Solved

How to get the public certificate

Posted on 2011-02-27
5
893 Views
Last Modified: 2012-06-27
Hello I am trying to use the openssl s_client option to see the public file of one host which is running on port 1234. Please note this is not web server but a application which uses the SSL cert. How can I see the cert of this app on host on 1234? I am getting below errors. Thanks!

user@hostname:~$ openssl s_client -connect example.company.com:1234
CONNECTED(00000003)
depth=1 /C=US/ST=California/L=San Jose/O=Company, Inc./OU=IT/CN=IT DEV CA/emailAddress=webmasters@company.com
verify error:num=19:self signed certificate in certificate chain
verify return:0
27556:error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure:s3_pkt.c:1102:SSL alert number 40
27556:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:188:

Open in new window

0
Comment
Question by:beer9
  • 2
  • 2
5 Comments
 
LVL 7

Expert Comment

by:gnurl
ID: 34994646
Hi,

this is nor really my source of interest, but did you already try to access the https://example.company.com:1234
in a webbrowser, even if it is not a web server? Maybe the browser can handle it, too?

Good luck
gnurl
0
 
LVL 33

Expert Comment

by:Dave Howe
ID: 34997523
effectively you ARE seeing it - its the line:

depth=1 /C=US/ST=California/L=San Jose/O=Company, Inc./OU=IT/CN=IT DEV CA/emailAddress=webmasters@company.com

however, if you want to see the full cert, add

-showcerts

to the command :)
0
 

Author Comment

by:beer9
ID: 34998288
Hi DaveHow, I tried with -showcerts but still getting the same error.

verify error:num=19:self signed certificate in certificate chain
verify return:0
29827:error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure:s3_pkt.c:1102:SSL alert number 40
29827:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:188:

Open in new window

0
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
ID: 35002055
odd, just did
openssl -connect 127.0.0.1:143 -showcerts
here and it worked perfectly. try with -debug instead to see if that gives any further information?
0
 

Author Closing Comment

by:beer9
ID: 35059621
Thank you! :-)
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine a situation that you have installed SSL (http://en.wikipedia.org/wiki/Secure_Sockets_Layer) Certificate on your Cisco ASA (Cisco Adaptive Security Appliance) firewall. Installation of SSL certificate on ASA is an another topic for which you …
SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question