https://bugs.winehq.org/show_bug.cgi?id=47234
Bug ID: 47234 Summary: Wine fails to properly parse and import some of the standard root certificates Product: Wine Version: 4.7 Hardware: x86 OS: Linux Status: UNCONFIRMED Severity: major Priority: P2 Component: crypt32 Assignee: wine-bugs@winehq.org Reporter: oakad@yahoo.com Distribution: ---
While starting a wine application on Fedora 30 instance, quite a few of the root certificates can not be imported by Wine because of what appears to be a certificate parser bug. The remaining certificates still work, but those may be not enough and the bug may affect custom certificates as well.
004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0x103be8: version 2 004b:trace:chain:dump_element issued by L"thawte Primary Root CA - G2" 004b:trace:chain:dump_element issued to L"thawte Primary Root CA - G2" 004b:trace:chain:dump_element valid from 11/5/2007 to 1/18/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xfeca8: version 2 004b:trace:chain:dump_element issued by L"VeriSign Class 3 Public Primary Certification Authority - G4" 004b:trace:chain:dump_element issued to L"VeriSign Class 3 Public Primary Certification Authority - G4" 004b:trace:chain:dump_element valid from 11/5/2007 to 1/18/2038 004b:trace:chain:dump_element 4 extensions 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "1.3.6.1.5.5.7.1.12" (not critical) 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xfb668: version 2 004b:trace:chain:dump_element issued by L"USERTrust ECC Certification Authority" 004b:trace:chain:dump_element issued to L"USERTrust ECC Certification Authority" 004b:trace:chain:dump_element valid from 2/1/2010 to 1/18/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xc9478: version 2 004b:trace:chain:dump_element issued by L"SSL.com Root Certification Authority ECC" 004b:trace:chain:dump_element issued to L"SSL.com Root Certification Authority ECC" 004b:trace:chain:dump_element valid from 2/12/2016 to 2/12/2041 004b:trace:chain:dump_element 4 extensions 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.35" (not critical) 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_DIGITAL_SIGNATURE_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6\6850\091d" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xd8798: version 2 004b:trace:chain:dump_element issued by L"SSL.com EV Root Certification Authority ECC" 004b:trace:chain:dump_element issued to L"SSL.com EV Root Certification Authority ECC" 004b:trace:chain:dump_element valid from 2/12/2016 to 2/12/2041 004b:trace:chain:dump_element 4 extensions 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.35" (not critical) 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_DIGITAL_SIGNATURE_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6\80d0\091d" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xc29a8: version 2 004b:trace:chain:dump_element issued by L"OISTE WISeKey Global Root GC CA" 004b:trace:chain:dump_element issued to L"OISTE WISeKey Global Root GC CA" 004b:trace:chain:dump_element valid from 5/9/2017 to 5/9/2042 004b:trace:chain:dump_element 4 extensions 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:dump_extension "1.3.6.1.4.1.311.21.1" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_name_constraints 0 excluded subtrees: 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xb0fc8: version 2 004b:trace:chain:dump_element issued by L"Hellenic Academic and Research Institutions ECC RootCA 2015" 004b:trace:chain:dump_element issued to L"Hellenic Academic and Research Institutions ECC RootCA 2015" 004b:trace:chain:dump_element valid from 7/7/2015 to 6/30/2040 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xae008: version 2 004b:trace:chain:dump_element issued by L"GlobalSign" 004b:trace:chain:dump_element issued to L"GlobalSign" 004b:trace:chain:dump_element valid from 11/13/2012 to 1/19/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xa7888: version 2 004b:trace:chain:dump_element issued by L"GlobalSign" 004b:trace:chain:dump_element issued to L"GlobalSign" 004b:trace:chain:dump_element valid from 11/13/2012 to 1/19/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\bdf7\c5f5\e4be\cd43\718a\1bf0\ab31\8a06\95ee\75ef\e619\6c12\d6db\c9bb\6aee\e300\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xac358: version 2 004b:trace:chain:dump_element issued by L"GeoTrust Primary Certification Authority - G2" 004b:trace:chain:dump_element issued to L"GeoTrust Primary Certification Authority - G2" 004b:trace:chain:dump_element valid from 11/5/2007 to 1/18/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xa3f78: version 2 004b:trace:chain:dump_element issued by L"Entrust Root Certification Authority - EC1" 004b:trace:chain:dump_element issued to L"Entrust Root Certification Authority - EC1" 004b:trace:chain:dump_element valid from 12/18/2012 to 12/18/2037 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0xa68b8: version 2 004b:trace:chain:dump_element issued by L"DigiCert Global Root G3" 004b:trace:chain:dump_element issued to L"DigiCert Global Root G3" 004b:trace:chain:dump_element valid from 8/1/2013 to 1/15/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_DIGITAL_SIGNATURE_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0x937b8: version 2 004b:trace:chain:dump_element issued by L"DigiCert Assured ID Root G3" 004b:trace:chain:dump_element issued to L"DigiCert Assured ID Root G3" 004b:trace:chain:dump_element valid from 8/1/2013 to 1/15/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_DIGITAL_SIGNATURE_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028 -- 004b:trace:chain:dump_basic_constraints2 path length=0 004b:trace:chain:CertGetCertificateChain error status: 00000020 004b:trace:chain:dump_chain_para 32 004b:trace:chain:CRYPT_CheckSimpleChain checking chain with 1 elements for time (null) 004b:trace:chain:dump_element 0x942a8: version 2 004b:trace:chain:dump_element issued by L"COMODO ECC Certification Authority" 004b:trace:chain:dump_element issued to L"COMODO ECC Certification Authority" 004b:trace:chain:dump_element valid from 3/6/2008 to 1/18/2038 004b:trace:chain:dump_element 3 extensions 004b:trace:chain:dump_extension "2.5.29.14" (not critical) 004b:trace:chain:dump_extension "2.5.29.15" (critical) 004b:trace:chain:dump_key_usage CERT_KEY_CERT_SIGN_KEY_USAGE 004b:trace:chain:dump_key_usage CERT_CRL_SIGN_KEY_USAGE 004b:trace:chain:dump_extension "2.5.29.19" (critical) 004b:trace:chain:dump_basic_constraints2 basic constraints: 004b:trace:chain:dump_basic_constraints2 can be a CA 004b:trace:chain:dump_basic_constraints2 doesn't have path length constraint 004b:trace:chain:dump_basic_constraints2 path length=0 004b:fixme:bcrypt:BCryptOpenAlgorithmProvider algorithm L"\377f\9eec\d340\4879\1a44\ad71\0dc0\aca8\4b4f\c055\19df\8cba\d67c\e6b2\03b0\6212\2dc5\e797\46d4\f60e\c322\68b2\3b93\475e\4db3\d630\592d\8d33\caf6\3f30\2210\5ee6" not supported 004b:trace:chain:CRYPT_CheckRootCert Last certificate's signature is invalid 004b:trace:chain:CertGetCertificateChain error status: 00000028