/*
 * Copyright 2020 Google LLC
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     https://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
// Generated by the protocol buffer compiler.  DO NOT EDIT!
// source: google/cloud/security/privateca/v1/resources.proto

package com.google.cloud.security.privateca.v1;

/**
 *
 *
 * <pre>
 * Describes a set of X.509 extensions that may be part of some certificate
 * issuance controls.
 * </pre>
 *
 * Protobuf type {@code google.cloud.security.privateca.v1.CertificateExtensionConstraints}
 */
public final class CertificateExtensionConstraints extends com.google.protobuf.GeneratedMessageV3
    implements
    // @@protoc_insertion_point(message_implements:google.cloud.security.privateca.v1.CertificateExtensionConstraints)
    CertificateExtensionConstraintsOrBuilder {
  private static final long serialVersionUID = 0L;
  // Use CertificateExtensionConstraints.newBuilder() to construct.
  private CertificateExtensionConstraints(
      com.google.protobuf.GeneratedMessageV3.Builder<?> builder) {
    super(builder);
  }

  private CertificateExtensionConstraints() {
    knownExtensions_ = java.util.Collections.emptyList();
    additionalExtensions_ = java.util.Collections.emptyList();
  }

  @java.lang.Override
  @SuppressWarnings({"unused"})
  protected java.lang.Object newInstance(UnusedPrivateParameter unused) {
    return new CertificateExtensionConstraints();
  }

  @java.lang.Override
  public final com.google.protobuf.UnknownFieldSet getUnknownFields() {
    return this.unknownFields;
  }

  public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
    return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
        .internal_static_google_cloud_security_privateca_v1_CertificateExtensionConstraints_descriptor;
  }

  @java.lang.Override
  protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
      internalGetFieldAccessorTable() {
    return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
        .internal_static_google_cloud_security_privateca_v1_CertificateExtensionConstraints_fieldAccessorTable
        .ensureFieldAccessorsInitialized(
            com.google.cloud.security.privateca.v1.CertificateExtensionConstraints.class,
            com.google.cloud.security.privateca.v1.CertificateExtensionConstraints.Builder.class);
  }

  /**
   *
   *
   * <pre>
   * Describes well-known X.509 extensions that can appear in a
   * [Certificate][google.cloud.security.privateca.v1.Certificate], not
   * including the
   * [SubjectAltNames][google.cloud.security.privateca.v1.SubjectAltNames]
   * extension.
   * </pre>
   *
   * Protobuf enum {@code
   * google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension}
   */
  public enum KnownCertificateExtension implements com.google.protobuf.ProtocolMessageEnum {
    /**
     *
     *
     * <pre>
     * Not specified.
     * </pre>
     *
     * <code>KNOWN_CERTIFICATE_EXTENSION_UNSPECIFIED = 0;</code>
     */
    KNOWN_CERTIFICATE_EXTENSION_UNSPECIFIED(0),
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Key Usage extension, as described in [RFC 5280
     * section 4.2.1.3](https://tools.ietf.org/html/rfc5280#section-4.2.1.3).
     * This corresponds to the
     * [KeyUsage.base_key_usage][google.cloud.security.privateca.v1.KeyUsage.base_key_usage]
     * field.
     * </pre>
     *
     * <code>BASE_KEY_USAGE = 1;</code>
     */
    BASE_KEY_USAGE(1),
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Extended Key Usage extension, as described in
     * [RFC 5280
     * section 4.2.1.12](https://tools.ietf.org/html/rfc5280#section-4.2.1.12).
     * This corresponds to the
     * [KeyUsage.extended_key_usage][google.cloud.security.privateca.v1.KeyUsage.extended_key_usage]
     * message.
     * </pre>
     *
     * <code>EXTENDED_KEY_USAGE = 2;</code>
     */
    EXTENDED_KEY_USAGE(2),
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Basic Constraints extension, as described in
     * [RFC 5280
     * section 4.2.1.9](https://tools.ietf.org/html/rfc5280#section-4.2.1.9).
     * This corresponds to the
     * [X509Parameters.ca_options][google.cloud.security.privateca.v1.X509Parameters.ca_options]
     * field.
     * </pre>
     *
     * <code>CA_OPTIONS = 3;</code>
     */
    CA_OPTIONS(3),
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Policy object identifiers, as described in
     * [RFC 5280
     * section 4.2.1.4](https://tools.ietf.org/html/rfc5280#section-4.2.1.4).
     * This corresponds to the
     * [X509Parameters.policy_ids][google.cloud.security.privateca.v1.X509Parameters.policy_ids]
     * field.
     * </pre>
     *
     * <code>POLICY_IDS = 4;</code>
     */
    POLICY_IDS(4),
    /**
     *
     *
     * <pre>
     * Refers to OCSP servers in a certificate's Authority Information Access
     * extension, as described in
     * [RFC 5280
     * section 4.2.2.1](https://tools.ietf.org/html/rfc5280#section-4.2.2.1),
     * This corresponds to the
     * [X509Parameters.aia_ocsp_servers][google.cloud.security.privateca.v1.X509Parameters.aia_ocsp_servers]
     * field.
     * </pre>
     *
     * <code>AIA_OCSP_SERVERS = 5;</code>
     */
    AIA_OCSP_SERVERS(5),
    /**
     *
     *
     * <pre>
     * Refers to Name Constraints extension as described in
     * [RFC 5280
     * section 4.2.1.10](https://tools.ietf.org/html/rfc5280#section-4.2.1.10)
     * </pre>
     *
     * <code>NAME_CONSTRAINTS = 6;</code>
     */
    NAME_CONSTRAINTS(6),
    UNRECOGNIZED(-1),
    ;

    /**
     *
     *
     * <pre>
     * Not specified.
     * </pre>
     *
     * <code>KNOWN_CERTIFICATE_EXTENSION_UNSPECIFIED = 0;</code>
     */
    public static final int KNOWN_CERTIFICATE_EXTENSION_UNSPECIFIED_VALUE = 0;
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Key Usage extension, as described in [RFC 5280
     * section 4.2.1.3](https://tools.ietf.org/html/rfc5280#section-4.2.1.3).
     * This corresponds to the
     * [KeyUsage.base_key_usage][google.cloud.security.privateca.v1.KeyUsage.base_key_usage]
     * field.
     * </pre>
     *
     * <code>BASE_KEY_USAGE = 1;</code>
     */
    public static final int BASE_KEY_USAGE_VALUE = 1;
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Extended Key Usage extension, as described in
     * [RFC 5280
     * section 4.2.1.12](https://tools.ietf.org/html/rfc5280#section-4.2.1.12).
     * This corresponds to the
     * [KeyUsage.extended_key_usage][google.cloud.security.privateca.v1.KeyUsage.extended_key_usage]
     * message.
     * </pre>
     *
     * <code>EXTENDED_KEY_USAGE = 2;</code>
     */
    public static final int EXTENDED_KEY_USAGE_VALUE = 2;
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Basic Constraints extension, as described in
     * [RFC 5280
     * section 4.2.1.9](https://tools.ietf.org/html/rfc5280#section-4.2.1.9).
     * This corresponds to the
     * [X509Parameters.ca_options][google.cloud.security.privateca.v1.X509Parameters.ca_options]
     * field.
     * </pre>
     *
     * <code>CA_OPTIONS = 3;</code>
     */
    public static final int CA_OPTIONS_VALUE = 3;
    /**
     *
     *
     * <pre>
     * Refers to a certificate's Policy object identifiers, as described in
     * [RFC 5280
     * section 4.2.1.4](https://tools.ietf.org/html/rfc5280#section-4.2.1.4).
     * This corresponds to the
     * [X509Parameters.policy_ids][google.cloud.security.privateca.v1.X509Parameters.policy_ids]
     * field.
     * </pre>
     *
     * <code>POLICY_IDS = 4;</code>
     */
    public static final int POLICY_IDS_VALUE = 4;
    /**
     *
     *
     * <pre>
     * Refers to OCSP servers in a certificate's Authority Information Access
     * extension, as described in
     * [RFC 5280
     * section 4.2.2.1](https://tools.ietf.org/html/rfc5280#section-4.2.2.1),
     * This corresponds to the
     * [X509Parameters.aia_ocsp_servers][google.cloud.security.privateca.v1.X509Parameters.aia_ocsp_servers]
     * field.
     * </pre>
     *
     * <code>AIA_OCSP_SERVERS = 5;</code>
     */
    public static final int AIA_OCSP_SERVERS_VALUE = 5;
    /**
     *
     *
     * <pre>
     * Refers to Name Constraints extension as described in
     * [RFC 5280
     * section 4.2.1.10](https://tools.ietf.org/html/rfc5280#section-4.2.1.10)
     * </pre>
     *
     * <code>NAME_CONSTRAINTS = 6;</code>
     */
    public static final int NAME_CONSTRAINTS_VALUE = 6;

    public final int getNumber() {
      if (this == UNRECOGNIZED) {
        throw new java.lang.IllegalArgumentException(
            "Can't get the number of an unknown enum value.");
      }
      return value;
    }

    /**
     * @param value The numeric wire value of the corresponding enum entry.
     * @return The enum associated with the given numeric wire value.
     * @deprecated Use {@link #forNumber(int)} instead.
     */
    @java.lang.Deprecated
    public static KnownCertificateExtension valueOf(int value) {
      return forNumber(value);
    }

    /**
     * @param value The numeric wire value of the corresponding enum entry.
     * @return The enum associated with the given numeric wire value.
     */
    public static KnownCertificateExtension forNumber(int value) {
      switch (value) {
        case 0:
          return KNOWN_CERTIFICATE_EXTENSION_UNSPECIFIED;
        case 1:
          return BASE_KEY_USAGE;
        case 2:
          return EXTENDED_KEY_USAGE;
        case 3:
          return CA_OPTIONS;
        case 4:
          return POLICY_IDS;
        case 5:
          return AIA_OCSP_SERVERS;
        case 6:
          return NAME_CONSTRAINTS;
        default:
          return null;
      }
    }

    public static com.google.protobuf.Internal.EnumLiteMap<KnownCertificateExtension>
        internalGetValueMap() {
      return internalValueMap;
    }

    private static final com.google.protobuf.Internal.EnumLiteMap<KnownCertificateExtension>
        internalValueMap =
            new com.google.protobuf.Internal.EnumLiteMap<KnownCertificateExtension>() {
              public KnownCertificateExtension findValueByNumber(int number) {
                return KnownCertificateExtension.forNumber(number);
              }
            };

    public final com.google.protobuf.Descriptors.EnumValueDescriptor getValueDescriptor() {
      if (this == UNRECOGNIZED) {
        throw new java.lang.IllegalStateException(
            "Can't get the descriptor of an unrecognized enum value.");
      }
      return getDescriptor().getValues().get(ordinal());
    }

    public final com.google.protobuf.Descriptors.EnumDescriptor getDescriptorForType() {
      return getDescriptor();
    }

    public static final com.google.protobuf.Descriptors.EnumDescriptor getDescriptor() {
      return com.google.cloud.security.privateca.v1.CertificateExtensionConstraints.getDescriptor()
          .getEnumTypes()
          .get(0);
    }

    private static final KnownCertificateExtension[] VALUES = values();

    public static KnownCertificateExtension valueOf(
        com.google.protobuf.Descriptors.EnumValueDescriptor desc) {
      if (desc.getType() != getDescriptor()) {
        throw new java.lang.IllegalArgumentException("EnumValueDescriptor is not for this type.");
      }
      if (desc.getIndex() == -1) {
        return UNRECOGNIZED;
      }
      return VALUES[desc.getIndex()];
    }

    private final int value;

    private KnownCertificateExtension(int value) {
      this.value = value;
    }

    // @@protoc_insertion_point(enum_scope:google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension)
  }

  public static final int KNOWN_EXTENSIONS_FIELD_NUMBER = 1;

  @SuppressWarnings("serial")
  private java.util.List<java.lang.Integer> knownExtensions_;

  private static final com.google.protobuf.Internal.ListAdapter.Converter<
          java.lang.Integer,
          com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
              .KnownCertificateExtension>
      knownExtensions_converter_ =
          new com.google.protobuf.Internal.ListAdapter.Converter<
              java.lang.Integer,
              com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                  .KnownCertificateExtension>() {
            public com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                    .KnownCertificateExtension
                convert(java.lang.Integer from) {
              com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                      .KnownCertificateExtension
                  result =
                      com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                          .KnownCertificateExtension.forNumber(from);
              return result == null
                  ? com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                      .KnownCertificateExtension.UNRECOGNIZED
                  : result;
            }
          };
  /**
   *
   *
   * <pre>
   * Optional. A set of named X.509 extensions. Will be combined with
   * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return A list containing the knownExtensions.
   */
  @java.lang.Override
  public java.util.List<
          com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
              .KnownCertificateExtension>
      getKnownExtensionsList() {
    return new com.google.protobuf.Internal.ListAdapter<
        java.lang.Integer,
        com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
            .KnownCertificateExtension>(knownExtensions_, knownExtensions_converter_);
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of named X.509 extensions. Will be combined with
   * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return The count of knownExtensions.
   */
  @java.lang.Override
  public int getKnownExtensionsCount() {
    return knownExtensions_.size();
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of named X.509 extensions. Will be combined with
   * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @param index The index of the element to return.
   * @return The knownExtensions at the given index.
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
          .KnownCertificateExtension
      getKnownExtensions(int index) {
    return knownExtensions_converter_.convert(knownExtensions_.get(index));
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of named X.509 extensions. Will be combined with
   * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return A list containing the enum numeric values on the wire for knownExtensions.
   */
  @java.lang.Override
  public java.util.List<java.lang.Integer> getKnownExtensionsValueList() {
    return knownExtensions_;
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of named X.509 extensions. Will be combined with
   * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @param index The index of the value to return.
   * @return The enum numeric value on the wire of knownExtensions at the given index.
   */
  @java.lang.Override
  public int getKnownExtensionsValue(int index) {
    return knownExtensions_.get(index);
  }

  private int knownExtensionsMemoizedSerializedSize;

  public static final int ADDITIONAL_EXTENSIONS_FIELD_NUMBER = 2;

  @SuppressWarnings("serial")
  private java.util.List<com.google.cloud.security.privateca.v1.ObjectId> additionalExtensions_;
  /**
   *
   *
   * <pre>
   * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
   * identifying custom X.509 extensions. Will be combined with
   * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public java.util.List<com.google.cloud.security.privateca.v1.ObjectId>
      getAdditionalExtensionsList() {
    return additionalExtensions_;
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
   * identifying custom X.509 extensions. Will be combined with
   * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public java.util.List<? extends com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
      getAdditionalExtensionsOrBuilderList() {
    return additionalExtensions_;
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
   * identifying custom X.509 extensions. Will be combined with
   * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public int getAdditionalExtensionsCount() {
    return additionalExtensions_.size();
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
   * identifying custom X.509 extensions. Will be combined with
   * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.ObjectId getAdditionalExtensions(int index) {
    return additionalExtensions_.get(index);
  }
  /**
   *
   *
   * <pre>
   * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
   * identifying custom X.509 extensions. Will be combined with
   * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
   * to determine the full set of X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.ObjectIdOrBuilder getAdditionalExtensionsOrBuilder(
      int index) {
    return additionalExtensions_.get(index);
  }

  private byte memoizedIsInitialized = -1;

  @java.lang.Override
  public final boolean isInitialized() {
    byte isInitialized = memoizedIsInitialized;
    if (isInitialized == 1) return true;
    if (isInitialized == 0) return false;

    memoizedIsInitialized = 1;
    return true;
  }

  @java.lang.Override
  public void writeTo(com.google.protobuf.CodedOutputStream output) throws java.io.IOException {
    getSerializedSize();
    if (getKnownExtensionsList().size() > 0) {
      output.writeUInt32NoTag(10);
      output.writeUInt32NoTag(knownExtensionsMemoizedSerializedSize);
    }
    for (int i = 0; i < knownExtensions_.size(); i++) {
      output.writeEnumNoTag(knownExtensions_.get(i));
    }
    for (int i = 0; i < additionalExtensions_.size(); i++) {
      output.writeMessage(2, additionalExtensions_.get(i));
    }
    getUnknownFields().writeTo(output);
  }

  @java.lang.Override
  public int getSerializedSize() {
    int size = memoizedSize;
    if (size != -1) return size;

    size = 0;
    {
      int dataSize = 0;
      for (int i = 0; i < knownExtensions_.size(); i++) {
        dataSize +=
            com.google.protobuf.CodedOutputStream.computeEnumSizeNoTag(knownExtensions_.get(i));
      }
      size += dataSize;
      if (!getKnownExtensionsList().isEmpty()) {
        size += 1;
        size += com.google.protobuf.CodedOutputStream.computeUInt32SizeNoTag(dataSize);
      }
      knownExtensionsMemoizedSerializedSize = dataSize;
    }
    for (int i = 0; i < additionalExtensions_.size(); i++) {
      size +=
          com.google.protobuf.CodedOutputStream.computeMessageSize(2, additionalExtensions_.get(i));
    }
    size += getUnknownFields().getSerializedSize();
    memoizedSize = size;
    return size;
  }

  @java.lang.Override
  public boolean equals(final java.lang.Object obj) {
    if (obj == this) {
      return true;
    }
    if (!(obj instanceof com.google.cloud.security.privateca.v1.CertificateExtensionConstraints)) {
      return super.equals(obj);
    }
    com.google.cloud.security.privateca.v1.CertificateExtensionConstraints other =
        (com.google.cloud.security.privateca.v1.CertificateExtensionConstraints) obj;

    if (!knownExtensions_.equals(other.knownExtensions_)) return false;
    if (!getAdditionalExtensionsList().equals(other.getAdditionalExtensionsList())) return false;
    if (!getUnknownFields().equals(other.getUnknownFields())) return false;
    return true;
  }

  @java.lang.Override
  public int hashCode() {
    if (memoizedHashCode != 0) {
      return memoizedHashCode;
    }
    int hash = 41;
    hash = (19 * hash) + getDescriptor().hashCode();
    if (getKnownExtensionsCount() > 0) {
      hash = (37 * hash) + KNOWN_EXTENSIONS_FIELD_NUMBER;
      hash = (53 * hash) + knownExtensions_.hashCode();
    }
    if (getAdditionalExtensionsCount() > 0) {
      hash = (37 * hash) + ADDITIONAL_EXTENSIONS_FIELD_NUMBER;
      hash = (53 * hash) + getAdditionalExtensionsList().hashCode();
    }
    hash = (29 * hash) + getUnknownFields().hashCode();
    memoizedHashCode = hash;
    return hash;
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      java.nio.ByteBuffer data) throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      java.nio.ByteBuffer data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      com.google.protobuf.ByteString data)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      com.google.protobuf.ByteString data,
      com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      byte[] data) throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      byte[] data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      java.io.InputStream input) throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
        PARSER, input, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
      parseDelimitedFrom(java.io.InputStream input) throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(PARSER, input);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
      parseDelimitedFrom(
          java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
          throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(
        PARSER, input, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      com.google.protobuf.CodedInputStream input) throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints parseFrom(
      com.google.protobuf.CodedInputStream input,
      com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
        PARSER, input, extensionRegistry);
  }

  @java.lang.Override
  public Builder newBuilderForType() {
    return newBuilder();
  }

  public static Builder newBuilder() {
    return DEFAULT_INSTANCE.toBuilder();
  }

  public static Builder newBuilder(
      com.google.cloud.security.privateca.v1.CertificateExtensionConstraints prototype) {
    return DEFAULT_INSTANCE.toBuilder().mergeFrom(prototype);
  }

  @java.lang.Override
  public Builder toBuilder() {
    return this == DEFAULT_INSTANCE ? new Builder() : new Builder().mergeFrom(this);
  }

  @java.lang.Override
  protected Builder newBuilderForType(com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
    Builder builder = new Builder(parent);
    return builder;
  }
  /**
   *
   *
   * <pre>
   * Describes a set of X.509 extensions that may be part of some certificate
   * issuance controls.
   * </pre>
   *
   * Protobuf type {@code google.cloud.security.privateca.v1.CertificateExtensionConstraints}
   */
  public static final class Builder extends com.google.protobuf.GeneratedMessageV3.Builder<Builder>
      implements
      // @@protoc_insertion_point(builder_implements:google.cloud.security.privateca.v1.CertificateExtensionConstraints)
      com.google.cloud.security.privateca.v1.CertificateExtensionConstraintsOrBuilder {
    public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_CertificateExtensionConstraints_descriptor;
    }

    @java.lang.Override
    protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
        internalGetFieldAccessorTable() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_CertificateExtensionConstraints_fieldAccessorTable
          .ensureFieldAccessorsInitialized(
              com.google.cloud.security.privateca.v1.CertificateExtensionConstraints.class,
              com.google.cloud.security.privateca.v1.CertificateExtensionConstraints.Builder.class);
    }

    // Construct using
    // com.google.cloud.security.privateca.v1.CertificateExtensionConstraints.newBuilder()
    private Builder() {}

    private Builder(com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
      super(parent);
    }

    @java.lang.Override
    public Builder clear() {
      super.clear();
      bitField0_ = 0;
      knownExtensions_ = java.util.Collections.emptyList();
      bitField0_ = (bitField0_ & ~0x00000001);
      if (additionalExtensionsBuilder_ == null) {
        additionalExtensions_ = java.util.Collections.emptyList();
      } else {
        additionalExtensions_ = null;
        additionalExtensionsBuilder_.clear();
      }
      bitField0_ = (bitField0_ & ~0x00000002);
      return this;
    }

    @java.lang.Override
    public com.google.protobuf.Descriptors.Descriptor getDescriptorForType() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_CertificateExtensionConstraints_descriptor;
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
        getDefaultInstanceForType() {
      return com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
          .getDefaultInstance();
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.CertificateExtensionConstraints build() {
      com.google.cloud.security.privateca.v1.CertificateExtensionConstraints result =
          buildPartial();
      if (!result.isInitialized()) {
        throw newUninitializedMessageException(result);
      }
      return result;
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.CertificateExtensionConstraints buildPartial() {
      com.google.cloud.security.privateca.v1.CertificateExtensionConstraints result =
          new com.google.cloud.security.privateca.v1.CertificateExtensionConstraints(this);
      buildPartialRepeatedFields(result);
      if (bitField0_ != 0) {
        buildPartial0(result);
      }
      onBuilt();
      return result;
    }

    private void buildPartialRepeatedFields(
        com.google.cloud.security.privateca.v1.CertificateExtensionConstraints result) {
      if (((bitField0_ & 0x00000001) != 0)) {
        knownExtensions_ = java.util.Collections.unmodifiableList(knownExtensions_);
        bitField0_ = (bitField0_ & ~0x00000001);
      }
      result.knownExtensions_ = knownExtensions_;
      if (additionalExtensionsBuilder_ == null) {
        if (((bitField0_ & 0x00000002) != 0)) {
          additionalExtensions_ = java.util.Collections.unmodifiableList(additionalExtensions_);
          bitField0_ = (bitField0_ & ~0x00000002);
        }
        result.additionalExtensions_ = additionalExtensions_;
      } else {
        result.additionalExtensions_ = additionalExtensionsBuilder_.build();
      }
    }

    private void buildPartial0(
        com.google.cloud.security.privateca.v1.CertificateExtensionConstraints result) {
      int from_bitField0_ = bitField0_;
    }

    @java.lang.Override
    public Builder clone() {
      return super.clone();
    }

    @java.lang.Override
    public Builder setField(
        com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
      return super.setField(field, value);
    }

    @java.lang.Override
    public Builder clearField(com.google.protobuf.Descriptors.FieldDescriptor field) {
      return super.clearField(field);
    }

    @java.lang.Override
    public Builder clearOneof(com.google.protobuf.Descriptors.OneofDescriptor oneof) {
      return super.clearOneof(oneof);
    }

    @java.lang.Override
    public Builder setRepeatedField(
        com.google.protobuf.Descriptors.FieldDescriptor field, int index, java.lang.Object value) {
      return super.setRepeatedField(field, index, value);
    }

    @java.lang.Override
    public Builder addRepeatedField(
        com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
      return super.addRepeatedField(field, value);
    }

    @java.lang.Override
    public Builder mergeFrom(com.google.protobuf.Message other) {
      if (other instanceof com.google.cloud.security.privateca.v1.CertificateExtensionConstraints) {
        return mergeFrom(
            (com.google.cloud.security.privateca.v1.CertificateExtensionConstraints) other);
      } else {
        super.mergeFrom(other);
        return this;
      }
    }

    public Builder mergeFrom(
        com.google.cloud.security.privateca.v1.CertificateExtensionConstraints other) {
      if (other
          == com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
              .getDefaultInstance()) return this;
      if (!other.knownExtensions_.isEmpty()) {
        if (knownExtensions_.isEmpty()) {
          knownExtensions_ = other.knownExtensions_;
          bitField0_ = (bitField0_ & ~0x00000001);
        } else {
          ensureKnownExtensionsIsMutable();
          knownExtensions_.addAll(other.knownExtensions_);
        }
        onChanged();
      }
      if (additionalExtensionsBuilder_ == null) {
        if (!other.additionalExtensions_.isEmpty()) {
          if (additionalExtensions_.isEmpty()) {
            additionalExtensions_ = other.additionalExtensions_;
            bitField0_ = (bitField0_ & ~0x00000002);
          } else {
            ensureAdditionalExtensionsIsMutable();
            additionalExtensions_.addAll(other.additionalExtensions_);
          }
          onChanged();
        }
      } else {
        if (!other.additionalExtensions_.isEmpty()) {
          if (additionalExtensionsBuilder_.isEmpty()) {
            additionalExtensionsBuilder_.dispose();
            additionalExtensionsBuilder_ = null;
            additionalExtensions_ = other.additionalExtensions_;
            bitField0_ = (bitField0_ & ~0x00000002);
            additionalExtensionsBuilder_ =
                com.google.protobuf.GeneratedMessageV3.alwaysUseFieldBuilders
                    ? getAdditionalExtensionsFieldBuilder()
                    : null;
          } else {
            additionalExtensionsBuilder_.addAllMessages(other.additionalExtensions_);
          }
        }
      }
      this.mergeUnknownFields(other.getUnknownFields());
      onChanged();
      return this;
    }

    @java.lang.Override
    public final boolean isInitialized() {
      return true;
    }

    @java.lang.Override
    public Builder mergeFrom(
        com.google.protobuf.CodedInputStream input,
        com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws java.io.IOException {
      if (extensionRegistry == null) {
        throw new java.lang.NullPointerException();
      }
      try {
        boolean done = false;
        while (!done) {
          int tag = input.readTag();
          switch (tag) {
            case 0:
              done = true;
              break;
            case 8:
              {
                int tmpRaw = input.readEnum();
                ensureKnownExtensionsIsMutable();
                knownExtensions_.add(tmpRaw);
                break;
              } // case 8
            case 10:
              {
                int length = input.readRawVarint32();
                int oldLimit = input.pushLimit(length);
                while (input.getBytesUntilLimit() > 0) {
                  int tmpRaw = input.readEnum();
                  ensureKnownExtensionsIsMutable();
                  knownExtensions_.add(tmpRaw);
                }
                input.popLimit(oldLimit);
                break;
              } // case 10
            case 18:
              {
                com.google.cloud.security.privateca.v1.ObjectId m =
                    input.readMessage(
                        com.google.cloud.security.privateca.v1.ObjectId.parser(),
                        extensionRegistry);
                if (additionalExtensionsBuilder_ == null) {
                  ensureAdditionalExtensionsIsMutable();
                  additionalExtensions_.add(m);
                } else {
                  additionalExtensionsBuilder_.addMessage(m);
                }
                break;
              } // case 18
            default:
              {
                if (!super.parseUnknownField(input, extensionRegistry, tag)) {
                  done = true; // was an endgroup tag
                }
                break;
              } // default:
          } // switch (tag)
        } // while (!done)
      } catch (com.google.protobuf.InvalidProtocolBufferException e) {
        throw e.unwrapIOException();
      } finally {
        onChanged();
      } // finally
      return this;
    }

    private int bitField0_;

    private java.util.List<java.lang.Integer> knownExtensions_ = java.util.Collections.emptyList();

    private void ensureKnownExtensionsIsMutable() {
      if (!((bitField0_ & 0x00000001) != 0)) {
        knownExtensions_ = new java.util.ArrayList<java.lang.Integer>(knownExtensions_);
        bitField0_ |= 0x00000001;
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return A list containing the knownExtensions.
     */
    public java.util.List<
            com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                .KnownCertificateExtension>
        getKnownExtensionsList() {
      return new com.google.protobuf.Internal.ListAdapter<
          java.lang.Integer,
          com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
              .KnownCertificateExtension>(knownExtensions_, knownExtensions_converter_);
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return The count of knownExtensions.
     */
    public int getKnownExtensionsCount() {
      return knownExtensions_.size();
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param index The index of the element to return.
     * @return The knownExtensions at the given index.
     */
    public com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
            .KnownCertificateExtension
        getKnownExtensions(int index) {
      return knownExtensions_converter_.convert(knownExtensions_.get(index));
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param index The index to set the value at.
     * @param value The knownExtensions to set.
     * @return This builder for chaining.
     */
    public Builder setKnownExtensions(
        int index,
        com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                .KnownCertificateExtension
            value) {
      if (value == null) {
        throw new NullPointerException();
      }
      ensureKnownExtensionsIsMutable();
      knownExtensions_.set(index, value.getNumber());
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param value The knownExtensions to add.
     * @return This builder for chaining.
     */
    public Builder addKnownExtensions(
        com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                .KnownCertificateExtension
            value) {
      if (value == null) {
        throw new NullPointerException();
      }
      ensureKnownExtensionsIsMutable();
      knownExtensions_.add(value.getNumber());
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param values The knownExtensions to add.
     * @return This builder for chaining.
     */
    public Builder addAllKnownExtensions(
        java.lang.Iterable<
                ? extends
                    com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
                        .KnownCertificateExtension>
            values) {
      ensureKnownExtensionsIsMutable();
      for (com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
              .KnownCertificateExtension
          value : values) {
        knownExtensions_.add(value.getNumber());
      }
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return This builder for chaining.
     */
    public Builder clearKnownExtensions() {
      knownExtensions_ = java.util.Collections.emptyList();
      bitField0_ = (bitField0_ & ~0x00000001);
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return A list containing the enum numeric values on the wire for knownExtensions.
     */
    public java.util.List<java.lang.Integer> getKnownExtensionsValueList() {
      return java.util.Collections.unmodifiableList(knownExtensions_);
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param index The index of the value to return.
     * @return The enum numeric value on the wire of knownExtensions at the given index.
     */
    public int getKnownExtensionsValue(int index) {
      return knownExtensions_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param index The index to set the value at.
     * @param value The enum numeric value on the wire for knownExtensions to set.
     * @return This builder for chaining.
     */
    public Builder setKnownExtensionsValue(int index, int value) {
      ensureKnownExtensionsIsMutable();
      knownExtensions_.set(index, value);
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param value The enum numeric value on the wire for knownExtensions to add.
     * @return This builder for chaining.
     */
    public Builder addKnownExtensionsValue(int value) {
      ensureKnownExtensionsIsMutable();
      knownExtensions_.add(value);
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of named X.509 extensions. Will be combined with
     * [additional_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.additional_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.CertificateExtensionConstraints.KnownCertificateExtension known_extensions = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @param values The enum numeric values on the wire for knownExtensions to add.
     * @return This builder for chaining.
     */
    public Builder addAllKnownExtensionsValue(java.lang.Iterable<java.lang.Integer> values) {
      ensureKnownExtensionsIsMutable();
      for (int value : values) {
        knownExtensions_.add(value);
      }
      onChanged();
      return this;
    }

    private java.util.List<com.google.cloud.security.privateca.v1.ObjectId> additionalExtensions_ =
        java.util.Collections.emptyList();

    private void ensureAdditionalExtensionsIsMutable() {
      if (!((bitField0_ & 0x00000002) != 0)) {
        additionalExtensions_ =
            new java.util.ArrayList<com.google.cloud.security.privateca.v1.ObjectId>(
                additionalExtensions_);
        bitField0_ |= 0x00000002;
      }
    }

    private com.google.protobuf.RepeatedFieldBuilderV3<
            com.google.cloud.security.privateca.v1.ObjectId,
            com.google.cloud.security.privateca.v1.ObjectId.Builder,
            com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
        additionalExtensionsBuilder_;

    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<com.google.cloud.security.privateca.v1.ObjectId>
        getAdditionalExtensionsList() {
      if (additionalExtensionsBuilder_ == null) {
        return java.util.Collections.unmodifiableList(additionalExtensions_);
      } else {
        return additionalExtensionsBuilder_.getMessageList();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public int getAdditionalExtensionsCount() {
      if (additionalExtensionsBuilder_ == null) {
        return additionalExtensions_.size();
      } else {
        return additionalExtensionsBuilder_.getCount();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId getAdditionalExtensions(int index) {
      if (additionalExtensionsBuilder_ == null) {
        return additionalExtensions_.get(index);
      } else {
        return additionalExtensionsBuilder_.getMessage(index);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.ObjectId value) {
      if (additionalExtensionsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.set(index, value);
        onChanged();
      } else {
        additionalExtensionsBuilder_.setMessage(index, value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.ObjectId.Builder builderForValue) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.set(index, builderForValue.build());
        onChanged();
      } else {
        additionalExtensionsBuilder_.setMessage(index, builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(com.google.cloud.security.privateca.v1.ObjectId value) {
      if (additionalExtensionsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(value);
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.ObjectId value) {
      if (additionalExtensionsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(index, value);
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(index, value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(
        com.google.cloud.security.privateca.v1.ObjectId.Builder builderForValue) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(builderForValue.build());
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.ObjectId.Builder builderForValue) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(index, builderForValue.build());
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(index, builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAllAdditionalExtensions(
        java.lang.Iterable<? extends com.google.cloud.security.privateca.v1.ObjectId> values) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, additionalExtensions_);
        onChanged();
      } else {
        additionalExtensionsBuilder_.addAllMessages(values);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder clearAdditionalExtensions() {
      if (additionalExtensionsBuilder_ == null) {
        additionalExtensions_ = java.util.Collections.emptyList();
        bitField0_ = (bitField0_ & ~0x00000002);
        onChanged();
      } else {
        additionalExtensionsBuilder_.clear();
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder removeAdditionalExtensions(int index) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.remove(index);
        onChanged();
      } else {
        additionalExtensionsBuilder_.remove(index);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId.Builder getAdditionalExtensionsBuilder(
        int index) {
      return getAdditionalExtensionsFieldBuilder().getBuilder(index);
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectIdOrBuilder
        getAdditionalExtensionsOrBuilder(int index) {
      if (additionalExtensionsBuilder_ == null) {
        return additionalExtensions_.get(index);
      } else {
        return additionalExtensionsBuilder_.getMessageOrBuilder(index);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<? extends com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
        getAdditionalExtensionsOrBuilderList() {
      if (additionalExtensionsBuilder_ != null) {
        return additionalExtensionsBuilder_.getMessageOrBuilderList();
      } else {
        return java.util.Collections.unmodifiableList(additionalExtensions_);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId.Builder
        addAdditionalExtensionsBuilder() {
      return getAdditionalExtensionsFieldBuilder()
          .addBuilder(com.google.cloud.security.privateca.v1.ObjectId.getDefaultInstance());
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId.Builder addAdditionalExtensionsBuilder(
        int index) {
      return getAdditionalExtensionsFieldBuilder()
          .addBuilder(index, com.google.cloud.security.privateca.v1.ObjectId.getDefaultInstance());
    }
    /**
     *
     *
     * <pre>
     * Optional. A set of [ObjectIds][google.cloud.security.privateca.v1.ObjectId]
     * identifying custom X.509 extensions. Will be combined with
     * [known_extensions][google.cloud.security.privateca.v1.CertificateExtensionConstraints.known_extensions]
     * to determine the full set of X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId additional_extensions = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<com.google.cloud.security.privateca.v1.ObjectId.Builder>
        getAdditionalExtensionsBuilderList() {
      return getAdditionalExtensionsFieldBuilder().getBuilderList();
    }

    private com.google.protobuf.RepeatedFieldBuilderV3<
            com.google.cloud.security.privateca.v1.ObjectId,
            com.google.cloud.security.privateca.v1.ObjectId.Builder,
            com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
        getAdditionalExtensionsFieldBuilder() {
      if (additionalExtensionsBuilder_ == null) {
        additionalExtensionsBuilder_ =
            new com.google.protobuf.RepeatedFieldBuilderV3<
                com.google.cloud.security.privateca.v1.ObjectId,
                com.google.cloud.security.privateca.v1.ObjectId.Builder,
                com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>(
                additionalExtensions_,
                ((bitField0_ & 0x00000002) != 0),
                getParentForChildren(),
                isClean());
        additionalExtensions_ = null;
      }
      return additionalExtensionsBuilder_;
    }

    @java.lang.Override
    public final Builder setUnknownFields(final com.google.protobuf.UnknownFieldSet unknownFields) {
      return super.setUnknownFields(unknownFields);
    }

    @java.lang.Override
    public final Builder mergeUnknownFields(
        final com.google.protobuf.UnknownFieldSet unknownFields) {
      return super.mergeUnknownFields(unknownFields);
    }

    // @@protoc_insertion_point(builder_scope:google.cloud.security.privateca.v1.CertificateExtensionConstraints)
  }

  // @@protoc_insertion_point(class_scope:google.cloud.security.privateca.v1.CertificateExtensionConstraints)
  private static final com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
      DEFAULT_INSTANCE;

  static {
    DEFAULT_INSTANCE = new com.google.cloud.security.privateca.v1.CertificateExtensionConstraints();
  }

  public static com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
      getDefaultInstance() {
    return DEFAULT_INSTANCE;
  }

  private static final com.google.protobuf.Parser<CertificateExtensionConstraints> PARSER =
      new com.google.protobuf.AbstractParser<CertificateExtensionConstraints>() {
        @java.lang.Override
        public CertificateExtensionConstraints parsePartialFrom(
            com.google.protobuf.CodedInputStream input,
            com.google.protobuf.ExtensionRegistryLite extensionRegistry)
            throws com.google.protobuf.InvalidProtocolBufferException {
          Builder builder = newBuilder();
          try {
            builder.mergeFrom(input, extensionRegistry);
          } catch (com.google.protobuf.InvalidProtocolBufferException e) {
            throw e.setUnfinishedMessage(builder.buildPartial());
          } catch (com.google.protobuf.UninitializedMessageException e) {
            throw e.asInvalidProtocolBufferException().setUnfinishedMessage(builder.buildPartial());
          } catch (java.io.IOException e) {
            throw new com.google.protobuf.InvalidProtocolBufferException(e)
                .setUnfinishedMessage(builder.buildPartial());
          }
          return builder.buildPartial();
        }
      };

  public static com.google.protobuf.Parser<CertificateExtensionConstraints> parser() {
    return PARSER;
  }

  @java.lang.Override
  public com.google.protobuf.Parser<CertificateExtensionConstraints> getParserForType() {
    return PARSER;
  }

  @java.lang.Override
  public com.google.cloud.security.privateca.v1.CertificateExtensionConstraints
      getDefaultInstanceForType() {
    return DEFAULT_INSTANCE;
  }
}
