Search
Duplicate

openssl 명령어 예제

C:\Program Files\OpenSSL-Win64\bin>openssl s_client -connect host:port
[example]
C:\Program Files\OpenSSL-Win64\bin>openssl s_client -connect mail.parkjw.in:587
CONNECTED(00000198)
depth=1 C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN = mail.parkjw.in
verify return:1
---
Certificate chain
0 s:CN = mail.parkjw.in
i:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
1 s:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
i:O = Digital Signature Trust Co., CN = DST Root CA X3
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFcjCCBFqgAwIBAgISA6I4ultc/zK+SZFCE6lpw80MMA0GCSqGSIb3DQEBCwUA
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0yMDA4MjMxMzU0MjVaFw0y
MDExMjExMzU0MjVaMBkxFzAVBgNVBAMTDm1haWwucGFya2p3LmluMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0f/MPnTFiF5QDuKATYrj0pPkA4fasRGi
q7GuBozfcHZyodrlqx4HhZccJkjhbIMsz1Gfu/TiJjFEG+DBEoMOivjJobtf5FOI
mfCerEha8C+prgbgpW1gVlYW66Kua73KQpS7Y+TSuOqR6gbNe0QuHXImLWUMaN8c
jXvfjaiXgF7Thi5nQRMplGkadhGDFcEpQx5W6znXiH+xKHj3GEZ2DeO+TK5Hhn56
e7dRYX8DtRWNsZeSttAJhfFhMbl2lVG51ywvqMWKT0IeSww3+Y0fP/oC5gmRH8Br
DaHgnVNoF0GYcCCDW9n3T0TfNnmCfSeEAfATqumb6ocPNa2Y8+yAUwIDAQABo4IC
gTCCAn0wDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF
BQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSOcn916Y+M7HpoSVjebL4KusOg
yDAfBgNVHSMEGDAWgBSoSmpjBH3duubRObemRWXv86jsoTBvBggrBgEFBQcBAQRj
MGEwLgYIKwYBBQUHMAGGImh0dHA6Ly9vY3NwLmludC14My5sZXRzZW5jcnlwdC5v
cmcwLwYIKwYBBQUHMAKGI2h0dHA6Ly9jZXJ0LmludC14My5sZXRzZW5jcnlwdC5v
cmcvMDYGA1UdEQQvMC2CDWRldi5wYXJrancuaW6CDG1haWwuZGV2ai5pboIObWFp
bC5wYXJrancuaW4wTAYDVR0gBEUwQzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEw
KDAmBggrBgEFBQcCARYaaHR0cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEFBgor
BgEEAdZ5AgQCBIH2BIHzAPEAdgDwlaRZ8gDRgkAQLS+TiI6tS/4dR+OZ4dA0prCo
qo6ycwAAAXQb0DlvAAAEAwBHMEUCIDmOwIhacqKrhHvpUSBMgzgkcta1GLiJ8FTB
6vGq4z/lAiEA2+M17p+asEjSsClZm95UmxOqZawBzdDDKfCF5s/0d7gAdwCyHgXM
i6LNiiBOh2b5K7mKJSBna9r6cOeySVMt74uQXgAAAXQb0DmNAAAEAwBIMEYCIQCy
3PI9CUhPjG0PGBEiLMKhEqo8oVo1fq+MGxYAw7KwfQIhAP9SpdBQSWXO5BpTPMce
YcLBYC6M9ppt8bYsu23maI1JMA0GCSqGSIb3DQEBCwUAA4IBAQBA5egHfC4Qrtgh
PJpjo8ag8g8LLl48RfzQorAU9jk9xz9viyl8tQpEZ3mH8OkDz2Fogmerh5Y21KmN
5aIm4OAmPNKgnNSXKIAVgg/NcAN7QyXbFDxxuZmz5ChHTrmawy9Wk4fLDX5Eqfa/
cuwlLPxnNp5sWRysqYIZnh25SQH2fFZp59GWzfs/6dnhJ/63a1i3tvhHjS8eoihJ
DyfawJ4vWT7bvqCOlLC0xijevDJ2oFAIxX6IPiH4X5uVb847ACqkFVfeAaO3AxmN
MXVVL5H+ZpAQbhCsCPlCo66hSZHgmdrPmhCXymccrfrzyddk2kYdYfYnnfsw3K0C
KC7PdM2v
-----END CERTIFICATE-----
subject=CN = mail.parkjw.in
issuer=C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 3450 bytes and written 850 bytes
Verification error: unable to get local issuer certificate
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 2048 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 20 (unable to get local issuer certificate)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol  : TLSv1.3
Cipher    : TLS_AES_256_GCM_SHA384
Session-ID: BA000F4BFC00D86EE02ACBA40B51A86EDCF2095241DDCFC8BCA5E5F91324598C
Session-ID-ctx:
Resumption PSK: A159C5B3E6088DBBD283C4234F755FDAC1F9B544FA381DEFAE2B2590315C598840F092EC242CF55D4E903F5DE1CFCB9C
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 86400 (seconds)
TLS session ticket:
0000 - 15 07 7f bb 5a 6a d1 64-53 ac a3 6e 7a c4 36 4a   ....Zj.dS..nz.6J
0010 - c6 c1 04 b5 74 43 f7 8b-40 34 38 6d 5b 4b 4a e1   ....tC..@48m[KJ.
Start Time: 1599118253
Timeout   : 7200 (sec)
Verify return code: 20 (unable to get local issuer certificate)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
220 parkjw.in SMTP Server (Crinity Message Backbone-5.9.6) ready Thu, 3 Sep 2020 16:30:53 +0900 (KST)
HELO 블라블라