Skip to content

Instantly share code, notes, and snippets.

@lidaobing
Created June 4, 2013 04:52
Show Gist options
  • Save lidaobing/5703663 to your computer and use it in GitHub Desktop.
Save lidaobing/5703663 to your computer and use it in GitHub Desktop.
$ ping mail.qq.com
PING mail.qq.com (14.17.19.167): 56 data bytes
64 bytes from 14.17.19.167: icmp_seq=0 ttl=51 time=34.707 ms
64 bytes from 14.17.19.167: icmp_seq=1 ttl=51 time=53.788 ms
^C
--- mail.qq.com ping statistics ---
2 packets transmitted, 2 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 34.707/44.248/53.788/9.540 ms
$ echo | openssl s_client -connect mail.qq.com:443 2>&1
CONNECTED(00000003)
depth=0 /serialNumber=HKsF4cYQQE8ArVyVLzd9WTovoOK/Vt9h/C=CN/ST=Guangdong/L=Shenzhen/O=Shenzhen Tencent Computer Systems Company Limited/OU=R&D/CN=mail.qq.com
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 /serialNumber=HKsF4cYQQE8ArVyVLzd9WTovoOK/Vt9h/C=CN/ST=Guangdong/L=Shenzhen/O=Shenzhen Tencent Computer Systems Company Limited/OU=R&D/CN=mail.qq.com
verify error:num=27:certificate not trusted
verify return:1
depth=0 /serialNumber=HKsF4cYQQE8ArVyVLzd9WTovoOK/Vt9h/C=CN/ST=Guangdong/L=Shenzhen/O=Shenzhen Tencent Computer Systems Company Limited/OU=R&D/CN=mail.qq.com
verify error:num=21:unable to verify the first certificate
verify return:1
---
Certificate chain
0 s:/serialNumber=HKsF4cYQQE8ArVyVLzd9WTovoOK/Vt9h/C=CN/ST=Guangdong/L=Shenzhen/O=Shenzhen Tencent Computer Systems Company Limited/OU=R&D/CN=mail.qq.com
i:/C=US/ST=VeriSign, Inc./L=VeriSign Trust Network/O=Terms of use at https://www.verisign.com/rpa/OU=Terms of use at https://www.verisign.com/rpa/CN=VeriSign Class 1 Extended Validation CA
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIEizCCA/SgAwIBAgIDAe3lMA0GCSqGSIb3DQEBBAUAMIHnMQswCQYDVQQGEwJV
UzEXMBUGA1UECBMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAcTFlZlcmlTaWduIFRy
dXN0IE5ldHdvcmsxNTAzBgNVBAoTLFRlcm1zIG9mIHVzZSBhdCBodHRwczovL3d3
dy52ZXJpc2lnbi5jb20vcnBhMTUwMwYDVQQLEyxUZXJtcyBvZiB1c2UgYXQgaHR0
cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYTEwMC4GA1UEAxMnVmVyaVNpZ24gQ2xh
c3MgMSBFeHRlbmRlZCBWYWxpZGF0aW9uIENBMB4XDTEzMDEwODAxMTUxN1oXDTE0
MDMyOTEwMTcyMFowgb8xKTAnBgNVBAUTIEhLc0Y0Y1lRUUU4QXJWeVZMemQ5V1Rv
dm9PSy9WdDloMQswCQYDVQQGEwJDTjESMBAGA1UECBMJR3Vhbmdkb25nMREwDwYD
VQQHEwhTaGVuemhlbjE6MDgGA1UEChMxU2hlbnpoZW4gVGVuY2VudCBDb21wdXRl
ciBTeXN0ZW1zIENvbXBhbnkgTGltaXRlZDEMMAoGA1UECwwDUiZEMRQwEgYDVQQD
EwttYWlsLnFxLmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAwKdt/R9q
RgzyKuoIF1OCXsRYZjsv0ZnP0qQX0BaqQqqt6UBUiZnqvH6GhkiWsWyefIExU+Ap
F6ehpm4oU9s+Hx40jTeDP9PM7q+QP1LFUr4qMDPQN1yGh0Lbblpg7UrTIfBJ6ONa
CihfwLP8xlLm8vQnr2GDKbL7WviSQlC1qWECAwEAAaOCAWkwggFlMIIBYQYDVR0R
BIIBWDCCAVSCD3Jlcy5tYWlsLnFxLmNvbYIUc3RvY2t3ZWIubWFpbC5xcS5jb22C
EnFxc2hvdy5tYWlsLnFxLmNvbYISd2VicXEyLm1haWwucXEuY29tghJ3ZWJxcTEu
bWFpbC5xcS5jb22CDnh5Lm1haWwucXEuY29tghNodGFvdGFvLm1haWwucXEuY29t
ghRwdGxvZ2luMi5tYWlsLnFxLmNvbYIOZHIubWFpbC5xcS5jb22CEnJlc2Nkbi5t
YWlsLnFxLmNvbYIQYmFrMS5tYWlsLnFxLmNvbYIQYmFrMi5tYWlsLnFxLmNvbYIQ
YmFrMy5tYWlsLnFxLmNvbYIOd3MubWFpbC5xcS5jb22CDndwLm1haWwucXEuY29t
gg1yZXMud3gucXEuY29tgg5ybC5tYWlsLnFxLmNvbYIOZW4ubWFpbC5xcS5jb22C
C21haWwucXEuY29tMA0GCSqGSIb3DQEBBAUAA4GBAC8wCyE/wAvjVT4KDl5fNAHJ
utmERrAHrAnt73kFPKEuclqOLiRSBLazfcjHHJ7wf5Zt92CUjjKx8lHdEmASX8Na
ThOO/knYojdueiABvGXFYz03pTTb+fnHx8f1undGEEZV0rBmaYmziW3RLUHk+ajC
4gFuBA8Tvz+pNpguZz9G
-----END CERTIFICATE-----
subject=/serialNumber=HKsF4cYQQE8ArVyVLzd9WTovoOK/Vt9h/C=CN/ST=Guangdong/L=Shenzhen/O=Shenzhen Tencent Computer Systems Company Limited/OU=R&D/CN=mail.qq.com
issuer=/C=US/ST=VeriSign, Inc./L=VeriSign Trust Network/O=Terms of use at https://www.verisign.com/rpa/OU=Terms of use at https://www.verisign.com/rpa/CN=VeriSign Class 1 Extended Validation CA
---
No client certificate CA names sent
---
SSL handshake has read 1329 bytes and written 328 bytes
---
New, TLSv1/SSLv3, Cipher is AES256-SHA
Server public key is 1024 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : AES256-SHA
Session-ID: 21E700A1A3AAF577647EB7045F70975FD80D680C5A5C451ECB957EE9A719336B
Session-ID-ctx:
Master-Key: 8F08BB3A7D56D3F02FD866A4124133586886920B546C984AB8BF36B27AD99D365E66B48C489F11DD829932CB74E24FFD
Key-Arg : None
Start Time: 1370321458
Timeout : 300 (sec)
Verify return code: 21 (unable to verify the first certificate)
---
DONE
@deepentarget
Copy link

I met the same question, how to solve it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment