!openssl version
OpenSSL 1.1.1w 11 Sep 2023
!echo QUIT | openssl s_client -connect www.upjs.sk:443
CONNECTED(000001AC) --- Certificate chain 0 s:C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk i:C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 1 s:C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 i:C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority 2 s:C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority i:C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services 3 s:C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services i:C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services --- Server certificate -----BEGIN CERTIFICATE----- MIIIdzCCBl+gAwIBAgIQBteC4zZRCAr8uA4hnNdOJjANBgkqhkiG9w0BAQwFADBE MQswCQYDVQQGEwJOTDEZMBcGA1UEChMQR0VBTlQgVmVyZW5pZ2luZzEaMBgGA1UE AxMRR0VBTlQgT1YgUlNBIENBIDQwHhcNMjMwMjA5MDAwMDAwWhcNMjQwMjA5MjM1 OTU5WjB2MQswCQYDVQQGEwJTSzEXMBUGA1UECAwOS2/FoWlja8O9IGtyYWoxODA2 BgNVBAoML1VuaXZlcnppdGEgUGF2bGEgSm96ZWZhIMWgYWbDoXJpa2EgdiBLb8Wh aWNpYWNoMRQwEgYDVQQDEwt3d3cudXBqcy5zazCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBAMYsLDB0+U0F7F6Z8ZvYeisdUgrCCWDo/7YLZM72Cmg2clZr w+aNLcMQ+wRXNlNjWGGASJvbeJnNnK6pOrXzUWQ1fs20TM3KDIJgxJqMkAl9ydg0 UFqj/iQCTfslG2UQe9j7pZ9J/DCCL62XnXrTKGkLU2UCwTW/e895MBC5xxiRO+V5 nG/E5Btqonv6+ZI9DCFLgypKym0TjHhh0fHKWu07HTg6DomaQm4FZ2ElF9ImunmS 9mUyomdq1OuiEPpWUlDILklq9UmXGHv+hWwk5rN8531Xy9n0XiXSfaXkEl8FLw3n RuB2LxGAZNtZju7aKNammAVySzNotkbYN/hMKb0CAwEAAaOCBDEwggQtMB8GA1Ud IwQYMBaAFG8dNUkQbDL6WaCevIroH5W+cXoMMB0GA1UdDgQWBBR99RJSGaRT/+q8 AXuKKXs+bVYFxjAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNVHSUE FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwSQYDVR0gBEIwQDA0BgsrBgEEAbIxAQIC TzAlMCMGCCsGAQUFBwIBFhdodHRwczovL3NlY3RpZ28uY29tL0NQUzAIBgZngQwB AgIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL0dFQU5ULmNybC5zZWN0aWdvLmNv bS9HRUFOVE9WUlNBQ0E0LmNybDB1BggrBgEFBQcBAQRpMGcwOgYIKwYBBQUHMAKG Lmh0dHA6Ly9HRUFOVC5jcnQuc2VjdGlnby5jb20vR0VBTlRPVlJTQUNBNC5jcnQw KQYIKwYBBQUHMAGGHWh0dHA6Ly9HRUFOVC5vY3NwLnNlY3RpZ28uY29tMIIBfQYK KwYBBAHWeQIEAgSCAW0EggFpAWcAdQB2/4g/Crb7lVHCYcz1h7o0tKTNuyncaEIK n+ZnTFo6dAAAAYYziLM4AAAEAwBGMEQCIGwMr8UliK32+hWPNQRlxAnPWm9PomdF LNgu9czAJiDAAiB3R/61ay209FIveBXlHNdAnjdcAmrhM1c2cnVKLb1N9QB2ANq2 v2s/tbYin5vCu1xr6HCRcWy7UYSFNL2kPTBI1/urAAABhjOIswUAAAQDAEcwRQIh ALJVMYh+YG1pX8ytUemJJH5Bzdv55J/kViiykZy7j+MZAiBKd9GtXsR6o2hpbHq4 c9i2EhGxsGcw8GYxs252hgLyywB2AO7N0GTV2xrOxVy3nbTNE6Iyh0Z8vOzew1FI WUZxH7WbAAABhjOIstkAAAQDAEcwRQIhAONouSzPK37CdGYU3+30CwMOFQoW192R Q4O4wW7kA75kAiBSH+SGmXp9zkzVCy7eoleQCP6JS0Cju5Yh8lyFGYC6KTCCASgG A1UdEQSCAR8wggEbggt3d3cudXBqcy5za4IKZmYudXBqcy5za4IKbGYudXBqcy5z a4IPbGlicmFyeS51cGpzLnNrgg1tZWRpYy51cGpzLnNrggpwZi51cGpzLnNrgg1w cmF2by51cGpzLnNrgg9zY2llbmNlLnVwanMuc2uCB3VwanMuc2uCDnd3dy5mZi51 cGpzLnNrgg93d3cuZnZzLnVwanMuc2uCDnd3dy5sZi51cGpzLnNrghN3d3cubGli cmFyeS51cGpzLnNrghF3d3cubWVkaWMudXBqcy5za4IOd3d3LnBmLnVwanMuc2uC EXd3dy5wcmF2by51cGpzLnNrghN3d3cuc2NpZW5jZS51cGpzLnNrgg53d3cudWsu dXBqcy5zazANBgkqhkiG9w0BAQwFAAOCAgEAHGvD4btx+r6a7/vLZLyktwY6IbEj hIYAwsjQXmmmclaNOYZ90mE7F6eQBIFPrDMwDly4AZUoE6DjTb7RJFp6oI1ZZCy7 JfWKOfK3mFXOKftO5269mAosjLhecsbxL4GDc7WPjgg5Tres2c2hhZDpuz/ydzNt DNNV088s5Miz0jFN6LPfA538HAcixng3e1uHqxz9KLh46Hci1LRGMf48K4Kq3Uki ywIgf58ObM4DrHymGxt6ioLk0NaYyyjmBYjMkuJPUJ0IFwRuN0ymLQTE4NKu8/iT je8QOVEEeXyDm2WfFi0g8NajXBZMRChfdAY9DvLZ+VGiQNR4+HTCkD4O+2WCytm7 tTnea+5K8K/SDuvcdbtZY4mqNtgs+tWKUXGH7J2f73uiYByQiBY7cFrjJs13iBGq JStBdqcC6hE0KLN+m9fNdhNm1aqiZ1jCW5hVAAUNoUFsh0VaYgm+hCDfyEVHs47g AyHFjPgMXkAoiI/eQ8nDeVERWhJhnEMXJnafe0bya+YT305NNr7cxZJpLLvyfeFG 9amVCk3E/7Fy5NpBcPUFrOu38CzdeHWeS20hv2qJomJ6GyD6YRviUCjuIiYOrYG1 bbGMiNNdlV8xUEn+4yHjwBBKjOrmEuhhyM4wZuvYyPidv5HVrQqJQXf8AvcJ2H1+ Nm33SDD2wRo6sqk= -----END CERTIFICATE----- subject=C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk issuer=C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 7006 bytes and written 393 bytes Verification error: self signed certificate in certificate chain --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 19 (self signed certificate in certificate chain) --- --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: 0F2B6D22100D7072A9482A8877C424B4E874F21A2E4ED2BCBC993D4FE780451F Session-ID-ctx: Resumption PSK: 15BF146EB833CEEA53B438DFAD8942D7DDD22B5CC8AA3E7C4929687AE1996BC6D4FECD3DA2B034879639854B8836DF3E PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 300 (seconds) TLS session ticket: 0000 - 17 3a 38 eb 2e 3d 61 57-db 13 13 38 40 7c 6d c9 .:8..=aW...8@|m. 0010 - 73 fb 46 ce b0 5a d2 5e-91 6c d1 9e bb 48 7c 1d s.F..Z.^.l...H|. 0020 - fc 96 4d d5 cb 40 c2 61-7f 98 92 62 25 a0 05 b3 ..M..@.a...b%... 0030 - b0 b7 ce 76 83 86 76 e9-6e b2 97 61 ed 7f 2f c8 ...v..v.n..a../. 0040 - d2 04 4c 78 f0 7a 17 43-c7 0f 04 f4 0b be 34 23 ..Lx.z.C......4# 0050 - 63 04 6f 01 a4 94 89 e6-74 4a ef 25 57 32 c1 13 c.o.....tJ.%W2.. 0060 - 94 9d d1 b1 2b 0e 27 c2-a7 09 6e 7b 1e 1d d9 b8 ....+.'...n{.... 0070 - 71 16 6e 96 49 92 1c 71-49 cd 02 1e fc b9 d6 e7 q.n.I..qI....... 0080 - 6d b3 5f 4f 44 a5 bf 72-d3 25 cb 5a 59 3a 34 2a m._OD..r.%.ZY:4* 0090 - 3f 73 0a 75 ff 7e e1 b9-9c 2f cc fd fa df 98 59 ?s.u.~.../.....Y 00a0 - 63 44 1d d4 6d db 86 1d-5a 23 f4 21 05 7c e2 cf cD..m...Z#.!.|.. 00b0 - bc 0d 8c f2 71 82 15 f0-c0 16 57 b0 c1 cf 06 44 ....q.....W....D 00c0 - 30 83 c6 ef 82 9e b2 cf-2e f4 7c bd d9 ea 69 01 0.........|...i. 00d0 - 1c 20 6e 2d ec 8e 45 04-9f bd d0 b0 bb 37 07 1b . n-..E......7.. 00e0 - c8 02 ed 22 18 4c 05 7d-4a 71 2a d4 8b 30 71 a1 ...".L.}Jq*..0q. 00f0 - f4 eb 69 90 4a 97 08 ad-74 ed 4b af 66 cf 1c 85 ..i.J...t.K.f... Start Time: 1702551086 Timeout : 7200 (sec) Verify return code: 19 (self signed certificate in certificate chain) Extended master secret: no Max Early Data: 0 --- read R BLOCK --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: 8E3A583EC6C14A4BB10962BBC46FC86017ECC3B602D5DBF540BCFC78E11E9D5F Session-ID-ctx: Resumption PSK: 2D70106B94B70512AF3D0B995CDAB63451F86E8E91964D774F1461D7B113955860E4A56B6C72B779CA7C41229B6F7ABA PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 300 (seconds) TLS session ticket: 0000 - 17 3a 38 eb 2e 3d 61 57-db 13 13 38 40 7c 6d c9 .:8..=aW...8@|m. 0010 - 71 00 9b c7 5e 15 10 c6-8f d2 34 84 79 21 ff 2c q...^.....4.y!., 0020 - 35 5d 58 6d 19 a5 0c 9f-13 70 6f 82 2c 00 28 bd 5]Xm.....po.,.(. 0030 - b3 82 61 7e 5b cb 3a a0-3d 77 65 d7 3b b5 14 17 ..a~[.:.=we.;... 0040 - 44 6e 98 74 a7 72 9d 7b-ba b6 7b 1f db 5e 2b 89 Dn.t.r.{..{..^+. 0050 - 20 78 4f 50 af cc b1 f4-48 bb 9c 24 f8 1d 02 17 xOP....H..$.... 0060 - 5b 05 3d 6b 4c 79 78 94-21 84 fd df e0 54 69 dd [.=kLyx.!....Ti. 0070 - 22 8e 3f c4 55 d2 52 16-51 e2 c9 73 71 e6 91 ef ".?.U.R.Q..sq... 0080 - d4 ff 44 e6 bc d6 d1 4d-48 26 02 95 ef c8 24 ca ..D....MH&....$. 0090 - 25 e5 14 36 a3 08 ee a7-fb 6c 86 12 b3 da 39 b6 %..6.....l....9. 00a0 - 31 65 08 90 6a e7 56 42-05 17 a2 af c4 9e 63 b3 1e..j.VB......c. 00b0 - 86 4f f4 a7 58 70 88 13-23 f0 c9 ed d2 05 e5 db .O..Xp..#....... 00c0 - b7 13 80 31 1b ac 1b ac-c9 35 8c d9 5f cf 78 55 ...1.....5.._.xU 00d0 - fc ea 4e a8 10 35 00 b4-5b 5c 95 5d 47 00 82 ca ..N..5..[\.]G... 00e0 - b2 f7 ab 93 c5 e8 b5 85-78 35 93 8e 23 0d 48 dc ........x5..#.H. 00f0 - b5 c8 3c 03 10 3a f8 e7-a7 b4 98 2b ed 52 c0 85 ..<..:.....+.R.. Start Time: 1702551086 Timeout : 7200 (sec) Verify return code: 19 (self signed certificate in certificate chain) Extended master secret: no Max Early Data: 0 --- read R BLOCK
depth=3 C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services verify error:num=19:self signed certificate in certificate chain verify return:1 depth=3 C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services verify return:1 depth=2 C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority verify return:1 depth=1 C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 verify return:1 depth=0 C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk verify return:1 DONE
!echo QUIT | openssl s_client -status -showcerts -connect www.upjs.sk:443
CONNECTED(000001A4) OCSP response: no response sent --- Certificate chain 0 s:C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk i:C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 -----BEGIN CERTIFICATE----- MIIIdzCCBl+gAwIBAgIQBteC4zZRCAr8uA4hnNdOJjANBgkqhkiG9w0BAQwFADBE MQswCQYDVQQGEwJOTDEZMBcGA1UEChMQR0VBTlQgVmVyZW5pZ2luZzEaMBgGA1UE AxMRR0VBTlQgT1YgUlNBIENBIDQwHhcNMjMwMjA5MDAwMDAwWhcNMjQwMjA5MjM1 OTU5WjB2MQswCQYDVQQGEwJTSzEXMBUGA1UECAwOS2/FoWlja8O9IGtyYWoxODA2 BgNVBAoML1VuaXZlcnppdGEgUGF2bGEgSm96ZWZhIMWgYWbDoXJpa2EgdiBLb8Wh aWNpYWNoMRQwEgYDVQQDEwt3d3cudXBqcy5zazCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBAMYsLDB0+U0F7F6Z8ZvYeisdUgrCCWDo/7YLZM72Cmg2clZr w+aNLcMQ+wRXNlNjWGGASJvbeJnNnK6pOrXzUWQ1fs20TM3KDIJgxJqMkAl9ydg0 UFqj/iQCTfslG2UQe9j7pZ9J/DCCL62XnXrTKGkLU2UCwTW/e895MBC5xxiRO+V5 nG/E5Btqonv6+ZI9DCFLgypKym0TjHhh0fHKWu07HTg6DomaQm4FZ2ElF9ImunmS 9mUyomdq1OuiEPpWUlDILklq9UmXGHv+hWwk5rN8531Xy9n0XiXSfaXkEl8FLw3n RuB2LxGAZNtZju7aKNammAVySzNotkbYN/hMKb0CAwEAAaOCBDEwggQtMB8GA1Ud IwQYMBaAFG8dNUkQbDL6WaCevIroH5W+cXoMMB0GA1UdDgQWBBR99RJSGaRT/+q8 AXuKKXs+bVYFxjAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNVHSUE FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwSQYDVR0gBEIwQDA0BgsrBgEEAbIxAQIC TzAlMCMGCCsGAQUFBwIBFhdodHRwczovL3NlY3RpZ28uY29tL0NQUzAIBgZngQwB AgIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL0dFQU5ULmNybC5zZWN0aWdvLmNv bS9HRUFOVE9WUlNBQ0E0LmNybDB1BggrBgEFBQcBAQRpMGcwOgYIKwYBBQUHMAKG Lmh0dHA6Ly9HRUFOVC5jcnQuc2VjdGlnby5jb20vR0VBTlRPVlJTQUNBNC5jcnQw KQYIKwYBBQUHMAGGHWh0dHA6Ly9HRUFOVC5vY3NwLnNlY3RpZ28uY29tMIIBfQYK KwYBBAHWeQIEAgSCAW0EggFpAWcAdQB2/4g/Crb7lVHCYcz1h7o0tKTNuyncaEIK n+ZnTFo6dAAAAYYziLM4AAAEAwBGMEQCIGwMr8UliK32+hWPNQRlxAnPWm9PomdF LNgu9czAJiDAAiB3R/61ay209FIveBXlHNdAnjdcAmrhM1c2cnVKLb1N9QB2ANq2 v2s/tbYin5vCu1xr6HCRcWy7UYSFNL2kPTBI1/urAAABhjOIswUAAAQDAEcwRQIh ALJVMYh+YG1pX8ytUemJJH5Bzdv55J/kViiykZy7j+MZAiBKd9GtXsR6o2hpbHq4 c9i2EhGxsGcw8GYxs252hgLyywB2AO7N0GTV2xrOxVy3nbTNE6Iyh0Z8vOzew1FI WUZxH7WbAAABhjOIstkAAAQDAEcwRQIhAONouSzPK37CdGYU3+30CwMOFQoW192R Q4O4wW7kA75kAiBSH+SGmXp9zkzVCy7eoleQCP6JS0Cju5Yh8lyFGYC6KTCCASgG A1UdEQSCAR8wggEbggt3d3cudXBqcy5za4IKZmYudXBqcy5za4IKbGYudXBqcy5z a4IPbGlicmFyeS51cGpzLnNrgg1tZWRpYy51cGpzLnNrggpwZi51cGpzLnNrgg1w cmF2by51cGpzLnNrgg9zY2llbmNlLnVwanMuc2uCB3VwanMuc2uCDnd3dy5mZi51 cGpzLnNrgg93d3cuZnZzLnVwanMuc2uCDnd3dy5sZi51cGpzLnNrghN3d3cubGli cmFyeS51cGpzLnNrghF3d3cubWVkaWMudXBqcy5za4IOd3d3LnBmLnVwanMuc2uC EXd3dy5wcmF2by51cGpzLnNrghN3d3cuc2NpZW5jZS51cGpzLnNrgg53d3cudWsu dXBqcy5zazANBgkqhkiG9w0BAQwFAAOCAgEAHGvD4btx+r6a7/vLZLyktwY6IbEj hIYAwsjQXmmmclaNOYZ90mE7F6eQBIFPrDMwDly4AZUoE6DjTb7RJFp6oI1ZZCy7 JfWKOfK3mFXOKftO5269mAosjLhecsbxL4GDc7WPjgg5Tres2c2hhZDpuz/ydzNt DNNV088s5Miz0jFN6LPfA538HAcixng3e1uHqxz9KLh46Hci1LRGMf48K4Kq3Uki ywIgf58ObM4DrHymGxt6ioLk0NaYyyjmBYjMkuJPUJ0IFwRuN0ymLQTE4NKu8/iT je8QOVEEeXyDm2WfFi0g8NajXBZMRChfdAY9DvLZ+VGiQNR4+HTCkD4O+2WCytm7 tTnea+5K8K/SDuvcdbtZY4mqNtgs+tWKUXGH7J2f73uiYByQiBY7cFrjJs13iBGq JStBdqcC6hE0KLN+m9fNdhNm1aqiZ1jCW5hVAAUNoUFsh0VaYgm+hCDfyEVHs47g AyHFjPgMXkAoiI/eQ8nDeVERWhJhnEMXJnafe0bya+YT305NNr7cxZJpLLvyfeFG 9amVCk3E/7Fy5NpBcPUFrOu38CzdeHWeS20hv2qJomJ6GyD6YRviUCjuIiYOrYG1 bbGMiNNdlV8xUEn+4yHjwBBKjOrmEuhhyM4wZuvYyPidv5HVrQqJQXf8AvcJ2H1+ Nm33SDD2wRo6sqk= -----END CERTIFICATE----- 1 s:C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 i:C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority -----BEGIN CERTIFICATE----- MIIG5TCCBM2gAwIBAgIRANpDvROb0li7TdYcrMTz2+AwDQYJKoZIhvcNAQEMBQAw gYgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpOZXcgSmVyc2V5MRQwEgYDVQQHEwtK ZXJzZXkgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMS4wLAYD VQQDEyVVU0VSVHJ1c3QgUlNBIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTIw MDIxODAwMDAwMFoXDTMzMDUwMTIzNTk1OVowRDELMAkGA1UEBhMCTkwxGTAXBgNV BAoTEEdFQU5UIFZlcmVuaWdpbmcxGjAYBgNVBAMTEUdFQU5UIE9WIFJTQSBDQSA0 MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEApYhi1aEiPsg9ZKRMAw9Q r8Mthsr6R20VSfFeh7TgwtLQi6RSRLOh4or4EMG/1th8lijv7xnBMVZkTysFiPmT PiLOfvz+QwO1NwjvgY+Jrs7fSoVA/TQkXzcxu4Tl3WHi+qJmKLJVu/JOuHud6mOp LWkIbhODSzOxANJ24IGPx9h4OXDyy6/342eE6UPXCtJ8AzeumTG6Dfv5KVx24lCF TGUzHUB+j+g0lSKg/Sf1OzgCajJV9enmZ/84ydh48wPp6vbWf1H0O3Rd3LhpMSVn TqFTLKZSbQeLcx/l9DOKZfBCC9ghWxsgTqW9gQ7v3T3aIfSaVC9rnwVxO0VjmDdP FNbdoxnh0zYwf45nV1QQgpRwZJ93yWedhp4ch1a6Ajwqs+wv4mZzmBSjovtV0mKw d+CQbSToalEUP4QeJq4Udz5WNmNMI4OYP6cgrnlJ50aa0DZPlJqrKQPGL69KQQz1 2WgxvhCuVU70y6ZWAPopBa1ykbsttpLxADZre5cH573lIuLHdjx7NjpYIXRx2+QJ URnX2qx37eZIxYXz8ggM+wXH6RDbU3V2o5DP67hXPHSAbA+p0orjAocpk2osxHKo NSE3LCjNx8WVdxnXvuQ28tKdaK69knfm3bB7xpdfsNNTPH9ElcjscWZxpeZ5Iij8 lyrCG1z0vSWtSBsgSnUyG/sCAwEAAaOCAYswggGHMB8GA1UdIwQYMBaAFFN5v1qq K0rPVIDh2JvAnfKyA2bLMB0GA1UdDgQWBBRvHTVJEGwy+lmgnryK6B+VvnF6DDAO BgNVHQ8BAf8EBAMCAYYwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHSUEFjAUBggr BgEFBQcDAQYIKwYBBQUHAwIwOAYDVR0gBDEwLzAtBgRVHSAAMCUwIwYIKwYBBQUH AgEWF2h0dHBzOi8vc2VjdGlnby5jb20vQ1BTMFAGA1UdHwRJMEcwRaBDoEGGP2h0 dHA6Ly9jcmwudXNlcnRydXN0LmNvbS9VU0VSVHJ1c3RSU0FDZXJ0aWZpY2F0aW9u QXV0aG9yaXR5LmNybDB2BggrBgEFBQcBAQRqMGgwPwYIKwYBBQUHMAKGM2h0dHA6 Ly9jcnQudXNlcnRydXN0LmNvbS9VU0VSVHJ1c3RSU0FBZGRUcnVzdENBLmNydDAl BggrBgEFBQcwAYYZaHR0cDovL29jc3AudXNlcnRydXN0LmNvbTANBgkqhkiG9w0B AQwFAAOCAgEAUtlC3e0xj/1BMfPhdQhUXeLjb0xp8UE28kzWE5xDzGKbfGgnrT2R lw5gLIx+/cNVrad//+MrpTppMlxq59AsXYZW3xRasrvkjGfNR3vt/1RAl8iI31lG hIg6dfIX5N4esLkrQeN8HiyHKH6khm4966IkVVtnxz5CgUPqEYn4eQ+4eeESrWBh AqXaiv7HRvpsdwLYekAhnrlGpioZ/CJIT2PTTxf+GHM6cuUnNqdUzfvrQgA8kt1/ ASXx2od/M+c8nlJqrGz29lrJveJOSEMX0c/ts02WhsfMhkYa6XujUZLmvR1Eq08r 48/EZ4l+t5L4wt0DV8VaPbsEBF1EOFpz/YS2H6mSwcFaNJbnYqqJHIvm3PLJHkFm EoLXRVrQXdCT+3wgBfgU6heCV5CYBz/YkrdWES7tiiT8sVUDqXmVlTsbiRNiyLs2 bmEWWFUl76jViIJog5fongEqN3jLIGTG/mXrJT1UyymIcobnIGrbwwRVz/mpFQo0 vBYIi1k2ThVh0Dx88BbF9YiP84dd8Fkn5wbE6FxXYJ287qfRTgmhePecPc73Yrzt apdRcsKVGkOpaTIJP/l+lAHRLZxk/dUtyN95G++bOSQqnOCpVPabUGl2E/OEyFrp Ipwgu2L/WJclvd6g+ZA/iWkLSMcpnFb+uX6QBqvD6+RNxul1FaB5iHY= -----END CERTIFICATE----- 2 s:C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority i:C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services -----BEGIN CERTIFICATE----- MIIFgTCCBGmgAwIBAgIQOXJEOvkit1HX02wQ3TE1lTANBgkqhkiG9w0BAQwFADB7 MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYD VQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEhMB8GA1UE AwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTE5MDMxMjAwMDAwMFoXDTI4 MTIzMTIzNTk1OVowgYgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpOZXcgSmVyc2V5 MRQwEgYDVQQHEwtKZXJzZXkgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBO ZXR3b3JrMS4wLAYDVQQDEyVVU0VSVHJ1c3QgUlNBIENlcnRpZmljYXRpb24gQXV0 aG9yaXR5MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAgBJlFzYOw9sI s9CsVw127c0n00ytUINh4qogTQktZAnczomfzD2p7PbPwdzx07HWezcoEStH2jnG vDoZtF+mvX2do2NCtnbyqTsrkfjib9DsFiCQCT7i6HTJGLSR1GJk23+jBvGIGGqQ Ijy8/hPwhxR79uQfjtTkUcYRZ0YIUcuGFFQ/vDP+fmyc/xadGL1RjjWmp2bIcmfb IWax1Jt4A8BQOujM8Ny8nkz+rwWWNR9XWrf/zvk9tyy29lTdyOcSOk2uTIq3XJq0 tyA9yn8iNK5+O2hmAUTnAU5GU5szYPeUvlM3kHND8zLDU+/bqv50TmnHa4xgk97E xwzf4TKuzJM7UXiVZ4vuPVb+DNBpDxsP8yUmazNt925H+nND5X4OpWaxKXwyhGNV icQNwZNUMBkTrNN9N6frXTpsNVzbQdcS2qlJC9/YgIoJk2KOtWbPJYjNhLixP6Q5 D9kCnusSTJV882sFqV4Wg8y4Z+LoE53MW4LTTLPtW//e5XOsIzstAL81VXQJSdhJ WBp/kjbmUZIO8yZ9HE0XvMnsQybQv0FfQKlERPSZ51eHnlAfV1SoPv10Yy+xUGUJ 5lhCLkMaTLTwJUdZ+gQek9QmRkpQgbLevni3/GcV4clXhB4PY9bpYrrWX1Uu6lzG KAgEJTm4Diup8kyXHAc/DVL17e8vgg8CAwEAAaOB8jCB7zAfBgNVHSMEGDAWgBSg EQojPpbxB+zirynvgqV/0DCktDAdBgNVHQ4EFgQUU3m/WqorSs9UgOHYm8Cd8rID ZsswDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wEQYDVR0gBAowCDAG BgRVHSAAMEMGA1UdHwQ8MDowOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29t L0FBQUNlcnRpZmljYXRlU2VydmljZXMuY3JsMDQGCCsGAQUFBwEBBCgwJjAkBggr BgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2RvY2EuY29tMA0GCSqGSIb3DQEBDAUA A4IBAQAYh1HcdCE9nIrgJ7cz0C7M7PDmy14R3iJvm3WOnnL+5Nb+qh+cli3vA0p+ rvSNb3I8QzvAP+u431yqqcau8vzY7qN7Q/aGNnwU4M309z/+3ri0ivCRlv79Q2R+ /czSAaF9ffgZGclCKxO/WIu6pKJmBHaIkU4MiRTOok3JMrO66BQavHHxW/BBC5gA CiIDEOUMsfnNkjcZ7Tvx5Dq2+UUTJnWvu6rvP3t3O9LEApE9GQDTF1w52z97GA1F zZOFli9d31kWTz9RvdVFGD/tSo7oBmF0Ixa1DVBzJ0RHfxBdiSprhTEUxOipakyA vGp4z7h/jnZymQyd/teRCBaho1+V -----END CERTIFICATE----- 3 s:C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services i:C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services -----BEGIN CERTIFICATE----- MIIEMjCCAxqgAwIBAgIBATANBgkqhkiG9w0BAQUFADB7MQswCQYDVQQGEwJHQjEb MBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYDVQQHDAdTYWxmb3JkMRow GAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEhMB8GA1UEAwwYQUFBIENlcnRpZmlj YXRlIFNlcnZpY2VzMB4XDTA0MDEwMTAwMDAwMFoXDTI4MTIzMTIzNTk1OVowezEL MAkGA1UEBhMCR0IxGzAZBgNVBAgMEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UE BwwHU2FsZm9yZDEaMBgGA1UECgwRQ29tb2RvIENBIExpbWl0ZWQxITAfBgNVBAMM GEFBQSBDZXJ0aWZpY2F0ZSBTZXJ2aWNlczCCASIwDQYJKoZIhvcNAQEBBQADggEP ADCCAQoCggEBAL5AnfRu4ep2hxxNRUSOvkbIgwadwSr+GB+O5AL686tdUIoWMQua BtDFcCLNSS1UY8y2bmhGC1Pqy0wkwLxyTurxFa70VJoSCsN6sjNg4tqJVfMiWPPe 3M/vg4aijJRPn2jymJBGhCfHdr/jzDUsi14HZGWCwEiwqJH5YZ92IFCokcdmtet4 YgNW8IoaE+oxox6gmf049vYnMlhvB/VruPsUK6+3qszWY19zjNoFmag4qMsXeDZR rOme9Hg6jc8P2ULimAyrL58OAd7vn5lJ8S3frHRNG5i1R8XlKdH5kBjHYpy+g8cm ez6KJcfA3Z3mNWgQIJ2P2N7Sw4ScDV7oL8kCAwEAAaOBwDCBvTAdBgNVHQ4EFgQU oBEKIz6W8Qfs4q8p74Klf9AwpLQwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQF MAMBAf8wewYDVR0fBHQwcjA4oDagNIYyaHR0cDovL2NybC5jb21vZG9jYS5jb20v QUFBQ2VydGlmaWNhdGVTZXJ2aWNlcy5jcmwwNqA0oDKGMGh0dHA6Ly9jcmwuY29t b2RvLm5ldC9BQUFDZXJ0aWZpY2F0ZVNlcnZpY2VzLmNybDANBgkqhkiG9w0BAQUF AAOCAQEACFb8AvCb6P+k+tZ7xkSAzk/ExfYAWMymtrwUSWgEdujm7l3sAg9g1o1Q GE8mTgHj5rCl7r+8dFRBv/38ErjHT1r0iWAFf2C3BUrz9vHCv8S5dIa2LX1rzNLz Rt0vxuBqw8M0Ayx9lt1awg6nCpnBBYurDC/zXDrPbDdVCYfeU0BsWO/8tqtlbgT2 G9w84FoVxp7Z8VlIMCFlA2zs6SFz7JsDoeA3raAVGI/6ugLOpyypEBMs1OUIJqsi l2D4kF501KKaU73yqWjgom7C12yxow+ev+to51byrvLjKzg6CYG1a4XXvi3tPxq3 smPi9WIsgtRqAEFQ8TmDn5XpNpaYbg== -----END CERTIFICATE----- --- Server certificate subject=C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk issuer=C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 7006 bytes and written 402 bytes Verification error: self signed certificate in certificate chain --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 19 (self signed certificate in certificate chain) --- --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: B62EF52D8CA8DF9760352616D340627B3D628DEBF748CCD7806185A5480B668F Session-ID-ctx: Resumption PSK: EF0ED6AAD5E946F349E03BCCD6357DA90BF3537B4C1A7E9EA84FF8F14EA3FCDE51ABF1CF505473AE9EC508EE55450010 PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 300 (seconds) TLS session ticket: 0000 - 17 3a 38 eb 2e 3d 61 57-db 13 13 38 40 7c 6d c9 .:8..=aW...8@|m. 0010 - 7d 50 0d ac b6 27 00 e5-c9 8b cb fb 38 a6 85 05 }P...'......8... 0020 - a1 0f 5e 9a e8 1f ba a5-59 47 81 c8 8d 8f 8f a9 ..^.....YG...... 0030 - 73 ca 00 58 0c 19 f3 54-7c 3d fa 57 7c bb f6 55 s..X...T|=.W|..U 0040 - bb 4b 64 3e 4c 30 d1 31-32 0f 2e ea 5e 83 2d 43 .Kd>L0.12...^.-C 0050 - 5e 6f d0 07 f3 f5 af 66-11 26 f6 91 6d 53 61 e4 ^o.....f.&..mSa. 0060 - 1f f4 34 3f 42 a9 1e cd-5b 35 88 a1 0b 0e 3e 4b ..4?B...[5....>K 0070 - 05 83 62 01 9a 0e f1 9a-f5 a6 fa ab 3d ac 84 15 ..b.........=... 0080 - c8 6b e2 aa 3c 19 f5 f7-3f c1 fc 40 cf 43 85 17 .k..<...?..@.C.. 0090 - 19 e3 bd 30 34 a0 cc 7e-1a 25 00 45 b8 cc 2b 15 ...04..~.%.E..+. 00a0 - 3f 8e b9 7f 59 af 76 d5-b1 5e 3d f7 d3 7f 24 bc ?...Y.v..^=...$. 00b0 - 81 a9 dc 94 f5 84 54 a0-8b b6 03 4b 1c 8f f4 28 ......T....K...( 00c0 - 3c 80 f4 00 90 2f 30 2b-ac 27 0b 4a af 09 c0 74 <..../0+.'.J...t 00d0 - 61 67 7b 91 78 01 22 aa-ba 33 eb f2 b4 a2 f2 44 ag{.x."..3.....D 00e0 - 5f b3 17 7e dc c7 a0 47-2c 06 c9 d3 62 02 52 19 _..~...G,...b.R. 00f0 - d9 9c 55 1b c7 02 11 24-93 b1 b4 bf a0 99 3d a2 ..U....$......=. Start Time: 1702551216 Timeout : 7200 (sec) Verify return code: 19 (self signed certificate in certificate chain) Extended master secret: no Max Early Data: 0 --- read R BLOCK --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: 5E9F4A4181F14950006FDC06F23CE2D0856B92FACB82EE90A9316D84667D8FF3 Session-ID-ctx: Resumption PSK: A68C0331A68CF4A2D92FB8BFD00D0047F89D0E3E8435CFFF7E15336E17C7E1A64C76D56BB918A51E431138B9E1C8048B PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 300 (seconds) TLS session ticket: 0000 - 17 3a 38 eb 2e 3d 61 57-db 13 13 38 40 7c 6d c9 .:8..=aW...8@|m. 0010 - e9 2c b6 63 f1 fc 0a d0-4f 44 b4 ed 71 0c a9 d6 .,.c....OD..q... 0020 - a2 49 41 66 ab 2c e9 86-6c f9 b1 5f 29 d9 18 c6 .IAf.,..l.._)... 0030 - 7c 71 d1 81 f7 a7 8d 09-de ad 43 b1 61 74 02 ef |q........C.at.. 0040 - 47 06 75 b8 6b a7 59 ce-ee 29 ee 93 f8 35 e0 5f G.u.k.Y..)...5._ 0050 - 13 3a 5d 33 74 a2 d2 95-52 df de cd 0b 23 38 90 .:]3t...R....#8. 0060 - 0c ae 66 56 df 45 a2 b7-5c 6c 98 1e f7 f7 cc 6b ..fV.E..\l.....k 0070 - 56 9e 7b 21 7a 94 ed 28-3b b0 e1 77 66 52 17 9c V.{!z..(;..wfR.. 0080 - 4e c5 6c fa fd fe 34 1d-f6 c0 7c 74 1b 2d d5 7a N.l...4...|t.-.z 0090 - 7e 81 51 2f dc ea b6 ce-ce 83 ba 37 ae 64 99 d9 ~.Q/.......7.d.. 00a0 - c7 4e 70 ac f0 2a 0e 55-f9 8f 4b dc 73 76 59 b9 .Np..*.U..K.svY. 00b0 - 00 0f 03 8e d7 bb 8b 5b-ce 6a 87 e3 2d 41 5f 53 .......[.j..-A_S 00c0 - bf 7e 57 bf e2 65 b6 39-1b 37 f0 ac 41 dd 06 06 .~W..e.9.7..A... 00d0 - 6e 47 dd d7 53 5f 3f 67-1b 0e 61 5f 3c 1e 19 0c nG..S_?g..a_<... 00e0 - 2f 23 30 6e 72 01 9f 53-5b 6f 11 a5 38 d9 9c 36 /#0nr..S[o..8..6 00f0 - 9d 0a e3 b5 a3 19 01 94-d0 78 7c ee b2 de c8 31 .........x|....1 Start Time: 1702551216 Timeout : 7200 (sec) Verify return code: 19 (self signed certificate in certificate chain) Extended master secret: no Max Early Data: 0 --- read R BLOCK
depth=3 C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services verify error:num=19:self signed certificate in certificate chain verify return:1 depth=3 C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services verify return:1 depth=2 C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority verify return:1 depth=1 C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 verify return:1 depth=0 C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk verify return:1 DONE
!echo QUIT | openssl s_client -status -showcerts -connect www.upjs.sk:443 | openssl x509 -text -noout
Certificate: Data: Version: 3 (0x2) Serial Number: 06:d7:82:e3:36:51:08:0a:fc:b8:0e:21:9c:d7:4e:26 Signature Algorithm: sha384WithRSAEncryption Issuer: C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 Validity Not Before: Feb 9 00:00:00 2023 GMT Not After : Feb 9 23:59:59 2024 GMT Subject: C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:c6:2c:2c:30:74:f9:4d:05:ec:5e:99:f1:9b:d8: 7a:2b:1d:52:0a:c2:09:60:e8:ff:b6:0b:64:ce:f6: 0a:68:36:72:56:6b:c3:e6:8d:2d:c3:10:fb:04:57: 36:53:63:58:61:80:48:9b:db:78:99:cd:9c:ae:a9: 3a:b5:f3:51:64:35:7e:cd:b4:4c:cd:ca:0c:82:60: c4:9a:8c:90:09:7d:c9:d8:34:50:5a:a3:fe:24:02: 4d:fb:25:1b:65:10:7b:d8:fb:a5:9f:49:fc:30:82: 2f:ad:97:9d:7a:d3:28:69:0b:53:65:02:c1:35:bf: 7b:cf:79:30:10:b9:c7:18:91:3b:e5:79:9c:6f:c4: e4:1b:6a:a2:7b:fa:f9:92:3d:0c:21:4b:83:2a:4a: ca:6d:13:8c:78:61:d1:f1:ca:5a:ed:3b:1d:38:3a: 0e:89:9a:42:6e:05:67:61:25:17:d2:26:ba:79:92: f6:65:32:a2:67:6a:d4:eb:a2:10:fa:56:52:50:c8: 2e:49:6a:f5:49:97:18:7b:fe:85:6c:24:e6:b3:7c: e7:7d:57:cb:d9:f4:5e:25:d2:7d:a5:e4:12:5f:05: 2f:0d:e7:46:e0:76:2f:11:80:64:db:59:8e:ee:da: 28:d6:a6:98:05:72:4b:33:68:b6:46:d8:37:f8:4c: 29:bd Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: keyid:6F:1D:35:49:10:6C:32:FA:59:A0:9E:BC:8A:E8:1F:95:BE:71:7A:0C X509v3 Subject Key Identifier: 7D:F5:12:52:19:A4:53:FF:EA:BC:01:7B:8A:29:7B:3E:6D:56:05:C6 X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 1.3.6.1.4.1.6449.1.2.2.79 CPS: https://sectigo.com/CPS Policy: 2.23.140.1.2.2 X509v3 CRL Distribution Points: Full Name: URI:http://GEANT.crl.sectigo.com/GEANTOVRSACA4.crl Authority Information Access: CA Issuers - URI:http://GEANT.crt.sectigo.com/GEANTOVRSACA4.crt OCSP - URI:http://GEANT.ocsp.sectigo.com CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 76:FF:88:3F:0A:B6:FB:95:51:C2:61:CC:F5:87:BA:34: B4:A4:CD:BB:29:DC:68:42:0A:9F:E6:67:4C:5A:3A:74 Timestamp : Feb 9 00:17:22.232 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:44:02:20:6C:0C:AF:C5:25:88:AD:F6:FA:15:8F:35: 04:65:C4:09:CF:5A:6F:4F:A2:67:45:2C:D8:2E:F5:CC: C0:26:20:C0:02:20:77:47:FE:B5:6B:2D:B4:F4:52:2F: 78:15:E5:1C:D7:40:9E:37:5C:02:6A:E1:33:57:36:72: 75:4A:2D:BD:4D:F5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DA:B6:BF:6B:3F:B5:B6:22:9F:9B:C2:BB:5C:6B:E8:70: 91:71:6C:BB:51:84:85:34:BD:A4:3D:30:48:D7:FB:AB Timestamp : Feb 9 00:17:22.181 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:B2:55:31:88:7E:60:6D:69:5F:CC:AD: 51:E9:89:24:7E:41:CD:DB:F9:E4:9F:E4:56:28:B2:91: 9C:BB:8F:E3:19:02:20:4A:77:D1:AD:5E:C4:7A:A3:68: 69:6C:7A:B8:73:D8:B6:12:11:B1:B0:67:30:F0:66:31: B3:6E:76:86:02:F2:CB Signed Certificate Timestamp: Version : v1 (0x0) Log ID : EE:CD:D0:64:D5:DB:1A:CE:C5:5C:B7:9D:B4:CD:13:A2: 32:87:46:7C:BC:EC:DE:C3:51:48:59:46:71:1F:B5:9B Timestamp : Feb 9 00:17:22.137 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:E3:68:B9:2C:CF:2B:7E:C2:74:66:14: DF:ED:F4:0B:03:0E:15:0A:16:D7:DD:91:43:83:B8:C1: 6E:E4:03:BE:64:02:20:52:1F:E4:86:99:7A:7D:CE:4C: D5:0B:2E:DE:A2:57:90:08:FE:89:4B:40:A3:BB:96:21: F2:5C:85:19:80:BA:29 X509v3 Subject Alternative Name: DNS:www.upjs.sk, DNS:ff.upjs.sk, DNS:lf.upjs.sk, DNS:library.upjs.sk, DNS:medic.upjs.sk, DNS:pf.upjs.sk, DNS:pravo.upjs.sk, DNS:science.upjs.sk, DNS:upjs.sk, DNS:www.ff.upjs.sk, DNS:www.fvs.upjs.sk, DNS:www.lf.upjs.sk, DNS:www.library.upjs.sk, DNS:www.medic.upjs.sk, DNS:www.pf.upjs.sk, DNS:www.pravo.upjs.sk, DNS:www.science.upjs.sk, DNS:www.uk.upjs.sk Signature Algorithm: sha384WithRSAEncryption 1c:6b:c3:e1:bb:71:fa:be:9a:ef:fb:cb:64:bc:a4:b7:06:3a: 21:b1:23:84:86:00:c2:c8:d0:5e:69:a6:72:56:8d:39:86:7d: d2:61:3b:17:a7:90:04:81:4f:ac:33:30:0e:5c:b8:01:95:28: 13:a0:e3:4d:be:d1:24:5a:7a:a0:8d:59:64:2c:bb:25:f5:8a: 39:f2:b7:98:55:ce:29:fb:4e:e7:6e:bd:98:0a:2c:8c:b8:5e: 72:c6:f1:2f:81:83:73:b5:8f:8e:08:39:4e:b7:ac:d9:cd:a1: 85:90:e9:bb:3f:f2:77:33:6d:0c:d3:55:d3:cf:2c:e4:c8:b3: d2:31:4d:e8:b3:df:03:9d:fc:1c:07:22:c6:78:37:7b:5b:87: ab:1c:fd:28:b8:78:e8:77:22:d4:b4:46:31:fe:3c:2b:82:aa: dd:49:22:cb:02:20:7f:9f:0e:6c:ce:03:ac:7c:a6:1b:1b:7a: 8a:82:e4:d0:d6:98:cb:28:e6:05:88:cc:92:e2:4f:50:9d:08: 17:04:6e:37:4c:a6:2d:04:c4:e0:d2:ae:f3:f8:93:8d:ef:10: 39:51:04:79:7c:83:9b:65:9f:16:2d:20:f0:d6:a3:5c:16:4c: 44:28:5f:74:06:3d:0e:f2:d9:f9:51:a2:40:d4:78:f8:74:c2: 90:3e:0e:fb:65:82:ca:d9:bb:b5:39:de:6b:ee:4a:f0:af:d2: 0e:eb:dc:75:bb:59:63:89:aa:36:d8:2c:fa:d5:8a:51:71:87: ec:9d:9f:ef:7b:a2:60:1c:90:88:16:3b:70:5a:e3:26:cd:77: 88:11:aa:25:2b:41:76:a7:02:ea:11:34:28:b3:7e:9b:d7:cd: 76:13:66:d5:aa:a2:67:58:c2:5b:98:55:00:05:0d:a1:41:6c: 87:45:5a:62:09:be:84:20:df:c8:45:47:b3:8e:e0:03:21:c5: 8c:f8:0c:5e:40:28:88:8f:de:43:c9:c3:79:51:11:5a:12:61: 9c:43:17:26:76:9f:7b:46:f2:6b:e6:13:df:4e:4d:36:be:dc: c5:92:69:2c:bb:f2:7d:e1:46:f5:a9:95:0a:4d:c4:ff:b1:72: e4:da:41:70:f5:05:ac:eb:b7:f0:2c:dd:78:75:9e:4b:6d:21: bf:6a:89:a2:62:7a:1b:20:fa:61:1b:e2:50:28:ee:22:26:0e: ad:81:b5:6d:b1:8c:88:d3:5d:95:5f:31:50:49:fe:e3:21:e3: c0:10:4a:8c:ea:e6:12:e8:61:c8:ce:30:66:eb:d8:c8:f8:9d: bf:91:d5:ad:0a:89:41:77:fc:02:f7:09:d8:7d:7e:36:6d:f7: 48:30:f6:c1:1a:3a:b2:a9
depth=3 C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services verify error:num=19:self signed certificate in certificate chain verify return:1 depth=3 C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services verify return:1 depth=2 C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority verify return:1 depth=1 C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4 verify return:1 depth=0 C = SK, ST = Ko\C5\A1ick\C3\BD kraj, O = Univerzita Pavla Jozefa \C5\A0af\C3\A1rika v Ko\C5\A1iciach, CN = www.upjs.sk verify return:1 DONE
!echo QUIT | openssl s_client -status -showcerts -connect www.google.sk:443 | openssl x509 -text -noout
Certificate: Data: Version: 3 (0x2) Serial Number: 55:80:12:15:e7:84:25:e4:12:29:24:f5:95:39:03:cd Signature Algorithm: sha256WithRSAEncryption Issuer: C = US, O = Google Trust Services LLC, CN = GTS CA 1C3 Validity Not Before: Nov 20 08:12:24 2023 GMT Not After : Feb 12 08:12:23 2024 GMT Subject: CN = *.google.sk Subject Public Key Info: Public Key Algorithm: id-ecPublicKey Public-Key: (256 bit) pub: 04:0c:27:e8:52:fc:b3:26:e4:6b:8f:ac:ee:94:1f: 47:db:e4:06:59:bd:fb:7d:2c:e4:c9:67:c7:b6:66: 4c:cc:a0:6f:35:83:e4:ef:29:89:2b:3f:22:29:5e: 30:52:4e:e9:f3:81:34:be:30:3a:e7:81:f7:c4:40: 54:3a:6a:28:93 ASN1 OID: prime256v1 NIST CURVE: P-256 X509v3 extensions: X509v3 Key Usage: critical Digital Signature X509v3 Extended Key Usage: TLS Web Server Authentication X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: C1:7F:9E:50:21:18:33:A9:06:E0:35:6E:80:B4:0C:AA:04:CD:C7:65 X509v3 Authority Key Identifier: keyid:8A:74:7F:AF:85:CD:EE:95:CD:3D:9C:D0:E2:46:14:F3:71:35:1D:27 Authority Information Access: OCSP - URI:http://ocsp.pki.goog/gts1c3 CA Issuers - URI:http://pki.goog/repo/certs/gts1c3.der X509v3 Subject Alternative Name: DNS:*.google.sk, DNS:google.sk X509v3 Certificate Policies: Policy: 2.23.140.1.2.1 Policy: 1.3.6.1.4.1.11129.2.5.3 X509v3 CRL Distribution Points: Full Name: URI:http://crls.pki.goog/gts1c3/moVDfISia2k.crl CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : EE:CD:D0:64:D5:DB:1A:CE:C5:5C:B7:9D:B4:CD:13:A2: 32:87:46:7C:BC:EC:DE:C3:51:48:59:46:71:1F:B5:9B Timestamp : Nov 20 09:12:25.044 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:78:2A:24:97:A7:C2:E3:AF:4F:EC:20:BE: 3B:F6:91:E8:84:78:48:88:D4:15:02:CE:A6:6E:A2:5D: 44:34:E3:E1:02:21:00:8B:C9:EE:ED:58:81:AA:7A:84: 23:10:DC:F2:73:26:7D:4C:91:96:09:AD:C0:CD:0C:35: 85:CA:47:38:B1:FE:2C Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 48:B0:E3:6B:DA:A6:47:34:0F:E5:6A:02:FA:9D:30:EB: 1C:52:01:CB:56:DD:2C:81:D9:BB:BF:AB:39:D8:84:73 Timestamp : Nov 20 09:12:25.088 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:44:02:20:2F:AF:1A:DA:27:A5:62:33:AB:9E:EC:61: E0:C5:3D:24:64:4E:96:6B:FB:DB:16:07:34:F8:E8:F2: F5:FE:92:BC:02:20:5A:E9:0A:8B:BD:DD:C2:6B:9C:5D: 0F:A0:57:F5:0E:31:9A:FB:09:8C:C9:C2:02:FC:1F:62: 16:AC:D3:48:68:63 Signature Algorithm: sha256WithRSAEncryption 1b:63:17:27:99:de:9c:23:e7:41:01:27:1a:ad:dc:5f:92:e3: 55:a5:29:a4:89:cd:87:ac:b1:d1:20:53:56:36:09:65:a4:32: 9e:fe:60:14:22:02:b5:90:55:a9:19:a6:e5:9a:74:77:9d:fb: 00:c7:54:9e:0e:13:e9:7d:ec:4d:d0:9b:25:24:cd:99:51:14: 32:e0:80:38:ad:6a:27:dd:61:6d:92:30:82:66:23:ef:1e:45: 8c:3a:63:37:5e:ec:3e:37:3c:f2:2e:f0:c2:b3:a0:2d:b2:74: 87:39:fb:74:21:21:e6:0e:2e:7e:16:fd:bc:2f:99:bd:4c:ae: 41:e4:7b:d9:bc:ba:35:a6:a9:d0:b7:b4:d8:63:2a:b0:04:b5: 03:3c:61:61:a5:13:d6:43:94:66:da:17:18:91:8b:c5:da:7d: b3:db:b1:16:a3:8e:79:b3:4a:59:2a:8c:a4:48:2e:c4:53:f3: 60:10:d0:00:2a:0b:a3:46:07:4c:3c:6d:82:cd:cf:a7:f5:60: 2e:19:f6:0a:e8:7a:54:cd:ac:94:d6:4a:7f:66:cb:63:c9:a6: 29:52:0f:e2:f5:e0:92:26:a6:da:c4:01:54:43:09:c6:54:48: 25:05:04:e5:42:52:75:22:f6:87:75:19:ea:b0:74:74:d4:87: 0b:7b:4a:51
depth=2 C = US, O = Google Trust Services LLC, CN = GTS Root R1 verify error:num=20:unable to get local issuer certificate verify return:1 depth=1 C = US, O = Google Trust Services LLC, CN = GTS CA 1C3 verify return:1 depth=0 CN = *.google.sk verify return:1 DONE
!echo QUIT | openssl s_client -status -showcerts -starttls smtp -connect smtp.gmail.com:587 | openssl x509 -text -noout
Certificate: Data: Version: 3 (0x2) Serial Number: 80:72:4c:b5:17:76:00:bc:09:88:08:53:dd:46:e7:40 Signature Algorithm: sha256WithRSAEncryption Issuer: C = US, O = Google Trust Services LLC, CN = GTS CA 1C3 Validity Not Before: Nov 20 08:09:17 2023 GMT Not After : Feb 12 08:09:16 2024 GMT Subject: CN = smtp.gmail.com Subject Public Key Info: Public Key Algorithm: id-ecPublicKey Public-Key: (256 bit) pub: 04:43:e6:78:8b:e5:e1:4d:cb:6e:2e:26:42:e6:d4: 45:3b:d0:21:7a:d4:89:37:ab:5b:58:fd:9d:ec:61: 72:ec:fd:2a:92:76:ae:dd:f8:12:d6:c5:3d:bb:83: 7d:85:95:0b:6c:e3:8b:d6:be:48:56:11:53:be:7e: 6a:7c:b5:bb:e5 ASN1 OID: prime256v1 NIST CURVE: P-256 X509v3 extensions: X509v3 Key Usage: critical Digital Signature X509v3 Extended Key Usage: TLS Web Server Authentication X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: FA:42:61:67:A1:04:68:1B:DA:4C:7D:71:39:F8:C2:DE:A7:71:CC:2D X509v3 Authority Key Identifier: keyid:8A:74:7F:AF:85:CD:EE:95:CD:3D:9C:D0:E2:46:14:F3:71:35:1D:27 Authority Information Access: OCSP - URI:http://ocsp.pki.goog/gts1c3 CA Issuers - URI:http://pki.goog/repo/certs/gts1c3.der X509v3 Subject Alternative Name: DNS:smtp.gmail.com X509v3 Certificate Policies: Policy: 2.23.140.1.2.1 Policy: 1.3.6.1.4.1.11129.2.5.3 X509v3 CRL Distribution Points: Full Name: URI:http://crls.pki.goog/gts1c3/QOvJ0N1sT2A.crl CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 76:FF:88:3F:0A:B6:FB:95:51:C2:61:CC:F5:87:BA:34: B4:A4:CD:BB:29:DC:68:42:0A:9F:E6:67:4C:5A:3A:74 Timestamp : Nov 20 09:09:18.941 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F8:E7:A7:1A:0E:8E:6B:FC:60:15:B7: C5:3D:0B:C4:C5:69:3E:97:DE:8F:CB:54:08:B6:83:04: 4B:4C:B3:E5:ED:02:21:00:AA:91:59:16:96:6B:40:D7: 75:F6:D7:E4:7F:98:84:5C:4F:ED:B2:4E:95:B1:03:46: 99:6B:2E:8E:36:48:08:53 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 48:B0:E3:6B:DA:A6:47:34:0F:E5:6A:02:FA:9D:30:EB: 1C:52:01:CB:56:DD:2C:81:D9:BB:BF:AB:39:D8:84:73 Timestamp : Nov 20 09:09:18.931 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:73:D9:11:BF:46:44:30:D8:28:CA:D1:20: A2:30:1C:04:99:D4:9D:42:1F:D9:63:AA:24:63:0C:FB: 78:E3:FB:11:02:21:00:8A:62:80:23:7B:10:28:29:E6: 5A:5F:F8:34:C9:8D:09:25:4B:D6:EC:9E:03:72:A9:B9: 43:1B:04:E1:CF:07:7E Signature Algorithm: sha256WithRSAEncryption 5a:a8:e9:85:20:cd:cc:f6:3b:cb:65:2e:6e:41:a7:5c:dd:b1: d2:f8:bb:3c:b7:af:ba:0b:75:ee:f7:ec:b4:87:bb:cd:64:61: 0b:a8:cd:5f:49:3a:38:a0:0a:84:f7:6c:82:38:41:9e:9c:43: e8:22:a0:c3:65:d9:48:13:96:38:77:b1:17:af:04:e8:b4:90: 36:da:ce:49:1e:f7:e9:0a:c6:e5:48:06:24:0b:93:1c:2c:0a: 90:a2:c0:af:c4:4d:6c:a2:6f:fd:44:83:c6:59:f7:a2:5f:54: ce:1d:af:2c:54:5b:a2:ff:fb:fa:4f:84:99:8b:31:63:5c:b1: 56:23:38:5e:79:6e:53:58:a4:07:d4:9f:98:99:51:13:0b:fe: db:05:71:73:f8:e0:0d:af:7a:e1:96:21:1b:8c:e2:43:f4:a9: 2b:8b:03:83:bd:ee:f2:c5:2f:c0:bc:1e:ca:47:1f:4a:0b:47: 10:3f:45:dc:b0:aa:b0:3a:66:72:29:f4:e0:0e:50:dd:63:8d: 99:3e:cb:64:43:b8:32:dc:d1:fa:75:c0:5b:e0:87:be:9e:89: 59:0e:ee:f1:c6:0e:18:12:a8:75:fe:c5:62:9e:2d:ab:a8:d3: 77:d3:2c:4c:a5:d3:5c:63:db:1a:71:a7:ad:08:8b:6e:ed:93: 1d:92:af:2a
depth=2 C = US, O = Google Trust Services LLC, CN = GTS Root R1 verify error:num=20:unable to get local issuer certificate verify return:1 depth=1 C = US, O = Google Trust Services LLC, CN = GTS CA 1C3 verify return:1 depth=0 CN = smtp.gmail.com verify return:1 250 SMTPUTF8 DONE