How to list certificates, trusted by OpenSSL?

前端 未结 4 711
天涯浪人
天涯浪人 2020-12-13 14:34

As I understand, any software working with X.509 certificates may have own basis to decide, whether a certificate is trusted or not.

AFAIK OpenSSL just consults a l

4条回答
  •  陌清茗
    陌清茗 (楼主)
    2020-12-13 15:22

    I'm wonder if this has changed in some way since jww's response.

    If I submit: $ openssl s_client -connect google.com:443

    It works successfully, retrieves 4 total certs, and returns:

    Start Time: 1484661709
    Timeout   : 300 (sec)
    Verify return code: 0 (ok)
    

    I believe this is because servers should be setup to send, along with the certificate, any intermediate and root certificates that are needed to verify the full chain, right?

提交回复
热议问题