[Cryptography] nytimes.com switches to https

Viktor Dukhovni cryptography at dukhovni.org
Tue Jan 10 23:59:40 EST 2017


On Tue, Jan 10, 2017 at 07:18:00PM -0700, John Denker wrote:

> More-or-less everybody else seems not to care.
> -- npr.org has an invalid certificate

The npr.org certificate looks good when I connect, however the
HTTPS site redirects to HTTP.

    $ (sleep 3; exit) | 
	openssl s_client -showcerts -connect www.npr.org:443 2>&1 |
	openssl crl2pkcs7 -nocrl -certfile /dev/stdin |
	openssl pkcs7 -print_certs -text |
	tee /tmp/npr.pem
    ...

    $ openssl verify -untrusted /tmp/npr.pem -trusted /tmp/root.pem /tmp/npr.pem
    /tmp/npr.pem: OK

The npr.org chain and root CA PEM files attached.

-- 
	Viktor.
-------------- next part --------------
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            2e:a1:12:ca:76:09:4e:97:a2:5d:0c:97:22:2c:a6:08
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=GeoTrust Inc., CN=GeoTrust SSL CA - G3
        Validity
            Not Before: Nov 11 00:00:00 2016 GMT
            Not After : Dec 11 23:59:59 2017 GMT
        Subject: C=US, ST=District Of Columbia, L=Washington, O=National Public Radio, Inc., OU=Digital Media, CN=*.npr.org
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:e2:5b:83:c1:05:b2:a5:c5:cc:84:8e:9d:24:24:
                    bf:5b:6b:a9:78:e9:fe:65:02:c5:9f:90:90:ea:ea:
                    2c:2b:0c:8e:88:eb:81:0b:ce:76:43:65:8d:6c:41:
                    d0:47:b5:f0:31:f0:72:c5:2d:fd:53:8c:35:94:0d:
                    97:98:7c:53:c0:d6:3e:64:af:be:63:18:84:e8:47:
                    5b:ab:a0:79:bc:1c:30:be:9f:77:b8:c0:ac:ad:c3:
                    8a:91:46:c7:d8:c1:cc:e3:0d:e2:fa:8c:54:eb:8a:
                    a9:76:78:ed:40:39:2a:ac:da:13:73:98:f2:27:25:
                    d7:b2:d9:2e:7c:07:fd:2b:0d:d5:17:ac:3a:1d:73:
                    0a:89:3c:62:71:0a:04:1d:a0:a8:0e:55:7b:d2:b2:
                    ae:d8:06:19:83:44:6b:a0:3f:e5:29:0e:bd:77:06:
                    f2:d1:bf:8e:2a:af:8e:30:aa:ee:1a:69:b7:71:a8:
                    08:52:5d:1f:2b:2f:ee:f9:fe:51:d3:38:ad:2d:7f:
                    13:64:af:a7:62:7d:e0:77:27:85:27:62:98:68:9d:
                    28:aa:83:e9:3d:67:2d:c6:ea:99:02:ef:31:ff:ad:
                    db:79:51:fe:94:7d:46:2e:5d:03:17:6c:43:e2:95:
                    27:58:87:f1:91:10:c5:4f:fe:01:cc:7b:1c:0f:ff:
                    44:0b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Alternative Name: 
                DNS:*.npr.org, DNS:npr.org
            X509v3 Basic Constraints: 
                CA:FALSE
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 CRL Distribution Points: 
                URI:http://gn.symcb.com/gn.crl

            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.2
                  CPS: https://www.geotrust.com/resources/repository/legal
                  User Notice:
                    Explicit Text: https://www.geotrust.com/resources/repository/legal

            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Authority Key Identifier: 
                keyid:D2:6F:F7:96:F4:85:3F:72:3C:30:7D:23:DA:85:78:9B:A3:7C:5A:7C

            Authority Information Access: 
                OCSP - URI:http://gn.symcd.com
                CA Issuers - URI:http://gn.symcb.com/gn.crt

            1.3.6.1.4.1.11129.2.4.2: 
                ......w....+z
O. ....hp~.....\..=..........XT.A......H0F.!....}s.W..y.......*..D.. at .#55...h.!..m..@=...t*V..v.t.....2.?*.......v.h....d..:...(.L.qQ]g..D.
g..OO.....XT.B......G0E. ..;I`..+.fC.D+u(.\.Sk.2.......QI.!............I.......u at ..r..xq...a
    Signature Algorithm: sha256WithRSAEncryption
        81:a7:f1:34:0d:01:e6:57:ee:ee:02:b8:fa:fc:23:b1:23:3d:
        3d:23:9d:d7:47:b1:59:02:30:79:e3:e7:28:06:9f:6f:7b:53:
        50:05:50:a2:ca:f0:16:eb:21:1c:b3:c5:37:e3:5c:71:9f:7c:
        53:5d:e3:60:89:db:62:53:b0:9d:16:7b:bd:9d:1b:0f:2d:20:
        d2:92:15:10:99:cb:c2:ff:55:02:3a:f2:39:b9:e5:d8:90:5e:
        9b:c9:39:5d:f4:b5:88:15:0c:32:e8:2a:a8:1a:52:3a:95:e9:
        ba:80:b5:a5:d9:12:f8:e0:5a:3c:a5:2f:ea:d1:cb:d5:06:fc:
        c5:90:66:e2:6d:39:b5:7f:90:63:1c:45:c8:57:95:8e:92:d9:
        42:95:81:02:9f:28:cd:36:2f:a3:0c:1c:9c:60:68:2e:bd:49:
        f1:4b:23:3b:0c:7d:86:db:95:b4:c9:0b:36:99:65:44:50:08:
        2b:e2:c0:eb:f8:96:09:35:3a:f2:03:57:98:72:ca:63:f1:3c:
        91:31:ff:22:5c:0d:06:cd:5e:d9:68:86:00:d9:57:43:a9:d2:
        61:fb:3a:1b:ca:e1:93:6b:1c:0a:56:83:9e:46:1b:f8:4c:8e:
        8e:e1:94:a5:7e:ce:23:45:26:9a:f8:77:84:17:f6:e8:2d:36:
        01:e1:16:45
-----BEGIN CERTIFICATE-----
MIIGETCCBPmgAwIBAgIQLqESynYJTpeiXQyXIiymCDANBgkqhkiG9w0BAQsFADBE
MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEdMBsGA1UEAxMU
R2VvVHJ1c3QgU1NMIENBIC0gRzMwHhcNMTYxMTExMDAwMDAwWhcNMTcxMjExMjM1
OTU5WjCBkzELMAkGA1UEBhMCVVMxHTAbBgNVBAgMFERpc3RyaWN0IE9mIENvbHVt
YmlhMRMwEQYDVQQHDApXYXNoaW5ndG9uMSQwIgYDVQQKDBtOYXRpb25hbCBQdWJs
aWMgUmFkaW8sIEluYy4xFjAUBgNVBAsMDURpZ2l0YWwgTWVkaWExEjAQBgNVBAMM
CSoubnByLm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOJbg8EF
sqXFzISOnSQkv1trqXjp/mUCxZ+QkOrqLCsMjojrgQvOdkNljWxB0Ee18DHwcsUt
/VOMNZQNl5h8U8DWPmSvvmMYhOhHW6ugebwcML6fd7jArK3DipFGx9jBzOMN4vqM
VOuKqXZ47UA5KqzaE3OY8icl17LZLnwH/SsN1ResOh1zCok8YnEKBB2gqA5Ve9Ky
rtgGGYNEa6A/5SkOvXcG8tG/jiqvjjCq7hppt3GoCFJdHysv7vn+UdM4rS1/E2Sv
p2J94HcnhSdimGidKKqD6T1nLcbqmQLvMf+t23lR/pR9Ri5dAxdsQ+KVJ1iH8ZEQ
xU/+Acx7HA//RAsCAwEAAaOCAq0wggKpMB0GA1UdEQQWMBSCCSoubnByLm9yZ4IH
bnByLm9yZzAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDArBgNVHR8EJDAiMCCg
HqAchhpodHRwOi8vZ24uc3ltY2IuY29tL2duLmNybDCBnQYDVR0gBIGVMIGSMIGP
BgZngQwBAgIwgYQwPwYIKwYBBQUHAgEWM2h0dHBzOi8vd3d3Lmdlb3RydXN0LmNv
bS9yZXNvdXJjZXMvcmVwb3NpdG9yeS9sZWdhbDBBBggrBgEFBQcCAjA1DDNodHRw
czovL3d3dy5nZW90cnVzdC5jb20vcmVzb3VyY2VzL3JlcG9zaXRvcnkvbGVnYWww
HQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB8GA1UdIwQYMBaAFNJv95b0
hT9yPDB9I9qFeJujfFp8MFcGCCsGAQUFBwEBBEswSTAfBggrBgEFBQcwAYYTaHR0
cDovL2duLnN5bWNkLmNvbTAmBggrBgEFBQcwAoYaaHR0cDovL2duLnN5bWNiLmNv
bS9nbi5jcnQwggEFBgorBgEEAdZ5AgQCBIH2BIHzAPEAdwDd6x0reg1PpiCLga2B
aHB+Lo6dAdVciI09EcTNtuy+zAAAAVhU3kH/AAAEAwBIMEYCIQCCkYZ9c9lXHAt5
rH/1vuOyyCrN6EQaD0D5IzU1F/yTaAIhAONt2axAPdHi8HQqVgS0dqN0yZeiC5ky
4D8qs+nYkaKSAHYAaPaY+B9kgr46jO65KB1M/HFRXWeT1ETRCmesu09P+8QAAAFY
VN5CFAAABAMARzBFAiAA4TtJYNwOK4FmQ5NEK3Uo31z0U2u1MhiLzsQTkbxRSQIh
AN3r5QGPsRULwqjjSR8cAQ6e3uh1QIYdcq3seHET2/1hMA0GCSqGSIb3DQEBCwUA
A4IBAQCBp/E0DQHmV+7uArj6/COxIz09I53XR7FZAjB54+coBp9ve1NQBVCiyvAW
6yEcs8U341xxn3xTXeNgidtiU7CdFnu9nRsPLSDSkhUQmcvC/1UCOvI5ueXYkF6b
yTld9LWIFQwy6CqoGlI6lem6gLWl2RL44Fo8pS/q0cvVBvzFkGbibTm1f5BjHEXI
V5WOktlClYECnyjNNi+jDBycYGguvUnxSyM7DH2G25W0yQs2mWVEUAgr4sDr+JYJ
NTryA1eYcspj8TyRMf8iXA0GzV7ZaIYA2VdDqdJh+zobyuGTaxwKVoOeRhv4TI6O
4ZSlfs4jRSaa+HeEF/boLTYB4RZF
-----END CERTIFICATE-----

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 146031 (0x23a6f)
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
        Validity
            Not Before: Nov  5 21:36:50 2013 GMT
            Not After : May 20 21:36:50 2022 GMT
        Subject: C=US, O=GeoTrust Inc., CN=GeoTrust SSL CA - G3
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:e3:be:7e:0a:86:a3:cf:6b:6d:3d:2b:a1:97:ad:
                    49:24:4d:d7:77:b9:34:79:08:a5:9e:a2:9e:de:47:
                    12:92:3d:7e:ea:19:86:b1:e8:4f:3d:5f:f7:d0:a7:
                    77:9a:5b:1f:0a:03:b5:19:53:db:a5:21:94:69:63:
                    9d:6a:4c:91:0c:10:47:be:11:fa:6c:86:25:b7:ab:
                    04:68:42:38:09:65:f0:14:da:19:9e:fa:6b:0b:ab:
                    62:ef:8d:a7:ef:63:70:23:a8:af:81:f3:d1:6e:88:
                    67:53:ec:12:a4:29:75:8a:a7:f2:57:3d:a2:83:98:
                    97:f2:0a:7d:d4:e7:43:6e:30:78:62:22:59:59:b8:
                    71:27:45:aa:0f:66:c6:55:3f:fa:32:17:2b:31:8f:
                    46:a0:fa:69:14:7c:9d:9f:5a:e2:eb:33:4e:10:a6:
                    b3:ed:77:63:d8:c3:9e:f4:dd:df:79:9a:7a:d4:ee:
                    de:dd:9a:cc:c3:b7:a9:5d:cc:11:3a:07:bb:6f:97:
                    a4:01:23:47:95:1f:a3:77:fa:58:92:c6:c7:d0:bd:
                    cf:93:18:42:b7:7e:f7:9e:65:ea:d5:3b:ca:ed:ac:
                    c5:70:a1:fe:d4:10:9a:f0:12:04:44:ac:1a:5b:78:
                    50:45:57:4c:6f:bd:80:cb:81:5c:2d:b3:bc:76:a1:
                    1e:65
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:C0:7A:98:68:8D:89:FB:AB:05:64:0C:11:7D:AA:7D:65:B8:CA:CC:4E

            X509v3 Subject Key Identifier: 
                D2:6F:F7:96:F4:85:3F:72:3C:30:7D:23:DA:85:78:9B:A3:7C:5A:7C
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 CRL Distribution Points: 
                URI:http://g1.symcb.com/crls/gtglobal.crl

            Authority Information Access: 
                OCSP - URI:http://g2.symcb.com

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.113733.1.7.54
                  CPS: http://www.geotrust.com/resources/cps

            X509v3 Subject Alternative Name: 
                DirName:/CN=SymantecPKI-1-539
    Signature Algorithm: sha256WithRSAEncryption
        a0:d4:f7:2c:fb:74:0b:7f:64:f1:cd:43:6a:9f:62:53:1c:02:
        7c:98:90:a2:ee:4f:68:d4:20:1a:73:12:3e:77:b3:50:eb:72:
        bc:ee:88:be:7f:17:ea:77:8f:83:61:95:4f:84:a1:cb:32:4f:
        6c:21:be:d2:69:96:7d:63:bd:dc:2b:a8:1f:d0:13:84:70:fe:
        f6:35:95:89:f9:a6:77:b0:46:c8:bb:b7:13:f5:c9:60:69:d6:
        4c:fe:d2:8e:ef:d3:60:c1:80:80:e1:e7:fb:8b:6f:21:79:4a:
        e0:dc:a9:1b:c1:b7:fb:c3:49:59:5c:b5:77:07:44:d4:97:fc:
        49:00:89:6f:06:4e:01:70:19:ac:2f:11:c0:e2:e6:0f:2f:86:
        4b:8d:7b:c3:b9:a7:2e:f4:f1:ac:16:3e:39:49:51:9e:17:4b:
        4f:10:3a:5b:a5:a8:92:6f:fd:fa:d6:0b:03:4d:47:56:57:19:
        f3:cb:6b:f5:f3:d6:cf:b0:f5:f5:a3:11:d2:20:53:13:34:37:
        05:2c:43:5a:63:df:8d:40:d6:85:1e:51:e9:51:17:1e:03:56:
        c9:f1:30:ad:e7:9b:11:a2:b9:d0:31:81:9b:68:b1:d9:e8:f3:
        e6:94:7e:c7:ae:13:2f:87:ed:d0:25:b0:68:f9:de:08:5a:f3:
        29:cc:d4:92
-----BEGIN CERTIFICATE-----
MIIETzCCAzegAwIBAgIDAjpvMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNVBAYTAlVT
MRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJHZW9UcnVzdCBHbG9i
YWwgQ0EwHhcNMTMxMTA1MjEzNjUwWhcNMjIwNTIwMjEzNjUwWjBEMQswCQYDVQQG
EwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEdMBsGA1UEAxMUR2VvVHJ1c3Qg
U1NMIENBIC0gRzMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDjvn4K
hqPPa209K6GXrUkkTdd3uTR5CKWeop7eRxKSPX7qGYax6E89X/fQp3eaWx8KA7UZ
U9ulIZRpY51qTJEMEEe+EfpshiW3qwRoQjgJZfAU2hme+msLq2LvjafvY3AjqK+B
89FuiGdT7BKkKXWKp/JXPaKDmJfyCn3U50NuMHhiIllZuHEnRaoPZsZVP/oyFysx
j0ag+mkUfJ2fWuLrM04QprPtd2PYw5703d95mnrU7t7dmszDt6ldzBE6B7tvl6QB
I0eVH6N3+liSxsfQvc+TGEK3fveeZerVO8rtrMVwof7UEJrwEgRErBpbeFBFV0xv
vYDLgVwts7x2oR5lAgMBAAGjggFKMIIBRjAfBgNVHSMEGDAWgBTAephojYn7qwVk
DBF9qn1luMrMTjAdBgNVHQ4EFgQU0m/3lvSFP3I8MH0j2oV4m6N8WnwwEgYDVR0T
AQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwNgYDVR0fBC8wLTAroCmgJ4Yl
aHR0cDovL2cxLnN5bWNiLmNvbS9jcmxzL2d0Z2xvYmFsLmNybDAvBggrBgEFBQcB
AQQjMCEwHwYIKwYBBQUHMAGGE2h0dHA6Ly9nMi5zeW1jYi5jb20wTAYDVR0gBEUw
QzBBBgpghkgBhvhFAQc2MDMwMQYIKwYBBQUHAgEWJWh0dHA6Ly93d3cuZ2VvdHJ1
c3QuY29tL3Jlc291cmNlcy9jcHMwKQYDVR0RBCIwIKQeMBwxGjAYBgNVBAMTEVN5
bWFudGVjUEtJLTEtNTM5MA0GCSqGSIb3DQEBCwUAA4IBAQCg1Pcs+3QLf2TxzUNq
n2JTHAJ8mJCi7k9o1CAacxI+d7NQ63K87oi+fxfqd4+DYZVPhKHLMk9sIb7SaZZ9
Y73cK6gf0BOEcP72NZWJ+aZ3sEbIu7cT9clgadZM/tKO79NgwYCA4ef7i28heUrg
3Kkbwbf7w0lZXLV3B0TUl/xJAIlvBk4BcBmsLxHA4uYPL4ZLjXvDuacu9PGsFj45
SVGeF0tPEDpbpaiSb/361gsDTUdWVxnzy2v189bPsPX1oxHSIFMTNDcFLENaY9+N
QNaFHlHpURceA1bJ8TCt55sRornQMYGbaLHZ6PPmlH7HrhMvh+3QJbBo+d4IWvMp
zNSS
-----END CERTIFICATE-----

-------------- next part --------------
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 144470 (0x23456)
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
        Validity
            Not Before: May 21 04:00:00 2002 GMT
            Not After : May 21 04:00:00 2022 GMT
        Subject: C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:da:cc:18:63:30:fd:f4:17:23:1a:56:7e:5b:df:
                    3c:6c:38:e4:71:b7:78:91:d4:bc:a1:d8:4c:f8:a8:
                    43:b6:03:e9:4d:21:07:08:88:da:58:2f:66:39:29:
                    bd:05:78:8b:9d:38:e8:05:b7:6a:7e:71:a4:e6:c4:
                    60:a6:b0:ef:80:e4:89:28:0f:9e:25:d6:ed:83:f3:
                    ad:a6:91:c7:98:c9:42:18:35:14:9d:ad:98:46:92:
                    2e:4f:ca:f1:87:43:c1:16:95:57:2d:50:ef:89:2d:
                    80:7a:57:ad:f2:ee:5f:6b:d2:00:8d:b9:14:f8:14:
                    15:35:d9:c0:46:a3:7b:72:c8:91:bf:c9:55:2b:cd:
                    d0:97:3e:9c:26:64:cc:df:ce:83:19:71:ca:4e:e6:
                    d4:d5:7b:a9:19:cd:55:de:c8:ec:d2:5e:38:53:e5:
                    5c:4f:8c:2d:fe:50:23:36:fc:66:e6:cb:8e:a4:39:
                    19:00:b7:95:02:39:91:0b:0e:fe:38:2e:d1:1d:05:
                    9a:f6:4d:3e:6f:0f:07:1d:af:2c:1e:8f:60:39:e2:
                    fa:36:53:13:39:d4:5e:26:2b:db:3d:a8:14:bd:32:
                    eb:18:03:28:52:04:71:e5:ab:33:3d:e1:38:bb:07:
                    36:84:62:9c:79:ea:16:30:f4:5f:c0:2b:e8:71:6b:
                    e4:f9
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Subject Key Identifier: 
                C0:7A:98:68:8D:89:FB:AB:05:64:0C:11:7D:AA:7D:65:B8:CA:CC:4E
            X509v3 Authority Key Identifier: 
                keyid:C0:7A:98:68:8D:89:FB:AB:05:64:0C:11:7D:AA:7D:65:B8:CA:CC:4E

    Signature Algorithm: sha1WithRSAEncryption
        35:e3:29:6a:e5:2f:5d:54:8e:29:50:94:9f:99:1a:14:e4:8f:
        78:2a:62:94:a2:27:67:9e:d0:cf:1a:5e:47:e9:c1:b2:a4:cf:
        dd:41:1a:05:4e:9b:4b:ee:4a:6f:55:52:b3:24:a1:37:0a:eb:
        64:76:2a:2e:2c:f3:fd:3b:75:90:bf:fa:71:d8:c7:3d:37:d2:
        b5:05:95:62:b9:a6:de:89:3d:36:7b:38:77:48:97:ac:a6:20:
        8f:2e:a6:c9:0c:c2:b2:99:45:00:c7:ce:11:51:22:22:e0:a5:
        ea:b6:15:48:09:64:ea:5e:4f:74:f7:05:3e:c7:8a:52:0c:db:
        15:b4:bd:6d:9b:e5:c6:b1:54:68:a9:e3:69:90:b6:9a:a5:0f:
        b8:b9:3f:20:7d:ae:4a:b5:b8:9c:e4:1d:b6:ab:e6:94:a5:c1:
        c7:83:ad:db:f5:27:87:0e:04:6c:d5:ff:dd:a0:5d:ed:87:52:
        b7:2b:15:02:ae:39:a6:6a:74:e9:da:c4:e7:bc:4d:34:1e:a9:
        5c:4d:33:5f:92:09:2f:88:66:5d:77:97:c7:1d:76:13:a9:d5:
        e5:f1:16:09:11:35:d5:ac:db:24:71:70:2c:98:56:0b:d9:17:
        b4:d1:e3:51:2b:5e:75:e8:d5:d0:dc:4f:34:ed:c2:05:66:80:
        a1:cb:e6:33
-----BEGIN CERTIFICATE-----
MIIDVDCCAjygAwIBAgIDAjRWMA0GCSqGSIb3DQEBBQUAMEIxCzAJBgNVBAYTAlVT
MRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJHZW9UcnVzdCBHbG9i
YWwgQ0EwHhcNMDIwNTIxMDQwMDAwWhcNMjIwNTIxMDQwMDAwWjBCMQswCQYDVQQG
EwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEbMBkGA1UEAxMSR2VvVHJ1c3Qg
R2xvYmFsIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2swYYzD9
9BcjGlZ+W988bDjkcbd4kdS8odhM+KhDtgPpTSEHCIjaWC9mOSm9BXiLnTjoBbdq
fnGk5sRgprDvgOSJKA+eJdbtg/OtppHHmMlCGDUUna2YRpIuT8rxh0PBFpVXLVDv
iS2Aelet8u5fa9IAjbkU+BQVNdnARqN7csiRv8lVK83Qlz6cJmTM386DGXHKTubU
1XupGc1V3sjs0l44U+VcT4wt/lAjNvxm5suOpDkZALeVAjmRCw7+OC7RHQWa9k0+
bw8HHa8sHo9gOeL6NlMTOdReJivbPagUvTLrGAMoUgRx5aszPeE4uwc2hGKceeoW
MPRfwCvocWvk+QIDAQABo1MwUTAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTA
ephojYn7qwVkDBF9qn1luMrMTjAfBgNVHSMEGDAWgBTAephojYn7qwVkDBF9qn1l
uMrMTjANBgkqhkiG9w0BAQUFAAOCAQEANeMpauUvXVSOKVCUn5kaFOSPeCpilKIn
Z57QzxpeR+nBsqTP3UEaBU6bS+5Kb1VSsyShNwrrZHYqLizz/Tt1kL/6cdjHPTfS
tQWVYrmm3ok9Nns4d0iXrKYgjy6myQzCsplFAMfOEVEiIuCl6rYVSAlk6l5PdPcF
PseKUgzbFbS9bZvlxrFUaKnjaZC2mqUPuLk/IH2uSrW4nOQdtqvmlKXBx4Ot2/Un
hw4EbNX/3aBd7YdStysVAq45pmp06drE57xNNB6pXE0zX5IJL4hmXXeXxx12E6nV
5fEWCRE11azbJHFwLJhWC9kXtNHjUStedejV0NxPNO3CBWaAocvmMw==
-----END CERTIFICATE-----


More information about the cryptography mailing list