diff --git a/authserv/test/testca/.random b/authserv/test/testca/.random
new file mode 100644
index 0000000000000000000000000000000000000000..e5fe640fa14ec5161a380831f9b376b69d89013f
Binary files /dev/null and b/authserv/test/testca/.random differ
diff --git a/authserv/test/testca/conf/ca.conf b/authserv/test/testca/conf/ca.conf
index 112fca8c7d2e55e461df4405eb92d383174e5160..07c0ba0a10eb98af4f503df690896dcef4ca6d3b 100644
--- a/authserv/test/testca/conf/ca.conf
+++ b/authserv/test/testca/conf/ca.conf
@@ -2,6 +2,7 @@ RANDFILE = ${ENV::CAROOT}/.random
 
 [ ca ]
 default_ca              = CA_default
+unique_subject          = no
 
 [ CA_default ]
 dir                     = ${ENV::CAROOT}
@@ -37,7 +38,7 @@ commonName              = supplied
 emailAddress            = optional
 
 [ req ]
-default_bits            = 4096
+default_bits            = 2048
 default_md              = sha1
 distinguished_name      = req_distinguished_name
 attributes              = req_attributes
diff --git a/authserv/test/testca/crlnumber b/authserv/test/testca/crlnumber
index 8a0f05e166aa61225bf6649cb345f87416b5f509..9e22bcb8e3440869e9e1303f3b7045d1fc8e58c5 100644
--- a/authserv/test/testca/crlnumber
+++ b/authserv/test/testca/crlnumber
@@ -1 +1 @@
-01
+02
diff --git a/authserv/test/testca/crlnumber.old b/authserv/test/testca/crlnumber.old
new file mode 100644
index 0000000000000000000000000000000000000000..8a0f05e166aa61225bf6649cb345f87416b5f509
--- /dev/null
+++ b/authserv/test/testca/crlnumber.old
@@ -0,0 +1 @@
+01
diff --git a/authserv/test/testca/index b/authserv/test/testca/index
index 16938ac1cf9e25c1b2df0a16ab7be9b4563c1626..7a318c7ade40f66503167aa40d7bfd4aa27bfde0 100644
--- a/authserv/test/testca/index
+++ b/authserv/test/testca/index
@@ -1,3 +1,4 @@
 V	240615222645Z		19028A9B	unknown	/C=xx/O=test/OU=CA/CN=test certification authority
 V	240615222705Z		19028A9C	unknown	/C=xx/O=test/OU=CA/CN=client
-V	240615222709Z		19028A9D	unknown	/C=xx/O=test/OU=CA/CN=server
+R	240615222709Z	161002155408Z	19028A9D	unknown	/C=xx/O=test/OU=CA/CN=server
+V	260930155408Z		19028A9E	unknown	/C=xx/O=test/OU=CA/CN=server
diff --git a/authserv/test/testca/index.old b/authserv/test/testca/index.old
index 1d9fc059aed28be38e6285ab9826e05717d15aaa..93287355d2d2b0939871098a4b4ecec05d118fcb 100644
--- a/authserv/test/testca/index.old
+++ b/authserv/test/testca/index.old
@@ -1,2 +1,3 @@
 V	240615222645Z		19028A9B	unknown	/C=xx/O=test/OU=CA/CN=test certification authority
 V	240615222705Z		19028A9C	unknown	/C=xx/O=test/OU=CA/CN=client
+R	240615222709Z	161002155408Z	19028A9D	unknown	/C=xx/O=test/OU=CA/CN=server
diff --git a/authserv/test/testca/newcerts/19028A9E.pem b/authserv/test/testca/newcerts/19028A9E.pem
new file mode 100644
index 0000000000000000000000000000000000000000..633ac08ec57db104b1242360a985602c01feba6e
--- /dev/null
+++ b/authserv/test/testca/newcerts/19028A9E.pem
@@ -0,0 +1,119 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 419596958 (0x19028a9e)
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=xx, O=test, OU=CA, CN=test certification authority
+        Validity
+            Not Before: Oct  2 15:54:08 2016 GMT
+            Not After : Sep 30 15:54:08 2026 GMT
+        Subject: C=xx, O=test, OU=CA, CN=server
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (2048 bit)
+                Modulus:
+                    00:c3:f9:42:b8:f3:69:9a:24:45:ba:fa:ff:50:8c:
+                    4a:4f:20:11:1b:e4:ba:56:90:70:e6:2c:18:36:6f:
+                    4c:43:83:1a:42:d2:57:62:49:78:a7:6f:c6:50:95:
+                    cc:aa:3d:95:d0:2e:0e:0c:25:b2:0c:74:9e:ff:70:
+                    b9:e3:ed:bb:6f:89:81:7b:ff:32:fd:ef:5a:4b:77:
+                    64:1c:86:73:e0:7c:d7:bc:9f:ac:34:ca:a6:d0:5f:
+                    2d:66:10:63:ca:d2:11:de:9b:93:58:6c:94:ec:ef:
+                    d6:5f:0d:d4:07:75:99:a1:7e:20:eb:8d:3c:dc:04:
+                    eb:07:46:c3:5c:84:a7:47:8f:f7:af:36:c5:18:1b:
+                    b1:00:fb:23:03:a3:f3:b4:4c:be:d1:60:a7:58:c7:
+                    e5:70:f5:a1:e4:88:ee:cf:e4:17:33:83:a7:c4:0e:
+                    f3:87:5e:fd:a5:34:40:52:26:a1:46:ef:b2:04:11:
+                    0b:81:d8:e2:df:66:fd:ef:fe:dd:c7:66:2a:73:97:
+                    40:ae:22:11:b3:99:23:00:55:d4:62:1c:a1:cb:0b:
+                    52:5f:ba:e8:9b:71:74:4f:79:0c:6c:96:9d:ba:7f:
+                    20:fb:c3:cd:3f:3a:32:c5:60:f0:6c:50:88:8f:bb:
+                    0e:15:60:c9:8b:b8:d8:0b:80:05:ec:84:7e:69:d2:
+                    67:01
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Basic Constraints: 
+                CA:FALSE
+            Netscape Cert Type: 
+                SSL Client, SSL Server
+            X509v3 Key Usage: 
+                Digital Signature, Non Repudiation, Key Encipherment
+            X509v3 Extended Key Usage: 
+                TLS Web Client Authentication, TLS Web Server Authentication
+            X509v3 Subject Key Identifier: 
+                39:3A:53:CE:75:65:C6:92:D0:F3:29:6D:9A:F5:F2:D2:64:07:67:CA
+            X509v3 Authority Key Identifier: 
+                keyid:C0:24:9A:D1:70:E0:B2:DF:75:E5:00:E2:7F:94:A1:01:87:20:DF:3E
+                DirName:/C=xx/O=test/OU=CA/CN=test certification authority
+                serial:19:02:8A:9B
+
+            X509v3 Subject Alternative Name: 
+                DNS:server, DNS:localhost
+            X509v3 Issuer Alternative Name: 
+                email:ca@example.org
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:
+
+    Signature Algorithm: sha256WithRSAEncryption
+         c4:f6:02:42:ed:42:1e:69:09:f8:a5:a4:31:81:f5:2c:c8:d6:
+         fe:3a:6c:e1:81:cc:a1:d2:05:36:29:d7:84:cd:08:55:14:d3:
+         b8:88:4f:12:e9:6b:40:96:0e:f4:93:63:ad:6d:ce:88:fc:8f:
+         a2:6e:e4:99:a8:a7:0b:95:2c:07:24:e3:8e:01:4b:27:fb:ec:
+         4f:27:de:21:16:d0:e3:27:a5:a2:1e:f0:46:97:90:31:bd:df:
+         4a:27:85:06:1f:7f:40:dd:45:ee:93:45:eb:c4:87:d4:5d:07:
+         e2:03:9f:fa:ff:b3:8d:37:fd:07:18:61:1d:43:8f:84:0e:9b:
+         e7:87:91:9d:f9:0f:35:45:eb:ea:7a:e0:4d:cf:33:4e:6a:31:
+         94:e4:1b:2d:88:5b:27:da:48:4c:28:02:8e:71:0d:f2:b2:f9:
+         05:77:ac:33:42:7a:a4:7a:b4:57:32:e5:67:7a:66:d7:3e:1d:
+         9c:3d:af:ae:10:5d:e4:2f:37:0f:fc:26:9e:66:c5:c5:3e:a8:
+         6e:19:10:ed:57:73:96:a1:71:8d:55:51:0c:ec:83:62:99:29:
+         4f:64:0a:fb:bd:68:34:61:3c:48:4d:44:bd:6d:c6:77:b5:f7:
+         70:bf:fc:19:df:ad:c1:e1:aa:f4:c0:50:ee:c4:58:d1:29:1f:
+         a1:c7:d4:41:0b:98:7f:f4:97:51:6e:91:50:2e:e2:3d:17:cb:
+         2f:b9:d7:9b:4b:0e:a7:20:f7:ad:a5:96:b0:e6:3e:ce:87:65:
+         90:3f:0e:f6:73:0c:21:3a:56:43:f0:dd:62:59:23:d3:e2:75:
+         8a:71:96:52:da:ad:9b:6f:70:a7:0f:16:a5:89:25:f2:5f:e5:
+         1c:2c:1a:b3:fa:43:6a:59:0e:4d:c7:b9:8d:67:fd:ea:a6:71:
+         92:46:f5:a7:d3:72:5c:ee:d8:35:47:ec:56:d5:23:a7:0e:f8:
+         25:46:83:0d:b6:c3:db:7d:14:ff:75:2f:70:2f:28:7b:80:77:
+         dc:41:c6:9d:0d:61:0a:9e:05:2f:91:69:b7:b3:6c:18:01:e6:
+         60:ab:23:56:b1:a1:76:5c:3d:00:14:ba:52:9a:ad:fa:34:21:
+         f8:33:eb:e4:19:85:01:14:27:6d:fc:59:e0:17:aa:d5:ea:72:
+         5c:ff:20:32:65:14:4b:b7:91:69:c9:29:74:13:73:06:12:55:
+         94:cc:0d:2f:a2:f4:91:e9:95:c9:5c:2a:c8:4c:8a:4f:b9:07:
+         74:e3:dc:b6:09:ce:0d:63:06:24:d7:ed:a9:1e:b7:55:2a:da:
+         bf:df:80:48:bf:6e:a1:e8:f8:c5:4f:90:5a:a2:59:1f:4d:6d:
+         4d:83:9a:15:97:96:0d:10
+-----BEGIN CERTIFICATE-----
+MIIFQDCCAyigAwIBAgIEGQKKnjANBgkqhkiG9w0BAQsFADBQMQswCQYDVQQGEwJ4
+eDENMAsGA1UEChMEdGVzdDELMAkGA1UECxMCQ0ExJTAjBgNVBAMTHHRlc3QgY2Vy
+dGlmaWNhdGlvbiBhdXRob3JpdHkwHhcNMTYxMDAyMTU1NDA4WhcNMjYwOTMwMTU1
+NDA4WjA6MQswCQYDVQQGEwJ4eDENMAsGA1UEChMEdGVzdDELMAkGA1UECxMCQ0Ex
+DzANBgNVBAMTBnNlcnZlcjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
+AMP5QrjzaZokRbr6/1CMSk8gERvkulaQcOYsGDZvTEODGkLSV2JJeKdvxlCVzKo9
+ldAuDgwlsgx0nv9wuePtu2+JgXv/Mv3vWkt3ZByGc+B817yfrDTKptBfLWYQY8rS
+Ed6bk1hslOzv1l8N1Ad1maF+IOuNPNwE6wdGw1yEp0eP9682xRgbsQD7IwOj87RM
+vtFgp1jH5XD1oeSI7s/kFzODp8QO84de/aU0QFImoUbvsgQRC4HY4t9m/e/+3cdm
+KnOXQK4iEbOZIwBV1GIcocsLUl+66JtxdE95DGyWnbp/IPvDzT86MsVg8GxQiI+7
+DhVgyYu42AuABeyEfmnSZwECAwEAAaOCATYwggEyMAkGA1UdEwQCMAAwEQYJYIZI
+AYb4QgEBBAQDAgbAMAsGA1UdDwQEAwIF4DAdBgNVHSUEFjAUBggrBgEFBQcDAgYI
+KwYBBQUHAwEwHQYDVR0OBBYEFDk6U851ZcaS0PMpbZr18tJkB2fKMHsGA1UdIwR0
+MHKAFMAkmtFw4LLfdeUA4n+UoQGHIN8+oVSkUjBQMQswCQYDVQQGEwJ4eDENMAsG
+A1UEChMEdGVzdDELMAkGA1UECxMCQ0ExJTAjBgNVBAMTHHRlc3QgY2VydGlmaWNh
+dGlvbiBhdXRob3JpdHmCBBkCipswHAYDVR0RBBUwE4IGc2VydmVygglsb2NhbGhv
+c3QwGQYDVR0SBBIwEIEOY2FAZXhhbXBsZS5vcmcwEQYDVR0fBAowCDAGoASgAoYA
+MA0GCSqGSIb3DQEBCwUAA4ICAQDE9gJC7UIeaQn4paQxgfUsyNb+Omzhgcyh0gU2
+KdeEzQhVFNO4iE8S6WtAlg70k2Otbc6I/I+ibuSZqKcLlSwHJOOOAUsn++xPJ94h
+FtDjJ6WiHvBGl5Axvd9KJ4UGH39A3UXuk0XrxIfUXQfiA5/6/7ONN/0HGGEdQ4+E
+Dpvnh5Gd+Q81RevqeuBNzzNOajGU5BstiFsn2khMKAKOcQ3ysvkFd6wzQnqkerRX
+MuVnembXPh2cPa+uEF3kLzcP/CaeZsXFPqhuGRDtV3OWoXGNVVEM7INimSlPZAr7
+vWg0YTxITUS9bcZ3tfdwv/wZ363B4ar0wFDuxFjRKR+hx9RBC5h/9JdRbpFQLuI9
+F8svudebSw6nIPetpZaw5j7Oh2WQPw72cwwhOlZD8N1iWSPT4nWKcZZS2q2bb3Cn
+DxaliSXyX+UcLBqz+kNqWQ5Nx7mNZ/3qpnGSRvWn03Jc7tg1R+xW1SOnDvglRoMN
+tsPbfRT/dS9wLyh7gHfcQcadDWEKngUvkWm3s2wYAeZgqyNWsaF2XD0AFLpSmq36
+NCH4M+vkGYUBFCdt/FngF6rV6nJc/yAyZRRLt5FpySl0E3MGElWUzA0vovSR6ZXJ
+XCrITIpPuQd049y2Cc4NYwYk1+2pHrdVKtq/34BIv26h6PjFT5BaolkfTW1Ng5oV
+l5YNEA==
+-----END CERTIFICATE-----
diff --git a/authserv/test/testca/private/server.key b/authserv/test/testca/private/server.key
index cd359f638ae6fe48d290e9d1b99f3f6e6bf7c09b..5f21cdf37ae99060ef702178b80b4f61fd5860d5 100644
--- a/authserv/test/testca/private/server.key
+++ b/authserv/test/testca/private/server.key
@@ -1,52 +1,28 @@
 -----BEGIN PRIVATE KEY-----
-MIIJQQIBADANBgkqhkiG9w0BAQEFAASCCSswggknAgEAAoICAQCxYS0T/XS+ZONS
-VD0ibFepm60Ng+9G5XUch8NUIjX0R6KOvG/jUDrdg4c9AjW7ab4mRIkLDpwLWk0T
-9XWB/vPmQHc8Fl31FChrUtJ85KYG02IaBMUlGgnKCPeKStF6JfeEduBYfXKb5q8T
-XuYsExDzCf+Ez3fYr6oo1i/0SKh0JX1pk/RqH4QGiwczhTc0NGX4vKfwgKns47vs
-GPRHWunol2rB/5gGOJP7vfJ1cAUY23xzKoa7SrsSiSM0R+fZgcRPi91Bwl2LlMUN
-TuEOlrkTq69ZJZHe321v6KWIKJhZrZio53GrIOf+j6AHUrEO2JrI1AcYaDX3/Npq
-DvrexvhJgUC8ScV8/+O+cg3paJ0MbpsdPuhQlvgdopKaygXaG5GrGecImKILulk0
-BhJUe4Quc/FKizqTslPou6lf9jFP3Mpq/j6AUEkARxdNcY8WpN5UvR9tDEVCCTtz
-lilRCOojPKoMxgGoEpmUddWpojrBkMhOBZUQlsawjajd91fqOc2sivAVpjJ+sLXA
-zow+mCVtYUPPU+YwNnySb4ABquY8TNNrezTzo8DRNCPypVW1/zo9NTbODCjifLmf
-qCipTxJmi+u9sLbWNdP7u5BLDFKZ5dPi3aYYSVUC6GRqMqq7ssrJn9j1o+YDxPw6
-6+2pP2z+pa82dy0dsWHOpdtYe44w6QIDAQABAoICACMuCMi8LhlM3SEJAA8Buekz
-rQDPN/exrqZ37q+TEWxfgMgaa36D/QjN+1aIR6vh7wqb8So2PZCq2jqpJiMgM7No
-+bz7Gqtu0g1nIcQPfTZBWmWaqJcRMPvXB3FwIVe+i/bDtP8X8lElUXfgDHqVVXk+
-dGUc2MIrJO5wfJZQishuXw8/fuxFT+QUUttPAoHiGo9Yq14xxoHrMOxEjr5QM7Aj
-x9KuJLKnKgJ1y86q5vflICufNZWT3sJwXIET+dHTwOGd9cYDDJaQbPyUtmI0VoSm
-OmLN5r5zRbs6QwpcMssmeO6W6J5uKlT8m1qYdfFh2GEYXEfk8z858P+z9OGWSMvG
-u2/3RIX/I5tmRLl07zg4x5kI7TNpz5TTbGanXr3Rn4b2BbmgZWE7OyYoVsxHHg9B
-i08IG6Nk72Z3Hy+ZnDoTaYvhW3rTX7yq2SrQeF3X0wZZTIkyZwK2U4v/gEHsL7Pn
-zUVIb1PhkHXP+APqXMi3iWL8EY0z671Dx77S8KSHRtXsAGa3dK5P6Voq8qc8i6/n
-xcqX+acsvodPdtJ92YaIH6DBotJPTeC3NY7LdTIRrJb+ddtAeZEVOKXvY42eXDYS
-B9AawKe016Kr+U2xHQvXzMwBLDa/YB7wkmesBuNyYae5eOT5CL1xzP05uZ/+bSoP
-fWA9aF6Yn7w3cmMrNpH5AoIBAQDbyNKyEBzlGd7ycMXhsb2swJInE54nV3luMlik
-SLrWyNUowYPQ2Dcyiic9ID+6e3cxA4XJxPC6KAi3NPDh21eQUgwpQt/DNHMkCtIc
-aLdp9Cw2IjTLr5xe5V9J68ecgjUskSTNL8li2xWbcaW7dEIczQ91trdtbFXNclmc
-nOvVNli6aICZH7jHUI7arxQhI8onibdRvYS2srsRXWdEMmVSK5Qzg6rjZ9lX1c1E
-tRa0aK/5V4xv2rf2+ASSa07COBfsWb5SwASLWV6R7nlP9q7VMSt9DkN1Gw9sD+ay
-alWAQe27uVgFEkGQhXEFztKnWflhp10e8uBaDlXxeu8Eojf/AoIBAQDOm5YwTF/V
-5u7I1rGnwfbMQaHj1JyN5jtx62J93hutTQTxpSbAo4y/qEMdYWMQengCAHfCJ8Vi
-tR+9wWOZ36WBscbOOGdCnu4Q2oBr0M8st4myndhbXbrUy1bExVPsFBrSCKfjnZeb
-sAMUQkyR3+xIffjFvpMJbY3FbpjxNpy0pT+DCrMb5WZMgkON55nMd0nl6NfikAw8
-HwC6YrFQNcg265NYezOsxESckNWXYXLr1ayvtAzmObsmR1B6bquyWyVCI06cJaU+
-PxCVwo88cWgdHB9KX1jBqACg5cgcbK9ID0ICSNlWjQr8/k/QKcFIXTkXS0B0OOZ3
-EYPUMT/MDNcXAoIBAD0CMfpbnqm51LlXtJZB0HTzv545Q92H2p1MPG7eAX89oG3/
-yadfXXMaBmphWU9almt0nt6zXF9QXZr9hyAq0tOs8tNBTPvSw2Nt3YUlTESNEviz
-5hPkW3O8GAdc+7vmKPyGDcEnUq+uQQE1OtweGXwFMBVs8t3dBLRS2a0vogc9XsPf
-3lKjC5fINN9fWicY2DTBdbGq+fv9ARCA7PlxQ87bafgixHz7hslq/9/ipLrPlImS
-U9l4zTgxAJPkVah0CbAB+WLfCmPkGuxHVkVsJHvpejjsjK0lJdLJVzCPc8x2gJdr
-i5NczfZgFE+YacEqqJ8C5kaBBOX6tMCjb1XJ8eECggEAJmhH8CySeDoY058NoYju
-LyRYSvkgLUTKci/2vD1I2duCesVfwdnldU97Qn/zIYISwxSBLsej6uiOwQCtWlJ3
-+vcoZPeZQoo26U0lKGXFzaNE5r5vFPUEoUA3nhastis6nSbcxvRp1ZhPyjlU8J02
-2HcKgwAdZ1hFTZl0twqW8QHzH5Iin6HydXCVzFBsh9T5GNNDJqvuilKdGQj1u1p0
-ILmER6OHhKtrscs+2YhVC8BJ/NO0viunPcNuE4R1SI+nCndzypU49axVkfF8HRlb
-6GVs769v2Xg4vbBZleciYnvrom8Wb/+CNmu0PJc2hhRGY60qizB0r1fDMPQCzxTn
-+wKCAQAkxRFWI3ugDfG0Oo5NOlaWu048UnI9lPG6IoRn0o+/yqoVbUKd41pUhIkG
-hhvm0OaSwxTohdy+wpCLVqk2FIXuq5qGDDYmO1sNpU0V7CP1rPcc0/yLiA6vUv2w
-k3JZt2GanDx5v3Uuf9CmP7GMMSDtr0hvjDYuWuOXJTtG/qtyloMAcXv6wBfdBciL
-9EoIfM3L6Iqp+lsLiAjmD4xqSxIUyJ+amRS/C7jaEio6i3g9A9a4PWh0uvHt88/E
-BqTLJspKw8eWIyDa4Xt4ocips7P71DyD2BXqdx36Q/r/s29PhSM+2knRQr8w9MD2
-r3NG3cIWPVpxmb/zCSXe6mo8RPDR
+MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDD+UK482maJEW6
++v9QjEpPIBEb5LpWkHDmLBg2b0xDgxpC0ldiSXinb8ZQlcyqPZXQLg4MJbIMdJ7/
+cLnj7btviYF7/zL971pLd2QchnPgfNe8n6w0yqbQXy1mEGPK0hHem5NYbJTs79Zf
+DdQHdZmhfiDrjTzcBOsHRsNchKdHj/evNsUYG7EA+yMDo/O0TL7RYKdYx+Vw9aHk
+iO7P5Bczg6fEDvOHXv2lNEBSJqFG77IEEQuB2OLfZv3v/t3HZipzl0CuIhGzmSMA
+VdRiHKHLC1JfuuibcXRPeQxslp26fyD7w80/OjLFYPBsUIiPuw4VYMmLuNgLgAXs
+hH5p0mcBAgMBAAECggEAKt/jqxcF6YU6BDhZl0O6FimL1LBr2/hp2tGW0oHzC2op
+WqkuGQC99tPLbWH4jt4+YndQ93Nfyr3Q8020PZuLQFGzFG+2tjuhY5VRP7RisaBe
+ipPcVwhnCntoMUYwrvTal/std1D6HAQ0wEMEOkWOQPiZNy+FOxWQXd0rbJhRCKSi
+pJqPluSIlxAKc4FglbXjnYP70ryXvLN/23Os7Zyy63lf0ojYVXtkeiCu++kYFQNn
+5As73utJKYBXUQNa4WQjgYIxdTSAmjwLfM2Rt2u7eqPtWCIzwxds8F5erMKuOMo1
+MhA+xbm0pPVpb35pUqrWExsAnjFCYE/YTWsuDvM9YQKBgQDjmJ47NFnxdyfi8aWr
+PDMO7J+xa+HQg9HZ4ov4FvC4IXCruECnfw1rqtf4A9qzb0x6mukCnSQdA86fcpl4
+qv9XW20dKx/EAE8pCBt69eTlr5cG9Eb5VoAFKKH3mg0ASw/PljCsQcNoPCBlaWVH
+1ImXkheg0CC3WcHAez8mYDbf/QKBgQDcblkLRjSG8kN+SLP4bNfsLncEu1zOhSr8
+DhD0RXAPCv+bYfXiE8AggJtTQgwCcdboSe0m0KcPHoX21lYBk2cO/DWn01HnKnB5
+3X+dt4nZodbH+QM86fhlnvqFpMUNrdjW1m0VYpWQ47PpqRzfzAJrqILn702zCefT
+b5DqA8yoVQKBgBG2ErowvL8ZsrTqcSX+LUsABv1bk9sSJwZ5psLLpjfuAkKauA1Q
+yc6TIPNf+Wj1RFJWM8PMTr8jSLUHygGl7PDzYG5gqLwr+f0LcHgFIqbtHyefYtaM
+cLH2E4SdLF3VeYmB+o+tHnPCGhNKPGN2mq584/HTwHgEOBuue5+U5TBRAoGBANKn
+ScUydGQ6BTIb/JF+QuLcjLUi8NAUBz4VmzI1YZ+enSM6/KXuxf7JqKZqSdvUOtKG
+Q3KCmAQk4VVBA7RBz41MjWIy2uSVdCOh/6ETk1M+DGnSmLuPxOgog7VP/1jROJYn
+GNwE+HYchQTZrlRZPD7yLRfFY3WkE73FsrFQrDZ5AoGAQ2gmVC5XbJFy2sZ2MYqp
++NQPIlqqHHdXlyNZkyi2hFbPnMNiwSbtxrQgDlzkaitzQd3SJ23ZqftJa09llgnx
+icf+aj9AB/bCTWOViA1Ew9fakV+R9hmTfyEXEWJwqDRomNP4j6dX7897k1M+gPPv
+K3EzLOFhJeufF2ZmonN2UlE=
 -----END PRIVATE KEY-----
diff --git a/authserv/test/testca/public/ca.crl b/authserv/test/testca/public/ca.crl
new file mode 100644
index 0000000000000000000000000000000000000000..15d0abee34e7e31c121092a5441958e97a4ca513
Binary files /dev/null and b/authserv/test/testca/public/ca.crl differ
diff --git a/authserv/test/testca/public/certs/server.pem b/authserv/test/testca/public/certs/server.pem
index 9a0c738155da69da80ec3cd62c82b8e8eeb35bce..633ac08ec57db104b1242360a985602c01feba6e 100644
--- a/authserv/test/testca/public/certs/server.pem
+++ b/authserv/test/testca/public/certs/server.pem
@@ -1,52 +1,35 @@
 Certificate:
     Data:
         Version: 3 (0x2)
-        Serial Number: 419596957 (0x19028a9d)
-    Signature Algorithm: sha1WithRSAEncryption
+        Serial Number: 419596958 (0x19028a9e)
+    Signature Algorithm: sha256WithRSAEncryption
         Issuer: C=xx, O=test, OU=CA, CN=test certification authority
         Validity
-            Not Before: Jun 18 22:27:09 2014 GMT
-            Not After : Jun 15 22:27:09 2024 GMT
+            Not Before: Oct  2 15:54:08 2016 GMT
+            Not After : Sep 30 15:54:08 2026 GMT
         Subject: C=xx, O=test, OU=CA, CN=server
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                Public-Key: (4096 bit)
+                Public-Key: (2048 bit)
                 Modulus:
-                    00:b1:61:2d:13:fd:74:be:64:e3:52:54:3d:22:6c:
-                    57:a9:9b:ad:0d:83:ef:46:e5:75:1c:87:c3:54:22:
-                    35:f4:47:a2:8e:bc:6f:e3:50:3a:dd:83:87:3d:02:
-                    35:bb:69:be:26:44:89:0b:0e:9c:0b:5a:4d:13:f5:
-                    75:81:fe:f3:e6:40:77:3c:16:5d:f5:14:28:6b:52:
-                    d2:7c:e4:a6:06:d3:62:1a:04:c5:25:1a:09:ca:08:
-                    f7:8a:4a:d1:7a:25:f7:84:76:e0:58:7d:72:9b:e6:
-                    af:13:5e:e6:2c:13:10:f3:09:ff:84:cf:77:d8:af:
-                    aa:28:d6:2f:f4:48:a8:74:25:7d:69:93:f4:6a:1f:
-                    84:06:8b:07:33:85:37:34:34:65:f8:bc:a7:f0:80:
-                    a9:ec:e3:bb:ec:18:f4:47:5a:e9:e8:97:6a:c1:ff:
-                    98:06:38:93:fb:bd:f2:75:70:05:18:db:7c:73:2a:
-                    86:bb:4a:bb:12:89:23:34:47:e7:d9:81:c4:4f:8b:
-                    dd:41:c2:5d:8b:94:c5:0d:4e:e1:0e:96:b9:13:ab:
-                    af:59:25:91:de:df:6d:6f:e8:a5:88:28:98:59:ad:
-                    98:a8:e7:71:ab:20:e7:fe:8f:a0:07:52:b1:0e:d8:
-                    9a:c8:d4:07:18:68:35:f7:fc:da:6a:0e:fa:de:c6:
-                    f8:49:81:40:bc:49:c5:7c:ff:e3:be:72:0d:e9:68:
-                    9d:0c:6e:9b:1d:3e:e8:50:96:f8:1d:a2:92:9a:ca:
-                    05:da:1b:91:ab:19:e7:08:98:a2:0b:ba:59:34:06:
-                    12:54:7b:84:2e:73:f1:4a:8b:3a:93:b2:53:e8:bb:
-                    a9:5f:f6:31:4f:dc:ca:6a:fe:3e:80:50:49:00:47:
-                    17:4d:71:8f:16:a4:de:54:bd:1f:6d:0c:45:42:09:
-                    3b:73:96:29:51:08:ea:23:3c:aa:0c:c6:01:a8:12:
-                    99:94:75:d5:a9:a2:3a:c1:90:c8:4e:05:95:10:96:
-                    c6:b0:8d:a8:dd:f7:57:ea:39:cd:ac:8a:f0:15:a6:
-                    32:7e:b0:b5:c0:ce:8c:3e:98:25:6d:61:43:cf:53:
-                    e6:30:36:7c:92:6f:80:01:aa:e6:3c:4c:d3:6b:7b:
-                    34:f3:a3:c0:d1:34:23:f2:a5:55:b5:ff:3a:3d:35:
-                    36:ce:0c:28:e2:7c:b9:9f:a8:28:a9:4f:12:66:8b:
-                    eb:bd:b0:b6:d6:35:d3:fb:bb:90:4b:0c:52:99:e5:
-                    d3:e2:dd:a6:18:49:55:02:e8:64:6a:32:aa:bb:b2:
-                    ca:c9:9f:d8:f5:a3:e6:03:c4:fc:3a:eb:ed:a9:3f:
-                    6c:fe:a5:af:36:77:2d:1d:b1:61:ce:a5:db:58:7b:
-                    8e:30:e9
+                    00:c3:f9:42:b8:f3:69:9a:24:45:ba:fa:ff:50:8c:
+                    4a:4f:20:11:1b:e4:ba:56:90:70:e6:2c:18:36:6f:
+                    4c:43:83:1a:42:d2:57:62:49:78:a7:6f:c6:50:95:
+                    cc:aa:3d:95:d0:2e:0e:0c:25:b2:0c:74:9e:ff:70:
+                    b9:e3:ed:bb:6f:89:81:7b:ff:32:fd:ef:5a:4b:77:
+                    64:1c:86:73:e0:7c:d7:bc:9f:ac:34:ca:a6:d0:5f:
+                    2d:66:10:63:ca:d2:11:de:9b:93:58:6c:94:ec:ef:
+                    d6:5f:0d:d4:07:75:99:a1:7e:20:eb:8d:3c:dc:04:
+                    eb:07:46:c3:5c:84:a7:47:8f:f7:af:36:c5:18:1b:
+                    b1:00:fb:23:03:a3:f3:b4:4c:be:d1:60:a7:58:c7:
+                    e5:70:f5:a1:e4:88:ee:cf:e4:17:33:83:a7:c4:0e:
+                    f3:87:5e:fd:a5:34:40:52:26:a1:46:ef:b2:04:11:
+                    0b:81:d8:e2:df:66:fd:ef:fe:dd:c7:66:2a:73:97:
+                    40:ae:22:11:b3:99:23:00:55:d4:62:1c:a1:cb:0b:
+                    52:5f:ba:e8:9b:71:74:4f:79:0c:6c:96:9d:ba:7f:
+                    20:fb:c3:cd:3f:3a:32:c5:60:f0:6c:50:88:8f:bb:
+                    0e:15:60:c9:8b:b8:d8:0b:80:05:ec:84:7e:69:d2:
+                    67:01
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Basic Constraints: 
@@ -58,14 +41,14 @@ Certificate:
             X509v3 Extended Key Usage: 
                 TLS Web Client Authentication, TLS Web Server Authentication
             X509v3 Subject Key Identifier: 
-                70:D2:9C:0D:EE:05:06:6B:86:D6:CA:79:0F:08:3D:A6:BF:F4:6C:C2
+                39:3A:53:CE:75:65:C6:92:D0:F3:29:6D:9A:F5:F2:D2:64:07:67:CA
             X509v3 Authority Key Identifier: 
                 keyid:C0:24:9A:D1:70:E0:B2:DF:75:E5:00:E2:7F:94:A1:01:87:20:DF:3E
                 DirName:/C=xx/O=test/OU=CA/CN=test certification authority
                 serial:19:02:8A:9B
 
             X509v3 Subject Alternative Name: 
-                DNS:server
+                DNS:server, DNS:localhost
             X509v3 Issuer Alternative Name: 
                 email:ca@example.org
             X509v3 CRL Distribution Points: 
@@ -73,69 +56,64 @@ Certificate:
                 Full Name:
                   URI:
 
-    Signature Algorithm: sha1WithRSAEncryption
-         27:38:16:00:29:27:7a:51:89:39:39:b5:83:47:86:1a:8b:cf:
-         12:e6:79:ca:f3:b3:c1:dc:0b:8d:3b:63:43:89:6e:9e:c2:43:
-         8c:95:0b:0f:d2:e8:91:11:96:56:68:99:61:39:00:da:11:f7:
-         e3:cd:d0:62:b8:b2:e1:e8:86:76:16:fd:2b:2b:93:f7:11:7c:
-         d1:72:ac:a3:c0:62:83:c1:f6:16:6e:73:21:08:ba:b0:03:cd:
-         70:47:13:6d:ea:6d:74:8d:2b:9e:e1:0b:d7:f7:5d:df:88:52:
-         2e:a2:8b:23:53:cb:02:fd:42:b4:e5:39:76:e8:85:20:12:f4:
-         36:d5:22:ca:21:93:d7:f9:aa:99:91:98:30:a8:3e:0b:7e:ee:
-         c8:d8:0c:ad:cc:49:32:f5:0f:c4:7d:cb:bb:41:29:ce:81:b6:
-         88:75:2c:97:1d:56:c6:a1:06:7a:3f:c3:01:8c:ce:ec:79:3a:
-         cf:53:d1:af:9d:f4:8d:61:c8:78:8c:13:73:9a:40:1d:b3:d9:
-         4a:28:64:34:2f:68:41:41:15:76:0a:4b:53:62:b9:ec:92:74:
-         ef:65:bc:8a:c0:50:72:4b:77:aa:71:76:55:d5:c3:df:90:bc:
-         90:c9:8f:f4:40:4e:60:d1:69:0a:34:07:71:b4:cd:a6:dd:ab:
-         14:bf:74:3e:e7:e0:ad:df:9b:5d:62:eb:fc:4f:35:fc:3a:33:
-         29:ca:80:cf:81:cd:e8:ec:e0:08:07:68:03:6e:b0:0d:ae:2a:
-         fe:c2:43:97:cb:d9:89:43:55:c7:29:a1:06:9e:ba:5a:da:01:
-         28:be:a7:39:df:0f:2b:36:ee:b0:99:4b:71:b3:a2:eb:54:56:
-         a1:a1:41:5e:1c:e9:05:f0:32:54:bf:20:9a:89:68:1a:17:5f:
-         b1:d3:1f:b4:c7:e5:de:94:d1:c4:e1:ae:33:a9:1b:7c:34:21:
-         24:38:70:85:bf:16:52:f4:73:df:5c:05:82:e3:23:78:6a:be:
-         fd:08:8d:5f:29:86:d5:99:44:48:cf:1f:3e:fd:4d:d2:9d:ad:
-         a6:27:83:56:64:17:43:bb:a4:4a:f2:fe:f5:c1:f1:28:2f:8b:
-         8c:09:6a:19:75:05:de:c8:aa:57:a7:0a:1a:ae:ca:e7:76:90:
-         5f:a7:41:06:fe:9f:3d:95:c9:da:f2:67:23:e0:71:ec:ea:12:
-         9f:1d:18:4c:65:b6:e9:10:1b:ca:85:41:8a:ba:ea:5f:21:a8:
-         23:c4:5f:ae:90:1c:f7:e6:a5:f2:6a:1b:42:aa:80:4a:f0:54:
-         1c:89:68:56:68:50:c8:70:bb:28:88:80:f4:03:0e:97:48:e6:
-         7c:34:0d:cc:92:55:1a:e3
+    Signature Algorithm: sha256WithRSAEncryption
+         c4:f6:02:42:ed:42:1e:69:09:f8:a5:a4:31:81:f5:2c:c8:d6:
+         fe:3a:6c:e1:81:cc:a1:d2:05:36:29:d7:84:cd:08:55:14:d3:
+         b8:88:4f:12:e9:6b:40:96:0e:f4:93:63:ad:6d:ce:88:fc:8f:
+         a2:6e:e4:99:a8:a7:0b:95:2c:07:24:e3:8e:01:4b:27:fb:ec:
+         4f:27:de:21:16:d0:e3:27:a5:a2:1e:f0:46:97:90:31:bd:df:
+         4a:27:85:06:1f:7f:40:dd:45:ee:93:45:eb:c4:87:d4:5d:07:
+         e2:03:9f:fa:ff:b3:8d:37:fd:07:18:61:1d:43:8f:84:0e:9b:
+         e7:87:91:9d:f9:0f:35:45:eb:ea:7a:e0:4d:cf:33:4e:6a:31:
+         94:e4:1b:2d:88:5b:27:da:48:4c:28:02:8e:71:0d:f2:b2:f9:
+         05:77:ac:33:42:7a:a4:7a:b4:57:32:e5:67:7a:66:d7:3e:1d:
+         9c:3d:af:ae:10:5d:e4:2f:37:0f:fc:26:9e:66:c5:c5:3e:a8:
+         6e:19:10:ed:57:73:96:a1:71:8d:55:51:0c:ec:83:62:99:29:
+         4f:64:0a:fb:bd:68:34:61:3c:48:4d:44:bd:6d:c6:77:b5:f7:
+         70:bf:fc:19:df:ad:c1:e1:aa:f4:c0:50:ee:c4:58:d1:29:1f:
+         a1:c7:d4:41:0b:98:7f:f4:97:51:6e:91:50:2e:e2:3d:17:cb:
+         2f:b9:d7:9b:4b:0e:a7:20:f7:ad:a5:96:b0:e6:3e:ce:87:65:
+         90:3f:0e:f6:73:0c:21:3a:56:43:f0:dd:62:59:23:d3:e2:75:
+         8a:71:96:52:da:ad:9b:6f:70:a7:0f:16:a5:89:25:f2:5f:e5:
+         1c:2c:1a:b3:fa:43:6a:59:0e:4d:c7:b9:8d:67:fd:ea:a6:71:
+         92:46:f5:a7:d3:72:5c:ee:d8:35:47:ec:56:d5:23:a7:0e:f8:
+         25:46:83:0d:b6:c3:db:7d:14:ff:75:2f:70:2f:28:7b:80:77:
+         dc:41:c6:9d:0d:61:0a:9e:05:2f:91:69:b7:b3:6c:18:01:e6:
+         60:ab:23:56:b1:a1:76:5c:3d:00:14:ba:52:9a:ad:fa:34:21:
+         f8:33:eb:e4:19:85:01:14:27:6d:fc:59:e0:17:aa:d5:ea:72:
+         5c:ff:20:32:65:14:4b:b7:91:69:c9:29:74:13:73:06:12:55:
+         94:cc:0d:2f:a2:f4:91:e9:95:c9:5c:2a:c8:4c:8a:4f:b9:07:
+         74:e3:dc:b6:09:ce:0d:63:06:24:d7:ed:a9:1e:b7:55:2a:da:
+         bf:df:80:48:bf:6e:a1:e8:f8:c5:4f:90:5a:a2:59:1f:4d:6d:
+         4d:83:9a:15:97:96:0d:10
 -----BEGIN CERTIFICATE-----
-MIIGNTCCBB2gAwIBAgIEGQKKnTANBgkqhkiG9w0BAQUFADBQMQswCQYDVQQGEwJ4
+MIIFQDCCAyigAwIBAgIEGQKKnjANBgkqhkiG9w0BAQsFADBQMQswCQYDVQQGEwJ4
 eDENMAsGA1UEChMEdGVzdDELMAkGA1UECxMCQ0ExJTAjBgNVBAMTHHRlc3QgY2Vy
-dGlmaWNhdGlvbiBhdXRob3JpdHkwHhcNMTQwNjE4MjIyNzA5WhcNMjQwNjE1MjIy
-NzA5WjA6MQswCQYDVQQGEwJ4eDENMAsGA1UEChMEdGVzdDELMAkGA1UECxMCQ0Ex
-DzANBgNVBAMTBnNlcnZlcjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIB
-ALFhLRP9dL5k41JUPSJsV6mbrQ2D70bldRyHw1QiNfRHoo68b+NQOt2Dhz0CNbtp
-viZEiQsOnAtaTRP1dYH+8+ZAdzwWXfUUKGtS0nzkpgbTYhoExSUaCcoI94pK0Xol
-94R24Fh9cpvmrxNe5iwTEPMJ/4TPd9ivqijWL/RIqHQlfWmT9GofhAaLBzOFNzQ0
-Zfi8p/CAqezju+wY9Eda6eiXasH/mAY4k/u98nVwBRjbfHMqhrtKuxKJIzRH59mB
-xE+L3UHCXYuUxQ1O4Q6WuROrr1klkd7fbW/opYgomFmtmKjncasg5/6PoAdSsQ7Y
-msjUBxhoNff82moO+t7G+EmBQLxJxXz/475yDelonQxumx0+6FCW+B2ikprKBdob
-kasZ5wiYogu6WTQGElR7hC5z8UqLOpOyU+i7qV/2MU/cymr+PoBQSQBHF01xjxak
-3lS9H20MRUIJO3OWKVEI6iM8qgzGAagSmZR11amiOsGQyE4FlRCWxrCNqN33V+o5
-zayK8BWmMn6wtcDOjD6YJW1hQ89T5jA2fJJvgAGq5jxM02t7NPOjwNE0I/KlVbX/
-Oj01Ns4MKOJ8uZ+oKKlPEmaL672wttY10/u7kEsMUpnl0+LdphhJVQLoZGoyqruy
-ysmf2PWj5gPE/Drr7ak/bP6lrzZ3LR2xYc6l21h7jjDpAgMBAAGjggErMIIBJzAJ
-BgNVHRMEAjAAMBEGCWCGSAGG+EIBAQQEAwIGwDALBgNVHQ8EBAMCBeAwHQYDVR0l
-BBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMB0GA1UdDgQWBBRw0pwN7gUGa4bWynkP
-CD2mv/RswjB7BgNVHSMEdDBygBTAJJrRcOCy33XlAOJ/lKEBhyDfPqFUpFIwUDEL
-MAkGA1UEBhMCeHgxDTALBgNVBAoTBHRlc3QxCzAJBgNVBAsTAkNBMSUwIwYDVQQD
-Exx0ZXN0IGNlcnRpZmljYXRpb24gYXV0aG9yaXR5ggQZAoqbMBEGA1UdEQQKMAiC
-BnNlcnZlcjAZBgNVHRIEEjAQgQ5jYUBleGFtcGxlLm9yZzARBgNVHR8ECjAIMAag
-BKAChgAwDQYJKoZIhvcNAQEFBQADggIBACc4FgApJ3pRiTk5tYNHhhqLzxLmecrz
-s8HcC407Y0OJbp7CQ4yVCw/S6JERllZomWE5ANoR9+PN0GK4suHohnYW/Ssrk/cR
-fNFyrKPAYoPB9hZucyEIurADzXBHE23qbXSNK57hC9f3Xd+IUi6iiyNTywL9QrTl
-OXbohSAS9DbVIsohk9f5qpmRmDCoPgt+7sjYDK3MSTL1D8R9y7tBKc6Btoh1LJcd
-VsahBno/wwGMzux5Os9T0a+d9I1hyHiME3OaQB2z2UooZDQvaEFBFXYKS1NiueyS
-dO9lvIrAUHJLd6pxdlXVw9+QvJDJj/RATmDRaQo0B3G0zabdqxS/dD7n4K3fm11i
-6/xPNfw6MynKgM+Bzejs4AgHaANusA2uKv7CQ5fL2YlDVccpoQaeulraASi+pznf
-Dys27rCZS3GzoutUVqGhQV4c6QXwMlS/IJqJaBoXX7HTH7TH5d6U0cThrjOpG3w0
-ISQ4cIW/FlL0c99cBYLjI3hqvv0IjV8phtWZREjPHz79TdKdraYng1ZkF0O7pEry
-/vXB8Sgvi4wJahl1Bd7IqlenChquyud2kF+nQQb+nz2VydryZyPgcezqEp8dGExl
-tukQG8qFQYq66l8hqCPEX66QHPfmpfJqG0KqgErwVByJaFZoUMhwuyiIgPQDDpdI
-5nw0DcySVRrj
+dGlmaWNhdGlvbiBhdXRob3JpdHkwHhcNMTYxMDAyMTU1NDA4WhcNMjYwOTMwMTU1
+NDA4WjA6MQswCQYDVQQGEwJ4eDENMAsGA1UEChMEdGVzdDELMAkGA1UECxMCQ0Ex
+DzANBgNVBAMTBnNlcnZlcjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
+AMP5QrjzaZokRbr6/1CMSk8gERvkulaQcOYsGDZvTEODGkLSV2JJeKdvxlCVzKo9
+ldAuDgwlsgx0nv9wuePtu2+JgXv/Mv3vWkt3ZByGc+B817yfrDTKptBfLWYQY8rS
+Ed6bk1hslOzv1l8N1Ad1maF+IOuNPNwE6wdGw1yEp0eP9682xRgbsQD7IwOj87RM
+vtFgp1jH5XD1oeSI7s/kFzODp8QO84de/aU0QFImoUbvsgQRC4HY4t9m/e/+3cdm
+KnOXQK4iEbOZIwBV1GIcocsLUl+66JtxdE95DGyWnbp/IPvDzT86MsVg8GxQiI+7
+DhVgyYu42AuABeyEfmnSZwECAwEAAaOCATYwggEyMAkGA1UdEwQCMAAwEQYJYIZI
+AYb4QgEBBAQDAgbAMAsGA1UdDwQEAwIF4DAdBgNVHSUEFjAUBggrBgEFBQcDAgYI
+KwYBBQUHAwEwHQYDVR0OBBYEFDk6U851ZcaS0PMpbZr18tJkB2fKMHsGA1UdIwR0
+MHKAFMAkmtFw4LLfdeUA4n+UoQGHIN8+oVSkUjBQMQswCQYDVQQGEwJ4eDENMAsG
+A1UEChMEdGVzdDELMAkGA1UECxMCQ0ExJTAjBgNVBAMTHHRlc3QgY2VydGlmaWNh
+dGlvbiBhdXRob3JpdHmCBBkCipswHAYDVR0RBBUwE4IGc2VydmVygglsb2NhbGhv
+c3QwGQYDVR0SBBIwEIEOY2FAZXhhbXBsZS5vcmcwEQYDVR0fBAowCDAGoASgAoYA
+MA0GCSqGSIb3DQEBCwUAA4ICAQDE9gJC7UIeaQn4paQxgfUsyNb+Omzhgcyh0gU2
+KdeEzQhVFNO4iE8S6WtAlg70k2Otbc6I/I+ibuSZqKcLlSwHJOOOAUsn++xPJ94h
+FtDjJ6WiHvBGl5Axvd9KJ4UGH39A3UXuk0XrxIfUXQfiA5/6/7ONN/0HGGEdQ4+E
+Dpvnh5Gd+Q81RevqeuBNzzNOajGU5BstiFsn2khMKAKOcQ3ysvkFd6wzQnqkerRX
+MuVnembXPh2cPa+uEF3kLzcP/CaeZsXFPqhuGRDtV3OWoXGNVVEM7INimSlPZAr7
+vWg0YTxITUS9bcZ3tfdwv/wZ363B4ar0wFDuxFjRKR+hx9RBC5h/9JdRbpFQLuI9
+F8svudebSw6nIPetpZaw5j7Oh2WQPw72cwwhOlZD8N1iWSPT4nWKcZZS2q2bb3Cn
+DxaliSXyX+UcLBqz+kNqWQ5Nx7mNZ/3qpnGSRvWn03Jc7tg1R+xW1SOnDvglRoMN
+tsPbfRT/dS9wLyh7gHfcQcadDWEKngUvkWm3s2wYAeZgqyNWsaF2XD0AFLpSmq36
+NCH4M+vkGYUBFCdt/FngF6rV6nJc/yAyZRRLt5FpySl0E3MGElWUzA0vovSR6ZXJ
+XCrITIpPuQd049y2Cc4NYwYk1+2pHrdVKtq/34BIv26h6PjFT5BaolkfTW1Ng5oV
+l5YNEA==
 -----END CERTIFICATE-----
diff --git a/authserv/test/testca/serial b/authserv/test/testca/serial
index 3ff0d5f2ab9d6c511eb8c2749d66fdf0bf07ac88..b0f4647556adffef5ca2ef836ea83f8378958260 100644
--- a/authserv/test/testca/serial
+++ b/authserv/test/testca/serial
@@ -1 +1 @@
-19028A9E
+19028A9F
diff --git a/authserv/test/testca/serial.old b/authserv/test/testca/serial.old
index e63189e135d886b8b983468784b015c2a6ef0800..3ff0d5f2ab9d6c511eb8c2749d66fdf0bf07ac88 100644
--- a/authserv/test/testca/serial.old
+++ b/authserv/test/testca/serial.old
@@ -1 +1 @@
-19028A9D
+19028A9E
diff --git a/authserv/test/testca/testca.conf b/authserv/test/testca/testca.conf
index f48d3831d67a0854c7f8bf254bbe4538b540402c..4015a3c9ad16322437bab990a1abdd34b076ec9f 100644
--- a/authserv/test/testca/testca.conf
+++ b/authserv/test/testca/testca.conf
@@ -13,4 +13,5 @@ usage = client
 
 [server]
 cn = server
+alt_names = localhost
 usage = server