Skip to content

Instantly share code, notes, and snippets.

@dottedmag
Created October 29, 2021 17:34
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save dottedmag/54507a17f1d84d8ba5cf41b0dd1c2d3e to your computer and use it in GitHub Desktop.
Save dottedmag/54507a17f1d84d8ba5cf41b0dd1c2d3e to your computer and use it in GitHub Desktop.
% openssl s_client -servername gitlab.freedesktop.org -connect gitlab.freedesktop.org:443
CONNECTED(00000005)
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
---
Certificate chain
0 s:/CN=gitlab.freedesktop.org
i:/C=US/O=Let's Encrypt/CN=R3
1 s:/C=US/O=Let's Encrypt/CN=R3
i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
2 s:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
i:/O=Digital Signature Trust Co./CN=DST Root CA X3
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFMjCCBBqgAwIBAgISBBTxdJKth8Aiu584QlXUNmRAMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yMTEwMDcwODUxMzRaFw0yMjAxMDUwODUxMzNaMCExHzAdBgNVBAMT
FmdpdGxhYi5mcmVlZGVza3RvcC5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQChw44I/cpzXL40QGqsjmvAmWfKetnvdsLtAHH60DvPDixyi+S59lpp
cUc39H3L2dWD5wnqkEUdUxC8Wp2EHe/LyT5/U1ytKzGGrdYOVt4I0vbssVWlfh/t
Y9WKSfKApcKOM1OM+cueCnmaXED6l/V1RVqMeAX9A4UTZ9Hhgoo3maExRIrVt6Xh
qDOhqhN0y1VwsfCqENilMxXcWqaKiSy5i4ECqY/8mwW7B8xaLFHWSnOeY+o2u1Y1
oXtmCdKEIzdshzDvhVIMU+D2wxrwvD5ONU7eZ4DbQmUCKR47fLkt879rU/fcWsvK
TxfyHlU7ANPlUkt9jzx/xtFjR8BxnydlAgMBAAGjggJRMIICTTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQC
MAAwHQYDVR0OBBYEFL4D0wDlHBlDoKmcLmKwu7gRNDi6MB8GA1UdIwQYMBaAFBQu
sxe3WFbLrlAJQOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYV
aHR0cDovL3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5s
ZW5jci5vcmcvMCEGA1UdEQQaMBiCFmdpdGxhYi5mcmVlZGVza3RvcC5vcmcwTAYD
VR0gBEUwQzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYa
aHR0cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEEBgorBgEEAdZ5AgQCBIH1BIHy
APAAdwBGpVXrdfqRIDC1oolp9PN9ESxBdL79SbiFq/L8cP5tRwAAAXxaKk41AAAE
AwBIMEYCIQCP3vib6LCenfYQL4cvnX1M7lyYlo67FhwNv6ow7gL3bwIhAKlPyS0k
6QXOYLfM8ODw3N5HSyAJtBxX0GMf8S80DY/PAHUAQcjKsd8iRkoQxqE6CUKHXk4x
ixsD6+tLx2jwkGKWBvYAAAF8WipObQAABAMARjBEAiARJ+6npcTpSiUfZBnNA0ps
eKQTghpXDwCTJyJmrABaYQIgWDK/iHJ/1DmO+8o9CzmSqMeFsjIPm71KzKjRe2Ky
ehwwDQYJKoZIhvcNAQELBQADggEBAIj0YLoXYu0xexEHiW+PlCAzDgpHLi3cuT1y
BvgTxDCF28bBL5y99aEftdWH+PY/kR9NnJGIgnGuKmPT6A898amzqesqs6fXJVUT
ceKaVGYc8nI7ogH0VpD+IdLOuepEqniSJOJWRBkVg8+eJ+SV0iDH4jjHWa5yXV4I
7kw8Db0q4ZPaJs1O83hV5ldgSaPLiggNumqC64RsfyEaI5KbvbjXBpo2NKmEBlms
85sYkM6OkzvDXTrKt5OcqGmjVPYdbae+vIsqwGbCQdjdF2aGJQY318cy+ezvTwtJ
K8xToqpHJcA+W6t3njW+SqynrKVdtTrG63WYgccNinOITC1cyFE=
-----END CERTIFICATE-----
subject=/CN=gitlab.freedesktop.org
issuer=/C=US/O=Let's Encrypt/CN=R3
---
No client certificate CA names sent
Server Temp Key: ECDH, X25519, 253 bits
---
SSL handshake has read 4504 bytes and written 324 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES128-GCM-SHA256
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-RSA-AES128-GCM-SHA256
Session-ID: 80A40D43FF10538BBE75AF0E011ADFE3C4C30A682984AF3603E5DFD406BB0E06
Session-ID-ctx:
Master-Key: 7B4806F5148B463DAD3E0D643F7D85319AC8D73D034603C07971500AA95C6EA49BC10BB61CE539524B57053A65EAE981
Start Time: 1635528756
Timeout : 7200 (sec)
Verify return code: 10 (certificate has expired)
---
DONE
[dottedmag@newton:~]% openssl s_client -servername gitlab.freedesktop.org -connect 147.75.198.156:443
CONNECTED(00000003)
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=1 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
verify return:0
---
Certificate chain
0 s:/CN=gitlab.freedesktop.org
i:/C=US/O=Let's Encrypt/CN=R3
1 s:/C=US/O=Let's Encrypt/CN=R3
i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
2 s:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
i:/O=Digital Signature Trust Co./CN=DST Root CA X3
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFMjCCBBqgAwIBAgISBBTxdJKth8Aiu584QlXUNmRAMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yMTEwMDcwODUxMzRaFw0yMjAxMDUwODUxMzNaMCExHzAdBgNVBAMT
FmdpdGxhYi5mcmVlZGVza3RvcC5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQChw44I/cpzXL40QGqsjmvAmWfKetnvdsLtAHH60DvPDixyi+S59lpp
cUc39H3L2dWD5wnqkEUdUxC8Wp2EHe/LyT5/U1ytKzGGrdYOVt4I0vbssVWlfh/t
Y9WKSfKApcKOM1OM+cueCnmaXED6l/V1RVqMeAX9A4UTZ9Hhgoo3maExRIrVt6Xh
qDOhqhN0y1VwsfCqENilMxXcWqaKiSy5i4ECqY/8mwW7B8xaLFHWSnOeY+o2u1Y1
oXtmCdKEIzdshzDvhVIMU+D2wxrwvD5ONU7eZ4DbQmUCKR47fLkt879rU/fcWsvK
TxfyHlU7ANPlUkt9jzx/xtFjR8BxnydlAgMBAAGjggJRMIICTTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQC
MAAwHQYDVR0OBBYEFL4D0wDlHBlDoKmcLmKwu7gRNDi6MB8GA1UdIwQYMBaAFBQu
sxe3WFbLrlAJQOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYV
aHR0cDovL3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5s
ZW5jci5vcmcvMCEGA1UdEQQaMBiCFmdpdGxhYi5mcmVlZGVza3RvcC5vcmcwTAYD
VR0gBEUwQzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYa
aHR0cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEEBgorBgEEAdZ5AgQCBIH1BIHy
APAAdwBGpVXrdfqRIDC1oolp9PN9ESxBdL79SbiFq/L8cP5tRwAAAXxaKk41AAAE
AwBIMEYCIQCP3vib6LCenfYQL4cvnX1M7lyYlo67FhwNv6ow7gL3bwIhAKlPyS0k
6QXOYLfM8ODw3N5HSyAJtBxX0GMf8S80DY/PAHUAQcjKsd8iRkoQxqE6CUKHXk4x
ixsD6+tLx2jwkGKWBvYAAAF8WipObQAABAMARjBEAiARJ+6npcTpSiUfZBnNA0ps
eKQTghpXDwCTJyJmrABaYQIgWDK/iHJ/1DmO+8o9CzmSqMeFsjIPm71KzKjRe2Ky
ehwwDQYJKoZIhvcNAQELBQADggEBAIj0YLoXYu0xexEHiW+PlCAzDgpHLi3cuT1y
BvgTxDCF28bBL5y99aEftdWH+PY/kR9NnJGIgnGuKmPT6A898amzqesqs6fXJVUT
ceKaVGYc8nI7ogH0VpD+IdLOuepEqniSJOJWRBkVg8+eJ+SV0iDH4jjHWa5yXV4I
7kw8Db0q4ZPaJs1O83hV5ldgSaPLiggNumqC64RsfyEaI5KbvbjXBpo2NKmEBlms
85sYkM6OkzvDXTrKt5OcqGmjVPYdbae+vIsqwGbCQdjdF2aGJQY318cy+ezvTwtJ
K8xToqpHJcA+W6t3njW+SqynrKVdtTrG63WYgccNinOITC1cyFE=
-----END CERTIFICATE-----
subject=/CN=gitlab.freedesktop.org
issuer=/C=US/O=Let's Encrypt/CN=R3
---
No client certificate CA names sent
Server Temp Key: ECDH, X25519, 253 bits
---
SSL handshake has read 4504 bytes and written 324 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES128-GCM-SHA256
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-RSA-AES128-GCM-SHA256
Session-ID: F7CEB24C0D6BC5C2945BE4E499987D46EC3A17CAFF32A5C8D9BC912F8F7AE1A9
Session-ID-ctx:
Master-Key: 08DB63B0B5BD33D87327B2D9009D25157095C1B7CD4B88619DC6C434266EAC32214E97451922C1FF27787BBE9F754E8F
Start Time: 1635528861
Timeout : 7200 (sec)
Verify return code: 10 (certificate has expired)
---
DONE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment