeBSD-EN-15:13.vidcontrol"
date = "2015-08-18"
[[notices]]
name = "FreeBSD-EN-15:12.netstat"
date = "2015-08-18"
[[notices]]
name = "FreeBSD-EN-15:11.toolchain"
date = "2015-08-18"
[[notices]]
name = "FreeBSD-EN-15:10.iconv"
date = "2015-06-30"
[[notices]]
name = "FreeBSD-EN-15:09.xlocale"
date = "2015-06-30"
[[notices]]
name = "FreeBSD-EN-15:08.sendmail"
date = "2015-06-18"
[[notices]]
name = "FreeBSD-EN-15:07.zfs"
date = "2015-06-09"
[[notices]]
name = "FreeBSD-EN-15:06.file"
date = "2015-06-09"
[[notices]]
name = "FreeBSD-EN-15:05.ufs"
date = "2015-05-13"
[[notices]]
name = "FreeBSD-EN-15:04.freebsd-update"
date = "2015-05-13"
[[notices]]
name = "FreeBSD-EN-15:03.freebsd-update"
date = "2015-02-25"
[[notices]]
name = "FreeBSD-EN-15:02.openssl"
date = "2015-02-25"
[[notices]]
name = "FreeBSD-EN-15:01.vt"
date = "2015-02-25"
[[notices]]
name = "FreeBSD-EN-14:13.freebsd-update"
date = "2014-12-23"
[[notices]]
name = "FreeBSD-EN-14:12.zfs"
date = "2014-11-04"
[[notices]]
name = "FreeBSD-EN-14:11.crypt"
date = "2014-10-22"
[[notices]]
name = "FreeBSD-EN-14:10.tzdata"
date = "2014-10-22"
[[notices]]
name = "FreeBSD-EN-14:09.jail"
date = "2014-07-08"
[[notices]]
name = "FreeBSD-EN-14:08.heimdal"
date = "2014-06-24"
[[notices]]
name = "FreeBSD-EN-14:07.pmap"
date = "2014-06-24"
[[notices]]
name = "FreeBSD-EN-14:06.exec"
date = "2014-06-03"
[[notices]]
name = "FreeBSD-EN-14:05.ciss"
date = "2014-05-13"
[[notices]]
name = "FreeBSD-EN-14:04.kldxref"
date = "2014-05-13"
[[notices]]
name = "FreeBSD-EN-14:03.pkg"
date = "2014-05-13"
[[notices]]
name = "FreeBSD-EN-14:02.mmap"
date = "2014-01-14"
[[notices]]
name = "FreeBSD-EN-14:01.random"
date = "2014-01-14"
[[notices]]
name = "FreeBSD-EN-13:05.freebsd-update"
date = "2013-11-28"
[[notices]]
name = "FreeBSD-EN-13:04.freebsd-update"
date = "2013-10-26"
[[notices]]
name = "FreeBSD-EN-13:03.mfi"
date = "2013-08-22"
[[notices]]
name = "FreeBSD-EN-13:01.fxp"
date = "2013-06-28"
[[notices]]
name = "FreeBSD-EN-13:02.vtnet"
date = "2013-06-28"
[[notices]]
name = "FreeBSD-EN-12:02.ipv6refcount"
date = "2012-06-12"
[[notices]]
name = "FreeBSD-EN-12:01.freebsd-update"
date = "2012-01-04"
[[notices]]
name = "FreeBSD-EN-10:02.sched_ule"
date = "2010-02-27"
[[notices]]
name = "FreeBSD-EN-10:01.freebsd"
date = "2010-01-06"
[[notices]]
name = "FreeBSD-EN-09:05.null"
date = "2009-10-02"
[[notices]]
name = "FreeBSD-EN-09:04.fork"
date = "2009-06-24"
[[notices]]
name = "FreeBSD-EN-09:03.fxp"
date = "2009-06-24"
[[notices]]
name = "FreeBSD-EN-09:02.bce"
date = "2009-06-24"
[[notices]]
name = "FreeBSD-EN-09:01.kenv"
date = "2009-03-23"
[[notices]]
name = "FreeBSD-EN-08:02.tcp"
date = "2008-06-19"
[[notices]]
name = "FreeBSD-EN-08:01.libpthread"
date = "2008-04-17"
[[notices]]
name = "FreeBSD-EN-07:05.freebsd-update"
date = "2007-03-15"
[[notices]]
name = "FreeBSD-EN-07:04.zoneinfo"
date = "2007-02-28"
[[notices]]
name = "FreeBSD-EN-07:03.rc.d_jail"
date = "2007-02-28"
[[notices]]
name = "FreeBSD-EN-07:02.net"
date = "2007-02-28"
[[notices]]
name = "FreeBSD-EN-07:01.nfs"
date = "2007-02-14"
[[notices]]
name = "FreeBSD-EN-06:02.net"
date = "2006-08-28"
[[notices]]
name = "FreeBSD-EN-06:01.jail"
date = "2006-07-07"
[[notices]]
name = "FreeBSD-EN-05:04.nfs"
date = "2005-12-19"
[[notices]]
name = "FreeBSD-EN-05:03.ipi"
date = "2005-01-16"
[[notices]]
name = "FreeBSD-EN-05:02.sk"
date = "2005-01-06"
[[notices]]
name = "FreeBSD-EN-05:01.nfs"
date = "2005-01-05"
[[notices]]
name = "FreeBSD-EN-04:01.twe"
date = "2004-06-28"
diff --git a/website/static/security/advisories/FreeBSD-EN-21:26.libevent.asc b/website/static/security/advisories/FreeBSD-EN-21:26.libevent.asc
new file mode 100644
index 0000000000..a169171d52
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-21:26.libevent.asc
@@ -0,0 +1,132 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-21:26.libevent Errata Notice
+ The FreeBSD Project
+
+Topic: libevent1 ABI breakage
+
+Category: core
+Module: libevent1
+Announced: 2021-11-03
+Affects: FreeBSD 13.0
+Corrected: 2021-04-01 17:29:20 UTC (stable/13, 13.0-STABLE)
+ 2021-11-03 20:37:22 UTC (releng/13.0, 13.0-RELEASE-p5)
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security
+branches, and the following sections, please visit
+.
+
+I. Background
+
+libevent1 is a version of libevent in the base system used in ftp-proxy(8) and
+ypldap(8).
+
+II. Problem Description
+
+libevent1 maintains a local copy of some structure definitions from system
+headers to simplify consumers of the library. One of these structures no
+longer matched the corresponding system definition, causing inconsistent views
+of the `struct event` and `struct bufferevent` layouts.
+
+III. Impact
+
+ftp-proxy(8) will no longer handle incoming connections, ypldap(8) is likely
+affected as well.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date. No reboot will be required,
+but ftp-proxy and ypldap will need to be restarted.
+
+Perform one of the following:
+
+1) To update your system via a binary patch:
+
+Systems running a RELEASE version of FreeBSD on the amd64, i386, or
+(on FreeBSD 13 and later) arm64 platforms can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+
+2) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/EN-21:26/libevent.patch
+# fetch https://security.FreeBSD.org/patches/EN-21:26/libevent.patch.asc
+# gpg --verify libevent.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch < /path/to/patch
+
+c) Recompile the operating system using buildworld and installworld as
+described in .
+
+Restart the applicable daemons, or reboot the system.
+
+VI. Correction details
+
+This issue is corrected by the corresponding Git commit hash or Subversion
+revision number in the following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/13/ e0ad785a5d29 stable/13-n245086
+releng/13.0/ 5cd45ad4784b releng/13.0-n244761
+- -------------------------------------------------------------------------
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+Or visit the following URL, replacing NNNNNN with the revision number:
+
+
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD8QACgkQ05eS9J6n
+5cJe9g/6A2NIX4/0rlO0gGzTvYcRGb/0aAiR58mcinn5SNPVN40kzG93iq8AxKhq
+h9U2BtM/KZEIgbmwaltoQWQUrzHwF/K1pKFo6+u1nNSSbUy3dLV+rIDKXSinNND6
+vPkZIZbVBIsEWvMRbLexuuBI9QT+jEQFrMnRKocEXp3Yr0eooEzpseKUEfAS5yvt
++WlbN4m7lwCnod8gCT7phKATPfQZ1aKj46z5f99qc1+VyJ3323uI//1LsN9A7ra5
+sWW40FeNfbxKweaqgYZRqdwPvxtwh7luQGWBTk/2uQZ7yxEKLgGp5mRkIYG8GQsM
+d3gvGgw0ZUuRAjlA9io10T1Drb31pOR8/7aeD3EtsnBNEc3+M7OSOju5C1bU3put
+zAvForqifSq45wMTnW3CbsMdurq2JKhhAwpYXFib19Lv2yKVWNTOrtR6MGtbBv9b
+KSsJw2w8xLVN1/xGCtbrd4qZQhakQijyoqgG4reP1J+mw073WJVJMRG29YDvDcwD
+Zu+rAVlO7dz/uQZKowQJrWh4+kKxZCRbBPIQiQUxQ1T5XsCrQ6DNzvNZHuRWWoDs
+KV43T2RNgq70ur1sX4L+VSU0RVx4q9akGSD0lEl8pb/OvbEwCTWzs+UmjdpiTnUS
+b8ySlj56z6/yTpAVjQsHQijTCOy8L/uaVd2sXlr4sfDnbL+2mgg=
+=oYzJ
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-EN-21:27.caroot.asc b/website/static/security/advisories/FreeBSD-EN-21:27.caroot.asc
new file mode 100644
index 0000000000..2c7c5f51be
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-21:27.caroot.asc
@@ -0,0 +1,154 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-21:27.caroot Errata Notice
+ The FreeBSD Project
+
+Topic: Root certificate bundle update
+
+Category: core
+Module: caroot
+Announced: 2021-11-03
+Affects: FreeBSD 12.2 and later.
+Corrected: 2021-09-04 07:39:07 UTC (stable/13, 13.0-STABLE)
+ 2021-11-03 20:37:26 UTC (releng/13.0, 13.0-RELEASE-p5)
+ 2021-09-04 07:39:03 UTC (stable/12, 12.2-STABLE)
+ 2021-11-03 20:55:26 UTC (releng/12.2, 12.2-RELEASE-p11)
+
+Note: Systems running FreeBSD 12.3-BETA are unaffected.
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security
+branches, and the following sections, please visit
+.
+
+I. Background
+
+The root certificate bundle is the trust store that is used by OpenSSL
+programs and libraries to aide in determining whether it should trust
+a given TLS certificate.
+
+II. Problem Description
+
+Several certificates were removed from the bundle after the latest release
+of FreeBSD 12.2 and FreeBSD 13.0. Additionally, an oversight in the root
+bundle processor included some roots that were not intended to be trusted for
+these purposes (SERVER_AUTH).
+
+III. Impact
+
+Certificates are often removed from the root bundle due to a failure to
+meet the standards established by Mozilla for being considered a trusted
+Certificate Authority. Continuing to trust roots despite their removal from
+the bundle should be considered risky.
+
+IV. Workaround
+
+No workaround is available. Software that uses an internal trust store
+is not affected.
+
+V. Solution
+
+Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date.
+
+Perform one of the following:
+
+1) To update your system via a binary patch:
+
+Systems running a RELEASE version of FreeBSD on the amd64, i386, or
+(on FreeBSD 13 and later) arm64 platforms can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+
+2) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+[FreeBSD 13.0]
+# fetch https://security.FreeBSD.org/patches/EN-21:27/caroot.13.patch
+# fetch https://security.FreeBSD.org/patches/EN-21:27/caroot.13.patch.asc
+# gpg --verify caroot.13.patch.asc
+
+[FreeBSD 12.2]
+# fetch https://security.FreeBSD.org/patches/EN-21:27/caroot.12.patch
+# fetch https://security.FreeBSD.org/patches/EN-21:27/caroot.12.patch.asc
+# gpg --verify caroot.12.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch < /path/to/patch
+
+c) Recompile the operating system using buildworld and installworld as
+described in .
+
+Restart all applications that may be using OpenSSL, or reboot the system.
+
+VI. Correction details
+
+This issue is corrected by the corresponding Git commit hash or Subversion
+revision number in the following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/13/ 62aaa70143a6 stable/13-n247098
+releng/13.0/ b76aaa35423e releng/13.0-n244762
+stable/12/ r370507
+releng/12.2/ r370978
+- -------------------------------------------------------------------------
+
+For FreeBSD 13 and later:
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+For FreeBSD 12 and earlier:
+
+Run the following command to see which files were modified by a particular
+revision, replacing NNNNNN with the revision number:
+
+# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
+
+Or visit the following URL, replacing NNNNNN with the revision number:
+
+
+
+VII. References
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD88ACgkQ05eS9J6n
+5cKyaA//RQJ2wYygqL8o9iQK9FAl+gZO8x9C7Vlbgj1PBe0VHxlKoEmE48Iu4+vi
+56DR0rgPflx4EdqStFYzkjWnwIEhWGCJLIxFnDpL15/b3cxYoD+R9ipF3qt8ljz+
+Yyuw0NCCgyq36IfJMThQ3pKBOBbY8Bw4GLHAJE790AqXY+wIdUKdo+DxzYj/NcyS
+kbis9f+PCGPoDXSf4wMIj2IbE5LiMZbM6NF9QkmPE1ZzOh9eegsO2opm1FWE8UyD
+43i3HkpnBbKooq9yE/MpldrUH3+4VWiXpD0FtBMUY65ZMBSw2ddzzvupQ8jROkQq
+F6ZB4nwAVLwCiq7Yvwg5gTFyy6KUywdYs211R3SycjHwMoyCZOPLLFPqM1vio8u+
+Z1TItxKfW0/MT0yTQFNQK6CAPd92Co3mmEGKzPmvbxwK7idfB2lgFjExCeF3FwVU
+guUeIDTXDKQ+V0nynWERmDdI1S3x9bllZzIMU23BuuwKZDdR+lPJiKX1vUXmpe8p
+lmISyCVIg+0bIRL4WNAqceAIuUA/7zLCtCWF4OEl6utmb7hWVxmPH8GyjyzktLWh
+BwwHCspeT2h5y1leCVXigFv9nGgTj+kDXtgE4itIJXRPiliQ2j9VueGOe/I0gS/4
+9R2ro6t4UIi/E4T7Mp+oaiOGKARnE3Uf2aAelQbt9Do68taqTSU=
+=9hM5
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-EN-21:28.vmci.asc b/website/static/security/advisories/FreeBSD-EN-21:28.vmci.asc
new file mode 100644
index 0000000000..d4ec4fd0ff
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-21:28.vmci.asc
@@ -0,0 +1,145 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-21:28.vmci Errata Notice
+ The FreeBSD Project
+
+Topic: Fix kernel panic in vmci driver initialization
+
+Category: core
+Module: vmci
+Announced: 2021-11-03
+Affects: FreeBSD 12.x, FreeBSD 13.0
+Corrected: 2021-10-16 18:22:43 UTC (stable/13, 13.0-STABLE)
+ 2021-11-03 20:40:19 UTC (releng/13.0, 13.0-RELEASE-p5)
+ 2021-10-17 18:51:19 UTC (stable/12, 12.2-STABLE)
+ 2021-11-03 20:55:32 UTC (releng/12.2, 12.2-RELEASE-p11)
+
+Note: Systems running FreeBSD 12.3-BETA are unaffected.
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security
+branches, and the following sections, please visit
+.
+
+I. Background
+
+The vmci(4) driver implements VMware Virtual Machine Communication Interface
+for FreeBSD. It allows virtual machines to communicate with host kernel modules
+and VMware hypervisors.
+
+II. Problem Description
+
+An error during driver initialization results in a kernel panic due to unallocated
+resources being freed up.
+
+III. Impact
+
+The vmci(4) driver is loaded automatically by devd when the system is being
+run on the VMWare hypervisor. The kernel panic happens at the system boot stage.
+
+IV. Workaround
+
+No workaround is available.
+
+V. Solution
+
+Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date.
+
+Perform one of the following:
+
+1) To update your system via a binary patch:
+
+Systems running a RELEASE version of FreeBSD on the amd64, i386, or
+(on FreeBSD 13 and later) arm64 platforms can be updated via the
+freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+# shutdown -r now
+
+2) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/EN-21:28/vmci.patch
+# fetch https://security.FreeBSD.org/patches/EN-21:28/vmci.patch.asc
+# gpg --verify vmci.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch < /path/to/patch
+
+c) Recompile your kernel as described in
+ and reboot the
+system.
+
+VI. Correction details
+
+This issue is corrected by the corresponding Git commit hash or Subversion
+revision number in the following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/13/ 4e5c1be4202a stable/13-n247688
+releng/13.0/ 847819dca14d releng/13.0-n244763
+stable/12/ r370935
+releng/12.2/ r370979
+- -------------------------------------------------------------------------
+
+For FreeBSD 13 and later:
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+For FreeBSD 12 and earlier:
+
+Run the following command to see which files were modified by a particular
+revision, replacing NNNNNN with the revision number:
+
+# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
+
+Or visit the following URL, replacing NNNNNN with the revision number:
+
+
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD9AACgkQ05eS9J6n
+5cLAKxAApP3naU6wV6gwTGIVfugBt74TG6Q3thkg8mWqFUIRnpBgHH5yBrP7SESu
+N07Y21Z84tNzOoQtZs1MrF2gfW8KUdBC80wIT+1I8fEmteX/+8/6CKsu0JRh//n4
+8YXf5/BjqgC2aQXfm0Zp4ddKLymmq1rLrxJcjOGqlrVsxXgSyh/ExUbpM/vIUBDi
+DKSpK0zjv+54R0B3ihWM2+qRmMEMKEAwxNTm3IKVUyZymYm7SpLpKZetE9GFOmKU
+1AFlTomJmxbPcSGR2APu0R8xHf+wZIMiw1SqJR8bBrXxHjoVTrjl+PosIlX9jakE
+S9V0xbnVBSxsmIOfEXw3U8Q+AYCQ3bQXXJ1E6YmKCpOcqKYF8wC+iD7Q/OHzUCFE
+Hrnf8mNJHdZ8QK3WjdzfLwR2JAQ6yVJ2F2Bojqp+wwBIX+/Sq/mGPsZMVPVImdXj
+9OOo+O+nZmBVqRHcLeis/GOy7CdPlnVQOxdhMcR4DMv739dJwKDYb0iYHw86KM++
+3RNbJk89TSHGYGR4bKNZsDtq+9UUclBqwZesZSVDsgyB4gJvmqeBbV1g21yVdjw8
+ZvUI7MgI/4IB3Ac8qH5XSYdfUDZtDqzcjo6FnK/cEOYKFAgTPsCbBbbi3lZHoV9y
+Hz1Hwg0mqS1VEIUh8ipMTIod3yBiGoYEMiF4TGhpJhn100LaVFQ=
+=+4Iy
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/advisories/FreeBSD-EN-21:29.tzdata.asc b/website/static/security/advisories/FreeBSD-EN-21:29.tzdata.asc
new file mode 100644
index 0000000000..5da76853cf
--- /dev/null
+++ b/website/static/security/advisories/FreeBSD-EN-21:29.tzdata.asc
@@ -0,0 +1,168 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+=============================================================================
+FreeBSD-EN-21:29.tzdata Errata Notice
+ The FreeBSD Project
+
+Topic: Timezone database information update
+
+Category: contrib
+Module: zoneinfo
+Announced: 2021-11-03
+Affects: All supported versions of FreeBSD.
+Corrected: 2021-10-25 01:09:01 UTC (stable/13, 13.0-STABLE)
+ 2021-11-03 20:44:52 UTC (releng/13.0, 13.0-RELEASE-p5)
+ 2021-10-25 01:09:08 UTC (stable/12, 12.3-STABLE)
+ 2021-10-25 01:12:50 UTC (releng/12.3, 12.3-BETA1)
+ 2021-11-03 20:55:36 UTC (releng/12.2, 12.2-RELEASE-p11)
+
+Note: Systems running FreeBSD 12.3-BETA1 are affected, however 12.3-BETA2
+ and later are already remediated.
+
+For general information regarding FreeBSD Errata Notices and Security
+Advisories, including descriptions of the fields above, security
+branches, and the following sections, please visit
+.
+
+I. Background
+
+The tzsetup(8) program allows the user to specify the default local timezone.
+Based on the selected timezone, tzsetup(8) copies one of the files from
+/usr/share/zoneinfo to /etc/localtime. This file actually controls the
+conversion.
+
+II. Problem Description
+
+Several changes in Daylight Saving Time transition dates happened after
+previous FreeBSD releases were released affecting many users in different
+parts of the world. Because of these changes, the data in the zoneinfo files
+need to be updated, and if the local timezone on the running system is
+affected, tzsetup(8) needs to be run so the /etc/localtime is updated.
+
+III. Impact
+
+An incorrect time will be displayed on a system configured to use one of the
+affected timezones if the /usr/share/zoneinfo and /etc/localtime files are
+not updated, and all applications on the system that rely on the system time,
+such as cron(8) and syslog(8), will be affected.
+
+IV. Workaround
+
+The system administrator can install an updated timezone database from the
+misc/zoneinfo port and run tzsetup(8) to get the timezone database corrected.
+
+Applications that store and display times in Coordinated Universal Time (UTC)
+are not affected.
+
+V. Solution
+
+Please note that some third party software, for instance PHP, Ruby, Java, Perl
+and Python, may be using different zoneinfo data source, in such cases this
+software must be updated separately. Software packages that are installed via
+binary packages can be upgraded by executing `pkg upgrade'.
+
+Following the instructions in this Errata Notice will update all of the
+zoneinfo files to be the same as what was released with FreeBSD release.
+
+Perform one of the following:
+
+1) Upgrade your system to a supported FreeBSD stable or release / security
+branch (releng) dated after the correction date. Restart all the affected
+applications and daemons, or reboot the system.
+
+2) To update your system via a binary patch:
+
+Systems running a RELEASE version of FreeBSD on the i386 or amd64
+platforms can be updated via the freebsd-update(8) utility:
+
+# freebsd-update fetch
+# freebsd-update install
+
+Restart all the affected applications and daemons, or reboot the system.
+
+3) To update your system via a source code patch:
+
+The following patches have been verified to apply to the applicable
+FreeBSD release branches.
+
+a) Download the relevant patch from the location below, and verify the
+detached PGP signature using your PGP utility.
+
+# fetch https://security.FreeBSD.org/patches/EN-21:29/tzdata-2021a3.patch
+# fetch https://security.FreeBSD.org/patches/EN-21:29/tzdata-2021a3.patch.asc
+# gpg --verify tzdata-2021a3.patch.asc
+
+b) Apply the patch. Execute the following commands as root:
+
+# cd /usr/src
+# patch < /path/to/patch
+
+c) Recompile the operating system using buildworld and installworld as
+described in .
+
+Restart all the affected applications and daemons, or reboot the system.
+
+VI. Correction details
+
+This issue is corrected by the corresponding Git commit hash or Subversion
+revision number in the following stable and release branches:
+
+Branch/path Hash Revision
+- -------------------------------------------------------------------------
+stable/13/ ed325e2ec2dc stable/13-n247816
+releng/13.0/ 11754a61115f releng/13.0-n244764
+stable/12/ r370968
+releng/12.3/ r370969
+releng/12.2/ r370980
+- -------------------------------------------------------------------------
+
+For FreeBSD 13 and later:
+
+Run the following command to see which files were modified by a
+particular commit:
+
+# git show --stat
+
+Or visit the following URL, replacing NNNNNN with the hash:
+
+
+
+To determine the commit count in a working tree (for comparison against
+nNNNNNN in the table above), run:
+
+# git rev-list --count --first-parent HEAD
+
+For FreeBSD 12 and earlier:
+
+Run the following command to see which files were modified by a particular
+revision, replacing NNNNNN with the revision number:
+
+# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
+
+Or visit the following URL, replacing NNNNNN with the revision number:
+
+
+
+VII. References
+
+
+
+The latest revision of this advisory is available at
+
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD9AACgkQ05eS9J6n
+5cLIrg/+L/OYcepPmR4va4+0Q+vv90D0lsZGH/So6FJ2aa8zXdAmpQJaA5g+cptW
+pwwOPa58UzOVCuIZSlAsBubqj9XPT/LUFN0FxcsduyHf0izf2+tfjS/RsmOtzCD0
+muE5UwIDQwXdmDNnyWnrdBbBW94nqD3BU526LbG/RkmKumDgd4wPIuGsbFAcSiAW
+BVyrZQXdttyw6ZK7I7YxITsXtqrCMmYwDm4ZpnI+iLzh5droQxf7S2ejMTyKLPxQ
+mRNHQxa+TAVWZUyLDPT6mZc9yWzuM0huuIl70iTaz59SFcs2/s4Qw+J2WTVammsl
+4FzVoFjLD9/Bkx2JyghC5MD45XE5oHrxQ2duL6TLgqu1ZnN1EUvw8AS9TRD51pEP
+6ryG9OZ5ICpaiEniEbgfuvzbM3sJm0DwA84LVahpVD7fCflzimn4NESz6UyVDp86
+B9l1O2yRLpaMz5CIUBI9yRI7QefK2em3PE19n0/JGYZbSMOd5J9no3692vIMZhS9
+xEgUCRTpr68s2df+liXK1oKJe6v8uZWIeptINGLA9aHfYPw4pI4jYN67S93mhqXc
+ORO9VPTeJPrmmn82/fpPKFRZsi8nE+pHatCYeKwLA1ZiClDJo+nTcdIP8jMJAixW
+S1yDx0acbOWth7NzgRf3bdA3NZ9Vp8jX0oxmYYbJxQjh4K+mwRY=
+=uW9d
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-21:26/libevent.patch b/website/static/security/patches/EN-21:26/libevent.patch
new file mode 100644
index 0000000000..5cdc37d825
--- /dev/null
+++ b/website/static/security/patches/EN-21:26/libevent.patch
@@ -0,0 +1,10 @@
+--- contrib/pf/libevent/event.h.orig
++++ contrib/pf/libevent/event.h
+@@ -73,7 +73,6 @@
+ struct type *rbe_left; /* left element */ \
+ struct type *rbe_right; /* right element */ \
+ struct type *rbe_parent; /* parent element */ \
+- int rbe_color; /* node color */ \
+ }
+ #endif /* !RB_ENTRY */
+
diff --git a/website/static/security/patches/EN-21:26/libevent.patch.asc b/website/static/security/patches/EN-21:26/libevent.patch.asc
new file mode 100644
index 0000000000..aefeb09f3d
--- /dev/null
+++ b/website/static/security/patches/EN-21:26/libevent.patch.asc
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAABCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD88ACgkQ05eS9J6n
+5cLSDxAAmQxhTq0KDh6Sde2t92VLvkAj4WZbRnSCMP7fkqqd7YoC05/ptINbM2+I
+vB8SakIx8Ic5AUqniF43wRnTz1V4XIeM9f0iZyZyy+ksMB0hYPVVdx1AjWrCWDfA
+wEF38MoWXk4EPDinBL9QCfa85Vq0beivdcIFMbiDal1X6zK3iDATq8qNSX+ChshP
+Xno2QCCPwoZjPpZhRpb+j4MGP8Ro+jCJuawzwhsm999MbAF4GzKZqAzdF8i8oTda
+RHF9blnqo4Q3ENMfBs6pdKcxaymu+E82GioHqpEUkZdmQzcW2z15TBcX405Zbl8/
+vGeY7GMhTr7JDvw324bYdpRoDaO2HbBrDGaowCo1PgsAUKsat0qqGIzZ5aS22tPt
+DIixovSuGe8u1n21l3SX1LKmrVGfhLjl3IH8DHWrYxOMhI1iAQ42qDtD+kTUc5zS
+vNdGno1CBlCGKqUOwUlwJSE+hSxYV3+NOuqzunv5eHmnfwlEa4AtNZqx6NCBEcnt
+T9PCpEa3fIB5HiHGD1mFm8Zyjnk6kwdnUpnQeQKcYz+ShkjytXQ7tR79W+XdTSgf
+H6HDWEYGF1oRN+et/I/TgspdFcvq036xAFX7XzOFrp/93cZkPS2Dddwow7rzKGPK
+I/NpXu0tHiUwrkZu5BXmbuqLyLRRVQjsTehJGfKve9gdlWYZiEA=
+=tm73
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-21:27/caroot.12.patch b/website/static/security/patches/EN-21:27/caroot.12.patch
new file mode 100644
index 0000000000..b41f372bab
--- /dev/null
+++ b/website/static/security/patches/EN-21:27/caroot.12.patch
@@ -0,0 +1,6734 @@
+--- secure/caroot/MAca-bundle.pl.orig
++++ secure/caroot/MAca-bundle.pl
+@@ -76,6 +76,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $VERSION
+ ##
+@@ -91,6 +93,8 @@
+ ## Authorities (CA). These were automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt').
+ ##
++## It contains certificates trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $VERSION
+ ##
+@@ -100,6 +104,13 @@
+ }
+ }
+
++# returns a string like YYMMDDhhmmssZ of current time in GMT zone
++sub timenow()
++{
++ my ($sec,$min,$hour,$mday,$mon,$year,undef,undef,undef) = gmtime(time);
++ return sprintf "%02d%02d%02d%02d%02d%02dZ", $year-100, $mon+1, $mday, $hour, $min, $sec;
++}
++
+ sub printcert($$$)
+ {
+ my ($fh, $label, $certdata) = @_;
+@@ -110,6 +121,8 @@
+ close(OUT) or die "openssl x509 failed with exit code $?";
+ }
+
++# converts a datastream that is to be \177-style octal constants
++# from <> to a (binary) string and returns it
+ sub graboct($)
+ {
+ my $ifh = shift;
+@@ -125,13 +138,13 @@
+ return $data;
+ }
+
+-
+ sub grabcert($)
+ {
+ my $ifh = shift;
+ my $certdata;
+- my $cka_label;
+- my $serial;
++ my $cka_label = '';
++ my $serial = 0;
++ my $distrust = 0;
+
+ while (<$ifh>) {
+ chomp;
+@@ -148,6 +161,19 @@
+ if (/^CKA_SERIAL_NUMBER MULTILINE_OCTAL/) {
+ $serial = graboct($ifh);
+ }
++
++ if (/^CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL/)
++ {
++ my $distrust_after = graboct($ifh);
++ my $time_now = timenow();
++ if ($time_now >= $distrust_after) { $distrust = 1; }
++ if ($debug) {
++ printf STDERR "line $.: $cka_label ser #%d: distrust after %s, now: %s -> distrust $distrust\n", $serial, $distrust_after, timenow();
++ }
++ if ($distrust) {
++ return undef;
++ }
++ }
+ }
+ return ($serial, $cka_label, $certdata);
+ }
+@@ -171,13 +197,13 @@
+ $serial = graboct($ifh);
+ }
+
+- if (/^CKA_TRUST_(SERVER_AUTH|EMAIL_PROTECTION|CODE_SIGNING) CK_TRUST (\S+)$/)
++ if (/^CKA_TRUST_SERVER_AUTH CK_TRUST (\S+)$/)
+ {
+- if ($2 eq 'CKT_NSS_NOT_TRUSTED') {
++ if ($1 eq 'CKT_NSS_NOT_TRUSTED') {
+ $distrust = 1;
+- } elsif ($2 eq 'CKT_NSS_TRUSTED_DELEGATOR') {
++ } elsif ($1 eq 'CKT_NSS_TRUSTED_DELEGATOR') {
+ $maytrust = 1;
+- } elsif ($2 ne 'CKT_NSS_MUST_VERIFY_TRUST') {
++ } elsif ($1 ne 'CKT_NSS_MUST_VERIFY_TRUST') {
+ confess "Unknown trust setting on line $.:\n"
+ . "$_\n"
+ . "Script must be updated:";
+@@ -197,16 +223,22 @@
+ print_header(*STDOUT, "");
+ }
+
++my $untrusted = 0;
++
+ while (<$inputfh>) {
+ if (/^CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE/) {
+ my ($serial, $label, $certdata) = grabcert($inputfh);
+ if (defined $certs{$label."\0".$serial}) {
+ warn "Certificate $label duplicated!\n";
+ }
+- $certs{$label."\0".$serial} = $certdata;
+- # We store the label in a separate hash because truncating the key
+- # with \0 was causing garbage data after the end of the text.
+- $labels{$label."\0".$serial} = $label;
++ if (defined $certdata) {
++ $certs{$label."\0".$serial} = $certdata;
++ # We store the label in a separate hash because truncating the key
++ # with \0 was causing garbage data after the end of the text.
++ $labels{$label."\0".$serial} = $label;
++ } else { # $certdata undefined? distrust_after in effect
++ $untrusted ++;
++ }
+ } elsif (/^CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST/) {
+ my ($serial, $label, $trust) = grabtrust($inputfh);
+ if (defined $trusts{$label."\0".$serial}) {
+@@ -226,7 +258,6 @@
+ }
+
+ # weed out untrusted certificates
+-my $untrusted = 0;
+ foreach my $it (keys %trusts) {
+ if (!$trusts{$it}) {
+ if (!exists($certs{$it})) {
+--- /dev/null
++++ secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
+@@ -0,0 +1,112 @@
++##
++## Camerfirma Chambers of Commerce Root
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 0 (0x0)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
++ Validity
++ Not Before: Sep 30 16:13:43 2003 GMT
++ Not After : Sep 30 16:13:44 2037 GMT
++ Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:b7:36:55:e5:a5:5d:18:30:e0:da:89:54:91:fc:
++ c8:c7:52:f8:2f:50:d9:ef:b1:75:73:65:47:7d:1b:
++ 5b:ba:75:c5:fc:a1:88:24:fa:2f:ed:ca:08:4a:39:
++ 54:c4:51:7a:b5:da:60:ea:38:3c:81:b2:cb:f1:bb:
++ d9:91:23:3f:48:01:70:75:a9:05:2a:ad:1f:71:f3:
++ c9:54:3d:1d:06:6a:40:3e:b3:0c:85:ee:5c:1b:79:
++ c2:62:c4:b8:36:8e:35:5d:01:0c:23:04:47:35:aa:
++ 9b:60:4e:a0:66:3d:cb:26:0a:9c:40:a1:f4:5d:98:
++ bf:71:ab:a5:00:68:2a:ed:83:7a:0f:a2:14:b5:d4:
++ 22:b3:80:b0:3c:0c:5a:51:69:2d:58:18:8f:ed:99:
++ 9e:f1:ae:e2:95:e6:f6:47:a8:d6:0c:0f:b0:58:58:
++ db:c3:66:37:9e:9b:91:54:33:37:d2:94:1c:6a:48:
++ c9:c9:f2:a5:da:a5:0c:23:f7:23:0e:9c:32:55:5e:
++ 71:9c:84:05:51:9a:2d:fd:e6:4e:2a:34:5a:de:ca:
++ 40:37:67:0c:54:21:55:77:da:0a:0c:cc:97:ae:80:
++ dc:94:36:4a:f4:3e:ce:36:13:1e:53:e4:ac:4e:3a:
++ 05:ec:db:ae:72:9c:38:8b:d0:39:3b:89:0a:3e:77:
++ fe:75
++ Exponent: 3 (0x3)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 CRL Distribution Points:
++
++ Full Name:
++ URI:http://crl.chambersign.org/chambersroot.crl
++
++ X509v3 Subject Key Identifier:
++ E3:94:F5:B1:4D:E9:DB:A1:29:5B:57:8B:4D:76:06:76:E1:D1:A2:8A
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Netscape Cert Type:
++ SSL CA, S/MIME CA, Object Signing CA
++ X509v3 Subject Alternative Name:
++ email:chambersroot@chambersign.org
++ X509v3 Issuer Alternative Name:
++ email:chambersroot@chambersign.org
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.17326.10.3.1
++ CPS: http://cps.chambersign.org/cps/chambersroot.html
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 0c:41:97:c2:1a:86:c0:22:7c:9f:fb:90:f3:1a:d1:03:b1:ef:
++ 13:f9:21:5f:04:9c:da:c9:a5:8d:27:6c:96:87:91:be:41:90:
++ 01:72:93:e7:1e:7d:5f:f6:89:c6:5d:a7:40:09:3d:ac:49:45:
++ 45:dc:2e:8d:30:68:b2:09:ba:fb:c3:2f:cc:ba:0b:df:3f:77:
++ 7b:46:7d:3a:12:24:8e:96:8f:3c:05:0a:6f:d2:94:28:1d:6d:
++ 0c:c0:2e:88:22:d5:d8:cf:1d:13:c7:f0:48:d7:d7:05:a7:cf:
++ c7:47:9e:3b:3c:34:c8:80:4f:d4:14:bb:fc:0d:50:f7:fa:b3:
++ ec:42:5f:a9:dd:6d:c8:f4:75:cf:7b:c1:72:26:b1:01:1c:5c:
++ 2c:fd:7a:4e:b4:01:c5:05:57:b9:e7:3c:aa:05:d9:88:e9:07:
++ 46:41:ce:ef:41:81:ae:58:df:83:a2:ae:ca:d7:77:1f:e7:00:
++ 3c:9d:6f:8e:e4:32:09:1d:4d:78:34:78:34:3c:94:9b:26:ed:
++ 4f:71:c6:19:7a:bd:20:22:48:5a:fe:4b:7d:03:b7:e7:58:be:
++ c6:32:4e:74:1e:68:dd:a8:68:5b:b3:3e:ee:62:7d:d9:80:e8:
++ 0a:75:7a:b7:ee:b4:65:9a:21:90:e0:aa:d0:98:bc:38:b5:73:
++ 3c:8b:f8:dc
++SHA1 Fingerprint=6E:3A:55:A4:19:0C:19:5C:93:84:3C:C0:DB:72:2E:31:30:61:F0:B1
++-----BEGIN CERTIFICATE-----
++MIIEvTCCA6WgAwIBAgIBADANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJFVTEn
++MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
++ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEiMCAGA1UEAxMZQ2hhbWJlcnMg
++b2YgQ29tbWVyY2UgUm9vdDAeFw0wMzA5MzAxNjEzNDNaFw0zNzA5MzAxNjEzNDRa
++MH8xCzAJBgNVBAYTAkVVMScwJQYDVQQKEx5BQyBDYW1lcmZpcm1hIFNBIENJRiBB
++ODI3NDMyODcxIzAhBgNVBAsTGmh0dHA6Ly93d3cuY2hhbWJlcnNpZ24ub3JnMSIw
++IAYDVQQDExlDaGFtYmVycyBvZiBDb21tZXJjZSBSb290MIIBIDANBgkqhkiG9w0B
++AQEFAAOCAQ0AMIIBCAKCAQEAtzZV5aVdGDDg2olUkfzIx1L4L1DZ77F1c2VHfRtb
++unXF/KGIJPov7coISjlUxFF6tdpg6jg8gbLL8bvZkSM/SAFwdakFKq0fcfPJVD0d
++BmpAPrMMhe5cG3nCYsS4No41XQEMIwRHNaqbYE6gZj3LJgqcQKH0XZi/caulAGgq
++7YN6D6IUtdQis4CwPAxaUWktWBiP7Zme8a7ileb2R6jWDA+wWFjbw2Y3npuRVDM3
++0pQcakjJyfKl2qUMI/cjDpwyVV5xnIQFUZot/eZOKjRa3spAN2cMVCFVd9oKDMyX
++roDclDZK9D7ONhMeU+SsTjoF7Nuucpw4i9A5O4kKPnf+dQIBA6OCAUQwggFAMBIG
++A1UdEwEB/wQIMAYBAf8CAQwwPAYDVR0fBDUwMzAxoC+gLYYraHR0cDovL2NybC5j
++aGFtYmVyc2lnbi5vcmcvY2hhbWJlcnNyb290LmNybDAdBgNVHQ4EFgQU45T1sU3p
++26EpW1eLTXYGduHRooowDgYDVR0PAQH/BAQDAgEGMBEGCWCGSAGG+EIBAQQEAwIA
++BzAnBgNVHREEIDAegRxjaGFtYmVyc3Jvb3RAY2hhbWJlcnNpZ24ub3JnMCcGA1Ud
++EgQgMB6BHGNoYW1iZXJzcm9vdEBjaGFtYmVyc2lnbi5vcmcwWAYDVR0gBFEwTzBN
++BgsrBgEEAYGHLgoDATA+MDwGCCsGAQUFBwIBFjBodHRwOi8vY3BzLmNoYW1iZXJz
++aWduLm9yZy9jcHMvY2hhbWJlcnNyb290Lmh0bWwwDQYJKoZIhvcNAQEFBQADggEB
++AAxBl8IahsAifJ/7kPMa0QOx7xP5IV8EnNrJpY0nbJaHkb5BkAFyk+cefV/2icZd
++p0AJPaxJRUXcLo0waLIJuvvDL8y6C98/d3tGfToSJI6WjzwFCm/SlCgdbQzALogi
++1djPHRPH8EjX1wWnz8dHnjs8NMiAT9QUu/wNUPf6s+xCX6ndbcj0dc97wXImsQEc
++XCz9ek60AcUFV7nnPKoF2YjpB0ZBzu9Bga5Y34OirsrXdx/nADydb47kMgkdTXg0
++eDQ8lJsm7U9xxhl6vSAiSFr+S30Dt+dYvsYyTnQeaN2oaFuzPu5ifdmA6Ap1erfu
++tGWaIZDgqtCYvDi1czyL+Nw=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem
+@@ -0,0 +1,112 @@
++##
++## Camerfirma Global Chambersign Root
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 0 (0x0)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
++ Validity
++ Not Before: Sep 30 16:14:18 2003 GMT
++ Not After : Sep 30 16:14:18 2037 GMT
++ Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:a2:70:a2:d0:9f:42:ae:5b:17:c7:d8:7d:cf:14:
++ 83:fc:4f:c9:a1:b7:13:af:8a:d7:9e:3e:04:0a:92:
++ 8b:60:56:fa:b4:32:2f:88:4d:a1:60:08:f4:b7:09:
++ 4e:a0:49:2f:49:d6:d3:df:9d:97:5a:9f:94:04:70:
++ ec:3f:59:d9:b7:cc:66:8b:98:52:28:09:02:df:c5:
++ 2f:84:8d:7a:97:77:bf:ec:40:9d:25:72:ab:b5:3f:
++ 32:98:fb:b7:b7:fc:72:84:e5:35:87:f9:55:fa:a3:
++ 1f:0e:6f:2e:28:dd:69:a0:d9:42:10:c6:f8:b5:44:
++ c2:d0:43:7f:db:bc:e4:a2:3c:6a:55:78:0a:77:a9:
++ d8:ea:19:32:b7:2f:fe:5c:3f:1b:ee:b1:98:ec:ca:
++ ad:7a:69:45:e3:96:0f:55:f6:e6:ed:75:ea:65:e8:
++ 32:56:93:46:89:a8:25:8a:65:06:ee:6b:bf:79:07:
++ d0:f1:b7:af:ed:2c:4d:92:bb:c0:a8:5f:a7:67:7d:
++ 04:f2:15:08:70:ac:92:d6:7d:04:d2:33:fb:4c:b6:
++ 0b:0b:fb:1a:c9:c4:8d:03:a9:7e:5c:f2:50:ab:12:
++ a5:a1:cf:48:50:a5:ef:d2:c8:1a:13:fa:b0:7f:b1:
++ 82:1c:77:6a:0f:5f:dc:0b:95:8f:ef:43:7e:e6:45:
++ 09:25
++ Exponent: 3 (0x3)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 CRL Distribution Points:
++
++ Full Name:
++ URI:http://crl.chambersign.org/chambersignroot.crl
++
++ X509v3 Subject Key Identifier:
++ 43:9C:36:9F:B0:9E:30:4D:C6:CE:5F:AD:10:AB:E5:03:A5:FA:A9:14
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Netscape Cert Type:
++ SSL CA, S/MIME CA, Object Signing CA
++ X509v3 Subject Alternative Name:
++ email:chambersignroot@chambersign.org
++ X509v3 Issuer Alternative Name:
++ email:chambersignroot@chambersign.org
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.17326.10.1.1
++ CPS: http://cps.chambersign.org/cps/chambersignroot.html
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 3c:3b:70:91:f9:04:54:27:91:e1:ed:ed:fe:68:7f:61:5d:e5:
++ 41:65:4f:32:f1:18:05:94:6a:1c:de:1f:70:db:3e:7b:32:02:
++ 34:b5:0c:6c:a1:8a:7c:a5:f4:8f:ff:d4:d8:ad:17:d5:2d:04:
++ d1:3f:58:80:e2:81:59:88:be:c0:e3:46:93:24:fe:90:bd:26:
++ a2:30:2d:e8:97:26:57:35:89:74:96:18:f6:15:e2:af:24:19:
++ 56:02:02:b2:ba:0f:14:ea:c6:8a:66:c1:86:45:55:8b:be:92:
++ be:9c:a4:04:c7:49:3c:9e:e8:29:7a:89:d7:fe:af:ff:68:f5:
++ a5:17:90:bd:ac:99:cc:a5:86:57:09:67:46:db:d6:16:c2:46:
++ f1:e4:a9:50:f5:8f:d1:92:15:d3:5f:3e:c6:00:49:3a:6e:58:
++ b2:d1:d1:27:0d:25:c8:32:f8:20:11:cd:7d:32:33:48:94:54:
++ 4c:dd:dc:79:c4:30:9f:eb:8e:b8:55:b5:d7:88:5c:c5:6a:24:
++ 3d:b2:d3:05:03:51:c6:07:ef:cc:14:72:74:3d:6e:72:ce:18:
++ 28:8c:4a:a0:77:e5:09:2b:45:44:47:ac:b7:67:7f:01:8a:05:
++ 5a:93:be:a1:c1:ff:f8:e7:0e:67:a4:47:49:76:5d:75:90:1a:
++ f5:26:8f:f0
++SHA1 Fingerprint=33:9B:6B:14:50:24:9B:55:7A:01:87:72:84:D9:E0:2F:C3:D2:D8:E9
++-----BEGIN CERTIFICATE-----
++MIIExTCCA62gAwIBAgIBADANBgkqhkiG9w0BAQUFADB9MQswCQYDVQQGEwJFVTEn
++MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
++ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4GA1UEAxMXR2xvYmFsIENo
++YW1iZXJzaWduIFJvb3QwHhcNMDMwOTMwMTYxNDE4WhcNMzcwOTMwMTYxNDE4WjB9
++MQswCQYDVQQGEwJFVTEnMCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgy
++NzQzMjg3MSMwIQYDVQQLExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4G
++A1UEAxMXR2xvYmFsIENoYW1iZXJzaWduIFJvb3QwggEgMA0GCSqGSIb3DQEBAQUA
++A4IBDQAwggEIAoIBAQCicKLQn0KuWxfH2H3PFIP8T8mhtxOviteePgQKkotgVvq0
++Mi+ITaFgCPS3CU6gSS9J1tPfnZdan5QEcOw/Wdm3zGaLmFIoCQLfxS+EjXqXd7/s
++QJ0lcqu1PzKY+7e3/HKE5TWH+VX6ox8Oby4o3Wmg2UIQxvi1RMLQQ3/bvOSiPGpV
++eAp3qdjqGTK3L/5cPxvusZjsyq16aUXjlg9V9ubtdepl6DJWk0aJqCWKZQbua795
++B9Dxt6/tLE2Su8CoX6dnfQTyFQhwrJLWfQTSM/tMtgsL+xrJxI0DqX5c8lCrEqWh
++z0hQpe/SyBoT+rB/sYIcd2oPX9wLlY/vQ37mRQklAgEDo4IBUDCCAUwwEgYDVR0T
++AQH/BAgwBgEB/wIBDDA/BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vY3JsLmNoYW1i
++ZXJzaWduLm9yZy9jaGFtYmVyc2lnbnJvb3QuY3JsMB0GA1UdDgQWBBRDnDafsJ4w
++TcbOX60Qq+UDpfqpFDAOBgNVHQ8BAf8EBAMCAQYwEQYJYIZIAYb4QgEBBAQDAgAH
++MCoGA1UdEQQjMCGBH2NoYW1iZXJzaWducm9vdEBjaGFtYmVyc2lnbi5vcmcwKgYD
++VR0SBCMwIYEfY2hhbWJlcnNpZ25yb290QGNoYW1iZXJzaWduLm9yZzBbBgNVHSAE
++VDBSMFAGCysGAQQBgYcuCgEBMEEwPwYIKwYBBQUHAgEWM2h0dHA6Ly9jcHMuY2hh
++bWJlcnNpZ24ub3JnL2Nwcy9jaGFtYmVyc2lnbnJvb3QuaHRtbDANBgkqhkiG9w0B
++AQUFAAOCAQEAPDtwkfkEVCeR4e3t/mh/YV3lQWVPMvEYBZRqHN4fcNs+ezICNLUM
++bKGKfKX0j//U2K0X1S0E0T9YgOKBWYi+wONGkyT+kL0mojAt6JcmVzWJdJYY9hXi
++ryQZVgICsroPFOrGimbBhkVVi76SvpykBMdJPJ7oKXqJ1/6v/2j1pReQvayZzKWG
++VwlnRtvWFsJG8eSpUPWP0ZIV018+xgBJOm5YstHRJw0lyDL4IBHNfTIzSJRUTN3c
++ecQwn+uOuFW114hcxWokPbLTBQNRxgfvzBRydD1ucs4YKIxKoHflCStFREest2d/
++AYoFWpO+ocH/+OcOZ6RHSXZddZAa9SaP8A==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Certum_Root_CA.pem
+@@ -0,0 +1,84 @@
++##
++## Certum Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 65568 (0x10020)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
++ Validity
++ Not Before: Jun 11 10:46:39 2002 GMT
++ Not After : Jun 11 10:46:39 2027 GMT
++ Subject: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:ce:b1:c1:2e:d3:4f:7c:cd:25:ce:18:3e:4f:c4:
++ 8c:6f:80:6a:73:c8:5b:51:f8:9b:d2:dc:bb:00:5c:
++ b1:a0:fc:75:03:ee:81:f0:88:ee:23:52:e9:e6:15:
++ 33:8d:ac:2d:09:c5:76:f9:2b:39:80:89:e4:97:4b:
++ 90:a5:a8:78:f8:73:43:7b:a4:61:b0:d8:58:cc:e1:
++ 6c:66:7e:9c:f3:09:5e:55:63:84:d5:a8:ef:f3:b1:
++ 2e:30:68:b3:c4:3c:d8:ac:6e:8d:99:5a:90:4e:34:
++ dc:36:9a:8f:81:88:50:b7:6d:96:42:09:f3:d7:95:
++ 83:0d:41:4b:b0:6a:6b:f8:fc:0f:7e:62:9f:67:c4:
++ ed:26:5f:10:26:0f:08:4f:f0:a4:57:28:ce:8f:b8:
++ ed:45:f6:6e:ee:25:5d:aa:6e:39:be:e4:93:2f:d9:
++ 47:a0:72:eb:fa:a6:5b:af:ca:53:3f:e2:0e:c6:96:
++ 56:11:6e:f7:e9:66:a9:26:d8:7f:95:53:ed:0a:85:
++ 88:ba:4f:29:a5:42:8c:5e:b6:fc:85:20:00:aa:68:
++ 0b:a1:1a:85:01:9c:c4:46:63:82:88:b6:22:b1:ee:
++ fe:aa:46:59:7e:cf:35:2c:d5:b6:da:5d:f7:48:33:
++ 14:54:b6:eb:d9:6f:ce:cd:88:d6:ab:1b:da:96:3b:
++ 1d:59
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ Signature Algorithm: sha1WithRSAEncryption
++ b8:8d:ce:ef:e7:14:ba:cf:ee:b0:44:92:6c:b4:39:3e:a2:84:
++ 6e:ad:b8:21:77:d2:d4:77:82:87:e6:20:41:81:ee:e2:f8:11:
++ b7:63:d1:17:37:be:19:76:24:1c:04:1a:4c:eb:3d:aa:67:6f:
++ 2d:d4:cd:fe:65:31:70:c5:1b:a6:02:0a:ba:60:7b:6d:58:c2:
++ 9a:49:fe:63:32:0b:6b:e3:3a:c0:ac:ab:3b:b0:e8:d3:09:51:
++ 8c:10:83:c6:34:e0:c5:2b:e0:1a:b6:60:14:27:6c:32:77:8c:
++ bc:b2:72:98:cf:cd:cc:3f:b9:c8:24:42:14:d6:57:fc:e6:26:
++ 43:a9:1d:e5:80:90:ce:03:54:28:3e:f7:3f:d3:f8:4d:ed:6a:
++ 0a:3a:93:13:9b:3b:14:23:13:63:9c:3f:d1:87:27:79:e5:4c:
++ 51:e3:01:ad:85:5d:1a:3b:b1:d5:73:10:a4:d3:f2:bc:6e:64:
++ f5:5a:56:90:a8:c7:0e:4c:74:0f:2e:71:3b:f7:c8:47:f4:69:
++ 6f:15:f2:11:5e:83:1e:9c:7c:52:ae:fd:02:da:12:a8:59:67:
++ 18:db:bc:70:dd:9b:b1:69:ed:80:ce:89:40:48:6a:0e:35:ca:
++ 29:66:15:21:94:2c:e8:60:2a:9b:85:4a:40:f3:6b:8a:24:ec:
++ 06:16:2c:73
++SHA1 Fingerprint=62:52:DC:40:F7:11:43:A2:2F:DE:9E:F7:34:8E:06:42:51:B1:81:18
++-----BEGIN CERTIFICATE-----
++MIIDDDCCAfSgAwIBAgIDAQAgMA0GCSqGSIb3DQEBBQUAMD4xCzAJBgNVBAYTAlBM
++MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
++QTAeFw0wMjA2MTExMDQ2MzlaFw0yNzA2MTExMDQ2MzlaMD4xCzAJBgNVBAYTAlBM
++MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
++QTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM6xwS7TT3zNJc4YPk/E
++jG+AanPIW1H4m9LcuwBcsaD8dQPugfCI7iNS6eYVM42sLQnFdvkrOYCJ5JdLkKWo
++ePhzQ3ukYbDYWMzhbGZ+nPMJXlVjhNWo7/OxLjBos8Q82KxujZlakE403Daaj4GI
++ULdtlkIJ89eVgw1BS7Bqa/j8D35in2fE7SZfECYPCE/wpFcozo+47UX2bu4lXapu
++Ob7kky/ZR6By6/qmW6/KUz/iDsaWVhFu9+lmqSbYf5VT7QqFiLpPKaVCjF62/IUg
++AKpoC6EahQGcxEZjgoi2IrHu/qpGWX7PNSzVttpd90gzFFS269lvzs2I1qsb2pY7
++HVkCAwEAAaMTMBEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEA
++uI3O7+cUus/usESSbLQ5PqKEbq24IXfS1HeCh+YgQYHu4vgRt2PRFze+GXYkHAQa
++TOs9qmdvLdTN/mUxcMUbpgIKumB7bVjCmkn+YzILa+M6wKyrO7Do0wlRjBCDxjTg
++xSvgGrZgFCdsMneMvLJymM/NzD+5yCRCFNZX/OYmQ6kd5YCQzgNUKD73P9P4Te1q
++CjqTE5s7FCMTY5w/0YcneeVMUeMBrYVdGjux1XMQpNPyvG5k9VpWkKjHDkx0Dy5x
++O/fIR/RpbxXyEV6DHpx8Uq79AtoSqFlnGNu8cN2bsWntgM6JQEhqDjXKKWYVIZQs
++6GAqm4VKQPNriiTsBhYscw==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
+@@ -0,0 +1,152 @@
++##
++## Chambers of Commerce Root - 2008
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ a3:da:42:7e:a4:b1:ae:da
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
++ Validity
++ Not Before: Aug 1 12:29:50 2008 GMT
++ Not After : Jul 31 12:29:50 2038 GMT
++ Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:af:00:cb:70:37:2b:80:5a:4a:3a:6c:78:94:7d:
++ a3:7f:1a:1f:f6:35:d5:bd:db:cb:0d:44:72:3e:26:
++ b2:90:52:ba:63:3b:28:58:6f:a5:b3:6d:94:a6:f3:
++ dd:64:0c:55:f6:f6:e7:f2:22:22:80:5e:e1:62:c6:
++ b6:29:e1:81:6c:f2:bf:e5:7d:32:6a:54:a0:32:19:
++ 59:fe:1f:8b:d7:3d:60:86:85:24:6f:e3:11:b3:77:
++ 3e:20:96:35:21:6b:b3:08:d9:70:2e:64:f7:84:92:
++ 53:d6:0e:b0:90:8a:8a:e3:87:8d:06:d3:bd:90:0e:
++ e2:99:a1:1b:86:0e:da:9a:0a:bb:0b:61:50:06:52:
++ f1:9e:7f:76:ec:cb:0f:d0:1e:0d:cf:99:30:3d:1c:
++ c4:45:10:58:ac:d6:d3:e8:d7:e5:ea:c5:01:07:77:
++ d6:51:e6:03:7f:8a:48:a5:4d:68:75:b9:e9:bc:9e:
++ 4e:19:71:f5:32:4b:9c:6d:60:19:0b:fb:cc:9d:75:
++ dc:bf:26:cd:8f:93:78:39:79:73:5e:25:0e:ca:5c:
++ eb:77:12:07:cb:64:41:47:72:93:ab:50:c3:eb:09:
++ 76:64:34:d2:39:b7:76:11:09:0d:76:45:c4:a9:ae:
++ 3d:6a:af:b5:7d:65:2f:94:58:10:ec:5c:7c:af:7e:
++ e2:b6:18:d9:d0:9b:4e:5a:49:df:a9:66:0b:cc:3c:
++ c6:78:7c:a7:9c:1d:e3:ce:8e:53:be:05:de:60:0f:
++ 6b:e5:1a:db:3f:e3:e1:21:c9:29:c1:f1:eb:07:9c:
++ 52:1b:01:44:51:3c:7b:25:d7:c4:e5:52:54:5d:25:
++ 07:ca:16:20:b8:ad:e4:41:ee:7a:08:fe:99:6f:83:
++ a6:91:02:b0:6c:36:55:6a:e7:7d:f5:96:e6:ca:81:
++ d6:97:f1:94:83:e9:ed:b0:b1:6b:12:69:1e:ac:fb:
++ 5d:a9:c5:98:e9:b4:5b:58:7a:be:3d:a2:44:3a:63:
++ 59:d4:0b:25:de:1b:4f:bd:e5:01:9e:cd:d2:29:d5:
++ 9f:17:19:0a:6f:bf:0c:90:d3:09:5f:d9:e3:8a:35:
++ cc:79:5a:4d:19:37:92:b7:c4:c1:ad:af:f4:79:24:
++ 9a:b2:01:0b:b1:af:5c:96:f3:80:32:fb:5c:3d:98:
++ f1:a0:3f:4a:de:be:af:94:2e:d9:55:9a:17:6e:60:
++ 9d:63:6c:b8:63:c9:ae:81:5c:18:35:e0:90:bb:be:
++ 3c:4f:37:22:b9:7e:eb:cf:9e:77:21:a6:3d:38:81:
++ fb:48:da:31:3d:2b:e3:89:f5:d0:b5:bd:7e:e0:50:
++ c4:12:89:b3:23:9a:10:31:85:db:ae:6f:ef:38:33:
++ 18:76:11
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 Subject Key Identifier:
++ F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
++ X509v3 Authority Key Identifier:
++ keyid:F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
++ DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Chambers of Commerce Root - 2008
++ serial:A3:DA:42:7E:A4:B1:AE:DA
++
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Certificate Policies:
++ Policy: X509v3 Any Policy
++ CPS: http://policy.camerfirma.com
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 90:12:af:22:35:c2:a3:39:f0:2e:de:e9:b5:e9:78:7c:48:be:
++ 3f:7d:45:92:5e:e9:da:b1:19:fc:16:3c:9f:b4:5b:66:9e:6a:
++ e7:c3:b9:5d:88:e8:0f:ad:cf:23:0f:de:25:3a:5e:cc:4f:a5:
++ c1:b5:2d:ac:24:d2:58:07:de:a2:cf:69:84:60:33:e8:10:0d:
++ 13:a9:23:d0:85:e5:8e:7b:a6:9e:3d:72:13:72:33:f5:aa:7d:
++ c6:63:1f:08:f4:fe:01:7f:24:cf:2b:2c:54:09:de:e2:2b:6d:
++ 92:c6:39:4f:16:ea:3c:7e:7a:46:d4:45:6a:46:a8:eb:75:82:
++ 56:a7:ab:a0:7c:68:13:33:f6:9d:30:f0:6f:27:39:24:23:2a:
++ 90:fd:90:29:35:f2:93:df:34:a5:c6:f7:f8:ef:8c:0f:62:4a:
++ 7c:ae:d3:f5:54:f8:8d:b6:9a:56:87:16:82:3a:33:ab:5a:22:
++ 08:f7:82:ba:ea:2e:e0:47:9a:b4:b5:45:a3:05:3b:d9:dc:2e:
++ 45:40:3b:ea:dc:7f:e8:3b:eb:d1:ec:26:d8:35:a4:30:c5:3a:
++ ac:57:9e:b3:76:a5:20:7b:f9:1e:4a:05:62:01:a6:28:75:60:
++ 97:92:0d:6e:3e:4d:37:43:0d:92:15:9c:18:22:cd:51:99:a0:
++ 29:1a:3c:5f:8a:32:33:5b:30:c7:89:2f:47:98:0f:a3:03:c6:
++ f6:f1:ac:df:32:f0:d9:81:1a:e4:9c:bd:f6:80:14:f0:d1:2c:
++ b9:85:f5:d8:a3:b1:c8:a5:21:e5:1c:13:97:ee:0e:bd:df:29:
++ a9:ef:34:53:5b:d3:e4:6a:13:84:06:b6:32:02:c4:52:ae:22:
++ d2:dc:b2:21:42:1a:da:40:f0:29:c9:ec:0a:0c:5c:e2:d0:ba:
++ cc:48:d3:37:0a:cc:12:0a:8a:79:b0:3d:03:7f:69:4b:f4:34:
++ 20:7d:b3:34:ea:8e:4b:64:f5:3e:fd:b3:23:67:15:0d:04:b8:
++ f0:2d:c1:09:51:3c:b2:6c:15:f0:a5:23:d7:83:74:e4:e5:2e:
++ c9:fe:98:27:42:c6:ab:c6:9e:b0:d0:5b:38:a5:9b:50:de:7e:
++ 18:98:b5:45:3b:f6:79:b4:e8:f7:1a:7b:06:83:fb:d0:8b:da:
++ bb:c7:bd:18:ab:08:6f:3c:80:6b:40:3f:19:19:ba:65:8a:e6:
++ be:d5:5c:d3:36:d7:ef:40:52:24:60:38:67:04:31:ec:8f:f3:
++ 82:c6:de:b9:55:f3:3b:31:91:5a:dc:b5:08:15:ad:76:25:0a:
++ 0d:7b:2e:87:e2:0c:a6:06:bc:26:10:6d:37:9d:ec:dd:78:8c:
++ 7c:80:c5:f0:d9:77:48:d0
++SHA1 Fingerprint=78:6A:74:AC:76:AB:14:7F:9C:6A:30:50:BA:9E:A8:7E:FE:9A:CE:3C
++-----BEGIN CERTIFICATE-----
++MIIHTzCCBTegAwIBAgIJAKPaQn6ksa7aMA0GCSqGSIb3DQEBBQUAMIGuMQswCQYD
++VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
++IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
++MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xKTAnBgNVBAMTIENoYW1iZXJz
++IG9mIENvbW1lcmNlIFJvb3QgLSAyMDA4MB4XDTA4MDgwMTEyMjk1MFoXDTM4MDcz
++MTEyMjk1MFowga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpNYWRyaWQgKHNlZSBj
++dXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29tL2FkZHJlc3MpMRIw
++EAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVyZmlybWEgUy5BLjEp
++MCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAtIDIwMDgwggIiMA0G
++CSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCvAMtwNyuAWko6bHiUfaN/Gh/2NdW9
++28sNRHI+JrKQUrpjOyhYb6WzbZSm891kDFX29ufyIiKAXuFixrYp4YFs8r/lfTJq
++VKAyGVn+H4vXPWCGhSRv4xGzdz4gljUha7MI2XAuZPeEklPWDrCQiorjh40G072Q
++DuKZoRuGDtqaCrsLYVAGUvGef3bsyw/QHg3PmTA9HMRFEFis1tPo1+XqxQEHd9ZR
++5gN/ikilTWh1uem8nk4ZcfUyS5xtYBkL+8ydddy/Js2Pk3g5eXNeJQ7KXOt3EgfL
++ZEFHcpOrUMPrCXZkNNI5t3YRCQ12RcSprj1qr7V9ZS+UWBDsXHyvfuK2GNnQm05a
++Sd+pZgvMPMZ4fKecHePOjlO+Bd5gD2vlGts/4+EhySnB8esHnFIbAURRPHsl18Tl
++UlRdJQfKFiC4reRB7noI/plvg6aRArBsNlVq5331lubKgdaX8ZSD6e2wsWsSaR6s
+++12pxZjptFtYer49okQ6Y1nUCyXeG0+95QGezdIp1Z8XGQpvvwyQ0wlf2eOKNcx5
++Wk0ZN5K3xMGtr/R5JJqyAQuxr1yW84Ay+1w9mPGgP0revq+ULtlVmhduYJ1jbLhj
++ya6BXBg14JC7vjxPNyK5fuvPnnchpj04gftI2jE9K+OJ9dC1vX7gUMQSibMjmhAx
++hduub+84Mxh2EQIDAQABo4IBbDCCAWgwEgYDVR0TAQH/BAgwBgEB/wIBDDAdBgNV
++HQ4EFgQU+SSsD7K1+HnA+mCIG8TZTQKeFxkwgeMGA1UdIwSB2zCB2IAU+SSsD7K1
+++HnA+mCIG8TZTQKeFxmhgbSkgbEwga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpN
++YWRyaWQgKHNlZSBjdXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29t
++L2FkZHJlc3MpMRIwEAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVy
++ZmlybWEgUy5BLjEpMCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAt
++IDIwMDiCCQCj2kJ+pLGu2jAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRV
++HSAAMCowKAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20w
++DQYJKoZIhvcNAQEFBQADggIBAJASryI1wqM58C7e6bXpeHxIvj99RZJe6dqxGfwW
++PJ+0W2aeaufDuV2I6A+tzyMP3iU6XsxPpcG1Lawk0lgH3qLPaYRgM+gQDROpI9CF
++5Y57pp49chNyM/WqfcZjHwj0/gF/JM8rLFQJ3uIrbZLGOU8W6jx+ekbURWpGqOt1
++glanq6B8aBMz9p0w8G8nOSQjKpD9kCk18pPfNKXG9/jvjA9iSnyu0/VU+I22mlaH
++FoI6M6taIgj3grrqLuBHmrS1RaMFO9ncLkVAO+rcf+g769HsJtg1pDDFOqxXnrN2
++pSB7+R5KBWIBpih1YJeSDW4+TTdDDZIVnBgizVGZoCkaPF+KMjNbMMeJL0eYD6MD
++xvbxrN8y8NmBGuScvfaAFPDRLLmF9dijscilIeUcE5fuDr3fKanvNFNb0+RqE4QG
++tjICxFKuItLcsiFCGtpA8CnJ7AoMXOLQusxI0zcKzBIKinmwPQN/aUv0NCB9szTq
++jktk9T79syNnFQ0EuPAtwQlRPLJsFfClI9eDdOTlLsn+mCdCxqvGnrDQWzilm1De
++fhiYtUU79nm06PcaewaD+9CL2rvHvRirCG88gGtAPxkZumWK5r7VXNM21+9AUiRg
++OGcEMeyP84LG3rlV8zsxkVrctQgVrXYlCg17LofiDKYGvCYQbTed7N14jHyAxfDZ
++d0jQ
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem
+@@ -0,0 +1,101 @@
++##
++## D-TRUST Root CA 3 2013
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 1039788 (0xfddac)
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
++ Validity
++ Not Before: Sep 20 08:25:51 2013 GMT
++ Not After : Sep 20 08:25:51 2028 GMT
++ Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c4:7b:42:92:82:1f:ec:ed:54:98:8e:12:c0:ca:
++ 09:df:93:6e:3a:93:5c:1b:e4:10:77:9e:4e:69:88:
++ 6c:f6:e1:69:f2:f6:9b:a2:61:b1:bd:07:20:74:98:
++ 65:f1:8c:26:08:cd:a8:35:ca:80:36:d1:63:6d:e8:
++ 44:7a:82:c3:6c:5e:de:bb:e8:36:d2:c4:68:36:8c:
++ 9f:32:bd:84:22:e0:dc:c2:ee:10:46:39:6d:af:93:
++ 39:ae:87:e6:c3:bc:09:c9:2c:6b:67:5b:d9:9b:76:
++ 75:4c:0b:e0:bb:c5:d7:bc:3e:79:f2:5f:be:d1:90:
++ 57:f9:ae:f6:66:5f:31:bf:d3:6d:8f:a7:ba:4a:f3:
++ 23:65:bb:b7:ef:a3:25:d7:0a:ea:58:b6:ef:88:fa:
++ fa:79:b2:52:58:d5:f0:ac:8c:a1:51:74:29:95:aa:
++ 51:3b:90:32:03:9f:1c:72:74:90:de:3d:ed:61:d2:
++ e5:e3:fd:64:47:e5:b9:b7:4a:a9:f7:1f:ae:96:86:
++ 04:ac:2f:e3:a4:81:77:b7:5a:16:ff:d8:0f:3f:f6:
++ b7:78:cc:a4:af:fa:5b:3c:12:5b:a8:52:89:72:ef:
++ 88:f3:d5:44:81:86:95:23:9f:7b:dd:bc:d9:34:ef:
++ 7c:94:3c:aa:c0:41:c2:e3:9d:50:1a:c0:e4:19:22:
++ fc:b3
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 3F:90:C8:7D:C7:15:6F:F3:24:8F:A9:C3:2F:4B:A2:0F:21:B2:2F:E7
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 CRL Distribution Points:
++
++ Full Name:
++ URI:ldap://directory.d-trust.net/CN=D-TRUST%20Root%20CA%203%202013,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
++
++ Full Name:
++ URI:http://crl.d-trust.net/crl/d-trust_root_ca_3_2013.crl
++
++ Signature Algorithm: sha256WithRSAEncryption
++ 0e:59:0e:58:e4:74:48:23:44:cf:34:21:b5:9c:14:1a:ad:9a:
++ 4b:b7:b3:88:6d:5c:a9:17:70:f0:2a:9f:8d:7b:f9:7b:85:fa:
++ c7:39:e8:10:08:b0:35:2b:5f:cf:02:d2:d3:9c:c8:0b:1e:ee:
++ 05:54:ae:37:93:04:09:7d:6c:8f:c2:74:bc:f8:1c:94:be:31:
++ 01:40:2d:f3:24:20:b7:84:55:2c:5c:c8:f5:74:4a:10:19:8b:
++ a3:c7:ed:35:d6:09:48:d3:0e:c0:ba:39:a8:b0:46:02:b0:db:
++ c6:88:59:c2:be:fc:7b:b1:2b:cf:7e:62:87:55:96:cc:01:6f:
++ 9b:67:21:95:35:8b:f8:10:fc:71:1b:b7:4b:37:69:a6:3b:d6:
++ ec:8b:ee:c1:b0:f3:25:c9:8f:92:7d:a1:ea:c3:ca:44:bf:26:
++ a5:74:92:9c:e3:74:eb:9d:74:d9:cb:4d:87:d8:fc:b4:69:6c:
++ 8b:a0:43:07:60:78:97:e9:d9:93:7c:c2:46:bc:9b:37:52:a3:
++ ed:8a:3c:13:a9:7b:53:4b:49:9a:11:05:2c:0b:6e:56:ac:1f:
++ 2e:82:6c:e0:69:67:b5:0e:6d:2d:d9:e4:c0:15:f1:3f:fa:18:
++ 72:e1:15:6d:27:5b:2d:30:28:2b:9f:48:9a:64:2b:99:ef:f2:
++ 75:49:5f:5c
++SHA1 Fingerprint=6C:7C:CC:E7:D4:AE:51:5F:99:08:CD:3F:F6:E8:C3:78:DF:6F:EF:97
++-----BEGIN CERTIFICATE-----
++MIIEDjCCAvagAwIBAgIDD92sMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkRF
++MRUwEwYDVQQKDAxELVRydXN0IEdtYkgxHzAdBgNVBAMMFkQtVFJVU1QgUm9vdCBD
++QSAzIDIwMTMwHhcNMTMwOTIwMDgyNTUxWhcNMjgwOTIwMDgyNTUxWjBFMQswCQYD
++VQQGEwJERTEVMBMGA1UECgwMRC1UcnVzdCBHbWJIMR8wHQYDVQQDDBZELVRSVVNU
++IFJvb3QgQ0EgMyAyMDEzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
++xHtCkoIf7O1UmI4SwMoJ35NuOpNcG+QQd55OaYhs9uFp8vabomGxvQcgdJhl8Ywm
++CM2oNcqANtFjbehEeoLDbF7eu+g20sRoNoyfMr2EIuDcwu4QRjltr5M5rofmw7wJ
++ySxrZ1vZm3Z1TAvgu8XXvD558l++0ZBX+a72Zl8xv9Ntj6e6SvMjZbu376Ml1wrq
++WLbviPr6ebJSWNXwrIyhUXQplapRO5AyA58ccnSQ3j3tYdLl4/1kR+W5t0qp9x+u
++loYErC/jpIF3t1oW/9gPP/a3eMykr/pbPBJbqFKJcu+I89VEgYaVI5973bzZNO98
++lDyqwEHC451QGsDkGSL8swIDAQABo4IBBTCCAQEwDwYDVR0TAQH/BAUwAwEB/zAd
++BgNVHQ4EFgQUP5DIfccVb/Mkj6nDL0uiDyGyL+cwDgYDVR0PAQH/BAQDAgEGMIG+
++BgNVHR8EgbYwgbMwdKByoHCGbmxkYXA6Ly9kaXJlY3RvcnkuZC10cnVzdC5uZXQv
++Q049RC1UUlVTVCUyMFJvb3QlMjBDQSUyMDMlMjAyMDEzLE89RC1UcnVzdCUyMEdt
++YkgsQz1ERT9jZXJ0aWZpY2F0ZXJldm9jYXRpb25saXN0MDugOaA3hjVodHRwOi8v
++Y3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X3Jvb3RfY2FfM18yMDEzLmNybDAN
++BgkqhkiG9w0BAQsFAAOCAQEADlkOWOR0SCNEzzQhtZwUGq2aS7eziG1cqRdw8Cqf
++jXv5e4X6xznoEAiwNStfzwLS05zICx7uBVSuN5MECX1sj8J0vPgclL4xAUAt8yQg
++t4RVLFzI9XRKEBmLo8ftNdYJSNMOwLo5qLBGArDbxohZwr78e7Erz35ih1WWzAFv
++m2chlTWL+BD8cRu3SzdppjvW7IvuwbDzJcmPkn2h6sPKRL8mpXSSnON065102ctN
++h9j8tGlsi6BDB2B4l+nZk3zCRrybN1Kj7Yo8E6l7U0tJmhEFLAtuVqwfLoJs4Gln
++tQ5tLdnkwBXxP/oYcuEVbSdbLTAoK59ImmQrme/ydUlfXA==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/EC-ACC.pem
+@@ -0,0 +1,109 @@
++##
++## EC-ACC
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ (Negative)11:d4:c2:14:2b:de:21:eb:57:9d:53:fb:0c:22:3b:ff
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
++ Validity
++ Not Before: Jan 7 23:00:00 2003 GMT
++ Not After : Jan 7 22:59:59 2031 GMT
++ Subject: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:b3:22:c7:4f:e2:97:42:95:88:47:83:40:f6:1d:
++ 17:f3:83:73:24:1e:51:f3:98:8a:c3:92:b8:ff:40:
++ 90:05:70:87:60:c9:00:a9:b5:94:65:19:22:15:17:
++ c2:43:6c:66:44:9a:0d:04:3e:39:6f:a5:4b:7a:aa:
++ 63:b7:8a:44:9d:d9:63:91:84:66:e0:28:0f:ba:42:
++ e3:6e:8e:f7:14:27:93:69:ee:91:0e:a3:5f:0e:b1:
++ eb:66:a2:72:4f:12:13:86:65:7a:3e:db:4f:07:f4:
++ a7:09:60:da:3a:42:99:c7:b2:7f:b3:16:95:1c:c7:
++ f9:34:b5:94:85:d5:99:5e:a0:48:a0:7e:e7:17:65:
++ b8:a2:75:b8:1e:f3:e5:42:7d:af:ed:f3:8a:48:64:
++ 5d:82:14:93:d8:c0:e4:ff:b3:50:72:f2:76:f6:b3:
++ 5d:42:50:79:d0:94:3e:6b:0c:00:be:d8:6b:0e:4e:
++ 2a:ec:3e:d2:cc:82:a2:18:65:33:13:77:9e:9a:5d:
++ 1a:13:d8:c3:db:3d:c8:97:7a:ee:70:ed:a7:e6:7c:
++ db:71:cf:2d:94:62:df:6d:d6:f5:38:be:3f:a5:85:
++ 0a:19:b8:a8:d8:09:75:42:70:c4:ea:ef:cb:0e:c8:
++ 34:a8:12:22:98:0c:b8:13:94:b6:4b:ec:f0:d0:90:
++ e7:27
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Subject Alternative Name:
++ email:ec_acc@catcert.net
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ A0:C3:8B:44:AA:37:A5:45:BF:97:80:5A:D1:F1:78:A2:9B:E9:5D:8D
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.15096.1.3.1.10
++ CPS: https://www.catcert.net/verarrel
++ User Notice:
++ Explicit Text: Vegeu https://www.catcert.net/verarrel
++
++ Signature Algorithm: sha1WithRSAEncryption
++ a0:48:5b:82:01:f6:4d:48:b8:39:55:35:9c:80:7a:53:99:d5:
++ 5a:ff:b1:71:3b:cc:39:09:94:5e:d6:da:ef:be:01:5b:5d:d3:
++ 1e:d8:fd:7d:4f:cd:a0:41:e0:34:93:bf:cb:e2:86:9c:37:92:
++ 90:56:1c:dc:eb:29:05:e5:c4:9e:c7:35:df:8a:0c:cd:c5:21:
++ 43:e9:aa:88:e5:35:c0:19:42:63:5a:02:5e:a4:48:18:3a:85:
++ 6f:dc:9d:bc:3f:9d:9c:c1:87:b8:7a:61:08:e9:77:0b:7f:70:
++ ab:7a:dd:d9:97:2c:64:1e:85:bf:bc:74:96:a1:c3:7a:12:ec:
++ 0c:1a:6e:83:0c:3c:e8:72:46:9f:fb:48:d5:5e:97:e6:b1:a1:
++ f8:e4:ef:46:25:94:9c:89:db:69:38:be:ec:5c:0e:56:c7:65:
++ 51:e5:50:88:88:bf:42:d5:2b:3d:e5:f9:ba:9e:2e:b3:ca:f4:
++ 73:92:02:0b:be:4c:66:eb:20:fe:b9:cb:b5:99:7f:e6:b6:13:
++ fa:ca:4b:4d:d9:ee:53:46:06:3b:c6:4e:ad:93:5a:81:7e:6c:
++ 2a:4b:6a:05:45:8c:f2:21:a4:31:90:87:6c:65:9c:9d:a5:60:
++ 95:3a:52:7f:f5:d1:ab:08:6e:f3:ee:5b:f9:88:3d:7e:b8:6f:
++ 6e:03:e4:42
++SHA1 Fingerprint=28:90:3A:63:5B:52:80:FA:E6:77:4C:0B:6D:A7:D6:BA:A6:4A:F2:E8
++-----BEGIN CERTIFICATE-----
++MIIFVjCCBD6gAwIBAgIQ7is969Qh3hSoYqwE893EATANBgkqhkiG9w0BAQUFADCB
++8zELMAkGA1UEBhMCRVMxOzA5BgNVBAoTMkFnZW5jaWEgQ2F0YWxhbmEgZGUgQ2Vy
++dGlmaWNhY2lvIChOSUYgUS0wODAxMTc2LUkpMSgwJgYDVQQLEx9TZXJ2ZWlzIFB1
++YmxpY3MgZGUgQ2VydGlmaWNhY2lvMTUwMwYDVQQLEyxWZWdldSBodHRwczovL3d3
++dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAoYykwMzE1MDMGA1UECxMsSmVyYXJxdWlh
++IEVudGl0YXRzIGRlIENlcnRpZmljYWNpbyBDYXRhbGFuZXMxDzANBgNVBAMTBkVD
++LUFDQzAeFw0wMzAxMDcyMzAwMDBaFw0zMTAxMDcyMjU5NTlaMIHzMQswCQYDVQQG
++EwJFUzE7MDkGA1UEChMyQWdlbmNpYSBDYXRhbGFuYSBkZSBDZXJ0aWZpY2FjaW8g
++KE5JRiBRLTA4MDExNzYtSSkxKDAmBgNVBAsTH1NlcnZlaXMgUHVibGljcyBkZSBD
++ZXJ0aWZpY2FjaW8xNTAzBgNVBAsTLFZlZ2V1IGh0dHBzOi8vd3d3LmNhdGNlcnQu
++bmV0L3ZlcmFycmVsIChjKTAzMTUwMwYDVQQLEyxKZXJhcnF1aWEgRW50aXRhdHMg
++ZGUgQ2VydGlmaWNhY2lvIENhdGFsYW5lczEPMA0GA1UEAxMGRUMtQUNDMIIBIjAN
++BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsyLHT+KXQpWIR4NA9h0X84NzJB5R
++85iKw5K4/0CQBXCHYMkAqbWUZRkiFRfCQ2xmRJoNBD45b6VLeqpjt4pEndljkYRm
++4CgPukLjbo73FCeTae6RDqNfDrHrZqJyTxIThmV6PttPB/SnCWDaOkKZx7J/sxaV
++HMf5NLWUhdWZXqBIoH7nF2W4onW4HvPlQn2v7fOKSGRdghST2MDk/7NQcvJ29rNd
++QlB50JQ+awwAvthrDk4q7D7SzIKiGGUzE3eeml0aE9jD2z3Il3rucO2n5nzbcc8t
++lGLfbdb1OL4/pYUKGbio2Al1QnDE6u/LDsg0qBIimAy4E5S2S+zw0JDnJwIDAQAB
++o4HjMIHgMB0GA1UdEQQWMBSBEmVjX2FjY0BjYXRjZXJ0Lm5ldDAPBgNVHRMBAf8E
++BTADAQH/MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUoMOLRKo3pUW/l4Ba0fF4
++opvpXY0wfwYDVR0gBHgwdjB0BgsrBgEEAfV4AQMBCjBlMCwGCCsGAQUFBwIBFiBo
++dHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbDA1BggrBgEFBQcCAjApGidW
++ZWdldSBodHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAwDQYJKoZIhvcN
++AQEFBQADggEBAKBIW4IB9k1IuDlVNZyAelOZ1Vr/sXE7zDkJlF7W2u++AVtd0x7Y
++/X1PzaBB4DSTv8vihpw3kpBWHNzrKQXlxJ7HNd+KDM3FIUPpqojlNcAZQmNaAl6k
++SBg6hW/cnbw/nZzBh7h6YQjpdwt/cKt63dmXLGQehb+8dJahw3oS7AwaboMMPOhy
++Rp/7SNVel+axofjk70YllJyJ22k4vuxcDlbHZVHlUIiIv0LVKz3l+bqeLrPK9HOS
++Agu+TGbrIP65y7WZf+a2E/rKS03Z7lNGBjvGTq2TWoF+bCpLagVFjPIhpDGQh2xl
++nJ2lYJU6Un/10asIbvPuW/mIPX64b24D5EI=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G2.pem
+@@ -0,0 +1,68 @@
++##
++## GeoTrust Primary Certification Authority - G2
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 3c:b2:f4:48:0a:00:e2:fe:eb:24:3b:5e:60:3e:c3:6b
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
++ Validity
++ Not Before: Nov 5 00:00:00 2007 GMT
++ Not After : Jan 18 23:59:59 2038 GMT
++ Subject: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:15:b1:e8:fd:03:15:43:e5:ac:eb:87:37:11:62:
++ ef:d2:83:36:52:7d:45:57:0b:4a:8d:7b:54:3b:3a:
++ 6e:5f:15:02:c0:50:a6:cf:25:2f:7d:ca:48:b8:c7:
++ 50:63:1c:2a:21:08:7c:9a:36:d8:0b:fe:d1:26:c5:
++ 58:31:30:28:25:f3:5d:5d:a3:b8:b6:a5:b4:92:ed:
++ 6c:2c:9f:eb:dd:43:89:a2:3c:4b:48:91:1d:50:ec:
++ 26:df:d6:60:2e:bd:21
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ 15:5F:35:57:51:55:FB:25:B2:AD:03:69:FC:01:A3:FA:BE:11:55:D5
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:64:02:30:64:96:59:a6:e8:09:de:8b:ba:fa:5a:88:88:f0:
++ 1f:91:d3:46:a8:f2:4a:4c:02:63:fb:6c:5f:38:db:2e:41:93:
++ a9:0e:e6:9d:dc:31:1c:b2:a0:a7:18:1c:79:e1:c7:36:02:30:
++ 3a:56:af:9a:74:6c:f6:fb:83:e0:33:d3:08:5f:a1:9c:c2:5b:
++ 9f:46:d6:b6:cb:91:06:63:a2:06:e7:33:ac:3e:a8:81:12:d0:
++ cb:ba:d0:92:0b:b6:9e:96:aa:04:0f:8a
++SHA1 Fingerprint=8D:17:84:D5:37:F3:03:7D:EC:70:FE:57:8B:51:9A:99:E6:10:D7:B0
++-----BEGIN CERTIFICATE-----
++MIICrjCCAjWgAwIBAgIQPLL0SAoA4v7rJDteYD7DazAKBggqhkjOPQQDAzCBmDEL
++MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUdlb1RydXN0IEluYy4xOTA3BgNVBAsTMChj
++KSAyMDA3IEdlb1RydXN0IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTE2
++MDQGA1UEAxMtR2VvVHJ1c3QgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
++eSAtIEcyMB4XDTA3MTEwNTAwMDAwMFoXDTM4MDExODIzNTk1OVowgZgxCzAJBgNV
++BAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMTkwNwYDVQQLEzAoYykgMjAw
++NyBHZW9UcnVzdCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxNjA0BgNV
++BAMTLUdlb1RydXN0IFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBH
++MjB2MBAGByqGSM49AgEGBSuBBAAiA2IABBWx6P0DFUPlrOuHNxFi79KDNlJ9RVcL
++So17VDs6bl8VAsBQps8lL33KSLjHUGMcKiEIfJo22Av+0SbFWDEwKCXzXV2juLal
++tJLtbCyf691DiaI8S0iRHVDsJt/WYC69IaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAO
++BgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFBVfNVdRVfslsq0DafwBo/q+EVXVMAoG
++CCqGSM49BAMDA2cAMGQCMGSWWaboCd6LuvpaiIjwH5HTRqjySkwCY/tsXzjbLkGT
++qQ7mndwxHLKgpxgceeHHNgIwOlavmnRs9vuD4DPTCF+hnMJbn0bWtsuRBmOiBucz
++rD6ogRLQy7rQkgu2npaqBA+K
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Global_Chambersign_Root_-_2008.pem
+@@ -0,0 +1,151 @@
++##
++## Global Chambersign Root - 2008
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ c9:cd:d3:e9:d5:7d:23:ce
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
++ Validity
++ Not Before: Aug 1 12:31:40 2008 GMT
++ Not After : Jul 31 12:31:40 2038 GMT
++ Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:c0:df:56:d3:e4:3a:9b:76:45:b4:13:db:ff:c1:
++ b6:19:8b:37:41:18:95:52:47:eb:17:9d:29:88:8e:
++ 35:6c:06:32:2e:47:62:f3:49:04:bf:7d:44:36:b1:
++ 71:cc:bd:5a:09:73:d5:d9:85:44:ff:91:57:25:df:
++ 5e:36:8e:70:d1:5c:71:43:1d:d9:da:ef:5c:d2:fb:
++ 1b:bd:3a:b5:cb:ad:a3:cc:44:a7:0d:ae:21:15:3f:
++ b9:7a:5b:92:75:d8:a4:12:38:89:19:8a:b7:80:d2:
++ e2:32:6f:56:9c:91:d6:88:10:0b:b3:74:64:92:74:
++ 60:f3:f6:cf:18:4f:60:b2:23:d0:c7:3b:ce:61:4b:
++ 99:8f:c2:0c:d0:40:b2:98:dc:0d:a8:4e:a3:b9:0a:
++ ae:60:a0:ad:45:52:63:ba:66:bd:68:e0:f9:be:1a:
++ a8:81:bb:1e:41:78:75:d3:c1:fe:00:55:b0:87:54:
++ e8:27:90:35:1d:4c:33:ad:97:fc:97:2e:98:84:bf:
++ 2c:c9:a3:bf:d1:98:11:14:ed:63:f8:ca:98:88:58:
++ 17:99:ed:45:03:97:7e:3c:86:1e:88:8c:be:f2:91:
++ 84:8f:65:34:d8:00:4c:7d:b7:31:17:5a:29:7a:0a:
++ 18:24:30:a3:37:b5:7a:a9:01:7d:26:d6:f9:0e:8e:
++ 59:f1:fd:1b:33:b5:29:3b:17:3b:41:b6:21:dd:d4:
++ c0:3d:a5:9f:9f:1f:43:50:c9:bb:bc:6c:7a:97:98:
++ ee:cd:8c:1f:fb:9c:51:ae:8b:70:bd:27:9f:71:c0:
++ 6b:ac:7d:90:66:e8:d7:5d:3a:0d:b0:d5:c2:8d:d5:
++ c8:9d:9d:c1:6d:d0:d0:bf:51:e4:e3:f8:c3:38:36:
++ ae:d6:a7:75:e6:af:84:43:5d:93:92:0c:6a:07:de:
++ 3b:1d:98:22:d6:ac:c1:35:db:a3:a0:25:ff:72:b5:
++ 76:1d:de:6d:e9:2c:66:2c:52:84:d0:45:92:ce:1c:
++ e5:e5:33:1d:dc:07:53:54:a3:aa:82:3b:9a:37:2f:
++ dc:dd:a0:64:e9:e6:dd:bd:ae:fc:64:85:1d:3c:a7:
++ c9:06:de:84:ff:6b:e8:6b:1a:3c:c5:a2:b3:42:fb:
++ 8b:09:3e:5f:08:52:c7:62:c4:d4:05:71:bf:c4:64:
++ e4:f8:a1:83:e8:3e:12:9b:a8:1e:d4:36:4d:2f:71:
++ f6:8d:28:f6:83:a9:13:d2:61:c1:91:bb:48:c0:34:
++ 8f:41:8c:4b:4c:db:69:12:ff:50:94:9c:20:83:59:
++ 73:ed:7c:a1:f2:f1:fd:dd:f7:49:d3:43:58:a0:56:
++ 63:ca:3d:3d:e5:35:56:59:e9:0e:ca:20:cc:2b:4b:
++ 93:29:0f
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 Subject Key Identifier:
++ B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
++ X509v3 Authority Key Identifier:
++ keyid:B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
++ DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Global Chambersign Root - 2008
++ serial:C9:CD:D3:E9:D5:7D:23:CE
++
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Certificate Policies:
++ Policy: X509v3 Any Policy
++ CPS: http://policy.camerfirma.com
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 80:88:7f:70:de:92:28:d9:05:94:46:ff:90:57:a9:f1:2f:df:
++ 1a:0d:6b:fa:7c:0e:1c:49:24:79:27:d8:46:aa:6f:29:59:52:
++ 88:70:12:ea:dd:3d:f5:9b:53:54:6f:e1:60:a2:a8:09:b9:ec:
++ eb:59:7c:c6:35:f1:dc:18:e9:f1:67:e5:af:ba:45:e0:09:de:
++ ca:44:0f:c2:17:0e:77:91:45:7a:33:5f:5f:96:2c:68:8b:c1:
++ 47:8f:98:9b:3d:c0:ec:cb:f5:d5:82:92:84:35:d1:be:36:38:
++ 56:72:31:5b:47:2d:aa:17:a4:63:51:eb:0a:01:ad:7f:ec:75:
++ 9e:cb:a1:1f:f1:7f:12:b1:b9:e4:64:7f:67:d6:23:2a:f4:b8:
++ 39:5d:98:e8:21:a7:e1:bd:3d:42:1a:74:9a:70:af:68:6c:50:
++ 5d:49:cf:ff:fb:0e:5d:e6:2c:47:d7:81:3a:59:00:b5:73:6b:
++ 63:20:f6:31:45:08:39:0e:f4:70:7e:40:70:5a:3f:d0:6b:42:
++ a9:74:3d:28:2f:02:6d:75:72:95:09:8d:48:63:c6:c6:23:57:
++ 92:93:5e:35:c1:8d:f9:0a:f7:2c:9d:62:1c:f6:ad:7c:dd:a6:
++ 31:1e:b6:b1:c7:7e:85:26:fa:a4:6a:b5:da:63:30:d1:ef:93:
++ 37:b2:66:2f:7d:05:f7:e7:b7:4b:98:94:35:c0:d9:3a:29:c1:
++ 9d:b2:50:33:1d:4a:a9:5a:a6:c9:03:ef:ed:f4:e7:a8:6e:8a:
++ b4:57:84:eb:a4:3f:d0:ee:aa:aa:87:5b:63:e8:93:e2:6b:a8:
++ d4:b8:72:78:6b:1b:ed:39:e4:5d:cb:9b:aa:87:d5:4f:4e:00:
++ fe:d9:6a:9f:3c:31:0f:28:02:01:7d:98:e8:a7:b0:a2:64:9e:
++ 79:f8:48:f2:15:a9:cc:e6:c8:44:eb:3f:78:99:f2:7b:71:3e:
++ 3c:f1:98:a7:c5:18:12:3f:e6:bb:28:33:42:e9:45:0a:7c:6d:
++ f2:86:79:2f:c5:82:19:7d:09:89:7c:b2:54:76:88:ae:de:c1:
++ f3:cc:e1:6e:db:31:d6:93:ae:99:a0:ef:25:6a:73:98:89:5b:
++ 3a:2e:13:88:1e:bf:c0:92:94:34:1b:e3:27:b7:8b:1e:6f:42:
++ ff:e7:e9:37:9b:50:1d:2d:a2:f9:02:ee:cb:58:58:3a:71:bc:
++ 68:e3:aa:c1:af:1c:28:1f:a2:dc:23:65:3f:81:ea:ae:99:d3:
++ d8:30:cf:13:0d:4f:15:c9:84:bc:a7:48:2d:f8:30:23:77:d8:
++ 46:4b:79:6d:f6:8c:ed:3a:7f:60:11:78:f4:e9:9b:ae:d5:54:
++ c0:74:80:d1:0b:42:9f:c1
++SHA1 Fingerprint=4A:BD:EE:EC:95:0D:35:9C:89:AE:C7:52:A1:2C:5B:29:F6:D6:AA:0C
++-----BEGIN CERTIFICATE-----
++MIIHSTCCBTGgAwIBAgIJAMnN0+nVfSPOMA0GCSqGSIb3DQEBBQUAMIGsMQswCQYD
++VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
++IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
++MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAlBgNVBAMTHkdsb2JhbCBD
++aGFtYmVyc2lnbiBSb290IC0gMjAwODAeFw0wODA4MDExMjMxNDBaFw0zODA3MzEx
++MjMxNDBaMIGsMQswCQYDVQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3Vy
++cmVudCBhZGRyZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAG
++A1UEBRMJQTgyNzQzMjg3MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAl
++BgNVBAMTHkdsb2JhbCBDaGFtYmVyc2lnbiBSb290IC0gMjAwODCCAiIwDQYJKoZI
++hvcNAQEBBQADggIPADCCAgoCggIBAMDfVtPkOpt2RbQT2//BthmLN0EYlVJH6xed
++KYiONWwGMi5HYvNJBL99RDaxccy9Wglz1dmFRP+RVyXfXjaOcNFccUMd2drvXNL7
++G706tcuto8xEpw2uIRU/uXpbknXYpBI4iRmKt4DS4jJvVpyR1ogQC7N0ZJJ0YPP2
++zxhPYLIj0Mc7zmFLmY/CDNBAspjcDahOo7kKrmCgrUVSY7pmvWjg+b4aqIG7HkF4
++ddPB/gBVsIdU6CeQNR1MM62X/JcumIS/LMmjv9GYERTtY/jKmIhYF5ntRQOXfjyG
++HoiMvvKRhI9lNNgATH23MRdaKXoKGCQwoze1eqkBfSbW+Q6OWfH9GzO1KTsXO0G2
++Id3UwD2ln58fQ1DJu7xsepeY7s2MH/ucUa6LcL0nn3HAa6x9kGbo1106DbDVwo3V
++yJ2dwW3Q0L9R5OP4wzg2rtandeavhENdk5IMagfeOx2YItaswTXbo6Al/3K1dh3e
++beksZixShNBFks4c5eUzHdwHU1SjqoI7mjcv3N2gZOnm3b2u/GSFHTynyQbehP9r
++6GsaPMWis0L7iwk+XwhSx2LE1AVxv8Rk5Pihg+g+EpuoHtQ2TS9x9o0o9oOpE9Jh
++wZG7SMA0j0GMS0zbaRL/UJScIINZc+18ofLx/d33SdNDWKBWY8o9PeU1VlnpDsog
++zCtLkykPAgMBAAGjggFqMIIBZjASBgNVHRMBAf8ECDAGAQH/AgEMMB0GA1UdDgQW
++BBS5CcqcHtvTbDprru1U8VuTBjUuXjCB4QYDVR0jBIHZMIHWgBS5CcqcHtvTbDpr
++ru1U8VuTBjUuXqGBsqSBrzCBrDELMAkGA1UEBhMCRVUxQzBBBgNVBAcTOk1hZHJp
++ZCAoc2VlIGN1cnJlbnQgYWRkcmVzcyBhdCB3d3cuY2FtZXJmaXJtYS5jb20vYWRk
++cmVzcykxEjAQBgNVBAUTCUE4Mjc0MzI4NzEbMBkGA1UEChMSQUMgQ2FtZXJmaXJt
++YSBTLkEuMScwJQYDVQQDEx5HbG9iYWwgQ2hhbWJlcnNpZ24gUm9vdCAtIDIwMDiC
++CQDJzdPp1X0jzjAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRVHSAAMCow
++KAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20wDQYJKoZI
++hvcNAQEFBQADggIBAICIf3DekijZBZRG/5BXqfEv3xoNa/p8DhxJJHkn2EaqbylZ
++UohwEurdPfWbU1Rv4WCiqAm57OtZfMY18dwY6fFn5a+6ReAJ3spED8IXDneRRXoz
++X1+WLGiLwUePmJs9wOzL9dWCkoQ10b42OFZyMVtHLaoXpGNR6woBrX/sdZ7LoR/x
++fxKxueRkf2fWIyr0uDldmOghp+G9PUIadJpwr2hsUF1Jz//7Dl3mLEfXgTpZALVz
++a2Mg9jFFCDkO9HB+QHBaP9BrQql0PSgvAm11cpUJjUhjxsYjV5KTXjXBjfkK9yyd
++Yhz2rXzdpjEetrHHfoUm+qRqtdpjMNHvkzeyZi99Bffnt0uYlDXA2TopwZ2yUDMd
++SqlapskD7+3056huirRXhOukP9DuqqqHW2Pok+JrqNS4cnhrG+055F3Lm6qH1U9O
++AP7Zap88MQ8oAgF9mOinsKJknnn4SPIVqczmyETrP3iZ8ntxPjzxmKfFGBI/5rso
++M0LpRQp8bfKGeS/Fghl9CYl8slR2iK7ewfPM4W7bMdaTrpmg7yVqc5iJWzouE4ge
++v8CSlDQb4ye3ix5vQv/n6TebUB0tovkC7stYWDpxvGjjqsGvHCgfotwjZT+B6q6Z
++09gwzxMNTxXJhLynSC34MCN32EZLeW32jO06f2ARePTpm67VVMB0gNELQp/B
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/OISTE_WISeKey_Global_Root_GA_CA.pem
+@@ -0,0 +1,96 @@
++##
++## OISTE WISeKey Global Root GA CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 41:3d:72:c7:f4:6b:1f:81:43:7d:f1:d2:28:54:df:9a
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
++ Validity
++ Not Before: Dec 11 16:03:44 2005 GMT
++ Not After : Dec 11 16:09:51 2037 GMT
++ Subject: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:cb:4f:b3:00:9b:3d:36:dd:f9:d1:49:6a:6b:10:
++ 49:1f:ec:d8:2b:b2:c6:f8:32:81:29:43:95:4c:9a:
++ 19:23:21:15:45:de:e3:c8:1c:51:55:5b:ae:93:e8:
++ 37:ff:2b:6b:e9:d4:ea:be:2a:dd:a8:51:2b:d7:66:
++ c3:61:5c:60:02:c8:f5:ce:72:7b:3b:b8:f2:4e:65:
++ 08:9a:cd:a4:6a:19:c1:01:bb:73:a6:d7:f6:c3:dd:
++ cd:bc:a4:8b:b5:99:61:b8:01:a2:a3:d4:4d:d4:05:
++ 3d:91:ad:f8:b4:08:71:64:af:70:f1:1c:6b:7e:f6:
++ c3:77:9d:24:73:7b:e4:0c:8c:e1:d9:36:e1:99:8b:
++ 05:99:0b:ed:45:31:09:ca:c2:00:db:f7:72:a0:96:
++ aa:95:87:d0:8e:c7:b6:61:73:0d:76:66:8c:dc:1b:
++ b4:63:a2:9f:7f:93:13:30:f1:a1:27:db:d9:ff:2c:
++ 55:88:91:a0:e0:4f:07:b0:28:56:8c:18:1b:97:44:
++ 8e:89:dd:e0:17:6e:e7:2a:ef:8f:39:0a:31:84:82:
++ d8:40:14:49:2e:7a:41:e4:a7:fe:e3:64:cc:c1:59:
++ 71:4b:2c:21:a7:5b:7d:e0:1d:d1:2e:81:9b:c3:d8:
++ 68:f7:bd:96:1b:ac:70:b1:16:14:0b:db:60:b9:26:
++ 01:05
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage:
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ B3:03:7E:AE:36:BC:B0:79:D1:DC:94:26:B6:11:BE:21:B2:69:86:94
++ 1.3.6.1.4.1.311.21.1:
++ ...
++ Signature Algorithm: sha1WithRSAEncryption
++ 4b:a1:ff:0b:87:6e:b3:f9:c1:43:b1:48:f3:28:c0:1d:2e:c9:
++ 09:41:fa:94:00:1c:a4:a4:ab:49:4f:8f:3d:1e:ef:4d:6f:bd:
++ bc:a4:f6:f2:26:30:c9:10:ca:1d:88:fb:74:19:1f:85:45:bd:
++ b0:6c:51:f9:36:7e:db:f5:4c:32:3a:41:4f:5b:47:cf:e8:0b:
++ 2d:b6:c4:19:9d:74:c5:47:c6:3b:6a:0f:ac:14:db:3c:f4:73:
++ 9c:a9:05:df:00:dc:74:78:fa:f8:35:60:59:02:13:18:7c:bc:
++ fb:4d:b0:20:6d:43:bb:60:30:7a:67:33:5c:c5:99:d1:f8:2d:
++ 39:52:73:fb:8c:aa:97:25:5c:72:d9:08:1e:ab:4e:3c:e3:81:
++ 31:9f:03:a6:fb:c0:fe:29:88:55:da:84:d5:50:03:b6:e2:84:
++ a3:a6:36:aa:11:3a:01:e1:18:4b:d6:44:68:b3:3d:f9:53:74:
++ 84:b3:46:91:46:96:00:b7:80:2c:b6:e1:e3:10:e2:db:a2:e7:
++ 28:8f:01:96:62:16:3e:00:e3:1c:a5:36:81:18:a2:4c:52:76:
++ c0:11:a3:6e:e6:1d:ba:e3:5a:be:36:53:c5:3e:75:8f:86:69:
++ 29:58:53:b5:9c:bb:6f:9f:5c:c5:18:ec:dd:2f:e1:98:c9:fc:
++ be:df:0a:0d
++SHA1 Fingerprint=59:22:A1:E1:5A:EA:16:35:21:F8:98:39:6A:46:46:B0:44:1B:0F:A9
++-----BEGIN CERTIFICATE-----
++MIID8TCCAtmgAwIBAgIQQT1yx/RrH4FDffHSKFTfmjANBgkqhkiG9w0BAQUFADCB
++ijELMAkGA1UEBhMCQ0gxEDAOBgNVBAoTB1dJU2VLZXkxGzAZBgNVBAsTEkNvcHly
++aWdodCAoYykgMjAwNTEiMCAGA1UECxMZT0lTVEUgRm91bmRhdGlvbiBFbmRvcnNl
++ZDEoMCYGA1UEAxMfT0lTVEUgV0lTZUtleSBHbG9iYWwgUm9vdCBHQSBDQTAeFw0w
++NTEyMTExNjAzNDRaFw0zNzEyMTExNjA5NTFaMIGKMQswCQYDVQQGEwJDSDEQMA4G
++A1UEChMHV0lTZUtleTEbMBkGA1UECxMSQ29weXJpZ2h0IChjKSAyMDA1MSIwIAYD
++VQQLExlPSVNURSBGb3VuZGF0aW9uIEVuZG9yc2VkMSgwJgYDVQQDEx9PSVNURSBX
++SVNlS2V5IEdsb2JhbCBSb290IEdBIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
++MIIBCgKCAQEAy0+zAJs9Nt350UlqaxBJH+zYK7LG+DKBKUOVTJoZIyEVRd7jyBxR
++VVuuk+g3/ytr6dTqvirdqFEr12bDYVxgAsj1znJ7O7jyTmUIms2kahnBAbtzptf2
++w93NvKSLtZlhuAGio9RN1AU9ka34tAhxZK9w8RxrfvbDd50kc3vkDIzh2TbhmYsF
++mQvtRTEJysIA2/dyoJaqlYfQjse2YXMNdmaM3Bu0Y6Kff5MTMPGhJ9vZ/yxViJGg
++4E8HsChWjBgbl0SOid3gF27nKu+POQoxhILYQBRJLnpB5Kf+42TMwVlxSywhp1t9
++4B3RLoGbw9ho972WG6xwsRYUC9tguSYBBQIDAQABo1EwTzALBgNVHQ8EBAMCAYYw
++DwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUswN+rja8sHnR3JQmthG+IbJphpQw
++EAYJKwYBBAGCNxUBBAMCAQAwDQYJKoZIhvcNAQEFBQADggEBAEuh/wuHbrP5wUOx
++SPMowB0uyQlB+pQAHKSkq0lPjz0e701vvbyk9vImMMkQyh2I+3QZH4VFvbBsUfk2
++ftv1TDI6QU9bR8/oCy22xBmddMVHxjtqD6wU2zz0c5ypBd8A3HR4+vg1YFkCExh8
++vPtNsCBtQ7tgMHpnM1zFmdH4LTlSc/uMqpclXHLZCB6rTjzjgTGfA6b7wP4piFXa
++hNVQA7bihKOmNqoROgHhGEvWRGizPflTdISzRpFGlgC3gCy24eMQ4tui5yiPAZZi
++Fj4A4xylNoEYokxSdsARo27mHbrjWr42U8U+dY+GaSlYU7Wcu2+fXMUY7N0v4ZjJ
++/L7fCg0=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/QuoVadis_Root_CA.pem
+@@ -0,0 +1,119 @@
++##
++## QuoVadis Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 985026699 (0x3ab6508b)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
++ Validity
++ Not Before: Mar 19 18:33:33 2001 GMT
++ Not After : Mar 17 18:33:33 2021 GMT
++ Subject: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:bf:61:b5:95:53:ba:57:fc:fa:f2:67:0b:3a:1a:
++ df:11:80:64:95:b4:d1:bc:cd:7a:cf:f6:29:96:2e:
++ 24:54:40:24:38:f7:1a:85:dc:58:4c:cb:a4:27:42:
++ 97:d0:9f:83:8a:c3:e4:06:03:5b:00:a5:51:1e:70:
++ 04:74:e2:c1:d4:3a:ab:d7:ad:3b:07:18:05:8e:fd:
++ 83:ac:ea:66:d9:18:1b:68:8a:f5:57:1a:98:ba:f5:
++ ed:76:3d:7c:d9:de:94:6a:3b:4b:17:c1:d5:8f:bd:
++ 65:38:3a:95:d0:3d:55:36:4e:df:79:57:31:2a:1e:
++ d8:59:65:49:58:20:98:7e:ab:5f:7e:9f:e9:d6:4d:
++ ec:83:74:a9:c7:6c:d8:ee:29:4a:85:2a:06:14:f9:
++ 54:e6:d3:da:65:07:8b:63:37:12:d7:d0:ec:c3:7b:
++ 20:41:44:a3:ed:cb:a0:17:e1:71:65:ce:1d:66:31:
++ f7:76:01:19:c8:7d:03:58:b6:95:49:1d:a6:12:26:
++ e8:c6:0c:76:e0:e3:66:cb:ea:5d:a6:26:ee:e5:cc:
++ 5f:bd:67:a7:01:27:0e:a2:ca:54:c5:b1:7a:95:1d:
++ 71:1e:4a:29:8a:03:dc:6a:45:c1:a4:19:5e:6f:36:
++ cd:c3:a2:b0:b7:fe:5c:38:e2:52:bc:f8:44:43:e6:
++ 90:bb
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ Authority Information Access:
++ OCSP - URI:https://ocsp.quovadisoffshore.com
++
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.8024.0.1
++ User Notice:
++ Explicit Text: Reliance on the QuoVadis Root Certificate by any party assumes acceptance of the then applicable standard terms and conditions of use, certification practices, and the QuoVadis Certificate Policy.
++ CPS: http://www.quovadis.bm
++
++ X509v3 Subject Key Identifier:
++ 8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
++ X509v3 Authority Key Identifier:
++ keyid:8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
++ DirName:/C=BM/O=QuoVadis Limited/OU=Root Certification Authority/CN=QuoVadis Root Certification Authority
++ serial:3A:B6:50:8B
++
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Signature Algorithm: sha1WithRSAEncryption
++ 8a:d4:14:b5:fe:f4:9a:92:a7:19:d4:a4:7e:72:18:8f:d9:68:
++ 7c:52:24:dd:67:6f:39:7a:c4:aa:5e:3d:e2:58:b0:4d:70:98:
++ 84:61:e8:1b:e3:69:18:0e:ce:fb:47:50:a0:4e:ff:f0:24:1f:
++ bd:b2:ce:f5:27:fc:ec:2f:53:aa:73:7b:03:3d:74:6e:e6:16:
++ 9e:eb:a5:2e:c4:bf:56:27:50:2b:62:ba:be:4b:1c:3c:55:5c:
++ 41:1d:24:be:82:20:47:5d:d5:44:7e:7a:16:68:df:7d:4d:51:
++ 70:78:57:1d:33:1e:fd:02:99:9c:0c:cd:0a:05:4f:c7:bb:8e:
++ a4:75:fa:4a:6d:b1:80:8e:09:56:b9:9c:1a:60:fe:5d:c1:d7:
++ 7a:dc:11:78:d0:d6:5d:c1:b7:d5:ad:32:99:03:3a:8a:cc:54:
++ 25:39:31:81:7b:13:22:51:ba:46:6c:a1:bb:9e:fa:04:6c:49:
++ 26:74:8f:d2:73:eb:cc:30:a2:e6:ea:59:22:87:f8:97:f5:0e:
++ fd:ea:cc:92:a4:16:c4:52:18:ea:21:ce:b1:f1:e6:84:81:e5:
++ ba:a9:86:28:f2:43:5a:5d:12:9d:ac:1e:d9:a8:e5:0a:6a:a7:
++ 7f:a0:87:29:cf:f2:89:4d:d4:ec:c5:e2:e6:7a:d0:36:23:8a:
++ 4a:74:36:f9
++SHA1 Fingerprint=DE:3F:40:BD:50:93:D3:9B:6C:60:F6:DA:BC:07:62:01:00:89:76:C9
++-----BEGIN CERTIFICATE-----
++MIIF0DCCBLigAwIBAgIEOrZQizANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJC
++TTEZMBcGA1UEChMQUXVvVmFkaXMgTGltaXRlZDElMCMGA1UECxMcUm9vdCBDZXJ0
++aWZpY2F0aW9uIEF1dGhvcml0eTEuMCwGA1UEAxMlUXVvVmFkaXMgUm9vdCBDZXJ0
++aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wMTAzMTkxODMzMzNaFw0yMTAzMTcxODMz
++MzNaMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1pdGVkMSUw
++IwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYDVQQDEyVR
++dW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG
++9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2G1lVO6V/z68mcLOhrfEYBklbTRvM16z/Yp
++li4kVEAkOPcahdxYTMukJ0KX0J+DisPkBgNbAKVRHnAEdOLB1Dqr1607BxgFjv2D
++rOpm2RgbaIr1VxqYuvXtdj182d6UajtLF8HVj71lODqV0D1VNk7feVcxKh7YWWVJ
++WCCYfqtffp/p1k3sg3Spx2zY7ilKhSoGFPlU5tPaZQeLYzcS19Dsw3sgQUSj7cug
++F+FxZc4dZjH3dgEZyH0DWLaVSR2mEiboxgx24ONmy+pdpibu5cxfvWenAScOospU
++xbF6lR1xHkopigPcakXBpBlebzbNw6Kwt/5cOOJSvPhEQ+aQuwIDAQABo4ICUjCC
++Ak4wPQYIKwYBBQUHAQEEMTAvMC0GCCsGAQUFBzABhiFodHRwczovL29jc3AucXVv
++dmFkaXNvZmZzaG9yZS5jb20wDwYDVR0TAQH/BAUwAwEB/zCCARoGA1UdIASCAREw
++ggENMIIBCQYJKwYBBAG+WAABMIH7MIHUBggrBgEFBQcCAjCBxxqBxFJlbGlhbmNl
++IG9uIHRoZSBRdW9WYWRpcyBSb290IENlcnRpZmljYXRlIGJ5IGFueSBwYXJ0eSBh
++c3N1bWVzIGFjY2VwdGFuY2Ugb2YgdGhlIHRoZW4gYXBwbGljYWJsZSBzdGFuZGFy
++ZCB0ZXJtcyBhbmQgY29uZGl0aW9ucyBvZiB1c2UsIGNlcnRpZmljYXRpb24gcHJh
++Y3RpY2VzLCBhbmQgdGhlIFF1b1ZhZGlzIENlcnRpZmljYXRlIFBvbGljeS4wIgYI
++KwYBBQUHAgEWFmh0dHA6Ly93d3cucXVvdmFkaXMuYm0wHQYDVR0OBBYEFItLbe3T
++KbkGGew5Oanwl4Rqy+/fMIGuBgNVHSMEgaYwgaOAFItLbe3TKbkGGew5Oanwl4Rq
++y+/foYGEpIGBMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1p
++dGVkMSUwIwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYD
++VQQDEyVRdW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5ggQ6tlCL
++MA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQUFAAOCAQEAitQUtf70mpKnGdSk
++fnIYj9lofFIk3WdvOXrEql494liwTXCYhGHoG+NpGA7O+0dQoE7/8CQfvbLO9Sf8
++7C9TqnN7Az10buYWnuulLsS/VidQK2K6vkscPFVcQR0kvoIgR13VRH56FmjffU1R
++cHhXHTMe/QKZnAzNCgVPx7uOpHX6Sm2xgI4JVrmcGmD+XcHXetwReNDWXcG31a0y
++mQM6isxUJTkxgXsTIlG6Rmyhu576BGxJJnSP0nPrzDCi5upZIof4l/UO/erMkqQW
++xFIY6iHOsfHmhIHluqmGKPJDWl0Snawe2ajlCmqnf6CHKc/yiU3U7MXi5nrQNiOK
++SnQ2+Q==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Sonera_Class_2_Root_CA.pem
+@@ -0,0 +1,90 @@
++##
++## Sonera Class 2 Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 29 (0x1d)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = FI, O = Sonera, CN = Sonera Class2 CA
++ Validity
++ Not Before: Apr 6 07:29:40 2001 GMT
++ Not After : Apr 6 07:29:40 2021 GMT
++ Subject: C = FI, O = Sonera, CN = Sonera Class2 CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:90:17:4a:35:9d:ca:f0:0d:96:c7:44:fa:16:37:
++ fc:48:bd:bd:7f:80:2d:35:3b:e1:6f:a8:67:a9:bf:
++ 03:1c:4d:8c:6f:32:47:d5:41:68:a4:13:04:c1:35:
++ 0c:9a:84:43:fc:5c:1d:ff:89:b3:e8:17:18:cd:91:
++ 5f:fb:89:e3:ea:bf:4e:5d:7c:1b:26:d3:75:79:ed:
++ e6:84:e3:57:e5:ad:29:c4:f4:3a:28:e7:a5:7b:84:
++ 36:69:b3:fd:5e:76:bd:a3:2d:99:d3:90:4e:23:28:
++ 7d:18:63:f1:54:3b:26:9d:76:5b:97:42:b2:ff:ae:
++ f0:4e:ec:dd:39:95:4e:83:06:7f:e7:49:40:c8:c5:
++ 01:b2:54:5a:66:1d:3d:fc:f9:e9:3c:0a:9e:81:b8:
++ 70:f0:01:8b:e4:23:54:7c:c8:ae:f8:90:1e:00:96:
++ 72:d4:54:cf:61:23:bc:ea:fb:9d:02:95:d1:b6:b9:
++ 71:3a:69:08:3f:0f:b4:e1:42:c7:88:f5:3f:98:a8:
++ a7:ba:1c:e0:71:71:ef:58:57:81:50:7a:5c:6b:74:
++ 46:0e:83:03:98:c3:8e:a8:6e:f2:76:32:6e:27:83:
++ c2:73:f3:dc:18:e8:b4:93:ea:75:44:6b:04:60:20:
++ 71:57:87:9d:f3:be:a0:90:23:3d:8a:24:e1:da:21:
++ db:c3
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 4A:A0:AA:58:84:D3:5E:3C
++ X509v3 Key Usage:
++ Certificate Sign, CRL Sign
++ Signature Algorithm: sha1WithRSAEncryption
++ 5a:ce:87:f9:16:72:15:57:4b:1d:d9:9b:e7:a2:26:30:ec:93:
++ 67:df:d6:2d:d2:34:af:f7:38:a5:ce:ab:16:b9:ab:2f:7c:35:
++ cb:ac:d0:0f:b4:4c:2b:fc:80:ef:6b:8c:91:5f:36:76:f7:db:
++ b3:1b:19:ea:f4:b2:11:fd:61:71:44:bf:28:b3:3a:1d:bf:b3:
++ 43:e8:9f:bf:dc:31:08:71:b0:9d:8d:d6:34:47:32:90:c6:65:
++ 24:f7:a0:4a:7c:04:73:8f:39:6f:17:8c:72:b5:bd:4b:c8:7a:
++ f8:7b:83:c3:28:4e:9c:09:ea:67:3f:b2:67:04:1b:c3:14:da:
++ f8:e7:49:24:91:d0:1d:6a:fa:61:39:ef:6b:e7:21:75:06:07:
++ d8:12:b4:21:20:70:42:71:81:da:3c:9a:36:be:a6:5b:0d:6a:
++ 6c:9a:1f:91:7b:f9:f9:ef:42:ba:4e:4e:9e:cc:0c:8d:94:dc:
++ d9:45:9c:5e:ec:42:50:63:ae:f4:5d:c4:b1:12:dc:ca:3b:a8:
++ 2e:9d:14:5a:05:75:b7:ec:d7:63:e2:ba:35:b6:04:08:91:e8:
++ da:9d:9c:f6:66:b5:18:ac:0a:a6:54:26:34:33:d2:1b:c1:d4:
++ 7f:1a:3a:8e:0b:aa:32:6e:db:fc:4f:25:9f:d9:32:c7:96:5a:
++ 70:ac:df:4c
++SHA1 Fingerprint=37:F7:6D:E6:07:7C:90:C5:B1:3E:93:1A:B7:41:10:B4:F2:E4:9A:27
++-----BEGIN CERTIFICATE-----
++MIIDIDCCAgigAwIBAgIBHTANBgkqhkiG9w0BAQUFADA5MQswCQYDVQQGEwJGSTEP
++MA0GA1UEChMGU29uZXJhMRkwFwYDVQQDExBTb25lcmEgQ2xhc3MyIENBMB4XDTAx
++MDQwNjA3Mjk0MFoXDTIxMDQwNjA3Mjk0MFowOTELMAkGA1UEBhMCRkkxDzANBgNV
++BAoTBlNvbmVyYTEZMBcGA1UEAxMQU29uZXJhIENsYXNzMiBDQTCCASIwDQYJKoZI
++hvcNAQEBBQADggEPADCCAQoCggEBAJAXSjWdyvANlsdE+hY3/Ei9vX+ALTU74W+o
++Z6m/AxxNjG8yR9VBaKQTBME1DJqEQ/xcHf+Js+gXGM2RX/uJ4+q/Tl18GybTdXnt
++5oTjV+WtKcT0OijnpXuENmmz/V52vaMtmdOQTiMofRhj8VQ7Jp12W5dCsv+u8E7s
++3TmVToMGf+dJQMjFAbJUWmYdPfz56TwKnoG4cPABi+QjVHzIrviQHgCWctRUz2Ej
++vOr7nQKV0ba5cTppCD8PtOFCx4j1P5iop7oc4HFx71hXgVB6XGt0Rg6DA5jDjqhu
++8nYybieDwnPz3BjotJPqdURrBGAgcVeHnfO+oJAjPYok4doh28MCAwEAAaMzMDEw
++DwYDVR0TAQH/BAUwAwEB/zARBgNVHQ4ECgQISqCqWITTXjwwCwYDVR0PBAQDAgEG
++MA0GCSqGSIb3DQEBBQUAA4IBAQBazof5FnIVV0sd2ZvnoiYw7JNn39Yt0jSv9zil
++zqsWuasvfDXLrNAPtEwr/IDva4yRXzZ299uzGxnq9LIR/WFxRL8oszodv7ND6J+/
++3DEIcbCdjdY0RzKQxmUk96BKfARzjzlvF4xytb1LyHr4e4PDKE6cCepnP7JnBBvD
++FNr450kkkdAdavphOe9r5yF1BgfYErQhIHBCcYHaPJo2vqZbDWpsmh+Re/n570K6
++Tk6ezAyNlNzZRZxe7EJQY670XcSxEtzKO6gunRRaBXW37Ndj4ro1tgQIkejanZz2
++ZrUYrAqmVCY0M9IbwdR/GjqOC6oybtv8TyWf2TLHllpwrN9M
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Staat_der_Nederlanden_Root_CA_-_G3.pem
+@@ -0,0 +1,132 @@
++##
++## Staat der Nederlanden Root CA - G3
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 10003001 (0x98a239)
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
++ Validity
++ Not Before: Nov 14 11:28:42 2013 GMT
++ Not After : Nov 13 23:00:00 2028 GMT
++ Subject: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:be:32:a2:54:0f:70:fb:2c:5c:59:eb:6c:c4:a4:
++ 51:e8:85:2a:b3:cc:4a:34:f2:b0:5f:f3:0e:c7:1c:
++ 3d:53:1e:88:08:68:d8:6f:3d:ad:c2:9e:cc:82:67:
++ 07:27:87:68:71:3a:9f:75:96:22:46:05:b0:ed:ad:
++ c7:5b:9e:2a:de:9c:fc:3a:c6:95:a7:f5:17:67:18:
++ e7:2f:49:08:0c:5c:cf:e6:cc:34:ed:78:fb:50:b1:
++ dc:6b:32:f0:a2:fe:b6:3c:e4:ec:5a:97:c7:3f:1e:
++ 70:08:30:a0:dc:c5:b3:6d:6f:d0:82:72:11:ab:d2:
++ 81:68:59:82:17:b7:78:92:60:fa:cc:de:3f:84:eb:
++ 8d:38:33:90:0a:72:23:fa:35:cc:26:71:31:d1:72:
++ 28:92:d9:5b:23:6d:66:b5:6d:07:42:eb:a6:33:ce:
++ 92:db:c0:f6:6c:63:78:cd:ca:4e:3d:b5:e5:52:9b:
++ f1:be:3b:e6:54:60:b0:66:1e:09:ab:07:fe:54:89:
++ 11:42:d1:f7:24:ba:60:78:1a:98:f7:c9:11:fd:16:
++ c1:35:1a:54:75:ef:43:d3:e5:ae:4e:ce:e7:7b:c3:
++ c6:4e:61:51:4b:ab:9a:45:4b:a1:1f:41:bd:48:53:
++ 15:71:64:0b:86:b3:e5:2e:be:ce:a4:1b:c1:29:84:
++ a2:b5:cb:08:23:76:43:22:24:1f:17:04:d4:6e:9c:
++ c6:fc:7f:2b:66:1a:ec:8a:e5:d6:cf:4d:f5:63:09:
++ b7:15:39:d6:7b:ac:eb:e3:7c:e9:4e:fc:75:42:c8:
++ ed:58:95:0c:06:42:a2:9c:f7:e4:70:b3:df:72:6f:
++ 5a:37:40:89:d8:85:a4:d7:f1:0b:de:43:19:d4:4a:
++ 58:2c:8c:8a:39:9e:bf:84:87:f1:16:3b:36:0c:e9:
++ d3:b4:ca:6c:19:41:52:09:a1:1d:b0:6a:bf:82:ef:
++ 70:51:21:32:dc:05:76:8c:cb:f7:64:e4:03:50:af:
++ 8c:91:67:ab:c5:f2:ee:58:d8:de:be:f7:e7:31:cf:
++ 6c:c9:3b:71:c1:d5:88:b5:65:bc:c0:e8:17:17:07:
++ 12:b5:5c:d2:ab:20:93:b4:e6:82:83:70:36:c5:cd:
++ a3:8d:ad:8b:ec:a3:c1:43:87:e6:43:e2:34:be:95:
++ 8b:35:ed:07:39:da:a8:1d:7a:9f:36:9e:12:b0:0c:
++ 65:12:90:15:60:d9:26:40:44:e3:56:60:a5:10:d4:
++ 6a:3c:fd:41:dc:0e:5a:47:b6:ef:97:61:75:4f:d9:
++ fe:c7:b2:1d:d4:ed:5d:49:b3:a9:6a:cb:66:84:13:
++ d5:5c:a0:dc:df:6e:77:06:d1:71:75:c8:57:6f:af:
++ 0f:77:5b
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ 54:AD:FA:C7:92:57:AE:CA:35:9C:2E:12:FB:E4:BA:5D:20:DC:94:57
++ Signature Algorithm: sha256WithRSAEncryption
++ 30:99:9d:05:32:c8:5e:0e:3b:98:01:3a:8a:a4:e7:07:f7:7a:
++ f8:e7:9a:df:50:43:53:97:2a:3d:ca:3c:47:98:2e:e1:15:7b:
++ f1:92:f3:61:da:90:25:16:65:c0:9f:54:5d:0e:03:3b:5b:77:
++ 02:9c:84:b6:0d:98:5f:34:dd:3b:63:c2:c3:28:81:c2:9c:29:
++ 2e:29:e2:c8:c3:01:f2:33:ea:2a:aa:cc:09:08:f7:65:67:c6:
++ cd:df:d3:b6:2b:a7:bd:cc:d1:0e:70:5f:b8:23:d1:cb:91:4e:
++ 0a:f4:c8:7a:e5:d9:63:36:c1:d4:df:fc:22:97:f7:60:5d:ea:
++ 29:2f:58:b2:bd:58:bd:8d:96:4f:10:75:bf:48:7b:3d:51:87:
++ a1:3c:74:22:c2:fc:07:7f:80:dc:c4:ac:fe:6a:c1:70:30:b0:
++ e9:8e:69:e2:2c:69:81:94:09:ba:dd:fe:4d:c0:83:8c:94:58:
++ c0:46:20:af:9c:1f:02:f8:35:55:49:2f:46:d4:c0:f0:a0:96:
++ 02:0f:33:c5:71:f3:9e:23:7d:94:b7:fd:3a:d3:09:83:06:21:
++ fd:60:3d:ae:32:c0:d2:ee:8d:a6:f0:e7:b4:82:7c:0a:cc:70:
++ c9:79:80:f8:fe:4c:f7:35:84:19:8a:31:fb:0a:d9:d7:7f:9b:
++ f0:a2:9a:6b:c3:05:4a:ed:41:60:14:30:d1:aa:11:42:6e:d3:
++ 23:02:04:0b:c6:65:dd:dd:52:77:da:81:6b:b2:a8:fa:01:38:
++ b9:96:ea:2a:6c:67:97:89:94:9e:bc:e1:54:d5:e4:6a:78:ef:
++ 4a:bd:2b:9a:3d:40:7e:c6:c0:75:d2:6e:fb:68:30:ec:ec:8b:
++ 9d:f9:49:35:9a:1a:2c:d9:b3:95:39:d5:1e:92:f7:a6:b9:65:
++ 2f:e5:3d:6d:3a:48:4c:08:dc:e4:28:12:28:be:7d:35:5c:ea:
++ e0:16:7e:13:1b:6a:d7:3e:d7:9e:fc:2d:75:b2:c1:14:d5:23:
++ 03:db:5b:6f:0b:3e:78:2f:0d:de:33:8d:16:b7:48:e7:83:9a:
++ 81:0f:7b:c1:43:4d:55:04:17:38:4a:51:d5:59:a2:89:74:d3:
++ 9f:be:1e:4b:d7:c6:6d:b7:88:24:6f:60:91:a4:82:85:5b:56:
++ 41:bc:d0:44:ab:6a:13:be:d1:2c:58:b7:12:33:58:b2:37:63:
++ dc:13:f5:94:1d:3f:40:51:f5:4f:f5:3a:ed:c8:c5:eb:c2:1e:
++ 1d:16:95:7a:c7:7e:42:71:93:6e:4b:15:b7:30:df:aa:ed:57:
++ 85:48:ac:1d:6a:dd:39:69:e4:e1:79:78:be:ce:05:bf:a1:0c:
++ f7:80:7b:21:67:27:30:59
++SHA1 Fingerprint=D8:EB:6B:41:51:92:59:E0:F3:E7:85:00:C0:3D:B6:88:97:C9:EE:FC
++-----BEGIN CERTIFICATE-----
++MIIFdDCCA1ygAwIBAgIEAJiiOTANBgkqhkiG9w0BAQsFADBaMQswCQYDVQQGEwJO
++TDEeMBwGA1UECgwVU3RhYXQgZGVyIE5lZGVybGFuZGVuMSswKQYDVQQDDCJTdGFh
++dCBkZXIgTmVkZXJsYW5kZW4gUm9vdCBDQSAtIEczMB4XDTEzMTExNDExMjg0MloX
++DTI4MTExMzIzMDAwMFowWjELMAkGA1UEBhMCTkwxHjAcBgNVBAoMFVN0YWF0IGRl
++ciBOZWRlcmxhbmRlbjErMCkGA1UEAwwiU3RhYXQgZGVyIE5lZGVybGFuZGVuIFJv
++b3QgQ0EgLSBHMzCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAL4yolQP
++cPssXFnrbMSkUeiFKrPMSjTysF/zDsccPVMeiAho2G89rcKezIJnByeHaHE6n3WW
++IkYFsO2tx1ueKt6c/DrGlaf1F2cY5y9JCAxcz+bMNO14+1Cx3Gsy8KL+tjzk7FqX
++xz8ecAgwoNzFs21v0IJyEavSgWhZghe3eJJg+szeP4TrjTgzkApyI/o1zCZxMdFy
++KJLZWyNtZrVtB0LrpjPOktvA9mxjeM3KTj215VKb8b475lRgsGYeCasH/lSJEULR
++9yS6YHgamPfJEf0WwTUaVHXvQ9Plrk7O53vDxk5hUUurmkVLoR9BvUhTFXFkC4az
++5S6+zqQbwSmEorXLCCN2QyIkHxcE1G6cxvx/K2Ya7Irl1s9N9WMJtxU51nus6+N8
++6U78dULI7ViVDAZCopz35HCz33JvWjdAidiFpNfxC95DGdRKWCyMijmev4SH8RY7
++Ngzp07TKbBlBUgmhHbBqv4LvcFEhMtwFdozL92TkA1CvjJFnq8Xy7ljY3r735zHP
++bMk7ccHViLVlvMDoFxcHErVc0qsgk7TmgoNwNsXNo42ti+yjwUOH5kPiNL6VizXt
++BznaqB16nzaeErAMZRKQFWDZJkBE41ZgpRDUajz9QdwOWke275dhdU/Z/seyHdTt
++XUmzqWrLZoQT1Vyg3N9udwbRcXXIV2+vD3dbAgMBAAGjQjBAMA8GA1UdEwEB/wQF
++MAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBRUrfrHkleuyjWcLhL75Lpd
++INyUVzANBgkqhkiG9w0BAQsFAAOCAgEAMJmdBTLIXg47mAE6iqTnB/d6+Oea31BD
++U5cqPco8R5gu4RV78ZLzYdqQJRZlwJ9UXQ4DO1t3ApyEtg2YXzTdO2PCwyiBwpwp
++LiniyMMB8jPqKqrMCQj3ZWfGzd/TtiunvczRDnBfuCPRy5FOCvTIeuXZYzbB1N/8
++Ipf3YF3qKS9Ysr1YvY2WTxB1v0h7PVGHoTx0IsL8B3+A3MSs/mrBcDCw6Y5p4ixp
++gZQJut3+TcCDjJRYwEYgr5wfAvg1VUkvRtTA8KCWAg8zxXHzniN9lLf9OtMJgwYh
++/WA9rjLA0u6NpvDntIJ8CsxwyXmA+P5M9zWEGYox+wrZ13+b8KKaa8MFSu1BYBQw
++0aoRQm7TIwIEC8Zl3d1Sd9qBa7Ko+gE4uZbqKmxnl4mUnrzhVNXkanjvSr0rmj1A
++fsbAddJu+2gw7OyLnflJNZoaLNmzlTnVHpL3prllL+U9bTpITAjc5CgSKL59NVzq
++4BZ+Extq1z7XnvwtdbLBFNUjA9tbbws+eC8N3jONFrdI54OagQ97wUNNVQQXOEpR
++1VmiiXTTn74eS9fGbbeIJG9gkaSChVtWQbzQRKtqE77RLFi3EjNYsjdj3BP1lB0/
++QFH1T/U67cjF68IeHRaVesd+QnGTbksVtzDfqu1XhUisHWrdOWnk4Xl4vs4Fv6EM
++94B7IWcnMFk=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/SwissSign_Platinum_CA_-_G2.pem
+@@ -0,0 +1,140 @@
++##
++## SwissSign Platinum CA - G2
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 5670595323396054351 (0x4eb200670c035d4f)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
++ Validity
++ Not Before: Oct 25 08:36:00 2006 GMT
++ Not After : Oct 25 08:36:00 2036 GMT
++ Subject: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:ca:df:a2:02:e2:da:f8:fc:07:16:b1:de:60:aa:
++ de:96:5c:64:1f:c7:2f:7e:cf:67:fa:44:42:d6:76:
++ 63:95:ae:eb:af:72:20:8a:45:47:86:62:78:86:d6:
++ 20:39:26:f4:ae:a3:fd:23:e7:a5:9c:b5:22:21:19:
++ b7:37:93:22:c0:50:9c:82:7b:d4:d5:04:44:5c:cb:
++ b4:c2:9f:92:be:24:d8:7b:67:22:e2:69:5f:e5:05:
++ 78:d4:87:d9:71:70:33:25:53:b4:87:3b:29:90:28:
++ 36:9a:55:44:30:68:a4:83:97:7f:0d:1e:9c:76:ff:
++ 15:9d:60:97:00:8d:8a:85:03:ec:80:be:ea:2c:6e:
++ 10:51:92:cc:7e:d5:a3:33:d8:d6:49:de:58:2a:af:
++ f6:16:eb:4b:7b:90:32:97:b9:ba:9d:58:f1:f8:57:
++ 49:04:1e:a2:5d:06:70:dd:71:db:f9:dd:8b:9a:1b:
++ 8c:cf:3d:a3:4d:ce:cb:7c:f6:bb:9c:a0:fa:09:ce:
++ 23:62:b2:e9:0d:1f:e2:72:28:8f:9f:ac:68:20:7d:
++ 6f:3b:a8:85:31:09:7f:0b:c7:e8:65:e9:e3:78:0e:
++ 09:67:30:8b:34:82:fb:5d:e0:cc:9d:81:6d:62:ee:
++ 08:1e:04:2c:4e:9b:ec:fe:a9:4f:5f:fd:69:78:ef:
++ 09:1f:a1:b4:bf:fa:f3:ef:90:1e:4c:05:8b:1e:ea:
++ 7a:91:7a:c3:d7:e5:fb:30:bc:6c:1b:10:58:98:f7:
++ 1a:5f:d0:29:32:03:13:46:4d:61:6a:85:4c:52:74:
++ 2f:06:1f:7b:11:e2:84:97:c6:99:f3:6d:7f:d7:67:
++ 83:7e:13:68:d8:71:28:5a:d8:ce:dd:e8:10:14:9a:
++ fe:6d:23:87:6e:8e:5a:70:3c:d5:8d:09:00:a7:aa:
++ bc:b0:31:37:6d:c8:84:14:1e:5b:bd:45:63:20:6b:
++ 4b:74:8c:bd:db:3a:0e:c1:cf:5a:16:8f:a5:98:f2:
++ 76:89:b2:13:12:3b:0b:77:77:ac:bb:e5:3c:29:4a:
++ 92:72:ca:61:1a:2b:5e:4c:e2:83:74:77:fa:35:48:
++ 7a:85:4d:8d:9a:53:c4:df:78:ca:97:91:48:2b:45:
++ 2b:01:f7:1c:1a:a2:ed:18:ba:0a:bd:83:fa:6f:bc:
++ 8d:57:93:3b:d4:d4:a6:ce:1e:f1:a0:b1:ce:ab:fd:
++ 2b:28:9a:4f:1b:d7:c3:72:db:a4:c4:bf:5d:4c:f5:
++ dd:7b:96:69:ee:68:80:e6:e7:98:ba:36:b7:fe:6e:
++ ed:2b:bd:20:f8:65:19:da:55:09:7e:25:dc:fe:61:
++ 62:72:f9:7e:18:02:ef:63:b4:d0:fb:af:e5:3b:63:
++ 8c:67:8f
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
++ X509v3 Authority Key Identifier:
++ keyid:50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
++
++ X509v3 Certificate Policies:
++ Policy: 2.16.756.1.89.1.1.1.1
++ CPS: http://repository.swisssign.com/
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 08:85:a6:f5:16:0c:fc:44:1a:c1:63:e0:f9:55:46:08:fc:70:
++ 1c:42:28:96:8e:b7:c5:c1:41:75:4e:09:71:79:e5:6d:96:ca:
++ 4b:a5:88:60:d0:30:74:b8:ca:08:dc:b4:30:9e:40:07:16:6b:
++ 65:95:77:01:ae:a4:b7:35:0b:81:da:71:15:a9:74:17:38:7b:
++ 58:ca:f9:2f:fb:c0:65:76:8d:5b:01:b9:7d:de:82:3d:64:b8:
++ be:14:74:a3:0a:54:d3:2c:95:18:17:35:f5:51:6b:3f:8f:a2:
++ 96:61:39:78:6b:4b:e5:a6:a0:f8:53:df:51:10:93:62:e7:80:
++ 2f:e2:d1:e0:bc:8e:36:46:77:33:ec:b8:fb:8e:9a:2c:89:4d:
++ 31:11:0f:26:9e:04:bb:b7:04:8d:0b:f2:b9:fc:5a:9d:3b:16:
++ b7:2f:c8:98:ab:fe:8a:50:59:2e:a3:3b:fc:29:5d:8b:c1:4b:
++ c9:e2:8a:13:1d:b1:bf:bb:42:1d:52:dd:4e:d8:14:5e:10:c6:
++ 31:07:ef:71:27:f7:1b:39:09:dc:82:ea:8b:b3:95:86:5e:fd:
++ f5:da:5d:31:a6:e0:31:b6:94:e6:44:49:74:c5:16:e5:f7:1f:
++ 03:61:28:c5:c8:cb:12:a0:42:4b:f9:6b:88:08:8d:b4:32:18:
++ f3:75:9f:c4:7f:00:4f:05:95:9c:a3:17:02:c3:b3:53:9b:aa:
++ 20:39:29:2b:66:fa:9d:af:5e:b3:92:d2:b5:a6:e1:1a:f9:2d:
++ 41:69:81:14:b4:b4:b5:ed:89:3d:ce:fb:a9:9d:35:42:44:b1:
++ 1c:14:73:81:cf:2a:01:35:9a:31:d5:2d:8f:6d:84:df:80:4d:
++ 57:e3:3f:c5:84:75:da:89:c6:30:bb:eb:8f:cb:22:08:a0:ae:
++ aa:f1:03:6c:3a:4b:4d:09:a5:0e:72:c6:56:6b:21:42:4e:23:
++ 25:14:68:ae:76:0a:7c:0c:07:70:64:f9:9a:2f:f6:05:39:26:
++ c6:0c:8f:19:7f:43:5e:6e:f4:5b:15:2f:db:61:5d:e6:67:2f:
++ 3f:08:94:f9:60:b4:98:31:da:74:f1:84:93:71:4d:5f:fb:60:
++ 58:d1:fb:c4:c1:6d:89:a2:bb:20:1f:9d:71:91:cb:32:9b:13:
++ 3d:3e:7d:92:52:35:ac:92:94:a2:d3:18:c2:7c:c7:ea:af:76:
++ 05:16:dd:67:27:c2:7e:1c:07:22:21:f3:40:0a:1b:34:07:44:
++ 13:c2:84:6a:8e:df:19:5a:bf:7f:eb:1d:e2:1a:38:d1:5c:af:
++ 47:92:6b:80:b5:30:a5:c9:8d:d8:ab:31:81:1f:df:c2:66:37:
++ d3:93:a9:85:86:79:65:d2
++SHA1 Fingerprint=56:E0:FA:C0:3B:8F:18:23:55:18:E5:D3:11:CA:E8:C2:43:31:AB:66
++-----BEGIN CERTIFICATE-----
++MIIFwTCCA6mgAwIBAgIITrIAZwwDXU8wDQYJKoZIhvcNAQEFBQAwSTELMAkGA1UE
++BhMCQ0gxFTATBgNVBAoTDFN3aXNzU2lnbiBBRzEjMCEGA1UEAxMaU3dpc3NTaWdu
++IFBsYXRpbnVtIENBIC0gRzIwHhcNMDYxMDI1MDgzNjAwWhcNMzYxMDI1MDgzNjAw
++WjBJMQswCQYDVQQGEwJDSDEVMBMGA1UEChMMU3dpc3NTaWduIEFHMSMwIQYDVQQD
++ExpTd2lzc1NpZ24gUGxhdGludW0gQ0EgLSBHMjCCAiIwDQYJKoZIhvcNAQEBBQAD
++ggIPADCCAgoCggIBAMrfogLi2vj8Bxax3mCq3pZcZB/HL37PZ/pEQtZ2Y5Wu669y
++IIpFR4ZieIbWIDkm9K6j/SPnpZy1IiEZtzeTIsBQnIJ71NUERFzLtMKfkr4k2Htn
++IuJpX+UFeNSH2XFwMyVTtIc7KZAoNppVRDBopIOXfw0enHb/FZ1glwCNioUD7IC+
++6ixuEFGSzH7VozPY1kneWCqv9hbrS3uQMpe5up1Y8fhXSQQeol0GcN1x2/ndi5ob
++jM89o03Oy3z2u5yg+gnOI2Ky6Q0f4nIoj5+saCB9bzuohTEJfwvH6GXp43gOCWcw
++izSC+13gzJ2BbWLuCB4ELE6b7P6pT1/9aXjvCR+htL/68++QHkwFix7qepF6w9fl
+++zC8bBsQWJj3Gl/QKTIDE0ZNYWqFTFJ0LwYfexHihJfGmfNtf9dng34TaNhxKFrY
++zt3oEBSa/m0jh26OWnA81Y0JAKeqvLAxN23IhBQeW71FYyBrS3SMvds6DsHPWhaP
++pZjydomyExI7C3d3rLvlPClKknLKYRorXkzig3R3+jVIeoVNjZpTxN94ypeRSCtF
++KwH3HBqi7Ri6Cr2D+m+8jVeTO9TUps4e8aCxzqv9KyiaTxvXw3LbpMS/XUz13XuW
++ae5ogObnmLo2t/5u7Su9IPhlGdpVCX4l3P5hYnL5fhgC72O00Puv5TtjjGePAgMB
++AAGjgawwgakwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0O
++BBYEFFCvzAeHFUdvOMW0ZdHelarp35zMMB8GA1UdIwQYMBaAFFCvzAeHFUdvOMW0
++ZdHelarp35zMMEYGA1UdIAQ/MD0wOwYJYIV0AVkBAQEBMC4wLAYIKwYBBQUHAgEW
++IGh0dHA6Ly9yZXBvc2l0b3J5LnN3aXNzc2lnbi5jb20vMA0GCSqGSIb3DQEBBQUA
++A4ICAQAIhab1Fgz8RBrBY+D5VUYI/HAcQiiWjrfFwUF1TglxeeVtlspLpYhg0DB0
++uMoI3LQwnkAHFmtllXcBrqS3NQuB2nEVqXQXOHtYyvkv+8Bldo1bAbl93oI9ZLi+
++FHSjClTTLJUYFzX1UWs/j6KWYTl4a0vlpqD4U99REJNi54Av4tHgvI42Rncz7Lj7
++jposiU0xEQ8mngS7twSNC/K5/FqdOxa3L8iYq/6KUFkuozv8KV2LwUvJ4ooTHbG/
++u0IdUt1O2BReEMYxB+9xJ/cbOQncguqLs5WGXv312l0xpuAxtpTmREl0xRbl9x8D
++YSjFyMsSoEJL+WuICI20MhjzdZ/EfwBPBZWcoxcCw7NTm6ogOSkrZvqdr16zktK1
++puEa+S1BaYEUtLS17Yk9zvupnTVCRLEcFHOBzyoBNZox1S2PbYTfgE1X4z/FhHXa
++icYwu+uPyyIIoK6q8QNsOktNCaUOcsZWayFCTiMlFGiudgp8DAdwZPmaL/YFOSbG
++DI8Zf0NebvRbFS/bYV3mZy8/CJT5YLSYMdp08YSTcU1f+2BY0fvEwW2JorsgH51x
++kcsymxM9Pn2SUjWskpSi0xjCfMfqr3YFFt1nJ8J+HAciIfNAChs0B0QTwoRqjt8Z
++Wr9/6x3iGjjRXK9HkmuAtTClyY3YqzGBH9/CZjfTk6mFhnll0g==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
+@@ -0,0 +1,94 @@
++##
++## Symantec Class 1 Public Primary Certification Authority - G6
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 24:32:75:f2:1d:2f:d2:09:33:f7:b4:6a:ca:d0:f3:98
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
++ Validity
++ Not Before: Oct 18 00:00:00 2011 GMT
++ Not After : Dec 1 23:59:59 2037 GMT
++ Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c7:39:d7:49:64:a9:99:82:22:4c:ea:45:d9:07:
++ 16:e3:7b:f4:83:e8:99:73:fa:6b:b1:36:e0:9a:77:
++ a0:40:c2:81:8d:01:c7:cc:8c:bd:8f:7d:f7:79:e3:
++ 7a:4c:03:4d:d9:fb:fd:87:38:28:2c:dd:9a:8b:54:
++ 08:db:67:fb:1b:8c:fe:28:92:2f:be:b7:b2:48:a7:
++ 81:a1:d8:5e:88:c3:cc:39:40:41:5a:d1:dc:e5:da:
++ 10:9f:2f:da:01:4d:fd:2e:46:7c:f9:2e:27:0a:69:
++ 37:ee:91:a3:1b:6a:cc:44:bf:1b:c7:c3:d4:11:b2:
++ 50:60:97:09:bd:2e:22:f5:41:84:66:9f:cd:40:a6:
++ a9:00:80:c1:1f:95:92:9f:de:f3:48:ef:db:1d:77:
++ 61:fc:7f:df:ee:96:a4:72:d0:b6:3e:ff:78:27:af:
++ cb:92:15:69:08:db:63:10:e2:e6:97:ac:6e:dc:ac:
++ f6:a2:ce:1e:47:99:b9:89:b7:12:e6:a1:d4:cd:59:
++ 11:67:c3:6f:85:d8:42:4e:28:be:59:55:59:04:95:
++ ab:8f:37:80:bf:0d:f0:fc:1f:3a:64:31:58:81:78:
++ d7:e2:35:f6:20:3f:29:b8:8f:16:6e:3e:48:dc:b5:
++ 4c:07:e1:f2:1a:ea:7e:0a:79:d6:a8:bd:eb:5d:86:
++ 2b:4d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 33:41:E8:C8:39:12:15:93:48:F2:96:32:2E:5A:F5:DA:94:5F:53:60
++ Signature Algorithm: sha256WithRSAEncryption
++ 15:e3:73:57:b1:17:b6:5f:49:69:44:a6:f6:5e:7a:67:ac:d2:
++ de:75:49:ab:fe:25:55:c7:3a:c9:44:15:10:6e:bf:31:6b:cb:
++ d9:07:93:7f:1c:85:63:00:e3:32:12:e0:cc:cb:fb:39:6c:8f:
++ e2:53:e2:3c:40:33:d9:a4:8c:47:e6:ad:58:fb:89:af:e3:de:
++ 86:29:56:34:2c:45:b8:12:fa:44:89:6e:2d:14:25:28:24:01:
++ 65:d6:ea:52:ac:05:6e:56:12:09:3d:d0:74:f4:d7:bd:06:ca:
++ a8:3a:8d:56:42:fa:8d:72:3e:74:f1:03:72:df:87:1b:5e:0e:
++ 7a:55:96:2c:38:b7:98:85:cd:4d:33:44:c9:94:8f:5a:31:30:
++ 37:4b:a3:3a:12:b3:e7:36:d1:21:68:4b:2d:38:e6:53:ae:1c:
++ 25:56:08:56:03:67:84:9d:c6:c3:ce:24:62:c7:4c:36:cf:b0:
++ 06:44:b7:f5:5f:02:dd:d9:54:e9:2f:90:4e:7a:c8:4e:83:40:
++ 0c:9a:97:3c:37:bf:bf:ec:f6:f0:b4:85:77:28:c1:0b:c8:67:
++ 82:10:17:38:a2:b7:06:ea:9b:bf:3a:f8:e9:23:07:bf:74:e0:
++ 98:38:15:55:78:ee:72:00:5c:19:a3:f4:d2:33:e0:ff:bd:d1:
++ 54:39:29:0f
++SHA1 Fingerprint=51:7F:61:1E:29:91:6B:53:82:FB:72:E7:44:D9:8D:C3:CC:53:6D:64
++-----BEGIN CERTIFICATE-----
++MIID9jCCAt6gAwIBAgIQJDJ18h0v0gkz97RqytDzmDANBgkqhkiG9w0BAQsFADCB
++lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
++HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
++YyBDbGFzcyAxIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
++IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
++BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
++eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAx
++IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
++MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHOddJZKmZgiJM6kXZBxbje/SD
++6Jlz+muxNuCad6BAwoGNAcfMjL2Pffd543pMA03Z+/2HOCgs3ZqLVAjbZ/sbjP4o
++ki++t7JIp4Gh2F6Iw8w5QEFa0dzl2hCfL9oBTf0uRnz5LicKaTfukaMbasxEvxvH
++w9QRslBglwm9LiL1QYRmn81ApqkAgMEflZKf3vNI79sdd2H8f9/ulqRy0LY+/3gn
++r8uSFWkI22MQ4uaXrG7crPaizh5HmbmJtxLmodTNWRFnw2+F2EJOKL5ZVVkElauP
++N4C/DfD8HzpkMViBeNfiNfYgPym4jxZuPkjctUwH4fIa6n4KedaovetdhitNAgMB
++AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
++BBQzQejIORIVk0jyljIuWvXalF9TYDANBgkqhkiG9w0BAQsFAAOCAQEAFeNzV7EX
++tl9JaUSm9l56Z6zS3nVJq/4lVcc6yUQVEG6/MWvL2QeTfxyFYwDjMhLgzMv7OWyP
++4lPiPEAz2aSMR+atWPuJr+PehilWNCxFuBL6RIluLRQlKCQBZdbqUqwFblYSCT3Q
++dPTXvQbKqDqNVkL6jXI+dPEDct+HG14OelWWLDi3mIXNTTNEyZSPWjEwN0ujOhKz
++5zbRIWhLLTjmU64cJVYIVgNnhJ3Gw84kYsdMNs+wBkS39V8C3dlU6S+QTnrIToNA
++DJqXPDe/v+z28LSFdyjBC8hnghAXOKK3Buqbvzr46SMHv3TgmDgVVXjucgBcGaP0
++0jPg/73RVDkpDw==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
+@@ -0,0 +1,94 @@
++##
++## Symantec Class 2 Public Primary Certification Authority - G6
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 64:82:9e:fc:37:1e:74:5d:fc:97:ff:97:c8:b1:ff:41
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
++ Validity
++ Not Before: Oct 18 00:00:00 2011 GMT
++ Not After : Dec 1 23:59:59 2037 GMT
++ Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:cd:cc:e9:05:c8:63:85:cb:3f:40:63:17:bd:18:
++ fa:35:e6:04:67:57:65:98:29:a4:4f:c9:5c:8f:0f:
++ 34:d2:f8:da:a8:13:62:aa:b8:1e:50:67:78:b0:16:
++ 4c:a0:39:a9:15:7a:ae:ed:d2:a2:c0:f0:90:37:29:
++ 18:26:5c:e8:0d:3c:b6:6c:49:3f:c1:e0:dc:d9:4b:
++ b6:14:19:0b:a6:d3:96:e1:d6:09:e3:19:26:1c:f9:
++ 1f:65:4b:f9:1a:43:1c:00:83:d6:d0:aa:49:a2:d4:
++ db:e6:62:38:ba:50:14:43:6d:f9:31:f8:56:16:d9:
++ 38:02:91:cf:eb:6c:dd:bb:39:4e:99:e1:30:67:45:
++ f1:d4:f0:8d:c3:df:fe:f2:38:07:21:7d:00:5e:56:
++ 44:b3:e4:60:bd:91:2b:9c:ab:5b:04:72:0f:b2:28:
++ d9:72:ab:05:20:42:25:a9:5b:03:6a:20:10:cc:31:
++ f0:2b:da:35:2c:d0:fb:9a:97:4e:f0:82:4b:2b:d8:
++ 5f:36:a3:0b:2d:af:63:0d:1d:25:7f:a1:6e:5c:62:
++ a1:8d:28:3e:a1:fc:1c:20:f8:01:2f:ba:55:9a:11:
++ b0:19:d2:c8:50:79:6b:0e:6a:05:d7:aa:04:36:b2:
++ a3:f2:e1:5f:77:a7:77:9c:e5:1e:dc:e9:df:6a:c1:
++ 65:5d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 87:8C:20:95:C8:98:4A:D1:D6:80:06:4A:90:34:44:DF:1C:4D:BF:B0
++ Signature Algorithm: sha256WithRSAEncryption
++ 81:8e:b2:a5:66:96:b7:21:a5:b6:ef:6f:23:5a:5f:db:81:c5:
++ 42:a5:78:c1:69:fd:f4:3c:d7:f9:5c:6b:70:72:1a:fc:5a:97:
++ 4d:00:80:88:88:82:8a:c3:71:0d:8e:c5:89:9b:2c:ed:8d:0b:
++ d2:72:54:f5:7d:d4:5c:43:57:e9:f3:ae:a5:02:11:f6:76:2b:
++ 81:57:dd:7d:da:74:30:fd:54:47:f6:e0:16:6e:a6:b4:0a:48:
++ e6:e7:75:07:0f:29:19:39:ce:79:f4:b6:6c:c5:5f:99:d5:1f:
++ 4b:fa:df:6d:2c:3c:0d:54:80:70:f0:88:0b:80:cf:c6:68:a2:
++ b8:1d:70:d9:76:8c:fc:ee:a5:c9:cf:ad:1d:cf:99:25:57:5a:
++ 62:45:cb:16:6b:bd:49:cd:a5:a3:8c:69:79:25:ae:b8:4c:6c:
++ 8b:40:66:4b:16:3f:cf:02:1a:dd:e1:6c:6b:07:61:6a:76:15:
++ 29:99:7f:1b:dd:88:80:c1:bf:b5:8f:73:c5:a6:96:23:84:a6:
++ 28:86:24:33:6a:01:2e:57:73:25:b6:5e:bf:8f:e6:1d:61:a8:
++ 40:29:67:1d:87:9b:1d:7f:9b:9f:99:cd:31:d6:54:be:62:bb:
++ 39:ac:68:12:48:91:20:a5:cb:b1:dd:fe:6f:fc:5a:e4:82:55:
++ 59:af:31:a9
++SHA1 Fingerprint=40:B3:31:A0:E9:BF:E8:55:BC:39:93:CA:70:4F:4E:C2:51:D4:1D:8F
++-----BEGIN CERTIFICATE-----
++MIID9jCCAt6gAwIBAgIQZIKe/DcedF38l/+XyLH/QTANBgkqhkiG9w0BAQsFADCB
++lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
++HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
++YyBDbGFzcyAyIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
++IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
++BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
++eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAy
++IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
++MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDNzOkFyGOFyz9AYxe9GPo15gRn
++V2WYKaRPyVyPDzTS+NqoE2KquB5QZ3iwFkygOakVeq7t0qLA8JA3KRgmXOgNPLZs
++ST/B4NzZS7YUGQum05bh1gnjGSYc+R9lS/kaQxwAg9bQqkmi1NvmYji6UBRDbfkx
+++FYW2TgCkc/rbN27OU6Z4TBnRfHU8I3D3/7yOAchfQBeVkSz5GC9kSucq1sEcg+y
++KNlyqwUgQiWpWwNqIBDMMfAr2jUs0Pual07wgksr2F82owstr2MNHSV/oW5cYqGN
++KD6h/Bwg+AEvulWaEbAZ0shQeWsOagXXqgQ2sqPy4V93p3ec5R7c6d9qwWVdAgMB
++AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
++BBSHjCCVyJhK0daABkqQNETfHE2/sDANBgkqhkiG9w0BAQsFAAOCAQEAgY6ypWaW
++tyGltu9vI1pf24HFQqV4wWn99DzX+VxrcHIa/FqXTQCAiIiCisNxDY7FiZss7Y0L
++0nJU9X3UXENX6fOupQIR9nYrgVfdfdp0MP1UR/bgFm6mtApI5ud1Bw8pGTnOefS2
++bMVfmdUfS/rfbSw8DVSAcPCIC4DPxmiiuB1w2XaM/O6lyc+tHc+ZJVdaYkXLFmu9
++Sc2lo4xpeSWuuExsi0BmSxY/zwIa3eFsawdhanYVKZl/G92IgMG/tY9zxaaWI4Sm
++KIYkM2oBLldzJbZev4/mHWGoQClnHYebHX+bn5nNMdZUvmK7OaxoEkiRIKXLsd3+
++b/xa5IJVWa8xqQ==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Trustis_FPS_Root_CA.pem
+@@ -0,0 +1,92 @@
++##
++## Trustis FPS Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 1b:1f:ad:b6:20:f9:24:d3:36:6b:f7:c7:f1:8c:a0:59
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
++ Validity
++ Not Before: Dec 23 12:14:06 2003 GMT
++ Not After : Jan 21 11:36:54 2024 GMT
++ Subject: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c5:50:7b:9e:3b:35:d0:df:c4:8c:cd:8e:9b:ed:
++ a3:c0:36:99:f4:42:ea:a7:3e:80:83:0f:a6:a7:59:
++ 87:c9:90:45:43:7e:00:ea:86:79:2a:03:bd:3d:37:
++ 99:89:66:b7:e5:8a:56:86:93:9c:68:4b:68:04:8c:
++ 93:93:02:3e:30:d2:37:3a:22:61:89:1c:85:4e:7d:
++ 8f:d5:af:7b:35:f6:7e:28:47:89:31:dc:0e:79:64:
++ 1f:99:d2:5b:ba:fe:7f:60:bf:ad:eb:e7:3c:38:29:
++ 6a:2f:e5:91:0b:55:ff:ec:6f:58:d5:2d:c9:de:4c:
++ 66:71:8f:0c:d7:04:da:07:e6:1e:18:e3:bd:29:02:
++ a8:fa:1c:e1:5b:b9:83:a8:41:48:bc:1a:71:8d:e7:
++ 62:e5:2d:b2:eb:df:7c:cf:db:ab:5a:ca:31:f1:4c:
++ 22:f3:05:13:f7:82:f9:73:79:0c:be:d7:4b:1c:c0:
++ d1:15:3c:93:41:64:d1:e6:be:23:17:22:00:89:5e:
++ 1f:6b:a5:ac:6e:a7:4b:8c:ed:a3:72:e6:af:63:4d:
++ 2f:85:d2:14:35:9a:2e:4e:8c:ea:32:98:28:86:a1:
++ 91:09:41:3a:b4:e1:e3:f2:fa:f0:c9:0a:a2:41:dd:
++ a9:e3:03:c7:88:15:3b:1c:d4:1a:94:d7:9f:64:59:
++ 12:6d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Authority Key Identifier:
++ keyid:BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
++
++ X509v3 Subject Key Identifier:
++ BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
++ Signature Algorithm: sha1WithRSAEncryption
++ 7e:58:ff:fd:35:19:7d:9c:18:4f:9e:b0:2b:bc:8e:8c:14:ff:
++ 2c:a0:da:47:5b:c3:ef:81:2d:af:05:ea:74:48:5b:f3:3e:4e:
++ 07:c7:6d:c5:b3:93:cf:22:35:5c:b6:3f:75:27:5f:09:96:cd:
++ a0:fe:be:40:0c:5c:12:55:f8:93:82:ca:29:e9:5e:3f:56:57:
++ 8b:38:36:f7:45:1a:4c:28:cd:9e:41:b8:ed:56:4c:84:a4:40:
++ c8:b8:b0:a5:2b:69:70:04:6a:c3:f8:d4:12:32:f9:0e:c3:b1:
++ dc:32:84:44:2c:6f:cb:46:0f:ea:66:41:0f:4f:f1:58:a5:a6:
++ 0d:0d:0f:61:de:a5:9e:5d:7d:65:a1:3c:17:e7:a8:55:4e:ef:
++ a0:c7:ed:c6:44:7f:54:f5:a3:e0:8f:f0:7c:55:22:8f:29:b6:
++ 81:a3:e1:6d:4e:2c:1b:80:67:ec:ad:20:9f:0c:62:61:d5:97:
++ ff:43:ed:2d:c1:da:5d:29:2a:85:3f:ac:65:ee:86:0f:05:8d:
++ 90:5f:df:ee:9f:f4:bf:ee:1d:fb:98:e4:7f:90:2b:84:78:10:
++ 0e:6c:49:53:ef:15:5b:65:46:4a:5d:af:ba:fb:3a:72:1d:cd:
++ f6:25:88:1e:97:cc:21:9c:29:01:0d:65:eb:57:d9:f3:57:96:
++ bb:48:cd:81
++SHA1 Fingerprint=3B:C0:38:0B:33:C3:F6:A6:0C:86:15:22:93:D9:DF:F5:4B:81:C0:04
++-----BEGIN CERTIFICATE-----
++MIIDZzCCAk+gAwIBAgIQGx+ttiD5JNM2a/fH8YygWTANBgkqhkiG9w0BAQUFADBF
++MQswCQYDVQQGEwJHQjEYMBYGA1UEChMPVHJ1c3RpcyBMaW1pdGVkMRwwGgYDVQQL
++ExNUcnVzdGlzIEZQUyBSb290IENBMB4XDTAzMTIyMzEyMTQwNloXDTI0MDEyMTEx
++MzY1NFowRTELMAkGA1UEBhMCR0IxGDAWBgNVBAoTD1RydXN0aXMgTGltaXRlZDEc
++MBoGA1UECxMTVHJ1c3RpcyBGUFMgUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQAD
++ggEPADCCAQoCggEBAMVQe547NdDfxIzNjpvto8A2mfRC6qc+gIMPpqdZh8mQRUN+
++AOqGeSoDvT03mYlmt+WKVoaTnGhLaASMk5MCPjDSNzoiYYkchU59j9WvezX2fihH
++iTHcDnlkH5nSW7r+f2C/revnPDgpai/lkQtV/+xvWNUtyd5MZnGPDNcE2gfmHhjj
++vSkCqPoc4Vu5g6hBSLwacY3nYuUtsuvffM/bq1rKMfFMIvMFE/eC+XN5DL7XSxzA
++0RU8k0Fk0ea+IxciAIleH2ulrG6nS4zto3Lmr2NNL4XSFDWaLk6M6jKYKIahkQlB
++OrTh4/L68MkKokHdqeMDx4gVOxzUGpTXn2RZEm0CAwEAAaNTMFEwDwYDVR0TAQH/
++BAUwAwEB/zAfBgNVHSMEGDAWgBS6+nEleYtXQSUhhgtx67JkDoshZzAdBgNVHQ4E
++FgQUuvpxJXmLV0ElIYYLceuyZA6LIWcwDQYJKoZIhvcNAQEFBQADggEBAH5Y//01
++GX2cGE+esCu8jowU/yyg2kdbw++BLa8F6nRIW/M+TgfHbcWzk88iNVy2P3UnXwmW
++zaD+vkAMXBJV+JOCyinpXj9WV4s4NvdFGkwozZ5BuO1WTISkQMi4sKUraXAEasP4
++1BIy+Q7DsdwyhEQsb8tGD+pmQQ9P8Vilpg0ND2HepZ5dfWWhPBfnqFVO76DH7cZE
++f1T1o+CP8HxVIo8ptoGj4W1OLBuAZ+ytIJ8MYmHVl/9D7S3B2l0pKoU/rGXuhg8F
++jZBf3+6f9L/uHfuY5H+QK4R4EA5sSVPvFVtlRkpdr7r7OnIdzfYliB6XzCGcKQEN
++ZetX2fNXlrtIzYE=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/VeriSign_Universal_Root_Certification_Authority.pem
+@@ -0,0 +1,100 @@
++##
++## VeriSign Universal Root Certification Authority
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 40:1a:c4:64:21:b3:13:21:03:0e:bb:e4:12:1a:c5:1d
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
++ Validity
++ Not Before: Apr 2 00:00:00 2008 GMT
++ Not After : Dec 1 23:59:59 2037 GMT
++ Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c7:61:37:5e:b1:01:34:db:62:d7:15:9b:ff:58:
++ 5a:8c:23:23:d6:60:8e:91:d7:90:98:83:7a:e6:58:
++ 19:38:8c:c5:f6:e5:64:85:b4:a2:71:fb:ed:bd:b9:
++ da:cd:4d:00:b4:c8:2d:73:a5:c7:69:71:95:1f:39:
++ 3c:b2:44:07:9c:e8:0e:fa:4d:4a:c4:21:df:29:61:
++ 8f:32:22:61:82:c5:87:1f:6e:8c:7c:5f:16:20:51:
++ 44:d1:70:4f:57:ea:e3:1c:e3:cc:79:ee:58:d8:0e:
++ c2:b3:45:93:c0:2c:e7:9a:17:2b:7b:00:37:7a:41:
++ 33:78:e1:33:e2:f3:10:1a:7f:87:2c:be:f6:f5:f7:
++ 42:e2:e5:bf:87:62:89:5f:00:4b:df:c5:dd:e4:75:
++ 44:32:41:3a:1e:71:6e:69:cb:0b:75:46:08:d1:ca:
++ d2:2b:95:d0:cf:fb:b9:40:6b:64:8c:57:4d:fc:13:
++ 11:79:84:ed:5e:54:f6:34:9f:08:01:f3:10:25:06:
++ 17:4a:da:f1:1d:7a:66:6b:98:60:66:a4:d9:ef:d2:
++ 2e:82:f1:f0:ef:09:ea:44:c9:15:6a:e2:03:6e:33:
++ d3:ac:9f:55:00:c7:f6:08:6a:94:b9:5f:dc:e0:33:
++ f1:84:60:f9:5b:27:11:b4:fc:16:f2:bb:56:6a:80:
++ 25:8d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ 1.3.6.1.5.5.7.1.12:
++ 0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif
++ X509v3 Subject Key Identifier:
++ B6:77:FA:69:48:47:9F:53:12:D5:C2:EA:07:32:76:07:D1:97:07:19
++ Signature Algorithm: sha256WithRSAEncryption
++ 4a:f8:f8:b0:03:e6:2c:67:7b:e4:94:77:63:cc:6e:4c:f9:7d:
++ 0e:0d:dc:c8:b9:35:b9:70:4f:63:fa:24:fa:6c:83:8c:47:9d:
++ 3b:63:f3:9a:f9:76:32:95:91:b1:77:bc:ac:9a:be:b1:e4:31:
++ 21:c6:81:95:56:5a:0e:b1:c2:d4:b1:a6:59:ac:f1:63:cb:b8:
++ 4c:1d:59:90:4a:ef:90:16:28:1f:5a:ae:10:fb:81:50:38:0c:
++ 6c:cc:f1:3d:c3:f5:63:e3:b3:e3:21:c9:24:39:e9:fd:15:66:
++ 46:f4:1b:11:d0:4d:73:a3:7d:46:f9:3d:ed:a8:5f:62:d4:f1:
++ 3f:f8:e0:74:57:2b:18:9d:81:b4:c4:28:da:94:97:a5:70:eb:
++ ac:1d:be:07:11:f0:d5:db:dd:e5:8c:f0:d5:32:b0:83:e6:57:
++ e2:8f:bf:be:a1:aa:bf:3d:1d:b5:d4:38:ea:d7:b0:5c:3a:4f:
++ 6a:3f:8f:c0:66:6c:63:aa:e9:d9:a4:16:f4:81:d1:95:14:0e:
++ 7d:cd:95:34:d9:d2:8f:70:73:81:7b:9c:7e:bd:98:61:d8:45:
++ 87:98:90:c5:eb:86:30:c6:35:bf:f0:ff:c3:55:88:83:4b:ef:
++ 05:92:06:71:f2:b8:98:93:b7:ec:cd:82:61:f1:38:e6:4f:97:
++ 98:2a:5a:8d
++SHA1 Fingerprint=36:79:CA:35:66:87:72:30:4D:30:A5:FB:87:3B:0F:A7:7B:B7:0D:54
++-----BEGIN CERTIFICATE-----
++MIIEuTCCA6GgAwIBAgIQQBrEZCGzEyEDDrvkEhrFHTANBgkqhkiG9w0BAQsFADCB
++vTELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
++ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwOCBWZXJp
++U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MTgwNgYDVQQDEy9W
++ZXJpU2lnbiBVbml2ZXJzYWwgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAe
++Fw0wODA0MDIwMDAwMDBaFw0zNzEyMDEyMzU5NTlaMIG9MQswCQYDVQQGEwJVUzEX
++MBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0
++IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAyMDA4IFZlcmlTaWduLCBJbmMuIC0gRm9y
++IGF1dGhvcml6ZWQgdXNlIG9ubHkxODA2BgNVBAMTL1ZlcmlTaWduIFVuaXZlcnNh
++bCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG9w0BAQEF
++AAOCAQ8AMIIBCgKCAQEAx2E3XrEBNNti1xWb/1hajCMj1mCOkdeQmIN65lgZOIzF
++9uVkhbSicfvtvbnazU0AtMgtc6XHaXGVHzk8skQHnOgO+k1KxCHfKWGPMiJhgsWH
++H26MfF8WIFFE0XBPV+rjHOPMee5Y2A7Cs0WTwCznmhcrewA3ekEzeOEz4vMQGn+H
++LL729fdC4uW/h2KJXwBL38Xd5HVEMkE6HnFuacsLdUYI0crSK5XQz/u5QGtkjFdN
++/BMReYTtXlT2NJ8IAfMQJQYXStrxHXpma5hgZqTZ79IugvHw7wnqRMkVauIDbjPT
++rJ9VAMf2CGqUuV/c4DPxhGD5WycRtPwW8rtWaoAljQIDAQABo4GyMIGvMA8GA1Ud
++EwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMG0GCCsGAQUFBwEMBGEwX6FdoFsw
++WTBXMFUWCWltYWdlL2dpZjAhMB8wBwYFKw4DAhoEFI/l0xqGrI2Oa8PPgGrUSBgs
++exkuMCUWI2h0dHA6Ly9sb2dvLnZlcmlzaWduLmNvbS92c2xvZ28uZ2lmMB0GA1Ud
++DgQWBBS2d/ppSEefUxLVwuoHMnYH0ZcHGTANBgkqhkiG9w0BAQsFAAOCAQEASvj4
++sAPmLGd75JR3Y8xuTPl9Dg3cyLk1uXBPY/ok+myDjEedO2Pzmvl2MpWRsXe8rJq+
++seQxIcaBlVZaDrHC1LGmWazxY8u4TB1ZkErvkBYoH1quEPuBUDgMbMzxPcP1Y+Oz
++4yHJJDnp/RVmRvQbEdBNc6N9Rvk97ahfYtTxP/jgdFcrGJ2BtMQo2pSXpXDrrB2+
++BxHw1dvd5Yzw1TKwg+ZX4o+/vqGqvz0dtdQ46tewXDpPaj+PwGZsY6rp2aQW9IHR
++lRQOfc2VNNnSj3BzgXucfr2YYdhFh5iQxeuGMMY1v/D/w1WIg0vvBZIGcfK4mJO3
++7M2CYfE45k+XmCpajQ==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
+@@ -0,0 +1,87 @@
++##
++## Verisign Class 1 Public Primary Certification Authority - G3
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 1 (0x0)
++ Serial Number:
++ 8b:5b:75:56:84:54:85:0b:00:cf:af:38:48:ce:b1:a4
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
++ Validity
++ Not Before: Oct 1 00:00:00 1999 GMT
++ Not After : Jul 16 23:59:59 2036 GMT
++ Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:dd:84:d4:b9:b4:f9:a7:d8:f3:04:78:9c:de:3d:
++ dc:6c:13:16:d9:7a:dd:24:51:66:c0:c7:26:59:0d:
++ ac:06:08:c2:94:d1:33:1f:f0:83:35:1f:6e:1b:c8:
++ de:aa:6e:15:4e:54:27:ef:c4:6d:1a:ec:0b:e3:0e:
++ f0:44:a5:57:c7:40:58:1e:a3:47:1f:71:ec:60:f6:
++ 6d:94:c8:18:39:ed:fe:42:18:56:df:e4:4c:49:10:
++ 78:4e:01:76:35:63:12:36:dd:66:bc:01:04:36:a3:
++ 55:68:d5:a2:36:09:ac:ab:21:26:54:06:ad:3f:ca:
++ 14:e0:ac:ca:ad:06:1d:95:e2:f8:9d:f1:e0:60:ff:
++ c2:7f:75:2b:4c:cc:da:fe:87:99:21:ea:ba:fe:3e:
++ 54:d7:d2:59:78:db:3c:6e:cf:a0:13:00:1a:b8:27:
++ a1:e4:be:67:96:ca:a0:c5:b3:9c:dd:c9:75:9e:eb:
++ 30:9a:5f:a3:cd:d9:ae:78:19:3f:23:e9:5c:db:29:
++ bd:ad:55:c8:1b:54:8c:63:f6:e8:a6:ea:c7:37:12:
++ 5c:a3:29:1e:02:d9:db:1f:3b:b4:d7:0f:56:47:81:
++ 15:04:4a:af:83:27:d1:c5:58:88:c1:dd:f6:aa:a7:
++ a3:18:da:68:aa:6d:11:51:e1:bf:65:6b:9f:96:76:
++ d1:3d
++ Exponent: 65537 (0x10001)
++ Signature Algorithm: sha1WithRSAEncryption
++ ab:66:8d:d7:b3:ba:c7:9a:b6:e6:55:d0:05:f1:9f:31:8d:5a:
++ aa:d9:aa:46:26:0f:71:ed:a5:ad:53:56:62:01:47:2a:44:e9:
++ fe:3f:74:0b:13:9b:b9:f4:4d:1b:b2:d1:5f:b2:b6:d2:88:5c:
++ b3:9f:cd:cb:d4:a7:d9:60:95:84:3a:f8:c1:37:1d:61:ca:e7:
++ b0:c5:e5:91:da:54:a6:ac:31:81:ae:97:de:cd:08:ac:b8:c0:
++ 97:80:7f:6e:72:a4:e7:69:13:95:65:1f:c4:93:3c:fd:79:8f:
++ 04:d4:3e:4f:ea:f7:9e:ce:cd:67:7c:4f:65:02:ff:91:85:54:
++ 73:c7:ff:36:f7:86:2d:ec:d0:5e:4f:ff:11:9f:72:06:d6:b8:
++ 1a:f1:4c:0d:26:65:e2:44:80:1e:c7:9f:e3:dd:e8:0a:da:ec:
++ a5:20:80:69:68:a1:4f:7e:e1:6b:cf:07:41:fa:83:8e:bc:38:
++ dd:b0:2e:11:b1:6b:b2:42:cc:9a:bc:f9:48:22:79:4a:19:0f:
++ b2:1c:3e:20:74:d9:6a:c3:be:f2:28:78:13:56:79:4f:6d:50:
++ ea:1b:b0:b5:57:b1:37:66:58:23:f3:dc:0f:df:0a:87:c4:ef:
++ 86:05:d5:38:14:60:99:a3:4b:de:06:96:71:2c:f2:db:b6:1f:
++ a4:ef:3f:ee
++SHA1 Fingerprint=20:42:85:DC:F7:EB:76:41:95:57:8E:13:6B:D4:B7:D1:E9:8E:46:A5
++-----BEGIN CERTIFICATE-----
++MIIEGjCCAwICEQCLW3VWhFSFCwDPrzhIzrGkMA0GCSqGSIb3DQEBBQUAMIHKMQsw
++CQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZl
++cmlTaWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWdu
++LCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlT
++aWduIENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3Jp
++dHkgLSBHMzAeFw05OTEwMDEwMDAwMDBaFw0zNjA3MTYyMzU5NTlaMIHKMQswCQYD
++VQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlT
++aWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWduLCBJ
++bmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlTaWdu
++IENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkg
++LSBHMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAN2E1Lm0+afY8wR4
++nN493GwTFtl63SRRZsDHJlkNrAYIwpTRMx/wgzUfbhvI3qpuFU5UJ+/EbRrsC+MO
++8ESlV8dAWB6jRx9x7GD2bZTIGDnt/kIYVt/kTEkQeE4BdjVjEjbdZrwBBDajVWjV
++ojYJrKshJlQGrT/KFOCsyq0GHZXi+J3x4GD/wn91K0zM2v6HmSHquv4+VNfSWXjb
++PG7PoBMAGrgnoeS+Z5bKoMWznN3JdZ7rMJpfo83ZrngZPyPpXNspva1VyBtUjGP2
++6KbqxzcSXKMpHgLZ2x87tNcPVkeBFQRKr4Mn0cVYiMHd9qqnoxjaaKptEVHhv2Vr
++n5Z20T0CAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAq2aN17O6x5q25lXQBfGfMY1a
++qtmqRiYPce2lrVNWYgFHKkTp/j90CxObufRNG7LRX7K20ohcs5/Ny9Sn2WCVhDr4
++wTcdYcrnsMXlkdpUpqwxga6X3s0IrLjAl4B/bnKk52kTlWUfxJM8/XmPBNQ+T+r3
++ns7NZ3xPZQL/kYVUc8f/NveGLezQXk//EZ9yBta4GvFMDSZl4kSAHsef493oCtrs
++pSCAaWihT37ha88HQfqDjrw43bAuEbFrskLMmrz5SCJ5ShkPshw+IHTZasO+8ih4
++E1Z5T21Q6huwtVexN2ZYI/PcD98Kh8TvhgXVOBRgmaNL3gaWcSzy27YfpO8/7g==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
+@@ -0,0 +1,87 @@
++##
++## Verisign Class 2 Public Primary Certification Authority - G3
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 1 (0x0)
++ Serial Number:
++ 61:70:cb:49:8c:5f:98:45:29:e7:b0:a6:d9:50:5b:7a
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
++ Validity
++ Not Before: Oct 1 00:00:00 1999 GMT
++ Not After : Jul 16 23:59:59 2036 GMT
++ Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:af:0a:0d:c2:d5:2c:db:67:b9:2d:e5:94:27:dd:
++ a5:be:e0:b0:4d:8f:b3:61:56:3c:d6:7c:c3:f4:cd:
++ 3e:86:cb:a2:88:e2:e1:d8:a4:69:c5:b5:e2:bf:c1:
++ a6:47:50:5e:46:39:8b:d5:96:ba:b5:6f:14:bf:10:
++ ce:27:13:9e:05:47:9b:31:7a:13:d8:1f:d9:d3:02:
++ 37:8b:ad:2c:47:f0:8e:81:06:a7:0d:30:0c:eb:f7:
++ 3c:0f:20:1d:dc:72:46:ee:a5:02:c8:5b:c3:c9:56:
++ 69:4c:c5:18:c1:91:7b:0b:d5:13:00:9b:bc:ef:c3:
++ 48:3e:46:60:20:85:2a:d5:90:b6:cd:8b:a0:cc:32:
++ dd:b7:fd:40:55:b2:50:1c:56:ae:cc:8d:77:4d:c7:
++ 20:4d:a7:31:76:ef:68:92:8a:90:1e:08:81:56:b2:
++ ad:69:a3:52:d0:cb:1c:c4:23:3d:1f:99:fe:4c:e8:
++ 16:63:8e:c6:08:8e:f6:31:f6:d2:fa:e5:76:dd:b5:
++ 1c:92:a3:49:cd:cd:01:cd:68:cd:a9:69:ba:a3:eb:
++ 1d:0d:9c:a4:20:a6:c1:a0:c5:d1:46:4c:17:6d:d2:
++ ac:66:3f:96:8c:e0:84:d4:36:ff:22:59:c5:f9:11:
++ 60:a8:5f:04:7d:f2:1a:f6:25:42:61:0f:c4:4a:b8:
++ 3e:89
++ Exponent: 65537 (0x10001)
++ Signature Algorithm: sha1WithRSAEncryption
++ 34:26:15:3c:c0:8d:4d:43:49:1d:bd:e9:21:92:d7:66:9c:b7:
++ de:c5:b8:d0:e4:5d:5f:76:22:c0:26:f9:84:3a:3a:f9:8c:b5:
++ fb:ec:60:f1:e8:ce:04:b0:c8:dd:a7:03:8f:30:f3:98:df:a4:
++ e6:a4:31:df:d3:1c:0b:46:dc:72:20:3f:ae:ee:05:3c:a4:33:
++ 3f:0b:39:ac:70:78:73:4b:99:2b:df:30:c2:54:b0:a8:3b:55:
++ a1:fe:16:28:cd:42:bd:74:6e:80:db:27:44:a7:ce:44:5d:d4:
++ 1b:90:98:0d:1e:42:94:b1:00:2c:04:d0:74:a3:02:05:22:63:
++ 63:cd:83:b5:fb:c1:6d:62:6b:69:75:fd:5d:70:41:b9:f5:bf:
++ 7c:df:be:c1:32:73:22:21:8b:58:81:7b:15:91:7a:ba:e3:64:
++ 48:b0:7f:fb:36:25:da:95:d0:f1:24:14:17:dd:18:80:6b:46:
++ 23:39:54:f5:8e:62:09:04:1d:94:90:a6:9b:e6:25:e2:42:45:
++ aa:b8:90:ad:be:08:8f:a9:0b:42:18:94:cf:72:39:e1:b1:43:
++ e0:28:cf:b7:e7:5a:6c:13:6b:49:b3:ff:e3:18:7c:89:8b:33:
++ 5d:ac:33:d7:a7:f9:da:3a:55:c9:58:10:f9:aa:ef:5a:b6:cf:
++ 4b:4b:df:2a
++SHA1 Fingerprint=61:EF:43:D7:7F:CA:D4:61:51:BC:98:E0:C3:59:12:AF:9F:EB:63:11
++-----BEGIN CERTIFICATE-----
++MIIEGTCCAwECEGFwy0mMX5hFKeewptlQW3owDQYJKoZIhvcNAQEFBQAwgcoxCzAJ
++BgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVy
++aVNpZ24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24s
++IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNp
++Z24gQ2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
++eSAtIEczMB4XDTk5MTAwMTAwMDAwMFoXDTM2MDcxNjIzNTk1OVowgcoxCzAJBgNV
++BAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVyaVNp
++Z24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24sIElu
++Yy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNpZ24g
++Q2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAt
++IEczMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArwoNwtUs22e5LeWU
++J92lvuCwTY+zYVY81nzD9M0+hsuiiOLh2KRpxbXiv8GmR1BeRjmL1Za6tW8UvxDO
++JxOeBUebMXoT2B/Z0wI3i60sR/COgQanDTAM6/c8DyAd3HJG7qUCyFvDyVZpTMUY
++wZF7C9UTAJu878NIPkZgIIUq1ZC2zYugzDLdt/1AVbJQHFauzI13TccgTacxdu9o
++koqQHgiBVrKtaaNS0MscxCM9H5n+TOgWY47GCI72MfbS+uV23bUckqNJzc0BzWjN
++qWm6o+sdDZykIKbBoMXRRkwXbdKsZj+WjOCE1Db/IlnF+RFgqF8EffIa9iVCYQ/E
++Srg+iQIDAQABMA0GCSqGSIb3DQEBBQUAA4IBAQA0JhU8wI1NQ0kdvekhktdmnLfe
++xbjQ5F1fdiLAJvmEOjr5jLX77GDx6M4EsMjdpwOPMPOY36TmpDHf0xwLRtxyID+u
++7gU8pDM/CzmscHhzS5kr3zDCVLCoO1Wh/hYozUK9dG6A2ydEp85EXdQbkJgNHkKU
++sQAsBNB0owIFImNjzYO1+8FtYmtpdf1dcEG59b98377BMnMiIYtYgXsVkXq642RI
++sH/7NiXaldDxJBQX3RiAa0YjOVT1jmIJBB2UkKab5iXiQkWquJCtvgiPqQtCGJTP
++cjnhsUPgKM+351psE2tJs//jGHyJizNdrDPXp/naOlXJWBD5qu9ats9LS98q
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/ACCVRAIZ1.pem.orig
++++ secure/caroot/trusted/ACCVRAIZ1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem.orig
++++ secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- /dev/null
++++ secure/caroot/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
+@@ -0,0 +1,69 @@
++##
++## AC RAIZ FNMT-RCM SERVIDORES SEGUROS
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 62:f6:32:6c:e5:c4:e3:68:5c:1b:62:dd:9c:2e:9d:95
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = ES, O = FNMT-RCM, OU = Ceres, organizationIdentifier = VATES-Q2826004J, CN = AC RAIZ FNMT-RCM SERVIDORES SEGUROS
++ Validity
++ Not Before: Dec 20 09:37:33 2018 GMT
++ Not After : Dec 20 09:37:33 2043 GMT
++ Subject: C = ES, O = FNMT-RCM, OU = Ceres, organizationIdentifier = VATES-Q2826004J, CN = AC RAIZ FNMT-RCM SERVIDORES SEGUROS
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:f6:ba:57:53:c8:ca:ab:df:36:4a:52:21:e4:97:
++ d2:83:67:9e:f0:65:51:d0:5e:87:c7:47:b1:59:f2:
++ 57:47:9b:00:02:93:44:17:69:db:42:c7:b1:b2:3a:
++ 18:0e:b4:5d:8c:b3:66:5d:a1:34:f9:36:2c:49:db:
++ f3:46:fc:b3:44:69:44:13:66:fd:d7:c5:fd:af:36:
++ 4d:ce:03:4d:07:71:cf:af:6a:05:d2:a2:43:5a:0a:
++ 52:6f:01:03:4e:8e:8b
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ 01:B9:2F:EF:BF:11:86:60:F2:4F:D0:41:6E:AB:73:1F:E7:D2:6E:49
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:66:02:31:00:ae:4a:e3:2b:40:c3:74:11:f2:95:ad:16:23:
++ de:4e:0c:1a:e6:5d:a5:24:5e:6b:44:7b:fc:38:e2:4f:cb:9c:
++ 45:17:11:4c:14:27:26:55:39:75:4a:03:cc:13:90:9f:92:02:
++ 31:00:fa:4a:6c:60:88:73:f3:ee:b8:98:62:a9:ce:2b:c2:d9:
++ 8a:a6:70:31:1d:af:b0:94:4c:eb:4f:c6:e3:d1:f3:62:a7:3c:
++ ff:93:2e:07:5c:49:01:67:69:12:02:72:bf:e7
++SHA1 Fingerprint=62:FF:D9:9E:C0:65:0D:03:CE:75:93:D2:ED:3F:2D:32:C9:E3:E5:4A
++-----BEGIN CERTIFICATE-----
++MIICbjCCAfOgAwIBAgIQYvYybOXE42hcG2LdnC6dlTAKBggqhkjOPQQDAzB4MQsw
++CQYDVQQGEwJFUzERMA8GA1UECgwIRk5NVC1SQ00xDjAMBgNVBAsMBUNlcmVzMRgw
++FgYDVQRhDA9WQVRFUy1RMjgyNjAwNEoxLDAqBgNVBAMMI0FDIFJBSVogRk5NVC1S
++Q00gU0VSVklET1JFUyBTRUdVUk9TMB4XDTE4MTIyMDA5MzczM1oXDTQzMTIyMDA5
++MzczM1oweDELMAkGA1UEBhMCRVMxETAPBgNVBAoMCEZOTVQtUkNNMQ4wDAYDVQQL
++DAVDZXJlczEYMBYGA1UEYQwPVkFURVMtUTI4MjYwMDRKMSwwKgYDVQQDDCNBQyBS
++QUlaIEZOTVQtUkNNIFNFUlZJRE9SRVMgU0VHVVJPUzB2MBAGByqGSM49AgEGBSuB
++BAAiA2IABPa6V1PIyqvfNkpSIeSX0oNnnvBlUdBeh8dHsVnyV0ebAAKTRBdp20LH
++sbI6GA60XYyzZl2hNPk2LEnb80b8s0RpRBNm/dfF/a82Tc4DTQdxz69qBdKiQ1oK
++Um8BA06Oi6NCMEAwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwHQYD
++VR0OBBYEFAG5L++/EYZg8k/QQW6rcx/n0m5JMAoGCCqGSM49BAMDA2kAMGYCMQCu
++SuMrQMN0EfKVrRYj3k4MGuZdpSRea0R7/DjiT8ucRRcRTBQnJlU5dUoDzBOQn5IC
++MQD6SmxgiHPz7riYYqnOK8LZiqZwMR2vsJRM60/G49HzYqc8/5MuB1xJAWdpEgJy
++v+c=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/trusted/ANF_Secure_Server_Root_CA.pem
+@@ -0,0 +1,139 @@
++##
++## ANF Secure Server Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 996390341000653745 (0xdd3e3bc6cf96bb1)
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: serialNumber = G63287510, C = ES, O = ANF Autoridad de Certificacion, OU = ANF CA Raiz, CN = ANF Secure Server Root CA
++ Validity
++ Not Before: Sep 4 10:00:38 2019 GMT
++ Not After : Aug 30 10:00:38 2039 GMT
++ Subject: serialNumber = G63287510, C = ES, O = ANF Autoridad de Certificacion, OU = ANF CA Raiz, CN = ANF Secure Server Root CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:db:eb:6b:2b:e6:64:54:95:82:90:a3:72:a4:19:
++ 01:9d:9c:0b:81:5f:73:49:ba:a7:ac:f3:04:4e:7b:
++ 96:0b:ec:11:e0:5b:a6:1c:ce:1b:d2:0d:83:1c:2b:
++ b8:9e:1d:7e:45:32:60:0f:07:e9:77:58:7e:9f:6a:
++ c8:61:4e:b6:26:c1:4c:8d:ff:4c:ef:34:b2:1f:65:
++ d8:b9:78:f5:ad:a9:71:b9:ef:4f:58:1d:a5:de:74:
++ 20:97:a1:ed:68:4c:de:92:17:4b:bc:ab:ff:65:9a:
++ 9e:fb:47:d9:57:72:f3:09:a1:ae:76:44:13:6e:9c:
++ 2d:44:39:bc:f9:c7:3b:a4:58:3d:41:bd:b4:c2:49:
++ a3:c8:0d:d2:97:2f:07:65:52:00:a7:6e:c8:af:68:
++ ec:f4:14:96:b6:57:1f:56:c3:39:9f:2b:6d:e4:f3:
++ 3e:f6:35:64:da:0c:1c:a1:84:4b:2f:4b:4b:e2:2c:
++ 24:9d:6d:93:40:eb:b5:23:8e:32:ca:6f:45:d3:a8:
++ 89:7b:1e:cf:1e:fa:5b:43:8b:cd:cd:a8:0f:6a:ca:
++ 0c:5e:b9:9e:47:8f:f0:d9:b6:0a:0b:58:65:17:33:
++ b9:23:e4:77:19:7d:cb:4a:2e:92:7b:4f:2f:10:77:
++ b1:8d:2f:68:9c:62:cc:e0:50:f8:ec:91:a7:54:4c:
++ 57:09:d5:76:63:c5:e8:65:1e:ee:6d:6a:cf:09:9d:
++ fa:7c:4f:ad:60:08:fd:56:99:0f:15:2c:7b:a9:80:
++ ab:8c:61:8f:4a:07:76:42:de:3d:f4:dd:b2:24:33:
++ 5b:b8:b5:a3:44:c9:ac:7f:77:3c:1d:23:ec:82:a9:
++ a6:e2:c8:06:4c:02:fe:ac:5c:99:99:0b:2f:10:8a:
++ a6:f4:7f:d5:87:74:0d:59:49:45:f6:f0:71:5c:39:
++ 29:d6:bf:4a:23:8b:f5:5f:01:63:d2:87:73:28:b5:
++ 4b:0a:f5:f8:ab:82:2c:7e:73:25:32:1d:0b:63:0a:
++ 17:81:00:ff:b6:76:5e:e7:b4:b1:40:ca:21:bb:d5:
++ 80:51:e5:48:52:67:2c:d2:61:89:07:0d:0f:ce:42:
++ 77:c0:44:73:9c:44:50:a0:db:10:0a:2d:95:1c:81:
++ af:e4:1c:e5:14:1e:f1:36:41:01:02:2f:7d:73:a7:
++ de:42:cc:4c:e9:89:0d:56:f7:9f:91:d4:03:c6:6c:
++ c9:8f:db:d8:1c:e0:40:98:5d:66:99:98:80:6e:2d:
++ ff:01:c5:ce:cb:46:1f:ac:02:c6:43:e6:ae:a2:84:
++ 3c:c5:4e:1e:3d:6d:c9:14:4c:e3:2e:41:bb:ca:39:
++ bf:36:3c:2a:19:aa:41:87:4e:a5:ce:4b:32:79:dd:
++ 90:49:7f
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Authority Key Identifier:
++ keyid:9C:5F:D0:6C:63:A3:5F:93:CA:93:98:08:AD:8C:87:A5:2C:5C:C1:37
++
++ X509v3 Subject Key Identifier:
++ 9C:5F:D0:6C:63:A3:5F:93:CA:93:98:08:AD:8C:87:A5:2C:5C:C1:37
++ X509v3 Key Usage: critical
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ Signature Algorithm: sha256WithRSAEncryption
++ 4e:1e:b9:8a:c6:a0:98:3f:6e:c3:69:c0:6a:5c:49:52:ac:cb:
++ 2b:5d:78:38:c1:d5:54:84:9f:93:f0:87:19:3d:2c:66:89:eb:
++ 0d:42:fc:cc:f0:75:85:3f:8b:f4:80:5d:79:e5:17:67:bd:35:
++ 82:e2:f2:3c:8e:7d:5b:36:cb:5a:80:00:29:f2:ce:2b:2c:f1:
++ 8f:aa:6d:05:93:6c:72:c7:56:eb:df:50:23:28:e5:45:10:3d:
++ e8:67:a3:af:0e:55:0f:90:09:62:ef:4b:59:a2:f6:53:f1:c0:
++ 35:e4:2f:c1:24:bd:79:2f:4e:20:22:3b:fd:1a:20:b0:a4:0e:
++ 2c:70:ed:74:3f:b8:13:95:06:51:c8:e8:87:26:ca:a4:5b:6a:
++ 16:21:92:dd:73:60:9e:10:18:de:3c:81:ea:e8:18:c3:7c:89:
++ f2:8b:50:3e:bd:11:e2:15:03:a8:36:7d:33:01:6c:48:15:d7:
++ 88:90:99:04:c5:cc:e6:07:f4:bc:f4:90:ed:13:e2:ea:8b:c3:
++ 8f:a3:33:0f:c1:29:4c:13:4e:da:15:56:71:73:72:82:50:f6:
++ 9a:33:7c:a2:b1:a8:1a:34:74:65:5c:ce:d1:eb:ab:53:e0:1a:
++ 80:d8:ea:3a:49:e4:26:30:9b:e5:1c:8a:a8:a9:15:32:86:99:
++ 92:0a:10:23:56:12:e0:f6:ce:4c:e2:bb:be:db:8d:92:73:01:
++ 66:2f:62:3e:b2:72:27:45:36:ed:4d:56:e3:97:99:ff:3a:35:
++ 3e:a5:54:4a:52:59:4b:60:db:ee:fe:78:11:7f:4a:dc:14:79:
++ 60:b6:6b:64:03:db:15:83:e1:a2:be:f6:23:97:50:f0:09:33:
++ 36:a7:71:96:25:f3:b9:42:7d:db:38:3f:2c:58:ac:e8:42:e1:
++ 0e:d8:d3:3b:4c:2e:82:e9:83:2e:6b:31:d9:dd:47:86:4f:6d:
++ 97:91:2e:4f:e2:28:71:35:16:d1:f2:73:fe:25:2b:07:47:24:
++ 63:27:c8:f8:f6:d9:6b:fc:12:31:56:08:c0:53:42:af:9c:d0:
++ 33:7e:fc:06:f0:31:44:03:14:f1:58:ea:f2:6a:0d:a9:11:b2:
++ 83:be:c5:1a:bf:07:ea:59:dc:a3:88:35:ef:9c:76:32:3c:4d:
++ 06:22:ce:15:e5:dd:9e:d8:8f:da:de:d2:c4:39:e5:17:81:cf:
++ 38:47:eb:7f:88:6d:59:1b:df:9f:42:14:ae:7e:cf:a8:b0:66:
++ 65:da:37:af:9f:aa:3d:ea:28:b6:de:d5:31:58:16:82:5b:ea:
++ bb:19:75:02:73:1a:ca:48:1a:21:93:90:0a:8e:93:84:a7:7d:
++ 3b:23:18:92:89:a0:8d:ac
++SHA1 Fingerprint=5B:6E:68:D0:CC:15:B6:A0:5F:1E:C1:5F:AE:02:FC:6B:2F:5D:6F:74
++-----BEGIN CERTIFICATE-----
++MIIF7zCCA9egAwIBAgIIDdPjvGz5a7EwDQYJKoZIhvcNAQELBQAwgYQxEjAQBgNV
++BAUTCUc2MzI4NzUxMDELMAkGA1UEBhMCRVMxJzAlBgNVBAoTHkFORiBBdXRvcmlk
++YWQgZGUgQ2VydGlmaWNhY2lvbjEUMBIGA1UECxMLQU5GIENBIFJhaXoxIjAgBgNV
++BAMTGUFORiBTZWN1cmUgU2VydmVyIFJvb3QgQ0EwHhcNMTkwOTA0MTAwMDM4WhcN
++MzkwODMwMTAwMDM4WjCBhDESMBAGA1UEBRMJRzYzMjg3NTEwMQswCQYDVQQGEwJF
++UzEnMCUGA1UEChMeQU5GIEF1dG9yaWRhZCBkZSBDZXJ0aWZpY2FjaW9uMRQwEgYD
++VQQLEwtBTkYgQ0EgUmFpejEiMCAGA1UEAxMZQU5GIFNlY3VyZSBTZXJ2ZXIgUm9v
++dCBDQTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANvrayvmZFSVgpCj
++cqQZAZ2cC4Ffc0m6p6zzBE57lgvsEeBbphzOG9INgxwruJ4dfkUyYA8H6XdYfp9q
++yGFOtibBTI3/TO80sh9l2Ll49a2pcbnvT1gdpd50IJeh7WhM3pIXS7yr/2WanvtH
++2Vdy8wmhrnZEE26cLUQ5vPnHO6RYPUG9tMJJo8gN0pcvB2VSAKduyK9o7PQUlrZX
++H1bDOZ8rbeTzPvY1ZNoMHKGESy9LS+IsJJ1tk0DrtSOOMspvRdOoiXsezx76W0OL
++zc2oD2rKDF65nkeP8Nm2CgtYZRczuSPkdxl9y0oukntPLxB3sY0vaJxizOBQ+OyR
++p1RMVwnVdmPF6GUe7m1qzwmd+nxPrWAI/VaZDxUse6mAq4xhj0oHdkLePfTdsiQz
++W7i1o0TJrH93PB0j7IKppuLIBkwC/qxcmZkLLxCKpvR/1Yd0DVlJRfbwcVw5Kda/
++SiOL9V8BY9KHcyi1Swr1+KuCLH5zJTIdC2MKF4EA/7Z2Xue0sUDKIbvVgFHlSFJn
++LNJhiQcND85Cd8BEc5xEUKDbEAotlRyBr+Qc5RQe8TZBAQIvfXOn3kLMTOmJDVb3
++n5HUA8ZsyY/b2BzgQJhdZpmYgG4t/wHFzstGH6wCxkPmrqKEPMVOHj1tyRRM4y5B
++u8o5vzY8KhmqQYdOpc5LMnndkEl/AgMBAAGjYzBhMB8GA1UdIwQYMBaAFJxf0Gxj
++o1+TypOYCK2Mh6UsXME3MB0GA1UdDgQWBBScX9BsY6Nfk8qTmAitjIelLFzBNzAO
++BgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOC
++AgEATh65isagmD9uw2nAalxJUqzLK114OMHVVISfk/CHGT0sZonrDUL8zPB1hT+L
++9IBdeeUXZ701guLyPI59WzbLWoAAKfLOKyzxj6ptBZNscsdW699QIyjlRRA96Gej
++rw5VD5AJYu9LWaL2U/HANeQvwSS9eS9OICI7/RogsKQOLHDtdD+4E5UGUcjohybK
++pFtqFiGS3XNgnhAY3jyB6ugYw3yJ8otQPr0R4hUDqDZ9MwFsSBXXiJCZBMXM5gf0
++vPSQ7RPi6ovDj6MzD8EpTBNO2hVWcXNyglD2mjN8orGoGjR0ZVzO0eurU+AagNjq
++OknkJjCb5RyKqKkVMoaZkgoQI1YS4PbOTOK7vtuNknMBZi9iPrJyJ0U27U1W45eZ
++/zo1PqVUSlJZS2Db7v54EX9K3BR5YLZrZAPbFYPhor72I5dQ8AkzNqdxliXzuUJ9
++2zg/LFis6ELhDtjTO0wugumDLmsx2d1Hhk9tl5EuT+IocTUW0fJz/iUrB0ckYyfI
+++PbZa/wSMVYIwFNCr5zQM378BvAxRAMU8Vjq8moNqRGyg77FGr8H6lnco4g175x2
++MjxNBiLOFeXdntiP2t7SxDnlF4HPOEfrf4htWRvfn0IUrn7PqLBmZdo3r5+qPeoo
++tt7VMVgWglvquxl1AnMaykgaIZOQCo6ThKd9OyMYkomgjaw=
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Actalis_Authentication_Root_CA.pem.orig
++++ secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/AffirmTrust_Commercial.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Commercial.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/AffirmTrust_Networking.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Networking.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/AffirmTrust_Premium.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Premium.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/AffirmTrust_Premium_ECC.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_1.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_2.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_3.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_4.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_4.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Atos_TrustedRoot_2011.pem.orig
++++ secure/caroot/trusted/Atos_TrustedRoot_2011.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem.orig
++++ secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Baltimore_CyberTrust_Root.pem.orig
++++ secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Buypass_Class_2_Root_CA.pem.orig
++++ secure/caroot/trusted/Buypass_Class_2_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Buypass_Class_3_Root_CA.pem.orig
++++ secure/caroot/trusted/Buypass_Class_3_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/CA_Disig_Root_R2.pem.orig
++++ secure/caroot/trusted/CA_Disig_Root_R2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/CFCA_EV_ROOT.pem.orig
++++ secure/caroot/trusted/CFCA_EV_ROOT.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/COMODO_Certification_Authority.pem.orig
++++ secure/caroot/trusted/COMODO_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem.orig
++++ secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem.orig
++++ secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem.orig
++++ secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
+@@ -1,112 +0,0 @@
+-##
+-## Camerfirma Chambers of Commerce Root
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 0 (0x0)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
+- Validity
+- Not Before: Sep 30 16:13:43 2003 GMT
+- Not After : Sep 30 16:13:44 2037 GMT
+- Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:b7:36:55:e5:a5:5d:18:30:e0:da:89:54:91:fc:
+- c8:c7:52:f8:2f:50:d9:ef:b1:75:73:65:47:7d:1b:
+- 5b:ba:75:c5:fc:a1:88:24:fa:2f:ed:ca:08:4a:39:
+- 54:c4:51:7a:b5:da:60:ea:38:3c:81:b2:cb:f1:bb:
+- d9:91:23:3f:48:01:70:75:a9:05:2a:ad:1f:71:f3:
+- c9:54:3d:1d:06:6a:40:3e:b3:0c:85:ee:5c:1b:79:
+- c2:62:c4:b8:36:8e:35:5d:01:0c:23:04:47:35:aa:
+- 9b:60:4e:a0:66:3d:cb:26:0a:9c:40:a1:f4:5d:98:
+- bf:71:ab:a5:00:68:2a:ed:83:7a:0f:a2:14:b5:d4:
+- 22:b3:80:b0:3c:0c:5a:51:69:2d:58:18:8f:ed:99:
+- 9e:f1:ae:e2:95:e6:f6:47:a8:d6:0c:0f:b0:58:58:
+- db:c3:66:37:9e:9b:91:54:33:37:d2:94:1c:6a:48:
+- c9:c9:f2:a5:da:a5:0c:23:f7:23:0e:9c:32:55:5e:
+- 71:9c:84:05:51:9a:2d:fd:e6:4e:2a:34:5a:de:ca:
+- 40:37:67:0c:54:21:55:77:da:0a:0c:cc:97:ae:80:
+- dc:94:36:4a:f4:3e:ce:36:13:1e:53:e4:ac:4e:3a:
+- 05:ec:db:ae:72:9c:38:8b:d0:39:3b:89:0a:3e:77:
+- fe:75
+- Exponent: 3 (0x3)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 CRL Distribution Points:
+-
+- Full Name:
+- URI:http://crl.chambersign.org/chambersroot.crl
+-
+- X509v3 Subject Key Identifier:
+- E3:94:F5:B1:4D:E9:DB:A1:29:5B:57:8B:4D:76:06:76:E1:D1:A2:8A
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- Netscape Cert Type:
+- SSL CA, S/MIME CA, Object Signing CA
+- X509v3 Subject Alternative Name:
+- email:chambersroot@chambersign.org
+- X509v3 Issuer Alternative Name:
+- email:chambersroot@chambersign.org
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.17326.10.3.1
+- CPS: http://cps.chambersign.org/cps/chambersroot.html
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 0c:41:97:c2:1a:86:c0:22:7c:9f:fb:90:f3:1a:d1:03:b1:ef:
+- 13:f9:21:5f:04:9c:da:c9:a5:8d:27:6c:96:87:91:be:41:90:
+- 01:72:93:e7:1e:7d:5f:f6:89:c6:5d:a7:40:09:3d:ac:49:45:
+- 45:dc:2e:8d:30:68:b2:09:ba:fb:c3:2f:cc:ba:0b:df:3f:77:
+- 7b:46:7d:3a:12:24:8e:96:8f:3c:05:0a:6f:d2:94:28:1d:6d:
+- 0c:c0:2e:88:22:d5:d8:cf:1d:13:c7:f0:48:d7:d7:05:a7:cf:
+- c7:47:9e:3b:3c:34:c8:80:4f:d4:14:bb:fc:0d:50:f7:fa:b3:
+- ec:42:5f:a9:dd:6d:c8:f4:75:cf:7b:c1:72:26:b1:01:1c:5c:
+- 2c:fd:7a:4e:b4:01:c5:05:57:b9:e7:3c:aa:05:d9:88:e9:07:
+- 46:41:ce:ef:41:81:ae:58:df:83:a2:ae:ca:d7:77:1f:e7:00:
+- 3c:9d:6f:8e:e4:32:09:1d:4d:78:34:78:34:3c:94:9b:26:ed:
+- 4f:71:c6:19:7a:bd:20:22:48:5a:fe:4b:7d:03:b7:e7:58:be:
+- c6:32:4e:74:1e:68:dd:a8:68:5b:b3:3e:ee:62:7d:d9:80:e8:
+- 0a:75:7a:b7:ee:b4:65:9a:21:90:e0:aa:d0:98:bc:38:b5:73:
+- 3c:8b:f8:dc
+-SHA1 Fingerprint=6E:3A:55:A4:19:0C:19:5C:93:84:3C:C0:DB:72:2E:31:30:61:F0:B1
+------BEGIN CERTIFICATE-----
+-MIIEvTCCA6WgAwIBAgIBADANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJFVTEn
+-MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
+-ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEiMCAGA1UEAxMZQ2hhbWJlcnMg
+-b2YgQ29tbWVyY2UgUm9vdDAeFw0wMzA5MzAxNjEzNDNaFw0zNzA5MzAxNjEzNDRa
+-MH8xCzAJBgNVBAYTAkVVMScwJQYDVQQKEx5BQyBDYW1lcmZpcm1hIFNBIENJRiBB
+-ODI3NDMyODcxIzAhBgNVBAsTGmh0dHA6Ly93d3cuY2hhbWJlcnNpZ24ub3JnMSIw
+-IAYDVQQDExlDaGFtYmVycyBvZiBDb21tZXJjZSBSb290MIIBIDANBgkqhkiG9w0B
+-AQEFAAOCAQ0AMIIBCAKCAQEAtzZV5aVdGDDg2olUkfzIx1L4L1DZ77F1c2VHfRtb
+-unXF/KGIJPov7coISjlUxFF6tdpg6jg8gbLL8bvZkSM/SAFwdakFKq0fcfPJVD0d
+-BmpAPrMMhe5cG3nCYsS4No41XQEMIwRHNaqbYE6gZj3LJgqcQKH0XZi/caulAGgq
+-7YN6D6IUtdQis4CwPAxaUWktWBiP7Zme8a7ileb2R6jWDA+wWFjbw2Y3npuRVDM3
+-0pQcakjJyfKl2qUMI/cjDpwyVV5xnIQFUZot/eZOKjRa3spAN2cMVCFVd9oKDMyX
+-roDclDZK9D7ONhMeU+SsTjoF7Nuucpw4i9A5O4kKPnf+dQIBA6OCAUQwggFAMBIG
+-A1UdEwEB/wQIMAYBAf8CAQwwPAYDVR0fBDUwMzAxoC+gLYYraHR0cDovL2NybC5j
+-aGFtYmVyc2lnbi5vcmcvY2hhbWJlcnNyb290LmNybDAdBgNVHQ4EFgQU45T1sU3p
+-26EpW1eLTXYGduHRooowDgYDVR0PAQH/BAQDAgEGMBEGCWCGSAGG+EIBAQQEAwIA
+-BzAnBgNVHREEIDAegRxjaGFtYmVyc3Jvb3RAY2hhbWJlcnNpZ24ub3JnMCcGA1Ud
+-EgQgMB6BHGNoYW1iZXJzcm9vdEBjaGFtYmVyc2lnbi5vcmcwWAYDVR0gBFEwTzBN
+-BgsrBgEEAYGHLgoDATA+MDwGCCsGAQUFBwIBFjBodHRwOi8vY3BzLmNoYW1iZXJz
+-aWduLm9yZy9jcHMvY2hhbWJlcnNyb290Lmh0bWwwDQYJKoZIhvcNAQEFBQADggEB
+-AAxBl8IahsAifJ/7kPMa0QOx7xP5IV8EnNrJpY0nbJaHkb5BkAFyk+cefV/2icZd
+-p0AJPaxJRUXcLo0waLIJuvvDL8y6C98/d3tGfToSJI6WjzwFCm/SlCgdbQzALogi
+-1djPHRPH8EjX1wWnz8dHnjs8NMiAT9QUu/wNUPf6s+xCX6ndbcj0dc97wXImsQEc
+-XCz9ek60AcUFV7nnPKoF2YjpB0ZBzu9Bga5Y34OirsrXdx/nADydb47kMgkdTXg0
+-eDQ8lJsm7U9xxhl6vSAiSFr+S30Dt+dYvsYyTnQeaN2oaFuzPu5ifdmA6Ap1erfu
+-tGWaIZDgqtCYvDi1czyL+Nw=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem.orig
++++ secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem
+@@ -1,112 +0,0 @@
+-##
+-## Camerfirma Global Chambersign Root
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 0 (0x0)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
+- Validity
+- Not Before: Sep 30 16:14:18 2003 GMT
+- Not After : Sep 30 16:14:18 2037 GMT
+- Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:a2:70:a2:d0:9f:42:ae:5b:17:c7:d8:7d:cf:14:
+- 83:fc:4f:c9:a1:b7:13:af:8a:d7:9e:3e:04:0a:92:
+- 8b:60:56:fa:b4:32:2f:88:4d:a1:60:08:f4:b7:09:
+- 4e:a0:49:2f:49:d6:d3:df:9d:97:5a:9f:94:04:70:
+- ec:3f:59:d9:b7:cc:66:8b:98:52:28:09:02:df:c5:
+- 2f:84:8d:7a:97:77:bf:ec:40:9d:25:72:ab:b5:3f:
+- 32:98:fb:b7:b7:fc:72:84:e5:35:87:f9:55:fa:a3:
+- 1f:0e:6f:2e:28:dd:69:a0:d9:42:10:c6:f8:b5:44:
+- c2:d0:43:7f:db:bc:e4:a2:3c:6a:55:78:0a:77:a9:
+- d8:ea:19:32:b7:2f:fe:5c:3f:1b:ee:b1:98:ec:ca:
+- ad:7a:69:45:e3:96:0f:55:f6:e6:ed:75:ea:65:e8:
+- 32:56:93:46:89:a8:25:8a:65:06:ee:6b:bf:79:07:
+- d0:f1:b7:af:ed:2c:4d:92:bb:c0:a8:5f:a7:67:7d:
+- 04:f2:15:08:70:ac:92:d6:7d:04:d2:33:fb:4c:b6:
+- 0b:0b:fb:1a:c9:c4:8d:03:a9:7e:5c:f2:50:ab:12:
+- a5:a1:cf:48:50:a5:ef:d2:c8:1a:13:fa:b0:7f:b1:
+- 82:1c:77:6a:0f:5f:dc:0b:95:8f:ef:43:7e:e6:45:
+- 09:25
+- Exponent: 3 (0x3)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 CRL Distribution Points:
+-
+- Full Name:
+- URI:http://crl.chambersign.org/chambersignroot.crl
+-
+- X509v3 Subject Key Identifier:
+- 43:9C:36:9F:B0:9E:30:4D:C6:CE:5F:AD:10:AB:E5:03:A5:FA:A9:14
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- Netscape Cert Type:
+- SSL CA, S/MIME CA, Object Signing CA
+- X509v3 Subject Alternative Name:
+- email:chambersignroot@chambersign.org
+- X509v3 Issuer Alternative Name:
+- email:chambersignroot@chambersign.org
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.17326.10.1.1
+- CPS: http://cps.chambersign.org/cps/chambersignroot.html
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 3c:3b:70:91:f9:04:54:27:91:e1:ed:ed:fe:68:7f:61:5d:e5:
+- 41:65:4f:32:f1:18:05:94:6a:1c:de:1f:70:db:3e:7b:32:02:
+- 34:b5:0c:6c:a1:8a:7c:a5:f4:8f:ff:d4:d8:ad:17:d5:2d:04:
+- d1:3f:58:80:e2:81:59:88:be:c0:e3:46:93:24:fe:90:bd:26:
+- a2:30:2d:e8:97:26:57:35:89:74:96:18:f6:15:e2:af:24:19:
+- 56:02:02:b2:ba:0f:14:ea:c6:8a:66:c1:86:45:55:8b:be:92:
+- be:9c:a4:04:c7:49:3c:9e:e8:29:7a:89:d7:fe:af:ff:68:f5:
+- a5:17:90:bd:ac:99:cc:a5:86:57:09:67:46:db:d6:16:c2:46:
+- f1:e4:a9:50:f5:8f:d1:92:15:d3:5f:3e:c6:00:49:3a:6e:58:
+- b2:d1:d1:27:0d:25:c8:32:f8:20:11:cd:7d:32:33:48:94:54:
+- 4c:dd:dc:79:c4:30:9f:eb:8e:b8:55:b5:d7:88:5c:c5:6a:24:
+- 3d:b2:d3:05:03:51:c6:07:ef:cc:14:72:74:3d:6e:72:ce:18:
+- 28:8c:4a:a0:77:e5:09:2b:45:44:47:ac:b7:67:7f:01:8a:05:
+- 5a:93:be:a1:c1:ff:f8:e7:0e:67:a4:47:49:76:5d:75:90:1a:
+- f5:26:8f:f0
+-SHA1 Fingerprint=33:9B:6B:14:50:24:9B:55:7A:01:87:72:84:D9:E0:2F:C3:D2:D8:E9
+------BEGIN CERTIFICATE-----
+-MIIExTCCA62gAwIBAgIBADANBgkqhkiG9w0BAQUFADB9MQswCQYDVQQGEwJFVTEn
+-MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
+-ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4GA1UEAxMXR2xvYmFsIENo
+-YW1iZXJzaWduIFJvb3QwHhcNMDMwOTMwMTYxNDE4WhcNMzcwOTMwMTYxNDE4WjB9
+-MQswCQYDVQQGEwJFVTEnMCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgy
+-NzQzMjg3MSMwIQYDVQQLExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4G
+-A1UEAxMXR2xvYmFsIENoYW1iZXJzaWduIFJvb3QwggEgMA0GCSqGSIb3DQEBAQUA
+-A4IBDQAwggEIAoIBAQCicKLQn0KuWxfH2H3PFIP8T8mhtxOviteePgQKkotgVvq0
+-Mi+ITaFgCPS3CU6gSS9J1tPfnZdan5QEcOw/Wdm3zGaLmFIoCQLfxS+EjXqXd7/s
+-QJ0lcqu1PzKY+7e3/HKE5TWH+VX6ox8Oby4o3Wmg2UIQxvi1RMLQQ3/bvOSiPGpV
+-eAp3qdjqGTK3L/5cPxvusZjsyq16aUXjlg9V9ubtdepl6DJWk0aJqCWKZQbua795
+-B9Dxt6/tLE2Su8CoX6dnfQTyFQhwrJLWfQTSM/tMtgsL+xrJxI0DqX5c8lCrEqWh
+-z0hQpe/SyBoT+rB/sYIcd2oPX9wLlY/vQ37mRQklAgEDo4IBUDCCAUwwEgYDVR0T
+-AQH/BAgwBgEB/wIBDDA/BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vY3JsLmNoYW1i
+-ZXJzaWduLm9yZy9jaGFtYmVyc2lnbnJvb3QuY3JsMB0GA1UdDgQWBBRDnDafsJ4w
+-TcbOX60Qq+UDpfqpFDAOBgNVHQ8BAf8EBAMCAQYwEQYJYIZIAYb4QgEBBAQDAgAH
+-MCoGA1UdEQQjMCGBH2NoYW1iZXJzaWducm9vdEBjaGFtYmVyc2lnbi5vcmcwKgYD
+-VR0SBCMwIYEfY2hhbWJlcnNpZ25yb290QGNoYW1iZXJzaWduLm9yZzBbBgNVHSAE
+-VDBSMFAGCysGAQQBgYcuCgEBMEEwPwYIKwYBBQUHAgEWM2h0dHA6Ly9jcHMuY2hh
+-bWJlcnNpZ24ub3JnL2Nwcy9jaGFtYmVyc2lnbnJvb3QuaHRtbDANBgkqhkiG9w0B
+-AQUFAAOCAQEAPDtwkfkEVCeR4e3t/mh/YV3lQWVPMvEYBZRqHN4fcNs+ezICNLUM
+-bKGKfKX0j//U2K0X1S0E0T9YgOKBWYi+wONGkyT+kL0mojAt6JcmVzWJdJYY9hXi
+-ryQZVgICsroPFOrGimbBhkVVi76SvpykBMdJPJ7oKXqJ1/6v/2j1pReQvayZzKWG
+-VwlnRtvWFsJG8eSpUPWP0ZIV018+xgBJOm5YstHRJw0lyDL4IBHNfTIzSJRUTN3c
+-ecQwn+uOuFW114hcxWokPbLTBQNRxgfvzBRydD1ucs4YKIxKoHflCStFREest2d/
+-AYoFWpO+ocH/+OcOZ6RHSXZddZAa9SaP8A==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Certigna.pem.orig
++++ secure/caroot/trusted/Certigna.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Certigna_Root_CA.pem.orig
++++ secure/caroot/trusted/Certigna_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- /dev/null
++++ secure/caroot/trusted/Certum_EC-384_CA.pem
+@@ -0,0 +1,68 @@
++##
++## Certum EC-384 CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 78:8f:27:5c:81:12:52:20:a5:04:d0:2d:dd:ba:73:f4
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum EC-384 CA
++ Validity
++ Not Before: Mar 26 07:24:54 2018 GMT
++ Not After : Mar 26 07:24:54 2043 GMT
++ Subject: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum EC-384 CA
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:c4:28:8e:ab:18:5b:6a:be:6e:64:37:63:e4:cd:
++ ec:ab:3a:f7:cc:a1:b8:0e:82:49:d7:86:29:9f:a1:
++ 94:f2:e3:60:78:98:81:78:06:4d:f2:ec:9a:0e:57:
++ 60:83:9f:b4:e6:17:2f:1a:b3:5d:02:5b:89:23:3c:
++ c2:11:05:2a:a7:88:13:18:f3:50:84:d7:bd:34:2c:
++ 27:89:55:ff:ce:4c:e7:df:a6:1f:28:c4:f0:54:c3:
++ b9:7c:b7:53:ad:eb:c2
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 8D:06:66:74:24:76:3A:F3:89:F7:BC:D6:BD:47:7D:2F:BC:10:5F:4B
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:65:02:30:03:55:2d:a6:e6:18:c4:7c:ef:c9:50:6e:c1:27:
++ 0f:9c:87:af:6e:d5:1b:08:18:bd:92:29:c1:ef:94:91:78:d2:
++ 3a:1c:55:89:62:e5:1b:09:1e:ba:64:6b:f1:76:b4:d4:02:31:
++ 00:b4:42:84:99:ff:ab:e7:9e:fb:91:97:27:5d:dc:b0:5b:30:
++ 71:ce:5e:38:1a:6a:d9:25:e7:ea:f7:61:92:56:f8:ea:da:36:
++ c2:87:65:96:2e:72:25:2f:7f:df:c3:13:c9
++SHA1 Fingerprint=F3:3E:78:3C:AC:DF:F4:A2:CC:AC:67:55:69:56:D7:E5:16:3C:E1:ED
++-----BEGIN CERTIFICATE-----
++MIICZTCCAeugAwIBAgIQeI8nXIESUiClBNAt3bpz9DAKBggqhkjOPQQDAzB0MQsw
++CQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEgU3lzdGVtcyBTLkEuMScw
++JQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxGTAXBgNVBAMT
++EENlcnR1bSBFQy0zODQgQ0EwHhcNMTgwMzI2MDcyNDU0WhcNNDMwMzI2MDcyNDU0
++WjB0MQswCQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEgU3lzdGVtcyBT
++LkEuMScwJQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxGTAX
++BgNVBAMTEENlcnR1bSBFQy0zODQgQ0EwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAATE
++KI6rGFtqvm5kN2PkzeyrOvfMobgOgknXhimfoZTy42B4mIF4Bk3y7JoOV2CDn7Tm
++Fy8as10CW4kjPMIRBSqniBMY81CE1700LCeJVf/OTOffph8oxPBUw7l8t1Ot68Kj
++QjBAMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFI0GZnQkdjrzife81r1HfS+8
++EF9LMA4GA1UdDwEB/wQEAwIBBjAKBggqhkjOPQQDAwNoADBlAjADVS2m5hjEfO/J
++UG7BJw+ch69u1RsIGL2SKcHvlJF40jocVYli5RsJHrpka/F2tNQCMQC0QoSZ/6vn
++nvuRlydd3LBbMHHOXjgaatkl5+r3YZJW+OraNsKHZZYuciUvf9/DE8k=
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Certum_Root_CA.pem.orig
++++ secure/caroot/trusted/Certum_Root_CA.pem
+@@ -1,84 +0,0 @@
+-##
+-## Certum Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 65568 (0x10020)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
+- Validity
+- Not Before: Jun 11 10:46:39 2002 GMT
+- Not After : Jun 11 10:46:39 2027 GMT
+- Subject: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:ce:b1:c1:2e:d3:4f:7c:cd:25:ce:18:3e:4f:c4:
+- 8c:6f:80:6a:73:c8:5b:51:f8:9b:d2:dc:bb:00:5c:
+- b1:a0:fc:75:03:ee:81:f0:88:ee:23:52:e9:e6:15:
+- 33:8d:ac:2d:09:c5:76:f9:2b:39:80:89:e4:97:4b:
+- 90:a5:a8:78:f8:73:43:7b:a4:61:b0:d8:58:cc:e1:
+- 6c:66:7e:9c:f3:09:5e:55:63:84:d5:a8:ef:f3:b1:
+- 2e:30:68:b3:c4:3c:d8:ac:6e:8d:99:5a:90:4e:34:
+- dc:36:9a:8f:81:88:50:b7:6d:96:42:09:f3:d7:95:
+- 83:0d:41:4b:b0:6a:6b:f8:fc:0f:7e:62:9f:67:c4:
+- ed:26:5f:10:26:0f:08:4f:f0:a4:57:28:ce:8f:b8:
+- ed:45:f6:6e:ee:25:5d:aa:6e:39:be:e4:93:2f:d9:
+- 47:a0:72:eb:fa:a6:5b:af:ca:53:3f:e2:0e:c6:96:
+- 56:11:6e:f7:e9:66:a9:26:d8:7f:95:53:ed:0a:85:
+- 88:ba:4f:29:a5:42:8c:5e:b6:fc:85:20:00:aa:68:
+- 0b:a1:1a:85:01:9c:c4:46:63:82:88:b6:22:b1:ee:
+- fe:aa:46:59:7e:cf:35:2c:d5:b6:da:5d:f7:48:33:
+- 14:54:b6:eb:d9:6f:ce:cd:88:d6:ab:1b:da:96:3b:
+- 1d:59
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- Signature Algorithm: sha1WithRSAEncryption
+- b8:8d:ce:ef:e7:14:ba:cf:ee:b0:44:92:6c:b4:39:3e:a2:84:
+- 6e:ad:b8:21:77:d2:d4:77:82:87:e6:20:41:81:ee:e2:f8:11:
+- b7:63:d1:17:37:be:19:76:24:1c:04:1a:4c:eb:3d:aa:67:6f:
+- 2d:d4:cd:fe:65:31:70:c5:1b:a6:02:0a:ba:60:7b:6d:58:c2:
+- 9a:49:fe:63:32:0b:6b:e3:3a:c0:ac:ab:3b:b0:e8:d3:09:51:
+- 8c:10:83:c6:34:e0:c5:2b:e0:1a:b6:60:14:27:6c:32:77:8c:
+- bc:b2:72:98:cf:cd:cc:3f:b9:c8:24:42:14:d6:57:fc:e6:26:
+- 43:a9:1d:e5:80:90:ce:03:54:28:3e:f7:3f:d3:f8:4d:ed:6a:
+- 0a:3a:93:13:9b:3b:14:23:13:63:9c:3f:d1:87:27:79:e5:4c:
+- 51:e3:01:ad:85:5d:1a:3b:b1:d5:73:10:a4:d3:f2:bc:6e:64:
+- f5:5a:56:90:a8:c7:0e:4c:74:0f:2e:71:3b:f7:c8:47:f4:69:
+- 6f:15:f2:11:5e:83:1e:9c:7c:52:ae:fd:02:da:12:a8:59:67:
+- 18:db:bc:70:dd:9b:b1:69:ed:80:ce:89:40:48:6a:0e:35:ca:
+- 29:66:15:21:94:2c:e8:60:2a:9b:85:4a:40:f3:6b:8a:24:ec:
+- 06:16:2c:73
+-SHA1 Fingerprint=62:52:DC:40:F7:11:43:A2:2F:DE:9E:F7:34:8E:06:42:51:B1:81:18
+------BEGIN CERTIFICATE-----
+-MIIDDDCCAfSgAwIBAgIDAQAgMA0GCSqGSIb3DQEBBQUAMD4xCzAJBgNVBAYTAlBM
+-MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
+-QTAeFw0wMjA2MTExMDQ2MzlaFw0yNzA2MTExMDQ2MzlaMD4xCzAJBgNVBAYTAlBM
+-MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
+-QTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM6xwS7TT3zNJc4YPk/E
+-jG+AanPIW1H4m9LcuwBcsaD8dQPugfCI7iNS6eYVM42sLQnFdvkrOYCJ5JdLkKWo
+-ePhzQ3ukYbDYWMzhbGZ+nPMJXlVjhNWo7/OxLjBos8Q82KxujZlakE403Daaj4GI
+-ULdtlkIJ89eVgw1BS7Bqa/j8D35in2fE7SZfECYPCE/wpFcozo+47UX2bu4lXapu
+-Ob7kky/ZR6By6/qmW6/KUz/iDsaWVhFu9+lmqSbYf5VT7QqFiLpPKaVCjF62/IUg
+-AKpoC6EahQGcxEZjgoi2IrHu/qpGWX7PNSzVttpd90gzFFS269lvzs2I1qsb2pY7
+-HVkCAwEAAaMTMBEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEA
+-uI3O7+cUus/usESSbLQ5PqKEbq24IXfS1HeCh+YgQYHu4vgRt2PRFze+GXYkHAQa
+-TOs9qmdvLdTN/mUxcMUbpgIKumB7bVjCmkn+YzILa+M6wKyrO7Do0wlRjBCDxjTg
+-xSvgGrZgFCdsMneMvLJymM/NzD+5yCRCFNZX/OYmQ6kd5YCQzgNUKD73P9P4Te1q
+-CjqTE5s7FCMTY5w/0YcneeVMUeMBrYVdGjux1XMQpNPyvG5k9VpWkKjHDkx0Dy5x
+-O/fIR/RpbxXyEV6DHpx8Uq79AtoSqFlnGNu8cN2bsWntgM6JQEhqDjXKKWYVIZQs
+-6GAqm4VKQPNriiTsBhYscw==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Certum_Trusted_Network_CA.pem.orig
++++ secure/caroot/trusted/Certum_Trusted_Network_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem.orig
++++ secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- /dev/null
++++ secure/caroot/trusted/Certum_Trusted_Root_CA.pem
+@@ -0,0 +1,136 @@
++##
++## Certum Trusted Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 1e:bf:59:50:b8:c9:80:37:4c:06:f7:eb:55:4f:b5:ed
++ Signature Algorithm: sha512WithRSAEncryption
++ Issuer: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum Trusted Root CA
++ Validity
++ Not Before: Mar 16 12:10:13 2018 GMT
++ Not After : Mar 16 12:10:13 2043 GMT
++ Subject: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum Trusted Root CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:d1:2d:8e:bb:b7:36:ea:6d:37:91:9f:4e:93:a7:
++ 05:e4:29:03:25:ce:1c:82:f7:7c:99:9f:41:06:cd:
++ ed:a3:ba:c0:db:09:2c:c1:7c:df:29:7e:4b:65:2f:
++ 93:a7:d4:01:6b:03:28:18:a3:d8:9d:05:c1:2a:d8:
++ 45:f1:91:de:df:3b:d0:80:02:8c:cf:38:0f:ea:a7:
++ 5c:78:11:a4:c1:c8:85:5c:25:d3:d3:b2:e7:25:cf:
++ 11:54:97:ab:35:c0:1e:76:1c:ef:00:53:9f:39:dc:
++ 14:a5:2c:22:25:b3:72:72:fc:8d:b3:e5:3e:08:1e:
++ 14:2a:37:0b:88:3c:ca:b0:f4:c8:c2:a1:ae:bc:c1:
++ be:29:67:55:e2:fc:ad:59:5c:fe:bd:57:2c:b0:90:
++ 8d:c2:ed:37:b6:7c:99:88:b5:d5:03:9a:3d:15:0d:
++ 3d:3a:a8:a8:45:f0:95:4e:25:59:1d:cd:98:69:bb:
++ d3:cc:32:c9:8d:ef:81:fe:ad:7d:89:bb:ba:60:13:
++ ca:65:95:67:a0:f3:19:f6:03:56:d4:6a:d3:27:e2:
++ a1:ad:83:f0:4a:12:22:77:1c:05:73:e2:19:71:42:
++ c0:ec:75:46:9a:90:58:e0:6a:8e:2b:a5:46:30:04:
++ 8e:19:b2:17:e3:be:a9:ba:7f:56:f1:24:03:d7:b2:
++ 21:28:76:0e:36:30:4c:79:d5:41:9a:9a:a8:b8:35:
++ ba:0c:3a:f2:44:1b:20:88:f7:c5:25:d7:3d:c6:e3:
++ 3e:43:dd:87:fe:c4:ea:f5:53:3e:4c:65:ff:3b:4a:
++ cb:78:5a:6b:17:5f:0d:c7:c3:4f:4e:9a:2a:a2:ed:
++ 57:4d:22:e2:46:9a:3f:0f:91:34:24:7d:55:e3:8c:
++ 95:37:d3:1a:f0:09:2b:2c:d2:c9:8d:b4:0d:00:ab:
++ 67:29:28:d8:01:f5:19:04:b6:1d:be:76:fe:72:5c:
++ c4:85:ca:d2:80:41:df:05:a8:a3:d5:84:90:4f:0b:
++ f3:e0:3f:9b:19:d2:37:89:3f:f2:7b:52:1c:8c:f6:
++ e1:f7:3c:07:97:8c:0e:a2:59:81:0c:b2:90:3d:d3:
++ e3:59:46:ed:0f:a9:a7:de:80:6b:5a:aa:07:b6:19:
++ cb:bc:57:f3:97:21:7a:0c:b1:2b:74:3e:eb:da:a7:
++ 67:2d:4c:c4:98:9e:36:09:76:66:66:fc:1a:3f:ea:
++ 48:54:1c:be:30:bd:80:50:bf:7c:b5:ce:00:f6:0c:
++ 61:d9:e7:24:03:e0:e3:01:81:0e:bd:d8:85:34:88:
++ bd:b2:36:a8:7b:5c:08:e5:44:80:8c:6f:f8:2f:d5:
++ 21:ca:1d:1c:d0:fb:c4:b5:87:d1:3a:4e:c7:76:b5:
++ 35:48:b5
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 8C:FB:1C:75:BC:02:D3:9F:4E:2E:48:D9:F9:60:54:AA:C4:B3:4F:FA
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Signature Algorithm: sha512WithRSAEncryption
++ 48:a2:d5:00:0b:2e:d0:3f:bc:1c:d5:b5:54:49:1e:5a:6b:f4:
++ e4:f2:e0:40:37:e0:cc:14:7b:b9:c9:fa:35:b5:75:17:93:6a:
++ 05:69:85:9c:cd:4f:19:78:5b:19:81:f3:63:3e:c3:ce:5b:8f:
++ f5:2f:5e:01:76:13:3f:2c:00:b9:cd:96:52:39:49:6d:04:4e:
++ c5:e9:0f:86:0d:e1:fa:b3:5f:82:12:f1:3a:ce:66:06:24:34:
++ 2b:e8:cc:ca:e7:69:dc:87:9d:c2:34:d7:79:d1:d3:77:b8:aa:
++ 59:58:fe:9d:26:fa:38:86:3e:9d:8a:87:64:57:e5:17:3a:e2:
++ f9:8d:b9:e3:33:78:c1:90:d8:b8:dd:b7:83:51:e4:c4:cc:23:
++ d5:06:7c:e6:51:d3:cd:34:31:c0:f6:46:bb:0b:ad:fc:3d:10:
++ 05:2a:3b:4a:91:25:ee:8c:d4:84:87:80:2a:bc:09:8c:aa:3a:
++ 13:5f:e8:34:79:50:c1:10:19:f9:d3:28:1e:d4:d1:51:30:29:
++ b3:ae:90:67:d6:1f:0a:63:b1:c5:a9:c6:42:31:63:17:94:ef:
++ 69:cb:2f:fa:8c:14:7d:c4:43:18:89:d9:f0:32:40:e6:80:e2:
++ 46:5f:e5:e3:c1:00:59:a8:f9:e8:20:bc:89:2c:0e:47:34:0b:
++ ea:57:c2:53:36:fc:a7:d4:af:31:cd:fe:02:e5:75:fa:b9:27:
++ 09:f9:f3:f5:3b:ca:7d:9f:a9:22:cb:88:c9:aa:d1:47:3d:36:
++ 77:a8:59:64:6b:27:cf:ef:27:c1:e3:24:b5:86:f7:ae:7e:32:
++ 4d:b0:79:68:d1:39:e8:90:58:c3:83:bc:0f:2c:d6:97:eb:ce:
++ 0c:e1:20:c7:da:b7:3e:c3:3f:bf:2f:dc:34:a4:fb:2b:21:cd:
++ 67:8f:4b:f4:e3:ea:d4:3f:e7:4f:ba:b9:a5:93:45:1c:66:1f:
++ 21:fa:64:5e:6f:e0:76:94:32:cb:75:f5:6e:e5:f6:8f:c7:b8:
++ a4:cc:a8:96:7d:64:fb:24:5a:4a:03:6c:6b:38:c6:e8:03:43:
++ 9a:f7:57:b9:b3:29:69:93:38:f4:03:f2:bb:fb:82:6b:07:20:
++ d1:52:1f:9a:64:02:7b:98:66:db:5c:4d:5a:0f:d0:84:95:a0:
++ 3c:14:43:06:ca:ca:db:b8:41:36:da:6a:44:67:87:af:af:e3:
++ 45:11:15:69:08:b2:be:16:39:97:24:6f:12:45:d1:67:5d:09:
++ a8:c9:15:da:fa:d2:a6:5f:13:61:1f:bf:85:ac:b4:ad:ad:05:
++ 94:08:83:1e:75:17:d3:71:3b:93:50:23:59:a0:ed:3c:91:54:
++ 9d:76:00:c5:c3:b8:38:db
++SHA1 Fingerprint=C8:83:44:C0:18:AE:9F:CC:F1:87:B7:8F:22:D1:C5:D7:45:84:BA:E5
++-----BEGIN CERTIFICATE-----
++MIIFwDCCA6igAwIBAgIQHr9ZULjJgDdMBvfrVU+17TANBgkqhkiG9w0BAQ0FADB6
++MQswCQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEgU3lzdGVtcyBTLkEu
++MScwJQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxHzAdBgNV
++BAMTFkNlcnR1bSBUcnVzdGVkIFJvb3QgQ0EwHhcNMTgwMzE2MTIxMDEzWhcNNDMw
++MzE2MTIxMDEzWjB6MQswCQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEg
++U3lzdGVtcyBTLkEuMScwJQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRo
++b3JpdHkxHzAdBgNVBAMTFkNlcnR1bSBUcnVzdGVkIFJvb3QgQ0EwggIiMA0GCSqG
++SIb3DQEBAQUAA4ICDwAwggIKAoICAQDRLY67tzbqbTeRn06TpwXkKQMlzhyC93yZ
++n0EGze2jusDbCSzBfN8pfktlL5On1AFrAygYo9idBcEq2EXxkd7fO9CAAozPOA/q
++p1x4EaTByIVcJdPTsuclzxFUl6s1wB52HO8AU5853BSlLCIls3Jy/I2z5T4IHhQq
++NwuIPMqw9MjCoa68wb4pZ1Xi/K1ZXP69VyywkI3C7Te2fJmItdUDmj0VDT06qKhF
++8JVOJVkdzZhpu9PMMsmN74H+rX2Ju7pgE8pllWeg8xn2A1bUatMn4qGtg/BKEiJ3
++HAVz4hlxQsDsdUaakFjgao4rpUYwBI4Zshfjvqm6f1bxJAPXsiEodg42MEx51UGa
++mqi4NboMOvJEGyCI98Ul1z3G4z5D3Yf+xOr1Uz5MZf87Sst4WmsXXw3Hw09Omiqi
++7VdNIuJGmj8PkTQkfVXjjJU30xrwCSss0smNtA0Aq2cpKNgB9RkEth2+dv5yXMSF
++ytKAQd8FqKPVhJBPC/PgP5sZ0jeJP/J7UhyM9uH3PAeXjA6iWYEMspA90+NZRu0P
++qafegGtaqge2Gcu8V/OXIXoMsSt0Puvap2ctTMSYnjYJdmZm/Bo/6khUHL4wvYBQ
++v3y1zgD2DGHZ5yQD4OMBgQ692IU0iL2yNqh7XAjlRICMb/gv1SHKHRzQ+8S1h9E6
++Tsd2tTVItQIDAQABo0IwQDAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBSM+xx1
++vALTn04uSNn5YFSqxLNP+jAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQAD
++ggIBAEii1QALLtA/vBzVtVRJHlpr9OTy4EA34MwUe7nJ+jW1dReTagVphZzNTxl4
++WxmB82M+w85bj/UvXgF2Ez8sALnNllI5SW0ETsXpD4YN4fqzX4IS8TrOZgYkNCvo
++zMrnadyHncI013nR03e4qllY/p0m+jiGPp2Kh2RX5Rc64vmNueMzeMGQ2Ljdt4NR
++5MTMI9UGfOZR0800McD2RrsLrfw9EAUqO0qRJe6M1ISHgCq8CYyqOhNf6DR5UMEQ
++GfnTKB7U0VEwKbOukGfWHwpjscWpxkIxYxeU72nLL/qMFH3EQxiJ2fAyQOaA4kZf
++5ePBAFmo+eggvIksDkc0C+pXwlM2/KfUrzHN/gLldfq5Jwn58/U7yn2fqSLLiMmq
++0Uc9NneoWWRrJ8/vJ8HjJLWG965+Mk2weWjROeiQWMODvA8s1pfrzgzhIMfatz7D
++P78v3DSk+yshzWePS/Tj6tQ/50+6uaWTRRxmHyH6ZF5v4HaUMst19W7l9o/HuKTM
++qJZ9ZPskWkoDbGs4xugDQ5r3V7mzKWmTOPQD8rv7gmsHINFSH5pkAnuYZttcTVoP
++0ISVoDwUQwbKytu4QTbaakRnh6+v40URFWkIsr4WOZckbxJF0WddCajJFdr60qZf
++E2Efv4WstK2tBZQIgx51F9NxO5NQI1mg7TyRVJ12AMXDuDjb
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem.orig
++++ secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem
+@@ -1,152 +0,0 @@
+-##
+-## Chambers of Commerce Root - 2008
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- a3:da:42:7e:a4:b1:ae:da
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
+- Validity
+- Not Before: Aug 1 12:29:50 2008 GMT
+- Not After : Jul 31 12:29:50 2038 GMT
+- Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:af:00:cb:70:37:2b:80:5a:4a:3a:6c:78:94:7d:
+- a3:7f:1a:1f:f6:35:d5:bd:db:cb:0d:44:72:3e:26:
+- b2:90:52:ba:63:3b:28:58:6f:a5:b3:6d:94:a6:f3:
+- dd:64:0c:55:f6:f6:e7:f2:22:22:80:5e:e1:62:c6:
+- b6:29:e1:81:6c:f2:bf:e5:7d:32:6a:54:a0:32:19:
+- 59:fe:1f:8b:d7:3d:60:86:85:24:6f:e3:11:b3:77:
+- 3e:20:96:35:21:6b:b3:08:d9:70:2e:64:f7:84:92:
+- 53:d6:0e:b0:90:8a:8a:e3:87:8d:06:d3:bd:90:0e:
+- e2:99:a1:1b:86:0e:da:9a:0a:bb:0b:61:50:06:52:
+- f1:9e:7f:76:ec:cb:0f:d0:1e:0d:cf:99:30:3d:1c:
+- c4:45:10:58:ac:d6:d3:e8:d7:e5:ea:c5:01:07:77:
+- d6:51:e6:03:7f:8a:48:a5:4d:68:75:b9:e9:bc:9e:
+- 4e:19:71:f5:32:4b:9c:6d:60:19:0b:fb:cc:9d:75:
+- dc:bf:26:cd:8f:93:78:39:79:73:5e:25:0e:ca:5c:
+- eb:77:12:07:cb:64:41:47:72:93:ab:50:c3:eb:09:
+- 76:64:34:d2:39:b7:76:11:09:0d:76:45:c4:a9:ae:
+- 3d:6a:af:b5:7d:65:2f:94:58:10:ec:5c:7c:af:7e:
+- e2:b6:18:d9:d0:9b:4e:5a:49:df:a9:66:0b:cc:3c:
+- c6:78:7c:a7:9c:1d:e3:ce:8e:53:be:05:de:60:0f:
+- 6b:e5:1a:db:3f:e3:e1:21:c9:29:c1:f1:eb:07:9c:
+- 52:1b:01:44:51:3c:7b:25:d7:c4:e5:52:54:5d:25:
+- 07:ca:16:20:b8:ad:e4:41:ee:7a:08:fe:99:6f:83:
+- a6:91:02:b0:6c:36:55:6a:e7:7d:f5:96:e6:ca:81:
+- d6:97:f1:94:83:e9:ed:b0:b1:6b:12:69:1e:ac:fb:
+- 5d:a9:c5:98:e9:b4:5b:58:7a:be:3d:a2:44:3a:63:
+- 59:d4:0b:25:de:1b:4f:bd:e5:01:9e:cd:d2:29:d5:
+- 9f:17:19:0a:6f:bf:0c:90:d3:09:5f:d9:e3:8a:35:
+- cc:79:5a:4d:19:37:92:b7:c4:c1:ad:af:f4:79:24:
+- 9a:b2:01:0b:b1:af:5c:96:f3:80:32:fb:5c:3d:98:
+- f1:a0:3f:4a:de:be:af:94:2e:d9:55:9a:17:6e:60:
+- 9d:63:6c:b8:63:c9:ae:81:5c:18:35:e0:90:bb:be:
+- 3c:4f:37:22:b9:7e:eb:cf:9e:77:21:a6:3d:38:81:
+- fb:48:da:31:3d:2b:e3:89:f5:d0:b5:bd:7e:e0:50:
+- c4:12:89:b3:23:9a:10:31:85:db:ae:6f:ef:38:33:
+- 18:76:11
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 Subject Key Identifier:
+- F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
+- X509v3 Authority Key Identifier:
+- keyid:F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
+- DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Chambers of Commerce Root - 2008
+- serial:A3:DA:42:7E:A4:B1:AE:DA
+-
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Certificate Policies:
+- Policy: X509v3 Any Policy
+- CPS: http://policy.camerfirma.com
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 90:12:af:22:35:c2:a3:39:f0:2e:de:e9:b5:e9:78:7c:48:be:
+- 3f:7d:45:92:5e:e9:da:b1:19:fc:16:3c:9f:b4:5b:66:9e:6a:
+- e7:c3:b9:5d:88:e8:0f:ad:cf:23:0f:de:25:3a:5e:cc:4f:a5:
+- c1:b5:2d:ac:24:d2:58:07:de:a2:cf:69:84:60:33:e8:10:0d:
+- 13:a9:23:d0:85:e5:8e:7b:a6:9e:3d:72:13:72:33:f5:aa:7d:
+- c6:63:1f:08:f4:fe:01:7f:24:cf:2b:2c:54:09:de:e2:2b:6d:
+- 92:c6:39:4f:16:ea:3c:7e:7a:46:d4:45:6a:46:a8:eb:75:82:
+- 56:a7:ab:a0:7c:68:13:33:f6:9d:30:f0:6f:27:39:24:23:2a:
+- 90:fd:90:29:35:f2:93:df:34:a5:c6:f7:f8:ef:8c:0f:62:4a:
+- 7c:ae:d3:f5:54:f8:8d:b6:9a:56:87:16:82:3a:33:ab:5a:22:
+- 08:f7:82:ba:ea:2e:e0:47:9a:b4:b5:45:a3:05:3b:d9:dc:2e:
+- 45:40:3b:ea:dc:7f:e8:3b:eb:d1:ec:26:d8:35:a4:30:c5:3a:
+- ac:57:9e:b3:76:a5:20:7b:f9:1e:4a:05:62:01:a6:28:75:60:
+- 97:92:0d:6e:3e:4d:37:43:0d:92:15:9c:18:22:cd:51:99:a0:
+- 29:1a:3c:5f:8a:32:33:5b:30:c7:89:2f:47:98:0f:a3:03:c6:
+- f6:f1:ac:df:32:f0:d9:81:1a:e4:9c:bd:f6:80:14:f0:d1:2c:
+- b9:85:f5:d8:a3:b1:c8:a5:21:e5:1c:13:97:ee:0e:bd:df:29:
+- a9:ef:34:53:5b:d3:e4:6a:13:84:06:b6:32:02:c4:52:ae:22:
+- d2:dc:b2:21:42:1a:da:40:f0:29:c9:ec:0a:0c:5c:e2:d0:ba:
+- cc:48:d3:37:0a:cc:12:0a:8a:79:b0:3d:03:7f:69:4b:f4:34:
+- 20:7d:b3:34:ea:8e:4b:64:f5:3e:fd:b3:23:67:15:0d:04:b8:
+- f0:2d:c1:09:51:3c:b2:6c:15:f0:a5:23:d7:83:74:e4:e5:2e:
+- c9:fe:98:27:42:c6:ab:c6:9e:b0:d0:5b:38:a5:9b:50:de:7e:
+- 18:98:b5:45:3b:f6:79:b4:e8:f7:1a:7b:06:83:fb:d0:8b:da:
+- bb:c7:bd:18:ab:08:6f:3c:80:6b:40:3f:19:19:ba:65:8a:e6:
+- be:d5:5c:d3:36:d7:ef:40:52:24:60:38:67:04:31:ec:8f:f3:
+- 82:c6:de:b9:55:f3:3b:31:91:5a:dc:b5:08:15:ad:76:25:0a:
+- 0d:7b:2e:87:e2:0c:a6:06:bc:26:10:6d:37:9d:ec:dd:78:8c:
+- 7c:80:c5:f0:d9:77:48:d0
+-SHA1 Fingerprint=78:6A:74:AC:76:AB:14:7F:9C:6A:30:50:BA:9E:A8:7E:FE:9A:CE:3C
+------BEGIN CERTIFICATE-----
+-MIIHTzCCBTegAwIBAgIJAKPaQn6ksa7aMA0GCSqGSIb3DQEBBQUAMIGuMQswCQYD
+-VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
+-IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
+-MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xKTAnBgNVBAMTIENoYW1iZXJz
+-IG9mIENvbW1lcmNlIFJvb3QgLSAyMDA4MB4XDTA4MDgwMTEyMjk1MFoXDTM4MDcz
+-MTEyMjk1MFowga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpNYWRyaWQgKHNlZSBj
+-dXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29tL2FkZHJlc3MpMRIw
+-EAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVyZmlybWEgUy5BLjEp
+-MCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAtIDIwMDgwggIiMA0G
+-CSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCvAMtwNyuAWko6bHiUfaN/Gh/2NdW9
+-28sNRHI+JrKQUrpjOyhYb6WzbZSm891kDFX29ufyIiKAXuFixrYp4YFs8r/lfTJq
+-VKAyGVn+H4vXPWCGhSRv4xGzdz4gljUha7MI2XAuZPeEklPWDrCQiorjh40G072Q
+-DuKZoRuGDtqaCrsLYVAGUvGef3bsyw/QHg3PmTA9HMRFEFis1tPo1+XqxQEHd9ZR
+-5gN/ikilTWh1uem8nk4ZcfUyS5xtYBkL+8ydddy/Js2Pk3g5eXNeJQ7KXOt3EgfL
+-ZEFHcpOrUMPrCXZkNNI5t3YRCQ12RcSprj1qr7V9ZS+UWBDsXHyvfuK2GNnQm05a
+-Sd+pZgvMPMZ4fKecHePOjlO+Bd5gD2vlGts/4+EhySnB8esHnFIbAURRPHsl18Tl
+-UlRdJQfKFiC4reRB7noI/plvg6aRArBsNlVq5331lubKgdaX8ZSD6e2wsWsSaR6s
+-+12pxZjptFtYer49okQ6Y1nUCyXeG0+95QGezdIp1Z8XGQpvvwyQ0wlf2eOKNcx5
+-Wk0ZN5K3xMGtr/R5JJqyAQuxr1yW84Ay+1w9mPGgP0revq+ULtlVmhduYJ1jbLhj
+-ya6BXBg14JC7vjxPNyK5fuvPnnchpj04gftI2jE9K+OJ9dC1vX7gUMQSibMjmhAx
+-hduub+84Mxh2EQIDAQABo4IBbDCCAWgwEgYDVR0TAQH/BAgwBgEB/wIBDDAdBgNV
+-HQ4EFgQU+SSsD7K1+HnA+mCIG8TZTQKeFxkwgeMGA1UdIwSB2zCB2IAU+SSsD7K1
+-+HnA+mCIG8TZTQKeFxmhgbSkgbEwga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpN
+-YWRyaWQgKHNlZSBjdXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29t
+-L2FkZHJlc3MpMRIwEAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVy
+-ZmlybWEgUy5BLjEpMCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAt
+-IDIwMDiCCQCj2kJ+pLGu2jAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRV
+-HSAAMCowKAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20w
+-DQYJKoZIhvcNAQEFBQADggIBAJASryI1wqM58C7e6bXpeHxIvj99RZJe6dqxGfwW
+-PJ+0W2aeaufDuV2I6A+tzyMP3iU6XsxPpcG1Lawk0lgH3qLPaYRgM+gQDROpI9CF
+-5Y57pp49chNyM/WqfcZjHwj0/gF/JM8rLFQJ3uIrbZLGOU8W6jx+ekbURWpGqOt1
+-glanq6B8aBMz9p0w8G8nOSQjKpD9kCk18pPfNKXG9/jvjA9iSnyu0/VU+I22mlaH
+-FoI6M6taIgj3grrqLuBHmrS1RaMFO9ncLkVAO+rcf+g769HsJtg1pDDFOqxXnrN2
+-pSB7+R5KBWIBpih1YJeSDW4+TTdDDZIVnBgizVGZoCkaPF+KMjNbMMeJL0eYD6MD
+-xvbxrN8y8NmBGuScvfaAFPDRLLmF9dijscilIeUcE5fuDr3fKanvNFNb0+RqE4QG
+-tjICxFKuItLcsiFCGtpA8CnJ7AoMXOLQusxI0zcKzBIKinmwPQN/aUv0NCB9szTq
+-jktk9T79syNnFQ0EuPAtwQlRPLJsFfClI9eDdOTlLsn+mCdCxqvGnrDQWzilm1De
+-fhiYtUU79nm06PcaewaD+9CL2rvHvRirCG88gGtAPxkZumWK5r7VXNM21+9AUiRg
+-OGcEMeyP84LG3rlV8zsxkVrctQgVrXYlCg17LofiDKYGvCYQbTed7N14jHyAxfDZ
+-d0jQ
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Comodo_AAA_Services_root.pem.orig
++++ secure/caroot/trusted/Comodo_AAA_Services_root.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Cybertrust_Global_Root.pem.orig
++++ secure/caroot/trusted/Cybertrust_Global_Root.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem.orig
++++ secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem
+@@ -1,101 +0,0 @@
+-##
+-## D-TRUST Root CA 3 2013
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 1039788 (0xfddac)
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
+- Validity
+- Not Before: Sep 20 08:25:51 2013 GMT
+- Not After : Sep 20 08:25:51 2028 GMT
+- Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c4:7b:42:92:82:1f:ec:ed:54:98:8e:12:c0:ca:
+- 09:df:93:6e:3a:93:5c:1b:e4:10:77:9e:4e:69:88:
+- 6c:f6:e1:69:f2:f6:9b:a2:61:b1:bd:07:20:74:98:
+- 65:f1:8c:26:08:cd:a8:35:ca:80:36:d1:63:6d:e8:
+- 44:7a:82:c3:6c:5e:de:bb:e8:36:d2:c4:68:36:8c:
+- 9f:32:bd:84:22:e0:dc:c2:ee:10:46:39:6d:af:93:
+- 39:ae:87:e6:c3:bc:09:c9:2c:6b:67:5b:d9:9b:76:
+- 75:4c:0b:e0:bb:c5:d7:bc:3e:79:f2:5f:be:d1:90:
+- 57:f9:ae:f6:66:5f:31:bf:d3:6d:8f:a7:ba:4a:f3:
+- 23:65:bb:b7:ef:a3:25:d7:0a:ea:58:b6:ef:88:fa:
+- fa:79:b2:52:58:d5:f0:ac:8c:a1:51:74:29:95:aa:
+- 51:3b:90:32:03:9f:1c:72:74:90:de:3d:ed:61:d2:
+- e5:e3:fd:64:47:e5:b9:b7:4a:a9:f7:1f:ae:96:86:
+- 04:ac:2f:e3:a4:81:77:b7:5a:16:ff:d8:0f:3f:f6:
+- b7:78:cc:a4:af:fa:5b:3c:12:5b:a8:52:89:72:ef:
+- 88:f3:d5:44:81:86:95:23:9f:7b:dd:bc:d9:34:ef:
+- 7c:94:3c:aa:c0:41:c2:e3:9d:50:1a:c0:e4:19:22:
+- fc:b3
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 3F:90:C8:7D:C7:15:6F:F3:24:8F:A9:C3:2F:4B:A2:0F:21:B2:2F:E7
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 CRL Distribution Points:
+-
+- Full Name:
+- URI:ldap://directory.d-trust.net/CN=D-TRUST%20Root%20CA%203%202013,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
+-
+- Full Name:
+- URI:http://crl.d-trust.net/crl/d-trust_root_ca_3_2013.crl
+-
+- Signature Algorithm: sha256WithRSAEncryption
+- 0e:59:0e:58:e4:74:48:23:44:cf:34:21:b5:9c:14:1a:ad:9a:
+- 4b:b7:b3:88:6d:5c:a9:17:70:f0:2a:9f:8d:7b:f9:7b:85:fa:
+- c7:39:e8:10:08:b0:35:2b:5f:cf:02:d2:d3:9c:c8:0b:1e:ee:
+- 05:54:ae:37:93:04:09:7d:6c:8f:c2:74:bc:f8:1c:94:be:31:
+- 01:40:2d:f3:24:20:b7:84:55:2c:5c:c8:f5:74:4a:10:19:8b:
+- a3:c7:ed:35:d6:09:48:d3:0e:c0:ba:39:a8:b0:46:02:b0:db:
+- c6:88:59:c2:be:fc:7b:b1:2b:cf:7e:62:87:55:96:cc:01:6f:
+- 9b:67:21:95:35:8b:f8:10:fc:71:1b:b7:4b:37:69:a6:3b:d6:
+- ec:8b:ee:c1:b0:f3:25:c9:8f:92:7d:a1:ea:c3:ca:44:bf:26:
+- a5:74:92:9c:e3:74:eb:9d:74:d9:cb:4d:87:d8:fc:b4:69:6c:
+- 8b:a0:43:07:60:78:97:e9:d9:93:7c:c2:46:bc:9b:37:52:a3:
+- ed:8a:3c:13:a9:7b:53:4b:49:9a:11:05:2c:0b:6e:56:ac:1f:
+- 2e:82:6c:e0:69:67:b5:0e:6d:2d:d9:e4:c0:15:f1:3f:fa:18:
+- 72:e1:15:6d:27:5b:2d:30:28:2b:9f:48:9a:64:2b:99:ef:f2:
+- 75:49:5f:5c
+-SHA1 Fingerprint=6C:7C:CC:E7:D4:AE:51:5F:99:08:CD:3F:F6:E8:C3:78:DF:6F:EF:97
+------BEGIN CERTIFICATE-----
+-MIIEDjCCAvagAwIBAgIDD92sMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkRF
+-MRUwEwYDVQQKDAxELVRydXN0IEdtYkgxHzAdBgNVBAMMFkQtVFJVU1QgUm9vdCBD
+-QSAzIDIwMTMwHhcNMTMwOTIwMDgyNTUxWhcNMjgwOTIwMDgyNTUxWjBFMQswCQYD
+-VQQGEwJERTEVMBMGA1UECgwMRC1UcnVzdCBHbWJIMR8wHQYDVQQDDBZELVRSVVNU
+-IFJvb3QgQ0EgMyAyMDEzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
+-xHtCkoIf7O1UmI4SwMoJ35NuOpNcG+QQd55OaYhs9uFp8vabomGxvQcgdJhl8Ywm
+-CM2oNcqANtFjbehEeoLDbF7eu+g20sRoNoyfMr2EIuDcwu4QRjltr5M5rofmw7wJ
+-ySxrZ1vZm3Z1TAvgu8XXvD558l++0ZBX+a72Zl8xv9Ntj6e6SvMjZbu376Ml1wrq
+-WLbviPr6ebJSWNXwrIyhUXQplapRO5AyA58ccnSQ3j3tYdLl4/1kR+W5t0qp9x+u
+-loYErC/jpIF3t1oW/9gPP/a3eMykr/pbPBJbqFKJcu+I89VEgYaVI5973bzZNO98
+-lDyqwEHC451QGsDkGSL8swIDAQABo4IBBTCCAQEwDwYDVR0TAQH/BAUwAwEB/zAd
+-BgNVHQ4EFgQUP5DIfccVb/Mkj6nDL0uiDyGyL+cwDgYDVR0PAQH/BAQDAgEGMIG+
+-BgNVHR8EgbYwgbMwdKByoHCGbmxkYXA6Ly9kaXJlY3RvcnkuZC10cnVzdC5uZXQv
+-Q049RC1UUlVTVCUyMFJvb3QlMjBDQSUyMDMlMjAyMDEzLE89RC1UcnVzdCUyMEdt
+-YkgsQz1ERT9jZXJ0aWZpY2F0ZXJldm9jYXRpb25saXN0MDugOaA3hjVodHRwOi8v
+-Y3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X3Jvb3RfY2FfM18yMDEzLmNybDAN
+-BgkqhkiG9w0BAQsFAAOCAQEADlkOWOR0SCNEzzQhtZwUGq2aS7eziG1cqRdw8Cqf
+-jXv5e4X6xznoEAiwNStfzwLS05zICx7uBVSuN5MECX1sj8J0vPgclL4xAUAt8yQg
+-t4RVLFzI9XRKEBmLo8ftNdYJSNMOwLo5qLBGArDbxohZwr78e7Erz35ih1WWzAFv
+-m2chlTWL+BD8cRu3SzdppjvW7IvuwbDzJcmPkn2h6sPKRL8mpXSSnON065102ctN
+-h9j8tGlsi6BDB2B4l+nZk3zCRrybN1Kj7Yo8E6l7U0tJmhEFLAtuVqwfLoJs4Gln
+-tQ5tLdnkwBXxP/oYcuEVbSdbLTAoK59ImmQrme/ydUlfXA==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem.orig
++++ secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem.orig
++++ secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DST_Root_CA_X3.pem.orig
++++ secure/caroot/trusted/DST_Root_CA_X3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem.orig
++++ secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem.orig
++++ secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem.orig
++++ secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_Global_Root_CA.pem.orig
++++ secure/caroot/trusted/DigiCert_Global_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_Global_Root_G2.pem.orig
++++ secure/caroot/trusted/DigiCert_Global_Root_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_Global_Root_G3.pem.orig
++++ secure/caroot/trusted/DigiCert_Global_Root_G3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem.orig
++++ secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem.orig
++++ secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/E-Tugra_Certification_Authority.pem.orig
++++ secure/caroot/trusted/E-Tugra_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/EC-ACC.pem.orig
++++ secure/caroot/trusted/EC-ACC.pem
+@@ -1,109 +0,0 @@
+-##
+-## EC-ACC
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- (Negative)11:d4:c2:14:2b:de:21:eb:57:9d:53:fb:0c:22:3b:ff
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
+- Validity
+- Not Before: Jan 7 23:00:00 2003 GMT
+- Not After : Jan 7 22:59:59 2031 GMT
+- Subject: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:b3:22:c7:4f:e2:97:42:95:88:47:83:40:f6:1d:
+- 17:f3:83:73:24:1e:51:f3:98:8a:c3:92:b8:ff:40:
+- 90:05:70:87:60:c9:00:a9:b5:94:65:19:22:15:17:
+- c2:43:6c:66:44:9a:0d:04:3e:39:6f:a5:4b:7a:aa:
+- 63:b7:8a:44:9d:d9:63:91:84:66:e0:28:0f:ba:42:
+- e3:6e:8e:f7:14:27:93:69:ee:91:0e:a3:5f:0e:b1:
+- eb:66:a2:72:4f:12:13:86:65:7a:3e:db:4f:07:f4:
+- a7:09:60:da:3a:42:99:c7:b2:7f:b3:16:95:1c:c7:
+- f9:34:b5:94:85:d5:99:5e:a0:48:a0:7e:e7:17:65:
+- b8:a2:75:b8:1e:f3:e5:42:7d:af:ed:f3:8a:48:64:
+- 5d:82:14:93:d8:c0:e4:ff:b3:50:72:f2:76:f6:b3:
+- 5d:42:50:79:d0:94:3e:6b:0c:00:be:d8:6b:0e:4e:
+- 2a:ec:3e:d2:cc:82:a2:18:65:33:13:77:9e:9a:5d:
+- 1a:13:d8:c3:db:3d:c8:97:7a:ee:70:ed:a7:e6:7c:
+- db:71:cf:2d:94:62:df:6d:d6:f5:38:be:3f:a5:85:
+- 0a:19:b8:a8:d8:09:75:42:70:c4:ea:ef:cb:0e:c8:
+- 34:a8:12:22:98:0c:b8:13:94:b6:4b:ec:f0:d0:90:
+- e7:27
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Subject Alternative Name:
+- email:ec_acc@catcert.net
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Subject Key Identifier:
+- A0:C3:8B:44:AA:37:A5:45:BF:97:80:5A:D1:F1:78:A2:9B:E9:5D:8D
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.15096.1.3.1.10
+- CPS: https://www.catcert.net/verarrel
+- User Notice:
+- Explicit Text: Vegeu https://www.catcert.net/verarrel
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- a0:48:5b:82:01:f6:4d:48:b8:39:55:35:9c:80:7a:53:99:d5:
+- 5a:ff:b1:71:3b:cc:39:09:94:5e:d6:da:ef:be:01:5b:5d:d3:
+- 1e:d8:fd:7d:4f:cd:a0:41:e0:34:93:bf:cb:e2:86:9c:37:92:
+- 90:56:1c:dc:eb:29:05:e5:c4:9e:c7:35:df:8a:0c:cd:c5:21:
+- 43:e9:aa:88:e5:35:c0:19:42:63:5a:02:5e:a4:48:18:3a:85:
+- 6f:dc:9d:bc:3f:9d:9c:c1:87:b8:7a:61:08:e9:77:0b:7f:70:
+- ab:7a:dd:d9:97:2c:64:1e:85:bf:bc:74:96:a1:c3:7a:12:ec:
+- 0c:1a:6e:83:0c:3c:e8:72:46:9f:fb:48:d5:5e:97:e6:b1:a1:
+- f8:e4:ef:46:25:94:9c:89:db:69:38:be:ec:5c:0e:56:c7:65:
+- 51:e5:50:88:88:bf:42:d5:2b:3d:e5:f9:ba:9e:2e:b3:ca:f4:
+- 73:92:02:0b:be:4c:66:eb:20:fe:b9:cb:b5:99:7f:e6:b6:13:
+- fa:ca:4b:4d:d9:ee:53:46:06:3b:c6:4e:ad:93:5a:81:7e:6c:
+- 2a:4b:6a:05:45:8c:f2:21:a4:31:90:87:6c:65:9c:9d:a5:60:
+- 95:3a:52:7f:f5:d1:ab:08:6e:f3:ee:5b:f9:88:3d:7e:b8:6f:
+- 6e:03:e4:42
+-SHA1 Fingerprint=28:90:3A:63:5B:52:80:FA:E6:77:4C:0B:6D:A7:D6:BA:A6:4A:F2:E8
+------BEGIN CERTIFICATE-----
+-MIIFVjCCBD6gAwIBAgIQ7is969Qh3hSoYqwE893EATANBgkqhkiG9w0BAQUFADCB
+-8zELMAkGA1UEBhMCRVMxOzA5BgNVBAoTMkFnZW5jaWEgQ2F0YWxhbmEgZGUgQ2Vy
+-dGlmaWNhY2lvIChOSUYgUS0wODAxMTc2LUkpMSgwJgYDVQQLEx9TZXJ2ZWlzIFB1
+-YmxpY3MgZGUgQ2VydGlmaWNhY2lvMTUwMwYDVQQLEyxWZWdldSBodHRwczovL3d3
+-dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAoYykwMzE1MDMGA1UECxMsSmVyYXJxdWlh
+-IEVudGl0YXRzIGRlIENlcnRpZmljYWNpbyBDYXRhbGFuZXMxDzANBgNVBAMTBkVD
+-LUFDQzAeFw0wMzAxMDcyMzAwMDBaFw0zMTAxMDcyMjU5NTlaMIHzMQswCQYDVQQG
+-EwJFUzE7MDkGA1UEChMyQWdlbmNpYSBDYXRhbGFuYSBkZSBDZXJ0aWZpY2FjaW8g
+-KE5JRiBRLTA4MDExNzYtSSkxKDAmBgNVBAsTH1NlcnZlaXMgUHVibGljcyBkZSBD
+-ZXJ0aWZpY2FjaW8xNTAzBgNVBAsTLFZlZ2V1IGh0dHBzOi8vd3d3LmNhdGNlcnQu
+-bmV0L3ZlcmFycmVsIChjKTAzMTUwMwYDVQQLEyxKZXJhcnF1aWEgRW50aXRhdHMg
+-ZGUgQ2VydGlmaWNhY2lvIENhdGFsYW5lczEPMA0GA1UEAxMGRUMtQUNDMIIBIjAN
+-BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsyLHT+KXQpWIR4NA9h0X84NzJB5R
+-85iKw5K4/0CQBXCHYMkAqbWUZRkiFRfCQ2xmRJoNBD45b6VLeqpjt4pEndljkYRm
+-4CgPukLjbo73FCeTae6RDqNfDrHrZqJyTxIThmV6PttPB/SnCWDaOkKZx7J/sxaV
+-HMf5NLWUhdWZXqBIoH7nF2W4onW4HvPlQn2v7fOKSGRdghST2MDk/7NQcvJ29rNd
+-QlB50JQ+awwAvthrDk4q7D7SzIKiGGUzE3eeml0aE9jD2z3Il3rucO2n5nzbcc8t
+-lGLfbdb1OL4/pYUKGbio2Al1QnDE6u/LDsg0qBIimAy4E5S2S+zw0JDnJwIDAQAB
+-o4HjMIHgMB0GA1UdEQQWMBSBEmVjX2FjY0BjYXRjZXJ0Lm5ldDAPBgNVHRMBAf8E
+-BTADAQH/MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUoMOLRKo3pUW/l4Ba0fF4
+-opvpXY0wfwYDVR0gBHgwdjB0BgsrBgEEAfV4AQMBCjBlMCwGCCsGAQUFBwIBFiBo
+-dHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbDA1BggrBgEFBQcCAjApGidW
+-ZWdldSBodHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAwDQYJKoZIhvcN
+-AQEFBQADggEBAKBIW4IB9k1IuDlVNZyAelOZ1Vr/sXE7zDkJlF7W2u++AVtd0x7Y
+-/X1PzaBB4DSTv8vihpw3kpBWHNzrKQXlxJ7HNd+KDM3FIUPpqojlNcAZQmNaAl6k
+-SBg6hW/cnbw/nZzBh7h6YQjpdwt/cKt63dmXLGQehb+8dJahw3oS7AwaboMMPOhy
+-Rp/7SNVel+axofjk70YllJyJ22k4vuxcDlbHZVHlUIiIv0LVKz3l+bqeLrPK9HOS
+-Agu+TGbrIP65y7WZf+a2E/rKS03Z7lNGBjvGTq2TWoF+bCpLagVFjPIhpDGQh2xl
+-nJ2lYJU6Un/10asIbvPuW/mIPX64b24D5EI=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem.orig
++++ secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem.orig
++++ secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- /dev/null
++++ secure/caroot/trusted/GLOBALTRUST_2020.pem
+@@ -0,0 +1,138 @@
++##
++## GLOBALTRUST 2020
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 5a:4b:bd:5a:fb:4f:8a:5b:fa:65:e5
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = AT, O = e-commerce monitoring GmbH, CN = GLOBALTRUST 2020
++ Validity
++ Not Before: Feb 10 00:00:00 2020 GMT
++ Not After : Jun 10 00:00:00 2040 GMT
++ Subject: C = AT, O = e-commerce monitoring GmbH, CN = GLOBALTRUST 2020
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:ae:2e:56:ad:1b:1c:ef:f6:95:8f:a0:77:1b:2b:
++ d3:63:8f:84:4d:45:a2:0f:9f:5b:45:ab:59:7b:51:
++ 34:f9:ec:8b:8a:78:c5:dd:6b:af:bd:c4:df:93:45:
++ 1e:bf:91:38:0b:ae:0e:16:e7:41:73:f8:db:bb:d1:
++ b8:51:e0:cb:83:3b:73:38:6e:77:8a:0f:59:63:26:
++ cd:a7:2a:ce:54:fb:b8:e2:c0:7c:47:ce:60:7c:3f:
++ b2:73:f2:c0:19:b6:8a:92:87:35:0d:90:28:a2:e4:
++ 15:04:63:3e:ba:af:ee:7c:5e:cc:a6:8b:50:b2:38:
++ f7:41:63:ca:ce:ff:69:8f:68:0e:95:36:e5:cc:b9:
++ 8c:09:ca:4b:dd:31:90:96:c8:cc:1f:fd:56:96:34:
++ db:8e:1c:ea:2c:be:85:2e:63:dd:aa:a9:95:d3:fd:
++ 29:95:13:f0:c8:98:93:d9:2d:16:47:90:11:83:a2:
++ 3a:22:a2:28:57:a2:eb:fe:c0:8c:28:a0:a6:7d:e7:
++ 2a:42:3b:82:80:63:a5:63:1f:19:cc:7c:b2:66:a8:
++ c2:d3:6d:37:6f:e2:7e:06:51:d9:45:84:1f:12:ce:
++ 24:52:64:85:0b:48:80:4e:87:b1:22:22:30:aa:eb:
++ ae:be:e0:02:e0:40:e8:b0:42:80:03:51:aa:b4:7e:
++ aa:44:d7:43:61:f3:a2:6b:16:89:49:a4:a3:a4:2b:
++ 8a:02:c4:78:f4:68:8a:c1:e4:7a:36:b1:6f:1b:96:
++ 1b:77:49:8d:d4:c9:06:72:8f:cf:53:e3:dc:17:85:
++ 20:4a:dc:98:27:d3:91:26:2b:47:1e:69:07:af:de:
++ a2:e4:e4:d4:6b:0b:b3:5e:7c:d4:24:80:47:29:69:
++ 3b:6e:e8:ac:fd:40:eb:d8:ed:71:71:2b:f2:e8:58:
++ 1d:eb:41:97:22:c5:1f:d4:39:d0:27:8f:87:e3:18:
++ f4:e0:a9:46:0d:f5:74:3a:82:2e:d0:6e:2c:91:a3:
++ 31:5c:3b:46:ea:7b:04:10:56:5e:80:1d:f5:a5:65:
++ e8:82:fc:e2:07:8c:62:45:f5:20:de:46:70:86:a1:
++ bc:93:d3:1e:74:a6:6c:b0:2c:f7:03:0c:88:0c:cb:
++ d4:72:53:86:bc:60:46:f3:98:6a:c2:f1:bf:43:f9:
++ 70:20:77:ca:37:41:79:55:52:63:8d:5b:12:9f:c5:
++ 68:c4:88:9d:ac:f2:30:ab:b7:a3:31:97:67:ad:8f:
++ 17:0f:6c:c7:73:ed:24:94:6b:c8:83:9a:d0:9a:37:
++ 49:04:ab:b1:16:c8:6c:49:49:2d:ab:a1:d0:8c:92:
++ f2:41:4a:79:21:25:db:63:d7:b6:9c:a7:7e:42:69:
++ fb:3a:63
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ DC:2E:1F:D1:61:37:79:E4:AB:D5:D5:B3:12:71:68:3D:6A:68:9C:22
++ X509v3 Authority Key Identifier:
++ keyid:DC:2E:1F:D1:61:37:79:E4:AB:D5:D5:B3:12:71:68:3D:6A:68:9C:22
++
++ Signature Algorithm: sha256WithRSAEncryption
++ 91:f0:42:02:68:40:ee:c3:68:c0:54:2f:df:ec:62:c3:c3:9e:
++ 8a:a0:31:28:aa:83:8e:a4:56:96:12:10:86:56:ba:97:72:d2:
++ 54:30:7c:ad:19:d5:1d:68:6f:fb:14:42:d8:8d:0e:f3:b5:d1:
++ a5:e3:02:42:5e:dc:e8:46:58:07:35:02:30:e0:bc:74:4a:c1:
++ 43:2a:ff:db:1a:d0:b0:af:6c:c3:fd:cb:b3:f5:7f:6d:03:2e:
++ 59:56:9d:2d:2d:35:8c:b2:d6:43:17:2c:92:0a:cb:5d:e8:8c:
++ 0f:4b:70:43:d0:82:ff:a8:cc:bf:a4:94:c0:be:87:bd:8a:e3:
++ 93:7b:c6:8f:9b:16:9d:27:65:bc:7a:c5:42:82:6c:5c:07:d0:
++ a9:c1:88:60:44:e9:98:85:16:5f:f8:8f:ca:01:10:ce:25:c3:
++ f9:60:1b:a0:c5:97:c3:d3:2c:88:31:a2:bd:30:ec:d0:d0:c0:
++ 12:f1:c1:39:e3:e5:f5:f8:d6:4a:dd:34:cd:fb:6f:c1:4f:e3:
++ 00:8b:56:e2:92:f7:28:b2:42:77:72:23:67:c7:3f:11:15:b2:
++ c4:03:05:be:bb:11:7b:0a:bf:a8:6e:e7:ff:58:43:cf:9b:67:
++ a0:80:07:b6:1d:ca:ad:6d:ea:41:11:7e:2d:74:93:fb:c2:bc:
++ be:51:44:c5:ef:68:25:27:80:e3:c8:a0:d4:12:ec:d9:a5:37:
++ 1d:37:7c:b4:91:ca:da:d4:b1:96:81:ef:68:5c:76:10:49:af:
++ 7e:a5:37:80:b1:1c:52:bd:33:81:4c:8f:f9:dd:65:d9:14:cd:
++ 8a:25:58:f4:e2:c5:83:a5:09:90:d4:6c:14:63:b5:40:df:eb:
++ c0:fc:c4:58:7e:0d:14:16:87:54:27:6e:56:e4:70:84:b8:6c:
++ 32:12:7e:82:31:43:be:d7:dd:7c:a1:ad:ae:d6:ab:20:12:ef:
++ 0a:c3:10:8c:49:96:35:dc:0b:75:5e:b1:4f:d5:4f:34:0e:11:
++ 20:07:75:43:45:e9:a3:11:da:ac:a3:99:c2:b6:79:27:e2:b9:
++ ef:c8:e2:f6:35:29:7a:74:fa:c5:7f:82:05:62:a6:0a:ea:68:
++ b2:79:47:06:6e:f2:57:a8:15:33:c6:f7:78:4a:3d:42:7b:6b:
++ 7e:fe:f7:46:ea:d1:eb:8e:ef:88:68:5b:e8:c1:d9:71:7e:fd:
++ 64:ef:ff:67:47:88:58:25:2f:3e:86:07:bd:fb:a8:e5:82:a8:
++ ac:a5:d3:69:43:cd:31:88:49:84:53:92:c0:b1:39:1b:39:83:
++ 01:30:c4:f2:a9:fa:d0:03:bd:72:37:60:56:1f:36:7c:bd:39:
++ 91:f5:6d:0d:bf:7b:d7:92
++SHA1 Fingerprint=D0:67:C1:13:51:01:0C:AA:D0:C7:6A:65:37:31:16:26:4F:53:71:A2
++-----BEGIN CERTIFICATE-----
++MIIFgjCCA2qgAwIBAgILWku9WvtPilv6ZeUwDQYJKoZIhvcNAQELBQAwTTELMAkG
++A1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9uaXRvcmluZyBHbWJIMRkw
++FwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMB4XDTIwMDIxMDAwMDAwMFoXDTQwMDYx
++MDAwMDAwMFowTTELMAkGA1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9u
++aXRvcmluZyBHbWJIMRkwFwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMIICIjANBgkq
++hkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAri5WrRsc7/aVj6B3GyvTY4+ETUWiD59b
++RatZe1E0+eyLinjF3WuvvcTfk0Uev5E4C64OFudBc/jbu9G4UeDLgztzOG53ig9Z
++YybNpyrOVPu44sB8R85gfD+yc/LAGbaKkoc1DZAoouQVBGM+uq/ufF7MpotQsjj3
++QWPKzv9pj2gOlTblzLmMCcpL3TGQlsjMH/1WljTbjhzqLL6FLmPdqqmV0/0plRPw
++yJiT2S0WR5ARg6I6IqIoV6Lr/sCMKKCmfecqQjuCgGOlYx8ZzHyyZqjC0203b+J+
++BlHZRYQfEs4kUmSFC0iAToexIiIwquuuvuAC4EDosEKAA1GqtH6qRNdDYfOiaxaJ
++SaSjpCuKAsR49GiKweR6NrFvG5Ybd0mN1MkGco/PU+PcF4UgStyYJ9ORJitHHmkH
++r96i5OTUawuzXnzUJIBHKWk7buis/UDr2O1xcSvy6Fgd60GXIsUf1DnQJ4+H4xj0
++4KlGDfV0OoIu0G4skaMxXDtG6nsEEFZegB31pWXogvziB4xiRfUg3kZwhqG8k9Me
++dKZssCz3AwyIDMvUclOGvGBG85hqwvG/Q/lwIHfKN0F5VVJjjVsSn8VoxIidrPIw
++q7ejMZdnrY8XD2zHc+0klGvIg5rQmjdJBKuxFshsSUktq6HQjJLyQUp5ISXbY9e2
++nKd+Qmn7OmMCAwEAAaNjMGEwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMC
++AQYwHQYDVR0OBBYEFNwuH9FhN3nkq9XVsxJxaD1qaJwiMB8GA1UdIwQYMBaAFNwu
++H9FhN3nkq9XVsxJxaD1qaJwiMA0GCSqGSIb3DQEBCwUAA4ICAQCR8EICaEDuw2jA
++VC/f7GLDw56KoDEoqoOOpFaWEhCGVrqXctJUMHytGdUdaG/7FELYjQ7ztdGl4wJC
++XtzoRlgHNQIw4Lx0SsFDKv/bGtCwr2zD/cuz9X9tAy5ZVp0tLTWMstZDFyySCstd
++6IwPS3BD0IL/qMy/pJTAvoe9iuOTe8aPmxadJ2W8esVCgmxcB9CpwYhgROmYhRZf
+++I/KARDOJcP5YBugxZfD0yyIMaK9MOzQ0MAS8cE54+X1+NZK3TTN+2/BT+MAi1bi
++kvcoskJ3ciNnxz8RFbLEAwW+uxF7Cr+obuf/WEPPm2eggAe2HcqtbepBEX4tdJP7
++wry+UUTF72glJ4DjyKDUEuzZpTcdN3y0kcra1LGWge9oXHYQSa9+pTeAsRxSvTOB
++TI/53WXZFM2KJVj04sWDpQmQ1GwUY7VA3+vA/MRYfg0UFodUJ25W5HCEuGwyEn6C
++MUO+1918oa2u1qsgEu8KwxCMSZY13At1XrFP1U80DhEgB3VDRemjEdqso5nCtnkn
++4rnvyOL2NSl6dPrFf4IFYqYK6miyeUcGbvJXqBUzxvd4Sj1Ce2t+/vdG6tHrju+I
++aFvowdlxfv1k7/9nR4hYJS8+hge9+6jlgqispdNpQ80xiEmEU5LAsTkbOYMBMMTy
++qfrQA71yN2BWHzZ8vTmR9W0Nv3vXkg==
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/GTS_Root_R1.pem.orig
++++ secure/caroot/trusted/GTS_Root_R1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GTS_Root_R2.pem.orig
++++ secure/caroot/trusted/GTS_Root_R2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GTS_Root_R3.pem.orig
++++ secure/caroot/trusted/GTS_Root_R3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GTS_Root_R4.pem.orig
++++ secure/caroot/trusted/GTS_Root_R4.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
+@@ -1,68 +0,0 @@
+-##
+-## GeoTrust Primary Certification Authority - G2
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 3c:b2:f4:48:0a:00:e2:fe:eb:24:3b:5e:60:3e:c3:6b
+- Signature Algorithm: ecdsa-with-SHA384
+- Issuer: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
+- Validity
+- Not Before: Nov 5 00:00:00 2007 GMT
+- Not After : Jan 18 23:59:59 2038 GMT
+- Subject: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
+- Subject Public Key Info:
+- Public Key Algorithm: id-ecPublicKey
+- Public-Key: (384 bit)
+- pub:
+- 04:15:b1:e8:fd:03:15:43:e5:ac:eb:87:37:11:62:
+- ef:d2:83:36:52:7d:45:57:0b:4a:8d:7b:54:3b:3a:
+- 6e:5f:15:02:c0:50:a6:cf:25:2f:7d:ca:48:b8:c7:
+- 50:63:1c:2a:21:08:7c:9a:36:d8:0b:fe:d1:26:c5:
+- 58:31:30:28:25:f3:5d:5d:a3:b8:b6:a5:b4:92:ed:
+- 6c:2c:9f:eb:dd:43:89:a2:3c:4b:48:91:1d:50:ec:
+- 26:df:d6:60:2e:bd:21
+- ASN1 OID: secp384r1
+- NIST CURVE: P-384
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Subject Key Identifier:
+- 15:5F:35:57:51:55:FB:25:B2:AD:03:69:FC:01:A3:FA:BE:11:55:D5
+- Signature Algorithm: ecdsa-with-SHA384
+- 30:64:02:30:64:96:59:a6:e8:09:de:8b:ba:fa:5a:88:88:f0:
+- 1f:91:d3:46:a8:f2:4a:4c:02:63:fb:6c:5f:38:db:2e:41:93:
+- a9:0e:e6:9d:dc:31:1c:b2:a0:a7:18:1c:79:e1:c7:36:02:30:
+- 3a:56:af:9a:74:6c:f6:fb:83:e0:33:d3:08:5f:a1:9c:c2:5b:
+- 9f:46:d6:b6:cb:91:06:63:a2:06:e7:33:ac:3e:a8:81:12:d0:
+- cb:ba:d0:92:0b:b6:9e:96:aa:04:0f:8a
+-SHA1 Fingerprint=8D:17:84:D5:37:F3:03:7D:EC:70:FE:57:8B:51:9A:99:E6:10:D7:B0
+------BEGIN CERTIFICATE-----
+-MIICrjCCAjWgAwIBAgIQPLL0SAoA4v7rJDteYD7DazAKBggqhkjOPQQDAzCBmDEL
+-MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUdlb1RydXN0IEluYy4xOTA3BgNVBAsTMChj
+-KSAyMDA3IEdlb1RydXN0IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTE2
+-MDQGA1UEAxMtR2VvVHJ1c3QgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
+-eSAtIEcyMB4XDTA3MTEwNTAwMDAwMFoXDTM4MDExODIzNTk1OVowgZgxCzAJBgNV
+-BAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMTkwNwYDVQQLEzAoYykgMjAw
+-NyBHZW9UcnVzdCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxNjA0BgNV
+-BAMTLUdlb1RydXN0IFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBH
+-MjB2MBAGByqGSM49AgEGBSuBBAAiA2IABBWx6P0DFUPlrOuHNxFi79KDNlJ9RVcL
+-So17VDs6bl8VAsBQps8lL33KSLjHUGMcKiEIfJo22Av+0SbFWDEwKCXzXV2juLal
+-tJLtbCyf691DiaI8S0iRHVDsJt/WYC69IaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAO
+-BgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFBVfNVdRVfslsq0DafwBo/q+EVXVMAoG
+-CCqGSM49BAMDA2cAMGQCMGSWWaboCd6LuvpaiIjwH5HTRqjySkwCY/tsXzjbLkGT
+-qQ7mndwxHLKgpxgceeHHNgIwOlavmnRs9vuD4DPTCF+hnMJbn0bWtsuRBmOiBucz
+-rD6ogRLQy7rQkgu2npaqBA+K
+------END CERTIFICATE-----
+--- secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem.orig
++++ secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem.orig
++++ secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- /dev/null
++++ secure/caroot/trusted/GlobalSign_Root_E46.pem
+@@ -0,0 +1,66 @@
++##
++## GlobalSign Root E46
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root E46
++ Validity
++ Not Before: Mar 20 00:00:00 2019 GMT
++ Not After : Mar 20 00:00:00 2046 GMT
++ Subject: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root E46
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:9c:0e:b1:cf:b7:e8:9e:52:77:75:34:fa:a5:46:
++ a7:ad:32:19:32:b4:07:a9:27:ca:94:bb:0c:d2:0a:
++ 10:c7:da:89:b0:97:0c:70:13:09:01:8e:d8:ea:47:
++ ea:be:b2:80:2b:cd:fc:28:0d:db:ac:bc:a4:86:37:
++ ed:70:08:00:75:ea:93:0b:7b:2e:52:9c:23:68:23:
++ 06:43:ec:92:2f:53:84:db:fb:47:14:07:e8:5f:94:
++ 67:5d:c9:7a:81:3c:20
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 31:0A:90:8F:B6:C6:9D:D2:44:4B:80:B5:A2:E6:1F:B1:12:4F:1B:95
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:65:02:31:00:df:54:90:ed:9b:ef:8b:94:02:93:17:82:99:
++ be:b3:9e:2c:f6:0b:91:8c:9f:4a:14:b1:f6:64:bc:bb:68:51:
++ 13:0c:03:f7:15:8b:84:60:b9:8b:ff:52:8e:e7:8c:bc:1c:02:
++ 30:3c:f9:11:d4:8c:4e:c0:c1:61:c2:15:4c:aa:ab:1d:0b:31:
++ 5f:3b:1c:e2:00:97:44:31:e6:fe:73:96:2f:da:96:d3:fe:08:
++ 07:b3:34:89:bc:05:9f:f7:1e:86:ee:8b:70
++SHA1 Fingerprint=39:B4:6C:D5:FE:80:06:EB:E2:2F:4A:BB:08:33:A0:AF:DB:B9:DD:84
++-----BEGIN CERTIFICATE-----
++MIICCzCCAZGgAwIBAgISEdK7ujNu1LzmJGjFDYQdmOhDMAoGCCqGSM49BAMDMEYx
++CzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMRwwGgYDVQQD
++ExNHbG9iYWxTaWduIFJvb3QgRTQ2MB4XDTE5MDMyMDAwMDAwMFoXDTQ2MDMyMDAw
++MDAwMFowRjELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2Ex
++HDAaBgNVBAMTE0dsb2JhbFNpZ24gUm9vdCBFNDYwdjAQBgcqhkjOPQIBBgUrgQQA
++IgNiAAScDrHPt+ieUnd1NPqlRqetMhkytAepJ8qUuwzSChDH2omwlwxwEwkBjtjq
++R+q+soArzfwoDdusvKSGN+1wCAB16pMLey5SnCNoIwZD7JIvU4Tb+0cUB+hflGdd
++yXqBPCCjQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
++DgQWBBQxCpCPtsad0kRLgLWi5h+xEk8blTAKBggqhkjOPQQDAwNoADBlAjEA31SQ
++7Zvvi5QCkxeCmb6zniz2C5GMn0oUsfZkvLtoURMMA/cVi4RguYv/Uo7njLwcAjA8
+++RHUjE7AwWHCFUyqqx0LMV87HOIAl0Qx5v5zli/altP+CAezNIm8BZ/3Hobui3A=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/trusted/GlobalSign_Root_R46.pem
+@@ -0,0 +1,134 @@
++##
++## GlobalSign Root R46
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 11:d2:bb:b9:d7:23:18:9e:40:5f:0a:9d:2d:d0:df:25:67:d1
++ Signature Algorithm: sha384WithRSAEncryption
++ Issuer: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root R46
++ Validity
++ Not Before: Mar 20 00:00:00 2019 GMT
++ Not After : Mar 20 00:00:00 2046 GMT
++ Subject: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root R46
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:ac:ac:74:32:e8:b3:65:e5:ba:ed:43:26:1d:a6:
++ 89:0d:45:ba:29:88:b2:a4:1d:63:dd:d3:c1:2c:09:
++ 57:89:39:a1:55:e9:67:34:77:0c:6e:e4:55:1d:52:
++ 25:d2:13:6b:5e:e1:1d:a9:b7:7d:89:32:5f:0d:9e:
++ 9f:2c:7a:63:60:40:1f:a6:b0:b6:78:8f:99:54:96:
++ 08:58:ae:e4:06:bc:62:05:02:16:bf:af:a8:23:03:
++ b6:94:0f:bc:6e:6c:c2:cb:d5:a6:bb:0c:e9:f6:c1:
++ 02:fb:21:de:66:dd:17:ab:74:42:ef:f0:74:2f:25:
++ f4:ea:6b:55:5b:90:db:9d:df:5e:87:0a:40:fb:ad:
++ 19:6b:fb:f7:ca:60:88:de:da:c1:8f:d6:ae:d5:7f:
++ d4:3c:83:ee:d7:16:4c:83:45:33:6b:27:d0:86:d0:
++ 1c:2d:6b:f3:ab:7d:f1:85:a9:f5:28:d2:ad:ef:f3:
++ 84:4b:1c:87:fc:13:a3:3a:72:a2:5a:11:2b:d6:27:
++ 71:27:ed:81:2d:6d:66:81:92:87:b4:1b:58:7a:cc:
++ 3f:0a:fa:46:4f:4d:78:5c:f8:2b:48:e3:04:84:cb:
++ 5d:f6:b4:6a:b3:65:fc:42:9e:51:26:23:20:cb:3d:
++ 14:f9:81:ed:65:16:00:4f:1a:64:97:66:08:cf:8c:
++ 7b:e3:2b:c0:9d:f9:14:f2:1b:f1:56:6a:16:bf:2c:
++ 85:85:cd:78:38:9a:eb:42:6a:02:34:18:83:17:4e:
++ 94:56:f8:b6:82:b5:f3:96:dd:3d:f3:be:7f:20:77:
++ 3e:7b:19:23:6b:2c:d4:72:73:43:57:7d:e0:f8:d7:
++ 69:4f:17:36:04:f9:c0:90:60:37:45:de:e6:0c:d8:
++ 74:8d:ae:9c:a2:6d:74:5d:42:be:06:f5:d9:64:6e:
++ 02:10:ac:89:b0:4c:3b:07:4d:40:7e:24:c5:8a:98:
++ 82:79:8e:a4:a7:82:20:8d:23:fa:27:71:c9:df:c6:
++ 41:74:a0:4d:f6:91:16:dc:46:8c:5f:29:63:31:59:
++ 71:0c:d8:6f:c2:b6:32:7d:fb:e6:5d:53:a6:7e:15:
++ fc:bb:75:7c:5d:ec:f8:f6:17:1c:ec:c7:6b:19:cb:
++ f3:7b:f0:2b:07:a5:d9:6c:79:54:76:6c:9d:1c:a6:
++ 6e:0e:e9:79:0c:a8:23:6a:a3:df:1b:30:31:9f:b1:
++ 54:7b:fe:6a:cb:66:aa:dc:65:d0:a2:9e:4a:9a:07:
++ 21:6b:81:8f:db:c4:59:fa:de:22:c0:04:9c:e3:aa:
++ 5b:36:93:e8:3d:bd:7a:a1:9d:0b:76:b1:0b:c7:9d:
++ fd:cf:98:a8:06:c2:f8:2a:a3:a1:83:a0:b7:25:72:
++ a5:02:e3
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 03:5C:AB:73:81:87:A8:CC:B0:A6:D5:94:E2:36:96:49:FF:05:99:2C
++ Signature Algorithm: sha384WithRSAEncryption
++ 7c:78:ec:f6:02:2c:bb:5b:7e:92:2b:5d:39:dc:be:d8:1d:a2:
++ 42:33:4d:f9:ef:a4:2a:3b:44:69:1e:ac:d9:45:a3:4e:3c:a7:
++ d8:24:51:b2:54:1c:93:4e:c4:ef:7b:93:85:60:26:ea:09:48:
++ e0:f5:bb:c7:e9:68:d2:bb:6a:31:71:cc:79:ae:11:a8:f0:99:
++ fd:e5:1f:bc:2f:a8:cc:57:eb:76:c4:21:a6:47:53:55:4d:68:
++ bf:05:a4:ee:d7:26:ab:62:da:43:37:4b:e2:c6:b5:e5:b2:83:
++ 19:3a:c7:d3:db:4d:9e:08:7a:f3:ee:cf:3e:62:fb:ac:e8:60:
++ cc:d1:c7:a1:5c:83:45:c4:45:cc:f3:17:6b:14:c9:04:02:3e:
++ d2:24:a6:79:e9:1e:ce:a2:e7:c1:59:15:9f:1d:e2:4b:9a:3e:
++ 9f:76:08:2d:6b:d8:ba:57:14:da:83:ea:fe:8c:55:e9:d0:4e:
++ a9:cc:77:31:b1:44:11:7a:5c:b1:3e:d3:14:45:15:18:62:24:
++ 13:d2:cb:4d:ce:5c:83:c1:36:f2:10:b5:0e:88:6d:b8:e1:56:
++ 9f:89:de:96:66:39:47:64:2c:6e:4d:ae:62:7b:bf:60:74:19:
++ b8:56:ac:92:ac:16:32:ed:ad:68:55:fe:98:ba:d3:34:de:f4:
++ c9:61:c3:0e:86:f6:4b:84:60:ee:0d:7b:b5:32:58:79:91:55:
++ 2c:81:43:b3:74:1f:7a:aa:25:9e:1d:d7:a1:8b:b9:cd:42:2e:
++ 04:a4:66:83:4d:89:35:b6:6c:a8:36:4a:79:21:78:22:d0:42:
++ bc:d1:40:31:90:a1:be:04:cf:ca:67:ed:f5:f0:80:d3:60:c9:
++ 83:2a:22:05:d0:07:3b:52:bf:0c:9e:aa:2b:f9:bb:e6:1f:8f:
++ 25:ba:85:8d:17:1e:02:fe:5d:50:04:57:cf:fe:2d:bc:ef:5c:
++ c0:1a:ab:b6:9f:24:c6:df:73:68:48:90:2c:14:f4:3f:52:1a:
++ e4:d2:cb:14:c3:61:69:cf:e2:f9:18:c5:ba:33:9f:14:a3:04:
++ 5d:b9:71:f7:b5:94:d8:f6:33:c1:5a:c1:34:8b:7c:9b:dd:93:
++ 3a:e7:13:a2:70:61:9f:af:8f:eb:d8:c5:75:f8:33:66:d4:74:
++ 67:3a:37:77:9c:e7:dd:a4:0f:76:43:66:8a:43:f2:9f:fb:0c:
++ 42:78:63:d1:e2:0f:6f:7b:d4:a1:3d:74:97:85:b7:48:39:41:
++ d6:20:fc:d0:3a:b3:fa:e8:6f:c4:8a:ba:71:37:be:8b:97:b1:
++ 78:31:4f:b3:e7:b6:03:13:ce:54:9d:ae:25:59:cc:7f:35:5f:
++ 08:f7:40:45:31:78:2a:7a
++SHA1 Fingerprint=53:A2:B0:4B:CA:6B:D6:45:E6:39:8A:8E:C4:0D:D2:BF:77:C3:A2:90
++-----BEGIN CERTIFICATE-----
++MIIFWjCCA0KgAwIBAgISEdK7udcjGJ5AXwqdLdDfJWfRMA0GCSqGSIb3DQEBDAUA
++MEYxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMRwwGgYD
++VQQDExNHbG9iYWxTaWduIFJvb3QgUjQ2MB4XDTE5MDMyMDAwMDAwMFoXDTQ2MDMy
++MDAwMDAwMFowRjELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYt
++c2ExHDAaBgNVBAMTE0dsb2JhbFNpZ24gUm9vdCBSNDYwggIiMA0GCSqGSIb3DQEB
++AQUAA4ICDwAwggIKAoICAQCsrHQy6LNl5brtQyYdpokNRbopiLKkHWPd08EsCVeJ
++OaFV6Wc0dwxu5FUdUiXSE2te4R2pt32JMl8Nnp8semNgQB+msLZ4j5lUlghYruQG
++vGIFAha/r6gjA7aUD7xubMLL1aa7DOn2wQL7Id5m3RerdELv8HQvJfTqa1VbkNud
++316HCkD7rRlr+/fKYIje2sGP1q7Vf9Q8g+7XFkyDRTNrJ9CG0Bwta/OrffGFqfUo
++0q3v84RLHIf8E6M6cqJaESvWJ3En7YEtbWaBkoe0G1h6zD8K+kZPTXhc+CtI4wSE
++y132tGqzZfxCnlEmIyDLPRT5ge1lFgBPGmSXZgjPjHvjK8Cd+RTyG/FWaha/LIWF
++zXg4mutCagI0GIMXTpRW+LaCtfOW3T3zvn8gdz57GSNrLNRyc0NXfeD412lPFzYE
+++cCQYDdF3uYM2HSNrpyibXRdQr4G9dlkbgIQrImwTDsHTUB+JMWKmIJ5jqSngiCN
++I/onccnfxkF0oE32kRbcRoxfKWMxWXEM2G/CtjJ9++ZdU6Z+Ffy7dXxd7Pj2Fxzs
++x2sZy/N78CsHpdlseVR2bJ0cpm4O6XkMqCNqo98bMDGfsVR7/mrLZqrcZdCinkqa
++ByFrgY/bxFn63iLABJzjqls2k+g9vXqhnQt2sQvHnf3PmKgGwvgqo6GDoLclcqUC
++4wIDAQABo0IwQDAOBgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
++HQ4EFgQUA1yrc4GHqMywptWU4jaWSf8FmSwwDQYJKoZIhvcNAQEMBQADggIBAHx4
++7PYCLLtbfpIrXTncvtgdokIzTfnvpCo7RGkerNlFo048p9gkUbJUHJNOxO97k4Vg
++JuoJSOD1u8fpaNK7ajFxzHmuEajwmf3lH7wvqMxX63bEIaZHU1VNaL8FpO7XJqti
++2kM3S+LGteWygxk6x9PbTZ4IevPuzz5i+6zoYMzRx6Fcg0XERczzF2sUyQQCPtIk
++pnnpHs6i58FZFZ8d4kuaPp92CC1r2LpXFNqD6v6MVenQTqnMdzGxRBF6XLE+0xRF
++FRhiJBPSy03OXIPBNvIQtQ6IbbjhVp+J3pZmOUdkLG5NrmJ7v2B0GbhWrJKsFjLt
++rWhV/pi60zTe9Mlhww6G9kuEYO4Ne7UyWHmRVSyBQ7N0H3qqJZ4d16GLuc1CLgSk
++ZoNNiTW2bKg2SnkheCLQQrzRQDGQob4Ez8pn7fXwgNNgyYMqIgXQBztSvwyeqiv5
++u+YfjyW6hY0XHgL+XVAEV8/+LbzvXMAaq7afJMbfc2hIkCwU9D9SGuTSyxTDYWnP
++4vkYxboznxSjBF25cfe1lNj2M8FawTSLfJvdkzrnE6JwYZ+vj+vYxXX4M2bUdGc6
++N3ec592kD3ZDZopD8p/7DEJ4Y9HiD2971KE9dJeFt0g5QdYg/NA6s/rob8SKunE3
++vouXsXgxT7PntgMTzlSdriVZzH81Xwj3QEUxeCp6
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem.orig
++++ secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem
+@@ -1,151 +0,0 @@
+-##
+-## Global Chambersign Root - 2008
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- c9:cd:d3:e9:d5:7d:23:ce
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
+- Validity
+- Not Before: Aug 1 12:31:40 2008 GMT
+- Not After : Jul 31 12:31:40 2038 GMT
+- Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:c0:df:56:d3:e4:3a:9b:76:45:b4:13:db:ff:c1:
+- b6:19:8b:37:41:18:95:52:47:eb:17:9d:29:88:8e:
+- 35:6c:06:32:2e:47:62:f3:49:04:bf:7d:44:36:b1:
+- 71:cc:bd:5a:09:73:d5:d9:85:44:ff:91:57:25:df:
+- 5e:36:8e:70:d1:5c:71:43:1d:d9:da:ef:5c:d2:fb:
+- 1b:bd:3a:b5:cb:ad:a3:cc:44:a7:0d:ae:21:15:3f:
+- b9:7a:5b:92:75:d8:a4:12:38:89:19:8a:b7:80:d2:
+- e2:32:6f:56:9c:91:d6:88:10:0b:b3:74:64:92:74:
+- 60:f3:f6:cf:18:4f:60:b2:23:d0:c7:3b:ce:61:4b:
+- 99:8f:c2:0c:d0:40:b2:98:dc:0d:a8:4e:a3:b9:0a:
+- ae:60:a0:ad:45:52:63:ba:66:bd:68:e0:f9:be:1a:
+- a8:81:bb:1e:41:78:75:d3:c1:fe:00:55:b0:87:54:
+- e8:27:90:35:1d:4c:33:ad:97:fc:97:2e:98:84:bf:
+- 2c:c9:a3:bf:d1:98:11:14:ed:63:f8:ca:98:88:58:
+- 17:99:ed:45:03:97:7e:3c:86:1e:88:8c:be:f2:91:
+- 84:8f:65:34:d8:00:4c:7d:b7:31:17:5a:29:7a:0a:
+- 18:24:30:a3:37:b5:7a:a9:01:7d:26:d6:f9:0e:8e:
+- 59:f1:fd:1b:33:b5:29:3b:17:3b:41:b6:21:dd:d4:
+- c0:3d:a5:9f:9f:1f:43:50:c9:bb:bc:6c:7a:97:98:
+- ee:cd:8c:1f:fb:9c:51:ae:8b:70:bd:27:9f:71:c0:
+- 6b:ac:7d:90:66:e8:d7:5d:3a:0d:b0:d5:c2:8d:d5:
+- c8:9d:9d:c1:6d:d0:d0:bf:51:e4:e3:f8:c3:38:36:
+- ae:d6:a7:75:e6:af:84:43:5d:93:92:0c:6a:07:de:
+- 3b:1d:98:22:d6:ac:c1:35:db:a3:a0:25:ff:72:b5:
+- 76:1d:de:6d:e9:2c:66:2c:52:84:d0:45:92:ce:1c:
+- e5:e5:33:1d:dc:07:53:54:a3:aa:82:3b:9a:37:2f:
+- dc:dd:a0:64:e9:e6:dd:bd:ae:fc:64:85:1d:3c:a7:
+- c9:06:de:84:ff:6b:e8:6b:1a:3c:c5:a2:b3:42:fb:
+- 8b:09:3e:5f:08:52:c7:62:c4:d4:05:71:bf:c4:64:
+- e4:f8:a1:83:e8:3e:12:9b:a8:1e:d4:36:4d:2f:71:
+- f6:8d:28:f6:83:a9:13:d2:61:c1:91:bb:48:c0:34:
+- 8f:41:8c:4b:4c:db:69:12:ff:50:94:9c:20:83:59:
+- 73:ed:7c:a1:f2:f1:fd:dd:f7:49:d3:43:58:a0:56:
+- 63:ca:3d:3d:e5:35:56:59:e9:0e:ca:20:cc:2b:4b:
+- 93:29:0f
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 Subject Key Identifier:
+- B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
+- X509v3 Authority Key Identifier:
+- keyid:B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
+- DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Global Chambersign Root - 2008
+- serial:C9:CD:D3:E9:D5:7D:23:CE
+-
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Certificate Policies:
+- Policy: X509v3 Any Policy
+- CPS: http://policy.camerfirma.com
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 80:88:7f:70:de:92:28:d9:05:94:46:ff:90:57:a9:f1:2f:df:
+- 1a:0d:6b:fa:7c:0e:1c:49:24:79:27:d8:46:aa:6f:29:59:52:
+- 88:70:12:ea:dd:3d:f5:9b:53:54:6f:e1:60:a2:a8:09:b9:ec:
+- eb:59:7c:c6:35:f1:dc:18:e9:f1:67:e5:af:ba:45:e0:09:de:
+- ca:44:0f:c2:17:0e:77:91:45:7a:33:5f:5f:96:2c:68:8b:c1:
+- 47:8f:98:9b:3d:c0:ec:cb:f5:d5:82:92:84:35:d1:be:36:38:
+- 56:72:31:5b:47:2d:aa:17:a4:63:51:eb:0a:01:ad:7f:ec:75:
+- 9e:cb:a1:1f:f1:7f:12:b1:b9:e4:64:7f:67:d6:23:2a:f4:b8:
+- 39:5d:98:e8:21:a7:e1:bd:3d:42:1a:74:9a:70:af:68:6c:50:
+- 5d:49:cf:ff:fb:0e:5d:e6:2c:47:d7:81:3a:59:00:b5:73:6b:
+- 63:20:f6:31:45:08:39:0e:f4:70:7e:40:70:5a:3f:d0:6b:42:
+- a9:74:3d:28:2f:02:6d:75:72:95:09:8d:48:63:c6:c6:23:57:
+- 92:93:5e:35:c1:8d:f9:0a:f7:2c:9d:62:1c:f6:ad:7c:dd:a6:
+- 31:1e:b6:b1:c7:7e:85:26:fa:a4:6a:b5:da:63:30:d1:ef:93:
+- 37:b2:66:2f:7d:05:f7:e7:b7:4b:98:94:35:c0:d9:3a:29:c1:
+- 9d:b2:50:33:1d:4a:a9:5a:a6:c9:03:ef:ed:f4:e7:a8:6e:8a:
+- b4:57:84:eb:a4:3f:d0:ee:aa:aa:87:5b:63:e8:93:e2:6b:a8:
+- d4:b8:72:78:6b:1b:ed:39:e4:5d:cb:9b:aa:87:d5:4f:4e:00:
+- fe:d9:6a:9f:3c:31:0f:28:02:01:7d:98:e8:a7:b0:a2:64:9e:
+- 79:f8:48:f2:15:a9:cc:e6:c8:44:eb:3f:78:99:f2:7b:71:3e:
+- 3c:f1:98:a7:c5:18:12:3f:e6:bb:28:33:42:e9:45:0a:7c:6d:
+- f2:86:79:2f:c5:82:19:7d:09:89:7c:b2:54:76:88:ae:de:c1:
+- f3:cc:e1:6e:db:31:d6:93:ae:99:a0:ef:25:6a:73:98:89:5b:
+- 3a:2e:13:88:1e:bf:c0:92:94:34:1b:e3:27:b7:8b:1e:6f:42:
+- ff:e7:e9:37:9b:50:1d:2d:a2:f9:02:ee:cb:58:58:3a:71:bc:
+- 68:e3:aa:c1:af:1c:28:1f:a2:dc:23:65:3f:81:ea:ae:99:d3:
+- d8:30:cf:13:0d:4f:15:c9:84:bc:a7:48:2d:f8:30:23:77:d8:
+- 46:4b:79:6d:f6:8c:ed:3a:7f:60:11:78:f4:e9:9b:ae:d5:54:
+- c0:74:80:d1:0b:42:9f:c1
+-SHA1 Fingerprint=4A:BD:EE:EC:95:0D:35:9C:89:AE:C7:52:A1:2C:5B:29:F6:D6:AA:0C
+------BEGIN CERTIFICATE-----
+-MIIHSTCCBTGgAwIBAgIJAMnN0+nVfSPOMA0GCSqGSIb3DQEBBQUAMIGsMQswCQYD
+-VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
+-IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
+-MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAlBgNVBAMTHkdsb2JhbCBD
+-aGFtYmVyc2lnbiBSb290IC0gMjAwODAeFw0wODA4MDExMjMxNDBaFw0zODA3MzEx
+-MjMxNDBaMIGsMQswCQYDVQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3Vy
+-cmVudCBhZGRyZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAG
+-A1UEBRMJQTgyNzQzMjg3MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAl
+-BgNVBAMTHkdsb2JhbCBDaGFtYmVyc2lnbiBSb290IC0gMjAwODCCAiIwDQYJKoZI
+-hvcNAQEBBQADggIPADCCAgoCggIBAMDfVtPkOpt2RbQT2//BthmLN0EYlVJH6xed
+-KYiONWwGMi5HYvNJBL99RDaxccy9Wglz1dmFRP+RVyXfXjaOcNFccUMd2drvXNL7
+-G706tcuto8xEpw2uIRU/uXpbknXYpBI4iRmKt4DS4jJvVpyR1ogQC7N0ZJJ0YPP2
+-zxhPYLIj0Mc7zmFLmY/CDNBAspjcDahOo7kKrmCgrUVSY7pmvWjg+b4aqIG7HkF4
+-ddPB/gBVsIdU6CeQNR1MM62X/JcumIS/LMmjv9GYERTtY/jKmIhYF5ntRQOXfjyG
+-HoiMvvKRhI9lNNgATH23MRdaKXoKGCQwoze1eqkBfSbW+Q6OWfH9GzO1KTsXO0G2
+-Id3UwD2ln58fQ1DJu7xsepeY7s2MH/ucUa6LcL0nn3HAa6x9kGbo1106DbDVwo3V
+-yJ2dwW3Q0L9R5OP4wzg2rtandeavhENdk5IMagfeOx2YItaswTXbo6Al/3K1dh3e
+-beksZixShNBFks4c5eUzHdwHU1SjqoI7mjcv3N2gZOnm3b2u/GSFHTynyQbehP9r
+-6GsaPMWis0L7iwk+XwhSx2LE1AVxv8Rk5Pihg+g+EpuoHtQ2TS9x9o0o9oOpE9Jh
+-wZG7SMA0j0GMS0zbaRL/UJScIINZc+18ofLx/d33SdNDWKBWY8o9PeU1VlnpDsog
+-zCtLkykPAgMBAAGjggFqMIIBZjASBgNVHRMBAf8ECDAGAQH/AgEMMB0GA1UdDgQW
+-BBS5CcqcHtvTbDprru1U8VuTBjUuXjCB4QYDVR0jBIHZMIHWgBS5CcqcHtvTbDpr
+-ru1U8VuTBjUuXqGBsqSBrzCBrDELMAkGA1UEBhMCRVUxQzBBBgNVBAcTOk1hZHJp
+-ZCAoc2VlIGN1cnJlbnQgYWRkcmVzcyBhdCB3d3cuY2FtZXJmaXJtYS5jb20vYWRk
+-cmVzcykxEjAQBgNVBAUTCUE4Mjc0MzI4NzEbMBkGA1UEChMSQUMgQ2FtZXJmaXJt
+-YSBTLkEuMScwJQYDVQQDEx5HbG9iYWwgQ2hhbWJlcnNpZ24gUm9vdCAtIDIwMDiC
+-CQDJzdPp1X0jzjAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRVHSAAMCow
+-KAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20wDQYJKoZI
+-hvcNAQEFBQADggIBAICIf3DekijZBZRG/5BXqfEv3xoNa/p8DhxJJHkn2EaqbylZ
+-UohwEurdPfWbU1Rv4WCiqAm57OtZfMY18dwY6fFn5a+6ReAJ3spED8IXDneRRXoz
+-X1+WLGiLwUePmJs9wOzL9dWCkoQ10b42OFZyMVtHLaoXpGNR6woBrX/sdZ7LoR/x
+-fxKxueRkf2fWIyr0uDldmOghp+G9PUIadJpwr2hsUF1Jz//7Dl3mLEfXgTpZALVz
+-a2Mg9jFFCDkO9HB+QHBaP9BrQql0PSgvAm11cpUJjUhjxsYjV5KTXjXBjfkK9yyd
+-Yhz2rXzdpjEetrHHfoUm+qRqtdpjMNHvkzeyZi99Bffnt0uYlDXA2TopwZ2yUDMd
+-SqlapskD7+3056huirRXhOukP9DuqqqHW2Pok+JrqNS4cnhrG+055F3Lm6qH1U9O
+-AP7Zap88MQ8oAgF9mOinsKJknnn4SPIVqczmyETrP3iZ8ntxPjzxmKfFGBI/5rso
+-M0LpRQp8bfKGeS/Fghl9CYl8slR2iK7ewfPM4W7bMdaTrpmg7yVqc5iJWzouE4ge
+-v8CSlDQb4ye3ix5vQv/n6TebUB0tovkC7stYWDpxvGjjqsGvHCgfotwjZT+B6q6Z
+-09gwzxMNTxXJhLynSC34MCN32EZLeW32jO06f2ARePTpm67VVMB0gNELQp/B
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Go_Daddy_Class_2_CA.pem.orig
++++ secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem.orig
++++ secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem.orig
++++ secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem.orig
++++ secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem.orig
++++ secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem.orig
++++ secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/ISRG_Root_X1.pem.orig
++++ secure/caroot/trusted/ISRG_Root_X1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem.orig
++++ secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem.orig
++++ secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Izenpe_com.pem.orig
++++ secure/caroot/trusted/Izenpe_com.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem.orig
++++ secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Microsoft_ECC_Root_Certificate_Authority_2017.pem.orig
++++ secure/caroot/trusted/Microsoft_ECC_Root_Certificate_Authority_2017.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Microsoft_RSA_Root_Certificate_Authority_2017.pem.orig
++++ secure/caroot/trusted/Microsoft_RSA_Root_Certificate_Authority_2017.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem.orig
++++ secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem.orig
++++ secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem.orig
++++ secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
+@@ -1,96 +0,0 @@
+-##
+-## OISTE WISeKey Global Root GA CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 41:3d:72:c7:f4:6b:1f:81:43:7d:f1:d2:28:54:df:9a
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
+- Validity
+- Not Before: Dec 11 16:03:44 2005 GMT
+- Not After : Dec 11 16:09:51 2037 GMT
+- Subject: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:cb:4f:b3:00:9b:3d:36:dd:f9:d1:49:6a:6b:10:
+- 49:1f:ec:d8:2b:b2:c6:f8:32:81:29:43:95:4c:9a:
+- 19:23:21:15:45:de:e3:c8:1c:51:55:5b:ae:93:e8:
+- 37:ff:2b:6b:e9:d4:ea:be:2a:dd:a8:51:2b:d7:66:
+- c3:61:5c:60:02:c8:f5:ce:72:7b:3b:b8:f2:4e:65:
+- 08:9a:cd:a4:6a:19:c1:01:bb:73:a6:d7:f6:c3:dd:
+- cd:bc:a4:8b:b5:99:61:b8:01:a2:a3:d4:4d:d4:05:
+- 3d:91:ad:f8:b4:08:71:64:af:70:f1:1c:6b:7e:f6:
+- c3:77:9d:24:73:7b:e4:0c:8c:e1:d9:36:e1:99:8b:
+- 05:99:0b:ed:45:31:09:ca:c2:00:db:f7:72:a0:96:
+- aa:95:87:d0:8e:c7:b6:61:73:0d:76:66:8c:dc:1b:
+- b4:63:a2:9f:7f:93:13:30:f1:a1:27:db:d9:ff:2c:
+- 55:88:91:a0:e0:4f:07:b0:28:56:8c:18:1b:97:44:
+- 8e:89:dd:e0:17:6e:e7:2a:ef:8f:39:0a:31:84:82:
+- d8:40:14:49:2e:7a:41:e4:a7:fe:e3:64:cc:c1:59:
+- 71:4b:2c:21:a7:5b:7d:e0:1d:d1:2e:81:9b:c3:d8:
+- 68:f7:bd:96:1b:ac:70:b1:16:14:0b:db:60:b9:26:
+- 01:05
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage:
+- Digital Signature, Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- B3:03:7E:AE:36:BC:B0:79:D1:DC:94:26:B6:11:BE:21:B2:69:86:94
+- 1.3.6.1.4.1.311.21.1:
+- ...
+- Signature Algorithm: sha1WithRSAEncryption
+- 4b:a1:ff:0b:87:6e:b3:f9:c1:43:b1:48:f3:28:c0:1d:2e:c9:
+- 09:41:fa:94:00:1c:a4:a4:ab:49:4f:8f:3d:1e:ef:4d:6f:bd:
+- bc:a4:f6:f2:26:30:c9:10:ca:1d:88:fb:74:19:1f:85:45:bd:
+- b0:6c:51:f9:36:7e:db:f5:4c:32:3a:41:4f:5b:47:cf:e8:0b:
+- 2d:b6:c4:19:9d:74:c5:47:c6:3b:6a:0f:ac:14:db:3c:f4:73:
+- 9c:a9:05:df:00:dc:74:78:fa:f8:35:60:59:02:13:18:7c:bc:
+- fb:4d:b0:20:6d:43:bb:60:30:7a:67:33:5c:c5:99:d1:f8:2d:
+- 39:52:73:fb:8c:aa:97:25:5c:72:d9:08:1e:ab:4e:3c:e3:81:
+- 31:9f:03:a6:fb:c0:fe:29:88:55:da:84:d5:50:03:b6:e2:84:
+- a3:a6:36:aa:11:3a:01:e1:18:4b:d6:44:68:b3:3d:f9:53:74:
+- 84:b3:46:91:46:96:00:b7:80:2c:b6:e1:e3:10:e2:db:a2:e7:
+- 28:8f:01:96:62:16:3e:00:e3:1c:a5:36:81:18:a2:4c:52:76:
+- c0:11:a3:6e:e6:1d:ba:e3:5a:be:36:53:c5:3e:75:8f:86:69:
+- 29:58:53:b5:9c:bb:6f:9f:5c:c5:18:ec:dd:2f:e1:98:c9:fc:
+- be:df:0a:0d
+-SHA1 Fingerprint=59:22:A1:E1:5A:EA:16:35:21:F8:98:39:6A:46:46:B0:44:1B:0F:A9
+------BEGIN CERTIFICATE-----
+-MIID8TCCAtmgAwIBAgIQQT1yx/RrH4FDffHSKFTfmjANBgkqhkiG9w0BAQUFADCB
+-ijELMAkGA1UEBhMCQ0gxEDAOBgNVBAoTB1dJU2VLZXkxGzAZBgNVBAsTEkNvcHly
+-aWdodCAoYykgMjAwNTEiMCAGA1UECxMZT0lTVEUgRm91bmRhdGlvbiBFbmRvcnNl
+-ZDEoMCYGA1UEAxMfT0lTVEUgV0lTZUtleSBHbG9iYWwgUm9vdCBHQSBDQTAeFw0w
+-NTEyMTExNjAzNDRaFw0zNzEyMTExNjA5NTFaMIGKMQswCQYDVQQGEwJDSDEQMA4G
+-A1UEChMHV0lTZUtleTEbMBkGA1UECxMSQ29weXJpZ2h0IChjKSAyMDA1MSIwIAYD
+-VQQLExlPSVNURSBGb3VuZGF0aW9uIEVuZG9yc2VkMSgwJgYDVQQDEx9PSVNURSBX
+-SVNlS2V5IEdsb2JhbCBSb290IEdBIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+-MIIBCgKCAQEAy0+zAJs9Nt350UlqaxBJH+zYK7LG+DKBKUOVTJoZIyEVRd7jyBxR
+-VVuuk+g3/ytr6dTqvirdqFEr12bDYVxgAsj1znJ7O7jyTmUIms2kahnBAbtzptf2
+-w93NvKSLtZlhuAGio9RN1AU9ka34tAhxZK9w8RxrfvbDd50kc3vkDIzh2TbhmYsF
+-mQvtRTEJysIA2/dyoJaqlYfQjse2YXMNdmaM3Bu0Y6Kff5MTMPGhJ9vZ/yxViJGg
+-4E8HsChWjBgbl0SOid3gF27nKu+POQoxhILYQBRJLnpB5Kf+42TMwVlxSywhp1t9
+-4B3RLoGbw9ho972WG6xwsRYUC9tguSYBBQIDAQABo1EwTzALBgNVHQ8EBAMCAYYw
+-DwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUswN+rja8sHnR3JQmthG+IbJphpQw
+-EAYJKwYBBAGCNxUBBAMCAQAwDQYJKoZIhvcNAQEFBQADggEBAEuh/wuHbrP5wUOx
+-SPMowB0uyQlB+pQAHKSkq0lPjz0e701vvbyk9vImMMkQyh2I+3QZH4VFvbBsUfk2
+-ftv1TDI6QU9bR8/oCy22xBmddMVHxjtqD6wU2zz0c5ypBd8A3HR4+vg1YFkCExh8
+-vPtNsCBtQ7tgMHpnM1zFmdH4LTlSc/uMqpclXHLZCB6rTjzjgTGfA6b7wP4piFXa
+-hNVQA7bihKOmNqoROgHhGEvWRGizPflTdISzRpFGlgC3gCy24eMQ4tui5yiPAZZi
+-Fj4A4xylNoEYokxSdsARo27mHbrjWr42U8U+dY+GaSlYU7Wcu2+fXMUY7N0v4ZjJ
+-/L7fCg0=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem.orig
++++ secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem.orig
++++ secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA.pem
+@@ -1,117 +0,0 @@
+-##
+-## QuoVadis Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 985026699 (0x3ab6508b)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
+- Validity
+- Not Before: Mar 19 18:33:33 2001 GMT
+- Not After : Mar 17 18:33:33 2021 GMT
+- Subject: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:bf:61:b5:95:53:ba:57:fc:fa:f2:67:0b:3a:1a:
+- df:11:80:64:95:b4:d1:bc:cd:7a:cf:f6:29:96:2e:
+- 24:54:40:24:38:f7:1a:85:dc:58:4c:cb:a4:27:42:
+- 97:d0:9f:83:8a:c3:e4:06:03:5b:00:a5:51:1e:70:
+- 04:74:e2:c1:d4:3a:ab:d7:ad:3b:07:18:05:8e:fd:
+- 83:ac:ea:66:d9:18:1b:68:8a:f5:57:1a:98:ba:f5:
+- ed:76:3d:7c:d9:de:94:6a:3b:4b:17:c1:d5:8f:bd:
+- 65:38:3a:95:d0:3d:55:36:4e:df:79:57:31:2a:1e:
+- d8:59:65:49:58:20:98:7e:ab:5f:7e:9f:e9:d6:4d:
+- ec:83:74:a9:c7:6c:d8:ee:29:4a:85:2a:06:14:f9:
+- 54:e6:d3:da:65:07:8b:63:37:12:d7:d0:ec:c3:7b:
+- 20:41:44:a3:ed:cb:a0:17:e1:71:65:ce:1d:66:31:
+- f7:76:01:19:c8:7d:03:58:b6:95:49:1d:a6:12:26:
+- e8:c6:0c:76:e0:e3:66:cb:ea:5d:a6:26:ee:e5:cc:
+- 5f:bd:67:a7:01:27:0e:a2:ca:54:c5:b1:7a:95:1d:
+- 71:1e:4a:29:8a:03:dc:6a:45:c1:a4:19:5e:6f:36:
+- cd:c3:a2:b0:b7:fe:5c:38:e2:52:bc:f8:44:43:e6:
+- 90:bb
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- Authority Information Access:
+- OCSP - URI:https://ocsp.quovadisoffshore.com
+-
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.8024.0.1
+- User Notice:
+- Explicit Text: Reliance on the QuoVadis Root Certificate by any party assumes acceptance of the then applicable standard terms and conditions of use, certification practices, and the QuoVadis Certificate Policy.
+- CPS: http://www.quovadis.bm
+-
+- X509v3 Subject Key Identifier:
+- 8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
+- X509v3 Authority Key Identifier:
+- keyid:8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
+- DirName:/C=BM/O=QuoVadis Limited/OU=Root Certification Authority/CN=QuoVadis Root Certification Authority
+- serial:3A:B6:50:8B
+-
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- Signature Algorithm: sha1WithRSAEncryption
+- 8a:d4:14:b5:fe:f4:9a:92:a7:19:d4:a4:7e:72:18:8f:d9:68:
+- 7c:52:24:dd:67:6f:39:7a:c4:aa:5e:3d:e2:58:b0:4d:70:98:
+- 84:61:e8:1b:e3:69:18:0e:ce:fb:47:50:a0:4e:ff:f0:24:1f:
+- bd:b2:ce:f5:27:fc:ec:2f:53:aa:73:7b:03:3d:74:6e:e6:16:
+- 9e:eb:a5:2e:c4:bf:56:27:50:2b:62:ba:be:4b:1c:3c:55:5c:
+- 41:1d:24:be:82:20:47:5d:d5:44:7e:7a:16:68:df:7d:4d:51:
+- 70:78:57:1d:33:1e:fd:02:99:9c:0c:cd:0a:05:4f:c7:bb:8e:
+- a4:75:fa:4a:6d:b1:80:8e:09:56:b9:9c:1a:60:fe:5d:c1:d7:
+- 7a:dc:11:78:d0:d6:5d:c1:b7:d5:ad:32:99:03:3a:8a:cc:54:
+- 25:39:31:81:7b:13:22:51:ba:46:6c:a1:bb:9e:fa:04:6c:49:
+- 26:74:8f:d2:73:eb:cc:30:a2:e6:ea:59:22:87:f8:97:f5:0e:
+- fd:ea:cc:92:a4:16:c4:52:18:ea:21:ce:b1:f1:e6:84:81:e5:
+- ba:a9:86:28:f2:43:5a:5d:12:9d:ac:1e:d9:a8:e5:0a:6a:a7:
+- 7f:a0:87:29:cf:f2:89:4d:d4:ec:c5:e2:e6:7a:d0:36:23:8a:
+- 4a:74:36:f9
+-SHA1 Fingerprint=DE:3F:40:BD:50:93:D3:9B:6C:60:F6:DA:BC:07:62:01:00:89:76:C9
+------BEGIN CERTIFICATE-----
+-MIIF0DCCBLigAwIBAgIEOrZQizANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJC
+-TTEZMBcGA1UEChMQUXVvVmFkaXMgTGltaXRlZDElMCMGA1UECxMcUm9vdCBDZXJ0
+-aWZpY2F0aW9uIEF1dGhvcml0eTEuMCwGA1UEAxMlUXVvVmFkaXMgUm9vdCBDZXJ0
+-aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wMTAzMTkxODMzMzNaFw0yMTAzMTcxODMz
+-MzNaMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1pdGVkMSUw
+-IwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYDVQQDEyVR
+-dW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG
+-9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2G1lVO6V/z68mcLOhrfEYBklbTRvM16z/Yp
+-li4kVEAkOPcahdxYTMukJ0KX0J+DisPkBgNbAKVRHnAEdOLB1Dqr1607BxgFjv2D
+-rOpm2RgbaIr1VxqYuvXtdj182d6UajtLF8HVj71lODqV0D1VNk7feVcxKh7YWWVJ
+-WCCYfqtffp/p1k3sg3Spx2zY7ilKhSoGFPlU5tPaZQeLYzcS19Dsw3sgQUSj7cug
+-F+FxZc4dZjH3dgEZyH0DWLaVSR2mEiboxgx24ONmy+pdpibu5cxfvWenAScOospU
+-xbF6lR1xHkopigPcakXBpBlebzbNw6Kwt/5cOOJSvPhEQ+aQuwIDAQABo4ICUjCC
+-Ak4wPQYIKwYBBQUHAQEEMTAvMC0GCCsGAQUFBzABhiFodHRwczovL29jc3AucXVv
+-dmFkaXNvZmZzaG9yZS5jb20wDwYDVR0TAQH/BAUwAwEB/zCCARoGA1UdIASCAREw
+-ggENMIIBCQYJKwYBBAG+WAABMIH7MIHUBggrBgEFBQcCAjCBxxqBxFJlbGlhbmNl
+-IG9uIHRoZSBRdW9WYWRpcyBSb290IENlcnRpZmljYXRlIGJ5IGFueSBwYXJ0eSBh
+-c3N1bWVzIGFjY2VwdGFuY2Ugb2YgdGhlIHRoZW4gYXBwbGljYWJsZSBzdGFuZGFy
+-ZCB0ZXJtcyBhbmQgY29uZGl0aW9ucyBvZiB1c2UsIGNlcnRpZmljYXRpb24gcHJh
+-Y3RpY2VzLCBhbmQgdGhlIFF1b1ZhZGlzIENlcnRpZmljYXRlIFBvbGljeS4wIgYI
+-KwYBBQUHAgEWFmh0dHA6Ly93d3cucXVvdmFkaXMuYm0wHQYDVR0OBBYEFItLbe3T
+-KbkGGew5Oanwl4Rqy+/fMIGuBgNVHSMEgaYwgaOAFItLbe3TKbkGGew5Oanwl4Rq
+-y+/foYGEpIGBMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1p
+-dGVkMSUwIwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYD
+-VQQDEyVRdW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5ggQ6tlCL
+-MA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQUFAAOCAQEAitQUtf70mpKnGdSk
+-fnIYj9lofFIk3WdvOXrEql494liwTXCYhGHoG+NpGA7O+0dQoE7/8CQfvbLO9Sf8
+-7C9TqnN7Az10buYWnuulLsS/VidQK2K6vkscPFVcQR0kvoIgR13VRH56FmjffU1R
+-cHhXHTMe/QKZnAzNCgVPx7uOpHX6Sm2xgI4JVrmcGmD+XcHXetwReNDWXcG31a0y
+-mQM6isxUJTkxgXsTIlG6Rmyhu576BGxJJnSP0nPrzDCi5upZIof4l/UO/erMkqQW
+-xFIY6iHOsfHmhIHluqmGKPJDWl0Snawe2ajlCmqnf6CHKc/yiU3U7MXi5nrQNiOK
+-SnQ2+Q==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_2.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem.orig
++++ secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem.orig
++++ secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem.orig
++++ secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem.orig
++++ secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SZAFIR_ROOT_CA2.pem.orig
++++ secure/caroot/trusted/SZAFIR_ROOT_CA2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SecureSign_RootCA11.pem.orig
++++ secure/caroot/trusted/SecureSign_RootCA11.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SecureTrust_CA.pem.orig
++++ secure/caroot/trusted/SecureTrust_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Secure_Global_CA.pem.orig
++++ secure/caroot/trusted/Secure_Global_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Security_Communication_RootCA2.pem.orig
++++ secure/caroot/trusted/Security_Communication_RootCA2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Security_Communication_Root_CA.pem.orig
++++ secure/caroot/trusted/Security_Communication_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Sonera_Class_2_Root_CA.pem.orig
++++ secure/caroot/trusted/Sonera_Class_2_Root_CA.pem
+@@ -1,88 +0,0 @@
+-##
+-## Sonera Class 2 Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 29 (0x1d)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = FI, O = Sonera, CN = Sonera Class2 CA
+- Validity
+- Not Before: Apr 6 07:29:40 2001 GMT
+- Not After : Apr 6 07:29:40 2021 GMT
+- Subject: C = FI, O = Sonera, CN = Sonera Class2 CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:90:17:4a:35:9d:ca:f0:0d:96:c7:44:fa:16:37:
+- fc:48:bd:bd:7f:80:2d:35:3b:e1:6f:a8:67:a9:bf:
+- 03:1c:4d:8c:6f:32:47:d5:41:68:a4:13:04:c1:35:
+- 0c:9a:84:43:fc:5c:1d:ff:89:b3:e8:17:18:cd:91:
+- 5f:fb:89:e3:ea:bf:4e:5d:7c:1b:26:d3:75:79:ed:
+- e6:84:e3:57:e5:ad:29:c4:f4:3a:28:e7:a5:7b:84:
+- 36:69:b3:fd:5e:76:bd:a3:2d:99:d3:90:4e:23:28:
+- 7d:18:63:f1:54:3b:26:9d:76:5b:97:42:b2:ff:ae:
+- f0:4e:ec:dd:39:95:4e:83:06:7f:e7:49:40:c8:c5:
+- 01:b2:54:5a:66:1d:3d:fc:f9:e9:3c:0a:9e:81:b8:
+- 70:f0:01:8b:e4:23:54:7c:c8:ae:f8:90:1e:00:96:
+- 72:d4:54:cf:61:23:bc:ea:fb:9d:02:95:d1:b6:b9:
+- 71:3a:69:08:3f:0f:b4:e1:42:c7:88:f5:3f:98:a8:
+- a7:ba:1c:e0:71:71:ef:58:57:81:50:7a:5c:6b:74:
+- 46:0e:83:03:98:c3:8e:a8:6e:f2:76:32:6e:27:83:
+- c2:73:f3:dc:18:e8:b4:93:ea:75:44:6b:04:60:20:
+- 71:57:87:9d:f3:be:a0:90:23:3d:8a:24:e1:da:21:
+- db:c3
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 4A:A0:AA:58:84:D3:5E:3C
+- X509v3 Key Usage:
+- Certificate Sign, CRL Sign
+- Signature Algorithm: sha1WithRSAEncryption
+- 5a:ce:87:f9:16:72:15:57:4b:1d:d9:9b:e7:a2:26:30:ec:93:
+- 67:df:d6:2d:d2:34:af:f7:38:a5:ce:ab:16:b9:ab:2f:7c:35:
+- cb:ac:d0:0f:b4:4c:2b:fc:80:ef:6b:8c:91:5f:36:76:f7:db:
+- b3:1b:19:ea:f4:b2:11:fd:61:71:44:bf:28:b3:3a:1d:bf:b3:
+- 43:e8:9f:bf:dc:31:08:71:b0:9d:8d:d6:34:47:32:90:c6:65:
+- 24:f7:a0:4a:7c:04:73:8f:39:6f:17:8c:72:b5:bd:4b:c8:7a:
+- f8:7b:83:c3:28:4e:9c:09:ea:67:3f:b2:67:04:1b:c3:14:da:
+- f8:e7:49:24:91:d0:1d:6a:fa:61:39:ef:6b:e7:21:75:06:07:
+- d8:12:b4:21:20:70:42:71:81:da:3c:9a:36:be:a6:5b:0d:6a:
+- 6c:9a:1f:91:7b:f9:f9:ef:42:ba:4e:4e:9e:cc:0c:8d:94:dc:
+- d9:45:9c:5e:ec:42:50:63:ae:f4:5d:c4:b1:12:dc:ca:3b:a8:
+- 2e:9d:14:5a:05:75:b7:ec:d7:63:e2:ba:35:b6:04:08:91:e8:
+- da:9d:9c:f6:66:b5:18:ac:0a:a6:54:26:34:33:d2:1b:c1:d4:
+- 7f:1a:3a:8e:0b:aa:32:6e:db:fc:4f:25:9f:d9:32:c7:96:5a:
+- 70:ac:df:4c
+-SHA1 Fingerprint=37:F7:6D:E6:07:7C:90:C5:B1:3E:93:1A:B7:41:10:B4:F2:E4:9A:27
+------BEGIN CERTIFICATE-----
+-MIIDIDCCAgigAwIBAgIBHTANBgkqhkiG9w0BAQUFADA5MQswCQYDVQQGEwJGSTEP
+-MA0GA1UEChMGU29uZXJhMRkwFwYDVQQDExBTb25lcmEgQ2xhc3MyIENBMB4XDTAx
+-MDQwNjA3Mjk0MFoXDTIxMDQwNjA3Mjk0MFowOTELMAkGA1UEBhMCRkkxDzANBgNV
+-BAoTBlNvbmVyYTEZMBcGA1UEAxMQU29uZXJhIENsYXNzMiBDQTCCASIwDQYJKoZI
+-hvcNAQEBBQADggEPADCCAQoCggEBAJAXSjWdyvANlsdE+hY3/Ei9vX+ALTU74W+o
+-Z6m/AxxNjG8yR9VBaKQTBME1DJqEQ/xcHf+Js+gXGM2RX/uJ4+q/Tl18GybTdXnt
+-5oTjV+WtKcT0OijnpXuENmmz/V52vaMtmdOQTiMofRhj8VQ7Jp12W5dCsv+u8E7s
+-3TmVToMGf+dJQMjFAbJUWmYdPfz56TwKnoG4cPABi+QjVHzIrviQHgCWctRUz2Ej
+-vOr7nQKV0ba5cTppCD8PtOFCx4j1P5iop7oc4HFx71hXgVB6XGt0Rg6DA5jDjqhu
+-8nYybieDwnPz3BjotJPqdURrBGAgcVeHnfO+oJAjPYok4doh28MCAwEAAaMzMDEw
+-DwYDVR0TAQH/BAUwAwEB/zARBgNVHQ4ECgQISqCqWITTXjwwCwYDVR0PBAQDAgEG
+-MA0GCSqGSIb3DQEBBQUAA4IBAQBazof5FnIVV0sd2ZvnoiYw7JNn39Yt0jSv9zil
+-zqsWuasvfDXLrNAPtEwr/IDva4yRXzZ299uzGxnq9LIR/WFxRL8oszodv7ND6J+/
+-3DEIcbCdjdY0RzKQxmUk96BKfARzjzlvF4xytb1LyHr4e4PDKE6cCepnP7JnBBvD
+-FNr450kkkdAdavphOe9r5yF1BgfYErQhIHBCcYHaPJo2vqZbDWpsmh+Re/n570K6
+-Tk6ezAyNlNzZRZxe7EJQY670XcSxEtzKO6gunRRaBXW37Ndj4ro1tgQIkejanZz2
+-ZrUYrAqmVCY0M9IbwdR/GjqOC6oybtv8TyWf2TLHllpwrN9M
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem.orig
++++ secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem.orig
++++ secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
+@@ -1,132 +0,0 @@
+-##
+-## Staat der Nederlanden Root CA - G3
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 10003001 (0x98a239)
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
+- Validity
+- Not Before: Nov 14 11:28:42 2013 GMT
+- Not After : Nov 13 23:00:00 2028 GMT
+- Subject: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:be:32:a2:54:0f:70:fb:2c:5c:59:eb:6c:c4:a4:
+- 51:e8:85:2a:b3:cc:4a:34:f2:b0:5f:f3:0e:c7:1c:
+- 3d:53:1e:88:08:68:d8:6f:3d:ad:c2:9e:cc:82:67:
+- 07:27:87:68:71:3a:9f:75:96:22:46:05:b0:ed:ad:
+- c7:5b:9e:2a:de:9c:fc:3a:c6:95:a7:f5:17:67:18:
+- e7:2f:49:08:0c:5c:cf:e6:cc:34:ed:78:fb:50:b1:
+- dc:6b:32:f0:a2:fe:b6:3c:e4:ec:5a:97:c7:3f:1e:
+- 70:08:30:a0:dc:c5:b3:6d:6f:d0:82:72:11:ab:d2:
+- 81:68:59:82:17:b7:78:92:60:fa:cc:de:3f:84:eb:
+- 8d:38:33:90:0a:72:23:fa:35:cc:26:71:31:d1:72:
+- 28:92:d9:5b:23:6d:66:b5:6d:07:42:eb:a6:33:ce:
+- 92:db:c0:f6:6c:63:78:cd:ca:4e:3d:b5:e5:52:9b:
+- f1:be:3b:e6:54:60:b0:66:1e:09:ab:07:fe:54:89:
+- 11:42:d1:f7:24:ba:60:78:1a:98:f7:c9:11:fd:16:
+- c1:35:1a:54:75:ef:43:d3:e5:ae:4e:ce:e7:7b:c3:
+- c6:4e:61:51:4b:ab:9a:45:4b:a1:1f:41:bd:48:53:
+- 15:71:64:0b:86:b3:e5:2e:be:ce:a4:1b:c1:29:84:
+- a2:b5:cb:08:23:76:43:22:24:1f:17:04:d4:6e:9c:
+- c6:fc:7f:2b:66:1a:ec:8a:e5:d6:cf:4d:f5:63:09:
+- b7:15:39:d6:7b:ac:eb:e3:7c:e9:4e:fc:75:42:c8:
+- ed:58:95:0c:06:42:a2:9c:f7:e4:70:b3:df:72:6f:
+- 5a:37:40:89:d8:85:a4:d7:f1:0b:de:43:19:d4:4a:
+- 58:2c:8c:8a:39:9e:bf:84:87:f1:16:3b:36:0c:e9:
+- d3:b4:ca:6c:19:41:52:09:a1:1d:b0:6a:bf:82:ef:
+- 70:51:21:32:dc:05:76:8c:cb:f7:64:e4:03:50:af:
+- 8c:91:67:ab:c5:f2:ee:58:d8:de:be:f7:e7:31:cf:
+- 6c:c9:3b:71:c1:d5:88:b5:65:bc:c0:e8:17:17:07:
+- 12:b5:5c:d2:ab:20:93:b4:e6:82:83:70:36:c5:cd:
+- a3:8d:ad:8b:ec:a3:c1:43:87:e6:43:e2:34:be:95:
+- 8b:35:ed:07:39:da:a8:1d:7a:9f:36:9e:12:b0:0c:
+- 65:12:90:15:60:d9:26:40:44:e3:56:60:a5:10:d4:
+- 6a:3c:fd:41:dc:0e:5a:47:b6:ef:97:61:75:4f:d9:
+- fe:c7:b2:1d:d4:ed:5d:49:b3:a9:6a:cb:66:84:13:
+- d5:5c:a0:dc:df:6e:77:06:d1:71:75:c8:57:6f:af:
+- 0f:77:5b
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Subject Key Identifier:
+- 54:AD:FA:C7:92:57:AE:CA:35:9C:2E:12:FB:E4:BA:5D:20:DC:94:57
+- Signature Algorithm: sha256WithRSAEncryption
+- 30:99:9d:05:32:c8:5e:0e:3b:98:01:3a:8a:a4:e7:07:f7:7a:
+- f8:e7:9a:df:50:43:53:97:2a:3d:ca:3c:47:98:2e:e1:15:7b:
+- f1:92:f3:61:da:90:25:16:65:c0:9f:54:5d:0e:03:3b:5b:77:
+- 02:9c:84:b6:0d:98:5f:34:dd:3b:63:c2:c3:28:81:c2:9c:29:
+- 2e:29:e2:c8:c3:01:f2:33:ea:2a:aa:cc:09:08:f7:65:67:c6:
+- cd:df:d3:b6:2b:a7:bd:cc:d1:0e:70:5f:b8:23:d1:cb:91:4e:
+- 0a:f4:c8:7a:e5:d9:63:36:c1:d4:df:fc:22:97:f7:60:5d:ea:
+- 29:2f:58:b2:bd:58:bd:8d:96:4f:10:75:bf:48:7b:3d:51:87:
+- a1:3c:74:22:c2:fc:07:7f:80:dc:c4:ac:fe:6a:c1:70:30:b0:
+- e9:8e:69:e2:2c:69:81:94:09:ba:dd:fe:4d:c0:83:8c:94:58:
+- c0:46:20:af:9c:1f:02:f8:35:55:49:2f:46:d4:c0:f0:a0:96:
+- 02:0f:33:c5:71:f3:9e:23:7d:94:b7:fd:3a:d3:09:83:06:21:
+- fd:60:3d:ae:32:c0:d2:ee:8d:a6:f0:e7:b4:82:7c:0a:cc:70:
+- c9:79:80:f8:fe:4c:f7:35:84:19:8a:31:fb:0a:d9:d7:7f:9b:
+- f0:a2:9a:6b:c3:05:4a:ed:41:60:14:30:d1:aa:11:42:6e:d3:
+- 23:02:04:0b:c6:65:dd:dd:52:77:da:81:6b:b2:a8:fa:01:38:
+- b9:96:ea:2a:6c:67:97:89:94:9e:bc:e1:54:d5:e4:6a:78:ef:
+- 4a:bd:2b:9a:3d:40:7e:c6:c0:75:d2:6e:fb:68:30:ec:ec:8b:
+- 9d:f9:49:35:9a:1a:2c:d9:b3:95:39:d5:1e:92:f7:a6:b9:65:
+- 2f:e5:3d:6d:3a:48:4c:08:dc:e4:28:12:28:be:7d:35:5c:ea:
+- e0:16:7e:13:1b:6a:d7:3e:d7:9e:fc:2d:75:b2:c1:14:d5:23:
+- 03:db:5b:6f:0b:3e:78:2f:0d:de:33:8d:16:b7:48:e7:83:9a:
+- 81:0f:7b:c1:43:4d:55:04:17:38:4a:51:d5:59:a2:89:74:d3:
+- 9f:be:1e:4b:d7:c6:6d:b7:88:24:6f:60:91:a4:82:85:5b:56:
+- 41:bc:d0:44:ab:6a:13:be:d1:2c:58:b7:12:33:58:b2:37:63:
+- dc:13:f5:94:1d:3f:40:51:f5:4f:f5:3a:ed:c8:c5:eb:c2:1e:
+- 1d:16:95:7a:c7:7e:42:71:93:6e:4b:15:b7:30:df:aa:ed:57:
+- 85:48:ac:1d:6a:dd:39:69:e4:e1:79:78:be:ce:05:bf:a1:0c:
+- f7:80:7b:21:67:27:30:59
+-SHA1 Fingerprint=D8:EB:6B:41:51:92:59:E0:F3:E7:85:00:C0:3D:B6:88:97:C9:EE:FC
+------BEGIN CERTIFICATE-----
+-MIIFdDCCA1ygAwIBAgIEAJiiOTANBgkqhkiG9w0BAQsFADBaMQswCQYDVQQGEwJO
+-TDEeMBwGA1UECgwVU3RhYXQgZGVyIE5lZGVybGFuZGVuMSswKQYDVQQDDCJTdGFh
+-dCBkZXIgTmVkZXJsYW5kZW4gUm9vdCBDQSAtIEczMB4XDTEzMTExNDExMjg0MloX
+-DTI4MTExMzIzMDAwMFowWjELMAkGA1UEBhMCTkwxHjAcBgNVBAoMFVN0YWF0IGRl
+-ciBOZWRlcmxhbmRlbjErMCkGA1UEAwwiU3RhYXQgZGVyIE5lZGVybGFuZGVuIFJv
+-b3QgQ0EgLSBHMzCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAL4yolQP
+-cPssXFnrbMSkUeiFKrPMSjTysF/zDsccPVMeiAho2G89rcKezIJnByeHaHE6n3WW
+-IkYFsO2tx1ueKt6c/DrGlaf1F2cY5y9JCAxcz+bMNO14+1Cx3Gsy8KL+tjzk7FqX
+-xz8ecAgwoNzFs21v0IJyEavSgWhZghe3eJJg+szeP4TrjTgzkApyI/o1zCZxMdFy
+-KJLZWyNtZrVtB0LrpjPOktvA9mxjeM3KTj215VKb8b475lRgsGYeCasH/lSJEULR
+-9yS6YHgamPfJEf0WwTUaVHXvQ9Plrk7O53vDxk5hUUurmkVLoR9BvUhTFXFkC4az
+-5S6+zqQbwSmEorXLCCN2QyIkHxcE1G6cxvx/K2Ya7Irl1s9N9WMJtxU51nus6+N8
+-6U78dULI7ViVDAZCopz35HCz33JvWjdAidiFpNfxC95DGdRKWCyMijmev4SH8RY7
+-Ngzp07TKbBlBUgmhHbBqv4LvcFEhMtwFdozL92TkA1CvjJFnq8Xy7ljY3r735zHP
+-bMk7ccHViLVlvMDoFxcHErVc0qsgk7TmgoNwNsXNo42ti+yjwUOH5kPiNL6VizXt
+-BznaqB16nzaeErAMZRKQFWDZJkBE41ZgpRDUajz9QdwOWke275dhdU/Z/seyHdTt
+-XUmzqWrLZoQT1Vyg3N9udwbRcXXIV2+vD3dbAgMBAAGjQjBAMA8GA1UdEwEB/wQF
+-MAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBRUrfrHkleuyjWcLhL75Lpd
+-INyUVzANBgkqhkiG9w0BAQsFAAOCAgEAMJmdBTLIXg47mAE6iqTnB/d6+Oea31BD
+-U5cqPco8R5gu4RV78ZLzYdqQJRZlwJ9UXQ4DO1t3ApyEtg2YXzTdO2PCwyiBwpwp
+-LiniyMMB8jPqKqrMCQj3ZWfGzd/TtiunvczRDnBfuCPRy5FOCvTIeuXZYzbB1N/8
+-Ipf3YF3qKS9Ysr1YvY2WTxB1v0h7PVGHoTx0IsL8B3+A3MSs/mrBcDCw6Y5p4ixp
+-gZQJut3+TcCDjJRYwEYgr5wfAvg1VUkvRtTA8KCWAg8zxXHzniN9lLf9OtMJgwYh
+-/WA9rjLA0u6NpvDntIJ8CsxwyXmA+P5M9zWEGYox+wrZ13+b8KKaa8MFSu1BYBQw
+-0aoRQm7TIwIEC8Zl3d1Sd9qBa7Ko+gE4uZbqKmxnl4mUnrzhVNXkanjvSr0rmj1A
+-fsbAddJu+2gw7OyLnflJNZoaLNmzlTnVHpL3prllL+U9bTpITAjc5CgSKL59NVzq
+-4BZ+Extq1z7XnvwtdbLBFNUjA9tbbws+eC8N3jONFrdI54OagQ97wUNNVQQXOEpR
+-1VmiiXTTn74eS9fGbbeIJG9gkaSChVtWQbzQRKtqE77RLFi3EjNYsjdj3BP1lB0/
+-QFH1T/U67cjF68IeHRaVesd+QnGTbksVtzDfqu1XhUisHWrdOWnk4Xl4vs4Fv6EM
+-94B7IWcnMFk=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Starfield_Class_2_CA.pem.orig
++++ secure/caroot/trusted/Starfield_Class_2_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem.orig
++++ secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem.orig
++++ secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem
+@@ -1,140 +0,0 @@
+-##
+-## SwissSign Platinum CA - G2
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 5670595323396054351 (0x4eb200670c035d4f)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
+- Validity
+- Not Before: Oct 25 08:36:00 2006 GMT
+- Not After : Oct 25 08:36:00 2036 GMT
+- Subject: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:ca:df:a2:02:e2:da:f8:fc:07:16:b1:de:60:aa:
+- de:96:5c:64:1f:c7:2f:7e:cf:67:fa:44:42:d6:76:
+- 63:95:ae:eb:af:72:20:8a:45:47:86:62:78:86:d6:
+- 20:39:26:f4:ae:a3:fd:23:e7:a5:9c:b5:22:21:19:
+- b7:37:93:22:c0:50:9c:82:7b:d4:d5:04:44:5c:cb:
+- b4:c2:9f:92:be:24:d8:7b:67:22:e2:69:5f:e5:05:
+- 78:d4:87:d9:71:70:33:25:53:b4:87:3b:29:90:28:
+- 36:9a:55:44:30:68:a4:83:97:7f:0d:1e:9c:76:ff:
+- 15:9d:60:97:00:8d:8a:85:03:ec:80:be:ea:2c:6e:
+- 10:51:92:cc:7e:d5:a3:33:d8:d6:49:de:58:2a:af:
+- f6:16:eb:4b:7b:90:32:97:b9:ba:9d:58:f1:f8:57:
+- 49:04:1e:a2:5d:06:70:dd:71:db:f9:dd:8b:9a:1b:
+- 8c:cf:3d:a3:4d:ce:cb:7c:f6:bb:9c:a0:fa:09:ce:
+- 23:62:b2:e9:0d:1f:e2:72:28:8f:9f:ac:68:20:7d:
+- 6f:3b:a8:85:31:09:7f:0b:c7:e8:65:e9:e3:78:0e:
+- 09:67:30:8b:34:82:fb:5d:e0:cc:9d:81:6d:62:ee:
+- 08:1e:04:2c:4e:9b:ec:fe:a9:4f:5f:fd:69:78:ef:
+- 09:1f:a1:b4:bf:fa:f3:ef:90:1e:4c:05:8b:1e:ea:
+- 7a:91:7a:c3:d7:e5:fb:30:bc:6c:1b:10:58:98:f7:
+- 1a:5f:d0:29:32:03:13:46:4d:61:6a:85:4c:52:74:
+- 2f:06:1f:7b:11:e2:84:97:c6:99:f3:6d:7f:d7:67:
+- 83:7e:13:68:d8:71:28:5a:d8:ce:dd:e8:10:14:9a:
+- fe:6d:23:87:6e:8e:5a:70:3c:d5:8d:09:00:a7:aa:
+- bc:b0:31:37:6d:c8:84:14:1e:5b:bd:45:63:20:6b:
+- 4b:74:8c:bd:db:3a:0e:c1:cf:5a:16:8f:a5:98:f2:
+- 76:89:b2:13:12:3b:0b:77:77:ac:bb:e5:3c:29:4a:
+- 92:72:ca:61:1a:2b:5e:4c:e2:83:74:77:fa:35:48:
+- 7a:85:4d:8d:9a:53:c4:df:78:ca:97:91:48:2b:45:
+- 2b:01:f7:1c:1a:a2:ed:18:ba:0a:bd:83:fa:6f:bc:
+- 8d:57:93:3b:d4:d4:a6:ce:1e:f1:a0:b1:ce:ab:fd:
+- 2b:28:9a:4f:1b:d7:c3:72:db:a4:c4:bf:5d:4c:f5:
+- dd:7b:96:69:ee:68:80:e6:e7:98:ba:36:b7:fe:6e:
+- ed:2b:bd:20:f8:65:19:da:55:09:7e:25:dc:fe:61:
+- 62:72:f9:7e:18:02:ef:63:b4:d0:fb:af:e5:3b:63:
+- 8c:67:8f
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
+- X509v3 Authority Key Identifier:
+- keyid:50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
+-
+- X509v3 Certificate Policies:
+- Policy: 2.16.756.1.89.1.1.1.1
+- CPS: http://repository.swisssign.com/
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 08:85:a6:f5:16:0c:fc:44:1a:c1:63:e0:f9:55:46:08:fc:70:
+- 1c:42:28:96:8e:b7:c5:c1:41:75:4e:09:71:79:e5:6d:96:ca:
+- 4b:a5:88:60:d0:30:74:b8:ca:08:dc:b4:30:9e:40:07:16:6b:
+- 65:95:77:01:ae:a4:b7:35:0b:81:da:71:15:a9:74:17:38:7b:
+- 58:ca:f9:2f:fb:c0:65:76:8d:5b:01:b9:7d:de:82:3d:64:b8:
+- be:14:74:a3:0a:54:d3:2c:95:18:17:35:f5:51:6b:3f:8f:a2:
+- 96:61:39:78:6b:4b:e5:a6:a0:f8:53:df:51:10:93:62:e7:80:
+- 2f:e2:d1:e0:bc:8e:36:46:77:33:ec:b8:fb:8e:9a:2c:89:4d:
+- 31:11:0f:26:9e:04:bb:b7:04:8d:0b:f2:b9:fc:5a:9d:3b:16:
+- b7:2f:c8:98:ab:fe:8a:50:59:2e:a3:3b:fc:29:5d:8b:c1:4b:
+- c9:e2:8a:13:1d:b1:bf:bb:42:1d:52:dd:4e:d8:14:5e:10:c6:
+- 31:07:ef:71:27:f7:1b:39:09:dc:82:ea:8b:b3:95:86:5e:fd:
+- f5:da:5d:31:a6:e0:31:b6:94:e6:44:49:74:c5:16:e5:f7:1f:
+- 03:61:28:c5:c8:cb:12:a0:42:4b:f9:6b:88:08:8d:b4:32:18:
+- f3:75:9f:c4:7f:00:4f:05:95:9c:a3:17:02:c3:b3:53:9b:aa:
+- 20:39:29:2b:66:fa:9d:af:5e:b3:92:d2:b5:a6:e1:1a:f9:2d:
+- 41:69:81:14:b4:b4:b5:ed:89:3d:ce:fb:a9:9d:35:42:44:b1:
+- 1c:14:73:81:cf:2a:01:35:9a:31:d5:2d:8f:6d:84:df:80:4d:
+- 57:e3:3f:c5:84:75:da:89:c6:30:bb:eb:8f:cb:22:08:a0:ae:
+- aa:f1:03:6c:3a:4b:4d:09:a5:0e:72:c6:56:6b:21:42:4e:23:
+- 25:14:68:ae:76:0a:7c:0c:07:70:64:f9:9a:2f:f6:05:39:26:
+- c6:0c:8f:19:7f:43:5e:6e:f4:5b:15:2f:db:61:5d:e6:67:2f:
+- 3f:08:94:f9:60:b4:98:31:da:74:f1:84:93:71:4d:5f:fb:60:
+- 58:d1:fb:c4:c1:6d:89:a2:bb:20:1f:9d:71:91:cb:32:9b:13:
+- 3d:3e:7d:92:52:35:ac:92:94:a2:d3:18:c2:7c:c7:ea:af:76:
+- 05:16:dd:67:27:c2:7e:1c:07:22:21:f3:40:0a:1b:34:07:44:
+- 13:c2:84:6a:8e:df:19:5a:bf:7f:eb:1d:e2:1a:38:d1:5c:af:
+- 47:92:6b:80:b5:30:a5:c9:8d:d8:ab:31:81:1f:df:c2:66:37:
+- d3:93:a9:85:86:79:65:d2
+-SHA1 Fingerprint=56:E0:FA:C0:3B:8F:18:23:55:18:E5:D3:11:CA:E8:C2:43:31:AB:66
+------BEGIN CERTIFICATE-----
+-MIIFwTCCA6mgAwIBAgIITrIAZwwDXU8wDQYJKoZIhvcNAQEFBQAwSTELMAkGA1UE
+-BhMCQ0gxFTATBgNVBAoTDFN3aXNzU2lnbiBBRzEjMCEGA1UEAxMaU3dpc3NTaWdu
+-IFBsYXRpbnVtIENBIC0gRzIwHhcNMDYxMDI1MDgzNjAwWhcNMzYxMDI1MDgzNjAw
+-WjBJMQswCQYDVQQGEwJDSDEVMBMGA1UEChMMU3dpc3NTaWduIEFHMSMwIQYDVQQD
+-ExpTd2lzc1NpZ24gUGxhdGludW0gQ0EgLSBHMjCCAiIwDQYJKoZIhvcNAQEBBQAD
+-ggIPADCCAgoCggIBAMrfogLi2vj8Bxax3mCq3pZcZB/HL37PZ/pEQtZ2Y5Wu669y
+-IIpFR4ZieIbWIDkm9K6j/SPnpZy1IiEZtzeTIsBQnIJ71NUERFzLtMKfkr4k2Htn
+-IuJpX+UFeNSH2XFwMyVTtIc7KZAoNppVRDBopIOXfw0enHb/FZ1glwCNioUD7IC+
+-6ixuEFGSzH7VozPY1kneWCqv9hbrS3uQMpe5up1Y8fhXSQQeol0GcN1x2/ndi5ob
+-jM89o03Oy3z2u5yg+gnOI2Ky6Q0f4nIoj5+saCB9bzuohTEJfwvH6GXp43gOCWcw
+-izSC+13gzJ2BbWLuCB4ELE6b7P6pT1/9aXjvCR+htL/68++QHkwFix7qepF6w9fl
+-+zC8bBsQWJj3Gl/QKTIDE0ZNYWqFTFJ0LwYfexHihJfGmfNtf9dng34TaNhxKFrY
+-zt3oEBSa/m0jh26OWnA81Y0JAKeqvLAxN23IhBQeW71FYyBrS3SMvds6DsHPWhaP
+-pZjydomyExI7C3d3rLvlPClKknLKYRorXkzig3R3+jVIeoVNjZpTxN94ypeRSCtF
+-KwH3HBqi7Ri6Cr2D+m+8jVeTO9TUps4e8aCxzqv9KyiaTxvXw3LbpMS/XUz13XuW
+-ae5ogObnmLo2t/5u7Su9IPhlGdpVCX4l3P5hYnL5fhgC72O00Puv5TtjjGePAgMB
+-AAGjgawwgakwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0O
+-BBYEFFCvzAeHFUdvOMW0ZdHelarp35zMMB8GA1UdIwQYMBaAFFCvzAeHFUdvOMW0
+-ZdHelarp35zMMEYGA1UdIAQ/MD0wOwYJYIV0AVkBAQEBMC4wLAYIKwYBBQUHAgEW
+-IGh0dHA6Ly9yZXBvc2l0b3J5LnN3aXNzc2lnbi5jb20vMA0GCSqGSIb3DQEBBQUA
+-A4ICAQAIhab1Fgz8RBrBY+D5VUYI/HAcQiiWjrfFwUF1TglxeeVtlspLpYhg0DB0
+-uMoI3LQwnkAHFmtllXcBrqS3NQuB2nEVqXQXOHtYyvkv+8Bldo1bAbl93oI9ZLi+
+-FHSjClTTLJUYFzX1UWs/j6KWYTl4a0vlpqD4U99REJNi54Av4tHgvI42Rncz7Lj7
+-jposiU0xEQ8mngS7twSNC/K5/FqdOxa3L8iYq/6KUFkuozv8KV2LwUvJ4ooTHbG/
+-u0IdUt1O2BReEMYxB+9xJ/cbOQncguqLs5WGXv312l0xpuAxtpTmREl0xRbl9x8D
+-YSjFyMsSoEJL+WuICI20MhjzdZ/EfwBPBZWcoxcCw7NTm6ogOSkrZvqdr16zktK1
+-puEa+S1BaYEUtLS17Yk9zvupnTVCRLEcFHOBzyoBNZox1S2PbYTfgE1X4z/FhHXa
+-icYwu+uPyyIIoK6q8QNsOktNCaUOcsZWayFCTiMlFGiudgp8DAdwZPmaL/YFOSbG
+-DI8Zf0NebvRbFS/bYV3mZy8/CJT5YLSYMdp08YSTcU1f+2BY0fvEwW2JorsgH51x
+-kcsymxM9Pn2SUjWskpSi0xjCfMfqr3YFFt1nJ8J+HAciIfNAChs0B0QTwoRqjt8Z
+-Wr9/6x3iGjjRXK9HkmuAtTClyY3YqzGBH9/CZjfTk6mFhnll0g==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem.orig
++++ secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem.orig
++++ secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
+@@ -1,94 +0,0 @@
+-##
+-## Symantec Class 1 Public Primary Certification Authority - G6
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 24:32:75:f2:1d:2f:d2:09:33:f7:b4:6a:ca:d0:f3:98
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
+- Validity
+- Not Before: Oct 18 00:00:00 2011 GMT
+- Not After : Dec 1 23:59:59 2037 GMT
+- Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c7:39:d7:49:64:a9:99:82:22:4c:ea:45:d9:07:
+- 16:e3:7b:f4:83:e8:99:73:fa:6b:b1:36:e0:9a:77:
+- a0:40:c2:81:8d:01:c7:cc:8c:bd:8f:7d:f7:79:e3:
+- 7a:4c:03:4d:d9:fb:fd:87:38:28:2c:dd:9a:8b:54:
+- 08:db:67:fb:1b:8c:fe:28:92:2f:be:b7:b2:48:a7:
+- 81:a1:d8:5e:88:c3:cc:39:40:41:5a:d1:dc:e5:da:
+- 10:9f:2f:da:01:4d:fd:2e:46:7c:f9:2e:27:0a:69:
+- 37:ee:91:a3:1b:6a:cc:44:bf:1b:c7:c3:d4:11:b2:
+- 50:60:97:09:bd:2e:22:f5:41:84:66:9f:cd:40:a6:
+- a9:00:80:c1:1f:95:92:9f:de:f3:48:ef:db:1d:77:
+- 61:fc:7f:df:ee:96:a4:72:d0:b6:3e:ff:78:27:af:
+- cb:92:15:69:08:db:63:10:e2:e6:97:ac:6e:dc:ac:
+- f6:a2:ce:1e:47:99:b9:89:b7:12:e6:a1:d4:cd:59:
+- 11:67:c3:6f:85:d8:42:4e:28:be:59:55:59:04:95:
+- ab:8f:37:80:bf:0d:f0:fc:1f:3a:64:31:58:81:78:
+- d7:e2:35:f6:20:3f:29:b8:8f:16:6e:3e:48:dc:b5:
+- 4c:07:e1:f2:1a:ea:7e:0a:79:d6:a8:bd:eb:5d:86:
+- 2b:4d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 33:41:E8:C8:39:12:15:93:48:F2:96:32:2E:5A:F5:DA:94:5F:53:60
+- Signature Algorithm: sha256WithRSAEncryption
+- 15:e3:73:57:b1:17:b6:5f:49:69:44:a6:f6:5e:7a:67:ac:d2:
+- de:75:49:ab:fe:25:55:c7:3a:c9:44:15:10:6e:bf:31:6b:cb:
+- d9:07:93:7f:1c:85:63:00:e3:32:12:e0:cc:cb:fb:39:6c:8f:
+- e2:53:e2:3c:40:33:d9:a4:8c:47:e6:ad:58:fb:89:af:e3:de:
+- 86:29:56:34:2c:45:b8:12:fa:44:89:6e:2d:14:25:28:24:01:
+- 65:d6:ea:52:ac:05:6e:56:12:09:3d:d0:74:f4:d7:bd:06:ca:
+- a8:3a:8d:56:42:fa:8d:72:3e:74:f1:03:72:df:87:1b:5e:0e:
+- 7a:55:96:2c:38:b7:98:85:cd:4d:33:44:c9:94:8f:5a:31:30:
+- 37:4b:a3:3a:12:b3:e7:36:d1:21:68:4b:2d:38:e6:53:ae:1c:
+- 25:56:08:56:03:67:84:9d:c6:c3:ce:24:62:c7:4c:36:cf:b0:
+- 06:44:b7:f5:5f:02:dd:d9:54:e9:2f:90:4e:7a:c8:4e:83:40:
+- 0c:9a:97:3c:37:bf:bf:ec:f6:f0:b4:85:77:28:c1:0b:c8:67:
+- 82:10:17:38:a2:b7:06:ea:9b:bf:3a:f8:e9:23:07:bf:74:e0:
+- 98:38:15:55:78:ee:72:00:5c:19:a3:f4:d2:33:e0:ff:bd:d1:
+- 54:39:29:0f
+-SHA1 Fingerprint=51:7F:61:1E:29:91:6B:53:82:FB:72:E7:44:D9:8D:C3:CC:53:6D:64
+------BEGIN CERTIFICATE-----
+-MIID9jCCAt6gAwIBAgIQJDJ18h0v0gkz97RqytDzmDANBgkqhkiG9w0BAQsFADCB
+-lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
+-HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
+-YyBDbGFzcyAxIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
+-IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
+-BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
+-eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAx
+-IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
+-MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHOddJZKmZgiJM6kXZBxbje/SD
+-6Jlz+muxNuCad6BAwoGNAcfMjL2Pffd543pMA03Z+/2HOCgs3ZqLVAjbZ/sbjP4o
+-ki++t7JIp4Gh2F6Iw8w5QEFa0dzl2hCfL9oBTf0uRnz5LicKaTfukaMbasxEvxvH
+-w9QRslBglwm9LiL1QYRmn81ApqkAgMEflZKf3vNI79sdd2H8f9/ulqRy0LY+/3gn
+-r8uSFWkI22MQ4uaXrG7crPaizh5HmbmJtxLmodTNWRFnw2+F2EJOKL5ZVVkElauP
+-N4C/DfD8HzpkMViBeNfiNfYgPym4jxZuPkjctUwH4fIa6n4KedaovetdhitNAgMB
+-AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
+-BBQzQejIORIVk0jyljIuWvXalF9TYDANBgkqhkiG9w0BAQsFAAOCAQEAFeNzV7EX
+-tl9JaUSm9l56Z6zS3nVJq/4lVcc6yUQVEG6/MWvL2QeTfxyFYwDjMhLgzMv7OWyP
+-4lPiPEAz2aSMR+atWPuJr+PehilWNCxFuBL6RIluLRQlKCQBZdbqUqwFblYSCT3Q
+-dPTXvQbKqDqNVkL6jXI+dPEDct+HG14OelWWLDi3mIXNTTNEyZSPWjEwN0ujOhKz
+-5zbRIWhLLTjmU64cJVYIVgNnhJ3Gw84kYsdMNs+wBkS39V8C3dlU6S+QTnrIToNA
+-DJqXPDe/v+z28LSFdyjBC8hnghAXOKK3Buqbvzr46SMHv3TgmDgVVXjucgBcGaP0
+-0jPg/73RVDkpDw==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem.orig
++++ secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
+@@ -1,94 +0,0 @@
+-##
+-## Symantec Class 2 Public Primary Certification Authority - G6
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 64:82:9e:fc:37:1e:74:5d:fc:97:ff:97:c8:b1:ff:41
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
+- Validity
+- Not Before: Oct 18 00:00:00 2011 GMT
+- Not After : Dec 1 23:59:59 2037 GMT
+- Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:cd:cc:e9:05:c8:63:85:cb:3f:40:63:17:bd:18:
+- fa:35:e6:04:67:57:65:98:29:a4:4f:c9:5c:8f:0f:
+- 34:d2:f8:da:a8:13:62:aa:b8:1e:50:67:78:b0:16:
+- 4c:a0:39:a9:15:7a:ae:ed:d2:a2:c0:f0:90:37:29:
+- 18:26:5c:e8:0d:3c:b6:6c:49:3f:c1:e0:dc:d9:4b:
+- b6:14:19:0b:a6:d3:96:e1:d6:09:e3:19:26:1c:f9:
+- 1f:65:4b:f9:1a:43:1c:00:83:d6:d0:aa:49:a2:d4:
+- db:e6:62:38:ba:50:14:43:6d:f9:31:f8:56:16:d9:
+- 38:02:91:cf:eb:6c:dd:bb:39:4e:99:e1:30:67:45:
+- f1:d4:f0:8d:c3:df:fe:f2:38:07:21:7d:00:5e:56:
+- 44:b3:e4:60:bd:91:2b:9c:ab:5b:04:72:0f:b2:28:
+- d9:72:ab:05:20:42:25:a9:5b:03:6a:20:10:cc:31:
+- f0:2b:da:35:2c:d0:fb:9a:97:4e:f0:82:4b:2b:d8:
+- 5f:36:a3:0b:2d:af:63:0d:1d:25:7f:a1:6e:5c:62:
+- a1:8d:28:3e:a1:fc:1c:20:f8:01:2f:ba:55:9a:11:
+- b0:19:d2:c8:50:79:6b:0e:6a:05:d7:aa:04:36:b2:
+- a3:f2:e1:5f:77:a7:77:9c:e5:1e:dc:e9:df:6a:c1:
+- 65:5d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 87:8C:20:95:C8:98:4A:D1:D6:80:06:4A:90:34:44:DF:1C:4D:BF:B0
+- Signature Algorithm: sha256WithRSAEncryption
+- 81:8e:b2:a5:66:96:b7:21:a5:b6:ef:6f:23:5a:5f:db:81:c5:
+- 42:a5:78:c1:69:fd:f4:3c:d7:f9:5c:6b:70:72:1a:fc:5a:97:
+- 4d:00:80:88:88:82:8a:c3:71:0d:8e:c5:89:9b:2c:ed:8d:0b:
+- d2:72:54:f5:7d:d4:5c:43:57:e9:f3:ae:a5:02:11:f6:76:2b:
+- 81:57:dd:7d:da:74:30:fd:54:47:f6:e0:16:6e:a6:b4:0a:48:
+- e6:e7:75:07:0f:29:19:39:ce:79:f4:b6:6c:c5:5f:99:d5:1f:
+- 4b:fa:df:6d:2c:3c:0d:54:80:70:f0:88:0b:80:cf:c6:68:a2:
+- b8:1d:70:d9:76:8c:fc:ee:a5:c9:cf:ad:1d:cf:99:25:57:5a:
+- 62:45:cb:16:6b:bd:49:cd:a5:a3:8c:69:79:25:ae:b8:4c:6c:
+- 8b:40:66:4b:16:3f:cf:02:1a:dd:e1:6c:6b:07:61:6a:76:15:
+- 29:99:7f:1b:dd:88:80:c1:bf:b5:8f:73:c5:a6:96:23:84:a6:
+- 28:86:24:33:6a:01:2e:57:73:25:b6:5e:bf:8f:e6:1d:61:a8:
+- 40:29:67:1d:87:9b:1d:7f:9b:9f:99:cd:31:d6:54:be:62:bb:
+- 39:ac:68:12:48:91:20:a5:cb:b1:dd:fe:6f:fc:5a:e4:82:55:
+- 59:af:31:a9
+-SHA1 Fingerprint=40:B3:31:A0:E9:BF:E8:55:BC:39:93:CA:70:4F:4E:C2:51:D4:1D:8F
+------BEGIN CERTIFICATE-----
+-MIID9jCCAt6gAwIBAgIQZIKe/DcedF38l/+XyLH/QTANBgkqhkiG9w0BAQsFADCB
+-lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
+-HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
+-YyBDbGFzcyAyIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
+-IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
+-BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
+-eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAy
+-IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
+-MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDNzOkFyGOFyz9AYxe9GPo15gRn
+-V2WYKaRPyVyPDzTS+NqoE2KquB5QZ3iwFkygOakVeq7t0qLA8JA3KRgmXOgNPLZs
+-ST/B4NzZS7YUGQum05bh1gnjGSYc+R9lS/kaQxwAg9bQqkmi1NvmYji6UBRDbfkx
+-+FYW2TgCkc/rbN27OU6Z4TBnRfHU8I3D3/7yOAchfQBeVkSz5GC9kSucq1sEcg+y
+-KNlyqwUgQiWpWwNqIBDMMfAr2jUs0Pual07wgksr2F82owstr2MNHSV/oW5cYqGN
+-KD6h/Bwg+AEvulWaEbAZ0shQeWsOagXXqgQ2sqPy4V93p3ec5R7c6d9qwWVdAgMB
+-AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
+-BBSHjCCVyJhK0daABkqQNETfHE2/sDANBgkqhkiG9w0BAQsFAAOCAQEAgY6ypWaW
+-tyGltu9vI1pf24HFQqV4wWn99DzX+VxrcHIa/FqXTQCAiIiCisNxDY7FiZss7Y0L
+-0nJU9X3UXENX6fOupQIR9nYrgVfdfdp0MP1UR/bgFm6mtApI5ud1Bw8pGTnOefS2
+-bMVfmdUfS/rfbSw8DVSAcPCIC4DPxmiiuB1w2XaM/O6lyc+tHc+ZJVdaYkXLFmu9
+-Sc2lo4xpeSWuuExsi0BmSxY/zwIa3eFsawdhanYVKZl/G92IgMG/tY9zxaaWI4Sm
+-KIYkM2oBLldzJbZev4/mHWGoQClnHYebHX+bn5nNMdZUvmK7OaxoEkiRIKXLsd3+
+-b/xa5IJVWa8xqQ==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem.orig
++++ secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem.orig
++++ secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem.orig
++++ secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/TWCA_Global_Root_CA.pem.orig
++++ secure/caroot/trusted/TWCA_Global_Root_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/TWCA_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/TWCA_Root_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem.orig
++++ secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/TrustCor_ECA-1.pem.orig
++++ secure/caroot/trusted/TrustCor_ECA-1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/TrustCor_RootCert_CA-1.pem.orig
++++ secure/caroot/trusted/TrustCor_RootCert_CA-1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/TrustCor_RootCert_CA-2.pem.orig
++++ secure/caroot/trusted/TrustCor_RootCert_CA-2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Trustis_FPS_Root_CA.pem.orig
++++ secure/caroot/trusted/Trustis_FPS_Root_CA.pem
+@@ -1,92 +0,0 @@
+-##
+-## Trustis FPS Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 1b:1f:ad:b6:20:f9:24:d3:36:6b:f7:c7:f1:8c:a0:59
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
+- Validity
+- Not Before: Dec 23 12:14:06 2003 GMT
+- Not After : Jan 21 11:36:54 2024 GMT
+- Subject: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c5:50:7b:9e:3b:35:d0:df:c4:8c:cd:8e:9b:ed:
+- a3:c0:36:99:f4:42:ea:a7:3e:80:83:0f:a6:a7:59:
+- 87:c9:90:45:43:7e:00:ea:86:79:2a:03:bd:3d:37:
+- 99:89:66:b7:e5:8a:56:86:93:9c:68:4b:68:04:8c:
+- 93:93:02:3e:30:d2:37:3a:22:61:89:1c:85:4e:7d:
+- 8f:d5:af:7b:35:f6:7e:28:47:89:31:dc:0e:79:64:
+- 1f:99:d2:5b:ba:fe:7f:60:bf:ad:eb:e7:3c:38:29:
+- 6a:2f:e5:91:0b:55:ff:ec:6f:58:d5:2d:c9:de:4c:
+- 66:71:8f:0c:d7:04:da:07:e6:1e:18:e3:bd:29:02:
+- a8:fa:1c:e1:5b:b9:83:a8:41:48:bc:1a:71:8d:e7:
+- 62:e5:2d:b2:eb:df:7c:cf:db:ab:5a:ca:31:f1:4c:
+- 22:f3:05:13:f7:82:f9:73:79:0c:be:d7:4b:1c:c0:
+- d1:15:3c:93:41:64:d1:e6:be:23:17:22:00:89:5e:
+- 1f:6b:a5:ac:6e:a7:4b:8c:ed:a3:72:e6:af:63:4d:
+- 2f:85:d2:14:35:9a:2e:4e:8c:ea:32:98:28:86:a1:
+- 91:09:41:3a:b4:e1:e3:f2:fa:f0:c9:0a:a2:41:dd:
+- a9:e3:03:c7:88:15:3b:1c:d4:1a:94:d7:9f:64:59:
+- 12:6d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Authority Key Identifier:
+- keyid:BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
+-
+- X509v3 Subject Key Identifier:
+- BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
+- Signature Algorithm: sha1WithRSAEncryption
+- 7e:58:ff:fd:35:19:7d:9c:18:4f:9e:b0:2b:bc:8e:8c:14:ff:
+- 2c:a0:da:47:5b:c3:ef:81:2d:af:05:ea:74:48:5b:f3:3e:4e:
+- 07:c7:6d:c5:b3:93:cf:22:35:5c:b6:3f:75:27:5f:09:96:cd:
+- a0:fe:be:40:0c:5c:12:55:f8:93:82:ca:29:e9:5e:3f:56:57:
+- 8b:38:36:f7:45:1a:4c:28:cd:9e:41:b8:ed:56:4c:84:a4:40:
+- c8:b8:b0:a5:2b:69:70:04:6a:c3:f8:d4:12:32:f9:0e:c3:b1:
+- dc:32:84:44:2c:6f:cb:46:0f:ea:66:41:0f:4f:f1:58:a5:a6:
+- 0d:0d:0f:61:de:a5:9e:5d:7d:65:a1:3c:17:e7:a8:55:4e:ef:
+- a0:c7:ed:c6:44:7f:54:f5:a3:e0:8f:f0:7c:55:22:8f:29:b6:
+- 81:a3:e1:6d:4e:2c:1b:80:67:ec:ad:20:9f:0c:62:61:d5:97:
+- ff:43:ed:2d:c1:da:5d:29:2a:85:3f:ac:65:ee:86:0f:05:8d:
+- 90:5f:df:ee:9f:f4:bf:ee:1d:fb:98:e4:7f:90:2b:84:78:10:
+- 0e:6c:49:53:ef:15:5b:65:46:4a:5d:af:ba:fb:3a:72:1d:cd:
+- f6:25:88:1e:97:cc:21:9c:29:01:0d:65:eb:57:d9:f3:57:96:
+- bb:48:cd:81
+-SHA1 Fingerprint=3B:C0:38:0B:33:C3:F6:A6:0C:86:15:22:93:D9:DF:F5:4B:81:C0:04
+------BEGIN CERTIFICATE-----
+-MIIDZzCCAk+gAwIBAgIQGx+ttiD5JNM2a/fH8YygWTANBgkqhkiG9w0BAQUFADBF
+-MQswCQYDVQQGEwJHQjEYMBYGA1UEChMPVHJ1c3RpcyBMaW1pdGVkMRwwGgYDVQQL
+-ExNUcnVzdGlzIEZQUyBSb290IENBMB4XDTAzMTIyMzEyMTQwNloXDTI0MDEyMTEx
+-MzY1NFowRTELMAkGA1UEBhMCR0IxGDAWBgNVBAoTD1RydXN0aXMgTGltaXRlZDEc
+-MBoGA1UECxMTVHJ1c3RpcyBGUFMgUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQAD
+-ggEPADCCAQoCggEBAMVQe547NdDfxIzNjpvto8A2mfRC6qc+gIMPpqdZh8mQRUN+
+-AOqGeSoDvT03mYlmt+WKVoaTnGhLaASMk5MCPjDSNzoiYYkchU59j9WvezX2fihH
+-iTHcDnlkH5nSW7r+f2C/revnPDgpai/lkQtV/+xvWNUtyd5MZnGPDNcE2gfmHhjj
+-vSkCqPoc4Vu5g6hBSLwacY3nYuUtsuvffM/bq1rKMfFMIvMFE/eC+XN5DL7XSxzA
+-0RU8k0Fk0ea+IxciAIleH2ulrG6nS4zto3Lmr2NNL4XSFDWaLk6M6jKYKIahkQlB
+-OrTh4/L68MkKokHdqeMDx4gVOxzUGpTXn2RZEm0CAwEAAaNTMFEwDwYDVR0TAQH/
+-BAUwAwEB/zAfBgNVHSMEGDAWgBS6+nEleYtXQSUhhgtx67JkDoshZzAdBgNVHQ4E
+-FgQUuvpxJXmLV0ElIYYLceuyZA6LIWcwDQYJKoZIhvcNAQEFBQADggEBAH5Y//01
+-GX2cGE+esCu8jowU/yyg2kdbw++BLa8F6nRIW/M+TgfHbcWzk88iNVy2P3UnXwmW
+-zaD+vkAMXBJV+JOCyinpXj9WV4s4NvdFGkwozZ5BuO1WTISkQMi4sKUraXAEasP4
+-1BIy+Q7DsdwyhEQsb8tGD+pmQQ9P8Vilpg0ND2HepZ5dfWWhPBfnqFVO76DH7cZE
+-f1T1o+CP8HxVIo8ptoGj4W1OLBuAZ+ytIJ8MYmHVl/9D7S3B2l0pKoU/rGXuhg8F
+-jZBf3+6f9L/uHfuY5H+QK4R4EA5sSVPvFVtlRkpdr7r7OnIdzfYliB6XzCGcKQEN
+-ZetX2fNXlrtIzYE=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Trustwave_Global_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Trustwave_Global_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/UCA_Extended_Validation_Root.pem.orig
++++ secure/caroot/trusted/UCA_Extended_Validation_Root.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/UCA_Global_G2_Root.pem.orig
++++ secure/caroot/trusted/UCA_Global_G2_Root.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem.orig
++++ secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem.orig
++++ secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem
+@@ -1,100 +0,0 @@
+-##
+-## VeriSign Universal Root Certification Authority
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 40:1a:c4:64:21:b3:13:21:03:0e:bb:e4:12:1a:c5:1d
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
+- Validity
+- Not Before: Apr 2 00:00:00 2008 GMT
+- Not After : Dec 1 23:59:59 2037 GMT
+- Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c7:61:37:5e:b1:01:34:db:62:d7:15:9b:ff:58:
+- 5a:8c:23:23:d6:60:8e:91:d7:90:98:83:7a:e6:58:
+- 19:38:8c:c5:f6:e5:64:85:b4:a2:71:fb:ed:bd:b9:
+- da:cd:4d:00:b4:c8:2d:73:a5:c7:69:71:95:1f:39:
+- 3c:b2:44:07:9c:e8:0e:fa:4d:4a:c4:21:df:29:61:
+- 8f:32:22:61:82:c5:87:1f:6e:8c:7c:5f:16:20:51:
+- 44:d1:70:4f:57:ea:e3:1c:e3:cc:79:ee:58:d8:0e:
+- c2:b3:45:93:c0:2c:e7:9a:17:2b:7b:00:37:7a:41:
+- 33:78:e1:33:e2:f3:10:1a:7f:87:2c:be:f6:f5:f7:
+- 42:e2:e5:bf:87:62:89:5f:00:4b:df:c5:dd:e4:75:
+- 44:32:41:3a:1e:71:6e:69:cb:0b:75:46:08:d1:ca:
+- d2:2b:95:d0:cf:fb:b9:40:6b:64:8c:57:4d:fc:13:
+- 11:79:84:ed:5e:54:f6:34:9f:08:01:f3:10:25:06:
+- 17:4a:da:f1:1d:7a:66:6b:98:60:66:a4:d9:ef:d2:
+- 2e:82:f1:f0:ef:09:ea:44:c9:15:6a:e2:03:6e:33:
+- d3:ac:9f:55:00:c7:f6:08:6a:94:b9:5f:dc:e0:33:
+- f1:84:60:f9:5b:27:11:b4:fc:16:f2:bb:56:6a:80:
+- 25:8d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- 1.3.6.1.5.5.7.1.12:
+- 0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif
+- X509v3 Subject Key Identifier:
+- B6:77:FA:69:48:47:9F:53:12:D5:C2:EA:07:32:76:07:D1:97:07:19
+- Signature Algorithm: sha256WithRSAEncryption
+- 4a:f8:f8:b0:03:e6:2c:67:7b:e4:94:77:63:cc:6e:4c:f9:7d:
+- 0e:0d:dc:c8:b9:35:b9:70:4f:63:fa:24:fa:6c:83:8c:47:9d:
+- 3b:63:f3:9a:f9:76:32:95:91:b1:77:bc:ac:9a:be:b1:e4:31:
+- 21:c6:81:95:56:5a:0e:b1:c2:d4:b1:a6:59:ac:f1:63:cb:b8:
+- 4c:1d:59:90:4a:ef:90:16:28:1f:5a:ae:10:fb:81:50:38:0c:
+- 6c:cc:f1:3d:c3:f5:63:e3:b3:e3:21:c9:24:39:e9:fd:15:66:
+- 46:f4:1b:11:d0:4d:73:a3:7d:46:f9:3d:ed:a8:5f:62:d4:f1:
+- 3f:f8:e0:74:57:2b:18:9d:81:b4:c4:28:da:94:97:a5:70:eb:
+- ac:1d:be:07:11:f0:d5:db:dd:e5:8c:f0:d5:32:b0:83:e6:57:
+- e2:8f:bf:be:a1:aa:bf:3d:1d:b5:d4:38:ea:d7:b0:5c:3a:4f:
+- 6a:3f:8f:c0:66:6c:63:aa:e9:d9:a4:16:f4:81:d1:95:14:0e:
+- 7d:cd:95:34:d9:d2:8f:70:73:81:7b:9c:7e:bd:98:61:d8:45:
+- 87:98:90:c5:eb:86:30:c6:35:bf:f0:ff:c3:55:88:83:4b:ef:
+- 05:92:06:71:f2:b8:98:93:b7:ec:cd:82:61:f1:38:e6:4f:97:
+- 98:2a:5a:8d
+-SHA1 Fingerprint=36:79:CA:35:66:87:72:30:4D:30:A5:FB:87:3B:0F:A7:7B:B7:0D:54
+------BEGIN CERTIFICATE-----
+-MIIEuTCCA6GgAwIBAgIQQBrEZCGzEyEDDrvkEhrFHTANBgkqhkiG9w0BAQsFADCB
+-vTELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
+-ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwOCBWZXJp
+-U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MTgwNgYDVQQDEy9W
+-ZXJpU2lnbiBVbml2ZXJzYWwgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAe
+-Fw0wODA0MDIwMDAwMDBaFw0zNzEyMDEyMzU5NTlaMIG9MQswCQYDVQQGEwJVUzEX
+-MBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0
+-IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAyMDA4IFZlcmlTaWduLCBJbmMuIC0gRm9y
+-IGF1dGhvcml6ZWQgdXNlIG9ubHkxODA2BgNVBAMTL1ZlcmlTaWduIFVuaXZlcnNh
+-bCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG9w0BAQEF
+-AAOCAQ8AMIIBCgKCAQEAx2E3XrEBNNti1xWb/1hajCMj1mCOkdeQmIN65lgZOIzF
+-9uVkhbSicfvtvbnazU0AtMgtc6XHaXGVHzk8skQHnOgO+k1KxCHfKWGPMiJhgsWH
+-H26MfF8WIFFE0XBPV+rjHOPMee5Y2A7Cs0WTwCznmhcrewA3ekEzeOEz4vMQGn+H
+-LL729fdC4uW/h2KJXwBL38Xd5HVEMkE6HnFuacsLdUYI0crSK5XQz/u5QGtkjFdN
+-/BMReYTtXlT2NJ8IAfMQJQYXStrxHXpma5hgZqTZ79IugvHw7wnqRMkVauIDbjPT
+-rJ9VAMf2CGqUuV/c4DPxhGD5WycRtPwW8rtWaoAljQIDAQABo4GyMIGvMA8GA1Ud
+-EwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMG0GCCsGAQUFBwEMBGEwX6FdoFsw
+-WTBXMFUWCWltYWdlL2dpZjAhMB8wBwYFKw4DAhoEFI/l0xqGrI2Oa8PPgGrUSBgs
+-exkuMCUWI2h0dHA6Ly9sb2dvLnZlcmlzaWduLmNvbS92c2xvZ28uZ2lmMB0GA1Ud
+-DgQWBBS2d/ppSEefUxLVwuoHMnYH0ZcHGTANBgkqhkiG9w0BAQsFAAOCAQEASvj4
+-sAPmLGd75JR3Y8xuTPl9Dg3cyLk1uXBPY/ok+myDjEedO2Pzmvl2MpWRsXe8rJq+
+-seQxIcaBlVZaDrHC1LGmWazxY8u4TB1ZkErvkBYoH1quEPuBUDgMbMzxPcP1Y+Oz
+-4yHJJDnp/RVmRvQbEdBNc6N9Rvk97ahfYtTxP/jgdFcrGJ2BtMQo2pSXpXDrrB2+
+-BxHw1dvd5Yzw1TKwg+ZX4o+/vqGqvz0dtdQ46tewXDpPaj+PwGZsY6rp2aQW9IHR
+-lRQOfc2VNNnSj3BzgXucfr2YYdhFh5iQxeuGMMY1v/D/w1WIg0vvBZIGcfK4mJO3
+-7M2CYfE45k+XmCpajQ==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem.orig
++++ secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
+@@ -1,87 +0,0 @@
+-##
+-## Verisign Class 1 Public Primary Certification Authority - G3
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 1 (0x0)
+- Serial Number:
+- 8b:5b:75:56:84:54:85:0b:00:cf:af:38:48:ce:b1:a4
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
+- Validity
+- Not Before: Oct 1 00:00:00 1999 GMT
+- Not After : Jul 16 23:59:59 2036 GMT
+- Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:dd:84:d4:b9:b4:f9:a7:d8:f3:04:78:9c:de:3d:
+- dc:6c:13:16:d9:7a:dd:24:51:66:c0:c7:26:59:0d:
+- ac:06:08:c2:94:d1:33:1f:f0:83:35:1f:6e:1b:c8:
+- de:aa:6e:15:4e:54:27:ef:c4:6d:1a:ec:0b:e3:0e:
+- f0:44:a5:57:c7:40:58:1e:a3:47:1f:71:ec:60:f6:
+- 6d:94:c8:18:39:ed:fe:42:18:56:df:e4:4c:49:10:
+- 78:4e:01:76:35:63:12:36:dd:66:bc:01:04:36:a3:
+- 55:68:d5:a2:36:09:ac:ab:21:26:54:06:ad:3f:ca:
+- 14:e0:ac:ca:ad:06:1d:95:e2:f8:9d:f1:e0:60:ff:
+- c2:7f:75:2b:4c:cc:da:fe:87:99:21:ea:ba:fe:3e:
+- 54:d7:d2:59:78:db:3c:6e:cf:a0:13:00:1a:b8:27:
+- a1:e4:be:67:96:ca:a0:c5:b3:9c:dd:c9:75:9e:eb:
+- 30:9a:5f:a3:cd:d9:ae:78:19:3f:23:e9:5c:db:29:
+- bd:ad:55:c8:1b:54:8c:63:f6:e8:a6:ea:c7:37:12:
+- 5c:a3:29:1e:02:d9:db:1f:3b:b4:d7:0f:56:47:81:
+- 15:04:4a:af:83:27:d1:c5:58:88:c1:dd:f6:aa:a7:
+- a3:18:da:68:aa:6d:11:51:e1:bf:65:6b:9f:96:76:
+- d1:3d
+- Exponent: 65537 (0x10001)
+- Signature Algorithm: sha1WithRSAEncryption
+- ab:66:8d:d7:b3:ba:c7:9a:b6:e6:55:d0:05:f1:9f:31:8d:5a:
+- aa:d9:aa:46:26:0f:71:ed:a5:ad:53:56:62:01:47:2a:44:e9:
+- fe:3f:74:0b:13:9b:b9:f4:4d:1b:b2:d1:5f:b2:b6:d2:88:5c:
+- b3:9f:cd:cb:d4:a7:d9:60:95:84:3a:f8:c1:37:1d:61:ca:e7:
+- b0:c5:e5:91:da:54:a6:ac:31:81:ae:97:de:cd:08:ac:b8:c0:
+- 97:80:7f:6e:72:a4:e7:69:13:95:65:1f:c4:93:3c:fd:79:8f:
+- 04:d4:3e:4f:ea:f7:9e:ce:cd:67:7c:4f:65:02:ff:91:85:54:
+- 73:c7:ff:36:f7:86:2d:ec:d0:5e:4f:ff:11:9f:72:06:d6:b8:
+- 1a:f1:4c:0d:26:65:e2:44:80:1e:c7:9f:e3:dd:e8:0a:da:ec:
+- a5:20:80:69:68:a1:4f:7e:e1:6b:cf:07:41:fa:83:8e:bc:38:
+- dd:b0:2e:11:b1:6b:b2:42:cc:9a:bc:f9:48:22:79:4a:19:0f:
+- b2:1c:3e:20:74:d9:6a:c3:be:f2:28:78:13:56:79:4f:6d:50:
+- ea:1b:b0:b5:57:b1:37:66:58:23:f3:dc:0f:df:0a:87:c4:ef:
+- 86:05:d5:38:14:60:99:a3:4b:de:06:96:71:2c:f2:db:b6:1f:
+- a4:ef:3f:ee
+-SHA1 Fingerprint=20:42:85:DC:F7:EB:76:41:95:57:8E:13:6B:D4:B7:D1:E9:8E:46:A5
+------BEGIN CERTIFICATE-----
+-MIIEGjCCAwICEQCLW3VWhFSFCwDPrzhIzrGkMA0GCSqGSIb3DQEBBQUAMIHKMQsw
+-CQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZl
+-cmlTaWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWdu
+-LCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlT
+-aWduIENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3Jp
+-dHkgLSBHMzAeFw05OTEwMDEwMDAwMDBaFw0zNjA3MTYyMzU5NTlaMIHKMQswCQYD
+-VQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlT
+-aWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWduLCBJ
+-bmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlTaWdu
+-IENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkg
+-LSBHMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAN2E1Lm0+afY8wR4
+-nN493GwTFtl63SRRZsDHJlkNrAYIwpTRMx/wgzUfbhvI3qpuFU5UJ+/EbRrsC+MO
+-8ESlV8dAWB6jRx9x7GD2bZTIGDnt/kIYVt/kTEkQeE4BdjVjEjbdZrwBBDajVWjV
+-ojYJrKshJlQGrT/KFOCsyq0GHZXi+J3x4GD/wn91K0zM2v6HmSHquv4+VNfSWXjb
+-PG7PoBMAGrgnoeS+Z5bKoMWznN3JdZ7rMJpfo83ZrngZPyPpXNspva1VyBtUjGP2
+-6KbqxzcSXKMpHgLZ2x87tNcPVkeBFQRKr4Mn0cVYiMHd9qqnoxjaaKptEVHhv2Vr
+-n5Z20T0CAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAq2aN17O6x5q25lXQBfGfMY1a
+-qtmqRiYPce2lrVNWYgFHKkTp/j90CxObufRNG7LRX7K20ohcs5/Ny9Sn2WCVhDr4
+-wTcdYcrnsMXlkdpUpqwxga6X3s0IrLjAl4B/bnKk52kTlWUfxJM8/XmPBNQ+T+r3
+-ns7NZ3xPZQL/kYVUc8f/NveGLezQXk//EZ9yBta4GvFMDSZl4kSAHsef493oCtrs
+-pSCAaWihT37ha88HQfqDjrw43bAuEbFrskLMmrz5SCJ5ShkPshw+IHTZasO+8ih4
+-E1Z5T21Q6huwtVexN2ZYI/PcD98Kh8TvhgXVOBRgmaNL3gaWcSzy27YfpO8/7g==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem.orig
++++ secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
+@@ -1,87 +0,0 @@
+-##
+-## Verisign Class 2 Public Primary Certification Authority - G3
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 1 (0x0)
+- Serial Number:
+- 61:70:cb:49:8c:5f:98:45:29:e7:b0:a6:d9:50:5b:7a
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
+- Validity
+- Not Before: Oct 1 00:00:00 1999 GMT
+- Not After : Jul 16 23:59:59 2036 GMT
+- Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:af:0a:0d:c2:d5:2c:db:67:b9:2d:e5:94:27:dd:
+- a5:be:e0:b0:4d:8f:b3:61:56:3c:d6:7c:c3:f4:cd:
+- 3e:86:cb:a2:88:e2:e1:d8:a4:69:c5:b5:e2:bf:c1:
+- a6:47:50:5e:46:39:8b:d5:96:ba:b5:6f:14:bf:10:
+- ce:27:13:9e:05:47:9b:31:7a:13:d8:1f:d9:d3:02:
+- 37:8b:ad:2c:47:f0:8e:81:06:a7:0d:30:0c:eb:f7:
+- 3c:0f:20:1d:dc:72:46:ee:a5:02:c8:5b:c3:c9:56:
+- 69:4c:c5:18:c1:91:7b:0b:d5:13:00:9b:bc:ef:c3:
+- 48:3e:46:60:20:85:2a:d5:90:b6:cd:8b:a0:cc:32:
+- dd:b7:fd:40:55:b2:50:1c:56:ae:cc:8d:77:4d:c7:
+- 20:4d:a7:31:76:ef:68:92:8a:90:1e:08:81:56:b2:
+- ad:69:a3:52:d0:cb:1c:c4:23:3d:1f:99:fe:4c:e8:
+- 16:63:8e:c6:08:8e:f6:31:f6:d2:fa:e5:76:dd:b5:
+- 1c:92:a3:49:cd:cd:01:cd:68:cd:a9:69:ba:a3:eb:
+- 1d:0d:9c:a4:20:a6:c1:a0:c5:d1:46:4c:17:6d:d2:
+- ac:66:3f:96:8c:e0:84:d4:36:ff:22:59:c5:f9:11:
+- 60:a8:5f:04:7d:f2:1a:f6:25:42:61:0f:c4:4a:b8:
+- 3e:89
+- Exponent: 65537 (0x10001)
+- Signature Algorithm: sha1WithRSAEncryption
+- 34:26:15:3c:c0:8d:4d:43:49:1d:bd:e9:21:92:d7:66:9c:b7:
+- de:c5:b8:d0:e4:5d:5f:76:22:c0:26:f9:84:3a:3a:f9:8c:b5:
+- fb:ec:60:f1:e8:ce:04:b0:c8:dd:a7:03:8f:30:f3:98:df:a4:
+- e6:a4:31:df:d3:1c:0b:46:dc:72:20:3f:ae:ee:05:3c:a4:33:
+- 3f:0b:39:ac:70:78:73:4b:99:2b:df:30:c2:54:b0:a8:3b:55:
+- a1:fe:16:28:cd:42:bd:74:6e:80:db:27:44:a7:ce:44:5d:d4:
+- 1b:90:98:0d:1e:42:94:b1:00:2c:04:d0:74:a3:02:05:22:63:
+- 63:cd:83:b5:fb:c1:6d:62:6b:69:75:fd:5d:70:41:b9:f5:bf:
+- 7c:df:be:c1:32:73:22:21:8b:58:81:7b:15:91:7a:ba:e3:64:
+- 48:b0:7f:fb:36:25:da:95:d0:f1:24:14:17:dd:18:80:6b:46:
+- 23:39:54:f5:8e:62:09:04:1d:94:90:a6:9b:e6:25:e2:42:45:
+- aa:b8:90:ad:be:08:8f:a9:0b:42:18:94:cf:72:39:e1:b1:43:
+- e0:28:cf:b7:e7:5a:6c:13:6b:49:b3:ff:e3:18:7c:89:8b:33:
+- 5d:ac:33:d7:a7:f9:da:3a:55:c9:58:10:f9:aa:ef:5a:b6:cf:
+- 4b:4b:df:2a
+-SHA1 Fingerprint=61:EF:43:D7:7F:CA:D4:61:51:BC:98:E0:C3:59:12:AF:9F:EB:63:11
+------BEGIN CERTIFICATE-----
+-MIIEGTCCAwECEGFwy0mMX5hFKeewptlQW3owDQYJKoZIhvcNAQEFBQAwgcoxCzAJ
+-BgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVy
+-aVNpZ24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24s
+-IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNp
+-Z24gQ2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
+-eSAtIEczMB4XDTk5MTAwMTAwMDAwMFoXDTM2MDcxNjIzNTk1OVowgcoxCzAJBgNV
+-BAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVyaVNp
+-Z24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24sIElu
+-Yy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNpZ24g
+-Q2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAt
+-IEczMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArwoNwtUs22e5LeWU
+-J92lvuCwTY+zYVY81nzD9M0+hsuiiOLh2KRpxbXiv8GmR1BeRjmL1Za6tW8UvxDO
+-JxOeBUebMXoT2B/Z0wI3i60sR/COgQanDTAM6/c8DyAd3HJG7qUCyFvDyVZpTMUY
+-wZF7C9UTAJu878NIPkZgIIUq1ZC2zYugzDLdt/1AVbJQHFauzI13TccgTacxdu9o
+-koqQHgiBVrKtaaNS0MscxCM9H5n+TOgWY47GCI72MfbS+uV23bUckqNJzc0BzWjN
+-qWm6o+sdDZykIKbBoMXRRkwXbdKsZj+WjOCE1Db/IlnF+RFgqF8EffIa9iVCYQ/E
+-Srg+iQIDAQABMA0GCSqGSIb3DQEBBQUAA4IBAQA0JhU8wI1NQ0kdvekhktdmnLfe
+-xbjQ5F1fdiLAJvmEOjr5jLX77GDx6M4EsMjdpwOPMPOY36TmpDHf0xwLRtxyID+u
+-7gU8pDM/CzmscHhzS5kr3zDCVLCoO1Wh/hYozUK9dG6A2ydEp85EXdQbkJgNHkKU
+-sQAsBNB0owIFImNjzYO1+8FtYmtpdf1dcEG59b98377BMnMiIYtYgXsVkXq642RI
+-sH/7NiXaldDxJBQX3RiAa0YjOVT1jmIJBB2UkKab5iXiQkWquJCtvgiPqQtCGJTP
+-cjnhsUPgKM+351psE2tJs//jGHyJizNdrDPXp/naOlXJWBD5qu9ats9LS98q
+------END CERTIFICATE-----
+--- secure/caroot/trusted/XRamp_Global_CA_Root.pem.orig
++++ secure/caroot/trusted/XRamp_Global_CA_Root.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/certSIGN_ROOT_CA.pem.orig
++++ secure/caroot/trusted/certSIGN_ROOT_CA.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/certSIGN_Root_CA_G2.pem.orig
++++ secure/caroot/trusted/certSIGN_Root_CA_G2.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/e-Szigno_Root_CA_2017.pem.orig
++++ secure/caroot/trusted/e-Szigno_Root_CA_2017.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/ePKI_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/ePKI_Root_Certification_Authority.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem.orig
++++ secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem.orig
++++ secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/emSign_Root_CA_-_C1.pem.orig
++++ secure/caroot/trusted/emSign_Root_CA_-_C1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
+--- secure/caroot/trusted/emSign_Root_CA_-_G1.pem.orig
++++ secure/caroot/trusted/emSign_Root_CA_-_G1.pem
+@@ -5,8 +5,10 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+-## with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
++## with $FreeBSD$
+ ##
+ ## @generated
+ ##
diff --git a/website/static/security/patches/EN-21:27/caroot.12.patch.asc b/website/static/security/patches/EN-21:27/caroot.12.patch.asc
new file mode 100644
index 0000000000..0c46316c29
--- /dev/null
+++ b/website/static/security/patches/EN-21:27/caroot.12.patch.asc
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAABCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD88ACgkQ05eS9J6n
+5cJjuw//TgMbCZWYID1+KnRaHYShV2B4jVn+17/3u/ttvMIk+HGSgWhVq43o5Jb0
+0Ovt1A2lwK3rTnG1NZthQe/esnDc/OIbISY4TZ5pCYEo388ayn1rmGooItqpHBjQ
+kI8u/Xh9ObICnezCu54wVuOkQhI0c2JlToekdowDTzG0YokyrxpfIzI+ZbdMtpNa
+YAYZKMHxhd6sWvUvGtVJUITWXVA9zVWETFq8aV19GEfV/L5HwAO84tR1krTch2c/
+hy6oQWNvbuvrvKkOWz7LPvcNyw9JyWvRvhgJt2+7WVmHe99Myh4zE9VuduT3IE9v
+iuujitefySngz38ZE4ZpLRj9WdC1LrsXZNeZpg5jFWOnoXHHneAPwQCIMy3/26U3
+TbrPujUlcff5lx2COZkl0+Xi2qSIJGLFtfWSsTxN7QOptKER++8RcUabTp9MAY7j
+E4lGBxGztUg6fb3LJsEEvr9v0YdTV2AgWfrAJy5M9FLPksVZdyEQvtqYh2yhk/Ww
+l0I7C2FH9TMp51VtbKajOGGR8OwLAu5EIKjebZfYxOFRRIqfhQ3Ebemp8n0bo4oP
+HrtwJUKR2+NJ8KmmQtYKWNf9N3JfgUf+B4pTdi9JgD4OrYlqN1r8z4XehcHjZwg0
+bA7KgDaesEY+kBw2aZlWBbBTKlaeL51chzp8nk4n0xHZxn8E8PQ=
+=swRb
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-21:27/caroot.13.patch b/website/static/security/patches/EN-21:27/caroot.13.patch
new file mode 100644
index 0000000000..b443c2d4d3
--- /dev/null
+++ b/website/static/security/patches/EN-21:27/caroot.13.patch
@@ -0,0 +1,6374 @@
+--- secure/caroot/MAca-bundle.pl.orig
++++ secure/caroot/MAca-bundle.pl
+@@ -76,6 +76,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $VERSION
+ ##
+@@ -91,6 +93,8 @@
+ ## Authorities (CA). These were automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt').
+ ##
++## It contains certificates trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $VERSION
+ ##
+@@ -100,6 +104,13 @@
+ }
+ }
+
++# returns a string like YYMMDDhhmmssZ of current time in GMT zone
++sub timenow()
++{
++ my ($sec,$min,$hour,$mday,$mon,$year,undef,undef,undef) = gmtime(time);
++ return sprintf "%02d%02d%02d%02d%02d%02dZ", $year-100, $mon+1, $mday, $hour, $min, $sec;
++}
++
+ sub printcert($$$)
+ {
+ my ($fh, $label, $certdata) = @_;
+@@ -110,6 +121,8 @@
+ close(OUT) or die "openssl x509 failed with exit code $?";
+ }
+
++# converts a datastream that is to be \177-style octal constants
++# from <> to a (binary) string and returns it
+ sub graboct($)
+ {
+ my $ifh = shift;
+@@ -125,13 +138,13 @@
+ return $data;
+ }
+
+-
+ sub grabcert($)
+ {
+ my $ifh = shift;
+ my $certdata;
+- my $cka_label;
+- my $serial;
++ my $cka_label = '';
++ my $serial = 0;
++ my $distrust = 0;
+
+ while (<$ifh>) {
+ chomp;
+@@ -148,6 +161,19 @@
+ if (/^CKA_SERIAL_NUMBER MULTILINE_OCTAL/) {
+ $serial = graboct($ifh);
+ }
++
++ if (/^CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL/)
++ {
++ my $distrust_after = graboct($ifh);
++ my $time_now = timenow();
++ if ($time_now >= $distrust_after) { $distrust = 1; }
++ if ($debug) {
++ printf STDERR "line $.: $cka_label ser #%d: distrust after %s, now: %s -> distrust $distrust\n", $serial, $distrust_after, timenow();
++ }
++ if ($distrust) {
++ return undef;
++ }
++ }
+ }
+ return ($serial, $cka_label, $certdata);
+ }
+@@ -171,13 +197,13 @@
+ $serial = graboct($ifh);
+ }
+
+- if (/^CKA_TRUST_(SERVER_AUTH|EMAIL_PROTECTION|CODE_SIGNING) CK_TRUST (\S+)$/)
++ if (/^CKA_TRUST_SERVER_AUTH CK_TRUST (\S+)$/)
+ {
+- if ($2 eq 'CKT_NSS_NOT_TRUSTED') {
++ if ($1 eq 'CKT_NSS_NOT_TRUSTED') {
+ $distrust = 1;
+- } elsif ($2 eq 'CKT_NSS_TRUSTED_DELEGATOR') {
++ } elsif ($1 eq 'CKT_NSS_TRUSTED_DELEGATOR') {
+ $maytrust = 1;
+- } elsif ($2 ne 'CKT_NSS_MUST_VERIFY_TRUST') {
++ } elsif ($1 ne 'CKT_NSS_MUST_VERIFY_TRUST') {
+ confess "Unknown trust setting on line $.:\n"
+ . "$_\n"
+ . "Script must be updated:";
+@@ -197,16 +223,22 @@
+ print_header(*STDOUT, "");
+ }
+
++my $untrusted = 0;
++
+ while (<$inputfh>) {
+ if (/^CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE/) {
+ my ($serial, $label, $certdata) = grabcert($inputfh);
+ if (defined $certs{$label."\0".$serial}) {
+ warn "Certificate $label duplicated!\n";
+ }
+- $certs{$label."\0".$serial} = $certdata;
+- # We store the label in a separate hash because truncating the key
+- # with \0 was causing garbage data after the end of the text.
+- $labels{$label."\0".$serial} = $label;
++ if (defined $certdata) {
++ $certs{$label."\0".$serial} = $certdata;
++ # We store the label in a separate hash because truncating the key
++ # with \0 was causing garbage data after the end of the text.
++ $labels{$label."\0".$serial} = $label;
++ } else { # $certdata undefined? distrust_after in effect
++ $untrusted ++;
++ }
+ } elsif (/^CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST/) {
+ my ($serial, $label, $trust) = grabtrust($inputfh);
+ if (defined $trusts{$label."\0".$serial}) {
+@@ -226,7 +258,6 @@
+ }
+
+ # weed out untrusted certificates
+-my $untrusted = 0;
+ foreach my $it (keys %trusts) {
+ if (!$trusts{$it}) {
+ if (!exists($certs{$it})) {
+--- /dev/null
++++ secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
+@@ -0,0 +1,112 @@
++##
++## Camerfirma Chambers of Commerce Root
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 0 (0x0)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
++ Validity
++ Not Before: Sep 30 16:13:43 2003 GMT
++ Not After : Sep 30 16:13:44 2037 GMT
++ Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:b7:36:55:e5:a5:5d:18:30:e0:da:89:54:91:fc:
++ c8:c7:52:f8:2f:50:d9:ef:b1:75:73:65:47:7d:1b:
++ 5b:ba:75:c5:fc:a1:88:24:fa:2f:ed:ca:08:4a:39:
++ 54:c4:51:7a:b5:da:60:ea:38:3c:81:b2:cb:f1:bb:
++ d9:91:23:3f:48:01:70:75:a9:05:2a:ad:1f:71:f3:
++ c9:54:3d:1d:06:6a:40:3e:b3:0c:85:ee:5c:1b:79:
++ c2:62:c4:b8:36:8e:35:5d:01:0c:23:04:47:35:aa:
++ 9b:60:4e:a0:66:3d:cb:26:0a:9c:40:a1:f4:5d:98:
++ bf:71:ab:a5:00:68:2a:ed:83:7a:0f:a2:14:b5:d4:
++ 22:b3:80:b0:3c:0c:5a:51:69:2d:58:18:8f:ed:99:
++ 9e:f1:ae:e2:95:e6:f6:47:a8:d6:0c:0f:b0:58:58:
++ db:c3:66:37:9e:9b:91:54:33:37:d2:94:1c:6a:48:
++ c9:c9:f2:a5:da:a5:0c:23:f7:23:0e:9c:32:55:5e:
++ 71:9c:84:05:51:9a:2d:fd:e6:4e:2a:34:5a:de:ca:
++ 40:37:67:0c:54:21:55:77:da:0a:0c:cc:97:ae:80:
++ dc:94:36:4a:f4:3e:ce:36:13:1e:53:e4:ac:4e:3a:
++ 05:ec:db:ae:72:9c:38:8b:d0:39:3b:89:0a:3e:77:
++ fe:75
++ Exponent: 3 (0x3)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 CRL Distribution Points:
++
++ Full Name:
++ URI:http://crl.chambersign.org/chambersroot.crl
++
++ X509v3 Subject Key Identifier:
++ E3:94:F5:B1:4D:E9:DB:A1:29:5B:57:8B:4D:76:06:76:E1:D1:A2:8A
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Netscape Cert Type:
++ SSL CA, S/MIME CA, Object Signing CA
++ X509v3 Subject Alternative Name:
++ email:chambersroot@chambersign.org
++ X509v3 Issuer Alternative Name:
++ email:chambersroot@chambersign.org
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.17326.10.3.1
++ CPS: http://cps.chambersign.org/cps/chambersroot.html
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 0c:41:97:c2:1a:86:c0:22:7c:9f:fb:90:f3:1a:d1:03:b1:ef:
++ 13:f9:21:5f:04:9c:da:c9:a5:8d:27:6c:96:87:91:be:41:90:
++ 01:72:93:e7:1e:7d:5f:f6:89:c6:5d:a7:40:09:3d:ac:49:45:
++ 45:dc:2e:8d:30:68:b2:09:ba:fb:c3:2f:cc:ba:0b:df:3f:77:
++ 7b:46:7d:3a:12:24:8e:96:8f:3c:05:0a:6f:d2:94:28:1d:6d:
++ 0c:c0:2e:88:22:d5:d8:cf:1d:13:c7:f0:48:d7:d7:05:a7:cf:
++ c7:47:9e:3b:3c:34:c8:80:4f:d4:14:bb:fc:0d:50:f7:fa:b3:
++ ec:42:5f:a9:dd:6d:c8:f4:75:cf:7b:c1:72:26:b1:01:1c:5c:
++ 2c:fd:7a:4e:b4:01:c5:05:57:b9:e7:3c:aa:05:d9:88:e9:07:
++ 46:41:ce:ef:41:81:ae:58:df:83:a2:ae:ca:d7:77:1f:e7:00:
++ 3c:9d:6f:8e:e4:32:09:1d:4d:78:34:78:34:3c:94:9b:26:ed:
++ 4f:71:c6:19:7a:bd:20:22:48:5a:fe:4b:7d:03:b7:e7:58:be:
++ c6:32:4e:74:1e:68:dd:a8:68:5b:b3:3e:ee:62:7d:d9:80:e8:
++ 0a:75:7a:b7:ee:b4:65:9a:21:90:e0:aa:d0:98:bc:38:b5:73:
++ 3c:8b:f8:dc
++SHA1 Fingerprint=6E:3A:55:A4:19:0C:19:5C:93:84:3C:C0:DB:72:2E:31:30:61:F0:B1
++-----BEGIN CERTIFICATE-----
++MIIEvTCCA6WgAwIBAgIBADANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJFVTEn
++MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
++ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEiMCAGA1UEAxMZQ2hhbWJlcnMg
++b2YgQ29tbWVyY2UgUm9vdDAeFw0wMzA5MzAxNjEzNDNaFw0zNzA5MzAxNjEzNDRa
++MH8xCzAJBgNVBAYTAkVVMScwJQYDVQQKEx5BQyBDYW1lcmZpcm1hIFNBIENJRiBB
++ODI3NDMyODcxIzAhBgNVBAsTGmh0dHA6Ly93d3cuY2hhbWJlcnNpZ24ub3JnMSIw
++IAYDVQQDExlDaGFtYmVycyBvZiBDb21tZXJjZSBSb290MIIBIDANBgkqhkiG9w0B
++AQEFAAOCAQ0AMIIBCAKCAQEAtzZV5aVdGDDg2olUkfzIx1L4L1DZ77F1c2VHfRtb
++unXF/KGIJPov7coISjlUxFF6tdpg6jg8gbLL8bvZkSM/SAFwdakFKq0fcfPJVD0d
++BmpAPrMMhe5cG3nCYsS4No41XQEMIwRHNaqbYE6gZj3LJgqcQKH0XZi/caulAGgq
++7YN6D6IUtdQis4CwPAxaUWktWBiP7Zme8a7ileb2R6jWDA+wWFjbw2Y3npuRVDM3
++0pQcakjJyfKl2qUMI/cjDpwyVV5xnIQFUZot/eZOKjRa3spAN2cMVCFVd9oKDMyX
++roDclDZK9D7ONhMeU+SsTjoF7Nuucpw4i9A5O4kKPnf+dQIBA6OCAUQwggFAMBIG
++A1UdEwEB/wQIMAYBAf8CAQwwPAYDVR0fBDUwMzAxoC+gLYYraHR0cDovL2NybC5j
++aGFtYmVyc2lnbi5vcmcvY2hhbWJlcnNyb290LmNybDAdBgNVHQ4EFgQU45T1sU3p
++26EpW1eLTXYGduHRooowDgYDVR0PAQH/BAQDAgEGMBEGCWCGSAGG+EIBAQQEAwIA
++BzAnBgNVHREEIDAegRxjaGFtYmVyc3Jvb3RAY2hhbWJlcnNpZ24ub3JnMCcGA1Ud
++EgQgMB6BHGNoYW1iZXJzcm9vdEBjaGFtYmVyc2lnbi5vcmcwWAYDVR0gBFEwTzBN
++BgsrBgEEAYGHLgoDATA+MDwGCCsGAQUFBwIBFjBodHRwOi8vY3BzLmNoYW1iZXJz
++aWduLm9yZy9jcHMvY2hhbWJlcnNyb290Lmh0bWwwDQYJKoZIhvcNAQEFBQADggEB
++AAxBl8IahsAifJ/7kPMa0QOx7xP5IV8EnNrJpY0nbJaHkb5BkAFyk+cefV/2icZd
++p0AJPaxJRUXcLo0waLIJuvvDL8y6C98/d3tGfToSJI6WjzwFCm/SlCgdbQzALogi
++1djPHRPH8EjX1wWnz8dHnjs8NMiAT9QUu/wNUPf6s+xCX6ndbcj0dc97wXImsQEc
++XCz9ek60AcUFV7nnPKoF2YjpB0ZBzu9Bga5Y34OirsrXdx/nADydb47kMgkdTXg0
++eDQ8lJsm7U9xxhl6vSAiSFr+S30Dt+dYvsYyTnQeaN2oaFuzPu5ifdmA6Ap1erfu
++tGWaIZDgqtCYvDi1czyL+Nw=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem
+@@ -0,0 +1,112 @@
++##
++## Camerfirma Global Chambersign Root
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 0 (0x0)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
++ Validity
++ Not Before: Sep 30 16:14:18 2003 GMT
++ Not After : Sep 30 16:14:18 2037 GMT
++ Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:a2:70:a2:d0:9f:42:ae:5b:17:c7:d8:7d:cf:14:
++ 83:fc:4f:c9:a1:b7:13:af:8a:d7:9e:3e:04:0a:92:
++ 8b:60:56:fa:b4:32:2f:88:4d:a1:60:08:f4:b7:09:
++ 4e:a0:49:2f:49:d6:d3:df:9d:97:5a:9f:94:04:70:
++ ec:3f:59:d9:b7:cc:66:8b:98:52:28:09:02:df:c5:
++ 2f:84:8d:7a:97:77:bf:ec:40:9d:25:72:ab:b5:3f:
++ 32:98:fb:b7:b7:fc:72:84:e5:35:87:f9:55:fa:a3:
++ 1f:0e:6f:2e:28:dd:69:a0:d9:42:10:c6:f8:b5:44:
++ c2:d0:43:7f:db:bc:e4:a2:3c:6a:55:78:0a:77:a9:
++ d8:ea:19:32:b7:2f:fe:5c:3f:1b:ee:b1:98:ec:ca:
++ ad:7a:69:45:e3:96:0f:55:f6:e6:ed:75:ea:65:e8:
++ 32:56:93:46:89:a8:25:8a:65:06:ee:6b:bf:79:07:
++ d0:f1:b7:af:ed:2c:4d:92:bb:c0:a8:5f:a7:67:7d:
++ 04:f2:15:08:70:ac:92:d6:7d:04:d2:33:fb:4c:b6:
++ 0b:0b:fb:1a:c9:c4:8d:03:a9:7e:5c:f2:50:ab:12:
++ a5:a1:cf:48:50:a5:ef:d2:c8:1a:13:fa:b0:7f:b1:
++ 82:1c:77:6a:0f:5f:dc:0b:95:8f:ef:43:7e:e6:45:
++ 09:25
++ Exponent: 3 (0x3)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 CRL Distribution Points:
++
++ Full Name:
++ URI:http://crl.chambersign.org/chambersignroot.crl
++
++ X509v3 Subject Key Identifier:
++ 43:9C:36:9F:B0:9E:30:4D:C6:CE:5F:AD:10:AB:E5:03:A5:FA:A9:14
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Netscape Cert Type:
++ SSL CA, S/MIME CA, Object Signing CA
++ X509v3 Subject Alternative Name:
++ email:chambersignroot@chambersign.org
++ X509v3 Issuer Alternative Name:
++ email:chambersignroot@chambersign.org
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.17326.10.1.1
++ CPS: http://cps.chambersign.org/cps/chambersignroot.html
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 3c:3b:70:91:f9:04:54:27:91:e1:ed:ed:fe:68:7f:61:5d:e5:
++ 41:65:4f:32:f1:18:05:94:6a:1c:de:1f:70:db:3e:7b:32:02:
++ 34:b5:0c:6c:a1:8a:7c:a5:f4:8f:ff:d4:d8:ad:17:d5:2d:04:
++ d1:3f:58:80:e2:81:59:88:be:c0:e3:46:93:24:fe:90:bd:26:
++ a2:30:2d:e8:97:26:57:35:89:74:96:18:f6:15:e2:af:24:19:
++ 56:02:02:b2:ba:0f:14:ea:c6:8a:66:c1:86:45:55:8b:be:92:
++ be:9c:a4:04:c7:49:3c:9e:e8:29:7a:89:d7:fe:af:ff:68:f5:
++ a5:17:90:bd:ac:99:cc:a5:86:57:09:67:46:db:d6:16:c2:46:
++ f1:e4:a9:50:f5:8f:d1:92:15:d3:5f:3e:c6:00:49:3a:6e:58:
++ b2:d1:d1:27:0d:25:c8:32:f8:20:11:cd:7d:32:33:48:94:54:
++ 4c:dd:dc:79:c4:30:9f:eb:8e:b8:55:b5:d7:88:5c:c5:6a:24:
++ 3d:b2:d3:05:03:51:c6:07:ef:cc:14:72:74:3d:6e:72:ce:18:
++ 28:8c:4a:a0:77:e5:09:2b:45:44:47:ac:b7:67:7f:01:8a:05:
++ 5a:93:be:a1:c1:ff:f8:e7:0e:67:a4:47:49:76:5d:75:90:1a:
++ f5:26:8f:f0
++SHA1 Fingerprint=33:9B:6B:14:50:24:9B:55:7A:01:87:72:84:D9:E0:2F:C3:D2:D8:E9
++-----BEGIN CERTIFICATE-----
++MIIExTCCA62gAwIBAgIBADANBgkqhkiG9w0BAQUFADB9MQswCQYDVQQGEwJFVTEn
++MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
++ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4GA1UEAxMXR2xvYmFsIENo
++YW1iZXJzaWduIFJvb3QwHhcNMDMwOTMwMTYxNDE4WhcNMzcwOTMwMTYxNDE4WjB9
++MQswCQYDVQQGEwJFVTEnMCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgy
++NzQzMjg3MSMwIQYDVQQLExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4G
++A1UEAxMXR2xvYmFsIENoYW1iZXJzaWduIFJvb3QwggEgMA0GCSqGSIb3DQEBAQUA
++A4IBDQAwggEIAoIBAQCicKLQn0KuWxfH2H3PFIP8T8mhtxOviteePgQKkotgVvq0
++Mi+ITaFgCPS3CU6gSS9J1tPfnZdan5QEcOw/Wdm3zGaLmFIoCQLfxS+EjXqXd7/s
++QJ0lcqu1PzKY+7e3/HKE5TWH+VX6ox8Oby4o3Wmg2UIQxvi1RMLQQ3/bvOSiPGpV
++eAp3qdjqGTK3L/5cPxvusZjsyq16aUXjlg9V9ubtdepl6DJWk0aJqCWKZQbua795
++B9Dxt6/tLE2Su8CoX6dnfQTyFQhwrJLWfQTSM/tMtgsL+xrJxI0DqX5c8lCrEqWh
++z0hQpe/SyBoT+rB/sYIcd2oPX9wLlY/vQ37mRQklAgEDo4IBUDCCAUwwEgYDVR0T
++AQH/BAgwBgEB/wIBDDA/BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vY3JsLmNoYW1i
++ZXJzaWduLm9yZy9jaGFtYmVyc2lnbnJvb3QuY3JsMB0GA1UdDgQWBBRDnDafsJ4w
++TcbOX60Qq+UDpfqpFDAOBgNVHQ8BAf8EBAMCAQYwEQYJYIZIAYb4QgEBBAQDAgAH
++MCoGA1UdEQQjMCGBH2NoYW1iZXJzaWducm9vdEBjaGFtYmVyc2lnbi5vcmcwKgYD
++VR0SBCMwIYEfY2hhbWJlcnNpZ25yb290QGNoYW1iZXJzaWduLm9yZzBbBgNVHSAE
++VDBSMFAGCysGAQQBgYcuCgEBMEEwPwYIKwYBBQUHAgEWM2h0dHA6Ly9jcHMuY2hh
++bWJlcnNpZ24ub3JnL2Nwcy9jaGFtYmVyc2lnbnJvb3QuaHRtbDANBgkqhkiG9w0B
++AQUFAAOCAQEAPDtwkfkEVCeR4e3t/mh/YV3lQWVPMvEYBZRqHN4fcNs+ezICNLUM
++bKGKfKX0j//U2K0X1S0E0T9YgOKBWYi+wONGkyT+kL0mojAt6JcmVzWJdJYY9hXi
++ryQZVgICsroPFOrGimbBhkVVi76SvpykBMdJPJ7oKXqJ1/6v/2j1pReQvayZzKWG
++VwlnRtvWFsJG8eSpUPWP0ZIV018+xgBJOm5YstHRJw0lyDL4IBHNfTIzSJRUTN3c
++ecQwn+uOuFW114hcxWokPbLTBQNRxgfvzBRydD1ucs4YKIxKoHflCStFREest2d/
++AYoFWpO+ocH/+OcOZ6RHSXZddZAa9SaP8A==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Certum_Root_CA.pem
+@@ -0,0 +1,84 @@
++##
++## Certum Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 65568 (0x10020)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
++ Validity
++ Not Before: Jun 11 10:46:39 2002 GMT
++ Not After : Jun 11 10:46:39 2027 GMT
++ Subject: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:ce:b1:c1:2e:d3:4f:7c:cd:25:ce:18:3e:4f:c4:
++ 8c:6f:80:6a:73:c8:5b:51:f8:9b:d2:dc:bb:00:5c:
++ b1:a0:fc:75:03:ee:81:f0:88:ee:23:52:e9:e6:15:
++ 33:8d:ac:2d:09:c5:76:f9:2b:39:80:89:e4:97:4b:
++ 90:a5:a8:78:f8:73:43:7b:a4:61:b0:d8:58:cc:e1:
++ 6c:66:7e:9c:f3:09:5e:55:63:84:d5:a8:ef:f3:b1:
++ 2e:30:68:b3:c4:3c:d8:ac:6e:8d:99:5a:90:4e:34:
++ dc:36:9a:8f:81:88:50:b7:6d:96:42:09:f3:d7:95:
++ 83:0d:41:4b:b0:6a:6b:f8:fc:0f:7e:62:9f:67:c4:
++ ed:26:5f:10:26:0f:08:4f:f0:a4:57:28:ce:8f:b8:
++ ed:45:f6:6e:ee:25:5d:aa:6e:39:be:e4:93:2f:d9:
++ 47:a0:72:eb:fa:a6:5b:af:ca:53:3f:e2:0e:c6:96:
++ 56:11:6e:f7:e9:66:a9:26:d8:7f:95:53:ed:0a:85:
++ 88:ba:4f:29:a5:42:8c:5e:b6:fc:85:20:00:aa:68:
++ 0b:a1:1a:85:01:9c:c4:46:63:82:88:b6:22:b1:ee:
++ fe:aa:46:59:7e:cf:35:2c:d5:b6:da:5d:f7:48:33:
++ 14:54:b6:eb:d9:6f:ce:cd:88:d6:ab:1b:da:96:3b:
++ 1d:59
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ Signature Algorithm: sha1WithRSAEncryption
++ b8:8d:ce:ef:e7:14:ba:cf:ee:b0:44:92:6c:b4:39:3e:a2:84:
++ 6e:ad:b8:21:77:d2:d4:77:82:87:e6:20:41:81:ee:e2:f8:11:
++ b7:63:d1:17:37:be:19:76:24:1c:04:1a:4c:eb:3d:aa:67:6f:
++ 2d:d4:cd:fe:65:31:70:c5:1b:a6:02:0a:ba:60:7b:6d:58:c2:
++ 9a:49:fe:63:32:0b:6b:e3:3a:c0:ac:ab:3b:b0:e8:d3:09:51:
++ 8c:10:83:c6:34:e0:c5:2b:e0:1a:b6:60:14:27:6c:32:77:8c:
++ bc:b2:72:98:cf:cd:cc:3f:b9:c8:24:42:14:d6:57:fc:e6:26:
++ 43:a9:1d:e5:80:90:ce:03:54:28:3e:f7:3f:d3:f8:4d:ed:6a:
++ 0a:3a:93:13:9b:3b:14:23:13:63:9c:3f:d1:87:27:79:e5:4c:
++ 51:e3:01:ad:85:5d:1a:3b:b1:d5:73:10:a4:d3:f2:bc:6e:64:
++ f5:5a:56:90:a8:c7:0e:4c:74:0f:2e:71:3b:f7:c8:47:f4:69:
++ 6f:15:f2:11:5e:83:1e:9c:7c:52:ae:fd:02:da:12:a8:59:67:
++ 18:db:bc:70:dd:9b:b1:69:ed:80:ce:89:40:48:6a:0e:35:ca:
++ 29:66:15:21:94:2c:e8:60:2a:9b:85:4a:40:f3:6b:8a:24:ec:
++ 06:16:2c:73
++SHA1 Fingerprint=62:52:DC:40:F7:11:43:A2:2F:DE:9E:F7:34:8E:06:42:51:B1:81:18
++-----BEGIN CERTIFICATE-----
++MIIDDDCCAfSgAwIBAgIDAQAgMA0GCSqGSIb3DQEBBQUAMD4xCzAJBgNVBAYTAlBM
++MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
++QTAeFw0wMjA2MTExMDQ2MzlaFw0yNzA2MTExMDQ2MzlaMD4xCzAJBgNVBAYTAlBM
++MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
++QTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM6xwS7TT3zNJc4YPk/E
++jG+AanPIW1H4m9LcuwBcsaD8dQPugfCI7iNS6eYVM42sLQnFdvkrOYCJ5JdLkKWo
++ePhzQ3ukYbDYWMzhbGZ+nPMJXlVjhNWo7/OxLjBos8Q82KxujZlakE403Daaj4GI
++ULdtlkIJ89eVgw1BS7Bqa/j8D35in2fE7SZfECYPCE/wpFcozo+47UX2bu4lXapu
++Ob7kky/ZR6By6/qmW6/KUz/iDsaWVhFu9+lmqSbYf5VT7QqFiLpPKaVCjF62/IUg
++AKpoC6EahQGcxEZjgoi2IrHu/qpGWX7PNSzVttpd90gzFFS269lvzs2I1qsb2pY7
++HVkCAwEAAaMTMBEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEA
++uI3O7+cUus/usESSbLQ5PqKEbq24IXfS1HeCh+YgQYHu4vgRt2PRFze+GXYkHAQa
++TOs9qmdvLdTN/mUxcMUbpgIKumB7bVjCmkn+YzILa+M6wKyrO7Do0wlRjBCDxjTg
++xSvgGrZgFCdsMneMvLJymM/NzD+5yCRCFNZX/OYmQ6kd5YCQzgNUKD73P9P4Te1q
++CjqTE5s7FCMTY5w/0YcneeVMUeMBrYVdGjux1XMQpNPyvG5k9VpWkKjHDkx0Dy5x
++O/fIR/RpbxXyEV6DHpx8Uq79AtoSqFlnGNu8cN2bsWntgM6JQEhqDjXKKWYVIZQs
++6GAqm4VKQPNriiTsBhYscw==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
+@@ -0,0 +1,152 @@
++##
++## Chambers of Commerce Root - 2008
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ a3:da:42:7e:a4:b1:ae:da
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
++ Validity
++ Not Before: Aug 1 12:29:50 2008 GMT
++ Not After : Jul 31 12:29:50 2038 GMT
++ Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:af:00:cb:70:37:2b:80:5a:4a:3a:6c:78:94:7d:
++ a3:7f:1a:1f:f6:35:d5:bd:db:cb:0d:44:72:3e:26:
++ b2:90:52:ba:63:3b:28:58:6f:a5:b3:6d:94:a6:f3:
++ dd:64:0c:55:f6:f6:e7:f2:22:22:80:5e:e1:62:c6:
++ b6:29:e1:81:6c:f2:bf:e5:7d:32:6a:54:a0:32:19:
++ 59:fe:1f:8b:d7:3d:60:86:85:24:6f:e3:11:b3:77:
++ 3e:20:96:35:21:6b:b3:08:d9:70:2e:64:f7:84:92:
++ 53:d6:0e:b0:90:8a:8a:e3:87:8d:06:d3:bd:90:0e:
++ e2:99:a1:1b:86:0e:da:9a:0a:bb:0b:61:50:06:52:
++ f1:9e:7f:76:ec:cb:0f:d0:1e:0d:cf:99:30:3d:1c:
++ c4:45:10:58:ac:d6:d3:e8:d7:e5:ea:c5:01:07:77:
++ d6:51:e6:03:7f:8a:48:a5:4d:68:75:b9:e9:bc:9e:
++ 4e:19:71:f5:32:4b:9c:6d:60:19:0b:fb:cc:9d:75:
++ dc:bf:26:cd:8f:93:78:39:79:73:5e:25:0e:ca:5c:
++ eb:77:12:07:cb:64:41:47:72:93:ab:50:c3:eb:09:
++ 76:64:34:d2:39:b7:76:11:09:0d:76:45:c4:a9:ae:
++ 3d:6a:af:b5:7d:65:2f:94:58:10:ec:5c:7c:af:7e:
++ e2:b6:18:d9:d0:9b:4e:5a:49:df:a9:66:0b:cc:3c:
++ c6:78:7c:a7:9c:1d:e3:ce:8e:53:be:05:de:60:0f:
++ 6b:e5:1a:db:3f:e3:e1:21:c9:29:c1:f1:eb:07:9c:
++ 52:1b:01:44:51:3c:7b:25:d7:c4:e5:52:54:5d:25:
++ 07:ca:16:20:b8:ad:e4:41:ee:7a:08:fe:99:6f:83:
++ a6:91:02:b0:6c:36:55:6a:e7:7d:f5:96:e6:ca:81:
++ d6:97:f1:94:83:e9:ed:b0:b1:6b:12:69:1e:ac:fb:
++ 5d:a9:c5:98:e9:b4:5b:58:7a:be:3d:a2:44:3a:63:
++ 59:d4:0b:25:de:1b:4f:bd:e5:01:9e:cd:d2:29:d5:
++ 9f:17:19:0a:6f:bf:0c:90:d3:09:5f:d9:e3:8a:35:
++ cc:79:5a:4d:19:37:92:b7:c4:c1:ad:af:f4:79:24:
++ 9a:b2:01:0b:b1:af:5c:96:f3:80:32:fb:5c:3d:98:
++ f1:a0:3f:4a:de:be:af:94:2e:d9:55:9a:17:6e:60:
++ 9d:63:6c:b8:63:c9:ae:81:5c:18:35:e0:90:bb:be:
++ 3c:4f:37:22:b9:7e:eb:cf:9e:77:21:a6:3d:38:81:
++ fb:48:da:31:3d:2b:e3:89:f5:d0:b5:bd:7e:e0:50:
++ c4:12:89:b3:23:9a:10:31:85:db:ae:6f:ef:38:33:
++ 18:76:11
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 Subject Key Identifier:
++ F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
++ X509v3 Authority Key Identifier:
++ keyid:F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
++ DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Chambers of Commerce Root - 2008
++ serial:A3:DA:42:7E:A4:B1:AE:DA
++
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Certificate Policies:
++ Policy: X509v3 Any Policy
++ CPS: http://policy.camerfirma.com
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 90:12:af:22:35:c2:a3:39:f0:2e:de:e9:b5:e9:78:7c:48:be:
++ 3f:7d:45:92:5e:e9:da:b1:19:fc:16:3c:9f:b4:5b:66:9e:6a:
++ e7:c3:b9:5d:88:e8:0f:ad:cf:23:0f:de:25:3a:5e:cc:4f:a5:
++ c1:b5:2d:ac:24:d2:58:07:de:a2:cf:69:84:60:33:e8:10:0d:
++ 13:a9:23:d0:85:e5:8e:7b:a6:9e:3d:72:13:72:33:f5:aa:7d:
++ c6:63:1f:08:f4:fe:01:7f:24:cf:2b:2c:54:09:de:e2:2b:6d:
++ 92:c6:39:4f:16:ea:3c:7e:7a:46:d4:45:6a:46:a8:eb:75:82:
++ 56:a7:ab:a0:7c:68:13:33:f6:9d:30:f0:6f:27:39:24:23:2a:
++ 90:fd:90:29:35:f2:93:df:34:a5:c6:f7:f8:ef:8c:0f:62:4a:
++ 7c:ae:d3:f5:54:f8:8d:b6:9a:56:87:16:82:3a:33:ab:5a:22:
++ 08:f7:82:ba:ea:2e:e0:47:9a:b4:b5:45:a3:05:3b:d9:dc:2e:
++ 45:40:3b:ea:dc:7f:e8:3b:eb:d1:ec:26:d8:35:a4:30:c5:3a:
++ ac:57:9e:b3:76:a5:20:7b:f9:1e:4a:05:62:01:a6:28:75:60:
++ 97:92:0d:6e:3e:4d:37:43:0d:92:15:9c:18:22:cd:51:99:a0:
++ 29:1a:3c:5f:8a:32:33:5b:30:c7:89:2f:47:98:0f:a3:03:c6:
++ f6:f1:ac:df:32:f0:d9:81:1a:e4:9c:bd:f6:80:14:f0:d1:2c:
++ b9:85:f5:d8:a3:b1:c8:a5:21:e5:1c:13:97:ee:0e:bd:df:29:
++ a9:ef:34:53:5b:d3:e4:6a:13:84:06:b6:32:02:c4:52:ae:22:
++ d2:dc:b2:21:42:1a:da:40:f0:29:c9:ec:0a:0c:5c:e2:d0:ba:
++ cc:48:d3:37:0a:cc:12:0a:8a:79:b0:3d:03:7f:69:4b:f4:34:
++ 20:7d:b3:34:ea:8e:4b:64:f5:3e:fd:b3:23:67:15:0d:04:b8:
++ f0:2d:c1:09:51:3c:b2:6c:15:f0:a5:23:d7:83:74:e4:e5:2e:
++ c9:fe:98:27:42:c6:ab:c6:9e:b0:d0:5b:38:a5:9b:50:de:7e:
++ 18:98:b5:45:3b:f6:79:b4:e8:f7:1a:7b:06:83:fb:d0:8b:da:
++ bb:c7:bd:18:ab:08:6f:3c:80:6b:40:3f:19:19:ba:65:8a:e6:
++ be:d5:5c:d3:36:d7:ef:40:52:24:60:38:67:04:31:ec:8f:f3:
++ 82:c6:de:b9:55:f3:3b:31:91:5a:dc:b5:08:15:ad:76:25:0a:
++ 0d:7b:2e:87:e2:0c:a6:06:bc:26:10:6d:37:9d:ec:dd:78:8c:
++ 7c:80:c5:f0:d9:77:48:d0
++SHA1 Fingerprint=78:6A:74:AC:76:AB:14:7F:9C:6A:30:50:BA:9E:A8:7E:FE:9A:CE:3C
++-----BEGIN CERTIFICATE-----
++MIIHTzCCBTegAwIBAgIJAKPaQn6ksa7aMA0GCSqGSIb3DQEBBQUAMIGuMQswCQYD
++VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
++IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
++MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xKTAnBgNVBAMTIENoYW1iZXJz
++IG9mIENvbW1lcmNlIFJvb3QgLSAyMDA4MB4XDTA4MDgwMTEyMjk1MFoXDTM4MDcz
++MTEyMjk1MFowga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpNYWRyaWQgKHNlZSBj
++dXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29tL2FkZHJlc3MpMRIw
++EAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVyZmlybWEgUy5BLjEp
++MCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAtIDIwMDgwggIiMA0G
++CSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCvAMtwNyuAWko6bHiUfaN/Gh/2NdW9
++28sNRHI+JrKQUrpjOyhYb6WzbZSm891kDFX29ufyIiKAXuFixrYp4YFs8r/lfTJq
++VKAyGVn+H4vXPWCGhSRv4xGzdz4gljUha7MI2XAuZPeEklPWDrCQiorjh40G072Q
++DuKZoRuGDtqaCrsLYVAGUvGef3bsyw/QHg3PmTA9HMRFEFis1tPo1+XqxQEHd9ZR
++5gN/ikilTWh1uem8nk4ZcfUyS5xtYBkL+8ydddy/Js2Pk3g5eXNeJQ7KXOt3EgfL
++ZEFHcpOrUMPrCXZkNNI5t3YRCQ12RcSprj1qr7V9ZS+UWBDsXHyvfuK2GNnQm05a
++Sd+pZgvMPMZ4fKecHePOjlO+Bd5gD2vlGts/4+EhySnB8esHnFIbAURRPHsl18Tl
++UlRdJQfKFiC4reRB7noI/plvg6aRArBsNlVq5331lubKgdaX8ZSD6e2wsWsSaR6s
+++12pxZjptFtYer49okQ6Y1nUCyXeG0+95QGezdIp1Z8XGQpvvwyQ0wlf2eOKNcx5
++Wk0ZN5K3xMGtr/R5JJqyAQuxr1yW84Ay+1w9mPGgP0revq+ULtlVmhduYJ1jbLhj
++ya6BXBg14JC7vjxPNyK5fuvPnnchpj04gftI2jE9K+OJ9dC1vX7gUMQSibMjmhAx
++hduub+84Mxh2EQIDAQABo4IBbDCCAWgwEgYDVR0TAQH/BAgwBgEB/wIBDDAdBgNV
++HQ4EFgQU+SSsD7K1+HnA+mCIG8TZTQKeFxkwgeMGA1UdIwSB2zCB2IAU+SSsD7K1
+++HnA+mCIG8TZTQKeFxmhgbSkgbEwga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpN
++YWRyaWQgKHNlZSBjdXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29t
++L2FkZHJlc3MpMRIwEAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVy
++ZmlybWEgUy5BLjEpMCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAt
++IDIwMDiCCQCj2kJ+pLGu2jAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRV
++HSAAMCowKAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20w
++DQYJKoZIhvcNAQEFBQADggIBAJASryI1wqM58C7e6bXpeHxIvj99RZJe6dqxGfwW
++PJ+0W2aeaufDuV2I6A+tzyMP3iU6XsxPpcG1Lawk0lgH3qLPaYRgM+gQDROpI9CF
++5Y57pp49chNyM/WqfcZjHwj0/gF/JM8rLFQJ3uIrbZLGOU8W6jx+ekbURWpGqOt1
++glanq6B8aBMz9p0w8G8nOSQjKpD9kCk18pPfNKXG9/jvjA9iSnyu0/VU+I22mlaH
++FoI6M6taIgj3grrqLuBHmrS1RaMFO9ncLkVAO+rcf+g769HsJtg1pDDFOqxXnrN2
++pSB7+R5KBWIBpih1YJeSDW4+TTdDDZIVnBgizVGZoCkaPF+KMjNbMMeJL0eYD6MD
++xvbxrN8y8NmBGuScvfaAFPDRLLmF9dijscilIeUcE5fuDr3fKanvNFNb0+RqE4QG
++tjICxFKuItLcsiFCGtpA8CnJ7AoMXOLQusxI0zcKzBIKinmwPQN/aUv0NCB9szTq
++jktk9T79syNnFQ0EuPAtwQlRPLJsFfClI9eDdOTlLsn+mCdCxqvGnrDQWzilm1De
++fhiYtUU79nm06PcaewaD+9CL2rvHvRirCG88gGtAPxkZumWK5r7VXNM21+9AUiRg
++OGcEMeyP84LG3rlV8zsxkVrctQgVrXYlCg17LofiDKYGvCYQbTed7N14jHyAxfDZ
++d0jQ
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem
+@@ -0,0 +1,101 @@
++##
++## D-TRUST Root CA 3 2013
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 1039788 (0xfddac)
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
++ Validity
++ Not Before: Sep 20 08:25:51 2013 GMT
++ Not After : Sep 20 08:25:51 2028 GMT
++ Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c4:7b:42:92:82:1f:ec:ed:54:98:8e:12:c0:ca:
++ 09:df:93:6e:3a:93:5c:1b:e4:10:77:9e:4e:69:88:
++ 6c:f6:e1:69:f2:f6:9b:a2:61:b1:bd:07:20:74:98:
++ 65:f1:8c:26:08:cd:a8:35:ca:80:36:d1:63:6d:e8:
++ 44:7a:82:c3:6c:5e:de:bb:e8:36:d2:c4:68:36:8c:
++ 9f:32:bd:84:22:e0:dc:c2:ee:10:46:39:6d:af:93:
++ 39:ae:87:e6:c3:bc:09:c9:2c:6b:67:5b:d9:9b:76:
++ 75:4c:0b:e0:bb:c5:d7:bc:3e:79:f2:5f:be:d1:90:
++ 57:f9:ae:f6:66:5f:31:bf:d3:6d:8f:a7:ba:4a:f3:
++ 23:65:bb:b7:ef:a3:25:d7:0a:ea:58:b6:ef:88:fa:
++ fa:79:b2:52:58:d5:f0:ac:8c:a1:51:74:29:95:aa:
++ 51:3b:90:32:03:9f:1c:72:74:90:de:3d:ed:61:d2:
++ e5:e3:fd:64:47:e5:b9:b7:4a:a9:f7:1f:ae:96:86:
++ 04:ac:2f:e3:a4:81:77:b7:5a:16:ff:d8:0f:3f:f6:
++ b7:78:cc:a4:af:fa:5b:3c:12:5b:a8:52:89:72:ef:
++ 88:f3:d5:44:81:86:95:23:9f:7b:dd:bc:d9:34:ef:
++ 7c:94:3c:aa:c0:41:c2:e3:9d:50:1a:c0:e4:19:22:
++ fc:b3
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 3F:90:C8:7D:C7:15:6F:F3:24:8F:A9:C3:2F:4B:A2:0F:21:B2:2F:E7
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 CRL Distribution Points:
++
++ Full Name:
++ URI:ldap://directory.d-trust.net/CN=D-TRUST%20Root%20CA%203%202013,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
++
++ Full Name:
++ URI:http://crl.d-trust.net/crl/d-trust_root_ca_3_2013.crl
++
++ Signature Algorithm: sha256WithRSAEncryption
++ 0e:59:0e:58:e4:74:48:23:44:cf:34:21:b5:9c:14:1a:ad:9a:
++ 4b:b7:b3:88:6d:5c:a9:17:70:f0:2a:9f:8d:7b:f9:7b:85:fa:
++ c7:39:e8:10:08:b0:35:2b:5f:cf:02:d2:d3:9c:c8:0b:1e:ee:
++ 05:54:ae:37:93:04:09:7d:6c:8f:c2:74:bc:f8:1c:94:be:31:
++ 01:40:2d:f3:24:20:b7:84:55:2c:5c:c8:f5:74:4a:10:19:8b:
++ a3:c7:ed:35:d6:09:48:d3:0e:c0:ba:39:a8:b0:46:02:b0:db:
++ c6:88:59:c2:be:fc:7b:b1:2b:cf:7e:62:87:55:96:cc:01:6f:
++ 9b:67:21:95:35:8b:f8:10:fc:71:1b:b7:4b:37:69:a6:3b:d6:
++ ec:8b:ee:c1:b0:f3:25:c9:8f:92:7d:a1:ea:c3:ca:44:bf:26:
++ a5:74:92:9c:e3:74:eb:9d:74:d9:cb:4d:87:d8:fc:b4:69:6c:
++ 8b:a0:43:07:60:78:97:e9:d9:93:7c:c2:46:bc:9b:37:52:a3:
++ ed:8a:3c:13:a9:7b:53:4b:49:9a:11:05:2c:0b:6e:56:ac:1f:
++ 2e:82:6c:e0:69:67:b5:0e:6d:2d:d9:e4:c0:15:f1:3f:fa:18:
++ 72:e1:15:6d:27:5b:2d:30:28:2b:9f:48:9a:64:2b:99:ef:f2:
++ 75:49:5f:5c
++SHA1 Fingerprint=6C:7C:CC:E7:D4:AE:51:5F:99:08:CD:3F:F6:E8:C3:78:DF:6F:EF:97
++-----BEGIN CERTIFICATE-----
++MIIEDjCCAvagAwIBAgIDD92sMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkRF
++MRUwEwYDVQQKDAxELVRydXN0IEdtYkgxHzAdBgNVBAMMFkQtVFJVU1QgUm9vdCBD
++QSAzIDIwMTMwHhcNMTMwOTIwMDgyNTUxWhcNMjgwOTIwMDgyNTUxWjBFMQswCQYD
++VQQGEwJERTEVMBMGA1UECgwMRC1UcnVzdCBHbWJIMR8wHQYDVQQDDBZELVRSVVNU
++IFJvb3QgQ0EgMyAyMDEzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
++xHtCkoIf7O1UmI4SwMoJ35NuOpNcG+QQd55OaYhs9uFp8vabomGxvQcgdJhl8Ywm
++CM2oNcqANtFjbehEeoLDbF7eu+g20sRoNoyfMr2EIuDcwu4QRjltr5M5rofmw7wJ
++ySxrZ1vZm3Z1TAvgu8XXvD558l++0ZBX+a72Zl8xv9Ntj6e6SvMjZbu376Ml1wrq
++WLbviPr6ebJSWNXwrIyhUXQplapRO5AyA58ccnSQ3j3tYdLl4/1kR+W5t0qp9x+u
++loYErC/jpIF3t1oW/9gPP/a3eMykr/pbPBJbqFKJcu+I89VEgYaVI5973bzZNO98
++lDyqwEHC451QGsDkGSL8swIDAQABo4IBBTCCAQEwDwYDVR0TAQH/BAUwAwEB/zAd
++BgNVHQ4EFgQUP5DIfccVb/Mkj6nDL0uiDyGyL+cwDgYDVR0PAQH/BAQDAgEGMIG+
++BgNVHR8EgbYwgbMwdKByoHCGbmxkYXA6Ly9kaXJlY3RvcnkuZC10cnVzdC5uZXQv
++Q049RC1UUlVTVCUyMFJvb3QlMjBDQSUyMDMlMjAyMDEzLE89RC1UcnVzdCUyMEdt
++YkgsQz1ERT9jZXJ0aWZpY2F0ZXJldm9jYXRpb25saXN0MDugOaA3hjVodHRwOi8v
++Y3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X3Jvb3RfY2FfM18yMDEzLmNybDAN
++BgkqhkiG9w0BAQsFAAOCAQEADlkOWOR0SCNEzzQhtZwUGq2aS7eziG1cqRdw8Cqf
++jXv5e4X6xznoEAiwNStfzwLS05zICx7uBVSuN5MECX1sj8J0vPgclL4xAUAt8yQg
++t4RVLFzI9XRKEBmLo8ftNdYJSNMOwLo5qLBGArDbxohZwr78e7Erz35ih1WWzAFv
++m2chlTWL+BD8cRu3SzdppjvW7IvuwbDzJcmPkn2h6sPKRL8mpXSSnON065102ctN
++h9j8tGlsi6BDB2B4l+nZk3zCRrybN1Kj7Yo8E6l7U0tJmhEFLAtuVqwfLoJs4Gln
++tQ5tLdnkwBXxP/oYcuEVbSdbLTAoK59ImmQrme/ydUlfXA==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/EC-ACC.pem
+@@ -0,0 +1,109 @@
++##
++## EC-ACC
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ (Negative)11:d4:c2:14:2b:de:21:eb:57:9d:53:fb:0c:22:3b:ff
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
++ Validity
++ Not Before: Jan 7 23:00:00 2003 GMT
++ Not After : Jan 7 22:59:59 2031 GMT
++ Subject: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:b3:22:c7:4f:e2:97:42:95:88:47:83:40:f6:1d:
++ 17:f3:83:73:24:1e:51:f3:98:8a:c3:92:b8:ff:40:
++ 90:05:70:87:60:c9:00:a9:b5:94:65:19:22:15:17:
++ c2:43:6c:66:44:9a:0d:04:3e:39:6f:a5:4b:7a:aa:
++ 63:b7:8a:44:9d:d9:63:91:84:66:e0:28:0f:ba:42:
++ e3:6e:8e:f7:14:27:93:69:ee:91:0e:a3:5f:0e:b1:
++ eb:66:a2:72:4f:12:13:86:65:7a:3e:db:4f:07:f4:
++ a7:09:60:da:3a:42:99:c7:b2:7f:b3:16:95:1c:c7:
++ f9:34:b5:94:85:d5:99:5e:a0:48:a0:7e:e7:17:65:
++ b8:a2:75:b8:1e:f3:e5:42:7d:af:ed:f3:8a:48:64:
++ 5d:82:14:93:d8:c0:e4:ff:b3:50:72:f2:76:f6:b3:
++ 5d:42:50:79:d0:94:3e:6b:0c:00:be:d8:6b:0e:4e:
++ 2a:ec:3e:d2:cc:82:a2:18:65:33:13:77:9e:9a:5d:
++ 1a:13:d8:c3:db:3d:c8:97:7a:ee:70:ed:a7:e6:7c:
++ db:71:cf:2d:94:62:df:6d:d6:f5:38:be:3f:a5:85:
++ 0a:19:b8:a8:d8:09:75:42:70:c4:ea:ef:cb:0e:c8:
++ 34:a8:12:22:98:0c:b8:13:94:b6:4b:ec:f0:d0:90:
++ e7:27
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Subject Alternative Name:
++ email:ec_acc@catcert.net
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ A0:C3:8B:44:AA:37:A5:45:BF:97:80:5A:D1:F1:78:A2:9B:E9:5D:8D
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.15096.1.3.1.10
++ CPS: https://www.catcert.net/verarrel
++ User Notice:
++ Explicit Text: Vegeu https://www.catcert.net/verarrel
++
++ Signature Algorithm: sha1WithRSAEncryption
++ a0:48:5b:82:01:f6:4d:48:b8:39:55:35:9c:80:7a:53:99:d5:
++ 5a:ff:b1:71:3b:cc:39:09:94:5e:d6:da:ef:be:01:5b:5d:d3:
++ 1e:d8:fd:7d:4f:cd:a0:41:e0:34:93:bf:cb:e2:86:9c:37:92:
++ 90:56:1c:dc:eb:29:05:e5:c4:9e:c7:35:df:8a:0c:cd:c5:21:
++ 43:e9:aa:88:e5:35:c0:19:42:63:5a:02:5e:a4:48:18:3a:85:
++ 6f:dc:9d:bc:3f:9d:9c:c1:87:b8:7a:61:08:e9:77:0b:7f:70:
++ ab:7a:dd:d9:97:2c:64:1e:85:bf:bc:74:96:a1:c3:7a:12:ec:
++ 0c:1a:6e:83:0c:3c:e8:72:46:9f:fb:48:d5:5e:97:e6:b1:a1:
++ f8:e4:ef:46:25:94:9c:89:db:69:38:be:ec:5c:0e:56:c7:65:
++ 51:e5:50:88:88:bf:42:d5:2b:3d:e5:f9:ba:9e:2e:b3:ca:f4:
++ 73:92:02:0b:be:4c:66:eb:20:fe:b9:cb:b5:99:7f:e6:b6:13:
++ fa:ca:4b:4d:d9:ee:53:46:06:3b:c6:4e:ad:93:5a:81:7e:6c:
++ 2a:4b:6a:05:45:8c:f2:21:a4:31:90:87:6c:65:9c:9d:a5:60:
++ 95:3a:52:7f:f5:d1:ab:08:6e:f3:ee:5b:f9:88:3d:7e:b8:6f:
++ 6e:03:e4:42
++SHA1 Fingerprint=28:90:3A:63:5B:52:80:FA:E6:77:4C:0B:6D:A7:D6:BA:A6:4A:F2:E8
++-----BEGIN CERTIFICATE-----
++MIIFVjCCBD6gAwIBAgIQ7is969Qh3hSoYqwE893EATANBgkqhkiG9w0BAQUFADCB
++8zELMAkGA1UEBhMCRVMxOzA5BgNVBAoTMkFnZW5jaWEgQ2F0YWxhbmEgZGUgQ2Vy
++dGlmaWNhY2lvIChOSUYgUS0wODAxMTc2LUkpMSgwJgYDVQQLEx9TZXJ2ZWlzIFB1
++YmxpY3MgZGUgQ2VydGlmaWNhY2lvMTUwMwYDVQQLEyxWZWdldSBodHRwczovL3d3
++dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAoYykwMzE1MDMGA1UECxMsSmVyYXJxdWlh
++IEVudGl0YXRzIGRlIENlcnRpZmljYWNpbyBDYXRhbGFuZXMxDzANBgNVBAMTBkVD
++LUFDQzAeFw0wMzAxMDcyMzAwMDBaFw0zMTAxMDcyMjU5NTlaMIHzMQswCQYDVQQG
++EwJFUzE7MDkGA1UEChMyQWdlbmNpYSBDYXRhbGFuYSBkZSBDZXJ0aWZpY2FjaW8g
++KE5JRiBRLTA4MDExNzYtSSkxKDAmBgNVBAsTH1NlcnZlaXMgUHVibGljcyBkZSBD
++ZXJ0aWZpY2FjaW8xNTAzBgNVBAsTLFZlZ2V1IGh0dHBzOi8vd3d3LmNhdGNlcnQu
++bmV0L3ZlcmFycmVsIChjKTAzMTUwMwYDVQQLEyxKZXJhcnF1aWEgRW50aXRhdHMg
++ZGUgQ2VydGlmaWNhY2lvIENhdGFsYW5lczEPMA0GA1UEAxMGRUMtQUNDMIIBIjAN
++BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsyLHT+KXQpWIR4NA9h0X84NzJB5R
++85iKw5K4/0CQBXCHYMkAqbWUZRkiFRfCQ2xmRJoNBD45b6VLeqpjt4pEndljkYRm
++4CgPukLjbo73FCeTae6RDqNfDrHrZqJyTxIThmV6PttPB/SnCWDaOkKZx7J/sxaV
++HMf5NLWUhdWZXqBIoH7nF2W4onW4HvPlQn2v7fOKSGRdghST2MDk/7NQcvJ29rNd
++QlB50JQ+awwAvthrDk4q7D7SzIKiGGUzE3eeml0aE9jD2z3Il3rucO2n5nzbcc8t
++lGLfbdb1OL4/pYUKGbio2Al1QnDE6u/LDsg0qBIimAy4E5S2S+zw0JDnJwIDAQAB
++o4HjMIHgMB0GA1UdEQQWMBSBEmVjX2FjY0BjYXRjZXJ0Lm5ldDAPBgNVHRMBAf8E
++BTADAQH/MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUoMOLRKo3pUW/l4Ba0fF4
++opvpXY0wfwYDVR0gBHgwdjB0BgsrBgEEAfV4AQMBCjBlMCwGCCsGAQUFBwIBFiBo
++dHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbDA1BggrBgEFBQcCAjApGidW
++ZWdldSBodHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAwDQYJKoZIhvcN
++AQEFBQADggEBAKBIW4IB9k1IuDlVNZyAelOZ1Vr/sXE7zDkJlF7W2u++AVtd0x7Y
++/X1PzaBB4DSTv8vihpw3kpBWHNzrKQXlxJ7HNd+KDM3FIUPpqojlNcAZQmNaAl6k
++SBg6hW/cnbw/nZzBh7h6YQjpdwt/cKt63dmXLGQehb+8dJahw3oS7AwaboMMPOhy
++Rp/7SNVel+axofjk70YllJyJ22k4vuxcDlbHZVHlUIiIv0LVKz3l+bqeLrPK9HOS
++Agu+TGbrIP65y7WZf+a2E/rKS03Z7lNGBjvGTq2TWoF+bCpLagVFjPIhpDGQh2xl
++nJ2lYJU6Un/10asIbvPuW/mIPX64b24D5EI=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G2.pem
+@@ -0,0 +1,68 @@
++##
++## GeoTrust Primary Certification Authority - G2
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 3c:b2:f4:48:0a:00:e2:fe:eb:24:3b:5e:60:3e:c3:6b
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
++ Validity
++ Not Before: Nov 5 00:00:00 2007 GMT
++ Not After : Jan 18 23:59:59 2038 GMT
++ Subject: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:15:b1:e8:fd:03:15:43:e5:ac:eb:87:37:11:62:
++ ef:d2:83:36:52:7d:45:57:0b:4a:8d:7b:54:3b:3a:
++ 6e:5f:15:02:c0:50:a6:cf:25:2f:7d:ca:48:b8:c7:
++ 50:63:1c:2a:21:08:7c:9a:36:d8:0b:fe:d1:26:c5:
++ 58:31:30:28:25:f3:5d:5d:a3:b8:b6:a5:b4:92:ed:
++ 6c:2c:9f:eb:dd:43:89:a2:3c:4b:48:91:1d:50:ec:
++ 26:df:d6:60:2e:bd:21
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ 15:5F:35:57:51:55:FB:25:B2:AD:03:69:FC:01:A3:FA:BE:11:55:D5
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:64:02:30:64:96:59:a6:e8:09:de:8b:ba:fa:5a:88:88:f0:
++ 1f:91:d3:46:a8:f2:4a:4c:02:63:fb:6c:5f:38:db:2e:41:93:
++ a9:0e:e6:9d:dc:31:1c:b2:a0:a7:18:1c:79:e1:c7:36:02:30:
++ 3a:56:af:9a:74:6c:f6:fb:83:e0:33:d3:08:5f:a1:9c:c2:5b:
++ 9f:46:d6:b6:cb:91:06:63:a2:06:e7:33:ac:3e:a8:81:12:d0:
++ cb:ba:d0:92:0b:b6:9e:96:aa:04:0f:8a
++SHA1 Fingerprint=8D:17:84:D5:37:F3:03:7D:EC:70:FE:57:8B:51:9A:99:E6:10:D7:B0
++-----BEGIN CERTIFICATE-----
++MIICrjCCAjWgAwIBAgIQPLL0SAoA4v7rJDteYD7DazAKBggqhkjOPQQDAzCBmDEL
++MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUdlb1RydXN0IEluYy4xOTA3BgNVBAsTMChj
++KSAyMDA3IEdlb1RydXN0IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTE2
++MDQGA1UEAxMtR2VvVHJ1c3QgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
++eSAtIEcyMB4XDTA3MTEwNTAwMDAwMFoXDTM4MDExODIzNTk1OVowgZgxCzAJBgNV
++BAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMTkwNwYDVQQLEzAoYykgMjAw
++NyBHZW9UcnVzdCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxNjA0BgNV
++BAMTLUdlb1RydXN0IFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBH
++MjB2MBAGByqGSM49AgEGBSuBBAAiA2IABBWx6P0DFUPlrOuHNxFi79KDNlJ9RVcL
++So17VDs6bl8VAsBQps8lL33KSLjHUGMcKiEIfJo22Av+0SbFWDEwKCXzXV2juLal
++tJLtbCyf691DiaI8S0iRHVDsJt/WYC69IaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAO
++BgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFBVfNVdRVfslsq0DafwBo/q+EVXVMAoG
++CCqGSM49BAMDA2cAMGQCMGSWWaboCd6LuvpaiIjwH5HTRqjySkwCY/tsXzjbLkGT
++qQ7mndwxHLKgpxgceeHHNgIwOlavmnRs9vuD4DPTCF+hnMJbn0bWtsuRBmOiBucz
++rD6ogRLQy7rQkgu2npaqBA+K
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Global_Chambersign_Root_-_2008.pem
+@@ -0,0 +1,151 @@
++##
++## Global Chambersign Root - 2008
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ c9:cd:d3:e9:d5:7d:23:ce
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
++ Validity
++ Not Before: Aug 1 12:31:40 2008 GMT
++ Not After : Jul 31 12:31:40 2038 GMT
++ Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:c0:df:56:d3:e4:3a:9b:76:45:b4:13:db:ff:c1:
++ b6:19:8b:37:41:18:95:52:47:eb:17:9d:29:88:8e:
++ 35:6c:06:32:2e:47:62:f3:49:04:bf:7d:44:36:b1:
++ 71:cc:bd:5a:09:73:d5:d9:85:44:ff:91:57:25:df:
++ 5e:36:8e:70:d1:5c:71:43:1d:d9:da:ef:5c:d2:fb:
++ 1b:bd:3a:b5:cb:ad:a3:cc:44:a7:0d:ae:21:15:3f:
++ b9:7a:5b:92:75:d8:a4:12:38:89:19:8a:b7:80:d2:
++ e2:32:6f:56:9c:91:d6:88:10:0b:b3:74:64:92:74:
++ 60:f3:f6:cf:18:4f:60:b2:23:d0:c7:3b:ce:61:4b:
++ 99:8f:c2:0c:d0:40:b2:98:dc:0d:a8:4e:a3:b9:0a:
++ ae:60:a0:ad:45:52:63:ba:66:bd:68:e0:f9:be:1a:
++ a8:81:bb:1e:41:78:75:d3:c1:fe:00:55:b0:87:54:
++ e8:27:90:35:1d:4c:33:ad:97:fc:97:2e:98:84:bf:
++ 2c:c9:a3:bf:d1:98:11:14:ed:63:f8:ca:98:88:58:
++ 17:99:ed:45:03:97:7e:3c:86:1e:88:8c:be:f2:91:
++ 84:8f:65:34:d8:00:4c:7d:b7:31:17:5a:29:7a:0a:
++ 18:24:30:a3:37:b5:7a:a9:01:7d:26:d6:f9:0e:8e:
++ 59:f1:fd:1b:33:b5:29:3b:17:3b:41:b6:21:dd:d4:
++ c0:3d:a5:9f:9f:1f:43:50:c9:bb:bc:6c:7a:97:98:
++ ee:cd:8c:1f:fb:9c:51:ae:8b:70:bd:27:9f:71:c0:
++ 6b:ac:7d:90:66:e8:d7:5d:3a:0d:b0:d5:c2:8d:d5:
++ c8:9d:9d:c1:6d:d0:d0:bf:51:e4:e3:f8:c3:38:36:
++ ae:d6:a7:75:e6:af:84:43:5d:93:92:0c:6a:07:de:
++ 3b:1d:98:22:d6:ac:c1:35:db:a3:a0:25:ff:72:b5:
++ 76:1d:de:6d:e9:2c:66:2c:52:84:d0:45:92:ce:1c:
++ e5:e5:33:1d:dc:07:53:54:a3:aa:82:3b:9a:37:2f:
++ dc:dd:a0:64:e9:e6:dd:bd:ae:fc:64:85:1d:3c:a7:
++ c9:06:de:84:ff:6b:e8:6b:1a:3c:c5:a2:b3:42:fb:
++ 8b:09:3e:5f:08:52:c7:62:c4:d4:05:71:bf:c4:64:
++ e4:f8:a1:83:e8:3e:12:9b:a8:1e:d4:36:4d:2f:71:
++ f6:8d:28:f6:83:a9:13:d2:61:c1:91:bb:48:c0:34:
++ 8f:41:8c:4b:4c:db:69:12:ff:50:94:9c:20:83:59:
++ 73:ed:7c:a1:f2:f1:fd:dd:f7:49:d3:43:58:a0:56:
++ 63:ca:3d:3d:e5:35:56:59:e9:0e:ca:20:cc:2b:4b:
++ 93:29:0f
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE, pathlen:12
++ X509v3 Subject Key Identifier:
++ B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
++ X509v3 Authority Key Identifier:
++ keyid:B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
++ DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Global Chambersign Root - 2008
++ serial:C9:CD:D3:E9:D5:7D:23:CE
++
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Certificate Policies:
++ Policy: X509v3 Any Policy
++ CPS: http://policy.camerfirma.com
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 80:88:7f:70:de:92:28:d9:05:94:46:ff:90:57:a9:f1:2f:df:
++ 1a:0d:6b:fa:7c:0e:1c:49:24:79:27:d8:46:aa:6f:29:59:52:
++ 88:70:12:ea:dd:3d:f5:9b:53:54:6f:e1:60:a2:a8:09:b9:ec:
++ eb:59:7c:c6:35:f1:dc:18:e9:f1:67:e5:af:ba:45:e0:09:de:
++ ca:44:0f:c2:17:0e:77:91:45:7a:33:5f:5f:96:2c:68:8b:c1:
++ 47:8f:98:9b:3d:c0:ec:cb:f5:d5:82:92:84:35:d1:be:36:38:
++ 56:72:31:5b:47:2d:aa:17:a4:63:51:eb:0a:01:ad:7f:ec:75:
++ 9e:cb:a1:1f:f1:7f:12:b1:b9:e4:64:7f:67:d6:23:2a:f4:b8:
++ 39:5d:98:e8:21:a7:e1:bd:3d:42:1a:74:9a:70:af:68:6c:50:
++ 5d:49:cf:ff:fb:0e:5d:e6:2c:47:d7:81:3a:59:00:b5:73:6b:
++ 63:20:f6:31:45:08:39:0e:f4:70:7e:40:70:5a:3f:d0:6b:42:
++ a9:74:3d:28:2f:02:6d:75:72:95:09:8d:48:63:c6:c6:23:57:
++ 92:93:5e:35:c1:8d:f9:0a:f7:2c:9d:62:1c:f6:ad:7c:dd:a6:
++ 31:1e:b6:b1:c7:7e:85:26:fa:a4:6a:b5:da:63:30:d1:ef:93:
++ 37:b2:66:2f:7d:05:f7:e7:b7:4b:98:94:35:c0:d9:3a:29:c1:
++ 9d:b2:50:33:1d:4a:a9:5a:a6:c9:03:ef:ed:f4:e7:a8:6e:8a:
++ b4:57:84:eb:a4:3f:d0:ee:aa:aa:87:5b:63:e8:93:e2:6b:a8:
++ d4:b8:72:78:6b:1b:ed:39:e4:5d:cb:9b:aa:87:d5:4f:4e:00:
++ fe:d9:6a:9f:3c:31:0f:28:02:01:7d:98:e8:a7:b0:a2:64:9e:
++ 79:f8:48:f2:15:a9:cc:e6:c8:44:eb:3f:78:99:f2:7b:71:3e:
++ 3c:f1:98:a7:c5:18:12:3f:e6:bb:28:33:42:e9:45:0a:7c:6d:
++ f2:86:79:2f:c5:82:19:7d:09:89:7c:b2:54:76:88:ae:de:c1:
++ f3:cc:e1:6e:db:31:d6:93:ae:99:a0:ef:25:6a:73:98:89:5b:
++ 3a:2e:13:88:1e:bf:c0:92:94:34:1b:e3:27:b7:8b:1e:6f:42:
++ ff:e7:e9:37:9b:50:1d:2d:a2:f9:02:ee:cb:58:58:3a:71:bc:
++ 68:e3:aa:c1:af:1c:28:1f:a2:dc:23:65:3f:81:ea:ae:99:d3:
++ d8:30:cf:13:0d:4f:15:c9:84:bc:a7:48:2d:f8:30:23:77:d8:
++ 46:4b:79:6d:f6:8c:ed:3a:7f:60:11:78:f4:e9:9b:ae:d5:54:
++ c0:74:80:d1:0b:42:9f:c1
++SHA1 Fingerprint=4A:BD:EE:EC:95:0D:35:9C:89:AE:C7:52:A1:2C:5B:29:F6:D6:AA:0C
++-----BEGIN CERTIFICATE-----
++MIIHSTCCBTGgAwIBAgIJAMnN0+nVfSPOMA0GCSqGSIb3DQEBBQUAMIGsMQswCQYD
++VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
++IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
++MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAlBgNVBAMTHkdsb2JhbCBD
++aGFtYmVyc2lnbiBSb290IC0gMjAwODAeFw0wODA4MDExMjMxNDBaFw0zODA3MzEx
++MjMxNDBaMIGsMQswCQYDVQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3Vy
++cmVudCBhZGRyZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAG
++A1UEBRMJQTgyNzQzMjg3MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAl
++BgNVBAMTHkdsb2JhbCBDaGFtYmVyc2lnbiBSb290IC0gMjAwODCCAiIwDQYJKoZI
++hvcNAQEBBQADggIPADCCAgoCggIBAMDfVtPkOpt2RbQT2//BthmLN0EYlVJH6xed
++KYiONWwGMi5HYvNJBL99RDaxccy9Wglz1dmFRP+RVyXfXjaOcNFccUMd2drvXNL7
++G706tcuto8xEpw2uIRU/uXpbknXYpBI4iRmKt4DS4jJvVpyR1ogQC7N0ZJJ0YPP2
++zxhPYLIj0Mc7zmFLmY/CDNBAspjcDahOo7kKrmCgrUVSY7pmvWjg+b4aqIG7HkF4
++ddPB/gBVsIdU6CeQNR1MM62X/JcumIS/LMmjv9GYERTtY/jKmIhYF5ntRQOXfjyG
++HoiMvvKRhI9lNNgATH23MRdaKXoKGCQwoze1eqkBfSbW+Q6OWfH9GzO1KTsXO0G2
++Id3UwD2ln58fQ1DJu7xsepeY7s2MH/ucUa6LcL0nn3HAa6x9kGbo1106DbDVwo3V
++yJ2dwW3Q0L9R5OP4wzg2rtandeavhENdk5IMagfeOx2YItaswTXbo6Al/3K1dh3e
++beksZixShNBFks4c5eUzHdwHU1SjqoI7mjcv3N2gZOnm3b2u/GSFHTynyQbehP9r
++6GsaPMWis0L7iwk+XwhSx2LE1AVxv8Rk5Pihg+g+EpuoHtQ2TS9x9o0o9oOpE9Jh
++wZG7SMA0j0GMS0zbaRL/UJScIINZc+18ofLx/d33SdNDWKBWY8o9PeU1VlnpDsog
++zCtLkykPAgMBAAGjggFqMIIBZjASBgNVHRMBAf8ECDAGAQH/AgEMMB0GA1UdDgQW
++BBS5CcqcHtvTbDprru1U8VuTBjUuXjCB4QYDVR0jBIHZMIHWgBS5CcqcHtvTbDpr
++ru1U8VuTBjUuXqGBsqSBrzCBrDELMAkGA1UEBhMCRVUxQzBBBgNVBAcTOk1hZHJp
++ZCAoc2VlIGN1cnJlbnQgYWRkcmVzcyBhdCB3d3cuY2FtZXJmaXJtYS5jb20vYWRk
++cmVzcykxEjAQBgNVBAUTCUE4Mjc0MzI4NzEbMBkGA1UEChMSQUMgQ2FtZXJmaXJt
++YSBTLkEuMScwJQYDVQQDEx5HbG9iYWwgQ2hhbWJlcnNpZ24gUm9vdCAtIDIwMDiC
++CQDJzdPp1X0jzjAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRVHSAAMCow
++KAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20wDQYJKoZI
++hvcNAQEFBQADggIBAICIf3DekijZBZRG/5BXqfEv3xoNa/p8DhxJJHkn2EaqbylZ
++UohwEurdPfWbU1Rv4WCiqAm57OtZfMY18dwY6fFn5a+6ReAJ3spED8IXDneRRXoz
++X1+WLGiLwUePmJs9wOzL9dWCkoQ10b42OFZyMVtHLaoXpGNR6woBrX/sdZ7LoR/x
++fxKxueRkf2fWIyr0uDldmOghp+G9PUIadJpwr2hsUF1Jz//7Dl3mLEfXgTpZALVz
++a2Mg9jFFCDkO9HB+QHBaP9BrQql0PSgvAm11cpUJjUhjxsYjV5KTXjXBjfkK9yyd
++Yhz2rXzdpjEetrHHfoUm+qRqtdpjMNHvkzeyZi99Bffnt0uYlDXA2TopwZ2yUDMd
++SqlapskD7+3056huirRXhOukP9DuqqqHW2Pok+JrqNS4cnhrG+055F3Lm6qH1U9O
++AP7Zap88MQ8oAgF9mOinsKJknnn4SPIVqczmyETrP3iZ8ntxPjzxmKfFGBI/5rso
++M0LpRQp8bfKGeS/Fghl9CYl8slR2iK7ewfPM4W7bMdaTrpmg7yVqc5iJWzouE4ge
++v8CSlDQb4ye3ix5vQv/n6TebUB0tovkC7stYWDpxvGjjqsGvHCgfotwjZT+B6q6Z
++09gwzxMNTxXJhLynSC34MCN32EZLeW32jO06f2ARePTpm67VVMB0gNELQp/B
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/OISTE_WISeKey_Global_Root_GA_CA.pem
+@@ -0,0 +1,96 @@
++##
++## OISTE WISeKey Global Root GA CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 41:3d:72:c7:f4:6b:1f:81:43:7d:f1:d2:28:54:df:9a
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
++ Validity
++ Not Before: Dec 11 16:03:44 2005 GMT
++ Not After : Dec 11 16:09:51 2037 GMT
++ Subject: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:cb:4f:b3:00:9b:3d:36:dd:f9:d1:49:6a:6b:10:
++ 49:1f:ec:d8:2b:b2:c6:f8:32:81:29:43:95:4c:9a:
++ 19:23:21:15:45:de:e3:c8:1c:51:55:5b:ae:93:e8:
++ 37:ff:2b:6b:e9:d4:ea:be:2a:dd:a8:51:2b:d7:66:
++ c3:61:5c:60:02:c8:f5:ce:72:7b:3b:b8:f2:4e:65:
++ 08:9a:cd:a4:6a:19:c1:01:bb:73:a6:d7:f6:c3:dd:
++ cd:bc:a4:8b:b5:99:61:b8:01:a2:a3:d4:4d:d4:05:
++ 3d:91:ad:f8:b4:08:71:64:af:70:f1:1c:6b:7e:f6:
++ c3:77:9d:24:73:7b:e4:0c:8c:e1:d9:36:e1:99:8b:
++ 05:99:0b:ed:45:31:09:ca:c2:00:db:f7:72:a0:96:
++ aa:95:87:d0:8e:c7:b6:61:73:0d:76:66:8c:dc:1b:
++ b4:63:a2:9f:7f:93:13:30:f1:a1:27:db:d9:ff:2c:
++ 55:88:91:a0:e0:4f:07:b0:28:56:8c:18:1b:97:44:
++ 8e:89:dd:e0:17:6e:e7:2a:ef:8f:39:0a:31:84:82:
++ d8:40:14:49:2e:7a:41:e4:a7:fe:e3:64:cc:c1:59:
++ 71:4b:2c:21:a7:5b:7d:e0:1d:d1:2e:81:9b:c3:d8:
++ 68:f7:bd:96:1b:ac:70:b1:16:14:0b:db:60:b9:26:
++ 01:05
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage:
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ B3:03:7E:AE:36:BC:B0:79:D1:DC:94:26:B6:11:BE:21:B2:69:86:94
++ 1.3.6.1.4.1.311.21.1:
++ ...
++ Signature Algorithm: sha1WithRSAEncryption
++ 4b:a1:ff:0b:87:6e:b3:f9:c1:43:b1:48:f3:28:c0:1d:2e:c9:
++ 09:41:fa:94:00:1c:a4:a4:ab:49:4f:8f:3d:1e:ef:4d:6f:bd:
++ bc:a4:f6:f2:26:30:c9:10:ca:1d:88:fb:74:19:1f:85:45:bd:
++ b0:6c:51:f9:36:7e:db:f5:4c:32:3a:41:4f:5b:47:cf:e8:0b:
++ 2d:b6:c4:19:9d:74:c5:47:c6:3b:6a:0f:ac:14:db:3c:f4:73:
++ 9c:a9:05:df:00:dc:74:78:fa:f8:35:60:59:02:13:18:7c:bc:
++ fb:4d:b0:20:6d:43:bb:60:30:7a:67:33:5c:c5:99:d1:f8:2d:
++ 39:52:73:fb:8c:aa:97:25:5c:72:d9:08:1e:ab:4e:3c:e3:81:
++ 31:9f:03:a6:fb:c0:fe:29:88:55:da:84:d5:50:03:b6:e2:84:
++ a3:a6:36:aa:11:3a:01:e1:18:4b:d6:44:68:b3:3d:f9:53:74:
++ 84:b3:46:91:46:96:00:b7:80:2c:b6:e1:e3:10:e2:db:a2:e7:
++ 28:8f:01:96:62:16:3e:00:e3:1c:a5:36:81:18:a2:4c:52:76:
++ c0:11:a3:6e:e6:1d:ba:e3:5a:be:36:53:c5:3e:75:8f:86:69:
++ 29:58:53:b5:9c:bb:6f:9f:5c:c5:18:ec:dd:2f:e1:98:c9:fc:
++ be:df:0a:0d
++SHA1 Fingerprint=59:22:A1:E1:5A:EA:16:35:21:F8:98:39:6A:46:46:B0:44:1B:0F:A9
++-----BEGIN CERTIFICATE-----
++MIID8TCCAtmgAwIBAgIQQT1yx/RrH4FDffHSKFTfmjANBgkqhkiG9w0BAQUFADCB
++ijELMAkGA1UEBhMCQ0gxEDAOBgNVBAoTB1dJU2VLZXkxGzAZBgNVBAsTEkNvcHly
++aWdodCAoYykgMjAwNTEiMCAGA1UECxMZT0lTVEUgRm91bmRhdGlvbiBFbmRvcnNl
++ZDEoMCYGA1UEAxMfT0lTVEUgV0lTZUtleSBHbG9iYWwgUm9vdCBHQSBDQTAeFw0w
++NTEyMTExNjAzNDRaFw0zNzEyMTExNjA5NTFaMIGKMQswCQYDVQQGEwJDSDEQMA4G
++A1UEChMHV0lTZUtleTEbMBkGA1UECxMSQ29weXJpZ2h0IChjKSAyMDA1MSIwIAYD
++VQQLExlPSVNURSBGb3VuZGF0aW9uIEVuZG9yc2VkMSgwJgYDVQQDEx9PSVNURSBX
++SVNlS2V5IEdsb2JhbCBSb290IEdBIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
++MIIBCgKCAQEAy0+zAJs9Nt350UlqaxBJH+zYK7LG+DKBKUOVTJoZIyEVRd7jyBxR
++VVuuk+g3/ytr6dTqvirdqFEr12bDYVxgAsj1znJ7O7jyTmUIms2kahnBAbtzptf2
++w93NvKSLtZlhuAGio9RN1AU9ka34tAhxZK9w8RxrfvbDd50kc3vkDIzh2TbhmYsF
++mQvtRTEJysIA2/dyoJaqlYfQjse2YXMNdmaM3Bu0Y6Kff5MTMPGhJ9vZ/yxViJGg
++4E8HsChWjBgbl0SOid3gF27nKu+POQoxhILYQBRJLnpB5Kf+42TMwVlxSywhp1t9
++4B3RLoGbw9ho972WG6xwsRYUC9tguSYBBQIDAQABo1EwTzALBgNVHQ8EBAMCAYYw
++DwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUswN+rja8sHnR3JQmthG+IbJphpQw
++EAYJKwYBBAGCNxUBBAMCAQAwDQYJKoZIhvcNAQEFBQADggEBAEuh/wuHbrP5wUOx
++SPMowB0uyQlB+pQAHKSkq0lPjz0e701vvbyk9vImMMkQyh2I+3QZH4VFvbBsUfk2
++ftv1TDI6QU9bR8/oCy22xBmddMVHxjtqD6wU2zz0c5ypBd8A3HR4+vg1YFkCExh8
++vPtNsCBtQ7tgMHpnM1zFmdH4LTlSc/uMqpclXHLZCB6rTjzjgTGfA6b7wP4piFXa
++hNVQA7bihKOmNqoROgHhGEvWRGizPflTdISzRpFGlgC3gCy24eMQ4tui5yiPAZZi
++Fj4A4xylNoEYokxSdsARo27mHbrjWr42U8U+dY+GaSlYU7Wcu2+fXMUY7N0v4ZjJ
++/L7fCg0=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/QuoVadis_Root_CA.pem
+@@ -0,0 +1,119 @@
++##
++## QuoVadis Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 985026699 (0x3ab6508b)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
++ Validity
++ Not Before: Mar 19 18:33:33 2001 GMT
++ Not After : Mar 17 18:33:33 2021 GMT
++ Subject: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:bf:61:b5:95:53:ba:57:fc:fa:f2:67:0b:3a:1a:
++ df:11:80:64:95:b4:d1:bc:cd:7a:cf:f6:29:96:2e:
++ 24:54:40:24:38:f7:1a:85:dc:58:4c:cb:a4:27:42:
++ 97:d0:9f:83:8a:c3:e4:06:03:5b:00:a5:51:1e:70:
++ 04:74:e2:c1:d4:3a:ab:d7:ad:3b:07:18:05:8e:fd:
++ 83:ac:ea:66:d9:18:1b:68:8a:f5:57:1a:98:ba:f5:
++ ed:76:3d:7c:d9:de:94:6a:3b:4b:17:c1:d5:8f:bd:
++ 65:38:3a:95:d0:3d:55:36:4e:df:79:57:31:2a:1e:
++ d8:59:65:49:58:20:98:7e:ab:5f:7e:9f:e9:d6:4d:
++ ec:83:74:a9:c7:6c:d8:ee:29:4a:85:2a:06:14:f9:
++ 54:e6:d3:da:65:07:8b:63:37:12:d7:d0:ec:c3:7b:
++ 20:41:44:a3:ed:cb:a0:17:e1:71:65:ce:1d:66:31:
++ f7:76:01:19:c8:7d:03:58:b6:95:49:1d:a6:12:26:
++ e8:c6:0c:76:e0:e3:66:cb:ea:5d:a6:26:ee:e5:cc:
++ 5f:bd:67:a7:01:27:0e:a2:ca:54:c5:b1:7a:95:1d:
++ 71:1e:4a:29:8a:03:dc:6a:45:c1:a4:19:5e:6f:36:
++ cd:c3:a2:b0:b7:fe:5c:38:e2:52:bc:f8:44:43:e6:
++ 90:bb
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ Authority Information Access:
++ OCSP - URI:https://ocsp.quovadisoffshore.com
++
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Certificate Policies:
++ Policy: 1.3.6.1.4.1.8024.0.1
++ User Notice:
++ Explicit Text: Reliance on the QuoVadis Root Certificate by any party assumes acceptance of the then applicable standard terms and conditions of use, certification practices, and the QuoVadis Certificate Policy.
++ CPS: http://www.quovadis.bm
++
++ X509v3 Subject Key Identifier:
++ 8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
++ X509v3 Authority Key Identifier:
++ keyid:8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
++ DirName:/C=BM/O=QuoVadis Limited/OU=Root Certification Authority/CN=QuoVadis Root Certification Authority
++ serial:3A:B6:50:8B
++
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Signature Algorithm: sha1WithRSAEncryption
++ 8a:d4:14:b5:fe:f4:9a:92:a7:19:d4:a4:7e:72:18:8f:d9:68:
++ 7c:52:24:dd:67:6f:39:7a:c4:aa:5e:3d:e2:58:b0:4d:70:98:
++ 84:61:e8:1b:e3:69:18:0e:ce:fb:47:50:a0:4e:ff:f0:24:1f:
++ bd:b2:ce:f5:27:fc:ec:2f:53:aa:73:7b:03:3d:74:6e:e6:16:
++ 9e:eb:a5:2e:c4:bf:56:27:50:2b:62:ba:be:4b:1c:3c:55:5c:
++ 41:1d:24:be:82:20:47:5d:d5:44:7e:7a:16:68:df:7d:4d:51:
++ 70:78:57:1d:33:1e:fd:02:99:9c:0c:cd:0a:05:4f:c7:bb:8e:
++ a4:75:fa:4a:6d:b1:80:8e:09:56:b9:9c:1a:60:fe:5d:c1:d7:
++ 7a:dc:11:78:d0:d6:5d:c1:b7:d5:ad:32:99:03:3a:8a:cc:54:
++ 25:39:31:81:7b:13:22:51:ba:46:6c:a1:bb:9e:fa:04:6c:49:
++ 26:74:8f:d2:73:eb:cc:30:a2:e6:ea:59:22:87:f8:97:f5:0e:
++ fd:ea:cc:92:a4:16:c4:52:18:ea:21:ce:b1:f1:e6:84:81:e5:
++ ba:a9:86:28:f2:43:5a:5d:12:9d:ac:1e:d9:a8:e5:0a:6a:a7:
++ 7f:a0:87:29:cf:f2:89:4d:d4:ec:c5:e2:e6:7a:d0:36:23:8a:
++ 4a:74:36:f9
++SHA1 Fingerprint=DE:3F:40:BD:50:93:D3:9B:6C:60:F6:DA:BC:07:62:01:00:89:76:C9
++-----BEGIN CERTIFICATE-----
++MIIF0DCCBLigAwIBAgIEOrZQizANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJC
++TTEZMBcGA1UEChMQUXVvVmFkaXMgTGltaXRlZDElMCMGA1UECxMcUm9vdCBDZXJ0
++aWZpY2F0aW9uIEF1dGhvcml0eTEuMCwGA1UEAxMlUXVvVmFkaXMgUm9vdCBDZXJ0
++aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wMTAzMTkxODMzMzNaFw0yMTAzMTcxODMz
++MzNaMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1pdGVkMSUw
++IwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYDVQQDEyVR
++dW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG
++9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2G1lVO6V/z68mcLOhrfEYBklbTRvM16z/Yp
++li4kVEAkOPcahdxYTMukJ0KX0J+DisPkBgNbAKVRHnAEdOLB1Dqr1607BxgFjv2D
++rOpm2RgbaIr1VxqYuvXtdj182d6UajtLF8HVj71lODqV0D1VNk7feVcxKh7YWWVJ
++WCCYfqtffp/p1k3sg3Spx2zY7ilKhSoGFPlU5tPaZQeLYzcS19Dsw3sgQUSj7cug
++F+FxZc4dZjH3dgEZyH0DWLaVSR2mEiboxgx24ONmy+pdpibu5cxfvWenAScOospU
++xbF6lR1xHkopigPcakXBpBlebzbNw6Kwt/5cOOJSvPhEQ+aQuwIDAQABo4ICUjCC
++Ak4wPQYIKwYBBQUHAQEEMTAvMC0GCCsGAQUFBzABhiFodHRwczovL29jc3AucXVv
++dmFkaXNvZmZzaG9yZS5jb20wDwYDVR0TAQH/BAUwAwEB/zCCARoGA1UdIASCAREw
++ggENMIIBCQYJKwYBBAG+WAABMIH7MIHUBggrBgEFBQcCAjCBxxqBxFJlbGlhbmNl
++IG9uIHRoZSBRdW9WYWRpcyBSb290IENlcnRpZmljYXRlIGJ5IGFueSBwYXJ0eSBh
++c3N1bWVzIGFjY2VwdGFuY2Ugb2YgdGhlIHRoZW4gYXBwbGljYWJsZSBzdGFuZGFy
++ZCB0ZXJtcyBhbmQgY29uZGl0aW9ucyBvZiB1c2UsIGNlcnRpZmljYXRpb24gcHJh
++Y3RpY2VzLCBhbmQgdGhlIFF1b1ZhZGlzIENlcnRpZmljYXRlIFBvbGljeS4wIgYI
++KwYBBQUHAgEWFmh0dHA6Ly93d3cucXVvdmFkaXMuYm0wHQYDVR0OBBYEFItLbe3T
++KbkGGew5Oanwl4Rqy+/fMIGuBgNVHSMEgaYwgaOAFItLbe3TKbkGGew5Oanwl4Rq
++y+/foYGEpIGBMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1p
++dGVkMSUwIwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYD
++VQQDEyVRdW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5ggQ6tlCL
++MA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQUFAAOCAQEAitQUtf70mpKnGdSk
++fnIYj9lofFIk3WdvOXrEql494liwTXCYhGHoG+NpGA7O+0dQoE7/8CQfvbLO9Sf8
++7C9TqnN7Az10buYWnuulLsS/VidQK2K6vkscPFVcQR0kvoIgR13VRH56FmjffU1R
++cHhXHTMe/QKZnAzNCgVPx7uOpHX6Sm2xgI4JVrmcGmD+XcHXetwReNDWXcG31a0y
++mQM6isxUJTkxgXsTIlG6Rmyhu576BGxJJnSP0nPrzDCi5upZIof4l/UO/erMkqQW
++xFIY6iHOsfHmhIHluqmGKPJDWl0Snawe2ajlCmqnf6CHKc/yiU3U7MXi5nrQNiOK
++SnQ2+Q==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Sonera_Class_2_Root_CA.pem
+@@ -0,0 +1,90 @@
++##
++## Sonera Class 2 Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 29 (0x1d)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = FI, O = Sonera, CN = Sonera Class2 CA
++ Validity
++ Not Before: Apr 6 07:29:40 2001 GMT
++ Not After : Apr 6 07:29:40 2021 GMT
++ Subject: C = FI, O = Sonera, CN = Sonera Class2 CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:90:17:4a:35:9d:ca:f0:0d:96:c7:44:fa:16:37:
++ fc:48:bd:bd:7f:80:2d:35:3b:e1:6f:a8:67:a9:bf:
++ 03:1c:4d:8c:6f:32:47:d5:41:68:a4:13:04:c1:35:
++ 0c:9a:84:43:fc:5c:1d:ff:89:b3:e8:17:18:cd:91:
++ 5f:fb:89:e3:ea:bf:4e:5d:7c:1b:26:d3:75:79:ed:
++ e6:84:e3:57:e5:ad:29:c4:f4:3a:28:e7:a5:7b:84:
++ 36:69:b3:fd:5e:76:bd:a3:2d:99:d3:90:4e:23:28:
++ 7d:18:63:f1:54:3b:26:9d:76:5b:97:42:b2:ff:ae:
++ f0:4e:ec:dd:39:95:4e:83:06:7f:e7:49:40:c8:c5:
++ 01:b2:54:5a:66:1d:3d:fc:f9:e9:3c:0a:9e:81:b8:
++ 70:f0:01:8b:e4:23:54:7c:c8:ae:f8:90:1e:00:96:
++ 72:d4:54:cf:61:23:bc:ea:fb:9d:02:95:d1:b6:b9:
++ 71:3a:69:08:3f:0f:b4:e1:42:c7:88:f5:3f:98:a8:
++ a7:ba:1c:e0:71:71:ef:58:57:81:50:7a:5c:6b:74:
++ 46:0e:83:03:98:c3:8e:a8:6e:f2:76:32:6e:27:83:
++ c2:73:f3:dc:18:e8:b4:93:ea:75:44:6b:04:60:20:
++ 71:57:87:9d:f3:be:a0:90:23:3d:8a:24:e1:da:21:
++ db:c3
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 4A:A0:AA:58:84:D3:5E:3C
++ X509v3 Key Usage:
++ Certificate Sign, CRL Sign
++ Signature Algorithm: sha1WithRSAEncryption
++ 5a:ce:87:f9:16:72:15:57:4b:1d:d9:9b:e7:a2:26:30:ec:93:
++ 67:df:d6:2d:d2:34:af:f7:38:a5:ce:ab:16:b9:ab:2f:7c:35:
++ cb:ac:d0:0f:b4:4c:2b:fc:80:ef:6b:8c:91:5f:36:76:f7:db:
++ b3:1b:19:ea:f4:b2:11:fd:61:71:44:bf:28:b3:3a:1d:bf:b3:
++ 43:e8:9f:bf:dc:31:08:71:b0:9d:8d:d6:34:47:32:90:c6:65:
++ 24:f7:a0:4a:7c:04:73:8f:39:6f:17:8c:72:b5:bd:4b:c8:7a:
++ f8:7b:83:c3:28:4e:9c:09:ea:67:3f:b2:67:04:1b:c3:14:da:
++ f8:e7:49:24:91:d0:1d:6a:fa:61:39:ef:6b:e7:21:75:06:07:
++ d8:12:b4:21:20:70:42:71:81:da:3c:9a:36:be:a6:5b:0d:6a:
++ 6c:9a:1f:91:7b:f9:f9:ef:42:ba:4e:4e:9e:cc:0c:8d:94:dc:
++ d9:45:9c:5e:ec:42:50:63:ae:f4:5d:c4:b1:12:dc:ca:3b:a8:
++ 2e:9d:14:5a:05:75:b7:ec:d7:63:e2:ba:35:b6:04:08:91:e8:
++ da:9d:9c:f6:66:b5:18:ac:0a:a6:54:26:34:33:d2:1b:c1:d4:
++ 7f:1a:3a:8e:0b:aa:32:6e:db:fc:4f:25:9f:d9:32:c7:96:5a:
++ 70:ac:df:4c
++SHA1 Fingerprint=37:F7:6D:E6:07:7C:90:C5:B1:3E:93:1A:B7:41:10:B4:F2:E4:9A:27
++-----BEGIN CERTIFICATE-----
++MIIDIDCCAgigAwIBAgIBHTANBgkqhkiG9w0BAQUFADA5MQswCQYDVQQGEwJGSTEP
++MA0GA1UEChMGU29uZXJhMRkwFwYDVQQDExBTb25lcmEgQ2xhc3MyIENBMB4XDTAx
++MDQwNjA3Mjk0MFoXDTIxMDQwNjA3Mjk0MFowOTELMAkGA1UEBhMCRkkxDzANBgNV
++BAoTBlNvbmVyYTEZMBcGA1UEAxMQU29uZXJhIENsYXNzMiBDQTCCASIwDQYJKoZI
++hvcNAQEBBQADggEPADCCAQoCggEBAJAXSjWdyvANlsdE+hY3/Ei9vX+ALTU74W+o
++Z6m/AxxNjG8yR9VBaKQTBME1DJqEQ/xcHf+Js+gXGM2RX/uJ4+q/Tl18GybTdXnt
++5oTjV+WtKcT0OijnpXuENmmz/V52vaMtmdOQTiMofRhj8VQ7Jp12W5dCsv+u8E7s
++3TmVToMGf+dJQMjFAbJUWmYdPfz56TwKnoG4cPABi+QjVHzIrviQHgCWctRUz2Ej
++vOr7nQKV0ba5cTppCD8PtOFCx4j1P5iop7oc4HFx71hXgVB6XGt0Rg6DA5jDjqhu
++8nYybieDwnPz3BjotJPqdURrBGAgcVeHnfO+oJAjPYok4doh28MCAwEAAaMzMDEw
++DwYDVR0TAQH/BAUwAwEB/zARBgNVHQ4ECgQISqCqWITTXjwwCwYDVR0PBAQDAgEG
++MA0GCSqGSIb3DQEBBQUAA4IBAQBazof5FnIVV0sd2ZvnoiYw7JNn39Yt0jSv9zil
++zqsWuasvfDXLrNAPtEwr/IDva4yRXzZ299uzGxnq9LIR/WFxRL8oszodv7ND6J+/
++3DEIcbCdjdY0RzKQxmUk96BKfARzjzlvF4xytb1LyHr4e4PDKE6cCepnP7JnBBvD
++FNr450kkkdAdavphOe9r5yF1BgfYErQhIHBCcYHaPJo2vqZbDWpsmh+Re/n570K6
++Tk6ezAyNlNzZRZxe7EJQY670XcSxEtzKO6gunRRaBXW37Ndj4ro1tgQIkejanZz2
++ZrUYrAqmVCY0M9IbwdR/GjqOC6oybtv8TyWf2TLHllpwrN9M
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Staat_der_Nederlanden_Root_CA_-_G3.pem
+@@ -0,0 +1,132 @@
++##
++## Staat der Nederlanden Root CA - G3
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 10003001 (0x98a239)
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
++ Validity
++ Not Before: Nov 14 11:28:42 2013 GMT
++ Not After : Nov 13 23:00:00 2028 GMT
++ Subject: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:be:32:a2:54:0f:70:fb:2c:5c:59:eb:6c:c4:a4:
++ 51:e8:85:2a:b3:cc:4a:34:f2:b0:5f:f3:0e:c7:1c:
++ 3d:53:1e:88:08:68:d8:6f:3d:ad:c2:9e:cc:82:67:
++ 07:27:87:68:71:3a:9f:75:96:22:46:05:b0:ed:ad:
++ c7:5b:9e:2a:de:9c:fc:3a:c6:95:a7:f5:17:67:18:
++ e7:2f:49:08:0c:5c:cf:e6:cc:34:ed:78:fb:50:b1:
++ dc:6b:32:f0:a2:fe:b6:3c:e4:ec:5a:97:c7:3f:1e:
++ 70:08:30:a0:dc:c5:b3:6d:6f:d0:82:72:11:ab:d2:
++ 81:68:59:82:17:b7:78:92:60:fa:cc:de:3f:84:eb:
++ 8d:38:33:90:0a:72:23:fa:35:cc:26:71:31:d1:72:
++ 28:92:d9:5b:23:6d:66:b5:6d:07:42:eb:a6:33:ce:
++ 92:db:c0:f6:6c:63:78:cd:ca:4e:3d:b5:e5:52:9b:
++ f1:be:3b:e6:54:60:b0:66:1e:09:ab:07:fe:54:89:
++ 11:42:d1:f7:24:ba:60:78:1a:98:f7:c9:11:fd:16:
++ c1:35:1a:54:75:ef:43:d3:e5:ae:4e:ce:e7:7b:c3:
++ c6:4e:61:51:4b:ab:9a:45:4b:a1:1f:41:bd:48:53:
++ 15:71:64:0b:86:b3:e5:2e:be:ce:a4:1b:c1:29:84:
++ a2:b5:cb:08:23:76:43:22:24:1f:17:04:d4:6e:9c:
++ c6:fc:7f:2b:66:1a:ec:8a:e5:d6:cf:4d:f5:63:09:
++ b7:15:39:d6:7b:ac:eb:e3:7c:e9:4e:fc:75:42:c8:
++ ed:58:95:0c:06:42:a2:9c:f7:e4:70:b3:df:72:6f:
++ 5a:37:40:89:d8:85:a4:d7:f1:0b:de:43:19:d4:4a:
++ 58:2c:8c:8a:39:9e:bf:84:87:f1:16:3b:36:0c:e9:
++ d3:b4:ca:6c:19:41:52:09:a1:1d:b0:6a:bf:82:ef:
++ 70:51:21:32:dc:05:76:8c:cb:f7:64:e4:03:50:af:
++ 8c:91:67:ab:c5:f2:ee:58:d8:de:be:f7:e7:31:cf:
++ 6c:c9:3b:71:c1:d5:88:b5:65:bc:c0:e8:17:17:07:
++ 12:b5:5c:d2:ab:20:93:b4:e6:82:83:70:36:c5:cd:
++ a3:8d:ad:8b:ec:a3:c1:43:87:e6:43:e2:34:be:95:
++ 8b:35:ed:07:39:da:a8:1d:7a:9f:36:9e:12:b0:0c:
++ 65:12:90:15:60:d9:26:40:44:e3:56:60:a5:10:d4:
++ 6a:3c:fd:41:dc:0e:5a:47:b6:ef:97:61:75:4f:d9:
++ fe:c7:b2:1d:d4:ed:5d:49:b3:a9:6a:cb:66:84:13:
++ d5:5c:a0:dc:df:6e:77:06:d1:71:75:c8:57:6f:af:
++ 0f:77:5b
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ 54:AD:FA:C7:92:57:AE:CA:35:9C:2E:12:FB:E4:BA:5D:20:DC:94:57
++ Signature Algorithm: sha256WithRSAEncryption
++ 30:99:9d:05:32:c8:5e:0e:3b:98:01:3a:8a:a4:e7:07:f7:7a:
++ f8:e7:9a:df:50:43:53:97:2a:3d:ca:3c:47:98:2e:e1:15:7b:
++ f1:92:f3:61:da:90:25:16:65:c0:9f:54:5d:0e:03:3b:5b:77:
++ 02:9c:84:b6:0d:98:5f:34:dd:3b:63:c2:c3:28:81:c2:9c:29:
++ 2e:29:e2:c8:c3:01:f2:33:ea:2a:aa:cc:09:08:f7:65:67:c6:
++ cd:df:d3:b6:2b:a7:bd:cc:d1:0e:70:5f:b8:23:d1:cb:91:4e:
++ 0a:f4:c8:7a:e5:d9:63:36:c1:d4:df:fc:22:97:f7:60:5d:ea:
++ 29:2f:58:b2:bd:58:bd:8d:96:4f:10:75:bf:48:7b:3d:51:87:
++ a1:3c:74:22:c2:fc:07:7f:80:dc:c4:ac:fe:6a:c1:70:30:b0:
++ e9:8e:69:e2:2c:69:81:94:09:ba:dd:fe:4d:c0:83:8c:94:58:
++ c0:46:20:af:9c:1f:02:f8:35:55:49:2f:46:d4:c0:f0:a0:96:
++ 02:0f:33:c5:71:f3:9e:23:7d:94:b7:fd:3a:d3:09:83:06:21:
++ fd:60:3d:ae:32:c0:d2:ee:8d:a6:f0:e7:b4:82:7c:0a:cc:70:
++ c9:79:80:f8:fe:4c:f7:35:84:19:8a:31:fb:0a:d9:d7:7f:9b:
++ f0:a2:9a:6b:c3:05:4a:ed:41:60:14:30:d1:aa:11:42:6e:d3:
++ 23:02:04:0b:c6:65:dd:dd:52:77:da:81:6b:b2:a8:fa:01:38:
++ b9:96:ea:2a:6c:67:97:89:94:9e:bc:e1:54:d5:e4:6a:78:ef:
++ 4a:bd:2b:9a:3d:40:7e:c6:c0:75:d2:6e:fb:68:30:ec:ec:8b:
++ 9d:f9:49:35:9a:1a:2c:d9:b3:95:39:d5:1e:92:f7:a6:b9:65:
++ 2f:e5:3d:6d:3a:48:4c:08:dc:e4:28:12:28:be:7d:35:5c:ea:
++ e0:16:7e:13:1b:6a:d7:3e:d7:9e:fc:2d:75:b2:c1:14:d5:23:
++ 03:db:5b:6f:0b:3e:78:2f:0d:de:33:8d:16:b7:48:e7:83:9a:
++ 81:0f:7b:c1:43:4d:55:04:17:38:4a:51:d5:59:a2:89:74:d3:
++ 9f:be:1e:4b:d7:c6:6d:b7:88:24:6f:60:91:a4:82:85:5b:56:
++ 41:bc:d0:44:ab:6a:13:be:d1:2c:58:b7:12:33:58:b2:37:63:
++ dc:13:f5:94:1d:3f:40:51:f5:4f:f5:3a:ed:c8:c5:eb:c2:1e:
++ 1d:16:95:7a:c7:7e:42:71:93:6e:4b:15:b7:30:df:aa:ed:57:
++ 85:48:ac:1d:6a:dd:39:69:e4:e1:79:78:be:ce:05:bf:a1:0c:
++ f7:80:7b:21:67:27:30:59
++SHA1 Fingerprint=D8:EB:6B:41:51:92:59:E0:F3:E7:85:00:C0:3D:B6:88:97:C9:EE:FC
++-----BEGIN CERTIFICATE-----
++MIIFdDCCA1ygAwIBAgIEAJiiOTANBgkqhkiG9w0BAQsFADBaMQswCQYDVQQGEwJO
++TDEeMBwGA1UECgwVU3RhYXQgZGVyIE5lZGVybGFuZGVuMSswKQYDVQQDDCJTdGFh
++dCBkZXIgTmVkZXJsYW5kZW4gUm9vdCBDQSAtIEczMB4XDTEzMTExNDExMjg0MloX
++DTI4MTExMzIzMDAwMFowWjELMAkGA1UEBhMCTkwxHjAcBgNVBAoMFVN0YWF0IGRl
++ciBOZWRlcmxhbmRlbjErMCkGA1UEAwwiU3RhYXQgZGVyIE5lZGVybGFuZGVuIFJv
++b3QgQ0EgLSBHMzCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAL4yolQP
++cPssXFnrbMSkUeiFKrPMSjTysF/zDsccPVMeiAho2G89rcKezIJnByeHaHE6n3WW
++IkYFsO2tx1ueKt6c/DrGlaf1F2cY5y9JCAxcz+bMNO14+1Cx3Gsy8KL+tjzk7FqX
++xz8ecAgwoNzFs21v0IJyEavSgWhZghe3eJJg+szeP4TrjTgzkApyI/o1zCZxMdFy
++KJLZWyNtZrVtB0LrpjPOktvA9mxjeM3KTj215VKb8b475lRgsGYeCasH/lSJEULR
++9yS6YHgamPfJEf0WwTUaVHXvQ9Plrk7O53vDxk5hUUurmkVLoR9BvUhTFXFkC4az
++5S6+zqQbwSmEorXLCCN2QyIkHxcE1G6cxvx/K2Ya7Irl1s9N9WMJtxU51nus6+N8
++6U78dULI7ViVDAZCopz35HCz33JvWjdAidiFpNfxC95DGdRKWCyMijmev4SH8RY7
++Ngzp07TKbBlBUgmhHbBqv4LvcFEhMtwFdozL92TkA1CvjJFnq8Xy7ljY3r735zHP
++bMk7ccHViLVlvMDoFxcHErVc0qsgk7TmgoNwNsXNo42ti+yjwUOH5kPiNL6VizXt
++BznaqB16nzaeErAMZRKQFWDZJkBE41ZgpRDUajz9QdwOWke275dhdU/Z/seyHdTt
++XUmzqWrLZoQT1Vyg3N9udwbRcXXIV2+vD3dbAgMBAAGjQjBAMA8GA1UdEwEB/wQF
++MAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBRUrfrHkleuyjWcLhL75Lpd
++INyUVzANBgkqhkiG9w0BAQsFAAOCAgEAMJmdBTLIXg47mAE6iqTnB/d6+Oea31BD
++U5cqPco8R5gu4RV78ZLzYdqQJRZlwJ9UXQ4DO1t3ApyEtg2YXzTdO2PCwyiBwpwp
++LiniyMMB8jPqKqrMCQj3ZWfGzd/TtiunvczRDnBfuCPRy5FOCvTIeuXZYzbB1N/8
++Ipf3YF3qKS9Ysr1YvY2WTxB1v0h7PVGHoTx0IsL8B3+A3MSs/mrBcDCw6Y5p4ixp
++gZQJut3+TcCDjJRYwEYgr5wfAvg1VUkvRtTA8KCWAg8zxXHzniN9lLf9OtMJgwYh
++/WA9rjLA0u6NpvDntIJ8CsxwyXmA+P5M9zWEGYox+wrZ13+b8KKaa8MFSu1BYBQw
++0aoRQm7TIwIEC8Zl3d1Sd9qBa7Ko+gE4uZbqKmxnl4mUnrzhVNXkanjvSr0rmj1A
++fsbAddJu+2gw7OyLnflJNZoaLNmzlTnVHpL3prllL+U9bTpITAjc5CgSKL59NVzq
++4BZ+Extq1z7XnvwtdbLBFNUjA9tbbws+eC8N3jONFrdI54OagQ97wUNNVQQXOEpR
++1VmiiXTTn74eS9fGbbeIJG9gkaSChVtWQbzQRKtqE77RLFi3EjNYsjdj3BP1lB0/
++QFH1T/U67cjF68IeHRaVesd+QnGTbksVtzDfqu1XhUisHWrdOWnk4Xl4vs4Fv6EM
++94B7IWcnMFk=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/SwissSign_Platinum_CA_-_G2.pem
+@@ -0,0 +1,140 @@
++##
++## SwissSign Platinum CA - G2
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 5670595323396054351 (0x4eb200670c035d4f)
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
++ Validity
++ Not Before: Oct 25 08:36:00 2006 GMT
++ Not After : Oct 25 08:36:00 2036 GMT
++ Subject: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:ca:df:a2:02:e2:da:f8:fc:07:16:b1:de:60:aa:
++ de:96:5c:64:1f:c7:2f:7e:cf:67:fa:44:42:d6:76:
++ 63:95:ae:eb:af:72:20:8a:45:47:86:62:78:86:d6:
++ 20:39:26:f4:ae:a3:fd:23:e7:a5:9c:b5:22:21:19:
++ b7:37:93:22:c0:50:9c:82:7b:d4:d5:04:44:5c:cb:
++ b4:c2:9f:92:be:24:d8:7b:67:22:e2:69:5f:e5:05:
++ 78:d4:87:d9:71:70:33:25:53:b4:87:3b:29:90:28:
++ 36:9a:55:44:30:68:a4:83:97:7f:0d:1e:9c:76:ff:
++ 15:9d:60:97:00:8d:8a:85:03:ec:80:be:ea:2c:6e:
++ 10:51:92:cc:7e:d5:a3:33:d8:d6:49:de:58:2a:af:
++ f6:16:eb:4b:7b:90:32:97:b9:ba:9d:58:f1:f8:57:
++ 49:04:1e:a2:5d:06:70:dd:71:db:f9:dd:8b:9a:1b:
++ 8c:cf:3d:a3:4d:ce:cb:7c:f6:bb:9c:a0:fa:09:ce:
++ 23:62:b2:e9:0d:1f:e2:72:28:8f:9f:ac:68:20:7d:
++ 6f:3b:a8:85:31:09:7f:0b:c7:e8:65:e9:e3:78:0e:
++ 09:67:30:8b:34:82:fb:5d:e0:cc:9d:81:6d:62:ee:
++ 08:1e:04:2c:4e:9b:ec:fe:a9:4f:5f:fd:69:78:ef:
++ 09:1f:a1:b4:bf:fa:f3:ef:90:1e:4c:05:8b:1e:ea:
++ 7a:91:7a:c3:d7:e5:fb:30:bc:6c:1b:10:58:98:f7:
++ 1a:5f:d0:29:32:03:13:46:4d:61:6a:85:4c:52:74:
++ 2f:06:1f:7b:11:e2:84:97:c6:99:f3:6d:7f:d7:67:
++ 83:7e:13:68:d8:71:28:5a:d8:ce:dd:e8:10:14:9a:
++ fe:6d:23:87:6e:8e:5a:70:3c:d5:8d:09:00:a7:aa:
++ bc:b0:31:37:6d:c8:84:14:1e:5b:bd:45:63:20:6b:
++ 4b:74:8c:bd:db:3a:0e:c1:cf:5a:16:8f:a5:98:f2:
++ 76:89:b2:13:12:3b:0b:77:77:ac:bb:e5:3c:29:4a:
++ 92:72:ca:61:1a:2b:5e:4c:e2:83:74:77:fa:35:48:
++ 7a:85:4d:8d:9a:53:c4:df:78:ca:97:91:48:2b:45:
++ 2b:01:f7:1c:1a:a2:ed:18:ba:0a:bd:83:fa:6f:bc:
++ 8d:57:93:3b:d4:d4:a6:ce:1e:f1:a0:b1:ce:ab:fd:
++ 2b:28:9a:4f:1b:d7:c3:72:db:a4:c4:bf:5d:4c:f5:
++ dd:7b:96:69:ee:68:80:e6:e7:98:ba:36:b7:fe:6e:
++ ed:2b:bd:20:f8:65:19:da:55:09:7e:25:dc:fe:61:
++ 62:72:f9:7e:18:02:ef:63:b4:d0:fb:af:e5:3b:63:
++ 8c:67:8f
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
++ X509v3 Authority Key Identifier:
++ keyid:50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
++
++ X509v3 Certificate Policies:
++ Policy: 2.16.756.1.89.1.1.1.1
++ CPS: http://repository.swisssign.com/
++
++ Signature Algorithm: sha1WithRSAEncryption
++ 08:85:a6:f5:16:0c:fc:44:1a:c1:63:e0:f9:55:46:08:fc:70:
++ 1c:42:28:96:8e:b7:c5:c1:41:75:4e:09:71:79:e5:6d:96:ca:
++ 4b:a5:88:60:d0:30:74:b8:ca:08:dc:b4:30:9e:40:07:16:6b:
++ 65:95:77:01:ae:a4:b7:35:0b:81:da:71:15:a9:74:17:38:7b:
++ 58:ca:f9:2f:fb:c0:65:76:8d:5b:01:b9:7d:de:82:3d:64:b8:
++ be:14:74:a3:0a:54:d3:2c:95:18:17:35:f5:51:6b:3f:8f:a2:
++ 96:61:39:78:6b:4b:e5:a6:a0:f8:53:df:51:10:93:62:e7:80:
++ 2f:e2:d1:e0:bc:8e:36:46:77:33:ec:b8:fb:8e:9a:2c:89:4d:
++ 31:11:0f:26:9e:04:bb:b7:04:8d:0b:f2:b9:fc:5a:9d:3b:16:
++ b7:2f:c8:98:ab:fe:8a:50:59:2e:a3:3b:fc:29:5d:8b:c1:4b:
++ c9:e2:8a:13:1d:b1:bf:bb:42:1d:52:dd:4e:d8:14:5e:10:c6:
++ 31:07:ef:71:27:f7:1b:39:09:dc:82:ea:8b:b3:95:86:5e:fd:
++ f5:da:5d:31:a6:e0:31:b6:94:e6:44:49:74:c5:16:e5:f7:1f:
++ 03:61:28:c5:c8:cb:12:a0:42:4b:f9:6b:88:08:8d:b4:32:18:
++ f3:75:9f:c4:7f:00:4f:05:95:9c:a3:17:02:c3:b3:53:9b:aa:
++ 20:39:29:2b:66:fa:9d:af:5e:b3:92:d2:b5:a6:e1:1a:f9:2d:
++ 41:69:81:14:b4:b4:b5:ed:89:3d:ce:fb:a9:9d:35:42:44:b1:
++ 1c:14:73:81:cf:2a:01:35:9a:31:d5:2d:8f:6d:84:df:80:4d:
++ 57:e3:3f:c5:84:75:da:89:c6:30:bb:eb:8f:cb:22:08:a0:ae:
++ aa:f1:03:6c:3a:4b:4d:09:a5:0e:72:c6:56:6b:21:42:4e:23:
++ 25:14:68:ae:76:0a:7c:0c:07:70:64:f9:9a:2f:f6:05:39:26:
++ c6:0c:8f:19:7f:43:5e:6e:f4:5b:15:2f:db:61:5d:e6:67:2f:
++ 3f:08:94:f9:60:b4:98:31:da:74:f1:84:93:71:4d:5f:fb:60:
++ 58:d1:fb:c4:c1:6d:89:a2:bb:20:1f:9d:71:91:cb:32:9b:13:
++ 3d:3e:7d:92:52:35:ac:92:94:a2:d3:18:c2:7c:c7:ea:af:76:
++ 05:16:dd:67:27:c2:7e:1c:07:22:21:f3:40:0a:1b:34:07:44:
++ 13:c2:84:6a:8e:df:19:5a:bf:7f:eb:1d:e2:1a:38:d1:5c:af:
++ 47:92:6b:80:b5:30:a5:c9:8d:d8:ab:31:81:1f:df:c2:66:37:
++ d3:93:a9:85:86:79:65:d2
++SHA1 Fingerprint=56:E0:FA:C0:3B:8F:18:23:55:18:E5:D3:11:CA:E8:C2:43:31:AB:66
++-----BEGIN CERTIFICATE-----
++MIIFwTCCA6mgAwIBAgIITrIAZwwDXU8wDQYJKoZIhvcNAQEFBQAwSTELMAkGA1UE
++BhMCQ0gxFTATBgNVBAoTDFN3aXNzU2lnbiBBRzEjMCEGA1UEAxMaU3dpc3NTaWdu
++IFBsYXRpbnVtIENBIC0gRzIwHhcNMDYxMDI1MDgzNjAwWhcNMzYxMDI1MDgzNjAw
++WjBJMQswCQYDVQQGEwJDSDEVMBMGA1UEChMMU3dpc3NTaWduIEFHMSMwIQYDVQQD
++ExpTd2lzc1NpZ24gUGxhdGludW0gQ0EgLSBHMjCCAiIwDQYJKoZIhvcNAQEBBQAD
++ggIPADCCAgoCggIBAMrfogLi2vj8Bxax3mCq3pZcZB/HL37PZ/pEQtZ2Y5Wu669y
++IIpFR4ZieIbWIDkm9K6j/SPnpZy1IiEZtzeTIsBQnIJ71NUERFzLtMKfkr4k2Htn
++IuJpX+UFeNSH2XFwMyVTtIc7KZAoNppVRDBopIOXfw0enHb/FZ1glwCNioUD7IC+
++6ixuEFGSzH7VozPY1kneWCqv9hbrS3uQMpe5up1Y8fhXSQQeol0GcN1x2/ndi5ob
++jM89o03Oy3z2u5yg+gnOI2Ky6Q0f4nIoj5+saCB9bzuohTEJfwvH6GXp43gOCWcw
++izSC+13gzJ2BbWLuCB4ELE6b7P6pT1/9aXjvCR+htL/68++QHkwFix7qepF6w9fl
+++zC8bBsQWJj3Gl/QKTIDE0ZNYWqFTFJ0LwYfexHihJfGmfNtf9dng34TaNhxKFrY
++zt3oEBSa/m0jh26OWnA81Y0JAKeqvLAxN23IhBQeW71FYyBrS3SMvds6DsHPWhaP
++pZjydomyExI7C3d3rLvlPClKknLKYRorXkzig3R3+jVIeoVNjZpTxN94ypeRSCtF
++KwH3HBqi7Ri6Cr2D+m+8jVeTO9TUps4e8aCxzqv9KyiaTxvXw3LbpMS/XUz13XuW
++ae5ogObnmLo2t/5u7Su9IPhlGdpVCX4l3P5hYnL5fhgC72O00Puv5TtjjGePAgMB
++AAGjgawwgakwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0O
++BBYEFFCvzAeHFUdvOMW0ZdHelarp35zMMB8GA1UdIwQYMBaAFFCvzAeHFUdvOMW0
++ZdHelarp35zMMEYGA1UdIAQ/MD0wOwYJYIV0AVkBAQEBMC4wLAYIKwYBBQUHAgEW
++IGh0dHA6Ly9yZXBvc2l0b3J5LnN3aXNzc2lnbi5jb20vMA0GCSqGSIb3DQEBBQUA
++A4ICAQAIhab1Fgz8RBrBY+D5VUYI/HAcQiiWjrfFwUF1TglxeeVtlspLpYhg0DB0
++uMoI3LQwnkAHFmtllXcBrqS3NQuB2nEVqXQXOHtYyvkv+8Bldo1bAbl93oI9ZLi+
++FHSjClTTLJUYFzX1UWs/j6KWYTl4a0vlpqD4U99REJNi54Av4tHgvI42Rncz7Lj7
++jposiU0xEQ8mngS7twSNC/K5/FqdOxa3L8iYq/6KUFkuozv8KV2LwUvJ4ooTHbG/
++u0IdUt1O2BReEMYxB+9xJ/cbOQncguqLs5WGXv312l0xpuAxtpTmREl0xRbl9x8D
++YSjFyMsSoEJL+WuICI20MhjzdZ/EfwBPBZWcoxcCw7NTm6ogOSkrZvqdr16zktK1
++puEa+S1BaYEUtLS17Yk9zvupnTVCRLEcFHOBzyoBNZox1S2PbYTfgE1X4z/FhHXa
++icYwu+uPyyIIoK6q8QNsOktNCaUOcsZWayFCTiMlFGiudgp8DAdwZPmaL/YFOSbG
++DI8Zf0NebvRbFS/bYV3mZy8/CJT5YLSYMdp08YSTcU1f+2BY0fvEwW2JorsgH51x
++kcsymxM9Pn2SUjWskpSi0xjCfMfqr3YFFt1nJ8J+HAciIfNAChs0B0QTwoRqjt8Z
++Wr9/6x3iGjjRXK9HkmuAtTClyY3YqzGBH9/CZjfTk6mFhnll0g==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
+@@ -0,0 +1,94 @@
++##
++## Symantec Class 1 Public Primary Certification Authority - G6
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 24:32:75:f2:1d:2f:d2:09:33:f7:b4:6a:ca:d0:f3:98
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
++ Validity
++ Not Before: Oct 18 00:00:00 2011 GMT
++ Not After : Dec 1 23:59:59 2037 GMT
++ Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c7:39:d7:49:64:a9:99:82:22:4c:ea:45:d9:07:
++ 16:e3:7b:f4:83:e8:99:73:fa:6b:b1:36:e0:9a:77:
++ a0:40:c2:81:8d:01:c7:cc:8c:bd:8f:7d:f7:79:e3:
++ 7a:4c:03:4d:d9:fb:fd:87:38:28:2c:dd:9a:8b:54:
++ 08:db:67:fb:1b:8c:fe:28:92:2f:be:b7:b2:48:a7:
++ 81:a1:d8:5e:88:c3:cc:39:40:41:5a:d1:dc:e5:da:
++ 10:9f:2f:da:01:4d:fd:2e:46:7c:f9:2e:27:0a:69:
++ 37:ee:91:a3:1b:6a:cc:44:bf:1b:c7:c3:d4:11:b2:
++ 50:60:97:09:bd:2e:22:f5:41:84:66:9f:cd:40:a6:
++ a9:00:80:c1:1f:95:92:9f:de:f3:48:ef:db:1d:77:
++ 61:fc:7f:df:ee:96:a4:72:d0:b6:3e:ff:78:27:af:
++ cb:92:15:69:08:db:63:10:e2:e6:97:ac:6e:dc:ac:
++ f6:a2:ce:1e:47:99:b9:89:b7:12:e6:a1:d4:cd:59:
++ 11:67:c3:6f:85:d8:42:4e:28:be:59:55:59:04:95:
++ ab:8f:37:80:bf:0d:f0:fc:1f:3a:64:31:58:81:78:
++ d7:e2:35:f6:20:3f:29:b8:8f:16:6e:3e:48:dc:b5:
++ 4c:07:e1:f2:1a:ea:7e:0a:79:d6:a8:bd:eb:5d:86:
++ 2b:4d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 33:41:E8:C8:39:12:15:93:48:F2:96:32:2E:5A:F5:DA:94:5F:53:60
++ Signature Algorithm: sha256WithRSAEncryption
++ 15:e3:73:57:b1:17:b6:5f:49:69:44:a6:f6:5e:7a:67:ac:d2:
++ de:75:49:ab:fe:25:55:c7:3a:c9:44:15:10:6e:bf:31:6b:cb:
++ d9:07:93:7f:1c:85:63:00:e3:32:12:e0:cc:cb:fb:39:6c:8f:
++ e2:53:e2:3c:40:33:d9:a4:8c:47:e6:ad:58:fb:89:af:e3:de:
++ 86:29:56:34:2c:45:b8:12:fa:44:89:6e:2d:14:25:28:24:01:
++ 65:d6:ea:52:ac:05:6e:56:12:09:3d:d0:74:f4:d7:bd:06:ca:
++ a8:3a:8d:56:42:fa:8d:72:3e:74:f1:03:72:df:87:1b:5e:0e:
++ 7a:55:96:2c:38:b7:98:85:cd:4d:33:44:c9:94:8f:5a:31:30:
++ 37:4b:a3:3a:12:b3:e7:36:d1:21:68:4b:2d:38:e6:53:ae:1c:
++ 25:56:08:56:03:67:84:9d:c6:c3:ce:24:62:c7:4c:36:cf:b0:
++ 06:44:b7:f5:5f:02:dd:d9:54:e9:2f:90:4e:7a:c8:4e:83:40:
++ 0c:9a:97:3c:37:bf:bf:ec:f6:f0:b4:85:77:28:c1:0b:c8:67:
++ 82:10:17:38:a2:b7:06:ea:9b:bf:3a:f8:e9:23:07:bf:74:e0:
++ 98:38:15:55:78:ee:72:00:5c:19:a3:f4:d2:33:e0:ff:bd:d1:
++ 54:39:29:0f
++SHA1 Fingerprint=51:7F:61:1E:29:91:6B:53:82:FB:72:E7:44:D9:8D:C3:CC:53:6D:64
++-----BEGIN CERTIFICATE-----
++MIID9jCCAt6gAwIBAgIQJDJ18h0v0gkz97RqytDzmDANBgkqhkiG9w0BAQsFADCB
++lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
++HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
++YyBDbGFzcyAxIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
++IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
++BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
++eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAx
++IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
++MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHOddJZKmZgiJM6kXZBxbje/SD
++6Jlz+muxNuCad6BAwoGNAcfMjL2Pffd543pMA03Z+/2HOCgs3ZqLVAjbZ/sbjP4o
++ki++t7JIp4Gh2F6Iw8w5QEFa0dzl2hCfL9oBTf0uRnz5LicKaTfukaMbasxEvxvH
++w9QRslBglwm9LiL1QYRmn81ApqkAgMEflZKf3vNI79sdd2H8f9/ulqRy0LY+/3gn
++r8uSFWkI22MQ4uaXrG7crPaizh5HmbmJtxLmodTNWRFnw2+F2EJOKL5ZVVkElauP
++N4C/DfD8HzpkMViBeNfiNfYgPym4jxZuPkjctUwH4fIa6n4KedaovetdhitNAgMB
++AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
++BBQzQejIORIVk0jyljIuWvXalF9TYDANBgkqhkiG9w0BAQsFAAOCAQEAFeNzV7EX
++tl9JaUSm9l56Z6zS3nVJq/4lVcc6yUQVEG6/MWvL2QeTfxyFYwDjMhLgzMv7OWyP
++4lPiPEAz2aSMR+atWPuJr+PehilWNCxFuBL6RIluLRQlKCQBZdbqUqwFblYSCT3Q
++dPTXvQbKqDqNVkL6jXI+dPEDct+HG14OelWWLDi3mIXNTTNEyZSPWjEwN0ujOhKz
++5zbRIWhLLTjmU64cJVYIVgNnhJ3Gw84kYsdMNs+wBkS39V8C3dlU6S+QTnrIToNA
++DJqXPDe/v+z28LSFdyjBC8hnghAXOKK3Buqbvzr46SMHv3TgmDgVVXjucgBcGaP0
++0jPg/73RVDkpDw==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
+@@ -0,0 +1,94 @@
++##
++## Symantec Class 2 Public Primary Certification Authority - G6
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 64:82:9e:fc:37:1e:74:5d:fc:97:ff:97:c8:b1:ff:41
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
++ Validity
++ Not Before: Oct 18 00:00:00 2011 GMT
++ Not After : Dec 1 23:59:59 2037 GMT
++ Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:cd:cc:e9:05:c8:63:85:cb:3f:40:63:17:bd:18:
++ fa:35:e6:04:67:57:65:98:29:a4:4f:c9:5c:8f:0f:
++ 34:d2:f8:da:a8:13:62:aa:b8:1e:50:67:78:b0:16:
++ 4c:a0:39:a9:15:7a:ae:ed:d2:a2:c0:f0:90:37:29:
++ 18:26:5c:e8:0d:3c:b6:6c:49:3f:c1:e0:dc:d9:4b:
++ b6:14:19:0b:a6:d3:96:e1:d6:09:e3:19:26:1c:f9:
++ 1f:65:4b:f9:1a:43:1c:00:83:d6:d0:aa:49:a2:d4:
++ db:e6:62:38:ba:50:14:43:6d:f9:31:f8:56:16:d9:
++ 38:02:91:cf:eb:6c:dd:bb:39:4e:99:e1:30:67:45:
++ f1:d4:f0:8d:c3:df:fe:f2:38:07:21:7d:00:5e:56:
++ 44:b3:e4:60:bd:91:2b:9c:ab:5b:04:72:0f:b2:28:
++ d9:72:ab:05:20:42:25:a9:5b:03:6a:20:10:cc:31:
++ f0:2b:da:35:2c:d0:fb:9a:97:4e:f0:82:4b:2b:d8:
++ 5f:36:a3:0b:2d:af:63:0d:1d:25:7f:a1:6e:5c:62:
++ a1:8d:28:3e:a1:fc:1c:20:f8:01:2f:ba:55:9a:11:
++ b0:19:d2:c8:50:79:6b:0e:6a:05:d7:aa:04:36:b2:
++ a3:f2:e1:5f:77:a7:77:9c:e5:1e:dc:e9:df:6a:c1:
++ 65:5d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 87:8C:20:95:C8:98:4A:D1:D6:80:06:4A:90:34:44:DF:1C:4D:BF:B0
++ Signature Algorithm: sha256WithRSAEncryption
++ 81:8e:b2:a5:66:96:b7:21:a5:b6:ef:6f:23:5a:5f:db:81:c5:
++ 42:a5:78:c1:69:fd:f4:3c:d7:f9:5c:6b:70:72:1a:fc:5a:97:
++ 4d:00:80:88:88:82:8a:c3:71:0d:8e:c5:89:9b:2c:ed:8d:0b:
++ d2:72:54:f5:7d:d4:5c:43:57:e9:f3:ae:a5:02:11:f6:76:2b:
++ 81:57:dd:7d:da:74:30:fd:54:47:f6:e0:16:6e:a6:b4:0a:48:
++ e6:e7:75:07:0f:29:19:39:ce:79:f4:b6:6c:c5:5f:99:d5:1f:
++ 4b:fa:df:6d:2c:3c:0d:54:80:70:f0:88:0b:80:cf:c6:68:a2:
++ b8:1d:70:d9:76:8c:fc:ee:a5:c9:cf:ad:1d:cf:99:25:57:5a:
++ 62:45:cb:16:6b:bd:49:cd:a5:a3:8c:69:79:25:ae:b8:4c:6c:
++ 8b:40:66:4b:16:3f:cf:02:1a:dd:e1:6c:6b:07:61:6a:76:15:
++ 29:99:7f:1b:dd:88:80:c1:bf:b5:8f:73:c5:a6:96:23:84:a6:
++ 28:86:24:33:6a:01:2e:57:73:25:b6:5e:bf:8f:e6:1d:61:a8:
++ 40:29:67:1d:87:9b:1d:7f:9b:9f:99:cd:31:d6:54:be:62:bb:
++ 39:ac:68:12:48:91:20:a5:cb:b1:dd:fe:6f:fc:5a:e4:82:55:
++ 59:af:31:a9
++SHA1 Fingerprint=40:B3:31:A0:E9:BF:E8:55:BC:39:93:CA:70:4F:4E:C2:51:D4:1D:8F
++-----BEGIN CERTIFICATE-----
++MIID9jCCAt6gAwIBAgIQZIKe/DcedF38l/+XyLH/QTANBgkqhkiG9w0BAQsFADCB
++lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
++HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
++YyBDbGFzcyAyIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
++IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
++BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
++eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAy
++IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
++MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDNzOkFyGOFyz9AYxe9GPo15gRn
++V2WYKaRPyVyPDzTS+NqoE2KquB5QZ3iwFkygOakVeq7t0qLA8JA3KRgmXOgNPLZs
++ST/B4NzZS7YUGQum05bh1gnjGSYc+R9lS/kaQxwAg9bQqkmi1NvmYji6UBRDbfkx
+++FYW2TgCkc/rbN27OU6Z4TBnRfHU8I3D3/7yOAchfQBeVkSz5GC9kSucq1sEcg+y
++KNlyqwUgQiWpWwNqIBDMMfAr2jUs0Pual07wgksr2F82owstr2MNHSV/oW5cYqGN
++KD6h/Bwg+AEvulWaEbAZ0shQeWsOagXXqgQ2sqPy4V93p3ec5R7c6d9qwWVdAgMB
++AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
++BBSHjCCVyJhK0daABkqQNETfHE2/sDANBgkqhkiG9w0BAQsFAAOCAQEAgY6ypWaW
++tyGltu9vI1pf24HFQqV4wWn99DzX+VxrcHIa/FqXTQCAiIiCisNxDY7FiZss7Y0L
++0nJU9X3UXENX6fOupQIR9nYrgVfdfdp0MP1UR/bgFm6mtApI5ud1Bw8pGTnOefS2
++bMVfmdUfS/rfbSw8DVSAcPCIC4DPxmiiuB1w2XaM/O6lyc+tHc+ZJVdaYkXLFmu9
++Sc2lo4xpeSWuuExsi0BmSxY/zwIa3eFsawdhanYVKZl/G92IgMG/tY9zxaaWI4Sm
++KIYkM2oBLldzJbZev4/mHWGoQClnHYebHX+bn5nNMdZUvmK7OaxoEkiRIKXLsd3+
++b/xa5IJVWa8xqQ==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Trustis_FPS_Root_CA.pem
+@@ -0,0 +1,92 @@
++##
++## Trustis FPS Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 1b:1f:ad:b6:20:f9:24:d3:36:6b:f7:c7:f1:8c:a0:59
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
++ Validity
++ Not Before: Dec 23 12:14:06 2003 GMT
++ Not After : Jan 21 11:36:54 2024 GMT
++ Subject: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c5:50:7b:9e:3b:35:d0:df:c4:8c:cd:8e:9b:ed:
++ a3:c0:36:99:f4:42:ea:a7:3e:80:83:0f:a6:a7:59:
++ 87:c9:90:45:43:7e:00:ea:86:79:2a:03:bd:3d:37:
++ 99:89:66:b7:e5:8a:56:86:93:9c:68:4b:68:04:8c:
++ 93:93:02:3e:30:d2:37:3a:22:61:89:1c:85:4e:7d:
++ 8f:d5:af:7b:35:f6:7e:28:47:89:31:dc:0e:79:64:
++ 1f:99:d2:5b:ba:fe:7f:60:bf:ad:eb:e7:3c:38:29:
++ 6a:2f:e5:91:0b:55:ff:ec:6f:58:d5:2d:c9:de:4c:
++ 66:71:8f:0c:d7:04:da:07:e6:1e:18:e3:bd:29:02:
++ a8:fa:1c:e1:5b:b9:83:a8:41:48:bc:1a:71:8d:e7:
++ 62:e5:2d:b2:eb:df:7c:cf:db:ab:5a:ca:31:f1:4c:
++ 22:f3:05:13:f7:82:f9:73:79:0c:be:d7:4b:1c:c0:
++ d1:15:3c:93:41:64:d1:e6:be:23:17:22:00:89:5e:
++ 1f:6b:a5:ac:6e:a7:4b:8c:ed:a3:72:e6:af:63:4d:
++ 2f:85:d2:14:35:9a:2e:4e:8c:ea:32:98:28:86:a1:
++ 91:09:41:3a:b4:e1:e3:f2:fa:f0:c9:0a:a2:41:dd:
++ a9:e3:03:c7:88:15:3b:1c:d4:1a:94:d7:9f:64:59:
++ 12:6d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Authority Key Identifier:
++ keyid:BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
++
++ X509v3 Subject Key Identifier:
++ BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
++ Signature Algorithm: sha1WithRSAEncryption
++ 7e:58:ff:fd:35:19:7d:9c:18:4f:9e:b0:2b:bc:8e:8c:14:ff:
++ 2c:a0:da:47:5b:c3:ef:81:2d:af:05:ea:74:48:5b:f3:3e:4e:
++ 07:c7:6d:c5:b3:93:cf:22:35:5c:b6:3f:75:27:5f:09:96:cd:
++ a0:fe:be:40:0c:5c:12:55:f8:93:82:ca:29:e9:5e:3f:56:57:
++ 8b:38:36:f7:45:1a:4c:28:cd:9e:41:b8:ed:56:4c:84:a4:40:
++ c8:b8:b0:a5:2b:69:70:04:6a:c3:f8:d4:12:32:f9:0e:c3:b1:
++ dc:32:84:44:2c:6f:cb:46:0f:ea:66:41:0f:4f:f1:58:a5:a6:
++ 0d:0d:0f:61:de:a5:9e:5d:7d:65:a1:3c:17:e7:a8:55:4e:ef:
++ a0:c7:ed:c6:44:7f:54:f5:a3:e0:8f:f0:7c:55:22:8f:29:b6:
++ 81:a3:e1:6d:4e:2c:1b:80:67:ec:ad:20:9f:0c:62:61:d5:97:
++ ff:43:ed:2d:c1:da:5d:29:2a:85:3f:ac:65:ee:86:0f:05:8d:
++ 90:5f:df:ee:9f:f4:bf:ee:1d:fb:98:e4:7f:90:2b:84:78:10:
++ 0e:6c:49:53:ef:15:5b:65:46:4a:5d:af:ba:fb:3a:72:1d:cd:
++ f6:25:88:1e:97:cc:21:9c:29:01:0d:65:eb:57:d9:f3:57:96:
++ bb:48:cd:81
++SHA1 Fingerprint=3B:C0:38:0B:33:C3:F6:A6:0C:86:15:22:93:D9:DF:F5:4B:81:C0:04
++-----BEGIN CERTIFICATE-----
++MIIDZzCCAk+gAwIBAgIQGx+ttiD5JNM2a/fH8YygWTANBgkqhkiG9w0BAQUFADBF
++MQswCQYDVQQGEwJHQjEYMBYGA1UEChMPVHJ1c3RpcyBMaW1pdGVkMRwwGgYDVQQL
++ExNUcnVzdGlzIEZQUyBSb290IENBMB4XDTAzMTIyMzEyMTQwNloXDTI0MDEyMTEx
++MzY1NFowRTELMAkGA1UEBhMCR0IxGDAWBgNVBAoTD1RydXN0aXMgTGltaXRlZDEc
++MBoGA1UECxMTVHJ1c3RpcyBGUFMgUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQAD
++ggEPADCCAQoCggEBAMVQe547NdDfxIzNjpvto8A2mfRC6qc+gIMPpqdZh8mQRUN+
++AOqGeSoDvT03mYlmt+WKVoaTnGhLaASMk5MCPjDSNzoiYYkchU59j9WvezX2fihH
++iTHcDnlkH5nSW7r+f2C/revnPDgpai/lkQtV/+xvWNUtyd5MZnGPDNcE2gfmHhjj
++vSkCqPoc4Vu5g6hBSLwacY3nYuUtsuvffM/bq1rKMfFMIvMFE/eC+XN5DL7XSxzA
++0RU8k0Fk0ea+IxciAIleH2ulrG6nS4zto3Lmr2NNL4XSFDWaLk6M6jKYKIahkQlB
++OrTh4/L68MkKokHdqeMDx4gVOxzUGpTXn2RZEm0CAwEAAaNTMFEwDwYDVR0TAQH/
++BAUwAwEB/zAfBgNVHSMEGDAWgBS6+nEleYtXQSUhhgtx67JkDoshZzAdBgNVHQ4E
++FgQUuvpxJXmLV0ElIYYLceuyZA6LIWcwDQYJKoZIhvcNAQEFBQADggEBAH5Y//01
++GX2cGE+esCu8jowU/yyg2kdbw++BLa8F6nRIW/M+TgfHbcWzk88iNVy2P3UnXwmW
++zaD+vkAMXBJV+JOCyinpXj9WV4s4NvdFGkwozZ5BuO1WTISkQMi4sKUraXAEasP4
++1BIy+Q7DsdwyhEQsb8tGD+pmQQ9P8Vilpg0ND2HepZ5dfWWhPBfnqFVO76DH7cZE
++f1T1o+CP8HxVIo8ptoGj4W1OLBuAZ+ytIJ8MYmHVl/9D7S3B2l0pKoU/rGXuhg8F
++jZBf3+6f9L/uHfuY5H+QK4R4EA5sSVPvFVtlRkpdr7r7OnIdzfYliB6XzCGcKQEN
++ZetX2fNXlrtIzYE=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/VeriSign_Universal_Root_Certification_Authority.pem
+@@ -0,0 +1,100 @@
++##
++## VeriSign Universal Root Certification Authority
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 40:1a:c4:64:21:b3:13:21:03:0e:bb:e4:12:1a:c5:1d
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
++ Validity
++ Not Before: Apr 2 00:00:00 2008 GMT
++ Not After : Dec 1 23:59:59 2037 GMT
++ Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:c7:61:37:5e:b1:01:34:db:62:d7:15:9b:ff:58:
++ 5a:8c:23:23:d6:60:8e:91:d7:90:98:83:7a:e6:58:
++ 19:38:8c:c5:f6:e5:64:85:b4:a2:71:fb:ed:bd:b9:
++ da:cd:4d:00:b4:c8:2d:73:a5:c7:69:71:95:1f:39:
++ 3c:b2:44:07:9c:e8:0e:fa:4d:4a:c4:21:df:29:61:
++ 8f:32:22:61:82:c5:87:1f:6e:8c:7c:5f:16:20:51:
++ 44:d1:70:4f:57:ea:e3:1c:e3:cc:79:ee:58:d8:0e:
++ c2:b3:45:93:c0:2c:e7:9a:17:2b:7b:00:37:7a:41:
++ 33:78:e1:33:e2:f3:10:1a:7f:87:2c:be:f6:f5:f7:
++ 42:e2:e5:bf:87:62:89:5f:00:4b:df:c5:dd:e4:75:
++ 44:32:41:3a:1e:71:6e:69:cb:0b:75:46:08:d1:ca:
++ d2:2b:95:d0:cf:fb:b9:40:6b:64:8c:57:4d:fc:13:
++ 11:79:84:ed:5e:54:f6:34:9f:08:01:f3:10:25:06:
++ 17:4a:da:f1:1d:7a:66:6b:98:60:66:a4:d9:ef:d2:
++ 2e:82:f1:f0:ef:09:ea:44:c9:15:6a:e2:03:6e:33:
++ d3:ac:9f:55:00:c7:f6:08:6a:94:b9:5f:dc:e0:33:
++ f1:84:60:f9:5b:27:11:b4:fc:16:f2:bb:56:6a:80:
++ 25:8d
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ 1.3.6.1.5.5.7.1.12:
++ 0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif
++ X509v3 Subject Key Identifier:
++ B6:77:FA:69:48:47:9F:53:12:D5:C2:EA:07:32:76:07:D1:97:07:19
++ Signature Algorithm: sha256WithRSAEncryption
++ 4a:f8:f8:b0:03:e6:2c:67:7b:e4:94:77:63:cc:6e:4c:f9:7d:
++ 0e:0d:dc:c8:b9:35:b9:70:4f:63:fa:24:fa:6c:83:8c:47:9d:
++ 3b:63:f3:9a:f9:76:32:95:91:b1:77:bc:ac:9a:be:b1:e4:31:
++ 21:c6:81:95:56:5a:0e:b1:c2:d4:b1:a6:59:ac:f1:63:cb:b8:
++ 4c:1d:59:90:4a:ef:90:16:28:1f:5a:ae:10:fb:81:50:38:0c:
++ 6c:cc:f1:3d:c3:f5:63:e3:b3:e3:21:c9:24:39:e9:fd:15:66:
++ 46:f4:1b:11:d0:4d:73:a3:7d:46:f9:3d:ed:a8:5f:62:d4:f1:
++ 3f:f8:e0:74:57:2b:18:9d:81:b4:c4:28:da:94:97:a5:70:eb:
++ ac:1d:be:07:11:f0:d5:db:dd:e5:8c:f0:d5:32:b0:83:e6:57:
++ e2:8f:bf:be:a1:aa:bf:3d:1d:b5:d4:38:ea:d7:b0:5c:3a:4f:
++ 6a:3f:8f:c0:66:6c:63:aa:e9:d9:a4:16:f4:81:d1:95:14:0e:
++ 7d:cd:95:34:d9:d2:8f:70:73:81:7b:9c:7e:bd:98:61:d8:45:
++ 87:98:90:c5:eb:86:30:c6:35:bf:f0:ff:c3:55:88:83:4b:ef:
++ 05:92:06:71:f2:b8:98:93:b7:ec:cd:82:61:f1:38:e6:4f:97:
++ 98:2a:5a:8d
++SHA1 Fingerprint=36:79:CA:35:66:87:72:30:4D:30:A5:FB:87:3B:0F:A7:7B:B7:0D:54
++-----BEGIN CERTIFICATE-----
++MIIEuTCCA6GgAwIBAgIQQBrEZCGzEyEDDrvkEhrFHTANBgkqhkiG9w0BAQsFADCB
++vTELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
++ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwOCBWZXJp
++U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MTgwNgYDVQQDEy9W
++ZXJpU2lnbiBVbml2ZXJzYWwgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAe
++Fw0wODA0MDIwMDAwMDBaFw0zNzEyMDEyMzU5NTlaMIG9MQswCQYDVQQGEwJVUzEX
++MBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0
++IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAyMDA4IFZlcmlTaWduLCBJbmMuIC0gRm9y
++IGF1dGhvcml6ZWQgdXNlIG9ubHkxODA2BgNVBAMTL1ZlcmlTaWduIFVuaXZlcnNh
++bCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG9w0BAQEF
++AAOCAQ8AMIIBCgKCAQEAx2E3XrEBNNti1xWb/1hajCMj1mCOkdeQmIN65lgZOIzF
++9uVkhbSicfvtvbnazU0AtMgtc6XHaXGVHzk8skQHnOgO+k1KxCHfKWGPMiJhgsWH
++H26MfF8WIFFE0XBPV+rjHOPMee5Y2A7Cs0WTwCznmhcrewA3ekEzeOEz4vMQGn+H
++LL729fdC4uW/h2KJXwBL38Xd5HVEMkE6HnFuacsLdUYI0crSK5XQz/u5QGtkjFdN
++/BMReYTtXlT2NJ8IAfMQJQYXStrxHXpma5hgZqTZ79IugvHw7wnqRMkVauIDbjPT
++rJ9VAMf2CGqUuV/c4DPxhGD5WycRtPwW8rtWaoAljQIDAQABo4GyMIGvMA8GA1Ud
++EwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMG0GCCsGAQUFBwEMBGEwX6FdoFsw
++WTBXMFUWCWltYWdlL2dpZjAhMB8wBwYFKw4DAhoEFI/l0xqGrI2Oa8PPgGrUSBgs
++exkuMCUWI2h0dHA6Ly9sb2dvLnZlcmlzaWduLmNvbS92c2xvZ28uZ2lmMB0GA1Ud
++DgQWBBS2d/ppSEefUxLVwuoHMnYH0ZcHGTANBgkqhkiG9w0BAQsFAAOCAQEASvj4
++sAPmLGd75JR3Y8xuTPl9Dg3cyLk1uXBPY/ok+myDjEedO2Pzmvl2MpWRsXe8rJq+
++seQxIcaBlVZaDrHC1LGmWazxY8u4TB1ZkErvkBYoH1quEPuBUDgMbMzxPcP1Y+Oz
++4yHJJDnp/RVmRvQbEdBNc6N9Rvk97ahfYtTxP/jgdFcrGJ2BtMQo2pSXpXDrrB2+
++BxHw1dvd5Yzw1TKwg+ZX4o+/vqGqvz0dtdQ46tewXDpPaj+PwGZsY6rp2aQW9IHR
++lRQOfc2VNNnSj3BzgXucfr2YYdhFh5iQxeuGMMY1v/D/w1WIg0vvBZIGcfK4mJO3
++7M2CYfE45k+XmCpajQ==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
+@@ -0,0 +1,87 @@
++##
++## Verisign Class 1 Public Primary Certification Authority - G3
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 1 (0x0)
++ Serial Number:
++ 8b:5b:75:56:84:54:85:0b:00:cf:af:38:48:ce:b1:a4
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
++ Validity
++ Not Before: Oct 1 00:00:00 1999 GMT
++ Not After : Jul 16 23:59:59 2036 GMT
++ Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:dd:84:d4:b9:b4:f9:a7:d8:f3:04:78:9c:de:3d:
++ dc:6c:13:16:d9:7a:dd:24:51:66:c0:c7:26:59:0d:
++ ac:06:08:c2:94:d1:33:1f:f0:83:35:1f:6e:1b:c8:
++ de:aa:6e:15:4e:54:27:ef:c4:6d:1a:ec:0b:e3:0e:
++ f0:44:a5:57:c7:40:58:1e:a3:47:1f:71:ec:60:f6:
++ 6d:94:c8:18:39:ed:fe:42:18:56:df:e4:4c:49:10:
++ 78:4e:01:76:35:63:12:36:dd:66:bc:01:04:36:a3:
++ 55:68:d5:a2:36:09:ac:ab:21:26:54:06:ad:3f:ca:
++ 14:e0:ac:ca:ad:06:1d:95:e2:f8:9d:f1:e0:60:ff:
++ c2:7f:75:2b:4c:cc:da:fe:87:99:21:ea:ba:fe:3e:
++ 54:d7:d2:59:78:db:3c:6e:cf:a0:13:00:1a:b8:27:
++ a1:e4:be:67:96:ca:a0:c5:b3:9c:dd:c9:75:9e:eb:
++ 30:9a:5f:a3:cd:d9:ae:78:19:3f:23:e9:5c:db:29:
++ bd:ad:55:c8:1b:54:8c:63:f6:e8:a6:ea:c7:37:12:
++ 5c:a3:29:1e:02:d9:db:1f:3b:b4:d7:0f:56:47:81:
++ 15:04:4a:af:83:27:d1:c5:58:88:c1:dd:f6:aa:a7:
++ a3:18:da:68:aa:6d:11:51:e1:bf:65:6b:9f:96:76:
++ d1:3d
++ Exponent: 65537 (0x10001)
++ Signature Algorithm: sha1WithRSAEncryption
++ ab:66:8d:d7:b3:ba:c7:9a:b6:e6:55:d0:05:f1:9f:31:8d:5a:
++ aa:d9:aa:46:26:0f:71:ed:a5:ad:53:56:62:01:47:2a:44:e9:
++ fe:3f:74:0b:13:9b:b9:f4:4d:1b:b2:d1:5f:b2:b6:d2:88:5c:
++ b3:9f:cd:cb:d4:a7:d9:60:95:84:3a:f8:c1:37:1d:61:ca:e7:
++ b0:c5:e5:91:da:54:a6:ac:31:81:ae:97:de:cd:08:ac:b8:c0:
++ 97:80:7f:6e:72:a4:e7:69:13:95:65:1f:c4:93:3c:fd:79:8f:
++ 04:d4:3e:4f:ea:f7:9e:ce:cd:67:7c:4f:65:02:ff:91:85:54:
++ 73:c7:ff:36:f7:86:2d:ec:d0:5e:4f:ff:11:9f:72:06:d6:b8:
++ 1a:f1:4c:0d:26:65:e2:44:80:1e:c7:9f:e3:dd:e8:0a:da:ec:
++ a5:20:80:69:68:a1:4f:7e:e1:6b:cf:07:41:fa:83:8e:bc:38:
++ dd:b0:2e:11:b1:6b:b2:42:cc:9a:bc:f9:48:22:79:4a:19:0f:
++ b2:1c:3e:20:74:d9:6a:c3:be:f2:28:78:13:56:79:4f:6d:50:
++ ea:1b:b0:b5:57:b1:37:66:58:23:f3:dc:0f:df:0a:87:c4:ef:
++ 86:05:d5:38:14:60:99:a3:4b:de:06:96:71:2c:f2:db:b6:1f:
++ a4:ef:3f:ee
++SHA1 Fingerprint=20:42:85:DC:F7:EB:76:41:95:57:8E:13:6B:D4:B7:D1:E9:8E:46:A5
++-----BEGIN CERTIFICATE-----
++MIIEGjCCAwICEQCLW3VWhFSFCwDPrzhIzrGkMA0GCSqGSIb3DQEBBQUAMIHKMQsw
++CQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZl
++cmlTaWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWdu
++LCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlT
++aWduIENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3Jp
++dHkgLSBHMzAeFw05OTEwMDEwMDAwMDBaFw0zNjA3MTYyMzU5NTlaMIHKMQswCQYD
++VQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlT
++aWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWduLCBJ
++bmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlTaWdu
++IENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkg
++LSBHMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAN2E1Lm0+afY8wR4
++nN493GwTFtl63SRRZsDHJlkNrAYIwpTRMx/wgzUfbhvI3qpuFU5UJ+/EbRrsC+MO
++8ESlV8dAWB6jRx9x7GD2bZTIGDnt/kIYVt/kTEkQeE4BdjVjEjbdZrwBBDajVWjV
++ojYJrKshJlQGrT/KFOCsyq0GHZXi+J3x4GD/wn91K0zM2v6HmSHquv4+VNfSWXjb
++PG7PoBMAGrgnoeS+Z5bKoMWznN3JdZ7rMJpfo83ZrngZPyPpXNspva1VyBtUjGP2
++6KbqxzcSXKMpHgLZ2x87tNcPVkeBFQRKr4Mn0cVYiMHd9qqnoxjaaKptEVHhv2Vr
++n5Z20T0CAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAq2aN17O6x5q25lXQBfGfMY1a
++qtmqRiYPce2lrVNWYgFHKkTp/j90CxObufRNG7LRX7K20ohcs5/Ny9Sn2WCVhDr4
++wTcdYcrnsMXlkdpUpqwxga6X3s0IrLjAl4B/bnKk52kTlWUfxJM8/XmPBNQ+T+r3
++ns7NZ3xPZQL/kYVUc8f/NveGLezQXk//EZ9yBta4GvFMDSZl4kSAHsef493oCtrs
++pSCAaWihT37ha88HQfqDjrw43bAuEbFrskLMmrz5SCJ5ShkPshw+IHTZasO+8ih4
++E1Z5T21Q6huwtVexN2ZYI/PcD98Kh8TvhgXVOBRgmaNL3gaWcSzy27YfpO8/7g==
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/blacklisted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
+@@ -0,0 +1,87 @@
++##
++## Verisign Class 2 Public Primary Certification Authority - G3
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 1 (0x0)
++ Serial Number:
++ 61:70:cb:49:8c:5f:98:45:29:e7:b0:a6:d9:50:5b:7a
++ Signature Algorithm: sha1WithRSAEncryption
++ Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
++ Validity
++ Not Before: Oct 1 00:00:00 1999 GMT
++ Not After : Jul 16 23:59:59 2036 GMT
++ Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (2048 bit)
++ Modulus:
++ 00:af:0a:0d:c2:d5:2c:db:67:b9:2d:e5:94:27:dd:
++ a5:be:e0:b0:4d:8f:b3:61:56:3c:d6:7c:c3:f4:cd:
++ 3e:86:cb:a2:88:e2:e1:d8:a4:69:c5:b5:e2:bf:c1:
++ a6:47:50:5e:46:39:8b:d5:96:ba:b5:6f:14:bf:10:
++ ce:27:13:9e:05:47:9b:31:7a:13:d8:1f:d9:d3:02:
++ 37:8b:ad:2c:47:f0:8e:81:06:a7:0d:30:0c:eb:f7:
++ 3c:0f:20:1d:dc:72:46:ee:a5:02:c8:5b:c3:c9:56:
++ 69:4c:c5:18:c1:91:7b:0b:d5:13:00:9b:bc:ef:c3:
++ 48:3e:46:60:20:85:2a:d5:90:b6:cd:8b:a0:cc:32:
++ dd:b7:fd:40:55:b2:50:1c:56:ae:cc:8d:77:4d:c7:
++ 20:4d:a7:31:76:ef:68:92:8a:90:1e:08:81:56:b2:
++ ad:69:a3:52:d0:cb:1c:c4:23:3d:1f:99:fe:4c:e8:
++ 16:63:8e:c6:08:8e:f6:31:f6:d2:fa:e5:76:dd:b5:
++ 1c:92:a3:49:cd:cd:01:cd:68:cd:a9:69:ba:a3:eb:
++ 1d:0d:9c:a4:20:a6:c1:a0:c5:d1:46:4c:17:6d:d2:
++ ac:66:3f:96:8c:e0:84:d4:36:ff:22:59:c5:f9:11:
++ 60:a8:5f:04:7d:f2:1a:f6:25:42:61:0f:c4:4a:b8:
++ 3e:89
++ Exponent: 65537 (0x10001)
++ Signature Algorithm: sha1WithRSAEncryption
++ 34:26:15:3c:c0:8d:4d:43:49:1d:bd:e9:21:92:d7:66:9c:b7:
++ de:c5:b8:d0:e4:5d:5f:76:22:c0:26:f9:84:3a:3a:f9:8c:b5:
++ fb:ec:60:f1:e8:ce:04:b0:c8:dd:a7:03:8f:30:f3:98:df:a4:
++ e6:a4:31:df:d3:1c:0b:46:dc:72:20:3f:ae:ee:05:3c:a4:33:
++ 3f:0b:39:ac:70:78:73:4b:99:2b:df:30:c2:54:b0:a8:3b:55:
++ a1:fe:16:28:cd:42:bd:74:6e:80:db:27:44:a7:ce:44:5d:d4:
++ 1b:90:98:0d:1e:42:94:b1:00:2c:04:d0:74:a3:02:05:22:63:
++ 63:cd:83:b5:fb:c1:6d:62:6b:69:75:fd:5d:70:41:b9:f5:bf:
++ 7c:df:be:c1:32:73:22:21:8b:58:81:7b:15:91:7a:ba:e3:64:
++ 48:b0:7f:fb:36:25:da:95:d0:f1:24:14:17:dd:18:80:6b:46:
++ 23:39:54:f5:8e:62:09:04:1d:94:90:a6:9b:e6:25:e2:42:45:
++ aa:b8:90:ad:be:08:8f:a9:0b:42:18:94:cf:72:39:e1:b1:43:
++ e0:28:cf:b7:e7:5a:6c:13:6b:49:b3:ff:e3:18:7c:89:8b:33:
++ 5d:ac:33:d7:a7:f9:da:3a:55:c9:58:10:f9:aa:ef:5a:b6:cf:
++ 4b:4b:df:2a
++SHA1 Fingerprint=61:EF:43:D7:7F:CA:D4:61:51:BC:98:E0:C3:59:12:AF:9F:EB:63:11
++-----BEGIN CERTIFICATE-----
++MIIEGTCCAwECEGFwy0mMX5hFKeewptlQW3owDQYJKoZIhvcNAQEFBQAwgcoxCzAJ
++BgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVy
++aVNpZ24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24s
++IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNp
++Z24gQ2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
++eSAtIEczMB4XDTk5MTAwMTAwMDAwMFoXDTM2MDcxNjIzNTk1OVowgcoxCzAJBgNV
++BAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVyaVNp
++Z24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24sIElu
++Yy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNpZ24g
++Q2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAt
++IEczMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArwoNwtUs22e5LeWU
++J92lvuCwTY+zYVY81nzD9M0+hsuiiOLh2KRpxbXiv8GmR1BeRjmL1Za6tW8UvxDO
++JxOeBUebMXoT2B/Z0wI3i60sR/COgQanDTAM6/c8DyAd3HJG7qUCyFvDyVZpTMUY
++wZF7C9UTAJu878NIPkZgIIUq1ZC2zYugzDLdt/1AVbJQHFauzI13TccgTacxdu9o
++koqQHgiBVrKtaaNS0MscxCM9H5n+TOgWY47GCI72MfbS+uV23bUckqNJzc0BzWjN
++qWm6o+sdDZykIKbBoMXRRkwXbdKsZj+WjOCE1Db/IlnF+RFgqF8EffIa9iVCYQ/E
++Srg+iQIDAQABMA0GCSqGSIb3DQEBBQUAA4IBAQA0JhU8wI1NQ0kdvekhktdmnLfe
++xbjQ5F1fdiLAJvmEOjr5jLX77GDx6M4EsMjdpwOPMPOY36TmpDHf0xwLRtxyID+u
++7gU8pDM/CzmscHhzS5kr3zDCVLCoO1Wh/hYozUK9dG6A2ydEp85EXdQbkJgNHkKU
++sQAsBNB0owIFImNjzYO1+8FtYmtpdf1dcEG59b98377BMnMiIYtYgXsVkXq642RI
++sH/7NiXaldDxJBQX3RiAa0YjOVT1jmIJBB2UkKab5iXiQkWquJCtvgiPqQtCGJTP
++cjnhsUPgKM+351psE2tJs//jGHyJizNdrDPXp/naOlXJWBD5qu9ats9LS98q
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/ACCVRAIZ1.pem.orig
++++ secure/caroot/trusted/ACCVRAIZ1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem.orig
++++ secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- /dev/null
++++ secure/caroot/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
+@@ -0,0 +1,69 @@
++##
++## AC RAIZ FNMT-RCM SERVIDORES SEGUROS
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 62:f6:32:6c:e5:c4:e3:68:5c:1b:62:dd:9c:2e:9d:95
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = ES, O = FNMT-RCM, OU = Ceres, organizationIdentifier = VATES-Q2826004J, CN = AC RAIZ FNMT-RCM SERVIDORES SEGUROS
++ Validity
++ Not Before: Dec 20 09:37:33 2018 GMT
++ Not After : Dec 20 09:37:33 2043 GMT
++ Subject: C = ES, O = FNMT-RCM, OU = Ceres, organizationIdentifier = VATES-Q2826004J, CN = AC RAIZ FNMT-RCM SERVIDORES SEGUROS
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:f6:ba:57:53:c8:ca:ab:df:36:4a:52:21:e4:97:
++ d2:83:67:9e:f0:65:51:d0:5e:87:c7:47:b1:59:f2:
++ 57:47:9b:00:02:93:44:17:69:db:42:c7:b1:b2:3a:
++ 18:0e:b4:5d:8c:b3:66:5d:a1:34:f9:36:2c:49:db:
++ f3:46:fc:b3:44:69:44:13:66:fd:d7:c5:fd:af:36:
++ 4d:ce:03:4d:07:71:cf:af:6a:05:d2:a2:43:5a:0a:
++ 52:6f:01:03:4e:8e:8b
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ 01:B9:2F:EF:BF:11:86:60:F2:4F:D0:41:6E:AB:73:1F:E7:D2:6E:49
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:66:02:31:00:ae:4a:e3:2b:40:c3:74:11:f2:95:ad:16:23:
++ de:4e:0c:1a:e6:5d:a5:24:5e:6b:44:7b:fc:38:e2:4f:cb:9c:
++ 45:17:11:4c:14:27:26:55:39:75:4a:03:cc:13:90:9f:92:02:
++ 31:00:fa:4a:6c:60:88:73:f3:ee:b8:98:62:a9:ce:2b:c2:d9:
++ 8a:a6:70:31:1d:af:b0:94:4c:eb:4f:c6:e3:d1:f3:62:a7:3c:
++ ff:93:2e:07:5c:49:01:67:69:12:02:72:bf:e7
++SHA1 Fingerprint=62:FF:D9:9E:C0:65:0D:03:CE:75:93:D2:ED:3F:2D:32:C9:E3:E5:4A
++-----BEGIN CERTIFICATE-----
++MIICbjCCAfOgAwIBAgIQYvYybOXE42hcG2LdnC6dlTAKBggqhkjOPQQDAzB4MQsw
++CQYDVQQGEwJFUzERMA8GA1UECgwIRk5NVC1SQ00xDjAMBgNVBAsMBUNlcmVzMRgw
++FgYDVQRhDA9WQVRFUy1RMjgyNjAwNEoxLDAqBgNVBAMMI0FDIFJBSVogRk5NVC1S
++Q00gU0VSVklET1JFUyBTRUdVUk9TMB4XDTE4MTIyMDA5MzczM1oXDTQzMTIyMDA5
++MzczM1oweDELMAkGA1UEBhMCRVMxETAPBgNVBAoMCEZOTVQtUkNNMQ4wDAYDVQQL
++DAVDZXJlczEYMBYGA1UEYQwPVkFURVMtUTI4MjYwMDRKMSwwKgYDVQQDDCNBQyBS
++QUlaIEZOTVQtUkNNIFNFUlZJRE9SRVMgU0VHVVJPUzB2MBAGByqGSM49AgEGBSuB
++BAAiA2IABPa6V1PIyqvfNkpSIeSX0oNnnvBlUdBeh8dHsVnyV0ebAAKTRBdp20LH
++sbI6GA60XYyzZl2hNPk2LEnb80b8s0RpRBNm/dfF/a82Tc4DTQdxz69qBdKiQ1oK
++Um8BA06Oi6NCMEAwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwHQYD
++VR0OBBYEFAG5L++/EYZg8k/QQW6rcx/n0m5JMAoGCCqGSM49BAMDA2kAMGYCMQCu
++SuMrQMN0EfKVrRYj3k4MGuZdpSRea0R7/DjiT8ucRRcRTBQnJlU5dUoDzBOQn5IC
++MQD6SmxgiHPz7riYYqnOK8LZiqZwMR2vsJRM60/G49HzYqc8/5MuB1xJAWdpEgJy
++v+c=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/trusted/ANF_Secure_Server_Root_CA.pem
+@@ -0,0 +1,139 @@
++##
++## ANF Secure Server Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number: 996390341000653745 (0xdd3e3bc6cf96bb1)
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: serialNumber = G63287510, C = ES, O = ANF Autoridad de Certificacion, OU = ANF CA Raiz, CN = ANF Secure Server Root CA
++ Validity
++ Not Before: Sep 4 10:00:38 2019 GMT
++ Not After : Aug 30 10:00:38 2039 GMT
++ Subject: serialNumber = G63287510, C = ES, O = ANF Autoridad de Certificacion, OU = ANF CA Raiz, CN = ANF Secure Server Root CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:db:eb:6b:2b:e6:64:54:95:82:90:a3:72:a4:19:
++ 01:9d:9c:0b:81:5f:73:49:ba:a7:ac:f3:04:4e:7b:
++ 96:0b:ec:11:e0:5b:a6:1c:ce:1b:d2:0d:83:1c:2b:
++ b8:9e:1d:7e:45:32:60:0f:07:e9:77:58:7e:9f:6a:
++ c8:61:4e:b6:26:c1:4c:8d:ff:4c:ef:34:b2:1f:65:
++ d8:b9:78:f5:ad:a9:71:b9:ef:4f:58:1d:a5:de:74:
++ 20:97:a1:ed:68:4c:de:92:17:4b:bc:ab:ff:65:9a:
++ 9e:fb:47:d9:57:72:f3:09:a1:ae:76:44:13:6e:9c:
++ 2d:44:39:bc:f9:c7:3b:a4:58:3d:41:bd:b4:c2:49:
++ a3:c8:0d:d2:97:2f:07:65:52:00:a7:6e:c8:af:68:
++ ec:f4:14:96:b6:57:1f:56:c3:39:9f:2b:6d:e4:f3:
++ 3e:f6:35:64:da:0c:1c:a1:84:4b:2f:4b:4b:e2:2c:
++ 24:9d:6d:93:40:eb:b5:23:8e:32:ca:6f:45:d3:a8:
++ 89:7b:1e:cf:1e:fa:5b:43:8b:cd:cd:a8:0f:6a:ca:
++ 0c:5e:b9:9e:47:8f:f0:d9:b6:0a:0b:58:65:17:33:
++ b9:23:e4:77:19:7d:cb:4a:2e:92:7b:4f:2f:10:77:
++ b1:8d:2f:68:9c:62:cc:e0:50:f8:ec:91:a7:54:4c:
++ 57:09:d5:76:63:c5:e8:65:1e:ee:6d:6a:cf:09:9d:
++ fa:7c:4f:ad:60:08:fd:56:99:0f:15:2c:7b:a9:80:
++ ab:8c:61:8f:4a:07:76:42:de:3d:f4:dd:b2:24:33:
++ 5b:b8:b5:a3:44:c9:ac:7f:77:3c:1d:23:ec:82:a9:
++ a6:e2:c8:06:4c:02:fe:ac:5c:99:99:0b:2f:10:8a:
++ a6:f4:7f:d5:87:74:0d:59:49:45:f6:f0:71:5c:39:
++ 29:d6:bf:4a:23:8b:f5:5f:01:63:d2:87:73:28:b5:
++ 4b:0a:f5:f8:ab:82:2c:7e:73:25:32:1d:0b:63:0a:
++ 17:81:00:ff:b6:76:5e:e7:b4:b1:40:ca:21:bb:d5:
++ 80:51:e5:48:52:67:2c:d2:61:89:07:0d:0f:ce:42:
++ 77:c0:44:73:9c:44:50:a0:db:10:0a:2d:95:1c:81:
++ af:e4:1c:e5:14:1e:f1:36:41:01:02:2f:7d:73:a7:
++ de:42:cc:4c:e9:89:0d:56:f7:9f:91:d4:03:c6:6c:
++ c9:8f:db:d8:1c:e0:40:98:5d:66:99:98:80:6e:2d:
++ ff:01:c5:ce:cb:46:1f:ac:02:c6:43:e6:ae:a2:84:
++ 3c:c5:4e:1e:3d:6d:c9:14:4c:e3:2e:41:bb:ca:39:
++ bf:36:3c:2a:19:aa:41:87:4e:a5:ce:4b:32:79:dd:
++ 90:49:7f
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Authority Key Identifier:
++ keyid:9C:5F:D0:6C:63:A3:5F:93:CA:93:98:08:AD:8C:87:A5:2C:5C:C1:37
++
++ X509v3 Subject Key Identifier:
++ 9C:5F:D0:6C:63:A3:5F:93:CA:93:98:08:AD:8C:87:A5:2C:5C:C1:37
++ X509v3 Key Usage: critical
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ Signature Algorithm: sha256WithRSAEncryption
++ 4e:1e:b9:8a:c6:a0:98:3f:6e:c3:69:c0:6a:5c:49:52:ac:cb:
++ 2b:5d:78:38:c1:d5:54:84:9f:93:f0:87:19:3d:2c:66:89:eb:
++ 0d:42:fc:cc:f0:75:85:3f:8b:f4:80:5d:79:e5:17:67:bd:35:
++ 82:e2:f2:3c:8e:7d:5b:36:cb:5a:80:00:29:f2:ce:2b:2c:f1:
++ 8f:aa:6d:05:93:6c:72:c7:56:eb:df:50:23:28:e5:45:10:3d:
++ e8:67:a3:af:0e:55:0f:90:09:62:ef:4b:59:a2:f6:53:f1:c0:
++ 35:e4:2f:c1:24:bd:79:2f:4e:20:22:3b:fd:1a:20:b0:a4:0e:
++ 2c:70:ed:74:3f:b8:13:95:06:51:c8:e8:87:26:ca:a4:5b:6a:
++ 16:21:92:dd:73:60:9e:10:18:de:3c:81:ea:e8:18:c3:7c:89:
++ f2:8b:50:3e:bd:11:e2:15:03:a8:36:7d:33:01:6c:48:15:d7:
++ 88:90:99:04:c5:cc:e6:07:f4:bc:f4:90:ed:13:e2:ea:8b:c3:
++ 8f:a3:33:0f:c1:29:4c:13:4e:da:15:56:71:73:72:82:50:f6:
++ 9a:33:7c:a2:b1:a8:1a:34:74:65:5c:ce:d1:eb:ab:53:e0:1a:
++ 80:d8:ea:3a:49:e4:26:30:9b:e5:1c:8a:a8:a9:15:32:86:99:
++ 92:0a:10:23:56:12:e0:f6:ce:4c:e2:bb:be:db:8d:92:73:01:
++ 66:2f:62:3e:b2:72:27:45:36:ed:4d:56:e3:97:99:ff:3a:35:
++ 3e:a5:54:4a:52:59:4b:60:db:ee:fe:78:11:7f:4a:dc:14:79:
++ 60:b6:6b:64:03:db:15:83:e1:a2:be:f6:23:97:50:f0:09:33:
++ 36:a7:71:96:25:f3:b9:42:7d:db:38:3f:2c:58:ac:e8:42:e1:
++ 0e:d8:d3:3b:4c:2e:82:e9:83:2e:6b:31:d9:dd:47:86:4f:6d:
++ 97:91:2e:4f:e2:28:71:35:16:d1:f2:73:fe:25:2b:07:47:24:
++ 63:27:c8:f8:f6:d9:6b:fc:12:31:56:08:c0:53:42:af:9c:d0:
++ 33:7e:fc:06:f0:31:44:03:14:f1:58:ea:f2:6a:0d:a9:11:b2:
++ 83:be:c5:1a:bf:07:ea:59:dc:a3:88:35:ef:9c:76:32:3c:4d:
++ 06:22:ce:15:e5:dd:9e:d8:8f:da:de:d2:c4:39:e5:17:81:cf:
++ 38:47:eb:7f:88:6d:59:1b:df:9f:42:14:ae:7e:cf:a8:b0:66:
++ 65:da:37:af:9f:aa:3d:ea:28:b6:de:d5:31:58:16:82:5b:ea:
++ bb:19:75:02:73:1a:ca:48:1a:21:93:90:0a:8e:93:84:a7:7d:
++ 3b:23:18:92:89:a0:8d:ac
++SHA1 Fingerprint=5B:6E:68:D0:CC:15:B6:A0:5F:1E:C1:5F:AE:02:FC:6B:2F:5D:6F:74
++-----BEGIN CERTIFICATE-----
++MIIF7zCCA9egAwIBAgIIDdPjvGz5a7EwDQYJKoZIhvcNAQELBQAwgYQxEjAQBgNV
++BAUTCUc2MzI4NzUxMDELMAkGA1UEBhMCRVMxJzAlBgNVBAoTHkFORiBBdXRvcmlk
++YWQgZGUgQ2VydGlmaWNhY2lvbjEUMBIGA1UECxMLQU5GIENBIFJhaXoxIjAgBgNV
++BAMTGUFORiBTZWN1cmUgU2VydmVyIFJvb3QgQ0EwHhcNMTkwOTA0MTAwMDM4WhcN
++MzkwODMwMTAwMDM4WjCBhDESMBAGA1UEBRMJRzYzMjg3NTEwMQswCQYDVQQGEwJF
++UzEnMCUGA1UEChMeQU5GIEF1dG9yaWRhZCBkZSBDZXJ0aWZpY2FjaW9uMRQwEgYD
++VQQLEwtBTkYgQ0EgUmFpejEiMCAGA1UEAxMZQU5GIFNlY3VyZSBTZXJ2ZXIgUm9v
++dCBDQTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANvrayvmZFSVgpCj
++cqQZAZ2cC4Ffc0m6p6zzBE57lgvsEeBbphzOG9INgxwruJ4dfkUyYA8H6XdYfp9q
++yGFOtibBTI3/TO80sh9l2Ll49a2pcbnvT1gdpd50IJeh7WhM3pIXS7yr/2WanvtH
++2Vdy8wmhrnZEE26cLUQ5vPnHO6RYPUG9tMJJo8gN0pcvB2VSAKduyK9o7PQUlrZX
++H1bDOZ8rbeTzPvY1ZNoMHKGESy9LS+IsJJ1tk0DrtSOOMspvRdOoiXsezx76W0OL
++zc2oD2rKDF65nkeP8Nm2CgtYZRczuSPkdxl9y0oukntPLxB3sY0vaJxizOBQ+OyR
++p1RMVwnVdmPF6GUe7m1qzwmd+nxPrWAI/VaZDxUse6mAq4xhj0oHdkLePfTdsiQz
++W7i1o0TJrH93PB0j7IKppuLIBkwC/qxcmZkLLxCKpvR/1Yd0DVlJRfbwcVw5Kda/
++SiOL9V8BY9KHcyi1Swr1+KuCLH5zJTIdC2MKF4EA/7Z2Xue0sUDKIbvVgFHlSFJn
++LNJhiQcND85Cd8BEc5xEUKDbEAotlRyBr+Qc5RQe8TZBAQIvfXOn3kLMTOmJDVb3
++n5HUA8ZsyY/b2BzgQJhdZpmYgG4t/wHFzstGH6wCxkPmrqKEPMVOHj1tyRRM4y5B
++u8o5vzY8KhmqQYdOpc5LMnndkEl/AgMBAAGjYzBhMB8GA1UdIwQYMBaAFJxf0Gxj
++o1+TypOYCK2Mh6UsXME3MB0GA1UdDgQWBBScX9BsY6Nfk8qTmAitjIelLFzBNzAO
++BgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOC
++AgEATh65isagmD9uw2nAalxJUqzLK114OMHVVISfk/CHGT0sZonrDUL8zPB1hT+L
++9IBdeeUXZ701guLyPI59WzbLWoAAKfLOKyzxj6ptBZNscsdW699QIyjlRRA96Gej
++rw5VD5AJYu9LWaL2U/HANeQvwSS9eS9OICI7/RogsKQOLHDtdD+4E5UGUcjohybK
++pFtqFiGS3XNgnhAY3jyB6ugYw3yJ8otQPr0R4hUDqDZ9MwFsSBXXiJCZBMXM5gf0
++vPSQ7RPi6ovDj6MzD8EpTBNO2hVWcXNyglD2mjN8orGoGjR0ZVzO0eurU+AagNjq
++OknkJjCb5RyKqKkVMoaZkgoQI1YS4PbOTOK7vtuNknMBZi9iPrJyJ0U27U1W45eZ
++/zo1PqVUSlJZS2Db7v54EX9K3BR5YLZrZAPbFYPhor72I5dQ8AkzNqdxliXzuUJ9
++2zg/LFis6ELhDtjTO0wugumDLmsx2d1Hhk9tl5EuT+IocTUW0fJz/iUrB0ckYyfI
+++PbZa/wSMVYIwFNCr5zQM378BvAxRAMU8Vjq8moNqRGyg77FGr8H6lnco4g175x2
++MjxNBiLOFeXdntiP2t7SxDnlF4HPOEfrf4htWRvfn0IUrn7PqLBmZdo3r5+qPeoo
++tt7VMVgWglvquxl1AnMaykgaIZOQCo6ThKd9OyMYkomgjaw=
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Actalis_Authentication_Root_CA.pem.orig
++++ secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/AffirmTrust_Commercial.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Commercial.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/AffirmTrust_Networking.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Networking.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/AffirmTrust_Premium.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Premium.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/AffirmTrust_Premium_ECC.pem.orig
++++ secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_1.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_2.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_3.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Amazon_Root_CA_4.pem.orig
++++ secure/caroot/trusted/Amazon_Root_CA_4.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Atos_TrustedRoot_2011.pem.orig
++++ secure/caroot/trusted/Atos_TrustedRoot_2011.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem.orig
++++ secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Baltimore_CyberTrust_Root.pem.orig
++++ secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Buypass_Class_2_Root_CA.pem.orig
++++ secure/caroot/trusted/Buypass_Class_2_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Buypass_Class_3_Root_CA.pem.orig
++++ secure/caroot/trusted/Buypass_Class_3_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/CA_Disig_Root_R2.pem.orig
++++ secure/caroot/trusted/CA_Disig_Root_R2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/CFCA_EV_ROOT.pem.orig
++++ secure/caroot/trusted/CFCA_EV_ROOT.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/COMODO_Certification_Authority.pem.orig
++++ secure/caroot/trusted/COMODO_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem.orig
++++ secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem.orig
++++ secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem.orig
++++ secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
+@@ -1,112 +0,0 @@
+-##
+-## Camerfirma Chambers of Commerce Root
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 0 (0x0)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
+- Validity
+- Not Before: Sep 30 16:13:43 2003 GMT
+- Not After : Sep 30 16:13:44 2037 GMT
+- Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:b7:36:55:e5:a5:5d:18:30:e0:da:89:54:91:fc:
+- c8:c7:52:f8:2f:50:d9:ef:b1:75:73:65:47:7d:1b:
+- 5b:ba:75:c5:fc:a1:88:24:fa:2f:ed:ca:08:4a:39:
+- 54:c4:51:7a:b5:da:60:ea:38:3c:81:b2:cb:f1:bb:
+- d9:91:23:3f:48:01:70:75:a9:05:2a:ad:1f:71:f3:
+- c9:54:3d:1d:06:6a:40:3e:b3:0c:85:ee:5c:1b:79:
+- c2:62:c4:b8:36:8e:35:5d:01:0c:23:04:47:35:aa:
+- 9b:60:4e:a0:66:3d:cb:26:0a:9c:40:a1:f4:5d:98:
+- bf:71:ab:a5:00:68:2a:ed:83:7a:0f:a2:14:b5:d4:
+- 22:b3:80:b0:3c:0c:5a:51:69:2d:58:18:8f:ed:99:
+- 9e:f1:ae:e2:95:e6:f6:47:a8:d6:0c:0f:b0:58:58:
+- db:c3:66:37:9e:9b:91:54:33:37:d2:94:1c:6a:48:
+- c9:c9:f2:a5:da:a5:0c:23:f7:23:0e:9c:32:55:5e:
+- 71:9c:84:05:51:9a:2d:fd:e6:4e:2a:34:5a:de:ca:
+- 40:37:67:0c:54:21:55:77:da:0a:0c:cc:97:ae:80:
+- dc:94:36:4a:f4:3e:ce:36:13:1e:53:e4:ac:4e:3a:
+- 05:ec:db:ae:72:9c:38:8b:d0:39:3b:89:0a:3e:77:
+- fe:75
+- Exponent: 3 (0x3)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 CRL Distribution Points:
+-
+- Full Name:
+- URI:http://crl.chambersign.org/chambersroot.crl
+-
+- X509v3 Subject Key Identifier:
+- E3:94:F5:B1:4D:E9:DB:A1:29:5B:57:8B:4D:76:06:76:E1:D1:A2:8A
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- Netscape Cert Type:
+- SSL CA, S/MIME CA, Object Signing CA
+- X509v3 Subject Alternative Name:
+- email:chambersroot@chambersign.org
+- X509v3 Issuer Alternative Name:
+- email:chambersroot@chambersign.org
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.17326.10.3.1
+- CPS: http://cps.chambersign.org/cps/chambersroot.html
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 0c:41:97:c2:1a:86:c0:22:7c:9f:fb:90:f3:1a:d1:03:b1:ef:
+- 13:f9:21:5f:04:9c:da:c9:a5:8d:27:6c:96:87:91:be:41:90:
+- 01:72:93:e7:1e:7d:5f:f6:89:c6:5d:a7:40:09:3d:ac:49:45:
+- 45:dc:2e:8d:30:68:b2:09:ba:fb:c3:2f:cc:ba:0b:df:3f:77:
+- 7b:46:7d:3a:12:24:8e:96:8f:3c:05:0a:6f:d2:94:28:1d:6d:
+- 0c:c0:2e:88:22:d5:d8:cf:1d:13:c7:f0:48:d7:d7:05:a7:cf:
+- c7:47:9e:3b:3c:34:c8:80:4f:d4:14:bb:fc:0d:50:f7:fa:b3:
+- ec:42:5f:a9:dd:6d:c8:f4:75:cf:7b:c1:72:26:b1:01:1c:5c:
+- 2c:fd:7a:4e:b4:01:c5:05:57:b9:e7:3c:aa:05:d9:88:e9:07:
+- 46:41:ce:ef:41:81:ae:58:df:83:a2:ae:ca:d7:77:1f:e7:00:
+- 3c:9d:6f:8e:e4:32:09:1d:4d:78:34:78:34:3c:94:9b:26:ed:
+- 4f:71:c6:19:7a:bd:20:22:48:5a:fe:4b:7d:03:b7:e7:58:be:
+- c6:32:4e:74:1e:68:dd:a8:68:5b:b3:3e:ee:62:7d:d9:80:e8:
+- 0a:75:7a:b7:ee:b4:65:9a:21:90:e0:aa:d0:98:bc:38:b5:73:
+- 3c:8b:f8:dc
+-SHA1 Fingerprint=6E:3A:55:A4:19:0C:19:5C:93:84:3C:C0:DB:72:2E:31:30:61:F0:B1
+------BEGIN CERTIFICATE-----
+-MIIEvTCCA6WgAwIBAgIBADANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJFVTEn
+-MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
+-ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEiMCAGA1UEAxMZQ2hhbWJlcnMg
+-b2YgQ29tbWVyY2UgUm9vdDAeFw0wMzA5MzAxNjEzNDNaFw0zNzA5MzAxNjEzNDRa
+-MH8xCzAJBgNVBAYTAkVVMScwJQYDVQQKEx5BQyBDYW1lcmZpcm1hIFNBIENJRiBB
+-ODI3NDMyODcxIzAhBgNVBAsTGmh0dHA6Ly93d3cuY2hhbWJlcnNpZ24ub3JnMSIw
+-IAYDVQQDExlDaGFtYmVycyBvZiBDb21tZXJjZSBSb290MIIBIDANBgkqhkiG9w0B
+-AQEFAAOCAQ0AMIIBCAKCAQEAtzZV5aVdGDDg2olUkfzIx1L4L1DZ77F1c2VHfRtb
+-unXF/KGIJPov7coISjlUxFF6tdpg6jg8gbLL8bvZkSM/SAFwdakFKq0fcfPJVD0d
+-BmpAPrMMhe5cG3nCYsS4No41XQEMIwRHNaqbYE6gZj3LJgqcQKH0XZi/caulAGgq
+-7YN6D6IUtdQis4CwPAxaUWktWBiP7Zme8a7ileb2R6jWDA+wWFjbw2Y3npuRVDM3
+-0pQcakjJyfKl2qUMI/cjDpwyVV5xnIQFUZot/eZOKjRa3spAN2cMVCFVd9oKDMyX
+-roDclDZK9D7ONhMeU+SsTjoF7Nuucpw4i9A5O4kKPnf+dQIBA6OCAUQwggFAMBIG
+-A1UdEwEB/wQIMAYBAf8CAQwwPAYDVR0fBDUwMzAxoC+gLYYraHR0cDovL2NybC5j
+-aGFtYmVyc2lnbi5vcmcvY2hhbWJlcnNyb290LmNybDAdBgNVHQ4EFgQU45T1sU3p
+-26EpW1eLTXYGduHRooowDgYDVR0PAQH/BAQDAgEGMBEGCWCGSAGG+EIBAQQEAwIA
+-BzAnBgNVHREEIDAegRxjaGFtYmVyc3Jvb3RAY2hhbWJlcnNpZ24ub3JnMCcGA1Ud
+-EgQgMB6BHGNoYW1iZXJzcm9vdEBjaGFtYmVyc2lnbi5vcmcwWAYDVR0gBFEwTzBN
+-BgsrBgEEAYGHLgoDATA+MDwGCCsGAQUFBwIBFjBodHRwOi8vY3BzLmNoYW1iZXJz
+-aWduLm9yZy9jcHMvY2hhbWJlcnNyb290Lmh0bWwwDQYJKoZIhvcNAQEFBQADggEB
+-AAxBl8IahsAifJ/7kPMa0QOx7xP5IV8EnNrJpY0nbJaHkb5BkAFyk+cefV/2icZd
+-p0AJPaxJRUXcLo0waLIJuvvDL8y6C98/d3tGfToSJI6WjzwFCm/SlCgdbQzALogi
+-1djPHRPH8EjX1wWnz8dHnjs8NMiAT9QUu/wNUPf6s+xCX6ndbcj0dc97wXImsQEc
+-XCz9ek60AcUFV7nnPKoF2YjpB0ZBzu9Bga5Y34OirsrXdx/nADydb47kMgkdTXg0
+-eDQ8lJsm7U9xxhl6vSAiSFr+S30Dt+dYvsYyTnQeaN2oaFuzPu5ifdmA6Ap1erfu
+-tGWaIZDgqtCYvDi1czyL+Nw=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem.orig
++++ secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem
+@@ -1,112 +0,0 @@
+-##
+-## Camerfirma Global Chambersign Root
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 0 (0x0)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
+- Validity
+- Not Before: Sep 30 16:14:18 2003 GMT
+- Not After : Sep 30 16:14:18 2037 GMT
+- Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:a2:70:a2:d0:9f:42:ae:5b:17:c7:d8:7d:cf:14:
+- 83:fc:4f:c9:a1:b7:13:af:8a:d7:9e:3e:04:0a:92:
+- 8b:60:56:fa:b4:32:2f:88:4d:a1:60:08:f4:b7:09:
+- 4e:a0:49:2f:49:d6:d3:df:9d:97:5a:9f:94:04:70:
+- ec:3f:59:d9:b7:cc:66:8b:98:52:28:09:02:df:c5:
+- 2f:84:8d:7a:97:77:bf:ec:40:9d:25:72:ab:b5:3f:
+- 32:98:fb:b7:b7:fc:72:84:e5:35:87:f9:55:fa:a3:
+- 1f:0e:6f:2e:28:dd:69:a0:d9:42:10:c6:f8:b5:44:
+- c2:d0:43:7f:db:bc:e4:a2:3c:6a:55:78:0a:77:a9:
+- d8:ea:19:32:b7:2f:fe:5c:3f:1b:ee:b1:98:ec:ca:
+- ad:7a:69:45:e3:96:0f:55:f6:e6:ed:75:ea:65:e8:
+- 32:56:93:46:89:a8:25:8a:65:06:ee:6b:bf:79:07:
+- d0:f1:b7:af:ed:2c:4d:92:bb:c0:a8:5f:a7:67:7d:
+- 04:f2:15:08:70:ac:92:d6:7d:04:d2:33:fb:4c:b6:
+- 0b:0b:fb:1a:c9:c4:8d:03:a9:7e:5c:f2:50:ab:12:
+- a5:a1:cf:48:50:a5:ef:d2:c8:1a:13:fa:b0:7f:b1:
+- 82:1c:77:6a:0f:5f:dc:0b:95:8f:ef:43:7e:e6:45:
+- 09:25
+- Exponent: 3 (0x3)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 CRL Distribution Points:
+-
+- Full Name:
+- URI:http://crl.chambersign.org/chambersignroot.crl
+-
+- X509v3 Subject Key Identifier:
+- 43:9C:36:9F:B0:9E:30:4D:C6:CE:5F:AD:10:AB:E5:03:A5:FA:A9:14
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- Netscape Cert Type:
+- SSL CA, S/MIME CA, Object Signing CA
+- X509v3 Subject Alternative Name:
+- email:chambersignroot@chambersign.org
+- X509v3 Issuer Alternative Name:
+- email:chambersignroot@chambersign.org
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.17326.10.1.1
+- CPS: http://cps.chambersign.org/cps/chambersignroot.html
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 3c:3b:70:91:f9:04:54:27:91:e1:ed:ed:fe:68:7f:61:5d:e5:
+- 41:65:4f:32:f1:18:05:94:6a:1c:de:1f:70:db:3e:7b:32:02:
+- 34:b5:0c:6c:a1:8a:7c:a5:f4:8f:ff:d4:d8:ad:17:d5:2d:04:
+- d1:3f:58:80:e2:81:59:88:be:c0:e3:46:93:24:fe:90:bd:26:
+- a2:30:2d:e8:97:26:57:35:89:74:96:18:f6:15:e2:af:24:19:
+- 56:02:02:b2:ba:0f:14:ea:c6:8a:66:c1:86:45:55:8b:be:92:
+- be:9c:a4:04:c7:49:3c:9e:e8:29:7a:89:d7:fe:af:ff:68:f5:
+- a5:17:90:bd:ac:99:cc:a5:86:57:09:67:46:db:d6:16:c2:46:
+- f1:e4:a9:50:f5:8f:d1:92:15:d3:5f:3e:c6:00:49:3a:6e:58:
+- b2:d1:d1:27:0d:25:c8:32:f8:20:11:cd:7d:32:33:48:94:54:
+- 4c:dd:dc:79:c4:30:9f:eb:8e:b8:55:b5:d7:88:5c:c5:6a:24:
+- 3d:b2:d3:05:03:51:c6:07:ef:cc:14:72:74:3d:6e:72:ce:18:
+- 28:8c:4a:a0:77:e5:09:2b:45:44:47:ac:b7:67:7f:01:8a:05:
+- 5a:93:be:a1:c1:ff:f8:e7:0e:67:a4:47:49:76:5d:75:90:1a:
+- f5:26:8f:f0
+-SHA1 Fingerprint=33:9B:6B:14:50:24:9B:55:7A:01:87:72:84:D9:E0:2F:C3:D2:D8:E9
+------BEGIN CERTIFICATE-----
+-MIIExTCCA62gAwIBAgIBADANBgkqhkiG9w0BAQUFADB9MQswCQYDVQQGEwJFVTEn
+-MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
+-ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4GA1UEAxMXR2xvYmFsIENo
+-YW1iZXJzaWduIFJvb3QwHhcNMDMwOTMwMTYxNDE4WhcNMzcwOTMwMTYxNDE4WjB9
+-MQswCQYDVQQGEwJFVTEnMCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgy
+-NzQzMjg3MSMwIQYDVQQLExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4G
+-A1UEAxMXR2xvYmFsIENoYW1iZXJzaWduIFJvb3QwggEgMA0GCSqGSIb3DQEBAQUA
+-A4IBDQAwggEIAoIBAQCicKLQn0KuWxfH2H3PFIP8T8mhtxOviteePgQKkotgVvq0
+-Mi+ITaFgCPS3CU6gSS9J1tPfnZdan5QEcOw/Wdm3zGaLmFIoCQLfxS+EjXqXd7/s
+-QJ0lcqu1PzKY+7e3/HKE5TWH+VX6ox8Oby4o3Wmg2UIQxvi1RMLQQ3/bvOSiPGpV
+-eAp3qdjqGTK3L/5cPxvusZjsyq16aUXjlg9V9ubtdepl6DJWk0aJqCWKZQbua795
+-B9Dxt6/tLE2Su8CoX6dnfQTyFQhwrJLWfQTSM/tMtgsL+xrJxI0DqX5c8lCrEqWh
+-z0hQpe/SyBoT+rB/sYIcd2oPX9wLlY/vQ37mRQklAgEDo4IBUDCCAUwwEgYDVR0T
+-AQH/BAgwBgEB/wIBDDA/BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vY3JsLmNoYW1i
+-ZXJzaWduLm9yZy9jaGFtYmVyc2lnbnJvb3QuY3JsMB0GA1UdDgQWBBRDnDafsJ4w
+-TcbOX60Qq+UDpfqpFDAOBgNVHQ8BAf8EBAMCAQYwEQYJYIZIAYb4QgEBBAQDAgAH
+-MCoGA1UdEQQjMCGBH2NoYW1iZXJzaWducm9vdEBjaGFtYmVyc2lnbi5vcmcwKgYD
+-VR0SBCMwIYEfY2hhbWJlcnNpZ25yb290QGNoYW1iZXJzaWduLm9yZzBbBgNVHSAE
+-VDBSMFAGCysGAQQBgYcuCgEBMEEwPwYIKwYBBQUHAgEWM2h0dHA6Ly9jcHMuY2hh
+-bWJlcnNpZ24ub3JnL2Nwcy9jaGFtYmVyc2lnbnJvb3QuaHRtbDANBgkqhkiG9w0B
+-AQUFAAOCAQEAPDtwkfkEVCeR4e3t/mh/YV3lQWVPMvEYBZRqHN4fcNs+ezICNLUM
+-bKGKfKX0j//U2K0X1S0E0T9YgOKBWYi+wONGkyT+kL0mojAt6JcmVzWJdJYY9hXi
+-ryQZVgICsroPFOrGimbBhkVVi76SvpykBMdJPJ7oKXqJ1/6v/2j1pReQvayZzKWG
+-VwlnRtvWFsJG8eSpUPWP0ZIV018+xgBJOm5YstHRJw0lyDL4IBHNfTIzSJRUTN3c
+-ecQwn+uOuFW114hcxWokPbLTBQNRxgfvzBRydD1ucs4YKIxKoHflCStFREest2d/
+-AYoFWpO+ocH/+OcOZ6RHSXZddZAa9SaP8A==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Certigna.pem.orig
++++ secure/caroot/trusted/Certigna.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Certigna_Root_CA.pem.orig
++++ secure/caroot/trusted/Certigna_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- /dev/null
++++ secure/caroot/trusted/Certum_EC-384_CA.pem
+@@ -0,0 +1,68 @@
++##
++## Certum EC-384 CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 78:8f:27:5c:81:12:52:20:a5:04:d0:2d:dd:ba:73:f4
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum EC-384 CA
++ Validity
++ Not Before: Mar 26 07:24:54 2018 GMT
++ Not After : Mar 26 07:24:54 2043 GMT
++ Subject: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum EC-384 CA
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:c4:28:8e:ab:18:5b:6a:be:6e:64:37:63:e4:cd:
++ ec:ab:3a:f7:cc:a1:b8:0e:82:49:d7:86:29:9f:a1:
++ 94:f2:e3:60:78:98:81:78:06:4d:f2:ec:9a:0e:57:
++ 60:83:9f:b4:e6:17:2f:1a:b3:5d:02:5b:89:23:3c:
++ c2:11:05:2a:a7:88:13:18:f3:50:84:d7:bd:34:2c:
++ 27:89:55:ff:ce:4c:e7:df:a6:1f:28:c4:f0:54:c3:
++ b9:7c:b7:53:ad:eb:c2
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 8D:06:66:74:24:76:3A:F3:89:F7:BC:D6:BD:47:7D:2F:BC:10:5F:4B
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:65:02:30:03:55:2d:a6:e6:18:c4:7c:ef:c9:50:6e:c1:27:
++ 0f:9c:87:af:6e:d5:1b:08:18:bd:92:29:c1:ef:94:91:78:d2:
++ 3a:1c:55:89:62:e5:1b:09:1e:ba:64:6b:f1:76:b4:d4:02:31:
++ 00:b4:42:84:99:ff:ab:e7:9e:fb:91:97:27:5d:dc:b0:5b:30:
++ 71:ce:5e:38:1a:6a:d9:25:e7:ea:f7:61:92:56:f8:ea:da:36:
++ c2:87:65:96:2e:72:25:2f:7f:df:c3:13:c9
++SHA1 Fingerprint=F3:3E:78:3C:AC:DF:F4:A2:CC:AC:67:55:69:56:D7:E5:16:3C:E1:ED
++-----BEGIN CERTIFICATE-----
++MIICZTCCAeugAwIBAgIQeI8nXIESUiClBNAt3bpz9DAKBggqhkjOPQQDAzB0MQsw
++CQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEgU3lzdGVtcyBTLkEuMScw
++JQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxGTAXBgNVBAMT
++EENlcnR1bSBFQy0zODQgQ0EwHhcNMTgwMzI2MDcyNDU0WhcNNDMwMzI2MDcyNDU0
++WjB0MQswCQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEgU3lzdGVtcyBT
++LkEuMScwJQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxGTAX
++BgNVBAMTEENlcnR1bSBFQy0zODQgQ0EwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAATE
++KI6rGFtqvm5kN2PkzeyrOvfMobgOgknXhimfoZTy42B4mIF4Bk3y7JoOV2CDn7Tm
++Fy8as10CW4kjPMIRBSqniBMY81CE1700LCeJVf/OTOffph8oxPBUw7l8t1Ot68Kj
++QjBAMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFI0GZnQkdjrzife81r1HfS+8
++EF9LMA4GA1UdDwEB/wQEAwIBBjAKBggqhkjOPQQDAwNoADBlAjADVS2m5hjEfO/J
++UG7BJw+ch69u1RsIGL2SKcHvlJF40jocVYli5RsJHrpka/F2tNQCMQC0QoSZ/6vn
++nvuRlydd3LBbMHHOXjgaatkl5+r3YZJW+OraNsKHZZYuciUvf9/DE8k=
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Certum_Root_CA.pem.orig
++++ secure/caroot/trusted/Certum_Root_CA.pem
+@@ -1,84 +0,0 @@
+-##
+-## Certum Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 65568 (0x10020)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
+- Validity
+- Not Before: Jun 11 10:46:39 2002 GMT
+- Not After : Jun 11 10:46:39 2027 GMT
+- Subject: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:ce:b1:c1:2e:d3:4f:7c:cd:25:ce:18:3e:4f:c4:
+- 8c:6f:80:6a:73:c8:5b:51:f8:9b:d2:dc:bb:00:5c:
+- b1:a0:fc:75:03:ee:81:f0:88:ee:23:52:e9:e6:15:
+- 33:8d:ac:2d:09:c5:76:f9:2b:39:80:89:e4:97:4b:
+- 90:a5:a8:78:f8:73:43:7b:a4:61:b0:d8:58:cc:e1:
+- 6c:66:7e:9c:f3:09:5e:55:63:84:d5:a8:ef:f3:b1:
+- 2e:30:68:b3:c4:3c:d8:ac:6e:8d:99:5a:90:4e:34:
+- dc:36:9a:8f:81:88:50:b7:6d:96:42:09:f3:d7:95:
+- 83:0d:41:4b:b0:6a:6b:f8:fc:0f:7e:62:9f:67:c4:
+- ed:26:5f:10:26:0f:08:4f:f0:a4:57:28:ce:8f:b8:
+- ed:45:f6:6e:ee:25:5d:aa:6e:39:be:e4:93:2f:d9:
+- 47:a0:72:eb:fa:a6:5b:af:ca:53:3f:e2:0e:c6:96:
+- 56:11:6e:f7:e9:66:a9:26:d8:7f:95:53:ed:0a:85:
+- 88:ba:4f:29:a5:42:8c:5e:b6:fc:85:20:00:aa:68:
+- 0b:a1:1a:85:01:9c:c4:46:63:82:88:b6:22:b1:ee:
+- fe:aa:46:59:7e:cf:35:2c:d5:b6:da:5d:f7:48:33:
+- 14:54:b6:eb:d9:6f:ce:cd:88:d6:ab:1b:da:96:3b:
+- 1d:59
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- Signature Algorithm: sha1WithRSAEncryption
+- b8:8d:ce:ef:e7:14:ba:cf:ee:b0:44:92:6c:b4:39:3e:a2:84:
+- 6e:ad:b8:21:77:d2:d4:77:82:87:e6:20:41:81:ee:e2:f8:11:
+- b7:63:d1:17:37:be:19:76:24:1c:04:1a:4c:eb:3d:aa:67:6f:
+- 2d:d4:cd:fe:65:31:70:c5:1b:a6:02:0a:ba:60:7b:6d:58:c2:
+- 9a:49:fe:63:32:0b:6b:e3:3a:c0:ac:ab:3b:b0:e8:d3:09:51:
+- 8c:10:83:c6:34:e0:c5:2b:e0:1a:b6:60:14:27:6c:32:77:8c:
+- bc:b2:72:98:cf:cd:cc:3f:b9:c8:24:42:14:d6:57:fc:e6:26:
+- 43:a9:1d:e5:80:90:ce:03:54:28:3e:f7:3f:d3:f8:4d:ed:6a:
+- 0a:3a:93:13:9b:3b:14:23:13:63:9c:3f:d1:87:27:79:e5:4c:
+- 51:e3:01:ad:85:5d:1a:3b:b1:d5:73:10:a4:d3:f2:bc:6e:64:
+- f5:5a:56:90:a8:c7:0e:4c:74:0f:2e:71:3b:f7:c8:47:f4:69:
+- 6f:15:f2:11:5e:83:1e:9c:7c:52:ae:fd:02:da:12:a8:59:67:
+- 18:db:bc:70:dd:9b:b1:69:ed:80:ce:89:40:48:6a:0e:35:ca:
+- 29:66:15:21:94:2c:e8:60:2a:9b:85:4a:40:f3:6b:8a:24:ec:
+- 06:16:2c:73
+-SHA1 Fingerprint=62:52:DC:40:F7:11:43:A2:2F:DE:9E:F7:34:8E:06:42:51:B1:81:18
+------BEGIN CERTIFICATE-----
+-MIIDDDCCAfSgAwIBAgIDAQAgMA0GCSqGSIb3DQEBBQUAMD4xCzAJBgNVBAYTAlBM
+-MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
+-QTAeFw0wMjA2MTExMDQ2MzlaFw0yNzA2MTExMDQ2MzlaMD4xCzAJBgNVBAYTAlBM
+-MRswGQYDVQQKExJVbml6ZXRvIFNwLiB6IG8uby4xEjAQBgNVBAMTCUNlcnR1bSBD
+-QTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM6xwS7TT3zNJc4YPk/E
+-jG+AanPIW1H4m9LcuwBcsaD8dQPugfCI7iNS6eYVM42sLQnFdvkrOYCJ5JdLkKWo
+-ePhzQ3ukYbDYWMzhbGZ+nPMJXlVjhNWo7/OxLjBos8Q82KxujZlakE403Daaj4GI
+-ULdtlkIJ89eVgw1BS7Bqa/j8D35in2fE7SZfECYPCE/wpFcozo+47UX2bu4lXapu
+-Ob7kky/ZR6By6/qmW6/KUz/iDsaWVhFu9+lmqSbYf5VT7QqFiLpPKaVCjF62/IUg
+-AKpoC6EahQGcxEZjgoi2IrHu/qpGWX7PNSzVttpd90gzFFS269lvzs2I1qsb2pY7
+-HVkCAwEAAaMTMBEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEA
+-uI3O7+cUus/usESSbLQ5PqKEbq24IXfS1HeCh+YgQYHu4vgRt2PRFze+GXYkHAQa
+-TOs9qmdvLdTN/mUxcMUbpgIKumB7bVjCmkn+YzILa+M6wKyrO7Do0wlRjBCDxjTg
+-xSvgGrZgFCdsMneMvLJymM/NzD+5yCRCFNZX/OYmQ6kd5YCQzgNUKD73P9P4Te1q
+-CjqTE5s7FCMTY5w/0YcneeVMUeMBrYVdGjux1XMQpNPyvG5k9VpWkKjHDkx0Dy5x
+-O/fIR/RpbxXyEV6DHpx8Uq79AtoSqFlnGNu8cN2bsWntgM6JQEhqDjXKKWYVIZQs
+-6GAqm4VKQPNriiTsBhYscw==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Certum_Trusted_Network_CA.pem.orig
++++ secure/caroot/trusted/Certum_Trusted_Network_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem.orig
++++ secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- /dev/null
++++ secure/caroot/trusted/Certum_Trusted_Root_CA.pem
+@@ -0,0 +1,136 @@
++##
++## Certum Trusted Root CA
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 1e:bf:59:50:b8:c9:80:37:4c:06:f7:eb:55:4f:b5:ed
++ Signature Algorithm: sha512WithRSAEncryption
++ Issuer: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum Trusted Root CA
++ Validity
++ Not Before: Mar 16 12:10:13 2018 GMT
++ Not After : Mar 16 12:10:13 2043 GMT
++ Subject: C = PL, O = Asseco Data Systems S.A., OU = Certum Certification Authority, CN = Certum Trusted Root CA
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:d1:2d:8e:bb:b7:36:ea:6d:37:91:9f:4e:93:a7:
++ 05:e4:29:03:25:ce:1c:82:f7:7c:99:9f:41:06:cd:
++ ed:a3:ba:c0:db:09:2c:c1:7c:df:29:7e:4b:65:2f:
++ 93:a7:d4:01:6b:03:28:18:a3:d8:9d:05:c1:2a:d8:
++ 45:f1:91:de:df:3b:d0:80:02:8c:cf:38:0f:ea:a7:
++ 5c:78:11:a4:c1:c8:85:5c:25:d3:d3:b2:e7:25:cf:
++ 11:54:97:ab:35:c0:1e:76:1c:ef:00:53:9f:39:dc:
++ 14:a5:2c:22:25:b3:72:72:fc:8d:b3:e5:3e:08:1e:
++ 14:2a:37:0b:88:3c:ca:b0:f4:c8:c2:a1:ae:bc:c1:
++ be:29:67:55:e2:fc:ad:59:5c:fe:bd:57:2c:b0:90:
++ 8d:c2:ed:37:b6:7c:99:88:b5:d5:03:9a:3d:15:0d:
++ 3d:3a:a8:a8:45:f0:95:4e:25:59:1d:cd:98:69:bb:
++ d3:cc:32:c9:8d:ef:81:fe:ad:7d:89:bb:ba:60:13:
++ ca:65:95:67:a0:f3:19:f6:03:56:d4:6a:d3:27:e2:
++ a1:ad:83:f0:4a:12:22:77:1c:05:73:e2:19:71:42:
++ c0:ec:75:46:9a:90:58:e0:6a:8e:2b:a5:46:30:04:
++ 8e:19:b2:17:e3:be:a9:ba:7f:56:f1:24:03:d7:b2:
++ 21:28:76:0e:36:30:4c:79:d5:41:9a:9a:a8:b8:35:
++ ba:0c:3a:f2:44:1b:20:88:f7:c5:25:d7:3d:c6:e3:
++ 3e:43:dd:87:fe:c4:ea:f5:53:3e:4c:65:ff:3b:4a:
++ cb:78:5a:6b:17:5f:0d:c7:c3:4f:4e:9a:2a:a2:ed:
++ 57:4d:22:e2:46:9a:3f:0f:91:34:24:7d:55:e3:8c:
++ 95:37:d3:1a:f0:09:2b:2c:d2:c9:8d:b4:0d:00:ab:
++ 67:29:28:d8:01:f5:19:04:b6:1d:be:76:fe:72:5c:
++ c4:85:ca:d2:80:41:df:05:a8:a3:d5:84:90:4f:0b:
++ f3:e0:3f:9b:19:d2:37:89:3f:f2:7b:52:1c:8c:f6:
++ e1:f7:3c:07:97:8c:0e:a2:59:81:0c:b2:90:3d:d3:
++ e3:59:46:ed:0f:a9:a7:de:80:6b:5a:aa:07:b6:19:
++ cb:bc:57:f3:97:21:7a:0c:b1:2b:74:3e:eb:da:a7:
++ 67:2d:4c:c4:98:9e:36:09:76:66:66:fc:1a:3f:ea:
++ 48:54:1c:be:30:bd:80:50:bf:7c:b5:ce:00:f6:0c:
++ 61:d9:e7:24:03:e0:e3:01:81:0e:bd:d8:85:34:88:
++ bd:b2:36:a8:7b:5c:08:e5:44:80:8c:6f:f8:2f:d5:
++ 21:ca:1d:1c:d0:fb:c4:b5:87:d1:3a:4e:c7:76:b5:
++ 35:48:b5
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 8C:FB:1C:75:BC:02:D3:9F:4E:2E:48:D9:F9:60:54:AA:C4:B3:4F:FA
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ Signature Algorithm: sha512WithRSAEncryption
++ 48:a2:d5:00:0b:2e:d0:3f:bc:1c:d5:b5:54:49:1e:5a:6b:f4:
++ e4:f2:e0:40:37:e0:cc:14:7b:b9:c9:fa:35:b5:75:17:93:6a:
++ 05:69:85:9c:cd:4f:19:78:5b:19:81:f3:63:3e:c3:ce:5b:8f:
++ f5:2f:5e:01:76:13:3f:2c:00:b9:cd:96:52:39:49:6d:04:4e:
++ c5:e9:0f:86:0d:e1:fa:b3:5f:82:12:f1:3a:ce:66:06:24:34:
++ 2b:e8:cc:ca:e7:69:dc:87:9d:c2:34:d7:79:d1:d3:77:b8:aa:
++ 59:58:fe:9d:26:fa:38:86:3e:9d:8a:87:64:57:e5:17:3a:e2:
++ f9:8d:b9:e3:33:78:c1:90:d8:b8:dd:b7:83:51:e4:c4:cc:23:
++ d5:06:7c:e6:51:d3:cd:34:31:c0:f6:46:bb:0b:ad:fc:3d:10:
++ 05:2a:3b:4a:91:25:ee:8c:d4:84:87:80:2a:bc:09:8c:aa:3a:
++ 13:5f:e8:34:79:50:c1:10:19:f9:d3:28:1e:d4:d1:51:30:29:
++ b3:ae:90:67:d6:1f:0a:63:b1:c5:a9:c6:42:31:63:17:94:ef:
++ 69:cb:2f:fa:8c:14:7d:c4:43:18:89:d9:f0:32:40:e6:80:e2:
++ 46:5f:e5:e3:c1:00:59:a8:f9:e8:20:bc:89:2c:0e:47:34:0b:
++ ea:57:c2:53:36:fc:a7:d4:af:31:cd:fe:02:e5:75:fa:b9:27:
++ 09:f9:f3:f5:3b:ca:7d:9f:a9:22:cb:88:c9:aa:d1:47:3d:36:
++ 77:a8:59:64:6b:27:cf:ef:27:c1:e3:24:b5:86:f7:ae:7e:32:
++ 4d:b0:79:68:d1:39:e8:90:58:c3:83:bc:0f:2c:d6:97:eb:ce:
++ 0c:e1:20:c7:da:b7:3e:c3:3f:bf:2f:dc:34:a4:fb:2b:21:cd:
++ 67:8f:4b:f4:e3:ea:d4:3f:e7:4f:ba:b9:a5:93:45:1c:66:1f:
++ 21:fa:64:5e:6f:e0:76:94:32:cb:75:f5:6e:e5:f6:8f:c7:b8:
++ a4:cc:a8:96:7d:64:fb:24:5a:4a:03:6c:6b:38:c6:e8:03:43:
++ 9a:f7:57:b9:b3:29:69:93:38:f4:03:f2:bb:fb:82:6b:07:20:
++ d1:52:1f:9a:64:02:7b:98:66:db:5c:4d:5a:0f:d0:84:95:a0:
++ 3c:14:43:06:ca:ca:db:b8:41:36:da:6a:44:67:87:af:af:e3:
++ 45:11:15:69:08:b2:be:16:39:97:24:6f:12:45:d1:67:5d:09:
++ a8:c9:15:da:fa:d2:a6:5f:13:61:1f:bf:85:ac:b4:ad:ad:05:
++ 94:08:83:1e:75:17:d3:71:3b:93:50:23:59:a0:ed:3c:91:54:
++ 9d:76:00:c5:c3:b8:38:db
++SHA1 Fingerprint=C8:83:44:C0:18:AE:9F:CC:F1:87:B7:8F:22:D1:C5:D7:45:84:BA:E5
++-----BEGIN CERTIFICATE-----
++MIIFwDCCA6igAwIBAgIQHr9ZULjJgDdMBvfrVU+17TANBgkqhkiG9w0BAQ0FADB6
++MQswCQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEgU3lzdGVtcyBTLkEu
++MScwJQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxHzAdBgNV
++BAMTFkNlcnR1bSBUcnVzdGVkIFJvb3QgQ0EwHhcNMTgwMzE2MTIxMDEzWhcNNDMw
++MzE2MTIxMDEzWjB6MQswCQYDVQQGEwJQTDEhMB8GA1UEChMYQXNzZWNvIERhdGEg
++U3lzdGVtcyBTLkEuMScwJQYDVQQLEx5DZXJ0dW0gQ2VydGlmaWNhdGlvbiBBdXRo
++b3JpdHkxHzAdBgNVBAMTFkNlcnR1bSBUcnVzdGVkIFJvb3QgQ0EwggIiMA0GCSqG
++SIb3DQEBAQUAA4ICDwAwggIKAoICAQDRLY67tzbqbTeRn06TpwXkKQMlzhyC93yZ
++n0EGze2jusDbCSzBfN8pfktlL5On1AFrAygYo9idBcEq2EXxkd7fO9CAAozPOA/q
++p1x4EaTByIVcJdPTsuclzxFUl6s1wB52HO8AU5853BSlLCIls3Jy/I2z5T4IHhQq
++NwuIPMqw9MjCoa68wb4pZ1Xi/K1ZXP69VyywkI3C7Te2fJmItdUDmj0VDT06qKhF
++8JVOJVkdzZhpu9PMMsmN74H+rX2Ju7pgE8pllWeg8xn2A1bUatMn4qGtg/BKEiJ3
++HAVz4hlxQsDsdUaakFjgao4rpUYwBI4Zshfjvqm6f1bxJAPXsiEodg42MEx51UGa
++mqi4NboMOvJEGyCI98Ul1z3G4z5D3Yf+xOr1Uz5MZf87Sst4WmsXXw3Hw09Omiqi
++7VdNIuJGmj8PkTQkfVXjjJU30xrwCSss0smNtA0Aq2cpKNgB9RkEth2+dv5yXMSF
++ytKAQd8FqKPVhJBPC/PgP5sZ0jeJP/J7UhyM9uH3PAeXjA6iWYEMspA90+NZRu0P
++qafegGtaqge2Gcu8V/OXIXoMsSt0Puvap2ctTMSYnjYJdmZm/Bo/6khUHL4wvYBQ
++v3y1zgD2DGHZ5yQD4OMBgQ692IU0iL2yNqh7XAjlRICMb/gv1SHKHRzQ+8S1h9E6
++Tsd2tTVItQIDAQABo0IwQDAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBSM+xx1
++vALTn04uSNn5YFSqxLNP+jAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQAD
++ggIBAEii1QALLtA/vBzVtVRJHlpr9OTy4EA34MwUe7nJ+jW1dReTagVphZzNTxl4
++WxmB82M+w85bj/UvXgF2Ez8sALnNllI5SW0ETsXpD4YN4fqzX4IS8TrOZgYkNCvo
++zMrnadyHncI013nR03e4qllY/p0m+jiGPp2Kh2RX5Rc64vmNueMzeMGQ2Ljdt4NR
++5MTMI9UGfOZR0800McD2RrsLrfw9EAUqO0qRJe6M1ISHgCq8CYyqOhNf6DR5UMEQ
++GfnTKB7U0VEwKbOukGfWHwpjscWpxkIxYxeU72nLL/qMFH3EQxiJ2fAyQOaA4kZf
++5ePBAFmo+eggvIksDkc0C+pXwlM2/KfUrzHN/gLldfq5Jwn58/U7yn2fqSLLiMmq
++0Uc9NneoWWRrJ8/vJ8HjJLWG965+Mk2weWjROeiQWMODvA8s1pfrzgzhIMfatz7D
++P78v3DSk+yshzWePS/Tj6tQ/50+6uaWTRRxmHyH6ZF5v4HaUMst19W7l9o/HuKTM
++qJZ9ZPskWkoDbGs4xugDQ5r3V7mzKWmTOPQD8rv7gmsHINFSH5pkAnuYZttcTVoP
++0ISVoDwUQwbKytu4QTbaakRnh6+v40URFWkIsr4WOZckbxJF0WddCajJFdr60qZf
++E2Efv4WstK2tBZQIgx51F9NxO5NQI1mg7TyRVJ12AMXDuDjb
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem.orig
++++ secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem
+@@ -1,152 +0,0 @@
+-##
+-## Chambers of Commerce Root - 2008
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- a3:da:42:7e:a4:b1:ae:da
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
+- Validity
+- Not Before: Aug 1 12:29:50 2008 GMT
+- Not After : Jul 31 12:29:50 2038 GMT
+- Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:af:00:cb:70:37:2b:80:5a:4a:3a:6c:78:94:7d:
+- a3:7f:1a:1f:f6:35:d5:bd:db:cb:0d:44:72:3e:26:
+- b2:90:52:ba:63:3b:28:58:6f:a5:b3:6d:94:a6:f3:
+- dd:64:0c:55:f6:f6:e7:f2:22:22:80:5e:e1:62:c6:
+- b6:29:e1:81:6c:f2:bf:e5:7d:32:6a:54:a0:32:19:
+- 59:fe:1f:8b:d7:3d:60:86:85:24:6f:e3:11:b3:77:
+- 3e:20:96:35:21:6b:b3:08:d9:70:2e:64:f7:84:92:
+- 53:d6:0e:b0:90:8a:8a:e3:87:8d:06:d3:bd:90:0e:
+- e2:99:a1:1b:86:0e:da:9a:0a:bb:0b:61:50:06:52:
+- f1:9e:7f:76:ec:cb:0f:d0:1e:0d:cf:99:30:3d:1c:
+- c4:45:10:58:ac:d6:d3:e8:d7:e5:ea:c5:01:07:77:
+- d6:51:e6:03:7f:8a:48:a5:4d:68:75:b9:e9:bc:9e:
+- 4e:19:71:f5:32:4b:9c:6d:60:19:0b:fb:cc:9d:75:
+- dc:bf:26:cd:8f:93:78:39:79:73:5e:25:0e:ca:5c:
+- eb:77:12:07:cb:64:41:47:72:93:ab:50:c3:eb:09:
+- 76:64:34:d2:39:b7:76:11:09:0d:76:45:c4:a9:ae:
+- 3d:6a:af:b5:7d:65:2f:94:58:10:ec:5c:7c:af:7e:
+- e2:b6:18:d9:d0:9b:4e:5a:49:df:a9:66:0b:cc:3c:
+- c6:78:7c:a7:9c:1d:e3:ce:8e:53:be:05:de:60:0f:
+- 6b:e5:1a:db:3f:e3:e1:21:c9:29:c1:f1:eb:07:9c:
+- 52:1b:01:44:51:3c:7b:25:d7:c4:e5:52:54:5d:25:
+- 07:ca:16:20:b8:ad:e4:41:ee:7a:08:fe:99:6f:83:
+- a6:91:02:b0:6c:36:55:6a:e7:7d:f5:96:e6:ca:81:
+- d6:97:f1:94:83:e9:ed:b0:b1:6b:12:69:1e:ac:fb:
+- 5d:a9:c5:98:e9:b4:5b:58:7a:be:3d:a2:44:3a:63:
+- 59:d4:0b:25:de:1b:4f:bd:e5:01:9e:cd:d2:29:d5:
+- 9f:17:19:0a:6f:bf:0c:90:d3:09:5f:d9:e3:8a:35:
+- cc:79:5a:4d:19:37:92:b7:c4:c1:ad:af:f4:79:24:
+- 9a:b2:01:0b:b1:af:5c:96:f3:80:32:fb:5c:3d:98:
+- f1:a0:3f:4a:de:be:af:94:2e:d9:55:9a:17:6e:60:
+- 9d:63:6c:b8:63:c9:ae:81:5c:18:35:e0:90:bb:be:
+- 3c:4f:37:22:b9:7e:eb:cf:9e:77:21:a6:3d:38:81:
+- fb:48:da:31:3d:2b:e3:89:f5:d0:b5:bd:7e:e0:50:
+- c4:12:89:b3:23:9a:10:31:85:db:ae:6f:ef:38:33:
+- 18:76:11
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 Subject Key Identifier:
+- F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
+- X509v3 Authority Key Identifier:
+- keyid:F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
+- DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Chambers of Commerce Root - 2008
+- serial:A3:DA:42:7E:A4:B1:AE:DA
+-
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Certificate Policies:
+- Policy: X509v3 Any Policy
+- CPS: http://policy.camerfirma.com
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 90:12:af:22:35:c2:a3:39:f0:2e:de:e9:b5:e9:78:7c:48:be:
+- 3f:7d:45:92:5e:e9:da:b1:19:fc:16:3c:9f:b4:5b:66:9e:6a:
+- e7:c3:b9:5d:88:e8:0f:ad:cf:23:0f:de:25:3a:5e:cc:4f:a5:
+- c1:b5:2d:ac:24:d2:58:07:de:a2:cf:69:84:60:33:e8:10:0d:
+- 13:a9:23:d0:85:e5:8e:7b:a6:9e:3d:72:13:72:33:f5:aa:7d:
+- c6:63:1f:08:f4:fe:01:7f:24:cf:2b:2c:54:09:de:e2:2b:6d:
+- 92:c6:39:4f:16:ea:3c:7e:7a:46:d4:45:6a:46:a8:eb:75:82:
+- 56:a7:ab:a0:7c:68:13:33:f6:9d:30:f0:6f:27:39:24:23:2a:
+- 90:fd:90:29:35:f2:93:df:34:a5:c6:f7:f8:ef:8c:0f:62:4a:
+- 7c:ae:d3:f5:54:f8:8d:b6:9a:56:87:16:82:3a:33:ab:5a:22:
+- 08:f7:82:ba:ea:2e:e0:47:9a:b4:b5:45:a3:05:3b:d9:dc:2e:
+- 45:40:3b:ea:dc:7f:e8:3b:eb:d1:ec:26:d8:35:a4:30:c5:3a:
+- ac:57:9e:b3:76:a5:20:7b:f9:1e:4a:05:62:01:a6:28:75:60:
+- 97:92:0d:6e:3e:4d:37:43:0d:92:15:9c:18:22:cd:51:99:a0:
+- 29:1a:3c:5f:8a:32:33:5b:30:c7:89:2f:47:98:0f:a3:03:c6:
+- f6:f1:ac:df:32:f0:d9:81:1a:e4:9c:bd:f6:80:14:f0:d1:2c:
+- b9:85:f5:d8:a3:b1:c8:a5:21:e5:1c:13:97:ee:0e:bd:df:29:
+- a9:ef:34:53:5b:d3:e4:6a:13:84:06:b6:32:02:c4:52:ae:22:
+- d2:dc:b2:21:42:1a:da:40:f0:29:c9:ec:0a:0c:5c:e2:d0:ba:
+- cc:48:d3:37:0a:cc:12:0a:8a:79:b0:3d:03:7f:69:4b:f4:34:
+- 20:7d:b3:34:ea:8e:4b:64:f5:3e:fd:b3:23:67:15:0d:04:b8:
+- f0:2d:c1:09:51:3c:b2:6c:15:f0:a5:23:d7:83:74:e4:e5:2e:
+- c9:fe:98:27:42:c6:ab:c6:9e:b0:d0:5b:38:a5:9b:50:de:7e:
+- 18:98:b5:45:3b:f6:79:b4:e8:f7:1a:7b:06:83:fb:d0:8b:da:
+- bb:c7:bd:18:ab:08:6f:3c:80:6b:40:3f:19:19:ba:65:8a:e6:
+- be:d5:5c:d3:36:d7:ef:40:52:24:60:38:67:04:31:ec:8f:f3:
+- 82:c6:de:b9:55:f3:3b:31:91:5a:dc:b5:08:15:ad:76:25:0a:
+- 0d:7b:2e:87:e2:0c:a6:06:bc:26:10:6d:37:9d:ec:dd:78:8c:
+- 7c:80:c5:f0:d9:77:48:d0
+-SHA1 Fingerprint=78:6A:74:AC:76:AB:14:7F:9C:6A:30:50:BA:9E:A8:7E:FE:9A:CE:3C
+------BEGIN CERTIFICATE-----
+-MIIHTzCCBTegAwIBAgIJAKPaQn6ksa7aMA0GCSqGSIb3DQEBBQUAMIGuMQswCQYD
+-VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
+-IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
+-MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xKTAnBgNVBAMTIENoYW1iZXJz
+-IG9mIENvbW1lcmNlIFJvb3QgLSAyMDA4MB4XDTA4MDgwMTEyMjk1MFoXDTM4MDcz
+-MTEyMjk1MFowga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpNYWRyaWQgKHNlZSBj
+-dXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29tL2FkZHJlc3MpMRIw
+-EAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVyZmlybWEgUy5BLjEp
+-MCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAtIDIwMDgwggIiMA0G
+-CSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCvAMtwNyuAWko6bHiUfaN/Gh/2NdW9
+-28sNRHI+JrKQUrpjOyhYb6WzbZSm891kDFX29ufyIiKAXuFixrYp4YFs8r/lfTJq
+-VKAyGVn+H4vXPWCGhSRv4xGzdz4gljUha7MI2XAuZPeEklPWDrCQiorjh40G072Q
+-DuKZoRuGDtqaCrsLYVAGUvGef3bsyw/QHg3PmTA9HMRFEFis1tPo1+XqxQEHd9ZR
+-5gN/ikilTWh1uem8nk4ZcfUyS5xtYBkL+8ydddy/Js2Pk3g5eXNeJQ7KXOt3EgfL
+-ZEFHcpOrUMPrCXZkNNI5t3YRCQ12RcSprj1qr7V9ZS+UWBDsXHyvfuK2GNnQm05a
+-Sd+pZgvMPMZ4fKecHePOjlO+Bd5gD2vlGts/4+EhySnB8esHnFIbAURRPHsl18Tl
+-UlRdJQfKFiC4reRB7noI/plvg6aRArBsNlVq5331lubKgdaX8ZSD6e2wsWsSaR6s
+-+12pxZjptFtYer49okQ6Y1nUCyXeG0+95QGezdIp1Z8XGQpvvwyQ0wlf2eOKNcx5
+-Wk0ZN5K3xMGtr/R5JJqyAQuxr1yW84Ay+1w9mPGgP0revq+ULtlVmhduYJ1jbLhj
+-ya6BXBg14JC7vjxPNyK5fuvPnnchpj04gftI2jE9K+OJ9dC1vX7gUMQSibMjmhAx
+-hduub+84Mxh2EQIDAQABo4IBbDCCAWgwEgYDVR0TAQH/BAgwBgEB/wIBDDAdBgNV
+-HQ4EFgQU+SSsD7K1+HnA+mCIG8TZTQKeFxkwgeMGA1UdIwSB2zCB2IAU+SSsD7K1
+-+HnA+mCIG8TZTQKeFxmhgbSkgbEwga4xCzAJBgNVBAYTAkVVMUMwQQYDVQQHEzpN
+-YWRyaWQgKHNlZSBjdXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVyZmlybWEuY29t
+-L2FkZHJlc3MpMRIwEAYDVQQFEwlBODI3NDMyODcxGzAZBgNVBAoTEkFDIENhbWVy
+-ZmlybWEgUy5BLjEpMCcGA1UEAxMgQ2hhbWJlcnMgb2YgQ29tbWVyY2UgUm9vdCAt
+-IDIwMDiCCQCj2kJ+pLGu2jAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRV
+-HSAAMCowKAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20w
+-DQYJKoZIhvcNAQEFBQADggIBAJASryI1wqM58C7e6bXpeHxIvj99RZJe6dqxGfwW
+-PJ+0W2aeaufDuV2I6A+tzyMP3iU6XsxPpcG1Lawk0lgH3qLPaYRgM+gQDROpI9CF
+-5Y57pp49chNyM/WqfcZjHwj0/gF/JM8rLFQJ3uIrbZLGOU8W6jx+ekbURWpGqOt1
+-glanq6B8aBMz9p0w8G8nOSQjKpD9kCk18pPfNKXG9/jvjA9iSnyu0/VU+I22mlaH
+-FoI6M6taIgj3grrqLuBHmrS1RaMFO9ncLkVAO+rcf+g769HsJtg1pDDFOqxXnrN2
+-pSB7+R5KBWIBpih1YJeSDW4+TTdDDZIVnBgizVGZoCkaPF+KMjNbMMeJL0eYD6MD
+-xvbxrN8y8NmBGuScvfaAFPDRLLmF9dijscilIeUcE5fuDr3fKanvNFNb0+RqE4QG
+-tjICxFKuItLcsiFCGtpA8CnJ7AoMXOLQusxI0zcKzBIKinmwPQN/aUv0NCB9szTq
+-jktk9T79syNnFQ0EuPAtwQlRPLJsFfClI9eDdOTlLsn+mCdCxqvGnrDQWzilm1De
+-fhiYtUU79nm06PcaewaD+9CL2rvHvRirCG88gGtAPxkZumWK5r7VXNM21+9AUiRg
+-OGcEMeyP84LG3rlV8zsxkVrctQgVrXYlCg17LofiDKYGvCYQbTed7N14jHyAxfDZ
+-d0jQ
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Comodo_AAA_Services_root.pem.orig
++++ secure/caroot/trusted/Comodo_AAA_Services_root.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Cybertrust_Global_Root.pem.orig
++++ secure/caroot/trusted/Cybertrust_Global_Root.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem.orig
++++ secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem
+@@ -1,101 +0,0 @@
+-##
+-## D-TRUST Root CA 3 2013
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 1039788 (0xfddac)
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
+- Validity
+- Not Before: Sep 20 08:25:51 2013 GMT
+- Not After : Sep 20 08:25:51 2028 GMT
+- Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c4:7b:42:92:82:1f:ec:ed:54:98:8e:12:c0:ca:
+- 09:df:93:6e:3a:93:5c:1b:e4:10:77:9e:4e:69:88:
+- 6c:f6:e1:69:f2:f6:9b:a2:61:b1:bd:07:20:74:98:
+- 65:f1:8c:26:08:cd:a8:35:ca:80:36:d1:63:6d:e8:
+- 44:7a:82:c3:6c:5e:de:bb:e8:36:d2:c4:68:36:8c:
+- 9f:32:bd:84:22:e0:dc:c2:ee:10:46:39:6d:af:93:
+- 39:ae:87:e6:c3:bc:09:c9:2c:6b:67:5b:d9:9b:76:
+- 75:4c:0b:e0:bb:c5:d7:bc:3e:79:f2:5f:be:d1:90:
+- 57:f9:ae:f6:66:5f:31:bf:d3:6d:8f:a7:ba:4a:f3:
+- 23:65:bb:b7:ef:a3:25:d7:0a:ea:58:b6:ef:88:fa:
+- fa:79:b2:52:58:d5:f0:ac:8c:a1:51:74:29:95:aa:
+- 51:3b:90:32:03:9f:1c:72:74:90:de:3d:ed:61:d2:
+- e5:e3:fd:64:47:e5:b9:b7:4a:a9:f7:1f:ae:96:86:
+- 04:ac:2f:e3:a4:81:77:b7:5a:16:ff:d8:0f:3f:f6:
+- b7:78:cc:a4:af:fa:5b:3c:12:5b:a8:52:89:72:ef:
+- 88:f3:d5:44:81:86:95:23:9f:7b:dd:bc:d9:34:ef:
+- 7c:94:3c:aa:c0:41:c2:e3:9d:50:1a:c0:e4:19:22:
+- fc:b3
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 3F:90:C8:7D:C7:15:6F:F3:24:8F:A9:C3:2F:4B:A2:0F:21:B2:2F:E7
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 CRL Distribution Points:
+-
+- Full Name:
+- URI:ldap://directory.d-trust.net/CN=D-TRUST%20Root%20CA%203%202013,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
+-
+- Full Name:
+- URI:http://crl.d-trust.net/crl/d-trust_root_ca_3_2013.crl
+-
+- Signature Algorithm: sha256WithRSAEncryption
+- 0e:59:0e:58:e4:74:48:23:44:cf:34:21:b5:9c:14:1a:ad:9a:
+- 4b:b7:b3:88:6d:5c:a9:17:70:f0:2a:9f:8d:7b:f9:7b:85:fa:
+- c7:39:e8:10:08:b0:35:2b:5f:cf:02:d2:d3:9c:c8:0b:1e:ee:
+- 05:54:ae:37:93:04:09:7d:6c:8f:c2:74:bc:f8:1c:94:be:31:
+- 01:40:2d:f3:24:20:b7:84:55:2c:5c:c8:f5:74:4a:10:19:8b:
+- a3:c7:ed:35:d6:09:48:d3:0e:c0:ba:39:a8:b0:46:02:b0:db:
+- c6:88:59:c2:be:fc:7b:b1:2b:cf:7e:62:87:55:96:cc:01:6f:
+- 9b:67:21:95:35:8b:f8:10:fc:71:1b:b7:4b:37:69:a6:3b:d6:
+- ec:8b:ee:c1:b0:f3:25:c9:8f:92:7d:a1:ea:c3:ca:44:bf:26:
+- a5:74:92:9c:e3:74:eb:9d:74:d9:cb:4d:87:d8:fc:b4:69:6c:
+- 8b:a0:43:07:60:78:97:e9:d9:93:7c:c2:46:bc:9b:37:52:a3:
+- ed:8a:3c:13:a9:7b:53:4b:49:9a:11:05:2c:0b:6e:56:ac:1f:
+- 2e:82:6c:e0:69:67:b5:0e:6d:2d:d9:e4:c0:15:f1:3f:fa:18:
+- 72:e1:15:6d:27:5b:2d:30:28:2b:9f:48:9a:64:2b:99:ef:f2:
+- 75:49:5f:5c
+-SHA1 Fingerprint=6C:7C:CC:E7:D4:AE:51:5F:99:08:CD:3F:F6:E8:C3:78:DF:6F:EF:97
+------BEGIN CERTIFICATE-----
+-MIIEDjCCAvagAwIBAgIDD92sMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkRF
+-MRUwEwYDVQQKDAxELVRydXN0IEdtYkgxHzAdBgNVBAMMFkQtVFJVU1QgUm9vdCBD
+-QSAzIDIwMTMwHhcNMTMwOTIwMDgyNTUxWhcNMjgwOTIwMDgyNTUxWjBFMQswCQYD
+-VQQGEwJERTEVMBMGA1UECgwMRC1UcnVzdCBHbWJIMR8wHQYDVQQDDBZELVRSVVNU
+-IFJvb3QgQ0EgMyAyMDEzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
+-xHtCkoIf7O1UmI4SwMoJ35NuOpNcG+QQd55OaYhs9uFp8vabomGxvQcgdJhl8Ywm
+-CM2oNcqANtFjbehEeoLDbF7eu+g20sRoNoyfMr2EIuDcwu4QRjltr5M5rofmw7wJ
+-ySxrZ1vZm3Z1TAvgu8XXvD558l++0ZBX+a72Zl8xv9Ntj6e6SvMjZbu376Ml1wrq
+-WLbviPr6ebJSWNXwrIyhUXQplapRO5AyA58ccnSQ3j3tYdLl4/1kR+W5t0qp9x+u
+-loYErC/jpIF3t1oW/9gPP/a3eMykr/pbPBJbqFKJcu+I89VEgYaVI5973bzZNO98
+-lDyqwEHC451QGsDkGSL8swIDAQABo4IBBTCCAQEwDwYDVR0TAQH/BAUwAwEB/zAd
+-BgNVHQ4EFgQUP5DIfccVb/Mkj6nDL0uiDyGyL+cwDgYDVR0PAQH/BAQDAgEGMIG+
+-BgNVHR8EgbYwgbMwdKByoHCGbmxkYXA6Ly9kaXJlY3RvcnkuZC10cnVzdC5uZXQv
+-Q049RC1UUlVTVCUyMFJvb3QlMjBDQSUyMDMlMjAyMDEzLE89RC1UcnVzdCUyMEdt
+-YkgsQz1ERT9jZXJ0aWZpY2F0ZXJldm9jYXRpb25saXN0MDugOaA3hjVodHRwOi8v
+-Y3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X3Jvb3RfY2FfM18yMDEzLmNybDAN
+-BgkqhkiG9w0BAQsFAAOCAQEADlkOWOR0SCNEzzQhtZwUGq2aS7eziG1cqRdw8Cqf
+-jXv5e4X6xznoEAiwNStfzwLS05zICx7uBVSuN5MECX1sj8J0vPgclL4xAUAt8yQg
+-t4RVLFzI9XRKEBmLo8ftNdYJSNMOwLo5qLBGArDbxohZwr78e7Erz35ih1WWzAFv
+-m2chlTWL+BD8cRu3SzdppjvW7IvuwbDzJcmPkn2h6sPKRL8mpXSSnON065102ctN
+-h9j8tGlsi6BDB2B4l+nZk3zCRrybN1Kj7Yo8E6l7U0tJmhEFLAtuVqwfLoJs4Gln
+-tQ5tLdnkwBXxP/oYcuEVbSdbLTAoK59ImmQrme/ydUlfXA==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem.orig
++++ secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem.orig
++++ secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DST_Root_CA_X3.pem.orig
++++ secure/caroot/trusted/DST_Root_CA_X3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem.orig
++++ secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem.orig
++++ secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem.orig
++++ secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_Global_Root_CA.pem.orig
++++ secure/caroot/trusted/DigiCert_Global_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_Global_Root_G2.pem.orig
++++ secure/caroot/trusted/DigiCert_Global_Root_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_Global_Root_G3.pem.orig
++++ secure/caroot/trusted/DigiCert_Global_Root_G3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem.orig
++++ secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem.orig
++++ secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/E-Tugra_Certification_Authority.pem.orig
++++ secure/caroot/trusted/E-Tugra_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/EC-ACC.pem.orig
++++ secure/caroot/trusted/EC-ACC.pem
+@@ -1,109 +0,0 @@
+-##
+-## EC-ACC
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- (Negative)11:d4:c2:14:2b:de:21:eb:57:9d:53:fb:0c:22:3b:ff
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
+- Validity
+- Not Before: Jan 7 23:00:00 2003 GMT
+- Not After : Jan 7 22:59:59 2031 GMT
+- Subject: C = ES, O = Agencia Catalana de Certificacio (NIF Q-0801176-I), OU = Serveis Publics de Certificacio, OU = Vegeu https://www.catcert.net/verarrel (c)03, OU = Jerarquia Entitats de Certificacio Catalanes, CN = EC-ACC
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:b3:22:c7:4f:e2:97:42:95:88:47:83:40:f6:1d:
+- 17:f3:83:73:24:1e:51:f3:98:8a:c3:92:b8:ff:40:
+- 90:05:70:87:60:c9:00:a9:b5:94:65:19:22:15:17:
+- c2:43:6c:66:44:9a:0d:04:3e:39:6f:a5:4b:7a:aa:
+- 63:b7:8a:44:9d:d9:63:91:84:66:e0:28:0f:ba:42:
+- e3:6e:8e:f7:14:27:93:69:ee:91:0e:a3:5f:0e:b1:
+- eb:66:a2:72:4f:12:13:86:65:7a:3e:db:4f:07:f4:
+- a7:09:60:da:3a:42:99:c7:b2:7f:b3:16:95:1c:c7:
+- f9:34:b5:94:85:d5:99:5e:a0:48:a0:7e:e7:17:65:
+- b8:a2:75:b8:1e:f3:e5:42:7d:af:ed:f3:8a:48:64:
+- 5d:82:14:93:d8:c0:e4:ff:b3:50:72:f2:76:f6:b3:
+- 5d:42:50:79:d0:94:3e:6b:0c:00:be:d8:6b:0e:4e:
+- 2a:ec:3e:d2:cc:82:a2:18:65:33:13:77:9e:9a:5d:
+- 1a:13:d8:c3:db:3d:c8:97:7a:ee:70:ed:a7:e6:7c:
+- db:71:cf:2d:94:62:df:6d:d6:f5:38:be:3f:a5:85:
+- 0a:19:b8:a8:d8:09:75:42:70:c4:ea:ef:cb:0e:c8:
+- 34:a8:12:22:98:0c:b8:13:94:b6:4b:ec:f0:d0:90:
+- e7:27
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Subject Alternative Name:
+- email:ec_acc@catcert.net
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Subject Key Identifier:
+- A0:C3:8B:44:AA:37:A5:45:BF:97:80:5A:D1:F1:78:A2:9B:E9:5D:8D
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.15096.1.3.1.10
+- CPS: https://www.catcert.net/verarrel
+- User Notice:
+- Explicit Text: Vegeu https://www.catcert.net/verarrel
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- a0:48:5b:82:01:f6:4d:48:b8:39:55:35:9c:80:7a:53:99:d5:
+- 5a:ff:b1:71:3b:cc:39:09:94:5e:d6:da:ef:be:01:5b:5d:d3:
+- 1e:d8:fd:7d:4f:cd:a0:41:e0:34:93:bf:cb:e2:86:9c:37:92:
+- 90:56:1c:dc:eb:29:05:e5:c4:9e:c7:35:df:8a:0c:cd:c5:21:
+- 43:e9:aa:88:e5:35:c0:19:42:63:5a:02:5e:a4:48:18:3a:85:
+- 6f:dc:9d:bc:3f:9d:9c:c1:87:b8:7a:61:08:e9:77:0b:7f:70:
+- ab:7a:dd:d9:97:2c:64:1e:85:bf:bc:74:96:a1:c3:7a:12:ec:
+- 0c:1a:6e:83:0c:3c:e8:72:46:9f:fb:48:d5:5e:97:e6:b1:a1:
+- f8:e4:ef:46:25:94:9c:89:db:69:38:be:ec:5c:0e:56:c7:65:
+- 51:e5:50:88:88:bf:42:d5:2b:3d:e5:f9:ba:9e:2e:b3:ca:f4:
+- 73:92:02:0b:be:4c:66:eb:20:fe:b9:cb:b5:99:7f:e6:b6:13:
+- fa:ca:4b:4d:d9:ee:53:46:06:3b:c6:4e:ad:93:5a:81:7e:6c:
+- 2a:4b:6a:05:45:8c:f2:21:a4:31:90:87:6c:65:9c:9d:a5:60:
+- 95:3a:52:7f:f5:d1:ab:08:6e:f3:ee:5b:f9:88:3d:7e:b8:6f:
+- 6e:03:e4:42
+-SHA1 Fingerprint=28:90:3A:63:5B:52:80:FA:E6:77:4C:0B:6D:A7:D6:BA:A6:4A:F2:E8
+------BEGIN CERTIFICATE-----
+-MIIFVjCCBD6gAwIBAgIQ7is969Qh3hSoYqwE893EATANBgkqhkiG9w0BAQUFADCB
+-8zELMAkGA1UEBhMCRVMxOzA5BgNVBAoTMkFnZW5jaWEgQ2F0YWxhbmEgZGUgQ2Vy
+-dGlmaWNhY2lvIChOSUYgUS0wODAxMTc2LUkpMSgwJgYDVQQLEx9TZXJ2ZWlzIFB1
+-YmxpY3MgZGUgQ2VydGlmaWNhY2lvMTUwMwYDVQQLEyxWZWdldSBodHRwczovL3d3
+-dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAoYykwMzE1MDMGA1UECxMsSmVyYXJxdWlh
+-IEVudGl0YXRzIGRlIENlcnRpZmljYWNpbyBDYXRhbGFuZXMxDzANBgNVBAMTBkVD
+-LUFDQzAeFw0wMzAxMDcyMzAwMDBaFw0zMTAxMDcyMjU5NTlaMIHzMQswCQYDVQQG
+-EwJFUzE7MDkGA1UEChMyQWdlbmNpYSBDYXRhbGFuYSBkZSBDZXJ0aWZpY2FjaW8g
+-KE5JRiBRLTA4MDExNzYtSSkxKDAmBgNVBAsTH1NlcnZlaXMgUHVibGljcyBkZSBD
+-ZXJ0aWZpY2FjaW8xNTAzBgNVBAsTLFZlZ2V1IGh0dHBzOi8vd3d3LmNhdGNlcnQu
+-bmV0L3ZlcmFycmVsIChjKTAzMTUwMwYDVQQLEyxKZXJhcnF1aWEgRW50aXRhdHMg
+-ZGUgQ2VydGlmaWNhY2lvIENhdGFsYW5lczEPMA0GA1UEAxMGRUMtQUNDMIIBIjAN
+-BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsyLHT+KXQpWIR4NA9h0X84NzJB5R
+-85iKw5K4/0CQBXCHYMkAqbWUZRkiFRfCQ2xmRJoNBD45b6VLeqpjt4pEndljkYRm
+-4CgPukLjbo73FCeTae6RDqNfDrHrZqJyTxIThmV6PttPB/SnCWDaOkKZx7J/sxaV
+-HMf5NLWUhdWZXqBIoH7nF2W4onW4HvPlQn2v7fOKSGRdghST2MDk/7NQcvJ29rNd
+-QlB50JQ+awwAvthrDk4q7D7SzIKiGGUzE3eeml0aE9jD2z3Il3rucO2n5nzbcc8t
+-lGLfbdb1OL4/pYUKGbio2Al1QnDE6u/LDsg0qBIimAy4E5S2S+zw0JDnJwIDAQAB
+-o4HjMIHgMB0GA1UdEQQWMBSBEmVjX2FjY0BjYXRjZXJ0Lm5ldDAPBgNVHRMBAf8E
+-BTADAQH/MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUoMOLRKo3pUW/l4Ba0fF4
+-opvpXY0wfwYDVR0gBHgwdjB0BgsrBgEEAfV4AQMBCjBlMCwGCCsGAQUFBwIBFiBo
+-dHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbDA1BggrBgEFBQcCAjApGidW
+-ZWdldSBodHRwczovL3d3dy5jYXRjZXJ0Lm5ldC92ZXJhcnJlbCAwDQYJKoZIhvcN
+-AQEFBQADggEBAKBIW4IB9k1IuDlVNZyAelOZ1Vr/sXE7zDkJlF7W2u++AVtd0x7Y
+-/X1PzaBB4DSTv8vihpw3kpBWHNzrKQXlxJ7HNd+KDM3FIUPpqojlNcAZQmNaAl6k
+-SBg6hW/cnbw/nZzBh7h6YQjpdwt/cKt63dmXLGQehb+8dJahw3oS7AwaboMMPOhy
+-Rp/7SNVel+axofjk70YllJyJ22k4vuxcDlbHZVHlUIiIv0LVKz3l+bqeLrPK9HOS
+-Agu+TGbrIP65y7WZf+a2E/rKS03Z7lNGBjvGTq2TWoF+bCpLagVFjPIhpDGQh2xl
+-nJ2lYJU6Un/10asIbvPuW/mIPX64b24D5EI=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem.orig
++++ secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem.orig
++++ secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem.orig
++++ secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- /dev/null
++++ secure/caroot/trusted/GLOBALTRUST_2020.pem
+@@ -0,0 +1,138 @@
++##
++## GLOBALTRUST 2020
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 5a:4b:bd:5a:fb:4f:8a:5b:fa:65:e5
++ Signature Algorithm: sha256WithRSAEncryption
++ Issuer: C = AT, O = e-commerce monitoring GmbH, CN = GLOBALTRUST 2020
++ Validity
++ Not Before: Feb 10 00:00:00 2020 GMT
++ Not After : Jun 10 00:00:00 2040 GMT
++ Subject: C = AT, O = e-commerce monitoring GmbH, CN = GLOBALTRUST 2020
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:ae:2e:56:ad:1b:1c:ef:f6:95:8f:a0:77:1b:2b:
++ d3:63:8f:84:4d:45:a2:0f:9f:5b:45:ab:59:7b:51:
++ 34:f9:ec:8b:8a:78:c5:dd:6b:af:bd:c4:df:93:45:
++ 1e:bf:91:38:0b:ae:0e:16:e7:41:73:f8:db:bb:d1:
++ b8:51:e0:cb:83:3b:73:38:6e:77:8a:0f:59:63:26:
++ cd:a7:2a:ce:54:fb:b8:e2:c0:7c:47:ce:60:7c:3f:
++ b2:73:f2:c0:19:b6:8a:92:87:35:0d:90:28:a2:e4:
++ 15:04:63:3e:ba:af:ee:7c:5e:cc:a6:8b:50:b2:38:
++ f7:41:63:ca:ce:ff:69:8f:68:0e:95:36:e5:cc:b9:
++ 8c:09:ca:4b:dd:31:90:96:c8:cc:1f:fd:56:96:34:
++ db:8e:1c:ea:2c:be:85:2e:63:dd:aa:a9:95:d3:fd:
++ 29:95:13:f0:c8:98:93:d9:2d:16:47:90:11:83:a2:
++ 3a:22:a2:28:57:a2:eb:fe:c0:8c:28:a0:a6:7d:e7:
++ 2a:42:3b:82:80:63:a5:63:1f:19:cc:7c:b2:66:a8:
++ c2:d3:6d:37:6f:e2:7e:06:51:d9:45:84:1f:12:ce:
++ 24:52:64:85:0b:48:80:4e:87:b1:22:22:30:aa:eb:
++ ae:be:e0:02:e0:40:e8:b0:42:80:03:51:aa:b4:7e:
++ aa:44:d7:43:61:f3:a2:6b:16:89:49:a4:a3:a4:2b:
++ 8a:02:c4:78:f4:68:8a:c1:e4:7a:36:b1:6f:1b:96:
++ 1b:77:49:8d:d4:c9:06:72:8f:cf:53:e3:dc:17:85:
++ 20:4a:dc:98:27:d3:91:26:2b:47:1e:69:07:af:de:
++ a2:e4:e4:d4:6b:0b:b3:5e:7c:d4:24:80:47:29:69:
++ 3b:6e:e8:ac:fd:40:eb:d8:ed:71:71:2b:f2:e8:58:
++ 1d:eb:41:97:22:c5:1f:d4:39:d0:27:8f:87:e3:18:
++ f4:e0:a9:46:0d:f5:74:3a:82:2e:d0:6e:2c:91:a3:
++ 31:5c:3b:46:ea:7b:04:10:56:5e:80:1d:f5:a5:65:
++ e8:82:fc:e2:07:8c:62:45:f5:20:de:46:70:86:a1:
++ bc:93:d3:1e:74:a6:6c:b0:2c:f7:03:0c:88:0c:cb:
++ d4:72:53:86:bc:60:46:f3:98:6a:c2:f1:bf:43:f9:
++ 70:20:77:ca:37:41:79:55:52:63:8d:5b:12:9f:c5:
++ 68:c4:88:9d:ac:f2:30:ab:b7:a3:31:97:67:ad:8f:
++ 17:0f:6c:c7:73:ed:24:94:6b:c8:83:9a:d0:9a:37:
++ 49:04:ab:b1:16:c8:6c:49:49:2d:ab:a1:d0:8c:92:
++ f2:41:4a:79:21:25:db:63:d7:b6:9c:a7:7e:42:69:
++ fb:3a:63
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Key Usage: critical
++ Certificate Sign, CRL Sign
++ X509v3 Subject Key Identifier:
++ DC:2E:1F:D1:61:37:79:E4:AB:D5:D5:B3:12:71:68:3D:6A:68:9C:22
++ X509v3 Authority Key Identifier:
++ keyid:DC:2E:1F:D1:61:37:79:E4:AB:D5:D5:B3:12:71:68:3D:6A:68:9C:22
++
++ Signature Algorithm: sha256WithRSAEncryption
++ 91:f0:42:02:68:40:ee:c3:68:c0:54:2f:df:ec:62:c3:c3:9e:
++ 8a:a0:31:28:aa:83:8e:a4:56:96:12:10:86:56:ba:97:72:d2:
++ 54:30:7c:ad:19:d5:1d:68:6f:fb:14:42:d8:8d:0e:f3:b5:d1:
++ a5:e3:02:42:5e:dc:e8:46:58:07:35:02:30:e0:bc:74:4a:c1:
++ 43:2a:ff:db:1a:d0:b0:af:6c:c3:fd:cb:b3:f5:7f:6d:03:2e:
++ 59:56:9d:2d:2d:35:8c:b2:d6:43:17:2c:92:0a:cb:5d:e8:8c:
++ 0f:4b:70:43:d0:82:ff:a8:cc:bf:a4:94:c0:be:87:bd:8a:e3:
++ 93:7b:c6:8f:9b:16:9d:27:65:bc:7a:c5:42:82:6c:5c:07:d0:
++ a9:c1:88:60:44:e9:98:85:16:5f:f8:8f:ca:01:10:ce:25:c3:
++ f9:60:1b:a0:c5:97:c3:d3:2c:88:31:a2:bd:30:ec:d0:d0:c0:
++ 12:f1:c1:39:e3:e5:f5:f8:d6:4a:dd:34:cd:fb:6f:c1:4f:e3:
++ 00:8b:56:e2:92:f7:28:b2:42:77:72:23:67:c7:3f:11:15:b2:
++ c4:03:05:be:bb:11:7b:0a:bf:a8:6e:e7:ff:58:43:cf:9b:67:
++ a0:80:07:b6:1d:ca:ad:6d:ea:41:11:7e:2d:74:93:fb:c2:bc:
++ be:51:44:c5:ef:68:25:27:80:e3:c8:a0:d4:12:ec:d9:a5:37:
++ 1d:37:7c:b4:91:ca:da:d4:b1:96:81:ef:68:5c:76:10:49:af:
++ 7e:a5:37:80:b1:1c:52:bd:33:81:4c:8f:f9:dd:65:d9:14:cd:
++ 8a:25:58:f4:e2:c5:83:a5:09:90:d4:6c:14:63:b5:40:df:eb:
++ c0:fc:c4:58:7e:0d:14:16:87:54:27:6e:56:e4:70:84:b8:6c:
++ 32:12:7e:82:31:43:be:d7:dd:7c:a1:ad:ae:d6:ab:20:12:ef:
++ 0a:c3:10:8c:49:96:35:dc:0b:75:5e:b1:4f:d5:4f:34:0e:11:
++ 20:07:75:43:45:e9:a3:11:da:ac:a3:99:c2:b6:79:27:e2:b9:
++ ef:c8:e2:f6:35:29:7a:74:fa:c5:7f:82:05:62:a6:0a:ea:68:
++ b2:79:47:06:6e:f2:57:a8:15:33:c6:f7:78:4a:3d:42:7b:6b:
++ 7e:fe:f7:46:ea:d1:eb:8e:ef:88:68:5b:e8:c1:d9:71:7e:fd:
++ 64:ef:ff:67:47:88:58:25:2f:3e:86:07:bd:fb:a8:e5:82:a8:
++ ac:a5:d3:69:43:cd:31:88:49:84:53:92:c0:b1:39:1b:39:83:
++ 01:30:c4:f2:a9:fa:d0:03:bd:72:37:60:56:1f:36:7c:bd:39:
++ 91:f5:6d:0d:bf:7b:d7:92
++SHA1 Fingerprint=D0:67:C1:13:51:01:0C:AA:D0:C7:6A:65:37:31:16:26:4F:53:71:A2
++-----BEGIN CERTIFICATE-----
++MIIFgjCCA2qgAwIBAgILWku9WvtPilv6ZeUwDQYJKoZIhvcNAQELBQAwTTELMAkG
++A1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9uaXRvcmluZyBHbWJIMRkw
++FwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMB4XDTIwMDIxMDAwMDAwMFoXDTQwMDYx
++MDAwMDAwMFowTTELMAkGA1UEBhMCQVQxIzAhBgNVBAoTGmUtY29tbWVyY2UgbW9u
++aXRvcmluZyBHbWJIMRkwFwYDVQQDExBHTE9CQUxUUlVTVCAyMDIwMIICIjANBgkq
++hkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAri5WrRsc7/aVj6B3GyvTY4+ETUWiD59b
++RatZe1E0+eyLinjF3WuvvcTfk0Uev5E4C64OFudBc/jbu9G4UeDLgztzOG53ig9Z
++YybNpyrOVPu44sB8R85gfD+yc/LAGbaKkoc1DZAoouQVBGM+uq/ufF7MpotQsjj3
++QWPKzv9pj2gOlTblzLmMCcpL3TGQlsjMH/1WljTbjhzqLL6FLmPdqqmV0/0plRPw
++yJiT2S0WR5ARg6I6IqIoV6Lr/sCMKKCmfecqQjuCgGOlYx8ZzHyyZqjC0203b+J+
++BlHZRYQfEs4kUmSFC0iAToexIiIwquuuvuAC4EDosEKAA1GqtH6qRNdDYfOiaxaJ
++SaSjpCuKAsR49GiKweR6NrFvG5Ybd0mN1MkGco/PU+PcF4UgStyYJ9ORJitHHmkH
++r96i5OTUawuzXnzUJIBHKWk7buis/UDr2O1xcSvy6Fgd60GXIsUf1DnQJ4+H4xj0
++4KlGDfV0OoIu0G4skaMxXDtG6nsEEFZegB31pWXogvziB4xiRfUg3kZwhqG8k9Me
++dKZssCz3AwyIDMvUclOGvGBG85hqwvG/Q/lwIHfKN0F5VVJjjVsSn8VoxIidrPIw
++q7ejMZdnrY8XD2zHc+0klGvIg5rQmjdJBKuxFshsSUktq6HQjJLyQUp5ISXbY9e2
++nKd+Qmn7OmMCAwEAAaNjMGEwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMC
++AQYwHQYDVR0OBBYEFNwuH9FhN3nkq9XVsxJxaD1qaJwiMB8GA1UdIwQYMBaAFNwu
++H9FhN3nkq9XVsxJxaD1qaJwiMA0GCSqGSIb3DQEBCwUAA4ICAQCR8EICaEDuw2jA
++VC/f7GLDw56KoDEoqoOOpFaWEhCGVrqXctJUMHytGdUdaG/7FELYjQ7ztdGl4wJC
++XtzoRlgHNQIw4Lx0SsFDKv/bGtCwr2zD/cuz9X9tAy5ZVp0tLTWMstZDFyySCstd
++6IwPS3BD0IL/qMy/pJTAvoe9iuOTe8aPmxadJ2W8esVCgmxcB9CpwYhgROmYhRZf
+++I/KARDOJcP5YBugxZfD0yyIMaK9MOzQ0MAS8cE54+X1+NZK3TTN+2/BT+MAi1bi
++kvcoskJ3ciNnxz8RFbLEAwW+uxF7Cr+obuf/WEPPm2eggAe2HcqtbepBEX4tdJP7
++wry+UUTF72glJ4DjyKDUEuzZpTcdN3y0kcra1LGWge9oXHYQSa9+pTeAsRxSvTOB
++TI/53WXZFM2KJVj04sWDpQmQ1GwUY7VA3+vA/MRYfg0UFodUJ25W5HCEuGwyEn6C
++MUO+1918oa2u1qsgEu8KwxCMSZY13At1XrFP1U80DhEgB3VDRemjEdqso5nCtnkn
++4rnvyOL2NSl6dPrFf4IFYqYK6miyeUcGbvJXqBUzxvd4Sj1Ce2t+/vdG6tHrju+I
++aFvowdlxfv1k7/9nR4hYJS8+hge9+6jlgqispdNpQ80xiEmEU5LAsTkbOYMBMMTy
++qfrQA71yN2BWHzZ8vTmR9W0Nv3vXkg==
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/GTS_Root_R1.pem.orig
++++ secure/caroot/trusted/GTS_Root_R1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GTS_Root_R2.pem.orig
++++ secure/caroot/trusted/GTS_Root_R2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GTS_Root_R3.pem.orig
++++ secure/caroot/trusted/GTS_Root_R3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GTS_Root_R4.pem.orig
++++ secure/caroot/trusted/GTS_Root_R4.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
+@@ -1,68 +0,0 @@
+-##
+-## GeoTrust Primary Certification Authority - G2
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 3c:b2:f4:48:0a:00:e2:fe:eb:24:3b:5e:60:3e:c3:6b
+- Signature Algorithm: ecdsa-with-SHA384
+- Issuer: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
+- Validity
+- Not Before: Nov 5 00:00:00 2007 GMT
+- Not After : Jan 18 23:59:59 2038 GMT
+- Subject: C = US, O = GeoTrust Inc., OU = (c) 2007 GeoTrust Inc. - For authorized use only, CN = GeoTrust Primary Certification Authority - G2
+- Subject Public Key Info:
+- Public Key Algorithm: id-ecPublicKey
+- Public-Key: (384 bit)
+- pub:
+- 04:15:b1:e8:fd:03:15:43:e5:ac:eb:87:37:11:62:
+- ef:d2:83:36:52:7d:45:57:0b:4a:8d:7b:54:3b:3a:
+- 6e:5f:15:02:c0:50:a6:cf:25:2f:7d:ca:48:b8:c7:
+- 50:63:1c:2a:21:08:7c:9a:36:d8:0b:fe:d1:26:c5:
+- 58:31:30:28:25:f3:5d:5d:a3:b8:b6:a5:b4:92:ed:
+- 6c:2c:9f:eb:dd:43:89:a2:3c:4b:48:91:1d:50:ec:
+- 26:df:d6:60:2e:bd:21
+- ASN1 OID: secp384r1
+- NIST CURVE: P-384
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Subject Key Identifier:
+- 15:5F:35:57:51:55:FB:25:B2:AD:03:69:FC:01:A3:FA:BE:11:55:D5
+- Signature Algorithm: ecdsa-with-SHA384
+- 30:64:02:30:64:96:59:a6:e8:09:de:8b:ba:fa:5a:88:88:f0:
+- 1f:91:d3:46:a8:f2:4a:4c:02:63:fb:6c:5f:38:db:2e:41:93:
+- a9:0e:e6:9d:dc:31:1c:b2:a0:a7:18:1c:79:e1:c7:36:02:30:
+- 3a:56:af:9a:74:6c:f6:fb:83:e0:33:d3:08:5f:a1:9c:c2:5b:
+- 9f:46:d6:b6:cb:91:06:63:a2:06:e7:33:ac:3e:a8:81:12:d0:
+- cb:ba:d0:92:0b:b6:9e:96:aa:04:0f:8a
+-SHA1 Fingerprint=8D:17:84:D5:37:F3:03:7D:EC:70:FE:57:8B:51:9A:99:E6:10:D7:B0
+------BEGIN CERTIFICATE-----
+-MIICrjCCAjWgAwIBAgIQPLL0SAoA4v7rJDteYD7DazAKBggqhkjOPQQDAzCBmDEL
+-MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUdlb1RydXN0IEluYy4xOTA3BgNVBAsTMChj
+-KSAyMDA3IEdlb1RydXN0IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTE2
+-MDQGA1UEAxMtR2VvVHJ1c3QgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
+-eSAtIEcyMB4XDTA3MTEwNTAwMDAwMFoXDTM4MDExODIzNTk1OVowgZgxCzAJBgNV
+-BAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMTkwNwYDVQQLEzAoYykgMjAw
+-NyBHZW9UcnVzdCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxNjA0BgNV
+-BAMTLUdlb1RydXN0IFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBH
+-MjB2MBAGByqGSM49AgEGBSuBBAAiA2IABBWx6P0DFUPlrOuHNxFi79KDNlJ9RVcL
+-So17VDs6bl8VAsBQps8lL33KSLjHUGMcKiEIfJo22Av+0SbFWDEwKCXzXV2juLal
+-tJLtbCyf691DiaI8S0iRHVDsJt/WYC69IaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAO
+-BgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFBVfNVdRVfslsq0DafwBo/q+EVXVMAoG
+-CCqGSM49BAMDA2cAMGQCMGSWWaboCd6LuvpaiIjwH5HTRqjySkwCY/tsXzjbLkGT
+-qQ7mndwxHLKgpxgceeHHNgIwOlavmnRs9vuD4DPTCF+hnMJbn0bWtsuRBmOiBucz
+-rD6ogRLQy7rQkgu2npaqBA+K
+------END CERTIFICATE-----
+--- secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem.orig
++++ secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem.orig
++++ secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem.orig
++++ secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- /dev/null
++++ secure/caroot/trusted/GlobalSign_Root_E46.pem
+@@ -0,0 +1,66 @@
++##
++## GlobalSign Root E46
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 11:d2:bb:ba:33:6e:d4:bc:e6:24:68:c5:0d:84:1d:98:e8:43
++ Signature Algorithm: ecdsa-with-SHA384
++ Issuer: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root E46
++ Validity
++ Not Before: Mar 20 00:00:00 2019 GMT
++ Not After : Mar 20 00:00:00 2046 GMT
++ Subject: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root E46
++ Subject Public Key Info:
++ Public Key Algorithm: id-ecPublicKey
++ Public-Key: (384 bit)
++ pub:
++ 04:9c:0e:b1:cf:b7:e8:9e:52:77:75:34:fa:a5:46:
++ a7:ad:32:19:32:b4:07:a9:27:ca:94:bb:0c:d2:0a:
++ 10:c7:da:89:b0:97:0c:70:13:09:01:8e:d8:ea:47:
++ ea:be:b2:80:2b:cd:fc:28:0d:db:ac:bc:a4:86:37:
++ ed:70:08:00:75:ea:93:0b:7b:2e:52:9c:23:68:23:
++ 06:43:ec:92:2f:53:84:db:fb:47:14:07:e8:5f:94:
++ 67:5d:c9:7a:81:3c:20
++ ASN1 OID: secp384r1
++ NIST CURVE: P-384
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 31:0A:90:8F:B6:C6:9D:D2:44:4B:80:B5:A2:E6:1F:B1:12:4F:1B:95
++ Signature Algorithm: ecdsa-with-SHA384
++ 30:65:02:31:00:df:54:90:ed:9b:ef:8b:94:02:93:17:82:99:
++ be:b3:9e:2c:f6:0b:91:8c:9f:4a:14:b1:f6:64:bc:bb:68:51:
++ 13:0c:03:f7:15:8b:84:60:b9:8b:ff:52:8e:e7:8c:bc:1c:02:
++ 30:3c:f9:11:d4:8c:4e:c0:c1:61:c2:15:4c:aa:ab:1d:0b:31:
++ 5f:3b:1c:e2:00:97:44:31:e6:fe:73:96:2f:da:96:d3:fe:08:
++ 07:b3:34:89:bc:05:9f:f7:1e:86:ee:8b:70
++SHA1 Fingerprint=39:B4:6C:D5:FE:80:06:EB:E2:2F:4A:BB:08:33:A0:AF:DB:B9:DD:84
++-----BEGIN CERTIFICATE-----
++MIICCzCCAZGgAwIBAgISEdK7ujNu1LzmJGjFDYQdmOhDMAoGCCqGSM49BAMDMEYx
++CzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMRwwGgYDVQQD
++ExNHbG9iYWxTaWduIFJvb3QgRTQ2MB4XDTE5MDMyMDAwMDAwMFoXDTQ2MDMyMDAw
++MDAwMFowRjELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2Ex
++HDAaBgNVBAMTE0dsb2JhbFNpZ24gUm9vdCBFNDYwdjAQBgcqhkjOPQIBBgUrgQQA
++IgNiAAScDrHPt+ieUnd1NPqlRqetMhkytAepJ8qUuwzSChDH2omwlwxwEwkBjtjq
++R+q+soArzfwoDdusvKSGN+1wCAB16pMLey5SnCNoIwZD7JIvU4Tb+0cUB+hflGdd
++yXqBPCCjQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
++DgQWBBQxCpCPtsad0kRLgLWi5h+xEk8blTAKBggqhkjOPQQDAwNoADBlAjEA31SQ
++7Zvvi5QCkxeCmb6zniz2C5GMn0oUsfZkvLtoURMMA/cVi4RguYv/Uo7njLwcAjA8
+++RHUjE7AwWHCFUyqqx0LMV87HOIAl0Qx5v5zli/altP+CAezNIm8BZ/3Hobui3A=
++-----END CERTIFICATE-----
+--- /dev/null
++++ secure/caroot/trusted/GlobalSign_Root_R46.pem
+@@ -0,0 +1,134 @@
++##
++## GlobalSign Root R46
++##
++## This is a single X.509 certificate for a public Certificate
++## Authority (CA). It was automatically extracted from Mozilla's
++## root CA list (the file `certdata.txt' in security/nss).
++##
++## It contains a certificate trusted for server authentication.
++##
++## Extracted from nss
++## with $FreeBSD$
++##
++## @generated
++##
++Certificate:
++ Data:
++ Version: 3 (0x2)
++ Serial Number:
++ 11:d2:bb:b9:d7:23:18:9e:40:5f:0a:9d:2d:d0:df:25:67:d1
++ Signature Algorithm: sha384WithRSAEncryption
++ Issuer: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root R46
++ Validity
++ Not Before: Mar 20 00:00:00 2019 GMT
++ Not After : Mar 20 00:00:00 2046 GMT
++ Subject: C = BE, O = GlobalSign nv-sa, CN = GlobalSign Root R46
++ Subject Public Key Info:
++ Public Key Algorithm: rsaEncryption
++ RSA Public-Key: (4096 bit)
++ Modulus:
++ 00:ac:ac:74:32:e8:b3:65:e5:ba:ed:43:26:1d:a6:
++ 89:0d:45:ba:29:88:b2:a4:1d:63:dd:d3:c1:2c:09:
++ 57:89:39:a1:55:e9:67:34:77:0c:6e:e4:55:1d:52:
++ 25:d2:13:6b:5e:e1:1d:a9:b7:7d:89:32:5f:0d:9e:
++ 9f:2c:7a:63:60:40:1f:a6:b0:b6:78:8f:99:54:96:
++ 08:58:ae:e4:06:bc:62:05:02:16:bf:af:a8:23:03:
++ b6:94:0f:bc:6e:6c:c2:cb:d5:a6:bb:0c:e9:f6:c1:
++ 02:fb:21:de:66:dd:17:ab:74:42:ef:f0:74:2f:25:
++ f4:ea:6b:55:5b:90:db:9d:df:5e:87:0a:40:fb:ad:
++ 19:6b:fb:f7:ca:60:88:de:da:c1:8f:d6:ae:d5:7f:
++ d4:3c:83:ee:d7:16:4c:83:45:33:6b:27:d0:86:d0:
++ 1c:2d:6b:f3:ab:7d:f1:85:a9:f5:28:d2:ad:ef:f3:
++ 84:4b:1c:87:fc:13:a3:3a:72:a2:5a:11:2b:d6:27:
++ 71:27:ed:81:2d:6d:66:81:92:87:b4:1b:58:7a:cc:
++ 3f:0a:fa:46:4f:4d:78:5c:f8:2b:48:e3:04:84:cb:
++ 5d:f6:b4:6a:b3:65:fc:42:9e:51:26:23:20:cb:3d:
++ 14:f9:81:ed:65:16:00:4f:1a:64:97:66:08:cf:8c:
++ 7b:e3:2b:c0:9d:f9:14:f2:1b:f1:56:6a:16:bf:2c:
++ 85:85:cd:78:38:9a:eb:42:6a:02:34:18:83:17:4e:
++ 94:56:f8:b6:82:b5:f3:96:dd:3d:f3:be:7f:20:77:
++ 3e:7b:19:23:6b:2c:d4:72:73:43:57:7d:e0:f8:d7:
++ 69:4f:17:36:04:f9:c0:90:60:37:45:de:e6:0c:d8:
++ 74:8d:ae:9c:a2:6d:74:5d:42:be:06:f5:d9:64:6e:
++ 02:10:ac:89:b0:4c:3b:07:4d:40:7e:24:c5:8a:98:
++ 82:79:8e:a4:a7:82:20:8d:23:fa:27:71:c9:df:c6:
++ 41:74:a0:4d:f6:91:16:dc:46:8c:5f:29:63:31:59:
++ 71:0c:d8:6f:c2:b6:32:7d:fb:e6:5d:53:a6:7e:15:
++ fc:bb:75:7c:5d:ec:f8:f6:17:1c:ec:c7:6b:19:cb:
++ f3:7b:f0:2b:07:a5:d9:6c:79:54:76:6c:9d:1c:a6:
++ 6e:0e:e9:79:0c:a8:23:6a:a3:df:1b:30:31:9f:b1:
++ 54:7b:fe:6a:cb:66:aa:dc:65:d0:a2:9e:4a:9a:07:
++ 21:6b:81:8f:db:c4:59:fa:de:22:c0:04:9c:e3:aa:
++ 5b:36:93:e8:3d:bd:7a:a1:9d:0b:76:b1:0b:c7:9d:
++ fd:cf:98:a8:06:c2:f8:2a:a3:a1:83:a0:b7:25:72:
++ a5:02:e3
++ Exponent: 65537 (0x10001)
++ X509v3 extensions:
++ X509v3 Key Usage: critical
++ Digital Signature, Certificate Sign, CRL Sign
++ X509v3 Basic Constraints: critical
++ CA:TRUE
++ X509v3 Subject Key Identifier:
++ 03:5C:AB:73:81:87:A8:CC:B0:A6:D5:94:E2:36:96:49:FF:05:99:2C
++ Signature Algorithm: sha384WithRSAEncryption
++ 7c:78:ec:f6:02:2c:bb:5b:7e:92:2b:5d:39:dc:be:d8:1d:a2:
++ 42:33:4d:f9:ef:a4:2a:3b:44:69:1e:ac:d9:45:a3:4e:3c:a7:
++ d8:24:51:b2:54:1c:93:4e:c4:ef:7b:93:85:60:26:ea:09:48:
++ e0:f5:bb:c7:e9:68:d2:bb:6a:31:71:cc:79:ae:11:a8:f0:99:
++ fd:e5:1f:bc:2f:a8:cc:57:eb:76:c4:21:a6:47:53:55:4d:68:
++ bf:05:a4:ee:d7:26:ab:62:da:43:37:4b:e2:c6:b5:e5:b2:83:
++ 19:3a:c7:d3:db:4d:9e:08:7a:f3:ee:cf:3e:62:fb:ac:e8:60:
++ cc:d1:c7:a1:5c:83:45:c4:45:cc:f3:17:6b:14:c9:04:02:3e:
++ d2:24:a6:79:e9:1e:ce:a2:e7:c1:59:15:9f:1d:e2:4b:9a:3e:
++ 9f:76:08:2d:6b:d8:ba:57:14:da:83:ea:fe:8c:55:e9:d0:4e:
++ a9:cc:77:31:b1:44:11:7a:5c:b1:3e:d3:14:45:15:18:62:24:
++ 13:d2:cb:4d:ce:5c:83:c1:36:f2:10:b5:0e:88:6d:b8:e1:56:
++ 9f:89:de:96:66:39:47:64:2c:6e:4d:ae:62:7b:bf:60:74:19:
++ b8:56:ac:92:ac:16:32:ed:ad:68:55:fe:98:ba:d3:34:de:f4:
++ c9:61:c3:0e:86:f6:4b:84:60:ee:0d:7b:b5:32:58:79:91:55:
++ 2c:81:43:b3:74:1f:7a:aa:25:9e:1d:d7:a1:8b:b9:cd:42:2e:
++ 04:a4:66:83:4d:89:35:b6:6c:a8:36:4a:79:21:78:22:d0:42:
++ bc:d1:40:31:90:a1:be:04:cf:ca:67:ed:f5:f0:80:d3:60:c9:
++ 83:2a:22:05:d0:07:3b:52:bf:0c:9e:aa:2b:f9:bb:e6:1f:8f:
++ 25:ba:85:8d:17:1e:02:fe:5d:50:04:57:cf:fe:2d:bc:ef:5c:
++ c0:1a:ab:b6:9f:24:c6:df:73:68:48:90:2c:14:f4:3f:52:1a:
++ e4:d2:cb:14:c3:61:69:cf:e2:f9:18:c5:ba:33:9f:14:a3:04:
++ 5d:b9:71:f7:b5:94:d8:f6:33:c1:5a:c1:34:8b:7c:9b:dd:93:
++ 3a:e7:13:a2:70:61:9f:af:8f:eb:d8:c5:75:f8:33:66:d4:74:
++ 67:3a:37:77:9c:e7:dd:a4:0f:76:43:66:8a:43:f2:9f:fb:0c:
++ 42:78:63:d1:e2:0f:6f:7b:d4:a1:3d:74:97:85:b7:48:39:41:
++ d6:20:fc:d0:3a:b3:fa:e8:6f:c4:8a:ba:71:37:be:8b:97:b1:
++ 78:31:4f:b3:e7:b6:03:13:ce:54:9d:ae:25:59:cc:7f:35:5f:
++ 08:f7:40:45:31:78:2a:7a
++SHA1 Fingerprint=53:A2:B0:4B:CA:6B:D6:45:E6:39:8A:8E:C4:0D:D2:BF:77:C3:A2:90
++-----BEGIN CERTIFICATE-----
++MIIFWjCCA0KgAwIBAgISEdK7udcjGJ5AXwqdLdDfJWfRMA0GCSqGSIb3DQEBDAUA
++MEYxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMRwwGgYD
++VQQDExNHbG9iYWxTaWduIFJvb3QgUjQ2MB4XDTE5MDMyMDAwMDAwMFoXDTQ2MDMy
++MDAwMDAwMFowRjELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYt
++c2ExHDAaBgNVBAMTE0dsb2JhbFNpZ24gUm9vdCBSNDYwggIiMA0GCSqGSIb3DQEB
++AQUAA4ICDwAwggIKAoICAQCsrHQy6LNl5brtQyYdpokNRbopiLKkHWPd08EsCVeJ
++OaFV6Wc0dwxu5FUdUiXSE2te4R2pt32JMl8Nnp8semNgQB+msLZ4j5lUlghYruQG
++vGIFAha/r6gjA7aUD7xubMLL1aa7DOn2wQL7Id5m3RerdELv8HQvJfTqa1VbkNud
++316HCkD7rRlr+/fKYIje2sGP1q7Vf9Q8g+7XFkyDRTNrJ9CG0Bwta/OrffGFqfUo
++0q3v84RLHIf8E6M6cqJaESvWJ3En7YEtbWaBkoe0G1h6zD8K+kZPTXhc+CtI4wSE
++y132tGqzZfxCnlEmIyDLPRT5ge1lFgBPGmSXZgjPjHvjK8Cd+RTyG/FWaha/LIWF
++zXg4mutCagI0GIMXTpRW+LaCtfOW3T3zvn8gdz57GSNrLNRyc0NXfeD412lPFzYE
+++cCQYDdF3uYM2HSNrpyibXRdQr4G9dlkbgIQrImwTDsHTUB+JMWKmIJ5jqSngiCN
++I/onccnfxkF0oE32kRbcRoxfKWMxWXEM2G/CtjJ9++ZdU6Z+Ffy7dXxd7Pj2Fxzs
++x2sZy/N78CsHpdlseVR2bJ0cpm4O6XkMqCNqo98bMDGfsVR7/mrLZqrcZdCinkqa
++ByFrgY/bxFn63iLABJzjqls2k+g9vXqhnQt2sQvHnf3PmKgGwvgqo6GDoLclcqUC
++4wIDAQABo0IwQDAOBgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
++HQ4EFgQUA1yrc4GHqMywptWU4jaWSf8FmSwwDQYJKoZIhvcNAQEMBQADggIBAHx4
++7PYCLLtbfpIrXTncvtgdokIzTfnvpCo7RGkerNlFo048p9gkUbJUHJNOxO97k4Vg
++JuoJSOD1u8fpaNK7ajFxzHmuEajwmf3lH7wvqMxX63bEIaZHU1VNaL8FpO7XJqti
++2kM3S+LGteWygxk6x9PbTZ4IevPuzz5i+6zoYMzRx6Fcg0XERczzF2sUyQQCPtIk
++pnnpHs6i58FZFZ8d4kuaPp92CC1r2LpXFNqD6v6MVenQTqnMdzGxRBF6XLE+0xRF
++FRhiJBPSy03OXIPBNvIQtQ6IbbjhVp+J3pZmOUdkLG5NrmJ7v2B0GbhWrJKsFjLt
++rWhV/pi60zTe9Mlhww6G9kuEYO4Ne7UyWHmRVSyBQ7N0H3qqJZ4d16GLuc1CLgSk
++ZoNNiTW2bKg2SnkheCLQQrzRQDGQob4Ez8pn7fXwgNNgyYMqIgXQBztSvwyeqiv5
++u+YfjyW6hY0XHgL+XVAEV8/+LbzvXMAaq7afJMbfc2hIkCwU9D9SGuTSyxTDYWnP
++4vkYxboznxSjBF25cfe1lNj2M8FawTSLfJvdkzrnE6JwYZ+vj+vYxXX4M2bUdGc6
++N3ec592kD3ZDZopD8p/7DEJ4Y9HiD2971KE9dJeFt0g5QdYg/NA6s/rob8SKunE3
++vouXsXgxT7PntgMTzlSdriVZzH81Xwj3QEUxeCp6
++-----END CERTIFICATE-----
+--- secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem.orig
++++ secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem
+@@ -1,151 +0,0 @@
+-##
+-## Global Chambersign Root - 2008
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- c9:cd:d3:e9:d5:7d:23:ce
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
+- Validity
+- Not Before: Aug 1 12:31:40 2008 GMT
+- Not After : Jul 31 12:31:40 2038 GMT
+- Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Global Chambersign Root - 2008
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:c0:df:56:d3:e4:3a:9b:76:45:b4:13:db:ff:c1:
+- b6:19:8b:37:41:18:95:52:47:eb:17:9d:29:88:8e:
+- 35:6c:06:32:2e:47:62:f3:49:04:bf:7d:44:36:b1:
+- 71:cc:bd:5a:09:73:d5:d9:85:44:ff:91:57:25:df:
+- 5e:36:8e:70:d1:5c:71:43:1d:d9:da:ef:5c:d2:fb:
+- 1b:bd:3a:b5:cb:ad:a3:cc:44:a7:0d:ae:21:15:3f:
+- b9:7a:5b:92:75:d8:a4:12:38:89:19:8a:b7:80:d2:
+- e2:32:6f:56:9c:91:d6:88:10:0b:b3:74:64:92:74:
+- 60:f3:f6:cf:18:4f:60:b2:23:d0:c7:3b:ce:61:4b:
+- 99:8f:c2:0c:d0:40:b2:98:dc:0d:a8:4e:a3:b9:0a:
+- ae:60:a0:ad:45:52:63:ba:66:bd:68:e0:f9:be:1a:
+- a8:81:bb:1e:41:78:75:d3:c1:fe:00:55:b0:87:54:
+- e8:27:90:35:1d:4c:33:ad:97:fc:97:2e:98:84:bf:
+- 2c:c9:a3:bf:d1:98:11:14:ed:63:f8:ca:98:88:58:
+- 17:99:ed:45:03:97:7e:3c:86:1e:88:8c:be:f2:91:
+- 84:8f:65:34:d8:00:4c:7d:b7:31:17:5a:29:7a:0a:
+- 18:24:30:a3:37:b5:7a:a9:01:7d:26:d6:f9:0e:8e:
+- 59:f1:fd:1b:33:b5:29:3b:17:3b:41:b6:21:dd:d4:
+- c0:3d:a5:9f:9f:1f:43:50:c9:bb:bc:6c:7a:97:98:
+- ee:cd:8c:1f:fb:9c:51:ae:8b:70:bd:27:9f:71:c0:
+- 6b:ac:7d:90:66:e8:d7:5d:3a:0d:b0:d5:c2:8d:d5:
+- c8:9d:9d:c1:6d:d0:d0:bf:51:e4:e3:f8:c3:38:36:
+- ae:d6:a7:75:e6:af:84:43:5d:93:92:0c:6a:07:de:
+- 3b:1d:98:22:d6:ac:c1:35:db:a3:a0:25:ff:72:b5:
+- 76:1d:de:6d:e9:2c:66:2c:52:84:d0:45:92:ce:1c:
+- e5:e5:33:1d:dc:07:53:54:a3:aa:82:3b:9a:37:2f:
+- dc:dd:a0:64:e9:e6:dd:bd:ae:fc:64:85:1d:3c:a7:
+- c9:06:de:84:ff:6b:e8:6b:1a:3c:c5:a2:b3:42:fb:
+- 8b:09:3e:5f:08:52:c7:62:c4:d4:05:71:bf:c4:64:
+- e4:f8:a1:83:e8:3e:12:9b:a8:1e:d4:36:4d:2f:71:
+- f6:8d:28:f6:83:a9:13:d2:61:c1:91:bb:48:c0:34:
+- 8f:41:8c:4b:4c:db:69:12:ff:50:94:9c:20:83:59:
+- 73:ed:7c:a1:f2:f1:fd:dd:f7:49:d3:43:58:a0:56:
+- 63:ca:3d:3d:e5:35:56:59:e9:0e:ca:20:cc:2b:4b:
+- 93:29:0f
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE, pathlen:12
+- X509v3 Subject Key Identifier:
+- B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
+- X509v3 Authority Key Identifier:
+- keyid:B9:09:CA:9C:1E:DB:D3:6C:3A:6B:AE:ED:54:F1:5B:93:06:35:2E:5E
+- DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Global Chambersign Root - 2008
+- serial:C9:CD:D3:E9:D5:7D:23:CE
+-
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Certificate Policies:
+- Policy: X509v3 Any Policy
+- CPS: http://policy.camerfirma.com
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 80:88:7f:70:de:92:28:d9:05:94:46:ff:90:57:a9:f1:2f:df:
+- 1a:0d:6b:fa:7c:0e:1c:49:24:79:27:d8:46:aa:6f:29:59:52:
+- 88:70:12:ea:dd:3d:f5:9b:53:54:6f:e1:60:a2:a8:09:b9:ec:
+- eb:59:7c:c6:35:f1:dc:18:e9:f1:67:e5:af:ba:45:e0:09:de:
+- ca:44:0f:c2:17:0e:77:91:45:7a:33:5f:5f:96:2c:68:8b:c1:
+- 47:8f:98:9b:3d:c0:ec:cb:f5:d5:82:92:84:35:d1:be:36:38:
+- 56:72:31:5b:47:2d:aa:17:a4:63:51:eb:0a:01:ad:7f:ec:75:
+- 9e:cb:a1:1f:f1:7f:12:b1:b9:e4:64:7f:67:d6:23:2a:f4:b8:
+- 39:5d:98:e8:21:a7:e1:bd:3d:42:1a:74:9a:70:af:68:6c:50:
+- 5d:49:cf:ff:fb:0e:5d:e6:2c:47:d7:81:3a:59:00:b5:73:6b:
+- 63:20:f6:31:45:08:39:0e:f4:70:7e:40:70:5a:3f:d0:6b:42:
+- a9:74:3d:28:2f:02:6d:75:72:95:09:8d:48:63:c6:c6:23:57:
+- 92:93:5e:35:c1:8d:f9:0a:f7:2c:9d:62:1c:f6:ad:7c:dd:a6:
+- 31:1e:b6:b1:c7:7e:85:26:fa:a4:6a:b5:da:63:30:d1:ef:93:
+- 37:b2:66:2f:7d:05:f7:e7:b7:4b:98:94:35:c0:d9:3a:29:c1:
+- 9d:b2:50:33:1d:4a:a9:5a:a6:c9:03:ef:ed:f4:e7:a8:6e:8a:
+- b4:57:84:eb:a4:3f:d0:ee:aa:aa:87:5b:63:e8:93:e2:6b:a8:
+- d4:b8:72:78:6b:1b:ed:39:e4:5d:cb:9b:aa:87:d5:4f:4e:00:
+- fe:d9:6a:9f:3c:31:0f:28:02:01:7d:98:e8:a7:b0:a2:64:9e:
+- 79:f8:48:f2:15:a9:cc:e6:c8:44:eb:3f:78:99:f2:7b:71:3e:
+- 3c:f1:98:a7:c5:18:12:3f:e6:bb:28:33:42:e9:45:0a:7c:6d:
+- f2:86:79:2f:c5:82:19:7d:09:89:7c:b2:54:76:88:ae:de:c1:
+- f3:cc:e1:6e:db:31:d6:93:ae:99:a0:ef:25:6a:73:98:89:5b:
+- 3a:2e:13:88:1e:bf:c0:92:94:34:1b:e3:27:b7:8b:1e:6f:42:
+- ff:e7:e9:37:9b:50:1d:2d:a2:f9:02:ee:cb:58:58:3a:71:bc:
+- 68:e3:aa:c1:af:1c:28:1f:a2:dc:23:65:3f:81:ea:ae:99:d3:
+- d8:30:cf:13:0d:4f:15:c9:84:bc:a7:48:2d:f8:30:23:77:d8:
+- 46:4b:79:6d:f6:8c:ed:3a:7f:60:11:78:f4:e9:9b:ae:d5:54:
+- c0:74:80:d1:0b:42:9f:c1
+-SHA1 Fingerprint=4A:BD:EE:EC:95:0D:35:9C:89:AE:C7:52:A1:2C:5B:29:F6:D6:AA:0C
+------BEGIN CERTIFICATE-----
+-MIIHSTCCBTGgAwIBAgIJAMnN0+nVfSPOMA0GCSqGSIb3DQEBBQUAMIGsMQswCQYD
+-VQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBhZGRyZXNzIGF0
+-IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3
+-MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAlBgNVBAMTHkdsb2JhbCBD
+-aGFtYmVyc2lnbiBSb290IC0gMjAwODAeFw0wODA4MDExMjMxNDBaFw0zODA3MzEx
+-MjMxNDBaMIGsMQswCQYDVQQGEwJFVTFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3Vy
+-cmVudCBhZGRyZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAG
+-A1UEBRMJQTgyNzQzMjg3MRswGQYDVQQKExJBQyBDYW1lcmZpcm1hIFMuQS4xJzAl
+-BgNVBAMTHkdsb2JhbCBDaGFtYmVyc2lnbiBSb290IC0gMjAwODCCAiIwDQYJKoZI
+-hvcNAQEBBQADggIPADCCAgoCggIBAMDfVtPkOpt2RbQT2//BthmLN0EYlVJH6xed
+-KYiONWwGMi5HYvNJBL99RDaxccy9Wglz1dmFRP+RVyXfXjaOcNFccUMd2drvXNL7
+-G706tcuto8xEpw2uIRU/uXpbknXYpBI4iRmKt4DS4jJvVpyR1ogQC7N0ZJJ0YPP2
+-zxhPYLIj0Mc7zmFLmY/CDNBAspjcDahOo7kKrmCgrUVSY7pmvWjg+b4aqIG7HkF4
+-ddPB/gBVsIdU6CeQNR1MM62X/JcumIS/LMmjv9GYERTtY/jKmIhYF5ntRQOXfjyG
+-HoiMvvKRhI9lNNgATH23MRdaKXoKGCQwoze1eqkBfSbW+Q6OWfH9GzO1KTsXO0G2
+-Id3UwD2ln58fQ1DJu7xsepeY7s2MH/ucUa6LcL0nn3HAa6x9kGbo1106DbDVwo3V
+-yJ2dwW3Q0L9R5OP4wzg2rtandeavhENdk5IMagfeOx2YItaswTXbo6Al/3K1dh3e
+-beksZixShNBFks4c5eUzHdwHU1SjqoI7mjcv3N2gZOnm3b2u/GSFHTynyQbehP9r
+-6GsaPMWis0L7iwk+XwhSx2LE1AVxv8Rk5Pihg+g+EpuoHtQ2TS9x9o0o9oOpE9Jh
+-wZG7SMA0j0GMS0zbaRL/UJScIINZc+18ofLx/d33SdNDWKBWY8o9PeU1VlnpDsog
+-zCtLkykPAgMBAAGjggFqMIIBZjASBgNVHRMBAf8ECDAGAQH/AgEMMB0GA1UdDgQW
+-BBS5CcqcHtvTbDprru1U8VuTBjUuXjCB4QYDVR0jBIHZMIHWgBS5CcqcHtvTbDpr
+-ru1U8VuTBjUuXqGBsqSBrzCBrDELMAkGA1UEBhMCRVUxQzBBBgNVBAcTOk1hZHJp
+-ZCAoc2VlIGN1cnJlbnQgYWRkcmVzcyBhdCB3d3cuY2FtZXJmaXJtYS5jb20vYWRk
+-cmVzcykxEjAQBgNVBAUTCUE4Mjc0MzI4NzEbMBkGA1UEChMSQUMgQ2FtZXJmaXJt
+-YSBTLkEuMScwJQYDVQQDEx5HbG9iYWwgQ2hhbWJlcnNpZ24gUm9vdCAtIDIwMDiC
+-CQDJzdPp1X0jzjAOBgNVHQ8BAf8EBAMCAQYwPQYDVR0gBDYwNDAyBgRVHSAAMCow
+-KAYIKwYBBQUHAgEWHGh0dHA6Ly9wb2xpY3kuY2FtZXJmaXJtYS5jb20wDQYJKoZI
+-hvcNAQEFBQADggIBAICIf3DekijZBZRG/5BXqfEv3xoNa/p8DhxJJHkn2EaqbylZ
+-UohwEurdPfWbU1Rv4WCiqAm57OtZfMY18dwY6fFn5a+6ReAJ3spED8IXDneRRXoz
+-X1+WLGiLwUePmJs9wOzL9dWCkoQ10b42OFZyMVtHLaoXpGNR6woBrX/sdZ7LoR/x
+-fxKxueRkf2fWIyr0uDldmOghp+G9PUIadJpwr2hsUF1Jz//7Dl3mLEfXgTpZALVz
+-a2Mg9jFFCDkO9HB+QHBaP9BrQql0PSgvAm11cpUJjUhjxsYjV5KTXjXBjfkK9yyd
+-Yhz2rXzdpjEetrHHfoUm+qRqtdpjMNHvkzeyZi99Bffnt0uYlDXA2TopwZ2yUDMd
+-SqlapskD7+3056huirRXhOukP9DuqqqHW2Pok+JrqNS4cnhrG+055F3Lm6qH1U9O
+-AP7Zap88MQ8oAgF9mOinsKJknnn4SPIVqczmyETrP3iZ8ntxPjzxmKfFGBI/5rso
+-M0LpRQp8bfKGeS/Fghl9CYl8slR2iK7ewfPM4W7bMdaTrpmg7yVqc5iJWzouE4ge
+-v8CSlDQb4ye3ix5vQv/n6TebUB0tovkC7stYWDpxvGjjqsGvHCgfotwjZT+B6q6Z
+-09gwzxMNTxXJhLynSC34MCN32EZLeW32jO06f2ARePTpm67VVMB0gNELQp/B
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Go_Daddy_Class_2_CA.pem.orig
++++ secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem.orig
++++ secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem.orig
++++ secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem.orig
++++ secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem.orig
++++ secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem.orig
++++ secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/ISRG_Root_X1.pem.orig
++++ secure/caroot/trusted/ISRG_Root_X1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem.orig
++++ secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem.orig
++++ secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Izenpe_com.pem.orig
++++ secure/caroot/trusted/Izenpe_com.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem.orig
++++ secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Microsoft_ECC_Root_Certificate_Authority_2017.pem.orig
++++ secure/caroot/trusted/Microsoft_ECC_Root_Certificate_Authority_2017.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Microsoft_RSA_Root_Certificate_Authority_2017.pem.orig
++++ secure/caroot/trusted/Microsoft_RSA_Root_Certificate_Authority_2017.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem.orig
++++ secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem.orig
++++ secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem.orig
++++ secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
+@@ -1,96 +0,0 @@
+-##
+-## OISTE WISeKey Global Root GA CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 41:3d:72:c7:f4:6b:1f:81:43:7d:f1:d2:28:54:df:9a
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
+- Validity
+- Not Before: Dec 11 16:03:44 2005 GMT
+- Not After : Dec 11 16:09:51 2037 GMT
+- Subject: C = CH, O = WISeKey, OU = Copyright (c) 2005, OU = OISTE Foundation Endorsed, CN = OISTE WISeKey Global Root GA CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:cb:4f:b3:00:9b:3d:36:dd:f9:d1:49:6a:6b:10:
+- 49:1f:ec:d8:2b:b2:c6:f8:32:81:29:43:95:4c:9a:
+- 19:23:21:15:45:de:e3:c8:1c:51:55:5b:ae:93:e8:
+- 37:ff:2b:6b:e9:d4:ea:be:2a:dd:a8:51:2b:d7:66:
+- c3:61:5c:60:02:c8:f5:ce:72:7b:3b:b8:f2:4e:65:
+- 08:9a:cd:a4:6a:19:c1:01:bb:73:a6:d7:f6:c3:dd:
+- cd:bc:a4:8b:b5:99:61:b8:01:a2:a3:d4:4d:d4:05:
+- 3d:91:ad:f8:b4:08:71:64:af:70:f1:1c:6b:7e:f6:
+- c3:77:9d:24:73:7b:e4:0c:8c:e1:d9:36:e1:99:8b:
+- 05:99:0b:ed:45:31:09:ca:c2:00:db:f7:72:a0:96:
+- aa:95:87:d0:8e:c7:b6:61:73:0d:76:66:8c:dc:1b:
+- b4:63:a2:9f:7f:93:13:30:f1:a1:27:db:d9:ff:2c:
+- 55:88:91:a0:e0:4f:07:b0:28:56:8c:18:1b:97:44:
+- 8e:89:dd:e0:17:6e:e7:2a:ef:8f:39:0a:31:84:82:
+- d8:40:14:49:2e:7a:41:e4:a7:fe:e3:64:cc:c1:59:
+- 71:4b:2c:21:a7:5b:7d:e0:1d:d1:2e:81:9b:c3:d8:
+- 68:f7:bd:96:1b:ac:70:b1:16:14:0b:db:60:b9:26:
+- 01:05
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage:
+- Digital Signature, Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- B3:03:7E:AE:36:BC:B0:79:D1:DC:94:26:B6:11:BE:21:B2:69:86:94
+- 1.3.6.1.4.1.311.21.1:
+- ...
+- Signature Algorithm: sha1WithRSAEncryption
+- 4b:a1:ff:0b:87:6e:b3:f9:c1:43:b1:48:f3:28:c0:1d:2e:c9:
+- 09:41:fa:94:00:1c:a4:a4:ab:49:4f:8f:3d:1e:ef:4d:6f:bd:
+- bc:a4:f6:f2:26:30:c9:10:ca:1d:88:fb:74:19:1f:85:45:bd:
+- b0:6c:51:f9:36:7e:db:f5:4c:32:3a:41:4f:5b:47:cf:e8:0b:
+- 2d:b6:c4:19:9d:74:c5:47:c6:3b:6a:0f:ac:14:db:3c:f4:73:
+- 9c:a9:05:df:00:dc:74:78:fa:f8:35:60:59:02:13:18:7c:bc:
+- fb:4d:b0:20:6d:43:bb:60:30:7a:67:33:5c:c5:99:d1:f8:2d:
+- 39:52:73:fb:8c:aa:97:25:5c:72:d9:08:1e:ab:4e:3c:e3:81:
+- 31:9f:03:a6:fb:c0:fe:29:88:55:da:84:d5:50:03:b6:e2:84:
+- a3:a6:36:aa:11:3a:01:e1:18:4b:d6:44:68:b3:3d:f9:53:74:
+- 84:b3:46:91:46:96:00:b7:80:2c:b6:e1:e3:10:e2:db:a2:e7:
+- 28:8f:01:96:62:16:3e:00:e3:1c:a5:36:81:18:a2:4c:52:76:
+- c0:11:a3:6e:e6:1d:ba:e3:5a:be:36:53:c5:3e:75:8f:86:69:
+- 29:58:53:b5:9c:bb:6f:9f:5c:c5:18:ec:dd:2f:e1:98:c9:fc:
+- be:df:0a:0d
+-SHA1 Fingerprint=59:22:A1:E1:5A:EA:16:35:21:F8:98:39:6A:46:46:B0:44:1B:0F:A9
+------BEGIN CERTIFICATE-----
+-MIID8TCCAtmgAwIBAgIQQT1yx/RrH4FDffHSKFTfmjANBgkqhkiG9w0BAQUFADCB
+-ijELMAkGA1UEBhMCQ0gxEDAOBgNVBAoTB1dJU2VLZXkxGzAZBgNVBAsTEkNvcHly
+-aWdodCAoYykgMjAwNTEiMCAGA1UECxMZT0lTVEUgRm91bmRhdGlvbiBFbmRvcnNl
+-ZDEoMCYGA1UEAxMfT0lTVEUgV0lTZUtleSBHbG9iYWwgUm9vdCBHQSBDQTAeFw0w
+-NTEyMTExNjAzNDRaFw0zNzEyMTExNjA5NTFaMIGKMQswCQYDVQQGEwJDSDEQMA4G
+-A1UEChMHV0lTZUtleTEbMBkGA1UECxMSQ29weXJpZ2h0IChjKSAyMDA1MSIwIAYD
+-VQQLExlPSVNURSBGb3VuZGF0aW9uIEVuZG9yc2VkMSgwJgYDVQQDEx9PSVNURSBX
+-SVNlS2V5IEdsb2JhbCBSb290IEdBIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+-MIIBCgKCAQEAy0+zAJs9Nt350UlqaxBJH+zYK7LG+DKBKUOVTJoZIyEVRd7jyBxR
+-VVuuk+g3/ytr6dTqvirdqFEr12bDYVxgAsj1znJ7O7jyTmUIms2kahnBAbtzptf2
+-w93NvKSLtZlhuAGio9RN1AU9ka34tAhxZK9w8RxrfvbDd50kc3vkDIzh2TbhmYsF
+-mQvtRTEJysIA2/dyoJaqlYfQjse2YXMNdmaM3Bu0Y6Kff5MTMPGhJ9vZ/yxViJGg
+-4E8HsChWjBgbl0SOid3gF27nKu+POQoxhILYQBRJLnpB5Kf+42TMwVlxSywhp1t9
+-4B3RLoGbw9ho972WG6xwsRYUC9tguSYBBQIDAQABo1EwTzALBgNVHQ8EBAMCAYYw
+-DwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUswN+rja8sHnR3JQmthG+IbJphpQw
+-EAYJKwYBBAGCNxUBBAMCAQAwDQYJKoZIhvcNAQEFBQADggEBAEuh/wuHbrP5wUOx
+-SPMowB0uyQlB+pQAHKSkq0lPjz0e701vvbyk9vImMMkQyh2I+3QZH4VFvbBsUfk2
+-ftv1TDI6QU9bR8/oCy22xBmddMVHxjtqD6wU2zz0c5ypBd8A3HR4+vg1YFkCExh8
+-vPtNsCBtQ7tgMHpnM1zFmdH4LTlSc/uMqpclXHLZCB6rTjzjgTGfA6b7wP4piFXa
+-hNVQA7bihKOmNqoROgHhGEvWRGizPflTdISzRpFGlgC3gCy24eMQ4tui5yiPAZZi
+-Fj4A4xylNoEYokxSdsARo27mHbrjWr42U8U+dY+GaSlYU7Wcu2+fXMUY7N0v4ZjJ
+-/L7fCg0=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem.orig
++++ secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem.orig
++++ secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA.pem
+@@ -1,117 +0,0 @@
+-##
+-## QuoVadis Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 985026699 (0x3ab6508b)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
+- Validity
+- Not Before: Mar 19 18:33:33 2001 GMT
+- Not After : Mar 17 18:33:33 2021 GMT
+- Subject: C = BM, O = QuoVadis Limited, OU = Root Certification Authority, CN = QuoVadis Root Certification Authority
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:bf:61:b5:95:53:ba:57:fc:fa:f2:67:0b:3a:1a:
+- df:11:80:64:95:b4:d1:bc:cd:7a:cf:f6:29:96:2e:
+- 24:54:40:24:38:f7:1a:85:dc:58:4c:cb:a4:27:42:
+- 97:d0:9f:83:8a:c3:e4:06:03:5b:00:a5:51:1e:70:
+- 04:74:e2:c1:d4:3a:ab:d7:ad:3b:07:18:05:8e:fd:
+- 83:ac:ea:66:d9:18:1b:68:8a:f5:57:1a:98:ba:f5:
+- ed:76:3d:7c:d9:de:94:6a:3b:4b:17:c1:d5:8f:bd:
+- 65:38:3a:95:d0:3d:55:36:4e:df:79:57:31:2a:1e:
+- d8:59:65:49:58:20:98:7e:ab:5f:7e:9f:e9:d6:4d:
+- ec:83:74:a9:c7:6c:d8:ee:29:4a:85:2a:06:14:f9:
+- 54:e6:d3:da:65:07:8b:63:37:12:d7:d0:ec:c3:7b:
+- 20:41:44:a3:ed:cb:a0:17:e1:71:65:ce:1d:66:31:
+- f7:76:01:19:c8:7d:03:58:b6:95:49:1d:a6:12:26:
+- e8:c6:0c:76:e0:e3:66:cb:ea:5d:a6:26:ee:e5:cc:
+- 5f:bd:67:a7:01:27:0e:a2:ca:54:c5:b1:7a:95:1d:
+- 71:1e:4a:29:8a:03:dc:6a:45:c1:a4:19:5e:6f:36:
+- cd:c3:a2:b0:b7:fe:5c:38:e2:52:bc:f8:44:43:e6:
+- 90:bb
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- Authority Information Access:
+- OCSP - URI:https://ocsp.quovadisoffshore.com
+-
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Certificate Policies:
+- Policy: 1.3.6.1.4.1.8024.0.1
+- User Notice:
+- Explicit Text: Reliance on the QuoVadis Root Certificate by any party assumes acceptance of the then applicable standard terms and conditions of use, certification practices, and the QuoVadis Certificate Policy.
+- CPS: http://www.quovadis.bm
+-
+- X509v3 Subject Key Identifier:
+- 8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
+- X509v3 Authority Key Identifier:
+- keyid:8B:4B:6D:ED:D3:29:B9:06:19:EC:39:39:A9:F0:97:84:6A:CB:EF:DF
+- DirName:/C=BM/O=QuoVadis Limited/OU=Root Certification Authority/CN=QuoVadis Root Certification Authority
+- serial:3A:B6:50:8B
+-
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- Signature Algorithm: sha1WithRSAEncryption
+- 8a:d4:14:b5:fe:f4:9a:92:a7:19:d4:a4:7e:72:18:8f:d9:68:
+- 7c:52:24:dd:67:6f:39:7a:c4:aa:5e:3d:e2:58:b0:4d:70:98:
+- 84:61:e8:1b:e3:69:18:0e:ce:fb:47:50:a0:4e:ff:f0:24:1f:
+- bd:b2:ce:f5:27:fc:ec:2f:53:aa:73:7b:03:3d:74:6e:e6:16:
+- 9e:eb:a5:2e:c4:bf:56:27:50:2b:62:ba:be:4b:1c:3c:55:5c:
+- 41:1d:24:be:82:20:47:5d:d5:44:7e:7a:16:68:df:7d:4d:51:
+- 70:78:57:1d:33:1e:fd:02:99:9c:0c:cd:0a:05:4f:c7:bb:8e:
+- a4:75:fa:4a:6d:b1:80:8e:09:56:b9:9c:1a:60:fe:5d:c1:d7:
+- 7a:dc:11:78:d0:d6:5d:c1:b7:d5:ad:32:99:03:3a:8a:cc:54:
+- 25:39:31:81:7b:13:22:51:ba:46:6c:a1:bb:9e:fa:04:6c:49:
+- 26:74:8f:d2:73:eb:cc:30:a2:e6:ea:59:22:87:f8:97:f5:0e:
+- fd:ea:cc:92:a4:16:c4:52:18:ea:21:ce:b1:f1:e6:84:81:e5:
+- ba:a9:86:28:f2:43:5a:5d:12:9d:ac:1e:d9:a8:e5:0a:6a:a7:
+- 7f:a0:87:29:cf:f2:89:4d:d4:ec:c5:e2:e6:7a:d0:36:23:8a:
+- 4a:74:36:f9
+-SHA1 Fingerprint=DE:3F:40:BD:50:93:D3:9B:6C:60:F6:DA:BC:07:62:01:00:89:76:C9
+------BEGIN CERTIFICATE-----
+-MIIF0DCCBLigAwIBAgIEOrZQizANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJC
+-TTEZMBcGA1UEChMQUXVvVmFkaXMgTGltaXRlZDElMCMGA1UECxMcUm9vdCBDZXJ0
+-aWZpY2F0aW9uIEF1dGhvcml0eTEuMCwGA1UEAxMlUXVvVmFkaXMgUm9vdCBDZXJ0
+-aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wMTAzMTkxODMzMzNaFw0yMTAzMTcxODMz
+-MzNaMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1pdGVkMSUw
+-IwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYDVQQDEyVR
+-dW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG
+-9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2G1lVO6V/z68mcLOhrfEYBklbTRvM16z/Yp
+-li4kVEAkOPcahdxYTMukJ0KX0J+DisPkBgNbAKVRHnAEdOLB1Dqr1607BxgFjv2D
+-rOpm2RgbaIr1VxqYuvXtdj182d6UajtLF8HVj71lODqV0D1VNk7feVcxKh7YWWVJ
+-WCCYfqtffp/p1k3sg3Spx2zY7ilKhSoGFPlU5tPaZQeLYzcS19Dsw3sgQUSj7cug
+-F+FxZc4dZjH3dgEZyH0DWLaVSR2mEiboxgx24ONmy+pdpibu5cxfvWenAScOospU
+-xbF6lR1xHkopigPcakXBpBlebzbNw6Kwt/5cOOJSvPhEQ+aQuwIDAQABo4ICUjCC
+-Ak4wPQYIKwYBBQUHAQEEMTAvMC0GCCsGAQUFBzABhiFodHRwczovL29jc3AucXVv
+-dmFkaXNvZmZzaG9yZS5jb20wDwYDVR0TAQH/BAUwAwEB/zCCARoGA1UdIASCAREw
+-ggENMIIBCQYJKwYBBAG+WAABMIH7MIHUBggrBgEFBQcCAjCBxxqBxFJlbGlhbmNl
+-IG9uIHRoZSBRdW9WYWRpcyBSb290IENlcnRpZmljYXRlIGJ5IGFueSBwYXJ0eSBh
+-c3N1bWVzIGFjY2VwdGFuY2Ugb2YgdGhlIHRoZW4gYXBwbGljYWJsZSBzdGFuZGFy
+-ZCB0ZXJtcyBhbmQgY29uZGl0aW9ucyBvZiB1c2UsIGNlcnRpZmljYXRpb24gcHJh
+-Y3RpY2VzLCBhbmQgdGhlIFF1b1ZhZGlzIENlcnRpZmljYXRlIFBvbGljeS4wIgYI
+-KwYBBQUHAgEWFmh0dHA6Ly93d3cucXVvdmFkaXMuYm0wHQYDVR0OBBYEFItLbe3T
+-KbkGGew5Oanwl4Rqy+/fMIGuBgNVHSMEgaYwgaOAFItLbe3TKbkGGew5Oanwl4Rq
+-y+/foYGEpIGBMH8xCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1p
+-dGVkMSUwIwYDVQQLExxSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MS4wLAYD
+-VQQDEyVRdW9WYWRpcyBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5ggQ6tlCL
+-MA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQUFAAOCAQEAitQUtf70mpKnGdSk
+-fnIYj9lofFIk3WdvOXrEql494liwTXCYhGHoG+NpGA7O+0dQoE7/8CQfvbLO9Sf8
+-7C9TqnN7Az10buYWnuulLsS/VidQK2K6vkscPFVcQR0kvoIgR13VRH56FmjffU1R
+-cHhXHTMe/QKZnAzNCgVPx7uOpHX6Sm2xgI4JVrmcGmD+XcHXetwReNDWXcG31a0y
+-mQM6isxUJTkxgXsTIlG6Rmyhu576BGxJJnSP0nPrzDCi5upZIof4l/UO/erMkqQW
+-xFIY6iHOsfHmhIHluqmGKPJDWl0Snawe2ajlCmqnf6CHKc/yiU3U7MXi5nrQNiOK
+-SnQ2+Q==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_2.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem.orig
++++ secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem.orig
++++ secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem.orig
++++ secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem.orig
++++ secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem.orig
++++ secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SZAFIR_ROOT_CA2.pem.orig
++++ secure/caroot/trusted/SZAFIR_ROOT_CA2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SecureSign_RootCA11.pem.orig
++++ secure/caroot/trusted/SecureSign_RootCA11.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SecureTrust_CA.pem.orig
++++ secure/caroot/trusted/SecureTrust_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Secure_Global_CA.pem.orig
++++ secure/caroot/trusted/Secure_Global_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Security_Communication_RootCA2.pem.orig
++++ secure/caroot/trusted/Security_Communication_RootCA2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Security_Communication_Root_CA.pem.orig
++++ secure/caroot/trusted/Security_Communication_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Sonera_Class_2_Root_CA.pem.orig
++++ secure/caroot/trusted/Sonera_Class_2_Root_CA.pem
+@@ -1,88 +0,0 @@
+-##
+-## Sonera Class 2 Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 29 (0x1d)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = FI, O = Sonera, CN = Sonera Class2 CA
+- Validity
+- Not Before: Apr 6 07:29:40 2001 GMT
+- Not After : Apr 6 07:29:40 2021 GMT
+- Subject: C = FI, O = Sonera, CN = Sonera Class2 CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:90:17:4a:35:9d:ca:f0:0d:96:c7:44:fa:16:37:
+- fc:48:bd:bd:7f:80:2d:35:3b:e1:6f:a8:67:a9:bf:
+- 03:1c:4d:8c:6f:32:47:d5:41:68:a4:13:04:c1:35:
+- 0c:9a:84:43:fc:5c:1d:ff:89:b3:e8:17:18:cd:91:
+- 5f:fb:89:e3:ea:bf:4e:5d:7c:1b:26:d3:75:79:ed:
+- e6:84:e3:57:e5:ad:29:c4:f4:3a:28:e7:a5:7b:84:
+- 36:69:b3:fd:5e:76:bd:a3:2d:99:d3:90:4e:23:28:
+- 7d:18:63:f1:54:3b:26:9d:76:5b:97:42:b2:ff:ae:
+- f0:4e:ec:dd:39:95:4e:83:06:7f:e7:49:40:c8:c5:
+- 01:b2:54:5a:66:1d:3d:fc:f9:e9:3c:0a:9e:81:b8:
+- 70:f0:01:8b:e4:23:54:7c:c8:ae:f8:90:1e:00:96:
+- 72:d4:54:cf:61:23:bc:ea:fb:9d:02:95:d1:b6:b9:
+- 71:3a:69:08:3f:0f:b4:e1:42:c7:88:f5:3f:98:a8:
+- a7:ba:1c:e0:71:71:ef:58:57:81:50:7a:5c:6b:74:
+- 46:0e:83:03:98:c3:8e:a8:6e:f2:76:32:6e:27:83:
+- c2:73:f3:dc:18:e8:b4:93:ea:75:44:6b:04:60:20:
+- 71:57:87:9d:f3:be:a0:90:23:3d:8a:24:e1:da:21:
+- db:c3
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 4A:A0:AA:58:84:D3:5E:3C
+- X509v3 Key Usage:
+- Certificate Sign, CRL Sign
+- Signature Algorithm: sha1WithRSAEncryption
+- 5a:ce:87:f9:16:72:15:57:4b:1d:d9:9b:e7:a2:26:30:ec:93:
+- 67:df:d6:2d:d2:34:af:f7:38:a5:ce:ab:16:b9:ab:2f:7c:35:
+- cb:ac:d0:0f:b4:4c:2b:fc:80:ef:6b:8c:91:5f:36:76:f7:db:
+- b3:1b:19:ea:f4:b2:11:fd:61:71:44:bf:28:b3:3a:1d:bf:b3:
+- 43:e8:9f:bf:dc:31:08:71:b0:9d:8d:d6:34:47:32:90:c6:65:
+- 24:f7:a0:4a:7c:04:73:8f:39:6f:17:8c:72:b5:bd:4b:c8:7a:
+- f8:7b:83:c3:28:4e:9c:09:ea:67:3f:b2:67:04:1b:c3:14:da:
+- f8:e7:49:24:91:d0:1d:6a:fa:61:39:ef:6b:e7:21:75:06:07:
+- d8:12:b4:21:20:70:42:71:81:da:3c:9a:36:be:a6:5b:0d:6a:
+- 6c:9a:1f:91:7b:f9:f9:ef:42:ba:4e:4e:9e:cc:0c:8d:94:dc:
+- d9:45:9c:5e:ec:42:50:63:ae:f4:5d:c4:b1:12:dc:ca:3b:a8:
+- 2e:9d:14:5a:05:75:b7:ec:d7:63:e2:ba:35:b6:04:08:91:e8:
+- da:9d:9c:f6:66:b5:18:ac:0a:a6:54:26:34:33:d2:1b:c1:d4:
+- 7f:1a:3a:8e:0b:aa:32:6e:db:fc:4f:25:9f:d9:32:c7:96:5a:
+- 70:ac:df:4c
+-SHA1 Fingerprint=37:F7:6D:E6:07:7C:90:C5:B1:3E:93:1A:B7:41:10:B4:F2:E4:9A:27
+------BEGIN CERTIFICATE-----
+-MIIDIDCCAgigAwIBAgIBHTANBgkqhkiG9w0BAQUFADA5MQswCQYDVQQGEwJGSTEP
+-MA0GA1UEChMGU29uZXJhMRkwFwYDVQQDExBTb25lcmEgQ2xhc3MyIENBMB4XDTAx
+-MDQwNjA3Mjk0MFoXDTIxMDQwNjA3Mjk0MFowOTELMAkGA1UEBhMCRkkxDzANBgNV
+-BAoTBlNvbmVyYTEZMBcGA1UEAxMQU29uZXJhIENsYXNzMiBDQTCCASIwDQYJKoZI
+-hvcNAQEBBQADggEPADCCAQoCggEBAJAXSjWdyvANlsdE+hY3/Ei9vX+ALTU74W+o
+-Z6m/AxxNjG8yR9VBaKQTBME1DJqEQ/xcHf+Js+gXGM2RX/uJ4+q/Tl18GybTdXnt
+-5oTjV+WtKcT0OijnpXuENmmz/V52vaMtmdOQTiMofRhj8VQ7Jp12W5dCsv+u8E7s
+-3TmVToMGf+dJQMjFAbJUWmYdPfz56TwKnoG4cPABi+QjVHzIrviQHgCWctRUz2Ej
+-vOr7nQKV0ba5cTppCD8PtOFCx4j1P5iop7oc4HFx71hXgVB6XGt0Rg6DA5jDjqhu
+-8nYybieDwnPz3BjotJPqdURrBGAgcVeHnfO+oJAjPYok4doh28MCAwEAAaMzMDEw
+-DwYDVR0TAQH/BAUwAwEB/zARBgNVHQ4ECgQISqCqWITTXjwwCwYDVR0PBAQDAgEG
+-MA0GCSqGSIb3DQEBBQUAA4IBAQBazof5FnIVV0sd2ZvnoiYw7JNn39Yt0jSv9zil
+-zqsWuasvfDXLrNAPtEwr/IDva4yRXzZ299uzGxnq9LIR/WFxRL8oszodv7ND6J+/
+-3DEIcbCdjdY0RzKQxmUk96BKfARzjzlvF4xytb1LyHr4e4PDKE6cCepnP7JnBBvD
+-FNr450kkkdAdavphOe9r5yF1BgfYErQhIHBCcYHaPJo2vqZbDWpsmh+Re/n570K6
+-Tk6ezAyNlNzZRZxe7EJQY670XcSxEtzKO6gunRRaBXW37Ndj4ro1tgQIkejanZz2
+-ZrUYrAqmVCY0M9IbwdR/GjqOC6oybtv8TyWf2TLHllpwrN9M
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem.orig
++++ secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem.orig
++++ secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
+@@ -1,132 +0,0 @@
+-##
+-## Staat der Nederlanden Root CA - G3
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 10003001 (0x98a239)
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
+- Validity
+- Not Before: Nov 14 11:28:42 2013 GMT
+- Not After : Nov 13 23:00:00 2028 GMT
+- Subject: C = NL, O = Staat der Nederlanden, CN = Staat der Nederlanden Root CA - G3
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:be:32:a2:54:0f:70:fb:2c:5c:59:eb:6c:c4:a4:
+- 51:e8:85:2a:b3:cc:4a:34:f2:b0:5f:f3:0e:c7:1c:
+- 3d:53:1e:88:08:68:d8:6f:3d:ad:c2:9e:cc:82:67:
+- 07:27:87:68:71:3a:9f:75:96:22:46:05:b0:ed:ad:
+- c7:5b:9e:2a:de:9c:fc:3a:c6:95:a7:f5:17:67:18:
+- e7:2f:49:08:0c:5c:cf:e6:cc:34:ed:78:fb:50:b1:
+- dc:6b:32:f0:a2:fe:b6:3c:e4:ec:5a:97:c7:3f:1e:
+- 70:08:30:a0:dc:c5:b3:6d:6f:d0:82:72:11:ab:d2:
+- 81:68:59:82:17:b7:78:92:60:fa:cc:de:3f:84:eb:
+- 8d:38:33:90:0a:72:23:fa:35:cc:26:71:31:d1:72:
+- 28:92:d9:5b:23:6d:66:b5:6d:07:42:eb:a6:33:ce:
+- 92:db:c0:f6:6c:63:78:cd:ca:4e:3d:b5:e5:52:9b:
+- f1:be:3b:e6:54:60:b0:66:1e:09:ab:07:fe:54:89:
+- 11:42:d1:f7:24:ba:60:78:1a:98:f7:c9:11:fd:16:
+- c1:35:1a:54:75:ef:43:d3:e5:ae:4e:ce:e7:7b:c3:
+- c6:4e:61:51:4b:ab:9a:45:4b:a1:1f:41:bd:48:53:
+- 15:71:64:0b:86:b3:e5:2e:be:ce:a4:1b:c1:29:84:
+- a2:b5:cb:08:23:76:43:22:24:1f:17:04:d4:6e:9c:
+- c6:fc:7f:2b:66:1a:ec:8a:e5:d6:cf:4d:f5:63:09:
+- b7:15:39:d6:7b:ac:eb:e3:7c:e9:4e:fc:75:42:c8:
+- ed:58:95:0c:06:42:a2:9c:f7:e4:70:b3:df:72:6f:
+- 5a:37:40:89:d8:85:a4:d7:f1:0b:de:43:19:d4:4a:
+- 58:2c:8c:8a:39:9e:bf:84:87:f1:16:3b:36:0c:e9:
+- d3:b4:ca:6c:19:41:52:09:a1:1d:b0:6a:bf:82:ef:
+- 70:51:21:32:dc:05:76:8c:cb:f7:64:e4:03:50:af:
+- 8c:91:67:ab:c5:f2:ee:58:d8:de:be:f7:e7:31:cf:
+- 6c:c9:3b:71:c1:d5:88:b5:65:bc:c0:e8:17:17:07:
+- 12:b5:5c:d2:ab:20:93:b4:e6:82:83:70:36:c5:cd:
+- a3:8d:ad:8b:ec:a3:c1:43:87:e6:43:e2:34:be:95:
+- 8b:35:ed:07:39:da:a8:1d:7a:9f:36:9e:12:b0:0c:
+- 65:12:90:15:60:d9:26:40:44:e3:56:60:a5:10:d4:
+- 6a:3c:fd:41:dc:0e:5a:47:b6:ef:97:61:75:4f:d9:
+- fe:c7:b2:1d:d4:ed:5d:49:b3:a9:6a:cb:66:84:13:
+- d5:5c:a0:dc:df:6e:77:06:d1:71:75:c8:57:6f:af:
+- 0f:77:5b
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Subject Key Identifier:
+- 54:AD:FA:C7:92:57:AE:CA:35:9C:2E:12:FB:E4:BA:5D:20:DC:94:57
+- Signature Algorithm: sha256WithRSAEncryption
+- 30:99:9d:05:32:c8:5e:0e:3b:98:01:3a:8a:a4:e7:07:f7:7a:
+- f8:e7:9a:df:50:43:53:97:2a:3d:ca:3c:47:98:2e:e1:15:7b:
+- f1:92:f3:61:da:90:25:16:65:c0:9f:54:5d:0e:03:3b:5b:77:
+- 02:9c:84:b6:0d:98:5f:34:dd:3b:63:c2:c3:28:81:c2:9c:29:
+- 2e:29:e2:c8:c3:01:f2:33:ea:2a:aa:cc:09:08:f7:65:67:c6:
+- cd:df:d3:b6:2b:a7:bd:cc:d1:0e:70:5f:b8:23:d1:cb:91:4e:
+- 0a:f4:c8:7a:e5:d9:63:36:c1:d4:df:fc:22:97:f7:60:5d:ea:
+- 29:2f:58:b2:bd:58:bd:8d:96:4f:10:75:bf:48:7b:3d:51:87:
+- a1:3c:74:22:c2:fc:07:7f:80:dc:c4:ac:fe:6a:c1:70:30:b0:
+- e9:8e:69:e2:2c:69:81:94:09:ba:dd:fe:4d:c0:83:8c:94:58:
+- c0:46:20:af:9c:1f:02:f8:35:55:49:2f:46:d4:c0:f0:a0:96:
+- 02:0f:33:c5:71:f3:9e:23:7d:94:b7:fd:3a:d3:09:83:06:21:
+- fd:60:3d:ae:32:c0:d2:ee:8d:a6:f0:e7:b4:82:7c:0a:cc:70:
+- c9:79:80:f8:fe:4c:f7:35:84:19:8a:31:fb:0a:d9:d7:7f:9b:
+- f0:a2:9a:6b:c3:05:4a:ed:41:60:14:30:d1:aa:11:42:6e:d3:
+- 23:02:04:0b:c6:65:dd:dd:52:77:da:81:6b:b2:a8:fa:01:38:
+- b9:96:ea:2a:6c:67:97:89:94:9e:bc:e1:54:d5:e4:6a:78:ef:
+- 4a:bd:2b:9a:3d:40:7e:c6:c0:75:d2:6e:fb:68:30:ec:ec:8b:
+- 9d:f9:49:35:9a:1a:2c:d9:b3:95:39:d5:1e:92:f7:a6:b9:65:
+- 2f:e5:3d:6d:3a:48:4c:08:dc:e4:28:12:28:be:7d:35:5c:ea:
+- e0:16:7e:13:1b:6a:d7:3e:d7:9e:fc:2d:75:b2:c1:14:d5:23:
+- 03:db:5b:6f:0b:3e:78:2f:0d:de:33:8d:16:b7:48:e7:83:9a:
+- 81:0f:7b:c1:43:4d:55:04:17:38:4a:51:d5:59:a2:89:74:d3:
+- 9f:be:1e:4b:d7:c6:6d:b7:88:24:6f:60:91:a4:82:85:5b:56:
+- 41:bc:d0:44:ab:6a:13:be:d1:2c:58:b7:12:33:58:b2:37:63:
+- dc:13:f5:94:1d:3f:40:51:f5:4f:f5:3a:ed:c8:c5:eb:c2:1e:
+- 1d:16:95:7a:c7:7e:42:71:93:6e:4b:15:b7:30:df:aa:ed:57:
+- 85:48:ac:1d:6a:dd:39:69:e4:e1:79:78:be:ce:05:bf:a1:0c:
+- f7:80:7b:21:67:27:30:59
+-SHA1 Fingerprint=D8:EB:6B:41:51:92:59:E0:F3:E7:85:00:C0:3D:B6:88:97:C9:EE:FC
+------BEGIN CERTIFICATE-----
+-MIIFdDCCA1ygAwIBAgIEAJiiOTANBgkqhkiG9w0BAQsFADBaMQswCQYDVQQGEwJO
+-TDEeMBwGA1UECgwVU3RhYXQgZGVyIE5lZGVybGFuZGVuMSswKQYDVQQDDCJTdGFh
+-dCBkZXIgTmVkZXJsYW5kZW4gUm9vdCBDQSAtIEczMB4XDTEzMTExNDExMjg0MloX
+-DTI4MTExMzIzMDAwMFowWjELMAkGA1UEBhMCTkwxHjAcBgNVBAoMFVN0YWF0IGRl
+-ciBOZWRlcmxhbmRlbjErMCkGA1UEAwwiU3RhYXQgZGVyIE5lZGVybGFuZGVuIFJv
+-b3QgQ0EgLSBHMzCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAL4yolQP
+-cPssXFnrbMSkUeiFKrPMSjTysF/zDsccPVMeiAho2G89rcKezIJnByeHaHE6n3WW
+-IkYFsO2tx1ueKt6c/DrGlaf1F2cY5y9JCAxcz+bMNO14+1Cx3Gsy8KL+tjzk7FqX
+-xz8ecAgwoNzFs21v0IJyEavSgWhZghe3eJJg+szeP4TrjTgzkApyI/o1zCZxMdFy
+-KJLZWyNtZrVtB0LrpjPOktvA9mxjeM3KTj215VKb8b475lRgsGYeCasH/lSJEULR
+-9yS6YHgamPfJEf0WwTUaVHXvQ9Plrk7O53vDxk5hUUurmkVLoR9BvUhTFXFkC4az
+-5S6+zqQbwSmEorXLCCN2QyIkHxcE1G6cxvx/K2Ya7Irl1s9N9WMJtxU51nus6+N8
+-6U78dULI7ViVDAZCopz35HCz33JvWjdAidiFpNfxC95DGdRKWCyMijmev4SH8RY7
+-Ngzp07TKbBlBUgmhHbBqv4LvcFEhMtwFdozL92TkA1CvjJFnq8Xy7ljY3r735zHP
+-bMk7ccHViLVlvMDoFxcHErVc0qsgk7TmgoNwNsXNo42ti+yjwUOH5kPiNL6VizXt
+-BznaqB16nzaeErAMZRKQFWDZJkBE41ZgpRDUajz9QdwOWke275dhdU/Z/seyHdTt
+-XUmzqWrLZoQT1Vyg3N9udwbRcXXIV2+vD3dbAgMBAAGjQjBAMA8GA1UdEwEB/wQF
+-MAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBRUrfrHkleuyjWcLhL75Lpd
+-INyUVzANBgkqhkiG9w0BAQsFAAOCAgEAMJmdBTLIXg47mAE6iqTnB/d6+Oea31BD
+-U5cqPco8R5gu4RV78ZLzYdqQJRZlwJ9UXQ4DO1t3ApyEtg2YXzTdO2PCwyiBwpwp
+-LiniyMMB8jPqKqrMCQj3ZWfGzd/TtiunvczRDnBfuCPRy5FOCvTIeuXZYzbB1N/8
+-Ipf3YF3qKS9Ysr1YvY2WTxB1v0h7PVGHoTx0IsL8B3+A3MSs/mrBcDCw6Y5p4ixp
+-gZQJut3+TcCDjJRYwEYgr5wfAvg1VUkvRtTA8KCWAg8zxXHzniN9lLf9OtMJgwYh
+-/WA9rjLA0u6NpvDntIJ8CsxwyXmA+P5M9zWEGYox+wrZ13+b8KKaa8MFSu1BYBQw
+-0aoRQm7TIwIEC8Zl3d1Sd9qBa7Ko+gE4uZbqKmxnl4mUnrzhVNXkanjvSr0rmj1A
+-fsbAddJu+2gw7OyLnflJNZoaLNmzlTnVHpL3prllL+U9bTpITAjc5CgSKL59NVzq
+-4BZ+Extq1z7XnvwtdbLBFNUjA9tbbws+eC8N3jONFrdI54OagQ97wUNNVQQXOEpR
+-1VmiiXTTn74eS9fGbbeIJG9gkaSChVtWQbzQRKtqE77RLFi3EjNYsjdj3BP1lB0/
+-QFH1T/U67cjF68IeHRaVesd+QnGTbksVtzDfqu1XhUisHWrdOWnk4Xl4vs4Fv6EM
+-94B7IWcnMFk=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Starfield_Class_2_CA.pem.orig
++++ secure/caroot/trusted/Starfield_Class_2_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem.orig
++++ secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem.orig
++++ secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem.orig
++++ secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem
+@@ -1,140 +0,0 @@
+-##
+-## SwissSign Platinum CA - G2
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number: 5670595323396054351 (0x4eb200670c035d4f)
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
+- Validity
+- Not Before: Oct 25 08:36:00 2006 GMT
+- Not After : Oct 25 08:36:00 2036 GMT
+- Subject: C = CH, O = SwissSign AG, CN = SwissSign Platinum CA - G2
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (4096 bit)
+- Modulus:
+- 00:ca:df:a2:02:e2:da:f8:fc:07:16:b1:de:60:aa:
+- de:96:5c:64:1f:c7:2f:7e:cf:67:fa:44:42:d6:76:
+- 63:95:ae:eb:af:72:20:8a:45:47:86:62:78:86:d6:
+- 20:39:26:f4:ae:a3:fd:23:e7:a5:9c:b5:22:21:19:
+- b7:37:93:22:c0:50:9c:82:7b:d4:d5:04:44:5c:cb:
+- b4:c2:9f:92:be:24:d8:7b:67:22:e2:69:5f:e5:05:
+- 78:d4:87:d9:71:70:33:25:53:b4:87:3b:29:90:28:
+- 36:9a:55:44:30:68:a4:83:97:7f:0d:1e:9c:76:ff:
+- 15:9d:60:97:00:8d:8a:85:03:ec:80:be:ea:2c:6e:
+- 10:51:92:cc:7e:d5:a3:33:d8:d6:49:de:58:2a:af:
+- f6:16:eb:4b:7b:90:32:97:b9:ba:9d:58:f1:f8:57:
+- 49:04:1e:a2:5d:06:70:dd:71:db:f9:dd:8b:9a:1b:
+- 8c:cf:3d:a3:4d:ce:cb:7c:f6:bb:9c:a0:fa:09:ce:
+- 23:62:b2:e9:0d:1f:e2:72:28:8f:9f:ac:68:20:7d:
+- 6f:3b:a8:85:31:09:7f:0b:c7:e8:65:e9:e3:78:0e:
+- 09:67:30:8b:34:82:fb:5d:e0:cc:9d:81:6d:62:ee:
+- 08:1e:04:2c:4e:9b:ec:fe:a9:4f:5f:fd:69:78:ef:
+- 09:1f:a1:b4:bf:fa:f3:ef:90:1e:4c:05:8b:1e:ea:
+- 7a:91:7a:c3:d7:e5:fb:30:bc:6c:1b:10:58:98:f7:
+- 1a:5f:d0:29:32:03:13:46:4d:61:6a:85:4c:52:74:
+- 2f:06:1f:7b:11:e2:84:97:c6:99:f3:6d:7f:d7:67:
+- 83:7e:13:68:d8:71:28:5a:d8:ce:dd:e8:10:14:9a:
+- fe:6d:23:87:6e:8e:5a:70:3c:d5:8d:09:00:a7:aa:
+- bc:b0:31:37:6d:c8:84:14:1e:5b:bd:45:63:20:6b:
+- 4b:74:8c:bd:db:3a:0e:c1:cf:5a:16:8f:a5:98:f2:
+- 76:89:b2:13:12:3b:0b:77:77:ac:bb:e5:3c:29:4a:
+- 92:72:ca:61:1a:2b:5e:4c:e2:83:74:77:fa:35:48:
+- 7a:85:4d:8d:9a:53:c4:df:78:ca:97:91:48:2b:45:
+- 2b:01:f7:1c:1a:a2:ed:18:ba:0a:bd:83:fa:6f:bc:
+- 8d:57:93:3b:d4:d4:a6:ce:1e:f1:a0:b1:ce:ab:fd:
+- 2b:28:9a:4f:1b:d7:c3:72:db:a4:c4:bf:5d:4c:f5:
+- dd:7b:96:69:ee:68:80:e6:e7:98:ba:36:b7:fe:6e:
+- ed:2b:bd:20:f8:65:19:da:55:09:7e:25:dc:fe:61:
+- 62:72:f9:7e:18:02:ef:63:b4:d0:fb:af:e5:3b:63:
+- 8c:67:8f
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
+- X509v3 Authority Key Identifier:
+- keyid:50:AF:CC:07:87:15:47:6F:38:C5:B4:65:D1:DE:95:AA:E9:DF:9C:CC
+-
+- X509v3 Certificate Policies:
+- Policy: 2.16.756.1.89.1.1.1.1
+- CPS: http://repository.swisssign.com/
+-
+- Signature Algorithm: sha1WithRSAEncryption
+- 08:85:a6:f5:16:0c:fc:44:1a:c1:63:e0:f9:55:46:08:fc:70:
+- 1c:42:28:96:8e:b7:c5:c1:41:75:4e:09:71:79:e5:6d:96:ca:
+- 4b:a5:88:60:d0:30:74:b8:ca:08:dc:b4:30:9e:40:07:16:6b:
+- 65:95:77:01:ae:a4:b7:35:0b:81:da:71:15:a9:74:17:38:7b:
+- 58:ca:f9:2f:fb:c0:65:76:8d:5b:01:b9:7d:de:82:3d:64:b8:
+- be:14:74:a3:0a:54:d3:2c:95:18:17:35:f5:51:6b:3f:8f:a2:
+- 96:61:39:78:6b:4b:e5:a6:a0:f8:53:df:51:10:93:62:e7:80:
+- 2f:e2:d1:e0:bc:8e:36:46:77:33:ec:b8:fb:8e:9a:2c:89:4d:
+- 31:11:0f:26:9e:04:bb:b7:04:8d:0b:f2:b9:fc:5a:9d:3b:16:
+- b7:2f:c8:98:ab:fe:8a:50:59:2e:a3:3b:fc:29:5d:8b:c1:4b:
+- c9:e2:8a:13:1d:b1:bf:bb:42:1d:52:dd:4e:d8:14:5e:10:c6:
+- 31:07:ef:71:27:f7:1b:39:09:dc:82:ea:8b:b3:95:86:5e:fd:
+- f5:da:5d:31:a6:e0:31:b6:94:e6:44:49:74:c5:16:e5:f7:1f:
+- 03:61:28:c5:c8:cb:12:a0:42:4b:f9:6b:88:08:8d:b4:32:18:
+- f3:75:9f:c4:7f:00:4f:05:95:9c:a3:17:02:c3:b3:53:9b:aa:
+- 20:39:29:2b:66:fa:9d:af:5e:b3:92:d2:b5:a6:e1:1a:f9:2d:
+- 41:69:81:14:b4:b4:b5:ed:89:3d:ce:fb:a9:9d:35:42:44:b1:
+- 1c:14:73:81:cf:2a:01:35:9a:31:d5:2d:8f:6d:84:df:80:4d:
+- 57:e3:3f:c5:84:75:da:89:c6:30:bb:eb:8f:cb:22:08:a0:ae:
+- aa:f1:03:6c:3a:4b:4d:09:a5:0e:72:c6:56:6b:21:42:4e:23:
+- 25:14:68:ae:76:0a:7c:0c:07:70:64:f9:9a:2f:f6:05:39:26:
+- c6:0c:8f:19:7f:43:5e:6e:f4:5b:15:2f:db:61:5d:e6:67:2f:
+- 3f:08:94:f9:60:b4:98:31:da:74:f1:84:93:71:4d:5f:fb:60:
+- 58:d1:fb:c4:c1:6d:89:a2:bb:20:1f:9d:71:91:cb:32:9b:13:
+- 3d:3e:7d:92:52:35:ac:92:94:a2:d3:18:c2:7c:c7:ea:af:76:
+- 05:16:dd:67:27:c2:7e:1c:07:22:21:f3:40:0a:1b:34:07:44:
+- 13:c2:84:6a:8e:df:19:5a:bf:7f:eb:1d:e2:1a:38:d1:5c:af:
+- 47:92:6b:80:b5:30:a5:c9:8d:d8:ab:31:81:1f:df:c2:66:37:
+- d3:93:a9:85:86:79:65:d2
+-SHA1 Fingerprint=56:E0:FA:C0:3B:8F:18:23:55:18:E5:D3:11:CA:E8:C2:43:31:AB:66
+------BEGIN CERTIFICATE-----
+-MIIFwTCCA6mgAwIBAgIITrIAZwwDXU8wDQYJKoZIhvcNAQEFBQAwSTELMAkGA1UE
+-BhMCQ0gxFTATBgNVBAoTDFN3aXNzU2lnbiBBRzEjMCEGA1UEAxMaU3dpc3NTaWdu
+-IFBsYXRpbnVtIENBIC0gRzIwHhcNMDYxMDI1MDgzNjAwWhcNMzYxMDI1MDgzNjAw
+-WjBJMQswCQYDVQQGEwJDSDEVMBMGA1UEChMMU3dpc3NTaWduIEFHMSMwIQYDVQQD
+-ExpTd2lzc1NpZ24gUGxhdGludW0gQ0EgLSBHMjCCAiIwDQYJKoZIhvcNAQEBBQAD
+-ggIPADCCAgoCggIBAMrfogLi2vj8Bxax3mCq3pZcZB/HL37PZ/pEQtZ2Y5Wu669y
+-IIpFR4ZieIbWIDkm9K6j/SPnpZy1IiEZtzeTIsBQnIJ71NUERFzLtMKfkr4k2Htn
+-IuJpX+UFeNSH2XFwMyVTtIc7KZAoNppVRDBopIOXfw0enHb/FZ1glwCNioUD7IC+
+-6ixuEFGSzH7VozPY1kneWCqv9hbrS3uQMpe5up1Y8fhXSQQeol0GcN1x2/ndi5ob
+-jM89o03Oy3z2u5yg+gnOI2Ky6Q0f4nIoj5+saCB9bzuohTEJfwvH6GXp43gOCWcw
+-izSC+13gzJ2BbWLuCB4ELE6b7P6pT1/9aXjvCR+htL/68++QHkwFix7qepF6w9fl
+-+zC8bBsQWJj3Gl/QKTIDE0ZNYWqFTFJ0LwYfexHihJfGmfNtf9dng34TaNhxKFrY
+-zt3oEBSa/m0jh26OWnA81Y0JAKeqvLAxN23IhBQeW71FYyBrS3SMvds6DsHPWhaP
+-pZjydomyExI7C3d3rLvlPClKknLKYRorXkzig3R3+jVIeoVNjZpTxN94ypeRSCtF
+-KwH3HBqi7Ri6Cr2D+m+8jVeTO9TUps4e8aCxzqv9KyiaTxvXw3LbpMS/XUz13XuW
+-ae5ogObnmLo2t/5u7Su9IPhlGdpVCX4l3P5hYnL5fhgC72O00Puv5TtjjGePAgMB
+-AAGjgawwgakwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0O
+-BBYEFFCvzAeHFUdvOMW0ZdHelarp35zMMB8GA1UdIwQYMBaAFFCvzAeHFUdvOMW0
+-ZdHelarp35zMMEYGA1UdIAQ/MD0wOwYJYIV0AVkBAQEBMC4wLAYIKwYBBQUHAgEW
+-IGh0dHA6Ly9yZXBvc2l0b3J5LnN3aXNzc2lnbi5jb20vMA0GCSqGSIb3DQEBBQUA
+-A4ICAQAIhab1Fgz8RBrBY+D5VUYI/HAcQiiWjrfFwUF1TglxeeVtlspLpYhg0DB0
+-uMoI3LQwnkAHFmtllXcBrqS3NQuB2nEVqXQXOHtYyvkv+8Bldo1bAbl93oI9ZLi+
+-FHSjClTTLJUYFzX1UWs/j6KWYTl4a0vlpqD4U99REJNi54Av4tHgvI42Rncz7Lj7
+-jposiU0xEQ8mngS7twSNC/K5/FqdOxa3L8iYq/6KUFkuozv8KV2LwUvJ4ooTHbG/
+-u0IdUt1O2BReEMYxB+9xJ/cbOQncguqLs5WGXv312l0xpuAxtpTmREl0xRbl9x8D
+-YSjFyMsSoEJL+WuICI20MhjzdZ/EfwBPBZWcoxcCw7NTm6ogOSkrZvqdr16zktK1
+-puEa+S1BaYEUtLS17Yk9zvupnTVCRLEcFHOBzyoBNZox1S2PbYTfgE1X4z/FhHXa
+-icYwu+uPyyIIoK6q8QNsOktNCaUOcsZWayFCTiMlFGiudgp8DAdwZPmaL/YFOSbG
+-DI8Zf0NebvRbFS/bYV3mZy8/CJT5YLSYMdp08YSTcU1f+2BY0fvEwW2JorsgH51x
+-kcsymxM9Pn2SUjWskpSi0xjCfMfqr3YFFt1nJ8J+HAciIfNAChs0B0QTwoRqjt8Z
+-Wr9/6x3iGjjRXK9HkmuAtTClyY3YqzGBH9/CZjfTk6mFhnll0g==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem.orig
++++ secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem.orig
++++ secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
+@@ -1,94 +0,0 @@
+-##
+-## Symantec Class 1 Public Primary Certification Authority - G6
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 24:32:75:f2:1d:2f:d2:09:33:f7:b4:6a:ca:d0:f3:98
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
+- Validity
+- Not Before: Oct 18 00:00:00 2011 GMT
+- Not After : Dec 1 23:59:59 2037 GMT
+- Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 1 Public Primary Certification Authority - G6
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c7:39:d7:49:64:a9:99:82:22:4c:ea:45:d9:07:
+- 16:e3:7b:f4:83:e8:99:73:fa:6b:b1:36:e0:9a:77:
+- a0:40:c2:81:8d:01:c7:cc:8c:bd:8f:7d:f7:79:e3:
+- 7a:4c:03:4d:d9:fb:fd:87:38:28:2c:dd:9a:8b:54:
+- 08:db:67:fb:1b:8c:fe:28:92:2f:be:b7:b2:48:a7:
+- 81:a1:d8:5e:88:c3:cc:39:40:41:5a:d1:dc:e5:da:
+- 10:9f:2f:da:01:4d:fd:2e:46:7c:f9:2e:27:0a:69:
+- 37:ee:91:a3:1b:6a:cc:44:bf:1b:c7:c3:d4:11:b2:
+- 50:60:97:09:bd:2e:22:f5:41:84:66:9f:cd:40:a6:
+- a9:00:80:c1:1f:95:92:9f:de:f3:48:ef:db:1d:77:
+- 61:fc:7f:df:ee:96:a4:72:d0:b6:3e:ff:78:27:af:
+- cb:92:15:69:08:db:63:10:e2:e6:97:ac:6e:dc:ac:
+- f6:a2:ce:1e:47:99:b9:89:b7:12:e6:a1:d4:cd:59:
+- 11:67:c3:6f:85:d8:42:4e:28:be:59:55:59:04:95:
+- ab:8f:37:80:bf:0d:f0:fc:1f:3a:64:31:58:81:78:
+- d7:e2:35:f6:20:3f:29:b8:8f:16:6e:3e:48:dc:b5:
+- 4c:07:e1:f2:1a:ea:7e:0a:79:d6:a8:bd:eb:5d:86:
+- 2b:4d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 33:41:E8:C8:39:12:15:93:48:F2:96:32:2E:5A:F5:DA:94:5F:53:60
+- Signature Algorithm: sha256WithRSAEncryption
+- 15:e3:73:57:b1:17:b6:5f:49:69:44:a6:f6:5e:7a:67:ac:d2:
+- de:75:49:ab:fe:25:55:c7:3a:c9:44:15:10:6e:bf:31:6b:cb:
+- d9:07:93:7f:1c:85:63:00:e3:32:12:e0:cc:cb:fb:39:6c:8f:
+- e2:53:e2:3c:40:33:d9:a4:8c:47:e6:ad:58:fb:89:af:e3:de:
+- 86:29:56:34:2c:45:b8:12:fa:44:89:6e:2d:14:25:28:24:01:
+- 65:d6:ea:52:ac:05:6e:56:12:09:3d:d0:74:f4:d7:bd:06:ca:
+- a8:3a:8d:56:42:fa:8d:72:3e:74:f1:03:72:df:87:1b:5e:0e:
+- 7a:55:96:2c:38:b7:98:85:cd:4d:33:44:c9:94:8f:5a:31:30:
+- 37:4b:a3:3a:12:b3:e7:36:d1:21:68:4b:2d:38:e6:53:ae:1c:
+- 25:56:08:56:03:67:84:9d:c6:c3:ce:24:62:c7:4c:36:cf:b0:
+- 06:44:b7:f5:5f:02:dd:d9:54:e9:2f:90:4e:7a:c8:4e:83:40:
+- 0c:9a:97:3c:37:bf:bf:ec:f6:f0:b4:85:77:28:c1:0b:c8:67:
+- 82:10:17:38:a2:b7:06:ea:9b:bf:3a:f8:e9:23:07:bf:74:e0:
+- 98:38:15:55:78:ee:72:00:5c:19:a3:f4:d2:33:e0:ff:bd:d1:
+- 54:39:29:0f
+-SHA1 Fingerprint=51:7F:61:1E:29:91:6B:53:82:FB:72:E7:44:D9:8D:C3:CC:53:6D:64
+------BEGIN CERTIFICATE-----
+-MIID9jCCAt6gAwIBAgIQJDJ18h0v0gkz97RqytDzmDANBgkqhkiG9w0BAQsFADCB
+-lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
+-HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
+-YyBDbGFzcyAxIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
+-IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
+-BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
+-eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAx
+-IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
+-MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHOddJZKmZgiJM6kXZBxbje/SD
+-6Jlz+muxNuCad6BAwoGNAcfMjL2Pffd543pMA03Z+/2HOCgs3ZqLVAjbZ/sbjP4o
+-ki++t7JIp4Gh2F6Iw8w5QEFa0dzl2hCfL9oBTf0uRnz5LicKaTfukaMbasxEvxvH
+-w9QRslBglwm9LiL1QYRmn81ApqkAgMEflZKf3vNI79sdd2H8f9/ulqRy0LY+/3gn
+-r8uSFWkI22MQ4uaXrG7crPaizh5HmbmJtxLmodTNWRFnw2+F2EJOKL5ZVVkElauP
+-N4C/DfD8HzpkMViBeNfiNfYgPym4jxZuPkjctUwH4fIa6n4KedaovetdhitNAgMB
+-AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
+-BBQzQejIORIVk0jyljIuWvXalF9TYDANBgkqhkiG9w0BAQsFAAOCAQEAFeNzV7EX
+-tl9JaUSm9l56Z6zS3nVJq/4lVcc6yUQVEG6/MWvL2QeTfxyFYwDjMhLgzMv7OWyP
+-4lPiPEAz2aSMR+atWPuJr+PehilWNCxFuBL6RIluLRQlKCQBZdbqUqwFblYSCT3Q
+-dPTXvQbKqDqNVkL6jXI+dPEDct+HG14OelWWLDi3mIXNTTNEyZSPWjEwN0ujOhKz
+-5zbRIWhLLTjmU64cJVYIVgNnhJ3Gw84kYsdMNs+wBkS39V8C3dlU6S+QTnrIToNA
+-DJqXPDe/v+z28LSFdyjBC8hnghAXOKK3Buqbvzr46SMHv3TgmDgVVXjucgBcGaP0
+-0jPg/73RVDkpDw==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem.orig
++++ secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
+@@ -1,94 +0,0 @@
+-##
+-## Symantec Class 2 Public Primary Certification Authority - G6
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 64:82:9e:fc:37:1e:74:5d:fc:97:ff:97:c8:b1:ff:41
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
+- Validity
+- Not Before: Oct 18 00:00:00 2011 GMT
+- Not After : Dec 1 23:59:59 2037 GMT
+- Subject: C = US, O = Symantec Corporation, OU = Symantec Trust Network, CN = Symantec Class 2 Public Primary Certification Authority - G6
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:cd:cc:e9:05:c8:63:85:cb:3f:40:63:17:bd:18:
+- fa:35:e6:04:67:57:65:98:29:a4:4f:c9:5c:8f:0f:
+- 34:d2:f8:da:a8:13:62:aa:b8:1e:50:67:78:b0:16:
+- 4c:a0:39:a9:15:7a:ae:ed:d2:a2:c0:f0:90:37:29:
+- 18:26:5c:e8:0d:3c:b6:6c:49:3f:c1:e0:dc:d9:4b:
+- b6:14:19:0b:a6:d3:96:e1:d6:09:e3:19:26:1c:f9:
+- 1f:65:4b:f9:1a:43:1c:00:83:d6:d0:aa:49:a2:d4:
+- db:e6:62:38:ba:50:14:43:6d:f9:31:f8:56:16:d9:
+- 38:02:91:cf:eb:6c:dd:bb:39:4e:99:e1:30:67:45:
+- f1:d4:f0:8d:c3:df:fe:f2:38:07:21:7d:00:5e:56:
+- 44:b3:e4:60:bd:91:2b:9c:ab:5b:04:72:0f:b2:28:
+- d9:72:ab:05:20:42:25:a9:5b:03:6a:20:10:cc:31:
+- f0:2b:da:35:2c:d0:fb:9a:97:4e:f0:82:4b:2b:d8:
+- 5f:36:a3:0b:2d:af:63:0d:1d:25:7f:a1:6e:5c:62:
+- a1:8d:28:3e:a1:fc:1c:20:f8:01:2f:ba:55:9a:11:
+- b0:19:d2:c8:50:79:6b:0e:6a:05:d7:aa:04:36:b2:
+- a3:f2:e1:5f:77:a7:77:9c:e5:1e:dc:e9:df:6a:c1:
+- 65:5d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Subject Key Identifier:
+- 87:8C:20:95:C8:98:4A:D1:D6:80:06:4A:90:34:44:DF:1C:4D:BF:B0
+- Signature Algorithm: sha256WithRSAEncryption
+- 81:8e:b2:a5:66:96:b7:21:a5:b6:ef:6f:23:5a:5f:db:81:c5:
+- 42:a5:78:c1:69:fd:f4:3c:d7:f9:5c:6b:70:72:1a:fc:5a:97:
+- 4d:00:80:88:88:82:8a:c3:71:0d:8e:c5:89:9b:2c:ed:8d:0b:
+- d2:72:54:f5:7d:d4:5c:43:57:e9:f3:ae:a5:02:11:f6:76:2b:
+- 81:57:dd:7d:da:74:30:fd:54:47:f6:e0:16:6e:a6:b4:0a:48:
+- e6:e7:75:07:0f:29:19:39:ce:79:f4:b6:6c:c5:5f:99:d5:1f:
+- 4b:fa:df:6d:2c:3c:0d:54:80:70:f0:88:0b:80:cf:c6:68:a2:
+- b8:1d:70:d9:76:8c:fc:ee:a5:c9:cf:ad:1d:cf:99:25:57:5a:
+- 62:45:cb:16:6b:bd:49:cd:a5:a3:8c:69:79:25:ae:b8:4c:6c:
+- 8b:40:66:4b:16:3f:cf:02:1a:dd:e1:6c:6b:07:61:6a:76:15:
+- 29:99:7f:1b:dd:88:80:c1:bf:b5:8f:73:c5:a6:96:23:84:a6:
+- 28:86:24:33:6a:01:2e:57:73:25:b6:5e:bf:8f:e6:1d:61:a8:
+- 40:29:67:1d:87:9b:1d:7f:9b:9f:99:cd:31:d6:54:be:62:bb:
+- 39:ac:68:12:48:91:20:a5:cb:b1:dd:fe:6f:fc:5a:e4:82:55:
+- 59:af:31:a9
+-SHA1 Fingerprint=40:B3:31:A0:E9:BF:E8:55:BC:39:93:CA:70:4F:4E:C2:51:D4:1D:8F
+------BEGIN CERTIFICATE-----
+-MIID9jCCAt6gAwIBAgIQZIKe/DcedF38l/+XyLH/QTANBgkqhkiG9w0BAQsFADCB
+-lDELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8w
+-HQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRl
+-YyBDbGFzcyAyIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5
+-IC0gRzYwHhcNMTExMDE4MDAwMDAwWhcNMzcxMjAxMjM1OTU5WjCBlDELMAkGA1UE
+-BhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZT
+-eW1hbnRlYyBUcnVzdCBOZXR3b3JrMUUwQwYDVQQDEzxTeW1hbnRlYyBDbGFzcyAy
+-IFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzYwggEi
+-MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDNzOkFyGOFyz9AYxe9GPo15gRn
+-V2WYKaRPyVyPDzTS+NqoE2KquB5QZ3iwFkygOakVeq7t0qLA8JA3KRgmXOgNPLZs
+-ST/B4NzZS7YUGQum05bh1gnjGSYc+R9lS/kaQxwAg9bQqkmi1NvmYji6UBRDbfkx
+-+FYW2TgCkc/rbN27OU6Z4TBnRfHU8I3D3/7yOAchfQBeVkSz5GC9kSucq1sEcg+y
+-KNlyqwUgQiWpWwNqIBDMMfAr2jUs0Pual07wgksr2F82owstr2MNHSV/oW5cYqGN
+-KD6h/Bwg+AEvulWaEbAZ0shQeWsOagXXqgQ2sqPy4V93p3ec5R7c6d9qwWVdAgMB
+-AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
+-BBSHjCCVyJhK0daABkqQNETfHE2/sDANBgkqhkiG9w0BAQsFAAOCAQEAgY6ypWaW
+-tyGltu9vI1pf24HFQqV4wWn99DzX+VxrcHIa/FqXTQCAiIiCisNxDY7FiZss7Y0L
+-0nJU9X3UXENX6fOupQIR9nYrgVfdfdp0MP1UR/bgFm6mtApI5ud1Bw8pGTnOefS2
+-bMVfmdUfS/rfbSw8DVSAcPCIC4DPxmiiuB1w2XaM/O6lyc+tHc+ZJVdaYkXLFmu9
+-Sc2lo4xpeSWuuExsi0BmSxY/zwIa3eFsawdhanYVKZl/G92IgMG/tY9zxaaWI4Sm
+-KIYkM2oBLldzJbZev4/mHWGoQClnHYebHX+bn5nNMdZUvmK7OaxoEkiRIKXLsd3+
+-b/xa5IJVWa8xqQ==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem.orig
++++ secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem.orig
++++ secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem.orig
++++ secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/TWCA_Global_Root_CA.pem.orig
++++ secure/caroot/trusted/TWCA_Global_Root_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/TWCA_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/TWCA_Root_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem.orig
++++ secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/TrustCor_ECA-1.pem.orig
++++ secure/caroot/trusted/TrustCor_ECA-1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/TrustCor_RootCert_CA-1.pem.orig
++++ secure/caroot/trusted/TrustCor_RootCert_CA-1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/TrustCor_RootCert_CA-2.pem.orig
++++ secure/caroot/trusted/TrustCor_RootCert_CA-2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Trustis_FPS_Root_CA.pem.orig
++++ secure/caroot/trusted/Trustis_FPS_Root_CA.pem
+@@ -1,92 +0,0 @@
+-##
+-## Trustis FPS Root CA
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 1b:1f:ad:b6:20:f9:24:d3:36:6b:f7:c7:f1:8c:a0:59
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
+- Validity
+- Not Before: Dec 23 12:14:06 2003 GMT
+- Not After : Jan 21 11:36:54 2024 GMT
+- Subject: C = GB, O = Trustis Limited, OU = Trustis FPS Root CA
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c5:50:7b:9e:3b:35:d0:df:c4:8c:cd:8e:9b:ed:
+- a3:c0:36:99:f4:42:ea:a7:3e:80:83:0f:a6:a7:59:
+- 87:c9:90:45:43:7e:00:ea:86:79:2a:03:bd:3d:37:
+- 99:89:66:b7:e5:8a:56:86:93:9c:68:4b:68:04:8c:
+- 93:93:02:3e:30:d2:37:3a:22:61:89:1c:85:4e:7d:
+- 8f:d5:af:7b:35:f6:7e:28:47:89:31:dc:0e:79:64:
+- 1f:99:d2:5b:ba:fe:7f:60:bf:ad:eb:e7:3c:38:29:
+- 6a:2f:e5:91:0b:55:ff:ec:6f:58:d5:2d:c9:de:4c:
+- 66:71:8f:0c:d7:04:da:07:e6:1e:18:e3:bd:29:02:
+- a8:fa:1c:e1:5b:b9:83:a8:41:48:bc:1a:71:8d:e7:
+- 62:e5:2d:b2:eb:df:7c:cf:db:ab:5a:ca:31:f1:4c:
+- 22:f3:05:13:f7:82:f9:73:79:0c:be:d7:4b:1c:c0:
+- d1:15:3c:93:41:64:d1:e6:be:23:17:22:00:89:5e:
+- 1f:6b:a5:ac:6e:a7:4b:8c:ed:a3:72:e6:af:63:4d:
+- 2f:85:d2:14:35:9a:2e:4e:8c:ea:32:98:28:86:a1:
+- 91:09:41:3a:b4:e1:e3:f2:fa:f0:c9:0a:a2:41:dd:
+- a9:e3:03:c7:88:15:3b:1c:d4:1a:94:d7:9f:64:59:
+- 12:6d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Authority Key Identifier:
+- keyid:BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
+-
+- X509v3 Subject Key Identifier:
+- BA:FA:71:25:79:8B:57:41:25:21:86:0B:71:EB:B2:64:0E:8B:21:67
+- Signature Algorithm: sha1WithRSAEncryption
+- 7e:58:ff:fd:35:19:7d:9c:18:4f:9e:b0:2b:bc:8e:8c:14:ff:
+- 2c:a0:da:47:5b:c3:ef:81:2d:af:05:ea:74:48:5b:f3:3e:4e:
+- 07:c7:6d:c5:b3:93:cf:22:35:5c:b6:3f:75:27:5f:09:96:cd:
+- a0:fe:be:40:0c:5c:12:55:f8:93:82:ca:29:e9:5e:3f:56:57:
+- 8b:38:36:f7:45:1a:4c:28:cd:9e:41:b8:ed:56:4c:84:a4:40:
+- c8:b8:b0:a5:2b:69:70:04:6a:c3:f8:d4:12:32:f9:0e:c3:b1:
+- dc:32:84:44:2c:6f:cb:46:0f:ea:66:41:0f:4f:f1:58:a5:a6:
+- 0d:0d:0f:61:de:a5:9e:5d:7d:65:a1:3c:17:e7:a8:55:4e:ef:
+- a0:c7:ed:c6:44:7f:54:f5:a3:e0:8f:f0:7c:55:22:8f:29:b6:
+- 81:a3:e1:6d:4e:2c:1b:80:67:ec:ad:20:9f:0c:62:61:d5:97:
+- ff:43:ed:2d:c1:da:5d:29:2a:85:3f:ac:65:ee:86:0f:05:8d:
+- 90:5f:df:ee:9f:f4:bf:ee:1d:fb:98:e4:7f:90:2b:84:78:10:
+- 0e:6c:49:53:ef:15:5b:65:46:4a:5d:af:ba:fb:3a:72:1d:cd:
+- f6:25:88:1e:97:cc:21:9c:29:01:0d:65:eb:57:d9:f3:57:96:
+- bb:48:cd:81
+-SHA1 Fingerprint=3B:C0:38:0B:33:C3:F6:A6:0C:86:15:22:93:D9:DF:F5:4B:81:C0:04
+------BEGIN CERTIFICATE-----
+-MIIDZzCCAk+gAwIBAgIQGx+ttiD5JNM2a/fH8YygWTANBgkqhkiG9w0BAQUFADBF
+-MQswCQYDVQQGEwJHQjEYMBYGA1UEChMPVHJ1c3RpcyBMaW1pdGVkMRwwGgYDVQQL
+-ExNUcnVzdGlzIEZQUyBSb290IENBMB4XDTAzMTIyMzEyMTQwNloXDTI0MDEyMTEx
+-MzY1NFowRTELMAkGA1UEBhMCR0IxGDAWBgNVBAoTD1RydXN0aXMgTGltaXRlZDEc
+-MBoGA1UECxMTVHJ1c3RpcyBGUFMgUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQAD
+-ggEPADCCAQoCggEBAMVQe547NdDfxIzNjpvto8A2mfRC6qc+gIMPpqdZh8mQRUN+
+-AOqGeSoDvT03mYlmt+WKVoaTnGhLaASMk5MCPjDSNzoiYYkchU59j9WvezX2fihH
+-iTHcDnlkH5nSW7r+f2C/revnPDgpai/lkQtV/+xvWNUtyd5MZnGPDNcE2gfmHhjj
+-vSkCqPoc4Vu5g6hBSLwacY3nYuUtsuvffM/bq1rKMfFMIvMFE/eC+XN5DL7XSxzA
+-0RU8k0Fk0ea+IxciAIleH2ulrG6nS4zto3Lmr2NNL4XSFDWaLk6M6jKYKIahkQlB
+-OrTh4/L68MkKokHdqeMDx4gVOxzUGpTXn2RZEm0CAwEAAaNTMFEwDwYDVR0TAQH/
+-BAUwAwEB/zAfBgNVHSMEGDAWgBS6+nEleYtXQSUhhgtx67JkDoshZzAdBgNVHQ4E
+-FgQUuvpxJXmLV0ElIYYLceuyZA6LIWcwDQYJKoZIhvcNAQEFBQADggEBAH5Y//01
+-GX2cGE+esCu8jowU/yyg2kdbw++BLa8F6nRIW/M+TgfHbcWzk88iNVy2P3UnXwmW
+-zaD+vkAMXBJV+JOCyinpXj9WV4s4NvdFGkwozZ5BuO1WTISkQMi4sKUraXAEasP4
+-1BIy+Q7DsdwyhEQsb8tGD+pmQQ9P8Vilpg0ND2HepZ5dfWWhPBfnqFVO76DH7cZE
+-f1T1o+CP8HxVIo8ptoGj4W1OLBuAZ+ytIJ8MYmHVl/9D7S3B2l0pKoU/rGXuhg8F
+-jZBf3+6f9L/uHfuY5H+QK4R4EA5sSVPvFVtlRkpdr7r7OnIdzfYliB6XzCGcKQEN
+-ZetX2fNXlrtIzYE=
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Trustwave_Global_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Trustwave_Global_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem.orig
++++ secure/caroot/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/UCA_Extended_Validation_Root.pem.orig
++++ secure/caroot/trusted/UCA_Extended_Validation_Root.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/UCA_Global_G2_Root.pem.orig
++++ secure/caroot/trusted/UCA_Global_G2_Root.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem.orig
++++ secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem.orig
++++ secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem
+@@ -1,100 +0,0 @@
+-##
+-## VeriSign Universal Root Certification Authority
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 3 (0x2)
+- Serial Number:
+- 40:1a:c4:64:21:b3:13:21:03:0e:bb:e4:12:1a:c5:1d
+- Signature Algorithm: sha256WithRSAEncryption
+- Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
+- Validity
+- Not Before: Apr 2 00:00:00 2008 GMT
+- Not After : Dec 1 23:59:59 2037 GMT
+- Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2008 VeriSign, Inc. - For authorized use only", CN = VeriSign Universal Root Certification Authority
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:c7:61:37:5e:b1:01:34:db:62:d7:15:9b:ff:58:
+- 5a:8c:23:23:d6:60:8e:91:d7:90:98:83:7a:e6:58:
+- 19:38:8c:c5:f6:e5:64:85:b4:a2:71:fb:ed:bd:b9:
+- da:cd:4d:00:b4:c8:2d:73:a5:c7:69:71:95:1f:39:
+- 3c:b2:44:07:9c:e8:0e:fa:4d:4a:c4:21:df:29:61:
+- 8f:32:22:61:82:c5:87:1f:6e:8c:7c:5f:16:20:51:
+- 44:d1:70:4f:57:ea:e3:1c:e3:cc:79:ee:58:d8:0e:
+- c2:b3:45:93:c0:2c:e7:9a:17:2b:7b:00:37:7a:41:
+- 33:78:e1:33:e2:f3:10:1a:7f:87:2c:be:f6:f5:f7:
+- 42:e2:e5:bf:87:62:89:5f:00:4b:df:c5:dd:e4:75:
+- 44:32:41:3a:1e:71:6e:69:cb:0b:75:46:08:d1:ca:
+- d2:2b:95:d0:cf:fb:b9:40:6b:64:8c:57:4d:fc:13:
+- 11:79:84:ed:5e:54:f6:34:9f:08:01:f3:10:25:06:
+- 17:4a:da:f1:1d:7a:66:6b:98:60:66:a4:d9:ef:d2:
+- 2e:82:f1:f0:ef:09:ea:44:c9:15:6a:e2:03:6e:33:
+- d3:ac:9f:55:00:c7:f6:08:6a:94:b9:5f:dc:e0:33:
+- f1:84:60:f9:5b:27:11:b4:fc:16:f2:bb:56:6a:80:
+- 25:8d
+- Exponent: 65537 (0x10001)
+- X509v3 extensions:
+- X509v3 Basic Constraints: critical
+- CA:TRUE
+- X509v3 Key Usage: critical
+- Certificate Sign, CRL Sign
+- 1.3.6.1.5.5.7.1.12:
+- 0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif
+- X509v3 Subject Key Identifier:
+- B6:77:FA:69:48:47:9F:53:12:D5:C2:EA:07:32:76:07:D1:97:07:19
+- Signature Algorithm: sha256WithRSAEncryption
+- 4a:f8:f8:b0:03:e6:2c:67:7b:e4:94:77:63:cc:6e:4c:f9:7d:
+- 0e:0d:dc:c8:b9:35:b9:70:4f:63:fa:24:fa:6c:83:8c:47:9d:
+- 3b:63:f3:9a:f9:76:32:95:91:b1:77:bc:ac:9a:be:b1:e4:31:
+- 21:c6:81:95:56:5a:0e:b1:c2:d4:b1:a6:59:ac:f1:63:cb:b8:
+- 4c:1d:59:90:4a:ef:90:16:28:1f:5a:ae:10:fb:81:50:38:0c:
+- 6c:cc:f1:3d:c3:f5:63:e3:b3:e3:21:c9:24:39:e9:fd:15:66:
+- 46:f4:1b:11:d0:4d:73:a3:7d:46:f9:3d:ed:a8:5f:62:d4:f1:
+- 3f:f8:e0:74:57:2b:18:9d:81:b4:c4:28:da:94:97:a5:70:eb:
+- ac:1d:be:07:11:f0:d5:db:dd:e5:8c:f0:d5:32:b0:83:e6:57:
+- e2:8f:bf:be:a1:aa:bf:3d:1d:b5:d4:38:ea:d7:b0:5c:3a:4f:
+- 6a:3f:8f:c0:66:6c:63:aa:e9:d9:a4:16:f4:81:d1:95:14:0e:
+- 7d:cd:95:34:d9:d2:8f:70:73:81:7b:9c:7e:bd:98:61:d8:45:
+- 87:98:90:c5:eb:86:30:c6:35:bf:f0:ff:c3:55:88:83:4b:ef:
+- 05:92:06:71:f2:b8:98:93:b7:ec:cd:82:61:f1:38:e6:4f:97:
+- 98:2a:5a:8d
+-SHA1 Fingerprint=36:79:CA:35:66:87:72:30:4D:30:A5:FB:87:3B:0F:A7:7B:B7:0D:54
+------BEGIN CERTIFICATE-----
+-MIIEuTCCA6GgAwIBAgIQQBrEZCGzEyEDDrvkEhrFHTANBgkqhkiG9w0BAQsFADCB
+-vTELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
+-ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwOCBWZXJp
+-U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MTgwNgYDVQQDEy9W
+-ZXJpU2lnbiBVbml2ZXJzYWwgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAe
+-Fw0wODA0MDIwMDAwMDBaFw0zNzEyMDEyMzU5NTlaMIG9MQswCQYDVQQGEwJVUzEX
+-MBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0
+-IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAyMDA4IFZlcmlTaWduLCBJbmMuIC0gRm9y
+-IGF1dGhvcml6ZWQgdXNlIG9ubHkxODA2BgNVBAMTL1ZlcmlTaWduIFVuaXZlcnNh
+-bCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIIBIjANBgkqhkiG9w0BAQEF
+-AAOCAQ8AMIIBCgKCAQEAx2E3XrEBNNti1xWb/1hajCMj1mCOkdeQmIN65lgZOIzF
+-9uVkhbSicfvtvbnazU0AtMgtc6XHaXGVHzk8skQHnOgO+k1KxCHfKWGPMiJhgsWH
+-H26MfF8WIFFE0XBPV+rjHOPMee5Y2A7Cs0WTwCznmhcrewA3ekEzeOEz4vMQGn+H
+-LL729fdC4uW/h2KJXwBL38Xd5HVEMkE6HnFuacsLdUYI0crSK5XQz/u5QGtkjFdN
+-/BMReYTtXlT2NJ8IAfMQJQYXStrxHXpma5hgZqTZ79IugvHw7wnqRMkVauIDbjPT
+-rJ9VAMf2CGqUuV/c4DPxhGD5WycRtPwW8rtWaoAljQIDAQABo4GyMIGvMA8GA1Ud
+-EwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMG0GCCsGAQUFBwEMBGEwX6FdoFsw
+-WTBXMFUWCWltYWdlL2dpZjAhMB8wBwYFKw4DAhoEFI/l0xqGrI2Oa8PPgGrUSBgs
+-exkuMCUWI2h0dHA6Ly9sb2dvLnZlcmlzaWduLmNvbS92c2xvZ28uZ2lmMB0GA1Ud
+-DgQWBBS2d/ppSEefUxLVwuoHMnYH0ZcHGTANBgkqhkiG9w0BAQsFAAOCAQEASvj4
+-sAPmLGd75JR3Y8xuTPl9Dg3cyLk1uXBPY/ok+myDjEedO2Pzmvl2MpWRsXe8rJq+
+-seQxIcaBlVZaDrHC1LGmWazxY8u4TB1ZkErvkBYoH1quEPuBUDgMbMzxPcP1Y+Oz
+-4yHJJDnp/RVmRvQbEdBNc6N9Rvk97ahfYtTxP/jgdFcrGJ2BtMQo2pSXpXDrrB2+
+-BxHw1dvd5Yzw1TKwg+ZX4o+/vqGqvz0dtdQ46tewXDpPaj+PwGZsY6rp2aQW9IHR
+-lRQOfc2VNNnSj3BzgXucfr2YYdhFh5iQxeuGMMY1v/D/w1WIg0vvBZIGcfK4mJO3
+-7M2CYfE45k+XmCpajQ==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem.orig
++++ secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
+@@ -1,87 +0,0 @@
+-##
+-## Verisign Class 1 Public Primary Certification Authority - G3
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 1 (0x0)
+- Serial Number:
+- 8b:5b:75:56:84:54:85:0b:00:cf:af:38:48:ce:b1:a4
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
+- Validity
+- Not Before: Oct 1 00:00:00 1999 GMT
+- Not After : Jul 16 23:59:59 2036 GMT
+- Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 1 Public Primary Certification Authority - G3
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:dd:84:d4:b9:b4:f9:a7:d8:f3:04:78:9c:de:3d:
+- dc:6c:13:16:d9:7a:dd:24:51:66:c0:c7:26:59:0d:
+- ac:06:08:c2:94:d1:33:1f:f0:83:35:1f:6e:1b:c8:
+- de:aa:6e:15:4e:54:27:ef:c4:6d:1a:ec:0b:e3:0e:
+- f0:44:a5:57:c7:40:58:1e:a3:47:1f:71:ec:60:f6:
+- 6d:94:c8:18:39:ed:fe:42:18:56:df:e4:4c:49:10:
+- 78:4e:01:76:35:63:12:36:dd:66:bc:01:04:36:a3:
+- 55:68:d5:a2:36:09:ac:ab:21:26:54:06:ad:3f:ca:
+- 14:e0:ac:ca:ad:06:1d:95:e2:f8:9d:f1:e0:60:ff:
+- c2:7f:75:2b:4c:cc:da:fe:87:99:21:ea:ba:fe:3e:
+- 54:d7:d2:59:78:db:3c:6e:cf:a0:13:00:1a:b8:27:
+- a1:e4:be:67:96:ca:a0:c5:b3:9c:dd:c9:75:9e:eb:
+- 30:9a:5f:a3:cd:d9:ae:78:19:3f:23:e9:5c:db:29:
+- bd:ad:55:c8:1b:54:8c:63:f6:e8:a6:ea:c7:37:12:
+- 5c:a3:29:1e:02:d9:db:1f:3b:b4:d7:0f:56:47:81:
+- 15:04:4a:af:83:27:d1:c5:58:88:c1:dd:f6:aa:a7:
+- a3:18:da:68:aa:6d:11:51:e1:bf:65:6b:9f:96:76:
+- d1:3d
+- Exponent: 65537 (0x10001)
+- Signature Algorithm: sha1WithRSAEncryption
+- ab:66:8d:d7:b3:ba:c7:9a:b6:e6:55:d0:05:f1:9f:31:8d:5a:
+- aa:d9:aa:46:26:0f:71:ed:a5:ad:53:56:62:01:47:2a:44:e9:
+- fe:3f:74:0b:13:9b:b9:f4:4d:1b:b2:d1:5f:b2:b6:d2:88:5c:
+- b3:9f:cd:cb:d4:a7:d9:60:95:84:3a:f8:c1:37:1d:61:ca:e7:
+- b0:c5:e5:91:da:54:a6:ac:31:81:ae:97:de:cd:08:ac:b8:c0:
+- 97:80:7f:6e:72:a4:e7:69:13:95:65:1f:c4:93:3c:fd:79:8f:
+- 04:d4:3e:4f:ea:f7:9e:ce:cd:67:7c:4f:65:02:ff:91:85:54:
+- 73:c7:ff:36:f7:86:2d:ec:d0:5e:4f:ff:11:9f:72:06:d6:b8:
+- 1a:f1:4c:0d:26:65:e2:44:80:1e:c7:9f:e3:dd:e8:0a:da:ec:
+- a5:20:80:69:68:a1:4f:7e:e1:6b:cf:07:41:fa:83:8e:bc:38:
+- dd:b0:2e:11:b1:6b:b2:42:cc:9a:bc:f9:48:22:79:4a:19:0f:
+- b2:1c:3e:20:74:d9:6a:c3:be:f2:28:78:13:56:79:4f:6d:50:
+- ea:1b:b0:b5:57:b1:37:66:58:23:f3:dc:0f:df:0a:87:c4:ef:
+- 86:05:d5:38:14:60:99:a3:4b:de:06:96:71:2c:f2:db:b6:1f:
+- a4:ef:3f:ee
+-SHA1 Fingerprint=20:42:85:DC:F7:EB:76:41:95:57:8E:13:6B:D4:B7:D1:E9:8E:46:A5
+------BEGIN CERTIFICATE-----
+-MIIEGjCCAwICEQCLW3VWhFSFCwDPrzhIzrGkMA0GCSqGSIb3DQEBBQUAMIHKMQsw
+-CQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZl
+-cmlTaWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWdu
+-LCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlT
+-aWduIENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3Jp
+-dHkgLSBHMzAeFw05OTEwMDEwMDAwMDBaFw0zNjA3MTYyMzU5NTlaMIHKMQswCQYD
+-VQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlT
+-aWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWduLCBJ
+-bmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlTaWdu
+-IENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkg
+-LSBHMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAN2E1Lm0+afY8wR4
+-nN493GwTFtl63SRRZsDHJlkNrAYIwpTRMx/wgzUfbhvI3qpuFU5UJ+/EbRrsC+MO
+-8ESlV8dAWB6jRx9x7GD2bZTIGDnt/kIYVt/kTEkQeE4BdjVjEjbdZrwBBDajVWjV
+-ojYJrKshJlQGrT/KFOCsyq0GHZXi+J3x4GD/wn91K0zM2v6HmSHquv4+VNfSWXjb
+-PG7PoBMAGrgnoeS+Z5bKoMWznN3JdZ7rMJpfo83ZrngZPyPpXNspva1VyBtUjGP2
+-6KbqxzcSXKMpHgLZ2x87tNcPVkeBFQRKr4Mn0cVYiMHd9qqnoxjaaKptEVHhv2Vr
+-n5Z20T0CAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAq2aN17O6x5q25lXQBfGfMY1a
+-qtmqRiYPce2lrVNWYgFHKkTp/j90CxObufRNG7LRX7K20ohcs5/Ny9Sn2WCVhDr4
+-wTcdYcrnsMXlkdpUpqwxga6X3s0IrLjAl4B/bnKk52kTlWUfxJM8/XmPBNQ+T+r3
+-ns7NZ3xPZQL/kYVUc8f/NveGLezQXk//EZ9yBta4GvFMDSZl4kSAHsef493oCtrs
+-pSCAaWihT37ha88HQfqDjrw43bAuEbFrskLMmrz5SCJ5ShkPshw+IHTZasO+8ih4
+-E1Z5T21Q6huwtVexN2ZYI/PcD98Kh8TvhgXVOBRgmaNL3gaWcSzy27YfpO8/7g==
+------END CERTIFICATE-----
+--- secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem.orig
++++ secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
+@@ -1,87 +0,0 @@
+-##
+-## Verisign Class 2 Public Primary Certification Authority - G3
+-##
+-## This is a single X.509 certificate for a public Certificate
+-## Authority (CA). It was automatically extracted from Mozilla's
+-## root CA list (the file `certdata.txt' in security/nss).
+-##
+-## Extracted from nss
+-## with $FreeBSD$
+-##
+-## @generated
+-##
+-Certificate:
+- Data:
+- Version: 1 (0x0)
+- Serial Number:
+- 61:70:cb:49:8c:5f:98:45:29:e7:b0:a6:d9:50:5b:7a
+- Signature Algorithm: sha1WithRSAEncryption
+- Issuer: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
+- Validity
+- Not Before: Oct 1 00:00:00 1999 GMT
+- Not After : Jul 16 23:59:59 2036 GMT
+- Subject: C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 1999 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 2 Public Primary Certification Authority - G3
+- Subject Public Key Info:
+- Public Key Algorithm: rsaEncryption
+- RSA Public-Key: (2048 bit)
+- Modulus:
+- 00:af:0a:0d:c2:d5:2c:db:67:b9:2d:e5:94:27:dd:
+- a5:be:e0:b0:4d:8f:b3:61:56:3c:d6:7c:c3:f4:cd:
+- 3e:86:cb:a2:88:e2:e1:d8:a4:69:c5:b5:e2:bf:c1:
+- a6:47:50:5e:46:39:8b:d5:96:ba:b5:6f:14:bf:10:
+- ce:27:13:9e:05:47:9b:31:7a:13:d8:1f:d9:d3:02:
+- 37:8b:ad:2c:47:f0:8e:81:06:a7:0d:30:0c:eb:f7:
+- 3c:0f:20:1d:dc:72:46:ee:a5:02:c8:5b:c3:c9:56:
+- 69:4c:c5:18:c1:91:7b:0b:d5:13:00:9b:bc:ef:c3:
+- 48:3e:46:60:20:85:2a:d5:90:b6:cd:8b:a0:cc:32:
+- dd:b7:fd:40:55:b2:50:1c:56:ae:cc:8d:77:4d:c7:
+- 20:4d:a7:31:76:ef:68:92:8a:90:1e:08:81:56:b2:
+- ad:69:a3:52:d0:cb:1c:c4:23:3d:1f:99:fe:4c:e8:
+- 16:63:8e:c6:08:8e:f6:31:f6:d2:fa:e5:76:dd:b5:
+- 1c:92:a3:49:cd:cd:01:cd:68:cd:a9:69:ba:a3:eb:
+- 1d:0d:9c:a4:20:a6:c1:a0:c5:d1:46:4c:17:6d:d2:
+- ac:66:3f:96:8c:e0:84:d4:36:ff:22:59:c5:f9:11:
+- 60:a8:5f:04:7d:f2:1a:f6:25:42:61:0f:c4:4a:b8:
+- 3e:89
+- Exponent: 65537 (0x10001)
+- Signature Algorithm: sha1WithRSAEncryption
+- 34:26:15:3c:c0:8d:4d:43:49:1d:bd:e9:21:92:d7:66:9c:b7:
+- de:c5:b8:d0:e4:5d:5f:76:22:c0:26:f9:84:3a:3a:f9:8c:b5:
+- fb:ec:60:f1:e8:ce:04:b0:c8:dd:a7:03:8f:30:f3:98:df:a4:
+- e6:a4:31:df:d3:1c:0b:46:dc:72:20:3f:ae:ee:05:3c:a4:33:
+- 3f:0b:39:ac:70:78:73:4b:99:2b:df:30:c2:54:b0:a8:3b:55:
+- a1:fe:16:28:cd:42:bd:74:6e:80:db:27:44:a7:ce:44:5d:d4:
+- 1b:90:98:0d:1e:42:94:b1:00:2c:04:d0:74:a3:02:05:22:63:
+- 63:cd:83:b5:fb:c1:6d:62:6b:69:75:fd:5d:70:41:b9:f5:bf:
+- 7c:df:be:c1:32:73:22:21:8b:58:81:7b:15:91:7a:ba:e3:64:
+- 48:b0:7f:fb:36:25:da:95:d0:f1:24:14:17:dd:18:80:6b:46:
+- 23:39:54:f5:8e:62:09:04:1d:94:90:a6:9b:e6:25:e2:42:45:
+- aa:b8:90:ad:be:08:8f:a9:0b:42:18:94:cf:72:39:e1:b1:43:
+- e0:28:cf:b7:e7:5a:6c:13:6b:49:b3:ff:e3:18:7c:89:8b:33:
+- 5d:ac:33:d7:a7:f9:da:3a:55:c9:58:10:f9:aa:ef:5a:b6:cf:
+- 4b:4b:df:2a
+-SHA1 Fingerprint=61:EF:43:D7:7F:CA:D4:61:51:BC:98:E0:C3:59:12:AF:9F:EB:63:11
+------BEGIN CERTIFICATE-----
+-MIIEGTCCAwECEGFwy0mMX5hFKeewptlQW3owDQYJKoZIhvcNAQEFBQAwgcoxCzAJ
+-BgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVy
+-aVNpZ24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24s
+-IEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNp
+-Z24gQ2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
+-eSAtIEczMB4XDTk5MTAwMTAwMDAwMFoXDTM2MDcxNjIzNTk1OVowgcoxCzAJBgNV
+-BAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVyaVNp
+-Z24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24sIElu
+-Yy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNpZ24g
+-Q2xhc3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAt
+-IEczMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArwoNwtUs22e5LeWU
+-J92lvuCwTY+zYVY81nzD9M0+hsuiiOLh2KRpxbXiv8GmR1BeRjmL1Za6tW8UvxDO
+-JxOeBUebMXoT2B/Z0wI3i60sR/COgQanDTAM6/c8DyAd3HJG7qUCyFvDyVZpTMUY
+-wZF7C9UTAJu878NIPkZgIIUq1ZC2zYugzDLdt/1AVbJQHFauzI13TccgTacxdu9o
+-koqQHgiBVrKtaaNS0MscxCM9H5n+TOgWY47GCI72MfbS+uV23bUckqNJzc0BzWjN
+-qWm6o+sdDZykIKbBoMXRRkwXbdKsZj+WjOCE1Db/IlnF+RFgqF8EffIa9iVCYQ/E
+-Srg+iQIDAQABMA0GCSqGSIb3DQEBBQUAA4IBAQA0JhU8wI1NQ0kdvekhktdmnLfe
+-xbjQ5F1fdiLAJvmEOjr5jLX77GDx6M4EsMjdpwOPMPOY36TmpDHf0xwLRtxyID+u
+-7gU8pDM/CzmscHhzS5kr3zDCVLCoO1Wh/hYozUK9dG6A2ydEp85EXdQbkJgNHkKU
+-sQAsBNB0owIFImNjzYO1+8FtYmtpdf1dcEG59b98377BMnMiIYtYgXsVkXq642RI
+-sH/7NiXaldDxJBQX3RiAa0YjOVT1jmIJBB2UkKab5iXiQkWquJCtvgiPqQtCGJTP
+-cjnhsUPgKM+351psE2tJs//jGHyJizNdrDPXp/naOlXJWBD5qu9ats9LS98q
+------END CERTIFICATE-----
+--- secure/caroot/trusted/XRamp_Global_CA_Root.pem.orig
++++ secure/caroot/trusted/XRamp_Global_CA_Root.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/certSIGN_ROOT_CA.pem.orig
++++ secure/caroot/trusted/certSIGN_ROOT_CA.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/certSIGN_Root_CA_G2.pem.orig
++++ secure/caroot/trusted/certSIGN_Root_CA_G2.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/e-Szigno_Root_CA_2017.pem.orig
++++ secure/caroot/trusted/e-Szigno_Root_CA_2017.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/ePKI_Root_Certification_Authority.pem.orig
++++ secure/caroot/trusted/ePKI_Root_Certification_Authority.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem.orig
++++ secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem.orig
++++ secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/emSign_Root_CA_-_C1.pem.orig
++++ secure/caroot/trusted/emSign_Root_CA_-_C1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
+--- secure/caroot/trusted/emSign_Root_CA_-_G1.pem.orig
++++ secure/caroot/trusted/emSign_Root_CA_-_G1.pem
+@@ -5,6 +5,8 @@
+ ## Authority (CA). It was automatically extracted from Mozilla's
+ ## root CA list (the file `certdata.txt' in security/nss).
+ ##
++## It contains a certificate trusted for server authentication.
++##
+ ## Extracted from nss
+ ## with $FreeBSD$
+ ##
diff --git a/website/static/security/patches/EN-21:27/caroot.13.patch.asc b/website/static/security/patches/EN-21:27/caroot.13.patch.asc
new file mode 100644
index 0000000000..7e3893c8da
--- /dev/null
+++ b/website/static/security/patches/EN-21:27/caroot.13.patch.asc
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAABCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD9AACgkQ05eS9J6n
+5cKn0w/9G9D8QUr1T97O6tZuRAsFa/Kvs5/gvvgenXzHGrMFOdktybuPMQuDp62r
+eYbHQyrUdX49CNKTVNRrB3WoFYI80BqpMyvuJz/x9RkX3RV/9ISuzl/EYuzBipHV
+16hCpeoscTm50eapZDH9tUyFi7eunpBdSS1c0iruWKC/roCsk6tB+1sBim5UWVh8
+KUiE9UeJFKCHRsqQP3ATV/Z7oU5IiIfLEsnCBd6b+LQqUfuMpuDHDNCRNH4wWGP8
+YYZuTlMYGjE0f18WhbjW/ZLerBJMoNbM7pNbPQDGEs6kYygOTs7Ri4ilxc0TGQft
+n4D73Bxr/frafZ6HvtLpxEBHLtC+YeD7IBntsB50WfL7nge9XkI7vDZwz0sEai5o
+54y6q6039rXahlFLQ1StOWvOvK20gGmYp/+UVmXmTKx+ATt23qpdpHK5x4lQP1mt
+hSqYEvcy9OhEJkgTyetaYY0YucnpNN+mSds9a9RTBxzhJItgwnoTRk9hxbRT8Z/B
+12RX4uLEQql9UCOXZOOJFPpc9XJ+s+V3JaICiu/u9CO+xgkaF0l3HD658157PsUf
+rbep1MXt0dvKUpGluycJ3Oxr5QxuPE//xe3wScL9Ctulzw1BZq4UC1z9mPr5lYRZ
+AhHSE22J78omKV/EiTjwxH5hjfGt+S9/B7OwZJNfG8ZnoZN9W10=
+=cDCv
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-21:28/vmci.patch b/website/static/security/patches/EN-21:28/vmci.patch
new file mode 100644
index 0000000000..410dfcfb1b
--- /dev/null
+++ b/website/static/security/patches/EN-21:28/vmci.patch
@@ -0,0 +1,138 @@
+--- sys/dev/vmware/vmci/vmci.c.orig
++++ sys/dev/vmware/vmci/vmci.c
+@@ -242,8 +242,10 @@
+
+ vmci_components_cleanup();
+
+- taskqueue_drain(taskqueue_thread, &sc->vmci_delayed_work_task);
+- mtx_destroy(&sc->vmci_delayed_work_lock);
++ if mtx_initialized(&sc->vmci_spinlock) {
++ taskqueue_drain(taskqueue_thread, &sc->vmci_delayed_work_task);
++ mtx_destroy(&sc->vmci_delayed_work_lock);
++ }
+
+ if (sc->vmci_res0 != NULL)
+ bus_space_write_4(sc->vmci_iot0, sc->vmci_ioh0,
+@@ -254,7 +256,8 @@
+
+ vmci_unmap_bars(sc);
+
+- mtx_destroy(&sc->vmci_spinlock);
++ if mtx_initialized(&sc->vmci_spinlock)
++ mtx_destroy(&sc->vmci_spinlock);
+
+ pci_disable_busmaster(dev);
+
+--- sys/dev/vmware/vmci/vmci_event.c.orig
++++ sys/dev/vmware/vmci/vmci_event.c
+@@ -593,6 +593,9 @@
+ {
+ struct vmci_subscription *s;
+
++ if (!vmci_initialized_lock(&subscriber_lock))
++ return NULL;
++
+ vmci_grab_lock_bh(&subscriber_lock);
+ s = vmci_event_find(sub_id);
+ if (s != NULL) {
+--- sys/dev/vmware/vmci/vmci_kernel_if.c.orig
++++ sys/dev/vmware/vmci/vmci_kernel_if.c
+@@ -70,7 +70,8 @@
+ vmci_cleanup_lock(vmci_lock *lock)
+ {
+
+- mtx_destroy(lock);
++ if mtx_initialized(lock)
++ mtx_destroy(lock);
+ }
+
+ /*
+@@ -165,6 +166,29 @@
+ mtx_unlock(lock);
+ }
+
++/*
++ *------------------------------------------------------------------------------
++ *
++ * vmci_initialized_lock
++ *
++ * Returns whether a lock has been initialized.
++ *
++ * Results:
++ * Return 1 if initialized or 0 if unininitialized.
++ *
++ * Side effects:
++ * None
++ *
++ *------------------------------------------------------------------------------
++ */
++
++int
++vmci_initialized_lock(vmci_lock *lock)
++{
++
++ return mtx_initialized(lock);
++}
++
+ /*
+ *------------------------------------------------------------------------------
+ *
+@@ -446,6 +470,28 @@
+ mtx_unlock(mutex);
+ }
+
++/*
++ *------------------------------------------------------------------------------
++ *
++ * vmci_mutex_initialized
++ *
++ * Returns whether a mutex has been initialized.
++ *
++ * Results:
++ * Return 1 if initialized or 0 if unininitialized.
++ *
++ * Side effects:
++ * None
++ *
++ *------------------------------------------------------------------------------
++ */
++
++int
++vmci_mutex_initialized(vmci_mutex *mutex)
++{
++
++ return mtx_initialized(mutex);
++}
+ /*
+ *------------------------------------------------------------------------------
+ *
+--- sys/dev/vmware/vmci/vmci_kernel_if.h.orig
++++ sys/dev/vmware/vmci/vmci_kernel_if.h
+@@ -48,6 +48,7 @@
+ void vmci_release_lock(vmci_lock *lock);
+ void vmci_grab_lock_bh(vmci_lock *lock);
+ void vmci_release_lock_bh(vmci_lock *lock);
++int vmci_initialized_lock(vmci_lock *lock);
+
+ void *vmci_alloc_kernel_mem(size_t size, int flags);
+ void vmci_free_kernel_mem(void *ptr, size_t size);
+@@ -72,6 +73,7 @@
+ void vmci_mutex_destroy(vmci_mutex *mutex);
+ void vmci_mutex_acquire(vmci_mutex *mutex);
+ void vmci_mutex_release(vmci_mutex *mutex);
++int vmci_mutex_initialized(vmci_mutex *mutex);
+
+ void *vmci_alloc_queue(uint64_t size, uint32_t flags);
+ void vmci_free_queue(void *q, uint64_t size);
+--- sys/dev/vmware/vmci/vmci_queue_pair.c.orig
++++ sys/dev/vmware/vmci/vmci_queue_pair.c
+@@ -338,6 +338,9 @@
+ {
+ struct qp_guest_endpoint *entry;
+
++ if (!vmci_mutex_initialized(&qp_guest_endpoints.mutex))
++ return;
++
+ vmci_mutex_acquire(&qp_guest_endpoints.mutex);
+
+ while ((entry =
diff --git a/website/static/security/patches/EN-21:28/vmci.patch.asc b/website/static/security/patches/EN-21:28/vmci.patch.asc
new file mode 100644
index 0000000000..ceb93729cf
--- /dev/null
+++ b/website/static/security/patches/EN-21:28/vmci.patch.asc
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAABCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD9AACgkQ05eS9J6n
+5cJfXw/9E8Ae3w3DXaiBDVSaXxIRK45cNMnrrlPSd4nUKOQvTwTMyi0uEgyxUwt1
+KSW+PP1lMPx4SB9UAy3VJfzkSZwiRLVh7XPzPWtsstJvx3+1FFAkXfu68XxCwLq8
+c3CxFPw9625EVNtwn7p6VY9J/6RJejXVw/i+Euka6F/06QMPt0ersHzp7IqlFkPV
+4A+eSilB1SRm7HwrTi8P6JaIw56VE7aK/atsv0dz0tL8STWJ7MRVj/2qLzA9uPAh
+CSz9oqtHTaecNrWjac2UEtdhpPEVWY8+A46fpnIJAdXIlmZ81WSO2Xv3PmRE2LNh
+1DT6VzsdwVsfG3Xwzw89y8yQp4Z/kc67STYrWsmFqPU/Q7IrNrNb2VjVCXJcO2C3
+fyvuLS55ajFkwlOyHa29fX2JGjTWN+alZRabk4+yt41EE2rWcJ6Mt9fKM10dRcRN
+iF5plWWgzkb9PvboajgdzRMHwUlqTBs0uvYqzdrCvnPpAcf6vEIqa18+Ic2ugkWP
+DAmmDeHebvMlMJjoEwOTiWMojNhuqoCNdYmhQCEO1yoR5fcwL8NJTmNSALxtJEOr
+EKYsZGUJsaoGT539WnIO5arSu6OiYn++TyKx7KonEa/G5ul4H5REIrMrJ/Fi6OPx
+R5O0ftl3aKJrrhMPEzR5ag04h5H0j7088S8unOTd7GL+iyIE2qI=
+=8EkP
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-21:29/tzdata-2021a3.patch b/website/static/security/patches/EN-21:29/tzdata-2021a3.patch
new file mode 100644
index 0000000000..7bd6502009
--- /dev/null
+++ b/website/static/security/patches/EN-21:29/tzdata-2021a3.patch
@@ -0,0 +1,205 @@
+--- contrib/tzdata/asia.orig
++++ contrib/tzdata/asia
+@@ -2234,6 +2234,14 @@
+ # From Paul Eggert (2013-12-11):
+ # As Steffen suggested, consider the past 21-month experiment to be DST.
+
++# From Steffen Thorsen (2021-09-24):
++# The Jordanian Government announced yesterday that they will start DST
++# in February instead of March:
++# https://petra.gov.jo/Include/InnerPage.jsp?ID=37683&lang=en&name=en_news (English)
++# https://petra.gov.jo/Include/InnerPage.jsp?ID=189969&lang=ar&name=news (Arabic)
++# From the Arabic version, it seems to say it would be at midnight
++# (assume 24:00) on the last Thursday in February, starting from 2022.
++
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Jordan 1973 only - Jun 6 0:00 1:00 S
+ Rule Jordan 1973 1975 - Oct 1 0:00 0 -
+@@ -2264,8 +2272,9 @@
+ Rule Jordan 2005 only - Sep lastFri 0:00s 0 -
+ Rule Jordan 2006 2011 - Oct lastFri 0:00s 0 -
+ Rule Jordan 2013 only - Dec 20 0:00 0 -
+-Rule Jordan 2014 max - Mar lastThu 24:00 1:00 S
++Rule Jordan 2014 2021 - Mar lastThu 24:00 1:00 S
+ Rule Jordan 2014 max - Oct lastFri 0:00s 0 -
++Rule Jordan 2022 max - Feb lastThu 24:00 1:00 S
+ # Zone NAME STDOFF RULES FORMAT [UNTIL]
+ Zone Asia/Amman 2:23:44 - LMT 1931
+ 2:00 Jordan EE%sT
+@@ -3379,11 +3388,6 @@
+ # shall [end] on Oct 24th 2020 at 01:00AM by delaying the clock by 60 minutes.
+ # http://www.palestinecabinet.gov.ps/portal/Meeting/Details/51584
+
+-# From Tim Parenti (2020-10-20):
+-# Predict future fall transitions at 01:00 on the Saturday preceding October's
+-# last Sunday (i.e., Sat>=24). This is consistent with our predictions since
+-# 2016, although the time of the change differed slightly in 2019.
+-
+ # From Pierre Cashon (2020-10-20):
+ # The summer time this year started on March 28 at 00:00.
+ # https://wafa.ps/ar_page.aspx?id=GveQNZa872839351758aGveQNZ
+@@ -3396,6 +3400,17 @@
+ # For now, guess spring-ahead transitions are at 00:00 on the Saturday
+ # preceding March's last Sunday (i.e., Sat>=24).
+
++# From P Chan (2021-10-18):
++# http://wafa.ps/Pages/Details/34701
++# Palestine winter time will start from midnight 2021-10-29 (Thursday-Friday).
++#
++# From Heba Hemad, Palestine Ministry of Telecom & IT (2021-10-20):
++# ... winter time will begin in Palestine from Friday 10-29, 01:00 AM
++# by 60 minutes backwards.
++#
++# From Paul Eggert (2021-10-20):
++# Guess future fall transitions on October's last Friday at 01:00.
++
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule EgyptAsia 1957 only - May 10 0:00 1:00 S
+ Rule EgyptAsia 1957 1958 - Oct 1 0:00 0 -
+@@ -3431,7 +3446,8 @@
+ Rule Palestine 2019 only - Mar 29 0:00 1:00 S
+ Rule Palestine 2019 only - Oct Sat>=24 0:00 0 -
+ Rule Palestine 2020 max - Mar Sat>=24 0:00 1:00 S
+-Rule Palestine 2020 max - Oct Sat>=24 1:00 0 -
++Rule Palestine 2020 only - Oct 24 1:00 0 -
++Rule Palestine 2021 max - Oct lastFri 1:00 0 -
+
+ # Zone NAME STDOFF RULES FORMAT [UNTIL]
+ Zone Asia/Gaza 2:17:52 - LMT 1900 Oct
+--- contrib/tzdata/australasia.orig
++++ contrib/tzdata/australasia
+@@ -385,9 +385,22 @@
+ # "Minister for Employment, Parveen Bala says they had never thought of
+ # stopping daylight saving. He says it was just to decide on when it should
+ # start and end. Bala says it is a short period..."
+-# Since the end date is still in line with our ongoing predictions, assume for
+-# now that the later-than-usual start date is a one-time departure from the
+-# recent second Sunday in November pattern.
++#
++# From Tim Parenti (2021-10-11), per Jashneel Kumar (2021-10-11) and P Chan
++# (2021-10-12):
++# https://www.fiji.gov.fj/Media-Centre/Speeches/English/PM-BAINIMARAMA-S-COVID-19-ANNOUNCEMENT-10-10-21
++# https://www.fbcnews.com.fj/news/covid-19/curfew-moved-back-to-11pm/
++# In a 2021-10-10 speech concerning updated Covid-19 mitigation measures in
++# Fiji, prime minister Josaia Voreqe "Frank" Bainimarama announced the
++# suspension of DST for the 2021/2022 season: "Given that we are in the process
++# of readjusting in the midst of so many changes, we will also put Daylight
++# Savings Time on hold for this year. It will also make the reopening of
++# scheduled commercial air service much smoother if we don't have to be
++# concerned shifting arrival and departure times, which may look like a simple
++# thing but requires some significant logistical adjustments domestically and
++# internationally."
++# Assume for now that DST will resume with the recent pre-2020 rules for the
++# 2022/2023 season.
+
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Fiji 1998 1999 - Nov Sun>=1 2:00 1:00 -
+@@ -399,10 +412,11 @@
+ Rule Fiji 2012 2013 - Jan Sun>=18 3:00 0 -
+ Rule Fiji 2014 only - Jan Sun>=18 2:00 0 -
+ Rule Fiji 2014 2018 - Nov Sun>=1 2:00 1:00 -
+-Rule Fiji 2015 max - Jan Sun>=12 3:00 0 -
++Rule Fiji 2015 2021 - Jan Sun>=12 3:00 0 -
+ Rule Fiji 2019 only - Nov Sun>=8 2:00 1:00 -
+ Rule Fiji 2020 only - Dec 20 2:00 1:00 -
+-Rule Fiji 2021 max - Nov Sun>=8 2:00 1:00 -
++Rule Fiji 2022 max - Nov Sun>=8 2:00 1:00 -
++Rule Fiji 2023 max - Jan Sun>=12 3:00 0 -
+ # Zone NAME STDOFF RULES FORMAT [UNTIL]
+ Zone Pacific/Fiji 11:55:44 - LMT 1915 Oct 26 # Suva
+ 12:00 Fiji +12/+13
+@@ -742,13 +756,17 @@
+ # From Paul Eggert (2014-07-08):
+ # That web page currently lists transitions for 2012/3 and 2013/4.
+ # Assume the pattern instituted in 2012 will continue indefinitely.
++#
++# From Geoffrey D. Bennett (2021-09-20):
++# https://www.mcil.gov.ws/storage/2021/09/MCIL-Scan_20210920_120553.pdf
++# DST has been cancelled for this year.
+
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule WS 2010 only - Sep lastSun 0:00 1 -
+ Rule WS 2011 only - Apr Sat>=1 4:00 0 -
+ Rule WS 2011 only - Sep lastSat 3:00 1 -
+-Rule WS 2012 max - Apr Sun>=1 4:00 0 -
+-Rule WS 2012 max - Sep lastSun 3:00 1 -
++Rule WS 2012 2021 - Apr Sun>=1 4:00 0 -
++Rule WS 2012 2020 - Sep lastSun 3:00 1 -
+ # Zone NAME STDOFF RULES FORMAT [UNTIL]
+ Zone Pacific/Apia 12:33:04 - LMT 1892 Jul 5
+ -11:26:56 - LMT 1911
+--- contrib/tzdata/europe.orig
++++ contrib/tzdata/europe
+@@ -822,7 +822,7 @@
+ # Shanks & Pottenger give 02:00, the BEV 00:00. Go with the BEV,
+ # and guess 02:00 for 1945-04-12.
+
+-# From Alois Triendl (2019-07-22):
++# From Alois Treindl (2019-07-22):
+ # In 1946 the end of DST was on Monday, 7 October 1946, at 3:00 am.
+ # Shanks had this right. Source: Die Weltpresse, 5. Oktober 1946, page 5.
+
+@@ -1736,19 +1736,22 @@
+ # advanced to sixty minutes later starting at hour two on 1944-04-02; ...
+ # Starting at hour three on the date 1944-09-17 standard time will be resumed.
+ #
+-# From Alois Triendl (2019-07-02):
++# From Alois Treindl (2019-07-02):
+ # I spent 6 Euros to buy two archive copies of Il Messaggero, a Roman paper,
+ # for 1 and 2 April 1944. The edition of 2 April has this note: "Tonight at 2
+ # am, put forward the clock by one hour. Remember that in the night between
+ # today and Monday the 'ora legale' will come in force again." That makes it
+ # clear that in Rome the change was on Monday, 3 April 1944 at 2 am.
+ #
+-# From Paul Eggert (2016-10-27):
++# From Paul Eggert (2021-10-05):
+ # Go with INRiM for DST rules, except as corrected by Inglis for 1944
+ # for the Kingdom of Italy. This is consistent with Renzo Baldini.
+ # Model Rome's occupation by using C-Eur rules from 1943-09-10
+ # to 1944-06-04; although Rome was an open city during this period, it
+-# was effectively controlled by Germany.
++# was effectively controlled by Germany. Using C-Eur is consistent
++# with Treindl's comment about Rome in April 1944, as the "Rule Italy"
++# lines during German occupation do not affect Europe/Rome
++# (though they do affect Europe/Malta).
+ #
+ # Rule NAME FROM TO - IN ON AT SAVE LETTER/S
+ Rule Italy 1916 only - Jun 3 24:00 1:00 S
+@@ -2618,7 +2621,7 @@
+ # Although Shanks lists 1945-01-01 as the date for transition from
+ # +01/+02 to +02/+03, more likely this is a placeholder. Guess that
+ # the transition occurred at 1945-04-10 00:00, which is about when
+-# Königsberg surrendered to Soviet troops. (Thanks to Alois Triendl.)
++# Königsberg surrendered to Soviet troops. (Thanks to Alois Treindl.)
+
+ # From Paul Eggert (2016-03-18):
+ # The 1989 transition is from USSR act No. 227 (1989-03-14).
+--- contrib/tzdata/northamerica.orig
++++ contrib/tzdata/northamerica
+@@ -970,7 +970,7 @@
+ -5:00 US E%sT
+ #
+ # Perry County, Indiana, switched from eastern to central time in April 2006.
+-# From Alois Triendl (2019-07-09):
++# From Alois Treindl (2019-07-09):
+ # The Indianapolis News, Friday 27 October 1967 states that Perry County
+ # returned to CST. It went again to EST on 27 April 1969, as documented by the
+ # Indianapolis star of Saturday 26 April.
+@@ -1998,7 +1998,7 @@
+
+ # Alberta
+
+-# From Alois Triendl (2019-07-19):
++# From Alois Treindl (2019-07-19):
+ # There was no DST in Alberta in 1967... Calgary Herald, 29 April 1967.
+ # 1969, no DST, from Edmonton Journal 18 April 1969
+ #
+@@ -2107,7 +2107,7 @@
+ #
+ # From Paul Eggert (2019-07-25):
+ # Shanks says Fort Nelson did not observe DST in 1946, unlike Vancouver.
+-# Alois Triendl confirmed this on 07-22, citing the 1946-04-27 Vancouver Daily
++# Alois Treindl confirmed this on 07-22, citing the 1946-04-27 Vancouver Daily
+ # Province. He also cited the 1946-09-28 Victoria Daily Times, which said
+ # that Vancouver, Victoria, etc. "change at midnight Saturday"; for now,
+ # guess they meant 02:00 Sunday since 02:00 was common practice in Vancouver.
diff --git a/website/static/security/patches/EN-21:29/tzdata-2021a3.patch.asc b/website/static/security/patches/EN-21:29/tzdata-2021a3.patch.asc
new file mode 100644
index 0000000000..12fda6f16b
--- /dev/null
+++ b/website/static/security/patches/EN-21:29/tzdata-2021a3.patch.asc
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAABCgAdFiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAmGDD9AACgkQ05eS9J6n
+5cIX0Q//Y2/ViumM0wPn67qMIu9tl7V0s+Sz7ap10Vi4hLs/Xicpw8rzkZhDJxX9
+yHMkVPg5OaJioBoyoRkKPZbaWhkDcxUz8SQeq5HIdoYNvECl7aIaHzSq4bdCvQeQ
+1rf7lwzWpzn6J4L/t/uD/k4xseiLbfO6rmcj1CoBtLCK1nhhv6EykYLIC1bi+B6t
+cy8qjDDxov6CapJC/bN/MMmvD9R8/ApuhOUGTbjp2g3ZtYze3Gq6/l9VF30oqsa0
+7/PAESxe7yUelVGSBQPM8XuN6iT4vkPQGWfVpyB3qCWwLtb12qBZyGcBDV8YZ+qi
+xR0toUFvDDONDkVwECv8ewdNav+aqXW442c7s8xk/UG/6xv5pkm16NUC1dfUB1AF
+lDv6yvDLuRsGgXEmTkIFO2u6lKVAbsRSZabCJzox84S4R0lTx4m2xtIZteObUJaO
+LovaHwAQUcdx22vR96UmADApbWNx+0rMxEFT8mE6DHdIfVIvR9oQALIuVtmR2nFB
+2zyTdKKJ/AQVi/m9NyNV6/PIoVdcNdw/MBbv+JuhC467ykXjCHlcTp4LHi0vz0d3
+BfaIacmV5qOXhKFhAyrtRCxlH8GIRRW7s/GUPoZLbSlQE/e8tFCx6s4cm33f4Hcd
+n+UtDMR8K/eoUaBAeUN1pfKa1RqUTCYBTojiN+2BIY1FS+4hm+Y=
+=vtZq
+-----END PGP SIGNATURE-----