security: Make addKey/Cert behavior of PibImpl consistent

Change-Id: I30c6dd0007e9095ee07f7a8eda3b20db4c34c513
Refs: #3351
diff --git a/src/security/pib/pib-impl.hpp b/src/security/pib/pib-impl.hpp
index 9b343f5..ef859a6 100644
--- a/src/security/pib/pib-impl.hpp
+++ b/src/security/pib/pib-impl.hpp
@@ -86,8 +86,8 @@
   /**
    * @brief Add an identity.
    *
-   * If the identity already exists, do nothing.
-   * If no default identity has been set, set the added one as default identity.
+   * If the identity already exists, do nothing.  If no default identity has been set, set the
+   * added one as default identity.
    *
    * @param identity The name of the identity to add.
    */
@@ -95,10 +95,10 @@
   addIdentity(const Name& identity) = 0;
 
   /**
-   * @brief Remove an identity
+   * @brief Remove an identity and related keys and certificates.
    *
-   * If the identity does not exist, do nothing.
-   * Remove related keys and certificates as well.
+   * If the default identity is being removed, no default identity will be selected.  If the
+   * identity does not exist, do nothing.
    *
    * @param identity The name of the identity to remove.
    */
@@ -120,8 +120,7 @@
   /**
    * @brief Set an identity with name @p identityName as the default identity.
    *
-   * Since adding an identity only requires the identity name, create the
-   * identity if it does not exist.
+   * If @p identityName identity does not exist, it will be created.
    *
    * @param identityName The name for the default identity.
    */
@@ -149,10 +148,10 @@
   /**
    * @brief Add a key.
    *
-   * If the key already exists, do nothing.
-   * If the identity does not exist, add the identity as well.
-   * If no default key of the identity has been set, set the added one as default
-   * key of the identity.
+   * If a key with the same name already exists, overwrite the key.  If the identity does not
+   * exist, it will be created.  If no default key of the identity has been set, set the added
+   * one as default key of the identity.  If no default identity has been set, @p identity
+   * becomes the default.
    *
    * @param identity The name of the belonged identity.
    * @param keyName The key name.
@@ -163,10 +162,9 @@
   addKey(const Name& identity, const Name& keyName, const uint8_t* key, size_t keyLen) = 0;
 
   /**
-   * @brief Remove a key with @p keyName
+   * @brief Remove a key with @p keyName and related certificates
    *
    * If the key does not exist, do nothing.
-   * Remove related certificates as well.
    */
   virtual void
   removeKey(const Name& keyName) = 0;
@@ -183,8 +181,8 @@
   /**
    * @brief Get all the key names of an identity with name @p identity
    *
-   * The returned key names can be used to create a KeyContainer.
-   * With key name, identity name, backend implementation, one can create a Key frontend instance.
+   * The returned key names can be used to create a KeyContainer.  With key name and backend
+   * implementation, one can create a Key frontend instance.
    *
    * @return the key name component set. If the identity does not exist, return an empty set.
    */
@@ -220,10 +218,12 @@
   /**
    * @brief Add a certificate.
    *
-   * If the certificate already exists, do nothing.
-   * If the key or identity do not exist, add them as well.
-   * If no default certificate of the key has been set, set the added one as
-   * default certificate of the key.
+   * If a certificate with the same name (without implicit digest) already exists, overwrite
+   * the certificate.  If the key or identity does not exist, they will be created.  If no
+   * default certificate of the key has been set, set the added one as default certificate of
+   * the key.  If no default key was set for the identity, it will be set as default key for
+   * the identity.  If no default identity was selected, the certificate's identity becomes
+   * default.
    *
    * @param certificate The certificate to add.
    */
@@ -253,8 +253,8 @@
   /**
    * @brief Get a list of certificate names of a key with id @p keyName.
    *
-   * The returned certificate names can be used to create a CertificateContainer.
-   * With certificate name and backend implementation, one can obtain the certificate directly.
+   * The returned certificate names can be used to create a CertificateContainer.  With
+   * certificate name and backend implementation, one can obtain the certificate.
    *
    * @return The certificate name set. If the key does not exist, return an empty set.
    */
diff --git a/src/security/pib/pib-memory.cpp b/src/security/pib/pib-memory.cpp
index edf2ce9..aa93ba7 100644
--- a/src/security/pib/pib-memory.cpp
+++ b/src/security/pib/pib-memory.cpp
@@ -65,12 +65,14 @@
 PibMemory::removeIdentity(const Name& identity)
 {
   m_identities.erase(identity);
-  if (identity == m_defaultIdentity)
+  if (identity == m_defaultIdentity) {
     m_hasDefaultIdentity = false;
+    m_defaultIdentity.clear();
+  }
 
-  auto keyNames = this->getKeysOfIdentity(identity);
+  auto keyNames = getKeysOfIdentity(identity);
   for (const Name& keyName : keyNames) {
-    this->removeKey(keyName);
+    removeKey(keyName);
   }
 }
 
@@ -80,9 +82,9 @@
   m_hasDefaultIdentity = false;
   m_defaultIdentity.clear();
   m_identities.clear();
-  m_defaultKey.clear();
+  m_defaultKeys.clear();
   m_keys.clear();
-  m_defaultCert.clear();
+  m_defaultCerts.clear();
   m_certs.clear();
 }
 
@@ -103,8 +105,9 @@
 Name
 PibMemory::getDefaultIdentity() const
 {
-  if (m_hasDefaultIdentity)
+  if (m_hasDefaultIdentity) {
     return m_defaultIdentity;
+  }
 
   BOOST_THROW_EXCEPTION(Pib::Error("No default identity"));
 }
@@ -119,12 +122,13 @@
 PibMemory::addKey(const Name& identity, const Name& keyName,
                   const uint8_t* key, size_t keyLen)
 {
-  this->addIdentity(identity);
+  addIdentity(identity);
 
   m_keys[keyName] = Buffer(key, keyLen);
 
-  if (m_defaultKey.find(identity) == m_defaultKey.end())
-    m_defaultKey[identity] = keyName;
+  if (m_defaultKeys.count(identity) == 0) {
+    m_defaultKeys[identity] = keyName;
+  }
 }
 
 void
@@ -133,31 +137,34 @@
   Name identity = v2::extractIdentityFromKeyName(keyName);
 
   m_keys.erase(keyName);
-  m_defaultKey.erase(identity);
+  m_defaultKeys.erase(identity);
 
-  auto certNames = this->getCertificatesOfKey(keyName);
+  auto certNames = getCertificatesOfKey(keyName);
   for (const auto& certName : certNames) {
-    this->removeCertificate(certName);
+    removeCertificate(certName);
   }
 }
 
 Buffer
 PibMemory::getKeyBits(const Name& keyName) const
 {
-  if (!hasKey(keyName))
+  if (!hasKey(keyName)) {
     BOOST_THROW_EXCEPTION(Pib::Error("Key `" + keyName.toUri() + "` not found"));
+  }
 
-  auto it = m_keys.find(keyName);
-  return it->second;
+  auto key = m_keys.find(keyName);
+  BOOST_ASSERT(key != m_keys.end());
+  return key->second;
 }
 
 std::set<Name>
 PibMemory::getKeysOfIdentity(const Name& identity) const
 {
   std::set<Name> ids;
-  for (const auto& it : m_keys) {
-    if (identity == v2::extractIdentityFromKeyName(it.first))
-      ids.insert(it.first);
+  for (const auto& key : m_keys) {
+    if (identity == v2::extractIdentityFromKeyName(key.first)) {
+      ids.insert(key.first);
+    }
   }
   return ids;
 }
@@ -165,20 +172,22 @@
 void
 PibMemory::setDefaultKeyOfIdentity(const Name& identity, const Name& keyName)
 {
-  if (!hasKey(keyName))
+  if (!hasKey(keyName)) {
     BOOST_THROW_EXCEPTION(Pib::Error("Key `" + keyName.toUri() + "` not found"));
+  }
 
-  m_defaultKey[identity] = keyName;
+  m_defaultKeys[identity] = keyName;
 }
 
 Name
 PibMemory::getDefaultKeyOfIdentity(const Name& identity) const
 {
-  auto it = m_defaultKey.find(identity);
-  if (it == m_defaultKey.end())
+  auto defaultKey = m_defaultKeys.find(identity);
+  if (defaultKey == m_defaultKeys.end()) {
     BOOST_THROW_EXCEPTION(Pib::Error("No default key for identity `" + identity.toUri() + "`"));
+  }
 
-  return it->second;
+  return defaultKey->second;
 }
 
 bool
@@ -194,25 +203,30 @@
   Name keyName = certificate.getKeyName();
   Name identity = certificate.getIdentity();
 
-  this->addKey(identity, keyName, certificate.getContent().value(), certificate.getContent().value_size());
+  addKey(identity, keyName, certificate.getContent().value(), certificate.getContent().value_size());
 
   m_certs[certName] = certificate;
-  if (m_defaultCert.find(keyName) == m_defaultCert.end())
-    m_defaultCert[keyName] = certName;
+  if (m_defaultCerts.count(keyName) == 0) {
+    m_defaultCerts[keyName] = certName;
+  }
 }
 
 void
 PibMemory::removeCertificate(const Name& certName)
 {
   m_certs.erase(certName);
-  m_defaultCert.erase(v2::extractKeyNameFromCertName(certName));
+  auto defaultCert = m_defaultCerts.find(v2::extractKeyNameFromCertName(certName));
+  if (defaultCert != m_defaultCerts.end() && defaultCert->second == certName) {
+    m_defaultCerts.erase(defaultCert);
+  }
 }
 
 v2::Certificate
 PibMemory::getCertificate(const Name& certName) const
 {
-  if (!hasCertificate(certName))
+  if (!hasCertificate(certName)) {
     BOOST_THROW_EXCEPTION(Pib::Error("Certificate `" + certName.toUri() +  "` does not exist"));
+  }
 
   auto it = m_certs.find(certName);
   return it->second;
@@ -223,8 +237,9 @@
 {
   std::set<Name> certNames;
   for (const auto& it : m_certs) {
-    if (v2::extractKeyNameFromCertName(it.second.getName()) == keyName)
+    if (v2::extractKeyNameFromCertName(it.second.getName()) == keyName) {
       certNames.insert(it.first);
+    }
   }
   return certNames;
 }
@@ -232,24 +247,24 @@
 void
 PibMemory::setDefaultCertificateOfKey(const Name& keyName, const Name& certName)
 {
-  if (!hasCertificate(certName))
+  if (!hasCertificate(certName)) {
     BOOST_THROW_EXCEPTION(Pib::Error("Certificate `" + certName.toUri() +  "` does not exist"));
+  }
 
-  m_defaultCert[keyName] = certName;
+  m_defaultCerts[keyName] = certName;
 }
 
 v2::Certificate
 PibMemory::getDefaultCertificateOfKey(const Name& keyName) const
 {
-  auto it = m_defaultCert.find(keyName);
-  if (it == m_defaultCert.end())
+  auto it = m_defaultCerts.find(keyName);
+  if (it == m_defaultCerts.end()) {
     BOOST_THROW_EXCEPTION(Pib::Error("No default certificate for key `" + keyName.toUri() + "`"));
+  }
 
   auto certIt = m_certs.find(it->second);
-  if (certIt == m_certs.end())
-    BOOST_THROW_EXCEPTION(Pib::Error("No default certificate for key `" + keyName.toUri() + "`"));
-  else
-    return certIt->second;
+  BOOST_ASSERT(certIt != m_certs.end());
+  return certIt->second;
 }
 
 } // namespace pib
diff --git a/src/security/pib/pib-memory.hpp b/src/security/pib/pib-memory.hpp
index c48f9fc..192f000 100644
--- a/src/security/pib/pib-memory.hpp
+++ b/src/security/pib/pib-memory.hpp
@@ -132,13 +132,13 @@
   std::set<Name> m_identities;
 
   /// @brief identity => default key Name
-  std::map<Name, Name> m_defaultKey;
+  std::map<Name, Name> m_defaultKeys;
 
   /// @brief keyName => keyBits
   std::map<Name, Buffer> m_keys;
 
   /// @brief keyName => default certificate Name
-  std::map<Name, Name> m_defaultCert;
+  std::map<Name, Name> m_defaultCerts;
 
   /// @brief certificate Name => certificate
   std::map<Name, v2::Certificate> m_certs;
diff --git a/src/security/pib/pib-sqlite3.cpp b/src/security/pib/pib-sqlite3.cpp
index 8d8c437..b19f32c 100644
--- a/src/security/pib/pib-sqlite3.cpp
+++ b/src/security/pib/pib-sqlite3.cpp
@@ -279,9 +279,15 @@
 void
 PibSqlite3::addIdentity(const Name& identity)
 {
-  Sqlite3Statement statement(m_database, "INSERT INTO identities (identity) values (?)");
-  statement.bind(1, identity.wireEncode(), SQLITE_TRANSIENT);
-  statement.step();
+  if (!hasIdentity(identity)) {
+    Sqlite3Statement statement(m_database, "INSERT INTO identities (identity) values (?)");
+    statement.bind(1, identity.wireEncode(), SQLITE_TRANSIENT);
+    statement.step();
+  }
+
+  if (!hasDefaultIdentity()) {
+    setDefaultIdentity(identity);
+  }
 }
 
 void
@@ -331,6 +337,13 @@
 }
 
 bool
+PibSqlite3::hasDefaultIdentity() const
+{
+  Sqlite3Statement statement(m_database, "SELECT identity FROM identities WHERE is_default=1");
+  return (statement.step() == SQLITE_ROW);
+}
+
+bool
 PibSqlite3::hasKey(const Name& keyName) const
 {
   Sqlite3Statement statement(m_database, "SELECT id FROM keys WHERE key_name=?");
@@ -343,20 +356,29 @@
 PibSqlite3::addKey(const Name& identity, const Name& keyName,
                    const uint8_t* key, size_t keyLen)
 {
-  if (hasKey(keyName)) {
-    return;
-  }
-
   // ensure identity exists
   addIdentity(identity);
 
-  Sqlite3Statement statement(m_database,
-                             "INSERT INTO keys (identity_id, key_name, key_bits) "
-                             "VALUES ((SELECT id FROM identities WHERE identity=?), ?, ?)");
-  statement.bind(1, identity.wireEncode(), SQLITE_TRANSIENT);
-  statement.bind(2, keyName.wireEncode(), SQLITE_TRANSIENT);
-  statement.bind(3, key, keyLen, SQLITE_STATIC);
-  statement.step();
+  if (!hasKey(keyName)) {
+    Sqlite3Statement statement(m_database,
+                               "INSERT INTO keys (identity_id, key_name, key_bits) "
+                               "VALUES ((SELECT id FROM identities WHERE identity=?), ?, ?)");
+    statement.bind(1, identity.wireEncode(), SQLITE_TRANSIENT);
+    statement.bind(2, keyName.wireEncode(), SQLITE_TRANSIENT);
+    statement.bind(3, key, keyLen, SQLITE_STATIC);
+    statement.step();
+  }
+  else {
+    Sqlite3Statement statement(m_database,
+                               "UPDATE keys SET key_bits=? WHERE key_name=?");
+    statement.bind(1, key, keyLen, SQLITE_STATIC);
+    statement.bind(2, keyName.wireEncode(), SQLITE_TRANSIENT);
+    statement.step();
+  }
+
+  if (!hasDefaultKeyOfIdentity(identity)) {
+    setDefaultKeyOfIdentity(identity, keyName);
+  }
 }
 
 void
@@ -430,6 +452,18 @@
 }
 
 bool
+PibSqlite3::hasDefaultKeyOfIdentity(const Name& identity) const
+{
+  Sqlite3Statement statement(m_database,
+                             "SELECT key_name "
+                             "FROM keys JOIN identities ON keys.identity_id=identities.id "
+                             "WHERE identities.identity=? AND keys.is_default=1");
+  statement.bind(1, identity.wireEncode(), SQLITE_TRANSIENT);
+
+  return (statement.step() == SQLITE_ROW);
+}
+
+bool
 PibSqlite3::hasCertificate(const Name& certName) const
 {
   Sqlite3Statement statement(m_database, "SELECT id FROM certificates WHERE certificate_name=?");
@@ -444,14 +478,27 @@
   const Block& content = certificate.getContent();
   addKey(certificate.getIdentity(), certificate.getKeyName(), content.value(), content.value_size());
 
-  Sqlite3Statement statement(m_database,
-                             "INSERT INTO certificates "
-                             "(key_id, certificate_name, certificate_data) "
-                             "VALUES ((SELECT id FROM keys WHERE key_name=?), ?, ?)");
-  statement.bind(1, certificate.getKeyName().wireEncode(), SQLITE_TRANSIENT);
-  statement.bind(2, certificate.getName().wireEncode(), SQLITE_TRANSIENT);
-  statement.bind(3, certificate.wireEncode(), SQLITE_STATIC);
-  statement.step();
+  if (!hasCertificate(certificate.getName())) {
+    Sqlite3Statement statement(m_database,
+                               "INSERT INTO certificates "
+                               "(key_id, certificate_name, certificate_data) "
+                               "VALUES ((SELECT id FROM keys WHERE key_name=?), ?, ?)");
+    statement.bind(1, certificate.getKeyName().wireEncode(), SQLITE_TRANSIENT);
+    statement.bind(2, certificate.getName().wireEncode(), SQLITE_TRANSIENT);
+    statement.bind(3, certificate.wireEncode(), SQLITE_STATIC);
+    statement.step();
+  }
+  else {
+    Sqlite3Statement statement(m_database,
+                               "UPDATE certificates SET certificate_data=? WHERE certificate_name=?");
+    statement.bind(1, certificate.wireEncode(), SQLITE_STATIC);
+    statement.bind(2, certificate.getName().wireEncode(), SQLITE_TRANSIENT);
+    statement.step();
+  }
+
+  if (!hasDefaultCertificateOfKey(certificate.getKeyName())) {
+    setDefaultCertificateOfKey(certificate.getKeyName(), certificate.getName());
+  }
 }
 
 void
@@ -520,6 +567,18 @@
     BOOST_THROW_EXCEPTION(Pib::Error("No default certificate for key `" + keyName.toUri() + "`"));
 }
 
+bool
+PibSqlite3::hasDefaultCertificateOfKey(const Name& keyName) const
+{
+  Sqlite3Statement statement(m_database,
+                             "SELECT certificate_data "
+                             "FROM certificates JOIN keys ON certificates.key_id=keys.id "
+                             "WHERE certificates.is_default=1 AND keys.key_name=?");
+  statement.bind(1, keyName.wireEncode(), SQLITE_TRANSIENT);
+
+  return (statement.step() == SQLITE_ROW);
+}
+
 } // namespace pib
 } // namespace security
 } // namespace ndn
diff --git a/src/security/pib/pib-sqlite3.hpp b/src/security/pib/pib-sqlite3.hpp
index 806a29c..8c47176 100644
--- a/src/security/pib/pib-sqlite3.hpp
+++ b/src/security/pib/pib-sqlite3.hpp
@@ -134,6 +134,16 @@
   getDefaultCertificateOfKey(const Name& keyName) const final;
 
 private:
+  bool
+  hasDefaultIdentity() const;
+
+  bool
+  hasDefaultKeyOfIdentity(const Name& identity) const;
+
+  bool
+  hasDefaultCertificateOfKey(const Name& keyName) const;
+
+private:
   sqlite3* m_database;
 };
 
diff --git a/src/security/pib/pib.hpp b/src/security/pib/pib.hpp
index 3d73098..06f100d 100644
--- a/src/security/pib/pib.hpp
+++ b/src/security/pib/pib.hpp
@@ -128,7 +128,6 @@
   getDefaultIdentity() const;
 
 NDN_CXX_PUBLIC_WITH_TESTS_ELSE_PRIVATE: // write operations should be private
-
   /*
    * @brief Create an identity with name @p identityName and return a reference to it.
    *
@@ -143,6 +142,8 @@
   /*
    * @brief Remove an identity with name @p identityName.
    *
+   * If the default identity is being removed, no default identity will be selected.
+   *
    * @param identityName The name for the identity to be deleted
    */
   void
diff --git a/src/security/v2/certificate.cpp b/src/security/v2/certificate.cpp
index b5188e9..b6a08ab 100644
--- a/src/security/v2/certificate.cpp
+++ b/src/security/v2/certificate.cpp
@@ -98,7 +98,7 @@
   return getName().at(ISSUER_ID_OFFSET);
 }
 
-const Buffer
+Buffer
 Certificate::getPublicKey() const
 {
   if (getContent().value_size() == 0)
diff --git a/src/security/v2/certificate.hpp b/src/security/v2/certificate.hpp
index 4e1b0eb..c451277 100644
--- a/src/security/v2/certificate.hpp
+++ b/src/security/v2/certificate.hpp
@@ -132,7 +132,7 @@
    * @brief Get public key bits (in PKCS#8 format)
    * @throw Error If content is empty
    */
-  const Buffer
+  Buffer
   getPublicKey() const;
 
   /**
diff --git a/tests/unit-tests/security/pib/pib-data-fixture.cpp b/tests/unit-tests/security/pib/pib-data-fixture.cpp
index c8144cd..544892d 100644
--- a/tests/unit-tests/security/pib/pib-data-fixture.cpp
+++ b/tests/unit-tests/security/pib/pib-data-fixture.cpp
@@ -22,59 +22,72 @@
 #include "pib-data-fixture.hpp"
 #include "../../identity-management-time-fixture.hpp"
 
-#include "util/string-helper.hpp"
+// #include "security/pib/pib-memory.hpp"
+// #include "security/tpm/tpm.hpp"
+// #include "security/tpm/back-end-mem.hpp"
+// #include <fstream>
 
 namespace ndn {
 namespace security {
 namespace tests {
 
-// class TestCertDataGenerator : public ndn::tests::IdentityManagementTimeFixture
+// class TestCertDataGenerator
 // {
 // public:
-//   void
-//   printTestDataForId(const std::string& prefix, const Name& id)
+//   TestCertDataGenerator()
+//     : tpm("test", "test", make_unique<tpm::BackEndMem>())
 //   {
-//     addIdentity(id, EcdsaKeyParams());
-
-//     Name key1Name = m_keyChain.getDefaultKeyNameForIdentity(id);
-//     shared_ptr<PublicKey> key1 = m_keyChain.getPublicKey(key1Name);
-//     printBytes(prefix + "_KEY1", key1->get());
-
-//     Name key1Cert1Name = m_keyChain.getDefaultCertificateNameForKey(key1Name);
-//     shared_ptr<IdentityCertificate> key1Cert1 = m_keyChain.getCertificate(key1Cert1Name);
-//     printBytes(prefix + "_KEY1_CERT1", key1Cert1->wireEncode());
-
-//     advanceClocks(time::seconds(10));
-
-//     Name key2Name = m_keyChain.generateEcdsaKeyPair(id, true);
-//     shared_ptr<PublicKey> key2 = m_keyChain.getPublicKey(key2Name);
-//     printBytes(prefix + "_KEY2", key2->get());
-
-//     shared_ptr<IdentityCertificate> key2Cert1 = m_keyChain.selfSign(key2Name);
-//     printBytes(prefix + "_KEY2_CERT1", key2Cert1->wireEncode());
-
-//     advanceClocks(time::seconds(20));
-
-//     shared_ptr<IdentityCertificate> key1Cert2 = m_keyChain.selfSign(key1Name);
-//     printBytes(prefix + "_KEY1_CERT2", key1Cert2->wireEncode());
-
-//     shared_ptr<IdentityCertificate> key2Cert2 = m_keyChain.selfSign(key2Name);
-//     printBytes(prefix + "_KEY2_CERT2", key2Cert2->wireEncode());
 //   }
 
 //   void
+//   printTestDataForId(const std::string& prefix, const Name& id)
+//   {
+//     for (int keyId : {1, 2}) {
+//       Name keyName = tpm.createKey(id, EcdsaKeyParams(name::Component::fromNumber(keyId)));
+
+//       for (int certVersion : {1, 2}) {
+//         Name certName = keyName;
+//         certName
+//           .append("issuer")
+//           .appendVersion(certVersion);
+//         v2::Certificate cert;
+//         cert.setName(certName);
+//         cert.setFreshnessPeriod(time::hours(1));
+//         cert.setContent(tpm.getPublicKey(keyName));
+
+//         // @TODO sign using the new KeyChain
+//         SignatureInfo info;
+//         info.setSignatureType(tlv::SignatureSha256WithEcdsa);
+//         info.setKeyLocator(KeyLocator(keyName));
+//         info.setValidityPeriod(ValidityPeriod(time::fromIsoString("20170102T000000"),
+//                                               time::fromIsoString("20180102T000000")));
+//         cert.setSignature(Signature(info, Block()));
+
+//         EncodingBuffer buf;
+//         cert.wireEncode(buf, true);
+
+//         cert.setSignatureValue(Block(tlv::SignatureValue,
+//                                      tpm.sign(buf.buf(), buf.size(), keyName, DigestAlgorithm::SHA256)));
+
+//         printBytes(prefix + "_KEY" + to_string(keyId) + "_CERT" + to_string(certVersion),
+//                    cert.wireEncode());
+//       }
+//     }
+//   }
+
+//   static void
 //   printBytes(const std::string& name, const Block& block)
 //   {
 //     printBytes(name, block.wire(), block.size());
 //   }
 
-//   void
+//   static void
 //   printBytes(const std::string& name, const Buffer& buffer)
 //   {
 //     printBytes(name, buffer.buf(), buffer.size());
 //   }
 
-//   void
+//   static void
 //   printBytes(const std::string& name, const uint8_t* buf, size_t size)
 //   {
 //     std::cout << "\nconst uint8_t " << name << "[] = {\n"
@@ -95,6 +108,10 @@
 //     std::cout << "\n"
 //               << "};" << std::endl;
 //   }
+
+// public:
+//   pib::PibMemory pib;
+//   Tpm tpm;
 // };
 
 // // The test data can be generated using this test case
@@ -104,250 +121,307 @@
 //   printTestDataForId("ID2", Name("/pib/interface/id/2"));
 // }
 
-const uint8_t ID1_KEY1[] = {
-  0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D,
-  0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04, 0x16, 0xEC, 0xC6, 0xD1, 0xE1, 0x53, 0xCC, 0x8E, 0xE6, 0x4A, 0xF3, 0x93, 0x0A,
-  0x0E, 0xFA, 0xA7, 0xDB, 0xBE, 0xFB, 0x61, 0xD1, 0xCA, 0x91, 0x98, 0x11, 0x0D, 0x0C, 0xC2, 0xF4, 0xF4, 0x8D, 0x9E, 0x9F,
-  0x42, 0x4B, 0x5E, 0xFC, 0x11, 0x63, 0x3A, 0x7E, 0x6B, 0x48, 0x82, 0x82, 0x5F, 0x1E, 0x90, 0xB1, 0x5E, 0x30, 0x2D, 0x83,
-  0x7E, 0xA9, 0x84, 0x8A, 0xCE, 0xBC, 0x2A, 0xA4, 0x05, 0xC8, 0x04
-};
-
 const uint8_t ID1_KEY1_CERT1[] = {
-  0x06, 0xFD, 0x01, 0x8F, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x33, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x59, 0x8C, 0xA0, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x35, 0x33, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x35, 0x33, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x31, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x33, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0x16, 0xEC, 0xC6, 0xD1, 0xE1, 0x53, 0xCC, 0x8E, 0xE6, 0x4A, 0xF3, 0x93, 0x0A, 0x0E, 0xFA, 0xA7, 0xDB, 0xBE, 0xFB, 0x61,
-  0xD1, 0xCA, 0x91, 0x98, 0x11, 0x0D, 0x0C, 0xC2, 0xF4, 0xF4, 0x8D, 0x9E, 0x9F, 0x42, 0x4B, 0x5E, 0xFC, 0x11, 0x63, 0x3A,
-  0x7E, 0x6B, 0x48, 0x82, 0x82, 0x5F, 0x1E, 0x90, 0xB1, 0x5E, 0x30, 0x2D, 0x83, 0x7E, 0xA9, 0x84, 0x8A, 0xCE, 0xBC, 0x2A,
-  0xA4, 0x05, 0xC8, 0x04, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x33, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x48, 0x30, 0x46, 0x02, 0x21, 0x00, 0xA0, 0x43, 0x43, 0xD2,
-  0x79, 0x76, 0x3D, 0x00, 0xA1, 0x85, 0xD0, 0x83, 0xD6, 0x2A, 0xBC, 0xAB, 0xAA, 0xC0, 0xA6, 0xF7, 0xBF, 0x53, 0x6C, 0xA8,
-  0x18, 0x14, 0x4B, 0x42, 0x21, 0x72, 0xFF, 0xA5, 0x02, 0x21, 0x00, 0xFB, 0xDE, 0x82, 0xBB, 0x81, 0x34, 0x97, 0x0E, 0xBA,
-  0x30, 0xEF, 0xD2, 0x14, 0x86, 0xE7, 0x83, 0xFB, 0x4C, 0x59, 0x4C, 0xD3, 0x41, 0x18, 0x2F, 0xE4, 0xDA, 0x33, 0xF0, 0x72,
-  0x3A, 0x28, 0xAE
-};
-
-const uint8_t ID1_KEY2[] = {
-  0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D,
-  0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04, 0xCB, 0xB2, 0x23, 0x26, 0x20, 0x19, 0x08, 0x23, 0xBA, 0xD4, 0x1D, 0x64, 0x53,
-  0xBB, 0xA5, 0xDC, 0x13, 0xD3, 0xB1, 0xEF, 0x32, 0x9E, 0xB9, 0x25, 0x68, 0x1A, 0x89, 0xCC, 0xC5, 0x63, 0x93, 0xDA, 0x5F,
-  0xF1, 0x70, 0xA3, 0xCF, 0xB8, 0x8A, 0xC9, 0xBF, 0xCC, 0xC7, 0x08, 0x9B, 0x27, 0x85, 0xB2, 0xC2, 0xFD, 0xF7, 0x86, 0x81,
-  0xE4, 0x40, 0xE8, 0x5C, 0x01, 0x35, 0xC4, 0x0B, 0x11, 0x00, 0xD4
-};
-
-const uint8_t ID1_KEY2_CERT1[] = {
-  0x06, 0xFD, 0x01, 0x8D, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x34, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x59, 0xB3, 0xB0, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x35, 0x34, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x35, 0x34, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x31, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x34, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0xCB, 0xB2, 0x23, 0x26, 0x20, 0x19, 0x08, 0x23, 0xBA, 0xD4, 0x1D, 0x64, 0x53, 0xBB, 0xA5, 0xDC, 0x13, 0xD3, 0xB1, 0xEF,
-  0x32, 0x9E, 0xB9, 0x25, 0x68, 0x1A, 0x89, 0xCC, 0xC5, 0x63, 0x93, 0xDA, 0x5F, 0xF1, 0x70, 0xA3, 0xCF, 0xB8, 0x8A, 0xC9,
-  0xBF, 0xCC, 0xC7, 0x08, 0x9B, 0x27, 0x85, 0xB2, 0xC2, 0xFD, 0xF7, 0x86, 0x81, 0xE4, 0x40, 0xE8, 0x5C, 0x01, 0x35, 0xC4,
-  0x0B, 0x11, 0x00, 0xD4, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x34, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x46, 0x30, 0x44, 0x02, 0x20, 0x51, 0x04, 0xC9, 0xC6, 0x19,
-  0x06, 0x91, 0x52, 0x9F, 0x58, 0xFD, 0xDC, 0xF0, 0xC0, 0xB7, 0xFA, 0x88, 0xF7, 0x49, 0xE6, 0xDD, 0xE4, 0xB9, 0x49, 0x2C,
-  0x52, 0xB1, 0xAA, 0xB2, 0x62, 0x48, 0x88, 0x02, 0x20, 0x09, 0xAF, 0x0D, 0xB9, 0x94, 0xD5, 0x7A, 0x1E, 0x7D, 0x31, 0x90,
-  0x45, 0x3A, 0xF4, 0x82, 0x54, 0x87, 0xD6, 0x73, 0x84, 0xD0, 0x59, 0xC6, 0xBC, 0x8E, 0x5F, 0xBA, 0xA5, 0xD6, 0x35, 0x91,
-  0xF3
+  0x06, 0xFD, 0x02, 0x25, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x01, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0xCB, 0x46, 0xF7, 0x16, 0x2E,
+  0x83, 0x3D, 0x5E, 0x4A, 0x80, 0x6A, 0x78, 0xB7, 0xA8, 0x7A, 0x15, 0x95, 0x2D, 0x23, 0xA8, 0x41, 0xF7, 0x62, 0xE4, 0x0E,
+  0x66, 0x36, 0xB3, 0xF3, 0x14, 0xD6, 0xB3, 0xAB, 0x19, 0x26, 0x9D, 0x5A, 0x8A, 0x51, 0xD4, 0x4E, 0xBA, 0xBE, 0x13, 0x96,
+  0xCA, 0x38, 0x52, 0x16, 0xE4, 0x3D, 0xB0, 0x88, 0xBA, 0xBB, 0x7B, 0x97, 0x00, 0xA5, 0x95, 0x97, 0x4E, 0xE8, 0xF6, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x46, 0x30, 0x44, 0x02, 0x20, 0x53, 0xC8, 0xAD, 0x88, 0xBA, 0x52, 0x29, 0x68, 0xFF, 0x74, 0xA8, 0x39, 0x7F,
+  0x2C, 0xE2, 0x8E, 0x04, 0xC1, 0x78, 0x36, 0x46, 0x89, 0x38, 0x58, 0x45, 0x22, 0x44, 0xA3, 0xC8, 0xC1, 0xFF, 0x72, 0x02,
+  0x20, 0x23, 0x9D, 0xE4, 0x92, 0x00, 0xF1, 0x43, 0x69, 0xF7, 0x32, 0xF6, 0xAA, 0x8C, 0xFD, 0x7F, 0x2B, 0xFB, 0xD2, 0x40,
+  0x6A, 0x1E, 0xA3, 0xE5, 0xF0, 0xF8, 0x2B, 0x92, 0x99, 0x6B, 0xDB, 0xE2, 0x6D
 };
 
 const uint8_t ID1_KEY1_CERT2[] = {
-  0x06, 0xFD, 0x01, 0x8D, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x33, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x5A, 0x01, 0xD0, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x36, 0x30, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x36, 0x30, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x31, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x33, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0x16, 0xEC, 0xC6, 0xD1, 0xE1, 0x53, 0xCC, 0x8E, 0xE6, 0x4A, 0xF3, 0x93, 0x0A, 0x0E, 0xFA, 0xA7, 0xDB, 0xBE, 0xFB, 0x61,
-  0xD1, 0xCA, 0x91, 0x98, 0x11, 0x0D, 0x0C, 0xC2, 0xF4, 0xF4, 0x8D, 0x9E, 0x9F, 0x42, 0x4B, 0x5E, 0xFC, 0x11, 0x63, 0x3A,
-  0x7E, 0x6B, 0x48, 0x82, 0x82, 0x5F, 0x1E, 0x90, 0xB1, 0x5E, 0x30, 0x2D, 0x83, 0x7E, 0xA9, 0x84, 0x8A, 0xCE, 0xBC, 0x2A,
-  0xA4, 0x05, 0xC8, 0x04, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x33, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x46, 0x30, 0x44, 0x02, 0x20, 0x0C, 0x4E, 0xBC, 0xA2, 0xA0,
-  0xCC, 0xBA, 0xD7, 0xFD, 0xCB, 0xFE, 0x7D, 0x28, 0x9C, 0xAC, 0x75, 0xF8, 0x49, 0x8F, 0xF4, 0x6F, 0xE2, 0xF6, 0x2A, 0xE5,
-  0x40, 0x5A, 0xCC, 0x91, 0x07, 0xEF, 0xF1, 0x02, 0x20, 0x39, 0x2A, 0x12, 0xDE, 0xF1, 0x4D, 0xB5, 0x13, 0xAC, 0x9F, 0xE7,
-  0xB3, 0xE5, 0xB3, 0xEF, 0x5F, 0xC0, 0x95, 0xEC, 0x3C, 0x8B, 0x11, 0x5A, 0xF5, 0x7B, 0xA1, 0xA7, 0x2A, 0x5D, 0x01, 0x02,
-  0xEE
+  0x06, 0xFD, 0x02, 0x26, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x02, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0xCB, 0x46, 0xF7, 0x16, 0x2E,
+  0x83, 0x3D, 0x5E, 0x4A, 0x80, 0x6A, 0x78, 0xB7, 0xA8, 0x7A, 0x15, 0x95, 0x2D, 0x23, 0xA8, 0x41, 0xF7, 0x62, 0xE4, 0x0E,
+  0x66, 0x36, 0xB3, 0xF3, 0x14, 0xD6, 0xB3, 0xAB, 0x19, 0x26, 0x9D, 0x5A, 0x8A, 0x51, 0xD4, 0x4E, 0xBA, 0xBE, 0x13, 0x96,
+  0xCA, 0x38, 0x52, 0x16, 0xE4, 0x3D, 0xB0, 0x88, 0xBA, 0xBB, 0x7B, 0x97, 0x00, 0xA5, 0x95, 0x97, 0x4E, 0xE8, 0xF6, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x47, 0x30, 0x45, 0x02, 0x21, 0x00, 0xB2, 0x93, 0xCD, 0x3D, 0x01, 0x00, 0xB5, 0xF1, 0x75, 0x22, 0x68, 0x9F,
+  0xE4, 0x5E, 0x0A, 0x76, 0x34, 0xBC, 0x9D, 0xCF, 0x9A, 0x4C, 0x21, 0x3F, 0xA5, 0x12, 0x51, 0xF7, 0x3A, 0x5E, 0x37, 0x7D,
+  0x02, 0x20, 0x33, 0xA9, 0xA9, 0x8F, 0xD8, 0x2E, 0xED, 0x3C, 0xE5, 0x18, 0x94, 0x59, 0x28, 0xEA, 0x82, 0x38, 0x5B, 0x20,
+  0xE4, 0xBF, 0x15, 0xF4, 0x0D, 0x45, 0xAE, 0x8B, 0x63, 0x19, 0x79, 0x78, 0x50, 0x3A
+};
+
+const uint8_t ID1_KEY2_CERT1[] = {
+  0x06, 0xFD, 0x02, 0x25, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x01, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0x34, 0xAA, 0x4B, 0x1A, 0x97,
+  0x4A, 0x6B, 0x6F, 0x3F, 0xB3, 0xC9, 0xD1, 0x39, 0x9F, 0x1E, 0x49, 0xB6, 0x6E, 0x19, 0x97, 0x13, 0x5E, 0xFA, 0xE6, 0xD3,
+  0xFE, 0xF3, 0xB0, 0xCA, 0x80, 0x09, 0x31, 0xCA, 0x50, 0x5C, 0xE6, 0x57, 0xBF, 0x13, 0x16, 0xCE, 0x3E, 0xF1, 0xD4, 0x23,
+  0xF8, 0x7F, 0x31, 0xFA, 0x13, 0x39, 0x09, 0xED, 0xC6, 0x74, 0x3D, 0xFD, 0x1A, 0x0B, 0xC7, 0xC1, 0x01, 0x15, 0x7F, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x46, 0x30, 0x44, 0x02, 0x20, 0x71, 0x3A, 0xB4, 0x19, 0x4B, 0xB3, 0x25, 0xA5, 0x03, 0x23, 0x8C, 0xC1, 0xB9,
+  0x68, 0xC1, 0x41, 0x4B, 0xED, 0x13, 0xCC, 0x87, 0x16, 0xB5, 0x13, 0x87, 0xA0, 0x54, 0xA2, 0x9F, 0xF0, 0xD7, 0x72, 0x02,
+  0x20, 0x4B, 0xEF, 0xB5, 0x6A, 0x8C, 0x40, 0x71, 0x17, 0xD2, 0x4F, 0xB6, 0x0F, 0xBE, 0x60, 0x1A, 0x46, 0x9B, 0x78, 0x15,
+  0x46, 0x09, 0xC2, 0x7A, 0x80, 0xD4, 0xE6, 0x71, 0x52, 0xD6, 0x83, 0x4B, 0x04
 };
 
 const uint8_t ID1_KEY2_CERT2[] = {
-  0x06, 0xFD, 0x01, 0x8E, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x34, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x5A, 0x01, 0xD0, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x36, 0x30, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x36, 0x30, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x31, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x34, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0xCB, 0xB2, 0x23, 0x26, 0x20, 0x19, 0x08, 0x23, 0xBA, 0xD4, 0x1D, 0x64, 0x53, 0xBB, 0xA5, 0xDC, 0x13, 0xD3, 0xB1, 0xEF,
-  0x32, 0x9E, 0xB9, 0x25, 0x68, 0x1A, 0x89, 0xCC, 0xC5, 0x63, 0x93, 0xDA, 0x5F, 0xF1, 0x70, 0xA3, 0xCF, 0xB8, 0x8A, 0xC9,
-  0xBF, 0xCC, 0xC7, 0x08, 0x9B, 0x27, 0x85, 0xB2, 0xC2, 0xFD, 0xF7, 0x86, 0x81, 0xE4, 0x40, 0xE8, 0x5C, 0x01, 0x35, 0xC4,
-  0x0B, 0x11, 0x00, 0xD4, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x34, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x47, 0x30, 0x45, 0x02, 0x20, 0x61, 0xF2, 0xE3, 0x70, 0xF6,
-  0x9C, 0xAC, 0x33, 0x65, 0xA7, 0xBE, 0x5D, 0x14, 0x9F, 0x9F, 0xBD, 0xC0, 0x9B, 0x22, 0xA9, 0xB1, 0x27, 0xBC, 0x30, 0xEF,
-  0x6A, 0xE5, 0x57, 0x04, 0x7A, 0x1A, 0xF1, 0x02, 0x21, 0x00, 0xC0, 0xAF, 0xC6, 0x2B, 0xB6, 0x10, 0xD2, 0x3C, 0x3C, 0x6B,
-  0x60, 0x93, 0x70, 0x4C, 0x49, 0x49, 0x7F, 0xF2, 0x11, 0x6C, 0x3A, 0x30, 0x26, 0x12, 0xF6, 0x82, 0x8A, 0xE8, 0x9A, 0xDE,
-  0xEC, 0x26
-};
-
-const uint8_t ID2_KEY1[] = {
-  0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D,
-  0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04, 0x1D, 0x29, 0xB2, 0x71, 0x6E, 0xD9, 0x80, 0x4D, 0xA9, 0xB0, 0xED, 0x27, 0x6F,
-  0x2C, 0x5B, 0x30, 0xF5, 0x40, 0xE8, 0x9E, 0xB5, 0x80, 0x02, 0x7C, 0xFB, 0x7D, 0x01, 0x1F, 0x87, 0x13, 0xE7, 0x1A, 0x02,
-  0x8F, 0xA0, 0x56, 0xA1, 0xD4, 0xBA, 0xBC, 0x72, 0x42, 0xAD, 0x89, 0xFB, 0x75, 0x04, 0x86, 0x98, 0xD1, 0x99, 0xED, 0x06,
-  0x23, 0x15, 0x02, 0x2A, 0x48, 0xD6, 0xAC, 0xBE, 0x1B, 0x44, 0xF1
+  0x06, 0xFD, 0x02, 0x26, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x02, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0x34, 0xAA, 0x4B, 0x1A, 0x97,
+  0x4A, 0x6B, 0x6F, 0x3F, 0xB3, 0xC9, 0xD1, 0x39, 0x9F, 0x1E, 0x49, 0xB6, 0x6E, 0x19, 0x97, 0x13, 0x5E, 0xFA, 0xE6, 0xD3,
+  0xFE, 0xF3, 0xB0, 0xCA, 0x80, 0x09, 0x31, 0xCA, 0x50, 0x5C, 0xE6, 0x57, 0xBF, 0x13, 0x16, 0xCE, 0x3E, 0xF1, 0xD4, 0x23,
+  0xF8, 0x7F, 0x31, 0xFA, 0x13, 0x39, 0x09, 0xED, 0xC6, 0x74, 0x3D, 0xFD, 0x1A, 0x0B, 0xC7, 0xC1, 0x01, 0x15, 0x7F, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x31, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x47, 0x30, 0x45, 0x02, 0x21, 0x00, 0xD2, 0x90, 0x8C, 0xA3, 0x52, 0x2F, 0x79, 0xB3, 0xD7, 0x39, 0xE1, 0x6C,
+  0x7F, 0xA0, 0xDF, 0xD1, 0x3E, 0x0F, 0x70, 0xBE, 0xF5, 0xDB, 0x08, 0xDF, 0xE1, 0x0B, 0xDF, 0x79, 0x99, 0xFE, 0x5C, 0xDC,
+  0x02, 0x20, 0x3D, 0xD4, 0x7C, 0xD1, 0x83, 0xBE, 0x29, 0xBB, 0x73, 0xA3, 0x82, 0xE5, 0xE6, 0x83, 0xA1, 0xC1, 0xBC, 0xF6,
+  0x84, 0x42, 0x85, 0x00, 0x92, 0x4B, 0xA2, 0xA8, 0xCA, 0x10, 0x7B, 0x92, 0x89, 0xB0
 };
 
 const uint8_t ID2_KEY1_CERT1[] = {
-  0x06, 0xFD, 0x01, 0x8E, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x36, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x5A, 0x01, 0xD0, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x36, 0x30, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x36, 0x30, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x32, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x36, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0x1D, 0x29, 0xB2, 0x71, 0x6E, 0xD9, 0x80, 0x4D, 0xA9, 0xB0, 0xED, 0x27, 0x6F, 0x2C, 0x5B, 0x30, 0xF5, 0x40, 0xE8, 0x9E,
-  0xB5, 0x80, 0x02, 0x7C, 0xFB, 0x7D, 0x01, 0x1F, 0x87, 0x13, 0xE7, 0x1A, 0x02, 0x8F, 0xA0, 0x56, 0xA1, 0xD4, 0xBA, 0xBC,
-  0x72, 0x42, 0xAD, 0x89, 0xFB, 0x75, 0x04, 0x86, 0x98, 0xD1, 0x99, 0xED, 0x06, 0x23, 0x15, 0x02, 0x2A, 0x48, 0xD6, 0xAC,
-  0xBE, 0x1B, 0x44, 0xF1, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x36, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x47, 0x30, 0x45, 0x02, 0x21, 0x00, 0xFE, 0x19, 0x3C, 0x02,
-  0x40, 0x87, 0x7D, 0x93, 0xD7, 0x99, 0xA3, 0x3A, 0x01, 0x25, 0xB9, 0x3C, 0x26, 0x64, 0x6A, 0x99, 0x7D, 0xA1, 0x21, 0x26,
-  0xB4, 0xC4, 0xB6, 0x60, 0xBE, 0x41, 0x24, 0xB4, 0x02, 0x20, 0x55, 0x6B, 0x86, 0xFF, 0xE2, 0x8A, 0x9F, 0x18, 0xBE, 0xA5,
-  0xA2, 0x74, 0xFC, 0x7C, 0x17, 0x68, 0x9F, 0x48, 0x71, 0x97, 0x64, 0x22, 0xB1, 0xB8, 0x05, 0xA6, 0x8F, 0x94, 0x42, 0xD8,
-  0x49, 0xE3
-};
-
-const uint8_t ID2_KEY2[] = {
-  0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D,
-  0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04, 0x57, 0xE5, 0x0D, 0xDE, 0x12, 0xAD, 0xF2, 0xA7, 0x34, 0x4A, 0x80, 0xFD, 0x7E,
-  0x75, 0x87, 0x5F, 0xD6, 0x29, 0x97, 0x1A, 0x56, 0x25, 0xAD, 0x67, 0x3E, 0x0C, 0x80, 0x21, 0x30, 0x76, 0x4E, 0x23, 0x17,
-  0xE6, 0xF4, 0x0B, 0xAA, 0xD2, 0xAF, 0x11, 0x20, 0xFC, 0xE6, 0xB2, 0xA4, 0x97, 0xDE, 0x45, 0x28, 0x40, 0x80, 0x1F, 0x42,
-  0xEC, 0x72, 0x06, 0xF3, 0xE6, 0x68, 0xB3, 0x20, 0x42, 0x53, 0xA7
-};
-
-const uint8_t ID2_KEY2_CERT1[] = {
-  0x06, 0xFD, 0x01, 0x8E, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x37, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x5A, 0x28, 0xE0, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x36, 0x31, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x36, 0x31, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x32, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x37, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0x57, 0xE5, 0x0D, 0xDE, 0x12, 0xAD, 0xF2, 0xA7, 0x34, 0x4A, 0x80, 0xFD, 0x7E, 0x75, 0x87, 0x5F, 0xD6, 0x29, 0x97, 0x1A,
-  0x56, 0x25, 0xAD, 0x67, 0x3E, 0x0C, 0x80, 0x21, 0x30, 0x76, 0x4E, 0x23, 0x17, 0xE6, 0xF4, 0x0B, 0xAA, 0xD2, 0xAF, 0x11,
-  0x20, 0xFC, 0xE6, 0xB2, 0xA4, 0x97, 0xDE, 0x45, 0x28, 0x40, 0x80, 0x1F, 0x42, 0xEC, 0x72, 0x06, 0xF3, 0xE6, 0x68, 0xB3,
-  0x20, 0x42, 0x53, 0xA7, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x37, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x47, 0x30, 0x45, 0x02, 0x21, 0x00, 0xB2, 0xE6, 0x70, 0x55,
-  0x42, 0x4E, 0x57, 0x32, 0xAD, 0x99, 0x5B, 0x54, 0x27, 0x0E, 0xCD, 0x31, 0xE1, 0x37, 0xF9, 0x7A, 0xF0, 0x20, 0x68, 0xB6,
-  0xE8, 0x6B, 0x46, 0xFB, 0x18, 0x25, 0x0E, 0xCA, 0x02, 0x20, 0x03, 0xE9, 0xC3, 0xB4, 0xCE, 0xAF, 0xBA, 0x65, 0xA1, 0xB8,
-  0x16, 0x5A, 0x44, 0xFA, 0x08, 0x50, 0xED, 0x54, 0xF2, 0x8D, 0x51, 0x86, 0xF3, 0xD9, 0xDF, 0xFF, 0xAF, 0xA4, 0x57, 0x09,
-  0x15, 0x24
+  0x06, 0xFD, 0x02, 0x25, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x01, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0xAC, 0x62, 0xD7, 0x31, 0x3B,
+  0x19, 0x1F, 0x44, 0x76, 0x6E, 0x79, 0x03, 0xB9, 0xC8, 0x26, 0xC4, 0x1E, 0x38, 0x3A, 0x41, 0xFE, 0xB4, 0x72, 0xA2, 0x36,
+  0xBB, 0x82, 0x9C, 0xB9, 0x07, 0x62, 0x6F, 0x1C, 0x79, 0x12, 0xCA, 0x9C, 0x3D, 0xAA, 0x7A, 0x96, 0xFF, 0xAF, 0x5B, 0x6F,
+  0xE1, 0x72, 0x60, 0xB0, 0x7F, 0x44, 0x38, 0x05, 0x21, 0xCC, 0x49, 0x78, 0x89, 0xC1, 0xEF, 0xEE, 0x81, 0x8E, 0xF5, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x46, 0x30, 0x44, 0x02, 0x20, 0x16, 0xC0, 0xF4, 0xE3, 0x15, 0x43, 0x6E, 0x27, 0x33, 0x7C, 0x46, 0x4D, 0x35,
+  0xA7, 0x8B, 0x0C, 0xE3, 0x27, 0x63, 0x4B, 0xB2, 0xB6, 0x4F, 0x06, 0x90, 0x2A, 0xD8, 0x54, 0x92, 0xE8, 0xBA, 0xBE, 0x02,
+  0x20, 0x67, 0xA6, 0x55, 0x8D, 0x16, 0x0E, 0x1E, 0x9E, 0x10, 0x0E, 0xB9, 0x3C, 0xEF, 0xEE, 0xB5, 0xF7, 0x9C, 0xB3, 0x1D,
+  0x04, 0xF1, 0xD4, 0xB5, 0x9F, 0xD4, 0x13, 0xBB, 0xFF, 0xA7, 0x58, 0xAE, 0xCB
 };
 
 const uint8_t ID2_KEY1_CERT2[] = {
-  0x06, 0xFD, 0x01, 0x8E, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x36, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x5A, 0x77, 0x00, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x36, 0x33, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x36, 0x33, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x32, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x36, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0x1D, 0x29, 0xB2, 0x71, 0x6E, 0xD9, 0x80, 0x4D, 0xA9, 0xB0, 0xED, 0x27, 0x6F, 0x2C, 0x5B, 0x30, 0xF5, 0x40, 0xE8, 0x9E,
-  0xB5, 0x80, 0x02, 0x7C, 0xFB, 0x7D, 0x01, 0x1F, 0x87, 0x13, 0xE7, 0x1A, 0x02, 0x8F, 0xA0, 0x56, 0xA1, 0xD4, 0xBA, 0xBC,
-  0x72, 0x42, 0xAD, 0x89, 0xFB, 0x75, 0x04, 0x86, 0x98, 0xD1, 0x99, 0xED, 0x06, 0x23, 0x15, 0x02, 0x2A, 0x48, 0xD6, 0xAC,
-  0xBE, 0x1B, 0x44, 0xF1, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x36, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x47, 0x30, 0x45, 0x02, 0x20, 0x08, 0x02, 0xFB, 0x78, 0xE0,
-  0xF6, 0x6F, 0xCB, 0x9E, 0xB3, 0xF9, 0xFC, 0xB5, 0xE0, 0x67, 0x20, 0xB1, 0xDF, 0x42, 0xBE, 0xA1, 0xD7, 0x31, 0x62, 0xCE,
-  0x2E, 0xC3, 0x02, 0x81, 0x6B, 0xAA, 0x4E, 0x02, 0x21, 0x00, 0xB6, 0xB8, 0x94, 0xA1, 0xFF, 0x1E, 0x4E, 0x36, 0x23, 0x40,
-  0xCF, 0xD9, 0x5B, 0x0E, 0xA3, 0xCE, 0xC1, 0x38, 0xE8, 0xCE, 0xA4, 0x83, 0xF0, 0xD4, 0x1F, 0x66, 0x44, 0x68, 0x0E, 0x24,
-  0x23, 0x7E
+  0x06, 0xFD, 0x02, 0x26, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x02, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0xAC, 0x62, 0xD7, 0x31, 0x3B,
+  0x19, 0x1F, 0x44, 0x76, 0x6E, 0x79, 0x03, 0xB9, 0xC8, 0x26, 0xC4, 0x1E, 0x38, 0x3A, 0x41, 0xFE, 0xB4, 0x72, 0xA2, 0x36,
+  0xBB, 0x82, 0x9C, 0xB9, 0x07, 0x62, 0x6F, 0x1C, 0x79, 0x12, 0xCA, 0x9C, 0x3D, 0xAA, 0x7A, 0x96, 0xFF, 0xAF, 0x5B, 0x6F,
+  0xE1, 0x72, 0x60, 0xB0, 0x7F, 0x44, 0x38, 0x05, 0x21, 0xCC, 0x49, 0x78, 0x89, 0xC1, 0xEF, 0xEE, 0x81, 0x8E, 0xF5, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x01, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x47, 0x30, 0x45, 0x02, 0x21, 0x00, 0xF2, 0x0D, 0x1D, 0x60, 0x0B, 0x2D, 0x97, 0x3A, 0x6B, 0xEE, 0xEC, 0x56,
+  0xD1, 0x64, 0xBF, 0xED, 0x68, 0xB7, 0x10, 0x0B, 0xDF, 0x81, 0x29, 0xCD, 0xB0, 0xBB, 0x87, 0x0D, 0xDA, 0x12, 0x52, 0xCC,
+  0x02, 0x20, 0x64, 0x33, 0x4E, 0x91, 0xAF, 0x81, 0xF4, 0xE7, 0xAD, 0x38, 0x8E, 0xBF, 0x79, 0xA7, 0x70, 0x1E, 0xD6, 0x71,
+  0x7E, 0xF5, 0xEB, 0x92, 0x56, 0x5F, 0xC7, 0x05, 0xDC, 0x27, 0xE5, 0x11, 0xC2, 0x43
+};
+
+const uint8_t ID2_KEY2_CERT1[] = {
+  0x06, 0xFD, 0x02, 0x26, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x01, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0x2C, 0xC3, 0xAF, 0xA8, 0x73,
+  0xF2, 0x61, 0xCF, 0x48, 0x04, 0x0F, 0x9D, 0xD3, 0xAF, 0x0B, 0xC6, 0x2F, 0x4D, 0xDA, 0x0E, 0x4C, 0x66, 0x1D, 0x03, 0x9D,
+  0xFE, 0x2C, 0x0B, 0xB6, 0x25, 0x60, 0xBC, 0xFA, 0xDA, 0xFE, 0x6F, 0x43, 0xFA, 0x95, 0x45, 0x57, 0x8A, 0x25, 0xEC, 0x0F,
+  0xF2, 0xB7, 0x43, 0x85, 0x0D, 0x0B, 0x8D, 0x97, 0x40, 0x83, 0x4C, 0x28, 0x1B, 0xD4, 0x2E, 0x99, 0x2C, 0x73, 0x7D, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x47, 0x30, 0x45, 0x02, 0x20, 0x56, 0x34, 0x49, 0xAC, 0x72, 0x4E, 0x58, 0x24, 0x6F, 0x14, 0xEE, 0xD3, 0x01,
+  0x5B, 0xD4, 0x0A, 0x26, 0x2B, 0x6A, 0xD1, 0xB3, 0x33, 0x69, 0x4D, 0x64, 0x0C, 0xAA, 0xAE, 0x63, 0x59, 0x6A, 0xFD, 0x02,
+  0x21, 0x00, 0xFD, 0xB9, 0x9E, 0x37, 0x70, 0x9C, 0xE2, 0x7A, 0x0A, 0xFD, 0x64, 0x99, 0x1B, 0xA3, 0x78, 0x83, 0x09, 0xC6,
+  0xA0, 0x6D, 0x7A, 0x55, 0x8F, 0x6C, 0x35, 0xAB, 0x63, 0x78, 0x9D, 0xF3, 0xDC, 0xBC
 };
 
 const uint8_t ID2_KEY2_CERT2[] = {
-  0x06, 0xFD, 0x01, 0x8D, 0x07, 0x43, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
-  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x37, 0x32, 0x30, 0x30, 0x30, 0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45,
-  0x52, 0x54, 0x08, 0x09, 0xFD, 0x00, 0x00, 0x01, 0x49, 0x9D, 0x5A, 0x77, 0x00, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04,
-  0x00, 0x36, 0xEE, 0x80, 0x15, 0xB2, 0x30, 0x81, 0xAF, 0x30, 0x22, 0x18, 0x0F, 0x32, 0x30, 0x31, 0x34, 0x31, 0x31, 0x31,
-  0x31, 0x30, 0x35, 0x33, 0x36, 0x33, 0x32, 0x5A, 0x18, 0x0F, 0x32, 0x30, 0x33, 0x34, 0x31, 0x31, 0x30, 0x36, 0x30, 0x35,
-  0x33, 0x36, 0x33, 0x32, 0x5A, 0x30, 0x2E, 0x30, 0x2C, 0x06, 0x03, 0x55, 0x04, 0x29, 0x13, 0x25, 0x2F, 0x70, 0x69, 0x62,
-  0x2F, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x2F, 0x69, 0x64, 0x2F, 0x32, 0x2F, 0x6B, 0x73, 0x6B, 0x2D,
-  0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x37, 0x32, 0x30, 0x30, 0x30, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2A,
-  0x86, 0x48, 0xCE, 0x3D, 0x02, 0x01, 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04,
-  0x57, 0xE5, 0x0D, 0xDE, 0x12, 0xAD, 0xF2, 0xA7, 0x34, 0x4A, 0x80, 0xFD, 0x7E, 0x75, 0x87, 0x5F, 0xD6, 0x29, 0x97, 0x1A,
-  0x56, 0x25, 0xAD, 0x67, 0x3E, 0x0C, 0x80, 0x21, 0x30, 0x76, 0x4E, 0x23, 0x17, 0xE6, 0xF4, 0x0B, 0xAA, 0xD2, 0xAF, 0x11,
-  0x20, 0xFC, 0xE6, 0xB2, 0xA4, 0x97, 0xDE, 0x45, 0x28, 0x40, 0x80, 0x1F, 0x42, 0xEC, 0x72, 0x06, 0xF3, 0xE6, 0x68, 0xB3,
-  0x20, 0x42, 0x53, 0xA7, 0x16, 0x3F, 0x1B, 0x01, 0x03, 0x1C, 0x3A, 0x07, 0x38, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09,
-  0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45,
-  0x59, 0x08, 0x11, 0x6B, 0x73, 0x6B, 0x2D, 0x31, 0x34, 0x31, 0x35, 0x36, 0x38, 0x34, 0x31, 0x37, 0x32, 0x30, 0x30, 0x30,
-  0x08, 0x07, 0x49, 0x44, 0x2D, 0x43, 0x45, 0x52, 0x54, 0x17, 0x46, 0x30, 0x44, 0x02, 0x20, 0x08, 0x60, 0xC2, 0x77, 0xFA,
-  0x21, 0x28, 0x15, 0x33, 0xF2, 0xFA, 0x5E, 0x3C, 0x70, 0x20, 0xDE, 0x7F, 0xCA, 0x02, 0xB8, 0x39, 0x9C, 0x2C, 0x9A, 0x16,
-  0x42, 0xBD, 0xB6, 0x8B, 0xBF, 0x48, 0xB4, 0x02, 0x20, 0x11, 0xCB, 0x62, 0xA3, 0xB0, 0xC0, 0xD8, 0xA7, 0x03, 0x9C, 0x6E,
-  0x63, 0xCB, 0x14, 0xBE, 0xA8, 0x1D, 0xC8, 0x38, 0x8A, 0xED, 0x31, 0x52, 0xC4, 0xD4, 0x18, 0x27, 0x83, 0x76, 0xB7, 0x50,
-  0xC8
+  0x06, 0xFD, 0x02, 0x27, 0x07, 0x2B, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72, 0x66, 0x61,
+  0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0x08, 0x06, 0x69,
+  0x73, 0x73, 0x75, 0x65, 0x72, 0x08, 0x02, 0xFD, 0x02, 0x14, 0x09, 0x18, 0x01, 0x02, 0x19, 0x04, 0x00, 0x36, 0xEE, 0x80,
+  0x15, 0xFD, 0x01, 0x4F, 0x30, 0x82, 0x01, 0x4B, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x02,
+  0x01, 0x30, 0x81, 0xF7, 0x02, 0x01, 0x01, 0x30, 0x2C, 0x06, 0x07, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x01, 0x01, 0x02, 0x21,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+  0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x30, 0x5B, 0x04, 0x20, 0xFF, 0xFF, 0xFF,
+  0xFF, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF,
+  0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFC, 0x04, 0x20, 0x5A, 0xC6, 0x35, 0xD8, 0xAA, 0x3A, 0x93, 0xE7, 0xB3,
+  0xEB, 0xBD, 0x55, 0x76, 0x98, 0x86, 0xBC, 0x65, 0x1D, 0x06, 0xB0, 0xCC, 0x53, 0xB0, 0xF6, 0x3B, 0xCE, 0x3C, 0x3E, 0x27,
+  0xD2, 0x60, 0x4B, 0x03, 0x15, 0x00, 0xC4, 0x9D, 0x36, 0x08, 0x86, 0xE7, 0x04, 0x93, 0x6A, 0x66, 0x78, 0xE1, 0x13, 0x9D,
+  0x26, 0xB7, 0x81, 0x9F, 0x7E, 0x90, 0x04, 0x41, 0x04, 0x6B, 0x17, 0xD1, 0xF2, 0xE1, 0x2C, 0x42, 0x47, 0xF8, 0xBC, 0xE6,
+  0xE5, 0x63, 0xA4, 0x40, 0xF2, 0x77, 0x03, 0x7D, 0x81, 0x2D, 0xEB, 0x33, 0xA0, 0xF4, 0xA1, 0x39, 0x45, 0xD8, 0x98, 0xC2,
+  0x96, 0x4F, 0xE3, 0x42, 0xE2, 0xFE, 0x1A, 0x7F, 0x9B, 0x8E, 0xE7, 0xEB, 0x4A, 0x7C, 0x0F, 0x9E, 0x16, 0x2B, 0xCE, 0x33,
+  0x57, 0x6B, 0x31, 0x5E, 0xCE, 0xCB, 0xB6, 0x40, 0x68, 0x37, 0xBF, 0x51, 0xF5, 0x02, 0x21, 0x00, 0xFF, 0xFF, 0xFF, 0xFF,
+  0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xBC, 0xE6, 0xFA, 0xAD, 0xA7, 0x17, 0x9E, 0x84,
+  0xF3, 0xB9, 0xCA, 0xC2, 0xFC, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00, 0x04, 0x2C, 0xC3, 0xAF, 0xA8, 0x73,
+  0xF2, 0x61, 0xCF, 0x48, 0x04, 0x0F, 0x9D, 0xD3, 0xAF, 0x0B, 0xC6, 0x2F, 0x4D, 0xDA, 0x0E, 0x4C, 0x66, 0x1D, 0x03, 0x9D,
+  0xFE, 0x2C, 0x0B, 0xB6, 0x25, 0x60, 0xBC, 0xFA, 0xDA, 0xFE, 0x6F, 0x43, 0xFA, 0x95, 0x45, 0x57, 0x8A, 0x25, 0xEC, 0x0F,
+  0xF2, 0xB7, 0x43, 0x85, 0x0D, 0x0B, 0x8D, 0x97, 0x40, 0x83, 0x4C, 0x28, 0x1B, 0xD4, 0x2E, 0x99, 0x2C, 0x73, 0x7D, 0x16,
+  0x50, 0x1B, 0x01, 0x03, 0x1C, 0x21, 0x07, 0x1F, 0x08, 0x03, 0x70, 0x69, 0x62, 0x08, 0x09, 0x69, 0x6E, 0x74, 0x65, 0x72,
+  0x66, 0x61, 0x63, 0x65, 0x08, 0x02, 0x69, 0x64, 0x08, 0x01, 0x32, 0x08, 0x03, 0x4B, 0x45, 0x59, 0x08, 0x01, 0x02, 0xFD,
+  0x00, 0xFD, 0x26, 0xFD, 0x00, 0xFE, 0x0F, 0x32, 0x30, 0x31, 0x37, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x30, 0xFD, 0x00, 0xFF, 0x0F, 0x32, 0x30, 0x31, 0x38, 0x30, 0x31, 0x30, 0x32, 0x54, 0x30, 0x30, 0x30, 0x30, 0x30,
+  0x30, 0x17, 0x48, 0x30, 0x46, 0x02, 0x21, 0x00, 0xB3, 0xF5, 0x96, 0x19, 0xE7, 0xF9, 0x6B, 0xCF, 0x14, 0x64, 0xB1, 0x08,
+  0xFA, 0xFF, 0xB3, 0x52, 0x8B, 0x41, 0xCB, 0xE7, 0xE0, 0x3D, 0x14, 0x7B, 0xC2, 0xD0, 0xC8, 0x89, 0x88, 0xFA, 0x95, 0x73,
+  0x02, 0x21, 0x00, 0xEC, 0x8E, 0x0C, 0x8B, 0x8C, 0x18, 0x8D, 0x00, 0x7C, 0x12, 0x68, 0x57, 0x87, 0xB1, 0x99, 0x69, 0xDA,
+  0x46, 0xEF, 0x14, 0x2D, 0x04, 0x18, 0xBE, 0x1D, 0xAE, 0x79, 0x49, 0xFD, 0x22, 0x8E, 0xBB
 };
 
 PibDataFixture::PibDataFixture()
-  : id1("/pib/interface/id/1")
-  , id2("/pib/interface/id/2")
-  , id1Key1Name("/pib/interface/id/1/KEY/ksk-1415684132000")
-  , id1Key2Name("/pib/interface/id/1/KEY/ksk-1415684152000")
-  , id2Key1Name("/pib/interface/id/2/KEY/ksk-1415684132000")
-  , id2Key2Name("/pib/interface/id/2/KEY/ksk-1415684152000")
-  , id1Key1(ID1_KEY1, sizeof(ID1_KEY1))
-  , id1Key2(ID1_KEY2, sizeof(ID1_KEY2))
-  , id2Key1(ID2_KEY1, sizeof(ID2_KEY1))
-  , id2Key2(ID2_KEY2, sizeof(ID2_KEY2))
-  , id1Key1Cert1(Block(ID1_KEY1_CERT1, sizeof(ID1_KEY1_CERT1)))
+  : id1Key1Cert1(Block(ID1_KEY1_CERT1, sizeof(ID1_KEY1_CERT1)))
   , id1Key1Cert2(Block(ID1_KEY1_CERT2, sizeof(ID1_KEY1_CERT2)))
   , id1Key2Cert1(Block(ID1_KEY2_CERT1, sizeof(ID1_KEY2_CERT1)))
   , id1Key2Cert2(Block(ID1_KEY2_CERT2, sizeof(ID1_KEY2_CERT2)))
+
   , id2Key1Cert1(Block(ID2_KEY1_CERT1, sizeof(ID2_KEY1_CERT1)))
   , id2Key1Cert2(Block(ID2_KEY1_CERT2, sizeof(ID2_KEY1_CERT2)))
   , id2Key2Cert1(Block(ID2_KEY2_CERT1, sizeof(ID2_KEY2_CERT1)))
   , id2Key2Cert2(Block(ID2_KEY2_CERT2, sizeof(ID2_KEY2_CERT2)))
+
+  , id1(id1Key1Cert1.getIdentity())
+  , id2(id2Key1Cert1.getIdentity())
+
+  , id1Key1Name(id1Key1Cert1.getKeyName())
+  , id1Key2Name(id1Key2Cert1.getKeyName())
+
+  , id2Key1Name(id2Key1Cert1.getKeyName())
+  , id2Key2Name(id2Key2Cert1.getKeyName())
+
+  , id1Key1(id1Key1Cert1.getPublicKey())
+  , id1Key2(id1Key2Cert1.getPublicKey())
+  , id2Key1(id2Key1Cert1.getPublicKey())
+  , id2Key2(id2Key2Cert1.getPublicKey())
 {
+  BOOST_ASSERT(id1Key1Cert1.getPublicKey() == id1Key1Cert2.getPublicKey());
+  BOOST_ASSERT(id1Key2Cert1.getPublicKey() == id1Key2Cert2.getPublicKey());
+  BOOST_ASSERT(id2Key1Cert1.getPublicKey() == id2Key1Cert2.getPublicKey());
+  BOOST_ASSERT(id2Key2Cert1.getPublicKey() == id2Key2Cert2.getPublicKey());
+
+  BOOST_ASSERT(id1Key1Cert1.getPublicKey() == id1Key1);
+  BOOST_ASSERT(id1Key1Cert2.getPublicKey() == id1Key1);
+  BOOST_ASSERT(id1Key2Cert1.getPublicKey() == id1Key2);
+  BOOST_ASSERT(id1Key2Cert2.getPublicKey() == id1Key2);
+
+  BOOST_ASSERT(id2Key1Cert1.getPublicKey() == id2Key1);
+  BOOST_ASSERT(id2Key1Cert2.getPublicKey() == id2Key1);
+  BOOST_ASSERT(id2Key2Cert1.getPublicKey() == id2Key2);
+  BOOST_ASSERT(id2Key2Cert2.getPublicKey() == id2Key2);
+
+  BOOST_ASSERT(id1Key1Cert2.getIdentity() == id1);
+  BOOST_ASSERT(id1Key2Cert1.getIdentity() == id1);
+  BOOST_ASSERT(id1Key2Cert2.getIdentity() == id1);
+
+  BOOST_ASSERT(id2Key1Cert2.getIdentity() == id2);
+  BOOST_ASSERT(id2Key2Cert1.getIdentity() == id2);
+  BOOST_ASSERT(id2Key2Cert2.getIdentity() == id2);
+
+  BOOST_ASSERT(id1Key1Cert2.getKeyName() == id1Key1Name);
+  BOOST_ASSERT(id1Key2Cert2.getKeyName() == id1Key2Name);
+
+  BOOST_ASSERT(id2Key1Cert2.getKeyName() == id2Key1Name);
+  BOOST_ASSERT(id2Key2Cert2.getKeyName() == id2Key2Name);
 }
 
 } // namespace tests
diff --git a/tests/unit-tests/security/pib/pib-data-fixture.hpp b/tests/unit-tests/security/pib/pib-data-fixture.hpp
index 82a8f3e..aad5916 100644
--- a/tests/unit-tests/security/pib/pib-data-fixture.hpp
+++ b/tests/unit-tests/security/pib/pib-data-fixture.hpp
@@ -36,6 +36,15 @@
   PibDataFixture();
 
 public:
+  v2::Certificate id1Key1Cert1;
+  v2::Certificate id1Key1Cert2;
+  v2::Certificate id1Key2Cert1;
+  v2::Certificate id1Key2Cert2;
+  v2::Certificate id2Key1Cert1;
+  v2::Certificate id2Key1Cert2;
+  v2::Certificate id2Key2Cert1;
+  v2::Certificate id2Key2Cert2;
+
   Name id1;
   Name id2;
 
@@ -48,15 +57,6 @@
   Buffer id1Key2;
   Buffer id2Key1;
   Buffer id2Key2;
-
-  v2::Certificate id1Key1Cert1;
-  v2::Certificate id1Key1Cert2;
-  v2::Certificate id1Key2Cert1;
-  v2::Certificate id1Key2Cert2;
-  v2::Certificate id2Key1Cert1;
-  v2::Certificate id2Key1Cert2;
-  v2::Certificate id2Key2Cert1;
-  v2::Certificate id2Key2Cert2;
 };
 
 } // namespace tests
diff --git a/tests/unit-tests/security/pib/pib-impl.t.cpp b/tests/unit-tests/security/pib/pib-impl.t.cpp
index 610d657..3103416 100644
--- a/tests/unit-tests/security/pib/pib-impl.t.cpp
+++ b/tests/unit-tests/security/pib/pib-impl.t.cpp
@@ -224,8 +224,7 @@
   BOOST_CHECK_EQUAL(this->pib.hasCertificate(this->id1Key1Cert1.getName()), true);
   BOOST_CHECK_EQUAL(this->pib.hasIdentity(this->id1), true);
   BOOST_CHECK_EQUAL(this->pib.hasKey(this->id1Key1Name), true);
-  const auto& cert = this->pib.getCertificate(this->id1Key1Cert1.getName());
-  BOOST_CHECK(cert.wireEncode() == this->id1Key1Cert1.wireEncode());
+  BOOST_CHECK(this->pib.getCertificate(this->id1Key1Cert1.getName()).wireEncode() == this->id1Key1Cert1.wireEncode());
   BOOST_CHECK_NO_THROW(this->pib.getDefaultCertificateOfKey(this->id1Key1Name));
   BOOST_CHECK_EQUAL(this->pib.getDefaultCertificateOfKey(this->id1Key1Name), this->id1Key1Cert1);
 
@@ -265,6 +264,81 @@
   BOOST_CHECK_EQUAL(certNames.size(), 0);
 }
 
+BOOST_FIXTURE_TEST_CASE_TEMPLATE(DefaultsManagement, T, PibImpls, T)
+{
+  this->pib.addIdentity(this->id1);
+  BOOST_CHECK_EQUAL(this->pib.getDefaultIdentity(), this->id1);
+
+  this->pib.addIdentity(this->id2);
+  BOOST_CHECK_EQUAL(this->pib.getDefaultIdentity(), this->id1);
+
+  this->pib.removeIdentity(this->id1);
+  BOOST_CHECK_THROW(this->pib.getDefaultIdentity(), Pib::Error);
+
+  this->pib.addKey(this->id2, this->id2Key1Name, this->id2Key1.buf(), this->id2Key1.size());
+  BOOST_CHECK_EQUAL(this->pib.getDefaultIdentity(), this->id2);
+  BOOST_CHECK_EQUAL(this->pib.getDefaultKeyOfIdentity(this->id2), this->id2Key1Name);
+
+  this->pib.addKey(this->id2, this->id2Key2Name, this->id2Key2.buf(), this->id2Key2.size());
+  BOOST_CHECK_EQUAL(this->pib.getDefaultKeyOfIdentity(this->id2), this->id2Key1Name);
+
+  this->pib.removeKey(this->id2Key1Name);
+  BOOST_CHECK_THROW(this->pib.getDefaultKeyOfIdentity(this->id2), Pib::Error);
+
+  this->pib.addCertificate(this->id2Key2Cert1);
+  BOOST_CHECK_EQUAL(this->pib.getDefaultKeyOfIdentity(this->id2), this->id2Key2Name);
+  BOOST_CHECK_EQUAL(this->pib.getDefaultCertificateOfKey(this->id2Key2Name).getName(), this->id2Key2Cert1.getName());
+
+  this->pib.addCertificate(this->id2Key2Cert2);
+  BOOST_CHECK_EQUAL(this->pib.getDefaultCertificateOfKey(this->id2Key2Name).getName(), this->id2Key2Cert1.getName());
+
+  this->pib.removeCertificate(this->id2Key2Cert2.getName());
+  BOOST_CHECK_EQUAL(this->pib.getDefaultCertificateOfKey(this->id2Key2Name).getName(), this->id2Key2Cert1.getName());
+}
+
+BOOST_FIXTURE_TEST_CASE_TEMPLATE(Overwrite, T, PibImpls, T)
+{
+  // check id1Key1, should not exist
+  this->pib.removeIdentity(this->id1);
+  BOOST_CHECK_EQUAL(this->pib.hasKey(this->id1Key1Name), false);
+
+  // add id1Key1
+  this->pib.addKey(this->id1, this->id1Key1Name, this->id1Key1.buf(), this->id1Key1.size());
+  BOOST_CHECK_EQUAL(this->pib.hasKey(this->id1Key1Name), true);
+  const Buffer& keyBits = this->pib.getKeyBits(this->id1Key1Name);
+  BOOST_CHECK(keyBits == this->id1Key1);
+
+  // check overwrite, add a key with the same name.
+  this->pib.addKey(this->id1, this->id1Key1Name, this->id1Key2.buf(), this->id1Key2.size());
+  const Buffer& keyBits2 = this->pib.getKeyBits(this->id1Key1Name);
+  BOOST_CHECK(keyBits2 == this->id1Key2);
+
+  // check id1Key1Cert1, should not exist
+  this->pib.removeIdentity(this->id1);
+  BOOST_CHECK_EQUAL(this->pib.hasCertificate(this->id1Key1Cert1.getName()), false);
+
+  // add id1Key1Cert1
+  this->pib.addKey(this->id1, this->id1Key1Name, this->id1Key1.buf(), this->id1Key1.size());
+  this->pib.addCertificate(this->id1Key1Cert1);
+  BOOST_CHECK_EQUAL(this->pib.hasCertificate(this->id1Key1Cert1.getName()), true);
+
+  auto cert = this->pib.getCertificate(this->id1Key1Cert1.getName());
+  BOOST_CHECK(cert.wireEncode() == this->id1Key1Cert1.wireEncode());
+
+  // Create a fake cert with the same name
+  auto cert2 = this->id1Key2Cert1;
+  cert2.setName(this->id1Key1Cert1.getName());
+  cert2.setSignature(this->id1Key2Cert1.getSignature());
+  this->pib.addCertificate(cert2);
+
+  auto cert3 = this->pib.getCertificate(this->id1Key1Cert1.getName());
+  BOOST_CHECK(cert3.wireEncode() == cert2.wireEncode());
+
+  // both key and certificate are overwritten
+  Buffer keyBits3 = this->pib.getKeyBits(this->id1Key1Name);
+  BOOST_CHECK(keyBits3 == this->id1Key2);
+}
+
 BOOST_AUTO_TEST_SUITE_END() // TestPibImpl
 BOOST_AUTO_TEST_SUITE_END() // Pib
 BOOST_AUTO_TEST_SUITE_END() // Security