public final class sun.security.validator.PKIXValidator extends sun.security.validator.Validator
  minor version: 0
  major version: 59
  flags: flags: (0x0031) ACC_PUBLIC, ACC_FINAL, ACC_SUPER
  this_class: sun.security.validator.PKIXValidator
  super_class: sun.security.validator.Validator
{
  private static final boolean checkTLSRevocation;
    descriptor: Z
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL

  private static final boolean ALLOW_NON_CA_ANCHOR;
    descriptor: Z
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL

  private final java.util.Set<java.security.cert.X509Certificate> trustedCerts;
    descriptor: Ljava/util/Set;
    flags: (0x0012) ACC_PRIVATE, ACC_FINAL
    Signature: Ljava/util/Set<Ljava/security/cert/X509Certificate;>;

  private final java.security.cert.PKIXBuilderParameters parameterTemplate;
    descriptor: Ljava/security/cert/PKIXBuilderParameters;
    flags: (0x0012) ACC_PRIVATE, ACC_FINAL

  private int certPathLength;
    descriptor: I
    flags: (0x0002) ACC_PRIVATE

  private final java.util.Map<javax.security.auth.x500.X500Principal, java.util.List<java.security.PublicKey>> trustedSubjects;
    descriptor: Ljava/util/Map;
    flags: (0x0012) ACC_PRIVATE, ACC_FINAL
    Signature: Ljava/util/Map<Ljavax/security/auth/x500/X500Principal;Ljava/util/List<Ljava/security/PublicKey;>;>;

  private final java.security.cert.CertificateFactory factory;
    descriptor: Ljava/security/cert/CertificateFactory;
    flags: (0x0012) ACC_PRIVATE, ACC_FINAL

  private final boolean plugin;
    descriptor: Z
    flags: (0x0012) ACC_PRIVATE, ACC_FINAL

  static void <clinit>();
    descriptor: ()V
    flags: (0x0008) ACC_STATIC
    Code:
      stack=1, locals=0, args_size=0
         0: .line 62
            ldc "com.sun.net.ssl.checkRevocation"
            invokestatic sun.security.action.GetBooleanAction.privilegedGetProperty:(Ljava/lang/String;)Z
         1: .line 61
            putstatic sun.security.validator.PKIXValidator.checkTLSRevocation:Z
         2: .line 69
            invokestatic sun.security.validator.PKIXValidator.allowNonCaAnchor:()Z
            putstatic sun.security.validator.PKIXValidator.ALLOW_NON_CA_ANCHOR:Z
            return
      LocalVariableTable:
        Start  End  Slot  Name  Signature

  private static boolean allowNonCaAnchor();
    descriptor: ()Z
    flags: (0x000a) ACC_PRIVATE, ACC_STATIC
    Code:
      stack=2, locals=1, args_size=0
         0: .line 72
            ldc "jdk.security.allowNonCaAnchor"
            invokestatic sun.security.action.GetPropertyAction.privilegedGetProperty:(Ljava/lang/String;)Ljava/lang/String;
         1: .line 71
            astore 0 /* prop */
        start local 0 // java.lang.String prop
         2: .line 73
            aload 0 /* prop */
            ifnull 4
            aload 0 /* prop */
            invokevirtual java.lang.String.isEmpty:()Z
            ifne 3
            aload 0 /* prop */
            ldc "true"
            invokevirtual java.lang.String.equalsIgnoreCase:(Ljava/lang/String;)Z
            ifeq 4
      StackMap locals: java.lang.String
      StackMap stack:
         3: iconst_1
            ireturn
      StackMap locals:
      StackMap stack:
         4: iconst_0
            ireturn
        end local 0 // java.lang.String prop
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            2    5     0  prop  Ljava/lang/String;

  void <init>(java.lang.String, java.util.Collection<java.security.cert.X509Certificate>);
    descriptor: (Ljava/lang/String;Ljava/util/Collection;)V
    flags: (0x0000) 
    Code:
      stack=5, locals=6, args_size=3
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.lang.String variant
        start local 2 // java.util.Collection trustedCerts
         0: .line 87
            aload 0 /* this */
            ldc "PKIX"
            aload 1 /* variant */
            invokespecial sun.security.validator.Validator.<init>:(Ljava/lang/String;Ljava/lang/String;)V
         1: .line 78
            aload 0 /* this */
            iconst_m1
            putfield sun.security.validator.PKIXValidator.certPathLength:I
         2: .line 88
            aload 0 /* this */
            aload 2 /* trustedCerts */
            instanceof java.util.Set
            ifeq 4
         3: .line 89
            aload 2 /* trustedCerts */
            checkcast java.util.Set
            goto 5
         4: .line 90
      StackMap locals: sun.security.validator.PKIXValidator java.lang.String java.util.Collection
      StackMap stack: sun.security.validator.PKIXValidator
            new java.util.HashSet
            dup
            aload 2 /* trustedCerts */
            invokespecial java.util.HashSet.<init>:(Ljava/util/Collection;)V
         5: .line 88
      StackMap locals: sun.security.validator.PKIXValidator java.lang.String java.util.Collection
      StackMap stack: sun.security.validator.PKIXValidator java.util.Set
            putfield sun.security.validator.PKIXValidator.trustedCerts:Ljava/util/Set;
         6: .line 92
            new java.util.HashSet
            dup
            invokespecial java.util.HashSet.<init>:()V
            astore 3 /* trustAnchors */
        start local 3 // java.util.Set trustAnchors
         7: .line 93
            aload 2 /* trustedCerts */
            invokeinterface java.util.Collection.iterator:()Ljava/util/Iterator;
            astore 5
            goto 10
      StackMap locals: sun.security.validator.PKIXValidator java.lang.String java.util.Collection java.util.Set top java.util.Iterator
      StackMap stack:
         8: aload 5
            invokeinterface java.util.Iterator.next:()Ljava/lang/Object;
            checkcast java.security.cert.X509Certificate
            astore 4 /* cert */
        start local 4 // java.security.cert.X509Certificate cert
         9: .line 94
            aload 3 /* trustAnchors */
            new java.security.cert.TrustAnchor
            dup
            aload 4 /* cert */
            aconst_null
            invokespecial java.security.cert.TrustAnchor.<init>:(Ljava/security/cert/X509Certificate;[B)V
            invokeinterface java.util.Set.add:(Ljava/lang/Object;)Z
            pop
        end local 4 // java.security.cert.X509Certificate cert
        10: .line 93
      StackMap locals:
      StackMap stack:
            aload 5
            invokeinterface java.util.Iterator.hasNext:()Z
            ifne 8
        11: .line 98
            aload 0 /* this */
            new java.security.cert.PKIXBuilderParameters
            dup
            aload 3 /* trustAnchors */
            aconst_null
            invokespecial java.security.cert.PKIXBuilderParameters.<init>:(Ljava/util/Set;Ljava/security/cert/CertSelector;)V
            putfield sun.security.validator.PKIXValidator.parameterTemplate:Ljava/security/cert/PKIXBuilderParameters;
        12: .line 99
            aload 0 /* this */
            ldc "X.509"
            invokestatic java.security.cert.CertificateFactory.getInstance:(Ljava/lang/String;)Ljava/security/cert/CertificateFactory;
            putfield sun.security.validator.PKIXValidator.factory:Ljava/security/cert/CertificateFactory;
        13: .line 100
            goto 18
      StackMap locals: sun.security.validator.PKIXValidator java.lang.String java.util.Collection java.util.Set
      StackMap stack: java.security.InvalidAlgorithmParameterException
        14: astore 4 /* e */
        start local 4 // java.security.InvalidAlgorithmParameterException e
        15: .line 101
            new java.lang.RuntimeException
            dup
            new java.lang.StringBuilder
            dup
            ldc "Unexpected error: "
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
            aload 4 /* e */
            invokevirtual java.security.InvalidAlgorithmParameterException.toString:()Ljava/lang/String;
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/String;)Ljava/lang/StringBuilder;
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
            aload 4 /* e */
            invokespecial java.lang.RuntimeException.<init>:(Ljava/lang/String;Ljava/lang/Throwable;)V
            athrow
        end local 4 // java.security.InvalidAlgorithmParameterException e
        16: .line 102
      StackMap locals:
      StackMap stack: java.security.cert.CertificateException
            astore 4 /* e */
        start local 4 // java.security.cert.CertificateException e
        17: .line 103
            new java.lang.RuntimeException
            dup
            ldc "Internal error"
            aload 4 /* e */
            invokespecial java.lang.RuntimeException.<init>:(Ljava/lang/String;Ljava/lang/Throwable;)V
            athrow
        end local 4 // java.security.cert.CertificateException e
        18: .line 106
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            aload 1 /* variant */
            invokevirtual sun.security.validator.PKIXValidator.setDefaultParameters:(Ljava/lang/String;)V
        19: .line 107
            aload 0 /* this */
            aload 1 /* variant */
            ldc "plugin code signing"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            putfield sun.security.validator.PKIXValidator.plugin:Z
        20: .line 109
            aload 0 /* this */
            aload 0 /* this */
            invokevirtual sun.security.validator.PKIXValidator.setTrustedSubjects:()Ljava/util/Map;
            putfield sun.security.validator.PKIXValidator.trustedSubjects:Ljava/util/Map;
        21: .line 110
            return
        end local 3 // java.util.Set trustAnchors
        end local 2 // java.util.Collection trustedCerts
        end local 1 // java.lang.String variant
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot          Name  Signature
            0   22     0          this  Lsun/security/validator/PKIXValidator;
            0   22     1       variant  Ljava/lang/String;
            0   22     2  trustedCerts  Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;
            7   22     3  trustAnchors  Ljava/util/Set<Ljava/security/cert/TrustAnchor;>;
            9   10     4          cert  Ljava/security/cert/X509Certificate;
           15   16     4             e  Ljava/security/InvalidAlgorithmParameterException;
           17   18     4             e  Ljava/security/cert/CertificateException;
      Exception table:
        from    to  target  type
          11    13      14  Class java.security.InvalidAlgorithmParameterException
          11    13      16  Class java.security.cert.CertificateException
    Signature: (Ljava/lang/String;Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;)V
    MethodParameters:
              Name  Flags
      variant       
      trustedCerts  

  void <init>(java.lang.String, java.security.cert.PKIXBuilderParameters);
    descriptor: (Ljava/lang/String;Ljava/security/cert/PKIXBuilderParameters;)V
    flags: (0x0000) 
    Code:
      stack=4, locals=6, args_size=3
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.lang.String variant
        start local 2 // java.security.cert.PKIXBuilderParameters params
         0: .line 113
            aload 0 /* this */
            ldc "PKIX"
            aload 1 /* variant */
            invokespecial sun.security.validator.Validator.<init>:(Ljava/lang/String;Ljava/lang/String;)V
         1: .line 78
            aload 0 /* this */
            iconst_m1
            putfield sun.security.validator.PKIXValidator.certPathLength:I
         2: .line 114
            aload 0 /* this */
            new java.util.HashSet
            dup
            invokespecial java.util.HashSet.<init>:()V
            putfield sun.security.validator.PKIXValidator.trustedCerts:Ljava/util/Set;
         3: .line 115
            aload 2 /* params */
            invokevirtual java.security.cert.PKIXBuilderParameters.getTrustAnchors:()Ljava/util/Set;
            invokeinterface java.util.Set.iterator:()Ljava/util/Iterator;
            astore 4
            goto 8
      StackMap locals: sun.security.validator.PKIXValidator java.lang.String java.security.cert.PKIXBuilderParameters top java.util.Iterator
      StackMap stack:
         4: aload 4
            invokeinterface java.util.Iterator.next:()Ljava/lang/Object;
            checkcast java.security.cert.TrustAnchor
            astore 3 /* anchor */
        start local 3 // java.security.cert.TrustAnchor anchor
         5: .line 116
            aload 3 /* anchor */
            invokevirtual java.security.cert.TrustAnchor.getTrustedCert:()Ljava/security/cert/X509Certificate;
            astore 5 /* cert */
        start local 5 // java.security.cert.X509Certificate cert
         6: .line 117
            aload 5 /* cert */
            ifnull 8
         7: .line 118
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedCerts:Ljava/util/Set;
            aload 5 /* cert */
            invokeinterface java.util.Set.add:(Ljava/lang/Object;)Z
            pop
        end local 5 // java.security.cert.X509Certificate cert
        end local 3 // java.security.cert.TrustAnchor anchor
         8: .line 115
      StackMap locals:
      StackMap stack:
            aload 4
            invokeinterface java.util.Iterator.hasNext:()Z
            ifne 4
         9: .line 121
            aload 0 /* this */
            aload 2 /* params */
            putfield sun.security.validator.PKIXValidator.parameterTemplate:Ljava/security/cert/PKIXBuilderParameters;
        10: .line 124
            aload 0 /* this */
            ldc "X.509"
            invokestatic java.security.cert.CertificateFactory.getInstance:(Ljava/lang/String;)Ljava/security/cert/CertificateFactory;
            putfield sun.security.validator.PKIXValidator.factory:Ljava/security/cert/CertificateFactory;
        11: .line 125
            goto 14
      StackMap locals: sun.security.validator.PKIXValidator java.lang.String java.security.cert.PKIXBuilderParameters
      StackMap stack: java.security.cert.CertificateException
        12: astore 3 /* e */
        start local 3 // java.security.cert.CertificateException e
        13: .line 126
            new java.lang.RuntimeException
            dup
            ldc "Internal error"
            aload 3 /* e */
            invokespecial java.lang.RuntimeException.<init>:(Ljava/lang/String;Ljava/lang/Throwable;)V
            athrow
        end local 3 // java.security.cert.CertificateException e
        14: .line 129
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            aload 1 /* variant */
            ldc "plugin code signing"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            putfield sun.security.validator.PKIXValidator.plugin:Z
        15: .line 131
            aload 0 /* this */
            aload 0 /* this */
            invokevirtual sun.security.validator.PKIXValidator.setTrustedSubjects:()Ljava/util/Map;
            putfield sun.security.validator.PKIXValidator.trustedSubjects:Ljava/util/Map;
        16: .line 132
            return
        end local 2 // java.security.cert.PKIXBuilderParameters params
        end local 1 // java.lang.String variant
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot     Name  Signature
            0   17     0     this  Lsun/security/validator/PKIXValidator;
            0   17     1  variant  Ljava/lang/String;
            0   17     2   params  Ljava/security/cert/PKIXBuilderParameters;
            5    8     3   anchor  Ljava/security/cert/TrustAnchor;
            6    8     5     cert  Ljava/security/cert/X509Certificate;
           13   14     3        e  Ljava/security/cert/CertificateException;
      Exception table:
        from    to  target  type
          10    11      12  Class java.security.cert.CertificateException
    MethodParameters:
         Name  Flags
      variant  
      params   

  private java.util.Map<javax.security.auth.x500.X500Principal, java.util.List<java.security.PublicKey>> setTrustedSubjects();
    descriptor: ()Ljava/util/Map;
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=3, locals=6, args_size=1
        start local 0 // sun.security.validator.PKIXValidator this
         0: .line 142
            new java.util.HashMap
            dup
            invokespecial java.util.HashMap.<init>:()V
            astore 1 /* subjectMap */
        start local 1 // java.util.Map subjectMap
         1: .line 144
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedCerts:Ljava/util/Set;
            invokeinterface java.util.Set.iterator:()Ljava/util/Iterator;
            astore 3
            goto 10
      StackMap locals: sun.security.validator.PKIXValidator java.util.Map top java.util.Iterator
      StackMap stack:
         2: aload 3
            invokeinterface java.util.Iterator.next:()Ljava/lang/Object;
            checkcast java.security.cert.X509Certificate
            astore 2 /* cert */
        start local 2 // java.security.cert.X509Certificate cert
         3: .line 145
            aload 2 /* cert */
            invokevirtual java.security.cert.X509Certificate.getSubjectX500Principal:()Ljavax/security/auth/x500/X500Principal;
            astore 4 /* dn */
        start local 4 // javax.security.auth.x500.X500Principal dn
         4: .line 147
            aload 1 /* subjectMap */
            aload 4 /* dn */
            invokeinterface java.util.Map.containsKey:(Ljava/lang/Object;)Z
            ifeq 7
         5: .line 148
            aload 1 /* subjectMap */
            aload 4 /* dn */
            invokeinterface java.util.Map.get:(Ljava/lang/Object;)Ljava/lang/Object;
            checkcast java.util.List
            astore 5 /* keys */
        start local 5 // java.util.List keys
         6: .line 149
            goto 9
        end local 5 // java.util.List keys
         7: .line 150
      StackMap locals: sun.security.validator.PKIXValidator java.util.Map java.security.cert.X509Certificate java.util.Iterator javax.security.auth.x500.X500Principal
      StackMap stack:
            new java.util.ArrayList
            dup
            invokespecial java.util.ArrayList.<init>:()V
            astore 5 /* keys */
        start local 5 // java.util.List keys
         8: .line 151
            aload 1 /* subjectMap */
            aload 4 /* dn */
            aload 5 /* keys */
            invokeinterface java.util.Map.put:(Ljava/lang/Object;Ljava/lang/Object;)Ljava/lang/Object;
            pop
         9: .line 153
      StackMap locals: java.util.List
      StackMap stack:
            aload 5 /* keys */
            aload 2 /* cert */
            invokevirtual java.security.cert.X509Certificate.getPublicKey:()Ljava/security/PublicKey;
            invokeinterface java.util.List.add:(Ljava/lang/Object;)Z
            pop
        end local 5 // java.util.List keys
        end local 4 // javax.security.auth.x500.X500Principal dn
        end local 2 // java.security.cert.X509Certificate cert
        10: .line 144
      StackMap locals: sun.security.validator.PKIXValidator java.util.Map top java.util.Iterator
      StackMap stack:
            aload 3
            invokeinterface java.util.Iterator.hasNext:()Z
            ifne 2
        11: .line 156
            aload 1 /* subjectMap */
            areturn
        end local 1 // java.util.Map subjectMap
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot        Name  Signature
            0   12     0        this  Lsun/security/validator/PKIXValidator;
            1   12     1  subjectMap  Ljava/util/Map<Ljavax/security/auth/x500/X500Principal;Ljava/util/List<Ljava/security/PublicKey;>;>;
            3   10     2        cert  Ljava/security/cert/X509Certificate;
            4   10     4          dn  Ljavax/security/auth/x500/X500Principal;
            6    7     5        keys  Ljava/util/List<Ljava/security/PublicKey;>;
            8   10     5        keys  Ljava/util/List<Ljava/security/PublicKey;>;
    Signature: ()Ljava/util/Map<Ljavax/security/auth/x500/X500Principal;Ljava/util/List<Ljava/security/PublicKey;>;>;

  public java.util.Collection<java.security.cert.X509Certificate> getTrustedCertificates();
    descriptor: ()Ljava/util/Collection;
    flags: (0x0001) ACC_PUBLIC
    Code:
      stack=1, locals=1, args_size=1
        start local 0 // sun.security.validator.PKIXValidator this
         0: .line 161
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedCerts:Ljava/util/Set;
            areturn
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0    1     0  this  Lsun/security/validator/PKIXValidator;
    Signature: ()Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;

  public int getCertPathLength();
    descriptor: ()I
    flags: (0x0001) ACC_PUBLIC
    Code:
      stack=1, locals=1, args_size=1
        start local 0 // sun.security.validator.PKIXValidator this
         0: .line 175
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.certPathLength:I
            ireturn
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0    1     0  this  Lsun/security/validator/PKIXValidator;

  private void setDefaultParameters(java.lang.String);
    descriptor: (Ljava/lang/String;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=2, locals=2, args_size=2
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.lang.String variant
         0: .line 183
            aload 1 /* variant */
            ldc "tls server"
            if_acmpeq 2
         1: .line 184
            aload 1 /* variant */
            ldc "tls client"
            if_acmpne 4
         2: .line 185
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.parameterTemplate:Ljava/security/cert/PKIXBuilderParameters;
            getstatic sun.security.validator.PKIXValidator.checkTLSRevocation:Z
            invokevirtual java.security.cert.PKIXBuilderParameters.setRevocationEnabled:(Z)V
         3: .line 186
            goto 5
         4: .line 187
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.parameterTemplate:Ljava/security/cert/PKIXBuilderParameters;
            iconst_0
            invokevirtual java.security.cert.PKIXBuilderParameters.setRevocationEnabled:(Z)V
         5: .line 189
      StackMap locals:
      StackMap stack:
            return
        end local 1 // java.lang.String variant
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot     Name  Signature
            0    6     0     this  Lsun/security/validator/PKIXValidator;
            0    6     1  variant  Ljava/lang/String;
    MethodParameters:
         Name  Flags
      variant  

  public java.security.cert.PKIXBuilderParameters getParameters();
    descriptor: ()Ljava/security/cert/PKIXBuilderParameters;
    flags: (0x0001) ACC_PUBLIC
    Code:
      stack=1, locals=1, args_size=1
        start local 0 // sun.security.validator.PKIXValidator this
         0: .line 197
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.parameterTemplate:Ljava/security/cert/PKIXBuilderParameters;
            areturn
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0    1     0  this  Lsun/security/validator/PKIXValidator;

  java.security.cert.X509Certificate[] engineValidate(java.security.cert.X509Certificate[], java.util.Collection<java.security.cert.X509Certificate>, java.util.List<byte[]>, java.security.AlgorithmConstraints, );
    descriptor: ([Ljava/security/cert/X509Certificate;Ljava/util/Collection;Ljava/util/List;Ljava/security/AlgorithmConstraints;Ljava/lang/Object;)[Ljava/security/cert/X509Certificate;
    flags: (0x0000) 
    Code:
      stack=6, locals=12, args_size=6
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.security.cert.X509Certificate[] chain
        start local 2 // java.util.Collection otherCerts
        start local 3 // java.util.List responseList
        start local 4 // java.security.AlgorithmConstraints constraints
        start local 5 // java.lang.Object parameter
         0: .line 206
            aload 1 /* chain */
            ifnull 1
            aload 1 /* chain */
            arraylength
            ifne 4
         1: .line 207
      StackMap locals:
      StackMap stack:
            new java.security.cert.CertificateException
            dup
         2: .line 208
            ldc "null or zero-length certificate chain"
         3: .line 207
            invokespecial java.security.cert.CertificateException.<init>:(Ljava/lang/String;)V
            athrow
         4: .line 213
      StackMap locals:
      StackMap stack:
            aconst_null
            astore 6 /* pkixParameters */
        start local 6 // java.security.cert.PKIXBuilderParameters pkixParameters
         5: .line 215
            new sun.security.provider.certpath.PKIXExtendedParameters
            dup
         6: .line 216
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.parameterTemplate:Ljava/security/cert/PKIXBuilderParameters;
            invokevirtual java.security.cert.PKIXBuilderParameters.clone:()Ljava/lang/Object;
            checkcast java.security.cert.PKIXBuilderParameters
         7: .line 217
            aload 5 /* parameter */
            instanceof java.security.Timestamp
            ifeq 9
         8: .line 218
            aload 5 /* parameter */
            checkcast java.security.Timestamp
            goto 10
      StackMap locals: sun.security.validator.PKIXValidator java.security.cert.X509Certificate[] java.util.Collection java.util.List java.security.AlgorithmConstraints java.lang.Object java.security.cert.PKIXBuilderParameters
      StackMap stack: new 5 new 5 java.security.cert.PKIXBuilderParameters
         9: aconst_null
        10: .line 219
      StackMap locals: sun.security.validator.PKIXValidator java.security.cert.X509Certificate[] java.util.Collection java.util.List java.security.AlgorithmConstraints java.lang.Object java.security.cert.PKIXBuilderParameters
      StackMap stack: new 5 new 5 java.security.cert.PKIXBuilderParameters java.security.Timestamp
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.variant:Ljava/lang/String;
        11: .line 215
            invokespecial sun.security.provider.certpath.PKIXExtendedParameters.<init>:(Ljava/security/cert/PKIXBuilderParameters;Ljava/security/Timestamp;Ljava/lang/String;)V
            astore 6 /* pkixParameters */
        12: .line 220
            goto 14
      StackMap locals:
      StackMap stack: java.security.InvalidAlgorithmParameterException
        13: pop
        14: .line 225
      StackMap locals:
      StackMap stack:
            aload 4 /* constraints */
            ifnull 18
        15: .line 226
            aload 6 /* pkixParameters */
        16: .line 227
            new sun.security.provider.certpath.AlgorithmChecker
            dup
            aload 4 /* constraints */
            aconst_null
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.variant:Ljava/lang/String;
            invokespecial sun.security.provider.certpath.AlgorithmChecker.<init>:(Ljava/security/AlgorithmConstraints;Ljava/security/Timestamp;Ljava/lang/String;)V
        17: .line 226
            invokevirtual java.security.cert.PKIXBuilderParameters.addCertPathChecker:(Ljava/security/cert/PKIXCertPathChecker;)V
        18: .line 231
      StackMap locals:
      StackMap stack:
            aload 3 /* responseList */
            invokeinterface java.util.List.isEmpty:()Z
            ifne 20
        19: .line 232
            aload 6 /* pkixParameters */
            aload 1 /* chain */
            aload 3 /* responseList */
            invokestatic sun.security.validator.PKIXValidator.addResponses:(Ljava/security/cert/PKIXBuilderParameters;[Ljava/security/cert/X509Certificate;Ljava/util/List;)V
        20: .line 237
      StackMap locals:
      StackMap stack:
            aconst_null
            astore 7 /* prevIssuer */
        start local 7 // javax.security.auth.x500.X500Principal prevIssuer
        21: .line 238
            iconst_0
            istore 8 /* i */
        start local 8 // int i
        22: goto 41
        23: .line 239
      StackMap locals: javax.security.auth.x500.X500Principal int
      StackMap stack:
            aload 1 /* chain */
            iload 8 /* i */
            aaload
            astore 9 /* cert */
        start local 9 // java.security.cert.X509Certificate cert
        24: .line 240
            aload 9 /* cert */
            invokevirtual java.security.cert.X509Certificate.getSubjectX500Principal:()Ljavax/security/auth/x500/X500Principal;
            astore 10 /* dn */
        start local 10 // javax.security.auth.x500.X500Principal dn
        25: .line 242
            iload 8 /* i */
            ifne 28
        26: .line 243
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedCerts:Ljava/util/Set;
            aload 9 /* cert */
            invokeinterface java.util.Set.contains:(Ljava/lang/Object;)Z
            ifeq 39
        27: .line 244
            iconst_1
            anewarray java.security.cert.X509Certificate
            dup
            iconst_0
            aload 1 /* chain */
            iconst_0
            aaload
            aastore
            areturn
        28: .line 247
      StackMap locals: java.security.cert.X509Certificate javax.security.auth.x500.X500Principal
      StackMap stack:
            aload 10 /* dn */
            aload 7 /* prevIssuer */
            invokevirtual javax.security.auth.x500.X500Principal.equals:(Ljava/lang/Object;)Z
            ifne 30
        29: .line 249
            aload 0 /* this */
            aload 1 /* chain */
            aload 2 /* otherCerts */
            aload 6 /* pkixParameters */
            invokevirtual sun.security.validator.PKIXValidator.doBuild:([Ljava/security/cert/X509Certificate;Ljava/util/Collection;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
            areturn
        30: .line 256
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedCerts:Ljava/util/Set;
            aload 9 /* cert */
            invokeinterface java.util.Set.contains:(Ljava/lang/Object;)Z
            ifne 36
        31: .line 257
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedSubjects:Ljava/util/Map;
            aload 10 /* dn */
            invokeinterface java.util.Map.containsKey:(Ljava/lang/Object;)Z
            ifeq 39
        32: .line 258
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedSubjects:Ljava/util/Map;
            aload 10 /* dn */
            invokeinterface java.util.Map.get:(Ljava/lang/Object;)Ljava/lang/Object;
            checkcast java.util.List
        33: .line 259
            aload 9 /* cert */
            invokevirtual java.security.cert.X509Certificate.getPublicKey:()Ljava/security/PublicKey;
        34: .line 258
            invokeinterface java.util.List.contains:(Ljava/lang/Object;)Z
        35: .line 259
            ifeq 39
        36: .line 261
      StackMap locals:
      StackMap stack:
            iload 8 /* i */
            anewarray java.security.cert.X509Certificate
            astore 11 /* newChain */
        start local 11 // java.security.cert.X509Certificate[] newChain
        37: .line 262
            aload 1 /* chain */
            iconst_0
            aload 11 /* newChain */
            iconst_0
            iload 8 /* i */
            invokestatic java.lang.System.arraycopy:(Ljava/lang/Object;ILjava/lang/Object;II)V
        38: .line 263
            aload 0 /* this */
            aload 11 /* newChain */
            aload 6 /* pkixParameters */
            invokevirtual sun.security.validator.PKIXValidator.doValidate:([Ljava/security/cert/X509Certificate;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
            areturn
        end local 11 // java.security.cert.X509Certificate[] newChain
        39: .line 266
      StackMap locals:
      StackMap stack:
            aload 9 /* cert */
            invokevirtual java.security.cert.X509Certificate.getIssuerX500Principal:()Ljavax/security/auth/x500/X500Principal;
            astore 7 /* prevIssuer */
        end local 10 // javax.security.auth.x500.X500Principal dn
        end local 9 // java.security.cert.X509Certificate cert
        40: .line 238
            iinc 8 /* i */ 1
      StackMap locals:
      StackMap stack:
        41: iload 8 /* i */
            aload 1 /* chain */
            arraylength
            if_icmplt 23
        end local 8 // int i
        42: .line 270
            aload 1 /* chain */
            aload 1 /* chain */
            arraylength
            iconst_1
            isub
            aaload
            astore 8 /* last */
        start local 8 // java.security.cert.X509Certificate last
        43: .line 271
            aload 8 /* last */
            invokevirtual java.security.cert.X509Certificate.getIssuerX500Principal:()Ljavax/security/auth/x500/X500Principal;
            astore 9 /* issuer */
        start local 9 // javax.security.auth.x500.X500Principal issuer
        44: .line 272
            aload 8 /* last */
            invokevirtual java.security.cert.X509Certificate.getSubjectX500Principal:()Ljavax/security/auth/x500/X500Principal;
            pop
        45: .line 273
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedSubjects:Ljava/util/Map;
            aload 9 /* issuer */
            invokeinterface java.util.Map.containsKey:(Ljava/lang/Object;)Z
            ifeq 48
        46: .line 274
            aload 0 /* this */
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.trustedSubjects:Ljava/util/Map;
            aload 9 /* issuer */
            invokeinterface java.util.Map.get:(Ljava/lang/Object;)Ljava/lang/Object;
            checkcast java.util.List
            aload 8 /* last */
            invokevirtual sun.security.validator.PKIXValidator.isSignatureValid:(Ljava/util/List;Ljava/security/cert/X509Certificate;)Z
            ifeq 48
        47: .line 275
            aload 0 /* this */
            aload 1 /* chain */
            aload 6 /* pkixParameters */
            invokevirtual sun.security.validator.PKIXValidator.doValidate:([Ljava/security/cert/X509Certificate;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
            areturn
        48: .line 279
      StackMap locals: sun.security.validator.PKIXValidator java.security.cert.X509Certificate[] java.util.Collection java.util.List java.security.AlgorithmConstraints java.lang.Object java.security.cert.PKIXBuilderParameters javax.security.auth.x500.X500Principal java.security.cert.X509Certificate javax.security.auth.x500.X500Principal
      StackMap stack:
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.plugin:Z
            ifeq 65
        49: .line 283
            aload 1 /* chain */
            arraylength
            iconst_1
            if_icmple 62
        50: .line 285
            aload 1 /* chain */
            arraylength
            iconst_1
            isub
            anewarray java.security.cert.X509Certificate
        51: .line 284
            astore 10 /* newChain */
        start local 10 // java.security.cert.X509Certificate[] newChain
        52: .line 286
            aload 1 /* chain */
            iconst_0
            aload 10 /* newChain */
            iconst_0
            aload 10 /* newChain */
            arraylength
            invokestatic java.lang.System.arraycopy:(Ljava/lang/Object;ILjava/lang/Object;II)V
        53: .line 290
            aload 6 /* pkixParameters */
        54: .line 291
            new java.security.cert.TrustAnchor
            dup
        55: .line 292
            aload 1 /* chain */
            aload 1 /* chain */
            arraylength
            iconst_1
            isub
            aaload
            aconst_null
        56: .line 291
            invokespecial java.security.cert.TrustAnchor.<init>:(Ljava/security/cert/X509Certificate;[B)V
            invokestatic java.util.Collections.singleton:(Ljava/lang/Object;)Ljava/util/Set;
        57: .line 290
            invokevirtual java.security.cert.PKIXBuilderParameters.setTrustAnchors:(Ljava/util/Set;)V
        58: .line 293
            goto 61
      StackMap locals: sun.security.validator.PKIXValidator java.security.cert.X509Certificate[] java.util.Collection java.util.List java.security.AlgorithmConstraints java.lang.Object java.security.cert.PKIXBuilderParameters javax.security.auth.x500.X500Principal java.security.cert.X509Certificate javax.security.auth.x500.X500Principal java.security.cert.X509Certificate[]
      StackMap stack: java.security.InvalidAlgorithmParameterException
        59: astore 11 /* iape */
        start local 11 // java.security.InvalidAlgorithmParameterException iape
        60: .line 295
            new java.security.cert.CertificateException
            dup
            aload 11 /* iape */
            invokespecial java.security.cert.CertificateException.<init>:(Ljava/lang/Throwable;)V
            athrow
        end local 11 // java.security.InvalidAlgorithmParameterException iape
        61: .line 297
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            aload 10 /* newChain */
            aload 6 /* pkixParameters */
            invokevirtual sun.security.validator.PKIXValidator.doValidate:([Ljava/security/cert/X509Certificate;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
            pop
        end local 10 // java.security.cert.X509Certificate[] newChain
        62: .line 301
      StackMap locals:
      StackMap stack:
            new sun.security.validator.ValidatorException
            dup
        63: .line 302
            getstatic sun.security.validator.ValidatorException.T_NO_TRUST_ANCHOR:Ljava/lang/Object;
        64: .line 301
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/Object;)V
            athrow
        65: .line 306
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            aload 1 /* chain */
            aload 2 /* otherCerts */
            aload 6 /* pkixParameters */
            invokevirtual sun.security.validator.PKIXValidator.doBuild:([Ljava/security/cert/X509Certificate;Ljava/util/Collection;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
            areturn
        end local 9 // javax.security.auth.x500.X500Principal issuer
        end local 8 // java.security.cert.X509Certificate last
        end local 7 // javax.security.auth.x500.X500Principal prevIssuer
        end local 6 // java.security.cert.PKIXBuilderParameters pkixParameters
        end local 5 // java.lang.Object parameter
        end local 4 // java.security.AlgorithmConstraints constraints
        end local 3 // java.util.List responseList
        end local 2 // java.util.Collection otherCerts
        end local 1 // java.security.cert.X509Certificate[] chain
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot            Name  Signature
            0   66     0            this  Lsun/security/validator/PKIXValidator;
            0   66     1           chain  [Ljava/security/cert/X509Certificate;
            0   66     2      otherCerts  Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;
            0   66     3    responseList  Ljava/util/List<[B>;
            0   66     4     constraints  Ljava/security/AlgorithmConstraints;
            0   66     5       parameter  Ljava/lang/Object;
            5   66     6  pkixParameters  Ljava/security/cert/PKIXBuilderParameters;
           21   66     7      prevIssuer  Ljavax/security/auth/x500/X500Principal;
           22   42     8               i  I
           24   40     9            cert  Ljava/security/cert/X509Certificate;
           25   40    10              dn  Ljavax/security/auth/x500/X500Principal;
           37   39    11        newChain  [Ljava/security/cert/X509Certificate;
           43   66     8            last  Ljava/security/cert/X509Certificate;
           44   66     9          issuer  Ljavax/security/auth/x500/X500Principal;
           52   62    10        newChain  [Ljava/security/cert/X509Certificate;
           60   61    11            iape  Ljava/security/InvalidAlgorithmParameterException;
      Exception table:
        from    to  target  type
           5    12      13  Class java.security.InvalidAlgorithmParameterException
          53    58      59  Class java.security.InvalidAlgorithmParameterException
    Exceptions:
      throws java.security.cert.CertificateException
    Signature: ([Ljava/security/cert/X509Certificate;Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;Ljava/util/List<[B>;Ljava/security/AlgorithmConstraints;Ljava/lang/Object;)[Ljava/security/cert/X509Certificate;
    MethodParameters:
              Name  Flags
      chain         
      otherCerts    
      responseList  
      constraints   
      parameter     

  private boolean isSignatureValid(java.util.List<java.security.PublicKey>, java.security.cert.X509Certificate);
    descriptor: (Ljava/util/List;Ljava/security/cert/X509Certificate;)Z
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=2, locals=5, args_size=3
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.util.List keys
        start local 2 // java.security.cert.X509Certificate sub
         0: .line 311
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.plugin:Z
            ifeq 8
         1: .line 312
            aload 1 /* keys */
            invokeinterface java.util.List.iterator:()Ljava/util/Iterator;
            astore 4
            goto 6
      StackMap locals: sun.security.validator.PKIXValidator java.util.List java.security.cert.X509Certificate top java.util.Iterator
      StackMap stack:
         2: aload 4
            invokeinterface java.util.Iterator.next:()Ljava/lang/Object;
            checkcast java.security.PublicKey
            astore 3 /* key */
        start local 3 // java.security.PublicKey key
         3: .line 314
            aload 2 /* sub */
            aload 3 /* key */
            invokevirtual java.security.cert.X509Certificate.verify:(Ljava/security/PublicKey;)V
         4: .line 315
            iconst_1
            ireturn
         5: .line 316
      StackMap locals: sun.security.validator.PKIXValidator java.util.List java.security.cert.X509Certificate java.security.PublicKey java.util.Iterator
      StackMap stack: java.lang.Exception
            pop
        end local 3 // java.security.PublicKey key
         6: .line 312
      StackMap locals: sun.security.validator.PKIXValidator java.util.List java.security.cert.X509Certificate top java.util.Iterator
      StackMap stack:
            aload 4
            invokeinterface java.util.Iterator.hasNext:()Z
            ifne 2
         7: .line 320
            iconst_0
            ireturn
         8: .line 322
      StackMap locals: sun.security.validator.PKIXValidator java.util.List java.security.cert.X509Certificate
      StackMap stack:
            iconst_1
            ireturn
        end local 2 // java.security.cert.X509Certificate sub
        end local 1 // java.util.List keys
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0    9     0  this  Lsun/security/validator/PKIXValidator;
            0    9     1  keys  Ljava/util/List<Ljava/security/PublicKey;>;
            0    9     2   sub  Ljava/security/cert/X509Certificate;
            3    6     3   key  Ljava/security/PublicKey;
      Exception table:
        from    to  target  type
           3     4       5  Class java.lang.Exception
    Signature: (Ljava/util/List<Ljava/security/PublicKey;>;Ljava/security/cert/X509Certificate;)Z
    MethodParameters:
      Name  Flags
      keys  
      sub   

  private static java.security.cert.X509Certificate[] toArray(java.security.cert.CertPath, java.security.cert.TrustAnchor);
    descriptor: (Ljava/security/cert/CertPath;Ljava/security/cert/TrustAnchor;)[Ljava/security/cert/X509Certificate;
    flags: (0x000a) ACC_PRIVATE, ACC_STATIC
    Code:
      stack=3, locals=5, args_size=2
        start local 0 // java.security.cert.CertPath path
        start local 1 // java.security.cert.TrustAnchor anchor
         0: .line 327
            aload 1 /* anchor */
            invokevirtual java.security.cert.TrustAnchor.getTrustedCert:()Ljava/security/cert/X509Certificate;
            astore 2 /* trustedCert */
        start local 2 // java.security.cert.X509Certificate trustedCert
         1: .line 328
            aload 2 /* trustedCert */
            ifnonnull 5
         2: .line 329
            new sun.security.validator.ValidatorException
            dup
         3: .line 330
            ldc "TrustAnchor must be specified as certificate"
         4: .line 329
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;)V
            athrow
         5: .line 333
      StackMap locals: java.security.cert.X509Certificate
      StackMap stack:
            aload 2 /* trustedCert */
            invokestatic sun.security.validator.PKIXValidator.verifyTrustAnchor:(Ljava/security/cert/X509Certificate;)V
         6: .line 336
            aload 0 /* path */
            invokevirtual java.security.cert.CertPath.getCertificates:()Ljava/util/List;
         7: .line 335
            astore 3 /* list */
        start local 3 // java.util.List list
         8: .line 337
            aload 3 /* list */
            invokeinterface java.util.List.size:()I
            iconst_1
            iadd
            anewarray java.security.cert.X509Certificate
            astore 4 /* chain */
        start local 4 // java.security.cert.X509Certificate[] chain
         9: .line 338
            aload 3 /* list */
            aload 4 /* chain */
            invokeinterface java.util.List.toArray:([Ljava/lang/Object;)[Ljava/lang/Object;
            pop
        10: .line 339
            aload 4 /* chain */
            aload 4 /* chain */
            arraylength
            iconst_1
            isub
            aload 2 /* trustedCert */
            aastore
        11: .line 340
            aload 4 /* chain */
            areturn
        end local 4 // java.security.cert.X509Certificate[] chain
        end local 3 // java.util.List list
        end local 2 // java.security.cert.X509Certificate trustedCert
        end local 1 // java.security.cert.TrustAnchor anchor
        end local 0 // java.security.cert.CertPath path
      LocalVariableTable:
        Start  End  Slot         Name  Signature
            0   12     0         path  Ljava/security/cert/CertPath;
            0   12     1       anchor  Ljava/security/cert/TrustAnchor;
            1   12     2  trustedCert  Ljava/security/cert/X509Certificate;
            8   12     3         list  Ljava/util/List<+Ljava/security/cert/Certificate;>;
            9   12     4        chain  [Ljava/security/cert/X509Certificate;
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
        Name  Flags
      path    
      anchor  

  private void setDate(java.security.cert.PKIXBuilderParameters);
    descriptor: (Ljava/security/cert/PKIXBuilderParameters;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=2, locals=3, args_size=2
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.security.cert.PKIXBuilderParameters params
         0: .line 348
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.validationDate:Ljava/util/Date;
            astore 2 /* date */
        start local 2 // java.util.Date date
         1: .line 349
            aload 2 /* date */
            ifnull 3
         2: .line 350
            aload 1 /* params */
            aload 2 /* date */
            invokevirtual java.security.cert.PKIXBuilderParameters.setDate:(Ljava/util/Date;)V
         3: .line 352
      StackMap locals: java.util.Date
      StackMap stack:
            return
        end local 2 // java.util.Date date
        end local 1 // java.security.cert.PKIXBuilderParameters params
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot    Name  Signature
            0    4     0    this  Lsun/security/validator/PKIXValidator;
            0    4     1  params  Ljava/security/cert/PKIXBuilderParameters;
            1    4     2    date  Ljava/util/Date;
    MethodParameters:
        Name  Flags
      params  

  private java.security.cert.X509Certificate[] doValidate(java.security.cert.X509Certificate[], java.security.cert.PKIXBuilderParameters);
    descriptor: ([Ljava/security/cert/X509Certificate;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=5, locals=6, args_size=3
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.security.cert.X509Certificate[] chain
        start local 2 // java.security.cert.PKIXBuilderParameters params
         0: .line 357
            aload 0 /* this */
            aload 2 /* params */
            invokevirtual sun.security.validator.PKIXValidator.setDate:(Ljava/security/cert/PKIXBuilderParameters;)V
         1: .line 360
            ldc "PKIX"
            invokestatic java.security.cert.CertPathValidator.getInstance:(Ljava/lang/String;)Ljava/security/cert/CertPathValidator;
            astore 3 /* validator */
        start local 3 // java.security.cert.CertPathValidator validator
         2: .line 361
            aload 0 /* this */
            getfield sun.security.validator.PKIXValidator.factory:Ljava/security/cert/CertificateFactory;
            aload 1 /* chain */
            invokestatic java.util.Arrays.asList:([Ljava/lang/Object;)Ljava/util/List;
            invokevirtual java.security.cert.CertificateFactory.generateCertPath:(Ljava/util/List;)Ljava/security/cert/CertPath;
            astore 4 /* path */
        start local 4 // java.security.cert.CertPath path
         3: .line 362
            aload 0 /* this */
            aload 1 /* chain */
            arraylength
            putfield sun.security.validator.PKIXValidator.certPathLength:I
         4: .line 364
            aload 3 /* validator */
            aload 4 /* path */
            aload 2 /* params */
            invokevirtual java.security.cert.CertPathValidator.validate:(Ljava/security/cert/CertPath;Ljava/security/cert/CertPathParameters;)Ljava/security/cert/CertPathValidatorResult;
            checkcast java.security.cert.PKIXCertPathValidatorResult
         5: .line 363
            astore 5 /* result */
        start local 5 // java.security.cert.PKIXCertPathValidatorResult result
         6: .line 366
            aload 4 /* path */
            aload 5 /* result */
            invokevirtual java.security.cert.PKIXCertPathValidatorResult.getTrustAnchor:()Ljava/security/cert/TrustAnchor;
            invokestatic sun.security.validator.PKIXValidator.toArray:(Ljava/security/cert/CertPath;Ljava/security/cert/TrustAnchor;)[Ljava/security/cert/X509Certificate;
         7: areturn
        end local 5 // java.security.cert.PKIXCertPathValidatorResult result
        end local 4 // java.security.cert.CertPath path
        end local 3 // java.security.cert.CertPathValidator validator
         8: .line 367
      StackMap locals:
      StackMap stack: java.security.GeneralSecurityException
            astore 3 /* e */
        start local 3 // java.security.GeneralSecurityException e
         9: .line 368
            new sun.security.validator.ValidatorException
            dup
        10: .line 369
            new java.lang.StringBuilder
            dup
            ldc "PKIX path validation failed: "
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
            aload 3 /* e */
            invokevirtual java.security.GeneralSecurityException.toString:()Ljava/lang/String;
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/String;)Ljava/lang/StringBuilder;
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
            aload 3 /* e */
        11: .line 368
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Throwable;)V
            athrow
        end local 3 // java.security.GeneralSecurityException e
        end local 2 // java.security.cert.PKIXBuilderParameters params
        end local 1 // java.security.cert.X509Certificate[] chain
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot       Name  Signature
            0   12     0       this  Lsun/security/validator/PKIXValidator;
            0   12     1      chain  [Ljava/security/cert/X509Certificate;
            0   12     2     params  Ljava/security/cert/PKIXBuilderParameters;
            2    8     3  validator  Ljava/security/cert/CertPathValidator;
            3    8     4       path  Ljava/security/cert/CertPath;
            6    8     5     result  Ljava/security/cert/PKIXCertPathValidatorResult;
            9   12     3          e  Ljava/security/GeneralSecurityException;
      Exception table:
        from    to  target  type
           0     7       8  Class java.security.GeneralSecurityException
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
        Name  Flags
      chain   
      params  

  private static void verifyTrustAnchor(java.security.cert.X509Certificate);
    descriptor: (Ljava/security/cert/X509Certificate;)V
    flags: (0x000a) ACC_PRIVATE, ACC_STATIC
    Code:
      stack=5, locals=2, args_size=1
        start local 0 // java.security.cert.X509Certificate trustedCert
         0: .line 380
            getstatic sun.security.validator.PKIXValidator.ALLOW_NON_CA_ANCHOR:Z
            ifeq 2
         1: .line 381
            return
         2: .line 385
      StackMap locals:
      StackMap stack:
            aload 0 /* trustedCert */
            invokevirtual java.security.cert.X509Certificate.getVersion:()I
            iconst_3
            if_icmpge 4
         3: .line 386
            return
         4: .line 390
      StackMap locals:
      StackMap stack:
            aload 0 /* trustedCert */
            invokevirtual java.security.cert.X509Certificate.getBasicConstraints:()I
            iconst_m1
            if_icmpne 11
         5: .line 391
            new sun.security.validator.ValidatorException
            dup
         6: .line 392
            new java.lang.StringBuilder
            dup
            ldc "TrustAnchor with subject \""
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
         7: .line 393
            aload 0 /* trustedCert */
            invokevirtual java.security.cert.X509Certificate.getSubjectX500Principal:()Ljavax/security/auth/x500/X500Principal;
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/Object;)Ljava/lang/StringBuilder;
         8: .line 394
            ldc "\" is not a CA certificate"
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/String;)Ljava/lang/StringBuilder;
         9: .line 392
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
        10: .line 391
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;)V
            athrow
        11: .line 399
      StackMap locals:
      StackMap stack:
            aload 0 /* trustedCert */
            invokevirtual java.security.cert.X509Certificate.getKeyUsage:()[Z
            astore 1 /* keyUsageBits */
        start local 1 // boolean[] keyUsageBits
        12: .line 400
            aload 1 /* keyUsageBits */
            ifnull 19
            aload 1 /* keyUsageBits */
            iconst_5
            baload
            ifne 19
        13: .line 401
            new sun.security.validator.ValidatorException
            dup
        14: .line 402
            new java.lang.StringBuilder
            dup
            ldc "TrustAnchor with subject \""
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
        15: .line 403
            aload 0 /* trustedCert */
            invokevirtual java.security.cert.X509Certificate.getSubjectX500Principal:()Ljavax/security/auth/x500/X500Principal;
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/Object;)Ljava/lang/StringBuilder;
        16: .line 404
            ldc "\" does not have keyCertSign bit set in KeyUsage extension"
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/String;)Ljava/lang/StringBuilder;
        17: .line 402
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
        18: .line 401
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;)V
            athrow
        19: .line 406
      StackMap locals: boolean[]
      StackMap stack:
            return
        end local 1 // boolean[] keyUsageBits
        end local 0 // java.security.cert.X509Certificate trustedCert
      LocalVariableTable:
        Start  End  Slot          Name  Signature
            0   20     0   trustedCert  Ljava/security/cert/X509Certificate;
           12   20     1  keyUsageBits  [Z
    Exceptions:
      throws sun.security.validator.ValidatorException
    MethodParameters:
             Name  Flags
      trustedCert  

  private java.security.cert.X509Certificate[] doBuild(java.security.cert.X509Certificate[], java.util.Collection<java.security.cert.X509Certificate>, java.security.cert.PKIXBuilderParameters);
    descriptor: ([Ljava/security/cert/X509Certificate;Ljava/util/Collection;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=5, locals=9, args_size=4
        start local 0 // sun.security.validator.PKIXValidator this
        start local 1 // java.security.cert.X509Certificate[] chain
        start local 2 // java.util.Collection otherCerts
        start local 3 // java.security.cert.PKIXBuilderParameters params
         0: .line 413
            aload 0 /* this */
            aload 3 /* params */
            invokevirtual sun.security.validator.PKIXValidator.setDate:(Ljava/security/cert/PKIXBuilderParameters;)V
         1: .line 416
            new java.security.cert.X509CertSelector
            dup
            invokespecial java.security.cert.X509CertSelector.<init>:()V
            astore 4 /* selector */
        start local 4 // java.security.cert.X509CertSelector selector
         2: .line 417
            aload 4 /* selector */
            aload 1 /* chain */
            iconst_0
            aaload
            invokevirtual java.security.cert.X509CertSelector.setCertificate:(Ljava/security/cert/X509Certificate;)V
         3: .line 418
            aload 3 /* params */
            aload 4 /* selector */
            invokevirtual java.security.cert.PKIXBuilderParameters.setTargetCertConstraints:(Ljava/security/cert/CertSelector;)V
         4: .line 422
            new java.util.ArrayList
            dup
            invokespecial java.util.ArrayList.<init>:()V
         5: .line 421
            astore 5 /* certs */
        start local 5 // java.util.Collection certs
         6: .line 423
            aload 5 /* certs */
            aload 1 /* chain */
            invokestatic java.util.Arrays.asList:([Ljava/lang/Object;)Ljava/util/List;
            invokeinterface java.util.Collection.addAll:(Ljava/util/Collection;)Z
            pop
         7: .line 424
            aload 2 /* otherCerts */
            ifnull 9
         8: .line 425
            aload 5 /* certs */
            aload 2 /* otherCerts */
            invokeinterface java.util.Collection.addAll:(Ljava/util/Collection;)Z
            pop
         9: .line 427
      StackMap locals: java.security.cert.X509CertSelector java.util.Collection
      StackMap stack:
            ldc "Collection"
        10: .line 428
            new java.security.cert.CollectionCertStoreParameters
            dup
            aload 5 /* certs */
            invokespecial java.security.cert.CollectionCertStoreParameters.<init>:(Ljava/util/Collection;)V
        11: .line 427
            invokestatic java.security.cert.CertStore.getInstance:(Ljava/lang/String;Ljava/security/cert/CertStoreParameters;)Ljava/security/cert/CertStore;
            astore 6 /* store */
        start local 6 // java.security.cert.CertStore store
        12: .line 429
            aload 3 /* params */
            aload 6 /* store */
            invokevirtual java.security.cert.PKIXBuilderParameters.addCertStore:(Ljava/security/cert/CertStore;)V
        13: .line 432
            ldc "PKIX"
            invokestatic java.security.cert.CertPathBuilder.getInstance:(Ljava/lang/String;)Ljava/security/cert/CertPathBuilder;
            astore 7 /* builder */
        start local 7 // java.security.cert.CertPathBuilder builder
        14: .line 434
            aload 7 /* builder */
            aload 3 /* params */
            invokevirtual java.security.cert.CertPathBuilder.build:(Ljava/security/cert/CertPathParameters;)Ljava/security/cert/CertPathBuilderResult;
            checkcast java.security.cert.PKIXCertPathBuilderResult
        15: .line 433
            astore 8 /* result */
        start local 8 // java.security.cert.PKIXCertPathBuilderResult result
        16: .line 436
            aload 8 /* result */
            invokevirtual java.security.cert.PKIXCertPathBuilderResult.getCertPath:()Ljava/security/cert/CertPath;
            aload 8 /* result */
            invokevirtual java.security.cert.PKIXCertPathBuilderResult.getTrustAnchor:()Ljava/security/cert/TrustAnchor;
            invokestatic sun.security.validator.PKIXValidator.toArray:(Ljava/security/cert/CertPath;Ljava/security/cert/TrustAnchor;)[Ljava/security/cert/X509Certificate;
        17: areturn
        end local 8 // java.security.cert.PKIXCertPathBuilderResult result
        end local 7 // java.security.cert.CertPathBuilder builder
        end local 6 // java.security.cert.CertStore store
        end local 5 // java.util.Collection certs
        end local 4 // java.security.cert.X509CertSelector selector
        18: .line 437
      StackMap locals: sun.security.validator.PKIXValidator java.security.cert.X509Certificate[] java.util.Collection java.security.cert.PKIXBuilderParameters
      StackMap stack: java.security.GeneralSecurityException
            astore 4 /* e */
        start local 4 // java.security.GeneralSecurityException e
        19: .line 438
            new sun.security.validator.ValidatorException
            dup
        20: .line 439
            new java.lang.StringBuilder
            dup
            ldc "PKIX path building failed: "
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
            aload 4 /* e */
            invokevirtual java.security.GeneralSecurityException.toString:()Ljava/lang/String;
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/String;)Ljava/lang/StringBuilder;
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
            aload 4 /* e */
        21: .line 438
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Throwable;)V
            athrow
        end local 4 // java.security.GeneralSecurityException e
        end local 3 // java.security.cert.PKIXBuilderParameters params
        end local 2 // java.util.Collection otherCerts
        end local 1 // java.security.cert.X509Certificate[] chain
        end local 0 // sun.security.validator.PKIXValidator this
      LocalVariableTable:
        Start  End  Slot        Name  Signature
            0   22     0        this  Lsun/security/validator/PKIXValidator;
            0   22     1       chain  [Ljava/security/cert/X509Certificate;
            0   22     2  otherCerts  Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;
            0   22     3      params  Ljava/security/cert/PKIXBuilderParameters;
            2   18     4    selector  Ljava/security/cert/X509CertSelector;
            6   18     5       certs  Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;
           12   18     6       store  Ljava/security/cert/CertStore;
           14   18     7     builder  Ljava/security/cert/CertPathBuilder;
           16   18     8      result  Ljava/security/cert/PKIXCertPathBuilderResult;
           19   22     4           e  Ljava/security/GeneralSecurityException;
      Exception table:
        from    to  target  type
           0    17      18  Class java.security.GeneralSecurityException
    Exceptions:
      throws java.security.cert.CertificateException
    Signature: ([Ljava/security/cert/X509Certificate;Ljava/util/Collection<Ljava/security/cert/X509Certificate;>;Ljava/security/cert/PKIXBuilderParameters;)[Ljava/security/cert/X509Certificate;
    MethodParameters:
            Name  Flags
      chain       
      otherCerts  
      params      

  private static void addResponses(java.security.cert.PKIXBuilderParameters, java.security.cert.X509Certificate[], java.util.List<byte[]>);
    descriptor: (Ljava/security/cert/PKIXBuilderParameters;[Ljava/security/cert/X509Certificate;Ljava/util/List;)V
    flags: (0x000a) ACC_PRIVATE, ACC_STATIC
    Code:
      stack=3, locals=10, args_size=3
        start local 0 // java.security.cert.PKIXBuilderParameters pkixParams
        start local 1 // java.security.cert.X509Certificate[] chain
        start local 2 // java.util.List responseList
         0: .line 458
            iconst_0
            istore 3 /* createdRevChk */
        start local 3 // boolean createdRevChk
         1: .line 461
            aconst_null
            astore 4 /* revChecker */
        start local 4 // java.security.cert.PKIXRevocationChecker revChecker
         2: .line 463
            aload 0 /* pkixParams */
            invokevirtual java.security.cert.PKIXBuilderParameters.getCertPathCheckers:()Ljava/util/List;
         3: .line 462
            astore 5 /* checkerList */
        start local 5 // java.util.List checkerList
         4: .line 466
            aload 5 /* checkerList */
            invokeinterface java.util.List.iterator:()Ljava/util/Iterator;
            astore 7
            goto 9
      StackMap locals: java.security.cert.PKIXBuilderParameters java.security.cert.X509Certificate[] java.util.List int java.security.cert.PKIXRevocationChecker java.util.List top java.util.Iterator
      StackMap stack:
         5: aload 7
            invokeinterface java.util.Iterator.next:()Ljava/lang/Object;
            checkcast java.security.cert.PKIXCertPathChecker
            astore 6 /* checker */
        start local 6 // java.security.cert.PKIXCertPathChecker checker
         6: .line 467
            aload 6 /* checker */
            instanceof java.security.cert.PKIXRevocationChecker
            ifeq 9
         7: .line 468
            aload 6 /* checker */
            checkcast java.security.cert.PKIXRevocationChecker
            astore 4 /* revChecker */
         8: .line 469
            goto 10
        end local 6 // java.security.cert.PKIXCertPathChecker checker
         9: .line 466
      StackMap locals:
      StackMap stack:
            aload 7
            invokeinterface java.util.Iterator.hasNext:()Z
            ifne 5
        10: .line 479
      StackMap locals: java.security.cert.PKIXBuilderParameters java.security.cert.X509Certificate[] java.util.List int java.security.cert.PKIXRevocationChecker java.util.List
      StackMap stack:
            aload 4 /* revChecker */
            ifnonnull 17
        11: .line 480
            aload 0 /* pkixParams */
            invokevirtual java.security.cert.PKIXBuilderParameters.isRevocationEnabled:()Z
            ifeq 16
        12: .line 482
            ldc "PKIX"
            invokestatic java.security.cert.CertPathValidator.getInstance:(Ljava/lang/String;)Ljava/security/cert/CertPathValidator;
            invokevirtual java.security.cert.CertPathValidator.getRevocationChecker:()Ljava/security/cert/CertPathChecker;
        13: .line 481
            checkcast java.security.cert.PKIXRevocationChecker
            astore 4 /* revChecker */
        14: .line 483
            iconst_1
            istore 3 /* createdRevChk */
        15: .line 484
            goto 17
        16: .line 485
      StackMap locals:
      StackMap stack:
            return
        17: .line 495
      StackMap locals:
      StackMap stack:
            aload 4 /* revChecker */
            invokevirtual java.security.cert.PKIXRevocationChecker.getOcspResponses:()Ljava/util/Map;
        18: .line 494
            astore 6 /* responseMap */
        start local 6 // java.util.Map responseMap
        19: .line 496
            aload 1 /* chain */
            arraylength
            aload 2 /* responseList */
            invokeinterface java.util.List.size:()I
            invokestatic java.lang.Integer.min:(II)I
            istore 7 /* limit */
        start local 7 // int limit
        20: .line 497
            iconst_0
            istore 8 /* idx */
        start local 8 // int idx
        21: goto 27
        22: .line 498
      StackMap locals: java.util.Map int int
      StackMap stack:
            aload 2 /* responseList */
            iload 8 /* idx */
            invokeinterface java.util.List.get:(I)Ljava/lang/Object;
            checkcast byte[]
            astore 9 /* respBytes */
        start local 9 // byte[] respBytes
        23: .line 499
            aload 9 /* respBytes */
            ifnull 26
            aload 9 /* respBytes */
            arraylength
            ifle 26
        24: .line 500
            aload 6 /* responseMap */
            aload 1 /* chain */
            iload 8 /* idx */
            aaload
            invokeinterface java.util.Map.containsKey:(Ljava/lang/Object;)Z
            ifne 26
        25: .line 501
            aload 6 /* responseMap */
            aload 1 /* chain */
            iload 8 /* idx */
            aaload
            aload 9 /* respBytes */
            invokeinterface java.util.Map.put:(Ljava/lang/Object;Ljava/lang/Object;)Ljava/lang/Object;
            pop
        end local 9 // byte[] respBytes
        26: .line 497
      StackMap locals:
      StackMap stack:
            iinc 8 /* idx */ 1
      StackMap locals:
      StackMap stack:
        27: iload 8 /* idx */
            iload 7 /* limit */
            if_icmplt 22
        end local 8 // int idx
        28: .line 504
            aload 4 /* revChecker */
            aload 6 /* responseMap */
            invokevirtual java.security.cert.PKIXRevocationChecker.setOcspResponses:(Ljava/util/Map;)V
        29: .line 508
            iload 3 /* createdRevChk */
            ifeq 32
        30: .line 509
            aload 0 /* pkixParams */
            aload 4 /* revChecker */
            invokevirtual java.security.cert.PKIXBuilderParameters.addCertPathChecker:(Ljava/security/cert/PKIXCertPathChecker;)V
        31: .line 510
            goto 35
        32: .line 511
      StackMap locals:
      StackMap stack:
            aload 0 /* pkixParams */
            aload 5 /* checkerList */
            invokevirtual java.security.cert.PKIXBuilderParameters.setCertPathCheckers:(Ljava/util/List;)V
        end local 7 // int limit
        end local 6 // java.util.Map responseMap
        end local 5 // java.util.List checkerList
        end local 4 // java.security.cert.PKIXRevocationChecker revChecker
        end local 3 // boolean createdRevChk
        33: .line 513
            goto 35
      StackMap locals: java.security.cert.PKIXBuilderParameters java.security.cert.X509Certificate[] java.util.List
      StackMap stack: java.security.NoSuchAlgorithmException
        34: pop
        35: .line 519
      StackMap locals:
      StackMap stack:
            return
        end local 2 // java.util.List responseList
        end local 1 // java.security.cert.X509Certificate[] chain
        end local 0 // java.security.cert.PKIXBuilderParameters pkixParams
      LocalVariableTable:
        Start  End  Slot           Name  Signature
            0   36     0     pkixParams  Ljava/security/cert/PKIXBuilderParameters;
            0   36     1          chain  [Ljava/security/cert/X509Certificate;
            0   36     2   responseList  Ljava/util/List<[B>;
            1   33     3  createdRevChk  Z
            2   33     4     revChecker  Ljava/security/cert/PKIXRevocationChecker;
            4   33     5    checkerList  Ljava/util/List<Ljava/security/cert/PKIXCertPathChecker;>;
            6    9     6        checker  Ljava/security/cert/PKIXCertPathChecker;
           19   33     6    responseMap  Ljava/util/Map<Ljava/security/cert/X509Certificate;[B>;
           20   33     7          limit  I
           21   28     8            idx  I
           23   26     9      respBytes  [B
      Exception table:
        from    to  target  type
           0    16      34  Class java.security.NoSuchAlgorithmException
          17    33      34  Class java.security.NoSuchAlgorithmException
    Signature: (Ljava/security/cert/PKIXBuilderParameters;[Ljava/security/cert/X509Certificate;Ljava/util/List<[B>;)V
    MethodParameters:
              Name  Flags
      pkixParams    
      chain         
      responseList  
}
SourceFile: "PKIXValidator.java"