aboutsummaryrefslogtreecommitdiff
path: root/scripts
diff options
context:
space:
mode:
authorRob Austein <sra@hactrn.net>2007-08-01 19:43:29 +0000
committerRob Austein <sra@hactrn.net>2007-08-01 19:43:29 +0000
commitb3ccbaca9cc2d7f6f50a5d0ddd51e187521286bc (patch)
treefaf5d64487aab8ab5783a9bcc1a18c34a8e8301e /scripts
parent1a05583256a6e4c771f9f5654012c020066bd6cf (diff)
Save sample certs now that I've embedded some of them in sample XML.
svn path=/scripts/resource-cert-samples/.stamp; revision=811
Diffstat (limited to 'scripts')
-rw-r--r--scripts/resource-cert-samples/.stamp0
-rw-r--r--scripts/resource-cert-samples/ISP1.cer96
-rw-r--r--scripts/resource-cert-samples/ISP1.cnf51
-rw-r--r--scripts/resource-cert-samples/ISP1.key27
-rw-r--r--scripts/resource-cert-samples/ISP1.req15
-rw-r--r--scripts/resource-cert-samples/ISP1/index0
-rw-r--r--scripts/resource-cert-samples/ISP1/serial1
-rw-r--r--scripts/resource-cert-samples/ISP2.cer92
-rw-r--r--scripts/resource-cert-samples/ISP2.cnf51
-rw-r--r--scripts/resource-cert-samples/ISP2.key27
-rw-r--r--scripts/resource-cert-samples/ISP2.req15
-rw-r--r--scripts/resource-cert-samples/ISP2/index0
-rw-r--r--scripts/resource-cert-samples/ISP2/serial1
-rw-r--r--scripts/resource-cert-samples/ISP3.cer92
-rw-r--r--scripts/resource-cert-samples/ISP3.cnf51
-rw-r--r--scripts/resource-cert-samples/ISP3.key27
-rw-r--r--scripts/resource-cert-samples/ISP3.req15
-rw-r--r--scripts/resource-cert-samples/ISP3/index0
-rw-r--r--scripts/resource-cert-samples/ISP3/serial1
-rw-r--r--scripts/resource-cert-samples/ISP4.cer96
-rw-r--r--scripts/resource-cert-samples/ISP4.cnf51
-rw-r--r--scripts/resource-cert-samples/ISP4.key27
-rw-r--r--scripts/resource-cert-samples/ISP4.req15
-rw-r--r--scripts/resource-cert-samples/ISP4/index0
-rw-r--r--scripts/resource-cert-samples/ISP4/serial1
-rw-r--r--scripts/resource-cert-samples/ISP5a.cer94
-rw-r--r--scripts/resource-cert-samples/ISP5a.cnf51
-rw-r--r--scripts/resource-cert-samples/ISP5a.key27
-rw-r--r--scripts/resource-cert-samples/ISP5a.req15
-rw-r--r--scripts/resource-cert-samples/ISP5a/index0
-rw-r--r--scripts/resource-cert-samples/ISP5a/serial1
-rw-r--r--scripts/resource-cert-samples/ISP5b.cer94
-rw-r--r--scripts/resource-cert-samples/ISP5b.cnf51
-rw-r--r--scripts/resource-cert-samples/ISP5b.key27
-rw-r--r--scripts/resource-cert-samples/ISP5b.req15
-rw-r--r--scripts/resource-cert-samples/ISP5b/index0
-rw-r--r--scripts/resource-cert-samples/ISP5b/serial1
-rw-r--r--scripts/resource-cert-samples/ISP5c.cer92
-rw-r--r--scripts/resource-cert-samples/ISP5c.cnf51
-rw-r--r--scripts/resource-cert-samples/ISP5c.key27
-rw-r--r--scripts/resource-cert-samples/ISP5c.req15
-rw-r--r--scripts/resource-cert-samples/ISP5c/index0
-rw-r--r--scripts/resource-cert-samples/ISP5c/serial1
-rw-r--r--scripts/resource-cert-samples/LIR1.cer98
-rw-r--r--scripts/resource-cert-samples/LIR1.cnf51
-rw-r--r--scripts/resource-cert-samples/LIR1.key27
-rw-r--r--scripts/resource-cert-samples/LIR1.req15
-rw-r--r--scripts/resource-cert-samples/LIR1/01.pem23
-rw-r--r--scripts/resource-cert-samples/LIR1/02.pem23
-rw-r--r--scripts/resource-cert-samples/LIR1/03.pem92
-rw-r--r--scripts/resource-cert-samples/LIR1/04.pem96
-rw-r--r--scripts/resource-cert-samples/LIR1/05.pem92
-rw-r--r--scripts/resource-cert-samples/LIR1/06.pem96
-rw-r--r--scripts/resource-cert-samples/LIR1/07.pem92
-rw-r--r--scripts/resource-cert-samples/LIR1/08.pem96
-rw-r--r--scripts/resource-cert-samples/LIR1/09.pem92
-rw-r--r--scripts/resource-cert-samples/LIR1/0A.pem96
-rw-r--r--scripts/resource-cert-samples/LIR1/index10
-rw-r--r--scripts/resource-cert-samples/LIR1/index.attr1
-rw-r--r--scripts/resource-cert-samples/LIR1/index.attr.old1
-rw-r--r--scripts/resource-cert-samples/LIR1/index.old9
-rw-r--r--scripts/resource-cert-samples/LIR1/serial1
-rw-r--r--scripts/resource-cert-samples/LIR1/serial.old1
-rw-r--r--scripts/resource-cert-samples/LIR2.cer98
-rw-r--r--scripts/resource-cert-samples/LIR2.cnf51
-rw-r--r--scripts/resource-cert-samples/LIR2.key27
-rw-r--r--scripts/resource-cert-samples/LIR2.req15
-rw-r--r--scripts/resource-cert-samples/LIR2/01.pem23
-rw-r--r--scripts/resource-cert-samples/LIR2/02.pem23
-rw-r--r--scripts/resource-cert-samples/LIR2/03.pem96
-rw-r--r--scripts/resource-cert-samples/LIR2/04.pem92
-rw-r--r--scripts/resource-cert-samples/LIR2/05.pem96
-rw-r--r--scripts/resource-cert-samples/LIR2/06.pem92
-rw-r--r--scripts/resource-cert-samples/LIR2/07.pem96
-rw-r--r--scripts/resource-cert-samples/LIR2/08.pem92
-rw-r--r--scripts/resource-cert-samples/LIR2/09.pem96
-rw-r--r--scripts/resource-cert-samples/LIR2/0A.pem92
-rw-r--r--scripts/resource-cert-samples/LIR2/index10
-rw-r--r--scripts/resource-cert-samples/LIR2/index.attr1
-rw-r--r--scripts/resource-cert-samples/LIR2/index.attr.old1
-rw-r--r--scripts/resource-cert-samples/LIR2/index.old9
-rw-r--r--scripts/resource-cert-samples/LIR2/serial1
-rw-r--r--scripts/resource-cert-samples/LIR2/serial.old1
-rw-r--r--scripts/resource-cert-samples/LIR3.cer101
-rw-r--r--scripts/resource-cert-samples/LIR3.cnf51
-rw-r--r--scripts/resource-cert-samples/LIR3.key27
-rw-r--r--scripts/resource-cert-samples/LIR3.req15
-rw-r--r--scripts/resource-cert-samples/LIR3/01.pem92
-rw-r--r--scripts/resource-cert-samples/LIR3/02.pem94
-rw-r--r--scripts/resource-cert-samples/LIR3/03.pem94
-rw-r--r--scripts/resource-cert-samples/LIR3/index3
-rw-r--r--scripts/resource-cert-samples/LIR3/index.attr1
-rw-r--r--scripts/resource-cert-samples/LIR3/index.attr.old1
-rw-r--r--scripts/resource-cert-samples/LIR3/index.old2
-rw-r--r--scripts/resource-cert-samples/LIR3/serial1
-rw-r--r--scripts/resource-cert-samples/LIR3/serial.old1
-rw-r--r--scripts/resource-cert-samples/Makefile166
-rw-r--r--scripts/resource-cert-samples/RIR.cer104
-rw-r--r--scripts/resource-cert-samples/RIR.cnf51
-rw-r--r--scripts/resource-cert-samples/RIR.key27
-rw-r--r--scripts/resource-cert-samples/RIR.req15
-rw-r--r--scripts/resource-cert-samples/RIR/01.pem24
-rw-r--r--scripts/resource-cert-samples/RIR/02.pem24
-rw-r--r--scripts/resource-cert-samples/RIR/03.pem24
-rw-r--r--scripts/resource-cert-samples/RIR/04.pem99
-rw-r--r--scripts/resource-cert-samples/RIR/05.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/06.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/07.pem99
-rw-r--r--scripts/resource-cert-samples/RIR/08.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/09.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/0A.pem99
-rw-r--r--scripts/resource-cert-samples/RIR/0B.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/0C.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/0D.pem104
-rw-r--r--scripts/resource-cert-samples/RIR/0E.pem101
-rw-r--r--scripts/resource-cert-samples/RIR/0F.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/10.pem98
-rw-r--r--scripts/resource-cert-samples/RIR/index16
-rw-r--r--scripts/resource-cert-samples/RIR/index.attr1
-rw-r--r--scripts/resource-cert-samples/RIR/index.attr.old1
-rw-r--r--scripts/resource-cert-samples/RIR/index.old15
-rw-r--r--scripts/resource-cert-samples/RIR/serial1
-rw-r--r--scripts/resource-cert-samples/RIR/serial.old1
123 files changed, 5577 insertions, 0 deletions
diff --git a/scripts/resource-cert-samples/.stamp b/scripts/resource-cert-samples/.stamp
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/.stamp
diff --git a/scripts/resource-cert-samples/ISP1.cer b/scripts/resource-cert-samples/ISP1.cer
new file mode 100644
index 00000000..86da6423
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP1.cer
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 10 (0xa)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 77:f8:b2:d3:a4:61:38:f7:23:0d:a8:bc:33:a9:5e:fe:b5:1d:
+ 09:ea:ee:5b:93:4c:b1:76:ea:27:9c:ad:ab:ba:b7:44:a1:8b:
+ 69:89:71:a7:50:39:05:e5:69:e6:f2:7b:33:70:2a:a1:1d:87:
+ ad:48:45:2a:ab:02:a2:fd:df:08:36:8d:2b:25:8d:c2:06:d5:
+ 10:49:8b:88:62:94:47:5a:27:78:2e:2d:51:aa:b8:9b:13:27:
+ ef:38:af:43:1f:61:f7:da:48:13:2a:0b:66:b4:7d:b4:3a:02:
+ 1a:d3:88:c3:c4:df:1c:1b:86:29:05:da:61:ef:f2:b4:d4:86:
+ 67:14:54:cb:21:b9:8f:38:7b:f8:ba:87:71:66:7d:cf:61:ee:
+ 0b:bb:55:89:46:9d:b4:96:ab:55:90:bd:2c:c6:cf:fa:2d:c3:
+ 18:a2:40:44:0e:85:dd:65:de:b1:2c:79:1b:12:e7:f6:2d:af:
+ 1d:88:61:4a:67:38:17:f1:dc:2e:7c:6a:79:c2:94:8e:f4:e6:
+ c2:6a:6a:7f:3f:40:bf:03:fd:22:ad:ee:df:9b:e4:bc:4b:a0:
+ 73:2d:14:75:ca:c9:7c:06:2c:79:b2:c8:6f:83:d2:81:72:a8:
+ 09:0b:a2:39:cb:68:b5:38:f4:09:bc:4a:83:53:26:f4:b2:ca:
+ 3d:31:ed:e7
+-----BEGIN CERTIFICATE-----
+MIID6DCCAtCgAwIBAgIBCjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCATUwggExMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUAwAAC
+AQMFAcAAAiAwDQYJKoZIhvcNAQEFBQADggEBAHf4stOkYTj3Iw2ovDOpXv61HQnq
+7luTTLF26iecrau6t0Shi2mJcadQOQXlaebyezNwKqEdh61IRSqrAqL93wg2jSsl
+jcIG1RBJi4hilEdaJ3guLVGquJsTJ+84r0MfYffaSBMqC2a0fbQ6AhrTiMPE3xwb
+hikF2mHv8rTUhmcUVMshuY84e/i6h3Fmfc9h7gu7VYlGnbSWq1WQvSzGz/otwxii
+QEQOhd1l3rEseRsS5/Ytrx2IYUpnOBfx3C58annClI705sJqan8/QL8D/SKt7t+b
+5LxLoHMtFHXKyXwGLHmyyG+D0oFyqAkLojnLaLU49Am8SoNTJvSyyj0x7ec=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP1.cnf b/scripts/resource-cert-samples/ISP1.cnf
new file mode 100644
index 00000000..179b2bd3
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP1.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = ISP1.cer
+serial = ISP1/serial
+private_key = ISP1.key
+database = ISP1/index
+new_certs_dir = ISP1
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY ISP1
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP1/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+sbgp-autonomousSysNum = critical,AS:64533
+sbgp-ipAddrBlock = critical,IPv4:192.0.2.1-192.0.2.33
diff --git a/scripts/resource-cert-samples/ISP1.key b/scripts/resource-cert-samples/ISP1.key
new file mode 100644
index 00000000..515efd60
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP1.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEpQIBAAKCAQEA64BUenRL5IEV0CUtXiG+R+Yxq+L+eVVItzZVPdwRiFu3Nr7T
+u9cWjfhL9MW9NMSOLGeX5icQQMU29LZsuSmCLnawKepDmtEw3gWhwVR8F2cd/Cnd
+gFOygTDbE+4+5l3HvD2mEW2Bd7efPjbffNbSWiI2aHwUzKxU7a794s2xo12pZewb
+i0vPgI6mmI9psaY1vWnJLmZ/IhFmVsV1TIGjbklxDfV1hxPoYugaDKgwgWq+kFkj
+O2HAFV9ov7XJP686on+AAXj29FXK7sqNCJvFPnSYArILptjobniIe5V2tsq+8YCp
+3eg8gJHOP/0L3bfYpoyUIAcZdPqG/8uXw/ak5wIDAQABAoIBAQDGU9TRK4+eaHeO
+S0DhvVkaA+pg71GPrRsH8GHpLqQ1ScgJ+rslvgXomeqdwMmO3tk83CE4Wj19zphx
+jhAR/7r6lknVgsxcXT/iOqv2vMekjdraugcoQ1RZKGPXbRTbvK6xANoSYz5dK+6X
+3m5oHCIadiWL6LM7iwYbBPwbPU8UW/bevhjBGLQLaeFooQ/MFFxKiVnvTMd6lzGA
+M9r83GcvB7S+rj6TcJRFq9YDajtjHoOeTNljy7bTPlbG+wtxVK3y6/BbH0tMO9mv
+snyktOyLWB/wue9/9H46Hzt8vExw8URT0k/hvJeTOwemIpWy7++QXRa+vW/02kqq
+A6GFhhbBAoGBAPqZ43SzlNPj8hccbjsjTQfoq4iW3BJTyMfba+VZfs+g+d+Rg60I
+UKnrCM4SCDOiw6d3sI+lrkyOepgzW5FdwORvncYIxUCxonDzwVv4uAVSR6JMl47X
+MrJkMm4lImo/VzSxRyYDmYaXARGNiSQN73Bv9rVm+auDIW3hb08ofoSVAoGBAPCT
+KcDbty6A1ANInSde3pOLw9WvJYmHhvCHH/6sNsuV4NxzCuYPvjLmJzrW0NNvBstp
+xZhxWYd+x9MofU9jUmrLfk1TugcGl2txBCl++u+HhS9ClMpkilowSHOiqvaWHLkE
+3CyYiI3Wevqo+utiqaJItYa5jXQ+BJbtiSqeoAiLAoGBALhAFw1B0AXujZtSavWO
+Id/TwPK/QHU1JuVSvcS2BVexGqa2/WJmP7B+v02L0n3siQADL0yeW0WsaBSphgSe
+MumB6zWkUysar71uatctSleXRFXfDHuYW4zvwGhdYy1M/tgeE5qugN2E/uMh9hgN
+KuO3XmPHn3/r/NMmMcm4kzT1AoGBANUwxLaIvttyBO/oAIRsOPgtylzpum0W8gji
+5gKM4H4nkr4pIMZhux5mAOvOg/5qjG3kjNubz0gYnMJORkX88YN8U6/4+4jQWY03
++QVA5uUvhmIsMajt0gE8emgnBjRBMLDxUqAeiByRrifFaZ8Aru0GW/9JHcaeUvjh
+BUYEjjMjAoGAW3wL8KyxoJMfC6BRC1rU6ZQovwVLa0dpRaUNh5Qi/G4wkzRKiu7l
+04MXoMggDF1XOl4noyjFsbnaZRUAbfVXalHOMIGWMXVlQy7u/RXOXcVJ2rgZj5z+
+Tt9aoZ1exEXzkm+IMfj8GqsXuv5qcgN1WibkhrC4KpJFbEFz35FGBTI=
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/ISP1.req b/scripts/resource-cert-samples/ISP1.req
new file mode 100644
index 00000000..6f65e175
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP1.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJ
+KoZIhvcNAQEBBQADggEPADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlV
+SLc2VT3cEYhbtza+07vXFo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rR
+MN4FocFUfBdnHfwp3YBTsoEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMys
+VO2u/eLNsaNdqWXsG4tLz4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT
+6GLoGgyoMIFqvpBZIzthwBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY
+6G54iHuVdrbKvvGAqd3oPICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaAA
+MA0GCSqGSIb3DQEBBQUAA4IBAQAyKlLYDwS59IWCvrnzXeuPsHkpseZ9AYZpVHDD
+6K8kmroKfhv5ockUFa2MjuAhy9+m6hnSA9XMrHV3qXBN/DPpi8wXbO4gCzfvoGvy
+EcneXLzlmhYDjjB4bqgvoCGwtehPS3epzXzFu/UONWTja0hLYXfXXZHZzRQfER55
+qZy6bVrSTSqCALl5bZr39AhnvF0EQDSa5sowfDCezsWrHYRGTsIY3m91j9CMTefA
+Pdf36rbBaCk9BvXpADNiwi91nI4U1jsQXcBRfKJFimLU20Vtce+i3M5ljWDwsBXl
+vXoAqKe3EKOs6NqK3C5G9A3yMtTVX7BxBWpjm5X76F05I0tj
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP1/index b/scripts/resource-cert-samples/ISP1/index
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP1/index
diff --git a/scripts/resource-cert-samples/ISP1/serial b/scripts/resource-cert-samples/ISP1/serial
new file mode 100644
index 00000000..8a0f05e1
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP1/serial
@@ -0,0 +1 @@
+01
diff --git a/scripts/resource-cert-samples/ISP2.cer b/scripts/resource-cert-samples/ISP2.cer
new file mode 100644
index 00000000..0a5c3837
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP2.cer
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 9 (0x9)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 0a:f1:b5:af:38:f9:7d:93:95:d4:ea:bf:48:ef:8d:63:3c:4e:
+ 1c:80:3d:7a:06:20:42:0e:0d:52:99:aa:4b:3e:af:d7:b4:61:
+ 47:4f:b7:b4:f7:cc:9b:3c:5e:a5:3b:3c:ba:dd:b7:2a:27:8e:
+ 1b:b4:5c:3c:6b:d1:d9:ff:c2:12:f7:9d:82:ba:cf:75:34:bc:
+ d7:0b:b4:d6:a8:4f:58:93:6a:ae:23:7a:37:e3:2e:f1:70:8a:
+ dd:f5:0e:fa:df:b0:3f:12:d4:5a:ac:33:ad:15:1c:a5:dc:be:
+ 08:c3:8e:1a:0f:35:12:0e:de:ef:b8:80:78:90:a9:eb:8f:00:
+ 0a:15:1d:05:12:3a:1d:37:e9:f4:f9:4a:77:6e:69:27:b7:e3:
+ 7f:ae:78:32:92:86:6d:39:16:5e:59:4f:93:10:b5:b0:be:1c:
+ 25:47:2a:e2:8f:92:9f:5c:c0:2a:48:d7:53:00:14:8e:9e:86:
+ ea:cf:a6:21:66:50:89:95:39:3e:ff:27:95:85:ef:3d:c8:98:
+ 7f:cd:fe:c1:30:65:94:b1:ad:48:5c:ae:b7:c8:64:e9:69:a2:
+ 07:ca:c2:d7:fe:63:4b:de:a9:25:a1:91:4b:17:a3:a9:dd:2b:
+ f7:d1:a5:3e:b7:be:42:03:1e:d9:34:5f:16:e3:35:7a:ca:1d:
+ ee:3d:4c:d5
+-----BEGIN CERTIFICATE-----
+MIIDzDCCArSgAwIBAgIBCTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOCARkwggEVMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFHOyFhrN3NcwYA/6gZX4ovVOlfOtMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMCkGCCsGAQUFBwEHAQH/
+BBowGDAWBAIAATAQMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEA
+CvG1rzj5fZOV1Oq/SO+NYzxOHIA9egYgQg4NUpmqSz6v17RhR0+3tPfMmzxepTs8
+ut23KieOG7RcPGvR2f/CEvedgrrPdTS81wu01qhPWJNqriN6N+Mu8XCK3fUO+t+w
+PxLUWqwzrRUcpdy+CMOOGg81Eg7e77iAeJCp648AChUdBRI6HTfp9PlKd25pJ7fj
+f654MpKGbTkWXllPkxC1sL4cJUcq4o+Sn1zAKkjXUwAUjp6G6s+mIWZQiZU5Pv8n
+lYXvPciYf83+wTBllLGtSFyut8hk6WmiB8rC1/5jS96pJaGRSxejqd0r99GlPre+
+QgMe2TRfFuM1esod7j1M1Q==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP2.cnf b/scripts/resource-cert-samples/ISP2.cnf
new file mode 100644
index 00000000..ffc02166
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP2.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = ISP2.cer
+serial = ISP2/serial
+private_key = ISP2.key
+database = ISP2/index
+new_certs_dir = ISP2
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY ISP2
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP2/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv4:192.0.2.44-192.0.2.100
diff --git a/scripts/resource-cert-samples/ISP2.key b/scripts/resource-cert-samples/ISP2.key
new file mode 100644
index 00000000..fdff214b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP2.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEpQIBAAKCAQEA0HffxCGvG1prqKco10PIm20l2I1/kSvjlf2SYKwUEtcjaIVL
+Dtsr5jjgSNsYN49AwJBYDj8JZ1+OPwR1BmCSQvPkRQQ1lV3pIkIs9lymfXmM4QgZ
+fDWdOv3n/5spte6JR8wNg6Dhc68fCYSoC4PMeYi/fB1z1qtCG2SaXBmDK53lrUxY
+BXaVcCPupcAxyqKnyB0e8snyPTiCwlPlVIbyfLFz4dzphnMIrFk7vi9YwULFgBiM
+OgoqMvb+KNAoUoPGMGlRkFkZm9PUwuBSasFOWZoY5HguV/l/K112KMnJxX7lQ6Gb
+aNIGHL4/afnC+p5PaM9jb9tt/Gc1wLFuCjfsMwIDAQABAoIBAQCXyZCOGBCNlAqr
+Y/risiIQuSpDQNPPeetdvKGl7eU3ypmnctYx3Pdby7HSmmRJn+5/xxm2VcOdFwBV
+dgNXP11/jmF4txXkydoD7bcbMl6vIZ+oAeO8grUWzOTtQabfJu2h7zsvyiYduzaY
+EZThvXdWTnFOB4velBewJlIWGSVezWqRr5T156dGA6RetSIZhGidm+HGA2o5cSPW
+jRC9gPL9PGEXmjpFeKqLMobIZvPnSnM03oZ76IJ/B/nInfk3uCBGmldspBa3Pcyl
+mP85VfYR83UQUigZeVHxgQN+ijDSGJHLp5dXCfkp/DO0MiRtobHBgvRP8+e8t2J7
+p2q+bRaBAoGBAOfyNu6z26DGIm1iYBeK114EiN/cXzIUD62eFmU9DESiGIrJzrfJ
+xpJyb70v42nCXCFoyM4HLeNqXEGhzOb3s1ueUlSqMoxp2RJ8ygedlN/YwtAb8+4+
+sQjQxGH1zwDbKeNSvKU3wtNs1HC1FU3I7yZaYc2NxB2y1Qmct/EIvO+TAoGBAOYW
+XERTVFkTDjTzn8orgGIkS0FtXTgdQMDBvJj1yiQCJn94imQrEQq/XMY/Kp2/w/W8
+rdtOWDlPP7vDLOtsFOzsAxsIkvfJpt/plpU1zaNN/BTthE1BX1HY1ql74QE5Kp13
+gzVwmrcaR79nZz/hH/yLBz8bcK7YTV38MzkDMrThAoGBAK3uo6TiuOraSYzPPZHJ
+6vC049NDVRufkZY3O0IVwnJhP5gr91k49TByojozhAyV1DK1egeNuKqV4rLQ22/E
+BfrJQaH9s0Q6R66mZ3XIhJBL4uLeY1CgMG+U5f8zrlRNBR9TtuUKaI3VSYVvNZeL
++1I+aqMTESLYLQs1O3aDf/MDAoGBAKKjSaMOWAACpTcuwlNQvpYg24Uq/gqtOtlF
+2L8ydilPz9Co7wHxI0G6lKSZf9Ez/RtVvHrZfSk9aGqbgsQCiSQTi/pu7Bv00V1T
+KxrbhjkZ5ccRQUSuoecj5FC2/Qw1UXcvRHLg3qvxCqg0OlqAEnEcAQpNpjAhO0bk
+/3wcU5phAoGAWkhNG8ehVyEeoAbw4A/ij66C3QjTQVMISqzGPERhxKKfAPdmgOeZ
+C6Gs+XTV3Y5w6cO6S74lLNvI0n2C759P4eAk2HxN/NwC5yxJNH/z+3lIV4LfY54+
+O96PzPOAAaHbjl7LklcM/E3AEZgI0Sx+U9yr+EQcijoR0QvyjdFXY38=
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/ISP2.req b/scripts/resource-cert-samples/ISP2.req
new file mode 100644
index 00000000..75b8f436
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP2.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJ
+KoZIhvcNAQEBBQADggEPADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er
+45X9kmCsFBLXI2iFSw7bK+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd
+6SJCLPZcpn15jOEIGXw1nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9ar
+QhtkmlwZgyud5a1MWAV2lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZz
+CKxZO74vWMFCxYAYjDoKKjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5
+fytddijJycV+5UOhm2jSBhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaAA
+MA0GCSqGSIb3DQEBBQUAA4IBAQDFKEbfAZaF563uK9VaYezw4OJ1a+atHbLlx0hF
+6Xc/XMxHVV1UD+nR7jVKLAH7IGwCe42slxcXgkcwtKXpRVPqmsYpwBbrVYSZmU/P
+3OP0PSZ1i9VWUN1XoUFJfE8E+2t1NhylBXqZTDUjPxLxWIYE9IFeN0aHiWrElbmU
+Qjrt7N/L+9rJTKtP0aT6uTUKAstfmZyp3yiHLjsszrMdZknAEvUVFkjQEt5GOOXL
+eyutwgj4sMnDpMnp6bCHNBqDmj7VBzUzaPtEQO4bDTur2O5Ny5zDGR35g4DXuhh7
+o0wI/sVzcMmTzc3nQ5YXNACUjCUxrM+L+EAmYoFQ1SDu5wPE
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP2/index b/scripts/resource-cert-samples/ISP2/index
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP2/index
diff --git a/scripts/resource-cert-samples/ISP2/serial b/scripts/resource-cert-samples/ISP2/serial
new file mode 100644
index 00000000..8a0f05e1
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP2/serial
@@ -0,0 +1 @@
+01
diff --git a/scripts/resource-cert-samples/ISP3.cer b/scripts/resource-cert-samples/ISP3.cer
new file mode 100644
index 00000000..c8f4890e
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP3.cer
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 10 (0xa)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 05:ba:27:d4:55:52:1b:f7:61:da:37:98:b3:16:e6:53:6a:2c:
+ 65:f5:80:7f:d4:cb:8f:fb:c2:1d:1a:9f:54:ed:a0:7a:03:a6:
+ ff:5a:e7:d6:c1:06:31:11:b5:c1:dc:ab:33:87:d7:57:0e:cd:
+ 19:44:16:9f:92:84:43:32:8b:d0:64:12:00:a7:ad:b7:fb:79:
+ c1:ec:e3:d0:77:3c:73:8a:5f:90:6b:da:a4:d4:e0:28:0a:45:
+ 99:5a:b8:b0:fa:96:3e:c3:a3:de:a6:df:f9:55:e9:1b:3e:37:
+ f0:21:38:7f:5f:b2:e0:75:f2:8c:82:10:e9:60:76:3b:de:dd:
+ 85:f2:1e:3c:22:f5:77:40:d9:a4:f9:72:46:29:99:a8:2e:5d:
+ b8:05:5c:b3:2b:d0:44:c5:8b:07:c7:69:d0:a9:cf:83:31:d1:
+ ed:36:d7:ce:b4:c6:7e:4a:58:10:20:46:16:ed:b5:e3:60:47:
+ e8:b2:36:1e:79:ed:ac:08:da:8b:a0:6d:92:f1:e4:73:60:6b:
+ 10:61:07:69:78:78:a9:51:fd:24:1d:3d:d6:63:62:c3:d4:1e:
+ 70:8d:f6:41:fc:42:09:cc:7b:1c:19:c7:59:0b:a0:da:5b:00:
+ fd:33:24:8b:9f:1e:d8:d8:04:cd:f4:71:06:ea:c6:2e:8d:8b:
+ 6f:cd:b9:a6
+-----BEGIN CERTIFICATE-----
+MIID5DCCAsygAwIBAgIBCjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCATEwggEtMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMEEGCCsGAQUFBwEHAQH/
+BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABADANBgkqhkiG9w0BAQUFAAOCAQEABbon1FVSG/dh2jeYsxbmU2osZfWAf9TL
+j/vCHRqfVO2gegOm/1rn1sEGMRG1wdyrM4fXVw7NGUQWn5KEQzKL0GQSAKett/t5
+wezj0Hc8c4pfkGvapNTgKApFmVq4sPqWPsOj3qbf+VXpGz438CE4f1+y4HXyjIIQ
+6WB2O97dhfIePCL1d0DZpPlyRimZqC5duAVcsyvQRMWLB8dp0KnPgzHR7TbXzrTG
+fkpYECBGFu2142BH6LI2HnntrAjai6BtkvHkc2BrEGEHaXh4qVH9JB091mNiw9Qe
+cI32QfxCCcx7HBnHWQug2lsA/TMki58e2NgEzfRxBurGLo2Lb825pg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP3.cnf b/scripts/resource-cert-samples/ISP3.cnf
new file mode 100644
index 00000000..c369f198
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP3.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = ISP3.cer
+serial = ISP3/serial
+private_key = ISP3.key
+database = ISP3/index
+new_certs_dir = ISP3
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY ISP3
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP3/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv6:2001:db8::44-2001:db8::100
diff --git a/scripts/resource-cert-samples/ISP3.key b/scripts/resource-cert-samples/ISP3.key
new file mode 100644
index 00000000..ad66c7a0
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP3.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEpAIBAAKCAQEA0SR1wUQpEpr+jB0eAaoF6h9HqxqNz9JCoTF9nD5mcs4s3wEX
+FUBAlNGubdfK/VLZ7F/wZDCjQnChoW8FLRDusQVlP/LBeITMHWbuNVLHrpl2sWNN
+wS4k+/dDLQshDdPWt89gUEk9F1M+K/holX4cxeIecwaMslOhcDnZnuVW/FjQs/OQ
+N1puWjvvBb7xZC8xLlpY8jB6c1J/uA1xPGNSFw+3BzvDRrmciLxz3xRavBb8+Hmw
+oUGHBflSqDZhYt6QaCGDu4yDR6+7gj5EKJcrAqiBBAUWzb/vngL5VGYqKJl5K7UZ
+ENTfNZXzP/oTagZv9Tgo1rYLinBbjXCNNJmWPwIDAQABAoIBAD88rv5JBcJCa0Ui
+aLhIGJG584mg9dAo20yyEjD0DTYZcSfcxIYAb4aQABXmcdI3Av2d5Knmqvaj57tQ
+PlhqDkIoR30WgblXLgCV5uDorsf0TxdD13bZ5QTqtr0f6Fat/vaFFbIw8u/ik6Hn
+8neBMmIDBQHysQgakW3FkC+jWLHj/OgtEfCxa4eE3chJkkiGmTFVnHsYEdv+yZVS
+3lLAoRyl6yfU/AH7QSM/UXPq41kkGViKgB4MgIBUuoHxCOnPomlGKZ8A83ba2Prf
+h1/RQPWdQCQJkVai4tC3sDsiJPzxF97zTBl2vjXE2TY7Ow2jF+cxY81F3qXGecef
+ATrevYECgYEA8YgdTsZqAaPBkWUReqBFJSusxQzcMQQTCN81mPqiGDYqUuTKbG/i
+86LGnw/2/J03bhdydak9BbsXqcpClqdV6RcDng49VW0HZsS5mebPqh9dkT7qFhf0
+JE0ocC0MHypl0zti1BfR3GL6yVD1fkzRl72s3tVhRPCJ3uchWBEGcukCgYEA3auo
+B8zgw55kYwnlp1AmYbBtHXJYJnMQQ6KhOniLVJQD/EvIAD6cvjU5dyGizZWG9E9A
+/rVL8G+A4vekElFiq1X3hED24rh4YNyeyKaJywFJnz416GuJHTn7FDo79149TQ51
+eQAAvdRS1NYNjrHzw+5AbKUe4R2Ay6JfN0j89ucCgYEA0x6cJ5BNdrNx7in+1kYj
+SnNbqD4udfXOwZGB4v8pEqq94gk0WwaNxVKB9OVaicLOgb+i/+/3c/vumi4+eDs6
+X+0K72wY9oO/1XedmEXlPRn/iocIzFkRwW1kLHFjyBYiPToKj8NmYBJwjenjPAvf
+pJhZ88lmJYFvsdQsFDOFhIkCgYBBcg2xB98QQjJXPzPLexFp5CHDAOBfsbcKkPhT
+AAX62Zx3n5QT5mh2i9ZEguzDD7OBa+i/ip06BmGiIQUS125vMXlbVabOdzIrPteu
+W+Twx5eJ6V8XGLCprVWgujS8KtmkZ3FtYP/XC9nMtsnX6FgU78GbkgCU7BX7iRvd
+gbIV3wKBgQDwLIYE6CuhmD68vELr2PLX8Su9VsxSBBwZKYAfLIOkacANFRSKkngN
+eFwWUOzhF6kc1cIrZJHLRUsqYx6VGgWZbXLQ0eOYgicdmXRYAOwH5569i5bQTjvp
+wBQ49yr3PKKbJiuNSpHAfXtmN8PlTcH7KOBqWBMzM7+XNld2yEn6Dg==
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/ISP3.req b/scripts/resource-cert-samples/ISP3.req
new file mode 100644
index 00000000..d0bdb9ca
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP3.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJ
+KoZIhvcNAQEBBQADggEPADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/S
+QqExfZw+ZnLOLN8BFxVAQJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiE
+zB1m7jVSx66ZdrFjTcEuJPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJT
+oXA52Z7lVvxY0LPzkDdablo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5
+nIi8c98UWrwW/Ph5sKFBhwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/
+754C+VRmKiiZeSu1GRDU3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaAA
+MA0GCSqGSIb3DQEBBQUAA4IBAQCezSRdM4ZX05WJKj/n8i4I1HCgGZzs9xnfwPoX
+5N7sTK3QTOdI+4nJXP4zXgJewM73rf0NBQ2DhC5bD3cGMzbM6TE95KZjuGwje5CO
+c0gZ17cxUBlTJpOFBze0JU7g6xyctB3bztBcEn9cSP3kHqP1XendqHEcU2xM5jwx
+0jV3usS5zit1ti3aFpHFiazFYrF7C8NWTwirJaK9c+bru7GQnVZBkNZBgcy56u+B
+TPv/x403w65CsYz+IfVHBbzKY/lzwZ0LXmE5rv+3SzgyXfzHUjMa8ucJVumJeWwf
+2ZEKTUJJ+BuF2Z3/MMNNmQqFV5FaO2hn7l83v6oOZHNfGafR
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP3/index b/scripts/resource-cert-samples/ISP3/index
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP3/index
diff --git a/scripts/resource-cert-samples/ISP3/serial b/scripts/resource-cert-samples/ISP3/serial
new file mode 100644
index 00000000..8a0f05e1
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP3/serial
@@ -0,0 +1 @@
+01
diff --git a/scripts/resource-cert-samples/ISP4.cer b/scripts/resource-cert-samples/ISP4.cer
new file mode 100644
index 00000000..b117c94d
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP4.cer
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 9 (0x9)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 1c:53:2a:8f:55:44:b1:71:d1:50:79:f1:3c:3d:fe:15:1d:72:
+ 5e:22:91:d1:54:3d:a4:e0:9e:ba:e4:8d:b3:71:c5:93:cd:5b:
+ 54:5c:e5:2c:af:a1:a9:d7:8d:32:b7:92:95:8c:0e:2e:05:d3:
+ 9d:da:ac:a9:7a:01:d2:19:9e:b7:88:80:92:b1:26:95:6d:0a:
+ b4:01:a3:f1:9f:15:fe:0b:29:0f:0f:72:b7:72:d2:18:9e:5d:
+ 7e:65:59:7b:30:75:33:7f:95:fc:cb:9d:7b:0f:36:44:0f:d0:
+ e6:a3:c1:a5:6b:d0:db:13:4b:fa:06:35:df:66:01:c3:d8:51:
+ 47:e7:89:26:56:6f:2a:2a:ba:46:29:a8:cb:9d:cc:5f:d9:9f:
+ 14:01:d5:fd:08:e9:db:1a:7a:89:3e:c8:36:6b:b4:6c:ca:a9:
+ df:43:46:89:48:a0:13:32:bb:c9:17:14:01:2d:21:fe:68:11:
+ 61:5a:b4:6f:af:ba:3b:0a:96:4c:25:33:5a:a6:cf:29:21:45:
+ 76:b8:e1:d9:20:0c:22:f7:7c:85:b2:45:90:94:c5:2c:ca:e1:
+ 82:65:36:75:9d:46:9b:f8:9a:d6:85:2f:71:8b:cd:88:fd:87:
+ 1b:1c:36:f8:36:f5:1c:18:e5:5b:68:3f:36:60:de:a0:59:e1:
+ cd:54:61:4c
+-----BEGIN CERTIFICATE-----
+MIID6zCCAtOgAwIBAgIBCTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCATgwggE0MA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBswGQQCAAIwEwMRACABDbgA
+AAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBABxTKo9VRLFx0VB58Tw9/hUd
+cl4ikdFUPaTgnrrkjbNxxZPNW1Rc5SyvoanXjTK3kpWMDi4F053arKl6AdIZnreI
+gJKxJpVtCrQBo/GfFf4LKQ8Pcrdy0hieXX5lWXswdTN/lfzLnXsPNkQP0OajwaVr
+0NsTS/oGNd9mAcPYUUfniSZWbyoqukYpqMudzF/ZnxQB1f0I6dsaeok+yDZrtGzK
+qd9DRolIoBMyu8kXFAEtIf5oEWFatG+vujsKlkwlM1qmzykhRXa44dkgDCL3fIWy
+RZCUxSzK4YJlNnWdRpv4mtaFL3GLzYj9hxscNvg29RwY5VtoPzZg3qBZ4c1UYUw=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP4.cnf b/scripts/resource-cert-samples/ISP4.cnf
new file mode 100644
index 00000000..b52752b6
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP4.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = ISP4.cer
+serial = ISP4/serial
+private_key = ISP4.key
+database = ISP4/index
+new_certs_dir = ISP4
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY ISP4
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP4/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+sbgp-autonomousSysNum = critical,AS:64544
+sbgp-ipAddrBlock = critical,IPv6:2001:db8::10:0:44/128
diff --git a/scripts/resource-cert-samples/ISP4.key b/scripts/resource-cert-samples/ISP4.key
new file mode 100644
index 00000000..20370dc9
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP4.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEpQIBAAKCAQEAswWt+wbbSYGt31AE4Bjo8fSD5iZLnvwtHN/iK1c4SOvEE6P9
+bMXiHNU6/WbX/y7/SrdaxfQZsY2eqElOOyBG2gjesJxxXnepFOJMIA7/xSD68207
+C87hcrb/9XV/PjWvHE/gkkXwH1fOOGw+9i+Wcx9g22OOY7PzNYXpADmSs59Ka73p
+oADKvv4neJtEI1NWE0h9zdEBOog2Zk9/8yyfx8RSdR4OPFApyTng/5BNlUdWE+Ew
+8zAz7gJgcLC93TuquSqGv+fiqOxkKgsSBQgDfthBuyPeKeUPmzsALk8O9TGR7L00
+Amht13GpjE0j0kOu1/jlaSuuE4YTJzhySHD4HwIDAQABAoIBAQCcCoNPnvZc5+/K
+ClF1k8DXxS2C2jZn6Z7Y4DyfUnL4/Kf4BqTKvuEMCMBWR+JVx302fwNcMByFKs/0
+F5Fc8BFR0xFoF7SphtuWHHoGJ4zBIrIapEcnT7gq6V/JcBTtAJYVs3onhVZ7u2lA
+vPlUVL5qshsWn3xpY1zGdmZVj9lTPjr186AVg+Di2D8RWKrBiLgT0gy9nK0dX7AU
+8C4w/C2b/1Yp6D8L7benbRCRjYcuyoS211B/yC7KDP+YoHv2AYqPXEUdyBMnk+KR
+lhw793xI5ec7ryinBtjmiIds0iDrJOztiWgLdGHrxT5OFOUJNjtZ6W9PvYi5Reu7
+vin+ugrhAoGBAOTIA0urho2JA1wsmMYtpUpsr+Ep+4SMpu0Gbrqs9uFHIFYGRrT8
+hgO1yZk3TwJVPsbYiROIIPkv9pJQKGzkyF+zEaJsnR40iybbW3arPr5UqKVauNLc
+KbqtChetfY81vA/8HjFB6mKq2K6tdOTqLGhJlX9Y9baNBNrRn0ReLnUtAoGBAMhS
+J4suczgkv27PWqa2nmzAxsArsCcubFTYJE0qV6qRbtN3eH+S8c1/tTk29MPRgzX4
++3oLowRhiArVui79X43Y+6J5akbnLoR3duGOpqdza+UmE5UExokpDag2/hKuUEZu
+youzuik3pMipu9rjc45CXGbvuaqg6mw48bnAS4n7AoGBAKFQLpKydQNjMo1RnL9P
+/BZIIJOBSKmjiyfhuz3BK6qYvkIp1r1SuSPwkB+KkhkxBjyq/axZ9fX+TbvI7Vgq
+0OY5mxuNvhNINT3Gue0overyQp+lImD7gCjyTgV3/Op3lw0mVhuhQKUllfdEswGd
+5IX8LH9IuKhpMp0f5U8NoXBZAoGBAL33EqLtYLxcNOHbZ2bzhVcylQgGJh1x66+l
+7P70aYBKPGPzRuUML5wmQHBKimDsXVagj7JUOLpd10oXFmGbS7NTkoWoSD2G3Fko
+hScvRSFE1ovOyQEnLzNBKD9eLyD+BwhT5mYHAUI3D2BvfcL8sUe17LR9H4AM62HH
+uovhLIFjAoGAVa8vZTyEude+ZCu5RmBmNx0N4uj7M2zLTUjWoyssZOnS1z7MIuFL
+9xr511YAc3FIkQj1byn7O9CkwaYfEeGaTr18aw7b1BZqOA9Sk329kH3Uahi2JTE1
+0eXQ2ExBRexCq5Aoz8tnmFhTEMS0ECN7poa+VAT7c9OsrDeB0XMOJJ4=
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/ISP4.req b/scripts/resource-cert-samples/ISP4.req
new file mode 100644
index 00000000..dee4e58f
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP4.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJ
+KoZIhvcNAQEBBQADggEPADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578
+LRzf4itXOEjrxBOj/WzF4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53
+qRTiTCAO/8Ug+vNtOwvO4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz
+8zWF6QA5krOfSmu96aAAyr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQ
+Kck54P+QTZVHVhPhMPMwM+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inl
+D5s7AC5PDvUxkey9NAJobddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaAA
+MA0GCSqGSIb3DQEBBQUAA4IBAQCwB+5YMpq5NcvR0wmWBfltr6V3OBz+fZv1HRRX
+uxGfCTIkQ5SEh2NbyFybflyrcz7OVOIvGRpmGY4aFfIvXBCJq+eGNgs0CFhPBelq
+z9/VaKyV6oSJ630L52qHqjbz7qTnT/zMzcHHQvxNxpNCFDehtgq86ht0hFtRziBS
+ZAjubz8Vmb8PtVQcOJXZwjNLMq6slAeNl9FLE2CTyNZ773vc0iHePpULtcL9p8/y
+d4fq1c+t6g9pQvWwQaa9qiKGuf83ZfsWxoEmypxr1cR1zyYVZ4VhHmfHM8AWXBKM
+i8PADB+5O59TUF9jihzuPmy/Se9AV6ghauAenJAbsU/J9/di
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP4/index b/scripts/resource-cert-samples/ISP4/index
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP4/index
diff --git a/scripts/resource-cert-samples/ISP4/serial b/scripts/resource-cert-samples/ISP4/serial
new file mode 100644
index 00000000..8a0f05e1
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP4/serial
@@ -0,0 +1 @@
+01
diff --git a/scripts/resource-cert-samples/ISP5a.cer b/scripts/resource-cert-samples/ISP5a.cer
new file mode 100644
index 00000000..50780320
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5a.cer
@@ -0,0 +1,94 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 3 (0x3)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP5a
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:e6:4b:ad:78:28:6b:e6:50:1b:65:81:d5:8d:2b:
+ 56:77:cd:bb:c9:47:a0:aa:32:b0:2c:ac:1f:f1:e4:
+ 90:2b:c2:33:6f:e7:53:b1:d0:1d:ab:05:27:9d:b7:
+ a1:ee:a8:4f:c8:5b:36:23:e3:12:e4:51:59:27:cd:
+ fd:7a:aa:dc:56:05:a1:73:ab:79:dd:3c:82:b2:8f:
+ ae:f9:ec:c0:36:38:e6:02:aa:fd:89:60:21:52:5b:
+ b6:33:80:75:e5:7f:fd:ac:6e:ec:d4:9a:26:2f:7e:
+ 28:45:16:29:47:7d:f3:8a:72:d5:e4:65:fa:f4:54:
+ 6f:ae:48:33:62:c1:32:f1:2b:83:33:36:63:60:9e:
+ bc:c7:e7:99:5d:51:da:cd:2f:8f:83:47:20:9e:e9:
+ cc:a3:72:c0:72:bd:49:2d:c4:52:ea:6f:da:42:46:
+ 71:90:c7:af:7f:9f:c7:dd:0b:96:96:3c:45:9f:c0:
+ ea:65:6a:43:e3:f3:92:d5:e1:73:c0:6e:20:f5:17:
+ e5:d1:58:da:21:b3:e9:0c:4d:f0:e8:bd:7c:b7:ef:
+ 81:c9:f5:70:cf:a8:20:7d:e2:6a:f9:1b:66:a9:c8:
+ 71:d6:32:f8:72:3d:83:99:19:0d:0c:6b:e9:f8:92:
+ cd:33:17:86:6a:3d:af:0d:05:94:ab:1c:d4:2c:a4:
+ 45:cb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 09:F0:14:0B:79:FB:0B:FF:A8:EF:54:B9:EC:3E:B9:8B:D0:CB:9C:EC
+ X509v3 Authority Key Identifier:
+ keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 93:32:99:62:dd:c5:ea:f0:1f:58:50:10:37:d3:39:37:d9:f6:
+ 92:51:26:2f:d6:fd:6f:82:b8:56:6b:fd:0c:f3:42:04:56:ed:
+ 67:2b:42:02:98:56:07:f1:48:2d:2e:b4:32:bb:d7:1c:27:14:
+ a0:e9:ad:3b:1d:fe:0b:0e:43:df:22:97:f1:8f:73:d8:76:d6:
+ 9b:0d:bf:ee:20:e8:77:17:a3:83:01:b3:23:43:85:6b:bf:6f:
+ cc:2e:69:47:05:73:f4:21:45:94:c8:ae:21:28:41:16:91:ee:
+ 48:49:66:5a:67:31:71:04:c9:49:71:94:d5:f4:86:5c:7b:c6:
+ 3e:fe:91:1d:21:b3:14:98:54:ad:6e:51:28:e9:a8:22:ba:a4:
+ d0:9c:8c:e3:d4:7c:21:10:0c:f9:a3:00:f8:c3:9f:00:b4:53:
+ 34:06:af:5b:4a:43:95:cb:b2:fb:8c:18:00:86:11:28:5e:24:
+ e1:90:d8:67:d8:00:fc:b6:27:1f:9e:b1:be:91:17:c1:11:35:
+ 6e:9c:60:50:2e:67:f3:04:2b:74:89:f9:fe:92:73:dd:1e:44:
+ 81:67:b8:08:63:a8:9f:f4:8c:bc:47:de:f1:df:8b:11:cd:02:
+ ec:b9:ad:0b:06:28:0c:e2:84:36:83:85:f3:4f:46:56:46:d5:
+ f5:f8:cb:f3
+-----BEGIN CERTIFICATE-----
+MIID3jCCAsagAwIBAgIBAzANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
+0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
+YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
+nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
+akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjggEqMIIBJjAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQJ8BQLefsL/6jvVLnsPrmL0Muc7DAfBgNVHSME
+GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
+BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDVhLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
+Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwOQYIKwYBBQUHAQcB
+Af8EKjAoMAwEAgABMAYDBAAKAAAwGAQCAAIwEgMQACABDbgAAAAAAAAAAAoAADAN
+BgkqhkiG9w0BAQUFAAOCAQEAkzKZYt3F6vAfWFAQN9M5N9n2klEmL9b9b4K4Vmv9
+DPNCBFbtZytCAphWB/FILS60MrvXHCcUoOmtOx3+Cw5D3yKX8Y9z2HbWmw2/7iDo
+dxejgwGzI0OFa79vzC5pRwVz9CFFlMiuIShBFpHuSElmWmcxcQTJSXGU1fSGXHvG
+Pv6RHSGzFJhUrW5RKOmoIrqk0JyM49R8IRAM+aMA+MOfALRTNAavW0pDlcuy+4wY
+AIYRKF4k4ZDYZ9gA/LYnH56xvpEXwRE1bpxgUC5n8wQrdIn5/pJz3R5EgWe4CGOo
+n/SMvEfe8d+LEc0C7LmtCwYoDOKENoOF809GVkbV9fjL8w==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP5a.cnf b/scripts/resource-cert-samples/ISP5a.cnf
new file mode 100644
index 00000000..c21f08e2
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5a.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = ISP5a.cer
+serial = ISP5a/serial
+private_key = ISP5a.key
+database = ISP5a/index
+new_certs_dir = ISP5a
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY ISP5a
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv6:2001:db8::a00:0/120
diff --git a/scripts/resource-cert-samples/ISP5a.key b/scripts/resource-cert-samples/ISP5a.key
new file mode 100644
index 00000000..0bec780e
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5a.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEpgIBAAKCAQEA5kuteChr5lAbZYHVjStWd827yUegqjKwLKwf8eSQK8Izb+dT
+sdAdqwUnnbeh7qhPyFs2I+MS5FFZJ839eqrcVgWhc6t53TyCso+u+ezANjjmAqr9
+iWAhUlu2M4B15X/9rG7s1JomL34oRRYpR33zinLV5GX69FRvrkgzYsEy8SuDMzZj
+YJ68x+eZXVHazS+Pg0cgnunMo3LAcr1JLcRS6m/aQkZxkMevf5/H3QuWljxFn8Dq
+ZWpD4/OS1eFzwG4g9Rfl0VjaIbPpDE3w6L18t++ByfVwz6ggfeJq+Rtmqchx1jL4
+cj2DmRkNDGvp+JLNMxeGaj2vDQWUqxzULKRFywIDAQABAoIBAQDf6vFOBa90Dqu0
+tNrZGixG7IkMGlMDaamWpf2hiuULRxYQVlIwb/SI1shAN86BaLG6U8V+e0lhKh+P
+7l/qJ7t5AJyNBUvGaxGBYOd3JlV14zjxmyRNsGR12ap8xQjdDueuA2TPCtraDsZE
+9llIpBRqp2GFZArwCjFUuesMuGE5z4aqQ1A0lno3bibyGx/bGTWxJi54djyGr/T/
+5htxmoGsAw7PWnJQ0Vi9XQ+ZcHTfVK0KVBUYHnWSRCGuW0oriwT8O5g90dU4O+tI
+vFDOAV8ANVAWBCKpQ/YxBS4c/txVUZJpUIDvWmvJiWwrXv5cmzOjvBEX1K/nwjw0
+oFjL0xdRAoGBAPpjxMVzmbDzbDHbctWnKafLVSrY2Guetvs04x+wuVAkSZNMgXpn
+vd2ETOmB/rqXf7cv406HctGYUSxcNIOrfQKXy69Ew9w5WwjrExRBLbbFET5kBIn2
+5kCiENydWZuEhK1KwLYKAu5ZN9fQ4zVRyHROPkr8DpCcnGrl6jR/IZLNAoGBAOt0
+pkaYTAX3A7siLulKZpwsRmRvkb+mXJL//K7BqUkFZbesBy6zVBKSStJfpV5aqml/
+GnWgzoSWh2Ur8zV98fnpwOTeYpGSoFLjwapSl4G9+zIeKhNMVj2369FQA5wwWm9v
+ey9nuaiOvMdka0A0C7XOR5qxTvp0/4dI+dfp0ir3AoGBANBi3i3ykrOpM5+e4sib
+0dg7Kot5Y0zWD7WsA2apfuELAkzb/FpyIptMc3JXZTfHxFwiN8xwgAed+9iueGoo
+++Z/jN42nccX2QLoGb3erPwSsNI7DWgBGwopl1z0e9IpjP5oW1BlrqDNkeNEjwQe
+J3VcdQ2VD04deTSiWrQMJlX1AoGBAI0STPWLFjGUuDWM25KHM0dq95oBhs/O+zRQ
+D7Mc8TKA+1q6xWrjowGliRLWn5wSsnuW3eGQQWwLTH//fy6TkUFtHleCLoiN02UW
+dNh5t7DShQiYLhl16U39Plsgl6kjB2ww3RugCArHyq+kqOXEySdaumgix/Ej3F3Q
+CXGl9HgtAoGBAK2r9s+RrQX4g/vnrFKXSv9LuxM0tWyAcfg6rug6vcKiWI8zHS6k
+zDTJnldKS0q+K76W07oSx2kDJYHeXimXoh9V4LE2n20hoJF4+qRIDLrcMU7nb4Sq
+gyE5TaX4CluAMoTCRmdUQFaVZ26nSk4GyCM1aXVQIYeWp7IXiufiyIUc
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/ISP5a.req b/scripts/resource-cert-samples/ISP5a.req
new file mode 100644
index 00000000..5e4214be
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5a.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYTCCAUkCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0G
+CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6Cq
+MrAsrB/x5JArwjNv51Ox0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3nd
+PIKyj6757MA2OOYCqv2JYCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0
+VG+uSDNiwTLxK4MzNmNgnrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQ
+x69/n8fdC5aWPEWfwOplakPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDP
+qCB94mr5G2apyHHWMvhyPYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGg
+ADANBgkqhkiG9w0BAQUFAAOCAQEAhd6yFtGSfIV5WrxAuBapGyClNWElBM3UI3ID
+JrVjyeKEGb7hMZXwnreqE5aefywR16ZzrQAlpH8cxKJb/0iGPboZ0CEbFKJp81h5
+oJQEK0ArNPw4qyxi99rBovzez/yziOrDbXRJPnnzmUJAMlSyyCEvRwetOCZ906BM
+5bj+cCEwLNVhKEMZVPlOLrXLZX8Jne7QbcA5jMxkA7hEn3p6/BEj45VuiFe+PdAa
+/NDGAepBLly6zNwMXy/LvFueUA+9EH/30tQ1HbhA6f+TzhHPEc4GJkCfhTP/Nwoq
+2Te9fTDyhugM8rHFUfjTgaQVxRFM4XJIrFlyPG+Jk5rk3MIBag==
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP5a/index b/scripts/resource-cert-samples/ISP5a/index
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5a/index
diff --git a/scripts/resource-cert-samples/ISP5a/serial b/scripts/resource-cert-samples/ISP5a/serial
new file mode 100644
index 00000000..8a0f05e1
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5a/serial
@@ -0,0 +1 @@
+01
diff --git a/scripts/resource-cert-samples/ISP5b.cer b/scripts/resource-cert-samples/ISP5b.cer
new file mode 100644
index 00000000..47299c75
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5b.cer
@@ -0,0 +1,94 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 2 (0x2)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 1 14:48:20 2007 GMT
+ Not After : Jul 31 14:48:20 2008 GMT
+ Subject: CN=TEST ENTITY ISP5b
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:bf:8f:59:d8:fc:fa:1d:04:70:29:ce:7b:01:64:
+ 21:40:dc:5c:43:fe:4c:af:88:c8:62:9b:be:9c:72:
+ 8f:8a:a5:34:8a:3b:23:8d:9b:8a:4f:bf:66:ac:68:
+ 71:9c:fd:68:59:f5:bf:9f:4d:2e:b5:d6:e3:fa:bd:
+ f3:60:53:5c:b7:11:ac:95:0b:c0:87:cd:99:9e:94:
+ 57:8d:ec:05:b8:df:aa:fc:8e:38:d3:0f:65:6d:09:
+ 60:f2:e1:98:81:72:d8:51:3e:41:91:b3:10:95:f5:
+ f5:d0:f9:e5:5c:a1:85:fa:71:26:85:e3:d1:4c:02:
+ 7f:14:e2:1e:4a:8a:96:68:9e:d6:16:a5:ef:ad:b5:
+ 83:62:cd:23:74:7c:82:56:b4:d1:34:53:5a:8a:7a:
+ 61:9f:ae:54:5b:ef:f9:56:de:87:6b:42:92:bc:49:
+ f4:b5:c3:35:07:4a:18:47:d2:92:c6:1c:16:74:74:
+ b1:e9:39:3c:53:12:05:9d:eb:dc:9c:72:2b:97:4d:
+ 27:21:77:96:7d:4c:ce:79:0c:fb:a7:b8:99:6b:66:
+ 20:2e:56:9c:44:b4:e3:5e:80:c4:7d:78:a1:b4:05:
+ f7:20:7d:26:1e:44:bf:5d:69:15:3c:7a:24:67:bd:
+ b9:b5:08:0f:33:4d:af:3b:2d:e7:b9:ab:1d:2b:d6:
+ fb:73
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 6C:B3:65:94:FE:C6:9F:4A:50:9D:4D:8B:40:1A:A1:FD:97:17:97:92
+ X509v3 Authority Key Identifier:
+ keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 44:d8:15:ad:71:7e:e9:6e:ec:33:2b:42:ed:8c:8a:4a:df:82:
+ a4:91:99:57:b0:2f:cc:a3:59:2a:ff:24:c5:ac:e1:79:fa:d7:
+ 92:ba:72:2b:47:1a:cf:80:6d:08:76:e9:b5:91:60:35:1f:dd:
+ 0c:e0:bd:33:7c:27:d0:f7:11:4e:1f:48:4a:05:bc:6d:e3:5f:
+ ba:dd:7a:ba:3d:45:7d:97:72:94:9b:cd:31:76:b8:96:df:f0:
+ 7d:16:f3:2a:a3:e2:72:eb:02:1f:49:ee:b6:44:48:5b:69:99:
+ b8:bb:80:3b:cb:f5:bc:aa:f8:ba:68:19:53:ec:ff:ad:75:ae:
+ 82:51:00:ec:e7:81:c2:6b:cf:a2:a2:a2:c5:b8:04:47:91:ad:
+ 9d:33:72:48:a2:15:55:ad:43:52:8f:f6:09:a3:d3:fd:88:d3:
+ e3:c3:f4:cd:71:e8:cb:aa:e7:36:07:27:d9:e9:a4:a1:e8:33:
+ cd:2d:9c:37:ee:48:e4:8f:8e:f0:84:67:64:89:ea:9a:23:e0:
+ 12:01:25:80:41:70:fa:b8:3a:c7:0d:b7:c9:ac:79:37:2a:b1:
+ d7:62:79:ea:db:74:b4:f5:86:86:b6:1e:d5:d0:b0:29:96:a3:
+ 58:a9:f7:3f:df:8d:31:c1:90:d1:df:1b:c3:f4:14:f8:1d:d1:
+ c9:57:95:7f
+-----BEGIN CERTIFICATE-----
+MIID3jCCAsagAwIBAgIBAjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgyMFoXDTA4MDczMTE0NDgyMFowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
+m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
+D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
+tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
+OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjggEqMIIBJjAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBRss2WU/safSlCdTYtAGqH9lxeXkjAfBgNVHSME
+GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
+BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDViLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
+Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwOQYIKwYBBQUHAQcB
+Af8EKjAoMAwEAgABMAYDBAAKAwAwGAQCAAIwEgMQACABDbgAAAAAAAAAAAoDADAN
+BgkqhkiG9w0BAQUFAAOCAQEARNgVrXF+6W7sMytC7YyKSt+CpJGZV7AvzKNZKv8k
+xazhefrXkrpyK0caz4BtCHbptZFgNR/dDOC9M3wn0PcRTh9ISgW8beNfut16uj1F
+fZdylJvNMXa4lt/wfRbzKqPicusCH0nutkRIW2mZuLuAO8v1vKr4umgZU+z/rXWu
+glEA7OeBwmvPoqKixbgER5GtnTNySKIVVa1DUo/2CaPT/YjT48P0zXHoy6rnNgcn
+2emkoegzzS2cN+5I5I+O8IRnZInqmiPgEgElgEFw+rg6xw23yax5Nyqx12J56tt0
+tPWGhrYe1dCwKZajWKn3P9+NMcGQ0d8bw/QU+B3RyVeVfw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP5b.cnf b/scripts/resource-cert-samples/ISP5b.cnf
new file mode 100644
index 00000000..aaaf9777
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5b.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = ISP5b.cer
+serial = ISP5b/serial
+private_key = ISP5b.key
+database = ISP5b/index
+new_certs_dir = ISP5b
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY ISP5b
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+#sbgp-autonomousSysNum = critical,???
+sbgp-ipAddrBlock = critical,IPv4:10.3.0.0/24,IPv6:2001:db8::a03:0/120
diff --git a/scripts/resource-cert-samples/ISP5b.key b/scripts/resource-cert-samples/ISP5b.key
new file mode 100644
index 00000000..60313862
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5b.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEpAIBAAKCAQEAv49Z2Pz6HQRwKc57AWQhQNxcQ/5Mr4jIYpu+nHKPiqU0ijsj
+jZuKT79mrGhxnP1oWfW/n00utdbj+r3zYFNctxGslQvAh82ZnpRXjewFuN+q/I44
+0w9lbQlg8uGYgXLYUT5BkbMQlfX10PnlXKGF+nEmhePRTAJ/FOIeSoqWaJ7WFqXv
+rbWDYs0jdHyCVrTRNFNainphn65UW+/5Vt6Ha0KSvEn0tcM1B0oYR9KSxhwWdHSx
+6Tk8UxIFnevcnHIrl00nIXeWfUzOeQz7p7iZa2YgLlacRLTjXoDEfXihtAX3IH0m
+HkS/XWkVPHokZ725tQgPM02vOy3nuasdK9b7cwIDAQABAoIBAEURnOW+ITiBNyf7
+ySIxRkQqsCHb+S55dTcIzOt/6v2kn5MPy7vtTyt96blUV1KxlASLtTHtFGCAQOdR
+wgUDSbTAbKe4+wx8N12UQxVq+o00KGSzqw1+yaVM8mXgrapPDGwOtHmiROKtMprM
+38RMgRBR5//yqq5rYALZnO5nld/WdcthhCjrb6zltE4n9E/jDwIC1ug5vfIX/wWq
+6f8lrQ/Lq5IduFntShh8Ld4rQewSjul6wprGsSeG3CLS+9+2cnR2uunhA9c2CS/X
+qnZgoUVrDI9ooBU/IQ7y68j+0JPureM/XMy2poyi+KmI8PTz3G6IgEqNDmbcc16Q
+K5hvBOECgYEA37OoIV+616WQme4uW2Wmk4ZLu5Qs4VeIIXg1WUi+s3YcHDfL/oib
+sNfDy7pEOvGA2F6hO5vuZ2QGZx8J7qJOCE2AbgVbvF4w70ft/g3ftDtZQHhp+NBN
+XyeIJeBcY0PVsUMgS4gKPqNib5bSDpMYN2w/rsO4ylSKs/cI5d/GB7sCgYEA2zev
+kem0+22dmBCggTWpTfvWxdJkkzMAoxvIfvfrN6Ic6h2Dw29qxYlw8+38PS/Xrw77
+kUhnMfMNvwWTkqQ/i5XLxsZ66Or6f/GEoQQMgsCXAOv4vAFWZVwLVQ3Lu4mcyPmJ
+1bX6KKKFpanMof9+54KPOxz+H0uesWBxLleLE6kCgYBTzhJmrl5o+3W4tSpYwzQs
+gFtO4qwNn6U4JLiXwlDvGohdaenaaYMqNSr838M/8cm7RXhRxJED2s0rRM2LwPJK
+2f4LOaasYv0iJ2hZjQkJlFJTfMj2ldLmmwC+b9csuPUNe4BVy5lK7hqqg24eV6zy
+1nLlHh3UbuenlByZQcQGkQKBgQDY1tpKILyuv5zVYA0EAkp4IxYtE5H8sMR+kurd
+/OmkXCzxv0QouzsILo2WG+AXvg1A0jcxXEcHd34vZ5qzwNhCgGfTNV06q8Qhbotc
+oh6l707u0Ht3rHMDS+rBtSXDWbnGal9XD+xk6W39kloiHBIxekmnlWQhHLHajqUl
+y958EQKBgQCIanjEpqaekayux7wQXPiJEAl3vQ71rbasqufX5f2x4TwIu4dUFoVo
+PoYfEesJ2iZYkK8jQJA9eGbq8c6AZFDcTkKW7rf3W8pxunXk0qF5FaVQMPl6jMLr
+aR6sRBSlwppoBgol/DcTphmTUgeTKhgNMyQ0LAQteLySqgzzouTG9g==
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/ISP5b.req b/scripts/resource-cert-samples/ISP5b.req
new file mode 100644
index 00000000..22759ecb
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5b.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYTCCAUkCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0G
+CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyv
+iMhim76cco+KpTSKOyONm4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CH
+zZmelFeN7AW436r8jjjTD2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FM
+An8U4h5KipZontYWpe+ttYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1
+wzUHShhH0pLGHBZ0dLHpOTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxE
+tONegMR9eKG0BfcgfSYeRL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGg
+ADANBgkqhkiG9w0BAQUFAAOCAQEAjh7C2XbXMGesB0yJGNQUwnS2ByB8SCA76s4f
+yNvJ7Q/sbd7q67/Bujx7F29MlIISPV/BPeLhktWfP7hOgYc+Y45dF4GikQpW1bFs
+o9M26Vk921rSctcvb3bvGT0Ri34zOYKjNki44n9EAG2CsRTfpyI+D14TzGlufEGy
+Ejdig28wuE+wr0QNtLG2i9t0KfSxbSofCvM1r2JplmHFf5xjHmXaA9agXrdx5I52
+FBLuLeE3RJL4hY+5aCk5sPKKEQUd2OTToNRyZbg3lfXaqlaqy81bC4T02tBsKjms
+09gk6kQoHB9vZ+9kqK/tkpb2ihVasnnm2KMwc147C4JHiOrfxA==
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP5b/index b/scripts/resource-cert-samples/ISP5b/index
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5b/index
diff --git a/scripts/resource-cert-samples/ISP5b/serial b/scripts/resource-cert-samples/ISP5b/serial
new file mode 100644
index 00000000..8a0f05e1
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5b/serial
@@ -0,0 +1 @@
+01
diff --git a/scripts/resource-cert-samples/ISP5c.cer b/scripts/resource-cert-samples/ISP5c.cer
new file mode 100644
index 00000000..5f7a0a59
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5c.cer
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 1 (0x1)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY ISP5c
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:c8:8b:a1:25:65:df:ee:a2:7f:54:af:52:0a:1a:
+ 1a:fa:0d:75:b3:3c:e9:e0:29:d3:89:20:e9:51:49:
+ 67:2c:43:da:a0:2c:d4:44:b3:96:14:a9:07:77:60:
+ b9:6f:01:ef:8e:54:a5:74:ac:5a:67:f8:30:4d:10:
+ f9:ac:9f:b8:75:61:0b:f6:e7:7c:ea:9b:5c:98:7a:
+ 4b:3e:c4:e2:59:42:d3:19:ca:0f:58:0e:b7:c8:82:
+ 4e:e5:bb:ac:fd:92:e5:88:b2:fc:64:cf:6e:38:3b:
+ 18:83:fc:e7:a6:ae:fb:90:36:d0:e1:ca:4d:90:41:
+ 0f:0f:3b:2a:c0:0c:d9:7b:7d:e8:50:13:f6:09:73:
+ 82:a3:d2:e3:bb:82:08:87:7f:d2:bb:0e:0e:7a:28:
+ b6:25:02:b5:d9:51:fc:33:32:47:47:ff:cf:7f:bc:
+ ee:00:01:bb:05:5e:2e:03:9a:ad:95:3b:ca:c2:c6:
+ 87:64:74:39:aa:59:6b:ae:e0:a7:51:1a:07:f2:8e:
+ 4c:8e:65:2f:df:f2:99:ba:e0:b6:8a:4f:c0:20:72:
+ 79:98:00:8f:0d:50:13:3d:d1:3e:8c:bd:dc:74:a9:
+ 33:a8:56:1d:31:78:7c:e7:02:9e:8d:0a:14:12:6d:
+ d3:37:c7:7a:f0:84:10:fe:fe:4d:28:97:26:6e:08:
+ 85:a1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 2D:87:C1:9A:F8:58:2B:BD:C2:F8:7E:30:47:B3:A9:88:37:C9:EB:46
+ X509v3 Authority Key Identifier:
+ keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 50:6b:1b:84:77:e5:93:08:5e:dc:42:24:86:70:11:24:f8:11:
+ 91:68:0f:08:9b:49:f6:4a:27:85:13:93:ed:59:49:d0:f8:a6:
+ d2:44:ab:25:69:41:59:40:8b:78:ab:d2:8d:09:a8:c0:fe:20:
+ 49:d7:47:c4:de:19:a1:79:d2:8d:bd:29:08:37:a8:9a:b6:5e:
+ 56:25:50:da:1c:47:e8:bf:ed:1e:49:79:48:81:07:97:d3:2f:
+ 14:e7:bc:8e:e9:ef:82:9a:bd:18:60:08:08:57:22:6e:45:bb:
+ 1a:9f:69:e0:0f:86:42:49:ec:d2:5f:6f:fb:01:b0:b9:56:66:
+ aa:62:64:e1:80:68:ee:11:d9:45:b8:3a:fc:81:4b:d4:c0:f7:
+ 1c:a7:97:9a:7d:f7:94:2c:05:86:35:2e:0c:83:17:45:b6:3f:
+ d6:4e:5f:ba:2d:77:41:4a:25:37:b9:8b:4a:4e:b4:36:f5:c9:
+ f7:84:e0:6b:af:1c:d5:e0:88:a5:aa:6f:87:10:18:c3:af:46:
+ ee:63:97:e3:66:98:bb:51:67:89:d6:4d:8f:b2:ed:f6:33:ae:
+ 5b:44:44:1e:56:af:ac:6d:7b:1f:13:f9:96:84:ee:08:db:4b:
+ 1f:56:48:ac:97:0e:ee:b5:33:f4:2d:03:62:a3:32:6d:85:85:
+ 52:a6:47:ca
+-----BEGIN CERTIFICATE-----
+MIIDxjCCAq6gAwIBAgIBATANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgxOFoXDTA4MDczMTE0NDgxOFowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
+s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
+DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
+c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
+dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjggESMIIBDjAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQth8Ga+FgrvcL4fjBHs6mIN8nrRjAfBgNVHSME
+GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
+BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDVjLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
+Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwIQYIKwYBBQUHAQgB
+Af8EEjAQoA4wDDAKAgMA/BYCAwD8HDANBgkqhkiG9w0BAQUFAAOCAQEAUGsbhHfl
+kwhe3EIkhnARJPgRkWgPCJtJ9konhROT7VlJ0Pim0kSrJWlBWUCLeKvSjQmowP4g
+SddHxN4ZoXnSjb0pCDeomrZeViVQ2hxH6L/tHkl5SIEHl9MvFOe8junvgpq9GGAI
+CFcibkW7Gp9p4A+GQkns0l9v+wGwuVZmqmJk4YBo7hHZRbg6/IFL1MD3HKeXmn33
+lCwFhjUuDIMXRbY/1k5fui13QUolN7mLSk60NvXJ94Tga68c1eCIpapvhxAYw69G
+7mOX42aYu1FnidZNj7Lt9jOuW0REHlavrG17HxP5loTuCNtLH1ZIrJcO7rUz9C0D
+YqMybYWFUqZHyg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/ISP5c.cnf b/scripts/resource-cert-samples/ISP5c.cnf
new file mode 100644
index 00000000..c1f892c2
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5c.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = ISP5c.cer
+serial = ISP5c/serial
+private_key = ISP5c.key
+database = ISP5c/index
+new_certs_dir = ISP5c
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY ISP5c
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+sbgp-autonomousSysNum = critical,AS:64534-64540
+#sbgp-ipAddrBlock = critical,???
diff --git a/scripts/resource-cert-samples/ISP5c.key b/scripts/resource-cert-samples/ISP5c.key
new file mode 100644
index 00000000..dc7595d0
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5c.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEogIBAAKCAQEAyIuhJWXf7qJ/VK9SChoa+g11szzp4CnTiSDpUUlnLEPaoCzU
+RLOWFKkHd2C5bwHvjlSldKxaZ/gwTRD5rJ+4dWEL9ud86ptcmHpLPsTiWULTGcoP
+WA63yIJO5bus/ZLliLL8ZM9uODsYg/znpq77kDbQ4cpNkEEPDzsqwAzZe33oUBP2
+CXOCo9Lju4IIh3/Suw4Oeii2JQK12VH8MzJHR//Pf7zuAAG7BV4uA5qtlTvKwsaH
+ZHQ5qllrruCnURoH8o5MjmUv3/KZuuC2ik/AIHJ5mACPDVATPdE+jL3cdKkzqFYd
+MXh85wKejQoUEm3TN8d68IQQ/v5NKJcmbgiFoQIDAQABAoIBAC5Y5rMn6irSby75
+HbKr+dQUTEFSMJLX18V3T7SzjB6Ux/AArEX8YxD/R3R1bCWVgvGX6m0eb/5bQ35s
+D+evOggWl5dGRH5LzYiHquAkzFLouLTbF9S4Ag1a4DUDvKUVz+pZwy7hKY3hSncm
+ebrx8b2QjZHBGU/fWUWh3O1pitGZDJ+D7zN4gsS+Q+L5heVuWlLKGsDBllIFEx+A
+lYHik6bnCWASv/ZRxxyv1v9Nc6+S1kLGkWAq/dzdRz5hS6/1/BYkYJYF+N+yOJlh
+dc8nknY3RqphRoUfKNF1mo2/CX3TiTIkI9RADl/JG7MvN8QcvsZtPY9HFvl8l3Jr
+bMeB+gECgYEA8qWQpwftUj4MFSa6H8N/cNfoNVDt6CRpy3BhqcGKstfdDNWxUEyW
+jKQnh4z+bypKuwtAzf26dlJzVz1tpTx81bvTyN/mhCd51ZLG/pWM/rmt0Hqt59M1
+AhDRaBVAN+mXZYv/4ULy0jcBzQJxRtSOGzb0CRT+SFyhlJ2aTBYh5xECgYEA05Tv
+tPhEREDYRexYEeOsAs9uxZuM1F07OYCSqsRFWjO3Qg3MvUowtZbPnryT4KCUirQY
+GCRt3zNWRkbHczxw6WWsxwv88tEQEb6HU2llZPvqz45MP77LBP7qvmASQmUOX6TI
+Qav/SLmuEwPwVrwxI2nbDQtYPryaBq5vBglcVZECgYA1AgBYzP2GYvGmyUAN4lp7
+317mDtj6RsIp5FIhkJtpOIkc3a4PubuF2/KaxS1sQZPzyqCMn6pVYOu7mjrSxyUK
+WC8LCgbExg7ynk8EnM0hdJTJH5PQOi6xVdU5ZLMTw98EGxJ6NnLvg37MN4VhkNu+
+jEHBnilyy3GtEsT7bDZZ0QKBgHqc1ej+8rjHB05GL6d2U+lxAlWb1hn/SWICY3x4
+r2QdkjbCPoL3qpChLAJmcB/9jvdudIQRIGb3niitvcnHHfvzwxO6m8SvaOuPiWbK
+Lks+Pg43/XH3hDmJ7MmUbSBy5ciBeter8A3aJMm6P55UAvntz1aY23PH4k666XYL
+GKoxAoGAB+YRlWhaIeUgTlImA33lZ89g8juxuttShAEZGtMOsX9I7J5XoxktOGI0
+Sqc2eCf/HLvcLrt1g66foAPvLmkxEHqncqLAE7MKIvMIIvCu7GVrVx/8O2vcFDed
+QV1Ruj41vFLljQqArXZ3dxCSxNRrWPFOO8c0Thfps2zBfRF1Rq0=
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/ISP5c.req b/scripts/resource-cert-samples/ISP5c.req
new file mode 100644
index 00000000..9545f976
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5c.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYTCCAUkCAQAwHDEaMBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0G
+CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOng
+KdOJIOlRSWcsQ9qgLNREs5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zq
+m1yYeks+xOJZQtMZyg9YDrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2Q
+QQ8POyrADNl7fehQE/YJc4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4A
+AbsFXi4Dmq2VO8rCxodkdDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8N
+UBM90T6Mvdx0qTOoVh0xeHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGg
+ADANBgkqhkiG9w0BAQUFAAOCAQEAj9bYIVfREySBzUhQSlbNi9kfdXgivC/4A7pn
+b4sMm081S05u0QLhyh1XNF/L3/U5yVElVHE8xobM/CuAkXpy7N5GSYj2T28Fmn77
+1y/xdGg6Jp26OkbrqY3gjQAaMigYg9/6tPAc9fgLiQAJLUUYb2hRqaqu4Ze8RrxU
+RsnVpAHWYDFWJhNqEp8eErzAVLqxpmoYJKgmpK6TKyYKuf8+xf3Rlkb4+iu2FotR
+DQrmcd6jmMjp9xLejDEuoPgcfpVP2CB1jUCAIW7yE7+a7vj9Mop1gs61zP8y/p2V
+rVnXgEy93WZLjQt1D29oKhlcFGtCG4nqIBCDAWVuz/LGACB85w==
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/ISP5c/index b/scripts/resource-cert-samples/ISP5c/index
new file mode 100644
index 00000000..e69de29b
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5c/index
diff --git a/scripts/resource-cert-samples/ISP5c/serial b/scripts/resource-cert-samples/ISP5c/serial
new file mode 100644
index 00000000..8a0f05e1
--- /dev/null
+++ b/scripts/resource-cert-samples/ISP5c/serial
@@ -0,0 +1 @@
+01
diff --git a/scripts/resource-cert-samples/LIR1.cer b/scripts/resource-cert-samples/LIR1.cer
new file mode 100644
index 00000000..64f73b83
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1.cer
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 16 (0x10)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 72:7d:dd:a4:60:23:71:e4:99:28:0b:9a:ba:5c:d3:97:4b:72:
+ eb:89:81:3c:11:85:8c:25:ed:79:b2:50:a5:e8:ae:0e:37:74:
+ f9:2c:a1:be:96:83:35:40:0d:36:f9:32:16:74:25:9c:f7:0f:
+ cd:46:47:8e:b9:cd:ac:0c:7e:d3:ac:84:5e:f6:31:f4:a9:f2:
+ 05:cd:82:d7:e0:d7:3b:24:9b:c7:15:d1:db:9d:c2:1d:92:f7:
+ 19:a9:b8:a1:67:0a:fb:3d:23:3a:05:83:29:05:50:e3:00:27:
+ a9:80:fe:bb:51:f1:3e:3b:0c:98:ae:f1:ee:d1:13:72:46:64:
+ 8f:4b:32:4e:cf:64:cf:1a:a5:b1:34:a6:f0:5f:18:f8:44:bb:
+ 13:ea:8d:5f:24:7d:3b:15:60:8e:be:f4:bd:d8:04:a7:d0:10:
+ 7e:d3:10:67:bf:35:49:c9:56:cf:b7:8b:7b:9b:17:0b:54:ee:
+ 21:cb:75:b0:3e:8d:b2:c1:c6:7c:26:b1:7c:58:a9:4a:31:24:
+ cd:e5:3f:a5:9a:1d:7d:11:14:41:2a:e5:55:b6:db:f4:75:34:
+ 37:9f:5e:1d:f1:86:2a:f6:74:be:88:e1:b9:63:ce:ad:5c:e9:
+ 3c:91:8a:4c:8d:b4:69:03:e7:f9:52:79:28:7d:cd:7f:52:02:
+ 49:ae:d5:c7
+-----BEGIN CERTIFICATE-----
+MIID9jCCAt6gAwIBAgIBEDANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBRDCCAUAwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYEAgABMCAwDgMFAMAAAgED
+BQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEAcn3dpGAj
+ceSZKAuaulzTl0ty64mBPBGFjCXtebJQpeiuDjd0+SyhvpaDNUANNvkyFnQlnPcP
+zUZHjrnNrAx+06yEXvYx9KnyBc2C1+DXOySbxxXR253CHZL3Gam4oWcK+z0jOgWD
+KQVQ4wAnqYD+u1HxPjsMmK7x7tETckZkj0syTs9kzxqlsTSm8F8Y+ES7E+qNXyR9
+OxVgjr70vdgEp9AQftMQZ781SclWz7eLe5sXC1TuIct1sD6NssHGfCaxfFipSjEk
+zeU/pZodfREUQSrlVbbb9HU0N59eHfGGKvZ0vojhuWPOrVzpPJGKTI20aQPn+VJ5
+KH3Nf1ICSa7Vxw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1.cnf b/scripts/resource-cert-samples/LIR1.cnf
new file mode 100644
index 00000000..437963ee
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = LIR1.cer
+serial = LIR1/serial
+private_key = LIR1.key
+database = LIR1/index
+new_certs_dir = LIR1
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY LIR1
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR1/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+sbgp-autonomousSysNum = critical,AS:64533
+sbgp-ipAddrBlock = critical,IPv4:192.0.2.1-192.0.2.33,IPv4:192.0.2.44-192.0.2.100
diff --git a/scripts/resource-cert-samples/LIR1.key b/scripts/resource-cert-samples/LIR1.key
new file mode 100644
index 00000000..0f79c031
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEpQIBAAKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64U
+Yum8tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/
+lizduJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisT
+ecKy8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++
+LJ1edSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLs
+r2XVuWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABAoIBAQCeqVFRIVWXiGb7
+3x2Hvz9sb9wPIy/hNkphCbJ4SL1UEUH6ao8ZWz8Zl4cKqEfmHm2EIW2vJmpOiwK7
+GNL6lrmrMOMItWFrXzPlgz/6lUKeZ9MzTcGR/y/wFvM8zggI0SpQV7XfxlkMJ6OS
+7H+On7yBobKen8eCkUzpksm/E3fK/9llCsY14arag7CxIR+G239Eh9yfKlIYPb7D
+U1UR7wrDeLvRVkP3C+BBCYrP4fNkSpdd5Xn02nrNXdSM+BR3O7cWXjtvGiUJbdSw
+Ec4sfApj0YCFP7ZBx+WvMavRGKfz8VCDzs2LNvu5szOGt87CVxVvjsheNCzDfmwD
+JzBo9q7hAoGBANe2RljcUbbEBF+PjjUHgmt/HCbyqhcwjiwJsQh6m6AY7HjrWawf
+zB7ud1oTrMUzW87qTZcn5XnNPl266bEjo54Xbm1QHvNxzWKmHclYjzYbyPnz6z91
+9WY/PKs7+VtHz/XZD9q8UbbrDM5GLBtNR2bd3AmKjDtnprIXhq30LCPxAoGBANAd
+r9gWSA6qnuhiCG5/b9LtR1hBYftchw3UQNdMrmmqK1OteuyPG5CkyMinq49uHRjX
+ZWU58y97PvSy+oqXeDQBNp85/ojkqBooV1JiA/leu0AzYNCOV2j/NaaTk35IoqFm
+OQyc90JA1yDAzSBaEGXc1L59Rrng/tPnRKEJvLEvAoGBAJYi6YeDoOQiPiD826+R
+EHcdO0zobPZC91EzVaJfI94kOsJWnE0uvHVy6GMren6upmG3tlVUkWVbMuMt6uU9
+tu2bxWIT99bdCGR21hiDqPmyEQnXeY7r3OdTcDiGP6IGs3mboGtP01gK9RjEwoIm
+IWI5XKLPaZcXJ3Cg6z47ylUhAoGBAMIN/Go8FIKAe93pkz0dXPLLx0u245sTIuc1
+NCTNXpAuWWoUB9vOcQCFdqcLGQCLx1vjdKtXxrdOb1ySCuXx6OZs/zanR/zzYP/K
+/+lUdaovt+BcR/kP0NeZqLgjQVNufR6MB8QIFNJVTYM/48U31bR1nnXksG8gKd0C
+905FmwmHAoGAa2SzsiVuvx+ROq7zsN/L32tJY8iL5N0r4qYQWuPK/+C6VK3zUtjb
+jcj76nGADSxGapDciZI2p/QCAxLQnLJHn4f67VctaifiaslmI2uHbN3opvtc1E7I
+PmPL7Jm4Ib3C6Q3Y4+TKHPRZvjDfmUfQdk2mWF72DlUBZE4EnTUYWVA=
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/LIR1.req b/scripts/resource-cert-samples/LIR1.req
new file mode 100644
index 00000000..78f52184
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMTCCASIwDQYJ
+KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK9dHPnZu9UB4Vs2zFH2/YZXYKqex+xO
+Ba/7UVx6wljEqFeuFGLpvLZyfc9JyEpAgkr0PjC1lCWebHiBV0PWhQKN0Zy11zQv
+4ql9GCe1R5pCFsiQf5Ys3biYFx93YkoIAC3gcww5N7oPp1lZTHzN4lzXmDYQbIg+
+RZmmiC/2fzFJukIrE3nCsvEJ2a03pEG2bUahGAWgUweO4Jiy0f1naHdk1fP+HSI2
+niZaGqoYlMMsfpqvviydXnUsSdY3KwYfzGOXfu4sX2evTWI+eh8M4R4C8tIGda4/
+EbyODxNkOBQ2HV0C7K9l1blo9CJmK+9HW6078q+2cQyUVop8ATbwOj8CAwEAAaAA
+MA0GCSqGSIb3DQEBBQUAA4IBAQBGjdamDbzptBCgaTgIBVCNV74KP1rBFIexYlue
+XG00WLdNuJxsy6a0PODSD7NuZexVlKLRLTPw4V1P7St0Vi1Cvf324MsDqfTc4wEv
+pbV/eLL6b3EPJbI8eLyH4NoadhovZNzzdYk8DAsMqvr+1h2Jc6oECy6ItH1TVFMR
+G06ovdkU5scfCFQkoAOppyhwAhhr96F9vjVvFAs3v/3YnyLk+Sjw2xS0KFmdCveV
+3AmguPTmfzdwdjvolnTPi3veaWIjNJDRv/vWKAGm2ZTPUYuUAKFUekok2XsiZRkg
+HmXYfBWnueSU09CQNJO7GIzFLO4/FfrsHaZdY4ObjuYKa6AV
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/LIR1/01.pem b/scripts/resource-cert-samples/LIR1/01.pem
new file mode 100644
index 00000000..29733e89
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/01.pem
@@ -0,0 +1,23 @@
+-----BEGIN CERTIFICATE-----
+MIIDzDCCArSgAwIBAgIBATANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTA1NDUyOVoXDTA4MDczMTA1NDUyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOCARkwggEVMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFHOyFhrN3NcwYA/6gZX4ovVOlfOtMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMCkGCCsGAQUFBwEHAQH/
+BBowGDAWBAIAATAQMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEA
+FmbqWBmcgPw3k/OjxA3mZX807TFQiP7mB8SCzWNbXeCRuWdhcNzcLSgxZovfvREB
+Op6/dlpd3XXrY94uwKsZbgq2+qRQZFdYHJh1WE0KHkgvf6krFNTl6hVKrbosSY9A
+T9uHihn6L4kBYp29D4wLINNDgJR4QdzhKjvH+l/pYACteUcFb5MFI2RvmNjRlCj4
+9QWwl0o1to0LlIvS+k1ROu69a6EvzBCO5JMpp8o6+yzz8UCbn+4rcJYaoxkq4cR/
+esIYsghTavMYgTm13U3IZfRoKTu32t9k8aYsQ/bcmF9l31pI7HQIUI6KwhgBAtkE
+Ivo8c0ekAlpRKRlodSrb+w==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/02.pem b/scripts/resource-cert-samples/LIR1/02.pem
new file mode 100644
index 00000000..0bcefb6f
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/02.pem
@@ -0,0 +1,23 @@
+-----BEGIN CERTIFICATE-----
+MIID6DCCAtCgAwIBAgIBAjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTA1NDUzMloXDTA4MDczMTA1NDUzMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCATUwggExMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUAwAAC
+AQMFAcAAAiAwDQYJKoZIhvcNAQEFBQADggEBABJPI16u1ywCxckILgDoEsNompwz
+KH1JqwC3ItaXvsUPmnMU1H4eN8Ehh226p10JmPlTEiEu3nnZGfmNN3D1fKvfeqdU
+C3Hwws/H1L/O1zymy/NBSp+bEAkdsmR1TX3brCfjigjxUY7CjI33Bjx9WI50ZVZn
++Pmj30Ojef8QhGwML7qiLE5xBzLoTyIMrIBiBq6H2DAUaL1PhSCXzUdHQNAYz9nK
+KrU4HP7Q8O2YtjNItgxyt7uGy0WbT13PdbmWasgf6lfLXMAqrqDXaWr6wGS9hlER
+SKRH53fVsd1oGtkJ0LbPuHu6p99CGMz6+Ah8UryjFQxGeZPdVEWbwTBZSms=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/03.pem b/scripts/resource-cert-samples/LIR1/03.pem
new file mode 100644
index 00000000..e6b6ac76
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/03.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 3 (0x3)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:05:29 2007 GMT
+ Not After : Jul 31 14:05:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 2c:66:2e:23:8b:0c:9a:b9:a4:48:06:1e:da:0d:8a:51:f0:f3:
+ c2:0c:0b:d8:ea:10:2e:24:a9:f1:a8:a2:da:dd:8c:09:0f:7a:
+ 9a:fb:54:b2:44:6a:32:91:9e:88:d3:db:5e:53:49:dc:12:59:
+ 9b:b5:7c:55:86:85:48:74:9e:03:e4:42:3d:68:f2:ee:e8:ca:
+ fa:cc:56:9f:1e:b0:49:61:af:b1:6d:f1:d5:1a:3c:3e:2e:86:
+ 4c:a3:ff:31:a5:2f:91:64:3a:f5:7e:6a:78:b5:cd:80:d7:34:
+ 38:72:f4:18:0c:c6:de:f5:bb:d8:89:84:6d:69:1f:da:42:b4:
+ fc:73:34:76:fa:42:df:bd:a1:e0:6e:f4:5b:b1:18:70:15:b3:
+ 75:02:a6:0d:e0:79:de:fd:d5:bd:2e:a0:22:df:bf:4f:dc:15:
+ 1f:8e:23:26:26:ab:7b:67:5a:c0:f3:39:25:fd:d6:97:47:f3:
+ e0:c5:8c:6e:b3:19:b6:f2:0f:98:f4:8c:57:59:88:9f:b0:b4:
+ c6:0e:f8:56:60:f2:1a:f5:ad:20:5e:dc:93:2d:7e:e8:2f:44:
+ 54:ff:5d:21:d6:df:17:36:31:c8:d7:af:c4:f8:c6:58:31:59:
+ df:34:12:81:4d:eb:5c:ca:ee:7f:b7:4c:c2:17:8a:94:66:f1:
+ e5:4d:e4:67
+-----BEGIN CERTIFICATE-----
+MIIDzDCCArSgAwIBAgIBAzANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0MDUyOVoXDTA4MDczMTE0MDUyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOCARkwggEVMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFHOyFhrN3NcwYA/6gZX4ovVOlfOtMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMCkGCCsGAQUFBwEHAQH/
+BBowGDAWBAIAATAQMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEA
+LGYuI4sMmrmkSAYe2g2KUfDzwgwL2OoQLiSp8aii2t2MCQ96mvtUskRqMpGeiNPb
+XlNJ3BJZm7V8VYaFSHSeA+RCPWjy7ujK+sxWnx6wSWGvsW3x1Ro8Pi6GTKP/MaUv
+kWQ69X5qeLXNgNc0OHL0GAzG3vW72ImEbWkf2kK0/HM0dvpC372h4G70W7EYcBWz
+dQKmDeB53v3VvS6gIt+/T9wVH44jJiare2dawPM5Jf3Wl0fz4MWMbrMZtvIPmPSM
+V1mIn7C0xg74VmDyGvWtIF7cky1+6C9EVP9dIdbfFzYxyNevxPjGWDFZ3zQSgU3r
+XMruf7dMwheKlGbx5U3kZw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/04.pem b/scripts/resource-cert-samples/LIR1/04.pem
new file mode 100644
index 00000000..193985fc
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/04.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 4 (0x4)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:05:29 2007 GMT
+ Not After : Jul 31 14:05:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 7b:5f:02:90:6c:dc:6a:39:29:5a:23:3a:03:ab:7b:7e:80:fe:
+ ed:ce:07:e2:9e:e9:0d:4d:dd:c2:40:6a:9d:07:ce:b3:af:ba:
+ cf:b5:7b:45:77:bd:c2:bf:b5:52:94:f6:14:37:2a:3c:a4:00:
+ c6:6a:bd:26:66:b8:51:5a:9d:16:1c:9b:69:8e:a4:8f:42:39:
+ 39:97:9f:77:0d:08:73:5d:8f:e3:d4:d9:2f:c0:8d:d2:e5:18:
+ f0:6a:4b:d2:15:d3:f6:8a:fd:1a:e9:da:28:98:93:87:21:97:
+ e6:dc:73:ac:80:e3:08:ff:0e:27:a5:f5:37:0d:dc:0a:29:eb:
+ 5a:48:03:57:24:29:fe:7f:62:07:7f:77:c0:11:ae:d7:27:c6:
+ f4:21:78:26:10:cb:f8:04:ba:21:5f:c3:4f:dc:b5:60:4b:44:
+ 0f:a5:64:f6:4d:d6:6e:08:9f:f2:bb:9a:04:89:44:65:1c:b5:
+ c2:01:0d:4f:03:c1:97:31:d5:0b:4e:66:99:85:df:d0:45:b1:
+ f2:a8:ba:47:9e:4d:c9:b9:73:d7:e4:fa:1f:e9:0a:d5:be:a5:
+ 34:32:c9:07:df:6d:2f:b3:9d:11:8c:f4:0a:68:bb:b1:fa:43:
+ 77:be:fd:84:d5:36:5c:f3:cb:ad:c4:ff:96:9b:79:77:79:01:
+ 46:e0:92:91
+-----BEGIN CERTIFICATE-----
+MIID6DCCAtCgAwIBAgIBBDANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0MDUyOVoXDTA4MDczMTE0MDUyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCATUwggExMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUAwAAC
+AQMFAcAAAiAwDQYJKoZIhvcNAQEFBQADggEBAHtfApBs3Go5KVojOgOre36A/u3O
+B+Ke6Q1N3cJAap0HzrOvus+1e0V3vcK/tVKU9hQ3KjykAMZqvSZmuFFanRYcm2mO
+pI9COTmXn3cNCHNdj+PU2S/AjdLlGPBqS9IV0/aK/Rrp2iiYk4chl+bcc6yA4wj/
+Diel9TcN3Aop61pIA1ckKf5/Ygd/d8ARrtcnxvQheCYQy/gEuiFfw0/ctWBLRA+l
+ZPZN1m4In/K7mgSJRGUctcIBDU8DwZcx1QtOZpmF39BFsfKoukeeTcm5c9fk+h/p
+CtW+pTQyyQffbS+znRGM9Apou7H6Q3e+/YTVNlzzy63E/5abeXd5AUbgkpE=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/05.pem b/scripts/resource-cert-samples/LIR1/05.pem
new file mode 100644
index 00000000..d39a4c28
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/05.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 5 (0x5)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:08:29 2007 GMT
+ Not After : Jul 31 14:08:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 46:2c:90:67:a5:55:7e:77:09:b8:1e:6a:87:44:25:86:d1:82:
+ 3a:c9:a8:54:5f:fd:cc:92:fe:55:32:11:12:6c:61:7c:13:aa:
+ 80:85:bf:68:1a:7f:98:67:32:23:0f:ff:61:70:6f:50:cb:e1:
+ 64:4a:76:85:f1:99:6b:b8:59:6a:1a:23:65:14:e5:dc:ae:de:
+ 50:92:54:98:eb:b2:80:2b:4a:32:77:87:71:1a:52:a8:64:a6:
+ b9:22:91:74:35:33:29:43:f2:db:0c:ba:21:99:e8:e3:98:e2:
+ 6d:a9:1e:7a:9f:db:fb:a7:2a:ab:8a:f5:f6:28:99:4b:11:5c:
+ f2:d2:d3:e7:4d:02:09:8a:b1:1b:b2:41:5d:72:fa:89:37:a6:
+ ec:f7:ed:7a:b2:0c:d7:2e:c0:17:16:1c:33:7f:22:49:3e:13:
+ 88:67:c3:b1:ac:1b:5f:b5:81:4d:25:9e:87:7b:6c:95:90:57:
+ e5:4e:2c:ab:4a:96:4a:e8:9c:d8:19:58:d0:a2:c5:9a:bc:f4:
+ 9a:96:17:bd:dd:a4:55:20:87:25:4c:91:70:73:99:fc:86:a9:
+ 1a:0f:8f:63:6a:9a:85:37:69:48:9d:b9:ff:59:7b:2e:ae:bb:
+ 70:27:0c:a2:1b:4d:2a:21:1f:b6:89:fa:c7:0a:5a:47:6d:22:
+ 1b:3f:97:a7
+-----BEGIN CERTIFICATE-----
+MIIDzDCCArSgAwIBAgIBBTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0MDgyOVoXDTA4MDczMTE0MDgyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOCARkwggEVMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFHOyFhrN3NcwYA/6gZX4ovVOlfOtMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMCkGCCsGAQUFBwEHAQH/
+BBowGDAWBAIAATAQMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEA
+RiyQZ6VVfncJuB5qh0QlhtGCOsmoVF/9zJL+VTIREmxhfBOqgIW/aBp/mGcyIw//
+YXBvUMvhZEp2hfGZa7hZahojZRTl3K7eUJJUmOuygCtKMneHcRpSqGSmuSKRdDUz
+KUPy2wy6IZno45jibakeep/b+6cqq4r19iiZSxFc8tLT500CCYqxG7JBXXL6iTem
+7PfterIM1y7AFxYcM38iST4TiGfDsawbX7WBTSWeh3tslZBX5U4sq0qWSuic2BlY
+0KLFmrz0mpYXvd2kVSCHJUyRcHOZ/IapGg+PY2qahTdpSJ25/1l7Lq67cCcMohtN
+KiEfton6xwpaR20iGz+Xpw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/06.pem b/scripts/resource-cert-samples/LIR1/06.pem
new file mode 100644
index 00000000..c03635c3
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/06.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 6 (0x6)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:08:29 2007 GMT
+ Not After : Jul 31 14:08:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha1WithRSAEncryption
+ a2:f2:1a:a9:b9:28:fd:c0:26:62:1f:01:e1:02:29:b7:8c:b8:
+ 96:4e:b7:e9:6d:00:f2:85:6c:c9:7c:af:b1:d7:e6:b5:90:21:
+ 7c:33:94:95:72:9c:c9:36:5e:68:1a:71:af:47:a7:ca:b5:4c:
+ 16:aa:ea:5d:fd:1b:c1:b9:52:a7:05:db:66:93:c4:95:a5:c6:
+ 58:16:60:04:73:94:3b:be:7c:a3:34:84:af:d5:7a:03:26:57:
+ 09:b2:db:02:59:0b:54:58:23:a5:3f:9c:f1:ad:b4:2e:2b:1b:
+ e5:67:9d:c5:41:01:05:b2:7b:76:26:00:dd:1c:c5:c4:d4:31:
+ 3d:9a:ba:1d:4f:7c:93:31:5f:fa:43:4a:ce:ab:db:6f:9d:d6:
+ fa:9b:c4:ad:be:2c:68:1b:64:23:fb:01:d3:b7:db:fc:a4:1c:
+ ec:f6:36:79:02:d8:b4:99:af:de:1f:a2:68:15:ad:bc:66:18:
+ 31:3e:6d:3b:97:2e:f8:b0:f0:89:36:67:8e:e3:54:45:65:bf:
+ aa:87:a7:81:83:c2:d3:19:4f:77:91:6a:50:12:9e:85:e8:b6:
+ 95:b1:7a:27:db:15:a7:19:66:04:d3:c6:47:49:10:a1:9f:72:
+ 3c:c3:62:1c:4a:66:5c:42:a0:2b:fd:fd:c6:48:ab:c7:55:6a:
+ 26:6e:12:8e
+-----BEGIN CERTIFICATE-----
+MIID6DCCAtCgAwIBAgIBBjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0MDgyOVoXDTA4MDczMTE0MDgyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCATUwggExMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUAwAAC
+AQMFAcAAAiAwDQYJKoZIhvcNAQEFBQADggEBAKLyGqm5KP3AJmIfAeECKbeMuJZO
+t+ltAPKFbMl8r7HX5rWQIXwzlJVynMk2Xmgaca9Hp8q1TBaq6l39G8G5UqcF22aT
+xJWlxlgWYARzlDu+fKM0hK/VegMmVwmy2wJZC1RYI6U/nPGttC4rG+VnncVBAQWy
+e3YmAN0cxcTUMT2auh1PfJMxX/pDSs6r22+d1vqbxK2+LGgbZCP7AdO32/ykHOz2
+NnkC2LSZr94fomgVrbxmGDE+bTuXLviw8Ik2Z47jVEVlv6qHp4GDwtMZT3eRalAS
+noXotpWxeifbFacZZgTTxkdJEKGfcjzDYhxKZlxCoCv9/cZIq8dVaiZuEo4=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/07.pem b/scripts/resource-cert-samples/LIR1/07.pem
new file mode 100644
index 00000000..a8742d9b
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/07.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 7 (0x7)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:09:35 2007 GMT
+ Not After : Jul 31 14:09:35 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 2d:8b:40:01:ec:c8:92:30:65:52:2b:3b:a0:66:e5:c6:e5:09:
+ 87:2b:c0:a4:10:4f:a9:e1:e2:da:17:ff:5e:30:19:16:68:78:
+ 91:5c:70:56:90:e8:e9:1a:06:94:3f:ed:0c:ef:94:aa:8a:85:
+ 55:ad:ee:ba:56:c0:fd:c1:59:6c:ac:3f:11:d5:fc:1f:10:74:
+ 3d:62:a1:c2:c3:46:76:ff:34:dd:b1:0b:c6:c1:b1:8c:7c:0c:
+ 14:aa:3b:34:a5:fb:da:6a:6c:cc:a5:3d:bc:29:66:f6:d1:7a:
+ db:84:fe:69:10:b7:02:c0:8b:29:98:1b:06:5c:fd:7b:02:64:
+ 25:91:4d:38:25:0f:2a:7a:3a:02:85:11:af:71:cc:cd:f3:45:
+ 93:e3:ae:bd:db:00:54:44:5c:c2:3e:6d:82:c1:fb:a0:13:44:
+ 02:6a:ae:25:98:8e:57:f0:b7:5f:13:e7:22:5d:36:0a:99:f7:
+ ab:21:b1:7d:79:27:ae:94:d0:97:b8:7d:a0:4e:5f:63:18:ef:
+ 7b:95:be:e6:df:e0:6c:75:a9:17:01:7e:18:41:0c:95:9f:b9:
+ a2:48:f9:13:e1:86:9a:1a:2a:9f:b8:a0:c3:8c:32:f5:10:40:
+ 77:72:65:40:c9:cf:17:fa:f3:4f:43:fe:9f:91:77:98:33:74:
+ cd:c4:6f:d9
+-----BEGIN CERTIFICATE-----
+MIIDzDCCArSgAwIBAgIBBzANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0MDkzNVoXDTA4MDczMTE0MDkzNVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOCARkwggEVMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFHOyFhrN3NcwYA/6gZX4ovVOlfOtMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMCkGCCsGAQUFBwEHAQH/
+BBowGDAWBAIAATAQMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEA
+LYtAAezIkjBlUis7oGblxuUJhyvApBBPqeHi2hf/XjAZFmh4kVxwVpDo6RoGlD/t
+DO+UqoqFVa3uulbA/cFZbKw/EdX8HxB0PWKhwsNGdv803bELxsGxjHwMFKo7NKX7
+2mpszKU9vClm9tF624T+aRC3AsCLKZgbBlz9ewJkJZFNOCUPKno6AoURr3HMzfNF
+k+OuvdsAVERcwj5tgsH7oBNEAmquJZiOV/C3XxPnIl02Cpn3qyGxfXknrpTQl7h9
+oE5fYxjve5W+5t/gbHWpFwF+GEEMlZ+5okj5E+GGmhoqn7igw4wy9RBAd3JlQMnP
+F/rzT0P+n5F3mDN0zcRv2Q==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/08.pem b/scripts/resource-cert-samples/LIR1/08.pem
new file mode 100644
index 00000000..7f2b5154
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/08.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 8 (0x8)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:09:35 2007 GMT
+ Not After : Jul 31 14:09:35 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 17:33:25:69:a3:33:ba:c8:75:1b:55:bd:1d:fb:4a:8f:f6:f5:
+ 51:f6:b6:5a:ff:e3:de:4f:cc:e9:f5:53:b1:2b:5d:7f:e4:2e:
+ a5:6d:c9:24:fa:5d:0b:dc:26:e4:45:1c:31:7e:8e:5f:3b:b4:
+ 6d:0f:6c:08:4c:90:8e:a6:50:7d:6b:32:47:2a:1e:24:f3:8f:
+ bf:4a:5a:93:1c:09:63:c1:97:2a:67:48:55:2f:95:57:41:48:
+ 48:60:6b:ef:b4:cc:9e:53:85:88:d5:b9:77:b6:a4:f2:d1:71:
+ 44:91:a1:e5:44:c5:05:2f:1d:b3:10:dd:28:39:24:1f:99:1f:
+ 12:21:4e:a8:bb:55:03:de:d0:82:7e:53:a1:9c:e9:d8:da:20:
+ 2d:3e:03:73:00:47:26:93:cc:e2:7e:84:0d:0d:67:f8:8d:e8:
+ c4:20:36:79:75:0b:d4:90:17:bf:b6:65:6f:24:07:f3:95:cd:
+ ba:49:28:c6:62:64:3a:1a:60:ea:34:7f:23:20:6f:1d:82:82:
+ 20:89:50:30:30:1a:e1:c8:8b:18:bc:eb:55:67:68:6b:12:05:
+ 42:ac:1b:1e:f2:0b:15:c3:5f:9e:8a:70:13:d5:0e:d2:d5:17:
+ 74:32:b1:32:93:a9:f1:4c:bf:8f:94:ca:70:11:4b:d5:02:8a:
+ 49:4a:df:30
+-----BEGIN CERTIFICATE-----
+MIID6DCCAtCgAwIBAgIBCDANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0MDkzNVoXDTA4MDczMTE0MDkzNVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCATUwggExMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUAwAAC
+AQMFAcAAAiAwDQYJKoZIhvcNAQEFBQADggEBABczJWmjM7rIdRtVvR37So/29VH2
+tlr/495PzOn1U7ErXX/kLqVtyST6XQvcJuRFHDF+jl87tG0PbAhMkI6mUH1rMkcq
+HiTzj79KWpMcCWPBlypnSFUvlVdBSEhga++0zJ5ThYjVuXe2pPLRcUSRoeVExQUv
+HbMQ3Sg5JB+ZHxIhTqi7VQPe0IJ+U6Gc6djaIC0+A3MARyaTzOJ+hA0NZ/iN6MQg
+Nnl1C9SQF7+2ZW8kB/OVzbpJKMZiZDoaYOo0fyMgbx2CgiCJUDAwGuHIixi861Vn
+aGsSBUKsGx7yCxXDX56KcBPVDtLVF3QysTKTqfFMv4+UynARS9UCiklK3zA=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/09.pem b/scripts/resource-cert-samples/LIR1/09.pem
new file mode 100644
index 00000000..0a5c3837
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/09.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 9 (0x9)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d0:77:df:c4:21:af:1b:5a:6b:a8:a7:28:d7:43:
+ c8:9b:6d:25:d8:8d:7f:91:2b:e3:95:fd:92:60:ac:
+ 14:12:d7:23:68:85:4b:0e:db:2b:e6:38:e0:48:db:
+ 18:37:8f:40:c0:90:58:0e:3f:09:67:5f:8e:3f:04:
+ 75:06:60:92:42:f3:e4:45:04:35:95:5d:e9:22:42:
+ 2c:f6:5c:a6:7d:79:8c:e1:08:19:7c:35:9d:3a:fd:
+ e7:ff:9b:29:b5:ee:89:47:cc:0d:83:a0:e1:73:af:
+ 1f:09:84:a8:0b:83:cc:79:88:bf:7c:1d:73:d6:ab:
+ 42:1b:64:9a:5c:19:83:2b:9d:e5:ad:4c:58:05:76:
+ 95:70:23:ee:a5:c0:31:ca:a2:a7:c8:1d:1e:f2:c9:
+ f2:3d:38:82:c2:53:e5:54:86:f2:7c:b1:73:e1:dc:
+ e9:86:73:08:ac:59:3b:be:2f:58:c1:42:c5:80:18:
+ 8c:3a:0a:2a:32:f6:fe:28:d0:28:52:83:c6:30:69:
+ 51:90:59:19:9b:d3:d4:c2:e0:52:6a:c1:4e:59:9a:
+ 18:e4:78:2e:57:f9:7f:2b:5d:76:28:c9:c9:c5:7e:
+ e5:43:a1:9b:68:d2:06:1c:be:3f:69:f9:c2:fa:9e:
+ 4f:68:cf:63:6f:db:6d:fc:67:35:c0:b1:6e:0a:37:
+ ec:33
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:B2:16:1A:CD:DC:D7:30:60:0F:FA:81:95:F8:A2:F5:4E:95:F3:AD
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 0a:f1:b5:af:38:f9:7d:93:95:d4:ea:bf:48:ef:8d:63:3c:4e:
+ 1c:80:3d:7a:06:20:42:0e:0d:52:99:aa:4b:3e:af:d7:b4:61:
+ 47:4f:b7:b4:f7:cc:9b:3c:5e:a5:3b:3c:ba:dd:b7:2a:27:8e:
+ 1b:b4:5c:3c:6b:d1:d9:ff:c2:12:f7:9d:82:ba:cf:75:34:bc:
+ d7:0b:b4:d6:a8:4f:58:93:6a:ae:23:7a:37:e3:2e:f1:70:8a:
+ dd:f5:0e:fa:df:b0:3f:12:d4:5a:ac:33:ad:15:1c:a5:dc:be:
+ 08:c3:8e:1a:0f:35:12:0e:de:ef:b8:80:78:90:a9:eb:8f:00:
+ 0a:15:1d:05:12:3a:1d:37:e9:f4:f9:4a:77:6e:69:27:b7:e3:
+ 7f:ae:78:32:92:86:6d:39:16:5e:59:4f:93:10:b5:b0:be:1c:
+ 25:47:2a:e2:8f:92:9f:5c:c0:2a:48:d7:53:00:14:8e:9e:86:
+ ea:cf:a6:21:66:50:89:95:39:3e:ff:27:95:85:ef:3d:c8:98:
+ 7f:cd:fe:c1:30:65:94:b1:ad:48:5c:ae:b7:c8:64:e9:69:a2:
+ 07:ca:c2:d7:fe:63:4b:de:a9:25:a1:91:4b:17:a3:a9:dd:2b:
+ f7:d1:a5:3e:b7:be:42:03:1e:d9:34:5f:16:e3:35:7a:ca:1d:
+ ee:3d:4c:d5
+-----BEGIN CERTIFICATE-----
+MIIDzDCCArSgAwIBAgIBCTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANB338Qhrxtaa6inKNdDyJttJdiNf5Er45X9kmCsFBLXI2iFSw7b
+K+Y44EjbGDePQMCQWA4/CWdfjj8EdQZgkkLz5EUENZVd6SJCLPZcpn15jOEIGXw1
+nTr95/+bKbXuiUfMDYOg4XOvHwmEqAuDzHmIv3wdc9arQhtkmlwZgyud5a1MWAV2
+lXAj7qXAMcqip8gdHvLJ8j04gsJT5VSG8nyxc+Hc6YZzCKxZO74vWMFCxYAYjDoK
+KjL2/ijQKFKDxjBpUZBZGZvT1MLgUmrBTlmaGOR4Llf5fytddijJycV+5UOhm2jS
+Bhy+P2n5wvqeT2jPY2/bbfxnNcCxbgo37DMCAwEAAaOCARkwggEVMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFHOyFhrN3NcwYA/6gZX4ovVOlfOtMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMi8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMCkGCCsGAQUFBwEHAQH/
+BBowGDAWBAIAATAQMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEA
+CvG1rzj5fZOV1Oq/SO+NYzxOHIA9egYgQg4NUpmqSz6v17RhR0+3tPfMmzxepTs8
+ut23KieOG7RcPGvR2f/CEvedgrrPdTS81wu01qhPWJNqriN6N+Mu8XCK3fUO+t+w
+PxLUWqwzrRUcpdy+CMOOGg81Eg7e77iAeJCp648AChUdBRI6HTfp9PlKd25pJ7fj
+f654MpKGbTkWXllPkxC1sL4cJUcq4o+Sn1zAKkjXUwAUjp6G6s+mIWZQiZU5Pv8n
+lYXvPciYf83+wTBllLGtSFyut8hk6WmiB8rC1/5jS96pJaGRSxejqd0r99GlPre+
+QgMe2TRfFuM1esod7j1M1Q==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/0A.pem b/scripts/resource-cert-samples/LIR1/0A.pem
new file mode 100644
index 00000000..86da6423
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/0A.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 10 (0xa)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR1
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:eb:80:54:7a:74:4b:e4:81:15:d0:25:2d:5e:21:
+ be:47:e6:31:ab:e2:fe:79:55:48:b7:36:55:3d:dc:
+ 11:88:5b:b7:36:be:d3:bb:d7:16:8d:f8:4b:f4:c5:
+ bd:34:c4:8e:2c:67:97:e6:27:10:40:c5:36:f4:b6:
+ 6c:b9:29:82:2e:76:b0:29:ea:43:9a:d1:30:de:05:
+ a1:c1:54:7c:17:67:1d:fc:29:dd:80:53:b2:81:30:
+ db:13:ee:3e:e6:5d:c7:bc:3d:a6:11:6d:81:77:b7:
+ 9f:3e:36:df:7c:d6:d2:5a:22:36:68:7c:14:cc:ac:
+ 54:ed:ae:fd:e2:cd:b1:a3:5d:a9:65:ec:1b:8b:4b:
+ cf:80:8e:a6:98:8f:69:b1:a6:35:bd:69:c9:2e:66:
+ 7f:22:11:66:56:c5:75:4c:81:a3:6e:49:71:0d:f5:
+ 75:87:13:e8:62:e8:1a:0c:a8:30:81:6a:be:90:59:
+ 23:3b:61:c0:15:5f:68:bf:b5:c9:3f:af:3a:a2:7f:
+ 80:01:78:f6:f4:55:ca:ee:ca:8d:08:9b:c5:3e:74:
+ 98:02:b2:0b:a6:d8:e8:6e:78:88:7b:95:76:b6:ca:
+ be:f1:80:a9:dd:e8:3c:80:91:ce:3f:fd:0b:dd:b7:
+ d8:a6:8c:94:20:07:19:74:fa:86:ff:cb:97:c3:f6:
+ a4:e7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 66:EC:29:21:2E:76:83:19:39:ED:8E:ED:B7:06:A8:4C:E5:0E:2E:11
+ X509v3 Authority Key Identifier:
+ keyid:8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR1.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 77:f8:b2:d3:a4:61:38:f7:23:0d:a8:bc:33:a9:5e:fe:b5:1d:
+ 09:ea:ee:5b:93:4c:b1:76:ea:27:9c:ad:ab:ba:b7:44:a1:8b:
+ 69:89:71:a7:50:39:05:e5:69:e6:f2:7b:33:70:2a:a1:1d:87:
+ ad:48:45:2a:ab:02:a2:fd:df:08:36:8d:2b:25:8d:c2:06:d5:
+ 10:49:8b:88:62:94:47:5a:27:78:2e:2d:51:aa:b8:9b:13:27:
+ ef:38:af:43:1f:61:f7:da:48:13:2a:0b:66:b4:7d:b4:3a:02:
+ 1a:d3:88:c3:c4:df:1c:1b:86:29:05:da:61:ef:f2:b4:d4:86:
+ 67:14:54:cb:21:b9:8f:38:7b:f8:ba:87:71:66:7d:cf:61:ee:
+ 0b:bb:55:89:46:9d:b4:96:ab:55:90:bd:2c:c6:cf:fa:2d:c3:
+ 18:a2:40:44:0e:85:dd:65:de:b1:2c:79:1b:12:e7:f6:2d:af:
+ 1d:88:61:4a:67:38:17:f1:dc:2e:7c:6a:79:c2:94:8e:f4:e6:
+ c2:6a:6a:7f:3f:40:bf:03:fd:22:ad:ee:df:9b:e4:bc:4b:a0:
+ 73:2d:14:75:ca:c9:7c:06:2c:79:b2:c8:6f:83:d2:81:72:a8:
+ 09:0b:a2:39:cb:68:b5:38:f4:09:bc:4a:83:53:26:f4:b2:ca:
+ 3d:31:ed:e7
+-----BEGIN CERTIFICATE-----
+MIID6DCCAtCgAwIBAgIBCjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIxMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBAOuAVHp0S+SBFdAlLV4hvkfmMavi/nlVSLc2VT3cEYhbtza+07vX
+Fo34S/TFvTTEjixnl+YnEEDFNvS2bLkpgi52sCnqQ5rRMN4FocFUfBdnHfwp3YBT
+soEw2xPuPuZdx7w9phFtgXe3nz4233zW0loiNmh8FMysVO2u/eLNsaNdqWXsG4tL
+z4COppiPabGmNb1pyS5mfyIRZlbFdUyBo25JcQ31dYcT6GLoGgyoMIFqvpBZIzth
+wBVfaL+1yT+vOqJ/gAF49vRVyu7KjQibxT50mAKyC6bY6G54iHuVdrbKvvGAqd3o
+PICRzj/9C9232KaMlCAHGXT6hv/Ll8P2pOcCAwEAAaOCATUwggExMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFGbsKSEudoMZOe2O7bcGqEzlDi4RMB8GA1UdIwQY
+MBaAFIqUF/lT8luUVFbfdlETKfZxGaizMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMS8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjEuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8FTApBggrBgEFBQcBBwEB/wQaMBgwFgQCAAEwEDAOAwUAwAAC
+AQMFAcAAAiAwDQYJKoZIhvcNAQEFBQADggEBAHf4stOkYTj3Iw2ovDOpXv61HQnq
+7luTTLF26iecrau6t0Shi2mJcadQOQXlaebyezNwKqEdh61IRSqrAqL93wg2jSsl
+jcIG1RBJi4hilEdaJ3guLVGquJsTJ+84r0MfYffaSBMqC2a0fbQ6AhrTiMPE3xwb
+hikF2mHv8rTUhmcUVMshuY84e/i6h3Fmfc9h7gu7VYlGnbSWq1WQvSzGz/otwxii
+QEQOhd1l3rEseRsS5/Ytrx2IYUpnOBfx3C58annClI705sJqan8/QL8D/SKt7t+b
+5LxLoHMtFHXKyXwGLHmyyG+D0oFyqAkLojnLaLU49Am8SoNTJvSyyj0x7ec=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR1/index b/scripts/resource-cert-samples/LIR1/index
new file mode 100644
index 00000000..81a48b97
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/index
@@ -0,0 +1,10 @@
+V 080731054529Z 01 unknown /CN=TEST ENTITY ISP2
+V 080731054532Z 02 unknown /CN=TEST ENTITY ISP1
+V 080731140529Z 03 unknown /CN=TEST ENTITY ISP2
+V 080731140529Z 04 unknown /CN=TEST ENTITY ISP1
+V 080731140829Z 05 unknown /CN=TEST ENTITY ISP2
+V 080731140829Z 06 unknown /CN=TEST ENTITY ISP1
+V 080731140935Z 07 unknown /CN=TEST ENTITY ISP2
+V 080731140935Z 08 unknown /CN=TEST ENTITY ISP1
+V 080731144822Z 09 unknown /CN=TEST ENTITY ISP2
+V 080731144822Z 0A unknown /CN=TEST ENTITY ISP1
diff --git a/scripts/resource-cert-samples/LIR1/index.attr b/scripts/resource-cert-samples/LIR1/index.attr
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/index.attr
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/LIR1/index.attr.old b/scripts/resource-cert-samples/LIR1/index.attr.old
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/index.attr.old
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/LIR1/index.old b/scripts/resource-cert-samples/LIR1/index.old
new file mode 100644
index 00000000..55a90252
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/index.old
@@ -0,0 +1,9 @@
+V 080731054529Z 01 unknown /CN=TEST ENTITY ISP2
+V 080731054532Z 02 unknown /CN=TEST ENTITY ISP1
+V 080731140529Z 03 unknown /CN=TEST ENTITY ISP2
+V 080731140529Z 04 unknown /CN=TEST ENTITY ISP1
+V 080731140829Z 05 unknown /CN=TEST ENTITY ISP2
+V 080731140829Z 06 unknown /CN=TEST ENTITY ISP1
+V 080731140935Z 07 unknown /CN=TEST ENTITY ISP2
+V 080731140935Z 08 unknown /CN=TEST ENTITY ISP1
+V 080731144822Z 09 unknown /CN=TEST ENTITY ISP2
diff --git a/scripts/resource-cert-samples/LIR1/serial b/scripts/resource-cert-samples/LIR1/serial
new file mode 100644
index 00000000..eb589e9d
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/serial
@@ -0,0 +1 @@
+0B
diff --git a/scripts/resource-cert-samples/LIR1/serial.old b/scripts/resource-cert-samples/LIR1/serial.old
new file mode 100644
index 00000000..d9bb888f
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR1/serial.old
@@ -0,0 +1 @@
+0A
diff --git a/scripts/resource-cert-samples/LIR2.cer b/scripts/resource-cert-samples/LIR2.cer
new file mode 100644
index 00000000..1094cb06
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2.cer
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 15 (0xf)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 1b:9a:85:77:61:fe:eb:5a:f8:ef:ad:5d:4d:79:4b:09:b3:c9:
+ 3e:46:f2:cf:4f:0c:26:28:7c:ec:72:da:17:6e:a0:2a:f2:4b:
+ 0f:af:e6:2e:b5:d7:2d:03:ae:8c:13:65:ec:cb:c2:4a:02:8f:
+ 81:60:44:60:eb:d2:d2:22:12:63:04:8c:6d:56:5a:c2:b8:f6:
+ c8:f5:17:99:69:25:bd:3e:1d:2a:ef:ce:51:48:4a:67:d0:b4:
+ ee:64:99:35:42:10:26:88:ac:e0:26:c8:27:cc:89:30:40:18:
+ 72:9c:82:03:ea:62:9d:83:c9:ab:c8:32:0a:59:98:50:0c:50:
+ 23:5a:93:ff:43:ba:08:b3:7d:61:d5:ed:a4:42:f2:cf:ab:2e:
+ 62:6b:67:bd:06:74:2c:bc:b7:b1:7e:1b:f4:c9:e4:40:94:ec:
+ 14:55:04:54:ce:44:26:d0:93:e3:ff:e2:e2:a2:a4:3f:44:87:
+ 7a:c2:29:a3:48:5f:12:1d:e4:eb:18:b3:1f:30:f4:e6:d3:a7:
+ 5a:7c:73:da:0a:8f:1e:29:63:cb:b6:16:2e:fe:76:84:93:88:
+ a1:72:83:4d:3d:8d:16:ef:16:df:c7:c6:d7:67:00:68:ec:4d:
+ b8:ed:b8:ff:3e:bf:c9:d5:3a:34:cf:4c:c0:7b:6e:11:60:46:
+ 25:91:d8:ad
+-----BEGIN CERTIFICATE-----
+MIIEETCCAvmgAwIBAgIBDzANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBXzCCAVswDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEEAgACMDswJgMRAiABDbgA
+AAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEAIAENuAAAAAAAAAAQAAAA
+RDANBgkqhkiG9w0BAQUFAAOCAQEAG5qFd2H+61r4761dTXlLCbPJPkbyz08MJih8
+7HLaF26gKvJLD6/mLrXXLQOujBNl7MvCSgKPgWBEYOvS0iISYwSMbVZawrj2yPUX
+mWklvT4dKu/OUUhKZ9C07mSZNUIQJois4CbIJ8yJMEAYcpyCA+pinYPJq8gyClmY
+UAxQI1qT/0O6CLN9YdXtpELyz6suYmtnvQZ0LLy3sX4b9MnkQJTsFFUEVM5EJtCT
+4//i4qKkP0SHesIpo0hfEh3k6xizHzD05tOnWnxz2gqPHiljy7YWLv52hJOIoXKD
+TT2NFu8W38fG12cAaOxNuO24/z6/ydU6NM9MwHtuEWBGJZHYrQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2.cnf b/scripts/resource-cert-samples/LIR2.cnf
new file mode 100644
index 00000000..a320a876
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = LIR2.cer
+serial = LIR2/serial
+private_key = LIR2.key
+database = LIR2/index
+new_certs_dir = LIR2
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY LIR2
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR2/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+sbgp-autonomousSysNum = critical,AS:64544
+sbgp-ipAddrBlock = critical,IPv6:2001:db8::44-2001:db8::100,IPv6:2001:db8::10:0:44/128
diff --git a/scripts/resource-cert-samples/LIR2.key b/scripts/resource-cert-samples/LIR2.key
new file mode 100644
index 00000000..4259796f
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEowIBAAKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccL
+m3h6Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286s
+ndNkPbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/d
+kRzwsCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bd
+u6B45TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N
+8Ar/f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABAoIBAQDGF27931cL9Nv1
+tE0WU36IzmZX6HH3xWwVNzS24MIIVkcV68A+umt+y6DvAtXtgLI4+WwW7ftf+3wA
+LdmhKoS/x/0bykbSnrsb99t7Z5X3Ca/iYFp1xpVLHNblZADCLHF3u1VR/4+PQi4M
+PmnobBRebmN5NyX1KzlVIS2FkU2G8T/TOmEv7ffzMAtBkZIdodUPVwQD2nCOeFeT
+pw0ih1g+r+/RZKXZBU/tPEPhJQhEm91Sos3s1LsgRI6XuJux4Qdp3zrXHglnOpMN
+tzoK4AUlDQOhm0xA0F0Ds2do1v3sQS2Bek0qGU/xUs469/wJljs+sFMwg1WfHyQn
+TZ4jkE8BAoGBAP2jp08Kv6q4vVudGSQVYfp893lI7DprhNTZi4byug8RAGdaPvat
+6UwRTEocl091i7k1bbNR7M2KFIRrqv81BXKWY9IF+jSHLMdkQiA9ftEPAPIPSMWk
+aIa4+gE+7QzK5YMJZN3iDLF+FUNQOLMqm08C6pLFmCsKcdWhBqeY4n73AoGBAPNX
+LHQZd+lmtPX4q22bEt820OGXxAcwkKua9+qchNVae95/PmhrAaWPXgbViD6YzMxX
+lZXGz1gE9gsiEL/KaQWrxFfCUaMDjoJKXOAw0/n1nLscE1FGcgnmXC3MDdOOuI50
+9ESkEAJa5880KVioRWGFyyHLDYyrSsLB2bHB8UWBAoGAXGlyHgRmjQc+RtDYRiNc
+TW2WpSQCnc5q2Tph8csiKzcglId3BV2b8NEkoKQGJTdIrzReQcWJp+G1VAH+jXl+
+AJ/2wqDW5qiRkhxfU2vUdssmpwsWkpwyUVO4ExggOlb6hGG51HX19f1gNeRWpEDT
+0VfYq50+sf/eNd2zlQDJFUUCgYBp6BfN08PPjkbWAstBYcud4HKarH3Bj053kXOy
+5ToezUm59XFI6sGFt9b5bHfmnoQLr1bIIAXfzhDzmXjmsAZzVGWYuFbldsfQRuMT
+I80uLcpv2PFDX0CEtICL4hJmb+g9AAPL2AerrrrTAGW6U0oW/q8A3ynffjGEf+/q
+IHmMgQKBgG+nAjRSJvdc7sMhHSbXCO4G3Jzy39iK0UeSKZHHHbJzmsPTJ5eJ36Zh
+yA19eiX8eC7/GTgrGg+daW8YADPS/wZ2KWZTgavvRhUkAsBW2MSybJgZ5QWEgSa3
+TxH462NH6PiJ755pEcU+ILwIJAcwskR0z2SsL6LaQbXlHNinYWMj
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/LIR2.req b/scripts/resource-cert-samples/LIR2.req
new file mode 100644
index 00000000..1cd9a376
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMjCCASIwDQYJ
+KoZIhvcNAQEBBQADggEPADCCAQoCggEBAPEYtnkLNcWDZEiDMQOe53IoZbGsYeF3
+LsBN8LEcYdjMWi3HC5t4ej79N636sHMLnPy7b2DqOO+u0Se4gVkPs+fQZ7Ki9U/i
+BMbME58zKDWWetvOrJ3TZD24RLzLQyKS1jwuv5duOWpuaJNdHKhYt6N6JkT+/jCt
+4gWJTMnvLOBOMWk/3ZEc8LAlTD6EiupeA7OozZAaHsjgr/4R7SEGvTxeCKGT4kFD
+QzjTIbNM+oWLQ1dgXbugeOUzR6gzdr7fbmNh4zGLXY4Mx/XIkQy+V8fyvL4Lunof
+9hnx6wB0wRLC3CsujfAK/3/oYAiQulH80JARN/OeRLZkQ2ldYdPhjXcCAwEAAaAA
+MA0GCSqGSIb3DQEBBQUAA4IBAQB2ULf+zorJ8tHI+ru/khJ+B3tOGYc/LNQdU39O
+bRsoXSEVGcUZ8YoD4rW3IJS6lskSKkZKkdCIui1SMGq9R2OdYaUICq+hMagX1ZQb
+z6WrSivm+Khc7BqB147ZQ8gO+96+2BzEIkEBeozuHoNvEfJZ6g5N/etd9AaFaeZU
+fO5bGkFOd9UKWPZGQ9Gk3sxFQM83Aek0D6LfQ81ezijqX2l83oqw3gHHxDPrEWIw
+wA8Ir2kBvR6GGt/8uqgtzF+oIQuOIe3peWT5JP2EahY7IW5AViXkOpVfFzzsI/pp
+xGGJGibt55hQTWF/kkRgAYYPnHr0HsNK8ZRvgOKOsmZOewYE
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/LIR2/01.pem b/scripts/resource-cert-samples/LIR2/01.pem
new file mode 100644
index 00000000..832d72fb
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/01.pem
@@ -0,0 +1,23 @@
+-----BEGIN CERTIFICATE-----
+MIID6zCCAtOgAwIBAgIBATANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTA1NDUyN1oXDTA4MDczMTA1NDUyN1owGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCATgwggE0MA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBswGQQCAAIwEwMRACABDbgA
+AAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBAMqX2PAuB9SLv2QsFdzblcv1
+84gGa2Raf1OXAe7J6j45YUxzwGsO1MlJ/lN5XWW6VDu3GayE/uZpuuD0jur0m1N0
+AweSWd9WVOF2kbR4QNPNTgbfNRCKTlWMUyiNoozf1wbAUVFE4VrVKY8k9eDBcECS
+3Kw+f2O5ozocba3ciWY7yVrQ6HquDMF3pmqpAcwsaOXHaMsAp6989fY81lg07sL3
+eeGef71CmplynfI3DNTkznlKOwC9rDLBROCvFBAKBswEQTZEfHBr+kjifJLh2Nsy
+wXE8Xx67UeerTmxnyyP1mOAkQcQ7TcE9xBELp+GrcgdYSTMmtlFuDsBPanAnVow=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/02.pem b/scripts/resource-cert-samples/LIR2/02.pem
new file mode 100644
index 00000000..055a369b
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/02.pem
@@ -0,0 +1,23 @@
+-----BEGIN CERTIFICATE-----
+MIID5DCCAsygAwIBAgIBAjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTA1NDUyOFoXDTA4MDczMTA1NDUyOFowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCATEwggEtMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMEEGCCsGAQUFBwEHAQH/
+BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABADANBgkqhkiG9w0BAQUFAAOCAQEAFiSiwdirDq2HcTM/KB/mU1NpVOf2CWFE
+nsU+gqeXMBOGdF9g0KzHXi09pYapo4xQGDJQmuQhDOOAJI0zKEM0hhito1vKD1xv
+Gxaw+VzXgqHkUaMQxPW+TsCi5+Gu0va7kBobK7i+6QYoSHcqMeahJPsiRT/Ni226
+vhoHDkmZmFfhbgIFg1Mysr9yZwDwECikCspsFjGrHRLqocDrEtnhLgWgK7c3L7Ia
+DVpmFhRzHor2XOu6heyu+FwUTy/MH+OcsVt8hMrdLcWig6iKXOJYbz5NB8y/azmY
+Dl5+MgWa3zFn/142ENc7JUegb/+dLia0ZuoUl5emkDy9zZ8tCrEFzg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/03.pem b/scripts/resource-cert-samples/LIR2/03.pem
new file mode 100644
index 00000000..380a3354
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/03.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 3 (0x3)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:05:29 2007 GMT
+ Not After : Jul 31 14:05:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 55:03:75:e5:85:6b:3b:7d:fd:6b:04:94:5c:6b:65:bb:c2:46:
+ 93:29:ba:ec:40:93:6c:65:b7:e4:eb:f9:47:cf:ed:cd:bf:a5:
+ 3e:32:1e:ce:d4:1c:39:9e:47:e4:31:c7:d9:8a:68:ea:ec:fa:
+ 5b:74:df:2d:5e:e4:7c:1a:41:53:1f:07:4f:7b:51:df:0d:0f:
+ e3:48:87:51:7c:81:72:25:1a:43:4f:f7:2e:1c:f5:3e:86:ae:
+ 72:b4:0c:5a:1e:4b:5d:57:16:4a:bf:ab:1f:23:4e:80:5b:b6:
+ de:09:f6:36:03:dc:9a:34:d5:52:47:c6:65:98:3a:2e:e1:4d:
+ 18:37:c9:24:f3:18:11:f1:81:0e:0c:9d:f5:6c:4d:c1:1c:bb:
+ 21:73:3c:b0:62:4d:83:28:40:2b:ce:9f:9e:2d:2b:59:f3:e2:
+ 5d:dc:03:98:db:c3:99:35:22:e7:a8:93:43:41:91:56:c0:6e:
+ af:df:83:a0:8e:2c:16:9c:00:ce:c6:db:86:f8:75:62:d8:fe:
+ af:e5:4d:dd:38:9d:bd:67:f8:2f:27:b1:f3:26:cd:7f:ad:af:
+ d0:e4:aa:09:6a:47:17:95:62:33:08:40:d5:09:c4:ee:ee:3a:
+ 4f:b2:82:f8:3a:74:d4:a5:b9:db:54:33:9b:c1:00:27:a7:8d:
+ 38:25:77:a4
+-----BEGIN CERTIFICATE-----
+MIID6zCCAtOgAwIBAgIBAzANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0MDUyOVoXDTA4MDczMTE0MDUyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCATgwggE0MA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBswGQQCAAIwEwMRACABDbgA
+AAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBAFUDdeWFazt9/WsElFxrZbvC
+RpMpuuxAk2xlt+Tr+UfP7c2/pT4yHs7UHDmeR+Qxx9mKaOrs+lt03y1e5HwaQVMf
+B097Ud8ND+NIh1F8gXIlGkNP9y4c9T6GrnK0DFoeS11XFkq/qx8jToBbtt4J9jYD
+3Jo01VJHxmWYOi7hTRg3ySTzGBHxgQ4MnfVsTcEcuyFzPLBiTYMoQCvOn54tK1nz
+4l3cA5jbw5k1Iueok0NBkVbAbq/fg6COLBacAM7G24b4dWLY/q/lTd04nb1n+C8n
+sfMmzX+tr9DkqglqRxeVYjMIQNUJxO7uOk+ygvg6dNSludtUM5vBACenjTgld6Q=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/04.pem b/scripts/resource-cert-samples/LIR2/04.pem
new file mode 100644
index 00000000..55678af1
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/04.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 4 (0x4)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:05:29 2007 GMT
+ Not After : Jul 31 14:05:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ e5:f9:79:e8:d7:09:da:a8:1b:3b:35:a2:2a:47:66:5e:ef:c7:
+ 0e:a3:0a:d5:28:d6:2c:78:42:c5:73:69:31:9b:89:fa:2e:7a:
+ 95:95:36:bd:bf:c7:09:de:04:3f:4e:fc:8b:52:d0:2b:db:da:
+ 91:a9:2c:c0:1e:d1:a4:2d:22:0a:e4:57:e4:06:e3:9c:08:22:
+ f9:02:1f:a9:b1:a2:ae:15:eb:40:d7:08:78:83:f4:de:0b:54:
+ 93:a6:c9:1c:0f:73:f3:43:d0:12:64:c8:29:19:d3:9b:07:91:
+ 24:4a:33:85:45:03:a7:73:01:80:b6:17:cf:24:18:1a:1e:e4:
+ 33:9d:1f:53:34:c6:fa:a3:ab:fa:2f:ea:ff:eb:69:a4:6e:d7:
+ 87:d6:aa:ed:64:d4:81:2f:aa:de:35:c4:44:3a:65:72:05:8e:
+ 3e:30:a4:30:3d:2b:b4:a5:53:12:af:0e:3c:56:bb:e3:24:d3:
+ bd:c7:b5:ad:25:19:2a:d0:f7:f3:9f:cf:21:33:9a:46:23:43:
+ 0b:13:9d:62:ac:bb:3d:3e:8a:f5:19:37:1f:05:4c:8f:be:2e:
+ 69:d6:78:ac:76:25:64:15:0c:12:65:6a:f9:4d:1d:eb:95:8c:
+ ef:00:d0:08:c0:5a:59:e0:cd:c5:78:51:cc:63:40:7e:36:a3:
+ 05:82:9e:67
+-----BEGIN CERTIFICATE-----
+MIID5DCCAsygAwIBAgIBBDANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0MDUyOVoXDTA4MDczMTE0MDUyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCATEwggEtMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMEEGCCsGAQUFBwEHAQH/
+BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABADANBgkqhkiG9w0BAQUFAAOCAQEA5fl56NcJ2qgbOzWiKkdmXu/HDqMK1SjW
+LHhCxXNpMZuJ+i56lZU2vb/HCd4EP078i1LQK9vakakswB7RpC0iCuRX5AbjnAgi
++QIfqbGirhXrQNcIeIP03gtUk6bJHA9z80PQEmTIKRnTmweRJEozhUUDp3MBgLYX
+zyQYGh7kM50fUzTG+qOr+i/q/+tppG7Xh9aq7WTUgS+q3jXERDplcgWOPjCkMD0r
+tKVTEq8OPFa74yTTvce1rSUZKtD385/PITOaRiNDCxOdYqy7PT6K9Rk3HwVMj74u
+adZ4rHYlZBUMEmVq+U0d65WM7wDQCMBaWeDNxXhRzGNAfjajBYKeZw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/05.pem b/scripts/resource-cert-samples/LIR2/05.pem
new file mode 100644
index 00000000..21fc68de
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/05.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 5 (0x5)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:08:29 2007 GMT
+ Not After : Jul 31 14:08:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ cf:89:36:be:f0:e0:c8:98:8d:4d:af:19:f7:14:c6:98:8c:7d:
+ 80:88:38:7e:4a:86:21:11:11:48:d1:5d:ab:45:c7:13:ea:40:
+ de:69:2b:a4:ed:b9:19:34:74:95:2d:65:5a:38:4d:5c:04:0b:
+ 1e:5c:59:15:ac:6c:0e:38:b0:ec:bf:f4:61:3c:78:5b:61:24:
+ 2a:e0:ec:38:df:f8:f0:6e:9f:91:52:56:c1:14:8f:b1:57:4a:
+ 3f:62:8d:55:a3:83:38:e2:e7:3f:bb:16:14:59:9a:97:b7:60:
+ 05:29:cc:0f:2d:74:1c:71:0e:1f:fb:59:31:76:c5:69:8f:98:
+ aa:9a:d2:d9:50:07:c8:67:23:cd:31:9a:ae:70:bd:be:82:7e:
+ a5:7d:4a:2a:eb:77:8e:59:cd:4b:eb:6b:78:39:82:ac:46:5d:
+ 0b:7c:26:76:ce:cc:c4:94:b3:3e:c6:7d:75:d0:32:ab:32:fd:
+ 5c:96:fa:aa:b3:c2:56:4d:6f:43:a4:7a:28:94:ce:40:1d:1c:
+ a6:72:d1:a3:66:7b:9b:5c:d2:cc:69:55:15:09:1d:aa:84:d2:
+ 4c:c1:65:d5:6c:d3:c0:82:7a:a9:6e:dc:37:77:ab:29:b3:8f:
+ 10:19:49:21:b4:e3:85:8d:d7:2a:34:5c:8c:fb:88:12:3c:23:
+ ea:18:34:22
+-----BEGIN CERTIFICATE-----
+MIID6zCCAtOgAwIBAgIBBTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0MDgyOVoXDTA4MDczMTE0MDgyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCATgwggE0MA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBswGQQCAAIwEwMRACABDbgA
+AAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBAM+JNr7w4MiYjU2vGfcUxpiM
+fYCIOH5KhiEREUjRXatFxxPqQN5pK6TtuRk0dJUtZVo4TVwECx5cWRWsbA44sOy/
+9GE8eFthJCrg7Djf+PBun5FSVsEUj7FXSj9ijVWjgzji5z+7FhRZmpe3YAUpzA8t
+dBxxDh/7WTF2xWmPmKqa0tlQB8hnI80xmq5wvb6CfqV9Sirrd45ZzUvra3g5gqxG
+XQt8JnbOzMSUsz7GfXXQMqsy/VyW+qqzwlZNb0OkeiiUzkAdHKZy0aNme5tc0sxp
+VRUJHaqE0kzBZdVs08CCeqlu3Dd3qymzjxAZSSG044WN1yo0XIz7iBI8I+oYNCI=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/06.pem b/scripts/resource-cert-samples/LIR2/06.pem
new file mode 100644
index 00000000..cdd0108c
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/06.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 6 (0x6)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:08:29 2007 GMT
+ Not After : Jul 31 14:08:29 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 82:d3:6f:ff:0f:ea:b2:49:89:b9:7a:6f:9f:7a:67:11:40:9e:
+ aa:00:cd:04:3e:6d:1f:88:c9:af:63:1e:ec:bd:7e:11:38:3c:
+ a0:cf:7f:89:9f:18:e5:ae:f6:3c:a9:f3:2a:84:4d:15:b3:6d:
+ 83:39:08:45:f6:ab:e0:d4:96:0d:38:93:0e:92:6a:ec:3e:ed:
+ ae:fc:42:1f:2e:d3:ef:e3:18:32:da:4c:ed:18:a6:08:a1:3d:
+ 79:af:41:b5:b4:f6:17:12:32:6a:bd:88:76:89:76:50:52:3d:
+ 71:01:b9:bf:79:6a:bf:e5:dd:d1:89:2d:8e:4f:89:7b:d2:9d:
+ 12:bc:42:d1:0b:a2:ff:b6:61:4e:86:79:af:f3:a5:57:a0:39:
+ 3b:e8:2e:6d:aa:65:1c:e7:58:36:47:de:3c:5f:a2:04:02:5b:
+ 63:d4:86:d1:2b:4a:1a:ce:00:8b:81:5b:9c:d1:71:a4:dd:4e:
+ d2:41:34:f7:69:f8:e0:df:80:08:35:90:c6:52:3b:4a:97:e0:
+ de:09:ad:36:f6:c1:aa:77:3d:26:e1:c9:7d:a3:34:3b:09:b9:
+ 83:40:86:d8:c9:7b:d1:05:48:8a:f6:90:97:bd:05:9b:6a:8f:
+ cf:96:7e:9b:f5:fa:aa:21:1a:95:aa:31:ce:fb:78:5d:d5:a8:
+ a6:2e:ca:c6
+-----BEGIN CERTIFICATE-----
+MIID5DCCAsygAwIBAgIBBjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0MDgyOVoXDTA4MDczMTE0MDgyOVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCATEwggEtMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMEEGCCsGAQUFBwEHAQH/
+BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABADANBgkqhkiG9w0BAQUFAAOCAQEAgtNv/w/qskmJuXpvn3pnEUCeqgDNBD5t
+H4jJr2Me7L1+ETg8oM9/iZ8Y5a72PKnzKoRNFbNtgzkIRfar4NSWDTiTDpJq7D7t
+rvxCHy7T7+MYMtpM7RimCKE9ea9BtbT2FxIyar2Idol2UFI9cQG5v3lqv+Xd0Ykt
+jk+Je9KdErxC0Qui/7ZhToZ5r/OlV6A5O+gubaplHOdYNkfePF+iBAJbY9SG0StK
+Gs4Ai4FbnNFxpN1O0kE092n44N+ACDWQxlI7Spfg3gmtNvbBqnc9JuHJfaM0Owm5
+g0CG2Ml70QVIivaQl70Fm2qPz5Z+m/X6qiEalaoxzvt4XdWopi7Kxg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/07.pem b/scripts/resource-cert-samples/LIR2/07.pem
new file mode 100644
index 00000000..00cf79e5
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/07.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 7 (0x7)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:09:35 2007 GMT
+ Not After : Jul 31 14:09:35 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ b8:19:54:a2:c8:99:67:2c:52:0c:a7:ab:fa:60:12:7e:3e:e9:
+ 72:81:c0:89:11:85:e0:cf:b7:f8:27:b4:18:3d:fd:cc:3c:69:
+ 9b:ec:f8:73:f8:81:ef:06:63:90:95:ad:9c:85:bf:ec:ad:13:
+ 53:59:d8:a3:1e:17:49:0d:94:ba:f1:38:4a:1e:9b:9d:a4:34:
+ b5:1b:c8:d4:8c:b8:35:07:04:d0:9f:54:81:05:3e:8f:56:10:
+ 32:6a:e8:32:ce:89:bb:44:c1:09:7a:c6:69:9b:12:2d:05:e2:
+ d9:5c:f9:ba:16:07:bc:d0:8b:92:68:5a:93:5b:d0:25:0a:4e:
+ 3c:7c:f4:62:44:43:98:7f:97:81:43:43:ef:1f:38:59:55:64:
+ ca:68:a6:bb:91:0f:26:51:47:d3:6c:19:c2:30:4d:55:55:91:
+ e9:fb:30:01:10:cd:eb:7e:42:33:1b:5b:82:95:c7:38:54:ab:
+ e5:0b:fc:8a:15:3d:7e:48:45:57:4c:26:e9:22:79:71:58:86:
+ 25:22:38:4d:c7:78:8c:58:a2:17:1b:ce:ff:ff:34:22:ba:6f:
+ 17:be:f0:47:76:a5:01:e6:33:07:62:f0:d8:47:8c:00:15:04:
+ d5:37:73:6d:62:7e:b9:de:60:41:e5:e3:f2:e4:96:c9:e2:7a:
+ db:56:f0:3a
+-----BEGIN CERTIFICATE-----
+MIID6zCCAtOgAwIBAgIBBzANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0MDkzNVoXDTA4MDczMTE0MDkzNVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCATgwggE0MA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBswGQQCAAIwEwMRACABDbgA
+AAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBALgZVKLImWcsUgynq/pgEn4+
+6XKBwIkRheDPt/gntBg9/cw8aZvs+HP4ge8GY5CVrZyFv+ytE1NZ2KMeF0kNlLrx
+OEoem52kNLUbyNSMuDUHBNCfVIEFPo9WEDJq6DLOibtEwQl6xmmbEi0F4tlc+boW
+B7zQi5JoWpNb0CUKTjx89GJEQ5h/l4FDQ+8fOFlVZMpopruRDyZRR9NsGcIwTVVV
+ken7MAEQzet+QjMbW4KVxzhUq+UL/IoVPX5IRVdMJukieXFYhiUiOE3HeIxYohcb
+zv//NCK6bxe+8Ed2pQHmMwdi8NhHjAAVBNU3c21ifrneYEHl4/LklsniettW8Do=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/08.pem b/scripts/resource-cert-samples/LIR2/08.pem
new file mode 100644
index 00000000..0d2eebd5
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/08.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 8 (0x8)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:09:35 2007 GMT
+ Not After : Jul 31 14:09:35 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ c9:76:93:8c:9f:ac:9a:b1:29:fb:5b:b0:ad:c4:e4:70:74:5b:
+ e3:a2:91:cd:39:ab:25:82:6b:8b:46:3d:86:74:73:04:95:5d:
+ f4:5d:6f:9b:78:91:44:f9:16:07:ca:75:56:2f:ac:84:3c:3c:
+ b4:1d:fe:f3:62:f2:70:16:86:7f:94:16:22:f3:7a:a5:98:7e:
+ 6b:1b:cc:61:3e:7c:a0:57:f4:80:3d:69:0b:a0:3c:3b:a1:3f:
+ f6:50:a6:1a:40:c0:85:e6:20:88:94:20:f2:b7:41:a1:42:39:
+ 91:b0:46:4f:07:df:b5:59:30:18:22:97:ad:95:4b:92:cc:d7:
+ 31:ee:cb:99:90:ec:82:e2:19:34:99:9e:94:2c:16:9f:6e:f4:
+ 89:9a:79:40:96:d2:1b:d6:79:e0:da:f2:a2:f7:ee:c4:3a:91:
+ 21:02:77:8a:6c:5f:c6:aa:77:c7:ae:15:6e:3f:38:b9:97:69:
+ ac:cf:44:95:74:dc:a6:bc:c8:e4:a0:f4:e4:c4:f9:55:de:5a:
+ ba:f5:ae:d7:e9:b9:44:c7:46:54:53:dc:74:cd:f7:fe:48:9a:
+ 1a:1a:57:bc:af:3d:47:38:9f:67:10:7f:6a:4f:17:d7:7d:45:
+ d0:05:ec:fd:8b:a2:aa:52:c3:7b:73:eb:96:f8:11:cc:12:4f:
+ e8:81:ad:f1
+-----BEGIN CERTIFICATE-----
+MIID5DCCAsygAwIBAgIBCDANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0MDkzNVoXDTA4MDczMTE0MDkzNVowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCATEwggEtMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMEEGCCsGAQUFBwEHAQH/
+BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABADANBgkqhkiG9w0BAQUFAAOCAQEAyXaTjJ+smrEp+1uwrcTkcHRb46KRzTmr
+JYJri0Y9hnRzBJVd9F1vm3iRRPkWB8p1Vi+shDw8tB3+82LycBaGf5QWIvN6pZh+
+axvMYT58oFf0gD1pC6A8O6E/9lCmGkDAheYgiJQg8rdBoUI5kbBGTwfftVkwGCKX
+rZVLkszXMe7LmZDsguIZNJmelCwWn270iZp5QJbSG9Z54NryovfuxDqRIQJ3imxf
+xqp3x64Vbj84uZdprM9ElXTcprzI5KD05MT5Vd5auvWu1+m5RMdGVFPcdM33/kia
+GhpXvK89RzifZxB/ak8X131F0AXs/YuiqlLDe3PrlvgRzBJP6IGt8Q==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/09.pem b/scripts/resource-cert-samples/LIR2/09.pem
new file mode 100644
index 00000000..b117c94d
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/09.pem
@@ -0,0 +1,96 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 9 (0x9)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP4
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:b3:05:ad:fb:06:db:49:81:ad:df:50:04:e0:18:
+ e8:f1:f4:83:e6:26:4b:9e:fc:2d:1c:df:e2:2b:57:
+ 38:48:eb:c4:13:a3:fd:6c:c5:e2:1c:d5:3a:fd:66:
+ d7:ff:2e:ff:4a:b7:5a:c5:f4:19:b1:8d:9e:a8:49:
+ 4e:3b:20:46:da:08:de:b0:9c:71:5e:77:a9:14:e2:
+ 4c:20:0e:ff:c5:20:fa:f3:6d:3b:0b:ce:e1:72:b6:
+ ff:f5:75:7f:3e:35:af:1c:4f:e0:92:45:f0:1f:57:
+ ce:38:6c:3e:f6:2f:96:73:1f:60:db:63:8e:63:b3:
+ f3:35:85:e9:00:39:92:b3:9f:4a:6b:bd:e9:a0:00:
+ ca:be:fe:27:78:9b:44:23:53:56:13:48:7d:cd:d1:
+ 01:3a:88:36:66:4f:7f:f3:2c:9f:c7:c4:52:75:1e:
+ 0e:3c:50:29:c9:39:e0:ff:90:4d:95:47:56:13:e1:
+ 30:f3:30:33:ee:02:60:70:b0:bd:dd:3b:aa:b9:2a:
+ 86:bf:e7:e2:a8:ec:64:2a:0b:12:05:08:03:7e:d8:
+ 41:bb:23:de:29:e5:0f:9b:3b:00:2e:4f:0e:f5:31:
+ 91:ec:bd:34:02:68:6d:d7:71:a9:8c:4d:23:d2:43:
+ ae:d7:f8:e5:69:2b:ae:13:86:13:27:38:72:48:70:
+ f8:1f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:CF:F8:00:82:EC:D7:E9:17:4F:BD:7A:87:60:32:A5:BB:9D:B5:0E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP4/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 1c:53:2a:8f:55:44:b1:71:d1:50:79:f1:3c:3d:fe:15:1d:72:
+ 5e:22:91:d1:54:3d:a4:e0:9e:ba:e4:8d:b3:71:c5:93:cd:5b:
+ 54:5c:e5:2c:af:a1:a9:d7:8d:32:b7:92:95:8c:0e:2e:05:d3:
+ 9d:da:ac:a9:7a:01:d2:19:9e:b7:88:80:92:b1:26:95:6d:0a:
+ b4:01:a3:f1:9f:15:fe:0b:29:0f:0f:72:b7:72:d2:18:9e:5d:
+ 7e:65:59:7b:30:75:33:7f:95:fc:cb:9d:7b:0f:36:44:0f:d0:
+ e6:a3:c1:a5:6b:d0:db:13:4b:fa:06:35:df:66:01:c3:d8:51:
+ 47:e7:89:26:56:6f:2a:2a:ba:46:29:a8:cb:9d:cc:5f:d9:9f:
+ 14:01:d5:fd:08:e9:db:1a:7a:89:3e:c8:36:6b:b4:6c:ca:a9:
+ df:43:46:89:48:a0:13:32:bb:c9:17:14:01:2d:21:fe:68:11:
+ 61:5a:b4:6f:af:ba:3b:0a:96:4c:25:33:5a:a6:cf:29:21:45:
+ 76:b8:e1:d9:20:0c:22:f7:7c:85:b2:45:90:94:c5:2c:ca:e1:
+ 82:65:36:75:9d:46:9b:f8:9a:d6:85:2f:71:8b:cd:88:fd:87:
+ 1b:1c:36:f8:36:f5:1c:18:e5:5b:68:3f:36:60:de:a0:59:e1:
+ cd:54:61:4c
+-----BEGIN CERTIFICATE-----
+MIID6zCCAtOgAwIBAgIBCTANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQNDCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBALMFrfsG20mBrd9QBOAY6PH0g+YmS578LRzf4itXOEjrxBOj/WzF
+4hzVOv1m1/8u/0q3WsX0GbGNnqhJTjsgRtoI3rCccV53qRTiTCAO/8Ug+vNtOwvO
+4XK2//V1fz41rxxP4JJF8B9XzjhsPvYvlnMfYNtjjmOz8zWF6QA5krOfSmu96aAA
+yr7+J3ibRCNTVhNIfc3RATqINmZPf/Msn8fEUnUeDjxQKck54P+QTZVHVhPhMPMw
+M+4CYHCwvd07qrkqhr/n4qjsZCoLEgUIA37YQbsj3inlD5s7AC5PDvUxkey9NAJo
+bddxqYxNI9JDrtf45WkrrhOGEyc4ckhw+B8CAwEAAaOCATgwggE0MA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFJjP+ACC7NfpF0+9eodgMqW7nbUOMB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQNC8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMBoGCCsGAQUFBwEIAQH/
+BAswCaAHMAUCAwD8IDAsBggrBgEFBQcBBwEB/wQdMBswGQQCAAIwEwMRACABDbgA
+AAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBABxTKo9VRLFx0VB58Tw9/hUd
+cl4ikdFUPaTgnrrkjbNxxZPNW1Rc5SyvoanXjTK3kpWMDi4F053arKl6AdIZnreI
+gJKxJpVtCrQBo/GfFf4LKQ8Pcrdy0hieXX5lWXswdTN/lfzLnXsPNkQP0OajwaVr
+0NsTS/oGNd9mAcPYUUfniSZWbyoqukYpqMudzF/ZnxQB1f0I6dsaeok+yDZrtGzK
+qd9DRolIoBMyu8kXFAEtIf5oEWFatG+vujsKlkwlM1qmzykhRXa44dkgDCL3fIWy
+RZCUxSzK4YJlNnWdRpv4mtaFL3GLzYj9hxscNvg29RwY5VtoPzZg3qBZ4c1UYUw=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/0A.pem b/scripts/resource-cert-samples/LIR2/0A.pem
new file mode 100644
index 00000000..c8f4890e
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/0A.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 10 (0xa)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR2
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:d1:24:75:c1:44:29:12:9a:fe:8c:1d:1e:01:aa:
+ 05:ea:1f:47:ab:1a:8d:cf:d2:42:a1:31:7d:9c:3e:
+ 66:72:ce:2c:df:01:17:15:40:40:94:d1:ae:6d:d7:
+ ca:fd:52:d9:ec:5f:f0:64:30:a3:42:70:a1:a1:6f:
+ 05:2d:10:ee:b1:05:65:3f:f2:c1:78:84:cc:1d:66:
+ ee:35:52:c7:ae:99:76:b1:63:4d:c1:2e:24:fb:f7:
+ 43:2d:0b:21:0d:d3:d6:b7:cf:60:50:49:3d:17:53:
+ 3e:2b:f8:68:95:7e:1c:c5:e2:1e:73:06:8c:b2:53:
+ a1:70:39:d9:9e:e5:56:fc:58:d0:b3:f3:90:37:5a:
+ 6e:5a:3b:ef:05:be:f1:64:2f:31:2e:5a:58:f2:30:
+ 7a:73:52:7f:b8:0d:71:3c:63:52:17:0f:b7:07:3b:
+ c3:46:b9:9c:88:bc:73:df:14:5a:bc:16:fc:f8:79:
+ b0:a1:41:87:05:f9:52:a8:36:61:62:de:90:68:21:
+ 83:bb:8c:83:47:af:bb:82:3e:44:28:97:2b:02:a8:
+ 81:04:05:16:cd:bf:ef:9e:02:f9:54:66:2a:28:99:
+ 79:2b:b5:19:10:d4:df:35:95:f3:3f:fa:13:6a:06:
+ 6f:f5:38:28:d6:b6:0b:8a:70:5b:8d:70:8d:34:99:
+ 96:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E1:97:2E:19:70:B5:7F:FC:82:4F:33:3D:6B:2C:DE:9A:9B:36:3D:7E
+ X509v3 Authority Key Identifier:
+ keyid:03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR2.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 05:ba:27:d4:55:52:1b:f7:61:da:37:98:b3:16:e6:53:6a:2c:
+ 65:f5:80:7f:d4:cb:8f:fb:c2:1d:1a:9f:54:ed:a0:7a:03:a6:
+ ff:5a:e7:d6:c1:06:31:11:b5:c1:dc:ab:33:87:d7:57:0e:cd:
+ 19:44:16:9f:92:84:43:32:8b:d0:64:12:00:a7:ad:b7:fb:79:
+ c1:ec:e3:d0:77:3c:73:8a:5f:90:6b:da:a4:d4:e0:28:0a:45:
+ 99:5a:b8:b0:fa:96:3e:c3:a3:de:a6:df:f9:55:e9:1b:3e:37:
+ f0:21:38:7f:5f:b2:e0:75:f2:8c:82:10:e9:60:76:3b:de:dd:
+ 85:f2:1e:3c:22:f5:77:40:d9:a4:f9:72:46:29:99:a8:2e:5d:
+ b8:05:5c:b3:2b:d0:44:c5:8b:07:c7:69:d0:a9:cf:83:31:d1:
+ ed:36:d7:ce:b4:c6:7e:4a:58:10:20:46:16:ed:b5:e3:60:47:
+ e8:b2:36:1e:79:ed:ac:08:da:8b:a0:6d:92:f1:e4:73:60:6b:
+ 10:61:07:69:78:78:a9:51:fd:24:1d:3d:d6:63:62:c3:d4:1e:
+ 70:8d:f6:41:fc:42:09:cc:7b:1c:19:c7:59:0b:a0:da:5b:00:
+ fd:33:24:8b:9f:1e:d8:d8:04:cd:f4:71:06:ea:c6:2e:8d:8b:
+ 6f:cd:b9:a6
+-----BEGIN CERTIFICATE-----
+MIID5DCCAsygAwIBAgIBCjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIyMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowGzEZ
+MBcGA1UEAxMQVEVTVCBFTlRJVFkgSVNQMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
+ADCCAQoCggEBANEkdcFEKRKa/owdHgGqBeofR6sajc/SQqExfZw+ZnLOLN8BFxVA
+QJTRrm3Xyv1S2exf8GQwo0JwoaFvBS0Q7rEFZT/ywXiEzB1m7jVSx66ZdrFjTcEu
+JPv3Qy0LIQ3T1rfPYFBJPRdTPiv4aJV+HMXiHnMGjLJToXA52Z7lVvxY0LPzkDda
+blo77wW+8WQvMS5aWPIwenNSf7gNcTxjUhcPtwc7w0a5nIi8c98UWrwW/Ph5sKFB
+hwX5Uqg2YWLekGghg7uMg0evu4I+RCiXKwKogQQFFs2/754C+VRmKiiZeSu1GRDU
+3zWV8z/6E2oGb/U4KNa2C4pwW41wjTSZlj8CAwEAAaOCATEwggEtMA8GA1UdEwEB
+/wQFMAMBAf8wHQYDVR0OBBYEFOGXLhlwtX/8gk8zPWss3pqbNj1+MB8GA1UdIwQY
+MBaAFAN63wzf3JM996XMJ3vcIvbpVZfwMA4GA1UdDwEB/wQEAwIBBjBBBggrBgEF
+BQcBCwQ1MDMwMQYIKwYBBQUHMAWGJXJzeW5jOi8vd29tYmF0cy1yLXVzLmhhY3Ry
+bi5uZXQvSVNQMy8wRAYIKwYBBQUHAQEEODA2MDQGCCsGAQUFBzAChihyc3luYzov
+L3dvbWJhdHMtci11cy5oYWN0cm4ubmV0L0xJUjIuY2VyMEEGCCsGAQUFBwEHAQH/
+BDIwMDAuBAIAAjAoMCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABADANBgkqhkiG9w0BAQUFAAOCAQEABbon1FVSG/dh2jeYsxbmU2osZfWAf9TL
+j/vCHRqfVO2gegOm/1rn1sEGMRG1wdyrM4fXVw7NGUQWn5KEQzKL0GQSAKett/t5
+wezj0Hc8c4pfkGvapNTgKApFmVq4sPqWPsOj3qbf+VXpGz438CE4f1+y4HXyjIIQ
+6WB2O97dhfIePCL1d0DZpPlyRimZqC5duAVcsyvQRMWLB8dp0KnPgzHR7TbXzrTG
+fkpYECBGFu2142BH6LI2HnntrAjai6BtkvHkc2BrEGEHaXh4qVH9JB091mNiw9Qe
+cI32QfxCCcx7HBnHWQug2lsA/TMki58e2NgEzfRxBurGLo2Lb825pg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR2/index b/scripts/resource-cert-samples/LIR2/index
new file mode 100644
index 00000000..9fcbd3ba
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/index
@@ -0,0 +1,10 @@
+V 080731054527Z 01 unknown /CN=TEST ENTITY ISP4
+V 080731054528Z 02 unknown /CN=TEST ENTITY ISP3
+V 080731140529Z 03 unknown /CN=TEST ENTITY ISP4
+V 080731140529Z 04 unknown /CN=TEST ENTITY ISP3
+V 080731140829Z 05 unknown /CN=TEST ENTITY ISP4
+V 080731140829Z 06 unknown /CN=TEST ENTITY ISP3
+V 080731140935Z 07 unknown /CN=TEST ENTITY ISP4
+V 080731140935Z 08 unknown /CN=TEST ENTITY ISP3
+V 080731144822Z 09 unknown /CN=TEST ENTITY ISP4
+V 080731144822Z 0A unknown /CN=TEST ENTITY ISP3
diff --git a/scripts/resource-cert-samples/LIR2/index.attr b/scripts/resource-cert-samples/LIR2/index.attr
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/index.attr
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/LIR2/index.attr.old b/scripts/resource-cert-samples/LIR2/index.attr.old
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/index.attr.old
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/LIR2/index.old b/scripts/resource-cert-samples/LIR2/index.old
new file mode 100644
index 00000000..b1af6c04
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/index.old
@@ -0,0 +1,9 @@
+V 080731054527Z 01 unknown /CN=TEST ENTITY ISP4
+V 080731054528Z 02 unknown /CN=TEST ENTITY ISP3
+V 080731140529Z 03 unknown /CN=TEST ENTITY ISP4
+V 080731140529Z 04 unknown /CN=TEST ENTITY ISP3
+V 080731140829Z 05 unknown /CN=TEST ENTITY ISP4
+V 080731140829Z 06 unknown /CN=TEST ENTITY ISP3
+V 080731140935Z 07 unknown /CN=TEST ENTITY ISP4
+V 080731140935Z 08 unknown /CN=TEST ENTITY ISP3
+V 080731144822Z 09 unknown /CN=TEST ENTITY ISP4
diff --git a/scripts/resource-cert-samples/LIR2/serial b/scripts/resource-cert-samples/LIR2/serial
new file mode 100644
index 00000000..eb589e9d
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/serial
@@ -0,0 +1 @@
+0B
diff --git a/scripts/resource-cert-samples/LIR2/serial.old b/scripts/resource-cert-samples/LIR2/serial.old
new file mode 100644
index 00000000..d9bb888f
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR2/serial.old
@@ -0,0 +1 @@
+0A
diff --git a/scripts/resource-cert-samples/LIR3.cer b/scripts/resource-cert-samples/LIR3.cer
new file mode 100644
index 00000000..54acaf38
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3.cer
@@ -0,0 +1,101 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 14 (0xe)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY LIR3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:a3:21:57:61:64:af:11:18:d4:cb:de:a6:dc:ad:
+ d9:2c:0f:0f:58:9f:7e:c8:85:55:11:26:4c:7c:f0:
+ 6b:68:1a:9e:6a:0c:8f:e6:dc:3d:83:58:2a:cc:77:
+ ac:19:73:6f:5a:f3:6e:24:ac:cd:1a:dc:1d:0b:4c:
+ 44:f5:6d:8b:0a:17:3d:86:f9:e8:fe:e6:60:e5:9f:
+ 40:6a:e5:94:e8:9a:56:17:17:1c:ab:c1:8c:37:40:
+ 2b:55:bf:2c:5e:dc:8d:ca:25:7f:8a:5f:ee:fb:16:
+ 86:eb:e0:08:d3:26:e5:e3:70:c5:0c:6b:fb:1b:8f:
+ 6b:5c:f6:e2:4a:58:a5:35:01:ea:05:1b:3e:ce:84:
+ be:b5:3f:6d:18:16:4b:68:e5:79:4c:88:7d:b6:a5:
+ 65:a3:3a:c2:32:dc:ad:8f:8a:05:ee:f6:e9:7a:80:
+ da:12:a9:0f:5a:b5:d2:d3:31:ac:3e:d3:19:25:2d:
+ 28:de:79:6c:ce:fd:77:66:d5:e3:2f:a9:cb:f9:85:
+ 8c:20:bb:a2:86:23:f0:93:95:20:04:78:c7:c7:07:
+ a6:fe:f0:f4:45:bb:cf:78:2b:dd:ce:9c:08:a5:46:
+ 68:10:4c:d7:05:62:6c:86:5a:2d:7f:06:38:c2:4d:
+ bb:44:87:00:43:79:d2:8f:f3:6b:b2:f4:5c:1c:b9:
+ 68:01
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 48:66:09:ae:e4:52:ea:33:07:a6:92:4f:41:9d:d9:74:ad:24:
+ 17:11:d6:85:88:f2:66:52:e5:61:0e:8e:78:db:56:fb:ab:c8:
+ 31:1b:d1:f2:ec:df:1d:87:80:21:d9:81:9e:c8:00:e8:37:d5:
+ c3:71:26:97:35:15:fe:99:60:41:be:9b:72:e9:91:c1:bf:c8:
+ e3:25:95:f3:95:2b:c4:50:49:8f:a7:2a:ec:9a:d9:f9:b6:27:
+ 77:42:38:aa:20:12:30:56:db:41:f0:c4:d7:75:5a:01:4b:ac:
+ 36:8e:4d:1f:55:fa:24:4e:04:f2:ac:de:9a:4c:3e:9e:a4:b0:
+ fa:84:a8:35:3f:dc:dd:db:2c:74:4e:20:84:a5:17:05:87:8a:
+ 55:ee:4c:ae:59:02:7c:e7:70:32:10:9e:6f:b3:52:ec:48:ff:
+ 47:77:bf:a1:69:f1:5c:55:94:d0:47:ab:3a:34:56:96:a4:64:
+ e9:31:c2:aa:34:d6:a2:51:b2:8c:55:68:8c:5e:7a:d1:8d:43:
+ 89:e8:3e:1b:63:e9:b1:0c:e1:8f:31:0d:2f:5f:dd:1e:e8:78:
+ 41:d4:49:39:ca:a2:73:1e:9a:6f:c0:07:72:99:9e:3c:0b:ee:
+ b9:0b:d8:52:35:4e:19:83:44:ed:d9:de:5a:6b:6d:38:63:4e:
+ 12:45:f0:45
+-----BEGIN CERTIFICATE-----
+MIIEFTCCAv2gAwIBAgIBDjANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
+g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
+N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
+zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4IBYzCCAV8wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUmL4E/4DRq5U5qj3yDmd9AK2j/cUwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIzLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAhBggrBgEFBQcBCAEB/wQS
+MBCgDjAMMAoCAwD8FgIDAPwcMFEGCCsGAQUFBwEHAQH/BEIwQDASBAIAATAMAwQA
+CgAAAwQACgMAMCoEAgACMCQDEAAgAQ24AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAA
+AAAKAwAwDQYJKoZIhvcNAQEFBQADggEBAEhmCa7kUuozB6aST0Gd2XStJBcR1oWI
+8mZS5WEOjnjbVvuryDEb0fLs3x2HgCHZgZ7IAOg31cNxJpc1Ff6ZYEG+m3LpkcG/
+yOMllfOVK8RQSY+nKuya2fm2J3dCOKogEjBW20HwxNd1WgFLrDaOTR9V+iROBPKs
+3ppMPp6ksPqEqDU/3N3bLHROIISlFwWHilXuTK5ZAnzncDIQnm+zUuxI/0d3v6Fp
+8VxVlNBHqzo0VpakZOkxwqo01qJRsoxVaIxeetGNQ4noPhtj6bEM4Y8xDS9f3R7o
+eEHUSTnKonMemm/AB3KZnjwL7rkL2FI1ThmDRO3Z3lprbThjThJF8EU=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3.cnf b/scripts/resource-cert-samples/LIR3.cnf
new file mode 100644
index 00000000..50d88f5b
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = LIR3.cer
+serial = LIR3/serial
+private_key = LIR3.key
+database = LIR3/index
+new_certs_dir = LIR3
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY LIR3
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/LIR3/
+authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+sbgp-autonomousSysNum = critical,AS:64534-64540
+sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv4:10.3.0.0/24,IPv6:2001:db8::a00:0/120,IPv6:2001:db8::a03:0/120
diff --git a/scripts/resource-cert-samples/LIR3.key b/scripts/resource-cert-samples/LIR3.key
new file mode 100644
index 00000000..d4d89f21
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEowIBAAKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP
+5tw9g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxcc
+q8GMN0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+
+zoS+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o
+3nlszv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzX
+BWJshlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABAoIBAFqJhaqrK7KsemYP
+08JExnR6g0TneIEn5veWrvrkoGft5h/riu5RK966zz4d6SlS9Omgk2/NbCRNJ91+
+XgNs4a8fCOnhx9u41ux6P1FUzBlwlvlHvYTh7cU4WxTC/ohDlnor56ZP6h32+bjt
+5VfzjcF2dBaZ04sPRUIaT6t9mWtaGmUolbHPAV6nsVfE+n6O5zLC2rTVhvdRuE83
+OUuw0PsgmathhpCSdm+kYhjgYEKb5gIv9EUQ8k0+b1+JTczJXJ0UbJpAQFGAnUPm
+kW3D4G4RedlIlP5ngCwPGa6cgTixTVZqMkP7BaBfPdkKuwvPOAHWjhy5JU37GQfj
+YubemXECgYEA2IYt0k1rHjT3r2hfMdUcScx2tTGzHBa0YkeDMtz3gpSDQEzehhHj
+UtP/vj+/XrVGK8V0Zv5bkKdJLjUCzCSVPjS5vESVHdzXrRFQUItMcG7FoqDV/hIt
+sFE2yYnrEx93xoHgSK6r0Btnn7GGKeYg8p8nLPI2Ed+vgmVsQ3C0VnUCgYEAwN8c
+iA5YNZKCOnL3ZFN7cYVVar6k04/T+StWRCqQyoKCUqTU2w0TMQ6HRzwpoCbTIPow
+Zz6cHY121pP0CI0Pdl0YYCbyQXLH0+hhRxBZ8LNBWVkuvn6Fv81J9idpO+yeCD0L
+dZzBXj1ZFa4T4zSWN5TdpcHd5yMjxl9Xo9J5Ed0CgYBtarDxG0pMQ3v+2gFxDz5y
+VK6QNgNK6HZTS8wTAfLZu+7vqWix24xCqPsNyu0MERLav7do7JSc7sxeW0+EleAN
+RVuutgGcy6L5xEwPx7TjBDc/TYOWFt2bwg6rndR7H2XJnIwYbpxIV/DvlCg2OCLi
+OGb1oZiNQ7pPbK1fDy8ymQKBgF5WAoeNtJlncqkSCG0a5BsPY0sVulr8U2rhRo2K
+4E0c7o9rre0ChSuOdp5iD94Uf1n25WvqVMOjqMelkEwKatCzEjQdeIqIkLLWS5ZN
+qiAwHTuNgm6MRfEdgRqUBkXYIyfWa99376Cfkw4mmfWciAjhmFP18gqWxm3FvoET
+dkJFAoGBAMVd38IG4NUbjhHs/8X0YyOD5CASxgFo29ByzCVpl/NUascqkpHRDh0l
+nhvGleI9YZvXSR8K8SJCkg65DwMfbAdlZKyrzr+Eo6/x6LlLOVDLMXFHiri+1Oaz
+nqjwZBLkzWGxtbVr+q1qWJUPzxzODgdPaaagMzrEK5BriWdw4Fil
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/LIR3.req b/scripts/resource-cert-samples/LIR3.req
new file mode 100644
index 00000000..013672c9
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICYDCCAUgCAQAwGzEZMBcGA1UEAxMQVEVTVCBFTlRJVFkgTElSMzCCASIwDQYJ
+KoZIhvcNAQEBBQADggEPADCCAQoCggEBAKMhV2FkrxEY1Mveptyt2SwPD1iffsiF
+VREmTHzwa2ganmoMj+bcPYNYKsx3rBlzb1rzbiSszRrcHQtMRPVtiwoXPYb56P7m
+YOWfQGrllOiaVhcXHKvBjDdAK1W/LF7cjcolf4pf7vsWhuvgCNMm5eNwxQxr+xuP
+a1z24kpYpTUB6gUbPs6EvrU/bRgWS2jleUyIfbalZaM6wjLcrY+KBe726XqA2hKp
+D1q10tMxrD7TGSUtKN55bM79d2bV4y+py/mFjCC7ooYj8JOVIAR4x8cHpv7w9EW7
+z3gr3c6cCKVGaBBM1wVibIZaLX8GOMJNu0SHAEN50o/za7L0XBy5aAECAwEAAaAA
+MA0GCSqGSIb3DQEBBQUAA4IBAQBcWckC9psoEBPLgzwz6COklAzOLW3nWnU4OIBm
+vlOWzOXF0HwKYaB2374yBzNlshVuxGboScJk7mogdckIJfZ2yRbRW1v83uVqbOBU
+KiGnFz1/AUeqdWnUVpFobbKuElUiqjY4ozWTkAZKGya9RgLMsxc0X3tK3cdmpgq6
+6AKiv1erjB6+yZPPvC3pgDYVrucQtng1HZrjW9iEc2RmX3i/rOrysvRUZ+951MD3
+2UDWLdv6rY2wpgBidGx96kj4OVb7j+XlCfjk3QN3SWUPbwUAsEQIr+H5a6E694Ru
+vLQ8/+pQ1tHTeReaRLtjzITQjfLPPM6fMptYs4572mdN3DjZ
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/LIR3/01.pem b/scripts/resource-cert-samples/LIR3/01.pem
new file mode 100644
index 00000000..5f7a0a59
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/01.pem
@@ -0,0 +1,92 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 1 (0x1)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY ISP5c
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:c8:8b:a1:25:65:df:ee:a2:7f:54:af:52:0a:1a:
+ 1a:fa:0d:75:b3:3c:e9:e0:29:d3:89:20:e9:51:49:
+ 67:2c:43:da:a0:2c:d4:44:b3:96:14:a9:07:77:60:
+ b9:6f:01:ef:8e:54:a5:74:ac:5a:67:f8:30:4d:10:
+ f9:ac:9f:b8:75:61:0b:f6:e7:7c:ea:9b:5c:98:7a:
+ 4b:3e:c4:e2:59:42:d3:19:ca:0f:58:0e:b7:c8:82:
+ 4e:e5:bb:ac:fd:92:e5:88:b2:fc:64:cf:6e:38:3b:
+ 18:83:fc:e7:a6:ae:fb:90:36:d0:e1:ca:4d:90:41:
+ 0f:0f:3b:2a:c0:0c:d9:7b:7d:e8:50:13:f6:09:73:
+ 82:a3:d2:e3:bb:82:08:87:7f:d2:bb:0e:0e:7a:28:
+ b6:25:02:b5:d9:51:fc:33:32:47:47:ff:cf:7f:bc:
+ ee:00:01:bb:05:5e:2e:03:9a:ad:95:3b:ca:c2:c6:
+ 87:64:74:39:aa:59:6b:ae:e0:a7:51:1a:07:f2:8e:
+ 4c:8e:65:2f:df:f2:99:ba:e0:b6:8a:4f:c0:20:72:
+ 79:98:00:8f:0d:50:13:3d:d1:3e:8c:bd:dc:74:a9:
+ 33:a8:56:1d:31:78:7c:e7:02:9e:8d:0a:14:12:6d:
+ d3:37:c7:7a:f0:84:10:fe:fe:4d:28:97:26:6e:08:
+ 85:a1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 2D:87:C1:9A:F8:58:2B:BD:C2:F8:7E:30:47:B3:A9:88:37:C9:EB:46
+ X509v3 Authority Key Identifier:
+ keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5c/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 50:6b:1b:84:77:e5:93:08:5e:dc:42:24:86:70:11:24:f8:11:
+ 91:68:0f:08:9b:49:f6:4a:27:85:13:93:ed:59:49:d0:f8:a6:
+ d2:44:ab:25:69:41:59:40:8b:78:ab:d2:8d:09:a8:c0:fe:20:
+ 49:d7:47:c4:de:19:a1:79:d2:8d:bd:29:08:37:a8:9a:b6:5e:
+ 56:25:50:da:1c:47:e8:bf:ed:1e:49:79:48:81:07:97:d3:2f:
+ 14:e7:bc:8e:e9:ef:82:9a:bd:18:60:08:08:57:22:6e:45:bb:
+ 1a:9f:69:e0:0f:86:42:49:ec:d2:5f:6f:fb:01:b0:b9:56:66:
+ aa:62:64:e1:80:68:ee:11:d9:45:b8:3a:fc:81:4b:d4:c0:f7:
+ 1c:a7:97:9a:7d:f7:94:2c:05:86:35:2e:0c:83:17:45:b6:3f:
+ d6:4e:5f:ba:2d:77:41:4a:25:37:b9:8b:4a:4e:b4:36:f5:c9:
+ f7:84:e0:6b:af:1c:d5:e0:88:a5:aa:6f:87:10:18:c3:af:46:
+ ee:63:97:e3:66:98:bb:51:67:89:d6:4d:8f:b2:ed:f6:33:ae:
+ 5b:44:44:1e:56:af:ac:6d:7b:1f:13:f9:96:84:ee:08:db:4b:
+ 1f:56:48:ac:97:0e:ee:b5:33:f4:2d:03:62:a3:32:6d:85:85:
+ 52:a6:47:ca
+-----BEGIN CERTIFICATE-----
+MIIDxjCCAq6gAwIBAgIBATANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgxOFoXDTA4MDczMTE0NDgxOFowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWMwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDIi6ElZd/uon9Ur1IKGhr6DXWzPOngKdOJIOlRSWcsQ9qgLNRE
+s5YUqQd3YLlvAe+OVKV0rFpn+DBNEPmsn7h1YQv253zqm1yYeks+xOJZQtMZyg9Y
+DrfIgk7lu6z9kuWIsvxkz244OxiD/OemrvuQNtDhyk2QQQ8POyrADNl7fehQE/YJ
+c4Kj0uO7ggiHf9K7Dg56KLYlArXZUfwzMkdH/89/vO4AAbsFXi4Dmq2VO8rCxodk
+dDmqWWuu4KdRGgfyjkyOZS/f8pm64LaKT8AgcnmYAI8NUBM90T6Mvdx0qTOoVh0x
+eHznAp6NChQSbdM3x3rwhBD+/k0olyZuCIWhAgMBAAGjggESMIIBDjAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQth8Ga+FgrvcL4fjBHs6mIN8nrRjAfBgNVHSME
+GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
+BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDVjLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
+Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwIQYIKwYBBQUHAQgB
+Af8EEjAQoA4wDDAKAgMA/BYCAwD8HDANBgkqhkiG9w0BAQUFAAOCAQEAUGsbhHfl
+kwhe3EIkhnARJPgRkWgPCJtJ9konhROT7VlJ0Pim0kSrJWlBWUCLeKvSjQmowP4g
+SddHxN4ZoXnSjb0pCDeomrZeViVQ2hxH6L/tHkl5SIEHl9MvFOe8junvgpq9GGAI
+CFcibkW7Gp9p4A+GQkns0l9v+wGwuVZmqmJk4YBo7hHZRbg6/IFL1MD3HKeXmn33
+lCwFhjUuDIMXRbY/1k5fui13QUolN7mLSk60NvXJ94Tga68c1eCIpapvhxAYw69G
+7mOX42aYu1FnidZNj7Lt9jOuW0REHlavrG17HxP5loTuCNtLH1ZIrJcO7rUz9C0D
+YqMybYWFUqZHyg==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/02.pem b/scripts/resource-cert-samples/LIR3/02.pem
new file mode 100644
index 00000000..47299c75
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/02.pem
@@ -0,0 +1,94 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 2 (0x2)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 1 14:48:20 2007 GMT
+ Not After : Jul 31 14:48:20 2008 GMT
+ Subject: CN=TEST ENTITY ISP5b
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:bf:8f:59:d8:fc:fa:1d:04:70:29:ce:7b:01:64:
+ 21:40:dc:5c:43:fe:4c:af:88:c8:62:9b:be:9c:72:
+ 8f:8a:a5:34:8a:3b:23:8d:9b:8a:4f:bf:66:ac:68:
+ 71:9c:fd:68:59:f5:bf:9f:4d:2e:b5:d6:e3:fa:bd:
+ f3:60:53:5c:b7:11:ac:95:0b:c0:87:cd:99:9e:94:
+ 57:8d:ec:05:b8:df:aa:fc:8e:38:d3:0f:65:6d:09:
+ 60:f2:e1:98:81:72:d8:51:3e:41:91:b3:10:95:f5:
+ f5:d0:f9:e5:5c:a1:85:fa:71:26:85:e3:d1:4c:02:
+ 7f:14:e2:1e:4a:8a:96:68:9e:d6:16:a5:ef:ad:b5:
+ 83:62:cd:23:74:7c:82:56:b4:d1:34:53:5a:8a:7a:
+ 61:9f:ae:54:5b:ef:f9:56:de:87:6b:42:92:bc:49:
+ f4:b5:c3:35:07:4a:18:47:d2:92:c6:1c:16:74:74:
+ b1:e9:39:3c:53:12:05:9d:eb:dc:9c:72:2b:97:4d:
+ 27:21:77:96:7d:4c:ce:79:0c:fb:a7:b8:99:6b:66:
+ 20:2e:56:9c:44:b4:e3:5e:80:c4:7d:78:a1:b4:05:
+ f7:20:7d:26:1e:44:bf:5d:69:15:3c:7a:24:67:bd:
+ b9:b5:08:0f:33:4d:af:3b:2d:e7:b9:ab:1d:2b:d6:
+ fb:73
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 6C:B3:65:94:FE:C6:9F:4A:50:9D:4D:8B:40:1A:A1:FD:97:17:97:92
+ X509v3 Authority Key Identifier:
+ keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5b/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 44:d8:15:ad:71:7e:e9:6e:ec:33:2b:42:ed:8c:8a:4a:df:82:
+ a4:91:99:57:b0:2f:cc:a3:59:2a:ff:24:c5:ac:e1:79:fa:d7:
+ 92:ba:72:2b:47:1a:cf:80:6d:08:76:e9:b5:91:60:35:1f:dd:
+ 0c:e0:bd:33:7c:27:d0:f7:11:4e:1f:48:4a:05:bc:6d:e3:5f:
+ ba:dd:7a:ba:3d:45:7d:97:72:94:9b:cd:31:76:b8:96:df:f0:
+ 7d:16:f3:2a:a3:e2:72:eb:02:1f:49:ee:b6:44:48:5b:69:99:
+ b8:bb:80:3b:cb:f5:bc:aa:f8:ba:68:19:53:ec:ff:ad:75:ae:
+ 82:51:00:ec:e7:81:c2:6b:cf:a2:a2:a2:c5:b8:04:47:91:ad:
+ 9d:33:72:48:a2:15:55:ad:43:52:8f:f6:09:a3:d3:fd:88:d3:
+ e3:c3:f4:cd:71:e8:cb:aa:e7:36:07:27:d9:e9:a4:a1:e8:33:
+ cd:2d:9c:37:ee:48:e4:8f:8e:f0:84:67:64:89:ea:9a:23:e0:
+ 12:01:25:80:41:70:fa:b8:3a:c7:0d:b7:c9:ac:79:37:2a:b1:
+ d7:62:79:ea:db:74:b4:f5:86:86:b6:1e:d5:d0:b0:29:96:a3:
+ 58:a9:f7:3f:df:8d:31:c1:90:d1:df:1b:c3:f4:14:f8:1d:d1:
+ c9:57:95:7f
+-----BEGIN CERTIFICATE-----
+MIID3jCCAsagAwIBAgIBAjANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgyMFoXDTA4MDczMTE0NDgyMFowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWIwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQC/j1nY/PodBHApznsBZCFA3FxD/kyviMhim76cco+KpTSKOyON
+m4pPv2asaHGc/WhZ9b+fTS611uP6vfNgU1y3EayVC8CHzZmelFeN7AW436r8jjjT
+D2VtCWDy4ZiBcthRPkGRsxCV9fXQ+eVcoYX6cSaF49FMAn8U4h5KipZontYWpe+t
+tYNizSN0fIJWtNE0U1qKemGfrlRb7/lW3odrQpK8SfS1wzUHShhH0pLGHBZ0dLHp
+OTxTEgWd69ycciuXTSchd5Z9TM55DPunuJlrZiAuVpxEtONegMR9eKG0BfcgfSYe
+RL9daRU8eiRnvbm1CA8zTa87Lee5qx0r1vtzAgMBAAGjggEqMIIBJjAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBRss2WU/safSlCdTYtAGqH9lxeXkjAfBgNVHSME
+GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
+BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDViLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
+Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwOQYIKwYBBQUHAQcB
+Af8EKjAoMAwEAgABMAYDBAAKAwAwGAQCAAIwEgMQACABDbgAAAAAAAAAAAoDADAN
+BgkqhkiG9w0BAQUFAAOCAQEARNgVrXF+6W7sMytC7YyKSt+CpJGZV7AvzKNZKv8k
+xazhefrXkrpyK0caz4BtCHbptZFgNR/dDOC9M3wn0PcRTh9ISgW8beNfut16uj1F
+fZdylJvNMXa4lt/wfRbzKqPicusCH0nutkRIW2mZuLuAO8v1vKr4umgZU+z/rXWu
+glEA7OeBwmvPoqKixbgER5GtnTNySKIVVa1DUo/2CaPT/YjT48P0zXHoy6rnNgcn
+2emkoegzzS2cN+5I5I+O8IRnZInqmiPgEgElgEFw+rg6xw23yax5Nyqx12J56tt0
+tPWGhrYe1dCwKZajWKn3P9+NMcGQ0d8bw/QU+B3RyVeVfw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/03.pem b/scripts/resource-cert-samples/LIR3/03.pem
new file mode 100644
index 00000000..50780320
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/03.pem
@@ -0,0 +1,94 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 3 (0x3)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY LIR3
+ Validity
+ Not Before: Aug 1 14:48:22 2007 GMT
+ Not After : Jul 31 14:48:22 2008 GMT
+ Subject: CN=TEST ENTITY ISP5a
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:e6:4b:ad:78:28:6b:e6:50:1b:65:81:d5:8d:2b:
+ 56:77:cd:bb:c9:47:a0:aa:32:b0:2c:ac:1f:f1:e4:
+ 90:2b:c2:33:6f:e7:53:b1:d0:1d:ab:05:27:9d:b7:
+ a1:ee:a8:4f:c8:5b:36:23:e3:12:e4:51:59:27:cd:
+ fd:7a:aa:dc:56:05:a1:73:ab:79:dd:3c:82:b2:8f:
+ ae:f9:ec:c0:36:38:e6:02:aa:fd:89:60:21:52:5b:
+ b6:33:80:75:e5:7f:fd:ac:6e:ec:d4:9a:26:2f:7e:
+ 28:45:16:29:47:7d:f3:8a:72:d5:e4:65:fa:f4:54:
+ 6f:ae:48:33:62:c1:32:f1:2b:83:33:36:63:60:9e:
+ bc:c7:e7:99:5d:51:da:cd:2f:8f:83:47:20:9e:e9:
+ cc:a3:72:c0:72:bd:49:2d:c4:52:ea:6f:da:42:46:
+ 71:90:c7:af:7f:9f:c7:dd:0b:96:96:3c:45:9f:c0:
+ ea:65:6a:43:e3:f3:92:d5:e1:73:c0:6e:20:f5:17:
+ e5:d1:58:da:21:b3:e9:0c:4d:f0:e8:bd:7c:b7:ef:
+ 81:c9:f5:70:cf:a8:20:7d:e2:6a:f9:1b:66:a9:c8:
+ 71:d6:32:f8:72:3d:83:99:19:0d:0c:6b:e9:f8:92:
+ cd:33:17:86:6a:3d:af:0d:05:94:ab:1c:d4:2c:a4:
+ 45:cb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 09:F0:14:0B:79:FB:0B:FF:A8:EF:54:B9:EC:3E:B9:8B:D0:CB:9C:EC
+ X509v3 Authority Key Identifier:
+ keyid:98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/ISP5a/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/LIR3.cer
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 93:32:99:62:dd:c5:ea:f0:1f:58:50:10:37:d3:39:37:d9:f6:
+ 92:51:26:2f:d6:fd:6f:82:b8:56:6b:fd:0c:f3:42:04:56:ed:
+ 67:2b:42:02:98:56:07:f1:48:2d:2e:b4:32:bb:d7:1c:27:14:
+ a0:e9:ad:3b:1d:fe:0b:0e:43:df:22:97:f1:8f:73:d8:76:d6:
+ 9b:0d:bf:ee:20:e8:77:17:a3:83:01:b3:23:43:85:6b:bf:6f:
+ cc:2e:69:47:05:73:f4:21:45:94:c8:ae:21:28:41:16:91:ee:
+ 48:49:66:5a:67:31:71:04:c9:49:71:94:d5:f4:86:5c:7b:c6:
+ 3e:fe:91:1d:21:b3:14:98:54:ad:6e:51:28:e9:a8:22:ba:a4:
+ d0:9c:8c:e3:d4:7c:21:10:0c:f9:a3:00:f8:c3:9f:00:b4:53:
+ 34:06:af:5b:4a:43:95:cb:b2:fb:8c:18:00:86:11:28:5e:24:
+ e1:90:d8:67:d8:00:fc:b6:27:1f:9e:b1:be:91:17:c1:11:35:
+ 6e:9c:60:50:2e:67:f3:04:2b:74:89:f9:fe:92:73:dd:1e:44:
+ 81:67:b8:08:63:a8:9f:f4:8c:bc:47:de:f1:df:8b:11:cd:02:
+ ec:b9:ad:0b:06:28:0c:e2:84:36:83:85:f3:4f:46:56:46:d5:
+ f5:f8:cb:f3
+-----BEGIN CERTIFICATE-----
+MIID3jCCAsagAwIBAgIBAzANBgkqhkiG9w0BAQUFADAbMRkwFwYDVQQDExBURVNU
+IEVOVElUWSBMSVIzMB4XDTA3MDgwMTE0NDgyMloXDTA4MDczMTE0NDgyMlowHDEa
+MBgGA1UEAxMRVEVTVCBFTlRJVFkgSVNQNWEwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDmS614KGvmUBtlgdWNK1Z3zbvJR6CqMrAsrB/x5JArwjNv51Ox
+0B2rBSedt6HuqE/IWzYj4xLkUVknzf16qtxWBaFzq3ndPIKyj6757MA2OOYCqv2J
+YCFSW7YzgHXlf/2sbuzUmiYvfihFFilHffOKctXkZfr0VG+uSDNiwTLxK4MzNmNg
+nrzH55ldUdrNL4+DRyCe6cyjcsByvUktxFLqb9pCRnGQx69/n8fdC5aWPEWfwOpl
+akPj85LV4XPAbiD1F+XRWNohs+kMTfDovXy374HJ9XDPqCB94mr5G2apyHHWMvhy
+PYOZGQ0Ma+n4ks0zF4ZqPa8NBZSrHNQspEXLAgMBAAGjggEqMIIBJjAPBgNVHRMB
+Af8EBTADAQH/MB0GA1UdDgQWBBQJ8BQLefsL/6jvVLnsPrmL0Muc7DAfBgNVHSME
+GDAWgBSYvgT/gNGrlTmqPfIOZ30AraP9xTAOBgNVHQ8BAf8EBAMCAQYwQgYIKwYB
+BQUHAQsENjA0MDIGCCsGAQUFBzAFhiZyc3luYzovL3dvbWJhdHMtci11cy5oYWN0
+cm4ubmV0L0lTUDVhLzBEBggrBgEFBQcBAQQ4MDYwNAYIKwYBBQUHMAKGKHJzeW5j
+Oi8vd29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvTElSMy5jZXIwOQYIKwYBBQUHAQcB
+Af8EKjAoMAwEAgABMAYDBAAKAAAwGAQCAAIwEgMQACABDbgAAAAAAAAAAAoAADAN
+BgkqhkiG9w0BAQUFAAOCAQEAkzKZYt3F6vAfWFAQN9M5N9n2klEmL9b9b4K4Vmv9
+DPNCBFbtZytCAphWB/FILS60MrvXHCcUoOmtOx3+Cw5D3yKX8Y9z2HbWmw2/7iDo
+dxejgwGzI0OFa79vzC5pRwVz9CFFlMiuIShBFpHuSElmWmcxcQTJSXGU1fSGXHvG
+Pv6RHSGzFJhUrW5RKOmoIrqk0JyM49R8IRAM+aMA+MOfALRTNAavW0pDlcuy+4wY
+AIYRKF4k4ZDYZ9gA/LYnH56xvpEXwRE1bpxgUC5n8wQrdIn5/pJz3R5EgWe4CGOo
+n/SMvEfe8d+LEc0C7LmtCwYoDOKENoOF809GVkbV9fjL8w==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/LIR3/index b/scripts/resource-cert-samples/LIR3/index
new file mode 100644
index 00000000..eb62d129
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/index
@@ -0,0 +1,3 @@
+V 080731144818Z 01 unknown /CN=TEST ENTITY ISP5c
+V 080731144820Z 02 unknown /CN=TEST ENTITY ISP5b
+V 080731144822Z 03 unknown /CN=TEST ENTITY ISP5a
diff --git a/scripts/resource-cert-samples/LIR3/index.attr b/scripts/resource-cert-samples/LIR3/index.attr
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/index.attr
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/LIR3/index.attr.old b/scripts/resource-cert-samples/LIR3/index.attr.old
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/index.attr.old
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/LIR3/index.old b/scripts/resource-cert-samples/LIR3/index.old
new file mode 100644
index 00000000..162abf18
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/index.old
@@ -0,0 +1,2 @@
+V 080731144818Z 01 unknown /CN=TEST ENTITY ISP5c
+V 080731144820Z 02 unknown /CN=TEST ENTITY ISP5b
diff --git a/scripts/resource-cert-samples/LIR3/serial b/scripts/resource-cert-samples/LIR3/serial
new file mode 100644
index 00000000..64969239
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/serial
@@ -0,0 +1 @@
+04
diff --git a/scripts/resource-cert-samples/LIR3/serial.old b/scripts/resource-cert-samples/LIR3/serial.old
new file mode 100644
index 00000000..75016ea3
--- /dev/null
+++ b/scripts/resource-cert-samples/LIR3/serial.old
@@ -0,0 +1 @@
+03
diff --git a/scripts/resource-cert-samples/Makefile b/scripts/resource-cert-samples/Makefile
new file mode 100644
index 00000000..651cc8ff
--- /dev/null
+++ b/scripts/resource-cert-samples/Makefile
@@ -0,0 +1,166 @@
+# Automatically generated, do not edit.
+
+all:: RIR.cer
+
+RIR.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+RIR.req: RIR.key RIR.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config RIR.cnf -key RIR.key -out $@
+
+RIR.cer: RIR.req RIR.cnf RIR.key Makefile
+ @test -d RIR || mkdir RIR
+ @test -f RIR/index || touch RIR/index
+ @test -f RIR/serial || echo 01 >RIR/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in RIR.req -extensions req_x509_ext -extfile RIR.cnf -config RIR.cnf -selfsign
+
+
+all:: LIR3.cer
+
+LIR3.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+LIR3.req: LIR3.key LIR3.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config LIR3.cnf -key LIR3.key -out $@
+
+LIR3.cer: LIR3.req LIR3.cnf RIR.key Makefile
+ @test -d LIR3 || mkdir LIR3
+ @test -f LIR3/index || touch LIR3/index
+ @test -f LIR3/serial || echo 01 >LIR3/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR3.req -extensions req_x509_ext -extfile LIR3.cnf -config RIR.cnf
+
+
+all:: LIR2.cer
+
+LIR2.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+LIR2.req: LIR2.key LIR2.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config LIR2.cnf -key LIR2.key -out $@
+
+LIR2.cer: LIR2.req LIR2.cnf RIR.key Makefile
+ @test -d LIR2 || mkdir LIR2
+ @test -f LIR2/index || touch LIR2/index
+ @test -f LIR2/serial || echo 01 >LIR2/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR2.req -extensions req_x509_ext -extfile LIR2.cnf -config RIR.cnf
+
+
+all:: LIR1.cer
+
+LIR1.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+LIR1.req: LIR1.key LIR1.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config LIR1.cnf -key LIR1.key -out $@
+
+LIR1.cer: LIR1.req LIR1.cnf RIR.key Makefile
+ @test -d LIR1 || mkdir LIR1
+ @test -f LIR1/index || touch LIR1/index
+ @test -f LIR1/serial || echo 01 >LIR1/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in LIR1.req -extensions req_x509_ext -extfile LIR1.cnf -config RIR.cnf
+
+
+all:: ISP5c.cer
+
+ISP5c.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+ISP5c.req: ISP5c.key ISP5c.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config ISP5c.cnf -key ISP5c.key -out $@
+
+ISP5c.cer: ISP5c.req ISP5c.cnf LIR3.key Makefile
+ @test -d ISP5c || mkdir ISP5c
+ @test -f ISP5c/index || touch ISP5c/index
+ @test -f ISP5c/serial || echo 01 >ISP5c/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5c.req -extensions req_x509_ext -extfile ISP5c.cnf -config LIR3.cnf
+
+
+all:: ISP5b.cer
+
+ISP5b.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+ISP5b.req: ISP5b.key ISP5b.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config ISP5b.cnf -key ISP5b.key -out $@
+
+ISP5b.cer: ISP5b.req ISP5b.cnf LIR3.key Makefile
+ @test -d ISP5b || mkdir ISP5b
+ @test -f ISP5b/index || touch ISP5b/index
+ @test -f ISP5b/serial || echo 01 >ISP5b/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5b.req -extensions req_x509_ext -extfile ISP5b.cnf -config LIR3.cnf
+
+
+all:: ISP5a.cer
+
+ISP5a.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+ISP5a.req: ISP5a.key ISP5a.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config ISP5a.cnf -key ISP5a.key -out $@
+
+ISP5a.cer: ISP5a.req ISP5a.cnf LIR3.key Makefile
+ @test -d ISP5a || mkdir ISP5a
+ @test -f ISP5a/index || touch ISP5a/index
+ @test -f ISP5a/serial || echo 01 >ISP5a/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP5a.req -extensions req_x509_ext -extfile ISP5a.cnf -config LIR3.cnf
+
+
+all:: ISP4.cer
+
+ISP4.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+ISP4.req: ISP4.key ISP4.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config ISP4.cnf -key ISP4.key -out $@
+
+ISP4.cer: ISP4.req ISP4.cnf LIR2.key Makefile
+ @test -d ISP4 || mkdir ISP4
+ @test -f ISP4/index || touch ISP4/index
+ @test -f ISP4/serial || echo 01 >ISP4/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP4.req -extensions req_x509_ext -extfile ISP4.cnf -config LIR2.cnf
+
+
+all:: ISP3.cer
+
+ISP3.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+ISP3.req: ISP3.key ISP3.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config ISP3.cnf -key ISP3.key -out $@
+
+ISP3.cer: ISP3.req ISP3.cnf LIR2.key Makefile
+ @test -d ISP3 || mkdir ISP3
+ @test -f ISP3/index || touch ISP3/index
+ @test -f ISP3/serial || echo 01 >ISP3/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP3.req -extensions req_x509_ext -extfile ISP3.cnf -config LIR2.cnf
+
+
+all:: ISP2.cer
+
+ISP2.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+ISP2.req: ISP2.key ISP2.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config ISP2.cnf -key ISP2.key -out $@
+
+ISP2.cer: ISP2.req ISP2.cnf LIR1.key Makefile
+ @test -d ISP2 || mkdir ISP2
+ @test -f ISP2/index || touch ISP2/index
+ @test -f ISP2/serial || echo 01 >ISP2/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP2.req -extensions req_x509_ext -extfile ISP2.cnf -config LIR1.cnf
+
+
+all:: ISP1.cer
+
+ISP1.key:
+ ../../openssl/openssl-0.9.8e/apps/openssl genrsa -out $@ 2048
+
+ISP1.req: ISP1.key ISP1.cnf Makefile
+ ../../openssl/openssl-0.9.8e/apps/openssl req -new -config ISP1.cnf -key ISP1.key -out $@
+
+ISP1.cer: ISP1.req ISP1.cnf LIR1.key Makefile
+ @test -d ISP1 || mkdir ISP1
+ @test -f ISP1/index || touch ISP1/index
+ @test -f ISP1/serial || echo 01 >ISP1/serial
+ ../../openssl/openssl-0.9.8e/apps/openssl ca -batch -out $@ -in ISP1.req -extensions req_x509_ext -extfile ISP1.cnf -config LIR1.cnf
+
diff --git a/scripts/resource-cert-samples/RIR.cer b/scripts/resource-cert-samples/RIR.cer
new file mode 100644
index 00000000..86579fdb
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR.cer
@@ -0,0 +1,104 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 13 (0xd)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:16 2007 GMT
+ Not After : Jul 31 14:48:16 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533-64540
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 4c:d4:6d:b2:81:45:07:3e:7b:b4:8b:6c:db:42:2b:30:73:cd:
+ e7:07:39:c3:e6:13:4b:ac:21:33:13:11:00:1c:e6:d1:d4:cf:
+ 96:08:6e:86:7b:41:64:93:88:20:ac:04:81:65:1a:ae:a9:52:
+ be:36:c0:2a:6a:c9:3a:2e:86:83:a2:cc:3e:5d:12:60:49:fb:
+ 48:23:6c:d7:9f:98:fa:b4:b0:d5:48:01:29:74:ca:d1:74:3c:
+ a7:8c:bb:1c:b3:85:90:2a:99:52:9e:e2:31:9a:09:28:2d:d6:
+ ca:eb:f5:c6:da:6f:1b:89:83:eb:b7:d9:6d:56:71:e9:82:8e:
+ b7:84:e1:40:ab:87:15:d2:a6:df:30:11:e1:52:a0:a1:4b:ef:
+ 8e:3a:db:e1:d1:23:74:39:ff:48:d4:4d:2f:74:4e:e3:77:3c:
+ f7:1b:16:0b:b3:1a:c7:46:8b:7c:63:3d:9d:2b:75:82:b7:5c:
+ 9d:7b:df:f9:78:d2:e8:98:48:6c:54:5f:71:2a:a6:95:c6:56:
+ 3e:6c:e2:0c:20:a2:2c:22:f4:1d:3c:05:b2:31:bd:58:f3:23:
+ 60:dd:1d:d2:5e:ab:65:72:06:d2:da:c9:d4:c4:33:c2:b0:7d:
+ 37:13:66:25:b7:28:9b:a3:9c:92:c4:58:b8:02:a2:82:63:fc:
+ a8:93:65:69
+-----BEGIN CERTIFICATE-----
+MIIEMTCCAxmgAwIBAgIBDTANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE2WhcNMDgwNzMxMTQ0ODE2WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggGAMIIBfDAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAfBgNVHSMEGDAW
+gBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8EBAMCAQYwQAYIKwYBBQUH
+AQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4u
+bmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAKAgMA/BUCAwD8HAIDAPwg
+MIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQACgAAAwQACgMAMA4DBQDA
+AAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIwXzAmAxECIAENuAAAAAAA
+AAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24AAAAAAAAAAAKAAADEAAg
+AQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABEMA0GCSqGSIb3DQEBBQUA
+A4IBAQBM1G2ygUUHPnu0i2zbQiswc83nBznD5hNLrCEzExEAHObR1M+WCG6Ge0Fk
+k4ggrASBZRquqVK+NsAqask6LoaDosw+XRJgSftII2zXn5j6tLDVSAEpdMrRdDyn
+jLscs4WQKplSnuIxmgkoLdbK6/XG2m8biYPrt9ltVnHpgo63hOFAq4cV0qbfMBHh
+UqChS++OOtvh0SN0Of9I1E0vdE7jdzz3GxYLsxrHRot8Yz2dK3WCt1yde9/5eNLo
+mEhsVF9xKqaVxlY+bOIMIKIsIvQdPAWyMb1Y8yNg3R3SXqtlcgbS2snUxDPCsH03
+E2Yltyibo5ySxFi4AqKCY/yok2Vp
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR.cnf b/scripts/resource-cert-samples/RIR.cnf
new file mode 100644
index 00000000..95726761
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR.cnf
@@ -0,0 +1,51 @@
+# Automatically generated, do not edit.
+
+[ ca ]
+default_ca = ca_default
+
+[ ca_default ]
+certificate = RIR.cer
+serial = RIR/serial
+private_key = RIR.key
+database = RIR/index
+new_certs_dir = RIR
+name_opt = ca_default
+cert_opt = ca_default
+default_days = 365
+default_crl_days = 30
+default_md = sha1
+preserve = no
+copy_extensions = copy
+policy = ca_policy_anything
+unique_subject = no
+
+[ ca_policy_anything ]
+countryName = optional
+stateOrProvinceName = optional
+localityName = optional
+organizationName = optional
+organizationalUnitName = optional
+commonName = supplied
+emailAddress = optional
+givenName = optional
+surname = optional
+
+[ req ]
+default_bits = 2048
+encrypt_key = no
+distinguished_name = req_dn
+x509_extensions = req_x509_ext
+prompt = no
+
+[ req_dn ]
+CN = TEST ENTITY RIR
+
+[ req_x509_ext ]
+basicConstraints = critical,CA:true
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid
+keyUsage = critical,keyCertSign,cRLSign
+subjectInfoAccess = 1.3.6.1.5.5.7.48.5;URI:rsync://wombats-r-us.hactrn.net/RIR/
+#authorityInfoAccess = caIssuers;URI:rsync://wombats-r-us.hactrn.net/???.cer
+sbgp-autonomousSysNum = critical,AS:64533,AS:64534-64540,AS:64544
+sbgp-ipAddrBlock = critical,IPv4:10.0.0.0/24,IPv4:10.3.0.0/24,IPv4:192.0.2.1-192.0.2.33,IPv4:192.0.2.44-192.0.2.100,IPv6:2001:db8::44-2001:db8::100,IPv6:2001:db8::a00:0/120,IPv6:2001:db8::a03:0/120,IPv6:2001:db8::10:0:44/128
diff --git a/scripts/resource-cert-samples/RIR.key b/scripts/resource-cert-samples/RIR.key
new file mode 100644
index 00000000..5721f051
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR.key
@@ -0,0 +1,27 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIEowIBAAKCAQEArKcmxJhombby58WXBX751/LsOeYrjsJCiLmPIrY8WbAOih0O
++IGxyP9KihpDvHiRPq+ysJVgqT6dwv+Zj4+23NhGt4Y1pvZCBcLFm4QV4lgPcJy8
+U9codvjyFHkivdaLbA4rAuXY8zP6FkObgIf5skWrvX0UsiQvQRNvRcTc+U1/2NPh
+qlxSncl6OLewQ723ajdD7Oc0xDtMysx7H5Hvq9Q1dkKC1PV54BI8JJIu3KJcg/Bx
+iiaWMNS4lk0ALBrwD3lSxydzVHfBhvmGYc7gaaeoPXc55yTuQY1SGTtXjITMmtUF
+fOaDLOMTbWYbhyCCR+EFJvA7KWltvK9IkcRA8QIDAQABAoIBAQCUKyLfJvjlqhcO
+BwlTQyRBSo2mJr0M1/PniG+pV4G1ap0ftE5rwEoF9+lNWbr13PaxOHF+j8OTm1Qi
+y95KUQiawNT3nSsgLUh9zyhtDU8Gn5Ioj6ojvYtRhtWh8k95YcznH8WTyBOGq/2c
+68pg5NDKSHZZuSVwuBMBox8kXg1RuOI7iEcj1q3QjkzZDQURzkW4jSrWgTeIXt6p
++0fngY15xhYP3FGNAOuqfs1GJK33sQO7A7XWew2UAiiPCxfgGDFRe/tV1I4KuS3/
+Uw23ZtGLQ3nu+SEvTK491uZ38Gld2qEBzNdQv+DwhBRyGl0K5QWFmr90Ko0zYgV8
+9OAGebYBAoGBAOBG2+6erAjy+wdeNLcY+pmgsNBZ9rPkHB2XQaxagId5WTYza0Yv
+JwjEiRo6/r1lZ1F0su7rtjQK9V0jfCHVe4jlpLA/qB+HRIbcTFI+GTr3onZwWLuK
+CX21a6Nw+FS462DBYWqh8qOUbi/14csGOYwU1ZB7vfSvlZZZyZYosbihAoGBAMUS
++XP0BCPtnY19BnrWBaQqzLNFiuDA/uBcxq9/BlLifu419Ado6EmqVn8A6aD0zWoE
+OSQrtJJhvMMLM/2ihYZaW/YtI1IAnDzV51QSbc/biFrSzvT102ABFOwpB33uFeWK
+hrQF+7n6imU4f+9iGceAOe/si3fieDUjJ2aEyxZRAoGAO7oDJgfxjqyOt4aaCUzI
+qBMII2Rh88RCzIqUfb7YTbu+S1XkMpuqDIaycF7Xqj6QBjxKzp/NNQzaDQS/MQ92
+R53Ifvtk3YibckLGvHw3IeICzQHcT41SO70Nvkf+iil43ZqCQ/B++pszwOf9SqEM
+wEZoHYMmsjv0XUbqDWgm9CECgYBliV8pFOJFOJniWjZKd5a0fLC29O+W2Rj4tBRS
+O1ogvj2zseynHLABtFeYW/oDSd3D76UZM8N3YBAHVfBVj7TIAio7bgoyp8nXtkXX
+lR8q5uscEF087KMZZbVH7+PCSDbT60l321VU/vbrK+8OgTbTCQfQy8kX3YEdr50P
+Pv/74QKBgAn1B3+6n6WYFkpIPFKrs4MhVmVveqXQy2DcZb+W0WTm+Z7xBCP496mc
+E3FEyKSYocIrDdmtcGDWO4kudrkXmpFJvd6Mi7v076khvQwDQ0++F7JWkAeUFEm4
+kBOCpCRpGlDgr14klqRJzO9swvt2TbPstE3Tofl9mIXaflud3bd3
+-----END RSA PRIVATE KEY-----
diff --git a/scripts/resource-cert-samples/RIR.req b/scripts/resource-cert-samples/RIR.req
new file mode 100644
index 00000000..7d7fb1ce
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR.req
@@ -0,0 +1,15 @@
+-----BEGIN CERTIFICATE REQUEST-----
+MIICXzCCAUcCAQAwGjEYMBYGA1UEAxMPVEVTVCBFTlRJVFkgUklSMIIBIjANBgkq
+hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArKcmxJhombby58WXBX751/LsOeYrjsJC
+iLmPIrY8WbAOih0O+IGxyP9KihpDvHiRPq+ysJVgqT6dwv+Zj4+23NhGt4Y1pvZC
+BcLFm4QV4lgPcJy8U9codvjyFHkivdaLbA4rAuXY8zP6FkObgIf5skWrvX0UsiQv
+QRNvRcTc+U1/2NPhqlxSncl6OLewQ723ajdD7Oc0xDtMysx7H5Hvq9Q1dkKC1PV5
+4BI8JJIu3KJcg/BxiiaWMNS4lk0ALBrwD3lSxydzVHfBhvmGYc7gaaeoPXc55yTu
+QY1SGTtXjITMmtUFfOaDLOMTbWYbhyCCR+EFJvA7KWltvK9IkcRA8QIDAQABoAAw
+DQYJKoZIhvcNAQEFBQADggEBAG3N++oUVHfXRj1clE/tRFfJ5Dtp8IwffnnOip+M
+OX51/0L/n/SiBhKGoOl68Cyg6L6n6+OTueUWv6FVYwmtzjFh2ocF60Ka7Zb26UYf
+wrdwxrRTbMqKmZh1Llq2fVep6DYxjoAXghBvs8MB8UjOrOe5aR+YMZPsOaZ8dCa/
+pLyfG/rjQxix057ukWnDv29MA+iaSYrcOijWAR6HH5mq9QsDi0RwoWMiG/C0GVLE
+QPXIJkR76P2ZqLRPmqQTwXZYiSGjMSeRKdyt6idCkSDCH2SlungYNxDJAS781AYK
+PC0UHnWQroMSW5dMm5GXo1bWhiCfkIE7z8yc5E0ob3GLoNE=
+-----END CERTIFICATE REQUEST-----
diff --git a/scripts/resource-cert-samples/RIR/01.pem b/scripts/resource-cert-samples/RIR/01.pem
new file mode 100644
index 00000000..07ee97f6
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/01.pem
@@ -0,0 +1,24 @@
+-----BEGIN CERTIFICATE-----
+MIID9zCCAt+gAwIBAgIBATANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMDU0NTIzWhcNMDgwNzMxMDU0NTIzWjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFGMIIBQjAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAfBgNVHSMEGDAW
+gBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8EBAMCAQYwQAYIKwYBBQUH
+AQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4u
+bmV0L1JJUi8wHwYIKwYBBQUHAQgBAf8EEDAOoAwwCgIDAPwVAgMA/CAwfAYIKwYB
+BQUHAQcBAf8EbTBrMCYEAgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUA
+wAACZDBBBAIAAjA7MCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABAAMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBAAMSdVb0
+8uyFbF8CPlOzqgJv/jG+qPWDRUh8XqHiMvoGtUXbHUn7dO/XHJ2rsdL14F7mUPbI
+jzdtbVeK4aMKQBJ9u2ZYsCcpmJYiF/GBMva93X5Fpbnzzj7pJ5AeoIo2qEi7zqqq
+hhnInDZmTNRvV21u18VMaz1YBsEJZjr99lqNibba6UsoISVU2KEPVxob/nRHisGX
+Sd7mxhkkpTKO11Z4/viUxEQORfjtqnkIk3lmJwTjz2ASmBfuwH4QsLLu9m92ueF5
+PoHO/P8c2TZg1go8jYlBAd61AZHNaixF9EFObfcRNRuFiUfdnMpn8msPpiM3WCbj
+CgdEWb4i5d2+jZM=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/02.pem b/scripts/resource-cert-samples/RIR/02.pem
new file mode 100644
index 00000000..b9922644
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/02.pem
@@ -0,0 +1,24 @@
+-----BEGIN CERTIFICATE-----
+MIIEETCCAvmgAwIBAgIBAjANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMDU0NTI0WhcNMDgwNzMxMDU0NTI0WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBXzCCAVswDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEEAgACMDswJgMRAiABDbgA
+AAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEAIAENuAAAAAAAAAAQAAAA
+RDANBgkqhkiG9w0BAQUFAAOCAQEAiSIKq9RWuFEow+iALzmf/bwwB8cn7TOcfQjf
+6U5/CHb4FlSMCfrcsxXdHQtDD2CAVhj3J3o2CDZ4FRVnROahg9QGbUv9CExEvAVZ
+PJWFvU2/i3yWblucCWonl9ObxmNiScYgU/wpjoSwO7uxlGujc8Weraqq9qW85vk3
+F17jB8O2aEGnKn2/wmAhgXcwrnZTVRSEtEqXc2CucpFkonLrGID1UCwkY83z5XRy
+h6UUSHf+XtpRLmEwxtTSYGLTUgMQFQPzyBL+OBSPJSJyAm1NbZuY9hvJ4Yn9at0d
+S6H1J1l1y6MTQBMF84qSaAVsuy0tZrsPaBh5tMK9Wtl6ACrHtQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/03.pem b/scripts/resource-cert-samples/RIR/03.pem
new file mode 100644
index 00000000..3b7fe4ac
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/03.pem
@@ -0,0 +1,24 @@
+-----BEGIN CERTIFICATE-----
+MIID9jCCAt6gAwIBAgIBAzANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMDU0NTI1WhcNMDgwNzMxMDU0NTI1WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBRDCCAUAwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYEAgABMCAwDgMFAMAAAgED
+BQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEAPENXZekh
+lKRhT+y1XgSOwZ2C9y7Gk6Ogdwj7yv8CIuCD/Es5+ekAYqW4vpch9jYvRind+MAU
+5DriEtdsjhn7cxQVgSgGJk3dyymhRvODLSR0r+KUYj0Yo4I6XB71ZdbsfCcY5KpG
+/r0MkM6aJxwDR26WvzMUcfU5tN1Dug2iW7dzKfnt/yo3w2vfr/f7ForU/eOde9Jr
+JAVXctcYLfYrAmaYEYZBMnWBeHKhLSzWEkhsW5EeFULIlSDvCDB0zXPvEjOY+PhT
+IM0GCPNv2OruGLAmCdc6MGfmhUKIxXMyXGBES3kjphudTF+zcZx9TV9U+M4/35M3
+X51eZH/pyqBKBw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/04.pem b/scripts/resource-cert-samples/RIR/04.pem
new file mode 100644
index 00000000..29900503
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/04.pem
@@ -0,0 +1,99 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 4 (0x4)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:05:29 2007 GMT
+ Not After : Jul 31 14:05:29 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 0a:c5:a7:72:a7:bf:b4:e6:ab:04:40:0f:39:bd:54:88:30:2b:
+ e7:a7:91:f4:e8:2f:38:8a:ff:99:68:0a:ab:ce:d8:7d:51:e3:
+ 73:2b:64:bf:6a:b5:78:db:96:2e:0d:5b:ec:99:da:aa:63:62:
+ 43:5c:f7:df:a8:c0:93:ab:5e:ff:de:8f:c6:c9:de:fd:f9:b6:
+ 6e:6e:96:81:db:db:cc:2c:47:3b:60:33:e2:8d:6d:28:23:13:
+ f8:e1:84:2d:6f:1c:45:fc:54:91:0e:21:53:3b:a3:23:37:2b:
+ 64:ab:99:33:66:30:b6:bb:20:c1:d6:d4:34:b4:2a:c8:84:5b:
+ 87:38:69:ea:82:ef:6d:59:2a:ed:7f:d3:ba:02:34:47:b7:75:
+ a8:43:30:15:24:9d:58:ed:0a:d3:a0:3f:32:f5:9b:4c:7b:2d:
+ 9d:73:91:5f:37:08:aa:e4:b3:48:5c:b8:64:dc:09:c4:13:72:
+ 15:f8:3d:f9:d4:96:d0:9a:83:52:8d:17:b9:c7:ea:33:10:08:
+ 67:c7:85:23:26:57:f2:cc:b5:d2:a0:65:cc:57:4e:77:7d:2f:
+ 68:7c:d7:e6:9a:9c:2f:c3:0b:c6:9d:05:5d:56:17:45:81:7f:
+ 7c:2c:77:fc:2a:f4:33:18:0d:ea:e8:3d:fd:00:55:90:8a:1d:
+ b8:2c:64:69
+-----BEGIN CERTIFICATE-----
+MIID9zCCAt+gAwIBAgIBBDANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwNTI5WhcNMDgwNzMxMTQwNTI5WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFGMIIBQjAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAfBgNVHSMEGDAW
+gBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8EBAMCAQYwQAYIKwYBBQUH
+AQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4u
+bmV0L1JJUi8wHwYIKwYBBQUHAQgBAf8EEDAOoAwwCgIDAPwVAgMA/CAwfAYIKwYB
+BQUHAQcBAf8EbTBrMCYEAgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUA
+wAACZDBBBAIAAjA7MCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABAAMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBAArFp3Kn
+v7TmqwRADzm9VIgwK+enkfToLziK/5loCqvO2H1R43MrZL9qtXjbli4NW+yZ2qpj
+YkNc99+owJOrXv/ej8bJ3v35tm5uloHb28wsRztgM+KNbSgjE/jhhC1vHEX8VJEO
+IVM7oyM3K2SrmTNmMLa7IMHW1DS0KsiEW4c4aeqC721ZKu1/07oCNEe3dahDMBUk
+nVjtCtOgPzL1m0x7LZ1zkV83CKrks0hcuGTcCcQTchX4PfnUltCag1KNF7nH6jMQ
+CGfHhSMmV/LMtdKgZcxXTnd9L2h81+aanC/DC8adBV1WF0WBf3wsd/wq9DMYDero
+Pf0AVZCKHbgsZGk=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/05.pem b/scripts/resource-cert-samples/RIR/05.pem
new file mode 100644
index 00000000..3e86b43b
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/05.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 5 (0x5)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:05:29 2007 GMT
+ Not After : Jul 31 14:05:29 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 2c:7e:f1:e6:b5:3f:58:22:09:5d:48:ab:9a:3b:67:b8:6c:c6:
+ 3d:f4:2e:81:f5:63:42:a0:3f:78:4a:9c:0f:6d:d5:64:21:7a:
+ a9:56:1c:2c:f6:d3:1e:7b:f8:c9:3a:69:09:18:4b:56:88:de:
+ c7:51:19:bf:63:2f:8b:a7:24:63:b9:a9:b1:93:21:14:e4:3d:
+ 38:68:0d:b8:f1:33:6b:1c:fa:5f:87:40:42:5e:f5:8d:15:f7:
+ 9d:7f:89:02:23:f3:fb:7e:29:4c:32:61:d5:b4:8e:68:5d:00:
+ a0:25:3a:99:76:c2:f2:48:b8:1f:05:5a:65:84:e6:71:a1:02:
+ ad:6e:b0:72:39:06:49:bc:ab:f9:d7:b4:76:a9:84:8b:fe:8a:
+ 45:11:1f:c3:58:f0:b4:9d:ee:0a:90:a7:2b:4b:11:ab:7a:90:
+ aa:b6:a2:63:c6:7d:bc:07:1d:f5:6e:67:b9:7d:bd:8e:c4:11:
+ cc:4f:96:2c:8e:95:ec:50:3c:e0:cf:e3:e1:ea:7e:4e:92:54:
+ 58:5b:82:58:8b:51:8a:79:3f:0b:00:d5:c1:00:7b:8d:75:ce:
+ 7b:36:2d:26:36:63:0e:43:01:17:6e:28:fe:d1:5d:12:68:34:
+ 85:0d:59:d3:81:33:73:b0:7c:57:cb:3b:f2:43:e0:7c:4a:44:
+ 89:6d:a3:4c
+-----BEGIN CERTIFICATE-----
+MIIEETCCAvmgAwIBAgIBBTANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwNTI5WhcNMDgwNzMxMTQwNTI5WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBXzCCAVswDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEEAgACMDswJgMRAiABDbgA
+AAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEAIAENuAAAAAAAAAAQAAAA
+RDANBgkqhkiG9w0BAQUFAAOCAQEALH7x5rU/WCIJXUirmjtnuGzGPfQugfVjQqA/
+eEqcD23VZCF6qVYcLPbTHnv4yTppCRhLVojex1EZv2Mvi6ckY7mpsZMhFOQ9OGgN
+uPEzaxz6X4dAQl71jRX3nX+JAiPz+34pTDJh1bSOaF0AoCU6mXbC8ki4HwVaZYTm
+caECrW6wcjkGSbyr+de0dqmEi/6KRREfw1jwtJ3uCpCnK0sRq3qQqraiY8Z9vAcd
+9W5nuX29jsQRzE+WLI6V7FA84M/j4ep+TpJUWFuCWItRink/CwDVwQB7jXXOezYt
+JjZjDkMBF24o/tFdEmg0hQ1Z04Ezc7B8V8s78kPgfEpEiW2jTA==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/06.pem b/scripts/resource-cert-samples/RIR/06.pem
new file mode 100644
index 00000000..3a8ea7f2
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/06.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 6 (0x6)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:05:29 2007 GMT
+ Not After : Jul 31 14:05:29 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 9c:f0:67:dc:b1:6f:9b:d1:1f:45:d2:2f:8d:09:75:80:39:4c:
+ 51:0b:73:7d:99:8e:e6:8a:89:55:c4:5d:69:6d:fb:55:ea:af:
+ ba:8c:45:3d:ee:b5:e4:7e:76:b9:d6:78:49:23:c9:df:c3:f5:
+ cb:f8:a8:d6:9a:6b:55:92:06:7d:58:84:35:78:df:5c:cc:28:
+ 4e:6c:43:17:31:89:6a:73:86:da:ec:42:ab:1f:94:a3:a4:7a:
+ aa:6b:31:99:22:b1:43:c0:e3:c0:ae:40:88:43:98:cf:8e:b6:
+ b4:e2:b3:46:ca:10:c9:35:8d:cc:8e:1b:d8:fa:a3:2c:24:29:
+ 03:7c:3c:65:78:70:e0:eb:89:96:e6:7f:76:da:cf:c9:d1:c7:
+ 2d:41:b2:3c:e6:8c:39:ca:52:2e:ed:74:81:dd:c2:e9:54:b3:
+ b7:05:53:96:67:6c:50:a3:b9:1c:a6:5a:23:02:c6:5a:df:f4:
+ 27:3f:13:25:25:e9:7f:14:96:90:eb:bd:4d:a7:b4:f5:42:f3:
+ 50:81:34:b9:c9:0b:19:a1:fd:62:96:b1:ed:24:f4:1a:41:60:
+ 9b:59:22:33:69:d3:d2:1e:73:ac:06:68:1c:4a:82:46:6d:57:
+ 9d:6a:d6:64:75:0b:d3:bb:33:31:fb:76:e6:9f:8e:48:de:3f:
+ b4:d7:12:18
+-----BEGIN CERTIFICATE-----
+MIID9jCCAt6gAwIBAgIBBjANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwNTI5WhcNMDgwNzMxMTQwNTI5WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBRDCCAUAwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYEAgABMCAwDgMFAMAAAgED
+BQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEAnPBn3LFv
+m9EfRdIvjQl1gDlMUQtzfZmO5oqJVcRdaW37VeqvuoxFPe615H52udZ4SSPJ38P1
+y/io1pprVZIGfViENXjfXMwoTmxDFzGJanOG2uxCqx+Uo6R6qmsxmSKxQ8DjwK5A
+iEOYz462tOKzRsoQyTWNzI4b2PqjLCQpA3w8ZXhw4OuJluZ/dtrPydHHLUGyPOaM
+OcpSLu10gd3C6VSztwVTlmdsUKO5HKZaIwLGWt/0Jz8TJSXpfxSWkOu9Tae09ULz
+UIE0uckLGaH9Ypax7ST0GkFgm1kiM2nT0h5zrAZoHEqCRm1XnWrWZHUL07szMft2
+5p+OSN4/tNcSGA==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/07.pem b/scripts/resource-cert-samples/RIR/07.pem
new file mode 100644
index 00000000..3d305e50
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/07.pem
@@ -0,0 +1,99 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 7 (0x7)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:08:29 2007 GMT
+ Not After : Jul 31 14:08:29 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 86:f6:b9:a8:10:25:3d:b8:28:c9:14:27:cc:5c:ef:31:6e:cc:
+ 30:b5:0e:9d:ab:c9:ec:4d:ae:8f:62:c9:11:ac:ef:1a:df:05:
+ e2:45:63:66:a4:cd:24:98:49:f0:e7:a2:8c:2c:5a:27:bc:03:
+ 60:1a:f9:0c:d5:dc:27:15:99:9f:c2:dd:cf:dc:b5:6d:1d:ef:
+ b5:1c:6c:14:49:15:ea:a2:1c:84:b8:95:0b:21:91:dd:e9:ee:
+ 26:59:0c:3b:f5:4a:b3:f7:90:42:af:3c:b6:bb:8a:d5:66:a4:
+ 42:28:48:53:81:c0:77:f5:65:27:7f:f0:3f:cf:a5:61:cd:6e:
+ 27:78:63:ea:ab:f5:34:d4:78:99:5e:a4:8f:df:61:32:97:55:
+ 16:55:68:01:83:ee:43:22:6d:7c:6d:cb:da:02:6b:24:68:78:
+ e8:f1:99:eb:f1:78:6b:6e:69:d8:9f:de:a5:bc:65:65:b1:c8:
+ 05:91:ce:ec:76:ef:81:01:e8:af:8f:c7:f8:89:98:8e:1e:77:
+ c4:81:22:96:3f:48:38:29:af:0f:f4:57:68:b2:83:13:95:55:
+ a5:02:64:1c:ed:0b:bb:59:35:69:d4:7a:cf:89:48:86:93:2f:
+ 03:1d:8f:3d:f3:bb:7c:06:f9:c3:aa:39:0d:c5:f0:15:f4:b4:
+ e2:85:6b:71
+-----BEGIN CERTIFICATE-----
+MIID9zCCAt+gAwIBAgIBBzANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwODI5WhcNMDgwNzMxMTQwODI5WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFGMIIBQjAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAfBgNVHSMEGDAW
+gBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8EBAMCAQYwQAYIKwYBBQUH
+AQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4u
+bmV0L1JJUi8wHwYIKwYBBQUHAQgBAf8EEDAOoAwwCgIDAPwVAgMA/CAwfAYIKwYB
+BQUHAQcBAf8EbTBrMCYEAgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUA
+wAACZDBBBAIAAjA7MCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABAAMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBAIb2uagQ
+JT24KMkUJ8xc7zFuzDC1Dp2ryexNro9iyRGs7xrfBeJFY2akzSSYSfDnoowsWie8
+A2Aa+QzV3CcVmZ/C3c/ctW0d77UcbBRJFeqiHIS4lQshkd3p7iZZDDv1SrP3kEKv
+PLa7itVmpEIoSFOBwHf1ZSd/8D/PpWHNbid4Y+qr9TTUeJlepI/fYTKXVRZVaAGD
+7kMibXxty9oCayRoeOjxmevxeGtuadif3qW8ZWWxyAWRzux274EB6K+Px/iJmI4e
+d8SBIpY/SDgprw/0V2iygxOVVaUCZBztC7tZNWnUes+JSIaTLwMdjz3zu3wG+cOq
+OQ3F8BX0tOKFa3E=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/08.pem b/scripts/resource-cert-samples/RIR/08.pem
new file mode 100644
index 00000000..056b591f
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/08.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 8 (0x8)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:08:29 2007 GMT
+ Not After : Jul 31 14:08:29 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ a5:ff:47:52:d6:cf:31:7d:5d:61:f7:71:ca:49:aa:94:9d:82:
+ c6:79:7d:b3:a4:f8:79:6d:df:35:91:a8:2f:d5:98:77:26:6d:
+ a6:9c:78:dd:cd:85:72:b4:4a:7c:b7:7d:01:18:61:29:e1:33:
+ 49:72:3e:f8:21:2c:70:2d:90:fd:5a:84:71:d6:86:79:ee:a4:
+ 4e:47:d3:cc:51:50:44:48:9f:f1:40:f2:4a:11:d0:2b:6d:b5:
+ 83:44:81:f5:18:0f:59:15:60:98:60:b0:81:98:4d:22:49:d6:
+ 1f:0d:8e:f4:7a:87:26:e9:e1:ac:dc:e3:b4:8e:3e:cb:be:25:
+ 7c:79:9d:d5:5a:ee:99:59:b7:ce:2f:29:3a:6f:af:73:28:46:
+ 9c:c6:d3:78:c8:62:c1:d1:79:bd:19:07:ff:75:68:20:29:4e:
+ ef:e9:73:9b:ff:86:ff:3f:7f:d0:a3:5e:15:df:2b:e4:35:1e:
+ 6c:03:fe:7a:6b:e2:94:ae:d5:fe:00:b1:4a:e0:48:e0:72:30:
+ d2:26:73:83:c1:df:6a:bf:f8:9f:be:69:db:c6:2c:7b:e1:57:
+ 45:05:c0:e4:ee:d9:f9:59:53:8f:68:01:9b:0c:6b:8f:a5:80:
+ 23:c2:26:76:8f:79:26:a1:31:e1:c8:42:c8:b3:4f:22:d6:32:
+ 46:62:dc:d2
+-----BEGIN CERTIFICATE-----
+MIIEETCCAvmgAwIBAgIBCDANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwODI5WhcNMDgwNzMxMTQwODI5WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBXzCCAVswDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEEAgACMDswJgMRAiABDbgA
+AAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEAIAENuAAAAAAAAAAQAAAA
+RDANBgkqhkiG9w0BAQUFAAOCAQEApf9HUtbPMX1dYfdxykmqlJ2Cxnl9s6T4eW3f
+NZGoL9WYdyZtppx43c2FcrRKfLd9ARhhKeEzSXI++CEscC2Q/VqEcdaGee6kTkfT
+zFFQREif8UDyShHQK221g0SB9RgPWRVgmGCwgZhNIknWHw2O9HqHJunhrNzjtI4+
+y74lfHmd1VrumVm3zi8pOm+vcyhGnMbTeMhiwdF5vRkH/3VoIClO7+lzm/+G/z9/
+0KNeFd8r5DUebAP+emvilK7V/gCxSuBI4HIw0iZzg8Hfar/4n75p28Yse+FXRQXA
+5O7Z+VlTj2gBmwxrj6WAI8Imdo95JqEx4chCyLNPItYyRmLc0g==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/09.pem b/scripts/resource-cert-samples/RIR/09.pem
new file mode 100644
index 00000000..b490cd62
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/09.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 9 (0x9)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:08:29 2007 GMT
+ Not After : Jul 31 14:08:29 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 9a:f2:47:ba:06:1a:9f:bd:cc:87:8a:8f:14:ac:99:bb:3f:9c:
+ d4:2c:71:5e:3e:75:75:49:e4:9c:bf:57:83:f7:c9:d4:de:6d:
+ d2:53:0a:0b:9b:95:69:b2:26:52:6b:b0:d7:09:7f:40:4d:34:
+ 7e:5d:42:80:b4:9a:1c:82:d0:e0:13:d9:7c:d0:15:81:cb:77:
+ d8:dc:4b:68:fa:33:8f:cd:6b:44:ba:fb:9e:79:23:f9:2b:f1:
+ c5:34:84:3b:e1:80:e8:08:e6:b4:f3:3f:17:ee:be:b0:57:6a:
+ 49:79:8f:c8:b8:75:8f:88:49:29:db:32:ee:4d:fb:f1:b4:96:
+ 28:26:f2:2e:00:27:ae:0c:b2:77:a6:f7:5a:e4:db:a2:0d:9a:
+ c1:77:90:9f:85:40:ef:d3:67:f2:51:99:57:ee:09:07:6a:43:
+ 82:ab:a7:4b:aa:9a:a7:87:84:de:29:ef:64:bd:e6:9b:be:9d:
+ 8f:17:f2:c0:0b:e8:21:ee:42:00:69:f8:9e:c3:06:c2:4f:08:
+ 49:84:a7:33:76:6d:77:ae:be:24:9c:9e:d3:d6:7d:72:5f:79:
+ 5b:ab:b8:1c:5f:95:0c:11:78:e3:94:11:ae:48:ae:33:fa:c4:
+ cb:af:b3:6a:0f:04:c9:a4:54:a6:c0:a5:a3:a2:57:31:53:bc:
+ 8e:e1:f3:28
+-----BEGIN CERTIFICATE-----
+MIID9jCCAt6gAwIBAgIBCTANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwODI5WhcNMDgwNzMxMTQwODI5WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBRDCCAUAwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYEAgABMCAwDgMFAMAAAgED
+BQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEAmvJHugYa
+n73Mh4qPFKyZuz+c1CxxXj51dUnknL9Xg/fJ1N5t0lMKC5uVabImUmuw1wl/QE00
+fl1CgLSaHILQ4BPZfNAVgct32NxLaPozj81rRLr7nnkj+SvxxTSEO+GA6AjmtPM/
+F+6+sFdqSXmPyLh1j4hJKdsy7k378bSWKCbyLgAnrgyyd6b3WuTbog2awXeQn4VA
+79Nn8lGZV+4JB2pDgqunS6qap4eE3invZL3mm76djxfywAvoIe5CAGn4nsMGwk8I
+SYSnM3Ztd66+JJye09Z9cl95W6u4HF+VDBF445QRrkiuM/rEy6+zag8EyaRUpsCl
+o6JXMVO8juHzKA==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/0A.pem b/scripts/resource-cert-samples/RIR/0A.pem
new file mode 100644
index 00000000..433dc6c9
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/0A.pem
@@ -0,0 +1,99 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 10 (0xa)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:09:34 2007 GMT
+ Not After : Jul 31 14:09:34 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 67:ed:a0:29:b8:66:7d:a6:2c:4f:76:52:df:45:15:6f:23:3d:
+ 9c:57:05:19:57:31:f0:76:17:32:17:a0:aa:55:6a:5d:ee:51:
+ 2b:06:6e:75:bd:f2:6c:79:2f:5a:ee:f0:2d:e8:59:dc:a3:86:
+ 5d:b2:98:e1:59:b3:ec:c9:9b:ed:3a:b0:c7:72:56:28:77:a1:
+ 4a:a7:17:03:37:e8:b1:d7:19:a3:85:5c:c8:5c:fb:ad:bc:6a:
+ 0a:65:d7:90:c3:f8:12:83:53:89:c5:7a:71:b4:1f:61:69:5a:
+ 23:b5:24:5a:6f:23:9d:b0:ac:bc:83:01:c1:e9:41:f8:9e:ae:
+ e0:2b:a7:76:03:10:86:7f:76:3d:3d:f4:5f:04:2f:1b:e0:37:
+ 14:6d:97:7c:4f:ba:34:84:d7:6d:c0:90:7c:6d:97:11:c9:a8:
+ aa:96:7f:65:f7:f4:b6:57:0f:13:2a:3e:68:23:98:b5:f6:11:
+ 5b:1a:b4:ab:0f:db:77:5b:0d:ff:a7:71:7c:21:93:b4:e3:76:
+ 22:9a:0e:dc:f3:a3:1f:34:b0:10:f9:f1:4e:ef:b2:42:c8:ed:
+ e3:03:1f:2d:65:09:20:9e:66:a2:b6:05:df:39:63:e3:ce:ff:
+ 11:ed:f0:46:39:ca:2f:43:39:59:b2:1e:1b:ea:61:12:e9:02:
+ 1b:0c:1d:95
+-----BEGIN CERTIFICATE-----
+MIID9zCCAt+gAwIBAgIBCjANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwOTM0WhcNMDgwNzMxMTQwOTM0WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggFGMIIBQjAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAfBgNVHSMEGDAW
+gBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8EBAMCAQYwQAYIKwYBBQUH
+AQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4u
+bmV0L1JJUi8wHwYIKwYBBQUHAQgBAf8EEDAOoAwwCgIDAPwVAgMA/CAwfAYIKwYB
+BQUHAQcBAf8EbTBrMCYEAgABMCAwDgMFAMAAAgEDBQHAAAIgMA4DBQLAAAIsAwUA
+wAACZDBBBAIAAjA7MCYDEQIgAQ24AAAAAAAAAAAAAABEAxEAIAENuAAAAAAAAAAA
+AAABAAMRACABDbgAAAAAAAAAEAAAAEQwDQYJKoZIhvcNAQEFBQADggEBAGftoCm4
+Zn2mLE92Ut9FFW8jPZxXBRlXMfB2FzIXoKpVal3uUSsGbnW98mx5L1ru8C3oWdyj
+hl2ymOFZs+zJm+06sMdyVih3oUqnFwM36LHXGaOFXMhc+628agpl15DD+BKDU4nF
+enG0H2FpWiO1JFpvI52wrLyDAcHpQfieruArp3YDEIZ/dj099F8ELxvgNxRtl3xP
+ujSE123AkHxtlxHJqKqWf2X39LZXDxMqPmgjmLX2EVsatKsP23dbDf+ncXwhk7Tj
+diKaDtzzox80sBD58U7vskLI7eMDHy1lCSCeZqK2Bd85Y+PO/xHt8EY5yi9DOVmy
+HhvqYRLpAhsMHZU=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/0B.pem b/scripts/resource-cert-samples/RIR/0B.pem
new file mode 100644
index 00000000..0d858937
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/0B.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 11 (0xb)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:09:34 2007 GMT
+ Not After : Jul 31 14:09:34 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 98:f6:66:a8:a7:f1:b4:d9:11:3c:57:d8:d6:45:e4:73:8f:ca:
+ a5:e2:1d:d0:7b:46:a0:1a:c5:96:df:3c:f8:6b:1b:07:12:75:
+ 80:74:64:2e:e6:6b:cf:df:25:d5:c9:2f:2e:06:4e:ca:c2:bf:
+ ba:35:0c:ae:ed:27:85:70:8f:2b:7f:71:bf:68:c9:bf:ed:4f:
+ 19:7c:31:69:84:3e:47:1a:05:96:bd:06:16:a9:46:42:98:22:
+ 3c:24:7b:fb:1f:c0:a3:b6:ce:f1:e1:37:d2:d3:52:f9:bc:e4:
+ 6d:30:26:3e:79:70:71:62:85:ad:cf:93:15:97:19:2c:f3:86:
+ 5e:33:13:8e:3d:83:6b:af:5c:b4:2b:f0:9e:fe:cc:1c:8e:79:
+ b6:28:26:5d:9d:4b:84:4b:81:5b:fa:f7:bc:e6:cd:5f:dc:4a:
+ ae:61:eb:83:6d:d1:63:68:f5:de:7f:97:1c:80:9d:43:e1:6b:
+ 6b:6d:43:fb:7a:32:73:26:ab:bb:c2:cf:bd:ae:cf:0a:dd:5b:
+ ee:bc:76:ea:57:0f:ed:9e:43:8d:6a:eb:8a:39:13:1d:13:85:
+ 85:4e:80:73:57:d8:7d:4a:ef:75:3e:cd:70:cc:f6:b0:f6:f9:
+ 5c:9a:50:32:c4:d3:f3:76:07:54:98:54:fa:c1:6a:78:33:36:
+ c6:eb:60:87
+-----BEGIN CERTIFICATE-----
+MIIEETCCAvmgAwIBAgIBCzANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwOTM0WhcNMDgwNzMxMTQwOTM0WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBXzCCAVswDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEEAgACMDswJgMRAiABDbgA
+AAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEAIAENuAAAAAAAAAAQAAAA
+RDANBgkqhkiG9w0BAQUFAAOCAQEAmPZmqKfxtNkRPFfY1kXkc4/KpeId0HtGoBrF
+lt88+GsbBxJ1gHRkLuZrz98l1ckvLgZOysK/ujUMru0nhXCPK39xv2jJv+1PGXwx
+aYQ+RxoFlr0GFqlGQpgiPCR7+x/Ao7bO8eE30tNS+bzkbTAmPnlwcWKFrc+TFZcZ
+LPOGXjMTjj2Da69ctCvwnv7MHI55tigmXZ1LhEuBW/r3vObNX9xKrmHrg23RY2j1
+3n+XHICdQ+Fra21D+3oycyaru8LPva7PCt1b7rx26lcP7Z5DjWrrijkTHROFhU6A
+c1fYfUrvdT7NcMz2sPb5XJpQMsTT83YHVJhU+sFqeDM2xutghw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/0C.pem b/scripts/resource-cert-samples/RIR/0C.pem
new file mode 100644
index 00000000..0e7d6905
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/0C.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 12 (0xc)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:09:34 2007 GMT
+ Not After : Jul 31 14:09:34 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 4c:57:4d:fd:a9:e6:f1:92:4a:d1:28:22:c5:f2:97:5f:3b:fd:
+ e6:c1:bf:a6:8f:20:43:45:c3:b1:20:ea:d4:9f:2e:6f:2c:0a:
+ 0b:74:d8:87:1e:b3:15:47:1d:78:7d:61:65:ae:2e:38:6e:9b:
+ d6:68:d0:21:21:e5:6c:45:b7:18:95:e4:05:94:52:93:b4:5e:
+ 02:e8:c9:fc:4f:2d:f6:de:3a:9b:35:c2:9e:e5:98:c3:77:40:
+ 41:eb:ca:55:33:5f:74:9a:27:44:b3:37:63:55:ae:1c:f2:26:
+ d7:ae:33:73:53:8a:7d:9f:89:82:19:9e:e1:05:04:a6:6e:ce:
+ 74:b3:aa:46:63:58:79:bf:49:ca:f0:c4:ac:1d:0d:29:bf:e4:
+ 43:66:fc:26:a4:4f:13:55:4f:0b:ae:b1:67:8c:f2:2c:7e:32:
+ 21:80:a6:1d:03:44:9d:50:98:8a:62:3b:ff:88:64:c8:e8:29:
+ ff:8b:dd:53:84:c7:5f:1a:42:12:64:6b:9d:18:c9:1c:6f:aa:
+ 48:cd:68:e3:d9:ed:fd:d9:85:7c:fc:00:8a:5f:8b:27:eb:05:
+ b0:40:f3:4e:f4:d7:17:0c:98:7d:58:f2:8c:0f:d6:8c:70:30:
+ cd:37:2e:bf:00:78:91:a4:ed:4a:61:87:b6:88:bd:bb:22:52:
+ 0f:9f:e1:4d
+-----BEGIN CERTIFICATE-----
+MIID9jCCAt6gAwIBAgIBDDANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQwOTM0WhcNMDgwNzMxMTQwOTM0WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBRDCCAUAwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYEAgABMCAwDgMFAMAAAgED
+BQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEATFdN/anm
+8ZJK0SgixfKXXzv95sG/po8gQ0XDsSDq1J8ubywKC3TYhx6zFUcdeH1hZa4uOG6b
+1mjQISHlbEW3GJXkBZRSk7ReAujJ/E8t9t46mzXCnuWYw3dAQevKVTNfdJonRLM3
+Y1WuHPIm164zc1OKfZ+Jghme4QUEpm7OdLOqRmNYeb9JyvDErB0NKb/kQ2b8JqRP
+E1VPC66xZ4zyLH4yIYCmHQNEnVCYimI7/4hkyOgp/4vdU4THXxpCEmRrnRjJHG+q
+SM1o49nt/dmFfPwAil+LJ+sFsEDzTvTXFwyYfVjyjA/WjHAwzTcuvwB4kaTtSmGH
+toi9uyJSD5/hTQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/0D.pem b/scripts/resource-cert-samples/RIR/0D.pem
new file mode 100644
index 00000000..86579fdb
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/0D.pem
@@ -0,0 +1,104 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 13 (0xd)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:16 2007 GMT
+ Not After : Jul 31 14:48:16 2008 GMT
+ Subject: CN=TEST ENTITY RIR
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:ac:a7:26:c4:98:68:99:b6:f2:e7:c5:97:05:7e:
+ f9:d7:f2:ec:39:e6:2b:8e:c2:42:88:b9:8f:22:b6:
+ 3c:59:b0:0e:8a:1d:0e:f8:81:b1:c8:ff:4a:8a:1a:
+ 43:bc:78:91:3e:af:b2:b0:95:60:a9:3e:9d:c2:ff:
+ 99:8f:8f:b6:dc:d8:46:b7:86:35:a6:f6:42:05:c2:
+ c5:9b:84:15:e2:58:0f:70:9c:bc:53:d7:28:76:f8:
+ f2:14:79:22:bd:d6:8b:6c:0e:2b:02:e5:d8:f3:33:
+ fa:16:43:9b:80:87:f9:b2:45:ab:bd:7d:14:b2:24:
+ 2f:41:13:6f:45:c4:dc:f9:4d:7f:d8:d3:e1:aa:5c:
+ 52:9d:c9:7a:38:b7:b0:43:bd:b7:6a:37:43:ec:e7:
+ 34:c4:3b:4c:ca:cc:7b:1f:91:ef:ab:d4:35:76:42:
+ 82:d4:f5:79:e0:12:3c:24:92:2e:dc:a2:5c:83:f0:
+ 71:8a:26:96:30:d4:b8:96:4d:00:2c:1a:f0:0f:79:
+ 52:c7:27:73:54:77:c1:86:f9:86:61:ce:e0:69:a7:
+ a8:3d:77:39:e7:24:ee:41:8d:52:19:3b:57:8c:84:
+ cc:9a:d5:05:7c:e6:83:2c:e3:13:6d:66:1b:87:20:
+ 82:47:e1:05:26:f0:3b:29:69:6d:bc:af:48:91:c4:
+ 40:f1
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/RIR/
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533-64540
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 4c:d4:6d:b2:81:45:07:3e:7b:b4:8b:6c:db:42:2b:30:73:cd:
+ e7:07:39:c3:e6:13:4b:ac:21:33:13:11:00:1c:e6:d1:d4:cf:
+ 96:08:6e:86:7b:41:64:93:88:20:ac:04:81:65:1a:ae:a9:52:
+ be:36:c0:2a:6a:c9:3a:2e:86:83:a2:cc:3e:5d:12:60:49:fb:
+ 48:23:6c:d7:9f:98:fa:b4:b0:d5:48:01:29:74:ca:d1:74:3c:
+ a7:8c:bb:1c:b3:85:90:2a:99:52:9e:e2:31:9a:09:28:2d:d6:
+ ca:eb:f5:c6:da:6f:1b:89:83:eb:b7:d9:6d:56:71:e9:82:8e:
+ b7:84:e1:40:ab:87:15:d2:a6:df:30:11:e1:52:a0:a1:4b:ef:
+ 8e:3a:db:e1:d1:23:74:39:ff:48:d4:4d:2f:74:4e:e3:77:3c:
+ f7:1b:16:0b:b3:1a:c7:46:8b:7c:63:3d:9d:2b:75:82:b7:5c:
+ 9d:7b:df:f9:78:d2:e8:98:48:6c:54:5f:71:2a:a6:95:c6:56:
+ 3e:6c:e2:0c:20:a2:2c:22:f4:1d:3c:05:b2:31:bd:58:f3:23:
+ 60:dd:1d:d2:5e:ab:65:72:06:d2:da:c9:d4:c4:33:c2:b0:7d:
+ 37:13:66:25:b7:28:9b:a3:9c:92:c4:58:b8:02:a2:82:63:fc:
+ a8:93:65:69
+-----BEGIN CERTIFICATE-----
+MIIEMTCCAxmgAwIBAgIBDTANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE2WhcNMDgwNzMxMTQ0ODE2WjAaMRgw
+FgYDVQQDEw9URVNUIEVOVElUWSBSSVIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
+ggEKAoIBAQCspybEmGiZtvLnxZcFfvnX8uw55iuOwkKIuY8itjxZsA6KHQ74gbHI
+/0qKGkO8eJE+r7KwlWCpPp3C/5mPj7bc2Ea3hjWm9kIFwsWbhBXiWA9wnLxT1yh2
++PIUeSK91otsDisC5djzM/oWQ5uAh/myRau9fRSyJC9BE29FxNz5TX/Y0+GqXFKd
+yXo4t7BDvbdqN0Ps5zTEO0zKzHsfke+r1DV2QoLU9XngEjwkki7colyD8HGKJpYw
+1LiWTQAsGvAPeVLHJ3NUd8GG+YZhzuBpp6g9dznnJO5BjVIZO1eMhMya1QV85oMs
+4xNtZhuHIIJH4QUm8DspaW28r0iRxEDxAgMBAAGjggGAMIIBfDAPBgNVHRMBAf8E
+BTADAQH/MB0GA1UdDgQWBBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAfBgNVHSMEGDAW
+gBT7uKejNkgKoJ/wLtyLaLyzXEUl1zAOBgNVHQ8BAf8EBAMCAQYwQAYIKwYBBQUH
+AQsENDAyMDAGCCsGAQUFBzAFhiRyc3luYzovL3dvbWJhdHMtci11cy5oYWN0cm4u
+bmV0L1JJUi8wJgYIKwYBBQUHAQgBAf8EFzAVoBMwETAKAgMA/BUCAwD8HAIDAPwg
+MIGuBggrBgEFBQcBBwEB/wSBnjCBmzAyBAIAATAsAwQACgAAAwQACgMAMA4DBQDA
+AAIBAwUBwAACIDAOAwUCwAACLAMFAMAAAmQwZQQCAAIwXzAmAxECIAENuAAAAAAA
+AAAAAAAARAMRACABDbgAAAAAAAAAAAAAAQADEAAgAQ24AAAAAAAAAAAKAAADEAAg
+AQ24AAAAAAAAAAAKAwADEQAgAQ24AAAAAAAAABAAAABEMA0GCSqGSIb3DQEBBQUA
+A4IBAQBM1G2ygUUHPnu0i2zbQiswc83nBznD5hNLrCEzExEAHObR1M+WCG6Ge0Fk
+k4ggrASBZRquqVK+NsAqask6LoaDosw+XRJgSftII2zXn5j6tLDVSAEpdMrRdDyn
+jLscs4WQKplSnuIxmgkoLdbK6/XG2m8biYPrt9ltVnHpgo63hOFAq4cV0qbfMBHh
+UqChS++OOtvh0SN0Of9I1E0vdE7jdzz3GxYLsxrHRot8Yz2dK3WCt1yde9/5eNLo
+mEhsVF9xKqaVxlY+bOIMIKIsIvQdPAWyMb1Y8yNg3R3SXqtlcgbS2snUxDPCsH03
+E2Yltyibo5ySxFi4AqKCY/yok2Vp
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/0E.pem b/scripts/resource-cert-samples/RIR/0E.pem
new file mode 100644
index 00000000..54acaf38
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/0E.pem
@@ -0,0 +1,101 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 14 (0xe)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY LIR3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:a3:21:57:61:64:af:11:18:d4:cb:de:a6:dc:ad:
+ d9:2c:0f:0f:58:9f:7e:c8:85:55:11:26:4c:7c:f0:
+ 6b:68:1a:9e:6a:0c:8f:e6:dc:3d:83:58:2a:cc:77:
+ ac:19:73:6f:5a:f3:6e:24:ac:cd:1a:dc:1d:0b:4c:
+ 44:f5:6d:8b:0a:17:3d:86:f9:e8:fe:e6:60:e5:9f:
+ 40:6a:e5:94:e8:9a:56:17:17:1c:ab:c1:8c:37:40:
+ 2b:55:bf:2c:5e:dc:8d:ca:25:7f:8a:5f:ee:fb:16:
+ 86:eb:e0:08:d3:26:e5:e3:70:c5:0c:6b:fb:1b:8f:
+ 6b:5c:f6:e2:4a:58:a5:35:01:ea:05:1b:3e:ce:84:
+ be:b5:3f:6d:18:16:4b:68:e5:79:4c:88:7d:b6:a5:
+ 65:a3:3a:c2:32:dc:ad:8f:8a:05:ee:f6:e9:7a:80:
+ da:12:a9:0f:5a:b5:d2:d3:31:ac:3e:d3:19:25:2d:
+ 28:de:79:6c:ce:fd:77:66:d5:e3:2f:a9:cb:f9:85:
+ 8c:20:bb:a2:86:23:f0:93:95:20:04:78:c7:c7:07:
+ a6:fe:f0:f4:45:bb:cf:78:2b:dd:ce:9c:08:a5:46:
+ 68:10:4c:d7:05:62:6c:86:5a:2d:7f:06:38:c2:4d:
+ bb:44:87:00:43:79:d2:8f:f3:6b:b2:f4:5c:1c:b9:
+ 68:01
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 98:BE:04:FF:80:D1:AB:95:39:AA:3D:F2:0E:67:7D:00:AD:A3:FD:C5
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR3/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64534-64540
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 10.0.0.0/24
+ 10.3.0.0/24
+ IPv6:
+ 2001:db8:0:0:0:0:a00::/120
+ 2001:db8:0:0:0:0:a03::/120
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 48:66:09:ae:e4:52:ea:33:07:a6:92:4f:41:9d:d9:74:ad:24:
+ 17:11:d6:85:88:f2:66:52:e5:61:0e:8e:78:db:56:fb:ab:c8:
+ 31:1b:d1:f2:ec:df:1d:87:80:21:d9:81:9e:c8:00:e8:37:d5:
+ c3:71:26:97:35:15:fe:99:60:41:be:9b:72:e9:91:c1:bf:c8:
+ e3:25:95:f3:95:2b:c4:50:49:8f:a7:2a:ec:9a:d9:f9:b6:27:
+ 77:42:38:aa:20:12:30:56:db:41:f0:c4:d7:75:5a:01:4b:ac:
+ 36:8e:4d:1f:55:fa:24:4e:04:f2:ac:de:9a:4c:3e:9e:a4:b0:
+ fa:84:a8:35:3f:dc:dd:db:2c:74:4e:20:84:a5:17:05:87:8a:
+ 55:ee:4c:ae:59:02:7c:e7:70:32:10:9e:6f:b3:52:ec:48:ff:
+ 47:77:bf:a1:69:f1:5c:55:94:d0:47:ab:3a:34:56:96:a4:64:
+ e9:31:c2:aa:34:d6:a2:51:b2:8c:55:68:8c:5e:7a:d1:8d:43:
+ 89:e8:3e:1b:63:e9:b1:0c:e1:8f:31:0d:2f:5f:dd:1e:e8:78:
+ 41:d4:49:39:ca:a2:73:1e:9a:6f:c0:07:72:99:9e:3c:0b:ee:
+ b9:0b:d8:52:35:4e:19:83:44:ed:d9:de:5a:6b:6d:38:63:4e:
+ 12:45:f0:45
+-----BEGIN CERTIFICATE-----
+MIIEFTCCAv2gAwIBAgIBDjANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAoyFXYWSvERjUy96m3K3ZLA8PWJ9+yIVVESZMfPBraBqeagyP5tw9
+g1gqzHesGXNvWvNuJKzNGtwdC0xE9W2LChc9hvno/uZg5Z9AauWU6JpWFxccq8GM
+N0ArVb8sXtyNyiV/il/u+xaG6+AI0ybl43DFDGv7G49rXPbiSlilNQHqBRs+zoS+
+tT9tGBZLaOV5TIh9tqVlozrCMtytj4oF7vbpeoDaEqkPWrXS0zGsPtMZJS0o3nls
+zv13ZtXjL6nL+YWMILuihiPwk5UgBHjHxwem/vD0RbvPeCvdzpwIpUZoEEzXBWJs
+hlotfwY4wk27RIcAQ3nSj/NrsvRcHLloAQIDAQABo4IBYzCCAV8wDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUmL4E/4DRq5U5qj3yDmd9AK2j/cUwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIzLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAhBggrBgEFBQcBCAEB/wQS
+MBCgDjAMMAoCAwD8FgIDAPwcMFEGCCsGAQUFBwEHAQH/BEIwQDASBAIAATAMAwQA
+CgAAAwQACgMAMCoEAgACMCQDEAAgAQ24AAAAAAAAAAAKAAADEAAgAQ24AAAAAAAA
+AAAKAwAwDQYJKoZIhvcNAQEFBQADggEBAEhmCa7kUuozB6aST0Gd2XStJBcR1oWI
+8mZS5WEOjnjbVvuryDEb0fLs3x2HgCHZgZ7IAOg31cNxJpc1Ff6ZYEG+m3LpkcG/
+yOMllfOVK8RQSY+nKuya2fm2J3dCOKogEjBW20HwxNd1WgFLrDaOTR9V+iROBPKs
+3ppMPp6ksPqEqDU/3N3bLHROIISlFwWHilXuTK5ZAnzncDIQnm+zUuxI/0d3v6Fp
+8VxVlNBHqzo0VpakZOkxwqo01qJRsoxVaIxeetGNQ4noPhtj6bEM4Y8xDS9f3R7o
+eEHUSTnKonMemm/AB3KZnjwL7rkL2FI1ThmDRO3Z3lprbThjThJF8EU=
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/0F.pem b/scripts/resource-cert-samples/RIR/0F.pem
new file mode 100644
index 00000000..1094cb06
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/0F.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 15 (0xf)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY LIR2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:f1:18:b6:79:0b:35:c5:83:64:48:83:31:03:9e:
+ e7:72:28:65:b1:ac:61:e1:77:2e:c0:4d:f0:b1:1c:
+ 61:d8:cc:5a:2d:c7:0b:9b:78:7a:3e:fd:37:ad:fa:
+ b0:73:0b:9c:fc:bb:6f:60:ea:38:ef:ae:d1:27:b8:
+ 81:59:0f:b3:e7:d0:67:b2:a2:f5:4f:e2:04:c6:cc:
+ 13:9f:33:28:35:96:7a:db:ce:ac:9d:d3:64:3d:b8:
+ 44:bc:cb:43:22:92:d6:3c:2e:bf:97:6e:39:6a:6e:
+ 68:93:5d:1c:a8:58:b7:a3:7a:26:44:fe:fe:30:ad:
+ e2:05:89:4c:c9:ef:2c:e0:4e:31:69:3f:dd:91:1c:
+ f0:b0:25:4c:3e:84:8a:ea:5e:03:b3:a8:cd:90:1a:
+ 1e:c8:e0:af:fe:11:ed:21:06:bd:3c:5e:08:a1:93:
+ e2:41:43:43:38:d3:21:b3:4c:fa:85:8b:43:57:60:
+ 5d:bb:a0:78:e5:33:47:a8:33:76:be:df:6e:63:61:
+ e3:31:8b:5d:8e:0c:c7:f5:c8:91:0c:be:57:c7:f2:
+ bc:be:0b:ba:7a:1f:f6:19:f1:eb:00:74:c1:12:c2:
+ dc:2b:2e:8d:f0:0a:ff:7f:e8:60:08:90:ba:51:fc:
+ d0:90:11:37:f3:9e:44:b6:64:43:69:5d:61:d3:e1:
+ 8d:77
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 03:7A:DF:0C:DF:DC:93:3D:F7:A5:CC:27:7B:DC:22:F6:E9:55:97:F0
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR2/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64544
+
+ sbgp-ipAddrBlock: critical
+ IPv6:
+ 2001:db8:0:0:0:0:0:44-2001:db8:0:0:0:0:0:100
+ 2001:db8:0:0:0:10:0:44/128
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 1b:9a:85:77:61:fe:eb:5a:f8:ef:ad:5d:4d:79:4b:09:b3:c9:
+ 3e:46:f2:cf:4f:0c:26:28:7c:ec:72:da:17:6e:a0:2a:f2:4b:
+ 0f:af:e6:2e:b5:d7:2d:03:ae:8c:13:65:ec:cb:c2:4a:02:8f:
+ 81:60:44:60:eb:d2:d2:22:12:63:04:8c:6d:56:5a:c2:b8:f6:
+ c8:f5:17:99:69:25:bd:3e:1d:2a:ef:ce:51:48:4a:67:d0:b4:
+ ee:64:99:35:42:10:26:88:ac:e0:26:c8:27:cc:89:30:40:18:
+ 72:9c:82:03:ea:62:9d:83:c9:ab:c8:32:0a:59:98:50:0c:50:
+ 23:5a:93:ff:43:ba:08:b3:7d:61:d5:ed:a4:42:f2:cf:ab:2e:
+ 62:6b:67:bd:06:74:2c:bc:b7:b1:7e:1b:f4:c9:e4:40:94:ec:
+ 14:55:04:54:ce:44:26:d0:93:e3:ff:e2:e2:a2:a4:3f:44:87:
+ 7a:c2:29:a3:48:5f:12:1d:e4:eb:18:b3:1f:30:f4:e6:d3:a7:
+ 5a:7c:73:da:0a:8f:1e:29:63:cb:b6:16:2e:fe:76:84:93:88:
+ a1:72:83:4d:3d:8d:16:ef:16:df:c7:c6:d7:67:00:68:ec:4d:
+ b8:ed:b8:ff:3e:bf:c9:d5:3a:34:cf:4c:c0:7b:6e:11:60:46:
+ 25:91:d8:ad
+-----BEGIN CERTIFICATE-----
+MIIEETCCAvmgAwIBAgIBDzANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEA8Ri2eQs1xYNkSIMxA57ncihlsaxh4XcuwE3wsRxh2MxaLccLm3h6
+Pv03rfqwcwuc/LtvYOo4767RJ7iBWQ+z59BnsqL1T+IExswTnzMoNZZ6286sndNk
+PbhEvMtDIpLWPC6/l245am5ok10cqFi3o3omRP7+MK3iBYlMye8s4E4xaT/dkRzw
+sCVMPoSK6l4Ds6jNkBoeyOCv/hHtIQa9PF4IoZPiQUNDONMhs0z6hYtDV2Bdu6B4
+5TNHqDN2vt9uY2HjMYtdjgzH9ciRDL5Xx/K8vgu6eh/2GfHrAHTBEsLcKy6N8Ar/
+f+hgCJC6UfzQkBE3855EtmRDaV1h0+GNdwIDAQABo4IBXzCCAVswDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUA3rfDN/ckz33pcwne9wi9ulVl/AwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIyLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/CAwVAYIKwYBBQUHAQcBAf8ERTBDMEEEAgACMDswJgMRAiABDbgA
+AAAAAAAAAAAAAEQDEQAgAQ24AAAAAAAAAAAAAAEAAxEAIAENuAAAAAAAAAAQAAAA
+RDANBgkqhkiG9w0BAQUFAAOCAQEAG5qFd2H+61r4761dTXlLCbPJPkbyz08MJih8
+7HLaF26gKvJLD6/mLrXXLQOujBNl7MvCSgKPgWBEYOvS0iISYwSMbVZawrj2yPUX
+mWklvT4dKu/OUUhKZ9C07mSZNUIQJois4CbIJ8yJMEAYcpyCA+pinYPJq8gyClmY
+UAxQI1qT/0O6CLN9YdXtpELyz6suYmtnvQZ0LLy3sX4b9MnkQJTsFFUEVM5EJtCT
+4//i4qKkP0SHesIpo0hfEh3k6xizHzD05tOnWnxz2gqPHiljy7YWLv52hJOIoXKD
+TT2NFu8W38fG12cAaOxNuO24/z6/ydU6NM9MwHtuEWBGJZHYrQ==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/10.pem b/scripts/resource-cert-samples/RIR/10.pem
new file mode 100644
index 00000000..64f73b83
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/10.pem
@@ -0,0 +1,98 @@
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number: 16 (0x10)
+ Signature Algorithm: sha1WithRSAEncryption
+ Issuer: CN=TEST ENTITY RIR
+ Validity
+ Not Before: Aug 1 14:48:18 2007 GMT
+ Not After : Jul 31 14:48:18 2008 GMT
+ Subject: CN=TEST ENTITY LIR1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public Key: (2048 bit)
+ Modulus (2048 bit):
+ 00:af:5d:1c:f9:d9:bb:d5:01:e1:5b:36:cc:51:f6:
+ fd:86:57:60:aa:9e:c7:ec:4e:05:af:fb:51:5c:7a:
+ c2:58:c4:a8:57:ae:14:62:e9:bc:b6:72:7d:cf:49:
+ c8:4a:40:82:4a:f4:3e:30:b5:94:25:9e:6c:78:81:
+ 57:43:d6:85:02:8d:d1:9c:b5:d7:34:2f:e2:a9:7d:
+ 18:27:b5:47:9a:42:16:c8:90:7f:96:2c:dd:b8:98:
+ 17:1f:77:62:4a:08:00:2d:e0:73:0c:39:37:ba:0f:
+ a7:59:59:4c:7c:cd:e2:5c:d7:98:36:10:6c:88:3e:
+ 45:99:a6:88:2f:f6:7f:31:49:ba:42:2b:13:79:c2:
+ b2:f1:09:d9:ad:37:a4:41:b6:6d:46:a1:18:05:a0:
+ 53:07:8e:e0:98:b2:d1:fd:67:68:77:64:d5:f3:fe:
+ 1d:22:36:9e:26:5a:1a:aa:18:94:c3:2c:7e:9a:af:
+ be:2c:9d:5e:75:2c:49:d6:37:2b:06:1f:cc:63:97:
+ 7e:ee:2c:5f:67:af:4d:62:3e:7a:1f:0c:e1:1e:02:
+ f2:d2:06:75:ae:3f:11:bc:8e:0f:13:64:38:14:36:
+ 1d:5d:02:ec:af:65:d5:b9:68:f4:22:66:2b:ef:47:
+ 5b:ad:3b:f2:af:b6:71:0c:94:56:8a:7c:01:36:f0:
+ 3a:3f
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 8A:94:17:F9:53:F2:5B:94:54:56:DF:76:51:13:29:F6:71:19:A8:B3
+ X509v3 Authority Key Identifier:
+ keyid:FB:B8:A7:A3:36:48:0A:A0:9F:F0:2E:DC:8B:68:BC:B3:5C:45:25:D7
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Subject Information Access:
+ 1.3.6.1.5.5.7.48.5 - URI:rsync://wombats-r-us.hactrn.net/LIR1/
+
+ Authority Information Access:
+ CA Issuers - URI:rsync://wombats-r-us.hactrn.net/RIR.cer
+
+ sbgp-autonomousSysNum: critical
+ Autonomous System Numbers:
+ 64533
+
+ sbgp-ipAddrBlock: critical
+ IPv4:
+ 192.0.2.1-192.0.2.33
+ 192.0.2.44-192.0.2.100
+
+ Signature Algorithm: sha1WithRSAEncryption
+ 72:7d:dd:a4:60:23:71:e4:99:28:0b:9a:ba:5c:d3:97:4b:72:
+ eb:89:81:3c:11:85:8c:25:ed:79:b2:50:a5:e8:ae:0e:37:74:
+ f9:2c:a1:be:96:83:35:40:0d:36:f9:32:16:74:25:9c:f7:0f:
+ cd:46:47:8e:b9:cd:ac:0c:7e:d3:ac:84:5e:f6:31:f4:a9:f2:
+ 05:cd:82:d7:e0:d7:3b:24:9b:c7:15:d1:db:9d:c2:1d:92:f7:
+ 19:a9:b8:a1:67:0a:fb:3d:23:3a:05:83:29:05:50:e3:00:27:
+ a9:80:fe:bb:51:f1:3e:3b:0c:98:ae:f1:ee:d1:13:72:46:64:
+ 8f:4b:32:4e:cf:64:cf:1a:a5:b1:34:a6:f0:5f:18:f8:44:bb:
+ 13:ea:8d:5f:24:7d:3b:15:60:8e:be:f4:bd:d8:04:a7:d0:10:
+ 7e:d3:10:67:bf:35:49:c9:56:cf:b7:8b:7b:9b:17:0b:54:ee:
+ 21:cb:75:b0:3e:8d:b2:c1:c6:7c:26:b1:7c:58:a9:4a:31:24:
+ cd:e5:3f:a5:9a:1d:7d:11:14:41:2a:e5:55:b6:db:f4:75:34:
+ 37:9f:5e:1d:f1:86:2a:f6:74:be:88:e1:b9:63:ce:ad:5c:e9:
+ 3c:91:8a:4c:8d:b4:69:03:e7:f9:52:79:28:7d:cd:7f:52:02:
+ 49:ae:d5:c7
+-----BEGIN CERTIFICATE-----
+MIID9jCCAt6gAwIBAgIBEDANBgkqhkiG9w0BAQUFADAaMRgwFgYDVQQDEw9URVNU
+IEVOVElUWSBSSVIwHhcNMDcwODAxMTQ0ODE4WhcNMDgwNzMxMTQ0ODE4WjAbMRkw
+FwYDVQQDExBURVNUIEVOVElUWSBMSVIxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
+MIIBCgKCAQEAr10c+dm71QHhWzbMUfb9hldgqp7H7E4Fr/tRXHrCWMSoV64UYum8
+tnJ9z0nISkCCSvQ+MLWUJZ5seIFXQ9aFAo3RnLXXNC/iqX0YJ7VHmkIWyJB/lizd
+uJgXH3diSggALeBzDDk3ug+nWVlMfM3iXNeYNhBsiD5FmaaIL/Z/MUm6QisTecKy
+8QnZrTekQbZtRqEYBaBTB47gmLLR/Wdod2TV8/4dIjaeJloaqhiUwyx+mq++LJ1e
+dSxJ1jcrBh/MY5d+7ixfZ69NYj56HwzhHgLy0gZ1rj8RvI4PE2Q4FDYdXQLsr2XV
+uWj0ImYr70dbrTvyr7ZxDJRWinwBNvA6PwIDAQABo4IBRDCCAUAwDwYDVR0TAQH/
+BAUwAwEB/zAdBgNVHQ4EFgQUipQX+VPyW5RUVt92URMp9nEZqLMwHwYDVR0jBBgw
+FoAU+7inozZICqCf8C7ci2i8s1xFJdcwDgYDVR0PAQH/BAQDAgEGMEEGCCsGAQUF
+BwELBDUwMzAxBggrBgEFBQcwBYYlcnN5bmM6Ly93b21iYXRzLXItdXMuaGFjdHJu
+Lm5ldC9MSVIxLzBDBggrBgEFBQcBAQQ3MDUwMwYIKwYBBQUHMAKGJ3JzeW5jOi8v
+d29tYmF0cy1yLXVzLmhhY3Rybi5uZXQvUklSLmNlcjAaBggrBgEFBQcBCAEB/wQL
+MAmgBzAFAgMA/BUwOQYIKwYBBQUHAQcBAf8EKjAoMCYEAgABMCAwDgMFAMAAAgED
+BQHAAAIgMA4DBQLAAAIsAwUAwAACZDANBgkqhkiG9w0BAQUFAAOCAQEAcn3dpGAj
+ceSZKAuaulzTl0ty64mBPBGFjCXtebJQpeiuDjd0+SyhvpaDNUANNvkyFnQlnPcP
+zUZHjrnNrAx+06yEXvYx9KnyBc2C1+DXOySbxxXR253CHZL3Gam4oWcK+z0jOgWD
+KQVQ4wAnqYD+u1HxPjsMmK7x7tETckZkj0syTs9kzxqlsTSm8F8Y+ES7E+qNXyR9
+OxVgjr70vdgEp9AQftMQZ781SclWz7eLe5sXC1TuIct1sD6NssHGfCaxfFipSjEk
+zeU/pZodfREUQSrlVbbb9HU0N59eHfGGKvZ0vojhuWPOrVzpPJGKTI20aQPn+VJ5
+KH3Nf1ICSa7Vxw==
+-----END CERTIFICATE-----
diff --git a/scripts/resource-cert-samples/RIR/index b/scripts/resource-cert-samples/RIR/index
new file mode 100644
index 00000000..754becc3
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/index
@@ -0,0 +1,16 @@
+V 080731054523Z 01 unknown /CN=TEST ENTITY RIR
+V 080731054524Z 02 unknown /CN=TEST ENTITY LIR2
+V 080731054525Z 03 unknown /CN=TEST ENTITY LIR1
+V 080731140529Z 04 unknown /CN=TEST ENTITY RIR
+V 080731140529Z 05 unknown /CN=TEST ENTITY LIR2
+V 080731140529Z 06 unknown /CN=TEST ENTITY LIR1
+V 080731140829Z 07 unknown /CN=TEST ENTITY RIR
+V 080731140829Z 08 unknown /CN=TEST ENTITY LIR2
+V 080731140829Z 09 unknown /CN=TEST ENTITY LIR1
+V 080731140934Z 0A unknown /CN=TEST ENTITY RIR
+V 080731140934Z 0B unknown /CN=TEST ENTITY LIR2
+V 080731140934Z 0C unknown /CN=TEST ENTITY LIR1
+V 080731144816Z 0D unknown /CN=TEST ENTITY RIR
+V 080731144818Z 0E unknown /CN=TEST ENTITY LIR3
+V 080731144818Z 0F unknown /CN=TEST ENTITY LIR2
+V 080731144818Z 10 unknown /CN=TEST ENTITY LIR1
diff --git a/scripts/resource-cert-samples/RIR/index.attr b/scripts/resource-cert-samples/RIR/index.attr
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/index.attr
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/RIR/index.attr.old b/scripts/resource-cert-samples/RIR/index.attr.old
new file mode 100644
index 00000000..3a7e39e6
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/index.attr.old
@@ -0,0 +1 @@
+unique_subject = no
diff --git a/scripts/resource-cert-samples/RIR/index.old b/scripts/resource-cert-samples/RIR/index.old
new file mode 100644
index 00000000..6ed26aac
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/index.old
@@ -0,0 +1,15 @@
+V 080731054523Z 01 unknown /CN=TEST ENTITY RIR
+V 080731054524Z 02 unknown /CN=TEST ENTITY LIR2
+V 080731054525Z 03 unknown /CN=TEST ENTITY LIR1
+V 080731140529Z 04 unknown /CN=TEST ENTITY RIR
+V 080731140529Z 05 unknown /CN=TEST ENTITY LIR2
+V 080731140529Z 06 unknown /CN=TEST ENTITY LIR1
+V 080731140829Z 07 unknown /CN=TEST ENTITY RIR
+V 080731140829Z 08 unknown /CN=TEST ENTITY LIR2
+V 080731140829Z 09 unknown /CN=TEST ENTITY LIR1
+V 080731140934Z 0A unknown /CN=TEST ENTITY RIR
+V 080731140934Z 0B unknown /CN=TEST ENTITY LIR2
+V 080731140934Z 0C unknown /CN=TEST ENTITY LIR1
+V 080731144816Z 0D unknown /CN=TEST ENTITY RIR
+V 080731144818Z 0E unknown /CN=TEST ENTITY LIR3
+V 080731144818Z 0F unknown /CN=TEST ENTITY LIR2
diff --git a/scripts/resource-cert-samples/RIR/serial b/scripts/resource-cert-samples/RIR/serial
new file mode 100644
index 00000000..b4de3947
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/serial
@@ -0,0 +1 @@
+11
diff --git a/scripts/resource-cert-samples/RIR/serial.old b/scripts/resource-cert-samples/RIR/serial.old
new file mode 100644
index 00000000..f599e28b
--- /dev/null
+++ b/scripts/resource-cert-samples/RIR/serial.old
@@ -0,0 +1 @@
+10