aboutsummaryrefslogtreecommitdiff
path: root/scripts/resource-cert-samples
diff options
context:
space:
mode:
authorRob Austein <sra@hactrn.net>2007-08-10 01:17:06 +0000
committerRob Austein <sra@hactrn.net>2007-08-10 01:17:06 +0000
commitcd0806578e330537a091f1f314b2ba2606f424a6 (patch)
tree1cce302ae0de9f6737580eb5653b8f433e1a5e49 /scripts/resource-cert-samples
parent02fea13d6241956f775e684d327600fadadd45ca (diff)
Another whack at fixing sample certs.
svn path=/scripts/generate-testrepo.py; revision=854
Diffstat (limited to 'scripts/resource-cert-samples')
-rw-r--r--scripts/resource-cert-samples/ISP1.cer73
-rw-r--r--scripts/resource-cert-samples/ISP1.cnf19
-rw-r--r--scripts/resource-cert-samples/ISP1.req22
-rw-r--r--scripts/resource-cert-samples/ISP2.cer72
-rw-r--r--scripts/resource-cert-samples/ISP2.cnf19
-rw-r--r--scripts/resource-cert-samples/ISP2.req22
-rw-r--r--scripts/resource-cert-samples/ISP3.cer73
-rw-r--r--scripts/resource-cert-samples/ISP3.cnf19
-rw-r--r--scripts/resource-cert-samples/ISP3.req22
-rw-r--r--scripts/resource-cert-samples/ISP4.cer73
-rw-r--r--scripts/resource-cert-samples/ISP4.cnf19
-rw-r--r--scripts/resource-cert-samples/ISP4.req22
-rw-r--r--scripts/resource-cert-samples/ISP5a.cer73
-rw-r--r--scripts/resource-cert-samples/ISP5a.cnf19
-rw-r--r--scripts/resource-cert-samples/ISP5a.req20
-rw-r--r--scripts/resource-cert-samples/ISP5b.cer73
-rw-r--r--scripts/resource-cert-samples/ISP5b.cnf19
-rw-r--r--scripts/resource-cert-samples/ISP5b.req20
-rw-r--r--scripts/resource-cert-samples/ISP5c.cer72
-rw-r--r--scripts/resource-cert-samples/ISP5c.cnf19
-rw-r--r--scripts/resource-cert-samples/ISP5c.req20
-rw-r--r--scripts/resource-cert-samples/LIR1.cer74
-rw-r--r--scripts/resource-cert-samples/LIR1.cnf19
-rw-r--r--scripts/resource-cert-samples/LIR1.req23
-rw-r--r--scripts/resource-cert-samples/LIR1/0B.pem79
-rw-r--r--scripts/resource-cert-samples/LIR1/0C.pem79
-rw-r--r--scripts/resource-cert-samples/LIR1/0D.pem88
-rw-r--r--scripts/resource-cert-samples/LIR1/0E.pem93
-rw-r--r--scripts/resource-cert-samples/LIR1/0F.pem88
-rw-r--r--scripts/resource-cert-samples/LIR1/10.pem93
-rw-r--r--scripts/resource-cert-samples/LIR1/11.pem76
-rw-r--r--scripts/resource-cert-samples/LIR1/12.pem76
-rw-r--r--scripts/resource-cert-samples/LIR1/13.pem88
-rw-r--r--scripts/resource-cert-samples/LIR1/14.pem93
-rw-r--r--scripts/resource-cert-samples/LIR1/index10
-rw-r--r--scripts/resource-cert-samples/LIR1/index.old10
-rw-r--r--scripts/resource-cert-samples/LIR1/serial2
-rw-r--r--scripts/resource-cert-samples/LIR1/serial.old2
-rw-r--r--scripts/resource-cert-samples/LIR2.cer75
-rw-r--r--scripts/resource-cert-samples/LIR2.cnf19
-rw-r--r--scripts/resource-cert-samples/LIR2.req23
-rw-r--r--scripts/resource-cert-samples/LIR2/0B.pem79
-rw-r--r--scripts/resource-cert-samples/LIR2/0C.pem79
-rw-r--r--scripts/resource-cert-samples/LIR2/0D.pem93
-rw-r--r--scripts/resource-cert-samples/LIR2/0E.pem89
-rw-r--r--scripts/resource-cert-samples/LIR2/0F.pem93
-rw-r--r--scripts/resource-cert-samples/LIR2/10.pem89
-rw-r--r--scripts/resource-cert-samples/LIR2/11.pem76
-rw-r--r--scripts/resource-cert-samples/LIR2/12.pem76
-rw-r--r--scripts/resource-cert-samples/LIR2/13.pem93
-rw-r--r--scripts/resource-cert-samples/LIR2/14.pem89
-rw-r--r--scripts/resource-cert-samples/LIR2/index10
-rw-r--r--scripts/resource-cert-samples/LIR2/index.old10
-rw-r--r--scripts/resource-cert-samples/LIR2/serial2
-rw-r--r--scripts/resource-cert-samples/LIR2/serial.old2
-rw-r--r--scripts/resource-cert-samples/LIR3.cer75
-rw-r--r--scripts/resource-cert-samples/LIR3.cnf19
-rw-r--r--scripts/resource-cert-samples/LIR3.req23
-rw-r--r--scripts/resource-cert-samples/LIR3/04.pem79
-rw-r--r--scripts/resource-cert-samples/LIR3/05.pem79
-rw-r--r--scripts/resource-cert-samples/LIR3/06.pem79
-rw-r--r--scripts/resource-cert-samples/LIR3/07.pem88
-rw-r--r--scripts/resource-cert-samples/LIR3/08.pem91
-rw-r--r--scripts/resource-cert-samples/LIR3/09.pem91
-rw-r--r--scripts/resource-cert-samples/LIR3/0A.pem88
-rw-r--r--scripts/resource-cert-samples/LIR3/0B.pem91
-rw-r--r--scripts/resource-cert-samples/LIR3/0C.pem91
-rw-r--r--scripts/resource-cert-samples/LIR3/0D.pem76
-rw-r--r--scripts/resource-cert-samples/LIR3/0E.pem76
-rw-r--r--scripts/resource-cert-samples/LIR3/0F.pem76
-rw-r--r--scripts/resource-cert-samples/LIR3/10.pem88
-rw-r--r--scripts/resource-cert-samples/LIR3/11.pem91
-rw-r--r--scripts/resource-cert-samples/LIR3/12.pem91
-rw-r--r--scripts/resource-cert-samples/LIR3/index15
-rw-r--r--scripts/resource-cert-samples/LIR3/index.old15
-rw-r--r--scripts/resource-cert-samples/LIR3/serial2
-rw-r--r--scripts/resource-cert-samples/LIR3/serial.old2
-rw-r--r--scripts/resource-cert-samples/Makefile88
-rw-r--r--scripts/resource-cert-samples/RIR.cer76
-rw-r--r--scripts/resource-cert-samples/RIR.cnf19
-rw-r--r--scripts/resource-cert-samples/RIR.req24
-rw-r--r--scripts/resource-cert-samples/RIR/11.pem100
-rw-r--r--scripts/resource-cert-samples/RIR/12.pem100
-rw-r--r--scripts/resource-cert-samples/RIR/13.pem79
-rw-r--r--scripts/resource-cert-samples/RIR/14.pem79
-rw-r--r--scripts/resource-cert-samples/RIR/15.pem79
-rw-r--r--scripts/resource-cert-samples/RIR/16.pem79
-rw-r--r--scripts/resource-cert-samples/RIR/17.pem100
-rw-r--r--scripts/resource-cert-samples/RIR/18.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/19.pem95
-rw-r--r--scripts/resource-cert-samples/RIR/1A.pem94
-rw-r--r--scripts/resource-cert-samples/RIR/1B.pem100
-rw-r--r--scripts/resource-cert-samples/RIR/1C.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/1D.pem95
-rw-r--r--scripts/resource-cert-samples/RIR/1E.pem94
-rw-r--r--scripts/resource-cert-samples/RIR/1F.pem76
-rw-r--r--scripts/resource-cert-samples/RIR/20.pem76
-rw-r--r--scripts/resource-cert-samples/RIR/21.pem76
-rw-r--r--scripts/resource-cert-samples/RIR/22.pem76
-rw-r--r--scripts/resource-cert-samples/RIR/23.pem100
-rw-r--r--scripts/resource-cert-samples/RIR/24.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/25.pem95
-rw-r--r--scripts/resource-cert-samples/RIR/26.pem94
-rw-r--r--scripts/resource-cert-samples/RIR/index22
-rw-r--r--scripts/resource-cert-samples/RIR/index.old22
-rw-r--r--scripts/resource-cert-samples/RIR/serial2
-rw-r--r--scripts/resource-cert-samples/RIR/serial.old2
107 files changed, 5882 insertions, 560 deletions
diff --git a/scripts/resource-cert-samples/ISP1.cer b/scripts/resource-cert-samples/ISP1.cer
index 86da6423..9121acc8 100644
--- a/scripts/resource-cert-samples/ISP1.cer
+++ b/scripts/resource-cert-samples/ISP1.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 10 (0xa)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 20 (0x14)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY LIR1
Validity
- Not Before: Aug 1 14:48:22 2007 GMT
- Not After : Jul 31 14:48:22 2008 GMT
+ Not Before: Aug 10 01:15:11 2007 GMT
+ Not After : Aug 9 01:15:11 2008 GMT
Subject: CN=TEST ENTITY ISP1
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
- X509v3 Authority Key Identifier:
- keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -55,42 +52,42 @@ Certificate:
IPv4:
192.0.2.1-192.0.2.33
- Signature Algorithm: sha1WithRSAEncryption
- 77:f8:b2:d3:a4:61:38:f7:23:0d:a8:bc:33:a9:5e:fe:b5:1d:
- 09:ea:ee:5b:93:4c:b1:76:ea:27:9c:ad:ab:ba:b7:44:a1:8b:
- 69:89:71:a7:50:39:05:e5:69:e6:f2:7b:33:70:2a:a1:1d:87:
- ad:48:45:2a:ab:02:a2:fd:df:08:36:8d:2b:25:8d:c2:06:d5:
- 10:49:8b:88:62:94:47:5a:27:78:2e:2d:51:aa:b8:9b:13:27:
- ef:38:af:43:1f:61:f7:da:48:13:2a:0b:66:b4:7d:b4:3a:02:
- 1a:d3:88:c3:c4:df:1c:1b:86:29:05:da:61:ef:f2:b4:d4:86:
- 67:14:54:cb:21:b9:8f:38:7b:f8:ba:87:71:66:7d:cf:61:ee:
- 0b:bb:55:89:46:9d:b4:96:ab:55:90:bd:2c:c6:cf:fa:2d:c3:
- 18:a2:40:44:0e:85:dd:65:de:b1:2c:79:1b:12:e7:f6:2d:af:
- 1d:88:61:4a:67:38:17:f1:dc:2e:7c:6a:79:c2:94:8e:f4:e6:
- c2:6a:6a:7f:3f:40:bf:03:fd:22:ad:ee:df:9b:e4:bc:4b:a0:
- 73:2d:14:75:ca:c9:7c:06:2c:79:b2:c8:6f:83:d2:81:72:a8:
- 09:0b:a2:39:cb:68:b5:38:f4:09:bc:4a:83:53:26:f4:b2:ca:
- 3d:31:ed:e7
+ Signature Algorithm: sha256WithRSAEncryption
+ 66:6a:10:37:c5:13:94:1c:b1:ca:85:50:7a:20:6e:d7:a1:e5:
+ b5:70:cb:bc:f9:99:b6:58:64:fa:2a:fb:f2:15:77:b8:ea:94:
+ 28:68:c6:e7:22:69:07:57:55:4f:02:5e:5a:60:cd:fd:d7:d0:
+ b9:c3:df:23:f8:af:22:25:48:e5:a9:48:ab:38:d9:91:33:fc:
+ 88:f7:0e:94:df:a0:4e:da:06:8d:91:ed:ba:41:e5:42:ac:58:
+ af:84:da:d1:69:ca:f5:c3:42:52:2e:9c:5d:e5:72:7f:66:4b:
+ 54:8b:55:87:3c:f8:e7:16:42:ea:a8:92:2a:4c:c3:ff:f9:8d:
+ 1c:74:5f:7e:48:fe:24:18:4e:59:6e:44:a2:2c:19:3f:48:fb:
+ 50:c9:33:0f:92:9e:f7:d0:da:4b:f3:e7:a6:51:a1:da:ba:a5:
+ 8c:b6:55:46:0c:33:2c:3c:92:f5:90:ca:d9:f4:88:eb:c5:9f:
+ 31:23:3f:1f:48:66:a0:5c:b1:c0:45:45:ff:ad:0e:e8:e5:2f:
+ 22:0d:e0:f5:3a:9f:ee:e9:c5:0e:48:2b:70:c1:44:5b:69:fe:
+ 10:83:10:7e:b4:e6:e2:90:cf:dd:fd:22:6c:8a:54:69:88:99:
+ bd:bc:2e:11:c7:47:62:78:45:34:73:1e:73:43:38:fc:15:07:
+ 24:ea:82:5c
-----BEGIN CERTIFICATE-----
-MIID6DCCAtCgAwIBAgIBCjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
-IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MIIDxzCCAq+gAwIBAgIBFDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMTUxMVoXDTA4MDgwOTAxMTUxMVowGzEZ
MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
-PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCATUwggExMA8GA1UdEwEB
-/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMB8GA1UdIwQY
-MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
-BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
-bi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
-L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMBoGCCsGAQUFBwEIAQH/
-BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUAwAAC
-AQMFAcAAAiAwDQYJKoZIhvcNAQEFBQADggEBAHf4stOkYTj3Iw2ovDOpXv61HQnq
-7luTTLF26iecrau6t0Shi2mJcadQOQXlaebyezNwKqEdh61IRSqrAqL93wg2jSsl
-jcIG1RBJi4hilEdaJ3guLVGquJsTJ+84r0MfYffaSBMqC2a0fbQ6AhrTiMPE3xwb
-hikF2mHv8rTUhmcUVMshuY84e/i6h3Fmfc9h7gu7VYlGnbSWq1WQvSzGz/otwxii
-QEQOhd1l3rEseRsS5/Ytrx2IYUpnOBfx3C58annClI705sJqan8/QL8D/SKt7t+b
-5LxLoHMtFHXKyXwGLHmyyG+D0oFyqAkLojnLaLU49Am8SoNTJvSyyj0x7ec=
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCARQwggEQMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgw
+FgQCAAEwEDAOAwUAwAACAQMFAcAAAiAwDQYJKoZIhvcNAQELBQADggEBAGZqEDfF
+E5QcscqFUHogbteh5bVwy7z5mbZYZPoq+/IVd7jqlChoxuciaQdXVU8CXlpgzf3X
+0LnD3yP4ryIlSOWpSKs42ZEz/Ij3DpTfoE7aBo2R7bpB5UKsWK+E2tFpyvXDQlIu
+nF3lcn9mS1SLVYc8+OcWQuqokipMw//5jRx0X35I/iQYTlluRKIsGT9I+1DJMw+S
+nvfQ2kvz56ZRodq6pYy2VUYMMyw8kvWQytn0iOvFnzEjPx9IZqBcscBFRf+tDujl
+LyIN4PU6n+7pxQ5IK3DBRFtp/hCDEH605uKQz939ImyKVGmImb28LhHHR2J4RTRz
+HnNDOPwVByTqglw=
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP1.cnf b/scripts/resource-cert-samples/ISP1.cnf
index 179b2bd3..b43440bf 100644
--- a/scripts/resource-cert-samples/ISP1.cnf
+++ b/scripts/resource-cert-samples/ISP1.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY ISP1
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP1/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
sbgp-autonomousSysNum = critical,AS:64533
sbgp-ipAddrBlock = critical,IPv4:192.0.2.1-192.0.2.33
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP1/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+sbgp-autonomousSysNum = critical,AS:64533
+sbgp-ipAddrBlock = critical,IPv4:192.0.2.1-192.0.2.33
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/ISP1.req b/scripts/resource-cert-samples/ISP1.req
index 6f65e175..eebdcca1 100644
--- a/scripts/resource-cert-samples/ISP1.req
+++ b/scripts/resource-cert-samples/ISP1.req
@@ -1,15 +1,21 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJ
+MIIDiTCCAnECAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlV
SLc2VT3cEYhbtza+07vXFo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rR
MN4FocFUfBdnHfwp3YBTsoEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMys
VO2u/eLNsaNdqWXsG4tLz4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT
6GLoGgyoMIFqvpBZIzthwBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY
-6G54iHuVdrbKvvGAqd3oPICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaAA
-MA0GCSqGSIb3DQEBBQUAA4IBAQAyKlLYDwS59IWCvrnzXeuPsHkpseZ9AYZpVHDD
-6K8kmroKfhv5ockUFa2MjuAhy9+m6hnSA9XMrHV3qXBN/DPpi8wXbO4gCzfvoGvy
-EcneXLzlmhYDjjB4bqgvoCGwtehPS3epzXzFu/UONWTja0hLYXfXXZHZzRQfER55
-qZy6bVrSTSqCALl5bZr39AhnvF0EQDSa5sowfDCezsWrHYRGTsIY3m91j9CMTefA
-Pdf36rbBaCk9BvXpADNiwi91nI4U1jsQXcBRfKJFimLU20Vtce+i3M5ljWDwsBXl
-vXoAqKe3EKOs6NqK3C5G9A3yMtTVX7BxBWpjm5X76F05I0tj
+6G54iHuVdrbKvvGAqd3oPICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaCC
+AScwggEjBgkqhkiG9w0BCQ4xggEUMIIBEDAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
+DgQWBBRm7CkhLnaDGTntju23BqhM5Q4uETAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYB
+BQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDEvMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEFBQcwAoYocnN5bmM6
+Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLmNlcjAaBggrBgEFBQcBCAEB
+/wQLMAmgBzAFAgMA/BUwKQYIKwYBBQUHAQcBAf8EGjAYMBYEAgABMBAwDgMFAMAA
+AgEDBQHAAAIgMA0GCSqGSIb3DQEBBQUAA4IBAQCx9lXfyZUDlBicMfvtaMwLWtGr
+kkYIccWF1QALOSihij3D1eZk5gRVElivTHwFr/FAVceNmbWij7Bj62qV19ayVju4
+kfuYQKzAA+ncMk4VxYCrJAbhcnF7OCwGM90S5MX2n/SfHqaufNv86aJCJ/q09Knl
+wta4E45lKUt3GGwHPeXxqCPGqmtUOFt1L//ZDBn9NEB9xZQK4+iZGYvx1TVfXLR6
+w7uUIwkWKD0mY1+JJ2iJuFWvs4hWiWQFnesMEBthIYIWEceXrvYK96jG3Q6PwpxK
+zLrGOdYQunifeSNoxis2jJ8cyKcBNNEa+XxEc1IJP5ySJyfJU651IGboFNiL
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP2.cer b/scripts/resource-cert-samples/ISP2.cer
index 0a5c3837..ca17b5f4 100644
--- a/scripts/resource-cert-samples/ISP2.cer
+++ b/scripts/resource-cert-samples/ISP2.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 9 (0x9)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 19 (0x13)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY LIR1
Validity
- Not Before: Aug 1 14:48:22 2007 GMT
- Not After : Jul 31 14:48:22 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY ISP2
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
- X509v3 Authority Key Identifier:
- keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -51,42 +48,41 @@ Certificate:
IPv4:
192.0.2.44-192.0.2.100
- Signature Algorithm: sha1WithRSAEncryption
- 0a:f1:b5:af:38:f9:7d:93:95:d4:ea:bf:48:ef:8d:63:3c:4e:
- 1c:80:3d:7a:06:20:42:0e:0d:52:99:aa:4b:3e:af:d7:b4:61:
- 47:4f:b7:b4:f7:cc:9b:3c:5e:a5:3b:3c:ba:dd:b7:2a:27:8e:
- 1b:b4:5c:3c:6b:d1:d9:ff:c2:12:f7:9d:82:ba:cf:75:34:bc:
- d7:0b:b4:d6:a8:4f:58:93:6a:ae:23:7a:37:e3:2e:f1:70:8a:
- dd:f5:0e:fa:df:b0:3f:12:d4:5a:ac:33:ad:15:1c:a5:dc:be:
- 08:c3:8e:1a:0f:35:12:0e:de:ef:b8:80:78:90:a9:eb:8f:00:
- 0a:15:1d:05:12:3a:1d:37:e9:f4:f9:4a:77:6e:69:27:b7:e3:
- 7f:ae:78:32:92:86:6d:39:16:5e:59:4f:93:10:b5:b0:be:1c:
- 25:47:2a:e2:8f:92:9f:5c:c0:2a:48:d7:53:00:14:8e:9e:86:
- ea:cf:a6:21:66:50:89:95:39:3e:ff:27:95:85:ef:3d:c8:98:
- 7f:cd:fe:c1:30:65:94:b1:ad:48:5c:ae:b7:c8:64:e9:69:a2:
- 07:ca:c2:d7:fe:63:4b:de:a9:25:a1:91:4b:17:a3:a9:dd:2b:
- f7:d1:a5:3e:b7:be:42:03:1e:d9:34:5f:16:e3:35:7a:ca:1d:
- ee:3d:4c:d5
+ Signature Algorithm: sha256WithRSAEncryption
+ a0:55:12:46:3d:61:d3:08:29:a5:43:f1:62:19:a9:75:90:17:
+ 51:85:19:8c:98:29:3c:ed:b8:13:5f:14:e4:8f:1a:85:18:4f:
+ 92:b5:5b:5f:2b:97:49:c2:ec:7b:cb:87:b5:28:4e:99:77:6c:
+ f9:8f:2a:14:86:fc:1b:93:90:92:c8:21:0c:c3:ab:02:e8:e3:
+ 6d:c2:cf:55:51:54:08:58:a0:2f:b4:70:56:21:48:ce:1c:ba:
+ c6:1f:08:cb:59:e0:37:9c:75:4d:ca:cb:5d:6d:6b:53:4f:7f:
+ 6e:b0:21:06:52:dd:0a:24:13:b8:95:c1:0b:62:4f:31:27:b5:
+ df:0c:31:ce:51:62:1e:a3:89:40:2b:14:34:58:ac:62:a6:1d:
+ 70:09:b1:e3:ee:bb:cc:ca:61:e2:27:2b:51:81:17:73:5f:a5:
+ 7b:1a:9b:fb:f9:4e:6f:d3:68:ad:43:8a:0e:87:32:6f:3e:9d:
+ 03:4b:61:d0:b2:30:38:ec:23:3a:48:f7:1e:5c:d6:6a:eb:03:
+ 14:4e:69:33:04:07:3e:87:6c:7f:cd:8d:0a:2d:75:32:18:cc:
+ 0e:9b:74:14:87:61:39:18:5c:53:d4:90:39:56:5e:14:ae:70:
+ 33:1c:88:58:a7:42:7e:35:88:c9:ba:a0:af:c1:03:18:fe:4d:
+ 9e:40:54:a5
-----BEGIN CERTIFICATE-----
-MIIDzDCCArSgAwIBAgIBCTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
-IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MIIDqTCCApGgAwIBAgIBEzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowGzEZ
MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
-Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOCARkwggEVMA8GA1UdEwEB
-/wQFMAMBAf8wHQYDVR0OBBYEFHOyFhrN3NcwYA/6gZX4ovVOlfOtMB8GA1UdIwQY
-MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
-BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
-bi5uZXQvSVNQMi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
-L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMCkGCCsGAQUFBwEHAQH/
-BBowGDAWBAIAATAQMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEA
-CvG1rzj5fZOV1Oq/SO+NYzxOHIA9egYgQg4NUpmqSz6v17RhR0+3tPfMmzxepTs8
-ut23KieOG7RcPGvR2f/CEvedgrrPdTS81wu01qhPWJNqriN6N+Mu8XCK3fUO+t+w
-PxLUWqwzrRUcpdy+CMOOGg81Eg7e77iAeJCp648AChUdBRI6HTfp9PlKd25pJ7fj
-f654MpKGbTkWXllPkxC1sL4cJUcq4o+Sn1zAKkjXUwAUjp6G6s+mIWZQiZU5Pv8n
-lYXvPciYf83+wTBllLGtSFyut8hk6WmiB8rC1/5jS96pJaGRSxejqd0r99GlPre+
-QgMe2TRfFuM1esod7j1M1Q==
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOB9zCB9DAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBRzshYazdzXMGAP+oGV+KL1TpXzrTAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDIvMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEF
+BQcwAoYocnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLmNlcjAp
+BggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUCwAACLAMFAMAAAmQwDQYJKoZI
+hvcNAQELBQADggEBAKBVEkY9YdMIKaVD8WIZqXWQF1GFGYyYKTztuBNfFOSPGoUY
+T5K1W18rl0nC7HvLh7UoTpl3bPmPKhSG/BuTkJLIIQzDqwLo423Cz1VRVAhYoC+0
+cFYhSM4cusYfCMtZ4DecdU3Ky11ta1NPf26wIQZS3QokE7iVwQtiTzEntd8MMc5R
+Yh6jiUArFDRYrGKmHXAJsePuu8zKYeInK1GBF3NfpXsam/v5Tm/TaK1Dig6HMm8+
+nQNLYdCyMDjsIzpI9x5c1mrrAxROaTMEBz6HbH/NjQotdTIYzA6bdBSHYTkYXFPU
+kDlWXhSucDMciFinQn41iMm6oK/BAxj+TZ5AVKU=
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP2.cnf b/scripts/resource-cert-samples/ISP2.cnf
index ffc02166..befdf77b 100644
--- a/scripts/resource-cert-samples/ISP2.cnf
+++ b/scripts/resource-cert-samples/ISP2.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY ISP2
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP2/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
#sbgp-autonomousSysNum = critical,???
sbgp-ipAddrBlock = critical,IPv4:192.0.2.44-192.0.2.100
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP2/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv4:192.0.2.44-192.0.2.100
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/ISP2.req b/scripts/resource-cert-samples/ISP2.req
index 75b8f436..63ee5838 100644
--- a/scripts/resource-cert-samples/ISP2.req
+++ b/scripts/resource-cert-samples/ISP2.req
@@ -1,15 +1,21 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJ
+MIIDazCCAlMCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er
45X9kmCsFBLXI2iFSw7bK+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd
6SJCLPZcpn15jOEIGXw1nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9ar
QhtkmlwZgyud5a1MWAV2lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZz
CKxZO74vWMFCxYAYjDoKKjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5
-fytddijJycV+5UOhm2jSBhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaAA
-MA0GCSqGSIb3DQEBBQUAA4IBAQDFKEbfAZaF563uK9VaYezw4OJ1a+atHbLlx0hF
-6Xc/XMxHVV1UD+nR7jVKLAH7IGwCe42slxcXgkcwtKXpRVPqmsYpwBbrVYSZmU/P
-3OP0PSZ1i9VWUN1XoUFJfE8E+2t1NhylBXqZTDUjPxLxWIYE9IFeN0aHiWrElbmU
-Qjrt7N/L+9rJTKtP0aT6uTUKAstfmZyp3yiHLjsszrMdZknAEvUVFkjQEt5GOOXL
-eyutwgj4sMnDpMnp6bCHNBqDmj7VBzUzaPtEQO4bDTur2O5Ny5zDGR35g4DXuhh7
-o0wI/sVzcMmTzc3nQ5YXNACUjCUxrM+L+EAmYoFQ1SDu5wPE
+fytddijJycV+5UOhm2jSBhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaCC
+AQkwggEFBgkqhkiG9w0BCQ4xgfcwgfQwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4E
+FgQUc7IWGs3c1zBgD/qBlfii9U6V860wDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9JU1AyLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMS5jZXIwKQYIKwYBBQUHAQcBAf8E
+GjAYMBYEAgABMBAwDgMFAsAAAiwDBQDAAAJkMA0GCSqGSIb3DQEBBQUAA4IBAQAA
+OhLVxJb0yeEqJ1TPd9J95a+mbWXtF2QbEDk6cJ+9Xd+5S/G7e7O7oVZfDyN4K5VT
+IsI+G4Rm9+bt1OaGsFz5DUC7fxVUnvTWykP8w/LMBdJcLxVc/ugPvKQZ0Z6TxaZo
+excGiDlkYCdUUxl3CoALC/pIMnNruqHCad2b9WkphGyk89diN5enRV14bcS622na
+FOfmpt+5RqO4EQK3NivX9T6YbLj80vZW95CxI/PRjqt5RsDhl1cYJ5+pexVOa10B
+BwA/R7S658Rs35Ad/DWM36DHVrGYBU2IRpyhnsADixZLXxWlhz9CqNvj+DWQvqpa
+IH++V9c1MUulNBZdmf7K
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP3.cer b/scripts/resource-cert-samples/ISP3.cer
index c8f4890e..c31add0d 100644
--- a/scripts/resource-cert-samples/ISP3.cer
+++ b/scripts/resource-cert-samples/ISP3.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 10 (0xa)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 20 (0x14)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY LIR2
Validity
- Not Before: Aug 1 14:48:22 2007 GMT
- Not After : Jul 31 14:48:22 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY ISP3
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
- X509v3 Authority Key Identifier:
- keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -51,42 +48,42 @@ Certificate:
IPv6:
2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
- Signature Algorithm: sha1WithRSAEncryption
- 05:ba:27:d4:55:52:1b:f7:61:da:37:98:b3:16:e6:53:6a:2c:
- 65:f5:80:7f:d4:cb:8f:fb:c2:1d:1a:9f:54:ed:a0:7a:03:a6:
- ff:5a:e7:d6:c1:06:31:11:b5:c1:dc:ab:33:87:d7:57:0e:cd:
- 19:44:16:9f:92:84:43:32:8b:d0:64:12:00:a7:ad:b7:fb:79:
- c1:ec:e3:d0:77:3c:73:8a:5f:90:6b:da:a4:d4:e0:28:0a:45:
- 99:5a:b8:b0:fa:96:3e:c3:a3:de:a6:df:f9:55:e9:1b:3e:37:
- f0:21:38:7f:5f:b2:e0:75:f2:8c:82:10:e9:60:76:3b:de:dd:
- 85:f2:1e:3c:22:f5:77:40:d9:a4:f9:72:46:29:99:a8:2e:5d:
- b8:05:5c:b3:2b:d0:44:c5:8b:07:c7:69:d0:a9:cf:83:31:d1:
- ed:36:d7:ce:b4:c6:7e:4a:58:10:20:46:16:ed:b5:e3:60:47:
- e8:b2:36:1e:79:ed:ac:08:da:8b:a0:6d:92:f1:e4:73:60:6b:
- 10:61:07:69:78:78:a9:51:fd:24:1d:3d:d6:63:62:c3:d4:1e:
- 70:8d:f6:41:fc:42:09:cc:7b:1c:19:c7:59:0b:a0:da:5b:00:
- fd:33:24:8b:9f:1e:d8:d8:04:cd:f4:71:06:ea:c6:2e:8d:8b:
- 6f:cd:b9:a6
+ Signature Algorithm: sha256WithRSAEncryption
+ 58:b8:cd:b3:34:ce:a2:4f:39:c1:15:09:b4:95:f8:5e:7b:23:
+ 9b:fb:42:6f:92:5a:29:ce:17:c1:99:d6:c7:39:00:43:e1:60:
+ bb:17:f5:34:df:33:86:73:77:f4:8f:6f:d5:88:1d:68:be:f8:
+ 13:fd:02:38:fa:aa:9c:39:80:1b:dc:50:72:23:d6:0a:64:55:
+ 14:78:fe:64:1a:63:53:bb:e6:78:35:88:2c:d1:7a:1b:3c:23:
+ 72:8a:a5:c0:5b:5c:7c:85:b1:26:a1:c0:ce:a9:c0:16:5d:30:
+ eb:2d:7e:69:48:57:6b:dc:34:88:56:47:99:ed:31:47:c1:3e:
+ ff:b6:9e:69:cc:68:2e:1c:4c:77:27:d4:a5:45:f9:cb:a5:21:
+ 23:46:18:20:2a:a0:7c:b9:eb:d1:d8:91:30:2e:b4:16:07:b6:
+ 9f:3a:28:71:1d:ee:f9:a7:88:59:45:78:b7:36:0e:15:f6:77:
+ e4:69:b4:b1:61:9a:5c:66:0f:c5:7c:67:d7:af:d3:24:24:4e:
+ e7:94:ce:a6:d6:3b:5a:c8:d7:49:58:93:d7:f5:41:2f:b3:9a:
+ 93:c8:6c:ec:2f:be:6a:c1:74:2a:44:bb:5c:7b:d8:16:f6:01:
+ ed:5b:e8:6b:02:48:ef:5b:57:f4:07:fd:5f:47:e6:06:38:3c:
+ a2:4b:d0:f9
-----BEGIN CERTIFICATE-----
-MIID5DCCAsygAwIBAgIBCjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
-IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MIIDwzCCAqugAwIBAgIBFDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowGzEZ
MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
-3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCATEwggEtMA8GA1UdEwEB
-/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MB8GA1UdIwQY
-MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
-BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
-bi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
-L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMEEGCCsGAQUFBwEHAQH/
-BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
-AAABADANBgkqhkiG9w0BAQUFAAOCAQEABbon1FVSG/dh2jeYsxbmU2osZfWAf9TL
-j/vCHRqfVO2gegOm/1rn1sEGMRG1wdyrM4fXVw7NGUQWn5KEQzKL0GQSAKett/t5
-wezj0Hc8c4pfkGvapNTgKApFmVq4sPqWPsOj3qbf+VXpGz438CE4f1+y4HXyjIIQ
-6WB2O97dhfIePCL1d0DZpPlyRimZqC5duAVcsyvQRMWLB8dp0KnPgzHR7TbXzrTG
-fkpYECBGFu2142BH6LI2HnntrAjai6BtkvHkc2BrEGEHaXh4qVH9JB091mNiw9Qe
-cI32QfxCCcx7HBnHWQug2lsA/TMki58e2NgEzfRxBurGLo2Lb825pg==
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCARAwggEMMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MEEGCCsGAQUFBwEHAQH/BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABE
+AxEAIAENuAAAAAAAAAAAAAABADANBgkqhkiG9w0BAQsFAAOCAQEAWLjNszTOok85
+wRUJtJX4Xnsjm/tCb5JaKc4XwZnWxzkAQ+Fguxf1NN8zhnN39I9v1YgdaL74E/0C
+OPqqnDmAG9xQciPWCmRVFHj+ZBpjU7vmeDWILNF6GzwjcoqlwFtcfIWxJqHAzqnA
+Fl0w6y1+aUhXa9w0iFZHme0xR8E+/7aeacxoLhxMdyfUpUX5y6UhI0YYICqgfLnr
+0diRMC60Fge2nzoocR3u+aeIWUV4tzYOFfZ35Gm0sWGaXGYPxXxn16/TJCRO55TO
+ptY7WsjXSViT1/VBL7Oak8hs7C++asF0KkS7XHvYFvYB7VvoawJI71tX9Af9X0fm
+Bjg8okvQ+Q==
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP3.cnf b/scripts/resource-cert-samples/ISP3.cnf
index c369f198..ded3be5d 100644
--- a/scripts/resource-cert-samples/ISP3.cnf
+++ b/scripts/resource-cert-samples/ISP3.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY ISP3
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP3/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
#sbgp-autonomousSysNum = critical,???
sbgp-ipAddrBlock = critical,IPv6:2001:db8::44-2001:db8::100
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP3/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv6:2001:db8::44-2001:db8::100
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/ISP3.req b/scripts/resource-cert-samples/ISP3.req
index d0bdb9ca..778b5d87 100644
--- a/scripts/resource-cert-samples/ISP3.req
+++ b/scripts/resource-cert-samples/ISP3.req
@@ -1,15 +1,21 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJ
+MIIDhTCCAm0CAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/S
QqExfZw+ZnLOLN8BFxVAQJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiE
zB1m7jVSx66ZdrFjTcEuJPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJT
oXA52Z7lVvxY0LPzkDdablo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5
nIi8c98UWrwW/Ph5sKFBhwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/
-754C+VRmKiiZeSu1GRDU3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaAA
-MA0GCSqGSIb3DQEBBQUAA4IBAQCezSRdM4ZX05WJKj/n8i4I1HCgGZzs9xnfwPoX
-5N7sTK3QTOdI+4nJXP4zXgJewM73rf0NBQ2DhC5bD3cGMzbM6TE95KZjuGwje5CO
-c0gZ17cxUBlTJpOFBze0JU7g6xyctB3bztBcEn9cSP3kHqP1XendqHEcU2xM5jwx
-0jV3usS5zit1ti3aFpHFiazFYrF7C8NWTwirJaK9c+bru7GQnVZBkNZBgcy56u+B
-TPv/x403w65CsYz+IfVHBbzKY/lzwZ0LXmE5rv+3SzgyXfzHUjMa8ucJVumJeWwf
-2ZEKTUJJ+BuF2Z3/MMNNmQqFV5FaO2hn7l83v6oOZHNfGafR
+754C+VRmKiiZeSu1GRDU3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaCC
+ASMwggEfBgkqhkiG9w0BCQ4xggEQMIIBDDAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
+DgQWBBThly4ZcLV//IJPMz1rLN6amzY9fjAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYB
+BQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDMvMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEFBQcwAoYocnN5bmM6
+Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9MSVIyLmNlcjBBBggrBgEFBQcBBwEB
+/wQyMDAwLgQCAAIwKDAmAxECIAENuAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAA
+AAAAAQAwDQYJKoZIhvcNAQEFBQADggEBAMA7nOGLldNHO8nRhTnDGiNPWIf+YRB1
+tsbUmD1IhvZiQQnl4s871cxid0cBAOJpY7glGJZ6XbHmLRtLpROkDHURt23QmFy5
+0RL3iQSRb0/yW7yP5hxtmPyU5FlgM/4Ft5np3OD2n9zNeAI/biH7VUMKQ12CzLf7
+PLBsfBK1dbUojxA8gi2s8xbIH9OMxPqJybx664JPOxR0NTaQRdS55jQhpHG10SxY
+mvbB6htt/nM4GG6FKfOsggMp0J6tdWhqJOljFGW07jZwUbHBZX1AsQJAl6B5Ykx7
+4B4SMGLiZXMfG1r72UcWCUlNyd/xo4GT9ay7hB6isl9U2Ac1nsTrdEw=
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP4.cer b/scripts/resource-cert-samples/ISP4.cer
index b117c94d..415517d5 100644
--- a/scripts/resource-cert-samples/ISP4.cer
+++ b/scripts/resource-cert-samples/ISP4.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 9 (0x9)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 19 (0x13)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY LIR2
Validity
- Not Before: Aug 1 14:48:22 2007 GMT
- Not After : Jul 31 14:48:22 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY ISP4
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
- X509v3 Authority Key Identifier:
- keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -55,42 +52,42 @@ Certificate:
IPv6:
2001:db8:0:0:0:10:0:44/128
- Signature Algorithm: sha1WithRSAEncryption
- 1c:53:2a:8f:55:44:b1:71:d1:50:79:f1:3c:3d:fe:15:1d:72:
- 5e:22:91:d1:54:3d:a4:e0:9e:ba:e4:8d:b3:71:c5:93:cd:5b:
- 54:5c:e5:2c:af:a1:a9:d7:8d:32:b7:92:95:8c:0e:2e:05:d3:
- 9d:da:ac:a9:7a:01:d2:19:9e:b7:88:80:92:b1:26:95:6d:0a:
- b4:01:a3:f1:9f:15:fe:0b:29:0f:0f:72:b7:72:d2:18:9e:5d:
- 7e:65:59:7b:30:75:33:7f:95:fc:cb:9d:7b:0f:36:44:0f:d0:
- e6:a3:c1:a5:6b:d0:db:13:4b:fa:06:35:df:66:01:c3:d8:51:
- 47:e7:89:26:56:6f:2a:2a:ba:46:29:a8:cb:9d:cc:5f:d9:9f:
- 14:01:d5:fd:08:e9:db:1a:7a:89:3e:c8:36:6b:b4:6c:ca:a9:
- df:43:46:89:48:a0:13:32:bb:c9:17:14:01:2d:21:fe:68:11:
- 61:5a:b4:6f:af:ba:3b:0a:96:4c:25:33:5a:a6:cf:29:21:45:
- 76:b8:e1:d9:20:0c:22:f7:7c:85:b2:45:90:94:c5:2c:ca:e1:
- 82:65:36:75:9d:46:9b:f8:9a:d6:85:2f:71:8b:cd:88:fd:87:
- 1b:1c:36:f8:36:f5:1c:18:e5:5b:68:3f:36:60:de:a0:59:e1:
- cd:54:61:4c
+ Signature Algorithm: sha256WithRSAEncryption
+ c4:46:cc:b9:a5:85:42:ff:9b:32:39:a8:0f:f6:51:35:09:fa:
+ b0:a8:1c:14:4f:72:ff:2c:17:fb:ab:6a:c2:c4:48:2a:2a:fe:
+ 42:c5:c2:92:4a:37:01:b7:69:b1:6c:83:52:2d:8e:8c:aa:04:
+ 82:bb:93:64:c2:0a:a9:7f:bd:82:2a:82:e4:df:2c:0e:5c:16:
+ 12:c7:33:39:0b:f7:99:5b:f5:5d:e0:d3:f8:48:3e:ff:25:a0:
+ e2:38:bb:fe:f1:fa:44:da:54:41:b2:1a:2c:1b:41:d2:54:3e:
+ 3b:43:35:a0:71:72:ff:a8:76:03:e2:9f:78:75:45:6c:8f:5e:
+ c2:5b:4f:e7:6b:ab:66:0a:d4:6c:47:10:ab:90:c5:b2:c9:53:
+ a6:2a:a4:c2:ca:b9:b3:f1:3d:9a:75:d0:d4:94:aa:79:6d:ec:
+ 16:1a:85:91:1d:d8:4a:ef:79:88:9e:2c:96:b0:bd:33:6b:e4:
+ 21:f1:ee:68:14:4b:58:cc:11:8f:6f:05:2d:6f:c3:99:9b:e6:
+ 8f:06:6b:a6:f9:45:2f:41:9f:38:9b:c8:80:98:1f:15:02:7d:
+ f1:08:19:a5:5a:30:c1:eb:72:ee:f4:a7:c5:fa:7a:35:af:24:
+ 62:b1:54:4c:d5:4c:42:ef:fe:9e:5f:65:80:4f:42:7e:e3:7f:
+ 35:18:5c:6b
-----BEGIN CERTIFICATE-----
-MIID6zCCAtOgAwIBAgIBCTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
-IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MIIDyjCCArKgAwIBAgIBEzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowGzEZ
MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
-bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCATgwggE0MA8GA1UdEwEB
-/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMB8GA1UdIwQY
-MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
-BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
-bi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
-L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMBoGCCsGAQUFBwEIAQH/
-BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBswGQQCAAIwEwMRACABDbgA
-AAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBABxTKo9VRLFx0VB58Tw9/hUd
-cl4ikdFUPaTgnrrkjbNxxZPNW1Rc5SyvoanXjTK3kpWMDi4F053arKl6AdIZnreI
-gJKxJpVtCrQBo/GfFf4LKQ8Pcrdy0hieXX5lWXswdTN/lfzLnXsPNkQP0OajwaVr
-0NsTS/oGNd9mAcPYUUfniSZWbyoqukYpqMudzF/ZnxQB1f0I6dsaeok+yDZrtGzK
-qd9DRolIoBMyu8kXFAEtIf5oEWFatG+vujsKlkwlM1qmzykhRXa44dkgDCL3fIWy
-RZCUxSzK4YJlNnWdRpv4mtaFL3GLzYj9hxscNvg29RwY5VtoPzZg3qBZ4c1UYUw=
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCARcwggETMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBsw
+GQQCAAIwEwMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQELBQADggEBAMRG
+zLmlhUL/mzI5qA/2UTUJ+rCoHBRPcv8sF/urasLESCoq/kLFwpJKNwG3abFsg1It
+joyqBIK7k2TCCql/vYIqguTfLA5cFhLHMzkL95lb9V3g0/hIPv8loOI4u/7x+kTa
+VEGyGiwbQdJUPjtDNaBxcv+odgPin3h1RWyPXsJbT+drq2YK1GxHEKuQxbLJU6Yq
+pMLKubPxPZp10NSUqnlt7BYahZEd2ErveYieLJawvTNr5CHx7mgUS1jMEY9vBS1v
+w5mb5o8Ga6b5RS9BnzibyICYHxUCffEIGaVaMMHrcu70p8X6ejWvJGKxVEzVTELv
+/p5fZYBPQn7jfzUYXGs=
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP4.cnf b/scripts/resource-cert-samples/ISP4.cnf
index b52752b6..f9effea4 100644
--- a/scripts/resource-cert-samples/ISP4.cnf
+++ b/scripts/resource-cert-samples/ISP4.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY ISP4
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP4/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
sbgp-autonomousSysNum = critical,AS:64544
sbgp-ipAddrBlock = critical,IPv6:2001:db8::10:0:44/128
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP4/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+sbgp-autonomousSysNum = critical,AS:64544
+sbgp-ipAddrBlock = critical,IPv6:2001:db8::10:0:44/128
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/ISP4.req b/scripts/resource-cert-samples/ISP4.req
index dee4e58f..5c9d865c 100644
--- a/scripts/resource-cert-samples/ISP4.req
+++ b/scripts/resource-cert-samples/ISP4.req
@@ -1,15 +1,21 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJ
+MIIDjDCCAnQCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578
LRzf4itXOEjrxBOj/WzF4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53
qRTiTCAO/8Ug+vNtOwvO4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz
8zWF6QA5krOfSmu96aAAyr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQ
Kck54P+QTZVHVhPhMPMwM+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inl
-D5s7AC5PDvUxkey9NAJobddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaAA
-MA0GCSqGSIb3DQEBBQUAA4IBAQCwB+5YMpq5NcvR0wmWBfltr6V3OBz+fZv1HRRX
-uxGfCTIkQ5SEh2NbyFybflyrcz7OVOIvGRpmGY4aFfIvXBCJq+eGNgs0CFhPBelq
-z9/VaKyV6oSJ630L52qHqjbz7qTnT/zMzcHHQvxNxpNCFDehtgq86ht0hFtRziBS
-ZAjubz8Vmb8PtVQcOJXZwjNLMq6slAeNl9FLE2CTyNZ773vc0iHePpULtcL9p8/y
-d4fq1c+t6g9pQvWwQaa9qiKGuf83ZfsWxoEmypxr1cR1zyYVZ4VhHmfHM8AWXBKM
-i8PADB+5O59TUF9jihzuPmy/Se9AV6ghauAenJAbsU/J9/di
+D5s7AC5PDvUxkey9NAJobddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaCC
+ASowggEmBgkqhkiG9w0BCQ4xggEXMIIBEzAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
+DgQWBBSYz/gAguzX6RdPvXqHYDKlu521DjAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYB
+BQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDQvMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEFBQcwAoYocnN5bmM6
+Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9MSVIyLmNlcjAaBggrBgEFBQcBCAEB
+/wQLMAmgBzAFAgMA/CAwLAYIKwYBBQUHAQcBAf8EHTAbMBkEAgACMBMDEQAgAQ24
+AAAAAAAAABAAAABEMA0GCSqGSIb3DQEBBQUAA4IBAQBq2qdZveIZPxJTOaKb5JUV
+0VlBFjDht7k9mw7dxqvFZ2CL7oNbTTG3n0t9060xR89jp2+4760LdAkNn62MQlzw
+p42DZy65fBnNpwDY9+0khoJqZIjYdYnUrW+002S+sxRFToAdpTd13RKre/KFPAx4
+jaMzCZ8ARONVR8TfjT0FGsh/0PpdwNsdihltVqw/SfPGK50kXX1Xlp1Yo82wjmZ/
+R9ohWBBJzcf//GdHp5yBoKFjBD6ZJ7QRP6I/vxYOpq4VrqkCa6MVmsoirRAHVgoe
+JsHjusxM9SRyBPaZXywaswuCC3jm1R6s6FYH0df+3IjfNXb6PqUXIFX3/xMIZI44
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP5a.cer b/scripts/resource-cert-samples/ISP5a.cer
index 50780320..2ca7eef4 100644
--- a/scripts/resource-cert-samples/ISP5a.cer
+++ b/scripts/resource-cert-samples/ISP5a.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 3 (0x3)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 18 (0x12)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY LIR3
Validity
- Not Before: Aug 1 14:48:22 2007 GMT
- Not After : Jul 31 14:48:22 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY ISP5a
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
09:F0:14:0B:79:FB:0B:FF:A8:EF:54:B9:EC:3E:B9:8B:D0:CB:9C:EC
- X509v3 Authority Key Identifier:
- keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -53,42 +50,42 @@ Certificate:
IPv6:
2001:db8:0:0:0:0:a00::/120
- Signature Algorithm: sha1WithRSAEncryption
- 93:32:99:62:dd:c5:ea:f0:1f:58:50:10:37:d3:39:37:d9:f6:
- 92:51:26:2f:d6:fd:6f:82:b8:56:6b:fd:0c:f3:42:04:56:ed:
- 67:2b:42:02:98:56:07:f1:48:2d:2e:b4:32:bb:d7:1c:27:14:
- a0:e9:ad:3b:1d:fe:0b:0e:43:df:22:97:f1:8f:73:d8:76:d6:
- 9b:0d:bf:ee:20:e8:77:17:a3:83:01:b3:23:43:85:6b:bf:6f:
- cc:2e:69:47:05:73:f4:21:45:94:c8:ae:21:28:41:16:91:ee:
- 48:49:66:5a:67:31:71:04:c9:49:71:94:d5:f4:86:5c:7b:c6:
- 3e:fe:91:1d:21:b3:14:98:54:ad:6e:51:28:e9:a8:22:ba:a4:
- d0:9c:8c:e3:d4:7c:21:10:0c:f9:a3:00:f8:c3:9f:00:b4:53:
- 34:06:af:5b:4a:43:95:cb:b2:fb:8c:18:00:86:11:28:5e:24:
- e1:90:d8:67:d8:00:fc:b6:27:1f:9e:b1:be:91:17:c1:11:35:
- 6e:9c:60:50:2e:67:f3:04:2b:74:89:f9:fe:92:73:dd:1e:44:
- 81:67:b8:08:63:a8:9f:f4:8c:bc:47:de:f1:df:8b:11:cd:02:
- ec:b9:ad:0b:06:28:0c:e2:84:36:83:85:f3:4f:46:56:46:d5:
- f5:f8:cb:f3
+ Signature Algorithm: sha256WithRSAEncryption
+ 36:9d:84:eb:95:7f:1e:45:82:16:54:14:e6:50:f9:61:6f:a2:
+ 16:01:57:9c:f6:c3:00:d7:00:8f:a4:af:12:c7:71:f9:ac:e7:
+ f5:57:5e:8a:92:6e:00:08:d4:b1:2e:bf:07:cc:e8:f9:05:97:
+ 21:fe:00:12:ab:33:ad:77:3d:01:54:be:c7:57:1d:b6:ba:e8:
+ 71:56:35:71:67:10:5f:78:67:92:d9:b2:3f:26:12:78:e2:5b:
+ 24:ed:b3:45:95:d7:6c:c3:0a:c9:7c:e7:db:e3:e9:90:24:cb:
+ a1:a0:3e:05:7f:8d:4e:bc:a5:39:c6:b1:ac:29:21:28:9f:d4:
+ 58:3f:cd:07:d0:81:fd:d4:e2:b8:cc:ef:b1:75:cb:eb:73:30:
+ f8:84:7a:bb:42:bf:bf:23:4e:e9:34:1e:c0:49:ea:ed:9a:62:
+ 70:f8:79:08:4b:b1:80:a1:da:a6:c5:3e:78:20:5e:10:da:81:
+ 29:8f:ff:6d:0e:d8:91:be:ee:2e:f7:c0:cc:87:88:45:3f:73:
+ 63:ba:a0:66:73:94:6c:79:aa:f4:ec:85:62:32:2b:aa:f2:0d:
+ a5:66:42:f4:ca:83:8b:b5:73:a5:78:2f:0e:bc:87:e4:ec:1a:
+ 2b:c3:83:55:8e:35:65:39:62:41:86:74:d5:2a:a5:c6:05:03:
+ 0a:e2:ea:76
-----BEGIN CERTIFICATE-----
-MIID3jCCAsagAwIBAgIBAzANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
-IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowHDEa
+MIIDvTCCAqWgAwIBAgIBEjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowHDEa
MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
-PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjggEqMIIBJjAPBgNVHRMB
-Af8EBTADAQH/MB0GA1UdDgQWBBQJ8BQLefsL/6jvVLnsPrmL0Muc7DAfBgNVHSME
-GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
-BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
-cm4ubmV0L0lTUDVhLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
-Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwOQYIKwYBBQUHAQcB
-Af8EKjAoMAwEAgABMAYDBAAKAAAwGAQCAAIwEgMQACABDbgAAAAAAAAAAAoAADAN
-BgkqhkiG9w0BAQUFAAOCAQEAkzKZYt3F6vAfWFAQN9M5N9n2klEmL9b9b4K4Vmv9
-DPNCBFbtZytCAphWB/FILS60MrvXHCcUoOmtOx3+Cw5D3yKX8Y9z2HbWmw2/7iDo
-dxejgwGzI0OFa79vzC5pRwVz9CFFlMiuIShBFpHuSElmWmcxcQTJSXGU1fSGXHvG
-Pv6RHSGzFJhUrW5RKOmoIrqk0JyM49R8IRAM+aMA+MOfALRTNAavW0pDlcuy+4wY
-AIYRKF4k4ZDYZ9gA/LYnH56xvpEXwRE1bpxgUC5n8wQrdIn5/pJz3R5EgWe4CGOo
-n/SMvEfe8d+LEc0C7LmtCwYoDOKENoOF809GVkbV9fjL8w==
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQJ8BQLefsL/6jvVLnsPrmL0Muc7DAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDVhLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAAAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoAADANBgkqhkiG9w0BAQsFAAOCAQEANp2E65V/HkWCFlQU5lD5
+YW+iFgFXnPbDANcAj6SvEsdx+azn9VdeipJuAAjUsS6/B8zo+QWXIf4AEqszrXc9
+AVS+x1cdtrrocVY1cWcQX3hnktmyPyYSeOJbJO2zRZXXbMMKyXzn2+PpkCTLoaA+
+BX+NTrylOcaxrCkhKJ/UWD/NB9CB/dTiuMzvsXXL63Mw+IR6u0K/vyNO6TQewEnq
+7ZpicPh5CEuxgKHapsU+eCBeENqBKY//bQ7Ykb7uLvfAzIeIRT9zY7qgZnOUbHmq
+9OyFYjIrqvINpWZC9MqDi7VzpXgvDryH5OwaK8ODVY41ZTliQYZ01SqlxgUDCuLq
+dg==
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP5a.cnf b/scripts/resource-cert-samples/ISP5a.cnf
index c21f08e2..fa470452 100644
--- a/scripts/resource-cert-samples/ISP5a.cnf
+++ b/scripts/resource-cert-samples/ISP5a.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY ISP5a
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5a/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
#sbgp-autonomousSysNum = critical,???
sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv6:2001:db8::a00:0/120
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv6:2001:db8::a00:0/120
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/ISP5a.req b/scripts/resource-cert-samples/ISP5a.req
index 5e4214be..66bc9022 100644
--- a/scripts/resource-cert-samples/ISP5a.req
+++ b/scripts/resource-cert-samples/ISP5a.req
@@ -1,15 +1,21 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYTCCAUkCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0G
+MIIDfzCCAmcCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6Cq
MrAsrB/x5JArwjNv51Ox0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3nd
PIKyj6757MA2OOYCqv2JYCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0
VG+uSDNiwTLxK4MzNmNgnrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQ
x69/n8fdC5aWPEWfwOplakPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDP
qCB94mr5G2apyHHWMvhyPYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGg
-ADANBgkqhkiG9w0BAQUFAAOCAQEAhd6yFtGSfIV5WrxAuBapGyClNWElBM3UI3ID
-JrVjyeKEGb7hMZXwnreqE5aefywR16ZzrQAlpH8cxKJb/0iGPboZ0CEbFKJp81h5
-oJQEK0ArNPw4qyxi99rBovzez/yziOrDbXRJPnnzmUJAMlSyyCEvRwetOCZ906BM
-5bj+cCEwLNVhKEMZVPlOLrXLZX8Jne7QbcA5jMxkA7hEn3p6/BEj45VuiFe+PdAa
-/NDGAepBLly6zNwMXy/LvFueUA+9EH/30tQ1HbhA6f+TzhHPEc4GJkCfhTP/Nwoq
-2Te9fTDyhugM8rHFUfjTgaQVxRFM4XJIrFlyPG+Jk5rk3MIBag==
+ggEcMIIBGAYJKoZIhvcNAQkOMYIBCTCCAQUwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
+HQ4EFgQUCfAUC3n7C/+o71S57D65i9DLnOwwDgYDVR0PAQH/BAQDAgEGMEIGCCsG
+AQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21iYXRzLXItdXMuaGFj
+dHJuLm5ldC9JU1A1YS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3lu
+YzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjMuY2VyMDkGCCsGAQUFBwEH
+AQH/BCowKDAMBAIAATAGAwQACgAAMBgEAgACMBIDEAAgAQ24AAAAAAAAAAAKAAAw
+DQYJKoZIhvcNAQEFBQADggEBABc2bf9ptC+SWMjUqZJ+WSb6DvrU2VKIDK75cbD9
+OVLCBqyjxDcctO1ZT8wXJNwEJaB6P4i83LfSttGpkWr6sBR+H1HVNptuXWo31m6D
+rRSZZ+DEx+01nzmEXJ2+Iskm1+/YQbxygqHQqm+i4ca/Y9PXTl1unH69ONdSfD3c
+qee4VepkOdru3LWkxoF/oPSg9WRjbBXTOfwJ1jGBTqRGYFA5cvzKKciHPhL0EPOZ
+XencgWNNzkumzH60Bu6TVf1TDSne/nDOMdMZaYgwOyaN7nyPXbjr+WhQT9GrZIIi
+YI3RaCitfdN9pPS2CLqHWXxHrJ5MdREdefks1XMfQk8dlWo=
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP5b.cer b/scripts/resource-cert-samples/ISP5b.cer
index 47299c75..7342b3c4 100644
--- a/scripts/resource-cert-samples/ISP5b.cer
+++ b/scripts/resource-cert-samples/ISP5b.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 2 (0x2)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 17 (0x11)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY LIR3
Validity
- Not Before: Aug 1 14:48:20 2007 GMT
- Not After : Jul 31 14:48:20 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY ISP5b
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
6C:B3:65:94:FE:C6:9F:4A:50:9D:4D:8B:40:1A:A1:FD:97:17:97:92
- X509v3 Authority Key Identifier:
- keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -53,42 +50,42 @@ Certificate:
IPv6:
2001:db8:0:0:0:0:a03::/120
- Signature Algorithm: sha1WithRSAEncryption
- 44:d8:15:ad:71:7e:e9:6e:ec:33:2b:42:ed:8c:8a:4a:df:82:
- a4:91:99:57:b0:2f:cc:a3:59:2a:ff:24:c5:ac:e1:79:fa:d7:
- 92:ba:72:2b:47:1a:cf:80:6d:08:76:e9:b5:91:60:35:1f:dd:
- 0c:e0:bd:33:7c:27:d0:f7:11:4e:1f:48:4a:05:bc:6d:e3:5f:
- ba:dd:7a:ba:3d:45:7d:97:72:94:9b:cd:31:76:b8:96:df:f0:
- 7d:16:f3:2a:a3:e2:72:eb:02:1f:49:ee:b6:44:48:5b:69:99:
- b8:bb:80:3b:cb:f5:bc:aa:f8:ba:68:19:53:ec:ff:ad:75:ae:
- 82:51:00:ec:e7:81:c2:6b:cf:a2:a2:a2:c5:b8:04:47:91:ad:
- 9d:33:72:48:a2:15:55:ad:43:52:8f:f6:09:a3:d3:fd:88:d3:
- e3:c3:f4:cd:71:e8:cb:aa:e7:36:07:27:d9:e9:a4:a1:e8:33:
- cd:2d:9c:37:ee:48:e4:8f:8e:f0:84:67:64:89:ea:9a:23:e0:
- 12:01:25:80:41:70:fa:b8:3a:c7:0d:b7:c9:ac:79:37:2a:b1:
- d7:62:79:ea:db:74:b4:f5:86:86:b6:1e:d5:d0:b0:29:96:a3:
- 58:a9:f7:3f:df:8d:31:c1:90:d1:df:1b:c3:f4:14:f8:1d:d1:
- c9:57:95:7f
+ Signature Algorithm: sha256WithRSAEncryption
+ 76:a6:64:04:5d:a3:16:7a:fe:0a:e7:44:c0:de:82:1c:c8:06:
+ a3:08:2b:4a:fb:44:99:79:dc:52:c8:8c:af:6f:17:24:9a:08:
+ 29:37:e2:ae:e7:39:cf:7e:ef:53:d1:82:87:1d:f8:a3:5c:ee:
+ db:a8:dc:6f:7b:78:9f:29:6b:c7:1c:98:28:e0:e3:e5:35:bb:
+ 87:46:fd:14:c1:d2:b7:92:6f:9d:d0:74:8a:54:30:97:ef:b5:
+ d3:4f:18:10:fc:ec:21:3f:76:08:7d:e9:ac:c5:5d:a7:b7:e8:
+ 4d:24:00:fa:e6:2b:82:b9:65:5f:b6:a3:7f:8c:bf:5d:9e:1b:
+ 9c:61:66:a3:37:db:59:d1:c4:eb:c3:06:3a:1b:2a:a1:a8:21:
+ 05:77:ab:bc:36:ef:08:7e:40:87:e3:c7:4c:eb:0c:5a:2a:03:
+ f8:26:b6:30:a8:04:a4:af:ad:63:e3:5c:19:7f:a9:50:30:e8:
+ f7:cc:fb:ef:ee:ba:90:e0:1b:24:dd:aa:dc:d9:90:11:5e:cb:
+ 3f:3a:d8:fd:c0:80:6b:1e:c2:eb:bb:70:57:b4:54:78:a2:12:
+ eb:6f:cd:5f:65:c3:3d:cf:62:0c:18:02:f1:8f:6e:04:30:25:
+ 82:15:6e:25:0f:3c:09:5e:e6:49:cd:73:e5:68:a9:82:3c:93:
+ 22:47:07:4f
-----BEGIN CERTIFICATE-----
-MIID3jCCAsagAwIBAgIBAjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
-IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgyMFoXDTA4MDczMTE0NDgyMFowHDEa
+MIIDvTCCAqWgAwIBAgIBETANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowHDEa
MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
-RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjggEqMIIBJjAPBgNVHRMB
-Af8EBTADAQH/MB0GA1UdDgQWBBRss2WU/safSlCdTYtAGqH9lxeXkjAfBgNVHSME
-GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
-BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
-cm4ubmV0L0lTUDViLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
-Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwOQYIKwYBBQUHAQcB
-Af8EKjAoMAwEAgABMAYDBAAKAwAwGAQCAAIwEgMQACABDbgAAAAAAAAAAAoDADAN
-BgkqhkiG9w0BAQUFAAOCAQEARNgVrXF+6W7sMytC7YyKSt+CpJGZV7AvzKNZKv8k
-xazhefrXkrpyK0caz4BtCHbptZFgNR/dDOC9M3wn0PcRTh9ISgW8beNfut16uj1F
-fZdylJvNMXa4lt/wfRbzKqPicusCH0nutkRIW2mZuLuAO8v1vKr4umgZU+z/rXWu
-glEA7OeBwmvPoqKixbgER5GtnTNySKIVVa1DUo/2CaPT/YjT48P0zXHoy6rnNgcn
-2emkoegzzS2cN+5I5I+O8IRnZInqmiPgEgElgEFw+rg6xw23yax5Nyqx12J56tt0
-tPWGhrYe1dCwKZajWKn3P9+NMcGQ0d8bw/QU+B3RyVeVfw==
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBRss2WU/safSlCdTYtAGqH9lxeXkjAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDViLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAwAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoDADANBgkqhkiG9w0BAQsFAAOCAQEAdqZkBF2jFnr+CudEwN6C
+HMgGowgrSvtEmXncUsiMr28XJJoIKTfiruc5z37vU9GChx34o1zu26jcb3t4nylr
+xxyYKODj5TW7h0b9FMHSt5JvndB0ilQwl++1008YEPzsIT92CH3prMVdp7foTSQA
++uYrgrllX7ajf4y/XZ4bnGFmozfbWdHE68MGOhsqoaghBXervDbvCH5Ah+PHTOsM
+WioD+Ca2MKgEpK+tY+NcGX+pUDDo98z77+66kOAbJN2q3NmQEV7LPzrY/cCAax7C
+67twV7RUeKIS62/NX2XDPc9iDBgC8Y9uBDAlghVuJQ88CV7mSc1z5WipgjyTIkcH
+Tw==
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP5b.cnf b/scripts/resource-cert-samples/ISP5b.cnf
index aaaf9777..c7127044 100644
--- a/scripts/resource-cert-samples/ISP5b.cnf
+++ b/scripts/resource-cert-samples/ISP5b.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY ISP5b
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5b/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
#sbgp-autonomousSysNum = critical,???
sbgp-ipAddrBlock = critical,IPv4:10.3.0.0/24,IPv6:2001:db8::a03:0/120
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv4:10.3.0.0/24,IPv6:2001:db8::a03:0/120
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/ISP5b.req b/scripts/resource-cert-samples/ISP5b.req
index 22759ecb..7ec17a74 100644
--- a/scripts/resource-cert-samples/ISP5b.req
+++ b/scripts/resource-cert-samples/ISP5b.req
@@ -1,15 +1,21 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYTCCAUkCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0G
+MIIDfzCCAmcCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyv
iMhim76cco+KpTSKOyONm4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CH
zZmelFeN7AW436r8jjjTD2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FM
An8U4h5KipZontYWpe+ttYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1
wzUHShhH0pLGHBZ0dLHpOTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxE
tONegMR9eKG0BfcgfSYeRL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGg
-ADANBgkqhkiG9w0BAQUFAAOCAQEAjh7C2XbXMGesB0yJGNQUwnS2ByB8SCA76s4f
-yNvJ7Q/sbd7q67/Bujx7F29MlIISPV/BPeLhktWfP7hOgYc+Y45dF4GikQpW1bFs
-o9M26Vk921rSctcvb3bvGT0Ri34zOYKjNki44n9EAG2CsRTfpyI+D14TzGlufEGy
-Ejdig28wuE+wr0QNtLG2i9t0KfSxbSofCvM1r2JplmHFf5xjHmXaA9agXrdx5I52
-FBLuLeE3RJL4hY+5aCk5sPKKEQUd2OTToNRyZbg3lfXaqlaqy81bC4T02tBsKjms
-09gk6kQoHB9vZ+9kqK/tkpb2ihVasnnm2KMwc147C4JHiOrfxA==
+ggEcMIIBGAYJKoZIhvcNAQkOMYIBCTCCAQUwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
+HQ4EFgQUbLNllP7Gn0pQnU2LQBqh/ZcXl5IwDgYDVR0PAQH/BAQDAgEGMEIGCCsG
+AQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21iYXRzLXItdXMuaGFj
+dHJuLm5ldC9JU1A1Yi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3lu
+YzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjMuY2VyMDkGCCsGAQUFBwEH
+AQH/BCowKDAMBAIAATAGAwQACgMAMBgEAgACMBIDEAAgAQ24AAAAAAAAAAAKAwAw
+DQYJKoZIhvcNAQEFBQADggEBAA/icNEGnX4wn19sxuN9GlvQnMVPiUeX3rMyFJxp
+VODe9wcHWIzz02tXVxaPbsbi5DVQih10HCgw/TC/zYoNjtjL3ygsWUZqCaCGhYUd
+hAKJhhZPwCB5ZX3F17JsWxDqDTjc6+DuUXhMS4jbAGWYeOSeTXfHGiP9IErJOL53
+e58y2QVVtlkjweUYy5bvu0xBS4pA/5PBcYIWxvmc+0tYMmaSpNWv80cMvaWnZ/Dd
+dzcEJJDiX7QcK8fFu4rzFiS7Kkr6zfzehgdrKBCLpWGoO0dYzYoq5tgShXxFAjR1
+l2Z6vyqq/NSYmTMYVFiyY7zY13gnFX9NyMQEnjsvtuLP4Ls=
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP5c.cer b/scripts/resource-cert-samples/ISP5c.cer
index 5f7a0a59..16656abb 100644
--- a/scripts/resource-cert-samples/ISP5c.cer
+++ b/scripts/resource-cert-samples/ISP5c.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 1 (0x1)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 16 (0x10)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY LIR3
Validity
- Not Before: Aug 1 14:48:18 2007 GMT
- Not After : Jul 31 14:48:18 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY ISP5c
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
2D:87:C1:9A:F8:58:2B:BD:C2:F8:7E:30:47:B3:A9:88:37:C9:EB:46
- X509v3 Authority Key Identifier:
- keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -51,42 +48,41 @@ Certificate:
Autonomous System Numbers:
64534-64540
- Signature Algorithm: sha1WithRSAEncryption
- 50:6b:1b:84:77:e5:93:08:5e:dc:42:24:86:70:11:24:f8:11:
- 91:68:0f:08:9b:49:f6:4a:27:85:13:93:ed:59:49:d0:f8:a6:
- d2:44:ab:25:69:41:59:40:8b:78:ab:d2:8d:09:a8:c0:fe:20:
- 49:d7:47:c4:de:19:a1:79:d2:8d:bd:29:08:37:a8:9a:b6:5e:
- 56:25:50:da:1c:47:e8:bf:ed:1e:49:79:48:81:07:97:d3:2f:
- 14:e7:bc:8e:e9:ef:82:9a:bd:18:60:08:08:57:22:6e:45:bb:
- 1a:9f:69:e0:0f:86:42:49:ec:d2:5f:6f:fb:01:b0:b9:56:66:
- aa:62:64:e1:80:68:ee:11:d9:45:b8:3a:fc:81:4b:d4:c0:f7:
- 1c:a7:97:9a:7d:f7:94:2c:05:86:35:2e:0c:83:17:45:b6:3f:
- d6:4e:5f:ba:2d:77:41:4a:25:37:b9:8b:4a:4e:b4:36:f5:c9:
- f7:84:e0:6b:af:1c:d5:e0:88:a5:aa:6f:87:10:18:c3:af:46:
- ee:63:97:e3:66:98:bb:51:67:89:d6:4d:8f:b2:ed:f6:33:ae:
- 5b:44:44:1e:56:af:ac:6d:7b:1f:13:f9:96:84:ee:08:db:4b:
- 1f:56:48:ac:97:0e:ee:b5:33:f4:2d:03:62:a3:32:6d:85:85:
- 52:a6:47:ca
+ Signature Algorithm: sha256WithRSAEncryption
+ 67:a7:55:49:7b:68:d4:dd:67:16:e5:09:f3:ac:fb:1b:ea:83:
+ 58:e4:ba:4f:a4:2f:88:af:1e:05:da:46:b5:85:1a:14:87:c1:
+ 34:74:2d:35:4f:3d:2e:63:9a:cc:ac:28:8d:e5:61:a0:a5:73:
+ f5:25:c0:1b:11:27:b6:dc:4c:41:81:f4:d6:0d:f1:8a:af:69:
+ ae:32:23:d0:4a:fe:1d:d2:c6:ef:87:f5:93:01:42:c5:54:4d:
+ ce:73:d5:19:c7:c9:e6:1d:4c:2f:92:28:03:b2:cd:c5:a6:f6:
+ 6b:b1:bf:7c:1d:71:38:ac:85:93:c8:c2:a4:73:06:4b:f4:ff:
+ 5e:44:e0:57:9a:7e:f5:5f:4c:7d:6f:b6:6a:30:27:5e:ff:7d:
+ 8d:49:04:34:05:1a:87:2e:36:c3:aa:13:b1:91:f0:57:ad:a7:
+ 9e:d3:be:fa:de:af:db:42:f6:bd:06:04:2e:71:e0:5e:82:4a:
+ 4f:dd:57:0f:29:ca:09:db:a8:e4:fd:82:5d:ff:55:24:a4:9a:
+ 64:26:d0:02:1f:f2:4d:92:28:9b:1d:bb:f6:6f:2a:d3:25:48:
+ 87:04:96:37:9f:90:7c:15:6d:c7:18:ef:a7:6b:0e:b1:37:6c:
+ ae:69:7e:49:81:8c:de:b9:f7:34:ee:6d:48:26:92:7f:8f:0c:
+ 95:7d:08:eb
-----BEGIN CERTIFICATE-----
-MIIDxjCCAq6gAwIBAgIBATANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
-IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgxOFoXDTA4MDczMTE0NDgxOFowHDEa
+MIIDozCCAougAwIBAgIBEDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowHDEa
MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
-eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjggESMIIBDjAPBgNVHRMB
-Af8EBTADAQH/MB0GA1UdDgQWBBQth8Ga+FgrvcL4fjBHs6mIN8nrRjAfBgNVHSME
-GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
-BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
-cm4ubmV0L0lTUDVjLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
-Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwIQYIKwYBBQUHAQgB
-Af8EEjAQoA4wDDAKAgMA/BYCAwD8HDANBgkqhkiG9w0BAQUFAAOCAQEAUGsbhHfl
-kwhe3EIkhnARJPgRkWgPCJtJ9konhROT7VlJ0Pim0kSrJWlBWUCLeKvSjQmowP4g
-SddHxN4ZoXnSjb0pCDeomrZeViVQ2hxH6L/tHkl5SIEHl9MvFOe8junvgpq9GGAI
-CFcibkW7Gp9p4A+GQkns0l9v+wGwuVZmqmJk4YBo7hHZRbg6/IFL1MD3HKeXmn33
-lCwFhjUuDIMXRbY/1k5fui13QUolN7mLSk60NvXJ94Tga68c1eCIpapvhxAYw69G
-7mOX42aYu1FnidZNj7Lt9jOuW0REHlavrG17HxP5loTuCNtLH1ZIrJcO7rUz9C0D
-YqMybYWFUqZHyg==
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjgfAwge0wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQULYfBmvhYK73C+H4wR7OpiDfJ60YwDgYDVR0PAQH/
+BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjMuY2Vy
+MCEGCCsGAQUFBwEIAQH/BBIwEKAOMAwwCgIDAPwWAgMA/BwwDQYJKoZIhvcNAQEL
+BQADggEBAGenVUl7aNTdZxblCfOs+xvqg1jkuk+kL4ivHgXaRrWFGhSHwTR0LTVP
+PS5jmsysKI3lYaClc/UlwBsRJ7bcTEGB9NYN8Yqvaa4yI9BK/h3Sxu+H9ZMBQsVU
+Tc5z1RnHyeYdTC+SKAOyzcWm9muxv3wdcTishZPIwqRzBkv0/15E4FeafvVfTH1v
+tmowJ17/fY1JBDQFGocuNsOqE7GR8Fetp57Tvvrer9tC9r0GBC5x4F6CSk/dVw8p
+ygnbqOT9gl3/VSSkmmQm0AIf8k2SKJsdu/ZvKtMlSIcEljefkHwVbccY76drDrE3
+bK5pfkmBjN659zTubUgmkn+PDJV9COs=
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP5c.cnf b/scripts/resource-cert-samples/ISP5c.cnf
index c1f892c2..cc689a77 100644
--- a/scripts/resource-cert-samples/ISP5c.cnf
+++ b/scripts/resource-cert-samples/ISP5c.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY ISP5c
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5c/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
sbgp-autonomousSysNum = critical,AS:64534-64540
#sbgp-ipAddrBlock = critical,???
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+sbgp-autonomousSysNum = critical,AS:64534-64540
+#sbgp-ipAddrBlock = critical,???
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/ISP5c.req b/scripts/resource-cert-samples/ISP5c.req
index 9545f976..fe5a3802 100644
--- a/scripts/resource-cert-samples/ISP5c.req
+++ b/scripts/resource-cert-samples/ISP5c.req
@@ -1,15 +1,21 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYTCCAUkCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0G
+MIIDZDCCAkwCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOng
KdOJIOlRSWcsQ9qgLNREs5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zq
m1yYeks+xOJZQtMZyg9YDrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2Q
QQ8POyrADNl7fehQE/YJc4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4A
AbsFXi4Dmq2VO8rCxodkdDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8N
UBM90T6Mvdx0qTOoVh0xeHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGg
-ADANBgkqhkiG9w0BAQUFAAOCAQEAj9bYIVfREySBzUhQSlbNi9kfdXgivC/4A7pn
-b4sMm081S05u0QLhyh1XNF/L3/U5yVElVHE8xobM/CuAkXpy7N5GSYj2T28Fmn77
-1y/xdGg6Jp26OkbrqY3gjQAaMigYg9/6tPAc9fgLiQAJLUUYb2hRqaqu4Ze8RrxU
-RsnVpAHWYDFWJhNqEp8eErzAVLqxpmoYJKgmpK6TKyYKuf8+xf3Rlkb4+iu2FotR
-DQrmcd6jmMjp9xLejDEuoPgcfpVP2CB1jUCAIW7yE7+a7vj9Mop1gs61zP8y/p2V
-rVnXgEy93WZLjQt1D29oKhlcFGtCG4nqIBCDAWVuz/LGACB85w==
+ggEBMIH+BgkqhkiG9w0BCQ4xgfAwge0wDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4E
+FgQULYfBmvhYK73C+H4wR7OpiDfJ60YwDgYDVR0PAQH/BAQDAgEGMEIGCCsGAQUF
+BwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9JU1A1Yy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjMuY2VyMCEGCCsGAQUFBwEIAQH/
+BBIwEKAOMAwwCgIDAPwWAgMA/BwwDQYJKoZIhvcNAQEFBQADggEBAEmtz8vZK79t
+8D6z0UadBwNhrxSQzoXBJQkjq0rRxAePomXejmnzLdFaCtMkgqVQ/bow4VGlqlzM
+tLUb7sqlKFw61vC1K80WwMjag4l3mQv7XJ0BQujhwzVvtfHhnRLuCCnN9yh30yDs
+2WE6cRoQl44zHNakXlGTW00sX8kA3o73r9Key40sa0UmOcDLKUvvxP0VCOjYOyl+
+I6V/GNAI+7dBDyAdkEXynOYuAkkcRMPAmgx+Nt+I8lxbyXPRtcD84ZwMbQ95RBBY
+QgjxJLABunz5i8L/XFp/6vXBGdLKsLv40IwxoaWCrbxsz5zqD+yemg8r3sXBQCs/
+OuVcypkSpdk=
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/LIR1.cer b/scripts/resource-cert-samples/LIR1.cer
index 64f73b83..77486c96 100644
--- a/scripts/resource-cert-samples/LIR1.cer
+++ b/scripts/resource-cert-samples/LIR1.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 16 (0x10)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 38 (0x26)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY RIR
Validity
- Not Before: Aug 1 14:48:18 2007 GMT
- Not After : Jul 31 14:48:18 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY LIR1
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
- X509v3 Authority Key Identifier:
- keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -56,43 +53,42 @@ Certificate:
192.0.2.1-192.0.2.33
192.0.2.44-192.0.2.100
- Signature Algorithm: sha1WithRSAEncryption
- 72:7d:dd:a4:60:23:71:e4:99:28:0b:9a:ba:5c:d3:97:4b:72:
- eb:89:81:3c:11:85:8c:25:ed:79:b2:50:a5:e8:ae:0e:37:74:
- f9:2c:a1:be:96:83:35:40:0d:36:f9:32:16:74:25:9c:f7:0f:
- cd:46:47:8e:b9:cd:ac:0c:7e:d3:ac:84:5e:f6:31:f4:a9:f2:
- 05:cd:82:d7:e0:d7:3b:24:9b:c7:15:d1:db:9d:c2:1d:92:f7:
- 19:a9:b8:a1:67:0a:fb:3d:23:3a:05:83:29:05:50:e3:00:27:
- a9:80:fe:bb:51:f1:3e:3b:0c:98:ae:f1:ee:d1:13:72:46:64:
- 8f:4b:32:4e:cf:64:cf:1a:a5:b1:34:a6:f0:5f:18:f8:44:bb:
- 13:ea:8d:5f:24:7d:3b:15:60:8e:be:f4:bd:d8:04:a7:d0:10:
- 7e:d3:10:67:bf:35:49:c9:56:cf:b7:8b:7b:9b:17:0b:54:ee:
- 21:cb:75:b0:3e:8d:b2:c1:c6:7c:26:b1:7c:58:a9:4a:31:24:
- cd:e5:3f:a5:9a:1d:7d:11:14:41:2a:e5:55:b6:db:f4:75:34:
- 37:9f:5e:1d:f1:86:2a:f6:74:be:88:e1:b9:63:ce:ad:5c:e9:
- 3c:91:8a:4c:8d:b4:69:03:e7:f9:52:79:28:7d:cd:7f:52:02:
- 49:ae:d5:c7
+ Signature Algorithm: sha256WithRSAEncryption
+ 5d:4b:e6:c3:ad:38:f8:49:32:34:7c:6a:06:ed:d0:7a:cf:9a:
+ c8:a9:22:e5:46:93:37:f1:ec:4d:cd:26:43:f6:e8:ea:7a:5c:
+ 08:2a:7d:e3:37:e4:98:45:16:d2:a8:0b:eb:df:d4:a0:91:04:
+ 35:40:a8:c7:a5:c9:db:86:03:e3:e0:c4:17:6a:27:49:e6:4b:
+ 63:68:84:0c:57:5a:ac:43:79:4e:05:41:05:e5:fc:89:f7:f4:
+ 03:95:7c:b2:9e:d8:aa:a4:b5:35:26:58:96:e0:f6:70:08:f2:
+ de:5c:f5:0a:c9:6a:21:3a:e6:c7:19:af:e3:d9:b1:50:e2:bf:
+ db:28:df:3c:ae:e3:29:8f:22:b6:7a:a9:f6:f4:f3:7f:48:92:
+ da:f4:f5:19:4d:50:63:e0:87:f6:9e:fc:8f:5e:3a:d0:81:3b:
+ 8d:8a:7a:8a:0c:e9:24:a3:83:16:ca:24:4e:ef:80:7a:61:1e:
+ 96:ee:5f:8d:07:68:e5:c2:13:44:30:60:02:71:9b:ef:5b:df:
+ cc:a6:62:60:95:38:41:ff:93:e9:9f:c7:b8:60:34:93:db:55:
+ 2b:e7:27:91:d9:06:56:8e:a4:38:28:ae:dc:02:b4:fd:33:d0:
+ 17:4a:29:0f:86:19:ed:48:dc:5a:b4:e4:7a:8d:de:bc:10:c1:
+ 14:d5:b2:59
-----BEGIN CERTIFICATE-----
-MIID9jCCAt6gAwIBAgIBEDANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
-IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+MIID1TCCAr2gAwIBAgIBJjANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTEwWhcNMDgwODA5MDExNTEwWjAbMRkw
FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
-uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBRDCCAUAwDwYDVR0TAQH/
-BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwHwYDVR0jBBgw
-FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
-BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
-Lm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
-d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
-MAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYEAgABMCAwDgMFAMAAAgED
-BQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEAcn3dpGAj
-ceSZKAuaulzTl0ty64mBPBGFjCXtebJQpeiuDjd0+SyhvpaDNUANNvkyFnQlnPcP
-zUZHjrnNrAx+06yEXvYx9KnyBc2C1+DXOySbxxXR253CHZL3Gam4oWcK+z0jOgWD
-KQVQ4wAnqYD+u1HxPjsMmK7x7tETckZkj0syTs9kzxqlsTSm8F8Y+ES7E+qNXyR9
-OxVgjr70vdgEp9AQftMQZ781SclWz7eLe5sXC1TuIct1sD6NssHGfCaxfFipSjEk
-zeU/pZodfREUQSrlVbbb9HU0N59eHfGGKvZ0vojhuWPOrVzpPJGKTI20aQPn+VJ5
-KH3Nf1ICSa7Vxw==
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBIzCCAR8wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYE
+AgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0B
+AQsFAAOCAQEAXUvmw604+EkyNHxqBu3Qes+ayKki5UaTN/HsTc0mQ/bo6npcCCp9
+4zfkmEUW0qgL69/UoJEENUCox6XJ24YD4+DEF2onSeZLY2iEDFdarEN5TgVBBeX8
+iff0A5V8sp7YqqS1NSZYluD2cAjy3lz1CslqITrmxxmv49mxUOK/2yjfPK7jKY8i
+tnqp9vTzf0iS2vT1GU1QY+CH9p78j1460IE7jYp6igzpJKODFsokTu+AemEelu5f
+jQdo5cITRDBgAnGb71vfzKZiYJU4Qf+T6Z/HuGA0k9tVK+cnkdkGVo6kOCiu3AK0
+/TPQF0opD4YZ7UjcWrTkeo3evBDBFNWyWQ==
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1.cnf b/scripts/resource-cert-samples/LIR1.cnf
index 437963ee..7e2fa61f 100644
--- a/scripts/resource-cert-samples/LIR1.cnf
+++ b/scripts/resource-cert-samples/LIR1.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY LIR1
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR1/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
sbgp-autonomousSysNum = critical,AS:64533
sbgp-ipAddrBlock = critical,IPv4:192.0.2.1-192.0.2.33,IPv4:192.0.2.44-192.0.2.100
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR1/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+sbgp-autonomousSysNum = critical,AS:64533
+sbgp-ipAddrBlock = critical,IPv4:192.0.2.1-192.0.2.33,IPv4:192.0.2.44-192.0.2.100
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/LIR1.req b/scripts/resource-cert-samples/LIR1.req
index 78f52184..d1390df5 100644
--- a/scripts/resource-cert-samples/LIR1.req
+++ b/scripts/resource-cert-samples/LIR1.req
@@ -1,15 +1,22 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMTCCASIwDQYJ
+MIIDmDCCAoACAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMTCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9dHPnZu9UB4Vs2zFH2/YZXYKqex+xO
Ba/7UVx6wljEqFeuFGLpvLZyfc9JyEpAgkr0PjC1lCWebHiBV0PWhQKN0Zy11zQv
4ql9GCe1R5pCFsiQf5Ys3biYFx93YkoIAC3gcww5N7oPp1lZTHzN4lzXmDYQbIg+
RZmmiC/2fzFJukIrE3nCsvEJ2a03pEG2bUahGAWgUweO4Jiy0f1naHdk1fP+HSI2
niZaGqoYlMMsfpqvviydXnUsSdY3KwYfzGOXfu4sX2evTWI+eh8M4R4C8tIGda4/
-EbyODxNkOBQ2HV0C7K9l1blo9CJmK+9HW6078q+2cQyUVop8ATbwOj8CAwEAAaAA
-MA0GCSqGSIb3DQEBBQUAA4IBAQBGjdamDbzptBCgaTgIBVCNV74KP1rBFIexYlue
-XG00WLdNuJxsy6a0PODSD7NuZexVlKLRLTPw4V1P7St0Vi1Cvf324MsDqfTc4wEv
-pbV/eLL6b3EPJbI8eLyH4NoadhovZNzzdYk8DAsMqvr+1h2Jc6oECy6ItH1TVFMR
-G06ovdkU5scfCFQkoAOppyhwAhhr96F9vjVvFAs3v/3YnyLk+Sjw2xS0KFmdCveV
-3AmguPTmfzdwdjvolnTPi3veaWIjNJDRv/vWKAGm2ZTPUYuUAKFUekok2XsiZRkg
-HmXYfBWnueSU09CQNJO7GIzFLO4/FfrsHaZdY4ObjuYKa6AV
+EbyODxNkOBQ2HV0C7K9l1blo9CJmK+9HW6078q+2cQyUVop8ATbwOj8CAwEAAaCC
+ATYwggEyBgkqhkiG9w0BCQ4xggEjMIIBHzAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
+DgQWBBSKlBf5U/JblFRW33ZREyn2cRmoszAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYB
+BQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0xJUjEvMEMGCCsGAQUFBwEBBDcwNTAzBggrBgEFBQcwAoYncnN5bmM6
+Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9SSVIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8FTA5BggrBgEFBQcBBwEB/wQqMCgwJgQCAAEwIDAOAwUAwAAC
+AQMFAcAAAiAwDgMFAsAAAiwDBQDAAAJkMA0GCSqGSIb3DQEBBQUAA4IBAQA/lEvf
+enGH4JCh23gVr/cnd19rfe4RgglfFtk0uUKFws2s9C8yIJjF13RhLURe9WD/kqh6
+aj/pZ3zvgKqe1gHK5WquZWTikK2l2O+E0HAgGIB2HY9WbGlfVdGcoQ72Fnu1u2KJ
+/SuZSiBCJIdbKhUi82T1JdDajSqrLuoFjWZhe6A0YUrcfcSeaGS7po+rLx7k58a6
+cxyXd69qKOGbDcx5RfEujCgQcWVMnbmOdhrbjbN9RoLSyLsLkYGPtLhLgKorFN2I
+e9tTJOMvoKwawKffimHAaZjv7+d7WYc4XjPl2IcDwyo41Mo0l+rjN/lwkOu6Y3qm
+XiKfe7oTJ5XJAmin
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/LIR1/0B.pem b/scripts/resource-cert-samples/LIR1/0B.pem
new file mode 100644
index 00000000..f078c91f
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/0B.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 11 (0xb)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 00:58:18 2007 GMT
+ Not After : Aug 9 00:58:18 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 48:2e:66:23:11:dd:1c:f1:3a:9a:28:62:9a:5c:73:75:4a:7a:
+ 2d:25:24:60:36:62:e5:92:ad:ff:69:08:49:d6:35:7f:e1:53:
+ c4:6c:17:30:d0:6d:f1:35:4c:9a:54:67:e2:78:d8:a3:88:c9:
+ ef:29:be:ad:5b:f1:2e:66:4e:b6:df:a5:f2:2b:c6:45:48:a5:
+ b6:54:2d:bb:35:96:75:0a:c1:7b:79:fc:00:ad:9b:a1:d3:dd:
+ f6:b3:72:1b:68:3a:24:92:96:46:1f:46:1e:a8:ea:50:27:f6:
+ d4:3c:ba:ce:11:d2:79:88:a9:fc:43:55:ed:1f:38:92:6c:e3:
+ 23:26:51:26:c4:5f:f5:11:a3:0f:bf:dd:ff:45:0c:54:08:0a:
+ 48:cd:7f:91:70:b2:e7:83:83:55:33:10:ba:36:27:5d:c5:e0:
+ d4:44:94:f7:19:25:8f:c0:e3:c4:99:5c:fd:f8:03:58:57:75:
+ 6d:de:e2:71:55:1f:1c:20:51:17:ae:98:8f:93:30:6c:59:49:
+ c9:a4:f1:cc:81:83:ae:49:10:d3:13:e8:44:61:c3:16:a2:f1:
+ c4:02:9e:0f:44:3b:9d:a5:3e:81:b1:01:37:e9:33:28:87:f0:
+ 4a:7b:c9:5a:25:ba:76:b0:09:97:b5:11:8c:60:96:1d:17:22:
+ 8e:72:80:4c
+-----BEGIN CERTIFICATE-----
+MIIDODCCAiCgAwIBAgIBCzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAwNTgxOFoXDTA4MDgwOTAwNTgxOFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOBhjCBgzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBRzshYazdzXMGAP+oGV+KL1TpXzrTAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDIvMA0GCSqGSIb3DQEBCwUAA4IBAQBILmYj
+Ed0c8TqaKGKaXHN1SnotJSRgNmLlkq3/aQhJ1jV/4VPEbBcw0G3xNUyaVGfieNij
+iMnvKb6tW/EuZk6236XyK8ZFSKW2VC27NZZ1CsF7efwArZuh0932s3IbaDokkpZG
+H0YeqOpQJ/bUPLrOEdJ5iKn8Q1XtHziSbOMjJlEmxF/1EaMPv93/RQxUCApIzX+R
+cLLng4NVMxC6NiddxeDURJT3GSWPwOPEmVz9+ANYV3Vt3uJxVR8cIFEXrpiPkzBs
+WUnJpPHMgYOuSRDTE+hEYcMWovHEAp4PRDudpT6BsQE36TMoh/BKe8laJbp2sAmX
+tRGMYJYdFyKOcoBM
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/0C.pem b/scripts/resource-cert-samples/LIR1/0C.pem
new file mode 100644
index 00000000..f10e0062
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/0C.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 12 (0xc)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 00:58:18 2007 GMT
+ Not After : Aug 9 00:58:18 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 91:b8:bc:18:27:a1:ec:e7:7b:49:59:f6:83:d7:e9:7a:86:73:
+ 54:84:23:20:5d:00:cc:a4:08:68:9e:ef:33:ad:75:1b:ed:34:
+ bb:36:82:b6:e9:ae:00:5d:a6:9e:11:98:cb:72:f7:a0:77:bd:
+ d0:8e:32:28:b6:cf:e9:3a:8c:bf:4c:94:2b:db:ca:1b:ee:07:
+ 37:c9:51:15:9b:f0:43:b7:31:a2:67:cc:7f:f9:2e:6a:33:ae:
+ 23:6b:de:04:03:03:99:bc:8a:e9:6c:e9:dd:8c:62:3c:b2:df:
+ c0:5c:19:c7:50:c5:5a:86:68:2a:52:fd:7d:85:8c:5f:a8:a2:
+ 5c:7d:58:70:1f:05:c3:cb:4b:f6:91:a3:9d:00:64:0e:1c:f2:
+ ed:1b:45:f4:e0:82:a1:0b:22:e0:77:c0:7a:e9:9d:ce:e3:62:
+ e7:f6:12:0d:4d:bb:be:fc:7a:3d:fd:54:14:4f:0b:5c:44:f5:
+ 7e:6a:74:20:cd:15:9d:3c:86:21:9c:54:ef:d5:ed:8d:b4:36:
+ 34:45:c1:3f:8b:49:27:4d:f5:2d:03:ab:b4:c6:b4:aa:74:da:
+ 37:23:b7:88:70:8e:e9:37:88:54:98:91:b3:42:50:8f:61:ce:
+ 8c:5f:99:4e:f7:61:0a:aa:b9:15:95:87:92:1f:ef:00:02:2b:
+ ea:5f:09:60
+-----BEGIN CERTIFICATE-----
+MIIDODCCAiCgAwIBAgIBDDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAwNTgxOFoXDTA4MDgwOTAwNTgxOFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOBhjCBgzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBRm7CkhLnaDGTntju23BqhM5Q4uETAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDEvMA0GCSqGSIb3DQEBCwUAA4IBAQCRuLwY
+J6Hs53tJWfaD1+l6hnNUhCMgXQDMpAhonu8zrXUb7TS7NoK26a4AXaaeEZjLcveg
+d73QjjIots/pOoy/TJQr28ob7gc3yVEVm/BDtzGiZ8x/+S5qM64ja94EAwOZvIrp
+bOndjGI8st/AXBnHUMVahmgqUv19hYxfqKJcfVhwHwXDy0v2kaOdAGQOHPLtG0X0
+4IKhCyLgd8B66Z3O42Ln9hINTbu+/Ho9/VQUTwtcRPV+anQgzRWdPIYhnFTv1e2N
+tDY0RcE/i0knTfUtA6u0xrSqdNo3I7eIcI7pN4hUmJGzQlCPYc6MX5lO92EKqrkV
+lYeSH+8AAivqXwlg
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/0D.pem b/scripts/resource-cert-samples/LIR1/0D.pem
new file mode 100644
index 00000000..cc8d1185
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/0D.pem
@@ -0,0 +1,88 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 13 (0xd)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 94:90:a1:91:c0:51:6b:ee:1c:74:7a:1f:7e:6e:4e:cc:50:c0:
+ 97:c7:15:df:63:ab:71:65:77:44:2f:f5:4f:91:1c:67:84:42:
+ 78:0a:ef:8c:cd:66:16:92:90:32:76:ca:d9:f0:6a:b4:e3:38:
+ 21:59:a5:13:a7:f7:bc:51:ac:6f:f6:f0:95:85:f3:bb:c7:4c:
+ cf:68:fd:07:9c:f5:cf:79:47:47:71:76:54:4f:8c:37:f1:d5:
+ 1f:85:a9:2c:27:80:57:40:6a:80:71:10:c6:ff:12:74:cb:1a:
+ 8a:a4:92:6a:66:2b:5c:3a:99:8c:d1:2f:ac:e1:66:17:19:20:
+ a9:27:2c:a4:e2:54:dc:d3:a9:71:30:0c:2b:48:a1:af:a4:52:
+ e8:a3:03:b2:03:00:b8:f2:51:b6:6c:c4:b4:c7:d5:cc:a4:d3:
+ f4:2d:70:de:99:76:21:6e:08:29:0f:90:f3:c9:bf:2c:7d:f2:
+ 9c:4f:6f:30:ed:75:a6:64:28:7a:e6:46:ed:ac:d4:b6:71:5d:
+ 91:da:20:2b:eb:eb:d7:32:82:30:5a:68:9a:2d:e8:ef:90:3b:
+ c9:85:fd:5a:0e:3c:55:f0:2b:59:ae:00:e3:d8:cc:e9:90:59:
+ 93:80:9c:26:87:90:15:6e:9e:00:17:b1:c7:95:e7:9e:0d:4a:
+ 92:68:8c:a0
+-----BEGIN CERTIFICATE-----
+MIIDqTCCApGgAwIBAgIBDTANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMDIzMVoXDTA4MDgwOTAxMDIzMVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOB9zCB9DAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBRzshYazdzXMGAP+oGV+KL1TpXzrTAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDIvMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEF
+BQcwAoYocnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLmNlcjAp
+BggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUCwAACLAMFAMAAAmQwDQYJKoZI
+hvcNAQELBQADggEBAJSQoZHAUWvuHHR6H35uTsxQwJfHFd9jq3Fld0Qv9U+RHGeE
+QngK74zNZhaSkDJ2ytnwarTjOCFZpROn97xRrG/28JWF87vHTM9o/Qec9c95R0dx
+dlRPjDfx1R+FqSwngFdAaoBxEMb/EnTLGoqkkmpmK1w6mYzRL6zhZhcZIKknLKTi
+VNzTqXEwDCtIoa+kUuijA7IDALjyUbZsxLTH1cyk0/QtcN6ZdiFuCCkPkPPJvyx9
+8pxPbzDtdaZkKHrmRu2s1LZxXZHaICvr69cygjBaaJot6O+QO8mF/VoOPFXwK1mu
+AOPYzOmQWZOAnCaHkBVungAXsceV554NSpJojKA=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/0E.pem b/scripts/resource-cert-samples/LIR1/0E.pem
new file mode 100644
index 00000000..08cab1ec
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/0E.pem
@@ -0,0 +1,93 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 14 (0xe)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 99:05:da:53:ce:ce:f7:7b:64:64:ad:31:94:37:41:ee:e1:05:
+ 25:5f:20:df:04:ae:b1:8b:56:98:b9:6e:f6:f8:e1:a1:03:e4:
+ 2b:28:58:4b:9f:fe:4b:bc:67:c0:3f:76:94:a7:2d:52:7e:81:
+ 5a:f4:9e:d8:36:59:ad:98:1e:0e:79:63:26:08:cf:c6:a9:37:
+ 39:3b:75:53:22:6f:e8:ad:3d:6e:3a:00:50:62:b3:4e:87:c3:
+ f3:38:58:15:b9:34:d5:0e:37:1e:2a:f9:16:42:ee:40:6b:6b:
+ 30:2b:1f:c1:ca:23:9d:66:66:ac:09:d2:e1:f3:63:41:12:d4:
+ 9c:d7:7c:5a:61:37:f1:70:a5:5a:50:bc:12:b0:cd:4a:7d:57:
+ cb:82:f3:bc:72:58:81:ab:ce:07:3b:e1:8e:4a:d7:03:f2:79:
+ 7a:2d:83:b5:27:4e:53:2a:99:1e:3c:01:cc:eb:ee:7e:47:34:
+ da:59:27:73:54:20:d2:cd:2d:a2:8d:c5:93:7e:4f:0a:8a:ee:
+ b2:3a:d0:5a:cb:c9:19:5b:55:d5:41:22:90:6e:a2:2f:df:81:
+ ad:ec:f4:ab:e7:31:68:e9:32:b3:9c:e3:87:b5:1e:22:5e:f8:
+ 8c:0e:da:7f:b0:cd:29:24:4b:c3:a5:cd:28:69:89:b2:1c:05:
+ b9:18:c5:2b
+-----BEGIN CERTIFICATE-----
+MIIDxzCCAq+gAwIBAgIBDjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMDIzMVoXDTA4MDgwOTAxMDIzMVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCARQwggEQMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgw
+FgQCAAEwEDAOAwUAwAACAQMFAcAAAiAwDQYJKoZIhvcNAQELBQADggEBAJkF2lPO
+zvd7ZGStMZQ3Qe7hBSVfIN8ErrGLVpi5bvb44aED5CsoWEuf/ku8Z8A/dpSnLVJ+
+gVr0ntg2Wa2YHg55YyYIz8apNzk7dVMib+itPW46AFBis06Hw/M4WBW5NNUONx4q
++RZC7kBrazArH8HKI51mZqwJ0uHzY0ES1JzXfFphN/FwpVpQvBKwzUp9V8uC87xy
+WIGrzgc74Y5K1wPyeXotg7UnTlMqmR48Aczr7n5HNNpZJ3NUINLNLaKNxZN+TwqK
+7rI60FrLyRlbVdVBIpBuoi/fga3s9KvnMWjpMrOc44e1HiJe+IwO2n+wzSkkS8Ol
+zShpibIcBbkYxSs=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/0F.pem b/scripts/resource-cert-samples/LIR1/0F.pem
new file mode 100644
index 00000000..8fc7b413
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/0F.pem
@@ -0,0 +1,88 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 15 (0xf)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:07:09 2007 GMT
+ Not After : Aug 9 01:07:09 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ a5:94:a6:fa:e0:84:ac:c4:8d:f8:46:1b:4d:69:0b:ca:0d:ba:
+ 20:e9:51:0d:7f:76:0b:ae:9a:76:0e:11:0e:7c:6a:2f:c8:a0:
+ 6e:83:6d:51:3c:93:f7:7d:1b:5f:8f:da:06:c5:2b:28:0f:41:
+ 96:a2:9a:d9:ca:0d:57:16:15:79:e5:58:7a:72:45:b9:63:a5:
+ 27:84:d8:e5:b5:8a:2b:27:90:b0:d8:58:67:30:7d:dc:7e:33:
+ 8d:d8:42:e4:af:04:3a:6a:b8:79:07:a3:30:85:7a:29:3c:7d:
+ 44:15:a8:48:f6:e1:f9:d1:50:f9:70:29:3a:ba:e5:43:37:e0:
+ 93:67:2e:a9:1a:03:ea:95:f2:14:46:bf:96:b2:c5:7e:d8:74:
+ 2f:23:e0:60:56:12:52:90:1f:f5:ce:b9:e4:5c:e7:69:64:62:
+ 56:b8:34:77:7a:c7:25:03:16:ff:fc:93:67:e5:54:4f:5f:23:
+ 19:05:59:9c:c9:01:97:6d:54:81:fd:1d:c8:3c:9f:c0:1e:a9:
+ ca:ba:52:ca:d4:7f:23:e7:1d:e9:b4:cd:56:82:d8:f2:58:83:
+ c8:28:fd:41:4d:fc:81:54:e2:24:be:7d:32:f4:02:10:cb:dc:
+ 6a:07:28:a2:4f:7d:bd:6d:f8:56:4f:74:87:fc:b4:88:20:17:
+ 0c:b9:28:fb
+-----BEGIN CERTIFICATE-----
+MIIDqTCCApGgAwIBAgIBDzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMDcwOVoXDTA4MDgwOTAxMDcwOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOB9zCB9DAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBRzshYazdzXMGAP+oGV+KL1TpXzrTAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDIvMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEF
+BQcwAoYocnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLmNlcjAp
+BggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUCwAACLAMFAMAAAmQwDQYJKoZI
+hvcNAQELBQADggEBAKWUpvrghKzEjfhGG01pC8oNuiDpUQ1/dguumnYOEQ58ai/I
+oG6DbVE8k/d9G1+P2gbFKygPQZaimtnKDVcWFXnlWHpyRbljpSeE2OW1iisnkLDY
+WGcwfdx+M43YQuSvBDpquHkHozCFeik8fUQVqEj24fnRUPlwKTq65UM34JNnLqka
+A+qV8hRGv5ayxX7YdC8j4GBWElKQH/XOueRc52lkYla4NHd6xyUDFv/8k2flVE9f
+IxkFWZzJAZdtVIH9Hcg8n8Aeqcq6UsrUfyPnHem0zVaC2PJYg8go/UFN/IFU4iS+
+fTL0AhDL3GoHKKJPfb1t+FZPdIf8tIggFwy5KPs=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/10.pem b/scripts/resource-cert-samples/LIR1/10.pem
new file mode 100644
index 00000000..6c572f7c
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/10.pem
@@ -0,0 +1,93 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 16 (0x10)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:07:09 2007 GMT
+ Not After : Aug 9 01:07:09 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 8a:0e:25:de:ee:ec:8e:ac:b0:c5:2c:20:60:1d:65:aa:c6:9c:
+ 60:a1:87:25:ae:fd:18:37:40:e5:8d:a2:7e:5f:fb:3d:df:25:
+ ca:4f:32:48:7b:4e:bc:b1:a9:d0:7a:10:67:84:cf:40:87:45:
+ 97:fd:2e:8e:4c:53:fa:0d:71:f9:33:d7:82:7a:76:d3:90:a4:
+ 46:e3:1a:55:a1:ec:3b:4d:29:0f:e1:49:6b:e7:e2:02:c8:79:
+ 73:99:92:85:b6:4e:b0:54:cc:9a:34:24:b3:0e:3d:64:3a:57:
+ 51:e4:a0:40:04:a2:e0:bb:38:fa:e7:52:49:e8:26:45:1e:07:
+ 98:93:a8:7b:2d:d0:08:74:75:1f:51:46:f5:2a:cf:e1:b7:79:
+ 4b:93:a1:c3:f8:0c:b3:67:ef:15:a8:64:10:51:bf:ac:6c:97:
+ ae:12:79:ec:2e:4e:b2:a1:b5:55:db:78:c6:6f:99:c4:42:cf:
+ 1e:49:cd:c2:2b:e6:ed:bb:c1:83:11:7b:c5:a1:ab:04:1a:2c:
+ 75:56:66:dc:cc:43:8e:61:07:88:22:21:6e:9c:a3:73:0d:b8:
+ f5:3f:71:89:05:2e:52:3c:7a:d3:90:af:4b:0b:cc:d6:e3:b1:
+ c6:dd:c4:0d:5c:36:79:05:1e:24:71:19:29:2a:68:13:e9:0a:
+ 10:8e:25:99
+-----BEGIN CERTIFICATE-----
+MIIDxzCCAq+gAwIBAgIBEDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMDcwOVoXDTA4MDgwOTAxMDcwOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCARQwggEQMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgw
+FgQCAAEwEDAOAwUAwAACAQMFAcAAAiAwDQYJKoZIhvcNAQELBQADggEBAIoOJd7u
+7I6ssMUsIGAdZarGnGChhyWu/Rg3QOWNon5f+z3fJcpPMkh7TryxqdB6EGeEz0CH
+RZf9Lo5MU/oNcfkz14J6dtOQpEbjGlWh7DtNKQ/hSWvn4gLIeXOZkoW2TrBUzJo0
+JLMOPWQ6V1HkoEAEouC7OPrnUknoJkUeB5iTqHst0Ah0dR9RRvUqz+G3eUuTocP4
+DLNn7xWoZBBRv6xsl64SeewuTrKhtVXbeMZvmcRCzx5JzcIr5u27wYMRe8WhqwQa
+LHVWZtzMQ45hB4giIW6co3MNuPU/cYkFLlI8etOQr0sLzNbjscbdxA1cNnkFHiRx
+GSkqaBPpChCOJZk=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/11.pem b/scripts/resource-cert-samples/LIR1/11.pem
new file mode 100644
index 00000000..b9659189
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/11.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 17 (0x11)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:13:40 2007 GMT
+ Not After : Aug 9 01:13:40 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 6d:01:ed:47:42:63:b1:28:58:2b:d2:a2:fc:c5:b2:b8:49:3b:
+ dd:1a:cf:5a:28:c2:35:ae:e8:7e:ec:39:e8:7f:ca:d3:eb:a5:
+ c6:7a:ef:46:6f:c8:48:5f:9d:eb:dc:c8:4c:cf:88:68:be:59:
+ a5:be:03:22:18:27:1c:3a:f2:90:3a:db:ae:6a:b0:fe:ce:4e:
+ 71:cb:3c:c9:d7:c1:ff:69:a8:78:6e:45:15:c5:b5:a5:74:92:
+ 87:7d:76:d1:ec:38:91:25:86:71:a0:5b:fb:e2:97:c4:b6:a3:
+ ec:21:22:89:71:d4:36:da:c2:90:a7:09:c9:3f:4a:a7:ed:eb:
+ 64:b5:4e:6f:44:16:60:42:72:49:38:e2:92:f4:62:a9:de:56:
+ a9:70:fb:aa:8e:63:1f:d6:71:a2:b0:6b:c2:76:a2:27:05:69:
+ 53:5b:fd:b8:9e:29:ee:ba:eb:a8:32:8c:28:0c:39:94:64:72:
+ 6f:d3:33:a9:6d:be:9a:62:86:62:60:95:57:1a:c4:fa:c9:cd:
+ dd:19:a2:90:76:24:01:47:32:8b:3a:95:dc:24:d9:79:07:c8:
+ 30:5d:7f:e8:23:ea:3d:5a:bd:d6:99:b3:1c:01:0e:6d:5d:0b:
+ 87:eb:88:4e:8c:78:2b:d0:b6:80:07:c6:10:3c:79:bd:ba:95:
+ 9c:0e:84:3e
+-----BEGIN CERTIFICATE-----
+MIIDFzCCAf+gAwIBAgIBETANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMTM0MFoXDTA4MDgwOTAxMTM0MFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaNmMGQwDwYDVR0TAQH/BAUw
+AwEB/zAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAF
+hiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDIvMA0GCSqGSIb3
+DQEBCwUAA4IBAQBtAe1HQmOxKFgr0qL8xbK4STvdGs9aKMI1ruh+7Dnof8rT66XG
+eu9Gb8hIX53r3MhMz4hovlmlvgMiGCccOvKQOtuuarD+zk5xyzzJ18H/aah4bkUV
+xbWldJKHfXbR7DiRJYZxoFv74pfEtqPsISKJcdQ22sKQpwnJP0qn7etktU5vRBZg
+QnJJOOKS9GKp3lapcPuqjmMf1nGisGvCdqInBWlTW/24ninuuuuoMowoDDmUZHJv
+0zOpbb6aYoZiYJVXGsT6yc3dGaKQdiQBRzKLOpXcJNl5B8gwXX/oI+o9Wr3WmbMc
+AQ5tXQuH64hOjHgr0LaAB8YQPHm9upWcDoQ+
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/12.pem b/scripts/resource-cert-samples/LIR1/12.pem
new file mode 100644
index 00000000..88877bb3
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/12.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 18 (0x12)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:13:40 2007 GMT
+ Not After : Aug 9 01:13:40 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 95:4a:1c:f9:a4:d7:b8:75:16:2e:25:5a:ae:7d:e4:d0:eb:27:
+ 51:b9:40:12:86:f2:98:9d:f2:76:ee:d4:be:0b:74:8f:81:f3:
+ 14:a7:57:10:be:2c:19:b6:80:1c:4f:8e:e0:8d:96:70:8d:50:
+ 0f:55:22:27:d1:1a:a4:e9:cf:77:32:89:54:3f:10:9d:d8:ab:
+ 17:26:67:3e:ea:99:89:d8:57:6c:e5:7b:9b:bd:5a:1c:f4:18:
+ 14:8f:d1:2f:6b:93:34:ad:19:8b:a0:90:dc:69:48:96:65:7c:
+ 7b:f0:6d:25:f9:5d:9d:2d:2f:57:bf:1c:c1:ee:01:e0:f7:e9:
+ 52:bc:45:4b:4e:fc:94:78:92:98:66:56:d3:e0:cb:38:7f:4e:
+ dd:97:b7:03:16:fa:fa:7b:2d:b8:78:f2:9f:f3:61:d3:02:3c:
+ 47:7a:a3:a7:36:27:19:d3:c9:53:a8:e7:09:d0:50:84:a7:fc:
+ 53:b3:37:8e:72:1f:a6:b9:1c:09:35:20:d9:ed:0c:66:ec:ef:
+ 93:39:9b:29:50:5b:ed:1f:0c:3d:30:f6:22:1a:0e:7d:4d:8d:
+ 17:07:96:4f:c3:a9:72:3d:6d:c0:da:af:a7:8b:14:85:0c:fc:
+ de:cd:cc:58:5c:a0:7b:bf:a9:de:0e:3b:92:0a:57:ab:e3:e4:
+ cb:83:1e:30
+-----BEGIN CERTIFICATE-----
+MIIDFzCCAf+gAwIBAgIBEjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMTM0MFoXDTA4MDgwOTAxMTM0MFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaNmMGQwDwYDVR0TAQH/BAUw
+AwEB/zAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAF
+hiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDEvMA0GCSqGSIb3
+DQEBCwUAA4IBAQCVShz5pNe4dRYuJVqufeTQ6ydRuUAShvKYnfJ27tS+C3SPgfMU
+p1cQviwZtoAcT47gjZZwjVAPVSIn0Rqk6c93MolUPxCd2KsXJmc+6pmJ2Fds5Xub
+vVoc9BgUj9Eva5M0rRmLoJDcaUiWZXx78G0l+V2dLS9XvxzB7gHg9+lSvEVLTvyU
+eJKYZlbT4Ms4f07dl7cDFvr6ey24ePKf82HTAjxHeqOnNicZ08lTqOcJ0FCEp/xT
+szeOch+muRwJNSDZ7Qxm7O+TOZspUFvtHww9MPYiGg59TY0XB5ZPw6lyPW3A2q+n
+ixSFDPzezcxYXKB7v6neDjuSCler4+TLgx4w
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/13.pem b/scripts/resource-cert-samples/LIR1/13.pem
new file mode 100644
index 00000000..ca17b5f4
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/13.pem
@@ -0,0 +1,88 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 19 (0x13)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ a0:55:12:46:3d:61:d3:08:29:a5:43:f1:62:19:a9:75:90:17:
+ 51:85:19:8c:98:29:3c:ed:b8:13:5f:14:e4:8f:1a:85:18:4f:
+ 92:b5:5b:5f:2b:97:49:c2:ec:7b:cb:87:b5:28:4e:99:77:6c:
+ f9:8f:2a:14:86:fc:1b:93:90:92:c8:21:0c:c3:ab:02:e8:e3:
+ 6d:c2:cf:55:51:54:08:58:a0:2f:b4:70:56:21:48:ce:1c:ba:
+ c6:1f:08:cb:59:e0:37:9c:75:4d:ca:cb:5d:6d:6b:53:4f:7f:
+ 6e:b0:21:06:52:dd:0a:24:13:b8:95:c1:0b:62:4f:31:27:b5:
+ df:0c:31:ce:51:62:1e:a3:89:40:2b:14:34:58:ac:62:a6:1d:
+ 70:09:b1:e3:ee:bb:cc:ca:61:e2:27:2b:51:81:17:73:5f:a5:
+ 7b:1a:9b:fb:f9:4e:6f:d3:68:ad:43:8a:0e:87:32:6f:3e:9d:
+ 03:4b:61:d0:b2:30:38:ec:23:3a:48:f7:1e:5c:d6:6a:eb:03:
+ 14:4e:69:33:04:07:3e:87:6c:7f:cd:8d:0a:2d:75:32:18:cc:
+ 0e:9b:74:14:87:61:39:18:5c:53:d4:90:39:56:5e:14:ae:70:
+ 33:1c:88:58:a7:42:7e:35:88:c9:ba:a0:af:c1:03:18:fe:4d:
+ 9e:40:54:a5
+-----BEGIN CERTIFICATE-----
+MIIDqTCCApGgAwIBAgIBEzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOB9zCB9DAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBRzshYazdzXMGAP+oGV+KL1TpXzrTAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDIvMEQGCCsGAQUFBwEBBDgwNjA0BggrBgEF
+BQcwAoYocnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLmNlcjAp
+BggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUCwAACLAMFAMAAAmQwDQYJKoZI
+hvcNAQELBQADggEBAKBVEkY9YdMIKaVD8WIZqXWQF1GFGYyYKTztuBNfFOSPGoUY
+T5K1W18rl0nC7HvLh7UoTpl3bPmPKhSG/BuTkJLIIQzDqwLo423Cz1VRVAhYoC+0
+cFYhSM4cusYfCMtZ4DecdU3Ky11ta1NPf26wIQZS3QokE7iVwQtiTzEntd8MMc5R
+Yh6jiUArFDRYrGKmHXAJsePuu8zKYeInK1GBF3NfpXsam/v5Tm/TaK1Dig6HMm8+
+nQNLYdCyMDjsIzpI9x5c1mrrAxROaTMEBz6HbH/NjQotdTIYzA6bdBSHYTkYXFPU
+kDlWXhSucDMciFinQn41iMm6oK/BAxj+TZ5AVKU=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/14.pem b/scripts/resource-cert-samples/LIR1/14.pem
new file mode 100644
index 00000000..9121acc8
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/14.pem
@@ -0,0 +1,93 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 20 (0x14)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 10 01:15:11 2007 GMT
+ Not After : Aug 9 01:15:11 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 66:6a:10:37:c5:13:94:1c:b1:ca:85:50:7a:20:6e:d7:a1:e5:
+ b5:70:cb:bc:f9:99:b6:58:64:fa:2a:fb:f2:15:77:b8:ea:94:
+ 28:68:c6:e7:22:69:07:57:55:4f:02:5e:5a:60:cd:fd:d7:d0:
+ b9:c3:df:23:f8:af:22:25:48:e5:a9:48:ab:38:d9:91:33:fc:
+ 88:f7:0e:94:df:a0:4e:da:06:8d:91:ed:ba:41:e5:42:ac:58:
+ af:84:da:d1:69:ca:f5:c3:42:52:2e:9c:5d:e5:72:7f:66:4b:
+ 54:8b:55:87:3c:f8:e7:16:42:ea:a8:92:2a:4c:c3:ff:f9:8d:
+ 1c:74:5f:7e:48:fe:24:18:4e:59:6e:44:a2:2c:19:3f:48:fb:
+ 50:c9:33:0f:92:9e:f7:d0:da:4b:f3:e7:a6:51:a1:da:ba:a5:
+ 8c:b6:55:46:0c:33:2c:3c:92:f5:90:ca:d9:f4:88:eb:c5:9f:
+ 31:23:3f:1f:48:66:a0:5c:b1:c0:45:45:ff:ad:0e:e8:e5:2f:
+ 22:0d:e0:f5:3a:9f:ee:e9:c5:0e:48:2b:70:c1:44:5b:69:fe:
+ 10:83:10:7e:b4:e6:e2:90:cf:dd:fd:22:6c:8a:54:69:88:99:
+ bd:bc:2e:11:c7:47:62:78:45:34:73:1e:73:43:38:fc:15:07:
+ 24:ea:82:5c
+-----BEGIN CERTIFICATE-----
+MIIDxzCCAq+gAwIBAgIBFDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgxMDAxMTUxMVoXDTA4MDgwOTAxMTUxMVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCARQwggEQMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgw
+FgQCAAEwEDAOAwUAwAACAQMFAcAAAiAwDQYJKoZIhvcNAQELBQADggEBAGZqEDfF
+E5QcscqFUHogbteh5bVwy7z5mbZYZPoq+/IVd7jqlChoxuciaQdXVU8CXlpgzf3X
+0LnD3yP4ryIlSOWpSKs42ZEz/Ij3DpTfoE7aBo2R7bpB5UKsWK+E2tFpyvXDQlIu
+nF3lcn9mS1SLVYc8+OcWQuqokipMw//5jRx0X35I/iQYTlluRKIsGT9I+1DJMw+S
+nvfQ2kvz56ZRodq6pYy2VUYMMyw8kvWQytn0iOvFnzEjPx9IZqBcscBFRf+tDujl
+LyIN4PU6n+7pxQ5IK3DBRFtp/hCDEH605uKQz939ImyKVGmImb28LhHHR2J4RTRz
+HnNDOPwVByTqglw=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/index b/scripts/resource-cert-samples/LIR1/index
index 81a48b97..3ddf74db 100644
--- a/scripts/resource-cert-samples/LIR1/index
+++ b/scripts/resource-cert-samples/LIR1/index
@@ -8,3 +8,13 @@ V 080731140935Z 07 unknown /CN=TEST ENTITY ISP2
V 080731140935Z 08 unknown /CN=TEST ENTITY ISP1
V 080731144822Z 09 unknown /CN=TEST ENTITY ISP2
V 080731144822Z 0A unknown /CN=TEST ENTITY ISP1
+V 080809005818Z 0B unknown /CN=TEST ENTITY ISP2
+V 080809005818Z 0C unknown /CN=TEST ENTITY ISP1
+V 080809010231Z 0D unknown /CN=TEST ENTITY ISP2
+V 080809010231Z 0E unknown /CN=TEST ENTITY ISP1
+V 080809010709Z 0F unknown /CN=TEST ENTITY ISP2
+V 080809010709Z 10 unknown /CN=TEST ENTITY ISP1
+V 080809011340Z 11 unknown /CN=TEST ENTITY ISP2
+V 080809011340Z 12 unknown /CN=TEST ENTITY ISP1
+V 080809011510Z 13 unknown /CN=TEST ENTITY ISP2
+V 080809011511Z 14 unknown /CN=TEST ENTITY ISP1
diff --git a/scripts/resource-cert-samples/LIR1/index.old b/scripts/resource-cert-samples/LIR1/index.old
index 55a90252..5c7caab4 100644
--- a/scripts/resource-cert-samples/LIR1/index.old
+++ b/scripts/resource-cert-samples/LIR1/index.old
@@ -7,3 +7,13 @@ V 080731140829Z 06 unknown /CN=TEST ENTITY ISP1
V 080731140935Z 07 unknown /CN=TEST ENTITY ISP2
V 080731140935Z 08 unknown /CN=TEST ENTITY ISP1
V 080731144822Z 09 unknown /CN=TEST ENTITY ISP2
+V 080731144822Z 0A unknown /CN=TEST ENTITY ISP1
+V 080809005818Z 0B unknown /CN=TEST ENTITY ISP2
+V 080809005818Z 0C unknown /CN=TEST ENTITY ISP1
+V 080809010231Z 0D unknown /CN=TEST ENTITY ISP2
+V 080809010231Z 0E unknown /CN=TEST ENTITY ISP1
+V 080809010709Z 0F unknown /CN=TEST ENTITY ISP2
+V 080809010709Z 10 unknown /CN=TEST ENTITY ISP1
+V 080809011340Z 11 unknown /CN=TEST ENTITY ISP2
+V 080809011340Z 12 unknown /CN=TEST ENTITY ISP1
+V 080809011510Z 13 unknown /CN=TEST ENTITY ISP2
diff --git a/scripts/resource-cert-samples/LIR1/serial b/scripts/resource-cert-samples/LIR1/serial
index eb589e9d..60d3b2f4 100644
--- a/scripts/resource-cert-samples/LIR1/serial
+++ b/scripts/resource-cert-samples/LIR1/serial
@@ -1 +1 @@
-0B
+15
diff --git a/scripts/resource-cert-samples/LIR1/serial.old b/scripts/resource-cert-samples/LIR1/serial.old
index d9bb888f..8351c193 100644
--- a/scripts/resource-cert-samples/LIR1/serial.old
+++ b/scripts/resource-cert-samples/LIR1/serial.old
@@ -1 +1 @@
-0A
+14
diff --git a/scripts/resource-cert-samples/LIR2.cer b/scripts/resource-cert-samples/LIR2.cer
index 1094cb06..06ca26ad 100644
--- a/scripts/resource-cert-samples/LIR2.cer
+++ b/scripts/resource-cert-samples/LIR2.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 15 (0xf)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 37 (0x25)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY RIR
Validity
- Not Before: Aug 1 14:48:18 2007 GMT
- Not After : Jul 31 14:48:18 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY LIR2
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
- X509v3 Authority Key Identifier:
- keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -56,43 +53,43 @@ Certificate:
2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
2001:db8:0:0:0:10:0:44/128
- Signature Algorithm: sha1WithRSAEncryption
- 1b:9a:85:77:61:fe:eb:5a:f8:ef:ad:5d:4d:79:4b:09:b3:c9:
- 3e:46:f2:cf:4f:0c:26:28:7c:ec:72:da:17:6e:a0:2a:f2:4b:
- 0f:af:e6:2e:b5:d7:2d:03:ae:8c:13:65:ec:cb:c2:4a:02:8f:
- 81:60:44:60:eb:d2:d2:22:12:63:04:8c:6d:56:5a:c2:b8:f6:
- c8:f5:17:99:69:25:bd:3e:1d:2a:ef:ce:51:48:4a:67:d0:b4:
- ee:64:99:35:42:10:26:88:ac:e0:26:c8:27:cc:89:30:40:18:
- 72:9c:82:03:ea:62:9d:83:c9:ab:c8:32:0a:59:98:50:0c:50:
- 23:5a:93:ff:43:ba:08:b3:7d:61:d5:ed:a4:42:f2:cf:ab:2e:
- 62:6b:67:bd:06:74:2c:bc:b7:b1:7e:1b:f4:c9:e4:40:94:ec:
- 14:55:04:54:ce:44:26:d0:93:e3:ff:e2:e2:a2:a4:3f:44:87:
- 7a:c2:29:a3:48:5f:12:1d:e4:eb:18:b3:1f:30:f4:e6:d3:a7:
- 5a:7c:73:da:0a:8f:1e:29:63:cb:b6:16:2e:fe:76:84:93:88:
- a1:72:83:4d:3d:8d:16:ef:16:df:c7:c6:d7:67:00:68:ec:4d:
- b8:ed:b8:ff:3e:bf:c9:d5:3a:34:cf:4c:c0:7b:6e:11:60:46:
- 25:91:d8:ad
+ Signature Algorithm: sha256WithRSAEncryption
+ 13:0b:5a:02:21:8a:26:5a:fd:8a:66:9c:ff:7c:61:aa:43:72:
+ d0:ac:b7:9f:91:85:a9:3d:97:2b:4c:cb:5b:c1:69:0d:d2:32:
+ 28:2b:5e:e6:fe:2b:71:1f:62:72:b0:ea:fd:5b:86:b0:86:09:
+ e8:a1:53:86:5a:7c:58:3d:b1:74:6d:9a:40:08:b6:33:46:7d:
+ 03:43:13:03:d3:c3:13:8c:71:92:5d:c0:76:bb:e0:08:95:4b:
+ ca:ac:0a:c5:3d:d2:50:f5:96:8a:db:c2:ea:d0:f7:a2:00:fa:
+ 10:19:44:1e:5b:93:30:ff:0f:e9:af:81:a2:6d:c4:46:d7:af:
+ e9:a7:42:7c:ba:db:9f:b9:46:3d:f5:b2:19:81:2c:a7:c6:56:
+ d1:37:3e:50:f1:93:0a:8a:0a:81:42:c6:f1:7f:e0:63:fa:a1:
+ 7b:74:c6:ea:be:d7:37:5c:df:c1:8f:46:81:d8:a2:ce:d9:ee:
+ d9:03:71:8c:cb:1c:69:2a:29:8e:09:58:de:09:7b:93:ab:7b:
+ b6:56:a0:22:1c:31:e9:4d:13:19:ae:ab:f5:fa:19:5a:ad:54:
+ 46:d1:6b:b3:48:7c:ac:41:75:9b:87:10:bd:ab:fa:df:37:a8:
+ 29:37:65:8b:f4:90:81:85:0f:e8:e4:6e:df:84:ab:4f:99:ae:
+ 67:b9:8c:db
-----BEGIN CERTIFICATE-----
-MIIEETCCAvmgAwIBAgIBDzANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
-IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+MIID8DCCAtigAwIBAgIBJTANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTEwWhcNMDgwODA5MDExNTEwWjAbMRkw
FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
-f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBXzCCAVswDwYDVR0TAQH/
-BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwHwYDVR0jBBgw
-FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
-BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
-Lm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
-d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
-MAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEEAgACMDswJgMRAiABDbgA
-AAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEAIAENuAAAAAAAAAAQAAAA
-RDANBgkqhkiG9w0BAQUFAAOCAQEAG5qFd2H+61r4761dTXlLCbPJPkbyz08MJih8
-7HLaF26gKvJLD6/mLrXXLQOujBNl7MvCSgKPgWBEYOvS0iISYwSMbVZawrj2yPUX
-mWklvT4dKu/OUUhKZ9C07mSZNUIQJois4CbIJ8yJMEAYcpyCA+pinYPJq8gyClmY
-UAxQI1qT/0O6CLN9YdXtpELyz6suYmtnvQZ0LLy3sX4b9MnkQJTsFFUEVM5EJtCT
-4//i4qKkP0SHesIpo0hfEh3k6xizHzD05tOnWnxz2gqPHiljy7YWLv52hJOIoXKD
-TT2NFu8W38fG12cAaOxNuO24/z6/ydU6NM9MwHtuEWBGJZHYrQ==
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBPjCCATowDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEE
+AgACMDswJgMRAiABDbgAAAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEA
+IAENuAAAAAAAAAAQAAAARDANBgkqhkiG9w0BAQsFAAOCAQEAEwtaAiGKJlr9imac
+/3xhqkNy0Ky3n5GFqT2XK0zLW8FpDdIyKCte5v4rcR9icrDq/VuGsIYJ6KFThlp8
+WD2xdG2aQAi2M0Z9A0MTA9PDE4xxkl3AdrvgCJVLyqwKxT3SUPWWitvC6tD3ogD6
+EBlEHluTMP8P6a+Bom3ERtev6adCfLrbn7lGPfWyGYEsp8ZW0Tc+UPGTCooKgULG
+8X/gY/qhe3TG6r7XN1zfwY9Ggdiiztnu2QNxjMscaSopjglY3gl7k6t7tlagIhwx
+6U0TGa6r9foZWq1URtFrs0h8rEF1m4cQvav63zeoKTdli/SQgYUP6ORu34SrT5mu
+Z7mM2w==
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2.cnf b/scripts/resource-cert-samples/LIR2.cnf
index a320a876..7e691e6d 100644
--- a/scripts/resource-cert-samples/LIR2.cnf
+++ b/scripts/resource-cert-samples/LIR2.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY LIR2
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR2/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
sbgp-autonomousSysNum = critical,AS:64544
sbgp-ipAddrBlock = critical,IPv6:2001:db8::44-2001:db8::100,IPv6:2001:db8::10:0:44/128
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR2/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+sbgp-autonomousSysNum = critical,AS:64544
+sbgp-ipAddrBlock = critical,IPv6:2001:db8::44-2001:db8::100,IPv6:2001:db8::10:0:44/128
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/LIR2.req b/scripts/resource-cert-samples/LIR2.req
index 1cd9a376..96d673be 100644
--- a/scripts/resource-cert-samples/LIR2.req
+++ b/scripts/resource-cert-samples/LIR2.req
@@ -1,15 +1,22 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMjCCASIwDQYJ
+MIIDszCCApsCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAPEYtnkLNcWDZEiDMQOe53IoZbGsYeF3
LsBN8LEcYdjMWi3HC5t4ej79N636sHMLnPy7b2DqOO+u0Se4gVkPs+fQZ7Ki9U/i
BMbME58zKDWWetvOrJ3TZD24RLzLQyKS1jwuv5duOWpuaJNdHKhYt6N6JkT+/jCt
4gWJTMnvLOBOMWk/3ZEc8LAlTD6EiupeA7OozZAaHsjgr/4R7SEGvTxeCKGT4kFD
QzjTIbNM+oWLQ1dgXbugeOUzR6gzdr7fbmNh4zGLXY4Mx/XIkQy+V8fyvL4Lunof
-9hnx6wB0wRLC3CsujfAK/3/oYAiQulH80JARN/OeRLZkQ2ldYdPhjXcCAwEAAaAA
-MA0GCSqGSIb3DQEBBQUAA4IBAQB2ULf+zorJ8tHI+ru/khJ+B3tOGYc/LNQdU39O
-bRsoXSEVGcUZ8YoD4rW3IJS6lskSKkZKkdCIui1SMGq9R2OdYaUICq+hMagX1ZQb
-z6WrSivm+Khc7BqB147ZQ8gO+96+2BzEIkEBeozuHoNvEfJZ6g5N/etd9AaFaeZU
-fO5bGkFOd9UKWPZGQ9Gk3sxFQM83Aek0D6LfQ81ezijqX2l83oqw3gHHxDPrEWIw
-wA8Ir2kBvR6GGt/8uqgtzF+oIQuOIe3peWT5JP2EahY7IW5AViXkOpVfFzzsI/pp
-xGGJGibt55hQTWF/kkRgAYYPnHr0HsNK8ZRvgOKOsmZOewYE
+9hnx6wB0wRLC3CsujfAK/3/oYAiQulH80JARN/OeRLZkQ2ldYdPhjXcCAwEAAaCC
+AVEwggFNBgkqhkiG9w0BCQ4xggE+MIIBOjAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
+DgQWBBQDet8M39yTPfelzCd73CL26VWX8DAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYB
+BQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0xJUjIvMEMGCCsGAQUFBwEBBDcwNTAzBggrBgEFBQcwAoYncnN5bmM6
+Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9SSVIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8IDBUBggrBgEFBQcBBwEB/wRFMEMwQQQCAAIwOzAmAxECIAEN
+uAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEQAgAQ24AAAAAAAAABAA
+AABEMA0GCSqGSIb3DQEBBQUAA4IBAQCFx6Mb43W5xnHDV/cqywQ3qJjVQUsl6Gcg
+1h426JuSWoB526DFqFxBAmZR5DK+L8jU7jxBJn7tG6P22GrITSbU4BDVdFCD9znO
+juds7+q/qvfTDSNrNwyzldW/UaL3VJ0YF2xXutLJC4jbkH4QfEcmGriGFTRiwvJS
+LJvotN7i2TNKtj3ARaIaKhonzPZg7Qn/bck2KJutG00gm9u3m9wGZ37+tDQE1yMd
+sqX/uhtZB/YM7q3OGeaj8hkjCMkInZL/1FCzxp4qo3F25KLiWNVz+0xxW4A/1kA8
+a1Rdzb9+y318vQce1eAgMo/64tABUYEILwkAXJ6sPBV2V7PdksW4
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/LIR2/0B.pem b/scripts/resource-cert-samples/LIR2/0B.pem
new file mode 100644
index 00000000..d4720f0d
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/0B.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 11 (0xb)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 87:7d:49:12:b5:b5:ca:35:8f:2c:ae:da:fc:4a:35:b2:09:2b:
+ ed:7e:64:3d:a2:3c:ce:a5:e6:f4:77:ca:6f:a0:fb:ff:d0:46:
+ db:d8:fc:2b:09:35:a3:f6:ca:c1:00:ae:e6:02:93:96:ff:f8:
+ 2c:f5:40:18:d1:43:aa:ba:80:a7:71:7c:aa:99:ba:bb:59:74:
+ fb:b9:64:40:4c:d6:ec:4a:f4:a1:7e:32:ae:94:8d:15:f0:ba:
+ bb:0c:20:0c:58:3c:eb:52:5a:02:32:56:1b:97:95:38:8e:a4:
+ a7:4d:33:92:d5:5e:8c:e4:ab:81:c9:48:dd:39:28:c3:0b:5d:
+ ea:13:8e:69:b0:e3:b6:e3:fb:d3:fe:a6:24:4c:48:fe:55:63:
+ dd:27:36:68:a5:51:86:8b:b5:8a:95:4c:ef:89:47:0e:d9:af:
+ 98:b6:e5:3d:52:5b:a7:b8:5d:d2:d0:bc:b8:7e:cf:65:d3:51:
+ 78:58:49:27:6c:3b:12:36:21:20:36:dd:e8:ea:d0:9d:55:9d:
+ e0:06:49:d2:27:58:a4:4a:64:65:72:8e:f9:43:80:53:94:04:
+ c0:de:0b:e1:42:81:da:c6:a0:1c:c6:d6:8b:d2:1b:ee:39:3b:
+ e5:c4:9e:99:da:2a:37:88:d7:e5:51:f8:55:d9:c3:4a:a3:69:
+ ff:3c:20:0c
+-----BEGIN CERTIFICATE-----
+MIIDODCCAiCgAwIBAgIBCzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAwNTgxN1oXDTA4MDgwOTAwNTgxN1owGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOBhjCBgzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBSYz/gAguzX6RdPvXqHYDKlu521DjAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDQvMA0GCSqGSIb3DQEBCwUAA4IBAQCHfUkS
+tbXKNY8srtr8SjWyCSvtfmQ9ojzOpeb0d8pvoPv/0Ebb2PwrCTWj9srBAK7mApOW
+//gs9UAY0UOquoCncXyqmbq7WXT7uWRATNbsSvShfjKulI0V8Lq7DCAMWDzrUloC
+MlYbl5U4jqSnTTOS1V6M5KuByUjdOSjDC13qE45psOO24/vT/qYkTEj+VWPdJzZo
+pVGGi7WKlUzviUcO2a+YtuU9UlunuF3S0Ly4fs9l01F4WEknbDsSNiEgNt3o6tCd
+VZ3gBknSJ1ikSmRlco75Q4BTlATA3gvhQoHaxqAcxtaL0hvuOTvlxJ6Z2io3iNfl
+UfhV2cNKo2n/PCAM
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/0C.pem b/scripts/resource-cert-samples/LIR2/0C.pem
new file mode 100644
index 00000000..42755368
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/0C.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 12 (0xc)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 00:58:18 2007 GMT
+ Not After : Aug 9 00:58:18 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 97:a4:c3:69:4c:4d:c3:a6:15:69:99:75:4b:04:37:02:b4:f2:
+ 02:ad:5d:22:4b:c8:73:e3:34:d0:20:34:e3:83:48:ef:e2:75:
+ f8:d7:67:4f:9f:d6:20:a4:0d:b1:ab:ba:64:cd:c6:98:0b:67:
+ c3:a8:a5:7a:48:fe:4c:a0:34:1c:01:ea:91:79:2c:37:05:56:
+ 4e:fe:4b:97:c5:f4:65:7b:a2:31:a5:6d:e2:47:c1:15:55:d7:
+ 90:cb:83:3b:d9:d6:62:3e:09:e1:a4:8b:aa:82:21:de:4b:39:
+ d5:c2:d1:c8:88:fc:73:ad:f7:e2:ca:c6:ec:7e:12:67:4c:f1:
+ e2:78:21:bf:b9:59:21:d1:3a:36:bc:6f:e8:1e:be:7a:74:4b:
+ 6e:60:d2:9d:62:21:ac:26:7d:f4:df:da:37:2e:b2:dd:4c:f1:
+ 64:b6:ef:75:2a:a8:dd:d2:d2:fb:64:c5:fe:e0:f5:68:44:e4:
+ 1c:48:99:a9:fb:5d:4b:34:bd:d3:4b:c0:40:e7:21:7c:dd:43:
+ f1:f7:4d:6b:f2:32:bd:34:14:c5:6c:3c:df:bb:ff:eb:bc:5b:
+ d2:76:d1:2c:e8:c0:8e:0c:03:3c:2d:a3:6e:76:00:9d:8d:b9:
+ 7d:86:8a:84:f9:76:7e:af:f3:ef:3c:8b:a6:0b:59:c0:8c:cf:
+ f8:6f:90:6d
+-----BEGIN CERTIFICATE-----
+MIIDODCCAiCgAwIBAgIBDDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAwNTgxOFoXDTA4MDgwOTAwNTgxOFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOBhjCBgzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBThly4ZcLV//IJPMz1rLN6amzY9fjAOBgNVHQ8BAf8E
+BAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L0lTUDMvMA0GCSqGSIb3DQEBCwUAA4IBAQCXpMNp
+TE3DphVpmXVLBDcCtPICrV0iS8hz4zTQIDTjg0jv4nX412dPn9YgpA2xq7pkzcaY
+C2fDqKV6SP5MoDQcAeqReSw3BVZO/kuXxfRle6IxpW3iR8EVVdeQy4M72dZiPgnh
+pIuqgiHeSznVwtHIiPxzrffiysbsfhJnTPHieCG/uVkh0To2vG/oHr56dEtuYNKd
+YiGsJn3039o3LrLdTPFktu91Kqjd0tL7ZMX+4PVoROQcSJmp+11LNL3TS8BA5yF8
+3UPx901r8jK9NBTFbDzfu//rvFvSdtEs6MCODAM8LaNudgCdjbl9hoqE+XZ+r/Pv
+PIumC1nAjM/4b5Bt
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/0D.pem b/scripts/resource-cert-samples/LIR2/0D.pem
new file mode 100644
index 00000000..a3e8fbab
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/0D.pem
@@ -0,0 +1,93 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 13 (0xd)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 39:43:cf:68:33:e0:80:03:70:71:f7:ae:88:a1:cb:0e:11:a3:
+ 5c:aa:a4:09:a3:4c:cc:b6:73:92:09:2f:50:57:f3:f8:4a:c2:
+ eb:f0:b8:64:19:37:7b:d2:3b:c9:43:50:ed:89:69:73:05:85:
+ bd:3c:dd:5b:47:b7:1b:0f:d2:ab:18:93:3a:bf:0a:20:9a:b3:
+ 2b:4c:b2:e1:08:df:39:53:9b:36:be:6b:54:b4:f3:7f:4d:5d:
+ 6f:b6:68:ee:26:3f:5f:a0:3f:89:8e:d2:10:54:0e:03:da:4f:
+ 22:4f:b8:d3:07:e8:51:6b:df:20:4f:2d:5b:67:fa:66:49:34:
+ 45:77:9f:88:57:aa:53:68:3c:9b:50:b3:71:74:34:79:26:29:
+ b2:2b:b3:8b:e1:24:fe:56:94:af:cc:56:cb:c6:5d:f3:cf:bb:
+ ff:16:32:90:96:72:76:14:10:d6:64:52:44:98:49:1b:9b:10:
+ 17:f8:8d:6d:27:6e:2e:8d:d7:d2:6d:73:31:70:31:fe:8a:be:
+ 74:06:62:33:13:c5:87:7a:89:c1:af:96:77:1f:af:da:e8:0d:
+ 38:8f:00:da:b3:3f:29:31:80:a1:32:a1:60:cc:6c:56:cb:8f:
+ 63:59:1f:a0:e4:50:9c:3e:4e:c3:53:8b:6f:88:b3:3c:97:d3:
+ 66:91:6e:a7
+-----BEGIN CERTIFICATE-----
+MIIDyjCCArKgAwIBAgIBDTANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMDIzMVoXDTA4MDgwOTAxMDIzMVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCARcwggETMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBsw
+GQQCAAIwEwMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQELBQADggEBADlD
+z2gz4IADcHH3roihyw4Ro1yqpAmjTMy2c5IJL1BX8/hKwuvwuGQZN3vSO8lDUO2J
+aXMFhb083VtHtxsP0qsYkzq/CiCasytMsuEI3zlTmza+a1S0839NXW+2aO4mP1+g
+P4mO0hBUDgPaTyJPuNMH6FFr3yBPLVtn+mZJNEV3n4hXqlNoPJtQs3F0NHkmKbIr
+s4vhJP5WlK/MVsvGXfPPu/8WMpCWcnYUENZkUkSYSRubEBf4jW0nbi6N19JtczFw
+Mf6KvnQGYjMTxYd6icGvlncfr9roDTiPANqzPykxgKEyoWDMbFbLj2NZH6DkUJw+
+TsNTi2+IszyX02aRbqc=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/0E.pem b/scripts/resource-cert-samples/LIR2/0E.pem
new file mode 100644
index 00000000..05f06437
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/0E.pem
@@ -0,0 +1,89 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 14 (0xe)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ ab:ee:14:3e:c4:4b:ea:20:a8:9a:0d:48:6e:12:6d:da:9c:c5:
+ e5:c0:23:8e:d8:13:5f:cf:ed:b6:b6:b7:4a:b7:50:81:c1:61:
+ 92:22:af:a3:47:60:21:89:74:6e:8a:5a:c6:16:2d:60:8e:c9:
+ 45:44:62:a6:73:07:3f:d7:db:85:a9:22:a1:f1:7c:b7:a5:e1:
+ 40:42:e5:0b:1a:a4:80:63:24:79:e8:87:82:6c:fa:ce:74:97:
+ c0:e2:81:77:bd:9b:06:ea:c8:3c:4d:84:93:44:38:c5:c9:b7:
+ 94:0a:d1:e9:ee:5f:02:a1:0f:2c:db:af:f4:7a:bb:a7:65:b0:
+ d6:a5:cb:df:21:ce:b5:4e:46:33:76:95:6b:c8:e5:2e:c6:54:
+ 14:e0:25:ee:9b:e9:14:42:a6:2b:53:59:36:6d:43:55:91:4f:
+ 97:08:e0:56:f4:f7:46:83:1d:46:34:6b:26:d7:14:4c:47:23:
+ 7c:31:73:d7:0d:1f:68:c5:19:ae:b4:c4:db:24:89:ae:a7:3c:
+ a3:90:7b:db:0d:fa:cc:1f:3f:f9:78:97:ec:c3:72:10:8b:44:
+ 4d:c7:1d:ae:20:ec:af:19:90:0d:ac:95:16:eb:73:d8:e5:30:
+ 2e:bc:f9:4e:d3:6a:48:13:f4:d7:b4:c5:a1:1a:c3:ef:b9:81:
+ e7:6a:fc:a4
+-----BEGIN CERTIFICATE-----
+MIIDwzCCAqugAwIBAgIBDjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMDIzMVoXDTA4MDgwOTAxMDIzMVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCARAwggEMMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MEEGCCsGAQUFBwEHAQH/BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABE
+AxEAIAENuAAAAAAAAAAAAAABADANBgkqhkiG9w0BAQsFAAOCAQEAq+4UPsRL6iCo
+mg1IbhJt2pzF5cAjjtgTX8/ttra3SrdQgcFhkiKvo0dgIYl0bopaxhYtYI7JRURi
+pnMHP9fbhakiofF8t6XhQELlCxqkgGMkeeiHgmz6znSXwOKBd72bBurIPE2Ek0Q4
+xcm3lArR6e5fAqEPLNuv9Hq7p2Ww1qXL3yHOtU5GM3aVa8jlLsZUFOAl7pvpFEKm
+K1NZNm1DVZFPlwjgVvT3RoMdRjRrJtcUTEcjfDFz1w0faMUZrrTE2ySJrqc8o5B7
+2w36zB8/+XiX7MNyEItETccdriDsrxmQDayVFutz2OUwLrz5TtNqSBP017TFoRrD
+77mB52r8pA==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/0F.pem b/scripts/resource-cert-samples/LIR2/0F.pem
new file mode 100644
index 00000000..0509dec8
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/0F.pem
@@ -0,0 +1,93 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 15 (0xf)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:07:09 2007 GMT
+ Not After : Aug 9 01:07:09 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ d5:b7:00:47:e6:b8:94:45:1f:7b:52:17:86:bc:e3:6c:37:b5:
+ f8:78:15:78:f9:8f:f1:59:b0:a5:ad:1d:d8:59:d4:9b:09:38:
+ 36:95:24:3a:9a:18:bb:52:52:19:30:80:1c:08:8c:7d:0c:de:
+ d5:59:5b:19:99:6c:53:69:d6:bc:b4:8a:f6:df:90:57:29:68:
+ 4e:db:81:8a:6b:ab:c8:2a:2b:cd:ed:7e:14:09:67:83:5b:ae:
+ d8:0d:b0:05:56:e5:4b:91:ed:5e:5b:88:b5:cc:71:c4:93:4a:
+ 57:c5:d5:c2:fb:da:ef:ab:d1:96:84:6b:af:53:80:12:75:7d:
+ 6c:37:9f:8c:45:e7:8e:3b:e1:a1:20:2e:2c:78:24:0e:98:82:
+ b7:73:21:0d:9d:8e:12:3a:cc:04:ea:94:e7:7b:c5:ee:c7:66:
+ 09:ac:b6:7e:d3:07:16:2c:48:3f:f5:38:e4:12:a7:24:50:26:
+ 7d:8c:1d:07:15:9a:1d:c1:bb:7f:95:44:30:7b:3d:06:ee:10:
+ 23:be:b0:91:0c:62:77:0f:3f:f1:51:d1:5a:8a:09:0d:83:d6:
+ 90:7f:41:8e:17:03:f2:c9:04:4e:7f:fb:4d:ab:49:73:de:96:
+ fd:33:3f:23:90:5b:38:38:73:c8:9a:dc:03:2e:d7:3f:7b:c5:
+ 96:96:5c:f2
+-----BEGIN CERTIFICATE-----
+MIIDyjCCArKgAwIBAgIBDzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMDcwOVoXDTA4MDgwOTAxMDcwOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCARcwggETMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBsw
+GQQCAAIwEwMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQELBQADggEBANW3
+AEfmuJRFH3tSF4a842w3tfh4FXj5j/FZsKWtHdhZ1JsJODaVJDqaGLtSUhkwgBwI
+jH0M3tVZWxmZbFNp1ry0ivbfkFcpaE7bgYprq8gqK83tfhQJZ4NbrtgNsAVW5UuR
+7V5biLXMccSTSlfF1cL72u+r0ZaEa69TgBJ1fWw3n4xF54474aEgLix4JA6Ygrdz
+IQ2djhI6zATqlOd7xe7HZgmstn7TBxYsSD/1OOQSpyRQJn2MHQcVmh3Bu3+VRDB7
+PQbuECO+sJEMYncPP/FR0VqKCQ2D1pB/QY4XA/LJBE5/+02rSXPelv0zPyOQWzg4
+c8ia3AMu1z97xZaWXPI=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/10.pem b/scripts/resource-cert-samples/LIR2/10.pem
new file mode 100644
index 00000000..a1ca8f31
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/10.pem
@@ -0,0 +1,89 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 16 (0x10)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:07:09 2007 GMT
+ Not After : Aug 9 01:07:09 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 46:39:56:56:54:34:70:e5:dd:f8:30:56:02:6f:45:81:e2:c3:
+ f4:1c:fa:82:1e:87:11:3f:64:28:14:22:b2:9b:6d:d0:84:ca:
+ 78:81:cb:f6:ed:45:5e:fd:7a:f8:e0:9d:a4:c9:8c:f5:a6:f8:
+ 63:a1:5d:b2:6f:e9:fd:83:1e:1b:82:a9:3a:03:f9:57:3c:81:
+ 0f:ef:6d:a6:5c:14:8f:38:49:38:c1:26:4b:d1:e5:13:94:77:
+ 63:b9:f8:7c:fc:bc:82:01:d0:f7:90:94:14:d9:32:b1:49:e3:
+ b1:e5:0f:da:8c:8e:0f:4a:e3:b1:60:38:b4:88:2f:a0:ed:68:
+ ee:f8:90:23:b1:1f:9a:6c:7a:24:12:a7:0f:57:aa:81:57:b3:
+ 37:66:79:1c:a0:9b:dc:f6:80:30:5d:02:5d:1f:9f:cb:e8:fe:
+ 4e:3d:67:85:2c:40:b4:f9:94:11:57:9c:22:4d:b0:51:83:1d:
+ bb:aa:83:a1:20:f0:ed:68:c5:82:9e:23:db:e4:ab:45:71:f6:
+ c6:fd:69:23:fb:dd:7e:cd:f8:32:49:a8:e7:42:c9:64:4b:c0:
+ e5:c2:c6:88:20:2c:df:89:82:01:f4:4d:e3:a4:fc:71:f5:a8:
+ 49:cb:88:00:48:a0:2c:19:04:ea:e9:74:b1:e4:a2:7a:63:d1:
+ 53:5d:e3:13
+-----BEGIN CERTIFICATE-----
+MIIDwzCCAqugAwIBAgIBEDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMDcwOVoXDTA4MDgwOTAxMDcwOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCARAwggEMMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MEEGCCsGAQUFBwEHAQH/BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABE
+AxEAIAENuAAAAAAAAAAAAAABADANBgkqhkiG9w0BAQsFAAOCAQEARjlWVlQ0cOXd
++DBWAm9FgeLD9Bz6gh6HET9kKBQisptt0ITKeIHL9u1FXv16+OCdpMmM9ab4Y6Fd
+sm/p/YMeG4KpOgP5VzyBD+9tplwUjzhJOMEmS9HlE5R3Y7n4fPy8ggHQ95CUFNky
+sUnjseUP2oyOD0rjsWA4tIgvoO1o7viQI7Efmmx6JBKnD1eqgVezN2Z5HKCb3PaA
+MF0CXR+fy+j+Tj1nhSxAtPmUEVecIk2wUYMdu6qDoSDw7WjFgp4j2+SrRXH2xv1p
+I/vdfs34Mkmo50LJZEvA5cLGiCAs34mCAfRN46T8cfWoScuIAEigLBkE6ul0seSi
+emPRU13jEw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/11.pem b/scripts/resource-cert-samples/LIR2/11.pem
new file mode 100644
index 00000000..44471417
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/11.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 17 (0x11)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ a8:55:fe:aa:11:d7:ec:08:34:d2:a3:70:f6:13:67:b5:7e:68:
+ 6e:b1:e8:3e:f6:e8:49:3f:4d:aa:86:19:01:43:2a:93:de:f3:
+ 43:06:cc:ff:bf:23:81:a4:42:50:92:cf:d9:64:de:a3:92:1c:
+ 3c:08:f3:97:6d:76:3c:b3:5f:cb:70:49:52:ec:bf:5d:c0:fc:
+ 72:4a:79:d9:19:02:96:cc:f5:3c:3d:b8:ea:b1:5a:6e:9d:17:
+ 08:d8:3e:4e:9f:d6:b6:6d:3f:0c:f5:28:ca:84:3d:65:1a:ba:
+ d5:72:52:e5:e6:01:d9:66:df:a7:42:4c:6e:76:f6:50:13:78:
+ 29:13:bd:0c:bc:a8:15:fb:9d:56:5e:cb:c2:36:86:b9:41:74:
+ 2c:79:83:06:fb:83:6b:80:56:9f:a3:b6:01:ab:58:d9:20:ba:
+ 9c:2c:47:b7:06:f0:55:18:89:02:34:e1:ae:f1:53:a2:66:5a:
+ 86:3c:2a:c2:ba:92:33:6e:18:20:2c:ae:f8:4f:bc:2f:2f:e4:
+ cc:f2:80:de:f5:2c:4d:4a:dc:29:3e:af:f9:f0:86:4a:a7:b7:
+ 3e:7a:42:11:69:5a:35:8a:5c:96:00:eb:65:d9:a8:2b:03:db:
+ fb:7e:c8:c9:dd:8c:55:b8:b6:da:58:51:a9:b6:59:60:45:6d:
+ b2:b5:64:7e
+-----BEGIN CERTIFICATE-----
+MIIDFzCCAf+gAwIBAgIBETANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMTMzOVoXDTA4MDgwOTAxMTMzOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaNmMGQwDwYDVR0TAQH/BAUw
+AwEB/zAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAF
+hiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDQvMA0GCSqGSIb3
+DQEBCwUAA4IBAQCoVf6qEdfsCDTSo3D2E2e1fmhuseg+9uhJP02qhhkBQyqT3vND
+Bsz/vyOBpEJQks/ZZN6jkhw8CPOXbXY8s1/LcElS7L9dwPxySnnZGQKWzPU8Pbjq
+sVpunRcI2D5On9a2bT8M9SjKhD1lGrrVclLl5gHZZt+nQkxudvZQE3gpE70MvKgV
++51WXsvCNoa5QXQseYMG+4NrgFafo7YBq1jZILqcLEe3BvBVGIkCNOGu8VOiZlqG
+PCrCupIzbhggLK74T7wvL+TM8oDe9SxNStwpPq/58IZKp7c+ekIRaVo1ilyWAOtl
+2agrA9v7fsjJ3YxVuLbaWFGptllgRW2ytWR+
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/12.pem b/scripts/resource-cert-samples/LIR2/12.pem
new file mode 100644
index 00000000..91e549e7
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/12.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 18 (0x12)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 7c:d9:69:a5:fc:d6:93:9c:2a:ee:7e:1b:f5:86:69:22:8c:66:
+ fb:d1:97:63:65:5c:1d:7c:81:c0:ff:ce:6f:48:bd:37:14:7b:
+ a6:51:c0:8d:82:a8:a0:97:e4:9a:cd:e8:b8:f8:6c:66:78:50:
+ 69:b4:66:82:a0:a4:4d:d8:0e:44:60:92:11:49:ab:70:28:95:
+ 41:a2:6f:8f:b9:8e:45:81:6f:74:4e:14:f9:a5:b6:07:bd:12:
+ 99:f9:7b:57:9a:0c:06:52:a0:93:d4:dd:23:ab:ae:92:0f:6d:
+ 8f:76:7b:30:cd:f6:07:ee:63:ff:82:88:bf:e1:25:73:98:f4:
+ 77:b0:00:16:cc:df:47:8d:c9:54:d0:f3:6b:04:f2:f1:5e:96:
+ e6:22:9b:3b:bf:25:89:2f:60:6e:4d:1a:ae:ed:d8:79:7a:8c:
+ e6:37:ac:ec:23:60:65:d6:63:38:64:77:1e:2f:b9:17:5f:8d:
+ 02:06:43:36:01:3f:20:f5:eb:ea:f6:a3:a4:f3:7f:da:d7:ae:
+ 92:6f:fe:b1:f7:4c:8c:ef:4d:e1:06:98:43:77:de:ea:07:1a:
+ 6a:3e:75:79:c1:5e:62:f3:f2:1d:8c:5e:d3:2f:6b:a5:f0:6e:
+ 8b:da:58:97:ec:16:35:3c:a5:7a:56:8f:80:c5:97:e3:30:df:
+ ab:8d:cd:36
+-----BEGIN CERTIFICATE-----
+MIIDFzCCAf+gAwIBAgIBEjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMTMzOVoXDTA4MDgwOTAxMTMzOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaNmMGQwDwYDVR0TAQH/BAUw
+AwEB/zAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYBBQUHAQsENTAzMDEGCCsGAQUFBzAF
+hiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDMvMA0GCSqGSIb3
+DQEBCwUAA4IBAQB82Wml/NaTnCrufhv1hmkijGb70ZdjZVwdfIHA/85vSL03FHum
+UcCNgqigl+Sazei4+GxmeFBptGaCoKRN2A5EYJIRSatwKJVBom+PuY5FgW90ThT5
+pbYHvRKZ+XtXmgwGUqCT1N0jq66SD22PdnswzfYH7mP/goi/4SVzmPR3sAAWzN9H
+jclU0PNrBPLxXpbmIps7vyWJL2BuTRqu7dh5eozmN6zsI2Bl1mM4ZHceL7kXX40C
+BkM2AT8g9evq9qOk83/a166Sb/6x90yM703hBphDd97qBxpqPnV5wV5i8/IdjF7T
+L2ul8G6L2liX7BY1PKV6Vo+AxZfjMN+rjc02
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/13.pem b/scripts/resource-cert-samples/LIR2/13.pem
new file mode 100644
index 00000000..415517d5
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/13.pem
@@ -0,0 +1,93 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 19 (0x13)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ c4:46:cc:b9:a5:85:42:ff:9b:32:39:a8:0f:f6:51:35:09:fa:
+ b0:a8:1c:14:4f:72:ff:2c:17:fb:ab:6a:c2:c4:48:2a:2a:fe:
+ 42:c5:c2:92:4a:37:01:b7:69:b1:6c:83:52:2d:8e:8c:aa:04:
+ 82:bb:93:64:c2:0a:a9:7f:bd:82:2a:82:e4:df:2c:0e:5c:16:
+ 12:c7:33:39:0b:f7:99:5b:f5:5d:e0:d3:f8:48:3e:ff:25:a0:
+ e2:38:bb:fe:f1:fa:44:da:54:41:b2:1a:2c:1b:41:d2:54:3e:
+ 3b:43:35:a0:71:72:ff:a8:76:03:e2:9f:78:75:45:6c:8f:5e:
+ c2:5b:4f:e7:6b:ab:66:0a:d4:6c:47:10:ab:90:c5:b2:c9:53:
+ a6:2a:a4:c2:ca:b9:b3:f1:3d:9a:75:d0:d4:94:aa:79:6d:ec:
+ 16:1a:85:91:1d:d8:4a:ef:79:88:9e:2c:96:b0:bd:33:6b:e4:
+ 21:f1:ee:68:14:4b:58:cc:11:8f:6f:05:2d:6f:c3:99:9b:e6:
+ 8f:06:6b:a6:f9:45:2f:41:9f:38:9b:c8:80:98:1f:15:02:7d:
+ f1:08:19:a5:5a:30:c1:eb:72:ee:f4:a7:c5:fa:7a:35:af:24:
+ 62:b1:54:4c:d5:4c:42:ef:fe:9e:5f:65:80:4f:42:7e:e3:7f:
+ 35:18:5c:6b
+-----BEGIN CERTIFICATE-----
+MIIDyjCCArKgAwIBAgIBEzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCARcwggETMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MBoGCCsGAQUFBwEIAQH/BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBsw
+GQQCAAIwEwMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQELBQADggEBAMRG
+zLmlhUL/mzI5qA/2UTUJ+rCoHBRPcv8sF/urasLESCoq/kLFwpJKNwG3abFsg1It
+joyqBIK7k2TCCql/vYIqguTfLA5cFhLHMzkL95lb9V3g0/hIPv8loOI4u/7x+kTa
+VEGyGiwbQdJUPjtDNaBxcv+odgPin3h1RWyPXsJbT+drq2YK1GxHEKuQxbLJU6Yq
+pMLKubPxPZp10NSUqnlt7BYahZEd2ErveYieLJawvTNr5CHx7mgUS1jMEY9vBS1v
+w5mb5o8Ga6b5RS9BnzibyICYHxUCffEIGaVaMMHrcu70p8X6ejWvJGKxVEzVTELv
+/p5fZYBPQn7jfzUYXGs=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/14.pem b/scripts/resource-cert-samples/LIR2/14.pem
new file mode 100644
index 00000000..c31add0d
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/14.pem
@@ -0,0 +1,89 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 20 (0x14)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 58:b8:cd:b3:34:ce:a2:4f:39:c1:15:09:b4:95:f8:5e:7b:23:
+ 9b:fb:42:6f:92:5a:29:ce:17:c1:99:d6:c7:39:00:43:e1:60:
+ bb:17:f5:34:df:33:86:73:77:f4:8f:6f:d5:88:1d:68:be:f8:
+ 13:fd:02:38:fa:aa:9c:39:80:1b:dc:50:72:23:d6:0a:64:55:
+ 14:78:fe:64:1a:63:53:bb:e6:78:35:88:2c:d1:7a:1b:3c:23:
+ 72:8a:a5:c0:5b:5c:7c:85:b1:26:a1:c0:ce:a9:c0:16:5d:30:
+ eb:2d:7e:69:48:57:6b:dc:34:88:56:47:99:ed:31:47:c1:3e:
+ ff:b6:9e:69:cc:68:2e:1c:4c:77:27:d4:a5:45:f9:cb:a5:21:
+ 23:46:18:20:2a:a0:7c:b9:eb:d1:d8:91:30:2e:b4:16:07:b6:
+ 9f:3a:28:71:1d:ee:f9:a7:88:59:45:78:b7:36:0e:15:f6:77:
+ e4:69:b4:b1:61:9a:5c:66:0f:c5:7c:67:d7:af:d3:24:24:4e:
+ e7:94:ce:a6:d6:3b:5a:c8:d7:49:58:93:d7:f5:41:2f:b3:9a:
+ 93:c8:6c:ec:2f:be:6a:c1:74:2a:44:bb:5c:7b:d8:16:f6:01:
+ ed:5b:e8:6b:02:48:ef:5b:57:f4:07:fd:5f:47:e6:06:38:3c:
+ a2:4b:d0:f9
+-----BEGIN CERTIFICATE-----
+MIIDwzCCAqugAwIBAgIBFDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCARAwggEMMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MA4GA1UdDwEB
+/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29t
+YmF0cy1yLXVzLmhhY3Rybi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2Vy
+MEEGCCsGAQUFBwEHAQH/BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABE
+AxEAIAENuAAAAAAAAAAAAAABADANBgkqhkiG9w0BAQsFAAOCAQEAWLjNszTOok85
+wRUJtJX4Xnsjm/tCb5JaKc4XwZnWxzkAQ+Fguxf1NN8zhnN39I9v1YgdaL74E/0C
+OPqqnDmAG9xQciPWCmRVFHj+ZBpjU7vmeDWILNF6GzwjcoqlwFtcfIWxJqHAzqnA
+Fl0w6y1+aUhXa9w0iFZHme0xR8E+/7aeacxoLhxMdyfUpUX5y6UhI0YYICqgfLnr
+0diRMC60Fge2nzoocR3u+aeIWUV4tzYOFfZ35Gm0sWGaXGYPxXxn16/TJCRO55TO
+ptY7WsjXSViT1/VBL7Oak8hs7C++asF0KkS7XHvYFvYB7VvoawJI71tX9Af9X0fm
+Bjg8okvQ+Q==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/index b/scripts/resource-cert-samples/LIR2/index
index 9fcbd3ba..fd08ba55 100644
--- a/scripts/resource-cert-samples/LIR2/index
+++ b/scripts/resource-cert-samples/LIR2/index
@@ -8,3 +8,13 @@ V 080731140935Z 07 unknown /CN=TEST ENTITY ISP4
V 080731140935Z 08 unknown /CN=TEST ENTITY ISP3
V 080731144822Z 09 unknown /CN=TEST ENTITY ISP4
V 080731144822Z 0A unknown /CN=TEST ENTITY ISP3
+V 080809005817Z 0B unknown /CN=TEST ENTITY ISP4
+V 080809005818Z 0C unknown /CN=TEST ENTITY ISP3
+V 080809010231Z 0D unknown /CN=TEST ENTITY ISP4
+V 080809010231Z 0E unknown /CN=TEST ENTITY ISP3
+V 080809010709Z 0F unknown /CN=TEST ENTITY ISP4
+V 080809010709Z 10 unknown /CN=TEST ENTITY ISP3
+V 080809011339Z 11 unknown /CN=TEST ENTITY ISP4
+V 080809011339Z 12 unknown /CN=TEST ENTITY ISP3
+V 080809011510Z 13 unknown /CN=TEST ENTITY ISP4
+V 080809011510Z 14 unknown /CN=TEST ENTITY ISP3
diff --git a/scripts/resource-cert-samples/LIR2/index.old b/scripts/resource-cert-samples/LIR2/index.old
index b1af6c04..73ef193c 100644
--- a/scripts/resource-cert-samples/LIR2/index.old
+++ b/scripts/resource-cert-samples/LIR2/index.old
@@ -7,3 +7,13 @@ V 080731140829Z 06 unknown /CN=TEST ENTITY ISP3
V 080731140935Z 07 unknown /CN=TEST ENTITY ISP4
V 080731140935Z 08 unknown /CN=TEST ENTITY ISP3
V 080731144822Z 09 unknown /CN=TEST ENTITY ISP4
+V 080731144822Z 0A unknown /CN=TEST ENTITY ISP3
+V 080809005817Z 0B unknown /CN=TEST ENTITY ISP4
+V 080809005818Z 0C unknown /CN=TEST ENTITY ISP3
+V 080809010231Z 0D unknown /CN=TEST ENTITY ISP4
+V 080809010231Z 0E unknown /CN=TEST ENTITY ISP3
+V 080809010709Z 0F unknown /CN=TEST ENTITY ISP4
+V 080809010709Z 10 unknown /CN=TEST ENTITY ISP3
+V 080809011339Z 11 unknown /CN=TEST ENTITY ISP4
+V 080809011339Z 12 unknown /CN=TEST ENTITY ISP3
+V 080809011510Z 13 unknown /CN=TEST ENTITY ISP4
diff --git a/scripts/resource-cert-samples/LIR2/serial b/scripts/resource-cert-samples/LIR2/serial
index eb589e9d..60d3b2f4 100644
--- a/scripts/resource-cert-samples/LIR2/serial
+++ b/scripts/resource-cert-samples/LIR2/serial
@@ -1 +1 @@
-0B
+15
diff --git a/scripts/resource-cert-samples/LIR2/serial.old b/scripts/resource-cert-samples/LIR2/serial.old
index d9bb888f..8351c193 100644
--- a/scripts/resource-cert-samples/LIR2/serial.old
+++ b/scripts/resource-cert-samples/LIR2/serial.old
@@ -1 +1 @@
-0A
+14
diff --git a/scripts/resource-cert-samples/LIR3.cer b/scripts/resource-cert-samples/LIR3.cer
index 54acaf38..419b192d 100644
--- a/scripts/resource-cert-samples/LIR3.cer
+++ b/scripts/resource-cert-samples/LIR3.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 14 (0xe)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 36 (0x24)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY RIR
Validity
- Not Before: Aug 1 14:48:18 2007 GMT
- Not After : Jul 31 14:48:18 2008 GMT
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
Subject: CN=TEST ENTITY LIR3
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
- X509v3 Authority Key Identifier:
- keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -59,43 +56,43 @@ Certificate:
2001:db8:0:0:0:0:a00::/120
2001:db8:0:0:0:0:a03::/120
- Signature Algorithm: sha1WithRSAEncryption
- 48:66:09:ae:e4:52:ea:33:07:a6:92:4f:41:9d:d9:74:ad:24:
- 17:11:d6:85:88:f2:66:52:e5:61:0e:8e:78:db:56:fb:ab:c8:
- 31:1b:d1:f2:ec:df:1d:87:80:21:d9:81:9e:c8:00:e8:37:d5:
- c3:71:26:97:35:15:fe:99:60:41:be:9b:72:e9:91:c1:bf:c8:
- e3:25:95:f3:95:2b:c4:50:49:8f:a7:2a:ec:9a:d9:f9:b6:27:
- 77:42:38:aa:20:12:30:56:db:41:f0:c4:d7:75:5a:01:4b:ac:
- 36:8e:4d:1f:55:fa:24:4e:04:f2:ac:de:9a:4c:3e:9e:a4:b0:
- fa:84:a8:35:3f:dc:dd:db:2c:74:4e:20:84:a5:17:05:87:8a:
- 55:ee:4c:ae:59:02:7c:e7:70:32:10:9e:6f:b3:52:ec:48:ff:
- 47:77:bf:a1:69:f1:5c:55:94:d0:47:ab:3a:34:56:96:a4:64:
- e9:31:c2:aa:34:d6:a2:51:b2:8c:55:68:8c:5e:7a:d1:8d:43:
- 89:e8:3e:1b:63:e9:b1:0c:e1:8f:31:0d:2f:5f:dd:1e:e8:78:
- 41:d4:49:39:ca:a2:73:1e:9a:6f:c0:07:72:99:9e:3c:0b:ee:
- b9:0b:d8:52:35:4e:19:83:44:ed:d9:de:5a:6b:6d:38:63:4e:
- 12:45:f0:45
+ Signature Algorithm: sha256WithRSAEncryption
+ 2a:bc:5b:b8:bc:0a:4f:52:b5:d5:01:bd:97:c3:79:df:8f:fd:
+ 7b:d7:0f:fd:fc:0c:8c:3f:69:b0:24:c0:b0:65:63:bf:ca:62:
+ 41:29:04:0a:52:73:b3:e1:c8:18:89:77:ba:b8:7c:6a:b7:19:
+ d7:b7:93:fa:dc:62:78:f9:bd:67:45:be:cd:97:bc:b7:f0:47:
+ 95:9b:97:92:70:ae:9c:58:04:49:d7:fa:af:2e:9e:d1:57:22:
+ 5b:10:c3:38:68:94:bf:0f:a8:a6:f4:1f:06:59:49:57:30:11:
+ 77:66:2a:f4:64:65:13:40:6b:e4:a9:6b:4d:75:4a:11:53:ab:
+ 28:44:67:b5:be:45:48:47:bf:67:61:4f:83:63:bf:33:3a:68:
+ 88:4e:0e:3a:60:79:86:52:65:a0:43:c6:0a:b8:ce:bc:37:eb:
+ 3c:7e:ed:11:f7:e6:42:c0:64:52:70:b3:5c:4c:dc:ed:49:96:
+ 64:2d:a6:19:27:87:11:ed:2d:10:96:c1:7f:ae:2d:a7:98:31:
+ 70:9b:35:1d:87:b9:ec:33:0a:f3:c3:d4:47:b6:7b:ff:7a:9f:
+ 04:a8:b6:bd:9d:10:12:e1:24:5a:44:5c:5b:68:c4:9a:09:64:
+ 27:21:aa:f1:d4:05:42:37:41:4f:8d:f9:0a:e2:c6:3b:94:76:
+ d9:d7:97:66
-----BEGIN CERTIFICATE-----
-MIIEFTCCAv2gAwIBAgIBDjANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
-IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+MIID9DCCAtygAwIBAgIBJDANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTEwWhcNMDgwODA5MDExNTEwWjAbMRkw
FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
-hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4IBYzCCAV8wDwYDVR0TAQH/
-BAUwAwEB/zAdBgNVHQ4EFgQUmL4E/4DRq5U5qj3yDmd9AK2j/cUwHwYDVR0jBBgw
-FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
-BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
-Lm5ldC9MSVIzLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
-d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAhBggrBgEFBQcBCAEB/wQS
-MBCgDjAMMAoCAwD8FgIDAPwcMFEGCCsGAQUFBwEHAQH/BEIwQDASBAIAATAMAwQA
-CgAAAwQACgMAMCoEAgACMCQDEAAgAQ24AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAA
-AAAKAwAwDQYJKoZIhvcNAQEFBQADggEBAEhmCa7kUuozB6aST0Gd2XStJBcR1oWI
-8mZS5WEOjnjbVvuryDEb0fLs3x2HgCHZgZ7IAOg31cNxJpc1Ff6ZYEG+m3LpkcG/
-yOMllfOVK8RQSY+nKuya2fm2J3dCOKogEjBW20HwxNd1WgFLrDaOTR9V+iROBPKs
-3ppMPp6ksPqEqDU/3N3bLHROIISlFwWHilXuTK5ZAnzncDIQnm+zUuxI/0d3v6Fp
-8VxVlNBHqzo0VpakZOkxwqo01qJRsoxVaIxeetGNQ4noPhtj6bEM4Y8xDS9f3R7o
-eEHUSTnKonMemm/AB3KZnjwL7rkL2FI1ThmDRO3Z3lprbThjThJF8EU=
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4IBQjCCAT4wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUmL4E/4DRq5U5qj3yDmd9AK2j/cUwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIzLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAh
+BggrBgEFBQcBCAEB/wQSMBCgDjAMMAoCAwD8FgIDAPwcMFEGCCsGAQUFBwEHAQH/
+BEIwQDASBAIAATAMAwQACgAAAwQACgMAMCoEAgACMCQDEAAgAQ24AAAAAAAAAAAK
+AAADEAAgAQ24AAAAAAAAAAAKAwAwDQYJKoZIhvcNAQELBQADggEBACq8W7i8Ck9S
+tdUBvZfDed+P/XvXD/38DIw/abAkwLBlY7/KYkEpBApSc7PhyBiJd7q4fGq3Gde3
+k/rcYnj5vWdFvs2XvLfwR5Wbl5JwrpxYBEnX+q8untFXIlsQwzholL8PqKb0HwZZ
+SVcwEXdmKvRkZRNAa+Spa011ShFTqyhEZ7W+RUhHv2dhT4NjvzM6aIhODjpgeYZS
+ZaBDxgq4zrw36zx+7RH35kLAZFJws1xM3O1JlmQtphknhxHtLRCWwX+uLaeYMXCb
+NR2HuewzCvPD1Ee2e/96nwSotr2dEBLhJFpEXFtoxJoJZCchqvHUBUI3QU+N+Qri
+xjuUdtnXl2Y=
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3.cnf b/scripts/resource-cert-samples/LIR3.cnf
index 50d88f5b..0f65ce12 100644
--- a/scripts/resource-cert-samples/LIR3.cnf
+++ b/scripts/resource-cert-samples/LIR3.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY LIR3
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR3/
authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
sbgp-autonomousSysNum = critical,AS:64534-64540
sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv4:10.3.0.0/24,IPv6:2001:db8::a00:0/120,IPv6:2001:db8::a03:0/120
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR3/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+sbgp-autonomousSysNum = critical,AS:64534-64540
+sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv4:10.3.0.0/24,IPv6:2001:db8::a00:0/120,IPv6:2001:db8::a03:0/120
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/LIR3.req b/scripts/resource-cert-samples/LIR3.req
index 013672c9..e22e9dd3 100644
--- a/scripts/resource-cert-samples/LIR3.req
+++ b/scripts/resource-cert-samples/LIR3.req
@@ -1,15 +1,22 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMzCCASIwDQYJ
+MIIDtzCCAp8CAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMzCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAKMhV2FkrxEY1Mveptyt2SwPD1iffsiF
VREmTHzwa2ganmoMj+bcPYNYKsx3rBlzb1rzbiSszRrcHQtMRPVtiwoXPYb56P7m
YOWfQGrllOiaVhcXHKvBjDdAK1W/LF7cjcolf4pf7vsWhuvgCNMm5eNwxQxr+xuP
a1z24kpYpTUB6gUbPs6EvrU/bRgWS2jleUyIfbalZaM6wjLcrY+KBe726XqA2hKp
D1q10tMxrD7TGSUtKN55bM79d2bV4y+py/mFjCC7ooYj8JOVIAR4x8cHpv7w9EW7
-z3gr3c6cCKVGaBBM1wVibIZaLX8GOMJNu0SHAEN50o/za7L0XBy5aAECAwEAAaAA
-MA0GCSqGSIb3DQEBBQUAA4IBAQBcWckC9psoEBPLgzwz6COklAzOLW3nWnU4OIBm
-vlOWzOXF0HwKYaB2374yBzNlshVuxGboScJk7mogdckIJfZ2yRbRW1v83uVqbOBU
-KiGnFz1/AUeqdWnUVpFobbKuElUiqjY4ozWTkAZKGya9RgLMsxc0X3tK3cdmpgq6
-6AKiv1erjB6+yZPPvC3pgDYVrucQtng1HZrjW9iEc2RmX3i/rOrysvRUZ+951MD3
-2UDWLdv6rY2wpgBidGx96kj4OVb7j+XlCfjk3QN3SWUPbwUAsEQIr+H5a6E694Ru
-vLQ8/+pQ1tHTeReaRLtjzITQjfLPPM6fMptYs4572mdN3DjZ
+z3gr3c6cCKVGaBBM1wVibIZaLX8GOMJNu0SHAEN50o/za7L0XBy5aAECAwEAAaCC
+AVUwggFRBgkqhkiG9w0BCQ4xggFCMIIBPjAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
+DgQWBBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQQYIKwYB
+BQUHAQsENTAzMDEGCCsGAQUFBzAFhiVyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0xJUjMvMEMGCCsGAQUFBwEBBDcwNTAzBggrBgEFBQcwAoYncnN5bmM6
+Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9SSVIuY2VyMCEGCCsGAQUFBwEIAQH/
+BBIwEKAOMAwwCgIDAPwWAgMA/BwwUQYIKwYBBQUHAQcBAf8EQjBAMBIEAgABMAwD
+BAAKAAADBAAKAwAwKgQCAAIwJAMQACABDbgAAAAAAAAAAAoAAAMQACABDbgAAAAA
+AAAAAAoDADANBgkqhkiG9w0BAQUFAAOCAQEAmuU3fGe4uEXPaD9zY3elmjHYcZ2m
+rMClydTpxMjNwJIoNdEP7DNolC3aHkDj27gbD2MVuMeKDb7XksmLgnAiJc9f6hMb
+NxpfLPVLHL5GTLQoaKUeLnNZenWElgFU3J2ebPFkhsqItb3YE3ok/0VGRhS+fMrI
+vNfPlx/7JpeuS0IZuEHrhQ4qy5xq+c9E9xFlytT2Txsqz6xWBccOO18cZ24nrexJ
+9xLS9RuD16z0RCM/WsGqlA6AiQXYKd3T8fOuB6CEklZNSCY4iLjK5jJDx/8HgHtg
+6FOQWM1bFGmOpKBFuSjQjNqgfpYpKaIIT81gPSUy/oG9bT5G8mkN4iWDOg==
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/LIR3/04.pem b/scripts/resource-cert-samples/LIR3/04.pem
new file mode 100644
index 00000000..2f339d8c
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/04.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 4 (0x4)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY ISP5c
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:c8:8b:a1:25:65:df:ee:a2:7f:54:af:52:0a:1a:
+ 1a:fa:0d:75:b3:3c:e9:e0:29:d3:89:20:e9:51:49:
+ 67:2c:43:da:a0:2c:d4:44:b3:96:14:a9:07:77:60:
+ b9:6f:01:ef:8e:54:a5:74:ac:5a:67:f8:30:4d:10:
+ f9:ac:9f:b8:75:61:0b:f6:e7:7c:ea:9b:5c:98:7a:
+ 4b:3e:c4:e2:59:42:d3:19:ca:0f:58:0e:b7:c8:82:
+ 4e:e5:bb:ac:fd:92:e5:88:b2:fc:64:cf:6e:38:3b:
+ 18:83:fc:e7:a6:ae:fb:90:36:d0:e1:ca:4d:90:41:
+ 0f:0f:3b:2a:c0:0c:d9:7b:7d:e8:50:13:f6:09:73:
+ 82:a3:d2:e3:bb:82:08:87:7f:d2:bb:0e:0e:7a:28:
+ b6:25:02:b5:d9:51:fc:33:32:47:47:ff:cf:7f:bc:
+ ee:00:01:bb:05:5e:2e:03:9a:ad:95:3b:ca:c2:c6:
+ 87:64:74:39:aa:59:6b:ae:e0:a7:51:1a:07:f2:8e:
+ 4c:8e:65:2f:df:f2:99:ba:e0:b6:8a:4f:c0:20:72:
+ 79:98:00:8f:0d:50:13:3d:d1:3e:8c:bd:dc:74:a9:
+ 33:a8:56:1d:31:78:7c:e7:02:9e:8d:0a:14:12:6d:
+ d3:37:c7:7a:f0:84:10:fe:fe:4d:28:97:26:6e:08:
+ 85:a1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 2D:87:C1:9A:F8:58:2B:BD:C2:F8:7E:30:47:B3:A9:88:37:C9:EB:46
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 54:9d:09:01:1d:1f:b7:ac:f9:0a:05:b4:68:22:0d:e2:d4:b3:
+ 28:80:eb:2b:e9:86:2b:6a:03:e5:a7:d4:34:cd:58:fd:0d:90:
+ d9:f4:1d:0d:95:ff:cf:23:1c:9d:dd:38:e4:54:4d:1f:9a:1d:
+ 20:8e:c0:b9:06:37:0b:06:ba:e9:6d:df:f4:07:d6:1d:2b:0b:
+ c4:16:24:38:98:6e:56:85:0f:c3:43:87:af:0c:b5:90:c1:c4:
+ 84:96:1d:d9:d0:d0:35:fe:ff:c1:ab:38:42:70:19:bd:3e:b2:
+ eb:4e:0a:20:a5:18:c0:aa:e8:8e:6b:ad:4f:51:a2:04:82:d6:
+ ef:12:33:57:fb:6e:9b:a3:9b:9e:a9:49:15:cd:f1:e1:38:40:
+ 11:af:06:88:48:52:2e:0a:ec:9a:03:4a:1b:3f:86:cf:67:f3:
+ 83:34:f9:53:f7:af:8f:cb:67:1a:23:b2:0c:89:38:4a:1e:44:
+ d1:25:4d:22:02:41:8a:1f:45:7d:8b:99:c1:83:90:1e:5b:f1:
+ 1b:ba:67:ba:c2:b8:93:2e:cd:5f:23:41:ba:f2:d5:2a:6e:33:
+ 1f:63:4c:ac:a5:be:fa:d9:18:13:42:71:43:2e:e2:24:5c:fb:
+ 25:5a:39:ab:b0:0a:81:31:51:13:65:eb:7d:0d:2b:7a:7c:3e:
+ 09:c0:4c:c8
+-----BEGIN CERTIFICATE-----
+MIIDOjCCAiKgAwIBAgIBBDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAwNTgxN1oXDTA4MDgwOTAwNTgxN1owHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
+s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
+DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
+c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
+dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjgYcwgYQwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQULYfBmvhYK73C+H4wR7OpiDfJ60YwDgYDVR0PAQH/
+BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yy8wDQYJKoZIhvcNAQELBQADggEBAFSd
+CQEdH7es+QoFtGgiDeLUsyiA6yvphitqA+Wn1DTNWP0NkNn0HQ2V/88jHJ3dOORU
+TR+aHSCOwLkGNwsGuult3/QH1h0rC8QWJDiYblaFD8NDh68MtZDBxISWHdnQ0DX+
+/8GrOEJwGb0+sutOCiClGMCq6I5rrU9RogSC1u8SM1f7bpujm56pSRXN8eE4QBGv
+BohIUi4K7JoDShs/hs9n84M0+VP3r4/LZxojsgyJOEoeRNElTSICQYofRX2LmcGD
+kB5b8Ru6Z7rCuJMuzV8jQbry1SpuMx9jTKylvvrZGBNCcUMu4iRc+yVaOauwCoEx
+URNl630NK3p8PgnATMg=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/05.pem b/scripts/resource-cert-samples/LIR3/05.pem
new file mode 100644
index 00000000..b3efd764
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/05.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 5 (0x5)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY ISP5b
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:bf:8f:59:d8:fc:fa:1d:04:70:29:ce:7b:01:64:
+ 21:40:dc:5c:43:fe:4c:af:88:c8:62:9b:be:9c:72:
+ 8f:8a:a5:34:8a:3b:23:8d:9b:8a:4f:bf:66:ac:68:
+ 71:9c:fd:68:59:f5:bf:9f:4d:2e:b5:d6:e3:fa:bd:
+ f3:60:53:5c:b7:11:ac:95:0b:c0:87:cd:99:9e:94:
+ 57:8d:ec:05:b8:df:aa:fc:8e:38:d3:0f:65:6d:09:
+ 60:f2:e1:98:81:72:d8:51:3e:41:91:b3:10:95:f5:
+ f5:d0:f9:e5:5c:a1:85:fa:71:26:85:e3:d1:4c:02:
+ 7f:14:e2:1e:4a:8a:96:68:9e:d6:16:a5:ef:ad:b5:
+ 83:62:cd:23:74:7c:82:56:b4:d1:34:53:5a:8a:7a:
+ 61:9f:ae:54:5b:ef:f9:56:de:87:6b:42:92:bc:49:
+ f4:b5:c3:35:07:4a:18:47:d2:92:c6:1c:16:74:74:
+ b1:e9:39:3c:53:12:05:9d:eb:dc:9c:72:2b:97:4d:
+ 27:21:77:96:7d:4c:ce:79:0c:fb:a7:b8:99:6b:66:
+ 20:2e:56:9c:44:b4:e3:5e:80:c4:7d:78:a1:b4:05:
+ f7:20:7d:26:1e:44:bf:5d:69:15:3c:7a:24:67:bd:
+ b9:b5:08:0f:33:4d:af:3b:2d:e7:b9:ab:1d:2b:d6:
+ fb:73
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 6C:B3:65:94:FE:C6:9F:4A:50:9D:4D:8B:40:1A:A1:FD:97:17:97:92
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 60:54:f0:88:c1:6e:25:22:90:35:05:b5:d9:a0:ca:1c:22:da:
+ 3e:32:f7:a2:c3:b7:31:f0:02:11:66:8f:be:be:ae:c7:69:bc:
+ 47:b9:ed:6e:d2:8f:b4:cc:0d:43:00:7a:3e:e0:d4:3d:08:c7:
+ c3:4e:5e:40:6a:30:bb:30:7c:f4:5e:2e:e0:74:fc:5d:8e:b4:
+ 2f:2e:98:12:41:31:0b:4c:d3:14:f5:1d:5c:66:e3:4f:e2:e1:
+ 1e:cb:48:80:b2:3b:59:10:30:90:7a:cd:9c:e4:a5:14:f8:b9:
+ 2a:39:3b:0b:a5:5d:5b:f2:4f:93:d9:2c:fb:3e:14:1b:f1:cd:
+ 8b:0c:9d:85:9e:1f:7c:b1:a9:97:fd:9b:51:12:62:c9:a7:9f:
+ a2:d0:86:ac:40:e5:6f:f5:57:00:df:60:5a:65:20:ae:a2:25:
+ 84:c3:04:d0:de:2e:15:28:22:cf:0d:d6:3a:03:70:2b:89:4e:
+ 72:08:00:ef:5f:fb:3f:82:6b:5b:a1:55:4f:60:54:aa:60:cb:
+ 3a:e4:5e:16:f7:e6:ca:30:5a:c9:1e:51:5f:b1:70:e8:7f:e4:
+ eb:be:e1:c0:37:b3:e3:46:a5:c1:e7:e7:30:81:8f:23:c7:24:
+ 63:c1:36:4a:fa:df:4d:34:35:86:fb:cc:ce:ba:2e:0e:d1:27:
+ bd:bc:55:54
+-----BEGIN CERTIFICATE-----
+MIIDOjCCAiKgAwIBAgIBBTANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAwNTgxN1oXDTA4MDgwOTAwNTgxN1owHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
+m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
+D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
+tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
+OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjgYcwgYQwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUbLNllP7Gn0pQnU2LQBqh/ZcXl5IwDgYDVR0PAQH/
+BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yi8wDQYJKoZIhvcNAQELBQADggEBAGBU
+8IjBbiUikDUFtdmgyhwi2j4y96LDtzHwAhFmj76+rsdpvEe57W7Sj7TMDUMAej7g
+1D0Ix8NOXkBqMLswfPReLuB0/F2OtC8umBJBMQtM0xT1HVxm40/i4R7LSICyO1kQ
+MJB6zZzkpRT4uSo5OwulXVvyT5PZLPs+FBvxzYsMnYWeH3yxqZf9m1ESYsmnn6LQ
+hqxA5W/1VwDfYFplIK6iJYTDBNDeLhUoIs8N1joDcCuJTnIIAO9f+z+Ca1uhVU9g
+VKpgyzrkXhb35sowWskeUV+xcOh/5Ou+4cA3s+NGpcHn5zCBjyPHJGPBNkr63000
+NYb7zM66Lg7RJ728VVQ=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/06.pem b/scripts/resource-cert-samples/LIR3/06.pem
new file mode 100644
index 00000000..cbf5d122
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/06.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 6 (0x6)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY ISP5a
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:e6:4b:ad:78:28:6b:e6:50:1b:65:81:d5:8d:2b:
+ 56:77:cd:bb:c9:47:a0:aa:32:b0:2c:ac:1f:f1:e4:
+ 90:2b:c2:33:6f:e7:53:b1:d0:1d:ab:05:27:9d:b7:
+ a1:ee:a8:4f:c8:5b:36:23:e3:12:e4:51:59:27:cd:
+ fd:7a:aa:dc:56:05:a1:73:ab:79:dd:3c:82:b2:8f:
+ ae:f9:ec:c0:36:38:e6:02:aa:fd:89:60:21:52:5b:
+ b6:33:80:75:e5:7f:fd:ac:6e:ec:d4:9a:26:2f:7e:
+ 28:45:16:29:47:7d:f3:8a:72:d5:e4:65:fa:f4:54:
+ 6f:ae:48:33:62:c1:32:f1:2b:83:33:36:63:60:9e:
+ bc:c7:e7:99:5d:51:da:cd:2f:8f:83:47:20:9e:e9:
+ cc:a3:72:c0:72:bd:49:2d:c4:52:ea:6f:da:42:46:
+ 71:90:c7:af:7f:9f:c7:dd:0b:96:96:3c:45:9f:c0:
+ ea:65:6a:43:e3:f3:92:d5:e1:73:c0:6e:20:f5:17:
+ e5:d1:58:da:21:b3:e9:0c:4d:f0:e8:bd:7c:b7:ef:
+ 81:c9:f5:70:cf:a8:20:7d:e2:6a:f9:1b:66:a9:c8:
+ 71:d6:32:f8:72:3d:83:99:19:0d:0c:6b:e9:f8:92:
+ cd:33:17:86:6a:3d:af:0d:05:94:ab:1c:d4:2c:a4:
+ 45:cb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 09:F0:14:0B:79:FB:0B:FF:A8:EF:54:B9:EC:3E:B9:8B:D0:CB:9C:EC
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 6b:75:56:d5:11:aa:e9:73:f5:1c:b8:ec:d8:52:52:8f:84:c4:
+ 3f:80:26:cc:f3:57:f5:71:db:2d:e6:33:9b:25:e4:c0:d8:ff:
+ 6e:96:30:d0:be:e4:0c:16:c1:0c:2f:5f:bc:94:44:14:64:74:
+ 11:37:2e:42:c5:2e:31:ca:09:2e:ca:d1:4e:76:74:a4:0d:2a:
+ 92:50:3e:c4:6d:85:98:23:e2:ce:28:9e:67:8e:35:27:af:06:
+ af:fb:af:e4:28:c6:ac:ad:e9:29:f9:5d:ba:fb:26:5a:e4:7c:
+ 0c:29:f0:d3:a5:b7:b8:b0:3b:93:6b:cb:6a:3f:73:b1:e0:2c:
+ c2:6e:35:6b:c9:56:e0:0e:b4:64:94:6a:7e:eb:be:52:2d:22:
+ 2c:4e:9d:09:8d:cb:20:5d:c2:f9:51:40:d4:f9:a5:0d:b3:4b:
+ 0c:a2:8a:fe:d1:63:16:54:68:1c:8d:d3:12:9b:96:84:9d:d9:
+ ba:02:68:04:7f:88:ac:2a:5b:f5:31:0a:d1:35:36:6b:ab:96:
+ c3:de:56:16:a8:71:a7:af:c5:a4:42:24:ba:a4:cf:2b:99:96:
+ 8a:eb:ce:5a:6b:40:0a:36:55:be:c5:ab:50:46:8f:66:4d:7d:
+ 6c:04:11:2a:0c:e0:2b:11:5e:53:48:32:39:f8:62:58:25:59:
+ c8:7e:31:22
+-----BEGIN CERTIFICATE-----
+MIIDOjCCAiKgAwIBAgIBBjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAwNTgxN1oXDTA4MDgwOTAwNTgxN1owHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
+0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
+YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
+nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
+akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjgYcwgYQwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUCfAUC3n7C/+o71S57D65i9DLnOwwDgYDVR0PAQH/
+BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1YS8wDQYJKoZIhvcNAQELBQADggEBAGt1
+VtURqulz9Ry47NhSUo+ExD+AJszzV/Vx2y3mM5sl5MDY/26WMNC+5AwWwQwvX7yU
+RBRkdBE3LkLFLjHKCS7K0U52dKQNKpJQPsRthZgj4s4onmeONSevBq/7r+Qoxqyt
+6Sn5Xbr7JlrkfAwp8NOlt7iwO5Nry2o/c7HgLMJuNWvJVuAOtGSUan7rvlItIixO
+nQmNyyBdwvlRQNT5pQ2zSwyiiv7RYxZUaByN0xKbloSd2boCaAR/iKwqW/UxCtE1
+NmurlsPeVhaocaevxaRCJLqkzyuZlorrzlprQAo2Vb7Fq1BGj2ZNfWwEESoM4CsR
+XlNIMjn4YlglWch+MSI=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/07.pem b/scripts/resource-cert-samples/LIR3/07.pem
new file mode 100644
index 00000000..96c90b92
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/07.pem
@@ -0,0 +1,88 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 7 (0x7)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY ISP5c
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:c8:8b:a1:25:65:df:ee:a2:7f:54:af:52:0a:1a:
+ 1a:fa:0d:75:b3:3c:e9:e0:29:d3:89:20:e9:51:49:
+ 67:2c:43:da:a0:2c:d4:44:b3:96:14:a9:07:77:60:
+ b9:6f:01:ef:8e:54:a5:74:ac:5a:67:f8:30:4d:10:
+ f9:ac:9f:b8:75:61:0b:f6:e7:7c:ea:9b:5c:98:7a:
+ 4b:3e:c4:e2:59:42:d3:19:ca:0f:58:0e:b7:c8:82:
+ 4e:e5:bb:ac:fd:92:e5:88:b2:fc:64:cf:6e:38:3b:
+ 18:83:fc:e7:a6:ae:fb:90:36:d0:e1:ca:4d:90:41:
+ 0f:0f:3b:2a:c0:0c:d9:7b:7d:e8:50:13:f6:09:73:
+ 82:a3:d2:e3:bb:82:08:87:7f:d2:bb:0e:0e:7a:28:
+ b6:25:02:b5:d9:51:fc:33:32:47:47:ff:cf:7f:bc:
+ ee:00:01:bb:05:5e:2e:03:9a:ad:95:3b:ca:c2:c6:
+ 87:64:74:39:aa:59:6b:ae:e0:a7:51:1a:07:f2:8e:
+ 4c:8e:65:2f:df:f2:99:ba:e0:b6:8a:4f:c0:20:72:
+ 79:98:00:8f:0d:50:13:3d:d1:3e:8c:bd:dc:74:a9:
+ 33:a8:56:1d:31:78:7c:e7:02:9e:8d:0a:14:12:6d:
+ d3:37:c7:7a:f0:84:10:fe:fe:4d:28:97:26:6e:08:
+ 85:a1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 2D:87:C1:9A:F8:58:2B:BD:C2:F8:7E:30:47:B3:A9:88:37:C9:EB:46
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 0c:a5:20:ee:a9:16:f5:45:6f:f6:55:c7:42:48:01:84:8a:e6:
+ be:11:15:47:85:bd:8b:f1:11:b9:32:0f:77:52:bf:64:cd:f9:
+ f2:c9:70:78:0e:d7:21:e0:79:4e:7e:08:a3:9f:07:0d:73:55:
+ 79:31:3f:93:a0:cb:88:3f:91:7b:83:6a:da:57:92:71:6c:a2:
+ 03:dc:e8:3d:dc:ab:07:5d:30:d1:62:fe:28:40:29:07:80:b1:
+ 41:36:58:fa:f0:a6:6a:ae:c8:a5:7d:01:e9:cb:84:7d:c7:39:
+ ec:87:c2:14:3b:ae:7a:85:66:6c:da:72:88:7e:aa:6b:81:a6:
+ 3d:bc:5d:de:fd:ad:20:42:8f:1e:75:73:4e:18:11:95:0e:87:
+ 15:d6:be:01:0a:77:ca:33:ce:d2:3b:9e:07:4a:55:e5:7a:70:
+ 46:e6:59:46:79:6e:0f:3d:1d:98:d1:a4:59:50:d6:22:e0:f1:
+ cd:44:97:72:9f:67:3a:23:ec:c7:68:44:5c:84:ba:30:60:01:
+ 06:78:dd:96:cf:98:e0:24:9b:f7:38:ea:6c:55:7a:f2:78:d6:
+ 0f:b3:03:1b:d9:d6:cc:b6:c4:b5:42:75:f8:fd:6f:bc:f0:8f:
+ 23:ba:8a:22:6b:f9:cc:d8:90:76:d4:7c:78:b5:ff:ee:96:6e:
+ f8:3b:db:31
+-----BEGIN CERTIFICATE-----
+MIIDozCCAougAwIBAgIBBzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMDIzMVoXDTA4MDgwOTAxMDIzMVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
+s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
+DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
+c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
+dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjgfAwge0wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQULYfBmvhYK73C+H4wR7OpiDfJ60YwDgYDVR0PAQH/
+BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjMuY2Vy
+MCEGCCsGAQUFBwEIAQH/BBIwEKAOMAwwCgIDAPwWAgMA/BwwDQYJKoZIhvcNAQEL
+BQADggEBAAylIO6pFvVFb/ZVx0JIAYSK5r4RFUeFvYvxEbkyD3dSv2TN+fLJcHgO
+1yHgeU5+CKOfBw1zVXkxP5Ogy4g/kXuDatpXknFsogPc6D3cqwddMNFi/ihAKQeA
+sUE2WPrwpmquyKV9AenLhH3HOeyHwhQ7rnqFZmzacoh+qmuBpj28Xd79rSBCjx51
+c04YEZUOhxXWvgEKd8ozztI7ngdKVeV6cEbmWUZ5bg89HZjRpFlQ1iLg8c1El3Kf
+Zzoj7MdoRFyEujBgAQZ43ZbPmOAkm/c46mxVevJ41g+zAxvZ1sy2xLVCdfj9b7zw
+jyO6iiJr+czYkHbUfHi1/+6Wbvg72zE=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/08.pem b/scripts/resource-cert-samples/LIR3/08.pem
new file mode 100644
index 00000000..eda14481
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/08.pem
@@ -0,0 +1,91 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 8 (0x8)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY ISP5b
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:bf:8f:59:d8:fc:fa:1d:04:70:29:ce:7b:01:64:
+ 21:40:dc:5c:43:fe:4c:af:88:c8:62:9b:be:9c:72:
+ 8f:8a:a5:34:8a:3b:23:8d:9b:8a:4f:bf:66:ac:68:
+ 71:9c:fd:68:59:f5:bf:9f:4d:2e:b5:d6:e3:fa:bd:
+ f3:60:53:5c:b7:11:ac:95:0b:c0:87:cd:99:9e:94:
+ 57:8d:ec:05:b8:df:aa:fc:8e:38:d3:0f:65:6d:09:
+ 60:f2:e1:98:81:72:d8:51:3e:41:91:b3:10:95:f5:
+ f5:d0:f9:e5:5c:a1:85:fa:71:26:85:e3:d1:4c:02:
+ 7f:14:e2:1e:4a:8a:96:68:9e:d6:16:a5:ef:ad:b5:
+ 83:62:cd:23:74:7c:82:56:b4:d1:34:53:5a:8a:7a:
+ 61:9f:ae:54:5b:ef:f9:56:de:87:6b:42:92:bc:49:
+ f4:b5:c3:35:07:4a:18:47:d2:92:c6:1c:16:74:74:
+ b1:e9:39:3c:53:12:05:9d:eb:dc:9c:72:2b:97:4d:
+ 27:21:77:96:7d:4c:ce:79:0c:fb:a7:b8:99:6b:66:
+ 20:2e:56:9c:44:b4:e3:5e:80:c4:7d:78:a1:b4:05:
+ f7:20:7d:26:1e:44:bf:5d:69:15:3c:7a:24:67:bd:
+ b9:b5:08:0f:33:4d:af:3b:2d:e7:b9:ab:1d:2b:d6:
+ fb:73
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 6C:B3:65:94:FE:C6:9F:4A:50:9D:4D:8B:40:1A:A1:FD:97:17:97:92
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 13:01:ba:b0:04:4c:97:5c:4a:37:a9:4f:0d:4e:ba:3a:b4:7f:
+ ba:30:a6:e8:d6:ad:5a:6f:d2:67:23:a4:92:33:b2:b7:3d:8f:
+ e6:57:95:d4:98:b5:d4:4d:95:dc:36:e0:39:02:7d:b9:49:6e:
+ 27:6e:d6:a1:37:85:fa:59:bf:97:5d:73:63:64:88:a7:87:36:
+ 17:8b:ed:40:8c:3c:29:f6:75:3e:cf:22:5b:83:d6:f6:b7:5d:
+ d3:05:c7:93:5d:d0:f3:5e:38:3b:21:66:0d:ef:ac:66:d9:a9:
+ 38:ee:0a:cc:8a:d5:1a:5a:8e:8d:05:df:f9:29:18:b7:0c:11:
+ 4f:e4:b3:34:f3:b7:f8:da:c5:6b:15:e1:1f:a4:29:e1:26:99:
+ 57:1c:08:83:2d:1c:15:39:bb:d6:23:4c:40:9d:be:2c:ce:12:
+ 31:ea:47:15:2d:c2:59:d1:02:95:cb:7f:21:6c:86:2b:b5:58:
+ 02:80:9c:81:5f:b9:34:c8:d9:b9:47:64:22:2b:ec:37:41:ac:
+ f5:b7:3d:d2:f4:da:56:c3:ed:dd:f3:fe:13:83:b5:e7:23:53:
+ 18:63:87:9a:6b:b6:89:16:c1:72:0a:95:7d:74:93:6d:ee:2d:
+ 54:ac:69:d0:06:03:71:fc:e9:7d:8f:ec:b3:a9:12:ef:06:a3:
+ 85:85:f4:13
+-----BEGIN CERTIFICATE-----
+MIIDvTCCAqWgAwIBAgIBCDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMDIzMVoXDTA4MDgwOTAxMDIzMVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
+m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
+D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
+tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
+OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBRss2WU/safSlCdTYtAGqH9lxeXkjAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDViLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAwAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoDADANBgkqhkiG9w0BAQsFAAOCAQEAEwG6sARMl1xKN6lPDU66
+OrR/ujCm6NatWm/SZyOkkjOytz2P5leV1Ji11E2V3DbgOQJ9uUluJ27WoTeF+lm/
+l11zY2SIp4c2F4vtQIw8KfZ1Ps8iW4PW9rdd0wXHk13Q8144OyFmDe+sZtmpOO4K
+zIrVGlqOjQXf+SkYtwwRT+SzNPO3+NrFaxXhH6Qp4SaZVxwIgy0cFTm71iNMQJ2+
+LM4SMepHFS3CWdEClct/IWyGK7VYAoCcgV+5NMjZuUdkIivsN0Gs9bc90vTaVsPt
+3fP+E4O15yNTGGOHmmu2iRbBcgqVfXSTbe4tVKxp0AYDcfzpfY/ss6kS7wajhYX0
+Ew==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/09.pem b/scripts/resource-cert-samples/LIR3/09.pem
new file mode 100644
index 00000000..280892fd
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/09.pem
@@ -0,0 +1,91 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 9 (0x9)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY ISP5a
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:e6:4b:ad:78:28:6b:e6:50:1b:65:81:d5:8d:2b:
+ 56:77:cd:bb:c9:47:a0:aa:32:b0:2c:ac:1f:f1:e4:
+ 90:2b:c2:33:6f:e7:53:b1:d0:1d:ab:05:27:9d:b7:
+ a1:ee:a8:4f:c8:5b:36:23:e3:12:e4:51:59:27:cd:
+ fd:7a:aa:dc:56:05:a1:73:ab:79:dd:3c:82:b2:8f:
+ ae:f9:ec:c0:36:38:e6:02:aa:fd:89:60:21:52:5b:
+ b6:33:80:75:e5:7f:fd:ac:6e:ec:d4:9a:26:2f:7e:
+ 28:45:16:29:47:7d:f3:8a:72:d5:e4:65:fa:f4:54:
+ 6f:ae:48:33:62:c1:32:f1:2b:83:33:36:63:60:9e:
+ bc:c7:e7:99:5d:51:da:cd:2f:8f:83:47:20:9e:e9:
+ cc:a3:72:c0:72:bd:49:2d:c4:52:ea:6f:da:42:46:
+ 71:90:c7:af:7f:9f:c7:dd:0b:96:96:3c:45:9f:c0:
+ ea:65:6a:43:e3:f3:92:d5:e1:73:c0:6e:20:f5:17:
+ e5:d1:58:da:21:b3:e9:0c:4d:f0:e8:bd:7c:b7:ef:
+ 81:c9:f5:70:cf:a8:20:7d:e2:6a:f9:1b:66:a9:c8:
+ 71:d6:32:f8:72:3d:83:99:19:0d:0c:6b:e9:f8:92:
+ cd:33:17:86:6a:3d:af:0d:05:94:ab:1c:d4:2c:a4:
+ 45:cb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 09:F0:14:0B:79:FB:0B:FF:A8:EF:54:B9:EC:3E:B9:8B:D0:CB:9C:EC
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ a2:9f:a6:5b:b3:c0:3c:68:b5:0f:d2:2f:fb:1a:6e:88:bb:29:
+ 53:68:29:48:c1:0e:8a:b6:02:58:24:16:d9:9c:e6:75:da:c6:
+ f1:24:51:d9:2e:a1:e1:46:ae:03:bb:55:2f:5c:0e:01:ce:cf:
+ 1b:65:3c:c7:7e:3c:37:84:88:86:70:91:eb:31:03:ba:48:f0:
+ 70:2f:b3:fe:a6:9d:62:75:a1:16:c8:10:a9:27:38:b1:34:53:
+ d7:4c:30:58:3f:49:c8:a5:59:b5:0c:7d:e1:70:40:ad:57:83:
+ 2b:66:cd:d7:82:28:85:f2:b0:ef:0e:ee:28:02:ac:59:27:b9:
+ e7:9f:a3:5a:09:da:34:b5:27:62:f5:7f:6b:d3:0b:85:66:f7:
+ fd:7d:cc:30:28:49:5a:da:1d:9f:21:38:d6:10:59:9e:e8:a8:
+ 5b:02:23:18:c8:20:e2:e7:df:34:a9:c0:aa:99:ec:20:25:35:
+ 38:a8:36:2a:08:e2:98:23:2c:ed:f0:85:2d:0c:2f:dc:a2:81:
+ 60:7b:f3:1b:53:ab:dd:f2:ea:1e:e7:bc:4d:20:a9:5e:a3:02:
+ 3c:24:c0:73:66:e1:2b:c1:8b:c5:7d:f7:04:09:8b:38:1a:95:
+ 6b:c0:d8:23:10:18:9d:61:37:03:d5:76:29:f2:a8:4e:a4:78:
+ 37:d1:5d:59
+-----BEGIN CERTIFICATE-----
+MIIDvTCCAqWgAwIBAgIBCTANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMDIzMVoXDTA4MDgwOTAxMDIzMVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
+0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
+YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
+nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
+akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQJ8BQLefsL/6jvVLnsPrmL0Muc7DAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDVhLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAAAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoAADANBgkqhkiG9w0BAQsFAAOCAQEAop+mW7PAPGi1D9Iv+xpu
+iLspU2gpSMEOirYCWCQW2ZzmddrG8SRR2S6h4UauA7tVL1wOAc7PG2U8x348N4SI
+hnCR6zEDukjwcC+z/qadYnWhFsgQqSc4sTRT10wwWD9JyKVZtQx94XBArVeDK2bN
+14IohfKw7w7uKAKsWSe555+jWgnaNLUnYvV/a9MLhWb3/X3MMChJWtodnyE41hBZ
+nuioWwIjGMgg4uffNKnAqpnsICU1OKg2KgjimCMs7fCFLQwv3KKBYHvzG1Or3fLq
+Hue8TSCpXqMCPCTAc2bhK8GLxX33BAmLOBqVa8DYIxAYnWE3A9V2KfKoTqR4N9Fd
+WQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/0A.pem b/scripts/resource-cert-samples/LIR3/0A.pem
new file mode 100644
index 00000000..e34e0d82
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/0A.pem
@@ -0,0 +1,88 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 10 (0xa)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:07:09 2007 GMT
+ Not After : Aug 9 01:07:09 2008 GMT
+ Subject: CN=TEST ENTITY ISP5c
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:c8:8b:a1:25:65:df:ee:a2:7f:54:af:52:0a:1a:
+ 1a:fa:0d:75:b3:3c:e9:e0:29:d3:89:20:e9:51:49:
+ 67:2c:43:da:a0:2c:d4:44:b3:96:14:a9:07:77:60:
+ b9:6f:01:ef:8e:54:a5:74:ac:5a:67:f8:30:4d:10:
+ f9:ac:9f:b8:75:61:0b:f6:e7:7c:ea:9b:5c:98:7a:
+ 4b:3e:c4:e2:59:42:d3:19:ca:0f:58:0e:b7:c8:82:
+ 4e:e5:bb:ac:fd:92:e5:88:b2:fc:64:cf:6e:38:3b:
+ 18:83:fc:e7:a6:ae:fb:90:36:d0:e1:ca:4d:90:41:
+ 0f:0f:3b:2a:c0:0c:d9:7b:7d:e8:50:13:f6:09:73:
+ 82:a3:d2:e3:bb:82:08:87:7f:d2:bb:0e:0e:7a:28:
+ b6:25:02:b5:d9:51:fc:33:32:47:47:ff:cf:7f:bc:
+ ee:00:01:bb:05:5e:2e:03:9a:ad:95:3b:ca:c2:c6:
+ 87:64:74:39:aa:59:6b:ae:e0:a7:51:1a:07:f2:8e:
+ 4c:8e:65:2f:df:f2:99:ba:e0:b6:8a:4f:c0:20:72:
+ 79:98:00:8f:0d:50:13:3d:d1:3e:8c:bd:dc:74:a9:
+ 33:a8:56:1d:31:78:7c:e7:02:9e:8d:0a:14:12:6d:
+ d3:37:c7:7a:f0:84:10:fe:fe:4d:28:97:26:6e:08:
+ 85:a1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 2D:87:C1:9A:F8:58:2B:BD:C2:F8:7E:30:47:B3:A9:88:37:C9:EB:46
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 2b:e4:c0:d0:33:fd:74:82:bc:70:b2:2f:e9:5d:9b:9e:b0:f8:
+ fb:be:db:ec:36:e5:55:03:82:a0:53:f1:9f:bb:06:b1:b2:3c:
+ cb:f5:b8:6d:f8:0d:b8:f3:00:b8:2d:84:0a:ca:ac:08:b9:0c:
+ 73:d9:5f:d9:87:97:8b:67:81:59:16:52:8a:f4:da:1c:94:5b:
+ 4b:4a:bf:01:7d:6e:1e:99:cf:fe:c3:93:79:ef:7a:d3:51:72:
+ 51:6d:cc:c3:60:25:f6:0a:ce:1b:de:3d:2a:82:3e:6c:ae:17:
+ 9a:ae:86:44:b6:7c:9d:41:ee:89:81:18:32:18:8b:46:42:7b:
+ 11:d2:03:71:93:d5:1e:3a:a5:90:d1:a3:45:16:a8:d5:37:63:
+ a7:89:01:6a:e6:1a:25:bb:68:e6:4c:13:ee:e3:3e:36:a7:33:
+ 8c:f3:b9:8d:fd:0d:db:73:e8:af:42:14:c7:bc:32:b7:2a:fd:
+ 9c:1d:fe:f0:2a:32:9d:35:6b:08:dc:06:81:ec:06:be:ad:56:
+ 77:6b:26:95:9d:09:ae:90:23:5d:50:30:1d:4a:67:70:80:88:
+ 72:ea:de:17:b4:03:35:0e:a7:36:b6:e2:aa:30:ba:1d:90:0e:
+ 1d:e6:9d:f0:f7:00:74:ee:39:09:3a:3e:e3:23:12:41:25:fc:
+ 9f:e6:8d:0c
+-----BEGIN CERTIFICATE-----
+MIIDozCCAougAwIBAgIBCjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMDcwOVoXDTA4MDgwOTAxMDcwOVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
+s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
+DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
+c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
+dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjgfAwge0wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQULYfBmvhYK73C+H4wR7OpiDfJ60YwDgYDVR0PAQH/
+BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjMuY2Vy
+MCEGCCsGAQUFBwEIAQH/BBIwEKAOMAwwCgIDAPwWAgMA/BwwDQYJKoZIhvcNAQEL
+BQADggEBACvkwNAz/XSCvHCyL+ldm56w+Pu+2+w25VUDgqBT8Z+7BrGyPMv1uG34
+DbjzALgthArKrAi5DHPZX9mHl4tngVkWUor02hyUW0tKvwF9bh6Zz/7Dk3nvetNR
+clFtzMNgJfYKzhvePSqCPmyuF5quhkS2fJ1B7omBGDIYi0ZCexHSA3GT1R46pZDR
+o0UWqNU3Y6eJAWrmGiW7aOZME+7jPjanM4zzuY39Ddtz6K9CFMe8Mrcq/Zwd/vAq
+Mp01awjcBoHsBr6tVndrJpWdCa6QI11QMB1KZ3CAiHLq3he0AzUOpza24qowuh2Q
+Dh3mnfD3AHTuOQk6PuMjEkEl/J/mjQw=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/0B.pem b/scripts/resource-cert-samples/LIR3/0B.pem
new file mode 100644
index 00000000..78d2f693
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/0B.pem
@@ -0,0 +1,91 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 11 (0xb)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:07:09 2007 GMT
+ Not After : Aug 9 01:07:09 2008 GMT
+ Subject: CN=TEST ENTITY ISP5b
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:bf:8f:59:d8:fc:fa:1d:04:70:29:ce:7b:01:64:
+ 21:40:dc:5c:43:fe:4c:af:88:c8:62:9b:be:9c:72:
+ 8f:8a:a5:34:8a:3b:23:8d:9b:8a:4f:bf:66:ac:68:
+ 71:9c:fd:68:59:f5:bf:9f:4d:2e:b5:d6:e3:fa:bd:
+ f3:60:53:5c:b7:11:ac:95:0b:c0:87:cd:99:9e:94:
+ 57:8d:ec:05:b8:df:aa:fc:8e:38:d3:0f:65:6d:09:
+ 60:f2:e1:98:81:72:d8:51:3e:41:91:b3:10:95:f5:
+ f5:d0:f9:e5:5c:a1:85:fa:71:26:85:e3:d1:4c:02:
+ 7f:14:e2:1e:4a:8a:96:68:9e:d6:16:a5:ef:ad:b5:
+ 83:62:cd:23:74:7c:82:56:b4:d1:34:53:5a:8a:7a:
+ 61:9f:ae:54:5b:ef:f9:56:de:87:6b:42:92:bc:49:
+ f4:b5:c3:35:07:4a:18:47:d2:92:c6:1c:16:74:74:
+ b1:e9:39:3c:53:12:05:9d:eb:dc:9c:72:2b:97:4d:
+ 27:21:77:96:7d:4c:ce:79:0c:fb:a7:b8:99:6b:66:
+ 20:2e:56:9c:44:b4:e3:5e:80:c4:7d:78:a1:b4:05:
+ f7:20:7d:26:1e:44:bf:5d:69:15:3c:7a:24:67:bd:
+ b9:b5:08:0f:33:4d:af:3b:2d:e7:b9:ab:1d:2b:d6:
+ fb:73
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 6C:B3:65:94:FE:C6:9F:4A:50:9D:4D:8B:40:1A:A1:FD:97:17:97:92
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 3f:f3:c1:ed:2e:d8:80:65:aa:b8:ea:d0:78:a9:fe:62:aa:70:
+ 6e:2e:af:19:8a:75:69:37:a0:d1:42:7e:da:c0:24:96:bc:00:
+ 7d:af:e9:a9:ab:c3:f1:e2:73:69:46:1c:61:83:ef:c9:7a:e3:
+ 75:4b:ca:93:91:9c:1f:c9:ab:2b:e5:71:f6:b2:06:55:eb:06:
+ b5:e4:89:76:44:c7:05:9e:b1:ee:7c:02:23:2e:6f:b0:ae:e8:
+ 80:ad:8f:de:20:e7:a8:6f:bf:8d:a5:6d:cf:c0:4a:c8:a0:24:
+ d1:65:34:29:58:87:eb:f1:4f:4b:bd:0a:ba:d0:e5:19:39:7b:
+ 8f:03:78:37:a6:fd:95:22:7d:be:ed:c6:af:90:e2:e3:bb:8a:
+ 74:73:93:2d:b8:76:ac:56:d8:a3:2b:d1:48:d6:51:46:32:72:
+ 7f:1d:b6:5b:ef:07:4f:f2:87:16:cd:8b:e5:f7:5a:c4:37:6f:
+ b7:dd:38:dc:c7:8b:21:91:46:b0:ba:76:3a:00:a8:fa:5d:24:
+ 80:56:14:d3:c3:8e:90:a8:4f:fa:de:79:91:9c:24:cc:aa:a1:
+ 85:b9:13:aa:88:12:f3:19:77:18:0e:62:a2:91:d9:fb:82:9e:
+ 13:83:b9:26:2e:cd:55:02:07:f4:53:35:f0:c4:e1:ec:99:ae:
+ 0f:ff:08:02
+-----BEGIN CERTIFICATE-----
+MIIDvTCCAqWgAwIBAgIBCzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMDcwOVoXDTA4MDgwOTAxMDcwOVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
+m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
+D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
+tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
+OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBRss2WU/safSlCdTYtAGqH9lxeXkjAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDViLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAwAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoDADANBgkqhkiG9w0BAQsFAAOCAQEAP/PB7S7YgGWquOrQeKn+
+Yqpwbi6vGYp1aTeg0UJ+2sAklrwAfa/pqavD8eJzaUYcYYPvyXrjdUvKk5GcH8mr
+K+Vx9rIGVesGteSJdkTHBZ6x7nwCIy5vsK7ogK2P3iDnqG+/jaVtz8BKyKAk0WU0
+KViH6/FPS70KutDlGTl7jwN4N6b9lSJ9vu3Gr5Di47uKdHOTLbh2rFbYoyvRSNZR
+RjJyfx22W+8HT/KHFs2L5fdaxDdvt9043MeLIZFGsLp2OgCo+l0kgFYU08OOkKhP
++t55kZwkzKqhhbkTqogS8xl3GA5iopHZ+4KeE4O5Ji7NVQIH9FM18MTh7JmuD/8I
+Ag==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/0C.pem b/scripts/resource-cert-samples/LIR3/0C.pem
new file mode 100644
index 00000000..e3a801b4
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/0C.pem
@@ -0,0 +1,91 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 12 (0xc)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:07:09 2007 GMT
+ Not After : Aug 9 01:07:09 2008 GMT
+ Subject: CN=TEST ENTITY ISP5a
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:e6:4b:ad:78:28:6b:e6:50:1b:65:81:d5:8d:2b:
+ 56:77:cd:bb:c9:47:a0:aa:32:b0:2c:ac:1f:f1:e4:
+ 90:2b:c2:33:6f:e7:53:b1:d0:1d:ab:05:27:9d:b7:
+ a1:ee:a8:4f:c8:5b:36:23:e3:12:e4:51:59:27:cd:
+ fd:7a:aa:dc:56:05:a1:73:ab:79:dd:3c:82:b2:8f:
+ ae:f9:ec:c0:36:38:e6:02:aa:fd:89:60:21:52:5b:
+ b6:33:80:75:e5:7f:fd:ac:6e:ec:d4:9a:26:2f:7e:
+ 28:45:16:29:47:7d:f3:8a:72:d5:e4:65:fa:f4:54:
+ 6f:ae:48:33:62:c1:32:f1:2b:83:33:36:63:60:9e:
+ bc:c7:e7:99:5d:51:da:cd:2f:8f:83:47:20:9e:e9:
+ cc:a3:72:c0:72:bd:49:2d:c4:52:ea:6f:da:42:46:
+ 71:90:c7:af:7f:9f:c7:dd:0b:96:96:3c:45:9f:c0:
+ ea:65:6a:43:e3:f3:92:d5:e1:73:c0:6e:20:f5:17:
+ e5:d1:58:da:21:b3:e9:0c:4d:f0:e8:bd:7c:b7:ef:
+ 81:c9:f5:70:cf:a8:20:7d:e2:6a:f9:1b:66:a9:c8:
+ 71:d6:32:f8:72:3d:83:99:19:0d:0c:6b:e9:f8:92:
+ cd:33:17:86:6a:3d:af:0d:05:94:ab:1c:d4:2c:a4:
+ 45:cb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 09:F0:14:0B:79:FB:0B:FF:A8:EF:54:B9:EC:3E:B9:8B:D0:CB:9C:EC
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 9c:79:5a:46:1a:3d:cc:72:7d:86:1f:86:4e:b9:13:a6:82:be:
+ 43:15:5b:dd:b0:1e:e0:f8:98:dc:5e:6b:b7:f4:05:45:36:29:
+ 73:1f:22:89:0a:7d:d9:7a:7c:b7:c0:31:f0:93:80:a0:66:68:
+ 72:15:4a:5a:09:9d:96:36:08:7c:78:ff:6f:81:ca:54:15:1f:
+ 57:4e:b2:b8:63:98:4d:12:20:6a:b1:91:ab:b0:a0:c0:dc:a6:
+ c2:03:88:58:e4:4d:2d:de:32:8f:1a:22:ef:c3:36:4c:ad:f6:
+ af:74:4f:2c:b2:55:3f:e2:0d:82:d1:d8:0d:c4:15:c9:3b:f4:
+ 9e:5c:de:47:62:e4:b5:59:6b:59:db:48:ca:46:10:af:2c:9c:
+ 31:c7:dc:50:bb:18:a7:ce:ec:50:f5:fb:90:55:4d:ff:3f:c1:
+ 6f:82:8f:0f:a3:00:00:fe:cf:5e:cf:48:59:15:de:36:37:ff:
+ c2:c8:bf:f8:82:39:52:eb:43:84:c4:d5:5f:de:e8:d8:56:58:
+ 7e:dd:82:a4:76:b8:31:42:45:cd:36:0b:52:87:4f:41:55:c4:
+ 42:4f:6b:2b:e5:57:1a:19:04:f9:70:d1:47:7a:ab:6e:94:91:
+ c8:d5:a4:17:01:56:ec:21:85:f9:03:1a:a8:6b:14:fc:a5:51:
+ cb:80:84:e3
+-----BEGIN CERTIFICATE-----
+MIIDvTCCAqWgAwIBAgIBDDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMDcwOVoXDTA4MDgwOTAxMDcwOVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
+0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
+YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
+nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
+akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQJ8BQLefsL/6jvVLnsPrmL0Muc7DAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDVhLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAAAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoAADANBgkqhkiG9w0BAQsFAAOCAQEAnHlaRho9zHJ9hh+GTrkT
+poK+QxVb3bAe4PiY3F5rt/QFRTYpcx8iiQp92Xp8t8Ax8JOAoGZochVKWgmdljYI
+fHj/b4HKVBUfV06yuGOYTRIgarGRq7CgwNymwgOIWORNLd4yjxoi78M2TK32r3RP
+LLJVP+INgtHYDcQVyTv0nlzeR2LktVlrWdtIykYQryycMcfcULsYp87sUPX7kFVN
+/z/Bb4KPD6MAAP7PXs9IWRXeNjf/wsi/+II5UutDhMTVX97o2FZYft2CpHa4MUJF
+zTYLUodPQVXEQk9rK+VXGhkE+XDRR3qrbpSRyNWkFwFW7CGF+QMaqGsU/KVRy4CE
+4w==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/0D.pem b/scripts/resource-cert-samples/LIR3/0D.pem
new file mode 100644
index 00000000..6634de32
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/0D.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 13 (0xd)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY ISP5c
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:c8:8b:a1:25:65:df:ee:a2:7f:54:af:52:0a:1a:
+ 1a:fa:0d:75:b3:3c:e9:e0:29:d3:89:20:e9:51:49:
+ 67:2c:43:da:a0:2c:d4:44:b3:96:14:a9:07:77:60:
+ b9:6f:01:ef:8e:54:a5:74:ac:5a:67:f8:30:4d:10:
+ f9:ac:9f:b8:75:61:0b:f6:e7:7c:ea:9b:5c:98:7a:
+ 4b:3e:c4:e2:59:42:d3:19:ca:0f:58:0e:b7:c8:82:
+ 4e:e5:bb:ac:fd:92:e5:88:b2:fc:64:cf:6e:38:3b:
+ 18:83:fc:e7:a6:ae:fb:90:36:d0:e1:ca:4d:90:41:
+ 0f:0f:3b:2a:c0:0c:d9:7b:7d:e8:50:13:f6:09:73:
+ 82:a3:d2:e3:bb:82:08:87:7f:d2:bb:0e:0e:7a:28:
+ b6:25:02:b5:d9:51:fc:33:32:47:47:ff:cf:7f:bc:
+ ee:00:01:bb:05:5e:2e:03:9a:ad:95:3b:ca:c2:c6:
+ 87:64:74:39:aa:59:6b:ae:e0:a7:51:1a:07:f2:8e:
+ 4c:8e:65:2f:df:f2:99:ba:e0:b6:8a:4f:c0:20:72:
+ 79:98:00:8f:0d:50:13:3d:d1:3e:8c:bd:dc:74:a9:
+ 33:a8:56:1d:31:78:7c:e7:02:9e:8d:0a:14:12:6d:
+ d3:37:c7:7a:f0:84:10:fe:fe:4d:28:97:26:6e:08:
+ 85:a1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 1f:7e:d1:95:bc:b5:52:1b:fc:3f:0b:29:18:d2:72:db:70:8b:
+ 00:7b:9a:d0:1e:f1:cc:bc:c7:7b:bf:eb:0f:01:13:8f:d4:29:
+ 5b:53:46:7b:d3:cb:72:a9:7b:98:ca:25:d3:8a:72:d2:f5:53:
+ 67:c6:e1:59:7b:1a:6b:92:37:fd:ce:98:12:5c:ae:f2:37:c4:
+ 41:7c:30:5d:19:54:9d:d2:ad:59:a2:df:b5:4a:d8:fb:ca:06:
+ bf:fb:2a:a5:85:64:d2:80:ab:d2:67:4e:a5:fa:92:cb:70:14:
+ 62:5d:ac:bf:1e:13:1f:7e:51:e7:56:08:7e:f7:6a:ae:d1:a2:
+ 14:d2:e7:e3:c7:aa:c6:29:65:66:f1:71:7f:59:8a:20:ba:01:
+ a4:12:c1:53:01:b4:c3:7c:fe:50:df:d9:7c:61:6f:e1:5d:54:
+ e4:1f:91:9c:80:ce:c9:e6:e9:c6:1c:8e:60:c2:dd:bf:72:6f:
+ 32:cb:37:fb:4b:b8:c3:46:16:53:ee:74:40:d4:f3:78:8a:1e:
+ e1:2d:2b:2b:fa:16:ea:f5:e3:85:10:57:43:68:33:54:cc:4d:
+ a7:16:ad:ce:79:da:dc:28:94:1d:54:36:2b:6a:37:9e:b0:85:
+ 44:9d:5c:f4:97:25:b0:3a:42:cf:c6:d0:c2:7c:f1:fc:81:53:
+ 0b:b7:b4:71
+-----BEGIN CERTIFICATE-----
+MIIDGTCCAgGgAwIBAgIBDTANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTMzOVoXDTA4MDgwOTAxMTMzOVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
+s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
+DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
+c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
+dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjZzBlMA8GA1UdEwEB/wQF
+MAMBAf8wDgYDVR0PAQH/BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcw
+BYYmcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yy8wDQYJKoZI
+hvcNAQELBQADggEBAB9+0ZW8tVIb/D8LKRjScttwiwB7mtAe8cy8x3u/6w8BE4/U
+KVtTRnvTy3Kpe5jKJdOKctL1U2fG4Vl7GmuSN/3OmBJcrvI3xEF8MF0ZVJ3SrVmi
+37VK2PvKBr/7KqWFZNKAq9JnTqX6kstwFGJdrL8eEx9+UedWCH73aq7RohTS5+PH
+qsYpZWbxcX9ZiiC6AaQSwVMBtMN8/lDf2Xxhb+FdVOQfkZyAzsnm6cYcjmDC3b9y
+bzLLN/tLuMNGFlPudEDU83iKHuEtKyv6Fur144UQV0NoM1TMTacWrc552twolB1U
+NitqN56whUSdXPSXJbA6Qs/G0MJ88fyBUwu3tHE=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/0E.pem b/scripts/resource-cert-samples/LIR3/0E.pem
new file mode 100644
index 00000000..a6a893b1
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/0E.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 14 (0xe)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY ISP5b
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:bf:8f:59:d8:fc:fa:1d:04:70:29:ce:7b:01:64:
+ 21:40:dc:5c:43:fe:4c:af:88:c8:62:9b:be:9c:72:
+ 8f:8a:a5:34:8a:3b:23:8d:9b:8a:4f:bf:66:ac:68:
+ 71:9c:fd:68:59:f5:bf:9f:4d:2e:b5:d6:e3:fa:bd:
+ f3:60:53:5c:b7:11:ac:95:0b:c0:87:cd:99:9e:94:
+ 57:8d:ec:05:b8:df:aa:fc:8e:38:d3:0f:65:6d:09:
+ 60:f2:e1:98:81:72:d8:51:3e:41:91:b3:10:95:f5:
+ f5:d0:f9:e5:5c:a1:85:fa:71:26:85:e3:d1:4c:02:
+ 7f:14:e2:1e:4a:8a:96:68:9e:d6:16:a5:ef:ad:b5:
+ 83:62:cd:23:74:7c:82:56:b4:d1:34:53:5a:8a:7a:
+ 61:9f:ae:54:5b:ef:f9:56:de:87:6b:42:92:bc:49:
+ f4:b5:c3:35:07:4a:18:47:d2:92:c6:1c:16:74:74:
+ b1:e9:39:3c:53:12:05:9d:eb:dc:9c:72:2b:97:4d:
+ 27:21:77:96:7d:4c:ce:79:0c:fb:a7:b8:99:6b:66:
+ 20:2e:56:9c:44:b4:e3:5e:80:c4:7d:78:a1:b4:05:
+ f7:20:7d:26:1e:44:bf:5d:69:15:3c:7a:24:67:bd:
+ b9:b5:08:0f:33:4d:af:3b:2d:e7:b9:ab:1d:2b:d6:
+ fb:73
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 96:34:8a:58:26:99:07:8d:0c:24:fe:84:fb:00:19:d6:cc:64:
+ 39:28:1b:33:69:82:b7:1f:3b:0c:ae:96:94:d6:fa:a3:00:2c:
+ 7e:f7:68:60:e3:11:98:5c:86:1e:7b:47:44:0d:b0:e7:62:60:
+ ec:57:d6:ea:64:7c:66:45:57:5e:c9:b3:c3:54:9a:18:59:7d:
+ d4:2e:5e:30:cd:a8:41:51:21:83:ad:b2:b1:27:4d:a1:e7:72:
+ 25:43:f3:34:50:5a:dd:67:4e:72:ba:fa:5a:6d:c9:aa:01:67:
+ b5:71:4a:28:ee:1e:e7:5f:27:59:11:be:ee:25:f3:a5:b2:2e:
+ 8f:9a:6d:19:54:17:0b:97:a9:4a:49:bf:c3:44:3e:73:7d:93:
+ 03:f6:e2:a1:b1:7c:0a:a5:62:b5:5c:9e:9c:c7:f1:3f:ce:f3:
+ 35:2b:47:30:e6:f4:a4:b3:27:9e:37:08:1f:da:d5:ac:19:e8:
+ ba:72:ab:85:fe:c1:c9:d2:cc:75:f2:62:bc:37:21:ff:0f:df:
+ 8f:7f:6e:07:c6:8f:84:80:16:4a:1d:a3:fe:28:78:ba:10:9a:
+ ad:ef:03:f9:0a:c0:b9:fe:20:f7:6d:49:30:c0:26:e3:63:8d:
+ f3:6d:88:6a:b3:74:28:a2:a3:5c:2e:4e:2c:1f:46:d3:4a:c5:
+ b1:6f:aa:06
+-----BEGIN CERTIFICATE-----
+MIIDGTCCAgGgAwIBAgIBDjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTMzOVoXDTA4MDgwOTAxMTMzOVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
+m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
+D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
+tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
+OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjZzBlMA8GA1UdEwEB/wQF
+MAMBAf8wDgYDVR0PAQH/BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcw
+BYYmcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yi8wDQYJKoZI
+hvcNAQELBQADggEBAJY0ilgmmQeNDCT+hPsAGdbMZDkoGzNpgrcfOwyulpTW+qMA
+LH73aGDjEZhchh57R0QNsOdiYOxX1upkfGZFV17Js8NUmhhZfdQuXjDNqEFRIYOt
+srEnTaHnciVD8zRQWt1nTnK6+lptyaoBZ7VxSijuHudfJ1kRvu4l86WyLo+abRlU
+FwuXqUpJv8NEPnN9kwP24qGxfAqlYrVcnpzH8T/O8zUrRzDm9KSzJ543CB/a1awZ
+6Lpyq4X+wcnSzHXyYrw3If8P349/bgfGj4SAFkodo/4oeLoQmq3vA/kKwLn+IPdt
+STDAJuNjjfNtiGqzdCiio1wuTiwfRtNKxbFvqgY=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/0F.pem b/scripts/resource-cert-samples/LIR3/0F.pem
new file mode 100644
index 00000000..cca0bb04
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/0F.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 15 (0xf)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY ISP5a
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:e6:4b:ad:78:28:6b:e6:50:1b:65:81:d5:8d:2b:
+ 56:77:cd:bb:c9:47:a0:aa:32:b0:2c:ac:1f:f1:e4:
+ 90:2b:c2:33:6f:e7:53:b1:d0:1d:ab:05:27:9d:b7:
+ a1:ee:a8:4f:c8:5b:36:23:e3:12:e4:51:59:27:cd:
+ fd:7a:aa:dc:56:05:a1:73:ab:79:dd:3c:82:b2:8f:
+ ae:f9:ec:c0:36:38:e6:02:aa:fd:89:60:21:52:5b:
+ b6:33:80:75:e5:7f:fd:ac:6e:ec:d4:9a:26:2f:7e:
+ 28:45:16:29:47:7d:f3:8a:72:d5:e4:65:fa:f4:54:
+ 6f:ae:48:33:62:c1:32:f1:2b:83:33:36:63:60:9e:
+ bc:c7:e7:99:5d:51:da:cd:2f:8f:83:47:20:9e:e9:
+ cc:a3:72:c0:72:bd:49:2d:c4:52:ea:6f:da:42:46:
+ 71:90:c7:af:7f:9f:c7:dd:0b:96:96:3c:45:9f:c0:
+ ea:65:6a:43:e3:f3:92:d5:e1:73:c0:6e:20:f5:17:
+ e5:d1:58:da:21:b3:e9:0c:4d:f0:e8:bd:7c:b7:ef:
+ 81:c9:f5:70:cf:a8:20:7d:e2:6a:f9:1b:66:a9:c8:
+ 71:d6:32:f8:72:3d:83:99:19:0d:0c:6b:e9:f8:92:
+ cd:33:17:86:6a:3d:af:0d:05:94:ab:1c:d4:2c:a4:
+ 45:cb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 71:9a:80:f3:ba:b7:60:6f:6c:f5:31:18:c9:e3:45:61:0a:93:
+ d9:c3:23:35:dc:11:da:cf:b4:c7:d5:36:cd:48:a7:63:c2:e9:
+ 44:3c:56:c1:60:e1:7a:ab:b1:03:32:22:c7:8d:d8:24:a9:e4:
+ 70:e9:d2:fd:7b:e6:20:2c:9d:ed:71:d2:9e:30:a0:f0:b2:67:
+ 87:87:f7:d5:96:da:67:d4:8a:e2:aa:f2:e8:2f:b2:cd:d7:92:
+ ed:9f:44:7f:f9:3d:f8:5d:c6:44:ef:a0:d3:98:41:ce:5b:c7:
+ c3:b1:bb:fc:08:ec:b4:4e:0c:4d:8e:30:63:f9:06:50:a3:b1:
+ 48:6e:c0:5b:ed:9a:7c:0e:ec:32:2e:c2:9e:12:28:94:9d:ed:
+ 3c:99:4c:74:73:6b:ec:58:41:b3:f9:58:fb:2c:31:00:7d:20:
+ 13:07:63:3e:a4:ca:59:95:37:3f:cf:b0:ae:6a:15:5a:09:8c:
+ 4b:77:c4:78:76:73:90:98:c6:2a:97:70:e1:c0:90:24:c0:3c:
+ a5:99:3f:74:d0:a2:e5:f5:d3:dc:52:35:71:7a:bd:48:38:a9:
+ 66:a7:42:28:ae:93:82:f3:1a:99:be:52:69:d4:f9:d1:15:4d:
+ 3f:2f:65:c6:9f:9f:73:00:59:f5:45:75:1f:35:06:e9:4a:b7:
+ b5:77:9a:bf
+-----BEGIN CERTIFICATE-----
+MIIDGTCCAgGgAwIBAgIBDzANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTMzOVoXDTA4MDgwOTAxMTMzOVowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
+0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
+YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
+nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
+akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjZzBlMA8GA1UdEwEB/wQF
+MAMBAf8wDgYDVR0PAQH/BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcw
+BYYmcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1YS8wDQYJKoZI
+hvcNAQELBQADggEBAHGagPO6t2BvbPUxGMnjRWEKk9nDIzXcEdrPtMfVNs1Ip2PC
+6UQ8VsFg4XqrsQMyIseN2CSp5HDp0v175iAsne1x0p4woPCyZ4eH99WW2mfUiuKq
+8ugvss3Xku2fRH/5PfhdxkTvoNOYQc5bx8Oxu/wI7LRODE2OMGP5BlCjsUhuwFvt
+mnwO7DIuwp4SKJSd7TyZTHRza+xYQbP5WPssMQB9IBMHYz6kylmVNz/PsK5qFVoJ
+jEt3xHh2c5CYxiqXcOHAkCTAPKWZP3TQouX109xSNXF6vUg4qWanQiiuk4LzGpm+
+UmnU+dEVTT8vZcafn3MAWfVFdR81BulKt7V3mr8=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/10.pem b/scripts/resource-cert-samples/LIR3/10.pem
new file mode 100644
index 00000000..16656abb
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/10.pem
@@ -0,0 +1,88 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 16 (0x10)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY ISP5c
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:c8:8b:a1:25:65:df:ee:a2:7f:54:af:52:0a:1a:
+ 1a:fa:0d:75:b3:3c:e9:e0:29:d3:89:20:e9:51:49:
+ 67:2c:43:da:a0:2c:d4:44:b3:96:14:a9:07:77:60:
+ b9:6f:01:ef:8e:54:a5:74:ac:5a:67:f8:30:4d:10:
+ f9:ac:9f:b8:75:61:0b:f6:e7:7c:ea:9b:5c:98:7a:
+ 4b:3e:c4:e2:59:42:d3:19:ca:0f:58:0e:b7:c8:82:
+ 4e:e5:bb:ac:fd:92:e5:88:b2:fc:64:cf:6e:38:3b:
+ 18:83:fc:e7:a6:ae:fb:90:36:d0:e1:ca:4d:90:41:
+ 0f:0f:3b:2a:c0:0c:d9:7b:7d:e8:50:13:f6:09:73:
+ 82:a3:d2:e3:bb:82:08:87:7f:d2:bb:0e:0e:7a:28:
+ b6:25:02:b5:d9:51:fc:33:32:47:47:ff:cf:7f:bc:
+ ee:00:01:bb:05:5e:2e:03:9a:ad:95:3b:ca:c2:c6:
+ 87:64:74:39:aa:59:6b:ae:e0:a7:51:1a:07:f2:8e:
+ 4c:8e:65:2f:df:f2:99:ba:e0:b6:8a:4f:c0:20:72:
+ 79:98:00:8f:0d:50:13:3d:d1:3e:8c:bd:dc:74:a9:
+ 33:a8:56:1d:31:78:7c:e7:02:9e:8d:0a:14:12:6d:
+ d3:37:c7:7a:f0:84:10:fe:fe:4d:28:97:26:6e:08:
+ 85:a1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 2D:87:C1:9A:F8:58:2B:BD:C2:F8:7E:30:47:B3:A9:88:37:C9:EB:46
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 67:a7:55:49:7b:68:d4:dd:67:16:e5:09:f3:ac:fb:1b:ea:83:
+ 58:e4:ba:4f:a4:2f:88:af:1e:05:da:46:b5:85:1a:14:87:c1:
+ 34:74:2d:35:4f:3d:2e:63:9a:cc:ac:28:8d:e5:61:a0:a5:73:
+ f5:25:c0:1b:11:27:b6:dc:4c:41:81:f4:d6:0d:f1:8a:af:69:
+ ae:32:23:d0:4a:fe:1d:d2:c6:ef:87:f5:93:01:42:c5:54:4d:
+ ce:73:d5:19:c7:c9:e6:1d:4c:2f:92:28:03:b2:cd:c5:a6:f6:
+ 6b:b1:bf:7c:1d:71:38:ac:85:93:c8:c2:a4:73:06:4b:f4:ff:
+ 5e:44:e0:57:9a:7e:f5:5f:4c:7d:6f:b6:6a:30:27:5e:ff:7d:
+ 8d:49:04:34:05:1a:87:2e:36:c3:aa:13:b1:91:f0:57:ad:a7:
+ 9e:d3:be:fa:de:af:db:42:f6:bd:06:04:2e:71:e0:5e:82:4a:
+ 4f:dd:57:0f:29:ca:09:db:a8:e4:fd:82:5d:ff:55:24:a4:9a:
+ 64:26:d0:02:1f:f2:4d:92:28:9b:1d:bb:f6:6f:2a:d3:25:48:
+ 87:04:96:37:9f:90:7c:15:6d:c7:18:ef:a7:6b:0e:b1:37:6c:
+ ae:69:7e:49:81:8c:de:b9:f7:34:ee:6d:48:26:92:7f:8f:0c:
+ 95:7d:08:eb
+-----BEGIN CERTIFICATE-----
+MIIDozCCAougAwIBAgIBEDANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
+s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
+DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
+c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
+dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjgfAwge0wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQULYfBmvhYK73C+H4wR7OpiDfJ60YwDgYDVR0PAQH/
+BAQDAgEGMEIGCCsGAQUFBwELBDYwNDAyBggrBgEFBQcwBYYmcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9JU1A1Yy8wRAYIKwYBBQUHAQEEODA2MDQGCCsG
+AQUFBzAChihyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjMuY2Vy
+MCEGCCsGAQUFBwEIAQH/BBIwEKAOMAwwCgIDAPwWAgMA/BwwDQYJKoZIhvcNAQEL
+BQADggEBAGenVUl7aNTdZxblCfOs+xvqg1jkuk+kL4ivHgXaRrWFGhSHwTR0LTVP
+PS5jmsysKI3lYaClc/UlwBsRJ7bcTEGB9NYN8Yqvaa4yI9BK/h3Sxu+H9ZMBQsVU
+Tc5z1RnHyeYdTC+SKAOyzcWm9muxv3wdcTishZPIwqRzBkv0/15E4FeafvVfTH1v
+tmowJ17/fY1JBDQFGocuNsOqE7GR8Fetp57Tvvrer9tC9r0GBC5x4F6CSk/dVw8p
+ygnbqOT9gl3/VSSkmmQm0AIf8k2SKJsdu/ZvKtMlSIcEljefkHwVbccY76drDrE3
+bK5pfkmBjN659zTubUgmkn+PDJV9COs=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/11.pem b/scripts/resource-cert-samples/LIR3/11.pem
new file mode 100644
index 00000000..7342b3c4
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/11.pem
@@ -0,0 +1,91 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 17 (0x11)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY ISP5b
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:bf:8f:59:d8:fc:fa:1d:04:70:29:ce:7b:01:64:
+ 21:40:dc:5c:43:fe:4c:af:88:c8:62:9b:be:9c:72:
+ 8f:8a:a5:34:8a:3b:23:8d:9b:8a:4f:bf:66:ac:68:
+ 71:9c:fd:68:59:f5:bf:9f:4d:2e:b5:d6:e3:fa:bd:
+ f3:60:53:5c:b7:11:ac:95:0b:c0:87:cd:99:9e:94:
+ 57:8d:ec:05:b8:df:aa:fc:8e:38:d3:0f:65:6d:09:
+ 60:f2:e1:98:81:72:d8:51:3e:41:91:b3:10:95:f5:
+ f5:d0:f9:e5:5c:a1:85:fa:71:26:85:e3:d1:4c:02:
+ 7f:14:e2:1e:4a:8a:96:68:9e:d6:16:a5:ef:ad:b5:
+ 83:62:cd:23:74:7c:82:56:b4:d1:34:53:5a:8a:7a:
+ 61:9f:ae:54:5b:ef:f9:56:de:87:6b:42:92:bc:49:
+ f4:b5:c3:35:07:4a:18:47:d2:92:c6:1c:16:74:74:
+ b1:e9:39:3c:53:12:05:9d:eb:dc:9c:72:2b:97:4d:
+ 27:21:77:96:7d:4c:ce:79:0c:fb:a7:b8:99:6b:66:
+ 20:2e:56:9c:44:b4:e3:5e:80:c4:7d:78:a1:b4:05:
+ f7:20:7d:26:1e:44:bf:5d:69:15:3c:7a:24:67:bd:
+ b9:b5:08:0f:33:4d:af:3b:2d:e7:b9:ab:1d:2b:d6:
+ fb:73
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 6C:B3:65:94:FE:C6:9F:4A:50:9D:4D:8B:40:1A:A1:FD:97:17:97:92
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 76:a6:64:04:5d:a3:16:7a:fe:0a:e7:44:c0:de:82:1c:c8:06:
+ a3:08:2b:4a:fb:44:99:79:dc:52:c8:8c:af:6f:17:24:9a:08:
+ 29:37:e2:ae:e7:39:cf:7e:ef:53:d1:82:87:1d:f8:a3:5c:ee:
+ db:a8:dc:6f:7b:78:9f:29:6b:c7:1c:98:28:e0:e3:e5:35:bb:
+ 87:46:fd:14:c1:d2:b7:92:6f:9d:d0:74:8a:54:30:97:ef:b5:
+ d3:4f:18:10:fc:ec:21:3f:76:08:7d:e9:ac:c5:5d:a7:b7:e8:
+ 4d:24:00:fa:e6:2b:82:b9:65:5f:b6:a3:7f:8c:bf:5d:9e:1b:
+ 9c:61:66:a3:37:db:59:d1:c4:eb:c3:06:3a:1b:2a:a1:a8:21:
+ 05:77:ab:bc:36:ef:08:7e:40:87:e3:c7:4c:eb:0c:5a:2a:03:
+ f8:26:b6:30:a8:04:a4:af:ad:63:e3:5c:19:7f:a9:50:30:e8:
+ f7:cc:fb:ef:ee:ba:90:e0:1b:24:dd:aa:dc:d9:90:11:5e:cb:
+ 3f:3a:d8:fd:c0:80:6b:1e:c2:eb:bb:70:57:b4:54:78:a2:12:
+ eb:6f:cd:5f:65:c3:3d:cf:62:0c:18:02:f1:8f:6e:04:30:25:
+ 82:15:6e:25:0f:3c:09:5e:e6:49:cd:73:e5:68:a9:82:3c:93:
+ 22:47:07:4f
+-----BEGIN CERTIFICATE-----
+MIIDvTCCAqWgAwIBAgIBETANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
+m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
+D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
+tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
+OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBRss2WU/safSlCdTYtAGqH9lxeXkjAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDViLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAwAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoDADANBgkqhkiG9w0BAQsFAAOCAQEAdqZkBF2jFnr+CudEwN6C
+HMgGowgrSvtEmXncUsiMr28XJJoIKTfiruc5z37vU9GChx34o1zu26jcb3t4nylr
+xxyYKODj5TW7h0b9FMHSt5JvndB0ilQwl++1008YEPzsIT92CH3prMVdp7foTSQA
++uYrgrllX7ajf4y/XZ4bnGFmozfbWdHE68MGOhsqoaghBXervDbvCH5Ah+PHTOsM
+WioD+Ca2MKgEpK+tY+NcGX+pUDDo98z77+66kOAbJN2q3NmQEV7LPzrY/cCAax7C
+67twV7RUeKIS62/NX2XDPc9iDBgC8Y9uBDAlghVuJQ88CV7mSc1z5WipgjyTIkcH
+Tw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/12.pem b/scripts/resource-cert-samples/LIR3/12.pem
new file mode 100644
index 00000000..2ca7eef4
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/12.pem
@@ -0,0 +1,91 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 18 (0x12)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY ISP5a
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:e6:4b:ad:78:28:6b:e6:50:1b:65:81:d5:8d:2b:
+ 56:77:cd:bb:c9:47:a0:aa:32:b0:2c:ac:1f:f1:e4:
+ 90:2b:c2:33:6f:e7:53:b1:d0:1d:ab:05:27:9d:b7:
+ a1:ee:a8:4f:c8:5b:36:23:e3:12:e4:51:59:27:cd:
+ fd:7a:aa:dc:56:05:a1:73:ab:79:dd:3c:82:b2:8f:
+ ae:f9:ec:c0:36:38:e6:02:aa:fd:89:60:21:52:5b:
+ b6:33:80:75:e5:7f:fd:ac:6e:ec:d4:9a:26:2f:7e:
+ 28:45:16:29:47:7d:f3:8a:72:d5:e4:65:fa:f4:54:
+ 6f:ae:48:33:62:c1:32:f1:2b:83:33:36:63:60:9e:
+ bc:c7:e7:99:5d:51:da:cd:2f:8f:83:47:20:9e:e9:
+ cc:a3:72:c0:72:bd:49:2d:c4:52:ea:6f:da:42:46:
+ 71:90:c7:af:7f:9f:c7:dd:0b:96:96:3c:45:9f:c0:
+ ea:65:6a:43:e3:f3:92:d5:e1:73:c0:6e:20:f5:17:
+ e5:d1:58:da:21:b3:e9:0c:4d:f0:e8:bd:7c:b7:ef:
+ 81:c9:f5:70:cf:a8:20:7d:e2:6a:f9:1b:66:a9:c8:
+ 71:d6:32:f8:72:3d:83:99:19:0d:0c:6b:e9:f8:92:
+ cd:33:17:86:6a:3d:af:0d:05:94:ab:1c:d4:2c:a4:
+ 45:cb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 09:F0:14:0B:79:FB:0B:FF:A8:EF:54:B9:EC:3E:B9:8B:D0:CB:9C:EC
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 36:9d:84:eb:95:7f:1e:45:82:16:54:14:e6:50:f9:61:6f:a2:
+ 16:01:57:9c:f6:c3:00:d7:00:8f:a4:af:12:c7:71:f9:ac:e7:
+ f5:57:5e:8a:92:6e:00:08:d4:b1:2e:bf:07:cc:e8:f9:05:97:
+ 21:fe:00:12:ab:33:ad:77:3d:01:54:be:c7:57:1d:b6:ba:e8:
+ 71:56:35:71:67:10:5f:78:67:92:d9:b2:3f:26:12:78:e2:5b:
+ 24:ed:b3:45:95:d7:6c:c3:0a:c9:7c:e7:db:e3:e9:90:24:cb:
+ a1:a0:3e:05:7f:8d:4e:bc:a5:39:c6:b1:ac:29:21:28:9f:d4:
+ 58:3f:cd:07:d0:81:fd:d4:e2:b8:cc:ef:b1:75:cb:eb:73:30:
+ f8:84:7a:bb:42:bf:bf:23:4e:e9:34:1e:c0:49:ea:ed:9a:62:
+ 70:f8:79:08:4b:b1:80:a1:da:a6:c5:3e:78:20:5e:10:da:81:
+ 29:8f:ff:6d:0e:d8:91:be:ee:2e:f7:c0:cc:87:88:45:3f:73:
+ 63:ba:a0:66:73:94:6c:79:aa:f4:ec:85:62:32:2b:aa:f2:0d:
+ a5:66:42:f4:ca:83:8b:b5:73:a5:78:2f:0e:bc:87:e4:ec:1a:
+ 2b:c3:83:55:8e:35:65:39:62:41:86:74:d5:2a:a5:c6:05:03:
+ 0a:e2:ea:76
+-----BEGIN CERTIFICATE-----
+MIIDvTCCAqWgAwIBAgIBEjANBgkqhkiG9w0BAQsFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgxMDAxMTUxMFoXDTA4MDgwOTAxMTUxMFowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
+0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
+YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
+nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
+akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjggEJMIIBBTAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQJ8BQLefsL/6jvVLnsPrmL0Muc7DAOBgNVHQ8B
+Af8EBAMCAQYwQgYIKwYBBQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dv
+bWJhdHMtci11cy5oYWN0cm4ubmV0L0lTUDVhLzBEBggrBgEFBQcBAQQ4MDYwNAYI
+KwYBBQUHMAKGKHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5j
+ZXIwOQYIKwYBBQUHAQcBAf8EKjAoMAwEAgABMAYDBAAKAAAwGAQCAAIwEgMQACAB
+DbgAAAAAAAAAAAoAADANBgkqhkiG9w0BAQsFAAOCAQEANp2E65V/HkWCFlQU5lD5
+YW+iFgFXnPbDANcAj6SvEsdx+azn9VdeipJuAAjUsS6/B8zo+QWXIf4AEqszrXc9
+AVS+x1cdtrrocVY1cWcQX3hnktmyPyYSeOJbJO2zRZXXbMMKyXzn2+PpkCTLoaA+
+BX+NTrylOcaxrCkhKJ/UWD/NB9CB/dTiuMzvsXXL63Mw+IR6u0K/vyNO6TQewEnq
+7ZpicPh5CEuxgKHapsU+eCBeENqBKY//bQ7Ykb7uLvfAzIeIRT9zY7qgZnOUbHmq
+9OyFYjIrqvINpWZC9MqDi7VzpXgvDryH5OwaK8ODVY41ZTliQYZ01SqlxgUDCuLq
+dg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/index b/scripts/resource-cert-samples/LIR3/index
index eb62d129..77e096e4 100644
--- a/scripts/resource-cert-samples/LIR3/index
+++ b/scripts/resource-cert-samples/LIR3/index
@@ -1,3 +1,18 @@
V 080731144818Z 01 unknown /CN=TEST ENTITY ISP5c
V 080731144820Z 02 unknown /CN=TEST ENTITY ISP5b
V 080731144822Z 03 unknown /CN=TEST ENTITY ISP5a
+V 080809005817Z 04 unknown /CN=TEST ENTITY ISP5c
+V 080809005817Z 05 unknown /CN=TEST ENTITY ISP5b
+V 080809005817Z 06 unknown /CN=TEST ENTITY ISP5a
+V 080809010231Z 07 unknown /CN=TEST ENTITY ISP5c
+V 080809010231Z 08 unknown /CN=TEST ENTITY ISP5b
+V 080809010231Z 09 unknown /CN=TEST ENTITY ISP5a
+V 080809010709Z 0A unknown /CN=TEST ENTITY ISP5c
+V 080809010709Z 0B unknown /CN=TEST ENTITY ISP5b
+V 080809010709Z 0C unknown /CN=TEST ENTITY ISP5a
+V 080809011339Z 0D unknown /CN=TEST ENTITY ISP5c
+V 080809011339Z 0E unknown /CN=TEST ENTITY ISP5b
+V 080809011339Z 0F unknown /CN=TEST ENTITY ISP5a
+V 080809011510Z 10 unknown /CN=TEST ENTITY ISP5c
+V 080809011510Z 11 unknown /CN=TEST ENTITY ISP5b
+V 080809011510Z 12 unknown /CN=TEST ENTITY ISP5a
diff --git a/scripts/resource-cert-samples/LIR3/index.old b/scripts/resource-cert-samples/LIR3/index.old
index 162abf18..3919af53 100644
--- a/scripts/resource-cert-samples/LIR3/index.old
+++ b/scripts/resource-cert-samples/LIR3/index.old
@@ -1,2 +1,17 @@
V 080731144818Z 01 unknown /CN=TEST ENTITY ISP5c
V 080731144820Z 02 unknown /CN=TEST ENTITY ISP5b
+V 080731144822Z 03 unknown /CN=TEST ENTITY ISP5a
+V 080809005817Z 04 unknown /CN=TEST ENTITY ISP5c
+V 080809005817Z 05 unknown /CN=TEST ENTITY ISP5b
+V 080809005817Z 06 unknown /CN=TEST ENTITY ISP5a
+V 080809010231Z 07 unknown /CN=TEST ENTITY ISP5c
+V 080809010231Z 08 unknown /CN=TEST ENTITY ISP5b
+V 080809010231Z 09 unknown /CN=TEST ENTITY ISP5a
+V 080809010709Z 0A unknown /CN=TEST ENTITY ISP5c
+V 080809010709Z 0B unknown /CN=TEST ENTITY ISP5b
+V 080809010709Z 0C unknown /CN=TEST ENTITY ISP5a
+V 080809011339Z 0D unknown /CN=TEST ENTITY ISP5c
+V 080809011339Z 0E unknown /CN=TEST ENTITY ISP5b
+V 080809011339Z 0F unknown /CN=TEST ENTITY ISP5a
+V 080809011510Z 10 unknown /CN=TEST ENTITY ISP5c
+V 080809011510Z 11 unknown /CN=TEST ENTITY ISP5b
diff --git a/scripts/resource-cert-samples/LIR3/serial b/scripts/resource-cert-samples/LIR3/serial
index 64969239..b1bd38b6 100644
--- a/scripts/resource-cert-samples/LIR3/serial
+++ b/scripts/resource-cert-samples/LIR3/serial
@@ -1 +1 @@
-04
+13
diff --git a/scripts/resource-cert-samples/LIR3/serial.old b/scripts/resource-cert-samples/LIR3/serial.old
index 75016ea3..48082f72 100644
--- a/scripts/resource-cert-samples/LIR3/serial.old
+++ b/scripts/resource-cert-samples/LIR3/serial.old
@@ -1 +1 @@
-03
+12
diff --git a/scripts/resource-cert-samples/Makefile b/scripts/resource-cert-samples/Makefile
index 651cc8ff..f2e74a25 100644
--- a/scripts/resource-cert-samples/Makefile
+++ b/scripts/resource-cert-samples/Makefile
@@ -12,9 +12,15 @@ RIR.cer: RIR.req RIR.cnf RIR.key Makefile
@test -d RIR || mkdir RIR
@test -f RIR/index || touch RIR/index
@test -f RIR/serial || echo 01 >RIR/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in RIR.req -extensions req_x509_ext -extfile RIR.cnf -config RIR.cnf -selfsign
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in RIR.req -extfile RIR.cnf -config RIR.cnf -selfsign
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in RIR.req -config /dev/null
+
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in RIR.cer
+
all:: LIR3.cer
LIR3.key:
@@ -27,8 +33,14 @@ LIR3.cer: LIR3.req LIR3.cnf RIR.key Makefile
@test -d LIR3 || mkdir LIR3
@test -f LIR3/index || touch LIR3/index
@test -f LIR3/serial || echo 01 >LIR3/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR3.req -extensions req_x509_ext -extfile LIR3.cnf -config RIR.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR3.req -extfile LIR3.cnf -config RIR.cnf
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in LIR3.req -config /dev/null
+
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in LIR3.cer
all:: LIR2.cer
@@ -42,8 +54,14 @@ LIR2.cer: LIR2.req LIR2.cnf RIR.key Makefile
@test -d LIR2 || mkdir LIR2
@test -f LIR2/index || touch LIR2/index
@test -f LIR2/serial || echo 01 >LIR2/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR2.req -extensions req_x509_ext -extfile LIR2.cnf -config RIR.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR2.req -extfile LIR2.cnf -config RIR.cnf
+
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in LIR2.req -config /dev/null
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in LIR2.cer
all:: LIR1.cer
@@ -57,9 +75,15 @@ LIR1.cer: LIR1.req LIR1.cnf RIR.key Makefile
@test -d LIR1 || mkdir LIR1
@test -f LIR1/index || touch LIR1/index
@test -f LIR1/serial || echo 01 >LIR1/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR1.req -extensions req_x509_ext -extfile LIR1.cnf -config RIR.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR1.req -extfile LIR1.cnf -config RIR.cnf
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in LIR1.req -config /dev/null
+
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in LIR1.cer
+
all:: ISP5c.cer
ISP5c.key:
@@ -72,8 +96,14 @@ ISP5c.cer: ISP5c.req ISP5c.cnf LIR3.key Makefile
@test -d ISP5c || mkdir ISP5c
@test -f ISP5c/index || touch ISP5c/index
@test -f ISP5c/serial || echo 01 >ISP5c/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5c.req -extensions req_x509_ext -extfile ISP5c.cnf -config LIR3.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5c.req -extfile ISP5c.cnf -config LIR3.cnf
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in ISP5c.req -config /dev/null
+
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in ISP5c.cer
all:: ISP5b.cer
@@ -87,8 +117,14 @@ ISP5b.cer: ISP5b.req ISP5b.cnf LIR3.key Makefile
@test -d ISP5b || mkdir ISP5b
@test -f ISP5b/index || touch ISP5b/index
@test -f ISP5b/serial || echo 01 >ISP5b/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5b.req -extensions req_x509_ext -extfile ISP5b.cnf -config LIR3.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5b.req -extfile ISP5b.cnf -config LIR3.cnf
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in ISP5b.req -config /dev/null
+
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in ISP5b.cer
all:: ISP5a.cer
@@ -102,8 +138,14 @@ ISP5a.cer: ISP5a.req ISP5a.cnf LIR3.key Makefile
@test -d ISP5a || mkdir ISP5a
@test -f ISP5a/index || touch ISP5a/index
@test -f ISP5a/serial || echo 01 >ISP5a/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5a.req -extensions req_x509_ext -extfile ISP5a.cnf -config LIR3.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5a.req -extfile ISP5a.cnf -config LIR3.cnf
+
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in ISP5a.req -config /dev/null
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in ISP5a.cer
all:: ISP4.cer
@@ -117,9 +159,15 @@ ISP4.cer: ISP4.req ISP4.cnf LIR2.key Makefile
@test -d ISP4 || mkdir ISP4
@test -f ISP4/index || touch ISP4/index
@test -f ISP4/serial || echo 01 >ISP4/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP4.req -extensions req_x509_ext -extfile ISP4.cnf -config LIR2.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP4.req -extfile ISP4.cnf -config LIR2.cnf
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in ISP4.req -config /dev/null
+
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in ISP4.cer
+
all:: ISP3.cer
ISP3.key:
@@ -132,8 +180,14 @@ ISP3.cer: ISP3.req ISP3.cnf LIR2.key Makefile
@test -d ISP3 || mkdir ISP3
@test -f ISP3/index || touch ISP3/index
@test -f ISP3/serial || echo 01 >ISP3/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP3.req -extensions req_x509_ext -extfile ISP3.cnf -config LIR2.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP3.req -extfile ISP3.cnf -config LIR2.cnf
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in ISP3.req -config /dev/null
+
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in ISP3.cer
all:: ISP2.cer
@@ -147,8 +201,14 @@ ISP2.cer: ISP2.req ISP2.cnf LIR1.key Makefile
@test -d ISP2 || mkdir ISP2
@test -f ISP2/index || touch ISP2/index
@test -f ISP2/serial || echo 01 >ISP2/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP2.req -extensions req_x509_ext -extfile ISP2.cnf -config LIR1.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP2.req -extfile ISP2.cnf -config LIR1.cnf
+
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in ISP2.req -config /dev/null
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in ISP2.cer
all:: ISP1.cer
@@ -162,5 +222,11 @@ ISP1.cer: ISP1.req ISP1.cnf LIR1.key Makefile
@test -d ISP1 || mkdir ISP1
@test -f ISP1/index || touch ISP1/index
@test -f ISP1/serial || echo 01 >ISP1/serial
- ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP1.req -extensions req_x509_ext -extfile ISP1.cnf -config LIR1.cnf
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP1.req -extfile ISP1.cnf -config LIR1.cnf
+
+
+show_req::
+ ../../openssl/openssl-0.9.8e/apps/openssl req -noout -text -in ISP1.req -config /dev/null
+show_cer::
+ ../../openssl/openssl-0.9.8e/apps/openssl x509 -noout -text -in ISP1.cer
diff --git a/scripts/resource-cert-samples/RIR.cer b/scripts/resource-cert-samples/RIR.cer
index 86579fdb..62954cf1 100644
--- a/scripts/resource-cert-samples/RIR.cer
+++ b/scripts/resource-cert-samples/RIR.cer
@@ -1,12 +1,12 @@
Certificate:
Data:
Version: 3 (0x2)
- Serial Number: 13 (0xd)
- Signature Algorithm: sha1WithRSAEncryption
+ Serial Number: 35 (0x23)
+ Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=TEST ENTITY RIR
Validity
- Not Before: Aug 1 14:48:16 2007 GMT
- Not After : Jul 31 14:48:16 2008 GMT
+ Not Before: Aug 10 01:15:09 2007 GMT
+ Not After : Aug 9 01:15:09 2008 GMT
Subject: CN=TEST ENTITY RIR
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
@@ -36,9 +36,6 @@ Certificate:
CA:TRUE
X509v3 Subject Key Identifier:
FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
- X509v3 Authority Key Identifier:
- keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
-
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
Subject Information Access:
@@ -61,44 +58,43 @@ Certificate:
2001:db8:0:0:0:0:a03::/120
2001:db8:0:0:0:10:0:44/128
- Signature Algorithm: sha1WithRSAEncryption
- 4c:d4:6d:b2:81:45:07:3e:7b:b4:8b:6c:db:42:2b:30:73:cd:
- e7:07:39:c3:e6:13:4b:ac:21:33:13:11:00:1c:e6:d1:d4:cf:
- 96:08:6e:86:7b:41:64:93:88:20:ac:04:81:65:1a:ae:a9:52:
- be:36:c0:2a:6a:c9:3a:2e:86:83:a2:cc:3e:5d:12:60:49:fb:
- 48:23:6c:d7:9f:98:fa:b4:b0:d5:48:01:29:74:ca:d1:74:3c:
- a7:8c:bb:1c:b3:85:90:2a:99:52:9e:e2:31:9a:09:28:2d:d6:
- ca:eb:f5:c6:da:6f:1b:89:83:eb:b7:d9:6d:56:71:e9:82:8e:
- b7:84:e1:40:ab:87:15:d2:a6:df:30:11:e1:52:a0:a1:4b:ef:
- 8e:3a:db:e1:d1:23:74:39:ff:48:d4:4d:2f:74:4e:e3:77:3c:
- f7:1b:16:0b:b3:1a:c7:46:8b:7c:63:3d:9d:2b:75:82:b7:5c:
- 9d:7b:df:f9:78:d2:e8:98:48:6c:54:5f:71:2a:a6:95:c6:56:
- 3e:6c:e2:0c:20:a2:2c:22:f4:1d:3c:05:b2:31:bd:58:f3:23:
- 60:dd:1d:d2:5e:ab:65:72:06:d2:da:c9:d4:c4:33:c2:b0:7d:
- 37:13:66:25:b7:28:9b:a3:9c:92:c4:58:b8:02:a2:82:63:fc:
- a8:93:65:69
+ Signature Algorithm: sha256WithRSAEncryption
+ 6b:3e:b4:ef:05:b1:6c:d0:7f:e1:86:49:86:64:44:10:16:65:
+ d2:ae:52:cf:da:08:79:bd:08:a2:fc:3b:90:bf:ec:6a:a3:cc:
+ 78:51:cf:f9:c7:9a:65:5e:a9:11:b3:db:76:0a:2d:14:96:c5:
+ d0:21:22:f1:64:b3:2c:ea:2e:20:f1:52:32:8d:c9:9a:3c:eb:
+ d1:82:53:e9:57:c9:01:ed:4f:c7:0f:b5:1f:a7:8f:1a:9d:9b:
+ 42:b2:c8:fa:c0:e9:24:7c:ea:b3:26:55:54:6c:fb:fc:36:3d:
+ 42:84:e1:b1:40:62:d9:d8:59:fd:02:9d:c9:eb:69:54:47:1a:
+ d6:b8:0a:ee:27:0c:59:ea:a4:e7:73:a8:cd:47:14:e0:2e:68:
+ f3:46:79:a9:7c:d6:07:8c:06:26:d1:66:7a:a5:e8:56:f8:5e:
+ f8:37:49:0a:f1:52:5c:78:c0:92:90:81:05:a5:4a:a7:60:0f:
+ 4b:d3:62:14:70:be:5f:90:5b:54:9f:79:d9:a8:c9:50:bc:ab:
+ ed:17:e6:a2:e0:25:b8:74:56:8c:12:66:19:41:fc:ed:eb:37:
+ 21:e5:3f:56:d0:d5:ee:f2:e6:d4:53:4e:ae:78:d4:50:fd:dd:
+ 03:6a:e3:29:72:5a:40:d5:3c:90:8e:d2:77:d2:28:9e:cb:77:
+ 85:8c:c3:e1
-----BEGIN CERTIFICATE-----
-MIIEMTCCAxmgAwIBAgIBDTANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
-IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE2WhcNMDgwNzMxMTQ0ODE2WjAaMRgw
+MIIEEDCCAvigAwIBAgIBIzANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTA5WhcNMDgwODA5MDExNTA5WjAaMRgw
FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
+PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
-4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggGAMIIBfDAPBgNVHRMBAf8E
-BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAfBgNVHSMEGDAW
-gBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8EBAMCAQYwQAYIKwYBBQUH
-AQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4u
-bmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAKAgMA/BUCAwD8HAIDAPwg
-MIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQACgAAAwQACgMAMA4DBQDA
-AAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIwXzAmAxECIAENuAAAAAAA
-AAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24AAAAAAAAAAAKAAADEAAg
-AQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABEMA0GCSqGSIb3DQEBBQUA
-A4IBAQBM1G2ygUUHPnu0i2zbQiswc83nBznD5hNLrCEzExEAHObR1M+WCG6Ge0Fk
-k4ggrASBZRquqVK+NsAqask6LoaDosw+XRJgSftII2zXn5j6tLDVSAEpdMrRdDyn
-jLscs4WQKplSnuIxmgkoLdbK6/XG2m8biYPrt9ltVnHpgo63hOFAq4cV0qbfMBHh
-UqChS++OOtvh0SN0Of9I1E0vdE7jdzz3GxYLsxrHRot8Yz2dK3WCt1yde9/5eNLo
-mEhsVF9xKqaVxlY+bOIMIKIsIvQdPAWyMb1Y8yNg3R3SXqtlcgbS2snUxDPCsH03
-E2Yltyibo5ySxFi4AqKCY/yok2Vp
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFfMIIBWzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8E
+BAMCAQYwQAYIKwYBBQUHAQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAK
+AgMA/BUCAwD8HAIDAPwgMIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQA
+CgAAAwQACgMAMA4DBQDAAAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIw
+XzAmAxECIAENuAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24
+AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABE
+MA0GCSqGSIb3DQEBCwUAA4IBAQBrPrTvBbFs0H/hhkmGZEQQFmXSrlLP2gh5vQii
+/DuQv+xqo8x4Uc/5x5plXqkRs9t2Ci0UlsXQISLxZLMs6i4g8VIyjcmaPOvRglPp
+V8kB7U/HD7Ufp48anZtCssj6wOkkfOqzJlVUbPv8Nj1ChOGxQGLZ2Fn9Ap3J62lU
+RxrWuAruJwxZ6qTnc6jNRxTgLmjzRnmpfNYHjAYm0WZ6pehW+F74N0kK8VJceMCS
+kIEFpUqnYA9L02IUcL5fkFtUn3nZqMlQvKvtF+ai4CW4dFaMEmYZQfzt6zch5T9W
+0NXu8ubUU06ueNRQ/d0DauMpclpA1TyQjtJ30iiey3eFjMPh
-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR.cnf b/scripts/resource-cert-samples/RIR.cnf
index 95726761..b70b41e8 100644
--- a/scripts/resource-cert-samples/RIR.cnf
+++ b/scripts/resource-cert-samples/RIR.cnf
@@ -13,11 +13,13 @@ name_opt = ca_default
cert_opt = ca_default
default_days = 365
default_crl_days = 30
-default_md = sha1
+default_md = sha256
preserve = no
copy_extensions = copy
policy = ca_policy_anything
unique_subject = no
+x509_extensions = ca_x509_ext
+crl_extensions = crl_x509_ext
[ ca_policy_anything ]
countryName = optional
@@ -34,7 +36,7 @@ surname = optional
default_bits = 2048
encrypt_key = no
distinguished_name = req_dn
-x509_extensions = req_x509_ext
+req_extensions = req_x509_ext
prompt = no
[ req_dn ]
@@ -43,9 +45,20 @@ CN = TEST ENTITY RIR
[ req_x509_ext ]
basicConstraints = critical,CA:true
subjectKeyIdentifier = hash
-authorityKeyIdentifier = keyid
keyUsage = critical,keyCertSign,cRLSign
subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/RIR/
#authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/???.cer
sbgp-autonomousSysNum = critical,AS:64533,AS:64534-64540,AS:64544
sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv4:10.3.0.0/24,IPv4:192.0.2.1-192.0.2.33,IPv4:192.0.2.44-192.0.2.100,IPv6:2001:db8::44-2001:db8::100,IPv6:2001:db8::a00:0/120,IPv6:2001:db8::a03:0/120,IPv6:2001:db8::10:0:44/128
+
+[ ca_x509_ext ]
+basicConstraints = critical,CA:true
+#authorityKeyIdentifier = keyid:always
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/RIR/
+#authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/???.cer
+sbgp-autonomousSysNum = critical,AS:64533,AS:64534-64540,AS:64544
+sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv4:10.3.0.0/24,IPv4:192.0.2.1-192.0.2.33,IPv4:192.0.2.44-192.0.2.100,IPv6:2001:db8::44-2001:db8::100,IPv6:2001:db8::a00:0/120,IPv6:2001:db8::a03:0/120,IPv6:2001:db8::10:0:44/128
+
+[ crl_x509_ext ]
+authorityKeyIdentifier = keyid:always
diff --git a/scripts/resource-cert-samples/RIR.req b/scripts/resource-cert-samples/RIR.req
index 7d7fb1ce..d86020df 100644
--- a/scripts/resource-cert-samples/RIR.req
+++ b/scripts/resource-cert-samples/RIR.req
@@ -1,15 +1,23 @@
-----BEGIN CERTIFICATE REQUEST-----
-MIICXzCCAUcCAQAwGjEYMBYGA1UEAxMPVEVTVCBFTlRJVFkgUklSMIIBIjANBgkq
+MIID0zCCArsCAQAwGjEYMBYGA1UEAxMPVEVTVCBFTlRJVFkgUklSMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArKcmxJhombby58WXBX751/LsOeYrjsJC
iLmPIrY8WbAOih0O+IGxyP9KihpDvHiRPq+ysJVgqT6dwv+Zj4+23NhGt4Y1pvZC
BcLFm4QV4lgPcJy8U9codvjyFHkivdaLbA4rAuXY8zP6FkObgIf5skWrvX0UsiQv
QRNvRcTc+U1/2NPhqlxSncl6OLewQ723ajdD7Oc0xDtMysx7H5Hvq9Q1dkKC1PV5
4BI8JJIu3KJcg/BxiiaWMNS4lk0ALBrwD3lSxydzVHfBhvmGYc7gaaeoPXc55yTu
-QY1SGTtXjITMmtUFfOaDLOMTbWYbhyCCR+EFJvA7KWltvK9IkcRA8QIDAQABoAAw
-DQYJKoZIhvcNAQEFBQADggEBAG3N++oUVHfXRj1clE/tRFfJ5Dtp8IwffnnOip+M
-OX51/0L/n/SiBhKGoOl68Cyg6L6n6+OTueUWv6FVYwmtzjFh2ocF60Ka7Zb26UYf
-wrdwxrRTbMqKmZh1Llq2fVep6DYxjoAXghBvs8MB8UjOrOe5aR+YMZPsOaZ8dCa/
-pLyfG/rjQxix057ukWnDv29MA+iaSYrcOijWAR6HH5mq9QsDi0RwoWMiG/C0GVLE
-QPXIJkR76P2ZqLRPmqQTwXZYiSGjMSeRKdyt6idCkSDCH2SlungYNxDJAS781AYK
-PC0UHnWQroMSW5dMm5GXo1bWhiCfkIE7z8yc5E0ob3GLoNE=
+QY1SGTtXjITMmtUFfOaDLOMTbWYbhyCCR+EFJvA7KWltvK9IkcRA8QIDAQABoIIB
+cjCCAW4GCSqGSIb3DQEJDjGCAV8wggFbMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0O
+BBYEFPu4p6M2SAqgn/Au3ItovLNcRSXXMA4GA1UdDwEB/wQEAwIBBjBABggrBgEF
+BQcBCwQ0MDIwMAYIKwYBBQUHMAWGJHJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvUklSLzAmBggrBgEFBQcBCAEB/wQXMBWgEzARMAoCAwD8FQIDAPwcAgMA
+/CAwga4GCCsGAQUFBwEHAQH/BIGeMIGbMDIEAgABMCwDBAAKAAADBAAKAwAwDgMF
+AMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUAwAACZDBlBAIAAjBfMCYDEQIgAQ24AAAA
+AAAAAAAAAABEAxEAIAENuAAAAAAAAAAAAAABAAMQACABDbgAAAAAAAAAAAoAAAMQ
+ACABDbgAAAAAAAAAAAoDAAMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEF
+BQADggEBACxlBDXYMPg+b4ob7rJxpi+V7mYAUkkdk3GlPuSJMyURO+51kSrEpp+q
+V7F8bWccjXR123Qjo6agabR22r+d961GflRKimhMZAY8rVRGHO+Pdca7eqxMRxwF
+kfuxb2W3TPGcdpuUsoMfe2vxjHZRd3uKL47SrctNpXYrvesjhQpLz1UTQ4Hnv/aw
+Ks0pxPqaVNcGXbJKSUwu5x36Cuky4r3dK299QBAuAsv0qPuxOPOLOY0bKTliEHlg
+qkadGSvnzLkTvFn41SDBZpFZY2o3RbIwMY0tSvnLN8lvlS9P20Wgl4xUJ39qRRfO
+94XlYnKios+AFEUAEzqFh/VnNclb1dw=
-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/RIR/11.pem b/scripts/resource-cert-samples/RIR/11.pem
new file mode 100644
index 00000000..f8e33d59
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/11.pem
@@ -0,0 +1,100 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 17 (0x11)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 9 23:30:59 2007 GMT
+ Not After : Aug 8 23:30:59 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533-64540
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 7b:22:d4:c2:f4:0b:74:d7:34:f4:f0:42:fa:cd:94:79:82:c3:
+ 12:dd:34:a3:e1:16:ea:de:f4:f6:b4:4d:fc:93:0e:f6:6f:7a:
+ e1:f9:bc:66:ee:56:b3:5b:28:36:ca:e8:0d:25:5b:62:31:c8:
+ 55:21:3f:4a:59:e7:cd:68:c7:6b:7c:e9:33:00:d2:59:80:23:
+ d8:58:17:e5:c6:3a:a3:d6:c3:fa:27:b2:12:9e:13:58:c3:37:
+ c2:c9:e9:d0:aa:4c:d4:82:e5:ce:ba:cc:11:d9:6d:95:24:04:
+ 75:bc:1c:56:57:2d:5f:90:19:54:38:06:13:fa:3f:b1:b4:8c:
+ 83:6c:2e:8a:e1:ca:e8:c0:6b:5c:2b:36:c5:9d:f0:65:1d:f2:
+ ab:97:77:20:5b:28:13:8f:d7:b4:1e:c3:89:5d:0f:03:fb:2c:
+ 9e:ac:59:98:ca:62:9c:cf:63:a3:ed:31:dd:0f:8f:d0:26:e8:
+ 40:bc:94:7c:b0:e6:44:07:7f:59:19:9d:1a:f7:04:d7:05:d9:
+ fc:0d:16:16:66:9c:2b:cd:87:dc:00:02:f1:e8:48:de:5f:8f:
+ b4:3e:22:fb:74:3b:7f:cb:90:7f:d6:6c:1d:26:65:e2:cc:55:
+ 3a:07:01:6c:48:61:7a:d4:55:09:c1:13:bb:ed:f5:69:e6:ba:
+ b6:80:9d:e5
+-----BEGIN CERTIFICATE-----
+MIIEEDCCAvigAwIBAgIBETANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODA5MjMzMDU5WhcNMDgwODA4MjMzMDU5WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFfMIIBWzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8E
+BAMCAQYwQAYIKwYBBQUHAQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAK
+AgMA/BUCAwD8HAIDAPwgMIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQA
+CgAAAwQACgMAMA4DBQDAAAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIw
+XzAmAxECIAENuAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24
+AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABE
+MA0GCSqGSIb3DQEBBQUAA4IBAQB7ItTC9At01zT08EL6zZR5gsMS3TSj4Rbq3vT2
+tE38kw72b3rh+bxm7lazWyg2yugNJVtiMchVIT9KWefNaMdrfOkzANJZgCPYWBfl
+xjqj1sP6J7ISnhNYwzfCyenQqkzUguXOuswR2W2VJAR1vBxWVy1fkBlUOAYT+j+x
+tIyDbC6K4crowGtcKzbFnfBlHfKrl3cgWygTj9e0HsOJXQ8D+yyerFmYymKcz2Oj
+7THdD4/QJuhAvJR8sOZEB39ZGZ0a9wTXBdn8DRYWZpwrzYfcAALx6EjeX4+0PiL7
+dDt/y5B/1mwdJmXizFU6BwFsSGF61FUJwRO77fVp5rq2gJ3l
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/12.pem b/scripts/resource-cert-samples/RIR/12.pem
new file mode 100644
index 00000000..71bb1954
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/12.pem
@@ -0,0 +1,100 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 18 (0x12)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 9 23:35:48 2007 GMT
+ Not After : Aug 8 23:35:48 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533-64540
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 80:5c:c5:27:3a:5d:bb:11:2c:ec:b4:89:ab:3f:79:a7:31:ef:
+ 7f:ed:93:75:2c:9d:4b:5c:f1:28:38:3e:cc:c4:98:e5:81:01:
+ db:e1:61:5c:37:0a:3f:91:52:34:a5:6b:28:8c:b7:ae:38:95:
+ a7:67:26:39:b2:43:cb:a5:db:fc:4f:12:6c:f4:69:82:ab:80:
+ 9c:8f:aa:d9:21:6e:3e:e1:f5:78:f4:59:d0:2e:97:1d:23:3d:
+ 27:86:70:5b:b7:59:e7:98:1c:ae:19:42:e8:65:ef:eb:bf:6c:
+ f8:94:6a:27:b9:11:5e:81:b6:ee:5f:10:ae:9f:b7:30:50:30:
+ e6:84:5c:90:ef:3d:24:e7:6a:20:5c:d2:4c:96:66:28:15:46:
+ 40:63:00:65:96:a5:5f:78:2a:66:d2:16:b1:86:77:e0:39:7d:
+ fc:14:e1:bc:54:5b:b1:08:65:aa:f1:1b:39:2f:bf:ca:07:a0:
+ ab:e7:e4:b0:8c:cb:48:c7:44:94:ff:04:a4:c9:85:6d:40:ca:
+ 8f:0c:01:e6:11:f6:eb:07:96:b5:83:15:87:27:88:72:b3:d9:
+ 41:4e:d0:f0:88:1a:17:10:72:89:85:c0:12:79:c1:5c:07:bb:
+ d7:39:ef:ce:49:85:11:62:01:50:71:91:b9:e3:7e:45:a8:45:
+ d6:d0:a9:3a
+-----BEGIN CERTIFICATE-----
+MIIEEDCCAvigAwIBAgIBEjANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODA5MjMzNTQ4WhcNMDgwODA4MjMzNTQ4WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFfMIIBWzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8E
+BAMCAQYwQAYIKwYBBQUHAQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAK
+AgMA/BUCAwD8HAIDAPwgMIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQA
+CgAAAwQACgMAMA4DBQDAAAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIw
+XzAmAxECIAENuAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24
+AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABE
+MA0GCSqGSIb3DQEBBQUAA4IBAQCAXMUnOl27ESzstImrP3mnMe9/7ZN1LJ1LXPEo
+OD7MxJjlgQHb4WFcNwo/kVI0pWsojLeuOJWnZyY5skPLpdv8TxJs9GmCq4Ccj6rZ
+IW4+4fV49FnQLpcdIz0nhnBbt1nnmByuGULoZe/rv2z4lGonuRFegbbuXxCun7cw
+UDDmhFyQ7z0k52ogXNJMlmYoFUZAYwBllqVfeCpm0haxhnfgOX38FOG8VFuxCGWq
+8Rs5L7/KB6Cr5+SwjMtIx0SU/wSkyYVtQMqPDAHmEfbrB5a1gxWHJ4hys9lBTtDw
+iBoXEHKJhcASecFcB7vXOe/OSYURYgFQcZG5435FqEXW0Kk6
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/13.pem b/scripts/resource-cert-samples/RIR/13.pem
new file mode 100644
index 00000000..3b1e67f4
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/13.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 19 (0x13)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 62:6a:d0:3e:02:bf:ad:3c:e5:c9:23:1f:66:6d:cc:80:59:a5:
+ 64:61:f2:20:64:bc:91:5d:76:d9:ce:6e:db:d1:c0:89:77:9d:
+ cc:a6:e2:4a:43:0e:bb:f3:36:60:3f:1d:b7:9a:38:ad:10:e0:
+ 89:82:61:c7:4a:48:70:c3:03:73:ae:ab:37:31:0c:36:cc:46:
+ 12:ea:54:3d:03:d6:ba:4c:d6:cf:73:ea:90:4c:37:da:a3:f6:
+ b6:f3:af:d8:a7:82:e7:1a:7b:05:23:77:20:52:b3:53:64:d0:
+ bd:24:83:21:49:2f:30:fc:12:3b:fa:73:c3:c9:de:3f:af:bb:
+ 5e:ed:b3:bf:9b:9e:71:83:37:f1:98:e3:77:e1:72:4f:1d:c6:
+ 7b:59:32:34:f7:e4:76:70:52:41:72:97:bb:61:c0:c8:26:ac:
+ 28:6e:e7:ef:f8:6c:ea:b2:4c:62:d0:28:5e:6c:50:94:09:a1:
+ d4:ab:0c:d3:b3:d1:4a:ea:ef:33:ed:08:43:54:71:fb:6d:40:
+ c8:dc:75:84:28:ff:4e:47:2c:08:54:72:40:af:cc:94:00:a8:
+ 9f:8e:d9:35:64:49:f1:db:69:a8:d5:71:86:41:46:e0:27:62:
+ 50:a4:0a:1e:f5:99:b4:d8:db:1c:4f:8b:af:51:4d:80:2b:af:
+ e3:b6:b0:6b
+-----BEGIN CERTIFICATE-----
+MIIDNTCCAh2gAwIBAgIBEzANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDA1ODE3WhcNMDgwODA5MDA1ODE3WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjgYUwgYIwDwYDVR0TAQH/BAUw
+AwEB/zAdBgNVHQ4EFgQU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQD
+AgEGMEAGCCsGAQUFBwELBDQwMjAwBggrBgEFBQcwBYYkcnN5bmM6Ly93b21iYXRz
+LXItdXMuaGFjdHJuLm5ldC9SSVIvMA0GCSqGSIb3DQEBCwUAA4IBAQBiatA+Ar+t
+POXJIx9mbcyAWaVkYfIgZLyRXXbZzm7b0cCJd53MpuJKQw678zZgPx23mjitEOCJ
+gmHHSkhwwwNzrqs3MQw2zEYS6lQ9A9a6TNbPc+qQTDfao/a286/Yp4LnGnsFI3cg
+UrNTZNC9JIMhSS8w/BI7+nPDyd4/r7te7bO/m55xgzfxmON34XJPHcZ7WTI09+R2
+cFJBcpe7YcDIJqwobufv+Gzqskxi0ChebFCUCaHUqwzTs9FK6u8z7QhDVHH7bUDI
+3HWEKP9ORywIVHJAr8yUAKifjtk1ZEnx22mo1XGGQUbgJ2JQpAoe9Zm02NscT4uv
+UU2AK6/jtrBr
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/14.pem b/scripts/resource-cert-samples/RIR/14.pem
new file mode 100644
index 00000000..430d3895
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/14.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 20 (0x14)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY LIR3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:a3:21:57:61:64:af:11:18:d4:cb:de:a6:dc:ad:
+ d9:2c:0f:0f:58:9f:7e:c8:85:55:11:26:4c:7c:f0:
+ 6b:68:1a:9e:6a:0c:8f:e6:dc:3d:83:58:2a:cc:77:
+ ac:19:73:6f:5a:f3:6e:24:ac:cd:1a:dc:1d:0b:4c:
+ 44:f5:6d:8b:0a:17:3d:86:f9:e8:fe:e6:60:e5:9f:
+ 40:6a:e5:94:e8:9a:56:17:17:1c:ab:c1:8c:37:40:
+ 2b:55:bf:2c:5e:dc:8d:ca:25:7f:8a:5f:ee:fb:16:
+ 86:eb:e0:08:d3:26:e5:e3:70:c5:0c:6b:fb:1b:8f:
+ 6b:5c:f6:e2:4a:58:a5:35:01:ea:05:1b:3e:ce:84:
+ be:b5:3f:6d:18:16:4b:68:e5:79:4c:88:7d:b6:a5:
+ 65:a3:3a:c2:32:dc:ad:8f:8a:05:ee:f6:e9:7a:80:
+ da:12:a9:0f:5a:b5:d2:d3:31:ac:3e:d3:19:25:2d:
+ 28:de:79:6c:ce:fd:77:66:d5:e3:2f:a9:cb:f9:85:
+ 8c:20:bb:a2:86:23:f0:93:95:20:04:78:c7:c7:07:
+ a6:fe:f0:f4:45:bb:cf:78:2b:dd:ce:9c:08:a5:46:
+ 68:10:4c:d7:05:62:6c:86:5a:2d:7f:06:38:c2:4d:
+ bb:44:87:00:43:79:d2:8f:f3:6b:b2:f4:5c:1c:b9:
+ 68:01
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR3/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 5a:9b:65:02:d5:6c:fc:4f:b2:df:3b:a8:a2:44:3b:fd:bc:4d:
+ 9f:32:30:e7:4f:e6:44:37:3f:35:68:d0:7e:ee:a5:cc:6e:0a:
+ 79:2d:6a:2d:35:45:13:ed:f8:67:fb:5b:41:fa:00:04:f5:28:
+ d4:72:0e:fe:05:d6:76:20:cf:4b:15:13:05:6c:9f:aa:05:8c:
+ 77:eb:e7:1d:57:ed:32:11:45:ba:3e:e8:53:68:85:98:bd:bf:
+ 56:7e:04:85:f1:7f:70:ba:e8:16:03:46:ff:c5:be:df:42:79:
+ 57:01:2f:1a:e2:bc:6b:79:3e:fa:79:ec:08:ca:7d:32:02:0c:
+ 94:47:9e:c8:01:60:de:b9:43:76:be:22:64:89:47:d7:b9:63:
+ 9f:1d:7d:c8:93:e6:48:2a:a6:f7:51:9c:bd:06:8a:c9:01:5d:
+ 51:83:85:09:1a:18:03:49:10:e9:fa:80:0a:d1:7c:2c:69:c0:
+ 6b:53:e6:97:24:cd:f1:ad:e2:b6:5f:ac:72:28:0c:e8:cb:ab:
+ 00:15:29:9e:cb:af:74:1e:dc:3b:c6:24:bc:2d:50:e3:12:fc:
+ 00:63:ec:b6:09:c9:27:33:d6:42:a2:87:d4:35:48:63:16:1a:
+ e0:f7:50:ed:e3:d9:11:d9:f1:1c:cd:a5:21:e0:56:ad:4d:fc:
+ da:a6:97:e9
+-----BEGIN CERTIFICATE-----
+MIIDNzCCAh+gAwIBAgIBFDANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDA1ODE3WhcNMDgwODA5MDA1ODE3WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
+g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
+N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
+zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4GGMIGDMA8GA1UdEwEB/wQF
+MAMBAf8wHQYDVR0OBBYEFJi+BP+A0auVOao98g5nfQCto/3FMA4GA1UdDwEB/wQE
+AwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0
+cy1yLXVzLmhhY3Rybi5uZXQvTElSMy8wDQYJKoZIhvcNAQELBQADggEBAFqbZQLV
+bPxPst87qKJEO/28TZ8yMOdP5kQ3PzVo0H7upcxuCnktai01RRPt+Gf7W0H6AAT1
+KNRyDv4F1nYgz0sVEwVsn6oFjHfr5x1X7TIRRbo+6FNohZi9v1Z+BIXxf3C66BYD
+Rv/Fvt9CeVcBLxrivGt5Pvp57AjKfTICDJRHnsgBYN65Q3a+ImSJR9e5Y58dfciT
+5kgqpvdRnL0GiskBXVGDhQkaGANJEOn6gArRfCxpwGtT5pckzfGt4rZfrHIoDOjL
+qwAVKZ7Lr3Qe3DvGJLwtUOMS/ABj7LYJyScz1kKih9Q1SGMWGuD3UO3j2RHZ8RzN
+pSHgVq1N/Nqml+k=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/15.pem b/scripts/resource-cert-samples/RIR/15.pem
new file mode 100644
index 00000000..625589ac
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/15.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 21 (0x15)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 6f:1a:6a:59:42:4b:0d:64:9e:e4:6e:80:ae:d4:ed:00:cc:52:
+ eb:04:bf:e2:48:2e:24:89:bd:df:a9:cf:93:27:47:80:c5:d6:
+ e1:94:f5:4a:d0:f7:52:48:49:c3:2a:20:de:87:76:e1:a0:11:
+ d5:a0:19:f5:70:df:45:1c:72:47:6b:af:5b:53:5d:1d:49:5a:
+ 62:21:f9:3b:49:18:9d:b1:6c:53:6d:9d:85:2c:fc:83:72:ff:
+ b7:7d:4f:01:36:41:df:a3:03:51:34:e2:5e:25:65:4c:d1:25:
+ f8:e3:92:06:7a:ca:97:42:6c:60:58:05:54:f5:9d:b9:90:fc:
+ ae:32:a3:c5:dc:db:75:55:97:2e:db:1a:32:65:44:e6:ab:81:
+ 14:b2:e1:8c:c5:a5:09:a4:07:2e:ed:ee:44:28:6a:29:0e:6f:
+ a0:08:aa:2a:28:24:e8:cf:7f:22:db:56:b4:fc:45:26:13:9a:
+ 41:55:5c:81:31:b3:6d:d0:3e:cc:62:6d:d1:d8:b9:2a:0f:2b:
+ 58:40:7a:e0:02:d2:31:4c:4f:df:c5:2c:d1:ba:c9:8c:e3:b9:
+ 74:7e:5c:dd:a5:f8:75:93:fe:26:69:52:70:bd:2e:01:1a:37:
+ d1:53:ae:80:d5:5b:56:0c:72:e4:c6:ba:7b:3f:99:2a:bf:a7:
+ b0:d7:3b:ec
+-----BEGIN CERTIFICATE-----
+MIIDNzCCAh+gAwIBAgIBFTANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDA1ODE3WhcNMDgwODA5MDA1ODE3WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4GGMIGDMA8GA1UdEwEB/wQF
+MAMBAf8wHQYDVR0OBBYEFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQE
+AwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0
+cy1yLXVzLmhhY3Rybi5uZXQvTElSMi8wDQYJKoZIhvcNAQELBQADggEBAG8aallC
+Sw1knuRugK7U7QDMUusEv+JILiSJvd+pz5MnR4DF1uGU9UrQ91JIScMqIN6HduGg
+EdWgGfVw30Ucckdrr1tTXR1JWmIh+TtJGJ2xbFNtnYUs/INy/7d9TwE2Qd+jA1E0
+4l4lZUzRJfjjkgZ6ypdCbGBYBVT1nbmQ/K4yo8Xc23VVly7bGjJlROargRSy4YzF
+pQmkBy7t7kQoaikOb6AIqiooJOjPfyLbVrT8RSYTmkFVXIExs23QPsxibdHYuSoP
+K1hAeuAC0jFMT9/FLNG6yYzjuXR+XN2l+HWT/iZpUnC9LgEaN9FTroDVW1YMcuTG
+uns/mSq/p7DXO+w=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/16.pem b/scripts/resource-cert-samples/RIR/16.pem
new file mode 100644
index 00000000..ebfd1e7b
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/16.pem
@@ -0,0 +1,79 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 22 (0x16)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 00:58:17 2007 GMT
+ Not After : Aug 9 00:58:17 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 45:76:2c:fa:d1:3b:02:23:5f:e3:3f:07:7e:ad:92:c0:7d:ba:
+ 8b:6d:ff:3c:33:c2:d4:06:4d:ca:71:41:6a:36:a2:e3:3a:34:
+ 0c:9e:b1:21:a2:17:91:3b:e9:e3:50:57:25:2e:dc:4f:1a:67:
+ 30:52:3e:36:04:0a:ce:03:84:f6:b0:1b:1c:59:66:4b:d1:68:
+ 5a:cf:3b:7d:f4:28:74:6d:16:ba:7c:ad:5c:f0:6a:39:73:33:
+ fe:c0:8d:d7:55:c0:cb:df:f3:d4:51:34:fe:62:42:97:70:61:
+ bd:cc:bc:1c:c7:37:5f:d4:f1:2b:cb:3b:11:4c:84:77:db:5e:
+ 66:2d:37:71:d5:f5:91:01:be:4e:97:8b:ae:6e:83:9a:9a:e3:
+ d8:47:a9:fc:7f:b3:80:67:c1:60:60:3e:66:64:e8:ae:d8:7a:
+ 72:50:fd:59:75:dd:fd:f0:69:92:ce:f6:c9:cc:49:72:eb:70:
+ 48:28:e7:f7:1c:d4:a0:75:40:ef:50:f4:9f:e4:74:26:e5:90:
+ ae:c4:fb:c5:b9:0a:5f:da:61:c2:78:f4:0d:0b:b8:ed:28:d9:
+ b7:26:6a:8f:1d:43:22:72:f3:a6:3c:36:d8:40:9f:d7:49:68:
+ d0:af:64:48:f8:69:55:98:9c:e9:47:5b:1b:15:06:5f:60:80:
+ e9:e2:72:f7
+-----BEGIN CERTIFICATE-----
+MIIDNzCCAh+gAwIBAgIBFjANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDA1ODE3WhcNMDgwODA5MDA1ODE3WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4GGMIGDMA8GA1UdEwEB/wQF
+MAMBAf8wHQYDVR0OBBYEFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQE
+AwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0
+cy1yLXVzLmhhY3Rybi5uZXQvTElSMS8wDQYJKoZIhvcNAQELBQADggEBAEV2LPrR
+OwIjX+M/B36tksB9uott/zwzwtQGTcpxQWo2ouM6NAyesSGiF5E76eNQVyUu3E8a
+ZzBSPjYECs4DhPawGxxZZkvRaFrPO330KHRtFrp8rVzwajlzM/7AjddVwMvf89RR
+NP5iQpdwYb3MvBzHN1/U8SvLOxFMhHfbXmYtN3HV9ZEBvk6Xi65ug5qa49hHqfx/
+s4BnwWBgPmZk6K7YenJQ/Vl13f3waZLO9snMSXLrcEgo5/cc1KB1QO9Q9J/kdCbl
+kK7E+8W5Cl/aYcJ49A0LuO0o2bcmao8dQyJy86Y8NthAn9dJaNCvZEj4aVWYnOlH
+WxsVBl9ggOnicvc=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/17.pem b/scripts/resource-cert-samples/RIR/17.pem
new file mode 100644
index 00000000..08089ed2
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/17.pem
@@ -0,0 +1,100 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 23 (0x17)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533-64540
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 98:59:33:64:37:e0:05:3f:f1:4a:d6:c3:45:92:92:f4:da:0e:
+ 35:de:70:0a:ab:49:10:c9:a2:74:c6:ad:2b:cb:de:3e:0e:3f:
+ 2e:2d:0d:f1:65:0a:b9:f6:c6:fe:80:8a:d2:a9:fe:41:f7:6d:
+ 8f:92:f4:f6:4a:d0:36:6f:06:de:f6:30:91:ac:1d:c3:a7:d0:
+ 7a:4a:40:9c:88:fd:0f:b8:f7:46:0c:d0:a5:85:48:e7:47:e1:
+ 9a:d2:e7:3e:36:fc:e5:e4:13:98:b2:48:a7:b1:bb:b5:86:11:
+ 35:42:20:97:6a:d6:a1:ae:1b:33:1b:6d:1c:9b:e8:9d:8c:05:
+ 44:e3:d3:7e:53:d6:d8:da:76:85:6d:8f:dc:d1:1b:c4:cd:87:
+ de:73:dd:09:26:eb:ac:49:62:5f:fb:44:42:d5:81:0f:11:eb:
+ 3f:5c:83:2d:ed:51:12:66:e6:ff:2c:83:ac:40:0a:85:01:b4:
+ 08:4b:32:14:ff:a5:a6:33:30:f2:10:ac:bb:55:9c:65:3b:78:
+ 35:0e:45:c6:0d:64:b0:ef:1f:f7:7f:79:43:fd:97:b9:ea:8b:
+ 8e:5d:56:76:fa:cb:39:17:f3:27:b2:b0:1d:87:1f:52:50:54:
+ 55:69:5a:37:f1:42:07:ed:68:90:b0:63:7c:f1:10:19:29:44:
+ f7:58:ee:eb
+-----BEGIN CERTIFICATE-----
+MIIEEDCCAvigAwIBAgIBFzANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwMjMxWhcNMDgwODA5MDEwMjMxWjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFfMIIBWzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8E
+BAMCAQYwQAYIKwYBBQUHAQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAK
+AgMA/BUCAwD8HAIDAPwgMIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQA
+CgAAAwQACgMAMA4DBQDAAAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIw
+XzAmAxECIAENuAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24
+AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABE
+MA0GCSqGSIb3DQEBCwUAA4IBAQCYWTNkN+AFP/FK1sNFkpL02g413nAKq0kQyaJ0
+xq0ry94+Dj8uLQ3xZQq59sb+gIrSqf5B922PkvT2StA2bwbe9jCRrB3Dp9B6SkCc
+iP0PuPdGDNClhUjnR+Ga0uc+Nvzl5BOYskinsbu1hhE1QiCXatahrhszG20cm+id
+jAVE49N+U9bY2naFbY/c0RvEzYfec90JJuusSWJf+0RC1YEPEes/XIMt7VESZub/
+LIOsQAqFAbQISzIU/6WmMzDyEKy7VZxlO3g1DkXGDWSw7x/3f3lD/Ze56ouOXVZ2
++ss5F/MnsrAdhx9SUFRVaVo38UIH7WiQsGN88RAZKUT3WO7r
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/18.pem b/scripts/resource-cert-samples/RIR/18.pem
new file mode 100644
index 00000000..61f31504
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/18.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 24 (0x18)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY LIR3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:a3:21:57:61:64:af:11:18:d4:cb:de:a6:dc:ad:
+ d9:2c:0f:0f:58:9f:7e:c8:85:55:11:26:4c:7c:f0:
+ 6b:68:1a:9e:6a:0c:8f:e6:dc:3d:83:58:2a:cc:77:
+ ac:19:73:6f:5a:f3:6e:24:ac:cd:1a:dc:1d:0b:4c:
+ 44:f5:6d:8b:0a:17:3d:86:f9:e8:fe:e6:60:e5:9f:
+ 40:6a:e5:94:e8:9a:56:17:17:1c:ab:c1:8c:37:40:
+ 2b:55:bf:2c:5e:dc:8d:ca:25:7f:8a:5f:ee:fb:16:
+ 86:eb:e0:08:d3:26:e5:e3:70:c5:0c:6b:fb:1b:8f:
+ 6b:5c:f6:e2:4a:58:a5:35:01:ea:05:1b:3e:ce:84:
+ be:b5:3f:6d:18:16:4b:68:e5:79:4c:88:7d:b6:a5:
+ 65:a3:3a:c2:32:dc:ad:8f:8a:05:ee:f6:e9:7a:80:
+ da:12:a9:0f:5a:b5:d2:d3:31:ac:3e:d3:19:25:2d:
+ 28:de:79:6c:ce:fd:77:66:d5:e3:2f:a9:cb:f9:85:
+ 8c:20:bb:a2:86:23:f0:93:95:20:04:78:c7:c7:07:
+ a6:fe:f0:f4:45:bb:cf:78:2b:dd:ce:9c:08:a5:46:
+ 68:10:4c:d7:05:62:6c:86:5a:2d:7f:06:38:c2:4d:
+ bb:44:87:00:43:79:d2:8f:f3:6b:b2:f4:5c:1c:b9:
+ 68:01
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 48:75:33:bf:1e:19:3b:50:a8:af:35:67:af:b3:e9:f5:53:68:
+ ea:41:f9:cf:21:a6:cb:ad:f3:ac:20:2b:79:c9:15:7a:9b:7f:
+ 88:70:ac:34:64:44:92:7f:56:41:f1:8e:af:9f:e6:28:6f:74:
+ d5:d3:d3:7b:99:1f:92:8f:58:9d:03:b3:f9:b1:9f:c4:8e:b1:
+ ea:bb:cf:11:02:70:7b:9c:0e:36:f9:13:41:fb:3f:94:aa:95:
+ 33:25:f4:4b:4c:cf:11:c4:39:1b:74:fc:98:92:84:4a:58:09:
+ f3:e5:d2:1c:06:cf:73:79:98:68:ec:17:c2:4f:24:38:7d:47:
+ b9:6d:62:c6:70:69:2e:83:0c:d1:77:e1:78:a2:b5:ea:0e:17:
+ d4:93:7b:9c:c1:1d:48:aa:ba:95:03:9d:0f:1a:d8:65:36:84:
+ 5b:2b:57:44:af:ef:0e:56:f8:3f:63:34:79:d4:98:8d:c6:7c:
+ 3c:b5:cc:26:ab:5c:04:01:aa:ff:c7:00:2c:12:4c:e4:9e:29:
+ f4:30:95:ab:28:d5:f0:91:b1:4b:cc:a9:43:58:d1:81:45:7b:
+ 48:50:7e:b8:21:25:2a:58:d7:65:e7:1f:09:30:25:09:08:83:
+ 5b:fd:c4:42:bd:d7:a1:72:e4:97:ce:f6:c9:72:38:59:2f:e6:
+ e4:06:a4:99
+-----BEGIN CERTIFICATE-----
+MIID9DCCAtygAwIBAgIBGDANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwMjMxWhcNMDgwODA5MDEwMjMxWjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
+g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
+N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
+zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4IBQjCCAT4wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUmL4E/4DRq5U5qj3yDmd9AK2j/cUwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIzLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAh
+BggrBgEFBQcBCAEB/wQSMBCgDjAMMAoCAwD8FgIDAPwcMFEGCCsGAQUFBwEHAQH/
+BEIwQDASBAIAATAMAwQACgAAAwQACgMAMCoEAgACMCQDEAAgAQ24AAAAAAAAAAAK
+AAADEAAgAQ24AAAAAAAAAAAKAwAwDQYJKoZIhvcNAQELBQADggEBAEh1M78eGTtQ
+qK81Z6+z6fVTaOpB+c8hpsut86wgK3nJFXqbf4hwrDRkRJJ/VkHxjq+f5ihvdNXT
+03uZH5KPWJ0Ds/mxn8SOseq7zxECcHucDjb5E0H7P5SqlTMl9EtMzxHEORt0/JiS
+hEpYCfPl0hwGz3N5mGjsF8JPJDh9R7ltYsZwaS6DDNF34XiiteoOF9STe5zBHUiq
+upUDnQ8a2GU2hFsrV0Sv7w5W+D9jNHnUmI3GfDy1zCarXAQBqv/HACwSTOSeKfQw
+laso1fCRsUvMqUNY0YFFe0hQfrghJSpY12XnHwkwJQkIg1v9xEK916Fy5JfO9sly
+OFkv5uQGpJk=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/19.pem b/scripts/resource-cert-samples/RIR/19.pem
new file mode 100644
index 00000000..e258d4d7
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/19.pem
@@ -0,0 +1,95 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 25 (0x19)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ ab:e6:eb:32:dd:27:9e:57:ba:21:b7:f2:7f:38:ba:b9:35:c6:
+ fb:73:c8:70:83:63:80:8f:10:99:56:fc:27:66:d3:19:36:61:
+ 0d:96:f5:aa:1e:2b:8d:75:3f:cf:9a:5e:8c:17:51:21:31:6f:
+ ac:ce:d7:18:21:03:3e:b9:b5:4b:50:23:3a:1c:45:5e:51:d9:
+ 91:73:84:19:98:bd:52:3f:77:f9:c1:ae:94:e0:be:5a:70:20:
+ 1b:68:55:4a:9b:02:7b:7f:a0:4c:86:d8:41:54:58:f0:65:b9:
+ 18:03:9e:92:d0:5e:bf:6b:d9:42:b3:20:fe:f8:87:65:54:17:
+ 88:69:cd:e1:b7:73:37:2b:bf:e0:10:52:0a:4f:72:e7:3e:c8:
+ 6c:91:37:cb:16:6b:e3:76:45:4d:68:80:92:45:7d:0f:7d:46:
+ 11:6d:5a:e9:63:38:c3:7f:84:87:4c:66:28:11:d9:a3:db:75:
+ d8:72:5e:a6:46:3a:14:28:9d:86:e3:bc:a5:15:4c:8c:0c:54:
+ 8c:9a:0b:4a:ad:72:9a:c5:60:f5:92:ef:9e:ef:be:38:c4:28:
+ 44:a8:26:80:dc:26:4a:27:4c:d0:ba:f6:ba:fb:9c:5c:7c:3b:
+ 80:7a:37:3f:bd:eb:8f:f5:21:db:b4:80:77:a8:bb:b0:19:07:
+ 00:65:9a:82
+-----BEGIN CERTIFICATE-----
+MIID8DCCAtigAwIBAgIBGTANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwMjMxWhcNMDgwODA5MDEwMjMxWjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBPjCCATowDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEE
+AgACMDswJgMRAiABDbgAAAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEA
+IAENuAAAAAAAAAAQAAAARDANBgkqhkiG9w0BAQsFAAOCAQEAq+brMt0nnle6Ibfy
+fzi6uTXG+3PIcINjgI8QmVb8J2bTGTZhDZb1qh4rjXU/z5pejBdRITFvrM7XGCED
+Prm1S1AjOhxFXlHZkXOEGZi9Uj93+cGulOC+WnAgG2hVSpsCe3+gTIbYQVRY8GW5
+GAOektBev2vZQrMg/viHZVQXiGnN4bdzNyu/4BBSCk9y5z7IbJE3yxZr43ZFTWiA
+kkV9D31GEW1a6WM4w3+Eh0xmKBHZo9t12HJepkY6FCidhuO8pRVMjAxUjJoLSq1y
+msVg9ZLvnu++OMQoRKgmgNwmSidM0Lr2uvucXHw7gHo3P73rj/Uh27SAd6i7sBkH
+AGWagg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/1A.pem b/scripts/resource-cert-samples/RIR/1A.pem
new file mode 100644
index 00000000..9b92b771
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/1A.pem
@@ -0,0 +1,94 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 26 (0x1a)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:02:31 2007 GMT
+ Not After : Aug 9 01:02:31 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 1f:83:71:23:e8:ef:c9:a9:7f:c1:a3:c3:73:64:67:f3:0a:c0:
+ b8:1f:17:71:b0:f6:97:be:db:5d:bf:79:ea:d8:af:cc:16:f4:
+ ee:f1:01:e3:df:a4:f5:a7:d9:d0:12:28:fc:02:69:91:eb:1f:
+ e5:fa:b3:3c:ba:9a:34:20:ce:0a:68:73:b8:aa:62:dd:b1:54:
+ f9:b6:ab:70:23:e0:c6:55:d5:a7:ad:ab:5b:bf:12:38:44:7b:
+ b1:36:20:6e:1b:d1:30:5e:c2:a3:c6:db:19:4e:f1:e8:71:32:
+ 1a:04:b4:96:31:9b:5e:c8:25:94:72:05:f1:96:a4:82:69:62:
+ c6:67:7f:53:b6:71:b1:72:7f:9b:94:f4:04:fe:32:ed:7b:ee:
+ 4e:4a:6a:6c:b8:70:db:2d:4a:7c:b9:23:8b:d0:39:b1:a5:9f:
+ c8:ee:51:95:3d:e0:e6:d2:45:0b:8a:83:d0:41:13:f6:39:ce:
+ 5f:a6:91:00:6c:e1:dc:51:e0:b8:7c:6c:e4:a7:54:b8:26:04:
+ 8c:bb:5a:35:0b:d9:4f:dd:52:78:21:e2:a7:ca:ef:a7:10:cf:
+ 44:27:2b:f4:88:d8:18:c3:e1:5a:42:12:a3:05:1e:08:7a:06:
+ 1f:24:64:05:14:d9:b2:2d:92:4e:cd:45:8b:45:c6:9e:ca:10:
+ 72:0d:43:09
+-----BEGIN CERTIFICATE-----
+MIID1TCCAr2gAwIBAgIBGjANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwMjMxWhcNMDgwODA5MDEwMjMxWjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBIzCCAR8wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYE
+AgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0B
+AQsFAAOCAQEAH4NxI+jvyal/waPDc2Rn8wrAuB8XcbD2l77bXb956tivzBb07vEB
+49+k9afZ0BIo/AJpkesf5fqzPLqaNCDOCmhzuKpi3bFU+barcCPgxlXVp62rW78S
+OER7sTYgbhvRMF7Co8bbGU7x6HEyGgS0ljGbXsgllHIF8Zakgmlixmd/U7ZxsXJ/
+m5T0BP4y7XvuTkpqbLhw2y1KfLkji9A5saWfyO5RlT3g5tJFC4qD0EET9jnOX6aR
+AGzh3FHguHxs5KdUuCYEjLtaNQvZT91SeCHip8rvpxDPRCcr9IjYGMPhWkISowUe
+CHoGHyRkBRTZsi2STs1Fi0XGnsoQcg1DCQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/1B.pem b/scripts/resource-cert-samples/RIR/1B.pem
new file mode 100644
index 00000000..300059d2
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/1B.pem
@@ -0,0 +1,100 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 27 (0x1b)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:07:08 2007 GMT
+ Not After : Aug 9 01:07:08 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533-64540
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 7c:1c:ce:a8:d1:0f:62:6e:a9:c2:b1:1a:5d:12:64:0b:07:3f:
+ 32:63:9e:f5:0c:29:f6:5a:72:40:7d:a2:02:a0:cb:2a:c0:e0:
+ 66:d7:bd:0a:1e:c4:59:ee:99:33:f8:c3:a7:4b:56:8c:1d:62:
+ f5:c3:ee:12:45:3e:2f:29:ed:11:29:ae:1f:c0:8f:d6:ac:dd:
+ f4:74:21:07:b0:54:cc:6b:ca:37:38:82:7b:d4:e1:1f:00:b4:
+ ac:be:b4:71:5f:74:96:1b:39:ef:fc:ae:0c:b5:b2:7b:be:e5:
+ 16:66:21:2f:aa:ba:1a:52:63:d3:3f:38:91:7b:2d:c8:fd:f6:
+ aa:f0:f1:c5:39:4f:7d:79:b3:e3:e6:a0:95:6b:a3:66:10:dd:
+ d4:0f:93:0f:34:13:b0:1c:a3:b4:88:ba:ba:b6:f5:55:ba:f2:
+ 1c:6c:1c:9d:1d:fe:e7:49:c9:10:9a:c7:68:b0:2c:d7:0e:c1:
+ 73:93:07:65:2b:3f:ed:98:ff:4d:f4:6b:b6:c0:4b:25:40:43:
+ 33:b6:44:b9:de:62:27:bf:cd:6d:36:9d:60:a8:bd:25:67:21:
+ 53:a4:64:d7:67:7b:0b:ff:a2:22:72:cd:8a:b2:57:7c:13:02:
+ 97:93:96:cc:3b:61:40:6d:5c:da:d6:79:b6:ac:e0:05:fe:dd:
+ f9:7f:24:2c
+-----BEGIN CERTIFICATE-----
+MIIEEDCCAvigAwIBAgIBGzANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwNzA4WhcNMDgwODA5MDEwNzA4WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFfMIIBWzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8E
+BAMCAQYwQAYIKwYBBQUHAQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAK
+AgMA/BUCAwD8HAIDAPwgMIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQA
+CgAAAwQACgMAMA4DBQDAAAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIw
+XzAmAxECIAENuAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24
+AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABE
+MA0GCSqGSIb3DQEBCwUAA4IBAQB8HM6o0Q9ibqnCsRpdEmQLBz8yY571DCn2WnJA
+faICoMsqwOBm170KHsRZ7pkz+MOnS1aMHWL1w+4SRT4vKe0RKa4fwI/WrN30dCEH
+sFTMa8o3OIJ71OEfALSsvrRxX3SWGznv/K4MtbJ7vuUWZiEvqroaUmPTPziRey3I
+/faq8PHFOU99ebPj5qCVa6NmEN3UD5MPNBOwHKO0iLq6tvVVuvIcbBydHf7nSckQ
+msdosCzXDsFzkwdlKz/tmP9N9Gu2wEslQEMztkS53mInv81tNp1gqL0lZyFTpGTX
+Z3sL/6Iics2Ksld8EwKXk5bMO2FAbVza1nm2rOAF/t35fyQs
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/1C.pem b/scripts/resource-cert-samples/RIR/1C.pem
new file mode 100644
index 00000000..786dc6b4
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/1C.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 28 (0x1c)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:07:08 2007 GMT
+ Not After : Aug 9 01:07:08 2008 GMT
+ Subject: CN=TEST ENTITY LIR3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:a3:21:57:61:64:af:11:18:d4:cb:de:a6:dc:ad:
+ d9:2c:0f:0f:58:9f:7e:c8:85:55:11:26:4c:7c:f0:
+ 6b:68:1a:9e:6a:0c:8f:e6:dc:3d:83:58:2a:cc:77:
+ ac:19:73:6f:5a:f3:6e:24:ac:cd:1a:dc:1d:0b:4c:
+ 44:f5:6d:8b:0a:17:3d:86:f9:e8:fe:e6:60:e5:9f:
+ 40:6a:e5:94:e8:9a:56:17:17:1c:ab:c1:8c:37:40:
+ 2b:55:bf:2c:5e:dc:8d:ca:25:7f:8a:5f:ee:fb:16:
+ 86:eb:e0:08:d3:26:e5:e3:70:c5:0c:6b:fb:1b:8f:
+ 6b:5c:f6:e2:4a:58:a5:35:01:ea:05:1b:3e:ce:84:
+ be:b5:3f:6d:18:16:4b:68:e5:79:4c:88:7d:b6:a5:
+ 65:a3:3a:c2:32:dc:ad:8f:8a:05:ee:f6:e9:7a:80:
+ da:12:a9:0f:5a:b5:d2:d3:31:ac:3e:d3:19:25:2d:
+ 28:de:79:6c:ce:fd:77:66:d5:e3:2f:a9:cb:f9:85:
+ 8c:20:bb:a2:86:23:f0:93:95:20:04:78:c7:c7:07:
+ a6:fe:f0:f4:45:bb:cf:78:2b:dd:ce:9c:08:a5:46:
+ 68:10:4c:d7:05:62:6c:86:5a:2d:7f:06:38:c2:4d:
+ bb:44:87:00:43:79:d2:8f:f3:6b:b2:f4:5c:1c:b9:
+ 68:01
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 59:02:31:4f:92:0b:01:2d:98:ab:45:b8:7b:a9:b8:60:88:a1:
+ 8c:e3:84:e7:0b:20:a7:9c:e1:a2:7c:aa:9f:e3:a2:f2:5c:0e:
+ 55:bd:a7:1d:96:e1:fb:0c:16:7d:85:07:42:95:bf:e9:14:c5:
+ 6f:e5:91:84:88:b7:e7:3b:16:7a:77:08:8e:68:ff:da:44:65:
+ 04:65:3e:7e:18:5f:ed:56:62:57:fb:b6:da:b4:08:c9:cf:17:
+ bb:83:34:7a:49:f6:22:02:a4:49:d7:55:c5:d1:22:df:92:f3:
+ 65:5d:2c:de:ac:0e:f3:9c:18:36:f9:b7:8a:5f:df:d6:5d:84:
+ 31:7f:76:95:e2:59:53:4a:40:8e:99:6d:ae:3b:9d:86:ce:2a:
+ 75:1d:49:7c:26:3e:90:2b:34:87:c9:4a:7a:aa:70:59:68:d3:
+ 81:7f:1b:ee:fc:ea:72:65:60:c9:9e:94:50:8d:62:93:d5:7e:
+ 52:68:06:c9:d8:e5:bf:a0:db:cd:c2:90:93:0e:9f:1a:66:2f:
+ 14:16:4a:57:4a:15:bb:0e:d4:73:96:91:1b:a6:00:5f:77:13:
+ 03:a7:93:65:9a:df:03:42:a8:7c:4e:dc:89:32:ae:80:94:f7:
+ c3:d7:ed:33:7c:45:ea:34:4d:ea:fe:bd:31:50:c3:81:3f:12:
+ c8:1f:f8:63
+-----BEGIN CERTIFICATE-----
+MIID9DCCAtygAwIBAgIBHDANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwNzA4WhcNMDgwODA5MDEwNzA4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
+g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
+N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
+zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4IBQjCCAT4wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUmL4E/4DRq5U5qj3yDmd9AK2j/cUwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIzLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAh
+BggrBgEFBQcBCAEB/wQSMBCgDjAMMAoCAwD8FgIDAPwcMFEGCCsGAQUFBwEHAQH/
+BEIwQDASBAIAATAMAwQACgAAAwQACgMAMCoEAgACMCQDEAAgAQ24AAAAAAAAAAAK
+AAADEAAgAQ24AAAAAAAAAAAKAwAwDQYJKoZIhvcNAQELBQADggEBAFkCMU+SCwEt
+mKtFuHupuGCIoYzjhOcLIKec4aJ8qp/jovJcDlW9px2W4fsMFn2FB0KVv+kUxW/l
+kYSIt+c7Fnp3CI5o/9pEZQRlPn4YX+1WYlf7ttq0CMnPF7uDNHpJ9iICpEnXVcXR
+It+S82VdLN6sDvOcGDb5t4pf39ZdhDF/dpXiWVNKQI6Zba47nYbOKnUdSXwmPpAr
+NIfJSnqqcFlo04F/G+786nJlYMmelFCNYpPVflJoBsnY5b+g283CkJMOnxpmLxQW
+SldKFbsO1HOWkRumAF93EwOnk2Wa3wNCqHxO3IkyroCU98PX7TN8Reo0Ter+vTFQ
+w4E/Esgf+GM=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/1D.pem b/scripts/resource-cert-samples/RIR/1D.pem
new file mode 100644
index 00000000..ef7eb793
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/1D.pem
@@ -0,0 +1,95 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 29 (0x1d)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:07:08 2007 GMT
+ Not After : Aug 9 01:07:08 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 0c:51:a0:58:12:e3:9e:03:0a:45:a2:db:eb:7b:98:b1:32:a8:
+ 87:e2:0a:79:4d:a6:56:83:7c:a3:14:78:98:ba:4d:8f:e4:59:
+ 06:15:f6:3a:01:6c:5c:21:a5:1e:97:09:42:24:7c:11:a0:4e:
+ f3:9a:de:50:c2:88:2b:1b:59:6c:12:0e:26:10:40:21:16:e1:
+ 60:96:bb:4d:53:0f:79:47:28:e0:10:cf:61:f3:82:5f:3a:7f:
+ ec:e2:3f:f5:60:70:d8:ca:05:ce:cb:f9:49:f8:15:be:0e:18:
+ e2:f4:3c:f3:1f:5a:31:77:9d:e4:69:17:4a:4f:4d:d6:eb:58:
+ d6:c7:28:87:15:7c:d0:51:69:59:02:a9:e7:14:a8:d6:5f:6e:
+ 25:b3:2c:8b:ed:58:f7:84:40:ae:95:4d:67:f5:86:d8:2e:9b:
+ 1f:29:3a:38:a9:7b:8c:6f:62:df:31:a6:a3:17:ec:19:94:93:
+ c9:17:36:9b:51:6c:79:c7:4a:4a:08:25:ef:db:13:d8:de:95:
+ 80:87:28:aa:ae:3d:fb:d8:80:54:cb:31:f3:40:49:28:8f:08:
+ c9:dc:c3:6d:1d:de:16:57:11:f5:56:89:1d:5a:b9:54:d1:f0:
+ c4:48:c6:39:05:53:26:15:be:1a:dc:6c:70:6c:f9:71:59:d8:
+ 2f:f4:b4:81
+-----BEGIN CERTIFICATE-----
+MIID8DCCAtigAwIBAgIBHTANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwNzA4WhcNMDgwODA5MDEwNzA4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBPjCCATowDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEE
+AgACMDswJgMRAiABDbgAAAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEA
+IAENuAAAAAAAAAAQAAAARDANBgkqhkiG9w0BAQsFAAOCAQEADFGgWBLjngMKRaLb
+63uYsTKoh+IKeU2mVoN8oxR4mLpNj+RZBhX2OgFsXCGlHpcJQiR8EaBO85reUMKI
+KxtZbBIOJhBAIRbhYJa7TVMPeUco4BDPYfOCXzp/7OI/9WBw2MoFzsv5SfgVvg4Y
+4vQ88x9aMXed5GkXSk9N1utY1scohxV80FFpWQKp5xSo1l9uJbMsi+1Y94RArpVN
+Z/WG2C6bHyk6OKl7jG9i3zGmoxfsGZSTyRc2m1FsecdKSggl79sT2N6VgIcoqq49
++9iAVMsx80BJKI8IydzDbR3eFlcR9VaJHVq5VNHwxEjGOQVTJhW+GtxscGz5cVnY
+L/S0gQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/1E.pem b/scripts/resource-cert-samples/RIR/1E.pem
new file mode 100644
index 00000000..93d846b8
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/1E.pem
@@ -0,0 +1,94 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 30 (0x1e)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:07:08 2007 GMT
+ Not After : Aug 9 01:07:08 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 1e:aa:13:82:d7:ac:b4:cf:87:8f:61:5e:f4:b5:0a:2c:36:5f:
+ 6c:ae:a2:65:46:06:b2:f7:86:f5:81:a7:15:51:87:a8:f1:9d:
+ b8:37:e8:5a:27:9a:27:a6:c4:fc:eb:64:03:b1:b9:ee:93:e4:
+ 6f:b6:b8:d7:40:47:20:91:a2:ba:50:f0:c4:98:a6:96:14:3f:
+ 79:1a:8c:de:3e:b2:57:6a:7a:83:22:9d:8c:05:4e:22:46:4a:
+ de:98:7f:9d:78:9e:e4:43:10:8c:29:4f:9f:d0:51:a4:70:e4:
+ ed:ef:b6:72:99:08:8c:5d:c3:4e:60:82:66:05:ae:a0:b8:31:
+ 4f:77:33:c9:57:9a:7d:bc:d2:8c:1f:60:10:58:8d:db:0a:c0:
+ 96:f4:29:a7:e1:54:d5:fa:a7:50:93:fa:18:3d:e3:98:14:c4:
+ 9d:d5:61:af:31:79:f6:af:eb:07:ae:ce:58:e6:62:ed:a0:2a:
+ c3:4a:93:8b:03:06:6a:e8:2a:ef:c9:82:c7:ae:49:25:65:94:
+ 85:e6:94:d6:6f:71:17:c7:e6:ab:50:60:a3:c8:7e:e6:51:05:
+ de:e8:bf:d5:9d:90:9d:b6:a7:eb:97:4d:47:99:b0:d9:de:ae:
+ d9:de:fb:36:3c:c2:7b:f5:25:ed:72:1a:c4:6b:eb:7c:ad:37:
+ 34:04:c5:cb
+-----BEGIN CERTIFICATE-----
+MIID1TCCAr2gAwIBAgIBHjANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDEwNzA4WhcNMDgwODA5MDEwNzA4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBIzCCAR8wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYE
+AgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0B
+AQsFAAOCAQEAHqoTgtestM+Hj2Fe9LUKLDZfbK6iZUYGsveG9YGnFVGHqPGduDfo
+WieaJ6bE/OtkA7G57pPkb7a410BHIJGiulDwxJimlhQ/eRqM3j6yV2p6gyKdjAVO
+IkZK3ph/nXie5EMQjClPn9BRpHDk7e+2cpkIjF3DTmCCZgWuoLgxT3czyVeafbzS
+jB9gEFiN2wrAlvQpp+FU1fqnUJP6GD3jmBTEndVhrzF59q/rB67OWOZi7aAqw0qT
+iwMGaugq78mCx65JJWWUheaU1m9xF8fmq1Bgo8h+5lEF3ui/1Z2Qnban65dNR5mw
+2d6u2d77NjzCe/Ul7XIaxGvrfK03NATFyw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/1F.pem b/scripts/resource-cert-samples/RIR/1F.pem
new file mode 100644
index 00000000..9dd25967
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/1F.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 31 (0x1f)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 4f:b2:00:11:14:e9:a9:dc:f3:20:a2:78:94:b7:c5:dd:0c:ff:
+ fc:e1:68:13:24:a6:e1:f5:32:47:b2:3a:d4:4c:90:e2:cd:64:
+ ef:6d:7d:5c:35:01:96:8f:68:69:dd:be:ff:fa:a2:33:a4:23:
+ 28:e5:8d:2e:f6:05:fd:54:85:84:86:2f:01:ba:71:cd:b0:ea:
+ d5:ab:06:8a:55:15:1e:1e:55:e5:c2:f5:93:0d:43:fc:c8:2d:
+ f6:d7:57:8b:d9:71:9a:e6:8b:5a:ce:ea:5d:3c:e8:ae:66:7d:
+ 69:3f:6d:1e:bd:5d:f4:7b:69:90:bb:72:4a:f3:7c:8e:08:33:
+ 75:c9:48:53:20:16:ca:02:71:0f:6d:e7:bd:14:73:60:42:69:
+ 8f:2e:b9:f5:fb:39:e5:5d:51:94:7b:3f:d3:6d:25:64:f8:0c:
+ 68:e6:cd:d5:e1:10:da:d5:24:00:b0:3c:97:b1:69:e5:67:0b:
+ 05:1b:46:86:d1:d7:2f:17:0e:17:98:bb:54:9f:4e:60:40:0f:
+ 7a:77:9e:f0:33:d4:0a:8e:56:f9:57:30:a0:cf:b1:86:41:35:
+ dd:d3:f3:b3:35:56:4b:e1:83:ba:a0:9d:40:8d:d0:70:dc:ff:
+ 60:9d:73:15:84:c5:8a:20:2b:28:02:16:5a:dd:b0:19:ee:cb:
+ bd:ea:1f:9b
+-----BEGIN CERTIFICATE-----
+MIIDFDCCAfygAwIBAgIBHzANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExMzM5WhcNMDgwODA5MDExMzM5WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjZTBjMA8GA1UdEwEB/wQFMAMB
+Af8wDgYDVR0PAQH/BAQDAgEGMEAGCCsGAQUFBwELBDQwMjAwBggrBgEFBQcwBYYk
+cnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJuLm5ldC9SSVIvMA0GCSqGSIb3DQEB
+CwUAA4IBAQBPsgARFOmp3PMgoniUt8XdDP/84WgTJKbh9TJHsjrUTJDizWTvbX1c
+NQGWj2hp3b7/+qIzpCMo5Y0u9gX9VIWEhi8BunHNsOrVqwaKVRUeHlXlwvWTDUP8
+yC3211eL2XGa5otazupdPOiuZn1pP20evV30e2mQu3JK83yOCDN1yUhTIBbKAnEP
+bee9FHNgQmmPLrn1+znlXVGUez/TbSVk+Axo5s3V4RDa1SQAsDyXsWnlZwsFG0aG
+0dcvFw4XmLtUn05gQA96d57wM9QKjlb5VzCgz7GGQTXd0/OzNVZL4YO6oJ1AjdBw
+3P9gnXMVhMWKICsoAhZa3bAZ7su96h+b
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/20.pem b/scripts/resource-cert-samples/RIR/20.pem
new file mode 100644
index 00000000..fe5d4fc2
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/20.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 32 (0x20)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY LIR3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:a3:21:57:61:64:af:11:18:d4:cb:de:a6:dc:ad:
+ d9:2c:0f:0f:58:9f:7e:c8:85:55:11:26:4c:7c:f0:
+ 6b:68:1a:9e:6a:0c:8f:e6:dc:3d:83:58:2a:cc:77:
+ ac:19:73:6f:5a:f3:6e:24:ac:cd:1a:dc:1d:0b:4c:
+ 44:f5:6d:8b:0a:17:3d:86:f9:e8:fe:e6:60:e5:9f:
+ 40:6a:e5:94:e8:9a:56:17:17:1c:ab:c1:8c:37:40:
+ 2b:55:bf:2c:5e:dc:8d:ca:25:7f:8a:5f:ee:fb:16:
+ 86:eb:e0:08:d3:26:e5:e3:70:c5:0c:6b:fb:1b:8f:
+ 6b:5c:f6:e2:4a:58:a5:35:01:ea:05:1b:3e:ce:84:
+ be:b5:3f:6d:18:16:4b:68:e5:79:4c:88:7d:b6:a5:
+ 65:a3:3a:c2:32:dc:ad:8f:8a:05:ee:f6:e9:7a:80:
+ da:12:a9:0f:5a:b5:d2:d3:31:ac:3e:d3:19:25:2d:
+ 28:de:79:6c:ce:fd:77:66:d5:e3:2f:a9:cb:f9:85:
+ 8c:20:bb:a2:86:23:f0:93:95:20:04:78:c7:c7:07:
+ a6:fe:f0:f4:45:bb:cf:78:2b:dd:ce:9c:08:a5:46:
+ 68:10:4c:d7:05:62:6c:86:5a:2d:7f:06:38:c2:4d:
+ bb:44:87:00:43:79:d2:8f:f3:6b:b2:f4:5c:1c:b9:
+ 68:01
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR3/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 21:11:08:a5:7c:20:fa:f3:da:ce:31:cd:f4:f4:e2:dc:46:9c:
+ 7c:3f:b0:02:04:9c:f8:2e:63:c9:d6:2d:8c:01:44:ea:99:5e:
+ 50:e2:33:f0:20:0b:df:3d:a5:59:2d:16:d7:e7:8f:3b:f0:84:
+ 57:d0:23:a3:52:7c:27:34:af:62:b3:97:aa:c4:21:93:8d:34:
+ 8d:56:9b:8e:b5:b7:da:24:46:e8:2f:e7:b5:f3:92:2b:46:21:
+ b2:b2:1f:7a:c2:be:f4:af:5d:1b:18:bb:39:3c:ee:e3:18:25:
+ 22:b4:fd:72:0c:4c:5a:e2:99:75:28:9b:9c:81:a1:da:64:83:
+ cf:26:22:99:d8:77:b4:6a:80:84:5d:cc:cb:62:5c:f5:00:dc:
+ 72:14:33:20:90:06:20:01:ed:3a:08:28:a4:7c:e4:51:00:33:
+ 8b:09:8a:bc:8a:fa:f0:81:a9:ae:69:a6:e6:df:4c:4d:08:47:
+ cf:46:6f:03:eb:7e:85:86:34:9a:0d:18:51:24:39:cf:47:23:
+ 25:b3:6e:27:3f:f9:59:7e:da:e0:bf:08:e5:8f:55:f0:cf:e4:
+ c5:c1:f4:a9:91:ae:09:3e:41:1b:f0:76:2d:0f:a8:4d:05:8d:
+ 3c:3e:81:81:ec:6c:62:2d:3a:63:81:12:b2:36:23:ed:25:8c:
+ b5:f4:3d:e1
+-----BEGIN CERTIFICATE-----
+MIIDFjCCAf6gAwIBAgIBIDANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExMzM5WhcNMDgwODA5MDExMzM5WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
+g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
+N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
+zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo2YwZDAPBgNVHRMBAf8EBTAD
+AQH/MA4GA1UdDwEB/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWG
+JXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy8wDQYJKoZIhvcN
+AQELBQADggEBACERCKV8IPrz2s4xzfT04txGnHw/sAIEnPguY8nWLYwBROqZXlDi
+M/AgC989pVktFtfnjzvwhFfQI6NSfCc0r2Kzl6rEIZONNI1Wm461t9okRugv57Xz
+kitGIbKyH3rCvvSvXRsYuzk87uMYJSK0/XIMTFrimXUom5yBodpkg88mIpnYd7Rq
+gIRdzMtiXPUA3HIUMyCQBiAB7ToIKKR85FEAM4sJiryK+vCBqa5ppubfTE0IR89G
+bwPrfoWGNJoNGFEkOc9HIyWzbic/+Vl+2uC/COWPVfDP5MXB9KmRrgk+QRvwdi0P
+qE0FjTw+gYHsbGItOmOBErI2I+0ljLX0PeE=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/21.pem b/scripts/resource-cert-samples/RIR/21.pem
new file mode 100644
index 00000000..0465b7a4
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/21.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 33 (0x21)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 69:44:b7:68:fa:e8:4a:16:7e:93:63:18:39:f4:3b:12:19:62:
+ 6b:9a:b8:2e:cf:b4:26:a7:fc:e1:01:9a:c9:33:00:34:47:76:
+ 24:1d:c3:09:65:fb:d4:68:31:47:ca:e8:07:20:6f:af:fe:ad:
+ 28:19:d5:12:31:d7:dd:60:3f:35:6d:fd:02:7a:a6:99:42:d5:
+ f4:c7:42:34:8f:53:20:a2:fb:8c:f6:87:97:c9:81:95:09:02:
+ a5:60:ad:0c:2d:01:15:8a:92:16:34:d6:5b:2e:ac:95:4f:93:
+ 04:27:ac:47:d8:f4:48:53:36:bc:2a:77:4b:16:f9:21:be:a4:
+ 85:65:62:9d:75:68:dd:95:fb:0f:74:2d:e0:be:4a:8b:86:88:
+ 03:fa:e4:58:a9:46:51:26:b4:d7:5c:a8:cf:6a:29:86:be:68:
+ 66:46:e0:92:b2:18:9a:14:e9:c0:02:51:68:31:9c:17:75:ac:
+ 86:b1:e1:41:d7:22:4d:9c:ef:55:4d:2a:85:0b:62:e6:b2:5c:
+ 04:8e:09:21:0a:a7:f6:cd:1e:f3:00:20:71:01:55:cf:7d:a0:
+ 03:85:82:49:7e:7a:e0:ba:a8:c8:e7:43:a7:29:08:f7:b6:ad:
+ fe:f7:4a:69:a5:03:47:87:c5:87:bd:f1:86:6e:ea:5b:34:51:
+ fe:00:a9:a7
+-----BEGIN CERTIFICATE-----
+MIIDFjCCAf6gAwIBAgIBITANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExMzM5WhcNMDgwODA5MDExMzM5WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo2YwZDAPBgNVHRMBAf8EBTAD
+AQH/MA4GA1UdDwEB/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWG
+JXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMi8wDQYJKoZIhvcN
+AQELBQADggEBAGlEt2j66EoWfpNjGDn0OxIZYmuauC7PtCan/OEBmskzADRHdiQd
+wwll+9RoMUfK6Acgb6/+rSgZ1RIx191gPzVt/QJ6pplC1fTHQjSPUyCi+4z2h5fJ
+gZUJAqVgrQwtARWKkhY01lsurJVPkwQnrEfY9EhTNrwqd0sW+SG+pIVlYp11aN2V
++w90LeC+SouGiAP65FipRlEmtNdcqM9qKYa+aGZG4JKyGJoU6cACUWgxnBd1rIax
+4UHXIk2c71VNKoULYuayXASOCSEKp/bNHvMAIHEBVc99oAOFgkl+euC6qMjnQ6cp
+CPe2rf73SmmlA0eHxYe98YZu6ls0Uf4Aqac=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/22.pem b/scripts/resource-cert-samples/RIR/22.pem
new file mode 100644
index 00000000..f46564dd
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/22.pem
@@ -0,0 +1,76 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 34 (0x22)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:13:39 2007 GMT
+ Not After : Aug 9 01:13:39 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 64:a2:b2:a2:9e:50:69:0e:9f:15:f1:85:10:e8:5e:bf:22:c0:
+ 2e:4c:58:1c:43:c8:ba:7d:3d:67:8c:a6:94:99:b0:fc:ec:2c:
+ e2:0c:69:a7:d6:9e:35:b7:06:bd:d0:30:9a:ba:c9:1c:49:96:
+ ee:06:68:45:e3:ed:48:4d:7a:c0:68:4f:57:52:e6:e7:f1:1c:
+ 14:58:d5:a2:da:d0:19:c5:e9:c4:63:4f:bc:3b:10:8b:2e:fe:
+ b7:95:8a:f4:7e:00:ac:f8:5b:dc:4e:70:81:d7:9e:d8:4b:e8:
+ 89:03:05:3e:11:dc:8f:7a:45:a3:14:78:5f:9d:dc:fe:7f:fd:
+ 4a:b0:bb:33:e0:7c:46:f4:e3:df:f7:2b:9e:64:44:ba:39:b0:
+ d4:72:a3:cf:35:55:ae:04:29:ed:d8:23:22:b0:a3:16:d2:5d:
+ 69:b9:c6:5a:e5:53:42:71:2b:5e:37:e1:1e:26:42:ce:29:23:
+ 64:2e:51:fd:a9:e4:9b:20:65:b1:f1:c2:ce:14:56:10:68:2f:
+ fc:f3:eb:55:6d:d7:a0:0e:1a:0c:52:4a:81:47:e6:34:1f:9e:
+ 3a:c5:38:2e:e6:f2:43:bf:f8:e3:cb:cd:44:83:4f:7c:fb:69:
+ a9:41:96:d6:50:22:b7:3c:06:e0:09:ff:34:cb:41:f6:17:97:
+ 86:7d:f0:c5
+-----BEGIN CERTIFICATE-----
+MIIDFjCCAf6gAwIBAgIBIjANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExMzM5WhcNMDgwODA5MDExMzM5WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo2YwZDAPBgNVHRMBAf8EBTAD
+AQH/MA4GA1UdDwEB/wQEAwIBBjBBBggrBgEFBQcBCwQ1MDMwMQYIKwYBBQUHMAWG
+JXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMS8wDQYJKoZIhvcN
+AQELBQADggEBAGSisqKeUGkOnxXxhRDoXr8iwC5MWBxDyLp9PWeMppSZsPzsLOIM
+aafWnjW3Br3QMJq6yRxJlu4GaEXj7UhNesBoT1dS5ufxHBRY1aLa0BnF6cRjT7w7
+EIsu/reVivR+AKz4W9xOcIHXnthL6IkDBT4R3I96RaMUeF+d3P5//UqwuzPgfEb0
+49/3K55kRLo5sNRyo881Va4EKe3YIyKwoxbSXWm5xlrlU0JxK1434R4mQs4pI2Qu
+Uf2p5JsgZbHxws4UVhBoL/zz61Vt16AOGgxSSoFH5jQfnjrFOC7m8kO/+OPLzUSD
+T3z7aalBltZQIrc8BuAJ/zTLQfYXl4Z98MU=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/23.pem b/scripts/resource-cert-samples/RIR/23.pem
new file mode 100644
index 00000000..62954cf1
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/23.pem
@@ -0,0 +1,100 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 35 (0x23)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:15:09 2007 GMT
+ Not After : Aug 9 01:15:09 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533-64540
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 6b:3e:b4:ef:05:b1:6c:d0:7f:e1:86:49:86:64:44:10:16:65:
+ d2:ae:52:cf:da:08:79:bd:08:a2:fc:3b:90:bf:ec:6a:a3:cc:
+ 78:51:cf:f9:c7:9a:65:5e:a9:11:b3:db:76:0a:2d:14:96:c5:
+ d0:21:22:f1:64:b3:2c:ea:2e:20:f1:52:32:8d:c9:9a:3c:eb:
+ d1:82:53:e9:57:c9:01:ed:4f:c7:0f:b5:1f:a7:8f:1a:9d:9b:
+ 42:b2:c8:fa:c0:e9:24:7c:ea:b3:26:55:54:6c:fb:fc:36:3d:
+ 42:84:e1:b1:40:62:d9:d8:59:fd:02:9d:c9:eb:69:54:47:1a:
+ d6:b8:0a:ee:27:0c:59:ea:a4:e7:73:a8:cd:47:14:e0:2e:68:
+ f3:46:79:a9:7c:d6:07:8c:06:26:d1:66:7a:a5:e8:56:f8:5e:
+ f8:37:49:0a:f1:52:5c:78:c0:92:90:81:05:a5:4a:a7:60:0f:
+ 4b:d3:62:14:70:be:5f:90:5b:54:9f:79:d9:a8:c9:50:bc:ab:
+ ed:17:e6:a2:e0:25:b8:74:56:8c:12:66:19:41:fc:ed:eb:37:
+ 21:e5:3f:56:d0:d5:ee:f2:e6:d4:53:4e:ae:78:d4:50:fd:dd:
+ 03:6a:e3:29:72:5a:40:d5:3c:90:8e:d2:77:d2:28:9e:cb:77:
+ 85:8c:c3:e1
+-----BEGIN CERTIFICATE-----
+MIIEEDCCAvigAwIBAgIBIzANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTA5WhcNMDgwODA5MDExNTA5WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFfMIIBWzAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8E
+BAMCAQYwQAYIKwYBBQUHAQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJh
+dHMtci11cy5oYWN0cm4ubmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAK
+AgMA/BUCAwD8HAIDAPwgMIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQA
+CgAAAwQACgMAMA4DBQDAAAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIw
+XzAmAxECIAENuAAAAAAAAAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24
+AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABE
+MA0GCSqGSIb3DQEBCwUAA4IBAQBrPrTvBbFs0H/hhkmGZEQQFmXSrlLP2gh5vQii
+/DuQv+xqo8x4Uc/5x5plXqkRs9t2Ci0UlsXQISLxZLMs6i4g8VIyjcmaPOvRglPp
+V8kB7U/HD7Ufp48anZtCssj6wOkkfOqzJlVUbPv8Nj1ChOGxQGLZ2Fn9Ap3J62lU
+RxrWuAruJwxZ6qTnc6jNRxTgLmjzRnmpfNYHjAYm0WZ6pehW+F74N0kK8VJceMCS
+kIEFpUqnYA9L02IUcL5fkFtUn3nZqMlQvKvtF+ai4CW4dFaMEmYZQfzt6zch5T9W
+0NXu8ubUU06ueNRQ/d0DauMpclpA1TyQjtJ30iiey3eFjMPh
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/24.pem b/scripts/resource-cert-samples/RIR/24.pem
new file mode 100644
index 00000000..419b192d
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/24.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 36 (0x24)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY LIR3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:a3:21:57:61:64:af:11:18:d4:cb:de:a6:dc:ad:
+ d9:2c:0f:0f:58:9f:7e:c8:85:55:11:26:4c:7c:f0:
+ 6b:68:1a:9e:6a:0c:8f:e6:dc:3d:83:58:2a:cc:77:
+ ac:19:73:6f:5a:f3:6e:24:ac:cd:1a:dc:1d:0b:4c:
+ 44:f5:6d:8b:0a:17:3d:86:f9:e8:fe:e6:60:e5:9f:
+ 40:6a:e5:94:e8:9a:56:17:17:1c:ab:c1:8c:37:40:
+ 2b:55:bf:2c:5e:dc:8d:ca:25:7f:8a:5f:ee:fb:16:
+ 86:eb:e0:08:d3:26:e5:e3:70:c5:0c:6b:fb:1b:8f:
+ 6b:5c:f6:e2:4a:58:a5:35:01:ea:05:1b:3e:ce:84:
+ be:b5:3f:6d:18:16:4b:68:e5:79:4c:88:7d:b6:a5:
+ 65:a3:3a:c2:32:dc:ad:8f:8a:05:ee:f6:e9:7a:80:
+ da:12:a9:0f:5a:b5:d2:d3:31:ac:3e:d3:19:25:2d:
+ 28:de:79:6c:ce:fd:77:66:d5:e3:2f:a9:cb:f9:85:
+ 8c:20:bb:a2:86:23:f0:93:95:20:04:78:c7:c7:07:
+ a6:fe:f0:f4:45:bb:cf:78:2b:dd:ce:9c:08:a5:46:
+ 68:10:4c:d7:05:62:6c:86:5a:2d:7f:06:38:c2:4d:
+ bb:44:87:00:43:79:d2:8f:f3:6b:b2:f4:5c:1c:b9:
+ 68:01
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 2a:bc:5b:b8:bc:0a:4f:52:b5:d5:01:bd:97:c3:79:df:8f:fd:
+ 7b:d7:0f:fd:fc:0c:8c:3f:69:b0:24:c0:b0:65:63:bf:ca:62:
+ 41:29:04:0a:52:73:b3:e1:c8:18:89:77:ba:b8:7c:6a:b7:19:
+ d7:b7:93:fa:dc:62:78:f9:bd:67:45:be:cd:97:bc:b7:f0:47:
+ 95:9b:97:92:70:ae:9c:58:04:49:d7:fa:af:2e:9e:d1:57:22:
+ 5b:10:c3:38:68:94:bf:0f:a8:a6:f4:1f:06:59:49:57:30:11:
+ 77:66:2a:f4:64:65:13:40:6b:e4:a9:6b:4d:75:4a:11:53:ab:
+ 28:44:67:b5:be:45:48:47:bf:67:61:4f:83:63:bf:33:3a:68:
+ 88:4e:0e:3a:60:79:86:52:65:a0:43:c6:0a:b8:ce:bc:37:eb:
+ 3c:7e:ed:11:f7:e6:42:c0:64:52:70:b3:5c:4c:dc:ed:49:96:
+ 64:2d:a6:19:27:87:11:ed:2d:10:96:c1:7f:ae:2d:a7:98:31:
+ 70:9b:35:1d:87:b9:ec:33:0a:f3:c3:d4:47:b6:7b:ff:7a:9f:
+ 04:a8:b6:bd:9d:10:12:e1:24:5a:44:5c:5b:68:c4:9a:09:64:
+ 27:21:aa:f1:d4:05:42:37:41:4f:8d:f9:0a:e2:c6:3b:94:76:
+ d9:d7:97:66
+-----BEGIN CERTIFICATE-----
+MIID9DCCAtygAwIBAgIBJDANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTEwWhcNMDgwODA5MDExNTEwWjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
+g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
+N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
+zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4IBQjCCAT4wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUmL4E/4DRq5U5qj3yDmd9AK2j/cUwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIzLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAh
+BggrBgEFBQcBCAEB/wQSMBCgDjAMMAoCAwD8FgIDAPwcMFEGCCsGAQUFBwEHAQH/
+BEIwQDASBAIAATAMAwQACgAAAwQACgMAMCoEAgACMCQDEAAgAQ24AAAAAAAAAAAK
+AAADEAAgAQ24AAAAAAAAAAAKAwAwDQYJKoZIhvcNAQELBQADggEBACq8W7i8Ck9S
+tdUBvZfDed+P/XvXD/38DIw/abAkwLBlY7/KYkEpBApSc7PhyBiJd7q4fGq3Gde3
+k/rcYnj5vWdFvs2XvLfwR5Wbl5JwrpxYBEnX+q8untFXIlsQwzholL8PqKb0HwZZ
+SVcwEXdmKvRkZRNAa+Spa011ShFTqyhEZ7W+RUhHv2dhT4NjvzM6aIhODjpgeYZS
+ZaBDxgq4zrw36zx+7RH35kLAZFJws1xM3O1JlmQtphknhxHtLRCWwX+uLaeYMXCb
+NR2HuewzCvPD1Ee2e/96nwSotr2dEBLhJFpEXFtoxJoJZCchqvHUBUI3QU+N+Qri
+xjuUdtnXl2Y=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/25.pem b/scripts/resource-cert-samples/RIR/25.pem
new file mode 100644
index 00000000..06ca26ad
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/25.pem
@@ -0,0 +1,95 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 37 (0x25)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 13:0b:5a:02:21:8a:26:5a:fd:8a:66:9c:ff:7c:61:aa:43:72:
+ d0:ac:b7:9f:91:85:a9:3d:97:2b:4c:cb:5b:c1:69:0d:d2:32:
+ 28:2b:5e:e6:fe:2b:71:1f:62:72:b0:ea:fd:5b:86:b0:86:09:
+ e8:a1:53:86:5a:7c:58:3d:b1:74:6d:9a:40:08:b6:33:46:7d:
+ 03:43:13:03:d3:c3:13:8c:71:92:5d:c0:76:bb:e0:08:95:4b:
+ ca:ac:0a:c5:3d:d2:50:f5:96:8a:db:c2:ea:d0:f7:a2:00:fa:
+ 10:19:44:1e:5b:93:30:ff:0f:e9:af:81:a2:6d:c4:46:d7:af:
+ e9:a7:42:7c:ba:db:9f:b9:46:3d:f5:b2:19:81:2c:a7:c6:56:
+ d1:37:3e:50:f1:93:0a:8a:0a:81:42:c6:f1:7f:e0:63:fa:a1:
+ 7b:74:c6:ea:be:d7:37:5c:df:c1:8f:46:81:d8:a2:ce:d9:ee:
+ d9:03:71:8c:cb:1c:69:2a:29:8e:09:58:de:09:7b:93:ab:7b:
+ b6:56:a0:22:1c:31:e9:4d:13:19:ae:ab:f5:fa:19:5a:ad:54:
+ 46:d1:6b:b3:48:7c:ac:41:75:9b:87:10:bd:ab:fa:df:37:a8:
+ 29:37:65:8b:f4:90:81:85:0f:e8:e4:6e:df:84:ab:4f:99:ae:
+ 67:b9:8c:db
+-----BEGIN CERTIFICATE-----
+MIID8DCCAtigAwIBAgIBJTANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTEwWhcNMDgwODA5MDExNTEwWjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBPjCCATowDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEE
+AgACMDswJgMRAiABDbgAAAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEA
+IAENuAAAAAAAAAAQAAAARDANBgkqhkiG9w0BAQsFAAOCAQEAEwtaAiGKJlr9imac
+/3xhqkNy0Ky3n5GFqT2XK0zLW8FpDdIyKCte5v4rcR9icrDq/VuGsIYJ6KFThlp8
+WD2xdG2aQAi2M0Z9A0MTA9PDE4xxkl3AdrvgCJVLyqwKxT3SUPWWitvC6tD3ogD6
+EBlEHluTMP8P6a+Bom3ERtev6adCfLrbn7lGPfWyGYEsp8ZW0Tc+UPGTCooKgULG
+8X/gY/qhe3TG6r7XN1zfwY9Ggdiiztnu2QNxjMscaSopjglY3gl7k6t7tlagIhwx
+6U0TGa6r9foZWq1URtFrs0h8rEF1m4cQvav63zeoKTdli/SQgYUP6ORu34SrT5mu
+Z7mM2w==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/26.pem b/scripts/resource-cert-samples/RIR/26.pem
new file mode 100644
index 00000000..77486c96
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/26.pem
@@ -0,0 +1,94 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 38 (0x26)
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 10 01:15:10 2007 GMT
+ Not After : Aug 9 01:15:10 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha256WithRSAEncryption
+ 5d:4b:e6:c3:ad:38:f8:49:32:34:7c:6a:06:ed:d0:7a:cf:9a:
+ c8:a9:22:e5:46:93:37:f1:ec:4d:cd:26:43:f6:e8:ea:7a:5c:
+ 08:2a:7d:e3:37:e4:98:45:16:d2:a8:0b:eb:df:d4:a0:91:04:
+ 35:40:a8:c7:a5:c9:db:86:03:e3:e0:c4:17:6a:27:49:e6:4b:
+ 63:68:84:0c:57:5a:ac:43:79:4e:05:41:05:e5:fc:89:f7:f4:
+ 03:95:7c:b2:9e:d8:aa:a4:b5:35:26:58:96:e0:f6:70:08:f2:
+ de:5c:f5:0a:c9:6a:21:3a:e6:c7:19:af:e3:d9:b1:50:e2:bf:
+ db:28:df:3c:ae:e3:29:8f:22:b6:7a:a9:f6:f4:f3:7f:48:92:
+ da:f4:f5:19:4d:50:63:e0:87:f6:9e:fc:8f:5e:3a:d0:81:3b:
+ 8d:8a:7a:8a:0c:e9:24:a3:83:16:ca:24:4e:ef:80:7a:61:1e:
+ 96:ee:5f:8d:07:68:e5:c2:13:44:30:60:02:71:9b:ef:5b:df:
+ cc:a6:62:60:95:38:41:ff:93:e9:9f:c7:b8:60:34:93:db:55:
+ 2b:e7:27:91:d9:06:56:8e:a4:38:28:ae:dc:02:b4:fd:33:d0:
+ 17:4a:29:0f:86:19:ed:48:dc:5a:b4:e4:7a:8d:de:bc:10:c1:
+ 14:d5:b2:59
+-----BEGIN CERTIFICATE-----
+MIID1TCCAr2gAwIBAgIBJjANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODEwMDExNTEwWhcNMDgwODA5MDExNTEwWjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBIzCCAR8wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwDgYDVR0PAQH/
+BAQDAgEGMEEGCCsGAQUFBwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21i
+YXRzLXItdXMuaGFjdHJuLm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYB
+BQUHMAKGJ3JzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAa
+BggrBgEFBQcBCAEB/wQLMAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYE
+AgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0B
+AQsFAAOCAQEAXUvmw604+EkyNHxqBu3Qes+ayKki5UaTN/HsTc0mQ/bo6npcCCp9
+4zfkmEUW0qgL69/UoJEENUCox6XJ24YD4+DEF2onSeZLY2iEDFdarEN5TgVBBeX8
+iff0A5V8sp7YqqS1NSZYluD2cAjy3lz1CslqITrmxxmv49mxUOK/2yjfPK7jKY8i
+tnqp9vTzf0iS2vT1GU1QY+CH9p78j1460IE7jYp6igzpJKODFsokTu+AemEelu5f
+jQdo5cITRDBgAnGb71vfzKZiYJU4Qf+T6Z/HuGA0k9tVK+cnkdkGVo6kOCiu3AK0
+/TPQF0opD4YZ7UjcWrTkeo3evBDBFNWyWQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/index b/scripts/resource-cert-samples/RIR/index
index 754becc3..c4154d2c 100644
--- a/scripts/resource-cert-samples/RIR/index
+++ b/scripts/resource-cert-samples/RIR/index
@@ -14,3 +14,25 @@ V 080731144816Z 0D unknown /CN=TEST ENTITY RIR
V 080731144818Z 0E unknown /CN=TEST ENTITY LIR3
V 080731144818Z 0F unknown /CN=TEST ENTITY LIR2
V 080731144818Z 10 unknown /CN=TEST ENTITY LIR1
+V 080808233059Z 11 unknown /CN=TEST ENTITY RIR
+V 080808233548Z 12 unknown /CN=TEST ENTITY RIR
+V 080809005817Z 13 unknown /CN=TEST ENTITY RIR
+V 080809005817Z 14 unknown /CN=TEST ENTITY LIR3
+V 080809005817Z 15 unknown /CN=TEST ENTITY LIR2
+V 080809005817Z 16 unknown /CN=TEST ENTITY LIR1
+V 080809010231Z 17 unknown /CN=TEST ENTITY RIR
+V 080809010231Z 18 unknown /CN=TEST ENTITY LIR3
+V 080809010231Z 19 unknown /CN=TEST ENTITY LIR2
+V 080809010231Z 1A unknown /CN=TEST ENTITY LIR1
+V 080809010708Z 1B unknown /CN=TEST ENTITY RIR
+V 080809010708Z 1C unknown /CN=TEST ENTITY LIR3
+V 080809010708Z 1D unknown /CN=TEST ENTITY LIR2
+V 080809010708Z 1E unknown /CN=TEST ENTITY LIR1
+V 080809011339Z 1F unknown /CN=TEST ENTITY RIR
+V 080809011339Z 20 unknown /CN=TEST ENTITY LIR3
+V 080809011339Z 21 unknown /CN=TEST ENTITY LIR2
+V 080809011339Z 22 unknown /CN=TEST ENTITY LIR1
+V 080809011509Z 23 unknown /CN=TEST ENTITY RIR
+V 080809011510Z 24 unknown /CN=TEST ENTITY LIR3
+V 080809011510Z 25 unknown /CN=TEST ENTITY LIR2
+V 080809011510Z 26 unknown /CN=TEST ENTITY LIR1
diff --git a/scripts/resource-cert-samples/RIR/index.old b/scripts/resource-cert-samples/RIR/index.old
index 6ed26aac..67898d16 100644
--- a/scripts/resource-cert-samples/RIR/index.old
+++ b/scripts/resource-cert-samples/RIR/index.old
@@ -13,3 +13,25 @@ V 080731140934Z 0C unknown /CN=TEST ENTITY LIR1
V 080731144816Z 0D unknown /CN=TEST ENTITY RIR
V 080731144818Z 0E unknown /CN=TEST ENTITY LIR3
V 080731144818Z 0F unknown /CN=TEST ENTITY LIR2
+V 080731144818Z 10 unknown /CN=TEST ENTITY LIR1
+V 080808233059Z 11 unknown /CN=TEST ENTITY RIR
+V 080808233548Z 12 unknown /CN=TEST ENTITY RIR
+V 080809005817Z 13 unknown /CN=TEST ENTITY RIR
+V 080809005817Z 14 unknown /CN=TEST ENTITY LIR3
+V 080809005817Z 15 unknown /CN=TEST ENTITY LIR2
+V 080809005817Z 16 unknown /CN=TEST ENTITY LIR1
+V 080809010231Z 17 unknown /CN=TEST ENTITY RIR
+V 080809010231Z 18 unknown /CN=TEST ENTITY LIR3
+V 080809010231Z 19 unknown /CN=TEST ENTITY LIR2
+V 080809010231Z 1A unknown /CN=TEST ENTITY LIR1
+V 080809010708Z 1B unknown /CN=TEST ENTITY RIR
+V 080809010708Z 1C unknown /CN=TEST ENTITY LIR3
+V 080809010708Z 1D unknown /CN=TEST ENTITY LIR2
+V 080809010708Z 1E unknown /CN=TEST ENTITY LIR1
+V 080809011339Z 1F unknown /CN=TEST ENTITY RIR
+V 080809011339Z 20 unknown /CN=TEST ENTITY LIR3
+V 080809011339Z 21 unknown /CN=TEST ENTITY LIR2
+V 080809011339Z 22 unknown /CN=TEST ENTITY LIR1
+V 080809011509Z 23 unknown /CN=TEST ENTITY RIR
+V 080809011510Z 24 unknown /CN=TEST ENTITY LIR3
+V 080809011510Z 25 unknown /CN=TEST ENTITY LIR2
diff --git a/scripts/resource-cert-samples/RIR/serial b/scripts/resource-cert-samples/RIR/serial
index b4de3947..f64f5d8d 100644
--- a/scripts/resource-cert-samples/RIR/serial
+++ b/scripts/resource-cert-samples/RIR/serial
@@ -1 +1 @@
-11
+27
diff --git a/scripts/resource-cert-samples/RIR/serial.old b/scripts/resource-cert-samples/RIR/serial.old
index f599e28b..6f4247a6 100644
--- a/scripts/resource-cert-samples/RIR/serial.old
+++ b/scripts/resource-cert-samples/RIR/serial.old
@@ -1 +1 @@
-10
+26