17913496 certificates for test suite are expiring
authorYiteng Zhang <yiteng.zhang@oracle.com>
Mon, 16 Dec 2013 10:35:54 -0800
changeset 3000 7cf05f1a8ebd
parent 2999 48ec8afeb87f
child 3001 03042a31cb3f
17913496 certificates for test suite are expiring
src/tests/cli/t_pkg_temp_sources.py
src/tests/ro_data/signing_certs/generate_certs.py
src/tests/ro_data/signing_certs/produced/chain_certs/01.pem
src/tests/ro_data/signing_certs/produced/chain_certs/02.pem
src/tests/ro_data/signing_certs/produced/chain_certs/03.pem
src/tests/ro_data/signing_certs/produced/chain_certs/04.pem
src/tests/ro_data/signing_certs/produced/chain_certs/05.pem
src/tests/ro_data/signing_certs/produced/chain_certs/08.pem
src/tests/ro_data/signing_certs/produced/chain_certs/0A.pem
src/tests/ro_data/signing_certs/produced/chain_certs/0C.pem
src/tests/ro_data/signing_certs/produced/chain_certs/0D.pem
src/tests/ro_data/signing_certs/produced/chain_certs/10.pem
src/tests/ro_data/signing_certs/produced/chain_certs/1A.pem
src/tests/ro_data/signing_certs/produced/chain_certs/1C.pem
src/tests/ro_data/signing_certs/produced/chain_certs/1E.pem
src/tests/ro_data/signing_certs/produced/chain_certs/20.pem
src/tests/ro_data/signing_certs/produced/chain_certs/22.pem
src/tests/ro_data/signing_certs/produced/chain_certs/26.pem
src/tests/ro_data/signing_certs/produced/chain_certs/28.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1.1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1.1_ta4_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1.2_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1.3_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1.4_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta4_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta5_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch2_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch3_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch4.3_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch4_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch5.1_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch5.2_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch5.3_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/chain_certs/ch5_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/06.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/07.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/09.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/0B.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/0E.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/0F.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/11.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/12.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/13.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/14.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/15.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/16.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/17.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/18.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/19.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/1B.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/1D.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/1F.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/21.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/23.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/24.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/25.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/27.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/29.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/2A.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/2B.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.1_ta4_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.2_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.3_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.4_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta4_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta5_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.1_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.2_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.3_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_cs8_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta10_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta11_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta2_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta6_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta7_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta8_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta9_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch1_ta4_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch5_ta1_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs3_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs3_ch1_ta4_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs4_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs5_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs6_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs7_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/code_signing_certs/cs8_ch1_ta3_cert.pem
src/tests/ro_data/signing_certs/produced/combined_cas.pem
src/tests/ro_data/signing_certs/produced/crl/ch1.1_ta4_crl.pem
src/tests/ro_data/signing_certs/produced/crl/ch1_ta4_crl.pem
src/tests/ro_data/signing_certs/produced/crl/ch5_ta1_crl.pem
src/tests/ro_data/signing_certs/produced/crl/ta5_crl.pem
src/tests/ro_data/signing_certs/produced/index
src/tests/ro_data/signing_certs/produced/keys/ch1.1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1.1_ta4_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1.2_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1.3_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1.4_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1_ta4_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch1_ta5_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch2_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch3_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch4.3_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch4_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch5.1_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch5.2_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch5.3_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ch5_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.1_ta4_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.2_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.3_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.4_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta4_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta5_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.1_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.2_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.3_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ch5_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_cs8_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta10_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta11_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta2_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta6_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta7_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta7_reqpass_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta8_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs1_ta9_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs2_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs2_ch1_ta4_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs2_ch5_ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs3_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs3_ch1_ta4_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs4_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs5_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs6_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs7_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/cs8_ch1_ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta10_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta11_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta1_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta2_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta3_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta4_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta5_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta6_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta7_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta8_key.pem
src/tests/ro_data/signing_certs/produced/keys/ta9_key.pem
src/tests/ro_data/signing_certs/produced/ta1/ta1_cert.pem
src/tests/ro_data/signing_certs/produced/ta10/ta10_cert.pem
src/tests/ro_data/signing_certs/produced/ta11/ta11_cert.pem
src/tests/ro_data/signing_certs/produced/ta2/ta2_cert.pem
src/tests/ro_data/signing_certs/produced/ta3/ta3_cert.pem
src/tests/ro_data/signing_certs/produced/ta4/ta4_cert.pem
src/tests/ro_data/signing_certs/produced/ta5/ta5_cert.pem
src/tests/ro_data/signing_certs/produced/ta6/ta6_cert.pem
src/tests/ro_data/signing_certs/produced/ta7/ta7_cert.pem
src/tests/ro_data/signing_certs/produced/ta8/ta8_cert.pem
src/tests/ro_data/signing_certs/produced/ta9/ta9_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta10_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta11_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta1_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta2_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta3_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta4_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta5_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta6_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta7_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta8_cert.pem
src/tests/ro_data/signing_certs/produced/trust_anchors/ta9_cert.pem
--- a/src/tests/cli/t_pkg_temp_sources.py	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/cli/t_pkg_temp_sources.py	Mon Dec 16 10:35:54 2013 -0800
@@ -517,7 +517,7 @@
        Version: 1.0
         Branch: None
 Packaging Date: %(signed10_pkg_date)s
-          Size: 7.79 kB
+          Size: 7.81 kB
           FMRI: %(signed10_pkg_fmri)s
 """ % { "foo10_pkg_date": pd(self.foo10), "foo10_pkg_fmri": \
         self.foo10.get_fmri(include_build=False),
--- a/src/tests/ro_data/signing_certs/generate_certs.py	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/generate_certs.py	Mon Dec 16 10:35:54 2013 -0800
@@ -97,8 +97,13 @@
         subj_str_to_use = subj_str
         if https:
                 subj_str_to_use = https_subj_str
+        cmd = ["openssl", "genrsa", "-out", "./keys/%s_key.pem" % new_name,
+            "1024"]
+        p = subprocess.Popen(cmd)
+        assert p.wait() == 0
+
         cmd = ["openssl", "req", "-new", "-nodes",
-            "-keyout", "./keys/%s_key.pem" % new_name,
+            "-key", "./keys/%s_key.pem" % new_name,
             "-out", "./%s/%s.csr" % (new_loc, new_name),
             "-sha256", "-subj", subj_str_to_use % (new_name, new_name)]
         p = subprocess.Popen(cmd)
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/01.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/01.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 1 (0x1)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta1/emailAddress=ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta1/emailAddress=ta1
         Validity
-            Not Before: Apr 11 22:37:38 2011 GMT
-            Not After : Jan  5 22:37:38 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b1:ac:f5:20:5c:bf:44:a0:a0:ff:0b:28:02:1b:
-                    9d:dd:1f:3c:6a:f7:16:c0:8e:ec:af:a1:a4:c4:cf:
-                    26:8e:43:ca:8a:aa:05:8f:a2:10:03:32:41:d0:6e:
-                    b4:52:45:47:a8:46:8b:c5:f3:cd:55:56:f5:d0:c3:
-                    ec:e4:a4:63:8b:9a:87:fa:74:78:ff:2c:f7:66:77:
-                    3f:05:c3:31:d0:46:5f:b6:17:af:b5:76:9f:d8:8d:
-                    22:d3:76:ac:ad:55:6f:4c:76:2a:27:8e:e9:22:74:
-                    42:ce:db:42:b9:00:54:01:fe:18:c6:4a:96:b5:b9:
-                    88:32:6d:c5:d9:56:fc:87:95
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:da:3a:b2:74:16:5c:38:7c:93:3a:48:cb:9f:71:
+                    7c:aa:b9:ff:d7:25:5f:cd:90:6c:e6:87:6d:ed:34:
+                    0f:12:19:00:a8:36:fe:51:4b:b2:38:76:55:2a:d1:
+                    ce:3b:a3:78:75:db:c8:ba:85:8b:ad:80:0e:84:ab:
+                    1f:4b:80:90:20:56:49:7b:71:a0:16:f8:15:8a:cd:
+                    70:ee:45:1f:53:34:3c:85:df:10:75:e2:b1:68:97:
+                    c5:0d:66:7f:bf:e7:b3:d1:09:03:1b:50:14:dc:e3:
+                    3e:a9:b6:6a:63:e6:0f:51:3e:06:59:50:43:da:10:
+                    99:0d:79:a3:b4:76:89:a2:01
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                C0:9E:26:BD:D6:FB:FB:BF:FA:CE:33:92:CA:4E:25:CF:EC:9E:BA:66
+                36:46:2D:8A:1B:8B:CE:C1:1D:02:37:B9:EC:A5:FF:BA:73:AE:E5:48
             X509v3 Authority Key Identifier: 
-                keyid:75:A9:2B:02:E8:FB:31:09:2A:F2:16:21:24:D8:B2:A5:D0:14:93:5B
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta1/emailAddress=ta1
-                serial:A1:49:EA:78:5A:F4:55:8D
+                keyid:81:54:6B:06:08:DD:44:4F:08:81:21:7A:7C:D5:96:EA:53:2B:E3:0A
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta1/emailAddress=ta1
+                serial:F6:A8:B6:5C:10:8D:04:4F
 
             X509v3 Basic Constraints: critical
                 CA:TRUE, pathlen:4
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        94:eb:ef:96:17:47:57:5e:c2:4f:4c:67:8b:bd:d7:14:22:1e:
-        d7:09:cc:b7:b2:f2:cf:df:51:e3:a6:ea:5a:7b:3a:5f:47:b1:
-        db:37:91:a3:ae:75:d2:d0:9e:9c:49:fc:ec:1f:2e:9b:b4:96:
-        43:60:c8:99:a7:a8:fb:93:c1:68:2e:c8:09:42:23:0c:8a:25:
-        08:67:e9:0e:6a:44:e9:18:08:d0:a0:ce:60:6c:d3:e8:c1:ec:
-        2d:f0:db:47:04:36:f3:27:86:69:c5:10:06:3b:93:65:ea:19:
-        e4:6d:cd:fb:8a:ee:21:58:de:f3:17:7a:ee:ce:80:06:cc:1f:
-        48:dd
+         38:4a:69:9d:14:fa:51:b9:35:9c:c8:ae:e5:c0:e2:2e:4c:d4:
+         57:ad:64:05:99:e4:94:b3:d3:97:e0:0e:bd:1c:b4:64:c8:2b:
+         07:18:26:7f:99:ef:9c:48:e6:23:b3:96:37:92:54:85:8b:29:
+         19:60:12:11:fc:d8:62:84:5c:75:73:76:9e:0f:f8:a7:95:79:
+         c8:3c:75:f7:13:73:1f:be:fa:60:79:5c:6c:12:8d:ca:f9:58:
+         4b:1f:ed:0a:52:4c:61:95:6f:9a:a7:57:0c:20:9a:19:73:dc:
+         3d:42:aa:47:29:ac:92:a9:cc:4a:eb:85:6d:ab:cd:ed:2b:9a:
+         e5:c1
 -----BEGIN CERTIFICATE-----
-MIIDMjCCApugAwIBAgIBATANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGExMRIwEAYJKoZIhvcNAQkBFgN0YTEwHhcNMTEw
-NDExMjIzNzM4WhcNMTQwMTA1MjIzNzM4WjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gxX3RhMTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAsaz1IFy/RKCg/wsoAhud3R88avcWwI7s
-r6GkxM8mjkPKiqoFj6IQAzJB0G60UkVHqEaLxfPNVVb10MPs5KRji5qH+nR4/yz3
-Znc/BcMx0EZfthevtXaf2I0i03asrVVvTHYqJ47pInRCzttCuQBUAf4YxkqWtbmI
-Mm3F2Vb8h5UCAwEAAaOB4zCB4DAdBgNVHQ4EFgQUwJ4mvdb7+7/6zjOSyk4lz+ye
-umYwgZoGA1UdIwSBkjCBj4AUdakrAuj7MQkq8hYhJNiypdAUk1uhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEW
-A3RhMYIJAKFJ6nha9FWNMBIGA1UdEwEB/wQIMAYBAf8CAQQwDgYDVR0PAQH/BAQD
-AgEGMA0GCSqGSIb3DQEBCwUAA4GBAJTr75YXR1dewk9MZ4u91xQiHtcJzLey8s/f
-UeOm6lp7Ol9Hsds3kaOuddLQnpxJ/OwfLpu0lkNgyJmnqPuTwWguyAlCIwyKJQhn
-6Q5qROkYCNCgzmBs0+jB7C3w20cENvMnhmnFEAY7k2XqGeRtzfuK7iFY3vMXeu7O
-gAbMH0jd
+MIIDNTCCAp6gAwIBAgIBATANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMTESMBAGCSqGSIb3DQEJARYDdGExMB4XDTEz
+MTIxMzAwMTMzNFoXDTE2MDkwODAwMTMzNFowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDFfdGExMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDaOrJ0Flw4fJM6SMufcXyquf/XJV/N
+kGzmh23tNA8SGQCoNv5RS7I4dlUq0c47o3h128i6hYutgA6Eqx9LgJAgVkl7caAW
++BWKzXDuRR9TNDyF3xB14rFol8UNZn+/57PRCQMbUBTc4z6ptmpj5g9RPgZZUEPa
+EJkNeaO0domiAQIDAQABo4HkMIHhMB0GA1UdDgQWBBQ2Ri2KG4vOwR0CN7nspf+6
+c67lSDCBmwYDVR0jBIGTMIGQgBSBVGsGCN1ETwiBIXp81ZbqUyvjCqFtpGswaTEL
+MAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRh
+IENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQDDAN0YTExEjAQBgkqhkiG9w0B
+CQEWA3RhMYIJAPaotlwQjQRPMBIGA1UdEwEB/wQIMAYBAf8CAQQwDgYDVR0PAQH/
+BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBADhKaZ0U+lG5NZzIruXA4i5M1FetZAWZ
+5JSz05fgDr0ctGTIKwcYJn+Z75xI5iOzljeSVIWLKRlgEhH82GKEXHVzdp4P+KeV
+ecg8dfcTcx+++mB5XGwSjcr5WEsf7QpSTGGVb5qnVwwgmhlz3D1CqkcprJKpzErr
+hW2rze0rmuXB
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/02.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/02.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 2 (0x2)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:f4:24:ed:3d:fe:70:c8:51:b6:8d:26:78:90:6a:
-                    77:ff:de:7d:58:1f:00:fe:63:b0:88:de:46:18:d2:
-                    16:84:af:65:a1:9a:97:b1:38:14:6b:e7:98:c1:79:
-                    6f:0a:db:b2:92:6e:d6:7e:cd:cb:55:39:a0:27:e9:
-                    06:c8:45:19:2c:16:c3:4f:f5:af:cd:f6:14:cb:85:
-                    59:5c:1b:83:dc:f6:b6:4d:30:06:28:66:f6:2b:19:
-                    03:3f:00:de:09:77:50:a2:98:b1:73:3d:d5:79:f0:
-                    7e:79:2b:8e:76:96:c9:43:cf:44:9a:15:2e:09:00:
-                    47:a6:5a:f0:35:8b:88:b7:61
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:be:c1:86:30:d2:a3:02:f4:00:33:fc:54:f3:6f:
+                    d7:27:99:7b:57:e2:f1:93:f8:58:1c:eb:9a:cc:6b:
+                    23:9b:b8:a9:11:27:50:9b:d7:a7:c2:fe:8b:ee:54:
+                    d0:5d:e2:24:04:47:1c:cc:54:b5:89:bb:a6:26:de:
+                    b9:3b:73:19:67:5e:9a:88:12:de:87:de:0e:26:c9:
+                    0c:44:13:65:23:cd:7f:34:d6:bb:45:20:87:7e:ba:
+                    48:d5:2f:3f:fc:d6:8d:d7:b7:b2:9f:42:ef:76:9a:
+                    cf:c3:01:ae:b9:8f:00:33:ea:28:15:ca:30:da:8f:
+                    25:76:a4:55:2a:2c:7a:b8:eb
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                C2:62:F6:27:E6:91:FB:98:5F:55:6E:11:EE:6E:E0:04:76:A0:E7:01
+                12:30:0A:74:FD:DE:71:CF:4A:77:1E:1E:57:5E:F8:76:71:D7:5B:9E
             X509v3 Authority Key Identifier: 
-                keyid:C0:9E:26:BD:D6:FB:FB:BF:FA:CE:33:92:CA:4E:25:CF:EC:9E:BA:66
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta1/emailAddress=ta1
+                keyid:36:46:2D:8A:1B:8B:CE:C1:1D:02:37:B9:EC:A5:FF:BA:73:AE:E5:48
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta1/emailAddress=ta1
                 serial:01
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        a0:f7:c7:f9:6b:cf:6e:6c:36:74:b2:47:8d:76:04:74:88:de:
-        3b:cb:2d:e7:6c:fd:78:43:0f:29:9c:ba:92:97:dd:62:89:88:
-        31:c7:9b:b2:46:42:4a:e0:c1:3f:a8:5f:63:86:d1:75:d9:47:
-        46:d1:d3:87:dc:3e:7a:22:ce:8c:05:51:95:19:c5:2b:83:0f:
-        02:4c:54:a6:e8:a9:c9:79:bd:0b:f0:e7:4d:31:77:e6:07:ea:
-        1d:b1:35:48:30:15:28:c2:2d:36:42:fd:e9:11:85:7f:b0:9f:
-        7b:9a:b6:0e:1d:94:02:3a:3b:c1:b8:bd:c8:c9:8d:c6:b6:9a:
-        11:17
+         8e:a5:2a:c9:3f:e0:1f:a9:8c:a3:45:b8:0d:0e:35:43:c3:d6:
+         fe:f6:bc:0d:76:f0:26:d6:ab:e7:39:30:92:6f:cc:8e:0e:5f:
+         b0:92:29:41:39:41:14:2a:43:b1:bb:e5:d4:8c:b3:6e:b7:7b:
+         89:ab:3d:a4:e1:98:45:40:b9:1e:86:7b:b6:3f:55:e3:46:ab:
+         ed:41:45:6a:cc:af:a4:63:54:c8:ab:27:3f:59:67:8a:f5:60:
+         1b:63:b7:bb:27:94:00:8f:ee:f9:31:53:59:98:85:76:77:db:
+         dd:39:6f:1a:61:fe:0d:68:88:20:a8:d5:2b:c7:6a:08:5b:f1:
+         ac:9a
 -----BEGIN CERTIFICATE-----
-MIIDMjCCApugAwIBAgIBAjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDJfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDJf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD0JO09/nDIUbaNJniQanf/
-3n1YHwD+Y7CI3kYY0haEr2WhmpexOBRr55jBeW8K27KSbtZ+zctVOaAn6QbIRRks
-FsNP9a/N9hTLhVlcG4Pc9rZNMAYoZvYrGQM/AN4Jd1CimLFzPdV58H55K452lslD
-z0SaFS4JAEemWvA1i4i3YQIDAQABo4HbMIHYMB0GA1UdDgQWBBTCYvYn5pH7mF9V
-bhHubuAEdqDnATCBkgYDVR0jBIGKMIGHgBTAnia91vv7v/rOM5LKTiXP7J66ZqFs
-pGowaDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAMTA3RhMTESMBAGCSqG
-SIb3DQEJARYDdGExggEBMBIGA1UdEwEB/wQIMAYBAf8CAQMwDgYDVR0PAQH/BAQD
-AgEGMA0GCSqGSIb3DQEBCwUAA4GBAKD3x/lrz25sNnSyR412BHSI3jvLLeds/XhD
-DymcupKX3WKJiDHHm7JGQkrgwT+oX2OG0XXZR0bR04fcPnoizowFUZUZxSuDDwJM
-VKboqcl5vQvw500xd+YH6h2xNUgwFSjCLTZC/ekRhX+wn3uatg4dlAI6O8G4vcjJ
-jca2mhEX
+MIIDNTCCAp6gAwIBAgIBAjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTExFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoMl90YTExFjAUBgkqhkiG9w0BCQEWB2No
+Ml90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAL7BhjDSowL0ADP8VPNv
+1yeZe1fi8ZP4WBzrmsxrI5u4qREnUJvXp8L+i+5U0F3iJARHHMxUtYm7pibeuTtz
+GWdemogS3ofeDibJDEQTZSPNfzTWu0Ugh366SNUvP/zWjde3sp9C73aaz8MBrrmP
+ADPqKBXKMNqPJXakVSoserjrAgMBAAGjgdwwgdkwHQYDVR0OBBYEFBIwCnT93nHP
+SnceHlde+HZx11ueMIGTBgNVHSMEgYswgYiAFDZGLYobi87BHQI3ueyl/7pzruVI
+oW2kazBpMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMTESMBAG
+CSqGSIb3DQEJARYDdGExggEBMBIGA1UdEwEB/wQIMAYBAf8CAQMwDgYDVR0PAQH/
+BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAI6lKsk/4B+pjKNFuA0ONUPD1v72vA12
+8CbWq+c5MJJvzI4OX7CSKUE5QRQqQ7G75dSMs263e4mrPaThmEVAuR6Ge7Y/VeNG
+q+1BRWrMr6RjVMirJz9ZZ4r1YBtjt7snlACP7vkxU1mYhXZ32905bxph/g1oiCCo
+1SvHaghb8aya
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/03.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/03.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 3 (0x3)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:ec:46:7e:e1:35:25:1c:92:37:51:fb:99:13:70:
-                    e7:89:d6:3e:3b:28:59:98:96:e2:81:87:3f:99:85:
-                    5d:06:0a:d0:df:04:3e:fe:8a:00:f5:aa:91:93:a9:
-                    48:5c:59:b9:cb:f2:94:dd:fe:71:11:af:9c:7e:71:
-                    ce:96:21:cc:fd:27:e9:7e:82:2b:84:d5:73:3a:89:
-                    c0:09:2b:aa:16:d6:5f:7a:ac:81:d1:9b:18:4d:85:
-                    1e:33:2f:86:a8:c3:7a:2d:68:24:30:1d:7f:db:c5:
-                    30:0c:bf:d9:72:04:98:9d:ff:2f:cf:94:e7:2e:88:
-                    b2:47:fd:ee:c1:d2:e0:e9:39
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d3:5b:f1:93:8f:01:0f:c0:25:d9:07:f1:70:29:
+                    1e:56:0b:ff:93:70:1d:45:02:ef:52:22:8a:04:c9:
+                    08:85:33:db:77:c3:33:d9:5c:fe:30:2a:a8:ac:9d:
+                    d8:97:dc:b4:69:51:5e:d1:c9:86:68:a7:e3:ab:35:
+                    e2:8f:d0:36:1b:67:be:50:88:66:7c:4b:4f:d3:86:
+                    78:92:d9:c5:62:c7:04:a3:d7:9e:8c:c3:ca:48:41:
+                    52:3f:a1:82:dc:f2:bb:d2:9c:a9:58:25:3a:0b:73:
+                    b6:41:ab:6a:c3:6a:70:ce:a1:20:0f:b6:db:e0:91:
+                    0b:0a:1f:dc:02:f4:ed:32:0f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                D0:F9:37:92:54:28:C0:40:AE:62:94:51:42:6A:7C:8E:37:5F:AC:A8
+                8F:2A:82:4C:1E:39:97:C3:4A:6A:52:FC:D4:CB:E6:37:CE:12:91:59
             X509v3 Authority Key Identifier: 
-                keyid:C2:62:F6:27:E6:91:FB:98:5F:55:6E:11:EE:6E:E0:04:76:A0:E7:01
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1_ta1/emailAddress=ch1_ta1
+                keyid:12:30:0A:74:FD:DE:71:CF:4A:77:1E:1E:57:5E:F8:76:71:D7:5B:9E
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1_ta1/emailAddress=ch1_ta1
                 serial:02
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        3e:60:a3:23:dc:e2:bc:b9:60:14:1b:e5:dd:af:bd:f2:8b:cb:
-        f1:55:8a:03:e1:ee:82:f2:d2:7b:3d:0d:4a:56:f5:61:80:97:
-        27:90:c0:05:e4:e9:18:e8:29:97:eb:aa:6b:d2:4a:0c:b8:c0:
-        f3:cf:a5:4f:95:dd:46:03:96:eb:29:e4:bb:22:fe:5b:34:da:
-        02:8c:36:12:b6:9c:3e:a4:e4:d7:33:a3:ac:d8:45:65:75:37:
-        68:55:63:eb:d8:d1:6f:28:66:fc:ac:ad:15:08:67:41:41:32:
-        3f:ed:60:fc:01:e1:b9:88:24:95:1e:9c:ee:69:3b:d2:91:f8:
-        ef:81
+         94:2a:c9:c9:21:b7:bd:3a:72:31:65:89:16:11:00:e1:46:38:
+         16:b6:cd:d4:04:b3:18:71:3d:8d:4a:0a:ec:02:4e:ee:58:2c:
+         7d:d2:0b:6f:c6:d2:be:a6:f9:1c:e7:c2:76:2a:09:87:d2:06:
+         8e:0d:aa:66:70:e8:8f:ff:7d:1d:e4:4e:9b:58:71:f7:40:46:
+         a8:79:9d:86:6c:bf:64:3b:76:66:6c:08:21:62:09:6d:7b:f4:
+         5d:e2:8e:1c:e6:e3:56:71:de:b7:fe:92:07:f0:7e:13:e0:ad:
+         62:b3:08:9f:06:7e:9b:f6:8b:76:96:df:86:30:0e:bb:ef:9b:
+         b3:07
 -----BEGIN CERTIFICATE-----
-MIIDOjCCAqOgAwIBAgIBAzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gyX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gyX3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDNfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDNf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDsRn7hNSUckjdR+5kTcOeJ
-1j47KFmYluKBhz+ZhV0GCtDfBD7+igD1qpGTqUhcWbnL8pTd/nERr5x+cc6WIcz9
-J+l+giuE1XM6icAJK6oW1l96rIHRmxhNhR4zL4aow3otaCQwHX/bxTAMv9lyBJid
-/y/PlOcuiLJH/e7B0uDpOQIDAQABo4HjMIHgMB0GA1UdDgQWBBTQ+TeSVCjAQK5i
-lFFCanyON1+sqDCBmgYDVR0jBIGSMIGPgBTCYvYn5pH7mF9VbhHubuAEdqDnAaF0
-pHIwcDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxEDAOBgNVBAMUB2NoMV90YTExFjAU
-BgkqhkiG9w0BCQEWB2NoMV90YTGCAQIwEgYDVR0TAQH/BAgwBgEB/wIBAjAOBgNV
-HQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAPmCjI9zivLlgFBvl3a+98ovL
-8VWKA+HugvLSez0NSlb1YYCXJ5DABeTpGOgpl+uqa9JKDLjA88+lT5XdRgOW6ynk
-uyL+WzTaAow2EracPqTk1zOjrNhFZXU3aFVj69jRbyhm/KytFQhnQUEyP+1g/AHh
-uYgklR6c7mk70pH474E=
+MIIDPTCCAqagAwIBAgIBAzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMl90YTExFjAUBgkqhkiG9w0BCQEWB2NoMl90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTExFjAUBgkqhkiG9w0BCQEWB2No
+M190YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANNb8ZOPAQ/AJdkH8XAp
+HlYL/5NwHUUC71IiigTJCIUz23fDM9lc/jAqqKyd2JfctGlRXtHJhmin46s14o/Q
+NhtnvlCIZnxLT9OGeJLZxWLHBKPXnozDykhBUj+hgtzyu9KcqVglOgtztkGrasNq
+cM6hIA+22+CRCwof3AL07TIPAgMBAAGjgeQwgeEwHQYDVR0OBBYEFI8qgkweOZfD
+SmpS/NTL5jfOEpFZMIGbBgNVHSMEgZMwgZCAFBIwCnT93nHPSnceHlde+HZx11ue
+oXWkczBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTEx
+FjAUBgkqhkiG9w0BCQEWB2NoMV90YTGCAQIwEgYDVR0TAQH/BAgwBgEB/wIBAjAO
+BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAlCrJySG3vTpyMWWJFhEA
+4UY4FrbN1ASzGHE9jUoK7AJO7lgsfdILb8bSvqb5HOfCdioJh9IGjg2qZnDoj/99
+HeROm1hx90BGqHmdhmy/ZDt2ZmwIIWIJbXv0XeKOHObjVnHet/6SB/B+E+CtYrMI
+nwZ+m/aLdpbfhjAOu++bswc=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/04.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/04.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 4 (0x4)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:f5:af:af:99:95:f3:52:3b:eb:be:62:e6:eb:9f:
-                    c5:f8:ff:8f:0c:d2:e3:c7:06:b1:45:ca:ff:8c:fc:
-                    3d:bc:f4:6d:e3:f9:ac:12:69:d5:a1:6f:02:52:ad:
-                    50:34:7e:cc:a7:ee:82:04:b3:5b:e6:be:cc:44:e6:
-                    b8:d2:fc:1d:2a:80:d8:0c:c1:3c:4f:95:31:68:8a:
-                    fb:2b:e2:aa:b2:54:7c:3a:d3:86:6d:5f:20:b6:29:
-                    23:ae:74:09:fd:9a:d3:45:e2:e3:2a:62:1f:91:fd:
-                    a2:b1:2f:26:68:fb:4d:69:fb:66:1f:0b:4b:1a:52:
-                    ac:e1:8b:69:b1:16:96:89:13
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:af:c3:8b:39:3e:21:56:8a:d6:97:1b:c7:aa:c7:
+                    51:9e:e9:cf:15:1f:24:e6:91:92:81:b3:7d:30:eb:
+                    ea:12:30:13:03:d0:b9:60:41:8b:eb:88:f4:1f:e5:
+                    43:cf:b5:ae:47:7a:4d:46:6e:f8:16:42:67:db:20:
+                    e4:0d:1f:96:4f:21:59:95:f6:70:33:32:45:81:18:
+                    5e:a5:5b:fd:4a:e6:d7:97:cf:45:65:e7:74:79:5f:
+                    a5:9f:e1:c7:a5:d0:5d:24:a7:32:18:68:13:57:4c:
+                    cf:78:12:6f:9f:5c:e6:4d:be:89:24:4b:29:d8:02:
+                    b2:f9:f9:13:cf:92:43:0f:e5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                B2:A1:C2:1D:B7:20:56:20:8C:64:DA:BA:06:C6:5A:E4:0A:23:6E:01
+                54:8A:14:10:0B:AF:89:DC:1E:65:8A:17:37:6A:AC:D2:2B:6C:27:5C
             X509v3 Authority Key Identifier: 
-                keyid:D0:F9:37:92:54:28:C0:40:AE:62:94:51:42:6A:7C:8E:37:5F:AC:A8
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
+                keyid:8F:2A:82:4C:1E:39:97:C3:4A:6A:52:FC:D4:CB:E6:37:CE:12:91:59
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
                 serial:03
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        d5:54:78:2a:2c:5f:82:26:03:07:71:54:04:2d:81:e5:dd:a6:
-        b1:92:8a:37:5f:52:f0:13:cd:35:4a:2b:a7:24:9c:44:7b:ac:
-        1d:3c:52:82:e4:15:85:a9:d4:19:4d:55:c6:85:74:ac:2a:6c:
-        42:9f:92:d9:86:02:d8:90:a8:53:28:31:e1:e2:33:1b:d5:05:
-        c3:f7:94:86:10:5d:78:62:96:a7:d1:e3:b4:be:0e:e6:8c:03:
-        ef:4c:03:96:4e:6d:9a:b2:32:55:46:20:cf:41:d1:4f:db:c6:
-        57:34:df:51:d4:b9:9d:bf:d1:20:a5:e6:a0:34:ef:ab:e8:e9:
-        93:ce
+         6a:17:96:16:a6:3f:96:b7:8e:fb:e5:d7:14:f9:a8:8e:52:16:
+         04:0d:58:4b:f7:c6:70:c4:3f:d3:2b:13:24:7b:47:2d:cf:89:
+         59:bf:5c:6c:17:31:46:c4:17:e5:41:fe:5e:3f:ec:44:2e:92:
+         94:eb:3b:c9:ff:d1:5e:c0:ad:d3:51:2b:12:11:87:b2:17:2f:
+         40:5a:ac:76:f0:0f:ed:cd:ca:be:b6:b2:ef:bf:d4:79:04:e0:
+         ed:88:33:96:b0:a4:27:41:a7:31:0b:c4:d9:6a:ad:7d:82:bb:
+         63:15:2a:00:8e:60:af:ee:a6:8a:d3:65:6a:b8:f9:7e:0e:cd:
+         bf:d5
 -----BEGIN CERTIFICATE-----
-MIIDOjCCAqOgAwIBAgIBBDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gzX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDRfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDRf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD1r6+ZlfNSO+u+Yubrn8X4
-/48M0uPHBrFFyv+M/D289G3j+awSadWhbwJSrVA0fsyn7oIEs1vmvsxE5rjS/B0q
-gNgMwTxPlTFoivsr4qqyVHw604ZtXyC2KSOudAn9mtNF4uMqYh+R/aKxLyZo+01p
-+2YfC0saUqzhi2mxFpaJEwIDAQABo4HjMIHgMB0GA1UdDgQWBBSyocIdtyBWIIxk
-2roGxlrkCiNuATCBmgYDVR0jBIGSMIGPgBTQ+TeSVCjAQK5ilFFCanyON1+sqKF0
-pHIwcDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxEDAOBgNVBAMUB2NoMl90YTExFjAU
-BgkqhkiG9w0BCQEWB2NoMl90YTGCAQMwEgYDVR0TAQH/BAgwBgEB/wIBATAOBgNV
-HQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEA1VR4KixfgiYDB3FUBC2B5d2m
-sZKKN19S8BPNNUorpyScRHusHTxSguQVhanUGU1VxoV0rCpsQp+S2YYC2JCoUygx
-4eIzG9UFw/eUhhBdeGKWp9HjtL4O5owD70wDlk5tmrIyVUYgz0HRT9vGVzTfUdS5
-nb/RIKXmoDTvq+jpk84=
+MIIDPTCCAqagAwIBAgIBBDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTExFjAUBgkqhkiG9w0BCQEWB2NoM190
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2No
+NF90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAK/Dizk+IVaK1pcbx6rH
+UZ7pzxUfJOaRkoGzfTDr6hIwEwPQuWBBi+uI9B/lQ8+1rkd6TUZu+BZCZ9sg5A0f
+lk8hWZX2cDMyRYEYXqVb/Urm15fPRWXndHlfpZ/hx6XQXSSnMhhoE1dMz3gSb59c
+5k2+iSRLKdgCsvn5E8+SQw/lAgMBAAGjgeQwgeEwHQYDVR0OBBYEFFSKFBALr4nc
+HmWKFzdqrNIrbCdcMIGbBgNVHSMEgZMwgZCAFI8qgkweOZfDSmpS/NTL5jfOEpFZ
+oXWkczBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoMl90YTEx
+FjAUBgkqhkiG9w0BCQEWB2NoMl90YTGCAQMwEgYDVR0TAQH/BAgwBgEB/wIBATAO
+BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAaheWFqY/lreO++XXFPmo
+jlIWBA1YS/fGcMQ/0ysTJHtHLc+JWb9cbBcxRsQX5UH+Xj/sRC6SlOs7yf/RXsCt
+01ErEhGHshcvQFqsdvAP7c3Kvray77/UeQTg7YgzlrCkJ0GnMQvE2WqtfYK7YxUq
+AI5gr+6mitNlarj5fg7Nv9U=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/05.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/05.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 5 (0x5)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c3:8d:d0:ab:25:75:ba:f5:20:df:7c:8a:d4:cd:
-                    40:f6:c3:ca:25:11:b5:30:d6:27:fa:e4:a0:11:d6:
-                    aa:32:7d:c8:15:9d:d7:6f:7f:ae:80:de:28:c3:ae:
-                    77:a8:7f:f1:05:e9:6b:bc:63:a9:a6:91:04:3b:79:
-                    6b:96:f2:e0:9a:17:79:d3:04:0a:5f:46:09:b5:6f:
-                    3e:a9:f4:34:47:62:18:f4:28:f7:d9:09:cd:4f:8a:
-                    33:df:9b:69:9b:61:ce:72:c7:35:ed:61:a0:5b:0c:
-                    c1:61:00:0a:ac:83:9a:6a:3c:6d:30:96:eb:77:8c:
-                    28:3f:fc:62:8a:fa:60:8e:17
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:df:c0:ed:cc:df:82:ab:d3:9b:54:8d:56:f7:0d:
+                    e4:d8:b4:ba:03:ef:a3:82:f6:b6:e6:4d:0f:b4:e5:
+                    61:98:88:bd:32:b3:47:21:4b:2c:e8:c3:9a:22:9c:
+                    35:63:a8:4f:2a:c1:47:1a:3a:b2:46:d6:61:4e:87:
+                    2a:13:3a:d8:35:3e:3c:ae:67:43:b8:3d:a9:95:df:
+                    7b:ba:e9:71:ec:31:99:b3:fa:00:96:8c:80:4b:1d:
+                    d9:77:e5:d2:14:9d:95:a2:ce:32:21:d5:2e:67:ae:
+                    b1:08:04:fb:9d:fb:70:16:74:5f:1a:d1:36:77:e8:
+                    4b:68:c3:d8:d4:fb:18:20:31
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                69:C7:BA:72:9C:7F:C3:92:8D:F6:A6:D0:20:48:5A:8E:A7:B6:E7:82
+                B7:43:D6:5A:46:C2:2F:15:50:05:D5:FB:5E:BE:EC:F8:33:9E:EC:EC
             X509v3 Authority Key Identifier: 
-                keyid:B2:A1:C2:1D:B7:20:56:20:8C:64:DA:BA:06:C6:5A:E4:0A:23:6E:01
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
+                keyid:54:8A:14:10:0B:AF:89:DC:1E:65:8A:17:37:6A:AC:D2:2B:6C:27:5C
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
                 serial:04
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        e7:9a:14:6b:dc:a5:fa:da:15:2a:f0:b5:87:ef:82:df:2c:b1:
-        8b:f9:f6:a5:a0:e6:d2:86:da:46:69:68:6f:68:26:5c:79:73:
-        21:31:ea:b4:a7:e6:58:c9:12:cd:8c:c0:d0:e2:05:f0:6f:1d:
-        56:e5:3f:4a:32:eb:02:39:b6:6e:cb:c4:e1:d5:21:0f:63:1e:
-        4f:0b:3d:af:ca:5a:7b:2b:9c:7f:51:44:7a:39:73:e5:f2:ba:
-        48:85:20:f9:36:b5:c2:14:44:da:7d:ae:83:2e:b4:d8:f1:77:
-        19:97:c0:c7:8b:e7:62:81:93:75:ed:93:dd:19:4b:36:00:ba:
-        c6:2d
+         96:fb:63:43:cf:70:0a:14:7b:47:4e:37:4b:2f:7c:7f:8c:75:
+         85:bb:e3:44:af:9c:2c:08:c5:9c:4d:c7:59:f1:70:3a:67:82:
+         1c:4c:3c:f7:8b:e7:00:f0:05:db:af:29:79:53:6f:09:a2:ac:
+         ae:4d:e2:df:4a:7d:4e:56:79:8c:85:97:47:14:4e:2f:7e:bd:
+         07:2c:70:01:85:43:3c:18:32:ed:24:36:24:1c:29:e0:0b:ce:
+         86:4d:a7:a9:88:b8:de:f1:0e:a3:13:c1:5c:d7:1b:76:81:c2:
+         3f:63:c3:76:1d:60:f7:e5:43:1f:25:3b:ae:d2:a5:1f:02:fa:
+         8c:a3
 -----BEGIN CERTIFICATE-----
-MIIDOjCCAqOgAwIBAgIBBTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g0X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g0X3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDVfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDVf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDjdCrJXW69SDffIrUzUD2
-w8olEbUw1if65KAR1qoyfcgVnddvf66A3ijDrneof/EF6Wu8Y6mmkQQ7eWuW8uCa
-F3nTBApfRgm1bz6p9DRHYhj0KPfZCc1PijPfm2mbYc5yxzXtYaBbDMFhAAqsg5pq
-PG0wlut3jCg//GKK+mCOFwIDAQABo4HjMIHgMB0GA1UdDgQWBBRpx7pynH/Dko32
-ptAgSFqOp7bngjCBmgYDVR0jBIGSMIGPgBSyocIdtyBWIIxk2roGxlrkCiNuAaF0
-pHIwcDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxEDAOBgNVBAMUB2NoM190YTExFjAU
-BgkqhkiG9w0BCQEWB2NoM190YTGCAQQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
-HQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEA55oUa9yl+toVKvC1h++C3yyx
-i/n2paDm0obaRmlob2gmXHlzITHqtKfmWMkSzYzA0OIF8G8dVuU/SjLrAjm2bsvE
-4dUhD2MeTws9r8paeyucf1FEejlz5fK6SIUg+Ta1whRE2n2ugy602PF3GZfAx4vn
-YoGTde2T3RlLNgC6xi0=
+MIIDPTCCAqagAwIBAgIBBTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2NoNF90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoNV90YTExFjAUBgkqhkiG9w0BCQEWB2No
+NV90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAN/A7czfgqvTm1SNVvcN
+5Ni0ugPvo4L2tuZND7TlYZiIvTKzRyFLLOjDmiKcNWOoTyrBRxo6skbWYU6HKhM6
+2DU+PK5nQ7g9qZXfe7rpcewxmbP6AJaMgEsd2Xfl0hSdlaLOMiHVLmeusQgE+537
+cBZ0XxrRNnfoS2jD2NT7GCAxAgMBAAGjgeQwgeEwHQYDVR0OBBYEFLdD1lpGwi8V
+UAXV+16+7PgznuzsMIGbBgNVHSMEgZMwgZCAFFSKFBALr4ncHmWKFzdqrNIrbCdc
+oXWkczBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTEx
+FjAUBgkqhkiG9w0BCQEWB2NoM190YTGCAQQwEgYDVR0TAQH/BAgwBgEB/wIBADAO
+BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAlvtjQ89wChR7R043Sy98
+f4x1hbvjRK+cLAjFnE3HWfFwOmeCHEw894vnAPAF268peVNvCaKsrk3i30p9TlZ5
+jIWXRxROL369ByxwAYVDPBgy7SQ2JBwp4AvOhk2nqYi43vEOoxPBXNcbdoHCP2PD
+dh1g9+VDHyU7rtKlHwL6jKM=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/08.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/08.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 8 (0x8)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Validity
-            Not Before: Apr 11 22:37:40 2011 GMT
-            Not After : Jan  5 22:37:40 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cc:de:54:ed:78:31:c0:7c:e4:25:98:a3:0d:fa:
-                    77:08:f3:39:c4:9f:88:41:ee:00:a3:35:ed:b6:f0:
-                    cc:a3:fd:0f:ce:3c:70:b5:aa:1e:42:4e:5c:ae:d8:
-                    cb:99:53:ef:1e:49:f9:4c:5f:47:be:d0:e6:e2:f1:
-                    12:29:d5:77:75:88:79:4c:3b:64:05:ba:08:5d:dc:
-                    ed:1f:7f:15:92:69:ec:b9:c9:84:f0:7d:3f:db:66:
-                    34:a5:35:8c:22:9b:5f:4b:19:83:15:35:49:7c:4b:
-                    77:35:2c:c4:58:34:15:f1:66:99:ce:65:d3:06:b7:
-                    d2:35:d7:96:39:ee:d8:08:91
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:9d:91:87:82:56:78:7f:64:32:62:7e:ee:6c:38:
+                    f2:a2:f6:34:ba:a9:ec:bb:6e:0f:87:ab:46:a4:37:
+                    ce:80:f1:b5:8b:9b:0a:4b:2a:b6:46:9b:f1:47:c0:
+                    6b:85:7f:64:08:61:ac:53:d4:3b:ce:54:2a:6d:a4:
+                    65:cd:a7:dc:a5:3a:33:bf:86:2b:f6:d0:fb:24:80:
+                    56:8f:4f:d4:f9:96:71:f3:86:74:4b:47:38:da:18:
+                    79:ae:d9:5b:9d:09:9e:f7:cb:b4:a7:85:33:85:20:
+                    d3:2a:fc:72:c1:37:62:01:d6:b1:cb:4a:a0:09:c2:
+                    72:ea:fd:b8:5d:03:68:33:7d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -29,27 +29,27 @@
                 <EMPTY>
 
     Signature Algorithm: sha256WithRSAEncryption
-        22:ec:49:fd:44:5e:9a:b1:55:f7:29:4c:cf:66:ff:1f:ce:d7:
-        e6:31:ae:b5:f3:3b:c9:d8:e4:d4:4a:59:ff:db:9a:88:23:28:
-        14:62:78:03:b8:36:d8:32:56:c6:d2:09:0f:e4:33:ea:02:7f:
-        24:02:fc:4c:58:5c:e7:3a:4c:b6:69:55:bc:5e:c8:3e:c2:97:
-        66:82:74:6a:1c:1e:ae:ae:3d:35:f5:6e:a3:a5:9b:9d:23:d5:
-        da:de:e2:47:ee:ea:78:8a:36:19:73:f5:7f:38:bd:0e:bb:56:
-        3c:c8:21:0e:5a:57:a0:cf:08:50:e6:80:ef:3e:e5:ed:64:69:
-        d6:6d
+         11:3c:6b:22:14:f6:1a:18:8b:59:a4:8d:38:d6:6f:48:8a:01:
+         e2:d3:9d:6a:26:40:61:d3:9b:ce:8a:ab:b9:25:c4:89:c4:f9:
+         98:1e:6c:f5:1c:d7:f7:6a:c9:7b:48:ba:d7:e0:03:59:41:4d:
+         29:28:7d:2d:61:c5:7f:7f:8c:2f:30:2b:c6:6e:16:31:7d:45:
+         d2:2a:83:ea:fc:25:92:1f:cb:85:28:0a:f4:2c:a0:c4:c2:fc:
+         52:43:53:d1:46:e7:fd:3c:0a:9b:11:45:0f:09:2e:c6:93:26:
+         72:c9:20:28:7a:db:18:55:1b:15:70:1f:bc:0e:ab:18:c1:f8:
+         64:03
 -----BEGIN CERTIFICATE-----
-MIICezCCAeSgAwIBAgIBCDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g0X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g0X3Rh
-MTAeFw0xMTA0MTEyMjM3NDBaFw0xNDAxMDUyMjM3NDBaMHQxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRIwEAYDVQQDFAljaDUuMV90YTExGDAWBgkqhkiG9w0BCQEWCWNo
-NS4xX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAzN5U7XgxwHzkJZij
-Dfp3CPM5xJ+IQe4AozXttvDMo/0PzjxwtaoeQk5crtjLmVPvHkn5TF9HvtDm4vES
-KdV3dYh5TDtkBboIXdztH38VkmnsucmE8H0/22Y0pTWMIptfSxmDFTVJfEt3NSzE
-WDQV8WaZzmXTBrfSNdeWOe7YCJECAwEAAaMhMB8wDwYDVR0TAQH/BAUwAwEB/zAM
-BgNVHRIBAf8EAjAAMA0GCSqGSIb3DQEBCwUAA4GBACLsSf1EXpqxVfcpTM9m/x/O
-1+YxrrXzO8nY5NRKWf/bmogjKBRieAO4NtgyVsbSCQ/kM+oCfyQC/ExYXOc6TLZp
-VbxeyD7Cl2aCdGocHq6uPTX1bqOlm50j1dre4kfu6niKNhlz9X84vQ67VjzIIQ5a
-V6DPCFDmgO8+5e1kadZt
+MIICfTCCAeagAwIBAgIBCDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2NoNF90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB1MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4xX3RhMTEYMBYGCSqGSIb3DQEJARYJ
+Y2g1LjFfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdkYeCVnh/ZDJi
+fu5sOPKi9jS6qey7bg+Hq0akN86A8bWLmwpLKrZGm/FHwGuFf2QIYaxT1DvOVCpt
+pGXNp9ylOjO/hiv20PskgFaPT9T5lnHzhnRLRzjaGHmu2VudCZ73y7SnhTOFINMq
+/HLBN2IB1rHLSqAJwnLq/bhdA2gzfQIDAQABoyEwHzAPBgNVHRMBAf8EBTADAQH/
+MAwGA1UdEgEB/wQCMAAwDQYJKoZIhvcNAQELBQADgYEAETxrIhT2GhiLWaSNONZv
+SIoB4tOdaiZAYdObzoqruSXEicT5mB5s9RzX92rJe0i61+ADWUFNKSh9LWHFf3+M
+LzArxm4WMX1F0iqD6vwlkh/LhSgK9CygxML8UkNT0Ubn/TwKmxFFDwkuxpMmcskg
+KHrbGFUbFXAfvA6rGMH4ZAM=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/0A.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/0A.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 10 (0xa)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Validity
-            Not Before: Apr 11 22:37:41 2011 GMT
-            Not After : Jan  5 22:37:41 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c5:27:9b:4d:c3:41:cf:96:d4:f0:21:59:1b:77:
-                    ce:54:81:dc:05:57:1f:56:69:8c:5f:58:3f:88:4a:
-                    c6:73:bd:a9:4a:d0:f8:a3:33:1b:4f:d8:94:b5:d3:
-                    95:bd:00:06:d1:18:e8:ea:9e:41:ad:06:ea:c6:cc:
-                    9f:93:a7:c4:a0:3e:05:62:4c:3f:1c:88:79:a0:a1:
-                    eb:f3:94:d0:1b:8c:a8:9f:4c:3b:37:80:06:6b:00:
-                    e7:30:6c:d4:c2:51:27:7f:1a:e5:95:a7:1c:15:d6:
-                    98:0e:1f:2f:28:b7:a7:75:60:56:8e:74:a0:86:9a:
-                    06:d5:23:0f:11:83:02:95:73
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:a0:b5:e8:50:6e:0b:2e:be:8a:39:95:a1:f3:8f:
+                    03:1c:da:d3:74:5c:9d:ed:34:54:5e:3f:ac:e2:91:
+                    40:50:5e:d7:e3:bc:b1:8e:a6:62:d1:0b:33:e2:59:
+                    d7:67:f1:b7:af:f9:61:37:b1:24:aa:6f:67:e0:4f:
+                    ef:5d:a2:72:42:70:41:1e:32:e5:1a:94:4f:de:60:
+                    6c:e7:e1:96:99:82:d0:35:f2:40:03:de:92:10:f3:
+                    4f:91:e8:78:24:a1:ef:92:da:7b:49:4b:57:03:80:
+                    57:d8:fc:41:60:8a:f0:e6:55:fe:67:55:5e:68:bf:
+                    fe:fd:23:2b:ab:94:cb:12:c3
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                89:81:B5:75:FE:47:C0:C6:F5:28:97:38:D7:FC:58:E9:62:8D:31:C0
+                A4:07:01:64:2E:FC:65:F5:BC:44:82:AB:87:E5:17:5F:91:F5:8A:DD
             X509v3 Authority Key Identifier: 
-                keyid:B2:A1:C2:1D:B7:20:56:20:8C:64:DA:BA:06:C6:5A:E4:0A:23:6E:01
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
+                keyid:54:8A:14:10:0B:AF:89:DC:1E:65:8A:17:37:6A:AC:D2:2B:6C:27:5C
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
                 serial:04
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        63:3d:1b:46:ff:99:65:19:01:e8:fc:b1:a4:22:30:8c:da:43:
-        c5:79:05:0c:60:3a:0f:4b:3f:53:63:f0:12:63:a9:ee:63:10:
-        15:aa:f4:ae:13:10:4f:43:b4:31:8c:84:f5:c1:0b:86:ab:7b:
-        78:7e:7c:9b:3c:26:56:8e:aa:54:3b:ad:7e:be:23:3e:8f:8c:
-        cf:47:22:7d:f6:83:53:ca:72:f1:02:9a:07:4a:f7:94:00:1b:
-        d2:57:80:6d:c9:37:ab:58:d6:54:71:90:de:c9:3f:ee:c3:b5:
-        5c:0e:46:09:30:cf:95:58:2f:07:64:fe:27:70:9e:d0:29:dd:
-        f5:25
+         04:21:55:e4:d4:f9:07:b1:55:dd:d3:6c:5e:17:f5:84:36:49:
+         08:3f:96:1b:79:f6:1f:c8:aa:0a:e2:64:bd:90:e1:00:89:23:
+         94:1c:d9:c8:7d:a6:5e:48:4f:e4:6a:9d:c1:2a:b9:6c:6b:ed:
+         24:14:54:9f:87:bf:a1:d3:fd:73:39:eb:c4:88:85:7e:f5:35:
+         91:3d:85:ad:9e:c5:1f:fc:f6:06:71:ce:3f:dc:12:e8:6c:a6:
+         61:07:b8:d0:78:03:de:e6:be:e9:67:59:2f:70:24:c3:54:4e:
+         b3:5c:6e:54:8e:04:c3:b6:f1:83:1b:8d:7f:e8:b7:5b:3d:b2:
+         26:fe
 -----BEGIN CERTIFICATE-----
-MIIDPjCCAqegAwIBAgIBCjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g0X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g0X3Rh
-MTAeFw0xMTA0MTEyMjM3NDFaFw0xNDAxMDUyMjM3NDFaMHQxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRIwEAYDVQQDFAljaDUuMl90YTExGDAWBgkqhkiG9w0BCQEWCWNo
-NS4yX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxSebTcNBz5bU8CFZ
-G3fOVIHcBVcfVmmMX1g/iErGc72pStD4ozMbT9iUtdOVvQAG0Rjo6p5BrQbqxsyf
-k6fEoD4FYkw/HIh5oKHr85TQG4yon0w7N4AGawDnMGzUwlEnfxrllaccFdaYDh8v
-KLendWBWjnSghpoG1SMPEYMClXMCAwEAAaOB4zCB4DAdBgNVHQ4EFgQUiYG1df5H
-wMb1KJc41/xY6WKNMcAwgZoGA1UdIwSBkjCBj4AUsqHCHbcgViCMZNq6BsZa5Aoj
-bgGhdKRyMHAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYD
-VQQHEwpNZW5sbyBQYXJrMQ0wCwYDVQQKEwRwa2c1MRAwDgYDVQQDFAdjaDNfdGEx
-MRYwFAYJKoZIhvcNAQkBFgdjaDNfdGExggEEMBIGA1UdEwEB/wQIMAYBAf8CAQEw
-DgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAGM9G0b/mWUZAej8saQi
-MIzaQ8V5BQxgOg9LP1Nj8BJjqe5jEBWq9K4TEE9DtDGMhPXBC4are3h+fJs8JlaO
-qlQ7rX6+Iz6PjM9HIn32g1PKcvECmgdK95QAG9JXgG3JN6tY1lRxkN7JP+7DtVwO
-Rgkwz5VYLwdk/idwntAp3fUl
+MIIDQTCCAqqgAwIBAgIBCjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2NoNF90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB1MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4yX3RhMTEYMBYGCSqGSIb3DQEJARYJ
+Y2g1LjJfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCgtehQbgsuvoo5
+laHzjwMc2tN0XJ3tNFReP6zikUBQXtfjvLGOpmLRCzPiWddn8bev+WE3sSSqb2fg
+T+9donJCcEEeMuUalE/eYGzn4ZaZgtA18kAD3pIQ80+R6Hgkoe+S2ntJS1cDgFfY
+/EFgivDmVf5nVV5ov/79IyurlMsSwwIDAQABo4HkMIHhMB0GA1UdDgQWBBSkBwFk
+Lvxl9bxEgquH5RdfkfWK3TCBmwYDVR0jBIGTMIGQgBRUihQQC6+J3B5lihc3aqzS
+K2wnXKF1pHMwcTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQDDAdjaDNf
+dGExMRYwFAYJKoZIhvcNAQkBFgdjaDNfdGExggEEMBIGA1UdEwEB/wQIMAYBAf8C
+AQEwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAAQhVeTU+QexVd3T
+bF4X9YQ2SQg/lht59h/IqgriZL2Q4QCJI5Qc2ch9pl5IT+RqncEquWxr7SQUVJ+H
+v6HT/XM568SIhX71NZE9ha2exR/89gZxzj/cEuhspmEHuNB4A97mvulnWS9wJMNU
+TrNcblSOBMO28YMbjX/ot1s9sib+
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/0C.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/0C.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 12 (0xc)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e2:d0:ba:91:89:c2:26:21:4c:9d:68:63:7e:87:
-                    9b:9e:31:52:4d:30:b3:2b:9c:26:85:40:63:69:66:
-                    7c:5d:52:73:d3:61:01:78:18:0e:46:21:6d:34:1f:
-                    84:e2:42:72:9c:ef:68:7e:49:a6:3d:62:82:f3:0f:
-                    95:74:13:88:a1:d1:bf:00:93:10:24:d2:fc:bd:1a:
-                    a7:4f:f2:24:b2:60:d5:57:96:62:09:c8:94:5f:b6:
-                    57:38:f1:00:62:97:d9:a2:35:d6:95:47:97:78:48:
-                    17:77:2b:c4:62:fa:00:0c:f1:d4:6e:e1:74:25:38:
-                    0f:5c:57:af:92:37:e7:18:21
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:dd:ec:30:ee:2a:39:ec:cf:6d:c0:b9:04:f2:e0:
+                    0f:04:7a:e9:ab:f0:27:28:d9:6b:70:e5:c4:9b:c6:
+                    1b:bb:71:16:42:d5:47:80:60:2c:f6:26:90:9d:0b:
+                    cc:1b:18:bf:54:98:c7:e8:ba:bf:a2:5d:60:c9:b3:
+                    09:79:de:ee:02:d9:b9:70:22:c3:cd:60:04:5f:1e:
+                    df:a3:8f:43:73:ea:68:5e:df:70:86:aa:67:75:5a:
+                    59:ef:cd:0d:e4:f1:6d:ee:d3:bb:04:c7:52:e5:72:
+                    53:2a:e2:f3:02:65:7f:53:46:c3:15:e4:cb:8d:1b:
+                    cf:8f:1e:8d:6d:04:07:09:77
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                9E:F5:29:85:12:A6:F3:26:1C:25:81:F4:75:82:9E:80:B1:33:8D:BE
+                16:06:DB:79:36:82:5D:96:BA:FD:0F:C3:3D:E2:64:BA:E6:03:E6:3A
             X509v3 Authority Key Identifier: 
-                keyid:D0:F9:37:92:54:28:C0:40:AE:62:94:51:42:6A:7C:8E:37:5F:AC:A8
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
+                keyid:8F:2A:82:4C:1E:39:97:C3:4A:6A:52:FC:D4:CB:E6:37:CE:12:91:59
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
                 serial:03
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        87:45:e7:89:11:9c:2a:47:8e:63:84:93:80:3f:03:27:65:dd:
-        19:50:aa:1f:e5:50:67:c9:d8:3f:1e:74:85:fb:46:b2:c8:1c:
-        22:cb:a9:d0:d4:26:60:06:6e:9e:15:7e:d3:5a:06:8d:95:26:
-        36:10:16:e9:08:92:fb:9a:45:14:99:b5:ac:ee:06:d2:6b:c4:
-        21:63:13:b4:55:1f:c3:35:02:56:9e:7d:d1:4a:1f:45:91:f6:
-        c1:28:c3:f9:aa:e0:31:63:cc:c0:5d:77:7f:54:65:98:a3:39:
-        eb:73:83:ab:74:f3:c2:3e:be:9b:fe:18:75:3c:44:ad:a2:fc:
-        c2:42
+         26:70:cc:69:5b:26:cf:cc:1d:19:b6:61:20:59:22:d7:fa:a3:
+         d9:fa:e2:e3:87:07:24:5a:41:5b:7e:21:4c:f5:32:d2:d8:fd:
+         a5:17:b5:c4:0f:9a:d2:a6:dd:45:9f:13:2a:30:8a:75:5b:69:
+         9b:dd:06:85:3e:19:06:7d:5d:0f:3f:15:64:76:41:e9:a8:30:
+         bd:d7:26:66:07:60:da:e2:ec:80:44:6d:a5:8b:fd:9a:3a:0b:
+         92:b9:6c:f8:72:cc:7e:24:78:a2:a3:f7:ef:47:7a:aa:8b:89:
+         45:33:ff:01:bd:a0:d0:18:ea:a1:46:98:b5:7f:00:e1:00:8e:
+         7e:68
 -----BEGIN CERTIFICATE-----
-MIIDPjCCAqegAwIBAgIBDDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gzX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3Rh
-MTAeFw0xMTA0MTEyMjM3NDJaFw0xNDAxMDUyMjM3NDJaMHQxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRIwEAYDVQQDFAljaDQuM190YTExGDAWBgkqhkiG9w0BCQEWCWNo
-NC4zX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA4tC6kYnCJiFMnWhj
-foebnjFSTTCzK5wmhUBjaWZ8XVJz02EBeBgORiFtNB+E4kJynO9ofkmmPWKC8w+V
-dBOIodG/AJMQJNL8vRqnT/IksmDVV5ZiCciUX7ZXOPEAYpfZojXWlUeXeEgXdyvE
-YvoADPHUbuF0JTgPXFevkjfnGCECAwEAAaOB4zCB4DAdBgNVHQ4EFgQUnvUphRKm
-8yYcJYH0dYKegLEzjb4wgZoGA1UdIwSBkjCBj4AU0Pk3klQowECuYpRRQmp8jjdf
-rKihdKRyMHAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYD
-VQQHEwpNZW5sbyBQYXJrMQ0wCwYDVQQKEwRwa2c1MRAwDgYDVQQDFAdjaDJfdGEx
-MRYwFAYJKoZIhvcNAQkBFgdjaDJfdGExggEDMBIGA1UdEwEB/wQIMAYBAf8CAQAw
-DgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAIdF54kRnCpHjmOEk4A/
-Aydl3RlQqh/lUGfJ2D8edIX7RrLIHCLLqdDUJmAGbp4VftNaBo2VJjYQFukIkvua
-RRSZtazuBtJrxCFjE7RVH8M1AlaefdFKH0WR9sEow/mq4DFjzMBdd39UZZijOetz
-g6t088I+vpv+GHU8RK2i/MJC
+MIIDQTCCAqqgAwIBAgIBDDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTExFjAUBgkqhkiG9w0BCQEWB2NoM190
+YTEwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjB1MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEjAQBgNVBAMMCWNoNC4zX3RhMTEYMBYGCSqGSIb3DQEJARYJ
+Y2g0LjNfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDd7DDuKjnsz23A
+uQTy4A8Eeumr8Cco2Wtw5cSbxhu7cRZC1UeAYCz2JpCdC8wbGL9UmMfour+iXWDJ
+swl53u4C2blwIsPNYARfHt+jj0Nz6mhe33CGqmd1WlnvzQ3k8W3u07sEx1LlclMq
+4vMCZX9TRsMV5MuNG8+PHo1tBAcJdwIDAQABo4HkMIHhMB0GA1UdDgQWBBQWBtt5
+NoJdlrr9D8M94mS65gPmOjCBmwYDVR0jBIGTMIGQgBSPKoJMHjmXw0pqUvzUy+Y3
+zhKRWaF1pHMwcTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQDDAdjaDJf
+dGExMRYwFAYJKoZIhvcNAQkBFgdjaDJfdGExggEDMBIGA1UdEwEB/wQIMAYBAf8C
+AQAwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBACZwzGlbJs/MHRm2
+YSBZItf6o9n64uOHByRaQVt+IUz1MtLY/aUXtcQPmtKm3UWfEyowinVbaZvdBoU+
+GQZ9XQ8/FWR2QemoML3XJmYHYNri7IBEbaWL/Zo6C5K5bPhyzH4keKKj9+9HeqqL
+iUUz/wG9oNAY6qFGmLV/AOEAjn5o
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/0D.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/0D.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 13 (0xd)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:be:99:38:81:c2:5f:37:c3:d2:cc:7f:01:19:61:
-                    8d:8b:57:70:3a:2c:36:c1:c8:e4:a6:33:2a:bc:27:
-                    e9:cf:d7:ca:49:90:d2:e0:f1:82:0e:7d:50:aa:e3:
-                    8c:ca:07:61:bf:d3:fd:1e:f3:af:ec:00:dd:d2:ab:
-                    70:6a:1a:5a:00:32:ec:04:a3:a4:25:b1:82:1d:90:
-                    3c:f9:ae:91:90:d7:d6:c2:0e:8d:31:55:62:e2:6b:
-                    10:e0:10:6f:33:93:78:2f:58:b7:46:f4:b9:1a:4c:
-                    fd:81:b2:66:42:95:4b:a1:ff:46:9e:9d:f6:32:56:
-                    63:88:bc:83:43:54:bb:ce:a1
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:9a:0b:35:00:7e:06:fd:e2:50:97:7e:d2:c2:b8:
+                    20:2a:d9:bb:b8:3f:14:f9:aa:e3:98:dc:b9:49:62:
+                    32:9e:e7:51:16:ef:6b:69:59:7e:0f:c3:50:08:3d:
+                    dc:23:18:37:fa:70:cc:45:b8:47:1e:49:ef:18:15:
+                    47:8e:e6:c9:65:64:02:a8:f5:2a:d1:ef:3a:91:8f:
+                    5a:52:21:46:8f:61:87:55:c9:61:ea:e8:98:18:c5:
+                    99:1f:bd:43:02:13:a6:bf:c0:cd:d9:a5:ee:40:a3:
+                    05:bf:18:28:57:f6:4e:21:d0:89:a1:21:1c:39:ed:
+                    2d:ed:45:f0:da:75:37:da:7b
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                9F:45:5B:75:2A:5E:64:78:D2:D9:6F:34:3C:19:AE:27:DE:D7:6C:98
+                A5:4B:BC:BC:6C:A7:1D:7E:CB:31:E5:DF:BE:24:BE:B9:86:28:DE:68
             X509v3 Authority Key Identifier: 
-                keyid:9E:F5:29:85:12:A6:F3:26:1C:25:81:F4:75:82:9E:80:B1:33:8D:BE
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
+                keyid:16:06:DB:79:36:82:5D:96:BA:FD:0F:C3:3D:E2:64:BA:E6:03:E6:3A
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
                 serial:0C
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        62:7d:64:11:6a:5f:cd:6d:09:ae:5c:5f:d7:ef:5e:08:1f:c0:
-        6d:b0:b5:a1:28:74:88:95:10:93:2b:50:a4:7f:f3:92:3c:75:
-        23:ad:4b:e6:bd:ae:62:35:74:1c:0f:fd:00:e4:e7:e2:53:80:
-        b9:c5:30:1e:47:83:39:a5:88:3d:9b:a2:ee:86:27:94:cb:f5:
-        57:ba:91:ce:70:d7:12:a0:61:39:64:af:70:91:12:41:5e:4c:
-        7e:5d:5e:b0:42:05:31:e5:13:fd:bc:86:cc:b6:bc:4e:4c:69:
-        b6:2f:0e:63:80:16:c2:6d:7c:68:07:b6:a7:b4:04:ff:0b:97:
-        51:ee
+         4b:1b:27:81:60:e8:9c:ca:e9:2b:c6:94:9e:64:d5:1a:44:18:
+         e7:fb:98:cf:a0:10:e3:ae:ad:b3:fa:a6:21:9d:be:35:46:17:
+         e6:42:3f:8c:79:81:c5:46:f4:f8:04:72:02:a5:5c:6a:1f:cf:
+         62:e1:f9:6f:3a:26:5c:7b:13:27:bd:27:e7:8d:e4:75:b0:04:
+         05:84:44:8b:cf:2c:8b:8b:44:35:c7:60:79:91:04:69:cc:35:
+         90:5b:e5:9a:71:cb:6d:65:dd:a1:09:2c:d0:35:69:cc:cf:0a:
+         62:41:8f:18:ac:9e:8f:52:4c:fa:77:14:98:45:ce:06:c5:f9:
+         5d:6a
 -----BEGIN CERTIFICATE-----
-MIIDQjCCAqugAwIBAgIBDTANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g0LjNfdGExMRgwFgYJKoZIhvcNAQkBFgljaDQu
-M190YTEwHhcNMTEwNDExMjIzNzQyWhcNMTQwMTA1MjIzNzQyWjB0MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTESMBAGA1UEAxQJY2g1LjNfdGExMRgwFgYJKoZIhvcNAQkB
-FgljaDUuM190YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAL6ZOIHCXzfD
-0sx/ARlhjYtXcDosNsHI5KYzKrwn6c/XykmQ0uDxgg59UKrjjMoHYb/T/R7zr+wA
-3dKrcGoaWgAy7ASjpCWxgh2QPPmukZDX1sIOjTFVYuJrEOAQbzOTeC9Yt0b0uRpM
-/YGyZkKVS6H/Rp6d9jJWY4i8g0NUu86hAgMBAAGjgeMwgeAwHQYDVR0OBBYEFJ9F
-W3UqXmR40tlvNDwZrife12yYMIGaBgNVHSMEgZIwgY+AFJ71KYUSpvMmHCWB9HWC
-noCxM42+oXSkcjBwMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTET
-MBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UEAxQHY2gz
-X3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3RhMYIBDDASBgNVHRMBAf8ECDAGAQH/
-AgEAMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQBifWQRal/NbQmu
-XF/X714IH8BtsLWhKHSIlRCTK1Ckf/OSPHUjrUvmva5iNXQcD/0A5OfiU4C5xTAe
-R4M5pYg9m6LuhieUy/VXupHOcNcSoGE5ZK9wkRJBXkx+XV6wQgUx5RP9vIbMtrxO
-TGm2Lw5jgBbCbXxoB7antAT/C5dR7g==
+MIIDRTCCAq6gAwIBAgIBDTANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNC4zX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g0
+LjNfdGExMB4XDTEzMTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowdTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRIwEAYDVQQDDAljaDUuM190YTExGDAWBgkqhkiG9w0B
+CQEWCWNoNS4zX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAmgs1AH4G
+/eJQl37SwrggKtm7uD8U+arjmNy5SWIynudRFu9raVl+D8NQCD3cIxg3+nDMRbhH
+HknvGBVHjubJZWQCqPUq0e86kY9aUiFGj2GHVclh6uiYGMWZH71DAhOmv8DN2aXu
+QKMFvxgoV/ZOIdCJoSEcOe0t7UXw2nU32nsCAwEAAaOB5DCB4TAdBgNVHQ4EFgQU
+pUu8vGynHX7LMeXfviS+uYYo3mgwgZsGA1UdIwSBkzCBkIAUFgbbeTaCXZa6/Q/D
+PeJkuuYD5jqhdaRzMHExCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlh
+MRQwEgYDVQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEQMA4GA1UEAwwH
+Y2gzX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3RhMYIBDDASBgNVHRMBAf8ECDAG
+AQH/AgEAMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQBLGyeBYOic
+yukrxpSeZNUaRBjn+5jPoBDjrq2z+qYhnb41RhfmQj+MeYHFRvT4BHICpVxqH89i
+4flvOiZcexMnvSfnjeR1sAQFhESLzyyLi0Q1x2B5kQRpzDWQW+WaccttZd2hCSzQ
+NWnMzwpiQY8YrJ6PUkz6dxSYRc4Gxfldag==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/10.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/10.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 16 (0x10)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
-            Not Before: Apr 11 22:37:44 2011 GMT
-            Not After : Jan  5 22:37:44 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e1:a3:d0:51:dc:0b:73:6f:44:f2:c7:6b:f2:9d:
-                    da:56:de:d4:41:61:75:48:78:10:2c:53:f1:c1:28:
-                    01:4a:10:53:7d:32:bc:e2:01:a2:75:59:0b:cf:3a:
-                    fc:41:b8:2c:36:fb:fe:3d:d9:a2:41:7b:6e:3c:0a:
-                    a9:7e:74:5a:86:ea:06:6a:2b:ad:3c:7e:32:8b:97:
-                    a4:ba:53:c1:b8:bc:f0:8f:80:22:53:97:66:bb:80:
-                    15:05:96:dc:df:62:29:4d:15:df:85:e6:90:30:4d:
-                    29:d3:04:b7:4f:22:40:b8:a1:22:ed:0e:4b:e6:00:
-                    82:df:89:48:63:87:b5:80:55
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ba:0e:36:90:a0:6b:75:19:6b:30:76:54:9e:20:
+                    b0:81:70:21:47:97:9c:c1:15:7c:9e:2d:50:3c:db:
+                    dc:8c:d0:31:9c:b9:78:c6:2a:5c:53:ca:ed:d3:44:
+                    e2:f9:93:d8:b5:b6:a6:8a:c2:bd:be:4f:8b:f5:a0:
+                    28:68:cf:ec:f9:e3:e9:57:a8:ab:cd:a5:45:0d:82:
+                    eb:f0:5b:aa:2d:1b:88:65:30:9f:a1:74:59:1f:e5:
+                    d2:25:f9:d6:31:3f:0a:a2:4a:92:5d:2a:30:2e:3f:
+                    2f:72:48:93:f8:8d:7c:bf:79:21:e3:e1:91:9a:a7:
+                    03:01:ba:20:95:a6:da:56:35
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                D9:77:48:13:09:B0:17:15:2A:95:47:CA:4C:13:2E:A9:AC:18:5D:AD
+                A7:11:90:E6:5F:5F:79:74:A3:1D:B5:9E:0C:15:F1:16:C5:D4:FB:6B
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        a5:b4:3f:fe:d9:aa:36:19:da:97:ab:60:50:43:50:e0:26:2e:
-        23:af:39:d9:d6:60:0a:41:5d:6a:2f:6f:f2:4c:4f:a8:22:40:
-        04:40:84:4e:0a:34:10:21:a5:9a:36:f6:7c:aa:e3:29:88:ce:
-        8c:1f:4a:cd:db:19:db:25:0c:04:46:28:67:ba:74:ff:74:78:
-        4e:20:9b:ef:31:95:c9:ab:46:53:f3:02:bb:25:78:3e:43:6a:
-        87:d6:86:61:a6:3e:8a:91:91:a6:88:f2:32:2d:b2:51:22:46:
-        9a:b3:b6:c9:45:90:83:c2:0f:d7:a2:4a:1b:61:30:3f:55:3d:
-        47:1f
+         5f:db:a1:d4:03:bc:a0:f9:d7:80:88:ac:94:2b:22:cc:1c:88:
+         56:65:bd:0d:57:d6:d4:ae:5c:a2:27:44:7c:5e:4d:23:8c:ba:
+         fe:1c:a6:49:96:20:c2:f5:45:cf:52:0e:0a:80:40:5b:1c:e7:
+         83:2b:d4:72:6c:95:10:c6:a7:44:27:85:6b:e5:37:f5:a4:25:
+         70:e4:e0:0e:de:1d:c1:72:1f:05:be:0f:4b:23:61:38:e3:52:
+         cb:05:c3:f4:41:26:80:58:ea:02:c6:6b:7d:f8:9f:41:40:76:
+         94:44:59:2e:da:bc:a8:54:11:22:bc:58:ff:61:85:3c:60:e7:
+         67:e6
 -----BEGIN CERTIFICATE-----
-MIIDLzCCApigAwIBAgIBEDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMTEw
-NDExMjIzNzQ0WhcNMTQwMTA1MjIzNzQ0WjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3RhMzCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA4aPQUdwLc29E8sdr8p3aVt7UQWF1SHgQ
-LFPxwSgBShBTfTK84gGidVkLzzr8QbgsNvv+PdmiQXtuPAqpfnRahuoGaiutPH4y
-i5ekulPBuLzwj4AiU5dmu4AVBZbc32IpTRXfheaQME0p0wS3TyJAuKEi7Q5L5gCC
-34lIY4e1gFUCAwEAAaOB4DCB3TAdBgNVHQ4EFgQU2XdIEwmwFxUqlUfKTBMuqawY
-Xa0wgZoGA1UdIwSBkjCBj4AUevZRen+bqzc9TpMDkG1qhAl8Ot2hbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEW
-A3RhM4IJAPRYVGqDImbpMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEG
-MA0GCSqGSIb3DQEBCwUAA4GBAKW0P/7ZqjYZ2perYFBDUOAmLiOvOdnWYApBXWov
-b/JMT6giQARAhE4KNBAhpZo29nyq4ymIzowfSs3bGdslDARGKGe6dP90eE4gm+8x
-lcmrRlPzArsleD5DaofWhmGmPoqRkaaI8jItslEiRpqztslFkIPCD9eiShthMD9V
-PUcf
+MIIDMjCCApugAwIBAgIBEDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTEz
+MTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGEzMRYwFAYJKoZIhvcNAQkBFgdjaDFfdGEzMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6DjaQoGt1GWswdlSeILCBcCFHl5zB
+FXyeLVA829yM0DGcuXjGKlxTyu3TROL5k9i1tqaKwr2+T4v1oChoz+z54+lXqKvN
+pUUNguvwW6otG4hlMJ+hdFkf5dIl+dYxPwqiSpJdKjAuPy9ySJP4jXy/eSHj4ZGa
+pwMBuiCVptpWNQIDAQABo4HhMIHeMB0GA1UdDgQWBBSnEZDmX195dKMdtZ4MFfEW
+xdT7azCBmwYDVR0jBIGTMIGQgBS01Daf+MuiX1CJ2iHjJ8SR94SIRaFtpGswaTEL
+MAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRh
+IENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQDDAN0YTMxEjAQBgkqhkiG9w0B
+CQEWA3RhM4IJAMDEtH2I1uM+MA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD
+AgEGMA0GCSqGSIb3DQEBCwUAA4GBAF/bodQDvKD514CIrJQrIswciFZlvQ1X1tSu
+XKInRHxeTSOMuv4cpkmWIML1Rc9SDgqAQFsc54Mr1HJslRDGp0QnhWvlN/WkJXDk
+4A7eHcFyHwW+D0sjYTjjUssFw/RBJoBY6gLGa334n0FAdpREWS7avKhUESK8WP9h
+hTxg52fm
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/1A.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/1A.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 26 (0x1a)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
-            Not Before: Apr 11 22:37:47 2011 GMT
-            Not After : Jan  5 22:37:47 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a1:1f:54:43:20:65:63:b2:fc:8b:d7:f6:a8:90:
-                    f0:1e:b8:e9:06:37:cb:1b:c9:47:56:3a:3f:ec:7e:
-                    e6:ee:c6:9a:d4:15:0d:64:f7:d5:77:2f:52:31:6c:
-                    36:8d:2f:07:7f:0d:a7:cf:79:af:68:70:2b:74:a7:
-                    30:92:1e:55:fc:2a:f4:b7:c3:47:01:57:4f:65:ba:
-                    58:bf:75:73:02:4c:4c:a8:51:3d:82:ee:57:fa:93:
-                    64:d6:53:05:12:10:36:c9:9c:c3:af:6c:56:9d:20:
-                    44:4b:b4:bc:67:d8:06:99:8e:fa:32:4c:c1:4f:09:
-                    5a:46:ec:06:cf:ac:e1:fa:21
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:df:da:60:8b:c6:d6:55:f7:d0:5b:a7:5a:87:d2:
+                    90:7b:9c:46:31:96:5e:15:a0:c7:44:b3:79:ce:ae:
+                    d7:af:99:a9:fe:6d:c6:69:23:09:45:68:64:01:dc:
+                    a0:7e:8c:ed:c9:bc:14:d3:84:62:2a:8a:21:30:48:
+                    30:97:94:99:84:69:f0:c0:46:a4:72:82:51:30:fe:
+                    f0:fc:60:6c:ea:b8:7d:52:ce:fd:e5:20:b7:9f:4b:
+                    03:21:74:f3:58:35:3a:ef:f7:e0:84:64:06:84:36:
+                    62:e8:82:65:82:1e:56:c7:ea:1e:eb:65:7d:b3:83:
+                    9c:fc:e6:ba:65:c4:82:e3:5f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -29,27 +29,27 @@
                 <EMPTY>
 
     Signature Algorithm: sha256WithRSAEncryption
-        34:ad:5e:5d:7a:64:12:a2:c0:f9:85:cb:e4:5c:43:0a:e9:f7:
-        68:be:c5:96:93:83:04:ca:dc:2c:93:f6:a6:ec:fb:26:a7:9d:
-        dc:d3:e7:ee:f2:d2:93:90:10:3c:4f:8f:ce:0e:63:60:d7:5d:
-        6a:af:97:4d:3d:1b:4b:5c:e6:ed:24:19:c7:d9:20:27:0d:8e:
-        d2:e2:85:68:c2:45:ba:2e:70:9b:78:bd:91:b6:29:0e:75:93:
-        f3:c2:38:14:ee:37:c2:66:1b:cf:de:81:b1:64:eb:8d:19:c4:
-        b2:1d:33:66:47:83:dc:e3:5b:14:d9:69:30:d8:5c:90:5f:34:
-        48:d5
+         ae:2b:af:4b:e6:7b:a1:28:27:46:1e:10:55:c2:2c:e4:6b:e9:
+         f2:6c:38:87:ed:f1:da:d5:92:39:89:22:53:3e:b4:da:3d:ae:
+         8d:ea:42:15:bb:4d:c6:ef:50:9c:1d:8b:93:92:7d:33:31:bd:
+         48:79:76:15:d4:8a:fd:bd:ae:1d:61:43:8d:88:ec:83:8d:15:
+         c9:50:73:e0:07:1a:41:e7:b2:a0:ac:9b:33:ed:bd:73:c5:32:
+         25:dd:ad:01:4b:90:62:25:e8:75:8e:19:e8:f5:4b:b8:89:2a:
+         c6:eb:d6:9c:31:f5:83:dd:1d:f9:71:11:ce:3b:0c:f5:e3:e4:
+         89:0a
 -----BEGIN CERTIFICATE-----
-MIICczCCAdygAwIBAgIBGjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMTEw
-NDExMjIzNzQ3WhcNMTQwMTA1MjIzNzQ3WjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjFfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuMV90YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKEfVEMgZWOy/IvX9qiQ8B646QY3
-yxvJR1Y6P+x+5u7GmtQVDWT31XcvUjFsNo0vB38Np895r2hwK3SnMJIeVfwq9LfD
-RwFXT2W6WL91cwJMTKhRPYLuV/qTZNZTBRIQNsmcw69sVp0gREu0vGfYBpmO+jJM
-wU8JWkbsBs+s4fohAgMBAAGjITAfMA8GA1UdEwEB/wQFMAMBAf8wDAYDVR0SAQH/
-BAIwADANBgkqhkiG9w0BAQsFAAOBgQA0rV5demQSosD5hcvkXEMK6fdovsWWk4ME
-ytwsk/am7Psmp53c0+fu8tKTkBA8T4/ODmNg111qr5dNPRtLXObtJBnH2SAnDY7S
-4oVowkW6LnCbeL2RtikOdZPzwjgU7jfCZhvP3oGxZOuNGcSyHTNmR4Pc41sU2Wkw
-2FyQXzRI1Q==
+MIICdTCCAd6gAwIBAgIBGjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTEz
+MTIxMzAwMTMzNloXDTE2MDkwODAwMTMzNlowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuMV90YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS4xX3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA39pgi8bWVffQW6dah9KQe5xG
+MZZeFaDHRLN5zq7Xr5mp/m3GaSMJRWhkAdygfoztybwU04RiKoohMEgwl5SZhGnw
+wEakcoJRMP7w/GBs6rh9Us795SC3n0sDIXTzWDU67/fghGQGhDZi6IJlgh5Wx+oe
+62V9s4Oc/Oa6ZcSC418CAwEAAaMhMB8wDwYDVR0TAQH/BAUwAwEB/zAMBgNVHRIB
+Af8EAjAAMA0GCSqGSIb3DQEBCwUAA4GBAK4rr0vme6EoJ0YeEFXCLORr6fJsOIft
+8drVkjmJIlM+tNo9ro3qQhW7TcbvUJwdi5OSfTMxvUh5dhXUiv29rh1hQ42I7ION
+FclQc+AHGkHnsqCsmzPtvXPFMiXdrQFLkGIl6HWOGej1S7iJKsbr1pwx9YPdHflx
+Ec47DPXj5IkK
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/1C.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/1C.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 28 (0x1c)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
             Not Before: Jan  1 01:01:01 2009 GMT
             Not After : Jan  2 01:01:01 2009 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c7:97:bd:7a:78:72:f6:bb:6f:5b:ca:07:34:d8:
-                    70:93:94:39:d6:9c:73:b2:58:c6:fa:10:eb:8e:c7:
-                    54:39:fd:9a:35:f5:2c:a4:ae:e6:ca:a2:9c:07:0c:
-                    57:05:78:cc:8b:98:2e:39:e8:74:73:28:bf:f7:bf:
-                    d1:fb:5d:10:9d:f0:19:75:9d:35:fe:50:97:76:70:
-                    6d:00:79:66:1a:2f:af:c6:12:45:16:45:ea:3e:f0:
-                    90:3b:56:9d:ed:f7:70:ba:de:f7:ec:55:2b:ee:b1:
-                    9b:fb:1d:55:46:65:86:c3:1b:9e:50:b9:8c:b9:d3:
-                    02:73:aa:e6:1e:4d:11:2b:bf
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:db:7e:41:d8:93:1f:35:e5:6b:38:25:93:e5:99:
+                    cf:fe:c7:b8:ab:0b:14:47:23:66:52:c7:d4:18:58:
+                    ff:39:a6:c4:a3:44:2e:46:be:24:7b:9d:71:26:12:
+                    6a:99:bd:92:01:5a:dc:a9:36:3c:2d:f8:42:b8:5f:
+                    db:87:8f:09:9a:83:32:5c:b6:1d:c5:e4:aa:47:6d:
+                    46:11:16:72:44:d7:49:ea:d3:4a:a4:52:9a:f4:8a:
+                    b5:e4:ef:32:7b:71:a0:d7:8e:71:86:22:34:44:4a:
+                    95:5a:37:ef:c4:7f:57:1f:99:32:39:ef:ab:94:05:
+                    1b:9a:88:de:39:85:56:4c:f7
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                5A:E6:5A:C4:85:7D:C2:25:75:F9:C2:6A:93:15:18:69:7F:57:47:7C
+                91:8B:82:B9:57:2C:1B:DB:4B:F6:16:04:D7:3F:04:10:DD:8B:3B:05
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        23:82:0a:78:02:e9:9f:de:a1:62:2d:47:42:8d:f8:88:26:cf:
-        3b:31:64:91:56:e1:50:eb:46:12:61:6b:e4:bd:97:43:f5:f7:
-        33:b4:92:34:62:31:8b:df:7c:13:44:ed:04:24:73:4a:35:17:
-        98:15:ad:75:3f:33:bf:86:84:e2:29:34:7e:de:90:a1:99:f5:
-        8a:37:85:98:7d:8e:71:64:6a:1d:aa:47:57:9d:ad:e3:07:90:
-        0a:06:7c:08:e2:97:25:20:38:c9:41:62:d5:96:fb:fe:0e:b4:
-        1c:e1:20:75:7d:6a:f3:62:1d:cc:72:90:a6:13:58:48:af:e4:
-        c9:b1
+         8a:bc:bf:7b:28:d4:bd:a2:a9:91:e8:24:cf:1e:1b:05:7c:32:
+         68:71:40:9a:ef:48:3c:58:43:6c:ae:90:7a:50:a3:49:86:12:
+         57:21:00:0c:49:28:ec:31:fb:04:58:a4:24:c6:7e:14:9d:5a:
+         96:bd:ba:cd:c1:31:cd:c8:f0:77:de:3f:81:0a:d0:31:65:f2:
+         d5:11:c9:6f:cc:5a:f8:f3:c1:8f:31:37:75:3a:c6:6d:6d:6e:
+         d7:16:0a:9b:b0:ce:07:d7:97:36:61:37:5e:4a:16:df:8d:97:
+         f4:71:fe:9b:32:4b:b6:d2:27:f4:9a:7c:b8:83:b3:92:48:2c:
+         ec:0c
 -----BEGIN CERTIFICATE-----
-MIIDMzCCApygAwIBAgIBHDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMDkw
-MTAxMDEwMTAxWhcNMDkwMTAyMDEwMTAxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjJfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuMl90YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMeXvXp4cva7b1vKBzTYcJOUOdac
-c7JYxvoQ647HVDn9mjX1LKSu5sqinAcMVwV4zIuYLjnodHMov/e/0ftdEJ3wGXWd
-Nf5Ql3ZwbQB5Zhovr8YSRRZF6j7wkDtWne33cLre9+xVK+6xm/sdVUZlhsMbnlC5
-jLnTAnOq5h5NESu/AgMBAAGjgeAwgd0wHQYDVR0OBBYEFFrmWsSFfcIldfnCapMV
-GGl/V0d8MIGaBgNVHSMEgZIwgY+AFHr2UXp/m6s3PU6TA5BtaoQJfDrdoWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcN
-AQkBFgN0YTOCCQD0WFRqgyJm6TAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
-AwIBBjANBgkqhkiG9w0BAQsFAAOBgQAjggp4Aumf3qFiLUdCjfiIJs87MWSRVuFQ
-60YSYWvkvZdD9fcztJI0YjGL33wTRO0EJHNKNReYFa11PzO/hoTiKTR+3pChmfWK
-N4WYfY5xZGodqkdXna3jB5AKBnwI4pclIDjJQWLVlvv+DrQc4SB1fWrzYh3McpCm
-E1hIr+TJsQ==
+MIIDNjCCAp+gAwIBAgIBHDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTA5
+MDEwMTAxMDEwMVoXDTA5MDEwMjAxMDEwMVowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuMl90YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS4yX3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA235B2JMfNeVrOCWT5ZnP/se4
+qwsURyNmUsfUGFj/OabEo0QuRr4ke51xJhJqmb2SAVrcqTY8LfhCuF/bh48JmoMy
+XLYdxeSqR21GERZyRNdJ6tNKpFKa9Iq15O8ye3Gg145xhiI0REqVWjfvxH9XH5ky
+Oe+rlAUbmojeOYVWTPcCAwEAAaOB4TCB3jAdBgNVHQ4EFgQUkYuCuVcsG9tL9hYE
+1z8EEN2LOwUwgZsGA1UdIwSBkzCBkIAUtNQ2n/jLol9Qidoh4yfEkfeEiEWhbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZI
+hvcNAQkBFgN0YTOCCQDAxLR9iNbjPjAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB
+/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQCKvL97KNS9oqmR6CTPHhsFfDJocUCa
+70g8WENsrpB6UKNJhhJXIQAMSSjsMfsEWKQkxn4UnVqWvbrNwTHNyPB33j+BCtAx
+ZfLVEclvzFr488GPMTd1OsZtbW7XFgqbsM4H15c2YTdeShbfjZf0cf6bMku20if0
+mny4g7OSSCzsDA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/1E.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/1E.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 30 (0x1e)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
             Not Before: Jan  1 01:01:01 2035 GMT
             Not After : Jan  2 01:01:01 2035 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d9:34:eb:28:22:6a:51:f8:11:2c:ee:1f:6d:c9:
-                    f1:12:5a:04:33:dd:d6:27:ca:9a:40:ae:df:5c:78:
-                    53:28:c8:37:d2:47:14:e1:fc:22:ea:90:d9:19:05:
-                    08:fd:b7:99:20:97:28:23:fd:3d:62:87:0d:29:a0:
-                    de:95:61:33:6c:d6:e0:65:db:c1:8b:8c:70:c3:ce:
-                    66:e9:93:ee:92:9f:87:2c:d4:6f:1d:e1:92:cb:8a:
-                    38:a4:95:0a:6a:a2:94:c6:41:25:17:ce:a6:01:fb:
-                    cf:03:52:40:93:34:37:b5:74:48:15:d4:e7:64:82:
-                    46:ee:b3:bd:b5:1f:3b:42:81
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ce:58:8a:05:67:47:a9:62:99:37:13:35:4c:74:
+                    75:9b:2f:d7:4c:23:7a:cd:60:35:0c:95:4b:58:b3:
+                    dd:c8:2d:69:ad:3c:8d:d3:27:0d:02:06:d0:4b:6c:
+                    6e:57:e9:1f:3c:dc:f3:88:22:25:86:35:13:91:3c:
+                    9f:76:67:a4:ae:98:63:d2:73:4d:2f:07:d5:7f:80:
+                    7e:27:92:25:16:aa:32:fe:7a:17:65:d5:9f:ee:39:
+                    9f:c8:a1:57:6a:9b:2d:e3:61:d9:35:d5:94:fb:fa:
+                    95:21:c3:31:33:50:d6:2f:e5:c0:7a:bb:a7:61:a4:
+                    e0:9b:5e:ca:99:2a:5d:6a:db
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                E0:C8:F3:4A:A9:FE:FA:63:97:C7:CE:EE:A8:27:45:F4:C5:11:8F:A6
+                28:44:43:26:57:0F:45:87:1A:A5:36:FB:0F:49:91:4B:A1:38:F3:ED
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        8d:45:1b:e3:e0:58:10:d4:92:66:aa:50:1a:ee:7a:d9:99:82:
-        7b:6e:3b:9b:88:9e:7c:a2:35:34:bb:77:9d:1f:79:d2:5d:aa:
-        b6:91:f8:07:ff:dc:63:81:d5:f3:e2:47:27:cc:79:2a:33:c8:
-        77:d5:9b:9a:f0:2e:58:64:d3:cb:fb:e4:f9:55:bb:89:9c:36:
-        8f:dd:84:95:a9:8c:8c:d3:6b:81:f8:64:b1:8a:15:20:59:10:
-        e3:5c:b3:05:c6:cd:d1:cb:03:3c:39:84:1c:93:f3:67:5c:10:
-        09:e9:99:1a:a0:45:21:ea:16:31:a1:3d:74:4d:27:75:f9:3d:
-        aa:df
+         b8:a1:7b:ba:b7:10:91:c0:21:86:fe:4d:01:f7:14:34:d9:aa:
+         dc:f3:04:56:c2:08:e6:66:f5:77:55:7e:dd:ea:b5:49:ff:d9:
+         32:39:2c:c9:9f:2f:9c:b3:cc:68:25:3e:d4:92:ef:be:b7:a1:
+         a5:d6:8c:31:3d:3a:7f:f4:5d:e8:ca:a3:30:29:ff:89:82:63:
+         cb:46:47:34:e8:ce:25:dd:a4:09:61:0b:08:7b:fd:24:1b:2b:
+         2d:9b:b9:84:ba:9e:fe:c1:2a:bd:df:e5:86:08:9c:74:ca:51:
+         c8:2e:b8:24:13:49:8c:a4:3e:c1:48:44:bd:30:18:40:88:43:
+         c1:a6
 -----BEGIN CERTIFICATE-----
-MIIDMzCCApygAwIBAgIBHjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMzUw
-MTAxMDEwMTAxWhcNMzUwMTAyMDEwMTAxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjNfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuM190YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANk06ygialH4ESzuH23J8RJaBDPd
-1ifKmkCu31x4UyjIN9JHFOH8IuqQ2RkFCP23mSCXKCP9PWKHDSmg3pVhM2zW4GXb
-wYuMcMPOZumT7pKfhyzUbx3hksuKOKSVCmqilMZBJRfOpgH7zwNSQJM0N7V0SBXU
-52SCRu6zvbUfO0KBAgMBAAGjgeAwgd0wHQYDVR0OBBYEFODI80qp/vpjl8fO7qgn
-RfTFEY+mMIGaBgNVHSMEgZIwgY+AFHr2UXp/m6s3PU6TA5BtaoQJfDrdoWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcN
-AQkBFgN0YTOCCQD0WFRqgyJm6TAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
-AwIBBjANBgkqhkiG9w0BAQsFAAOBgQCNRRvj4FgQ1JJmqlAa7nrZmYJ7bjubiJ58
-ojU0u3edH3nSXaq2kfgH/9xjgdXz4kcnzHkqM8h31Zua8C5YZNPL++T5VbuJnDaP
-3YSVqYyM02uB+GSxihUgWRDjXLMFxs3RywM8OYQck/NnXBAJ6ZkaoEUh6hYxoT10
-TSd1+T2q3w==
+MIIDNjCCAp+gAwIBAgIBHjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTM1
+MDEwMTAxMDEwMVoXDTM1MDEwMjAxMDEwMVowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuM190YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS4zX3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAzliKBWdHqWKZNxM1THR1my/X
+TCN6zWA1DJVLWLPdyC1prTyN0ycNAgbQS2xuV+kfPNzziCIlhjUTkTyfdmekrphj
+0nNNLwfVf4B+J5IlFqoy/noXZdWf7jmfyKFXapst42HZNdWU+/qVIcMxM1DWL+XA
+erunYaTgm17KmSpdatsCAwEAAaOB4TCB3jAdBgNVHQ4EFgQUKERDJlcPRYcapTb7
+D0mRS6E48+0wgZsGA1UdIwSBkzCBkIAUtNQ2n/jLol9Qidoh4yfEkfeEiEWhbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZI
+hvcNAQkBFgN0YTOCCQDAxLR9iNbjPjAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB
+/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQC4oXu6txCRwCGG/k0B9xQ02arc8wRW
+wgjmZvV3VX7d6rVJ/9kyOSzJny+cs8xoJT7Uku++t6Gl1owxPTp/9F3oyqMwKf+J
+gmPLRkc06M4l3aQJYQsIe/0kGystm7mEup7+wSq93+WGCJx0ylHILrgkE0mMpD7B
+SES9MBhAiEPBpg==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/20.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/20.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,61 +2,61 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 32 (0x20)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
             Not Before: Jan  1 01:01:01 2035 GMT
             Not After : Jan  2 01:01:01 2035 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cc:54:a0:55:75:b1:69:33:96:b6:97:29:82:06:
-                    06:46:f2:43:2f:19:57:bf:92:f0:4e:b5:01:65:d3:
-                    dc:e3:cf:5e:a9:f5:99:8e:91:e9:ad:88:15:8b:25:
-                    5e:92:c6:fd:d6:9e:e5:27:56:59:4a:09:e0:84:b8:
-                    86:af:bb:9d:e9:d2:99:f9:84:48:d6:b6:35:e8:aa:
-                    e0:b3:ac:94:09:7f:b8:67:53:75:26:65:16:b7:cf:
-                    92:52:be:5f:07:da:dd:f8:b1:1c:7c:54:37:7f:66:
-                    f7:dc:97:cd:d2:0d:fa:58:a4:2e:96:b8:83:fe:e2:
-                    3d:b6:fb:c5:08:46:ba:1b:47
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:e9:3c:28:6e:b8:7a:e3:7a:f2:ee:5e:69:7a:71:
+                    b8:bb:97:d5:d3:c4:77:3e:90:f3:29:69:b8:51:ba:
+                    8b:27:4d:3f:b2:10:76:86:6e:38:4a:49:be:ce:01:
+                    c5:d2:0e:6e:0e:a9:51:e9:94:57:ce:67:4b:99:ca:
+                    84:93:a9:f9:e6:35:1c:0f:d6:3d:b1:c1:c7:00:d7:
+                    fa:2c:05:a0:20:0d:86:6d:32:c0:54:0f:e8:b9:6e:
+                    b5:dd:1a:00:4c:89:bf:d4:6d:79:0e:e7:4e:10:d2:
+                    fb:75:2c:03:da:75:c8:e1:b7:dc:2e:42:c5:9b:ec:
+                    b2:f1:15:6d:db:56:f9:20:a3
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                F8:0C:60:C6:C6:4D:79:11:F2:CD:D2:91:28:DF:F6:26:6C:BB:B0:ED
+                33:65:69:5E:6D:D8:12:02:E9:68:A2:6C:7D:77:F1:38:D8:7B:97:E6
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        c8:ba:31:b9:ed:17:ae:ac:ca:cd:4d:48:f6:b6:66:1c:17:c5:
-        8a:18:96:e8:9b:47:de:b3:7e:23:21:78:cc:f9:63:09:4e:56:
-        64:a1:de:33:16:8b:6a:94:c1:68:0a:72:dd:8e:b6:8c:dd:61:
-        cf:05:07:12:e3:4f:41:52:bc:73:33:a5:3e:94:ca:40:53:74:
-        a7:9c:46:f2:73:5b:b7:7f:df:18:7f:60:2f:2d:4b:41:8c:78:
-        c4:5f:4c:a8:85:a4:2c:84:91:b3:ab:60:61:ca:93:67:1b:2a:
-        0e:9a:e1:e8:a5:dc:5e:78:18:a3:b3:4b:86:4d:03:08:78:9b:
-        70:bc
+         5c:06:87:8e:6c:26:b3:5d:7c:94:c0:e3:7d:9e:8c:7c:bf:86:
+         e0:07:8a:65:95:af:8f:93:0c:a6:72:e5:cb:36:a5:69:03:95:
+         03:7f:e0:18:c8:f2:da:ce:99:b8:54:7a:49:75:f2:61:00:d4:
+         f4:63:e1:5c:cc:f0:91:e7:85:92:0d:7e:91:4b:3a:8b:76:e6:
+         a0:c8:51:28:06:44:d2:c8:a8:4c:da:be:7e:78:88:45:d3:f7:
+         07:92:90:fc:96:4d:7d:ce:5a:c9:9a:21:d9:66:98:3e:9b:5d:
+         18:9a:0c:b8:c4:10:86:4d:06:15:d9:ea:19:9b:e7:f7:e2:74:
+         25:eb
 -----BEGIN CERTIFICATE-----
-MIIDIzCCAoygAwIBAgIBIDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMzUw
-MTAxMDEwMTAxWhcNMzUwMTAyMDEwMTAxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjRfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuNF90YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMxUoFV1sWkzlraXKYIGBkbyQy8Z
-V7+S8E61AWXT3OPPXqn1mY6R6a2IFYslXpLG/dae5SdWWUoJ4IS4hq+7nenSmfmE
-SNa2Neiq4LOslAl/uGdTdSZlFrfPklK+Xwfa3fixHHxUN39m99yXzdIN+likLpa4
-g/7iPbb7xQhGuhtHAgMBAAGjgdAwgc0wHQYDVR0OBBYEFPgMYMbGTXkR8s3SkSjf
-9iZsu7DtMIGaBgNVHSMEgZIwgY+AFHr2UXp/m6s3PU6TA5BtaoQJfDrdoWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcN
-AQkBFgN0YTOCCQD0WFRqgyJm6TAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEB
-CwUAA4GBAMi6MbntF66sys1NSPa2ZhwXxYoYluibR96zfiMheMz5YwlOVmSh3jMW
-i2qUwWgKct2OtozdYc8FBxLjT0FSvHMzpT6UykBTdKecRvJzW7d/3xh/YC8tS0GM
-eMRfTKiFpCyEkbOrYGHKk2cbKg6a4eil3F54GKOzS4ZNAwh4m3C8
+MIIDJjCCAo+gAwIBAgIBIDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTM1
+MDEwMTAxMDEwMVoXDTM1MDEwMjAxMDEwMVowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuNF90YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS40X3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA6Twobrh643ry7l5penG4u5fV
+08R3PpDzKWm4UbqLJ00/shB2hm44Skm+zgHF0g5uDqlR6ZRXzmdLmcqEk6n55jUc
+D9Y9scHHANf6LAWgIA2GbTLAVA/ouW613RoATIm/1G15DudOENL7dSwD2nXI4bfc
+LkLFm+yy8RVt21b5IKMCAwEAAaOB0TCBzjAdBgNVHQ4EFgQUM2VpXm3YEgLpaKJs
+fXfxONh7l+YwgZsGA1UdIwSBkzCBkIAUtNQ2n/jLol9Qidoh4yfEkfeEiEWhbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZI
+hvcNAQkBFgN0YTOCCQDAxLR9iNbjPjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3
+DQEBCwUAA4GBAFwGh45sJrNdfJTA432ejHy/huAHimWVr4+TDKZy5cs2pWkDlQN/
+4BjI8trOmbhUekl18mEA1PRj4VzM8JHnhZINfpFLOot25qDIUSgGRNLIqEzavn54
+iEXT9weSkPyWTX3OWsmaIdlmmD6bXRiaDLjEEIZNBhXZ6hmb5/fidCXr
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/22.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/22.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 34 (0x22)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Validity
-            Not Before: Apr 11 22:37:49 2011 GMT
-            Not After : Jan  5 22:37:49 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b6:ab:16:bb:1d:ee:25:5a:2f:58:e7:db:d8:0a:
-                    e7:36:63:d5:ca:de:60:b5:90:c2:82:e3:ec:7d:49:
-                    0c:a9:b6:95:c8:a1:ab:04:0c:a9:09:e1:93:a6:be:
-                    43:36:7e:1b:61:28:1b:38:03:a2:06:19:88:72:a9:
-                    b9:a2:71:ff:db:e1:3c:85:98:01:b2:5f:93:a0:4a:
-                    b8:e7:36:ad:8f:50:8c:d6:a1:14:29:b0:ee:ec:e2:
-                    08:3f:7d:34:a1:c4:5f:3a:e9:4f:b0:c0:d6:5f:f2:
-                    10:78:2b:ae:f4:ee:28:c8:29:21:9f:ce:70:d5:fb:
-                    ea:33:fc:e2:5a:5c:e2:1b:d9
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b4:25:1c:3a:c2:26:af:8d:82:4d:29:e3:e0:78:
+                    6f:2b:7f:3c:b1:8c:c0:37:96:71:d2:42:21:df:2e:
+                    c4:c0:5a:60:e4:71:6f:05:df:88:a8:4b:ec:87:54:
+                    8d:08:c9:f7:19:84:a5:d0:cc:cb:43:c3:70:69:67:
+                    2e:4c:be:e6:2d:93:90:f9:02:30:a7:43:d2:1f:e5:
+                    d4:cf:5b:5c:74:88:06:0e:ee:cd:78:2c:2f:27:4c:
+                    99:2f:be:9a:73:5b:9b:1c:e3:67:54:b6:74:a7:c9:
+                    31:d3:63:6a:c5:4a:50:22:eb:af:e2:cd:7a:de:59:
+                    68:6a:a6:0e:26:d6:52:b6:a1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                2A:94:C1:FF:E0:11:A0:91:F1:71:46:35:9A:37:3C:BC:C4:21:4A:8F
+                29:7A:F9:B4:E3:1B:8F:19:63:52:FA:19:A0:AB:DA:37:E4:70:A9:71
             X509v3 Authority Key Identifier: 
-                keyid:3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
-                serial:BA:06:FD:EC:89:18:B5:7F
+                keyid:84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
+                serial:E8:F7:8D:38:FA:4B:55:DD
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        9d:2d:ff:a2:d2:42:31:72:9e:6f:8d:45:2c:21:9b:15:cf:89:
-        06:70:3b:5f:3e:2c:73:b9:08:d9:be:48:d8:6b:dc:23:86:3a:
-        ab:3c:16:80:13:62:a4:12:f8:ee:e7:6f:d6:e8:4f:ad:36:eb:
-        1e:81:c8:03:1c:65:ba:be:55:6d:07:8f:bc:fa:ba:d2:14:90:
-        1d:02:35:bd:5d:bd:0b:fb:48:57:94:6d:fe:71:85:ce:9f:65:
-        9c:31:80:13:56:b2:6f:2a:03:b6:1d:7f:5a:4a:dd:50:63:7a:
-        46:40:4b:1d:c3:71:5d:72:72:f0:50:f8:db:60:56:97:c8:cd:
-        73:83
+         91:d2:2e:6f:55:ce:c6:39:d8:b4:1f:7a:df:7f:bd:8f:4e:66:
+         ec:10:3d:35:f1:36:22:90:ae:b7:16:e4:48:f5:ec:63:27:e8:
+         88:32:78:ac:21:cc:71:f9:46:6a:73:b7:09:24:a7:44:68:41:
+         a5:07:f9:a3:ec:c7:53:ca:68:e4:09:68:b7:ee:11:f2:8c:08:
+         80:3c:a5:56:e2:f3:a8:aa:1e:34:99:49:26:8a:1f:50:36:d2:
+         0e:ee:b6:a0:a6:e6:b0:94:41:a6:bc:de:93:6f:af:b3:fa:f4:
+         a3:c3:46:83:f8:27:67:8e:9e:40:ec:79:08:0b:e2:46:73:61:
+         0d:c6
 -----BEGIN CERTIFICATE-----
-MIIDLzCCApigAwIBAgIBIjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGE0MRIwEAYJKoZIhvcNAQkBFgN0YTQwHhcNMTEw
-NDExMjIzNzQ5WhcNMTQwMTA1MjIzNzQ5WjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3RhNDCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAtqsWux3uJVovWOfb2ArnNmPVyt5gtZDC
-guPsfUkMqbaVyKGrBAypCeGTpr5DNn4bYSgbOAOiBhmIcqm5onH/2+E8hZgBsl+T
-oEq45zatj1CM1qEUKbDu7OIIP300ocRfOulPsMDWX/IQeCuu9O4oyCkhn85w1fvq
-M/ziWlziG9kCAwEAAaOB4DCB3TAdBgNVHQ4EFgQUKpTB/+ARoJHxcUY1mjc8vMQh
-So8wgZoGA1UdIwSBkjCBj4AUPl9k6WPLnBDQkfRFYfLx6kJp7KWhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEW
-A3RhNIIJALoG/eyJGLV/MA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEG
-MA0GCSqGSIb3DQEBCwUAA4GBAJ0t/6LSQjFynm+NRSwhmxXPiQZwO18+LHO5CNm+
-SNhr3COGOqs8FoATYqQS+O7nb9boT6026x6ByAMcZbq+VW0Hj7z6utIUkB0CNb1d
-vQv7SFeUbf5xhc6fZZwxgBNWsm8qA7Ydf1pK3VBjekZASx3DcV1ycvBQ+NtgVpfI
-zXOD
+MIIDMjCCApugAwIBAgIBIjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhNDESMBAGCSqGSIb3DQEJARYDdGE0MB4XDTEz
+MTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGE0MRYwFAYJKoZIhvcNAQkBFgdjaDFfdGE0MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC0JRw6wiavjYJNKePgeG8rfzyxjMA3
+lnHSQiHfLsTAWmDkcW8F34ioS+yHVI0IyfcZhKXQzMtDw3BpZy5MvuYtk5D5AjCn
+Q9If5dTPW1x0iAYO7s14LC8nTJkvvppzW5sc42dUtnSnyTHTY2rFSlAi66/izXre
+WWhqpg4m1lK2oQIDAQABo4HhMIHeMB0GA1UdDgQWBBQpevm04xuPGWNS+hmgq9o3
+5HCpcTCBmwYDVR0jBIGTMIGQgBSERimIdDHvpsw841gp3r79G/RZmKFtpGswaTEL
+MAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRh
+IENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQDDAN0YTQxEjAQBgkqhkiG9w0B
+CQEWA3RhNIIJAOj3jTj6S1XdMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD
+AgEGMA0GCSqGSIb3DQEBCwUAA4GBAJHSLm9VzsY52LQfet9/vY9OZuwQPTXxNiKQ
+rrcW5Ej17GMn6IgyeKwhzHH5Rmpztwkkp0RoQaUH+aPsx1PKaOQJaLfuEfKMCIA8
+pVbi86iqHjSZSSaKH1A20g7utqCm5rCUQaa83pNvr7P69KPDRoP4J2eOnkDseQgL
+4kZzYQ3G
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/26.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/26.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 38 (0x26)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Validity
-            Not Before: Apr 11 22:37:51 2011 GMT
-            Not After : Jan  5 22:37:51 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b8:6a:e3:b5:bf:65:66:f4:b3:32:73:a9:64:b7:
-                    dd:a0:4a:e9:70:d3:7b:5c:1b:5b:76:e7:56:a3:72:
-                    0e:9d:fa:9f:b2:a5:47:eb:3f:db:9a:7b:45:d2:17:
-                    77:ca:05:b3:95:22:15:78:9e:ab:f3:4b:fa:83:89:
-                    e6:19:54:22:69:18:67:ba:bb:37:2a:b4:93:5a:bb:
-                    9c:68:5b:ec:b1:7e:ac:01:7b:b3:d9:91:57:93:eb:
-                    43:e6:a6:35:e1:b5:c2:2d:ca:bb:63:af:35:d6:b4:
-                    16:9a:a3:7a:1c:ad:e1:f4:fb:63:4a:fd:3d:57:99:
-                    33:b8:1e:41:e9:f9:42:80:33
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ba:40:be:7e:1b:2f:92:11:cc:dc:44:14:76:87:
+                    8a:6a:94:b6:28:4e:87:5b:bc:57:46:75:63:38:4d:
+                    90:3e:7a:46:0e:87:e9:a9:04:1a:7d:e5:20:dc:81:
+                    9a:79:7e:1b:ab:ce:50:ce:47:54:04:98:16:d5:a6:
+                    6d:16:3c:52:ef:ed:43:c5:9b:d3:c8:48:cb:47:5d:
+                    08:1d:d1:44:fd:7c:c7:54:41:11:3b:3e:ae:bb:7f:
+                    94:a6:13:8f:89:6c:24:b3:a8:5e:e2:5d:20:40:85:
+                    2b:a0:ac:ed:a3:a8:b2:15:59:fc:ad:e8:5d:72:ee:
+                    64:eb:9c:30:8c:0a:97:32:f9
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                C9:2D:8D:6C:97:26:48:F8:6F:14:66:05:ED:06:D8:BF:21:8A:6F:FD
+                D1:74:80:71:CE:2E:24:57:71:C0:CA:50:42:8B:B3:99:0C:C7:6B:AD
             X509v3 Authority Key Identifier: 
-                keyid:3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
-                serial:BA:06:FD:EC:89:18:B5:7F
+                keyid:84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
+                serial:E8:F7:8D:38:FA:4B:55:DD
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign
     Signature Algorithm: sha256WithRSAEncryption
-        8e:ea:a2:87:02:69:a4:9f:44:22:c3:62:83:9c:fb:e2:3f:59:
-        d0:09:0f:57:81:8f:59:37:21:c5:59:81:36:8d:9c:4e:c0:0f:
-        4b:40:e6:db:ba:9f:d4:b8:86:2f:1b:1b:fd:2d:5d:4e:df:1b:
-        d4:b4:04:d0:07:b8:ad:25:52:1c:0b:ec:07:6c:21:b7:1d:65:
-        d3:a2:dc:a0:96:03:9d:2e:13:7a:a7:8a:29:55:95:5a:dc:ff:
-        6a:a4:4b:7a:26:7f:eb:ad:88:e9:80:5d:53:5e:0f:48:6a:21:
-        18:c9:89:be:83:38:51:40:b6:ad:5d:71:b2:2e:45:60:b3:1d:
-        69:9b
+         25:f7:af:7c:b8:de:50:02:c2:31:ed:50:89:5e:85:bc:e5:f4:
+         a0:03:7e:35:85:d5:2c:4c:bb:62:39:45:e9:50:9b:db:7a:4b:
+         91:e1:dd:e7:dc:b6:da:36:69:d7:2d:68:5c:96:a9:7b:e8:33:
+         17:4c:28:75:c2:6c:53:a8:11:8f:8f:23:89:59:25:8b:26:75:
+         4c:ee:9a:13:eb:78:28:52:dc:b2:fd:96:04:73:a8:78:9e:24:
+         b2:b2:85:88:84:10:ec:83:42:65:22:f1:b5:15:76:14:db:5c:
+         28:43:a4:62:df:27:4a:c5:4b:00:d5:44:83:24:37:f5:c5:4d:
+         b0:4a
 -----BEGIN CERTIFICATE-----
-MIIDMzCCApygAwIBAgIBJjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGE0MRIwEAYJKoZIhvcNAQkBFgN0YTQwHhcNMTEw
-NDExMjIzNzUxWhcNMTQwMTA1MjIzNzUxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjFfdGE0MRgwFgYJKoZIhvcNAQkBFgljaDEuMV90YTQw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALhq47W/ZWb0szJzqWS33aBK6XDT
-e1wbW3bnVqNyDp36n7KlR+s/25p7RdIXd8oFs5UiFXieq/NL+oOJ5hlUImkYZ7q7
-Nyq0k1q7nGhb7LF+rAF7s9mRV5PrQ+amNeG1wi3Ku2OvNda0Fpqjehyt4fT7Y0r9
-PVeZM7geQen5QoAzAgMBAAGjgeAwgd0wHQYDVR0OBBYEFMktjWyXJkj4bxRmBe0G
-2L8him/9MIGaBgNVHSMEgZIwgY+AFD5fZOljy5wQ0JH0RWHy8epCaeyloWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGE0MRIwEAYJKoZIhvcN
-AQkBFgN0YTSCCQC6Bv3siRi1fzAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
-AwICBDANBgkqhkiG9w0BAQsFAAOBgQCO6qKHAmmkn0Qiw2KDnPviP1nQCQ9XgY9Z
-NyHFWYE2jZxOwA9LQObbup/UuIYvGxv9LV1O3xvUtATQB7itJVIcC+wHbCG3HWXT
-otyglgOdLhN6p4opVZVa3P9qpEt6Jn/rrYjpgF1TXg9IaiEYyYm+gzhRQLatXXGy
-LkVgsx1pmw==
+MIIDNjCCAp+gAwIBAgIBJjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhNDESMBAGCSqGSIb3DQEJARYDdGE0MB4XDTEz
+MTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuMV90YTQxGDAWBgkqhkiG9w0BCQEWCWNoMS4xX3Rh
+NDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAukC+fhsvkhHM3EQUdoeKapS2
+KE6HW7xXRnVjOE2QPnpGDofpqQQafeUg3IGaeX4bq85QzkdUBJgW1aZtFjxS7+1D
+xZvTyEjLR10IHdFE/XzHVEEROz6uu3+UphOPiWwks6he4l0gQIUroKzto6iyFVn8
+rehdcu5k65wwjAqXMvkCAwEAAaOB4TCB3jAdBgNVHQ4EFgQU0XSAcc4uJFdxwMpQ
+QouzmQzHa60wgZsGA1UdIwSBkzCBkIAUhEYpiHQx76bMPONYKd6+/Rv0WZihbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGE0MRIwEAYJKoZI
+hvcNAQkBFgN0YTSCCQDo9404+ktV3TAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB
+/wQEAwICBDANBgkqhkiG9w0BAQsFAAOBgQAl9698uN5QAsIx7VCJXoW85fSgA341
+hdUsTLtiOUXpUJvbekuR4d3n3LbaNmnXLWhclql76DMXTCh1wmxTqBGPjyOJWSWL
+JnVM7poT63goUtyy/ZYEc6h4niSysoWIhBDsg0JlIvG1FXYU21woQ6Ri3ydKxUsA
+1USDJDf1xU2wSg==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/28.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/28.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,68 +2,70 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 40 (0x28)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta5/emailAddress=ta5
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta5/emailAddress=ta5
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e7:14:d9:dc:4c:60:0f:ad:49:9f:14:f8:2f:d9:
-                    0e:65:93:a4:c4:e5:6b:13:93:c1:79:40:14:4f:19:
-                    56:d7:88:07:9b:de:45:40:ce:24:91:44:b0:14:6b:
-                    8b:4d:f5:d1:b2:75:cc:5c:d7:ed:73:2c:d2:75:aa:
-                    50:6f:94:00:8d:0e:bb:15:8c:ef:a1:5d:2c:23:73:
-                    95:f7:48:b5:4a:3b:de:2a:a1:7c:03:aa:28:17:f0:
-                    a7:46:b9:86:f3:98:a7:31:ff:e1:75:b4:28:b4:11:
-                    b4:4b:ca:64:e4:cd:2a:f7:d8:6f:6b:73:64:ab:55:
-                    0b:5b:60:76:5f:ea:86:57:1f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c6:67:76:93:23:82:9f:2f:70:27:4f:64:9e:c3:
+                    80:4d:e3:9d:bb:f9:ea:2e:f1:02:e1:e1:a8:5b:f6:
+                    dc:c9:7b:ef:be:5a:41:11:bd:c4:51:e1:d8:74:6a:
+                    16:89:83:f7:3a:fd:0b:cc:9b:e6:96:d8:13:e3:ef:
+                    78:65:97:ff:81:90:97:e8:77:fd:ed:9c:56:2e:c7:
+                    a4:ec:f7:2c:fc:a0:f6:de:ab:ec:d6:e7:9e:35:e6:
+                    b7:dc:65:1b:c8:e4:5a:a2:9d:d8:5b:b9:fa:26:8c:
+                    8d:00:66:c4:05:28:9c:a8:3c:b1:81:c7:75:0a:51:
+                    ed:4f:49:d7:96:b5:8b:34:f9
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                59:7D:00:A7:48:7C:5E:D9:A2:26:D0:9A:83:3F:D0:03:9C:36:D5:50
+                8E:29:B3:96:C1:67:FE:34:F3:55:99:68:C4:DA:2A:C0:24:8A:19:C6
             X509v3 Authority Key Identifier: 
-                keyid:E7:E6:72:5B:A0:5F:2C:A6:40:45:1A:66:E4:45:A5:0F:1D:67:5D:93
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta5/emailAddress=ta5
-                serial:9C:19:39:11:06:1A:55:91
+                keyid:29:DA:B1:46:E3:61:51:AC:3C:3E:F6:78:5B:95:7B:6D:B2:F9:17:21
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta5/emailAddress=ta5
+                serial:A7:8F:F0:5E:6B:64:C2:46
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ta5_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ta5_crl.pem
 
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        a0:48:28:f4:94:07:dd:08:f2:c6:74:0d:a9:31:10:71:64:f8:
-        b5:c3:fb:82:8e:46:9d:30:fb:fd:9d:4b:c9:92:5b:c4:06:d2:
-        d0:5e:aa:91:f5:19:7c:c3:11:b2:26:ef:e6:01:cf:3e:ea:07:
-        d6:d2:f8:22:e6:a0:50:86:40:53:cc:ed:81:73:33:b1:a8:2b:
-        92:1a:10:f9:fc:30:43:84:4b:ca:ef:8c:d3:be:0a:63:f0:40:
-        99:be:80:88:c9:8f:2b:9a:82:9f:7b:56:9a:f1:08:e1:67:88:
-        30:fa:a1:12:bc:c8:ea:22:60:64:0f:91:80:48:cd:2a:5d:05:
-        ca:f7
+         9d:32:27:d7:4e:4e:8b:e4:9f:d0:0d:11:f3:e5:be:5f:7f:7e:
+         cf:ef:98:41:33:ba:04:ba:d9:7a:11:88:b8:13:66:74:44:1c:
+         fb:1e:f3:fa:d4:18:85:cd:ed:f0:f8:c2:be:ab:75:cf:65:da:
+         1a:77:01:0e:aa:49:ea:af:a7:db:39:84:f2:01:1d:28:e7:df:
+         22:a9:59:5a:21:f9:f9:30:84:64:52:50:01:9b:b2:bf:ca:8a:
+         b4:8b:36:96:e3:1a:ea:51:53:36:82:ba:88:8f:15:8c:e6:79:
+         59:aa:71:9b:4c:58:a2:68:f0:43:36:15:af:69:af:32:ed:49:
+         c8:9c
 -----BEGIN CERTIFICATE-----
-MIIDbTCCAtagAwIBAgIBKDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGE1MRIwEAYJKoZIhvcNAQkBFgN0YTUwHhcNMTEw
-NDExMjIzNzUyWhcNMTQwMTA1MjIzNzUyWjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhNTEWMBQGCSqGSIb3DQEJARYHY2gxX3RhNTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA5xTZ3ExgD61JnxT4L9kOZZOkxOVrE5PB
-eUAUTxlW14gHm95FQM4kkUSwFGuLTfXRsnXMXNftcyzSdapQb5QAjQ67FYzvoV0s
-I3OV90i1SjveKqF8A6ooF/CnRrmG85inMf/hdbQotBG0S8pk5M0q99hva3Nkq1UL
-W2B2X+qGVx8CAwEAAaOCAR0wggEZMB0GA1UdDgQWBBRZfQCnSHxe2aIm0JqDP9AD
-nDbVUDCBmgYDVR0jBIGSMIGPgBTn5nJboF8spkBFGmbkRaUPHWddk6FspGowaDEL
-MAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxv
-IFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAMTA3RhNTESMBAGCSqGSIb3DQEJ
-ARYDdGE1ggkAnBk5EQYaVZEwDwYDVR0TAQH/BAUwAwEB/zA6BgNVHR8EMzAxMC+g
-LaArhilodHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUvMC90YTVfY3JsLnBlbTAO
-BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAoEgo9JQH3QjyxnQNqTEQ
-cWT4tcP7go5GnTD7/Z1LyZJbxAbS0F6qkfUZfMMRsibv5gHPPuoH1tL4IuagUIZA
-U8ztgXMzsagrkhoQ+fwwQ4RLyu+M074KY/BAmb6AiMmPK5qCn3tWmvEI4WeIMPqh
-ErzI6iJgZA+RgEjNKl0Fyvc=
+MIIDcDCCAtmgAwIBAgIBKDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhNTESMBAGCSqGSIb3DQEJARYDdGE1MB4XDTEz
+MTIxMzAwMTMzOFoXDTE2MDkwODAwMTMzOFowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGE1MRYwFAYJKoZIhvcNAQkBFgdjaDFfdGE1MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGZ3aTI4KfL3AnT2Sew4BN4527+eou
+8QLh4ahb9tzJe+++WkERvcRR4dh0ahaJg/c6/QvMm+aW2BPj73hll/+BkJfod/3t
+nFYux6Ts9yz8oPbeq+zW55415rfcZRvI5FqindhbufomjI0AZsQFKJyoPLGBx3UK
+Ue1PSdeWtYs0+QIDAQABo4IBHjCCARowHQYDVR0OBBYEFI4ps5bBZ/4081WZaMTa
+KsAkihnGMIGbBgNVHSMEgZMwgZCAFCnasUbjYVGsPD72eFuVe22y+RchoW2kazBp
+MQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2Fu
+dGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhNTESMBAGCSqGSIb3
+DQEJARYDdGE1ggkAp4/wXmtkwkYwDwYDVR0TAQH/BAUwAwEB/zA6BgNVHR8EMzAx
+MC+gLaArhilodHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUvMC90YTVfY3JsLnBl
+bTAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAnTIn105Oi+Sf0A0R
+8+W+X39+z++YQTO6BLrZehGIuBNmdEQc+x7z+tQYhc3t8PjCvqt1z2XaGncBDqpJ
+6q+n2zmE8gEdKOffIqlZWiH5+TCEZFJQAZuyv8qKtIs2luMa6lFTNoK6iI8VjOZ5
+Wapxm0xYomjwQzYVr2mvMu1JyJw=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 26 (0x1a)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
-            Not Before: Apr 11 22:37:47 2011 GMT
-            Not After : Jan  5 22:37:47 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a1:1f:54:43:20:65:63:b2:fc:8b:d7:f6:a8:90:
-                    f0:1e:b8:e9:06:37:cb:1b:c9:47:56:3a:3f:ec:7e:
-                    e6:ee:c6:9a:d4:15:0d:64:f7:d5:77:2f:52:31:6c:
-                    36:8d:2f:07:7f:0d:a7:cf:79:af:68:70:2b:74:a7:
-                    30:92:1e:55:fc:2a:f4:b7:c3:47:01:57:4f:65:ba:
-                    58:bf:75:73:02:4c:4c:a8:51:3d:82:ee:57:fa:93:
-                    64:d6:53:05:12:10:36:c9:9c:c3:af:6c:56:9d:20:
-                    44:4b:b4:bc:67:d8:06:99:8e:fa:32:4c:c1:4f:09:
-                    5a:46:ec:06:cf:ac:e1:fa:21
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:df:da:60:8b:c6:d6:55:f7:d0:5b:a7:5a:87:d2:
+                    90:7b:9c:46:31:96:5e:15:a0:c7:44:b3:79:ce:ae:
+                    d7:af:99:a9:fe:6d:c6:69:23:09:45:68:64:01:dc:
+                    a0:7e:8c:ed:c9:bc:14:d3:84:62:2a:8a:21:30:48:
+                    30:97:94:99:84:69:f0:c0:46:a4:72:82:51:30:fe:
+                    f0:fc:60:6c:ea:b8:7d:52:ce:fd:e5:20:b7:9f:4b:
+                    03:21:74:f3:58:35:3a:ef:f7:e0:84:64:06:84:36:
+                    62:e8:82:65:82:1e:56:c7:ea:1e:eb:65:7d:b3:83:
+                    9c:fc:e6:ba:65:c4:82:e3:5f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -29,27 +29,27 @@
                 <EMPTY>
 
     Signature Algorithm: sha256WithRSAEncryption
-        34:ad:5e:5d:7a:64:12:a2:c0:f9:85:cb:e4:5c:43:0a:e9:f7:
-        68:be:c5:96:93:83:04:ca:dc:2c:93:f6:a6:ec:fb:26:a7:9d:
-        dc:d3:e7:ee:f2:d2:93:90:10:3c:4f:8f:ce:0e:63:60:d7:5d:
-        6a:af:97:4d:3d:1b:4b:5c:e6:ed:24:19:c7:d9:20:27:0d:8e:
-        d2:e2:85:68:c2:45:ba:2e:70:9b:78:bd:91:b6:29:0e:75:93:
-        f3:c2:38:14:ee:37:c2:66:1b:cf:de:81:b1:64:eb:8d:19:c4:
-        b2:1d:33:66:47:83:dc:e3:5b:14:d9:69:30:d8:5c:90:5f:34:
-        48:d5
+         ae:2b:af:4b:e6:7b:a1:28:27:46:1e:10:55:c2:2c:e4:6b:e9:
+         f2:6c:38:87:ed:f1:da:d5:92:39:89:22:53:3e:b4:da:3d:ae:
+         8d:ea:42:15:bb:4d:c6:ef:50:9c:1d:8b:93:92:7d:33:31:bd:
+         48:79:76:15:d4:8a:fd:bd:ae:1d:61:43:8d:88:ec:83:8d:15:
+         c9:50:73:e0:07:1a:41:e7:b2:a0:ac:9b:33:ed:bd:73:c5:32:
+         25:dd:ad:01:4b:90:62:25:e8:75:8e:19:e8:f5:4b:b8:89:2a:
+         c6:eb:d6:9c:31:f5:83:dd:1d:f9:71:11:ce:3b:0c:f5:e3:e4:
+         89:0a
 -----BEGIN CERTIFICATE-----
-MIICczCCAdygAwIBAgIBGjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMTEw
-NDExMjIzNzQ3WhcNMTQwMTA1MjIzNzQ3WjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjFfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuMV90YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKEfVEMgZWOy/IvX9qiQ8B646QY3
-yxvJR1Y6P+x+5u7GmtQVDWT31XcvUjFsNo0vB38Np895r2hwK3SnMJIeVfwq9LfD
-RwFXT2W6WL91cwJMTKhRPYLuV/qTZNZTBRIQNsmcw69sVp0gREu0vGfYBpmO+jJM
-wU8JWkbsBs+s4fohAgMBAAGjITAfMA8GA1UdEwEB/wQFMAMBAf8wDAYDVR0SAQH/
-BAIwADANBgkqhkiG9w0BAQsFAAOBgQA0rV5demQSosD5hcvkXEMK6fdovsWWk4ME
-ytwsk/am7Psmp53c0+fu8tKTkBA8T4/ODmNg111qr5dNPRtLXObtJBnH2SAnDY7S
-4oVowkW6LnCbeL2RtikOdZPzwjgU7jfCZhvP3oGxZOuNGcSyHTNmR4Pc41sU2Wkw
-2FyQXzRI1Q==
+MIICdTCCAd6gAwIBAgIBGjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTEz
+MTIxMzAwMTMzNloXDTE2MDkwODAwMTMzNlowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuMV90YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS4xX3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA39pgi8bWVffQW6dah9KQe5xG
+MZZeFaDHRLN5zq7Xr5mp/m3GaSMJRWhkAdygfoztybwU04RiKoohMEgwl5SZhGnw
+wEakcoJRMP7w/GBs6rh9Us795SC3n0sDIXTzWDU67/fghGQGhDZi6IJlgh5Wx+oe
+62V9s4Oc/Oa6ZcSC418CAwEAAaMhMB8wDwYDVR0TAQH/BAUwAwEB/zAMBgNVHRIB
+Af8EAjAAMA0GCSqGSIb3DQEBCwUAA4GBAK4rr0vme6EoJ0YeEFXCLORr6fJsOIft
+8drVkjmJIlM+tNo9ro3qQhW7TcbvUJwdi5OSfTMxvUh5dhXUiv29rh1hQ42I7ION
+FclQc+AHGkHnsqCsmzPtvXPFMiXdrQFLkGIl6HWOGej1S7iJKsbr1pwx9YPdHflx
+Ec47DPXj5IkK
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.1_ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.1_ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 38 (0x26)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Validity
-            Not Before: Apr 11 22:37:51 2011 GMT
-            Not After : Jan  5 22:37:51 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b8:6a:e3:b5:bf:65:66:f4:b3:32:73:a9:64:b7:
-                    dd:a0:4a:e9:70:d3:7b:5c:1b:5b:76:e7:56:a3:72:
-                    0e:9d:fa:9f:b2:a5:47:eb:3f:db:9a:7b:45:d2:17:
-                    77:ca:05:b3:95:22:15:78:9e:ab:f3:4b:fa:83:89:
-                    e6:19:54:22:69:18:67:ba:bb:37:2a:b4:93:5a:bb:
-                    9c:68:5b:ec:b1:7e:ac:01:7b:b3:d9:91:57:93:eb:
-                    43:e6:a6:35:e1:b5:c2:2d:ca:bb:63:af:35:d6:b4:
-                    16:9a:a3:7a:1c:ad:e1:f4:fb:63:4a:fd:3d:57:99:
-                    33:b8:1e:41:e9:f9:42:80:33
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ba:40:be:7e:1b:2f:92:11:cc:dc:44:14:76:87:
+                    8a:6a:94:b6:28:4e:87:5b:bc:57:46:75:63:38:4d:
+                    90:3e:7a:46:0e:87:e9:a9:04:1a:7d:e5:20:dc:81:
+                    9a:79:7e:1b:ab:ce:50:ce:47:54:04:98:16:d5:a6:
+                    6d:16:3c:52:ef:ed:43:c5:9b:d3:c8:48:cb:47:5d:
+                    08:1d:d1:44:fd:7c:c7:54:41:11:3b:3e:ae:bb:7f:
+                    94:a6:13:8f:89:6c:24:b3:a8:5e:e2:5d:20:40:85:
+                    2b:a0:ac:ed:a3:a8:b2:15:59:fc:ad:e8:5d:72:ee:
+                    64:eb:9c:30:8c:0a:97:32:f9
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                C9:2D:8D:6C:97:26:48:F8:6F:14:66:05:ED:06:D8:BF:21:8A:6F:FD
+                D1:74:80:71:CE:2E:24:57:71:C0:CA:50:42:8B:B3:99:0C:C7:6B:AD
             X509v3 Authority Key Identifier: 
-                keyid:3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
-                serial:BA:06:FD:EC:89:18:B5:7F
+                keyid:84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
+                serial:E8:F7:8D:38:FA:4B:55:DD
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign
     Signature Algorithm: sha256WithRSAEncryption
-        8e:ea:a2:87:02:69:a4:9f:44:22:c3:62:83:9c:fb:e2:3f:59:
-        d0:09:0f:57:81:8f:59:37:21:c5:59:81:36:8d:9c:4e:c0:0f:
-        4b:40:e6:db:ba:9f:d4:b8:86:2f:1b:1b:fd:2d:5d:4e:df:1b:
-        d4:b4:04:d0:07:b8:ad:25:52:1c:0b:ec:07:6c:21:b7:1d:65:
-        d3:a2:dc:a0:96:03:9d:2e:13:7a:a7:8a:29:55:95:5a:dc:ff:
-        6a:a4:4b:7a:26:7f:eb:ad:88:e9:80:5d:53:5e:0f:48:6a:21:
-        18:c9:89:be:83:38:51:40:b6:ad:5d:71:b2:2e:45:60:b3:1d:
-        69:9b
+         25:f7:af:7c:b8:de:50:02:c2:31:ed:50:89:5e:85:bc:e5:f4:
+         a0:03:7e:35:85:d5:2c:4c:bb:62:39:45:e9:50:9b:db:7a:4b:
+         91:e1:dd:e7:dc:b6:da:36:69:d7:2d:68:5c:96:a9:7b:e8:33:
+         17:4c:28:75:c2:6c:53:a8:11:8f:8f:23:89:59:25:8b:26:75:
+         4c:ee:9a:13:eb:78:28:52:dc:b2:fd:96:04:73:a8:78:9e:24:
+         b2:b2:85:88:84:10:ec:83:42:65:22:f1:b5:15:76:14:db:5c:
+         28:43:a4:62:df:27:4a:c5:4b:00:d5:44:83:24:37:f5:c5:4d:
+         b0:4a
 -----BEGIN CERTIFICATE-----
-MIIDMzCCApygAwIBAgIBJjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGE0MRIwEAYJKoZIhvcNAQkBFgN0YTQwHhcNMTEw
-NDExMjIzNzUxWhcNMTQwMTA1MjIzNzUxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjFfdGE0MRgwFgYJKoZIhvcNAQkBFgljaDEuMV90YTQw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALhq47W/ZWb0szJzqWS33aBK6XDT
-e1wbW3bnVqNyDp36n7KlR+s/25p7RdIXd8oFs5UiFXieq/NL+oOJ5hlUImkYZ7q7
-Nyq0k1q7nGhb7LF+rAF7s9mRV5PrQ+amNeG1wi3Ku2OvNda0Fpqjehyt4fT7Y0r9
-PVeZM7geQen5QoAzAgMBAAGjgeAwgd0wHQYDVR0OBBYEFMktjWyXJkj4bxRmBe0G
-2L8him/9MIGaBgNVHSMEgZIwgY+AFD5fZOljy5wQ0JH0RWHy8epCaeyloWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGE0MRIwEAYJKoZIhvcN
-AQkBFgN0YTSCCQC6Bv3siRi1fzAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
-AwICBDANBgkqhkiG9w0BAQsFAAOBgQCO6qKHAmmkn0Qiw2KDnPviP1nQCQ9XgY9Z
-NyHFWYE2jZxOwA9LQObbup/UuIYvGxv9LV1O3xvUtATQB7itJVIcC+wHbCG3HWXT
-otyglgOdLhN6p4opVZVa3P9qpEt6Jn/rrYjpgF1TXg9IaiEYyYm+gzhRQLatXXGy
-LkVgsx1pmw==
+MIIDNjCCAp+gAwIBAgIBJjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhNDESMBAGCSqGSIb3DQEJARYDdGE0MB4XDTEz
+MTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuMV90YTQxGDAWBgkqhkiG9w0BCQEWCWNoMS4xX3Rh
+NDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAukC+fhsvkhHM3EQUdoeKapS2
+KE6HW7xXRnVjOE2QPnpGDofpqQQafeUg3IGaeX4bq85QzkdUBJgW1aZtFjxS7+1D
+xZvTyEjLR10IHdFE/XzHVEEROz6uu3+UphOPiWwks6he4l0gQIUroKzto6iyFVn8
+rehdcu5k65wwjAqXMvkCAwEAAaOB4TCB3jAdBgNVHQ4EFgQU0XSAcc4uJFdxwMpQ
+QouzmQzHa60wgZsGA1UdIwSBkzCBkIAUhEYpiHQx76bMPONYKd6+/Rv0WZihbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGE0MRIwEAYJKoZI
+hvcNAQkBFgN0YTSCCQDo9404+ktV3TAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB
+/wQEAwICBDANBgkqhkiG9w0BAQsFAAOBgQAl9698uN5QAsIx7VCJXoW85fSgA341
+hdUsTLtiOUXpUJvbekuR4d3n3LbaNmnXLWhclql76DMXTCh1wmxTqBGPjyOJWSWL
+JnVM7poT63goUtyy/ZYEc6h4niSysoWIhBDsg0JlIvG1FXYU21woQ6Ri3ydKxUsA
+1USDJDf1xU2wSg==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.2_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.2_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 28 (0x1c)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
             Not Before: Jan  1 01:01:01 2009 GMT
             Not After : Jan  2 01:01:01 2009 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c7:97:bd:7a:78:72:f6:bb:6f:5b:ca:07:34:d8:
-                    70:93:94:39:d6:9c:73:b2:58:c6:fa:10:eb:8e:c7:
-                    54:39:fd:9a:35:f5:2c:a4:ae:e6:ca:a2:9c:07:0c:
-                    57:05:78:cc:8b:98:2e:39:e8:74:73:28:bf:f7:bf:
-                    d1:fb:5d:10:9d:f0:19:75:9d:35:fe:50:97:76:70:
-                    6d:00:79:66:1a:2f:af:c6:12:45:16:45:ea:3e:f0:
-                    90:3b:56:9d:ed:f7:70:ba:de:f7:ec:55:2b:ee:b1:
-                    9b:fb:1d:55:46:65:86:c3:1b:9e:50:b9:8c:b9:d3:
-                    02:73:aa:e6:1e:4d:11:2b:bf
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:db:7e:41:d8:93:1f:35:e5:6b:38:25:93:e5:99:
+                    cf:fe:c7:b8:ab:0b:14:47:23:66:52:c7:d4:18:58:
+                    ff:39:a6:c4:a3:44:2e:46:be:24:7b:9d:71:26:12:
+                    6a:99:bd:92:01:5a:dc:a9:36:3c:2d:f8:42:b8:5f:
+                    db:87:8f:09:9a:83:32:5c:b6:1d:c5:e4:aa:47:6d:
+                    46:11:16:72:44:d7:49:ea:d3:4a:a4:52:9a:f4:8a:
+                    b5:e4:ef:32:7b:71:a0:d7:8e:71:86:22:34:44:4a:
+                    95:5a:37:ef:c4:7f:57:1f:99:32:39:ef:ab:94:05:
+                    1b:9a:88:de:39:85:56:4c:f7
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                5A:E6:5A:C4:85:7D:C2:25:75:F9:C2:6A:93:15:18:69:7F:57:47:7C
+                91:8B:82:B9:57:2C:1B:DB:4B:F6:16:04:D7:3F:04:10:DD:8B:3B:05
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        23:82:0a:78:02:e9:9f:de:a1:62:2d:47:42:8d:f8:88:26:cf:
-        3b:31:64:91:56:e1:50:eb:46:12:61:6b:e4:bd:97:43:f5:f7:
-        33:b4:92:34:62:31:8b:df:7c:13:44:ed:04:24:73:4a:35:17:
-        98:15:ad:75:3f:33:bf:86:84:e2:29:34:7e:de:90:a1:99:f5:
-        8a:37:85:98:7d:8e:71:64:6a:1d:aa:47:57:9d:ad:e3:07:90:
-        0a:06:7c:08:e2:97:25:20:38:c9:41:62:d5:96:fb:fe:0e:b4:
-        1c:e1:20:75:7d:6a:f3:62:1d:cc:72:90:a6:13:58:48:af:e4:
-        c9:b1
+         8a:bc:bf:7b:28:d4:bd:a2:a9:91:e8:24:cf:1e:1b:05:7c:32:
+         68:71:40:9a:ef:48:3c:58:43:6c:ae:90:7a:50:a3:49:86:12:
+         57:21:00:0c:49:28:ec:31:fb:04:58:a4:24:c6:7e:14:9d:5a:
+         96:bd:ba:cd:c1:31:cd:c8:f0:77:de:3f:81:0a:d0:31:65:f2:
+         d5:11:c9:6f:cc:5a:f8:f3:c1:8f:31:37:75:3a:c6:6d:6d:6e:
+         d7:16:0a:9b:b0:ce:07:d7:97:36:61:37:5e:4a:16:df:8d:97:
+         f4:71:fe:9b:32:4b:b6:d2:27:f4:9a:7c:b8:83:b3:92:48:2c:
+         ec:0c
 -----BEGIN CERTIFICATE-----
-MIIDMzCCApygAwIBAgIBHDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMDkw
-MTAxMDEwMTAxWhcNMDkwMTAyMDEwMTAxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjJfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuMl90YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMeXvXp4cva7b1vKBzTYcJOUOdac
-c7JYxvoQ647HVDn9mjX1LKSu5sqinAcMVwV4zIuYLjnodHMov/e/0ftdEJ3wGXWd
-Nf5Ql3ZwbQB5Zhovr8YSRRZF6j7wkDtWne33cLre9+xVK+6xm/sdVUZlhsMbnlC5
-jLnTAnOq5h5NESu/AgMBAAGjgeAwgd0wHQYDVR0OBBYEFFrmWsSFfcIldfnCapMV
-GGl/V0d8MIGaBgNVHSMEgZIwgY+AFHr2UXp/m6s3PU6TA5BtaoQJfDrdoWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcN
-AQkBFgN0YTOCCQD0WFRqgyJm6TAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
-AwIBBjANBgkqhkiG9w0BAQsFAAOBgQAjggp4Aumf3qFiLUdCjfiIJs87MWSRVuFQ
-60YSYWvkvZdD9fcztJI0YjGL33wTRO0EJHNKNReYFa11PzO/hoTiKTR+3pChmfWK
-N4WYfY5xZGodqkdXna3jB5AKBnwI4pclIDjJQWLVlvv+DrQc4SB1fWrzYh3McpCm
-E1hIr+TJsQ==
+MIIDNjCCAp+gAwIBAgIBHDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTA5
+MDEwMTAxMDEwMVoXDTA5MDEwMjAxMDEwMVowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuMl90YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS4yX3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA235B2JMfNeVrOCWT5ZnP/se4
+qwsURyNmUsfUGFj/OabEo0QuRr4ke51xJhJqmb2SAVrcqTY8LfhCuF/bh48JmoMy
+XLYdxeSqR21GERZyRNdJ6tNKpFKa9Iq15O8ye3Gg145xhiI0REqVWjfvxH9XH5ky
+Oe+rlAUbmojeOYVWTPcCAwEAAaOB4TCB3jAdBgNVHQ4EFgQUkYuCuVcsG9tL9hYE
+1z8EEN2LOwUwgZsGA1UdIwSBkzCBkIAUtNQ2n/jLol9Qidoh4yfEkfeEiEWhbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZI
+hvcNAQkBFgN0YTOCCQDAxLR9iNbjPjAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB
+/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQCKvL97KNS9oqmR6CTPHhsFfDJocUCa
+70g8WENsrpB6UKNJhhJXIQAMSSjsMfsEWKQkxn4UnVqWvbrNwTHNyPB33j+BCtAx
+ZfLVEclvzFr488GPMTd1OsZtbW7XFgqbsM4H15c2YTdeShbfjZf0cf6bMku20if0
+mny4g7OSSCzsDA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.3_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.3_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 30 (0x1e)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
             Not Before: Jan  1 01:01:01 2035 GMT
             Not After : Jan  2 01:01:01 2035 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d9:34:eb:28:22:6a:51:f8:11:2c:ee:1f:6d:c9:
-                    f1:12:5a:04:33:dd:d6:27:ca:9a:40:ae:df:5c:78:
-                    53:28:c8:37:d2:47:14:e1:fc:22:ea:90:d9:19:05:
-                    08:fd:b7:99:20:97:28:23:fd:3d:62:87:0d:29:a0:
-                    de:95:61:33:6c:d6:e0:65:db:c1:8b:8c:70:c3:ce:
-                    66:e9:93:ee:92:9f:87:2c:d4:6f:1d:e1:92:cb:8a:
-                    38:a4:95:0a:6a:a2:94:c6:41:25:17:ce:a6:01:fb:
-                    cf:03:52:40:93:34:37:b5:74:48:15:d4:e7:64:82:
-                    46:ee:b3:bd:b5:1f:3b:42:81
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ce:58:8a:05:67:47:a9:62:99:37:13:35:4c:74:
+                    75:9b:2f:d7:4c:23:7a:cd:60:35:0c:95:4b:58:b3:
+                    dd:c8:2d:69:ad:3c:8d:d3:27:0d:02:06:d0:4b:6c:
+                    6e:57:e9:1f:3c:dc:f3:88:22:25:86:35:13:91:3c:
+                    9f:76:67:a4:ae:98:63:d2:73:4d:2f:07:d5:7f:80:
+                    7e:27:92:25:16:aa:32:fe:7a:17:65:d5:9f:ee:39:
+                    9f:c8:a1:57:6a:9b:2d:e3:61:d9:35:d5:94:fb:fa:
+                    95:21:c3:31:33:50:d6:2f:e5:c0:7a:bb:a7:61:a4:
+                    e0:9b:5e:ca:99:2a:5d:6a:db
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                E0:C8:F3:4A:A9:FE:FA:63:97:C7:CE:EE:A8:27:45:F4:C5:11:8F:A6
+                28:44:43:26:57:0F:45:87:1A:A5:36:FB:0F:49:91:4B:A1:38:F3:ED
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        8d:45:1b:e3:e0:58:10:d4:92:66:aa:50:1a:ee:7a:d9:99:82:
-        7b:6e:3b:9b:88:9e:7c:a2:35:34:bb:77:9d:1f:79:d2:5d:aa:
-        b6:91:f8:07:ff:dc:63:81:d5:f3:e2:47:27:cc:79:2a:33:c8:
-        77:d5:9b:9a:f0:2e:58:64:d3:cb:fb:e4:f9:55:bb:89:9c:36:
-        8f:dd:84:95:a9:8c:8c:d3:6b:81:f8:64:b1:8a:15:20:59:10:
-        e3:5c:b3:05:c6:cd:d1:cb:03:3c:39:84:1c:93:f3:67:5c:10:
-        09:e9:99:1a:a0:45:21:ea:16:31:a1:3d:74:4d:27:75:f9:3d:
-        aa:df
+         b8:a1:7b:ba:b7:10:91:c0:21:86:fe:4d:01:f7:14:34:d9:aa:
+         dc:f3:04:56:c2:08:e6:66:f5:77:55:7e:dd:ea:b5:49:ff:d9:
+         32:39:2c:c9:9f:2f:9c:b3:cc:68:25:3e:d4:92:ef:be:b7:a1:
+         a5:d6:8c:31:3d:3a:7f:f4:5d:e8:ca:a3:30:29:ff:89:82:63:
+         cb:46:47:34:e8:ce:25:dd:a4:09:61:0b:08:7b:fd:24:1b:2b:
+         2d:9b:b9:84:ba:9e:fe:c1:2a:bd:df:e5:86:08:9c:74:ca:51:
+         c8:2e:b8:24:13:49:8c:a4:3e:c1:48:44:bd:30:18:40:88:43:
+         c1:a6
 -----BEGIN CERTIFICATE-----
-MIIDMzCCApygAwIBAgIBHjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMzUw
-MTAxMDEwMTAxWhcNMzUwMTAyMDEwMTAxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjNfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuM190YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANk06ygialH4ESzuH23J8RJaBDPd
-1ifKmkCu31x4UyjIN9JHFOH8IuqQ2RkFCP23mSCXKCP9PWKHDSmg3pVhM2zW4GXb
-wYuMcMPOZumT7pKfhyzUbx3hksuKOKSVCmqilMZBJRfOpgH7zwNSQJM0N7V0SBXU
-52SCRu6zvbUfO0KBAgMBAAGjgeAwgd0wHQYDVR0OBBYEFODI80qp/vpjl8fO7qgn
-RfTFEY+mMIGaBgNVHSMEgZIwgY+AFHr2UXp/m6s3PU6TA5BtaoQJfDrdoWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcN
-AQkBFgN0YTOCCQD0WFRqgyJm6TAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
-AwIBBjANBgkqhkiG9w0BAQsFAAOBgQCNRRvj4FgQ1JJmqlAa7nrZmYJ7bjubiJ58
-ojU0u3edH3nSXaq2kfgH/9xjgdXz4kcnzHkqM8h31Zua8C5YZNPL++T5VbuJnDaP
-3YSVqYyM02uB+GSxihUgWRDjXLMFxs3RywM8OYQck/NnXBAJ6ZkaoEUh6hYxoT10
-TSd1+T2q3w==
+MIIDNjCCAp+gAwIBAgIBHjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTM1
+MDEwMTAxMDEwMVoXDTM1MDEwMjAxMDEwMVowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuM190YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS4zX3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAzliKBWdHqWKZNxM1THR1my/X
+TCN6zWA1DJVLWLPdyC1prTyN0ycNAgbQS2xuV+kfPNzziCIlhjUTkTyfdmekrphj
+0nNNLwfVf4B+J5IlFqoy/noXZdWf7jmfyKFXapst42HZNdWU+/qVIcMxM1DWL+XA
+erunYaTgm17KmSpdatsCAwEAAaOB4TCB3jAdBgNVHQ4EFgQUKERDJlcPRYcapTb7
+D0mRS6E48+0wgZsGA1UdIwSBkzCBkIAUtNQ2n/jLol9Qidoh4yfEkfeEiEWhbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZI
+hvcNAQkBFgN0YTOCCQDAxLR9iNbjPjAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB
+/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQC4oXu6txCRwCGG/k0B9xQ02arc8wRW
+wgjmZvV3VX7d6rVJ/9kyOSzJny+cs8xoJT7Uku++t6Gl1owxPTp/9F3oyqMwKf+J
+gmPLRkc06M4l3aQJYQsIe/0kGystm7mEup7+wSq93+WGCJx0ylHILrgkE0mMpD7B
+SES9MBhAiEPBpg==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.4_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1.4_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,61 +2,61 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 32 (0x20)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
             Not Before: Jan  1 01:01:01 2035 GMT
             Not After : Jan  2 01:01:01 2035 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cc:54:a0:55:75:b1:69:33:96:b6:97:29:82:06:
-                    06:46:f2:43:2f:19:57:bf:92:f0:4e:b5:01:65:d3:
-                    dc:e3:cf:5e:a9:f5:99:8e:91:e9:ad:88:15:8b:25:
-                    5e:92:c6:fd:d6:9e:e5:27:56:59:4a:09:e0:84:b8:
-                    86:af:bb:9d:e9:d2:99:f9:84:48:d6:b6:35:e8:aa:
-                    e0:b3:ac:94:09:7f:b8:67:53:75:26:65:16:b7:cf:
-                    92:52:be:5f:07:da:dd:f8:b1:1c:7c:54:37:7f:66:
-                    f7:dc:97:cd:d2:0d:fa:58:a4:2e:96:b8:83:fe:e2:
-                    3d:b6:fb:c5:08:46:ba:1b:47
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:e9:3c:28:6e:b8:7a:e3:7a:f2:ee:5e:69:7a:71:
+                    b8:bb:97:d5:d3:c4:77:3e:90:f3:29:69:b8:51:ba:
+                    8b:27:4d:3f:b2:10:76:86:6e:38:4a:49:be:ce:01:
+                    c5:d2:0e:6e:0e:a9:51:e9:94:57:ce:67:4b:99:ca:
+                    84:93:a9:f9:e6:35:1c:0f:d6:3d:b1:c1:c7:00:d7:
+                    fa:2c:05:a0:20:0d:86:6d:32:c0:54:0f:e8:b9:6e:
+                    b5:dd:1a:00:4c:89:bf:d4:6d:79:0e:e7:4e:10:d2:
+                    fb:75:2c:03:da:75:c8:e1:b7:dc:2e:42:c5:9b:ec:
+                    b2:f1:15:6d:db:56:f9:20:a3
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                F8:0C:60:C6:C6:4D:79:11:F2:CD:D2:91:28:DF:F6:26:6C:BB:B0:ED
+                33:65:69:5E:6D:D8:12:02:E9:68:A2:6C:7D:77:F1:38:D8:7B:97:E6
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        c8:ba:31:b9:ed:17:ae:ac:ca:cd:4d:48:f6:b6:66:1c:17:c5:
-        8a:18:96:e8:9b:47:de:b3:7e:23:21:78:cc:f9:63:09:4e:56:
-        64:a1:de:33:16:8b:6a:94:c1:68:0a:72:dd:8e:b6:8c:dd:61:
-        cf:05:07:12:e3:4f:41:52:bc:73:33:a5:3e:94:ca:40:53:74:
-        a7:9c:46:f2:73:5b:b7:7f:df:18:7f:60:2f:2d:4b:41:8c:78:
-        c4:5f:4c:a8:85:a4:2c:84:91:b3:ab:60:61:ca:93:67:1b:2a:
-        0e:9a:e1:e8:a5:dc:5e:78:18:a3:b3:4b:86:4d:03:08:78:9b:
-        70:bc
+         5c:06:87:8e:6c:26:b3:5d:7c:94:c0:e3:7d:9e:8c:7c:bf:86:
+         e0:07:8a:65:95:af:8f:93:0c:a6:72:e5:cb:36:a5:69:03:95:
+         03:7f:e0:18:c8:f2:da:ce:99:b8:54:7a:49:75:f2:61:00:d4:
+         f4:63:e1:5c:cc:f0:91:e7:85:92:0d:7e:91:4b:3a:8b:76:e6:
+         a0:c8:51:28:06:44:d2:c8:a8:4c:da:be:7e:78:88:45:d3:f7:
+         07:92:90:fc:96:4d:7d:ce:5a:c9:9a:21:d9:66:98:3e:9b:5d:
+         18:9a:0c:b8:c4:10:86:4d:06:15:d9:ea:19:9b:e7:f7:e2:74:
+         25:eb
 -----BEGIN CERTIFICATE-----
-MIIDIzCCAoygAwIBAgIBIDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMzUw
-MTAxMDEwMTAxWhcNMzUwMTAyMDEwMTAxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTESMBAGA1UEAxQJY2gxLjRfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEuNF90YTMw
-gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMxUoFV1sWkzlraXKYIGBkbyQy8Z
-V7+S8E61AWXT3OPPXqn1mY6R6a2IFYslXpLG/dae5SdWWUoJ4IS4hq+7nenSmfmE
-SNa2Neiq4LOslAl/uGdTdSZlFrfPklK+Xwfa3fixHHxUN39m99yXzdIN+likLpa4
-g/7iPbb7xQhGuhtHAgMBAAGjgdAwgc0wHQYDVR0OBBYEFPgMYMbGTXkR8s3SkSjf
-9iZsu7DtMIGaBgNVHSMEgZIwgY+AFHr2UXp/m6s3PU6TA5BtaoQJfDrdoWykajBo
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcN
-AQkBFgN0YTOCCQD0WFRqgyJm6TAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEB
-CwUAA4GBAMi6MbntF66sys1NSPa2ZhwXxYoYluibR96zfiMheMz5YwlOVmSh3jMW
-i2qUwWgKct2OtozdYc8FBxLjT0FSvHMzpT6UykBTdKecRvJzW7d/3xh/YC8tS0GM
-eMRfTKiFpCyEkbOrYGHKk2cbKg6a4eil3F54GKOzS4ZNAwh4m3C8
+MIIDJjCCAo+gAwIBAgIBIDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTM1
+MDEwMTAxMDEwMVoXDTM1MDEwMjAxMDEwMVowdTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRIwEAYDVQQDDAljaDEuNF90YTMxGDAWBgkqhkiG9w0BCQEWCWNoMS40X3Rh
+MzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA6Twobrh643ry7l5penG4u5fV
+08R3PpDzKWm4UbqLJ00/shB2hm44Skm+zgHF0g5uDqlR6ZRXzmdLmcqEk6n55jUc
+D9Y9scHHANf6LAWgIA2GbTLAVA/ouW613RoATIm/1G15DudOENL7dSwD2nXI4bfc
+LkLFm+yy8RVt21b5IKMCAwEAAaOB0TCBzjAdBgNVHQ4EFgQUM2VpXm3YEgLpaKJs
+fXfxONh7l+YwgZsGA1UdIwSBkzCBkIAUtNQ2n/jLol9Qidoh4yfEkfeEiEWhbaRr
+MGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtT
+YW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZI
+hvcNAQkBFgN0YTOCCQDAxLR9iNbjPjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3
+DQEBCwUAA4GBAFwGh45sJrNdfJTA432ejHy/huAHimWVr4+TDKZy5cs2pWkDlQN/
+4BjI8trOmbhUekl18mEA1PRj4VzM8JHnhZINfpFLOot25qDIUSgGRNLIqEzavn54
+iEXT9weSkPyWTX3OWsmaIdlmmD6bXRiaDLjEEIZNBhXZ6hmb5/fidCXr
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 1 (0x1)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta1/emailAddress=ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta1/emailAddress=ta1
         Validity
-            Not Before: Apr 11 22:37:38 2011 GMT
-            Not After : Jan  5 22:37:38 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b1:ac:f5:20:5c:bf:44:a0:a0:ff:0b:28:02:1b:
-                    9d:dd:1f:3c:6a:f7:16:c0:8e:ec:af:a1:a4:c4:cf:
-                    26:8e:43:ca:8a:aa:05:8f:a2:10:03:32:41:d0:6e:
-                    b4:52:45:47:a8:46:8b:c5:f3:cd:55:56:f5:d0:c3:
-                    ec:e4:a4:63:8b:9a:87:fa:74:78:ff:2c:f7:66:77:
-                    3f:05:c3:31:d0:46:5f:b6:17:af:b5:76:9f:d8:8d:
-                    22:d3:76:ac:ad:55:6f:4c:76:2a:27:8e:e9:22:74:
-                    42:ce:db:42:b9:00:54:01:fe:18:c6:4a:96:b5:b9:
-                    88:32:6d:c5:d9:56:fc:87:95
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:da:3a:b2:74:16:5c:38:7c:93:3a:48:cb:9f:71:
+                    7c:aa:b9:ff:d7:25:5f:cd:90:6c:e6:87:6d:ed:34:
+                    0f:12:19:00:a8:36:fe:51:4b:b2:38:76:55:2a:d1:
+                    ce:3b:a3:78:75:db:c8:ba:85:8b:ad:80:0e:84:ab:
+                    1f:4b:80:90:20:56:49:7b:71:a0:16:f8:15:8a:cd:
+                    70:ee:45:1f:53:34:3c:85:df:10:75:e2:b1:68:97:
+                    c5:0d:66:7f:bf:e7:b3:d1:09:03:1b:50:14:dc:e3:
+                    3e:a9:b6:6a:63:e6:0f:51:3e:06:59:50:43:da:10:
+                    99:0d:79:a3:b4:76:89:a2:01
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                C0:9E:26:BD:D6:FB:FB:BF:FA:CE:33:92:CA:4E:25:CF:EC:9E:BA:66
+                36:46:2D:8A:1B:8B:CE:C1:1D:02:37:B9:EC:A5:FF:BA:73:AE:E5:48
             X509v3 Authority Key Identifier: 
-                keyid:75:A9:2B:02:E8:FB:31:09:2A:F2:16:21:24:D8:B2:A5:D0:14:93:5B
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta1/emailAddress=ta1
-                serial:A1:49:EA:78:5A:F4:55:8D
+                keyid:81:54:6B:06:08:DD:44:4F:08:81:21:7A:7C:D5:96:EA:53:2B:E3:0A
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta1/emailAddress=ta1
+                serial:F6:A8:B6:5C:10:8D:04:4F
 
             X509v3 Basic Constraints: critical
                 CA:TRUE, pathlen:4
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        94:eb:ef:96:17:47:57:5e:c2:4f:4c:67:8b:bd:d7:14:22:1e:
-        d7:09:cc:b7:b2:f2:cf:df:51:e3:a6:ea:5a:7b:3a:5f:47:b1:
-        db:37:91:a3:ae:75:d2:d0:9e:9c:49:fc:ec:1f:2e:9b:b4:96:
-        43:60:c8:99:a7:a8:fb:93:c1:68:2e:c8:09:42:23:0c:8a:25:
-        08:67:e9:0e:6a:44:e9:18:08:d0:a0:ce:60:6c:d3:e8:c1:ec:
-        2d:f0:db:47:04:36:f3:27:86:69:c5:10:06:3b:93:65:ea:19:
-        e4:6d:cd:fb:8a:ee:21:58:de:f3:17:7a:ee:ce:80:06:cc:1f:
-        48:dd
+         38:4a:69:9d:14:fa:51:b9:35:9c:c8:ae:e5:c0:e2:2e:4c:d4:
+         57:ad:64:05:99:e4:94:b3:d3:97:e0:0e:bd:1c:b4:64:c8:2b:
+         07:18:26:7f:99:ef:9c:48:e6:23:b3:96:37:92:54:85:8b:29:
+         19:60:12:11:fc:d8:62:84:5c:75:73:76:9e:0f:f8:a7:95:79:
+         c8:3c:75:f7:13:73:1f:be:fa:60:79:5c:6c:12:8d:ca:f9:58:
+         4b:1f:ed:0a:52:4c:61:95:6f:9a:a7:57:0c:20:9a:19:73:dc:
+         3d:42:aa:47:29:ac:92:a9:cc:4a:eb:85:6d:ab:cd:ed:2b:9a:
+         e5:c1
 -----BEGIN CERTIFICATE-----
-MIIDMjCCApugAwIBAgIBATANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGExMRIwEAYJKoZIhvcNAQkBFgN0YTEwHhcNMTEw
-NDExMjIzNzM4WhcNMTQwMTA1MjIzNzM4WjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gxX3RhMTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAsaz1IFy/RKCg/wsoAhud3R88avcWwI7s
-r6GkxM8mjkPKiqoFj6IQAzJB0G60UkVHqEaLxfPNVVb10MPs5KRji5qH+nR4/yz3
-Znc/BcMx0EZfthevtXaf2I0i03asrVVvTHYqJ47pInRCzttCuQBUAf4YxkqWtbmI
-Mm3F2Vb8h5UCAwEAAaOB4zCB4DAdBgNVHQ4EFgQUwJ4mvdb7+7/6zjOSyk4lz+ye
-umYwgZoGA1UdIwSBkjCBj4AUdakrAuj7MQkq8hYhJNiypdAUk1uhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEW
-A3RhMYIJAKFJ6nha9FWNMBIGA1UdEwEB/wQIMAYBAf8CAQQwDgYDVR0PAQH/BAQD
-AgEGMA0GCSqGSIb3DQEBCwUAA4GBAJTr75YXR1dewk9MZ4u91xQiHtcJzLey8s/f
-UeOm6lp7Ol9Hsds3kaOuddLQnpxJ/OwfLpu0lkNgyJmnqPuTwWguyAlCIwyKJQhn
-6Q5qROkYCNCgzmBs0+jB7C3w20cENvMnhmnFEAY7k2XqGeRtzfuK7iFY3vMXeu7O
-gAbMH0jd
+MIIDNTCCAp6gAwIBAgIBATANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMTESMBAGCSqGSIb3DQEJARYDdGExMB4XDTEz
+MTIxMzAwMTMzNFoXDTE2MDkwODAwMTMzNFowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDFfdGExMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDaOrJ0Flw4fJM6SMufcXyquf/XJV/N
+kGzmh23tNA8SGQCoNv5RS7I4dlUq0c47o3h128i6hYutgA6Eqx9LgJAgVkl7caAW
++BWKzXDuRR9TNDyF3xB14rFol8UNZn+/57PRCQMbUBTc4z6ptmpj5g9RPgZZUEPa
+EJkNeaO0domiAQIDAQABo4HkMIHhMB0GA1UdDgQWBBQ2Ri2KG4vOwR0CN7nspf+6
+c67lSDCBmwYDVR0jBIGTMIGQgBSBVGsGCN1ETwiBIXp81ZbqUyvjCqFtpGswaTEL
+MAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRh
+IENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQDDAN0YTExEjAQBgkqhkiG9w0B
+CQEWA3RhMYIJAPaotlwQjQRPMBIGA1UdEwEB/wQIMAYBAf8CAQQwDgYDVR0PAQH/
+BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBADhKaZ0U+lG5NZzIruXA4i5M1FetZAWZ
+5JSz05fgDr0ctGTIKwcYJn+Z75xI5iOzljeSVIWLKRlgEhH82GKEXHVzdp4P+KeV
+ecg8dfcTcx+++mB5XGwSjcr5WEsf7QpSTGGVb5qnVwwgmhlz3D1CqkcprJKpzErr
+hW2rze0rmuXB
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 16 (0x10)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
-            Not Before: Apr 11 22:37:44 2011 GMT
-            Not After : Jan  5 22:37:44 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e1:a3:d0:51:dc:0b:73:6f:44:f2:c7:6b:f2:9d:
-                    da:56:de:d4:41:61:75:48:78:10:2c:53:f1:c1:28:
-                    01:4a:10:53:7d:32:bc:e2:01:a2:75:59:0b:cf:3a:
-                    fc:41:b8:2c:36:fb:fe:3d:d9:a2:41:7b:6e:3c:0a:
-                    a9:7e:74:5a:86:ea:06:6a:2b:ad:3c:7e:32:8b:97:
-                    a4:ba:53:c1:b8:bc:f0:8f:80:22:53:97:66:bb:80:
-                    15:05:96:dc:df:62:29:4d:15:df:85:e6:90:30:4d:
-                    29:d3:04:b7:4f:22:40:b8:a1:22:ed:0e:4b:e6:00:
-                    82:df:89:48:63:87:b5:80:55
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ba:0e:36:90:a0:6b:75:19:6b:30:76:54:9e:20:
+                    b0:81:70:21:47:97:9c:c1:15:7c:9e:2d:50:3c:db:
+                    dc:8c:d0:31:9c:b9:78:c6:2a:5c:53:ca:ed:d3:44:
+                    e2:f9:93:d8:b5:b6:a6:8a:c2:bd:be:4f:8b:f5:a0:
+                    28:68:cf:ec:f9:e3:e9:57:a8:ab:cd:a5:45:0d:82:
+                    eb:f0:5b:aa:2d:1b:88:65:30:9f:a1:74:59:1f:e5:
+                    d2:25:f9:d6:31:3f:0a:a2:4a:92:5d:2a:30:2e:3f:
+                    2f:72:48:93:f8:8d:7c:bf:79:21:e3:e1:91:9a:a7:
+                    03:01:ba:20:95:a6:da:56:35
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                D9:77:48:13:09:B0:17:15:2A:95:47:CA:4C:13:2E:A9:AC:18:5D:AD
+                A7:11:90:E6:5F:5F:79:74:A3:1D:B5:9E:0C:15:F1:16:C5:D4:FB:6B
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta3/emailAddress=ta3
+                serial:C0:C4:B4:7D:88:D6:E3:3E
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        a5:b4:3f:fe:d9:aa:36:19:da:97:ab:60:50:43:50:e0:26:2e:
-        23:af:39:d9:d6:60:0a:41:5d:6a:2f:6f:f2:4c:4f:a8:22:40:
-        04:40:84:4e:0a:34:10:21:a5:9a:36:f6:7c:aa:e3:29:88:ce:
-        8c:1f:4a:cd:db:19:db:25:0c:04:46:28:67:ba:74:ff:74:78:
-        4e:20:9b:ef:31:95:c9:ab:46:53:f3:02:bb:25:78:3e:43:6a:
-        87:d6:86:61:a6:3e:8a:91:91:a6:88:f2:32:2d:b2:51:22:46:
-        9a:b3:b6:c9:45:90:83:c2:0f:d7:a2:4a:1b:61:30:3f:55:3d:
-        47:1f
+         5f:db:a1:d4:03:bc:a0:f9:d7:80:88:ac:94:2b:22:cc:1c:88:
+         56:65:bd:0d:57:d6:d4:ae:5c:a2:27:44:7c:5e:4d:23:8c:ba:
+         fe:1c:a6:49:96:20:c2:f5:45:cf:52:0e:0a:80:40:5b:1c:e7:
+         83:2b:d4:72:6c:95:10:c6:a7:44:27:85:6b:e5:37:f5:a4:25:
+         70:e4:e0:0e:de:1d:c1:72:1f:05:be:0f:4b:23:61:38:e3:52:
+         cb:05:c3:f4:41:26:80:58:ea:02:c6:6b:7d:f8:9f:41:40:76:
+         94:44:59:2e:da:bc:a8:54:11:22:bc:58:ff:61:85:3c:60:e7:
+         67:e6
 -----BEGIN CERTIFICATE-----
-MIIDLzCCApigAwIBAgIBEDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEzMRIwEAYJKoZIhvcNAQkBFgN0YTMwHhcNMTEw
-NDExMjIzNzQ0WhcNMTQwMTA1MjIzNzQ0WjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3RhMzCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA4aPQUdwLc29E8sdr8p3aVt7UQWF1SHgQ
-LFPxwSgBShBTfTK84gGidVkLzzr8QbgsNvv+PdmiQXtuPAqpfnRahuoGaiutPH4y
-i5ekulPBuLzwj4AiU5dmu4AVBZbc32IpTRXfheaQME0p0wS3TyJAuKEi7Q5L5gCC
-34lIY4e1gFUCAwEAAaOB4DCB3TAdBgNVHQ4EFgQU2XdIEwmwFxUqlUfKTBMuqawY
-Xa0wgZoGA1UdIwSBkjCBj4AUevZRen+bqzc9TpMDkG1qhAl8Ot2hbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEW
-A3RhM4IJAPRYVGqDImbpMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEG
-MA0GCSqGSIb3DQEBCwUAA4GBAKW0P/7ZqjYZ2perYFBDUOAmLiOvOdnWYApBXWov
-b/JMT6giQARAhE4KNBAhpZo29nyq4ymIzowfSs3bGdslDARGKGe6dP90eE4gm+8x
-lcmrRlPzArsleD5DaofWhmGmPoqRkaaI8jItslEiRpqztslFkIPCD9eiShthMD9V
-PUcf
+MIIDMjCCApugAwIBAgIBEDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMB4XDTEz
+MTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGEzMRYwFAYJKoZIhvcNAQkBFgdjaDFfdGEzMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6DjaQoGt1GWswdlSeILCBcCFHl5zB
+FXyeLVA829yM0DGcuXjGKlxTyu3TROL5k9i1tqaKwr2+T4v1oChoz+z54+lXqKvN
+pUUNguvwW6otG4hlMJ+hdFkf5dIl+dYxPwqiSpJdKjAuPy9ySJP4jXy/eSHj4ZGa
+pwMBuiCVptpWNQIDAQABo4HhMIHeMB0GA1UdDgQWBBSnEZDmX195dKMdtZ4MFfEW
+xdT7azCBmwYDVR0jBIGTMIGQgBS01Daf+MuiX1CJ2iHjJ8SR94SIRaFtpGswaTEL
+MAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRh
+IENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQDDAN0YTMxEjAQBgkqhkiG9w0B
+CQEWA3RhM4IJAMDEtH2I1uM+MA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD
+AgEGMA0GCSqGSIb3DQEBCwUAA4GBAF/bodQDvKD514CIrJQrIswciFZlvQ1X1tSu
+XKInRHxeTSOMuv4cpkmWIML1Rc9SDgqAQFsc54Mr1HJslRDGp0QnhWvlN/WkJXDk
+4A7eHcFyHwW+D0sjYTjjUssFw/RBJoBY6gLGa334n0FAdpREWS7avKhUESK8WP9h
+hTxg52fm
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,64 +2,64 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 34 (0x22)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Validity
-            Not Before: Apr 11 22:37:49 2011 GMT
-            Not After : Jan  5 22:37:49 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b6:ab:16:bb:1d:ee:25:5a:2f:58:e7:db:d8:0a:
-                    e7:36:63:d5:ca:de:60:b5:90:c2:82:e3:ec:7d:49:
-                    0c:a9:b6:95:c8:a1:ab:04:0c:a9:09:e1:93:a6:be:
-                    43:36:7e:1b:61:28:1b:38:03:a2:06:19:88:72:a9:
-                    b9:a2:71:ff:db:e1:3c:85:98:01:b2:5f:93:a0:4a:
-                    b8:e7:36:ad:8f:50:8c:d6:a1:14:29:b0:ee:ec:e2:
-                    08:3f:7d:34:a1:c4:5f:3a:e9:4f:b0:c0:d6:5f:f2:
-                    10:78:2b:ae:f4:ee:28:c8:29:21:9f:ce:70:d5:fb:
-                    ea:33:fc:e2:5a:5c:e2:1b:d9
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b4:25:1c:3a:c2:26:af:8d:82:4d:29:e3:e0:78:
+                    6f:2b:7f:3c:b1:8c:c0:37:96:71:d2:42:21:df:2e:
+                    c4:c0:5a:60:e4:71:6f:05:df:88:a8:4b:ec:87:54:
+                    8d:08:c9:f7:19:84:a5:d0:cc:cb:43:c3:70:69:67:
+                    2e:4c:be:e6:2d:93:90:f9:02:30:a7:43:d2:1f:e5:
+                    d4:cf:5b:5c:74:88:06:0e:ee:cd:78:2c:2f:27:4c:
+                    99:2f:be:9a:73:5b:9b:1c:e3:67:54:b6:74:a7:c9:
+                    31:d3:63:6a:c5:4a:50:22:eb:af:e2:cd:7a:de:59:
+                    68:6a:a6:0e:26:d6:52:b6:a1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                2A:94:C1:FF:E0:11:A0:91:F1:71:46:35:9A:37:3C:BC:C4:21:4A:8F
+                29:7A:F9:B4:E3:1B:8F:19:63:52:FA:19:A0:AB:DA:37:E4:70:A9:71
             X509v3 Authority Key Identifier: 
-                keyid:3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
-                serial:BA:06:FD:EC:89:18:B5:7F
+                keyid:84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
+                serial:E8:F7:8D:38:FA:4B:55:DD
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        9d:2d:ff:a2:d2:42:31:72:9e:6f:8d:45:2c:21:9b:15:cf:89:
-        06:70:3b:5f:3e:2c:73:b9:08:d9:be:48:d8:6b:dc:23:86:3a:
-        ab:3c:16:80:13:62:a4:12:f8:ee:e7:6f:d6:e8:4f:ad:36:eb:
-        1e:81:c8:03:1c:65:ba:be:55:6d:07:8f:bc:fa:ba:d2:14:90:
-        1d:02:35:bd:5d:bd:0b:fb:48:57:94:6d:fe:71:85:ce:9f:65:
-        9c:31:80:13:56:b2:6f:2a:03:b6:1d:7f:5a:4a:dd:50:63:7a:
-        46:40:4b:1d:c3:71:5d:72:72:f0:50:f8:db:60:56:97:c8:cd:
-        73:83
+         91:d2:2e:6f:55:ce:c6:39:d8:b4:1f:7a:df:7f:bd:8f:4e:66:
+         ec:10:3d:35:f1:36:22:90:ae:b7:16:e4:48:f5:ec:63:27:e8:
+         88:32:78:ac:21:cc:71:f9:46:6a:73:b7:09:24:a7:44:68:41:
+         a5:07:f9:a3:ec:c7:53:ca:68:e4:09:68:b7:ee:11:f2:8c:08:
+         80:3c:a5:56:e2:f3:a8:aa:1e:34:99:49:26:8a:1f:50:36:d2:
+         0e:ee:b6:a0:a6:e6:b0:94:41:a6:bc:de:93:6f:af:b3:fa:f4:
+         a3:c3:46:83:f8:27:67:8e:9e:40:ec:79:08:0b:e2:46:73:61:
+         0d:c6
 -----BEGIN CERTIFICATE-----
-MIIDLzCCApigAwIBAgIBIjANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGE0MRIwEAYJKoZIhvcNAQkBFgN0YTQwHhcNMTEw
-NDExMjIzNzQ5WhcNMTQwMTA1MjIzNzQ5WjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3RhNDCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAtqsWux3uJVovWOfb2ArnNmPVyt5gtZDC
-guPsfUkMqbaVyKGrBAypCeGTpr5DNn4bYSgbOAOiBhmIcqm5onH/2+E8hZgBsl+T
-oEq45zatj1CM1qEUKbDu7OIIP300ocRfOulPsMDWX/IQeCuu9O4oyCkhn85w1fvq
-M/ziWlziG9kCAwEAAaOB4DCB3TAdBgNVHQ4EFgQUKpTB/+ARoJHxcUY1mjc8vMQh
-So8wgZoGA1UdIwSBkjCBj4AUPl9k6WPLnBDQkfRFYfLx6kJp7KWhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEW
-A3RhNIIJALoG/eyJGLV/MA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEG
-MA0GCSqGSIb3DQEBCwUAA4GBAJ0t/6LSQjFynm+NRSwhmxXPiQZwO18+LHO5CNm+
-SNhr3COGOqs8FoATYqQS+O7nb9boT6026x6ByAMcZbq+VW0Hj7z6utIUkB0CNb1d
-vQv7SFeUbf5xhc6fZZwxgBNWsm8qA7Ydf1pK3VBjekZASx3DcV1ycvBQ+NtgVpfI
-zXOD
+MIIDMjCCApugAwIBAgIBIjANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhNDESMBAGCSqGSIb3DQEJARYDdGE0MB4XDTEz
+MTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGE0MRYwFAYJKoZIhvcNAQkBFgdjaDFfdGE0MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC0JRw6wiavjYJNKePgeG8rfzyxjMA3
+lnHSQiHfLsTAWmDkcW8F34ioS+yHVI0IyfcZhKXQzMtDw3BpZy5MvuYtk5D5AjCn
+Q9If5dTPW1x0iAYO7s14LC8nTJkvvppzW5sc42dUtnSnyTHTY2rFSlAi66/izXre
+WWhqpg4m1lK2oQIDAQABo4HhMIHeMB0GA1UdDgQWBBQpevm04xuPGWNS+hmgq9o3
+5HCpcTCBmwYDVR0jBIGTMIGQgBSERimIdDHvpsw841gp3r79G/RZmKFtpGswaTEL
+MAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRh
+IENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQDDAN0YTQxEjAQBgkqhkiG9w0B
+CQEWA3RhNIIJAOj3jTj6S1XdMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD
+AgEGMA0GCSqGSIb3DQEBCwUAA4GBAJHSLm9VzsY52LQfet9/vY9OZuwQPTXxNiKQ
+rrcW5Ej17GMn6IgyeKwhzHH5Rmpztwkkp0RoQaUH+aPsx1PKaOQJaLfuEfKMCIA8
+pVbi86iqHjSZSSaKH1A20g7utqCm5rCUQaa83pNvr7P69KPDRoP4J2eOnkDseQgL
+4kZzYQ3G
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta5_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch1_ta5_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,68 +2,70 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 40 (0x28)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta5/emailAddress=ta5
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta5/emailAddress=ta5
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e7:14:d9:dc:4c:60:0f:ad:49:9f:14:f8:2f:d9:
-                    0e:65:93:a4:c4:e5:6b:13:93:c1:79:40:14:4f:19:
-                    56:d7:88:07:9b:de:45:40:ce:24:91:44:b0:14:6b:
-                    8b:4d:f5:d1:b2:75:cc:5c:d7:ed:73:2c:d2:75:aa:
-                    50:6f:94:00:8d:0e:bb:15:8c:ef:a1:5d:2c:23:73:
-                    95:f7:48:b5:4a:3b:de:2a:a1:7c:03:aa:28:17:f0:
-                    a7:46:b9:86:f3:98:a7:31:ff:e1:75:b4:28:b4:11:
-                    b4:4b:ca:64:e4:cd:2a:f7:d8:6f:6b:73:64:ab:55:
-                    0b:5b:60:76:5f:ea:86:57:1f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c6:67:76:93:23:82:9f:2f:70:27:4f:64:9e:c3:
+                    80:4d:e3:9d:bb:f9:ea:2e:f1:02:e1:e1:a8:5b:f6:
+                    dc:c9:7b:ef:be:5a:41:11:bd:c4:51:e1:d8:74:6a:
+                    16:89:83:f7:3a:fd:0b:cc:9b:e6:96:d8:13:e3:ef:
+                    78:65:97:ff:81:90:97:e8:77:fd:ed:9c:56:2e:c7:
+                    a4:ec:f7:2c:fc:a0:f6:de:ab:ec:d6:e7:9e:35:e6:
+                    b7:dc:65:1b:c8:e4:5a:a2:9d:d8:5b:b9:fa:26:8c:
+                    8d:00:66:c4:05:28:9c:a8:3c:b1:81:c7:75:0a:51:
+                    ed:4f:49:d7:96:b5:8b:34:f9
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                59:7D:00:A7:48:7C:5E:D9:A2:26:D0:9A:83:3F:D0:03:9C:36:D5:50
+                8E:29:B3:96:C1:67:FE:34:F3:55:99:68:C4:DA:2A:C0:24:8A:19:C6
             X509v3 Authority Key Identifier: 
-                keyid:E7:E6:72:5B:A0:5F:2C:A6:40:45:1A:66:E4:45:A5:0F:1D:67:5D:93
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta5/emailAddress=ta5
-                serial:9C:19:39:11:06:1A:55:91
+                keyid:29:DA:B1:46:E3:61:51:AC:3C:3E:F6:78:5B:95:7B:6D:B2:F9:17:21
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta5/emailAddress=ta5
+                serial:A7:8F:F0:5E:6B:64:C2:46
 
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ta5_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ta5_crl.pem
 
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        a0:48:28:f4:94:07:dd:08:f2:c6:74:0d:a9:31:10:71:64:f8:
-        b5:c3:fb:82:8e:46:9d:30:fb:fd:9d:4b:c9:92:5b:c4:06:d2:
-        d0:5e:aa:91:f5:19:7c:c3:11:b2:26:ef:e6:01:cf:3e:ea:07:
-        d6:d2:f8:22:e6:a0:50:86:40:53:cc:ed:81:73:33:b1:a8:2b:
-        92:1a:10:f9:fc:30:43:84:4b:ca:ef:8c:d3:be:0a:63:f0:40:
-        99:be:80:88:c9:8f:2b:9a:82:9f:7b:56:9a:f1:08:e1:67:88:
-        30:fa:a1:12:bc:c8:ea:22:60:64:0f:91:80:48:cd:2a:5d:05:
-        ca:f7
+         9d:32:27:d7:4e:4e:8b:e4:9f:d0:0d:11:f3:e5:be:5f:7f:7e:
+         cf:ef:98:41:33:ba:04:ba:d9:7a:11:88:b8:13:66:74:44:1c:
+         fb:1e:f3:fa:d4:18:85:cd:ed:f0:f8:c2:be:ab:75:cf:65:da:
+         1a:77:01:0e:aa:49:ea:af:a7:db:39:84:f2:01:1d:28:e7:df:
+         22:a9:59:5a:21:f9:f9:30:84:64:52:50:01:9b:b2:bf:ca:8a:
+         b4:8b:36:96:e3:1a:ea:51:53:36:82:ba:88:8f:15:8c:e6:79:
+         59:aa:71:9b:4c:58:a2:68:f0:43:36:15:af:69:af:32:ed:49:
+         c8:9c
 -----BEGIN CERTIFICATE-----
-MIIDbTCCAtagAwIBAgIBKDANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGE1MRIwEAYJKoZIhvcNAQkBFgN0YTUwHhcNMTEw
-NDExMjIzNzUyWhcNMTQwMTA1MjIzNzUyWjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY2gxX3RhNTEWMBQGCSqGSIb3DQEJARYHY2gxX3RhNTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA5xTZ3ExgD61JnxT4L9kOZZOkxOVrE5PB
-eUAUTxlW14gHm95FQM4kkUSwFGuLTfXRsnXMXNftcyzSdapQb5QAjQ67FYzvoV0s
-I3OV90i1SjveKqF8A6ooF/CnRrmG85inMf/hdbQotBG0S8pk5M0q99hva3Nkq1UL
-W2B2X+qGVx8CAwEAAaOCAR0wggEZMB0GA1UdDgQWBBRZfQCnSHxe2aIm0JqDP9AD
-nDbVUDCBmgYDVR0jBIGSMIGPgBTn5nJboF8spkBFGmbkRaUPHWddk6FspGowaDEL
-MAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxv
-IFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAMTA3RhNTESMBAGCSqGSIb3DQEJ
-ARYDdGE1ggkAnBk5EQYaVZEwDwYDVR0TAQH/BAUwAwEB/zA6BgNVHR8EMzAxMC+g
-LaArhilodHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUvMC90YTVfY3JsLnBlbTAO
-BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAoEgo9JQH3QjyxnQNqTEQ
-cWT4tcP7go5GnTD7/Z1LyZJbxAbS0F6qkfUZfMMRsibv5gHPPuoH1tL4IuagUIZA
-U8ztgXMzsagrkhoQ+fwwQ4RLyu+M074KY/BAmb6AiMmPK5qCn3tWmvEI4WeIMPqh
-ErzI6iJgZA+RgEjNKl0Fyvc=
+MIIDcDCCAtmgAwIBAgIBKDANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhNTESMBAGCSqGSIb3DQEJARYDdGE1MB4XDTEz
+MTIxMzAwMTMzOFoXDTE2MDkwODAwMTMzOFowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjaDFfdGE1MRYwFAYJKoZIhvcNAQkBFgdjaDFfdGE1MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGZ3aTI4KfL3AnT2Sew4BN4527+eou
+8QLh4ahb9tzJe+++WkERvcRR4dh0ahaJg/c6/QvMm+aW2BPj73hll/+BkJfod/3t
+nFYux6Ts9yz8oPbeq+zW55415rfcZRvI5FqindhbufomjI0AZsQFKJyoPLGBx3UK
+Ue1PSdeWtYs0+QIDAQABo4IBHjCCARowHQYDVR0OBBYEFI4ps5bBZ/4081WZaMTa
+KsAkihnGMIGbBgNVHSMEgZMwgZCAFCnasUbjYVGsPD72eFuVe22y+RchoW2kazBp
+MQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2Fu
+dGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhNTESMBAGCSqGSIb3
+DQEJARYDdGE1ggkAp4/wXmtkwkYwDwYDVR0TAQH/BAUwAwEB/zA6BgNVHR8EMzAx
+MC+gLaArhilodHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUvMC90YTVfY3JsLnBl
+bTAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAnTIn105Oi+Sf0A0R
+8+W+X39+z++YQTO6BLrZehGIuBNmdEQc+x7z+tQYhc3t8PjCvqt1z2XaGncBDqpJ
+6q+n2zmE8gEdKOffIqlZWiH5+TCEZFJQAZuyv8qKtIs2luMa6lFTNoK6iI8VjOZ5
+Wapxm0xYomjwQzYVr2mvMu1JyJw=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch2_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch2_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 2 (0x2)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta1/emailAddress=ch1_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:f4:24:ed:3d:fe:70:c8:51:b6:8d:26:78:90:6a:
-                    77:ff:de:7d:58:1f:00:fe:63:b0:88:de:46:18:d2:
-                    16:84:af:65:a1:9a:97:b1:38:14:6b:e7:98:c1:79:
-                    6f:0a:db:b2:92:6e:d6:7e:cd:cb:55:39:a0:27:e9:
-                    06:c8:45:19:2c:16:c3:4f:f5:af:cd:f6:14:cb:85:
-                    59:5c:1b:83:dc:f6:b6:4d:30:06:28:66:f6:2b:19:
-                    03:3f:00:de:09:77:50:a2:98:b1:73:3d:d5:79:f0:
-                    7e:79:2b:8e:76:96:c9:43:cf:44:9a:15:2e:09:00:
-                    47:a6:5a:f0:35:8b:88:b7:61
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:be:c1:86:30:d2:a3:02:f4:00:33:fc:54:f3:6f:
+                    d7:27:99:7b:57:e2:f1:93:f8:58:1c:eb:9a:cc:6b:
+                    23:9b:b8:a9:11:27:50:9b:d7:a7:c2:fe:8b:ee:54:
+                    d0:5d:e2:24:04:47:1c:cc:54:b5:89:bb:a6:26:de:
+                    b9:3b:73:19:67:5e:9a:88:12:de:87:de:0e:26:c9:
+                    0c:44:13:65:23:cd:7f:34:d6:bb:45:20:87:7e:ba:
+                    48:d5:2f:3f:fc:d6:8d:d7:b7:b2:9f:42:ef:76:9a:
+                    cf:c3:01:ae:b9:8f:00:33:ea:28:15:ca:30:da:8f:
+                    25:76:a4:55:2a:2c:7a:b8:eb
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                C2:62:F6:27:E6:91:FB:98:5F:55:6E:11:EE:6E:E0:04:76:A0:E7:01
+                12:30:0A:74:FD:DE:71:CF:4A:77:1E:1E:57:5E:F8:76:71:D7:5B:9E
             X509v3 Authority Key Identifier: 
-                keyid:C0:9E:26:BD:D6:FB:FB:BF:FA:CE:33:92:CA:4E:25:CF:EC:9E:BA:66
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta1/emailAddress=ta1
+                keyid:36:46:2D:8A:1B:8B:CE:C1:1D:02:37:B9:EC:A5:FF:BA:73:AE:E5:48
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta1/emailAddress=ta1
                 serial:01
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        a0:f7:c7:f9:6b:cf:6e:6c:36:74:b2:47:8d:76:04:74:88:de:
-        3b:cb:2d:e7:6c:fd:78:43:0f:29:9c:ba:92:97:dd:62:89:88:
-        31:c7:9b:b2:46:42:4a:e0:c1:3f:a8:5f:63:86:d1:75:d9:47:
-        46:d1:d3:87:dc:3e:7a:22:ce:8c:05:51:95:19:c5:2b:83:0f:
-        02:4c:54:a6:e8:a9:c9:79:bd:0b:f0:e7:4d:31:77:e6:07:ea:
-        1d:b1:35:48:30:15:28:c2:2d:36:42:fd:e9:11:85:7f:b0:9f:
-        7b:9a:b6:0e:1d:94:02:3a:3b:c1:b8:bd:c8:c9:8d:c6:b6:9a:
-        11:17
+         8e:a5:2a:c9:3f:e0:1f:a9:8c:a3:45:b8:0d:0e:35:43:c3:d6:
+         fe:f6:bc:0d:76:f0:26:d6:ab:e7:39:30:92:6f:cc:8e:0e:5f:
+         b0:92:29:41:39:41:14:2a:43:b1:bb:e5:d4:8c:b3:6e:b7:7b:
+         89:ab:3d:a4:e1:98:45:40:b9:1e:86:7b:b6:3f:55:e3:46:ab:
+         ed:41:45:6a:cc:af:a4:63:54:c8:ab:27:3f:59:67:8a:f5:60:
+         1b:63:b7:bb:27:94:00:8f:ee:f9:31:53:59:98:85:76:77:db:
+         dd:39:6f:1a:61:fe:0d:68:88:20:a8:d5:2b:c7:6a:08:5b:f1:
+         ac:9a
 -----BEGIN CERTIFICATE-----
-MIIDMjCCApugAwIBAgIBAjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDJfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDJf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD0JO09/nDIUbaNJniQanf/
-3n1YHwD+Y7CI3kYY0haEr2WhmpexOBRr55jBeW8K27KSbtZ+zctVOaAn6QbIRRks
-FsNP9a/N9hTLhVlcG4Pc9rZNMAYoZvYrGQM/AN4Jd1CimLFzPdV58H55K452lslD
-z0SaFS4JAEemWvA1i4i3YQIDAQABo4HbMIHYMB0GA1UdDgQWBBTCYvYn5pH7mF9V
-bhHubuAEdqDnATCBkgYDVR0jBIGKMIGHgBTAnia91vv7v/rOM5LKTiXP7J66ZqFs
-pGowaDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAMTA3RhMTESMBAGCSqG
-SIb3DQEJARYDdGExggEBMBIGA1UdEwEB/wQIMAYBAf8CAQMwDgYDVR0PAQH/BAQD
-AgEGMA0GCSqGSIb3DQEBCwUAA4GBAKD3x/lrz25sNnSyR412BHSI3jvLLeds/XhD
-DymcupKX3WKJiDHHm7JGQkrgwT+oX2OG0XXZR0bR04fcPnoizowFUZUZxSuDDwJM
-VKboqcl5vQvw500xd+YH6h2xNUgwFSjCLTZC/ekRhX+wn3uatg4dlAI6O8G4vcjJ
-jca2mhEX
+MIIDNTCCAp6gAwIBAgIBAjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTExFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoMl90YTExFjAUBgkqhkiG9w0BCQEWB2No
+Ml90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAL7BhjDSowL0ADP8VPNv
+1yeZe1fi8ZP4WBzrmsxrI5u4qREnUJvXp8L+i+5U0F3iJARHHMxUtYm7pibeuTtz
+GWdemogS3ofeDibJDEQTZSPNfzTWu0Ugh366SNUvP/zWjde3sp9C73aaz8MBrrmP
+ADPqKBXKMNqPJXakVSoserjrAgMBAAGjgdwwgdkwHQYDVR0OBBYEFBIwCnT93nHP
+SnceHlde+HZx11ueMIGTBgNVHSMEgYswgYiAFDZGLYobi87BHQI3ueyl/7pzruVI
+oW2kazBpMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMTESMBAG
+CSqGSIb3DQEJARYDdGExggEBMBIGA1UdEwEB/wQIMAYBAf8CAQMwDgYDVR0PAQH/
+BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAI6lKsk/4B+pjKNFuA0ONUPD1v72vA12
+8CbWq+c5MJJvzI4OX7CSKUE5QRQqQ7G75dSMs263e4mrPaThmEVAuR6Ge7Y/VeNG
+q+1BRWrMr6RjVMirJz9ZZ4r1YBtjt7snlACP7vkxU1mYhXZ32905bxph/g1oiCCo
+1SvHaghb8aya
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch3_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch3_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 3 (0x3)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch2_ta1/emailAddress=ch2_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:ec:46:7e:e1:35:25:1c:92:37:51:fb:99:13:70:
-                    e7:89:d6:3e:3b:28:59:98:96:e2:81:87:3f:99:85:
-                    5d:06:0a:d0:df:04:3e:fe:8a:00:f5:aa:91:93:a9:
-                    48:5c:59:b9:cb:f2:94:dd:fe:71:11:af:9c:7e:71:
-                    ce:96:21:cc:fd:27:e9:7e:82:2b:84:d5:73:3a:89:
-                    c0:09:2b:aa:16:d6:5f:7a:ac:81:d1:9b:18:4d:85:
-                    1e:33:2f:86:a8:c3:7a:2d:68:24:30:1d:7f:db:c5:
-                    30:0c:bf:d9:72:04:98:9d:ff:2f:cf:94:e7:2e:88:
-                    b2:47:fd:ee:c1:d2:e0:e9:39
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d3:5b:f1:93:8f:01:0f:c0:25:d9:07:f1:70:29:
+                    1e:56:0b:ff:93:70:1d:45:02:ef:52:22:8a:04:c9:
+                    08:85:33:db:77:c3:33:d9:5c:fe:30:2a:a8:ac:9d:
+                    d8:97:dc:b4:69:51:5e:d1:c9:86:68:a7:e3:ab:35:
+                    e2:8f:d0:36:1b:67:be:50:88:66:7c:4b:4f:d3:86:
+                    78:92:d9:c5:62:c7:04:a3:d7:9e:8c:c3:ca:48:41:
+                    52:3f:a1:82:dc:f2:bb:d2:9c:a9:58:25:3a:0b:73:
+                    b6:41:ab:6a:c3:6a:70:ce:a1:20:0f:b6:db:e0:91:
+                    0b:0a:1f:dc:02:f4:ed:32:0f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                D0:F9:37:92:54:28:C0:40:AE:62:94:51:42:6A:7C:8E:37:5F:AC:A8
+                8F:2A:82:4C:1E:39:97:C3:4A:6A:52:FC:D4:CB:E6:37:CE:12:91:59
             X509v3 Authority Key Identifier: 
-                keyid:C2:62:F6:27:E6:91:FB:98:5F:55:6E:11:EE:6E:E0:04:76:A0:E7:01
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1_ta1/emailAddress=ch1_ta1
+                keyid:12:30:0A:74:FD:DE:71:CF:4A:77:1E:1E:57:5E:F8:76:71:D7:5B:9E
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1_ta1/emailAddress=ch1_ta1
                 serial:02
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        3e:60:a3:23:dc:e2:bc:b9:60:14:1b:e5:dd:af:bd:f2:8b:cb:
-        f1:55:8a:03:e1:ee:82:f2:d2:7b:3d:0d:4a:56:f5:61:80:97:
-        27:90:c0:05:e4:e9:18:e8:29:97:eb:aa:6b:d2:4a:0c:b8:c0:
-        f3:cf:a5:4f:95:dd:46:03:96:eb:29:e4:bb:22:fe:5b:34:da:
-        02:8c:36:12:b6:9c:3e:a4:e4:d7:33:a3:ac:d8:45:65:75:37:
-        68:55:63:eb:d8:d1:6f:28:66:fc:ac:ad:15:08:67:41:41:32:
-        3f:ed:60:fc:01:e1:b9:88:24:95:1e:9c:ee:69:3b:d2:91:f8:
-        ef:81
+         94:2a:c9:c9:21:b7:bd:3a:72:31:65:89:16:11:00:e1:46:38:
+         16:b6:cd:d4:04:b3:18:71:3d:8d:4a:0a:ec:02:4e:ee:58:2c:
+         7d:d2:0b:6f:c6:d2:be:a6:f9:1c:e7:c2:76:2a:09:87:d2:06:
+         8e:0d:aa:66:70:e8:8f:ff:7d:1d:e4:4e:9b:58:71:f7:40:46:
+         a8:79:9d:86:6c:bf:64:3b:76:66:6c:08:21:62:09:6d:7b:f4:
+         5d:e2:8e:1c:e6:e3:56:71:de:b7:fe:92:07:f0:7e:13:e0:ad:
+         62:b3:08:9f:06:7e:9b:f6:8b:76:96:df:86:30:0e:bb:ef:9b:
+         b3:07
 -----BEGIN CERTIFICATE-----
-MIIDOjCCAqOgAwIBAgIBAzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gyX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gyX3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDNfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDNf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDsRn7hNSUckjdR+5kTcOeJ
-1j47KFmYluKBhz+ZhV0GCtDfBD7+igD1qpGTqUhcWbnL8pTd/nERr5x+cc6WIcz9
-J+l+giuE1XM6icAJK6oW1l96rIHRmxhNhR4zL4aow3otaCQwHX/bxTAMv9lyBJid
-/y/PlOcuiLJH/e7B0uDpOQIDAQABo4HjMIHgMB0GA1UdDgQWBBTQ+TeSVCjAQK5i
-lFFCanyON1+sqDCBmgYDVR0jBIGSMIGPgBTCYvYn5pH7mF9VbhHubuAEdqDnAaF0
-pHIwcDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxEDAOBgNVBAMUB2NoMV90YTExFjAU
-BgkqhkiG9w0BCQEWB2NoMV90YTGCAQIwEgYDVR0TAQH/BAgwBgEB/wIBAjAOBgNV
-HQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAPmCjI9zivLlgFBvl3a+98ovL
-8VWKA+HugvLSez0NSlb1YYCXJ5DABeTpGOgpl+uqa9JKDLjA88+lT5XdRgOW6ynk
-uyL+WzTaAow2EracPqTk1zOjrNhFZXU3aFVj69jRbyhm/KytFQhnQUEyP+1g/AHh
-uYgklR6c7mk70pH474E=
+MIIDPTCCAqagAwIBAgIBAzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMl90YTExFjAUBgkqhkiG9w0BCQEWB2NoMl90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTExFjAUBgkqhkiG9w0BCQEWB2No
+M190YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANNb8ZOPAQ/AJdkH8XAp
+HlYL/5NwHUUC71IiigTJCIUz23fDM9lc/jAqqKyd2JfctGlRXtHJhmin46s14o/Q
+NhtnvlCIZnxLT9OGeJLZxWLHBKPXnozDykhBUj+hgtzyu9KcqVglOgtztkGrasNq
+cM6hIA+22+CRCwof3AL07TIPAgMBAAGjgeQwgeEwHQYDVR0OBBYEFI8qgkweOZfD
+SmpS/NTL5jfOEpFZMIGbBgNVHSMEgZMwgZCAFBIwCnT93nHPSnceHlde+HZx11ue
+oXWkczBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTEx
+FjAUBgkqhkiG9w0BCQEWB2NoMV90YTGCAQIwEgYDVR0TAQH/BAgwBgEB/wIBAjAO
+BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAlCrJySG3vTpyMWWJFhEA
+4UY4FrbN1ASzGHE9jUoK7AJO7lgsfdILb8bSvqb5HOfCdioJh9IGjg2qZnDoj/99
+HeROm1hx90BGqHmdhmy/ZDt2ZmwIIWIJbXv0XeKOHObjVnHet/6SB/B+E+CtYrMI
+nwZ+m/aLdpbfhjAOu++bswc=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch4.3_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch4.3_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 12 (0xc)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e2:d0:ba:91:89:c2:26:21:4c:9d:68:63:7e:87:
-                    9b:9e:31:52:4d:30:b3:2b:9c:26:85:40:63:69:66:
-                    7c:5d:52:73:d3:61:01:78:18:0e:46:21:6d:34:1f:
-                    84:e2:42:72:9c:ef:68:7e:49:a6:3d:62:82:f3:0f:
-                    95:74:13:88:a1:d1:bf:00:93:10:24:d2:fc:bd:1a:
-                    a7:4f:f2:24:b2:60:d5:57:96:62:09:c8:94:5f:b6:
-                    57:38:f1:00:62:97:d9:a2:35:d6:95:47:97:78:48:
-                    17:77:2b:c4:62:fa:00:0c:f1:d4:6e:e1:74:25:38:
-                    0f:5c:57:af:92:37:e7:18:21
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:dd:ec:30:ee:2a:39:ec:cf:6d:c0:b9:04:f2:e0:
+                    0f:04:7a:e9:ab:f0:27:28:d9:6b:70:e5:c4:9b:c6:
+                    1b:bb:71:16:42:d5:47:80:60:2c:f6:26:90:9d:0b:
+                    cc:1b:18:bf:54:98:c7:e8:ba:bf:a2:5d:60:c9:b3:
+                    09:79:de:ee:02:d9:b9:70:22:c3:cd:60:04:5f:1e:
+                    df:a3:8f:43:73:ea:68:5e:df:70:86:aa:67:75:5a:
+                    59:ef:cd:0d:e4:f1:6d:ee:d3:bb:04:c7:52:e5:72:
+                    53:2a:e2:f3:02:65:7f:53:46:c3:15:e4:cb:8d:1b:
+                    cf:8f:1e:8d:6d:04:07:09:77
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                9E:F5:29:85:12:A6:F3:26:1C:25:81:F4:75:82:9E:80:B1:33:8D:BE
+                16:06:DB:79:36:82:5D:96:BA:FD:0F:C3:3D:E2:64:BA:E6:03:E6:3A
             X509v3 Authority Key Identifier: 
-                keyid:D0:F9:37:92:54:28:C0:40:AE:62:94:51:42:6A:7C:8E:37:5F:AC:A8
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
+                keyid:8F:2A:82:4C:1E:39:97:C3:4A:6A:52:FC:D4:CB:E6:37:CE:12:91:59
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
                 serial:03
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        87:45:e7:89:11:9c:2a:47:8e:63:84:93:80:3f:03:27:65:dd:
-        19:50:aa:1f:e5:50:67:c9:d8:3f:1e:74:85:fb:46:b2:c8:1c:
-        22:cb:a9:d0:d4:26:60:06:6e:9e:15:7e:d3:5a:06:8d:95:26:
-        36:10:16:e9:08:92:fb:9a:45:14:99:b5:ac:ee:06:d2:6b:c4:
-        21:63:13:b4:55:1f:c3:35:02:56:9e:7d:d1:4a:1f:45:91:f6:
-        c1:28:c3:f9:aa:e0:31:63:cc:c0:5d:77:7f:54:65:98:a3:39:
-        eb:73:83:ab:74:f3:c2:3e:be:9b:fe:18:75:3c:44:ad:a2:fc:
-        c2:42
+         26:70:cc:69:5b:26:cf:cc:1d:19:b6:61:20:59:22:d7:fa:a3:
+         d9:fa:e2:e3:87:07:24:5a:41:5b:7e:21:4c:f5:32:d2:d8:fd:
+         a5:17:b5:c4:0f:9a:d2:a6:dd:45:9f:13:2a:30:8a:75:5b:69:
+         9b:dd:06:85:3e:19:06:7d:5d:0f:3f:15:64:76:41:e9:a8:30:
+         bd:d7:26:66:07:60:da:e2:ec:80:44:6d:a5:8b:fd:9a:3a:0b:
+         92:b9:6c:f8:72:cc:7e:24:78:a2:a3:f7:ef:47:7a:aa:8b:89:
+         45:33:ff:01:bd:a0:d0:18:ea:a1:46:98:b5:7f:00:e1:00:8e:
+         7e:68
 -----BEGIN CERTIFICATE-----
-MIIDPjCCAqegAwIBAgIBDDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gzX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3Rh
-MTAeFw0xMTA0MTEyMjM3NDJaFw0xNDAxMDUyMjM3NDJaMHQxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRIwEAYDVQQDFAljaDQuM190YTExGDAWBgkqhkiG9w0BCQEWCWNo
-NC4zX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA4tC6kYnCJiFMnWhj
-foebnjFSTTCzK5wmhUBjaWZ8XVJz02EBeBgORiFtNB+E4kJynO9ofkmmPWKC8w+V
-dBOIodG/AJMQJNL8vRqnT/IksmDVV5ZiCciUX7ZXOPEAYpfZojXWlUeXeEgXdyvE
-YvoADPHUbuF0JTgPXFevkjfnGCECAwEAAaOB4zCB4DAdBgNVHQ4EFgQUnvUphRKm
-8yYcJYH0dYKegLEzjb4wgZoGA1UdIwSBkjCBj4AU0Pk3klQowECuYpRRQmp8jjdf
-rKihdKRyMHAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYD
-VQQHEwpNZW5sbyBQYXJrMQ0wCwYDVQQKEwRwa2c1MRAwDgYDVQQDFAdjaDJfdGEx
-MRYwFAYJKoZIhvcNAQkBFgdjaDJfdGExggEDMBIGA1UdEwEB/wQIMAYBAf8CAQAw
-DgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAIdF54kRnCpHjmOEk4A/
-Aydl3RlQqh/lUGfJ2D8edIX7RrLIHCLLqdDUJmAGbp4VftNaBo2VJjYQFukIkvua
-RRSZtazuBtJrxCFjE7RVH8M1AlaefdFKH0WR9sEow/mq4DFjzMBdd39UZZijOetz
-g6t088I+vpv+GHU8RK2i/MJC
+MIIDQTCCAqqgAwIBAgIBDDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTExFjAUBgkqhkiG9w0BCQEWB2NoM190
+YTEwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjB1MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEjAQBgNVBAMMCWNoNC4zX3RhMTEYMBYGCSqGSIb3DQEJARYJ
+Y2g0LjNfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDd7DDuKjnsz23A
+uQTy4A8Eeumr8Cco2Wtw5cSbxhu7cRZC1UeAYCz2JpCdC8wbGL9UmMfour+iXWDJ
+swl53u4C2blwIsPNYARfHt+jj0Nz6mhe33CGqmd1WlnvzQ3k8W3u07sEx1LlclMq
+4vMCZX9TRsMV5MuNG8+PHo1tBAcJdwIDAQABo4HkMIHhMB0GA1UdDgQWBBQWBtt5
+NoJdlrr9D8M94mS65gPmOjCBmwYDVR0jBIGTMIGQgBSPKoJMHjmXw0pqUvzUy+Y3
+zhKRWaF1pHMwcTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQDDAdjaDJf
+dGExMRYwFAYJKoZIhvcNAQkBFgdjaDJfdGExggEDMBIGA1UdEwEB/wQIMAYBAf8C
+AQAwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBACZwzGlbJs/MHRm2
+YSBZItf6o9n64uOHByRaQVt+IUz1MtLY/aUXtcQPmtKm3UWfEyowinVbaZvdBoU+
+GQZ9XQ8/FWR2QemoML3XJmYHYNri7IBEbaWL/Zo6C5K5bPhyzH4keKKj9+9HeqqL
+iUUz/wG9oNAY6qFGmLV/AOEAjn5o
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch4_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch4_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 4 (0x4)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch3_ta1/emailAddress=ch3_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:f5:af:af:99:95:f3:52:3b:eb:be:62:e6:eb:9f:
-                    c5:f8:ff:8f:0c:d2:e3:c7:06:b1:45:ca:ff:8c:fc:
-                    3d:bc:f4:6d:e3:f9:ac:12:69:d5:a1:6f:02:52:ad:
-                    50:34:7e:cc:a7:ee:82:04:b3:5b:e6:be:cc:44:e6:
-                    b8:d2:fc:1d:2a:80:d8:0c:c1:3c:4f:95:31:68:8a:
-                    fb:2b:e2:aa:b2:54:7c:3a:d3:86:6d:5f:20:b6:29:
-                    23:ae:74:09:fd:9a:d3:45:e2:e3:2a:62:1f:91:fd:
-                    a2:b1:2f:26:68:fb:4d:69:fb:66:1f:0b:4b:1a:52:
-                    ac:e1:8b:69:b1:16:96:89:13
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:af:c3:8b:39:3e:21:56:8a:d6:97:1b:c7:aa:c7:
+                    51:9e:e9:cf:15:1f:24:e6:91:92:81:b3:7d:30:eb:
+                    ea:12:30:13:03:d0:b9:60:41:8b:eb:88:f4:1f:e5:
+                    43:cf:b5:ae:47:7a:4d:46:6e:f8:16:42:67:db:20:
+                    e4:0d:1f:96:4f:21:59:95:f6:70:33:32:45:81:18:
+                    5e:a5:5b:fd:4a:e6:d7:97:cf:45:65:e7:74:79:5f:
+                    a5:9f:e1:c7:a5:d0:5d:24:a7:32:18:68:13:57:4c:
+                    cf:78:12:6f:9f:5c:e6:4d:be:89:24:4b:29:d8:02:
+                    b2:f9:f9:13:cf:92:43:0f:e5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                B2:A1:C2:1D:B7:20:56:20:8C:64:DA:BA:06:C6:5A:E4:0A:23:6E:01
+                54:8A:14:10:0B:AF:89:DC:1E:65:8A:17:37:6A:AC:D2:2B:6C:27:5C
             X509v3 Authority Key Identifier: 
-                keyid:D0:F9:37:92:54:28:C0:40:AE:62:94:51:42:6A:7C:8E:37:5F:AC:A8
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
+                keyid:8F:2A:82:4C:1E:39:97:C3:4A:6A:52:FC:D4:CB:E6:37:CE:12:91:59
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
                 serial:03
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        d5:54:78:2a:2c:5f:82:26:03:07:71:54:04:2d:81:e5:dd:a6:
-        b1:92:8a:37:5f:52:f0:13:cd:35:4a:2b:a7:24:9c:44:7b:ac:
-        1d:3c:52:82:e4:15:85:a9:d4:19:4d:55:c6:85:74:ac:2a:6c:
-        42:9f:92:d9:86:02:d8:90:a8:53:28:31:e1:e2:33:1b:d5:05:
-        c3:f7:94:86:10:5d:78:62:96:a7:d1:e3:b4:be:0e:e6:8c:03:
-        ef:4c:03:96:4e:6d:9a:b2:32:55:46:20:cf:41:d1:4f:db:c6:
-        57:34:df:51:d4:b9:9d:bf:d1:20:a5:e6:a0:34:ef:ab:e8:e9:
-        93:ce
+         6a:17:96:16:a6:3f:96:b7:8e:fb:e5:d7:14:f9:a8:8e:52:16:
+         04:0d:58:4b:f7:c6:70:c4:3f:d3:2b:13:24:7b:47:2d:cf:89:
+         59:bf:5c:6c:17:31:46:c4:17:e5:41:fe:5e:3f:ec:44:2e:92:
+         94:eb:3b:c9:ff:d1:5e:c0:ad:d3:51:2b:12:11:87:b2:17:2f:
+         40:5a:ac:76:f0:0f:ed:cd:ca:be:b6:b2:ef:bf:d4:79:04:e0:
+         ed:88:33:96:b0:a4:27:41:a7:31:0b:c4:d9:6a:ad:7d:82:bb:
+         63:15:2a:00:8e:60:af:ee:a6:8a:d3:65:6a:b8:f9:7e:0e:cd:
+         bf:d5
 -----BEGIN CERTIFICATE-----
-MIIDOjCCAqOgAwIBAgIBBDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gzX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDRfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDRf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD1r6+ZlfNSO+u+Yubrn8X4
-/48M0uPHBrFFyv+M/D289G3j+awSadWhbwJSrVA0fsyn7oIEs1vmvsxE5rjS/B0q
-gNgMwTxPlTFoivsr4qqyVHw604ZtXyC2KSOudAn9mtNF4uMqYh+R/aKxLyZo+01p
-+2YfC0saUqzhi2mxFpaJEwIDAQABo4HjMIHgMB0GA1UdDgQWBBSyocIdtyBWIIxk
-2roGxlrkCiNuATCBmgYDVR0jBIGSMIGPgBTQ+TeSVCjAQK5ilFFCanyON1+sqKF0
-pHIwcDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxEDAOBgNVBAMUB2NoMl90YTExFjAU
-BgkqhkiG9w0BCQEWB2NoMl90YTGCAQMwEgYDVR0TAQH/BAgwBgEB/wIBATAOBgNV
-HQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEA1VR4KixfgiYDB3FUBC2B5d2m
-sZKKN19S8BPNNUorpyScRHusHTxSguQVhanUGU1VxoV0rCpsQp+S2YYC2JCoUygx
-4eIzG9UFw/eUhhBdeGKWp9HjtL4O5owD70wDlk5tmrIyVUYgz0HRT9vGVzTfUdS5
-nb/RIKXmoDTvq+jpk84=
+MIIDPTCCAqagAwIBAgIBBDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTExFjAUBgkqhkiG9w0BCQEWB2NoM190
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2No
+NF90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAK/Dizk+IVaK1pcbx6rH
+UZ7pzxUfJOaRkoGzfTDr6hIwEwPQuWBBi+uI9B/lQ8+1rkd6TUZu+BZCZ9sg5A0f
+lk8hWZX2cDMyRYEYXqVb/Urm15fPRWXndHlfpZ/hx6XQXSSnMhhoE1dMz3gSb59c
+5k2+iSRLKdgCsvn5E8+SQw/lAgMBAAGjgeQwgeEwHQYDVR0OBBYEFFSKFBALr4nc
+HmWKFzdqrNIrbCdcMIGbBgNVHSMEgZMwgZCAFI8qgkweOZfDSmpS/NTL5jfOEpFZ
+oXWkczBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoMl90YTEx
+FjAUBgkqhkiG9w0BCQEWB2NoMl90YTGCAQMwEgYDVR0TAQH/BAgwBgEB/wIBATAO
+BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAaheWFqY/lreO++XXFPmo
+jlIWBA1YS/fGcMQ/0ysTJHtHLc+JWb9cbBcxRsQX5UH+Xj/sRC6SlOs7yf/RXsCt
+01ErEhGHshcvQFqsdvAP7c3Kvray77/UeQTg7YgzlrCkJ0GnMQvE2WqtfYK7YxUq
+AI5gr+6mitNlarj5fg7Nv9U=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch5.1_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch5.1_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 8 (0x8)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Validity
-            Not Before: Apr 11 22:37:40 2011 GMT
-            Not After : Jan  5 22:37:40 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cc:de:54:ed:78:31:c0:7c:e4:25:98:a3:0d:fa:
-                    77:08:f3:39:c4:9f:88:41:ee:00:a3:35:ed:b6:f0:
-                    cc:a3:fd:0f:ce:3c:70:b5:aa:1e:42:4e:5c:ae:d8:
-                    cb:99:53:ef:1e:49:f9:4c:5f:47:be:d0:e6:e2:f1:
-                    12:29:d5:77:75:88:79:4c:3b:64:05:ba:08:5d:dc:
-                    ed:1f:7f:15:92:69:ec:b9:c9:84:f0:7d:3f:db:66:
-                    34:a5:35:8c:22:9b:5f:4b:19:83:15:35:49:7c:4b:
-                    77:35:2c:c4:58:34:15:f1:66:99:ce:65:d3:06:b7:
-                    d2:35:d7:96:39:ee:d8:08:91
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:9d:91:87:82:56:78:7f:64:32:62:7e:ee:6c:38:
+                    f2:a2:f6:34:ba:a9:ec:bb:6e:0f:87:ab:46:a4:37:
+                    ce:80:f1:b5:8b:9b:0a:4b:2a:b6:46:9b:f1:47:c0:
+                    6b:85:7f:64:08:61:ac:53:d4:3b:ce:54:2a:6d:a4:
+                    65:cd:a7:dc:a5:3a:33:bf:86:2b:f6:d0:fb:24:80:
+                    56:8f:4f:d4:f9:96:71:f3:86:74:4b:47:38:da:18:
+                    79:ae:d9:5b:9d:09:9e:f7:cb:b4:a7:85:33:85:20:
+                    d3:2a:fc:72:c1:37:62:01:d6:b1:cb:4a:a0:09:c2:
+                    72:ea:fd:b8:5d:03:68:33:7d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -29,27 +29,27 @@
                 <EMPTY>
 
     Signature Algorithm: sha256WithRSAEncryption
-        22:ec:49:fd:44:5e:9a:b1:55:f7:29:4c:cf:66:ff:1f:ce:d7:
-        e6:31:ae:b5:f3:3b:c9:d8:e4:d4:4a:59:ff:db:9a:88:23:28:
-        14:62:78:03:b8:36:d8:32:56:c6:d2:09:0f:e4:33:ea:02:7f:
-        24:02:fc:4c:58:5c:e7:3a:4c:b6:69:55:bc:5e:c8:3e:c2:97:
-        66:82:74:6a:1c:1e:ae:ae:3d:35:f5:6e:a3:a5:9b:9d:23:d5:
-        da:de:e2:47:ee:ea:78:8a:36:19:73:f5:7f:38:bd:0e:bb:56:
-        3c:c8:21:0e:5a:57:a0:cf:08:50:e6:80:ef:3e:e5:ed:64:69:
-        d6:6d
+         11:3c:6b:22:14:f6:1a:18:8b:59:a4:8d:38:d6:6f:48:8a:01:
+         e2:d3:9d:6a:26:40:61:d3:9b:ce:8a:ab:b9:25:c4:89:c4:f9:
+         98:1e:6c:f5:1c:d7:f7:6a:c9:7b:48:ba:d7:e0:03:59:41:4d:
+         29:28:7d:2d:61:c5:7f:7f:8c:2f:30:2b:c6:6e:16:31:7d:45:
+         d2:2a:83:ea:fc:25:92:1f:cb:85:28:0a:f4:2c:a0:c4:c2:fc:
+         52:43:53:d1:46:e7:fd:3c:0a:9b:11:45:0f:09:2e:c6:93:26:
+         72:c9:20:28:7a:db:18:55:1b:15:70:1f:bc:0e:ab:18:c1:f8:
+         64:03
 -----BEGIN CERTIFICATE-----
-MIICezCCAeSgAwIBAgIBCDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g0X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g0X3Rh
-MTAeFw0xMTA0MTEyMjM3NDBaFw0xNDAxMDUyMjM3NDBaMHQxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRIwEAYDVQQDFAljaDUuMV90YTExGDAWBgkqhkiG9w0BCQEWCWNo
-NS4xX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAzN5U7XgxwHzkJZij
-Dfp3CPM5xJ+IQe4AozXttvDMo/0PzjxwtaoeQk5crtjLmVPvHkn5TF9HvtDm4vES
-KdV3dYh5TDtkBboIXdztH38VkmnsucmE8H0/22Y0pTWMIptfSxmDFTVJfEt3NSzE
-WDQV8WaZzmXTBrfSNdeWOe7YCJECAwEAAaMhMB8wDwYDVR0TAQH/BAUwAwEB/zAM
-BgNVHRIBAf8EAjAAMA0GCSqGSIb3DQEBCwUAA4GBACLsSf1EXpqxVfcpTM9m/x/O
-1+YxrrXzO8nY5NRKWf/bmogjKBRieAO4NtgyVsbSCQ/kM+oCfyQC/ExYXOc6TLZp
-VbxeyD7Cl2aCdGocHq6uPTX1bqOlm50j1dre4kfu6niKNhlz9X84vQ67VjzIIQ5a
-V6DPCFDmgO8+5e1kadZt
+MIICfTCCAeagAwIBAgIBCDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2NoNF90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB1MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4xX3RhMTEYMBYGCSqGSIb3DQEJARYJ
+Y2g1LjFfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdkYeCVnh/ZDJi
+fu5sOPKi9jS6qey7bg+Hq0akN86A8bWLmwpLKrZGm/FHwGuFf2QIYaxT1DvOVCpt
+pGXNp9ylOjO/hiv20PskgFaPT9T5lnHzhnRLRzjaGHmu2VudCZ73y7SnhTOFINMq
+/HLBN2IB1rHLSqAJwnLq/bhdA2gzfQIDAQABoyEwHzAPBgNVHRMBAf8EBTADAQH/
+MAwGA1UdEgEB/wQCMAAwDQYJKoZIhvcNAQELBQADgYEAETxrIhT2GhiLWaSNONZv
+SIoB4tOdaiZAYdObzoqruSXEicT5mB5s9RzX92rJe0i61+ADWUFNKSh9LWHFf3+M
+LzArxm4WMX1F0iqD6vwlkh/LhSgK9CygxML8UkNT0Ubn/TwKmxFFDwkuxpMmcskg
+KHrbGFUbFXAfvA6rGMH4ZAM=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch5.2_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch5.2_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 10 (0xa)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Validity
-            Not Before: Apr 11 22:37:41 2011 GMT
-            Not After : Jan  5 22:37:41 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c5:27:9b:4d:c3:41:cf:96:d4:f0:21:59:1b:77:
-                    ce:54:81:dc:05:57:1f:56:69:8c:5f:58:3f:88:4a:
-                    c6:73:bd:a9:4a:d0:f8:a3:33:1b:4f:d8:94:b5:d3:
-                    95:bd:00:06:d1:18:e8:ea:9e:41:ad:06:ea:c6:cc:
-                    9f:93:a7:c4:a0:3e:05:62:4c:3f:1c:88:79:a0:a1:
-                    eb:f3:94:d0:1b:8c:a8:9f:4c:3b:37:80:06:6b:00:
-                    e7:30:6c:d4:c2:51:27:7f:1a:e5:95:a7:1c:15:d6:
-                    98:0e:1f:2f:28:b7:a7:75:60:56:8e:74:a0:86:9a:
-                    06:d5:23:0f:11:83:02:95:73
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:a0:b5:e8:50:6e:0b:2e:be:8a:39:95:a1:f3:8f:
+                    03:1c:da:d3:74:5c:9d:ed:34:54:5e:3f:ac:e2:91:
+                    40:50:5e:d7:e3:bc:b1:8e:a6:62:d1:0b:33:e2:59:
+                    d7:67:f1:b7:af:f9:61:37:b1:24:aa:6f:67:e0:4f:
+                    ef:5d:a2:72:42:70:41:1e:32:e5:1a:94:4f:de:60:
+                    6c:e7:e1:96:99:82:d0:35:f2:40:03:de:92:10:f3:
+                    4f:91:e8:78:24:a1:ef:92:da:7b:49:4b:57:03:80:
+                    57:d8:fc:41:60:8a:f0:e6:55:fe:67:55:5e:68:bf:
+                    fe:fd:23:2b:ab:94:cb:12:c3
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                89:81:B5:75:FE:47:C0:C6:F5:28:97:38:D7:FC:58:E9:62:8D:31:C0
+                A4:07:01:64:2E:FC:65:F5:BC:44:82:AB:87:E5:17:5F:91:F5:8A:DD
             X509v3 Authority Key Identifier: 
-                keyid:B2:A1:C2:1D:B7:20:56:20:8C:64:DA:BA:06:C6:5A:E4:0A:23:6E:01
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
+                keyid:54:8A:14:10:0B:AF:89:DC:1E:65:8A:17:37:6A:AC:D2:2B:6C:27:5C
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
                 serial:04
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        63:3d:1b:46:ff:99:65:19:01:e8:fc:b1:a4:22:30:8c:da:43:
-        c5:79:05:0c:60:3a:0f:4b:3f:53:63:f0:12:63:a9:ee:63:10:
-        15:aa:f4:ae:13:10:4f:43:b4:31:8c:84:f5:c1:0b:86:ab:7b:
-        78:7e:7c:9b:3c:26:56:8e:aa:54:3b:ad:7e:be:23:3e:8f:8c:
-        cf:47:22:7d:f6:83:53:ca:72:f1:02:9a:07:4a:f7:94:00:1b:
-        d2:57:80:6d:c9:37:ab:58:d6:54:71:90:de:c9:3f:ee:c3:b5:
-        5c:0e:46:09:30:cf:95:58:2f:07:64:fe:27:70:9e:d0:29:dd:
-        f5:25
+         04:21:55:e4:d4:f9:07:b1:55:dd:d3:6c:5e:17:f5:84:36:49:
+         08:3f:96:1b:79:f6:1f:c8:aa:0a:e2:64:bd:90:e1:00:89:23:
+         94:1c:d9:c8:7d:a6:5e:48:4f:e4:6a:9d:c1:2a:b9:6c:6b:ed:
+         24:14:54:9f:87:bf:a1:d3:fd:73:39:eb:c4:88:85:7e:f5:35:
+         91:3d:85:ad:9e:c5:1f:fc:f6:06:71:ce:3f:dc:12:e8:6c:a6:
+         61:07:b8:d0:78:03:de:e6:be:e9:67:59:2f:70:24:c3:54:4e:
+         b3:5c:6e:54:8e:04:c3:b6:f1:83:1b:8d:7f:e8:b7:5b:3d:b2:
+         26:fe
 -----BEGIN CERTIFICATE-----
-MIIDPjCCAqegAwIBAgIBCjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g0X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g0X3Rh
-MTAeFw0xMTA0MTEyMjM3NDFaFw0xNDAxMDUyMjM3NDFaMHQxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRIwEAYDVQQDFAljaDUuMl90YTExGDAWBgkqhkiG9w0BCQEWCWNo
-NS4yX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxSebTcNBz5bU8CFZ
-G3fOVIHcBVcfVmmMX1g/iErGc72pStD4ozMbT9iUtdOVvQAG0Rjo6p5BrQbqxsyf
-k6fEoD4FYkw/HIh5oKHr85TQG4yon0w7N4AGawDnMGzUwlEnfxrllaccFdaYDh8v
-KLendWBWjnSghpoG1SMPEYMClXMCAwEAAaOB4zCB4DAdBgNVHQ4EFgQUiYG1df5H
-wMb1KJc41/xY6WKNMcAwgZoGA1UdIwSBkjCBj4AUsqHCHbcgViCMZNq6BsZa5Aoj
-bgGhdKRyMHAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYD
-VQQHEwpNZW5sbyBQYXJrMQ0wCwYDVQQKEwRwa2c1MRAwDgYDVQQDFAdjaDNfdGEx
-MRYwFAYJKoZIhvcNAQkBFgdjaDNfdGExggEEMBIGA1UdEwEB/wQIMAYBAf8CAQEw
-DgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAGM9G0b/mWUZAej8saQi
-MIzaQ8V5BQxgOg9LP1Nj8BJjqe5jEBWq9K4TEE9DtDGMhPXBC4are3h+fJs8JlaO
-qlQ7rX6+Iz6PjM9HIn32g1PKcvECmgdK95QAG9JXgG3JN6tY1lRxkN7JP+7DtVwO
-Rgkwz5VYLwdk/idwntAp3fUl
+MIIDQTCCAqqgAwIBAgIBCjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2NoNF90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB1MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4yX3RhMTEYMBYGCSqGSIb3DQEJARYJ
+Y2g1LjJfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCgtehQbgsuvoo5
+laHzjwMc2tN0XJ3tNFReP6zikUBQXtfjvLGOpmLRCzPiWddn8bev+WE3sSSqb2fg
+T+9donJCcEEeMuUalE/eYGzn4ZaZgtA18kAD3pIQ80+R6Hgkoe+S2ntJS1cDgFfY
+/EFgivDmVf5nVV5ov/79IyurlMsSwwIDAQABo4HkMIHhMB0GA1UdDgQWBBSkBwFk
+Lvxl9bxEgquH5RdfkfWK3TCBmwYDVR0jBIGTMIGQgBRUihQQC6+J3B5lihc3aqzS
+K2wnXKF1pHMwcTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQDDAdjaDNf
+dGExMRYwFAYJKoZIhvcNAQkBFgdjaDNfdGExggEEMBIGA1UdEwEB/wQIMAYBAf8C
+AQEwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4GBAAQhVeTU+QexVd3T
+bF4X9YQ2SQg/lht59h/IqgriZL2Q4QCJI5Qc2ch9pl5IT+RqncEquWxr7SQUVJ+H
+v6HT/XM568SIhX71NZE9ha2exR/89gZxzj/cEuhspmEHuNB4A97mvulnWS9wJMNU
+TrNcblSOBMO28YMbjX/ot1s9sib+
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch5.3_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch5.3_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 13 (0xd)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4.3_ta1/emailAddress=ch4.3_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:be:99:38:81:c2:5f:37:c3:d2:cc:7f:01:19:61:
-                    8d:8b:57:70:3a:2c:36:c1:c8:e4:a6:33:2a:bc:27:
-                    e9:cf:d7:ca:49:90:d2:e0:f1:82:0e:7d:50:aa:e3:
-                    8c:ca:07:61:bf:d3:fd:1e:f3:af:ec:00:dd:d2:ab:
-                    70:6a:1a:5a:00:32:ec:04:a3:a4:25:b1:82:1d:90:
-                    3c:f9:ae:91:90:d7:d6:c2:0e:8d:31:55:62:e2:6b:
-                    10:e0:10:6f:33:93:78:2f:58:b7:46:f4:b9:1a:4c:
-                    fd:81:b2:66:42:95:4b:a1:ff:46:9e:9d:f6:32:56:
-                    63:88:bc:83:43:54:bb:ce:a1
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:9a:0b:35:00:7e:06:fd:e2:50:97:7e:d2:c2:b8:
+                    20:2a:d9:bb:b8:3f:14:f9:aa:e3:98:dc:b9:49:62:
+                    32:9e:e7:51:16:ef:6b:69:59:7e:0f:c3:50:08:3d:
+                    dc:23:18:37:fa:70:cc:45:b8:47:1e:49:ef:18:15:
+                    47:8e:e6:c9:65:64:02:a8:f5:2a:d1:ef:3a:91:8f:
+                    5a:52:21:46:8f:61:87:55:c9:61:ea:e8:98:18:c5:
+                    99:1f:bd:43:02:13:a6:bf:c0:cd:d9:a5:ee:40:a3:
+                    05:bf:18:28:57:f6:4e:21:d0:89:a1:21:1c:39:ed:
+                    2d:ed:45:f0:da:75:37:da:7b
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                9F:45:5B:75:2A:5E:64:78:D2:D9:6F:34:3C:19:AE:27:DE:D7:6C:98
+                A5:4B:BC:BC:6C:A7:1D:7E:CB:31:E5:DF:BE:24:BE:B9:86:28:DE:68
             X509v3 Authority Key Identifier: 
-                keyid:9E:F5:29:85:12:A6:F3:26:1C:25:81:F4:75:82:9E:80:B1:33:8D:BE
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
+                keyid:16:06:DB:79:36:82:5D:96:BA:FD:0F:C3:3D:E2:64:BA:E6:03:E6:3A
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
                 serial:0C
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        62:7d:64:11:6a:5f:cd:6d:09:ae:5c:5f:d7:ef:5e:08:1f:c0:
-        6d:b0:b5:a1:28:74:88:95:10:93:2b:50:a4:7f:f3:92:3c:75:
-        23:ad:4b:e6:bd:ae:62:35:74:1c:0f:fd:00:e4:e7:e2:53:80:
-        b9:c5:30:1e:47:83:39:a5:88:3d:9b:a2:ee:86:27:94:cb:f5:
-        57:ba:91:ce:70:d7:12:a0:61:39:64:af:70:91:12:41:5e:4c:
-        7e:5d:5e:b0:42:05:31:e5:13:fd:bc:86:cc:b6:bc:4e:4c:69:
-        b6:2f:0e:63:80:16:c2:6d:7c:68:07:b6:a7:b4:04:ff:0b:97:
-        51:ee
+         4b:1b:27:81:60:e8:9c:ca:e9:2b:c6:94:9e:64:d5:1a:44:18:
+         e7:fb:98:cf:a0:10:e3:ae:ad:b3:fa:a6:21:9d:be:35:46:17:
+         e6:42:3f:8c:79:81:c5:46:f4:f8:04:72:02:a5:5c:6a:1f:cf:
+         62:e1:f9:6f:3a:26:5c:7b:13:27:bd:27:e7:8d:e4:75:b0:04:
+         05:84:44:8b:cf:2c:8b:8b:44:35:c7:60:79:91:04:69:cc:35:
+         90:5b:e5:9a:71:cb:6d:65:dd:a1:09:2c:d0:35:69:cc:cf:0a:
+         62:41:8f:18:ac:9e:8f:52:4c:fa:77:14:98:45:ce:06:c5:f9:
+         5d:6a
 -----BEGIN CERTIFICATE-----
-MIIDQjCCAqugAwIBAgIBDTANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g0LjNfdGExMRgwFgYJKoZIhvcNAQkBFgljaDQu
-M190YTEwHhcNMTEwNDExMjIzNzQyWhcNMTQwMTA1MjIzNzQyWjB0MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTESMBAGA1UEAxQJY2g1LjNfdGExMRgwFgYJKoZIhvcNAQkB
-FgljaDUuM190YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAL6ZOIHCXzfD
-0sx/ARlhjYtXcDosNsHI5KYzKrwn6c/XykmQ0uDxgg59UKrjjMoHYb/T/R7zr+wA
-3dKrcGoaWgAy7ASjpCWxgh2QPPmukZDX1sIOjTFVYuJrEOAQbzOTeC9Yt0b0uRpM
-/YGyZkKVS6H/Rp6d9jJWY4i8g0NUu86hAgMBAAGjgeMwgeAwHQYDVR0OBBYEFJ9F
-W3UqXmR40tlvNDwZrife12yYMIGaBgNVHSMEgZIwgY+AFJ71KYUSpvMmHCWB9HWC
-noCxM42+oXSkcjBwMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTET
-MBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UEAxQHY2gz
-X3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3RhMYIBDDASBgNVHRMBAf8ECDAGAQH/
-AgEAMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQBifWQRal/NbQmu
-XF/X714IH8BtsLWhKHSIlRCTK1Ckf/OSPHUjrUvmva5iNXQcD/0A5OfiU4C5xTAe
-R4M5pYg9m6LuhieUy/VXupHOcNcSoGE5ZK9wkRJBXkx+XV6wQgUx5RP9vIbMtrxO
-TGm2Lw5jgBbCbXxoB7antAT/C5dR7g==
+MIIDRTCCAq6gAwIBAgIBDTANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNC4zX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g0
+LjNfdGExMB4XDTEzMTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowdTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRIwEAYDVQQDDAljaDUuM190YTExGDAWBgkqhkiG9w0B
+CQEWCWNoNS4zX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAmgs1AH4G
+/eJQl37SwrggKtm7uD8U+arjmNy5SWIynudRFu9raVl+D8NQCD3cIxg3+nDMRbhH
+HknvGBVHjubJZWQCqPUq0e86kY9aUiFGj2GHVclh6uiYGMWZH71DAhOmv8DN2aXu
+QKMFvxgoV/ZOIdCJoSEcOe0t7UXw2nU32nsCAwEAAaOB5DCB4TAdBgNVHQ4EFgQU
+pUu8vGynHX7LMeXfviS+uYYo3mgwgZsGA1UdIwSBkzCBkIAUFgbbeTaCXZa6/Q/D
+PeJkuuYD5jqhdaRzMHExCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlh
+MRQwEgYDVQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEQMA4GA1UEAwwH
+Y2gzX3RhMTEWMBQGCSqGSIb3DQEJARYHY2gzX3RhMYIBDDASBgNVHRMBAf8ECDAG
+AQH/AgEAMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOBgQBLGyeBYOic
+yukrxpSeZNUaRBjn+5jPoBDjrq2z+qYhnb41RhfmQj+MeYHFRvT4BHICpVxqH89i
+4flvOiZcexMnvSfnjeR1sAQFhESLzyyLi0Q1x2B5kQRpzDWQW+WaccttZd2hCSzQ
+NWnMzwpiQY8YrJ6PUkz6dxSYRc4Gxfldag==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/chain_certs/ch5_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/chain_certs/ch5_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,32 +2,32 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 5 (0x5)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch4_ta1/emailAddress=ch4_ta1
         Validity
-            Not Before: Apr 11 22:37:39 2011 GMT
-            Not After : Jan  5 22:37:39 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c3:8d:d0:ab:25:75:ba:f5:20:df:7c:8a:d4:cd:
-                    40:f6:c3:ca:25:11:b5:30:d6:27:fa:e4:a0:11:d6:
-                    aa:32:7d:c8:15:9d:d7:6f:7f:ae:80:de:28:c3:ae:
-                    77:a8:7f:f1:05:e9:6b:bc:63:a9:a6:91:04:3b:79:
-                    6b:96:f2:e0:9a:17:79:d3:04:0a:5f:46:09:b5:6f:
-                    3e:a9:f4:34:47:62:18:f4:28:f7:d9:09:cd:4f:8a:
-                    33:df:9b:69:9b:61:ce:72:c7:35:ed:61:a0:5b:0c:
-                    c1:61:00:0a:ac:83:9a:6a:3c:6d:30:96:eb:77:8c:
-                    28:3f:fc:62:8a:fa:60:8e:17
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:df:c0:ed:cc:df:82:ab:d3:9b:54:8d:56:f7:0d:
+                    e4:d8:b4:ba:03:ef:a3:82:f6:b6:e6:4d:0f:b4:e5:
+                    61:98:88:bd:32:b3:47:21:4b:2c:e8:c3:9a:22:9c:
+                    35:63:a8:4f:2a:c1:47:1a:3a:b2:46:d6:61:4e:87:
+                    2a:13:3a:d8:35:3e:3c:ae:67:43:b8:3d:a9:95:df:
+                    7b:ba:e9:71:ec:31:99:b3:fa:00:96:8c:80:4b:1d:
+                    d9:77:e5:d2:14:9d:95:a2:ce:32:21:d5:2e:67:ae:
+                    b1:08:04:fb:9d:fb:70:16:74:5f:1a:d1:36:77:e8:
+                    4b:68:c3:d8:d4:fb:18:20:31
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                69:C7:BA:72:9C:7F:C3:92:8D:F6:A6:D0:20:48:5A:8E:A7:B6:E7:82
+                B7:43:D6:5A:46:C2:2F:15:50:05:D5:FB:5E:BE:EC:F8:33:9E:EC:EC
             X509v3 Authority Key Identifier: 
-                keyid:B2:A1:C2:1D:B7:20:56:20:8C:64:DA:BA:06:C6:5A:E4:0A:23:6E:01
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
+                keyid:54:8A:14:10:0B:AF:89:DC:1E:65:8A:17:37:6A:AC:D2:2B:6C:27:5C
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
                 serial:04
 
             X509v3 Basic Constraints: critical
@@ -35,31 +35,31 @@
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-        e7:9a:14:6b:dc:a5:fa:da:15:2a:f0:b5:87:ef:82:df:2c:b1:
-        8b:f9:f6:a5:a0:e6:d2:86:da:46:69:68:6f:68:26:5c:79:73:
-        21:31:ea:b4:a7:e6:58:c9:12:cd:8c:c0:d0:e2:05:f0:6f:1d:
-        56:e5:3f:4a:32:eb:02:39:b6:6e:cb:c4:e1:d5:21:0f:63:1e:
-        4f:0b:3d:af:ca:5a:7b:2b:9c:7f:51:44:7a:39:73:e5:f2:ba:
-        48:85:20:f9:36:b5:c2:14:44:da:7d:ae:83:2e:b4:d8:f1:77:
-        19:97:c0:c7:8b:e7:62:81:93:75:ed:93:dd:19:4b:36:00:ba:
-        c6:2d
+         96:fb:63:43:cf:70:0a:14:7b:47:4e:37:4b:2f:7c:7f:8c:75:
+         85:bb:e3:44:af:9c:2c:08:c5:9c:4d:c7:59:f1:70:3a:67:82:
+         1c:4c:3c:f7:8b:e7:00:f0:05:db:af:29:79:53:6f:09:a2:ac:
+         ae:4d:e2:df:4a:7d:4e:56:79:8c:85:97:47:14:4e:2f:7e:bd:
+         07:2c:70:01:85:43:3c:18:32:ed:24:36:24:1c:29:e0:0b:ce:
+         86:4d:a7:a9:88:b8:de:f1:0e:a3:13:c1:5c:d7:1b:76:81:c2:
+         3f:63:c3:76:1d:60:f7:e5:43:1f:25:3b:ae:d2:a5:1f:02:fa:
+         8c:a3
 -----BEGIN CERTIFICATE-----
-MIIDOjCCAqOgAwIBAgIBBTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g0X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g0X3Rh
-MTAeFw0xMTA0MTEyMjM3MzlaFw0xNDAxMDUyMjM3MzlaMHAxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRAwDgYDVQQDFAdjaDVfdGExMRYwFAYJKoZIhvcNAQkBFgdjaDVf
-dGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDjdCrJXW69SDffIrUzUD2
-w8olEbUw1if65KAR1qoyfcgVnddvf66A3ijDrneof/EF6Wu8Y6mmkQQ7eWuW8uCa
-F3nTBApfRgm1bz6p9DRHYhj0KPfZCc1PijPfm2mbYc5yxzXtYaBbDMFhAAqsg5pq
-PG0wlut3jCg//GKK+mCOFwIDAQABo4HjMIHgMB0GA1UdDgQWBBRpx7pynH/Dko32
-ptAgSFqOp7bngjCBmgYDVR0jBIGSMIGPgBSyocIdtyBWIIxk2roGxlrkCiNuAaF0
-pHIwcDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcT
-Ck1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxEDAOBgNVBAMUB2NoM190YTExFjAU
-BgkqhkiG9w0BCQEWB2NoM190YTGCAQQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
-HQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEA55oUa9yl+toVKvC1h++C3yyx
-i/n2paDm0obaRmlob2gmXHlzITHqtKfmWMkSzYzA0OIF8G8dVuU/SjLrAjm2bsvE
-4dUhD2MeTws9r8paeyucf1FEejlz5fK6SIUg+Ta1whRE2n2ugy602PF3GZfAx4vn
-YoGTde2T3RlLNgC6xi0=
+MIIDPTCCAqagAwIBAgIBBTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNF90YTExFjAUBgkqhkiG9w0BCQEWB2NoNF90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjBxMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoNV90YTExFjAUBgkqhkiG9w0BCQEWB2No
+NV90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAN/A7czfgqvTm1SNVvcN
+5Ni0ugPvo4L2tuZND7TlYZiIvTKzRyFLLOjDmiKcNWOoTyrBRxo6skbWYU6HKhM6
+2DU+PK5nQ7g9qZXfe7rpcewxmbP6AJaMgEsd2Xfl0hSdlaLOMiHVLmeusQgE+537
+cBZ0XxrRNnfoS2jD2NT7GCAxAgMBAAGjgeQwgeEwHQYDVR0OBBYEFLdD1lpGwi8V
+UAXV+16+7PgznuzsMIGbBgNVHSMEgZMwgZCAFFSKFBALr4ncHmWKFzdqrNIrbCdc
+oXWkczBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UE
+BwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxEDAOBgNVBAMMB2NoM190YTEx
+FjAUBgkqhkiG9w0BCQEWB2NoM190YTGCAQQwEgYDVR0TAQH/BAgwBgEB/wIBADAO
+BgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADgYEAlvtjQ89wChR7R043Sy98
+f4x1hbvjRK+cLAjFnE3HWfFwOmeCHEw894vnAPAF268peVNvCaKsrk3i30p9TlZ5
+jIWXRxROL369ByxwAYVDPBgy7SQ2JBwp4AvOhk2nqYi43vEOoxPBXNcbdoHCP2PD
+dh1g9+VDHyU7rtKlHwL6jKM=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/06.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/06.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 6 (0x6)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
         Validity
-            Not Before: Apr 11 22:37:40 2011 GMT
-            Not After : Jan  5 22:37:40 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5_ta1/emailAddress=cs1_ch5_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5_ta1/emailAddress=cs1_ch5_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e9:6c:6d:b5:1a:ef:fa:b5:f6:42:f6:7e:e6:f3:
-                    3f:11:2f:a7:c9:10:14:67:c9:fb:4b:c4:2f:c4:25:
-                    0d:a3:3c:66:0f:a0:1a:86:d5:19:48:e6:54:a3:a6:
-                    8d:6a:a2:89:a9:a5:ed:e7:49:ae:20:95:39:0c:19:
-                    41:87:e0:63:af:27:92:1d:55:b1:10:ea:b4:6d:5a:
-                    e6:21:78:93:94:e2:06:e6:7d:c6:53:4e:d5:af:82:
-                    08:a1:82:64:c1:57:78:7e:52:18:f6:38:f0:5e:8e:
-                    09:ea:fa:fc:7d:f3:2d:87:5d:a9:8e:ef:87:7a:e5:
-                    97:ef:7b:fb:b4:96:09:6b:17
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ba:a7:a1:60:33:eb:59:84:e6:2f:b0:30:38:b8:
+                    49:97:86:3b:82:4e:51:6a:28:bf:2a:6d:d3:46:77:
+                    67:ec:10:70:69:22:7f:e1:5d:7a:45:b5:81:2b:d2:
+                    ea:7d:41:5c:e2:4d:e8:2d:06:89:1c:4c:17:aa:3c:
+                    f5:2f:32:12:04:80:69:52:80:4a:ce:a1:4f:dc:76:
+                    a1:5a:d2:53:43:8f:7c:fb:82:eb:96:06:cd:05:89:
+                    74:34:7d:99:62:bc:09:67:e9:27:80:5b:78:65:05:
+                    57:c8:b6:b4:b7:83:5a:46:b2:80:6c:3f:05:3c:c6:
+                    49:2d:75:7c:48:2e:22:35:b7
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        14:9a:25:22:78:e5:77:2e:7f:28:cb:57:a9:d8:22:b1:7a:f1:
-        75:b9:79:3f:f3:7e:bc:eb:49:1e:35:0f:7a:20:f0:0a:f6:a1:
-        eb:08:a1:be:4c:c7:98:22:5b:9f:f9:a6:9a:e2:4a:85:13:2a:
-        f1:7f:da:cc:04:b1:13:d5:52:90:59:17:a8:f8:77:f8:ba:02:
-        88:62:fb:9d:28:3f:0d:15:ad:79:3f:d0:a2:cb:a2:87:b7:e0:
-        10:3a:a1:1b:4b:0c:79:f6:1e:b0:20:dc:0f:01:7e:c0:9c:86:
-        91:6d:c4:06:4b:fb:3b:da:70:e0:1b:9b:f3:9d:2d:57:cb:16:
-        26:4f
+         c2:d0:56:dd:4a:bb:8f:f9:de:49:4c:0c:41:af:29:73:07:f5:
+         da:44:4a:aa:0b:9c:80:33:56:cc:eb:c5:58:14:f9:c2:c9:cc:
+         93:2f:75:eb:6c:fd:b8:79:de:0d:35:db:46:8b:a6:d7:0b:59:
+         3d:35:c9:ac:68:76:63:85:bd:b1:03:21:c7:53:a5:f5:22:9f:
+         f0:c2:23:7e:de:32:6f:4a:7b:d8:d5:2d:b1:ee:db:ad:5a:f9:
+         35:46:55:11:5a:bb:6b:53:21:1d:ea:c4:4d:16:5c:01:f5:af:
+         91:47:bb:16:c1:9b:71:4e:5b:52:b5:ea:f9:d8:7a:53:c0:ef:
+         e7:f4
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBBjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g1X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g1X3Rh
-MTAeFw0xMTA0MTEyMjM3NDBaFw0xNDAxMDUyMjM3NDBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2g1X3RhMTEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoNV90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAOlsbbUa7/q1
-9kL2fubzPxEvp8kQFGfJ+0vEL8QlDaM8Zg+gGobVGUjmVKOmjWqiiaml7edJriCV
-OQwZQYfgY68nkh1VsRDqtG1a5iF4k5TiBuZ9xlNO1a+CCKGCZMFXeH5SGPY48F6O
-Cer6/H3zLYddqY7vh3rll+97+7SWCWsXAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBABSaJSJ45XcufyjLV6nY
-IrF68XW5eT/zfrzrSR41D3og8Ar2oesIob5Mx5giW5/5ppriSoUTKvF/2swEsRPV
-UpBZF6j4d/i6Aohi+50oPw0VrXk/0KLLooe34BA6oRtLDHn2HrAg3A8BfsCchpFt
-xAZL+zvacOAbm/OdLVfLFiZP
+MIICgDCCAemgAwIBAgIBBjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNV90YTExFjAUBgkqhkiG9w0BCQEWB2NoNV90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDVfdGExMRowGAYJKoZIhvcNAQkB
+FgtjczFfY2g1X3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuqehYDPr
+WYTmL7AwOLhJl4Y7gk5Raii/Km3TRndn7BBwaSJ/4V16RbWBK9LqfUFc4k3oLQaJ
+HEwXqjz1LzISBIBpUoBKzqFP3HahWtJTQ498+4LrlgbNBYl0NH2ZYrwJZ+kngFt4
+ZQVXyLa0t4NaRrKAbD8FPMZJLXV8SC4iNbcCAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAwtBW3Uq7j/neSUwM
+Qa8pcwf12kRKqgucgDNWzOvFWBT5wsnMky9162z9uHneDTXbRoum1wtZPTXJrGh2
+Y4W9sQMhx1Ol9SKf8MIjft4yb0p72NUtse7brVr5NUZVEVq7a1MhHerETRZcAfWv
+kUe7FsGbcU5bUrXq+dh6U8Dv5/Q=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/07.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/07.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,55 +2,57 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 7 (0x7)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
         Validity
-            Not Before: Apr 11 22:37:40 2011 GMT
-            Not After : Jan  5 22:37:40 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs2_ch5_ta1/emailAddress=cs2_ch5_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs2_ch5_ta1/emailAddress=cs2_ch5_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cd:c9:ab:ee:a1:89:01:60:89:00:7c:93:1f:fe:
-                    4c:54:75:58:52:81:b0:cb:be:4c:a7:a7:23:18:86:
-                    0e:9f:e1:41:99:dd:ff:e7:f3:66:1d:41:dd:aa:9e:
-                    f7:23:2d:c4:0e:24:16:e2:4d:54:8b:38:72:55:b4:
-                    11:26:f9:fc:04:fe:de:9b:83:02:01:98:36:8e:41:
-                    42:f2:0b:a7:07:00:f9:0e:66:96:a0:e4:f3:32:06:
-                    26:9d:41:fb:91:bf:7e:a8:c0:c7:62:e1:c9:ce:37:
-                    de:07:b5:df:55:87:9a:a5:3b:d4:c5:b6:24:4b:2a:
-                    e4:88:50:85:e9:d9:13:12:47
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cc:51:a3:86:48:a6:81:11:01:ba:be:40:6d:dc:
+                    f7:b6:0a:f8:9a:11:71:ea:09:42:3a:ed:ee:4e:0f:
+                    87:10:99:6f:c8:ef:41:bd:f6:d0:17:a7:db:7b:fe:
+                    51:dd:de:3a:f2:3b:d7:de:7d:96:71:4e:7f:4e:d0:
+                    cf:dd:3b:d8:6b:ce:ca:83:3a:7d:6e:65:cd:b5:fb:
+                    4b:32:9a:e6:20:f8:ed:8e:4c:99:f4:02:de:c5:d4:
+                    3b:6e:35:a8:3c:b4:9f:3f:5e:3b:85:33:4a:4d:b3:
+                    35:a3:d0:76:78:74:d2:72:99:9e:c1:69:1f:d1:8f:
+                    2a:11:eb:35:32:7b:ba:8f:99
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ch5_ta1_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ch5_ta1_crl.pem
 
     Signature Algorithm: sha256WithRSAEncryption
-        58:ba:80:0f:56:d9:4e:90:97:38:a2:f5:b7:3d:98:ff:32:ec:
-        63:01:79:25:5a:5b:d4:ac:bc:aa:e1:2d:c8:ea:34:32:b0:aa:
-        ce:9f:de:e7:f2:f7:35:f8:e5:71:97:27:d1:66:80:e8:22:c7:
-        bc:23:31:2b:98:60:b4:76:7b:62:38:ff:14:57:24:64:37:6b:
-        9d:22:2a:f9:16:90:91:01:d7:f3:91:24:29:c3:c6:53:7a:0b:
-        e9:af:2b:3b:5e:77:61:83:48:e8:e2:f2:a6:44:cc:5e:90:36:
-        f2:8e:dd:59:b6:c8:21:92:17:30:87:66:c9:08:2d:b9:5b:3a:
-        f2:4e
+         2c:76:2d:19:cd:d6:f0:88:16:6c:99:6c:19:1b:5e:d3:ca:b1:
+         6d:3c:f1:5b:2c:3b:52:cd:7f:f5:1b:4f:e0:49:9e:48:5c:5e:
+         16:55:57:a3:0d:c6:eb:f5:a7:13:8d:57:c4:ff:df:3d:66:00:
+         a3:b9:18:c3:19:5c:ba:1c:ae:83:bd:90:a6:c8:6e:5a:c6:b5:
+         51:b5:33:69:59:7a:5a:00:24:61:02:41:c5:c2:ff:cc:12:a1:
+         d7:d4:d5:29:b9:22:94:e0:5c:5c:29:ec:82:ba:ff:1a:40:50:
+         88:58:98:a8:b3:2b:86:3c:a2:21:8b:b4:b2:fc:3a:b0:c7:f1:
+         03:e8
 -----BEGIN CERTIFICATE-----
-MIICrjCCAhegAwIBAgIBBzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g1X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g1X3Rh
-MTAeFw0xMTA0MTEyMjM3NDBaFw0xNDAxMDUyMjM3NDBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczJfY2g1X3RhMTEaMBgGCSqGSIb3DQEJARYL
-Y3MyX2NoNV90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAM3Jq+6hiQFg
-iQB8kx/+TFR1WFKBsMu+TKenIxiGDp/hQZnd/+fzZh1B3aqe9yMtxA4kFuJNVIs4
-clW0ESb5/AT+3puDAgGYNo5BQvILpwcA+Q5mlqDk8zIGJp1B+5G/fqjAx2Lhyc43
-3ge131WHmqU71MW2JEsq5IhQhenZExJHAgMBAAGjUDBOMAwGA1UdEwEB/wQCMAAw
-PgYDVR0fBDcwNTAzoDGgL4YtaHR0cDovL2xvY2FsaG9zdDoxMjAwMS9maWxlLzAv
-Y2g1X3RhMV9jcmwucGVtMA0GCSqGSIb3DQEBCwUAA4GBAFi6gA9W2U6Qlzii9bc9
-mP8y7GMBeSVaW9SsvKrhLcjqNDKwqs6f3ufy9zX45XGXJ9FmgOgix7wjMSuYYLR2
-e2I4/xRXJGQ3a50iKvkWkJEB1/ORJCnDxlN6C+mvKzted2GDSOji8qZEzF6QNvKO
-3Vm2yCGSFzCHZskILblbOvJO
+MIICsDCCAhmgAwIBAgIBBzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNV90YTExFjAUBgkqhkiG9w0BCQEWB2NoNV90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMl9jaDVfdGExMRowGAYJKoZIhvcNAQkB
+FgtjczJfY2g1X3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAzFGjhkim
+gREBur5Abdz3tgr4mhFx6glCOu3uTg+HEJlvyO9BvfbQF6fbe/5R3d468jvX3n2W
+cU5/TtDP3TvYa87Kgzp9bmXNtftLMprmIPjtjkyZ9ALexdQ7bjWoPLSfP147hTNK
+TbM1o9B2eHTScpmewWkf0Y8qEes1Mnu6j5kCAwEAAaNQME4wDAYDVR0TAQH/BAIw
+ADA+BgNVHR8ENzA1MDOgMaAvhi1odHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUv
+MC9jaDVfdGExX2NybC5wZW0wDQYJKoZIhvcNAQELBQADgYEALHYtGc3W8IgWbJls
+GRte08qxbTzxWyw7Us1/9RtP4EmeSFxeFlVXow3G6/WnE41XxP/fPWYAo7kYwxlc
+uhyug72QpshuWsa1UbUzaVl6WgAkYQJBxcL/zBKh19TVKbkilOBcXCnsgrr/GkBQ
+iFiYqLMrhjyiIYu0svw6sMfxA+g=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/09.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/09.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 9 (0x9)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
         Validity
-            Not Before: Apr 11 22:37:41 2011 GMT
-            Not After : Jan  5 22:37:41 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5.1_ta1/emailAddress=cs1_ch5.1_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5.1_ta1/emailAddress=cs1_ch5.1_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:9d:74:cf:25:35:26:cd:52:2e:9a:fc:8d:0b:4f:
-                    85:33:83:61:7a:f1:f1:c1:55:3d:dc:2e:20:77:8e:
-                    20:de:eb:e4:37:b6:6a:a4:c8:94:09:6c:f8:36:bd:
-                    78:a6:3f:2c:64:c3:23:d3:c7:fa:1c:36:a3:24:51:
-                    c0:ac:2d:20:6f:15:bf:aa:d8:94:5f:5f:8e:0a:c5:
-                    e0:aa:24:02:a5:f9:e4:cc:97:7f:74:b1:f1:a1:ab:
-                    30:6c:70:74:a4:5a:bd:5e:d7:69:64:6a:42:8d:c5:
-                    d0:b9:21:66:5a:9b:37:25:fa:34:cc:08:21:45:cb:
-                    23:10:eb:66:66:d2:9b:bc:19
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d5:b5:6f:9a:de:79:48:1e:9e:7c:61:b5:05:3f:
+                    f1:ef:a2:74:ac:83:92:f7:fa:6f:bc:ea:bf:7d:ac:
+                    d8:c9:ef:a3:50:01:2c:db:17:7c:68:6c:34:04:77:
+                    89:f6:77:db:63:08:2b:e7:59:6a:7a:d9:13:ef:d0:
+                    b1:1c:13:e0:3a:ee:0f:b6:e9:74:98:ce:30:25:dd:
+                    57:05:ed:55:f8:d2:5e:7a:c9:37:9d:29:87:a4:c8:
+                    55:f2:e7:a4:d8:cf:19:ee:af:d9:0d:35:e7:67:ae:
+                    87:70:f6:d2:98:1d:62:c6:aa:b6:ed:d0:50:77:79:
+                    ad:2e:5f:ef:a7:22:81:b3:2f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        3d:79:e6:0f:d3:33:eb:e7:fb:d4:39:f7:41:1e:f2:47:56:01:
-        d3:8b:bd:0d:0c:d5:ae:f1:85:6d:34:74:78:b3:27:20:88:4d:
-        bd:3a:b1:ac:d2:5c:f6:f3:87:f9:af:76:3a:93:60:a4:f5:97:
-        4c:c3:a6:aa:2a:f1:22:61:ea:2d:e4:97:f4:57:f7:30:84:85:
-        81:a1:aa:12:5a:37:82:96:11:d0:53:40:6c:5e:28:9f:42:1c:
-        3c:89:ae:d5:88:5d:cc:3e:4d:5c:ab:94:03:de:95:4a:b1:f2:
-        6b:cd:c1:cd:08:fa:87:88:80:e4:97:0f:36:55:3b:5d:60:a6:
-        1e:e3
+         75:2d:87:c6:b6:d7:5c:e7:bd:77:6f:d7:63:e4:f4:04:d1:df:
+         37:6f:80:99:9d:fe:b3:81:30:b4:1d:0b:3b:c7:f6:6c:15:a5:
+         ad:c2:2e:dc:5a:87:88:e0:b0:c9:81:99:33:c3:6a:f1:8d:4b:
+         8f:8c:cd:99:d4:ff:86:fe:3e:6e:b1:00:f0:15:16:d7:01:16:
+         13:8e:0e:31:35:ca:00:3c:88:7e:ca:8f:e3:32:6e:74:02:35:
+         66:3a:db:c8:83:37:b7:8c:7b:ba:bf:0d:aa:b8:d4:d8:28:03:
+         f5:f7:6f:c9:aa:d0:3c:03:cf:3d:da:aa:ae:1a:04:c6:7e:58:
+         ff:fe
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBCTANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g1LjFfdGExMRgwFgYJKoZIhvcNAQkBFgljaDUu
-MV90YTEwHhcNMTEwNDExMjIzNzQxWhcNMTQwMTA1MjIzNzQxWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoNS4xX3RhMTEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoNS4xX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-nXTPJTUmzVIumvyNC0+FM4NhevHxwVU93C4gd44g3uvkN7ZqpMiUCWz4Nr14pj8s
-ZMMj08f6HDajJFHArC0gbxW/qtiUX1+OCsXgqiQCpfnkzJd/dLHxoaswbHB0pFq9
-XtdpZGpCjcXQuSFmWps3Jfo0zAghRcsjEOtmZtKbvBkCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAPXnmD9Mz
-6+f71Dn3QR7yR1YB04u9DQzVrvGFbTR0eLMnIIhNvTqxrNJc9vOH+a92OpNgpPWX
-TMOmqirxImHqLeSX9Ff3MISFgaGqElo3gpYR0FNAbF4on0IcPImu1YhdzD5NXKuU
-A96VSrHya83BzQj6h4iA5JcPNlU7XWCmHuM=
+MIICiDCCAfGgAwIBAgIBCTANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4xX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g1
+LjFfdGExMB4XDTEzMTIxMzAwMTMzNFoXDTE2MDkwODAwMTMzNFowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2g1LjFfdGExMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2g1LjFfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDVtW+a3nlIHp58YbUFP/HvonSsg5L3+m+86r99rNjJ76NQASzbF3xobDQEd4n2
+d9tjCCvnWWp62RPv0LEcE+A67g+26XSYzjAl3VcF7VX40l56yTedKYekyFXy56TY
+zxnur9kNNednrodw9tKYHWLGqrbt0FB3ea0uX++nIoGzLwIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQB1LYfG
+ttdc5713b9dj5PQE0d83b4CZnf6zgTC0HQs7x/ZsFaWtwi7cWoeI4LDJgZkzw2rx
+jUuPjM2Z1P+G/j5usQDwFRbXARYTjg4xNcoAPIh+yo/jMm50AjVmOtvIgze3jHu6
+vw2quNTYKAP192/JqtA8A8892qquGgTGflj//g==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/0B.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/0B.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 11 (0xb)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5.2_ta1/emailAddress=cs1_ch5.2_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5.2_ta1/emailAddress=cs1_ch5.2_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c8:74:f3:2f:47:e9:02:0e:f4:93:b9:c2:65:ae:
-                    74:a2:90:3e:2c:36:bd:86:b1:44:f9:ac:ce:ac:0d:
-                    8f:c6:fa:b4:94:62:39:25:63:12:77:4e:4b:26:ca:
-                    7b:ad:7e:e2:1c:9a:18:6d:10:cf:6d:82:b6:00:db:
-                    57:d6:ca:56:bb:af:bd:72:76:19:5f:18:f3:ce:55:
-                    3e:c9:9f:a0:a5:65:6d:01:d4:0b:fe:a0:8e:ba:d2:
-                    2d:19:5f:72:93:ab:50:a7:91:ba:3d:e6:d7:5f:07:
-                    4a:61:c2:3a:7b:22:77:9e:93:73:16:b9:b8:e4:d6:
-                    a4:9f:95:1d:f3:54:69:19:3f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b5:6f:3b:c4:aa:e3:6b:1a:e2:26:41:f2:49:f1:
+                    40:85:73:dc:ec:ef:04:d4:c9:fa:05:29:fc:bb:b9:
+                    83:5f:f1:05:d2:06:9c:e2:52:09:91:d7:d5:3c:45:
+                    ef:3f:77:2b:c8:fc:69:78:19:96:e5:14:c3:7e:8a:
+                    af:56:c0:44:ca:5c:49:bc:3c:71:0a:b9:05:6e:2a:
+                    b7:3f:02:8a:80:da:e7:ab:47:eb:18:40:18:4a:80:
+                    54:2c:dd:97:09:df:7d:ae:0f:f2:3a:9a:51:11:af:
+                    86:bb:f1:ec:5d:45:4d:64:11:d5:0f:2f:bd:79:eb:
+                    91:c1:5e:23:2e:18:aa:6e:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        13:49:e0:c1:04:5e:6e:af:74:a7:15:5c:2d:b4:0d:26:fb:00:
-        ca:f3:ed:0a:87:fb:5f:1a:c9:d4:48:fd:30:96:eb:c2:f4:34:
-        af:09:ef:71:ad:1d:d0:dd:5d:53:12:cd:63:7f:09:2a:10:f7:
-        12:7d:61:78:29:5b:80:c3:c7:5f:e7:16:af:c4:11:72:1e:45:
-        82:0b:67:3b:76:8e:33:f0:d1:3a:b6:ca:5a:e9:8f:33:c9:79:
-        b6:7e:ac:b6:ef:c3:36:f8:a0:ae:88:0c:7e:ed:74:f9:44:b2:
-        1b:e3:de:36:d4:9e:dd:5b:99:86:b3:7e:13:19:31:6d:6d:ff:
-        bf:f7
+         30:93:85:ec:3e:1b:11:03:97:84:c4:63:bf:5c:02:32:b6:56:
+         af:42:a5:28:24:7d:63:6c:a5:9c:9a:f5:52:7b:cf:c0:22:91:
+         47:7a:92:10:19:c4:51:08:1a:68:5e:50:a2:f1:fc:ac:23:8c:
+         dd:0c:a4:6a:21:8d:db:78:e1:5b:29:7b:8d:3c:5e:85:d8:4e:
+         5f:24:f4:17:f8:96:a8:62:db:04:2d:92:3c:ea:9f:7e:3b:ef:
+         1e:45:aa:0d:88:84:e9:a3:ee:42:bd:13:43:dd:e4:8f:0d:db:
+         e2:ae:0c:be:40:7b:a6:f1:86:19:ee:ff:6d:6f:5b:11:3a:41:
+         51:9c
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBCzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g1LjJfdGExMRgwFgYJKoZIhvcNAQkBFgljaDUu
-Ml90YTEwHhcNMTEwNDExMjIzNzQyWhcNMTQwMTA1MjIzNzQyWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoNS4yX3RhMTEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoNS4yX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-yHTzL0fpAg70k7nCZa50opA+LDa9hrFE+azOrA2Pxvq0lGI5JWMSd05LJsp7rX7i
-HJoYbRDPbYK2ANtX1spWu6+9cnYZXxjzzlU+yZ+gpWVtAdQL/qCOutItGV9yk6tQ
-p5G6PebXXwdKYcI6eyJ3npNzFrm45Nakn5Ud81RpGT8CAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAE0ngwQRe
-bq90pxVcLbQNJvsAyvPtCof7XxrJ1Ej9MJbrwvQ0rwnvca0d0N1dUxLNY38JKhD3
-En1heClbgMPHX+cWr8QRch5FggtnO3aOM/DROrbKWumPM8l5tn6stu/DNvigrogM
-fu10+USyG+PeNtSe3VuZhrN+ExkxbW3/v/c=
+MIICiDCCAfGgAwIBAgIBCzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4yX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g1
+LjJfdGExMB4XDTEzMTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2g1LjJfdGExMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2g1LjJfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQC1bzvEquNrGuImQfJJ8UCFc9zs7wTUyfoFKfy7uYNf8QXSBpziUgmR19U8Re8/
+dyvI/Gl4GZblFMN+iq9WwETKXEm8PHEKuQVuKrc/AoqA2uerR+sYQBhKgFQs3ZcJ
+332uD/I6mlERr4a78exdRU1kEdUPL71565HBXiMuGKpuiQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQAwk4Xs
+PhsRA5eExGO/XAIytlavQqUoJH1jbKWcmvVSe8/AIpFHepIQGcRRCBpoXlCi8fys
+I4zdDKRqIY3beOFbKXuNPF6F2E5fJPQX+JaoYtsELZI86p9+O+8eRaoNiITpo+5C
+vRND3eSPDdvirgy+QHum8YYZ7v9tb1sROkFRnA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/0E.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/0E.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 14 (0xe)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5.3_ta1/emailAddress=cs1_ch5.3_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5.3_ta1/emailAddress=cs1_ch5.3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b5:76:e5:90:97:10:d5:aa:02:02:eb:87:f5:96:
-                    3a:94:31:a6:d9:1b:99:36:6b:62:13:36:cd:75:bf:
-                    5d:b9:19:02:15:79:e8:0c:95:12:80:a8:97:85:60:
-                    30:6f:4a:3d:cb:b4:bc:d8:a6:4d:a0:42:64:28:d3:
-                    07:2e:0a:f3:35:c3:35:10:08:f9:1e:e9:07:63:4b:
-                    7d:36:cc:65:7e:be:65:cb:a2:ad:8b:4a:1c:ec:9e:
-                    f6:f5:14:e7:93:42:5c:0b:a3:7e:73:ae:18:42:32:
-                    32:a0:45:96:2d:d5:d7:5c:75:f2:e3:48:23:34:20:
-                    88:4f:7e:1a:21:8c:45:30:0d
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c5:03:2b:f6:07:4e:f1:a3:9b:96:87:6d:ea:e2:
+                    bb:0b:fb:95:70:f6:34:a7:bb:e7:9f:df:ff:8a:fd:
+                    28:56:0b:fb:de:5d:79:d1:ba:0f:41:73:7f:5b:b9:
+                    17:6b:24:db:6f:20:a3:62:5e:3a:bb:71:29:18:33:
+                    52:24:ff:a9:9b:70:49:7f:78:94:f7:bd:a3:bf:2f:
+                    f4:de:e2:6f:61:13:ce:4f:f3:6a:85:84:35:ae:1d:
+                    a7:fb:00:2d:35:33:cc:18:ff:85:d9:37:0a:15:2b:
+                    15:71:de:ae:8c:99:ef:5b:dc:7b:4b:c1:b3:08:d9:
+                    57:29:29:e0:8d:46:e0:79:83
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        76:78:0e:96:48:35:42:08:26:68:65:9d:49:c6:3b:b7:f2:c7:
-        3b:41:e1:94:2b:30:ec:65:1d:90:bd:3e:6a:ec:66:f1:3d:e6:
-        76:b7:e7:a3:c7:96:b0:61:39:0b:e1:4e:15:cd:f7:95:48:c7:
-        ee:21:ce:81:5e:04:85:5b:2e:66:9f:2a:c1:6e:6f:4d:e3:c8:
-        32:1f:35:53:7d:4f:ff:0f:0f:07:25:6a:f9:da:74:0c:8d:cf:
-        86:3b:c1:30:bc:dd:a4:80:37:78:a3:03:1e:58:29:16:1b:d5:
-        b0:12:4e:8f:f4:da:c4:46:f4:28:4e:36:ac:d7:8a:95:c3:18:
-        e8:2e
+         0d:01:09:aa:c9:69:4c:33:74:70:07:ab:60:b6:0f:75:36:9e:
+         62:c2:96:82:f4:94:e4:9e:4b:6a:b4:fc:4e:45:21:e5:a7:20:
+         18:2a:a4:82:43:92:3a:d5:29:3a:f4:bb:e8:40:65:c8:08:53:
+         3b:46:42:4d:0b:f6:ba:8d:3f:08:ab:43:98:4b:41:40:8c:d6:
+         2d:58:dc:a8:53:e3:78:51:92:32:7e:00:9c:16:bb:c1:61:73:
+         68:2b:6d:4e:0f:f6:41:e4:08:43:b1:77:85:22:2b:06:1e:69:
+         48:38:28:9c:d5:60:65:7b:94:db:e7:d4:37:de:6a:0f:f3:cb:
+         53:45
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBDjANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g1LjNfdGExMRgwFgYJKoZIhvcNAQkBFgljaDUu
-M190YTEwHhcNMTEwNDExMjIzNzQyWhcNMTQwMTA1MjIzNzQyWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoNS4zX3RhMTEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoNS4zX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-tXblkJcQ1aoCAuuH9ZY6lDGm2RuZNmtiEzbNdb9duRkCFXnoDJUSgKiXhWAwb0o9
-y7S82KZNoEJkKNMHLgrzNcM1EAj5HukHY0t9Nsxlfr5ly6Kti0oc7J729RTnk0Jc
-C6N+c64YQjIyoEWWLdXXXHXy40gjNCCIT34aIYxFMA0CAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAdngOlkg1
-QggmaGWdScY7t/LHO0HhlCsw7GUdkL0+auxm8T3mdrfno8eWsGE5C+FOFc33lUjH
-7iHOgV4EhVsuZp8qwW5vTePIMh81U31P/w8PByVq+dp0DI3PhjvBMLzdpIA3eKMD
-HlgpFhvVsBJOj/TaxEb0KE42rNeKlcMY6C4=
+MIICiDCCAfGgAwIBAgIBDjANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4zX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g1
+LjNfdGExMB4XDTEzMTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2g1LjNfdGExMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2g1LjNfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDFAyv2B07xo5uWh23q4rsL+5Vw9jSnu+ef3/+K/ShWC/veXXnRug9Bc39buRdr
+JNtvIKNiXjq7cSkYM1Ik/6mbcEl/eJT3vaO/L/Te4m9hE85P82qFhDWuHaf7AC01
+M8wY/4XZNwoVKxVx3q6Mme9b3HtLwbMI2VcpKeCNRuB5gwIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQANAQmq
+yWlMM3RwB6tgtg91Np5iwpaC9JTknktqtPxORSHlpyAYKqSCQ5I61Sk69LvoQGXI
+CFM7RkJNC/a6jT8Iq0OYS0FAjNYtWNyoU+N4UZIyfgCcFrvBYXNoK21OD/ZB5AhD
+sXeFIisGHmlIOCic1WBle5Tb59Q33moP88tTRQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/0F.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/0F.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 15 (0xf)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta2/emailAddress=ta2
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta2/emailAddress=ta2
         Validity
-            Not Before: Apr 11 22:37:43 2011 GMT
-            Not After : Jan  5 22:37:43 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ta2/emailAddress=cs1_ta2
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ta2/emailAddress=cs1_ta2
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e7:3a:08:5d:d7:3d:c8:50:43:ad:92:87:40:58:
-                    59:5c:fa:34:ba:c9:bd:5b:d7:9f:17:b8:4f:d2:15:
-                    fd:86:d9:f0:3a:07:48:14:f3:c0:a4:9e:e3:ee:00:
-                    45:ba:aa:de:3a:5c:53:d6:0d:dd:46:88:d3:b6:13:
-                    aa:ee:f8:c0:3e:fa:eb:0a:6d:4a:0d:f7:39:21:ff:
-                    5d:dc:d7:13:5b:2a:e9:e4:c0:1e:31:2b:5b:00:ce:
-                    b0:55:44:72:97:66:06:ab:41:71:05:4a:83:6b:3b:
-                    cf:a7:ce:5d:61:43:3b:bb:60:19:c4:33:ac:23:72:
-                    66:9d:e9:72:be:bd:6c:ad:2b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:be:2d:d1:b2:aa:38:aa:c1:4f:f3:f7:07:f2:f3:
+                    30:0c:6d:f7:13:ed:c3:c7:c8:f8:87:8d:ea:a3:49:
+                    cf:74:dd:30:1b:1f:9d:a6:8e:b7:eb:fa:f5:f7:e5:
+                    e0:05:9a:e4:b1:ed:2d:ee:ff:f8:ab:23:9a:f3:24:
+                    ad:99:26:83:4d:e7:35:b7:c8:b1:60:3d:0c:44:e9:
+                    2c:24:50:ee:86:5c:f0:ba:61:34:5d:f9:6c:a3:b7:
+                    e3:16:0e:90:35:9e:05:15:99:32:ff:50:de:b5:e0:
+                    66:88:e6:d5:0b:ae:16:a9:91:f5:86:c4:23:c9:7e:
+                    f1:9d:2b:86:43:e6:fb:c1:a5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        49:7b:52:fd:1f:be:ee:30:38:0d:93:6b:07:01:95:14:35:6e:
-        5b:dd:74:9e:a0:a7:1a:bd:a8:cd:35:a9:7f:21:af:d7:a2:0c:
-        69:f9:d4:d0:eb:45:93:e2:48:fd:86:b4:70:fb:b5:dd:e5:48:
-        5f:93:d4:41:7a:cb:a5:73:02:d8:d9:e8:5f:9c:f8:4f:ad:50:
-        fb:88:24:b3:f5:e0:cf:d9:3e:bf:3f:5b:0c:db:a0:20:51:5d:
-        ea:13:0b:5b:44:6d:af:0f:6a:72:b6:25:8c:9f:bd:d0:a9:0e:
-        38:60:39:53:7e:9d:6e:ac:65:21:9a:32:f4:57:65:39:dc:f7:
-        36:9a
+         10:82:e5:2b:f8:67:14:0c:22:0d:f4:4e:17:c5:d5:7f:3d:fa:
+         24:2a:ad:33:47:ff:2a:f5:37:f6:83:81:2f:32:df:01:18:80:
+         7a:00:0b:f5:37:f9:eb:de:b0:38:cc:38:94:94:83:76:38:bb:
+         0e:0a:72:9b:2c:87:ce:8c:46:ef:68:f4:e0:a9:2f:cc:28:53:
+         c3:ac:63:7d:2b:87:fb:76:7b:9e:98:c6:0e:80:9e:80:4e:40:
+         b8:1e:2c:8b:c1:8b:cd:13:58:16:ea:aa:a0:0e:b6:b8:4b:a7:
+         74:a1:0d:d9:41:70:44:1e:19:d2:25:4b:b1:52:65:40:32:b0:
+         5d:3d
 -----BEGIN CERTIFICATE-----
-MIICbjCCAdegAwIBAgIBDzANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEyMRIwEAYJKoZIhvcNAQkBFgN0YTIwHhcNMTEw
-NDExMjIzNzQzWhcNMTQwMTA1MjIzNzQzWjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY3MxX3RhMjEWMBQGCSqGSIb3DQEJARYHY3MxX3RhMjCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA5zoIXdc9yFBDrZKHQFhZXPo0usm9W9ef
-F7hP0hX9htnwOgdIFPPApJ7j7gBFuqreOlxT1g3dRojTthOq7vjAPvrrCm1KDfc5
-If9d3NcTWyrp5MAeMStbAM6wVURyl2YGq0FxBUqDazvPp85dYUM7u2AZxDOsI3Jm
-nelyvr1srSsCAwEAAaMgMB4wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCB4Aw
-DQYJKoZIhvcNAQELBQADgYEASXtS/R++7jA4DZNrBwGVFDVuW910nqCnGr2ozTWp
-fyGv16IMafnU0OtFk+JI/Ya0cPu13eVIX5PUQXrLpXMC2NnoX5z4T61Q+4gks/Xg
-z9k+vz9bDNugIFFd6hMLW0Rtrw9qcrYljJ+90KkOOGA5U36dbqxlIZoy9FdlOdz3
-Npo=
+MIICcDCCAdmgAwIBAgIBDzANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMjESMBAGCSqGSIb3DQEJARYDdGEyMB4XDTEz
+MTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjczFfdGEyMRYwFAYJKoZIhvcNAQkBFgdjczFfdGEyMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+LdGyqjiqwU/z9wfy8zAMbfcT7cPH
+yPiHjeqjSc903TAbH52mjrfr+vX35eAFmuSx7S3u//irI5rzJK2ZJoNN5zW3yLFg
+PQxE6SwkUO6GXPC6YTRd+Wyjt+MWDpA1ngUVmTL/UN614GaI5tULrhapkfWGxCPJ
+fvGdK4ZD5vvBpQIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIH
+gDANBgkqhkiG9w0BAQsFAAOBgQAQguUr+GcUDCIN9E4XxdV/PfokKq0zR/8q9Tf2
+g4EvMt8BGIB6AAv1N/nr3rA4zDiUlIN2OLsOCnKbLIfOjEbvaPTgqS/MKFPDrGN9
+K4f7dnuemMYOgJ6ATkC4HiyLwYvNE1gW6qqgDra4S6d0oQ3ZQXBEHhnSJUuxUmVA
+MrBdPQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/11.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/11.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 17 (0x11)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:44 2011 GMT
-            Not After : Jan  5 22:37:44 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1_ta3/emailAddress=cs1_ch1_ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1_ta3/emailAddress=cs1_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cc:26:a7:16:78:9a:fb:e2:da:da:e3:c4:ef:7e:
-                    cb:5c:21:1c:aa:c1:53:35:df:cc:dc:f5:e2:98:0b:
-                    e6:8e:05:f4:e5:97:28:98:54:95:15:11:c9:1e:97:
-                    ed:ee:f4:49:4e:2f:0a:a2:16:83:0d:f5:49:65:78:
-                    6d:ba:a2:19:1b:74:27:64:1a:22:0b:85:47:d0:e1:
-                    85:25:1e:5c:fd:00:7a:37:9e:7e:83:43:cf:17:4e:
-                    2f:ea:7d:c9:5a:b8:70:7a:82:2c:74:0f:77:47:10:
-                    1a:a4:51:16:08:9e:71:b5:7c:54:53:60:92:a8:0c:
-                    1c:b3:b1:0f:ab:c3:0e:46:c5
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ea:17:76:34:ce:b3:de:ac:50:62:a0:0f:14:50:
+                    89:72:26:d5:a2:97:17:91:eb:df:97:7e:80:ff:69:
+                    8e:01:0a:bb:d1:a1:e0:f3:d2:27:56:c6:2d:0f:b5:
+                    84:e4:70:f3:e1:7e:fc:92:8e:fd:77:48:cb:ac:cd:
+                    bf:f4:aa:fa:29:5f:1b:44:03:cf:fa:6f:6d:ae:db:
+                    61:f1:3e:ef:95:de:41:23:36:a2:3a:e7:67:26:04:
+                    6b:7e:9d:f6:92:5e:5b:4c:ab:0a:aa:cf:99:b4:4c:
+                    54:05:73:81:a3:7b:5d:82:cb:e0:ee:9b:29:29:e6:
+                    fb:dd:93:64:23:13:85:d1:e1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        39:fc:dd:ed:5b:f5:75:d9:01:ed:86:33:11:21:27:c9:ad:78:
-        d3:e7:48:8a:3e:11:71:71:0f:d5:10:5b:5a:f0:16:a2:ac:70:
-        e9:3c:db:b9:30:c0:0d:2e:b4:8a:97:c3:50:d7:00:53:d3:4f:
-        b7:24:ff:38:64:e0:ff:87:01:18:6f:7c:bd:3c:2a:bc:fe:9b:
-        0a:d8:66:ce:9e:4e:fa:4c:5c:b5:62:ae:dc:1b:c4:ef:84:da:
-        45:3f:c2:a9:6d:74:a5:f0:44:7e:14:70:a4:4d:e3:dc:92:bb:
-        49:de:68:35:bb:59:a0:24:ba:d6:89:44:28:6b:b8:69:ca:64:
-        7f:f4
+         60:5d:82:5a:64:28:86:45:51:ab:d5:4c:74:ad:eb:84:37:fa:
+         ed:53:df:29:0d:00:9c:4b:33:f4:25:83:ad:b3:e4:cb:11:b0:
+         6e:92:cd:4f:9d:4b:7d:d0:bb:bc:c5:ef:b1:44:2e:54:e1:5e:
+         68:1f:a9:06:a7:e2:ca:82:f9:ac:e8:14:82:a3:26:03:7b:1b:
+         63:98:4f:bb:c9:5d:d5:79:77:bc:2e:e3:3d:7a:82:79:af:7d:
+         fc:e8:a0:9d:f9:e1:74:6d:e6:b9:47:84:19:dd:3f:43:51:8d:
+         9b:c1:27:9e:b7:c7:6b:e2:1f:77:29:bb:5f:a6:16:bf:d0:fd:
+         5a:c2
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBETANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDRaFw0xNDAxMDUyMjM3NDRaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMwmpxZ4mvvi
-2trjxO9+y1whHKrBUzXfzNz14pgL5o4F9OWXKJhUlRURyR6X7e70SU4vCqIWgw31
-SWV4bbqiGRt0J2QaIguFR9DhhSUeXP0AejeefoNDzxdOL+p9yVq4cHqCLHQPd0cQ
-GqRRFgiecbV8VFNgkqgMHLOxD6vDDkbFAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBADn83e1b9XXZAe2GMxEh
-J8mteNPnSIo+EXFxD9UQW1rwFqKscOk827kwwA0utIqXw1DXAFPTT7ck/zhk4P+H
-ARhvfL08Krz+mwrYZs6eTvpMXLVirtwbxO+E2kU/wqltdKXwRH4UcKRN49ySu0ne
-aDW7WaAkutaJRChruGnKZH/0
+MIICgDCCAemgAwIBAgIBETANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczFfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA6hd2NM6z
+3qxQYqAPFFCJcibVopcXkevfl36A/2mOAQq70aHg89InVsYtD7WE5HDz4X78ko79
+d0jLrM2/9Kr6KV8bRAPP+m9trtth8T7vld5BIzaiOudnJgRrfp32kl5bTKsKqs+Z
+tExUBXOBo3tdgsvg7pspKeb73ZNkIxOF0eECAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAYF2CWmQohkVRq9VM
+dK3rhDf67VPfKQ0AnEsz9CWDrbPkyxGwbpLNT51LfdC7vMXvsUQuVOFeaB+pBqfi
+yoL5rOgUgqMmA3sbY5hPu8ld1Xl3vC7jPXqCea99/OignfnhdG3muUeEGd0/Q1GN
+m8EnnrfHa+Ifdym7X6YWv9D9WsI=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/12.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/12.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 18 (0x12)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:44 2011 GMT
-            Not After : Jan  5 22:37:44 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs2_ch1_ta3/emailAddress=cs2_ch1_ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs2_ch1_ta3/emailAddress=cs2_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c5:b6:f8:33:c7:cd:e9:6d:d9:aa:77:60:23:86:
-                    71:56:dc:22:a3:cf:36:d7:b3:59:f7:5d:ae:82:ed:
-                    3f:17:12:62:09:3e:3e:ec:fa:a6:92:df:05:ce:9a:
-                    a2:6d:93:b9:7e:16:f9:c5:b3:83:1d:9a:96:6a:1b:
-                    35:df:f6:b8:82:55:45:5b:43:0a:71:66:4f:bc:df:
-                    00:13:25:22:df:79:76:b6:98:42:25:b2:a1:5c:47:
-                    72:7b:96:9f:65:3f:37:02:97:29:16:9c:75:22:7b:
-                    5d:31:53:80:0a:eb:cc:73:13:da:8e:61:f5:ca:f7:
-                    af:fc:53:cd:b9:11:95:3c:3f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:98:97:30:92:90:4d:45:5a:0c:e2:6f:fb:25:9e:
+                    72:7f:56:64:f5:64:f5:b2:5b:85:27:b7:ad:fa:24:
+                    d7:54:00:1d:5c:4d:c2:92:81:76:f1:37:49:14:b7:
+                    9d:8c:fb:96:69:2d:11:32:6a:19:eb:eb:eb:27:a3:
+                    be:1f:00:29:c8:ba:d6:ca:97:df:e0:83:68:51:9c:
+                    81:f5:63:e0:69:39:1a:fe:5e:af:c3:af:b6:23:b8:
+                    aa:b4:65:c7:f4:7e:63:db:ff:1b:7e:ce:ed:60:7d:
+                    be:2f:fd:05:ee:d0:cd:72:7e:91:93:69:82:29:8f:
+                    a8:a8:53:b1:d7:ea:83:df:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -29,27 +29,27 @@
                 <EMPTY>
 
     Signature Algorithm: sha256WithRSAEncryption
-        2e:40:56:59:03:e3:5b:62:73:0c:57:dc:12:d8:4b:97:00:8b:
-        66:c8:a6:10:29:78:3b:7a:52:fb:f9:63:94:44:b2:1b:eb:3f:
-        13:e9:40:9b:24:01:38:f6:b2:f7:99:1e:d9:17:57:e3:df:ff:
-        01:8b:00:02:7e:a0:f5:e5:3a:f0:72:4c:72:6f:76:07:26:ac:
-        97:6d:c2:12:e1:64:99:29:ff:25:fd:21:c7:43:41:87:c5:bb:
-        ce:06:c4:b1:f9:64:ad:e8:d8:90:ac:89:26:8a:1e:a3:d4:45:
-        2d:8a:27:a4:88:8c:f3:97:5f:f7:82:d7:c4:76:98:f5:20:af:
-        5e:23
+         53:10:01:62:32:bd:ff:7d:30:a5:09:5f:77:44:af:0d:81:d4:
+         4b:c8:f6:fe:ba:38:65:9f:b6:55:77:7a:36:86:42:64:1a:89:
+         66:4f:1d:f5:0a:65:1e:06:2c:07:46:b3:57:ba:98:1d:1c:46:
+         52:08:65:32:70:9d:98:3e:e9:6b:be:da:7e:91:54:60:52:ad:
+         0e:90:3f:ee:7c:2a:03:84:8f:4f:e4:1b:d3:4f:a8:d3:c2:29:
+         74:cc:ac:87:81:7e:38:07:cd:d8:5f:20:00:b6:e4:ea:c1:e5:
+         06:77:19:da:9c:3b:43:7f:91:ab:8c:f1:b7:03:09:09:0a:85:
+         de:91
 -----BEGIN CERTIFICATE-----
-MIICfDCCAeWgAwIBAgIBEjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDRaFw0xNDAxMDUyMjM3NDRaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczJfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3MyX2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMW2+DPHzelt
-2ap3YCOGcVbcIqPPNtezWfddroLtPxcSYgk+Puz6ppLfBc6aom2TuX4W+cWzgx2a
-lmobNd/2uIJVRVtDCnFmT7zfABMlIt95draYQiWyoVxHcnuWn2U/NwKXKRacdSJ7
-XTFTgArrzHMT2o5h9cr3r/xTzbkRlTw/AgMBAAGjHjAcMAwGA1UdEwEB/wQCMAAw
-DAYDVR0SAQH/BAIwADANBgkqhkiG9w0BAQsFAAOBgQAuQFZZA+NbYnMMV9wS2EuX
-AItmyKYQKXg7elL7+WOURLIb6z8T6UCbJAE49rL3mR7ZF1fj3/8BiwACfqD15Trw
-ckxyb3YHJqyXbcIS4WSZKf8l/SHHQ0GHxbvOBsSx+WSt6NiQrIkmih6j1EUtiiek
-iIzzl1/3gtfEdpj1IK9eIw==
+MIICfjCCAeegAwIBAgIBEjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMl9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczJfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAmJcwkpBN
+RVoM4m/7JZ5yf1Zk9WT1sluFJ7et+iTXVAAdXE3CkoF28TdJFLedjPuWaS0RMmoZ
+6+vrJ6O+HwApyLrWypff4INoUZyB9WPgaTka/l6vw6+2I7iqtGXH9H5j2/8bfs7t
+YH2+L/0F7tDNcn6Rk2mCKY+oqFOx1+qD34kCAwEAAaMeMBwwDAYDVR0TAQH/BAIw
+ADAMBgNVHRIBAf8EAjAAMA0GCSqGSIb3DQEBCwUAA4GBAFMQAWIyvf99MKUJX3dE
+rw2B1EvI9v66OGWftlV3ejaGQmQaiWZPHfUKZR4GLAdGs1e6mB0cRlIIZTJwnZg+
+6Wu+2n6RVGBSrQ6QP+58KgOEj0/kG9NPqNPCKXTMrIeBfjgHzdhfIAC25OrB5QZ3
+GdqcO0N/kauM8bcDCQkKhd6R
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/13.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/13.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 19 (0x13)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
             Not Before: Jan  1 01:01:01 2009 GMT
             Not After : Jan  2 01:01:01 2009 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs3_ch1_ta3/emailAddress=cs3_ch1_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs3_ch1_ta3/emailAddress=cs3_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b7:60:7b:08:47:0a:05:c1:6c:80:9a:84:e2:de:
-                    c6:11:65:df:a6:c7:30:bb:37:e9:ae:9e:37:9d:f9:
-                    f3:3a:18:38:ee:be:e0:fb:6b:84:fb:93:2c:5b:1e:
-                    9f:7a:78:da:26:28:c7:fb:6e:9f:2e:8f:f9:5a:1c:
-                    e8:0b:e0:f1:5c:45:f6:a0:0e:58:01:4e:86:20:bd:
-                    ff:7d:0c:41:4b:b2:50:5c:78:89:3c:4a:83:cf:59:
-                    9f:e4:17:27:de:ea:aa:ff:c8:19:f5:b7:c3:67:bd:
-                    5e:78:79:8e:46:33:1a:ef:36:40:f8:f2:7e:bc:ca:
-                    54:85:57:56:e5:e7:b8:52:4d
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d3:01:be:68:e6:07:6b:d4:f1:10:9e:99:93:cb:
+                    79:4d:15:d1:39:fb:b2:de:74:10:57:84:c3:ab:3e:
+                    25:cc:f4:7e:66:1e:f2:fa:f2:32:b4:c5:6c:80:e7:
+                    31:80:1a:96:79:96:83:b5:44:58:f1:2a:9b:3b:c0:
+                    0d:42:00:27:49:bf:6e:0a:d6:8b:b4:20:5c:a7:3d:
+                    11:74:25:95:08:45:bb:c5:ca:07:42:a3:e8:19:36:
+                    e1:62:42:53:bc:2f:1f:a8:10:31:ee:40:7d:ec:b5:
+                    54:04:c4:63:e8:43:12:09:7d:1e:99:60:f6:db:ec:
+                    65:d3:13:bb:36:be:e2:d8:ed
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        27:40:ae:0c:a2:ad:5d:28:30:53:fe:e4:35:31:02:e4:1a:ef:
-        6d:ec:95:1e:3e:a0:15:15:32:e8:88:46:68:45:a7:60:9f:93:
-        79:ab:ef:78:f6:2c:23:ef:a1:f4:71:b3:9a:f1:c6:4d:ac:34:
-        a1:24:d8:4e:38:36:3c:bb:90:30:9b:e4:b3:8e:55:e0:06:c4:
-        5a:c4:f1:23:90:fd:b3:ef:40:dd:4d:4c:2b:55:50:11:64:6b:
-        64:3f:e3:67:3c:6c:c1:da:55:6c:7d:8d:87:18:40:6a:cb:13:
-        17:3b:75:35:09:71:0b:e9:c4:7e:b1:a1:db:80:78:93:b3:5b:
-        d0:4e
+         5f:64:85:36:62:d2:01:78:45:6d:63:d5:c8:d8:01:cb:39:f7:
+         0f:75:61:87:9c:d0:2b:9d:3f:0f:56:4d:8c:7d:06:69:eb:60:
+         3a:ca:ed:91:39:ba:e8:8b:a9:42:58:33:32:e3:08:ac:a9:ca:
+         76:ef:37:39:74:46:2d:ea:54:e0:0d:e5:62:18:48:5e:e6:8b:
+         6c:6c:25:0c:8d:61:98:f6:7a:ae:b6:73:cb:8a:2d:27:a5:c7:
+         cf:5e:36:a5:2f:10:74:41:b0:93:6d:21:e2:52:c2:d5:88:6e:
+         ff:91:04:eb:92:8b:62:3a:81:a8:88:6c:10:67:4e:a2:6a:2c:
+         17:ec
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBEzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0wOTAxMDEwMTAxMDFaFw0wOTAxMDIwMTAxMDFaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczNfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3MzX2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALdgewhHCgXB
-bICahOLexhFl36bHMLs36a6eN5358zoYOO6+4PtrhPuTLFsen3p42iYox/tuny6P
-+Voc6Avg8VxF9qAOWAFOhiC9/30MQUuyUFx4iTxKg89Zn+QXJ97qqv/IGfW3w2e9
-Xnh5jkYzGu82QPjyfrzKVIVXVuXnuFJNAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBACdArgyirV0oMFP+5DUx
-AuQa723slR4+oBUVMuiIRmhFp2Cfk3mr73j2LCPvofRxs5rxxk2sNKEk2E44Njy7
-kDCb5LOOVeAGxFrE8SOQ/bPvQN1NTCtVUBFka2Q/42c8bMHaVWx9jYcYQGrLExc7
-dTUJcQvpxH6xoduAeJOzW9BO
+MIICgDCCAemgAwIBAgIBEzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMDkwMTAxMDEwMTAxWhcNMDkwMTAyMDEwMTAxWjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzM19jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczNfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA0wG+aOYH
+a9TxEJ6Zk8t5TRXROfuy3nQQV4TDqz4lzPR+Zh7y+vIytMVsgOcxgBqWeZaDtURY
+8SqbO8ANQgAnSb9uCtaLtCBcpz0RdCWVCEW7xcoHQqPoGTbhYkJTvC8fqBAx7kB9
+7LVUBMRj6EMSCX0emWD22+xl0xO7Nr7i2O0CAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAX2SFNmLSAXhFbWPV
+yNgByzn3D3Vhh5zQK50/D1ZNjH0GaetgOsrtkTm66IupQlgzMuMIrKnKdu83OXRG
+LepU4A3lYhhIXuaLbGwlDI1hmPZ6rrZzy4otJ6XHz142pS8QdEGwk20h4lLC1Yhu
+/5EE65KLYjqBqIhsEGdOomosF+w=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/14.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/14.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 20 (0x14)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
             Not Before: Jan  1 01:01:01 2035 GMT
             Not After : Jan  2 01:01:01 2035 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs4_ch1_ta3/emailAddress=cs4_ch1_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs4_ch1_ta3/emailAddress=cs4_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d7:42:45:a6:d0:f4:a9:54:6d:c8:4d:42:e8:05:
-                    a4:33:25:f1:b7:eb:20:df:33:26:6e:ca:30:63:57:
-                    df:d3:a9:02:b0:29:f3:cb:7b:64:77:34:7e:1d:c7:
-                    a8:2c:ca:73:23:22:43:71:6c:33:9e:89:0e:89:ce:
-                    6d:db:2b:f3:5a:af:e3:dc:f3:1c:48:64:60:5d:57:
-                    e6:17:6b:e6:61:4b:cb:e0:a9:e3:1c:aa:f6:70:34:
-                    b4:8b:d8:19:e6:26:06:60:24:82:c6:d8:5d:87:de:
-                    99:2b:0d:78:db:92:f2:c2:24:65:8b:f8:07:b6:fe:
-                    17:8d:bb:4f:c7:c0:ae:24:c9
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cb:2c:5a:74:59:a7:60:a1:a4:1b:36:25:92:c1:
+                    aa:39:3f:7c:17:de:d0:36:c3:1c:bf:c6:25:30:e0:
+                    10:7b:d7:76:7d:de:d6:71:6c:81:df:95:22:a4:dd:
+                    80:55:2a:5e:fd:82:df:94:a0:aa:f9:8e:b1:e9:20:
+                    be:04:26:18:17:e8:04:9e:af:67:ca:57:8e:f6:92:
+                    2c:6e:76:02:4b:84:d8:2b:78:2b:32:74:8e:4c:ea:
+                    ab:3c:61:62:cb:95:af:5c:77:74:19:b2:0e:4f:49:
+                    63:8a:72:ac:c1:77:6a:42:ed:91:6f:be:a4:df:c8:
+                    0b:1b:b4:32:18:46:dc:b9:f5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        b9:09:ff:d1:80:e1:9e:05:e8:27:40:d0:d3:76:d7:b6:72:cd:
-        4a:e4:d8:b7:e2:14:90:3a:74:61:b3:c8:3c:7c:bd:2e:9c:9d:
-        62:0d:cd:9b:e9:36:ba:aa:87:f7:c7:e4:3a:6c:5d:d9:99:d5:
-        33:a0:5a:3f:fd:5e:06:62:11:ad:ca:33:9d:0a:59:8a:a9:0e:
-        6e:4a:d8:6f:da:ff:96:89:e3:8a:3b:5e:a6:b4:8c:93:ff:70:
-        4d:d2:32:f8:44:c0:ff:84:65:b0:1f:59:4a:2c:10:d7:5e:a6:
-        ed:5b:a8:e2:eb:42:e0:0d:7b:f5:43:ca:1a:9a:cd:df:e6:f8:
-        4d:d5
+         40:91:53:35:b9:b9:31:8d:16:de:85:84:2f:b4:5e:35:7a:da:
+         a8:31:06:29:14:94:80:ee:0a:55:7d:8f:02:2f:74:f4:94:5e:
+         00:d1:c7:8b:2a:71:21:8d:3c:d6:f2:b6:50:84:fe:45:f1:56:
+         bd:36:68:72:b7:73:c6:b7:38:3b:fe:be:22:af:77:43:0d:32:
+         f7:7e:ce:2e:e9:1f:24:5a:b9:bb:ae:b3:fd:cd:ea:87:1a:43:
+         7b:22:71:2f:6b:16:74:e6:73:6b:af:38:17:c6:a4:c6:8c:01:
+         a9:c4:76:be:a3:02:8b:47:35:e1:53:c8:27:87:1e:5c:ad:cb:
+         93:4e
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBFDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0zNTAxMDEwMTAxMDFaFw0zNTAxMDIwMTAxMDFaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczRfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M0X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANdCRabQ9KlU
-bchNQugFpDMl8bfrIN8zJm7KMGNX39OpArAp88t7ZHc0fh3HqCzKcyMiQ3FsM56J
-DonObdsr81qv49zzHEhkYF1X5hdr5mFLy+Cp4xyq9nA0tIvYGeYmBmAkgsbYXYfe
-mSsNeNuS8sIkZYv4B7b+F427T8fAriTJAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBALkJ/9GA4Z4F6CdA0NN2
-17ZyzUrk2LfiFJA6dGGzyDx8vS6cnWINzZvpNrqqh/fH5DpsXdmZ1TOgWj/9XgZi
-Ea3KM50KWYqpDm5K2G/a/5aJ44o7Xqa0jJP/cE3SMvhEwP+EZbAfWUosENdepu1b
-qOLrQuANe/VDyhqazd/m+E3V
+MIICgDCCAemgAwIBAgIBFDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMzUwMTAxMDEwMTAxWhcNMzUwMTAyMDEwMTAxWjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzNF9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczRfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAyyxadFmn
+YKGkGzYlksGqOT98F97QNsMcv8YlMOAQe9d2fd7WcWyB35UipN2AVSpe/YLflKCq
++Y6x6SC+BCYYF+gEnq9nyleO9pIsbnYCS4TYK3grMnSOTOqrPGFiy5WvXHd0GbIO
+T0ljinKswXdqQu2Rb76k38gLG7QyGEbcufUCAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAQJFTNbm5MY0W3oWE
+L7ReNXraqDEGKRSUgO4KVX2PAi909JReANHHiypxIY081vK2UIT+RfFWvTZocrdz
+xrc4O/6+Iq93Qw0y937OLukfJFq5u66z/c3qhxpDeyJxL2sWdOZza684F8akxowB
+qcR2vqMCi0c14VPIJ4ceXK3Lk04=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/15.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/15.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 21 (0x15)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:45 2011 GMT
-            Not After : Jan  5 22:37:45 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs5_ch1_ta3/emailAddress=cs5_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs5_ch1_ta3/emailAddress=cs5_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c0:be:66:e6:55:cb:9e:d6:d2:7b:d3:b2:34:fb:
-                    c9:74:d5:30:4f:62:1c:68:bd:13:97:08:b7:8c:b6:
-                    4e:dd:7f:98:a5:e2:2f:2e:9c:74:92:01:43:62:8e:
-                    9c:62:23:3e:b6:e4:e2:18:2b:3f:ae:fb:17:e7:d8:
-                    c4:28:27:27:d9:3e:5c:d1:8f:51:b7:10:4c:44:f6:
-                    bb:6b:24:7c:2e:09:bc:fb:8a:af:fa:e4:ce:94:2f:
-                    27:cd:3d:e7:be:93:4b:62:37:f5:f1:a8:8e:7e:76:
-                    92:62:7b:02:41:98:c2:f6:ff:68:8e:d2:1d:fb:9e:
-                    f1:45:f5:6a:9c:8d:28:23:c1
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ea:23:95:11:2c:b5:2d:49:c5:10:77:74:82:98:
+                    da:5f:58:1f:2b:40:6e:1b:2e:d8:4f:30:07:6b:a2:
+                    ae:9f:f7:ed:8d:2d:b4:b3:68:48:ec:60:72:a2:fb:
+                    8b:7e:62:11:90:79:96:f9:ee:82:78:3f:09:22:2b:
+                    03:45:af:9e:ca:7e:3c:80:4f:ad:59:77:85:c5:e7:
+                    6b:4a:0b:a2:6b:4b:c5:e7:f9:38:81:64:05:ea:cd:
+                    76:9c:bf:eb:51:aa:29:6c:c1:3e:98:c6:ac:49:a2:
+                    ac:32:60:78:d8:ff:c6:79:f8:a5:a6:78:61:24:9a:
+                    27:26:2e:06:3a:19:8e:54:d1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: 
                 Encipher Only
     Signature Algorithm: sha256WithRSAEncryption
-        26:c1:64:ae:88:f7:19:f6:4f:f6:89:c9:d4:4e:46:cc:8f:51:
-        d3:b0:1c:d5:54:08:b0:5c:a7:51:48:24:be:e5:9f:d1:79:8b:
-        fb:92:84:aa:92:c6:2f:b1:76:e2:f2:21:f7:f1:5d:05:c3:5c:
-        01:90:20:8c:46:9e:a2:b9:dd:71:4f:a4:b9:3a:15:d3:74:98:
-        59:bf:f8:44:c5:a4:99:67:01:e7:d6:52:8d:2f:02:3a:f4:e8:
-        c8:b3:9c:f3:35:18:4e:41:03:a7:b6:b3:5c:84:61:43:6b:95:
-        b4:84:d1:c1:72:29:ac:d5:6f:e4:6c:f1:86:b6:eb:09:77:1e:
-        89:92
+         80:7c:f9:bc:bd:15:b1:9d:75:d1:82:b5:42:79:d3:5e:2c:e3:
+         c4:73:ed:3b:3c:8a:83:9c:51:e9:1f:93:75:1f:81:01:11:f9:
+         fd:a8:56:0f:cf:d3:a9:38:26:e3:f0:78:79:75:ef:97:7b:01:
+         0b:b7:37:65:6c:93:76:07:ec:fa:f5:1e:2d:6a:3b:6d:15:fc:
+         41:6f:fb:17:52:be:cc:a8:95:da:be:3b:6d:d8:5d:42:10:aa:
+         20:9e:8e:c5:33:ed:7b:8a:f1:e5:e3:45:21:05:2e:77:3b:c9:
+         66:46:25:37:e4:5c:b0:f5:29:0a:be:0d:bc:c8:e9:d8:fc:31:
+         22:e3
 -----BEGIN CERTIFICATE-----
-MIICezCCAeSgAwIBAgIBFTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDVaFw0xNDAxMDUyMjM3NDVaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczVfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M1X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMC+ZuZVy57W
-0nvTsjT7yXTVME9iHGi9E5cIt4y2Tt1/mKXiLy6cdJIBQ2KOnGIjPrbk4hgrP677
-F+fYxCgnJ9k+XNGPUbcQTET2u2skfC4JvPuKr/rkzpQvJ809576TS2I39fGojn52
-kmJ7AkGYwvb/aI7SHfue8UX1apyNKCPBAgMBAAGjHTAbMAwGA1UdEwEB/wQCMAAw
-CwYDVR0PBAQDAgABMA0GCSqGSIb3DQEBCwUAA4GBACbBZK6I9xn2T/aJydRORsyP
-UdOwHNVUCLBcp1FIJL7ln9F5i/uShKqSxi+xduLyIffxXQXDXAGQIIxGnqK53XFP
-pLk6FdN0mFm/+ETFpJlnAefWUo0vAjr06MiznPM1GE5BA6e2s1yEYUNrlbSE0cFy
-KazVb+Rs8Ya26wl3HomS
+MIICfTCCAeagAwIBAgIBFTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzNV9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczVfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA6iOVESy1
+LUnFEHd0gpjaX1gfK0BuGy7YTzAHa6Kun/ftjS20s2hI7GByovuLfmIRkHmW+e6C
+eD8JIisDRa+eyn48gE+tWXeFxedrSguia0vF5/k4gWQF6s12nL/rUaopbME+mMas
+SaKsMmB42P/GefilpnhhJJonJi4GOhmOVNECAwEAAaMdMBswDAYDVR0TAQH/BAIw
+ADALBgNVHQ8EBAMCAAEwDQYJKoZIhvcNAQELBQADgYEAgHz5vL0VsZ110YK1QnnT
+XizjxHPtOzyKg5xR6R+TdR+BARH5/ahWD8/TqTgm4/B4eXXvl3sBC7c3ZWyTdgfs
++vUeLWo7bRX8QW/7F1K+zKiV2r47bdhdQhCqIJ6OxTPte4rx5eNFIQUudzvJZkYl
+N+RcsPUpCr4NvMjp2PwxIuM=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/16.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/16.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 22 (0x16)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:45 2011 GMT
-            Not After : Jan  5 22:37:45 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs6_ch1_ta3/emailAddress=cs6_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs6_ch1_ta3/emailAddress=cs6_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c7:77:32:f6:35:5a:29:de:dc:61:89:a9:7e:d3:
-                    4f:ac:a1:db:f1:7f:58:1c:d3:46:a8:eb:61:62:80:
-                    d0:cf:40:6b:a4:39:ac:fb:f3:e4:a2:47:53:78:d4:
-                    cd:5a:5f:b1:c0:e8:2c:81:2d:00:98:d5:2f:6b:e9:
-                    e7:85:e6:0e:1e:46:d6:22:b9:f3:a7:e0:6c:18:ea:
-                    42:33:cd:c0:9c:e0:98:ec:29:67:39:c4:a3:f7:69:
-                    8b:04:66:f5:a2:3c:08:1b:24:e5:ba:d4:57:5b:14:
-                    f1:f2:c8:2b:0f:22:ae:6e:d1:ca:85:01:e6:75:82:
-                    03:df:7a:ed:96:8a:64:2f:5f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:a5:2e:d6:bd:fc:2f:5b:4c:b8:91:90:8e:f6:3f:
+                    bb:55:28:8d:4f:9d:47:70:ed:3e:a1:bd:70:42:47:
+                    b0:41:09:7b:87:4f:eb:1a:45:9f:09:6d:0a:8c:53:
+                    73:a3:3d:fb:3f:dc:67:f4:03:d3:7c:51:15:f3:ab:
+                    6c:2c:39:d0:a7:4e:c2:3f:5c:d2:d8:87:f1:03:3b:
+                    eb:75:9e:9e:66:d5:3d:d5:e5:6d:32:92:ad:05:b8:
+                    c2:3b:48:e5:72:b4:9d:c9:b7:42:4f:d7:b4:a5:8c:
+                    a4:88:76:df:11:3e:b1:5c:a2:bd:7d:56:f8:c8:76:
+                    00:c4:88:64:0f:36:7e:cb:23
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Encipher Only
     Signature Algorithm: sha256WithRSAEncryption
-        7b:52:05:af:d4:77:41:4d:3f:cf:39:bd:33:a2:82:96:38:df:
-        a5:f7:ab:44:a3:b4:fc:13:ad:f5:d0:48:81:34:10:12:e9:c7:
-        47:3f:13:1d:0a:20:8c:a7:df:23:a1:f5:5c:05:58:7a:ff:58:
-        61:57:25:2c:36:22:10:e6:a4:d4:e3:f4:ad:b3:35:a9:91:93:
-        24:52:f6:28:4c:90:12:98:31:9b:31:8c:64:2f:79:df:d1:f1:
-        6e:d2:43:84:fe:bf:e5:ea:a9:74:6c:ce:cd:44:89:6b:df:bf:
-        7c:dd:77:24:0b:18:07:42:89:41:b3:2c:60:30:db:75:05:82:
-        15:85
+         48:51:71:0e:8c:c2:42:98:91:34:dc:a9:8a:92:98:18:ce:30:
+         fd:61:11:66:9a:87:7a:7b:a6:dd:09:7f:36:9c:7d:d8:19:b6:
+         ab:5d:6a:22:b3:4a:00:45:66:1f:ed:d5:1f:b4:cc:c7:a5:07:
+         5f:6f:35:2c:bc:52:1a:c9:c0:96:56:fd:82:33:50:7b:2e:43:
+         79:2c:cb:e4:e9:22:55:0a:09:96:05:f7:96:e1:22:95:3a:8e:
+         66:b1:21:aa:88:f1:21:4a:20:ae:08:b1:27:7e:f6:6b:be:55:
+         68:0b:d0:d6:77:30:78:92:75:38:d2:ab:31:79:8e:5d:71:a3:
+         b3:2b
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBFjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDVaFw0xNDAxMDUyMjM3NDVaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczZfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M2X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMd3MvY1Wine
-3GGJqX7TT6yh2/F/WBzTRqjrYWKA0M9Aa6Q5rPvz5KJHU3jUzVpfscDoLIEtAJjV
-L2vp54XmDh5G1iK586fgbBjqQjPNwJzgmOwpZznEo/dpiwRm9aI8CBsk5brUV1sU
-8fLIKw8irm7RyoUB5nWCA9967ZaKZC9fAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgABMA0GCSqGSIb3DQEBCwUAA4GBAHtSBa/Ud0FNP885vTOi
-gpY436X3q0SjtPwTrfXQSIE0EBLpx0c/Ex0KIIyn3yOh9VwFWHr/WGFXJSw2IhDm
-pNTj9K2zNamRkyRS9ihMkBKYMZsxjGQved/R8W7SQ4T+v+XqqXRszs1EiWvfv3zd
-dyQLGAdCiUGzLGAw23UFghWF
+MIICgDCCAemgAwIBAgIBFjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzNl9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczZfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEApS7Wvfwv
+W0y4kZCO9j+7VSiNT51HcO0+ob1wQkewQQl7h0/rGkWfCW0KjFNzoz37P9xn9APT
+fFEV86tsLDnQp07CP1zS2IfxAzvrdZ6eZtU91eVtMpKtBbjCO0jlcrSdybdCT9e0
+pYykiHbfET6xXKK9fVb4yHYAxIhkDzZ+yyMCAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCAAEwDQYJKoZIhvcNAQELBQADgYEASFFxDozCQpiRNNyp
+ipKYGM4w/WERZpqHenum3Ql/Npx92Bm2q11qIrNKAEVmH+3VH7TMx6UHX281LLxS
+GsnAllb9gjNQey5DeSzL5OkiVQoJlgX3luEilTqOZrEhqojxIUogrgixJ372a75V
+aAvQ1ncweJJ1ONKrMXmOXXGjsys=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/17.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/17.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,51 +2,51 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 23 (0x17)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:46 2011 GMT
-            Not After : Jan  5 22:37:46 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs7_ch1_ta3/emailAddress=cs7_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs7_ch1_ta3/emailAddress=cs7_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c8:97:06:72:77:82:e7:03:53:56:f7:71:5c:f4:
-                    b5:ae:e1:22:08:f7:a7:70:47:2f:ad:6f:af:a9:39:
-                    c3:73:ca:f5:d5:54:e9:3d:46:f8:a4:a1:1a:27:d5:
-                    1a:c6:90:c9:4b:c1:21:32:06:9b:56:d7:23:3c:23:
-                    d9:aa:2a:17:15:61:0c:cc:08:e7:60:af:55:e6:9e:
-                    e2:24:bd:1f:e9:04:e8:09:ed:f4:a3:d8:5e:24:91:
-                    95:3e:9f:7e:f7:64:66:60:08:7d:cf:ac:b6:f4:6b:
-                    72:28:61:8c:dc:51:4d:00:3e:4d:67:70:0e:ae:3c:
-                    37:99:28:47:e7:61:fe:a3:73
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:bc:52:93:cc:6b:6d:63:bb:fe:a2:33:3d:40:a4:
+                    ba:3f:12:4c:72:69:a0:87:80:32:50:47:91:8f:39:
+                    6f:8a:78:78:9a:f6:34:83:2d:7d:6a:19:90:36:9f:
+                    fb:7c:1c:c8:13:f9:13:b2:6a:75:1a:2c:3a:76:2b:
+                    10:d2:f3:90:1f:65:df:65:04:0c:97:a2:fa:43:53:
+                    33:32:f8:8f:f3:30:a7:1c:4a:67:9c:da:81:b8:7a:
+                    55:c4:30:1d:59:5d:f1:0a:bc:b6:52:b3:09:41:24:
+                    1f:30:6b:ed:95:ba:90:cf:0d:af:eb:c7:fb:31:35:
+                    c5:5b:ff:67:9a:8a:1b:34:09
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
     Signature Algorithm: sha256WithRSAEncryption
-        7a:58:f4:9c:bc:64:08:aa:dc:9c:e2:d3:a0:92:cb:1a:b3:75:
-        c9:c7:39:07:84:cb:4a:0f:07:2c:b8:5d:8a:a3:22:69:2e:63:
-        04:d8:16:5f:8d:e8:11:de:fc:f5:df:a3:6c:c9:f0:c2:d7:5d:
-        6c:43:3c:e2:ae:ed:b2:01:cf:e1:77:b3:85:76:bb:76:f7:c9:
-        cd:50:7f:17:b7:82:22:ed:d9:1c:82:bf:da:3f:28:72:c5:45:
-        e3:08:96:ba:45:22:76:bb:b4:9d:f6:e1:a0:64:36:9b:a2:e2:
-        83:64:b1:76:1d:09:2f:6c:4b:a9:9b:00:e3:79:cf:7d:0b:91:
-        b3:95
+         68:79:a6:5a:7f:1d:50:2a:e9:60:26:b2:31:e8:66:e2:c1:5e:
+         12:78:d9:32:fc:0c:07:5d:15:22:f7:f7:22:52:96:0d:35:8e:
+         bd:dd:60:ab:0f:d9:dc:6b:4e:a5:d8:57:83:ff:d1:60:a5:c1:
+         c7:0c:49:c3:05:c4:9a:9f:87:ba:ff:47:9f:51:dd:04:2a:90:
+         53:b1:f9:8d:fa:34:97:a2:4b:4b:70:84:67:1d:de:f4:e6:e6:
+         bd:0e:c4:24:8a:e2:8b:fa:ac:06:2c:09:ed:bd:7d:b3:1e:df:
+         a9:be:4c:c5:49:c1:72:bd:d8:a7:3f:25:89:15:3f:1c:19:e6:
+         84:15
 -----BEGIN CERTIFICATE-----
-MIICbjCCAdegAwIBAgIBFzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDZaFw0xNDAxMDUyMjM3NDZaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczdfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M3X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMiXBnJ3gucD
-U1b3cVz0ta7hIgj3p3BHL61vr6k5w3PK9dVU6T1G+KShGifVGsaQyUvBITIGm1bX
-Izwj2aoqFxVhDMwI52CvVeae4iS9H+kE6Ant9KPYXiSRlT6ffvdkZmAIfc+stvRr
-cihhjNxRTQA+TWdwDq48N5koR+dh/qNzAgMBAAGjEDAOMAwGA1UdEwEB/wQCMAAw
-DQYJKoZIhvcNAQELBQADgYEAelj0nLxkCKrcnOLToJLLGrN1ycc5B4TLSg8HLLhd
-iqMiaS5jBNgWX43oEd789d+jbMnwwtddbEM84q7tsgHP4XezhXa7dvfJzVB/F7eC
-Iu3ZHIK/2j8ocsVF4wiWukUidru0nfbhoGQ2m6Lig2Sxdh0JL2xLqZsA43nPfQuR
-s5U=
+MIICcDCCAdmgAwIBAgIBFzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzN19jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczdfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAvFKTzGtt
+Y7v+ojM9QKS6PxJMcmmgh4AyUEeRjzlvinh4mvY0gy19ahmQNp/7fBzIE/kTsmp1
+Giw6disQ0vOQH2XfZQQMl6L6Q1MzMviP8zCnHEpnnNqBuHpVxDAdWV3xCry2UrMJ
+QSQfMGvtlbqQzw2v68f7MTXFW/9nmoobNAkCAwEAAaMQMA4wDAYDVR0TAQH/BAIw
+ADANBgkqhkiG9w0BAQsFAAOBgQBoeaZafx1QKulgJrIx6GbiwV4SeNky/AwHXRUi
+9/ciUpYNNY693WCrD9nca06l2FeD/9FgpcHHDEnDBcSan4e6/0efUd0EKpBTsfmN
++jSXoktLcIRnHd705ua9DsQkiuKL+qwGLAntvX2zHt+pvkzFScFyvdinPyWJFT8c
+GeaEFQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/18.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/18.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 24 (0x18)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:46 2011 GMT
-            Not After : Jan  5 22:37:46 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c4:da:c4:d3:72:c2:65:ec:7f:b8:41:e3:c7:14:
-                    83:bb:fc:9e:d5:87:15:5f:eb:52:da:cb:f4:c7:db:
-                    2f:58:65:01:0e:0e:d5:27:cf:c5:e5:2c:ce:99:7f:
-                    0f:48:8c:4f:54:47:6b:4b:5e:90:3f:95:96:60:b8:
-                    8e:39:1f:a9:cc:38:b6:9f:21:6d:4e:69:2e:14:c5:
-                    71:fe:e1:e1:44:24:d4:74:45:4a:9f:88:64:36:96:
-                    f7:ba:74:1e:88:f9:6d:ac:e9:25:f0:74:58:c6:13:
-                    b9:05:ab:fa:0e:5c:77:fc:a1:3d:48:9c:78:90:f8:
-                    67:41:99:7c:bf:45:6a:67:ef
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:de:50:67:d6:8e:a7:53:1b:73:03:fe:c7:ef:59:
+                    82:0c:d7:74:ef:ad:21:33:68:78:46:27:7f:f1:0c:
+                    76:67:8d:be:ba:f8:36:00:c7:1b:eb:82:1f:70:58:
+                    71:02:db:6a:9e:11:37:a8:b0:28:27:b4:9f:be:1d:
+                    2a:fb:67:4f:a1:3a:ce:e2:70:d2:d8:81:eb:92:5a:
+                    c6:3f:97:ec:2c:49:b5:5b:8a:e1:ea:60:35:28:6a:
+                    e8:37:b6:7a:1e:83:36:32:52:3f:c0:a5:b2:74:19:
+                    b1:32:34:66:da:f8:fc:e1:92:42:b2:a6:87:48:56:
+                    37:66:e3:3c:6f:58:73:26:a1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        1d:d4:91:76:de:42:bb:70:5b:57:39:fe:bd:50:85:66:ee:7c:
-        c7:7c:7c:00:18:71:73:50:5a:70:04:43:ca:81:23:2a:42:c8:
-        8e:34:91:b9:8b:b8:f7:37:b0:08:3f:ee:b2:5f:a2:fd:03:b1:
-        59:d1:ff:cf:b6:73:f6:82:51:0a:73:a0:43:79:36:a2:c4:fb:
-        98:6c:64:bc:3a:f5:b9:c5:e7:c1:cf:76:fb:73:23:d3:47:e2:
-        a9:19:60:08:a7:c8:1b:c3:73:24:f9:8d:dc:bf:ae:5d:5b:fe:
-        48:d0:06:a7:33:e5:d8:db:4c:c9:82:a0:32:c1:1e:45:67:67:
-        ce:54
+         55:cb:0c:50:d9:e0:bd:c9:b2:60:0f:0d:3e:ac:e3:e0:e2:2f:
+         02:a9:5b:5b:2d:4c:bb:55:e0:5a:83:63:46:46:92:cc:1f:f3:
+         8b:24:de:6f:9e:c6:b5:f5:ca:57:1d:07:d4:97:4e:d3:9b:a9:
+         17:56:6c:fa:57:7f:cd:a4:55:ab:64:b7:57:b4:59:a4:be:d6:
+         8c:6d:70:8a:4f:f4:13:20:e1:70:89:18:98:77:e9:91:87:a9:
+         01:66:07:43:df:df:4d:ac:e1:1b:b1:c5:d8:20:3f:fc:fd:5f:
+         1d:fc:61:8e:43:b9:ca:ed:db:83:88:e2:0f:4a:a9:f2:20:ee:
+         e6:54
 -----BEGIN CERTIFICATE-----
-MIICgTCCAeqgAwIBAgIBGDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDZaFw0xNDAxMDUyMjM3NDZaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczhfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M4X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMTaxNNywmXs
-f7hB48cUg7v8ntWHFV/rUtrL9MfbL1hlAQ4O1SfPxeUszpl/D0iMT1RHa0tekD+V
-lmC4jjkfqcw4tp8hbU5pLhTFcf7h4UQk1HRFSp+IZDaW97p0Hoj5bazpJfB0WMYT
-uQWr+g5cd/yhPUiceJD4Z0GZfL9FamfvAgMBAAGjIzAhMA8GA1UdEwEB/wQFMAMB
-Af8wDgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBAB3UkXbeQrtwW1c5
-/r1QhWbufMd8fAAYcXNQWnAEQ8qBIypCyI40kbmLuPc3sAg/7rJfov0DsVnR/8+2
-c/aCUQpzoEN5NqLE+5hsZLw69bnF58HPdvtzI9NH4qkZYAinyBvDcyT5jdy/rl1b
-/kjQBqcz5djbTMmCoDLBHkVnZ85U
+MIICgzCCAeygAwIBAgIBGDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzOF9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczhfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA3lBn1o6n
+UxtzA/7H71mCDNd0760hM2h4Rid/8Qx2Z42+uvg2AMcb64IfcFhxAttqnhE3qLAo
+J7Sfvh0q+2dPoTrO4nDS2IHrklrGP5fsLEm1W4rh6mA1KGroN7Z6HoM2MlI/wKWy
+dBmxMjRm2vj84ZJCsqaHSFY3ZuM8b1hzJqECAwEAAaMjMCEwDwYDVR0TAQH/BAUw
+AwEB/zAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAVcsMUNngvcmy
+YA8NPqzj4OIvAqlbWy1Mu1XgWoNjRkaSzB/ziyTeb57GtfXKVx0H1JdO05upF1Zs
++ld/zaRVq2S3V7RZpL7WjG1wik/0EyDhcIkYmHfpkYepAWYHQ9/fTazhG7HF2CA/
+/P1fHfxhjkO5yu3bg4jiD0qp8iDu5lQ=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/19.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/19.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 25 (0x19)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:46 2011 GMT
-            Not After : Jan  5 22:37:46 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_cs8_ch1_ta3/emailAddress=cs1_cs8_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_cs8_ch1_ta3/emailAddress=cs1_cs8_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a8:89:d6:f6:e1:32:a9:bc:a5:c2:c8:00:1c:a1:
-                    04:fc:93:5a:5c:29:1d:37:7e:29:e1:7f:69:79:24:
-                    ab:05:5a:83:71:d8:3c:bb:e5:1c:b8:e0:5e:a8:bd:
-                    41:06:cb:69:f6:d2:b9:48:c4:93:7c:ae:c6:38:bc:
-                    d7:9a:f2:db:8d:f9:5f:51:c4:1b:d2:c5:0e:57:6d:
-                    0b:73:19:a8:34:e6:5b:81:80:43:77:3a:8e:54:59:
-                    91:69:a9:aa:9f:2b:24:24:1e:06:e8:bc:f2:3f:c3:
-                    ee:33:3f:f4:5f:76:fd:24:05:48:a8:98:2f:15:eb:
-                    16:d5:24:6b:ea:59:e6:06:51
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cc:fd:f6:7a:f6:04:88:b5:e3:ff:6f:ce:2a:01:
+                    89:dd:07:a7:10:5d:ca:76:bf:d2:18:97:80:5a:b1:
+                    b8:6e:6b:bd:6b:65:9a:24:0d:3d:dc:7f:eb:53:1f:
+                    45:9e:9c:61:98:da:18:08:c3:3e:45:de:e0:1e:16:
+                    93:2d:30:a4:e3:52:48:5d:97:80:3d:b9:3e:25:28:
+                    b1:be:17:db:71:57:ba:3f:69:22:3e:83:c7:6f:fe:
+                    69:fd:6d:cf:7a:2f:72:36:8d:85:28:38:50:0f:45:
+                    2f:22:e8:49:04:da:17:d5:a1:15:7e:b6:0e:de:e4:
+                    cc:2f:2a:e2:21:95:08:cb:07
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        27:04:6d:7c:c0:89:81:f7:16:04:e2:f7:f1:4a:3b:60:17:4d:
-        f2:c3:0b:78:32:a5:f0:b4:e4:4e:2e:8e:06:d6:2d:3a:65:33:
-        a1:16:60:47:78:1f:f3:d3:72:c5:c7:43:f8:bb:0e:22:2a:7b:
-        a6:3e:9c:1e:40:c8:71:ff:28:82:0b:d9:93:8c:b9:f6:a2:ca:
-        d5:52:81:b6:b7:a1:20:09:e8:8a:68:e5:24:d1:dd:da:dc:1a:
-        01:3d:e5:77:77:fe:64:f5:b6:14:f9:8b:04:3f:11:7e:62:f5:
-        ee:01:7c:d9:d5:b7:00:19:a9:49:05:94:0b:30:22:63:d2:0d:
-        3e:7a
+         a7:ac:32:bc:eb:2c:bc:b7:f1:f5:7a:e0:5b:34:0f:f0:44:44:
+         c5:9d:19:ca:4d:81:a6:9c:ea:43:be:fb:4f:3c:86:26:cf:f8:
+         a5:d0:9b:4f:65:eb:90:a4:8c:12:54:1c:6b:7a:c8:d2:e5:2b:
+         46:81:23:bc:e2:1a:a7:53:35:ea:fe:a5:e7:d4:d4:12:12:f1:
+         28:65:e0:12:56:36:2e:78:e3:fa:ca:1e:5e:b5:6f:27:39:7a:
+         fd:a0:1c:38:0b:2f:d6:68:24:9f:66:62:ea:28:82:f8:d4:10:
+         40:02:af:d1:91:79:6d:bf:f8:de:d1:45:cd:7d:35:92:69:f3:
+         30:4d
 -----BEGIN CERTIFICATE-----
-MIICjzCCAfigAwIBAgIBGTANBgkqhkiG9w0BAQsFADB4MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEUMBIGA1UEAxQLY3M4X2NoMV90YTMxGjAYBgkqhkiG9w0BCQEWC2Nz
-OF9jaDFfdGEzMB4XDTExMDQxMTIyMzc0NloXDTE0MDEwNTIyMzc0NlowgYAxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MRgwFgYDVQQDFA9jczFfY3M4X2NoMV90YTMxHjAc
-BgkqhkiG9w0BCQEWD2NzMV9jczhfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOB
-jQAwgYkCgYEAqInW9uEyqbylwsgAHKEE/JNaXCkdN34p4X9peSSrBVqDcdg8u+Uc
-uOBeqL1BBstp9tK5SMSTfK7GOLzXmvLbjflfUcQb0sUOV20LcxmoNOZbgYBDdzqO
-VFmRaamqnyskJB4G6LzyP8PuMz/0X3b9JAVIqJgvFesW1SRr6lnmBlECAwEAAaMg
-MB4wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQAD
-gYEAJwRtfMCJgfcWBOL38Uo7YBdN8sMLeDKl8LTkTi6OBtYtOmUzoRZgR3gf89Ny
-xcdD+LsOIip7pj6cHkDIcf8oggvZk4y59qLK1VKBtrehIAnoimjlJNHd2twaAT3l
-d3f+ZPW2FPmLBD8RfmL17gF82dW3ABmpSQWUCzAiY9INPno=
+MIICkTCCAfqgAwIBAgIBGTANBgkqhkiG9w0BAQsFADB5MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxFDASBgNVBAMMC2NzOF9jaDFfdGEzMRowGAYJKoZIhvcNAQkBFgtj
+czhfY2gxX3RhMzAeFw0xMzEyMTMwMDEzMzZaFw0xNjA5MDgwMDEzMzZaMIGBMQsw
+CQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEg
+Q2xhcmExDTALBgNVBAoMBHBrZzUxGDAWBgNVBAMMD2NzMV9jczhfY2gxX3RhMzEe
+MBwGCSqGSIb3DQEJARYPY3MxX2NzOF9jaDFfdGEzMIGfMA0GCSqGSIb3DQEBAQUA
+A4GNADCBiQKBgQDM/fZ69gSIteP/b84qAYndB6cQXcp2v9IYl4Basbhua71rZZok
+DT3cf+tTH0WenGGY2hgIwz5F3uAeFpMtMKTjUkhdl4A9uT4lKLG+F9txV7o/aSI+
+g8dv/mn9bc96L3I2jYUoOFAPRS8i6EkE2hfVoRV+tg7e5MwvKuIhlQjLBwIDAQAB
+oyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsF
+AAOBgQCnrDK86yy8t/H1euBbNA/wRETFnRnKTYGmnOpDvvtPPIYmz/il0JtPZeuQ
+pIwSVBxresjS5StGgSO84hqnUzXq/qXn1NQSEvEoZeASVjYueOP6yh5etW8nOXr9
+oBw4Cy/WaCSfZmLqKIL41BBAAq/RkXltv/je0UXNfTWSafMwTQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/1B.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/1B.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 27 (0x1b)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
         Validity
-            Not Before: Apr 11 22:37:47 2011 GMT
-            Not After : Jan  5 22:37:47 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.1_ta3/emailAddress=cs1_ch1.1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.1_ta3/emailAddress=cs1_ch1.1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:eb:05:16:da:3a:66:0f:5c:d8:26:83:38:fa:4f:
-                    60:0f:8c:42:06:b6:45:be:2e:ca:6c:fd:d8:a7:5f:
-                    14:70:e9:04:ee:f2:c7:40:b2:28:f4:d9:99:65:b0:
-                    2e:a2:e6:2c:df:42:72:12:92:ca:c1:6e:4d:2f:76:
-                    41:aa:22:bc:8d:f4:e8:40:78:61:b5:92:a7:43:ef:
-                    1c:55:19:31:a8:45:23:0f:b6:d5:32:44:35:dd:78:
-                    d4:f1:80:39:68:d1:ac:c1:4d:18:e2:e5:4d:eb:a9:
-                    cb:95:51:6c:c7:3a:50:ba:d3:4a:dc:7d:21:ad:ee:
-                    5a:36:5b:ce:34:1c:58:a7:d3
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cb:04:cf:d4:10:a0:b8:0a:41:51:cc:92:ed:1d:
+                    e6:42:d0:be:20:9c:08:f4:eb:67:d9:88:86:90:3c:
+                    f5:44:60:42:95:d3:0c:27:9a:90:f5:af:c6:4d:22:
+                    36:ba:9f:e2:74:17:f7:dd:2a:04:50:db:f3:2b:df:
+                    68:16:d9:ae:83:3b:2a:fa:7e:05:00:4e:64:a5:1e:
+                    c1:8e:99:11:b5:99:64:ae:36:0c:6d:41:42:72:a6:
+                    b0:2f:8d:e7:f1:b6:a8:1a:88:e5:ce:bc:dc:3c:9a:
+                    d1:39:ad:09:ab:c7:a0:bd:3c:36:92:b2:31:12:f9:
+                    76:1a:68:24:e6:70:e3:2e:25
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        1d:bc:1d:73:ed:03:34:4b:73:87:24:58:03:61:5a:67:fc:64:
-        f5:5e:a0:db:84:be:f0:9d:91:37:36:fc:db:86:90:99:3a:c3:
-        07:23:07:90:e5:5a:68:97:8f:b1:e8:d1:57:e5:a8:7e:b0:19:
-        2b:b6:25:b0:42:56:da:0c:3c:a9:82:4d:af:8f:f0:b7:c0:c3:
-        d7:d2:4d:9f:c9:40:5c:72:c4:95:86:de:28:5d:64:fe:7d:fd:
-        3d:51:33:90:7b:c0:9f:2b:5c:2f:36:29:a8:72:4f:4f:ad:44:
-        0a:d5:b4:fe:1f:d4:01:82:07:ed:36:81:8b:b3:1d:1d:42:ab:
-        53:bc
+         86:83:0a:12:5d:ac:ff:51:37:a3:5f:b2:62:5b:87:29:77:27:
+         49:73:d0:01:ed:f1:a9:53:02:ad:8e:f5:51:d7:7c:56:76:68:
+         75:f5:9d:b1:6c:0a:99:4e:59:85:16:58:fd:d2:3d:83:41:9d:
+         5f:6e:3a:90:8f:1a:dd:8d:96:8e:91:3c:d2:bb:ed:94:c3:0f:
+         86:dd:07:35:cf:b9:7b:ac:3d:1d:4a:15:c7:c4:21:14:91:46:
+         0e:42:9f:41:4b:44:e7:3b:5d:68:f0:65:2c:ef:3a:76:cd:c5:
+         cc:db:be:21:d0:bc:a1:8e:8d:ce:a5:e8:b5:e7:a0:ae:cf:74:
+         72:24
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBGzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjFfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-MV90YTMwHhcNMTEwNDExMjIzNzQ3WhcNMTQwMTA1MjIzNzQ3WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4xX3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4xX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-6wUW2jpmD1zYJoM4+k9gD4xCBrZFvi7KbP3Yp18UcOkE7vLHQLIo9NmZZbAuouYs
-30JyEpLKwW5NL3ZBqiK8jfToQHhhtZKnQ+8cVRkxqEUjD7bVMkQ13XjU8YA5aNGs
-wU0Y4uVN66nLlVFsxzpQutNK3H0hre5aNlvONBxYp9MCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAHbwdc+0D
-NEtzhyRYA2FaZ/xk9V6g24S+8J2RNzb824aQmTrDByMHkOVaaJePsejRV+WofrAZ
-K7YlsEJW2gw8qYJNr4/wt8DD19JNn8lAXHLElYbeKF1k/n39PVEzkHvAnytcLzYp
-qHJPT61ECtW0/h/UAYIH7TaBi7MdHUKrU7w=
+MIICiDCCAfGgAwIBAgIBGzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4xX3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjFfdGEzMB4XDTEzMTIxMzAwMTMzNloXDTE2MDkwODAwMTMzNlowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjFfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjFfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDLBM/UEKC4CkFRzJLtHeZC0L4gnAj062fZiIaQPPVEYEKV0wwnmpD1r8ZNIja6
+n+J0F/fdKgRQ2/Mr32gW2a6DOyr6fgUATmSlHsGOmRG1mWSuNgxtQUJyprAvjefx
+tqgaiOXOvNw8mtE5rQmrx6C9PDaSsjES+XYaaCTmcOMuJQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQCGgwoS
+Xaz/UTejX7JiW4cpdydJc9AB7fGpUwKtjvVR13xWdmh19Z2xbAqZTlmFFlj90j2D
+QZ1fbjqQjxrdjZaOkTzSu+2Uww+G3Qc1z7l7rD0dShXHxCEUkUYOQp9BS0TnO11o
+8GUs7zp2zcXM274h0Lyhjo3Opei156Cuz3RyJA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/1D.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/1D.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 29 (0x1d)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
         Validity
-            Not Before: Apr 11 22:37:48 2011 GMT
-            Not After : Jan  5 22:37:48 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.2_ta3/emailAddress=cs1_ch1.2_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.2_ta3/emailAddress=cs1_ch1.2_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d7:e5:0a:18:00:54:5b:ee:5a:de:78:35:85:4f:
-                    db:06:0c:e0:87:10:97:78:78:dc:2b:ab:95:86:3c:
-                    35:c4:42:1a:e8:c3:98:c8:5d:a1:25:a5:94:d6:8b:
-                    8e:73:e5:75:82:0a:e7:a0:47:3d:d3:16:86:3d:55:
-                    4c:2e:65:75:1b:6f:90:48:a6:4b:84:ee:76:81:56:
-                    a0:36:17:9b:58:0c:45:a6:0c:b3:0c:f1:34:11:df:
-                    14:8e:99:be:22:a2:a5:62:65:f0:a8:57:57:39:b9:
-                    13:1c:8b:97:6d:fd:56:b7:ce:1b:cb:ff:ad:80:c6:
-                    a3:0d:42:fe:bc:82:8f:4a:03
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d0:f8:ae:0b:eb:1f:d2:8b:41:0a:36:62:76:eb:
+                    5d:55:d4:b8:8a:eb:80:b8:05:58:ed:29:5d:9c:3f:
+                    2b:84:e5:be:1e:f6:ab:dd:d4:32:04:ee:f4:9b:b2:
+                    38:1c:59:0a:12:33:f8:b7:b6:e2:37:66:2e:58:e5:
+                    3d:7e:b8:69:73:74:8c:ad:d1:ae:de:11:38:04:7e:
+                    26:92:d4:2c:2e:68:15:09:4a:4f:d1:04:b6:ad:c7:
+                    d8:d7:2a:6d:92:cc:ca:48:87:c6:68:a4:c5:37:af:
+                    cc:20:6d:83:ba:f8:6b:f5:9b:8e:7d:df:d6:8b:7d:
+                    f1:36:6f:a3:5b:0b:b1:e8:6b
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        6b:92:5b:ba:16:e4:ff:58:0a:03:6e:d0:db:10:cb:1d:b3:b1:
-        0f:b5:b7:51:52:82:41:8c:0f:c2:3a:75:9c:26:bf:1d:25:91:
-        bc:b4:ca:17:79:ee:d8:61:89:1c:de:b1:23:4f:35:58:4f:2d:
-        d9:f4:e8:9f:56:d1:83:cc:ac:70:cd:3c:51:6f:45:e1:50:47:
-        06:17:61:cb:85:ed:d2:61:da:72:c6:79:4c:b9:7c:44:3a:c6:
-        a0:91:27:67:e5:e7:be:47:ee:fc:f4:c7:49:11:e5:65:3e:87:
-        f2:54:10:a9:41:24:6e:fb:ad:e5:4c:c8:e6:3f:9c:1c:61:41:
-        cd:a0
+         9f:2e:57:b4:bd:52:dd:f4:83:fb:24:d6:f1:99:36:97:b3:90:
+         4f:0d:10:ff:09:00:a3:1a:1e:10:39:63:f6:a6:0a:ee:9f:52:
+         55:b9:35:94:11:04:62:12:8a:c5:cf:c6:c5:2b:85:86:af:00:
+         80:b1:8a:1d:d6:4d:c3:78:d6:67:60:54:27:2e:28:15:b7:22:
+         23:47:4e:b0:89:8a:1a:03:24:db:5d:6a:a2:a7:af:cc:62:ca:
+         cd:2e:fd:7d:e2:2c:fb:5b:89:fd:b6:38:8a:3d:37:61:a9:94:
+         ad:31:d4:f3:d1:b6:91:d9:37:98:f1:ed:aa:11:da:0d:8f:93:
+         1c:8e
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBHTANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjJfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-Ml90YTMwHhcNMTEwNDExMjIzNzQ4WhcNMTQwMTA1MjIzNzQ4WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4yX3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4yX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-1+UKGABUW+5a3ng1hU/bBgzghxCXeHjcK6uVhjw1xEIa6MOYyF2hJaWU1ouOc+V1
-ggrnoEc90xaGPVVMLmV1G2+QSKZLhO52gVagNhebWAxFpgyzDPE0Ed8Ujpm+IqKl
-YmXwqFdXObkTHIuXbf1Wt84by/+tgMajDUL+vIKPSgMCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAa5Jbuhbk
-/1gKA27Q2xDLHbOxD7W3UVKCQYwPwjp1nCa/HSWRvLTKF3nu2GGJHN6xI081WE8t
-2fTon1bRg8yscM08UW9F4VBHBhdhy4Xt0mHacsZ5TLl8RDrGoJEnZ+Xnvkfu/PTH
-SRHlZT6H8lQQqUEkbvut5UzI5j+cHGFBzaA=
+MIICiDCCAfGgAwIBAgIBHTANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4yX3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjJfdGEzMB4XDTEzMTIxMzAwMTMzNloXDTE2MDkwODAwMTMzNlowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjJfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjJfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDQ+K4L6x/Si0EKNmJ2611V1LiK64C4BVjtKV2cPyuE5b4e9qvd1DIE7vSbsjgc
+WQoSM/i3tuI3Zi5Y5T1+uGlzdIyt0a7eETgEfiaS1CwuaBUJSk/RBLatx9jXKm2S
+zMpIh8ZopMU3r8wgbYO6+Gv1m45939aLffE2b6NbC7HoawIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQCfLle0
+vVLd9IP7JNbxmTaXs5BPDRD/CQCjGh4QOWP2pgrun1JVuTWUEQRiEorFz8bFK4WG
+rwCAsYod1k3DeNZnYFQnLigVtyIjR06wiYoaAyTbXWqip6/MYsrNLv194iz7W4n9
+tjiKPTdhqZStMdTz0baR2TeY8e2qEdoNj5Mcjg==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/1F.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/1F.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 31 (0x1f)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
         Validity
-            Not Before: Apr 11 22:37:48 2011 GMT
-            Not After : Jan  5 22:37:48 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.3_ta3/emailAddress=cs1_ch1.3_ta3
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.3_ta3/emailAddress=cs1_ch1.3_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b3:bb:8d:94:21:ec:dd:1d:bd:c4:ab:b9:04:17:
-                    f2:ac:58:db:4b:93:f9:17:2d:16:fc:d1:a5:ea:ee:
-                    e9:2e:4e:05:43:c2:4b:35:2e:ba:bc:70:f2:20:d7:
-                    53:64:ec:7f:84:ca:ce:eb:4d:ac:12:f0:55:6a:a9:
-                    be:17:a9:ae:63:61:37:3a:72:91:b2:82:b6:c1:7e:
-                    07:39:28:5a:20:a3:db:a4:24:34:ca:78:c8:9e:26:
-                    db:26:da:4f:b6:a6:cf:3f:23:d9:06:be:ad:d3:8f:
-                    23:41:51:49:f5:e3:63:91:68:a1:34:b9:3e:fd:da:
-                    22:07:86:a9:bd:58:93:84:2b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:fd:95:49:ab:6d:49:08:5c:f2:9b:77:e1:d0:71:
+                    4d:98:1b:84:31:e2:90:b2:0a:f6:af:2e:12:5b:31:
+                    d0:82:b4:ce:79:12:a5:56:44:d3:a5:49:51:68:45:
+                    cc:73:0e:67:6f:05:74:ff:ce:e7:27:8e:21:72:6a:
+                    df:58:42:b0:82:5d:ee:5f:9c:bc:be:10:d2:98:49:
+                    2a:a6:13:47:ac:27:23:83:fd:90:fd:42:9f:4d:5d:
+                    56:02:84:ff:53:40:51:ed:68:99:c6:20:c6:0d:e6:
+                    fb:47:f9:d8:42:0b:36:ca:50:69:27:9f:b7:8a:36:
+                    f6:5c:1a:0b:3e:9e:d7:12:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        28:69:b9:22:7b:ff:dd:7f:a5:95:f6:67:73:2d:f0:85:e9:22:
-        6e:ce:5e:f4:0e:39:90:56:a9:23:28:4a:73:d1:2f:4a:d5:dc:
-        fb:42:f2:c8:3c:a2:d7:97:08:ec:86:cc:72:65:23:21:88:e1:
-        be:67:8e:f8:44:7b:0e:b7:3f:04:75:db:4a:3f:32:e6:5a:e1:
-        6a:8e:f7:e9:20:ae:2c:62:51:34:d4:b1:c0:3b:20:64:d0:8f:
-        b3:86:4b:e1:82:ff:a2:61:eb:3f:1d:bf:2f:11:d2:01:96:a0:
-        a5:0f:df:1f:c9:1c:34:64:97:7d:3e:97:70:bf:2b:68:2f:cf:
-        91:52
+         50:82:2e:b8:61:6b:62:5f:4f:cf:e8:f9:6f:67:ba:ea:b2:40:
+         0c:49:40:e7:8d:db:af:e4:b0:61:8b:3c:6c:e5:43:d8:e9:8c:
+         f7:c2:7b:5f:ce:c5:f8:0e:9c:e2:77:6a:38:e2:25:0f:f0:e3:
+         d1:14:69:4a:ea:13:8a:91:ad:97:59:27:5e:4e:7c:f7:dc:b0:
+         34:94:3c:b7:9e:3f:40:da:44:66:73:f9:2c:8b:7e:d4:85:d8:
+         a6:58:fb:39:90:6e:3c:fd:b5:a1:39:82:dc:c3:87:97:d3:a7:
+         ce:e1:9d:18:63:27:77:99:fa:a3:c3:d7:d1:67:1d:4e:d0:07:
+         c2:9c
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBHzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjNfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-M190YTMwHhcNMTEwNDExMjIzNzQ4WhcNMTQwMTA1MjIzNzQ4WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4zX3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4zX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-s7uNlCHs3R29xKu5BBfyrFjbS5P5Fy0W/NGl6u7pLk4FQ8JLNS66vHDyINdTZOx/
-hMrO602sEvBVaqm+F6muY2E3OnKRsoK2wX4HOShaIKPbpCQ0ynjInibbJtpPtqbP
-PyPZBr6t048jQVFJ9eNjkWihNLk+/doiB4apvViThCsCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAKGm5Inv/
-3X+llfZncy3whekibs5e9A45kFapIyhKc9EvStXc+0LyyDyi15cI7IbMcmUjIYjh
-vmeO+ER7Drc/BHXbSj8y5lrhao736SCuLGJRNNSxwDsgZNCPs4ZL4YL/omHrPx2/
-LxHSAZagpQ/fH8kcNGSXfT6XcL8raC/PkVI=
+MIICiDCCAfGgAwIBAgIBHzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4zX3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjNfdGEzMB4XDTEzMTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjNfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjNfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQD9lUmrbUkIXPKbd+HQcU2YG4Qx4pCyCvavLhJbMdCCtM55EqVWRNOlSVFoRcxz
+DmdvBXT/zucnjiFyat9YQrCCXe5fnLy+ENKYSSqmE0esJyOD/ZD9Qp9NXVYChP9T
+QFHtaJnGIMYN5vtH+dhCCzbKUGknn7eKNvZcGgs+ntcSiQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQBQgi64
+YWtiX0/P6PlvZ7rqskAMSUDnjduv5LBhizxs5UPY6Yz3wntfzsX4Dpzid2o44iUP
+8OPRFGlK6hOKka2XWSdeTnz33LA0lDy3nj9A2kRmc/ksi37UhdimWPs5kG48/bWh
+OYLcw4eX06fO4Z0YYyd3mfqjw9fRZx1O0AfCnA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/21.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/21.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 33 (0x21)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
         Validity
-            Not Before: Apr 11 22:37:49 2011 GMT
-            Not After : Jan  5 22:37:49 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.4_ta3/emailAddress=cs1_ch1.4_ta3
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.4_ta3/emailAddress=cs1_ch1.4_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:ae:be:e2:6c:c9:bb:11:1a:16:90:72:55:8c:f5:
-                    d6:64:e7:2d:5f:18:27:c7:1d:b5:6e:10:a4:8a:b9:
-                    0e:71:ef:d5:05:42:2b:12:da:79:51:58:08:2a:37:
-                    e9:3d:47:93:4f:0f:d2:2b:29:b3:de:84:02:86:a2:
-                    75:40:59:ef:26:7b:e5:23:f2:db:91:62:e0:d7:08:
-                    02:4c:c8:05:bf:f1:fc:d3:1a:cb:59:f9:86:a0:7f:
-                    99:c8:3a:08:82:ba:5f:4f:62:d7:74:a5:2d:3e:b8:
-                    17:d5:ca:25:0b:59:34:d0:f0:a0:ec:3a:cc:8a:e0:
-                    22:1d:fb:d0:b2:cf:62:db:13
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c2:93:d3:55:0b:34:cf:57:bc:a5:91:9e:80:a9:
+                    7a:83:fb:26:66:c5:c1:71:20:ab:f9:80:9a:59:eb:
+                    54:83:83:6b:ad:79:a8:7e:17:67:20:1a:a8:7e:57:
+                    6e:f8:dd:54:9a:6e:f0:2d:10:32:59:1f:74:53:6d:
+                    a2:50:6b:23:0c:bb:34:32:84:ed:7d:fe:f5:8e:a7:
+                    f4:92:bb:29:a8:91:7d:e8:5e:56:30:e6:fa:fb:d2:
+                    d7:b9:af:f2:86:c2:dc:b7:33:71:62:2a:2d:79:38:
+                    a0:b1:0d:eb:87:03:56:c5:1c:c9:fb:33:5c:3c:d2:
+                    b9:f2:c0:b6:3c:de:e2:d8:3d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        7a:92:69:a9:a5:d2:40:46:78:cf:22:7b:5c:36:44:e6:6b:00:
-        78:ab:ca:ff:45:ad:77:d7:87:fc:92:5b:23:3c:dc:27:c2:0f:
-        ee:fe:40:f4:3c:46:46:8f:86:c1:94:ff:60:31:db:24:0c:9c:
-        46:bb:fb:c6:80:55:61:dc:4d:b9:6c:d4:67:b1:a0:35:f1:a4:
-        94:30:25:9d:c2:16:d5:82:cd:a3:eb:fc:1c:44:b8:bb:44:ef:
-        5f:00:bd:68:04:57:a6:5a:03:a6:fd:44:72:22:28:7f:e3:85:
-        4a:0f:c6:45:a9:ae:8a:bd:b0:49:73:c3:e1:30:ad:c2:9f:f7:
-        04:4d
+         7c:85:b5:58:70:73:83:28:62:ea:1a:2f:5d:29:10:50:54:6e:
+         86:dc:e2:f8:7f:bd:5e:bb:52:40:62:60:45:72:56:2d:b3:29:
+         9f:29:d6:1e:90:f2:67:3f:98:5f:e4:d2:39:3c:9f:a4:df:0c:
+         f9:75:4c:0f:2d:94:d9:fe:a2:f9:68:66:3c:bf:0f:0a:73:12:
+         23:33:56:8f:40:65:44:59:b6:2e:90:a7:5e:fb:17:29:42:36:
+         4b:ac:f5:e2:67:ee:7e:94:c0:a2:29:9a:1c:bf:74:94:b8:83:
+         11:d7:ac:a4:e1:b0:c1:7e:db:79:de:b4:ab:67:52:2e:51:d4:
+         ab:65
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBITANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjRfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-NF90YTMwHhcNMTEwNDExMjIzNzQ5WhcNMTQwMTA1MjIzNzQ5WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS40X3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS40X3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-rr7ibMm7ERoWkHJVjPXWZOctXxgnxx21bhCkirkOce/VBUIrEtp5UVgIKjfpPUeT
-Tw/SKymz3oQChqJ1QFnvJnvlI/LbkWLg1wgCTMgFv/H80xrLWfmGoH+ZyDoIgrpf
-T2LXdKUtPrgX1colC1k00PCg7DrMiuAiHfvQss9i2xMCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAepJpqaXS
-QEZ4zyJ7XDZE5msAeKvK/0Wtd9eH/JJbIzzcJ8IP7v5A9DxGRo+GwZT/YDHbJAyc
-Rrv7xoBVYdxNuWzUZ7GgNfGklDAlncIW1YLNo+v8HES4u0TvXwC9aARXploDpv1E
-ciIof+OFSg/GRamuir2wSXPD4TCtwp/3BE0=
+MIICiDCCAfGgAwIBAgIBITANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS40X3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjRfdGEzMB4XDTEzMTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjRfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjRfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDCk9NVCzTPV7ylkZ6AqXqD+yZmxcFxIKv5gJpZ61SDg2uteah+F2cgGqh+V274
+3VSabvAtEDJZH3RTbaJQayMMuzQyhO19/vWOp/SSuymokX3oXlYw5vr70te5r/KG
+wty3M3FiKi15OKCxDeuHA1bFHMn7M1w80rnywLY83uLYPQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQB8hbVY
+cHODKGLqGi9dKRBQVG6G3OL4f71eu1JAYmBFclYtsymfKdYekPJnP5hf5NI5PJ+k
+3wz5dUwPLZTZ/qL5aGY8vw8KcxIjM1aPQGVEWbYukKde+xcpQjZLrPXiZ+5+lMCi
+KZocv3SUuIMR16yk4bDBftt53rSrZ1IuUdSrZQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/23.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/23.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,55 +2,57 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 35 (0x23)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Validity
-            Not Before: Apr 11 22:37:50 2011 GMT
-            Not After : Jan  5 22:37:50 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1_ta4/emailAddress=cs1_ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1_ta4/emailAddress=cs1_ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b2:8c:40:a3:36:97:32:f7:20:68:e2:f4:f5:76:
-                    a3:13:03:4c:1e:32:7c:47:2f:16:32:14:4e:df:0b:
-                    7a:6a:22:54:78:cf:69:c9:ea:a7:e6:82:17:6a:31:
-                    11:38:7e:e4:f9:ed:be:a2:89:42:df:f4:df:f6:e4:
-                    23:bd:ad:4a:c2:ba:a3:a9:26:39:60:ee:02:07:74:
-                    25:6c:b0:7e:9f:6b:33:e1:e7:37:13:77:7b:a6:7f:
-                    4e:e8:75:61:d4:6b:89:19:6b:e5:a5:df:52:5c:71:
-                    25:37:d6:a7:e2:c8:7f:cd:4f:c4:44:b5:15:7c:62:
-                    f3:d2:54:d2:9f:c5:99:7a:ad
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:bb:13:23:7f:7b:bc:24:4f:bd:c3:56:23:7e:84:
+                    f6:a5:cd:87:51:d1:45:92:5b:0d:68:b7:56:23:ae:
+                    88:d5:51:83:c0:f7:b4:49:1e:d2:d3:22:b8:c4:10:
+                    eb:a4:45:89:86:63:d5:1b:a8:4e:8e:30:8a:3c:44:
+                    3c:78:7b:cf:c0:20:3c:67:ff:7e:5f:e0:45:8c:f8:
+                    cb:0f:cf:ac:41:c4:1b:da:3f:d6:55:7d:31:14:ae:
+                    1e:5e:cd:dd:1d:34:22:dd:00:35:60:58:74:a3:2f:
+                    ae:d3:b4:4d:49:28:ea:78:cd:1d:fe:cb:9e:f8:19:
+                    09:ae:e3:10:40:03:b4:5e:7f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ch1_ta4_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ch1_ta4_crl.pem
 
     Signature Algorithm: sha256WithRSAEncryption
-        53:4e:93:21:c0:2f:46:e1:aa:bc:11:25:b1:ee:1a:6d:df:b8:
-        ef:5d:0e:59:3d:fb:1f:1e:62:83:66:98:cb:71:26:b9:87:df:
-        49:5f:8e:fb:ec:d5:4d:70:d7:57:64:7a:58:08:54:dd:2a:86:
-        26:b7:9b:a1:dd:1b:00:45:b3:c2:f9:8a:06:17:cf:28:c3:00:
-        13:7a:6c:83:52:ea:a3:0e:6e:3e:1e:98:56:c4:68:d9:1f:99:
-        af:11:00:e5:5f:42:4d:54:4f:88:c4:43:ee:24:ee:ce:ce:17:
-        9f:13:5a:f3:1c:e8:a6:76:7c:70:6e:63:1a:3b:52:1c:c0:83:
-        01:7b
+         4e:be:e0:f6:a4:b9:2a:9d:31:f1:88:8b:b8:b4:ff:36:12:51:
+         a0:ec:9e:a7:f2:cf:a8:56:1e:fa:26:2c:43:db:a2:14:76:53:
+         e4:c8:fa:0f:4e:63:25:70:79:6f:71:50:92:74:38:ce:f6:a6:
+         93:2e:92:58:ee:85:13:e2:b0:64:3f:1d:56:e3:0b:09:04:d5:
+         53:54:73:f2:37:54:78:27:64:b4:64:c8:ee:67:b9:b7:41:65:
+         f2:06:57:6a:33:c6:7a:15:8d:dd:62:7b:6a:30:b3:80:94:8a:
+         ea:88:db:76:1a:f6:ab:7c:af:e3:3e:63:65:ee:44:fc:b5:0b:
+         e7:7d
 -----BEGIN CERTIFICATE-----
-MIICrjCCAhegAwIBAgIBIzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NDAeFw0xMTA0MTEyMjM3NTBaFw0xNDAxMDUyMjM3NTBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2gxX3RhNDEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoMV90YTQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALKMQKM2lzL3
-IGji9PV2oxMDTB4yfEcvFjIUTt8LemoiVHjPacnqp+aCF2oxETh+5PntvqKJQt/0
-3/bkI72tSsK6o6kmOWDuAgd0JWywfp9rM+HnNxN3e6Z/Tuh1YdRriRlr5aXfUlxx
-JTfWp+LIf81PxES1FXxi89JU0p/FmXqtAgMBAAGjUDBOMAwGA1UdEwEB/wQCMAAw
-PgYDVR0fBDcwNTAzoDGgL4YtaHR0cDovL2xvY2FsaG9zdDoxMjAwMS9maWxlLzAv
-Y2gxX3RhNF9jcmwucGVtMA0GCSqGSIb3DQEBCwUAA4GBAFNOkyHAL0bhqrwRJbHu
-Gm3fuO9dDlk9+x8eYoNmmMtxJrmH30lfjvvs1U1w11dkelgIVN0qhia3m6HdGwBF
-s8L5igYXzyjDABN6bINS6qMObj4emFbEaNkfma8RAOVfQk1UT4jEQ+4k7s7OF58T
-WvMc6KZ2fHBuYxo7UhzAgwF7
+MIICsDCCAhmgAwIBAgIBIzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTQxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDFfdGE0MRowGAYJKoZIhvcNAQkB
+FgtjczFfY2gxX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuxMjf3u8
+JE+9w1YjfoT2pc2HUdFFklsNaLdWI66I1VGDwPe0SR7S0yK4xBDrpEWJhmPVG6hO
+jjCKPEQ8eHvPwCA8Z/9+X+BFjPjLD8+sQcQb2j/WVX0xFK4eXs3dHTQi3QA1YFh0
+oy+u07RNSSjqeM0d/sue+BkJruMQQAO0Xn8CAwEAAaNQME4wDAYDVR0TAQH/BAIw
+ADA+BgNVHR8ENzA1MDOgMaAvhi1odHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUv
+MC9jaDFfdGE0X2NybC5wZW0wDQYJKoZIhvcNAQELBQADgYEATr7g9qS5Kp0x8YiL
+uLT/NhJRoOyep/LPqFYe+iYsQ9uiFHZT5Mj6D05jJXB5b3FQknQ4zvamky6SWO6F
+E+KwZD8dVuMLCQTVU1Rz8jdUeCdktGTI7me5t0Fl8gZXajPGehWN3WJ7ajCzgJSK
+6ojbdhr2q3yv4z5jZe5E/LUL530=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/24.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/24.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,66 +2,68 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 36 (0x24)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Validity
-            Not Before: Apr 11 22:37:50 2011 GMT
-            Not After : Jan  5 22:37:50 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs2_ch1_ta4/emailAddress=cs2_ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs2_ch1_ta4/emailAddress=cs2_ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:bf:ac:9d:17:06:fb:0f:06:2b:8f:e1:70:02:28:
-                    81:03:f5:1f:f4:4a:41:87:c5:4c:e1:4c:5b:9d:89:
-                    2f:a2:d4:5e:1a:4b:b6:93:c7:10:41:d9:e9:e0:d5:
-                    43:64:9f:39:1d:c8:2a:93:52:23:08:92:78:a3:5f:
-                    3b:98:50:e8:72:3a:73:12:4f:99:4b:4d:0e:e8:5d:
-                    92:f3:0b:5d:78:f6:5b:4b:c8:36:23:e3:ca:ab:8a:
-                    aa:52:33:d1:1e:61:d1:3e:91:5d:ee:38:bc:c4:0e:
-                    ee:54:f9:aa:00:a3:51:55:95:7a:c0:7b:0e:b2:d8:
-                    55:9d:f8:ae:1f:32:a7:87:eb
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ad:94:3a:b1:fd:3e:be:1e:33:73:ab:48:e2:ea:
+                    99:d8:1d:4d:c4:80:e6:fe:b6:6e:86:45:c4:86:81:
+                    df:c5:63:3d:b7:9b:50:75:bc:09:9d:cd:95:6c:6c:
+                    47:88:6d:0c:0c:24:7a:b9:50:f0:39:12:4b:6b:0c:
+                    2e:a3:7d:80:27:61:53:8b:63:c0:2e:a2:9e:b1:4d:
+                    0b:5a:a4:fd:6f:32:20:1d:2c:ea:18:c4:e5:ed:62:
+                    4d:ec:a7:ab:07:6e:8b:3f:c2:29:c7:30:90:7f:6a:
+                    2a:cc:08:9b:82:4b:24:a1:79:a2:06:a6:5c:7a:60:
+                    83:c5:ba:68:2c:ff:01:1f:d1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                4E:1B:1F:2F:80:BA:AC:13:47:60:30:A5:43:F6:01:7D:54:3C:9B:24
+                9F:BB:AE:D3:46:0F:B1:D1:1B:E5:D0:7F:06:5D:5B:3D:15:22:E3:C5
             X509v3 Authority Key Identifier: 
-                keyid:2A:94:C1:FF:E0:11:A0:91:F1:71:46:35:9A:37:3C:BC:C4:21:4A:8F
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
+                keyid:29:7A:F9:B4:E3:1B:8F:19:63:52:FA:19:A0:AB:DA:37:E4:70:A9:71
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
                 serial:22
 
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/example_file
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/example_file
 
     Signature Algorithm: sha256WithRSAEncryption
-        6d:40:ad:c1:79:65:fc:25:80:f7:52:d5:6f:16:3c:b2:77:f8:
-        35:e2:b5:d4:3c:49:f1:1c:02:d7:5a:61:aa:c2:c7:bd:53:4a:
-        96:58:8e:3e:14:d3:38:89:43:70:f0:5c:73:e1:c0:36:5e:10:
-        73:f4:93:c3:de:0c:61:49:be:2d:d0:1e:37:b4:03:49:a9:a4:
-        37:42:77:6a:97:15:45:2f:7d:b2:dd:9d:b2:98:56:0a:70:14:
-        83:ac:6f:e1:1e:97:31:9e:0a:30:ca:7d:5f:87:30:41:05:63:
-        4b:38:cb:f0:c0:cd:4d:a6:d2:11:34:30:ba:f4:8a:74:73:70:
-        ee:45
+         19:54:e0:5b:f7:80:a2:90:05:af:21:fe:4c:1f:f1:4b:c1:2f:
+         36:f3:e4:d1:93:16:67:48:89:62:69:37:92:71:61:aa:f1:4a:
+         2d:fa:ca:cd:69:e5:50:53:45:0a:91:2c:44:f8:44:22:02:82:
+         cd:6d:4b:15:85:cf:8d:ea:f8:98:1b:ff:7c:54:10:48:07:81:
+         a4:04:37:36:c1:95:72:e6:a6:e7:db:59:2f:1c:c9:b4:46:da:
+         98:53:e6:2e:24:9a:f3:9d:74:62:d5:28:96:66:a1:a2:47:21:
+         0e:5d:8e:be:89:ac:d2:4f:89:eb:fd:db:2d:e0:92:d7:a8:99:
+         c7:cf
 -----BEGIN CERTIFICATE-----
-MIIDYjCCAsugAwIBAgIBJDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NDAeFw0xMTA0MTEyMjM3NTBaFw0xNDAxMDUyMjM3NTBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczJfY2gxX3RhNDEaMBgGCSqGSIb3DQEJARYL
-Y3MyX2NoMV90YTQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAL+snRcG+w8G
-K4/hcAIogQP1H/RKQYfFTOFMW52JL6LUXhpLtpPHEEHZ6eDVQ2SfOR3IKpNSIwiS
-eKNfO5hQ6HI6cxJPmUtNDuhdkvMLXXj2W0vINiPjyquKqlIz0R5h0T6RXe44vMQO
-7lT5qgCjUVWVesB7DrLYVZ34rh8yp4frAgMBAAGjggECMIH/MB0GA1UdDgQWBBRO
-Gx8vgLqsE0dgMKVD9gF9VDybJDCBkgYDVR0jBIGKMIGHgBQqlMH/4BGgkfFxRjWa
-Nzy8xCFKj6FspGowaDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWEx
-EzARBgNVBAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAMTA3Rh
-NDESMBAGCSqGSIb3DQEJARYDdGE0ggEiMAwGA1UdEwEB/wQCMAAwOwYDVR0fBDQw
-MjAwoC6gLIYqaHR0cDovL2xvY2FsaG9zdDoxMjAwMS9maWxlLzAvZXhhbXBsZV9m
-aWxlMA0GCSqGSIb3DQEBCwUAA4GBAG1ArcF5ZfwlgPdS1W8WPLJ3+DXitdQ8SfEc
-AtdaYarCx71TSpZYjj4U0ziJQ3DwXHPhwDZeEHP0k8PeDGFJvi3QHje0A0mppDdC
-d2qXFUUvfbLdnbKYVgpwFIOsb+EelzGeCjDKfV+HMEEFY0s4y/DAzU2m0hE0MLr0
-inRzcO5F
+MIIDZjCCAs+gAwIBAgIBJDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTQxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMl9jaDFfdGE0MRowGAYJKoZIhvcNAQkB
+FgtjczJfY2gxX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEArZQ6sf0+
+vh4zc6tI4uqZ2B1NxIDm/rZuhkXEhoHfxWM9t5tQdbwJnc2VbGxHiG0MDCR6uVDw
+ORJLawwuo32AJ2FTi2PALqKesU0LWqT9bzIgHSzqGMTl7WJN7KerB26LP8IpxzCQ
+f2oqzAibgkskoXmiBqZcemCDxbpoLP8BH9ECAwEAAaOCAQQwggEAMB0GA1UdDgQW
+BBSfu67TRg+x0Rvl0H8GXVs9FSLjxTCBkwYDVR0jBIGLMIGIgBQpevm04xuPGWNS
++hmgq9o35HCpcaFtpGswaTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3Ju
+aWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQD
+DAN0YTQxEjAQBgkqhkiG9w0BCQEWA3RhNIIBIjAMBgNVHRMBAf8EAjAAMDsGA1Ud
+HwQ0MDIwMKAuoCyGKmh0dHA6Ly9sb2NhbGhvc3Q6MTIwMDEvZmlsZS8wL2V4YW1w
+bGVfZmlsZTANBgkqhkiG9w0BAQsFAAOBgQAZVOBb94CikAWvIf5MH/FLwS828+TR
+kxZnSIliaTeScWGq8Uot+srNaeVQU0UKkSxE+EQiAoLNbUsVhc+N6viYG/98VBBI
+B4GkBDc2wZVy5qbn21kvHMm0RtqYU+YuJJrznXRi1SiWZqGiRyEOXY6+iazST4nr
+/dst4JLXqJnHzw==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/25.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/25.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,65 +2,67 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 37 (0x25)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Validity
-            Not Before: Apr 11 22:37:50 2011 GMT
-            Not After : Jan  5 22:37:50 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs3_ch1_ta4/emailAddress=cs3_ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs3_ch1_ta4/emailAddress=cs3_ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c3:0c:75:ca:f7:a7:94:08:4a:72:f4:27:88:98:
-                    9f:d7:cc:7b:41:e4:54:86:11:d1:c2:d8:a1:ce:68:
-                    b0:8f:6a:6e:78:bf:f9:08:c9:a3:44:99:27:24:da:
-                    c2:76:e8:59:76:be:b2:04:46:1c:f4:1a:77:76:73:
-                    cb:dd:53:b6:9f:c7:5e:04:0a:35:43:e1:5d:5d:62:
-                    9b:73:13:06:d3:96:8f:64:4e:34:0d:bf:31:33:3c:
-                    05:24:26:d7:71:a6:83:65:1f:cf:01:25:c1:87:49:
-                    35:b9:12:a1:9c:af:4c:4f:da:26:59:e4:13:ee:c1:
-                    72:52:1a:f5:49:84:92:18:3b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d6:0b:65:25:4a:ab:c6:97:60:f0:0a:13:02:12:
+                    58:0a:26:26:7f:ba:10:82:a4:68:2e:59:dc:9e:63:
+                    71:4c:03:85:55:7b:c0:20:c8:3b:f3:12:24:8c:e5:
+                    4d:d4:41:10:5f:5d:be:b6:76:77:41:e5:57:48:c7:
+                    01:42:be:18:a0:f7:39:fa:3f:30:07:e9:6f:05:16:
+                    00:43:98:5e:fa:62:46:36:79:b1:6a:84:22:15:36:
+                    16:2b:23:e5:6f:2f:c6:ca:ae:dc:72:95:7a:48:9b:
+                    9b:ae:72:bd:f0:ff:d2:0b:fe:82:ec:53:38:23:cd:
+                    6d:65:28:ba:53:5c:74:6f:5f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                90:5E:20:89:14:A6:9B:2F:BD:21:FA:EC:07:E1:37:24:59:70:10:C1
+                83:0A:1B:8B:11:B9:64:BB:0F:67:12:12:45:12:74:32:7C:36:15:F9
             X509v3 Authority Key Identifier: 
-                keyid:2A:94:C1:FF:E0:11:A0:91:F1:71:46:35:9A:37:3C:BC:C4:21:4A:8F
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
+                keyid:29:7A:F9:B4:E3:1B:8F:19:63:52:FA:19:A0:AB:DA:37:E4:70:A9:71
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
                 serial:22
 
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:foo://bar/baz
+
+                Full Name:
+                  URI:foo://bar/baz
 
     Signature Algorithm: sha256WithRSAEncryption
-        95:ab:fa:7f:38:e3:de:4d:db:7f:a4:ea:49:f6:99:0c:57:76:
-        36:df:e3:68:50:0d:b7:af:78:ea:e4:07:ad:63:75:15:48:34:
-        ca:81:6a:0b:64:6d:c5:ca:9b:3b:a2:fd:dd:19:90:8f:d4:4d:
-        35:a0:a2:18:84:bf:89:0d:22:cc:03:67:57:15:f7:70:16:2b:
-        f7:14:82:3e:a9:74:50:e5:22:11:13:5b:69:d1:d5:87:c2:44:
-        a6:b8:9c:73:d6:51:ec:20:89:1a:11:44:07:8f:e7:6d:df:a8:
-        0f:5e:71:36:9c:7b:0b:e4:2b:5a:94:77:06:c6:fb:f7:e5:dc:
-        77:a3
+         35:54:4b:75:7e:93:ad:b6:4a:01:0d:0b:90:a6:b8:97:82:f1:
+         53:14:12:ce:da:83:cd:0a:d2:57:68:c4:a2:b2:54:94:dc:f8:
+         fb:21:a5:e6:37:63:07:6a:eb:99:c9:61:b2:41:6f:76:a0:94:
+         97:ad:a3:7c:38:b8:da:4a:ff:cb:cd:e6:d2:75:1e:c3:ae:c3:
+         4f:28:32:7a:71:8d:58:c3:df:79:bb:f8:38:b8:2e:bb:fb:01:
+         dc:81:c8:85:91:66:2c:46:ee:0e:96:32:4c:3c:63:ba:7e:71:
+         ea:41:e1:2d:13:ac:34:2c:de:0e:9b:47:4c:41:24:0e:8a:ab:
+         c7:65
 -----BEGIN CERTIFICATE-----
-MIIDRDCCAq2gAwIBAgIBJTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NDAeFw0xMTA0MTEyMjM3NTBaFw0xNDAxMDUyMjM3NTBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczNfY2gxX3RhNDEaMBgGCSqGSIb3DQEJARYL
-Y3MzX2NoMV90YTQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMMMdcr3p5QI
-SnL0J4iYn9fMe0HkVIYR0cLYoc5osI9qbni/+QjJo0SZJyTawnboWXa+sgRGHPQa
-d3Zzy91Ttp/HXgQKNUPhXV1im3MTBtOWj2RONA2/MTM8BSQm13Gmg2UfzwElwYdJ
-NbkSoZyvTE/aJlnkE+7BclIa9UmEkhg7AgMBAAGjgeUwgeIwHQYDVR0OBBYEFJBe
-IIkUppsvvSH67AfhNyRZcBDBMIGSBgNVHSMEgYowgYeAFCqUwf/gEaCR8XFGNZo3
-PLzEIUqPoWykajBoMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTET
-MBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGE0
-MRIwEAYJKoZIhvcNAQkBFgN0YTSCASIwDAYDVR0TAQH/BAIwADAeBgNVHR8EFzAV
-MBOgEaAPhg1mb286Ly9iYXIvYmF6MA0GCSqGSIb3DQEBCwUAA4GBAJWr+n84495N
-23+k6kn2mQxXdjbf42hQDbeveOrkB61jdRVINMqBagtkbcXKmzui/d0ZkI/UTTWg
-ohiEv4kNIswDZ1cV93AWK/cUgj6pdFDlIhETW2nR1YfCRKa4nHPWUewgiRoRRAeP
-523fqA9ecTacewvkK1qUdwbG+/fl3Hej
+MIIDRzCCArCgAwIBAgIBJTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTQxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzM19jaDFfdGE0MRowGAYJKoZIhvcNAQkB
+FgtjczNfY2gxX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA1gtlJUqr
+xpdg8AoTAhJYCiYmf7oQgqRoLlncnmNxTAOFVXvAIMg78xIkjOVN1EEQX12+tnZ3
+QeVXSMcBQr4YoPc5+j8wB+lvBRYAQ5he+mJGNnmxaoQiFTYWKyPlby/Gyq7ccpV6
+SJubrnK98P/SC/6C7FM4I81tZSi6U1x0b18CAwEAAaOB5jCB4zAdBgNVHQ4EFgQU
+gwobixG5ZLsPZxISRRJ0Mnw2FfkwgZMGA1UdIwSBizCBiIAUKXr5tOMbjxljUvoZ
+oKvaN+RwqXGhbaRrMGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlh
+MRQwEgYDVQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwD
+dGE0MRIwEAYJKoZIhvcNAQkBFgN0YTSCASIwDAYDVR0TAQH/BAIwADAeBgNVHR8E
+FzAVMBOgEaAPhg1mb286Ly9iYXIvYmF6MA0GCSqGSIb3DQEBCwUAA4GBADVUS3V+
+k622SgENC5CmuJeC8VMUEs7ag80K0ldoxKKyVJTc+PshpeY3Ywdq65nJYbJBb3ag
+lJeto3w4uNpK/8vN5tJ1HsOuw08oMnpxjVjD33m7+Di4Lrv7AdyByIWRZixG7g6W
+Mkw8Y7p+cepB4S0TrDQs3g6bR0xBJA6Kq8dl
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/27.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/27.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,55 +2,57 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 39 (0x27)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
         Validity
-            Not Before: Apr 11 22:37:51 2011 GMT
-            Not After : Jan  5 22:37:51 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.1_ta4/emailAddress=cs1_ch1.1_ta4
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.1_ta4/emailAddress=cs1_ch1.1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:ad:e1:a3:b5:65:8f:6f:53:61:4b:15:7a:d7:c6:
-                    0a:a3:b0:ee:20:0b:11:d7:9c:99:ad:63:e4:8d:22:
-                    6d:13:7b:10:d3:73:fa:a8:0a:14:44:3d:fb:88:be:
-                    d1:27:79:d8:6b:b1:ba:8a:35:29:2d:99:21:3b:65:
-                    20:d5:3d:bf:e6:fc:b6:01:e2:b3:8d:f5:9f:73:63:
-                    ca:48:9b:92:d6:34:84:fb:7c:87:1e:f5:8e:48:bd:
-                    96:5c:ce:e0:69:ab:f4:17:e5:22:1a:68:81:15:40:
-                    52:75:c5:b0:47:16:93:23:8b:4d:59:10:d0:e3:46:
-                    3e:ab:fd:09:6a:69:fc:6f:9d
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b6:6e:c2:9c:e6:4b:a1:4b:40:2a:15:bd:63:6b:
+                    1b:bc:ee:81:e8:d4:c6:d0:1d:1c:62:27:c1:e5:ea:
+                    7d:20:30:9b:91:ca:92:2c:b0:21:90:14:7c:db:98:
+                    e9:79:e7:dc:1f:13:17:37:66:43:d3:a5:b1:93:90:
+                    01:b6:2f:a3:a9:1b:29:5c:ff:93:d0:fb:32:e6:d4:
+                    1e:87:ba:1a:a1:82:5e:15:91:46:5e:1a:30:7d:70:
+                    b5:33:fc:20:ec:dc:34:41:e7:ce:02:3e:ec:d1:8f:
+                    55:58:e5:85:26:76:e2:96:b9:a1:bd:df:6a:38:09:
+                    d5:46:e8:2b:79:5e:59:9b:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ch1.1_ta4_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ch1.1_ta4_crl.pem
 
     Signature Algorithm: sha256WithRSAEncryption
-        57:fb:2f:75:3a:7a:68:6d:65:67:9a:c0:28:9e:c8:12:bf:b5:
-        63:c2:b8:9e:d0:78:07:6a:91:69:9f:a2:93:e1:90:8b:5a:25:
-        ec:3f:37:25:93:a2:f6:58:91:f1:f5:1a:67:44:2a:aa:ee:6e:
-        7c:dd:02:5c:82:8d:4e:7f:ea:de:42:0a:ef:83:c2:ec:78:74:
-        db:a8:e1:ba:0d:b8:e8:2a:b1:9b:d8:c6:df:28:75:34:85:78:
-        7d:f2:dd:68:63:63:4f:18:8e:66:65:73:1c:30:b0:a9:9e:df:
-        ae:ef:be:d2:99:28:bd:2c:9e:d9:d8:20:06:49:89:bb:0c:8c:
-        00:0e
+         3a:43:96:50:db:7b:96:a3:07:92:28:02:06:de:70:45:80:fe:
+         05:07:e8:f9:42:60:3b:11:10:3a:14:9b:5a:af:e6:1d:c2:7d:
+         0a:10:7d:0f:ad:26:a9:d7:9a:92:5d:0f:c1:76:d9:a0:ff:2d:
+         a9:b6:35:64:79:32:97:9b:d1:cc:ef:e3:b7:75:f9:a6:e9:50:
+         47:37:80:ca:dd:b0:3c:28:d4:78:2b:e8:53:56:76:30:5f:67:
+         e7:07:b8:e7:cb:7b:19:71:2a:71:6d:6d:58:1a:5e:3a:0f:c9:
+         ff:c4:0e:d4:e9:e5:5e:2c:26:5d:cd:a1:77:f9:3b:24:23:ec:
+         14:6c
 -----BEGIN CERTIFICATE-----
-MIICuDCCAiGgAwIBAgIBJzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjFfdGE0MRgwFgYJKoZIhvcNAQkBFgljaDEu
-MV90YTQwHhcNMTEwNDExMjIzNzUxWhcNMTQwMTA1MjIzNzUxWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4xX3RhNDEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4xX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-reGjtWWPb1NhSxV618YKo7DuIAsR15yZrWPkjSJtE3sQ03P6qAoURD37iL7RJ3nY
-a7G6ijUpLZkhO2Ug1T2/5vy2AeKzjfWfc2PKSJuS1jSE+3yHHvWOSL2WXM7gaav0
-F+UiGmiBFUBSdcWwRxaTI4tNWRDQ40Y+q/0Jamn8b50CAwEAAaNSMFAwDAYDVR0T
-AQH/BAIwADBABgNVHR8EOTA3MDWgM6Axhi9odHRwOi8vbG9jYWxob3N0OjEyMDAx
-L2ZpbGUvMC9jaDEuMV90YTRfY3JsLnBlbTANBgkqhkiG9w0BAQsFAAOBgQBX+y91
-OnpobWVnmsAonsgSv7Vjwrie0HgHapFpn6KT4ZCLWiXsPzclk6L2WJHx9RpnRCqq
-7m583QJcgo1Of+reQgrvg8LseHTbqOG6DbjoKrGb2MbfKHU0hXh98t1oY2NPGI5m
-ZXMcMLCpnt+u777SmSi9LJ7Z2CAGSYm7DIwADg==
+MIICujCCAiOgAwIBAgIBJzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4xX3RhNDEYMBYGCSqGSIb3DQEJARYJY2gx
+LjFfdGE0MB4XDTEzMTIxMzAwMTMzOFoXDTE2MDkwODAwMTMzOFowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjFfdGE0MRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjFfdGE0MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQC2bsKc5kuhS0AqFb1jaxu87oHo1MbQHRxiJ8Hl6n0gMJuRypIssCGQFHzbmOl5
+59wfExc3ZkPTpbGTkAG2L6OpGylc/5PQ+zLm1B6Huhqhgl4VkUZeGjB9cLUz/CDs
+3DRB584CPuzRj1VY5YUmduKWuaG932o4CdVG6Ct5XlmbiQIDAQABo1IwUDAMBgNV
+HRMBAf8EAjAAMEAGA1UdHwQ5MDcwNaAzoDGGL2h0dHA6Ly9sb2NhbGhvc3Q6MTIw
+MDEvZmlsZS8wL2NoMS4xX3RhNF9jcmwucGVtMA0GCSqGSIb3DQEBCwUAA4GBADpD
+llDbe5ajB5IoAgbecEWA/gUH6PlCYDsREDoUm1qv5h3CfQoQfQ+tJqnXmpJdD8F2
+2aD/Lam2NWR5Mpeb0czv47d1+abpUEc3gMrdsDwo1Hgr6FNWdjBfZ+cHuOfLexlx
+KnFtbVgaXjoPyf/EDtTp5V4sJl3NoXf5OyQj7BRs
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/29.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/29.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 41 (0x29)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1_ta5/emailAddress=cs1_ch1_ta5
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1_ta5/emailAddress=cs1_ch1_ta5
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:bc:a1:03:22:dd:57:7e:99:4b:58:8c:04:98:41:
-                    f9:77:26:01:6f:24:72:d0:7f:82:33:d5:8f:5f:a6:
-                    20:6c:02:b2:2c:56:8d:4d:fc:0d:a6:19:29:23:2f:
-                    88:8c:67:49:c3:e9:90:a6:17:0e:1a:62:28:44:49:
-                    68:80:aa:5e:24:e0:97:38:58:45:c1:45:59:38:e0:
-                    33:00:7c:65:63:b9:ea:a1:81:d0:92:5f:fe:50:1b:
-                    92:85:79:c9:91:96:51:0a:bf:1c:c8:a6:52:4f:b0:
-                    3e:1c:08:09:3b:a1:6a:af:ef:40:7b:df:8b:e3:bd:
-                    de:41:9c:1b:9b:f7:85:9c:25
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b4:65:08:30:97:70:86:fd:f9:89:7b:39:c4:95:
+                    a5:a9:81:55:71:9e:f9:f1:72:94:ec:0a:fa:af:c6:
+                    0b:43:68:db:17:2b:4e:40:ea:22:91:60:02:05:a2:
+                    ef:88:ad:78:8a:28:13:ac:2f:8a:65:6d:38:f3:43:
+                    9b:10:0e:c4:d1:d7:e7:ba:0f:31:06:1e:f6:f7:56:
+                    3f:68:1e:95:91:5f:d8:02:13:66:21:72:ed:66:6e:
+                    26:83:9a:de:60:87:e0:3a:63:e8:09:82:af:df:50:
+                    ae:f6:19:41:ba:c5:ae:8f:3e:6a:ba:f7:8b:fb:cd:
+                    90:a2:24:1e:7b:09:3e:a4:af
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        9f:43:a8:af:30:0a:8a:ca:fb:ac:58:e1:f7:d4:76:f6:08:2d:
-        b3:3a:cb:62:48:90:06:6e:bb:d3:7f:cc:3c:cc:57:3f:88:87:
-        a1:fd:d1:db:5a:a1:73:c6:c5:5a:d9:b9:bc:ba:43:43:ee:bf:
-        6b:c5:bc:5c:a3:2a:a4:01:9b:2f:60:b0:86:99:00:d4:1b:d6:
-        74:22:e8:9a:8e:06:b3:4e:33:34:3c:f4:96:ab:58:66:68:f1:
-        f4:75:a4:09:2e:4c:15:17:6d:9f:e0:e9:9f:45:4c:1f:24:7f:
-        b7:af:70:76:4c:38:20:8e:00:6e:eb:bf:84:e7:6f:b0:98:b7:
-        4a:67
+         60:5d:6b:d5:f4:71:25:3c:8d:93:35:51:dd:44:66:1b:98:10:
+         03:07:04:a7:a9:73:e1:f8:8e:62:6e:05:6e:d5:e5:04:7d:47:
+         fa:4d:1c:c6:a4:91:2e:96:d2:43:2d:92:11:54:d9:29:9a:13:
+         a9:21:8c:06:de:e8:55:a0:ac:02:6e:8f:a2:bc:1b:50:20:5c:
+         03:ff:45:b7:13:3a:ea:b2:35:90:f6:0d:a4:06:4f:f1:b0:9c:
+         cc:ce:df:c0:b2:88:44:5a:f5:86:41:94:94:aa:67:d8:62:b8:
+         73:c1:60:87:04:51:25:1e:75:ac:d4:da:5b:fd:3f:5d:bc:ac:
+         8d:d7
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBKTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNTEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NTAeFw0xMTA0MTEyMjM3NTJaFw0xNDAxMDUyMjM3NTJaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2gxX3RhNTEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoMV90YTUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALyhAyLdV36Z
-S1iMBJhB+XcmAW8kctB/gjPVj1+mIGwCsixWjU38DaYZKSMviIxnScPpkKYXDhpi
-KERJaICqXiTglzhYRcFFWTjgMwB8ZWO56qGB0JJf/lAbkoV5yZGWUQq/HMimUk+w
-PhwICTuhaq/vQHvfi+O93kGcG5v3hZwlAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBAJ9DqK8wCorK+6xY4ffU
-dvYILbM6y2JIkAZuu9N/zDzMVz+Ih6H90dtaoXPGxVrZuby6Q0Puv2vFvFyjKqQB
-my9gsIaZANQb1nQi6JqOBrNOMzQ89JarWGZo8fR1pAkuTBUXbZ/g6Z9FTB8kf7ev
-cHZMOCCOAG7rv4Tnb7CYt0pn
+MIICgDCCAemgAwIBAgIBKTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTUxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTUwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDFfdGE1MRowGAYJKoZIhvcNAQkB
+FgtjczFfY2gxX3RhNTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAtGUIMJdw
+hv35iXs5xJWlqYFVcZ758XKU7Ar6r8YLQ2jbFytOQOoikWACBaLviK14iigTrC+K
+ZW0480ObEA7E0dfnug8xBh7291Y/aB6VkV/YAhNmIXLtZm4mg5reYIfgOmPoCYKv
+31Cu9hlBusWujz5quveL+82QoiQeewk+pK8CAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAYF1r1fRxJTyNkzVR
+3URmG5gQAwcEp6lz4fiOYm4FbtXlBH1H+k0cxqSRLpbSQy2SEVTZKZoTqSGMBt7o
+VaCsAm6PorwbUCBcA/9FtxM66rI1kPYNpAZP8bCczM7fwLKIRFr1hkGUlKpn2GK4
+c8FghwRRJR51rNTaW/0/Xbysjdc=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/2A.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/2A.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 42 (0x2a)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta6, CN=localhost/emailAddress=cs1_ta6
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta6, CN=localhost/emailAddress=cs1_ta6
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e1:f0:66:24:db:fa:5f:00:b6:c4:f6:63:f0:51:
-                    7d:49:f9:92:71:e1:b3:8c:e7:fc:e9:e4:4f:79:76:
-                    52:51:06:65:c1:5f:d4:51:26:30:46:c9:70:98:5a:
-                    c5:a9:9e:6a:67:24:25:7a:68:5b:63:af:90:e7:b1:
-                    fb:42:f9:15:9c:d4:41:c6:90:fd:c3:d3:d7:cf:fe:
-                    00:c6:39:cb:6c:ae:9c:cb:74:c4:b6:1f:be:1b:58:
-                    9f:c9:8a:33:66:ec:32:08:fc:d9:23:e1:29:e2:f3:
-                    3e:3d:53:a7:78:e7:69:49:2b:39:72:8b:74:33:46:
-                    b1:f7:3b:26:4f:8d:06:64:e7
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:e0:47:5b:b6:ff:33:b8:75:5d:d1:f8:31:47:d7:
+                    46:c1:12:4e:d3:95:54:a2:cd:d8:c0:19:35:21:ea:
+                    03:c3:73:e0:e0:50:a1:10:2e:cd:9a:a5:8a:b0:b9:
+                    2e:66:ad:2d:09:3f:38:42:ec:2f:bd:c2:d0:16:90:
+                    82:d0:1c:a9:c7:81:4c:3f:9d:c8:f5:6d:ca:38:04:
+                    c2:9e:77:3c:1f:0b:9f:4b:d2:ca:df:a2:af:f0:4e:
+                    b8:51:e1:2c:01:4b:a7:b7:56:6c:ee:96:22:2f:2f:
+                    33:83:e2:c1:a5:c0:aa:e5:45:2b:50:31:84:8a:d0:
+                    5b:06:0a:2f:5d:c3:d6:d5:1b
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        6b:e1:7e:83:a6:a1:f8:46:a6:85:bb:c7:25:20:83:bb:b4:e0:
-        58:63:36:5a:97:1c:4c:76:24:a2:9d:c3:45:73:1f:22:39:97:
-        2c:47:b1:f5:3e:ac:b4:00:6d:c5:32:49:0c:83:e9:94:44:fa:
-        d6:e1:2d:a7:ae:66:34:9c:85:3e:a4:43:af:c0:2a:6c:f9:22:
-        64:d2:bb:54:67:e8:99:df:41:f2:7c:87:77:67:b5:3d:14:37:
-        75:32:56:69:21:f2:53:f2:d2:83:a1:fc:c0:3d:b5:4e:b5:d8:
-        06:d8:4e:71:f8:cc:3c:3a:93:a4:a0:05:a3:4f:7b:b1:83:21:
-        96:60
+         36:42:59:49:7a:7a:58:88:a3:c2:e9:16:fc:dc:5c:7c:26:2e:
+         d5:ff:4f:2f:45:96:7f:c0:5a:10:fd:a5:c5:18:95:48:b3:bf:
+         49:a0:a1:4d:70:e0:39:00:94:5d:7c:0b:99:dc:7d:29:57:40:
+         7a:31:67:94:00:83:61:aa:ca:48:7f:64:db:81:90:3c:2a:e4:
+         26:33:3e:80:14:12:85:06:bc:e9:8b:e2:49:80:bd:e7:a4:f0:
+         3a:c7:ba:e8:c0:1f:f2:7a:48:af:aa:ba:20:be:b2:e8:99:4d:
+         66:90:34:78:b1:82:9a:90:15:a8:dc:76:8d:27:df:7b:40:04:
+         a1:03
 -----BEGIN CERTIFICATE-----
-MIIClzCCAgCgAwIBAgIBKjANBgkqhkiG9w0BAQsFADB8MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UECxMDdGE2MRIwEAYDVQQDEwlsb2NhbGhvc3QxEjAQBgkq
-hkiG9w0BCQEWA3RhNjAeFw0xMTA0MTEyMjM3NTRaFw0xNDAxMDUyMjM3NTRaMIGE
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UECxQHY3MxX3RhNjESMBAGA1UE
-AxMJbG9jYWxob3N0MRYwFAYJKoZIhvcNAQkBFgdjczFfdGE2MIGfMA0GCSqGSIb3
-DQEBAQUAA4GNADCBiQKBgQDh8GYk2/pfALbE9mPwUX1J+ZJx4bOM5/zp5E95dlJR
-BmXBX9RRJjBGyXCYWsWpnmpnJCV6aFtjr5DnsftC+RWc1EHGkP3D09fP/gDGOcts
-rpzLdMS2H74bWJ/JijNm7DII/Nkj4Sni8z49U6d452lJKzlyi3QzRrH3OyZPjQZk
-5wIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG
-9w0BAQsFAAOBgQBr4X6DpqH4RqaFu8clIIO7tOBYYzZalxxMdiSincNFcx8iOZcs
-R7H1Pqy0AG3FMkkMg+mURPrW4S2nrmY0nIU+pEOvwCps+SJk0rtUZ+iZ30HyfId3
-Z7U9FDd1MlZpIfJT8tKDofzAPbVOtdgG2E5x+Mw8OpOkoAWjT3uxgyGWYA==
+MIICmTCCAgKgAwIBAgIBKjANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAsMA3RhNjESMBAGA1UEAwwJbG9jYWxob3N0MRIwEAYJ
+KoZIhvcNAQkBFgN0YTYwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjCB
+hTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1Nh
+bnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQLDAdjczFfdGE2MRIwEAYD
+VQQDDAlsb2NhbGhvc3QxFjAUBgkqhkiG9w0BCQEWB2NzMV90YTYwgZ8wDQYJKoZI
+hvcNAQEBBQADgY0AMIGJAoGBAOBHW7b/M7h1XdH4MUfXRsESTtOVVKLN2MAZNSHq
+A8Nz4OBQoRAuzZqlirC5LmatLQk/OELsL73C0BaQgtAcqceBTD+dyPVtyjgEwp53
+PB8Ln0vSyt+ir/BOuFHhLAFLp7dWbO6WIi8vM4PiwaXAquVFK1AxhIrQWwYKL13D
+1tUbAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgeAMA0GCSqG
+SIb3DQEBCwUAA4GBADZCWUl6eliIo8LpFvzcXHwmLtX/Ty9Fln/AWhD9pcUYlUiz
+v0mgoU1w4DkAlF18C5ncfSlXQHoxZ5QAg2Gqykh/ZNuBkDwq5CYzPoAUEoUGvOmL
+4kmAveek8DrHuujAH/J6SK+quiC+suiZTWaQNHixgpqQFajcdo0n33tABKED
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/2B.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/2B.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 43 (0x2b)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta7, CN=localhost/emailAddress=cs1_ta7
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta7, CN=localhost/emailAddress=cs1_ta7
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c1:8e:b8:0a:bd:17:40:c0:8d:b3:6f:c3:ca:97:
-                    ca:b0:b6:95:01:9c:d8:a0:f3:9f:af:2e:c8:3f:0b:
-                    54:f3:f0:c6:ae:41:d0:b5:73:4d:6e:b3:93:f9:58:
-                    99:86:b4:66:21:2d:9f:78:ad:47:eb:81:78:5d:21:
-                    2e:19:38:7a:73:64:5e:c9:8f:5c:1c:f5:92:b9:5f:
-                    2f:f3:de:e7:a3:8c:8a:cb:d1:b2:00:ed:7c:24:a8:
-                    10:d2:2c:eb:32:7c:48:23:fe:c2:9d:41:b5:07:d7:
-                    52:aa:e9:20:d3:2a:63:60:c4:1a:60:27:05:28:ae:
-                    4f:88:fd:ba:8e:ff:02:c7:47
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d6:44:f3:0b:4a:01:1a:b9:6e:5a:01:90:e2:1d:
+                    39:37:48:16:5d:16:fe:7b:69:47:f0:e2:bb:e0:5b:
+                    e9:22:6c:cc:7c:2c:8a:0d:74:6d:30:f5:f5:83:b8:
+                    b5:87:7a:c1:0c:0a:5a:17:6e:dc:21:53:9f:8b:02:
+                    84:b0:45:9f:67:31:30:61:ff:1a:62:c2:a9:94:b4:
+                    f9:70:57:0d:03:af:a1:00:59:be:15:5c:08:75:e0:
+                    56:4d:30:ea:02:d0:8a:f1:2c:dd:fa:74:cc:f3:98:
+                    15:ae:1a:e0:c0:72:64:0a:26:b6:e2:04:17:24:5d:
+                    58:60:ac:01:a7:73:03:71:ef
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        b5:06:5c:d4:ad:4f:c3:e4:99:0c:07:e7:dd:33:09:94:42:7d:
-        8a:c8:04:56:c8:63:a0:be:4b:a7:60:52:e4:13:ef:82:bd:ce:
-        9f:4f:91:ee:e8:0e:09:35:e6:eb:c2:e3:da:78:8d:4e:a2:b4:
-        e5:f0:4c:99:29:02:0f:a8:b8:49:56:f8:d9:a3:4b:c7:bb:ce:
-        ba:63:78:ed:36:f9:34:6a:b8:9d:06:9b:ff:5e:e9:48:0e:b3:
-        39:d7:64:e5:c9:28:c8:3c:8f:42:52:08:56:ad:6d:f0:63:aa:
-        30:45:d4:40:17:34:be:24:4e:21:7a:b5:b3:2a:c7:ce:75:1b:
-        a5:eb
+         31:3b:0b:62:1c:06:94:b3:85:8c:08:b8:da:07:20:01:4c:23:
+         98:34:20:06:f4:ec:b9:fb:42:52:80:2c:0f:e9:91:b7:de:3f:
+         c4:42:4a:d7:22:0a:9b:ec:83:a0:1f:64:57:98:e9:1a:e1:ac:
+         08:78:ee:28:05:c1:53:50:3e:d1:e0:fa:55:9a:a0:ca:39:28:
+         9f:71:8b:ab:9d:a6:3e:04:e9:bf:b3:4d:97:74:b2:36:4e:65:
+         ed:cf:5c:44:3c:c1:37:77:1c:d3:7d:3b:76:fe:72:53:ac:90:
+         0a:07:37:b0:97:64:ab:b4:d3:63:28:ce:37:cf:80:26:8a:7e:
+         0b:f0
 -----BEGIN CERTIFICATE-----
-MIIClzCCAgCgAwIBAgIBKzANBgkqhkiG9w0BAQsFADB8MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UECxMDdGE3MRIwEAYDVQQDEwlsb2NhbGhvc3QxEjAQBgkq
-hkiG9w0BCQEWA3RhNzAeFw0xMTA0MTEyMjM3NTRaFw0xNDAxMDUyMjM3NTRaMIGE
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UECxQHY3MxX3RhNzESMBAGA1UE
-AxMJbG9jYWxob3N0MRYwFAYJKoZIhvcNAQkBFgdjczFfdGE3MIGfMA0GCSqGSIb3
-DQEBAQUAA4GNADCBiQKBgQDBjrgKvRdAwI2zb8PKl8qwtpUBnNig85+vLsg/C1Tz
-8MauQdC1c01us5P5WJmGtGYhLZ94rUfrgXhdIS4ZOHpzZF7Jj1wc9ZK5Xy/z3uej
-jIrL0bIA7XwkqBDSLOsyfEgj/sKdQbUH11Kq6SDTKmNgxBpgJwUork+I/bqO/wLH
-RwIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG
-9w0BAQsFAAOBgQC1BlzUrU/D5JkMB+fdMwmUQn2KyARWyGOgvkunYFLkE++Cvc6f
-T5Hu6A4JNebrwuPaeI1OorTl8EyZKQIPqLhJVvjZo0vHu866Y3jtNvk0aridBpv/
-XulIDrM512TlySjIPI9CUghWrW3wY6owRdRAFzS+JE4herWzKsfOdRul6w==
+MIICmTCCAgKgAwIBAgIBKzANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAsMA3RhNzESMBAGA1UEAwwJbG9jYWxob3N0MRIwEAYJ
+KoZIhvcNAQkBFgN0YTcwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjCB
+hTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1Nh
+bnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQLDAdjczFfdGE3MRIwEAYD
+VQQDDAlsb2NhbGhvc3QxFjAUBgkqhkiG9w0BCQEWB2NzMV90YTcwgZ8wDQYJKoZI
+hvcNAQEBBQADgY0AMIGJAoGBANZE8wtKARq5bloBkOIdOTdIFl0W/ntpR/Diu+Bb
+6SJszHwsig10bTD19YO4tYd6wQwKWhdu3CFTn4sChLBFn2cxMGH/GmLCqZS0+XBX
+DQOvoQBZvhVcCHXgVk0w6gLQivEs3fp0zPOYFa4a4MByZAomtuIEFyRdWGCsAadz
+A3HvAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgeAMA0GCSqG
+SIb3DQEBCwUAA4GBADE7C2IcBpSzhYwIuNoHIAFMI5g0IAb07Ln7QlKALA/pkbfe
+P8RCStciCpvsg6AfZFeY6RrhrAh47igFwVNQPtHg+lWaoMo5KJ9xi6udpj4E6b+z
+TZd0sjZOZe3PXEQ8wTd3HNN9O3b+clOskAoHN7CXZKu002MozjfPgCaKfgvw
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 27 (0x1b)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta3/emailAddress=ch1.1_ta3
         Validity
-            Not Before: Apr 11 22:37:47 2011 GMT
-            Not After : Jan  5 22:37:47 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.1_ta3/emailAddress=cs1_ch1.1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.1_ta3/emailAddress=cs1_ch1.1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:eb:05:16:da:3a:66:0f:5c:d8:26:83:38:fa:4f:
-                    60:0f:8c:42:06:b6:45:be:2e:ca:6c:fd:d8:a7:5f:
-                    14:70:e9:04:ee:f2:c7:40:b2:28:f4:d9:99:65:b0:
-                    2e:a2:e6:2c:df:42:72:12:92:ca:c1:6e:4d:2f:76:
-                    41:aa:22:bc:8d:f4:e8:40:78:61:b5:92:a7:43:ef:
-                    1c:55:19:31:a8:45:23:0f:b6:d5:32:44:35:dd:78:
-                    d4:f1:80:39:68:d1:ac:c1:4d:18:e2:e5:4d:eb:a9:
-                    cb:95:51:6c:c7:3a:50:ba:d3:4a:dc:7d:21:ad:ee:
-                    5a:36:5b:ce:34:1c:58:a7:d3
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cb:04:cf:d4:10:a0:b8:0a:41:51:cc:92:ed:1d:
+                    e6:42:d0:be:20:9c:08:f4:eb:67:d9:88:86:90:3c:
+                    f5:44:60:42:95:d3:0c:27:9a:90:f5:af:c6:4d:22:
+                    36:ba:9f:e2:74:17:f7:dd:2a:04:50:db:f3:2b:df:
+                    68:16:d9:ae:83:3b:2a:fa:7e:05:00:4e:64:a5:1e:
+                    c1:8e:99:11:b5:99:64:ae:36:0c:6d:41:42:72:a6:
+                    b0:2f:8d:e7:f1:b6:a8:1a:88:e5:ce:bc:dc:3c:9a:
+                    d1:39:ad:09:ab:c7:a0:bd:3c:36:92:b2:31:12:f9:
+                    76:1a:68:24:e6:70:e3:2e:25
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        1d:bc:1d:73:ed:03:34:4b:73:87:24:58:03:61:5a:67:fc:64:
-        f5:5e:a0:db:84:be:f0:9d:91:37:36:fc:db:86:90:99:3a:c3:
-        07:23:07:90:e5:5a:68:97:8f:b1:e8:d1:57:e5:a8:7e:b0:19:
-        2b:b6:25:b0:42:56:da:0c:3c:a9:82:4d:af:8f:f0:b7:c0:c3:
-        d7:d2:4d:9f:c9:40:5c:72:c4:95:86:de:28:5d:64:fe:7d:fd:
-        3d:51:33:90:7b:c0:9f:2b:5c:2f:36:29:a8:72:4f:4f:ad:44:
-        0a:d5:b4:fe:1f:d4:01:82:07:ed:36:81:8b:b3:1d:1d:42:ab:
-        53:bc
+         86:83:0a:12:5d:ac:ff:51:37:a3:5f:b2:62:5b:87:29:77:27:
+         49:73:d0:01:ed:f1:a9:53:02:ad:8e:f5:51:d7:7c:56:76:68:
+         75:f5:9d:b1:6c:0a:99:4e:59:85:16:58:fd:d2:3d:83:41:9d:
+         5f:6e:3a:90:8f:1a:dd:8d:96:8e:91:3c:d2:bb:ed:94:c3:0f:
+         86:dd:07:35:cf:b9:7b:ac:3d:1d:4a:15:c7:c4:21:14:91:46:
+         0e:42:9f:41:4b:44:e7:3b:5d:68:f0:65:2c:ef:3a:76:cd:c5:
+         cc:db:be:21:d0:bc:a1:8e:8d:ce:a5:e8:b5:e7:a0:ae:cf:74:
+         72:24
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBGzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjFfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-MV90YTMwHhcNMTEwNDExMjIzNzQ3WhcNMTQwMTA1MjIzNzQ3WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4xX3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4xX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-6wUW2jpmD1zYJoM4+k9gD4xCBrZFvi7KbP3Yp18UcOkE7vLHQLIo9NmZZbAuouYs
-30JyEpLKwW5NL3ZBqiK8jfToQHhhtZKnQ+8cVRkxqEUjD7bVMkQ13XjU8YA5aNGs
-wU0Y4uVN66nLlVFsxzpQutNK3H0hre5aNlvONBxYp9MCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAHbwdc+0D
-NEtzhyRYA2FaZ/xk9V6g24S+8J2RNzb824aQmTrDByMHkOVaaJePsejRV+WofrAZ
-K7YlsEJW2gw8qYJNr4/wt8DD19JNn8lAXHLElYbeKF1k/n39PVEzkHvAnytcLzYp
-qHJPT61ECtW0/h/UAYIH7TaBi7MdHUKrU7w=
+MIICiDCCAfGgAwIBAgIBGzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4xX3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjFfdGEzMB4XDTEzMTIxMzAwMTMzNloXDTE2MDkwODAwMTMzNlowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjFfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjFfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDLBM/UEKC4CkFRzJLtHeZC0L4gnAj062fZiIaQPPVEYEKV0wwnmpD1r8ZNIja6
+n+J0F/fdKgRQ2/Mr32gW2a6DOyr6fgUATmSlHsGOmRG1mWSuNgxtQUJyprAvjefx
+tqgaiOXOvNw8mtE5rQmrx6C9PDaSsjES+XYaaCTmcOMuJQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQCGgwoS
+Xaz/UTejX7JiW4cpdydJc9AB7fGpUwKtjvVR13xWdmh19Z2xbAqZTlmFFlj90j2D
+QZ1fbjqQjxrdjZaOkTzSu+2Uww+G3Qc1z7l7rD0dShXHxCEUkUYOQp9BS0TnO11o
+8GUs7zp2zcXM274h0Lyhjo3Opei156Cuz3RyJA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.1_ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.1_ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,55 +2,57 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 39 (0x27)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.1_ta4/emailAddress=ch1.1_ta4
         Validity
-            Not Before: Apr 11 22:37:51 2011 GMT
-            Not After : Jan  5 22:37:51 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.1_ta4/emailAddress=cs1_ch1.1_ta4
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.1_ta4/emailAddress=cs1_ch1.1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:ad:e1:a3:b5:65:8f:6f:53:61:4b:15:7a:d7:c6:
-                    0a:a3:b0:ee:20:0b:11:d7:9c:99:ad:63:e4:8d:22:
-                    6d:13:7b:10:d3:73:fa:a8:0a:14:44:3d:fb:88:be:
-                    d1:27:79:d8:6b:b1:ba:8a:35:29:2d:99:21:3b:65:
-                    20:d5:3d:bf:e6:fc:b6:01:e2:b3:8d:f5:9f:73:63:
-                    ca:48:9b:92:d6:34:84:fb:7c:87:1e:f5:8e:48:bd:
-                    96:5c:ce:e0:69:ab:f4:17:e5:22:1a:68:81:15:40:
-                    52:75:c5:b0:47:16:93:23:8b:4d:59:10:d0:e3:46:
-                    3e:ab:fd:09:6a:69:fc:6f:9d
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b6:6e:c2:9c:e6:4b:a1:4b:40:2a:15:bd:63:6b:
+                    1b:bc:ee:81:e8:d4:c6:d0:1d:1c:62:27:c1:e5:ea:
+                    7d:20:30:9b:91:ca:92:2c:b0:21:90:14:7c:db:98:
+                    e9:79:e7:dc:1f:13:17:37:66:43:d3:a5:b1:93:90:
+                    01:b6:2f:a3:a9:1b:29:5c:ff:93:d0:fb:32:e6:d4:
+                    1e:87:ba:1a:a1:82:5e:15:91:46:5e:1a:30:7d:70:
+                    b5:33:fc:20:ec:dc:34:41:e7:ce:02:3e:ec:d1:8f:
+                    55:58:e5:85:26:76:e2:96:b9:a1:bd:df:6a:38:09:
+                    d5:46:e8:2b:79:5e:59:9b:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ch1.1_ta4_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ch1.1_ta4_crl.pem
 
     Signature Algorithm: sha256WithRSAEncryption
-        57:fb:2f:75:3a:7a:68:6d:65:67:9a:c0:28:9e:c8:12:bf:b5:
-        63:c2:b8:9e:d0:78:07:6a:91:69:9f:a2:93:e1:90:8b:5a:25:
-        ec:3f:37:25:93:a2:f6:58:91:f1:f5:1a:67:44:2a:aa:ee:6e:
-        7c:dd:02:5c:82:8d:4e:7f:ea:de:42:0a:ef:83:c2:ec:78:74:
-        db:a8:e1:ba:0d:b8:e8:2a:b1:9b:d8:c6:df:28:75:34:85:78:
-        7d:f2:dd:68:63:63:4f:18:8e:66:65:73:1c:30:b0:a9:9e:df:
-        ae:ef:be:d2:99:28:bd:2c:9e:d9:d8:20:06:49:89:bb:0c:8c:
-        00:0e
+         3a:43:96:50:db:7b:96:a3:07:92:28:02:06:de:70:45:80:fe:
+         05:07:e8:f9:42:60:3b:11:10:3a:14:9b:5a:af:e6:1d:c2:7d:
+         0a:10:7d:0f:ad:26:a9:d7:9a:92:5d:0f:c1:76:d9:a0:ff:2d:
+         a9:b6:35:64:79:32:97:9b:d1:cc:ef:e3:b7:75:f9:a6:e9:50:
+         47:37:80:ca:dd:b0:3c:28:d4:78:2b:e8:53:56:76:30:5f:67:
+         e7:07:b8:e7:cb:7b:19:71:2a:71:6d:6d:58:1a:5e:3a:0f:c9:
+         ff:c4:0e:d4:e9:e5:5e:2c:26:5d:cd:a1:77:f9:3b:24:23:ec:
+         14:6c
 -----BEGIN CERTIFICATE-----
-MIICuDCCAiGgAwIBAgIBJzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjFfdGE0MRgwFgYJKoZIhvcNAQkBFgljaDEu
-MV90YTQwHhcNMTEwNDExMjIzNzUxWhcNMTQwMTA1MjIzNzUxWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4xX3RhNDEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4xX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-reGjtWWPb1NhSxV618YKo7DuIAsR15yZrWPkjSJtE3sQ03P6qAoURD37iL7RJ3nY
-a7G6ijUpLZkhO2Ug1T2/5vy2AeKzjfWfc2PKSJuS1jSE+3yHHvWOSL2WXM7gaav0
-F+UiGmiBFUBSdcWwRxaTI4tNWRDQ40Y+q/0Jamn8b50CAwEAAaNSMFAwDAYDVR0T
-AQH/BAIwADBABgNVHR8EOTA3MDWgM6Axhi9odHRwOi8vbG9jYWxob3N0OjEyMDAx
-L2ZpbGUvMC9jaDEuMV90YTRfY3JsLnBlbTANBgkqhkiG9w0BAQsFAAOBgQBX+y91
-OnpobWVnmsAonsgSv7Vjwrie0HgHapFpn6KT4ZCLWiXsPzclk6L2WJHx9RpnRCqq
-7m583QJcgo1Of+reQgrvg8LseHTbqOG6DbjoKrGb2MbfKHU0hXh98t1oY2NPGI5m
-ZXMcMLCpnt+u777SmSi9LJ7Z2CAGSYm7DIwADg==
+MIICujCCAiOgAwIBAgIBJzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4xX3RhNDEYMBYGCSqGSIb3DQEJARYJY2gx
+LjFfdGE0MB4XDTEzMTIxMzAwMTMzOFoXDTE2MDkwODAwMTMzOFowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjFfdGE0MRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjFfdGE0MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQC2bsKc5kuhS0AqFb1jaxu87oHo1MbQHRxiJ8Hl6n0gMJuRypIssCGQFHzbmOl5
+59wfExc3ZkPTpbGTkAG2L6OpGylc/5PQ+zLm1B6Huhqhgl4VkUZeGjB9cLUz/CDs
+3DRB584CPuzRj1VY5YUmduKWuaG932o4CdVG6Ct5XlmbiQIDAQABo1IwUDAMBgNV
+HRMBAf8EAjAAMEAGA1UdHwQ5MDcwNaAzoDGGL2h0dHA6Ly9sb2NhbGhvc3Q6MTIw
+MDEvZmlsZS8wL2NoMS4xX3RhNF9jcmwucGVtMA0GCSqGSIb3DQEBCwUAA4GBADpD
+llDbe5ajB5IoAgbecEWA/gUH6PlCYDsREDoUm1qv5h3CfQoQfQ+tJqnXmpJdD8F2
+2aD/Lam2NWR5Mpeb0czv47d1+abpUEc3gMrdsDwo1Hgr6FNWdjBfZ+cHuOfLexlx
+KnFtbVgaXjoPyf/EDtTp5V4sJl3NoXf5OyQj7BRs
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.2_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.2_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 29 (0x1d)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.2_ta3/emailAddress=ch1.2_ta3
         Validity
-            Not Before: Apr 11 22:37:48 2011 GMT
-            Not After : Jan  5 22:37:48 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.2_ta3/emailAddress=cs1_ch1.2_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.2_ta3/emailAddress=cs1_ch1.2_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d7:e5:0a:18:00:54:5b:ee:5a:de:78:35:85:4f:
-                    db:06:0c:e0:87:10:97:78:78:dc:2b:ab:95:86:3c:
-                    35:c4:42:1a:e8:c3:98:c8:5d:a1:25:a5:94:d6:8b:
-                    8e:73:e5:75:82:0a:e7:a0:47:3d:d3:16:86:3d:55:
-                    4c:2e:65:75:1b:6f:90:48:a6:4b:84:ee:76:81:56:
-                    a0:36:17:9b:58:0c:45:a6:0c:b3:0c:f1:34:11:df:
-                    14:8e:99:be:22:a2:a5:62:65:f0:a8:57:57:39:b9:
-                    13:1c:8b:97:6d:fd:56:b7:ce:1b:cb:ff:ad:80:c6:
-                    a3:0d:42:fe:bc:82:8f:4a:03
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d0:f8:ae:0b:eb:1f:d2:8b:41:0a:36:62:76:eb:
+                    5d:55:d4:b8:8a:eb:80:b8:05:58:ed:29:5d:9c:3f:
+                    2b:84:e5:be:1e:f6:ab:dd:d4:32:04:ee:f4:9b:b2:
+                    38:1c:59:0a:12:33:f8:b7:b6:e2:37:66:2e:58:e5:
+                    3d:7e:b8:69:73:74:8c:ad:d1:ae:de:11:38:04:7e:
+                    26:92:d4:2c:2e:68:15:09:4a:4f:d1:04:b6:ad:c7:
+                    d8:d7:2a:6d:92:cc:ca:48:87:c6:68:a4:c5:37:af:
+                    cc:20:6d:83:ba:f8:6b:f5:9b:8e:7d:df:d6:8b:7d:
+                    f1:36:6f:a3:5b:0b:b1:e8:6b
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        6b:92:5b:ba:16:e4:ff:58:0a:03:6e:d0:db:10:cb:1d:b3:b1:
-        0f:b5:b7:51:52:82:41:8c:0f:c2:3a:75:9c:26:bf:1d:25:91:
-        bc:b4:ca:17:79:ee:d8:61:89:1c:de:b1:23:4f:35:58:4f:2d:
-        d9:f4:e8:9f:56:d1:83:cc:ac:70:cd:3c:51:6f:45:e1:50:47:
-        06:17:61:cb:85:ed:d2:61:da:72:c6:79:4c:b9:7c:44:3a:c6:
-        a0:91:27:67:e5:e7:be:47:ee:fc:f4:c7:49:11:e5:65:3e:87:
-        f2:54:10:a9:41:24:6e:fb:ad:e5:4c:c8:e6:3f:9c:1c:61:41:
-        cd:a0
+         9f:2e:57:b4:bd:52:dd:f4:83:fb:24:d6:f1:99:36:97:b3:90:
+         4f:0d:10:ff:09:00:a3:1a:1e:10:39:63:f6:a6:0a:ee:9f:52:
+         55:b9:35:94:11:04:62:12:8a:c5:cf:c6:c5:2b:85:86:af:00:
+         80:b1:8a:1d:d6:4d:c3:78:d6:67:60:54:27:2e:28:15:b7:22:
+         23:47:4e:b0:89:8a:1a:03:24:db:5d:6a:a2:a7:af:cc:62:ca:
+         cd:2e:fd:7d:e2:2c:fb:5b:89:fd:b6:38:8a:3d:37:61:a9:94:
+         ad:31:d4:f3:d1:b6:91:d9:37:98:f1:ed:aa:11:da:0d:8f:93:
+         1c:8e
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBHTANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjJfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-Ml90YTMwHhcNMTEwNDExMjIzNzQ4WhcNMTQwMTA1MjIzNzQ4WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4yX3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4yX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-1+UKGABUW+5a3ng1hU/bBgzghxCXeHjcK6uVhjw1xEIa6MOYyF2hJaWU1ouOc+V1
-ggrnoEc90xaGPVVMLmV1G2+QSKZLhO52gVagNhebWAxFpgyzDPE0Ed8Ujpm+IqKl
-YmXwqFdXObkTHIuXbf1Wt84by/+tgMajDUL+vIKPSgMCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAa5Jbuhbk
-/1gKA27Q2xDLHbOxD7W3UVKCQYwPwjp1nCa/HSWRvLTKF3nu2GGJHN6xI081WE8t
-2fTon1bRg8yscM08UW9F4VBHBhdhy4Xt0mHacsZ5TLl8RDrGoJEnZ+Xnvkfu/PTH
-SRHlZT6H8lQQqUEkbvut5UzI5j+cHGFBzaA=
+MIICiDCCAfGgAwIBAgIBHTANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4yX3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjJfdGEzMB4XDTEzMTIxMzAwMTMzNloXDTE2MDkwODAwMTMzNlowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjJfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjJfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDQ+K4L6x/Si0EKNmJ2611V1LiK64C4BVjtKV2cPyuE5b4e9qvd1DIE7vSbsjgc
+WQoSM/i3tuI3Zi5Y5T1+uGlzdIyt0a7eETgEfiaS1CwuaBUJSk/RBLatx9jXKm2S
+zMpIh8ZopMU3r8wgbYO6+Gv1m45939aLffE2b6NbC7HoawIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQCfLle0
+vVLd9IP7JNbxmTaXs5BPDRD/CQCjGh4QOWP2pgrun1JVuTWUEQRiEorFz8bFK4WG
+rwCAsYod1k3DeNZnYFQnLigVtyIjR06wiYoaAyTbXWqip6/MYsrNLv194iz7W4n9
+tjiKPTdhqZStMdTz0baR2TeY8e2qEdoNj5Mcjg==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.3_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.3_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 31 (0x1f)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.3_ta3/emailAddress=ch1.3_ta3
         Validity
-            Not Before: Apr 11 22:37:48 2011 GMT
-            Not After : Jan  5 22:37:48 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.3_ta3/emailAddress=cs1_ch1.3_ta3
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.3_ta3/emailAddress=cs1_ch1.3_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b3:bb:8d:94:21:ec:dd:1d:bd:c4:ab:b9:04:17:
-                    f2:ac:58:db:4b:93:f9:17:2d:16:fc:d1:a5:ea:ee:
-                    e9:2e:4e:05:43:c2:4b:35:2e:ba:bc:70:f2:20:d7:
-                    53:64:ec:7f:84:ca:ce:eb:4d:ac:12:f0:55:6a:a9:
-                    be:17:a9:ae:63:61:37:3a:72:91:b2:82:b6:c1:7e:
-                    07:39:28:5a:20:a3:db:a4:24:34:ca:78:c8:9e:26:
-                    db:26:da:4f:b6:a6:cf:3f:23:d9:06:be:ad:d3:8f:
-                    23:41:51:49:f5:e3:63:91:68:a1:34:b9:3e:fd:da:
-                    22:07:86:a9:bd:58:93:84:2b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:fd:95:49:ab:6d:49:08:5c:f2:9b:77:e1:d0:71:
+                    4d:98:1b:84:31:e2:90:b2:0a:f6:af:2e:12:5b:31:
+                    d0:82:b4:ce:79:12:a5:56:44:d3:a5:49:51:68:45:
+                    cc:73:0e:67:6f:05:74:ff:ce:e7:27:8e:21:72:6a:
+                    df:58:42:b0:82:5d:ee:5f:9c:bc:be:10:d2:98:49:
+                    2a:a6:13:47:ac:27:23:83:fd:90:fd:42:9f:4d:5d:
+                    56:02:84:ff:53:40:51:ed:68:99:c6:20:c6:0d:e6:
+                    fb:47:f9:d8:42:0b:36:ca:50:69:27:9f:b7:8a:36:
+                    f6:5c:1a:0b:3e:9e:d7:12:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        28:69:b9:22:7b:ff:dd:7f:a5:95:f6:67:73:2d:f0:85:e9:22:
-        6e:ce:5e:f4:0e:39:90:56:a9:23:28:4a:73:d1:2f:4a:d5:dc:
-        fb:42:f2:c8:3c:a2:d7:97:08:ec:86:cc:72:65:23:21:88:e1:
-        be:67:8e:f8:44:7b:0e:b7:3f:04:75:db:4a:3f:32:e6:5a:e1:
-        6a:8e:f7:e9:20:ae:2c:62:51:34:d4:b1:c0:3b:20:64:d0:8f:
-        b3:86:4b:e1:82:ff:a2:61:eb:3f:1d:bf:2f:11:d2:01:96:a0:
-        a5:0f:df:1f:c9:1c:34:64:97:7d:3e:97:70:bf:2b:68:2f:cf:
-        91:52
+         50:82:2e:b8:61:6b:62:5f:4f:cf:e8:f9:6f:67:ba:ea:b2:40:
+         0c:49:40:e7:8d:db:af:e4:b0:61:8b:3c:6c:e5:43:d8:e9:8c:
+         f7:c2:7b:5f:ce:c5:f8:0e:9c:e2:77:6a:38:e2:25:0f:f0:e3:
+         d1:14:69:4a:ea:13:8a:91:ad:97:59:27:5e:4e:7c:f7:dc:b0:
+         34:94:3c:b7:9e:3f:40:da:44:66:73:f9:2c:8b:7e:d4:85:d8:
+         a6:58:fb:39:90:6e:3c:fd:b5:a1:39:82:dc:c3:87:97:d3:a7:
+         ce:e1:9d:18:63:27:77:99:fa:a3:c3:d7:d1:67:1d:4e:d0:07:
+         c2:9c
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBHzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjNfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-M190YTMwHhcNMTEwNDExMjIzNzQ4WhcNMTQwMTA1MjIzNzQ4WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS4zX3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS4zX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-s7uNlCHs3R29xKu5BBfyrFjbS5P5Fy0W/NGl6u7pLk4FQ8JLNS66vHDyINdTZOx/
-hMrO602sEvBVaqm+F6muY2E3OnKRsoK2wX4HOShaIKPbpCQ0ynjInibbJtpPtqbP
-PyPZBr6t048jQVFJ9eNjkWihNLk+/doiB4apvViThCsCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAKGm5Inv/
-3X+llfZncy3whekibs5e9A45kFapIyhKc9EvStXc+0LyyDyi15cI7IbMcmUjIYjh
-vmeO+ER7Drc/BHXbSj8y5lrhao736SCuLGJRNNSxwDsgZNCPs4ZL4YL/omHrPx2/
-LxHSAZagpQ/fH8kcNGSXfT6XcL8raC/PkVI=
+MIICiDCCAfGgAwIBAgIBHzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS4zX3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjNfdGEzMB4XDTEzMTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjNfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjNfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQD9lUmrbUkIXPKbd+HQcU2YG4Qx4pCyCvavLhJbMdCCtM55EqVWRNOlSVFoRcxz
+DmdvBXT/zucnjiFyat9YQrCCXe5fnLy+ENKYSSqmE0esJyOD/ZD9Qp9NXVYChP9T
+QFHtaJnGIMYN5vtH+dhCCzbKUGknn7eKNvZcGgs+ntcSiQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQBQgi64
+YWtiX0/P6PlvZ7rqskAMSUDnjduv5LBhizxs5UPY6Yz3wntfzsX4Dpzid2o44iUP
+8OPRFGlK6hOKka2XWSdeTnz33LA0lDy3nj9A2kRmc/ksi37UhdimWPs5kG48/bWh
+OYLcw4eX06fO4Z0YYyd3mfqjw9fRZx1O0AfCnA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.4_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1.4_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 33 (0x21)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1.4_ta3/emailAddress=ch1.4_ta3
         Validity
-            Not Before: Apr 11 22:37:49 2011 GMT
-            Not After : Jan  5 22:37:49 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1.4_ta3/emailAddress=cs1_ch1.4_ta3
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1.4_ta3/emailAddress=cs1_ch1.4_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:ae:be:e2:6c:c9:bb:11:1a:16:90:72:55:8c:f5:
-                    d6:64:e7:2d:5f:18:27:c7:1d:b5:6e:10:a4:8a:b9:
-                    0e:71:ef:d5:05:42:2b:12:da:79:51:58:08:2a:37:
-                    e9:3d:47:93:4f:0f:d2:2b:29:b3:de:84:02:86:a2:
-                    75:40:59:ef:26:7b:e5:23:f2:db:91:62:e0:d7:08:
-                    02:4c:c8:05:bf:f1:fc:d3:1a:cb:59:f9:86:a0:7f:
-                    99:c8:3a:08:82:ba:5f:4f:62:d7:74:a5:2d:3e:b8:
-                    17:d5:ca:25:0b:59:34:d0:f0:a0:ec:3a:cc:8a:e0:
-                    22:1d:fb:d0:b2:cf:62:db:13
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c2:93:d3:55:0b:34:cf:57:bc:a5:91:9e:80:a9:
+                    7a:83:fb:26:66:c5:c1:71:20:ab:f9:80:9a:59:eb:
+                    54:83:83:6b:ad:79:a8:7e:17:67:20:1a:a8:7e:57:
+                    6e:f8:dd:54:9a:6e:f0:2d:10:32:59:1f:74:53:6d:
+                    a2:50:6b:23:0c:bb:34:32:84:ed:7d:fe:f5:8e:a7:
+                    f4:92:bb:29:a8:91:7d:e8:5e:56:30:e6:fa:fb:d2:
+                    d7:b9:af:f2:86:c2:dc:b7:33:71:62:2a:2d:79:38:
+                    a0:b1:0d:eb:87:03:56:c5:1c:c9:fb:33:5c:3c:d2:
+                    b9:f2:c0:b6:3c:de:e2:d8:3d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        7a:92:69:a9:a5:d2:40:46:78:cf:22:7b:5c:36:44:e6:6b:00:
-        78:ab:ca:ff:45:ad:77:d7:87:fc:92:5b:23:3c:dc:27:c2:0f:
-        ee:fe:40:f4:3c:46:46:8f:86:c1:94:ff:60:31:db:24:0c:9c:
-        46:bb:fb:c6:80:55:61:dc:4d:b9:6c:d4:67:b1:a0:35:f1:a4:
-        94:30:25:9d:c2:16:d5:82:cd:a3:eb:fc:1c:44:b8:bb:44:ef:
-        5f:00:bd:68:04:57:a6:5a:03:a6:fd:44:72:22:28:7f:e3:85:
-        4a:0f:c6:45:a9:ae:8a:bd:b0:49:73:c3:e1:30:ad:c2:9f:f7:
-        04:4d
+         7c:85:b5:58:70:73:83:28:62:ea:1a:2f:5d:29:10:50:54:6e:
+         86:dc:e2:f8:7f:bd:5e:bb:52:40:62:60:45:72:56:2d:b3:29:
+         9f:29:d6:1e:90:f2:67:3f:98:5f:e4:d2:39:3c:9f:a4:df:0c:
+         f9:75:4c:0f:2d:94:d9:fe:a2:f9:68:66:3c:bf:0f:0a:73:12:
+         23:33:56:8f:40:65:44:59:b6:2e:90:a7:5e:fb:17:29:42:36:
+         4b:ac:f5:e2:67:ee:7e:94:c0:a2:29:9a:1c:bf:74:94:b8:83:
+         11:d7:ac:a4:e1:b0:c1:7e:db:79:de:b4:ab:67:52:2e:51:d4:
+         ab:65
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBITANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2gxLjRfdGEzMRgwFgYJKoZIhvcNAQkBFgljaDEu
-NF90YTMwHhcNMTEwNDExMjIzNzQ5WhcNMTQwMTA1MjIzNzQ5WjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoMS40X3RhMzEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoMS40X3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-rr7ibMm7ERoWkHJVjPXWZOctXxgnxx21bhCkirkOce/VBUIrEtp5UVgIKjfpPUeT
-Tw/SKymz3oQChqJ1QFnvJnvlI/LbkWLg1wgCTMgFv/H80xrLWfmGoH+ZyDoIgrpf
-T2LXdKUtPrgX1colC1k00PCg7DrMiuAiHfvQss9i2xMCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAepJpqaXS
-QEZ4zyJ7XDZE5msAeKvK/0Wtd9eH/JJbIzzcJ8IP7v5A9DxGRo+GwZT/YDHbJAyc
-Rrv7xoBVYdxNuWzUZ7GgNfGklDAlncIW1YLNo+v8HES4u0TvXwC9aARXploDpv1E
-ciIof+OFSg/GRamuir2wSXPD4TCtwp/3BE0=
+MIICiDCCAfGgAwIBAgIBITANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoMS40X3RhMzEYMBYGCSqGSIb3DQEJARYJY2gx
+LjRfdGEzMB4XDTEzMTIxMzAwMTMzN1oXDTE2MDkwODAwMTMzN1owfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2gxLjRfdGEzMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2gxLjRfdGEzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDCk9NVCzTPV7ylkZ6AqXqD+yZmxcFxIKv5gJpZ61SDg2uteah+F2cgGqh+V274
+3VSabvAtEDJZH3RTbaJQayMMuzQyhO19/vWOp/SSuymokX3oXlYw5vr70te5r/KG
+wty3M3FiKi15OKCxDeuHA1bFHMn7M1w80rnywLY83uLYPQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQB8hbVY
+cHODKGLqGi9dKRBQVG6G3OL4f71eu1JAYmBFclYtsymfKdYekPJnP5hf5NI5PJ+k
+3wz5dUwPLZTZ/qL5aGY8vw8KcxIjM1aPQGVEWbYukKde+xcpQjZLrPXiZ+5+lMCi
+KZocv3SUuIMR16yk4bDBftt53rSrZ1IuUdSrZQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 17 (0x11)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:44 2011 GMT
-            Not After : Jan  5 22:37:44 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1_ta3/emailAddress=cs1_ch1_ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1_ta3/emailAddress=cs1_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cc:26:a7:16:78:9a:fb:e2:da:da:e3:c4:ef:7e:
-                    cb:5c:21:1c:aa:c1:53:35:df:cc:dc:f5:e2:98:0b:
-                    e6:8e:05:f4:e5:97:28:98:54:95:15:11:c9:1e:97:
-                    ed:ee:f4:49:4e:2f:0a:a2:16:83:0d:f5:49:65:78:
-                    6d:ba:a2:19:1b:74:27:64:1a:22:0b:85:47:d0:e1:
-                    85:25:1e:5c:fd:00:7a:37:9e:7e:83:43:cf:17:4e:
-                    2f:ea:7d:c9:5a:b8:70:7a:82:2c:74:0f:77:47:10:
-                    1a:a4:51:16:08:9e:71:b5:7c:54:53:60:92:a8:0c:
-                    1c:b3:b1:0f:ab:c3:0e:46:c5
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ea:17:76:34:ce:b3:de:ac:50:62:a0:0f:14:50:
+                    89:72:26:d5:a2:97:17:91:eb:df:97:7e:80:ff:69:
+                    8e:01:0a:bb:d1:a1:e0:f3:d2:27:56:c6:2d:0f:b5:
+                    84:e4:70:f3:e1:7e:fc:92:8e:fd:77:48:cb:ac:cd:
+                    bf:f4:aa:fa:29:5f:1b:44:03:cf:fa:6f:6d:ae:db:
+                    61:f1:3e:ef:95:de:41:23:36:a2:3a:e7:67:26:04:
+                    6b:7e:9d:f6:92:5e:5b:4c:ab:0a:aa:cf:99:b4:4c:
+                    54:05:73:81:a3:7b:5d:82:cb:e0:ee:9b:29:29:e6:
+                    fb:dd:93:64:23:13:85:d1:e1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        39:fc:dd:ed:5b:f5:75:d9:01:ed:86:33:11:21:27:c9:ad:78:
-        d3:e7:48:8a:3e:11:71:71:0f:d5:10:5b:5a:f0:16:a2:ac:70:
-        e9:3c:db:b9:30:c0:0d:2e:b4:8a:97:c3:50:d7:00:53:d3:4f:
-        b7:24:ff:38:64:e0:ff:87:01:18:6f:7c:bd:3c:2a:bc:fe:9b:
-        0a:d8:66:ce:9e:4e:fa:4c:5c:b5:62:ae:dc:1b:c4:ef:84:da:
-        45:3f:c2:a9:6d:74:a5:f0:44:7e:14:70:a4:4d:e3:dc:92:bb:
-        49:de:68:35:bb:59:a0:24:ba:d6:89:44:28:6b:b8:69:ca:64:
-        7f:f4
+         60:5d:82:5a:64:28:86:45:51:ab:d5:4c:74:ad:eb:84:37:fa:
+         ed:53:df:29:0d:00:9c:4b:33:f4:25:83:ad:b3:e4:cb:11:b0:
+         6e:92:cd:4f:9d:4b:7d:d0:bb:bc:c5:ef:b1:44:2e:54:e1:5e:
+         68:1f:a9:06:a7:e2:ca:82:f9:ac:e8:14:82:a3:26:03:7b:1b:
+         63:98:4f:bb:c9:5d:d5:79:77:bc:2e:e3:3d:7a:82:79:af:7d:
+         fc:e8:a0:9d:f9:e1:74:6d:e6:b9:47:84:19:dd:3f:43:51:8d:
+         9b:c1:27:9e:b7:c7:6b:e2:1f:77:29:bb:5f:a6:16:bf:d0:fd:
+         5a:c2
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBETANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDRaFw0xNDAxMDUyMjM3NDRaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMwmpxZ4mvvi
-2trjxO9+y1whHKrBUzXfzNz14pgL5o4F9OWXKJhUlRURyR6X7e70SU4vCqIWgw31
-SWV4bbqiGRt0J2QaIguFR9DhhSUeXP0AejeefoNDzxdOL+p9yVq4cHqCLHQPd0cQ
-GqRRFgiecbV8VFNgkqgMHLOxD6vDDkbFAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBADn83e1b9XXZAe2GMxEh
-J8mteNPnSIo+EXFxD9UQW1rwFqKscOk827kwwA0utIqXw1DXAFPTT7ck/zhk4P+H
-ARhvfL08Krz+mwrYZs6eTvpMXLVirtwbxO+E2kU/wqltdKXwRH4UcKRN49ySu0ne
-aDW7WaAkutaJRChruGnKZH/0
+MIICgDCCAemgAwIBAgIBETANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczFfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA6hd2NM6z
+3qxQYqAPFFCJcibVopcXkevfl36A/2mOAQq70aHg89InVsYtD7WE5HDz4X78ko79
+d0jLrM2/9Kr6KV8bRAPP+m9trtth8T7vld5BIzaiOudnJgRrfp32kl5bTKsKqs+Z
+tExUBXOBo3tdgsvg7pspKeb73ZNkIxOF0eECAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAYF2CWmQohkVRq9VM
+dK3rhDf67VPfKQ0AnEsz9CWDrbPkyxGwbpLNT51LfdC7vMXvsUQuVOFeaB+pBqfi
+yoL5rOgUgqMmA3sbY5hPu8ld1Xl3vC7jPXqCea99/OignfnhdG3muUeEGd0/Q1GN
+m8EnnrfHa+Ifdym7X6YWv9D9WsI=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,55 +2,57 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 35 (0x23)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Validity
-            Not Before: Apr 11 22:37:50 2011 GMT
-            Not After : Jan  5 22:37:50 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1_ta4/emailAddress=cs1_ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1_ta4/emailAddress=cs1_ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b2:8c:40:a3:36:97:32:f7:20:68:e2:f4:f5:76:
-                    a3:13:03:4c:1e:32:7c:47:2f:16:32:14:4e:df:0b:
-                    7a:6a:22:54:78:cf:69:c9:ea:a7:e6:82:17:6a:31:
-                    11:38:7e:e4:f9:ed:be:a2:89:42:df:f4:df:f6:e4:
-                    23:bd:ad:4a:c2:ba:a3:a9:26:39:60:ee:02:07:74:
-                    25:6c:b0:7e:9f:6b:33:e1:e7:37:13:77:7b:a6:7f:
-                    4e:e8:75:61:d4:6b:89:19:6b:e5:a5:df:52:5c:71:
-                    25:37:d6:a7:e2:c8:7f:cd:4f:c4:44:b5:15:7c:62:
-                    f3:d2:54:d2:9f:c5:99:7a:ad
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:bb:13:23:7f:7b:bc:24:4f:bd:c3:56:23:7e:84:
+                    f6:a5:cd:87:51:d1:45:92:5b:0d:68:b7:56:23:ae:
+                    88:d5:51:83:c0:f7:b4:49:1e:d2:d3:22:b8:c4:10:
+                    eb:a4:45:89:86:63:d5:1b:a8:4e:8e:30:8a:3c:44:
+                    3c:78:7b:cf:c0:20:3c:67:ff:7e:5f:e0:45:8c:f8:
+                    cb:0f:cf:ac:41:c4:1b:da:3f:d6:55:7d:31:14:ae:
+                    1e:5e:cd:dd:1d:34:22:dd:00:35:60:58:74:a3:2f:
+                    ae:d3:b4:4d:49:28:ea:78:cd:1d:fe:cb:9e:f8:19:
+                    09:ae:e3:10:40:03:b4:5e:7f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ch1_ta4_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ch1_ta4_crl.pem
 
     Signature Algorithm: sha256WithRSAEncryption
-        53:4e:93:21:c0:2f:46:e1:aa:bc:11:25:b1:ee:1a:6d:df:b8:
-        ef:5d:0e:59:3d:fb:1f:1e:62:83:66:98:cb:71:26:b9:87:df:
-        49:5f:8e:fb:ec:d5:4d:70:d7:57:64:7a:58:08:54:dd:2a:86:
-        26:b7:9b:a1:dd:1b:00:45:b3:c2:f9:8a:06:17:cf:28:c3:00:
-        13:7a:6c:83:52:ea:a3:0e:6e:3e:1e:98:56:c4:68:d9:1f:99:
-        af:11:00:e5:5f:42:4d:54:4f:88:c4:43:ee:24:ee:ce:ce:17:
-        9f:13:5a:f3:1c:e8:a6:76:7c:70:6e:63:1a:3b:52:1c:c0:83:
-        01:7b
+         4e:be:e0:f6:a4:b9:2a:9d:31:f1:88:8b:b8:b4:ff:36:12:51:
+         a0:ec:9e:a7:f2:cf:a8:56:1e:fa:26:2c:43:db:a2:14:76:53:
+         e4:c8:fa:0f:4e:63:25:70:79:6f:71:50:92:74:38:ce:f6:a6:
+         93:2e:92:58:ee:85:13:e2:b0:64:3f:1d:56:e3:0b:09:04:d5:
+         53:54:73:f2:37:54:78:27:64:b4:64:c8:ee:67:b9:b7:41:65:
+         f2:06:57:6a:33:c6:7a:15:8d:dd:62:7b:6a:30:b3:80:94:8a:
+         ea:88:db:76:1a:f6:ab:7c:af:e3:3e:63:65:ee:44:fc:b5:0b:
+         e7:7d
 -----BEGIN CERTIFICATE-----
-MIICrjCCAhegAwIBAgIBIzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NDAeFw0xMTA0MTEyMjM3NTBaFw0xNDAxMDUyMjM3NTBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2gxX3RhNDEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoMV90YTQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALKMQKM2lzL3
-IGji9PV2oxMDTB4yfEcvFjIUTt8LemoiVHjPacnqp+aCF2oxETh+5PntvqKJQt/0
-3/bkI72tSsK6o6kmOWDuAgd0JWywfp9rM+HnNxN3e6Z/Tuh1YdRriRlr5aXfUlxx
-JTfWp+LIf81PxES1FXxi89JU0p/FmXqtAgMBAAGjUDBOMAwGA1UdEwEB/wQCMAAw
-PgYDVR0fBDcwNTAzoDGgL4YtaHR0cDovL2xvY2FsaG9zdDoxMjAwMS9maWxlLzAv
-Y2gxX3RhNF9jcmwucGVtMA0GCSqGSIb3DQEBCwUAA4GBAFNOkyHAL0bhqrwRJbHu
-Gm3fuO9dDlk9+x8eYoNmmMtxJrmH30lfjvvs1U1w11dkelgIVN0qhia3m6HdGwBF
-s8L5igYXzyjDABN6bINS6qMObj4emFbEaNkfma8RAOVfQk1UT4jEQ+4k7s7OF58T
-WvMc6KZ2fHBuYxo7UhzAgwF7
+MIICsDCCAhmgAwIBAgIBIzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTQxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDFfdGE0MRowGAYJKoZIhvcNAQkB
+FgtjczFfY2gxX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuxMjf3u8
+JE+9w1YjfoT2pc2HUdFFklsNaLdWI66I1VGDwPe0SR7S0yK4xBDrpEWJhmPVG6hO
+jjCKPEQ8eHvPwCA8Z/9+X+BFjPjLD8+sQcQb2j/WVX0xFK4eXs3dHTQi3QA1YFh0
+oy+u07RNSSjqeM0d/sue+BkJruMQQAO0Xn8CAwEAAaNQME4wDAYDVR0TAQH/BAIw
+ADA+BgNVHR8ENzA1MDOgMaAvhi1odHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUv
+MC9jaDFfdGE0X2NybC5wZW0wDQYJKoZIhvcNAQELBQADgYEATr7g9qS5Kp0x8YiL
+uLT/NhJRoOyep/LPqFYe+iYsQ9uiFHZT5Mj6D05jJXB5b3FQknQ4zvamky6SWO6F
+E+KwZD8dVuMLCQTVU1Rz8jdUeCdktGTI7me5t0Fl8gZXajPGehWN3WJ7ajCzgJSK
+6ojbdhr2q3yv4z5jZe5E/LUL530=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta5_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch1_ta5_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 41 (0x29)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta5/emailAddress=ch1_ta5
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch1_ta5/emailAddress=cs1_ch1_ta5
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch1_ta5/emailAddress=cs1_ch1_ta5
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:bc:a1:03:22:dd:57:7e:99:4b:58:8c:04:98:41:
-                    f9:77:26:01:6f:24:72:d0:7f:82:33:d5:8f:5f:a6:
-                    20:6c:02:b2:2c:56:8d:4d:fc:0d:a6:19:29:23:2f:
-                    88:8c:67:49:c3:e9:90:a6:17:0e:1a:62:28:44:49:
-                    68:80:aa:5e:24:e0:97:38:58:45:c1:45:59:38:e0:
-                    33:00:7c:65:63:b9:ea:a1:81:d0:92:5f:fe:50:1b:
-                    92:85:79:c9:91:96:51:0a:bf:1c:c8:a6:52:4f:b0:
-                    3e:1c:08:09:3b:a1:6a:af:ef:40:7b:df:8b:e3:bd:
-                    de:41:9c:1b:9b:f7:85:9c:25
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b4:65:08:30:97:70:86:fd:f9:89:7b:39:c4:95:
+                    a5:a9:81:55:71:9e:f9:f1:72:94:ec:0a:fa:af:c6:
+                    0b:43:68:db:17:2b:4e:40:ea:22:91:60:02:05:a2:
+                    ef:88:ad:78:8a:28:13:ac:2f:8a:65:6d:38:f3:43:
+                    9b:10:0e:c4:d1:d7:e7:ba:0f:31:06:1e:f6:f7:56:
+                    3f:68:1e:95:91:5f:d8:02:13:66:21:72:ed:66:6e:
+                    26:83:9a:de:60:87:e0:3a:63:e8:09:82:af:df:50:
+                    ae:f6:19:41:ba:c5:ae:8f:3e:6a:ba:f7:8b:fb:cd:
+                    90:a2:24:1e:7b:09:3e:a4:af
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        9f:43:a8:af:30:0a:8a:ca:fb:ac:58:e1:f7:d4:76:f6:08:2d:
-        b3:3a:cb:62:48:90:06:6e:bb:d3:7f:cc:3c:cc:57:3f:88:87:
-        a1:fd:d1:db:5a:a1:73:c6:c5:5a:d9:b9:bc:ba:43:43:ee:bf:
-        6b:c5:bc:5c:a3:2a:a4:01:9b:2f:60:b0:86:99:00:d4:1b:d6:
-        74:22:e8:9a:8e:06:b3:4e:33:34:3c:f4:96:ab:58:66:68:f1:
-        f4:75:a4:09:2e:4c:15:17:6d:9f:e0:e9:9f:45:4c:1f:24:7f:
-        b7:af:70:76:4c:38:20:8e:00:6e:eb:bf:84:e7:6f:b0:98:b7:
-        4a:67
+         60:5d:6b:d5:f4:71:25:3c:8d:93:35:51:dd:44:66:1b:98:10:
+         03:07:04:a7:a9:73:e1:f8:8e:62:6e:05:6e:d5:e5:04:7d:47:
+         fa:4d:1c:c6:a4:91:2e:96:d2:43:2d:92:11:54:d9:29:9a:13:
+         a9:21:8c:06:de:e8:55:a0:ac:02:6e:8f:a2:bc:1b:50:20:5c:
+         03:ff:45:b7:13:3a:ea:b2:35:90:f6:0d:a4:06:4f:f1:b0:9c:
+         cc:ce:df:c0:b2:88:44:5a:f5:86:41:94:94:aa:67:d8:62:b8:
+         73:c1:60:87:04:51:25:1e:75:ac:d4:da:5b:fd:3f:5d:bc:ac:
+         8d:d7
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBKTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNTEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NTAeFw0xMTA0MTEyMjM3NTJaFw0xNDAxMDUyMjM3NTJaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2gxX3RhNTEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoMV90YTUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALyhAyLdV36Z
-S1iMBJhB+XcmAW8kctB/gjPVj1+mIGwCsixWjU38DaYZKSMviIxnScPpkKYXDhpi
-KERJaICqXiTglzhYRcFFWTjgMwB8ZWO56qGB0JJf/lAbkoV5yZGWUQq/HMimUk+w
-PhwICTuhaq/vQHvfi+O93kGcG5v3hZwlAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBAJ9DqK8wCorK+6xY4ffU
-dvYILbM6y2JIkAZuu9N/zDzMVz+Ih6H90dtaoXPGxVrZuby6Q0Puv2vFvFyjKqQB
-my9gsIaZANQb1nQi6JqOBrNOMzQ89JarWGZo8fR1pAkuTBUXbZ/g6Z9FTB8kf7ev
-cHZMOCCOAG7rv4Tnb7CYt0pn
+MIICgDCCAemgAwIBAgIBKTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTUxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTUwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDFfdGE1MRowGAYJKoZIhvcNAQkB
+FgtjczFfY2gxX3RhNTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAtGUIMJdw
+hv35iXs5xJWlqYFVcZ758XKU7Ar6r8YLQ2jbFytOQOoikWACBaLviK14iigTrC+K
+ZW0480ObEA7E0dfnug8xBh7291Y/aB6VkV/YAhNmIXLtZm4mg5reYIfgOmPoCYKv
+31Cu9hlBusWujz5quveL+82QoiQeewk+pK8CAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAYF1r1fRxJTyNkzVR
+3URmG5gQAwcEp6lz4fiOYm4FbtXlBH1H+k0cxqSRLpbSQy2SEVTZKZoTqSGMBt7o
+VaCsAm6PorwbUCBcA/9FtxM66rI1kPYNpAZP8bCczM7fwLKIRFr1hkGUlKpn2GK4
+c8FghwRRJR51rNTaW/0/Xbysjdc=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.1_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.1_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 9 (0x9)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.1_ta1/emailAddress=ch5.1_ta1
         Validity
-            Not Before: Apr 11 22:37:41 2011 GMT
-            Not After : Jan  5 22:37:41 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5.1_ta1/emailAddress=cs1_ch5.1_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5.1_ta1/emailAddress=cs1_ch5.1_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:9d:74:cf:25:35:26:cd:52:2e:9a:fc:8d:0b:4f:
-                    85:33:83:61:7a:f1:f1:c1:55:3d:dc:2e:20:77:8e:
-                    20:de:eb:e4:37:b6:6a:a4:c8:94:09:6c:f8:36:bd:
-                    78:a6:3f:2c:64:c3:23:d3:c7:fa:1c:36:a3:24:51:
-                    c0:ac:2d:20:6f:15:bf:aa:d8:94:5f:5f:8e:0a:c5:
-                    e0:aa:24:02:a5:f9:e4:cc:97:7f:74:b1:f1:a1:ab:
-                    30:6c:70:74:a4:5a:bd:5e:d7:69:64:6a:42:8d:c5:
-                    d0:b9:21:66:5a:9b:37:25:fa:34:cc:08:21:45:cb:
-                    23:10:eb:66:66:d2:9b:bc:19
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d5:b5:6f:9a:de:79:48:1e:9e:7c:61:b5:05:3f:
+                    f1:ef:a2:74:ac:83:92:f7:fa:6f:bc:ea:bf:7d:ac:
+                    d8:c9:ef:a3:50:01:2c:db:17:7c:68:6c:34:04:77:
+                    89:f6:77:db:63:08:2b:e7:59:6a:7a:d9:13:ef:d0:
+                    b1:1c:13:e0:3a:ee:0f:b6:e9:74:98:ce:30:25:dd:
+                    57:05:ed:55:f8:d2:5e:7a:c9:37:9d:29:87:a4:c8:
+                    55:f2:e7:a4:d8:cf:19:ee:af:d9:0d:35:e7:67:ae:
+                    87:70:f6:d2:98:1d:62:c6:aa:b6:ed:d0:50:77:79:
+                    ad:2e:5f:ef:a7:22:81:b3:2f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        3d:79:e6:0f:d3:33:eb:e7:fb:d4:39:f7:41:1e:f2:47:56:01:
-        d3:8b:bd:0d:0c:d5:ae:f1:85:6d:34:74:78:b3:27:20:88:4d:
-        bd:3a:b1:ac:d2:5c:f6:f3:87:f9:af:76:3a:93:60:a4:f5:97:
-        4c:c3:a6:aa:2a:f1:22:61:ea:2d:e4:97:f4:57:f7:30:84:85:
-        81:a1:aa:12:5a:37:82:96:11:d0:53:40:6c:5e:28:9f:42:1c:
-        3c:89:ae:d5:88:5d:cc:3e:4d:5c:ab:94:03:de:95:4a:b1:f2:
-        6b:cd:c1:cd:08:fa:87:88:80:e4:97:0f:36:55:3b:5d:60:a6:
-        1e:e3
+         75:2d:87:c6:b6:d7:5c:e7:bd:77:6f:d7:63:e4:f4:04:d1:df:
+         37:6f:80:99:9d:fe:b3:81:30:b4:1d:0b:3b:c7:f6:6c:15:a5:
+         ad:c2:2e:dc:5a:87:88:e0:b0:c9:81:99:33:c3:6a:f1:8d:4b:
+         8f:8c:cd:99:d4:ff:86:fe:3e:6e:b1:00:f0:15:16:d7:01:16:
+         13:8e:0e:31:35:ca:00:3c:88:7e:ca:8f:e3:32:6e:74:02:35:
+         66:3a:db:c8:83:37:b7:8c:7b:ba:bf:0d:aa:b8:d4:d8:28:03:
+         f5:f7:6f:c9:aa:d0:3c:03:cf:3d:da:aa:ae:1a:04:c6:7e:58:
+         ff:fe
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBCTANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g1LjFfdGExMRgwFgYJKoZIhvcNAQkBFgljaDUu
-MV90YTEwHhcNMTEwNDExMjIzNzQxWhcNMTQwMTA1MjIzNzQxWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoNS4xX3RhMTEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoNS4xX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-nXTPJTUmzVIumvyNC0+FM4NhevHxwVU93C4gd44g3uvkN7ZqpMiUCWz4Nr14pj8s
-ZMMj08f6HDajJFHArC0gbxW/qtiUX1+OCsXgqiQCpfnkzJd/dLHxoaswbHB0pFq9
-XtdpZGpCjcXQuSFmWps3Jfo0zAghRcsjEOtmZtKbvBkCAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAPXnmD9Mz
-6+f71Dn3QR7yR1YB04u9DQzVrvGFbTR0eLMnIIhNvTqxrNJc9vOH+a92OpNgpPWX
-TMOmqirxImHqLeSX9Ff3MISFgaGqElo3gpYR0FNAbF4on0IcPImu1YhdzD5NXKuU
-A96VSrHya83BzQj6h4iA5JcPNlU7XWCmHuM=
+MIICiDCCAfGgAwIBAgIBCTANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4xX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g1
+LjFfdGExMB4XDTEzMTIxMzAwMTMzNFoXDTE2MDkwODAwMTMzNFowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2g1LjFfdGExMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2g1LjFfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDVtW+a3nlIHp58YbUFP/HvonSsg5L3+m+86r99rNjJ76NQASzbF3xobDQEd4n2
+d9tjCCvnWWp62RPv0LEcE+A67g+26XSYzjAl3VcF7VX40l56yTedKYekyFXy56TY
+zxnur9kNNednrodw9tKYHWLGqrbt0FB3ea0uX++nIoGzLwIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQB1LYfG
+ttdc5713b9dj5PQE0d83b4CZnf6zgTC0HQs7x/ZsFaWtwi7cWoeI4LDJgZkzw2rx
+jUuPjM2Z1P+G/j5usQDwFRbXARYTjg4xNcoAPIh+yo/jMm50AjVmOtvIgze3jHu6
+vw2quNTYKAP192/JqtA8A8892qquGgTGflj//g==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.2_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.2_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 11 (0xb)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.2_ta1/emailAddress=ch5.2_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5.2_ta1/emailAddress=cs1_ch5.2_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5.2_ta1/emailAddress=cs1_ch5.2_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c8:74:f3:2f:47:e9:02:0e:f4:93:b9:c2:65:ae:
-                    74:a2:90:3e:2c:36:bd:86:b1:44:f9:ac:ce:ac:0d:
-                    8f:c6:fa:b4:94:62:39:25:63:12:77:4e:4b:26:ca:
-                    7b:ad:7e:e2:1c:9a:18:6d:10:cf:6d:82:b6:00:db:
-                    57:d6:ca:56:bb:af:bd:72:76:19:5f:18:f3:ce:55:
-                    3e:c9:9f:a0:a5:65:6d:01:d4:0b:fe:a0:8e:ba:d2:
-                    2d:19:5f:72:93:ab:50:a7:91:ba:3d:e6:d7:5f:07:
-                    4a:61:c2:3a:7b:22:77:9e:93:73:16:b9:b8:e4:d6:
-                    a4:9f:95:1d:f3:54:69:19:3f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b5:6f:3b:c4:aa:e3:6b:1a:e2:26:41:f2:49:f1:
+                    40:85:73:dc:ec:ef:04:d4:c9:fa:05:29:fc:bb:b9:
+                    83:5f:f1:05:d2:06:9c:e2:52:09:91:d7:d5:3c:45:
+                    ef:3f:77:2b:c8:fc:69:78:19:96:e5:14:c3:7e:8a:
+                    af:56:c0:44:ca:5c:49:bc:3c:71:0a:b9:05:6e:2a:
+                    b7:3f:02:8a:80:da:e7:ab:47:eb:18:40:18:4a:80:
+                    54:2c:dd:97:09:df:7d:ae:0f:f2:3a:9a:51:11:af:
+                    86:bb:f1:ec:5d:45:4d:64:11:d5:0f:2f:bd:79:eb:
+                    91:c1:5e:23:2e:18:aa:6e:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        13:49:e0:c1:04:5e:6e:af:74:a7:15:5c:2d:b4:0d:26:fb:00:
-        ca:f3:ed:0a:87:fb:5f:1a:c9:d4:48:fd:30:96:eb:c2:f4:34:
-        af:09:ef:71:ad:1d:d0:dd:5d:53:12:cd:63:7f:09:2a:10:f7:
-        12:7d:61:78:29:5b:80:c3:c7:5f:e7:16:af:c4:11:72:1e:45:
-        82:0b:67:3b:76:8e:33:f0:d1:3a:b6:ca:5a:e9:8f:33:c9:79:
-        b6:7e:ac:b6:ef:c3:36:f8:a0:ae:88:0c:7e:ed:74:f9:44:b2:
-        1b:e3:de:36:d4:9e:dd:5b:99:86:b3:7e:13:19:31:6d:6d:ff:
-        bf:f7
+         30:93:85:ec:3e:1b:11:03:97:84:c4:63:bf:5c:02:32:b6:56:
+         af:42:a5:28:24:7d:63:6c:a5:9c:9a:f5:52:7b:cf:c0:22:91:
+         47:7a:92:10:19:c4:51:08:1a:68:5e:50:a2:f1:fc:ac:23:8c:
+         dd:0c:a4:6a:21:8d:db:78:e1:5b:29:7b:8d:3c:5e:85:d8:4e:
+         5f:24:f4:17:f8:96:a8:62:db:04:2d:92:3c:ea:9f:7e:3b:ef:
+         1e:45:aa:0d:88:84:e9:a3:ee:42:bd:13:43:dd:e4:8f:0d:db:
+         e2:ae:0c:be:40:7b:a6:f1:86:19:ee:ff:6d:6f:5b:11:3a:41:
+         51:9c
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBCzANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g1LjJfdGExMRgwFgYJKoZIhvcNAQkBFgljaDUu
-Ml90YTEwHhcNMTEwNDExMjIzNzQyWhcNMTQwMTA1MjIzNzQyWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoNS4yX3RhMTEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoNS4yX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-yHTzL0fpAg70k7nCZa50opA+LDa9hrFE+azOrA2Pxvq0lGI5JWMSd05LJsp7rX7i
-HJoYbRDPbYK2ANtX1spWu6+9cnYZXxjzzlU+yZ+gpWVtAdQL/qCOutItGV9yk6tQ
-p5G6PebXXwdKYcI6eyJ3npNzFrm45Nakn5Ud81RpGT8CAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAE0ngwQRe
-bq90pxVcLbQNJvsAyvPtCof7XxrJ1Ej9MJbrwvQ0rwnvca0d0N1dUxLNY38JKhD3
-En1heClbgMPHX+cWr8QRch5FggtnO3aOM/DROrbKWumPM8l5tn6stu/DNvigrogM
-fu10+USyG+PeNtSe3VuZhrN+ExkxbW3/v/c=
+MIICiDCCAfGgAwIBAgIBCzANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4yX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g1
+LjJfdGExMB4XDTEzMTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2g1LjJfdGExMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2g1LjJfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQC1bzvEquNrGuImQfJJ8UCFc9zs7wTUyfoFKfy7uYNf8QXSBpziUgmR19U8Re8/
+dyvI/Gl4GZblFMN+iq9WwETKXEm8PHEKuQVuKrc/AoqA2uerR+sYQBhKgFQs3ZcJ
+332uD/I6mlERr4a78exdRU1kEdUPL71565HBXiMuGKpuiQIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQAwk4Xs
+PhsRA5eExGO/XAIytlavQqUoJH1jbKWcmvVSe8/AIpFHepIQGcRRCBpoXlCi8fys
+I4zdDKRqIY3beOFbKXuNPF6F2E5fJPQX+JaoYtsELZI86p9+O+8eRaoNiITpo+5C
+vRND3eSPDdvirgy+QHum8YYZ7v9tb1sROkFRnA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.3_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5.3_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 14 (0xe)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5.3_ta1/emailAddress=ch5.3_ta1
         Validity
-            Not Before: Apr 11 22:37:42 2011 GMT
-            Not After : Jan  5 22:37:42 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5.3_ta1/emailAddress=cs1_ch5.3_ta1
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5.3_ta1/emailAddress=cs1_ch5.3_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b5:76:e5:90:97:10:d5:aa:02:02:eb:87:f5:96:
-                    3a:94:31:a6:d9:1b:99:36:6b:62:13:36:cd:75:bf:
-                    5d:b9:19:02:15:79:e8:0c:95:12:80:a8:97:85:60:
-                    30:6f:4a:3d:cb:b4:bc:d8:a6:4d:a0:42:64:28:d3:
-                    07:2e:0a:f3:35:c3:35:10:08:f9:1e:e9:07:63:4b:
-                    7d:36:cc:65:7e:be:65:cb:a2:ad:8b:4a:1c:ec:9e:
-                    f6:f5:14:e7:93:42:5c:0b:a3:7e:73:ae:18:42:32:
-                    32:a0:45:96:2d:d5:d7:5c:75:f2:e3:48:23:34:20:
-                    88:4f:7e:1a:21:8c:45:30:0d
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c5:03:2b:f6:07:4e:f1:a3:9b:96:87:6d:ea:e2:
+                    bb:0b:fb:95:70:f6:34:a7:bb:e7:9f:df:ff:8a:fd:
+                    28:56:0b:fb:de:5d:79:d1:ba:0f:41:73:7f:5b:b9:
+                    17:6b:24:db:6f:20:a3:62:5e:3a:bb:71:29:18:33:
+                    52:24:ff:a9:9b:70:49:7f:78:94:f7:bd:a3:bf:2f:
+                    f4:de:e2:6f:61:13:ce:4f:f3:6a:85:84:35:ae:1d:
+                    a7:fb:00:2d:35:33:cc:18:ff:85:d9:37:0a:15:2b:
+                    15:71:de:ae:8c:99:ef:5b:dc:7b:4b:c1:b3:08:d9:
+                    57:29:29:e0:8d:46:e0:79:83
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        76:78:0e:96:48:35:42:08:26:68:65:9d:49:c6:3b:b7:f2:c7:
-        3b:41:e1:94:2b:30:ec:65:1d:90:bd:3e:6a:ec:66:f1:3d:e6:
-        76:b7:e7:a3:c7:96:b0:61:39:0b:e1:4e:15:cd:f7:95:48:c7:
-        ee:21:ce:81:5e:04:85:5b:2e:66:9f:2a:c1:6e:6f:4d:e3:c8:
-        32:1f:35:53:7d:4f:ff:0f:0f:07:25:6a:f9:da:74:0c:8d:cf:
-        86:3b:c1:30:bc:dd:a4:80:37:78:a3:03:1e:58:29:16:1b:d5:
-        b0:12:4e:8f:f4:da:c4:46:f4:28:4e:36:ac:d7:8a:95:c3:18:
-        e8:2e
+         0d:01:09:aa:c9:69:4c:33:74:70:07:ab:60:b6:0f:75:36:9e:
+         62:c2:96:82:f4:94:e4:9e:4b:6a:b4:fc:4e:45:21:e5:a7:20:
+         18:2a:a4:82:43:92:3a:d5:29:3a:f4:bb:e8:40:65:c8:08:53:
+         3b:46:42:4d:0b:f6:ba:8d:3f:08:ab:43:98:4b:41:40:8c:d6:
+         2d:58:dc:a8:53:e3:78:51:92:32:7e:00:9c:16:bb:c1:61:73:
+         68:2b:6d:4e:0f:f6:41:e4:08:43:b1:77:85:22:2b:06:1e:69:
+         48:38:28:9c:d5:60:65:7b:94:db:e7:d4:37:de:6a:0f:f3:cb:
+         53:45
 -----BEGIN CERTIFICATE-----
-MIIChjCCAe+gAwIBAgIBDjANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTESMBAGA1UEAxQJY2g1LjNfdGExMRgwFgYJKoZIhvcNAQkBFgljaDUu
-M190YTEwHhcNMTEwNDExMjIzNzQyWhcNMTQwMTA1MjIzNzQyWjB8MQswCQYDVQQG
-EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazEN
-MAsGA1UEChMEcGtnNTEWMBQGA1UEAxQNY3MxX2NoNS4zX3RhMTEcMBoGCSqGSIb3
-DQEJARYNY3MxX2NoNS4zX3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
-tXblkJcQ1aoCAuuH9ZY6lDGm2RuZNmtiEzbNdb9duRkCFXnoDJUSgKiXhWAwb0o9
-y7S82KZNoEJkKNMHLgrzNcM1EAj5HukHY0t9Nsxlfr5ly6Kti0oc7J729RTnk0Jc
-C6N+c64YQjIyoEWWLdXXXHXy40gjNCCIT34aIYxFMA0CAwEAAaMgMB4wDAYDVR0T
-AQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAdngOlkg1
-QggmaGWdScY7t/LHO0HhlCsw7GUdkL0+auxm8T3mdrfno8eWsGE5C+FOFc33lUjH
-7iHOgV4EhVsuZp8qwW5vTePIMh81U31P/w8PByVq+dp0DI3PhjvBMLzdpIA3eKMD
-HlgpFhvVsBJOj/TaxEb0KE42rNeKlcMY6C4=
+MIICiDCCAfGgAwIBAgIBDjANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEjAQBgNVBAMMCWNoNS4zX3RhMTEYMBYGCSqGSIb3DQEJARYJY2g1
+LjNfdGExMB4XDTEzMTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowfTELMAkGA1UE
+BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJh
+MQ0wCwYDVQQKDARwa2c1MRYwFAYDVQQDDA1jczFfY2g1LjNfdGExMRwwGgYJKoZI
+hvcNAQkBFg1jczFfY2g1LjNfdGExMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
+gQDFAyv2B07xo5uWh23q4rsL+5Vw9jSnu+ef3/+K/ShWC/veXXnRug9Bc39buRdr
+JNtvIKNiXjq7cSkYM1Ik/6mbcEl/eJT3vaO/L/Te4m9hE85P82qFhDWuHaf7AC01
+M8wY/4XZNwoVKxVx3q6Mme9b3HtLwbMI2VcpKeCNRuB5gwIDAQABoyAwHjAMBgNV
+HRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsFAAOBgQANAQmq
+yWlMM3RwB6tgtg91Np5iwpaC9JTknktqtPxORSHlpyAYKqSCQ5I61Sk69LvoQGXI
+CFM7RkJNC/a6jT8Iq0OYS0FAjNYtWNyoU+N4UZIyfgCcFrvBYXNoK21OD/ZB5AhD
+sXeFIisGHmlIOCic1WBle5Tb59Q33moP88tTRQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ch5_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 6 (0x6)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
         Validity
-            Not Before: Apr 11 22:37:40 2011 GMT
-            Not After : Jan  5 22:37:40 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ch5_ta1/emailAddress=cs1_ch5_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ch5_ta1/emailAddress=cs1_ch5_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e9:6c:6d:b5:1a:ef:fa:b5:f6:42:f6:7e:e6:f3:
-                    3f:11:2f:a7:c9:10:14:67:c9:fb:4b:c4:2f:c4:25:
-                    0d:a3:3c:66:0f:a0:1a:86:d5:19:48:e6:54:a3:a6:
-                    8d:6a:a2:89:a9:a5:ed:e7:49:ae:20:95:39:0c:19:
-                    41:87:e0:63:af:27:92:1d:55:b1:10:ea:b4:6d:5a:
-                    e6:21:78:93:94:e2:06:e6:7d:c6:53:4e:d5:af:82:
-                    08:a1:82:64:c1:57:78:7e:52:18:f6:38:f0:5e:8e:
-                    09:ea:fa:fc:7d:f3:2d:87:5d:a9:8e:ef:87:7a:e5:
-                    97:ef:7b:fb:b4:96:09:6b:17
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ba:a7:a1:60:33:eb:59:84:e6:2f:b0:30:38:b8:
+                    49:97:86:3b:82:4e:51:6a:28:bf:2a:6d:d3:46:77:
+                    67:ec:10:70:69:22:7f:e1:5d:7a:45:b5:81:2b:d2:
+                    ea:7d:41:5c:e2:4d:e8:2d:06:89:1c:4c:17:aa:3c:
+                    f5:2f:32:12:04:80:69:52:80:4a:ce:a1:4f:dc:76:
+                    a1:5a:d2:53:43:8f:7c:fb:82:eb:96:06:cd:05:89:
+                    74:34:7d:99:62:bc:09:67:e9:27:80:5b:78:65:05:
+                    57:c8:b6:b4:b7:83:5a:46:b2:80:6c:3f:05:3c:c6:
+                    49:2d:75:7c:48:2e:22:35:b7
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        14:9a:25:22:78:e5:77:2e:7f:28:cb:57:a9:d8:22:b1:7a:f1:
-        75:b9:79:3f:f3:7e:bc:eb:49:1e:35:0f:7a:20:f0:0a:f6:a1:
-        eb:08:a1:be:4c:c7:98:22:5b:9f:f9:a6:9a:e2:4a:85:13:2a:
-        f1:7f:da:cc:04:b1:13:d5:52:90:59:17:a8:f8:77:f8:ba:02:
-        88:62:fb:9d:28:3f:0d:15:ad:79:3f:d0:a2:cb:a2:87:b7:e0:
-        10:3a:a1:1b:4b:0c:79:f6:1e:b0:20:dc:0f:01:7e:c0:9c:86:
-        91:6d:c4:06:4b:fb:3b:da:70:e0:1b:9b:f3:9d:2d:57:cb:16:
-        26:4f
+         c2:d0:56:dd:4a:bb:8f:f9:de:49:4c:0c:41:af:29:73:07:f5:
+         da:44:4a:aa:0b:9c:80:33:56:cc:eb:c5:58:14:f9:c2:c9:cc:
+         93:2f:75:eb:6c:fd:b8:79:de:0d:35:db:46:8b:a6:d7:0b:59:
+         3d:35:c9:ac:68:76:63:85:bd:b1:03:21:c7:53:a5:f5:22:9f:
+         f0:c2:23:7e:de:32:6f:4a:7b:d8:d5:2d:b1:ee:db:ad:5a:f9:
+         35:46:55:11:5a:bb:6b:53:21:1d:ea:c4:4d:16:5c:01:f5:af:
+         91:47:bb:16:c1:9b:71:4e:5b:52:b5:ea:f9:d8:7a:53:c0:ef:
+         e7:f4
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBBjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g1X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g1X3Rh
-MTAeFw0xMTA0MTEyMjM3NDBaFw0xNDAxMDUyMjM3NDBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczFfY2g1X3RhMTEaMBgGCSqGSIb3DQEJARYL
-Y3MxX2NoNV90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAOlsbbUa7/q1
-9kL2fubzPxEvp8kQFGfJ+0vEL8QlDaM8Zg+gGobVGUjmVKOmjWqiiaml7edJriCV
-OQwZQYfgY68nkh1VsRDqtG1a5iF4k5TiBuZ9xlNO1a+CCKGCZMFXeH5SGPY48F6O
-Cer6/H3zLYddqY7vh3rll+97+7SWCWsXAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBABSaJSJ45XcufyjLV6nY
-IrF68XW5eT/zfrzrSR41D3og8Ar2oesIob5Mx5giW5/5ppriSoUTKvF/2swEsRPV
-UpBZF6j4d/i6Aohi+50oPw0VrXk/0KLLooe34BA6oRtLDHn2HrAg3A8BfsCchpFt
-xAZL+zvacOAbm/OdLVfLFiZP
+MIICgDCCAemgAwIBAgIBBjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNV90YTExFjAUBgkqhkiG9w0BCQEWB2NoNV90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMV9jaDVfdGExMRowGAYJKoZIhvcNAQkB
+FgtjczFfY2g1X3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuqehYDPr
+WYTmL7AwOLhJl4Y7gk5Raii/Km3TRndn7BBwaSJ/4V16RbWBK9LqfUFc4k3oLQaJ
+HEwXqjz1LzISBIBpUoBKzqFP3HahWtJTQ498+4LrlgbNBYl0NH2ZYrwJZ+kngFt4
+ZQVXyLa0t4NaRrKAbD8FPMZJLXV8SC4iNbcCAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAwtBW3Uq7j/neSUwM
+Qa8pcwf12kRKqgucgDNWzOvFWBT5wsnMky9162z9uHneDTXbRoum1wtZPTXJrGh2
+Y4W9sQMhx1Ol9SKf8MIjft4yb0p72NUtse7brVr5NUZVEVq7a1MhHerETRZcAfWv
+kUe7FsGbcU5bUrXq+dh6U8Dv5/Q=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_cs8_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_cs8_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 25 (0x19)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:46 2011 GMT
-            Not After : Jan  5 22:37:46 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_cs8_ch1_ta3/emailAddress=cs1_cs8_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_cs8_ch1_ta3/emailAddress=cs1_cs8_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a8:89:d6:f6:e1:32:a9:bc:a5:c2:c8:00:1c:a1:
-                    04:fc:93:5a:5c:29:1d:37:7e:29:e1:7f:69:79:24:
-                    ab:05:5a:83:71:d8:3c:bb:e5:1c:b8:e0:5e:a8:bd:
-                    41:06:cb:69:f6:d2:b9:48:c4:93:7c:ae:c6:38:bc:
-                    d7:9a:f2:db:8d:f9:5f:51:c4:1b:d2:c5:0e:57:6d:
-                    0b:73:19:a8:34:e6:5b:81:80:43:77:3a:8e:54:59:
-                    91:69:a9:aa:9f:2b:24:24:1e:06:e8:bc:f2:3f:c3:
-                    ee:33:3f:f4:5f:76:fd:24:05:48:a8:98:2f:15:eb:
-                    16:d5:24:6b:ea:59:e6:06:51
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cc:fd:f6:7a:f6:04:88:b5:e3:ff:6f:ce:2a:01:
+                    89:dd:07:a7:10:5d:ca:76:bf:d2:18:97:80:5a:b1:
+                    b8:6e:6b:bd:6b:65:9a:24:0d:3d:dc:7f:eb:53:1f:
+                    45:9e:9c:61:98:da:18:08:c3:3e:45:de:e0:1e:16:
+                    93:2d:30:a4:e3:52:48:5d:97:80:3d:b9:3e:25:28:
+                    b1:be:17:db:71:57:ba:3f:69:22:3e:83:c7:6f:fe:
+                    69:fd:6d:cf:7a:2f:72:36:8d:85:28:38:50:0f:45:
+                    2f:22:e8:49:04:da:17:d5:a1:15:7e:b6:0e:de:e4:
+                    cc:2f:2a:e2:21:95:08:cb:07
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        27:04:6d:7c:c0:89:81:f7:16:04:e2:f7:f1:4a:3b:60:17:4d:
-        f2:c3:0b:78:32:a5:f0:b4:e4:4e:2e:8e:06:d6:2d:3a:65:33:
-        a1:16:60:47:78:1f:f3:d3:72:c5:c7:43:f8:bb:0e:22:2a:7b:
-        a6:3e:9c:1e:40:c8:71:ff:28:82:0b:d9:93:8c:b9:f6:a2:ca:
-        d5:52:81:b6:b7:a1:20:09:e8:8a:68:e5:24:d1:dd:da:dc:1a:
-        01:3d:e5:77:77:fe:64:f5:b6:14:f9:8b:04:3f:11:7e:62:f5:
-        ee:01:7c:d9:d5:b7:00:19:a9:49:05:94:0b:30:22:63:d2:0d:
-        3e:7a
+         a7:ac:32:bc:eb:2c:bc:b7:f1:f5:7a:e0:5b:34:0f:f0:44:44:
+         c5:9d:19:ca:4d:81:a6:9c:ea:43:be:fb:4f:3c:86:26:cf:f8:
+         a5:d0:9b:4f:65:eb:90:a4:8c:12:54:1c:6b:7a:c8:d2:e5:2b:
+         46:81:23:bc:e2:1a:a7:53:35:ea:fe:a5:e7:d4:d4:12:12:f1:
+         28:65:e0:12:56:36:2e:78:e3:fa:ca:1e:5e:b5:6f:27:39:7a:
+         fd:a0:1c:38:0b:2f:d6:68:24:9f:66:62:ea:28:82:f8:d4:10:
+         40:02:af:d1:91:79:6d:bf:f8:de:d1:45:cd:7d:35:92:69:f3:
+         30:4d
 -----BEGIN CERTIFICATE-----
-MIICjzCCAfigAwIBAgIBGTANBgkqhkiG9w0BAQsFADB4MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEUMBIGA1UEAxQLY3M4X2NoMV90YTMxGjAYBgkqhkiG9w0BCQEWC2Nz
-OF9jaDFfdGEzMB4XDTExMDQxMTIyMzc0NloXDTE0MDEwNTIyMzc0NlowgYAxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MRgwFgYDVQQDFA9jczFfY3M4X2NoMV90YTMxHjAc
-BgkqhkiG9w0BCQEWD2NzMV9jczhfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOB
-jQAwgYkCgYEAqInW9uEyqbylwsgAHKEE/JNaXCkdN34p4X9peSSrBVqDcdg8u+Uc
-uOBeqL1BBstp9tK5SMSTfK7GOLzXmvLbjflfUcQb0sUOV20LcxmoNOZbgYBDdzqO
-VFmRaamqnyskJB4G6LzyP8PuMz/0X3b9JAVIqJgvFesW1SRr6lnmBlECAwEAAaMg
-MB4wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQAD
-gYEAJwRtfMCJgfcWBOL38Uo7YBdN8sMLeDKl8LTkTi6OBtYtOmUzoRZgR3gf89Ny
-xcdD+LsOIip7pj6cHkDIcf8oggvZk4y59qLK1VKBtrehIAnoimjlJNHd2twaAT3l
-d3f+ZPW2FPmLBD8RfmL17gF82dW3ABmpSQWUCzAiY9INPno=
+MIICkTCCAfqgAwIBAgIBGTANBgkqhkiG9w0BAQsFADB5MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxFDASBgNVBAMMC2NzOF9jaDFfdGEzMRowGAYJKoZIhvcNAQkBFgtj
+czhfY2gxX3RhMzAeFw0xMzEyMTMwMDEzMzZaFw0xNjA5MDgwMDEzMzZaMIGBMQsw
+CQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEg
+Q2xhcmExDTALBgNVBAoMBHBrZzUxGDAWBgNVBAMMD2NzMV9jczhfY2gxX3RhMzEe
+MBwGCSqGSIb3DQEJARYPY3MxX2NzOF9jaDFfdGEzMIGfMA0GCSqGSIb3DQEBAQUA
+A4GNADCBiQKBgQDM/fZ69gSIteP/b84qAYndB6cQXcp2v9IYl4Basbhua71rZZok
+DT3cf+tTH0WenGGY2hgIwz5F3uAeFpMtMKTjUkhdl4A9uT4lKLG+F9txV7o/aSI+
+g8dv/mn9bc96L3I2jYUoOFAPRS8i6EkE2hfVoRV+tg7e5MwvKuIhlQjLBwIDAQAB
+oyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsF
+AAOBgQCnrDK86yy8t/H1euBbNA/wRETFnRnKTYGmnOpDvvtPPIYmz/il0JtPZeuQ
+pIwSVBxresjS5StGgSO84hqnUzXq/qXn1NQSEvEoZeASVjYueOP6yh5etW8nOXr9
+oBw4Cy/WaCSfZmLqKIL41BBAAq/RkXltv/je0UXNfTWSafMwTQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta10_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta10_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 46 (0x2e)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta10, CN=localhost/emailAddress=cs1_ta10
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta10, CN=localhost/emailAddress=cs1_ta10
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b2:6d:bc:ff:c2:ff:ef:b8:49:75:6b:8c:d4:5a:
-                    8c:de:94:66:55:60:46:1e:dc:0d:fd:e1:95:62:91:
-                    5c:11:1e:0e:2c:19:e2:e5:97:93:e5:dc:91:28:ac:
-                    83:69:8d:3a:86:2d:a1:e9:e6:17:b1:49:e8:98:49:
-                    af:5d:bb:0e:12:66:53:a2:d7:11:25:cf:1b:71:c2:
-                    f7:ad:50:7b:67:d1:2a:44:99:21:25:44:5f:f4:2d:
-                    a5:15:69:a2:12:ab:41:38:1c:c0:f0:9e:cc:49:30:
-                    91:38:6a:1e:e9:72:0d:f9:aa:0a:b9:32:dd:01:f2:
-                    6b:91:72:f6:4e:84:ab:fa:73
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:da:a5:56:23:b3:4b:c1:5a:2a:3c:95:5e:5e:98:
+                    21:7b:82:e5:7d:87:c2:b0:ef:f4:7c:1d:88:3c:f0:
+                    8d:c0:b3:da:44:fa:3e:1d:87:ca:86:7f:f6:64:5c:
+                    81:7c:4b:98:3b:0e:3e:ac:49:d9:dd:27:67:ef:a1:
+                    a7:b5:25:2e:62:f3:89:de:d4:46:a4:b3:76:16:67:
+                    1a:62:0e:d9:e7:03:67:aa:0a:b7:b2:2c:16:be:e3:
+                    d4:ca:8b:f6:2a:25:49:61:04:64:3b:e2:e5:94:e5:
+                    dc:81:a1:ff:e1:40:fc:e5:ef:3b:70:d0:40:2c:cb:
+                    3c:ea:d7:47:8f:1d:f8:47:3d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,28 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        09:46:77:32:eb:db:bb:3a:3f:98:4c:b7:3b:ae:ed:1e:dc:d8:
-        e6:cd:ea:e7:1d:33:e0:a0:b3:14:18:45:1d:a2:dd:62:ea:6b:
-        47:0d:26:a5:fa:17:10:94:5f:87:1a:3b:97:e1:72:3b:9c:71:
-        a8:b6:1e:33:28:cf:a7:ea:c1:d0:7e:8f:f0:de:80:1b:9f:3f:
-        23:4a:3c:0c:f5:6e:ad:9b:9b:87:32:93:43:c1:5f:4d:3b:23:
-        89:22:27:7d:89:67:f7:e4:e5:3d:48:ae:4d:53:6e:85:81:30:
-        6b:be:d1:dd:4d:f4:16:7d:3f:07:42:fc:f4:6e:86:14:f3:c7:
-        cd:45
+         6a:5b:26:9c:14:d2:2b:37:ba:32:2b:66:b7:a6:de:9f:03:85:
+         63:e7:59:c7:05:1f:72:04:44:01:49:d0:88:a9:23:c7:a0:20:
+         c2:6c:bb:0b:52:06:ee:34:b4:37:af:41:ad:e0:16:8f:8c:3d:
+         04:98:98:62:2f:45:66:57:c4:25:db:3e:16:09:ff:8c:07:63:
+         7e:59:31:24:ed:68:91:2d:b8:2e:3c:91:74:61:7e:8c:5e:e4:
+         5c:3f:9f:ff:05:99:20:78:b9:be:6b:79:e6:aa:91:9e:85:25:
+         07:79:dc:2b:22:dd:19:81:d5:c6:a9:e9:a8:5a:da:c6:09:8e:
+         91:c7
 -----BEGIN CERTIFICATE-----
-MIICmzCCAgSgAwIBAgIBLjANBgkqhkiG9w0BAQsFADB+MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTENMAsGA1UECxMEdGExMDESMBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJ
-KoZIhvcNAQkBFgR0YTEwMB4XDTExMDQxMTIyMzc1NVoXDTE0MDEwNTIyMzc1NVow
-gYYxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpN
-ZW5sbyBQYXJrMQ0wCwYDVQQKEwRwa2c1MREwDwYDVQQLFAhjczFfdGExMDESMBAG
-A1UEAxMJbG9jYWxob3N0MRcwFQYJKoZIhvcNAQkBFghjczFfdGExMDCBnzANBgkq
-hkiG9w0BAQEFAAOBjQAwgYkCgYEAsm28/8L/77hJdWuM1FqM3pRmVWBGHtwN/eGV
-YpFcER4OLBni5ZeT5dyRKKyDaY06hi2h6eYXsUnomEmvXbsOEmZTotcRJc8bccL3
-rVB7Z9EqRJkhJURf9C2lFWmiEqtBOBzA8J7MSTCROGoe6XIN+aoKuTLdAfJrkXL2
-ToSr+nMCAwEAAaMgMB4wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJ
-KoZIhvcNAQELBQADgYEACUZ3Muvbuzo/mEy3O67tHtzY5s3q5x0z4KCzFBhFHaLd
-YuprRw0mpfoXEJRfhxo7l+FyO5xxqLYeMyjPp+rB0H6P8N6AG58/I0o8DPVurZub
-hzKTQ8FfTTsjiSInfYln9+TlPUiuTVNuhYEwa77R3U30Fn0/B0L89G6GFPPHzUU=
+MIICnTCCAgagAwIBAgIBLjANBgkqhkiG9w0BAQsFADB/MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDTALBgNVBAsMBHRhMTAxEjAQBgNVBAMMCWxvY2FsaG9zdDETMBEG
+CSqGSIb3DQEJARYEdGExMDAeFw0xMzEyMTMwMDEzMzlaFw0xNjA5MDgwMDEzMzla
+MIGHMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwL
+U2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxETAPBgNVBAsMCGNzMV90YTEwMRIw
+EAYDVQQDDAlsb2NhbGhvc3QxFzAVBgkqhkiG9w0BCQEWCGNzMV90YTEwMIGfMA0G
+CSqGSIb3DQEBAQUAA4GNADCBiQKBgQDapVYjs0vBWio8lV5emCF7guV9h8Kw7/R8
+HYg88I3As9pE+j4dh8qGf/ZkXIF8S5g7Dj6sSdndJ2fvoae1JS5i84ne1Eaks3YW
+ZxpiDtnnA2eqCreyLBa+49TKi/YqJUlhBGQ74uWU5dyBof/hQPzl7ztw0EAsyzzq
+10ePHfhHPQIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDAN
+BgkqhkiG9w0BAQsFAAOBgQBqWyacFNIrN7oyK2a3pt6fA4Vj51nHBR9yBEQBSdCI
+qSPHoCDCbLsLUgbuNLQ3r0Gt4BaPjD0EmJhiL0VmV8Ql2z4WCf+MB2N+WTEk7WiR
+LbguPJF0YX6MXuRcP5//BZkgeLm+a3nmqpGehSUHedwrIt0ZgdXGqemoWtrGCY6R
+xw==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta11_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta11_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 47 (0x2f)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta11, CN=localhost/emailAddress=cs1_ta11
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta11, CN=localhost/emailAddress=cs1_ta11
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d0:21:b2:10:04:9f:9c:ed:82:b7:0e:98:3f:b6:
-                    27:97:24:74:1d:88:1e:42:29:bc:3b:1b:91:a5:92:
-                    4f:80:2a:81:05:71:2f:1b:3f:49:92:d1:9e:bf:e8:
-                    39:a8:6f:81:0d:53:20:04:fa:33:32:b7:96:3e:66:
-                    f7:85:d4:4d:32:e7:11:3e:aa:2f:3a:40:3f:28:97:
-                    b3:ee:9f:5d:b2:4c:e1:5e:7d:2e:d1:4f:ec:ff:b4:
-                    34:b4:64:b9:56:ed:2b:59:5c:e0:c5:e1:91:66:20:
-                    f2:56:9d:6e:55:69:60:38:6d:8a:c3:8d:d6:b9:30:
-                    37:ac:ed:eb:bf:ed:46:b7:5f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:e3:10:e4:f8:44:64:45:ea:54:25:0d:8e:5f:f7:
+                    1c:bb:80:f5:1e:af:19:dd:ba:30:fa:1b:6c:3e:00:
+                    9e:38:09:c8:e6:1a:5c:3f:4e:46:51:7d:2c:5e:82:
+                    5b:2d:03:5a:f3:30:da:fc:0b:45:2e:c2:4a:0a:a5:
+                    78:68:c5:81:d9:bb:b6:83:fc:90:64:0e:13:5d:75:
+                    d1:79:9c:38:11:15:f1:7a:98:70:3d:3d:65:a7:65:
+                    c4:c7:de:fb:70:02:81:0d:61:1c:f8:77:0d:c6:22:
+                    41:91:c9:11:24:5a:5a:cc:f3:30:2f:22:47:fd:8a:
+                    13:82:7a:c8:c2:3e:5e:78:57
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,28 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        6a:b0:56:90:12:50:3d:5b:96:88:2c:f3:fc:67:2b:ed:07:84:
-        f7:f6:34:e6:51:b4:fb:67:15:0f:88:65:f5:34:3c:53:9b:ab:
-        a4:fc:fd:06:96:f3:de:8f:2c:89:fd:26:41:20:cf:21:03:3b:
-        17:0c:8b:7b:f1:a9:85:8d:a7:f5:58:5a:58:a1:e4:fa:dc:b2:
-        3b:23:d6:ae:bc:f9:b9:34:5c:f2:00:49:9e:e7:f6:a7:60:ff:
-        1b:22:50:db:80:1a:c8:81:40:bc:00:ee:4b:44:ef:4b:d0:13:
-        b0:a2:e7:fb:03:e9:aa:39:7a:aa:00:f0:75:30:9c:31:8e:c8:
-        75:13
+         c2:e6:3c:ec:dd:c1:5d:d6:c9:2d:01:2a:7c:75:25:36:29:e1:
+         96:73:4b:4d:4c:09:76:f1:a0:f1:c0:1e:d3:d4:ba:16:22:68:
+         e7:3a:ba:31:7f:ac:67:69:4f:97:f8:f3:68:fa:6f:78:d6:cf:
+         86:e3:56:f0:f7:23:f9:f8:89:77:60:5a:06:af:d0:c8:34:b5:
+         07:23:be:97:03:8d:00:af:c3:43:26:46:24:97:03:e9:2e:74:
+         a3:31:92:bd:cb:b6:2a:c3:0e:df:b1:22:45:42:bf:45:fc:1f:
+         d9:49:66:22:77:90:08:a6:0c:2d:d7:0a:29:7f:be:7e:01:8b:
+         a8:99
 -----BEGIN CERTIFICATE-----
-MIICmzCCAgSgAwIBAgIBLzANBgkqhkiG9w0BAQsFADB+MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTENMAsGA1UECxMEdGExMTESMBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJ
-KoZIhvcNAQkBFgR0YTExMB4XDTExMDQxMTIyMzc1NVoXDTE0MDEwNTIyMzc1NVow
-gYYxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpN
-ZW5sbyBQYXJrMQ0wCwYDVQQKEwRwa2c1MREwDwYDVQQLFAhjczFfdGExMTESMBAG
-A1UEAxMJbG9jYWxob3N0MRcwFQYJKoZIhvcNAQkBFghjczFfdGExMTCBnzANBgkq
-hkiG9w0BAQEFAAOBjQAwgYkCgYEA0CGyEASfnO2Ctw6YP7YnlyR0HYgeQim8OxuR
-pZJPgCqBBXEvGz9JktGev+g5qG+BDVMgBPozMreWPmb3hdRNMucRPqovOkA/KJez
-7p9dskzhXn0u0U/s/7Q0tGS5Vu0rWVzgxeGRZiDyVp1uVWlgOG2Kw43WuTA3rO3r
-v+1Gt18CAwEAAaMgMB4wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwDQYJ
-KoZIhvcNAQELBQADgYEAarBWkBJQPVuWiCzz/Gcr7QeE9/Y05lG0+2cVD4hl9TQ8
-U5urpPz9Bpbz3o8sif0mQSDPIQM7FwyLe/GphY2n9VhaWKHk+tyyOyPWrrz5uTRc
-8gBJnuf2p2D/GyJQ24AayIFAvADuS0TvS9ATsKLn+wPpqjl6qgDwdTCcMY7IdRM=
+MIICnTCCAgagAwIBAgIBLzANBgkqhkiG9w0BAQsFADB/MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDTALBgNVBAsMBHRhMTExEjAQBgNVBAMMCWxvY2FsaG9zdDETMBEG
+CSqGSIb3DQEJARYEdGExMTAeFw0xMzEyMTMwMDEzMzlaFw0xNjA5MDgwMDEzMzla
+MIGHMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwL
+U2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUxETAPBgNVBAsMCGNzMV90YTExMRIw
+EAYDVQQDDAlsb2NhbGhvc3QxFzAVBgkqhkiG9w0BCQEWCGNzMV90YTExMIGfMA0G
+CSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjEOT4RGRF6lQlDY5f9xy7gPUerxndujD6
+G2w+AJ44CcjmGlw/TkZRfSxeglstA1rzMNr8C0UuwkoKpXhoxYHZu7aD/JBkDhNd
+ddF5nDgRFfF6mHA9PWWnZcTH3vtwAoENYRz4dw3GIkGRyREkWlrM8zAvIkf9ihOC
+esjCPl54VwIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDAN
+BgkqhkiG9w0BAQsFAAOBgQDC5jzs3cFd1sktASp8dSU2KeGWc0tNTAl28aDxwB7T
+1LoWImjnOroxf6xnaU+X+PNo+m941s+G41bw9yP5+Il3YFoGr9DINLUHI76XA40A
+r8NDJkYklwPpLnSjMZK9y7Yqww7fsSJFQr9F/B/ZSWYid5AIpgwt1wopf75+AYuo
+mQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta2_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta2_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 15 (0xf)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta2/emailAddress=ta2
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta2/emailAddress=ta2
         Validity
-            Not Before: Apr 11 22:37:43 2011 GMT
-            Not After : Jan  5 22:37:43 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs1_ta2/emailAddress=cs1_ta2
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs1_ta2/emailAddress=cs1_ta2
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e7:3a:08:5d:d7:3d:c8:50:43:ad:92:87:40:58:
-                    59:5c:fa:34:ba:c9:bd:5b:d7:9f:17:b8:4f:d2:15:
-                    fd:86:d9:f0:3a:07:48:14:f3:c0:a4:9e:e3:ee:00:
-                    45:ba:aa:de:3a:5c:53:d6:0d:dd:46:88:d3:b6:13:
-                    aa:ee:f8:c0:3e:fa:eb:0a:6d:4a:0d:f7:39:21:ff:
-                    5d:dc:d7:13:5b:2a:e9:e4:c0:1e:31:2b:5b:00:ce:
-                    b0:55:44:72:97:66:06:ab:41:71:05:4a:83:6b:3b:
-                    cf:a7:ce:5d:61:43:3b:bb:60:19:c4:33:ac:23:72:
-                    66:9d:e9:72:be:bd:6c:ad:2b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:be:2d:d1:b2:aa:38:aa:c1:4f:f3:f7:07:f2:f3:
+                    30:0c:6d:f7:13:ed:c3:c7:c8:f8:87:8d:ea:a3:49:
+                    cf:74:dd:30:1b:1f:9d:a6:8e:b7:eb:fa:f5:f7:e5:
+                    e0:05:9a:e4:b1:ed:2d:ee:ff:f8:ab:23:9a:f3:24:
+                    ad:99:26:83:4d:e7:35:b7:c8:b1:60:3d:0c:44:e9:
+                    2c:24:50:ee:86:5c:f0:ba:61:34:5d:f9:6c:a3:b7:
+                    e3:16:0e:90:35:9e:05:15:99:32:ff:50:de:b5:e0:
+                    66:88:e6:d5:0b:ae:16:a9:91:f5:86:c4:23:c9:7e:
+                    f1:9d:2b:86:43:e6:fb:c1:a5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        49:7b:52:fd:1f:be:ee:30:38:0d:93:6b:07:01:95:14:35:6e:
-        5b:dd:74:9e:a0:a7:1a:bd:a8:cd:35:a9:7f:21:af:d7:a2:0c:
-        69:f9:d4:d0:eb:45:93:e2:48:fd:86:b4:70:fb:b5:dd:e5:48:
-        5f:93:d4:41:7a:cb:a5:73:02:d8:d9:e8:5f:9c:f8:4f:ad:50:
-        fb:88:24:b3:f5:e0:cf:d9:3e:bf:3f:5b:0c:db:a0:20:51:5d:
-        ea:13:0b:5b:44:6d:af:0f:6a:72:b6:25:8c:9f:bd:d0:a9:0e:
-        38:60:39:53:7e:9d:6e:ac:65:21:9a:32:f4:57:65:39:dc:f7:
-        36:9a
+         10:82:e5:2b:f8:67:14:0c:22:0d:f4:4e:17:c5:d5:7f:3d:fa:
+         24:2a:ad:33:47:ff:2a:f5:37:f6:83:81:2f:32:df:01:18:80:
+         7a:00:0b:f5:37:f9:eb:de:b0:38:cc:38:94:94:83:76:38:bb:
+         0e:0a:72:9b:2c:87:ce:8c:46:ef:68:f4:e0:a9:2f:cc:28:53:
+         c3:ac:63:7d:2b:87:fb:76:7b:9e:98:c6:0e:80:9e:80:4e:40:
+         b8:1e:2c:8b:c1:8b:cd:13:58:16:ea:aa:a0:0e:b6:b8:4b:a7:
+         74:a1:0d:d9:41:70:44:1e:19:d2:25:4b:b1:52:65:40:32:b0:
+         5d:3d
 -----BEGIN CERTIFICATE-----
-MIICbjCCAdegAwIBAgIBDzANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UEAxMDdGEyMRIwEAYJKoZIhvcNAQkBFgN0YTIwHhcNMTEw
-NDExMjIzNzQzWhcNMTQwMTA1MjIzNzQzWjBwMQswCQYDVQQGEwJVUzETMBEGA1UE
-CBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtn
-NTEQMA4GA1UEAxQHY3MxX3RhMjEWMBQGCSqGSIb3DQEJARYHY3MxX3RhMjCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA5zoIXdc9yFBDrZKHQFhZXPo0usm9W9ef
-F7hP0hX9htnwOgdIFPPApJ7j7gBFuqreOlxT1g3dRojTthOq7vjAPvrrCm1KDfc5
-If9d3NcTWyrp5MAeMStbAM6wVURyl2YGq0FxBUqDazvPp85dYUM7u2AZxDOsI3Jm
-nelyvr1srSsCAwEAAaMgMB4wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCB4Aw
-DQYJKoZIhvcNAQELBQADgYEASXtS/R++7jA4DZNrBwGVFDVuW910nqCnGr2ozTWp
-fyGv16IMafnU0OtFk+JI/Ya0cPu13eVIX5PUQXrLpXMC2NnoX5z4T61Q+4gks/Xg
-z9k+vz9bDNugIFFd6hMLW0Rtrw9qcrYljJ+90KkOOGA5U36dbqxlIZoy9FdlOdz3
-Npo=
+MIICcDCCAdmgAwIBAgIBDzANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAMMA3RhMjESMBAGCSqGSIb3DQEJARYDdGEyMB4XDTEz
+MTIxMzAwMTMzNVoXDTE2MDkwODAwMTMzNVowcTELMAkGA1UEBhMCVVMxEzARBgNV
+BAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARw
+a2c1MRAwDgYDVQQDDAdjczFfdGEyMRYwFAYJKoZIhvcNAQkBFgdjczFfdGEyMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+LdGyqjiqwU/z9wfy8zAMbfcT7cPH
+yPiHjeqjSc903TAbH52mjrfr+vX35eAFmuSx7S3u//irI5rzJK2ZJoNN5zW3yLFg
+PQxE6SwkUO6GXPC6YTRd+Wyjt+MWDpA1ngUVmTL/UN614GaI5tULrhapkfWGxCPJ
+fvGdK4ZD5vvBpQIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIH
+gDANBgkqhkiG9w0BAQsFAAOBgQAQguUr+GcUDCIN9E4XxdV/PfokKq0zR/8q9Tf2
+g4EvMt8BGIB6AAv1N/nr3rA4zDiUlIN2OLsOCnKbLIfOjEbvaPTgqS/MKFPDrGN9
+K4f7dnuemMYOgJ6ATkC4HiyLwYvNE1gW6qqgDra4S6d0oQ3ZQXBEHhnSJUuxUmVA
+MrBdPQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta6_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta6_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 42 (0x2a)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta6, CN=localhost/emailAddress=cs1_ta6
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta6, CN=localhost/emailAddress=cs1_ta6
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e1:f0:66:24:db:fa:5f:00:b6:c4:f6:63:f0:51:
-                    7d:49:f9:92:71:e1:b3:8c:e7:fc:e9:e4:4f:79:76:
-                    52:51:06:65:c1:5f:d4:51:26:30:46:c9:70:98:5a:
-                    c5:a9:9e:6a:67:24:25:7a:68:5b:63:af:90:e7:b1:
-                    fb:42:f9:15:9c:d4:41:c6:90:fd:c3:d3:d7:cf:fe:
-                    00:c6:39:cb:6c:ae:9c:cb:74:c4:b6:1f:be:1b:58:
-                    9f:c9:8a:33:66:ec:32:08:fc:d9:23:e1:29:e2:f3:
-                    3e:3d:53:a7:78:e7:69:49:2b:39:72:8b:74:33:46:
-                    b1:f7:3b:26:4f:8d:06:64:e7
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:e0:47:5b:b6:ff:33:b8:75:5d:d1:f8:31:47:d7:
+                    46:c1:12:4e:d3:95:54:a2:cd:d8:c0:19:35:21:ea:
+                    03:c3:73:e0:e0:50:a1:10:2e:cd:9a:a5:8a:b0:b9:
+                    2e:66:ad:2d:09:3f:38:42:ec:2f:bd:c2:d0:16:90:
+                    82:d0:1c:a9:c7:81:4c:3f:9d:c8:f5:6d:ca:38:04:
+                    c2:9e:77:3c:1f:0b:9f:4b:d2:ca:df:a2:af:f0:4e:
+                    b8:51:e1:2c:01:4b:a7:b7:56:6c:ee:96:22:2f:2f:
+                    33:83:e2:c1:a5:c0:aa:e5:45:2b:50:31:84:8a:d0:
+                    5b:06:0a:2f:5d:c3:d6:d5:1b
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        6b:e1:7e:83:a6:a1:f8:46:a6:85:bb:c7:25:20:83:bb:b4:e0:
-        58:63:36:5a:97:1c:4c:76:24:a2:9d:c3:45:73:1f:22:39:97:
-        2c:47:b1:f5:3e:ac:b4:00:6d:c5:32:49:0c:83:e9:94:44:fa:
-        d6:e1:2d:a7:ae:66:34:9c:85:3e:a4:43:af:c0:2a:6c:f9:22:
-        64:d2:bb:54:67:e8:99:df:41:f2:7c:87:77:67:b5:3d:14:37:
-        75:32:56:69:21:f2:53:f2:d2:83:a1:fc:c0:3d:b5:4e:b5:d8:
-        06:d8:4e:71:f8:cc:3c:3a:93:a4:a0:05:a3:4f:7b:b1:83:21:
-        96:60
+         36:42:59:49:7a:7a:58:88:a3:c2:e9:16:fc:dc:5c:7c:26:2e:
+         d5:ff:4f:2f:45:96:7f:c0:5a:10:fd:a5:c5:18:95:48:b3:bf:
+         49:a0:a1:4d:70:e0:39:00:94:5d:7c:0b:99:dc:7d:29:57:40:
+         7a:31:67:94:00:83:61:aa:ca:48:7f:64:db:81:90:3c:2a:e4:
+         26:33:3e:80:14:12:85:06:bc:e9:8b:e2:49:80:bd:e7:a4:f0:
+         3a:c7:ba:e8:c0:1f:f2:7a:48:af:aa:ba:20:be:b2:e8:99:4d:
+         66:90:34:78:b1:82:9a:90:15:a8:dc:76:8d:27:df:7b:40:04:
+         a1:03
 -----BEGIN CERTIFICATE-----
-MIIClzCCAgCgAwIBAgIBKjANBgkqhkiG9w0BAQsFADB8MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UECxMDdGE2MRIwEAYDVQQDEwlsb2NhbGhvc3QxEjAQBgkq
-hkiG9w0BCQEWA3RhNjAeFw0xMTA0MTEyMjM3NTRaFw0xNDAxMDUyMjM3NTRaMIGE
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UECxQHY3MxX3RhNjESMBAGA1UE
-AxMJbG9jYWxob3N0MRYwFAYJKoZIhvcNAQkBFgdjczFfdGE2MIGfMA0GCSqGSIb3
-DQEBAQUAA4GNADCBiQKBgQDh8GYk2/pfALbE9mPwUX1J+ZJx4bOM5/zp5E95dlJR
-BmXBX9RRJjBGyXCYWsWpnmpnJCV6aFtjr5DnsftC+RWc1EHGkP3D09fP/gDGOcts
-rpzLdMS2H74bWJ/JijNm7DII/Nkj4Sni8z49U6d452lJKzlyi3QzRrH3OyZPjQZk
-5wIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG
-9w0BAQsFAAOBgQBr4X6DpqH4RqaFu8clIIO7tOBYYzZalxxMdiSincNFcx8iOZcs
-R7H1Pqy0AG3FMkkMg+mURPrW4S2nrmY0nIU+pEOvwCps+SJk0rtUZ+iZ30HyfId3
-Z7U9FDd1MlZpIfJT8tKDofzAPbVOtdgG2E5x+Mw8OpOkoAWjT3uxgyGWYA==
+MIICmTCCAgKgAwIBAgIBKjANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAsMA3RhNjESMBAGA1UEAwwJbG9jYWxob3N0MRIwEAYJ
+KoZIhvcNAQkBFgN0YTYwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjCB
+hTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1Nh
+bnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQLDAdjczFfdGE2MRIwEAYD
+VQQDDAlsb2NhbGhvc3QxFjAUBgkqhkiG9w0BCQEWB2NzMV90YTYwgZ8wDQYJKoZI
+hvcNAQEBBQADgY0AMIGJAoGBAOBHW7b/M7h1XdH4MUfXRsESTtOVVKLN2MAZNSHq
+A8Nz4OBQoRAuzZqlirC5LmatLQk/OELsL73C0BaQgtAcqceBTD+dyPVtyjgEwp53
+PB8Ln0vSyt+ir/BOuFHhLAFLp7dWbO6WIi8vM4PiwaXAquVFK1AxhIrQWwYKL13D
+1tUbAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgeAMA0GCSqG
+SIb3DQEBCwUAA4GBADZCWUl6eliIo8LpFvzcXHwmLtX/Ty9Fln/AWhD9pcUYlUiz
+v0mgoU1w4DkAlF18C5ncfSlXQHoxZ5QAg2Gqykh/ZNuBkDwq5CYzPoAUEoUGvOmL
+4kmAveek8DrHuujAH/J6SK+quiC+suiZTWaQNHixgpqQFajcdo0n33tABKED
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta7_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta7_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 43 (0x2b)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta7, CN=localhost/emailAddress=cs1_ta7
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta7, CN=localhost/emailAddress=cs1_ta7
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c1:8e:b8:0a:bd:17:40:c0:8d:b3:6f:c3:ca:97:
-                    ca:b0:b6:95:01:9c:d8:a0:f3:9f:af:2e:c8:3f:0b:
-                    54:f3:f0:c6:ae:41:d0:b5:73:4d:6e:b3:93:f9:58:
-                    99:86:b4:66:21:2d:9f:78:ad:47:eb:81:78:5d:21:
-                    2e:19:38:7a:73:64:5e:c9:8f:5c:1c:f5:92:b9:5f:
-                    2f:f3:de:e7:a3:8c:8a:cb:d1:b2:00:ed:7c:24:a8:
-                    10:d2:2c:eb:32:7c:48:23:fe:c2:9d:41:b5:07:d7:
-                    52:aa:e9:20:d3:2a:63:60:c4:1a:60:27:05:28:ae:
-                    4f:88:fd:ba:8e:ff:02:c7:47
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d6:44:f3:0b:4a:01:1a:b9:6e:5a:01:90:e2:1d:
+                    39:37:48:16:5d:16:fe:7b:69:47:f0:e2:bb:e0:5b:
+                    e9:22:6c:cc:7c:2c:8a:0d:74:6d:30:f5:f5:83:b8:
+                    b5:87:7a:c1:0c:0a:5a:17:6e:dc:21:53:9f:8b:02:
+                    84:b0:45:9f:67:31:30:61:ff:1a:62:c2:a9:94:b4:
+                    f9:70:57:0d:03:af:a1:00:59:be:15:5c:08:75:e0:
+                    56:4d:30:ea:02:d0:8a:f1:2c:dd:fa:74:cc:f3:98:
+                    15:ae:1a:e0:c0:72:64:0a:26:b6:e2:04:17:24:5d:
+                    58:60:ac:01:a7:73:03:71:ef
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        b5:06:5c:d4:ad:4f:c3:e4:99:0c:07:e7:dd:33:09:94:42:7d:
-        8a:c8:04:56:c8:63:a0:be:4b:a7:60:52:e4:13:ef:82:bd:ce:
-        9f:4f:91:ee:e8:0e:09:35:e6:eb:c2:e3:da:78:8d:4e:a2:b4:
-        e5:f0:4c:99:29:02:0f:a8:b8:49:56:f8:d9:a3:4b:c7:bb:ce:
-        ba:63:78:ed:36:f9:34:6a:b8:9d:06:9b:ff:5e:e9:48:0e:b3:
-        39:d7:64:e5:c9:28:c8:3c:8f:42:52:08:56:ad:6d:f0:63:aa:
-        30:45:d4:40:17:34:be:24:4e:21:7a:b5:b3:2a:c7:ce:75:1b:
-        a5:eb
+         31:3b:0b:62:1c:06:94:b3:85:8c:08:b8:da:07:20:01:4c:23:
+         98:34:20:06:f4:ec:b9:fb:42:52:80:2c:0f:e9:91:b7:de:3f:
+         c4:42:4a:d7:22:0a:9b:ec:83:a0:1f:64:57:98:e9:1a:e1:ac:
+         08:78:ee:28:05:c1:53:50:3e:d1:e0:fa:55:9a:a0:ca:39:28:
+         9f:71:8b:ab:9d:a6:3e:04:e9:bf:b3:4d:97:74:b2:36:4e:65:
+         ed:cf:5c:44:3c:c1:37:77:1c:d3:7d:3b:76:fe:72:53:ac:90:
+         0a:07:37:b0:97:64:ab:b4:d3:63:28:ce:37:cf:80:26:8a:7e:
+         0b:f0
 -----BEGIN CERTIFICATE-----
-MIIClzCCAgCgAwIBAgIBKzANBgkqhkiG9w0BAQsFADB8MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UECxMDdGE3MRIwEAYDVQQDEwlsb2NhbGhvc3QxEjAQBgkq
-hkiG9w0BCQEWA3RhNzAeFw0xMTA0MTEyMjM3NTRaFw0xNDAxMDUyMjM3NTRaMIGE
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UECxQHY3MxX3RhNzESMBAGA1UE
-AxMJbG9jYWxob3N0MRYwFAYJKoZIhvcNAQkBFgdjczFfdGE3MIGfMA0GCSqGSIb3
-DQEBAQUAA4GNADCBiQKBgQDBjrgKvRdAwI2zb8PKl8qwtpUBnNig85+vLsg/C1Tz
-8MauQdC1c01us5P5WJmGtGYhLZ94rUfrgXhdIS4ZOHpzZF7Jj1wc9ZK5Xy/z3uej
-jIrL0bIA7XwkqBDSLOsyfEgj/sKdQbUH11Kq6SDTKmNgxBpgJwUork+I/bqO/wLH
-RwIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG
-9w0BAQsFAAOBgQC1BlzUrU/D5JkMB+fdMwmUQn2KyARWyGOgvkunYFLkE++Cvc6f
-T5Hu6A4JNebrwuPaeI1OorTl8EyZKQIPqLhJVvjZo0vHu866Y3jtNvk0aridBpv/
-XulIDrM512TlySjIPI9CUghWrW3wY6owRdRAFzS+JE4herWzKsfOdRul6w==
+MIICmTCCAgKgAwIBAgIBKzANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAsMA3RhNzESMBAGA1UEAwwJbG9jYWxob3N0MRIwEAYJ
+KoZIhvcNAQkBFgN0YTcwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjCB
+hTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1Nh
+bnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQLDAdjczFfdGE3MRIwEAYD
+VQQDDAlsb2NhbGhvc3QxFjAUBgkqhkiG9w0BCQEWB2NzMV90YTcwgZ8wDQYJKoZI
+hvcNAQEBBQADgY0AMIGJAoGBANZE8wtKARq5bloBkOIdOTdIFl0W/ntpR/Diu+Bb
+6SJszHwsig10bTD19YO4tYd6wQwKWhdu3CFTn4sChLBFn2cxMGH/GmLCqZS0+XBX
+DQOvoQBZvhVcCHXgVk0w6gLQivEs3fp0zPOYFa4a4MByZAomtuIEFyRdWGCsAadz
+A3HvAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgeAMA0GCSqG
+SIb3DQEBCwUAA4GBADE7C2IcBpSzhYwIuNoHIAFMI5g0IAb07Ln7QlKALA/pkbfe
+P8RCStciCpvsg6AfZFeY6RrhrAh47igFwVNQPtHg+lWaoMo5KJ9xi6udpj4E6b+z
+TZd0sjZOZe3PXEQ8wTd3HNN9O3b+clOskAoHN7CXZKu002MozjfPgCaKfgvw
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta8_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta8_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 44 (0x2c)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta8, CN=localhost/emailAddress=cs1_ta8
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta8, CN=localhost/emailAddress=cs1_ta8
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e7:a7:dd:2e:a7:89:c3:cc:da:a2:8b:bd:3b:ba:
-                    bc:66:6a:cd:65:00:60:70:55:8c:f0:b7:89:c3:fc:
-                    97:42:5c:cb:2c:f5:0a:1c:55:c7:79:b7:b9:28:30:
-                    f4:9a:a4:e0:31:e5:52:df:f4:40:85:49:8e:fc:08:
-                    a5:05:44:ed:b7:6e:00:0b:a7:2d:a1:2c:47:95:18:
-                    dc:5e:d0:c4:24:3d:4c:a7:cb:76:91:fb:00:89:2a:
-                    3f:7f:ab:f1:5e:b7:cb:24:6e:42:19:4d:d8:a7:12:
-                    83:c1:8c:b6:fb:02:f0:9c:1f:51:c3:c5:49:ed:a7:
-                    6e:09:bb:11:2f:a5:3f:00:d5
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:eb:76:dd:67:17:86:2d:82:c1:49:8d:1e:fd:34:
+                    12:74:70:5b:bd:91:50:64:4f:53:48:65:85:cf:0d:
+                    a6:8b:54:ca:a4:4f:58:fc:5e:b8:e9:ce:61:7c:8e:
+                    04:0c:06:e8:4a:66:9f:77:d3:5c:ed:2e:b0:d7:c6:
+                    61:14:d4:33:8c:5e:71:1a:1a:0a:c9:e5:90:23:7d:
+                    9c:c5:f8:42:e1:13:40:6b:e2:20:ab:04:c1:80:b4:
+                    1b:03:de:6d:b5:99:03:34:28:b2:db:ca:32:00:ac:
+                    b8:36:4d:da:3c:33:8b:89:aa:4b:78:c5:9b:64:aa:
+                    74:7d:65:ff:86:11:ad:cd:15
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        b3:c8:ea:1e:23:23:a9:77:46:ae:c3:1c:cf:43:81:80:aa:a6:
-        fb:25:ec:a2:fa:d5:c3:e9:1e:c7:78:e1:cc:a4:d7:3f:08:2f:
-        5f:58:05:b8:d4:0b:c7:87:2e:93:f6:c5:cb:17:31:e3:fa:88:
-        a3:0d:8d:4b:39:2b:96:dd:4d:21:91:37:e9:e7:f5:87:12:0f:
-        4e:77:8f:f2:e0:ab:ed:39:76:69:e4:ee:bb:1a:eb:cf:50:a5:
-        3b:23:42:74:1e:e0:00:56:ff:8f:7e:7d:97:04:9e:fc:25:a7:
-        2a:ee:e7:6c:44:21:68:d3:39:79:e2:ac:02:38:a0:ad:dc:c1:
-        32:f0
+         37:1a:ca:2a:23:42:8d:36:41:51:8d:64:97:c6:51:e2:aa:c9:
+         b8:68:c0:20:40:23:1f:1a:db:9b:4b:65:39:f1:60:48:6f:e1:
+         c5:30:57:f3:02:35:f2:07:37:ea:a4:42:45:1c:6a:57:71:8b:
+         71:1a:ee:16:1e:03:e7:8a:c4:92:90:2f:82:ee:b2:cd:bd:39:
+         df:3d:e7:d0:1b:bd:82:58:e1:a6:29:bd:4d:b3:40:a4:35:c1:
+         e0:13:6f:ab:0c:1e:f2:7c:b2:8d:03:5c:fa:1a:e7:f0:76:1a:
+         84:a0:ec:c5:eb:c4:ac:7e:cf:35:11:36:5e:04:06:5c:4c:e2:
+         76:22
 -----BEGIN CERTIFICATE-----
-MIIClzCCAgCgAwIBAgIBLDANBgkqhkiG9w0BAQsFADB8MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UECxMDdGE4MRIwEAYDVQQDEwlsb2NhbGhvc3QxEjAQBgkq
-hkiG9w0BCQEWA3RhODAeFw0xMTA0MTEyMjM3NTRaFw0xNDAxMDUyMjM3NTRaMIGE
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UECxQHY3MxX3RhODESMBAGA1UE
-AxMJbG9jYWxob3N0MRYwFAYJKoZIhvcNAQkBFgdjczFfdGE4MIGfMA0GCSqGSIb3
-DQEBAQUAA4GNADCBiQKBgQDnp90up4nDzNqii707urxmas1lAGBwVYzwt4nD/JdC
-XMss9QocVcd5t7koMPSapOAx5VLf9ECFSY78CKUFRO23bgALpy2hLEeVGNxe0MQk
-PUyny3aR+wCJKj9/q/Fet8skbkIZTdinEoPBjLb7AvCcH1HDxUntp24JuxEvpT8A
-1QIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG
-9w0BAQsFAAOBgQCzyOoeIyOpd0auwxzPQ4GAqqb7Jeyi+tXD6R7HeOHMpNc/CC9f
-WAW41AvHhy6T9sXLFzHj+oijDY1LOSuW3U0hkTfp5/WHEg9Od4/y4KvtOXZp5O67
-GuvPUKU7I0J0HuAAVv+Pfn2XBJ78Jacq7udsRCFo0zl54qwCOKCt3MEy8A==
+MIICmTCCAgKgAwIBAgIBLDANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAsMA3RhODESMBAGA1UEAwwJbG9jYWxob3N0MRIwEAYJ
+KoZIhvcNAQkBFgN0YTgwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjCB
+hTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1Nh
+bnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQLDAdjczFfdGE4MRIwEAYD
+VQQDDAlsb2NhbGhvc3QxFjAUBgkqhkiG9w0BCQEWB2NzMV90YTgwgZ8wDQYJKoZI
+hvcNAQEBBQADgY0AMIGJAoGBAOt23WcXhi2CwUmNHv00EnRwW72RUGRPU0hlhc8N
+potUyqRPWPxeuOnOYXyOBAwG6Epmn3fTXO0usNfGYRTUM4xecRoaCsnlkCN9nMX4
+QuETQGviIKsEwYC0GwPebbWZAzQostvKMgCsuDZN2jwzi4mqS3jFm2SqdH1l/4YR
+rc0VAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgeAMA0GCSqG
+SIb3DQEBCwUAA4GBADcayiojQo02QVGNZJfGUeKqybhowCBAIx8a25tLZTnxYEhv
+4cUwV/MCNfIHN+qkQkUcaldxi3Ea7hYeA+eKxJKQL4Luss29Od8959AbvYJY4aYp
+vU2zQKQ1weATb6sMHvJ8so0DXPoa5/B2GoSg7MXrxKx+zzURNl4EBlxM4nYi
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta9_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs1_ta9_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 45 (0x2d)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=cs1_ta9, CN=localhost/emailAddress=cs1_ta9
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=cs1_ta9, CN=localhost/emailAddress=cs1_ta9
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a6:51:e1:02:04:84:16:9a:a9:17:63:51:f6:f2:
-                    b9:d4:54:53:8d:71:8b:2f:98:f8:0e:a8:fb:41:f4:
-                    7a:d3:74:9d:35:5b:58:e3:c8:46:13:86:67:8f:aa:
-                    9d:b0:c0:9e:0d:17:4a:f4:48:76:43:3e:ce:34:b6:
-                    d3:90:6d:77:42:ad:dc:50:aa:17:82:a4:0e:17:67:
-                    d7:b7:a2:11:ce:23:90:b2:24:1c:13:4d:f1:fb:33:
-                    e6:f1:e7:54:09:ae:ad:cb:27:e8:ae:0b:fc:d9:14:
-                    cd:c5:93:db:95:1f:13:cb:16:c0:a7:46:a3:66:53:
-                    8e:24:df:26:85:f1:72:27:03
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:a0:f2:5b:a5:e0:85:79:27:38:34:98:e1:0c:74:
+                    ac:c0:52:24:c6:8c:bb:1b:a3:12:cc:ef:97:2e:e7:
+                    ed:89:07:47:14:e6:04:70:03:ce:72:79:3a:f6:e4:
+                    9d:31:97:0c:7b:de:9f:99:a8:d4:7d:ea:69:03:12:
+                    87:89:20:d9:62:0d:bc:c9:29:cb:8a:5b:61:25:86:
+                    a2:a5:6e:50:6d:8d:56:ac:cc:05:41:4f:c9:ba:94:
+                    a4:34:0d:95:d9:82:98:bc:b0:6c:4e:39:ea:09:21:
+                    7a:ba:69:7f:fb:94:f5:37:93:b5:a8:c1:bc:1b:8c:
+                    7e:00:33:a8:b0:90:0f:9c:df
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        cb:2d:8d:51:65:6e:b3:e4:70:dd:e3:ac:40:35:41:f2:b2:69:
-        35:50:32:f1:04:6d:94:f6:ff:32:5a:77:22:d3:6f:8f:57:87:
-        7f:5a:ac:99:a4:8c:2a:e9:b5:1c:5b:58:ea:f7:63:b6:e3:8a:
-        c7:b2:9e:e3:37:e7:8c:c5:01:0a:0c:a6:48:31:6e:0a:d4:6d:
-        ec:da:77:07:a9:3c:ea:87:b7:5a:58:39:a7:37:00:ee:5b:8c:
-        a6:53:d9:b9:59:85:48:51:ea:49:cd:5b:ec:a6:ea:e7:07:dc:
-        5e:7e:79:db:e7:d6:be:94:ec:91:64:3c:ae:16:8d:a5:80:29:
-        48:39
+         5e:f9:9a:f9:3a:51:06:d4:4c:3b:1b:97:af:6f:28:7d:ce:f2:
+         78:9c:bf:d0:7c:1d:00:20:dd:84:58:e5:29:ba:51:a8:7c:30:
+         54:ff:d0:f3:25:2c:5d:19:4d:17:ca:e7:3e:f3:09:af:cf:82:
+         3d:d9:5c:c0:fc:e6:31:19:52:70:4f:17:12:0f:e1:c8:e0:22:
+         d1:10:db:a5:0e:75:3c:fb:33:ee:e9:ab:95:44:93:96:9e:7e:
+         c3:fa:14:2d:a3:ee:a0:35:af:b4:d9:63:c5:c2:77:18:23:01:
+         d9:be:88:0c:23:b1:19:dc:55:4f:7d:a9:cf:62:41:c5:19:02:
+         43:b5
 -----BEGIN CERTIFICATE-----
-MIIClzCCAgCgAwIBAgIBLTANBgkqhkiG9w0BAQsFADB8MQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEMMAoGA1UECxMDdGE5MRIwEAYDVQQDEwlsb2NhbGhvc3QxEjAQBgkq
-hkiG9w0BCQEWA3RhOTAeFw0xMTA0MTEyMjM3NTVaFw0xNDAxMDUyMjM3NTVaMIGE
-MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVu
-bG8gUGFyazENMAsGA1UEChMEcGtnNTEQMA4GA1UECxQHY3MxX3RhOTESMBAGA1UE
-AxMJbG9jYWxob3N0MRYwFAYJKoZIhvcNAQkBFgdjczFfdGE5MIGfMA0GCSqGSIb3
-DQEBAQUAA4GNADCBiQKBgQCmUeECBIQWmqkXY1H28rnUVFONcYsvmPgOqPtB9HrT
-dJ01W1jjyEYThmePqp2wwJ4NF0r0SHZDPs40ttOQbXdCrdxQqheCpA4XZ9e3ohHO
-I5CyJBwTTfH7M+bx51QJrq3LJ+iuC/zZFM3Fk9uVHxPLFsCnRqNmU44k3yaF8XIn
-AwIDAQABoyAwHjAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG
-9w0BAQsFAAOBgQDLLY1RZW6z5HDd46xANUHysmk1UDLxBG2U9v8yWnci02+PV4d/
-WqyZpIwq6bUcW1jq92O244rHsp7jN+eMxQEKDKZIMW4K1G3s2ncHqTzqh7daWDmn
-NwDuW4ymU9m5WYVIUepJzVvspurnB9xefnnb59a+lOyRZDyuFo2lgClIOQ==
+MIICmTCCAgKgAwIBAgIBLTANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxDDAKBgNVBAsMA3RhOTESMBAGA1UEAwwJbG9jYWxob3N0MRIwEAYJ
+KoZIhvcNAQkBFgN0YTkwHhcNMTMxMjEzMDAxMzM5WhcNMTYwOTA4MDAxMzM5WjCB
+hTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAcMC1Nh
+bnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MRAwDgYDVQQLDAdjczFfdGE5MRIwEAYD
+VQQDDAlsb2NhbGhvc3QxFjAUBgkqhkiG9w0BCQEWB2NzMV90YTkwgZ8wDQYJKoZI
+hvcNAQEBBQADgY0AMIGJAoGBAKDyW6XghXknODSY4Qx0rMBSJMaMuxujEszvly7n
+7YkHRxTmBHADznJ5OvbknTGXDHven5mo1H3qaQMSh4kg2WINvMkpy4pbYSWGoqVu
+UG2NVqzMBUFPybqUpDQNldmCmLywbE456gkherppf/uU9TeTtajBvBuMfgAzqLCQ
+D5zfAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgeAMA0GCSqG
+SIb3DQEBCwUAA4GBAF75mvk6UQbUTDsbl69vKH3O8nicv9B8HQAg3YRY5Sm6Uah8
+MFT/0PMlLF0ZTRfK5z7zCa/Pgj3ZXMD85jEZUnBPFxIP4cjgItEQ26UOdTz7M+7p
+q5VEk5aefsP6FC2j7qA1r7TZY8XCdxgjAdm+iAwjsRncVU99qc9iQcUZAkO1
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 18 (0x12)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:44 2011 GMT
-            Not After : Jan  5 22:37:44 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs2_ch1_ta3/emailAddress=cs2_ch1_ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs2_ch1_ta3/emailAddress=cs2_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c5:b6:f8:33:c7:cd:e9:6d:d9:aa:77:60:23:86:
-                    71:56:dc:22:a3:cf:36:d7:b3:59:f7:5d:ae:82:ed:
-                    3f:17:12:62:09:3e:3e:ec:fa:a6:92:df:05:ce:9a:
-                    a2:6d:93:b9:7e:16:f9:c5:b3:83:1d:9a:96:6a:1b:
-                    35:df:f6:b8:82:55:45:5b:43:0a:71:66:4f:bc:df:
-                    00:13:25:22:df:79:76:b6:98:42:25:b2:a1:5c:47:
-                    72:7b:96:9f:65:3f:37:02:97:29:16:9c:75:22:7b:
-                    5d:31:53:80:0a:eb:cc:73:13:da:8e:61:f5:ca:f7:
-                    af:fc:53:cd:b9:11:95:3c:3f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:98:97:30:92:90:4d:45:5a:0c:e2:6f:fb:25:9e:
+                    72:7f:56:64:f5:64:f5:b2:5b:85:27:b7:ad:fa:24:
+                    d7:54:00:1d:5c:4d:c2:92:81:76:f1:37:49:14:b7:
+                    9d:8c:fb:96:69:2d:11:32:6a:19:eb:eb:eb:27:a3:
+                    be:1f:00:29:c8:ba:d6:ca:97:df:e0:83:68:51:9c:
+                    81:f5:63:e0:69:39:1a:fe:5e:af:c3:af:b6:23:b8:
+                    aa:b4:65:c7:f4:7e:63:db:ff:1b:7e:ce:ed:60:7d:
+                    be:2f:fd:05:ee:d0:cd:72:7e:91:93:69:82:29:8f:
+                    a8:a8:53:b1:d7:ea:83:df:89
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -29,27 +29,27 @@
                 <EMPTY>
 
     Signature Algorithm: sha256WithRSAEncryption
-        2e:40:56:59:03:e3:5b:62:73:0c:57:dc:12:d8:4b:97:00:8b:
-        66:c8:a6:10:29:78:3b:7a:52:fb:f9:63:94:44:b2:1b:eb:3f:
-        13:e9:40:9b:24:01:38:f6:b2:f7:99:1e:d9:17:57:e3:df:ff:
-        01:8b:00:02:7e:a0:f5:e5:3a:f0:72:4c:72:6f:76:07:26:ac:
-        97:6d:c2:12:e1:64:99:29:ff:25:fd:21:c7:43:41:87:c5:bb:
-        ce:06:c4:b1:f9:64:ad:e8:d8:90:ac:89:26:8a:1e:a3:d4:45:
-        2d:8a:27:a4:88:8c:f3:97:5f:f7:82:d7:c4:76:98:f5:20:af:
-        5e:23
+         53:10:01:62:32:bd:ff:7d:30:a5:09:5f:77:44:af:0d:81:d4:
+         4b:c8:f6:fe:ba:38:65:9f:b6:55:77:7a:36:86:42:64:1a:89:
+         66:4f:1d:f5:0a:65:1e:06:2c:07:46:b3:57:ba:98:1d:1c:46:
+         52:08:65:32:70:9d:98:3e:e9:6b:be:da:7e:91:54:60:52:ad:
+         0e:90:3f:ee:7c:2a:03:84:8f:4f:e4:1b:d3:4f:a8:d3:c2:29:
+         74:cc:ac:87:81:7e:38:07:cd:d8:5f:20:00:b6:e4:ea:c1:e5:
+         06:77:19:da:9c:3b:43:7f:91:ab:8c:f1:b7:03:09:09:0a:85:
+         de:91
 -----BEGIN CERTIFICATE-----
-MIICfDCCAeWgAwIBAgIBEjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDRaFw0xNDAxMDUyMjM3NDRaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczJfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3MyX2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMW2+DPHzelt
-2ap3YCOGcVbcIqPPNtezWfddroLtPxcSYgk+Puz6ppLfBc6aom2TuX4W+cWzgx2a
-lmobNd/2uIJVRVtDCnFmT7zfABMlIt95draYQiWyoVxHcnuWn2U/NwKXKRacdSJ7
-XTFTgArrzHMT2o5h9cr3r/xTzbkRlTw/AgMBAAGjHjAcMAwGA1UdEwEB/wQCMAAw
-DAYDVR0SAQH/BAIwADANBgkqhkiG9w0BAQsFAAOBgQAuQFZZA+NbYnMMV9wS2EuX
-AItmyKYQKXg7elL7+WOURLIb6z8T6UCbJAE49rL3mR7ZF1fj3/8BiwACfqD15Trw
-ckxyb3YHJqyXbcIS4WSZKf8l/SHHQ0GHxbvOBsSx+WSt6NiQrIkmih6j1EUtiiek
-iIzzl1/3gtfEdpj1IK9eIw==
+MIICfjCCAeegAwIBAgIBEjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMl9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczJfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAmJcwkpBN
+RVoM4m/7JZ5yf1Zk9WT1sluFJ7et+iTXVAAdXE3CkoF28TdJFLedjPuWaS0RMmoZ
+6+vrJ6O+HwApyLrWypff4INoUZyB9WPgaTka/l6vw6+2I7iqtGXH9H5j2/8bfs7t
+YH2+L/0F7tDNcn6Rk2mCKY+oqFOx1+qD34kCAwEAAaMeMBwwDAYDVR0TAQH/BAIw
+ADAMBgNVHRIBAf8EAjAAMA0GCSqGSIb3DQEBCwUAA4GBAFMQAWIyvf99MKUJX3dE
+rw2B1EvI9v66OGWftlV3ejaGQmQaiWZPHfUKZR4GLAdGs1e6mB0cRlIIZTJwnZg+
+6Wu+2n6RVGBSrQ6QP+58KgOEj0/kG9NPqNPCKXTMrIeBfjgHzdhfIAC25OrB5QZ3
+GdqcO0N/kauM8bcDCQkKhd6R
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch1_ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch1_ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,66 +2,68 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 36 (0x24)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Validity
-            Not Before: Apr 11 22:37:50 2011 GMT
-            Not After : Jan  5 22:37:50 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs2_ch1_ta4/emailAddress=cs2_ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs2_ch1_ta4/emailAddress=cs2_ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:bf:ac:9d:17:06:fb:0f:06:2b:8f:e1:70:02:28:
-                    81:03:f5:1f:f4:4a:41:87:c5:4c:e1:4c:5b:9d:89:
-                    2f:a2:d4:5e:1a:4b:b6:93:c7:10:41:d9:e9:e0:d5:
-                    43:64:9f:39:1d:c8:2a:93:52:23:08:92:78:a3:5f:
-                    3b:98:50:e8:72:3a:73:12:4f:99:4b:4d:0e:e8:5d:
-                    92:f3:0b:5d:78:f6:5b:4b:c8:36:23:e3:ca:ab:8a:
-                    aa:52:33:d1:1e:61:d1:3e:91:5d:ee:38:bc:c4:0e:
-                    ee:54:f9:aa:00:a3:51:55:95:7a:c0:7b:0e:b2:d8:
-                    55:9d:f8:ae:1f:32:a7:87:eb
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ad:94:3a:b1:fd:3e:be:1e:33:73:ab:48:e2:ea:
+                    99:d8:1d:4d:c4:80:e6:fe:b6:6e:86:45:c4:86:81:
+                    df:c5:63:3d:b7:9b:50:75:bc:09:9d:cd:95:6c:6c:
+                    47:88:6d:0c:0c:24:7a:b9:50:f0:39:12:4b:6b:0c:
+                    2e:a3:7d:80:27:61:53:8b:63:c0:2e:a2:9e:b1:4d:
+                    0b:5a:a4:fd:6f:32:20:1d:2c:ea:18:c4:e5:ed:62:
+                    4d:ec:a7:ab:07:6e:8b:3f:c2:29:c7:30:90:7f:6a:
+                    2a:cc:08:9b:82:4b:24:a1:79:a2:06:a6:5c:7a:60:
+                    83:c5:ba:68:2c:ff:01:1f:d1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                4E:1B:1F:2F:80:BA:AC:13:47:60:30:A5:43:F6:01:7D:54:3C:9B:24
+                9F:BB:AE:D3:46:0F:B1:D1:1B:E5:D0:7F:06:5D:5B:3D:15:22:E3:C5
             X509v3 Authority Key Identifier: 
-                keyid:2A:94:C1:FF:E0:11:A0:91:F1:71:46:35:9A:37:3C:BC:C4:21:4A:8F
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
+                keyid:29:7A:F9:B4:E3:1B:8F:19:63:52:FA:19:A0:AB:DA:37:E4:70:A9:71
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
                 serial:22
 
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/example_file
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/example_file
 
     Signature Algorithm: sha256WithRSAEncryption
-        6d:40:ad:c1:79:65:fc:25:80:f7:52:d5:6f:16:3c:b2:77:f8:
-        35:e2:b5:d4:3c:49:f1:1c:02:d7:5a:61:aa:c2:c7:bd:53:4a:
-        96:58:8e:3e:14:d3:38:89:43:70:f0:5c:73:e1:c0:36:5e:10:
-        73:f4:93:c3:de:0c:61:49:be:2d:d0:1e:37:b4:03:49:a9:a4:
-        37:42:77:6a:97:15:45:2f:7d:b2:dd:9d:b2:98:56:0a:70:14:
-        83:ac:6f:e1:1e:97:31:9e:0a:30:ca:7d:5f:87:30:41:05:63:
-        4b:38:cb:f0:c0:cd:4d:a6:d2:11:34:30:ba:f4:8a:74:73:70:
-        ee:45
+         19:54:e0:5b:f7:80:a2:90:05:af:21:fe:4c:1f:f1:4b:c1:2f:
+         36:f3:e4:d1:93:16:67:48:89:62:69:37:92:71:61:aa:f1:4a:
+         2d:fa:ca:cd:69:e5:50:53:45:0a:91:2c:44:f8:44:22:02:82:
+         cd:6d:4b:15:85:cf:8d:ea:f8:98:1b:ff:7c:54:10:48:07:81:
+         a4:04:37:36:c1:95:72:e6:a6:e7:db:59:2f:1c:c9:b4:46:da:
+         98:53:e6:2e:24:9a:f3:9d:74:62:d5:28:96:66:a1:a2:47:21:
+         0e:5d:8e:be:89:ac:d2:4f:89:eb:fd:db:2d:e0:92:d7:a8:99:
+         c7:cf
 -----BEGIN CERTIFICATE-----
-MIIDYjCCAsugAwIBAgIBJDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NDAeFw0xMTA0MTEyMjM3NTBaFw0xNDAxMDUyMjM3NTBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczJfY2gxX3RhNDEaMBgGCSqGSIb3DQEJARYL
-Y3MyX2NoMV90YTQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAL+snRcG+w8G
-K4/hcAIogQP1H/RKQYfFTOFMW52JL6LUXhpLtpPHEEHZ6eDVQ2SfOR3IKpNSIwiS
-eKNfO5hQ6HI6cxJPmUtNDuhdkvMLXXj2W0vINiPjyquKqlIz0R5h0T6RXe44vMQO
-7lT5qgCjUVWVesB7DrLYVZ34rh8yp4frAgMBAAGjggECMIH/MB0GA1UdDgQWBBRO
-Gx8vgLqsE0dgMKVD9gF9VDybJDCBkgYDVR0jBIGKMIGHgBQqlMH/4BGgkfFxRjWa
-Nzy8xCFKj6FspGowaDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWEx
-EzARBgNVBAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAMTA3Rh
-NDESMBAGCSqGSIb3DQEJARYDdGE0ggEiMAwGA1UdEwEB/wQCMAAwOwYDVR0fBDQw
-MjAwoC6gLIYqaHR0cDovL2xvY2FsaG9zdDoxMjAwMS9maWxlLzAvZXhhbXBsZV9m
-aWxlMA0GCSqGSIb3DQEBCwUAA4GBAG1ArcF5ZfwlgPdS1W8WPLJ3+DXitdQ8SfEc
-AtdaYarCx71TSpZYjj4U0ziJQ3DwXHPhwDZeEHP0k8PeDGFJvi3QHje0A0mppDdC
-d2qXFUUvfbLdnbKYVgpwFIOsb+EelzGeCjDKfV+HMEEFY0s4y/DAzU2m0hE0MLr0
-inRzcO5F
+MIIDZjCCAs+gAwIBAgIBJDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTQxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMl9jaDFfdGE0MRowGAYJKoZIhvcNAQkB
+FgtjczJfY2gxX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEArZQ6sf0+
+vh4zc6tI4uqZ2B1NxIDm/rZuhkXEhoHfxWM9t5tQdbwJnc2VbGxHiG0MDCR6uVDw
+ORJLawwuo32AJ2FTi2PALqKesU0LWqT9bzIgHSzqGMTl7WJN7KerB26LP8IpxzCQ
+f2oqzAibgkskoXmiBqZcemCDxbpoLP8BH9ECAwEAAaOCAQQwggEAMB0GA1UdDgQW
+BBSfu67TRg+x0Rvl0H8GXVs9FSLjxTCBkwYDVR0jBIGLMIGIgBQpevm04xuPGWNS
++hmgq9o35HCpcaFtpGswaTELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3Ju
+aWExFDASBgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQwwCgYDVQQD
+DAN0YTQxEjAQBgkqhkiG9w0BCQEWA3RhNIIBIjAMBgNVHRMBAf8EAjAAMDsGA1Ud
+HwQ0MDIwMKAuoCyGKmh0dHA6Ly9sb2NhbGhvc3Q6MTIwMDEvZmlsZS8wL2V4YW1w
+bGVfZmlsZTANBgkqhkiG9w0BAQsFAAOBgQAZVOBb94CikAWvIf5MH/FLwS828+TR
+kxZnSIliaTeScWGq8Uot+srNaeVQU0UKkSxE+EQiAoLNbUsVhc+N6viYG/98VBBI
+B4GkBDc2wZVy5qbn21kvHMm0RtqYU+YuJJrznXRi1SiWZqGiRyEOXY6+iazST4nr
+/dst4JLXqJnHzw==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch5_ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs2_ch5_ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,55 +2,57 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 7 (0x7)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch5_ta1/emailAddress=ch5_ta1
         Validity
-            Not Before: Apr 11 22:37:40 2011 GMT
-            Not After : Jan  5 22:37:40 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs2_ch5_ta1/emailAddress=cs2_ch5_ta1
+            Not Before: Dec 13 00:13:34 2013 GMT
+            Not After : Sep  8 00:13:34 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs2_ch5_ta1/emailAddress=cs2_ch5_ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cd:c9:ab:ee:a1:89:01:60:89:00:7c:93:1f:fe:
-                    4c:54:75:58:52:81:b0:cb:be:4c:a7:a7:23:18:86:
-                    0e:9f:e1:41:99:dd:ff:e7:f3:66:1d:41:dd:aa:9e:
-                    f7:23:2d:c4:0e:24:16:e2:4d:54:8b:38:72:55:b4:
-                    11:26:f9:fc:04:fe:de:9b:83:02:01:98:36:8e:41:
-                    42:f2:0b:a7:07:00:f9:0e:66:96:a0:e4:f3:32:06:
-                    26:9d:41:fb:91:bf:7e:a8:c0:c7:62:e1:c9:ce:37:
-                    de:07:b5:df:55:87:9a:a5:3b:d4:c5:b6:24:4b:2a:
-                    e4:88:50:85:e9:d9:13:12:47
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cc:51:a3:86:48:a6:81:11:01:ba:be:40:6d:dc:
+                    f7:b6:0a:f8:9a:11:71:ea:09:42:3a:ed:ee:4e:0f:
+                    87:10:99:6f:c8:ef:41:bd:f6:d0:17:a7:db:7b:fe:
+                    51:dd:de:3a:f2:3b:d7:de:7d:96:71:4e:7f:4e:d0:
+                    cf:dd:3b:d8:6b:ce:ca:83:3a:7d:6e:65:cd:b5:fb:
+                    4b:32:9a:e6:20:f8:ed:8e:4c:99:f4:02:de:c5:d4:
+                    3b:6e:35:a8:3c:b4:9f:3f:5e:3b:85:33:4a:4d:b3:
+                    35:a3:d0:76:78:74:d2:72:99:9e:c1:69:1f:d1:8f:
+                    2a:11:eb:35:32:7b:ba:8f:99
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:http://localhost:12001/file/0/ch5_ta1_crl.pem
+
+                Full Name:
+                  URI:http://localhost:12001/file/0/ch5_ta1_crl.pem
 
     Signature Algorithm: sha256WithRSAEncryption
-        58:ba:80:0f:56:d9:4e:90:97:38:a2:f5:b7:3d:98:ff:32:ec:
-        63:01:79:25:5a:5b:d4:ac:bc:aa:e1:2d:c8:ea:34:32:b0:aa:
-        ce:9f:de:e7:f2:f7:35:f8:e5:71:97:27:d1:66:80:e8:22:c7:
-        bc:23:31:2b:98:60:b4:76:7b:62:38:ff:14:57:24:64:37:6b:
-        9d:22:2a:f9:16:90:91:01:d7:f3:91:24:29:c3:c6:53:7a:0b:
-        e9:af:2b:3b:5e:77:61:83:48:e8:e2:f2:a6:44:cc:5e:90:36:
-        f2:8e:dd:59:b6:c8:21:92:17:30:87:66:c9:08:2d:b9:5b:3a:
-        f2:4e
+         2c:76:2d:19:cd:d6:f0:88:16:6c:99:6c:19:1b:5e:d3:ca:b1:
+         6d:3c:f1:5b:2c:3b:52:cd:7f:f5:1b:4f:e0:49:9e:48:5c:5e:
+         16:55:57:a3:0d:c6:eb:f5:a7:13:8d:57:c4:ff:df:3d:66:00:
+         a3:b9:18:c3:19:5c:ba:1c:ae:83:bd:90:a6:c8:6e:5a:c6:b5:
+         51:b5:33:69:59:7a:5a:00:24:61:02:41:c5:c2:ff:cc:12:a1:
+         d7:d4:d5:29:b9:22:94:e0:5c:5c:29:ec:82:ba:ff:1a:40:50:
+         88:58:98:a8:b3:2b:86:3c:a2:21:8b:b4:b2:fc:3a:b0:c7:f1:
+         03:e8
 -----BEGIN CERTIFICATE-----
-MIICrjCCAhegAwIBAgIBBzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2g1X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g1X3Rh
-MTAeFw0xMTA0MTEyMjM3NDBaFw0xNDAxMDUyMjM3NDBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczJfY2g1X3RhMTEaMBgGCSqGSIb3DQEJARYL
-Y3MyX2NoNV90YTEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAM3Jq+6hiQFg
-iQB8kx/+TFR1WFKBsMu+TKenIxiGDp/hQZnd/+fzZh1B3aqe9yMtxA4kFuJNVIs4
-clW0ESb5/AT+3puDAgGYNo5BQvILpwcA+Q5mlqDk8zIGJp1B+5G/fqjAx2Lhyc43
-3ge131WHmqU71MW2JEsq5IhQhenZExJHAgMBAAGjUDBOMAwGA1UdEwEB/wQCMAAw
-PgYDVR0fBDcwNTAzoDGgL4YtaHR0cDovL2xvY2FsaG9zdDoxMjAwMS9maWxlLzAv
-Y2g1X3RhMV9jcmwucGVtMA0GCSqGSIb3DQEBCwUAA4GBAFi6gA9W2U6Qlzii9bc9
-mP8y7GMBeSVaW9SsvKrhLcjqNDKwqs6f3ufy9zX45XGXJ9FmgOgix7wjMSuYYLR2
-e2I4/xRXJGQ3a50iKvkWkJEB1/ORJCnDxlN6C+mvKzted2GDSOji8qZEzF6QNvKO
-3Vm2yCGSFzCHZskILblbOvJO
+MIICsDCCAhmgAwIBAgIBBzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoNV90YTExFjAUBgkqhkiG9w0BCQEWB2NoNV90
+YTEwHhcNMTMxMjEzMDAxMzM0WhcNMTYwOTA4MDAxMzM0WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzMl9jaDVfdGExMRowGAYJKoZIhvcNAQkB
+FgtjczJfY2g1X3RhMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAzFGjhkim
+gREBur5Abdz3tgr4mhFx6glCOu3uTg+HEJlvyO9BvfbQF6fbe/5R3d468jvX3n2W
+cU5/TtDP3TvYa87Kgzp9bmXNtftLMprmIPjtjkyZ9ALexdQ7bjWoPLSfP147hTNK
+TbM1o9B2eHTScpmewWkf0Y8qEes1Mnu6j5kCAwEAAaNQME4wDAYDVR0TAQH/BAIw
+ADA+BgNVHR8ENzA1MDOgMaAvhi1odHRwOi8vbG9jYWxob3N0OjEyMDAxL2ZpbGUv
+MC9jaDVfdGExX2NybC5wZW0wDQYJKoZIhvcNAQELBQADgYEALHYtGc3W8IgWbJls
+GRte08qxbTzxWyw7Us1/9RtP4EmeSFxeFlVXow3G6/WnE41XxP/fPWYAo7kYwxlc
+uhyug72QpshuWsa1UbUzaVl6WgAkYQJBxcL/zBKh19TVKbkilOBcXCnsgrr/GkBQ
+iFiYqLMrhjyiIYu0svw6sMfxA+g=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs3_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs3_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 19 (0x13)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
             Not Before: Jan  1 01:01:01 2009 GMT
             Not After : Jan  2 01:01:01 2009 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs3_ch1_ta3/emailAddress=cs3_ch1_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs3_ch1_ta3/emailAddress=cs3_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b7:60:7b:08:47:0a:05:c1:6c:80:9a:84:e2:de:
-                    c6:11:65:df:a6:c7:30:bb:37:e9:ae:9e:37:9d:f9:
-                    f3:3a:18:38:ee:be:e0:fb:6b:84:fb:93:2c:5b:1e:
-                    9f:7a:78:da:26:28:c7:fb:6e:9f:2e:8f:f9:5a:1c:
-                    e8:0b:e0:f1:5c:45:f6:a0:0e:58:01:4e:86:20:bd:
-                    ff:7d:0c:41:4b:b2:50:5c:78:89:3c:4a:83:cf:59:
-                    9f:e4:17:27:de:ea:aa:ff:c8:19:f5:b7:c3:67:bd:
-                    5e:78:79:8e:46:33:1a:ef:36:40:f8:f2:7e:bc:ca:
-                    54:85:57:56:e5:e7:b8:52:4d
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d3:01:be:68:e6:07:6b:d4:f1:10:9e:99:93:cb:
+                    79:4d:15:d1:39:fb:b2:de:74:10:57:84:c3:ab:3e:
+                    25:cc:f4:7e:66:1e:f2:fa:f2:32:b4:c5:6c:80:e7:
+                    31:80:1a:96:79:96:83:b5:44:58:f1:2a:9b:3b:c0:
+                    0d:42:00:27:49:bf:6e:0a:d6:8b:b4:20:5c:a7:3d:
+                    11:74:25:95:08:45:bb:c5:ca:07:42:a3:e8:19:36:
+                    e1:62:42:53:bc:2f:1f:a8:10:31:ee:40:7d:ec:b5:
+                    54:04:c4:63:e8:43:12:09:7d:1e:99:60:f6:db:ec:
+                    65:d3:13:bb:36:be:e2:d8:ed
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        27:40:ae:0c:a2:ad:5d:28:30:53:fe:e4:35:31:02:e4:1a:ef:
-        6d:ec:95:1e:3e:a0:15:15:32:e8:88:46:68:45:a7:60:9f:93:
-        79:ab:ef:78:f6:2c:23:ef:a1:f4:71:b3:9a:f1:c6:4d:ac:34:
-        a1:24:d8:4e:38:36:3c:bb:90:30:9b:e4:b3:8e:55:e0:06:c4:
-        5a:c4:f1:23:90:fd:b3:ef:40:dd:4d:4c:2b:55:50:11:64:6b:
-        64:3f:e3:67:3c:6c:c1:da:55:6c:7d:8d:87:18:40:6a:cb:13:
-        17:3b:75:35:09:71:0b:e9:c4:7e:b1:a1:db:80:78:93:b3:5b:
-        d0:4e
+         5f:64:85:36:62:d2:01:78:45:6d:63:d5:c8:d8:01:cb:39:f7:
+         0f:75:61:87:9c:d0:2b:9d:3f:0f:56:4d:8c:7d:06:69:eb:60:
+         3a:ca:ed:91:39:ba:e8:8b:a9:42:58:33:32:e3:08:ac:a9:ca:
+         76:ef:37:39:74:46:2d:ea:54:e0:0d:e5:62:18:48:5e:e6:8b:
+         6c:6c:25:0c:8d:61:98:f6:7a:ae:b6:73:cb:8a:2d:27:a5:c7:
+         cf:5e:36:a5:2f:10:74:41:b0:93:6d:21:e2:52:c2:d5:88:6e:
+         ff:91:04:eb:92:8b:62:3a:81:a8:88:6c:10:67:4e:a2:6a:2c:
+         17:ec
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBEzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0wOTAxMDEwMTAxMDFaFw0wOTAxMDIwMTAxMDFaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczNfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3MzX2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALdgewhHCgXB
-bICahOLexhFl36bHMLs36a6eN5358zoYOO6+4PtrhPuTLFsen3p42iYox/tuny6P
-+Voc6Avg8VxF9qAOWAFOhiC9/30MQUuyUFx4iTxKg89Zn+QXJ97qqv/IGfW3w2e9
-Xnh5jkYzGu82QPjyfrzKVIVXVuXnuFJNAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBACdArgyirV0oMFP+5DUx
-AuQa723slR4+oBUVMuiIRmhFp2Cfk3mr73j2LCPvofRxs5rxxk2sNKEk2E44Njy7
-kDCb5LOOVeAGxFrE8SOQ/bPvQN1NTCtVUBFka2Q/42c8bMHaVWx9jYcYQGrLExc7
-dTUJcQvpxH6xoduAeJOzW9BO
+MIICgDCCAemgAwIBAgIBEzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMDkwMTAxMDEwMTAxWhcNMDkwMTAyMDEwMTAxWjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzM19jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczNfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA0wG+aOYH
+a9TxEJ6Zk8t5TRXROfuy3nQQV4TDqz4lzPR+Zh7y+vIytMVsgOcxgBqWeZaDtURY
+8SqbO8ANQgAnSb9uCtaLtCBcpz0RdCWVCEW7xcoHQqPoGTbhYkJTvC8fqBAx7kB9
+7LVUBMRj6EMSCX0emWD22+xl0xO7Nr7i2O0CAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAX2SFNmLSAXhFbWPV
+yNgByzn3D3Vhh5zQK50/D1ZNjH0GaetgOsrtkTm66IupQlgzMuMIrKnKdu83OXRG
+LepU4A3lYhhIXuaLbGwlDI1hmPZ6rrZzy4otJ6XHz142pS8QdEGwk20h4lLC1Yhu
+/5EE65KLYjqBqIhsEGdOomosF+w=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs3_ch1_ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs3_ch1_ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,65 +2,67 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 37 (0x25)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta4/emailAddress=ch1_ta4
         Validity
-            Not Before: Apr 11 22:37:50 2011 GMT
-            Not After : Jan  5 22:37:50 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs3_ch1_ta4/emailAddress=cs3_ch1_ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs3_ch1_ta4/emailAddress=cs3_ch1_ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c3:0c:75:ca:f7:a7:94:08:4a:72:f4:27:88:98:
-                    9f:d7:cc:7b:41:e4:54:86:11:d1:c2:d8:a1:ce:68:
-                    b0:8f:6a:6e:78:bf:f9:08:c9:a3:44:99:27:24:da:
-                    c2:76:e8:59:76:be:b2:04:46:1c:f4:1a:77:76:73:
-                    cb:dd:53:b6:9f:c7:5e:04:0a:35:43:e1:5d:5d:62:
-                    9b:73:13:06:d3:96:8f:64:4e:34:0d:bf:31:33:3c:
-                    05:24:26:d7:71:a6:83:65:1f:cf:01:25:c1:87:49:
-                    35:b9:12:a1:9c:af:4c:4f:da:26:59:e4:13:ee:c1:
-                    72:52:1a:f5:49:84:92:18:3b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:d6:0b:65:25:4a:ab:c6:97:60:f0:0a:13:02:12:
+                    58:0a:26:26:7f:ba:10:82:a4:68:2e:59:dc:9e:63:
+                    71:4c:03:85:55:7b:c0:20:c8:3b:f3:12:24:8c:e5:
+                    4d:d4:41:10:5f:5d:be:b6:76:77:41:e5:57:48:c7:
+                    01:42:be:18:a0:f7:39:fa:3f:30:07:e9:6f:05:16:
+                    00:43:98:5e:fa:62:46:36:79:b1:6a:84:22:15:36:
+                    16:2b:23:e5:6f:2f:c6:ca:ae:dc:72:95:7a:48:9b:
+                    9b:ae:72:bd:f0:ff:d2:0b:fe:82:ec:53:38:23:cd:
+                    6d:65:28:ba:53:5c:74:6f:5f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                90:5E:20:89:14:A6:9B:2F:BD:21:FA:EC:07:E1:37:24:59:70:10:C1
+                83:0A:1B:8B:11:B9:64:BB:0F:67:12:12:45:12:74:32:7C:36:15:F9
             X509v3 Authority Key Identifier: 
-                keyid:2A:94:C1:FF:E0:11:A0:91:F1:71:46:35:9A:37:3C:BC:C4:21:4A:8F
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
+                keyid:29:7A:F9:B4:E3:1B:8F:19:63:52:FA:19:A0:AB:DA:37:E4:70:A9:71
+                DirName:/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta4/emailAddress=ta4
                 serial:22
 
             X509v3 Basic Constraints: critical
                 CA:FALSE
             X509v3 CRL Distribution Points: 
-                URI:foo://bar/baz
+
+                Full Name:
+                  URI:foo://bar/baz
 
     Signature Algorithm: sha256WithRSAEncryption
-        95:ab:fa:7f:38:e3:de:4d:db:7f:a4:ea:49:f6:99:0c:57:76:
-        36:df:e3:68:50:0d:b7:af:78:ea:e4:07:ad:63:75:15:48:34:
-        ca:81:6a:0b:64:6d:c5:ca:9b:3b:a2:fd:dd:19:90:8f:d4:4d:
-        35:a0:a2:18:84:bf:89:0d:22:cc:03:67:57:15:f7:70:16:2b:
-        f7:14:82:3e:a9:74:50:e5:22:11:13:5b:69:d1:d5:87:c2:44:
-        a6:b8:9c:73:d6:51:ec:20:89:1a:11:44:07:8f:e7:6d:df:a8:
-        0f:5e:71:36:9c:7b:0b:e4:2b:5a:94:77:06:c6:fb:f7:e5:dc:
-        77:a3
+         35:54:4b:75:7e:93:ad:b6:4a:01:0d:0b:90:a6:b8:97:82:f1:
+         53:14:12:ce:da:83:cd:0a:d2:57:68:c4:a2:b2:54:94:dc:f8:
+         fb:21:a5:e6:37:63:07:6a:eb:99:c9:61:b2:41:6f:76:a0:94:
+         97:ad:a3:7c:38:b8:da:4a:ff:cb:cd:e6:d2:75:1e:c3:ae:c3:
+         4f:28:32:7a:71:8d:58:c3:df:79:bb:f8:38:b8:2e:bb:fb:01:
+         dc:81:c8:85:91:66:2c:46:ee:0e:96:32:4c:3c:63:ba:7e:71:
+         ea:41:e1:2d:13:ac:34:2c:de:0e:9b:47:4c:41:24:0e:8a:ab:
+         c7:65
 -----BEGIN CERTIFICATE-----
-MIIDRDCCAq2gAwIBAgIBJTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-NDAeFw0xMTA0MTEyMjM3NTBaFw0xNDAxMDUyMjM3NTBaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczNfY2gxX3RhNDEaMBgGCSqGSIb3DQEJARYL
-Y3MzX2NoMV90YTQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMMMdcr3p5QI
-SnL0J4iYn9fMe0HkVIYR0cLYoc5osI9qbni/+QjJo0SZJyTawnboWXa+sgRGHPQa
-d3Zzy91Ttp/HXgQKNUPhXV1im3MTBtOWj2RONA2/MTM8BSQm13Gmg2UfzwElwYdJ
-NbkSoZyvTE/aJlnkE+7BclIa9UmEkhg7AgMBAAGjgeUwgeIwHQYDVR0OBBYEFJBe
-IIkUppsvvSH67AfhNyRZcBDBMIGSBgNVHSMEgYowgYeAFCqUwf/gEaCR8XFGNZo3
-PLzEIUqPoWykajBoMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTET
-MBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTEMMAoGA1UEAxMDdGE0
-MRIwEAYJKoZIhvcNAQkBFgN0YTSCASIwDAYDVR0TAQH/BAIwADAeBgNVHR8EFzAV
-MBOgEaAPhg1mb286Ly9iYXIvYmF6MA0GCSqGSIb3DQEBCwUAA4GBAJWr+n84495N
-23+k6kn2mQxXdjbf42hQDbeveOrkB61jdRVINMqBagtkbcXKmzui/d0ZkI/UTTWg
-ohiEv4kNIswDZ1cV93AWK/cUgj6pdFDlIhETW2nR1YfCRKa4nHPWUewgiRoRRAeP
-523fqA9ecTacewvkK1qUdwbG+/fl3Hej
+MIIDRzCCArCgAwIBAgIBJTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTQxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzM19jaDFfdGE0MRowGAYJKoZIhvcNAQkB
+FgtjczNfY2gxX3RhNDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA1gtlJUqr
+xpdg8AoTAhJYCiYmf7oQgqRoLlncnmNxTAOFVXvAIMg78xIkjOVN1EEQX12+tnZ3
+QeVXSMcBQr4YoPc5+j8wB+lvBRYAQ5he+mJGNnmxaoQiFTYWKyPlby/Gyq7ccpV6
+SJubrnK98P/SC/6C7FM4I81tZSi6U1x0b18CAwEAAaOB5jCB4zAdBgNVHQ4EFgQU
+gwobixG5ZLsPZxISRRJ0Mnw2FfkwgZMGA1UdIwSBizCBiIAUKXr5tOMbjxljUvoZ
+oKvaN+RwqXGhbaRrMGkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlh
+MRQwEgYDVQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwD
+dGE0MRIwEAYJKoZIhvcNAQkBFgN0YTSCASIwDAYDVR0TAQH/BAIwADAeBgNVHR8E
+FzAVMBOgEaAPhg1mb286Ly9iYXIvYmF6MA0GCSqGSIb3DQEBCwUAA4GBADVUS3V+
+k622SgENC5CmuJeC8VMUEs7ag80K0ldoxKKyVJTc+PshpeY3Ywdq65nJYbJBb3ag
+lJeto3w4uNpK/8vN5tJ1HsOuw08oMnpxjVjD33m7+Di4Lrv7AdyByIWRZixG7g6W
+Mkw8Y7p+cepB4S0TrDQs3g6bR0xBJA6Kq8dl
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs4_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs4_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 20 (0x14)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
             Not Before: Jan  1 01:01:01 2035 GMT
             Not After : Jan  2 01:01:01 2035 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs4_ch1_ta3/emailAddress=cs4_ch1_ta3
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs4_ch1_ta3/emailAddress=cs4_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d7:42:45:a6:d0:f4:a9:54:6d:c8:4d:42:e8:05:
-                    a4:33:25:f1:b7:eb:20:df:33:26:6e:ca:30:63:57:
-                    df:d3:a9:02:b0:29:f3:cb:7b:64:77:34:7e:1d:c7:
-                    a8:2c:ca:73:23:22:43:71:6c:33:9e:89:0e:89:ce:
-                    6d:db:2b:f3:5a:af:e3:dc:f3:1c:48:64:60:5d:57:
-                    e6:17:6b:e6:61:4b:cb:e0:a9:e3:1c:aa:f6:70:34:
-                    b4:8b:d8:19:e6:26:06:60:24:82:c6:d8:5d:87:de:
-                    99:2b:0d:78:db:92:f2:c2:24:65:8b:f8:07:b6:fe:
-                    17:8d:bb:4f:c7:c0:ae:24:c9
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cb:2c:5a:74:59:a7:60:a1:a4:1b:36:25:92:c1:
+                    aa:39:3f:7c:17:de:d0:36:c3:1c:bf:c6:25:30:e0:
+                    10:7b:d7:76:7d:de:d6:71:6c:81:df:95:22:a4:dd:
+                    80:55:2a:5e:fd:82:df:94:a0:aa:f9:8e:b1:e9:20:
+                    be:04:26:18:17:e8:04:9e:af:67:ca:57:8e:f6:92:
+                    2c:6e:76:02:4b:84:d8:2b:78:2b:32:74:8e:4c:ea:
+                    ab:3c:61:62:cb:95:af:5c:77:74:19:b2:0e:4f:49:
+                    63:8a:72:ac:c1:77:6a:42:ed:91:6f:be:a4:df:c8:
+                    0b:1b:b4:32:18:46:dc:b9:f5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        b9:09:ff:d1:80:e1:9e:05:e8:27:40:d0:d3:76:d7:b6:72:cd:
-        4a:e4:d8:b7:e2:14:90:3a:74:61:b3:c8:3c:7c:bd:2e:9c:9d:
-        62:0d:cd:9b:e9:36:ba:aa:87:f7:c7:e4:3a:6c:5d:d9:99:d5:
-        33:a0:5a:3f:fd:5e:06:62:11:ad:ca:33:9d:0a:59:8a:a9:0e:
-        6e:4a:d8:6f:da:ff:96:89:e3:8a:3b:5e:a6:b4:8c:93:ff:70:
-        4d:d2:32:f8:44:c0:ff:84:65:b0:1f:59:4a:2c:10:d7:5e:a6:
-        ed:5b:a8:e2:eb:42:e0:0d:7b:f5:43:ca:1a:9a:cd:df:e6:f8:
-        4d:d5
+         40:91:53:35:b9:b9:31:8d:16:de:85:84:2f:b4:5e:35:7a:da:
+         a8:31:06:29:14:94:80:ee:0a:55:7d:8f:02:2f:74:f4:94:5e:
+         00:d1:c7:8b:2a:71:21:8d:3c:d6:f2:b6:50:84:fe:45:f1:56:
+         bd:36:68:72:b7:73:c6:b7:38:3b:fe:be:22:af:77:43:0d:32:
+         f7:7e:ce:2e:e9:1f:24:5a:b9:bb:ae:b3:fd:cd:ea:87:1a:43:
+         7b:22:71:2f:6b:16:74:e6:73:6b:af:38:17:c6:a4:c6:8c:01:
+         a9:c4:76:be:a3:02:8b:47:35:e1:53:c8:27:87:1e:5c:ad:cb:
+         93:4e
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBFDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0zNTAxMDEwMTAxMDFaFw0zNTAxMDIwMTAxMDFaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczRfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M0X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANdCRabQ9KlU
-bchNQugFpDMl8bfrIN8zJm7KMGNX39OpArAp88t7ZHc0fh3HqCzKcyMiQ3FsM56J
-DonObdsr81qv49zzHEhkYF1X5hdr5mFLy+Cp4xyq9nA0tIvYGeYmBmAkgsbYXYfe
-mSsNeNuS8sIkZYv4B7b+F427T8fAriTJAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBALkJ/9GA4Z4F6CdA0NN2
-17ZyzUrk2LfiFJA6dGGzyDx8vS6cnWINzZvpNrqqh/fH5DpsXdmZ1TOgWj/9XgZi
-Ea3KM50KWYqpDm5K2G/a/5aJ44o7Xqa0jJP/cE3SMvhEwP+EZbAfWUosENdepu1b
-qOLrQuANe/VDyhqazd/m+E3V
+MIICgDCCAemgAwIBAgIBFDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMzUwMTAxMDEwMTAxWhcNMzUwMTAyMDEwMTAxWjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzNF9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczRfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAyyxadFmn
+YKGkGzYlksGqOT98F97QNsMcv8YlMOAQe9d2fd7WcWyB35UipN2AVSpe/YLflKCq
++Y6x6SC+BCYYF+gEnq9nyleO9pIsbnYCS4TYK3grMnSOTOqrPGFiy5WvXHd0GbIO
+T0ljinKswXdqQu2Rb76k38gLG7QyGEbcufUCAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAQJFTNbm5MY0W3oWE
+L7ReNXraqDEGKRSUgO4KVX2PAi909JReANHHiypxIY081vK2UIT+RfFWvTZocrdz
+xrc4O/6+Iq93Qw0y937OLukfJFq5u66z/c3qhxpDeyJxL2sWdOZza684F8akxowB
+qcR2vqMCi0c14VPIJ4ceXK3Lk04=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs5_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs5_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 21 (0x15)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:45 2011 GMT
-            Not After : Jan  5 22:37:45 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs5_ch1_ta3/emailAddress=cs5_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs5_ch1_ta3/emailAddress=cs5_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c0:be:66:e6:55:cb:9e:d6:d2:7b:d3:b2:34:fb:
-                    c9:74:d5:30:4f:62:1c:68:bd:13:97:08:b7:8c:b6:
-                    4e:dd:7f:98:a5:e2:2f:2e:9c:74:92:01:43:62:8e:
-                    9c:62:23:3e:b6:e4:e2:18:2b:3f:ae:fb:17:e7:d8:
-                    c4:28:27:27:d9:3e:5c:d1:8f:51:b7:10:4c:44:f6:
-                    bb:6b:24:7c:2e:09:bc:fb:8a:af:fa:e4:ce:94:2f:
-                    27:cd:3d:e7:be:93:4b:62:37:f5:f1:a8:8e:7e:76:
-                    92:62:7b:02:41:98:c2:f6:ff:68:8e:d2:1d:fb:9e:
-                    f1:45:f5:6a:9c:8d:28:23:c1
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ea:23:95:11:2c:b5:2d:49:c5:10:77:74:82:98:
+                    da:5f:58:1f:2b:40:6e:1b:2e:d8:4f:30:07:6b:a2:
+                    ae:9f:f7:ed:8d:2d:b4:b3:68:48:ec:60:72:a2:fb:
+                    8b:7e:62:11:90:79:96:f9:ee:82:78:3f:09:22:2b:
+                    03:45:af:9e:ca:7e:3c:80:4f:ad:59:77:85:c5:e7:
+                    6b:4a:0b:a2:6b:4b:c5:e7:f9:38:81:64:05:ea:cd:
+                    76:9c:bf:eb:51:aa:29:6c:c1:3e:98:c6:ac:49:a2:
+                    ac:32:60:78:d8:ff:c6:79:f8:a5:a6:78:61:24:9a:
+                    27:26:2e:06:3a:19:8e:54:d1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: 
                 Encipher Only
     Signature Algorithm: sha256WithRSAEncryption
-        26:c1:64:ae:88:f7:19:f6:4f:f6:89:c9:d4:4e:46:cc:8f:51:
-        d3:b0:1c:d5:54:08:b0:5c:a7:51:48:24:be:e5:9f:d1:79:8b:
-        fb:92:84:aa:92:c6:2f:b1:76:e2:f2:21:f7:f1:5d:05:c3:5c:
-        01:90:20:8c:46:9e:a2:b9:dd:71:4f:a4:b9:3a:15:d3:74:98:
-        59:bf:f8:44:c5:a4:99:67:01:e7:d6:52:8d:2f:02:3a:f4:e8:
-        c8:b3:9c:f3:35:18:4e:41:03:a7:b6:b3:5c:84:61:43:6b:95:
-        b4:84:d1:c1:72:29:ac:d5:6f:e4:6c:f1:86:b6:eb:09:77:1e:
-        89:92
+         80:7c:f9:bc:bd:15:b1:9d:75:d1:82:b5:42:79:d3:5e:2c:e3:
+         c4:73:ed:3b:3c:8a:83:9c:51:e9:1f:93:75:1f:81:01:11:f9:
+         fd:a8:56:0f:cf:d3:a9:38:26:e3:f0:78:79:75:ef:97:7b:01:
+         0b:b7:37:65:6c:93:76:07:ec:fa:f5:1e:2d:6a:3b:6d:15:fc:
+         41:6f:fb:17:52:be:cc:a8:95:da:be:3b:6d:d8:5d:42:10:aa:
+         20:9e:8e:c5:33:ed:7b:8a:f1:e5:e3:45:21:05:2e:77:3b:c9:
+         66:46:25:37:e4:5c:b0:f5:29:0a:be:0d:bc:c8:e9:d8:fc:31:
+         22:e3
 -----BEGIN CERTIFICATE-----
-MIICezCCAeSgAwIBAgIBFTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDVaFw0xNDAxMDUyMjM3NDVaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczVfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M1X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMC+ZuZVy57W
-0nvTsjT7yXTVME9iHGi9E5cIt4y2Tt1/mKXiLy6cdJIBQ2KOnGIjPrbk4hgrP677
-F+fYxCgnJ9k+XNGPUbcQTET2u2skfC4JvPuKr/rkzpQvJ809576TS2I39fGojn52
-kmJ7AkGYwvb/aI7SHfue8UX1apyNKCPBAgMBAAGjHTAbMAwGA1UdEwEB/wQCMAAw
-CwYDVR0PBAQDAgABMA0GCSqGSIb3DQEBCwUAA4GBACbBZK6I9xn2T/aJydRORsyP
-UdOwHNVUCLBcp1FIJL7ln9F5i/uShKqSxi+xduLyIffxXQXDXAGQIIxGnqK53XFP
-pLk6FdN0mFm/+ETFpJlnAefWUo0vAjr06MiznPM1GE5BA6e2s1yEYUNrlbSE0cFy
-KazVb+Rs8Ya26wl3HomS
+MIICfTCCAeagAwIBAgIBFTANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzNV9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczVfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA6iOVESy1
+LUnFEHd0gpjaX1gfK0BuGy7YTzAHa6Kun/ftjS20s2hI7GByovuLfmIRkHmW+e6C
+eD8JIisDRa+eyn48gE+tWXeFxedrSguia0vF5/k4gWQF6s12nL/rUaopbME+mMas
+SaKsMmB42P/GefilpnhhJJonJi4GOhmOVNECAwEAAaMdMBswDAYDVR0TAQH/BAIw
+ADALBgNVHQ8EBAMCAAEwDQYJKoZIhvcNAQELBQADgYEAgHz5vL0VsZ110YK1QnnT
+XizjxHPtOzyKg5xR6R+TdR+BARH5/ahWD8/TqTgm4/B4eXXvl3sBC7c3ZWyTdgfs
++vUeLWo7bRX8QW/7F1K+zKiV2r47bdhdQhCqIJ6OxTPte4rx5eNFIQUudzvJZkYl
+N+RcsPUpCr4NvMjp2PwxIuM=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs6_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs6_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 22 (0x16)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:45 2011 GMT
-            Not After : Jan  5 22:37:45 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs6_ch1_ta3/emailAddress=cs6_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs6_ch1_ta3/emailAddress=cs6_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c7:77:32:f6:35:5a:29:de:dc:61:89:a9:7e:d3:
-                    4f:ac:a1:db:f1:7f:58:1c:d3:46:a8:eb:61:62:80:
-                    d0:cf:40:6b:a4:39:ac:fb:f3:e4:a2:47:53:78:d4:
-                    cd:5a:5f:b1:c0:e8:2c:81:2d:00:98:d5:2f:6b:e9:
-                    e7:85:e6:0e:1e:46:d6:22:b9:f3:a7:e0:6c:18:ea:
-                    42:33:cd:c0:9c:e0:98:ec:29:67:39:c4:a3:f7:69:
-                    8b:04:66:f5:a2:3c:08:1b:24:e5:ba:d4:57:5b:14:
-                    f1:f2:c8:2b:0f:22:ae:6e:d1:ca:85:01:e6:75:82:
-                    03:df:7a:ed:96:8a:64:2f:5f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:a5:2e:d6:bd:fc:2f:5b:4c:b8:91:90:8e:f6:3f:
+                    bb:55:28:8d:4f:9d:47:70:ed:3e:a1:bd:70:42:47:
+                    b0:41:09:7b:87:4f:eb:1a:45:9f:09:6d:0a:8c:53:
+                    73:a3:3d:fb:3f:dc:67:f4:03:d3:7c:51:15:f3:ab:
+                    6c:2c:39:d0:a7:4e:c2:3f:5c:d2:d8:87:f1:03:3b:
+                    eb:75:9e:9e:66:d5:3d:d5:e5:6d:32:92:ad:05:b8:
+                    c2:3b:48:e5:72:b4:9d:c9:b7:42:4f:d7:b4:a5:8c:
+                    a4:88:76:df:11:3e:b1:5c:a2:bd:7d:56:f8:c8:76:
+                    00:c4:88:64:0f:36:7e:cb:23
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Encipher Only
     Signature Algorithm: sha256WithRSAEncryption
-        7b:52:05:af:d4:77:41:4d:3f:cf:39:bd:33:a2:82:96:38:df:
-        a5:f7:ab:44:a3:b4:fc:13:ad:f5:d0:48:81:34:10:12:e9:c7:
-        47:3f:13:1d:0a:20:8c:a7:df:23:a1:f5:5c:05:58:7a:ff:58:
-        61:57:25:2c:36:22:10:e6:a4:d4:e3:f4:ad:b3:35:a9:91:93:
-        24:52:f6:28:4c:90:12:98:31:9b:31:8c:64:2f:79:df:d1:f1:
-        6e:d2:43:84:fe:bf:e5:ea:a9:74:6c:ce:cd:44:89:6b:df:bf:
-        7c:dd:77:24:0b:18:07:42:89:41:b3:2c:60:30:db:75:05:82:
-        15:85
+         48:51:71:0e:8c:c2:42:98:91:34:dc:a9:8a:92:98:18:ce:30:
+         fd:61:11:66:9a:87:7a:7b:a6:dd:09:7f:36:9c:7d:d8:19:b6:
+         ab:5d:6a:22:b3:4a:00:45:66:1f:ed:d5:1f:b4:cc:c7:a5:07:
+         5f:6f:35:2c:bc:52:1a:c9:c0:96:56:fd:82:33:50:7b:2e:43:
+         79:2c:cb:e4:e9:22:55:0a:09:96:05:f7:96:e1:22:95:3a:8e:
+         66:b1:21:aa:88:f1:21:4a:20:ae:08:b1:27:7e:f6:6b:be:55:
+         68:0b:d0:d6:77:30:78:92:75:38:d2:ab:31:79:8e:5d:71:a3:
+         b3:2b
 -----BEGIN CERTIFICATE-----
-MIICfjCCAeegAwIBAgIBFjANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDVaFw0xNDAxMDUyMjM3NDVaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczZfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M2X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMd3MvY1Wine
-3GGJqX7TT6yh2/F/WBzTRqjrYWKA0M9Aa6Q5rPvz5KJHU3jUzVpfscDoLIEtAJjV
-L2vp54XmDh5G1iK586fgbBjqQjPNwJzgmOwpZznEo/dpiwRm9aI8CBsk5brUV1sU
-8fLIKw8irm7RyoUB5nWCA9967ZaKZC9fAgMBAAGjIDAeMAwGA1UdEwEB/wQCMAAw
-DgYDVR0PAQH/BAQDAgABMA0GCSqGSIb3DQEBCwUAA4GBAHtSBa/Ud0FNP885vTOi
-gpY436X3q0SjtPwTrfXQSIE0EBLpx0c/Ex0KIIyn3yOh9VwFWHr/WGFXJSw2IhDm
-pNTj9K2zNamRkyRS9ihMkBKYMZsxjGQved/R8W7SQ4T+v+XqqXRszs1EiWvfv3zd
-dyQLGAdCiUGzLGAw23UFghWF
+MIICgDCCAemgAwIBAgIBFjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzNl9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczZfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEApS7Wvfwv
+W0y4kZCO9j+7VSiNT51HcO0+ob1wQkewQQl7h0/rGkWfCW0KjFNzoz37P9xn9APT
+fFEV86tsLDnQp07CP1zS2IfxAzvrdZ6eZtU91eVtMpKtBbjCO0jlcrSdybdCT9e0
+pYykiHbfET6xXKK9fVb4yHYAxIhkDzZ+yyMCAwEAAaMgMB4wDAYDVR0TAQH/BAIw
+ADAOBgNVHQ8BAf8EBAMCAAEwDQYJKoZIhvcNAQELBQADgYEASFFxDozCQpiRNNyp
+ipKYGM4w/WERZpqHenum3Ql/Npx92Bm2q11qIrNKAEVmH+3VH7TMx6UHX281LLxS
+GsnAllb9gjNQey5DeSzL5OkiVQoJlgX3luEilTqOZrEhqojxIUogrgixJ372a75V
+aAvQ1ncweJJ1ONKrMXmOXXGjsys=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs7_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs7_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,51 +2,51 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 23 (0x17)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:46 2011 GMT
-            Not After : Jan  5 22:37:46 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs7_ch1_ta3/emailAddress=cs7_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs7_ch1_ta3/emailAddress=cs7_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c8:97:06:72:77:82:e7:03:53:56:f7:71:5c:f4:
-                    b5:ae:e1:22:08:f7:a7:70:47:2f:ad:6f:af:a9:39:
-                    c3:73:ca:f5:d5:54:e9:3d:46:f8:a4:a1:1a:27:d5:
-                    1a:c6:90:c9:4b:c1:21:32:06:9b:56:d7:23:3c:23:
-                    d9:aa:2a:17:15:61:0c:cc:08:e7:60:af:55:e6:9e:
-                    e2:24:bd:1f:e9:04:e8:09:ed:f4:a3:d8:5e:24:91:
-                    95:3e:9f:7e:f7:64:66:60:08:7d:cf:ac:b6:f4:6b:
-                    72:28:61:8c:dc:51:4d:00:3e:4d:67:70:0e:ae:3c:
-                    37:99:28:47:e7:61:fe:a3:73
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:bc:52:93:cc:6b:6d:63:bb:fe:a2:33:3d:40:a4:
+                    ba:3f:12:4c:72:69:a0:87:80:32:50:47:91:8f:39:
+                    6f:8a:78:78:9a:f6:34:83:2d:7d:6a:19:90:36:9f:
+                    fb:7c:1c:c8:13:f9:13:b2:6a:75:1a:2c:3a:76:2b:
+                    10:d2:f3:90:1f:65:df:65:04:0c:97:a2:fa:43:53:
+                    33:32:f8:8f:f3:30:a7:1c:4a:67:9c:da:81:b8:7a:
+                    55:c4:30:1d:59:5d:f1:0a:bc:b6:52:b3:09:41:24:
+                    1f:30:6b:ed:95:ba:90:cf:0d:af:eb:c7:fb:31:35:
+                    c5:5b:ff:67:9a:8a:1b:34:09
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
                 CA:FALSE
     Signature Algorithm: sha256WithRSAEncryption
-        7a:58:f4:9c:bc:64:08:aa:dc:9c:e2:d3:a0:92:cb:1a:b3:75:
-        c9:c7:39:07:84:cb:4a:0f:07:2c:b8:5d:8a:a3:22:69:2e:63:
-        04:d8:16:5f:8d:e8:11:de:fc:f5:df:a3:6c:c9:f0:c2:d7:5d:
-        6c:43:3c:e2:ae:ed:b2:01:cf:e1:77:b3:85:76:bb:76:f7:c9:
-        cd:50:7f:17:b7:82:22:ed:d9:1c:82:bf:da:3f:28:72:c5:45:
-        e3:08:96:ba:45:22:76:bb:b4:9d:f6:e1:a0:64:36:9b:a2:e2:
-        83:64:b1:76:1d:09:2f:6c:4b:a9:9b:00:e3:79:cf:7d:0b:91:
-        b3:95
+         68:79:a6:5a:7f:1d:50:2a:e9:60:26:b2:31:e8:66:e2:c1:5e:
+         12:78:d9:32:fc:0c:07:5d:15:22:f7:f7:22:52:96:0d:35:8e:
+         bd:dd:60:ab:0f:d9:dc:6b:4e:a5:d8:57:83:ff:d1:60:a5:c1:
+         c7:0c:49:c3:05:c4:9a:9f:87:ba:ff:47:9f:51:dd:04:2a:90:
+         53:b1:f9:8d:fa:34:97:a2:4b:4b:70:84:67:1d:de:f4:e6:e6:
+         bd:0e:c4:24:8a:e2:8b:fa:ac:06:2c:09:ed:bd:7d:b3:1e:df:
+         a9:be:4c:c5:49:c1:72:bd:d8:a7:3f:25:89:15:3f:1c:19:e6:
+         84:15
 -----BEGIN CERTIFICATE-----
-MIICbjCCAdegAwIBAgIBFzANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDZaFw0xNDAxMDUyMjM3NDZaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczdfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M3X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMiXBnJ3gucD
-U1b3cVz0ta7hIgj3p3BHL61vr6k5w3PK9dVU6T1G+KShGifVGsaQyUvBITIGm1bX
-Izwj2aoqFxVhDMwI52CvVeae4iS9H+kE6Ant9KPYXiSRlT6ffvdkZmAIfc+stvRr
-cihhjNxRTQA+TWdwDq48N5koR+dh/qNzAgMBAAGjEDAOMAwGA1UdEwEB/wQCMAAw
-DQYJKoZIhvcNAQELBQADgYEAelj0nLxkCKrcnOLToJLLGrN1ycc5B4TLSg8HLLhd
-iqMiaS5jBNgWX43oEd789d+jbMnwwtddbEM84q7tsgHP4XezhXa7dvfJzVB/F7eC
-Iu3ZHIK/2j8ocsVF4wiWukUidru0nfbhoGQ2m6Lig2Sxdh0JL2xLqZsA43nPfQuR
-s5U=
+MIICcDCCAdmgAwIBAgIBFzANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzN19jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczdfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAvFKTzGtt
+Y7v+ojM9QKS6PxJMcmmgh4AyUEeRjzlvinh4mvY0gy19ahmQNp/7fBzIE/kTsmp1
+Giw6disQ0vOQH2XfZQQMl6L6Q1MzMviP8zCnHEpnnNqBuHpVxDAdWV3xCry2UrMJ
+QSQfMGvtlbqQzw2v68f7MTXFW/9nmoobNAkCAwEAAaMQMA4wDAYDVR0TAQH/BAIw
+ADANBgkqhkiG9w0BAQsFAAOBgQBoeaZafx1QKulgJrIx6GbiwV4SeNky/AwHXRUi
+9/ciUpYNNY693WCrD9nca06l2FeD/9FgpcHHDEnDBcSan4e6/0efUd0EKpBTsfmN
++jSXoktLcIRnHd705ua9DsQkiuKL+qwGLAntvX2zHt+pvkzFScFyvdinPyWJFT8c
+GeaEFQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs8_ch1_ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/code_signing_certs/cs8_ch1_ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -2,25 +2,25 @@
     Data:
         Version: 3 (0x2)
         Serial Number: 24 (0x18)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ch1_ta3/emailAddress=ch1_ta3
         Validity
-            Not Before: Apr 11 22:37:46 2011 GMT
-            Not After : Jan  5 22:37:46 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
+            Not Before: Dec 13 00:13:36 2013 GMT
+            Not After : Sep  8 00:13:36 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c4:da:c4:d3:72:c2:65:ec:7f:b8:41:e3:c7:14:
-                    83:bb:fc:9e:d5:87:15:5f:eb:52:da:cb:f4:c7:db:
-                    2f:58:65:01:0e:0e:d5:27:cf:c5:e5:2c:ce:99:7f:
-                    0f:48:8c:4f:54:47:6b:4b:5e:90:3f:95:96:60:b8:
-                    8e:39:1f:a9:cc:38:b6:9f:21:6d:4e:69:2e:14:c5:
-                    71:fe:e1:e1:44:24:d4:74:45:4a:9f:88:64:36:96:
-                    f7:ba:74:1e:88:f9:6d:ac:e9:25:f0:74:58:c6:13:
-                    b9:05:ab:fa:0e:5c:77:fc:a1:3d:48:9c:78:90:f8:
-                    67:41:99:7c:bf:45:6a:67:ef
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:de:50:67:d6:8e:a7:53:1b:73:03:fe:c7:ef:59:
+                    82:0c:d7:74:ef:ad:21:33:68:78:46:27:7f:f1:0c:
+                    76:67:8d:be:ba:f8:36:00:c7:1b:eb:82:1f:70:58:
+                    71:02:db:6a:9e:11:37:a8:b0:28:27:b4:9f:be:1d:
+                    2a:fb:67:4f:a1:3a:ce:e2:70:d2:d8:81:eb:92:5a:
+                    c6:3f:97:ec:2c:49:b5:5b:8a:e1:ea:60:35:28:6a:
+                    e8:37:b6:7a:1e:83:36:32:52:3f:c0:a5:b2:74:19:
+                    b1:32:34:66:da:f8:fc:e1:92:42:b2:a6:87:48:56:
+                    37:66:e3:3c:6f:58:73:26:a1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: critical
@@ -28,27 +28,27 @@
             X509v3 Key Usage: critical
                 Digital Signature
     Signature Algorithm: sha256WithRSAEncryption
-        1d:d4:91:76:de:42:bb:70:5b:57:39:fe:bd:50:85:66:ee:7c:
-        c7:7c:7c:00:18:71:73:50:5a:70:04:43:ca:81:23:2a:42:c8:
-        8e:34:91:b9:8b:b8:f7:37:b0:08:3f:ee:b2:5f:a2:fd:03:b1:
-        59:d1:ff:cf:b6:73:f6:82:51:0a:73:a0:43:79:36:a2:c4:fb:
-        98:6c:64:bc:3a:f5:b9:c5:e7:c1:cf:76:fb:73:23:d3:47:e2:
-        a9:19:60:08:a7:c8:1b:c3:73:24:f9:8d:dc:bf:ae:5d:5b:fe:
-        48:d0:06:a7:33:e5:d8:db:4c:c9:82:a0:32:c1:1e:45:67:67:
-        ce:54
+         55:cb:0c:50:d9:e0:bd:c9:b2:60:0f:0d:3e:ac:e3:e0:e2:2f:
+         02:a9:5b:5b:2d:4c:bb:55:e0:5a:83:63:46:46:92:cc:1f:f3:
+         8b:24:de:6f:9e:c6:b5:f5:ca:57:1d:07:d4:97:4e:d3:9b:a9:
+         17:56:6c:fa:57:7f:cd:a4:55:ab:64:b7:57:b4:59:a4:be:d6:
+         8c:6d:70:8a:4f:f4:13:20:e1:70:89:18:98:77:e9:91:87:a9:
+         01:66:07:43:df:df:4d:ac:e1:1b:b1:c5:d8:20:3f:fc:fd:5f:
+         1d:fc:61:8e:43:b9:ca:ed:db:83:88:e2:0f:4a:a9:f2:20:ee:
+         e6:54
 -----BEGIN CERTIFICATE-----
-MIICgTCCAeqgAwIBAgIBGDANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzET
-MBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UE
-ChMEcGtnNTEQMA4GA1UEAxQHY2gxX3RhMzEWMBQGCSqGSIb3DQEJARYHY2gxX3Rh
-MzAeFw0xMTA0MTEyMjM3NDZaFw0xNDAxMDUyMjM3NDZaMHgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MRQwEgYDVQQDFAtjczhfY2gxX3RhMzEaMBgGCSqGSIb3DQEJARYL
-Y3M4X2NoMV90YTMwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMTaxNNywmXs
-f7hB48cUg7v8ntWHFV/rUtrL9MfbL1hlAQ4O1SfPxeUszpl/D0iMT1RHa0tekD+V
-lmC4jjkfqcw4tp8hbU5pLhTFcf7h4UQk1HRFSp+IZDaW97p0Hoj5bazpJfB0WMYT
-uQWr+g5cd/yhPUiceJD4Z0GZfL9FamfvAgMBAAGjIzAhMA8GA1UdEwEB/wQFMAMB
-Af8wDgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4GBAB3UkXbeQrtwW1c5
-/r1QhWbufMd8fAAYcXNQWnAEQ8qBIypCyI40kbmLuPc3sAg/7rJfov0DsVnR/8+2
-c/aCUQpzoEN5NqLE+5hsZLw69bnF58HPdvtzI9NH4qkZYAinyBvDcyT5jdy/rl1b
-/kjQBqcz5djbTMmCoDLBHkVnZ85U
+MIICgzCCAeygAwIBAgIBGDANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzET
+MBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNV
+BAoMBHBrZzUxEDAOBgNVBAMMB2NoMV90YTMxFjAUBgkqhkiG9w0BCQEWB2NoMV90
+YTMwHhcNMTMxMjEzMDAxMzM2WhcNMTYwOTA4MDAxMzM2WjB5MQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxFDASBgNVBAMMC2NzOF9jaDFfdGEzMRowGAYJKoZIhvcNAQkB
+FgtjczhfY2gxX3RhMzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA3lBn1o6n
+UxtzA/7H71mCDNd0760hM2h4Rid/8Qx2Z42+uvg2AMcb64IfcFhxAttqnhE3qLAo
+J7Sfvh0q+2dPoTrO4nDS2IHrklrGP5fsLEm1W4rh6mA1KGroN7Z6HoM2MlI/wKWy
+dBmxMjRm2vj84ZJCsqaHSFY3ZuM8b1hzJqECAwEAAaMjMCEwDwYDVR0TAQH/BAUw
+AwEB/zAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADgYEAVcsMUNngvcmy
+YA8NPqzj4OIvAqlbWy1Mu1XgWoNjRkaSzB/ziyTeb57GtfXKVx0H1JdO05upF1Zs
++ld/zaRVq2S3V7RZpL7WjG1wik/0EyDhcIkYmHfpkYepAWYHQ9/fTazhG7HF2CA/
+/P1fHfxhjkO5yu3bg4jiD0qp8iDu5lQ=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/combined_cas.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/combined_cas.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,322 +1,290 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            93:ae:7e:2d:c9:61:8f:4b
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+        Serial Number: 14039479151502690113 (0xc2d63fe768d20741)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c5:41:a2:3d:00:af:e2:71:29:e6:18:c2:73:65:
-                    fc:4a:9d:e3:f7:1a:6e:7a:f5:09:81:87:cd:cf:a9:
-                    74:a9:e4:47:da:e2:fa:bd:0e:0a:ae:ba:06:e8:1b:
-                    66:e3:8a:5e:bb:87:90:5e:d1:38:7d:12:93:72:a0:
-                    4b:88:77:dd:ce:02:67:9f:c5:be:49:cb:b7:e8:0e:
-                    bd:f0:78:37:55:bb:c5:91:6e:c7:7b:9c:b3:94:a2:
-                    24:7d:09:25:74:52:22:6d:4a:34:f8:92:71:b1:e9:
-                    74:9b:8e:87:d4:2a:46:f8:fa:8f:86:5c:b5:6b:20:
-                    24:d1:37:ea:8a:87:07:e3:ad
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c5:43:65:b9:e0:b5:bf:68:f6:d0:67:91:49:1f:
+                    53:c8:eb:36:57:b9:76:c9:d7:2d:26:4c:f2:08:38:
+                    e6:5d:56:b6:20:af:72:ea:ac:98:de:14:cd:35:ed:
+                    f9:b3:fb:e3:c4:1f:06:db:04:77:2a:cd:3e:3e:98:
+                    9f:52:f1:9e:27:db:91:ec:f4:de:3e:53:d5:fc:ba:
+                    5c:37:98:8b:b7:45:4c:bb:a9:d0:cc:b5:f8:45:a4:
+                    0c:58:a0:92:60:05:26:01:96:08:c1:8d:5f:18:e8:
+                    84:f1:d0:a2:f1:e3:32:67:20:52:a6:6f:7a:47:39:
+                    f1:f0:c0:47:6f:3b:9e:7c:81
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                0C:08:1A:2C:FA:77:26:CE:37:0F:A5:85:98:85:0F:4D:48:BA:83:B3
+                75:D7:5E:D6:65:E8:AA:54:31:F5:3A:5C:DA:C8:EE:5C:02:46:28:26
             X509v3 Authority Key Identifier: 
-                keyid:0C:08:1A:2C:FA:77:26:CE:37:0F:A5:85:98:85:0F:4D:48:BA:83:B3
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta6/CN=localhost/emailAddress=ta6
-                serial:93:AE:7E:2D:C9:61:8F:4B
+                keyid:75:D7:5E:D6:65:E8:AA:54:31:F5:3A:5C:DA:C8:EE:5C:02:46:28:26
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        10:2c:ed:b9:a4:aa:bd:9e:4d:47:dd:02:64:52:a9:7a:73:a7:
-        f3:58:45:cf:da:5c:1e:80:30:d9:10:a7:e4:79:d2:eb:85:8b:
-        70:4c:39:df:b6:40:fb:7f:11:cd:a8:85:d6:5c:d1:2f:29:9f:
-        8d:fa:53:bc:20:f3:c8:97:9b:11:f4:7d:39:9a:2c:a6:6e:1e:
-        a4:0d:81:e0:65:59:89:f6:a9:66:65:38:05:44:e7:47:a2:9e:
-        a2:e3:82:07:2c:cb:8e:dc:47:a2:e9:cb:01:6a:54:c1:26:14:
-        03:e9:c3:ac:fe:98:0e:76:52:f3:5b:67:ea:26:0d:98:6d:e4:
-        23:ac
+         c0:55:58:54:3d:b7:dd:d8:c4:3f:35:a4:d9:25:b3:45:08:f3:
+         5b:98:16:46:40:36:01:c9:60:d4:a6:2b:9e:29:6d:89:26:d7:
+         4e:69:35:ba:15:b2:d1:1a:5e:97:ad:b3:16:33:c5:5b:4f:4f:
+         0e:8d:8e:b3:28:50:00:ad:88:2a:2c:60:d3:66:7c:66:95:f9:
+         83:0a:ae:14:8b:d8:42:35:8d:50:7f:b2:23:1f:9b:28:ca:de:
+         61:b8:6d:c5:38:4a:e1:60:da:75:42:f3:18:4c:14:ae:b0:5d:
+         a9:ab:ae:10:89:09:cc:61:1e:ce:28:95:f0:44:98:33:04:9c:
+         db:8f
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAJOufi3JYY9LMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTYxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE2MB4XDTExMDQxMTIyMzc1MloXDTE0MDEwNTIy
-Mzc1MlowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNjESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTYwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAMVBoj0Ar+JxKeYYwnNl/Eqd4/cabnr1CYGHzc+pdKnk
-R9ri+r0OCq66BugbZuOKXruHkF7ROH0Sk3KgS4h33c4CZ5/FvknLt+gOvfB4N1W7
-xZFux3ucs5SiJH0JJXRSIm1KNPiScbHpdJuOh9QqRvj6j4ZctWsgJNE36oqHB+Ot
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFAwIGiz6dybONw+lhZiFD01IuoOzMIGvBgNV
-HSMEgacwgaSAFAwIGiz6dybONw+lhZiFD01IuoOzoYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNjESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTaCCQCTrn4tyWGPSzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBABAs7bmkqr2eTUfdAmRSqXpzp/NYRc/aXB6AMNkQp+R50uuF
-i3BMOd+2QPt/Ec2ohdZc0S8pn436U7wg88iXmxH0fTmaLKZuHqQNgeBlWYn2qWZl
-OAVE50einqLjggcsy47cR6LpywFqVMEmFAPpw6z+mA52UvNbZ+omDZht5COs
+MIICyDCCAjGgAwIBAgIJAMLWP+do0gdBMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE2MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhNjAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE2MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhNjCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAxUNlueC1v2j20GeRSR9TyOs2V7l2ydctJkzyCDjm
+XVa2IK9y6qyY3hTNNe35s/vjxB8G2wR3Ks0+PpifUvGeJ9uR7PTePlPV/LpcN5iL
+t0VMu6nQzLX4RaQMWKCSYAUmAZYIwY1fGOiE8dCi8eMyZyBSpm96Rznx8MBHbzue
+fIECAwEAAaNQME4wHQYDVR0OBBYEFHXXXtZl6KpUMfU6XNrI7lwCRigmMB8GA1Ud
+IwQYMBaAFHXXXtZl6KpUMfU6XNrI7lwCRigmMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAwFVYVD233djEPzWk2SWzRQjzW5gWRkA2Aclg1KYrniltiSbX
+Tmk1uhWy0Rpel62zFjPFW09PDo2OsyhQAK2IKixg02Z8ZpX5gwquFIvYQjWNUH+y
+Ix+bKMreYbhtxThK4WDadULzGEwUrrBdqauuEIkJzGEeziiV8ESYMwSc248=
 -----END CERTIFICATE-----
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            b8:9a:b1:4d:fa:a9:68:23
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
+        Serial Number: 16709229305513134148 (0xe7e31b8629a84844)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:da:5e:85:e0:17:14:35:c1:e8:f4:b6:97:15:d1:
-                    f5:c3:36:26:57:85:5c:0c:e8:8e:d7:2b:10:66:b2:
-                    61:92:a3:df:a4:4f:61:52:41:9c:3b:2f:0e:bc:bd:
-                    92:9b:e2:4c:ec:68:34:76:2c:86:54:e5:8b:9e:ac:
-                    2f:7e:4f:07:52:ec:7f:51:31:ed:9e:94:ed:7e:15:
-                    da:4f:fb:65:d0:07:85:c2:60:69:ce:ac:74:72:8a:
-                    45:31:e4:6c:3e:5e:05:bc:d3:2f:37:56:14:c2:2e:
-                    78:78:6b:93:14:e5:61:08:22:ef:4d:f9:bb:1b:1f:
-                    31:09:12:7a:ad:e5:cf:18:5b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c6:4d:f7:24:79:d7:8f:a0:93:61:37:d0:a4:5c:
+                    61:81:e2:1a:1c:0a:ff:ce:8b:3d:49:15:12:1c:1b:
+                    b7:9c:dd:28:f6:c5:5d:2e:63:f7:67:4b:c9:8c:95:
+                    5a:1c:e8:97:89:16:83:81:ff:bc:10:26:51:7c:f9:
+                    f1:03:f5:51:f4:01:45:da:d4:2f:cf:d9:35:68:0c:
+                    ae:11:2d:31:37:5a:73:73:c0:60:13:c8:10:73:3a:
+                    7d:c9:96:8c:07:00:b1:41:52:d2:b0:5f:cd:01:06:
+                    b8:d7:3f:d8:0f:17:f9:38:39:5d:2d:09:14:99:05:
+                    7c:1f:1f:6f:c9:2d:7d:6e:61
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                BB:CA:54:46:B9:0F:22:DB:69:82:15:BB:66:36:9D:50:1D:0B:1B:F5
+                9E:DE:D5:93:0F:57:31:37:6C:9A:F7:DA:A2:A0:D2:CE:F4:65:EC:86
             X509v3 Authority Key Identifier: 
-                keyid:BB:CA:54:46:B9:0F:22:DB:69:82:15:BB:66:36:9D:50:1D:0B:1B:F5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta8/CN=localhost/emailAddress=ta8
-                serial:B8:9A:B1:4D:FA:A9:68:23
+                keyid:9E:DE:D5:93:0F:57:31:37:6C:9A:F7:DA:A2:A0:D2:CE:F4:65:EC:86
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        7a:13:83:75:43:35:e1:4d:07:93:8d:1c:fd:4d:8f:5c:24:78:
-        f5:01:35:4c:a5:ad:5f:92:f3:23:21:0c:2d:dc:64:a5:7f:c2:
-        3c:c9:e3:b0:4e:d8:17:4e:76:4c:4d:71:fb:b9:3d:d9:51:b8:
-        fc:e0:91:a6:5c:18:c8:06:55:cc:a9:ba:9e:59:92:c4:5c:04:
-        11:e2:d9:99:1d:cb:bd:9d:6c:c2:0e:9e:f0:4c:20:69:6b:b1:
-        76:b6:d4:c0:e6:6c:4b:1e:18:cb:71:4a:9b:13:ca:db:c8:a4:
-        0e:35:c0:91:70:04:9c:32:bd:15:a2:36:72:97:d0:7b:d0:6c:
-        dc:03
+         81:1f:1d:b5:60:85:60:4f:9f:cc:9a:12:99:4a:dc:fb:49:2b:
+         70:9d:21:1e:d7:be:fe:a8:b8:eb:fd:49:e2:99:72:ae:0e:be:
+         cf:bc:c4:88:11:8e:5b:6c:d5:68:d0:cb:52:1a:7c:65:a2:c1:
+         1f:08:7e:31:6e:28:18:fa:04:90:70:d5:96:aa:89:97:9d:61:
+         08:47:f5:75:4c:9d:96:c7:37:8f:3e:f2:04:bc:48:a6:89:65:
+         25:27:13:70:5a:f7:97:ba:42:61:a5:d9:69:44:08:34:19:4d:
+         6e:1c:e7:23:25:1f:c0:f3:ad:fa:56:c2:02:75:ed:c2:51:ca:
+         cf:96
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJALiasU36qWgjMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTgxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE4MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhODESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTgwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBANpeheAXFDXB6PS2lxXR9cM2JleFXAzojtcrEGayYZKj
-36RPYVJBnDsvDry9kpviTOxoNHYshlTli56sL35PB1Lsf1Ex7Z6U7X4V2k/7ZdAH
-hcJgac6sdHKKRTHkbD5eBbzTLzdWFMIueHhrkxTlYQgi7035uxsfMQkSeq3lzxhb
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFLvKVEa5DyLbaYIVu2Y2nVAdCxv1MIGvBgNV
-HSMEgacwgaSAFLvKVEa5DyLbaYIVu2Y2nVAdCxv1oYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhODESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTiCCQC4mrFN+qloIzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAHoTg3VDNeFNB5ONHP1Nj1wkePUBNUylrV+S8yMhDC3cZKV/
-wjzJ47BO2BdOdkxNcfu5PdlRuPzgkaZcGMgGVcypup5ZksRcBBHi2Zkdy72dbMIO
-nvBMIGlrsXa21MDmbEseGMtxSpsTytvIpA41wJFwBJwyvRWiNnKX0HvQbNwD
+MIICyDCCAjGgAwIBAgIJAOfjG4YpqEhEMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE4MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhODAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE4MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhODCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAxk33JHnXj6CTYTfQpFxhgeIaHAr/zos9SRUSHBu3
+nN0o9sVdLmP3Z0vJjJVaHOiXiRaDgf+8ECZRfPnxA/VR9AFF2tQvz9k1aAyuES0x
+N1pzc8BgE8gQczp9yZaMBwCxQVLSsF/NAQa41z/YDxf5ODldLQkUmQV8Hx9vyS19
+bmECAwEAAaNQME4wHQYDVR0OBBYEFJ7e1ZMPVzE3bJr32qKg0s70ZeyGMB8GA1Ud
+IwQYMBaAFJ7e1ZMPVzE3bJr32qKg0s70ZeyGMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAgR8dtWCFYE+fzJoSmUrc+0krcJ0hHte+/qi46/1J4plyrg6+
+z7zEiBGOW2zVaNDLUhp8ZaLBHwh+MW4oGPoEkHDVlqqJl51hCEf1dUydlsc3jz7y
+BLxIpollJScTcFr3l7pCYaXZaUQINBlNbhznIyUfwPOt+lbCAnXtwlHKz5Y=
 -----END CERTIFICATE-----
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            a1:62:e1:e5:c0:a2:38:0d
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
+        Serial Number: 16519569919148996401 (0xe5414d51291ab731)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e8:ab:ef:91:ca:05:4a:18:a2:98:c4:d8:93:d0:
-                    ce:99:a9:5e:02:8d:5d:5c:e3:f3:84:49:6b:a7:6d:
-                    ef:38:77:2e:32:c2:9c:09:1d:f6:be:6c:c6:c4:b1:
-                    c8:c3:32:72:2b:84:87:f6:ba:bf:fc:cf:5c:05:c2:
-                    4f:62:23:7e:02:3f:ce:6c:c6:b6:95:86:84:d7:97:
-                    9f:1c:87:70:29:62:6a:29:7c:06:a3:b7:18:12:67:
-                    07:3a:89:aa:f0:99:fe:df:46:00:b1:2f:aa:30:1e:
-                    a2:1e:f8:2b:37:99:21:b8:85:53:42:98:4a:bd:c5:
-                    f9:b4:61:60:0a:73:bc:0e:d1
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c9:8a:2d:0d:53:04:e8:02:bb:bc:27:df:0e:b8:
+                    33:25:07:54:61:d0:d9:b6:08:33:5b:c3:eb:4c:a1:
+                    1f:9f:51:cc:a9:83:07:16:15:9c:69:0b:48:74:62:
+                    35:5f:a3:94:38:37:0f:3f:5f:58:26:9a:36:0b:a2:
+                    0f:bb:9b:57:ff:fd:70:01:d6:28:a2:b6:67:ed:a9:
+                    c8:90:15:b5:7f:91:60:32:ff:96:13:a4:3f:09:23:
+                    70:2f:38:6f:24:54:41:95:2f:91:5a:6e:a5:aa:77:
+                    da:6c:50:ee:62:e5:85:8a:67:63:7d:fc:07:30:ba:
+                    f3:96:93:6c:5d:5f:9e:2e:07
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                A6:CF:35:00:96:15:AD:B4:24:DE:1D:5A:B9:56:A2:6E:B4:2D:46:C5
+                E8:5E:8E:77:D1:61:64:BB:48:AF:38:95:0C:57:16:4E:E3:77:3D:35
             X509v3 Authority Key Identifier: 
-                keyid:A6:CF:35:00:96:15:AD:B4:24:DE:1D:5A:B9:56:A2:6E:B4:2D:46:C5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta9/CN=localhost/emailAddress=ta9
-                serial:A1:62:E1:E5:C0:A2:38:0D
+                keyid:E8:5E:8E:77:D1:61:64:BB:48:AF:38:95:0C:57:16:4E:E3:77:3D:35
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        44:02:da:cf:c3:07:27:84:e4:06:22:ff:fc:7e:c9:47:7a:79:
-        e1:9f:6a:84:68:a8:fb:48:18:80:58:0f:b0:5e:ef:43:bf:3a:
-        69:23:b2:18:3e:78:3a:8e:ff:c5:d8:76:4c:99:d5:9f:be:8a:
-        fd:0e:79:b9:7e:62:c4:c2:4b:6f:78:01:e7:52:19:ff:08:86:
-        a7:b2:17:0c:11:03:ef:42:1f:b5:5b:40:0a:3a:9f:2a:4f:57:
-        31:3d:b1:dd:a8:51:e1:2f:b2:e4:5b:2e:1b:9f:a7:d6:b7:6b:
-        76:68:f9:2e:b1:38:6f:11:21:0e:81:a2:32:01:7b:bc:c3:1f:
-        82:4e
+         3e:20:dc:10:1b:b4:83:9a:0a:9a:41:d3:6f:ec:ef:5b:51:0f:
+         a7:4a:49:0e:b3:86:f6:0f:c2:84:ea:0f:b2:08:6d:a2:7c:e4:
+         24:10:ba:45:c2:c3:9e:07:b9:c3:74:10:f2:74:7f:c7:61:2e:
+         0e:45:33:00:c4:19:32:61:2b:58:0a:f4:51:7a:03:66:68:32:
+         27:c3:20:27:af:c4:93:64:45:0d:16:0e:ca:2b:86:f6:1c:22:
+         13:74:5a:d2:68:fc:45:11:b8:f1:13:26:e1:e4:c2:b7:b5:b8:
+         f8:fc:cc:6d:fb:87:3e:5d:53:31:ba:99:16:65:7b:b1:6c:e9:
+         78:8a
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAKFi4eXAojgNMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTkxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE5MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhOTESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTkwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAOir75HKBUoYopjE2JPQzpmpXgKNXVzj84RJa6dt7zh3
-LjLCnAkd9r5sxsSxyMMyciuEh/a6v/zPXAXCT2IjfgI/zmzGtpWGhNeXnxyHcCli
-ail8BqO3GBJnBzqJqvCZ/t9GALEvqjAeoh74KzeZIbiFU0KYSr3F+bRhYApzvA7R
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFKbPNQCWFa20JN4dWrlWom60LUbFMIGvBgNV
-HSMEgacwgaSAFKbPNQCWFa20JN4dWrlWom60LUbFoYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhOTESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTmCCQChYuHlwKI4DTAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAEQC2s/DByeE5AYi//x+yUd6eeGfaoRoqPtIGIBYD7Be70O/
-Omkjshg+eDqO/8XYdkyZ1Z++iv0Oebl+YsTCS294AedSGf8IhqeyFwwRA+9CH7Vb
-QAo6nypPVzE9sd2oUeEvsuRbLhufp9a3a3Zo+S6xOG8RIQ6BojIBe7zDH4JO
+MIICyDCCAjGgAwIBAgIJAOVBTVEpGrcxMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE5MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhOTAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE5MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhOTCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAyYotDVME6AK7vCffDrgzJQdUYdDZtggzW8PrTKEf
+n1HMqYMHFhWcaQtIdGI1X6OUODcPP19YJpo2C6IPu5tX//1wAdYoorZn7anIkBW1
+f5FgMv+WE6Q/CSNwLzhvJFRBlS+RWm6lqnfabFDuYuWFimdjffwHMLrzlpNsXV+e
+LgcCAwEAAaNQME4wHQYDVR0OBBYEFOhejnfRYWS7SK84lQxXFk7jdz01MB8GA1Ud
+IwQYMBaAFOhejnfRYWS7SK84lQxXFk7jdz01MAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAPiDcEBu0g5oKmkHTb+zvW1EPp0pJDrOG9g/ChOoPsghtonzk
+JBC6RcLDnge5w3QQ8nR/x2EuDkUzAMQZMmErWAr0UXoDZmgyJ8MgJ6/Ek2RFDRYO
+yiuG9hwiE3Ra0mj8RRG48RMm4eTCt7W4+PzMbfuHPl1TMbqZFmV7sWzpeIo=
 -----END CERTIFICATE-----
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            86:f1:45:12:31:c7:2b:2a
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
+        Serial Number: 9711796497956498587 (0x86c73b75a7946c9b)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b6:50:43:73:64:12:40:26:54:0c:f9:67:e4:6a:
-                    ed:1f:18:e5:73:89:13:0f:c9:5f:6e:6e:c6:05:ad:
-                    2c:be:e4:6b:fd:c6:4f:ea:f3:6f:0d:f4:1a:34:7f:
-                    03:97:b0:a4:d1:6e:98:d2:36:fa:33:5d:51:37:de:
-                    8f:5b:3d:a0:07:52:c8:b7:71:30:71:fb:c3:a7:fa:
-                    61:f6:b4:28:be:9e:da:8b:8b:70:dd:8e:d0:a5:1a:
-                    00:70:1c:39:e1:cf:64:f8:ec:b4:83:b9:2b:67:fa:
-                    4d:ae:30:84:2f:2c:9d:6c:77:7e:09:95:43:77:6b:
-                    e1:9d:2b:c9:89:d9:a9:e5:8f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ab:08:de:44:e1:7d:cf:87:e5:0d:f9:b6:66:79:
+                    45:4b:18:3f:c4:c3:bc:3c:4e:10:1c:23:36:0b:17:
+                    8e:53:e9:1d:52:c0:d3:78:ce:74:30:13:d9:3e:98:
+                    8e:08:94:fe:76:94:55:7a:d9:73:87:01:5e:dd:c7:
+                    7b:5e:56:94:a6:5d:e6:8a:ab:22:03:cf:e1:7a:1c:
+                    7e:fb:16:c2:7c:f4:a3:6c:46:28:0b:15:15:e9:92:
+                    4f:50:a3:e3:04:25:91:6d:d0:71:2f:66:b3:20:64:
+                    db:f1:60:8d:3f:52:94:13:f1:f1:00:93:0b:20:be:
+                    f3:98:7d:c8:58:e3:f0:e9:c5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                B7:F0:DB:5F:BA:CC:10:6D:A6:64:62:10:84:A5:C9:39:4C:3C:27:86
+                61:D2:DF:69:D2:65:98:6E:36:8B:4E:A5:34:33:A7:EF:84:5D:DE:F4
             X509v3 Authority Key Identifier: 
-                keyid:B7:F0:DB:5F:BA:CC:10:6D:A6:64:62:10:84:A5:C9:39:4C:3C:27:86
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta10/CN=localhost/emailAddress=ta10
-                serial:86:F1:45:12:31:C7:2B:2A
+                keyid:61:D2:DF:69:D2:65:98:6E:36:8B:4E:A5:34:33:A7:EF:84:5D:DE:F4
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        5b:6d:71:b8:4e:e3:27:06:d9:2a:47:ab:21:a3:df:94:a9:d8:
-        62:f1:6a:97:33:cc:1c:52:55:9a:f8:ec:6d:b4:91:17:4d:2a:
-        0e:03:b4:4b:00:83:10:8e:12:c1:05:67:56:9a:30:90:91:ad:
-        8b:dc:0a:eb:3f:28:5d:f9:d4:87:0d:f7:3a:5a:f6:47:52:9e:
-        af:4e:21:d4:2f:b8:40:4f:7f:81:1f:93:ca:bc:e6:04:c5:18:
-        65:5e:b1:dd:0b:3c:5e:3a:6f:48:e3:fc:b2:c8:37:8d:9f:14:
-        1b:a7:12:79:bb:2d:b9:fc:7a:01:ef:66:c6:d4:c2:44:01:49:
-        23:a9
+         48:43:2e:21:5e:c5:85:b1:97:37:72:7a:4a:a3:c0:db:5f:c4:
+         42:51:d0:3e:f5:20:43:f6:72:61:b3:fb:8f:13:71:36:0e:8e:
+         33:8c:14:7d:c2:39:ed:36:a9:55:db:bd:24:de:96:2c:b2:61:
+         d5:95:36:97:e4:b6:17:d3:a5:6c:8c:96:1a:89:54:ab:43:f0:
+         76:b1:f6:f1:4a:0d:69:79:ea:95:38:76:c8:5b:cc:99:ca:ba:
+         0d:71:7d:0f:d0:31:8c:94:a9:2d:7b:91:56:98:a1:ea:75:08:
+         ea:fe:03:e0:23:09:32:00:88:1e:83:f6:fe:df:40:3c:78:25:
+         ae:e5
 -----BEGIN CERTIFICATE-----
-MIIDYDCCAsmgAwIBAgIJAIbxRRIxxysqMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQ0wCwYDVQQLEwR0YTEwMRIwEAYDVQQDEwlsb2NhbGhv
-c3QxEzARBgkqhkiG9w0BCQEWBHRhMTAwHhcNMTEwNDExMjIzNzU1WhcNMTQwMTA1
-MjIzNzU1WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEG
-A1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMDES
-MBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwMIGfMA0GCSqG
-SIb3DQEBAQUAA4GNADCBiQKBgQC2UENzZBJAJlQM+Wfkau0fGOVziRMPyV9ubsYF
-rSy+5Gv9xk/q828N9Bo0fwOXsKTRbpjSNvozXVE33o9bPaAHUsi3cTBx+8On+mH2
-tCi+ntqLi3DdjtClGgBwHDnhz2T47LSDuStn+k2uMIQvLJ1sd34JlUN3a+GdK8mJ
-2anljwIDAQABo4HlMIHiMB0GA1UdDgQWBBS38NtfuswQbaZkYhCEpck5TDwnhjCB
-sgYDVR0jBIGqMIGngBS38NtfuswQbaZkYhCEpck5TDwnhqGBg6SBgDB+MQswCQYD
-VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFy
-azENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMDESMBAGA1UEAxMJbG9jYWxo
-b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwggkAhvFFEjHHKyowDAYDVR0TBAUwAwEB
-/zANBgkqhkiG9w0BAQsFAAOBgQBbbXG4TuMnBtkqR6sho9+Uqdhi8WqXM8wcUlWa
-+OxttJEXTSoOA7RLAIMQjhLBBWdWmjCQka2L3ArrPyhd+dSHDfc6WvZHUp6vTiHU
-L7hAT3+BH5PKvOYExRhlXrHdCzxeOm9I4/yyyDeNnxQbpxJ5uy25/HoB72bG1MJE
-AUkjqQ==
+MIICzDCCAjWgAwIBAgIJAIbHO3WnlGybMA0GCSqGSIb3DQEBCwUAMH8xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTENMAsGA1UECwwEdGExMDESMBAGA1UEAwwJbG9jYWxo
+b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwMB4XDTEzMTIxMzAwMTMzOVoXDTE2MDkw
+ODAwMTMzOVowfzELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQ0wCwYDVQQLDAR0YTEw
+MRIwEAYDVQQDDAlsb2NhbGhvc3QxEzARBgkqhkiG9w0BCQEWBHRhMTAwgZ8wDQYJ
+KoZIhvcNAQEBBQADgY0AMIGJAoGBAKsI3kThfc+H5Q35tmZ5RUsYP8TDvDxOEBwj
+NgsXjlPpHVLA03jOdDAT2T6YjgiU/naUVXrZc4cBXt3He15WlKZd5oqrIgPP4Xoc
+fvsWwnz0o2xGKAsVFemST1Cj4wQlkW3QcS9msyBk2/FgjT9SlBPx8QCTCyC+85h9
+yFjj8OnFAgMBAAGjUDBOMB0GA1UdDgQWBBRh0t9p0mWYbjaLTqU0M6fvhF3e9DAf
+BgNVHSMEGDAWgBRh0t9p0mWYbjaLTqU0M6fvhF3e9DAMBgNVHRMEBTADAQH/MA0G
+CSqGSIb3DQEBCwUAA4GBAEhDLiFexYWxlzdyekqjwNtfxEJR0D71IEP2cmGz+48T
+cTYOjjOMFH3COe02qVXbvSTeliyyYdWVNpfkthfTpWyMlhqJVKtD8Hax9vFKDWl5
+6pU4dshbzJnKug1xfQ/QMYyUqS17kVaYoep1COr+A+AjCTIAiB6D9v7fQDx4Ja7l
 -----END CERTIFICATE-----
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            d7:f1:84:58:4b:42:ce:33
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
+        Serial Number: 10111560406944601325 (0x8c537a9de4d654ed)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a3:c5:d4:23:f8:e8:a4:02:1f:38:cd:53:dc:7c:
-                    e8:3c:49:bd:14:c1:c7:a2:b7:00:7a:d2:d1:c8:01:
-                    7c:9b:f7:78:50:95:07:69:90:a0:7a:25:0f:55:55:
-                    f7:b2:33:ae:ae:66:64:5c:4c:86:66:e0:28:e2:63:
-                    8c:11:5f:ee:a4:af:77:86:c2:c0:18:0d:24:18:5f:
-                    26:ff:67:cc:f4:f9:7d:0c:e7:d7:0c:01:e8:85:57:
-                    f4:a8:d8:2c:f1:ec:2f:c7:8c:34:d4:3d:d3:1b:5c:
-                    2d:44:bd:d1:a6:35:d2:21:36:f9:31:ac:24:cb:ec:
-                    7b:70:c8:10:97:c8:8e:37:19
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:f3:d5:2f:b4:3e:12:ee:e5:01:6a:41:a4:09:1b:
+                    12:5f:f3:d5:a2:7e:3c:d8:6f:6f:a7:30:af:72:3d:
+                    f4:f4:31:30:94:b9:09:d8:2f:36:ba:12:61:56:8c:
+                    87:f9:52:6f:8b:b5:28:d1:23:93:f3:20:d4:b5:2d:
+                    ca:29:10:f5:10:7b:ad:d6:ee:de:40:22:d9:10:32:
+                    30:93:27:22:6d:87:f9:ed:85:16:c2:6d:da:24:51:
+                    db:1a:00:53:2b:65:4a:ce:24:0f:cf:57:f1:c0:51:
+                    9e:0c:ac:2f:17:5d:72:c1:f4:8d:83:20:41:d3:10:
+                    5f:f2:e0:2d:9f:ec:da:97:7d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                CE:A0:CF:69:A4:17:A0:54:BE:C3:CB:28:70:86:6A:BD:3B:DE:E4:CC
+                BD:98:0D:A4:4D:61:87:11:83:C8:53:D1:C9:62:9D:ED:45:61:DD:42
             X509v3 Authority Key Identifier: 
-                keyid:CE:A0:CF:69:A4:17:A0:54:BE:C3:CB:28:70:86:6A:BD:3B:DE:E4:CC
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta11/CN=localhost/emailAddress=ta11
-                serial:D7:F1:84:58:4B:42:CE:33
+                keyid:BD:98:0D:A4:4D:61:87:11:83:C8:53:D1:C9:62:9D:ED:45:61:DD:42
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        89:34:9b:f9:55:53:63:83:82:0e:d0:f1:e5:0c:e3:4e:4b:2f:
-        54:20:2b:70:00:56:08:b4:18:88:59:e2:66:3e:5c:b6:0a:74:
-        16:bc:43:61:35:1e:df:e5:f6:f6:7e:de:87:18:61:b7:70:b0:
-        93:e8:5a:19:1d:01:a7:43:ca:38:ea:d2:e2:75:0e:3e:d2:b5:
-        91:57:1e:30:29:aa:2a:26:53:1b:9e:56:ad:61:41:3c:04:bb:
-        a5:af:da:75:63:5e:bb:31:21:f9:4c:dc:d0:c2:4c:90:07:45:
-        ed:32:0d:c0:c8:e9:6f:72:b5:ae:19:f2:88:9e:50:5c:5a:34:
-        47:a9
+         36:46:25:95:5e:65:37:e1:c4:14:31:7a:2a:a8:16:c0:bf:77:
+         ae:6a:17:f6:f2:dc:7c:0c:84:52:bb:07:4c:cb:1c:4e:80:b3:
+         55:74:15:69:40:a2:54:e9:e5:f8:2e:2f:b2:c9:37:ef:3d:7f:
+         87:64:02:e3:7c:f2:ec:97:77:b4:63:77:80:c1:61:25:fb:d5:
+         e0:26:c1:89:f0:0e:5d:65:d4:ba:d7:55:7b:ce:af:77:55:65:
+         96:7a:8d:7d:e5:79:a0:88:13:7a:cf:cf:4e:4d:a8:34:2d:3b:
+         f3:b2:44:f9:8b:c9:91:44:36:0f:94:eb:45:dd:2d:03:68:3e:
+         38:2e
 -----BEGIN CERTIFICATE-----
-MIIDYDCCAsmgAwIBAgIJANfxhFhLQs4zMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQ0wCwYDVQQLEwR0YTExMRIwEAYDVQQDEwlsb2NhbGhv
-c3QxEzARBgkqhkiG9w0BCQEWBHRhMTEwHhcNMTEwNDExMjIzNzU1WhcNMTQwMTA1
-MjIzNzU1WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEG
-A1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMTES
-MBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExMIGfMA0GCSqG
-SIb3DQEBAQUAA4GNADCBiQKBgQCjxdQj+OikAh84zVPcfOg8Sb0UwceitwB60tHI
-AXyb93hQlQdpkKB6JQ9VVfeyM66uZmRcTIZm4CjiY4wRX+6kr3eGwsAYDSQYXyb/
-Z8z0+X0M59cMAeiFV/So2Czx7C/HjDTUPdMbXC1EvdGmNdIhNvkxrCTL7HtwyBCX
-yI43GQIDAQABo4HlMIHiMB0GA1UdDgQWBBTOoM9ppBegVL7Dyyhwhmq9O97kzDCB
-sgYDVR0jBIGqMIGngBTOoM9ppBegVL7Dyyhwhmq9O97kzKGBg6SBgDB+MQswCQYD
-VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFy
-azENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMTESMBAGA1UEAxMJbG9jYWxo
-b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExggkA1/GEWEtCzjMwDAYDVR0TBAUwAwEB
-/zANBgkqhkiG9w0BAQsFAAOBgQCJNJv5VVNjg4IO0PHlDONOSy9UICtwAFYItBiI
-WeJmPly2CnQWvENhNR7f5fb2ft6HGGG3cLCT6FoZHQGnQ8o46tLidQ4+0rWRVx4w
-KaoqJlMbnlatYUE8BLulr9p1Y167MSH5TNzQwkyQB0XtMg3AyOlvcrWuGfKInlBc
-WjRHqQ==
+MIICzDCCAjWgAwIBAgIJAIxTep3k1lTtMA0GCSqGSIb3DQEBCwUAMH8xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTENMAsGA1UECwwEdGExMTESMBAGA1UEAwwJbG9jYWxo
+b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExMB4XDTEzMTIxMzAwMTMzOVoXDTE2MDkw
+ODAwMTMzOVowfzELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQ0wCwYDVQQLDAR0YTEx
+MRIwEAYDVQQDDAlsb2NhbGhvc3QxEzARBgkqhkiG9w0BCQEWBHRhMTEwgZ8wDQYJ
+KoZIhvcNAQEBBQADgY0AMIGJAoGBAPPVL7Q+Eu7lAWpBpAkbEl/z1aJ+PNhvb6cw
+r3I99PQxMJS5CdgvNroSYVaMh/lSb4u1KNEjk/Mg1LUtyikQ9RB7rdbu3kAi2RAy
+MJMnIm2H+e2FFsJt2iRR2xoAUytlSs4kD89X8cBRngysLxddcsH0jYMgQdMQX/Lg
+LZ/s2pd9AgMBAAGjUDBOMB0GA1UdDgQWBBS9mA2kTWGHEYPIU9HJYp3tRWHdQjAf
+BgNVHSMEGDAWgBS9mA2kTWGHEYPIU9HJYp3tRWHdQjAMBgNVHRMEBTADAQH/MA0G
+CSqGSIb3DQEBCwUAA4GBADZGJZVeZTfhxBQxeiqoFsC/d65qF/by3HwMhFK7B0zL
+HE6As1V0FWlAolTp5fguL7LJN+89f4dkAuN88uyXd7Rjd4DBYSX71eAmwYnwDl1l
+1LrXVXvOr3dVZZZ6jX3leaCIE3rPz05NqDQtO/OyRPmLyZFENg+U60XdLQNoPjgu
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/crl/ch1.1_ta4_crl.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/crl/ch1.1_ta4_crl.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,32 +1,32 @@
 Certificate Revocation List (CRL):
         Version 1 (0x0)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: /C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1.1_ta4/emailAddress=ch1.1_ta4
-        Last Update: Apr 11 22:37:52 2011 GMT
-        Next Update: Jan  5 22:37:52 2014 GMT
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: /C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1.1_ta4/emailAddress=ch1.1_ta4
+        Last Update: Dec 13 00:13:38 2013 GMT
+        Next Update: Sep  8 00:13:38 2016 GMT
 Revoked Certificates:
     Serial Number: 07
-        Revocation Date: Apr 11 22:37:40 2011 GMT
+        Revocation Date: Dec 13 00:13:34 2013 GMT
     Serial Number: 23
-        Revocation Date: Apr 11 22:37:50 2011 GMT
+        Revocation Date: Dec 13 00:13:37 2013 GMT
     Serial Number: 27
-        Revocation Date: Apr 11 22:37:51 2011 GMT
+        Revocation Date: Dec 13 00:13:38 2013 GMT
     Signature Algorithm: sha256WithRSAEncryption
-        43:11:2b:b7:e3:53:78:1d:44:94:46:89:65:a1:5a:92:32:97:
-        7a:77:06:4f:c0:49:01:c2:ad:32:d5:c8:f4:03:db:cb:71:5c:
-        7d:4c:b9:48:ae:7f:3d:18:11:9d:5d:f2:c0:75:a5:88:eb:0d:
-        b3:05:ed:0e:94:a0:19:2b:69:cf:6e:9a:04:bd:81:25:e8:aa:
-        7c:82:8d:37:c7:01:5f:21:79:5f:ed:ae:ff:79:e3:26:98:a9:
-        54:ba:53:3b:9c:bd:c4:67:24:5d:ec:a7:4f:d3:93:7e:1c:73:
-        48:79:e5:55:06:f5:88:49:10:4a:da:0a:66:05:5c:b2:0f:81:
-        37:c6
+         30:87:00:ce:08:9a:17:d1:76:60:ae:cc:53:9c:5d:89:51:72:
+         2b:f6:63:3f:72:73:63:70:4f:2d:f8:62:63:ca:b4:59:3e:e5:
+         4f:fc:90:81:9f:a8:72:2f:3a:4b:c0:db:f2:c3:7c:ec:c7:8a:
+         cc:6f:7e:a1:88:2a:6f:a1:e3:99:03:7d:1d:69:df:6b:35:f6:
+         00:1f:58:94:d8:fa:65:1c:a8:c4:a1:ed:69:80:ee:2a:72:b8:
+         34:04:89:f2:5a:26:96:f0:23:37:9f:5d:18:49:e8:74:8d:af:
+         5a:03:b8:ec:e0:b8:7b:1c:ca:29:7b:1d:54:b3:1b:73:89:e4:
+         ee:69
 -----BEGIN X509 CRL-----
-MIIBdzCB4TANBgkqhkiG9w0BAQsFADB0MQswCQYDVQQGEwJVUzETMBEGA1UECBMK
-Q2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTES
-MBAGA1UEAxQJY2gxLjFfdGE0MRgwFgYJKoZIhvcNAQkBFgljaDEuMV90YTQXDTEx
-MDQxMTIyMzc1MloXDTE0MDEwNTIyMzc1MlowPDASAgEHFw0xMTA0MTEyMjM3NDBa
-MBICASMXDTExMDQxMTIyMzc1MFowEgIBJxcNMTEwNDExMjIzNzUxWjANBgkqhkiG
-9w0BAQsFAAOBgQBDESu341N4HUSURolloVqSMpd6dwZPwEkBwq0y1cj0A9vLcVx9
-TLlIrn89GBGdXfLAdaWI6w2zBe0OlKAZK2nPbpoEvYEl6Kp8go03xwFfIXlf7a7/
-eeMmmKlUulM7nL3EZyRd7KdP05N+HHNIeeVVBvWISRBK2gpmBVyyD4E3xg==
+MIIBeDCB4jANBgkqhkiG9w0BAQsFADB1MQswCQYDVQQGEwJVUzETMBEGA1UECAwK
+Q2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUx
+EjAQBgNVBAMMCWNoMS4xX3RhNDEYMBYGCSqGSIb3DQEJARYJY2gxLjFfdGE0Fw0x
+MzEyMTMwMDEzMzhaFw0xNjA5MDgwMDEzMzhaMDwwEgIBBxcNMTMxMjEzMDAxMzM0
+WjASAgEjFw0xMzEyMTMwMDEzMzdaMBICAScXDTEzMTIxMzAwMTMzOFowDQYJKoZI
+hvcNAQELBQADgYEAMIcAzgiaF9F2YK7MU5xdiVFyK/ZjP3JzY3BPLfhiY8q0WT7l
+T/yQgZ+oci86S8Db8sN87MeKzG9+oYgqb6HjmQN9HWnfazX2AB9YlNj6ZRyoxKHt
+aYDuKnK4NASJ8lomlvAjN59dGEnodI2vWgO47OC4exzKKXsdVLMbc4nk7mk=
 -----END X509 CRL-----
--- a/src/tests/ro_data/signing_certs/produced/crl/ch1_ta4_crl.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/crl/ch1_ta4_crl.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,30 +1,30 @@
 Certificate Revocation List (CRL):
         Version 1 (0x0)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: /C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1_ta4/emailAddress=ch1_ta4
-        Last Update: Apr 11 22:37:50 2011 GMT
-        Next Update: Jan  5 22:37:50 2014 GMT
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: /C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1_ta4/emailAddress=ch1_ta4
+        Last Update: Dec 13 00:13:37 2013 GMT
+        Next Update: Sep  8 00:13:37 2016 GMT
 Revoked Certificates:
     Serial Number: 07
-        Revocation Date: Apr 11 22:37:40 2011 GMT
+        Revocation Date: Dec 13 00:13:34 2013 GMT
     Serial Number: 23
-        Revocation Date: Apr 11 22:37:50 2011 GMT
+        Revocation Date: Dec 13 00:13:37 2013 GMT
     Signature Algorithm: sha256WithRSAEncryption
-        9b:df:54:93:58:08:f4:fc:9b:4c:1c:91:ba:dd:15:38:3c:47:
-        d3:68:e8:ed:0d:cd:f5:0e:56:59:e3:55:ac:9d:5a:57:e8:36:
-        ea:60:30:f3:cb:79:93:0c:65:ba:44:9a:b1:b4:56:1e:98:bd:
-        c8:b9:34:7f:ec:79:13:da:2d:37:65:02:5b:29:a6:39:5f:55:
-        a3:00:a2:a0:0a:0b:c7:81:9d:13:da:0c:3e:09:ab:a9:80:3c:
-        ef:99:1d:1c:88:e2:c7:c2:de:4c:a0:f6:5b:a2:0e:7e:08:7f:
-        06:25:03:ec:0e:d0:ce:be:25:0b:52:34:68:94:e3:d1:f3:6f:
-        0b:d6
+         74:4b:93:6c:3f:55:63:8a:7f:48:4c:a5:70:aa:bf:a8:e6:bf:
+         d0:c6:76:0d:22:53:8b:aa:58:bd:ef:b5:b1:65:c1:60:35:3b:
+         5a:cd:e0:52:85:d8:32:e3:f4:ac:73:63:91:1b:a3:ec:df:17:
+         50:d7:1c:12:e8:30:9f:d1:71:cd:58:41:8d:bc:0e:d9:a3:ab:
+         1a:5d:7c:47:4b:f8:02:09:4f:8a:28:e5:1b:ef:45:3d:b1:c3:
+         da:fd:4b:cb:10:45:c3:12:55:42:6b:26:1e:39:7e:1c:3f:6d:
+         3b:a2:79:62:25:94:b3:f0:73:c0:4e:8f:12:16:15:2d:fb:e7:
+         6d:23
 -----BEGIN X509 CRL-----
-MIIBXzCByTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzETMBEGA1UECBMK
-Q2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTEQ
-MA4GA1UEAxQHY2gxX3RhNDEWMBQGCSqGSIb3DQEJARYHY2gxX3RhNBcNMTEwNDEx
-MjIzNzUwWhcNMTQwMTA1MjIzNzUwWjAoMBICAQcXDTExMDQxMTIyMzc0MFowEgIB
-IxcNMTEwNDExMjIzNzUwWjANBgkqhkiG9w0BAQsFAAOBgQCb31STWAj0/JtMHJG6
-3RU4PEfTaOjtDc31DlZZ41WsnVpX6DbqYDDzy3mTDGW6RJqxtFYemL3IuTR/7HkT
-2i03ZQJbKaY5X1WjAKKgCgvHgZ0T2gw+CaupgDzvmR0ciOLHwt5MoPZbog5+CH8G
-JQPsDtDOviULUjRolOPR828L1g==
+MIIBYDCByjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwK
+Q2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUx
+EDAOBgNVBAMMB2NoMV90YTQxFjAUBgkqhkiG9w0BCQEWB2NoMV90YTQXDTEzMTIx
+MzAwMTMzN1oXDTE2MDkwODAwMTMzN1owKDASAgEHFw0xMzEyMTMwMDEzMzRaMBIC
+ASMXDTEzMTIxMzAwMTMzN1owDQYJKoZIhvcNAQELBQADgYEAdEuTbD9VY4p/SEyl
+cKq/qOa/0MZ2DSJTi6pYve+1sWXBYDU7Ws3gUoXYMuP0rHNjkRuj7N8XUNccEugw
+n9FxzVhBjbwO2aOrGl18R0v4AglPiijlG+9FPbHD2v1LyxBFwxJVQmsmHjl+HD9t
+O6J5YiWUs/BzwE6PEhYVLfvnbSM=
 -----END X509 CRL-----
--- a/src/tests/ro_data/signing_certs/produced/crl/ch5_ta1_crl.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/crl/ch5_ta1_crl.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,27 +1,27 @@
 Certificate Revocation List (CRL):
         Version 1 (0x0)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: /C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch5_ta1/emailAddress=ch5_ta1
-        Last Update: Apr 11 22:37:40 2011 GMT
-        Next Update: Jan  5 22:37:40 2014 GMT
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: /C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch5_ta1/emailAddress=ch5_ta1
+        Last Update: Dec 13 00:13:34 2013 GMT
+        Next Update: Sep  8 00:13:34 2016 GMT
 Revoked Certificates:
     Serial Number: 07
-        Revocation Date: Apr 11 22:37:40 2011 GMT
+        Revocation Date: Dec 13 00:13:34 2013 GMT
     Signature Algorithm: sha256WithRSAEncryption
-        08:22:74:6f:ef:f6:1a:81:8a:04:6e:50:87:c8:95:f5:ba:de:
-        a9:f8:03:68:2b:c9:de:39:58:03:a9:cc:4d:04:ed:82:05:fa:
-        a7:54:2d:a5:a6:55:e9:37:1b:56:50:c4:ef:75:50:d1:d6:da:
-        42:dc:90:b2:e3:6f:4b:4e:29:45:70:ec:72:38:05:05:0e:0c:
-        3e:a0:a5:06:2e:57:50:d4:ea:b8:3e:cd:3e:20:a1:36:d6:d5:
-        81:a5:4c:ab:89:28:f5:d6:36:bf:42:4a:8d:50:12:79:ae:67:
-        24:7a:12:c7:73:76:b7:8b:1e:f7:fa:ee:25:f9:8e:8e:8e:66:
-        5d:21
+         ad:bf:ba:d1:11:86:e0:59:d6:ef:e1:1e:e6:03:40:54:85:f2:
+         f3:58:cd:44:5b:6d:43:4b:01:70:f7:20:cc:8a:24:58:9f:77:
+         74:74:66:02:a8:7a:8f:e7:64:65:bc:df:d8:f0:ad:72:cd:f2:
+         2a:ff:dc:41:dd:f3:c0:45:ad:cf:3d:ab:22:37:36:48:f5:9a:
+         4e:ef:ca:c0:5b:e0:f1:9f:91:a3:37:05:18:ca:cb:02:a9:b7:
+         5b:de:bd:c5:6c:62:8a:e6:06:1b:7c:70:f1:9b:6c:bc:0a:5c:
+         cd:4c:b6:e4:58:f8:e9:22:5f:29:17:54:77:64:a3:30:1b:f1:
+         f8:4e
 -----BEGIN X509 CRL-----
-MIIBSzCBtTANBgkqhkiG9w0BAQsFADBwMQswCQYDVQQGEwJVUzETMBEGA1UECBMK
-Q2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTEQ
-MA4GA1UEAxQHY2g1X3RhMTEWMBQGCSqGSIb3DQEJARYHY2g1X3RhMRcNMTEwNDEx
-MjIzNzQwWhcNMTQwMTA1MjIzNzQwWjAUMBICAQcXDTExMDQxMTIyMzc0MFowDQYJ
-KoZIhvcNAQELBQADgYEACCJ0b+/2GoGKBG5Qh8iV9breqfgDaCvJ3jlYA6nMTQTt
-ggX6p1QtpaZV6TcbVlDE73VQ0dbaQtyQsuNvS04pRXDscjgFBQ4MPqClBi5XUNTq
-uD7NPiChNtbVgaVMq4ko9dY2v0JKjVASea5nJHoSx3N2t4se9/ruJfmOjo5mXSE=
+MIIBTDCBtjANBgkqhkiG9w0BAQsFADBxMQswCQYDVQQGEwJVUzETMBEGA1UECAwK
+Q2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUx
+EDAOBgNVBAMMB2NoNV90YTExFjAUBgkqhkiG9w0BCQEWB2NoNV90YTEXDTEzMTIx
+MzAwMTMzNFoXDTE2MDkwODAwMTMzNFowFDASAgEHFw0xMzEyMTMwMDEzMzRaMA0G
+CSqGSIb3DQEBCwUAA4GBAK2/utERhuBZ1u/hHuYDQFSF8vNYzURbbUNLAXD3IMyK
+JFifd3R0ZgKoeo/nZGW839jwrXLN8ir/3EHd88BFrc89qyI3Nkj1mk7vysBb4PGf
+kaM3BRjKywKpt1vevcVsYormBht8cPGbbLwKXM1MtuRY+OkiXykXVHdkozAb8fhO
 -----END X509 CRL-----
--- a/src/tests/ro_data/signing_certs/produced/crl/ta5_crl.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/crl/ta5_crl.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,35 +1,35 @@
 Certificate Revocation List (CRL):
         Version 1 (0x0)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: /C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta5/emailAddress=ta5
-        Last Update: Apr 11 22:37:52 2011 GMT
-        Next Update: Jan  5 22:37:52 2014 GMT
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: /C=US/ST=California/L=Santa Clara/O=pkg5/CN=ta5/emailAddress=ta5
+        Last Update: Dec 13 00:13:38 2013 GMT
+        Next Update: Sep  8 00:13:38 2016 GMT
 Revoked Certificates:
     Serial Number: 07
-        Revocation Date: Apr 11 22:37:40 2011 GMT
+        Revocation Date: Dec 13 00:13:34 2013 GMT
     Serial Number: 23
-        Revocation Date: Apr 11 22:37:50 2011 GMT
+        Revocation Date: Dec 13 00:13:37 2013 GMT
     Serial Number: 27
-        Revocation Date: Apr 11 22:37:51 2011 GMT
+        Revocation Date: Dec 13 00:13:38 2013 GMT
     Serial Number: 28
-        Revocation Date: Apr 11 22:37:52 2011 GMT
+        Revocation Date: Dec 13 00:13:38 2013 GMT
     Signature Algorithm: sha256WithRSAEncryption
-        58:70:11:73:97:29:40:34:77:df:1e:5d:b1:77:6b:9a:6b:00:
-        33:d1:a3:50:34:05:f6:ba:ed:eb:c7:23:81:e5:da:56:3f:ac:
-        3a:32:e6:ff:e2:45:da:68:7d:03:70:ea:00:f4:f2:6d:52:f9:
-        5e:fc:0f:a9:83:1a:dd:a0:17:9b:6e:ee:9e:42:b5:25:e1:9f:
-        e1:38:db:99:21:71:53:fe:b6:ce:b4:57:1c:b7:d7:99:eb:6e:
-        a8:ba:65:e2:6d:16:53:7e:6c:6d:93:b0:0c:f7:48:ec:16:71:
-        ce:84:a6:27:c5:88:82:8d:76:09:c5:74:8f:5d:b9:29:46:6a:
-        e3:ae
+         4d:b9:05:ae:86:33:2a:45:ac:b2:d2:a6:82:a4:05:4d:95:20:
+         a6:3d:ed:57:b2:07:21:d4:8f:01:75:ad:4b:3d:62:9a:eb:85:
+         57:64:7e:e1:7b:04:54:25:b1:15:19:74:19:81:a5:82:f9:d7:
+         cb:d5:f3:5f:cb:54:21:b8:47:58:22:da:b8:3e:dc:31:53:4b:
+         c9:85:c4:d2:c0:ba:4d:57:60:ce:95:75:95:29:2d:3a:be:3e:
+         a2:c6:bc:41:1f:60:3a:03:ed:b7:c2:9d:9c:50:32:83:d3:9b:
+         8d:06:4a:72:1e:5e:13:a8:9d:5d:65:16:ec:87:3d:e0:b4:dc:
+         c4:16
 -----BEGIN X509 CRL-----
-MIIBfzCB6TANBgkqhkiG9w0BAQsFADBoMQswCQYDVQQGEwJVUzETMBEGA1UECBMK
-Q2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTEM
-MAoGA1UEAxMDdGE1MRIwEAYJKoZIhvcNAQkBFgN0YTUXDTExMDQxMTIyMzc1MloX
-DTE0MDEwNTIyMzc1MlowUDASAgEHFw0xMTA0MTEyMjM3NDBaMBICASMXDTExMDQx
-MTIyMzc1MFowEgIBJxcNMTEwNDExMjIzNzUxWjASAgEoFw0xMTA0MTEyMjM3NTJa
-MA0GCSqGSIb3DQEBCwUAA4GBAFhwEXOXKUA0d98eXbF3a5prADPRo1A0Bfa67evH
-I4Hl2lY/rDoy5v/iRdpofQNw6gD08m1S+V78D6mDGt2gF5tu7p5CtSXhn+E425kh
-cVP+ts60Vxy315nrbqi6ZeJtFlN+bG2TsAz3SOwWcc6EpifFiIKNdgnFdI9duSlG
-auOu
+MIIBgDCB6jANBgkqhkiG9w0BAQsFADBpMQswCQYDVQQGEwJVUzETMBEGA1UECAwK
+Q2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTALBgNVBAoMBHBrZzUx
+DDAKBgNVBAMMA3RhNTESMBAGCSqGSIb3DQEJARYDdGE1Fw0xMzEyMTMwMDEzMzha
+Fw0xNjA5MDgwMDEzMzhaMFAwEgIBBxcNMTMxMjEzMDAxMzM0WjASAgEjFw0xMzEy
+MTMwMDEzMzdaMBICAScXDTEzMTIxMzAwMTMzOFowEgIBKBcNMTMxMjEzMDAxMzM4
+WjANBgkqhkiG9w0BAQsFAAOBgQBNuQWuhjMqRayy0qaCpAVNlSCmPe1Xsgch1I8B
+da1LPWKa64VXZH7hewRUJbEVGXQZgaWC+dfL1fNfy1QhuEdYItq4PtwxU0vJhcTS
+wLpNV2DOlXWVKS06vj6ixrxBH2A6A+23wp2cUDKD05uNBkpyHl4TqJ1dZRbshz3g
+tNzEFg==
 -----END X509 CRL-----
--- a/src/tests/ro_data/signing_certs/produced/index	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/index	Mon Dec 16 10:35:54 2013 -0800
@@ -1,47 +1,47 @@
-V	140105223738Z		01	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1_ta1/emailAddress=ch1_ta1
-V	140105223739Z		02	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
-V	140105223739Z		03	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
-V	140105223739Z		04	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch4_ta1/emailAddress=ch4_ta1
-V	140105223739Z		05	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch5_ta1/emailAddress=ch5_ta1
-V	140105223740Z		06	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch5_ta1/emailAddress=cs1_ch5_ta1
-R	140105223740Z	110411223740Z	07	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs2_ch5_ta1/emailAddress=cs2_ch5_ta1
-V	140105223740Z		08	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch5.1_ta1/emailAddress=ch5.1_ta1
-V	140105223741Z		09	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch5.1_ta1/emailAddress=cs1_ch5.1_ta1
-V	140105223741Z		0A	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch5.2_ta1/emailAddress=ch5.2_ta1
-V	140105223742Z		0B	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch5.2_ta1/emailAddress=cs1_ch5.2_ta1
-V	140105223742Z		0C	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch4.3_ta1/emailAddress=ch4.3_ta1
-V	140105223742Z		0D	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch5.3_ta1/emailAddress=ch5.3_ta1
-V	140105223742Z		0E	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch5.3_ta1/emailAddress=cs1_ch5.3_ta1
-V	140105223743Z		0F	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ta2/emailAddress=cs1_ta2
-V	140105223744Z		10	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1_ta3/emailAddress=ch1_ta3
-V	140105223744Z		11	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1_ta3/emailAddress=cs1_ch1_ta3
-V	140105223744Z		12	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs2_ch1_ta3/emailAddress=cs2_ch1_ta3
-V	090102010101Z		13	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs3_ch1_ta3/emailAddress=cs3_ch1_ta3
-V	350102010101Z		14	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs4_ch1_ta3/emailAddress=cs4_ch1_ta3
-V	140105223745Z		15	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs5_ch1_ta3/emailAddress=cs5_ch1_ta3
-V	140105223745Z		16	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs6_ch1_ta3/emailAddress=cs6_ch1_ta3
-V	140105223746Z		17	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs7_ch1_ta3/emailAddress=cs7_ch1_ta3
-V	140105223746Z		18	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
-V	140105223746Z		19	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_cs8_ch1_ta3/emailAddress=cs1_cs8_ch1_ta3
-V	140105223747Z		1A	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1.1_ta3/emailAddress=ch1.1_ta3
-V	140105223747Z		1B	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1.1_ta3/emailAddress=cs1_ch1.1_ta3
-V	090102010101Z		1C	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1.2_ta3/emailAddress=ch1.2_ta3
-V	140105223748Z		1D	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1.2_ta3/emailAddress=cs1_ch1.2_ta3
-V	350102010101Z		1E	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1.3_ta3/emailAddress=ch1.3_ta3
-V	140105223748Z		1F	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1.3_ta3/emailAddress=cs1_ch1.3_ta3
-V	350102010101Z		20	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1.4_ta3/emailAddress=ch1.4_ta3
-V	140105223749Z		21	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1.4_ta3/emailAddress=cs1_ch1.4_ta3
-V	140105223749Z		22	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1_ta4/emailAddress=ch1_ta4
-R	140105223750Z	110411223750Z	23	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1_ta4/emailAddress=cs1_ch1_ta4
-V	140105223750Z		24	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs2_ch1_ta4/emailAddress=cs2_ch1_ta4
-V	140105223750Z		25	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs3_ch1_ta4/emailAddress=cs3_ch1_ta4
-V	140105223751Z		26	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1.1_ta4/emailAddress=ch1.1_ta4
-R	140105223751Z	110411223751Z	27	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1.1_ta4/emailAddress=cs1_ch1.1_ta4
-R	140105223752Z	110411223752Z	28	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ch1_ta5/emailAddress=ch1_ta5
-V	140105223752Z		29	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/CN=cs1_ch1_ta5/emailAddress=cs1_ch1_ta5
-V	140105223754Z		2A	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/OU=cs1_ta6/CN=localhost/emailAddress=cs1_ta6
-V	140105223754Z		2B	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/OU=cs1_ta7/CN=localhost/emailAddress=cs1_ta7
-V	140105223754Z		2C	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/OU=cs1_ta8/CN=localhost/emailAddress=cs1_ta8
-V	140105223755Z		2D	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/OU=cs1_ta9/CN=localhost/emailAddress=cs1_ta9
-V	140105223755Z		2E	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/OU=cs1_ta10/CN=localhost/emailAddress=cs1_ta10
-V	140105223755Z		2F	unknown	/C=US/ST=California/L=Menlo Park/O=pkg5/OU=cs1_ta11/CN=localhost/emailAddress=cs1_ta11
+V	160908001334Z		01	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1_ta1/emailAddress=ch1_ta1
+V	160908001334Z		02	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch2_ta1/emailAddress=ch2_ta1
+V	160908001334Z		03	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch3_ta1/emailAddress=ch3_ta1
+V	160908001334Z		04	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch4_ta1/emailAddress=ch4_ta1
+V	160908001334Z		05	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch5_ta1/emailAddress=ch5_ta1
+V	160908001334Z		06	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch5_ta1/emailAddress=cs1_ch5_ta1
+R	160908001334Z	131213001334Z	07	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs2_ch5_ta1/emailAddress=cs2_ch5_ta1
+V	160908001334Z		08	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch5.1_ta1/emailAddress=ch5.1_ta1
+V	160908001334Z		09	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch5.1_ta1/emailAddress=cs1_ch5.1_ta1
+V	160908001334Z		0A	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch5.2_ta1/emailAddress=ch5.2_ta1
+V	160908001335Z		0B	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch5.2_ta1/emailAddress=cs1_ch5.2_ta1
+V	160908001335Z		0C	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch4.3_ta1/emailAddress=ch4.3_ta1
+V	160908001335Z		0D	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch5.3_ta1/emailAddress=ch5.3_ta1
+V	160908001335Z		0E	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch5.3_ta1/emailAddress=cs1_ch5.3_ta1
+V	160908001335Z		0F	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ta2/emailAddress=cs1_ta2
+V	160908001335Z		10	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1_ta3/emailAddress=ch1_ta3
+V	160908001335Z		11	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1_ta3/emailAddress=cs1_ch1_ta3
+V	160908001335Z		12	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs2_ch1_ta3/emailAddress=cs2_ch1_ta3
+V	090102010101Z		13	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs3_ch1_ta3/emailAddress=cs3_ch1_ta3
+V	350102010101Z		14	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs4_ch1_ta3/emailAddress=cs4_ch1_ta3
+V	160908001336Z		15	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs5_ch1_ta3/emailAddress=cs5_ch1_ta3
+V	160908001336Z		16	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs6_ch1_ta3/emailAddress=cs6_ch1_ta3
+V	160908001336Z		17	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs7_ch1_ta3/emailAddress=cs7_ch1_ta3
+V	160908001336Z		18	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs8_ch1_ta3/emailAddress=cs8_ch1_ta3
+V	160908001336Z		19	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_cs8_ch1_ta3/emailAddress=cs1_cs8_ch1_ta3
+V	160908001336Z		1A	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1.1_ta3/emailAddress=ch1.1_ta3
+V	160908001336Z		1B	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1.1_ta3/emailAddress=cs1_ch1.1_ta3
+V	090102010101Z		1C	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1.2_ta3/emailAddress=ch1.2_ta3
+V	160908001336Z		1D	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1.2_ta3/emailAddress=cs1_ch1.2_ta3
+V	350102010101Z		1E	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1.3_ta3/emailAddress=ch1.3_ta3
+V	160908001337Z		1F	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1.3_ta3/emailAddress=cs1_ch1.3_ta3
+V	350102010101Z		20	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1.4_ta3/emailAddress=ch1.4_ta3
+V	160908001337Z		21	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1.4_ta3/emailAddress=cs1_ch1.4_ta3
+V	160908001337Z		22	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1_ta4/emailAddress=ch1_ta4
+R	160908001337Z	131213001337Z	23	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1_ta4/emailAddress=cs1_ch1_ta4
+V	160908001337Z		24	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs2_ch1_ta4/emailAddress=cs2_ch1_ta4
+V	160908001337Z		25	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs3_ch1_ta4/emailAddress=cs3_ch1_ta4
+V	160908001337Z		26	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1.1_ta4/emailAddress=ch1.1_ta4
+R	160908001338Z	131213001338Z	27	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1.1_ta4/emailAddress=cs1_ch1.1_ta4
+R	160908001338Z	131213001338Z	28	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=ch1_ta5/emailAddress=ch1_ta5
+V	160908001338Z		29	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/CN=cs1_ch1_ta5/emailAddress=cs1_ch1_ta5
+V	160908001338Z		2A	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/OU=cs1_ta6/CN=localhost/emailAddress=cs1_ta6
+V	160908001338Z		2B	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/OU=cs1_ta7/CN=localhost/emailAddress=cs1_ta7
+V	160908001338Z		2C	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/OU=cs1_ta8/CN=localhost/emailAddress=cs1_ta8
+V	160908001339Z		2D	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/OU=cs1_ta9/CN=localhost/emailAddress=cs1_ta9
+V	160908001339Z		2E	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/OU=cs1_ta10/CN=localhost/emailAddress=cs1_ta10
+V	160908001339Z		2F	unknown	/C=US/ST=California/L=Santa Clara/O=pkg5/OU=cs1_ta11/CN=localhost/emailAddress=cs1_ta11
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1.1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1.1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQChH1RDIGVjsvyL1/aokPAeuOkGN8sbyUdWOj/sfubuxprUFQ1k
-99V3L1IxbDaNLwd/DafPea9ocCt0pzCSHlX8KvS3w0cBV09luli/dXMCTEyoUT2C
-7lf6k2TWUwUSEDbJnMOvbFadIERLtLxn2AaZjvoyTMFPCVpG7AbPrOH6IQIDAQAB
-AoGAEQmRDXAViI9aqSbzDCwXWAhRi7jGn2+PPYz3SXi5zrHtmVOIkQ6r4eh9FoDM
-2+0HK+Yzwnqpk6+YyMMNHcZbbR3agEnwfL0TXE/WLR7x0FKq7jkEYo4o8F2+WaNf
-6EFd+3YFjWyN4HO4cDm6zVNu/YK7itBbBuWdXzKi3/J9bskCQQDSw6lKBlmPangw
-Q0odz7HNaTuFmyM7z4mxTAK6lWGgiLwgLV49/k/pajAo9E+ljg1cJ5aNcIY2wK7s
-V8fN4m1PAkEAw7QeC+EHB8xZER8Z+7HSgnZXvbjZghXUvvoKbQK6NybRkYg554Sq
-1lRiPpx3IFuy7DoPOmiHMSiZQSPj1x2ljwJBAMz9CmD57g+D0SO3vpViFR+g0whu
-TAV3JAex0xGgCpT1iGuPVJLdDuIJqo+alwCBOdNAmbg1EgScwUUTVzySlhcCQCDr
-W2KEJ7qYFSNcJ/K+prprTbcMMQpAwdieFsLfgpNkZDwmvhbDqjkDWMNPbnpy8lXq
-LkWU76jFO4JJlznIMuECQFcJ2+S+WaaS8CHkGclA/NF/YzciQMBZbbi8eRMED3iW
-DoWvdWM+TOJJ+2uEG62lssrJb668GnEY8M6ZdI5jWNc=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdQIBADANBgkqhkiG9w0BAQEFAASCAl8wggJbAgEAAoGBAN/aYIvG1lX30Fun
+WofSkHucRjGWXhWgx0Szec6u16+Zqf5txmkjCUVoZAHcoH6M7cm8FNOEYiqKITBI
+MJeUmYRp8MBGpHKCUTD+8PxgbOq4fVLO/eUgt59LAyF081g1Ou/34IRkBoQ2YuiC
+ZYIeVsfqHutlfbODnPzmumXEguNfAgMBAAECgYAnRt7Hx7SV0ux5GG0XBcgaGDps
+uvB5JQOxtzf5Hs5zXifon4Q/sEkRJ5bciMSUT8/tJJYW4tSCmEfoe9Ii1oz0zaPh
+nQ7JcKT8GPeiKWIZ9bP8nggCfhKLEIU7UMZWK0wQKSGIa84oIcDRvmFViH/+IYZK
+LWI8kJCwT8oAey19yQJBAP6Bs4dZjTDp9fFndefLh7U9W3Iv/aioXlTYO6cBe6zy
+xMZ2JlXn5q4ShmUf/JdoyG5tTbdgmbFixTCGZwEz/csCQQDhKqFra27TYuUp/rxv
+lfsHCSXp5FsOPmGNjE0U3AuPPrgXCngeDAFLSvConNxJ9mCD5kB5GMLBeuqEFSIF
+8P49AkAB6xxdUtF7oufVr//1hVU6ioHb9Hym/s3nOdIJSjuSbCoLjOxxDVRxz3Xv
+4TPYOFP6cRx622GNMr9lxD2WhrvNAkAlwGwIAp82OeKKQ/d8Df1klJgSuwK5RKQ+
+g0N5N9uITM+4rTyubPzajtoCqyoUDIbqFnTA2PHuVplzQ8fMjzdRAkAEal2tou53
+euNpN1JajivVxfbMn+o5BUxuSyiI/X/ANYhZU64cNzgqIgETkSJR8JIfauofbP/j
+pKSlFv+m4wBL
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1.1_ta4_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1.1_ta4_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQC4auO1v2Vm9LMyc6lkt92gSulw03tcG1t251ajcg6d+p+ypUfr
-P9uae0XSF3fKBbOVIhV4nqvzS/qDieYZVCJpGGe6uzcqtJNau5xoW+yxfqwBe7PZ
-kVeT60PmpjXhtcItyrtjrzXWtBaao3ocreH0+2NK/T1XmTO4HkHp+UKAMwIDAQAB
-AoGATJ2Dqq8wVnyUsgIhPsmwVnao0wnZNyPadOSZNuAcuH81t4c5AMAP4PcTw7ui
-NZj2yZ9WYj0xXKuVEO7KXH16qY8skQkH9ooVIOyy3V7r+/vmgJ+ey5R1AlkalJ+U
-7y/juiu4og9g8WwFqbu5zvUEVcwHE4qRpuaIzpcYdftClWECQQDyeuWwe5Uv4Jek
-o0sZuEr9VfjnXtcMkPSWP9ZPVXuyo4Kgx94f4m94IOuwWAZFEWIGDEgB5dBM+VgZ
-Kc3gOlsDAkEAwrM4tiObcQNBl3f9c8L2AZcOSRlqVBp00DA6x8j9FSxbpK7bmfW8
-9N37b1Mkm9bICoPuXZhyqF198uGVltcnEQJBALRqEKBhMz1uRCYxgV1frBwWbZ3p
-COTGrdVlJhXdKq5dzoHGdFUQ65NcG0EYHYIiTublGGahEX1UQOJoIlBl2vUCQQCw
-eJM5e3Kjb0kfSfGe4CHr9QdMuE2Ip2YjYOOWO5UwgMEbtiVzGanH4//GunxfB8DO
-zx/ZE5kxA3RqFY9pZd+RAkEA6eaGhnvreUcQQfRTSnyXf8AQPa5LzF/Dx9bUO/HU
-Un1M6et1+/bxf3ViW67Z0IX/+z+h+S8Nzk0ajIgmgv8qgQ==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBALpAvn4bL5IRzNxE
+FHaHimqUtihOh1u8V0Z1YzhNkD56Rg6H6akEGn3lINyBmnl+G6vOUM5HVASYFtWm
+bRY8Uu/tQ8Wb08hIy0ddCB3RRP18x1RBETs+rrt/lKYTj4lsJLOoXuJdIECFK6Cs
+7aOoshVZ/K3oXXLuZOucMIwKlzL5AgMBAAECgYAVKIe7YbE8wcLo/t7oPCuQQgaT
+e6BK3pF3kpxL6BvLzS4qNmxn4+xygtYB1sNKq/XOxahOVrIHt5NYgAiCbyXoo7DB
+aV5VSYhU9uG1SfpOKQJZafIEtOQg/UFRVsnkH364M5ht5qigkzG4hfbSln/ZMeOO
+PgO0TqCaZSUxHEwDAQJBAPXMmvZ96IVL3YLDDoV5VR88TnHnsFjZXIHXjMHk2Mj0
+18lMuC0RlmlYL2AMdk4Dd4FhmUsGjWt3yvJDjjAGzKECQQDB+4NJkcBFa1C1oEdS
+IuxefQNkYWWGHCP48tKwAzxVGlgPmgE7SH4rkHgnYzRBL/w+StH9hHsK471VLgF7
+WK9ZAkADJoQ19JcuXjKQon9lJpD4vYUj4JxaBy8wWtrrAUvmB31cjyctLLSI1SCG
+UqKRjWnStrWISKU3Y2mugT8pTm0BAkEAnilvOz3ucet1DBHZ9PtqlAQEDwVmnLk3
+D1UVOdP5jj4DjPz5gheyX9zUSvEU+w2f8j5ZBwbMt+1GQzxWkvaVSQJACH2saMhm
+iqiXr2i4tuL2/7rpdfe221bYkPEmkapiPO21aiWJN+KD0xt2422YpAtfImP2FekB
+KNaULsqs5It7jg==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1.2_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1.2_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDHl716eHL2u29bygc02HCTlDnWnHOyWMb6EOuOx1Q5/Zo19Syk
-rubKopwHDFcFeMyLmC456HRzKL/3v9H7XRCd8Bl1nTX+UJd2cG0AeWYaL6/GEkUW
-Reo+8JA7Vp3t93C63vfsVSvusZv7HVVGZYbDG55QuYy50wJzquYeTRErvwIDAQAB
-AoGBALu8ktE7soc5zoj8AsNGQr3N0ol3J6w9rQtSFv95plPVotPWBWPxz8wSH8jR
-ZpkTAvLa9cAqUj5vugGDQDO7WgBJ+2VWA+PbzRoL3QHcouiP+8ZuM5vM+gWczThg
-PxawMfH8N0L2Tq/F0LjMGyf5jMzSN2QOIfTYpSys2mUb6sPBAkEA91vupkbiVr+Q
-Yyg/J+60YPQO0gIo2gk1SCehyhAbNlX6edoFLrPMDVFkEaSNvJTdgTFIW/VqLlNE
-V2XxnkGQeQJBAM6QpU7WSK3Gdyp9/cK8siid41zsp9EV3kHBGd3rXfp2H1ZgkX6r
-aArmC9q4QzrwtSbK1BU002DeI99XGk0JP/cCQCJ0utyMmTCuRIWbcJi2Zofu1zWn
-uVsN108yvhWwgqnh9h8NIJWt0+mzAbZ3borrTaOWYtb0a5MCZE2sVKjPxzkCQQCv
-yw3EID1OFp8HvJ2fgzMjuerrBER1fmTeFNZMtKgQJULaIejwojMzQ0BHbZVZrcyd
-LPR8764MvEBPLDOn5/1VAkEAzmStPUqA2sqy6jwuVxhcUzHukPsdZ95ybQ/wC6dJ
-ZB9uXYprFvXTSt4l3h7a5d/+k4ARCd5YAhFZrId8fDy9Dg==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBANt+QdiTHzXlazgl
+k+WZz/7HuKsLFEcjZlLH1BhY/zmmxKNELka+JHudcSYSapm9kgFa3Kk2PC34Qrhf
+24ePCZqDMly2HcXkqkdtRhEWckTXSerTSqRSmvSKteTvMntxoNeOcYYiNERKlVo3
+78R/Vx+ZMjnvq5QFG5qI3jmFVkz3AgMBAAECgYBAC7hE7LD3tgiyKmzcWyRQ8JAX
+ALWbCF5MG1js/dMDTIEmLrfeFo9orokcldUbJTCcSpoGmfe3ZjB5wia5iGhBbldP
+ULZfElj2ynqhP/JUltMFP/RkdSu2w9QJQxrJG/4jAsA1/Nv69pgVoku37XKX1phN
+ryGGxu8DtdSILbEJIQJBAPHyv65WWVIPlQJS3iaBo9EE59EtnTPHOZwz/hFc/ugN
+nytytbnwgJLen114kUhQ9TROQWC0xk6MSZWgiRRMY4cCQQDoPaZtgtvSlJPE2gIb
+acmqWJv+1p61HvB49WrOoCnBSd9rBk0KHT0yeN2MJZb8dlhSjGOphWdBj1/g9uYG
+3QcRAkEAu8V3eafOHl+1d140xpGqP1edSbwq2rptPYskTPltY07fDusxmiLKxjE8
+YWBm8EbUZkmtd44UsXUyzosOl9BJFQJAdjzc/KhA7odCbFhp9jb3u0h9s1LlXmUw
+HQUlqakVWRkZLE367wlP3OB4Ox/wLPy7nttm6inHFjO+prRNDHV/YQJACM0ihM1g
+uXi26OnCXUAb/TUkexxgpoxBwVB6qR3iwORu0qMD5Ki86MeESyXm0vKMybN42QUJ
+Xfll9NdLZmFHjw==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1.3_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1.3_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDZNOsoImpR+BEs7h9tyfESWgQz3dYnyppArt9ceFMoyDfSRxTh
-/CLqkNkZBQj9t5kglygj/T1ihw0poN6VYTNs1uBl28GLjHDDzmbpk+6Sn4cs1G8d
-4ZLLijiklQpqopTGQSUXzqYB+88DUkCTNDe1dEgV1Odkgkbus721HztCgQIDAQAB
-AoGAKsOPdORpuF+1yfnL+EqlCu7sGuYXLthlzExhr4wFG2doDh9ujhudKD+Cbrme
-Do3iORdpkMRgHJDoV4TTredoPy1d/eCdEROIuRpCpn15a+LcLzI1l3V1Q8CsCe8R
-RYvnt9hOnJy+UuVWSPJe3KYV+cA0IQI9mnmTqdEVHtOvzNECQQD/QK7GifbUTfvk
-g+n/30zSs1M7+iHB5edQgIWfN0tjS/EjiBXrKlvLU/JXcY9w2Iu535h69epMu35E
-+HGhnPoVAkEA2de4OLuBbCvQw0MwdmZslRg3/PPZwl8nIN0IJEll5SoVvDU+dEJg
-k4o9EmH92g6D5iOAJDkqi+1Dnk8s+cldvQJBAPiuohjYTVxmZeUrCA28FnKpN4yV
-k9H/FS//JzAJhS9Gy7acXQ5yhGBCdzbucpu0vdznlP0nHZCIkurLSpn0AEkCQEnC
-PsAGzOWBWGgk4c3VFELPNnXRYxPq/+aisFUI/RVA0KcvJ/xZVTXfgposz7T7YTGV
-J5gcOwmxxkld6Y6R3ckCQHvkKIxyxgYRWM7whI4+1IYj/uyi6au0QHL33YegIGrV
-8PiPu1pHaHhUOdAZ/eezCOG5s716VW4Y74cAuLXm8Yk=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAM5YigVnR6limTcT
+NUx0dZsv10wjes1gNQyVS1iz3cgtaa08jdMnDQIG0EtsblfpHzzc84giJYY1E5E8
+n3ZnpK6YY9JzTS8H1X+AfieSJRaqMv56F2XVn+45n8ihV2qbLeNh2TXVlPv6lSHD
+MTNQ1i/lwHq7p2Gk4JteypkqXWrbAgMBAAECgYEAmQTflZI5eks8A7Oi2seiTyrz
+JetJrfOiY2pzLZx043WJ4IX/Ro62/sG+xa/rRBYErEXN8y4fVZ8Wm6WxO0UwwVQU
+/TSsJUv1DxMxSkGSPkESQvRYgS83K8ubuDrNGMrCzC4oL2cH4IQyvlS/LLEzcSKm
+yulGz4xa7pSwKvt28gECQQDrh+X2Aki1qKw+/Z/FnXp7Vs5dhlT+qR73Wfpf6goy
+0Awf1gt3HvV3cOWLIl+hJ3jXRxCdcDcU961IFW0lz9rhAkEA4EdU50RxIRygpP4U
+JuVqGnYwKTuI5dZuJ2PUy4iqEap08L5dJtcTeEtesS5h0n1Fy2NNzLUz0PX6Wnms
+D9YZOwJAH1A1AYzyL7yaEdHUUQiLxSQYUZTPbf/8DvSWdfP+oRzJz928Ln0eM1/+
+FI5gWmOODEj1a4kEubPoBMJcfX9x4QJAIJ6/XpO50JMVWmoKDE45zHd8McMS+jrh
+8qC2hpPuCHu+XnWRnuCRWGG9+A9C8xZ9XEOpQSjpzG66ZwZjXDpLmQJBAMwFdcdn
+KuOs92pThe0PpfZons0DUGHJt0r1cEHWy0wGVBkDQlGBo17NKeA7Rq9velNCGTlT
+nrC97VN4YgRwIM8=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1.4_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1.4_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDMVKBVdbFpM5a2lymCBgZG8kMvGVe/kvBOtQFl09zjz16p9ZmO
-kemtiBWLJV6Sxv3WnuUnVllKCeCEuIavu53p0pn5hEjWtjXoquCzrJQJf7hnU3Um
-ZRa3z5JSvl8H2t34sRx8VDd/Zvfcl83SDfpYpC6WuIP+4j22+8UIRrobRwIDAQAB
-AoGBAMZEN2+1S/iwvkVeWEB6aAzfdqF1DdguVE+LA1gzQ9splMmGLwJQQ1bG/WCP
-Wj1CKXzfoauR9gIJo3olM0vB2W8Vg67Sfi3PQnmXxfQU7rRV2/A8jCz/wjbIuQq4
-wYtq+7fyZnC4cv//+PUvw5n7fSTel594FG38b4yKLpF57UbBAkEA69e2W0ZAcS98
-KROaDAPVSs9RGQAghDaoZ8kXlPrFD53ejzfEtFvp0evuhdaoti4eurqKFiieSXUT
-azOQ5gkPvQJBAN3LbGPs+dvXZpJ8P8+i4L6ODNKLhzs22/5xdTA79IyM1eWckJiY
-uWotb1bhtKqynx5AfxfTgsudF+pgVqe1lVMCQF5n+Q1Mb9tfALqIqC+LEURi/Lmf
-PWTvZDY3XwM55sw7i62Uy17PNCfd45sbtGlIyPBCX6hDFimdfep5t9T9Z5kCQFE0
-mMPhUP4P2ItLmKVyMi0ynzk7QtEIXfXEHq8BVKFdMzd1Ym+sgz5/0iMSUm6pJZ8S
-6DWWCG56XvY+PZv73OcCQD5PKZHpX7FbHsQZ6Pz4LjJN4si5VjkPVpDCH5QN8kyp
-7L5BFk8UVp+jDP2T66H5brfa31a5MEq6NzDZjsgh3sk=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeQIBADANBgkqhkiG9w0BAQEFAASCAmMwggJfAgEAAoGBAOk8KG64euN68u5e
+aXpxuLuX1dPEdz6Q8ylpuFG6iydNP7IQdoZuOEpJvs4BxdIObg6pUemUV85nS5nK
+hJOp+eY1HA/WPbHBxwDX+iwFoCANhm0ywFQP6Llutd0aAEyJv9RteQ7nThDS+3Us
+A9p1yOG33C5CxZvssvEVbdtW+SCjAgMBAAECgYEAgpD60YDUyqP5exe/VJx1Hg9R
+1MsXNh9PAM/+L0KOw+Gq1rQApiDtwiimeAzmAUGyuuJuyKQSw6lv2RhWP5PYIMWl
+zX5AS80oGyL0F3UW9zmHMEjqz+ZvnWmkovhxAjC/wJuLX7BP4D6S7u0BEb+eYmz0
+8Jq9uUVS20ZerpMmWgECQQD+87rUM1az1NFumEba35hKmRdn1mB72vWR8rUrF8Zf
+aJwSzKyzYsmAFEVn7jbsAR2Xa7sxK1gjwBLPpl+kfUIRAkEA6jGTnK7ZV34Edo/R
+5m/WWv9aXoqoUkx7c81zbNCrcTiew8Iv/jik5HcAbeUxqAjzuDlQdhgPSnugzc3P
++cpDcwJBALJjl7YitefeYSwhIHLFQKnxtI7TUW9YJbuZN2qPmB3p9EqzK6PY22Ti
+yi2OYJ+BqFLq7m/ZBDL/kin5H7LYcgECQQDOpyygJ9H1WGfLzyDi/HDkH0u4/RWG
+eaK+Dt75eDCwWcwO5X3AEG/AghnI32Ov6SZWu4x6iMSFbw34TNJmksptAkEA1k/d
+oS1pjwo8yJtxmviqlVSoUyuQbuQJEmBfG3JZgNLJkFuVxrRMyR2x4aROuBUnPbNO
+yMcLBi+NXhgCttxckw==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQCxrPUgXL9EoKD/CygCG53dHzxq9xbAjuyvoaTEzyaOQ8qKqgWP
-ohADMkHQbrRSRUeoRovF881VVvXQw+zkpGOLmof6dHj/LPdmdz8FwzHQRl+2F6+1
-dp/YjSLTdqytVW9MdionjukidELO20K5AFQB/hjGSpa1uYgybcXZVvyHlQIDAQAB
-AoGAIqJLWhaaNh91oqGjF94YRK09EsC9j6WMn6PLwY17v4mZZrRDxz7ZDjZyu9WI
-kuzsTfIKdvjSUstTuXEnsV4WBSJeVrflxkOMWI5tuGEn/7l9Ywsc6Ajpp9UIbVlY
-Cpy/yZnznqaoiVObmkkrxZArImwUjRgaltA6Z03IWQWUZEECQQDZJQAvT9bt0wS7
-2jZIV56qQRCPjdGfboPb0CZ80urPxwFnCBe63OARcnG2psYd5V557xoynXCT2EXy
-QYW+odHlAkEA0Xf09H5M3ymXACR9Gfm83z+j8Ev9QPxK1vOFrw6GFpeseX8SSZ0f
-X+4A/M9vRMUyK6ukgXdRZREQFptV3GtD8QJABcqq2pgyj11Vfv0u/Xb40Gmz22BY
-+vujoLVIkYO+p5QTQYBBwcYqY8y9o7WHCz0W7AGonTj9y7O1CeUdgBwo0QJAc9r9
-SR1yNxwxwIpuByfyJyhz7DybXo4sdqdKkYBe+a/6XVjDLKQS7mQdd7bjvA21qiHN
-Yy4zfsrpMxfHbZqGgQJBAKwzkCzcCMAQK3P0jkGblsK8iBPsOiySRuH+7InuKKfs
-R/nPaeSdE/RCEFPsO1gbhAJPEd009sNktR3mlscBXqo=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBANo6snQWXDh8kzpI
+y59xfKq5/9clX82QbOaHbe00DxIZAKg2/lFLsjh2VSrRzjujeHXbyLqFi62ADoSr
+H0uAkCBWSXtxoBb4FYrNcO5FH1M0PIXfEHXisWiXxQ1mf7/ns9EJAxtQFNzjPqm2
+amPmD1E+BllQQ9oQmQ15o7R2iaIBAgMBAAECgYEAnj7AFsP8HY3gKPyOg1EFCLwV
+lEpqvSKEhWohQUdlwkbVHiW6pvLQCndsbL903/Q7LqOwW+jpD2fznyqDZ/mTCDjW
+yrWzI85x5NfasIKIRMtyxS35YuL1knPkM6tZmsUMHD6pgo6HF015MZQC0ftniWQk
+Ej2pKPtfpLpNc6czrX0CQQD2J5/JmboUS+fQ3njqeVrD6tViQ4uFLJcJCSFt5fyP
+EstsfMU+TjvpSmfGJ7DYusyTQmYW9MLjnZz4NjdLcAOLAkEA4vUk41yrIYBNwGii
+AS84fBYbd3WCS2qeuuA7SirFffdL35/3OmOtq5EyvxessGCCr7ln68Sr65v07QCe
+4ZgyIwJAYgQFLFF6NvrCo/jyTOtlqP2pWidrNuw6d+6a0RfzKUVimyBTqiucz5hB
+GjZTxPkc3MZjwGBV+iyYhH2SJwfDYQJABx3WvUZfm1pRldHyGoVniQSMce9+WW0L
+cyKq2UWEEdIaT/XNI8iSXoncBH/yi0lLb8UpjAwLtASc5n2Zfctu7wJAG0LrmIoB
+2b11B0S2zifCs9M2pmvOhcwkI8cRwf7CxuuN/z4yQLT+uOaZNduw9X1/XjPsP+Ol
+01sc3dlmZ2s4ig==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDho9BR3Atzb0Tyx2vyndpW3tRBYXVIeBAsU/HBKAFKEFN9Mrzi
-AaJ1WQvPOvxBuCw2+/492aJBe248Cql+dFqG6gZqK608fjKLl6S6U8G4vPCPgCJT
-l2a7gBUFltzfYilNFd+F5pAwTSnTBLdPIkC4oSLtDkvmAILfiUhjh7WAVQIDAQAB
-AoGAWMh3QK5/hvVCQPD85aL89W+KPwuU9WXgn0CMgH84Oqc/4qRjM96GyPu3rNu9
-xDIum5f9yuJmeLOThWaAmLQ5pd0Dirig+p19yQRZzZkFfUgtKY7MWqNbDF5PXjfv
-eNRE2ahH9I0R7925iRDiOpCDpHQrGgk9VTodEESvZHDX9QECQQD6pqxSmCfH7wVO
-DCfEaFD4Omxop2zRFpD+cSKTHQa35gRz2fE8iqYlbW4dQwISJ63C9eKmeKrHfO6V
-0kSHHcjBAkEA5nSAqcfm+Ky2DBjWCe7Ur6afgNnsSYwzRNEuPfonHVhriWAuO2y0
-6o8MKH8JwdFL/nl123Tve0a+eOZrZuGolQJBAOo0lS4z+G/sGoPb/cibRJU9WhDL
-6HTS5jaqFglqhN2O8zghPDU6xJaSUuLKuwOlycozIU410DXIudKKf/fUz8ECQQDD
-lhrgfVUstkAnEikN8xG1Jd/3Vnywivm0LShm11i9Eh7qT6PNMVx2OgOilvbr9Lrf
-dawuHhdl88uSBlUe0uPlAkBm2Vz/wge+qFNiaaBBzp7/PBbhv4+bzhPNyUR33F8h
-++iQhJPCY82FZUjz2i36JGjyT3Tmm6AcSL81fWwxo9Wx
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBALoONpCga3UZazB2
+VJ4gsIFwIUeXnMEVfJ4tUDzb3IzQMZy5eMYqXFPK7dNE4vmT2LW2porCvb5Pi/Wg
+KGjP7Pnj6Veoq82lRQ2C6/Bbqi0biGUwn6F0WR/l0iX51jE/CqJKkl0qMC4/L3JI
+k/iNfL95IePhkZqnAwG6IJWm2lY1AgMBAAECgYEAqUWPHSvmOAZlQBUYTTk+fLTw
+gjsM0Zpj42EklAoP8UjlKkqP9/LIRy/kCgetXRXG3yQLB0m/6Wpj0pfgy+MIHI+B
++AJwJIXEhF/urTWIVHvzcxPBUXOu0JUDqGq2GDto5Pnjs687ACgYYlb9S9d70n/D
+ZUjdr6NxklCSpDDs3g0CQQDsPBbcTVu29qS300zWmyacbzwfChwy0McL2bkUnluU
+jWOp6CRLU+QUckpNwhUn3bh0YQjb9o0j7YnkS4ZCU/obAkEAyZ9V7d7Wi5BuDiSx
+vSsLcP6SFjtzWQi51XLFaJsKXu6BaxD1eLGW1M+MM4wToHX1zJLF8I8edTtsdykn
+Vcj17wJBAMS+IrflQW32qiZit0rAOn7scSDUtblogW2QLYFLhbAJtShLKvcFbh3N
+Na7e5emm0bkzG0K+aruyWDYm5DEXaWMCQDEY6tzk8cvEnPg2uU1+aOfYJgzh50Hc
+HRy8ORQzBQB/Bebjl1MPs9IYxGRdDP57GyL47tiYkWss0EnoLJr4N+MCQFBvN/z4
+aadtBPqyp2vkgHSxggnLqDNHskKFJIUyqsUenPJM9On0Hd2E3k6EemSfdQQiKMMq
+9hfr/ycJD0LKEK4=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1_ta4_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1_ta4_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQC2qxa7He4lWi9Y59vYCuc2Y9XK3mC1kMKC4+x9SQyptpXIoasE
-DKkJ4ZOmvkM2fhthKBs4A6IGGYhyqbmicf/b4TyFmAGyX5OgSrjnNq2PUIzWoRQp
-sO7s4gg/fTShxF866U+wwNZf8hB4K6707ijIKSGfznDV++oz/OJaXOIb2QIDAQAB
-AoGAXmVdcsbNyTmonA39OtCvmRjQY2y1lz4+djtoe3njdFRpZOu+n3IXbIbIsXNC
-8ocKiRObtT+TXAmXzIFO79ZvfAYx721ww+RaUah+X5UKtHqe3QWsAaFmwrkNqJ6v
-vNkSCHP5BSIn8m9t5OGrhPUkyBePu5GTkVgWHwx0yP3ucbECQQDlJq0V3U4MxuaM
-XEN83U06LzAm5Ro4Jy5nt7ooMHcsWZrdSWSDlQLOG/8PeAZ91PS355xBfDP6oVxm
-m1QLZYilAkEAzBIsx9Wh4gSjpm4ODB0PnwO1bMYjti+7ZSdws3aJiywv6NGgQ3nL
-ciChW4aLn23u0X3W8VZ8BCVYGbbZToUsJQJACkiDCfEleINQg0n8qVTRC2Rkt8oe
-NBjmBzeCfh02q+HVhkqt3Q3J03AEMTCEsg7lcH9PTs0BFCU7nUspKV3EFQJAOUdk
-sFaDUKhSstUzNi02BEELPFPFFE8Df1n5pTXBV4H4lJW6MRZPh2InSERUjlRR8xUq
-LqVCu/srZlRPXF2+zQJBALG9X8lDFV6jvaBZq7/upwL6KgvVf14jMaDWA8a1eL0y
-RdwfXtdb2igXabexV+yBLebkACCKO+veN7NuO/KQk20=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBALQlHDrCJq+Ngk0p
+4+B4byt/PLGMwDeWcdJCId8uxMBaYORxbwXfiKhL7IdUjQjJ9xmEpdDMy0PDcGln
+Lky+5i2TkPkCMKdD0h/l1M9bXHSIBg7uzXgsLydMmS++mnNbmxzjZ1S2dKfJMdNj
+asVKUCLrr+LNet5ZaGqmDibWUrahAgMBAAECgYB0aZLfib2ULr8ofEyNL2av1i5z
+kkBY67isJh5bao6suvroRUF4qyZVk5LLNWFab6Fl9SluUBl+tdp70rjB0Y9Oh3hc
+BAt9f9qy4H3U+ObutWw6CYZh6BvEKlSJgtDZmZwRoYImfI9iooccsZaSYq76GtVz
+290WZmboO40/+xbRrQJBAO6fgwop0fhW4a3AUubURuFaNU2ZTp5C0P25MnymUps+
+fpCBgYm9kPmYoXhOiGEUR4m8OGZPMhavpEcfvUPDmoMCQQDBQ24rMTQRZYB2RqLr
+XBKFK/1IcMazvCKHR7GIhHxHHmecC9cWXNJ1LtlPhgt+chE66u1EjxCNO7MgsSJC
+yDELAkEAtcaFiER7Uva8TCPqAzVKGXkiic5zeVPk6KMftpzs6J4ew+4jw83IlpqS
+xpbshSdxp5beT/GccnOybQvcnbZwCQJAcaqIFC03M3ggSvAWiBi558tMh5uUskdX
+g3seJm3NbkKqq3OnSEbFnRg1xXjQL8lE6wMbE3SVRouzOeoUfXSiqwJBAIJnELnt
+PFx0NoYKpfjq1V9Jyh0u/N3KXNlV/fqFx3xTeD0C+ljmJ4tNsjexSEOxsTWw8tgP
+tUNWcnckwyiw/3c=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch1_ta5_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch1_ta5_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDnFNncTGAPrUmfFPgv2Q5lk6TE5WsTk8F5QBRPGVbXiAeb3kVA
-ziSRRLAUa4tN9dGydcxc1+1zLNJ1qlBvlACNDrsVjO+hXSwjc5X3SLVKO94qoXwD
-qigX8KdGuYbzmKcx/+F1tCi0EbRLymTkzSr32G9rc2SrVQtbYHZf6oZXHwIDAQAB
-AoGBAMWDpAfR3FXqB0CLeuvi+pRGE5MciV6Nb9TEudc2UG0fX2mSHd2bldP5Qwvh
-NIvpbli8qXY+Nj649BcRAXmtpp1LPXkd5zc9rAPsbY942a/4mw6JTYbDDl2x9nFm
-4FeaEou5tsNy+ukrodJSgEMyz/iWzg9ELBfMZQXoErmfq8EJAkEA93BZ3tjruxyL
-Bz+BZU+9GgaFH9yKoNcC/a21rhEMwW4xF+pe8dyR7mAOcJkEye3WZGvQ6UU28KdS
-Wc17TlU/swJBAO8TneZhhmXKQF7EXtXJT8FVBTcOz/qQZXVByQfn/sR+dJPGDmId
-Wo18kN8R4DDHSlL3E60za9pj2eBfpVFcNOUCQQC2XvFuJTVBWJ1Dv1Owhx/aQbn2
-rMbkGvUSYejJHbnoCz5V4SEPZEGOju+1n6J+7jQZGboFZEVFBB3XIHLkXkKvAkB4
-zHaqI3jfEdR4jcxFRVSxIR5jdW6M8kzxdG35OrW13xdUW2yFEsPgXaJttACNZQUe
-6ozcpPDIBk/eWTWU6HwpAkB/8uXEvZw9jF0B0S3u/5voLqM8ExVsFqZpbS4EZcO4
-8QAaG/C41RufSKhqX67tc4lZWSs4PUa6VCuyrtQSuIDY
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAMZndpMjgp8vcCdP
+ZJ7DgE3jnbv56i7xAuHhqFv23Ml7775aQRG9xFHh2HRqFomD9zr9C8yb5pbYE+Pv
+eGWX/4GQl+h3/e2cVi7HpOz3LPyg9t6r7NbnnjXmt9xlG8jkWqKd2Fu5+iaMjQBm
+xAUonKg8sYHHdQpR7U9J15a1izT5AgMBAAECgYAl3DR6W3pfmhPSzIms6i2fr2G4
+LzaLAp7EL+WKtw7mu+nB70MfeZDu9yPxAxWN5ErXTNZlkxJrkowpINdeu6Sb5Dn+
+cQfKel7BwxqjkDuHYul5D/lZtmTAcI3QBGEGSu8xHDX7/QizjXk3QhmGoUCsft4u
+pBkrCFmhEdXkDwZkAQJBAP199VdFahCJfgrmUx7uDVw+dugZx3sbvUsdf0HOIomB
+b/HzwfPUUkl1++wK5EYStXYtd141aaRmhZUDGpnorsECQQDIXfqZU4YpuN9fBhwu
+Ui81TyXxtctYZgAidJBupzaromC91+e0HrGKg9zncdYcpcCClPWGm0+VugQjoskO
+m0w5AkEAxkcF5pN3GSRSoLf0AFd3v9VkMLwpWlQiRmT2K0TPovrJ01k1NkG3c5qD
+yOfkEiOEKMH7gocI8Pz4M8xPvF9SgQJAIo9TMi8d7QReQt2i7rpuOhu0x8Q7lrvB
+OjAw2WUuINyZIyWiaYcByIqGB8Wy0K4mTl+zGcygJYs4O41QcJyIwQJBAIpHZBtS
+tTSIYqfpgZzOqfca2vRw53/rcHNascr09PEbrzNGGg9p60ioeJOu41jAZHaSm2A/
+gsBQoZYIPdca7iw=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch2_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch2_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXwIBAAKBgQD0JO09/nDIUbaNJniQanf/3n1YHwD+Y7CI3kYY0haEr2Whmpex
-OBRr55jBeW8K27KSbtZ+zctVOaAn6QbIRRksFsNP9a/N9hTLhVlcG4Pc9rZNMAYo
-ZvYrGQM/AN4Jd1CimLFzPdV58H55K452lslDz0SaFS4JAEemWvA1i4i3YQIDAQAB
-AoGBAKGrikaRJRIhuicCILhRKKGRLaOa9EeAsDgSKIzrIeo/U6eN/YFnR26k8Gy+
-AyBHl5qMNxHFKS6IeFu1Xb5ks2NJkmcAwpPQ8eaj8aP5fAiKNuYlGveDp2RIlyUP
-CS38SyR18V+00656/HUbzvHuk+TjYxmRl0E5gEalR0Ig8Op5AkEA/gcI7do/dy6Y
-pMWNHjA0D7pCc7goDlGFj5LBQ/DU1g/xyDOwt6Cf/F0iyCzNx0KKQ1V2jfeqMMJt
-aE1xwvc4kwJBAPYKPt8ZVNrFKtsN6oHT3bgvoaoeJVor6JVw7gQyEC2Ijuy/drjq
-uuLaTW6f29zJuj82l6BEGSDkgyKGB2U2jLsCQQD8RIo2gyXBuvF1uIXS8/XPpJ43
-gyusRIMJuKjbSsBisMTgl4yoXwhiOy++cNgOSOM7yRSKGejWsU6rZTVTc+WnAkEA
-vPQTYs0WgMjpZ7/hOIGYhqp18qsiLoUIIzTOZoR4Li/w69sC93K1wiC7VNkKRh7a
-nU901Q1Xaw5zs2DRbyacnwJBAPBdIt4sy14Hhl5aLcHdup6wRrqnFZBfgZog5MQU
-9E4hhYKL5AS8kWPo1GbqSDNxp+RH7nLB14RHloIhHmqGZYM=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAL7BhjDSowL0ADP8
+VPNv1yeZe1fi8ZP4WBzrmsxrI5u4qREnUJvXp8L+i+5U0F3iJARHHMxUtYm7pibe
+uTtzGWdemogS3ofeDibJDEQTZSPNfzTWu0Ugh366SNUvP/zWjde3sp9C73aaz8MB
+rrmPADPqKBXKMNqPJXakVSoserjrAgMBAAECgYALA5GD8CWJXh1E4yTkiWia2LnO
+cUQRjx1HTjM56lW8AAWDAAofdWwyThA2Sp9dTFlYBeMbyShSM4t8Yw++5v5oZ/ez
+8xfscm6IpZTFbzlhl8XMm2x6UVXctRdmJIyFVBP4glaUPXMM5mnNWDM4ObYeo3OD
+LXjmvARPdN8UMEnKgQJBAOkvfzXl1gs0djX20MDeapgPFadSQAVqtbBfmTRX964i
+vpza48uGWgJBj+i2Io0ZMbSKVXkXpnfK7r20U/WvfikCQQDRa0+TGkggC0Y3QADa
+dEQ5zxTRtGc3PnlHVUK/u4M5G8TJuG/2pZHxZ4Sv71w4rZ1vYcSUecxiYMpkSrXI
+hTjzAkEAz7wQh+OJG9JQvSJ0Nl3ueCh4EeekQS8fTVDdG1SCwg8R4IrgBKBb70aY
+/afEgA7BySSzoH0BQBb5OOc9JNKCgQJALK22Vm3/AUcmfdcb13+Cpsq1aGASvUiI
+210nVnyM7HwuKdM9n+OHFXe+aUKp7DWuJvs2026A2mRICcmeqt8xXQJBAOJyRyRk
+it1bjJwmxZBdu1OEPFpJkblwMRCB746oe0wROkEZVW6LeFUm7iGzBYKNA89DUsVH
+Eaq/pGHAdjto3BI=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch3_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch3_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDsRn7hNSUckjdR+5kTcOeJ1j47KFmYluKBhz+ZhV0GCtDfBD7+
-igD1qpGTqUhcWbnL8pTd/nERr5x+cc6WIcz9J+l+giuE1XM6icAJK6oW1l96rIHR
-mxhNhR4zL4aow3otaCQwHX/bxTAMv9lyBJid/y/PlOcuiLJH/e7B0uDpOQIDAQAB
-AoGAY/C5sHbzWK98WOAscq26MnJ95jX+F+4SpylXPI/NtkWS7hJ0tuQW3dMlOqlL
-I00MqvjUAUaj+xAmCNIIyTZI5yfux9nxkC3Fvl9CkfozzgXuey0pNgqONURR+osA
-NzshguNUmUN5cGeSd3Mgkvn7K84UIjisighYrres3sWmEwUCQQD+1oLiLHVblLd9
-rdoLLQP7JGsCepevHXQQjtT8xL9rBsG2g6+3lvql5bhM5b9WB9298fo0JKHK7FnD
-2WDJE6XrAkEA7VpQqYqWzQLxMQUymfA9Xe+9lCNTfHBRlkF90/H6FcvAiT9h0hu1
-kgjtpBJwnqSlF7/zPHD/0XIyhlSYzYuwawJBAN98O/ghySHxgCGlz2yxo6Yhv/7C
-iDe4esryl/K8kKpJmKR5RCabL2FB3qkBaxUFfP9RMH1+Cq2tLOPGxUxSANUCQCsb
-zzCr0i3UDfhoSEN7RboM8/K248/jGn5e0Lqw5UoWIpcK4vplO/oVEwxMqRW3M6D3
-pPbiUyQ4SILrVIFokJcCQQDyqLCgF7gr6xiP58th58/14ggZPm2vKTtiOrBxdV0e
-KVlv47uA25B/kd5BT7jwDPqoRQ1+4VFz2YcMDONr3GLV
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBANNb8ZOPAQ/AJdkH
+8XApHlYL/5NwHUUC71IiigTJCIUz23fDM9lc/jAqqKyd2JfctGlRXtHJhmin46s1
+4o/QNhtnvlCIZnxLT9OGeJLZxWLHBKPXnozDykhBUj+hgtzyu9KcqVglOgtztkGr
+asNqcM6hIA+22+CRCwof3AL07TIPAgMBAAECgYEAz/QZtuYv1DBozKW9Dm7WczDw
+8D6R/dGKaFSlWVn2sSA5ohcET6voSLngJZ5Uee5j729pDJ3sSdJN9alZ1ce1Qu0y
+sGdbWYXgXpL5rTaPEiVKOm0egC9YgTquASN3D2Vk6zzeKeyLIjv5VSF4518pSPeO
+uRM0J1CTrIz0NHAMqqkCQQD08nUDkdAP5AHslSLVBMRcgqe9s3PKaCn9oiEO9viA
+lHxxa9uIlZrM65SYkAq60/BofHcnmAOMFA5HvgW3GPF1AkEA3OV9jYrR/9ZgSIz8
+jrDKe8CtwLBy+W+lcJLdMKErRJAjb1/fh5WZt+y3P/yuzM6FuRZAbypZWqEGeUt2
+P0AA8wJBAKjOUt/z5CyfWMgfe1LMpzqN/GXavyi1ooKd8iRrBZUvP5e22iOF3pns
+nIqLcimRF/QaGs/ZjlBCHhlJFo05jmUCQHZR9o56bUG8cpZp7l4AFHV1H5y25t71
+DojeIdyKd8Kh8lkV4YWefFgoU3/SuU660KXzZVAmPvZsiisuYIhAoEECQQDSoLW7
+P1BDXk+2oW9fdMo6HQtg/RG8+HkhDuHu8fbv/yo744qJ5CCSrkSDPHqtx7IJHjXt
+9cE2g36k09yI71iY
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch4.3_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch4.3_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDi0LqRicImIUydaGN+h5ueMVJNMLMrnCaFQGNpZnxdUnPTYQF4
-GA5GIW00H4TiQnKc72h+SaY9YoLzD5V0E4ih0b8AkxAk0vy9GqdP8iSyYNVXlmIJ
-yJRftlc48QBil9miNdaVR5d4SBd3K8Ri+gAM8dRu4XQlOA9cV6+SN+cYIQIDAQAB
-AoGBAI2hHs7gQY6Dvo6P74jD7uVyEN1IaqjxoZAVa74WE9RGNzMn4L3373nVR5aD
-k/ug2GasjAhHvvmXuQNDmORZijesfsJ42vmBlIoXIRkqWD6lsaWpXIrgdReB7nco
-NPyOro+YXcnd8ntyu0Ik3zQFmZ1A+GLwBWuDAYlzK+zMhYSdAkEA9Z5PP8WqMe2v
-pQN1Ld8dERu9oJpMlvMCQENFXFHp0u8MLVhFf2n8q6/ZwvQr5n9zA5lq9u8WdoOm
-Em7xlnZe+wJBAOxm9m18nz8J6ZkTv17T3jpI+PIhxNT/MZ2AT7KB8HK4/VIYUWwu
-DLWd6ipa0OXJz+T5c005thRblZyRBN5OSpMCQQCpOT4+oNBHAAzQ8xXr2dmr7OH0
-Yfq80YbOgcqq9aDU/G/2WefgBkTYgRrWb+ZDM7IpW61PnqBqXP+xmZCHaty7AkBw
-JJPH8nNUoy4mSMDiih0EhzNZIX3PENQHhCPKaWuX8HtzI0gUym+LBENeHkC0kRzG
-4TK6MqNWWu/JGt41WuxzAkAig54QT8lO28bjQlsQJC+cNRNy2EMf45VUuzreGQUE
-XBsoCuSEfFLqZzaKNN3R5v+Hd/LVikGWQTK+6TVGRfc4
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAN3sMO4qOezPbcC5
+BPLgDwR66avwJyjZa3DlxJvGG7txFkLVR4BgLPYmkJ0LzBsYv1SYx+i6v6JdYMmz
+CXne7gLZuXAiw81gBF8e36OPQ3PqaF7fcIaqZ3VaWe/NDeTxbe7TuwTHUuVyUyri
+8wJlf1NGwxXky40bz48ejW0EBwl3AgMBAAECgYAP6kxoCCc3UHjyhVJRiLgK/jWb
+2xEz4MPPyOqcsUxz2Nxb1qfWEQ+oZ4Off6UXnGK8UmijzCDKKCA01t4rG02+TFdb
+AavVVpkbQfYeLY+o801j4QLLDaWlenb1nwEpkfzr3s1b31hiFTLl39kHPR00eZDb
+TIJGGY6Uo8vAYrBXwQJBAP0ER2ppfUWQTixgqicW43HG8Y+BjRfih93Wbn4geIDr
+incpp/PLarW2M+B6loGp3Isdfh42E0pnNkTmuKBgOnkCQQDgig5NOQhKeFKT3U4t
+P5mtqff3VO+Gt03Hp+KXHARXwQm948pgslKP5VlWoP7WTTUAo82EDBL90QYlqtWX
+P2dvAkEA+umjaQP0F2hkHd4+30TziYGhTI9NPMKJupVMPgg1eKQdTM8in8K6sDlg
+eN0ZJL0u2UcGKy+1MbPpPasQrPrBAQJBALt9K5H5tF2SeMl0+ik4ORdUnHQOnO7t
+MmorWj35K/smef7wLPVvEReMV3vJdOD2mPJO1HWVK2p61dov+qePTssCQF2Bfw7N
+oXXUcJHzNi305QYJ5PyNKLWYXSKTXoDelkGZMS2Vl+wNcblCInNq+kxcVuXxLvZ9
+ToRD++ah6d3wSdk=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch4_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch4_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQD1r6+ZlfNSO+u+Yubrn8X4/48M0uPHBrFFyv+M/D289G3j+awS
-adWhbwJSrVA0fsyn7oIEs1vmvsxE5rjS/B0qgNgMwTxPlTFoivsr4qqyVHw604Zt
-XyC2KSOudAn9mtNF4uMqYh+R/aKxLyZo+01p+2YfC0saUqzhi2mxFpaJEwIDAQAB
-AoGBAI/cYt90/Xhum9jsgrj/4mWuBy6EIlo9IfpzJnaAkQoeumYeoVJa5HvVy69r
-yqYihWXj9AAaojqYCHZj/1+TvuMpvatcl1H/pgcxL7hRg959chvh035eyJTCkEcg
-LqfJeYjWh9h/iRFEUvnx56aYzmRyT6OBCD9aFYYqH3t+7yyhAkEA/RYKtBlqyA1O
-e78kc760xLSc82UzOi0tAGcWgZlJZy7eVrd5pev48N3OVLdETXSWuOMcliijw5fA
-XauPwTyJMQJBAPiD1WFoGEnUJOYCG6Nho+8853opMOV/OtIL8oC/aJ//TTQKxMyM
-ZaCLLhwWFPqp6brQ8Qqv3a8Qbnpf/Bs8ZYMCQQDZB3XWS5WOSBrtc1RHDVrm9BtD
-fZ0YXnUgy0Y5jMGtgjuYEW54IosvwoWVkDM6WKiHk/qHqgIFULTdnqmAA/GBAkBz
-vhrUWgHt6LMiuNqcdm4+jzQT7jlKub3wdAYGtp8I3YPceCN+TOlMI2ZfSF2O/THR
-g1ywKIZr8ZAyyJ+HI9L3AkEA3oaUTA0xibu69MLgGBdGUtxxrnlA8iUqaEz0y7r6
-UdTgDUhSb1WYfTfB+VaFGdcd2utfiWBfbgH+0BwxeFhijg==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAK/Dizk+IVaK1pcb
+x6rHUZ7pzxUfJOaRkoGzfTDr6hIwEwPQuWBBi+uI9B/lQ8+1rkd6TUZu+BZCZ9sg
+5A0flk8hWZX2cDMyRYEYXqVb/Urm15fPRWXndHlfpZ/hx6XQXSSnMhhoE1dMz3gS
+b59c5k2+iSRLKdgCsvn5E8+SQw/lAgMBAAECgYEAhLrjoWfE30jbgqNs5g+9GIey
+ZV3ujNvzylSUPuR5ECETyvbNdt4o3sa+rHODARFPOhUm1ACrAoxFR5qP/UUUSQ8e
+rHEV3zeU5RbezqEaHZ7YZv7dyCNSALcHMuQkK6xy/iWqvekJqiDnfcbyxUHzU1my
+s5XLLYA3YXKvtjOyD6UCQQDWRN1XaniyBwc4+pg+ayn1WuggDVPy8z9Z9u/yzfxK
+moWyPG+j4zsWqNVKIQVIbMDhi2Qt8OFat2r52p+PHeY7AkEA0f7edIr602YsOM5Q
+03lL0yjejXFWK+yF3REuI7CBmhXYjQ6X+M0dceGuShIXT7wkOGL6VxcbX/WMuHyJ
+P7XgXwJASUFGA0rtdMAeYgaa4kw1DiNEVSD5YIh1UkawhmySItdteiBbcsaPPxH9
+ydg8PCSiVPoZB/Pgt+kZc86g2oc4XQJBALH7bJwmdzTZcj2rUAIM2mFcUFRdbQXJ
+cCPQPeTt4sqwHVxgtBmh74ToHIqXDr773U8VRMyvvvnz6pMqqkEfa80CQEeW8xjM
+hNugf785JLU5ywPzUrvCvsjUCJOQOD4GuWvuDk9yBfOsUln0IJjReLGnouWMJ4x2
+eqZ+4CwCKxtu3qg=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch5.1_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch5.1_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICWwIBAAKBgQDM3lTteDHAfOQlmKMN+ncI8znEn4hB7gCjNe228Myj/Q/OPHC1
-qh5CTlyu2MuZU+8eSflMX0e+0Obi8RIp1Xd1iHlMO2QFughd3O0ffxWSaey5yYTw
-fT/bZjSlNYwim19LGYMVNUl8S3c1LMRYNBXxZpnOZdMGt9I115Y57tgIkQIDAQAB
-AoGABKxhtZUTVXfD4JOtzIjVJFAgFjspaY+bVh3J0W2GzYrdTHAWhh5eWFbfSGHL
-qzC9+KvpUvOteE3dpnmnV2r2MZ67kt76VQvWf26EAAaGNZp0rSZ7LOP8ipndQcMb
-KRykm81UuqC0ClJp8qSQ9/8HnFv1kZlglHnz2/XbaXkkSH0CQQDljwvofHrFEWMN
-8lchh3ESPOhZx1xjTp1zIDK4s8zz0Qv1JnXRJK+Zuvo/UPRUNrVAzYbxyo8wcTxF
-xtHXNntHAkEA5Hc/X4qOhhS6l5iSKiTMH6TtJmUoBdVmonOMSEnT4+EMoyhm+uO5
-m/EiApRXt4b7Jqqe9v/CRLXAmJiN10mZZwJAd0H0Xshkg4K/4hv3Nh0GGgJ4d0PB
-9HmABLJCh4ApRrVgr/BWHtwfOg9QOJqXBDUTvuHHbE/eSb1aIanjlBniuwJAMBDW
-iGdCLPtXdmVm+u7a8x1jt1w422FWQn9E2ECQD7VdT0ZExCv89M36dch32+jOFgh3
-gUe1u3bxmikeTljxqQJAOCV/Eex12RSZxgb4szTqdT+3PvsaIWhUMlhsra22d2GD
-9/WIh55SayJ/wPLO9u9m/f6EsJCkBg2fsYAN9gIN9Q==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAJ2Rh4JWeH9kMmJ+
+7mw48qL2NLqp7LtuD4erRqQ3zoDxtYubCksqtkab8UfAa4V/ZAhhrFPUO85UKm2k
+Zc2n3KU6M7+GK/bQ+ySAVo9P1PmWcfOGdEtHONoYea7ZW50JnvfLtKeFM4Ug0yr8
+csE3YgHWsctKoAnCcur9uF0DaDN9AgMBAAECgYEAm+vqwFt5Gfa4tScOICGqWQBx
+5VVJYZ/j1kjyuoZO3uJQ2Dkv0noNrYmbFXmf7JbHElQ1By85j09SPPU1mHDHsVt9
+jcRYMSj+zMWUxlB7yzFhRsYRMuSiS68l5Oc5SKZpd1qG5VWdL+i4h9BPA4h0Ny1s
+DVoikHRUinibHxNiPYECQQDMX04thoMtwMRBcZCjuOh+UMaYNKqPdTf3GeeP8bXs
+srvhfoYna0ioqFydaQhnWjl8qPQGUjXS7Iy82bYK+t5lAkEAxV9vdbUkDWYXR46X
+7FGEOpTBmB2EntvmpwNEDagNSz3gSWY1+FKgthfTHuN+1acORztfgiMfPdad3bAO
+y1ODOQJBAMNuh8XFEYAZDBNA0/2b/sd72s0F3+wbPY9P+D2P+FYGfN+fLA5Z6ztM
+9HOaUuzyPHLW5bN9vfabOeIFlq1dRHkCQBy08MUx/3hjbOdfegFJKe5LTI0PXgas
+/TM1amSCGMzkxwZl81uWyQEzHeXUONJiZdU+cXnAGf8og/WGceBo2SECQCXdPFtB
+3+qvlMFbcl3YSpbk4q4509cuIwq7mmQz7BVz0rkUxt0+D1gVtTLcdnzYfV4SGzvS
+ucaQ+9jANRTqJzs=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch5.2_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch5.2_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICWwIBAAKBgQDFJ5tNw0HPltTwIVkbd85UgdwFVx9WaYxfWD+ISsZzvalK0Pij
-MxtP2JS105W9AAbRGOjqnkGtBurGzJ+Tp8SgPgViTD8ciHmgoevzlNAbjKifTDs3
-gAZrAOcwbNTCUSd/GuWVpxwV1pgOHy8ot6d1YFaOdKCGmgbVIw8RgwKVcwIDAQAB
-AoGAXA0FBwa+iHUNEN0RJLEIZg6HsvqdiBQZ1T5302POSqXoECWHoXMwMlSWAls6
-05bal/BAd6LSWT4cihtp+l/ffnv3kUIFHbvZJg/AJXwWjMLa3LiRlXrNsooZ5Rov
-CMwP04rQDskjChLv+PC4oNgrveKfcUiqBgg9sMmeIvtjnuECQQDnF2q3+J4liHmj
-3y2/aPl2FvtNOEWsmj5bzGd00LMTh5D7hFS8wf92Qe034bRIwOWpqW7Av2SMyD4c
-Ol+PZARDAkEA2mfC+balVPRdoAT7V6hEFdpBUg+iyUxBD3QGyWGLaY8q3WX5u8Ly
-3JNNyGjTF08fbTWLl+iKKv9Qw5d1DrIvEQJAXMeCCSrAE8GfVLOd4mN7BHZlnrMh
-BhNHRgPi5XuE6ipbgx+2BbK9pfUCEJWFlFAd5OgplylAbWVXym2FQESfkQJAYkRT
-XqWGJ/427duv9tW3pJlp0HFGjgmoMDrFHvCrmFgZMjpCre9d9E62rZg0egVYn3t7
-DmNLX2M2xHot6enT8QJAe09HhlcbFOThQA5vCgK3OVXXSFkcE+i3tTWZqkKCwIlq
-S5WRuIQ2NzRGzBdpLaXaHa0EbDr2k1hd2E3z0bRC2A==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBAKC16FBuCy6+ijmV
+ofOPAxza03Rcne00VF4/rOKRQFBe1+O8sY6mYtELM+JZ12fxt6/5YTexJKpvZ+BP
+712ickJwQR4y5RqUT95gbOfhlpmC0DXyQAPekhDzT5HoeCSh75Lae0lLVwOAV9j8
+QWCK8OZV/mdVXmi//v0jK6uUyxLDAgMBAAECgYBcsE2qha1BaneCOsDLHkJnU/X8
++KXE9xdpvEPT8H4tXGYbXOrzIReBBXsJI1PPCWQtxCDD5BEHk3VPtAqT8GsA6IyP
+IkjJNESXn50Wxq/TrjB9mpsilW4fHegE8BPth6QHlui+lbChdXlEYJVtARcMlZ4k
+AwfdbO8ZLGDNVLAZIQJBAM1FNiXGVPCsvoUqlNQxJSNKBEM4ZbsCFR4oCWZt7zF1
+wlrXOzdHO/BEO1t5oz+3ZBK2fZew4x/F+34kbxLowZsCQQDIbYsbym0twBzqaXEV
+qyv4qDVtrirf83yVkDHv0mO9z6iglOoSK6mO8onFZUPabefgyQh32cJVDdlgeUQV
+Nfn5AkEAvQ1cdGf4vPzsL2trTQ7CPIEj8eEUWKrvVinblnnzjWL+kHmgMSYrPvso
+i/Q4dStrQIzQmQ+x7waBvMjDf+/ctwJBALyHPgjAGn6kbQ6abELjphLZtpga8j2C
+PTg6UJ6zmhqbUJTsPlklNPM/dRR2sqKuKyUoNIz4CnIS+txidQY2pZECQQDB09o6
+g9Y3a1BTH0KN4Um4otLpAuHo9l++gdTD3g43xRDlOFTk93QoFqB5ugbXecNPvH+5
+ZV4JvdKMThUq/URE
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch5.3_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch5.3_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQC+mTiBwl83w9LMfwEZYY2LV3A6LDbByOSmMyq8J+nP18pJkNLg
-8YIOfVCq44zKB2G/0/0e86/sAN3Sq3BqGloAMuwEo6QlsYIdkDz5rpGQ19bCDo0x
-VWLiaxDgEG8zk3gvWLdG9LkaTP2BsmZClUuh/0aenfYyVmOIvINDVLvOoQIDAQAB
-AoGAcb3yUM10EU1VUSBBwanL1Gnb2XtlOgPvH5fNWvfeumAmofxBPGgjmw4Bw9mD
-vVTmapnRplT6mTZzKjORJGCRcCAY9Mxzdn7v4b03MWkxfSOuWOjflKUSlrHK2+gu
-0jmsb0dZlbWlDVRySPahA1lzYkwWE+t9A7GLSZ9Hv1BFqnkCQQDzFm5NepMpYaAf
-XdaVsO8LEk7LwEjB0FJB1MePBrJXdq9XtOSLYm+2ZpPIx2aNH6jdzYK/jW+A73tr
-5hUgTT7bAkEAyLkHgGFLt+hZpGSPMHmkB+QWhwQQsmurox4UUpNxCYje52+3Qthe
-TwJLeFDPNmfGmhSiHBAjcZzgRvTtbdSrMwJBAJectuEWATD/FapakZq9RupF2eVU
-oUxYjOVIO8rl51eLy6LNTPnuRDSkV6oTS8/bHixwoAquwQvO0dCjKSwDYZ8CQEkw
-ttyIHc0Ei1NXW6MIZ9h8wf4fbFsyyZYkDLMDkk8wul7XrJJSRSk4I/7OMJCdDJz4
-cxgahmISGvGks8K9rmMCQDyQSDB/BTykXIE3cZH8i8Sn8Z0SiwlQcxPtebuiynYH
-DmrUQs2BRy7cO8LG4rxTykqjH9JtAReI1Hry7Ny+QrI=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAJoLNQB+Bv3iUJd+
+0sK4ICrZu7g/FPmq45jcuUliMp7nURbva2lZfg/DUAg93CMYN/pwzEW4Rx5J7xgV
+R47myWVkAqj1KtHvOpGPWlIhRo9hh1XJYeromBjFmR+9QwITpr/Azdml7kCjBb8Y
+KFf2TiHQiaEhHDntLe1F8Np1N9p7AgMBAAECgYEAkmjOcm5WFN4SPTsT9HBuWmvh
+qGeEdxu+AF7hWGcVt8QhZUwfadzeHPtEyOCKp2xwX/7vl+Bi793Teq9W+PJPPS4p
+BkbeZzRzvE3xnO+f//nb9L3riRu9BozwA0rvTMPCaRHybfTFyc1qjGjCLCsrBmku
+0vgSOsmd+W+alSSj5hECQQDLwae7kS2l5QSWxCYbkuDdqWNBnGAY2YVOBscXOXDU
+2vwOo7jlutorxjo3ve8apPwzFV8sZld/o0sHGJWItSJjAkEAwYp3jYd76FQ8i9TZ
+GbecxO00cvuWQ7ykqbbEXVCXYpzgJauoxTdD6csCSLnbnuyYh8kxEq3K770/JVOW
+Sk5XCQJBAIGEFVR60eNTkfkrsXVxhZIgq8D233asPbn9QOwYTQpgMDw2Ab+1aBzP
+Ig5wot3y5YSrHxYf75pod7aI//Qn/zUCQElZtzG2dWl583BzfMxYYFvqIoSpgSuu
+5SFFGWrcTmObXQAp7M7BwUVsITN67RdwR+a+g5C2uUDfEn2NDlqfEjECQAabxwJ4
+fVemMHabTg6C3q+HzXo0A+CGwL/u/jocGIqNpHTesZU+KAkJ67bdxxLyJqcBcidy
+D5udYgkqbTEAycQ=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ch5_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ch5_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDDjdCrJXW69SDffIrUzUD2w8olEbUw1if65KAR1qoyfcgVnddv
-f66A3ijDrneof/EF6Wu8Y6mmkQQ7eWuW8uCaF3nTBApfRgm1bz6p9DRHYhj0KPfZ
-Cc1PijPfm2mbYc5yxzXtYaBbDMFhAAqsg5pqPG0wlut3jCg//GKK+mCOFwIDAQAB
-AoGAZo17rhViDV66E5nbsMfHVuHMo+4KaIcWxmOZcmFyNjJyeKujLGz4Vcqr9BsN
-04btHl2QS2a0tI5+erYtbycGE73NY7f8GFM99FckrlghBoARycoOo0gjXfO1FLub
-/nCgXktcs+OcS2axSioR/L3m5tg4wpLAFJDTmPveTSg2UqkCQQDzsqH6n6OXFgfN
-/S10ZRobR++BWjgw8t7PqemM8DSgeKiGBHjeZaOPqM7qZ7W432grrqGRefnwiSja
-pHM/pGiFAkEAzW0B/wreIWthQks15Ukv72Ai2E+y5YpzDzyD23nTWc0nbk1AVymI
-ZhyrHdJJRVJfVeR1Yw1XnQkT1/ChjdLs6wJBANn3Rwt753zGFpr2PMajevM1pxGC
-GUomoIUKyzrkyZ1R7iFYNKduLxnZ+aAMvKurHmgbnKUafSPX+fN9LRuaOGUCQFFx
-mWwDZAP97aZ56RlJhe6yv73hAz1MQcfVpzVZvHiLBMoPaKXl+oT5csI1AAWy3cdQ
-91VZEdZZpftkFLkE2hcCQQDzW4qLmaX1u4MTMtXeqtFdK/ohFw3dDK9wuqGVQlWZ
-7bBC1Ojb2QLr63TOSfv2t6GtY77Xp5BQ/rjR8oJIwO4X
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBAN/A7czfgqvTm1SN
+VvcN5Ni0ugPvo4L2tuZND7TlYZiIvTKzRyFLLOjDmiKcNWOoTyrBRxo6skbWYU6H
+KhM62DU+PK5nQ7g9qZXfe7rpcewxmbP6AJaMgEsd2Xfl0hSdlaLOMiHVLmeusQgE
++537cBZ0XxrRNnfoS2jD2NT7GCAxAgMBAAECgYEAiG7iUS7kRZN0vjykj2YIaV7h
+oa7IW/3Fjm3kqt/G/7Q48SZBs/pbut4yKPJo14h0JVTO3x51QB5OHQzryefylniF
+pfoQdSiCOHwiujzmkPPDL/C0Km0U+jYBye1wMxeQbfIa7SkUSssoySVnlMBBv9Kd
+UcNMwl/Swy+W9ZScZvECQQD2+P4MdumPxDrvYR+zv7bO+PjfmABXdZtEmLYoPSBz
+JYLnG3goyC6Al1DFbu0kp7PgFwci+oWSw4bBAfqELxINAkEA5+6rHBy0YcFYg5mY
+TBs/DNjqYcekTKIkOYAaKHnEx8C5iKrtX+ZAxMJDHvm+SWgREFZsqM4C2H4oekAy
+VDORtQJAIIlpHsdDufcGNKc8//dP5DCUyRBDa0JJNF5SETcMYV8dwciyqdzFk5db
+wsb8Ywnc/rbJ7+fFVTKBPEhAcs2ouQJBAJU0rG2kZcLxsHDQ8fIcIR6xuW74EVGf
+ibBYIfviAl8DNBig5Z6pMQejdazKu8jbowagoryh86C04HNtMzOKDXUCQQClJmmL
+alt17GPXVls29MVgqHI1h/Jo99xosPNRAZT9Mc8+4sevfi0ZQ3z5+jtsv0yRvAHm
+U9wRAPpyYbBQnr4r
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDrBRbaOmYPXNgmgzj6T2APjEIGtkW+Lsps/dinXxRw6QTu8sdA
-sij02ZllsC6i5izfQnISksrBbk0vdkGqIryN9OhAeGG1kqdD7xxVGTGoRSMPttUy
-RDXdeNTxgDlo0azBTRji5U3rqcuVUWzHOlC600rcfSGt7lo2W840HFin0wIDAQAB
-AoGBAN1q/gy72EvA/SPLnXK2NZpwWgRY1XxIOQ5WWjfVrDx0TOGSeYbKUyvbllnn
-kwiGMuBkiXRWOA/lC3MbxuGzuE93omfKCDawQoOCG97uF1nio2Bq3ocS8Kk99Uem
-EMcZ4BVT1dAfB3qwrcfdnZuZKxGHyo7Dy6dkP944OyzHpn4BAkEA+Ka4h7J7YHyz
-yWHppgeC/KXpIO9EvgQLuBfkNlgSYCg323SEKGvJXegW2QnA/UpA/tq32iwIyxKR
-WpwE2Wa3UQJBAPH3O/9YYyhxVJ9lPKPUvCljMyF6hJIae+qrpeLjVu4STi/8t2mH
-35etqHtIc2dBVw6AGn5dJylaV3zg1TqBq+MCQHUDOEmbg5YHeS/m5OZeGJU+mnQG
-RUpKax1qGNo+Hf+kTYz3yw2ek7eedcoTXf+Uhvun/+cq28R862xBicKpJNECQQDu
-ESQN8wf0xbTN84x7YRcU3Y50NRh0q+waE3JuzuE78fTN0CchhNcgZHNtgPZStH4U
-PURT6hFa5ZFIw+nn26ejAkEAweh2Jq7y09O1h47pAJn6rqwggslw/6bohoEDyKon
-MdCHyMiejE0DwlHQ4j/p8TxwMjv6yBS0PKQdh/YoWtQEgw==
+MIICXwIBAAKBgQDLBM/UEKC4CkFRzJLtHeZC0L4gnAj062fZiIaQPPVEYEKV0wwn
+mpD1r8ZNIja6n+J0F/fdKgRQ2/Mr32gW2a6DOyr6fgUATmSlHsGOmRG1mWSuNgxt
+QUJyprAvjefxtqgaiOXOvNw8mtE5rQmrx6C9PDaSsjES+XYaaCTmcOMuJQIDAQAB
+AoGBAMVBxqEZCt/m7vKIn9WOMJWI9sL+eOFn/P5q3bw1zmWCVg/3AJ9WWjStdjKp
+5J1ODhyY0TdtxMXAADUHm75gAWM6S7khQ/ELsfx3vSacB06u5RR+2jvNE/fhDO3r
+e0vIVkgS89EVQ9Sz1BxF+L/Ag2Qb2Izuk0xaTAWnbT30HDKBAkEA94w6UN5Z6e0B
+S4YHM+D6M6y3CJAvrukFOZS9LapP7PYRZsPlstmP73F7Na4Fi4iPeKmZvs0NEyQ0
+ecx5RlQ0hQJBANHzXTBXwa37c9kcmnmPvqQR+3as//7j2agGfDAUsTs1RLJu5ANv
+AFdQg8YRMNAmKrg07+JtnaGOLLC7GljLlSECQQCSIR4/pLJRK85K5eiUkGdCX9+A
+V5U+XGHwNsRiE5qw2CU3k8ahiFq2TzgbXQn673c6FGwkvOjN9t5fU/v3Lzf9AkEA
+x6D6i9v1qiO87MT40PtwDvuWOiqXI1qte8nmzaTvPFgTIQK1xdoG3f8NvQhdfJ29
+4vda3NbTmmjgb48Ip0O0YQJBANJBoWOQcybfmTi/VHruMwxPS9wMgROClA/4FYmp
+djFpokzGlxhJ8V49QhY5ldlYu9zh5Cqb64MJ8oJ3gXPaP2Q=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.1_ta4_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.1_ta4_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQCt4aO1ZY9vU2FLFXrXxgqjsO4gCxHXnJmtY+SNIm0TexDTc/qo
-ChREPfuIvtEnedhrsbqKNSktmSE7ZSDVPb/m/LYB4rON9Z9zY8pIm5LWNIT7fIce
-9Y5IvZZczuBpq/QX5SIaaIEVQFJ1xbBHFpMji01ZENDjRj6r/QlqafxvnQIDAQAB
-AoGAVD0KWKkZMi/M5NlFKB/Tq7XdxzxVqoU9lljcsttIyLVIU4jOmHY5l04H/Bml
-rmBDTvlNjANxLZwQE3xMycIeo3ZtQapvDQjGMWQjNH3iIx0wMbFHuiwQ5VfBuOR8
-JZUBelH11FgRhERe4q8TQUZZEL1iUMZS4dpEnqkDZfMh7oECQQDfQ8zhKzn1VsbJ
-fEdzxKcPv7SggPC0TLhwWu0W3K0cd9VRm2gp+C57qLseq1nkXDBhL9h2NrWRiYMh
-MV7ZuEqNAkEAx2A98Tkvo2/LZpV4RPTD/e2+9DOgzKgY8rE7QmIfFLnRgWIanMrS
-XqgoCQiRdWiscs1749VHYqOCopSAdN59UQJBAL38+yaNWze8TVL9z+vi52sObo26
-y5oSQ01RArpWtXUpQDy+q0gzqpKORhVWKRubm4vIZEJMUfvz8cNYOOe63K0CQQDA
-u1eFratQicyNUSZfOmGQQdhbBuGFlWXwjcVkSagUCADv2t8w/JvaJyH0gZTjc5lo
-rRz7RHxqbPfmpDl9QGrRAkA956+1yVojJHr03V20V4n4PkH6+4o8UpV2RYbSPpOQ
-NRFQCCzw/XK223UmJ7XOkb2s7045NA2ZRDsXzZpMqHyb
+MIICWwIBAAKBgQC2bsKc5kuhS0AqFb1jaxu87oHo1MbQHRxiJ8Hl6n0gMJuRypIs
+sCGQFHzbmOl559wfExc3ZkPTpbGTkAG2L6OpGylc/5PQ+zLm1B6Huhqhgl4VkUZe
+GjB9cLUz/CDs3DRB584CPuzRj1VY5YUmduKWuaG932o4CdVG6Ct5XlmbiQIDAQAB
+AoGAcSAHoAGSfmdKV455jS+62JJRjk57JkwW8KrUqryYcKCTp3kk4X8qoMyDjCyr
+AsQLFF3jNKA+iPyjO+y9kvrBkawnAIaQccUiEHOXHb+EUGztMy0dmKrIXQfmynWS
+yZEQusFBxG6cnUTm5dI5tJgzFWHSTvbT1Foq3GN685GO3vECQQDgeF/81ReCyKP+
+VHtzjj4xTCb1xM2ETItj91kD6hotCCd30m5U33SiZyLuYL1ZM3+QNmd9ONtR5AYX
+8l5K1FttAkEA0A7GfHLw5RYl8sm332bzgFr/blqKpI+6/dt6n/CHB6BKOXow1EGP
+b9fJa5OQZ9xsYVc5k2EsWhyqN/JBqBtzDQJAcu+QDrC50iCUQATYFWovFCTvCgbU
+SLq84Nnk/WkgMBCtzN+12MV2PjXbH/3u1j7VQW1p/idfvYWpTRewClbD3QJALopf
+lA8SG+ysaHb/DpY0+g1g/gp64PzV01t5PrXLPsV4VQskSRaxQ0992vaTYuhHxi6A
+zpr6FN48pW8niLc7MQJAYtieYiKsJ9Ra0ZNTlM8kHX88JP6ZGV0z838wm8ygfgKd
+K1YvPSB9Aq3YbsKp6hhVDOTg1A2ZlQqs1sU5DZpqFg==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.2_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.2_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDX5QoYAFRb7lreeDWFT9sGDOCHEJd4eNwrq5WGPDXEQhrow5jI
-XaElpZTWi45z5XWCCuegRz3TFoY9VUwuZXUbb5BIpkuE7naBVqA2F5tYDEWmDLMM
-8TQR3xSOmb4ioqViZfCoV1c5uRMci5dt/Va3zhvL/62AxqMNQv68go9KAwIDAQAB
-AoGALnIMuNshSuG9VM0BnptuYB/XEdeE7pr5qr9wHH/JhV4/UcH6lWhnKaU0nu9J
-By/fFsnnyLhq2YWn/XvjNrwG9CnWiLiGL0YK9Ly09IRu79r1DJ8Wr5xINPLindwO
-GCqLSo7KIJY6E79PjGNAzig8OI6EChqjZY6MMLouax2aFVkCQQDzVkEi6lC6UICU
-vacrJmRcb+UE7uCG6ZkqqPVKxLk3KKwVLIo/n4pYzpTUkURL+Za6JewpBcf3XAfh
-/7hXEFQfAkEA4yEyuf+l+StYX151sjMuTPOz/apOBmSF50luce2NEbosPuxURISJ
-T69IUC1ype+bqazDArIatwYahoGrwvXtnQJBAIM9F/BO069Iz7BpAQoCsMoyByC7
-/RiGUHdznKfwpbwcEYNx/DYIQ8NV12s11dHsEODgpxgQ6CJ+3jmDg9ZhFh0CQDCf
-lMp4zkFPZDXWdP/XMRxMN8YgRV/c+UWQVNKS9lZLMtmtokSg0vx6G9L+R8L6Tqq+
-T2kuU8XGyrrs26Z7G4kCQQDtMTiM8b8Qg9p3t9Wj0qUlECTUpeC+okFxFO7zHzSX
-zaPOQNgusuqT79nES2DOYgYDkkjj+leuFBzRnyqNtDSF
+MIICXAIBAAKBgQDQ+K4L6x/Si0EKNmJ2611V1LiK64C4BVjtKV2cPyuE5b4e9qvd
+1DIE7vSbsjgcWQoSM/i3tuI3Zi5Y5T1+uGlzdIyt0a7eETgEfiaS1CwuaBUJSk/R
+BLatx9jXKm2SzMpIh8ZopMU3r8wgbYO6+Gv1m45939aLffE2b6NbC7HoawIDAQAB
+AoGABYad65jDFakzBhccEXL12+AtJRdHJxaVHGhcnlYZS4FbvqvdLZd/3xuGglt7
+GlzMZGDVcd43KynbjeQ59RDhUOz7m7Xns6/kL33gvBQFCzXPtM2TqL+9P4RaO0/K
+1s0T9agNSEtVCEez84eSdWSScg6xaca4MkgZv1oUrODs6XkCQQD8Z+zxq9iAK10X
+ms3QlUC15PC8R/rI1xfbdgm6P9g0V00RApTpRCjGqoFO7dKXBizw99DLsOrhSC+A
+UtFP2CafAkEA0/JtCqRknHFXxQ3FMrHHmwIQY2s0a7w+FqvTfb8laOseUwaLs6Bu
+rDx47iKLBDWuf9PpLnH/s0HZ58beSf0mtQJALPXuNRZhWGNhD8VZiCAuCLihUUiZ
+GZGHBGbAUNbyklBCwBbvo6Wqhcj1g7PFYXWOJ9Zc8QuwqzSKkZcvBcQBDQJAdgc6
+0gJaRQSZbBMPDfwSvC+aEMNSnexmZxmo3Q3lN1g3uuSaR53ABAppDbQO1nlOg8Du
+yf6R9rFlN713bJydQQJBALqwH+/CV9ASBrUUbg5uovzDBA/DJFwGtCiwQe9FIq6e
+VTskU8t2A5M4iW7avYUadjMK+Jnju88ccuqTyV1V+lQ=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.3_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.3_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQCzu42UIezdHb3Eq7kEF/KsWNtLk/kXLRb80aXq7ukuTgVDwks1
-Lrq8cPIg11Nk7H+Eys7rTawS8FVqqb4Xqa5jYTc6cpGygrbBfgc5KFogo9ukJDTK
-eMieJtsm2k+2ps8/I9kGvq3TjyNBUUn142ORaKE0uT792iIHhqm9WJOEKwIDAQAB
-AoGAV4oR+wRLCaditletVYEUgT0GElmQCOm9OIYj+blDeXomtkn7t3t7GC0qwTQf
-Ohi2Q0dEYPcDyHWmJL1oCL5sYMoEmISCGadNwP8NPfcPaKS305pwhsTM9f0G7aEz
-7jRGJkJ1AGtbIyyIwhKYdRokCvYk4c8Spro7yiOnehLtlwECQQDb5go+X8fV6V60
-2MxYSEgdKiVtw5Cy9WM0mYNTslXZsmRX/D/t3TAVh1h0jpMdIKHC7qe6NPQDwMB0
-5U0WGclzAkEA0T1oFChvijl+ZoRLq+eAl+JyYC12bP9JPPa+BeV/yf+DV0G99WwL
-/rXXcqeQDQVt9ifmiE6D5T65aF70eZeMaQJBAL9TFmSQt3FR3Bnja2AAe+YMLoaj
-GjnqsUcprg7bYkDIKvA2xHSz90sz+G1pQ2ybYMMXHI4x1oGRaqIKhBiPlSsCQGDR
-jjhNoZcPFXrwWmd33pvpL01rm/HBiq0H61OlJyVb8vVMOU63qTE6CTBHcrNjwMb3
-HYgS9Jr+FCLEVVFyG4kCQQCicDltXxevyE3BNZ7kcyiEstq3UM3xQYY9iyXT8P2J
-EoMWjUnVw/EaH5X1i4G7tp+S4MMBq1YeiNOTpScEnYBQ
+MIICXAIBAAKBgQD9lUmrbUkIXPKbd+HQcU2YG4Qx4pCyCvavLhJbMdCCtM55EqVW
+RNOlSVFoRcxzDmdvBXT/zucnjiFyat9YQrCCXe5fnLy+ENKYSSqmE0esJyOD/ZD9
+Qp9NXVYChP9TQFHtaJnGIMYN5vtH+dhCCzbKUGknn7eKNvZcGgs+ntcSiQIDAQAB
+AoGAFLBwcUcaVU9YD+0pBFuqLAXatEM68PvKAqLspnoa+/8KdYBa8v3skqi3tp0z
+QBPlxn4YfKKB441KF0626DmQsvipil0LVO8Ivr3mjWQiRtEb2LKQyeAW/jNBpi1J
+koz8yVQAGSgAr3v2UTLvx2e2e7rNDAH9C/gx2p9DtHWjYk0CQQD+6er0BkK3wOXP
+A7gOSz190Pn81mXg9Ga9JXM+KMSwH8cOEoX4paGEN8nMGSid191K2woHbgJVxHqd
+qspPKyULAkEA/qnrIJy5kid9+QNLifUPwAhKZux1WLiIMyHjcrSq4TxtpzUV7JMp
+eF2mbm4G08kk+gcD1c6VdxtvY3cEjJQ7OwJAPPo9vuPkf8o/7tZH5/ttmTQtKKMs
+ubQdA2/68kqUSkE/v4kEzSbpzRP/TLhT8/YYNHjTHFXfbx7R6fdZ77g1YwJBANBV
+VaNSU4W7hRTnmy57Kq1gmu1kWAOCwvmBqb63CmxEsTfu98aYBX8Qrgz9OdycWwGo
+J30MCb5s1U07mp8ezO0CQHwV6D39VHAmFJInSIeP1stiXyg634hyrk1OawGGnxLI
+XWp0e7zknCiORPtLgkoLXkZSTzMv/BgvZCqzbY8JO5A=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.4_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1.4_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQCuvuJsybsRGhaQclWM9dZk5y1fGCfHHbVuEKSKuQ5x79UFQisS
-2nlRWAgqN+k9R5NPD9IrKbPehAKGonVAWe8me+Uj8tuRYuDXCAJMyAW/8fzTGstZ
-+Yagf5nIOgiCul9PYtd0pS0+uBfVyiULWTTQ8KDsOsyK4CId+9Cyz2LbEwIDAQAB
-AoGALk3aheU2sqNtEz2Yuc9yzi4L8cTe1X5j0xSJ5VCAKWTZ15je/RHzT8C5+SXz
-og9TU4HnuRRF21KzsKVf2Ht8SRAwM4Ml7Idy4HbQJvFjYDvOjspkIivHpI3UOn8M
-bvjLSuuEhOoq0ZUDOI4L85zwYY8y7Gz1bBYLp5APRkTZ83ECQQDYgSvrgs6rZ1wH
-cTOmSHJqybw9m4gqjj+1hFkzA3As7aIBpB6ptzKEDXOyxmz4owPKsMfwGp1Jji13
-BcDE1AR/AkEAzp+O5vuZcyvh/ZR2ez6t63WQfxffBKHAndkMRTcLscNZXvfVP/Qt
-4A+519shRKY5xPYw+J3sW5YghWZJOGaPbQJBANFlNS5FyE8c23RTNyoXHZpM3OQU
-/kBybgnIJGFjbOX3O14s9n8csR3oyMLaiOB9AZjTG70McJ2Ihk58YPG9QU8CQCwA
-Bmphwbeo7KMXbnOoUVkG3BJ0fuV5nI8AnYBPzIm6U9nJZPwNf4drUeQJofgAfeTX
-mG4ZEzAdtCc0NPtxu7ECQQCJiPY7V3Oqg3xfOAdL1GWwzeZo8dg22srzlmYWwmM+
-32gArO/ipkoiQp8B8xOTWDGHVjQFINhsmZs0nPvb5cvk
+MIICWwIBAAKBgQDCk9NVCzTPV7ylkZ6AqXqD+yZmxcFxIKv5gJpZ61SDg2uteah+
+F2cgGqh+V2743VSabvAtEDJZH3RTbaJQayMMuzQyhO19/vWOp/SSuymokX3oXlYw
+5vr70te5r/KGwty3M3FiKi15OKCxDeuHA1bFHMn7M1w80rnywLY83uLYPQIDAQAB
+AoGAZZMN64NiGitPC4+tErVmg6eEMHpjtU68+A6uhOpYwB7HA1RTJR/KcfP4qZuz
+Dq9cDxKCxsOBxQyqiTLeXOTQ8lYGURaypCE6WAoDbstgO/SDGAdVVmLze1f4ngBI
+YRsUPhHpctzSKJbpAC7pF4FEb8yiqDCog7Sv3uvAobNhpHECQQD5PiouZrCrvXXo
+e/gkQpgPDnB7+v5F5iXjgtpVmE2VudZ3V5JyGhhThfcaDaEdjCvc1xsQQT62liAr
+r6KIsKwvAkEAx9pDYmGbSAlOFRPo7Ye9PF/AHpjfazi0r4TWTpoGoHr0zWeQ/x/R
+uhTliGenBltWST0ofEtrFGu/8Bv2dtsLUwJAKFy1zf/ZOmabEoQI4i5am42WD63M
+wZsMpbRKETRx0/5dScRHteyd5eC67GAqqDNL4x5+hnpaYo0bNpfhtUsPBwJAcMmT
+IeCn+92UfXzBBdyHRZ1cFWh9HkvgXPYA5Fc0yjjaE1oRkInqmLPWXkbxEjtV1Pt4
+77y4b8vnhKCjVayFFQJAYsQVvvXTUaWDpHeH++EXrTv/cXmXVHrAEbxQ6fyDm+Td
+ccx48YQwWJw+9An+HNWTCVcEDS6gjjmy3md1cmXVJg==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDMJqcWeJr74tra48TvfstcIRyqwVM138zc9eKYC+aOBfTllyiY
-VJUVEckel+3u9ElOLwqiFoMN9UlleG26ohkbdCdkGiILhUfQ4YUlHlz9AHo3nn6D
-Q88XTi/qfclauHB6gix0D3dHEBqkURYInnG1fFRTYJKoDByzsQ+rww5GxQIDAQAB
-AoGAc4/lwXif8rnlvUZ1skSKBSrROW+aFMMNCn89t2f1KKwChvxcBG7MvVKGEIVc
-MImj/VfvovUvVnVlCMV1B9K+dqLXUFRe6wOd8KstqXWoxl9K9dZYTcE7nA69fWOC
-w07MlxkMhJHE/ihO3wEFuCEBso/6fR+6Gava5ags26iD8rkCQQDwBvaIPcPKWgkf
-We2P/6dfyY3Zjpe2pKEEImpseK6Bk0eFza1MQN+x/31klJOZwlKZpA3j7KzuWupd
-vvI5r+ZzAkEA2byDL1QBfeSZuTWh8Or9mkbwAkFcXcbSWu9Q41B81mhYK0F+I2IE
-Lr8r1nzW62qI3m41/JBi1UvbmtD0IJsX5wJAKTmI7i1tizubhX70hl7qaFE9w7fx
-5rSv0v32OVsg3bBmAF0q/oXF5dRzvOqnzyjI9wpuOE9WBDopNqCtCatkcQJAChYt
-jZe6qfZZGLdfVSXNscPvgms8uCtpu0Sy3pTv847J5tcV3NXBk9jPUxRdcHJy/Lrm
-TVjy+yaUecuMQ6ZrqQJBALxFiCUCBFCPHMb8f9qztsKonszK+0lifQaebpdID9Qi
-EG8s3wYxC31p6KAfWomT0oxITb/3zmOt5kUoXCBy+VI=
+MIICXwIBAAKBgQDqF3Y0zrPerFBioA8UUIlyJtWilxeR69+XfoD/aY4BCrvRoeDz
+0idWxi0PtYTkcPPhfvySjv13SMuszb/0qvopXxtEA8/6b22u22HxPu+V3kEjNqI6
+52cmBGt+nfaSXltMqwqqz5m0TFQFc4Gje12Cy+Dumykp5vvdk2QjE4XR4QIDAQAB
+AoGBAJ8HNUyGp/c8BJgbuGLKm7Uq4LNGBcMiBJG8ZRIeuVPH4PR3DoVVXVg75Vzo
+qdEvUt78D8XY0iR5FbTdSeyDQtIPpjYzpcoeAezQdDhCbDTTwXMTrCg84Bndf7O+
+Pz6hW8CaJh+53QhSW/WC5fwvz1I12hdeRV3C4SIvfi7BSXdJAkEA9j1FeiXSf6Ky
+adG4Wvo0NkvXVak1o8iMyzv85sLV7WDnI/5KqKXGdqwDQBlawZnfdbbpVcJ00Upd
+HA0yEXlXAwJBAPNe679nZnaGoDNR3ZDYiE69eI+jW6svm8FzZSleJI7pBTpIONKM
+7E8AgFaxKhdLxiy0hM2i/WUYYrZViXonHEsCQQCDobl0VKe0Z2rsupnMuJgUtnJE
+bpIoHdt2AXluepUVsomdaiDLCuOPKOEL8QHdIL6eFMujdrIv94rSphMv2Ce1AkEA
+iXwDFBL2yFiPYc6Kq4wXnNveos53N8Lia6uj53W+k1lCUcWBDDj+OjcfSVo2XAi7
+gH/OUlkUaysWgMjbrD0x9wJBAJXkqyY4CQgmKP3dmXZvWfatvokpP5SXMYDNgw0E
+6FT6ll2wf2CEpATESR3k1tUTKY2MUAFHGv76E55vFDRyVW0=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta4_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta4_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQCyjECjNpcy9yBo4vT1dqMTA0weMnxHLxYyFE7fC3pqIlR4z2nJ
-6qfmghdqMRE4fuT57b6iiULf9N/25CO9rUrCuqOpJjlg7gIHdCVssH6fazPh5zcT
-d3umf07odWHUa4kZa+Wl31JccSU31qfiyH/NT8REtRV8YvPSVNKfxZl6rQIDAQAB
-AoGBAKnH4mMRMx+8jS4Put17LcCTnxsL6M+Lv/BpDULdWE96S5cBrFfb8kKoK/nH
-pNdzGutqHp/SJCxwX1QXRsFD+tSuJUcDqmer7fGBR9dpxMzUAprl2c5Y3ulCBfLu
-Qn2W+j1SYll229IMO+dPHuplOSrtlaQPla6OYJF3FZ5z8eBFAkEA7C7Ik8UBeKs4
-eKeU7Eng18dnFmHm/OAK5thVyNl6FZoX4Xykb8K/l/yOV4ikbN3tfthW+O7qtcmI
-cfNKQMhjhwJBAMGHeAr0Mmjn9IT5JY8sFi6A1r+kcvz6pcZzQhBYNX1yu5KJdWer
-Jfcs6VqNeQa+k1YX2P5GynKDGykLC0IP5SsCQQDC7v4XkJNdUBxk4RP2TieokOjR
-vW5Tqmr1CvsKsgykhbFOJ3zkzV0rCYVGU/456JXbip2GClNoRPU776yKeZpDAkBZ
-EhNy3y9wTwmgRdc+jOjsoEm2TGbL/kRcEOIgCakcwriH2hIaE5BWsen4zlIcg4vm
-PPWXGlfE2oienEGjNxOfAkAYgUs7S579o+PcA+OdJx+wfSyK7W+xQNRDcDFkvcXj
-1A0VNfuJMZQ6JHgkkeWTQcYHCI4HWkQIpOh0SAOev0nA
+MIICXgIBAAKBgQC7EyN/e7wkT73DViN+hPalzYdR0UWSWw1ot1YjrojVUYPA97RJ
+HtLTIrjEEOukRYmGY9UbqE6OMIo8RDx4e8/AIDxn/35f4EWM+MsPz6xBxBvaP9ZV
+fTEUrh5ezd0dNCLdADVgWHSjL67TtE1JKOp4zR3+y574GQmu4xBAA7RefwIDAQAB
+AoGBAK5DiMjDgaItqe6hehTsVTpkN47Oq8lHCjmmtxYsCoj0ExCZbhbDIM7PRGBY
+BroSkKZgru7BnNO1gb/cLJxrcTzGpD7OUprXulO9ONPDZJfhU83FfoL28X5fDMuH
+q+0dO9HeaB6f0Hk/I85yV6y+kYCNRIGtntstDqOmfomOdlG5AkEA4YogcZAFDR4K
+lo5Lx0SdfuUofsBjoR51XwKJJ+TB+SS6D44ihHrU5S48CrRd0/i7PVwjgm3uyWeu
+HzJ9txVK2wJBANRXHksr0fxmQbYoFHs77/o84iG3VivPxlWS/Y3z8REQTCbAdL2B
+5YpkWysmhSFhvX/m5Y4Nc9KVaEo/9W3Jgi0CQQCIWTzr6qljGLpF8piVS0H7qQYm
+OqEAkq1aVuocGAu8Vxu0s7Tiam+ybZUW05u1vjVUDxPYkiU91VRKv/eIa3LpAkEA
+060VMfK5HlgB4ckKwd76WAchlmLhsEMsgFpMEZrBEjWg9HCe79vyK4fnqph31tNM
+yZgv9vBKKf9vO7WOwKdE8QJAVEpXPea9ltr1+0Csy4R/tCZe9iVe/T2BTg06G3GJ
+UaXMmRaVmLPdK0VW6wxQY3uewGDWg/0D/SErD1b9QP5b4w==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta5_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch1_ta5_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQC8oQMi3Vd+mUtYjASYQfl3JgFvJHLQf4Iz1Y9fpiBsArIsVo1N
-/A2mGSkjL4iMZ0nD6ZCmFw4aYihESWiAql4k4Jc4WEXBRVk44DMAfGVjueqhgdCS
-X/5QG5KFecmRllEKvxzIplJPsD4cCAk7oWqv70B734vjvd5BnBub94WcJQIDAQAB
-AoGBAJRcJ7VSVjDSrTpV1n9S1L1r/RDHoC5xO509SWk3pqSNckoBQV6m8q1DeOGd
-z05vJsuadxTLaWJC9dzPyAv689O/NNvC1duMD94zgiXG9oDZRchwZ1wXsBCyUtpb
-06w2Awey/IXNOyOyLZG+TlRdOf/lK/w/gES73jezcvH3VorBAkEA6QMIkJ6HTZlA
-cJGKdZ5Sip8PkECNJtbCK88VKfHDlTBvFvp5huXRzCI1tr/D+DfvpFai2AwHGiZd
-KVRYaQPk/QJBAM89CmyC1Jpp3vikn4zhRV+JOZHj3wvHxRJw+4cW6HeXMrS3xmr1
-aW7Gi/+eVyw2CIneXkV866rTVswZ/N93kEkCQQDX6B2pk5sfxh81r0Yy0i79j4Fm
-Usn38QseeNXNdd2agbSOAC1XV+BcXF6VJX+6omoFRtnBgvOZwW6VezgoppkpAkAR
-kNf4WKKSsBShOLr5YwLRVT1W+1ylj/pJVOBNFAkCUgOPQ+CComicZiHpuc8jxTS2
-Eu4kr7D+GsnJpQ5FFspZAkBen0kL6QyqrpJMIa30XV7OmGVTwwdhfJmuy//uhMt4
-nOvhP+HJHzd4y3ddTyBP12wZI1ijRwe4kEZddDfdjrbA
+MIICWwIBAAKBgQC0ZQgwl3CG/fmJeznElaWpgVVxnvnxcpTsCvqvxgtDaNsXK05A
+6iKRYAIFou+IrXiKKBOsL4plbTjzQ5sQDsTR1+e6DzEGHvb3Vj9oHpWRX9gCE2Yh
+cu1mbiaDmt5gh+A6Y+gJgq/fUK72GUG6xa6PPmq694v7zZCiJB57CT6krwIDAQAB
+AoGASUz8ZPJEUTYGHa0qrgy4wgXBuGeG3GtYxAk6EA6DKSMEU4fPRmVdIoFGkQ/C
+EWGbp1fdlovCyq/1AjQoYAAATS2gmLqQLfwAw0FhV1zCDJuqvFBzheXdBn4sm3cp
+9/FumkUCFhAs65nm6I+FK+jAwTWlmygzGsryromf11JIjFECQQDcdwsijcPt8nN5
+Ej1YRheaR3Nq0TgIy70MxLmS/W7WAuaM5R/gRxwyzz/Mq7Ztdj3eUNwgf1CMXaN/
+CJbx2DUtAkEA0XiU+gyOdgOeW0vOkE8d0H3ZoVW6+CrjDFU381TA52K+G69OSEQo
+PWZ8J4AzUMXh6ndDx9uro4JPBxQ6eX6iywJAJTBTiYWealH+loq0HGLecmDhIECg
+kiNEBZZds2TawHEG0PeJc/yqzgtVuMGyaS6L6yd6qmSvgq38+V3KkIsnFQJAbC+T
+AfIqQdlsmEp2zSGPjHbzR9g3UKUVzvDUjOBhISBmf3XzQG+zOMMNrHkSB82r+KTQ
+ZRCXfUN3/Xf9G3LEMQJAad8iyds/Kl83lieC2s8Ej2L//A7t3KHOnr8QWFAgAyCW
+BSjqdJyiDiym/L9qomPyT8tqciAUV4Y3Ztkdx0+tkg==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.1_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.1_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICWwIBAAKBgQCddM8lNSbNUi6a/I0LT4Uzg2F68fHBVT3cLiB3jiDe6+Q3tmqk
-yJQJbPg2vXimPyxkwyPTx/ocNqMkUcCsLSBvFb+q2JRfX44KxeCqJAKl+eTMl390
-sfGhqzBscHSkWr1e12lkakKNxdC5IWZamzcl+jTMCCFFyyMQ62Zm0pu8GQIDAQAB
-AoGABTw0AvWwc5Uu7YJGIkEjmaHdpNvUgOwXoXF7LN5x41eOf/e1tgLhQSr5WcCU
-+VoSXMtMLqdwfm2moPeC43agpGOH4NBW9JhHGKoaLfiiSqleMiqlqrF/+MK0/0D2
-+1TR963duGwGuTFw1fjMU5ARIIssnKsYTGmy5oLXwI1XoTECQQDJ0+dYj6dr8QIq
-cR3U+gBvgrhx5Mpu/EPt+hnuKPBLBTuLzfkJb7hBUKwjMCO9bt1dCYktUXji/ExQ
-xBXNkwQVAkEAx7gHnabbDWEBatCzGcg653Ky4z6iXtd+jiEP5j9zO5+kblXzsNBX
-Ub5E9XubCO+RxZDJaNrm3xF6gElVeRaE9QJASVAeEz9rc3xCayRXz8tYaSk00rpn
-BlXAXyugS7C3SKkH7krNka3xYlhpjwanlOI2qtsR51JW9Szsk9IGkXw72QJAA8zV
-oENPgbapzz1/Wus7a7H8A2TqtAFHsC6i3c+xQp4sA8lw5JliP/Tt3PnoHkhorqit
-nGgl4nKzsQM0NCSgjQJAJxhdwFACB/G2abV/Ghy5jPwl4R/ux7panMX2jrdzEoUK
-jBXQZAn9XtJ6Z2SdoqhGct6jRMPi0Z6Vom5HHkNPvw==
+MIICXQIBAAKBgQDVtW+a3nlIHp58YbUFP/HvonSsg5L3+m+86r99rNjJ76NQASzb
+F3xobDQEd4n2d9tjCCvnWWp62RPv0LEcE+A67g+26XSYzjAl3VcF7VX40l56yTed
+KYekyFXy56TYzxnur9kNNednrodw9tKYHWLGqrbt0FB3ea0uX++nIoGzLwIDAQAB
+AoGBAJge0FSS7A3UDchH3IziGZsULqzl82Wk1IjLKIeS07XaaIt4aq+BpkLGUrij
+Roc0heuWU3oYgdz0TGa2THvKAh9jJpabj2/DPKuZdLmzd87AFOoSef+y9RsycB10
+BHGuh3SPRr0UzKQmwvQDLQlm5Y2aWdkvNZJ39FCOUr2b++uRAkEA9Jr2pSywCbK3
+KOTQ2v5GdG+J+BKTH4Zvrr4ABqunlyPm6G6BxaRatrSKV6LwEfCMIKCNeJ6re/3S
+X9uoxfyq8wJBAN+qBAcX1HhtraA3fms5P/uCHohbFLOt3um+q515v4fVWc4BWBDB
+hn2KmhypW+BL/7CrNGFnTxVHFzx6s4cKbdUCQD57m0ekO6+uhFUg5i0ayRqTJ3ZE
+IGrsJ3lGtbD+hkf4dtKm7+Vxz25effxW9eZPQSxQdvL57So2M1gjP2Cb43sCQQCI
+YqkAFkTmhqLYTt6UzZ05ZZfut/OAuWZzjGQjq6jiUHPpjaJA3XGAPjNJhPBUbqNk
+/JD9UDzGEcqWg4/TqcVdAkAr/J1N/5rdDciYl/j16U8amIijOPHwNj0oo12ZEKC0
+ZkOxMClj6MgiXtA0wm9PxI/TRO/zt/n+N2k3X3Kx/Cck
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.2_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.2_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDIdPMvR+kCDvSTucJlrnSikD4sNr2GsUT5rM6sDY/G+rSUYjkl
-YxJ3TksmynutfuIcmhhtEM9tgrYA21fWyla7r71ydhlfGPPOVT7Jn6ClZW0B1Av+
-oI660i0ZX3KTq1Cnkbo95tdfB0phwjp7Ineek3MWubjk1qSflR3zVGkZPwIDAQAB
-AoGBALsFIb4DAUmCWn1Y2h2z3e2tVdQ6XijESu4GY+vx2ypxzPiDi31uKVRWH5dZ
-YnpD3wGAYzmebWhmgxfZjOJAdRmOCM0upjKdpL7N+zReXVCAU6swkU0dcGkliE7X
-CAZuAI3iOBqtQz9Ysu/DgfGIKX8qimAa8DlGDC4THUb1Q3qBAkEA+Rmk69C7hf7T
-6jNRmSPQisIpfKzU/8X49MSmQIxLj7C9xv/kfPl+zmn0LZr06ntAGqCvyaBkegoF
-v42g1NrfqQJBAM4CYOK6pk315b2RPKH2hb/jPEWRNqEYlMGRXKYFnB7x5Fqpv7em
-bD87Kcs2XQLq4zphnUcL7FsbeKTZMrN+4qcCQFLHreHb7OV7qMrUoRJGL6BdI9JV
-0TbqgHA/BYy/0sB+mKKQGUta0kQgO9AIBcoCiWwP6DsV/S39NKnSlBcIYXkCQETO
-VI/FqYAGbipHlQm/beKuQdY2bxmVPTH9nAUzgHZxckS5x3fOVP81gnsF+EDeNPCt
-47r0B4hSf5QHm0CKU6cCQQCEO+tctu6RPuBk8ghRABeS3PgZLuJABabTg2Mt7Np2
-Pw0hyZ5PVERGMXOVPPvYgaidUPhEHmF2SaH2uJ27rCKr
+MIICXgIBAAKBgQC1bzvEquNrGuImQfJJ8UCFc9zs7wTUyfoFKfy7uYNf8QXSBpzi
+UgmR19U8Re8/dyvI/Gl4GZblFMN+iq9WwETKXEm8PHEKuQVuKrc/AoqA2uerR+sY
+QBhKgFQs3ZcJ332uD/I6mlERr4a78exdRU1kEdUPL71565HBXiMuGKpuiQIDAQAB
+AoGBAIEBiYbqV3AFmn3HcEbBQrZhTtotjcrbnmnjk+/LFa23TAMtbonB+Un5JIaJ
+13bR/pEXYMrjrxZN8D9ezxOo/H+Ou7PNVo2499wDRo41fqZdbVq81kZQ1hPTjFkb
+S7Hyih89D1fYIu5+BeHN9JYIR8VLES4b5Tp3s0YLbxG94j4NAkEA7VzQid+gFXSV
+bnqre3KX1wU2m3+BsRiuiMTTmltZdBddEq6Ert38jpXsnX/AmAXSyttAnDMvwQEL
+l+Kt8ehqDwJBAMOuN+fYApBUSM495cjIODvOafW0tUok3oZn2dxTnkcyKRwUsjx/
+wMSZ0Brz5kKMpyHKv0JwzXL6mL3vE+pIlecCQQCHw3ev9I2O2BEEkPt2b3Pz05KJ
+XGPk1JY3ukTB3BANO7PLlLBliKkFMTGWYFTbXzFTQBbzgL+GqD9mT4xoeiP3AkAX
+yO9msOzu2i/XUdLCawPa0SY0BXkbwAuETs8+ZrOQd9pjXWikzeqCeye+fvL4F9yg
+0OIak1eFqEw0mgDTs2r1AkEAmHXxOs8eAqu2dZEhVHEDqcP8p97EfQqgKnJihIom
+a7YfY7RGgK3aZYS3FLWVjX9sLjmrP3yUEl0MD6nDTUSBZA==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.3_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5.3_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQC1duWQlxDVqgIC64f1ljqUMabZG5k2a2ITNs11v125GQIVeegM
-lRKAqJeFYDBvSj3LtLzYpk2gQmQo0wcuCvM1wzUQCPke6QdjS302zGV+vmXLoq2L
-Shzsnvb1FOeTQlwLo35zrhhCMjKgRZYt1ddcdfLjSCM0IIhPfhohjEUwDQIDAQAB
-AoGBAJf5zsNssW2wp2SYq9JTkhXhC5KS2ZtJDed3o1V1AuJtfmBMK7q18rwL9nJ+
-n7HlJKIBaZOsnCCW2dmS+1VlWFAJN9QFnEpunjZvQ0J1SGNfksvEj5sJUyVcuPEl
-TrBUKliwLTu31auUj9nZwEcIqKfBEiw1PH5IcozYOwrXbNhlAkEA6ks2pC5pbHMU
-Z3AD7oyzpH+MUQ/do1Pg7pRFo5RrQlubXkESn7hJycwRfJiSiPxMLyd7zM19ckhz
-K0LQuhSHWwJBAMZGuF6hChb1fo5V7E9OoSb1Ss8/RNgd8Y53bpY5OIHNHq2t5aSb
-+1OT86h3kxin/7AA7a98X0QOr3SpRDUCqrcCQBHbZ6+9xdU5NC3qELKm0K5R9lzb
-S7Y+F1+3t1MPZdlp5/6YERZRUnZp8k8/xbNhH2FcrgffBZenQ/fhIM198Q8CQG/y
-OeJjthikXuHqLVPRpzchwy0kIbCLp3iygeObRwYyU6HnzwKTduEHZci2SnzfTYOH
-4qrz462/RNzvPK1ZZh0CQQC3MCNFx6/85xbZB7lkwFXYWLd9yFSMOviGBVHWIJ3v
-FugIEWF4wktkRZtDq1wXBJbaO6vmpfAbgHICDDRTRXue
+MIICXAIBAAKBgQDFAyv2B07xo5uWh23q4rsL+5Vw9jSnu+ef3/+K/ShWC/veXXnR
+ug9Bc39buRdrJNtvIKNiXjq7cSkYM1Ik/6mbcEl/eJT3vaO/L/Te4m9hE85P82qF
+hDWuHaf7AC01M8wY/4XZNwoVKxVx3q6Mme9b3HtLwbMI2VcpKeCNRuB5gwIDAQAB
+AoGBAIxLu+ySO8ecKNpDSyUvnN/lowA0dD7WcxXI4CPMMANGuXAaxPtzMhX798AL
+yP+F2bYDWhZc4BpHdWpEccTjQ5Wru+CiO0efw/GuazgYtJDYI9V7p0aYntXwkwPs
+jk4EsF9136rKIzsulDVx/LPNXpAjhgxKrxTQOddKPsyBYZPxAkEA4r1qxxyZ2sqa
+F20jWFIuZ8jtptOnLk3HFEuxCRwEL6bq0NLjiftR+qFu8K6+N/OuguRyj27js9rZ
+3f6HYh5JHwJBAN5vrQJTBgFqMNq3dojZSsgUiVi1LdRVrsKpEdpEmMVm55teOtBn
+rBuqyalukSTrIthX0rVsdwj9wUq7Ad3Krx0CQF/ztLoqOlnCn08GmoyHyqeU+i09
+KGSJ+ZN3LKYkOwlHY9uXQz9jIaAkrOQhrtHSx6kQsAJO9QFpvgUZ74TwOBUCQCPM
+DyjHmbjSkSgxzFa7uYg3nd7z0XtRir1zHhdlYLysEev0Hzz44j7Vnnyw+ZTabpIo
+mBVwbju5MslHDUbXXpUCQCdQxpz9eFvnfPhOjYd3Xw7c+x/DyfzEuPVMSZgsuyj0
+K4pQzhH6PDUrpsOd+slz0HjbHLvAfFCaBZ1VYwBerHI=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ch5_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDpbG21Gu/6tfZC9n7m8z8RL6fJEBRnyftLxC/EJQ2jPGYPoBqG
-1RlI5lSjpo1qoomppe3nSa4glTkMGUGH4GOvJ5IdVbEQ6rRtWuYheJOU4gbmfcZT
-TtWvggihgmTBV3h+Uhj2OPBejgnq+vx98y2HXamO74d65Zfve/u0lglrFwIDAQAB
-AoGBAIQjqYdYlHmtAJevyu8azJ0CCU29GJAYu3WMvi2ffDToQC6gR+QERqgKG+f4
-pR20nZG4KRFBmJ1BXGYI9hvhXwv36ZTY0hzJ0WpwnBAh/AHq91h1L3hfL4KgHMw6
-9kN9+7JGjxOq95rLzlHS+KVkEQS8HAKLwD9LUoSPINiWAdmhAkEA9VE7gGLEIZ5X
-Zp7tkazr69AXTX63X8TPutnVDL6bNAGWWcPNluSEsJ6Q7VE3SPSL27ToPKXCBIQf
-mL7+zRHsAwJBAPOWmxpJwyOvdpJVDakLyLzZr/DFJ9pdrOlwkdYnHKRd+wbefH+h
-/R2ViuX9P61MGr6I7vXEeLy96xdIeFpaOl0CQGeWx8Ns8Vko3ctNrQ/ory7CjjSB
-H7nnB7jlJxvcmPka+nwpPHVNReK28ofj1a6O5Uf/WlnRvN3fVOBRNpMt0DUCQQDj
-Va+zvRut9lgHAfIZzrGt7sxRPO+Q0NRLmY/B+ga1MDDTnFk9FQWR0rsrIkuHhPuA
-z3OVU6QLIoSB2lTYnlTRAkBl4GdYElu/XS5mVrupO8hDpiPOLfKBTjMpKXCMuTMz
-In4MwPAfaYeAFO2fu2wCzqrs8ii1tZS+8SXWm2piKWxe
+MIICXQIBAAKBgQC6p6FgM+tZhOYvsDA4uEmXhjuCTlFqKL8qbdNGd2fsEHBpIn/h
+XXpFtYEr0up9QVziTegtBokcTBeqPPUvMhIEgGlSgErOoU/cdqFa0lNDj3z7guuW
+Bs0FiXQ0fZlivAln6SeAW3hlBVfItrS3g1pGsoBsPwU8xkktdXxILiI1twIDAQAB
+AoGBAIVYKgZTMQgj1FovMVPj+9b+81Z04t7HO0JxcST/OsO/Pr8tAVSb9jUEpMIN
+DK3s2xFk/L/l0l/f0Gwy3ioYSBurWDSigMxRz3AerkBh9mOKM306yxyjiYKIqD++
+eB1KHDiUIaN3WwhKR6S+PgH5Vf4M4JKkwvsCqvYM7avFOodJAkEA8R3hqUe2x8Dw
+0WUOIlyERfuk5FcYEHYa8omwxlpvtF5S7xH6zmZgWM/TF0bIxrOXvrBX4u4R+def
+o7Ko8ZNH7QJBAMYtJLkr7DUdEahLpym302OlnYOmIQbhBfi/kVUTnMMgNJAVNO1q
+uxi9kl7mJ0GhOXAPqZkK+DkHspjRxVIfN7MCQHVRpMtJKZZoOsSn9wihG3sxxjmU
+ZxEbZmE8vdbFijSo8JGCnhZvmdGczYk119tW5y7RfvHcBMMcN4DfHXTtxMECQQCz
+/mSQWrhbNV/IP45Acdnpc46w976fhNnrp/LUFtAW2bVj+B7uVDZCrku3LcsR7OFC
+Srd7bV8uTTOFYWGayQfJAkB/QuEnKLjuBoGq5E0e8df2R0cK1Ip74MXhKHMHtWG/
+3Ao7FcABx0du/dKR5qMf1onHRuTLVjUv5NgX7bqL+jPX
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_cs8_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_cs8_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICWwIBAAKBgQCoidb24TKpvKXCyAAcoQT8k1pcKR03finhf2l5JKsFWoNx2Dy7
-5Ry44F6ovUEGy2n20rlIxJN8rsY4vNea8tuN+V9RxBvSxQ5XbQtzGag05luBgEN3
-Oo5UWZFpqaqfKyQkHgbovPI/w+4zP/Rfdv0kBUiomC8V6xbVJGvqWeYGUQIDAQAB
-AoGAGpKpFwHIuCRrSju4cMseeyhMfe1pkt9MgSZSnewfHtf3k5KReNqV3bxakGZO
-g2C9E1KELin4SxdPX5C+ucqCvS086jIgEi+quRiqz1PmGm2aXQbXAskdMFaUUJ6U
-XVIzQKqROX0MqeTT8gZVy0LnWMeolFo8TvBg6Od+6JEi9GUCQQDZDbS8PHR1e35v
-W27Wz09CrsaOw1ea8PcshJfCkrHmwRs50hFqLJj9dYBm8HZYTUbfh0x54/vbfYEM
-9eI7J7bTAkEAxsebH0DmW1gP+1YVY0q0iueng8VnWBCuK9Hma0S49ACoE0G/W+9f
-u7LGXQuzMTQe4BqZXd/Ytlagj99GOtmfywI/WQZGGu6w1X7RXNsjmvdsiu0kg2mb
-hPFQb/HyTNveG8cYY57FhcbE+TA4egAmihEoAIZ914CqzFutkqNHJvwjAkEAqDDk
-VAF55/gPLb6cwjLHqHByENDKrH0QogssR78SL4MOs5yB6awU+KA/ryLjL9LF/SEE
-e6WXnFCX8qQcrFbPGQJAShAwR9+Jue0Zvbtp5tR4u2sAqFtQUSFKr9Krc8kcpgjs
-bJVeaWMeCmjF4KZnnWB3glVaDTSenOH/Q5L8I4gTWA==
+MIICXQIBAAKBgQDM/fZ69gSIteP/b84qAYndB6cQXcp2v9IYl4Basbhua71rZZok
+DT3cf+tTH0WenGGY2hgIwz5F3uAeFpMtMKTjUkhdl4A9uT4lKLG+F9txV7o/aSI+
+g8dv/mn9bc96L3I2jYUoOFAPRS8i6EkE2hfVoRV+tg7e5MwvKuIhlQjLBwIDAQAB
+AoGAJ+fQkcNOwqZWCiXjxn2iLusMdL0tasyQw8TKcd1i/+vtZfjTdu00+7XTQ800
+qlnbDfx27U3E06k9i93tLMDpeBXRlU6U2H/83dzKEV49Ns4BCvY/Jfn9GRqfPtLE
+JNQkPwuM/4y2B7Bi2xk7d6/b0OXNPNFFl69Kcq7bwTv6zFECQQD4juKmxVHZzMle
+jHDvIg4ejThkhpwnKemAy4I6ndp0sqzccBtZmnRvBUEe757+ABCRlyqyZHogz1lu
+AST6FFYdAkEA0yEobSKj3B/k7S6b2eTUSjwjPq0gjZg0v4IeiSLxoezc44bhu/a7
+A4qmWYfupFwjlAuzHb4zEJiqsMATr7PMcwJBAICREAWpbQQWnFZOmJ/o4prE+1Vs
+F1ten4xiN9NwES5puWYwisUXUoCWnC+PTJMfn3JfWdN6i31rI1v2NZUxbbUCQG4+
+eSqLlP6DVPmYhd8AQu3Eey7mHgJxwNFjM2iua3f/A9R3APYyPrL5uiUz+qOuTRGo
+Dk5wm5+F6FNE6MKtYwsCQQCPDwb8NyTW7QgK8GbXenjrch1x0JHWFdZpZk3H+BcN
+1g8pG9e6HVD21yBClcUuACoB2Ki078B91g5KKtDlw3tw
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta10_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta10_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQCybbz/wv/vuEl1a4zUWozelGZVYEYe3A394ZVikVwRHg4sGeLl
-l5Pl3JEorINpjTqGLaHp5hexSeiYSa9duw4SZlOi1xElzxtxwvetUHtn0SpEmSEl
-RF/0LaUVaaISq0E4HMDwnsxJMJE4ah7pcg35qgq5Mt0B8muRcvZOhKv6cwIDAQAB
-AoGAIJr9Fp/DtUKv6c0lhwilBWeI68EUDz+XLvWyHrkBYf9kB5sTY3E3jaGoxQ4B
-VaCBOVPNaripS7R91JZifXZZM6VJdpdKRyOQRt5h4rm+Iqro1Qgpqlhgfo/qXPpE
-TXPxIMmgs3Y+I8M41CxEtrTaLy/2AWLr4fjo3ChBtdxc58ECQQDj6wzkx/l/RkLn
-CZBYQm+RRtobZWVNnqOlQGBpdVh2Tr+gbvguPUCjT0Mq1avaFAVlf/xFKAc9AwDE
-zrm5H1F1AkEAyGmzLD08bsw9FNwiMX32hGNU7DucWbVd3NoV3Rcvrz+qXHsTI73Y
-z66PuugLSJv76tKIaLh3RYIbr71BCsN3RwJAVQlp8iI6kKYiaBlFZejDv6xzzCz0
-sxUxcYKndjF2JA4VqUI+DuKDr2rvYJgAWomFye0KrrLUoIrySnvnB48L0QJAXif6
-u8ARUmS2FcTOc74gQVaBoXLoI+VnscjsGLE5//XDTiusdFBPOlNix4cZNgXCtzIu
-UDTKJGfaJhieJDZtJQJBAMOEN++kynQ7Wc0crjSN1mGxj0ls8n1VNjO1+YH6yqQQ
-7NWOMU6j7DE35eAtSSnPtDH9iqr0RzoklOp/XZsFQGs=
+MIICXQIBAAKBgQDapVYjs0vBWio8lV5emCF7guV9h8Kw7/R8HYg88I3As9pE+j4d
+h8qGf/ZkXIF8S5g7Dj6sSdndJ2fvoae1JS5i84ne1Eaks3YWZxpiDtnnA2eqCrey
+LBa+49TKi/YqJUlhBGQ74uWU5dyBof/hQPzl7ztw0EAsyzzq10ePHfhHPQIDAQAB
+AoGBALjsX6eALJFS9igZWSB+YMs60WhTW3oU6N3UiHaqKeoS84elcsW9JLCPJ9CI
+YMfEk/NWv/Et4QLoIkMNoW9XDBv6bL5tSXp6JYYC6zvlrp6EWPmMB/N1qNt6nWLP
+yHWYZkxvSkeQfMdpusXEyGvG544+T0+Ri+0To7hKpJDC42HBAkEA81t/+NgbGEoi
+CyCrX5so9EHY7CObJTp6ETgYxWGeoX5zlizyC7v+SuWUpigi6Aei0PRK5t9pEbrk
+oIO20GP4bQJBAOYBMC/V8CTGofeqJrUIybY7+0zlM+iAXT91F+BmsfbzjYBKIMhs
+VLz+MpUSDxwtQaZz1AaiT/Vz35n2V4u66BECQGkr2xONObB2oV3TwZxw7vMY3gm3
+nZ4qNoTojHQJK0g54PQ++mAt38k4jNR+Ng+29Rt+6Dv8w2jBL3tbUQ+glMUCQHhP
+fM444UHLaSOsrEycCS861uvVJL7kjmJINLIb5dFges71d4p/KCAn83uIk8DQZ3vT
+MMA7nQmuj/LwKcEchpECQQDiuJHF8tri1ISrgOZpQ+NVUhbOl1YPHuLJ9klI+rjM
+QFChVvxeThsutz+liKhiv5/th0iA+mIH38XBb+Q3LTXn
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta11_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta11_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDQIbIQBJ+c7YK3Dpg/tieXJHQdiB5CKbw7G5Glkk+AKoEFcS8b
-P0mS0Z6/6Dmob4ENUyAE+jMyt5Y+ZveF1E0y5xE+qi86QD8ol7Pun12yTOFefS7R
-T+z/tDS0ZLlW7StZXODF4ZFmIPJWnW5VaWA4bYrDjda5MDes7eu/7Ua3XwIDAQAB
-AoGBAKejHDqOnsjU/L3YwYQ/gS/ZqrTGmCiOWQ/6qpsDd4kxsu3hNiHqHaZltEm6
-EAa8mONUmqunomktOZRVdvSSBQKPrB3phXGo4ngw9WD/YEIuyOyGZXUZMaJN8YmX
-v0wVshmKr1BKaCrxtXaaD1s2Hg96u7OB56nMmoDih6NGAuMhAkEA+2Tk1m1/FV+v
-uQreykAGJs4eJFWH3HFXrqIYmrqiA++ZcEgni6sY7PpLKdl0aLQmSFkS/Plzb4pd
-1om7hSZemQJBANPx44/6v7563QA7i2amxJYl5bBRv3tOmD4fLTLGV+0rpvQq2BQJ
-mfJFnsK/2fabiP1rlcmP64kxs1JGpWRI2LcCQQDA3KiKsLo8RYpkJajB9NhDUQHi
-0hNG1VV1TjoeCmxdJKXMdC6SghK/S036ry8VXI+6FUvx89XRjo9rFYNdJRCRAkA2
-nLKNbAgyVchSggVWiwxGwDciKr5TUJosD65+0drgMwpPCicpapvvcH8LIZJRWByB
-aFJtYJdJf7P8NFXztE2bAkEAqNQ9zutNLQi5PHKLZfEDz+AA+Fa7HXQeY2n+2gsv
-BB7f9KMyVxLbM822/45na7s2RO+JjK9jvPEPz2/zfuUvsA==
+MIICXgIBAAKBgQDjEOT4RGRF6lQlDY5f9xy7gPUerxndujD6G2w+AJ44CcjmGlw/
+TkZRfSxeglstA1rzMNr8C0UuwkoKpXhoxYHZu7aD/JBkDhNdddF5nDgRFfF6mHA9
+PWWnZcTH3vtwAoENYRz4dw3GIkGRyREkWlrM8zAvIkf9ihOCesjCPl54VwIDAQAB
+AoGBANgDe4CAN9CXk4NIeTjscoYisY6GUBozBmL5cakul1aCYIAfdcC364eciHhE
+lQ6mkYCn6rw60I8iQKQONRWfR94bs8Sa7wDtl2IPlCAZ7Qzk6ZdO0X1I9QcAfvjb
+wjXX8M3UNBOlC29UDRTGh2ZjcN9gChZdO3Ay13r+trHHI0mpAkEA9iUywAfaHU0m
+5qCZc/cYqSmvUU9INdvzaNx1j3q8IXJ/4wpscC0K/8TF4FeCDiVpyggQ0RRtILVs
+p0eO8s/LIwJBAOwoJdQY+EJtChD6dI/ixBj5VBw+98U8d+oLXow13xpYjpjS4h4y
+H6xqkgo87e6LWSmzb2LBb0QyXmmENlJuOz0CQQCD4cZhUVOyI2ZWZ3IQyjHyYR1I
+KXx9Lw4p/wUWDSLDoP+YfDtBl0CvbZS/8OMEBVO7Jbss6w7VWZ+PuS2EN4WVAkA+
+rm1T/YivgOeiGAgmRMdN5afIk4IKTQF7Eqd2ybm88XJv59FyuFUl22eF5iQ1I7F3
+2xOef787t67NjPUqLe31AkEAiQ2A5JJZPQDfpB5Zjcho5P06XW+qrJMxAn+ayYP7
+aVkhRXxokCNbUjmKzZzJv4a7mb3pLTIVj6RLLj1shkaq3w==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta2_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta2_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDnOghd1z3IUEOtkodAWFlc+jS6yb1b158XuE/SFf2G2fA6B0gU
-88CknuPuAEW6qt46XFPWDd1GiNO2E6ru+MA++usKbUoN9zkh/13c1xNbKunkwB4x
-K1sAzrBVRHKXZgarQXEFSoNrO8+nzl1hQzu7YBnEM6wjcmad6XK+vWytKwIDAQAB
-AoGAREGbSqhJMqKO9+PzTQlHh+zMN/9piH0EF6pu1aNsLayT/2062ASEb5P/0Lf/
-3XSnGS88CEobccDeTjdMFDMV/HHLp7Uu2OnCOeuogs9yhTiogEYuW8dz7MvxSdES
-4pSIWMNBZLIjTyoaom1CxaECwgXVaChfmhvD9Y5zJ3wPgFECQQD1lqNMkGliyyXx
-eAXtsqjxsEw5g+8tzwMVDf/wddkQ48d6pDXV3rzyzaBLfj7NIgfqTi4BPU0/P3AI
-EmHBYORHAkEA8QeHAfBEKIPZaZ8JziCPxsQGKbofZxGBf4qY1ilQ2lMQ7oyNkB1E
-ODR96zxBMMhHmxDtHMLOHBnL8/Ib8WTV/QJAR+ZhSsIgyHa3VhmQisW6pn+54UDa
-Hmwz988QdmLaORKmzSYUSNgcM222F0QPuNjUvmlDGMPMwM6eyw4upoHqcwJBAOUH
-ZBBBgGKHNtYYWzbU1gnnRnvr8d78UXMh/ayywbNTbyldwT6JsMM/jc8zCDcUeIYu
-hUDpEvS8xoJdMpQkXvkCQQCalOILTCDd10+NPQwa9q5o6EcfsULyvzd5CfaO/rIO
-aF8cGnI++bXAQipz025/mU7Dye/xsJYolWV0++rCFQW+
+MIICXQIBAAKBgQC+LdGyqjiqwU/z9wfy8zAMbfcT7cPHyPiHjeqjSc903TAbH52m
+jrfr+vX35eAFmuSx7S3u//irI5rzJK2ZJoNN5zW3yLFgPQxE6SwkUO6GXPC6YTRd
++Wyjt+MWDpA1ngUVmTL/UN614GaI5tULrhapkfWGxCPJfvGdK4ZD5vvBpQIDAQAB
+AoGAEaenQ/LRd+iiR3+zWTaCS2UZ/tufxTg++jaOhcIgZDT0dlAlDoVJRbrygqTw
+exS6Dlp6XSmeKCUSCWhqRUFyBuxHjTq/b31oQzdKJjxKqU4E84ag6vr3EsFGlpa0
+nWZ8JxCoIiAqBWpj9vJE4IbWIQ5jC6kjlv9zzsBYR14PBLECQQDv4wAdx6sQQC01
+b0DhMNraX/SwPy/T8cqLO4A3tClD2rVgWf26UQwl5kCcDrZp6AneFK1bwfq7c3jc
+p6un4MMXAkEAyvQQRTm6sZrAXi3CrnugCUmDDtsxWWa/PW3cTo/MmbizgGnN54Ek
+PbmetajC2TF9WHtFn56P2xtAPb4feDsGowJAZtn6G8qXIqGRgJ6Rv7uVqhmILOT6
+mbHKuMWrJLb/FlO4fnY3HmJPhhRh0UdRmLjfOjO9XGEgIqzQvjK5m4H3wwJBAJfY
+HOg+NfE1kCGmaRb0hZsNNhICaxyxY/nI3WCl8/U7HInCH3zKwVuxKg5OEmI/xcFS
+kZfIIWdULy9CtPbWarMCQQDBpYm0N7dqHT6FVeCyXgp51i2qHDJcNb/r6uOQZpaI
+9nbe9QpWqRt924QGEoXgVQD6aI/8KSqbbNj29kJ488Y5
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta6_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta6_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDh8GYk2/pfALbE9mPwUX1J+ZJx4bOM5/zp5E95dlJRBmXBX9RR
-JjBGyXCYWsWpnmpnJCV6aFtjr5DnsftC+RWc1EHGkP3D09fP/gDGOctsrpzLdMS2
-H74bWJ/JijNm7DII/Nkj4Sni8z49U6d452lJKzlyi3QzRrH3OyZPjQZk5wIDAQAB
-AoGAOjw4V6/LbMlGUqYfREX8wSBuuqOuH9d7vN14DpqMxQ2dFKaalv/82YH6X4ql
-//4w9ry+XDqhs6QA+XdKiAyjoPiam1mG8rsVGIVTLd+Nfih843GfECo2fUMos0+P
-bCgRI4l5p4EaLYEEH5HrxvjLVqjoVbZtriUxJO7eJjtTdKECQQD4JPyXgJERB4Or
-p0bPL9/uQppOB0vwR+QtgreY6Od3/VNLvQBMxoQ1IomR0ezWH5qu2CvXj2CHiMzx
-+hK5PvItAkEA6Rd0f2zjMjySe8IE+4AAkSS5z/Q/ytovv2wFY+H+GQNe54dsGbpC
-oIAzsiS0MIhulpVPNVPfAlbHt4QPVu+j4wJBAN7/3kAIulWjeyD34xqu238zO5iD
-1irJcLW1k2lHZTzf28tkvrBAdu+Jajgxf7WuEUSv4DaIEye6OPP82HbBqsECQQC3
-DLdtVoq5qf3zeLPG+of3dBsEJ7FtUZmLv34gKZsN86q1MpF/RtoKB4QRk2d6cbo/
-QXRZ0crhoFrpUKlnQXy3AkEA8qxGlRED2Ngr0rZk7KPgwpGc7jDe1vylwLkVfQ7C
-5MZBpxTL0HA9fnrsHiPg2WVOokJ52zBNNS4nKkspwcH0Rg==
+MIICXAIBAAKBgQDgR1u2/zO4dV3R+DFH10bBEk7TlVSizdjAGTUh6gPDc+DgUKEQ
+Ls2apYqwuS5mrS0JPzhC7C+9wtAWkILQHKnHgUw/ncj1bco4BMKedzwfC59L0srf
+oq/wTrhR4SwBS6e3VmzuliIvLzOD4sGlwKrlRStQMYSK0FsGCi9dw9bVGwIDAQAB
+AoGBAIzniBGCaCYdZqJCAgQWlhc6v1di3FekZ+bYb28tLMwhA0kqnuYh4X6lPmsl
+DKfpaQAEPf6dkKjxufZTODwzpd3KJGRplbCJ86lxXpI/A0+uUMT86iQdKhAJYZHY
+1Rprq5I8SIJZM5lXE+6njuvNMEh5DlCqeY38m1s1xEUwVlvRAkEA/bi9BagglU3x
+KwmC79Bg5dUGah6ODrXXe4TOk62SxsdEXFO8rpXDPgKSxT9dARdsLvU+M3wXL4HT
+k4iiImNppQJBAOJK75M0DiLVULrb9x8uRaeMADW7chmXG02TqlVyRl+7vdMF3fHo
+QEDxCjZbVEZiO3zbhSXytl26a+s1RQ8Rh78CQGfO9BeiaGJuF2Riad4wxdSDSjKU
++c5u/BEfj13AwLLvyLp10FcmE1IFv4NQn37Y1HyJ/r8V4G6hka1lU+D6B7kCQA+f
+1uzWAkfbbKiKOYTYoAySeQ08tQMZUNRJZtBhhIRlpRSl6g4i2BTjz62zHp2BeNQF
+ICtfl8He9kaWNf91WWcCQF30bCMIbOEqKvue4HfJ6Z8KfV5iCrZwRM6HLgv/1blb
+wg6lgLKxuPz2WPQTBZo1TLNJra/iJhQbO8WNrf/7VL0=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta7_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta7_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICWwIBAAKBgQDBjrgKvRdAwI2zb8PKl8qwtpUBnNig85+vLsg/C1Tz8MauQdC1
-c01us5P5WJmGtGYhLZ94rUfrgXhdIS4ZOHpzZF7Jj1wc9ZK5Xy/z3uejjIrL0bIA
-7XwkqBDSLOsyfEgj/sKdQbUH11Kq6SDTKmNgxBpgJwUork+I/bqO/wLHRwIDAQAB
-AoGAUINKYQUo8AFosBQ0kEg1wu4f60zP+5t7eAZwu3C+RL6KFqA/7cppkjvWuKi3
-LAZMWU6+ABesS/VOGQcdQtZwcGb64AlP2pwxEOU0bvmXgjVBIEw/WmEGKq56N1CB
-LQQXvJTSFYs9WV5YNBcZv8CEGPOSFGHhIx4JoQy9hY42UJkCQQD6hdKxmhD5zeBf
-lpYtjg7/ym3w4hvj2XApX+371VemphYfZCeEzPWZEO0qlJmQeVD5xXZMLm7Yb+SG
-HFAupFgzAkEAxcoPpYSh4KIB36YZHLpkE8SRjTzz0w+hb2KVkOTlbLju2YzFfXkr
-tErnBeP0UGon6KdrsOxVfn7XnW3clvSQnQJAEIV2yaOhbvf2zhb+PG7b6l6NNY+T
-y0jxrqjW5v7A0wqs9tECEi36HGgTW/WE0xRNFMvC6288fCWU6os/dnP8JQJAPixj
-OLt1i0BB6IS01iP9O32J52TmnE0IiRPrQg3B1KhZZIdsuSFyzIzTDDX44aJNA0RF
-hOr1gPrsWi9jrQwZvQJACGfFgsRY+W0mUhyBa4znyanuYbFZee0BfvBHe35IHa28
-KvIl4c6hO0HQ46z2ikPwJyTKRfcxt7WLa4kkGQQojQ==
+MIICXQIBAAKBgQDWRPMLSgEauW5aAZDiHTk3SBZdFv57aUfw4rvgW+kibMx8LIoN
+dG0w9fWDuLWHesEMCloXbtwhU5+LAoSwRZ9nMTBh/xpiwqmUtPlwVw0Dr6EAWb4V
+XAh14FZNMOoC0IrxLN36dMzzmBWuGuDAcmQKJrbiBBckXVhgrAGncwNx7wIDAQAB
+AoGAcVajYPNSRjqTvpRZeOGQZEeDXNZO4iS8YxTr4C990DHQsFY26AsPvvg7V+Oa
+UgGCn8XSBdckJZTALZ21ZjBNsiYy0TzdRMdBWAx7nqqZiUuCXULKu8hUNXy761Mv
+/Gdllg+7FrsUksQvr/qmKx4Vra68XLnLj4m68PVPan6+YyECQQDqg+DQyGP2ReMB
+cZINkJGm522GqOhmo44tMu/An49K6yTLMAkjthjYikvmFcYXCa67WLa+vlRO4HUx
+EhtVaCS5AkEA6eY+KMNiLbg5p+yh2Tx+hXiCFQdVFFnjbKXLTQa8bclKOQ4HmkrJ
+BOnc7HNhtkhxgvRVrEnP01AgLQ2mJzNH5wJBALobaEkoDjQ9p/XYVCjRptUGaePo
+nW3+s/DosF10ArpYu31IJKijdTo7Hhp9AxP7SiBBOd1LnApwlHAZx3lSyXkCQQCr
+Wm33Vww6CljS2NzJVTQre9lwpmqB+khOdDe4OlMY6vphShHvyxHxc5LR9sWC0Re3
+pGCPU5PZbz3jQ7iRx1PJAkBx31CeCRqUO8wFHTfxYQjZniel34gYXnTCFKOt1JDy
+CANlvHx3Wd6sSI9I6QcHlnIXEaoZ9GUOm7h46gA0tllw
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta7_reqpass_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta7_reqpass_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,18 +1,18 @@
 -----BEGIN RSA PRIVATE KEY-----
 Proc-Type: 4,ENCRYPTED
-DEK-Info: DES-EDE3-CBC,7BD624221BDD7236
+DEK-Info: DES-EDE3-CBC,80D66828DA255C89
 
-gNvIPXGF51x/X0fkeOqJiLQ+q18lZ3RdASIO/pLyi9pe7XTUzzmG7ZJbvuP57h1u
-e+yYSOGINEHZ7jaLHj3oAg/veNnB5jsJ0XXHOAV/E2HgmW24GEcLZpk73MBx9tdE
-Wp9v9yVgapjivwSKd8g28Pp/+yaeLIaghMtN02+M35X7q0vAdOlo3XX4iRiiGu7q
-EJGK+1TvVe+h+w5/Yo6n3I5OE8epRaFPk818s5FsHPBr1hAXgxv0GU3B9efZRaP8
-TVno7YRYfA+wKJQLbHv2y8TpkjvrwtUgeCF4qMrzOvtFECof5kXuBEzEntbSgAO3
-cCmoj87iUl1DFRgdWz0dacJk0XOOZD/1I2VhBBE5PLBBLMyiNNR+z4Sij21KkLa3
-5vrVWfHM9H8w6fQoCa6uOwt2DyeX5uukhGzqxu+JD2xDQ3oZjlEFaNqdNzIcacKd
-W2+yor1knPVKYAiOB/eqRAuGZ1XSlCyf7FVC+6JyBeSvrCxfGoZLo2tY9eKbJHxK
-BOWT55a1cXvkU8TizCd/5el2SDM11uFyGEEJcUiZoLhZL2nPXQtwbvtNQFJB9i7O
-mIF+ypcvVMynxSBroDDE9n/TTdHosLHNiCYEGRkexdwHen4d4KKpOANEmIMfneR3
-nvosZ7smOJzujtxu002rgay1Ud/RBbv/wwThi53/xmRCDtESAjdLdQSYZ0JQS9zq
-l5mvWFV5JoWRp5d18Wv9N9KqXizrCg2OFH2wwkUajwKykruNj4aFcIPrDr/d40wF
-fq5D7MKIXO/H8KIzWc0usYOlonRqJhMIyV8eyLK4RkU=
+6tZvi4N6BO7V1fNvYwtpKndYFJxod+VDyiQdDaXZ4UBrpRkEWyiRlh9uzO+y9ZPO
+RCPv62oect9XF1NZ2DFISF3euSjyJNxpSM74oEgmAogL3doRILuK0J0evUmz5Uqn
+M6xSTEaSJf0sF3+spnmnE8A0USienptId2WI8GVsW2eN7VgkSUqTCOxfXvssYY+w
+t8XrdZGeIxg+rDeEQs2wgXo/TPLtrblRT3921mmkMYII1z+fnw65egCtWc9ZCrw1
+3Rl82+H0Xg9APX7R8zZ96IZ1ONm7zZrv0oPfqFUmglYUu6JGmytuXJ9r4lKZ1yLG
+CCef2F1+RqY6pIHnEcD1zEL4r6zL7PpTWMb5OQmgl2x+h4rcjWS4GXY71NeJP22A
+IKb0azXB+Dz5BbVAualDl1XWzyKHU8PV+Mc6oxywmUbzBvTGXnhCq1Rkue31aOUq
+5U5/AxaHPkWDKGJk4cF9jxe/Xu3xulu7apky1H95LHhsTFdVmAYbUQkipTtnTiF3
+ihahSjoqpOIP+2Sqo/1TjQHu3DTr8UhDmgkwAXpG1I7Oyviu7g+8JgMrpsntsQ8w
+Mrfjgif9usvAFmzN71klyl7yA1PtlZK+wwJJ4NURpqwYLOBh3x04FH5JeX2edYQQ
+u5pi+2XCF+JBChrzoQGwawid83+Iq3K/amBx2VqLwuQnHuBJh/QB/TbOlf81DSi1
+kImZ+iSGnsNDy/KUAhY8dIiEXrcNDp59Ap0wLdIbGXW0ib9B7DtIx2JQGh9Wnclt
+5Q6+vVXWtk4ES+nZuJaL354U0TjYQpr83dgKbIUoLdtWD5Wwsbs1VA==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta8_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta8_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDnp90up4nDzNqii707urxmas1lAGBwVYzwt4nD/JdCXMss9Qoc
-Vcd5t7koMPSapOAx5VLf9ECFSY78CKUFRO23bgALpy2hLEeVGNxe0MQkPUyny3aR
-+wCJKj9/q/Fet8skbkIZTdinEoPBjLb7AvCcH1HDxUntp24JuxEvpT8A1QIDAQAB
-AoGAU3u5SBD0ou12dVGqtpXLQ5WFw7ppBtKt4ioiqdCjqjTKu77rD98R7hl5zrQl
-0n1Mlm6weSkK/33M26M55TY7/Ek8rKGbeuyRkipuhvmtffo1cD4PuCNzfHaTF5Zq
-c12YEMrHhQVu125xiVO9HxWNZ9BeL3Ohyw0gmB0r7TmSYAECQQD6zBg9CSwzPQnu
-XfE4V5FM/Ywyme1BBIGe1yjszS4ShADVSUltWnO+a7P5xqgQDUzM0ynEC1Y20vLi
-FfYi2JTVAkEA7HYdW/aqmsc5arKdSR6Zv7vtqoItau1w24OWOe1jsp3C/VFZQ6Ez
-o8XwE9rwse8nMrE+himvqpPg6hA/lbK8AQJAUmAzHekjYXkNCARHNPBeQ2GMaRpx
-+UcXpCqbwJvsJBzDgUrfGVH6bnNF3CbKEOutbCF3uHLY0I0dRfFctTlaOQJABXHO
-yUBLu1ac/tTwBC/9MEn+de+bZhvjflpwShMqOYGibLzDxmfezYWQOpTO9/neuC8W
-lnY9Qjs3cYxAOo0sAQJBANGpCsweW3ExlJJGiV3J9M8RIh6cS2uGd3CE93pus5YX
-7bNV7W4OWpzebjnm5hiDRj4C+5Q+b5ZehzEuOb0zcWE=
+MIICXgIBAAKBgQDrdt1nF4YtgsFJjR79NBJ0cFu9kVBkT1NIZYXPDaaLVMqkT1j8
+XrjpzmF8jgQMBuhKZp9301ztLrDXxmEU1DOMXnEaGgrJ5ZAjfZzF+ELhE0Br4iCr
+BMGAtBsD3m21mQM0KLLbyjIArLg2Tdo8M4uJqkt4xZtkqnR9Zf+GEa3NFQIDAQAB
+AoGAMbXqkDU7MqiEPg75F+PCcaq285KWMlc88e/dDBWJr6i7D21hEAa/az0S/8TL
+ve5HZE2+JQIOgFR3KVbMcCVMrFIj14goIGoIsExNOa38DpMLDTlVyoTt1IGWoyhy
+P7dW2GBd7STRwIa9tiTSJ4BBWa8V+a1NTV80ekShLsPWgJECQQD6bj+F88Jf2vKt
+FrSxZK2y1YiGgqDWuqGbeDaYaRV7yFpGs/cyf1EMS6Gx4MsPREicuAFNjqSVYlVW
+2qtZqzoHAkEA8LNpDCPlgwXkawctkC35EtM8rjsEbkLK+fAN5qrZOGsJaWQcRWtj
+wejArBpe0RNWXBtVqOpJSYJ55L8aIFcpAwJBAMY9lc2M69aDdM1uBvXSM+o4PM32
+BCpXLOzsWZOGw/nr3QLRHaL8xATOrh4oS7Y3IJ/mzSk+/KxAXjvV+ASQlesCQQDM
+28WSQZL7Gq63sNpElfwg24wPtcclmM9sPbV3Fv3dmKvf+QZexvGWfeROFfuQ8mZT
+6ifTpeNOHzBjUYqI7+XFAkEA5SHVPcCq/6b1AfLWaZo8ziiRoretX7cj9rKu3VsN
+GEHIfRt5eGS04bOPG68qTuWJteiEVO4ThIhByp2zG6SO3w==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs1_ta9_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs1_ta9_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQCmUeECBIQWmqkXY1H28rnUVFONcYsvmPgOqPtB9HrTdJ01W1jj
-yEYThmePqp2wwJ4NF0r0SHZDPs40ttOQbXdCrdxQqheCpA4XZ9e3ohHOI5CyJBwT
-TfH7M+bx51QJrq3LJ+iuC/zZFM3Fk9uVHxPLFsCnRqNmU44k3yaF8XInAwIDAQAB
-AoGAKam/JMM+1268xugRYzwggujw2TDFPhIiqYF5F2eH0SqYKwKL/NtxenijvqBt
-yhYmQX9BPnpcbbHw89GMo9RYGEuHAiKj1fPzIi/RqcX7wbshlfUg81ympTyH58lU
-I6wBvFgR2On+nGQ2OgANhsg/YLqZjk6scY/ZcHcnP3Ec4akCQQDVZYXdk0GAWtYf
-svJyj0r4O8MDP+M2CXeegxW9qULDKnl+qwRvjFWprUXd+yuLUF3L0OhWzEKUB95c
-GtgmC0HPAkEAx4ZQJSqo9wXyGSmYVA2MnugS544aZLDktpoq5CLs90+a7D5ZUniN
-uoUW/sC6kuc67P8La3xhmnVh9oVIthSYjQJBAJLfvGJD/xpL6wKIVMy6iVwPLern
-pwfDPlyQVn9ipzvS2SpwpK3uBeuyAduGC3NojhZBJBjRn6VpQQddxpVwvAsCQQCc
-pLovM7rLlQNo9dr9wlVwPEr7N/lIrAgjxA2AZlscHodGifyeXr8GfI59GtpfkuIU
-Rne0v0Xxec6bODDJoonRAkEArSCKAs5Q8BhzOSczjK0VrXrjOj3iTgnCxsTs0aNi
-1Agm/bwby4V993eNI0xOC/FoPnIbyYWzk++vxrZzBDCEPw==
+MIICXgIBAAKBgQCg8lul4IV5Jzg0mOEMdKzAUiTGjLsboxLM75cu5+2JB0cU5gRw
+A85yeTr25J0xlwx73p+ZqNR96mkDEoeJINliDbzJKcuKW2ElhqKlblBtjVaszAVB
+T8m6lKQ0DZXZgpi8sGxOOeoJIXq6aX/7lPU3k7WowbwbjH4AM6iwkA+c3wIDAQAB
+AoGBAJK4XZP5+bNYbYSFWaNhOZqZR6043dlz78+jGs9H3uLsH4CNr73tumXg3j/0
+aNisOlUxvYz2u7+N0e1bFvOLXp7yORWeYxRtFYpJs77QyJakwMb1IUpSfngZGwcY
+bKMbGUGCT6GjhcmqrL3qwFwknSYM3c2fzecMP4RwiwKKSQsBAkEA0+NgcHnii28v
++fYALl3xbRbusZKT/Cd4YcCFjsn9oD686WspYt0PSt4nBgNIprhxVJJz82kCXZ8T
+htZYrjq7pQJBAMJ0C4Ubr/haNMOq05OOxJq7gqMeoDc2cCtnLWIw7y9KYdYDmFlI
+BHaIYezjGMnK66MUjucphas1gwZuTV6yXzMCQQCphyu68hoKu3wkPumoL2uhf46c
+ro0OWzoa4+E3/G6bTnbxPtcPDZVVrmaEjg4LrlimdMKmxqao50TFRiwPwlgtAkEA
+mmyqEWVxlBufN5zcNZz1yaQMFRrnRbG31uAzjH0sFjROCjYEsTKeSLv6eLPJJcg+
+5d4XtsCk5Ni0W1ERpJinPQJAccqsclJZH/SW9OcfTzksJLEKtJN0zbQEV3hKvT8R
+RdONQFEyzfV7nzWSYHKU0yVdiektN2P6JuijDkJZd8dAqw==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs2_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs2_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDFtvgzx83pbdmqd2AjhnFW3CKjzzbXs1n3Xa6C7T8XEmIJPj7s
-+qaS3wXOmqJtk7l+FvnFs4MdmpZqGzXf9riCVUVbQwpxZk+83wATJSLfeXa2mEIl
-sqFcR3J7lp9lPzcClykWnHUie10xU4AK68xzE9qOYfXK96/8U825EZU8PwIDAQAB
-AoGBAKhpgmIY/7ymZZJevPWFv2VNffQqvXxeuXOLyOqdS/BLKFbXPqJ9nwXcEwY5
-kcHk40wUJg3RKw48b4NSSkHL1r0rpmHCGYBtBvippTLAiRqdxwk/WxsMisy1Bx/9
-m3AFdyDpG8ljB8Tc0HLQ4Ry1TZDuwG3At77AW/6u90hDdGeBAkEA/3IJ9Ao5sjYJ
-IXn/f5Oxwizoajt8u0F+IV7+Y1TEv+cPKneEVTtK9gqLuP9i2ksSilydlPqpb1pS
-+Dj5RfixGwJBAMYk2O/uOsFY2b61ICrTEj4kIfFmSpKt5QvwBtPHvVQ1lJ//MGdI
-661vC0sFZnFuRXqqDdnxX++rJWHKWh+2d60CQQCz4FTb8Rthv6U8WpEtAA7LYh4j
-OFKD9gFgdGkD/1wwmf9W8yRPdFo72X88PTIZ74VVwxQAJWaMj/ke69e0iwQDAkBI
-u9PqVv+4Y54idChnr+09ZFQVYeAz8aNne2d2LBbip3x0Mt+YulrQ4jc6BbRyJPFa
-Mrw86W628pMZT4c/puJNAkB8TFaqmEoERQp0l8fcTtFePcfbwDC0ltLVk2FsPO5S
-9VwKivuPZrFSkCSopBLT73TdbQCsfAmc7uNVJTEMiGAB
+MIICWwIBAAKBgQCYlzCSkE1FWgzib/slnnJ/VmT1ZPWyW4Unt636JNdUAB1cTcKS
+gXbxN0kUt52M+5ZpLREyahnr6+sno74fACnIutbKl9/gg2hRnIH1Y+BpORr+Xq/D
+r7YjuKq0Zcf0fmPb/xt+zu1gfb4v/QXu0M1yfpGTaYIpj6ioU7HX6oPfiQIDAQAB
+AoGAAUOnbF9ztHJlju68lvg0HKf7mCjo/DxT4xtbfqoVeqWxmJUwWoRmFuONYHWR
+AZ0IBwEPlmpYoqLGxQJPTfRzZCoZoQnwbTPFakLBptPFBqmJ5j0mUaIFEw4Ha2mG
+78ksElPMzmPSdUn+35BGvTmvs2lEFuLcN8bCCOfUmTnPXu0CQQDIJQD7WHCsgImT
+aWT9LMVNknnlq4Omc+RkQ8XdEX18RffWT9XykvqLSsPGh4Nk1zcgI1snMP5bzVTL
+MGsT5FVvAkEAwyzFkmi5w8GUGDlKbV8L2GkI7aype30k4SS4V4RX10gWMbCydw/b
+IBr/PHriBxr1m/SDPn8SOhMd2dRf6p1OhwJAVI6No6Lxt292sDjO2ceYc/V2Wnnj
+3OcJjvKzHXrOMTq+QmToVtuRzld/7thBwtDKEWHemOgyDkbplA6YrobBMQJARDpc
+fsf5WINNQAKXEBDP1UEyi9N2E+M1hzcM8hsjkfBzQb+hQ5nZYinN29ihNxankXMy
+hiBpwL96CfIB7cQ79QJATK054vPDaB6CkdPEQrRcVS5YO442q300G2YQHppfFuOp
+FrRrdwgZAO0GuRC9EsfVY1woD0pjq7GNt+D0lSQZvw==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs2_ch1_ta4_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs2_ch1_ta4_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQC/rJ0XBvsPBiuP4XACKIED9R/0SkGHxUzhTFudiS+i1F4aS7aT
-xxBB2eng1UNknzkdyCqTUiMIknijXzuYUOhyOnMST5lLTQ7oXZLzC1149ltLyDYj
-48qriqpSM9EeYdE+kV3uOLzEDu5U+aoAo1FVlXrAew6y2FWd+K4fMqeH6wIDAQAB
-AoGAC0WNX2NLtFB6k1WAjr/vBlqN7IHJZMCXitBAuvzsTjkK56T4MayNKjI0bMJd
-2jb61uOEjXFRGhny+jiJeqWXZbYijxJd22+nW/5vgDV3zVBIloshwVS1Z2cEe21d
-6+o9Uum83S7Ogfqo2ecE9Aa8MlTtF+uu/dbK3qZsBYWMq7ECQQDwQYaMjRjTA28U
-WgLR5qbaZeGdmNeiZDMnMIPvA5bdbt4Uw1nVj63+oLJb8VPWU5u9t73LHY6j2RyR
-C1Gk/evHAkEAzDwX/Sx+Ga0spVIBCC0rpMy1PqehHXtz+gBaKzTM/IfDhYT/OElU
-sNzPIQ1c+q0mCkhVqpFBlDkwJfbEak/avQJAdjG2MJUFXmH1Fo0FkB+pfA3dBXv4
-sVIb/C6Y6U/Zu0vcg1hrbG3HylliBWtetDTjjFzFSRRcZOzdadmoq8OjZwJBAL7m
-ZN3m2q+RaSvWLNTBtAvEtJ0t/rEaFdvWvHGqVvisxhtlp1GraZgvrQQOA5zkf6wY
-1MosIAo2MkUqFYnxvlkCQA0ouzbLD+HVZDpREo+vwijUfyOJ03aV5U8mbL60GnnN
-qT8pTnPDSvYbVm6ds7Rz2MqIB9pQ44hlrL8fnySZfCE=
+MIICXwIBAAKBgQCtlDqx/T6+HjNzq0ji6pnYHU3EgOb+tm6GRcSGgd/FYz23m1B1
+vAmdzZVsbEeIbQwMJHq5UPA5EktrDC6jfYAnYVOLY8Auop6xTQtapP1vMiAdLOoY
+xOXtYk3sp6sHbos/winHMJB/airMCJuCSySheaIGplx6YIPFumgs/wEf0QIDAQAB
+AoGBAIy3MxIh9CBaCWoG/JKAj3GE6AuaWCk7qcQOgTBtzwOM3XagYYzggIc+J5l6
++k6d4Htjg14CQIxzyVIh0RlW33E25iPFU4dhjeSKvsEjgzv5LA95uR5jjhzwglhQ
+7iMx+0ak3yyzq0EGUc5ni7wuRAc59oPsZlj5uRb5oFNpnjVxAkEA4C9BG4R/nKVM
+eWsDBejqrZGBm2bWX2Rr51gmPyVI47ElTgQvDGfdLQnO/pgUbp+XeGOTTKgUVQqq
+VCBK7vEdDQJBAMY2cp2BBdKbq2UPfYH3GAJI9WK0Diz0OeOyk972fG1+4c1ma0qx
+Mfm73pqhEjvKDmxl6000TEtsYgenh4E+xNUCQQDZEchH/b6WjZODyXMu6L06/LXz
+I9sUmKbGZZr6734pQeBuLyzjJTqKnoG4EMdP6eV/Y2NACUtOoLoWJQKJZBuNAkEA
+i35CB0qH+IIJiyPtpgtpYCJMX1xsJYLzQqWon19EjiKfcthDZdtyWli2/oegt2cp
+42uOv1Sw5Nuv2ccy++hayQJBALjUzaDQcH5YHPVIgaMdch402gtOVeaTa/w0Y7LO
+aSZ5V4Ge4nhajNMIbvke3UjBLWc99Tt6deHXOxG9Nxm+Ook=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs2_ch5_ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs2_ch5_ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDNyavuoYkBYIkAfJMf/kxUdVhSgbDLvkynpyMYhg6f4UGZ3f/n
-82YdQd2qnvcjLcQOJBbiTVSLOHJVtBEm+fwE/t6bgwIBmDaOQULyC6cHAPkOZpag
-5PMyBiadQfuRv36owMdi4cnON94Htd9Vh5qlO9TFtiRLKuSIUIXp2RMSRwIDAQAB
-AoGBAJU9NFsS+vDsuW6I6YnCOkjl8O+k7jpT//N12pXmYqTAD3su7G+irON66O7b
-6g6xGgXHVnE386Ajh4dv1yCVGpaXyi6O6EJZBbyzRi6UDrIHadcq/E/SLGyFmkAT
-wa6jpHA+RPLSf7q9FFCfzYsgraSmlRNl1ZHCKgaySVe7Ex6BAkEA7QK1jnRPuepU
-nFTsvu/qkbkQkdZDImO9R8lr1IUrwBaQRBQs/04TIrIGp5y1lo9EZ229eIH76ZDZ
-P0+ZYt4+/wJBAN5Gjk22wNBWBNpjsMmQFNxgiEwt4wv2qh8m01QzuYVxuhrFTXVH
-Tf66FeOnWrR0iH5BZ1NYq5ltJUi2XjoUdLkCQQDhRYjxjKXWrN6c9K9NUFYhCcix
-BPksb6aR2+XMyoLqAcg/nPmj9D6F5LYki/Og1i2LLShAqTOaLZ3/6hV9foZbAkEA
-mDR+S28CV2cfyaAMNenorwOXMXsWh2GwGsbOXVFSD7PRuXUz1kQuf2hThuFZdkp6
-EOKea29Dijs4FbNzkJfjWQJAOrDi5DycnrN+YB5LE/u19fCOdPJIJZ2igpBZeBoM
-LwiKycV71vjX3g9j6ODBmIspSnBREkORaIj1CKpL6iBT0w==
+MIICXgIBAAKBgQDMUaOGSKaBEQG6vkBt3Pe2CviaEXHqCUI67e5OD4cQmW/I70G9
+9tAXp9t7/lHd3jryO9fefZZxTn9O0M/dO9hrzsqDOn1uZc21+0symuYg+O2OTJn0
+At7F1DtuNag8tJ8/XjuFM0pNszWj0HZ4dNJymZ7BaR/RjyoR6zUye7qPmQIDAQAB
+AoGBAKZ2NPYopo8s3e3ZJwDbMG3+TkCnydlVJcKBKtAqUm4xtCNO2o78UNmVBnrk
+3qoWbowAOYWpaDJ0M8Bw24lxQoZMUf7fJ9ofJ6QPC7MLIxltaixlllOPREVfM4Si
+XDt2VUZAarHh9/fiCkkEcys8PYs280TdyCFnB+A3YOkhK1aJAkEA/Z2KttBipSxo
+Al+EE54WS9x5846bWGL3zQw0kTuq1HY4VuDWymLkZIuSwFbq51PLARiN0A0Kp+LK
+Te7fQGf/+wJBAM49cGkthicDk85xLkBK7OFZLkcjVS/jS/u7F6swmbn0K2lGA+6E
+4lc8dVA8KxXMygmWPrdcSnXQbTKUwHrZFnsCQGmuNTg6m3BykaCzhojaLjZMWDDq
+cscg7ltuQ5VlRKkl3hItvLM3BC71jiBB176vRv9c6PMSDCerNFvHNxZSf/MCQQCa
+cQ3d5XZhft9PqBffk3wiILt0EDR5wPekke1eh+2GgB+GHSVSl3Y7p42eQQBuucXO
+OhHLE7S61xL+3r/o/upDAkEA7/noNEwFbhk5ctzIPRr4PS7KrqR/x/ikHZ9YoDZc
+0J1o9lwIC3ye8J40Q/6gHw1owEmpuIFGreUcMgmTlwdg0A==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs3_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs3_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQC3YHsIRwoFwWyAmoTi3sYRZd+mxzC7N+munjed+fM6GDjuvuD7
-a4T7kyxbHp96eNomKMf7bp8uj/laHOgL4PFcRfagDlgBToYgvf99DEFLslBceIk8
-SoPPWZ/kFyfe6qr/yBn1t8NnvV54eY5GMxrvNkD48n68ylSFV1bl57hSTQIDAQAB
-AoGAAV79TICLeKOLliKRn8ienn6uf2a53Ix8eMvCCrJVuTd5JX/T2s1g/yiIil3e
-P2Ir72EarayUEBsPeDcDHSOfalfwRdkUDD5pZWO0ll5VdiYuQF0C/FaQFbbY8jb8
-DXFtrL48doq7DeylZTzpHDeKUlMpckItVsSBPnL52Q4YIRkCQQD0Bjd6bs4jIQkZ
-Mtvvm78dZy696+yngy34363ewCQDZPSEPN7pMQf3Dxdag5e6jum5eHLb8Lk29ewQ
-9CF3N3dvAkEAwGBS+VILOSqulBfSySTGPO4ecMRP32K0vnJVmnxnlTAC89I7zLFg
-+d2LzVuYMCrqlwZ5vv5ekDqS5AKe2nbUAwJBAMicy8M1kPZEVGyI6VME4YtUppKw
-gC/+oi62BQTZRUIdHwAP4tom2vt7RqG9CWHv16oIobS7JClQ56/QZCrUSLUCQQCG
-JaU2fmOdJYo/cq1l3eLusg1ADWS1HRt0gj33UDDa83PbmgphHn/FPRwzw19Il2Sm
-k7lp2e8PHAk6PimPpbUJAkEAonNbmJmyGdLyxj6gKb9vt37vMXmU0B/tQjHXGmT2
-OmBb/wT01cYRsOWqaPpb4d7yQWmSgZhXROZRzXwPQXBcCA==
+MIICXAIBAAKBgQDTAb5o5gdr1PEQnpmTy3lNFdE5+7LedBBXhMOrPiXM9H5mHvL6
+8jK0xWyA5zGAGpZ5loO1RFjxKps7wA1CACdJv24K1ou0IFynPRF0JZUIRbvFygdC
+o+gZNuFiQlO8Lx+oEDHuQH3stVQExGPoQxIJfR6ZYPbb7GXTE7s2vuLY7QIDAQAB
+AoGBAJcznrAodZTtqDiSjdZ8bdWxFpaIKGqDnNo6BsSE6i1t3c1rzA3K1E75UYEl
+KjFz2/QQyRxxd5KJR2ePfXCYD43Z9uzOvONUIqRPNL7vebVj3+40LBlhZPHuM/0+
+h/hPPTzUGUQ7ttulvsB1JIH89Tt0przV6+jmG2QNMY7l/rTBAkEA7U1v+A61xNpG
+fjo+iTkFmk1rhrCPZqUXKllFR5VkN9Gip87wKZ1TxAAD90em3gg44PyGimlb3BR0
+P+0Gdk3NeQJBAOOh51Gb00bAT+yBVIdj+bMARTLwlFsAdpb11pn3iH8/6broHALd
+jFja/vWTLxTduSM5XS2dkOLXnHduZjsvbhUCQG3k5KuNtGPbabXfJ0LJI20X2Wng
+rigs4BN+j/TcnDK1ZIwt6056S2aDU1La3c4JJL4cc/n5XM8IseVA0TNMSJECQBNQ
+tKknGMljHiUKYFrQr+pxdm25Hk2Of4GVwKz15R4vFS0n7uCLXhJYGtRJtfAGVGRZ
+xL9PJHErLHqx4njZMHUCQAt2UfaQSl//9Vjq+cF6n9oH4XWXV1jmDTkumc7j88Aj
+KJt47QGxDG3+U3zzuhDbX5VOUPjZvhTf8JGv2777HTQ=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs3_ch1_ta4_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs3_ch1_ta4_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDDDHXK96eUCEpy9CeImJ/XzHtB5FSGEdHC2KHOaLCPam54v/kI
-yaNEmSck2sJ26Fl2vrIERhz0Gnd2c8vdU7afx14ECjVD4V1dYptzEwbTlo9kTjQN
-vzEzPAUkJtdxpoNlH88BJcGHSTW5EqGcr0xP2iZZ5BPuwXJSGvVJhJIYOwIDAQAB
-AoGAb8picPREjem6kewyBG5Fnu/J7VgqwbTQ3rY+9wi1uV0s9/Q/jbPT6etFri/b
-qT8+l3pwmVZ+HcJVmgSAYdgrIKLDXgPwqb2r9PMYxxBUejme6kVnnqBa0930O2JV
-YEJ4mFAM0PZHN3sTI6cRQtmkgIZKVoLd9BpgUBzQOsy8R5ECQQD7K3zct7bMpwcS
-P6lWUJVZuKcSIShG6ETIJrEPHoVLfQJZaRRNUwWnwbGIdVzfXlC/cNBgtyGQ91Z4
-GRKeikV3AkEAxsyv4kxflDr844E+jyWyx8GSQSwnbfFdnry0SPAfuyg5y+I3r0dx
-MKB897eja4CbtAJCa5nR6sGL16LmSwcEXQJBAL/XyoonhGcyWJNWrrev2zNpd6rA
-SqxGMmsSKoEa1cL/27CBMzGQbSxiJIDO673sow5mU7LbjbbVRGV8+RzBDicCQQCr
-P0sLPwreX2nUeFLxcGHu3PollelpNY+V26vZYK+UwvP2gynAnWQNpVHA+bmWMzTs
-/T1F/zzqYksaN8L1QlgpAkA7i4L/XULip10VMWcxH+L0ACOlI+ZSUbLUda88eIQO
-ZPnvLqJXE3cyvanTWDTVEFOkLpFI38413VX5L2tSNJN9
+MIICXAIBAAKBgQDWC2UlSqvGl2DwChMCElgKJiZ/uhCCpGguWdyeY3FMA4VVe8Ag
+yDvzEiSM5U3UQRBfXb62dndB5VdIxwFCvhig9zn6PzAH6W8FFgBDmF76YkY2ebFq
+hCIVNhYrI+VvL8bKrtxylXpIm5uucr3w/9IL/oLsUzgjzW1lKLpTXHRvXwIDAQAB
+AoGAEJg3kkmUwcPQvyt4x8tWSgslJvfs+cP3U8ihwyHgkc0gFD2Q6rm7dB/u94F7
+pD4bH9mrxIewvUojlz/eiCcmz4enlCf0nRY7ylgqA6RO9xSJ8NvkLEhijpJ2IYL0
+hIeJi+zgPAq+YPK6UX6PdcVMJmqlcS3e6Tu+1fei4qTs/nECQQDz0YUZGHfF7AVh
+/kynstN7XerdXdNdFJqjbpzXlQNTXrhB3PF2dPNrxNoN76hjRBa6IG4E4zEOEpxe
+0VOaAEfHAkEA4L0Pv+zixpw2RWWvE5u1D0OFNTB21BQhsehM5UcgVTkXSq28Ur5o
+bZilFuot+IJIj9D+aorNocaevq6XElSLqQJADWxDf5YxQdw0j6iIX9MggXIyM+2u
+bTltKgI08Elr3XMhgb7ALF1T6WL0/j9rbcuZ1LVkWTCIytWLdkzf5WKOkQJAJm1t
+cf3JUPiI9xjJ9Opc7T04W73rs5u1nzv/WfztdGUMrIJEf0l7hbHiGKb2MVXlnmG3
+/vO48X6KykQEJOg78QJBANmC1XrEY0vj/bexDOYC7h4nYIMAB3y76/o5dTl8xX5c
+axsm5B311vJGDgH3ct3pALIf4KZhIqZkZNpk6QuTa14=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs4_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs4_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDXQkWm0PSpVG3ITULoBaQzJfG36yDfMyZuyjBjV9/TqQKwKfPL
-e2R3NH4dx6gsynMjIkNxbDOeiQ6Jzm3bK/Nar+Pc8xxIZGBdV+YXa+ZhS8vgqeMc
-qvZwNLSL2BnmJgZgJILG2F2H3pkrDXjbkvLCJGWL+Ae2/heNu0/HwK4kyQIDAQAB
-AoGBAKXdsBPpYQz1PJ6iQhLM/ghXjZk9eZfjLxMhgwWZmaPb0HFz8iJyEyjzbtZ9
-mS3iVbPV3AgS6veW/nfbc7T1ec6WI9ddCuP1EhzbCu7KNJ3GfcS+EylHFYVsV2Ky
-RsOJILsk92pfMy9KTOnuqJCSZxPb/39lZ/gz3uKu6YR0MHKNAkEA9ZqCT1NbT9oK
-X2morprP50aKvjS2FQLDdIZtcRSS6+wYOv56MbftPuCUldQur7CvWUYYvUq9vr58
-KCQYUJg1YwJBAOBe7pYBQy3fExhndMqmqQP7OoQmNEktPEBI+KHJwWVX5e6k6g2N
-k90qknwnC0ujk7p2hS+O64fLXFbrcvDmWuMCQDffT3e2UdaHlsZ/5eTaySMm9Bcz
-LJz5BPf0QN9xu7659gUtsSSwX+Nm+cZf/8LuIeXgQW6Gm0XSVbJYC8QB7FsCQQDa
-q6rbh19x1XdG0Y2B8+vFdZQSNym+J9gQzw2CoJ9bpc7yRsfVbaYuZs9dMLBRh5ry
-n5AuSZxDPG9CRzY+kkMBAkEAl+F+hF5cNS0QPoM+AKSOlmexMQmWa0R7+cxGYeZn
-kQBcY6tJuqjb2Q1OyiEwoZTDnLV8Hr2GbuNavry8SQQ7tQ==
+MIICXAIBAAKBgQDLLFp0WadgoaQbNiWSwao5P3wX3tA2wxy/xiUw4BB713Z93tZx
+bIHflSKk3YBVKl79gt+UoKr5jrHpIL4EJhgX6ASer2fKV472kixudgJLhNgreCsy
+dI5M6qs8YWLLla9cd3QZsg5PSWOKcqzBd2pC7ZFvvqTfyAsbtDIYRty59QIDAQAB
+AoGAKE+dhtY+8lo/4DJHFC4eowsoiOfpceQWcSpUOLVML/YZCXJMI+b+gajqXcGg
+88TbYfs0dx3FrowUWofni5UvVDxxvPebTPTcE2gdbDaEjR9VxSe1rOvRwAz2j8l6
+KfNzrQoviXEzxQYAAjnB+j9MZhK51OBXU2IEPwS3rEIpz4UCQQDkJsiWUDER104g
+bsVjvVElhnLgv8mF7zt4kz+cz9QQZrDqDfnqgTDMFiVypAEJTFVWzbr90XBNO35k
+jqvAe+NTAkEA4/kOcAcwDsm02AWr/H/Z/Psf50bHOg05R5hvbbt50mN0m0R3I6V8
+9LU+OEczf+vu+/ssoO2B66ESaiTpK99MlwJAOiXEU8MGbpSgPdXdiwkSKG021B8t
+Pmx1jMqCmPXDB5cUmeKMAn+Ar1Mpoik4dmU1DtWKRexeIeD62qgeEAXDLwJALLzK
+bYerkatZtu7eAm4gnDm32A4WuLixnfA3JcSdsoDb+EBmVPN74xXSQP8QBzGIs6Bl
+8KrLTS9NytC1hWuLvwJBANYdvObtm1sw1iXE8RIyRlBy8eUEtVHz2OgIDplQ37Os
+7lO/bq/Aur7WHgVG4M/rIn02G9HN75o6kgJ69k1g+0A=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs5_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs5_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDAvmbmVcue1tJ707I0+8l01TBPYhxovROXCLeMtk7df5il4i8u
-nHSSAUNijpxiIz625OIYKz+u+xfn2MQoJyfZPlzRj1G3EExE9rtrJHwuCbz7iq/6
-5M6ULyfNPee+k0tiN/XxqI5+dpJiewJBmML2/2iO0h37nvFF9WqcjSgjwQIDAQAB
-AoGAOnqKZeAqA2tSOVelfgXWvafhHHS8Ads8ElsGtZ6qlvGbstjJT+8QPyw68bAr
-KmtfH8aaApM8oy5ztlhCS5x1riC4PxUshCVhMX7/AsyN8GXyzTfE4gOuQmbOTRQi
-p6w+3uMo7Hdpl4iotuOu23SDiwPCWbGZ/s8c9t59WiCjRAECQQDypSwxLWoseJcc
-n7eKOQhpLtv+yqdCRKGOVS/xVtCpfwM/xNJy25pzcyr8iMklJn1+ZSsBeZk1mS56
-vS6y3mzRAkEAy1oge5qtyTx+UPXuDyeiaPJm4/und7A8aYEKwQITDtg6Ef7C0Rho
-fUYNd0svLVQS0xWnOjfsQlzN19XzXPlD8QJBANMAK0PAeFmfq9hqU1LRcaz14Lza
-QURxJgP9tCksE1uxZYPohhD3QoIunizoTfIOXIazNwibU022nSKCrL9CiGECQQDE
-uKPD75c/ni301HVAY+9R525yDvmrZ+qJhjSJEyCss7E5x2NgNGShDCvqw+kXyMWN
-Pt1QDNmaOX1I18leoCWBAkEAzfJZUAiRWIpkI6pnAXGbLSQRuC8VrxvMTY70Q6El
-0SrhKr9MgBSDiKLWpIYoA9E6InOyzr0wQEXiCSXbpirqcQ==
+MIICXwIBAAKBgQDqI5URLLUtScUQd3SCmNpfWB8rQG4bLthPMAdroq6f9+2NLbSz
+aEjsYHKi+4t+YhGQeZb57oJ4PwkiKwNFr57KfjyAT61Zd4XF52tKC6JrS8Xn+TiB
+ZAXqzXacv+tRqilswT6YxqxJoqwyYHjY/8Z5+KWmeGEkmicmLgY6GY5U0QIDAQAB
+AoGBAK5XJmUudA2v02PKft/Lrza1aCgNhq8I95onOi9EaGDG/IRWFypLqZkQy+te
+AGVv4oJAd1HM7itZTJS7kGkwNrxF+5vlCN93d8KdoGIjOElp9H3wB7o8Y3Px/VKD
+CfuG/HkO2zOEd2Jnjzhu003ytXwSltfLoLda7+bUZmxj2dfBAkEA+63F5SoF6zpH
+J2efJU2ZAcA0K4SWgXghQLczhaRLlB61PZDuWgJszCAppPn8K8NCpRmGWRp3ian3
+6eOHa9pK6QJBAO4otwYVqUFq3E4rsiQsn4m5nWPMUhAYmabC4ZsdvW3VdYnw1WrR
+RB8uEqhZWCa6t6i6LZzIvuRlGk8KaPh9OakCQQDMJeDoSnYSoGsnI36MG62JJgcr
+ZZlP28ndXL2GIgbMVzxcfDta96yYx14AXGaYeQKOOW4oyLc+C4j1R4KJkcBBAkEA
+5cO8B4/AUg+BaZ04aTPv2tSLZqvJhCPnoP4k4BzKE3u7wQ/rJfmsqhQuBeLka8D5
+zTuJI9h8aiasQhM+AHX3uQJBAOz4mqlT8ZHscyIg6SMyF3sKxNFxg9Qeuf11hsME
+U21JzVHzJsJ4qUewsvSPrvCfUwARl3LJAVh29Dqpjr0mjMk=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs6_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs6_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDHdzL2NVop3txhial+00+sodvxf1gc00ao62FigNDPQGukOaz7
-8+SiR1N41M1aX7HA6CyBLQCY1S9r6eeF5g4eRtYiufOn4GwY6kIzzcCc4JjsKWc5
-xKP3aYsEZvWiPAgbJOW61FdbFPHyyCsPIq5u0cqFAeZ1ggPfeu2WimQvXwIDAQAB
-AoGAKoihhlz0IA+U4Puw+AlpaP+O3h1wlZz76VNgDdg4LqmnCnr+BzAH5g7dntuJ
-+qaDSgZ4TwdgpDZ5iUJ0i1n2UmAa5UcZ+OUQSkTZvXR4lG3L6dzFB3pX1SxPNWF1
-D2A/c6cxdeFud0+RfD8y1XiOfRPp/W0wL1xPgdqD81INOVkCQQDiy8AALoAUWetu
-L2jaxy2kkOHkHBcSD/OOa1Q4Qtf5lCfRM+C/YCmVfraayja4vALuQ/n82xjoL7pQ
-ndT+cdm1AkEA4SaEB1Nl6g4MyKA993Y0AQ7hD120tPjimvvmUcnWdDotDgcWDvNn
-+emcs+z4FEpuCwAib8GeuKk422+dYtSBQwJBAKvnelno5SYH3j6/ar/hl0QUmVP4
-wrfrJVY/HjAi4meHmAKnSuRkNEDfMfPz8DRoNeR52+OAAsoDWzq913Mhwr0CQATC
-FJ43A/tbSqfewxB8vgKbtuPlPhFpBRjzY92sn0ybgiI+wheUy0i7yCUBSAjdvc+b
-tB6af+k1Ik9432GcThMCQFrYEoUHWhaD3SkSiuA7NRfwAKNSv2Us4nfwIXkzVW2i
-/3091BWmOmlM/lsIQe5rIG3d/mYEDnNh6FuquX05Ngc=
+MIICXAIBAAKBgQClLta9/C9bTLiRkI72P7tVKI1PnUdw7T6hvXBCR7BBCXuHT+sa
+RZ8JbQqMU3OjPfs/3Gf0A9N8URXzq2wsOdCnTsI/XNLYh/EDO+t1np5m1T3V5W0y
+kq0FuMI7SOVytJ3Jt0JP17SljKSIdt8RPrFcor19VvjIdgDEiGQPNn7LIwIDAQAB
+AoGAZddpAp13PR0iNm0gF2bXwvtLlKhtoYxEL0gy7EpyusZz6Ms3Mm12TkNyW24g
+P6c5PvhPBz1MqLr9g8xO1z2WDHN1quHV6C6GvvOlQcXIMT5XcAdfllt5HvrnzZE0
+AYoSM9ySyfoRY0BdFIBGFci8ehDcgMHEqpKAOhBLAxgVn5ECQQDS6cqVz/Idtjuc
+ESCVg3STIJJDpeC5PAUOxgiGoHLTEpiPXOa7L0ObavYv0Rz+rvn1lT7sinIekpRZ
+UdDTBKynAkEAyH52OZ53b6wkLHqDzI/FHpEXSiVOGsdEOkgsQ8YXRZx9J2XYIfYJ
+F5Q+CtLd9/IMBV8tO0wPG7fBNF+us2dRJQJAMsvr5rj2bwF8ydG2L0xBv02Q7In+
+3Z3++dfoJcRu4zcPVzfguiRf/AZ+1HVgrlYmDWesh/uwEHztDbYOvUPa8QJBAIbQ
+oma0K9OniNtvtlhDBGU9Ys+0rgRLoZEfHsSj2towE+f+D4smiY6VW/KjQCaNV4/1
+I9EPn8kfkobJIAv6mRECQCEqTVrHa/HRzgezDFL2UhjzHC+8Kb4J64Ua6e9mCI5j
+cFnAoT+Sok+93YpShXRL2bEMiQP5/VyefI9otSoo23E=
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs7_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs7_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDIlwZyd4LnA1NW93Fc9LWu4SII96dwRy+tb6+pOcNzyvXVVOk9
-RvikoRon1RrGkMlLwSEyBptW1yM8I9mqKhcVYQzMCOdgr1XmnuIkvR/pBOgJ7fSj
-2F4kkZU+n373ZGZgCH3PrLb0a3IoYYzcUU0APk1ncA6uPDeZKEfnYf6jcwIDAQAB
-AoGAFcI0I9SM8YwtzSA4PtIYpyiqrXhXxFkkddbIoj2u0u+wLPzx9ACv1gPXt3xp
-VCK+gyYm+Ks4zHm3y71Dzi6UpD6KGJ46zxX0JeYjewvoZF9CKUtfz9tuazxVJEqA
-9Hg1SlLdwlrZRfV2K0RlIJJRMcTD+67ubBU/STW3LtfzOukCQQD/DmcxQ+fw0CxU
-ypSSBIELL2/x6Hy/gbSvqjVnod58/fvHBWKj9zlaH7DN6tigI7eoL3BIb+V98wcS
-hhnMFMVvAkEAyVUHq8MdGwaB2bBix+r2MbwJ4vG2aTDk4+KWSOyCxP1+JEx8IwOe
-KR7foJUfsT3g6b4pLTvvLbUo3JgL6lHoPQJAMxRqXDZyTAsU5cJQcNHQGjJc5ACg
-gyXxzsByw5dqXHPtKZWNhLLtXHw+R28CBUhB7r/ZZ9hpCIlUYERVBEcgpwJBAKXF
-95z7+Nkp0H03+P33f2OQGuvcbn/KnIzvIyNEaqBcwSKOP6Bs+CuPmj6UyxWbh7eu
-tiTitpuCEPUh1J3Jd1kCQQDspev2/mMg5KNQFs8vrPoSZ5V/QKXmfss0QbXnqLW7
-cn8ZfkjzTN24/usQRbJ60ZiVXtojEubNxtECfjd5eZqt
+MIICXQIBAAKBgQC8UpPMa21ju/6iMz1ApLo/EkxyaaCHgDJQR5GPOW+KeHia9jSD
+LX1qGZA2n/t8HMgT+ROyanUaLDp2KxDS85AfZd9lBAyXovpDUzMy+I/zMKccSmec
+2oG4elXEMB1ZXfEKvLZSswlBJB8wa+2VupDPDa/rx/sxNcVb/2eaihs0CQIDAQAB
+AoGAZsQdOTkKSZmGG5cgfs0lgVOH+gtf+XFgg2R6rxClqIeTMOTXxRmmzaZDhzuI
+LbM7D4MlV4A2hODLyj44ARW+eCQnoJz8SJ510/fK6ZFGv+tOItHsoZOBlt7bXxI6
+f/yUxkgfxQde0VyJmNdLyIMJfn4W6dZsteyoz3EjaOa5Xc0CQQDdHJF8dsB+W3pN
+6e5mDegT+j0TI6mp1S8vxpFRznALbSWcVn0YEIIP9eVG8Ta8fMERz6m6ZgUhpCzQ
+OlivIwyzAkEA2gmNI2gSzwwo9xefd1rB8oF2p7QqggwwaVELVEPFi31EeZKgziH3
+J2Gnn1vKrqox4NYhL+q16jv/k0HUaYCSUwJBAKiJeBOo6LznuWfeIctEWluv6BHI
+ozBCwP7nmikC88Ch54MtIZjQLHNB+QuEHTa62OdcpIDh9pNX8pidgK+uRaUCQEDj
+ds2Cu5ZC2C4xKZQrvmydeuKOC9iIKCAvrl91i+Tncul7ab/u+88MkQYsGzXAEPgI
+wfewslLzaCw6+ywqx2ECQQDYBn+1Q+zJDscYg8exhL5lqCVuVZ5PzoRWvUXxKUo2
+3PGtaCSeKk8Dh0aWAkxqjhCJ14HSIiBKx3xhwLeGvp9A
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/cs8_ch1_ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/cs8_ch1_ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,15 @@
 -----BEGIN RSA PRIVATE KEY-----
-MIICWwIBAAKBgQDE2sTTcsJl7H+4QePHFIO7/J7VhxVf61Lay/TH2y9YZQEODtUn
-z8XlLM6Zfw9IjE9UR2tLXpA/lZZguI45H6nMOLafIW1OaS4UxXH+4eFEJNR0RUqf
-iGQ2lve6dB6I+W2s6SXwdFjGE7kFq/oOXHf8oT1InHiQ+GdBmXy/RWpn7wIDAQAB
-AoGAV3lnMRazr5rx/iy5TMOe7jAJXJUUOHVXcgZjlVOerEbluxt4OKKpK3dHrwm4
-/uHqdmbuFKXGr5qHIh+gg13Ak0kObYXDRtuk52e04MrNB5LY7oudDPLQU7aj7vh5
-MrBgc1Y6OqB0xfg+BDaR6WrLCPpf7dhiSYezGid6SzMGNfECQQDzad0Se1eKCgcw
-yNqoFQADalW+Khyovg061Eak0LYE3LcmSor7BQSje1g/7PItCUhBHrRq9ymDZozA
-6aZH6jtrAkEAzwiXMZc45gjmAAJTnCYV0pxxJ5yhL1De151LKI/0T4V7Y9Wayq5C
-i8Fx0Q3dv4qpJXFm60RzaZHFMQEP6CCKjQJAQcQpmfO/XCmHddPe2CkMXt/dGMsy
-ARmQY4O1LpTBiSDFT1A2qsnZTf5mgqcXa7mlTwrnvjrXeYw8nWbDqYyMzwJAQyec
-M1/D+wnj4RjgGgRYi8pnAdxShFCNGA9Tc8LOEoVPsuB0p03DFCYZTyBaT2kg2J5i
-Leo0LYg1GGIp0LfNeQJAKdPxQ1qY+jDe2y3a7FS/mR6DQvwGtqZLsdZ/akjPVIpr
-wQVD0Wa9QjW47ZvfD225x+xni870aXIivRJBJdDHIQ==
+MIICXgIBAAKBgQDeUGfWjqdTG3MD/sfvWYIM13TvrSEzaHhGJ3/xDHZnjb66+DYA
+xxvrgh9wWHEC22qeETeosCgntJ++HSr7Z0+hOs7icNLYgeuSWsY/l+wsSbVbiuHq
+YDUoaug3tnoegzYyUj/ApbJ0GbEyNGba+PzhkkKypodIVjdm4zxvWHMmoQIDAQAB
+AoGBAKLU/dl3TzNeDZZFjSfQxaKmRS4v/vtqb33i/KEP4cHjXmoP124maFrNSj29
+abkQAT2ZmszhiefbMo3LS2ost3MgiEMUaUDSKGPVypf3FaAG+j05b4h2jK8SfV7S
+p0Ghg+MpVvSV7qDv2ZlJMkZPFd3peVSffSMQbAvd2B+VvFmBAkEA+enzaXEOwly8
+ZswY3uqiZRB5sxhyft3ksjd+E9mM7J914lPWRmZeMGD0Q6lMRqcliyDGCJ2DhOGm
+uw26b73dqQJBAOO6Y2IQfoXFxwpqpjJIfANfPcmYzIFvTCxqnqZLxU38hS37elnR
+p3BS2WAAjfmH72DqBagh91iQ6iPJu4tN7DkCQQC107NXqfw1CUfB+wi1Vz0kDuKc
+nVLgXwz/ZUSDqKrRlgssyhaCTgSFamUNvWVTmlTEbunmZsPDsHGgcpKMrjVRAkEA
+tTw4LepMlzAAqTSZUflH4PMiXFejofsul0a/Pj+dJeSrJR43kFX/OLBm2TV3yDg7
+9Vgp6lYl4LFr9dFt1X7NWQJAB06/850+DD2XYSioGiELKFoFMFjYxvp/BdwM1bB/
+10BSg1Ra0DyPihv7S4e76oOUrHiFX4KRNKHvsedVPfYnRw==
 -----END RSA PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta10_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta10_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQC2UENzZBJAJlQM+Wfkau0fGOVziRMPyV9ubsYFrSy+5Gv9xk/q
-828N9Bo0fwOXsKTRbpjSNvozXVE33o9bPaAHUsi3cTBx+8On+mH2tCi+ntqLi3Dd
-jtClGgBwHDnhz2T47LSDuStn+k2uMIQvLJ1sd34JlUN3a+GdK8mJ2anljwIDAQAB
-AoGASKdByglWMJRVqHn3yhJGfr8IKXu1yfPBARxJ89coXsZettpB3Oq4FgJyMvtu
-7hNqC0AczKE2IiQNCsu5q22qiLNfwhlDoqckECZ48CuVpg31ZEuiX6o75duvEjNl
-RIo9Cwp7Vo22Uq/6R9rAJP09B84NdMSMTMij6BDIxiSInSECQQDxAwG9wyfI01eP
-ZzK71lB79RO0T6t9NPF2z8Ed0VbA2OKBAufh4LNqxvxc5ZyUNaqEU10MA8NT+PMk
-srew7FyxAkEAwabClJ8nVdY33ko5cUBoZWsgVlWEFhoRmp00AMGa7mGIvyAExXkQ
-qF/o2uH73ZQA7Vx/4MLF7wcNqyNCrH32PwJACt3y1yaUhaaZ3RpvHC8Wo/Ax+kBZ
-YCTh+lR1xa1ptvpQhDaoU/P4wwjD2kB0Je6hiKPlnyQQS5n/BJmWVMDjkQJATLat
-Goc54+0q0KqCuvSS5qpbcxgJbWACXUetVCdeItUMgPpEKZ5eFPV5n0wqpIp/G4ir
-N/SwyJH4vjUHsqFrrQJBAJsIRffGRMmMEC60E+KJTqWs18j2/igGt8W4KsRbzeSQ
-Ncw9f3QXgfNIXnmyW/L3i+8XxHzLlD+oT78Csuu8xCY=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAKsI3kThfc+H5Q35
+tmZ5RUsYP8TDvDxOEBwjNgsXjlPpHVLA03jOdDAT2T6YjgiU/naUVXrZc4cBXt3H
+e15WlKZd5oqrIgPP4XocfvsWwnz0o2xGKAsVFemST1Cj4wQlkW3QcS9msyBk2/Fg
+jT9SlBPx8QCTCyC+85h9yFjj8OnFAgMBAAECgYB+XRr7AS6Wuex9mtUseMS9arkS
+gxr74yD76Pfw0gKR9FV54oVbaA1nyAJlwQiPRqWKrqVJEofMYzLX4J5BYO6JlulN
+i9YHRLyM9GBKqoKIFt0ZCWrBOpwNTJwyrtWHVgztd4ZYcnPzC8vIT+V7QQohe7nT
+Bb97T2/Ihi31LrCxMQJBANXbpQlNDFkch/tT5eGVj8khpPIatUkLNsDSQaCKp3cm
+Mz7HzWhKBr+pTW7GXNEnx+IQIX0cfnq5P4NItyUbQ0cCQQDMvPEm5i+j6/9tS6gB
+GiIN73REBdWsaxfG189G+exoRMM6EQJxDaWl9yDpTt9s/IlGyHOnlpvtgOtrheUk
+QHiTAkB+vptUJNbRpWguGu4eQR6jbI4ucofIj53Wr4X3mNVhd0Fdztq9GUpgov1i
+TqvJxdLf9wFx/cY0A8BRlXH9yueXAkAI/nfdjJklK1XiOEOeIMbEM/O4lUUIuP+n
+ZY2egZYoEnU9FMg1rTLMsqmIdkWMZR+ms2GZSB17doFhDNW/HPHvAkEAkhDKvrTE
+oFwinFGnW9RYDX5nlUFmDumlh0io3JzTf0wUS0iUMnzFbfKGEd9UBm1MBbeku94G
+gX2ZxuXkbXODaA==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta11_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta11_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQCjxdQj+OikAh84zVPcfOg8Sb0UwceitwB60tHIAXyb93hQlQdp
-kKB6JQ9VVfeyM66uZmRcTIZm4CjiY4wRX+6kr3eGwsAYDSQYXyb/Z8z0+X0M59cM
-AeiFV/So2Czx7C/HjDTUPdMbXC1EvdGmNdIhNvkxrCTL7HtwyBCXyI43GQIDAQAB
-AoGAID+vU1oLLWiBj2TXM56g+GYoxnKWBhN1E7p5tqGcUPX9ChkeeYoSH5s2lr4z
-5TJKHmtpLcef25geVN33UeCLFDAU6wIRCzFFV5gzssHsTIB+Gl3GR28BPvbQU6jZ
-1C+FIq0tbCDPXgOW5Mh06y5gilSehLNK+w6wsveWCUfMtcUCQQDRDSWbm9V3lptR
-oaTqL4phHXAy6VNZ8GSqxeoFdbKJ0CH8atsazrmYyyyQ95indnf5e4eZl9k3qmHx
-PeP4wrurAkEAyI2CcK1o7GPA58PIPOyoaYunV4qwhGhJxzQNajQQH/3ift2lTMPG
-f2wqFNCeGrtr4V6c2EFSSfAwf1Ierae0SwJBAIiDylRUrlDa8/CZ22TmyLnkjHli
-rwCjoEl41vrbwkyGszrv2McnykGCJEdCuNha37v2tDVT2RCl3jG4ld/D4uMCQQCx
-DQSn9t9XOaV2tkfTSVZQf2LHjP/SlML1YsWpCbdmlttbBs/Eml1l5par85Rwox9V
-QhKTc+9yqOIXtOayhghLAkEAtlEde/1Gatz3itdyAvNRt4XZ4TBiVnvnK1cAULG9
-s86415CqQeI9BRZHG+B4lpFcV6J4ssRr1byXrs3jftzQWg==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBAPPVL7Q+Eu7lAWpB
+pAkbEl/z1aJ+PNhvb6cwr3I99PQxMJS5CdgvNroSYVaMh/lSb4u1KNEjk/Mg1LUt
+yikQ9RB7rdbu3kAi2RAyMJMnIm2H+e2FFsJt2iRR2xoAUytlSs4kD89X8cBRngys
+LxddcsH0jYMgQdMQX/LgLZ/s2pd9AgMBAAECgYBR0IiPK/ziV8jfxGKsA39o3sIi
+IcV8wfdu2/EinhNhFFg+rs/U0BLG4H/0sHa3e6ed8w1dD1kHTU7R9ClPGjd/xrPA
+BK7Xov8EBvAL4NSjPy7v8liQNXPBXprRNsfFFXAaOTMvJ0z9eFyJQwyD0ZpYXR4n
+qbhW0XajkUVh5ujU6QJBAPxfvhZmUJ34nixBLBCCUXb2QVZRZ7CHdvrHI6u8zsqT
+5gp2yI6B+84cfc1QX7hP4qtAZQiC4E85BzWpA7nT1/MCQQD3Vgc9BOOZkWjxd+FE
+3C3/J2Y5hZkpc3lGQ+eYxdCQgKkUh2WdOEw9WnhEbzQXzftNapXLMLo/ikggCoWo
+XZ7PAkEA6KJsu4MmzudNDmgo8TLfWzRWN/YkCZJld3c3h2gsionYpE6oQszIy05y
+HF75TRG+VLOwLi9OC1j7L1iTyajgRwJBAM6IGrE8VOWWQ6Bm70e15/7JIpZj1dqE
+Hz+qUkkC3b7cgNOwoAxhx1/wHL9gcIp0KSWjHAQ44z1Nth5zStqlmocCQQDQxu9i
+IjJcxhd31PaLs3B5yVpRhN8+GYjTlw8tXUHXvMXuc2d4IJvp5o5hMkvHGK6hKtqj
+sq6vLyVWjPizs2Em
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta1_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta1_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXQIBAAKBgQDgSjjGSBOrcavKbm7O6fwsaM3uefbCfh8Z7lt1GT26T4+jeflc
-690MMA/QdwUN/7ko5HQaZ7P/NuomYexRJeHAzZdY4GWNTFS8k5k3K/OH07jXhxXZ
-zxy2h/RtVL31ZVNgQ7IEcnmwv3ETEf28RTgUgtkFi/6fjn3RLLk2YcAKEQIDAQAB
-AoGANTiHdk1eFX14lSVVN9X/143a566bJhWFTcLogsXFhvMgE1t7F1iEcELrTb0g
-Pu0iQ5jKEAXxiSq/rvHngG3rvkFWnPkoF6rDqvzPRkMEKap+4siCGUcyY35haDgA
-OJmjJn1QjlmvZLt2VzUMgWR1VH0zmG4OMhJe5XcV8zpcbRECQQD/fth1Z3lCVNXz
-nKKTIjv9tAHQi/lrqLY6H8oCSq1qQ6Itsz1nDBs6b/kEtZLNYr+pDUT+V+3ZL61x
-80wxAnzVAkEA4LuaBSQoXze6PFJUY/e5Q6m2l+vYXdyOZBr0IIv/RUJ56MYBdtSD
-i6MkbtcYDUvK6D+EzVlBR7ftRhFBjIWGTQJBAKRAU8AGaXovN+yJQir80zxiwNfl
-ZM/FgoETdrbKc3nhSR3AITViHw8OdTSF1n6bgUOY+EXbGVmKwSKEmvLW+pECQQDM
-7SUQhR0vXpC7itObaPyOX8a6F/zv8jwBurZcq2x2Sp0CDvSs2DKv9W82h3tOPIvl
-Zm6CFl65uFVsLDYannONAkBN74frdwuxVHMwyT7t+EuEPe6oGzuc9tg8a7dd9bxD
-fszzNiA3q/mvM7Zd22ezuhUSOh+cbWuDGHVqSI/o/VKQ
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAMERIJWbakn14LOA
+lzcC/G+ZbXBnoUdmz/ckWFXIiOTaiaj8l/Fs/ERga1xx14QiFqQJd/ujrxAkexMD
+trnI8AMAdKLKEJ+tFzLoy/pWwfoMP0NaNu5rlBKUSKnZHDdcdm3VrW83rZ+IeFCS
+WdZPKiK6pewpxz61QZ7Om56e2Fj3AgMBAAECgYBjO79oxjISg8uT17Nhdipz3gNv
+NASkY4be+5JfvSwHnQAGmJYsZB0htAFaybTBWJgUhj1iXNZ9UJLlyhHgWhRqQPw1
+9PgzYsGHYxd2euaVBOpu2urVQg2Co7b5KKd8x2KPCG2LRNrORHX+bf72ARb3AvY7
+XkyxufM8j/dGzxHfqQJBAPSSrwL6Yg2DIs3zgzMv0cRztL/GfJ1+2ztYb5uHcB+1
+m3PKRAtXYon8Tk5McWupVzSSuh2lQoS0M9B/iBP03tsCQQDKFmJFJspZflOKfPOb
+J1W5PenOWyIhHNlIX6wYqASJ195vkAtJ9d0uXH5DvN3LOsEY6rlT6Z/oYI9VW12q
+qIMVAkBjgl8U3h0RFF8P3tlt9THrNYzATpkbV6cJkWTvqf6T2EdkqFJhLu/X5sFR
+mEa5oE/sAxsYvsm+xrciSRFr1UDrAkEAyCalS9IghcSdX0NkTx4FREPy5sPSKLOW
+7Jx9Kap3XELmdt5Wn/kYCIvpLpPHpDpb95660UZJb3D7ZVHpklX2BQJAHU9gzIZL
+GA3CmA6s+HBd8nrdNs3BxJPxbCWnONrOZyAHLFbhru/9yeQtAfif5gCIFLktfRV4
+Yv6luWmrmJsWPg==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta2_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta2_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDjdeFEbWix3GRrowYKO5GtEM5FmfPqMjySvLGF1cVipv0+M2T7
-hG4J4cZ2NENjf3uTvGwOMViwwMjHtG6q20CGZ7AseYL7MR9xbBCkuQvd2Hjks6Ov
-3sYPIf1c5gG2h4KbBBZuQqVXOf6F41dYzf6Qx9M1fZETvwXyIaxC5w/k4wIDAQAB
-AoGBAN8qzPYCEnJPNgeVT1vCzk7q6jbHsdTZrSybDeGtt5fvFxBsBGvxprTzW3Cm
-HmgEsA5nE+1o5QemXlfx45Kmw0pBiAKyYZDJFsbc9ABSWfJq0axIMg/Ta5XTQ7lU
-AE/ZPSOqlgJIuBl391j84zb9QTarIybMRjcFH0fF7oIyiuNhAkEA+8eg7SZb5fXG
-KiWdvtDM0gwqrG/sSglYYnEZSF4lzTbCB+mlvPCyyXY9xS9U089PHwiPL5i3b5EY
-T3rM8nUO3wJBAOdF5grjPhczOXCp2wvFfJDhHNp5eBrYzRysVd4I1dJW8aeOj7zQ
-U+u2MNFtWuFK3xBpHXXX3BkYFQbVVQSGnn0CQGvbwgG1vAqQNfsaMDBtLEETOzix
-nay9wiIxxx3sTw9RVN+k5P5CsqSBRcbyFsnB9mgZ95TxPCvMIXjy51c6dEsCQE2h
-0gGPnDUPddWSvrup1BGR7yyLH7zrT5azZrN8hcHwe3fCTA+WYsU5yBNUwO/lQRFy
-J3h6OCCYS96aV8qIIcUCQDQ0QUOQ5HNbCiUd2VnT6hWOBm+5WqLOaCr30adUuuBW
-09QfAz6cUfxYnkSMugGuMqyguJ+38PpwbPTtaG0kX4U=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBAMo09hWc3n2gNzUL
+UOLYW3GqMCfD+7JUJLJ9zFKlPZAeHDjUtPD0tmPb3CXCq7JqtpCFhapf7Q9TU4Jc
+GWPVu/uz2Mw8m0uZ8VVYuzZdcWuWGi8RyY4eSb1mOT9OnTD5Xn1ABY8uMwR1AHvc
+VE23N2hy5vO3PSlYhAFrmCm6TCvBAgMBAAECgYA/OpJcrcHQzKGWv6QaWwc1Ir+O
+H7V7zN3wxm92xF7cyt2OU80Er7C8xwou8JGZ586QoH/sh7RsH2U0lTIHStVNz95K
+fF7Xl353iRy/vk37dvAUel2EIMmwnP7eKTuxhcLUuv/lgZtWokLMuNeXSYBO8pDc
+T1oqHg943HVfdRHNtQJBAPfbxBNG8c11iCPPZfS3znGjELyhCxNsZvn7Z5q33Zq6
+VyuHApkKKSR+iGgCzLz7uGtfDXV+1Md2NXjVrz+viV8CQQDQ2VAIVXaJ8AcGeNnz
+zX3Zzk7Vc67ZLGUXqgwEq919JHYOcLoCkSzK8xEgpH/ghFxiU1v97jtHpKOv7Jca
+8b7fAkEApp49uRfABPY1hp0tVM0bIpkT7znzUCNXNkUi6IchmZoab1BbFrYV4kqN
+OB5ps8EjwEotqgaQ02VLnOdI3+8I0QJBAJ+bhGtqDPZrxqKulzqYb7aV0W+VQinc
+oMGOBjNHuTRbOhHdGnq9wfK0AgHlVYka/pNyS1prx0gATcwzzmMcHxcCQQCoassK
+g7Ml+zChn2B6DD8RQPQS3v8RA1TBaU2l6jSyMv+HNDyVnFIf6SgpoI3VIYALZC/T
+pMt9JLH6iOWCDVg6
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta3_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta3_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDQsOfAJ5bW/xaJ9Exn1SNXpq/+877ZHihEpqMOZwkfsvxw/SxK
-nBOgzzeXLDl8QqT3ZH6+SWcFAbP3RjSb2L1LrNZAllptoDOuAzMifQY5bgpeOT/m
-68f54xqn3RYUbY63hNmvt0PbXQ8r6D3+ZteeOgahn8M1gdTNvBY8osHdiQIDAQAB
-AoGBAMjOgKEYNv93guOJq/95SkGsBctoFOrsJskwItPX9yKGYnwCUJ0WI5jn61DO
-YB4eLohSLdbB4JwjsFyuNC8F1dX/QKJBwJJXQIr5e+UOSaybcX1cpYgGwDOd3SJb
-OVJVBWBnFUszRs3ATLJblRu8C2L0pPFWrQIlDbFE6I23gKGBAkEA79wRX0yt9HIc
-zytWbhWGmxl8svvLvdDO7UOEHHGxQrTPUebA/RmyZ5OelIeG9uSH+M7h0gCDN+3V
-QYXfG5nNkQJBAN676apCvN/lySLB7xVhOdcojwJgGSHkNUqoZqowpJkW+z2VCawZ
-KZmTjsE84q2Y+hK6Y9ooMsklUfL1hNpKdHkCQHfY8+00OS8M3Yw+UT9MDiftQjuE
-SLcdYGd49sfnnvR/t59qtz8/2b6bKf95AFzYr4AIjxkJHIeTlJzasTHvVaECQE7S
-AOaXp280SfFa39iZB3b0i2czyrELqTA6V9pyTE1ArLgmPb4BSY9ngGUxvqXgNN7b
-xuo0v4QfCNkJuXHmV0ECQEJLPASsU1sG6PPPawxI63/d98m8Ro8RLE8cvf7ZKiuX
-EDjWYXyVIdrmZFG7z2EnHyDj1maqD7LWmNaZnRrByUQ=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBAMyZ046Io1Tx2qY5
+vmkoWocFCwRZQSE5QIpG/fUg1Wu2As1fYi6INIs98cD+OPf2H2UQ1wwDTJAX9yWk
+YuuAg0QfslOk3sXSF372lv7iGrxFl9wp+UZwEY1K9La3LWcgj9BqDyAJ/3wRHJSb
+XoNXZzUuN6JUlyr70Thk1eB5L64vAgMBAAECgYBXmdU2xdII4LSZT0fzhk+cV9Br
+wDtemkDD87lwZup5/6gbfqdu/OpiY9dKpo6FvF+cyiUJA7CYUWqEN2oTIycQE0ti
+67gwQCiu1Iy2z20eyKa7nz1DJLW9mSNvtLcuq40oDpAmOq5vgWdxpnCDKs7DLWxZ
+1Ntty/fmHuHiRC52wQJBAPicF5d/31l7yGFI4LQupN5p9mrULFC3dfFZS2ti/PMs
+kiJszhJPaP9nZ9UFJ28SpY32I2png+DrABZGgxJ/mGcCQQDSrtQ8teaBI5+LdMUi
+dsgyUsDMKjnRLOQ7ta/BhynQlkOu8cuS2dbbV6bBJbTZBaUCY/PBTV7anoc3YwPd
+SL75AkEApovrQhLoDYpfMs0fu5WD3XwfGHILPgepe4XWgJpP2piBTY6Wfq20KWWc
+qZhKUp6rSe8ayq2OK59C76lNJZdVAQJBAJzDMXCq+ISGeSRPEo/+SiAHqyU/Fh4q
+hPhYzBn39IkcBeiaSZtPM6upoI5++/2vUYRh0vG2HCoXYw03Q5zXkCECQQCCF9+h
+Y/RChb+X2G122dcgPWSWx775zsYj6/AlzTJWwmydJnLn4gIOh34S40FBrWuDyCkc
+oMSO26JEI4jO7DB+
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta4_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta4_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDPwCWn+t+k5AIzhE2gP04JxK4KWNNFFdNelFZatdo+J2hmPbGD
-FLwTlPOoOJzomkZOBngNKZVpoCwSGTtrpj1G61aK94Ut2ZzwMGsKA42u2M+e38ml
-19OxqxN06B6ivjE/F3giTIOLJO9PXcRuJviw2SutnrDE/MIAEJnpORdoBQIDAQAB
-AoGAc0AwY7kMOsh25CeAfObBny+qMXlHcysBgJWgNmBuO07XXujYwlRNZjua1Hbb
-rTpwyDZUgVDRX7CI4l13Fmg5006nKDVmg0JU3KKIDhPKrDzwSIwZZPRh80R95/aE
-ieUpFm+FgAZYipFiI3PyxxHdEdHilyNa97SxvKt/idWv3GECQQD2iHoj5vLVqW1D
-0JCyobYNde7C+Ky1vXRveDLnenmOPQZhE2NMl/ATRdhwvpJek3i3ApYfjH9tmgvT
-t/h0cNAJAkEA17pr6KU0LCKN8repq3ByRfh8kx/XnHVBuqayW3hleheAT56QthwO
-s5Xeq+rj6TTwfRpVRS1VWu2AdNEsQFjfHQJBAOpl0nNmNwZMw5WRrLIarMRZl7yK
-wXM+gYEmcIfD2+UQQotz6pq9b0ZzxxlTKEmBv2mJrQCsDdBAgfQ326OiSzkCQC6l
-jc3JYyWj9yOjmRmL//mnSHCbswiOxj6w6uIif3bN/B27QLlQCdHFN1ffO5birpmu
-hv+lVM6Lino3/KSRUvUCQFNknvds2O6qGKHSpFu9JTXeiOCjQe0zxY/3nXE4T/da
-n0NGzS56tMTIxvmGEMvMZd22uhSxVUorl5av38nuP+k=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAKFjW/l4Khnf0U7V
+dSTGiy/paZmrgiS0D2bsTMF6vaRcEPFhx/4vU8EQjnyDS8VQyiCeqiVBORkOepka
+iiWb32e2Z2it8iIV6ObdOndKuW/hCnCSDt2o52Lnozr+ynW0LSxgza6H/LonwQ2F
+scx/2fMPfcs+FXBU4S6KiJ3nBVdHAgMBAAECgYB3FDz04XkPBloF9PIuZGCmxW6p
+eCbathD3PDuWNt5eu5+0uxU5s+n0dibsMGRj/qxlTSz1uB5NIqXK+g4cmdpIG/L9
+JEjKWFPGAeYoNWY5bmRCEqYR2ujlxLfMkfQDRNyW/eMfcm4AtZFxIkXOAxiZzAwB
+wdkUif3CPbr4JpSAYQJBANF5WXslw6SRBfm47Sp7M3kHznN26z35dU9HIC6Pa34r
+8cIzpGyNnEYXKyLEdhQ0WQo0MyDjiEx9fe6cql740G0CQQDFO9rwcVxMS3Txwbwg
+H9VA3hoL6lHq4hDYWKAAvg0Qq/lcwOQQ/IlVCrAdjypIzE6hMuekbsv1O+CTd0f+
+0r4DAkB1UA+z7xddb7a3/0AbfXn7O0r80Um3oKB5MK0uRjX+KGAx0bgw7zHo8wq+
+YuZ6NEL1evxzW9o2dEV1v5mOrKwVAkEAiN2+Unf32qHKJzGPgKNWcsstO/OAoQP7
+OIZXkexQWK9ePXVFTlxQWIkwKXL9nsLYFZijkkGomybP8sUlWrmXTQJBAKUN7kRu
+Uc528a8DPcN5eqG2kTuYhxEN1iR1Q/hzhfUO34SRw08Y3kB2WZO5iedQmPT/AkA+
+Se543GcgD6bkYP0=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta5_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta5_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDEZXB6DgOuhfPWA2/5oq9Ors3UmbZtFKQSYlQfi8bTjOh+hYKl
-9ckDZvbdSFhaeiDGHXtHeFJkPwpn0MwDqisAtYl7sVD7eeHVMozDSd+6KiFDy8U5
-ORK9Orp7KfJIMjeExq9m26KkAOxACMGoNgy2SMY5sf2+4mCkPca2sai+VQIDAQAB
-AoGADHB8Yk627vvvCNQo6H/kaLBruxaNVnVjOwLdXy4kRsv7AeCE+OwLclq4MiXd
-6sUnhETjxRAa79yKVS8FbQn/NSzcfThHZgoAaClHpZzRQ07rG+h3n3G1t6Pl+7WP
-BFxvhWCrS2MsZnynmOZki84um8dSVyXRBmjrCV5BnwDmmCECQQDpycFGHgPmRmX/
-H4CgI6SmZWyqjBrErezdKz15nzmjlXm4NMe28Itg8e4sdc//h5dLfRJV/ujPLPbO
-FnFxEjtpAkEA1w47Q//STVXbw0HpZSnKYxVmDLcevhTtX/zq9A6bJCIGHG/jI3mv
-9t5JWbWZgmmeKUAe5o/ATu80O6NddQiqDQJAfJGsEhhcK47HOjEm8C0Nxju0swsE
-GFg0JYSstOlKZQd4W9aDs85n9bfzGG2N7rHow6hY5Ml2cy2aNCVxPLZiQQJAcnGE
-YH93LuiN9q7QwaEnruroT8PzfDwuxnIVpqNPND9W+TMhsPNFDR7l8fOOKbSDEnio
-+RFuyZLKPSKGzY060QJBAJOnRcAqnpU4sg4TMecnsaaVHUJPjWUr6CMkSyCWZVi3
-jAkSrx2cv7F9yEhTWgDR/Klcvycip7Dg1D0IEOjtmCU=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBALeoEz3zZGCH2b3Q
+kll0udwn+EAVOZowUg9zXUXYuaGaclbihRrAGIyQVkQU5VBwaeU2W6L7PL/5eHcn
+Ld48Xjx90kACi7wEm49lC3Q6mCNN4Q1Nw0LLYahCv7IcgxiJT7TPzzT988d+G1Q+
+7ekKE4zCVvYlh0JAo8qr/8y6xsINAgMBAAECgYEAia0Ep7dSsw6EC0hUvZzES6bm
+8ds3cD/y9EQuUtLx7ZRjTIDI+VGx1YXKNYVYlmF+8OY78cTXOK6iQOhs+SFWHku1
+K6g+BM1PLP93UMyLur2MKUbj8Znow1XvCXgDs+fpydoaH9GWEY5Ovf9H0zu5dXw5
+vBY38HetWCKBRzWvRR0CQQDafosa70JyRuRWaXNJrmlSeZblALrZUz1ydLOHXMC3
+1bWAq36F1aeHbD2rySFucY48Wj4lF431e+hoT+plxOKLAkEA1y6hT2FWba75dytx
+DTG+OjXIsTbqkLubO9S2ix4+9FfqNMHq3BzroT8fbCxZKatrX3J5sQjTDgTPpahn
+Jkz4xwJAHZ13V2BEvl6Tho7mfH8ycWZfqIyPxvM8ae4dg2R0Drbd0iHslVFfUsC+
+HzG04VZs9As7TyXBLRvtZW4nlEG6fwJBALxlfCAG5efkMVAv/awCqD1Ix6y4mwga
+6V+p7iTBV3cQ3eJRAbKzs22a2YUZEvuTtM99Z6QjSL3WYoL0fVMgQxMCQFDX59WS
+U/ebkqGN1BftuFf+6T42jAxNfrfuq6K//GWfRaRJihkSzE4gAqfTBeMPBg9KYS+p
+Jvwj2jHUmUm96Gk=
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta6_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta6_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDFQaI9AK/icSnmGMJzZfxKneP3Gm569QmBh83PqXSp5Efa4vq9
-DgquugboG2bjil67h5Be0Th9EpNyoEuId93OAmefxb5Jy7foDr3weDdVu8WRbsd7
-nLOUoiR9CSV0UiJtSjT4knGx6XSbjofUKkb4+o+GXLVrICTRN+qKhwfjrQIDAQAB
-AoGANRQjNu0PZwxybNMux+SijeWMqTp4jiePpkZH0GBV3z1pRHIdbG/x2fB+2Ug+
-WG4sbaPd6lW8MJOmD4soqBExIrwqOLQygoaiLlJrp1LAsJQ11wuwSyGi/q2qNVhp
-DB/1zF2cG80dEOq+TwImPB6qcIS2FuDZRNU3JUF3DRKm8oECQQDoqdRxtbD9nSnf
-Cm6JachsUx1xneB5YHTjQJQrM8sLOQOQD2mgHriS1V3lKEw+hm41N5kyQsDb6kqD
-x7803t+hAkEA2Qqln2LWBPs+GQbSa+CuFxolHNUx1e9Y0LfhdFvxpF7kGJWxa5VF
-UimD1AE95vuI6Rp/iZZlIao5d3AHd6u4jQJBALUWYizy7sQmzE02cFxxwjZV5qfk
-6q9uHOw3+ls538JnaNd6t4qR/rUCbyeKWvWbajHviURuYm+IhuDU2oTLJ6ECQAch
-U2mWDKPjQRn/YGBM5Es7/6Yf1uBJWaiZsd1pu9mDiIjKOibno3xcgskvNUJmVwwZ
-Y8E4YKAngHXNB2HGEW0CQDY8gCLeMukl6J1XTvvSH6IjoktNZ7Apf2r4vxzDi1xD
-/d4dVVIeV8lxkO1Mh6Z64FGH7c/lKR70ufy9l0WFyk4=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAMVDZbngtb9o9tBn
+kUkfU8jrNle5dsnXLSZM8gg45l1WtiCvcuqsmN4UzTXt+bP748QfBtsEdyrNPj6Y
+n1Lxnifbkez03j5T1fy6XDeYi7dFTLup0My1+EWkDFigkmAFJgGWCMGNXxjohPHQ
+ovHjMmcgUqZvekc58fDAR287nnyBAgMBAAECgYAvFnOF91nrIwcnoFFR/yRk5aDH
+OAJfE/o3Fk8AH3T9+uDm1Hq+Ag1LlfOWWAQvLoWkHzPnvB0mHnApSQ1fI0X5Gl1x
+Jd7rY3FoleofYbLRxwA1Mx24MIBwx//Ckf6GYFgX/xJFxCwmDleJ3V0aZUS+PEe9
+hJtWhQB88nMos8PtMQJBAOgNi4+qG+w+M308qDNYs4QXGVP2k6VyMIziAzf6W4PO
+1V4GHZTYCmrfiDmUyh6iJrYC5eX3Z4hNU99JKhTn1AMCQQDZnsRxLlqHEHy7NqUh
+ODG9pHLTOBlIJsHB3edpwQ19w/So83Df8zg2E4G6jK+/V1AK6MJ+wyqSCzdwV04B
+ZKArAkBOrhEM9COllW2F4CQzzLaJaf+XfXqQVUhq7FMlDskqxt2HlNFA34OguwwI
+Yg+qFVbEzfS/ZYSALZ/rjHYtQnGbAkEAu7fslAT8Kg3aylM01hb3MTMtqW12wXpN
+IMId4GebD6V84lA8SbIwBtWEzjqVT2Qts3tcaqRHkHsEc2+b5i+6yQJAMvStoGb1
+16YRDyLdgMSqSjjvbt/LtaXgGloUT4xtP+50luzxQRAbxd3SEqeiIKLZX8BdYaO8
+wVIVuE2pJWn2Lg==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta7_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta7_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXAIBAAKBgQDI3lI2e25LbXqDc61Bza82AmI2PvdVBxEkQ8LrQ+RvHTzsc0uB
-WKIqfuDE8JquBNgqSTm/nuit8JZSXjxncX89QNc24xwl2gsp6YuBZhm8NDgaTstj
-9TDPgmz1FMzfu8ztcIbkum7bhc5g0Wk3SOgMwHaCD19lCWINcslas0ks/QIDAQAB
-AoGAXd+oxFWDAjUz4GMbQXmCvNb4VymuJUqcNDqGybR8+YDMjCSF0Pk/MGUDXoaj
-g1g4Peri1i7JxyB84BmyWRWtxHpqZAj2SIllnqupFCZpRAF274+DlTKX8YYOvnCu
-aZ0nECNafFNXcctRTtl4UefaOvEN9afAK/sGg8X1LDDKLYECQQDt4OvwNdZxMaLo
-rtAleu8MDka5rXqoocrZQWZp4nixbkzRiKR3YNVxSNXOd4kVIon+YjTKdkVNMG3d
-tkJYiDqFAkEA2Cuh0HosgflBUTz7ep2T3NAuzUrOd5yGO3B1oXrzGM6m9AalP8e8
-tD2kmSrj7akRqKEAKEa9af5Ysw52ntZ+GQJBAL5a6vNCYeQa8F565Z3Yjkp7ciVL
-qYggUI8iQq4gyKxTs61JRzMwjh0lR9L83PnItdyXAd+yXSqzwndVTipCeXECQAT+
-bQyN5f1SrsmbqQuaHFJblNk1QzPML+WroWwLlRYboAu/I44npRpc2jKXpRBWeYv1
-vDUx/So3sADi8qaUufECQE3cC815swdJZUYM0VrqsPHo1D50xrxWg2yxNAsB4EKe
-3HtXhk/wCM6b30mSiBt3Yh5TxEWe2yrBXWWi3Q09Qb0=
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBAPlTDeqrTS/Z+nU8
+9leA0ZIpRL7bfW1e906hdoOzMaVAPkTQji43+Ww+KE8eUmbr6UxS6X+U458s5GXD
+/CebLkKBPg0Tu1hS9lC29e8urJRSTkqpGucZDitKRllX3qRlVUNwV1JVleQXXc8N
+5Dv3QkvOJZ0hPkEpMMEisneFeoP9AgMBAAECgYB9mJ8sFfseHdqTcJBP6C6qSGu/
+EWaP0AUY8TF4iq55pnE3zS+yjLPzGSTJJmcwPasarbG+eUxpBP5RXXcKpJuaGmCL
+NmHfHOIlZhXGSt2f8hp8MQAJQhafG2OMYGS6FdH5wie4uOp81I7fF12w58Y9b8Oy
+2k30b+FYq4uWzGekqQJBAP8ioduFICamvUaXaRzHpQfhm2LgJu0NFawJLo734ca6
+A3rQSSuVvw54JWP/vCT8LzHkcsLM9krdEdFGBK86uDMCQQD6K2FdTMXWiebHvEUl
+Y6IrL9uWGMznSWRDExAsKcjZid41IdXnPgadRRrvuLtk2h2+Eef2EEfUfwLy6ZGu
++mMPAkEA2GNnI+gk/KMupVCFtgMd1TFjuNikKymN1/txoZBbzVC24tMFPBIlmQAN
+tmKQEE5TON2o988elSAqnHPmRThoQQJBAIfEaTfIRYoUFxII5AHRm54Sf/pqhTF0
+TBx2yQ0etCkTQGvXbA3uRIqviVnWCKVIFmIjt5574W+6anBIQE8VBhMCQQCXJWmG
+OMy6BeZJrQ2TUCdnsRHvlVaTGlF0SgoqYpksFPdluttT6r2d9LuyLJipIc1H7VXC
+UV+lwP69fl0s/azE
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta8_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta8_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDaXoXgFxQ1wej0tpcV0fXDNiZXhVwM6I7XKxBmsmGSo9+kT2FS
-QZw7Lw68vZKb4kzsaDR2LIZU5YuerC9+TwdS7H9RMe2elO1+FdpP+2XQB4XCYGnO
-rHRyikUx5Gw+XgW80y83VhTCLnh4a5MU5WEIIu9N+bsbHzEJEnqt5c8YWwIDAQAB
-AoGBAKkGkUmrk5Eoz1DcJIZXRowb1gHY0C+Ns0MJqmBTowMGpY1hhEtPTcbh3d5q
-Ppk6yaAT6MewHyqHo1LmpLx4H4m6OIfBsO/X7HDs3EWrAksSagjvsgJU+rdwKf30
-odr1hDeO5ngT6KEiBLiUMw6Fb4spxzOw7svGd9pBTseKBw2BAkEA8aMEW4vslpfD
-f5NsazVwZTCi2kVW+XOg7Gdf1ou1WDAajo4kK/KLKoBesDf2i7oxu4nBiXVIx/31
-ZZdTzAi2swJBAOdZcaVJGdOPIkGXGH6q6a7nIeWwRCYo2IF6Ra/kQGV6+QMdd3o6
-flb8NJMgfALcfTcPKjZd0b+0bPkGWbFhK7kCQQDOUZjo6eKK+u5sQd5y8+ASJqMG
-p+oJeJdRAzsrn4Kp1/j0+50bAS+ejJlM8ZvL1qGcNZVQ3xnT2Z3srndYYaBNAkBA
-T4Lh+YIuZzmUlhX/EC/JqQKpQOiQ2wXkaEL69C5ah2a1UPmnhp8cOxu6UmtmuDgu
-mA6Z8laePd+VEgjY4DQxAkEA3k9Ts4dilPVpMZn3su19okzQuXcESOW7Y4xVarel
-TGJ+UBsG/nL4v+IfwPPHaiXIamvRKJ3veW6kh2twH37RNw==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAMZN9yR514+gk2E3
+0KRcYYHiGhwK/86LPUkVEhwbt5zdKPbFXS5j92dLyYyVWhzol4kWg4H/vBAmUXz5
+8QP1UfQBRdrUL8/ZNWgMrhEtMTdac3PAYBPIEHM6fcmWjAcAsUFS0rBfzQEGuNc/
+2A8X+Tg5XS0JFJkFfB8fb8ktfW5hAgMBAAECgYEAtU+5xQcGGZM2zW+r+2tf19J0
+Dunbo+xZV4XFbh/FjM4FU0N3BCBwp2h62mf/4WikjLoh+W1qdNWkMgGQ5Q6bI0M1
+50l1Be8Trc4bVb+cNwFE4yxwvxRhB+WGuCPSXAAcuixhCVn/IHNZl/nLpT6n0nuf
+wIlVVVAamanwlHU537ECQQDh45JTkEgBrj+7l0BfYWWd/R66tdsV9TMV9VuauMV7
+TK8URQ4LaIZND8ax7JK74BuUh/TqEohhohThb69mGNTFAkEA4L0UgdFt6J5oZdSb
+yhCtt/w+xmAjQKe/evIpZw2nl7fG9schurDDdpbqIcou3zXN06S05+Z8DnEGF2up
+mQ3k7QJAJVFeXDXK35Q07T3YoalKi2ZEzF282wzOKsOFJbN+1Jbfmb6qylGzVknT
+7pMBzs4AYHJxkLYNF+wZ/QBhfsF9bQJAbmjWG1UNfxvbxDNoeiQphFs7Z/AxQYFo
+E/nGl2dg76uM5w47puFSlf9cdU9EKcrgHNstOUTFq76hNH5jKttlnQJAVyA7I677
+xhr9vvyZpubOlc994nzerYn9B+QmOX94oXLN59y50SEWILXKL/FS7xvJnt7z43wI
+yAQIHdgGPHrBWg==
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/keys/ta9_key.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/keys/ta9_key.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,15 +1,16 @@
------BEGIN RSA PRIVATE KEY-----
-MIICXgIBAAKBgQDoq++RygVKGKKYxNiT0M6ZqV4CjV1c4/OESWunbe84dy4ywpwJ
-Hfa+bMbEscjDMnIrhIf2ur/8z1wFwk9iI34CP85sxraVhoTXl58ch3ApYmopfAaj
-txgSZwc6iarwmf7fRgCxL6owHqIe+Cs3mSG4hVNCmEq9xfm0YWAKc7wO0QIDAQAB
-AoGBAMrWyb5BbqcQHwAr69vBl7tiafCzqQcIOw3CrDWEo56IWCAshLd2BdwxHH/x
-teJmIh5KJfY1DJard8AVi/s0ke5edIjAUT/PcVtcPfqYxa4Uyb2JX29B9JWk3wa+
-oR4xXVLcYpr6BCDth1dUVGbMqkIvesH9/gpvENhytHANol8hAkEA+Et6+2mNWAsf
-JKD/uztHlebzKh3fAAEYw3Zrp8YBzDNIDlK06ackVzO5/BnwDz7aRMiQTLpPcXui
-0ibg7bjhrQJBAO/kVycQxmbfi5A6RocKlJgrfNmdvagGv3R/WBd+Mh6jXKyOdANF
-f9uA56SmfY/itkbK6D1Hkq5zOjy6z+sRbjUCQQDxyTbyWmAMq4/hMHK3lcto+yQy
-EDKXI3pE5S2CjDw16H4zjHCl02B9Fl73Ux7FCdStBI4YWZmBDf+JG9kPRWllAkEA
-keZrhyvxrxGYvVBkIq+xrlcMqQICHlZ0TPNCbY9oBjBPJffB4Vd8qtDckcxco408
-VRQFaXfFY2pbaiIoYIyKXQJAGKbTNdkyNLZEqRXkV0g5rznU2y8almz01MPanoKp
-tlLYl5S/dkDVJYXJjABul6s/BOVsuuycPxdQ40G2LB5D/w==
------END RSA PRIVATE KEY-----
+-----BEGIN PRIVATE KEY-----
+MIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBAMmKLQ1TBOgCu7wn
+3w64MyUHVGHQ2bYIM1vD60yhH59RzKmDBxYVnGkLSHRiNV+jlDg3Dz9fWCaaNgui
+D7ubV//9cAHWKKK2Z+2pyJAVtX+RYDL/lhOkPwkjcC84byRUQZUvkVpupap32mxQ
+7mLlhYpnY338BzC685aTbF1fni4HAgMBAAECgYEAlB4F8EX0VCM2IBlZeLLte6hA
+XsckSgEK5cU+WAoOeIOgm3AdtCBb3GObc1V+DnTlCM+GWDfVTEGHuNL5JxMK/10Z
+DMqRQwqfIkJgyCZyJSi3giVisNyI211nDObL9Lym9zpg0pzTpVbg+oum38mAHK8+
+uzQpG3tPoOV3TWysgYECQQDqATw6GpwrNbt9rv/+ms73MkD2mWBvMTYKAvMxfFTo
+nE2n+pHMFmvXD358oYf5pvL61Cm4WCZMJR5pUBjSCpNBAkEA3Hu/Hzbc/xslKz0U
+otXvsVrbw/uGKoww1ZqyqlxgC6Fuk9x4NZa42F2EJYR4OrKedvF8QAvtvsbANazI
+8NSXRwJBAM4lrnAllyS93mF3tNAQg3nkDLTyI7FxMgEZ3jLfLFILuKHeLWkU64X3
+gV+8UfTObcoo9GQRTBPSs3rldCg95sECQB1ThFdVh82Swb3fkPgbtpcDe8m0keLk
+5LX0rqEESm4hmcCnCYIvOwTkY2hOF2PPUE6HzjwCmivO6c/53HxT+o8CQQCLKq92
+nbz7wz+H2a4Sue197zjfQqC4bc8wy0hwySH9W2y2W266y/hFj/W47+Lk+UH6NjkR
+/mKDg1LuFywz1pOG
+-----END PRIVATE KEY-----
--- a/src/tests/ro_data/signing_certs/produced/ta1/ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta1/ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            a1:49:ea:78:5a:f4:55:8d
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta1/emailAddress=ta1
+        Serial Number: 17773656435948586063 (0xf6a8b65c108d044f)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta1/emailAddress=ta1
         Validity
-            Not Before: Apr 11 22:37:38 2011 GMT
-            Not After : Jan  5 22:37:38 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta1/emailAddress=ta1
+            Not Before: Dec 13 00:13:33 2013 GMT
+            Not After : Sep  8 00:13:33 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta1/emailAddress=ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e0:4a:38:c6:48:13:ab:71:ab:ca:6e:6e:ce:e9:
-                    fc:2c:68:cd:ee:79:f6:c2:7e:1f:19:ee:5b:75:19:
-                    3d:ba:4f:8f:a3:79:f9:5c:eb:dd:0c:30:0f:d0:77:
-                    05:0d:ff:b9:28:e4:74:1a:67:b3:ff:36:ea:26:61:
-                    ec:51:25:e1:c0:cd:97:58:e0:65:8d:4c:54:bc:93:
-                    99:37:2b:f3:87:d3:b8:d7:87:15:d9:cf:1c:b6:87:
-                    f4:6d:54:bd:f5:65:53:60:43:b2:04:72:79:b0:bf:
-                    71:13:11:fd:bc:45:38:14:82:d9:05:8b:fe:9f:8e:
-                    7d:d1:2c:b9:36:61:c0:0a:11
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c1:11:20:95:9b:6a:49:f5:e0:b3:80:97:37:02:
+                    fc:6f:99:6d:70:67:a1:47:66:cf:f7:24:58:55:c8:
+                    88:e4:da:89:a8:fc:97:f1:6c:fc:44:60:6b:5c:71:
+                    d7:84:22:16:a4:09:77:fb:a3:af:10:24:7b:13:03:
+                    b6:b9:c8:f0:03:00:74:a2:ca:10:9f:ad:17:32:e8:
+                    cb:fa:56:c1:fa:0c:3f:43:5a:36:ee:6b:94:12:94:
+                    48:a9:d9:1c:37:5c:76:6d:d5:ad:6f:37:ad:9f:88:
+                    78:50:92:59:d6:4f:2a:22:ba:a5:ec:29:c7:3e:b5:
+                    41:9e:ce:9b:9e:9e:d8:58:f7
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                75:A9:2B:02:E8:FB:31:09:2A:F2:16:21:24:D8:B2:A5:D0:14:93:5B
+                81:54:6B:06:08:DD:44:4F:08:81:21:7A:7C:D5:96:EA:53:2B:E3:0A
             X509v3 Authority Key Identifier: 
-                keyid:75:A9:2B:02:E8:FB:31:09:2A:F2:16:21:24:D8:B2:A5:D0:14:93:5B
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta1/emailAddress=ta1
-                serial:A1:49:EA:78:5A:F4:55:8D
+                keyid:81:54:6B:06:08:DD:44:4F:08:81:21:7A:7C:D5:96:EA:53:2B:E3:0A
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        82:9d:88:f6:27:64:f1:c4:9f:18:10:ac:d3:6c:81:b9:25:34:
-        f8:74:1c:83:b3:94:65:1f:25:cd:5e:a7:e4:ad:d8:b2:6e:f1:
-        43:56:25:75:d5:db:02:d6:f2:7a:3f:12:a3:60:04:77:49:99:
-        37:d7:af:60:ff:d7:ee:d0:df:cd:4a:fb:75:ee:05:b0:af:00:
-        da:e2:80:6e:85:81:72:75:a5:3b:01:8c:00:3f:bb:8a:21:47:
-        0d:d4:bb:51:a5:4c:58:2a:d8:09:1f:fb:b1:e7:56:00:53:a8:
-        25:3e:ab:3d:f6:1b:28:7d:ef:76:68:62:be:28:a9:63:44:d1:
-        68:6a
+         94:f7:77:15:8b:2a:ab:eb:9a:7f:a2:7d:d9:5b:be:6d:bc:e2:
+         49:bf:7d:16:36:0a:72:24:be:72:af:59:2f:9a:cc:d2:da:74:
+         fc:03:f5:9e:c2:e8:a4:ea:99:90:30:7e:b2:b0:6f:b6:fe:af:
+         fd:d6:f0:51:50:52:99:d2:0c:dc:88:4a:54:3c:09:93:9b:83:
+         82:84:64:78:d7:d9:00:90:ee:01:9c:69:05:34:c1:2d:b3:46:
+         da:9b:3a:47:65:76:68:63:6c:3d:cb:47:cc:71:05:f2:22:6b:
+         bd:66:0b:6a:90:45:5f:60:11:4c:7e:11:32:8c:8b:ec:70:c6:
+         f6:b4
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAKFJ6nha9FWNMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEWA3Rh
-MTAeFw0xMTA0MTEyMjM3MzhaFw0xNDAxMDUyMjM3MzhaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEWA3RhMTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA4Eo4xkgTq3Grym5uzun8LGjN7nn2wn4f
-Ge5bdRk9uk+Po3n5XOvdDDAP0HcFDf+5KOR0Gmez/zbqJmHsUSXhwM2XWOBljUxU
-vJOZNyvzh9O414cV2c8ctof0bVS99WVTYEOyBHJ5sL9xExH9vEU4FILZBYv+n459
-0Sy5NmHAChECAwEAAaOBzTCByjAdBgNVHQ4EFgQUdakrAuj7MQkq8hYhJNiypdAU
-k1swgZoGA1UdIwSBkjCBj4AUdakrAuj7MQkq8hYhJNiypdAUk1uhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEW
-A3RhMYIJAKFJ6nha9FWNMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-gp2I9idk8cSfGBCs02yBuSU0+HQcg7OUZR8lzV6n5K3Ysm7xQ1YlddXbAtbyej8S
-o2AEd0mZN9evYP/X7tDfzUr7de4FsK8A2uKAboWBcnWlOwGMAD+7iiFHDdS7UaVM
-WCrYCR/7sedWAFOoJT6rPfYbKH3vdmhiviipY0TRaGo=
+MIICoDCCAgmgAwIBAgIJAPaotlwQjQRPMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGExMRIwEAYJKoZIhvcNAQkBFgN0
+YTEwHhcNMTMxMjEzMDAxMzMzWhcNMTYwOTA4MDAxMzMzWjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMTESMBAGCSqGSIb3DQEJARYDdGExMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBESCVm2pJ9eCzgJc3AvxvmW1wZ6FH
+Zs/3JFhVyIjk2omo/JfxbPxEYGtccdeEIhakCXf7o68QJHsTA7a5yPADAHSiyhCf
+rRcy6Mv6VsH6DD9DWjbua5QSlEip2Rw3XHZt1a1vN62fiHhQklnWTyoiuqXsKcc+
+tUGezpuenthY9wIDAQABo1AwTjAdBgNVHQ4EFgQUgVRrBgjdRE8IgSF6fNWW6lMr
+4wowHwYDVR0jBBgwFoAUgVRrBgjdRE8IgSF6fNWW6lMr4wowDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQCU93cViyqr65p/on3ZW75tvOJJv30WNgpyJL5y
+r1kvmszS2nT8A/Wewuik6pmQMH6ysG+2/q/91vBRUFKZ0gzciEpUPAmTm4OChGR4
+19kAkO4BnGkFNMEts0bamzpHZXZoY2w9y0fMcQXyImu9ZgtqkEVfYBFMfhEyjIvs
+cMb2tA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta10/ta10_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta10/ta10_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,65 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            86:f1:45:12:31:c7:2b:2a
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
+        Serial Number: 9711796497956498587 (0x86c73b75a7946c9b)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b6:50:43:73:64:12:40:26:54:0c:f9:67:e4:6a:
-                    ed:1f:18:e5:73:89:13:0f:c9:5f:6e:6e:c6:05:ad:
-                    2c:be:e4:6b:fd:c6:4f:ea:f3:6f:0d:f4:1a:34:7f:
-                    03:97:b0:a4:d1:6e:98:d2:36:fa:33:5d:51:37:de:
-                    8f:5b:3d:a0:07:52:c8:b7:71:30:71:fb:c3:a7:fa:
-                    61:f6:b4:28:be:9e:da:8b:8b:70:dd:8e:d0:a5:1a:
-                    00:70:1c:39:e1:cf:64:f8:ec:b4:83:b9:2b:67:fa:
-                    4d:ae:30:84:2f:2c:9d:6c:77:7e:09:95:43:77:6b:
-                    e1:9d:2b:c9:89:d9:a9:e5:8f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ab:08:de:44:e1:7d:cf:87:e5:0d:f9:b6:66:79:
+                    45:4b:18:3f:c4:c3:bc:3c:4e:10:1c:23:36:0b:17:
+                    8e:53:e9:1d:52:c0:d3:78:ce:74:30:13:d9:3e:98:
+                    8e:08:94:fe:76:94:55:7a:d9:73:87:01:5e:dd:c7:
+                    7b:5e:56:94:a6:5d:e6:8a:ab:22:03:cf:e1:7a:1c:
+                    7e:fb:16:c2:7c:f4:a3:6c:46:28:0b:15:15:e9:92:
+                    4f:50:a3:e3:04:25:91:6d:d0:71:2f:66:b3:20:64:
+                    db:f1:60:8d:3f:52:94:13:f1:f1:00:93:0b:20:be:
+                    f3:98:7d:c8:58:e3:f0:e9:c5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                B7:F0:DB:5F:BA:CC:10:6D:A6:64:62:10:84:A5:C9:39:4C:3C:27:86
+                61:D2:DF:69:D2:65:98:6E:36:8B:4E:A5:34:33:A7:EF:84:5D:DE:F4
             X509v3 Authority Key Identifier: 
-                keyid:B7:F0:DB:5F:BA:CC:10:6D:A6:64:62:10:84:A5:C9:39:4C:3C:27:86
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta10/CN=localhost/emailAddress=ta10
-                serial:86:F1:45:12:31:C7:2B:2A
+                keyid:61:D2:DF:69:D2:65:98:6E:36:8B:4E:A5:34:33:A7:EF:84:5D:DE:F4
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        5b:6d:71:b8:4e:e3:27:06:d9:2a:47:ab:21:a3:df:94:a9:d8:
-        62:f1:6a:97:33:cc:1c:52:55:9a:f8:ec:6d:b4:91:17:4d:2a:
-        0e:03:b4:4b:00:83:10:8e:12:c1:05:67:56:9a:30:90:91:ad:
-        8b:dc:0a:eb:3f:28:5d:f9:d4:87:0d:f7:3a:5a:f6:47:52:9e:
-        af:4e:21:d4:2f:b8:40:4f:7f:81:1f:93:ca:bc:e6:04:c5:18:
-        65:5e:b1:dd:0b:3c:5e:3a:6f:48:e3:fc:b2:c8:37:8d:9f:14:
-        1b:a7:12:79:bb:2d:b9:fc:7a:01:ef:66:c6:d4:c2:44:01:49:
-        23:a9
+         48:43:2e:21:5e:c5:85:b1:97:37:72:7a:4a:a3:c0:db:5f:c4:
+         42:51:d0:3e:f5:20:43:f6:72:61:b3:fb:8f:13:71:36:0e:8e:
+         33:8c:14:7d:c2:39:ed:36:a9:55:db:bd:24:de:96:2c:b2:61:
+         d5:95:36:97:e4:b6:17:d3:a5:6c:8c:96:1a:89:54:ab:43:f0:
+         76:b1:f6:f1:4a:0d:69:79:ea:95:38:76:c8:5b:cc:99:ca:ba:
+         0d:71:7d:0f:d0:31:8c:94:a9:2d:7b:91:56:98:a1:ea:75:08:
+         ea:fe:03:e0:23:09:32:00:88:1e:83:f6:fe:df:40:3c:78:25:
+         ae:e5
 -----BEGIN CERTIFICATE-----
-MIIDYDCCAsmgAwIBAgIJAIbxRRIxxysqMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQ0wCwYDVQQLEwR0YTEwMRIwEAYDVQQDEwlsb2NhbGhv
-c3QxEzARBgkqhkiG9w0BCQEWBHRhMTAwHhcNMTEwNDExMjIzNzU1WhcNMTQwMTA1
-MjIzNzU1WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEG
-A1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMDES
-MBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwMIGfMA0GCSqG
-SIb3DQEBAQUAA4GNADCBiQKBgQC2UENzZBJAJlQM+Wfkau0fGOVziRMPyV9ubsYF
-rSy+5Gv9xk/q828N9Bo0fwOXsKTRbpjSNvozXVE33o9bPaAHUsi3cTBx+8On+mH2
-tCi+ntqLi3DdjtClGgBwHDnhz2T47LSDuStn+k2uMIQvLJ1sd34JlUN3a+GdK8mJ
-2anljwIDAQABo4HlMIHiMB0GA1UdDgQWBBS38NtfuswQbaZkYhCEpck5TDwnhjCB
-sgYDVR0jBIGqMIGngBS38NtfuswQbaZkYhCEpck5TDwnhqGBg6SBgDB+MQswCQYD
-VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFy
-azENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMDESMBAGA1UEAxMJbG9jYWxo
-b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwggkAhvFFEjHHKyowDAYDVR0TBAUwAwEB
-/zANBgkqhkiG9w0BAQsFAAOBgQBbbXG4TuMnBtkqR6sho9+Uqdhi8WqXM8wcUlWa
-+OxttJEXTSoOA7RLAIMQjhLBBWdWmjCQka2L3ArrPyhd+dSHDfc6WvZHUp6vTiHU
-L7hAT3+BH5PKvOYExRhlXrHdCzxeOm9I4/yyyDeNnxQbpxJ5uy25/HoB72bG1MJE
-AUkjqQ==
+MIICzDCCAjWgAwIBAgIJAIbHO3WnlGybMA0GCSqGSIb3DQEBCwUAMH8xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTENMAsGA1UECwwEdGExMDESMBAGA1UEAwwJbG9jYWxo
+b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwMB4XDTEzMTIxMzAwMTMzOVoXDTE2MDkw
+ODAwMTMzOVowfzELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQ0wCwYDVQQLDAR0YTEw
+MRIwEAYDVQQDDAlsb2NhbGhvc3QxEzARBgkqhkiG9w0BCQEWBHRhMTAwgZ8wDQYJ
+KoZIhvcNAQEBBQADgY0AMIGJAoGBAKsI3kThfc+H5Q35tmZ5RUsYP8TDvDxOEBwj
+NgsXjlPpHVLA03jOdDAT2T6YjgiU/naUVXrZc4cBXt3He15WlKZd5oqrIgPP4Xoc
+fvsWwnz0o2xGKAsVFemST1Cj4wQlkW3QcS9msyBk2/FgjT9SlBPx8QCTCyC+85h9
+yFjj8OnFAgMBAAGjUDBOMB0GA1UdDgQWBBRh0t9p0mWYbjaLTqU0M6fvhF3e9DAf
+BgNVHSMEGDAWgBRh0t9p0mWYbjaLTqU0M6fvhF3e9DAMBgNVHRMEBTADAQH/MA0G
+CSqGSIb3DQEBCwUAA4GBAEhDLiFexYWxlzdyekqjwNtfxEJR0D71IEP2cmGz+48T
+cTYOjjOMFH3COe02qVXbvSTeliyyYdWVNpfkthfTpWyMlhqJVKtD8Hax9vFKDWl5
+6pU4dshbzJnKug1xfQ/QMYyUqS17kVaYoep1COr+A+AjCTIAiB6D9v7fQDx4Ja7l
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta11/ta11_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta11/ta11_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,65 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            d7:f1:84:58:4b:42:ce:33
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
+        Serial Number: 10111560406944601325 (0x8c537a9de4d654ed)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a3:c5:d4:23:f8:e8:a4:02:1f:38:cd:53:dc:7c:
-                    e8:3c:49:bd:14:c1:c7:a2:b7:00:7a:d2:d1:c8:01:
-                    7c:9b:f7:78:50:95:07:69:90:a0:7a:25:0f:55:55:
-                    f7:b2:33:ae:ae:66:64:5c:4c:86:66:e0:28:e2:63:
-                    8c:11:5f:ee:a4:af:77:86:c2:c0:18:0d:24:18:5f:
-                    26:ff:67:cc:f4:f9:7d:0c:e7:d7:0c:01:e8:85:57:
-                    f4:a8:d8:2c:f1:ec:2f:c7:8c:34:d4:3d:d3:1b:5c:
-                    2d:44:bd:d1:a6:35:d2:21:36:f9:31:ac:24:cb:ec:
-                    7b:70:c8:10:97:c8:8e:37:19
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:f3:d5:2f:b4:3e:12:ee:e5:01:6a:41:a4:09:1b:
+                    12:5f:f3:d5:a2:7e:3c:d8:6f:6f:a7:30:af:72:3d:
+                    f4:f4:31:30:94:b9:09:d8:2f:36:ba:12:61:56:8c:
+                    87:f9:52:6f:8b:b5:28:d1:23:93:f3:20:d4:b5:2d:
+                    ca:29:10:f5:10:7b:ad:d6:ee:de:40:22:d9:10:32:
+                    30:93:27:22:6d:87:f9:ed:85:16:c2:6d:da:24:51:
+                    db:1a:00:53:2b:65:4a:ce:24:0f:cf:57:f1:c0:51:
+                    9e:0c:ac:2f:17:5d:72:c1:f4:8d:83:20:41:d3:10:
+                    5f:f2:e0:2d:9f:ec:da:97:7d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                CE:A0:CF:69:A4:17:A0:54:BE:C3:CB:28:70:86:6A:BD:3B:DE:E4:CC
+                BD:98:0D:A4:4D:61:87:11:83:C8:53:D1:C9:62:9D:ED:45:61:DD:42
             X509v3 Authority Key Identifier: 
-                keyid:CE:A0:CF:69:A4:17:A0:54:BE:C3:CB:28:70:86:6A:BD:3B:DE:E4:CC
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta11/CN=localhost/emailAddress=ta11
-                serial:D7:F1:84:58:4B:42:CE:33
+                keyid:BD:98:0D:A4:4D:61:87:11:83:C8:53:D1:C9:62:9D:ED:45:61:DD:42
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        89:34:9b:f9:55:53:63:83:82:0e:d0:f1:e5:0c:e3:4e:4b:2f:
-        54:20:2b:70:00:56:08:b4:18:88:59:e2:66:3e:5c:b6:0a:74:
-        16:bc:43:61:35:1e:df:e5:f6:f6:7e:de:87:18:61:b7:70:b0:
-        93:e8:5a:19:1d:01:a7:43:ca:38:ea:d2:e2:75:0e:3e:d2:b5:
-        91:57:1e:30:29:aa:2a:26:53:1b:9e:56:ad:61:41:3c:04:bb:
-        a5:af:da:75:63:5e:bb:31:21:f9:4c:dc:d0:c2:4c:90:07:45:
-        ed:32:0d:c0:c8:e9:6f:72:b5:ae:19:f2:88:9e:50:5c:5a:34:
-        47:a9
+         36:46:25:95:5e:65:37:e1:c4:14:31:7a:2a:a8:16:c0:bf:77:
+         ae:6a:17:f6:f2:dc:7c:0c:84:52:bb:07:4c:cb:1c:4e:80:b3:
+         55:74:15:69:40:a2:54:e9:e5:f8:2e:2f:b2:c9:37:ef:3d:7f:
+         87:64:02:e3:7c:f2:ec:97:77:b4:63:77:80:c1:61:25:fb:d5:
+         e0:26:c1:89:f0:0e:5d:65:d4:ba:d7:55:7b:ce:af:77:55:65:
+         96:7a:8d:7d:e5:79:a0:88:13:7a:cf:cf:4e:4d:a8:34:2d:3b:
+         f3:b2:44:f9:8b:c9:91:44:36:0f:94:eb:45:dd:2d:03:68:3e:
+         38:2e
 -----BEGIN CERTIFICATE-----
-MIIDYDCCAsmgAwIBAgIJANfxhFhLQs4zMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQ0wCwYDVQQLEwR0YTExMRIwEAYDVQQDEwlsb2NhbGhv
-c3QxEzARBgkqhkiG9w0BCQEWBHRhMTEwHhcNMTEwNDExMjIzNzU1WhcNMTQwMTA1
-MjIzNzU1WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEG
-A1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMTES
-MBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExMIGfMA0GCSqG
-SIb3DQEBAQUAA4GNADCBiQKBgQCjxdQj+OikAh84zVPcfOg8Sb0UwceitwB60tHI
-AXyb93hQlQdpkKB6JQ9VVfeyM66uZmRcTIZm4CjiY4wRX+6kr3eGwsAYDSQYXyb/
-Z8z0+X0M59cMAeiFV/So2Czx7C/HjDTUPdMbXC1EvdGmNdIhNvkxrCTL7HtwyBCX
-yI43GQIDAQABo4HlMIHiMB0GA1UdDgQWBBTOoM9ppBegVL7Dyyhwhmq9O97kzDCB
-sgYDVR0jBIGqMIGngBTOoM9ppBegVL7Dyyhwhmq9O97kzKGBg6SBgDB+MQswCQYD
-VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFy
-azENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMTESMBAGA1UEAxMJbG9jYWxo
-b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExggkA1/GEWEtCzjMwDAYDVR0TBAUwAwEB
-/zANBgkqhkiG9w0BAQsFAAOBgQCJNJv5VVNjg4IO0PHlDONOSy9UICtwAFYItBiI
-WeJmPly2CnQWvENhNR7f5fb2ft6HGGG3cLCT6FoZHQGnQ8o46tLidQ4+0rWRVx4w
-KaoqJlMbnlatYUE8BLulr9p1Y167MSH5TNzQwkyQB0XtMg3AyOlvcrWuGfKInlBc
-WjRHqQ==
+MIICzDCCAjWgAwIBAgIJAIxTep3k1lTtMA0GCSqGSIb3DQEBCwUAMH8xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTENMAsGA1UECwwEdGExMTESMBAGA1UEAwwJbG9jYWxo
+b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExMB4XDTEzMTIxMzAwMTMzOVoXDTE2MDkw
+ODAwMTMzOVowfzELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQ0wCwYDVQQLDAR0YTEx
+MRIwEAYDVQQDDAlsb2NhbGhvc3QxEzARBgkqhkiG9w0BCQEWBHRhMTEwgZ8wDQYJ
+KoZIhvcNAQEBBQADgY0AMIGJAoGBAPPVL7Q+Eu7lAWpBpAkbEl/z1aJ+PNhvb6cw
+r3I99PQxMJS5CdgvNroSYVaMh/lSb4u1KNEjk/Mg1LUtyikQ9RB7rdbu3kAi2RAy
+MJMnIm2H+e2FFsJt2iRR2xoAUytlSs4kD89X8cBRngysLxddcsH0jYMgQdMQX/Lg
+LZ/s2pd9AgMBAAGjUDBOMB0GA1UdDgQWBBS9mA2kTWGHEYPIU9HJYp3tRWHdQjAf
+BgNVHSMEGDAWgBS9mA2kTWGHEYPIU9HJYp3tRWHdQjAMBgNVHRMEBTADAQH/MA0G
+CSqGSIb3DQEBCwUAA4GBADZGJZVeZTfhxBQxeiqoFsC/d65qF/by3HwMhFK7B0zL
+HE6As1V0FWlAolTp5fguL7LJN+89f4dkAuN88uyXd7Rjd4DBYSX71eAmwYnwDl1l
+1LrXVXvOr3dVZZZ6jX3leaCIE3rPz05NqDQtO/OyRPmLyZFENg+U60XdLQNoPjgu
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta2/ta2_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta2/ta2_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            e4:2c:84:25:53:01:eb:e0
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta2/emailAddress=ta2
+        Serial Number: 17668597499765822237 (0xf53377d054e5931d)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta2/emailAddress=ta2
         Validity
-            Not Before: Apr 11 22:37:43 2011 GMT
-            Not After : Jan  5 22:37:43 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta2/emailAddress=ta2
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta2/emailAddress=ta2
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e3:75:e1:44:6d:68:b1:dc:64:6b:a3:06:0a:3b:
-                    91:ad:10:ce:45:99:f3:ea:32:3c:92:bc:b1:85:d5:
-                    c5:62:a6:fd:3e:33:64:fb:84:6e:09:e1:c6:76:34:
-                    43:63:7f:7b:93:bc:6c:0e:31:58:b0:c0:c8:c7:b4:
-                    6e:aa:db:40:86:67:b0:2c:79:82:fb:31:1f:71:6c:
-                    10:a4:b9:0b:dd:d8:78:e4:b3:a3:af:de:c6:0f:21:
-                    fd:5c:e6:01:b6:87:82:9b:04:16:6e:42:a5:57:39:
-                    fe:85:e3:57:58:cd:fe:90:c7:d3:35:7d:91:13:bf:
-                    05:f2:21:ac:42:e7:0f:e4:e3
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ca:34:f6:15:9c:de:7d:a0:37:35:0b:50:e2:d8:
+                    5b:71:aa:30:27:c3:fb:b2:54:24:b2:7d:cc:52:a5:
+                    3d:90:1e:1c:38:d4:b4:f0:f4:b6:63:db:dc:25:c2:
+                    ab:b2:6a:b6:90:85:85:aa:5f:ed:0f:53:53:82:5c:
+                    19:63:d5:bb:fb:b3:d8:cc:3c:9b:4b:99:f1:55:58:
+                    bb:36:5d:71:6b:96:1a:2f:11:c9:8e:1e:49:bd:66:
+                    39:3f:4e:9d:30:f9:5e:7d:40:05:8f:2e:33:04:75:
+                    00:7b:dc:54:4d:b7:37:68:72:e6:f3:b7:3d:29:58:
+                    84:01:6b:98:29:ba:4c:2b:c1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                41:D6:E0:DA:6C:87:A3:44:65:CC:AB:12:C8:6C:0C:72:3A:39:90:2E
+                D2:63:03:4B:B8:08:98:F2:25:62:95:57:75:A2:F1:AA:83:E9:0B:5F
             X509v3 Authority Key Identifier: 
-                keyid:41:D6:E0:DA:6C:87:A3:44:65:CC:AB:12:C8:6C:0C:72:3A:39:90:2E
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta2/emailAddress=ta2
-                serial:E4:2C:84:25:53:01:EB:E0
+                keyid:D2:63:03:4B:B8:08:98:F2:25:62:95:57:75:A2:F1:AA:83:E9:0B:5F
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        b1:c5:14:e7:5f:ca:f0:de:3b:c5:f6:10:7c:5c:8a:63:a1:f6:
-        07:4b:9d:9f:53:a9:c8:5c:d7:01:d1:df:6c:20:5c:f5:13:a2:
-        bc:5a:65:4a:b2:f9:25:7a:28:1b:4a:03:14:d5:e9:df:36:58:
-        e9:2e:d1:48:f9:89:7f:2c:04:a5:80:01:38:b5:b9:68:01:f8:
-        78:65:38:af:33:2f:fa:17:61:e4:fd:73:f8:a4:f7:b5:f5:f5:
-        d6:b9:94:3a:32:70:37:b1:e8:58:84:58:92:6c:6a:57:da:84:
-        a5:f5:a9:7e:c1:10:6d:54:fb:82:f9:59:8a:6b:23:5d:33:3a:
-        97:2d
+         40:4c:5f:92:42:4b:a1:21:e1:76:e1:87:1c:42:1f:15:bd:08:
+         4b:bd:ec:a8:8d:6f:d8:f4:2a:df:5d:f8:4c:df:6a:ea:5f:07:
+         ce:00:0a:06:88:60:9c:32:13:4f:e5:99:99:90:56:bc:91:7a:
+         5b:e2:2f:f6:90:e9:97:11:6c:ff:7c:aa:32:37:60:95:0b:b5:
+         b1:99:ec:1d:62:26:51:2f:b9:a2:f1:d2:ed:89:e4:52:c7:fa:
+         9b:62:d3:92:c4:33:c7:95:cb:4c:23:02:2d:af:bf:0e:58:26:
+         24:b7:b7:1c:f2:f4:88:3a:12:36:40:e5:58:5a:25:db:24:f0:
+         dd:9d
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAOQshCVTAevgMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTIxEjAQBgkqhkiG9w0BCQEWA3Rh
-MjAeFw0xMTA0MTEyMjM3NDNaFw0xNDAxMDUyMjM3NDNaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTIxEjAQBgkqhkiG9w0BCQEWA3RhMjCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA43XhRG1osdxka6MGCjuRrRDORZnz6jI8
-kryxhdXFYqb9PjNk+4RuCeHGdjRDY397k7xsDjFYsMDIx7RuqttAhmewLHmC+zEf
-cWwQpLkL3dh45LOjr97GDyH9XOYBtoeCmwQWbkKlVzn+heNXWM3+kMfTNX2RE78F
-8iGsQucP5OMCAwEAAaOBzTCByjAdBgNVHQ4EFgQUQdbg2myHo0RlzKsSyGwMcjo5
-kC4wgZoGA1UdIwSBkjCBj4AUQdbg2myHo0RlzKsSyGwMcjo5kC6hbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTIxEjAQBgkqhkiG9w0BCQEW
-A3RhMoIJAOQshCVTAevgMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-scUU51/K8N47xfYQfFyKY6H2B0udn1OpyFzXAdHfbCBc9ROivFplSrL5JXooG0oD
-FNXp3zZY6S7RSPmJfywEpYABOLW5aAH4eGU4rzMv+hdh5P1z+KT3tfX11rmUOjJw
-N7HoWIRYkmxqV9qEpfWpfsEQbVT7gvlZimsjXTM6ly0=
+MIICoDCCAgmgAwIBAgIJAPUzd9BU5ZMdMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEyMRIwEAYJKoZIhvcNAQkBFgN0
+YTIwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMjESMBAGCSqGSIb3DQEJARYDdGEyMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDKNPYVnN59oDc1C1Di2FtxqjAnw/uy
+VCSyfcxSpT2QHhw41LTw9LZj29wlwquyaraQhYWqX+0PU1OCXBlj1bv7s9jMPJtL
+mfFVWLs2XXFrlhovEcmOHkm9Zjk/Tp0w+V59QAWPLjMEdQB73FRNtzdocubztz0p
+WIQBa5gpukwrwQIDAQABo1AwTjAdBgNVHQ4EFgQU0mMDS7gImPIlYpVXdaLxqoPp
+C18wHwYDVR0jBBgwFoAU0mMDS7gImPIlYpVXdaLxqoPpC18wDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQBATF+SQkuhIeF24YccQh8VvQhLveyojW/Y9Crf
+XfhM32rqXwfOAAoGiGCcMhNP5ZmZkFa8kXpb4i/2kOmXEWz/fKoyN2CVC7Wxmewd
+YiZRL7mi8dLtieRSx/qbYtOSxDPHlctMIwItr78OWCYkt7cc8vSIOhI2QOVYWiXb
+JPDdnQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta3/ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta3/ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            f4:58:54:6a:83:22:66:e9
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+        Serial Number: 13890425601977148222 (0xc0c4b47d88d6e33e)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
-            Not Before: Apr 11 22:37:43 2011 GMT
-            Not After : Jan  5 22:37:43 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d0:b0:e7:c0:27:96:d6:ff:16:89:f4:4c:67:d5:
-                    23:57:a6:af:fe:f3:be:d9:1e:28:44:a6:a3:0e:67:
-                    09:1f:b2:fc:70:fd:2c:4a:9c:13:a0:cf:37:97:2c:
-                    39:7c:42:a4:f7:64:7e:be:49:67:05:01:b3:f7:46:
-                    34:9b:d8:bd:4b:ac:d6:40:96:5a:6d:a0:33:ae:03:
-                    33:22:7d:06:39:6e:0a:5e:39:3f:e6:eb:c7:f9:e3:
-                    1a:a7:dd:16:14:6d:8e:b7:84:d9:af:b7:43:db:5d:
-                    0f:2b:e8:3d:fe:66:d7:9e:3a:06:a1:9f:c3:35:81:
-                    d4:cd:bc:16:3c:a2:c1:dd:89
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cc:99:d3:8e:88:a3:54:f1:da:a6:39:be:69:28:
+                    5a:87:05:0b:04:59:41:21:39:40:8a:46:fd:f5:20:
+                    d5:6b:b6:02:cd:5f:62:2e:88:34:8b:3d:f1:c0:fe:
+                    38:f7:f6:1f:65:10:d7:0c:03:4c:90:17:f7:25:a4:
+                    62:eb:80:83:44:1f:b2:53:a4:de:c5:d2:17:7e:f6:
+                    96:fe:e2:1a:bc:45:97:dc:29:f9:46:70:11:8d:4a:
+                    f4:b6:b7:2d:67:20:8f:d0:6a:0f:20:09:ff:7c:11:
+                    1c:94:9b:5e:83:57:67:35:2e:37:a2:54:97:2a:fb:
+                    d1:38:64:d5:e0:79:2f:ae:2f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
+                B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        26:1b:34:03:12:d5:13:94:0f:f8:57:6a:47:d8:d9:81:78:0b:
-        65:f1:51:b7:4e:b2:89:c2:6a:30:5d:37:ad:35:91:16:48:5f:
-        9b:b9:cd:30:1e:0e:f3:31:1e:7a:4e:72:13:c6:e4:66:0a:a9:
-        a4:66:5d:f6:fe:21:51:0f:ab:fd:d7:9d:5d:13:86:07:df:1d:
-        9d:d8:19:ce:6d:e9:7e:7a:19:06:20:07:cc:d1:a3:c2:04:28:
-        b8:9b:41:23:65:92:47:86:ee:ac:a5:7f:b7:2c:92:67:87:83:
-        5b:04:d0:e5:5d:3c:4c:a1:51:e0:9c:02:9a:d5:35:b4:7b:e0:
-        e4:c3
+         22:83:f2:64:c1:e3:e1:67:e4:55:ef:3b:0c:37:93:e9:c1:d7:
+         3f:0e:74:f1:03:59:1d:88:03:dd:d0:f5:38:40:c1:f3:da:93:
+         ff:c9:3f:6c:e8:14:ea:87:7f:25:34:3d:93:81:05:7d:89:70:
+         d2:18:50:17:a9:df:dd:c9:b2:88:80:7d:ed:3c:c5:8d:30:6d:
+         56:c8:f6:df:58:82:b5:76:0c:ab:e9:2d:78:be:1a:d2:e6:8e:
+         85:3f:00:6c:12:bf:d9:99:e1:dc:12:67:e0:57:9c:56:1e:2d:
+         e5:39:04:82:c2:a6:e0:ca:88:60:74:a2:1a:2a:2b:f4:a5:e9:
+         8e:07
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAPRYVGqDImbpMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEWA3Rh
-MzAeFw0xMTA0MTEyMjM3NDNaFw0xNDAxMDUyMjM3NDNaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEWA3RhMzCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA0LDnwCeW1v8WifRMZ9UjV6av/vO+2R4o
-RKajDmcJH7L8cP0sSpwToM83lyw5fEKk92R+vklnBQGz90Y0m9i9S6zWQJZabaAz
-rgMzIn0GOW4KXjk/5uvH+eMap90WFG2Ot4TZr7dD210PK+g9/mbXnjoGoZ/DNYHU
-zbwWPKLB3YkCAwEAAaOBzTCByjAdBgNVHQ4EFgQUevZRen+bqzc9TpMDkG1qhAl8
-Ot0wgZoGA1UdIwSBkjCBj4AUevZRen+bqzc9TpMDkG1qhAl8Ot2hbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEW
-A3RhM4IJAPRYVGqDImbpMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-Jhs0AxLVE5QP+FdqR9jZgXgLZfFRt06yicJqMF03rTWRFkhfm7nNMB4O8zEeek5y
-E8bkZgqppGZd9v4hUQ+r/dedXROGB98dndgZzm3pfnoZBiAHzNGjwgQouJtBI2WS
-R4burKV/tyySZ4eDWwTQ5V08TKFR4JwCmtU1tHvg5MM=
+MIICoDCCAgmgAwIBAgIJAMDEtH2I1uM+MA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZIhvcNAQkBFgN0
+YTMwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMmdOOiKNU8dqmOb5pKFqHBQsEWUEh
+OUCKRv31INVrtgLNX2IuiDSLPfHA/jj39h9lENcMA0yQF/clpGLrgINEH7JTpN7F
+0hd+9pb+4hq8RZfcKflGcBGNSvS2ty1nII/Qag8gCf98ERyUm16DV2c1LjeiVJcq
++9E4ZNXgeS+uLwIDAQABo1AwTjAdBgNVHQ4EFgQUtNQ2n/jLol9Qidoh4yfEkfeE
+iEUwHwYDVR0jBBgwFoAUtNQ2n/jLol9Qidoh4yfEkfeEiEUwDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQAig/JkwePhZ+RV7zsMN5Ppwdc/DnTxA1kdiAPd
+0PU4QMHz2pP/yT9s6BTqh38lND2TgQV9iXDSGFAXqd/dybKIgH3tPMWNMG1WyPbf
+WIK1dgyr6S14vhrS5o6FPwBsEr/ZmeHcEmfgV5xWHi3lOQSCwqbgyohgdKIaKiv0
+pemOBw==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta4/ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta4/ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            ba:06:fd:ec:89:18:b5:7f
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+        Serial Number: 16787041411903739357 (0xe8f78d38fa4b55dd)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Validity
-            Not Before: Apr 11 22:37:49 2011 GMT
-            Not After : Jan  5 22:37:49 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cf:c0:25:a7:fa:df:a4:e4:02:33:84:4d:a0:3f:
-                    4e:09:c4:ae:0a:58:d3:45:15:d3:5e:94:56:5a:b5:
-                    da:3e:27:68:66:3d:b1:83:14:bc:13:94:f3:a8:38:
-                    9c:e8:9a:46:4e:06:78:0d:29:95:69:a0:2c:12:19:
-                    3b:6b:a6:3d:46:eb:56:8a:f7:85:2d:d9:9c:f0:30:
-                    6b:0a:03:8d:ae:d8:cf:9e:df:c9:a5:d7:d3:b1:ab:
-                    13:74:e8:1e:a2:be:31:3f:17:78:22:4c:83:8b:24:
-                    ef:4f:5d:c4:6e:26:f8:b0:d9:2b:ad:9e:b0:c4:fc:
-                    c2:00:10:99:e9:39:17:68:05
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:a1:63:5b:f9:78:2a:19:df:d1:4e:d5:75:24:c6:
+                    8b:2f:e9:69:99:ab:82:24:b4:0f:66:ec:4c:c1:7a:
+                    bd:a4:5c:10:f1:61:c7:fe:2f:53:c1:10:8e:7c:83:
+                    4b:c5:50:ca:20:9e:aa:25:41:39:19:0e:7a:99:1a:
+                    8a:25:9b:df:67:b6:67:68:ad:f2:22:15:e8:e6:dd:
+                    3a:77:4a:b9:6f:e1:0a:70:92:0e:dd:a8:e7:62:e7:
+                    a3:3a:fe:ca:75:b4:2d:2c:60:cd:ae:87:fc:ba:27:
+                    c1:0d:85:b1:cc:7f:d9:f3:0f:7d:cb:3e:15:70:54:
+                    e1:2e:8a:88:9d:e7:05:57:47
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
+                84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
             X509v3 Authority Key Identifier: 
-                keyid:3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
-                serial:BA:06:FD:EC:89:18:B5:7F
+                keyid:84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        c2:01:c5:40:3c:24:aa:8a:f3:be:31:f8:82:12:df:b8:e7:b4:
-        92:b1:95:79:d4:f7:db:2a:81:a2:f6:5f:3a:1d:b1:e2:a1:bd:
-        f1:50:75:cc:d6:f7:ab:26:d6:eb:a8:c6:f8:44:25:53:94:ce:
-        6e:a4:6e:4f:40:c2:13:00:b7:cb:b1:82:99:e9:1f:68:54:d0:
-        69:ba:02:5f:07:be:c2:f8:e3:2c:40:73:61:c2:c3:ad:4c:91:
-        f0:ba:0a:61:df:95:d6:fc:d3:19:e3:98:8e:58:73:03:6f:04:
-        9e:b6:f7:8c:3c:1e:60:43:27:96:6d:f5:e7:31:43:bb:22:da:
-        07:9c
+         07:ae:c1:fc:3b:d3:b3:b5:02:32:28:cb:49:f5:dc:fe:2d:9f:
+         21:09:78:85:f7:97:e6:cc:03:b4:08:de:04:a1:64:75:fe:94:
+         a8:48:0f:b9:20:11:b8:ba:2e:f1:c4:7f:03:10:0b:1c:f1:ed:
+         1e:c8:04:b6:28:34:99:61:57:4d:f0:fc:6b:81:f7:a3:8b:74:
+         5a:5f:f7:1d:68:29:ef:5e:cd:b5:ee:2a:72:17:be:db:a4:26:
+         7d:ab:4b:09:85:66:bf:ff:94:56:b5:e1:67:f4:0f:dd:88:50:
+         10:d6:98:96:51:ac:2c:24:8c:83:21:5a:8a:12:0f:e2:58:8f:
+         ef:07
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJALoG/eyJGLV/MA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEWA3Rh
-NDAeFw0xMTA0MTEyMjM3NDlaFw0xNDAxMDUyMjM3NDlaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEWA3RhNDCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAz8Alp/rfpOQCM4RNoD9OCcSuCljTRRXT
-XpRWWrXaPidoZj2xgxS8E5TzqDic6JpGTgZ4DSmVaaAsEhk7a6Y9RutWiveFLdmc
-8DBrCgONrtjPnt/JpdfTsasTdOgeor4xPxd4IkyDiyTvT13Ebib4sNkrrZ6wxPzC
-ABCZ6TkXaAUCAwEAAaOBzTCByjAdBgNVHQ4EFgQUPl9k6WPLnBDQkfRFYfLx6kJp
-7KUwgZoGA1UdIwSBkjCBj4AUPl9k6WPLnBDQkfRFYfLx6kJp7KWhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEW
-A3RhNIIJALoG/eyJGLV/MAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-wgHFQDwkqorzvjH4ghLfuOe0krGVedT32yqBovZfOh2x4qG98VB1zNb3qybW66jG
-+EQlU5TObqRuT0DCEwC3y7GCmekfaFTQaboCXwe+wvjjLEBzYcLDrUyR8LoKYd+V
-1vzTGeOYjlhzA28Enrb3jDweYEMnlm315zFDuyLaB5w=
+MIICoDCCAgmgAwIBAgIJAOj3jTj6S1XdMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGE0MRIwEAYJKoZIhvcNAQkBFgN0
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhNDESMBAGCSqGSIb3DQEJARYDdGE0MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQChY1v5eCoZ39FO1XUkxosv6WmZq4Ik
+tA9m7EzBer2kXBDxYcf+L1PBEI58g0vFUMognqolQTkZDnqZGoolm99ntmdorfIi
+Fejm3Tp3Srlv4Qpwkg7dqOdi56M6/sp1tC0sYM2uh/y6J8ENhbHMf9nzD33LPhVw
+VOEuioid5wVXRwIDAQABo1AwTjAdBgNVHQ4EFgQUhEYpiHQx76bMPONYKd6+/Rv0
+WZgwHwYDVR0jBBgwFoAUhEYpiHQx76bMPONYKd6+/Rv0WZgwDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQAHrsH8O9OztQIyKMtJ9dz+LZ8hCXiF95fmzAO0
+CN4EoWR1/pSoSA+5IBG4ui7xxH8DEAsc8e0eyAS2KDSZYVdN8Pxrgfeji3RaX/cd
+aCnvXs217ipyF77bpCZ9q0sJhWa//5RWteFn9A/diFAQ1piWUawsJIyDIVqKEg/i
+WI/vBw==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta5/ta5_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta5/ta5_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            9c:19:39:11:06:1a:55:91
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta5/emailAddress=ta5
+        Serial Number: 12074133414322946630 (0xa78ff05e6b64c246)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta5/emailAddress=ta5
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta5/emailAddress=ta5
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta5/emailAddress=ta5
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c4:65:70:7a:0e:03:ae:85:f3:d6:03:6f:f9:a2:
-                    af:4e:ae:cd:d4:99:b6:6d:14:a4:12:62:54:1f:8b:
-                    c6:d3:8c:e8:7e:85:82:a5:f5:c9:03:66:f6:dd:48:
-                    58:5a:7a:20:c6:1d:7b:47:78:52:64:3f:0a:67:d0:
-                    cc:03:aa:2b:00:b5:89:7b:b1:50:fb:79:e1:d5:32:
-                    8c:c3:49:df:ba:2a:21:43:cb:c5:39:39:12:bd:3a:
-                    ba:7b:29:f2:48:32:37:84:c6:af:66:db:a2:a4:00:
-                    ec:40:08:c1:a8:36:0c:b6:48:c6:39:b1:fd:be:e2:
-                    60:a4:3d:c6:b6:b1:a8:be:55
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b7:a8:13:3d:f3:64:60:87:d9:bd:d0:92:59:74:
+                    b9:dc:27:f8:40:15:39:9a:30:52:0f:73:5d:45:d8:
+                    b9:a1:9a:72:56:e2:85:1a:c0:18:8c:90:56:44:14:
+                    e5:50:70:69:e5:36:5b:a2:fb:3c:bf:f9:78:77:27:
+                    2d:de:3c:5e:3c:7d:d2:40:02:8b:bc:04:9b:8f:65:
+                    0b:74:3a:98:23:4d:e1:0d:4d:c3:42:cb:61:a8:42:
+                    bf:b2:1c:83:18:89:4f:b4:cf:cf:34:fd:f3:c7:7e:
+                    1b:54:3e:ed:e9:0a:13:8c:c2:56:f6:25:87:42:40:
+                    a3:ca:ab:ff:cc:ba:c6:c2:0d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                E7:E6:72:5B:A0:5F:2C:A6:40:45:1A:66:E4:45:A5:0F:1D:67:5D:93
+                29:DA:B1:46:E3:61:51:AC:3C:3E:F6:78:5B:95:7B:6D:B2:F9:17:21
             X509v3 Authority Key Identifier: 
-                keyid:E7:E6:72:5B:A0:5F:2C:A6:40:45:1A:66:E4:45:A5:0F:1D:67:5D:93
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta5/emailAddress=ta5
-                serial:9C:19:39:11:06:1A:55:91
+                keyid:29:DA:B1:46:E3:61:51:AC:3C:3E:F6:78:5B:95:7B:6D:B2:F9:17:21
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        89:2d:87:d4:a5:2a:63:ce:4d:12:6f:ca:94:d3:e9:ac:3e:93:
-        30:f3:1a:20:05:9d:8c:72:7c:70:ea:00:c9:b6:39:d8:5a:d1:
-        87:1e:57:8f:2f:61:f1:ec:a8:f2:b9:2b:03:d5:0c:07:e4:f5:
-        01:8d:00:95:fd:9c:12:d0:86:3f:8d:cf:3a:5b:ae:2d:a2:6f:
-        2d:ee:a6:10:6f:f0:d0:5f:dd:78:02:3e:1f:0d:f3:ae:a2:fa:
-        c5:9d:96:ae:31:a8:a3:ba:a4:78:a8:ec:db:e7:61:de:d3:5c:
-        c4:c2:4d:5c:b4:cb:f8:27:6e:53:06:11:e0:e7:aa:41:7f:bd:
-        9a:8a
+         21:28:62:ac:b3:da:3a:66:ed:13:bc:72:15:0d:44:87:25:c9:
+         8e:0d:37:cf:b9:2b:3b:64:30:6f:67:6e:b7:6a:6e:c7:12:f9:
+         68:9c:78:cd:de:72:fe:05:bb:59:58:47:93:c3:f7:41:fe:30:
+         44:53:57:9a:6c:3e:6c:a4:c9:68:a1:5b:80:b1:3c:e7:e9:c1:
+         11:11:99:ad:60:24:0e:ca:17:56:d2:48:db:c5:9a:3f:f1:92:
+         01:a7:5a:2a:d0:6e:2e:6c:20:3d:97:ba:2e:b1:00:a1:6f:1b:
+         14:83:dd:32:3c:fd:18:c7:b2:85:b8:a6:03:98:fa:eb:d1:45:
+         4e:f9
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAJwZOREGGlWRMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTUxEjAQBgkqhkiG9w0BCQEWA3Rh
-NTAeFw0xMTA0MTEyMjM3NTJaFw0xNDAxMDUyMjM3NTJaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTUxEjAQBgkqhkiG9w0BCQEWA3RhNTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxGVweg4DroXz1gNv+aKvTq7N1Jm2bRSk
-EmJUH4vG04zofoWCpfXJA2b23UhYWnogxh17R3hSZD8KZ9DMA6orALWJe7FQ+3nh
-1TKMw0nfuiohQ8vFOTkSvTq6eynySDI3hMavZtuipADsQAjBqDYMtkjGObH9vuJg
-pD3GtrGovlUCAwEAAaOBzTCByjAdBgNVHQ4EFgQU5+ZyW6BfLKZARRpm5EWlDx1n
-XZMwgZoGA1UdIwSBkjCBj4AU5+ZyW6BfLKZARRpm5EWlDx1nXZOhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTUxEjAQBgkqhkiG9w0BCQEW
-A3RhNYIJAJwZOREGGlWRMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-iS2H1KUqY85NEm/KlNPprD6TMPMaIAWdjHJ8cOoAybY52FrRhx5Xjy9h8eyo8rkr
-A9UMB+T1AY0Alf2cEtCGP43POluuLaJvLe6mEG/w0F/deAI+Hw3zrqL6xZ2WrjGo
-o7qkeKjs2+dh3tNcxMJNXLTL+CduUwYR4OeqQX+9moo=
+MIICoDCCAgmgAwIBAgIJAKeP8F5rZMJGMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGE1MRIwEAYJKoZIhvcNAQkBFgN0
+YTUwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhNTESMBAGCSqGSIb3DQEJARYDdGE1MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3qBM982Rgh9m90JJZdLncJ/hAFTma
+MFIPc11F2LmhmnJW4oUawBiMkFZEFOVQcGnlNlui+zy/+Xh3Jy3ePF48fdJAAou8
+BJuPZQt0OpgjTeENTcNCy2GoQr+yHIMYiU+0z880/fPHfhtUPu3pChOMwlb2JYdC
+QKPKq//MusbCDQIDAQABo1AwTjAdBgNVHQ4EFgQUKdqxRuNhUaw8PvZ4W5V7bbL5
+FyEwHwYDVR0jBBgwFoAUKdqxRuNhUaw8PvZ4W5V7bbL5FyEwDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQAhKGKss9o6Zu0TvHIVDUSHJcmODTfPuSs7ZDBv
+Z263am7HEvlonHjN3nL+BbtZWEeTw/dB/jBEU1eabD5spMlooVuAsTzn6cEREZmt
+YCQOyhdW0kjbxZo/8ZIBp1oq0G4ubCA9l7ousQChbxsUg90yPP0Yx7KFuKYDmPrr
+0UVO+Q==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta6/ta6_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta6/ta6_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            93:ae:7e:2d:c9:61:8f:4b
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+        Serial Number: 14039479151502690113 (0xc2d63fe768d20741)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c5:41:a2:3d:00:af:e2:71:29:e6:18:c2:73:65:
-                    fc:4a:9d:e3:f7:1a:6e:7a:f5:09:81:87:cd:cf:a9:
-                    74:a9:e4:47:da:e2:fa:bd:0e:0a:ae:ba:06:e8:1b:
-                    66:e3:8a:5e:bb:87:90:5e:d1:38:7d:12:93:72:a0:
-                    4b:88:77:dd:ce:02:67:9f:c5:be:49:cb:b7:e8:0e:
-                    bd:f0:78:37:55:bb:c5:91:6e:c7:7b:9c:b3:94:a2:
-                    24:7d:09:25:74:52:22:6d:4a:34:f8:92:71:b1:e9:
-                    74:9b:8e:87:d4:2a:46:f8:fa:8f:86:5c:b5:6b:20:
-                    24:d1:37:ea:8a:87:07:e3:ad
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c5:43:65:b9:e0:b5:bf:68:f6:d0:67:91:49:1f:
+                    53:c8:eb:36:57:b9:76:c9:d7:2d:26:4c:f2:08:38:
+                    e6:5d:56:b6:20:af:72:ea:ac:98:de:14:cd:35:ed:
+                    f9:b3:fb:e3:c4:1f:06:db:04:77:2a:cd:3e:3e:98:
+                    9f:52:f1:9e:27:db:91:ec:f4:de:3e:53:d5:fc:ba:
+                    5c:37:98:8b:b7:45:4c:bb:a9:d0:cc:b5:f8:45:a4:
+                    0c:58:a0:92:60:05:26:01:96:08:c1:8d:5f:18:e8:
+                    84:f1:d0:a2:f1:e3:32:67:20:52:a6:6f:7a:47:39:
+                    f1:f0:c0:47:6f:3b:9e:7c:81
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                0C:08:1A:2C:FA:77:26:CE:37:0F:A5:85:98:85:0F:4D:48:BA:83:B3
+                75:D7:5E:D6:65:E8:AA:54:31:F5:3A:5C:DA:C8:EE:5C:02:46:28:26
             X509v3 Authority Key Identifier: 
-                keyid:0C:08:1A:2C:FA:77:26:CE:37:0F:A5:85:98:85:0F:4D:48:BA:83:B3
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta6/CN=localhost/emailAddress=ta6
-                serial:93:AE:7E:2D:C9:61:8F:4B
+                keyid:75:D7:5E:D6:65:E8:AA:54:31:F5:3A:5C:DA:C8:EE:5C:02:46:28:26
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        10:2c:ed:b9:a4:aa:bd:9e:4d:47:dd:02:64:52:a9:7a:73:a7:
-        f3:58:45:cf:da:5c:1e:80:30:d9:10:a7:e4:79:d2:eb:85:8b:
-        70:4c:39:df:b6:40:fb:7f:11:cd:a8:85:d6:5c:d1:2f:29:9f:
-        8d:fa:53:bc:20:f3:c8:97:9b:11:f4:7d:39:9a:2c:a6:6e:1e:
-        a4:0d:81:e0:65:59:89:f6:a9:66:65:38:05:44:e7:47:a2:9e:
-        a2:e3:82:07:2c:cb:8e:dc:47:a2:e9:cb:01:6a:54:c1:26:14:
-        03:e9:c3:ac:fe:98:0e:76:52:f3:5b:67:ea:26:0d:98:6d:e4:
-        23:ac
+         c0:55:58:54:3d:b7:dd:d8:c4:3f:35:a4:d9:25:b3:45:08:f3:
+         5b:98:16:46:40:36:01:c9:60:d4:a6:2b:9e:29:6d:89:26:d7:
+         4e:69:35:ba:15:b2:d1:1a:5e:97:ad:b3:16:33:c5:5b:4f:4f:
+         0e:8d:8e:b3:28:50:00:ad:88:2a:2c:60:d3:66:7c:66:95:f9:
+         83:0a:ae:14:8b:d8:42:35:8d:50:7f:b2:23:1f:9b:28:ca:de:
+         61:b8:6d:c5:38:4a:e1:60:da:75:42:f3:18:4c:14:ae:b0:5d:
+         a9:ab:ae:10:89:09:cc:61:1e:ce:28:95:f0:44:98:33:04:9c:
+         db:8f
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAJOufi3JYY9LMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTYxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE2MB4XDTExMDQxMTIyMzc1MloXDTE0MDEwNTIy
-Mzc1MlowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNjESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTYwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAMVBoj0Ar+JxKeYYwnNl/Eqd4/cabnr1CYGHzc+pdKnk
-R9ri+r0OCq66BugbZuOKXruHkF7ROH0Sk3KgS4h33c4CZ5/FvknLt+gOvfB4N1W7
-xZFux3ucs5SiJH0JJXRSIm1KNPiScbHpdJuOh9QqRvj6j4ZctWsgJNE36oqHB+Ot
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFAwIGiz6dybONw+lhZiFD01IuoOzMIGvBgNV
-HSMEgacwgaSAFAwIGiz6dybONw+lhZiFD01IuoOzoYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNjESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTaCCQCTrn4tyWGPSzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBABAs7bmkqr2eTUfdAmRSqXpzp/NYRc/aXB6AMNkQp+R50uuF
-i3BMOd+2QPt/Ec2ohdZc0S8pn436U7wg88iXmxH0fTmaLKZuHqQNgeBlWYn2qWZl
-OAVE50einqLjggcsy47cR6LpywFqVMEmFAPpw6z+mA52UvNbZ+omDZht5COs
+MIICyDCCAjGgAwIBAgIJAMLWP+do0gdBMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE2MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhNjAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE2MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhNjCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAxUNlueC1v2j20GeRSR9TyOs2V7l2ydctJkzyCDjm
+XVa2IK9y6qyY3hTNNe35s/vjxB8G2wR3Ks0+PpifUvGeJ9uR7PTePlPV/LpcN5iL
+t0VMu6nQzLX4RaQMWKCSYAUmAZYIwY1fGOiE8dCi8eMyZyBSpm96Rznx8MBHbzue
+fIECAwEAAaNQME4wHQYDVR0OBBYEFHXXXtZl6KpUMfU6XNrI7lwCRigmMB8GA1Ud
+IwQYMBaAFHXXXtZl6KpUMfU6XNrI7lwCRigmMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAwFVYVD233djEPzWk2SWzRQjzW5gWRkA2Aclg1KYrniltiSbX
+Tmk1uhWy0Rpel62zFjPFW09PDo2OsyhQAK2IKixg02Z8ZpX5gwquFIvYQjWNUH+y
+Ix+bKMreYbhtxThK4WDadULzGEwUrrBdqauuEIkJzGEeziiV8ESYMwSc248=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta7/ta7_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta7/ta7_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            e2:68:f4:95:eb:49:89:87
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
+        Serial Number: 17133169234141367739 (0xedc53ea49da5cdbb)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c8:de:52:36:7b:6e:4b:6d:7a:83:73:ad:41:cd:
-                    af:36:02:62:36:3e:f7:55:07:11:24:43:c2:eb:43:
-                    e4:6f:1d:3c:ec:73:4b:81:58:a2:2a:7e:e0:c4:f0:
-                    9a:ae:04:d8:2a:49:39:bf:9e:e8:ad:f0:96:52:5e:
-                    3c:67:71:7f:3d:40:d7:36:e3:1c:25:da:0b:29:e9:
-                    8b:81:66:19:bc:34:38:1a:4e:cb:63:f5:30:cf:82:
-                    6c:f5:14:cc:df:bb:cc:ed:70:86:e4:ba:6e:db:85:
-                    ce:60:d1:69:37:48:e8:0c:c0:76:82:0f:5f:65:09:
-                    62:0d:72:c9:5a:b3:49:2c:fd
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:f9:53:0d:ea:ab:4d:2f:d9:fa:75:3c:f6:57:80:
+                    d1:92:29:44:be:db:7d:6d:5e:f7:4e:a1:76:83:b3:
+                    31:a5:40:3e:44:d0:8e:2e:37:f9:6c:3e:28:4f:1e:
+                    52:66:eb:e9:4c:52:e9:7f:94:e3:9f:2c:e4:65:c3:
+                    fc:27:9b:2e:42:81:3e:0d:13:bb:58:52:f6:50:b6:
+                    f5:ef:2e:ac:94:52:4e:4a:a9:1a:e7:19:0e:2b:4a:
+                    46:59:57:de:a4:65:55:43:70:57:52:55:95:e4:17:
+                    5d:cf:0d:e4:3b:f7:42:4b:ce:25:9d:21:3e:41:29:
+                    30:c1:22:b2:77:85:7a:83:fd
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                78:FA:1D:E8:35:33:AD:40:EB:A9:B4:3E:87:7A:B0:65:17:CF:36:35
+                45:9D:B1:D7:6F:E2:FD:4F:9C:E9:10:78:EE:E7:33:1A:14:E1:AF:9D
             X509v3 Authority Key Identifier: 
-                keyid:78:FA:1D:E8:35:33:AD:40:EB:A9:B4:3E:87:7A:B0:65:17:CF:36:35
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta7/CN=localhost/emailAddress=ta7
-                serial:E2:68:F4:95:EB:49:89:87
+                keyid:45:9D:B1:D7:6F:E2:FD:4F:9C:E9:10:78:EE:E7:33:1A:14:E1:AF:9D
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        07:20:33:b6:af:9e:b1:49:90:57:19:86:e9:8b:18:8a:e9:7b:
-        b1:b4:ff:29:5e:de:df:c9:f9:c8:7d:de:61:0d:36:fc:55:dc:
-        e7:51:ff:89:b5:69:07:72:60:b6:19:4e:c4:90:e6:e7:c1:0e:
-        56:ba:d6:1c:c7:34:10:38:2d:c5:71:79:8a:de:a6:b2:d6:cf:
-        98:dc:9a:3e:df:d3:57:67:bd:15:83:95:00:1c:2d:45:9c:73:
-        6d:82:57:9d:ac:57:f1:d8:39:ae:92:3b:ff:36:a1:0e:08:46:
-        e6:00:a9:d6:3e:5b:fa:65:7f:8c:c6:ee:4e:84:e0:a8:81:b7:
-        3c:a5
+         b3:53:c9:a1:7f:13:e8:4b:ff:f0:81:84:9a:8c:1d:44:ef:3c:
+         fb:a8:e6:0d:62:9b:0f:f9:a9:c9:ca:4b:26:2e:51:6d:f3:ac:
+         b9:9e:2c:10:96:1c:f7:80:ff:5e:30:4f:a0:67:9b:84:3e:bc:
+         b5:6f:78:42:02:12:d9:e6:4f:a3:a0:82:eb:bf:00:44:b3:6f:
+         2f:56:c3:36:03:d1:b9:b9:e5:3c:53:3a:17:69:af:42:91:fa:
+         b5:91:b2:06:7f:07:88:e7:ac:7a:2b:b7:c3:41:e8:7d:9b:96:
+         c9:3d:38:4a:4c:39:45:35:c1:43:05:b2:32:00:99:22:72:2a:
+         7c:00
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAOJo9JXrSYmHMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTcxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE3MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNzESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTcwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAMjeUjZ7bktteoNzrUHNrzYCYjY+91UHESRDwutD5G8d
-POxzS4FYoip+4MTwmq4E2CpJOb+e6K3wllJePGdxfz1A1zbjHCXaCynpi4FmGbw0
-OBpOy2P1MM+CbPUUzN+7zO1whuS6btuFzmDRaTdI6AzAdoIPX2UJYg1yyVqzSSz9
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFHj6Heg1M61A66m0Pod6sGUXzzY1MIGvBgNV
-HSMEgacwgaSAFHj6Heg1M61A66m0Pod6sGUXzzY1oYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNzESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTeCCQDiaPSV60mJhzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAAcgM7avnrFJkFcZhumLGIrpe7G0/yle3t/J+ch93mENNvxV
-3OdR/4m1aQdyYLYZTsSQ5ufBDla61hzHNBA4LcVxeYreprLWz5jcmj7f01dnvRWD
-lQAcLUWcc22CV52sV/HYOa6SO/82oQ4IRuYAqdY+W/plf4zG7k6E4KiBtzyl
+MIICyDCCAjGgAwIBAgIJAO3FPqSdpc27MA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE3MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhNzAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE3MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhNzCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEA+VMN6qtNL9n6dTz2V4DRkilEvtt9bV73TqF2g7Mx
+pUA+RNCOLjf5bD4oTx5SZuvpTFLpf5TjnyzkZcP8J5suQoE+DRO7WFL2ULb17y6s
+lFJOSqka5xkOK0pGWVfepGVVQ3BXUlWV5Bddzw3kO/dCS84lnSE+QSkwwSKyd4V6
+g/0CAwEAAaNQME4wHQYDVR0OBBYEFEWdsddv4v1PnOkQeO7nMxoU4a+dMB8GA1Ud
+IwQYMBaAFEWdsddv4v1PnOkQeO7nMxoU4a+dMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAs1PJoX8T6Ev/8IGEmowdRO88+6jmDWKbD/mpycpLJi5RbfOs
+uZ4sEJYc94D/XjBPoGebhD68tW94QgIS2eZPo6CC678ARLNvL1bDNgPRubnlPFM6
+F2mvQpH6tZGyBn8HiOeseiu3w0HofZuWyT04Skw5RTXBQwWyMgCZInIqfAA=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta8/ta8_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta8/ta8_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            b8:9a:b1:4d:fa:a9:68:23
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
+        Serial Number: 16709229305513134148 (0xe7e31b8629a84844)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:da:5e:85:e0:17:14:35:c1:e8:f4:b6:97:15:d1:
-                    f5:c3:36:26:57:85:5c:0c:e8:8e:d7:2b:10:66:b2:
-                    61:92:a3:df:a4:4f:61:52:41:9c:3b:2f:0e:bc:bd:
-                    92:9b:e2:4c:ec:68:34:76:2c:86:54:e5:8b:9e:ac:
-                    2f:7e:4f:07:52:ec:7f:51:31:ed:9e:94:ed:7e:15:
-                    da:4f:fb:65:d0:07:85:c2:60:69:ce:ac:74:72:8a:
-                    45:31:e4:6c:3e:5e:05:bc:d3:2f:37:56:14:c2:2e:
-                    78:78:6b:93:14:e5:61:08:22:ef:4d:f9:bb:1b:1f:
-                    31:09:12:7a:ad:e5:cf:18:5b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c6:4d:f7:24:79:d7:8f:a0:93:61:37:d0:a4:5c:
+                    61:81:e2:1a:1c:0a:ff:ce:8b:3d:49:15:12:1c:1b:
+                    b7:9c:dd:28:f6:c5:5d:2e:63:f7:67:4b:c9:8c:95:
+                    5a:1c:e8:97:89:16:83:81:ff:bc:10:26:51:7c:f9:
+                    f1:03:f5:51:f4:01:45:da:d4:2f:cf:d9:35:68:0c:
+                    ae:11:2d:31:37:5a:73:73:c0:60:13:c8:10:73:3a:
+                    7d:c9:96:8c:07:00:b1:41:52:d2:b0:5f:cd:01:06:
+                    b8:d7:3f:d8:0f:17:f9:38:39:5d:2d:09:14:99:05:
+                    7c:1f:1f:6f:c9:2d:7d:6e:61
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                BB:CA:54:46:B9:0F:22:DB:69:82:15:BB:66:36:9D:50:1D:0B:1B:F5
+                9E:DE:D5:93:0F:57:31:37:6C:9A:F7:DA:A2:A0:D2:CE:F4:65:EC:86
             X509v3 Authority Key Identifier: 
-                keyid:BB:CA:54:46:B9:0F:22:DB:69:82:15:BB:66:36:9D:50:1D:0B:1B:F5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta8/CN=localhost/emailAddress=ta8
-                serial:B8:9A:B1:4D:FA:A9:68:23
+                keyid:9E:DE:D5:93:0F:57:31:37:6C:9A:F7:DA:A2:A0:D2:CE:F4:65:EC:86
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        7a:13:83:75:43:35:e1:4d:07:93:8d:1c:fd:4d:8f:5c:24:78:
-        f5:01:35:4c:a5:ad:5f:92:f3:23:21:0c:2d:dc:64:a5:7f:c2:
-        3c:c9:e3:b0:4e:d8:17:4e:76:4c:4d:71:fb:b9:3d:d9:51:b8:
-        fc:e0:91:a6:5c:18:c8:06:55:cc:a9:ba:9e:59:92:c4:5c:04:
-        11:e2:d9:99:1d:cb:bd:9d:6c:c2:0e:9e:f0:4c:20:69:6b:b1:
-        76:b6:d4:c0:e6:6c:4b:1e:18:cb:71:4a:9b:13:ca:db:c8:a4:
-        0e:35:c0:91:70:04:9c:32:bd:15:a2:36:72:97:d0:7b:d0:6c:
-        dc:03
+         81:1f:1d:b5:60:85:60:4f:9f:cc:9a:12:99:4a:dc:fb:49:2b:
+         70:9d:21:1e:d7:be:fe:a8:b8:eb:fd:49:e2:99:72:ae:0e:be:
+         cf:bc:c4:88:11:8e:5b:6c:d5:68:d0:cb:52:1a:7c:65:a2:c1:
+         1f:08:7e:31:6e:28:18:fa:04:90:70:d5:96:aa:89:97:9d:61:
+         08:47:f5:75:4c:9d:96:c7:37:8f:3e:f2:04:bc:48:a6:89:65:
+         25:27:13:70:5a:f7:97:ba:42:61:a5:d9:69:44:08:34:19:4d:
+         6e:1c:e7:23:25:1f:c0:f3:ad:fa:56:c2:02:75:ed:c2:51:ca:
+         cf:96
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJALiasU36qWgjMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTgxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE4MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhODESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTgwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBANpeheAXFDXB6PS2lxXR9cM2JleFXAzojtcrEGayYZKj
-36RPYVJBnDsvDry9kpviTOxoNHYshlTli56sL35PB1Lsf1Ex7Z6U7X4V2k/7ZdAH
-hcJgac6sdHKKRTHkbD5eBbzTLzdWFMIueHhrkxTlYQgi7035uxsfMQkSeq3lzxhb
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFLvKVEa5DyLbaYIVu2Y2nVAdCxv1MIGvBgNV
-HSMEgacwgaSAFLvKVEa5DyLbaYIVu2Y2nVAdCxv1oYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhODESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTiCCQC4mrFN+qloIzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAHoTg3VDNeFNB5ONHP1Nj1wkePUBNUylrV+S8yMhDC3cZKV/
-wjzJ47BO2BdOdkxNcfu5PdlRuPzgkaZcGMgGVcypup5ZksRcBBHi2Zkdy72dbMIO
-nvBMIGlrsXa21MDmbEseGMtxSpsTytvIpA41wJFwBJwyvRWiNnKX0HvQbNwD
+MIICyDCCAjGgAwIBAgIJAOfjG4YpqEhEMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE4MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhODAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE4MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhODCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAxk33JHnXj6CTYTfQpFxhgeIaHAr/zos9SRUSHBu3
+nN0o9sVdLmP3Z0vJjJVaHOiXiRaDgf+8ECZRfPnxA/VR9AFF2tQvz9k1aAyuES0x
+N1pzc8BgE8gQczp9yZaMBwCxQVLSsF/NAQa41z/YDxf5ODldLQkUmQV8Hx9vyS19
+bmECAwEAAaNQME4wHQYDVR0OBBYEFJ7e1ZMPVzE3bJr32qKg0s70ZeyGMB8GA1Ud
+IwQYMBaAFJ7e1ZMPVzE3bJr32qKg0s70ZeyGMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAgR8dtWCFYE+fzJoSmUrc+0krcJ0hHte+/qi46/1J4plyrg6+
+z7zEiBGOW2zVaNDLUhp8ZaLBHwh+MW4oGPoEkHDVlqqJl51hCEf1dUydlsc3jz7y
+BLxIpollJScTcFr3l7pCYaXZaUQINBlNbhznIyUfwPOt+lbCAnXtwlHKz5Y=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/ta9/ta9_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/ta9/ta9_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            a1:62:e1:e5:c0:a2:38:0d
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
+        Serial Number: 16519569919148996401 (0xe5414d51291ab731)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e8:ab:ef:91:ca:05:4a:18:a2:98:c4:d8:93:d0:
-                    ce:99:a9:5e:02:8d:5d:5c:e3:f3:84:49:6b:a7:6d:
-                    ef:38:77:2e:32:c2:9c:09:1d:f6:be:6c:c6:c4:b1:
-                    c8:c3:32:72:2b:84:87:f6:ba:bf:fc:cf:5c:05:c2:
-                    4f:62:23:7e:02:3f:ce:6c:c6:b6:95:86:84:d7:97:
-                    9f:1c:87:70:29:62:6a:29:7c:06:a3:b7:18:12:67:
-                    07:3a:89:aa:f0:99:fe:df:46:00:b1:2f:aa:30:1e:
-                    a2:1e:f8:2b:37:99:21:b8:85:53:42:98:4a:bd:c5:
-                    f9:b4:61:60:0a:73:bc:0e:d1
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c9:8a:2d:0d:53:04:e8:02:bb:bc:27:df:0e:b8:
+                    33:25:07:54:61:d0:d9:b6:08:33:5b:c3:eb:4c:a1:
+                    1f:9f:51:cc:a9:83:07:16:15:9c:69:0b:48:74:62:
+                    35:5f:a3:94:38:37:0f:3f:5f:58:26:9a:36:0b:a2:
+                    0f:bb:9b:57:ff:fd:70:01:d6:28:a2:b6:67:ed:a9:
+                    c8:90:15:b5:7f:91:60:32:ff:96:13:a4:3f:09:23:
+                    70:2f:38:6f:24:54:41:95:2f:91:5a:6e:a5:aa:77:
+                    da:6c:50:ee:62:e5:85:8a:67:63:7d:fc:07:30:ba:
+                    f3:96:93:6c:5d:5f:9e:2e:07
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                A6:CF:35:00:96:15:AD:B4:24:DE:1D:5A:B9:56:A2:6E:B4:2D:46:C5
+                E8:5E:8E:77:D1:61:64:BB:48:AF:38:95:0C:57:16:4E:E3:77:3D:35
             X509v3 Authority Key Identifier: 
-                keyid:A6:CF:35:00:96:15:AD:B4:24:DE:1D:5A:B9:56:A2:6E:B4:2D:46:C5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta9/CN=localhost/emailAddress=ta9
-                serial:A1:62:E1:E5:C0:A2:38:0D
+                keyid:E8:5E:8E:77:D1:61:64:BB:48:AF:38:95:0C:57:16:4E:E3:77:3D:35
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        44:02:da:cf:c3:07:27:84:e4:06:22:ff:fc:7e:c9:47:7a:79:
-        e1:9f:6a:84:68:a8:fb:48:18:80:58:0f:b0:5e:ef:43:bf:3a:
-        69:23:b2:18:3e:78:3a:8e:ff:c5:d8:76:4c:99:d5:9f:be:8a:
-        fd:0e:79:b9:7e:62:c4:c2:4b:6f:78:01:e7:52:19:ff:08:86:
-        a7:b2:17:0c:11:03:ef:42:1f:b5:5b:40:0a:3a:9f:2a:4f:57:
-        31:3d:b1:dd:a8:51:e1:2f:b2:e4:5b:2e:1b:9f:a7:d6:b7:6b:
-        76:68:f9:2e:b1:38:6f:11:21:0e:81:a2:32:01:7b:bc:c3:1f:
-        82:4e
+         3e:20:dc:10:1b:b4:83:9a:0a:9a:41:d3:6f:ec:ef:5b:51:0f:
+         a7:4a:49:0e:b3:86:f6:0f:c2:84:ea:0f:b2:08:6d:a2:7c:e4:
+         24:10:ba:45:c2:c3:9e:07:b9:c3:74:10:f2:74:7f:c7:61:2e:
+         0e:45:33:00:c4:19:32:61:2b:58:0a:f4:51:7a:03:66:68:32:
+         27:c3:20:27:af:c4:93:64:45:0d:16:0e:ca:2b:86:f6:1c:22:
+         13:74:5a:d2:68:fc:45:11:b8:f1:13:26:e1:e4:c2:b7:b5:b8:
+         f8:fc:cc:6d:fb:87:3e:5d:53:31:ba:99:16:65:7b:b1:6c:e9:
+         78:8a
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAKFi4eXAojgNMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTkxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE5MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhOTESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTkwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAOir75HKBUoYopjE2JPQzpmpXgKNXVzj84RJa6dt7zh3
-LjLCnAkd9r5sxsSxyMMyciuEh/a6v/zPXAXCT2IjfgI/zmzGtpWGhNeXnxyHcCli
-ail8BqO3GBJnBzqJqvCZ/t9GALEvqjAeoh74KzeZIbiFU0KYSr3F+bRhYApzvA7R
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFKbPNQCWFa20JN4dWrlWom60LUbFMIGvBgNV
-HSMEgacwgaSAFKbPNQCWFa20JN4dWrlWom60LUbFoYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhOTESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTmCCQChYuHlwKI4DTAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAEQC2s/DByeE5AYi//x+yUd6eeGfaoRoqPtIGIBYD7Be70O/
-Omkjshg+eDqO/8XYdkyZ1Z++iv0Oebl+YsTCS294AedSGf8IhqeyFwwRA+9CH7Vb
-QAo6nypPVzE9sd2oUeEvsuRbLhufp9a3a3Zo+S6xOG8RIQ6BojIBe7zDH4JO
+MIICyDCCAjGgAwIBAgIJAOVBTVEpGrcxMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE5MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhOTAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE5MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhOTCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAyYotDVME6AK7vCffDrgzJQdUYdDZtggzW8PrTKEf
+n1HMqYMHFhWcaQtIdGI1X6OUODcPP19YJpo2C6IPu5tX//1wAdYoorZn7anIkBW1
+f5FgMv+WE6Q/CSNwLzhvJFRBlS+RWm6lqnfabFDuYuWFimdjffwHMLrzlpNsXV+e
+LgcCAwEAAaNQME4wHQYDVR0OBBYEFOhejnfRYWS7SK84lQxXFk7jdz01MB8GA1Ud
+IwQYMBaAFOhejnfRYWS7SK84lQxXFk7jdz01MAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAPiDcEBu0g5oKmkHTb+zvW1EPp0pJDrOG9g/ChOoPsghtonzk
+JBC6RcLDnge5w3QQ8nR/x2EuDkUzAMQZMmErWAr0UXoDZmgyJ8MgJ6/Ek2RFDRYO
+yiuG9hwiE3Ra0mj8RRG48RMm4eTCt7W4+PzMbfuHPl1TMbqZFmV7sWzpeIo=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta10_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta10_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,65 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            86:f1:45:12:31:c7:2b:2a
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
+        Serial Number: 9711796497956498587 (0x86c73b75a7946c9b)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta10, CN=localhost/emailAddress=ta10
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:b6:50:43:73:64:12:40:26:54:0c:f9:67:e4:6a:
-                    ed:1f:18:e5:73:89:13:0f:c9:5f:6e:6e:c6:05:ad:
-                    2c:be:e4:6b:fd:c6:4f:ea:f3:6f:0d:f4:1a:34:7f:
-                    03:97:b0:a4:d1:6e:98:d2:36:fa:33:5d:51:37:de:
-                    8f:5b:3d:a0:07:52:c8:b7:71:30:71:fb:c3:a7:fa:
-                    61:f6:b4:28:be:9e:da:8b:8b:70:dd:8e:d0:a5:1a:
-                    00:70:1c:39:e1:cf:64:f8:ec:b4:83:b9:2b:67:fa:
-                    4d:ae:30:84:2f:2c:9d:6c:77:7e:09:95:43:77:6b:
-                    e1:9d:2b:c9:89:d9:a9:e5:8f
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ab:08:de:44:e1:7d:cf:87:e5:0d:f9:b6:66:79:
+                    45:4b:18:3f:c4:c3:bc:3c:4e:10:1c:23:36:0b:17:
+                    8e:53:e9:1d:52:c0:d3:78:ce:74:30:13:d9:3e:98:
+                    8e:08:94:fe:76:94:55:7a:d9:73:87:01:5e:dd:c7:
+                    7b:5e:56:94:a6:5d:e6:8a:ab:22:03:cf:e1:7a:1c:
+                    7e:fb:16:c2:7c:f4:a3:6c:46:28:0b:15:15:e9:92:
+                    4f:50:a3:e3:04:25:91:6d:d0:71:2f:66:b3:20:64:
+                    db:f1:60:8d:3f:52:94:13:f1:f1:00:93:0b:20:be:
+                    f3:98:7d:c8:58:e3:f0:e9:c5
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                B7:F0:DB:5F:BA:CC:10:6D:A6:64:62:10:84:A5:C9:39:4C:3C:27:86
+                61:D2:DF:69:D2:65:98:6E:36:8B:4E:A5:34:33:A7:EF:84:5D:DE:F4
             X509v3 Authority Key Identifier: 
-                keyid:B7:F0:DB:5F:BA:CC:10:6D:A6:64:62:10:84:A5:C9:39:4C:3C:27:86
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta10/CN=localhost/emailAddress=ta10
-                serial:86:F1:45:12:31:C7:2B:2A
+                keyid:61:D2:DF:69:D2:65:98:6E:36:8B:4E:A5:34:33:A7:EF:84:5D:DE:F4
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        5b:6d:71:b8:4e:e3:27:06:d9:2a:47:ab:21:a3:df:94:a9:d8:
-        62:f1:6a:97:33:cc:1c:52:55:9a:f8:ec:6d:b4:91:17:4d:2a:
-        0e:03:b4:4b:00:83:10:8e:12:c1:05:67:56:9a:30:90:91:ad:
-        8b:dc:0a:eb:3f:28:5d:f9:d4:87:0d:f7:3a:5a:f6:47:52:9e:
-        af:4e:21:d4:2f:b8:40:4f:7f:81:1f:93:ca:bc:e6:04:c5:18:
-        65:5e:b1:dd:0b:3c:5e:3a:6f:48:e3:fc:b2:c8:37:8d:9f:14:
-        1b:a7:12:79:bb:2d:b9:fc:7a:01:ef:66:c6:d4:c2:44:01:49:
-        23:a9
+         48:43:2e:21:5e:c5:85:b1:97:37:72:7a:4a:a3:c0:db:5f:c4:
+         42:51:d0:3e:f5:20:43:f6:72:61:b3:fb:8f:13:71:36:0e:8e:
+         33:8c:14:7d:c2:39:ed:36:a9:55:db:bd:24:de:96:2c:b2:61:
+         d5:95:36:97:e4:b6:17:d3:a5:6c:8c:96:1a:89:54:ab:43:f0:
+         76:b1:f6:f1:4a:0d:69:79:ea:95:38:76:c8:5b:cc:99:ca:ba:
+         0d:71:7d:0f:d0:31:8c:94:a9:2d:7b:91:56:98:a1:ea:75:08:
+         ea:fe:03:e0:23:09:32:00:88:1e:83:f6:fe:df:40:3c:78:25:
+         ae:e5
 -----BEGIN CERTIFICATE-----
-MIIDYDCCAsmgAwIBAgIJAIbxRRIxxysqMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQ0wCwYDVQQLEwR0YTEwMRIwEAYDVQQDEwlsb2NhbGhv
-c3QxEzARBgkqhkiG9w0BCQEWBHRhMTAwHhcNMTEwNDExMjIzNzU1WhcNMTQwMTA1
-MjIzNzU1WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEG
-A1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMDES
-MBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwMIGfMA0GCSqG
-SIb3DQEBAQUAA4GNADCBiQKBgQC2UENzZBJAJlQM+Wfkau0fGOVziRMPyV9ubsYF
-rSy+5Gv9xk/q828N9Bo0fwOXsKTRbpjSNvozXVE33o9bPaAHUsi3cTBx+8On+mH2
-tCi+ntqLi3DdjtClGgBwHDnhz2T47LSDuStn+k2uMIQvLJ1sd34JlUN3a+GdK8mJ
-2anljwIDAQABo4HlMIHiMB0GA1UdDgQWBBS38NtfuswQbaZkYhCEpck5TDwnhjCB
-sgYDVR0jBIGqMIGngBS38NtfuswQbaZkYhCEpck5TDwnhqGBg6SBgDB+MQswCQYD
-VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFy
-azENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMDESMBAGA1UEAxMJbG9jYWxo
-b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwggkAhvFFEjHHKyowDAYDVR0TBAUwAwEB
-/zANBgkqhkiG9w0BAQsFAAOBgQBbbXG4TuMnBtkqR6sho9+Uqdhi8WqXM8wcUlWa
-+OxttJEXTSoOA7RLAIMQjhLBBWdWmjCQka2L3ArrPyhd+dSHDfc6WvZHUp6vTiHU
-L7hAT3+BH5PKvOYExRhlXrHdCzxeOm9I4/yyyDeNnxQbpxJ5uy25/HoB72bG1MJE
-AUkjqQ==
+MIICzDCCAjWgAwIBAgIJAIbHO3WnlGybMA0GCSqGSIb3DQEBCwUAMH8xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTENMAsGA1UECwwEdGExMDESMBAGA1UEAwwJbG9jYWxo
+b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTEwMB4XDTEzMTIxMzAwMTMzOVoXDTE2MDkw
+ODAwMTMzOVowfzELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQ0wCwYDVQQLDAR0YTEw
+MRIwEAYDVQQDDAlsb2NhbGhvc3QxEzARBgkqhkiG9w0BCQEWBHRhMTAwgZ8wDQYJ
+KoZIhvcNAQEBBQADgY0AMIGJAoGBAKsI3kThfc+H5Q35tmZ5RUsYP8TDvDxOEBwj
+NgsXjlPpHVLA03jOdDAT2T6YjgiU/naUVXrZc4cBXt3He15WlKZd5oqrIgPP4Xoc
+fvsWwnz0o2xGKAsVFemST1Cj4wQlkW3QcS9msyBk2/FgjT9SlBPx8QCTCyC+85h9
+yFjj8OnFAgMBAAGjUDBOMB0GA1UdDgQWBBRh0t9p0mWYbjaLTqU0M6fvhF3e9DAf
+BgNVHSMEGDAWgBRh0t9p0mWYbjaLTqU0M6fvhF3e9DAMBgNVHRMEBTADAQH/MA0G
+CSqGSIb3DQEBCwUAA4GBAEhDLiFexYWxlzdyekqjwNtfxEJR0D71IEP2cmGz+48T
+cTYOjjOMFH3COe02qVXbvSTeliyyYdWVNpfkthfTpWyMlhqJVKtD8Hax9vFKDWl5
+6pU4dshbzJnKug1xfQ/QMYyUqS17kVaYoep1COr+A+AjCTIAiB6D9v7fQDx4Ja7l
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta11_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta11_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,65 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            d7:f1:84:58:4b:42:ce:33
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
+        Serial Number: 10111560406944601325 (0x8c537a9de4d654ed)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
         Validity
-            Not Before: Apr 11 22:37:55 2011 GMT
-            Not After : Jan  5 22:37:55 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
+            Not Before: Dec 13 00:13:39 2013 GMT
+            Not After : Sep  8 00:13:39 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta11, CN=localhost/emailAddress=ta11
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:a3:c5:d4:23:f8:e8:a4:02:1f:38:cd:53:dc:7c:
-                    e8:3c:49:bd:14:c1:c7:a2:b7:00:7a:d2:d1:c8:01:
-                    7c:9b:f7:78:50:95:07:69:90:a0:7a:25:0f:55:55:
-                    f7:b2:33:ae:ae:66:64:5c:4c:86:66:e0:28:e2:63:
-                    8c:11:5f:ee:a4:af:77:86:c2:c0:18:0d:24:18:5f:
-                    26:ff:67:cc:f4:f9:7d:0c:e7:d7:0c:01:e8:85:57:
-                    f4:a8:d8:2c:f1:ec:2f:c7:8c:34:d4:3d:d3:1b:5c:
-                    2d:44:bd:d1:a6:35:d2:21:36:f9:31:ac:24:cb:ec:
-                    7b:70:c8:10:97:c8:8e:37:19
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:f3:d5:2f:b4:3e:12:ee:e5:01:6a:41:a4:09:1b:
+                    12:5f:f3:d5:a2:7e:3c:d8:6f:6f:a7:30:af:72:3d:
+                    f4:f4:31:30:94:b9:09:d8:2f:36:ba:12:61:56:8c:
+                    87:f9:52:6f:8b:b5:28:d1:23:93:f3:20:d4:b5:2d:
+                    ca:29:10:f5:10:7b:ad:d6:ee:de:40:22:d9:10:32:
+                    30:93:27:22:6d:87:f9:ed:85:16:c2:6d:da:24:51:
+                    db:1a:00:53:2b:65:4a:ce:24:0f:cf:57:f1:c0:51:
+                    9e:0c:ac:2f:17:5d:72:c1:f4:8d:83:20:41:d3:10:
+                    5f:f2:e0:2d:9f:ec:da:97:7d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                CE:A0:CF:69:A4:17:A0:54:BE:C3:CB:28:70:86:6A:BD:3B:DE:E4:CC
+                BD:98:0D:A4:4D:61:87:11:83:C8:53:D1:C9:62:9D:ED:45:61:DD:42
             X509v3 Authority Key Identifier: 
-                keyid:CE:A0:CF:69:A4:17:A0:54:BE:C3:CB:28:70:86:6A:BD:3B:DE:E4:CC
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta11/CN=localhost/emailAddress=ta11
-                serial:D7:F1:84:58:4B:42:CE:33
+                keyid:BD:98:0D:A4:4D:61:87:11:83:C8:53:D1:C9:62:9D:ED:45:61:DD:42
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        89:34:9b:f9:55:53:63:83:82:0e:d0:f1:e5:0c:e3:4e:4b:2f:
-        54:20:2b:70:00:56:08:b4:18:88:59:e2:66:3e:5c:b6:0a:74:
-        16:bc:43:61:35:1e:df:e5:f6:f6:7e:de:87:18:61:b7:70:b0:
-        93:e8:5a:19:1d:01:a7:43:ca:38:ea:d2:e2:75:0e:3e:d2:b5:
-        91:57:1e:30:29:aa:2a:26:53:1b:9e:56:ad:61:41:3c:04:bb:
-        a5:af:da:75:63:5e:bb:31:21:f9:4c:dc:d0:c2:4c:90:07:45:
-        ed:32:0d:c0:c8:e9:6f:72:b5:ae:19:f2:88:9e:50:5c:5a:34:
-        47:a9
+         36:46:25:95:5e:65:37:e1:c4:14:31:7a:2a:a8:16:c0:bf:77:
+         ae:6a:17:f6:f2:dc:7c:0c:84:52:bb:07:4c:cb:1c:4e:80:b3:
+         55:74:15:69:40:a2:54:e9:e5:f8:2e:2f:b2:c9:37:ef:3d:7f:
+         87:64:02:e3:7c:f2:ec:97:77:b4:63:77:80:c1:61:25:fb:d5:
+         e0:26:c1:89:f0:0e:5d:65:d4:ba:d7:55:7b:ce:af:77:55:65:
+         96:7a:8d:7d:e5:79:a0:88:13:7a:cf:cf:4e:4d:a8:34:2d:3b:
+         f3:b2:44:f9:8b:c9:91:44:36:0f:94:eb:45:dd:2d:03:68:3e:
+         38:2e
 -----BEGIN CERTIFICATE-----
-MIIDYDCCAsmgAwIBAgIJANfxhFhLQs4zMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQ0wCwYDVQQLEwR0YTExMRIwEAYDVQQDEwlsb2NhbGhv
-c3QxEzARBgkqhkiG9w0BCQEWBHRhMTEwHhcNMTEwNDExMjIzNzU1WhcNMTQwMTA1
-MjIzNzU1WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEG
-A1UEBxMKTWVubG8gUGFyazENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMTES
-MBAGA1UEAxMJbG9jYWxob3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExMIGfMA0GCSqG
-SIb3DQEBAQUAA4GNADCBiQKBgQCjxdQj+OikAh84zVPcfOg8Sb0UwceitwB60tHI
-AXyb93hQlQdpkKB6JQ9VVfeyM66uZmRcTIZm4CjiY4wRX+6kr3eGwsAYDSQYXyb/
-Z8z0+X0M59cMAeiFV/So2Czx7C/HjDTUPdMbXC1EvdGmNdIhNvkxrCTL7HtwyBCX
-yI43GQIDAQABo4HlMIHiMB0GA1UdDgQWBBTOoM9ppBegVL7Dyyhwhmq9O97kzDCB
-sgYDVR0jBIGqMIGngBTOoM9ppBegVL7Dyyhwhmq9O97kzKGBg6SBgDB+MQswCQYD
-VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTETMBEGA1UEBxMKTWVubG8gUGFy
-azENMAsGA1UEChMEcGtnNTENMAsGA1UECxMEdGExMTESMBAGA1UEAxMJbG9jYWxo
-b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExggkA1/GEWEtCzjMwDAYDVR0TBAUwAwEB
-/zANBgkqhkiG9w0BAQsFAAOBgQCJNJv5VVNjg4IO0PHlDONOSy9UICtwAFYItBiI
-WeJmPly2CnQWvENhNR7f5fb2ft6HGGG3cLCT6FoZHQGnQ8o46tLidQ4+0rWRVx4w
-KaoqJlMbnlatYUE8BLulr9p1Y167MSH5TNzQwkyQB0XtMg3AyOlvcrWuGfKInlBc
-WjRHqQ==
+MIICzDCCAjWgAwIBAgIJAIxTep3k1lTtMA0GCSqGSIb3DQEBCwUAMH8xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTENMAsGA1UECwwEdGExMTESMBAGA1UEAwwJbG9jYWxo
+b3N0MRMwEQYJKoZIhvcNAQkBFgR0YTExMB4XDTEzMTIxMzAwMTMzOVoXDTE2MDkw
+ODAwMTMzOVowfzELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFDAS
+BgNVBAcMC1NhbnRhIENsYXJhMQ0wCwYDVQQKDARwa2c1MQ0wCwYDVQQLDAR0YTEx
+MRIwEAYDVQQDDAlsb2NhbGhvc3QxEzARBgkqhkiG9w0BCQEWBHRhMTEwgZ8wDQYJ
+KoZIhvcNAQEBBQADgY0AMIGJAoGBAPPVL7Q+Eu7lAWpBpAkbEl/z1aJ+PNhvb6cw
+r3I99PQxMJS5CdgvNroSYVaMh/lSb4u1KNEjk/Mg1LUtyikQ9RB7rdbu3kAi2RAy
+MJMnIm2H+e2FFsJt2iRR2xoAUytlSs4kD89X8cBRngysLxddcsH0jYMgQdMQX/Lg
+LZ/s2pd9AgMBAAGjUDBOMB0GA1UdDgQWBBS9mA2kTWGHEYPIU9HJYp3tRWHdQjAf
+BgNVHSMEGDAWgBS9mA2kTWGHEYPIU9HJYp3tRWHdQjAMBgNVHRMEBTADAQH/MA0G
+CSqGSIb3DQEBCwUAA4GBADZGJZVeZTfhxBQxeiqoFsC/d65qF/by3HwMhFK7B0zL
+HE6As1V0FWlAolTp5fguL7LJN+89f4dkAuN88uyXd7Rjd4DBYSX71eAmwYnwDl1l
+1LrXVXvOr3dVZZZ6jX3leaCIE3rPz05NqDQtO/OyRPmLyZFENg+U60XdLQNoPjgu
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta1_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta1_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            a1:49:ea:78:5a:f4:55:8d
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta1/emailAddress=ta1
+        Serial Number: 17773656435948586063 (0xf6a8b65c108d044f)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta1/emailAddress=ta1
         Validity
-            Not Before: Apr 11 22:37:38 2011 GMT
-            Not After : Jan  5 22:37:38 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta1/emailAddress=ta1
+            Not Before: Dec 13 00:13:33 2013 GMT
+            Not After : Sep  8 00:13:33 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta1/emailAddress=ta1
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e0:4a:38:c6:48:13:ab:71:ab:ca:6e:6e:ce:e9:
-                    fc:2c:68:cd:ee:79:f6:c2:7e:1f:19:ee:5b:75:19:
-                    3d:ba:4f:8f:a3:79:f9:5c:eb:dd:0c:30:0f:d0:77:
-                    05:0d:ff:b9:28:e4:74:1a:67:b3:ff:36:ea:26:61:
-                    ec:51:25:e1:c0:cd:97:58:e0:65:8d:4c:54:bc:93:
-                    99:37:2b:f3:87:d3:b8:d7:87:15:d9:cf:1c:b6:87:
-                    f4:6d:54:bd:f5:65:53:60:43:b2:04:72:79:b0:bf:
-                    71:13:11:fd:bc:45:38:14:82:d9:05:8b:fe:9f:8e:
-                    7d:d1:2c:b9:36:61:c0:0a:11
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c1:11:20:95:9b:6a:49:f5:e0:b3:80:97:37:02:
+                    fc:6f:99:6d:70:67:a1:47:66:cf:f7:24:58:55:c8:
+                    88:e4:da:89:a8:fc:97:f1:6c:fc:44:60:6b:5c:71:
+                    d7:84:22:16:a4:09:77:fb:a3:af:10:24:7b:13:03:
+                    b6:b9:c8:f0:03:00:74:a2:ca:10:9f:ad:17:32:e8:
+                    cb:fa:56:c1:fa:0c:3f:43:5a:36:ee:6b:94:12:94:
+                    48:a9:d9:1c:37:5c:76:6d:d5:ad:6f:37:ad:9f:88:
+                    78:50:92:59:d6:4f:2a:22:ba:a5:ec:29:c7:3e:b5:
+                    41:9e:ce:9b:9e:9e:d8:58:f7
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                75:A9:2B:02:E8:FB:31:09:2A:F2:16:21:24:D8:B2:A5:D0:14:93:5B
+                81:54:6B:06:08:DD:44:4F:08:81:21:7A:7C:D5:96:EA:53:2B:E3:0A
             X509v3 Authority Key Identifier: 
-                keyid:75:A9:2B:02:E8:FB:31:09:2A:F2:16:21:24:D8:B2:A5:D0:14:93:5B
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta1/emailAddress=ta1
-                serial:A1:49:EA:78:5A:F4:55:8D
+                keyid:81:54:6B:06:08:DD:44:4F:08:81:21:7A:7C:D5:96:EA:53:2B:E3:0A
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        82:9d:88:f6:27:64:f1:c4:9f:18:10:ac:d3:6c:81:b9:25:34:
-        f8:74:1c:83:b3:94:65:1f:25:cd:5e:a7:e4:ad:d8:b2:6e:f1:
-        43:56:25:75:d5:db:02:d6:f2:7a:3f:12:a3:60:04:77:49:99:
-        37:d7:af:60:ff:d7:ee:d0:df:cd:4a:fb:75:ee:05:b0:af:00:
-        da:e2:80:6e:85:81:72:75:a5:3b:01:8c:00:3f:bb:8a:21:47:
-        0d:d4:bb:51:a5:4c:58:2a:d8:09:1f:fb:b1:e7:56:00:53:a8:
-        25:3e:ab:3d:f6:1b:28:7d:ef:76:68:62:be:28:a9:63:44:d1:
-        68:6a
+         94:f7:77:15:8b:2a:ab:eb:9a:7f:a2:7d:d9:5b:be:6d:bc:e2:
+         49:bf:7d:16:36:0a:72:24:be:72:af:59:2f:9a:cc:d2:da:74:
+         fc:03:f5:9e:c2:e8:a4:ea:99:90:30:7e:b2:b0:6f:b6:fe:af:
+         fd:d6:f0:51:50:52:99:d2:0c:dc:88:4a:54:3c:09:93:9b:83:
+         82:84:64:78:d7:d9:00:90:ee:01:9c:69:05:34:c1:2d:b3:46:
+         da:9b:3a:47:65:76:68:63:6c:3d:cb:47:cc:71:05:f2:22:6b:
+         bd:66:0b:6a:90:45:5f:60:11:4c:7e:11:32:8c:8b:ec:70:c6:
+         f6:b4
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAKFJ6nha9FWNMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEWA3Rh
-MTAeFw0xMTA0MTEyMjM3MzhaFw0xNDAxMDUyMjM3MzhaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEWA3RhMTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA4Eo4xkgTq3Grym5uzun8LGjN7nn2wn4f
-Ge5bdRk9uk+Po3n5XOvdDDAP0HcFDf+5KOR0Gmez/zbqJmHsUSXhwM2XWOBljUxU
-vJOZNyvzh9O414cV2c8ctof0bVS99WVTYEOyBHJ5sL9xExH9vEU4FILZBYv+n459
-0Sy5NmHAChECAwEAAaOBzTCByjAdBgNVHQ4EFgQUdakrAuj7MQkq8hYhJNiypdAU
-k1swgZoGA1UdIwSBkjCBj4AUdakrAuj7MQkq8hYhJNiypdAUk1uhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTExEjAQBgkqhkiG9w0BCQEW
-A3RhMYIJAKFJ6nha9FWNMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-gp2I9idk8cSfGBCs02yBuSU0+HQcg7OUZR8lzV6n5K3Ysm7xQ1YlddXbAtbyej8S
-o2AEd0mZN9evYP/X7tDfzUr7de4FsK8A2uKAboWBcnWlOwGMAD+7iiFHDdS7UaVM
-WCrYCR/7sedWAFOoJT6rPfYbKH3vdmhiviipY0TRaGo=
+MIICoDCCAgmgAwIBAgIJAPaotlwQjQRPMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGExMRIwEAYJKoZIhvcNAQkBFgN0
+YTEwHhcNMTMxMjEzMDAxMzMzWhcNMTYwOTA4MDAxMzMzWjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMTESMBAGCSqGSIb3DQEJARYDdGExMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBESCVm2pJ9eCzgJc3AvxvmW1wZ6FH
+Zs/3JFhVyIjk2omo/JfxbPxEYGtccdeEIhakCXf7o68QJHsTA7a5yPADAHSiyhCf
+rRcy6Mv6VsH6DD9DWjbua5QSlEip2Rw3XHZt1a1vN62fiHhQklnWTyoiuqXsKcc+
+tUGezpuenthY9wIDAQABo1AwTjAdBgNVHQ4EFgQUgVRrBgjdRE8IgSF6fNWW6lMr
+4wowHwYDVR0jBBgwFoAUgVRrBgjdRE8IgSF6fNWW6lMr4wowDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQCU93cViyqr65p/on3ZW75tvOJJv30WNgpyJL5y
+r1kvmszS2nT8A/Wewuik6pmQMH6ysG+2/q/91vBRUFKZ0gzciEpUPAmTm4OChGR4
+19kAkO4BnGkFNMEts0bamzpHZXZoY2w9y0fMcQXyImu9ZgtqkEVfYBFMfhEyjIvs
+cMb2tA==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta2_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta2_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            e4:2c:84:25:53:01:eb:e0
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta2/emailAddress=ta2
+        Serial Number: 17668597499765822237 (0xf53377d054e5931d)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta2/emailAddress=ta2
         Validity
-            Not Before: Apr 11 22:37:43 2011 GMT
-            Not After : Jan  5 22:37:43 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta2/emailAddress=ta2
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta2/emailAddress=ta2
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e3:75:e1:44:6d:68:b1:dc:64:6b:a3:06:0a:3b:
-                    91:ad:10:ce:45:99:f3:ea:32:3c:92:bc:b1:85:d5:
-                    c5:62:a6:fd:3e:33:64:fb:84:6e:09:e1:c6:76:34:
-                    43:63:7f:7b:93:bc:6c:0e:31:58:b0:c0:c8:c7:b4:
-                    6e:aa:db:40:86:67:b0:2c:79:82:fb:31:1f:71:6c:
-                    10:a4:b9:0b:dd:d8:78:e4:b3:a3:af:de:c6:0f:21:
-                    fd:5c:e6:01:b6:87:82:9b:04:16:6e:42:a5:57:39:
-                    fe:85:e3:57:58:cd:fe:90:c7:d3:35:7d:91:13:bf:
-                    05:f2:21:ac:42:e7:0f:e4:e3
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:ca:34:f6:15:9c:de:7d:a0:37:35:0b:50:e2:d8:
+                    5b:71:aa:30:27:c3:fb:b2:54:24:b2:7d:cc:52:a5:
+                    3d:90:1e:1c:38:d4:b4:f0:f4:b6:63:db:dc:25:c2:
+                    ab:b2:6a:b6:90:85:85:aa:5f:ed:0f:53:53:82:5c:
+                    19:63:d5:bb:fb:b3:d8:cc:3c:9b:4b:99:f1:55:58:
+                    bb:36:5d:71:6b:96:1a:2f:11:c9:8e:1e:49:bd:66:
+                    39:3f:4e:9d:30:f9:5e:7d:40:05:8f:2e:33:04:75:
+                    00:7b:dc:54:4d:b7:37:68:72:e6:f3:b7:3d:29:58:
+                    84:01:6b:98:29:ba:4c:2b:c1
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                41:D6:E0:DA:6C:87:A3:44:65:CC:AB:12:C8:6C:0C:72:3A:39:90:2E
+                D2:63:03:4B:B8:08:98:F2:25:62:95:57:75:A2:F1:AA:83:E9:0B:5F
             X509v3 Authority Key Identifier: 
-                keyid:41:D6:E0:DA:6C:87:A3:44:65:CC:AB:12:C8:6C:0C:72:3A:39:90:2E
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta2/emailAddress=ta2
-                serial:E4:2C:84:25:53:01:EB:E0
+                keyid:D2:63:03:4B:B8:08:98:F2:25:62:95:57:75:A2:F1:AA:83:E9:0B:5F
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        b1:c5:14:e7:5f:ca:f0:de:3b:c5:f6:10:7c:5c:8a:63:a1:f6:
-        07:4b:9d:9f:53:a9:c8:5c:d7:01:d1:df:6c:20:5c:f5:13:a2:
-        bc:5a:65:4a:b2:f9:25:7a:28:1b:4a:03:14:d5:e9:df:36:58:
-        e9:2e:d1:48:f9:89:7f:2c:04:a5:80:01:38:b5:b9:68:01:f8:
-        78:65:38:af:33:2f:fa:17:61:e4:fd:73:f8:a4:f7:b5:f5:f5:
-        d6:b9:94:3a:32:70:37:b1:e8:58:84:58:92:6c:6a:57:da:84:
-        a5:f5:a9:7e:c1:10:6d:54:fb:82:f9:59:8a:6b:23:5d:33:3a:
-        97:2d
+         40:4c:5f:92:42:4b:a1:21:e1:76:e1:87:1c:42:1f:15:bd:08:
+         4b:bd:ec:a8:8d:6f:d8:f4:2a:df:5d:f8:4c:df:6a:ea:5f:07:
+         ce:00:0a:06:88:60:9c:32:13:4f:e5:99:99:90:56:bc:91:7a:
+         5b:e2:2f:f6:90:e9:97:11:6c:ff:7c:aa:32:37:60:95:0b:b5:
+         b1:99:ec:1d:62:26:51:2f:b9:a2:f1:d2:ed:89:e4:52:c7:fa:
+         9b:62:d3:92:c4:33:c7:95:cb:4c:23:02:2d:af:bf:0e:58:26:
+         24:b7:b7:1c:f2:f4:88:3a:12:36:40:e5:58:5a:25:db:24:f0:
+         dd:9d
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAOQshCVTAevgMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTIxEjAQBgkqhkiG9w0BCQEWA3Rh
-MjAeFw0xMTA0MTEyMjM3NDNaFw0xNDAxMDUyMjM3NDNaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTIxEjAQBgkqhkiG9w0BCQEWA3RhMjCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA43XhRG1osdxka6MGCjuRrRDORZnz6jI8
-kryxhdXFYqb9PjNk+4RuCeHGdjRDY397k7xsDjFYsMDIx7RuqttAhmewLHmC+zEf
-cWwQpLkL3dh45LOjr97GDyH9XOYBtoeCmwQWbkKlVzn+heNXWM3+kMfTNX2RE78F
-8iGsQucP5OMCAwEAAaOBzTCByjAdBgNVHQ4EFgQUQdbg2myHo0RlzKsSyGwMcjo5
-kC4wgZoGA1UdIwSBkjCBj4AUQdbg2myHo0RlzKsSyGwMcjo5kC6hbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTIxEjAQBgkqhkiG9w0BCQEW
-A3RhMoIJAOQshCVTAevgMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-scUU51/K8N47xfYQfFyKY6H2B0udn1OpyFzXAdHfbCBc9ROivFplSrL5JXooG0oD
-FNXp3zZY6S7RSPmJfywEpYABOLW5aAH4eGU4rzMv+hdh5P1z+KT3tfX11rmUOjJw
-N7HoWIRYkmxqV9qEpfWpfsEQbVT7gvlZimsjXTM6ly0=
+MIICoDCCAgmgAwIBAgIJAPUzd9BU5ZMdMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEyMRIwEAYJKoZIhvcNAQkBFgN0
+YTIwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMjESMBAGCSqGSIb3DQEJARYDdGEyMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDKNPYVnN59oDc1C1Di2FtxqjAnw/uy
+VCSyfcxSpT2QHhw41LTw9LZj29wlwquyaraQhYWqX+0PU1OCXBlj1bv7s9jMPJtL
+mfFVWLs2XXFrlhovEcmOHkm9Zjk/Tp0w+V59QAWPLjMEdQB73FRNtzdocubztz0p
+WIQBa5gpukwrwQIDAQABo1AwTjAdBgNVHQ4EFgQU0mMDS7gImPIlYpVXdaLxqoPp
+C18wHwYDVR0jBBgwFoAU0mMDS7gImPIlYpVXdaLxqoPpC18wDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQBATF+SQkuhIeF24YccQh8VvQhLveyojW/Y9Crf
+XfhM32rqXwfOAAoGiGCcMhNP5ZmZkFa8kXpb4i/2kOmXEWz/fKoyN2CVC7Wxmewd
+YiZRL7mi8dLtieRSx/qbYtOSxDPHlctMIwItr78OWCYkt7cc8vSIOhI2QOVYWiXb
+JPDdnQ==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta3_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta3_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            f4:58:54:6a:83:22:66:e9
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+        Serial Number: 13890425601977148222 (0xc0c4b47d88d6e33e)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Validity
-            Not Before: Apr 11 22:37:43 2011 GMT
-            Not After : Jan  5 22:37:43 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta3/emailAddress=ta3
+            Not Before: Dec 13 00:13:35 2013 GMT
+            Not After : Sep  8 00:13:35 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta3/emailAddress=ta3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:d0:b0:e7:c0:27:96:d6:ff:16:89:f4:4c:67:d5:
-                    23:57:a6:af:fe:f3:be:d9:1e:28:44:a6:a3:0e:67:
-                    09:1f:b2:fc:70:fd:2c:4a:9c:13:a0:cf:37:97:2c:
-                    39:7c:42:a4:f7:64:7e:be:49:67:05:01:b3:f7:46:
-                    34:9b:d8:bd:4b:ac:d6:40:96:5a:6d:a0:33:ae:03:
-                    33:22:7d:06:39:6e:0a:5e:39:3f:e6:eb:c7:f9:e3:
-                    1a:a7:dd:16:14:6d:8e:b7:84:d9:af:b7:43:db:5d:
-                    0f:2b:e8:3d:fe:66:d7:9e:3a:06:a1:9f:c3:35:81:
-                    d4:cd:bc:16:3c:a2:c1:dd:89
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:cc:99:d3:8e:88:a3:54:f1:da:a6:39:be:69:28:
+                    5a:87:05:0b:04:59:41:21:39:40:8a:46:fd:f5:20:
+                    d5:6b:b6:02:cd:5f:62:2e:88:34:8b:3d:f1:c0:fe:
+                    38:f7:f6:1f:65:10:d7:0c:03:4c:90:17:f7:25:a4:
+                    62:eb:80:83:44:1f:b2:53:a4:de:c5:d2:17:7e:f6:
+                    96:fe:e2:1a:bc:45:97:dc:29:f9:46:70:11:8d:4a:
+                    f4:b6:b7:2d:67:20:8f:d0:6a:0f:20:09:ff:7c:11:
+                    1c:94:9b:5e:83:57:67:35:2e:37:a2:54:97:2a:fb:
+                    d1:38:64:d5:e0:79:2f:ae:2f
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
+                B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
             X509v3 Authority Key Identifier: 
-                keyid:7A:F6:51:7A:7F:9B:AB:37:3D:4E:93:03:90:6D:6A:84:09:7C:3A:DD
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta3/emailAddress=ta3
-                serial:F4:58:54:6A:83:22:66:E9
+                keyid:B4:D4:36:9F:F8:CB:A2:5F:50:89:DA:21:E3:27:C4:91:F7:84:88:45
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        26:1b:34:03:12:d5:13:94:0f:f8:57:6a:47:d8:d9:81:78:0b:
-        65:f1:51:b7:4e:b2:89:c2:6a:30:5d:37:ad:35:91:16:48:5f:
-        9b:b9:cd:30:1e:0e:f3:31:1e:7a:4e:72:13:c6:e4:66:0a:a9:
-        a4:66:5d:f6:fe:21:51:0f:ab:fd:d7:9d:5d:13:86:07:df:1d:
-        9d:d8:19:ce:6d:e9:7e:7a:19:06:20:07:cc:d1:a3:c2:04:28:
-        b8:9b:41:23:65:92:47:86:ee:ac:a5:7f:b7:2c:92:67:87:83:
-        5b:04:d0:e5:5d:3c:4c:a1:51:e0:9c:02:9a:d5:35:b4:7b:e0:
-        e4:c3
+         22:83:f2:64:c1:e3:e1:67:e4:55:ef:3b:0c:37:93:e9:c1:d7:
+         3f:0e:74:f1:03:59:1d:88:03:dd:d0:f5:38:40:c1:f3:da:93:
+         ff:c9:3f:6c:e8:14:ea:87:7f:25:34:3d:93:81:05:7d:89:70:
+         d2:18:50:17:a9:df:dd:c9:b2:88:80:7d:ed:3c:c5:8d:30:6d:
+         56:c8:f6:df:58:82:b5:76:0c:ab:e9:2d:78:be:1a:d2:e6:8e:
+         85:3f:00:6c:12:bf:d9:99:e1:dc:12:67:e0:57:9c:56:1e:2d:
+         e5:39:04:82:c2:a6:e0:ca:88:60:74:a2:1a:2a:2b:f4:a5:e9:
+         8e:07
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAPRYVGqDImbpMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEWA3Rh
-MzAeFw0xMTA0MTEyMjM3NDNaFw0xNDAxMDUyMjM3NDNaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEWA3RhMzCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA0LDnwCeW1v8WifRMZ9UjV6av/vO+2R4o
-RKajDmcJH7L8cP0sSpwToM83lyw5fEKk92R+vklnBQGz90Y0m9i9S6zWQJZabaAz
-rgMzIn0GOW4KXjk/5uvH+eMap90WFG2Ot4TZr7dD210PK+g9/mbXnjoGoZ/DNYHU
-zbwWPKLB3YkCAwEAAaOBzTCByjAdBgNVHQ4EFgQUevZRen+bqzc9TpMDkG1qhAl8
-Ot0wgZoGA1UdIwSBkjCBj4AUevZRen+bqzc9TpMDkG1qhAl8Ot2hbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTMxEjAQBgkqhkiG9w0BCQEW
-A3RhM4IJAPRYVGqDImbpMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-Jhs0AxLVE5QP+FdqR9jZgXgLZfFRt06yicJqMF03rTWRFkhfm7nNMB4O8zEeek5y
-E8bkZgqppGZd9v4hUQ+r/dedXROGB98dndgZzm3pfnoZBiAHzNGjwgQouJtBI2WS
-R4burKV/tyySZ4eDWwTQ5V08TKFR4JwCmtU1tHvg5MM=
+MIICoDCCAgmgAwIBAgIJAMDEtH2I1uM+MA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGEzMRIwEAYJKoZIhvcNAQkBFgN0
+YTMwHhcNMTMxMjEzMDAxMzM1WhcNMTYwOTA4MDAxMzM1WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhMzESMBAGCSqGSIb3DQEJARYDdGEzMIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMmdOOiKNU8dqmOb5pKFqHBQsEWUEh
+OUCKRv31INVrtgLNX2IuiDSLPfHA/jj39h9lENcMA0yQF/clpGLrgINEH7JTpN7F
+0hd+9pb+4hq8RZfcKflGcBGNSvS2ty1nII/Qag8gCf98ERyUm16DV2c1LjeiVJcq
++9E4ZNXgeS+uLwIDAQABo1AwTjAdBgNVHQ4EFgQUtNQ2n/jLol9Qidoh4yfEkfeE
+iEUwHwYDVR0jBBgwFoAUtNQ2n/jLol9Qidoh4yfEkfeEiEUwDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQAig/JkwePhZ+RV7zsMN5Ppwdc/DnTxA1kdiAPd
+0PU4QMHz2pP/yT9s6BTqh38lND2TgQV9iXDSGFAXqd/dybKIgH3tPMWNMG1WyPbf
+WIK1dgyr6S14vhrS5o6FPwBsEr/ZmeHcEmfgV5xWHi3lOQSCwqbgyohgdKIaKiv0
+pemOBw==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta4_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta4_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            ba:06:fd:ec:89:18:b5:7f
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+        Serial Number: 16787041411903739357 (0xe8f78d38fa4b55dd)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Validity
-            Not Before: Apr 11 22:37:49 2011 GMT
-            Not After : Jan  5 22:37:49 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta4/emailAddress=ta4
+            Not Before: Dec 13 00:13:37 2013 GMT
+            Not After : Sep  8 00:13:37 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta4/emailAddress=ta4
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:cf:c0:25:a7:fa:df:a4:e4:02:33:84:4d:a0:3f:
-                    4e:09:c4:ae:0a:58:d3:45:15:d3:5e:94:56:5a:b5:
-                    da:3e:27:68:66:3d:b1:83:14:bc:13:94:f3:a8:38:
-                    9c:e8:9a:46:4e:06:78:0d:29:95:69:a0:2c:12:19:
-                    3b:6b:a6:3d:46:eb:56:8a:f7:85:2d:d9:9c:f0:30:
-                    6b:0a:03:8d:ae:d8:cf:9e:df:c9:a5:d7:d3:b1:ab:
-                    13:74:e8:1e:a2:be:31:3f:17:78:22:4c:83:8b:24:
-                    ef:4f:5d:c4:6e:26:f8:b0:d9:2b:ad:9e:b0:c4:fc:
-                    c2:00:10:99:e9:39:17:68:05
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:a1:63:5b:f9:78:2a:19:df:d1:4e:d5:75:24:c6:
+                    8b:2f:e9:69:99:ab:82:24:b4:0f:66:ec:4c:c1:7a:
+                    bd:a4:5c:10:f1:61:c7:fe:2f:53:c1:10:8e:7c:83:
+                    4b:c5:50:ca:20:9e:aa:25:41:39:19:0e:7a:99:1a:
+                    8a:25:9b:df:67:b6:67:68:ad:f2:22:15:e8:e6:dd:
+                    3a:77:4a:b9:6f:e1:0a:70:92:0e:dd:a8:e7:62:e7:
+                    a3:3a:fe:ca:75:b4:2d:2c:60:cd:ae:87:fc:ba:27:
+                    c1:0d:85:b1:cc:7f:d9:f3:0f:7d:cb:3e:15:70:54:
+                    e1:2e:8a:88:9d:e7:05:57:47
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
+                84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
             X509v3 Authority Key Identifier: 
-                keyid:3E:5F:64:E9:63:CB:9C:10:D0:91:F4:45:61:F2:F1:EA:42:69:EC:A5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta4/emailAddress=ta4
-                serial:BA:06:FD:EC:89:18:B5:7F
+                keyid:84:46:29:88:74:31:EF:A6:CC:3C:E3:58:29:DE:BE:FD:1B:F4:59:98
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        c2:01:c5:40:3c:24:aa:8a:f3:be:31:f8:82:12:df:b8:e7:b4:
-        92:b1:95:79:d4:f7:db:2a:81:a2:f6:5f:3a:1d:b1:e2:a1:bd:
-        f1:50:75:cc:d6:f7:ab:26:d6:eb:a8:c6:f8:44:25:53:94:ce:
-        6e:a4:6e:4f:40:c2:13:00:b7:cb:b1:82:99:e9:1f:68:54:d0:
-        69:ba:02:5f:07:be:c2:f8:e3:2c:40:73:61:c2:c3:ad:4c:91:
-        f0:ba:0a:61:df:95:d6:fc:d3:19:e3:98:8e:58:73:03:6f:04:
-        9e:b6:f7:8c:3c:1e:60:43:27:96:6d:f5:e7:31:43:bb:22:da:
-        07:9c
+         07:ae:c1:fc:3b:d3:b3:b5:02:32:28:cb:49:f5:dc:fe:2d:9f:
+         21:09:78:85:f7:97:e6:cc:03:b4:08:de:04:a1:64:75:fe:94:
+         a8:48:0f:b9:20:11:b8:ba:2e:f1:c4:7f:03:10:0b:1c:f1:ed:
+         1e:c8:04:b6:28:34:99:61:57:4d:f0:fc:6b:81:f7:a3:8b:74:
+         5a:5f:f7:1d:68:29:ef:5e:cd:b5:ee:2a:72:17:be:db:a4:26:
+         7d:ab:4b:09:85:66:bf:ff:94:56:b5:e1:67:f4:0f:dd:88:50:
+         10:d6:98:96:51:ac:2c:24:8c:83:21:5a:8a:12:0f:e2:58:8f:
+         ef:07
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJALoG/eyJGLV/MA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEWA3Rh
-NDAeFw0xMTA0MTEyMjM3NDlaFw0xNDAxMDUyMjM3NDlaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEWA3RhNDCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAz8Alp/rfpOQCM4RNoD9OCcSuCljTRRXT
-XpRWWrXaPidoZj2xgxS8E5TzqDic6JpGTgZ4DSmVaaAsEhk7a6Y9RutWiveFLdmc
-8DBrCgONrtjPnt/JpdfTsasTdOgeor4xPxd4IkyDiyTvT13Ebib4sNkrrZ6wxPzC
-ABCZ6TkXaAUCAwEAAaOBzTCByjAdBgNVHQ4EFgQUPl9k6WPLnBDQkfRFYfLx6kJp
-7KUwgZoGA1UdIwSBkjCBj4AUPl9k6WPLnBDQkfRFYfLx6kJp7KWhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTQxEjAQBgkqhkiG9w0BCQEW
-A3RhNIIJALoG/eyJGLV/MAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-wgHFQDwkqorzvjH4ghLfuOe0krGVedT32yqBovZfOh2x4qG98VB1zNb3qybW66jG
-+EQlU5TObqRuT0DCEwC3y7GCmekfaFTQaboCXwe+wvjjLEBzYcLDrUyR8LoKYd+V
-1vzTGeOYjlhzA28Enrb3jDweYEMnlm315zFDuyLaB5w=
+MIICoDCCAgmgAwIBAgIJAOj3jTj6S1XdMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGE0MRIwEAYJKoZIhvcNAQkBFgN0
+YTQwHhcNMTMxMjEzMDAxMzM3WhcNMTYwOTA4MDAxMzM3WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhNDESMBAGCSqGSIb3DQEJARYDdGE0MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQChY1v5eCoZ39FO1XUkxosv6WmZq4Ik
+tA9m7EzBer2kXBDxYcf+L1PBEI58g0vFUMognqolQTkZDnqZGoolm99ntmdorfIi
+Fejm3Tp3Srlv4Qpwkg7dqOdi56M6/sp1tC0sYM2uh/y6J8ENhbHMf9nzD33LPhVw
+VOEuioid5wVXRwIDAQABo1AwTjAdBgNVHQ4EFgQUhEYpiHQx76bMPONYKd6+/Rv0
+WZgwHwYDVR0jBBgwFoAUhEYpiHQx76bMPONYKd6+/Rv0WZgwDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQAHrsH8O9OztQIyKMtJ9dz+LZ8hCXiF95fmzAO0
+CN4EoWR1/pSoSA+5IBG4ui7xxH8DEAsc8e0eyAS2KDSZYVdN8Pxrgfeji3RaX/cd
+aCnvXs217ipyF77bpCZ9q0sJhWa//5RWteFn9A/diFAQ1piWUawsJIyDIVqKEg/i
+WI/vBw==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta5_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta5_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,63 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            9c:19:39:11:06:1a:55:91
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta5/emailAddress=ta5
+        Serial Number: 12074133414322946630 (0xa78ff05e6b64c246)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta5/emailAddress=ta5
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, CN=ta5/emailAddress=ta5
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, CN=ta5/emailAddress=ta5
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c4:65:70:7a:0e:03:ae:85:f3:d6:03:6f:f9:a2:
-                    af:4e:ae:cd:d4:99:b6:6d:14:a4:12:62:54:1f:8b:
-                    c6:d3:8c:e8:7e:85:82:a5:f5:c9:03:66:f6:dd:48:
-                    58:5a:7a:20:c6:1d:7b:47:78:52:64:3f:0a:67:d0:
-                    cc:03:aa:2b:00:b5:89:7b:b1:50:fb:79:e1:d5:32:
-                    8c:c3:49:df:ba:2a:21:43:cb:c5:39:39:12:bd:3a:
-                    ba:7b:29:f2:48:32:37:84:c6:af:66:db:a2:a4:00:
-                    ec:40:08:c1:a8:36:0c:b6:48:c6:39:b1:fd:be:e2:
-                    60:a4:3d:c6:b6:b1:a8:be:55
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:b7:a8:13:3d:f3:64:60:87:d9:bd:d0:92:59:74:
+                    b9:dc:27:f8:40:15:39:9a:30:52:0f:73:5d:45:d8:
+                    b9:a1:9a:72:56:e2:85:1a:c0:18:8c:90:56:44:14:
+                    e5:50:70:69:e5:36:5b:a2:fb:3c:bf:f9:78:77:27:
+                    2d:de:3c:5e:3c:7d:d2:40:02:8b:bc:04:9b:8f:65:
+                    0b:74:3a:98:23:4d:e1:0d:4d:c3:42:cb:61:a8:42:
+                    bf:b2:1c:83:18:89:4f:b4:cf:cf:34:fd:f3:c7:7e:
+                    1b:54:3e:ed:e9:0a:13:8c:c2:56:f6:25:87:42:40:
+                    a3:ca:ab:ff:cc:ba:c6:c2:0d
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                E7:E6:72:5B:A0:5F:2C:A6:40:45:1A:66:E4:45:A5:0F:1D:67:5D:93
+                29:DA:B1:46:E3:61:51:AC:3C:3E:F6:78:5B:95:7B:6D:B2:F9:17:21
             X509v3 Authority Key Identifier: 
-                keyid:E7:E6:72:5B:A0:5F:2C:A6:40:45:1A:66:E4:45:A5:0F:1D:67:5D:93
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/CN=ta5/emailAddress=ta5
-                serial:9C:19:39:11:06:1A:55:91
+                keyid:29:DA:B1:46:E3:61:51:AC:3C:3E:F6:78:5B:95:7B:6D:B2:F9:17:21
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        89:2d:87:d4:a5:2a:63:ce:4d:12:6f:ca:94:d3:e9:ac:3e:93:
-        30:f3:1a:20:05:9d:8c:72:7c:70:ea:00:c9:b6:39:d8:5a:d1:
-        87:1e:57:8f:2f:61:f1:ec:a8:f2:b9:2b:03:d5:0c:07:e4:f5:
-        01:8d:00:95:fd:9c:12:d0:86:3f:8d:cf:3a:5b:ae:2d:a2:6f:
-        2d:ee:a6:10:6f:f0:d0:5f:dd:78:02:3e:1f:0d:f3:ae:a2:fa:
-        c5:9d:96:ae:31:a8:a3:ba:a4:78:a8:ec:db:e7:61:de:d3:5c:
-        c4:c2:4d:5c:b4:cb:f8:27:6e:53:06:11:e0:e7:aa:41:7f:bd:
-        9a:8a
+         21:28:62:ac:b3:da:3a:66:ed:13:bc:72:15:0d:44:87:25:c9:
+         8e:0d:37:cf:b9:2b:3b:64:30:6f:67:6e:b7:6a:6e:c7:12:f9:
+         68:9c:78:cd:de:72:fe:05:bb:59:58:47:93:c3:f7:41:fe:30:
+         44:53:57:9a:6c:3e:6c:a4:c9:68:a1:5b:80:b1:3c:e7:e9:c1:
+         11:11:99:ad:60:24:0e:ca:17:56:d2:48:db:c5:9a:3f:f1:92:
+         01:a7:5a:2a:d0:6e:2e:6c:20:3d:97:ba:2e:b1:00:a1:6f:1b:
+         14:83:dd:32:3c:fd:18:c7:b2:85:b8:a6:03:98:fa:eb:d1:45:
+         4e:f9
 -----BEGIN CERTIFICATE-----
-MIIDHDCCAoWgAwIBAgIJAJwZOREGGlWRMA0GCSqGSIb3DQEBCwUAMGgxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTUxEjAQBgkqhkiG9w0BCQEWA3Rh
-NTAeFw0xMTA0MTEyMjM3NTJaFw0xNDAxMDUyMjM3NTJaMGgxCzAJBgNVBAYTAlVT
-MRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJrMQ0wCwYD
-VQQKEwRwa2c1MQwwCgYDVQQDEwN0YTUxEjAQBgkqhkiG9w0BCQEWA3RhNTCBnzAN
-BgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxGVweg4DroXz1gNv+aKvTq7N1Jm2bRSk
-EmJUH4vG04zofoWCpfXJA2b23UhYWnogxh17R3hSZD8KZ9DMA6orALWJe7FQ+3nh
-1TKMw0nfuiohQ8vFOTkSvTq6eynySDI3hMavZtuipADsQAjBqDYMtkjGObH9vuJg
-pD3GtrGovlUCAwEAAaOBzTCByjAdBgNVHQ4EFgQU5+ZyW6BfLKZARRpm5EWlDx1n
-XZMwgZoGA1UdIwSBkjCBj4AU5+ZyW6BfLKZARRpm5EWlDx1nXZOhbKRqMGgxCzAJ
-BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQ
-YXJrMQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQDEwN0YTUxEjAQBgkqhkiG9w0BCQEW
-A3RhNYIJAJwZOREGGlWRMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEA
-iS2H1KUqY85NEm/KlNPprD6TMPMaIAWdjHJ8cOoAybY52FrRhx5Xjy9h8eyo8rkr
-A9UMB+T1AY0Alf2cEtCGP43POluuLaJvLe6mEG/w0F/deAI+Hw3zrqL6xZ2WrjGo
-o7qkeKjs2+dh3tNcxMJNXLTL+CduUwYR4OeqQX+9moo=
+MIICoDCCAgmgAwIBAgIJAKeP8F5rZMJGMA0GCSqGSIb3DQEBCwUAMGkxCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UEAwwDdGE1MRIwEAYJKoZIhvcNAQkBFgN0
+YTUwHhcNMTMxMjEzMDAxMzM4WhcNMTYwOTA4MDAxMzM4WjBpMQswCQYDVQQGEwJV
+UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEUMBIGA1UEBwwLU2FudGEgQ2xhcmExDTAL
+BgNVBAoMBHBrZzUxDDAKBgNVBAMMA3RhNTESMBAGCSqGSIb3DQEJARYDdGE1MIGf
+MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3qBM982Rgh9m90JJZdLncJ/hAFTma
+MFIPc11F2LmhmnJW4oUawBiMkFZEFOVQcGnlNlui+zy/+Xh3Jy3ePF48fdJAAou8
+BJuPZQt0OpgjTeENTcNCy2GoQr+yHIMYiU+0z880/fPHfhtUPu3pChOMwlb2JYdC
+QKPKq//MusbCDQIDAQABo1AwTjAdBgNVHQ4EFgQUKdqxRuNhUaw8PvZ4W5V7bbL5
+FyEwHwYDVR0jBBgwFoAUKdqxRuNhUaw8PvZ4W5V7bbL5FyEwDAYDVR0TBAUwAwEB
+/zANBgkqhkiG9w0BAQsFAAOBgQAhKGKss9o6Zu0TvHIVDUSHJcmODTfPuSs7ZDBv
+Z263am7HEvlonHjN3nL+BbtZWEeTw/dB/jBEU1eabD5spMlooVuAsTzn6cEREZmt
+YCQOyhdW0kjbxZo/8ZIBp1oq0G4ubCA9l7ousQChbxsUg90yPP0Yx7KFuKYDmPrr
+0UVO+Q==
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta6_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta6_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            93:ae:7e:2d:c9:61:8f:4b
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+        Serial Number: 14039479151502690113 (0xc2d63fe768d20741)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Validity
-            Not Before: Apr 11 22:37:52 2011 GMT
-            Not After : Jan  5 22:37:52 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta6, CN=localhost/emailAddress=ta6
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c5:41:a2:3d:00:af:e2:71:29:e6:18:c2:73:65:
-                    fc:4a:9d:e3:f7:1a:6e:7a:f5:09:81:87:cd:cf:a9:
-                    74:a9:e4:47:da:e2:fa:bd:0e:0a:ae:ba:06:e8:1b:
-                    66:e3:8a:5e:bb:87:90:5e:d1:38:7d:12:93:72:a0:
-                    4b:88:77:dd:ce:02:67:9f:c5:be:49:cb:b7:e8:0e:
-                    bd:f0:78:37:55:bb:c5:91:6e:c7:7b:9c:b3:94:a2:
-                    24:7d:09:25:74:52:22:6d:4a:34:f8:92:71:b1:e9:
-                    74:9b:8e:87:d4:2a:46:f8:fa:8f:86:5c:b5:6b:20:
-                    24:d1:37:ea:8a:87:07:e3:ad
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c5:43:65:b9:e0:b5:bf:68:f6:d0:67:91:49:1f:
+                    53:c8:eb:36:57:b9:76:c9:d7:2d:26:4c:f2:08:38:
+                    e6:5d:56:b6:20:af:72:ea:ac:98:de:14:cd:35:ed:
+                    f9:b3:fb:e3:c4:1f:06:db:04:77:2a:cd:3e:3e:98:
+                    9f:52:f1:9e:27:db:91:ec:f4:de:3e:53:d5:fc:ba:
+                    5c:37:98:8b:b7:45:4c:bb:a9:d0:cc:b5:f8:45:a4:
+                    0c:58:a0:92:60:05:26:01:96:08:c1:8d:5f:18:e8:
+                    84:f1:d0:a2:f1:e3:32:67:20:52:a6:6f:7a:47:39:
+                    f1:f0:c0:47:6f:3b:9e:7c:81
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                0C:08:1A:2C:FA:77:26:CE:37:0F:A5:85:98:85:0F:4D:48:BA:83:B3
+                75:D7:5E:D6:65:E8:AA:54:31:F5:3A:5C:DA:C8:EE:5C:02:46:28:26
             X509v3 Authority Key Identifier: 
-                keyid:0C:08:1A:2C:FA:77:26:CE:37:0F:A5:85:98:85:0F:4D:48:BA:83:B3
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta6/CN=localhost/emailAddress=ta6
-                serial:93:AE:7E:2D:C9:61:8F:4B
+                keyid:75:D7:5E:D6:65:E8:AA:54:31:F5:3A:5C:DA:C8:EE:5C:02:46:28:26
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        10:2c:ed:b9:a4:aa:bd:9e:4d:47:dd:02:64:52:a9:7a:73:a7:
-        f3:58:45:cf:da:5c:1e:80:30:d9:10:a7:e4:79:d2:eb:85:8b:
-        70:4c:39:df:b6:40:fb:7f:11:cd:a8:85:d6:5c:d1:2f:29:9f:
-        8d:fa:53:bc:20:f3:c8:97:9b:11:f4:7d:39:9a:2c:a6:6e:1e:
-        a4:0d:81:e0:65:59:89:f6:a9:66:65:38:05:44:e7:47:a2:9e:
-        a2:e3:82:07:2c:cb:8e:dc:47:a2:e9:cb:01:6a:54:c1:26:14:
-        03:e9:c3:ac:fe:98:0e:76:52:f3:5b:67:ea:26:0d:98:6d:e4:
-        23:ac
+         c0:55:58:54:3d:b7:dd:d8:c4:3f:35:a4:d9:25:b3:45:08:f3:
+         5b:98:16:46:40:36:01:c9:60:d4:a6:2b:9e:29:6d:89:26:d7:
+         4e:69:35:ba:15:b2:d1:1a:5e:97:ad:b3:16:33:c5:5b:4f:4f:
+         0e:8d:8e:b3:28:50:00:ad:88:2a:2c:60:d3:66:7c:66:95:f9:
+         83:0a:ae:14:8b:d8:42:35:8d:50:7f:b2:23:1f:9b:28:ca:de:
+         61:b8:6d:c5:38:4a:e1:60:da:75:42:f3:18:4c:14:ae:b0:5d:
+         a9:ab:ae:10:89:09:cc:61:1e:ce:28:95:f0:44:98:33:04:9c:
+         db:8f
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAJOufi3JYY9LMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTYxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE2MB4XDTExMDQxMTIyMzc1MloXDTE0MDEwNTIy
-Mzc1MlowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNjESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTYwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAMVBoj0Ar+JxKeYYwnNl/Eqd4/cabnr1CYGHzc+pdKnk
-R9ri+r0OCq66BugbZuOKXruHkF7ROH0Sk3KgS4h33c4CZ5/FvknLt+gOvfB4N1W7
-xZFux3ucs5SiJH0JJXRSIm1KNPiScbHpdJuOh9QqRvj6j4ZctWsgJNE36oqHB+Ot
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFAwIGiz6dybONw+lhZiFD01IuoOzMIGvBgNV
-HSMEgacwgaSAFAwIGiz6dybONw+lhZiFD01IuoOzoYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNjESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTaCCQCTrn4tyWGPSzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBABAs7bmkqr2eTUfdAmRSqXpzp/NYRc/aXB6AMNkQp+R50uuF
-i3BMOd+2QPt/Ec2ohdZc0S8pn436U7wg88iXmxH0fTmaLKZuHqQNgeBlWYn2qWZl
-OAVE50einqLjggcsy47cR6LpywFqVMEmFAPpw6z+mA52UvNbZ+omDZht5COs
+MIICyDCCAjGgAwIBAgIJAMLWP+do0gdBMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE2MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhNjAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE2MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhNjCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAxUNlueC1v2j20GeRSR9TyOs2V7l2ydctJkzyCDjm
+XVa2IK9y6qyY3hTNNe35s/vjxB8G2wR3Ks0+PpifUvGeJ9uR7PTePlPV/LpcN5iL
+t0VMu6nQzLX4RaQMWKCSYAUmAZYIwY1fGOiE8dCi8eMyZyBSpm96Rznx8MBHbzue
+fIECAwEAAaNQME4wHQYDVR0OBBYEFHXXXtZl6KpUMfU6XNrI7lwCRigmMB8GA1Ud
+IwQYMBaAFHXXXtZl6KpUMfU6XNrI7lwCRigmMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAwFVYVD233djEPzWk2SWzRQjzW5gWRkA2Aclg1KYrniltiSbX
+Tmk1uhWy0Rpel62zFjPFW09PDo2OsyhQAK2IKixg02Z8ZpX5gwquFIvYQjWNUH+y
+Ix+bKMreYbhtxThK4WDadULzGEwUrrBdqauuEIkJzGEeziiV8ESYMwSc248=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta7_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta7_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            e2:68:f4:95:eb:49:89:87
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
+        Serial Number: 17133169234141367739 (0xedc53ea49da5cdbb)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta7, CN=localhost/emailAddress=ta7
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:c8:de:52:36:7b:6e:4b:6d:7a:83:73:ad:41:cd:
-                    af:36:02:62:36:3e:f7:55:07:11:24:43:c2:eb:43:
-                    e4:6f:1d:3c:ec:73:4b:81:58:a2:2a:7e:e0:c4:f0:
-                    9a:ae:04:d8:2a:49:39:bf:9e:e8:ad:f0:96:52:5e:
-                    3c:67:71:7f:3d:40:d7:36:e3:1c:25:da:0b:29:e9:
-                    8b:81:66:19:bc:34:38:1a:4e:cb:63:f5:30:cf:82:
-                    6c:f5:14:cc:df:bb:cc:ed:70:86:e4:ba:6e:db:85:
-                    ce:60:d1:69:37:48:e8:0c:c0:76:82:0f:5f:65:09:
-                    62:0d:72:c9:5a:b3:49:2c:fd
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:f9:53:0d:ea:ab:4d:2f:d9:fa:75:3c:f6:57:80:
+                    d1:92:29:44:be:db:7d:6d:5e:f7:4e:a1:76:83:b3:
+                    31:a5:40:3e:44:d0:8e:2e:37:f9:6c:3e:28:4f:1e:
+                    52:66:eb:e9:4c:52:e9:7f:94:e3:9f:2c:e4:65:c3:
+                    fc:27:9b:2e:42:81:3e:0d:13:bb:58:52:f6:50:b6:
+                    f5:ef:2e:ac:94:52:4e:4a:a9:1a:e7:19:0e:2b:4a:
+                    46:59:57:de:a4:65:55:43:70:57:52:55:95:e4:17:
+                    5d:cf:0d:e4:3b:f7:42:4b:ce:25:9d:21:3e:41:29:
+                    30:c1:22:b2:77:85:7a:83:fd
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                78:FA:1D:E8:35:33:AD:40:EB:A9:B4:3E:87:7A:B0:65:17:CF:36:35
+                45:9D:B1:D7:6F:E2:FD:4F:9C:E9:10:78:EE:E7:33:1A:14:E1:AF:9D
             X509v3 Authority Key Identifier: 
-                keyid:78:FA:1D:E8:35:33:AD:40:EB:A9:B4:3E:87:7A:B0:65:17:CF:36:35
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta7/CN=localhost/emailAddress=ta7
-                serial:E2:68:F4:95:EB:49:89:87
+                keyid:45:9D:B1:D7:6F:E2:FD:4F:9C:E9:10:78:EE:E7:33:1A:14:E1:AF:9D
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        07:20:33:b6:af:9e:b1:49:90:57:19:86:e9:8b:18:8a:e9:7b:
-        b1:b4:ff:29:5e:de:df:c9:f9:c8:7d:de:61:0d:36:fc:55:dc:
-        e7:51:ff:89:b5:69:07:72:60:b6:19:4e:c4:90:e6:e7:c1:0e:
-        56:ba:d6:1c:c7:34:10:38:2d:c5:71:79:8a:de:a6:b2:d6:cf:
-        98:dc:9a:3e:df:d3:57:67:bd:15:83:95:00:1c:2d:45:9c:73:
-        6d:82:57:9d:ac:57:f1:d8:39:ae:92:3b:ff:36:a1:0e:08:46:
-        e6:00:a9:d6:3e:5b:fa:65:7f:8c:c6:ee:4e:84:e0:a8:81:b7:
-        3c:a5
+         b3:53:c9:a1:7f:13:e8:4b:ff:f0:81:84:9a:8c:1d:44:ef:3c:
+         fb:a8:e6:0d:62:9b:0f:f9:a9:c9:ca:4b:26:2e:51:6d:f3:ac:
+         b9:9e:2c:10:96:1c:f7:80:ff:5e:30:4f:a0:67:9b:84:3e:bc:
+         b5:6f:78:42:02:12:d9:e6:4f:a3:a0:82:eb:bf:00:44:b3:6f:
+         2f:56:c3:36:03:d1:b9:b9:e5:3c:53:3a:17:69:af:42:91:fa:
+         b5:91:b2:06:7f:07:88:e7:ac:7a:2b:b7:c3:41:e8:7d:9b:96:
+         c9:3d:38:4a:4c:39:45:35:c1:43:05:b2:32:00:99:22:72:2a:
+         7c:00
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAOJo9JXrSYmHMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTcxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE3MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNzESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTcwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAMjeUjZ7bktteoNzrUHNrzYCYjY+91UHESRDwutD5G8d
-POxzS4FYoip+4MTwmq4E2CpJOb+e6K3wllJePGdxfz1A1zbjHCXaCynpi4FmGbw0
-OBpOy2P1MM+CbPUUzN+7zO1whuS6btuFzmDRaTdI6AzAdoIPX2UJYg1yyVqzSSz9
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFHj6Heg1M61A66m0Pod6sGUXzzY1MIGvBgNV
-HSMEgacwgaSAFHj6Heg1M61A66m0Pod6sGUXzzY1oYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhNzESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTeCCQDiaPSV60mJhzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAAcgM7avnrFJkFcZhumLGIrpe7G0/yle3t/J+ch93mENNvxV
-3OdR/4m1aQdyYLYZTsSQ5ufBDla61hzHNBA4LcVxeYreprLWz5jcmj7f01dnvRWD
-lQAcLUWcc22CV52sV/HYOa6SO/82oQ4IRuYAqdY+W/plf4zG7k6E4KiBtzyl
+MIICyDCCAjGgAwIBAgIJAO3FPqSdpc27MA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE3MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhNzAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE3MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhNzCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEA+VMN6qtNL9n6dTz2V4DRkilEvtt9bV73TqF2g7Mx
+pUA+RNCOLjf5bD4oTx5SZuvpTFLpf5TjnyzkZcP8J5suQoE+DRO7WFL2ULb17y6s
+lFJOSqka5xkOK0pGWVfepGVVQ3BXUlWV5Bddzw3kO/dCS84lnSE+QSkwwSKyd4V6
+g/0CAwEAAaNQME4wHQYDVR0OBBYEFEWdsddv4v1PnOkQeO7nMxoU4a+dMB8GA1Ud
+IwQYMBaAFEWdsddv4v1PnOkQeO7nMxoU4a+dMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAs1PJoX8T6Ev/8IGEmowdRO88+6jmDWKbD/mpycpLJi5RbfOs
+uZ4sEJYc94D/XjBPoGebhD68tW94QgIS2eZPo6CC678ARLNvL1bDNgPRubnlPFM6
+F2mvQpH6tZGyBn8HiOeseiu3w0HofZuWyT04Skw5RTXBQwWyMgCZInIqfAA=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta8_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta8_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            b8:9a:b1:4d:fa:a9:68:23
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
+        Serial Number: 16709229305513134148 (0xe7e31b8629a84844)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta8, CN=localhost/emailAddress=ta8
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:da:5e:85:e0:17:14:35:c1:e8:f4:b6:97:15:d1:
-                    f5:c3:36:26:57:85:5c:0c:e8:8e:d7:2b:10:66:b2:
-                    61:92:a3:df:a4:4f:61:52:41:9c:3b:2f:0e:bc:bd:
-                    92:9b:e2:4c:ec:68:34:76:2c:86:54:e5:8b:9e:ac:
-                    2f:7e:4f:07:52:ec:7f:51:31:ed:9e:94:ed:7e:15:
-                    da:4f:fb:65:d0:07:85:c2:60:69:ce:ac:74:72:8a:
-                    45:31:e4:6c:3e:5e:05:bc:d3:2f:37:56:14:c2:2e:
-                    78:78:6b:93:14:e5:61:08:22:ef:4d:f9:bb:1b:1f:
-                    31:09:12:7a:ad:e5:cf:18:5b
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c6:4d:f7:24:79:d7:8f:a0:93:61:37:d0:a4:5c:
+                    61:81:e2:1a:1c:0a:ff:ce:8b:3d:49:15:12:1c:1b:
+                    b7:9c:dd:28:f6:c5:5d:2e:63:f7:67:4b:c9:8c:95:
+                    5a:1c:e8:97:89:16:83:81:ff:bc:10:26:51:7c:f9:
+                    f1:03:f5:51:f4:01:45:da:d4:2f:cf:d9:35:68:0c:
+                    ae:11:2d:31:37:5a:73:73:c0:60:13:c8:10:73:3a:
+                    7d:c9:96:8c:07:00:b1:41:52:d2:b0:5f:cd:01:06:
+                    b8:d7:3f:d8:0f:17:f9:38:39:5d:2d:09:14:99:05:
+                    7c:1f:1f:6f:c9:2d:7d:6e:61
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                BB:CA:54:46:B9:0F:22:DB:69:82:15:BB:66:36:9D:50:1D:0B:1B:F5
+                9E:DE:D5:93:0F:57:31:37:6C:9A:F7:DA:A2:A0:D2:CE:F4:65:EC:86
             X509v3 Authority Key Identifier: 
-                keyid:BB:CA:54:46:B9:0F:22:DB:69:82:15:BB:66:36:9D:50:1D:0B:1B:F5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta8/CN=localhost/emailAddress=ta8
-                serial:B8:9A:B1:4D:FA:A9:68:23
+                keyid:9E:DE:D5:93:0F:57:31:37:6C:9A:F7:DA:A2:A0:D2:CE:F4:65:EC:86
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        7a:13:83:75:43:35:e1:4d:07:93:8d:1c:fd:4d:8f:5c:24:78:
-        f5:01:35:4c:a5:ad:5f:92:f3:23:21:0c:2d:dc:64:a5:7f:c2:
-        3c:c9:e3:b0:4e:d8:17:4e:76:4c:4d:71:fb:b9:3d:d9:51:b8:
-        fc:e0:91:a6:5c:18:c8:06:55:cc:a9:ba:9e:59:92:c4:5c:04:
-        11:e2:d9:99:1d:cb:bd:9d:6c:c2:0e:9e:f0:4c:20:69:6b:b1:
-        76:b6:d4:c0:e6:6c:4b:1e:18:cb:71:4a:9b:13:ca:db:c8:a4:
-        0e:35:c0:91:70:04:9c:32:bd:15:a2:36:72:97:d0:7b:d0:6c:
-        dc:03
+         81:1f:1d:b5:60:85:60:4f:9f:cc:9a:12:99:4a:dc:fb:49:2b:
+         70:9d:21:1e:d7:be:fe:a8:b8:eb:fd:49:e2:99:72:ae:0e:be:
+         cf:bc:c4:88:11:8e:5b:6c:d5:68:d0:cb:52:1a:7c:65:a2:c1:
+         1f:08:7e:31:6e:28:18:fa:04:90:70:d5:96:aa:89:97:9d:61:
+         08:47:f5:75:4c:9d:96:c7:37:8f:3e:f2:04:bc:48:a6:89:65:
+         25:27:13:70:5a:f7:97:ba:42:61:a5:d9:69:44:08:34:19:4d:
+         6e:1c:e7:23:25:1f:c0:f3:ad:fa:56:c2:02:75:ed:c2:51:ca:
+         cf:96
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJALiasU36qWgjMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTgxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE4MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhODESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTgwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBANpeheAXFDXB6PS2lxXR9cM2JleFXAzojtcrEGayYZKj
-36RPYVJBnDsvDry9kpviTOxoNHYshlTli56sL35PB1Lsf1Ex7Z6U7X4V2k/7ZdAH
-hcJgac6sdHKKRTHkbD5eBbzTLzdWFMIueHhrkxTlYQgi7035uxsfMQkSeq3lzxhb
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFLvKVEa5DyLbaYIVu2Y2nVAdCxv1MIGvBgNV
-HSMEgacwgaSAFLvKVEa5DyLbaYIVu2Y2nVAdCxv1oYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhODESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTiCCQC4mrFN+qloIzAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAHoTg3VDNeFNB5ONHP1Nj1wkePUBNUylrV+S8yMhDC3cZKV/
-wjzJ47BO2BdOdkxNcfu5PdlRuPzgkaZcGMgGVcypup5ZksRcBBHi2Zkdy72dbMIO
-nvBMIGlrsXa21MDmbEseGMtxSpsTytvIpA41wJFwBJwyvRWiNnKX0HvQbNwD
+MIICyDCCAjGgAwIBAgIJAOfjG4YpqEhEMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE4MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhODAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE4MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhODCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAxk33JHnXj6CTYTfQpFxhgeIaHAr/zos9SRUSHBu3
+nN0o9sVdLmP3Z0vJjJVaHOiXiRaDgf+8ECZRfPnxA/VR9AFF2tQvz9k1aAyuES0x
+N1pzc8BgE8gQczp9yZaMBwCxQVLSsF/NAQa41z/YDxf5ODldLQkUmQV8Hx9vyS19
+bmECAwEAAaNQME4wHQYDVR0OBBYEFJ7e1ZMPVzE3bJr32qKg0s70ZeyGMB8GA1Ud
+IwQYMBaAFJ7e1ZMPVzE3bJr32qKg0s70ZeyGMAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAgR8dtWCFYE+fzJoSmUrc+0krcJ0hHte+/qi46/1J4plyrg6+
+z7zEiBGOW2zVaNDLUhp8ZaLBHwh+MW4oGPoEkHDVlqqJl51hCEf1dUydlsc3jz7y
+BLxIpollJScTcFr3l7pCYaXZaUQINBlNbhznIyUfwPOt+lbCAnXtwlHKz5Y=
 -----END CERTIFICATE-----
--- a/src/tests/ro_data/signing_certs/produced/trust_anchors/ta9_cert.pem	Thu Dec 12 15:14:05 2013 -0800
+++ b/src/tests/ro_data/signing_certs/produced/trust_anchors/ta9_cert.pem	Mon Dec 16 10:35:54 2013 -0800
@@ -1,64 +1,58 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number:
-            a1:62:e1:e5:c0:a2:38:0d
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
+        Serial Number: 16519569919148996401 (0xe5414d51291ab731)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
         Validity
-            Not Before: Apr 11 22:37:54 2011 GMT
-            Not After : Jan  5 22:37:54 2014 GMT
-        Subject: C=US, ST=California, L=Menlo Park, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
+            Not Before: Dec 13 00:13:38 2013 GMT
+            Not After : Sep  8 00:13:38 2016 GMT
+        Subject: C=US, ST=California, L=Santa Clara, O=pkg5, OU=ta9, CN=localhost/emailAddress=ta9
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-            RSA Public Key: (1024 bit)
-                Modulus (1024 bit):
-                    00:e8:ab:ef:91:ca:05:4a:18:a2:98:c4:d8:93:d0:
-                    ce:99:a9:5e:02:8d:5d:5c:e3:f3:84:49:6b:a7:6d:
-                    ef:38:77:2e:32:c2:9c:09:1d:f6:be:6c:c6:c4:b1:
-                    c8:c3:32:72:2b:84:87:f6:ba:bf:fc:cf:5c:05:c2:
-                    4f:62:23:7e:02:3f:ce:6c:c6:b6:95:86:84:d7:97:
-                    9f:1c:87:70:29:62:6a:29:7c:06:a3:b7:18:12:67:
-                    07:3a:89:aa:f0:99:fe:df:46:00:b1:2f:aa:30:1e:
-                    a2:1e:f8:2b:37:99:21:b8:85:53:42:98:4a:bd:c5:
-                    f9:b4:61:60:0a:73:bc:0e:d1
+                Public-Key: (1024 bit)
+                Modulus:
+                    00:c9:8a:2d:0d:53:04:e8:02:bb:bc:27:df:0e:b8:
+                    33:25:07:54:61:d0:d9:b6:08:33:5b:c3:eb:4c:a1:
+                    1f:9f:51:cc:a9:83:07:16:15:9c:69:0b:48:74:62:
+                    35:5f:a3:94:38:37:0f:3f:5f:58:26:9a:36:0b:a2:
+                    0f:bb:9b:57:ff:fd:70:01:d6:28:a2:b6:67:ed:a9:
+                    c8:90:15:b5:7f:91:60:32:ff:96:13:a4:3f:09:23:
+                    70:2f:38:6f:24:54:41:95:2f:91:5a:6e:a5:aa:77:
+                    da:6c:50:ee:62:e5:85:8a:67:63:7d:fc:07:30:ba:
+                    f3:96:93:6c:5d:5f:9e:2e:07
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Subject Key Identifier: 
-                A6:CF:35:00:96:15:AD:B4:24:DE:1D:5A:B9:56:A2:6E:B4:2D:46:C5
+                E8:5E:8E:77:D1:61:64:BB:48:AF:38:95:0C:57:16:4E:E3:77:3D:35
             X509v3 Authority Key Identifier: 
-                keyid:A6:CF:35:00:96:15:AD:B4:24:DE:1D:5A:B9:56:A2:6E:B4:2D:46:C5
-                DirName:/C=US/ST=California/L=Menlo Park/O=pkg5/OU=ta9/CN=localhost/emailAddress=ta9
-                serial:A1:62:E1:E5:C0:A2:38:0D
+                keyid:E8:5E:8E:77:D1:61:64:BB:48:AF:38:95:0C:57:16:4E:E3:77:3D:35
 
             X509v3 Basic Constraints: 
                 CA:TRUE
     Signature Algorithm: sha256WithRSAEncryption
-        44:02:da:cf:c3:07:27:84:e4:06:22:ff:fc:7e:c9:47:7a:79:
-        e1:9f:6a:84:68:a8:fb:48:18:80:58:0f:b0:5e:ef:43:bf:3a:
-        69:23:b2:18:3e:78:3a:8e:ff:c5:d8:76:4c:99:d5:9f:be:8a:
-        fd:0e:79:b9:7e:62:c4:c2:4b:6f:78:01:e7:52:19:ff:08:86:
-        a7:b2:17:0c:11:03:ef:42:1f:b5:5b:40:0a:3a:9f:2a:4f:57:
-        31:3d:b1:dd:a8:51:e1:2f:b2:e4:5b:2e:1b:9f:a7:d6:b7:6b:
-        76:68:f9:2e:b1:38:6f:11:21:0e:81:a2:32:01:7b:bc:c3:1f:
-        82:4e
+         3e:20:dc:10:1b:b4:83:9a:0a:9a:41:d3:6f:ec:ef:5b:51:0f:
+         a7:4a:49:0e:b3:86:f6:0f:c2:84:ea:0f:b2:08:6d:a2:7c:e4:
+         24:10:ba:45:c2:c3:9e:07:b9:c3:74:10:f2:74:7f:c7:61:2e:
+         0e:45:33:00:c4:19:32:61:2b:58:0a:f4:51:7a:03:66:68:32:
+         27:c3:20:27:af:c4:93:64:45:0d:16:0e:ca:2b:86:f6:1c:22:
+         13:74:5a:d2:68:fc:45:11:b8:f1:13:26:e1:e4:c2:b7:b5:b8:
+         f8:fc:cc:6d:fb:87:3e:5d:53:31:ba:99:16:65:7b:b1:6c:e9:
+         78:8a
 -----BEGIN CERTIFICATE-----
-MIIDWTCCAsKgAwIBAgIJAKFi4eXAojgNMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV
-BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRMwEQYDVQQHEwpNZW5sbyBQYXJr
-MQ0wCwYDVQQKEwRwa2c1MQwwCgYDVQQLEwN0YTkxEjAQBgNVBAMTCWxvY2FsaG9z
-dDESMBAGCSqGSIb3DQEJARYDdGE5MB4XDTExMDQxMTIyMzc1NFoXDTE0MDEwNTIy
-Mzc1NFowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNV
-BAcTCk1lbmxvIFBhcmsxDTALBgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhOTESMBAG
-A1UEAxMJbG9jYWxob3N0MRIwEAYJKoZIhvcNAQkBFgN0YTkwgZ8wDQYJKoZIhvcN
-AQEBBQADgY0AMIGJAoGBAOir75HKBUoYopjE2JPQzpmpXgKNXVzj84RJa6dt7zh3
-LjLCnAkd9r5sxsSxyMMyciuEh/a6v/zPXAXCT2IjfgI/zmzGtpWGhNeXnxyHcCli
-ail8BqO3GBJnBzqJqvCZ/t9GALEvqjAeoh74KzeZIbiFU0KYSr3F+bRhYApzvA7R
-AgMBAAGjgeIwgd8wHQYDVR0OBBYEFKbPNQCWFa20JN4dWrlWom60LUbFMIGvBgNV
-HSMEgacwgaSAFKbPNQCWFa20JN4dWrlWom60LUbFoYGApH4wfDELMAkGA1UEBhMC
-VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEzARBgNVBAcTCk1lbmxvIFBhcmsxDTAL
-BgNVBAoTBHBrZzUxDDAKBgNVBAsTA3RhOTESMBAGA1UEAxMJbG9jYWxob3N0MRIw
-EAYJKoZIhvcNAQkBFgN0YTmCCQChYuHlwKI4DTAMBgNVHRMEBTADAQH/MA0GCSqG
-SIb3DQEBCwUAA4GBAEQC2s/DByeE5AYi//x+yUd6eeGfaoRoqPtIGIBYD7Be70O/
-Omkjshg+eDqO/8XYdkyZ1Z++iv0Oebl+YsTCS294AedSGf8IhqeyFwwRA+9CH7Vb
-QAo6nypPVzE9sd2oUeEvsuRbLhufp9a3a3Zo+S6xOG8RIQ6BojIBe7zDH4JO
+MIICyDCCAjGgAwIBAgIJAOVBTVEpGrcxMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNV
+BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYDVQQHDAtTYW50YSBDbGFy
+YTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE5MRIwEAYDVQQDDAlsb2NhbGhv
+c3QxEjAQBgkqhkiG9w0BCQEWA3RhOTAeFw0xMzEyMTMwMDEzMzhaFw0xNjA5MDgw
+MDEzMzhaMH0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRQwEgYD
+VQQHDAtTYW50YSBDbGFyYTENMAsGA1UECgwEcGtnNTEMMAoGA1UECwwDdGE5MRIw
+EAYDVQQDDAlsb2NhbGhvc3QxEjAQBgkqhkiG9w0BCQEWA3RhOTCBnzANBgkqhkiG
+9w0BAQEFAAOBjQAwgYkCgYEAyYotDVME6AK7vCffDrgzJQdUYdDZtggzW8PrTKEf
+n1HMqYMHFhWcaQtIdGI1X6OUODcPP19YJpo2C6IPu5tX//1wAdYoorZn7anIkBW1
+f5FgMv+WE6Q/CSNwLzhvJFRBlS+RWm6lqnfabFDuYuWFimdjffwHMLrzlpNsXV+e
+LgcCAwEAAaNQME4wHQYDVR0OBBYEFOhejnfRYWS7SK84lQxXFk7jdz01MB8GA1Ud
+IwQYMBaAFOhejnfRYWS7SK84lQxXFk7jdz01MAwGA1UdEwQFMAMBAf8wDQYJKoZI
+hvcNAQELBQADgYEAPiDcEBu0g5oKmkHTb+zvW1EPp0pJDrOG9g/ChOoPsghtonzk
+JBC6RcLDnge5w3QQ8nR/x2EuDkUzAMQZMmErWAr0UXoDZmgyJ8MgJ6/Ek2RFDRYO
+yiuG9hwiE3Ra0mj8RRG48RMm4eTCt7W4+PzMbfuHPl1TMbqZFmV7sWzpeIo=
 -----END CERTIFICATE-----