[Full-disclosure] verify ssl cert command line

From: Dave King (davefd_at_davewking.com)
Date: 06/30/05

  • Next message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 733-1] New crip packages fix insecure temporary files"
    Date: Thu, 30 Jun 2005 01:32:18 -0600
    To: full-disclosure@lists.grok.org.uk
    
    

    Sorry about the messed up subject. I realized it right after I sent
    it. Anyways, thanks for the advice and I think I can use openssl
    s_client to do what I need, I had considered openssl verify but I'm
    going to have to check a bunch of certs and didn't want to have to deal
    with downloading and storing certs tempararily to check them if possible.

    Thanks,
    Dave

    Harry Hoffman wrote:

    > openssl s_client -connect host:port
    >
    > will tell you if the cert is not valid
    >
    > Dave wrote:
    >
    >> Hi All-
    >> I need a command line tool that will verify that an SSL cert is
    >> valid, much like the check a browser performs. I'm pretty sure I
    >> could hack one using the SSLeay perl module, but if one's already
    >> available, I'd rather use that. If nobody knows of one, but has some
    >> tips on how to use SSLeay or some other library to check certs then
    >> I'd appreciate any advice.
    >
    >
    >
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 733-1] New crip packages fix insecure temporary files"

    Relevant Pages

    • Re: Cipher strength
      ... The other day I had to update/renewed some of my certs ... few on server. ... What happened when you tried the advice? ... >> Unfortunately I have resorted to using Netscape ...
      (microsoft.public.security)
    • RE: LDAP SSL Problems (was: service script (/etc/init.d/ldap))
      ... The server certs are as directed ... the openssl is looking for /usr/share/ssl/openssl.cnf ... > kinit was not found. ... I don't have access to my FC4 machine at the moment - kinit part ...
      (Fedora)
    • Re: Where are the CA certificates in Solaris 10?
      ... I just want the standard CA bundle. ... The apache and apache2 cert directories are also empty. ... openssl to generate self-signed certificates or certificate signing ... Blastwave ships some certs with their version of openssl. ...
      (comp.unix.solaris)
    • OpenSSL X509_verify_cert, verifying certificates, errors
      ... I am verifying certificates with OpenSSL version 0.9.6. ... then I add all the root certs from the Microsoft root ... - unable to get local issuer certificate ...
      (sci.crypt)
    • Re: career advice
      ... > i recently got my mcsd and mcad.net. ... >advice on how to fully use these certs to get a job ... >outside my country. ...
      (microsoft.public.cert.exam.mcsd)