git: 8ed0ecf8024d - main - caroot: regenerate the root bundle with OpenSSL 3

From: Kyle Evans <kevans_at_FreeBSD.org>
Date: Sat, 26 Aug 2023 01:17:12 UTC
The branch main has been updated by kevans:

URL: https://cgit.FreeBSD.org/src/commit/?id=8ed0ecf8024d10e9cd21f5880723a6cec4fd4ae6

commit 8ed0ecf8024d10e9cd21f5880723a6cec4fd4ae6
Author:     Kyle Evans <kevans@FreeBSD.org>
AuthorDate: 2023-08-26 01:15:39 +0000
Commit:     Kyle Evans <kevans@FreeBSD.org>
CommitDate: 2023-08-26 01:16:36 +0000

    caroot: regenerate the root bundle with OpenSSL 3
    
    No functional change intended.
---
 secure/caroot/trusted/ACCVRAIZ1.pem                | 68 ++++++++++------------
 secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem         | 62 ++++++++++----------
 .../AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem        | 13 +++--
 .../caroot/trusted/ANF_Secure_Server_Root_CA.pem   | 64 ++++++++++----------
 .../trusted/Actalis_Authentication_Root_CA.pem     | 64 ++++++++++----------
 secure/caroot/trusted/AffirmTrust_Commercial.pem   | 33 ++++++-----
 secure/caroot/trusted/AffirmTrust_Networking.pem   | 33 ++++++-----
 secure/caroot/trusted/AffirmTrust_Premium.pem      | 61 +++++++++----------
 secure/caroot/trusted/AffirmTrust_Premium_ECC.pem  | 13 +++--
 secure/caroot/trusted/Amazon_Root_CA_1.pem         | 33 ++++++-----
 secure/caroot/trusted/Amazon_Root_CA_2.pem         | 61 +++++++++----------
 secure/caroot/trusted/Amazon_Root_CA_3.pem         |  9 +--
 secure/caroot/trusted/Amazon_Root_CA_4.pem         | 13 +++--
 secure/caroot/trusted/Atos_TrustedRoot_2011.pem    | 37 ++++++------
 .../Atos_TrustedRoot_Root_CA_ECC_TLS_2021.pem      | 13 +++--
 .../Atos_TrustedRoot_Root_CA_RSA_TLS_2021.pem      | 61 +++++++++----------
 ...ertificacion_Firmaprofesional_CIF_A62634068.pem | 62 ++++++++++----------
 secure/caroot/trusted/BJCA_Global_Root_CA1.pem     | 61 +++++++++----------
 secure/caroot/trusted/BJCA_Global_Root_CA2.pem     | 13 +++--
 .../caroot/trusted/Baltimore_CyberTrust_Root.pem   | 33 ++++++-----
 secure/caroot/trusted/Buypass_Class_2_Root_CA.pem  | 61 +++++++++----------
 secure/caroot/trusted/Buypass_Class_3_Root_CA.pem  | 61 +++++++++----------
 secure/caroot/trusted/CA_Disig_Root_R2.pem         | 61 +++++++++----------
 secure/caroot/trusted/CFCA_EV_ROOT.pem             | 64 ++++++++++----------
 .../trusted/COMODO_Certification_Authority.pem     | 35 ++++++-----
 .../trusted/COMODO_ECC_Certification_Authority.pem | 13 +++--
 .../trusted/COMODO_RSA_Certification_Authority.pem | 61 +++++++++----------
 secure/caroot/trusted/Certainly_Root_E1.pem        | 13 +++--
 secure/caroot/trusted/Certainly_Root_R1.pem        | 61 +++++++++----------
 secure/caroot/trusted/Certigna.pem                 | 34 +++++------
 secure/caroot/trusted/Certigna_Root_CA.pem         | 68 ++++++++++------------
 secure/caroot/trusted/Certum_EC-384_CA.pem         | 13 +++--
 .../caroot/trusted/Certum_Trusted_Network_CA.pem   | 33 ++++++-----
 .../caroot/trusted/Certum_Trusted_Network_CA_2.pem | 61 +++++++++----------
 secure/caroot/trusted/Certum_Trusted_Root_CA.pem   | 61 +++++++++----------
 secure/caroot/trusted/Comodo_AAA_Services_root.pem | 36 ++++++------
 .../caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem   | 16 +++--
 .../caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem   | 16 +++--
 .../trusted/D-TRUST_Root_Class_3_CA_2_2009.pem     | 36 ++++++------
 .../trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem  | 36 ++++++------
 .../caroot/trusted/DigiCert_Assured_ID_Root_CA.pem | 36 ++++++------
 .../caroot/trusted/DigiCert_Assured_ID_Root_G2.pem | 33 ++++++-----
 .../caroot/trusted/DigiCert_Assured_ID_Root_G3.pem | 13 +++--
 secure/caroot/trusted/DigiCert_Global_Root_CA.pem  | 36 ++++++------
 secure/caroot/trusted/DigiCert_Global_Root_G2.pem  | 33 ++++++-----
 secure/caroot/trusted/DigiCert_Global_Root_G3.pem  | 13 +++--
 .../trusted/DigiCert_High_Assurance_EV_Root_CA.pem | 36 ++++++------
 .../trusted/DigiCert_TLS_ECC_P384_Root_G5.pem      | 13 +++--
 .../trusted/DigiCert_TLS_RSA4096_Root_G5.pem       | 61 +++++++++----------
 secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem | 61 +++++++++----------
 .../Entrust_Root_Certification_Authority.pem       | 36 ++++++------
 .../Entrust_Root_Certification_Authority_-_EC1.pem | 13 +++--
 .../Entrust_Root_Certification_Authority_-_G2.pem  | 33 ++++++-----
 .../Entrust_Root_Certification_Authority_-_G4.pem  | 61 +++++++++----------
 .../Entrust_net_Premium_2048_Secure_Server_CA.pem  | 33 ++++++-----
 secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem   | 61 +++++++++----------
 secure/caroot/trusted/GLOBALTRUST_2020.pem         | 64 ++++++++++----------
 secure/caroot/trusted/GTS_Root_R1.pem              | 61 +++++++++----------
 secure/caroot/trusted/GTS_Root_R2.pem              | 61 +++++++++----------
 secure/caroot/trusted/GTS_Root_R3.pem              | 13 +++--
 secure/caroot/trusted/GTS_Root_R4.pem              | 13 +++--
 .../caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem |  9 +--
 .../caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem | 13 +++--
 secure/caroot/trusted/GlobalSign_Root_CA.pem       | 33 ++++++-----
 secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem  | 33 ++++++-----
 secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem  | 64 ++++++++++----------
 secure/caroot/trusted/GlobalSign_Root_E46.pem      | 13 +++--
 secure/caroot/trusted/GlobalSign_Root_R46.pem      | 61 +++++++++----------
 secure/caroot/trusted/Go_Daddy_Class_2_CA.pem      | 34 +++++------
 .../Go_Daddy_Root_Certificate_Authority_-_G2.pem   | 33 ++++++-----
 .../caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem | 13 +++--
 .../caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem | 61 +++++++++----------
 ...c_and_Research_Institutions_ECC_RootCA_2015.pem | 13 +++--
 ...demic_and_Research_Institutions_RootCA_2015.pem | 61 +++++++++----------
 secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem       | 61 +++++++++----------
 secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem  | 64 ++++++++++----------
 secure/caroot/trusted/ISRG_Root_X1.pem             | 61 +++++++++----------
 secure/caroot/trusted/ISRG_Root_X2.pem             | 13 +++--
 .../trusted/IdenTrust_Commercial_Root_CA_1.pem     | 61 +++++++++----------
 .../trusted/IdenTrust_Public_Sector_Root_CA_1.pem  | 61 +++++++++----------
 secure/caroot/trusted/Izenpe_com.pem               | 61 +++++++++----------
 .../trusted/Microsec_e-Szigno_Root_CA_2009.pem     | 36 ++++++------
 ...crosoft_ECC_Root_Certificate_Authority_2017.pem | 13 +++--
 ...crosoft_RSA_Root_Certificate_Authority_2017.pem | 61 +++++++++----------
 .../NAVER_Global_Root_Certification_Authority.pem  | 61 +++++++++----------
 ...etLock_Arany__Class_Gold__F__tan__s__tv__ny.pem | 33 ++++++-----
 .../trusted/OISTE_WISeKey_Global_Root_GB_CA.pem    | 33 ++++++-----
 .../trusted/OISTE_WISeKey_Global_Root_GC_CA.pem    | 13 +++--
 secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem    | 61 +++++++++----------
 secure/caroot/trusted/QuoVadis_Root_CA_2.pem       | 62 ++++++++++----------
 secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem    | 61 +++++++++----------
 secure/caroot/trusted/QuoVadis_Root_CA_3.pem       | 63 ++++++++++----------
 secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem    | 61 +++++++++----------
 ...SSL_com_EV_Root_Certification_Authority_ECC.pem | 16 ++---
 ..._com_EV_Root_Certification_Authority_RSA_R2.pem | 64 ++++++++++----------
 .../SSL_com_Root_Certification_Authority_ECC.pem   | 16 ++---
 .../SSL_com_Root_Certification_Authority_RSA.pem   | 64 ++++++++++----------
 .../trusted/SSL_com_TLS_ECC_Root_CA_2022.pem       | 16 ++---
 .../trusted/SSL_com_TLS_RSA_Root_CA_2022.pem       | 64 ++++++++++----------
 secure/caroot/trusted/SZAFIR_ROOT_CA2.pem          | 33 ++++++-----
 ...ctigo_Public_Server_Authentication_Root_E46.pem | 13 +++--
 ...ctigo_Public_Server_Authentication_Root_R46.pem | 61 +++++++++----------
 secure/caroot/trusted/SecureSign_RootCA11.pem      | 33 ++++++-----
 secure/caroot/trusted/SecureTrust_CA.pem           | 35 ++++++-----
 secure/caroot/trusted/Secure_Global_CA.pem         | 35 ++++++-----
 .../trusted/Security_Communication_ECC_RootCA1.pem | 13 +++--
 .../trusted/Security_Communication_RootCA2.pem     | 33 ++++++-----
 .../trusted/Security_Communication_RootCA3.pem     | 61 +++++++++----------
 .../trusted/Security_Communication_Root_CA.pem     | 33 ++++++-----
 secure/caroot/trusted/Starfield_Class_2_CA.pem     | 34 +++++------
 .../Starfield_Root_Certificate_Authority_-_G2.pem  | 33 ++++++-----
 ...ld_Services_Root_Certificate_Authority_-_G2.pem | 33 ++++++-----
 secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem   | 65 ++++++++++-----------
 secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem | 65 ++++++++++-----------
 .../trusted/T-TeleSec_GlobalRoot_Class_2.pem       | 33 ++++++-----
 .../trusted/T-TeleSec_GlobalRoot_Class_3.pem       | 33 ++++++-----
 ...BITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem | 33 ++++++-----
 secure/caroot/trusted/TWCA_Global_Root_CA.pem      | 61 +++++++++----------
 .../trusted/TWCA_Root_Certification_Authority.pem  | 33 ++++++-----
 secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem   | 61 +++++++++----------
 secure/caroot/trusted/Telia_Root_CA_v2.pem         | 64 ++++++++++----------
 .../Trustwave_Global_Certification_Authority.pem   | 61 +++++++++----------
 ...ave_Global_ECC_P256_Certification_Authority.pem |  9 +--
 ...ave_Global_ECC_P384_Certification_Authority.pem | 13 +++--
 secure/caroot/trusted/TunTrust_Root_CA.pem         | 64 ++++++++++----------
 .../trusted/UCA_Extended_Validation_Root.pem       | 61 +++++++++----------
 secure/caroot/trusted/UCA_Global_G2_Root.pem       | 61 +++++++++----------
 .../USERTrust_ECC_Certification_Authority.pem      | 13 +++--
 .../USERTrust_RSA_Certification_Authority.pem      | 61 +++++++++----------
 secure/caroot/trusted/XRamp_Global_CA_Root.pem     | 35 ++++++-----
 secure/caroot/trusted/certSIGN_ROOT_CA.pem         | 33 ++++++-----
 secure/caroot/trusted/certSIGN_Root_CA_G2.pem      | 61 +++++++++----------
 secure/caroot/trusted/e-Szigno_Root_CA_2017.pem    | 12 ++--
 .../trusted/ePKI_Root_Certification_Authority.pem  | 61 +++++++++----------
 secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem  | 13 +++--
 secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem  | 13 +++--
 secure/caroot/trusted/emSign_Root_CA_-_C1.pem      | 33 ++++++-----
 secure/caroot/trusted/emSign_Root_CA_-_G1.pem      | 33 ++++++-----
 secure/caroot/trusted/vTrus_ECC_Root_CA.pem        | 13 +++--
 secure/caroot/trusted/vTrus_Root_CA.pem            | 61 +++++++++----------
 secure/caroot/untrusted/AddTrust_External_Root.pem | 34 +++++------
 .../untrusted/AddTrust_Low-Value_Services_Root.pem | 34 +++++------
 .../Camerfirma_Chambers_of_Commerce_Root.pem       | 36 ++++++------
 .../Camerfirma_Global_Chambersign_Root.pem         | 36 ++++++------
 secure/caroot/untrusted/Certum_Root_CA.pem         | 33 ++++++-----
 .../untrusted/Chambers_of_Commerce_Root_-_2008.pem | 65 ++++++++++-----------
 secure/caroot/untrusted/Cybertrust_Global_Root.pem | 38 ++++++------
 secure/caroot/untrusted/D-TRUST_Root_CA_3_2013.pem | 36 ++++++------
 secure/caroot/untrusted/DST_Root_CA_X3.pem         | 33 ++++++-----
 .../untrusted/E-Tugra_Certification_Authority.pem  | 64 ++++++++++----------
 .../untrusted/E-Tugra_Global_Root_CA_ECC_v3.pem    | 16 ++---
 .../untrusted/E-Tugra_Global_Root_CA_RSA_v3.pem    | 64 ++++++++++----------
 secure/caroot/untrusted/EC-ACC.pem                 | 34 +++++------
 .../untrusted/EE_Certification_Centre_Root_CA.pem  | 33 ++++++-----
 secure/caroot/untrusted/GeoTrust_Global_CA.pem     | 36 ++++++------
 .../GeoTrust_Primary_Certification_Authority.pem   | 33 ++++++-----
 ...oTrust_Primary_Certification_Authority_-_G2.pem | 13 +++--
 ...oTrust_Primary_Certification_Authority_-_G3.pem | 33 ++++++-----
 secure/caroot/untrusted/GeoTrust_Universal_CA.pem  | 64 ++++++++++----------
 .../caroot/untrusted/GeoTrust_Universal_CA_2.pem   | 64 ++++++++++----------
 .../caroot/untrusted/GlobalSign_Root_CA_-_R2.pem   | 38 ++++++------
 .../untrusted/Global_Chambersign_Root_-_2008.pem   | 65 ++++++++++-----------
 ...demic_and_Research_Institutions_RootCA_2011.pem | 34 +++++------
 .../caroot/untrusted/Hongkong_Post_Root_CA_1.pem   | 33 ++++++-----
 secure/caroot/untrusted/LuxTrust_Global_Root_2.pem | 65 ++++++++++-----------
 .../Network_Solutions_Certificate_Authority.pem    | 35 ++++++-----
 .../untrusted/OISTE_WISeKey_Global_Root_GA_CA.pem  | 33 ++++++-----
 secure/caroot/untrusted/QuoVadis_Root_CA.pem       | 36 ++++++------
 secure/caroot/untrusted/Sonera_Class_2_Root_CA.pem | 33 ++++++-----
 .../untrusted/Staat_der_Nederlanden_EV_Root_CA.pem | 61 +++++++++----------
 .../Staat_der_Nederlanden_Root_CA_-_G2.pem         | 62 ++++++++++----------
 .../Staat_der_Nederlanden_Root_CA_-_G3.pem         | 61 +++++++++----------
 .../untrusted/SwissSign_Platinum_CA_-_G2.pem       | 65 ++++++++++-----------
 ...Public_Primary_Certification_Authority_-_G4.pem | 13 +++--
 ...Public_Primary_Certification_Authority_-_G6.pem | 33 ++++++-----
 ...Public_Primary_Certification_Authority_-_G4.pem | 13 +++--
 ...Public_Primary_Certification_Authority_-_G6.pem | 33 ++++++-----
 secure/caroot/untrusted/Taiwan_GRCA.pem            | 61 +++++++++----------
 secure/caroot/untrusted/TrustCor_ECA-1.pem         | 36 ++++++------
 secure/caroot/untrusted/TrustCor_RootCert_CA-1.pem | 36 ++++++------
 secure/caroot/untrusted/TrustCor_RootCert_CA-2.pem | 64 ++++++++++----------
 secure/caroot/untrusted/Trustis_FPS_Root_CA.pem    | 36 ++++++------
 ...Public_Primary_Certification_Authority_-_G4.pem | 13 +++--
 ...Public_Primary_Certification_Authority_-_G5.pem | 33 ++++++-----
 ...Sign_Universal_Root_Certification_Authority.pem | 33 ++++++-----
 ...Public_Primary_Certification_Authority_-_G3.pem | 33 ++++++-----
 ...Public_Primary_Certification_Authority_-_G3.pem | 33 ++++++-----
 ...Public_Primary_Certification_Authority_-_G3.pem | 33 ++++++-----
 secure/caroot/untrusted/thawte_Primary_Root_CA.pem | 33 ++++++-----
 .../untrusted/thawte_Primary_Root_CA_-_G2.pem      | 13 +++--
 .../untrusted/thawte_Primary_Root_CA_-_G3.pem      | 33 ++++++-----
 191 files changed, 3872 insertions(+), 3791 deletions(-)

diff --git a/secure/caroot/trusted/ACCVRAIZ1.pem b/secure/caroot/trusted/ACCVRAIZ1.pem
index dbe720481fe4..9c48cb1f7155 100644
--- a/secure/caroot/trusted/ACCVRAIZ1.pem
+++ b/secure/caroot/trusted/ACCVRAIZ1.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: CN = ACCVRAIZ1, OU = PKIACCV, O = ACCV, C = ES
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:9b:a9:ab:bf:61:4a:97:af:2f:97:66:9a:74:5f:
                     d0:d9:96:fd:cf:e2:e4:66:ef:1f:1f:47:33:c2:44:
@@ -65,59 +65,55 @@ Certificate:
             Authority Information Access: 
                 CA Issuers - URI:http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt
                 OCSP - URI:http://ocsp.accv.es
-
             X509v3 Subject Key Identifier: 
                 D2:87:B4:E3:DF:37:27:93:55:F6:56:EA:81:E5:36:CC:8C:1E:3F:BD
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Authority Key Identifier: 
-                keyid:D2:87:B4:E3:DF:37:27:93:55:F6:56:EA:81:E5:36:CC:8C:1E:3F:BD
-
+                D2:87:B4:E3:DF:37:27:93:55:F6:56:EA:81:E5:36:CC:8C:1E:3F:BD
             X509v3 Certificate Policies: 
                 Policy: X509v3 Any Policy
                   User Notice:
                     Explicit Text: 
                   CPS: http://www.accv.es/legislacion_c.htm
-
             X509v3 CRL Distribution Points: 
-
                 Full Name:
                   URI:http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
-
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
             X509v3 Subject Alternative Name: 
                 email:accv@accv.es
     Signature Algorithm: sha1WithRSAEncryption
-         97:31:02:9f:e7:fd:43:67:48:44:14:e4:29:87:ed:4c:28:66:
-         d0:8f:35:da:4d:61:b7:4a:97:4d:b5:db:90:e0:05:2e:0e:c6:
-         79:d0:f2:97:69:0f:bd:04:47:d9:be:db:b5:29:da:9b:d9:ae:
-         a9:99:d5:d3:3c:30:93:f5:8d:a1:a8:fc:06:8d:44:f4:ca:16:
-         95:7c:33:dc:62:8b:a8:37:f8:27:d8:09:2d:1b:ef:c8:14:27:
-         20:a9:64:44:ff:2e:d6:75:aa:6c:4d:60:40:19:49:43:54:63:
-         da:e2:cc:ba:66:e5:4f:44:7a:5b:d9:6a:81:2b:40:d5:7f:f9:
-         01:27:58:2c:c8:ed:48:91:7c:3f:a6:00:cf:c4:29:73:11:36:
-         de:86:19:3e:9d:ee:19:8a:1b:d5:b0:ed:8e:3d:9c:2a:c0:0d:
-         d8:3d:66:e3:3c:0d:bd:d5:94:5c:e2:e2:a7:35:1b:04:00:f6:
-         3f:5a:8d:ea:43:bd:5f:89:1d:a9:c1:b0:cc:99:e2:4d:00:0a:
-         da:c9:27:5b:e7:13:90:5c:e4:f5:33:a2:55:6d:dc:e0:09:4d:
-         2f:b1:26:5b:27:75:00:09:c4:62:77:29:08:5f:9e:59:ac:b6:
-         7e:ad:9f:54:30:22:03:c1:1e:71:64:fe:f9:38:0a:96:18:dd:
-         02:14:ac:23:cb:06:1c:1e:a4:7d:8d:0d:de:27:41:e8:ad:da:
-         15:b7:b0:23:dd:2b:a8:d3:da:25:87:ed:e8:55:44:4d:88:f4:
-         36:7e:84:9a:78:ac:f7:0e:56:49:0e:d6:33:25:d6:84:50:42:
-         6c:20:12:1d:2a:d5:be:bc:f2:70:81:a4:70:60:be:05:b5:9b:
-         9e:04:44:be:61:23:ac:e9:a5:24:8c:11:80:94:5a:a2:a2:b9:
-         49:d2:c1:dc:d1:a7:ed:31:11:2c:9e:19:a6:ee:e1:55:e1:c0:
-         ea:cf:0d:84:e4:17:b7:a2:7c:a5:de:55:25:06:ee:cc:c0:87:
-         5c:40:da:cc:95:3f:55:e0:35:c7:b8:84:be:b4:5d:cd:7a:83:
-         01:72:ee:87:e6:5f:1d:ae:b5:85:c6:26:df:e6:c1:9a:e9:1e:
-         02:47:9f:2a:a8:6d:a9:5b:cf:ec:45:77:7f:98:27:9a:32:5d:
-         2a:e3:84:ee:c5:98:66:2f:96:20:1d:dd:d8:c3:27:d7:b0:f9:
-         fe:d9:7d:cd:d0:9f:8f:0b:14:58:51:9f:2f:8b:c3:38:2d:de:
-         e8:8f:d6:8d:87:a4:f5:56:43:16:99:2c:f4:a4:56:b4:34:b8:
-         61:37:c9:c2:58:80:1b:a0:97:a1:fc:59:8d:e9:11:f6:d1:0f:
-         4b:55:34:46:2a:8b:86:3b
+    Signature Value:
+        97:31:02:9f:e7:fd:43:67:48:44:14:e4:29:87:ed:4c:28:66:
+        d0:8f:35:da:4d:61:b7:4a:97:4d:b5:db:90:e0:05:2e:0e:c6:
+        79:d0:f2:97:69:0f:bd:04:47:d9:be:db:b5:29:da:9b:d9:ae:
+        a9:99:d5:d3:3c:30:93:f5:8d:a1:a8:fc:06:8d:44:f4:ca:16:
+        95:7c:33:dc:62:8b:a8:37:f8:27:d8:09:2d:1b:ef:c8:14:27:
+        20:a9:64:44:ff:2e:d6:75:aa:6c:4d:60:40:19:49:43:54:63:
+        da:e2:cc:ba:66:e5:4f:44:7a:5b:d9:6a:81:2b:40:d5:7f:f9:
+        01:27:58:2c:c8:ed:48:91:7c:3f:a6:00:cf:c4:29:73:11:36:
+        de:86:19:3e:9d:ee:19:8a:1b:d5:b0:ed:8e:3d:9c:2a:c0:0d:
+        d8:3d:66:e3:3c:0d:bd:d5:94:5c:e2:e2:a7:35:1b:04:00:f6:
+        3f:5a:8d:ea:43:bd:5f:89:1d:a9:c1:b0:cc:99:e2:4d:00:0a:
+        da:c9:27:5b:e7:13:90:5c:e4:f5:33:a2:55:6d:dc:e0:09:4d:
+        2f:b1:26:5b:27:75:00:09:c4:62:77:29:08:5f:9e:59:ac:b6:
+        7e:ad:9f:54:30:22:03:c1:1e:71:64:fe:f9:38:0a:96:18:dd:
+        02:14:ac:23:cb:06:1c:1e:a4:7d:8d:0d:de:27:41:e8:ad:da:
+        15:b7:b0:23:dd:2b:a8:d3:da:25:87:ed:e8:55:44:4d:88:f4:
+        36:7e:84:9a:78:ac:f7:0e:56:49:0e:d6:33:25:d6:84:50:42:
+        6c:20:12:1d:2a:d5:be:bc:f2:70:81:a4:70:60:be:05:b5:9b:
+        9e:04:44:be:61:23:ac:e9:a5:24:8c:11:80:94:5a:a2:a2:b9:
+        49:d2:c1:dc:d1:a7:ed:31:11:2c:9e:19:a6:ee:e1:55:e1:c0:
+        ea:cf:0d:84:e4:17:b7:a2:7c:a5:de:55:25:06:ee:cc:c0:87:
+        5c:40:da:cc:95:3f:55:e0:35:c7:b8:84:be:b4:5d:cd:7a:83:
+        01:72:ee:87:e6:5f:1d:ae:b5:85:c6:26:df:e6:c1:9a:e9:1e:
+        02:47:9f:2a:a8:6d:a9:5b:cf:ec:45:77:7f:98:27:9a:32:5d:
+        2a:e3:84:ee:c5:98:66:2f:96:20:1d:dd:d8:c3:27:d7:b0:f9:
+        fe:d9:7d:cd:d0:9f:8f:0b:14:58:51:9f:2f:8b:c3:38:2d:de:
+        e8:8f:d6:8d:87:a4:f5:56:43:16:99:2c:f4:a4:56:b4:34:b8:
+        61:37:c9:c2:58:80:1b:a0:97:a1:fc:59:8d:e9:11:f6:d1:0f:
+        4b:55:34:46:2a:8b:86:3b
 SHA1 Fingerprint=93:05:7A:88:15:C6:4F:CE:88:2F:FA:91:16:52:28:78:BC:53:64:17
 -----BEGIN CERTIFICATE-----
 MIIH0zCCBbugAwIBAgIIXsO3pkN/pOAwDQYJKoZIhvcNAQEFBQAwQjESMBAGA1UE
diff --git a/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem b/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
index 22f5764a5d3f..b526b6694741 100644
--- a/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
+++ b/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
@@ -24,7 +24,7 @@ Certificate:
         Subject: C = ES, O = FNMT-RCM, OU = AC RAIZ FNMT-RCM
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:ba:71:80:7a:4c:86:6e:7f:c8:13:6d:c0:c6:7d:
                     1c:00:97:8f:2c:0c:23:bb:10:9a:40:a9:1a:b7:87:
@@ -72,37 +72,37 @@ Certificate:
             X509v3 Certificate Policies: 
                 Policy: X509v3 Any Policy
                   CPS: http://www.cert.fnmt.es/dpcs/
-
     Signature Algorithm: sha256WithRSAEncryption
-         07:90:4a:df:f3:23:4e:f0:c3:9c:51:65:9b:9c:22:a2:8a:0c:
-         85:f3:73:29:6b:4d:fe:01:e2:a9:0c:63:01:bf:04:67:a5:9d:
-         98:5f:fd:01:13:fa:ec:9a:62:e9:86:fe:b6:62:d2:6e:4c:94:
-         fb:c0:75:45:7c:65:0c:f8:b2:37:cf:ac:0f:cf:8d:6f:f9:19:
-         f7:8f:ec:1e:f2:70:9e:f0:ca:b8:ef:b7:ff:76:37:76:5b:f6:
-         6e:88:f3:af:62:32:22:93:0d:3a:6a:8e:14:66:0c:2d:53:74:
-         57:65:1e:d5:b2:dd:23:81:3b:a5:66:23:27:67:09:8f:e1:77:
-         aa:43:cd:65:51:08:ed:51:58:fe:e6:39:f9:cb:47:84:a4:15:
-         f1:76:bb:a4:ee:a4:3b:c4:5f:ef:b2:33:96:11:18:b7:c9:65:
-         be:18:e1:a3:a4:dc:fa:18:f9:d3:bc:13:9b:39:7a:34:ba:d3:
-         41:fb:fa:32:8a:2a:b7:2b:86:0b:69:83:38:be:cd:8a:2e:0b:
-         70:ad:8d:26:92:ee:1e:f5:01:2b:0a:d9:d6:97:9b:6e:e0:a8:
-         19:1c:3a:21:8b:0c:1e:40:ad:03:e7:dd:66:7e:f5:b9:20:0d:
-         03:e8:96:f9:82:45:d4:39:e0:a0:00:5d:d7:98:e6:7d:9e:67:
-         73:c3:9a:2a:f7:ab:8b:a1:3a:14:ef:34:bc:52:0e:89:98:9a:
-         04:40:84:1d:7e:45:69:93:57:ce:eb:ce:f8:50:7c:4f:1c:6e:
-         04:43:9b:f9:d6:3b:23:18:e9:ea:8e:d1:4d:46:8d:f1:3b:e4:
-         6a:ca:ba:fb:23:b7:9b:fa:99:01:29:5a:58:5a:2d:e3:f9:d4:
-         6d:0e:26:ad:c1:6e:34:bc:32:f8:0c:05:fa:65:a3:db:3b:37:
-         83:22:e9:d6:dc:72:33:fd:5d:f2:20:bd:76:3c:23:da:28:f7:
-         f9:1b:eb:59:64:d5:dc:5f:72:7e:20:fc:cd:89:b5:90:67:4d:
-         62:7a:3f:4e:ad:1d:c3:39:fe:7a:f4:28:16:df:41:f6:48:80:
-         05:d7:0f:51:79:ac:10:ab:d4:ec:03:66:e6:6a:b0:ba:31:92:
-         42:40:6a:be:3a:d3:72:e1:6a:37:55:bc:ac:1d:95:b7:69:61:
-         f2:43:91:74:e6:a0:d3:0a:24:46:a1:08:af:d6:da:45:19:96:
-         d4:53:1d:5b:84:79:f0:c0:f7:47:ef:8b:8f:c5:06:ae:9d:4c:
-         62:9d:ff:46:04:f8:d3:c9:b6:10:25:40:75:fe:16:aa:c9:4a:
-         60:86:2f:ba:ef:30:77:e4:54:e2:b8:84:99:58:80:aa:13:8b:
-         51:3a:4f:48:f6:8b:b6:b3
+    Signature Value:
+        07:90:4a:df:f3:23:4e:f0:c3:9c:51:65:9b:9c:22:a2:8a:0c:
+        85:f3:73:29:6b:4d:fe:01:e2:a9:0c:63:01:bf:04:67:a5:9d:
+        98:5f:fd:01:13:fa:ec:9a:62:e9:86:fe:b6:62:d2:6e:4c:94:
+        fb:c0:75:45:7c:65:0c:f8:b2:37:cf:ac:0f:cf:8d:6f:f9:19:
+        f7:8f:ec:1e:f2:70:9e:f0:ca:b8:ef:b7:ff:76:37:76:5b:f6:
+        6e:88:f3:af:62:32:22:93:0d:3a:6a:8e:14:66:0c:2d:53:74:
+        57:65:1e:d5:b2:dd:23:81:3b:a5:66:23:27:67:09:8f:e1:77:
+        aa:43:cd:65:51:08:ed:51:58:fe:e6:39:f9:cb:47:84:a4:15:
+        f1:76:bb:a4:ee:a4:3b:c4:5f:ef:b2:33:96:11:18:b7:c9:65:
+        be:18:e1:a3:a4:dc:fa:18:f9:d3:bc:13:9b:39:7a:34:ba:d3:
+        41:fb:fa:32:8a:2a:b7:2b:86:0b:69:83:38:be:cd:8a:2e:0b:
+        70:ad:8d:26:92:ee:1e:f5:01:2b:0a:d9:d6:97:9b:6e:e0:a8:
+        19:1c:3a:21:8b:0c:1e:40:ad:03:e7:dd:66:7e:f5:b9:20:0d:
+        03:e8:96:f9:82:45:d4:39:e0:a0:00:5d:d7:98:e6:7d:9e:67:
+        73:c3:9a:2a:f7:ab:8b:a1:3a:14:ef:34:bc:52:0e:89:98:9a:
+        04:40:84:1d:7e:45:69:93:57:ce:eb:ce:f8:50:7c:4f:1c:6e:
+        04:43:9b:f9:d6:3b:23:18:e9:ea:8e:d1:4d:46:8d:f1:3b:e4:
+        6a:ca:ba:fb:23:b7:9b:fa:99:01:29:5a:58:5a:2d:e3:f9:d4:
+        6d:0e:26:ad:c1:6e:34:bc:32:f8:0c:05:fa:65:a3:db:3b:37:
+        83:22:e9:d6:dc:72:33:fd:5d:f2:20:bd:76:3c:23:da:28:f7:
+        f9:1b:eb:59:64:d5:dc:5f:72:7e:20:fc:cd:89:b5:90:67:4d:
+        62:7a:3f:4e:ad:1d:c3:39:fe:7a:f4:28:16:df:41:f6:48:80:
+        05:d7:0f:51:79:ac:10:ab:d4:ec:03:66:e6:6a:b0:ba:31:92:
+        42:40:6a:be:3a:d3:72:e1:6a:37:55:bc:ac:1d:95:b7:69:61:
+        f2:43:91:74:e6:a0:d3:0a:24:46:a1:08:af:d6:da:45:19:96:
+        d4:53:1d:5b:84:79:f0:c0:f7:47:ef:8b:8f:c5:06:ae:9d:4c:
+        62:9d:ff:46:04:f8:d3:c9:b6:10:25:40:75:fe:16:aa:c9:4a:
+        60:86:2f:ba:ef:30:77:e4:54:e2:b8:84:99:58:80:aa:13:8b:
+        51:3a:4f:48:f6:8b:b6:b3
 SHA1 Fingerprint=EC:50:35:07:B2:15:C4:95:62:19:E2:A8:9A:5B:42:99:2C:4C:2C:20
 -----BEGIN CERTIFICATE-----
 MIIFgzCCA2ugAwIBAgIPXZONMGc2yAYdGsdUhGkHMA0GCSqGSIb3DQEBCwUAMDsx
diff --git a/secure/caroot/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem b/secure/caroot/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
index bbd47304c5c9..c90964ddb4d3 100644
--- a/secure/caroot/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
+++ b/secure/caroot/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
@@ -43,12 +43,13 @@ Certificate:
             X509v3 Subject Key Identifier: 
                 01:B9:2F:EF:BF:11:86:60:F2:4F:D0:41:6E:AB:73:1F:E7:D2:6E:49
     Signature Algorithm: ecdsa-with-SHA384
-         30:66:02:31:00:ae:4a:e3:2b:40:c3:74:11:f2:95:ad:16:23:
-         de:4e:0c:1a:e6:5d:a5:24:5e:6b:44:7b:fc:38:e2:4f:cb:9c:
-         45:17:11:4c:14:27:26:55:39:75:4a:03:cc:13:90:9f:92:02:
-         31:00:fa:4a:6c:60:88:73:f3:ee:b8:98:62:a9:ce:2b:c2:d9:
-         8a:a6:70:31:1d:af:b0:94:4c:eb:4f:c6:e3:d1:f3:62:a7:3c:
-         ff:93:2e:07:5c:49:01:67:69:12:02:72:bf:e7
+    Signature Value:
+        30:66:02:31:00:ae:4a:e3:2b:40:c3:74:11:f2:95:ad:16:23:
+        de:4e:0c:1a:e6:5d:a5:24:5e:6b:44:7b:fc:38:e2:4f:cb:9c:
+        45:17:11:4c:14:27:26:55:39:75:4a:03:cc:13:90:9f:92:02:
+        31:00:fa:4a:6c:60:88:73:f3:ee:b8:98:62:a9:ce:2b:c2:d9:
+        8a:a6:70:31:1d:af:b0:94:4c:eb:4f:c6:e3:d1:f3:62:a7:3c:
+        ff:93:2e:07:5c:49:01:67:69:12:02:72:bf:e7
 SHA1 Fingerprint=62:FF:D9:9E:C0:65:0D:03:CE:75:93:D2:ED:3F:2D:32:C9:E3:E5:4A
 -----BEGIN CERTIFICATE-----
 MIICbjCCAfOgAwIBAgIQYvYybOXE42hcG2LdnC6dlTAKBggqhkjOPQQDAzB4MQsw
diff --git a/secure/caroot/trusted/ANF_Secure_Server_Root_CA.pem b/secure/caroot/trusted/ANF_Secure_Server_Root_CA.pem
index 4369ffbf1b30..158d806bffc3 100644
--- a/secure/caroot/trusted/ANF_Secure_Server_Root_CA.pem
+++ b/secure/caroot/trusted/ANF_Secure_Server_Root_CA.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: serialNumber = G63287510, C = ES, O = ANF Autoridad de Certificacion, OU = ANF CA Raiz, CN = ANF Secure Server Root CA
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:db:eb:6b:2b:e6:64:54:95:82:90:a3:72:a4:19:
                     01:9d:9c:0b:81:5f:73:49:ba:a7:ac:f3:04:4e:7b:
@@ -63,8 +63,7 @@ Certificate:
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Authority Key Identifier: 
-                keyid:9C:5F:D0:6C:63:A3:5F:93:CA:93:98:08:AD:8C:87:A5:2C:5C:C1:37
-
+                9C:5F:D0:6C:63:A3:5F:93:CA:93:98:08:AD:8C:87:A5:2C:5C:C1:37
             X509v3 Subject Key Identifier: 
                 9C:5F:D0:6C:63:A3:5F:93:CA:93:98:08:AD:8C:87:A5:2C:5C:C1:37
             X509v3 Key Usage: critical
@@ -72,35 +71,36 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-         4e:1e:b9:8a:c6:a0:98:3f:6e:c3:69:c0:6a:5c:49:52:ac:cb:
-         2b:5d:78:38:c1:d5:54:84:9f:93:f0:87:19:3d:2c:66:89:eb:
-         0d:42:fc:cc:f0:75:85:3f:8b:f4:80:5d:79:e5:17:67:bd:35:
-         82:e2:f2:3c:8e:7d:5b:36:cb:5a:80:00:29:f2:ce:2b:2c:f1:
-         8f:aa:6d:05:93:6c:72:c7:56:eb:df:50:23:28:e5:45:10:3d:
-         e8:67:a3:af:0e:55:0f:90:09:62:ef:4b:59:a2:f6:53:f1:c0:
-         35:e4:2f:c1:24:bd:79:2f:4e:20:22:3b:fd:1a:20:b0:a4:0e:
-         2c:70:ed:74:3f:b8:13:95:06:51:c8:e8:87:26:ca:a4:5b:6a:
-         16:21:92:dd:73:60:9e:10:18:de:3c:81:ea:e8:18:c3:7c:89:
-         f2:8b:50:3e:bd:11:e2:15:03:a8:36:7d:33:01:6c:48:15:d7:
-         88:90:99:04:c5:cc:e6:07:f4:bc:f4:90:ed:13:e2:ea:8b:c3:
-         8f:a3:33:0f:c1:29:4c:13:4e:da:15:56:71:73:72:82:50:f6:
-         9a:33:7c:a2:b1:a8:1a:34:74:65:5c:ce:d1:eb:ab:53:e0:1a:
-         80:d8:ea:3a:49:e4:26:30:9b:e5:1c:8a:a8:a9:15:32:86:99:
-         92:0a:10:23:56:12:e0:f6:ce:4c:e2:bb:be:db:8d:92:73:01:
-         66:2f:62:3e:b2:72:27:45:36:ed:4d:56:e3:97:99:ff:3a:35:
-         3e:a5:54:4a:52:59:4b:60:db:ee:fe:78:11:7f:4a:dc:14:79:
-         60:b6:6b:64:03:db:15:83:e1:a2:be:f6:23:97:50:f0:09:33:
-         36:a7:71:96:25:f3:b9:42:7d:db:38:3f:2c:58:ac:e8:42:e1:
-         0e:d8:d3:3b:4c:2e:82:e9:83:2e:6b:31:d9:dd:47:86:4f:6d:
-         97:91:2e:4f:e2:28:71:35:16:d1:f2:73:fe:25:2b:07:47:24:
-         63:27:c8:f8:f6:d9:6b:fc:12:31:56:08:c0:53:42:af:9c:d0:
-         33:7e:fc:06:f0:31:44:03:14:f1:58:ea:f2:6a:0d:a9:11:b2:
-         83:be:c5:1a:bf:07:ea:59:dc:a3:88:35:ef:9c:76:32:3c:4d:
-         06:22:ce:15:e5:dd:9e:d8:8f:da:de:d2:c4:39:e5:17:81:cf:
-         38:47:eb:7f:88:6d:59:1b:df:9f:42:14:ae:7e:cf:a8:b0:66:
-         65:da:37:af:9f:aa:3d:ea:28:b6:de:d5:31:58:16:82:5b:ea:
-         bb:19:75:02:73:1a:ca:48:1a:21:93:90:0a:8e:93:84:a7:7d:
-         3b:23:18:92:89:a0:8d:ac
+    Signature Value:
+        4e:1e:b9:8a:c6:a0:98:3f:6e:c3:69:c0:6a:5c:49:52:ac:cb:
+        2b:5d:78:38:c1:d5:54:84:9f:93:f0:87:19:3d:2c:66:89:eb:
+        0d:42:fc:cc:f0:75:85:3f:8b:f4:80:5d:79:e5:17:67:bd:35:
+        82:e2:f2:3c:8e:7d:5b:36:cb:5a:80:00:29:f2:ce:2b:2c:f1:
+        8f:aa:6d:05:93:6c:72:c7:56:eb:df:50:23:28:e5:45:10:3d:
+        e8:67:a3:af:0e:55:0f:90:09:62:ef:4b:59:a2:f6:53:f1:c0:
+        35:e4:2f:c1:24:bd:79:2f:4e:20:22:3b:fd:1a:20:b0:a4:0e:
+        2c:70:ed:74:3f:b8:13:95:06:51:c8:e8:87:26:ca:a4:5b:6a:
+        16:21:92:dd:73:60:9e:10:18:de:3c:81:ea:e8:18:c3:7c:89:
+        f2:8b:50:3e:bd:11:e2:15:03:a8:36:7d:33:01:6c:48:15:d7:
+        88:90:99:04:c5:cc:e6:07:f4:bc:f4:90:ed:13:e2:ea:8b:c3:
+        8f:a3:33:0f:c1:29:4c:13:4e:da:15:56:71:73:72:82:50:f6:
+        9a:33:7c:a2:b1:a8:1a:34:74:65:5c:ce:d1:eb:ab:53:e0:1a:
+        80:d8:ea:3a:49:e4:26:30:9b:e5:1c:8a:a8:a9:15:32:86:99:
+        92:0a:10:23:56:12:e0:f6:ce:4c:e2:bb:be:db:8d:92:73:01:
+        66:2f:62:3e:b2:72:27:45:36:ed:4d:56:e3:97:99:ff:3a:35:
+        3e:a5:54:4a:52:59:4b:60:db:ee:fe:78:11:7f:4a:dc:14:79:
+        60:b6:6b:64:03:db:15:83:e1:a2:be:f6:23:97:50:f0:09:33:
+        36:a7:71:96:25:f3:b9:42:7d:db:38:3f:2c:58:ac:e8:42:e1:
+        0e:d8:d3:3b:4c:2e:82:e9:83:2e:6b:31:d9:dd:47:86:4f:6d:
+        97:91:2e:4f:e2:28:71:35:16:d1:f2:73:fe:25:2b:07:47:24:
+        63:27:c8:f8:f6:d9:6b:fc:12:31:56:08:c0:53:42:af:9c:d0:
+        33:7e:fc:06:f0:31:44:03:14:f1:58:ea:f2:6a:0d:a9:11:b2:
+        83:be:c5:1a:bf:07:ea:59:dc:a3:88:35:ef:9c:76:32:3c:4d:
+        06:22:ce:15:e5:dd:9e:d8:8f:da:de:d2:c4:39:e5:17:81:cf:
+        38:47:eb:7f:88:6d:59:1b:df:9f:42:14:ae:7e:cf:a8:b0:66:
+        65:da:37:af:9f:aa:3d:ea:28:b6:de:d5:31:58:16:82:5b:ea:
+        bb:19:75:02:73:1a:ca:48:1a:21:93:90:0a:8e:93:84:a7:7d:
+        3b:23:18:92:89:a0:8d:ac
 SHA1 Fingerprint=5B:6E:68:D0:CC:15:B6:A0:5F:1E:C1:5F:AE:02:FC:6B:2F:5D:6F:74
 -----BEGIN CERTIFICATE-----
 MIIF7zCCA9egAwIBAgIIDdPjvGz5a7EwDQYJKoZIhvcNAQELBQAwgYQxEjAQBgNV
diff --git a/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem b/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
index 8ea77deeda58..b71e3f700c29 100644
--- a/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
+++ b/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: C = IT, L = Milan, O = Actalis S.p.A./03358520967, CN = Actalis Authentication Root CA
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:a7:c6:c4:a5:29:a4:2c:ef:e5:18:c5:b0:50:a3:
                     6f:51:3b:9f:0a:5a:c9:c2:48:38:0a:c2:1c:a0:18:
@@ -67,40 +67,40 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Authority Key Identifier: 
-                keyid:52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0
-
+                52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-         0b:7b:72:87:c0:60:a6:49:4c:88:58:e6:1d:88:f7:14:64:48:
-         a6:d8:58:0a:0e:4f:13:35:df:35:1d:d4:ed:06:31:c8:81:3e:
-         6a:d5:dd:3b:1a:32:ee:90:3d:11:d2:2e:f4:8e:c3:63:2e:23:
-         66:b0:67:be:6f:b6:c0:13:39:60:aa:a2:34:25:93:75:52:de:
-         a7:9d:ad:0e:87:89:52:71:6a:16:3c:19:1d:83:f8:9a:29:65:
-         be:f4:3f:9a:d9:f0:f3:5a:87:21:71:80:4d:cb:e0:38:9b:3f:
-         bb:fa:e0:30:4d:cf:86:d3:65:10:19:18:d1:97:02:b1:2b:72:
-         42:68:ac:a0:bd:4e:5a:da:18:bf:6b:98:81:d0:fd:9a:be:5e:
-         15:48:cd:11:15:b9:c0:29:5c:b4:e8:88:f7:3e:36:ae:b7:62:
-         fd:1e:62:de:70:78:10:1c:48:5b:da:bc:a4:38:ba:67:ed:55:
-         3e:5e:57:df:d4:03:40:4c:81:a4:d2:4f:63:a7:09:42:09:14:
-         fc:00:a9:c2:80:73:4f:2e:c0:40:d9:11:7b:48:ea:7a:02:c0:
-         d3:eb:28:01:26:58:74:c1:c0:73:22:6d:93:95:fd:39:7d:bb:
-         2a:e3:f6:82:e3:2c:97:5f:4e:1f:91:94:fa:fe:2c:a3:d8:76:
-         1a:b8:4d:b2:38:4f:9b:fa:1d:48:60:79:26:e2:f3:fd:a9:d0:
-         9a:e8:70:8f:49:7a:d6:e5:bd:0a:0e:db:2d:f3:8d:bf:eb:e3:
-         a4:7d:cb:c7:95:71:e8:da:a3:7c:c5:c2:f8:74:92:04:1b:86:
-         ac:a4:22:53:40:b6:ac:fe:4c:76:cf:fb:94:32:c0:35:9f:76:
-         3f:6e:e5:90:6e:a0:a6:26:a2:b8:2c:be:d1:2b:85:fd:a7:68:
-         c8:ba:01:2b:b1:6c:74:1d:b8:73:95:e7:ee:b7:c7:25:f0:00:
-         4c:00:b2:7e:b6:0b:8b:1c:f3:c0:50:9e:25:b9:e0:08:de:36:
-         66:ff:37:a5:d1:bb:54:64:2c:c9:27:b5:4b:92:7e:65:ff:d3:
-         2d:e1:b9:4e:bc:7f:a4:41:21:90:41:77:a6:39:1f:ea:9e:e3:
-         9f:d0:66:6f:05:ec:aa:76:7e:bf:6b:16:a0:eb:b5:c7:fc:92:
-         54:2f:2b:11:27:25:37:78:4c:51:6a:b0:f3:cc:58:5d:14:f1:
-         6a:48:15:ff:c2:07:b6:b1:8d:0f:8e:5c:50:46:b3:3d:bf:01:
-         98:4f:b2:59:54:47:3e:34:7b:78:6d:56:93:2e:73:ea:66:28:
-         78:cd:1d:14:bf:a0:8f:2f:2e:b8:2e:8e:f2:14:8a:cc:e9:b5:
-         7c:fb:6c:9d:0c:a5:e1:96
+    Signature Value:
+        0b:7b:72:87:c0:60:a6:49:4c:88:58:e6:1d:88:f7:14:64:48:
+        a6:d8:58:0a:0e:4f:13:35:df:35:1d:d4:ed:06:31:c8:81:3e:
+        6a:d5:dd:3b:1a:32:ee:90:3d:11:d2:2e:f4:8e:c3:63:2e:23:
+        66:b0:67:be:6f:b6:c0:13:39:60:aa:a2:34:25:93:75:52:de:
+        a7:9d:ad:0e:87:89:52:71:6a:16:3c:19:1d:83:f8:9a:29:65:
+        be:f4:3f:9a:d9:f0:f3:5a:87:21:71:80:4d:cb:e0:38:9b:3f:
+        bb:fa:e0:30:4d:cf:86:d3:65:10:19:18:d1:97:02:b1:2b:72:
+        42:68:ac:a0:bd:4e:5a:da:18:bf:6b:98:81:d0:fd:9a:be:5e:
+        15:48:cd:11:15:b9:c0:29:5c:b4:e8:88:f7:3e:36:ae:b7:62:
+        fd:1e:62:de:70:78:10:1c:48:5b:da:bc:a4:38:ba:67:ed:55:
+        3e:5e:57:df:d4:03:40:4c:81:a4:d2:4f:63:a7:09:42:09:14:
+        fc:00:a9:c2:80:73:4f:2e:c0:40:d9:11:7b:48:ea:7a:02:c0:
+        d3:eb:28:01:26:58:74:c1:c0:73:22:6d:93:95:fd:39:7d:bb:
+        2a:e3:f6:82:e3:2c:97:5f:4e:1f:91:94:fa:fe:2c:a3:d8:76:
+        1a:b8:4d:b2:38:4f:9b:fa:1d:48:60:79:26:e2:f3:fd:a9:d0:
+        9a:e8:70:8f:49:7a:d6:e5:bd:0a:0e:db:2d:f3:8d:bf:eb:e3:
+        a4:7d:cb:c7:95:71:e8:da:a3:7c:c5:c2:f8:74:92:04:1b:86:
+        ac:a4:22:53:40:b6:ac:fe:4c:76:cf:fb:94:32:c0:35:9f:76:
+        3f:6e:e5:90:6e:a0:a6:26:a2:b8:2c:be:d1:2b:85:fd:a7:68:
+        c8:ba:01:2b:b1:6c:74:1d:b8:73:95:e7:ee:b7:c7:25:f0:00:
+        4c:00:b2:7e:b6:0b:8b:1c:f3:c0:50:9e:25:b9:e0:08:de:36:
+        66:ff:37:a5:d1:bb:54:64:2c:c9:27:b5:4b:92:7e:65:ff:d3:
+        2d:e1:b9:4e:bc:7f:a4:41:21:90:41:77:a6:39:1f:ea:9e:e3:
+        9f:d0:66:6f:05:ec:aa:76:7e:bf:6b:16:a0:eb:b5:c7:fc:92:
+        54:2f:2b:11:27:25:37:78:4c:51:6a:b0:f3:cc:58:5d:14:f1:
+        6a:48:15:ff:c2:07:b6:b1:8d:0f:8e:5c:50:46:b3:3d:bf:01:
+        98:4f:b2:59:54:47:3e:34:7b:78:6d:56:93:2e:73:ea:66:28:
+        78:cd:1d:14:bf:a0:8f:2f:2e:b8:2e:8e:f2:14:8a:cc:e9:b5:
+        7c:fb:6c:9d:0c:a5:e1:96
 SHA1 Fingerprint=F3:73:B3:87:06:5A:28:84:8A:F2:F3:4A:CE:19:2B:DD:C7:8E:9C:AC
 -----BEGIN CERTIFICATE-----
 MIIFuzCCA6OgAwIBAgIIVwoRl0LE48wwDQYJKoZIhvcNAQELBQAwazELMAkGA1UE
diff --git a/secure/caroot/trusted/AffirmTrust_Commercial.pem b/secure/caroot/trusted/AffirmTrust_Commercial.pem
index b1031ad0f348..b59fd17d8d7b 100644
--- a/secure/caroot/trusted/AffirmTrust_Commercial.pem
+++ b/secure/caroot/trusted/AffirmTrust_Commercial.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: C = US, O = AffirmTrust, CN = AffirmTrust Commercial
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:f6:1b:4f:67:07:2b:a1:15:f5:06:22:cb:1f:01:
                     b2:e3:73:45:06:44:49:2c:bb:49:25:14:d6:ce:c3:
@@ -52,21 +52,22 @@ Certificate:
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-         58:ac:f4:04:0e:cd:c0:0d:ff:0a:fd:d4:ba:16:5f:29:bd:7b:
-         68:99:58:49:d2:b4:1d:37:4d:7f:27:7d:46:06:5d:43:c6:86:
-         2e:3e:73:b2:26:7d:4f:93:a9:b6:c4:2a:9a:ab:21:97:14:b1:
-         de:8c:d3:ab:89:15:d8:6b:24:d4:f1:16:ae:d8:a4:5c:d4:7f:
-         51:8e:ed:18:01:b1:93:63:bd:bc:f8:61:80:9a:9e:b1:ce:42:
-         70:e2:a9:7d:06:25:7d:27:a1:fe:6f:ec:b3:1e:24:da:e3:4b:
-         55:1a:00:3b:35:b4:3b:d9:d7:5d:30:fd:81:13:89:f2:c2:06:
-         2b:ed:67:c4:8e:c9:43:b2:5c:6b:15:89:02:bc:62:fc:4e:f2:
-         b5:33:aa:b2:6f:d3:0a:a2:50:e3:f6:3b:e8:2e:44:c2:db:66:
-         38:a9:33:56:48:f1:6d:1b:33:8d:0d:8c:3f:60:37:9d:d3:ca:
-         6d:7e:34:7e:0d:9f:72:76:8b:1b:9f:72:fd:52:35:41:45:02:
-         96:2f:1c:b2:9a:73:49:21:b1:49:47:45:47:b4:ef:6a:34:11:
-         c9:4d:9a:cc:59:b7:d6:02:9e:5a:4e:65:b5:94:ae:1b:df:29:
-         b0:16:f1:bf:00:9e:07:3a:17:64:b5:04:b5:23:21:99:0a:95:
-         3b:97:7c:ef
+    Signature Value:
+        58:ac:f4:04:0e:cd:c0:0d:ff:0a:fd:d4:ba:16:5f:29:bd:7b:
+        68:99:58:49:d2:b4:1d:37:4d:7f:27:7d:46:06:5d:43:c6:86:
+        2e:3e:73:b2:26:7d:4f:93:a9:b6:c4:2a:9a:ab:21:97:14:b1:
+        de:8c:d3:ab:89:15:d8:6b:24:d4:f1:16:ae:d8:a4:5c:d4:7f:
+        51:8e:ed:18:01:b1:93:63:bd:bc:f8:61:80:9a:9e:b1:ce:42:
+        70:e2:a9:7d:06:25:7d:27:a1:fe:6f:ec:b3:1e:24:da:e3:4b:
+        55:1a:00:3b:35:b4:3b:d9:d7:5d:30:fd:81:13:89:f2:c2:06:
+        2b:ed:67:c4:8e:c9:43:b2:5c:6b:15:89:02:bc:62:fc:4e:f2:
+        b5:33:aa:b2:6f:d3:0a:a2:50:e3:f6:3b:e8:2e:44:c2:db:66:
+        38:a9:33:56:48:f1:6d:1b:33:8d:0d:8c:3f:60:37:9d:d3:ca:
+        6d:7e:34:7e:0d:9f:72:76:8b:1b:9f:72:fd:52:35:41:45:02:
+        96:2f:1c:b2:9a:73:49:21:b1:49:47:45:47:b4:ef:6a:34:11:
+        c9:4d:9a:cc:59:b7:d6:02:9e:5a:4e:65:b5:94:ae:1b:df:29:
+        b0:16:f1:bf:00:9e:07:3a:17:64:b5:04:b5:23:21:99:0a:95:
+        3b:97:7c:ef
 SHA1 Fingerprint=F9:B5:B6:32:45:5F:9C:BE:EC:57:5F:80:DC:E9:6E:2C:C7:B2:78:B7
 -----BEGIN CERTIFICATE-----
 MIIDTDCCAjSgAwIBAgIId3cGJyapsXwwDQYJKoZIhvcNAQELBQAwRDELMAkGA1UE
diff --git a/secure/caroot/trusted/AffirmTrust_Networking.pem b/secure/caroot/trusted/AffirmTrust_Networking.pem
index 1d6a82f767f7..33f7a4bebcb6 100644
--- a/secure/caroot/trusted/AffirmTrust_Networking.pem
+++ b/secure/caroot/trusted/AffirmTrust_Networking.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: C = US, O = AffirmTrust, CN = AffirmTrust Networking
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:b4:84:cc:33:17:2e:6b:94:6c:6b:61:52:a0:eb:
                     a3:cf:79:94:4c:e5:94:80:99:cb:55:64:44:65:8f:
@@ -52,21 +52,22 @@ Certificate:
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha1WithRSAEncryption
-         89:57:b2:16:7a:a8:c2:fd:d6:d9:9b:9b:34:c2:9c:b4:32:14:
-         4d:a7:a4:df:ec:be:a7:be:f8:43:db:91:37:ce:b4:32:2e:50:
-         55:1a:35:4e:76:43:71:20:ef:93:77:4e:15:70:2e:87:c3:c1:
-         1d:6d:dc:cb:b5:27:d4:2c:56:d1:52:53:3a:44:d2:73:c8:c4:
-         1b:05:65:5a:62:92:9c:ee:41:8d:31:db:e7:34:ea:59:21:d5:
-         01:7a:d7:64:b8:64:39:cd:c9:ed:af:ed:4b:03:48:a7:a0:99:
-         01:80:dc:65:a3:36:ae:65:59:48:4f:82:4b:c8:65:f1:57:1d:
-         e5:59:2e:0a:3f:6c:d8:d1:f5:e5:09:b4:6c:54:00:0a:e0:15:
-         4d:87:75:6d:b7:58:96:5a:dd:6d:d2:00:a0:f4:9b:48:be:c3:
-         37:a4:ba:36:e0:7c:87:85:97:1a:15:a2:de:2e:a2:5b:bd:af:
-         18:f9:90:50:cd:70:59:f8:27:67:47:cb:c7:a0:07:3a:7d:d1:
-         2c:5d:6c:19:3a:66:b5:7d:fd:91:6f:82:b1:be:08:93:db:14:
-         47:f1:a2:37:c7:45:9e:3c:c7:77:af:64:a8:93:df:f6:69:83:
-         82:60:f2:49:42:34:ed:5a:00:54:85:1c:16:36:92:0c:5c:fa:
-         a6:ad:bf:db
+    Signature Value:
+        89:57:b2:16:7a:a8:c2:fd:d6:d9:9b:9b:34:c2:9c:b4:32:14:
+        4d:a7:a4:df:ec:be:a7:be:f8:43:db:91:37:ce:b4:32:2e:50:
+        55:1a:35:4e:76:43:71:20:ef:93:77:4e:15:70:2e:87:c3:c1:
+        1d:6d:dc:cb:b5:27:d4:2c:56:d1:52:53:3a:44:d2:73:c8:c4:
+        1b:05:65:5a:62:92:9c:ee:41:8d:31:db:e7:34:ea:59:21:d5:
+        01:7a:d7:64:b8:64:39:cd:c9:ed:af:ed:4b:03:48:a7:a0:99:
+        01:80:dc:65:a3:36:ae:65:59:48:4f:82:4b:c8:65:f1:57:1d:
+        e5:59:2e:0a:3f:6c:d8:d1:f5:e5:09:b4:6c:54:00:0a:e0:15:
+        4d:87:75:6d:b7:58:96:5a:dd:6d:d2:00:a0:f4:9b:48:be:c3:
+        37:a4:ba:36:e0:7c:87:85:97:1a:15:a2:de:2e:a2:5b:bd:af:
+        18:f9:90:50:cd:70:59:f8:27:67:47:cb:c7:a0:07:3a:7d:d1:
+        2c:5d:6c:19:3a:66:b5:7d:fd:91:6f:82:b1:be:08:93:db:14:
+        47:f1:a2:37:c7:45:9e:3c:c7:77:af:64:a8:93:df:f6:69:83:
+        82:60:f2:49:42:34:ed:5a:00:54:85:1c:16:36:92:0c:5c:fa:
+        a6:ad:bf:db
 SHA1 Fingerprint=29:36:21:02:8B:20:ED:02:F5:66:C5:32:D1:D6:ED:90:9F:45:00:2F
 -----BEGIN CERTIFICATE-----
 MIIDTDCCAjSgAwIBAgIIfE8EORzUmS0wDQYJKoZIhvcNAQEFBQAwRDELMAkGA1UE
diff --git a/secure/caroot/trusted/AffirmTrust_Premium.pem b/secure/caroot/trusted/AffirmTrust_Premium.pem
index ef4c3286bf1c..ec32ac850bbd 100644
--- a/secure/caroot/trusted/AffirmTrust_Premium.pem
+++ b/secure/caroot/trusted/AffirmTrust_Premium.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: C = US, O = AffirmTrust, CN = AffirmTrust Premium
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:c4:12:df:a9:5f:fe:41:dd:dd:f5:9f:8a:e3:f6:
                     ac:e1:3c:78:9a:bc:d8:f0:7f:7a:a0:33:2a:dc:8d:
@@ -69,35 +69,36 @@ Certificate:
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha384WithRSAEncryption
-         b3:57:4d:10:62:4e:3a:e4:ac:ea:b8:1c:af:32:23:c8:b3:49:
-         5a:51:9c:76:28:8d:79:aa:57:46:17:d5:f5:52:f6:b7:44:e8:
-         08:44:bf:18:84:d2:0b:80:cd:c5:12:fd:00:55:05:61:87:41:
-         dc:b5:24:9e:3c:c4:d8:c8:fb:70:9e:2f:78:96:83:20:36:de:
-         7c:0f:69:13:88:a5:75:36:98:08:a6:c6:df:ac:ce:e3:58:d6:
-         b7:3e:de:ba:f3:eb:34:40:d8:a2:81:f5:78:3f:2f:d5:a5:fc:
-         d9:a2:d4:5e:04:0e:17:ad:fe:41:f0:e5:b2:72:fa:44:82:33:
-         42:e8:2d:58:f7:56:8c:62:3f:ba:42:b0:9c:0c:5c:7e:2e:65:
-         26:5c:53:4f:00:b2:78:7e:a1:0d:99:2d:8d:b8:1d:8e:a2:c4:
-         b0:fd:60:d0:30:a4:8e:c8:04:62:a9:c4:ed:35:de:7a:97:ed:
-         0e:38:5e:92:2f:93:70:a5:a9:9c:6f:a7:7d:13:1d:7e:c6:08:
-         48:b1:5e:67:eb:51:08:25:e9:e6:25:6b:52:29:91:9c:d2:39:
-         73:08:57:de:99:06:b4:5b:9d:10:06:e1:c2:00:a8:b8:1c:4a:
-         02:0a:14:d0:c1:41:ca:fb:8c:35:21:7d:82:38:f2:a9:54:91:
-         19:35:93:94:6d:6a:3a:c5:b2:d0:bb:89:86:93:e8:9b:c9:0f:
-         3a:a7:7a:b8:a1:f0:78:46:fa:fc:37:2f:e5:8a:84:f3:df:fe:
-         04:d9:a1:68:a0:2f:24:e2:09:95:06:d5:95:ca:e1:24:96:eb:
-         7c:f6:93:05:bb:ed:73:e9:2d:d1:75:39:d7:e7:24:db:d8:4e:
-         5f:43:8f:9e:d0:14:39:bf:55:70:48:99:57:31:b4:9c:ee:4a:
-         98:03:96:30:1f:60:06:ee:1b:23:fe:81:60:23:1a:47:62:85:
-         a5:cc:19:34:80:6f:b3:ac:1a:e3:9f:f0:7b:48:ad:d5:01:d9:
-         67:b6:a9:72:93:ea:2d:66:b5:b2:b8:e4:3d:3c:b2:ef:4c:8c:
-         ea:eb:07:bf:ab:35:9a:55:86:bc:18:a6:b5:a8:5e:b4:83:6c:
-         6b:69:40:d3:9f:dc:f1:c3:69:6b:b9:e1:6d:09:f4:f1:aa:50:
-         76:0a:7a:7d:7a:17:a1:55:96:42:99:31:09:dd:60:11:8d:05:
-         30:7e:e6:8e:46:d1:9d:14:da:c7:17:e4:05:96:8c:c4:24:b5:
-         1b:cf:14:07:b2:40:f8:a3:9e:41:86:bc:04:d0:6b:96:c8:2a:
-         80:34:fd:bf:ef:06:a3:dd:58:c5:85:3d:3e:8f:fe:9e:29:e0:
-         b6:b8:09:68:19:1c:18:43
+    Signature Value:
+        b3:57:4d:10:62:4e:3a:e4:ac:ea:b8:1c:af:32:23:c8:b3:49:
+        5a:51:9c:76:28:8d:79:aa:57:46:17:d5:f5:52:f6:b7:44:e8:
+        08:44:bf:18:84:d2:0b:80:cd:c5:12:fd:00:55:05:61:87:41:
+        dc:b5:24:9e:3c:c4:d8:c8:fb:70:9e:2f:78:96:83:20:36:de:
+        7c:0f:69:13:88:a5:75:36:98:08:a6:c6:df:ac:ce:e3:58:d6:
+        b7:3e:de:ba:f3:eb:34:40:d8:a2:81:f5:78:3f:2f:d5:a5:fc:
+        d9:a2:d4:5e:04:0e:17:ad:fe:41:f0:e5:b2:72:fa:44:82:33:
+        42:e8:2d:58:f7:56:8c:62:3f:ba:42:b0:9c:0c:5c:7e:2e:65:
+        26:5c:53:4f:00:b2:78:7e:a1:0d:99:2d:8d:b8:1d:8e:a2:c4:
+        b0:fd:60:d0:30:a4:8e:c8:04:62:a9:c4:ed:35:de:7a:97:ed:
+        0e:38:5e:92:2f:93:70:a5:a9:9c:6f:a7:7d:13:1d:7e:c6:08:
+        48:b1:5e:67:eb:51:08:25:e9:e6:25:6b:52:29:91:9c:d2:39:
+        73:08:57:de:99:06:b4:5b:9d:10:06:e1:c2:00:a8:b8:1c:4a:
+        02:0a:14:d0:c1:41:ca:fb:8c:35:21:7d:82:38:f2:a9:54:91:
+        19:35:93:94:6d:6a:3a:c5:b2:d0:bb:89:86:93:e8:9b:c9:0f:
+        3a:a7:7a:b8:a1:f0:78:46:fa:fc:37:2f:e5:8a:84:f3:df:fe:
+        04:d9:a1:68:a0:2f:24:e2:09:95:06:d5:95:ca:e1:24:96:eb:
+        7c:f6:93:05:bb:ed:73:e9:2d:d1:75:39:d7:e7:24:db:d8:4e:
+        5f:43:8f:9e:d0:14:39:bf:55:70:48:99:57:31:b4:9c:ee:4a:
+        98:03:96:30:1f:60:06:ee:1b:23:fe:81:60:23:1a:47:62:85:
+        a5:cc:19:34:80:6f:b3:ac:1a:e3:9f:f0:7b:48:ad:d5:01:d9:
+        67:b6:a9:72:93:ea:2d:66:b5:b2:b8:e4:3d:3c:b2:ef:4c:8c:
+        ea:eb:07:bf:ab:35:9a:55:86:bc:18:a6:b5:a8:5e:b4:83:6c:
+        6b:69:40:d3:9f:dc:f1:c3:69:6b:b9:e1:6d:09:f4:f1:aa:50:
+        76:0a:7a:7d:7a:17:a1:55:96:42:99:31:09:dd:60:11:8d:05:
+        30:7e:e6:8e:46:d1:9d:14:da:c7:17:e4:05:96:8c:c4:24:b5:
+        1b:cf:14:07:b2:40:f8:a3:9e:41:86:bc:04:d0:6b:96:c8:2a:
+        80:34:fd:bf:ef:06:a3:dd:58:c5:85:3d:3e:8f:fe:9e:29:e0:
+        b6:b8:09:68:19:1c:18:43
 SHA1 Fingerprint=D8:A6:33:2C:E0:03:6F:B1:85:F6:63:4F:7D:6A:06:65:26:32:28:27
 -----BEGIN CERTIFICATE-----
 MIIFRjCCAy6gAwIBAgIIbYwURrGmCu4wDQYJKoZIhvcNAQEMBQAwQTELMAkGA1UE
diff --git a/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem b/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
index 1a1b7b14e7be..19a9ffb6b45b 100644
--- a/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
+++ b/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
@@ -42,12 +42,13 @@ Certificate:
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: ecdsa-with-SHA384
-         30:64:02:30:17:09:f3:87:88:50:5a:af:c8:c0:42:bf:47:5f:
-         f5:6c:6a:86:e0:c4:27:74:e4:38:53:d7:05:7f:1b:34:e3:c6:
-         2f:b3:ca:09:3c:37:9d:d7:e7:b8:46:f1:fd:a1:e2:71:02:30:
-         42:59:87:43:d4:51:df:ba:d3:09:32:5a:ce:88:7e:57:3d:9c:
-         5f:42:6b:f5:07:2d:b5:f0:82:93:f9:59:6f:ae:64:fa:58:e5:
-         8b:1e:e3:63:be:b5:81:cd:6f:02:8c:79
+    Signature Value:
+        30:64:02:30:17:09:f3:87:88:50:5a:af:c8:c0:42:bf:47:5f:
+        f5:6c:6a:86:e0:c4:27:74:e4:38:53:d7:05:7f:1b:34:e3:c6:
+        2f:b3:ca:09:3c:37:9d:d7:e7:b8:46:f1:fd:a1:e2:71:02:30:
+        42:59:87:43:d4:51:df:ba:d3:09:32:5a:ce:88:7e:57:3d:9c:
+        5f:42:6b:f5:07:2d:b5:f0:82:93:f9:59:6f:ae:64:fa:58:e5:
+        8b:1e:e3:63:be:b5:81:cd:6f:02:8c:79
 SHA1 Fingerprint=B8:23:6B:00:2F:1D:16:86:53:01:55:6C:11:A4:37:CA:EB:FF:C3:BB
 -----BEGIN CERTIFICATE-----
 MIIB/jCCAYWgAwIBAgIIdJclisc/elQwCgYIKoZIzj0EAwMwRTELMAkGA1UEBhMC
diff --git a/secure/caroot/trusted/Amazon_Root_CA_1.pem b/secure/caroot/trusted/Amazon_Root_CA_1.pem
index 996e32e056e9..5a7236d01703 100644
--- a/secure/caroot/trusted/Amazon_Root_CA_1.pem
+++ b/secure/caroot/trusted/Amazon_Root_CA_1.pem
@@ -24,7 +24,7 @@ Certificate:
         Subject: C = US, O = Amazon, CN = Amazon Root CA 1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:b2:78:80:71:ca:78:d5:e3:71:af:47:80:50:74:
                     7d:6e:d8:d7:88:76:f4:99:68:f7:58:21:60:f9:74:
@@ -53,21 +53,22 @@ Certificate:
             X509v3 Subject Key Identifier: 
                 84:18:CC:85:34:EC:BC:0C:94:94:2E:08:59:9C:C7:B2:10:4E:0A:08
     Signature Algorithm: sha256WithRSAEncryption
-         98:f2:37:5a:41:90:a1:1a:c5:76:51:28:20:36:23:0e:ae:e6:
-         28:bb:aa:f8:94:ae:48:a4:30:7f:1b:fc:24:8d:4b:b4:c8:a1:
-         97:f6:b6:f1:7a:70:c8:53:93:cc:08:28:e3:98:25:cf:23:a4:
-         f9:de:21:d3:7c:85:09:ad:4e:9a:75:3a:c2:0b:6a:89:78:76:
-         44:47:18:65:6c:8d:41:8e:3b:7f:9a:cb:f4:b5:a7:50:d7:05:
-         2c:37:e8:03:4b:ad:e9:61:a0:02:6e:f5:f2:f0:c5:b2:ed:5b:
-         b7:dc:fa:94:5c:77:9e:13:a5:7f:52:ad:95:f2:f8:93:3b:de:
-         8b:5c:5b:ca:5a:52:5b:60:af:14:f7:4b:ef:a3:fb:9f:40:95:
-         6d:31:54:fc:42:d3:c7:46:1f:23:ad:d9:0f:48:70:9a:d9:75:
-         78:71:d1:72:43:34:75:6e:57:59:c2:02:5c:26:60:29:cf:23:
-         19:16:8e:88:43:a5:d4:e4:cb:08:fb:23:11:43:e8:43:29:72:
-         62:a1:a9:5d:5e:08:d4:90:ae:b8:d8:ce:14:c2:d0:55:f2:86:
-         f6:c4:93:43:77:66:61:c0:b9:e8:41:d7:97:78:60:03:6e:4a:
-         72:ae:a5:d1:7d:ba:10:9e:86:6c:1b:8a:b9:59:33:f8:eb:c4:
-         90:be:f1:b9
+    Signature Value:
+        98:f2:37:5a:41:90:a1:1a:c5:76:51:28:20:36:23:0e:ae:e6:
+        28:bb:aa:f8:94:ae:48:a4:30:7f:1b:fc:24:8d:4b:b4:c8:a1:
+        97:f6:b6:f1:7a:70:c8:53:93:cc:08:28:e3:98:25:cf:23:a4:
+        f9:de:21:d3:7c:85:09:ad:4e:9a:75:3a:c2:0b:6a:89:78:76:
+        44:47:18:65:6c:8d:41:8e:3b:7f:9a:cb:f4:b5:a7:50:d7:05:
+        2c:37:e8:03:4b:ad:e9:61:a0:02:6e:f5:f2:f0:c5:b2:ed:5b:
+        b7:dc:fa:94:5c:77:9e:13:a5:7f:52:ad:95:f2:f8:93:3b:de:
+        8b:5c:5b:ca:5a:52:5b:60:af:14:f7:4b:ef:a3:fb:9f:40:95:
+        6d:31:54:fc:42:d3:c7:46:1f:23:ad:d9:0f:48:70:9a:d9:75:
+        78:71:d1:72:43:34:75:6e:57:59:c2:02:5c:26:60:29:cf:23:
+        19:16:8e:88:43:a5:d4:e4:cb:08:fb:23:11:43:e8:43:29:72:
+        62:a1:a9:5d:5e:08:d4:90:ae:b8:d8:ce:14:c2:d0:55:f2:86:
+        f6:c4:93:43:77:66:61:c0:b9:e8:41:d7:97:78:60:03:6e:4a:
+        72:ae:a5:d1:7d:ba:10:9e:86:6c:1b:8a:b9:59:33:f8:eb:c4:
+        90:be:f1:b9
 SHA1 Fingerprint=8D:A7:F9:65:EC:5E:FC:37:91:0F:1C:6E:59:FD:C1:CC:6A:6E:DE:16
 -----BEGIN CERTIFICATE-----
 MIIDQTCCAimgAwIBAgITBmyfz5m/jAo54vB4ikPmljZbyjANBgkqhkiG9w0BAQsF
diff --git a/secure/caroot/trusted/Amazon_Root_CA_2.pem b/secure/caroot/trusted/Amazon_Root_CA_2.pem
index fbcb6a47f445..5418e52f1cfd 100644
--- a/secure/caroot/trusted/Amazon_Root_CA_2.pem
+++ b/secure/caroot/trusted/Amazon_Root_CA_2.pem
@@ -24,7 +24,7 @@ Certificate:
         Subject: C = US, O = Amazon, CN = Amazon Root CA 2
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:ad:96:9f:2d:9c:4a:4c:4a:81:79:51:99:ec:8a:
                     cb:6b:60:51:13:bc:4d:6d:06:fc:b0:08:8d:dd:19:
@@ -70,35 +70,36 @@ Certificate:
             X509v3 Subject Key Identifier: 
                 B0:0C:F0:4C:30:F4:05:58:02:48:FD:33:E5:52:AF:4B:84:E3:66:52
     Signature Algorithm: sha384WithRSAEncryption
-         aa:a8:80:8f:0e:78:a3:e0:a2:d4:cd:e6:f5:98:7a:3b:ea:00:
-         03:b0:97:0e:93:bc:5a:a8:f6:2c:8c:72:87:a9:b1:fc:7f:73:
-         fd:63:71:78:a5:87:59:cf:30:e1:0d:10:b2:13:5a:6d:82:f5:
-         6a:e6:80:9f:a0:05:0b:68:e4:47:6b:c7:6a:df:b6:fd:77:32:
-         72:e5:18:fa:09:f4:a0:93:2c:5d:d2:8c:75:85:76:65:90:0c:
-         03:79:b7:31:23:63:ad:78:83:09:86:68:84:ca:ff:f9:cf:26:
-         9a:92:79:e7:cd:4b:c5:e7:61:a7:17:cb:f3:a9:12:93:93:6b:
-         a7:e8:2f:53:92:c4:60:58:b0:cc:02:51:18:5b:85:8d:62:59:
-         63:b6:ad:b4:de:9a:fb:26:f7:00:27:c0:5d:55:37:74:99:c9:
-         50:7f:e3:59:2e:44:e3:2c:25:ee:ec:4c:32:77:b4:9f:1a:e9:
-         4b:5d:20:c5:da:fd:1c:87:16:c6:43:e8:d4:bb:26:9a:45:70:
-         5e:a9:0b:37:53:e2:46:7b:27:fd:e0:46:f2:89:b7:cc:42:b6:
-         cb:28:26:6e:d9:a5:c9:3a:c8:41:13:60:f7:50:8c:15:ae:b2:
-         6d:1a:15:1a:57:78:e6:92:2a:d9:65:90:82:3f:6c:02:af:ae:
-         12:3a:27:96:36:04:d7:1d:a2:80:63:a9:9b:f1:e5:ba:b4:7c:
-         14:b0:4e:c9:b1:1f:74:5f:38:f6:51:ea:9b:fa:2c:a2:11:d4:
-         a9:2d:27:1a:45:b1:af:b2:4e:71:0d:c0:58:46:d6:69:06:cb:
-         53:cb:b3:fe:6b:41:cd:41:7e:7d:4c:0f:7c:72:79:7a:59:cd:
-         5e:4a:0e:ac:9b:a9:98:73:79:7c:b4:f4:cc:b9:b8:07:0c:b2:
-         74:5c:b8:c7:6f:88:a1:90:a7:f4:aa:f9:bf:67:3a:f4:1a:15:
-         62:1e:b7:9f:be:3d:b1:29:af:67:a1:12:f2:58:10:19:53:03:
-         30:1b:b8:1a:89:f6:9c:bd:97:03:8e:a3:09:f3:1d:8b:21:f1:
-         b4:df:e4:1c:d1:9f:65:02:06:ea:5c:d6:13:b3:84:ef:a2:a5:
-         5c:8c:77:29:a7:68:c0:6b:ae:40:d2:a8:b4:ea:cd:f0:8d:4b:
-         38:9c:19:9a:1b:28:54:b8:89:90:ef:ca:75:81:3e:1e:f2:64:
-         24:c7:18:af:4e:ff:47:9e:07:f6:35:65:a4:d3:0a:56:ff:f5:
-         17:64:6c:ef:a8:22:25:49:93:b6:df:00:17:da:58:7e:5d:ee:
-         c5:1b:b0:d1:d1:5f:21:10:c7:f9:f3:ba:02:0a:27:07:c5:f1:
-         d6:c7:d3:e0:fb:09:60:6c
+    Signature Value:
+        aa:a8:80:8f:0e:78:a3:e0:a2:d4:cd:e6:f5:98:7a:3b:ea:00:
+        03:b0:97:0e:93:bc:5a:a8:f6:2c:8c:72:87:a9:b1:fc:7f:73:
+        fd:63:71:78:a5:87:59:cf:30:e1:0d:10:b2:13:5a:6d:82:f5:
+        6a:e6:80:9f:a0:05:0b:68:e4:47:6b:c7:6a:df:b6:fd:77:32:
+        72:e5:18:fa:09:f4:a0:93:2c:5d:d2:8c:75:85:76:65:90:0c:
+        03:79:b7:31:23:63:ad:78:83:09:86:68:84:ca:ff:f9:cf:26:
+        9a:92:79:e7:cd:4b:c5:e7:61:a7:17:cb:f3:a9:12:93:93:6b:
+        a7:e8:2f:53:92:c4:60:58:b0:cc:02:51:18:5b:85:8d:62:59:
+        63:b6:ad:b4:de:9a:fb:26:f7:00:27:c0:5d:55:37:74:99:c9:
+        50:7f:e3:59:2e:44:e3:2c:25:ee:ec:4c:32:77:b4:9f:1a:e9:
+        4b:5d:20:c5:da:fd:1c:87:16:c6:43:e8:d4:bb:26:9a:45:70:
+        5e:a9:0b:37:53:e2:46:7b:27:fd:e0:46:f2:89:b7:cc:42:b6:
+        cb:28:26:6e:d9:a5:c9:3a:c8:41:13:60:f7:50:8c:15:ae:b2:
+        6d:1a:15:1a:57:78:e6:92:2a:d9:65:90:82:3f:6c:02:af:ae:
+        12:3a:27:96:36:04:d7:1d:a2:80:63:a9:9b:f1:e5:ba:b4:7c:
+        14:b0:4e:c9:b1:1f:74:5f:38:f6:51:ea:9b:fa:2c:a2:11:d4:
+        a9:2d:27:1a:45:b1:af:b2:4e:71:0d:c0:58:46:d6:69:06:cb:
+        53:cb:b3:fe:6b:41:cd:41:7e:7d:4c:0f:7c:72:79:7a:59:cd:
+        5e:4a:0e:ac:9b:a9:98:73:79:7c:b4:f4:cc:b9:b8:07:0c:b2:
+        74:5c:b8:c7:6f:88:a1:90:a7:f4:aa:f9:bf:67:3a:f4:1a:15:
+        62:1e:b7:9f:be:3d:b1:29:af:67:a1:12:f2:58:10:19:53:03:
+        30:1b:b8:1a:89:f6:9c:bd:97:03:8e:a3:09:f3:1d:8b:21:f1:
+        b4:df:e4:1c:d1:9f:65:02:06:ea:5c:d6:13:b3:84:ef:a2:a5:
+        5c:8c:77:29:a7:68:c0:6b:ae:40:d2:a8:b4:ea:cd:f0:8d:4b:
+        38:9c:19:9a:1b:28:54:b8:89:90:ef:ca:75:81:3e:1e:f2:64:
+        24:c7:18:af:4e:ff:47:9e:07:f6:35:65:a4:d3:0a:56:ff:f5:
+        17:64:6c:ef:a8:22:25:49:93:b6:df:00:17:da:58:7e:5d:ee:
+        c5:1b:b0:d1:d1:5f:21:10:c7:f9:f3:ba:02:0a:27:07:c5:f1:
+        d6:c7:d3:e0:fb:09:60:6c
 SHA1 Fingerprint=5A:8C:EF:45:D7:A6:98:59:76:7A:8C:8B:44:96:B5:78:CF:47:4B:1A
 -----BEGIN CERTIFICATE-----
 MIIFQTCCAymgAwIBAgITBmyf0pY1hp8KD+WGePhbJruKNzANBgkqhkiG9w0BAQwF
diff --git a/secure/caroot/trusted/Amazon_Root_CA_3.pem b/secure/caroot/trusted/Amazon_Root_CA_3.pem
index 1e45a816b669..0baa14e92de3 100644
--- a/secure/caroot/trusted/Amazon_Root_CA_3.pem
+++ b/secure/caroot/trusted/Amazon_Root_CA_3.pem
@@ -41,10 +41,11 @@ Certificate:
             X509v3 Subject Key Identifier: 
                 AB:B6:DB:D7:06:9E:37:AC:30:86:07:91:70:C7:9C:C4:19:B1:78:C0
     Signature Algorithm: ecdsa-with-SHA256
-         30:46:02:21:00:e0:85:92:a3:17:b7:8d:f9:2b:06:a5:93:ac:
-         1a:98:68:61:72:fa:e1:a1:d0:fb:1c:78:60:a6:43:99:c5:b8:
-         c4:02:21:00:9c:02:ef:f1:94:9c:b3:96:f9:eb:c6:2a:f8:b6:
-         2c:fe:3a:90:14:16:d7:8c:63:24:48:1c:df:30:7d:d5:68:3b
+    Signature Value:
+        30:46:02:21:00:e0:85:92:a3:17:b7:8d:f9:2b:06:a5:93:ac:
+        1a:98:68:61:72:fa:e1:a1:d0:fb:1c:78:60:a6:43:99:c5:b8:
+        c4:02:21:00:9c:02:ef:f1:94:9c:b3:96:f9:eb:c6:2a:f8:b6:
+        2c:fe:3a:90:14:16:d7:8c:63:24:48:1c:df:30:7d:d5:68:3b
 SHA1 Fingerprint=0D:44:DD:8C:3C:8C:1A:1A:58:75:64:81:E9:0F:2E:2A:FF:B3:D2:6E
 -----BEGIN CERTIFICATE-----
 MIIBtjCCAVugAwIBAgITBmyf1XSXNmY/Owua2eiedgPySjAKBggqhkjOPQQDAjA5
diff --git a/secure/caroot/trusted/Amazon_Root_CA_4.pem b/secure/caroot/trusted/Amazon_Root_CA_4.pem
index 889f1dc33d52..06ccb20544dc 100644
--- a/secure/caroot/trusted/Amazon_Root_CA_4.pem
+++ b/secure/caroot/trusted/Amazon_Root_CA_4.pem
@@ -43,12 +43,13 @@ Certificate:
             X509v3 Subject Key Identifier: 
                 D3:EC:C7:3A:65:6E:CC:E1:DA:76:9A:56:FB:9C:F3:86:6D:57:E5:81
     Signature Algorithm: ecdsa-with-SHA384
-         30:65:02:30:3a:8b:21:f1:bd:7e:11:ad:d0:ef:58:96:2f:d6:
-         eb:9d:7e:90:8d:2b:cf:66:55:c3:2c:e3:28:a9:70:0a:47:0e:
-         f0:37:59:12:ff:2d:99:94:28:4e:2a:4f:35:4d:33:5a:02:31:
-         00:ea:75:00:4e:3b:c4:3a:94:12:91:c9:58:46:9d:21:13:72:
-         a7:88:9c:8a:e4:4c:4a:db:96:d4:ac:8b:6b:6b:49:12:53:33:
-         ad:d7:e4:be:24:fc:b5:0a:76:d4:a5:bc:10
+    Signature Value:
+        30:65:02:30:3a:8b:21:f1:bd:7e:11:ad:d0:ef:58:96:2f:d6:
+        eb:9d:7e:90:8d:2b:cf:66:55:c3:2c:e3:28:a9:70:0a:47:0e:
+        f0:37:59:12:ff:2d:99:94:28:4e:2a:4f:35:4d:33:5a:02:31:
+        00:ea:75:00:4e:3b:c4:3a:94:12:91:c9:58:46:9d:21:13:72:
+        a7:88:9c:8a:e4:4c:4a:db:96:d4:ac:8b:6b:6b:49:12:53:33:
+        ad:d7:e4:be:24:fc:b5:0a:76:d4:a5:bc:10
 SHA1 Fingerprint=F6:10:84:07:D6:F8:BB:67:98:0C:C2:E2:44:C2:EB:AE:1C:EF:63:BE
 -----BEGIN CERTIFICATE-----
 MIIB8jCCAXigAwIBAgITBmyf18G7EEwpQ+Vxe3ssyBrBDjAKBggqhkjOPQQDAzA5
diff --git a/secure/caroot/trusted/Atos_TrustedRoot_2011.pem b/secure/caroot/trusted/Atos_TrustedRoot_2011.pem
index b65333ef383d..736143dc94ff 100644
--- a/secure/caroot/trusted/Atos_TrustedRoot_2011.pem
+++ b/secure/caroot/trusted/Atos_TrustedRoot_2011.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: CN = Atos TrustedRoot 2011, O = Atos, C = DE
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:95:85:3b:97:6f:2a:3b:2e:3b:cf:a6:f3:29:35:
                     be:cf:18:ac:3e:aa:d9:f8:4d:a0:3e:1a:47:b9:bc:
@@ -50,29 +50,28 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Authority Key Identifier: 
*** 10317 LINES SKIPPED ***