Skip to content

Instantly share code, notes, and snippets.

@KIVagant
Last active August 3, 2020 18:45
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save KIVagant/37b87245b27810f359acb22fdfa4c13b to your computer and use it in GitHub Desktop.
Save KIVagant/37b87245b27810f359acb22fdfa4c13b to your computer and use it in GitHub Desktop.
tls results (linkerd2)
349309 1858.306418996 172.20.0.10 → 10.56.43.237 DNS 108 Standard query response 0x6f78 A www.example.com A 93.184.216.34
349310 1858.306576019 10.56.43.237 → 127.0.0.1 TCP 76 [TCP Port numbers reused] 51046 → 4140 [SYN] Seq=0 Win=26883 Len=0 MSS=8961 SACK_PERM=1 TSval=1099592030 TSecr=0 WS=512
349311 1858.306588068 93.184.216.34 → 10.56.43.237 TCP 76 443 → 51046 [SYN, ACK] Seq=0 Ack=1 Win=43690 Len=0 MSS=65495 SACK_PERM=1 TSval=3444165818 TSecr=1099592030 WS=512
349312 1858.306598463 10.56.43.237 → 127.0.0.1 TCP 68 51046 → 4140 [ACK] Seq=1 Ack=1 Win=27136 Len=0 TSval=1099592030 TSecr=3444165818
349313 1858.306755035 10.56.43.237 → 127.0.0.1 TLSv1 170 Client Hello
349314 1858.306764426 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51046 [ACK] Seq=1 Ack=103 Win=44032 Len=0 TSval=3444165818 TSecr=1099592030
349315 1858.306848506 10.56.43.237 → 93.184.216.34 TCP 76 51048 → 443 [SYN] Seq=0 Win=26883 Len=0 MSS=8961 SACK_PERM=1 TSval=1099592030 TSecr=0 WS=512
349316 1858.308819576 93.184.216.34 → 10.56.43.237 TCP 76 443 → 51048 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460 SACK_PERM=1 TSval=2742442733 TSecr=1099592030 WS=512
349317 1858.308836941 10.56.43.237 → 93.184.216.34 TCP 68 51048 → 443 [ACK] Seq=1 Ack=1 Win=27136 Len=0 TSval=1099592032 TSecr=2742442733
349318 1858.308900911 10.56.43.237 → 93.184.216.34 TLSv1 170 Client Hello
349319 1858.310116791 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51048 [ACK] Seq=1 Ack=103 Win=65536 Len=0 TSval=2742442734 TSecr=1099592033
349320 1858.311080839 93.184.216.34 → 10.56.43.237 TLSv1 4164 Server Hello, Certificate
349321 1858.311105282 10.56.43.237 → 93.184.216.34 TCP 68 51048 → 443 [ACK] Seq=103 Ack=4097 Win=45056 Len=0 TSval=1099592035 TSecr=2742442735
349322 1858.311085527 93.184.216.34 → 10.56.43.237 TLSv1 395 Server Key Exchange, Server Hello Done
349323 1858.311110119 10.56.43.237 → 93.184.216.34 TCP 68 51048 → 443 [ACK] Seq=103 Ack=4424 Win=48128 Len=0 TSval=1099592035 TSecr=2742442735
349324 1858.311166352 93.184.216.34 → 10.56.43.237 TLSv1 4164 Server Hello, Certificate
349325 1858.311186214 10.56.43.237 → 127.0.0.1 TCP 68 51046 → 4140 [ACK] Seq=103 Ack=4097 Win=45056 Len=0 TSval=1099592035 TSecr=3444165823
349326 1858.311206289 93.184.216.34 → 10.56.43.237 TLSv1 395 Server Key Exchange, Server Hello Done
349327 1858.311212959 10.56.43.237 → 127.0.0.1 TCP 68 51046 → 4140 [ACK] Seq=103 Ack=4424 Win=53248 Len=0 TSval=1099592035 TSecr=3444165823
349328 1858.313958194 10.56.43.237 → 127.0.0.1 TLSv1 206 Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message
349329 1858.314028909 10.56.43.237 → 93.184.216.34 TLSv1 206 Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message
349330 1858.315509019 93.184.216.34 → 10.56.43.237 TLSv1 306 New Session Ticket, Change Cipher Spec, Encrypted Handshake Message
349331 1858.315568848 93.184.216.34 → 10.56.43.237 TLSv1 306 New Session Ticket, Change Cipher Spec, Encrypted Handshake Message
349332 1858.315923692 10.56.43.237 → 127.0.0.1 TLSv1 150 Application Data, Application Data
349333 1858.315983576 10.56.43.237 → 127.0.0.1 TLSv1 109 Encrypted Alert
349334 1858.315990724 10.56.43.237 → 93.184.216.34 TLSv1 150 Application Data, Application Data
349335 1858.316017780 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51046 [ACK] Seq=4662 Ack=365 Win=45056 Len=0 TSval=3444165828 TSecr=1099592040
349336 1858.316037288 10.56.43.237 → 93.184.216.34 TLSv1 109 Encrypted Alert
349337 1858.316057102 10.56.43.237 → 93.184.216.34 TCP 68 51048 → 443 [FIN, ACK] Seq=364 Ack=4662 Win=50688 Len=0 TSval=1099592040 TSecr=2742442740
349338 1858.317263160 93.184.216.34 → 10.56.43.237 TLSv1 760 Application Data, Application Data, Application Data, Application Data
349339 1858.317316674 93.184.216.34 → 10.56.43.237 TLSv1 109 Encrypted Alert
349340 1858.317331265 93.184.216.34 → 10.56.43.237 TLSv1 760 Application Data, Application Data, Application Data, Application Data
349341 1858.317323785 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51048 [FIN, ACK] Seq=5395 Ack=365 Win=67072 Len=0 TSval=2742442742 TSecr=1099592040
349342 1858.317345121 10.56.43.237 → 93.184.216.34 TCP 68 51048 → 443 [ACK] Seq=365 Ack=5396 Win=53760 Len=0 TSval=1099592041 TSecr=2742442742
349343 1858.317345962 10.56.43.237 → 127.0.0.1 TCP 56 51046 → 4140 [RST] Seq=365 Win=0 Len=0
349251 1858.284685216 172.20.0.10 → 10.56.43.237 DNS 108 Standard query response 0xfdec A www.example.com A 93.184.216.34
349252 1858.284838893 10.56.43.237 → 127.0.0.1 TCP 76 [TCP Port numbers reused] 51042 → 4140 [SYN] Seq=0 Win=26883 Len=0 MSS=8961 SACK_PERM=1 TSval=1099592008 TSecr=0 WS=512
349253 1858.284853931 93.184.216.34 → 10.56.43.237 TCP 76 443 → 51042 [SYN, ACK] Seq=0 Ack=1 Win=43690 Len=0 MSS=65495 SACK_PERM=1 TSval=3444165796 TSecr=1099592008 WS=512
349254 1858.284866180 10.56.43.237 → 127.0.0.1 TCP 68 51042 → 4140 [ACK] Seq=1 Ack=1 Win=27136 Len=0 TSval=1099592008 TSecr=3444165796
349255 1858.285013995 10.56.43.237 → 127.0.0.1 TLSv1 170 Client Hello
349256 1858.285022277 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51042 [ACK] Seq=1 Ack=103 Win=44032 Len=0 TSval=3444165797 TSecr=1099592009
349257 1858.285113405 10.56.43.237 → 93.184.216.34 TCP 76 51044 → 443 [SYN] Seq=0 Win=26883 Len=0 MSS=8961 SACK_PERM=1 TSval=1099592009 TSecr=0 WS=512
349258 1858.287231976 93.184.216.34 → 10.56.43.237 TCP 76 443 → 51044 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460 SACK_PERM=1 TSval=1528624365 TSecr=1099592009 WS=512
349259 1858.287250292 10.56.43.237 → 93.184.216.34 TCP 68 51044 → 443 [ACK] Seq=1 Ack=1 Win=27136 Len=0 TSval=1099592011 TSecr=1528624365
349260 1858.287331199 10.56.43.237 → 93.184.216.34 TLSv1 170 Client Hello
349261 1858.288502697 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51044 [ACK] Seq=1 Ack=103 Win=65536 Len=0 TSval=1528624366 TSecr=1099592011
349262 1858.289577916 93.184.216.34 → 10.56.43.237 TLSv1 4164 Server Hello, Certificate
349263 1858.289600820 10.56.43.237 → 93.184.216.34 TCP 68 51044 → 443 [ACK] Seq=103 Ack=4097 Win=45056 Len=0 TSval=1099592013 TSecr=1528624367
349264 1858.289582757 93.184.216.34 → 10.56.43.237 TLSv1 395 Server Key Exchange, Server Hello Done
349265 1858.289605830 10.56.43.237 → 93.184.216.34 TCP 68 51044 → 443 [ACK] Seq=103 Ack=4424 Win=48128 Len=0 TSval=1099592013 TSecr=1528624367
349266 1858.289670215 93.184.216.34 → 10.56.43.237 TLSv1 4164 Server Hello, Certificate
349267 1858.289686377 10.56.43.237 → 127.0.0.1 TCP 68 51042 → 4140 [ACK] Seq=103 Ack=4097 Win=45056 Len=0 TSval=1099592013 TSecr=3444165801
349268 1858.289699543 93.184.216.34 → 10.56.43.237 TLSv1 395 Server Key Exchange, Server Hello Done
349269 1858.289714069 10.56.43.237 → 127.0.0.1 TCP 68 51042 → 4140 [ACK] Seq=103 Ack=4424 Win=53248 Len=0 TSval=1099592013 TSecr=3444165801
349270 1858.292247358 10.56.43.237 → 127.0.0.1 TLSv1 206 Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message
349271 1858.292316341 10.56.43.237 → 93.184.216.34 TLSv1 206 Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message
349272 1858.293745233 93.184.216.34 → 10.56.43.237 TLSv1 306 New Session Ticket, Change Cipher Spec, Encrypted Handshake Message
349273 1858.293797863 93.184.216.34 → 10.56.43.237 TLSv1 306 New Session Ticket, Change Cipher Spec, Encrypted Handshake Message
349274 1858.294171323 10.56.43.237 → 127.0.0.1 TLSv1 150 Application Data, Application Data
349275 1858.294230294 10.56.43.237 → 127.0.0.1 TLSv1 109 Encrypted Alert
349276 1858.294230991 10.56.43.237 → 93.184.216.34 TLSv1 150 Application Data, Application Data
349277 1858.294259393 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51042 [ACK] Seq=4662 Ack=365 Win=45056 Len=0 TSval=3444165806 TSecr=1099592018
349278 1858.294298757 10.56.43.237 → 93.184.216.34 TLSv1 109 Encrypted Alert
349279 1858.294321239 10.56.43.237 → 93.184.216.34 TCP 68 51044 → 443 [FIN, ACK] Seq=364 Ack=4662 Win=50688 Len=0 TSval=1099592018 TSecr=1528624372
349280 1858.295528609 93.184.216.34 → 10.56.43.237 TLSv1 760 Application Data, Application Data, Application Data, Application Data
349281 1858.295548983 93.184.216.34 → 10.56.43.237 TLSv1 109 Encrypted Alert
349282 1858.295557373 93.184.216.34 → 10.56.43.237 TCP 68 443 → 51044 [FIN, ACK] Seq=5395 Ack=365 Win=67072 Len=0 TSval=1528624373 TSecr=1099592018
349283 1858.295591972 10.56.43.237 → 93.184.216.34 TCP 68 51044 → 443 [ACK] Seq=365 Ack=5396 Win=53760 Len=0 TSval=1099592019 TSecr=1528624373
349284 1858.295628614 93.184.216.34 → 10.56.43.237 TLSv1 801 Application Data, Application Data, Application Data, Application Data, Encrypted Alert
349285 1858.295641907 10.56.43.237 → 127.0.0.1 TCP 56 51042 → 4140 [RST] Seq=365 Win=0 Len=0
#!/usr/bin/env bash
echo "" > out_2
while :
do
echo "*****" >> out_2
echo "GET /" | openssl s_client -connect www.example.com:443 >> out_2 #-no_tls1_1
ret=$?
if [ $ret -ne 0 ]; then
echo "!!!!!!" >> out_2
exit
fi
done
\n\n*****\n\n
CONNECTED(00000003)
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 0 bytes and written 102 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1
Cipher : 0000
Session-ID:
Session-ID-ctx:
Master-Key:
PSK identity: None
PSK identity hint: None
SRP username: None
Start Time: 1596476867
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
---
!!!!!!
\n\n*****\n\n
CONNECTED(00000003)
---
Certificate chain
0 s:/C=US/ST=California/L=Los Angeles/O=Internet Corporation for Assigned Names and Numbers/OU=Technology/CN=www.example.org
i:/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA
1 s:/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA
i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root CA
2 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root CA
i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root CA
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIHQDCCBiigAwIBAgIQD9B43Ujxor1NDyupa2A4/jANBgkqhkiG9w0BAQsFADBN
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMScwJQYDVQQDEx5E
aWdpQ2VydCBTSEEyIFNlY3VyZSBTZXJ2ZXIgQ0EwHhcNMTgxMTI4MDAwMDAwWhcN
MjAxMjAyMTIwMDAwWjCBpTELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3Ju
aWExFDASBgNVBAcTC0xvcyBBbmdlbGVzMTwwOgYDVQQKEzNJbnRlcm5ldCBDb3Jw
b3JhdGlvbiBmb3IgQXNzaWduZWQgTmFtZXMgYW5kIE51bWJlcnMxEzARBgNVBAsT
ClRlY2hub2xvZ3kxGDAWBgNVBAMTD3d3dy5leGFtcGxlLm9yZzCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBANDwEnSgliByCGUZElpdStA6jGaPoCkrp9vV
rAzPpXGSFUIVsAeSdjF11yeOTVBqddF7U14nqu3rpGA68o5FGGtFM1yFEaogEv5g
rJ1MRY/d0w4+dw8JwoVlNMci+3QTuUKf9yH28JxEdG3J37Mfj2C3cREGkGNBnY80
eyRJRqzy8I0LSPTTkhr3okXuzOXXg38ugr1x3SgZWDNuEaE6oGpyYJIBWZ9jF3pJ
QnucP9vTBejMh374qvyd0QVQq3WxHrogy4nUbWw3gihMxT98wRD1oKVma1NTydvt
hcNtBfhkp8kO64/hxLHrLWgOFT/l4tz8IWQt7mkrBHjbd2XLVPkCAwEAAaOCA8Ew
ggO9MB8GA1UdIwQYMBaAFA+AYRyCMWHVLyjnjUY4tCzhxtniMB0GA1UdDgQWBBRm
mGIC4AmRp9njNvt2xrC/oW2nvjCBgQYDVR0RBHoweIIPd3d3LmV4YW1wbGUub3Jn
ggtleGFtcGxlLmNvbYILZXhhbXBsZS5lZHWCC2V4YW1wbGUubmV0ggtleGFtcGxl
Lm9yZ4IPd3d3LmV4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5lZHWCD3d3dy5leGFt
cGxlLm5ldDAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsG
AQUFBwMCMGsGA1UdHwRkMGIwL6AtoCuGKWh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNv
bS9zc2NhLXNoYTItZzYuY3JsMC+gLaArhilodHRwOi8vY3JsNC5kaWdpY2VydC5j
b20vc3NjYS1zaGEyLWc2LmNybDBMBgNVHSAERTBDMDcGCWCGSAGG/WwBATAqMCgG
CCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMAgGBmeBDAEC
AjB8BggrBgEFBQcBAQRwMG4wJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2lj
ZXJ0LmNvbTBGBggrBgEFBQcwAoY6aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29t
L0RpZ2lDZXJ0U0hBMlNlY3VyZVNlcnZlckNBLmNydDAMBgNVHRMBAf8EAjAAMIIB
fwYKKwYBBAHWeQIEAgSCAW8EggFrAWkAdwCkuQmQtBhYFIe7E6LMZ3AKPDWYBPkb
37jjd80OyA3cEAAAAWdcMZVGAAAEAwBIMEYCIQCEZIG3IR36Gkj1dq5L6EaGVycX
sHvpO7dKV0JsooTEbAIhALuTtf4wxGTkFkx8blhTV+7sf6pFT78ORo7+cP39jkJC
AHYAh3W/51l8+IxDmV+9827/Vo1HVjb/SrVgwbTq/16ggw8AAAFnXDGWFQAABAMA
RzBFAiBvqnfSHKeUwGMtLrOG3UGLQIoaL3+uZsGTX3MfSJNQEQIhANL5nUiGBR6g
l0QlCzzqzvorGXyB/yd7nttYttzo8EpOAHYAb1N2rDHwMRnYmQCkURX/dxUcEdkC
wQApBo2yCJo32RMAAAFnXDGWnAAABAMARzBFAiEA5Hn7Q4SOyqHkT+kDsHq7ku7z
RDuM7P4UDX2ft2Mpny0CIE13WtxJAUr0aASFYZ/XjSAMMfrB0/RxClvWVss9LHKM
MA0GCSqGSIb3DQEBCwUAA4IBAQBzcIXvQEGnakPVeJx7VUjmvGuZhrr7DQOLeP4R
8CmgDM1pFAvGBHiyzvCH1QGdxFl6cf7wbp7BoLCRLR/qPVXFMwUMzcE1GLBqaGZM
v1Yh2lvZSLmMNSGRXdx113pGLCInpm/TOhfrvr0TxRImc8BdozWJavsn1N2qdHQu
N+UBO6bQMLCD0KHEdSGFsuX6ZwAworxTg02/1qiDu7zW7RyzHvFYA4IAjpzvkPIa
X6KjBtpdvp/aXabmL95YgBjT8WJ7pqOfrqhpcmOBZa6Cg6O1l4qbIFH/Gj9hQB5I
0Gs4+eH6F9h3SojmPTYkT+8KuZ9w84Mn+M8qBXUQoYoKgIjN
-----END CERTIFICATE-----
subject=/C=US/ST=California/L=Los Angeles/O=Internet Corporation for Assigned Names and Numbers/OU=Technology/CN=www.example.org
issuer=/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA
---
No client certificate CA names sent
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 4661 bytes and written 240 bytes
Verification: OK
---
New, TLSv1.0, Cipher is ECDHE-RSA-AES128-SHA
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1
Cipher : ECDHE-RSA-AES128-SHA
Session-ID: 769E89B296DE1ACC8BCC30AC655297FC1A3C020051F330DFD2AE461C338A8C1A
Session-ID-ctx:
Master-Key: D5AD33A54D8550E06BC89CDCD77A8399C92D038F9E7E20E3EE062E1E64E17F1DFFFD2A743135E2DF9D5A31CA92E99445
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - 26 7f 82 6e 28 b9 cc e5-50 3b 4b f1 2d bd 11 73 &..n(...P;K.-..s
0010 - 91 68 8a 2c 09 a2 80 28-eb 00 30 9e 59 ee 8a e4 .h.,...(..0.Y...
0020 - 7e a3 7a fb 3e 91 ac 28-ba cc 03 26 6a 74 87 64 ~.z.>..(...&jt.d
0030 - be 40 c9 f4 08 c1 53 93-bf a2 79 2a 25 aa 48 9a .@....S...y*%.H.
0040 - 35 29 42 65 65 01 f6 0d-2f 74 99 07 68 0b e6 09 5)Bee.../t..h...
0050 - 1f 8c e4 c8 10 c3 92 00-b1 d8 80 71 85 c7 21 c2 ...........q..!.
0060 - dd ef 97 cb 69 1a a3 96-f7 3d 13 6a 06 d0 69 40 ....i....=.j..i@
0070 - 0e 32 f7 b8 76 df 0f 9a-62 fd 2d 99 38 f7 3f 0e .2..v...b.-.8.?.
0080 - f4 11 00 63 1b 32 ea a9-7a 55 e2 48 d9 a0 18 b3 ...c.2..zU.H....
0090 - f2 8f e9 7d 81 04 a2 84-a7 ee 2b 6e ac 21 ee 82 ...}......+n.!..
Start Time: 1596476867
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: yes
---
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment