This tool validates a certificate chain using X509 standard rules. Along with signature validation, it checks the following extensions: Basic Constraints, Key Usage, Policy Constraints, and Inhibit Any Policy. If the end entity certificate has alternate signature extensions it uses the signer certifcate's SubjectAltPublicKeyInfo extension to validate the alternate signature.