/*
 * Copyright 2020 Google LLC
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     https://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
// Generated by the protocol buffer compiler.  DO NOT EDIT!
// source: google/cloud/security/privateca/v1/resources.proto

package com.google.cloud.security.privateca.v1;

/**
 *
 *
 * <pre>
 * An [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] is
 * used to describe certain fields of an X.509 certificate, such as the key
 * usage fields, fields specific to CA certificates, certificate policy
 * extensions and custom extensions.
 * </pre>
 *
 * Protobuf type {@code google.cloud.security.privateca.v1.X509Parameters}
 */
public final class X509Parameters extends com.google.protobuf.GeneratedMessageV3
    implements
    // @@protoc_insertion_point(message_implements:google.cloud.security.privateca.v1.X509Parameters)
    X509ParametersOrBuilder {
  private static final long serialVersionUID = 0L;
  // Use X509Parameters.newBuilder() to construct.
  private X509Parameters(com.google.protobuf.GeneratedMessageV3.Builder<?> builder) {
    super(builder);
  }

  private X509Parameters() {
    policyIds_ = java.util.Collections.emptyList();
    aiaOcspServers_ = com.google.protobuf.LazyStringArrayList.EMPTY;
    additionalExtensions_ = java.util.Collections.emptyList();
  }

  @java.lang.Override
  @SuppressWarnings({"unused"})
  protected java.lang.Object newInstance(UnusedPrivateParameter unused) {
    return new X509Parameters();
  }

  @java.lang.Override
  public final com.google.protobuf.UnknownFieldSet getUnknownFields() {
    return this.unknownFields;
  }

  public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
    return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
        .internal_static_google_cloud_security_privateca_v1_X509Parameters_descriptor;
  }

  @java.lang.Override
  protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
      internalGetFieldAccessorTable() {
    return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
        .internal_static_google_cloud_security_privateca_v1_X509Parameters_fieldAccessorTable
        .ensureFieldAccessorsInitialized(
            com.google.cloud.security.privateca.v1.X509Parameters.class,
            com.google.cloud.security.privateca.v1.X509Parameters.Builder.class);
  }

  public interface CaOptionsOrBuilder
      extends
      // @@protoc_insertion_point(interface_extends:google.cloud.security.privateca.v1.X509Parameters.CaOptions)
      com.google.protobuf.MessageOrBuilder {

    /**
     *
     *
     * <pre>
     * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
     * When this value is missing, the extension will be omitted from the CA
     * certificate.
     * </pre>
     *
     * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @return Whether the isCa field is set.
     */
    boolean hasIsCa();
    /**
     *
     *
     * <pre>
     * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
     * When this value is missing, the extension will be omitted from the CA
     * certificate.
     * </pre>
     *
     * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @return The isCa.
     */
    boolean getIsCa();

    /**
     *
     *
     * <pre>
     * Optional. Refers to the path length restriction X.509 extension. For a CA
     * certificate, this value describes the depth of subordinate CA
     * certificates that are allowed.
     * If this value is less than 0, the request will fail.
     * If this value is missing, the max path length will be omitted from the
     * CA certificate.
     * </pre>
     *
     * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return Whether the maxIssuerPathLength field is set.
     */
    boolean hasMaxIssuerPathLength();
    /**
     *
     *
     * <pre>
     * Optional. Refers to the path length restriction X.509 extension. For a CA
     * certificate, this value describes the depth of subordinate CA
     * certificates that are allowed.
     * If this value is less than 0, the request will fail.
     * If this value is missing, the max path length will be omitted from the
     * CA certificate.
     * </pre>
     *
     * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return The maxIssuerPathLength.
     */
    int getMaxIssuerPathLength();
  }
  /**
   *
   *
   * <pre>
   * Describes values that are relevant in a CA certificate.
   * </pre>
   *
   * Protobuf type {@code google.cloud.security.privateca.v1.X509Parameters.CaOptions}
   */
  public static final class CaOptions extends com.google.protobuf.GeneratedMessageV3
      implements
      // @@protoc_insertion_point(message_implements:google.cloud.security.privateca.v1.X509Parameters.CaOptions)
      CaOptionsOrBuilder {
    private static final long serialVersionUID = 0L;
    // Use CaOptions.newBuilder() to construct.
    private CaOptions(com.google.protobuf.GeneratedMessageV3.Builder<?> builder) {
      super(builder);
    }

    private CaOptions() {}

    @java.lang.Override
    @SuppressWarnings({"unused"})
    protected java.lang.Object newInstance(UnusedPrivateParameter unused) {
      return new CaOptions();
    }

    @java.lang.Override
    public final com.google.protobuf.UnknownFieldSet getUnknownFields() {
      return this.unknownFields;
    }

    public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_X509Parameters_CaOptions_descriptor;
    }

    @java.lang.Override
    protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
        internalGetFieldAccessorTable() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_X509Parameters_CaOptions_fieldAccessorTable
          .ensureFieldAccessorsInitialized(
              com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.class,
              com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.Builder.class);
    }

    private int bitField0_;
    public static final int IS_CA_FIELD_NUMBER = 1;
    private boolean isCa_ = false;
    /**
     *
     *
     * <pre>
     * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
     * When this value is missing, the extension will be omitted from the CA
     * certificate.
     * </pre>
     *
     * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @return Whether the isCa field is set.
     */
    @java.lang.Override
    public boolean hasIsCa() {
      return ((bitField0_ & 0x00000001) != 0);
    }
    /**
     *
     *
     * <pre>
     * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
     * When this value is missing, the extension will be omitted from the CA
     * certificate.
     * </pre>
     *
     * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @return The isCa.
     */
    @java.lang.Override
    public boolean getIsCa() {
      return isCa_;
    }

    public static final int MAX_ISSUER_PATH_LENGTH_FIELD_NUMBER = 2;
    private int maxIssuerPathLength_ = 0;
    /**
     *
     *
     * <pre>
     * Optional. Refers to the path length restriction X.509 extension. For a CA
     * certificate, this value describes the depth of subordinate CA
     * certificates that are allowed.
     * If this value is less than 0, the request will fail.
     * If this value is missing, the max path length will be omitted from the
     * CA certificate.
     * </pre>
     *
     * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return Whether the maxIssuerPathLength field is set.
     */
    @java.lang.Override
    public boolean hasMaxIssuerPathLength() {
      return ((bitField0_ & 0x00000002) != 0);
    }
    /**
     *
     *
     * <pre>
     * Optional. Refers to the path length restriction X.509 extension. For a CA
     * certificate, this value describes the depth of subordinate CA
     * certificates that are allowed.
     * If this value is less than 0, the request will fail.
     * If this value is missing, the max path length will be omitted from the
     * CA certificate.
     * </pre>
     *
     * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return The maxIssuerPathLength.
     */
    @java.lang.Override
    public int getMaxIssuerPathLength() {
      return maxIssuerPathLength_;
    }

    private byte memoizedIsInitialized = -1;

    @java.lang.Override
    public final boolean isInitialized() {
      byte isInitialized = memoizedIsInitialized;
      if (isInitialized == 1) return true;
      if (isInitialized == 0) return false;

      memoizedIsInitialized = 1;
      return true;
    }

    @java.lang.Override
    public void writeTo(com.google.protobuf.CodedOutputStream output) throws java.io.IOException {
      if (((bitField0_ & 0x00000001) != 0)) {
        output.writeBool(1, isCa_);
      }
      if (((bitField0_ & 0x00000002) != 0)) {
        output.writeInt32(2, maxIssuerPathLength_);
      }
      getUnknownFields().writeTo(output);
    }

    @java.lang.Override
    public int getSerializedSize() {
      int size = memoizedSize;
      if (size != -1) return size;

      size = 0;
      if (((bitField0_ & 0x00000001) != 0)) {
        size += com.google.protobuf.CodedOutputStream.computeBoolSize(1, isCa_);
      }
      if (((bitField0_ & 0x00000002) != 0)) {
        size += com.google.protobuf.CodedOutputStream.computeInt32Size(2, maxIssuerPathLength_);
      }
      size += getUnknownFields().getSerializedSize();
      memoizedSize = size;
      return size;
    }

    @java.lang.Override
    public boolean equals(final java.lang.Object obj) {
      if (obj == this) {
        return true;
      }
      if (!(obj instanceof com.google.cloud.security.privateca.v1.X509Parameters.CaOptions)) {
        return super.equals(obj);
      }
      com.google.cloud.security.privateca.v1.X509Parameters.CaOptions other =
          (com.google.cloud.security.privateca.v1.X509Parameters.CaOptions) obj;

      if (hasIsCa() != other.hasIsCa()) return false;
      if (hasIsCa()) {
        if (getIsCa() != other.getIsCa()) return false;
      }
      if (hasMaxIssuerPathLength() != other.hasMaxIssuerPathLength()) return false;
      if (hasMaxIssuerPathLength()) {
        if (getMaxIssuerPathLength() != other.getMaxIssuerPathLength()) return false;
      }
      if (!getUnknownFields().equals(other.getUnknownFields())) return false;
      return true;
    }

    @java.lang.Override
    public int hashCode() {
      if (memoizedHashCode != 0) {
        return memoizedHashCode;
      }
      int hash = 41;
      hash = (19 * hash) + getDescriptor().hashCode();
      if (hasIsCa()) {
        hash = (37 * hash) + IS_CA_FIELD_NUMBER;
        hash = (53 * hash) + com.google.protobuf.Internal.hashBoolean(getIsCa());
      }
      if (hasMaxIssuerPathLength()) {
        hash = (37 * hash) + MAX_ISSUER_PATH_LENGTH_FIELD_NUMBER;
        hash = (53 * hash) + getMaxIssuerPathLength();
      }
      hash = (29 * hash) + getUnknownFields().hashCode();
      memoizedHashCode = hash;
      return hash;
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        java.nio.ByteBuffer data) throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        java.nio.ByteBuffer data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        com.google.protobuf.ByteString data)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        com.google.protobuf.ByteString data,
        com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        byte[] data) throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        byte[] data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        java.io.InputStream input) throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
          PARSER, input, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions
        parseDelimitedFrom(java.io.InputStream input) throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(PARSER, input);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions
        parseDelimitedFrom(
            java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
            throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(
          PARSER, input, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        com.google.protobuf.CodedInputStream input) throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions parseFrom(
        com.google.protobuf.CodedInputStream input,
        com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
          PARSER, input, extensionRegistry);
    }

    @java.lang.Override
    public Builder newBuilderForType() {
      return newBuilder();
    }

    public static Builder newBuilder() {
      return DEFAULT_INSTANCE.toBuilder();
    }

    public static Builder newBuilder(
        com.google.cloud.security.privateca.v1.X509Parameters.CaOptions prototype) {
      return DEFAULT_INSTANCE.toBuilder().mergeFrom(prototype);
    }

    @java.lang.Override
    public Builder toBuilder() {
      return this == DEFAULT_INSTANCE ? new Builder() : new Builder().mergeFrom(this);
    }

    @java.lang.Override
    protected Builder newBuilderForType(
        com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
      Builder builder = new Builder(parent);
      return builder;
    }
    /**
     *
     *
     * <pre>
     * Describes values that are relevant in a CA certificate.
     * </pre>
     *
     * Protobuf type {@code google.cloud.security.privateca.v1.X509Parameters.CaOptions}
     */
    public static final class Builder
        extends com.google.protobuf.GeneratedMessageV3.Builder<Builder>
        implements
        // @@protoc_insertion_point(builder_implements:google.cloud.security.privateca.v1.X509Parameters.CaOptions)
        com.google.cloud.security.privateca.v1.X509Parameters.CaOptionsOrBuilder {
      public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
        return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
            .internal_static_google_cloud_security_privateca_v1_X509Parameters_CaOptions_descriptor;
      }

      @java.lang.Override
      protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
          internalGetFieldAccessorTable() {
        return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
            .internal_static_google_cloud_security_privateca_v1_X509Parameters_CaOptions_fieldAccessorTable
            .ensureFieldAccessorsInitialized(
                com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.class,
                com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.Builder.class);
      }

      // Construct using
      // com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.newBuilder()
      private Builder() {}

      private Builder(com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
        super(parent);
      }

      @java.lang.Override
      public Builder clear() {
        super.clear();
        bitField0_ = 0;
        isCa_ = false;
        maxIssuerPathLength_ = 0;
        return this;
      }

      @java.lang.Override
      public com.google.protobuf.Descriptors.Descriptor getDescriptorForType() {
        return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
            .internal_static_google_cloud_security_privateca_v1_X509Parameters_CaOptions_descriptor;
      }

      @java.lang.Override
      public com.google.cloud.security.privateca.v1.X509Parameters.CaOptions
          getDefaultInstanceForType() {
        return com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.getDefaultInstance();
      }

      @java.lang.Override
      public com.google.cloud.security.privateca.v1.X509Parameters.CaOptions build() {
        com.google.cloud.security.privateca.v1.X509Parameters.CaOptions result = buildPartial();
        if (!result.isInitialized()) {
          throw newUninitializedMessageException(result);
        }
        return result;
      }

      @java.lang.Override
      public com.google.cloud.security.privateca.v1.X509Parameters.CaOptions buildPartial() {
        com.google.cloud.security.privateca.v1.X509Parameters.CaOptions result =
            new com.google.cloud.security.privateca.v1.X509Parameters.CaOptions(this);
        if (bitField0_ != 0) {
          buildPartial0(result);
        }
        onBuilt();
        return result;
      }

      private void buildPartial0(
          com.google.cloud.security.privateca.v1.X509Parameters.CaOptions result) {
        int from_bitField0_ = bitField0_;
        int to_bitField0_ = 0;
        if (((from_bitField0_ & 0x00000001) != 0)) {
          result.isCa_ = isCa_;
          to_bitField0_ |= 0x00000001;
        }
        if (((from_bitField0_ & 0x00000002) != 0)) {
          result.maxIssuerPathLength_ = maxIssuerPathLength_;
          to_bitField0_ |= 0x00000002;
        }
        result.bitField0_ |= to_bitField0_;
      }

      @java.lang.Override
      public Builder clone() {
        return super.clone();
      }

      @java.lang.Override
      public Builder setField(
          com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
        return super.setField(field, value);
      }

      @java.lang.Override
      public Builder clearField(com.google.protobuf.Descriptors.FieldDescriptor field) {
        return super.clearField(field);
      }

      @java.lang.Override
      public Builder clearOneof(com.google.protobuf.Descriptors.OneofDescriptor oneof) {
        return super.clearOneof(oneof);
      }

      @java.lang.Override
      public Builder setRepeatedField(
          com.google.protobuf.Descriptors.FieldDescriptor field,
          int index,
          java.lang.Object value) {
        return super.setRepeatedField(field, index, value);
      }

      @java.lang.Override
      public Builder addRepeatedField(
          com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
        return super.addRepeatedField(field, value);
      }

      @java.lang.Override
      public Builder mergeFrom(com.google.protobuf.Message other) {
        if (other instanceof com.google.cloud.security.privateca.v1.X509Parameters.CaOptions) {
          return mergeFrom((com.google.cloud.security.privateca.v1.X509Parameters.CaOptions) other);
        } else {
          super.mergeFrom(other);
          return this;
        }
      }

      public Builder mergeFrom(
          com.google.cloud.security.privateca.v1.X509Parameters.CaOptions other) {
        if (other
            == com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.getDefaultInstance())
          return this;
        if (other.hasIsCa()) {
          setIsCa(other.getIsCa());
        }
        if (other.hasMaxIssuerPathLength()) {
          setMaxIssuerPathLength(other.getMaxIssuerPathLength());
        }
        this.mergeUnknownFields(other.getUnknownFields());
        onChanged();
        return this;
      }

      @java.lang.Override
      public final boolean isInitialized() {
        return true;
      }

      @java.lang.Override
      public Builder mergeFrom(
          com.google.protobuf.CodedInputStream input,
          com.google.protobuf.ExtensionRegistryLite extensionRegistry)
          throws java.io.IOException {
        if (extensionRegistry == null) {
          throw new java.lang.NullPointerException();
        }
        try {
          boolean done = false;
          while (!done) {
            int tag = input.readTag();
            switch (tag) {
              case 0:
                done = true;
                break;
              case 8:
                {
                  isCa_ = input.readBool();
                  bitField0_ |= 0x00000001;
                  break;
                } // case 8
              case 16:
                {
                  maxIssuerPathLength_ = input.readInt32();
                  bitField0_ |= 0x00000002;
                  break;
                } // case 16
              default:
                {
                  if (!super.parseUnknownField(input, extensionRegistry, tag)) {
                    done = true; // was an endgroup tag
                  }
                  break;
                } // default:
            } // switch (tag)
          } // while (!done)
        } catch (com.google.protobuf.InvalidProtocolBufferException e) {
          throw e.unwrapIOException();
        } finally {
          onChanged();
        } // finally
        return this;
      }

      private int bitField0_;

      private boolean isCa_;
      /**
       *
       *
       * <pre>
       * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
       * When this value is missing, the extension will be omitted from the CA
       * certificate.
       * </pre>
       *
       * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
       *
       * @return Whether the isCa field is set.
       */
      @java.lang.Override
      public boolean hasIsCa() {
        return ((bitField0_ & 0x00000001) != 0);
      }
      /**
       *
       *
       * <pre>
       * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
       * When this value is missing, the extension will be omitted from the CA
       * certificate.
       * </pre>
       *
       * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
       *
       * @return The isCa.
       */
      @java.lang.Override
      public boolean getIsCa() {
        return isCa_;
      }
      /**
       *
       *
       * <pre>
       * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
       * When this value is missing, the extension will be omitted from the CA
       * certificate.
       * </pre>
       *
       * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
       *
       * @param value The isCa to set.
       * @return This builder for chaining.
       */
      public Builder setIsCa(boolean value) {

        isCa_ = value;
        bitField0_ |= 0x00000001;
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Optional. Refers to the "CA" X.509 extension, which is a boolean value.
       * When this value is missing, the extension will be omitted from the CA
       * certificate.
       * </pre>
       *
       * <code>optional bool is_ca = 1 [(.google.api.field_behavior) = OPTIONAL];</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearIsCa() {
        bitField0_ = (bitField0_ & ~0x00000001);
        isCa_ = false;
        onChanged();
        return this;
      }

      private int maxIssuerPathLength_;
      /**
       *
       *
       * <pre>
       * Optional. Refers to the path length restriction X.509 extension. For a CA
       * certificate, this value describes the depth of subordinate CA
       * certificates that are allowed.
       * If this value is less than 0, the request will fail.
       * If this value is missing, the max path length will be omitted from the
       * CA certificate.
       * </pre>
       *
       * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
       * </code>
       *
       * @return Whether the maxIssuerPathLength field is set.
       */
      @java.lang.Override
      public boolean hasMaxIssuerPathLength() {
        return ((bitField0_ & 0x00000002) != 0);
      }
      /**
       *
       *
       * <pre>
       * Optional. Refers to the path length restriction X.509 extension. For a CA
       * certificate, this value describes the depth of subordinate CA
       * certificates that are allowed.
       * If this value is less than 0, the request will fail.
       * If this value is missing, the max path length will be omitted from the
       * CA certificate.
       * </pre>
       *
       * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
       * </code>
       *
       * @return The maxIssuerPathLength.
       */
      @java.lang.Override
      public int getMaxIssuerPathLength() {
        return maxIssuerPathLength_;
      }
      /**
       *
       *
       * <pre>
       * Optional. Refers to the path length restriction X.509 extension. For a CA
       * certificate, this value describes the depth of subordinate CA
       * certificates that are allowed.
       * If this value is less than 0, the request will fail.
       * If this value is missing, the max path length will be omitted from the
       * CA certificate.
       * </pre>
       *
       * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
       * </code>
       *
       * @param value The maxIssuerPathLength to set.
       * @return This builder for chaining.
       */
      public Builder setMaxIssuerPathLength(int value) {

        maxIssuerPathLength_ = value;
        bitField0_ |= 0x00000002;
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Optional. Refers to the path length restriction X.509 extension. For a CA
       * certificate, this value describes the depth of subordinate CA
       * certificates that are allowed.
       * If this value is less than 0, the request will fail.
       * If this value is missing, the max path length will be omitted from the
       * CA certificate.
       * </pre>
       *
       * <code>optional int32 max_issuer_path_length = 2 [(.google.api.field_behavior) = OPTIONAL];
       * </code>
       *
       * @return This builder for chaining.
       */
      public Builder clearMaxIssuerPathLength() {
        bitField0_ = (bitField0_ & ~0x00000002);
        maxIssuerPathLength_ = 0;
        onChanged();
        return this;
      }

      @java.lang.Override
      public final Builder setUnknownFields(
          final com.google.protobuf.UnknownFieldSet unknownFields) {
        return super.setUnknownFields(unknownFields);
      }

      @java.lang.Override
      public final Builder mergeUnknownFields(
          final com.google.protobuf.UnknownFieldSet unknownFields) {
        return super.mergeUnknownFields(unknownFields);
      }

      // @@protoc_insertion_point(builder_scope:google.cloud.security.privateca.v1.X509Parameters.CaOptions)
    }

    // @@protoc_insertion_point(class_scope:google.cloud.security.privateca.v1.X509Parameters.CaOptions)
    private static final com.google.cloud.security.privateca.v1.X509Parameters.CaOptions
        DEFAULT_INSTANCE;

    static {
      DEFAULT_INSTANCE = new com.google.cloud.security.privateca.v1.X509Parameters.CaOptions();
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.CaOptions
        getDefaultInstance() {
      return DEFAULT_INSTANCE;
    }

    private static final com.google.protobuf.Parser<CaOptions> PARSER =
        new com.google.protobuf.AbstractParser<CaOptions>() {
          @java.lang.Override
          public CaOptions parsePartialFrom(
              com.google.protobuf.CodedInputStream input,
              com.google.protobuf.ExtensionRegistryLite extensionRegistry)
              throws com.google.protobuf.InvalidProtocolBufferException {
            Builder builder = newBuilder();
            try {
              builder.mergeFrom(input, extensionRegistry);
            } catch (com.google.protobuf.InvalidProtocolBufferException e) {
              throw e.setUnfinishedMessage(builder.buildPartial());
            } catch (com.google.protobuf.UninitializedMessageException e) {
              throw e.asInvalidProtocolBufferException()
                  .setUnfinishedMessage(builder.buildPartial());
            } catch (java.io.IOException e) {
              throw new com.google.protobuf.InvalidProtocolBufferException(e)
                  .setUnfinishedMessage(builder.buildPartial());
            }
            return builder.buildPartial();
          }
        };

    public static com.google.protobuf.Parser<CaOptions> parser() {
      return PARSER;
    }

    @java.lang.Override
    public com.google.protobuf.Parser<CaOptions> getParserForType() {
      return PARSER;
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.X509Parameters.CaOptions
        getDefaultInstanceForType() {
      return DEFAULT_INSTANCE;
    }
  }

  public interface NameConstraintsOrBuilder
      extends
      // @@protoc_insertion_point(interface_extends:google.cloud.security.privateca.v1.X509Parameters.NameConstraints)
      com.google.protobuf.MessageOrBuilder {

    /**
     *
     *
     * <pre>
     * Indicates whether or not the name constraints are marked critical.
     * </pre>
     *
     * <code>bool critical = 1;</code>
     *
     * @return The critical.
     */
    boolean getCritical();

    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @return A list containing the permittedDnsNames.
     */
    java.util.List<java.lang.String> getPermittedDnsNamesList();
    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @return The count of permittedDnsNames.
     */
    int getPermittedDnsNamesCount();
    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedDnsNames at the given index.
     */
    java.lang.String getPermittedDnsNames(int index);
    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedDnsNames at the given index.
     */
    com.google.protobuf.ByteString getPermittedDnsNamesBytes(int index);

    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @return A list containing the excludedDnsNames.
     */
    java.util.List<java.lang.String> getExcludedDnsNamesList();
    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @return The count of excludedDnsNames.
     */
    int getExcludedDnsNamesCount();
    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedDnsNames at the given index.
     */
    java.lang.String getExcludedDnsNames(int index);
    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedDnsNames at the given index.
     */
    com.google.protobuf.ByteString getExcludedDnsNamesBytes(int index);

    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @return A list containing the permittedIpRanges.
     */
    java.util.List<java.lang.String> getPermittedIpRangesList();
    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @return The count of permittedIpRanges.
     */
    int getPermittedIpRangesCount();
    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedIpRanges at the given index.
     */
    java.lang.String getPermittedIpRanges(int index);
    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedIpRanges at the given index.
     */
    com.google.protobuf.ByteString getPermittedIpRangesBytes(int index);

    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @return A list containing the excludedIpRanges.
     */
    java.util.List<java.lang.String> getExcludedIpRangesList();
    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @return The count of excludedIpRanges.
     */
    int getExcludedIpRangesCount();
    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedIpRanges at the given index.
     */
    java.lang.String getExcludedIpRanges(int index);
    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedIpRanges at the given index.
     */
    com.google.protobuf.ByteString getExcludedIpRangesBytes(int index);

    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @return A list containing the permittedEmailAddresses.
     */
    java.util.List<java.lang.String> getPermittedEmailAddressesList();
    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @return The count of permittedEmailAddresses.
     */
    int getPermittedEmailAddressesCount();
    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedEmailAddresses at the given index.
     */
    java.lang.String getPermittedEmailAddresses(int index);
    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedEmailAddresses at the given index.
     */
    com.google.protobuf.ByteString getPermittedEmailAddressesBytes(int index);

    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @return A list containing the excludedEmailAddresses.
     */
    java.util.List<java.lang.String> getExcludedEmailAddressesList();
    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @return The count of excludedEmailAddresses.
     */
    int getExcludedEmailAddressesCount();
    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedEmailAddresses at the given index.
     */
    java.lang.String getExcludedEmailAddresses(int index);
    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedEmailAddresses at the given index.
     */
    com.google.protobuf.ByteString getExcludedEmailAddressesBytes(int index);

    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @return A list containing the permittedUris.
     */
    java.util.List<java.lang.String> getPermittedUrisList();
    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @return The count of permittedUris.
     */
    int getPermittedUrisCount();
    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedUris at the given index.
     */
    java.lang.String getPermittedUris(int index);
    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedUris at the given index.
     */
    com.google.protobuf.ByteString getPermittedUrisBytes(int index);

    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @return A list containing the excludedUris.
     */
    java.util.List<java.lang.String> getExcludedUrisList();
    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @return The count of excludedUris.
     */
    int getExcludedUrisCount();
    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedUris at the given index.
     */
    java.lang.String getExcludedUris(int index);
    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedUris at the given index.
     */
    com.google.protobuf.ByteString getExcludedUrisBytes(int index);
  }
  /**
   *
   *
   * <pre>
   * Describes the X.509 name constraints extension, per
   * https://tools.ietf.org/html/rfc5280#section-4.2.1.10
   * </pre>
   *
   * Protobuf type {@code google.cloud.security.privateca.v1.X509Parameters.NameConstraints}
   */
  public static final class NameConstraints extends com.google.protobuf.GeneratedMessageV3
      implements
      // @@protoc_insertion_point(message_implements:google.cloud.security.privateca.v1.X509Parameters.NameConstraints)
      NameConstraintsOrBuilder {
    private static final long serialVersionUID = 0L;
    // Use NameConstraints.newBuilder() to construct.
    private NameConstraints(com.google.protobuf.GeneratedMessageV3.Builder<?> builder) {
      super(builder);
    }

    private NameConstraints() {
      permittedDnsNames_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      excludedDnsNames_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      permittedIpRanges_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      excludedIpRanges_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      permittedEmailAddresses_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      excludedEmailAddresses_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      permittedUris_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      excludedUris_ = com.google.protobuf.LazyStringArrayList.EMPTY;
    }

    @java.lang.Override
    @SuppressWarnings({"unused"})
    protected java.lang.Object newInstance(UnusedPrivateParameter unused) {
      return new NameConstraints();
    }

    @java.lang.Override
    public final com.google.protobuf.UnknownFieldSet getUnknownFields() {
      return this.unknownFields;
    }

    public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_X509Parameters_NameConstraints_descriptor;
    }

    @java.lang.Override
    protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
        internalGetFieldAccessorTable() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_X509Parameters_NameConstraints_fieldAccessorTable
          .ensureFieldAccessorsInitialized(
              com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.class,
              com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.Builder.class);
    }

    public static final int CRITICAL_FIELD_NUMBER = 1;
    private boolean critical_ = false;
    /**
     *
     *
     * <pre>
     * Indicates whether or not the name constraints are marked critical.
     * </pre>
     *
     * <code>bool critical = 1;</code>
     *
     * @return The critical.
     */
    @java.lang.Override
    public boolean getCritical() {
      return critical_;
    }

    public static final int PERMITTED_DNS_NAMES_FIELD_NUMBER = 2;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList permittedDnsNames_;
    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @return A list containing the permittedDnsNames.
     */
    public com.google.protobuf.ProtocolStringList getPermittedDnsNamesList() {
      return permittedDnsNames_;
    }
    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @return The count of permittedDnsNames.
     */
    public int getPermittedDnsNamesCount() {
      return permittedDnsNames_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedDnsNames at the given index.
     */
    public java.lang.String getPermittedDnsNames(int index) {
      return permittedDnsNames_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains permitted DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string permitted_dns_names = 2;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedDnsNames at the given index.
     */
    public com.google.protobuf.ByteString getPermittedDnsNamesBytes(int index) {
      return permittedDnsNames_.getByteString(index);
    }

    public static final int EXCLUDED_DNS_NAMES_FIELD_NUMBER = 3;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList excludedDnsNames_;
    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @return A list containing the excludedDnsNames.
     */
    public com.google.protobuf.ProtocolStringList getExcludedDnsNamesList() {
      return excludedDnsNames_;
    }
    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @return The count of excludedDnsNames.
     */
    public int getExcludedDnsNamesCount() {
      return excludedDnsNames_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedDnsNames at the given index.
     */
    public java.lang.String getExcludedDnsNames(int index) {
      return excludedDnsNames_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains excluded DNS names. Any DNS name that can be
     * constructed by simply adding zero or more labels to
     * the left-hand side of the name satisfies the name constraint.
     * For example, `example.com`, `www.example.com`, `www.sub.example.com`
     * would satisfy `example.com` while `example1.com` does not.
     * </pre>
     *
     * <code>repeated string excluded_dns_names = 3;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedDnsNames at the given index.
     */
    public com.google.protobuf.ByteString getExcludedDnsNamesBytes(int index) {
      return excludedDnsNames_.getByteString(index);
    }

    public static final int PERMITTED_IP_RANGES_FIELD_NUMBER = 4;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList permittedIpRanges_;
    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @return A list containing the permittedIpRanges.
     */
    public com.google.protobuf.ProtocolStringList getPermittedIpRangesList() {
      return permittedIpRanges_;
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @return The count of permittedIpRanges.
     */
    public int getPermittedIpRangesCount() {
      return permittedIpRanges_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedIpRanges at the given index.
     */
    public java.lang.String getPermittedIpRanges(int index) {
      return permittedIpRanges_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string permitted_ip_ranges = 4;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedIpRanges at the given index.
     */
    public com.google.protobuf.ByteString getPermittedIpRangesBytes(int index) {
      return permittedIpRanges_.getByteString(index);
    }

    public static final int EXCLUDED_IP_RANGES_FIELD_NUMBER = 5;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList excludedIpRanges_;
    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @return A list containing the excludedIpRanges.
     */
    public com.google.protobuf.ProtocolStringList getExcludedIpRangesList() {
      return excludedIpRanges_;
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @return The count of excludedIpRanges.
     */
    public int getExcludedIpRangesCount() {
      return excludedIpRanges_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedIpRanges at the given index.
     */
    public java.lang.String getExcludedIpRanges(int index) {
      return excludedIpRanges_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded IP ranges. For IPv4 addresses, the ranges
     * are expressed using CIDR notation as specified in RFC 4632.
     * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
     * addresses.
     * </pre>
     *
     * <code>repeated string excluded_ip_ranges = 5;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedIpRanges at the given index.
     */
    public com.google.protobuf.ByteString getExcludedIpRangesBytes(int index) {
      return excludedIpRanges_.getByteString(index);
    }

    public static final int PERMITTED_EMAIL_ADDRESSES_FIELD_NUMBER = 6;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList permittedEmailAddresses_;
    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @return A list containing the permittedEmailAddresses.
     */
    public com.google.protobuf.ProtocolStringList getPermittedEmailAddressesList() {
      return permittedEmailAddresses_;
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @return The count of permittedEmailAddresses.
     */
    public int getPermittedEmailAddressesCount() {
      return permittedEmailAddresses_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedEmailAddresses at the given index.
     */
    public java.lang.String getPermittedEmailAddresses(int index) {
      return permittedEmailAddresses_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string permitted_email_addresses = 6;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedEmailAddresses at the given index.
     */
    public com.google.protobuf.ByteString getPermittedEmailAddressesBytes(int index) {
      return permittedEmailAddresses_.getByteString(index);
    }

    public static final int EXCLUDED_EMAIL_ADDRESSES_FIELD_NUMBER = 7;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList excludedEmailAddresses_;
    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @return A list containing the excludedEmailAddresses.
     */
    public com.google.protobuf.ProtocolStringList getExcludedEmailAddressesList() {
      return excludedEmailAddresses_;
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @return The count of excludedEmailAddresses.
     */
    public int getExcludedEmailAddressesCount() {
      return excludedEmailAddresses_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedEmailAddresses at the given index.
     */
    public java.lang.String getExcludedEmailAddresses(int index) {
      return excludedEmailAddresses_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded email addresses. The value can be a particular
     * email address, a hostname to indicate all email addresses on that host or
     * a domain with a leading period (e.g. `.example.com`) to indicate
     * all email addresses in that domain.
     * </pre>
     *
     * <code>repeated string excluded_email_addresses = 7;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedEmailAddresses at the given index.
     */
    public com.google.protobuf.ByteString getExcludedEmailAddressesBytes(int index) {
      return excludedEmailAddresses_.getByteString(index);
    }

    public static final int PERMITTED_URIS_FIELD_NUMBER = 8;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList permittedUris_;
    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @return A list containing the permittedUris.
     */
    public com.google.protobuf.ProtocolStringList getPermittedUrisList() {
      return permittedUris_;
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @return The count of permittedUris.
     */
    public int getPermittedUrisCount() {
      return permittedUris_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @param index The index of the element to return.
     * @return The permittedUris at the given index.
     */
    public java.lang.String getPermittedUris(int index) {
      return permittedUris_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains the permitted URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string permitted_uris = 8;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the permittedUris at the given index.
     */
    public com.google.protobuf.ByteString getPermittedUrisBytes(int index) {
      return permittedUris_.getByteString(index);
    }

    public static final int EXCLUDED_URIS_FIELD_NUMBER = 9;

    @SuppressWarnings("serial")
    private com.google.protobuf.LazyStringList excludedUris_;
    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @return A list containing the excludedUris.
     */
    public com.google.protobuf.ProtocolStringList getExcludedUrisList() {
      return excludedUris_;
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @return The count of excludedUris.
     */
    public int getExcludedUrisCount() {
      return excludedUris_.size();
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @param index The index of the element to return.
     * @return The excludedUris at the given index.
     */
    public java.lang.String getExcludedUris(int index) {
      return excludedUris_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Contains the excluded URIs that apply to the host part of the name.
     * The value can be a hostname or a domain with a
     * leading period (like `.example.com`)
     * </pre>
     *
     * <code>repeated string excluded_uris = 9;</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the excludedUris at the given index.
     */
    public com.google.protobuf.ByteString getExcludedUrisBytes(int index) {
      return excludedUris_.getByteString(index);
    }

    private byte memoizedIsInitialized = -1;

    @java.lang.Override
    public final boolean isInitialized() {
      byte isInitialized = memoizedIsInitialized;
      if (isInitialized == 1) return true;
      if (isInitialized == 0) return false;

      memoizedIsInitialized = 1;
      return true;
    }

    @java.lang.Override
    public void writeTo(com.google.protobuf.CodedOutputStream output) throws java.io.IOException {
      if (critical_ != false) {
        output.writeBool(1, critical_);
      }
      for (int i = 0; i < permittedDnsNames_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(output, 2, permittedDnsNames_.getRaw(i));
      }
      for (int i = 0; i < excludedDnsNames_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(output, 3, excludedDnsNames_.getRaw(i));
      }
      for (int i = 0; i < permittedIpRanges_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(output, 4, permittedIpRanges_.getRaw(i));
      }
      for (int i = 0; i < excludedIpRanges_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(output, 5, excludedIpRanges_.getRaw(i));
      }
      for (int i = 0; i < permittedEmailAddresses_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(
            output, 6, permittedEmailAddresses_.getRaw(i));
      }
      for (int i = 0; i < excludedEmailAddresses_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(
            output, 7, excludedEmailAddresses_.getRaw(i));
      }
      for (int i = 0; i < permittedUris_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(output, 8, permittedUris_.getRaw(i));
      }
      for (int i = 0; i < excludedUris_.size(); i++) {
        com.google.protobuf.GeneratedMessageV3.writeString(output, 9, excludedUris_.getRaw(i));
      }
      getUnknownFields().writeTo(output);
    }

    @java.lang.Override
    public int getSerializedSize() {
      int size = memoizedSize;
      if (size != -1) return size;

      size = 0;
      if (critical_ != false) {
        size += com.google.protobuf.CodedOutputStream.computeBoolSize(1, critical_);
      }
      {
        int dataSize = 0;
        for (int i = 0; i < permittedDnsNames_.size(); i++) {
          dataSize += computeStringSizeNoTag(permittedDnsNames_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getPermittedDnsNamesList().size();
      }
      {
        int dataSize = 0;
        for (int i = 0; i < excludedDnsNames_.size(); i++) {
          dataSize += computeStringSizeNoTag(excludedDnsNames_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getExcludedDnsNamesList().size();
      }
      {
        int dataSize = 0;
        for (int i = 0; i < permittedIpRanges_.size(); i++) {
          dataSize += computeStringSizeNoTag(permittedIpRanges_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getPermittedIpRangesList().size();
      }
      {
        int dataSize = 0;
        for (int i = 0; i < excludedIpRanges_.size(); i++) {
          dataSize += computeStringSizeNoTag(excludedIpRanges_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getExcludedIpRangesList().size();
      }
      {
        int dataSize = 0;
        for (int i = 0; i < permittedEmailAddresses_.size(); i++) {
          dataSize += computeStringSizeNoTag(permittedEmailAddresses_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getPermittedEmailAddressesList().size();
      }
      {
        int dataSize = 0;
        for (int i = 0; i < excludedEmailAddresses_.size(); i++) {
          dataSize += computeStringSizeNoTag(excludedEmailAddresses_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getExcludedEmailAddressesList().size();
      }
      {
        int dataSize = 0;
        for (int i = 0; i < permittedUris_.size(); i++) {
          dataSize += computeStringSizeNoTag(permittedUris_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getPermittedUrisList().size();
      }
      {
        int dataSize = 0;
        for (int i = 0; i < excludedUris_.size(); i++) {
          dataSize += computeStringSizeNoTag(excludedUris_.getRaw(i));
        }
        size += dataSize;
        size += 1 * getExcludedUrisList().size();
      }
      size += getUnknownFields().getSerializedSize();
      memoizedSize = size;
      return size;
    }

    @java.lang.Override
    public boolean equals(final java.lang.Object obj) {
      if (obj == this) {
        return true;
      }
      if (!(obj instanceof com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints)) {
        return super.equals(obj);
      }
      com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints other =
          (com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints) obj;

      if (getCritical() != other.getCritical()) return false;
      if (!getPermittedDnsNamesList().equals(other.getPermittedDnsNamesList())) return false;
      if (!getExcludedDnsNamesList().equals(other.getExcludedDnsNamesList())) return false;
      if (!getPermittedIpRangesList().equals(other.getPermittedIpRangesList())) return false;
      if (!getExcludedIpRangesList().equals(other.getExcludedIpRangesList())) return false;
      if (!getPermittedEmailAddressesList().equals(other.getPermittedEmailAddressesList()))
        return false;
      if (!getExcludedEmailAddressesList().equals(other.getExcludedEmailAddressesList()))
        return false;
      if (!getPermittedUrisList().equals(other.getPermittedUrisList())) return false;
      if (!getExcludedUrisList().equals(other.getExcludedUrisList())) return false;
      if (!getUnknownFields().equals(other.getUnknownFields())) return false;
      return true;
    }

    @java.lang.Override
    public int hashCode() {
      if (memoizedHashCode != 0) {
        return memoizedHashCode;
      }
      int hash = 41;
      hash = (19 * hash) + getDescriptor().hashCode();
      hash = (37 * hash) + CRITICAL_FIELD_NUMBER;
      hash = (53 * hash) + com.google.protobuf.Internal.hashBoolean(getCritical());
      if (getPermittedDnsNamesCount() > 0) {
        hash = (37 * hash) + PERMITTED_DNS_NAMES_FIELD_NUMBER;
        hash = (53 * hash) + getPermittedDnsNamesList().hashCode();
      }
      if (getExcludedDnsNamesCount() > 0) {
        hash = (37 * hash) + EXCLUDED_DNS_NAMES_FIELD_NUMBER;
        hash = (53 * hash) + getExcludedDnsNamesList().hashCode();
      }
      if (getPermittedIpRangesCount() > 0) {
        hash = (37 * hash) + PERMITTED_IP_RANGES_FIELD_NUMBER;
        hash = (53 * hash) + getPermittedIpRangesList().hashCode();
      }
      if (getExcludedIpRangesCount() > 0) {
        hash = (37 * hash) + EXCLUDED_IP_RANGES_FIELD_NUMBER;
        hash = (53 * hash) + getExcludedIpRangesList().hashCode();
      }
      if (getPermittedEmailAddressesCount() > 0) {
        hash = (37 * hash) + PERMITTED_EMAIL_ADDRESSES_FIELD_NUMBER;
        hash = (53 * hash) + getPermittedEmailAddressesList().hashCode();
      }
      if (getExcludedEmailAddressesCount() > 0) {
        hash = (37 * hash) + EXCLUDED_EMAIL_ADDRESSES_FIELD_NUMBER;
        hash = (53 * hash) + getExcludedEmailAddressesList().hashCode();
      }
      if (getPermittedUrisCount() > 0) {
        hash = (37 * hash) + PERMITTED_URIS_FIELD_NUMBER;
        hash = (53 * hash) + getPermittedUrisList().hashCode();
      }
      if (getExcludedUrisCount() > 0) {
        hash = (37 * hash) + EXCLUDED_URIS_FIELD_NUMBER;
        hash = (53 * hash) + getExcludedUrisList().hashCode();
      }
      hash = (29 * hash) + getUnknownFields().hashCode();
      memoizedHashCode = hash;
      return hash;
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        java.nio.ByteBuffer data) throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        java.nio.ByteBuffer data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        com.google.protobuf.ByteString data)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        com.google.protobuf.ByteString data,
        com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        byte[] data) throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        byte[] data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws com.google.protobuf.InvalidProtocolBufferException {
      return PARSER.parseFrom(data, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        java.io.InputStream input) throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
          PARSER, input, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
        parseDelimitedFrom(java.io.InputStream input) throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(PARSER, input);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
        parseDelimitedFrom(
            java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
            throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(
          PARSER, input, extensionRegistry);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        com.google.protobuf.CodedInputStream input) throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints parseFrom(
        com.google.protobuf.CodedInputStream input,
        com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws java.io.IOException {
      return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
          PARSER, input, extensionRegistry);
    }

    @java.lang.Override
    public Builder newBuilderForType() {
      return newBuilder();
    }

    public static Builder newBuilder() {
      return DEFAULT_INSTANCE.toBuilder();
    }

    public static Builder newBuilder(
        com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints prototype) {
      return DEFAULT_INSTANCE.toBuilder().mergeFrom(prototype);
    }

    @java.lang.Override
    public Builder toBuilder() {
      return this == DEFAULT_INSTANCE ? new Builder() : new Builder().mergeFrom(this);
    }

    @java.lang.Override
    protected Builder newBuilderForType(
        com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
      Builder builder = new Builder(parent);
      return builder;
    }
    /**
     *
     *
     * <pre>
     * Describes the X.509 name constraints extension, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.10
     * </pre>
     *
     * Protobuf type {@code google.cloud.security.privateca.v1.X509Parameters.NameConstraints}
     */
    public static final class Builder
        extends com.google.protobuf.GeneratedMessageV3.Builder<Builder>
        implements
        // @@protoc_insertion_point(builder_implements:google.cloud.security.privateca.v1.X509Parameters.NameConstraints)
        com.google.cloud.security.privateca.v1.X509Parameters.NameConstraintsOrBuilder {
      public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
        return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
            .internal_static_google_cloud_security_privateca_v1_X509Parameters_NameConstraints_descriptor;
      }

      @java.lang.Override
      protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
          internalGetFieldAccessorTable() {
        return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
            .internal_static_google_cloud_security_privateca_v1_X509Parameters_NameConstraints_fieldAccessorTable
            .ensureFieldAccessorsInitialized(
                com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.class,
                com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.Builder
                    .class);
      }

      // Construct using
      // com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.newBuilder()
      private Builder() {}

      private Builder(com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
        super(parent);
      }

      @java.lang.Override
      public Builder clear() {
        super.clear();
        bitField0_ = 0;
        critical_ = false;
        permittedDnsNames_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000002);
        excludedDnsNames_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000004);
        permittedIpRanges_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000008);
        excludedIpRanges_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000010);
        permittedEmailAddresses_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000020);
        excludedEmailAddresses_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000040);
        permittedUris_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000080);
        excludedUris_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000100);
        return this;
      }

      @java.lang.Override
      public com.google.protobuf.Descriptors.Descriptor getDescriptorForType() {
        return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
            .internal_static_google_cloud_security_privateca_v1_X509Parameters_NameConstraints_descriptor;
      }

      @java.lang.Override
      public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
          getDefaultInstanceForType() {
        return com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
            .getDefaultInstance();
      }

      @java.lang.Override
      public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints build() {
        com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints result =
            buildPartial();
        if (!result.isInitialized()) {
          throw newUninitializedMessageException(result);
        }
        return result;
      }

      @java.lang.Override
      public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints buildPartial() {
        com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints result =
            new com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints(this);
        buildPartialRepeatedFields(result);
        if (bitField0_ != 0) {
          buildPartial0(result);
        }
        onBuilt();
        return result;
      }

      private void buildPartialRepeatedFields(
          com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints result) {
        if (((bitField0_ & 0x00000002) != 0)) {
          permittedDnsNames_ = permittedDnsNames_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000002);
        }
        result.permittedDnsNames_ = permittedDnsNames_;
        if (((bitField0_ & 0x00000004) != 0)) {
          excludedDnsNames_ = excludedDnsNames_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000004);
        }
        result.excludedDnsNames_ = excludedDnsNames_;
        if (((bitField0_ & 0x00000008) != 0)) {
          permittedIpRanges_ = permittedIpRanges_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000008);
        }
        result.permittedIpRanges_ = permittedIpRanges_;
        if (((bitField0_ & 0x00000010) != 0)) {
          excludedIpRanges_ = excludedIpRanges_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000010);
        }
        result.excludedIpRanges_ = excludedIpRanges_;
        if (((bitField0_ & 0x00000020) != 0)) {
          permittedEmailAddresses_ = permittedEmailAddresses_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000020);
        }
        result.permittedEmailAddresses_ = permittedEmailAddresses_;
        if (((bitField0_ & 0x00000040) != 0)) {
          excludedEmailAddresses_ = excludedEmailAddresses_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000040);
        }
        result.excludedEmailAddresses_ = excludedEmailAddresses_;
        if (((bitField0_ & 0x00000080) != 0)) {
          permittedUris_ = permittedUris_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000080);
        }
        result.permittedUris_ = permittedUris_;
        if (((bitField0_ & 0x00000100) != 0)) {
          excludedUris_ = excludedUris_.getUnmodifiableView();
          bitField0_ = (bitField0_ & ~0x00000100);
        }
        result.excludedUris_ = excludedUris_;
      }

      private void buildPartial0(
          com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints result) {
        int from_bitField0_ = bitField0_;
        if (((from_bitField0_ & 0x00000001) != 0)) {
          result.critical_ = critical_;
        }
      }

      @java.lang.Override
      public Builder clone() {
        return super.clone();
      }

      @java.lang.Override
      public Builder setField(
          com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
        return super.setField(field, value);
      }

      @java.lang.Override
      public Builder clearField(com.google.protobuf.Descriptors.FieldDescriptor field) {
        return super.clearField(field);
      }

      @java.lang.Override
      public Builder clearOneof(com.google.protobuf.Descriptors.OneofDescriptor oneof) {
        return super.clearOneof(oneof);
      }

      @java.lang.Override
      public Builder setRepeatedField(
          com.google.protobuf.Descriptors.FieldDescriptor field,
          int index,
          java.lang.Object value) {
        return super.setRepeatedField(field, index, value);
      }

      @java.lang.Override
      public Builder addRepeatedField(
          com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
        return super.addRepeatedField(field, value);
      }

      @java.lang.Override
      public Builder mergeFrom(com.google.protobuf.Message other) {
        if (other
            instanceof com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints) {
          return mergeFrom(
              (com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints) other);
        } else {
          super.mergeFrom(other);
          return this;
        }
      }

      public Builder mergeFrom(
          com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints other) {
        if (other
            == com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
                .getDefaultInstance()) return this;
        if (other.getCritical() != false) {
          setCritical(other.getCritical());
        }
        if (!other.permittedDnsNames_.isEmpty()) {
          if (permittedDnsNames_.isEmpty()) {
            permittedDnsNames_ = other.permittedDnsNames_;
            bitField0_ = (bitField0_ & ~0x00000002);
          } else {
            ensurePermittedDnsNamesIsMutable();
            permittedDnsNames_.addAll(other.permittedDnsNames_);
          }
          onChanged();
        }
        if (!other.excludedDnsNames_.isEmpty()) {
          if (excludedDnsNames_.isEmpty()) {
            excludedDnsNames_ = other.excludedDnsNames_;
            bitField0_ = (bitField0_ & ~0x00000004);
          } else {
            ensureExcludedDnsNamesIsMutable();
            excludedDnsNames_.addAll(other.excludedDnsNames_);
          }
          onChanged();
        }
        if (!other.permittedIpRanges_.isEmpty()) {
          if (permittedIpRanges_.isEmpty()) {
            permittedIpRanges_ = other.permittedIpRanges_;
            bitField0_ = (bitField0_ & ~0x00000008);
          } else {
            ensurePermittedIpRangesIsMutable();
            permittedIpRanges_.addAll(other.permittedIpRanges_);
          }
          onChanged();
        }
        if (!other.excludedIpRanges_.isEmpty()) {
          if (excludedIpRanges_.isEmpty()) {
            excludedIpRanges_ = other.excludedIpRanges_;
            bitField0_ = (bitField0_ & ~0x00000010);
          } else {
            ensureExcludedIpRangesIsMutable();
            excludedIpRanges_.addAll(other.excludedIpRanges_);
          }
          onChanged();
        }
        if (!other.permittedEmailAddresses_.isEmpty()) {
          if (permittedEmailAddresses_.isEmpty()) {
            permittedEmailAddresses_ = other.permittedEmailAddresses_;
            bitField0_ = (bitField0_ & ~0x00000020);
          } else {
            ensurePermittedEmailAddressesIsMutable();
            permittedEmailAddresses_.addAll(other.permittedEmailAddresses_);
          }
          onChanged();
        }
        if (!other.excludedEmailAddresses_.isEmpty()) {
          if (excludedEmailAddresses_.isEmpty()) {
            excludedEmailAddresses_ = other.excludedEmailAddresses_;
            bitField0_ = (bitField0_ & ~0x00000040);
          } else {
            ensureExcludedEmailAddressesIsMutable();
            excludedEmailAddresses_.addAll(other.excludedEmailAddresses_);
          }
          onChanged();
        }
        if (!other.permittedUris_.isEmpty()) {
          if (permittedUris_.isEmpty()) {
            permittedUris_ = other.permittedUris_;
            bitField0_ = (bitField0_ & ~0x00000080);
          } else {
            ensurePermittedUrisIsMutable();
            permittedUris_.addAll(other.permittedUris_);
          }
          onChanged();
        }
        if (!other.excludedUris_.isEmpty()) {
          if (excludedUris_.isEmpty()) {
            excludedUris_ = other.excludedUris_;
            bitField0_ = (bitField0_ & ~0x00000100);
          } else {
            ensureExcludedUrisIsMutable();
            excludedUris_.addAll(other.excludedUris_);
          }
          onChanged();
        }
        this.mergeUnknownFields(other.getUnknownFields());
        onChanged();
        return this;
      }

      @java.lang.Override
      public final boolean isInitialized() {
        return true;
      }

      @java.lang.Override
      public Builder mergeFrom(
          com.google.protobuf.CodedInputStream input,
          com.google.protobuf.ExtensionRegistryLite extensionRegistry)
          throws java.io.IOException {
        if (extensionRegistry == null) {
          throw new java.lang.NullPointerException();
        }
        try {
          boolean done = false;
          while (!done) {
            int tag = input.readTag();
            switch (tag) {
              case 0:
                done = true;
                break;
              case 8:
                {
                  critical_ = input.readBool();
                  bitField0_ |= 0x00000001;
                  break;
                } // case 8
              case 18:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensurePermittedDnsNamesIsMutable();
                  permittedDnsNames_.add(s);
                  break;
                } // case 18
              case 26:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensureExcludedDnsNamesIsMutable();
                  excludedDnsNames_.add(s);
                  break;
                } // case 26
              case 34:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensurePermittedIpRangesIsMutable();
                  permittedIpRanges_.add(s);
                  break;
                } // case 34
              case 42:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensureExcludedIpRangesIsMutable();
                  excludedIpRanges_.add(s);
                  break;
                } // case 42
              case 50:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensurePermittedEmailAddressesIsMutable();
                  permittedEmailAddresses_.add(s);
                  break;
                } // case 50
              case 58:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensureExcludedEmailAddressesIsMutable();
                  excludedEmailAddresses_.add(s);
                  break;
                } // case 58
              case 66:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensurePermittedUrisIsMutable();
                  permittedUris_.add(s);
                  break;
                } // case 66
              case 74:
                {
                  java.lang.String s = input.readStringRequireUtf8();
                  ensureExcludedUrisIsMutable();
                  excludedUris_.add(s);
                  break;
                } // case 74
              default:
                {
                  if (!super.parseUnknownField(input, extensionRegistry, tag)) {
                    done = true; // was an endgroup tag
                  }
                  break;
                } // default:
            } // switch (tag)
          } // while (!done)
        } catch (com.google.protobuf.InvalidProtocolBufferException e) {
          throw e.unwrapIOException();
        } finally {
          onChanged();
        } // finally
        return this;
      }

      private int bitField0_;

      private boolean critical_;
      /**
       *
       *
       * <pre>
       * Indicates whether or not the name constraints are marked critical.
       * </pre>
       *
       * <code>bool critical = 1;</code>
       *
       * @return The critical.
       */
      @java.lang.Override
      public boolean getCritical() {
        return critical_;
      }
      /**
       *
       *
       * <pre>
       * Indicates whether or not the name constraints are marked critical.
       * </pre>
       *
       * <code>bool critical = 1;</code>
       *
       * @param value The critical to set.
       * @return This builder for chaining.
       */
      public Builder setCritical(boolean value) {

        critical_ = value;
        bitField0_ |= 0x00000001;
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Indicates whether or not the name constraints are marked critical.
       * </pre>
       *
       * <code>bool critical = 1;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearCritical() {
        bitField0_ = (bitField0_ & ~0x00000001);
        critical_ = false;
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList permittedDnsNames_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensurePermittedDnsNamesIsMutable() {
        if (!((bitField0_ & 0x00000002) != 0)) {
          permittedDnsNames_ = new com.google.protobuf.LazyStringArrayList(permittedDnsNames_);
          bitField0_ |= 0x00000002;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @return A list containing the permittedDnsNames.
       */
      public com.google.protobuf.ProtocolStringList getPermittedDnsNamesList() {
        return permittedDnsNames_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @return The count of permittedDnsNames.
       */
      public int getPermittedDnsNamesCount() {
        return permittedDnsNames_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @param index The index of the element to return.
       * @return The permittedDnsNames at the given index.
       */
      public java.lang.String getPermittedDnsNames(int index) {
        return permittedDnsNames_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the permittedDnsNames at the given index.
       */
      public com.google.protobuf.ByteString getPermittedDnsNamesBytes(int index) {
        return permittedDnsNames_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @param index The index to set the value at.
       * @param value The permittedDnsNames to set.
       * @return This builder for chaining.
       */
      public Builder setPermittedDnsNames(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedDnsNamesIsMutable();
        permittedDnsNames_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @param value The permittedDnsNames to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedDnsNames(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedDnsNamesIsMutable();
        permittedDnsNames_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @param values The permittedDnsNames to add.
       * @return This builder for chaining.
       */
      public Builder addAllPermittedDnsNames(java.lang.Iterable<java.lang.String> values) {
        ensurePermittedDnsNamesIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, permittedDnsNames_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearPermittedDnsNames() {
        permittedDnsNames_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000002);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains permitted DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string permitted_dns_names = 2;</code>
       *
       * @param value The bytes of the permittedDnsNames to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedDnsNamesBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensurePermittedDnsNamesIsMutable();
        permittedDnsNames_.add(value);
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList excludedDnsNames_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensureExcludedDnsNamesIsMutable() {
        if (!((bitField0_ & 0x00000004) != 0)) {
          excludedDnsNames_ = new com.google.protobuf.LazyStringArrayList(excludedDnsNames_);
          bitField0_ |= 0x00000004;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @return A list containing the excludedDnsNames.
       */
      public com.google.protobuf.ProtocolStringList getExcludedDnsNamesList() {
        return excludedDnsNames_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @return The count of excludedDnsNames.
       */
      public int getExcludedDnsNamesCount() {
        return excludedDnsNames_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @param index The index of the element to return.
       * @return The excludedDnsNames at the given index.
       */
      public java.lang.String getExcludedDnsNames(int index) {
        return excludedDnsNames_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the excludedDnsNames at the given index.
       */
      public com.google.protobuf.ByteString getExcludedDnsNamesBytes(int index) {
        return excludedDnsNames_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @param index The index to set the value at.
       * @param value The excludedDnsNames to set.
       * @return This builder for chaining.
       */
      public Builder setExcludedDnsNames(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedDnsNamesIsMutable();
        excludedDnsNames_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @param value The excludedDnsNames to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedDnsNames(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedDnsNamesIsMutable();
        excludedDnsNames_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @param values The excludedDnsNames to add.
       * @return This builder for chaining.
       */
      public Builder addAllExcludedDnsNames(java.lang.Iterable<java.lang.String> values) {
        ensureExcludedDnsNamesIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, excludedDnsNames_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearExcludedDnsNames() {
        excludedDnsNames_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000004);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains excluded DNS names. Any DNS name that can be
       * constructed by simply adding zero or more labels to
       * the left-hand side of the name satisfies the name constraint.
       * For example, `example.com`, `www.example.com`, `www.sub.example.com`
       * would satisfy `example.com` while `example1.com` does not.
       * </pre>
       *
       * <code>repeated string excluded_dns_names = 3;</code>
       *
       * @param value The bytes of the excludedDnsNames to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedDnsNamesBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensureExcludedDnsNamesIsMutable();
        excludedDnsNames_.add(value);
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList permittedIpRanges_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensurePermittedIpRangesIsMutable() {
        if (!((bitField0_ & 0x00000008) != 0)) {
          permittedIpRanges_ = new com.google.protobuf.LazyStringArrayList(permittedIpRanges_);
          bitField0_ |= 0x00000008;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @return A list containing the permittedIpRanges.
       */
      public com.google.protobuf.ProtocolStringList getPermittedIpRangesList() {
        return permittedIpRanges_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @return The count of permittedIpRanges.
       */
      public int getPermittedIpRangesCount() {
        return permittedIpRanges_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @param index The index of the element to return.
       * @return The permittedIpRanges at the given index.
       */
      public java.lang.String getPermittedIpRanges(int index) {
        return permittedIpRanges_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the permittedIpRanges at the given index.
       */
      public com.google.protobuf.ByteString getPermittedIpRangesBytes(int index) {
        return permittedIpRanges_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @param index The index to set the value at.
       * @param value The permittedIpRanges to set.
       * @return This builder for chaining.
       */
      public Builder setPermittedIpRanges(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedIpRangesIsMutable();
        permittedIpRanges_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @param value The permittedIpRanges to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedIpRanges(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedIpRangesIsMutable();
        permittedIpRanges_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @param values The permittedIpRanges to add.
       * @return This builder for chaining.
       */
      public Builder addAllPermittedIpRanges(java.lang.Iterable<java.lang.String> values) {
        ensurePermittedIpRangesIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, permittedIpRanges_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearPermittedIpRanges() {
        permittedIpRanges_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000008);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string permitted_ip_ranges = 4;</code>
       *
       * @param value The bytes of the permittedIpRanges to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedIpRangesBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensurePermittedIpRangesIsMutable();
        permittedIpRanges_.add(value);
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList excludedIpRanges_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensureExcludedIpRangesIsMutable() {
        if (!((bitField0_ & 0x00000010) != 0)) {
          excludedIpRanges_ = new com.google.protobuf.LazyStringArrayList(excludedIpRanges_);
          bitField0_ |= 0x00000010;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @return A list containing the excludedIpRanges.
       */
      public com.google.protobuf.ProtocolStringList getExcludedIpRangesList() {
        return excludedIpRanges_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @return The count of excludedIpRanges.
       */
      public int getExcludedIpRangesCount() {
        return excludedIpRanges_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @param index The index of the element to return.
       * @return The excludedIpRanges at the given index.
       */
      public java.lang.String getExcludedIpRanges(int index) {
        return excludedIpRanges_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the excludedIpRanges at the given index.
       */
      public com.google.protobuf.ByteString getExcludedIpRangesBytes(int index) {
        return excludedIpRanges_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @param index The index to set the value at.
       * @param value The excludedIpRanges to set.
       * @return This builder for chaining.
       */
      public Builder setExcludedIpRanges(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedIpRangesIsMutable();
        excludedIpRanges_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @param value The excludedIpRanges to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedIpRanges(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedIpRangesIsMutable();
        excludedIpRanges_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @param values The excludedIpRanges to add.
       * @return This builder for chaining.
       */
      public Builder addAllExcludedIpRanges(java.lang.Iterable<java.lang.String> values) {
        ensureExcludedIpRangesIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, excludedIpRanges_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearExcludedIpRanges() {
        excludedIpRanges_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000010);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded IP ranges. For IPv4 addresses, the ranges
       * are expressed using CIDR notation as specified in RFC 4632.
       * For IPv6 addresses, the ranges are expressed in similar encoding as IPv4
       * addresses.
       * </pre>
       *
       * <code>repeated string excluded_ip_ranges = 5;</code>
       *
       * @param value The bytes of the excludedIpRanges to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedIpRangesBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensureExcludedIpRangesIsMutable();
        excludedIpRanges_.add(value);
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList permittedEmailAddresses_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensurePermittedEmailAddressesIsMutable() {
        if (!((bitField0_ & 0x00000020) != 0)) {
          permittedEmailAddresses_ =
              new com.google.protobuf.LazyStringArrayList(permittedEmailAddresses_);
          bitField0_ |= 0x00000020;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @return A list containing the permittedEmailAddresses.
       */
      public com.google.protobuf.ProtocolStringList getPermittedEmailAddressesList() {
        return permittedEmailAddresses_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @return The count of permittedEmailAddresses.
       */
      public int getPermittedEmailAddressesCount() {
        return permittedEmailAddresses_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @param index The index of the element to return.
       * @return The permittedEmailAddresses at the given index.
       */
      public java.lang.String getPermittedEmailAddresses(int index) {
        return permittedEmailAddresses_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the permittedEmailAddresses at the given index.
       */
      public com.google.protobuf.ByteString getPermittedEmailAddressesBytes(int index) {
        return permittedEmailAddresses_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @param index The index to set the value at.
       * @param value The permittedEmailAddresses to set.
       * @return This builder for chaining.
       */
      public Builder setPermittedEmailAddresses(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedEmailAddressesIsMutable();
        permittedEmailAddresses_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @param value The permittedEmailAddresses to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedEmailAddresses(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedEmailAddressesIsMutable();
        permittedEmailAddresses_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @param values The permittedEmailAddresses to add.
       * @return This builder for chaining.
       */
      public Builder addAllPermittedEmailAddresses(java.lang.Iterable<java.lang.String> values) {
        ensurePermittedEmailAddressesIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, permittedEmailAddresses_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearPermittedEmailAddresses() {
        permittedEmailAddresses_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000020);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string permitted_email_addresses = 6;</code>
       *
       * @param value The bytes of the permittedEmailAddresses to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedEmailAddressesBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensurePermittedEmailAddressesIsMutable();
        permittedEmailAddresses_.add(value);
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList excludedEmailAddresses_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensureExcludedEmailAddressesIsMutable() {
        if (!((bitField0_ & 0x00000040) != 0)) {
          excludedEmailAddresses_ =
              new com.google.protobuf.LazyStringArrayList(excludedEmailAddresses_);
          bitField0_ |= 0x00000040;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @return A list containing the excludedEmailAddresses.
       */
      public com.google.protobuf.ProtocolStringList getExcludedEmailAddressesList() {
        return excludedEmailAddresses_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @return The count of excludedEmailAddresses.
       */
      public int getExcludedEmailAddressesCount() {
        return excludedEmailAddresses_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @param index The index of the element to return.
       * @return The excludedEmailAddresses at the given index.
       */
      public java.lang.String getExcludedEmailAddresses(int index) {
        return excludedEmailAddresses_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the excludedEmailAddresses at the given index.
       */
      public com.google.protobuf.ByteString getExcludedEmailAddressesBytes(int index) {
        return excludedEmailAddresses_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @param index The index to set the value at.
       * @param value The excludedEmailAddresses to set.
       * @return This builder for chaining.
       */
      public Builder setExcludedEmailAddresses(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedEmailAddressesIsMutable();
        excludedEmailAddresses_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @param value The excludedEmailAddresses to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedEmailAddresses(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedEmailAddressesIsMutable();
        excludedEmailAddresses_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @param values The excludedEmailAddresses to add.
       * @return This builder for chaining.
       */
      public Builder addAllExcludedEmailAddresses(java.lang.Iterable<java.lang.String> values) {
        ensureExcludedEmailAddressesIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, excludedEmailAddresses_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearExcludedEmailAddresses() {
        excludedEmailAddresses_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000040);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded email addresses. The value can be a particular
       * email address, a hostname to indicate all email addresses on that host or
       * a domain with a leading period (e.g. `.example.com`) to indicate
       * all email addresses in that domain.
       * </pre>
       *
       * <code>repeated string excluded_email_addresses = 7;</code>
       *
       * @param value The bytes of the excludedEmailAddresses to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedEmailAddressesBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensureExcludedEmailAddressesIsMutable();
        excludedEmailAddresses_.add(value);
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList permittedUris_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensurePermittedUrisIsMutable() {
        if (!((bitField0_ & 0x00000080) != 0)) {
          permittedUris_ = new com.google.protobuf.LazyStringArrayList(permittedUris_);
          bitField0_ |= 0x00000080;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @return A list containing the permittedUris.
       */
      public com.google.protobuf.ProtocolStringList getPermittedUrisList() {
        return permittedUris_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @return The count of permittedUris.
       */
      public int getPermittedUrisCount() {
        return permittedUris_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @param index The index of the element to return.
       * @return The permittedUris at the given index.
       */
      public java.lang.String getPermittedUris(int index) {
        return permittedUris_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the permittedUris at the given index.
       */
      public com.google.protobuf.ByteString getPermittedUrisBytes(int index) {
        return permittedUris_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @param index The index to set the value at.
       * @param value The permittedUris to set.
       * @return This builder for chaining.
       */
      public Builder setPermittedUris(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedUrisIsMutable();
        permittedUris_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @param value The permittedUris to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedUris(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePermittedUrisIsMutable();
        permittedUris_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @param values The permittedUris to add.
       * @return This builder for chaining.
       */
      public Builder addAllPermittedUris(java.lang.Iterable<java.lang.String> values) {
        ensurePermittedUrisIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, permittedUris_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearPermittedUris() {
        permittedUris_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000080);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the permitted URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string permitted_uris = 8;</code>
       *
       * @param value The bytes of the permittedUris to add.
       * @return This builder for chaining.
       */
      public Builder addPermittedUrisBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensurePermittedUrisIsMutable();
        permittedUris_.add(value);
        onChanged();
        return this;
      }

      private com.google.protobuf.LazyStringList excludedUris_ =
          com.google.protobuf.LazyStringArrayList.EMPTY;

      private void ensureExcludedUrisIsMutable() {
        if (!((bitField0_ & 0x00000100) != 0)) {
          excludedUris_ = new com.google.protobuf.LazyStringArrayList(excludedUris_);
          bitField0_ |= 0x00000100;
        }
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @return A list containing the excludedUris.
       */
      public com.google.protobuf.ProtocolStringList getExcludedUrisList() {
        return excludedUris_.getUnmodifiableView();
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @return The count of excludedUris.
       */
      public int getExcludedUrisCount() {
        return excludedUris_.size();
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @param index The index of the element to return.
       * @return The excludedUris at the given index.
       */
      public java.lang.String getExcludedUris(int index) {
        return excludedUris_.get(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @param index The index of the value to return.
       * @return The bytes of the excludedUris at the given index.
       */
      public com.google.protobuf.ByteString getExcludedUrisBytes(int index) {
        return excludedUris_.getByteString(index);
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @param index The index to set the value at.
       * @param value The excludedUris to set.
       * @return This builder for chaining.
       */
      public Builder setExcludedUris(int index, java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedUrisIsMutable();
        excludedUris_.set(index, value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @param value The excludedUris to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedUris(java.lang.String value) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureExcludedUrisIsMutable();
        excludedUris_.add(value);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @param values The excludedUris to add.
       * @return This builder for chaining.
       */
      public Builder addAllExcludedUris(java.lang.Iterable<java.lang.String> values) {
        ensureExcludedUrisIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, excludedUris_);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @return This builder for chaining.
       */
      public Builder clearExcludedUris() {
        excludedUris_ = com.google.protobuf.LazyStringArrayList.EMPTY;
        bitField0_ = (bitField0_ & ~0x00000100);
        onChanged();
        return this;
      }
      /**
       *
       *
       * <pre>
       * Contains the excluded URIs that apply to the host part of the name.
       * The value can be a hostname or a domain with a
       * leading period (like `.example.com`)
       * </pre>
       *
       * <code>repeated string excluded_uris = 9;</code>
       *
       * @param value The bytes of the excludedUris to add.
       * @return This builder for chaining.
       */
      public Builder addExcludedUrisBytes(com.google.protobuf.ByteString value) {
        if (value == null) {
          throw new NullPointerException();
        }
        checkByteStringIsUtf8(value);
        ensureExcludedUrisIsMutable();
        excludedUris_.add(value);
        onChanged();
        return this;
      }

      @java.lang.Override
      public final Builder setUnknownFields(
          final com.google.protobuf.UnknownFieldSet unknownFields) {
        return super.setUnknownFields(unknownFields);
      }

      @java.lang.Override
      public final Builder mergeUnknownFields(
          final com.google.protobuf.UnknownFieldSet unknownFields) {
        return super.mergeUnknownFields(unknownFields);
      }

      // @@protoc_insertion_point(builder_scope:google.cloud.security.privateca.v1.X509Parameters.NameConstraints)
    }

    // @@protoc_insertion_point(class_scope:google.cloud.security.privateca.v1.X509Parameters.NameConstraints)
    private static final com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
        DEFAULT_INSTANCE;

    static {
      DEFAULT_INSTANCE =
          new com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints();
    }

    public static com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
        getDefaultInstance() {
      return DEFAULT_INSTANCE;
    }

    private static final com.google.protobuf.Parser<NameConstraints> PARSER =
        new com.google.protobuf.AbstractParser<NameConstraints>() {
          @java.lang.Override
          public NameConstraints parsePartialFrom(
              com.google.protobuf.CodedInputStream input,
              com.google.protobuf.ExtensionRegistryLite extensionRegistry)
              throws com.google.protobuf.InvalidProtocolBufferException {
            Builder builder = newBuilder();
            try {
              builder.mergeFrom(input, extensionRegistry);
            } catch (com.google.protobuf.InvalidProtocolBufferException e) {
              throw e.setUnfinishedMessage(builder.buildPartial());
            } catch (com.google.protobuf.UninitializedMessageException e) {
              throw e.asInvalidProtocolBufferException()
                  .setUnfinishedMessage(builder.buildPartial());
            } catch (java.io.IOException e) {
              throw new com.google.protobuf.InvalidProtocolBufferException(e)
                  .setUnfinishedMessage(builder.buildPartial());
            }
            return builder.buildPartial();
          }
        };

    public static com.google.protobuf.Parser<NameConstraints> parser() {
      return PARSER;
    }

    @java.lang.Override
    public com.google.protobuf.Parser<NameConstraints> getParserForType() {
      return PARSER;
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
        getDefaultInstanceForType() {
      return DEFAULT_INSTANCE;
    }
  }

  public static final int KEY_USAGE_FIELD_NUMBER = 1;
  private com.google.cloud.security.privateca.v1.KeyUsage keyUsage_;
  /**
   *
   *
   * <pre>
   * Optional. Indicates the intended use for keys that correspond to a
   * certificate.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return Whether the keyUsage field is set.
   */
  @java.lang.Override
  public boolean hasKeyUsage() {
    return keyUsage_ != null;
  }
  /**
   *
   *
   * <pre>
   * Optional. Indicates the intended use for keys that correspond to a
   * certificate.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return The keyUsage.
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.KeyUsage getKeyUsage() {
    return keyUsage_ == null
        ? com.google.cloud.security.privateca.v1.KeyUsage.getDefaultInstance()
        : keyUsage_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Indicates the intended use for keys that correspond to a
   * certificate.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.KeyUsageOrBuilder getKeyUsageOrBuilder() {
    return keyUsage_ == null
        ? com.google.cloud.security.privateca.v1.KeyUsage.getDefaultInstance()
        : keyUsage_;
  }

  public static final int CA_OPTIONS_FIELD_NUMBER = 2;
  private com.google.cloud.security.privateca.v1.X509Parameters.CaOptions caOptions_;
  /**
   *
   *
   * <pre>
   * Optional. Describes options in this
   * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
   * are relevant in a CA certificate.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return Whether the caOptions field is set.
   */
  @java.lang.Override
  public boolean hasCaOptions() {
    return caOptions_ != null;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes options in this
   * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
   * are relevant in a CA certificate.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return The caOptions.
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.X509Parameters.CaOptions getCaOptions() {
    return caOptions_ == null
        ? com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.getDefaultInstance()
        : caOptions_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes options in this
   * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
   * are relevant in a CA certificate.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.X509Parameters.CaOptionsOrBuilder
      getCaOptionsOrBuilder() {
    return caOptions_ == null
        ? com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.getDefaultInstance()
        : caOptions_;
  }

  public static final int POLICY_IDS_FIELD_NUMBER = 3;

  @SuppressWarnings("serial")
  private java.util.List<com.google.cloud.security.privateca.v1.ObjectId> policyIds_;
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 certificate policy object identifiers, per
   * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public java.util.List<com.google.cloud.security.privateca.v1.ObjectId> getPolicyIdsList() {
    return policyIds_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 certificate policy object identifiers, per
   * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public java.util.List<? extends com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
      getPolicyIdsOrBuilderList() {
    return policyIds_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 certificate policy object identifiers, per
   * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public int getPolicyIdsCount() {
    return policyIds_.size();
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 certificate policy object identifiers, per
   * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.ObjectId getPolicyIds(int index) {
    return policyIds_.get(index);
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 certificate policy object identifiers, per
   * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.ObjectIdOrBuilder getPolicyIdsOrBuilder(int index) {
    return policyIds_.get(index);
  }

  public static final int AIA_OCSP_SERVERS_FIELD_NUMBER = 4;

  @SuppressWarnings("serial")
  private com.google.protobuf.LazyStringList aiaOcspServers_;
  /**
   *
   *
   * <pre>
   * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
   * addresses that appear in the "Authority Information Access" extension in
   * the certificate.
   * </pre>
   *
   * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
   *
   * @return A list containing the aiaOcspServers.
   */
  public com.google.protobuf.ProtocolStringList getAiaOcspServersList() {
    return aiaOcspServers_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
   * addresses that appear in the "Authority Information Access" extension in
   * the certificate.
   * </pre>
   *
   * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
   *
   * @return The count of aiaOcspServers.
   */
  public int getAiaOcspServersCount() {
    return aiaOcspServers_.size();
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
   * addresses that appear in the "Authority Information Access" extension in
   * the certificate.
   * </pre>
   *
   * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
   *
   * @param index The index of the element to return.
   * @return The aiaOcspServers at the given index.
   */
  public java.lang.String getAiaOcspServers(int index) {
    return aiaOcspServers_.get(index);
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
   * addresses that appear in the "Authority Information Access" extension in
   * the certificate.
   * </pre>
   *
   * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
   *
   * @param index The index of the value to return.
   * @return The bytes of the aiaOcspServers at the given index.
   */
  public com.google.protobuf.ByteString getAiaOcspServersBytes(int index) {
    return aiaOcspServers_.getByteString(index);
  }

  public static final int NAME_CONSTRAINTS_FIELD_NUMBER = 6;
  private com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints nameConstraints_;
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 name constraints extension.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return Whether the nameConstraints field is set.
   */
  @java.lang.Override
  public boolean hasNameConstraints() {
    return nameConstraints_ != null;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 name constraints extension.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   *
   * @return The nameConstraints.
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
      getNameConstraints() {
    return nameConstraints_ == null
        ? com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.getDefaultInstance()
        : nameConstraints_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes the X.509 name constraints extension.
   * </pre>
   *
   * <code>
   * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraintsOrBuilder
      getNameConstraintsOrBuilder() {
    return nameConstraints_ == null
        ? com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.getDefaultInstance()
        : nameConstraints_;
  }

  public static final int ADDITIONAL_EXTENSIONS_FIELD_NUMBER = 5;

  @SuppressWarnings("serial")
  private java.util.List<com.google.cloud.security.privateca.v1.X509Extension>
      additionalExtensions_;
  /**
   *
   *
   * <pre>
   * Optional. Describes custom X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public java.util.List<com.google.cloud.security.privateca.v1.X509Extension>
      getAdditionalExtensionsList() {
    return additionalExtensions_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes custom X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public java.util.List<? extends com.google.cloud.security.privateca.v1.X509ExtensionOrBuilder>
      getAdditionalExtensionsOrBuilderList() {
    return additionalExtensions_;
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes custom X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public int getAdditionalExtensionsCount() {
    return additionalExtensions_.size();
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes custom X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.X509Extension getAdditionalExtensions(int index) {
    return additionalExtensions_.get(index);
  }
  /**
   *
   *
   * <pre>
   * Optional. Describes custom X.509 extensions.
   * </pre>
   *
   * <code>
   * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
   * </code>
   */
  @java.lang.Override
  public com.google.cloud.security.privateca.v1.X509ExtensionOrBuilder
      getAdditionalExtensionsOrBuilder(int index) {
    return additionalExtensions_.get(index);
  }

  private byte memoizedIsInitialized = -1;

  @java.lang.Override
  public final boolean isInitialized() {
    byte isInitialized = memoizedIsInitialized;
    if (isInitialized == 1) return true;
    if (isInitialized == 0) return false;

    memoizedIsInitialized = 1;
    return true;
  }

  @java.lang.Override
  public void writeTo(com.google.protobuf.CodedOutputStream output) throws java.io.IOException {
    if (keyUsage_ != null) {
      output.writeMessage(1, getKeyUsage());
    }
    if (caOptions_ != null) {
      output.writeMessage(2, getCaOptions());
    }
    for (int i = 0; i < policyIds_.size(); i++) {
      output.writeMessage(3, policyIds_.get(i));
    }
    for (int i = 0; i < aiaOcspServers_.size(); i++) {
      com.google.protobuf.GeneratedMessageV3.writeString(output, 4, aiaOcspServers_.getRaw(i));
    }
    for (int i = 0; i < additionalExtensions_.size(); i++) {
      output.writeMessage(5, additionalExtensions_.get(i));
    }
    if (nameConstraints_ != null) {
      output.writeMessage(6, getNameConstraints());
    }
    getUnknownFields().writeTo(output);
  }

  @java.lang.Override
  public int getSerializedSize() {
    int size = memoizedSize;
    if (size != -1) return size;

    size = 0;
    if (keyUsage_ != null) {
      size += com.google.protobuf.CodedOutputStream.computeMessageSize(1, getKeyUsage());
    }
    if (caOptions_ != null) {
      size += com.google.protobuf.CodedOutputStream.computeMessageSize(2, getCaOptions());
    }
    for (int i = 0; i < policyIds_.size(); i++) {
      size += com.google.protobuf.CodedOutputStream.computeMessageSize(3, policyIds_.get(i));
    }
    {
      int dataSize = 0;
      for (int i = 0; i < aiaOcspServers_.size(); i++) {
        dataSize += computeStringSizeNoTag(aiaOcspServers_.getRaw(i));
      }
      size += dataSize;
      size += 1 * getAiaOcspServersList().size();
    }
    for (int i = 0; i < additionalExtensions_.size(); i++) {
      size +=
          com.google.protobuf.CodedOutputStream.computeMessageSize(5, additionalExtensions_.get(i));
    }
    if (nameConstraints_ != null) {
      size += com.google.protobuf.CodedOutputStream.computeMessageSize(6, getNameConstraints());
    }
    size += getUnknownFields().getSerializedSize();
    memoizedSize = size;
    return size;
  }

  @java.lang.Override
  public boolean equals(final java.lang.Object obj) {
    if (obj == this) {
      return true;
    }
    if (!(obj instanceof com.google.cloud.security.privateca.v1.X509Parameters)) {
      return super.equals(obj);
    }
    com.google.cloud.security.privateca.v1.X509Parameters other =
        (com.google.cloud.security.privateca.v1.X509Parameters) obj;

    if (hasKeyUsage() != other.hasKeyUsage()) return false;
    if (hasKeyUsage()) {
      if (!getKeyUsage().equals(other.getKeyUsage())) return false;
    }
    if (hasCaOptions() != other.hasCaOptions()) return false;
    if (hasCaOptions()) {
      if (!getCaOptions().equals(other.getCaOptions())) return false;
    }
    if (!getPolicyIdsList().equals(other.getPolicyIdsList())) return false;
    if (!getAiaOcspServersList().equals(other.getAiaOcspServersList())) return false;
    if (hasNameConstraints() != other.hasNameConstraints()) return false;
    if (hasNameConstraints()) {
      if (!getNameConstraints().equals(other.getNameConstraints())) return false;
    }
    if (!getAdditionalExtensionsList().equals(other.getAdditionalExtensionsList())) return false;
    if (!getUnknownFields().equals(other.getUnknownFields())) return false;
    return true;
  }

  @java.lang.Override
  public int hashCode() {
    if (memoizedHashCode != 0) {
      return memoizedHashCode;
    }
    int hash = 41;
    hash = (19 * hash) + getDescriptor().hashCode();
    if (hasKeyUsage()) {
      hash = (37 * hash) + KEY_USAGE_FIELD_NUMBER;
      hash = (53 * hash) + getKeyUsage().hashCode();
    }
    if (hasCaOptions()) {
      hash = (37 * hash) + CA_OPTIONS_FIELD_NUMBER;
      hash = (53 * hash) + getCaOptions().hashCode();
    }
    if (getPolicyIdsCount() > 0) {
      hash = (37 * hash) + POLICY_IDS_FIELD_NUMBER;
      hash = (53 * hash) + getPolicyIdsList().hashCode();
    }
    if (getAiaOcspServersCount() > 0) {
      hash = (37 * hash) + AIA_OCSP_SERVERS_FIELD_NUMBER;
      hash = (53 * hash) + getAiaOcspServersList().hashCode();
    }
    if (hasNameConstraints()) {
      hash = (37 * hash) + NAME_CONSTRAINTS_FIELD_NUMBER;
      hash = (53 * hash) + getNameConstraints().hashCode();
    }
    if (getAdditionalExtensionsCount() > 0) {
      hash = (37 * hash) + ADDITIONAL_EXTENSIONS_FIELD_NUMBER;
      hash = (53 * hash) + getAdditionalExtensionsList().hashCode();
    }
    hash = (29 * hash) + getUnknownFields().hashCode();
    memoizedHashCode = hash;
    return hash;
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      java.nio.ByteBuffer data) throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      java.nio.ByteBuffer data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      com.google.protobuf.ByteString data)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      com.google.protobuf.ByteString data,
      com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(byte[] data)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      byte[] data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws com.google.protobuf.InvalidProtocolBufferException {
    return PARSER.parseFrom(data, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      java.io.InputStream input) throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
        PARSER, input, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseDelimitedFrom(
      java.io.InputStream input) throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(PARSER, input);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseDelimitedFrom(
      java.io.InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseDelimitedWithIOException(
        PARSER, input, extensionRegistry);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      com.google.protobuf.CodedInputStream input) throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(PARSER, input);
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters parseFrom(
      com.google.protobuf.CodedInputStream input,
      com.google.protobuf.ExtensionRegistryLite extensionRegistry)
      throws java.io.IOException {
    return com.google.protobuf.GeneratedMessageV3.parseWithIOException(
        PARSER, input, extensionRegistry);
  }

  @java.lang.Override
  public Builder newBuilderForType() {
    return newBuilder();
  }

  public static Builder newBuilder() {
    return DEFAULT_INSTANCE.toBuilder();
  }

  public static Builder newBuilder(
      com.google.cloud.security.privateca.v1.X509Parameters prototype) {
    return DEFAULT_INSTANCE.toBuilder().mergeFrom(prototype);
  }

  @java.lang.Override
  public Builder toBuilder() {
    return this == DEFAULT_INSTANCE ? new Builder() : new Builder().mergeFrom(this);
  }

  @java.lang.Override
  protected Builder newBuilderForType(com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
    Builder builder = new Builder(parent);
    return builder;
  }
  /**
   *
   *
   * <pre>
   * An [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] is
   * used to describe certain fields of an X.509 certificate, such as the key
   * usage fields, fields specific to CA certificates, certificate policy
   * extensions and custom extensions.
   * </pre>
   *
   * Protobuf type {@code google.cloud.security.privateca.v1.X509Parameters}
   */
  public static final class Builder extends com.google.protobuf.GeneratedMessageV3.Builder<Builder>
      implements
      // @@protoc_insertion_point(builder_implements:google.cloud.security.privateca.v1.X509Parameters)
      com.google.cloud.security.privateca.v1.X509ParametersOrBuilder {
    public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_X509Parameters_descriptor;
    }

    @java.lang.Override
    protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
        internalGetFieldAccessorTable() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_X509Parameters_fieldAccessorTable
          .ensureFieldAccessorsInitialized(
              com.google.cloud.security.privateca.v1.X509Parameters.class,
              com.google.cloud.security.privateca.v1.X509Parameters.Builder.class);
    }

    // Construct using com.google.cloud.security.privateca.v1.X509Parameters.newBuilder()
    private Builder() {}

    private Builder(com.google.protobuf.GeneratedMessageV3.BuilderParent parent) {
      super(parent);
    }

    @java.lang.Override
    public Builder clear() {
      super.clear();
      bitField0_ = 0;
      keyUsage_ = null;
      if (keyUsageBuilder_ != null) {
        keyUsageBuilder_.dispose();
        keyUsageBuilder_ = null;
      }
      caOptions_ = null;
      if (caOptionsBuilder_ != null) {
        caOptionsBuilder_.dispose();
        caOptionsBuilder_ = null;
      }
      if (policyIdsBuilder_ == null) {
        policyIds_ = java.util.Collections.emptyList();
      } else {
        policyIds_ = null;
        policyIdsBuilder_.clear();
      }
      bitField0_ = (bitField0_ & ~0x00000004);
      aiaOcspServers_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      bitField0_ = (bitField0_ & ~0x00000008);
      nameConstraints_ = null;
      if (nameConstraintsBuilder_ != null) {
        nameConstraintsBuilder_.dispose();
        nameConstraintsBuilder_ = null;
      }
      if (additionalExtensionsBuilder_ == null) {
        additionalExtensions_ = java.util.Collections.emptyList();
      } else {
        additionalExtensions_ = null;
        additionalExtensionsBuilder_.clear();
      }
      bitField0_ = (bitField0_ & ~0x00000020);
      return this;
    }

    @java.lang.Override
    public com.google.protobuf.Descriptors.Descriptor getDescriptorForType() {
      return com.google.cloud.security.privateca.v1.PrivateCaResourcesProto
          .internal_static_google_cloud_security_privateca_v1_X509Parameters_descriptor;
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.X509Parameters getDefaultInstanceForType() {
      return com.google.cloud.security.privateca.v1.X509Parameters.getDefaultInstance();
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.X509Parameters build() {
      com.google.cloud.security.privateca.v1.X509Parameters result = buildPartial();
      if (!result.isInitialized()) {
        throw newUninitializedMessageException(result);
      }
      return result;
    }

    @java.lang.Override
    public com.google.cloud.security.privateca.v1.X509Parameters buildPartial() {
      com.google.cloud.security.privateca.v1.X509Parameters result =
          new com.google.cloud.security.privateca.v1.X509Parameters(this);
      buildPartialRepeatedFields(result);
      if (bitField0_ != 0) {
        buildPartial0(result);
      }
      onBuilt();
      return result;
    }

    private void buildPartialRepeatedFields(
        com.google.cloud.security.privateca.v1.X509Parameters result) {
      if (policyIdsBuilder_ == null) {
        if (((bitField0_ & 0x00000004) != 0)) {
          policyIds_ = java.util.Collections.unmodifiableList(policyIds_);
          bitField0_ = (bitField0_ & ~0x00000004);
        }
        result.policyIds_ = policyIds_;
      } else {
        result.policyIds_ = policyIdsBuilder_.build();
      }
      if (((bitField0_ & 0x00000008) != 0)) {
        aiaOcspServers_ = aiaOcspServers_.getUnmodifiableView();
        bitField0_ = (bitField0_ & ~0x00000008);
      }
      result.aiaOcspServers_ = aiaOcspServers_;
      if (additionalExtensionsBuilder_ == null) {
        if (((bitField0_ & 0x00000020) != 0)) {
          additionalExtensions_ = java.util.Collections.unmodifiableList(additionalExtensions_);
          bitField0_ = (bitField0_ & ~0x00000020);
        }
        result.additionalExtensions_ = additionalExtensions_;
      } else {
        result.additionalExtensions_ = additionalExtensionsBuilder_.build();
      }
    }

    private void buildPartial0(com.google.cloud.security.privateca.v1.X509Parameters result) {
      int from_bitField0_ = bitField0_;
      if (((from_bitField0_ & 0x00000001) != 0)) {
        result.keyUsage_ = keyUsageBuilder_ == null ? keyUsage_ : keyUsageBuilder_.build();
      }
      if (((from_bitField0_ & 0x00000002) != 0)) {
        result.caOptions_ = caOptionsBuilder_ == null ? caOptions_ : caOptionsBuilder_.build();
      }
      if (((from_bitField0_ & 0x00000010) != 0)) {
        result.nameConstraints_ =
            nameConstraintsBuilder_ == null ? nameConstraints_ : nameConstraintsBuilder_.build();
      }
    }

    @java.lang.Override
    public Builder clone() {
      return super.clone();
    }

    @java.lang.Override
    public Builder setField(
        com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
      return super.setField(field, value);
    }

    @java.lang.Override
    public Builder clearField(com.google.protobuf.Descriptors.FieldDescriptor field) {
      return super.clearField(field);
    }

    @java.lang.Override
    public Builder clearOneof(com.google.protobuf.Descriptors.OneofDescriptor oneof) {
      return super.clearOneof(oneof);
    }

    @java.lang.Override
    public Builder setRepeatedField(
        com.google.protobuf.Descriptors.FieldDescriptor field, int index, java.lang.Object value) {
      return super.setRepeatedField(field, index, value);
    }

    @java.lang.Override
    public Builder addRepeatedField(
        com.google.protobuf.Descriptors.FieldDescriptor field, java.lang.Object value) {
      return super.addRepeatedField(field, value);
    }

    @java.lang.Override
    public Builder mergeFrom(com.google.protobuf.Message other) {
      if (other instanceof com.google.cloud.security.privateca.v1.X509Parameters) {
        return mergeFrom((com.google.cloud.security.privateca.v1.X509Parameters) other);
      } else {
        super.mergeFrom(other);
        return this;
      }
    }

    public Builder mergeFrom(com.google.cloud.security.privateca.v1.X509Parameters other) {
      if (other == com.google.cloud.security.privateca.v1.X509Parameters.getDefaultInstance())
        return this;
      if (other.hasKeyUsage()) {
        mergeKeyUsage(other.getKeyUsage());
      }
      if (other.hasCaOptions()) {
        mergeCaOptions(other.getCaOptions());
      }
      if (policyIdsBuilder_ == null) {
        if (!other.policyIds_.isEmpty()) {
          if (policyIds_.isEmpty()) {
            policyIds_ = other.policyIds_;
            bitField0_ = (bitField0_ & ~0x00000004);
          } else {
            ensurePolicyIdsIsMutable();
            policyIds_.addAll(other.policyIds_);
          }
          onChanged();
        }
      } else {
        if (!other.policyIds_.isEmpty()) {
          if (policyIdsBuilder_.isEmpty()) {
            policyIdsBuilder_.dispose();
            policyIdsBuilder_ = null;
            policyIds_ = other.policyIds_;
            bitField0_ = (bitField0_ & ~0x00000004);
            policyIdsBuilder_ =
                com.google.protobuf.GeneratedMessageV3.alwaysUseFieldBuilders
                    ? getPolicyIdsFieldBuilder()
                    : null;
          } else {
            policyIdsBuilder_.addAllMessages(other.policyIds_);
          }
        }
      }
      if (!other.aiaOcspServers_.isEmpty()) {
        if (aiaOcspServers_.isEmpty()) {
          aiaOcspServers_ = other.aiaOcspServers_;
          bitField0_ = (bitField0_ & ~0x00000008);
        } else {
          ensureAiaOcspServersIsMutable();
          aiaOcspServers_.addAll(other.aiaOcspServers_);
        }
        onChanged();
      }
      if (other.hasNameConstraints()) {
        mergeNameConstraints(other.getNameConstraints());
      }
      if (additionalExtensionsBuilder_ == null) {
        if (!other.additionalExtensions_.isEmpty()) {
          if (additionalExtensions_.isEmpty()) {
            additionalExtensions_ = other.additionalExtensions_;
            bitField0_ = (bitField0_ & ~0x00000020);
          } else {
            ensureAdditionalExtensionsIsMutable();
            additionalExtensions_.addAll(other.additionalExtensions_);
          }
          onChanged();
        }
      } else {
        if (!other.additionalExtensions_.isEmpty()) {
          if (additionalExtensionsBuilder_.isEmpty()) {
            additionalExtensionsBuilder_.dispose();
            additionalExtensionsBuilder_ = null;
            additionalExtensions_ = other.additionalExtensions_;
            bitField0_ = (bitField0_ & ~0x00000020);
            additionalExtensionsBuilder_ =
                com.google.protobuf.GeneratedMessageV3.alwaysUseFieldBuilders
                    ? getAdditionalExtensionsFieldBuilder()
                    : null;
          } else {
            additionalExtensionsBuilder_.addAllMessages(other.additionalExtensions_);
          }
        }
      }
      this.mergeUnknownFields(other.getUnknownFields());
      onChanged();
      return this;
    }

    @java.lang.Override
    public final boolean isInitialized() {
      return true;
    }

    @java.lang.Override
    public Builder mergeFrom(
        com.google.protobuf.CodedInputStream input,
        com.google.protobuf.ExtensionRegistryLite extensionRegistry)
        throws java.io.IOException {
      if (extensionRegistry == null) {
        throw new java.lang.NullPointerException();
      }
      try {
        boolean done = false;
        while (!done) {
          int tag = input.readTag();
          switch (tag) {
            case 0:
              done = true;
              break;
            case 10:
              {
                input.readMessage(getKeyUsageFieldBuilder().getBuilder(), extensionRegistry);
                bitField0_ |= 0x00000001;
                break;
              } // case 10
            case 18:
              {
                input.readMessage(getCaOptionsFieldBuilder().getBuilder(), extensionRegistry);
                bitField0_ |= 0x00000002;
                break;
              } // case 18
            case 26:
              {
                com.google.cloud.security.privateca.v1.ObjectId m =
                    input.readMessage(
                        com.google.cloud.security.privateca.v1.ObjectId.parser(),
                        extensionRegistry);
                if (policyIdsBuilder_ == null) {
                  ensurePolicyIdsIsMutable();
                  policyIds_.add(m);
                } else {
                  policyIdsBuilder_.addMessage(m);
                }
                break;
              } // case 26
            case 34:
              {
                java.lang.String s = input.readStringRequireUtf8();
                ensureAiaOcspServersIsMutable();
                aiaOcspServers_.add(s);
                break;
              } // case 34
            case 42:
              {
                com.google.cloud.security.privateca.v1.X509Extension m =
                    input.readMessage(
                        com.google.cloud.security.privateca.v1.X509Extension.parser(),
                        extensionRegistry);
                if (additionalExtensionsBuilder_ == null) {
                  ensureAdditionalExtensionsIsMutable();
                  additionalExtensions_.add(m);
                } else {
                  additionalExtensionsBuilder_.addMessage(m);
                }
                break;
              } // case 42
            case 50:
              {
                input.readMessage(getNameConstraintsFieldBuilder().getBuilder(), extensionRegistry);
                bitField0_ |= 0x00000010;
                break;
              } // case 50
            default:
              {
                if (!super.parseUnknownField(input, extensionRegistry, tag)) {
                  done = true; // was an endgroup tag
                }
                break;
              } // default:
          } // switch (tag)
        } // while (!done)
      } catch (com.google.protobuf.InvalidProtocolBufferException e) {
        throw e.unwrapIOException();
      } finally {
        onChanged();
      } // finally
      return this;
    }

    private int bitField0_;

    private com.google.cloud.security.privateca.v1.KeyUsage keyUsage_;
    private com.google.protobuf.SingleFieldBuilderV3<
            com.google.cloud.security.privateca.v1.KeyUsage,
            com.google.cloud.security.privateca.v1.KeyUsage.Builder,
            com.google.cloud.security.privateca.v1.KeyUsageOrBuilder>
        keyUsageBuilder_;
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return Whether the keyUsage field is set.
     */
    public boolean hasKeyUsage() {
      return ((bitField0_ & 0x00000001) != 0);
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return The keyUsage.
     */
    public com.google.cloud.security.privateca.v1.KeyUsage getKeyUsage() {
      if (keyUsageBuilder_ == null) {
        return keyUsage_ == null
            ? com.google.cloud.security.privateca.v1.KeyUsage.getDefaultInstance()
            : keyUsage_;
      } else {
        return keyUsageBuilder_.getMessage();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setKeyUsage(com.google.cloud.security.privateca.v1.KeyUsage value) {
      if (keyUsageBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        keyUsage_ = value;
      } else {
        keyUsageBuilder_.setMessage(value);
      }
      bitField0_ |= 0x00000001;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setKeyUsage(
        com.google.cloud.security.privateca.v1.KeyUsage.Builder builderForValue) {
      if (keyUsageBuilder_ == null) {
        keyUsage_ = builderForValue.build();
      } else {
        keyUsageBuilder_.setMessage(builderForValue.build());
      }
      bitField0_ |= 0x00000001;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder mergeKeyUsage(com.google.cloud.security.privateca.v1.KeyUsage value) {
      if (keyUsageBuilder_ == null) {
        if (((bitField0_ & 0x00000001) != 0)
            && keyUsage_ != null
            && keyUsage_ != com.google.cloud.security.privateca.v1.KeyUsage.getDefaultInstance()) {
          getKeyUsageBuilder().mergeFrom(value);
        } else {
          keyUsage_ = value;
        }
      } else {
        keyUsageBuilder_.mergeFrom(value);
      }
      bitField0_ |= 0x00000001;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder clearKeyUsage() {
      bitField0_ = (bitField0_ & ~0x00000001);
      keyUsage_ = null;
      if (keyUsageBuilder_ != null) {
        keyUsageBuilder_.dispose();
        keyUsageBuilder_ = null;
      }
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.KeyUsage.Builder getKeyUsageBuilder() {
      bitField0_ |= 0x00000001;
      onChanged();
      return getKeyUsageFieldBuilder().getBuilder();
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.KeyUsageOrBuilder getKeyUsageOrBuilder() {
      if (keyUsageBuilder_ != null) {
        return keyUsageBuilder_.getMessageOrBuilder();
      } else {
        return keyUsage_ == null
            ? com.google.cloud.security.privateca.v1.KeyUsage.getDefaultInstance()
            : keyUsage_;
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Indicates the intended use for keys that correspond to a
     * certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.KeyUsage key_usage = 1 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    private com.google.protobuf.SingleFieldBuilderV3<
            com.google.cloud.security.privateca.v1.KeyUsage,
            com.google.cloud.security.privateca.v1.KeyUsage.Builder,
            com.google.cloud.security.privateca.v1.KeyUsageOrBuilder>
        getKeyUsageFieldBuilder() {
      if (keyUsageBuilder_ == null) {
        keyUsageBuilder_ =
            new com.google.protobuf.SingleFieldBuilderV3<
                com.google.cloud.security.privateca.v1.KeyUsage,
                com.google.cloud.security.privateca.v1.KeyUsage.Builder,
                com.google.cloud.security.privateca.v1.KeyUsageOrBuilder>(
                getKeyUsage(), getParentForChildren(), isClean());
        keyUsage_ = null;
      }
      return keyUsageBuilder_;
    }

    private com.google.cloud.security.privateca.v1.X509Parameters.CaOptions caOptions_;
    private com.google.protobuf.SingleFieldBuilderV3<
            com.google.cloud.security.privateca.v1.X509Parameters.CaOptions,
            com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.Builder,
            com.google.cloud.security.privateca.v1.X509Parameters.CaOptionsOrBuilder>
        caOptionsBuilder_;
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return Whether the caOptions field is set.
     */
    public boolean hasCaOptions() {
      return ((bitField0_ & 0x00000002) != 0);
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return The caOptions.
     */
    public com.google.cloud.security.privateca.v1.X509Parameters.CaOptions getCaOptions() {
      if (caOptionsBuilder_ == null) {
        return caOptions_ == null
            ? com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.getDefaultInstance()
            : caOptions_;
      } else {
        return caOptionsBuilder_.getMessage();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setCaOptions(
        com.google.cloud.security.privateca.v1.X509Parameters.CaOptions value) {
      if (caOptionsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        caOptions_ = value;
      } else {
        caOptionsBuilder_.setMessage(value);
      }
      bitField0_ |= 0x00000002;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setCaOptions(
        com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.Builder builderForValue) {
      if (caOptionsBuilder_ == null) {
        caOptions_ = builderForValue.build();
      } else {
        caOptionsBuilder_.setMessage(builderForValue.build());
      }
      bitField0_ |= 0x00000002;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder mergeCaOptions(
        com.google.cloud.security.privateca.v1.X509Parameters.CaOptions value) {
      if (caOptionsBuilder_ == null) {
        if (((bitField0_ & 0x00000002) != 0)
            && caOptions_ != null
            && caOptions_
                != com.google.cloud.security.privateca.v1.X509Parameters.CaOptions
                    .getDefaultInstance()) {
          getCaOptionsBuilder().mergeFrom(value);
        } else {
          caOptions_ = value;
        }
      } else {
        caOptionsBuilder_.mergeFrom(value);
      }
      bitField0_ |= 0x00000002;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder clearCaOptions() {
      bitField0_ = (bitField0_ & ~0x00000002);
      caOptions_ = null;
      if (caOptionsBuilder_ != null) {
        caOptionsBuilder_.dispose();
        caOptionsBuilder_ = null;
      }
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.Builder
        getCaOptionsBuilder() {
      bitField0_ |= 0x00000002;
      onChanged();
      return getCaOptionsFieldBuilder().getBuilder();
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Parameters.CaOptionsOrBuilder
        getCaOptionsOrBuilder() {
      if (caOptionsBuilder_ != null) {
        return caOptionsBuilder_.getMessageOrBuilder();
      } else {
        return caOptions_ == null
            ? com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.getDefaultInstance()
            : caOptions_;
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes options in this
     * [X509Parameters][google.cloud.security.privateca.v1.X509Parameters] that
     * are relevant in a CA certificate.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.CaOptions ca_options = 2 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    private com.google.protobuf.SingleFieldBuilderV3<
            com.google.cloud.security.privateca.v1.X509Parameters.CaOptions,
            com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.Builder,
            com.google.cloud.security.privateca.v1.X509Parameters.CaOptionsOrBuilder>
        getCaOptionsFieldBuilder() {
      if (caOptionsBuilder_ == null) {
        caOptionsBuilder_ =
            new com.google.protobuf.SingleFieldBuilderV3<
                com.google.cloud.security.privateca.v1.X509Parameters.CaOptions,
                com.google.cloud.security.privateca.v1.X509Parameters.CaOptions.Builder,
                com.google.cloud.security.privateca.v1.X509Parameters.CaOptionsOrBuilder>(
                getCaOptions(), getParentForChildren(), isClean());
        caOptions_ = null;
      }
      return caOptionsBuilder_;
    }

    private java.util.List<com.google.cloud.security.privateca.v1.ObjectId> policyIds_ =
        java.util.Collections.emptyList();

    private void ensurePolicyIdsIsMutable() {
      if (!((bitField0_ & 0x00000004) != 0)) {
        policyIds_ =
            new java.util.ArrayList<com.google.cloud.security.privateca.v1.ObjectId>(policyIds_);
        bitField0_ |= 0x00000004;
      }
    }

    private com.google.protobuf.RepeatedFieldBuilderV3<
            com.google.cloud.security.privateca.v1.ObjectId,
            com.google.cloud.security.privateca.v1.ObjectId.Builder,
            com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
        policyIdsBuilder_;

    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<com.google.cloud.security.privateca.v1.ObjectId> getPolicyIdsList() {
      if (policyIdsBuilder_ == null) {
        return java.util.Collections.unmodifiableList(policyIds_);
      } else {
        return policyIdsBuilder_.getMessageList();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public int getPolicyIdsCount() {
      if (policyIdsBuilder_ == null) {
        return policyIds_.size();
      } else {
        return policyIdsBuilder_.getCount();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId getPolicyIds(int index) {
      if (policyIdsBuilder_ == null) {
        return policyIds_.get(index);
      } else {
        return policyIdsBuilder_.getMessage(index);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setPolicyIds(int index, com.google.cloud.security.privateca.v1.ObjectId value) {
      if (policyIdsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePolicyIdsIsMutable();
        policyIds_.set(index, value);
        onChanged();
      } else {
        policyIdsBuilder_.setMessage(index, value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setPolicyIds(
        int index, com.google.cloud.security.privateca.v1.ObjectId.Builder builderForValue) {
      if (policyIdsBuilder_ == null) {
        ensurePolicyIdsIsMutable();
        policyIds_.set(index, builderForValue.build());
        onChanged();
      } else {
        policyIdsBuilder_.setMessage(index, builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addPolicyIds(com.google.cloud.security.privateca.v1.ObjectId value) {
      if (policyIdsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePolicyIdsIsMutable();
        policyIds_.add(value);
        onChanged();
      } else {
        policyIdsBuilder_.addMessage(value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addPolicyIds(int index, com.google.cloud.security.privateca.v1.ObjectId value) {
      if (policyIdsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensurePolicyIdsIsMutable();
        policyIds_.add(index, value);
        onChanged();
      } else {
        policyIdsBuilder_.addMessage(index, value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addPolicyIds(
        com.google.cloud.security.privateca.v1.ObjectId.Builder builderForValue) {
      if (policyIdsBuilder_ == null) {
        ensurePolicyIdsIsMutable();
        policyIds_.add(builderForValue.build());
        onChanged();
      } else {
        policyIdsBuilder_.addMessage(builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addPolicyIds(
        int index, com.google.cloud.security.privateca.v1.ObjectId.Builder builderForValue) {
      if (policyIdsBuilder_ == null) {
        ensurePolicyIdsIsMutable();
        policyIds_.add(index, builderForValue.build());
        onChanged();
      } else {
        policyIdsBuilder_.addMessage(index, builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAllPolicyIds(
        java.lang.Iterable<? extends com.google.cloud.security.privateca.v1.ObjectId> values) {
      if (policyIdsBuilder_ == null) {
        ensurePolicyIdsIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, policyIds_);
        onChanged();
      } else {
        policyIdsBuilder_.addAllMessages(values);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder clearPolicyIds() {
      if (policyIdsBuilder_ == null) {
        policyIds_ = java.util.Collections.emptyList();
        bitField0_ = (bitField0_ & ~0x00000004);
        onChanged();
      } else {
        policyIdsBuilder_.clear();
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder removePolicyIds(int index) {
      if (policyIdsBuilder_ == null) {
        ensurePolicyIdsIsMutable();
        policyIds_.remove(index);
        onChanged();
      } else {
        policyIdsBuilder_.remove(index);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId.Builder getPolicyIdsBuilder(int index) {
      return getPolicyIdsFieldBuilder().getBuilder(index);
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectIdOrBuilder getPolicyIdsOrBuilder(
        int index) {
      if (policyIdsBuilder_ == null) {
        return policyIds_.get(index);
      } else {
        return policyIdsBuilder_.getMessageOrBuilder(index);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<? extends com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
        getPolicyIdsOrBuilderList() {
      if (policyIdsBuilder_ != null) {
        return policyIdsBuilder_.getMessageOrBuilderList();
      } else {
        return java.util.Collections.unmodifiableList(policyIds_);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId.Builder addPolicyIdsBuilder() {
      return getPolicyIdsFieldBuilder()
          .addBuilder(com.google.cloud.security.privateca.v1.ObjectId.getDefaultInstance());
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.ObjectId.Builder addPolicyIdsBuilder(int index) {
      return getPolicyIdsFieldBuilder()
          .addBuilder(index, com.google.cloud.security.privateca.v1.ObjectId.getDefaultInstance());
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 certificate policy object identifiers, per
     * https://tools.ietf.org/html/rfc5280#section-4.2.1.4.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.ObjectId policy_ids = 3 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<com.google.cloud.security.privateca.v1.ObjectId.Builder>
        getPolicyIdsBuilderList() {
      return getPolicyIdsFieldBuilder().getBuilderList();
    }

    private com.google.protobuf.RepeatedFieldBuilderV3<
            com.google.cloud.security.privateca.v1.ObjectId,
            com.google.cloud.security.privateca.v1.ObjectId.Builder,
            com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>
        getPolicyIdsFieldBuilder() {
      if (policyIdsBuilder_ == null) {
        policyIdsBuilder_ =
            new com.google.protobuf.RepeatedFieldBuilderV3<
                com.google.cloud.security.privateca.v1.ObjectId,
                com.google.cloud.security.privateca.v1.ObjectId.Builder,
                com.google.cloud.security.privateca.v1.ObjectIdOrBuilder>(
                policyIds_, ((bitField0_ & 0x00000004) != 0), getParentForChildren(), isClean());
        policyIds_ = null;
      }
      return policyIdsBuilder_;
    }

    private com.google.protobuf.LazyStringList aiaOcspServers_ =
        com.google.protobuf.LazyStringArrayList.EMPTY;

    private void ensureAiaOcspServersIsMutable() {
      if (!((bitField0_ & 0x00000008) != 0)) {
        aiaOcspServers_ = new com.google.protobuf.LazyStringArrayList(aiaOcspServers_);
        bitField0_ |= 0x00000008;
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @return A list containing the aiaOcspServers.
     */
    public com.google.protobuf.ProtocolStringList getAiaOcspServersList() {
      return aiaOcspServers_.getUnmodifiableView();
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @return The count of aiaOcspServers.
     */
    public int getAiaOcspServersCount() {
      return aiaOcspServers_.size();
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @param index The index of the element to return.
     * @return The aiaOcspServers at the given index.
     */
    public java.lang.String getAiaOcspServers(int index) {
      return aiaOcspServers_.get(index);
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @param index The index of the value to return.
     * @return The bytes of the aiaOcspServers at the given index.
     */
    public com.google.protobuf.ByteString getAiaOcspServersBytes(int index) {
      return aiaOcspServers_.getByteString(index);
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @param index The index to set the value at.
     * @param value The aiaOcspServers to set.
     * @return This builder for chaining.
     */
    public Builder setAiaOcspServers(int index, java.lang.String value) {
      if (value == null) {
        throw new NullPointerException();
      }
      ensureAiaOcspServersIsMutable();
      aiaOcspServers_.set(index, value);
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @param value The aiaOcspServers to add.
     * @return This builder for chaining.
     */
    public Builder addAiaOcspServers(java.lang.String value) {
      if (value == null) {
        throw new NullPointerException();
      }
      ensureAiaOcspServersIsMutable();
      aiaOcspServers_.add(value);
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @param values The aiaOcspServers to add.
     * @return This builder for chaining.
     */
    public Builder addAllAiaOcspServers(java.lang.Iterable<java.lang.String> values) {
      ensureAiaOcspServersIsMutable();
      com.google.protobuf.AbstractMessageLite.Builder.addAll(values, aiaOcspServers_);
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @return This builder for chaining.
     */
    public Builder clearAiaOcspServers() {
      aiaOcspServers_ = com.google.protobuf.LazyStringArrayList.EMPTY;
      bitField0_ = (bitField0_ & ~0x00000008);
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes Online Certificate Status Protocol (OCSP) endpoint
     * addresses that appear in the "Authority Information Access" extension in
     * the certificate.
     * </pre>
     *
     * <code>repeated string aia_ocsp_servers = 4 [(.google.api.field_behavior) = OPTIONAL];</code>
     *
     * @param value The bytes of the aiaOcspServers to add.
     * @return This builder for chaining.
     */
    public Builder addAiaOcspServersBytes(com.google.protobuf.ByteString value) {
      if (value == null) {
        throw new NullPointerException();
      }
      checkByteStringIsUtf8(value);
      ensureAiaOcspServersIsMutable();
      aiaOcspServers_.add(value);
      onChanged();
      return this;
    }

    private com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints nameConstraints_;
    private com.google.protobuf.SingleFieldBuilderV3<
            com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints,
            com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.Builder,
            com.google.cloud.security.privateca.v1.X509Parameters.NameConstraintsOrBuilder>
        nameConstraintsBuilder_;
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return Whether the nameConstraints field is set.
     */
    public boolean hasNameConstraints() {
      return ((bitField0_ & 0x00000010) != 0);
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     *
     * @return The nameConstraints.
     */
    public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
        getNameConstraints() {
      if (nameConstraintsBuilder_ == null) {
        return nameConstraints_ == null
            ? com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
                .getDefaultInstance()
            : nameConstraints_;
      } else {
        return nameConstraintsBuilder_.getMessage();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setNameConstraints(
        com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints value) {
      if (nameConstraintsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        nameConstraints_ = value;
      } else {
        nameConstraintsBuilder_.setMessage(value);
      }
      bitField0_ |= 0x00000010;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setNameConstraints(
        com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.Builder
            builderForValue) {
      if (nameConstraintsBuilder_ == null) {
        nameConstraints_ = builderForValue.build();
      } else {
        nameConstraintsBuilder_.setMessage(builderForValue.build());
      }
      bitField0_ |= 0x00000010;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder mergeNameConstraints(
        com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints value) {
      if (nameConstraintsBuilder_ == null) {
        if (((bitField0_ & 0x00000010) != 0)
            && nameConstraints_ != null
            && nameConstraints_
                != com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
                    .getDefaultInstance()) {
          getNameConstraintsBuilder().mergeFrom(value);
        } else {
          nameConstraints_ = value;
        }
      } else {
        nameConstraintsBuilder_.mergeFrom(value);
      }
      bitField0_ |= 0x00000010;
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder clearNameConstraints() {
      bitField0_ = (bitField0_ & ~0x00000010);
      nameConstraints_ = null;
      if (nameConstraintsBuilder_ != null) {
        nameConstraintsBuilder_.dispose();
        nameConstraintsBuilder_ = null;
      }
      onChanged();
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.Builder
        getNameConstraintsBuilder() {
      bitField0_ |= 0x00000010;
      onChanged();
      return getNameConstraintsFieldBuilder().getBuilder();
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Parameters.NameConstraintsOrBuilder
        getNameConstraintsOrBuilder() {
      if (nameConstraintsBuilder_ != null) {
        return nameConstraintsBuilder_.getMessageOrBuilder();
      } else {
        return nameConstraints_ == null
            ? com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints
                .getDefaultInstance()
            : nameConstraints_;
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes the X.509 name constraints extension.
     * </pre>
     *
     * <code>
     * .google.cloud.security.privateca.v1.X509Parameters.NameConstraints name_constraints = 6 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    private com.google.protobuf.SingleFieldBuilderV3<
            com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints,
            com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.Builder,
            com.google.cloud.security.privateca.v1.X509Parameters.NameConstraintsOrBuilder>
        getNameConstraintsFieldBuilder() {
      if (nameConstraintsBuilder_ == null) {
        nameConstraintsBuilder_ =
            new com.google.protobuf.SingleFieldBuilderV3<
                com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints,
                com.google.cloud.security.privateca.v1.X509Parameters.NameConstraints.Builder,
                com.google.cloud.security.privateca.v1.X509Parameters.NameConstraintsOrBuilder>(
                getNameConstraints(), getParentForChildren(), isClean());
        nameConstraints_ = null;
      }
      return nameConstraintsBuilder_;
    }

    private java.util.List<com.google.cloud.security.privateca.v1.X509Extension>
        additionalExtensions_ = java.util.Collections.emptyList();

    private void ensureAdditionalExtensionsIsMutable() {
      if (!((bitField0_ & 0x00000020) != 0)) {
        additionalExtensions_ =
            new java.util.ArrayList<com.google.cloud.security.privateca.v1.X509Extension>(
                additionalExtensions_);
        bitField0_ |= 0x00000020;
      }
    }

    private com.google.protobuf.RepeatedFieldBuilderV3<
            com.google.cloud.security.privateca.v1.X509Extension,
            com.google.cloud.security.privateca.v1.X509Extension.Builder,
            com.google.cloud.security.privateca.v1.X509ExtensionOrBuilder>
        additionalExtensionsBuilder_;

    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<com.google.cloud.security.privateca.v1.X509Extension>
        getAdditionalExtensionsList() {
      if (additionalExtensionsBuilder_ == null) {
        return java.util.Collections.unmodifiableList(additionalExtensions_);
      } else {
        return additionalExtensionsBuilder_.getMessageList();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public int getAdditionalExtensionsCount() {
      if (additionalExtensionsBuilder_ == null) {
        return additionalExtensions_.size();
      } else {
        return additionalExtensionsBuilder_.getCount();
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Extension getAdditionalExtensions(int index) {
      if (additionalExtensionsBuilder_ == null) {
        return additionalExtensions_.get(index);
      } else {
        return additionalExtensionsBuilder_.getMessage(index);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.X509Extension value) {
      if (additionalExtensionsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.set(index, value);
        onChanged();
      } else {
        additionalExtensionsBuilder_.setMessage(index, value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder setAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.X509Extension.Builder builderForValue) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.set(index, builderForValue.build());
        onChanged();
      } else {
        additionalExtensionsBuilder_.setMessage(index, builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(
        com.google.cloud.security.privateca.v1.X509Extension value) {
      if (additionalExtensionsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(value);
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.X509Extension value) {
      if (additionalExtensionsBuilder_ == null) {
        if (value == null) {
          throw new NullPointerException();
        }
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(index, value);
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(index, value);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(
        com.google.cloud.security.privateca.v1.X509Extension.Builder builderForValue) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(builderForValue.build());
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAdditionalExtensions(
        int index, com.google.cloud.security.privateca.v1.X509Extension.Builder builderForValue) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.add(index, builderForValue.build());
        onChanged();
      } else {
        additionalExtensionsBuilder_.addMessage(index, builderForValue.build());
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder addAllAdditionalExtensions(
        java.lang.Iterable<? extends com.google.cloud.security.privateca.v1.X509Extension> values) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        com.google.protobuf.AbstractMessageLite.Builder.addAll(values, additionalExtensions_);
        onChanged();
      } else {
        additionalExtensionsBuilder_.addAllMessages(values);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder clearAdditionalExtensions() {
      if (additionalExtensionsBuilder_ == null) {
        additionalExtensions_ = java.util.Collections.emptyList();
        bitField0_ = (bitField0_ & ~0x00000020);
        onChanged();
      } else {
        additionalExtensionsBuilder_.clear();
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public Builder removeAdditionalExtensions(int index) {
      if (additionalExtensionsBuilder_ == null) {
        ensureAdditionalExtensionsIsMutable();
        additionalExtensions_.remove(index);
        onChanged();
      } else {
        additionalExtensionsBuilder_.remove(index);
      }
      return this;
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Extension.Builder
        getAdditionalExtensionsBuilder(int index) {
      return getAdditionalExtensionsFieldBuilder().getBuilder(index);
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509ExtensionOrBuilder
        getAdditionalExtensionsOrBuilder(int index) {
      if (additionalExtensionsBuilder_ == null) {
        return additionalExtensions_.get(index);
      } else {
        return additionalExtensionsBuilder_.getMessageOrBuilder(index);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<? extends com.google.cloud.security.privateca.v1.X509ExtensionOrBuilder>
        getAdditionalExtensionsOrBuilderList() {
      if (additionalExtensionsBuilder_ != null) {
        return additionalExtensionsBuilder_.getMessageOrBuilderList();
      } else {
        return java.util.Collections.unmodifiableList(additionalExtensions_);
      }
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Extension.Builder
        addAdditionalExtensionsBuilder() {
      return getAdditionalExtensionsFieldBuilder()
          .addBuilder(com.google.cloud.security.privateca.v1.X509Extension.getDefaultInstance());
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public com.google.cloud.security.privateca.v1.X509Extension.Builder
        addAdditionalExtensionsBuilder(int index) {
      return getAdditionalExtensionsFieldBuilder()
          .addBuilder(
              index, com.google.cloud.security.privateca.v1.X509Extension.getDefaultInstance());
    }
    /**
     *
     *
     * <pre>
     * Optional. Describes custom X.509 extensions.
     * </pre>
     *
     * <code>
     * repeated .google.cloud.security.privateca.v1.X509Extension additional_extensions = 5 [(.google.api.field_behavior) = OPTIONAL];
     * </code>
     */
    public java.util.List<com.google.cloud.security.privateca.v1.X509Extension.Builder>
        getAdditionalExtensionsBuilderList() {
      return getAdditionalExtensionsFieldBuilder().getBuilderList();
    }

    private com.google.protobuf.RepeatedFieldBuilderV3<
            com.google.cloud.security.privateca.v1.X509Extension,
            com.google.cloud.security.privateca.v1.X509Extension.Builder,
            com.google.cloud.security.privateca.v1.X509ExtensionOrBuilder>
        getAdditionalExtensionsFieldBuilder() {
      if (additionalExtensionsBuilder_ == null) {
        additionalExtensionsBuilder_ =
            new com.google.protobuf.RepeatedFieldBuilderV3<
                com.google.cloud.security.privateca.v1.X509Extension,
                com.google.cloud.security.privateca.v1.X509Extension.Builder,
                com.google.cloud.security.privateca.v1.X509ExtensionOrBuilder>(
                additionalExtensions_,
                ((bitField0_ & 0x00000020) != 0),
                getParentForChildren(),
                isClean());
        additionalExtensions_ = null;
      }
      return additionalExtensionsBuilder_;
    }

    @java.lang.Override
    public final Builder setUnknownFields(final com.google.protobuf.UnknownFieldSet unknownFields) {
      return super.setUnknownFields(unknownFields);
    }

    @java.lang.Override
    public final Builder mergeUnknownFields(
        final com.google.protobuf.UnknownFieldSet unknownFields) {
      return super.mergeUnknownFields(unknownFields);
    }

    // @@protoc_insertion_point(builder_scope:google.cloud.security.privateca.v1.X509Parameters)
  }

  // @@protoc_insertion_point(class_scope:google.cloud.security.privateca.v1.X509Parameters)
  private static final com.google.cloud.security.privateca.v1.X509Parameters DEFAULT_INSTANCE;

  static {
    DEFAULT_INSTANCE = new com.google.cloud.security.privateca.v1.X509Parameters();
  }

  public static com.google.cloud.security.privateca.v1.X509Parameters getDefaultInstance() {
    return DEFAULT_INSTANCE;
  }

  private static final com.google.protobuf.Parser<X509Parameters> PARSER =
      new com.google.protobuf.AbstractParser<X509Parameters>() {
        @java.lang.Override
        public X509Parameters parsePartialFrom(
            com.google.protobuf.CodedInputStream input,
            com.google.protobuf.ExtensionRegistryLite extensionRegistry)
            throws com.google.protobuf.InvalidProtocolBufferException {
          Builder builder = newBuilder();
          try {
            builder.mergeFrom(input, extensionRegistry);
          } catch (com.google.protobuf.InvalidProtocolBufferException e) {
            throw e.setUnfinishedMessage(builder.buildPartial());
          } catch (com.google.protobuf.UninitializedMessageException e) {
            throw e.asInvalidProtocolBufferException().setUnfinishedMessage(builder.buildPartial());
          } catch (java.io.IOException e) {
            throw new com.google.protobuf.InvalidProtocolBufferException(e)
                .setUnfinishedMessage(builder.buildPartial());
          }
          return builder.buildPartial();
        }
      };

  public static com.google.protobuf.Parser<X509Parameters> parser() {
    return PARSER;
  }

  @java.lang.Override
  public com.google.protobuf.Parser<X509Parameters> getParserForType() {
    return PARSER;
  }

  @java.lang.Override
  public com.google.cloud.security.privateca.v1.X509Parameters getDefaultInstanceForType() {
    return DEFAULT_INSTANCE;
  }
}
