<ConstraintsParameters Name="Certificate policy TL based" xmlns="http://dss.esig.europa.eu/validation/policy">
    <Description>Validates electronic certificates and indicates its qualification status at issuance and validation time.
        All certificates and their related chains are validated against the EU Member State Trusted Lists and
        third country Trusted Lists with voluntary-based AdES recognition (this includes target certificate and
        certificates used to validate certificate validity status services - CRLs, OCSP).
    </Description>
    <SignatureConstraints>
        <BasicSignatureConstraints>
            <ProspectiveCertificateChain Level="FAIL" />
            <SigningCertificate>
                <Recognition Level="FAIL" />
                <Signature Level="FAIL" />
                <NotExpired Level="FAIL" />
                <SunsetDate Level="FAIL" />
                <RevocationDataSkip Level="INFORM">
                    <CertificateExtensions>
                        <Id>0.4.0.194121.2.1</Id> <!-- valassured-ST-certs -->
                        <Id>2.5.29.56</Id> <!-- noRevAvail -->
                    </CertificateExtensions>
                </RevocationDataSkip>
                <RevocationDataAvailable Level="FAIL" />
                <AcceptableRevocationDataFound Level="FAIL" />
                <CRLNextUpdatePresent Level="WARN" />
                <RevocationFreshness Level="IGNORE" Unit="DAYS" Value="0" />
                <KeyUsage Level="WARN">
                    <Id>*</Id>
                </KeyUsage>
                <PolicyTree Level="WARN" />
                <NameConstraints Level="WARN" />
                <AuthorityKeyIdentifierPresent Level="WARN" />
                <NoRevAvail Level="WARN" />
                <SupportedCriticalExtensions Level="WARN">
                    <Id>2.5.29.15</Id> <!-- keyUsage -->
                    <Id>2.5.29.32</Id> <!-- certificatePolicies -->
                    <Id>2.5.29.17</Id> <!-- subjectAlternativeName -->
                    <Id>2.5.29.19</Id> <!-- basicConstraints -->
                    <Id>2.5.29.30</Id> <!-- nameConstraints -->
                    <Id>2.5.29.36</Id> <!-- policyConstraints -->
                    <Id>2.5.29.37</Id> <!-- extendedKeyUsage -->
                    <Id>2.5.29.31</Id> <!-- CRLDistributionPoints -->
                    <Id>2.5.29.54</Id> <!-- inhibitAnyPolicy -->
                    <Id>1.3.6.1.5.5.7.1.3</Id> <!-- QCStatements -->
                    <Id>1.3.6.1.5.5.7.48.1.5</Id> <!-- ocsp_noCheck -->
                    <!-- policyMappings 2.5.29.33 not supported -->
                </SupportedCriticalExtensions>
                <IssuerName Level="FAIL" />
                <SerialNumberPresent Level="WARN" />
                <NotRevoked Level="FAIL" />
                <NotOnHold Level="FAIL" />
                <RevocationIssuerNotExpired Level="FAIL" />
                <NotSelfSigned Level="INFORM" />
                <UsePseudonym Level="INFORM" />
                <Cryptographic />
            </SigningCertificate>
            <CACertificate>
                <Signature Level="FAIL" />
                <NotExpired Level="FAIL" />
                <SunsetDate Level="FAIL" />
                <RevocationDataAvailable Level="FAIL" />
                <AcceptableRevocationDataFound Level="FAIL" />
                <CRLNextUpdatePresent Level="WARN" />
                <RevocationFreshness Level="IGNORE" Unit="DAYS" Value="0" />
                <CA Level="FAIL" />
                <MaxPathLength Level="FAIL" />
                <KeyUsage Level="FAIL">
                    <Id>keyCertSign</Id>
                </KeyUsage>
                <PolicyTree Level="WARN" />
                <NameConstraints Level="WARN" />
                <AuthorityKeyIdentifierPresent Level="WARN" />
                <SubjectKeyIdentifierPresent Level="FAIL" />
                <SupportedCriticalExtensions Level="WARN">
                    <Id>2.5.29.15</Id> <!-- keyUsage -->
                    <Id>2.5.29.32</Id> <!-- certificatePolicies -->
                    <Id>2.5.29.17</Id> <!-- subjectAlternativeName -->
                    <Id>2.5.29.19</Id> <!-- basicConstraints -->
                    <Id>2.5.29.30</Id> <!-- nameConstraints -->
                    <Id>2.5.29.36</Id> <!-- policyConstraints -->
                    <Id>2.5.29.37</Id> <!-- extendedKeyUsage -->
                    <Id>2.5.29.31</Id> <!-- CRLDistributionPoints -->
                    <Id>2.5.29.54</Id> <!-- inhibitAnyPolicy -->
                    <Id>1.3.6.1.5.5.7.1.3</Id> <!-- QCStatements -->
                    <!-- policyMappings 2.5.29.33 not supported -->
                </SupportedCriticalExtensions>
                <ForbiddenExtensions Level="FAIL">
                    <Id>1.3.6.1.5.5.7.48.1.5</Id> <!-- ocsp_noCheck -->
                    <Id>2.5.29.56</Id> <!-- noRevAvail -->
                </ForbiddenExtensions>
                <IssuerName Level="FAIL" />
                <NotRevoked Level="FAIL" />
                <NotOnHold Level="FAIL" />
                <Cryptographic />
            </CACertificate>
            <Cryptographic />
        </BasicSignatureConstraints>
    </SignatureConstraints>
    <Revocation>
        <UnknownStatus Level="FAIL" />
        <ThisUpdatePresent Level="FAIL" />
        <RevocationIssuerKnown Level="FAIL" />
        <RevocationIssuerValidAtProductionTime Level="FAIL" />
        <RevocationAfterCertificateIssuance Level="FAIL" />
        <RevocationHasInformationAboutCertificate Level="FAIL" />
        <OCSPResponderIdMatch Level="FAIL" />
        <SelfIssuedOCSP Level="WARN" />
        <BasicSignatureConstraints>
            <ReferenceDataExistence Level="FAIL" />
            <ReferenceDataIntact Level="FAIL" />
            <SignatureIntact Level="FAIL" />
            <ProspectiveCertificateChain Level="FAIL" />
            <SigningCertificate>
                <Recognition Level="FAIL" />
                <Signature Level="FAIL" />
                <NotExpired Level="FAIL" />
                <SunsetDate Level="FAIL" />
                <RevocationDataSkip Level="IGNORE">
                    <CertificateExtensions>
                        <Id>1.3.6.1.5.5.7.48.1.5</Id> <!-- ocsp_noCheck -->
                    </CertificateExtensions>
                </RevocationDataSkip>
                <RevocationDataAvailable Level="FAIL" />
                <AcceptableRevocationDataFound Level="FAIL" />
                <CRLNextUpdatePresent Level="WARN" />
                <RevocationFreshness Level="IGNORE" Unit="DAYS" Value="0" />
                <PolicyTree Level="WARN" />
                <NameConstraints Level="WARN" />
                <AuthorityKeyIdentifierPresent Level="WARN" />
                <SupportedCriticalExtensions Level="WARN">
                    <Id>2.5.29.15</Id> <!-- keyUsage -->
                    <Id>2.5.29.32</Id> <!-- certificatePolicies -->
                    <Id>2.5.29.17</Id> <!-- subjectAlternativeName -->
                    <Id>2.5.29.19</Id> <!-- basicConstraints -->
                    <Id>2.5.29.30</Id> <!-- nameConstraints -->
                    <Id>2.5.29.36</Id> <!-- policyConstraints -->
                    <Id>2.5.29.37</Id> <!-- extendedKeyUsage -->
                    <Id>2.5.29.31</Id> <!-- CRLDistributionPoints -->
                    <Id>2.5.29.54</Id> <!-- inhibitAnyPolicy -->
                    <Id>1.3.6.1.5.5.7.1.3</Id> <!-- QCStatements -->
                    <Id>1.3.6.1.5.5.7.48.1.5</Id> <!-- ocsp_noCheck -->
                    <!-- policyMappings 2.5.29.33 not supported -->
                </SupportedCriticalExtensions>
                <IssuerName Level="FAIL" />
                <NotRevoked Level="FAIL" />
                <NotOnHold Level="FAIL" />
                <Cryptographic />
            </SigningCertificate>
            <CACertificate>
                <Signature Level="FAIL" />
                <NotExpired Level="FAIL" />
                <SunsetDate Level="FAIL" />
                <RevocationDataAvailable Level="WARN" />
                <AcceptableRevocationDataFound Level="WARN" />
                <CRLNextUpdatePresent Level="WARN" />
                <RevocationFreshness Level="IGNORE" Unit="DAYS" Value="0" />
                <CA Level="FAIL" />
                <MaxPathLength Level="FAIL" />
                <KeyUsage Level="FAIL">
                    <Id>keyCertSign</Id>
                </KeyUsage>
                <PolicyTree Level="WARN" />
                <NameConstraints Level="WARN" />
                <AuthorityKeyIdentifierPresent Level="WARN" />
                <SubjectKeyIdentifierPresent Level="FAIL" />
                <SupportedCriticalExtensions Level="WARN">
                    <Id>2.5.29.15</Id> <!-- keyUsage -->
                    <Id>2.5.29.32</Id> <!-- certificatePolicies -->
                    <Id>2.5.29.17</Id> <!-- subjectAlternativeName -->
                    <Id>2.5.29.19</Id> <!-- basicConstraints -->
                    <Id>2.5.29.30</Id> <!-- nameConstraints -->
                    <Id>2.5.29.36</Id> <!-- policyConstraints -->
                    <Id>2.5.29.37</Id> <!-- extendedKeyUsage -->
                    <Id>2.5.29.31</Id> <!-- CRLDistributionPoints -->
                    <Id>2.5.29.54</Id> <!-- inhibitAnyPolicy -->
                    <Id>1.3.6.1.5.5.7.1.3</Id> <!-- QCStatements -->
                    <!-- policyMappings 2.5.29.33 not supported -->
                </SupportedCriticalExtensions>
                <ForbiddenExtensions Level="FAIL">
                    <Id>1.3.6.1.5.5.7.48.1.5</Id> <!-- ocsp_noCheck -->
                    <Id>2.5.29.56</Id> <!-- noRevAvail -->
                </ForbiddenExtensions>
                <IssuerName Level="FAIL" />
                <NotRevoked Level="FAIL" />
                <NotOnHold Level="FAIL" />
                <Cryptographic />
            </CACertificate>
            <Cryptographic />
        </BasicSignatureConstraints>
    </Revocation>
    <EvidenceRecord>
        <DataObjectExistence Level="FAIL" />
        <DataObjectIntact Level="FAIL" />
        <DataObjectFound Level="FAIL" />
        <DataObjectGroup Level="WARN" />
        <SignedFilesCovered Level="WARN" />
        <ContainerSignedAndTimestampedFilesCovered Level="WARN" />
        <HashTreeRenewal Level="FAIL" />
        <Cryptographic />
    </EvidenceRecord>
    <Cryptographic Level="FAIL">
        <AcceptableEncryptionAlgo>
            <Algo>RSA</Algo>
            <Algo>RSASSA-PSS</Algo>
            <Algo>DSA</Algo>
            <Algo>ECDSA</Algo>
            <Algo>PLAIN-ECDSA</Algo>
            <!-- 		<Algo>EdDSA</Algo> 				Not referenced in ETSI/SOGIS -->
        </AcceptableEncryptionAlgo>
        <MiniPublicKeySize>
            <Algo Size="1024">DSA</Algo>
            <Algo Size="786">RSA</Algo>
            <Algo Size="786">RSASSA-PSS</Algo>
            <Algo Size="160">ECDSA</Algo>
            <Algo Size="160">PLAIN-ECDSA</Algo>
            <!-- 		<Algo Size="24">EdDSA</Algo> 		Not referenced in ETSI/SOGIS -->
        </MiniPublicKeySize>
        <AcceptableDigestAlgo>
            <!--		<Algo>MD2</Algo> 		Not referenced in ETSI/SOGIS -->
            <Algo>MD5</Algo>
            <Algo>SHA1</Algo>
            <Algo>SHA224</Algo>
            <Algo>SHA256</Algo>
            <Algo>SHA384</Algo>
            <Algo>SHA512</Algo>
            <!--		<Algo>SHA3-224</Algo> 		Not referenced in ETSI/SOGIS -->
            <Algo>SHA3-256</Algo>
            <Algo>SHA3-384</Algo>
            <Algo>SHA3-512</Algo>
            <Algo>RIPEMD160</Algo>
            <Algo>WHIRLPOOL</Algo>
        </AcceptableDigestAlgo>
        <AlgoExpirationDate Level="FAIL" Format="yyyy-MM-dd" UpdateDate="2024-10-13" LevelAfterUpdate="WARN">
            <!-- Digest algorithms -->
            <Algo Date="2004-08-01">MD5</Algo> <!-- ETSI TS 102 176-1 (Historical) V2.1.1 -->
            <Algo Date="2012-08-01">SHA1</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2029-01-01">SHA224</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo>SHA256</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo>SHA384</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo>SHA512</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo>SHA3-256</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo>SHA3-384</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo>SHA3-512</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo Date="2014-08-01">RIPEMD160</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2020-12-01">WHIRLPOOL</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <!-- end Digest algorithms -->
            <!-- Encryption algorithms -->
            <Algo Date="2015-12-01" Size="1024">DSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2029-01-01" Size="1900">DSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Size="3000">DSA</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo Date="2010-08-01" Size="786">RSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2019-10-01" Size="1024">RSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2019-10-01" Size="1536">RSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2029-01-01" Size="1900">RSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2029-01-01" Size="3000">RSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2010-08-01" Size="786">RSASSA-PSS</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2019-10-01" Size="1024">RSASSA-PSS</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2019-10-01" Size="1536">RSASSA-PSS</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2029-01-01" Size="1900">RSASSA-PSS</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Size="3000">RSASSA-PSS</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo Date="2012-08-01" Size="160">ECDSA</Algo> <!-- ETSI TS 102 176-1 (Historical) V2.1.1 -->
            <Algo Date="2012-08-01" Size="163">ECDSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2021-10-01" Size="224">ECDSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Size="256">ECDSA</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <Algo Date="2012-08-01" Size="160">PLAIN-ECDSA</Algo> <!-- ETSI TS 102 176-1 (Historical) V2.1.1 -->
            <Algo Date="2012-08-01" Size="163">PLAIN-ECDSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Date="2021-10-01" Size="224">PLAIN-ECDSA</Algo> <!-- ETSI TS 119 312 v1.5.1 -->
            <Algo Size="256">PLAIN-ECDSA</Algo> <!-- ETSI TS 119 312 v1.5.1 --> <!-- R -->
            <!-- end Encryption algorithms -->
        </AlgoExpirationDate>
    </Cryptographic>

    <Model Value="SHELL" />

    <!-- eIDAS REGL 910/EU/2014 -->
    <eIDAS>
        <TLFreshness Level="WARN" Unit="HOURS" Value="6" />
        <TLNotExpired Level="WARN" />
        <TLWellSigned Level="WARN" />
        <TLVersion Level="FAIL">
            <Id>5</Id>
            <Id>6</Id>
        </TLVersion>
        <TLStructure Level="WARN" />
    </eIDAS>
</ConstraintsParameters>
