Code Monkey home page Code Monkey logo

certaintls.app's Introduction

CertainTLS

A “trusted certificate checker” … which would determine whether a device’s OS and/or applications is trusting root TLS certs it shouldn’t. Automated tests

Problem statement

Online HTTPS communications (e.g. via a browser) with an online service such as Facebook or Gmail are normally end-to-end-encrypted using TLS. But the security this system provides depends on the TLS public cert presented by the remote service being “good,” which in turn depends on it being “anchored” to a trusted cert—which depends on the anchor being trustworthy. But if the end user is trusting a “bad” root cert (for whatever reason), a monster-in-the-middle attack (MitM) will be able to read and decrypt their web traffic, inject fake content in real time, and harvest credentials, thereby nullifying the security the end user believed they had. How can a user know whether the root certs they're trusting are all “good”?

How does CertainTLS work?

CertainTLS consists of two parts: a multi-platform app, and a back-end server. The server periodically aggregates the "canonical" root certificates from the Google Android pipeline, Apple MacOS pipeline, Microsoft Windows pipline and Mozilla Mozilla pipeline certificate authority programs. CertainTLS's back end then analyzes these certificates and marks the ones from certificate authorities (CAs) in the countries whose Freedom in the World score's lower than 40 as untrustworthy. The CertainTLS app scans both the root certificates shipped by the OS and user-installed trusted root certificates, then validates each of them against the CertainTLS back end's "source of truth," and displays the result in the app, i.e. flagging root certs which are being trusted but maybe shouldn't be. The app also supports OSes' specific way to distrust certificates. Due to different security models and the app's limitation as a "third-party tool" in different OSes, CertainTLS currently supports Android, macOS, and Windows, but not (yet?) iOS, and the app's functionality on each platform differs slightly. For more information about which features are supported on each platform, please see here.

The impetus to develop CertainTLS came from inter alia the (allegedly Iranian) 2011 DigiNotar hack, China's 2015 Great Cannon (not a root cert problem but, more generally, an authoritarian government's willingness to force domestic private actors to compromise the internet's security), and the 2019 middling (by the КНБ) of all access to ~250 key foreign sites (including Facebook and Gmail) by all netizens using Kazakhstan's biggest ISP in that country's capital—supposedly "a test," but, well ...

Download the app

From the trusted distribution channel (recommended):

Get it on Google Play

From github.com CertainTLS releases:

Download directly

Download Windows version Certaintls Windowns release 1.4.3.zip

Download MacOS version Certaintls Mac release 1.4.1.zip

Contribution guidline

You are invited to contribute new features, fixes, or updates, large or small; we are always thrilled to receive pull requests, and do our best to process them as fast as we can. Besides the code, a reproducible bug report or documentation improvement is also welcome. To start filing bugs or asking questions, please use the CertainTLS app's GitHub issues. You are also welcomed to submit your feedback or suggestion to [email protected].

Technical documentation

Privacy Policy

Read the CertainTLS privacy policy

Sponsorship

Creation of CertainTLS was underwritten by the USAID-funded Information Safety & Capacity Project (ISC) via a grant to Counterpart International, an international NGO working in the civil society development sector. The ISC supports internet freedom by improving the defensive cybersecurity capabilities of local partners (rights-defending activists, journalists) in developing countries.

certaintls.app's People

Contributors

certaintls avatar

Stargazers

 avatar  avatar  avatar

Watchers

 avatar  avatar

certaintls.app's Issues

Parse Windows CertUtil output

The output doesn't have PEM section.

Root "Trusted Root Certification Authorities"
================ Certificate 0 ================
X509 Certificate:
Version: 3
Serial Number: 79ad16a14aa0a5ad4c7358f407132e65
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.5 sha1RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Microsoft Root Certificate Authority
    DC=microsoft
    DC=com
  Name Hash(sha1): c35f66c9a07c78a3f82b876f15d832cbd21fdb33
  Name Hash(md5): f0c402f0404ea9adbf25a03ddf2ca6fa

 NotBefore: 5/10/2001 7:19 AM
 NotAfter: 5/10/2021 7:28 AM

Subject:
    CN=Microsoft Root Certificate Authority
    DC=microsoft
    DC=com
  Name Hash(sha1): c35f66c9a07c78a3f82b876f15d832cbd21fdb33
  Name Hash(md5): f0c402f0404ea9adbf25a03ddf2ca6fa

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA
    Algorithm Parameters:
    05 00
Public Key Length: 4096 bits
Public Key: UnusedBits = 0
    0000  30 82 02 0a 02 82 02 01  00 f3 5d fa 80 67 d4 5a
    0010  a7 a9 0c 2c 90 20 d0 35  08 3c 75 84 cd b7 07 89
    0020  9c 89 da de ce c3 60 fa  91 68 5a 9e 94 71 29 18
    0030  76 7c c2 e0 c8 25 76 94  0e 58 fa 04 34 36 e6 df
    0040  af f7 80 ba e9 58 0b 2b  93 e5 9d 05 e3 77 22 91
    0050  f7 34 64 3c 22 91 1d 5e  e1 09 90 bc 14 fe fc 75
    0060  58 19 e1 79 b7 07 92 a3  ae 88 59 08 d8 9f 07 ca
    0070  03 58 fc 68 29 6d 32 d7  d2 a8 cb 4b fc e1 0b 48
    0080  32 4f e6 eb b8 ad 4f e4  5c 6f 13 94 99 db 95 d5
    0090  75 db a8 1a b7 94 91 b4  77 5b f5 48 0c 8f 6a 79
    00a0  7d 14 70 04 7d 6d af 90  f5 da 70 d8 47 b7 bf 9b
    00b0  2f 6c e7 05 b7 e1 11 60  ac 79 91 14 7c c5 d6 a6
    00c0  e4 e1 7e d5 c3 7e e5 92  d2 3c 00 b5 36 82 de 79
    00d0  e1 6d f3 b5 6e f8 9f 33  c9 cb 52 7d 73 98 36 db
    00e0  8b a1 6b a2 95 97 9b a3  de c2 4d 26 ff 06 96 67
    00f0  25 06 c8 e7 ac e4 ee 12  33 95 31 99 c8 35 08 4e
    0100  34 ca 79 53 d5 b5 be 63  32 59 40 36 c0 a5 4e 04
    0110  4d 3d db 5b 07 33 e4 58  bf ef 3f 53 64 d8 42 59
    0120  35 57 fd 0f 45 7c 24 04  4d 9e d6 38 74 11 97 22
    0130  90 ce 68 44 74 92 6f d5  4b 6f b0 86 e3 c7 36 42
    0140  a0 d0 fc c1 c0 5a f9 a3  61 b9 30 47 71 96 0a 16
    0150  b0 91 c0 42 95 ef 10 7f  28 6a e3 2a 1f b1 e4 cd
    0160  03 3f 77 71 04 c7 20 fc  49 0f 1d 45 88 a4 d7 cb
    0170  7e 88 ad 8e 2d ec 45 db  c4 51 04 c9 2a fc ec 86
    0180  9e 9a 11 97 5b de ce 53  88 e6 e2 b7 fd ac 95 c2
    0190  28 40 db ef 04 90 df 81  33 39 d9 b2 45 a5 23 87
    01a0  06 a5 55 89 31 bb 06 2d  60 0e 41 18 7d 1f 2e b5
    01b0  97 cb 11 eb 15 d5 24 a5  94 ef 15 14 89 fd 4b 73
    01c0  fa 32 5b fc d1 33 00 f9  59 62 70 07 32 ea 2e ab
    01d0  40 2d 7b ca dd 21 67 1b  30 99 8f 16 aa 23 a8 41
    01e0  d1 b0 6e 11 9b 36 c4 de  40 74 9c e1 58 65 c1 60
    01f0  1e 7a 5b 38 c8 8f bb 04  26 7c d4 16 40 e5 b6 6b
    0200  6c aa 86 fd 00 bf ce c1  35 02 03 01 00 01
Certificate Extensions: 4
    2.5.29.15: Flags = 0, Length = 4
    Key Usage
        Digital Signature, Non-Repudiation, Certificate Signing, Off-line CRL Signing, CRL Signing (c6)

    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.29.14: Flags = 0, Length = 16
    Subject Key Identifier
        0eac826040562797e52513fc2ae10a539559e4a4

    1.3.6.1.4.1.311.21.1: Flags = 0, Length = 3
    CA Version
        V0.0

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.5 sha1RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  da b0 3f 77 43 99 9d a1  d1 fd 4a 9d 6b 8a fd c3
    0010  e0 3d c9 21 14 21 6e 3d  92 30 4d 04 f8 9f 6d 96
    0020  ca 7d 2f a5 69 62 64 13  73 db 9e 6c 7e 33 75 85
    0030  a1 e6 8d 89 fb 10 c8 9f  88 30 d9 2b 43 c1 2b 0a
    0040  52 5a 82 9e 7f d8 fe a3  2e eb 7d 12 89 bd 69 3c
    0050  14 5b 70 71 30 f5 87 35  29 de dd 26 49 31 c4 8f
    0060  58 e7 d8 2e 6e 57 62 a2  93 b6 ec 7c 1d 6b 64 c0
    0070  68 56 08 f3 d9 db 25 b6  84 43 ea 00 22 6e 3e e6
    0080  59 5f d3 22 31 d7 e1 58  97 f9 42 a0 95 9d 56 db
    0090  ce fd ef 96 76 ef d5 bb  cf d7 18 f5 97 9e a5 ec
    00a0  47 81 08 03 24 12 24 7e  f3 67 7c 6d 25 20 38 ce
    00b0  cb 37 29 9c f1 a2 68 43  14 3b 3d f0 29 f2 2d 92
    00c0  30 b7 f2 6b 10 22 66 9c  12 f5 94 a2 66 51 bf aa
    00d0  e2 38 c1 62 64 1d 6a 56  85 f2 7b 5b 36 a2 38 13
    00e0  39 b8 17 63 bd f7 c0 0c  d7 eb da 7a e5 b2 78 69
    00f0  2f ff da a0 c9 d0 84 36  12 19 c3 69 d7 2d 6b 89
    0100  c1 b0 06 b9 1d 55 88 e2  39 34 5a 62 3a 9e 93 de
    0110  f5 bd 90 59 5f 33 9d 72  28 99 aa 87 24 3b 8d d0
    0120  68 9b 0c bc 82 10 b2 be  70 6b 11 9d b7 00 4b 2b
    0130  27 24 01 20 28 6c 51 c2  a7 3d b2 30 99 5d aa a2
    0140  f7 4b 94 ca e1 b5 30 e8  b6 4d 6b b8 63 d8 f2 3d
    0150  68 ed 03 95 7e 23 0e 6d  d0 13 a5 b3 56 6c 71 60
    0160  89 20 e3 be bb ec bd aa  5b a8 27 9a 92 39 05 d4
    0170  17 4d e5 3a 62 51 1b 95  3b 54 d4 36 16 ce 06 13
    0180  fc 0f 03 63 ed 37 a0 39  7a 7d af 50 bf ab 64 d2
    0190  54 6f 33 6c 8d 4b 85 4e  2e 05 6d e4 1f 0f 0d 84
    01a0  4e 5a af ff 00 53 51 fe  26 a3 0d 12 30 0e 33 4c
    01b0  38 6c 3e 1b c4 36 34 66  ac 74 59 ac 78 cd 19 df
    01c0  ac e9 c3 cc 6e b8 d2 bc  a0 68 50 a9 d6 5f 26 b1
    01d0  04 f1 55 d2 57 26 6f 47  9a d4 63 c8 b6 35 13 06
    01e0  fa 22 1c b6 03 13 5c 9d  20 d8 a8 b7 b4 bf 05 b2
    01f0  c8 36 bb b2 8f 77 11 52  5d dd 60 3a 03 4d 11 c5
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): dc6c94d3de8780a9f343d940faa3f717d931de3f
Key Id Hash(sha1): 0eac826040562797e52513fc2ae10a539559e4a4
Key Id Hash(bcrypt-sha1): 4262744205ad1c46fe848575840c243180b66caa
Key Id Hash(bcrypt-sha256): 6539fd29e311baa6850942463e4aa686b151271ceed8558273b57464e4a40625
Key Id Hash(md5): 983b132635b7e91deef54a6780c09269
Key Id Hash(sha256): 60bded75c5fd119010d6832f76defc393473d7a0ce64fbd68daba29bfd0b2f7c
Key Id Hash(pin-sha256): 31MLrJ/NkUwlLC+9zt3GGD1K6MaArWXwPiBIYd17HHM=
Key Id Hash(pin-sha256-hex): df530bac9fcd914c252c2fbdceddc6183d4ae8c680ad65f03e204861dd7b1c73
Cert Hash(md5): e1c07ea0aabbd4b77b84c228117808a7
Cert Hash(sha1): cdd4eeae6000ac7f40c3802c171e30148030c072
Cert Hash(sha256): 885de64c340e3ea70658f01e1145f957fcda27aabeea1ab9faa9fdb0102d4077
Signature Hash: 391be92883d52509155bfeae27b9bd340170b76b

  CERT_MD5_HASH_PROP_ID(4):
    e1c07ea0aabbd4b77b84c228117808a7

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    0eac826040562797e52513fc2ae10a539559e4a4

  CERT_ROOT_PROGRAM_CHAIN_POLICIES_PROP_ID(105):
    Enhanced Key Usage
        Unknown Key Usage (1.3.6.1.4.1.311.60.3.2)

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft Root Certificate Authority

  CERT_SHA1_HASH_PROP_ID(3):
    cdd4eeae6000ac7f40c3802c171e30148030c072

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
    391be92883d52509155bfeae27b9bd340170b76b

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    983b132635b7e91deef54a6780c09269

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00001000 (4096)

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 1 ================
X509 Certificate:
Version: 3
Serial Number: 00
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Thawte Timestamping CA
    OU=Thawte Certification
    O=Thawte
    L=Durbanville
    S=Western Cape
    C=ZA
  Name Hash(sha1): 09d5304b06b43d3a73c75cf55a59bf3b33190d96
  Name Hash(md5): 6454a4aa36f9b5cc8338e5a67fabff17

 NotBefore: 1/1/1997 8:00 AM
 NotAfter: 1/1/2021 7:59 AM

Subject:
    CN=Thawte Timestamping CA
    OU=Thawte Certification
    O=Thawte
    L=Durbanville
    S=Western Cape
    C=ZA
  Name Hash(sha1): 09d5304b06b43d3a73c75cf55a59bf3b33190d96
  Name Hash(md5): 6454a4aa36f9b5cc8338e5a67fabff17

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA (RSA_SIGN)
    Algorithm Parameters:
    05 00
Public Key Length: 1024 bits
Public Key: UnusedBits = 0
    0000  30 81 89 02 81 81 00 d6  2b 58 78 61 45 86 53 ea
    0010  34 7b 51 9c ed b0 e6 2e  18 0e fe e0 5f a8 27 d3
    0020  b4 c9 e0 7c 59 4e 16 0e  73 54 60 c1 7f f6 9f 2e
    0030  e9 3a 85 24 15 3c db 47  04 63 c3 9e c4 94 1a 5a
    0040  df 4c 7a f3 d9 43 1d 3c  10 7a 79 25 db 90 fe f0
    0050  51 e7 30 d6 41 00 fd 9f  28 df 79 be 94 bb 9d b6
    0060  14 e3 23 85 d7 a9 41 e0  4c a4 79 b0 2b 1a 8b f2
    0070  f8 3b 8a 3e 45 ac 71 92  00 b4 90 41 98 fb 5f ed
    0080  fa b7 2e 8a f8 88 37 02  03 01 00 01
Certificate Extensions: 1
    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  d3 49 89 ac 09 19 19 50  b1 fc ca 28 af 38 14 30
    0010  01 58 b7 91 84 03 85 8b  31 13 54 74 32 0a 10 7b
    0020  a9 e5 dd 5c bf ec 68 1c  d3 9c 16 42 94 27 cd fc
    0030  fa 77 9e 00 a6 90 dc 79  33 9b 27 b5 cb c1 35 f0
    0040  c3 76 e5 27 e3 db 7b b6  88 5b de e7 b9 4a 6f 94
    0050  b0 e4 5e c6 69 ef d7 f4  3e 36 4d d0 8a 05 a2 cb
    0060  bf 0d 08 10 f5 c2 86 89  04 aa ba a8 20 66 0c c3
    0070  9a ce 1f 7d 35 37 86 83  40 3d 87 e6 c2 e2 db 67
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): c2eefd17d7feb70fc672227b7ef6c0e20233ec3e
Key Id Hash(sha1): ddbcbd869c3f07ed40e31b08efcec4d188cd3b15
Key Id Hash(bcrypt-sha1): 1e07d73817aa69ec96c3dd319b54b703c1dd829e
Key Id Hash(bcrypt-sha256): 831263e1546ba58ce5cee7c01ce7611b959d2471d8475bf591c96a2e7ce4b8f9
Key Id Hash(md5): 181c2be05851f96993e196f279954b23
Key Id Hash(sha256): e0713b2c83f07e6c0c5640ffc949f104548e502e30e0304c3edff7caed76d117
Key Id Hash(pin-sha256): qzh2w9pd4MnPZzaGjuW4i/m6Hf+cnXLS/lqNL3gwIWY=
Key Id Hash(pin-sha256-hex): ab3876c3da5de0c9cf6736868ee5b88bf9ba1dff9c9d72d2fe5a8d2f78302166
Cert Hash(md5): 7f667a71d3eb6978209a51149d83da20
Cert Hash(sha1): be36a4562fb2ee05dbb3d32323adf445084ed656
Cert Hash(sha256): 6b6c1e01f590f5afc5fcf85cd0b9396884048659fc2c6d1170d68b045216c3fd
Signature Hash: e8a598be84828efeae701115013576b2

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
    e8a598be84828efeae701115013576b2

  CERT_MD5_HASH_PROP_ID(4):
    7f667a71d3eb6978209a51149d83da20

  CERT_SHA1_HASH_PROP_ID(3):
    be36a4562fb2ee05dbb3d32323adf445084ed656

  CERT_ENHKEY_USAGE_PROP_ID(9):
    Enhanced Key Usage
        Time Stamping (1.3.6.1.5.5.7.3.8)

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Thawte Timestamping CA

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    181c2be05851f96993e196f279954b23

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    ddbcbd869c3f07ed40e31b08efcec4d188cd3b15

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00000400 (1024)

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 2 ================
X509 Certificate:
Version: 3
Serial Number: c1008b3c3c8811d13ef663ecdf40
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Microsoft Root Authority
    OU=Microsoft Corporation
    OU=Copyright (c) 1997 Microsoft Corp.
  Name Hash(sha1): 6f7079ad4e270737dfc7a4ffdb99e352e74937cc
  Name Hash(md5): 6c6fe103005e9dda7f0d5b92f8ca4a40

 NotBefore: 1/10/1997 3:00 PM
 NotAfter: 12/31/2020 3:00 PM

Subject:
    CN=Microsoft Root Authority
    OU=Microsoft Corporation
    OU=Copyright (c) 1997 Microsoft Corp.
  Name Hash(sha1): 6f7079ad4e270737dfc7a4ffdb99e352e74937cc
  Name Hash(md5): 6c6fe103005e9dda7f0d5b92f8ca4a40

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA (RSA_SIGN)
    Algorithm Parameters:
    05 00
Public Key Length: 2048 bits
Public Key: UnusedBits = 0
    0000  30 82 01 0a 02 82 01 01  00 a9 02 bd c1 70 e6 3b
    0010  f2 4e 1b 28 9f 97 78 5e  30 ea a2 a9 8d 25 5f f8
    0020  fe 95 4c a3 b7 fe 9d a2  20 3e 7c 51 a2 9b a2 8f
    0030  60 32 6b d1 42 64 79 ee  ac 76 c9 54 da f2 eb 9c
    0040  86 1c 8f 9f 84 66 b3 c5  6b 7a 62 23 d6 1d 3c de
    0050  0f 01 92 e8 96 c4 bf 2d  66 9a 9a 68 26 99 d0 3a
    0060  2c bf 0c b5 58 26 c1 46  e7 0a 3e 38 96 2c a9 28
    0070  39 a8 ec 49 83 42 e3 84  0f bb 9a 6c 55 61 ac 82
    0080  7c a1 60 2d 77 4c e9 99  b4 64 3b 9a 50 1c 31 08
    0090  24 14 9f a9 e7 91 2b 18  e6 3d 98 63 14 60 58 05
    00a0  65 9f 1d 37 52 87 f7 a7  ef 94 02 c6 1b d3 bf 55
    00b0  45 b3 89 80 bf 3a ec 54  94 4e ae fd a7 7a 6d 74
    00c0  4e af 18 cc 96 09 28 21  00 57 90 60 69 37 bb 4b
    00d0  12 07 3c 56 ff 5b fb a4  66 0a 08 a6 d2 81 56 57
    00e0  ef b6 3b 5e 16 81 77 04  da f6 be ae 80 95 fe b0
    00f0  cd 7f d6 a7 1a 72 5c 3c  ca bc f0 08 a3 22 30 b3
    0100  06 85 c9 b3 20 77 13 85  df 02 03 01 00 01
Certificate Extensions: 1
    2.5.29.1: Flags = 0, Length = 9a
    Authority Key Identifier
        KeyID=5bd070ef69729e23517e14b24d8effcb
        Certificate Issuer:
             CN=Microsoft Root Authority
             OU=Microsoft Corporation
             OU=Copyright (c) 1997 Microsoft Corp.
        Certificate SerialNumber=00c1008b3c3c8811d13ef663ecdf40

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  a0 d2 a7 9f 75 93 87 3a  12 db 70 a6 55 1c cd 46
    0010  3f 54 d5 d3 8c a2 0a b7  62 0d 1c 4d 6e 38 33 5a
    0020  c8 04 45 a8 e4 04 1c d4  e1 35 db 6a 1b 6a 35 a8
    0030  12 41 e0 8a 36 d2 c1 3f  6a d0 00 a0 76 e3 77 a8
    0040  e4 7a e4 2c 37 ab c5 97  b8 7e 8f 08 f0 d6 90 ff
    0050  12 28 03 b4 b6 54 52 c7  49 65 ee 57 c8 dd b1 f4
    0060  5b b4 03 e0 80 f1 a5 02  1d d5 4d 1a 29 95 1d 88
    0070  09 31 20 fc 30 c4 e7 bd  c7 52 f1 bd f6 51 0d 6c
    0080  67 e5 f8 17 82 fd 07 32  43 6e ac 52 f3 15 d6 c9
    0090  21 f9 1c 54 f7 a3 63 0f  25 8a 12 a1 65 be 2d 25
    00a0  37 2b c8 19 aa af 7b 62  ea 4f 20 5a 11 e3 43 d0
    00b0  fc c0 69 18 4f 12 fe bb  6a 70 10 9f 3d 8d 31 dd
    00c0  7c 05 de aa cc c9 3f 6d  24 fe 69 54 36 a9 5a 3b
    00d0  3b cc d7 fc ef 62 c8 47  a0 b5 2c 93 57 f0 f2 21
    00e0  e6 3a c9 8f 88 91 05 3e  cb 0b 9e 9f 32 60 5c f3
    00f0  11 77 d8 24 01 b8 ed 35  18 97 f3 8d c0 0b e8 95
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): f244bbf1c303761b7defe61cefab3068f461d5cd
Key Id Hash(sha1): 4a5c7522aa46bfa4089d39974ebdb4a360f7a01d
Key Id Hash(bcrypt-sha1): 7a2273267dbeecae74d490df504167bef709fb59
Key Id Hash(bcrypt-sha256): d223c42177b934f2be32ab5b0e5fb5dd6bb3ab5c8bd51f4cb4b1401d567c5228
Key Id Hash(md5): 3fc8cb0bc05241e58d65e9448b2d07c2
Key Id Hash(sha256): ee09b07a85e8f24a01ef631ae671fef8dea8015a09a715e6a67390119092b816
Key Id Hash(pin-sha256): RGLBB8SF3WpUQ/XnoWBEFgNKN0w/TRCHXxw3FQJ1Y68=
Key Id Hash(pin-sha256-hex): 4462c107c485dd6a5443f5e7a1604416034a374c3f4d10875f1c3715027563af
Cert Hash(md5): 2a954eca79b2874573d92d90baf99fb6
Cert Hash(sha1): a43489159a520f0d93d032ccaf37e7fe20a8b419
Cert Hash(sha256): f38406e540d7a9d90cb4a9479299640ffb6df9e224ecc7a01c0d9558d8dad77d
Signature Hash: 8b3c3087b7056f5ec5ddba91a1b901f0

  CERT_MD5_HASH_PROP_ID(4):
    2a954eca79b2874573d92d90baf99fb6

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    4a5c7522aa46bfa4089d39974ebdb4a360f7a01d

  CERT_SHA1_HASH_PROP_ID(3):
    a43489159a520f0d93d032ccaf37e7fe20a8b419

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft Root Authority

  CERT_ROOT_PROGRAM_CHAIN_POLICIES_PROP_ID(105):
    Enhanced Key Usage
        Unknown Key Usage (1.3.6.1.4.1.311.60.3.2)

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
    8b3c3087b7056f5ec5ddba91a1b901f0

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    3fc8cb0bc05241e58d65e9448b2d07c2

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00000800 (2048)

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 3 ================
X509 Certificate:
Version: 3
Serial Number: 0f6b552f9ebf907b0f6629a9bdf4d8ce
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Symantec Enterprise Mobile Root for Microsoft
    O=Symantec Corporation
    C=US
  Name Hash(sha1): a4b17b528bf21ec3f32e7553cd13bb66f8bb533e
  Name Hash(md5): 2d5c4f086672f79a961516b2adcb1316

 NotBefore: 3/15/2012 8:00 AM
 NotAfter: 3/15/2032 7:59 AM

Subject:
    CN=Symantec Enterprise Mobile Root for Microsoft
    O=Symantec Corporation
    C=US
  Name Hash(sha1): a4b17b528bf21ec3f32e7553cd13bb66f8bb533e
  Name Hash(md5): 2d5c4f086672f79a961516b2adcb1316

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA
    Algorithm Parameters:
    05 00
Public Key Length: 2048 bits
Public Key: UnusedBits = 0
    0000  30 82 01 0a 02 82 01 01  00 b5 3d b0 72 ee 91 e9
    0010  a5 69 9c 11 4d 7a f9 b3  fa 3d f2 94 9b 23 b7 a6
    0020  03 ec 62 18 fc 85 12 22  fe c1 71 7d 54 93 b9 91
    0030  7d 62 f6 ca a8 38 15 65  f8 77 3d e5 82 20 3a d4
    0040  b5 d1 6e 8d 06 49 bd df  82 0e 24 85 e7 ef 78 2d
    0050  18 f2 e0 0b 68 46 3e 24  10 c8 57 ee 0e 6d 71 a6
    0060  d3 b1 56 1c d7 29 d5 b2  ea 54 05 0a a8 3c a1 b8
    0070  25 52 07 05 a0 df e7 dc  ee 5c 3b 41 b5 ab 5c 33
    0080  32 d2 ce eb e9 96 f8 40  f4 0a ba 33 1d f8 56 03
    0090  09 82 f5 67 07 c4 c0 34  c1 5d fc 45 bb ea 3c 9a
    00a0  d5 74 71 6d d5 86 d3 c2  fc 85 bc 54 eb a3 d5 f2
    00b0  4f d5 45 af 57 bc f0 22  c0 8f a2 45 c8 75 34 77
    00c0  de a1 6d 37 72 b3 73 8d  0c 6b 53 ba 59 e1 a8 3e
    00d0  80 57 d2 5f 59 ee 68 75  cf 81 9c a3 ca 45 8c 37
    00e0  db 05 72 34 1c 32 02 f8  d5 f9 2c 0d da 58 9e c4
    00f0  17 b4 9b c9 90 c4 88 59  3f 71 91 90 44 18 be 22
    0100  8b 79 92 2e 42 b0 8b 97  5b 02 03 01 00 01
Certificate Extensions: 4
    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.29.15: Flags = 1(Critical), Length = 4
    Key Usage
        Certificate Signing, Off-line CRL Signing, CRL Signing (06)

    2.5.29.17: Flags = 0, Length = 20
    Subject Alternative Name
        Directory Address:
             CN=MPKI-2048-1-111

    2.5.29.14: Flags = 0, Length = 16
    Subject Key Identifier
        4decdf2606dc2410c0b699f4d739c76f19f82628

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  88 25 14 12 e4 ed 97 c8  4b b1 fe 24 f8 27 39 bf
    0010  bf 88 f7 da f3 a5 1b 80  e1 82 9c da 4c 17 5e 77
    0020  2c 07 0b be 1c 9e 9c e9  ca 32 23 a0 73 35 08 09
    0030  92 90 f2 f1 a5 b4 cf ed  49 7d 8c 61 e2 04 c7 ec
    0040  4c 80 d8 18 e4 43 f6 e4  38 50 35 f6 d1 01 99 08
    0050  6a f9 7d fe 10 a7 c5 01  9f 1b b8 5a 21 a7 c0 ce
    0060  c4 df 55 bb e8 38 74 0c  a9 7d ac 39 51 7b a4 76
    0070  4a 1a 5b e8 9d 7b 11 7b  d0 5e 65 70 7c fc ed 32
    0080  b3 f1 fa 2b ab fa e0 3a  89 0b 19 d9 69 4f e2 05
    0090  b0 a6 71 de 60 a8 f4 76  1c 91 2d 40 f4 e2 94 a4
    00a0  97 29 f0 85 44 fa 0e fa  9f 0e 4f 41 23 df 09 fc
    00b0  77 26 64 e4 da 87 0f 86  8a 98 7f 5b 34 1c 50 1d
    00c0  e0 eb 45 9b 2e f4 bb e1  7a 45 7e 78 f2 5e 14 e8
    00d0  6e 6d a3 38 cb 5f 2f bd  c0 19 6a a2 bc fe c9 43
    00e0  5c 73 46 f1 35 f3 f1 b4  31 a3 88 e4 81 1d 3a d8
    00f0  5b 2a 6a 0c 54 79 c7 af  46 14 54 01 d0 59 57 a9
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): 4decdf2606dc2410c0b699f4d739c76f19f82628
Key Id Hash(sha1): 5cb869fe8defc1ed6627eeb2120f721bb80a0e04
Key Id Hash(bcrypt-sha1): 4189a5b3c75f42e44d99e640bffbae8836fd7357
Key Id Hash(bcrypt-sha256): 580066a527458260a133d740dbcfca0b6a91cee1b06e5cd519ed7986a2eb2ab8
Key Id Hash(md5): c8b53318bff7f689dfea6bfc3fd79372
Key Id Hash(sha256): 0c09f8cfec303687f96411f10e3f042344679bb6fb1a98986e5dd596473b4a3c
Key Id Hash(pin-sha256): XE8oU4jzgzYmmlXHwSwLPKc/7ypaTfgriRQehBpsTeQ=
Key Id Hash(pin-sha256-hex): 5c4f285388f38336269a55c7c12c0b3ca73fef2a5a4df82b89141e841a6c4de4
Cert Hash(md5): 71d0a5ff2d59741694bee37d1e5c860b
Cert Hash(sha1): 92b46c76e13054e104f230517e6e504d43ab10b5
Cert Hash(sha256): 8a5e4881d42f7475e8ec3726fcd5e51884aa04daa9fa7adac8cd26452cf885d4
Signature Hash: 5753d57d68f332262c4cc2e5ef76848e03ddc8212c34c757087c2aa7e320a946

  CERT_SIGN_HASH_CNG_ALG_PROP_ID(89):
    RSA/SHA256

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    c8b53318bff7f689dfea6bfc3fd79372

  CERT_SHA256_HASH_PROP_ID(107):
 8a5e4881d42f7475e8ec3726fcd5e51884aa04daa9fa7adac8cd26452cf885d4

  CERT_SHA1_HASH_PROP_ID(3):
    92b46c76e13054e104f230517e6e504d43ab10b5

  CERT_MD5_HASH_PROP_ID(4):
    71d0a5ff2d59741694bee37d1e5c860b

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
 5753d57d68f332262c4cc2e5ef76848e03ddc8212c34c757087c2aa7e320a946

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    4decdf2606dc2410c0b699f4d739c76f19f82628

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00000800 (2048)

  CERT_ENHKEY_USAGE_PROP_ID(9):
    Enhanced Key Usage
        Code Signing (1.3.6.1.5.5.7.3.3)

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 4 ================
X509 Certificate:
Version: 3
Serial Number: 3f8bc8b5fc9fb29643b569d66c42e144
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Microsoft Root Certificate Authority 2011
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): 1c1374c7b3d6941d5b9071b8ad089db1597b730a
  Name Hash(md5): eeb61628d6a59948d98a184ddd6861c0

 NotBefore: 3/23/2011 6:05 AM
 NotAfter: 3/23/2036 6:13 AM

Subject:
    CN=Microsoft Root Certificate Authority 2011
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): 1c1374c7b3d6941d5b9071b8ad089db1597b730a
  Name Hash(md5): eeb61628d6a59948d98a184ddd6861c0

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA
    Algorithm Parameters:
    05 00
Public Key Length: 4096 bits
Public Key: UnusedBits = 0
    0000  30 82 02 0a 02 82 02 01  00 b2 80 41 aa 35 38 4d
    0010  13 72 32 68 22 4d b8 b2  f1 ff d5 52 bc 6c c7 f5
    0020  d2 4a 8c 36 ee d1 c2 5c  7e 8c 8a ae af 13 28 6f
    0030  c0 73 e3 3a ce d0 25 a8  5a 3a 6d ef a8 b8 59 ab
    0040  13 23 68 cd 0c 29 87 d1  6f 80 5c 8f 44 7f 5d 90
    0050  01 52 58 ac 51 c5 5f 2a  87 dc dc d8 0a 1d c1 03
    0060  b9 7b b0 56 e8 a3 de 64  61 c2 9e f8 f3 7c b9 ec
    0070  0d b5 54 fe 4c b6 65 4f  88 f0 9c 48 99 0c 42 0b
    0080  09 7c 31 59 17 79 06 78  28 8d 89 3a 4c 03 25 be
    0090  71 6a 5c 0b e7 84 60 a4  99 22 e3 d2 af 84 a4 a7
    00a0  fb d1 98 ed 0c a9 de 94  89 e1 0e a0 dc c0 ce 99
    00b0  3d ea 08 52 bb 56 79 e4  1f 84 ba 1e b8 b4 c4 49
    00c0  5c 4f 31 4b 87 dd dd 05  67 26 99 80 e0 71 11 a3
    00d0  b8 a5 41 e2 a4 53 b9 f7  32 29 83 0c 13 bf 36 5e
    00e0  04 b3 4b 43 47 2f 6b e2  91 1e d3 98 4f dd 42 07
    00f0  c8 e8 1d 12 fc 99 a9 6b  3e 92 7e c8 d6 69 3a fc
    0100  64 bd b6 09 9d ca fd 0c  0b a2 9b 77 60 4b 03 94
    0110  a4 30 69 12 d6 42 2d c1  41 4c ca dc aa fd 8f 5b
    0120  83 46 9a d9 fc b1 d1 e3  b3 c9 7f 48 7a cd 24 f0
    0130  41 8f 5c 74 d0 ac b0 10  20 06 49 b7 c7 2d 21 c8
    0140  57 e3 d0 86 f3 03 68 fb  d0 ce 71 c1 89 99 4a 64
    0150  01 6c fd ec 30 91 cf 41  3c 92 c7 e5 ba 86 1d 61
    0160  84 c7 5f 83 39 62 ae b4  92 2f 47 f3 0b f8 55 eb
    0170  a0 1f 59 d0 bb 74 9b 1e  d0 76 e6 f2 e9 06 d7 10
    0180  e8 fa 64 de 69 c6 35 96  88 02 f0 46 b8 3f 27 99
    0190  6f cb 71 89 29 35 f7 48  16 02 35 8f d5 79 7c 4d
    01a0  02 cf 5f eb 8a 83 4f 45  71 88 f9 a9 0d 4e 72 e9
    01b0  c2 9c 07 cf 49 1b 4e 04  0e 63 51 8c 5e d8 00 c1
    01c0  55 2c b6 c6 e0 c2 65 4e  c9 34 39 f5 9c b3 c4 7e
    01d0  e8 61 6e 13 5f 15 c4 5f  d9 7e ed 1d ce ee 44 ec
    01e0  cb 2e 86 b1 ec 38 f6 70  ed ab 5c 13 c1 d9 0f 0d
    01f0  c7 80 b2 55 ed 34 f7 ac  9b e4 c3 da e7 47 3c a6
    0200  b5 8f 31 df c5 4b af eb  f1 02 03 01 00 01
Certificate Extensions: 4
    2.5.29.15: Flags = 0, Length = 4
    Key Usage
        Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)

    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.29.14: Flags = 0, Length = 16
    Subject Key Identifier
        722d3a02319043b914054ee1eaa7c731d1238934

    1.3.6.1.4.1.311.21.1: Flags = 0, Length = 3
    CA Version
        V0.0

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  47 54 ac 0f c7 1e c0 b8  17 49 10 22 65 ec 54 95
    0010  ad 6c b7 4e 84 63 38 1a  55 bb c5 a5 ef f4 dc 1f
    0020  48 10 82 ab d1 2a 89 8c  70 29 98 3d 6a 0a d5 1d
    0030  c6 34 1d b9 bd 8e 52 3c  13 9d 37 81 e0 f0 eb ce
    0040  3b 87 e6 6e 4a df a4 3a  3c 50 36 a7 a3 1c c7 28
    0050  a2 be 61 96 9a 05 66 d6  ca dd 89 52 fc e1 6d cb
    0060  e7 32 66 3c 12 7d 1e 38  92 6f 37 a1 76 63 13 31
    0070  cd aa d2 73 71 9a d9 08  4a 0a a4 99 37 43 28 e6
    0080  d0 4e d1 bf d1 e9 01 05  47 19 99 8c f1 00 48 cd
    0090  2b 80 09 77 0d 37 dd af  22 34 35 93 f6 32 09 f8
    00a0  3f 01 e5 83 b0 6b 8c ae  3b d4 5c 12 2b eb 58 c9
    00b0  4d 92 dc d1 a4 38 b2 72  86 90 78 df 1d dc 93 3b
    00c0  4c 70 b2 49 67 67 d4 26  aa 35 f0 a8 4b bb 75 8e
    00d0  4f bc 88 81 d7 e1 4e e9  3a b7 52 ee ec b6 d6 57
    00e0  b3 51 4f 67 55 43 c7 1e  51 9e fe 0b ac 72 ab b0
    00f0  26 2f ea 17 8f 9c ac cc  9f f6 82 ca e8 01 52 80
    0100  75 b4 4c 7d 29 91 b6 47  ac ab 01 0b 54 d2 12 49
    0110  33 b9 09 56 d8 ec 00 4e  e9 3b 92 c7 36 c8 14 00
    0120  9f 2a 73 ea 25 02 e5 2f  db 86 59 50 e0 33 79 a2
    0130  d3 a0 73 1c 8b 03 20 23  66 b5 45 96 87 9d 15 62
    0140  64 a6 79 08 ba 69 40 b5  57 5b 58 29 80 7c 93 6c
    0150  7a cb 5e 85 9b 66 92 c5  2c cb fb a4 38 c3 e8 a4
    0160  50 6e 87 5c 0b c5 d4 5e  d8 1c 97 db 06 00 4b bd
    0170  22 21 0f 3f d7 84 a7 5e  24 bf bb 14 06 3d c3 21
    0180  70 2d aa 81 dd 8b 7e 92  08 6d 0c 17 a8 6b 4f 0d
    0190  cc 67 c3 c5 93 74 5e 54  37 7e c9 7f 15 a6 75 87
    01a0  e9 a1 c9 71 e5 b5 95 09  ed e8 aa 51 6c 18 fe 11
    01b0  8f 89 7e f1 fb 9a 57 53  b4 4b 86 36 a9 40 4b 2f
    01c0  10 d1 56 24 21 39 40 57  3f fd 09 e6 03 24 81 13
    01d0  9e 91 b8 e5 b0 41 c2 a3  3a a9 ef ac a0 97 d7 ed
    01e0  ae 19 ae b3 4d 3f 4b f2  5f 97 db d2 f0 d3 e6 13
    01f0  9e fe 5b 26 ca 49 c0 9b  db 15 c5 b7 0f cf 72 7f
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): 722d3a02319043b914054ee1eaa7c731d1238934
Key Id Hash(sha1): 6a47a267c92e2f19688b9b86616695edc12c1300
Key Id Hash(bcrypt-sha1): 7f12e54fb8e49b3d19002a236e45c4c60fb5b565
Key Id Hash(bcrypt-sha256): 3a5247dc903026b743063f980961f945206bd7911777eea95968716e1e039939
Key Id Hash(md5): bb048f1838395f6fc3a1f3d2b7e97654
Key Id Hash(sha256): 4abb0594d303ef7077138834ab315e941e963093e05b4b14af5dcb527712c00a
Key Id Hash(pin-sha256): AjdtCQisIwQcx9Zm2drxklVPf8NjF6qcuACQhhayivg=
Key Id Hash(pin-sha256-hex): 02376d0908ac23041cc7d666d9daf192554f7fc36317aa9cb800908616b28af8
Cert Hash(md5): ce0490d5e56c34a5ae0be98be581185d
Cert Hash(sha1): 8f43288ad272f3103b6fb1428485ea3014c0bcfe
Cert Hash(sha256): 847df6a78497943f27fc72eb93f9a637320a02b561d0a91b09e87a7807ed7c61
Signature Hash: 279cd652c4e252bfbe5217ac722205d7729ba409148cfa9e6d9e5b1cb94eaff1

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00001000 (4096)

  CERT_MD5_HASH_PROP_ID(4):
    ce0490d5e56c34a5ae0be98be581185d

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
 279cd652c4e252bfbe5217ac722205d7729ba409148cfa9e6d9e5b1cb94eaff1

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft Root Certificate Authority 2011

  CERT_ROOT_PROGRAM_CHAIN_POLICIES_PROP_ID(105):
    Enhanced Key Usage
        Unknown Key Usage (1.3.6.1.4.1.311.60.3.2)

  CERT_SHA1_HASH_PROP_ID(3):
    8f43288ad272f3103b6fb1428485ea3014c0bcfe

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    722d3a02319043b914054ee1eaa7c731d1238934

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    bb048f1838395f6fc3a1f3d2b7e97654

  CERT_SIGN_HASH_CNG_ALG_PROP_ID(89):
    RSA/SHA256

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 5 ================
X509 Certificate:
Version: 3
Serial Number: 01
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Microsoft Authenticode(tm) Root Authority
    O=MSFT
    C=US
  Name Hash(sha1): 33a873744669f7386e1741e4c22906347ef1ca23
  Name Hash(md5): 27bfe6e77aacead3b6547a88bf3541b6

 NotBefore: 1/1/1995 4:00 PM
 NotAfter: 1/1/2000 7:59 AM

Subject:
    CN=Microsoft Authenticode(tm) Root Authority
    O=MSFT
    C=US
  Name Hash(sha1): 33a873744669f7386e1741e4c22906347ef1ca23
  Name Hash(md5): 27bfe6e77aacead3b6547a88bf3541b6

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA (RSA_SIGN)
    Algorithm Parameters:
    05 00
Public Key Length: 2048 bits
Public Key: UnusedBits = 0
    0000  30 82 01 0a 02 82 01 01  00 df 08 ba e3 3f 6e 64
    0010  9b f5 89 af 28 96 4a 07  8f 1b 2e 8b 3e 1d fc b8
    0020  80 69 a3 a1 ce db df b0  8e 6c 89 76 29 4f ca 60
    0030  35 39 ad 72 32 e0 0b ae  29 3d 4c 16 d9 4b 3c 9d
    0040  da c5 d3 d1 09 c9 2c 6f  a6 c2 60 53 45 dd 4b d1
    0050  55 cd 03 1c d2 59 56 24  f3 e5 78 d8 07 cc d8 b3
    0060  1f 90 3f c0 1a 71 50 1d  2d a7 12 08 6d 7c b0 86
    0070  6c c7 ba 85 32 07 e1 61  6f af 03 c5 6d e5 d6 a1
    0080  8f 36 f6 c1 0b d1 3e 69  97 48 72 c9 7f a4 c8 c2
    0090  4a 4c 7e a1 d1 94 a6 d7  dc eb 05 46 2e b8 18 b4
    00a0  57 1d 86 49 db 69 4a 2c  21 f5 5e 0f 54 2d 5a 43
    00b0  a9 7a 7e 6a 8e 50 4d 25  57 a1 bf 1b 15 05 43 7b
    00c0  2c 05 8d bd 3d 03 8c 93  22 7d 63 ea 0a 57 05 06
    00d0  0a db 61 98 65 2d 47 49  a8 e7 e6 56 75 5c b8 64
    00e0  08 63 a9 30 40 66 b2 f9  b6 e3 34 e8 67 30 e1 43
    00f0  0b 87 ff c9 be 72 10 5e  23 f0 9b a7 48 65 bf 09
    0100  88 7b cd 72 bc 2e 79 9b  7b 02 03 01 00 01
Certificate Extensions: 3
    2.5.29.10: Flags = 0, Length = 6
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.4.3: Flags = 0, Length = 2b
    Common Name (CN)

    0000  13 29 4d 69 63 72 6f 73  6f 66 74 20 41 75 74 68   .)Microsoft Auth
    0010  65 6e 74 69 63 6f 64 65  28 74 6d 29 20 52 6f 6f   enticode(tm) Roo
    0020  74 20 41 75 74 68 6f 72  69 74 79                  t Authority
0000: 13 29					; PRINTABLE_STRING (29 Bytes)
0002:    4d 69 63 72 6f 73 6f 66  74 20 41 75 74 68 65 6e  ; Microsoft Authen
0012:    74 69 63 6f 64 65 28 74  6d 29 20 52 6f 6f 74 20  ; ticode(tm) Root 
0022:    41 75 74 68 6f 72 69 74  79                       ; Authority
            ; "Microsoft Authenticode(tm) Root Authority"

    2.5.29.1: Flags = 0, Length = 6b
    Authority Key Identifier
        KeyID=1a1be75b9ffd8c2ac339ae0c622e5332
        Certificate Issuer:
             CN=Microsoft Authenticode(tm) Root Authority
             O=MSFT
             C=US
        Certificate SerialNumber=01

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  0f 0d de 37 1d d8 b4 b1  df 1a 82 2a 7d 5b 59 0f
    0010  91 71 62 c1 6c 31 66 15  c5 5c 74 4f 6a 19 ac f1
    0020  d6 7e 06 74 ce fb 1f 82  dc 60 42 cf 7b c3 c2 56
    0030  8e 5a a9 1f a2 a5 c8 44  d2 44 12 c2 8a 44 da cc
    0040  fe 85 95 49 a2 2c 75 a9  58 73 a1 ff e8 e3 ef 95
    0050  b2 f4 10 7f 00 cb e2 1a  6c 5d 1b 4a 8e 36 b9 5d
    0060  8d 0e a2 d2 b4 ac 02 dd  c4 98 20 6b 8e a2 19 c2
    0070  1c 04 76 44 4b 42 01 e1  a0 45 c8 48 b4 91 8b 27
    0080  a9 ef 3c fa 0b f3 50 17  70 ee 84 d3 9d fc a5 a2
    0090  bf 98 29 b1 c1 3b 68 a2  be ea 7d 65 83 83 fe c4
    00a0  d5 86 d4 97 52 a4 41 cc  13 01 50 02 e3 4c ff 4b
    00b0  5c 45 1d e4 76 09 23 ee  58 51 86 22 53 ab 98 f4
    00c0  b6 e7 1d eb d1 a4 12 f0  66 30 3f 7a d8 40 47 fc
    00d0  04 18 e6 74 22 8f 3b 5f  6b 9d e2 7c a6 b3 19 f8
    00e0  c5 80 50 da 58 cd f3 26  6e 85 28 02 14 80 5c 56
    00f0  29 dc 7e 9a 4b fa fa 67  56 5d 9e 12 f6 e2 c9 2d
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): 6975dade085cc564e41cda875540dcaa5d701ff9
Key Id Hash(sha1): 01f0334c1aa1d9ee5b7ba9de43bc027d570933fb
Key Id Hash(bcrypt-sha1): d4a1d066f8c821a5ac1ff09735b8756c4d50f89c
Key Id Hash(bcrypt-sha256): 2b6b9a89d793e88ff9ae82d22faa029528765d24d5d3bfd75093b6d35c90ff81
Key Id Hash(md5): 07d34ded498d4577f261bd38b6b8736e
Key Id Hash(sha256): 7a4cc6c2b7fbaebc29ee705a8572c1c18a9aa57de9b3e9eb80d796aa7cd2a30e
Key Id Hash(pin-sha256): hcTJ2WqisAA8f/DqHs9hwRIgVFE9fIu2Y0RJycqsMo0=
Key Id Hash(pin-sha256-hex): 85c4c9d96aa2b0003c7ff0ea1ecf61c1122054513d7c8bb6634449c9caac328d
Cert Hash(md5): dc6d6faf897cdd17332fb5ba9035e9ce
Cert Hash(sha1): 7f88cd7223f3c813818c994614a89c99fa3b5247
Cert Hash(sha256): 4898b1749717a594a2030f47c83c272bd14bae3dceb2eae382174ef2ec1c75c9
Signature Hash: d67576f5521d1ccab52e9215e0f9f743

  CERT_MD5_HASH_PROP_ID(4):
    dc6d6faf897cdd17332fb5ba9035e9ce

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    01f0334c1aa1d9ee5b7ba9de43bc027d570933fb

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft Authenticode(tm) Root

  CERT_ENHKEY_USAGE_PROP_ID(9):
    Enhanced Key Usage
        Secure Email (1.3.6.1.5.5.7.3.4)
        Code Signing (1.3.6.1.5.5.7.3.3)

  CERT_SHA1_HASH_PROP_ID(3):
    7f88cd7223f3c813818c994614a89c99fa3b5247

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
    d67576f5521d1ccab52e9215e0f9f743

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    07d34ded498d4577f261bd38b6b8736e

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 6 ================
X509 Certificate:
Version: 3
Serial Number: 28cc3a25bfba44ac449a9b586b4339aa
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Microsoft Root Certificate Authority 2010
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): 36c61e7e4edbe33d203ae1c16d5e7d8a6f9d8f23
  Name Hash(md5): 83d006c6d15405e6ce2847a90a3f3ec9

 NotBefore: 6/24/2010 5:57 AM
 NotAfter: 6/24/2035 6:04 AM

Subject:
    CN=Microsoft Root Certificate Authority 2010
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): 36c61e7e4edbe33d203ae1c16d5e7d8a6f9d8f23
  Name Hash(md5): 83d006c6d15405e6ce2847a90a3f3ec9

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA
    Algorithm Parameters:
    05 00
Public Key Length: 4096 bits
Public Key: UnusedBits = 0
    0000  30 82 02 0a 02 82 02 01  00 b9 08 9e 28 e4 e4 ec
    0010  06 4e 50 68 b3 41 c5 7b  eb ae b6 8e af 81 ba 22
    0020  44 1f 65 34 69 4c be 70  40 17 f2 16 7b e2 79 fd
    0030  86 ed 0d 39 f4 1b a8 ad  92 90 1e cb 3d 76 8f 5a
    0040  d9 b5 91 10 2e 3c 05 8d  8a 6d 24 54 e7 1f ed 56
    0050  ad 83 b4 50 9c 15 a5 17  74 88 59 20 fc 08 c5 84
    0060  76 d3 68 d4 6f 28 78 ce  5c b8 f3 50 90 44 ff e3
    0070  63 5f be a1 9a 2c 96 15  04 d6 07 fe 1e 84 21 e0
    0080  42 31 11 c4 28 36 94 cf  50 a4 62 9e c9 d6 ab 71
    0090  00 b2 5b 0c e6 96 d4 0a  24 96 f5 ff c6 d5 b7 1b
    00a0  d7 cb b7 21 62 af 12 dc  a1 5d 37 e3 1a fb 1a 46
    00b0  98 c0 9b c0 e7 63 1f 2a  08 93 02 7e 1e 6a 8e f2
    00c0  9f 18 89 e4 22 85 a2 b1  84 57 40 ff f5 0e d8 6f
    00d0  9c ed e2 45 31 01 cd 17  e9 7f b0 81 45 e3 aa 21
    00e0  40 26 a1 72 aa a7 4f 3c  01 05 7e ee 83 58 b1 5e
    00f0  06 63 99 62 91 78 82 b7  0d 93 0c 24 6a b4 1b db
    0100  27 ec 5f 95 04 3f 93 4a  30 f5 97 18 b3 a7 f9 19
    0110  a7 93 33 1d 01 c8 db 22  52 5c d7 25 c9 46 f9 a2
    0120  fb 87 59 43 be 9b 62 b1  8d 2d 86 44 1a 46 ac 78
    0130  61 7e 30 09 fa ae 89 c4  41 2a 22 66 03 91 39 45
    0140  9c c7 8b 0c a8 ca 0d 2f  fb 52 ea 0c f7 63 33 23
    0150  9d fe b0 1f ad 67 d6 a7  50 03 c6 04 70 63 b5 2c
    0160  b1 86 5a 43 b7 fb ae f9  6e 29 6e 21 21 41 26 06
    0170  8c c9 c3 ee b0 c2 85 93  a1 b9 85 d9 e6 32 6c 4b
    0180  4c 3f d6 5d a3 e5 b5 9d  77 c3 9c c0 55 b7 74 00
    0190  e3 b8 38 ab 83 97 50 e1  9a 42 24 1d c6 c0 a3 30
    01a0  d1 1a 5a c8 52 34 f7 73  f1 c7 18 1f 33 ad 7a ec
    01b0  cb 41 60 f3 23 94 20 c2  48 45 ac 5c 51 c6 2e 80
    01c0  c2 e2 77 15 bd 85 87 ed  36 9d 96 91 ee 00 b5 a3
    01d0  70 ec 9f e3 8d 80 68 83  76 ba af 5d 70 52 22 16
    01e0  e2 66 fb ba b3 c5 c2 f7  3e 2f 77 a6 ca de c1 a6
    01f0  c6 48 4c c3 37 51 23 d3  27 d7 b8 4e 70 96 f0 a1
    0200  44 76 af 78 cf 9a e1 66  13 02 03 01 00 01
Certificate Extensions: 4
    2.5.29.15: Flags = 0, Length = 4
    Key Usage
        Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)

    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.29.14: Flags = 0, Length = 16
    Subject Key Identifier
        d5f656cb8fe8a25c6268d13d94905bd7ce9a18c4

    1.3.6.1.4.1.311.21.1: Flags = 0, Length = 3
    CA Version
        V0.0

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  69 f1 0c 64 d7 38 8a 73  a9 7c 69 33 d5 d1 71 86
    0010  59 ff 40 b4 61 05 50 cb  1e 6f ab e0 12 04 91 82
    0020  64 36 a3 17 22 23 12 a4  0b 60 ab 11 4c b6 0e 31
    0030  1e ed a4 f8 21 b3 ea f6  8d 8b cf 5a c1 83 f3 95
    0040  dc 2e 32 36 b3 c7 29 cd  09 a0 bf f6 a8 31 65 5d
    0050  35 e9 c0 39 25 03 55 09  84 c3 6e e5 33 fe cd ee
    0060  c7 fb 3a 40 25 87 50 20  c6 ec 82 d4 db 5b b3 5f
    0070  dd 9e da 0a eb de 96 e2  14 91 bc 1e 5c 24 52 ec
    0080  d8 24 cc 88 c7 d9 e4 e3  69 ab 8a 26 57 74 81 61
    0090  09 93 99 7d 07 b0 4b 6d  48 13 a6 8d b9 25 2d 12
    00a0  5d 34 41 ba d4 f3 d6 85  24 c9 be 71 18 b7 45 66
    00b0  3d 11 e1 04 5a b1 76 9a  61 dc 7f f7 42 b9 f8 f8
    00c0  32 ae 31 1c 0c 8b c5 db  4f ca b7 11 2b 59 61 bd
    00d0  ff 27 83 dc 44 3f b7 2a  ba 0b 26 dd 23 33 9e 4d
    00e0  97 f9 ef ea 73 18 84 36  70 fc 7b 10 56 47 9b 81
    00f0  f3 b5 42 69 ee ed e9 a7  3a 45 7a 99 8d 47 9f fa
    0100  62 68 00 c5 63 2a 84 19  33 2b 7b 7c 92 c0 fd a1
    0110  9e 89 80 32 62 69 ba b8  c5 8c 57 bb 02 9a 26 2e
    0120  97 5b 23 68 09 16 40 66  83 da b8 e4 10 6f de 55
    0130  10 79 59 ce 18 42 97 f2  07 7a 41 22 cc 2c d6 f9
    0140  67 ce 30 af 0f 9f 71 79  4d a0 53 19 af ae 1e 0c
    0150  77 c5 83 bd b2 d3 c0 ec  8b d7 82 15 77 40 aa 30
    0160  b9 40 9f 56 30 06 8c f5  22 66 2a 75 6c de 72 de
    0170  a0 75 a0 37 93 58 0b 9c  f5 f2 1f ef f3 33 84 d0
    0180  2a 5b f5 cd f8 09 65 27  b1 c1 a7 ad ca 20 e4 49
    0190  36 1b 10 8e 43 60 ef b5  c4 67 c2 61 8f bf d1 b6
    01a0  d7 1c d8 69 98 18 47 f9  34 26 9c 40 9b 1e 2b b9
    01b0  84 e4 7b 56 bf f3 79 6d  67 b8 51 f5 f3 02 1a df
    01c0  5a b1 f2 b7 66 70 65 64  3b 5b b9 6d cc 09 d4 e7
    01d0  b2 b2 89 fb 4f b8 ba 14  7f 14 16 3e 05 26 02 f3
    01e0  f1 14 e2 37 af f2 91 f0  d4 b7 35 5b 71 32 1c fd
    01f0  88 56 31 43 87 71 d7 f6  a6 ae bb bf 8c 96 a5 ac
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): d5f656cb8fe8a25c6268d13d94905bd7ce9a18c4
Key Id Hash(sha1): 88a95aefc084fc1374416bb16332c2cf9259bb3b
Key Id Hash(bcrypt-sha1): e0521607ddc600cdd6c8930bfb9a93c8d34ca902
Key Id Hash(bcrypt-sha256): 776c914e87ed10f91dbf9b0d15de6fb75cb27a95460cd654bb6ac1ff0f1e7f8f
Key Id Hash(md5): 3c70faea25600ce3b2cc5f0b222ed629
Key Id Hash(sha256): 12eb31fdc89249a0eb67eb65c2977dbe2ad96a909ccbd180f7e2e16b2782caee
Key Id Hash(pin-sha256): yZBbDuASAik8oCbmTwhBJELFUEwG5Eyn6XJtYfIOQIk=
Key Id Hash(pin-sha256-hex): c9905b0ee01202293ca026e64f08412442c5504c06e44ca7e9726d61f20e4089
Cert Hash(md5): a266bb7dcc38a562631361bbf61dd11b
Cert Hash(sha1): 3b1efd3a66ea28b16697394703a72ca340a05bd5
Cert Hash(sha256): df545bf919a2439c36983b54cdfc903dfa4f37d3996d8d84b4c31eec6f3c163e
Signature Hash: 08fba831c08544208f5208686b991ca1b2cfc510e7301784ddf1eb5bf0393239

  CERT_MD5_HASH_PROP_ID(4):
    a266bb7dcc38a562631361bbf61dd11b

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    d5f656cb8fe8a25c6268d13d94905bd7ce9a18c4

  CERT_SHA1_HASH_PROP_ID(3):
    3b1efd3a66ea28b16697394703a72ca340a05bd5

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft Root Certificate Authority 2010

  CERT_ROOT_PROGRAM_CHAIN_POLICIES_PROP_ID(105):
    Enhanced Key Usage
        Unknown Key Usage (1.3.6.1.4.1.311.60.3.2)

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
 08fba831c08544208f5208686b991ca1b2cfc510e7301784ddf1eb5bf0393239

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    3c70faea25600ce3b2cc5f0b222ed629

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00001000 (4096)

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 7 ================
X509 Certificate:
Version: 3
Serial Number: 153875e1647ed1b047b4efaf41128245
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.10045.4.3.3 sha384ECDSA
    Algorithm Parameters: NULL
Issuer:
    CN=Microsoft ECC TS Root Certificate Authority 2018
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): 6553b8775310ca02f66a200e51ea2ffbb6f61e26
  Name Hash(md5): 2c773b026a40f680ee66a05994ea99a8

 NotBefore: 2/28/2018 4:51 AM
 NotAfter: 2/28/2043 5:00 AM

Subject:
    CN=Microsoft ECC TS Root Certificate Authority 2018
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): 6553b8775310ca02f66a200e51ea2ffbb6f61e26
  Name Hash(md5): 2c773b026a40f680ee66a05994ea99a8

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.10045.2.1 ECC
    Algorithm Parameters:
    06 05 2b 81 04 00 22
        1.3.132.0.34 ECDSA_P384
Public Key Length: 384 bits
Public Key: UnusedBits = 0
    0000  04 de cd bb 70 20 f1 25  20 b4 94 e8 d7 b4 3b 0f
    0010  6e 87 dd ab ac cf 4d 40  2f 81 33 6b 59 09 18 d6
    0020  87 0d 26 23 9c b4 8d 95  9d 76 9f a5 b9 06 42 e6
    0030  ad 36 b2 c4 b3 ae 7a 3c  08 d5 cb 9d 3a 5e 45 21
    0040  6c 0b e3 20 f5 9b c2 dd  44 33 e3 42 b9 ea f2 28
    0050  42 92 aa fe 0c 07 ca 8a  13 99 3b 62 00 ed da f3
    0060  35
Certificate Extensions: 5
    2.5.29.15: Flags = 1(Critical), Length = 4
    Key Usage
        Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)

    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.29.14: Flags = 0, Length = 16
    Subject Key Identifier
        e847c8429ab09dae6f0b283b98158fe3b1e880b2

    1.3.6.1.4.1.311.21.1: Flags = 0, Length = 3
    CA Version
        V0.0

    2.5.29.32: Flags = 0, Length = 5e
    Certificate Policies
        [1]Certificate Policy:
             Policy Identifier=All issuance policies
        [2]Certificate Policy:
             Policy Identifier=1.3.6.1.4.1.311.76.509.1.1
             [2,1]Policy Qualifier Info:
                  Policy Qualifier Id=CPS
                  Qualifier:
                       http://www.microsoft.com/pkiops/Docs/Repository.htm

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.10045.4.3.3 sha384ECDSA
    Algorithm Parameters: NULL
Signature: UnusedBits=0
    0000  2f 91 89 41 71 28 8f 0d  51 df 02 3e 69 81 6b 9a
    0010  46 e7 d5 93 dc fa e3 af  bf 63 e5 f2 c6 94 00 3a
    0020  b7 d2 4a 13 87 1b 27 0c  fa 64 8d 3a 1e b4 94 18
    0030  30 02 db 42 03 55 a3 58  d7 1a 6e 43 a1 82 19 78
    0040  9d a5 e1 b9 56 7d df b4  0f 6b 35 6b d5 40 50 c7
    0050  33 a5 39 63 df 5b 3a 77  14 a1 ea eb 1a 26 c0 50
    0060  86 14 30 02 64 30
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): e847c8429ab09dae6f0b283b98158fe3b1e880b2
Key Id Hash(sha1): f927b61b0a37f3c31afa17ec2d461716129d0c0e
Key Id Hash(bcrypt-sha1): fbbe026486261142b05d35bafddebad619df7874
Key Id Hash(bcrypt-sha256): 14439b1679ebcd878d32308cb67aa252a7987046509124658e80a1d411e2fae1
Key Id Hash(md5): a40f3cb7f5ffa3e812bec7f85507cbf4
Key Id Hash(sha256): 8b24ff5620c8191fd96d52ecb6b60c55e82ba849043fea273927dbf43553e659
Key Id Hash(pin-sha256): xXUL+F9Fn7cOK2zRiY03XpLXk45HpuA0zODBLTA3LM0=
Key Id Hash(pin-sha256-hex): c5750bf85f459fb70e2b6cd1898d375e92d7938e47a6e034cce0c12d30372ccd
Cert Hash(md5): 37942958862a06e6bbcfd7ab59c7f23c
Cert Hash(sha1): 31f9fc8ba3805986b721ea7295c65b3a44534274
Cert Hash(sha256): 3fd4be8baad2f26e1bde06c7584bb720dd1a972d111f5a4999bc44b08fb4960d
Signature Hash: 03d1c76765eda88bc8e0875e6091d060432543d180bcb86c064936adb941c42163780b8289921a94febb7f9e47edac12

  CERT_PIN_SHA256_HASH_PROP_ID(124):
 c5750bf85f459fb70e2b6cd1898d375e92d7938e47a6e034cce0c12d30372ccd

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    a40f3cb7f5ffa3e812bec7f85507cbf4

  CERT_SHA256_HASH_PROP_ID(107):
 3fd4be8baad2f26e1bde06c7584bb720dd1a972d111f5a4999bc44b08fb4960d

  CERT_SHA1_HASH_PROP_ID(3):
    31f9fc8ba3805986b721ea7295c65b3a44534274

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft ECC TS Root Certificate Authority 2018

  CERT_ROOT_PROGRAM_CHAIN_POLICIES_PROP_ID(105):
    Enhanced Key Usage
        Unknown Key Usage (1.3.6.1.4.1.311.60.3.2)

  CERT_MD5_HASH_PROP_ID(4):
    37942958862a06e6bbcfd7ab59c7f23c

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
 03d1c76765eda88bc8e0875e6091d060432543d180bcb86c064936adb941c42163780b8289921a94febb7f9e47edac12

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    e847c8429ab09dae6f0b283b98158fe3b1e880b2

  CERT_SIGN_HASH_CNG_ALG_PROP_ID(89):
    ECDSA/SHA384

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 8 ================
X509 Certificate:
Version: 1
Serial Number: 01
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Issuer:
    OU=Copyright (c) 1997 Microsoft Corp.
    OU=Microsoft Time Stamping Service Root
    OU=Microsoft Corporation
    O=Microsoft Trust Network
  Name Hash(sha1): 7730e74e400c66e471a566e8d43b88c0f2adbfa0
  Name Hash(md5): d1d6c55a7f592938d957bc5dbf9002ed

 NotBefore: 5/14/1997 12:12 AM
 NotAfter: 12/31/1999 7:59 AM

Subject:
    OU=Copyright (c) 1997 Microsoft Corp.
    OU=Microsoft Time Stamping Service Root
    OU=Microsoft Corporation
    O=Microsoft Trust Network
  Name Hash(sha1): 7730e74e400c66e471a566e8d43b88c0f2adbfa0
  Name Hash(md5): d1d6c55a7f592938d957bc5dbf9002ed

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA (RSA_SIGN)
    Algorithm Parameters:
    05 00
Public Key Length: 1024 bits
Public Key: UnusedBits = 0
    0000  30 81 89 02 81 81 00 b7  5a 38 f5 1f 37 cc a9 43
    0010  c4 dc 24 18 be f2 85 52  b4 1d 5b 5f 18 b9 0b 8f
    0020  4b 6d a8 ff cd 40 50 6c  d3 a0 d3 5c 47 c2 b9 f7
    0030  86 e4 cd 7d 35 05 69 37  1f af 3d dd 1f fd 8f 15
    0040  34 c2 c4 79 cc 59 74 8a  6f 8c 0e c3 e8 11 eb 84
    0050  38 47 98 53 e1 f1 0c 0d  e4 01 0c f0 1b 1e 20 da
    0060  2a 7a 3d c2 15 52 8e 8a  ff 7b 32 bf 58 1e 25 98
    0070  83 26 cb 8a c9 c4 07 14  24 bc 49 9e d7 7a b3 87
    0080  1a 25 33 bc 6d 08 47 02  03 01 00 01
Certificate Extensions: 0
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  91 0c df f6 2f 49 ae 04  24 45 1f 2b 40 9f 64 dc
    0010  6b c3 fa c7 8b 83 df 3e  cf ab 16 59 b1 1d 9e 10
    0020  50 8f 3a 95 a7 ce 9a 44  f6 72 93 0b 47 24 83 5e
    0030  ba 63 c1 ca fa 51 a7 e2  8e 4c c5 3e 76 6f 6f 36
    0040  fb 25 b8 fd 82 16 5c 40  97 e8 08 eb 67 99 28 86
    0050  b6 18 bf ce 70 3a 1e af  01 51 02 43 f7 4e 60 a1
    0060  b5 e0 21 95 70 52 eb a4  14 ba 4a 4c ae ca 87 0a
    0070  ca 98 73 34 ac bd c9 0d  5b 52 8d 6f 6b c5 5b 50
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): 1c40f42e93a7bc02ed19ad406ec77b79356d2209
Key Id Hash(sha1): 344f302d25693191eaf7735cabf5868d378240ec
Key Id Hash(bcrypt-sha1): 61ca35166367bc66ad623ac10db71903ee383b64
Key Id Hash(bcrypt-sha256): 3cdf2f0bf0897551b1cab7540c27569fe55038de548bf7a8ea94bcd150571b2b
Key Id Hash(md5): 7fdff50729446710244a447ca2a197ea
Key Id Hash(sha256): 23073d6c87d66479d74921d712ea126cebffc5395262d2fc6ff51c149aa6b1aa
Key Id Hash(pin-sha256): vO+bACUu/4abU+V7GINTcO6qwwA13lYarOH95w9+rwg=
Key Id Hash(pin-sha256-hex): bcef9b00252eff869b53e57b18835370eeaac30035de561aace1fde70f7eaf08
Cert Hash(md5): 556ebef54c1d7c0360c43418bc9649c1
Cert Hash(sha1): 245c97df7514e7cf2df8be72ae957b9e04741e85
Cert Hash(sha256): 6ef914723f089d2adaff98d470a3651ccf1768e559fbdcc0faaa640aa12e5753
Signature Hash: 9df0d13100123aeca770130f4ad8d209

  CERT_MD5_HASH_PROP_ID(4):
    556ebef54c1d7c0360c43418bc9649c1

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    344f302d25693191eaf7735cabf5868d378240ec

  CERT_SHA1_HASH_PROP_ID(3):
    245c97df7514e7cf2df8be72ae957b9e04741e85

  CERT_ENHKEY_USAGE_PROP_ID(9):
    Enhanced Key Usage
        Time Stamping (1.3.6.1.5.5.7.3.8)

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft Timestamp Root

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
    9df0d13100123aeca770130f4ad8d209

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    7fdff50729446710244a447ca2a197ea

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 9 ================
X509 Certificate:
Version: 1
Serial Number: 4a19d2388c82591ca55d735f155ddca3
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Issuer:
    OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
    OU=VeriSign Time Stamping Service Root
    OU=VeriSign, Inc.
    O=VeriSign Trust Network
  Name Hash(sha1): 7cac367b5c754ce2ff5d95e025fdf6879fd6bfa1
  Name Hash(md5): 4ff7db56d0fd88a19fe3ba8bc00e0662

 NotBefore: 5/12/1997 8:00 AM
 NotAfter: 1/8/2004 7:59 AM

Subject:
    OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
    OU=VeriSign Time Stamping Service Root
    OU=VeriSign, Inc.
    O=VeriSign Trust Network
  Name Hash(sha1): 7cac367b5c754ce2ff5d95e025fdf6879fd6bfa1
  Name Hash(md5): 4ff7db56d0fd88a19fe3ba8bc00e0662

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA (RSA_SIGN)
    Algorithm Parameters:
    05 00
Public Key Length: 1024 bits
Public Key: UnusedBits = 0
    0000  30 81 89 02 81 81 00 d3  2e 20 f0 68 7c 2c 2d 2e
    0010  81 1c b1 06 b2 a7 0b b7  11 0d 57 da 53 d8 75 e3
    0020  c9 33 2a b2 d4 f6 09 5b  34 f3 e9 90 fe 09 0c d0
    0030  db 1b 5a b9 cd e7 f6 88  b1 9d c0 87 25 eb 7d 58
    0040  10 73 6a 78 cb 71 15 fd  c6 58 f6 29 ab 58 5e 96
    0050  04 fd 2d 62 11 58 81 1c  ca 71 94 d5 22 58 2f d5
    0060  cc 14 05 84 36 ba 94 aa  b4 4d 4a e9 ee 3b 22 ad
    0070  56 99 7e 21 9c 6c 86 c0  4a 47 97 6a b4 a6 36 d5
    0080  fc 09 2d d3 b4 39 9b 02  03 01 00 01
Certificate Extensions: 0
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.4 md5RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  63 63 11 fd d1 55 ac 84  4f 9d fd f8 3f 73 d1 93
    0010  e5 53 9c f8 61 bf e4 10  90 a6 48 42 67 ba ff dc
    0020  92 84 29 79 c4 96 28 af  b3 ce 8f 09 10 ca 0a cd
    0030  5d d2 a9 aa ed f5 8a 28  95 b0 2e 73 07 69 79 bf
    0040  63 e5 ce 17 7f 2a 8e f6  56 70 9f 0b 34 50 3d 46
    0050  fb a4 b3 ef 61 4e db 4c  94 89 e3 84 cc ef 59 e2
    0060  1e 72 07 a7 f3 7e a4 9e  78 0b e4 44 e8 5b 2b 13
    0070  b3 d4 cc 22 8e 10 11 7e  12 92 c7 7b 3e 0e 55 61
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): c1f058c73a70e15267dfbe577e6227c874522627
Key Id Hash(sha1): 3edf290cc1f5cc732ceb3d24e17e52dabd27e2f0
Key Id Hash(bcrypt-sha1): 42bbb5824624be35c499e7b7dd9485f628b6f2d6
Key Id Hash(bcrypt-sha256): 0d0648b8a841368c00dd7313771951143bf7184c1a46e45191664021b76ef4d3
Key Id Hash(md5): e53d34cecb05c17ee332c749d78c0256
Key Id Hash(sha256): 1d4e46d36b0e941a7407768a6b1ef80b0b199ee5ff76738287e561f80c678621
Key Id Hash(pin-sha256): YOOF2fbmkG6F5D+esOQ+ZScZMZ6cgKYUaJG+I69f4uk=
Key Id Hash(pin-sha256-hex): 60e385d9f6e6906e85e43f9eb0e43e652719319e9c80a6146891be23af5fe2e9
Cert Hash(md5): ebb04f1d3a2e372f1dda6e27d6b680fa
Cert Hash(sha1): 18f7c1fcc3090203fd5baa2f861a754976c8dd25
Cert Hash(sha256): 5b789987f3c4055b8700941b33783a5f16e0cff937ea32011fe04779f7635308
Signature Hash: 65fc47520f66383962ec0b7b88a0821d

  CERT_MD5_HASH_PROP_ID(4):
    ebb04f1d3a2e372f1dda6e27d6b680fa

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    3edf290cc1f5cc732ceb3d24e17e52dabd27e2f0

  CERT_FRIENDLY_NAME_PROP_ID(11):
    VeriSign Time Stamping CA

  CERT_ENHKEY_USAGE_PROP_ID(9):
    Enhanced Key Usage
        Time Stamping (1.3.6.1.5.5.7.3.8)

  CERT_SHA1_HASH_PROP_ID(3):
    18f7c1fcc3090203fd5baa2f861a754976c8dd25

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
    65fc47520f66383962ec0b7b88a0821d

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    e53d34cecb05c17ee332c749d78c0256

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 10 ================
X509 Certificate:
Version: 3
Serial Number: 14982666dc7ccd8f4053677bb999ec85
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.10045.4.3.3 sha384ECDSA
    Algorithm Parameters: NULL
Issuer:
    CN=Microsoft ECC Product Root Certificate Authority 2018
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): d620cdd19cc0542f9306444fd8c7c7238e9dbaca
  Name Hash(md5): 1ab5d2ac7d870a5f7818b3c1d8e34e5a

 NotBefore: 2/28/2018 4:42 AM
 NotAfter: 2/28/2043 4:50 AM

Subject:
    CN=Microsoft ECC Product Root Certificate Authority 2018
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): d620cdd19cc0542f9306444fd8c7c7238e9dbaca
  Name Hash(md5): 1ab5d2ac7d870a5f7818b3c1d8e34e5a

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.10045.2.1 ECC
    Algorithm Parameters:
    06 05 2b 81 04 00 22
        1.3.132.0.34 ECDSA_P384
Public Key Length: 384 bits
Public Key: UnusedBits = 0
    0000  04 c7 11 16 2a 76 1d 56  8e be b9 62 65 d4 c3 ce
    0010  b4 f0 c3 30 ec 8f 6d d7  6e 39 bc c8 49 ab ab b8
    0020  e3 43 78 d5 81 06 5d ef  c7 7d 9f ce d6 b3 90 75
    0030  de 0c b0 90 de 23 ba c8  d1 3e 67 e0 19 a9 1b 86
    0040  31 1e 5f 34 2d ee 17 fd  15 fb 7e 27 8a 32 a1 ea
    0050  c9 8f c9 7e 18 cb 2f 3b  2c 48 7a 7d a6 f4 01 07
    0060  ac
Certificate Extensions: 5
    2.5.29.15: Flags = 1(Critical), Length = 4
    Key Usage
        Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)

    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.29.14: Flags = 0, Length = 16
    Subject Key Identifier
        43ef7087b89dbfec8819dcc6c46b750d75343308

    1.3.6.1.4.1.311.21.1: Flags = 0, Length = 3
    CA Version
        V0.0

    2.5.29.32: Flags = 0, Length = 5e
    Certificate Policies
        [1]Certificate Policy:
             Policy Identifier=All issuance policies
        [2]Certificate Policy:
             Policy Identifier=1.3.6.1.4.1.311.76.509.1.1
             [2,1]Policy Qualifier Info:
                  Policy Qualifier Id=CPS
                  Qualifier:
                       http://www.microsoft.com/pkiops/Docs/Repository.htm

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.10045.4.3.3 sha384ECDSA
    Algorithm Parameters: NULL
Signature: UnusedBits=0
    0000  68 c1 8f 56 56 96 05 bb  f0 be b0 f2 14 99 b5 a7
    0010  60 9c 2b 7a fe bb 60 e4  02 a5 b9 2a 45 f1 92 e5
    0020  79 60 3d 62 7f 09 27 ac  b0 3e c7 72 eb 28 d3 c5
    0030  00 31 02 bf 45 1c 70 15  06 9b 45 22 c2 9e c9 57
    0040  b5 e1 9c dd cd 1c 4f 6f  f9 a3 2a 49 49 91 c7 35
    0050  51 9b 5b 24 9d 22 25 6e  90 3e cc 27 55 32 5d 44
    0060  49 c0 a1 00 31 02 66 30
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): 43ef7087b89dbfec8819dcc6c46b750d75343308
Key Id Hash(sha1): 7c32d485fd890a66b597ce86f4d526a92107e83e
Key Id Hash(bcrypt-sha1): ff2ce25bd4a0e011e025960dcb86c00fe58f916a
Key Id Hash(bcrypt-sha256): ef4f95e8795b7dd70409231aee41f205e667b9e9ace71506aea0a824db733bb2
Key Id Hash(md5): 7d9e7d1e8d5da11dc0c84b0757ecedcb
Key Id Hash(sha256): 9ab5e4c61155a9396ea1c8bf4829d3e108535257b71be380972162320ffb133b
Key Id Hash(pin-sha256): aN7ZogP/bjZ+EqpJl3zSAPcSeoAPqm+Fnwuv7YKGpPs=
Key Id Hash(pin-sha256-hex): 68ded9a203ff6e367e12aa49977cd200f7127a800faa6f859f0bafed8286a4fb
Cert Hash(md5): 1f124ede13e06a023cd7c09a4f48c3d6
Cert Hash(sha1): 06f1aa330b927b753a40e68cdf22e34bcbef3352
Cert Hash(sha256): caca93b9d23d2b6fa76e8b8471931e0df3ec6f63af3cdbb936c41954a1872326
Signature Hash: 32991981bf1575a1a5303bb93a381723ea346b9ec130fdb596a75ba1d7ce0b0a06570bb985d25841e23be944e8ff118f

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00000180 (384)

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    43ef7087b89dbfec8819dcc6c46b750d75343308

  CERT_MD5_HASH_PROP_ID(4):
    1f124ede13e06a023cd7c09a4f48c3d6

  CERT_SHA1_HASH_PROP_ID(3):
    06f1aa330b927b753a40e68cdf22e34bcbef3352

  CERT_ROOT_PROGRAM_CHAIN_POLICIES_PROP_ID(105):
    Enhanced Key Usage
        Unknown Key Usage (1.3.6.1.4.1.311.60.3.2)

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft ECC Product Root Certificate Authority 2018

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
 32991981bf1575a1a5303bb93a381723ea346b9ec130fdb596a75ba1d7ce0b0a06570bb985d25841e23be944e8ff118f

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    7d9e7d1e8d5da11dc0c84b0757ecedcb

  CERT_SIGN_HASH_CNG_ALG_PROP_ID(89):
    ECDSA/SHA384

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.

================ Certificate 11 ================
X509 Certificate:
Version: 3
Serial Number: 2fd67a432293329045e953343ee27466
Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Issuer:
    CN=Microsoft Time Stamp Root Certificate Authority 2014
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): e1607171d7c4d96166b3671c5d5342610809fc6e
  Name Hash(md5): 53308366b78c6bdbb2b1b524da63c4ed

 NotBefore: 10/23/2014 6:08 AM
 NotAfter: 10/23/2039 6:15 AM

Subject:
    CN=Microsoft Time Stamp Root Certificate Authority 2014
    O=Microsoft Corporation
    L=Redmond
    S=Washington
    C=US
  Name Hash(sha1): e1607171d7c4d96166b3671c5d5342610809fc6e
  Name Hash(md5): 53308366b78c6bdbb2b1b524da63c4ed

Public Key Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.1 RSA
    Algorithm Parameters:
    05 00
Public Key Length: 4096 bits
Public Key: UnusedBits = 0
    0000  30 82 02 0a 02 82 02 01  00 ae 01 d4 5d a0 58 ca
    0010  ed e8 cc e1 37 46 46 10  5b 7a c4 52 b8 0b 58 8f
    0020  05 3d 5d a9 ad 51 e2 03  89 e0 06 12 f8 02 78 6b
    0030  5e 04 50 cf b6 d6 04 0c  54 1e 79 37 20 3c e3 7e
    0040  63 1d 45 77 98 14 1d be  76 22 dc 5a aa 3f e4 6f
    0050  40 62 24 63 c8 3c c0 4c  87 28 3d 6b 78 6b 98 39
    0060  95 1a 41 7f 73 51 fe 07  fc 14 7c f3 8f 84 09 e1
    0070  f8 c2 2f a1 4e bd 39 7d  cc 63 67 89 0c 80 04 cd
    0080  b0 82 c9 00 8b 3e 09 87  03 9d c2 79 42 c4 5c 21
    0090  91 2b 95 1a 6c 35 47 6c  c8 bf 3c 0a 4e ea f6 85
    00a0  70 d5 c5 5f c1 9e 47 db  5c c2 32 61 5a 08 d6 71
    00b0  9d 2c 81 9f 7e b8 be 6d  a1 d8 66 43 69 0a e4 f3
    00c0  72 f0 91 4b 28 60 a8 d5  e3 dd 84 ae 28 65 55 9f
    00d0  84 2b 4a 75 ed 24 a6 2c  75 31 d4 85 77 74 f2 80
    00e0  55 02 63 41 f2 70 08 f4  c8 c2 53 91 db 14 07 65
    00f0  20 09 81 e6 8a d7 9b 0f  ca 0c d7 1b 5f fd d1 e5
    0100  74 85 5c 10 fb 9a c9 a6  2b 9e 43 96 cc 5b 72 73
    0110  d0 0f 55 99 87 18 1b 3d  f8 29 78 b0 6f d1 74 bc
    0120  e5 20 ba 43 8b 14 38 69  64 a1 73 0f c1 16 29 79
    0130  4f 9b 85 29 68 b1 3e 99  2a 8f b2 dc 47 06 cd df
    0140  d0 eb 22 dc 1e 57 1c 7e  59 90 25 a3 03 82 be 8c
    0150  cb 1d 9b b9 8d 2a b8 a1  10 e7 fa ad 16 fe ec e5
    0160  53 c6 ad c0 97 7c 44 9b  81 f3 7a a6 f9 ff ae fa
    0170  ac 17 a9 a6 60 bd 67 3c  79 6c 85 0b 55 af 31 c4
    0180  c3 59 90 0e a1 d5 7c 48  39 8b ad e3 bb 0e e4 e5
    0190  fa df fd da 9d 9e 5b 6f  1b 32 0e a6 37 d3 aa aa
    01a0  2c 04 17 65 d3 c6 4e 47  24 ad 82 50 99 41 2b d6
    01b0  b3 e7 26 5a b1 35 9b e6  71 55 e1 c8 6f a2 44 1d
    01c0  c8 5c 84 fc f9 78 01 76  c1 3e 77 93 f2 a2 94 e1
    01d0  da 70 30 ec 64 0a ae a2  a1 1d 3f 83 43 73 40 d2
    01e0  e0 89 70 59 af 8d 2e d4  d4 21 0a 61 a4 f4 f7 23
    01f0  86 43 80 28 b2 1c 43 0c  45 da fc 06 f8 25 40 07
    0200  75 69 78 e3 a6 13 83 d7  97 02 03 01 00 01
Certificate Extensions: 4
    2.5.29.15: Flags = 0, Length = 4
    Key Usage
        Digital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)

    2.5.29.19: Flags = 1(Critical), Length = 5
    Basic Constraints
        Subject Type=CA
        Path Length Constraint=None

    2.5.29.14: Flags = 0, Length = 16
    Subject Key Identifier
        cbd1f2ce48fd019fea56aa57d17e9958f83fffe0

    1.3.6.1.4.1.311.21.1: Flags = 0, Length = 3
    CA Version
        V0.0

Signature Algorithm:
    Algorithm ObjectId: 1.2.840.113549.1.1.11 sha256RSA
    Algorithm Parameters:
    05 00
Signature: UnusedBits=0
    0000  8d f8 96 fa 07 e5 58 c4  72 6c 63 ec a4 80 9e 5f
    0010  63 ca 42 c3 d4 67 cd 2d  d1 a4 e9 b4 69 3a 03 af
    0020  55 13 c3 08 b6 f7 ad ca  a3 e1 3b 36 0b dc 53 3b
    0030  c2 a8 ca fc 38 08 22 a2  0b c9 a1 d5 70 01 c7 7a
    0040  47 f7 8b 4e b9 87 78 1d  26 1e 42 52 27 2c c8 df
    0050  ac 92 c4 59 ac 17 92 e5  ae e7 81 f6 ce 31 25 92
    0060  8e 80 a1 e1 06 1a 37 bd  02 3d 92 b2 c7 df 34 b1
    0070  02 a1 37 b6 55 02 4d 48  92 45 6e eb 34 a3 e5 f8
    0080  6f 7f 29 17 d5 f2 8c ab  6f b6 e5 52 3b a9 b2 b0
    0090  73 01 44 42 98 76 1d df  d0 09 a3 a0 af 05 9e 98
    00a0  dd 83 b4 77 92 1b f5 b0  39 13 36 8a b0 11 a5 2c
    00b0  49 0f 1e f2 2d a3 dc bf  9d 4d f1 52 87 dd a5 77
    00c0  d3 75 43 38 26 fe 0e 41  92 28 79 91 b8 df a0 46
    00d0  55 b2 cb 83 20 2e 3d aa  29 cd e2 68 8e 3c d0 60
    00e0  00 0a 54 56 2f d2 7c d8  f0 ce 97 36 d6 7d b4 fa
    00f0  96 aa fa 2d ef 4d a3 9a  4a 70 9f f9 9f 6f dd 9e
    0100  78 4a d4 09 c2 96 52 45  12 82 2a c2 b3 8e 5b 79
    0110  3c 46 ef 25 4a c3 54 ce  3d 02 bb 23 3e 6d 3c 4a
    0120  d9 3b 86 34 15 ff d7 2b  1a 43 f1 c9 b0 10 ce c6
    0130  1b d6 6d 98 c6 cf ba c6  2e ea d0 1c 03 50 c1 c1
    0140  66 79 b4 29 83 d5 6f 61  b6 96 aa d2 1f 3f 6a c1
    0150  da 18 16 ed af 18 31 63  dd a6 4a 63 c2 b4 dd 58
    0160  65 5d a3 69 c1 57 8a 94  ff c9 9e 7b 45 e9 06 2e
    0170  bb a3 a5 e4 4b 1c e6 20  66 8e 8e fa 07 10 f2 8b
    0180  40 e4 06 e0 56 b8 0c 9a  b6 ec 32 4c 5b 24 64 c5
    0190  34 1d e9 47 8f e7 41 b3  be 1e a9 e8 90 a3 55 29
    01a0  9c c4 87 68 c6 37 21 6e  0f 22 19 45 f7 3e cf a0
    01b0  53 21 d3 5c 03 76 12 bc  2c 86 0b 3e 20 5c c8 fa
    01c0  27 7d 57 20 ae ef 83 ca  33 dc d9 75 e6 0f f8 bf
    01d0  0b 65 e2 fd 38 10 01 59  af 46 ce f5 1e b2 4e 1d
    01e0  ec 14 ca 0a 48 be 46 62  00 29 9c 95 7d da 85 96
    01f0  a3 fb be 80 ef 47 3b fd  ce 26 d8 a3 e4 d3 d8 13
Signature matches Public Key
Root Certificate: Subject matches Issuer
Key Id Hash(rfc-sha1): cbd1f2ce48fd019fea56aa57d17e9958f83fffe0
Key Id Hash(sha1): 641df8d50e2331c229b250cb32f56df55c8e00fa
Key Id Hash(bcrypt-sha1): a1855181a6fe56272c854938b187e936b3ae3894
Key Id Hash(bcrypt-sha256): 38ef31a8084ecee964c8e0806d4e0a49fa0b4e8a80cd3fe52d19e85ffcdbb5e4
Key Id Hash(md5): 842773950086d06b04d7022d62a284be
Key Id Hash(sha256): 299470b8bb2678780cf020a3322f69b40a1162240571afd53a805b9b03f2eb5d
Key Id Hash(pin-sha256): /AKkni4ejkiMopEhNVcswvjnG7Di8oWWs3IimfXLnGI=
Key Id Hash(pin-sha256-hex): fc02a49e2e1e8e488ca2912135572cc2f8e71bb0e2f28596b3722299f5cb9c62
Cert Hash(md5): 34f72698d70e231f8dc45b57f118a44b
Cert Hash(sha1): 0119e81be9a14cd8e22f40ac118c687ecba3f4d8
Cert Hash(sha256): 65af95f4be86847344634282f941b2e605063ef0c8542f014ca088d182109e4f
Signature Hash: e4a2f6fe9ca7f18a2beba96161308baa8880b013161ddd8532d4259e27e50570

  CERT_SIGN_HASH_CNG_ALG_PROP_ID(89):
    RSA/SHA256

  CERT_KEY_IDENTIFIER_PROP_ID(20):
    cbd1f2ce48fd019fea56aa57d17e9958f83fffe0

  CERT_SIGNATURE_HASH_PROP_ID(15) disallowedHash:
 e4a2f6fe9ca7f18a2beba96161308baa8880b013161ddd8532d4259e27e50570

  CERT_MD5_HASH_PROP_ID(4):
    34f72698d70e231f8dc45b57f118a44b

  CERT_SHA1_HASH_PROP_ID(3):
    0119e81be9a14cd8e22f40ac118c687ecba3f4d8

  CERT_ROOT_PROGRAM_CHAIN_POLICIES_PROP_ID(105):
    Enhanced Key Usage
        Unknown Key Usage (1.3.6.1.4.1.311.60.3.2)

  CERT_FRIENDLY_NAME_PROP_ID(11):
    Microsoft Time Stamp Root Certificate Authority 2014

  CERT_SHA256_HASH_PROP_ID(107):
 65af95f4be86847344634282f941b2e605063ef0c8542f014ca088d182109e4f

  CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID(25):
    842773950086d06b04d7022d62a284be

  CERT_PIN_SHA256_HASH_PROP_ID(124):
 fc02a49e2e1e8e488ca2912135572cc2f8e71bb0e2f28596b3722299f5cb9c62

  CERT_SUBJECT_PUB_KEY_BIT_LENGTH_PROP_ID(92):
    0x00001000 (4096)

  CERT_ACCESS_STATE_PROP_ID(14):
  AccessState = 6
    CERT_ACCESS_STATE_SYSTEM_STORE_FLAG -- 2
    CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG -- 4

Cannot find the certificate and private key for decryption.
CertUtil: -store command completed successfully.

Re-scan feature

If a user distrusts a cert, they probably want to rescan.

If someone unexpected happens, a user wants to rescan

Which server data do we use to verify root certificates

Once the app acquires the certificate (file) data, we need to verify each root certificate is intact.

The public key and other identifiable information of each certificate is published by trusted CA root programs.

The client app can either 1. directly download the root certificates data from the CA root programs 2. download the data from the CertainTLS backend, which download the data from the CA root programs

If the client app does 1) then there is a chance the request being man-in-the-middle-attacked, therefore, the result cannot be trusted. However, downloading the data directly can make the client app less dependent to its server; in case the server is not available, the client app can still be useful

If the client app does 2) then in case that server is not reachable (blocked, DDoSed), then the client app is useless. However, the app in capable of serving might be better than telling the false information.

If the client app does 2) first then fall back to 1), then the risk is lower, but the attacker can still DDoS the server then man-in-the-middle-attack, which results the same as 1)

For the first milestone, we will do 1)

Data privacy concerns

In milestone 3, we will start collecting user device certificates data, especially the user installed certificates.

We probably need a strategy and follow up legal work?

migrate to null-safety

Hi @certaintls ,

Hope you are well !

I was wondering if you could migrate to null-safety so I can contribute to your project too.

Cheers,
Luc

Auto remove certs from backend

For whatever reasons, certs can get removed or revoked from the official programs, we need to add a step to incrementally remove their program tags from backend or update their status

"Mark as disabled " option

Some OS doesn't allow the app to read the cert state, so we want to implement our own state records to keep track. Users can mark them as disabled.

Cross verify certs on different root CA programs

If a root cert is found on, e.g. Android, then let's cross check if the same cert is on other root programs.

Android root CA programs rely on hashed cert file name, needs to figure out how to hash the file name.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.