Quantcast
Channel: Comcast XFINITY forum - dslreports.com
Viewing all articles
Browse latest Browse all 15788

MX servers using a sample certificate?

$
0
0
While checking an email server log I noticed that STARTTLS certificate verifications were OK during July, August, and much of September: STARTTLS=client, relay=mx1.comcast.net., version=TLSv1/SSLv3, verify=OK, cipher=DHE-RSA-AES256-SHA, bits=256/256STARTTLS=client, cert-subject=/C=US/2.5.4.17=19103/ST=PA/L=Philadelphia/2.5.4.9=1+20Comcast+20Center/O=Comcast+20Corporation/OU=Business+20Center/OU=Hosted+20by+20Comcast+20Corporation/OU=EliteSSL/CN=mx1.comcast.net, cert-issuer=/C=GB/ST=Greater+20Manchester/L=Salford/O=COMODO+20CA+20Limited/CN=COMODO+20High-Assurance+20Secure+20Server+20CA, verifymsg=ok-STARTTLS=client, relay=mx2.comcast.net., version=TLSv1/SSLv3, verify=OK, cipher=DHE-RSA-AES256-SHA, bits=256/256STARTTLS=client, cert-subject=/C=US/2.5.4.17=19103/ST=PA/L=Philadelphia/2.5.4.9=1+20Comcast+20Center/O=Comcast+20Corporation/OU=Business+20Center/OU=Hosted+20by+20Comcast+20Corporation/OU=EliteSSL/CN=mx2.comcast.net, cert-issuer=/C=GB/ST=Greater+20Manchester/L=Salford/O=COMODO+20CA+20Limited/CN=COMODO+20High-Assurance+20Secure+20Server+20CA, verifymsg=ok They were failing for both mx1 and mx2 by October, and continue to fail: STARTTLS=client, relay=mx1.comcast.net., version=TLSv1/SSLv3, verify=FAIL, cipher=DHE-RSA-AES256-SHA, bits=256/256STARTTLS=client, cert-subject=/C=US/O=Sample,+20Inc./OU=IT+20Team/CN=Server, cert-issuer=/C=US/O=Sample,+20Inc./OU=IT+20Team/CN=CA, verifymsg=self signed certificate in certificate chain-STARTTLS=client, relay=mx2.comcast.net., version=TLSv1/SSLv3, verify=FAIL, cipher=DHE-RSA-AES256-SHA, bits=256/256STARTTLS=client, cert-subject=/C=US/O=Sample,+20Inc./OU=IT+20Team/CN=Server, cert-issuer=/C=US/O=Sample,+20Inc./OU=IT+20Team/CN=CA, verifymsg=self signed certificate in certificate chainThis is the sample cert that is presently being served to that server, and also another unrelated server: Certificate: Data: Version: 3 (0x2) Serial Number: 2 (0x2) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=Sample, Inc., OU=IT Team, CN=CA Validity Not Before: Nov 18 14:58:26 2010 GMT Not After : Nov 15 14:58:26 2020 GMT Subject: C=US, O=Sample, Inc., OU=IT Team, CN=Server Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (1024 bit) Modulus: 00:f3:89:dd:43:f0:ad:84:1a:dd:f1:fd:2c:83:bd: ae:01:17:d8:ab:4e:02:f4:7f:85:0a:ec:70:5e:8b: 19:69:78:6c:61:b8:82:5b:dd:e8:ea:48:23:6b:9f: 68:80:76:67:34:d3:94:e7:a4:54:38:bb:72:c7:ba: da:cc:d6:cb:f8:6b:91:53:f2:be:44:61:9c:a0:64: d1:02:e8:df:5b:95:7f:ae:e3:82:d1:e7:2a:96:eb: 53:9e:17:b3:f5:d9:d1:7a:ca:dd:74:1e:97:3a:44: 54:5d:02:54:8d:f0:7b:85:39:9f:e9:a3:f3:e7:20: 14:1d:58:c9:f9:0d:63:fc:d3 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: CA:FALSE Netscape Comment: Sample server certificate, do not use on production systems! Netscape Cert Type: SSL Server X509v3 Extended Key Usage: TLS Web Server Authentication X509v3 Key Usage: Digital Signature, Key Encipherment Signature Algorithm: sha1WithRSAEncryption 38:d1:85:a8:51:8c:1b:04:a5:95:39:19:7c:6e:38:f6:e8:ef: 27:23:40:17:11:ba:bc:7a:0c:be:39:ee:f4:2b:8d:5c:5d:dd: c4:ea:54:e1:d9:fd:7c:96:b2:a0:9b:67:cd:f9:06:ed:7e:02: 8a:96:fd:f6:4d:bf:64:22:17:a5:9b:e3:33:15:7e:fe:a7:30: 53:21:55:ba:20:c5:a6:19:50:f0:d2:44:e9:a9:1c:5a:37:20: cb:26:15:da:73:ba:67:29:f3:1d:f2:69:97:31:26:92:04:f9: 6a:c3:ec:ff:6a:65:60:ef:78:54:44:7f:81:22:24:aa:e8:cd: fa:6b-----BEGIN CERTIFICATE-----MIICkTCCAfqgAwIBAgIBAjANBgkqhkiG9w0BAQUFADBDMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMU2FtcGxlLCBJbmMuMRAwDgYDVQQLEwdJVCBUZWFtMQswCQYDVQQDEwJDQTAeFw0xMDExMTgxNDU4MjZaFw0yMDExMTUxNDU4MjZaMEcxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxTYW1wbGUsIEluYy4xEDAOBgNVBAsTB0lUIFRlYW0xDzANBgNVBAMTBlNlcnZlcjCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA84ndQ/CthBrd8f0sg72uARfYq04C9H+FCuxwXosZaXhsYbiCW93o6kgja59ogHZnNNOU56RUOLtyx7razNbL+GuRU/K+RGGcoGTRAujfW5V/ruOC0ecqlutTnhez9dnResrddB6XOkRUXQJUjfB7hTmf6aPz5yAUHVjJ+Q1j/NMCAwEAAaOBkDCBjTAJBgNVHRMEAjAAMEsGCWCGSAGG+EIBDQQ+FjxTYW1wbGUgc2VydmVyIGNlcnRpZmljYXRlLCBkbyBub3QgdXNlIG9uIHByb2R1Y3Rpb24gc3lzdGVtcyEwEQYJYIZIAYb4QgEBBAQDAgZAMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQUFAAOBgQA40YWoUYwbBKWVORl8bjj26O8nI0AXEbq8egy+Oe70K41cXd3E6lTh2f18lrKgm2fN+QbtfgKKlv32Tb9kIhelm+MzFX7+pzBTIVW6IMWmGVDw0kTpqRxaNyDLJhXac7pnKfMd8mmXMSaSBPlqw+z/amVg73hURH+BIiSq6M36aw==-----END CERTIFICATE----- What are you seeing?

Viewing all articles
Browse latest Browse all 15788

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>