Skip to content

Instantly share code, notes, and snippets.

@kitchen
Created July 23, 2012 03:19
Show Gist options
  • Save kitchen/3161865 to your computer and use it in GitHub Desktop.
Save kitchen/3161865 to your computer and use it in GitHub Desktop.
certificate info
% openssl s_client -crlf -connect foilhat.org:443 !8215
CONNECTED(00000003)
depth=1 /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=PositiveSSL CA 2
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
0 s:/OU=Domain Control Validated/OU=Provided by New Dream Network, LLC/OU=DreamHost Basic SSL/CN=foilhat.org
i:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=PositiveSSL CA 2
1 s:/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=PositiveSSL CA 2
i:/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFIjCCBAqgAwIBAgIRAMnCapl7g7bNu2XUnccUVPEwDQYJKoZIhvcNAQEFBQAw
czELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxGTAXBgNV
BAMTEFBvc2l0aXZlU1NMIENBIDIwHhcNMTIwNzE3MDAwMDAwWhcNMTMwNzIyMjM1
OTU5WjCBhDEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMSswKQYD
VQQLEyJQcm92aWRlZCBieSBOZXcgRHJlYW0gTmV0d29yaywgTExDMRwwGgYDVQQL
ExNEcmVhbUhvc3QgQmFzaWMgU1NMMRQwEgYDVQQDEwtmb2lsaGF0Lm9yZzCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANq6bcqTKoCJsEMNHFhBZUkyLKpJ
TaqonbXwQl/YkVMjuqE+dmI5A9mIOqam9JqjYChnQq9lhhAzNmY1VgN0HA//SIxm
oi7t0YSzaPBANfnN5xvBhyRA5s+M15cyWBFAA3PlDpnVAXy3WMkuNe4ubAp1LVvJ
oy0SswJpdgm5kmCS0mybEFeVy57o6OXhPgZmV4y27k0fdBVTpkZ35qjjQpP//TIR
GaWR4osZWGHfkpXE9Psfvy+Uc5tBNQAtl+5ei4j6OeeDmW0TVwo8UpALvnEPlt5c
62ktJdLwWRGJ9QkGzv7oT2fxu1LSg1iCofWk21oM0VBeRzkXewd1EbmeD28CAwEA
AaOCAZ0wggGZMB8GA1UdIwQYMBaAFJnkQF9rFF4+Bdnd02NU/GK49wCsMB0GA1Ud
DgQWBBQTGhfehYN/1fCpXXF6a1D1VK+ERjAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0T
AQH/BAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwRgYDVR0gBD8w
PTA7BgsrBgEEAbIxAQICBzAsMCoGCCsGAQUFBwIBFh5odHRwOi8vd3d3LnBvc2l0
aXZlc3NsLmNvbS9DUFMwOwYDVR0fBDQwMjAwoC6gLIYqaHR0cDovL2NybC5jb21v
ZG9jYS5jb20vUG9zaXRpdmVTU0xDQTIuY3JsMGwGCCsGAQUFBwEBBGAwXjA2Bggr
BgEFBQcwAoYqaHR0cDovL2NydC5jb21vZG9jYS5jb20vUG9zaXRpdmVTU0xDQTIu
Y3J0MCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5jb21vZG9jYS5jb20wJwYDVR0R
BCAwHoILZm9pbGhhdC5vcmeCD3d3dy5mb2lsaGF0Lm9yZzANBgkqhkiG9w0BAQUF
AAOCAQEAZvWRCgyK6WD2hoOl50xnA7XhPlNn+fDk0pwwHy9jjxvY25Uf2YJj43uU
MJow+19PATy3O89elGDilHfkAYiOH5zbklWnlwUNy9yLZ3uSXLuCdG2cn0t84hUS
uEYAuylfgrV/iM/8fNCeVL7p/WDXBbWPD15q6KCHpnwUcPTqG92h4TOgvg9VS494
UJCMzn+2o/gT5wSf9lhystkA1KUfeZlOqtC3bfau+TAJmWiPzeDhE34abF6+phUS
KKQgQgpJ4EY8+/Y0tl5zO9PA0cWbPgjIjM5XoGP2OW4m0rCL4l155EgajNkVnAZV
GIwCESboJR9kBk/bAL+ewGtxjT5XEA==
-----END CERTIFICATE-----
subject=/OU=Domain Control Validated/OU=Provided by New Dream Network, LLC/OU=DreamHost Basic SSL/CN=foilhat.org
issuer=/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=PositiveSSL CA 2
---
No client certificate CA names sent
---
SSL handshake has read 3277 bytes and written 328 bytes
---
New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : DHE-RSA-AES256-SHA
Session-ID: 046C9D7A3DF6823A38AD35E6B5DE2AA9A4CAF4C7F31ADC488CC7E95E9EEAD3D7
Session-ID-ctx:
Master-Key: A6F744C33AC6B19C0AAD0B14880E1119D84B62A9E3746E8B82996E3AAE21D3C6939EE8ECBA0D56949D5874E6B686595A
Key-Arg : None
Start Time: 1343013496
Timeout : 300 (sec)
Verify return code: 0 (ok)
± % openssl x509 -text -in foilhat.org.crt !8217
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
c9:c2:6a:99:7b:83:b6:cd:bb:65:d4:9d:c7:14:54:f1
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=PositiveSSL CA 2
Validity
Not Before: Jul 17 00:00:00 2012 GMT
Not After : Jul 22 23:59:59 2013 GMT
Subject: OU=Domain Control Validated, OU=Provided by New Dream Network, LLC, OU=DreamHost Basic SSL, CN=foilhat.org
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public Key: (2048 bit)
Modulus (2048 bit):
00:da:ba:6d:ca:93:2a:80:89:b0:43:0d:1c:58:41:
65:49:32:2c:aa:49:4d:aa:a8:9d:b5:f0:42:5f:d8:
91:53:23:ba:a1:3e:76:62:39:03:d9:88:3a:a6:a6:
f4:9a:a3:60:28:67:42:af:65:86:10:33:36:66:35:
56:03:74:1c:0f:ff:48:8c:66:a2:2e:ed:d1:84:b3:
68:f0:40:35:f9:cd:e7:1b:c1:87:24:40:e6:cf:8c:
d7:97:32:58:11:40:03:73:e5:0e:99:d5:01:7c:b7:
58:c9:2e:35:ee:2e:6c:0a:75:2d:5b:c9:a3:2d:12:
b3:02:69:76:09:b9:92:60:92:d2:6c:9b:10:57:95:
cb:9e:e8:e8:e5:e1:3e:06:66:57:8c:b6:ee:4d:1f:
74:15:53:a6:46:77:e6:a8:e3:42:93:ff:fd:32:11:
19:a5:91:e2:8b:19:58:61:df:92:95:c4:f4:fb:1f:
bf:2f:94:73:9b:41:35:00:2d:97:ee:5e:8b:88:fa:
39:e7:83:99:6d:13:57:0a:3c:52:90:0b:be:71:0f:
96:de:5c:eb:69:2d:25:d2:f0:59:11:89:f5:09:06:
ce:fe:e8:4f:67:f1:bb:52:d2:83:58:82:a1:f5:a4:
db:5a:0c:d1:50:5e:47:39:17:7b:07:75:11:b9:9e:
0f:6f
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
keyid:99:E4:40:5F:6B:14:5E:3E:05:D9:DD:D3:63:54:FC:62:B8:F7:00:AC
X509v3 Subject Key Identifier:
13:1A:17:DE:85:83:7F:D5:F0:A9:5D:71:7A:6B:50:F5:54:AF:84:46
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Certificate Policies:
Policy: 1.3.6.1.4.1.6449.1.2.2.7
CPS: http://www.positivessl.com/CPS
X509v3 CRL Distribution Points:
URI:http://crl.comodoca.com/PositiveSSLCA2.crl
Authority Information Access:
CA Issuers - URI:http://crt.comodoca.com/PositiveSSLCA2.crt
OCSP - URI:http://ocsp.comodoca.com
X509v3 Subject Alternative Name:
DNS:foilhat.org, DNS:www.foilhat.org
Signature Algorithm: sha1WithRSAEncryption
66:f5:91:0a:0c:8a:e9:60:f6:86:83:a5:e7:4c:67:03:b5:e1:
3e:53:67:f9:f0:e4:d2:9c:30:1f:2f:63:8f:1b:d8:db:95:1f:
d9:82:63:e3:7b:94:30:9a:30:fb:5f:4f:01:3c:b7:3b:cf:5e:
94:60:e2:94:77:e4:01:88:8e:1f:9c:db:92:55:a7:97:05:0d:
cb:dc:8b:67:7b:92:5c:bb:82:74:6d:9c:9f:4b:7c:e2:15:12:
b8:46:00:bb:29:5f:82:b5:7f:88:cf:fc:7c:d0:9e:54:be:e9:
fd:60:d7:05:b5:8f:0f:5e:6a:e8:a0:87:a6:7c:14:70:f4:ea:
1b:dd:a1:e1:33:a0:be:0f:55:4b:8f:78:50:90:8c:ce:7f:b6:
a3:f8:13:e7:04:9f:f6:58:72:b2:d9:00:d4:a5:1f:79:99:4e:
aa:d0:b7:6d:f6:ae:f9:30:09:99:68:8f:cd:e0:e1:13:7e:1a:
6c:5e:be:a6:15:12:28:a4:20:42:0a:49:e0:46:3c:fb:f6:34:
b6:5e:73:3b:d3:c0:d1:c5:9b:3e:08:c8:8c:ce:57:a0:63:f6:
39:6e:26:d2:b0:8b:e2:5d:79:e4:48:1a:8c:d9:15:9c:06:55:
18:8c:02:11:26:e8:25:1f:64:06:4f:db:00:bf:9e:c0:6b:71:
8d:3e:57:10
-----BEGIN CERTIFICATE-----
MIIFIjCCBAqgAwIBAgIRAMnCapl7g7bNu2XUnccUVPEwDQYJKoZIhvcNAQEFBQAw
czELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxGTAXBgNV
BAMTEFBvc2l0aXZlU1NMIENBIDIwHhcNMTIwNzE3MDAwMDAwWhcNMTMwNzIyMjM1
OTU5WjCBhDEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMSswKQYD
VQQLEyJQcm92aWRlZCBieSBOZXcgRHJlYW0gTmV0d29yaywgTExDMRwwGgYDVQQL
ExNEcmVhbUhvc3QgQmFzaWMgU1NMMRQwEgYDVQQDEwtmb2lsaGF0Lm9yZzCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANq6bcqTKoCJsEMNHFhBZUkyLKpJ
TaqonbXwQl/YkVMjuqE+dmI5A9mIOqam9JqjYChnQq9lhhAzNmY1VgN0HA//SIxm
oi7t0YSzaPBANfnN5xvBhyRA5s+M15cyWBFAA3PlDpnVAXy3WMkuNe4ubAp1LVvJ
oy0SswJpdgm5kmCS0mybEFeVy57o6OXhPgZmV4y27k0fdBVTpkZ35qjjQpP//TIR
GaWR4osZWGHfkpXE9Psfvy+Uc5tBNQAtl+5ei4j6OeeDmW0TVwo8UpALvnEPlt5c
62ktJdLwWRGJ9QkGzv7oT2fxu1LSg1iCofWk21oM0VBeRzkXewd1EbmeD28CAwEA
AaOCAZ0wggGZMB8GA1UdIwQYMBaAFJnkQF9rFF4+Bdnd02NU/GK49wCsMB0GA1Ud
DgQWBBQTGhfehYN/1fCpXXF6a1D1VK+ERjAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0T
AQH/BAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwRgYDVR0gBD8w
PTA7BgsrBgEEAbIxAQICBzAsMCoGCCsGAQUFBwIBFh5odHRwOi8vd3d3LnBvc2l0
aXZlc3NsLmNvbS9DUFMwOwYDVR0fBDQwMjAwoC6gLIYqaHR0cDovL2NybC5jb21v
ZG9jYS5jb20vUG9zaXRpdmVTU0xDQTIuY3JsMGwGCCsGAQUFBwEBBGAwXjA2Bggr
BgEFBQcwAoYqaHR0cDovL2NydC5jb21vZG9jYS5jb20vUG9zaXRpdmVTU0xDQTIu
Y3J0MCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5jb21vZG9jYS5jb20wJwYDVR0R
BCAwHoILZm9pbGhhdC5vcmeCD3d3dy5mb2lsaGF0Lm9yZzANBgkqhkiG9w0BAQUF
AAOCAQEAZvWRCgyK6WD2hoOl50xnA7XhPlNn+fDk0pwwHy9jjxvY25Uf2YJj43uU
MJow+19PATy3O89elGDilHfkAYiOH5zbklWnlwUNy9yLZ3uSXLuCdG2cn0t84hUS
uEYAuylfgrV/iM/8fNCeVL7p/WDXBbWPD15q6KCHpnwUcPTqG92h4TOgvg9VS494
UJCMzn+2o/gT5wSf9lhystkA1KUfeZlOqtC3bfau+TAJmWiPzeDhE34abF6+phUS
KKQgQgpJ4EY8+/Y0tl5zO9PA0cWbPgjIjM5XoGP2OW4m0rCL4l155EgajNkVnAZV
GIwCESboJR9kBk/bAL+ewGtxjT5XEA==
-----END CERTIFICATE-----
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment