Advertisement
bastischubert

Untitled

May 23rd, 2022
13
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. Looking at the certs presented by the server:
  2.  
  3. ✘ basti@basti-nuc  /etc/pki/ca-trust/extracted/java  openssl s_client -connect jabber.space.net:5223
  4. CONNECTED(00000003)
  5. depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root G2
  6. verify return:1
  7. depth=1 C = US, O = DigiCert Inc, OU = www.digi cert.com, CN = RapidSSL TLS RSA CA G1
  8. verify return:1
  9. depth=0 CN = *.space.net
  10. verify return:1
  11. ---
  12. Certificate chain
  13. 0 s:CN = *.space.net
  14. i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = RapidSSL TLS RSA CA G1
  15. a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
  16. v:NotBefore: May 2 00:00:00 2022 GMT; NotAfter: May 16 23:59:59 2023 GMT
  17. 1 s:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = RapidSSL TLS RSA CA G1
  18. i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root G2
  19. a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
  20. v:NotBefore: Nov 2 12:24:33 2017 GMT; NotAfter: Nov 2 12:24:33 2027 GMT
  21. ---
  22.  
  23. Looking at they keystore for the Certs shows that it's there:
  24. basti@basti-nuc  /etc/pki/ca-trust/extracted/java  /usr/lib/jvm/java-17-openjdk-17.0.3.0.7-1.fc36.x86_64/bin/keytool -list -cacerts -alias digicertglobalrootg2 -v
  25. Keystore-Kennwort eingeben:
  26.  
  27.  
  28. Aliasname: digicertglobalrootg2
  29. Erstellungsdatum: 10.05.2022
  30. Eintragstyp: trustedCertEntry
  31.  
  32. Eigentümer: CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
  33. Aussteller: CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
  34. Seriennummer: 33af1e6a711a9a0bb2864b11d09fae5
  35. Gültig von: Thu Aug 01 14:00:00 CEST 2013 bis: Fri Jan 15 13:00:00 CET 2038
  36. Zertifikatsfingerprints:
  37. SHA1: DF:3C:24:F9:BF:D6:66:76:1B:26:80:73:FE:06:D1:CC:8D:4F:82:A4
  38. SHA256: CB:3C:CB:B7:60:31:E5:E0:13:8F:8D:D3:9A:23:F9:DE:47:FF:C3:5E:43:C1:14:4C:EA:27:D4:6A:5A:B1:CB:5F
  39. Signaturalgorithmusname: SHA256withRSA
  40. Public Key-Algorithmus von Subject: 2048-Bit-RSA-Schlüssel
  41. Version: 3
  42.  
  43. Erweiterungen:
  44.  
  45. #1: ObjectId: 2.5.29.19 Criticality=true
  46. BasicConstraints:[
  47. CA:true
  48. PathLen: no limit
  49. ]
  50.  
  51. #2: ObjectId: 2.5.29.15 Criticality=true
  52. KeyUsage [
  53. DigitalSignature
  54. Key_CertSign
  55. Crl_Sign
  56. ]
  57.  
  58. #3: ObjectId: 2.5.29.14 Criticality=false
  59. SubjectKeyIdentifier [
  60. KeyIdentifier [
  61. 0000: 4E 22 54 20 18 95 E6 E3 6E E6 0F FA FA B9 12 ED N"T ....n.......
  62. 0010: 06 17 8F 39 ...9
  63. ]
  64. ]
  65.  
Advertisement
RAW Paste Data Copied
Advertisement