Greetings

I'm are trying to configure apache with client authentication using some commercial certificates, but we are getting troubles with it. In Apache logs we can see the following error *Certificate Verification: Error (20): unable to get local issuer certificate*

I tried to verify the certificate using OpenSSL first and as I expected I got the same error, but I really don't know why...

The certificate hierarchy is the following (from root to the leaf):

Global -> ACCamerfirma -> racer -> prueba

I can successfully verify the certificate chain till the leaf, where I always get the error mentioned before. I tried the same steps using the CAPath flag (creating the hash links as well) and I get the same...


   * *Global.pem* is one of the Root certificates accepted by Mozilla
     foundation


   * *ACCamerfirma verification* - OK


/[amsterdam:~/test]# openssl verify -CAfile Global.pem ACCamerfirma.pem
ACCamerfirma.cer: OK/


   * *RACER verification* (trustedCAs.pem contains both Global.pem and
     ACCamerfirma.pem certificates) - OK


/[amsterdam:~/test]# openssl verify -CAfile trustedCAs.pem racer.pem
racer.pem: OK
/

   * but when I try to verify *prueba.pem*... (note that now,
     trustedCAs contains Global.pem, ACCamerfirma.pem and racer.pem
     certificates)


/[amsterdam:~/test/]# openssl verify -CAfile trustedCAs.pem prueba.pem
prueba.pem: /C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
*error 20 at 0 depth lookup:unable to get local issuer certificate*/

From this error, I understand that OpenSSL isn't able to find the issuer of the certificate I'm verifying. So, reading the documentation, I've noticed that first, OpenSSL checks issuer/subject match and, then the Authority Key Identifier/Subject Key Identifier. Also, the CA certificate has to have the Certificate Sign Key Usage. So I checked this

   * *prueba.pem: issuer*

/[amsterdam:~/test]# openssl x509 -in prueba.pem -issuer -noout
issuer= /C=ES/emailaddress=cara...@camerfirma.com/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma SA/CN=RACER

/

   * /*racer.pem: subject*/

/[amsterdam:~/test]# openssl x509 -in racer.pem -subject -noout
subject= /C=ES/emailaddress=cara...@camerfirma.com/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma SA/CN=RACER


/As you can see, they match. I also checked the results using *the issuer_hash and subject_hash flags* and they are the same



I also checked the AuthorityKeyIdentifier and SubjectKeyIdentifier

   * *prueba.pem: AuthorityKeyIdentifier*


[amsterdam:~/test]# openssl x509 -in prueba.pem -text -noout
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            58:71:1b:db:5f:f3:4f:4b
        Signature Algorithm: sha1WithRSAEncryption
Issuer: C=ES/emailaddress=cara...@camerfirma.com, L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287, O=AC Camerfirma SA, CN=RACER
        Validity
            Not Before: Aug 18 08:16:47 2010 GMT
            Not After : Aug 17 08:26:47 2012 GMT
Subject: C=ES/emailaddress=rali...@indenova.com, SN=indenova1808/serialNumber=96588742N, GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111, O=demo, OU=demo, CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (1024 bit)
                Modulus (1024 bit):
                    00:a7:c0:58:b9:ce:67:e3:2c:ae:af:80:01:b1:7f:
                    2e:3a:47:f7:c6:02:2a:90:b0:79:4b:2a:a4:55:22:
                    3e:7c:94:ef:00:dc:c3:bd:86:3b:7b:fa:66:56:ff:
                    f1:51:7e:1b:8f:d4:9f:83:73:9f:ac:ad:c5:ae:d1:
                    0a:1c:30:a7:35:e3:44:44:22:e5:66:2e:09:e3:97:
                    d4:a3:40:24:b7:6c:c6:e3:19:27:8d:74:06:2d:2e:
                    b1:3b:6f:6d:f7:44:59:8a:9f:f4:d6:a0:36:6e:1f:
                    a6:00:d8:1f:37:2a:e2:e7:cb:45:6e:ee:9a:29:70:
                    57:63:63:76:79:3d:fb:8c:bf
                Exponent: 3 (0x3)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Key Usage: critical
Digital Signature, Non Repudiation, Key Encipherment, Data Encipherment, Key Agreement
            X509v3 Extended Key Usage:
TLS Web Client Authentication, E-mail Protection, Microsoft Smartcardlogin
            X509v3 Subject Key Identifier:
                0F:F3:9F:CC:D3:A2:82:4E:48:2E:61:38:37:81:21:14:46:DA:0B:26
            Authority Information Access:
                OCSP - URI:http://ocsp.camerfirma.com
                CA Issuers - URI:http://www.camerfirma.com/certs/racer.crt

*X509v3 Authority Key Identifier:
keyid:BE:BC:08:D4:2E:BA:00:4C:80:DC:26:67:B4:A5:D8:DD:C3:4A:1A:F9* DirName:/C=ES/emailaddress=cara...@camerfirma.com/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma SA/CN=RACER
                serial:01

            X509v3 CRL Distribution Points:
                URI:http://crl.camerfirma.com/racer_f.crl

            X509v3 Subject Alternative Name:
                email:rali...@indenova.com
            X509v3 Issuer Alternative Name:
                email:cara...@camerfirma.com
            X509v3 Certificate Policies:
                Policy: 1.3.6.1.4.1.17326.10.8.2.1.1
                  CPS: https://policy.camerfirma.com
                  User Notice:
Explicit Text: Qualified Certificate - Registrant: RA_ENDESA - Subject Statement: https://subjectstatement.camerfirma.com/RA_ENDESA.html

            qcStatements:
                0!0......F..0......F..0...EUR......
    Signature Algorithm: sha1WithRSAEncryption
        13:83:0f:92:08:3f:7a:d0:c9:80:3c:d6:3d:29:18:d9:20:33:
        d7:c7:ab:10:a5:c3:34:dd:63:f4:c3:50:38:c9:37:f6:a0:5f:
        7d:d4:2c:e5:bc:85:66:83:d7:91:03:b1:13:4f:6c:e5:23:1a:
        9c:54:ec:46:42:47:44:30:34:29:e8:62:c0:4d:d6:59:13:1d:
        2a:81:81:db:2c:40:f7:e3:cc:52:ff:6a:4f:d3:bd:ea:7c:62:
        10:ec:54:57:ad:b5:c5:c4:8f:e6:83:3c:83:e4:43:71:91:ce:
        a7:34:a6:51:92:7a:69:7c:c5:cc:36:3f:7d:a4:35:e5:7a:0b:
        6a:12:58:16:a2:ca:6d:c3:3d:73:fc:93:78:45:98:5e:4a:50:
        65:48:ba:d9:8f:54:31:3f:4a:9d:a6:6c:35:8a:7c:0e:e1:07:
        d0:7b:70:04:2b:45:08:fc:a8:d6:7d:26:e7:9f:2e:d5:0c:16:
        f3:fd:1f:88:a2:07:5b:4d:10:7e:85:63:b3:6a:b1:f9:6e:4f:
        e2:c0:90:ca:93:f6:e8:6c:82:6c:92:72:ff:60:41:46:3d:bb:
        45:21:ea:81:fd:f5:e9:26:93:5e:08:d1:8d:28:45:34:7f:ae:
        6b:1c:ef:fb:1b:8f:0c:ef:b8:c7:00:0a:88:e2:79:eb:e7:6d:
        e4:55:74:39

   * *racer.pem: Subject Key Identifier*

[amsterdam:~/test]# openssl x509 -in racer.pem -text -noout
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 1 (0x1)
        Signature Algorithm: sha1WithRSAEncryption
Issuer: C=ES/emailaddress=ac_camerfi...@camerfirma.com/serialNumber=A82743287, L=Madrid (see current address at www.camerfirma.com/address), O=AC Camerfirma SA, CN=AC Camerfirma
        Validity
            Not Before: Dec  4 17:26:41 2003 GMT
            Not After : Dec  4 17:26:41 2023 GMT
Subject: C=ES/emailaddress=cara...@camerfirma.com, L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287, O=AC Camerfirma SA, CN=RACER
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2047 bit)
                Modulus (2047 bit):
                    7b:4d:f2:cb:51:d9:c6:0b:5d:83:56:f6:36:87:17:
                    aa:d3:3b:df:1e:bd:f7:69:20:f5:f7:9e:70:4d:ed:
                    df:a3:40:75:89:b2:fa:88:7a:30:aa:d3:dc:22:10:
                    46:21:cb:9b:ef:d1:cb:2b:9d:0f:aa:34:0f:42:cd:
                    78:6a:d1:62:97:05:c3:bc:c4:39:85:ff:98:c1:93:
                    21:72:8b:3e:4b:bb:05:da:02:be:0c:b1:e1:a9:b2:
                    06:28:19:57:a0:23:1a:7e:3e:c4:8c:d0:cb:99:63:
                    3b:25:65:9d:f1:5f:23:8f:5a:c2:47:d7:d3:e0:4d:
                    bf:9a:96:2a:9b:21:83:e5:a7:14:e5:b5:19:dd:0c:
                    25:73:07:ea:e3:6c:bb:6f:c7:76:a4:a0:b2:f5:10:
                    d5:d4:0d:7a:52:b1:cf:e1:1b:4d:f8:ae:c3:e1:f0:
                    81:06:e9:7f:f9:ec:7b:8a:06:bf:47:2a:d2:90:3c:
                    e6:07:44:a0:ef:9f:2c:ec:11:67:c0:ce:7c:06:95:
                    60:04:e7:a9:f4:ef:61:ec:70:61:87:10:ec:d5:83:
                    c4:25:f4:e6:25:6c:e7:5a:db:b7:94:2b:c0:8a:bf:
                    4a:de:cb:ff:ac:50:77:ef:b4:9a:57:c0:26:80:bb:
                    4c:5e:42:6a:ca:a1:da:e4:b9:29:23:20:23:d5:8f:
                    c3
                Exponent: 3 (0x3)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:10
            X509v3 CRL Distribution Points:
                URI:http://crl.camerfirma.com/racer.crl

*X509v3 Subject Key Identifier:
BE:BC:08:D4:2E:BA:00:4C:80:DC:26:67:B4:A5:D8:DD:C3:4A:1A:F9*
            X509v3 Authority Key Identifier:
keyid:70:C1:95:FA:5D:A5:16:BE:62:E8:A4:7D:E3:D4:64:5F:C4:E1:3E:9D DirName:/C=EU/O=AC Camerfirma SA CIF A82743287/OU=http://www.chambersign.org/CN=Global Chambersign Root
                serial:02

            Authority Information Access:
CA Issuers - URI:http://www.camerfirma.com/certs/ac_camerfirma.crt

* X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign*
            X509v3 Subject Alternative Name:
                email:cara...@camerfirma.com
            X509v3 Issuer Alternative Name:
                email:ac_camerfi...@camerfirma.com
            X509v3 Certificate Policies:
                Policy: 1.3.6.1.4.1.17326.10.8.1
                  CPS: http://cps.camerfirma.com/cps/racer.html

    Signature Algorithm: sha1WithRSAEncryption
        54:fa:8e:00:b0:f1:97:61:7c:ae:0b:ba:ec:e7:2a:a2:63:17:
        47:76:8f:23:21:44:e2:61:5e:28:ec:d5:a5:01:6c:45:1c:e4:
        96:cd:dc:d5:90:d3:19:89:55:87:d5:e7:2f:80:08:04:9f:d4:
        d6:e9:11:90:6b:88:64:72:18:51:68:8d:00:35:9d:d0:72:26:
        3d:be:47:ce:08:a9:d1:1f:5d:35:73:f6:4a:b4:a8:e1:dd:a2:
        07:b8:2a:47:ce:97:d6:dd:db:8d:d7:f5:e7:63:ee:0a:6f:ed:
        13:ab:25:99:1d:77:56:a2:a6:8d:27:75:b1:8c:53:34:02:9e:
        3e:ed:c8:60:36:60:18:b9:cd:15:dd:ea:37:64:1b:3d:6a:ba:
        f5:9f:f5:aa:5f:bb:2f:b6:b5:e5:35:dc:04:d4:17:b1:f4:04:
        38:b1:b1:e6:2f:59:78:d0:d5:9a:94:87:27:ab:30:1c:ed:c6:
        aa:5d:a7:fe:a3:6e:34:78:1b:c3:bf:90:65:f6:47:6a:bc:b6:
        02:b8:0c:09:4d:92:9a:90:a6:a7:26:e4:b6:bb:8a:c0:66:de:
        95:01:d8:0b:6a:09:6a:f4:c7:a0:b7:79:19:e1:c8:e0:68:af:
        3c:81:3d:73:18:73:7f:c5:e3:65:71:02:28:be:78:6b:fe:28:
        f4:84:81:70


They also match. And racer.pem also has the the *Certificate Sign key usage*

I also checked the information given by the issuer_checks flag, and I get this

prueba.pem: /C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
*error 29 at 0 depth lookup:subject issuer mismatch*
/C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
error 29 at 0 depth lookup:subject issuer mismatch
/C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
error 29 at 0 depth lookup:subject issuer mismatch
/C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
error 31 at 0 depth lookup:authority and issuer serial number mismatch
/C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
error 31 at 0 depth lookup:authority and issuer serial number mismatch
/C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
error 29 at 0 depth lookup:subject issuer mismatch
/C=ES/emailaddress=rali...@indenova.com/SN=indenova1808/serialNumber=96588742N/GN=prueba/1.3.6.1.4.1.17326.30.2=CIF/1.3.6.1.4.1.17326.30.3=B11111111/O=demo/OU=demo/CN=prueba indenova1808/title=demo/description=RACER: Natural Person RACER-PF-1.1.1
error 20 at 0 depth lookup:unable to get local issuer certificate


The first error I get says that subject issuer doesn't match... but as u can see they are the same!!!

Honestly, I have no idea what I'm doing wrong.. I've checked all the requirements OpenSSL needs and the certificates fulfill them all...

Could you please help me? I'm getting desperate...

I attach the certificates

   * *Global.cer*


-----BEGIN CERTIFICATE-----
MIIExTCCA62gAwIBAgIBADANBgkqhkiG9w0BAQUFADB9MQswCQYDVQQGEwJFVTEn
MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4GA1UEAxMXR2xvYmFsIENo
YW1iZXJzaWduIFJvb3QwHhcNMDMwOTMwMTYxNDE4WhcNMzcwOTMwMTYxNDE4WjB9
MQswCQYDVQQGEwJFVTEnMCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgy
NzQzMjg3MSMwIQYDVQQLExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4G
A1UEAxMXR2xvYmFsIENoYW1iZXJzaWduIFJvb3QwggEgMA0GCSqGSIb3DQEBAQUA
A4IBDQAwggEIAoIBAQCicKLQn0KuWxfH2H3PFIP8T8mhtxOviteePgQKkotgVvq0
Mi+ITaFgCPS3CU6gSS9J1tPfnZdan5QEcOw/Wdm3zGaLmFIoCQLfxS+EjXqXd7/s
QJ0lcqu1PzKY+7e3/HKE5TWH+VX6ox8Oby4o3Wmg2UIQxvi1RMLQQ3/bvOSiPGpV
eAp3qdjqGTK3L/5cPxvusZjsyq16aUXjlg9V9ubtdepl6DJWk0aJqCWKZQbua795
B9Dxt6/tLE2Su8CoX6dnfQTyFQhwrJLWfQTSM/tMtgsL+xrJxI0DqX5c8lCrEqWh
z0hQpe/SyBoT+rB/sYIcd2oPX9wLlY/vQ37mRQklAgEDo4IBUDCCAUwwEgYDVR0T
AQH/BAgwBgEB/wIBDDA/BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vY3JsLmNoYW1i
ZXJzaWduLm9yZy9jaGFtYmVyc2lnbnJvb3QuY3JsMB0GA1UdDgQWBBRDnDafsJ4w
TcbOX60Qq+UDpfqpFDAOBgNVHQ8BAf8EBAMCAQYwEQYJYIZIAYb4QgEBBAQDAgAH
MCoGA1UdEQQjMCGBH2NoYW1iZXJzaWducm9vdEBjaGFtYmVyc2lnbi5vcmcwKgYD
VR0SBCMwIYEfY2hhbWJlcnNpZ25yb290QGNoYW1iZXJzaWduLm9yZzBbBgNVHSAE
VDBSMFAGCysGAQQBgYcuCgEBMEEwPwYIKwYBBQUHAgEWM2h0dHA6Ly9jcHMuY2hh
bWJlcnNpZ24ub3JnL2Nwcy9jaGFtYmVyc2lnbnJvb3QuaHRtbDANBgkqhkiG9w0B
AQUFAAOCAQEAPDtwkfkEVCeR4e3t/mh/YV3lQWVPMvEYBZRqHN4fcNs+ezICNLUM
bKGKfKX0j//U2K0X1S0E0T9YgOKBWYi+wONGkyT+kL0mojAt6JcmVzWJdJYY9hXi
ryQZVgICsroPFOrGimbBhkVVi76SvpykBMdJPJ7oKXqJ1/6v/2j1pReQvayZzKWG
VwlnRtvWFsJG8eSpUPWP0ZIV018+xgBJOm5YstHRJw0lyDL4IBHNfTIzSJRUTN3c
ecQwn+uOuFW114hcxWokPbLTBQNRxgfvzBRydD1ucs4YKIxKoHflCStFREest2d/
AYoFWpO+ocH/+OcOZ6RHSXZddZAa9SaP8A==
-----END CERTIFICATE-----


   * *ACCamerfirma.pem*

-----BEGIN CERTIFICATE-----
MIIFnTCCBIWgAwIBAgIBAjANBgkqhkiG9w0BAQUFADB9MQswCQYDVQQGEwJFVTEn
MCUGA1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQL
ExpodHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4GA1UEAxMXR2xvYmFsIENo
YW1iZXJzaWduIFJvb3QwHhcNMDMxMTE0MTM0OTA4WhcNMzMxMTE0MTM0OTA4WjCB
xjELMAkGA1UEBhMCRVMxKzApBgkqhkiG9w0BCQEWHGFjX2NhbWVyZmlybWFAY2Ft
ZXJmaXJtYS5jb20xEjAQBgNVBAUTCUE4Mjc0MzI4NzFDMEEGA1UEBxM6TWFkcmlk
IChzZWUgY3VycmVudCBhZGRyZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRy
ZXNzKTEZMBcGA1UEChMQQUMgQ2FtZXJmaXJtYSBTQTEWMBQGA1UEAxMNQUMgQ2Ft
ZXJmaXJtYTCCAR8wDQYJKoZIhvcNAQEBBQADggEMADCCAQcCggEAcYlZO6/h24nT
orYU6BTdGuIYtxRc6TdV3SAClsN/rZFFVkTjXgfNmnFXZEuSVqAihLOrbtMaCG6l
Km5S6bnAckqonY3n9qhbkY4pzqMkltgBL86BhrZehbr+gGWN6mx8RcAXpvj3Vr8h
SpWfts0F+5rmJocAC/gEekSYiIvstRErXUke1plsmzpo5i++4YJTI4EQZ8cMwQjt
wbHTqe0FR8jcnSU001c031EmXvMje8XtnrfAiSoD4nVq9V0pSZW2kFeDT4JihjZm
ly3ec0j8MkcqcY5KBHv+0nuGYRYQSHDl3f2Zu7AnPGbkWhGaBn+SeVbpuCbxk8vy
Vp4IptTxFwIBA6OCAd8wggHbMBIGA1UdEwEB/wQIMAYBAf8CAQswPAYDVR0fBDUw
MzAxoC+gLYYraHR0cDovL2NybC5jYW1lcmZpcm1hLmNvbS9hY19jYW1lcmZpcm1h
LmNybDAdBgNVHQ4EFgQUcMGV+l2lFr5i6KR949RkX8ThPp0wgagGA1UdIwSBoDCB
nYAUQ5w2n7CeME3Gzl+tEKvlA6X6qRShgYGkfzB9MQswCQYDVQQGEwJFVTEnMCUG
A1UEChMeQUMgQ2FtZXJmaXJtYSBTQSBDSUYgQTgyNzQzMjg3MSMwIQYDVQQLExpo
dHRwOi8vd3d3LmNoYW1iZXJzaWduLm9yZzEgMB4GA1UEAxMXR2xvYmFsIENoYW1i
ZXJzaWduIFJvb3SCAQAwDgYDVR0PAQH/BAQDAgGGMCcGA1UdEQQgMB6BHGFjX2Nh
bWVyZmlybWFAY2FtZXJmaXJtYS5jb20wKgYDVR0SBCMwIYEfY2hhbWJlcnNpZ25y
b290QGNoYW1iZXJzaWduLm9yZzBYBgNVHSAEUTBPME0GCysGAQQBgYcuCgQBMD4w
PAYIKwYBBQUHAgEWMGh0dHA6Ly9jcHMuY2FtZXJmaXJtYS5jb20vY3BzL2FjX2Nh
bWVyZmlybWEuaHRtbDANBgkqhkiG9w0BAQUFAAOCAQEAP9WJ1qa16NtY9/a3dTmC
QAVbr6XR2tFA6rleKf/Aa9DMLPAoIOA2rEN80jbT0ajC4LKmCt3lOyCYWg8Tekq8
xj/gANyOD2BKmGsuhLhY/rxuzKUEhxWqqmPmJmDXOGrghHOKhztN/ean5gl+haoO
b7XIpxw70vbdYX+b1L19w8An5bqJZfsaQ9u10aolVFWEGDPbRB6Nc7zxILc/Dl4O
rjLBmA9ppOcTyiBWhpw607UOt4YVnns1YwlPAoNmMeEVOoDDUAm7Gx53DwSFCs3N
4xTxu3qGLwTVWAxrv/ZjS3fOKzbg1X7ytL4KFdwcftfRexHgfWi9JBb9Uh/495q7
bg==
-----END CERTIFICATE-----


   * *racer.pem*

-----BEGIN CERTIFICATE-----
MIIGDzCCBPegAwIBAgIBATANBgkqhkiG9w0BAQUFADCBxjELMAkGA1UEBhMCRVMx
KzApBgkqhkiG9w0BCQEWHGFjX2NhbWVyZmlybWFAY2FtZXJmaXJtYS5jb20xEjAQ
BgNVBAUTCUE4Mjc0MzI4NzFDMEEGA1UEBxM6TWFkcmlkIChzZWUgY3VycmVudCBh
ZGRyZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTEZMBcGA1UEChMQ
QUMgQ2FtZXJmaXJtYSBTQTEWMBQGA1UEAxMNQUMgQ2FtZXJmaXJtYTAeFw0wMzEy
MDQxNzI2NDFaFw0yMzEyMDQxNzI2NDFaMIG4MQswCQYDVQQGEwJFUzElMCMGCSqG
SIb3DQEJARYWY2FyYWNlckBjYW1lcmZpcm1hLmNvbTFDMEEGA1UEBxM6TWFkcmlk
IChzZWUgY3VycmVudCBhZGRyZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRy
ZXNzKTESMBAGA1UEBRMJQTgyNzQzMjg3MRkwFwYDVQQKExBBQyBDYW1lcmZpcm1h
IFNBMQ4wDAYDVQQDEwVSQUNFUjCCAR8wDQYJKoZIhvcNAQEBBQADggEMADCCAQcC
ggEAe03yy1HZxgtdg1b2NocXqtM73x6992kg9feecE3t36NAdYmy+oh6MKrT3CIQ
RiHLm+/RyyudD6o0D0LNeGrRYpcFw7zEOYX/mMGTIXKLPku7BdoCvgyx4amyBigZ
V6AjGn4+xIzQy5ljOyVlnfFfI49awkfX0+BNv5qWKpshg+WnFOW1Gd0MJXMH6uNs
u2/HdqSgsvUQ1dQNelKxz+EbTfiuw+HwgQbpf/nse4oGv0cq0pA85gdEoO+fLOwR
Z8DOfAaVYATnqfTvYexwYYcQ7NWDxCX05iVs51rbt5QrwIq/St7L/6xQd++0mlfA
JoC7TF5Casqh2uS5KSMgI9WPwwIBA6OCAhUwggIRMBIGA1UdEwEB/wQIMAYBAf8C
AQowNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL2NybC5jYW1lcmZpcm1hLmNvbS9y
YWNlci5jcmwwHQYDVR0OBBYEFL68CNQuugBMgNwmZ7Sl2N3DShr5MIGoBgNVHSME
gaAwgZ2AFHDBlfpdpRa+YuikfePUZF/E4T6doYGBpH8wfTELMAkGA1UEBhMCRVUx
JzAlBgNVBAoTHkFDIENhbWVyZmlybWEgU0EgQ0lGIEE4Mjc0MzI4NzEjMCEGA1UE
CxMaaHR0cDovL3d3dy5jaGFtYmVyc2lnbi5vcmcxIDAeBgNVBAMTF0dsb2JhbCBD
aGFtYmVyc2lnbiBSb290ggECME0GCCsGAQUFBwEBBEEwPzA9BggrBgEFBQcwAoYx
aHR0cDovL3d3dy5jYW1lcmZpcm1hLmNvbS9jZXJ0cy9hY19jYW1lcmZpcm1hLmNy
dDAOBgNVHQ8BAf8EBAMCAYYwIQYDVR0RBBowGIEWY2FyYWNlckBjYW1lcmZpcm1h
LmNvbTAnBgNVHRIEIDAegRxhY19jYW1lcmZpcm1hQGNhbWVyZmlybWEuY29tMFAG
A1UdIARJMEcwRQYLKwYBBAGBhy4KCAEwNjA0BggrBgEFBQcCARYoaHR0cDovL2Nw
cy5jYW1lcmZpcm1hLmNvbS9jcHMvcmFjZXIuaHRtbDANBgkqhkiG9w0BAQUFAAOC
AQEAVPqOALDxl2F8rgu67OcqomMXR3aPIyFE4mFeKOzVpQFsRRzkls3c1ZDTGYlV
h9XnL4AIBJ/U1ukRkGuIZHIYUWiNADWd0HImPb5Hzgip0R9dNXP2SrSo4d2iB7gq
R86X1t3bjdf152PuCm/tE6slmR13VqKmjSd1sYxTNAKePu3IYDZgGLnNFd3qN2Qb
PWq69Z/1ql+7L7a15TXcBNQXsfQEOLGx5i9ZeNDVmpSHJ6swHO3Gql2n/qNuNHgb
w7+QZfZHary2ArgMCU2SmpCmpybktruKwGbelQHYC2oJavTHoLd5GeHI4GivPIE9
cxhzf8XjZXECKL54a/4o9ISBcA==
-----END CERTIFICATE-----

   * *prueba.pem*

-----BEGIN CERTIFICATE-----
MIIHGTCCBgGgAwIBAgIIWHEb21/zT0swDQYJKoZIhvcNAQEFBQAwgbgxCzAJBgNV
BAYTAkVTMSUwIwYJKoZIhvcNAQkBFhZjYXJhY2VyQGNhbWVyZmlybWEuY29tMUMw
QQYDVQQHEzpNYWRyaWQgKHNlZSBjdXJyZW50IGFkZHJlc3MgYXQgd3d3LmNhbWVy
ZmlybWEuY29tL2FkZHJlc3MpMRIwEAYDVQQFEwlBODI3NDMyODcxGTAXBgNVBAoT
EEFDIENhbWVyZmlybWEgU0ExDjAMBgNVBAMTBVJBQ0VSMB4XDTEwMDgxODA4MTY0
N1oXDTEyMDgxNzA4MjY0N1owggEYMQswCQYDVQQGEwJFUzEjMCEGCSqGSIb3DQEJ
ARYUcmFsaWFnYUBpbmRlbm92YS5jb20xFTATBgNVBAQTDGluZGVub3ZhMTgwODES
MBAGA1UEBRMJOTY1ODg3NDJOMQ8wDQYDVQQqEwZwcnVlYmExEzARBgorBgEEAYGH
Lh4CEwNDSUYxGTAXBgorBgEEAYGHLh4DEwlCMTExMTExMTExDTALBgNVBAoTBGRl
bW8xDTALBgNVBAsTBGRlbW8xHDAaBgNVBAMTE3BydWViYSBpbmRlbm92YTE4MDgx
DTALBgNVBAwTBGRlbW8xLTArBgNVBA0TJFJBQ0VSOiBOYXR1cmFsIFBlcnNvbiBS
QUNFUi1QRi0xLjEuMTCBnTANBgkqhkiG9w0BAQEFAAOBiwAwgYcCgYEAp8BYuc5n
4yyur4ABsX8uOkf3xgIqkLB5SyqkVSI+fJTvANzDvYY7e/pmVv/xUX4bj9Sfg3Of
rK3FrtEKHDCnNeNERCLlZi4J45fUo0Akt2zG4xknjXQGLS6xO29t90RZip/01qA2
bh+mANgfNyri58tFbu6aKXBXY2N2eT37jL8CAQOjggNIMIIDRDAMBgNVHRMBAf8E
AjAAMA4GA1UdDwEB/wQEAwID+DApBgNVHSUEIjAgBggrBgEFBQcDAgYIKwYBBQUH
AwQGCisGAQQBgjcUAgIwHQYDVR0OBBYEFA/zn8zTooJOSC5hODeBIRRG2gsmMG0G
CCsGAQUFBwEBBGEwXzAmBggrBgEFBQcwAYYaaHR0cDovL29jc3AuY2FtZXJmaXJt
YS5jb20wNQYIKwYBBQUHMAKGKWh0dHA6Ly93d3cuY2FtZXJmaXJtYS5jb20vY2Vy
dHMvcmFjZXIuY3J0MIHlBgNVHSMEgd0wgdqAFL68CNQuugBMgNwmZ7Sl2N3DShr5
oYG+pIG7MIG4MQswCQYDVQQGEwJFUzElMCMGCSqGSIb3DQEJARYWY2FyYWNlckBj
YW1lcmZpcm1hLmNvbTFDMEEGA1UEBww6TWFkcmlkIChzZWUgY3VycmVudCBhZGRy
ZXNzIGF0IHd3dy5jYW1lcmZpcm1hLmNvbS9hZGRyZXNzKTESMBAGA1UEBRMJQTgy
NzQzMjg3MRkwFwYDVQQKExBBQyBDYW1lcmZpcm1hIFNBMQ4wDAYDVQQDEwVSQUNF
UoIBATA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLmNhbWVyZmlybWEuY29t
L3JhY2VyX2YuY3JsMB8GA1UdEQQYMBaBFHJhbGlhZ2FAaW5kZW5vdmEuY29tMCEG
A1UdEgQaMBiBFmNhcmFjZXJAY2FtZXJmaXJtYS5jb20wgdUGA1UdIASBzTCByjCB
xwYNKwYBBAGBhy4KCAIBATCBtTApBggrBgEFBQcCARYdaHR0cHM6Ly9wb2xpY3ku
Y2FtZXJmaXJtYS5jb20wgYcGCCsGAQUFBwICMHsaeVF1YWxpZmllZCBDZXJ0aWZp
Y2F0ZSAtIFJlZ2lzdHJhbnQ6IFJBX0VOREVTQSAtIFN1YmplY3QgU3RhdGVtZW50
OiBodHRwczovL3N1YmplY3RzdGF0ZW1lbnQuY2FtZXJmaXJtYS5jb20vUkFfRU5E
RVNBLmh0bWwwLwYIKwYBBQUHAQMEIzAhMAgGBgQAjkYBATAVBgYEAI5GAQIwCxMD
RVVSAgEBAgEBMA0GCSqGSIb3DQEBBQUAA4IBAQATgw+SCD960MmAPNY9KRjZIDPX
x6sQpcM03WP0w1A4yTf2oF991CzlvIVmg9eRA7ETT2zlIxqcVOxGQkdEMDQp6GLA
TdZZEx0qgYHbLED348xS/2pP073qfGIQ7FRXrbXFxI/mgzyD5ENxkc6nNKZRknpp
fMXMNj99pDXlegtqElgWosptwz1z/JN4RZheSlBlSLrZj1QxP0qdpmw1inwO4QfQ
e3AEK0UI/KjWfSbnny7VDBbz/R+IogdbTRB+hWOzarH5bk/iwJDKk/bobIJsknL/
YEFGPbtFIeqB/fXpJpNeCNGNKEU0f65rHO/7G48M77jHAAqI4nnr523kVXQ5
-----END CERTIFICATE-----





--
Un saludo,

Tomás Tormo Franco
Area de sistemas

INDENOVA S.L.
C/ Dels Traginers 14, 2º B
Polígono Vara de Quart
46014 Valencia
Tel. (34) 96 381 99 47
Fax. (34) 96 381 99 48

tto...@indenova.com
http://www.indenova.com

Descárguese gratuitamente el software eSigna Viewer para visualizar documentos 
firmados electrónicamente: http://www.indenova.com/eSignaViewer.php

Reply via email to