class sun.security.validator.EndEntityChecker
  minor version: 0
  major version: 59
  flags: flags: (0x0020) ACC_SUPER
  this_class: sun.security.validator.EndEntityChecker
  super_class: java.lang.Object
{
  private static final java.lang.String OID_EXTENDED_KEY_USAGE;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "2.5.29.37"

  private static final java.lang.String OID_EKU_TLS_SERVER;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "1.3.6.1.5.5.7.3.1"

  private static final java.lang.String OID_EKU_TLS_CLIENT;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "1.3.6.1.5.5.7.3.2"

  private static final java.lang.String OID_EKU_CODE_SIGNING;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "1.3.6.1.5.5.7.3.3"

  private static final java.lang.String OID_EKU_TIME_STAMPING;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "1.3.6.1.5.5.7.3.8"

  private static final java.lang.String OID_EKU_ANY_USAGE;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "2.5.29.37.0"

  private static final java.lang.String OID_EKU_NS_SGC;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "2.16.840.1.113730.4.1"

  private static final java.lang.String OID_EKU_MS_SGC;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "1.3.6.1.4.1.311.10.3.3"

  private static final java.lang.String OID_SUBJECT_ALT_NAME;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "2.5.29.17"

  private static final java.lang.String NSCT_SSL_CLIENT;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "ssl_client"

  private static final java.lang.String NSCT_SSL_SERVER;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "ssl_server"

  private static final java.lang.String NSCT_CODE_SIGNING;
    descriptor: Ljava/lang/String;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: "object_signing"

  private static final int KU_SIGNATURE;
    descriptor: I
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: 0

  private static final int KU_KEY_ENCIPHERMENT;
    descriptor: I
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: 2

  private static final int KU_KEY_AGREEMENT;
    descriptor: I
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    ConstantValue: 4

  private static final java.util.Collection<java.lang.String> KU_SERVER_SIGNATURE;
    descriptor: Ljava/util/Collection;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    Signature: Ljava/util/Collection<Ljava/lang/String;>;

  private static final java.util.Collection<java.lang.String> KU_SERVER_ENCRYPTION;
    descriptor: Ljava/util/Collection;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    Signature: Ljava/util/Collection<Ljava/lang/String;>;

  private static final java.util.Collection<java.lang.String> KU_SERVER_KEY_AGREEMENT;
    descriptor: Ljava/util/Collection;
    flags: (0x001a) ACC_PRIVATE, ACC_STATIC, ACC_FINAL
    Signature: Ljava/util/Collection<Ljava/lang/String;>;

  private final java.lang.String variant;
    descriptor: Ljava/lang/String;
    flags: (0x0012) ACC_PRIVATE, ACC_FINAL

  private final java.lang.String type;
    descriptor: Ljava/lang/String;
    flags: (0x0012) ACC_PRIVATE, ACC_FINAL

  static void <clinit>();
    descriptor: ()V
    flags: (0x0008) ACC_STATIC
    Code:
      stack=4, locals=0, args_size=0
         0: .line 108
            bipush 6
            anewarray java.lang.String
            dup
            iconst_0
         1: .line 109
            ldc "DHE_DSS"
            aastore
            dup
            iconst_1
            ldc "DHE_RSA"
            aastore
            dup
            iconst_2
            ldc "ECDHE_ECDSA"
            aastore
            dup
            iconst_3
            ldc "ECDHE_RSA"
            aastore
            dup
            iconst_4
         2: .line 110
            ldc "RSA_EXPORT"
            aastore
            dup
            iconst_5
            ldc "UNKNOWN"
            aastore
         3: .line 109
            invokestatic java.util.Arrays.asList:([Ljava/lang/Object;)Ljava/util/List;
            putstatic sun.security.validator.EndEntityChecker.KU_SERVER_SIGNATURE:Ljava/util/Collection;
         4: .line 113
            iconst_1
            anewarray java.lang.String
            dup
            iconst_0
         5: .line 114
            ldc "RSA"
            aastore
            invokestatic java.util.Arrays.asList:([Ljava/lang/Object;)Ljava/util/List;
            putstatic sun.security.validator.EndEntityChecker.KU_SERVER_ENCRYPTION:Ljava/util/Collection;
         6: .line 117
            iconst_4
            anewarray java.lang.String
            dup
            iconst_0
         7: .line 118
            ldc "DH_DSS"
            aastore
            dup
            iconst_1
            ldc "DH_RSA"
            aastore
            dup
            iconst_2
            ldc "ECDH_ECDSA"
            aastore
            dup
            iconst_3
            ldc "ECDH_RSA"
            aastore
            invokestatic java.util.Arrays.asList:([Ljava/lang/Object;)Ljava/util/List;
            putstatic sun.security.validator.EndEntityChecker.KU_SERVER_KEY_AGREEMENT:Ljava/util/Collection;
            return
      LocalVariableTable:
        Start  End  Slot  Name  Signature

  private void <init>(java.lang.String, java.lang.String);
    descriptor: (Ljava/lang/String;Ljava/lang/String;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=2, locals=3, args_size=3
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.lang.String type
        start local 2 // java.lang.String variant
         0: .line 126
            aload 0 /* this */
            invokespecial java.lang.Object.<init>:()V
         1: .line 127
            aload 0 /* this */
            aload 1 /* type */
            putfield sun.security.validator.EndEntityChecker.type:Ljava/lang/String;
         2: .line 128
            aload 0 /* this */
            aload 2 /* variant */
            putfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
         3: .line 129
            return
        end local 2 // java.lang.String variant
        end local 1 // java.lang.String type
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot     Name  Signature
            0    4     0     this  Lsun/security/validator/EndEntityChecker;
            0    4     1     type  Ljava/lang/String;
            0    4     2  variant  Ljava/lang/String;
    MethodParameters:
         Name  Flags
      type     
      variant  

  static sun.security.validator.EndEntityChecker getInstance(java.lang.String, java.lang.String);
    descriptor: (Ljava/lang/String;Ljava/lang/String;)Lsun/security/validator/EndEntityChecker;
    flags: (0x0008) ACC_STATIC
    Code:
      stack=4, locals=2, args_size=2
        start local 0 // java.lang.String type
        start local 1 // java.lang.String variant
         0: .line 132
            new sun.security.validator.EndEntityChecker
            dup
            aload 0 /* type */
            aload 1 /* variant */
            invokespecial sun.security.validator.EndEntityChecker.<init>:(Ljava/lang/String;Ljava/lang/String;)V
            areturn
        end local 1 // java.lang.String variant
        end local 0 // java.lang.String type
      LocalVariableTable:
        Start  End  Slot     Name  Signature
            0    1     0     type  Ljava/lang/String;
            0    1     1  variant  Ljava/lang/String;
    MethodParameters:
         Name  Flags
      type     
      variant  

  void check(java.security.cert.X509Certificate, java.lang.Object);
    descriptor: (Ljava/security/cert/X509Certificate;Ljava/lang/Object;)V
    flags: (0x0000) 
    Code:
      stack=5, locals=3, args_size=3
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
        start local 2 // java.lang.Object parameter
         0: .line 137
            aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "generic"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifeq 2
         1: .line 139
            return
         2: .line 140
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "tls server"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifeq 5
         3: .line 141
            aload 0 /* this */
            aload 1 /* cert */
            aload 2 /* parameter */
            checkcast java.lang.String
            invokevirtual sun.security.validator.EndEntityChecker.checkTLSServer:(Ljava/security/cert/X509Certificate;Ljava/lang/String;)V
         4: .line 142
            goto 21
      StackMap locals:
      StackMap stack:
         5: aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "tls client"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifeq 8
         6: .line 143
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.checkTLSClient:(Ljava/security/cert/X509Certificate;)V
         7: .line 144
            goto 21
      StackMap locals:
      StackMap stack:
         8: aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "code signing"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifeq 11
         9: .line 145
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.checkCodeSigning:(Ljava/security/cert/X509Certificate;)V
        10: .line 146
            goto 21
      StackMap locals:
      StackMap stack:
        11: aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "jce signing"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifeq 14
        12: .line 147
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.checkCodeSigning:(Ljava/security/cert/X509Certificate;)V
        13: .line 148
            goto 21
      StackMap locals:
      StackMap stack:
        14: aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "plugin code signing"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifeq 17
        15: .line 149
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.checkCodeSigning:(Ljava/security/cert/X509Certificate;)V
        16: .line 150
            goto 21
      StackMap locals:
      StackMap stack:
        17: aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "tsa server"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifeq 20
        18: .line 151
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.checkTSAServer:(Ljava/security/cert/X509Certificate;)V
        19: .line 152
            goto 21
        20: .line 153
      StackMap locals:
      StackMap stack:
            new java.security.cert.CertificateException
            dup
            new java.lang.StringBuilder
            dup
            ldc "Unknown variant: "
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
            aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/String;)Ljava/lang/StringBuilder;
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
            invokespecial java.security.cert.CertificateException.<init>:(Ljava/lang/String;)V
            athrow
        21: .line 155
      StackMap locals:
      StackMap stack:
            return
        end local 2 // java.lang.Object parameter
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot       Name  Signature
            0   22     0       this  Lsun/security/validator/EndEntityChecker;
            0   22     1       cert  Ljava/security/cert/X509Certificate;
            0   22     2  parameter  Ljava/lang/Object;
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
           Name  Flags
      cert       
      parameter  

  private java.util.Set<java.lang.String> getCriticalExtensions(java.security.cert.X509Certificate);
    descriptor: (Ljava/security/cert/X509Certificate;)Ljava/util/Set;
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=1, locals=3, args_size=2
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
         0: .line 162
            aload 1 /* cert */
            invokevirtual java.security.cert.X509Certificate.getCriticalExtensionOIDs:()Ljava/util/Set;
            astore 2 /* exts */
        start local 2 // java.util.Set exts
         1: .line 163
            aload 2 /* exts */
            ifnonnull 3
         2: .line 164
            invokestatic java.util.Collections.emptySet:()Ljava/util/Set;
            astore 2 /* exts */
         3: .line 166
      StackMap locals: java.util.Set
      StackMap stack:
            aload 2 /* exts */
            areturn
        end local 2 // java.util.Set exts
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0    4     0  this  Lsun/security/validator/EndEntityChecker;
            0    4     1  cert  Ljava/security/cert/X509Certificate;
            1    4     2  exts  Ljava/util/Set<Ljava/lang/String;>;
    Signature: (Ljava/security/cert/X509Certificate;)Ljava/util/Set<Ljava/lang/String;>;
    MethodParameters:
      Name  Flags
      cert  

  private void checkRemainingExtensions(java.util.Set<java.lang.String>);
    descriptor: (Ljava/util/Set;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=5, locals=2, args_size=2
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.util.Set exts
         0: .line 176
            aload 1 /* exts */
            ldc "2.5.29.19"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
         1: .line 182
            aload 1 /* exts */
            ldc "2.5.29.17"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
         2: .line 184
            aload 1 /* exts */
            invokeinterface java.util.Set.isEmpty:()Z
            ifne 6
         3: .line 185
            new java.security.cert.CertificateException
            dup
            new java.lang.StringBuilder
            dup
            ldc "Certificate contains unsupported critical extensions: "
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
         4: .line 186
            aload 1 /* exts */
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/Object;)Ljava/lang/StringBuilder;
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
         5: .line 185
            invokespecial java.security.cert.CertificateException.<init>:(Ljava/lang/String;)V
            athrow
         6: .line 188
      StackMap locals:
      StackMap stack:
            return
        end local 1 // java.util.Set exts
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0    7     0  this  Lsun/security/validator/EndEntityChecker;
            0    7     1  exts  Ljava/util/Set<Ljava/lang/String;>;
    Exceptions:
      throws java.security.cert.CertificateException
    Signature: (Ljava/util/Set<Ljava/lang/String;>;)V
    MethodParameters:
      Name  Flags
      exts  

  private boolean checkEKU(java.security.cert.X509Certificate, java.util.Set<java.lang.String>, java.lang.String);
    descriptor: (Ljava/security/cert/X509Certificate;Ljava/util/Set;Ljava/lang/String;)Z
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=2, locals=5, args_size=4
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
        start local 2 // java.util.Set exts
        start local 3 // java.lang.String expectedEKU
         0: .line 196
            aload 1 /* cert */
            invokevirtual java.security.cert.X509Certificate.getExtendedKeyUsage:()Ljava/util/List;
            astore 4 /* eku */
        start local 4 // java.util.List eku
         1: .line 197
            aload 4 /* eku */
            ifnonnull 3
         2: .line 198
            iconst_1
            ireturn
         3: .line 200
      StackMap locals: java.util.List
      StackMap stack:
            aload 4 /* eku */
            aload 3 /* expectedEKU */
            invokeinterface java.util.List.contains:(Ljava/lang/Object;)Z
            ifne 4
            aload 4 /* eku */
            ldc "2.5.29.37.0"
            invokeinterface java.util.List.contains:(Ljava/lang/Object;)Z
            ifne 4
            iconst_0
            ireturn
      StackMap locals:
      StackMap stack:
         4: iconst_1
            ireturn
        end local 4 // java.util.List eku
        end local 3 // java.lang.String expectedEKU
        end local 2 // java.util.Set exts
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot         Name  Signature
            0    5     0         this  Lsun/security/validator/EndEntityChecker;
            0    5     1         cert  Ljava/security/cert/X509Certificate;
            0    5     2         exts  Ljava/util/Set<Ljava/lang/String;>;
            0    5     3  expectedEKU  Ljava/lang/String;
            1    5     4          eku  Ljava/util/List<Ljava/lang/String;>;
    Exceptions:
      throws java.security.cert.CertificateException
    Signature: (Ljava/security/cert/X509Certificate;Ljava/util/Set<Ljava/lang/String;>;Ljava/lang/String;)Z
    MethodParameters:
             Name  Flags
      cert         
      exts         
      expectedEKU  

  private boolean checkKeyUsage(java.security.cert.X509Certificate, int);
    descriptor: (Ljava/security/cert/X509Certificate;I)Z
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=2, locals=4, args_size=3
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
        start local 2 // int bit
         0: .line 210
            aload 1 /* cert */
            invokevirtual java.security.cert.X509Certificate.getKeyUsage:()[Z
            astore 3 /* keyUsage */
        start local 3 // boolean[] keyUsage
         1: .line 211
            aload 3 /* keyUsage */
            ifnonnull 3
         2: .line 212
            iconst_1
            ireturn
         3: .line 214
      StackMap locals: boolean[]
      StackMap stack:
            aload 3 /* keyUsage */
            arraylength
            iload 2 /* bit */
            if_icmple 4
            aload 3 /* keyUsage */
            iload 2 /* bit */
            baload
            ifeq 4
            iconst_1
            ireturn
      StackMap locals:
      StackMap stack:
         4: iconst_0
            ireturn
        end local 3 // boolean[] keyUsage
        end local 2 // int bit
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot      Name  Signature
            0    5     0      this  Lsun/security/validator/EndEntityChecker;
            0    5     1      cert  Ljava/security/cert/X509Certificate;
            0    5     2       bit  I
            1    5     3  keyUsage  [Z
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
      Name  Flags
      cert  
      bit   

  private void checkTLSClient(java.security.cert.X509Certificate);
    descriptor: (Ljava/security/cert/X509Certificate;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=5, locals=3, args_size=2
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
         0: .line 224
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.getCriticalExtensions:(Ljava/security/cert/X509Certificate;)Ljava/util/Set;
            astore 2 /* exts */
        start local 2 // java.util.Set exts
         1: .line 226
            aload 0 /* this */
            aload 1 /* cert */
            iconst_0
            invokevirtual sun.security.validator.EndEntityChecker.checkKeyUsage:(Ljava/security/cert/X509Certificate;I)Z
            ifne 6
         2: .line 227
            new sun.security.validator.ValidatorException
            dup
         3: .line 228
            ldc "KeyUsage does not allow digital signatures"
         4: .line 229
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
         5: .line 227
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
         6: .line 232
      StackMap locals: java.util.Set
      StackMap stack:
            aload 0 /* this */
            aload 1 /* cert */
            aload 2 /* exts */
            ldc "1.3.6.1.5.5.7.3.2"
            invokevirtual sun.security.validator.EndEntityChecker.checkEKU:(Ljava/security/cert/X509Certificate;Ljava/util/Set;Ljava/lang/String;)Z
            ifne 10
         7: .line 233
            new sun.security.validator.ValidatorException
            dup
            ldc "Extended key usage does not permit use for TLS client authentication"
         8: .line 235
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
         9: .line 233
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        10: .line 238
      StackMap locals:
      StackMap stack:
            aload 1 /* cert */
            ldc "ssl_client"
            invokestatic sun.security.validator.SimpleValidator.getNetscapeCertTypeBit:(Ljava/security/cert/X509Certificate;Ljava/lang/String;)Z
            ifne 15
        11: .line 239
            new sun.security.validator.ValidatorException
            dup
        12: .line 240
            ldc "Netscape cert type does not permit use for SSL client"
        13: .line 241
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        14: .line 239
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        15: .line 245
      StackMap locals:
      StackMap stack:
            aload 2 /* exts */
            ldc "2.5.29.15"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        16: .line 246
            aload 2 /* exts */
            ldc "2.5.29.37"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        17: .line 247
            aload 2 /* exts */
            ldc "2.16.840.1.113730.1.1"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        18: .line 249
            aload 0 /* this */
            aload 2 /* exts */
            invokevirtual sun.security.validator.EndEntityChecker.checkRemainingExtensions:(Ljava/util/Set;)V
        19: .line 250
            return
        end local 2 // java.util.Set exts
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0   20     0  this  Lsun/security/validator/EndEntityChecker;
            0   20     1  cert  Ljava/security/cert/X509Certificate;
            1   20     2  exts  Ljava/util/Set<Ljava/lang/String;>;
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
      Name  Flags
      cert  

  private void checkTLSServer(java.security.cert.X509Certificate, java.lang.String);
    descriptor: (Ljava/security/cert/X509Certificate;Ljava/lang/String;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=5, locals=4, args_size=3
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
        start local 2 // java.lang.String parameter
         0: .line 260
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.getCriticalExtensions:(Ljava/security/cert/X509Certificate;)Ljava/util/Set;
            astore 3 /* exts */
        start local 3 // java.util.Set exts
         1: .line 262
            getstatic sun.security.validator.EndEntityChecker.KU_SERVER_ENCRYPTION:Ljava/util/Collection;
            aload 2 /* parameter */
            invokeinterface java.util.Collection.contains:(Ljava/lang/Object;)Z
            ifeq 7
         2: .line 263
            aload 0 /* this */
            aload 1 /* cert */
            iconst_2
            invokevirtual sun.security.validator.EndEntityChecker.checkKeyUsage:(Ljava/security/cert/X509Certificate;I)Z
            ifne 20
         3: .line 264
            new sun.security.validator.ValidatorException
            dup
         4: .line 265
            ldc "KeyUsage does not allow key encipherment"
         5: .line 266
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
         6: .line 264
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
         7: .line 268
      StackMap locals: java.util.Set
      StackMap stack:
            getstatic sun.security.validator.EndEntityChecker.KU_SERVER_SIGNATURE:Ljava/util/Collection;
            aload 2 /* parameter */
            invokeinterface java.util.Collection.contains:(Ljava/lang/Object;)Z
            ifeq 13
         8: .line 269
            aload 0 /* this */
            aload 1 /* cert */
            iconst_0
            invokevirtual sun.security.validator.EndEntityChecker.checkKeyUsage:(Ljava/security/cert/X509Certificate;I)Z
            ifne 20
         9: .line 270
            new sun.security.validator.ValidatorException
            dup
        10: .line 271
            ldc "KeyUsage does not allow digital signatures"
        11: .line 272
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        12: .line 270
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        13: .line 274
      StackMap locals:
      StackMap stack:
            getstatic sun.security.validator.EndEntityChecker.KU_SERVER_KEY_AGREEMENT:Ljava/util/Collection;
            aload 2 /* parameter */
            invokeinterface java.util.Collection.contains:(Ljava/lang/Object;)Z
            ifeq 19
        14: .line 275
            aload 0 /* this */
            aload 1 /* cert */
            iconst_4
            invokevirtual sun.security.validator.EndEntityChecker.checkKeyUsage:(Ljava/security/cert/X509Certificate;I)Z
            ifne 20
        15: .line 276
            new sun.security.validator.ValidatorException
            dup
        16: .line 277
            ldc "KeyUsage does not allow key agreement"
        17: .line 278
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        18: .line 276
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        19: .line 281
      StackMap locals:
      StackMap stack:
            new java.security.cert.CertificateException
            dup
            new java.lang.StringBuilder
            dup
            ldc "Unknown authType: "
            invokespecial java.lang.StringBuilder.<init>:(Ljava/lang/String;)V
            aload 2 /* parameter */
            invokevirtual java.lang.StringBuilder.append:(Ljava/lang/String;)Ljava/lang/StringBuilder;
            invokevirtual java.lang.StringBuilder.toString:()Ljava/lang/String;
            invokespecial java.security.cert.CertificateException.<init>:(Ljava/lang/String;)V
            athrow
        20: .line 284
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            aload 1 /* cert */
            aload 3 /* exts */
            ldc "1.3.6.1.5.5.7.3.1"
            invokevirtual sun.security.validator.EndEntityChecker.checkEKU:(Ljava/security/cert/X509Certificate;Ljava/util/Set;Ljava/lang/String;)Z
            ifne 27
        21: .line 287
            aload 0 /* this */
            aload 1 /* cert */
            aload 3 /* exts */
            ldc "1.3.6.1.4.1.311.10.3.3"
            invokevirtual sun.security.validator.EndEntityChecker.checkEKU:(Ljava/security/cert/X509Certificate;Ljava/util/Set;Ljava/lang/String;)Z
            ifne 27
        22: .line 288
            aload 0 /* this */
            aload 1 /* cert */
            aload 3 /* exts */
            ldc "2.16.840.1.113730.4.1"
            invokevirtual sun.security.validator.EndEntityChecker.checkEKU:(Ljava/security/cert/X509Certificate;Ljava/util/Set;Ljava/lang/String;)Z
            ifne 27
        23: .line 289
            new sun.security.validator.ValidatorException
            dup
        24: .line 290
            ldc "Extended key usage does not permit use for TLS server authentication"
        25: .line 292
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        26: .line 289
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        27: .line 296
      StackMap locals:
      StackMap stack:
            aload 1 /* cert */
            ldc "ssl_server"
            invokestatic sun.security.validator.SimpleValidator.getNetscapeCertTypeBit:(Ljava/security/cert/X509Certificate;Ljava/lang/String;)Z
            ifne 32
        28: .line 297
            new sun.security.validator.ValidatorException
            dup
        29: .line 298
            ldc "Netscape cert type does not permit use for SSL server"
        30: .line 299
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        31: .line 297
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        32: .line 303
      StackMap locals:
      StackMap stack:
            aload 3 /* exts */
            ldc "2.5.29.15"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        33: .line 304
            aload 3 /* exts */
            ldc "2.5.29.37"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        34: .line 305
            aload 3 /* exts */
            ldc "2.16.840.1.113730.1.1"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        35: .line 307
            aload 0 /* this */
            aload 3 /* exts */
            invokevirtual sun.security.validator.EndEntityChecker.checkRemainingExtensions:(Ljava/util/Set;)V
        36: .line 308
            return
        end local 3 // java.util.Set exts
        end local 2 // java.lang.String parameter
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot       Name  Signature
            0   37     0       this  Lsun/security/validator/EndEntityChecker;
            0   37     1       cert  Ljava/security/cert/X509Certificate;
            0   37     2  parameter  Ljava/lang/String;
            1   37     3       exts  Ljava/util/Set<Ljava/lang/String;>;
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
           Name  Flags
      cert       
      parameter  

  private void checkCodeSigning(java.security.cert.X509Certificate);
    descriptor: (Ljava/security/cert/X509Certificate;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=5, locals=3, args_size=2
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
         0: .line 316
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.getCriticalExtensions:(Ljava/security/cert/X509Certificate;)Ljava/util/Set;
            astore 2 /* exts */
        start local 2 // java.util.Set exts
         1: .line 318
            aload 0 /* this */
            aload 1 /* cert */
            iconst_0
            invokevirtual sun.security.validator.EndEntityChecker.checkKeyUsage:(Ljava/security/cert/X509Certificate;I)Z
            ifne 6
         2: .line 319
            new sun.security.validator.ValidatorException
            dup
         3: .line 320
            ldc "KeyUsage does not allow digital signatures"
         4: .line 321
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
         5: .line 319
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
         6: .line 324
      StackMap locals: java.util.Set
      StackMap stack:
            aload 0 /* this */
            aload 1 /* cert */
            aload 2 /* exts */
            ldc "1.3.6.1.5.5.7.3.3"
            invokevirtual sun.security.validator.EndEntityChecker.checkEKU:(Ljava/security/cert/X509Certificate;Ljava/util/Set;Ljava/lang/String;)Z
            ifne 11
         7: .line 325
            new sun.security.validator.ValidatorException
            dup
         8: .line 326
            ldc "Extended key usage does not permit use for code signing"
         9: .line 327
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        10: .line 325
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        11: .line 332
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            getfield sun.security.validator.EndEntityChecker.variant:Ljava/lang/String;
            ldc "jce signing"
            invokevirtual java.lang.String.equals:(Ljava/lang/Object;)Z
            ifne 18
        12: .line 333
            aload 1 /* cert */
            ldc "object_signing"
            invokestatic sun.security.validator.SimpleValidator.getNetscapeCertTypeBit:(Ljava/security/cert/X509Certificate;Ljava/lang/String;)Z
            ifne 17
        13: .line 334
            new sun.security.validator.ValidatorException
            dup
        14: .line 335
            ldc "Netscape cert type does not permit use for code signing"
        15: .line 336
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        16: .line 334
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        17: .line 338
      StackMap locals:
      StackMap stack:
            aload 2 /* exts */
            ldc "2.16.840.1.113730.1.1"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        18: .line 342
      StackMap locals:
      StackMap stack:
            aload 2 /* exts */
            ldc "2.5.29.15"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        19: .line 343
            aload 2 /* exts */
            ldc "2.5.29.37"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        20: .line 345
            aload 0 /* this */
            aload 2 /* exts */
            invokevirtual sun.security.validator.EndEntityChecker.checkRemainingExtensions:(Ljava/util/Set;)V
        21: .line 346
            return
        end local 2 // java.util.Set exts
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0   22     0  this  Lsun/security/validator/EndEntityChecker;
            0   22     1  cert  Ljava/security/cert/X509Certificate;
            1   22     2  exts  Ljava/util/Set<Ljava/lang/String;>;
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
      Name  Flags
      cert  

  private void checkTSAServer(java.security.cert.X509Certificate);
    descriptor: (Ljava/security/cert/X509Certificate;)V
    flags: (0x0002) ACC_PRIVATE
    Code:
      stack=5, locals=3, args_size=2
        start local 0 // sun.security.validator.EndEntityChecker this
        start local 1 // java.security.cert.X509Certificate cert
         0: .line 355
            aload 0 /* this */
            aload 1 /* cert */
            invokevirtual sun.security.validator.EndEntityChecker.getCriticalExtensions:(Ljava/security/cert/X509Certificate;)Ljava/util/Set;
            astore 2 /* exts */
        start local 2 // java.util.Set exts
         1: .line 357
            aload 0 /* this */
            aload 1 /* cert */
            iconst_0
            invokevirtual sun.security.validator.EndEntityChecker.checkKeyUsage:(Ljava/security/cert/X509Certificate;I)Z
            ifne 6
         2: .line 358
            new sun.security.validator.ValidatorException
            dup
         3: .line 359
            ldc "KeyUsage does not allow digital signatures"
         4: .line 360
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
         5: .line 358
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
         6: .line 363
      StackMap locals: java.util.Set
      StackMap stack:
            aload 1 /* cert */
            invokevirtual java.security.cert.X509Certificate.getExtendedKeyUsage:()Ljava/util/List;
            ifnonnull 11
         7: .line 364
            new sun.security.validator.ValidatorException
            dup
         8: .line 365
            ldc "Certificate does not contain an extended key usage extension required for a TSA server"
         9: .line 367
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        10: .line 364
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        11: .line 370
      StackMap locals:
      StackMap stack:
            aload 0 /* this */
            aload 1 /* cert */
            aload 2 /* exts */
            ldc "1.3.6.1.5.5.7.3.8"
            invokevirtual sun.security.validator.EndEntityChecker.checkEKU:(Ljava/security/cert/X509Certificate;Ljava/util/Set;Ljava/lang/String;)Z
            ifne 16
        12: .line 371
            new sun.security.validator.ValidatorException
            dup
        13: .line 372
            ldc "Extended key usage does not permit use for TSA server"
        14: .line 373
            getstatic sun.security.validator.ValidatorException.T_EE_EXTENSIONS:Ljava/lang/Object;
            aload 1 /* cert */
        15: .line 371
            invokespecial sun.security.validator.ValidatorException.<init>:(Ljava/lang/String;Ljava/lang/Object;Ljava/security/cert/X509Certificate;)V
            athrow
        16: .line 377
      StackMap locals:
      StackMap stack:
            aload 2 /* exts */
            ldc "2.5.29.15"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        17: .line 378
            aload 2 /* exts */
            ldc "2.5.29.37"
            invokeinterface java.util.Set.remove:(Ljava/lang/Object;)Z
            pop
        18: .line 380
            aload 0 /* this */
            aload 2 /* exts */
            invokevirtual sun.security.validator.EndEntityChecker.checkRemainingExtensions:(Ljava/util/Set;)V
        19: .line 381
            return
        end local 2 // java.util.Set exts
        end local 1 // java.security.cert.X509Certificate cert
        end local 0 // sun.security.validator.EndEntityChecker this
      LocalVariableTable:
        Start  End  Slot  Name  Signature
            0   20     0  this  Lsun/security/validator/EndEntityChecker;
            0   20     1  cert  Ljava/security/cert/X509Certificate;
            1   20     2  exts  Ljava/util/Set<Ljava/lang/String;>;
    Exceptions:
      throws java.security.cert.CertificateException
    MethodParameters:
      Name  Flags
      cert  
}
SourceFile: "EndEntityChecker.java"