Skip to content

Instantly share code, notes, and snippets.

@suzannealdrich
Created March 5, 2015 08:51
Show Gist options
  • Save suzannealdrich/9f10bd5e4e42816b6c7c to your computer and use it in GitHub Desktop.
Save suzannealdrich/9f10bd5e4e42816b6c7c to your computer and use it in GitHub Desktop.
FREAK
$ openssl s_client -cipher EXPORT -connect www.nsa.gov:443
CONNECTED(00000003)
depth=1 /C=US/O=GeoTrust Inc./CN=GeoTrust SSL CA - G4
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
0 s:/C=US/ST=Maryland/L=Fort George G Meade/O=National Security Agency/OU=Akamai SAN SSL OV/CN=www.nsa.gov
i:/C=US/O=GeoTrust Inc./CN=GeoTrust SSL CA - G4
1 s:/C=US/O=GeoTrust Inc./CN=GeoTrust SSL CA - G4
i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIE1DCCA7ygAwIBAgICA8MwDQYJKoZIhvcNAQELBQAwRDELMAkGA1UEBhMCVVMx
FjAUBgNVBAoTDUdlb1RydXN0IEluYy4xHTAbBgNVBAMTFEdlb1RydXN0IFNTTCBD
QSAtIEc0MB4XDTE1MDIwNTA1MzcwMloXDTE2MDIwODIxMTQ0MlowgZMxCzAJBgNV
BAYTAlVTMREwDwYDVQQIEwhNYXJ5bGFuZDEcMBoGA1UEBxMTRm9ydCBHZW9yZ2Ug
RyBNZWFkZTEhMB8GA1UEChMYTmF0aW9uYWwgU2VjdXJpdHkgQWdlbmN5MRowGAYD
VQQLExFBa2FtYWkgU0FOIFNTTCBPVjEUMBIGA1UEAxMLd3d3Lm5zYS5nb3YwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+6hKL64sK2vBUZJHETzSlWneR
9pPTIqajXNi7tuNbwNkoCGBxMMclMhxlVUv9dTIjW45MOICkbcfxKXbEi6BAXkJR
nIpl6Afv0WEniHiK+8HdDTPV6jBH0sYRFGae0tLhD/3iayQ60PLNVyTYqw5Y9mum
GIeGaf4xh4Hz7QTwcxjUrBkA1r4+Vgo9oHus4f0y+2/28frMX153zhPzS0gWejxW
rHljY6vRmQFaPLsuy++8dn4VQiBpoZhngnEw4zDuLNUhdhoj/LMAiIT2kPBN2wsU
o5pQW4ZGRMLs8bsVdH+Az6CGGRVMmhKTGkhSv2TrX27Yda+721bnWW2NpkRPAgMB
AAGjggF+MIIBejAfBgNVHSMEGDAWgBSsMu1ayeDeMJyQWFUmY/ZyplRf4zBXBggr
BgEFBQcBAQRLMEkwHwYIKwYBBQUHMAGGE2h0dHA6Ly9ndy5zeW1jZC5jb20wJgYI
KwYBBQUHMAKGGmh0dHA6Ly9ndy5zeW1jYi5jb20vZ3cuY3J0MA4GA1UdDwEB/wQE
AwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwOAYDVR0RBDEwL4IJ
bS5uc2EuZ292ggx3d3cyLm5zYS5nb3aCC3d3dy5uc2EuZ292ggduc2EuZ292MCsG
A1UdHwQkMCIwIKAeoByGGmh0dHA6Ly9ndy5zeW1jYi5jb20vZ3cuY3JsMAwGA1Ud
EwEB/wQCMAAwWgYDVR0gBFMwUTBPBgpghkgBhvhFAQc2MEEwPwYIKwYBBQUHAgEW
M2h0dHBzOi8vd3d3Lmdlb3RydXN0LmNvbS9yZXNvdXJjZXMvcmVwb3NpdG9yeS9s
ZWdhbDANBgkqhkiG9w0BAQsFAAOCAQEAAtlVZNnllOkxsQolOqZMyp9FDtMnkOH6
lUyW8J9SrCgYc5hAEYjFtdeqVQhMQq5gZUguIYLGNhEKFKqnKDuqd290K+//Qohk
Qtv+TVppB5RqPDIgU+LqeLvAAFxffR9VEuxfFB5S1NnN4xiP2/JNlfxuAEkhGYGj
T455putBdHv9Ztf5ODfIg1qSWVKNOpLaS4hEqb4hYKBoFZ/cMP51soVDUFXnQHjG
2cQn8awjc4Rr6HSQdLjFpEd4it95nycBg8sE6Z5R8bg+yTPBEvk02DmOZLni64BS
1n8d9NrXpmp5UUIsCEa50d5jGmh7ZfQv3XpPyAww3ZaBh0blhAPJ9g==
-----END CERTIFICATE-----
subject=/C=US/ST=Maryland/L=Fort George G Meade/O=National Security Agency/OU=Akamai SAN SSL OV/CN=www.nsa.gov
issuer=/C=US/O=GeoTrust Inc./CN=GeoTrust SSL CA - G4
---
No client certificate CA names sent
---
SSL handshake has read 2804 bytes and written 199 bytes
---
New, TLSv1/SSLv3, Cipher is EXP-DES-CBC-SHA
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : EXP-DES-CBC-SHA
Session-ID: 17C501C5E3C4A9F18363FAD5F467C48C825B5BA5A9E4D470BA76BDE14E21592C
Session-ID-ctx:
Master-Key: 1F10B1713E35101AC2168904CE9C8749327547F15AA07AEFCE9EEA87C6B25FE8F8CB32D5FC0541CDF5CB141A7FE2CABF
Key-Arg : None
Start Time: 1425545372
Timeout : 300 (sec)
Verify return code: 0 (ok)
---
^C
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment