Skip to content

Instantly share code, notes, and snippets.

@atonse
Created March 14, 2019 14:02
Show Gist options
  • Save atonse/e62c4cf4c01bdbc5f2a2c6da365534ab to your computer and use it in GitHub Desktop.
Save atonse/e62c4cf4c01bdbc5f2a2c6da365534ab to your computer and use it in GitHub Desktop.
WebKit.org Issues
➜ ~ curl https://webkit.org
curl: (60) SSL certificate problem: self signed certificate in certificate chain
More details here: https://curl.haxx.se/docs/sslcerts.html
curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.
HTTPS-proxy has similar options --proxy-cacert and --proxy-insecure.
➜ ~ openssl s_client -showcerts -connect webkit.org:443
CONNECTED(00000005)
depth=2 CN = Apple Corporate Root CA, OU = Certification Authority, O = Apple Inc., C = US
verify error:num=19:self signed certificate in certificate chain
verify return:0
---
Certificate chain
0 s:/CN=www.webkit.org/OU=management:idms.group.764034/O=Apple Inc./ST=California/C=US
i:/CN=Apple Corporate Server CA 1/OU=Certification Authority/O=Apple Inc./C=US
-----BEGIN CERTIFICATE-----
MIIGMDCCBRigAwIBAgIIXVCjs/SFspUwDQYJKoZIhvcNAQELBQAwajEkMCIGA1UE
AwwbQXBwbGUgQ29ycG9yYXRlIFNlcnZlciBDQSAxMSAwHgYDVQQLDBdDZXJ0aWZp
Y2F0aW9uIEF1dGhvcml0eTETMBEGA1UECgwKQXBwbGUgSW5jLjELMAkGA1UEBhMC
VVMwHhcNMTkwMzE0MDEyMTA3WhcNMjEwNDEyMDEyMTA3WjB3MRcwFQYDVQQDDA53
d3cud2Via2l0Lm9yZzElMCMGA1UECwwcbWFuYWdlbWVudDppZG1zLmdyb3VwLjc2
NDAzNDETMBEGA1UECgwKQXBwbGUgSW5jLjETMBEGA1UECAwKQ2FsaWZvcm5pYTEL
MAkGA1UEBhMCVVMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDyy+Gl
QWO/kA1OWR9xX5VFb/nktp/u0+xBIbUJBRSdzPrpZhcHok9J6Df0/al7JtSWFGQP
qbNTfW8ntYdGsthOdalzqRHz5MQrXCut4W2jqcjwN9hyeHZfmI3P4lhrmoFRqcCH
aWtksIoNjLTApPmROwE7hYGYdJmSzHinndEwJkIElevlIqWoLkx9F0Ul/6ZzMnEg
Cry/x0+GdFAM9JyWucEhkZ66AwCceTIuYicAJscWv24KsCDsHGgt9NCzQb7pYtBf
ARSdI5nxjZORhb03Jk4ZdkRD45Ad3ELJBzQa35k7hy1+rhOuFfQlXnukS02OOYGA
M5c5jrhWI90BMqupAgMBAAGjggLLMIICxzAMBgNVHRMBAf8EAjAAMB8GA1UdIwQY
MBaAFLYjtVrrfuu28ygeBNCtXJOppJptMIGDBggrBgEFBQcBAQR3MHUwOQYIKwYB
BQUHMAKGLWh0dHA6Ly9jZXJ0cy5hcHBsZS5jb20vYXBwbGVjb3Jwc2VydmVyY2Ex
LmRlcjA4BggrBgEFBQcwAYYsaHR0cDovL29jc3AuYXBwbGUuY29tL29jc3AwMy1j
b3Jwc2VydmVyY2ExMDQwbgYDVR0RBGcwZYIOd3d3LndlYmtpdC5vcmeCCndlYmtp
dC5vcmeCEm5pZ2h0bHkud2Via2l0Lm9yZ4IRcXVldWVzLndlYmtpdC5vcmeCD3d3
dzIud2Via2l0Lm9yZ4IPYmxvZy53ZWJraXQub3JnMIIBEgYDVR0gBIIBCTCCAQUw
ggEBBgoqhkiG92NkBQ8CMIHyMIGkBggrBgEFBQcCAjCBlwyBlFJlbGlhbmNlIG9u
IHRoaXMgY2VydGlmaWNhdGUgYnkgYW55IHBhcnR5IGFzc3VtZXMgYWNjZXB0YW5j
ZSBvZiBhbnkgYXBwbGljYWJsZSB0ZXJtcyBhbmQgY29uZGl0aW9ucyBvZiB1c2Ug
YW5kL29yIGNlcnRpZmljYXRpb24gcHJhY3RpY2Ugc3RhdGVtZW50cy4wSQYIKwYB
BQUHAgEWPWh0dHBzOi8vY2VydGlmaWNhdGVtYW5hZ2VyLmFwcGxlLmNvbS8jaGVs
cC9wb2xpY2llcy9jb3Jwb3JhdGUwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUF
BwMCMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuYXBwbGUuY29tL2FwcGxl
Y29ycHNlcnZlcmNhMS5jcmwwHQYDVR0OBBYEFNLXYmbkkrf4rA2rwmijuj54irye
MA4GA1UdDwEB/wQEAwIFoDANBgkqhkiG9w0BAQsFAAOCAQEATDFbswUo2xZBoP1b
kjLSste7SfLm86dUc0jkcMNnq1t1/tT+/7FMFg3PsAtV0VmJ3qwrq8gKwaCTJM39
GckMeWClXZwU3JIo7mse+yHCzq9q249Rsz15GHqV3Y9Hx3NDi7j13l7K92S7s9/X
lN5iaxNOFSRcItzu5D+4WLT8V/X0o6ZtJNwTOHUxs3MWh5GGb/m6qqe3Cuu9Xlfm
YrO8WfoI9SP20vfKBNdPGTpmz+JAbY45WDY/Gkq9Qqenvi/MYHVzcXDShv3tgc1G
s0CW9k/y5/3hRQtMaA0cZXtm1Xqxci6IAEgs+G0d4z/sgtrgueMUUakNSgSac/MX
T8pcTQ==
-----END CERTIFICATE-----
1 s:/CN=Apple Corporate Server CA 1/OU=Certification Authority/O=Apple Inc./C=US
i:/CN=Apple Corporate Root CA/OU=Certification Authority/O=Apple Inc./C=US
-----BEGIN CERTIFICATE-----
MIIEQDCCAyigAwIBAgIIDV3faSebIxEwDQYJKoZIhvcNAQELBQAwZjEgMB4GA1UE
AwwXQXBwbGUgQ29ycG9yYXRlIFJvb3QgQ0ExIDAeBgNVBAsMF0NlcnRpZmljYXRp
b24gQXV0aG9yaXR5MRMwEQYDVQQKDApBcHBsZSBJbmMuMQswCQYDVQQGEwJVUzAe
Fw0xNDAzMjYxNjUzMzdaFw0yOTAzMjYxNjUzMzdaMGoxJDAiBgNVBAMMG0FwcGxl
IENvcnBvcmF0ZSBTZXJ2ZXIgQ0EgMTEgMB4GA1UECwwXQ2VydGlmaWNhdGlvbiBB
dXRob3JpdHkxEzARBgNVBAoMCkFwcGxlIEluYy4xCzAJBgNVBAYTAlVTMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4+looeebvPeHSCKbCV/IyaaazM1A
Fvih0PYnFUzn08Fu3xEGmmPFh1Xa368VMZhF9IzCPJOiHMDwKnf0GZSW9HtSdISG
WmZ9aJKhXuGpIeAUOIQhMoshlUcnF6C6e9fY1yUgd8tii8YPwUnGK0LpAnCemUR3
UQVieLyw0qemkXElWBONishGQduJQcUjfYTpArAa+F1m0OHhcvSkZXmXCnvA4yR0
g0qBXsOiv1Eylo8oMghJ+wJDYkKzhIQwGyjkBbm71rXEoquOV1MpvAtP1h6kUtwW
HJXCjZdruz7Ik8cBlx4YCVk5D11zTqmPSf1JFr0l7NkF6uOwBA7ZCZ7AtwIDAQAB
o4HtMIHqMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL29jc3Au
YXBwbGUuY29tL29jc3AwNC1jb3Jwcm9vdDAdBgNVHQ4EFgQUtiO1Wut+67bzKB4E
0K1ck6mkmm0wDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBQ1ICbOhb5JJiAB
3cju/z1oyNDf9TAyBgNVHR8EKzApMCegJaAjhiFodHRwOi8vY3JsLmFwcGxlLmNv
bS9jb3Jwcm9vdC5jcmwwDgYDVR0PAQH/BAQDAgEGMBAGCiqGSIb3Y2QGGAQEAgUA
MA0GCSqGSIb3DQEBCwUAA4IBAQANNC+ywvHw3KKfj0GchMpm3JCcxJDJ2tk3T67J
2c/iS45ZR5qDMt+nl0WdHkZYXdccF8UcnqJ09nN3+TWtZ8M81YcelhY9i0BRqBag
Uxz1yzLEqMUqOiHZ/VGBWW8b+UCGls+gc6NbYAK2Ia059fr8qG40AXxZ83P8ur70
ThY2nlF3gPWhx67/BHFrs74+p9F0K01YWDuUdKNlJ8F0qdL5ioGzR7MGjpzmQoZ3
+JaZH+0wj0vVD15xbKzbSOM8WCvom54kil3NVl+pB+rNLJQ9p38b6BC40h5DWg0T
2vU/EJ0tH+aUES9A/18hlgLwX1RWMpDVZ64pDiJw4yt6lcDH
-----END CERTIFICATE-----
2 s:/CN=Apple Corporate Root CA/OU=Certification Authority/O=Apple Inc./C=US
i:/CN=Apple Corporate Root CA/OU=Certification Authority/O=Apple Inc./C=US
-----BEGIN CERTIFICATE-----
MIIDsTCCApmgAwIBAgIIFJlrSmrkQKAwDQYJKoZIhvcNAQELBQAwZjEgMB4GA1UE
AwwXQXBwbGUgQ29ycG9yYXRlIFJvb3QgQ0ExIDAeBgNVBAsMF0NlcnRpZmljYXRp
b24gQXV0aG9yaXR5MRMwEQYDVQQKDApBcHBsZSBJbmMuMQswCQYDVQQGEwJVUzAe
Fw0xMzA3MTYxOTIwNDVaFw0yOTA3MTcxOTIwNDVaMGYxIDAeBgNVBAMMF0FwcGxl
IENvcnBvcmF0ZSBSb290IENBMSAwHgYDVQQLDBdDZXJ0aWZpY2F0aW9uIEF1dGhv
cml0eTETMBEGA1UECgwKQXBwbGUgSW5jLjELMAkGA1UEBhMCVVMwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC1O+Ofah0ORlEe0LUXawZLkq84ECWh7h5O
7xngc7U3M3IhIctiSj2paNgHtOuNCtswMyEvb9P3Xc4gCgTb/791CEI/PtjI76T4
VnsTZGvzojgQ+u6dg5Md++8TbDhJ3etxppJYBN4BQSuZXr0kP2moRPKqAXi5OAYQ
dzb48qM+2V/q9Ytqpl/mUdCbUKAe9YWeSVBKYXjaKaczcouD7nuneU6OAm+dJZcm
hgyCxYwWfklh/f8aoA0o4Wj1roVy86vgdHXMV2Q8LFUFyY2qs+zIYogVKsRZYDfB
7WvO6cqvsKVFuv8WMqqShtm5oRN1lZuXXC21EspraznWm0s0R6s1AgMBAAGjYzBh
MB0GA1UdDgQWBBQ1ICbOhb5JJiAB3cju/z1oyNDf9TAPBgNVHRMBAf8EBTADAQH/
MB8GA1UdIwQYMBaAFDUgJs6FvkkmIAHdyO7/PWjI0N/1MA4GA1UdDwEB/wQEAwIB
BjANBgkqhkiG9w0BAQsFAAOCAQEAcwJKpncCp+HLUpediRGgj7zzjxQBKfOlRRcG
+ATybdXDd7gAwgoaCTI2NmnBKvBEN7x+XxX3CJwZJx1wT9wXlDy7JLTm/HGa1M8s
Errwto94maqMF36UDGo3WzWRUvpkozM0mTcAPLRObmPtwx03W0W034LN/qqSZMgv
1i0use1qBPHCSI1LtIQ5ozFN9mO0w26hpS/SHrDGDNEEOjG8h0n4JgvTDAgpu59N
CPCcEdOlLI2YsRuxV9Nprp4t1WQ4WMmyhASrEB3Kaymlq8z+u3T0NQOPZSoLu8cX
akk0gzCSjdeuldDXI6fjKQmhsTTDlUnDpPE2AAnTpAmt8lyXsg==
-----END CERTIFICATE-----
---
Server certificate
subject=/CN=www.webkit.org/OU=management:idms.group.764034/O=Apple Inc./ST=California/C=US
issuer=/CN=Apple Corporate Server CA 1/OU=Certification Authority/O=Apple Inc./C=US
---
No client certificate CA names sent
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 4321 bytes and written 326 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES128-GCM-SHA256
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-RSA-AES128-GCM-SHA256
Session-ID: 6DFB4EE5231DECA48336A43352C63001E4FCB31559EA5529D053F52C8CF40A6E
Session-ID-ctx:
Master-Key: 65A7D7C330E15D98560BB835408196F64E0820B261127621246B668CD7E520C6EDAC7C5A9073430196A4D1887A35B880
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - a8 92 04 2b eb d7 33 b1-09 4a 66 ad 48 26 40 94 ...+..3..Jf.H&@.
0010 - 9c 5d 10 56 d0 1e 20 c6-fb fd f6 61 2d 3f 03 22 .].V.. ....a-?."
0020 - 42 5a d1 1d 0f 82 f7 b2-28 aa 46 99 5d ee b0 76 BZ......(.F.]..v
0030 - 5b 33 6d 3f 17 b7 85 b2-7e b0 3b 28 b9 73 78 f3 [3m?....~.;(.sx.
0040 - e6 61 d9 32 d5 4e 9a 13-11 05 f1 0b ea 7e f7 18 .a.2.N.......~..
0050 - 2c cf 4b 6d bd b0 59 1c-00 34 cc d6 08 74 64 21 ,.Km..Y..4...td!
0060 - f0 c6 d2 85 79 6a 45 e5-d0 c3 3b 51 04 6b c0 31 ....yjE...;Q.k.1
0070 - d3 03 18 9f b4 7b d0 ac-b4 70 68 95 9a 2d 8c be .....{...ph..-..
0080 - b5 3c 20 f8 e7 67 2e f8-29 b6 43 5e 0c c2 bd 56 .< ..g..).C^...V
0090 - 86 65 af 43 29 a2 78 a5-69 ea a5 d3 35 f3 4f 9f .e.C).x.i...5.O.
00a0 - b1 55 08 5b 4a d2 b8 40-b5 db be 5d a5 bc 1d 57 .U.[J..@...]...W
00b0 - a5 48 30 b7 33 7b 37 8f-e3 c7 d6 11 98 3e a2 99 .H0.3{7......>..
Start Time: 1552572139
Timeout : 7200 (sec)
Verify return code: 19 (self signed certificate in certificate chain)
---
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment