Re: [openssl-users] Why construct so wierd certificate chain for one web site

2014-12-30 Thread Matt Caswell
On 29/12/14 10:00, Jerry OELoo wrote: > Thanks Jeffrey & Matt > > Now I have a more question, I do not want to make code use tlsv1 > method and SSL_set_tlsext_host_name to query all website, I just want > to when encounter this issue, then I will construct tlsv1 and set sni > name to query certi

Re: [openssl-users] Why construct so wierd certificate chain for one web site

2014-12-29 Thread Jerry OELoo
Thanks Jeffrey & Matt Now I have a more question, I do not want to make code use tlsv1 method and SSL_set_tlsext_host_name to query all website, I just want to when encounter this issue, then I will construct tlsv1 and set sni name to query certificate, So how can I get this kind of information, o

Re: [openssl-users] Why construct so wierd certificate chain for one web site

2014-12-29 Thread Matt Caswell
On 29/12/14 08:32, Jerry OELoo wrote: > Hi. > I am using X509_STORE_CTX_get1_chain() to construct certificate chain > base on local root ca store. Now it works fine. > > But when I access this website, https://www.sgetvous.societegenerale.fr/ > I get a very strange result. > > Peer cert subject

Re: [openssl-users] Why construct so wierd certificate chain for one web site

2014-12-29 Thread Jeffrey Walton
On Mon, Dec 29, 2014 at 3:43 AM, Jeffrey Walton wrote: > On Mon, Dec 29, 2014 at 3:32 AM, Jerry OELoo wrote: >> Hi. >> I am using X509_STORE_CTX_get1_chain() to construct certificate chain >> base on local root ca store. Now it works fine. >> >> But when I access this website, https://www.sgetvou

Re: [openssl-users] Why construct so wierd certificate chain for one web site

2014-12-29 Thread Jeffrey Walton
On Mon, Dec 29, 2014 at 3:32 AM, Jerry OELoo wrote: > Hi. > I am using X509_STORE_CTX_get1_chain() to construct certificate chain > base on local root ca store. Now it works fine. > > But when I access this website, https://www.sgetvous.societegenerale.fr/ > I get a very strange result. > > Peer c

[openssl-users] Why construct so wierd certificate chain for one web site

2014-12-29 Thread Jerry OELoo
Hi. I am using X509_STORE_CTX_get1_chain() to construct certificate chain base on local root ca store. Now it works fine. But when I access this website, https://www.sgetvous.societegenerale.fr/ I get a very strange result. Peer cert subject[/C=FR/O=GANDI SAS/CN=Gandi Standard SSL CA] depth[1] er