{
  "source_file": "C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts",
  "cacerts_mode": true,
  "hostname": "check-certificat",
  "generated_at": "2026-06-02T17:59:45.223984+00:00",
  "reference_date": "2026-06-02",
  "certificates": [
    {
      "type": "CERT",
      "label": "c=de,o=atos,cn=atos_trustedroot_2011",
      "subject": "C=DE,O=Atos,CN=Atos TrustedRoot 2011",
      "issuer": "C=DE,O=Atos,CN=Atos TrustedRoot 2011",
      "serial_number": "5c33cb622c5fb332",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "c=de,o=atos,cn=atos_trustedroot_root_ca_ecc_tls_2021",
      "subject": "C=DE,O=Atos,CN=Atos TrustedRoot Root CA ECC TLS 2021",
      "issuer": "C=DE,O=Atos,CN=Atos TrustedRoot Root CA ECC TLS 2021",
      "serial_number": "3d983ba6663d9063f77e26573804ef00",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "c=de,o=atos,cn=atos_trustedroot_root_ca_rsa_tls_2021",
      "subject": "C=DE,O=Atos,CN=Atos TrustedRoot Root CA RSA TLS 2021",
      "issuer": "C=DE,O=Atos,CN=Atos TrustedRoot Root CA RSA TLS 2021",
      "serial_number": "53d5cfe619930bfb2b0512d8c22aa2a4",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "c=es,o=accv,ou=pkiaccv,cn=accvraiz1",
      "subject": "C=ES,O=ACCV,OU=PKIACCV,CN=ACCVRAIZ1",
      "issuer": "C=ES,O=ACCV,OU=PKIACCV,CN=ACCVRAIZ1",
      "serial_number": "5ec3b7a6437fa4e0",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [
          "accv@accv.es"
        ],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ac_raiz_fnmt-rcm_servidores_seguros,ou=ceres,o=fnmt-rcm,c=es",
      "subject": "CN=AC RAIZ FNMT-RCM SERVIDORES SEGUROS,2.5.4.97=VATES-Q2826004J,OU=Ceres,O=FNMT-RCM,C=ES",
      "issuer": "CN=AC RAIZ FNMT-RCM SERVIDORES SEGUROS,2.5.4.97=VATES-Q2826004J,OU=Ceres,O=FNMT-RCM,C=ES",
      "serial_number": "62f6326ce5c4e3685c1b62dd9c2e9d95",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=actalis_authentication_root_ca,o=actalis_s.p.a./03358520967,l=milan,c=it",
      "subject": "CN=Actalis Authentication Root CA,O=Actalis S.p.A./03358520967,L=Milan,C=IT",
      "issuer": "CN=Actalis Authentication Root CA,O=Actalis S.p.A./03358520967,L=Milan,C=IT",
      "serial_number": "570a119742c4e3cc",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=affirmtrust_commercial,o=affirmtrust,c=us",
      "subject": "CN=AffirmTrust Commercial,O=AffirmTrust,C=US",
      "issuer": "CN=AffirmTrust Commercial,O=AffirmTrust,C=US",
      "serial_number": "7777062726a9b17c",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=affirmtrust_networking,o=affirmtrust,c=us",
      "subject": "CN=AffirmTrust Networking,O=AffirmTrust,C=US",
      "issuer": "CN=AffirmTrust Networking,O=AffirmTrust,C=US",
      "serial_number": "7c4f04391cd4992d",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=affirmtrust_premium,o=affirmtrust,c=us",
      "subject": "CN=AffirmTrust Premium,O=AffirmTrust,C=US",
      "issuer": "CN=AffirmTrust Premium,O=AffirmTrust,C=US",
      "serial_number": "6d8c1446b1a60aee",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=affirmtrust_premium_ecc,o=affirmtrust,c=us",
      "subject": "CN=AffirmTrust Premium ECC,O=AffirmTrust,C=US",
      "issuer": "CN=AffirmTrust Premium ECC,O=AffirmTrust,C=US",
      "serial_number": "7497258ac73f7a54",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=amazon_root_ca_1,o=amazon,c=us",
      "subject": "CN=Amazon Root CA 1,O=Amazon,C=US",
      "issuer": "CN=Amazon Root CA 1,O=Amazon,C=US",
      "serial_number": "66c9fcf99bf8c0a39e2f0788a43e696365bca",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=amazon_root_ca_2,o=amazon,c=us",
      "subject": "CN=Amazon Root CA 2,O=Amazon,C=US",
      "issuer": "CN=Amazon Root CA 2,O=Amazon,C=US",
      "serial_number": "66c9fd29635869f0a0fe58678f85b26bb8a37",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=amazon_root_ca_3,o=amazon,c=us",
      "subject": "CN=Amazon Root CA 3,O=Amazon,C=US",
      "issuer": "CN=Amazon Root CA 3,O=Amazon,C=US",
      "serial_number": "66c9fd5749736663f3b0b9ad9e89e7603f24a",
      "key_size": 256,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA256",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=amazon_root_ca_4,o=amazon,c=us",
      "subject": "CN=Amazon Root CA 4,O=Amazon,C=US",
      "issuer": "CN=Amazon Root CA 4,O=Amazon,C=US",
      "serial_number": "66c9fd7c1bb104c2943e5717b7b2cc81ac10e",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=anf_secure_server_root_ca,ou=anf_ca_raiz,o=anf_autoridad_de_certificacion,c=es",
      "subject": "CN=ANF Secure Server Root CA,OU=ANF CA Raiz,O=ANF Autoridad de Certificacion,C=ES,2.5.4.5=G63287510",
      "issuer": "CN=ANF Secure Server Root CA,OU=ANF CA Raiz,O=ANF Autoridad de Certificacion,C=ES,2.5.4.5=G63287510",
      "serial_number": "dd3e3bc6cf96bb1",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=autoridad_de_certificacion_firmaprofesional_cif_a62634068,c=es",
      "subject": "CN=Autoridad de Certificacion Firmaprofesional CIF A62634068,C=ES",
      "issuer": "CN=Autoridad de Certificacion Firmaprofesional CIF A62634068,C=ES",
      "serial_number": "1b70e9d2ffae6c71",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true,
        "path_length": 1
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=bjca_global_root_ca1,o=beijing_certificate_authority,c=cn",
      "subject": "CN=BJCA Global Root CA1,O=BEIJING CERTIFICATE AUTHORITY,C=CN",
      "issuer": "CN=BJCA Global Root CA1,O=BEIJING CERTIFICATE AUTHORITY,C=CN",
      "serial_number": "556f65e3b4d9906a1b09d16c3ec06c20",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=bjca_global_root_ca2,o=beijing_certificate_authority,c=cn",
      "subject": "CN=BJCA Global Root CA2,O=BEIJING CERTIFICATE AUTHORITY,C=CN",
      "issuer": "CN=BJCA Global Root CA2,O=BEIJING CERTIFICATE AUTHORITY,C=CN",
      "serial_number": "2c17087d642ac0fe85185906cfb44aeb",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=buypass_class_2_root_ca,o=buypass_as-983163327,c=no",
      "subject": "CN=Buypass Class 2 Root CA,O=Buypass AS-983163327,C=NO",
      "issuer": "CN=Buypass Class 2 Root CA,O=Buypass AS-983163327,C=NO",
      "serial_number": "2",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=buypass_class_3_root_ca,o=buypass_as-983163327,c=no",
      "subject": "CN=Buypass Class 3 Root CA,O=Buypass AS-983163327,C=NO",
      "issuer": "CN=Buypass Class 3 Root CA,O=Buypass AS-983163327,C=NO",
      "serial_number": "2",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ca_disig_root_r2,o=disig_a.s.,l=bratislava,c=sk",
      "subject": "CN=CA Disig Root R2,O=Disig a.s.,L=Bratislava,C=SK",
      "issuer": "CN=CA Disig Root R2,O=Disig a.s.,L=Bratislava,C=SK",
      "serial_number": "92b888dbb08ac163",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certainly_root_e1,o=certainly,c=us",
      "subject": "CN=Certainly Root E1,O=Certainly,C=US",
      "issuer": "CN=Certainly Root E1,O=Certainly,C=US",
      "serial_number": "62533b1470333275cf98d9ab9bfccf8",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certainly_root_r1,o=certainly,c=us",
      "subject": "CN=Certainly Root R1,O=Certainly,C=US",
      "issuer": "CN=Certainly Root R1,O=Certainly,C=US",
      "serial_number": "8e0ff94b907168653354f4d44439b7e0",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certigna,o=dhimyotis,c=fr",
      "subject": "CN=Certigna,O=Dhimyotis,C=FR",
      "issuer": "CN=Certigna,O=Dhimyotis,C=FR",
      "serial_number": "fedce3010fc948ff",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certigna_root_ca,ou=0002_48146308100036,o=dhimyotis,c=fr",
      "subject": "CN=Certigna Root CA,OU=0002 48146308100036,O=Dhimyotis,C=FR",
      "issuer": "CN=Certigna Root CA,OU=0002 48146308100036,O=Dhimyotis,C=FR",
      "serial_number": "cae91b89f155030da3e6416dc4e3a6e1",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certum_ec-384_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl",
      "subject": "CN=Certum EC-384 CA,OU=Certum Certification Authority,O=Asseco Data Systems S.A.,C=PL",
      "issuer": "CN=Certum EC-384 CA,OU=Certum Certification Authority,O=Asseco Data Systems S.A.,C=PL",
      "serial_number": "788f275c81125220a504d02dddba73f4",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certum_trusted_network_ca,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl",
      "subject": "CN=Certum Trusted Network CA,OU=Certum Certification Authority,O=Unizeto Technologies S.A.,C=PL",
      "issuer": "CN=Certum Trusted Network CA,OU=Certum Certification Authority,O=Unizeto Technologies S.A.,C=PL",
      "serial_number": "444c0",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certum_trusted_network_ca_2,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl",
      "subject": "CN=Certum Trusted Network CA 2,OU=Certum Certification Authority,O=Unizeto Technologies S.A.,C=PL",
      "issuer": "CN=Certum Trusted Network CA 2,OU=Certum Certification Authority,O=Unizeto Technologies S.A.,C=PL",
      "serial_number": "21d6d04a4f250fc93237fcaa5e128de9",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha512WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=certum_trusted_root_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl",
      "subject": "CN=Certum Trusted Root CA,OU=Certum Certification Authority,O=Asseco Data Systems S.A.,C=PL",
      "issuer": "CN=Certum Trusted Root CA,OU=Certum Certification Authority,O=Asseco Data Systems S.A.,C=PL",
      "serial_number": "1ebf5950b8c980374c06f7eb554fb5ed",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha512WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=cfca_ev_root,o=china_financial_certification_authority,c=cn",
      "subject": "CN=CFCA EV ROOT,O=China Financial Certification Authority,C=CN",
      "issuer": "CN=CFCA EV ROOT,O=China Financial Certification Authority,C=CN",
      "serial_number": "184accd6",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=comodo_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb",
      "subject": "CN=COMODO Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB",
      "issuer": "CN=COMODO Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB",
      "serial_number": "4e812d8a8265e00b02ee3e350246e53d",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=comodo_ecc_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb",
      "subject": "CN=COMODO ECC Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB",
      "issuer": "CN=COMODO ECC Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB",
      "serial_number": "1f47afaa62007050544c019e9b63992a",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=comodo_rsa_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb",
      "subject": "CN=COMODO RSA Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB",
      "issuer": "CN=COMODO RSA Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB",
      "serial_number": "4caaf9cadb636fe01ff74ed85b03869d",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=d-trust_br_root_ca_1_2020,o=d-trust_gmbh,c=de",
      "subject": "CN=D-TRUST BR Root CA 1 2020,O=D-Trust GmbH,C=DE",
      "issuer": "CN=D-TRUST BR Root CA 1 2020,O=D-Trust GmbH,C=DE",
      "serial_number": "7cc98f2b84d7dfea0fc9659ad34b4d96",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=d-trust_br_root_ca_2_2023,o=d-trust_gmbh,c=de",
      "subject": "CN=D-TRUST BR Root CA 2 2023,O=D-Trust GmbH,C=DE",
      "issuer": "CN=D-TRUST BR Root CA 2 2023,O=D-Trust GmbH,C=DE",
      "serial_number": "733b3004485bd94d782e734bc9a1dc66",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha512WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=d-trust_ev_root_ca_1_2020,o=d-trust_gmbh,c=de",
      "subject": "CN=D-TRUST EV Root CA 1 2020,O=D-Trust GmbH,C=DE",
      "issuer": "CN=D-TRUST EV Root CA 1 2020,O=D-Trust GmbH,C=DE",
      "serial_number": "5f0241d77a877c4c03a3ac968dfbffd0",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=d-trust_ev_root_ca_2_2023,o=d-trust_gmbh,c=de",
      "subject": "CN=D-TRUST EV Root CA 2 2023,O=D-Trust GmbH,C=DE",
      "issuer": "CN=D-TRUST EV Root CA 2 2023,O=D-Trust GmbH,C=DE",
      "serial_number": "6926097e804b4ca0a78c7862535f5a6f",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha512WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=d-trust_root_class_3_ca_2_2009,o=d-trust_gmbh,c=de",
      "subject": "CN=D-TRUST Root Class 3 CA 2 2009,O=D-Trust GmbH,C=DE",
      "issuer": "CN=D-TRUST Root Class 3 CA 2 2009,O=D-Trust GmbH,C=DE",
      "serial_number": "983f3",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=d-trust_root_class_3_ca_2_ev_2009,o=d-trust_gmbh,c=de",
      "subject": "CN=D-TRUST Root Class 3 CA 2 EV 2009,O=D-Trust GmbH,C=DE",
      "issuer": "CN=D-TRUST Root Class 3 CA 2 EV 2009,O=D-Trust GmbH,C=DE",
      "serial_number": "983f4",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_assured_id_root_ca,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert Assured ID Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert Assured ID Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "ce7e0e517d846fe8fe560fc1bf03039",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_assured_id_root_g2,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert Assured ID Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert Assured ID Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "b931c3ad63967ea6723bfc3af9af44b",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_assured_id_root_g3,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert Assured ID Root G3,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert Assured ID Root G3,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "ba15afa1ddfa0b54944afcd24a06cec",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_global_root_ca,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert Global Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert Global Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "83be056904246b1a1756ac95991c74a",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_global_root_g2,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "33af1e6a711a9a0bb2864b11d09fae5",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_global_root_g3,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert Global Root G3,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert Global Root G3,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "55556bcf25ea43535c3a40fd5ab4572",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_high_assurance_ev_root_ca,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert High Assurance EV Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert High Assurance EV Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "2ac5c266a0b409b8f0b79f2ae462577",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_tls_ecc_p384_root_g5,o=digicert__inc.,c=us",
      "subject": "CN=DigiCert TLS ECC P384 Root G5,O=DigiCert\\, Inc.,C=US",
      "issuer": "CN=DigiCert TLS ECC P384 Root G5,O=DigiCert\\, Inc.,C=US",
      "serial_number": "9e09365acf7d9c8b93e1c0b042a2ef3",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_tls_rsa4096_root_g5,o=digicert__inc.,c=us",
      "subject": "CN=DigiCert TLS RSA4096 Root G5,O=DigiCert\\, Inc.,C=US",
      "issuer": "CN=DigiCert TLS RSA4096 Root G5,O=DigiCert\\, Inc.,C=US",
      "serial_number": "8f9b478a8fa7eda6a333789de7ccf8a",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=digicert_trusted_root_g4,ou=www.digicert.com,o=digicert_inc,c=us",
      "subject": "CN=DigiCert Trusted Root G4,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "issuer": "CN=DigiCert Trusted Root G4,OU=www.digicert.com,O=DigiCert Inc,C=US",
      "serial_number": "59b1b579e8e2132e23907bda777755c",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=e-szigno_root_ca_2017,o=microsec_ltd.,l=budapest,c=hu",
      "subject": "CN=e-Szigno Root CA 2017,2.5.4.97=VATHU-23584497,O=Microsec Ltd.,L=Budapest,C=HU",
      "issuer": "CN=e-Szigno Root CA 2017,2.5.4.97=VATHU-23584497,O=Microsec Ltd.,L=Budapest,C=HU",
      "serial_number": "15448ef21fd97590df5040a",
      "key_size": 256,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA256",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=emsign_ecc_root_ca_-_c3,o=emudhra_inc,ou=emsign_pki,c=us",
      "subject": "CN=emSign ECC Root CA - C3,O=eMudhra Inc,OU=emSign PKI,C=US",
      "issuer": "CN=emSign ECC Root CA - C3,O=eMudhra Inc,OU=emSign PKI,C=US",
      "serial_number": "7b71b68256b8127c9ca8",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=emsign_ecc_root_ca_-_g3,o=emudhra_technologies_limited,ou=emsign_pki,c=in",
      "subject": "CN=emSign ECC Root CA - G3,O=eMudhra Technologies Limited,OU=emSign PKI,C=IN",
      "issuer": "CN=emSign ECC Root CA - G3,O=eMudhra Technologies Limited,OU=emSign PKI,C=IN",
      "serial_number": "3cf607a968700eda8b84",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=emsign_root_ca_-_c1,o=emudhra_inc,ou=emsign_pki,c=us",
      "subject": "CN=emSign Root CA - C1,O=eMudhra Inc,OU=emSign PKI,C=US",
      "issuer": "CN=emSign Root CA - C1,O=eMudhra Inc,OU=emSign PKI,C=US",
      "serial_number": "aecf00bac4cf32f843b2",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=emsign_root_ca_-_g1,o=emudhra_technologies_limited,ou=emsign_pki,c=in",
      "subject": "CN=emSign Root CA - G1,O=eMudhra Technologies Limited,OU=emSign PKI,C=IN",
      "issuer": "CN=emSign Root CA - G1,O=eMudhra Technologies Limited,OU=emSign PKI,C=IN",
      "serial_number": "31f5e4620c6c58edd6d8",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=entrust_root_certification_authority,ou=(c)_2006_entrust__inc.,ou=www.entrust.net/cps_is_incorporated_by_reference,o=entrust__inc.,c=us",
      "subject": "CN=Entrust Root Certification Authority,OU=(c) 2006 Entrust\\, Inc.,OU=www.entrust.net/CPS is incorporated by reference,O=Entrust\\, Inc.,C=US",
      "issuer": "CN=Entrust Root Certification Authority,OU=(c) 2006 Entrust\\, Inc.,OU=www.entrust.net/CPS is incorporated by reference,O=Entrust\\, Inc.,C=US",
      "serial_number": "456b5054",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=entrust_root_certification_authority_-_ec1,ou=(c)_2012_entrust__inc._-_for_authorized_use_only,ou=see_www.entrust.net/legal-terms,o=entrust__inc.,c=us",
      "subject": "CN=Entrust Root Certification Authority - EC1,OU=(c) 2012 Entrust\\, Inc. - for authorized use only,OU=See www.entrust.net/legal-terms,O=Entrust\\, Inc.,C=US",
      "issuer": "CN=Entrust Root Certification Authority - EC1,OU=(c) 2012 Entrust\\, Inc. - for authorized use only,OU=See www.entrust.net/legal-terms,O=Entrust\\, Inc.,C=US",
      "serial_number": "a68b79290000000050d091f9",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=entrust_root_certification_authority_-_g2,ou=(c)_2009_entrust__inc._-_for_authorized_use_only,ou=see_www.entrust.net/legal-terms,o=entrust__inc.,c=us",
      "subject": "CN=Entrust Root Certification Authority - G2,OU=(c) 2009 Entrust\\, Inc. - for authorized use only,OU=See www.entrust.net/legal-terms,O=Entrust\\, Inc.,C=US",
      "issuer": "CN=Entrust Root Certification Authority - G2,OU=(c) 2009 Entrust\\, Inc. - for authorized use only,OU=See www.entrust.net/legal-terms,O=Entrust\\, Inc.,C=US",
      "serial_number": "4a538c28",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=firmaprofesional_ca_root-a_web,o=firmaprofesional_sa,c=es",
      "subject": "CN=FIRMAPROFESIONAL CA ROOT-A WEB,2.5.4.97=VATES-A62634068,O=Firmaprofesional SA,C=ES",
      "issuer": "CN=FIRMAPROFESIONAL CA ROOT-A WEB,2.5.4.97=VATES-A62634068,O=Firmaprofesional SA,C=ES",
      "serial_number": "319721edaf89427f354187a167564c6d",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=gdca_trustauth_r5_root,o=guang_dong_certificate_authority_co._ltd.,c=cn",
      "subject": "CN=GDCA TrustAUTH R5 ROOT,O=GUANG DONG CERTIFICATE AUTHORITY CO.\\,LTD.,C=CN",
      "issuer": "CN=GDCA TrustAUTH R5 ROOT,O=GUANG DONG CERTIFICATE AUTHORITY CO.\\,LTD.,C=CN",
      "serial_number": "7d0997fef047ea7a",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=globalsign,o=globalsign,ou=globalsign_ecc_root_ca_-_r4",
      "subject": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign ECC Root CA - R4",
      "issuer": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign ECC Root CA - R4",
      "serial_number": "203e57ef53f93fda50921b2a6",
      "key_size": 256,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA256",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=globalsign,o=globalsign,ou=globalsign_ecc_root_ca_-_r5",
      "subject": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign ECC Root CA - R5",
      "issuer": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign ECC Root CA - R5",
      "serial_number": "605949e0262ebb55f90a778a71f94ad86c",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=globalsign,o=globalsign,ou=globalsign_root_ca_-_r3",
      "subject": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R3",
      "issuer": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R3",
      "serial_number": "4000000000121585308a2",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=globalsign,o=globalsign,ou=globalsign_root_ca_-_r6",
      "subject": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R6",
      "issuer": "CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R6",
      "serial_number": "45e6bb038333c3856548e6ff4551",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=globalsign_root_e46,o=globalsign_nv-sa,c=be",
      "subject": "CN=GlobalSign Root E46,O=GlobalSign nv-sa,C=BE",
      "issuer": "CN=GlobalSign Root E46,O=GlobalSign nv-sa,C=BE",
      "serial_number": "11d2bbba336ed4bce62468c50d841d98e843",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=globalsign_root_r46,o=globalsign_nv-sa,c=be",
      "subject": "CN=GlobalSign Root R46,O=GlobalSign nv-sa,C=BE",
      "issuer": "CN=GlobalSign Root R46,O=GlobalSign nv-sa,C=BE",
      "serial_number": "11d2bbb9d723189e405f0a9d2dd0df2567d1",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=globaltrust_2020,o=e-commerce_monitoring_gmbh,c=at",
      "subject": "CN=GLOBALTRUST 2020,O=e-commerce monitoring GmbH,C=AT",
      "issuer": "CN=GLOBALTRUST 2020,O=e-commerce monitoring GmbH,C=AT",
      "serial_number": "5a4bbd5afb4f8a5bfa65e5",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=go_daddy_root_certificate_authority_-_g2,o=godaddy.com__inc.,l=scottsdale,st=arizona,c=us",
      "subject": "CN=Go Daddy Root Certificate Authority - G2,O=GoDaddy.com\\, Inc.,L=Scottsdale,ST=Arizona,C=US",
      "issuer": "CN=Go Daddy Root Certificate Authority - G2,O=GoDaddy.com\\, Inc.,L=Scottsdale,ST=Arizona,C=US",
      "serial_number": "0",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=gts_root_r1,o=google_trust_services_llc,c=us",
      "subject": "CN=GTS Root R1,O=Google Trust Services LLC,C=US",
      "issuer": "CN=GTS Root R1,O=Google Trust Services LLC,C=US",
      "serial_number": "203e5936f31b01349886ba217",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=gts_root_r2,o=google_trust_services_llc,c=us",
      "subject": "CN=GTS Root R2,O=Google Trust Services LLC,C=US",
      "issuer": "CN=GTS Root R2,O=Google Trust Services LLC,C=US",
      "serial_number": "203e5aec58d04251aab1125aa",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=gts_root_r3,o=google_trust_services_llc,c=us",
      "subject": "CN=GTS Root R3,O=Google Trust Services LLC,C=US",
      "issuer": "CN=GTS Root R3,O=Google Trust Services LLC,C=US",
      "serial_number": "203e5b882eb20f825276d3d66",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=gts_root_r4,o=google_trust_services_llc,c=us",
      "subject": "CN=GTS Root R4,O=Google Trust Services LLC,C=US",
      "issuer": "CN=GTS Root R4,O=Google Trust Services LLC,C=US",
      "serial_number": "203e5c068ef631a9c72905052",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=harica_tls_ecc_root_ca_2021,o=hellenic_academic_and_research_institutions_ca,c=gr",
      "subject": "CN=HARICA TLS ECC Root CA 2021,O=Hellenic Academic and Research Institutions CA,C=GR",
      "issuer": "CN=HARICA TLS ECC Root CA 2021,O=Hellenic Academic and Research Institutions CA,C=GR",
      "serial_number": "67749d8d77d83b6adb22f4ff59e2bfce",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=harica_tls_rsa_root_ca_2021,o=hellenic_academic_and_research_institutions_ca,c=gr",
      "subject": "CN=HARICA TLS RSA Root CA 2021,O=Hellenic Academic and Research Institutions CA,C=GR",
      "issuer": "CN=HARICA TLS RSA Root CA 2021,O=Hellenic Academic and Research Institutions CA,C=GR",
      "serial_number": "39ca931cef43f3c68e93c7f46489387e",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=hellenic_academic_and_research_institutions_ecc_rootca_2015,o=hellenic_academic_and_research_institutions_cert._authority,l=athens,c=gr",
      "subject": "CN=Hellenic Academic and Research Institutions ECC RootCA 2015,O=Hellenic Academic and Research Institutions Cert. Authority,L=Athens,C=GR",
      "issuer": "CN=Hellenic Academic and Research Institutions ECC RootCA 2015,O=Hellenic Academic and Research Institutions Cert. Authority,L=Athens,C=GR",
      "serial_number": "0",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA256",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=hellenic_academic_and_research_institutions_rootca_2015,o=hellenic_academic_and_research_institutions_cert._authority,l=athens,c=gr",
      "subject": "CN=Hellenic Academic and Research Institutions RootCA 2015,O=Hellenic Academic and Research Institutions Cert. Authority,L=Athens,C=GR",
      "issuer": "CN=Hellenic Academic and Research Institutions RootCA 2015,O=Hellenic Academic and Research Institutions Cert. Authority,L=Athens,C=GR",
      "serial_number": "0",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=hipki_root_ca_-_g1,o=chunghwa_telecom_co.__ltd.,c=tw",
      "subject": "CN=HiPKI Root CA - G1,O=Chunghwa Telecom Co.\\, Ltd.,C=TW",
      "issuer": "CN=HiPKI Root CA - G1,O=Chunghwa Telecom Co.\\, Ltd.,C=TW",
      "serial_number": "2dddacce629794a143e8b0cd766a5e60",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=hongkong_post_root_ca_3,o=hongkong_post,l=hong_kong,st=hong_kong,c=hk",
      "subject": "CN=Hongkong Post Root CA 3,O=Hongkong Post,L=Hong Kong,ST=Hong Kong,C=HK",
      "issuer": "CN=Hongkong Post Root CA 3,O=Hongkong Post,L=Hong Kong,ST=Hong Kong,C=HK",
      "serial_number": "8165f8a4ca5ec00c99340dfc4c6ae23b81c5aa4",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=identrust_commercial_root_ca_1,o=identrust,c=us",
      "subject": "CN=IdenTrust Commercial Root CA 1,O=IdenTrust,C=US",
      "issuer": "CN=IdenTrust Commercial Root CA 1,O=IdenTrust,C=US",
      "serial_number": "a0142800000014523c844b500000002",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=identrust_public_sector_root_ca_1,o=identrust,c=us",
      "subject": "CN=IdenTrust Public Sector Root CA 1,O=IdenTrust,C=US",
      "issuer": "CN=IdenTrust Public Sector Root CA 1,O=IdenTrust,C=US",
      "serial_number": "a0142800000014523cf467c00000002",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=isrg_root_x1,o=internet_security_research_group,c=us",
      "subject": "CN=ISRG Root X1,O=Internet Security Research Group,C=US",
      "issuer": "CN=ISRG Root X1,O=Internet Security Research Group,C=US",
      "serial_number": "8210cfb0d240e3594463e0bb63828b00",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=isrg_root_x2,o=internet_security_research_group,c=us",
      "subject": "CN=ISRG Root X2,O=Internet Security Research Group,C=US",
      "issuer": "CN=ISRG Root X2,O=Internet Security Research Group,C=US",
      "serial_number": "41d29dd172eaeea780c12c6ce92f8752",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=izenpe.com,o=izenpe_s.a.,c=es",
      "subject": "CN=Izenpe.com,O=IZENPE S.A.,C=ES",
      "issuer": "CN=Izenpe.com,O=IZENPE S.A.,C=ES",
      "serial_number": "b0b75a16485fbfe1cbf58bd719e67d",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [
          "info@izenpe.com"
        ],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=microsec_e-szigno_root_ca_2009,o=microsec_ltd.,l=budapest,c=hu",
      "subject": "emailAddress=info@e-szigno.hu,CN=Microsec e-Szigno Root CA 2009,O=Microsec Ltd.,L=Budapest,C=HU",
      "issuer": "emailAddress=info@e-szigno.hu,CN=Microsec e-Szigno Root CA 2009,O=Microsec Ltd.,L=Budapest,C=HU",
      "serial_number": "c27e43044e473f19",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [
          "info@e-szigno.hu"
        ],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=microsoft_ecc_root_certificate_authority_2017,o=microsoft_corporation,c=us",
      "subject": "CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US",
      "issuer": "CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,C=US",
      "serial_number": "66f23daf87de8bb14aea0c573101c2ec",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=microsoft_rsa_root_certificate_authority_2017,o=microsoft_corporation,c=us",
      "subject": "CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US",
      "issuer": "CN=Microsoft RSA Root Certificate Authority 2017,O=Microsoft Corporation,C=US",
      "serial_number": "1ed397095fd8b4b347701eaabe7f45b3",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=naver_global_root_certification_authority,o=naver_business_platform_corp.,c=kr",
      "subject": "CN=NAVER Global Root Certification Authority,O=NAVER BUSINESS PLATFORM Corp.,C=KR",
      "issuer": "CN=NAVER Global Root Certification Authority,O=NAVER BUSINESS PLATFORM Corp.,C=KR",
      "serial_number": "194301ea20bddf5c5332ab1434471f8d6504d0d",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=netlock_arany_(class_gold)_f\\c5\\91tan\\c3\\bas\\c3\\adtv\\c3\\a1ny,ou=tan\\c3\\bas\\c3\\adtv\\c3\\a1nykiad\\c3\\b3k_(certification_services),o=netlock_kft.,l=budapest,c=hu",
      "subject": "CN=NetLock Arany (Class Gold) Főtanúsítvány,OU=Tanúsítványkiadók (Certification Services),O=NetLock Kft.,L=Budapest,C=HU",
      "issuer": "CN=NetLock Arany (Class Gold) Főtanúsítvány,OU=Tanúsítványkiadók (Certification Services),O=NetLock Kft.,L=Budapest,C=HU",
      "serial_number": "49412ce40010",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true,
        "path_length": 4
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=oiste_server_root_ecc_g1,o=oiste_foundation,c=ch",
      "subject": "CN=OISTE Server Root ECC G1,O=OISTE Foundation,C=CH",
      "issuer": "CN=OISTE Server Root ECC G1,O=OISTE Foundation,C=CH",
      "serial_number": "23f9c3d635af8f284b1ff054ea7e979d",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=oiste_server_root_rsa_g1,o=oiste_foundation,c=ch",
      "subject": "CN=OISTE Server Root RSA G1,O=OISTE Foundation,C=CH",
      "issuer": "CN=OISTE Server Root RSA G1,O=OISTE Foundation,C=CH",
      "serial_number": "55a5d9679428c6ed0cfa27dd5b014d18",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=oiste_wisekey_global_root_gb_ca,ou=oiste_foundation_endorsed,o=wisekey,c=ch",
      "subject": "CN=OISTE WISeKey Global Root GB CA,OU=OISTE Foundation Endorsed,O=WISeKey,C=CH",
      "issuer": "CN=OISTE WISeKey Global Root GB CA,OU=OISTE Foundation Endorsed,O=WISeKey,C=CH",
      "serial_number": "76b1205274f0858746b3f8231af6c2c0",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=oiste_wisekey_global_root_gc_ca,ou=oiste_foundation_endorsed,o=wisekey,c=ch",
      "subject": "CN=OISTE WISeKey Global Root GC CA,OU=OISTE Foundation Endorsed,O=WISeKey,C=CH",
      "issuer": "CN=OISTE WISeKey Global Root GC CA,OU=OISTE Foundation Endorsed,O=WISeKey,C=CH",
      "serial_number": "212a560caeda0cab4045bf2ba22d3aea",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=quovadis_root_ca_1_g3,o=quovadis_limited,c=bm",
      "subject": "CN=QuoVadis Root CA 1 G3,O=QuoVadis Limited,C=BM",
      "issuer": "CN=QuoVadis Root CA 1 G3,O=QuoVadis Limited,C=BM",
      "serial_number": "78585f2ead2c194be3370735341328b596d46593",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=quovadis_root_ca_2,o=quovadis_limited,c=bm",
      "subject": "CN=QuoVadis Root CA 2,O=QuoVadis Limited,C=BM",
      "issuer": "CN=QuoVadis Root CA 2,O=QuoVadis Limited,C=BM",
      "serial_number": "509",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=quovadis_root_ca_2_g3,o=quovadis_limited,c=bm",
      "subject": "CN=QuoVadis Root CA 2 G3,O=QuoVadis Limited,C=BM",
      "issuer": "CN=QuoVadis Root CA 2 G3,O=QuoVadis Limited,C=BM",
      "serial_number": "445734245b81899b35f2ceb82b3b5ba726f07528",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=quovadis_root_ca_3,o=quovadis_limited,c=bm",
      "subject": "CN=QuoVadis Root CA 3,O=QuoVadis Limited,C=BM",
      "issuer": "CN=QuoVadis Root CA 3,O=QuoVadis Limited,C=BM",
      "serial_number": "5c6",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=quovadis_root_ca_3_g3,o=quovadis_limited,c=bm",
      "subject": "CN=QuoVadis Root CA 3 G3,O=QuoVadis Limited,C=BM",
      "issuer": "CN=QuoVadis Root CA 3 G3,O=QuoVadis Limited,C=BM",
      "serial_number": "2ef59b0228a7db7affd5a3a9eebd03a0cf126a1d",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=sectigo_public_server_authentication_root_e46,o=sectigo_limited,c=gb",
      "subject": "CN=Sectigo Public Server Authentication Root E46,O=Sectigo Limited,C=GB",
      "issuer": "CN=Sectigo Public Server Authentication Root E46,O=Sectigo Limited,C=GB",
      "serial_number": "42f2ccda1b6937445f15fe752810b8f4",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=sectigo_public_server_authentication_root_r46,o=sectigo_limited,c=gb",
      "subject": "CN=Sectigo Public Server Authentication Root R46,O=Sectigo Limited,C=GB",
      "issuer": "CN=Sectigo Public Server Authentication Root R46,O=Sectigo Limited,C=GB",
      "serial_number": "758dfd8bae7c0700faa925a7e1c7ad14",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=secure_global_ca,o=securetrust_corporation,c=us",
      "subject": "CN=Secure Global CA,O=SecureTrust Corporation,C=US",
      "issuer": "CN=Secure Global CA,O=SecureTrust Corporation,C=US",
      "serial_number": "75622a4e8d48a894df413c8f0f8eaa5",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=securesign_root_ca12,o=cybertrust_japan_co.__ltd.,c=jp",
      "subject": "CN=SecureSign Root CA12,O=Cybertrust Japan Co.\\, Ltd.,C=JP",
      "issuer": "CN=SecureSign Root CA12,O=Cybertrust Japan Co.\\, Ltd.,C=JP",
      "serial_number": "66f9c7c1afecc251b4ed5397e6e682c32b1c9016",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=securesign_root_ca14,o=cybertrust_japan_co.__ltd.,c=jp",
      "subject": "CN=SecureSign Root CA14,O=Cybertrust Japan Co.\\, Ltd.,C=JP",
      "issuer": "CN=SecureSign Root CA14,O=Cybertrust Japan Co.\\, Ltd.,C=JP",
      "serial_number": "64db5a0c204ee8d72977c85027a25a27dd2df2cb",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=securesign_root_ca15,o=cybertrust_japan_co.__ltd.,c=jp",
      "subject": "CN=SecureSign Root CA15,O=Cybertrust Japan Co.\\, Ltd.,C=JP",
      "issuer": "CN=SecureSign Root CA15,O=Cybertrust Japan Co.\\, Ltd.,C=JP",
      "serial_number": "1615c7c3d849a7be690c8a88edf070f9ddb73e87",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=securetrust_ca,o=securetrust_corporation,c=us",
      "subject": "CN=SecureTrust CA,O=SecureTrust Corporation,C=US",
      "issuer": "CN=SecureTrust CA,O=SecureTrust Corporation,C=US",
      "serial_number": "cf08e5c0816a5ad427ff0eb271859d0",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=security_communication_ecc_rootca1,o=secom_trust_systems_co._ltd.,c=jp",
      "subject": "CN=Security Communication ECC RootCA1,O=SECOM Trust Systems CO.\\,LTD.,C=JP",
      "issuer": "CN=Security Communication ECC RootCA1,O=SECOM Trust Systems CO.\\,LTD.,C=JP",
      "serial_number": "d65d9bb378812eeb",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ssl.com_ev_root_certification_authority_ecc,o=ssl_corporation,l=houston,st=texas,c=us",
      "subject": "CN=SSL.com EV Root Certification Authority ECC,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "issuer": "CN=SSL.com EV Root Certification Authority ECC,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "serial_number": "2c299c5b16ed0595",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA256",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ssl.com_ev_root_certification_authority_rsa_r2,o=ssl_corporation,l=houston,st=texas,c=us",
      "subject": "CN=SSL.com EV Root Certification Authority RSA R2,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "issuer": "CN=SSL.com EV Root Certification Authority RSA R2,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "serial_number": "56b629cd34bc78f6",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ssl.com_root_certification_authority_ecc,o=ssl_corporation,l=houston,st=texas,c=us",
      "subject": "CN=SSL.com Root Certification Authority ECC,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "issuer": "CN=SSL.com Root Certification Authority ECC,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "serial_number": "75e6dfcbc1685ba8",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA256",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ssl.com_root_certification_authority_rsa,o=ssl_corporation,l=houston,st=texas,c=us",
      "subject": "CN=SSL.com Root Certification Authority RSA,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "issuer": "CN=SSL.com Root Certification Authority RSA,O=SSL Corporation,L=Houston,ST=Texas,C=US",
      "serial_number": "7b2c9bd316803299",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ssl.com_tls_ecc_root_ca_2022,o=ssl_corporation,c=us",
      "subject": "CN=SSL.com TLS ECC Root CA 2022,O=SSL Corporation,C=US",
      "issuer": "CN=SSL.com TLS ECC Root CA 2022,O=SSL Corporation,C=US",
      "serial_number": "1403f5abfb378b17405be243b2a5d1c4",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=ssl.com_tls_rsa_root_ca_2022,o=ssl_corporation,c=us",
      "subject": "CN=SSL.com TLS RSA Root CA 2022,O=SSL Corporation,C=US",
      "issuer": "CN=SSL.com TLS RSA Root CA 2022,O=SSL Corporation,C=US",
      "serial_number": "6fbedaad73bd0840e28b4dbed4f75b91",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=starfield_root_certificate_authority_-_g2,o=starfield_technologies__inc.,l=scottsdale,st=arizona,c=us",
      "subject": "CN=Starfield Root Certificate Authority - G2,O=Starfield Technologies\\, Inc.,L=Scottsdale,ST=Arizona,C=US",
      "issuer": "CN=Starfield Root Certificate Authority - G2,O=Starfield Technologies\\, Inc.,L=Scottsdale,ST=Arizona,C=US",
      "serial_number": "0",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=starfield_services_root_certificate_authority_-_g2,o=starfield_technologies__inc.,l=scottsdale,st=arizona,c=us",
      "subject": "CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\\, Inc.,L=Scottsdale,ST=Arizona,C=US",
      "issuer": "CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\\, Inc.,L=Scottsdale,ST=Arizona,C=US",
      "serial_number": "0",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=swisssign_gold_ca_-_g2,o=swisssign_ag,c=ch",
      "subject": "CN=SwissSign Gold CA - G2,O=SwissSign AG,C=CH",
      "issuer": "CN=SwissSign Gold CA - G2,O=SwissSign AG,C=CH",
      "serial_number": "bb401c43f55e4fb0",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=swisssign_rsa_tls_root_ca_2022_-_1,o=swisssign_ag,c=ch",
      "subject": "CN=SwissSign RSA TLS Root CA 2022 - 1,O=SwissSign AG,C=CH",
      "issuer": "CN=SwissSign RSA TLS Root CA 2022 - 1,O=SwissSign AG,C=CH",
      "serial_number": "43fa0c5f4e1b801844efd1b44f351f44f480edcb",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=szafir_root_ca2,o=krajowa_izba_rozliczeniowa_s.a.,c=pl",
      "subject": "CN=SZAFIR ROOT CA2,O=Krajowa Izba Rozliczeniowa S.A.,C=PL",
      "issuer": "CN=SZAFIR ROOT CA2,O=Krajowa Izba Rozliczeniowa S.A.,C=PL",
      "serial_number": "3e8a5d07ec55d232d5b7e3b65f01eb2ddce4d6e4",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=t-telesec_globalroot_class_2,ou=t-systems_trust_center,o=t-systems_enterprise_services_gmbh,c=de",
      "subject": "CN=T-TeleSec GlobalRoot Class 2,OU=T-Systems Trust Center,O=T-Systems Enterprise Services GmbH,C=DE",
      "issuer": "CN=T-TeleSec GlobalRoot Class 2,OU=T-Systems Trust Center,O=T-Systems Enterprise Services GmbH,C=DE",
      "serial_number": "1",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=t-telesec_globalroot_class_3,ou=t-systems_trust_center,o=t-systems_enterprise_services_gmbh,c=de",
      "subject": "CN=T-TeleSec GlobalRoot Class 3,OU=T-Systems Trust Center,O=T-Systems Enterprise Services GmbH,C=DE",
      "issuer": "CN=T-TeleSec GlobalRoot Class 3,OU=T-Systems Trust Center,O=T-Systems Enterprise Services GmbH,C=DE",
      "serial_number": "1",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=telekom_security_tls_ecc_root_2020,o=deutsche_telekom_security_gmbh,c=de",
      "subject": "CN=Telekom Security TLS ECC Root 2020,O=Deutsche Telekom Security GmbH,C=DE",
      "issuer": "CN=Telekom Security TLS ECC Root 2020,O=Deutsche Telekom Security GmbH,C=DE",
      "serial_number": "363a968cc95cb258cdd0015dc5e55700",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=telekom_security_tls_rsa_root_2023,o=deutsche_telekom_security_gmbh,c=de",
      "subject": "CN=Telekom Security TLS RSA Root 2023,O=Deutsche Telekom Security GmbH,C=DE",
      "issuer": "CN=Telekom Security TLS RSA Root 2023,O=Deutsche Telekom Security GmbH,C=DE",
      "serial_number": "219c542de8f6ec7177fa4ee8c3705797",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=telia_root_ca_v2,o=telia_finland_oyj,c=fi",
      "subject": "CN=Telia Root CA v2,O=Telia Finland Oyj,C=FI",
      "issuer": "CN=Telia Root CA v2,O=Telia Finland Oyj,C=FI",
      "serial_number": "1675f27d6fe7ae3e4acbe095b059e",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=teliasonera_root_ca_v1,o=teliasonera",
      "subject": "CN=TeliaSonera Root CA v1,O=TeliaSonera",
      "issuer": "CN=TeliaSonera Root CA v1,O=TeliaSonera",
      "serial_number": "95be16a0f72e46f17b398272fa8bcd96",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=trustasia_global_root_ca_g3,o=trustasia_technologies__inc.,c=cn",
      "subject": "CN=TrustAsia Global Root CA G3,O=TrustAsia Technologies\\, Inc.,C=CN",
      "issuer": "CN=TrustAsia Global Root CA G3,O=TrustAsia Technologies\\, Inc.,C=CN",
      "serial_number": "64f60e6577616aab3bb4ea8584bbb189b871930f",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=trustasia_global_root_ca_g4,o=trustasia_technologies__inc.,c=cn",
      "subject": "CN=TrustAsia Global Root CA G4,O=TrustAsia Technologies\\, Inc.,C=CN",
      "issuer": "CN=TrustAsia Global Root CA G4,O=TrustAsia Technologies\\, Inc.,C=CN",
      "serial_number": "4f2364b88e97639ec65381c1764ecb2a7415d6d7",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=trustasia_tls_ecc_root_ca,o=trustasia_technologies__inc.,c=cn",
      "subject": "CN=TrustAsia TLS ECC Root CA,O=TrustAsia Technologies\\, Inc.,C=CN",
      "issuer": "CN=TrustAsia TLS ECC Root CA,O=TrustAsia Technologies\\, Inc.,C=CN",
      "serial_number": "3674e14d7c6513c9ac835525a03e527e2f5068c7",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=trustasia_tls_rsa_root_ca,o=trustasia_technologies__inc.,c=cn",
      "subject": "CN=TrustAsia TLS RSA Root CA,O=TrustAsia Technologies\\, Inc.,C=CN",
      "issuer": "CN=TrustAsia TLS RSA Root CA,O=TrustAsia Technologies\\, Inc.,C=CN",
      "serial_number": "1c18d8cfe5533f2235465354243c6c47d15c4a9c",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=trustwave_global_certification_authority,o=trustwave_holdings__inc.,l=chicago,st=illinois,c=us",
      "subject": "CN=Trustwave Global Certification Authority,O=Trustwave Holdings\\, Inc.,L=Chicago,ST=Illinois,C=US",
      "issuer": "CN=Trustwave Global Certification Authority,O=Trustwave Holdings\\, Inc.,L=Chicago,ST=Illinois,C=US",
      "serial_number": "5f70e86da49f346352ebab2",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=trustwave_global_ecc_p256_certification_authority,o=trustwave_holdings__inc.,l=chicago,st=illinois,c=us",
      "subject": "CN=Trustwave Global ECC P256 Certification Authority,O=Trustwave Holdings\\, Inc.,L=Chicago,ST=Illinois,C=US",
      "issuer": "CN=Trustwave Global ECC P256 Certification Authority,O=Trustwave Holdings\\, Inc.,L=Chicago,ST=Illinois,C=US",
      "serial_number": "d6a5f083f285c3e5195df5d",
      "key_size": 256,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA256",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=trustwave_global_ecc_p384_certification_authority,o=trustwave_holdings__inc.,l=chicago,st=illinois,c=us",
      "subject": "CN=Trustwave Global ECC P384 Certification Authority,O=Trustwave Holdings\\, Inc.,L=Chicago,ST=Illinois,C=US",
      "issuer": "CN=Trustwave Global ECC P384 Certification Authority,O=Trustwave Holdings\\, Inc.,L=Chicago,ST=Illinois,C=US",
      "serial_number": "8bd85976c9927a48068473b",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=tubitak_kamu_sm_ssl_kok_sertifikasi_-_surum_1,ou=kamu_sertifikasyon_merkezi_-_kamu_sm,o=turkiye_bilimsel_ve_teknolojik_arastirma_kurumu_-_tubitak,l=gebze_-_kocaeli,c=tr",
      "subject": "CN=TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1,OU=Kamu Sertifikasyon Merkezi - Kamu SM,O=Turkiye Bilimsel ve Teknolojik Arastirma Kurumu - TUBITAK,L=Gebze - Kocaeli,C=TR",
      "issuer": "CN=TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1,OU=Kamu Sertifikasyon Merkezi - Kamu SM,O=Turkiye Bilimsel ve Teknolojik Arastirma Kurumu - TUBITAK,L=Gebze - Kocaeli,C=TR",
      "serial_number": "1",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=tuntrust_root_ca,o=agence_nationale_de_certification_electronique,c=tn",
      "subject": "CN=TunTrust Root CA,O=Agence Nationale de Certification Electronique,C=TN",
      "issuer": "CN=TunTrust Root CA,O=Agence Nationale de Certification Electronique,C=TN",
      "serial_number": "1302d5e2404c92468616675db4bbbbb26b3efc13",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=twca_cyber_root_ca,ou=root_ca,o=taiwan-ca,c=tw",
      "subject": "CN=TWCA CYBER Root CA,OU=Root CA,O=TAIWAN-CA,C=TW",
      "issuer": "CN=TWCA CYBER Root CA,OU=Root CA,O=TAIWAN-CA,C=TW",
      "serial_number": "4001348cc200000000000000013cf2c6",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=twca_global_root_ca,ou=root_ca,o=taiwan-ca,c=tw",
      "subject": "CN=TWCA Global Root CA,OU=Root CA,O=TAIWAN-CA,C=TW",
      "issuer": "CN=TWCA Global Root CA,OU=Root CA,O=TAIWAN-CA,C=TW",
      "serial_number": "cbe",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw",
      "subject": "CN=TWCA Root Certification Authority,OU=Root CA,O=TAIWAN-CA,C=TW",
      "issuer": "CN=TWCA Root Certification Authority,OU=Root CA,O=TAIWAN-CA,C=TW",
      "serial_number": "1",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=uca_extended_validation_root,o=unitrust,c=cn",
      "subject": "CN=UCA Extended Validation Root,O=UniTrust,C=CN",
      "issuer": "CN=UCA Extended Validation Root,O=UniTrust,C=CN",
      "serial_number": "4fd22b8ff564c8339e4f345866237060",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "DigitalSignature",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=uca_global_g2_root,o=unitrust,c=cn",
      "subject": "CN=UCA Global G2 Root,O=UniTrust,C=CN",
      "issuer": "CN=UCA Global G2 Root,O=UniTrust,C=CN",
      "serial_number": "5ddfb1da5aa3ed5dbe5a6520650390ef",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=usertrust_ecc_certification_authority,o=the_usertrust_network,l=jersey_city,st=new_jersey,c=us",
      "subject": "CN=USERTrust ECC Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US",
      "issuer": "CN=USERTrust ECC Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US",
      "serial_number": "5c8b99c55a94c5d27156decd8980cc26",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=usertrust_rsa_certification_authority,o=the_usertrust_network,l=jersey_city,st=new_jersey,c=us",
      "subject": "CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US",
      "issuer": "CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US",
      "serial_number": "1fd6d30fca3ca51a81bbc640e35032d",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha384WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=vtrus_ecc_root_ca,o=itruschina_co._ltd.,c=cn",
      "subject": "CN=vTrus ECC Root CA,O=iTrusChina Co.\\,Ltd.,C=CN",
      "issuer": "CN=vTrus ECC Root CA,O=iTrusChina Co.\\,Ltd.,C=CN",
      "serial_number": "6e6abc59aa53be983967a2d26ba43be66d1cd6da",
      "key_size": 384,
      "key_algo": "EC",
      "ca_flag": true,
      "signature_algorithm": "ecdsa-with-SHA384",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "cn=vtrus_root_ca,o=itruschina_co._ltd.,c=cn",
      "subject": "CN=vTrus Root CA,O=iTrusChina Co.\\,Ltd.,C=CN",
      "issuer": "CN=vTrus Root CA,O=iTrusChina Co.\\,Ltd.,C=CN",
      "serial_number": "43e37113d8b359145db7ce8cfd35fd6fbc058d45",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "ou=ac_raiz_fnmt-rcm,o=fnmt-rcm,c=es",
      "subject": "OU=AC RAIZ FNMT-RCM,O=FNMT-RCM,C=ES",
      "issuer": "OU=AC RAIZ FNMT-RCM,O=FNMT-RCM,C=ES",
      "serial_number": "5d938d306736c8061d1ac754846907",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "ou=certsign_root_ca,o=certsign,c=ro",
      "subject": "OU=certSIGN ROOT CA,O=certSIGN,C=RO",
      "issuer": "OU=certSIGN ROOT CA,O=certSIGN,C=RO",
      "serial_number": "200605167002",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [
        "DigitalSignature",
        "ContentCommitment",
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "ou=certsign_root_ca_g2,o=certsign_sa,c=ro",
      "subject": "OU=certSIGN ROOT CA G2,O=CERTSIGN SA,C=RO",
      "issuer": "OU=certSIGN ROOT CA G2,O=CERTSIGN SA,C=RO",
      "serial_number": "110034b64ec6362d36",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "ou=epki_root_certification_authority,o=chunghwa_telecom_co.__ltd.,c=tw",
      "subject": "OU=ePKI Root Certification Authority,O=Chunghwa Telecom Co.\\, Ltd.,C=TW",
      "issuer": "OU=ePKI Root Certification Authority,O=Chunghwa Telecom Co.\\, Ltd.,C=TW",
      "serial_number": "15c8bd65475cafb897005ee406d2bc9d",
      "key_size": 4096,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha1WithRSA",
      "key_usage": [],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    },
    {
      "type": "CERT",
      "label": "ou=security_communication_rootca2,o=secom_trust_systems_co._ltd.,c=jp",
      "subject": "OU=Security Communication RootCA2,O=SECOM Trust Systems CO.\\,LTD.,C=JP",
      "issuer": "OU=Security Communication RootCA2,O=SECOM Trust Systems CO.\\,LTD.,C=JP",
      "serial_number": "0",
      "key_size": 2048,
      "key_algo": "RSA",
      "ca_flag": true,
      "signature_algorithm": "sha256WithRSA",
      "key_usage": [
        "KeyCertSign",
        "CrlSign"
      ],
      "extended_key_usage": [],
      "subject_alternative_name": {
        "dns": [],
        "ip": [],
        "email": [],
        "uri": []
      },
      "basic_constraints": {
        "present": true,
        "ca": true
      },
      "matched": true
    }
  ],
  "chain_alias": [
    {
      "chain": [
        "c=de,o=atos,cn=atos_trustedroot_2011"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "c=de,o=atos,cn=atos_trustedroot_root_ca_ecc_tls_2021"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "c=de,o=atos,cn=atos_trustedroot_root_ca_rsa_tls_2021"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "c=es,o=accv,ou=pkiaccv,cn=accvraiz1"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ac_raiz_fnmt-rcm_servidores_seguros,ou=ceres,o=fnmt-rcm,c=es"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=actalis_authentication_root_ca,o=actalis_s.p.a./03358520967,l=milan,c=it"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=affirmtrust_commercial,o=affirmtrust,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=affirmtrust_networking,o=affirmtrust,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=affirmtrust_premium,o=affirmtrust,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=affirmtrust_premium_ecc,o=affirmtrust,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=amazon_root_ca_1,o=amazon,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=amazon_root_ca_2,o=amazon,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=amazon_root_ca_3,o=amazon,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=amazon_root_ca_4,o=amazon,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=anf_secure_server_root_ca,ou=anf_ca_raiz,o=anf_autoridad_de_certificacion,c=es"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=autoridad_de_certificacion_firmaprofesional_cif_a62634068,c=es"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=bjca_global_root_ca1,o=beijing_certificate_authority,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=bjca_global_root_ca2,o=beijing_certificate_authority,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=buypass_class_2_root_ca,o=buypass_as-983163327,c=no"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=buypass_class_3_root_ca,o=buypass_as-983163327,c=no"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ca_disig_root_r2,o=disig_a.s.,l=bratislava,c=sk"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certainly_root_e1,o=certainly,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certainly_root_r1,o=certainly,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certigna,o=dhimyotis,c=fr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certigna_root_ca,ou=0002_48146308100036,o=dhimyotis,c=fr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certum_ec-384_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certum_trusted_network_ca,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certum_trusted_network_ca_2,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=certum_trusted_root_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=cfca_ev_root,o=china_financial_certification_authority,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=comodo_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=comodo_ecc_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=comodo_rsa_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=d-trust_br_root_ca_1_2020,o=d-trust_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=d-trust_br_root_ca_2_2023,o=d-trust_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=d-trust_ev_root_ca_1_2020,o=d-trust_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=d-trust_ev_root_ca_2_2023,o=d-trust_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=d-trust_root_class_3_ca_2_2009,o=d-trust_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=d-trust_root_class_3_ca_2_ev_2009,o=d-trust_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_assured_id_root_ca,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_assured_id_root_g2,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_assured_id_root_g3,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_global_root_ca,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_global_root_g2,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_global_root_g3,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_high_assurance_ev_root_ca,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_tls_ecc_p384_root_g5,o=digicert__inc.,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_tls_rsa4096_root_g5,o=digicert__inc.,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=digicert_trusted_root_g4,ou=www.digicert.com,o=digicert_inc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=e-szigno_root_ca_2017,o=microsec_ltd.,l=budapest,c=hu"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=emsign_ecc_root_ca_-_c3,o=emudhra_inc,ou=emsign_pki,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=emsign_ecc_root_ca_-_g3,o=emudhra_technologies_limited,ou=emsign_pki,c=in"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=emsign_root_ca_-_c1,o=emudhra_inc,ou=emsign_pki,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=emsign_root_ca_-_g1,o=emudhra_technologies_limited,ou=emsign_pki,c=in"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=entrust_root_certification_authority,ou=(c)_2006_entrust__inc.,ou=www.entrust.net/cps_is_incorporated_by_reference,o=entrust__inc.,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=entrust_root_certification_authority_-_ec1,ou=(c)_2012_entrust__inc._-_for_authorized_use_only,ou=see_www.entrust.net/legal-terms,o=entrust__inc.,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=entrust_root_certification_authority_-_g2,ou=(c)_2009_entrust__inc._-_for_authorized_use_only,ou=see_www.entrust.net/legal-terms,o=entrust__inc.,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=firmaprofesional_ca_root-a_web,o=firmaprofesional_sa,c=es"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=gdca_trustauth_r5_root,o=guang_dong_certificate_authority_co._ltd.,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=globalsign,o=globalsign,ou=globalsign_ecc_root_ca_-_r4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=globalsign,o=globalsign,ou=globalsign_ecc_root_ca_-_r5"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=globalsign,o=globalsign,ou=globalsign_root_ca_-_r3"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=globalsign,o=globalsign,ou=globalsign_root_ca_-_r6"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=globalsign_root_e46,o=globalsign_nv-sa,c=be"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=globalsign_root_r46,o=globalsign_nv-sa,c=be"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=globaltrust_2020,o=e-commerce_monitoring_gmbh,c=at"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=go_daddy_root_certificate_authority_-_g2,o=godaddy.com__inc.,l=scottsdale,st=arizona,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=gts_root_r1,o=google_trust_services_llc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=gts_root_r2,o=google_trust_services_llc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=gts_root_r3,o=google_trust_services_llc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=gts_root_r4,o=google_trust_services_llc,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=harica_tls_ecc_root_ca_2021,o=hellenic_academic_and_research_institutions_ca,c=gr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=harica_tls_rsa_root_ca_2021,o=hellenic_academic_and_research_institutions_ca,c=gr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=hellenic_academic_and_research_institutions_ecc_rootca_2015,o=hellenic_academic_and_research_institutions_cert._authority,l=athens,c=gr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=hellenic_academic_and_research_institutions_rootca_2015,o=hellenic_academic_and_research_institutions_cert._authority,l=athens,c=gr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=hipki_root_ca_-_g1,o=chunghwa_telecom_co.__ltd.,c=tw"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=hongkong_post_root_ca_3,o=hongkong_post,l=hong_kong,st=hong_kong,c=hk"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=identrust_commercial_root_ca_1,o=identrust,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=identrust_public_sector_root_ca_1,o=identrust,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=isrg_root_x1,o=internet_security_research_group,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=isrg_root_x2,o=internet_security_research_group,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=izenpe.com,o=izenpe_s.a.,c=es"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=microsec_e-szigno_root_ca_2009,o=microsec_ltd.,l=budapest,c=hu"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=microsoft_ecc_root_certificate_authority_2017,o=microsoft_corporation,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=microsoft_rsa_root_certificate_authority_2017,o=microsoft_corporation,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=naver_global_root_certification_authority,o=naver_business_platform_corp.,c=kr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=netlock_arany_(class_gold)_f\\c5\\91tan\\c3\\bas\\c3\\adtv\\c3\\a1ny,ou=tan\\c3\\bas\\c3\\adtv\\c3\\a1nykiad\\c3\\b3k_(certification_services),o=netlock_kft.,l=budapest,c=hu"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=oiste_server_root_ecc_g1,o=oiste_foundation,c=ch"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=oiste_server_root_rsa_g1,o=oiste_foundation,c=ch"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=oiste_wisekey_global_root_gb_ca,ou=oiste_foundation_endorsed,o=wisekey,c=ch"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=oiste_wisekey_global_root_gc_ca,ou=oiste_foundation_endorsed,o=wisekey,c=ch"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=quovadis_root_ca_1_g3,o=quovadis_limited,c=bm"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=quovadis_root_ca_2,o=quovadis_limited,c=bm"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=quovadis_root_ca_2_g3,o=quovadis_limited,c=bm"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=quovadis_root_ca_3,o=quovadis_limited,c=bm"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=quovadis_root_ca_3_g3,o=quovadis_limited,c=bm"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=sectigo_public_server_authentication_root_e46,o=sectigo_limited,c=gb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=sectigo_public_server_authentication_root_r46,o=sectigo_limited,c=gb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=secure_global_ca,o=securetrust_corporation,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=securesign_root_ca12,o=cybertrust_japan_co.__ltd.,c=jp"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=securesign_root_ca14,o=cybertrust_japan_co.__ltd.,c=jp"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=securesign_root_ca15,o=cybertrust_japan_co.__ltd.,c=jp"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=securetrust_ca,o=securetrust_corporation,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=security_communication_ecc_rootca1,o=secom_trust_systems_co._ltd.,c=jp"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ssl.com_ev_root_certification_authority_ecc,o=ssl_corporation,l=houston,st=texas,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ssl.com_ev_root_certification_authority_rsa_r2,o=ssl_corporation,l=houston,st=texas,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ssl.com_root_certification_authority_ecc,o=ssl_corporation,l=houston,st=texas,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ssl.com_root_certification_authority_rsa,o=ssl_corporation,l=houston,st=texas,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ssl.com_tls_ecc_root_ca_2022,o=ssl_corporation,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=ssl.com_tls_rsa_root_ca_2022,o=ssl_corporation,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=starfield_root_certificate_authority_-_g2,o=starfield_technologies__inc.,l=scottsdale,st=arizona,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=starfield_services_root_certificate_authority_-_g2,o=starfield_technologies__inc.,l=scottsdale,st=arizona,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=swisssign_gold_ca_-_g2,o=swisssign_ag,c=ch"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=swisssign_rsa_tls_root_ca_2022_-_1,o=swisssign_ag,c=ch"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=szafir_root_ca2,o=krajowa_izba_rozliczeniowa_s.a.,c=pl"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=t-telesec_globalroot_class_2,ou=t-systems_trust_center,o=t-systems_enterprise_services_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=t-telesec_globalroot_class_3,ou=t-systems_trust_center,o=t-systems_enterprise_services_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=telekom_security_tls_ecc_root_2020,o=deutsche_telekom_security_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=telekom_security_tls_rsa_root_2023,o=deutsche_telekom_security_gmbh,c=de"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=telia_root_ca_v2,o=telia_finland_oyj,c=fi"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=teliasonera_root_ca_v1,o=teliasonera"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=trustasia_global_root_ca_g3,o=trustasia_technologies__inc.,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=trustasia_global_root_ca_g4,o=trustasia_technologies__inc.,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=trustasia_tls_ecc_root_ca,o=trustasia_technologies__inc.,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=trustasia_tls_rsa_root_ca,o=trustasia_technologies__inc.,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=trustwave_global_certification_authority,o=trustwave_holdings__inc.,l=chicago,st=illinois,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=trustwave_global_ecc_p256_certification_authority,o=trustwave_holdings__inc.,l=chicago,st=illinois,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=trustwave_global_ecc_p384_certification_authority,o=trustwave_holdings__inc.,l=chicago,st=illinois,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=tubitak_kamu_sm_ssl_kok_sertifikasi_-_surum_1,ou=kamu_sertifikasyon_merkezi_-_kamu_sm,o=turkiye_bilimsel_ve_teknolojik_arastirma_kurumu_-_tubitak,l=gebze_-_kocaeli,c=tr"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=tuntrust_root_ca,o=agence_nationale_de_certification_electronique,c=tn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=twca_cyber_root_ca,ou=root_ca,o=taiwan-ca,c=tw"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=twca_global_root_ca,ou=root_ca,o=taiwan-ca,c=tw"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=uca_extended_validation_root,o=unitrust,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=uca_global_g2_root,o=unitrust,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=usertrust_ecc_certification_authority,o=the_usertrust_network,l=jersey_city,st=new_jersey,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=usertrust_rsa_certification_authority,o=the_usertrust_network,l=jersey_city,st=new_jersey,c=us"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=vtrus_ecc_root_ca,o=itruschina_co._ltd.,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cn=vtrus_root_ca,o=itruschina_co._ltd.,c=cn"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "ou=ac_raiz_fnmt-rcm,o=fnmt-rcm,c=es"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "ou=certsign_root_ca,o=certsign,c=ro"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "ou=certsign_root_ca_g2,o=certsign_sa,c=ro"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "ou=epki_root_certification_authority,o=chunghwa_telecom_co.__ltd.,c=tw"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "ou=security_communication_rootca2,o=secom_trust_systems_co._ltd.,c=jp"
      ],
      "tag": "(root)"
    }
  ],
  "chain_serial": [
    {
      "chain": [
        "0 (cn=go_daddy_root_certificate_authority_-_g2,o=godaddy.com__inc.,l=scottsdale,st=arizona,c=us)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "0 (cn=hellenic_academic_and_research_institutions_ecc_rootca_2015,o=hellenic_academic_and_research_institutions_cert._authority,l=athens,c=gr)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "0 (cn=hellenic_academic_and_research_institutions_rootca_2015,o=hellenic_academic_and_research_institutions_cert._authority,l=athens,c=gr)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "0 (cn=starfield_root_certificate_authority_-_g2,o=starfield_technologies__inc.,l=scottsdale,st=arizona,c=us)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "0 (cn=starfield_services_root_certificate_authority_-_g2,o=starfield_technologies__inc.,l=scottsdale,st=arizona,c=us)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "0 (ou=security_communication_rootca2,o=secom_trust_systems_co._ltd.,c=jp)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1 (cn=t-telesec_globalroot_class_2,ou=t-systems_trust_center,o=t-systems_enterprise_services_gmbh,c=de)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1 (cn=t-telesec_globalroot_class_3,ou=t-systems_trust_center,o=t-systems_enterprise_services_gmbh,c=de)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1 (cn=tubitak_kamu_sm_ssl_kok_sertifikasi_-_surum_1,ou=kamu_sertifikasyon_merkezi_-_kamu_sm,o=turkiye_bilimsel_ve_teknolojik_arastirma_kurumu_-_tubitak,l=gebze_-_kocaeli,c=tr)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1 (cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "110034b64ec6362d36"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "11d2bbb9d723189e405f0a9d2dd0df2567d1"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "11d2bbba336ed4bce62468c50d841d98e843"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1302d5e2404c92468616675db4bbbbb26b3efc13"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1403f5abfb378b17405be243b2a5d1c4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "15448ef21fd97590df5040a"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "15c8bd65475cafb897005ee406d2bc9d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1615c7c3d849a7be690c8a88edf070f9ddb73e87"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1675f27d6fe7ae3e4acbe095b059e"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "184accd6"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "194301ea20bddf5c5332ab1434471f8d6504d0d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1b70e9d2ffae6c71"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1c18d8cfe5533f2235465354243c6c47d15c4a9c"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1ebf5950b8c980374c06f7eb554fb5ed"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1ed397095fd8b4b347701eaabe7f45b3"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1f47afaa62007050544c019e9b63992a"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "1fd6d30fca3ca51a81bbc640e35032d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "2 (cn=buypass_class_2_root_ca,o=buypass_as-983163327,c=no)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "2 (cn=buypass_class_3_root_ca,o=buypass_as-983163327,c=no)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "200605167002"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "203e57ef53f93fda50921b2a6"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "203e5936f31b01349886ba217"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "203e5aec58d04251aab1125aa"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "203e5b882eb20f825276d3d66"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "203e5c068ef631a9c72905052"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "212a560caeda0cab4045bf2ba22d3aea"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "219c542de8f6ec7177fa4ee8c3705797"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "21d6d04a4f250fc93237fcaa5e128de9"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "23f9c3d635af8f284b1ff054ea7e979d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "2ac5c266a0b409b8f0b79f2ae462577"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "2c17087d642ac0fe85185906cfb44aeb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "2c299c5b16ed0595"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "2dddacce629794a143e8b0cd766a5e60"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "2ef59b0228a7db7affd5a3a9eebd03a0cf126a1d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "319721edaf89427f354187a167564c6d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "31f5e4620c6c58edd6d8"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "33af1e6a711a9a0bb2864b11d09fae5"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "363a968cc95cb258cdd0015dc5e55700"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "3674e14d7c6513c9ac835525a03e527e2f5068c7"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "39ca931cef43f3c68e93c7f46489387e"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "3cf607a968700eda8b84"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "3d983ba6663d9063f77e26573804ef00"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "3e8a5d07ec55d232d5b7e3b65f01eb2ddce4d6e4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "4000000000121585308a2"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "4001348cc200000000000000013cf2c6"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "41d29dd172eaeea780c12c6ce92f8752"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "42f2ccda1b6937445f15fe752810b8f4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "43e37113d8b359145db7ce8cfd35fd6fbc058d45"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "43fa0c5f4e1b801844efd1b44f351f44f480edcb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "444c0"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "445734245b81899b35f2ceb82b3b5ba726f07528"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "456b5054"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "45e6bb038333c3856548e6ff4551"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "49412ce40010"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "4a538c28"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "4caaf9cadb636fe01ff74ed85b03869d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "4e812d8a8265e00b02ee3e350246e53d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "4f2364b88e97639ec65381c1764ecb2a7415d6d7"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "4fd22b8ff564c8339e4f345866237060"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "509 (cn=quovadis_root_ca_2,o=quovadis_limited,c=bm)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "53d5cfe619930bfb2b0512d8c22aa2a4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "55556bcf25ea43535c3a40fd5ab4572"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "556f65e3b4d9906a1b09d16c3ec06c20"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "55a5d9679428c6ed0cfa27dd5b014d18"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "56b629cd34bc78f6"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "570a119742c4e3cc"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "59b1b579e8e2132e23907bda777755c"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5a4bbd5afb4f8a5bfa65e5"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5c33cb622c5fb332"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5c6 (cn=quovadis_root_ca_3,o=quovadis_limited,c=bm)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5c8b99c55a94c5d27156decd8980cc26"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5d938d306736c8061d1ac754846907"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5ddfb1da5aa3ed5dbe5a6520650390ef"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5ec3b7a6437fa4e0"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5f0241d77a877c4c03a3ac968dfbffd0"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "5f70e86da49f346352ebab2"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "605949e0262ebb55f90a778a71f94ad86c"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "62533b1470333275cf98d9ab9bfccf8"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "62f6326ce5c4e3685c1b62dd9c2e9d95"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "64db5a0c204ee8d72977c85027a25a27dd2df2cb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "64f60e6577616aab3bb4ea8584bbb189b871930f"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "66c9fcf99bf8c0a39e2f0788a43e696365bca"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "66c9fd29635869f0a0fe58678f85b26bb8a37"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "66c9fd5749736663f3b0b9ad9e89e7603f24a"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "66c9fd7c1bb104c2943e5717b7b2cc81ac10e"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "66f23daf87de8bb14aea0c573101c2ec"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "66f9c7c1afecc251b4ed5397e6e682c32b1c9016"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "67749d8d77d83b6adb22f4ff59e2bfce"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "6926097e804b4ca0a78c7862535f5a6f"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "6d8c1446b1a60aee"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "6e6abc59aa53be983967a2d26ba43be66d1cd6da"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "6fbedaad73bd0840e28b4dbed4f75b91"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "733b3004485bd94d782e734bc9a1dc66"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "7497258ac73f7a54"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "75622a4e8d48a894df413c8f0f8eaa5"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "758dfd8bae7c0700faa925a7e1c7ad14"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "75e6dfcbc1685ba8"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "76b1205274f0858746b3f8231af6c2c0"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "7777062726a9b17c"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "78585f2ead2c194be3370735341328b596d46593"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "788f275c81125220a504d02dddba73f4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "7b2c9bd316803299"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "7b71b68256b8127c9ca8"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "7c4f04391cd4992d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "7cc98f2b84d7dfea0fc9659ad34b4d96"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "7d0997fef047ea7a"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "8165f8a4ca5ec00c99340dfc4c6ae23b81c5aa4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "8210cfb0d240e3594463e0bb63828b00"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "83be056904246b1a1756ac95991c74a"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "8bd85976c9927a48068473b"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "8e0ff94b907168653354f4d44439b7e0"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "8f9b478a8fa7eda6a333789de7ccf8a"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "92b888dbb08ac163"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "95be16a0f72e46f17b398272fa8bcd96"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "983f3"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "983f4"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "9e09365acf7d9c8b93e1c0b042a2ef3"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "a0142800000014523c844b500000002"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "a0142800000014523cf467c00000002"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "a68b79290000000050d091f9"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "aecf00bac4cf32f843b2"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "b0b75a16485fbfe1cbf58bd719e67d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "b931c3ad63967ea6723bfc3af9af44b"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "ba15afa1ddfa0b54944afcd24a06cec"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "bb401c43f55e4fb0"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "c27e43044e473f19"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cae91b89f155030da3e6416dc4e3a6e1"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cbe (cn=twca_global_root_ca,ou=root_ca,o=taiwan-ca,c=tw)"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "ce7e0e517d846fe8fe560fc1bf03039"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "cf08e5c0816a5ad427ff0eb271859d0"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "d65d9bb378812eeb"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "d6a5f083f285c3e5195df5d"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "dd3e3bc6cf96bb1"
      ],
      "tag": "(root)"
    },
    {
      "chain": [
        "fedce3010fc948ff"
      ],
      "tag": "(root)"
    }
  ],
  "warnings": [
    "⚠️ Warning: Certificate 4 Alias: c=es,o=accv,ou=pkiaccv,cn=accvraiz1 Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 8 Alias: cn=affirmtrust_networking,o=affirmtrust,c=us Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 24 Alias: cn=certigna,o=dhimyotis,c=fr Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 27 Alias: cn=certum_trusted_network_ca,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 31 Alias: cn=comodo_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 40 Alias: cn=digicert_assured_id_root_ca,ou=www.digicert.com,o=digicert_inc,c=us Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 43 Alias: cn=digicert_global_root_ca,ou=www.digicert.com,o=digicert_inc,c=us Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 46 Alias: cn=digicert_high_assurance_ev_root_ca,ou=www.digicert.com,o=digicert_inc,c=us Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 55 Alias: cn=entrust_root_certification_authority,ou=(c)_2006_entrust__inc.,ou=www.entrust.net/cps_is_incorporated_by_reference,o=entrust__inc.,c=us Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 93 Alias: cn=quovadis_root_ca_2,o=quovadis_limited,c=bm Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 95 Alias: cn=quovadis_root_ca_3,o=quovadis_limited,c=bm Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 99 Alias: cn=secure_global_ca,o=securetrust_corporation,c=us Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 103 Alias: cn=securetrust_ca,o=securetrust_corporation,c=us Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 113 Alias: cn=swisssign_gold_ca_-_g2,o=swisssign_ag,c=ch Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 121 Alias: cn=teliasonera_root_ca_v1,o=teliasonera Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 133 Alias: cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 141 Alias: ou=certsign_root_ca,o=certsign,c=ro Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update.",
    "⚠️ Warning: Certificate 143 Alias: ou=epki_root_certification_authority,o=chunghwa_telecom_co.__ltd.,c=tw Detail: uses the SHA1withRSA signature algorithm, which is considered a security risk and will be disabled in a future update."
  ],
  "errors": [
    "❌ Error: Certificate 28 Alias: cn=certum_trusted_network_ca_2,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl Detail: uses the sha512 signature algorithm, which requires manual verification for this environment.",
    "❌ Error: Certificate 29 Alias: cn=certum_trusted_root_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl Detail: uses the sha512 signature algorithm, which requires manual verification for this environment.",
    "❌ Error: Certificate 35 Alias: cn=d-trust_br_root_ca_2_2023,o=d-trust_gmbh,c=de Detail: uses the sha512 signature algorithm, which requires manual verification for this environment.",
    "❌ Error: Certificate 37 Alias: cn=d-trust_ev_root_ca_2_2023,o=d-trust_gmbh,c=de Detail: uses the sha512 signature algorithm, which requires manual verification for this environment."
  ],
  "action_items": [
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "c=es,o=accv,ou=pkiaccv,cn=accvraiz1",
      "serial": "5ec3b7a6437fa4e0",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"c=es,o=accv,ou=pkiaccv,cn=accvraiz1\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"c=es,o=accv,ou=pkiaccv,cn=accvraiz1\" -file \"<new_c=es,o=accv,ou=pkiaccv,cn=accvraiz1.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=affirmtrust_networking,o=affirmtrust,c=us",
      "serial": "7c4f04391cd4992d",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=affirmtrust_networking,o=affirmtrust,c=us\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=affirmtrust_networking,o=affirmtrust,c=us\" -file \"<new_cn=affirmtrust_networking,o=affirmtrust,c=us.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=certigna,o=dhimyotis,c=fr",
      "serial": "fedce3010fc948ff",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certigna,o=dhimyotis,c=fr\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certigna,o=dhimyotis,c=fr\" -file \"<new_cn=certigna,o=dhimyotis,c=fr.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=certum_trusted_network_ca,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl",
      "serial": "444c0",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certum_trusted_network_ca,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certum_trusted_network_ca,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl\" -file \"<new_cn=certum_trusted_network_ca,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl.crt>\" -trustcacerts"
    },
    {
      "priority": 1,
      "severity": "CRITICAL",
      "category": "ALGORITHM",
      "alias": "cn=certum_trusted_network_ca_2,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl",
      "serial": "21d6d04a4f250fc93237fcaa5e128de9",
      "message": "sha512 signature algorithm — manual verification required",
      "action": "Replace certificate using SHA256withRSA or stronger.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certum_trusted_network_ca_2,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certum_trusted_network_ca_2,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl\" -file \"<new_cn=certum_trusted_network_ca_2,ou=certum_certification_authority,o=unizeto_technologies_s.a.,c=pl.crt>\" -trustcacerts"
    },
    {
      "priority": 1,
      "severity": "CRITICAL",
      "category": "ALGORITHM",
      "alias": "cn=certum_trusted_root_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl",
      "serial": "1ebf5950b8c980374c06f7eb554fb5ed",
      "message": "sha512 signature algorithm — manual verification required",
      "action": "Replace certificate using SHA256withRSA or stronger.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certum_trusted_root_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=certum_trusted_root_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl\" -file \"<new_cn=certum_trusted_root_ca,ou=certum_certification_authority,o=asseco_data_systems_s.a.,c=pl.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=comodo_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb",
      "serial": "4e812d8a8265e00b02ee3e350246e53d",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=comodo_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=comodo_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb\" -file \"<new_cn=comodo_certification_authority,o=comodo_ca_limited,l=salford,st=greater_manchester,c=gb.crt>\" -trustcacerts"
    },
    {
      "priority": 1,
      "severity": "CRITICAL",
      "category": "ALGORITHM",
      "alias": "cn=d-trust_br_root_ca_2_2023,o=d-trust_gmbh,c=de",
      "serial": "733b3004485bd94d782e734bc9a1dc66",
      "message": "sha512 signature algorithm — manual verification required",
      "action": "Replace certificate using SHA256withRSA or stronger.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=d-trust_br_root_ca_2_2023,o=d-trust_gmbh,c=de\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=d-trust_br_root_ca_2_2023,o=d-trust_gmbh,c=de\" -file \"<new_cn=d-trust_br_root_ca_2_2023,o=d-trust_gmbh,c=de.crt>\" -trustcacerts"
    },
    {
      "priority": 1,
      "severity": "CRITICAL",
      "category": "ALGORITHM",
      "alias": "cn=d-trust_ev_root_ca_2_2023,o=d-trust_gmbh,c=de",
      "serial": "6926097e804b4ca0a78c7862535f5a6f",
      "message": "sha512 signature algorithm — manual verification required",
      "action": "Replace certificate using SHA256withRSA or stronger.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=d-trust_ev_root_ca_2_2023,o=d-trust_gmbh,c=de\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=d-trust_ev_root_ca_2_2023,o=d-trust_gmbh,c=de\" -file \"<new_cn=d-trust_ev_root_ca_2_2023,o=d-trust_gmbh,c=de.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=digicert_assured_id_root_ca,ou=www.digicert.com,o=digicert_inc,c=us",
      "serial": "ce7e0e517d846fe8fe560fc1bf03039",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=digicert_assured_id_root_ca,ou=www.digicert.com,o=digicert_inc,c=us\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=digicert_assured_id_root_ca,ou=www.digicert.com,o=digicert_inc,c=us\" -file \"<new_cn=digicert_assured_id_root_ca,ou=www.digicert.com,o=digicert_inc,c=us.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=digicert_global_root_ca,ou=www.digicert.com,o=digicert_inc,c=us",
      "serial": "83be056904246b1a1756ac95991c74a",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=digicert_global_root_ca,ou=www.digicert.com,o=digicert_inc,c=us\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=digicert_global_root_ca,ou=www.digicert.com,o=digicert_inc,c=us\" -file \"<new_cn=digicert_global_root_ca,ou=www.digicert.com,o=digicert_inc,c=us.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=digicert_high_assurance_ev_root_ca,ou=www.digicert.com,o=digicert_inc,c=us",
      "serial": "2ac5c266a0b409b8f0b79f2ae462577",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=digicert_high_assurance_ev_root_ca,ou=www.digicert.com,o=digicert_inc,c=us\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=digicert_high_assurance_ev_root_ca,ou=www.digicert.com,o=digicert_inc,c=us\" -file \"<new_cn=digicert_high_assurance_ev_root_ca,ou=www.digicert.com,o=digicert_inc,c=us.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=entrust_root_certification_authority,ou=(c)_2006_entrust__inc.,ou=www.entrust.net/cps_is_incorporated_by_reference,o=entrust__inc.,c=us",
      "serial": "456b5054",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=entrust_root_certification_authority,ou=(c)_2006_entrust__inc.,ou=www.entrust.net/cps_is_incorporated_by_reference,o=entrust__inc.,c=us\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=entrust_root_certification_authority,ou=(c)_2006_entrust__inc.,ou=www.entrust.net/cps_is_incorporated_by_reference,o=entrust__inc.,c=us\" -file \"<new_cn=entrust_root_certification_authority,ou=(c)_2006_entrust__inc.,ou=www.entrust.net/cps_is_incorporated_by_reference,o=entrust__inc.,c=us.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=quovadis_root_ca_2,o=quovadis_limited,c=bm",
      "serial": "509",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=quovadis_root_ca_2,o=quovadis_limited,c=bm\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=quovadis_root_ca_2,o=quovadis_limited,c=bm\" -file \"<new_cn=quovadis_root_ca_2,o=quovadis_limited,c=bm.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=quovadis_root_ca_3,o=quovadis_limited,c=bm",
      "serial": "5c6",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=quovadis_root_ca_3,o=quovadis_limited,c=bm\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=quovadis_root_ca_3,o=quovadis_limited,c=bm\" -file \"<new_cn=quovadis_root_ca_3,o=quovadis_limited,c=bm.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=secure_global_ca,o=securetrust_corporation,c=us",
      "serial": "75622a4e8d48a894df413c8f0f8eaa5",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=secure_global_ca,o=securetrust_corporation,c=us\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=secure_global_ca,o=securetrust_corporation,c=us\" -file \"<new_cn=secure_global_ca,o=securetrust_corporation,c=us.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=securetrust_ca,o=securetrust_corporation,c=us",
      "serial": "cf08e5c0816a5ad427ff0eb271859d0",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=securetrust_ca,o=securetrust_corporation,c=us\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=securetrust_ca,o=securetrust_corporation,c=us\" -file \"<new_cn=securetrust_ca,o=securetrust_corporation,c=us.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=swisssign_gold_ca_-_g2,o=swisssign_ag,c=ch",
      "serial": "bb401c43f55e4fb0",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=swisssign_gold_ca_-_g2,o=swisssign_ag,c=ch\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=swisssign_gold_ca_-_g2,o=swisssign_ag,c=ch\" -file \"<new_cn=swisssign_gold_ca_-_g2,o=swisssign_ag,c=ch.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=teliasonera_root_ca_v1,o=teliasonera",
      "serial": "95be16a0f72e46f17b398272fa8bcd96",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=teliasonera_root_ca_v1,o=teliasonera\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=teliasonera_root_ca_v1,o=teliasonera\" -file \"<new_cn=teliasonera_root_ca_v1,o=teliasonera.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw",
      "serial": "1",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw\" -file \"<new_cn=twca_root_certification_authority,ou=root_ca,o=taiwan-ca,c=tw.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "ou=certsign_root_ca,o=certsign,c=ro",
      "serial": "200605167002",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"ou=certsign_root_ca,o=certsign,c=ro\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"ou=certsign_root_ca,o=certsign,c=ro\" -file \"<new_ou=certsign_root_ca,o=certsign,c=ro.crt>\" -trustcacerts"
    },
    {
      "priority": 2,
      "severity": "WARNING",
      "category": "ALGORITHM",
      "alias": "ou=epki_root_certification_authority,o=chunghwa_telecom_co.__ltd.,c=tw",
      "serial": "15c8bd65475cafb897005ee406d2bc9d",
      "message": "SHA1withRSA — deprecated, will be disabled",
      "action": "Plan migration to SHA256withRSA at next renewal.",
      "deadline": null,
      "cmd": "keytool -delete -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"ou=epki_root_certification_authority,o=chunghwa_telecom_co.__ltd.,c=tw\"\n        keytool -importcert -keystore \"C:\\Tools\\jdk-25.0.3+9\\lib\\security\\cacerts\" -alias \"ou=epki_root_certification_authority,o=chunghwa_telecom_co.__ltd.,c=tw\" -file \"<new_ou=epki_root_certification_authority,o=chunghwa_telecom_co.__ltd.,c=tw.crt>\" -trustcacerts"
    }
  ]
}