Skip to content

Instantly share code, notes, and snippets.

@YannRobert
Last active October 8, 2015 13:13
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save YannRobert/bc48b857d7fc08a4f079 to your computer and use it in GitHub Desktop.
Save YannRobert/bc48b857d7fc08a4f079 to your computer and use it in GitHub Desktop.
TLS certificate issue with carbon.hostedgraphite.com:20030
# openssl s_client -connect carbon.hostedgraphite.com:20030
CONNECTED(00000003)
depth=0 OU = Domain Control Validated, OU = PositiveSSL Wildcard, CN = *.hostedgraphite.com
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 OU = Domain Control Validated, OU = PositiveSSL Wildcard, CN = *.hostedgraphite.com
verify error:num=27:certificate not trusted
verify return:1
depth=0 OU = Domain Control Validated, OU = PositiveSSL Wildcard, CN = *.hostedgraphite.com
verify error:num=21:unable to verify the first certificate
verify return:1
---
Certificate chain
0 s:/OU=Domain Control Validated/OU=PositiveSSL Wildcard/CN=*.hostedgraphite.com
i:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
1 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
2 s:/C=US/O=GeoTrust, Inc./CN=RapidSSL CA
i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFZDCCBEygAwIBAgIRALPi/FBcD6ki9F/ZRMESzgUwDQYJKoZIhvcNAQELBQAw
gZAxCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAO
BgNVBAcTB1NhbGZvcmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1pdGVkMTYwNAYD
VQQDEy1DT01PRE8gUlNBIERvbWFpbiBWYWxpZGF0aW9uIFNlY3VyZSBTZXJ2ZXIg
Q0EwHhcNMTUxMDA2MDAwMDAwWhcNMTcxMTEzMjM1OTU5WjBhMSEwHwYDVQQLExhE
b21haW4gQ29udHJvbCBWYWxpZGF0ZWQxHTAbBgNVBAsTFFBvc2l0aXZlU1NMIFdp
bGRjYXJkMR0wGwYDVQQDDBQqLmhvc3RlZGdyYXBoaXRlLmNvbTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMy9kNOdFtOcqhSOtWK13jw8++890nklht7Q
gXAzrRu+T9XmoWXKq7o7P79A8CKUcSeOfTN9lkch0bmm1Olqia0JZm4JBb9Si8KD
E8L5qqbREIEzU4Ob0XIc9tKyU1dhQFCQgxZRNstHqTp2OlAJNpxE4q8mPWSClxdp
jLF8w0pdgQqlFKbAmFN6Nc2GdVwU1nNrR2gGdnu/OTriGKffEm686wyjxfPZ1JmB
oO9MIXikyb5e6nycGSH2Fb+Wi3r6sYV8D4VFX8Yv97GkyyzLPQyX+XKnf4Lh4gnU
jdo3acHT0LiLgofFHQ3eTHTQKz9iSSPFDqhnCfdHSJJ8PPvzdS0CAwEAAaOCAeUw
ggHhMB8GA1UdIwQYMBaAFJCvajqUWgvYkOoSVnPfQ7Q6KNrnMB0GA1UdDgQWBBS1
dIYkqcv+gyV6PCSPlygZ1IcDczAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIw
ADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwTwYDVR0gBEgwRjA6Bgsr
BgEEAbIxAQICBzArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8u
Y29tL0NQUzAIBgZngQwBAgEwVAYDVR0fBE0wSzBJoEegRYZDaHR0cDovL2NybC5j
b21vZG9jYS5jb20vQ09NT0RPUlNBRG9tYWluVmFsaWRhdGlvblNlY3VyZVNlcnZl
ckNBLmNybDCBhQYIKwYBBQUHAQEEeTB3ME8GCCsGAQUFBzAChkNodHRwOi8vY3J0
LmNvbW9kb2NhLmNvbS9DT01PRE9SU0FEb21haW5WYWxpZGF0aW9uU2VjdXJlU2Vy
dmVyQ0EuY3J0MCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5jb21vZG9jYS5jb20w
MwYDVR0RBCwwKoIUKi5ob3N0ZWRncmFwaGl0ZS5jb22CEmhvc3RlZGdyYXBoaXRl
LmNvbTANBgkqhkiG9w0BAQsFAAOCAQEAg2oAFbBRHzg0UQRHE7HHmOU2MbOVoJ9V
XVWCsRbVa9kFxSH1c86e6zWhLCiH53hsgT4GOtjEgondofVZ17TxONZWNCMDavy4
KL6AYSe81Y97GvWBhTvaNEZEtCsQhHVciha5v6xiOffvnm+FukkJXAAZi4IFo+Gg
1FqSSLHJQoNvvU5IQi5GOcFf1fHmpwiAY7jeWxZ392DRLc40H+vzOSbFbDp+S00b
8bjneb3kD6XMjm90Bp+jGu0RqtfU2LQ5PULCP4aV3gE7F4Znm8TsSMB2lZeXePp4
iKoCYUD3z2WdBBwLHTt09CDueuaXF1QzDsC5FuKBl/fPRDKON27ezw==
-----END CERTIFICATE-----
subject=/OU=Domain Control Validated/OU=PositiveSSL Wildcard/CN=*.hostedgraphite.com
issuer=/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
---
No client certificate CA names sent
Server Temp Key: ECDH, prime256v1, 256 bits
---
SSL handshake has read 3931 bytes and written 375 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-RSA-AES256-GCM-SHA384
Session-ID: 7BAA265CBA0BAC0D4D63A96BCAB1F9AF54D50186CF02D7B63D9A21AF77D1E4C3
Session-ID-ctx:
Master-Key: C56C8EED63731078A2D99D70023290CACC5A889248793316DC6F9F2EDE7E579C6E508D1C8EE237E5B224ADE34F1B4866
Key-Arg : None
Krb5 Principal: None
PSK identity: None
PSK identity hint: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - 6b 92 16 9f ae 18 59 4b-65 c7 02 5c 86 c2 95 9e k.....YKe..\....
0010 - d0 30 d0 e7 31 af 08 28-7c 86 81 b6 a7 d7 cc 45 .0..1..(|......E
0020 - 67 a1 71 f8 45 c2 a8 42-dd 66 38 35 b1 8a 7b 7a g.q.E..B.f85..{z
0030 - 04 37 35 3c bb c0 0f 3a-87 82 c6 86 6e 38 47 d4 .75<...:....n8G.
0040 - 5a de 2a fe 6d b2 0f 54-5c 34 ee 4e 1d bd 14 1d Z.*.m..T\4.N....
0050 - d4 cc 89 c6 0f 73 48 11-b0 95 4a 85 bb ef e5 c5 .....sH...J.....
0060 - 53 a6 43 d2 56 40 14 a6-ea f0 10 a8 bd 30 ff 8a S.C.V@.......0..
0070 - 8d 0f 55 55 23 bb 63 01-c8 57 e4 0f 25 cd c9 29 ..UU#.c..W..%..)
0080 - cb 2e 21 2b 10 b1 e5 c8-96 0c 00 d6 07 6a ef 4a ..!+.........j.J
0090 - db 06 36 5d 7d 7b bb 7d-e8 c3 72 cb 31 c1 a2 2a ..6]}{.}..r.1..*
Start Time: 1444294242
Timeout : 300 (sec)
Verify return code: 21 (unable to verify the first certificate)
---
# openssl x509 -in ./hostedgraphite-cert.pem -text -noout
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
b3:e2:fc:50:5c:0f:a9:22:f4:5f:d9:44:c1:12:ce:05
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Domain Validation Secure Server CA
Validity
Not Before: Oct 6 00:00:00 2015 GMT
Not After : Nov 13 23:59:59 2017 GMT
Subject: OU=Domain Control Validated, OU=PositiveSSL Wildcard, CN=*.hostedgraphite.com
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:cc:bd:90:d3:9d:16:d3:9c:aa:14:8e:b5:62:b5:
de:3c:3c:fb:ef:3d:d2:79:25:86:de:d0:81:70:33:
ad:1b:be:4f:d5:e6:a1:65:ca:ab:ba:3b:3f:bf:40:
f0:22:94:71:27:8e:7d:33:7d:96:47:21:d1:b9:a6:
d4:e9:6a:89:ad:09:66:6e:09:05:bf:52:8b:c2:83:
13:c2:f9:aa:a6:d1:10:81:33:53:83:9b:d1:72:1c:
f6:d2:b2:53:57:61:40:50:90:83:16:51:36:cb:47:
a9:3a:76:3a:50:09:36:9c:44:e2:af:26:3d:64:82:
97:17:69:8c:b1:7c:c3:4a:5d:81:0a:a5:14:a6:c0:
98:53:7a:35:cd:86:75:5c:14:d6:73:6b:47:68:06:
76:7b:bf:39:3a:e2:18:a7:df:12:6e:bc:eb:0c:a3:
c5:f3:d9:d4:99:81:a0:ef:4c:21:78:a4:c9:be:5e:
ea:7c:9c:19:21:f6:15:bf:96:8b:7a:fa:b1:85:7c:
0f:85:45:5f:c6:2f:f7:b1:a4:cb:2c:cb:3d:0c:97:
f9:72:a7:7f:82:e1:e2:09:d4:8d:da:37:69:c1:d3:
d0:b8:8b:82:87:c5:1d:0d:de:4c:74:d0:2b:3f:62:
49:23:c5:0e:a8:67:09:f7:47:48:92:7c:3c:fb:f3:
75:2d
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
keyid:90:AF:6A:3A:94:5A:0B:D8:90:EA:12:56:73:DF:43:B4:3A:28:DA:E7
X509v3 Subject Key Identifier:
B5:74:86:24:A9:CB:FE:83:25:7A:3C:24:8F:97:28:19:D4:87:03:73
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Certificate Policies:
Policy: 1.3.6.1.4.1.6449.1.2.2.7
CPS: https://secure.comodo.com/CPS
Policy: 2.23.140.1.2.1
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.comodoca.com/COMODORSADomainValidationSecureServerCA.crl
Authority Information Access:
CA Issuers - URI:http://crt.comodoca.com/COMODORSADomainValidationSecureServerCA.crt
OCSP - URI:http://ocsp.comodoca.com
X509v3 Subject Alternative Name:
DNS:*.hostedgraphite.com, DNS:hostedgraphite.com
Signature Algorithm: sha256WithRSAEncryption
83:6a:00:15:b0:51:1f:38:34:51:04:47:13:b1:c7:98:e5:36:
31:b3:95:a0:9f:55:5d:55:82:b1:16:d5:6b:d9:05:c5:21:f5:
73:ce:9e:eb:35:a1:2c:28:87:e7:78:6c:81:3e:06:3a:d8:c4:
82:89:dd:a1:f5:59:d7:b4:f1:38:d6:56:34:23:03:6a:fc:b8:
28:be:80:61:27:bc:d5:8f:7b:1a:f5:81:85:3b:da:34:46:44:
b4:2b:10:84:75:5c:8a:16:b9:bf:ac:62:39:f7:ef:9e:6f:85:
ba:49:09:5c:00:19:8b:82:05:a3:e1:a0:d4:5a:92:48:b1:c9:
42:83:6f:bd:4e:48:42:2e:46:39:c1:5f:d5:f1:e6:a7:08:80:
63:b8:de:5b:16:77:f7:60:d1:2d:ce:34:1f:eb:f3:39:26:c5:
6c:3a:7e:4b:4d:1b:f1:b8:e7:79:bd:e4:0f:a5:cc:8e:6f:74:
06:9f:a3:1a:ed:11:aa:d7:d4:d8:b4:39:3d:42:c2:3f:86:95:
de:01:3b:17:86:67:9b:c4:ec:48:c0:76:95:97:97:78:fa:78:
88:aa:02:61:40:f7:cf:65:9d:04:1c:0b:1d:3b:74:f4:20:ee:
7a:e6:97:17:54:33:0e:c0:b9:16:e2:81:97:f7:cf:44:32:8e:
37:6e:de:cf
$ openssl s_client -connect carbon.hostedgraphite.com:20030
CONNECTED(00000003)
depth=3 C = SE, O = AddTrust AB, OU = AddTrust External TTP Network, CN = AddTrust External CA Root
verify return:1
depth=2 C = GB, ST = Greater Manchester, L = Salford, O = COMODO CA Limited, CN = COMODO RSA Certification Authority
verify return:1
depth=1 C = GB, ST = Greater Manchester, L = Salford, O = COMODO CA Limited, CN = COMODO RSA Domain Validation Secure Server CA
verify return:1
depth=0 OU = Domain Control Validated, OU = PositiveSSL Wildcard, CN = *.hostedgraphite.com
verify return:1
---
Certificate chain
0 s:/OU=Domain Control Validated/OU=PositiveSSL Wildcard/CN=*.hostedgraphite.com
i:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
1 s:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
i:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority
2 s:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority
i:/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFZDCCBEygAwIBAgIRALPi/FBcD6ki9F/ZRMESzgUwDQYJKoZIhvcNAQELBQAw
gZAxCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAO
BgNVBAcTB1NhbGZvcmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1pdGVkMTYwNAYD
VQQDEy1DT01PRE8gUlNBIERvbWFpbiBWYWxpZGF0aW9uIFNlY3VyZSBTZXJ2ZXIg
Q0EwHhcNMTUxMDA2MDAwMDAwWhcNMTcxMTEzMjM1OTU5WjBhMSEwHwYDVQQLExhE
b21haW4gQ29udHJvbCBWYWxpZGF0ZWQxHTAbBgNVBAsTFFBvc2l0aXZlU1NMIFdp
bGRjYXJkMR0wGwYDVQQDDBQqLmhvc3RlZGdyYXBoaXRlLmNvbTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMy9kNOdFtOcqhSOtWK13jw8++890nklht7Q
gXAzrRu+T9XmoWXKq7o7P79A8CKUcSeOfTN9lkch0bmm1Olqia0JZm4JBb9Si8KD
E8L5qqbREIEzU4Ob0XIc9tKyU1dhQFCQgxZRNstHqTp2OlAJNpxE4q8mPWSClxdp
jLF8w0pdgQqlFKbAmFN6Nc2GdVwU1nNrR2gGdnu/OTriGKffEm686wyjxfPZ1JmB
oO9MIXikyb5e6nycGSH2Fb+Wi3r6sYV8D4VFX8Yv97GkyyzLPQyX+XKnf4Lh4gnU
jdo3acHT0LiLgofFHQ3eTHTQKz9iSSPFDqhnCfdHSJJ8PPvzdS0CAwEAAaOCAeUw
ggHhMB8GA1UdIwQYMBaAFJCvajqUWgvYkOoSVnPfQ7Q6KNrnMB0GA1UdDgQWBBS1
dIYkqcv+gyV6PCSPlygZ1IcDczAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIw
ADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwTwYDVR0gBEgwRjA6Bgsr
BgEEAbIxAQICBzArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8u
Y29tL0NQUzAIBgZngQwBAgEwVAYDVR0fBE0wSzBJoEegRYZDaHR0cDovL2NybC5j
b21vZG9jYS5jb20vQ09NT0RPUlNBRG9tYWluVmFsaWRhdGlvblNlY3VyZVNlcnZl
ckNBLmNybDCBhQYIKwYBBQUHAQEEeTB3ME8GCCsGAQUFBzAChkNodHRwOi8vY3J0
LmNvbW9kb2NhLmNvbS9DT01PRE9SU0FEb21haW5WYWxpZGF0aW9uU2VjdXJlU2Vy
dmVyQ0EuY3J0MCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5jb21vZG9jYS5jb20w
MwYDVR0RBCwwKoIUKi5ob3N0ZWRncmFwaGl0ZS5jb22CEmhvc3RlZGdyYXBoaXRl
LmNvbTANBgkqhkiG9w0BAQsFAAOCAQEAg2oAFbBRHzg0UQRHE7HHmOU2MbOVoJ9V
XVWCsRbVa9kFxSH1c86e6zWhLCiH53hsgT4GOtjEgondofVZ17TxONZWNCMDavy4
KL6AYSe81Y97GvWBhTvaNEZEtCsQhHVciha5v6xiOffvnm+FukkJXAAZi4IFo+Gg
1FqSSLHJQoNvvU5IQi5GOcFf1fHmpwiAY7jeWxZ392DRLc40H+vzOSbFbDp+S00b
8bjneb3kD6XMjm90Bp+jGu0RqtfU2LQ5PULCP4aV3gE7F4Znm8TsSMB2lZeXePp4
iKoCYUD3z2WdBBwLHTt09CDueuaXF1QzDsC5FuKBl/fPRDKON27ezw==
-----END CERTIFICATE-----
subject=/OU=Domain Control Validated/OU=PositiveSSL Wildcard/CN=*.hostedgraphite.com
issuer=/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
---
No client certificate CA names sent
Server Temp Key: ECDH, prime256v1, 256 bits
---
SSL handshake has read 4997 bytes and written 375 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-RSA-AES256-GCM-SHA384
Session-ID: 465DE044E2771D4646840D0C5AE7E832B8D6EE15260F72ABF139F2F14DB5BAC2
Session-ID-ctx:
Master-Key: 2DA1D194ECFE0EF10D1213F6D2DF009E7654498EA21024768678A25CD24B22ABC33783BB6F94AAB19C6CDF716A43C6E3
Key-Arg : None
Krb5 Principal: None
PSK identity: None
PSK identity hint: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - d6 82 db 17 ac 75 3e 6b-09 34 bb 2d 9e 02 ad f1 .....u>k.4.-....
0010 - 31 ad 58 50 2c 38 2a 43-7c f5 b8 e2 a0 0f 26 e1 1.XP,8*C|.....&.
0020 - 10 f8 cf fc c0 14 6d f2-33 77 b0 9f 46 bf 6c b7 ......m.3w..F.l.
0030 - 4c 57 42 aa f5 c2 40 90-bc fd 4b 8e 13 02 41 60 LWB...@...K...A`
0040 - 7b bc 53 4e 30 ea 52 e3-4b 4f fe 3b 3e c0 59 b0 {.SN0.R.KO.;>.Y.
0050 - 50 1b 52 63 26 ba 9e 12-dc db 7e f2 d5 e9 4b 20 P.Rc&.....~...K
0060 - c0 97 64 55 a2 87 56 df-5f 10 1b d0 cd 6a 63 43 ..dU..V._....jcC
0070 - 3c db 95 1a 53 82 dd b3-11 69 13 30 de 77 3d c5 <...S....i.0.w=.
0080 - 71 50 4a b2 bd 11 2b 72-86 0f 6f 0a cd e7 7b 38 qPJ...+r..o...{8
0090 - e8 6e f4 d8 e9 a7 1f 6d-5d 75 b3 e5 00 e1 a9 17 .n.....m]u......
Start Time: 1444307005
Timeout : 300 (sec)
Verify return code: 0 (ok)
---
@YannRobert
Copy link
Author

@hostedgraphite
Issue started on Oct 07 2015 at 14:02:45 UTC

@YannRobert
Copy link
Author

@YannRobert
Copy link
Author

problem solved on Oct 08 at 11:43:46 UTC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment