Hi, This is regarding one of the issues I'm facing while using openssl. We are using openssl to retrive the server certificate to store that in the truststore to do a connect to the server.
The command we run is as follows and we redirect the certificate into a file. This is then imported into our truststore before making further communication with the server. cat /dev/null | openssl s_client -connect <hostname>:<port> | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' This works in most of the cases except one where the above command hangs. In this specific case it works if I remove all the applications (This is a J2EE application server which we are trying to get the certs for). For all other channels (browser, application server command line) the server presents the certificate and we are able to use it. Only with Open SSL it hangs. Following are the logs with -msg and -debug options. <<CommandWithmsgoption.txt>> <<CommandWithdebugoption.txt>> Following are logs for the same parameters on server where this is working. <<workingwithdebugoption.txt>> <<workingwithmsgoption.txt>> Any help on this would be much appreciated. Also let me know incase you need more details. Regards, Krishna This e-mail, including any attachment(s) hereto, is intended only for the individual or entity to whom it is addressed. It may contain proprietary, confidential or privileged information or attorney work product belonging to FIL India Business Services Private Limited (FIL-IBS) or its affiliates. If you are not the intended recipient of this e-mail, or if you have otherwise received this e-mail in error, please immediately notify the sender via return e-mail and permanently delete the original mail, any print outs and any copies, including any attachments. Any dissemination, distribution, alteration or copying of this e-mail is strictly prohibited. The originator of this e-mail does not guarantee the security of this message and will not be responsible for any damages arising from any dissemination, distribution, alteration or copying of this message and/or any attachments to this message by a third party or as a result of any virus being passed on. Any comments or statements made in this are not necessarily those of FIL - IBS or any other Fidelity entity. All e-mails sent from or to FIL- IBS may be subject to our monitoring and recording procedures.
bash-3.2$ cat /dev/null | openssl s_client -connect dcasit1.uk.fid-intl.com:15012 -msg CONNECTED(00000003) >>> SSL 2.0 [length 0077], CLIENT-HELLO 01 03 01 00 4e 00 00 00 20 00 00 39 00 00 38 00 00 35 00 00 16 00 00 13 00 00 0a 07 00 c0 00 00 33 00 00 32 00 00 2f 03 00 80 00 00 05 00 00 04 01 00 80 00 00 15 00 00 12 00 00 09 06 00 40 00 00 14 00 00 11 00 00 08 00 00 06 04 00 80 00 00 03 02 00 80 00 00 ff 9b 1b 20 ac fa cf 07 a1 74 87 b3 c2 a5 b8 44 b1 f3 4e 98 71 3f 84 99 4a 9e 76 0a 9e 1c 79 8f 83 <<< TLS 1.0 Handshake [length 004a], ServerHello 02 00 00 46 03 01 4d ac 1e ef 95 87 aa 7c 31 97 99 b3 99 29 67 ae dd 11 72 a3 3f 85 65 5a 4e b2 8d f3 01 7b bf 77 20 4d ac 1e ef a9 47 86 50 46 c0 6f 38 7c d2 9e 4f bf d9 27 b6 f7 05 6b 00 10 5f 6d 9a 39 b4 ad ec 00 16 00 <<< TLS 1.0 Handshake [length 0223], Certificate 0b 00 02 1f 00 02 1c 00 02 19 30 82 02 15 30 82 01 7e a0 03 02 01 02 02 04 4d 70 bc c7 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 30 4f 31 0b 30 09 06 03 55 04 06 13 02 47 42 31 1f 30 1d 06 03 55 04 0a 13 16 46 69 64 65 6c 69 74 79 20 49 6e 74 65 72 6e 61 74 69 6f 6e 61 6c 31 1f 30 1d 06 03 55 04 03 13 16 64 63 61 73 69 74 2e 75 6b 2e 66 69 64 2d 69 6e 74 6c 2e 63 6f 6d 30 1e 17 0d 31 31 30 33 30 34 31 30 31 39 35 31 5a 17 0d 32 31 30 33 30 31 31 30 31 39 35 31 5a 30 4f 31 0b 30 09 06 03 55 04 06 13 02 47 42 31 1f 30 1d 06 03 55 04 0a 13 16 46 69 64 65 6c 69 74 79 20 49 6e 74 65 72 6e 61 74 69 6f 6e 61 6c 31 1f 30 1d 06 03 55 04 03 13 16 64 63 61 73 69 74 2e 75 6b 2e 66 69 64 2d 69 6e 74 6c 2e 63 6f 6d 30 81 9f 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 81 8d 00 30 81 89 02 81 81 00 a2 fe 46 15 d0 bf 6c 53 35 60 40 f9 7c 6e e4 fc a3 bc c3 a7 96 2c 4f 1d d0 14 2b 50 7c fb 24 e8 93 22 20 e2 cf 8a 3d 22 cd 13 12 7a dc 58 03 d6 92 35 1b 7c 74 d6 d1 97 01 35 a2 3a c9 f5 20 29 a9 7b f3 c3 a5 80 50 8a b1 8e 8c 33 bf 86 43 0b df b8 8c 1c 7f 93 18 2a 0d 64 ae 6a 9c da f0 53 a3 d6 a0 62 ce ee fe 48 44 79 02 f6 d1 8b c1 43 96 b1 3a dd c1 76 8d 29 4e 3d 8f 78 78 99 97 45 02 03 01 00 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 56 8e 9a d0 f8 d5 24 3a 93 19 78 ac b3 5c 30 7e 34 9e 10 8a d7 3f cb 10 70 cd 23 df 8f 27 db 6f a5 f4 32 9a 7b 24 4e 2f ac 2a 9e 57 06 f8 7a 55 73 30 13 5a ee 83 17 2e 00 15 1d 6d d9 95 f5 c9 36 19 bf a2 21 2c 1d 06 1a a6 85 f6 7e 8c f1 4b 2f f5 00 e3 ac c8 5f 59 04 21 6a b3 5d 52 d9 81 25 7e 60 55 97 95 e9 e7 52 a8 7f 19 f3 39 5b 2a 55 d5 85 e5 4e e0 93 2c 8f 64 21 ca d8 ef ab 9c depth=0 /C=GB/O=Fidelity International/CN=dcasit.uk.fid-intl.com verify error:num=18:self signed certificate verify return:1 depth=0 /C=GB/O=Fidelity International/CN=dcasit.uk.fid-intl.com verify return:1 <<< TLS 1.0 Handshake [length 01a0], ServerKeyExchange 0c 00 01 9c 00 80 fd 7f 53 81 1d 75 12 29 52 df 4a 9c 2e ec e4 e7 f6 11 b7 52 3c ef 44 00 c3 1e 3f 80 b6 51 26 69 45 5d 40 22 51 fb 59 3d 8d 58 fa bf c5 f5 ba 30 f6 cb 9b 55 6c d7 81 3b 80 1d 34 6f f2 66 60 b7 6b 99 50 a5 a4 9f 9f e8 04 7b 10 22 c2 4f bb a9 d7 fe b7 c6 1b f8 3b 57 e7 c6 a8 a6 15 0f 04 fb 83 f6 d3 c5 1e c3 02 35 54 13 5a 16 91 32 f6 75 f3 ae 2b 61 d7 2a ef f2 22 03 19 9d d1 48 01 c7 00 14 97 60 50 8f 15 23 0b cc b2 92 b9 82 a2 eb 84 0b f0 58 1c f5 00 80 51 cc 79 d5 44 29 0d f4 d0 54 ca 7b fa b6 16 3c 53 cf dc 32 ab 89 b6 69 11 01 cf 84 a2 21 b0 6a 51 f7 30 ef ab 64 7a dd 17 30 6f 74 59 43 84 1e 9e 5b cb f3 b1 ff 28 05 c1 8e 93 81 d3 c4 e5 6f b6 44 29 b6 a8 b0 38 0d 03 f8 25 b9 83 0f 25 ff 2c e9 5c fa 39 a6 66 b4 65 c5 df 85 b7 8b 5e 67 50 3b c1 95 5c b3 da 34 23 bd 6a f1 b3 b3 96 2b 7b 9d 2e 05 82 19 23 08 8d 4f 6e 76 c2 09 4d 44 00 80 5c 65 90 0b 8d ca 0f 1e 8c ed 56 82 cf a2 f3 0f 16 bc b7 3e 88 d0 3a 13 30 20 52 0a 0d c3 0b 58 d0 4a 91 0b d9 f8 e3 f4 9a 9d a2 36 d1 d8 6e 54 3b 00 01 80 ac a9 0f 7b 93 a9 a2 18 b7 2d 60 71 d2 9f 86 82 59 13 29 01 a2 ad 8e a7 e6 18 c8 74 8a 19 64 c7 eb 3c 1d 19 c2 ee 55 d8 03 11 9d 14 30 0a 2d ff 2a 59 14 2d 2b 0c 31 7c cb 68 95 64 cf d2 08 6c 06 ca b5 fe ec 0e 86 f7 91 2c c3 c0 <<< TLS 1.0 Handshake [length 0004], ServerHelloDone 0e 00 00 00 >>> TLS 1.0 Handshake [length 0086], ClientKeyExchange 10 00 00 82 00 80 dc 70 89 93 93 74 61 e5 14 d0 a2 28 f4 1f da 4f b0 75 fa b0 a7 3a a2 de a7 16 22 bd e6 aa 9f 84 30 8d 56 43 5b 11 48 ff c8 00 82 38 b3 7c 6c b3 61 a1 f7 1f d1 06 5e 14 9e e8 db 16 ad 5e 25 4d f0 56 58 a8 f1 ef 15 b8 17 0e c3 fb dc ac 79 d2 13 d4 c5 68 e7 0c 82 31 87 69 d8 38 21 c5 5e de d7 b1 01 49 b5 dc 23 c2 e7 09 99 c8 cb 5e b0 87 82 d4 1c 40 d4 60 90 9a 27 c3 d7 be d1 cf 7b 2e >>> TLS 1.0 ChangeCipherSpec [length 0001] 01 >>> TLS 1.0 Handshake [length 0010], Finished 14 00 00 0c 88 6c 7d 91 ea 0a dd a3 93 0c c6 d7
bash-3.2$ cat /dev/null | openssl s_client -connect dcasit1.uk.fid-intl.com:15012 -debug CONNECTED(00000003) write to 0x9aff1c0 [0x9b00620] (121 bytes => 121 (0x79)) 0000 - 80 77 01 03 01 00 4e 00-00 00 20 00 00 39 00 00 .w....N... ..9.. 0010 - 38 00 00 35 00 00 16 00-00 13 00 00 0a 07 00 c0 8..5............ 0020 - 00 00 33 00 00 32 00 00-2f 03 00 80 00 00 05 00 ..3..2../....... 0030 - 00 04 01 00 80 00 00 15-00 00 12 00 00 09 06 00 ................ 0040 - 40 00 00 14 00 00 11 00-00 08 00 00 06 04 00 80 @............... 0050 - 00 00 03 02 00 80 00 00-ff 26 90 0a 5a 14 c3 32 .........&..Z..2 0060 - a9 4e bb 22 52 29 d1 b9-6f ef 2a c7 e6 9b a0 07 .N."R)..o.*..... 0070 - 38 b2 ad b4 c0 f4 46 f9-dd 8.....F.. read from 0x9aff1c0 [0x9b05b80] (7 bytes => 7 (0x7)) 0000 - 16 03 01 04 11 02 ...... 0007 - <SPACES/NULS> read from 0x9aff1c0 [0x9b05b87] (1039 bytes => 1039 (0x40F)) 0000 - 00 46 03 01 4d ac 1f 1c-e6 83 43 2a 0d 5f 25 9d .F..M.....C*._%. 0010 - 4d e9 bd e1 5a ab 25 e5-77 de 86 e1 5e 66 4f 5e M...Z.%.w...^fO^ 0020 - 14 94 58 7c 20 4d ac 1f-1d 51 20 b7 f4 b1 1c f4 ..X| M...Q ..... 0030 - 0d c2 0c f6 e4 b0 ea 68-74 a0 85 c0 44 75 3c 14 .......ht...Du<. 0040 - 48 ca 88 be 7f 00 16 00-0b 00 02 1f 00 02 1c 00 H............... 0050 - 02 19 30 82 02 15 30 82-01 7e a0 03 02 01 02 02 ..0...0..~...... 0060 - 04 4d 70 bc c7 30 0d 06-09 2a 86 48 86 f7 0d 01 .Mp..0...*.H.... 0070 - 01 05 05 00 30 4f 31 0b-30 09 06 03 55 04 06 13 ....0O1.0...U... 0080 - 02 47 42 31 1f 30 1d 06-03 55 04 0a 13 16 46 69 .GB1.0...U....Fi 0090 - 64 65 6c 69 74 79 20 49-6e 74 65 72 6e 61 74 69 delity Internati 00a0 - 6f 6e 61 6c 31 1f 30 1d-06 03 55 04 03 13 16 64 onal1.0...U....d 00b0 - 63 61 73 69 74 2e 75 6b-2e 66 69 64 2d 69 6e 74 casit.uk.fid-int 00c0 - 6c 2e 63 6f 6d 30 1e 17-0d 31 31 30 33 30 34 31 l.com0...1103041 00d0 - 30 31 39 35 31 5a 17 0d-32 31 30 33 30 31 31 30 01951Z..21030110 00e0 - 31 39 35 31 5a 30 4f 31-0b 30 09 06 03 55 04 06 1951Z0O1.0...U.. 00f0 - 13 02 47 42 31 1f 30 1d-06 03 55 04 0a 13 16 46 ..GB1.0...U....F 0100 - 69 64 65 6c 69 74 79 20-49 6e 74 65 72 6e 61 74 idelity Internat 0110 - 69 6f 6e 61 6c 31 1f 30-1d 06 03 55 04 03 13 16 ional1.0...U.... 0120 - 64 63 61 73 69 74 2e 75-6b 2e 66 69 64 2d 69 6e dcasit.uk.fid-in 0130 - 74 6c 2e 63 6f 6d 30 81-9f 30 0d 06 09 2a 86 48 tl.com0..0...*.H 0140 - 86 f7 0d 01 01 01 05 00-03 81 8d 00 30 81 89 02 ............0... 0150 - 81 81 00 a2 fe 46 15 d0-bf 6c 53 35 60 40 f9 7c .....F...lS5`@.| 0160 - 6e e4 fc a3 bc c3 a7 96-2c 4f 1d d0 14 2b 50 7c n.......,O...+P| 0170 - fb 24 e8 93 22 20 e2 cf-8a 3d 22 cd 13 12 7a dc .$.." ...="...z. 0180 - 58 03 d6 92 35 1b 7c 74-d6 d1 97 01 35 a2 3a c9 X...5.|t....5.:. 0190 - f5 20 29 a9 7b f3 c3 a5-80 50 8a b1 8e 8c 33 bf . ).{....P....3. 01a0 - 86 43 0b df b8 8c 1c 7f-93 18 2a 0d 64 ae 6a 9c .C........*.d.j. 01b0 - da f0 53 a3 d6 a0 62 ce-ee fe 48 44 79 02 f6 d1 ..S...b...HDy... 01c0 - 8b c1 43 96 b1 3a dd c1-76 8d 29 4e 3d 8f 78 78 ..C..:..v.)N=.xx 01d0 - 99 97 45 02 03 01 00 01-30 0d 06 09 2a 86 48 86 ..E.....0...*.H. 01e0 - f7 0d 01 01 05 05 00 03-81 81 00 56 8e 9a d0 f8 ...........V.... 01f0 - d5 24 3a 93 19 78 ac b3-5c 30 7e 34 9e 10 8a d7 .$:..x..\0~4.... 0200 - 3f cb 10 70 cd 23 df 8f-27 db 6f a5 f4 32 9a 7b ?..p.#..'.o..2.{ 0210 - 24 4e 2f ac 2a 9e 57 06-f8 7a 55 73 30 13 5a ee $N/.*.W..zUs0.Z. 0220 - 83 17 2e 00 15 1d 6d d9-95 f5 c9 36 19 bf a2 21 ......m....6...! 0230 - 2c 1d 06 1a a6 85 f6 7e-8c f1 4b 2f f5 00 e3 ac ,......~..K/.... 0240 - c8 5f 59 04 21 6a b3 5d-52 d9 81 25 7e 60 55 97 ._Y.!j.]R..%~`U. 0250 - 95 e9 e7 52 a8 7f 19 f3-39 5b 2a 55 d5 85 e5 4e ...R....9[*U...N 0260 - e0 93 2c 8f 64 21 ca d8-ef ab 9c 0c 00 01 9c 00 ..,.d!.......... 0270 - 80 fd 7f 53 81 1d 75 12-29 52 df 4a 9c 2e ec e4 ...S..u.)R.J.... 0280 - e7 f6 11 b7 52 3c ef 44-00 c3 1e 3f 80 b6 51 26 ....R<.D...?..Q& 0290 - 69 45 5d 40 22 51 fb 59-3d 8d 58 fa bf c5 f5 ba iE]@"Q.Y=.X..... 02a0 - 30 f6 cb 9b 55 6c d7 81-3b 80 1d 34 6f f2 66 60 0...Ul..;..4o.f` 02b0 - b7 6b 99 50 a5 a4 9f 9f-e8 04 7b 10 22 c2 4f bb .k.P......{.".O. 02c0 - a9 d7 fe b7 c6 1b f8 3b-57 e7 c6 a8 a6 15 0f 04 .......;W....... 02d0 - fb 83 f6 d3 c5 1e c3 02-35 54 13 5a 16 91 32 f6 ........5T.Z..2. 02e0 - 75 f3 ae 2b 61 d7 2a ef-f2 22 03 19 9d d1 48 01 u..+a.*.."....H. 02f0 - c7 00 14 97 60 50 8f 15-23 0b cc b2 92 b9 82 a2 ....`P..#....... 0300 - eb 84 0b f0 58 1c f5 00-80 8a 8d 7a 19 3a 0f 49 ....X......z.:.I 0310 - 3d aa 68 ff 59 24 f9 6c-11 9d a6 42 88 4f d6 2a =.h.Y$.l...B.O.* 0320 - fb 90 e6 27 e2 2b 55 80-af 9f 0d 18 a5 7b 79 02 ...'.+U......{y. 0330 - 46 cd 5f 66 13 62 e6 d8-e5 f1 ef dd 04 77 90 67 F._f.b.......w.g 0340 - f1 f9 32 d8 31 94 46 4b-16 e3 17 04 59 05 66 bf ..2.1.FK....Y.f. 0350 - b1 44 70 1f 4e a9 70 95-78 13 ae f7 7d bf 7f c1 .Dp.N.p.x...}... 0360 - 70 ad 89 83 1e af 0f 6d-4b bd 64 a9 87 05 99 0b p......mK.d..... 0370 - c1 18 47 9b ba 4d cf 2e-d9 a9 46 cc 6d 67 c8 39 ..G..M....F.mg.9 0380 - 34 34 f8 8f 87 a4 2a 43-2d 00 80 30 bb 5c 54 3d 44....*C-..0.\T= 0390 - d7 91 ec 6f f3 2e e6 38-2a 0c ea 13 19 1d be 38 ...o...8*......8 03a0 - 66 9c 07 ea 4f fe 5f 79-34 fe ad 4c c8 ae 73 a8 f...O._y4..L..s. 03b0 - 6f 6f 35 33 e9 25 45 4c-b9 1f 6c e8 fc 73 a7 e2 oo53.%EL..l..s.. 03c0 - 7a 60 9c 11 9f e4 24 1e-42 e8 f1 44 39 7c c9 57 z`....$.B..D9|.W 03d0 - 27 47 e0 46 76 1d 06 5a-6b 81 d0 77 e4 c1 d0 0f 'G.Fv..Zk..w.... 03e0 - 00 0e 08 bf 8f a7 7c 0b-7c 45 6d 36 5c d5 04 f9 ......|.|Em6\... 03f0 - 9d d1 2b ce 2b e4 96 9b-16 b9 5b 0f d6 2a 08 b5 ..+.+.....[..*.. 0400 - 9f 1e d6 7d 61 fa be 69-2f a4 9f 0e ...}a..i/... 040f - <SPACES/NULS> depth=0 /C=GB/O=Fidelity International/CN=dcasit.uk.fid-intl.com verify error:num=18:self signed certificate verify return:1 depth=0 /C=GB/O=Fidelity International/CN=dcasit.uk.fid-intl.com verify return:1 write to 0x9aff1c0 [0x9b107e0] (139 bytes => 139 (0x8B)) 0000 - 16 03 01 00 86 10 00 00-82 00 80 df 2b 1c 3e 50 ............+.>P 0010 - 08 ad 18 91 af d4 b4 ad-80 ab 20 db 7b e5 f7 e7 .......... .{... 0020 - e4 0c aa ba 4b 75 3b 04-b5 f8 59 8b 40 bb 56 7d ....Ku;...Y.@.V} 0030 - d0 78 4d fc 84 a2 55 0d-05 fc f2 73 90 09 53 ad .xM...U....s..S. 0040 - bf 06 1d d4 f7 fc e1 6e-0d 96 a5 52 cc 73 42 fa .......n...R.sB. 0050 - f8 31 e9 15 2b 4d 13 fe-46 93 15 65 09 5b fa a6 .1..+M..F..e.[.. 0060 - 86 cb d8 b3 6b 67 3f 0e-7b 0f 54 34 c0 c6 25 d3 ....kg?.{.T4..%. 0070 - 1b 9d 0f 4c 83 f7 56 a2-b1 86 22 f5 67 b0 3a 44 ...L..V...".g.:D 0080 - 88 1e b7 90 7b 14 03 34-48 35 94 ....{..4H5. write to 0x9aff1c0 [0x9b107e0] (6 bytes => 6 (0x6)) 0000 - 14 03 01 00 01 01 ...... write to 0x9aff1c0 [0x9b107e0] (45 bytes => 45 (0x2D)) 0000 - 16 03 01 00 28 2c 16 ce-55 bb 29 b8 d5 03 1e 86 ....(,..U.)..... 0010 - 75 37 32 50 ac 20 3a c0-58 0e 1f 44 34 cc 25 89 u72P. :.X..D4.%. 0020 - ee b1 0e 56 a0 e4 c1 3e-f0 d3 41 3d 7d ...V...>..A=}
bash-3.2$ cat /dev/null | openssl s_client -connect lintst5.uk.fid-intl.com:15012 -debug CONNECTED(00000003) write to 0x144b81c0 [0x144b9620] (121 bytes => 121 (0x79)) 0000 - 80 77 01 03 01 00 4e 00-00 00 20 00 00 39 00 00 .w....N... ..9.. 0010 - 38 00 00 35 00 00 16 00-00 13 00 00 0a 07 00 c0 8..5............ 0020 - 00 00 33 00 00 32 00 00-2f 03 00 80 00 00 05 00 ..3..2../....... 0030 - 00 04 01 00 80 00 00 15-00 00 12 00 00 09 06 00 ................ 0040 - 40 00 00 14 00 00 11 00-00 08 00 00 06 04 00 80 @............... 0050 - 00 00 03 02 00 80 00 00-ff 23 45 ed 2b a5 20 89 .........#E.+. . 0060 - 1e d8 e9 02 68 8f 07 1d-d8 a4 63 83 65 b7 fe 5f ....h.....c.e.._ 0070 - d2 07 9e 6f 2c 53 f0 24-df ...o,S.$. read from 0x144b81c0 [0x144beb80] (7 bytes => 7 (0x7)) 0000 - 16 03 01 03 fa 02 ...... 0007 - <SPACES/NULS> read from 0x144b81c0 [0x144beb87] (1016 bytes => 1016 (0x3F8)) 0000 - 00 4d 03 01 4d ac 1f 65-29 76 db 42 be 71 dc 81 .M..M..e)v.B.q.. 0010 - 7b a2 f3 43 87 02 6c 2f-e8 4e c6 ea b7 6f 81 d6 {..C..l/.N...o.. 0020 - 46 bd 69 e5 20 4d ac 1f-65 1c 3f 30 4e b7 64 f5 F.i. M..e.?0N.d. 0030 - fc 14 be 89 9e 04 7e 49-10 75 32 1d 4d 01 25 97 ......~I.u2.M.%. 0040 - 52 c2 15 0b 4b 00 16 00-00 05 ff 01 00 01 00 0b R...K........... 0050 - 00 02 01 00 01 fe 00 01-fb 30 82 01 f7 30 82 01 .........0...0.. 0060 - 60 a0 03 02 01 02 02 04-4c f8 cb d9 30 0d 06 09 `.......L...0... 0070 - 2a 86 48 86 f7 0d 01 01-05 05 00 30 40 31 0b 30 *.H........0@1.0 0080 - 09 06 03 55 04 06 13 02-47 42 31 1f 30 1d 06 03 ...U....GB1.0... 0090 - 55 04 0a 13 16 46 69 64-65 6c 69 74 79 20 49 6e U....Fidelity In 00a0 - 74 65 72 6e 61 74 69 6f-6e 61 6c 31 10 30 0e 06 ternational1.0.. 00b0 - 03 55 04 03 13 07 63 72-77 73 64 76 32 30 1e 17 .U....crwsdv20.. 00c0 - 0d 31 30 31 32 30 33 31-30 35 32 30 39 5a 17 0d .101203105209Z.. 00d0 - 32 30 31 31 33 30 31 30-35 32 30 39 5a 30 40 31 201130105209Z0@1 00e0 - 0b 30 09 06 03 55 04 06-13 02 47 42 31 1f 30 1d .0...U....GB1.0. 00f0 - 06 03 55 04 0a 13 16 46-69 64 65 6c 69 74 79 20 ..U....Fidelity 0100 - 49 6e 74 65 72 6e 61 74-69 6f 6e 61 6c 31 10 30 International1.0 0110 - 0e 06 03 55 04 03 13 07-63 72 77 73 64 76 32 30 ...U....crwsdv20 0120 - 81 9f 30 0d 06 09 2a 86-48 86 f7 0d 01 01 01 05 ..0...*.H....... 0130 - 00 03 81 8d 00 30 81 89-02 81 81 00 b1 35 42 01 .....0.......5B. 0140 - 00 67 de 90 ae 31 58 e8-20 75 c7 3d fb d7 ec 2e .g...1X. u.=.... 0150 - 59 b4 21 0a 24 11 3e 35-85 d5 17 9f 78 f0 b3 92 Y.!.$.>5....x... 0160 - 7f d4 48 2f 91 bf c4 7f-32 0a d9 eb 0a dc fd d4 ..H/....2....... 0170 - 12 a4 46 af 80 29 da 92-cd 22 0d c4 2a f4 4c 13 ..F..)..."..*.L. 0180 - 56 c6 0c ca b5 76 a4 12-2a 4b f2 c5 21 09 70 c7 V....v..*K..!.p. 0190 - e5 0f bc 51 ea 28 41 e6-47 d8 93 93 c0 23 a0 b0 ...Q.(A.G....#.. 01a0 - e4 38 6a 3d d8 6d ce 7d-f7 4f f6 52 cd 0b 04 c1 .8j=.m.}.O.R.... 01b0 - 4e e2 4f a0 76 83 74 dc-ae 15 f4 cf 02 03 01 00 N.O.v.t......... 01c0 - 01 30 0d 06 09 2a 86 48-86 f7 0d 01 01 05 05 00 .0...*.H........ 01d0 - 03 81 81 00 08 9e 15 90-66 de d9 cc 7a ff be 34 ........f...z..4 01e0 - 7f da 70 92 5f 32 11 4c-7b 02 83 56 0e 4a b7 03 ..p._2.L{..V.J.. 01f0 - 8e d4 00 51 cf 77 21 b9-85 e8 fe 9f b6 ba c1 86 ...Q.w!......... 0200 - 1e 3e f7 44 f9 bb cf 93-1f bb 78 8b 76 51 c0 d6 .>.D......x.vQ.. 0210 - ae cc d6 86 92 3d 9f 47-8b a8 53 b0 19 61 b7 68 .....=.G..S..a.h 0220 - af 77 21 e6 83 2b 90 2b-73 87 2c 29 1a 1c f6 84 .w!..+.+s.,).... 0230 - 86 f3 7f d8 38 5f a4 bc-23 88 2d 9f 2c 22 71 5d ....8_..#.-.,"q] 0240 - 44 39 a6 30 6e cc bf 78-c1 e6 ee e3 a6 f8 bf 2b D9.0n..x.......+ 0250 - 51 08 08 52 0c 00 01 9c-00 80 fd 7f 53 81 1d 75 Q..R........S..u 0260 - 12 29 52 df 4a 9c 2e ec-e4 e7 f6 11 b7 52 3c ef .)R.J........R<. 0270 - 44 00 c3 1e 3f 80 b6 51-26 69 45 5d 40 22 51 fb D...?..Q&iE]@"Q. 0280 - 59 3d 8d 58 fa bf c5 f5-ba 30 f6 cb 9b 55 6c d7 Y=.X.....0...Ul. 0290 - 81 3b 80 1d 34 6f f2 66-60 b7 6b 99 50 a5 a4 9f .;..4o.f`.k.P... 02a0 - 9f e8 04 7b 10 22 c2 4f-bb a9 d7 fe b7 c6 1b f8 ...{.".O........ 02b0 - 3b 57 e7 c6 a8 a6 15 0f-04 fb 83 f6 d3 c5 1e c3 ;W.............. 02c0 - 02 35 54 13 5a 16 91 32-f6 75 f3 ae 2b 61 d7 2a .5T.Z..2.u..+a.* 02d0 - ef f2 22 03 19 9d d1 48-01 c7 00 14 97 60 50 8f .."....H.....`P. 02e0 - 15 23 0b cc b2 92 b9 82-a2 eb 84 0b f0 58 1c f5 .#...........X.. 02f0 - 00 80 21 36 17 b8 db 48-32 04 5b 5a 10 7d 08 15 ..!6...H2.[Z.}.. 0300 - e0 f6 7e 73 1b 76 6a 2a-35 3a 36 8c f6 ea 3d c9 ..~s.vj*5:6...=. 0310 - bb 18 0e ba 21 c3 08 81-55 b4 e1 94 0f bf c9 ab ....!...U....... 0320 - 22 89 1f 4b 61 35 65 30-ac 05 a8 fd 70 c2 d4 8f "..Ka5e0....p... 0330 - 45 9e 59 93 ae 55 b2 53-95 0e 6e 6d 51 10 a8 50 E.Y..U.S..nmQ..P 0340 - bd 72 fd 44 b6 c6 fc 90-35 47 64 41 d2 52 c0 f0 .r.D....5GdA.R.. 0350 - 02 31 56 85 a2 ef 52 77-14 23 1f 49 67 b4 1a 38 .1V...Rw.#.Ig..8 0360 - f5 a8 29 98 72 30 03 31-3c eb 84 39 85 d7 d6 d6 ..).r0.1<..9.... 0370 - c9 90 00 80 0e 1d 78 96-49 35 70 e9 ab 64 a0 92 ......x.I5p..d.. 0380 - d7 9e 0b dc 1e 07 fb 40-e9 95 80 8b 55 c8 07 03 .......@....U... 0390 - c7 4f 53 2e 7e 9a af f2-8c 09 b6 bd f7 58 07 f6 .OS.~........X.. 03a0 - d4 1a cc 9c 00 94 24 62-38 ad ee 6b ad f8 14 ba ......$b8..k.... 03b0 - 7f 97 2e a8 0a f1 bb ef-a9 57 ba e5 5a d1 2e ec .........W..Z... 03c0 - 32 74 ee d8 65 48 4b 5e-8c c1 db a0 26 08 17 42 2t..eHK^....&..B 03d0 - 83 0e 80 2d c6 e4 00 6c-21 76 16 3a cd e3 00 83 ...-...l!v.:.... 03e0 - 37 28 e0 17 53 a6 7d 19-3a a3 d4 1e 34 5d 6f 41 7(..S.}.:...4]oA 03f0 - dd 50 c3 65 0e .P.e. 03f8 - <SPACES/NULS> depth=0 /C=GB/O=Fidelity International/CN=crwsdv2 verify error:num=18:self signed certificate verify return:1 depth=0 /C=GB/O=Fidelity International/CN=crwsdv2 verify return:1 write to 0x144b81c0 [0x144c97e0] (139 bytes => 139 (0x8B)) 0000 - 16 03 01 00 86 10 00 00-82 00 80 0d e7 7e bd 02 .............~.. 0010 - bb bb e7 43 40 66 7c b9-bc 58 26 57 ff 42 cb c5 ...C@f|..X&W.B.. 0020 - 13 ed 38 d8 0b de 05 7a-4d e8 56 02 17 af f6 a4 ..8....zM.V..... 0030 - da 86 e8 3b fe bf 18 b6-ed 58 0e bd 13 11 ad 9a ...;.....X...... 0040 - 82 b4 65 3b a9 39 f2 ca-66 7e 6e 49 6b 7e 80 88 ..e;.9..f~nIk~.. 0050 - a0 9f 05 e4 6b 6f ab d3-c8 ba 41 b9 ca 7b ee e0 ....ko....A..{.. 0060 - 4f 9a 38 5a 18 d3 0f 0f-03 95 29 40 bf 90 29 4e O.8Z......)@..)N 0070 - 88 d3 69 17 2b eb e2 54-e9 47 2c 73 4b 9a 5f 2d ..i.+..T.G,sK._- 0080 - 47 5f d3 10 e5 38 81 38-89 bb be G_...8.8... write to 0x144b81c0 [0x144c97e0] (6 bytes => 6 (0x6)) 0000 - 14 03 01 00 01 01 ...... write to 0x144b81c0 [0x144c97e0] (45 bytes => 45 (0x2D)) 0000 - 16 03 01 00 28 50 84 8a-d2 4a bf b6 6b 84 6b 4a ....(P...J..k.kJ 0010 - 09 21 96 b9 74 3b 0b c0-4f eb 96 14 07 52 b8 84 .!..t;..O....R.. 0020 - e1 22 5c 55 f7 71 9c 90-9b 3b ab 9a 18 ."\U.q...;... read from 0x144b81c0 [0x144beb80] (5 bytes => 5 (0x5)) 0000 - 14 03 01 00 01 ..... read from 0x144b81c0 [0x144beb85] (1 bytes => 1 (0x1)) 0000 - 01 . read from 0x144b81c0 [0x144beb80] (5 bytes => 5 (0x5)) 0000 - 16 03 01 00 28 ....( read from 0x144b81c0 [0x144beb85] (40 bytes => 40 (0x28)) 0000 - ac d1 b9 b9 14 df 31 38-a0 d0 84 47 7c d8 01 bc ......18...G|... 0010 - 70 ac a8 99 17 9b 5c 68-67 3f e3 11 8c 1d ed 4c p.....\hg?.....L 0020 - fa 52 10 b2 4b eb 70 97- .R..K.p. --- Certificate chain 0 s:/C=GB/O=Fidelity International/CN=crwsdv2 i:/C=GB/O=Fidelity International/CN=crwsdv2 --- Server certificate -----BEGIN CERTIFICATE----- MIIB9zCCAWCgAwIBAgIETPjL2TANBgkqhkiG9w0BAQUFADBAMQswCQYDVQQGEwJH QjEfMB0GA1UEChMWRmlkZWxpdHkgSW50ZXJuYXRpb25hbDEQMA4GA1UEAxMHY3J3 c2R2MjAeFw0xMDEyMDMxMDUyMDlaFw0yMDExMzAxMDUyMDlaMEAxCzAJBgNVBAYT AkdCMR8wHQYDVQQKExZGaWRlbGl0eSBJbnRlcm5hdGlvbmFsMRAwDgYDVQQDEwdj cndzZHYyMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxNUIBAGfekK4xWOgg dcc9+9fsLlm0IQokET41hdUXn3jws5J/1Egvkb/EfzIK2esK3P3UEqRGr4Ap2pLN Ig3EKvRME1bGDMq1dqQSKkvyxSEJcMflD7xR6ihB5kfYk5PAI6Cw5DhqPdhtzn33 T/ZSzQsEwU7iT6B2g3TcrhX0zwIDAQABMA0GCSqGSIb3DQEBBQUAA4GBAAieFZBm 3tnMev++NH/acJJfMhFMewKDVg5KtwOO1ABRz3chuYXo/p+2usGGHj73RPm7z5Mf u3iLdlHA1q7M1oaSPZ9Hi6hTsBlht2ivdyHmgyuQK3OHLCkaHPaEhvN/2DhfpLwj iC2fLCJxXUQ5pjBuzL94webu46b4vytRCAhS -----END CERTIFICATE----- subject=/C=GB/O=Fidelity International/CN=crwsdv2 issuer=/C=GB/O=Fidelity International/CN=crwsdv2 --- No client certificate CA names sent --- SSL handshake has read 1074 bytes and written 311 bytes --- New, TLSv1/SSLv3, Cipher is EDH-RSA-DES-CBC3-SHA Server public key is 1024 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE SSL-Session: Protocol : TLSv1 Cipher : EDH-RSA-DES-CBC3-SHA Session-ID: 4DAC1F651C3F304EB764F5FC14BE899E047E491075321D4D01259752C2150B4B Session-ID-ctx: Master-Key: 27444E8E39841626D19DDD3E878EE7ED872D502D9BB62EDBDD5D04853AA7C7F9CE7BC666417075700E4A9D3A5F026E5F Key-Arg : None Krb5 Principal: None Start Time: 1303125861 Timeout : 300 (sec) Verify return code: 18 (self signed certificate) --- DONE write to 0x144b81c0 [0x144c3390] (29 bytes => 29 (0x1D)) 0000 - 15 03 01 00 18 4a 4d d5-91 ca 80 63 87 b6 e4 ca .....JM....c.... 0010 - 92 07 68 74 3d 5d 4c 2a-fe 97 10 00 d4 ..ht=]L*.....
bash-3.2$ cat /dev/null | openssl s_client -connect lintst5.uk.fid-intl.com:15012 -msg CONNECTED(00000003) >>> SSL 2.0 [length 0077], CLIENT-HELLO 01 03 01 00 4e 00 00 00 20 00 00 39 00 00 38 00 00 35 00 00 16 00 00 13 00 00 0a 07 00 c0 00 00 33 00 00 32 00 00 2f 03 00 80 00 00 05 00 00 04 01 00 80 00 00 15 00 00 12 00 00 09 06 00 40 00 00 14 00 00 11 00 00 08 00 00 06 04 00 80 00 00 03 02 00 80 00 00 ff 46 25 fb e5 8b 39 53 3e f1 21 71 d9 a6 91 ad 58 62 72 77 80 1b df ec 93 a1 18 ea be c2 84 0f 8e <<< TLS 1.0 Handshake [length 0051], ServerHello 02 00 00 4d 03 01 4d ac 1f 41 37 d8 e9 b8 47 3e c3 c2 e3 c7 80 a1 d8 04 51 72 b1 34 61 33 4b ce 83 b5 ce 67 9c cc 20 4d ac 1f 41 b3 94 0f 83 3a 4b f8 c9 60 b3 11 e9 39 e9 cc c1 92 8e 96 fa 34 54 90 96 f5 ac 66 3a 00 16 00 00 05 ff 01 00 01 00 <<< TLS 1.0 Handshake [length 0205], Certificate 0b 00 02 01 00 01 fe 00 01 fb 30 82 01 f7 30 82 01 60 a0 03 02 01 02 02 04 4c f8 cb d9 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 30 40 31 0b 30 09 06 03 55 04 06 13 02 47 42 31 1f 30 1d 06 03 55 04 0a 13 16 46 69 64 65 6c 69 74 79 20 49 6e 74 65 72 6e 61 74 69 6f 6e 61 6c 31 10 30 0e 06 03 55 04 03 13 07 63 72 77 73 64 76 32 30 1e 17 0d 31 30 31 32 30 33 31 30 35 32 30 39 5a 17 0d 32 30 31 31 33 30 31 30 35 32 30 39 5a 30 40 31 0b 30 09 06 03 55 04 06 13 02 47 42 31 1f 30 1d 06 03 55 04 0a 13 16 46 69 64 65 6c 69 74 79 20 49 6e 74 65 72 6e 61 74 69 6f 6e 61 6c 31 10 30 0e 06 03 55 04 03 13 07 63 72 77 73 64 76 32 30 81 9f 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 81 8d 00 30 81 89 02 81 81 00 b1 35 42 01 00 67 de 90 ae 31 58 e8 20 75 c7 3d fb d7 ec 2e 59 b4 21 0a 24 11 3e 35 85 d5 17 9f 78 f0 b3 92 7f d4 48 2f 91 bf c4 7f 32 0a d9 eb 0a dc fd d4 12 a4 46 af 80 29 da 92 cd 22 0d c4 2a f4 4c 13 56 c6 0c ca b5 76 a4 12 2a 4b f2 c5 21 09 70 c7 e5 0f bc 51 ea 28 41 e6 47 d8 93 93 c0 23 a0 b0 e4 38 6a 3d d8 6d ce 7d f7 4f f6 52 cd 0b 04 c1 4e e2 4f a0 76 83 74 dc ae 15 f4 cf 02 03 01 00 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 08 9e 15 90 66 de d9 cc 7a ff be 34 7f da 70 92 5f 32 11 4c 7b 02 83 56 0e 4a b7 03 8e d4 00 51 cf 77 21 b9 85 e8 fe 9f b6 ba c1 86 1e 3e f7 44 f9 bb cf 93 1f bb 78 8b 76 51 c0 d6 ae cc d6 86 92 3d 9f 47 8b a8 53 b0 19 61 b7 68 af 77 21 e6 83 2b 90 2b 73 87 2c 29 1a 1c f6 84 86 f3 7f d8 38 5f a4 bc 23 88 2d 9f 2c 22 71 5d 44 39 a6 30 6e cc bf 78 c1 e6 ee e3 a6 f8 bf 2b 51 08 08 52 depth=0 /C=GB/O=Fidelity International/CN=crwsdv2 verify error:num=18:self signed certificate verify return:1 depth=0 /C=GB/O=Fidelity International/CN=crwsdv2 verify return:1 <<< TLS 1.0 Handshake [length 01a0], ServerKeyExchange 0c 00 01 9c 00 80 fd 7f 53 81 1d 75 12 29 52 df 4a 9c 2e ec e4 e7 f6 11 b7 52 3c ef 44 00 c3 1e 3f 80 b6 51 26 69 45 5d 40 22 51 fb 59 3d 8d 58 fa bf c5 f5 ba 30 f6 cb 9b 55 6c d7 81 3b 80 1d 34 6f f2 66 60 b7 6b 99 50 a5 a4 9f 9f e8 04 7b 10 22 c2 4f bb a9 d7 fe b7 c6 1b f8 3b 57 e7 c6 a8 a6 15 0f 04 fb 83 f6 d3 c5 1e c3 02 35 54 13 5a 16 91 32 f6 75 f3 ae 2b 61 d7 2a ef f2 22 03 19 9d d1 48 01 c7 00 14 97 60 50 8f 15 23 0b cc b2 92 b9 82 a2 eb 84 0b f0 58 1c f5 00 80 09 ee 15 6b 9c 8e 68 b8 a4 02 68 0d 4b 93 2f ea ad 5b 0a 6d 7f f6 3e a7 3a c3 a2 e2 cf c1 3f a6 95 6e 65 4f 60 a3 b9 8e db 40 02 86 b1 90 0a dc d9 9e 0f aa e6 9e 45 74 25 a8 89 ee eb fc 5a bb 9d 81 7a 55 ee 27 ce d6 34 9b bc c9 2d fa 03 c9 3d 0b a8 79 de 4b c1 7c e9 49 f0 f8 51 97 a2 a6 37 83 cc 47 a4 df db db e5 38 d4 ba 6c 4d a2 29 24 8d 61 27 2a 03 71 80 35 80 20 6d 57 e6 7a ad 00 80 ac 8c cf e9 77 2e e4 a9 17 94 c7 01 55 69 59 6c 1b be 3c dd 82 4d 9a d6 57 6b 16 58 35 12 af 54 0c 49 df b5 d8 22 a0 49 98 52 09 53 6e 81 78 05 bf 60 15 91 ac 48 e1 cb 8e 45 ad 32 01 d1 a4 f9 6d 97 87 6f f2 54 60 04 cf c8 bc 85 66 34 cc 90 39 41 ba 90 a1 e9 35 37 9f 6d 9e 22 c7 33 73 3e b0 f8 55 3c 37 f7 6e a9 72 f9 3a 23 c1 35 e4 41 c3 97 e4 6a df 0e e0 b9 21 49 cb 2b 8c 6e 0c f2 <<< TLS 1.0 Handshake [length 0004], ServerHelloDone 0e 00 00 00 >>> TLS 1.0 Handshake [length 0086], ClientKeyExchange 10 00 00 82 00 80 ba 3d 3d d3 2c ef 11 3f d1 6c ca 77 2c 78 66 5c b2 77 4a 60 ce 69 d2 2b 6c 92 b7 63 7d a1 e9 79 08 e6 f6 10 1b 11 5e ef e7 6a 74 c0 19 eb 1a c8 1a 62 bf 58 ed 85 0a c5 df d2 92 83 79 13 ec fd 66 56 70 1b ab 58 3c fe 08 8b 3f e6 ae 78 e4 1b 81 3e c8 2d 20 0b 6f 50 ae 17 55 6c 06 7d a0 f6 3a 12 bb 6c 0c 35 ee 85 79 65 4f 95 e3 5b 76 f4 cd 3a 68 63 69 0a 08 f9 4e 6c d6 ec 06 70 54 6d >>> TLS 1.0 ChangeCipherSpec [length 0001] 01 >>> TLS 1.0 Handshake [length 0010], Finished 14 00 00 0c 23 b8 e8 65 82 89 be 0e a9 b3 e3 fb <<< TLS 1.0 ChangeCipherSpec [length 0001] 01 <<< TLS 1.0 Handshake [length 0010], Finished 14 00 00 0c e8 98 d0 c2 ff bb b2 7e cd 92 b9 3c --- Certificate chain 0 s:/C=GB/O=Fidelity International/CN=crwsdv2 i:/C=GB/O=Fidelity International/CN=crwsdv2 --- Server certificate -----BEGIN CERTIFICATE----- MIIB9zCCAWCgAwIBAgIETPjL2TANBgkqhkiG9w0BAQUFADBAMQswCQYDVQQGEwJH QjEfMB0GA1UEChMWRmlkZWxpdHkgSW50ZXJuYXRpb25hbDEQMA4GA1UEAxMHY3J3 c2R2MjAeFw0xMDEyMDMxMDUyMDlaFw0yMDExMzAxMDUyMDlaMEAxCzAJBgNVBAYT AkdCMR8wHQYDVQQKExZGaWRlbGl0eSBJbnRlcm5hdGlvbmFsMRAwDgYDVQQDEwdj cndzZHYyMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxNUIBAGfekK4xWOgg dcc9+9fsLlm0IQokET41hdUXn3jws5J/1Egvkb/EfzIK2esK3P3UEqRGr4Ap2pLN Ig3EKvRME1bGDMq1dqQSKkvyxSEJcMflD7xR6ihB5kfYk5PAI6Cw5DhqPdhtzn33 T/ZSzQsEwU7iT6B2g3TcrhX0zwIDAQABMA0GCSqGSIb3DQEBBQUAA4GBAAieFZBm 3tnMev++NH/acJJfMhFMewKDVg5KtwOO1ABRz3chuYXo/p+2usGGHj73RPm7z5Mf u3iLdlHA1q7M1oaSPZ9Hi6hTsBlht2ivdyHmgyuQK3OHLCkaHPaEhvN/2DhfpLwj iC2fLCJxXUQ5pjBuzL94webu46b4vytRCAhS -----END CERTIFICATE----- subject=/C=GB/O=Fidelity International/CN=crwsdv2 issuer=/C=GB/O=Fidelity International/CN=crwsdv2 --- No client certificate CA names sent --- SSL handshake has read 1074 bytes and written 311 bytes --- New, TLSv1/SSLv3, Cipher is EDH-RSA-DES-CBC3-SHA Server public key is 1024 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE SSL-Session: Protocol : TLSv1 Cipher : EDH-RSA-DES-CBC3-SHA Session-ID: 4DAC1F41B3940F833A4BF8C960B311E939E9CCC1928E96FA34549096F5AC663A Session-ID-ctx: Master-Key: 6D772C94415ADC029C7D15A782A7EE3E20CE81E80FC76258595525F94775F366E23982B1C0978CA94CBFC1B3E2825462 Key-Arg : None Krb5 Principal: None Start Time: 1303125825 Timeout : 300 (sec) Verify return code: 18 (self signed certificate) --- DONE >>> TLS 1.0 Alert [length 0002], warning close_notify 01 00