safihre wrote: ↑June 29th, 2017, 2:08 am
So it's an intermittent error, that's very strange. Sander, do you have a clue how that could be?
We need to read out the certificate, can you run this command:
openssl s_client -connect news-us.usenetserver.com:563
Here is the results of that command:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Program Files (x86)\F-Secure\Web User Interface\bin>openssl s_client -connect
news-us.usenetserver.com:563
Loading 'screen' into random state - done
CONNECTED(000001C8)
depth=1 /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
0 s:/CN=news.usenetserver.com
i:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
1 s:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
i:/O=Digital Signature Trust Co./CN=DST Root CA X3
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIJADCCB+igAwIBAgISBBkCKzF6RbQud9kqMlvPz1X+MA0GCSqGSIb3DQEBCwUA
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0xNzA2MjAxNjU1MDBaFw0x
NzA5MTgxNjU1MDBaMCAxHjAcBgNVBAMTFW5ld3MudXNlbmV0c2VydmVyLmNvbTCC
AiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANXuHY7jp++ptpNPBxP072xB
3RhQXAsFN0ZrcgNMJZw5gfh7t0gzZ2cZr+w3e7LgiOHToXaPV8zKx/M9YriNq472
xO7AHJU5WU75gehd1r/68ZIdS++x4D/bwhy56aGIZgrxfMoNnwtG0s4DWTV0tVlR
TB3gWV50Al8xzYVg9K1QSZBKRdTj7/+qjs7l/Zk4ULki+/xtVyksh4ll34F5WWkK
vWTMNsmSobT8ZafB6hIjDj6gLwEB+KPD8kWTegiaTNKCnRPEV8G28IZI9K3jQWrK
gbTvgQjqzxxjjxuEB8padM6mEQP/goosI49BH6eqYcDYiG6wZNILfW+rADWIyZpZ
KVR0dT0K80hFcL+B7l/hw/iJbBhFw8iOqTARdiYOVKHxMo7DchQHW0ivp3FC/V/H
98jnUQ3EUlRSrOKgFr0duNaX4vt3hirTlzxvluvW2NVS6Vfki+Yf3bPAGZN1Cyuy
LJ4lCN3nWvwGR0RthA58h4I1OZStKfA6EjRT/rQw+GdM3CPaNBA9qhXLpBlSAek3
GWZs5QX3p39JxM6WovCfpuY+pU0omkrEaB40tznmeLs0tVBpgLBCLA1JoILFw6Ce
xCACNe91B0ONQrkhasqBWT9s+4/564PVmKEF2DFBcmvlWbs2k4yyPewQ9ZFO8sKg
nTB9zsC6ZsuknZrD7L+JAgMBAAGjggUIMIIFBDAOBgNVHQ8BAf8EBAMCBaAwHQYD
VR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0O
BBYEFDC5I71EOfIbbnOHEH2s2cFnA0gxMB8GA1UdIwQYMBaAFKhKamMEfd265tE5
t6ZFZe/zqOyhMG8GCCsGAQUFBwEBBGMwYTAuBggrBgEFBQcwAYYiaHR0cDovL29j
c3AuaW50LXgzLmxldHNlbmNyeXB0Lm9yZzAvBggrBgEFBQcwAoYjaHR0cDovL2Nl
cnQuaW50LXgzLmxldHNlbmNyeXB0Lm9yZy8wggMRBgNVHREEggMIMIIDBIIVYmV0
YS51c2VuZXRzZXJ2ZXIuY29tghhjaGljYWdvLnVzZW5ldHNlcnZlci5jb22CFWVh
c3QudXNlbmV0c2VydmVyLmNvbYIXaHNwbHVzLnVzZW5ldHNlcnZlci5jb22CGmhz
cHNlY3VyZS51c2VuZXRzZXJ2ZXIuY29tghNteS51c2VuZXRzZXJ2ZXIuY29tghhu
ZXdzLWV1LnVzZW5ldHNlcnZlci5jb22CGW5ld3MtZXU2LnVzZW5ldHNlcnZlci5j
b22CGG5ld3MtdXMudXNlbmV0c2VydmVyLmNvbYIZbmV3cy11czYudXNlbmV0c2Vy
dmVyLmNvbYIZbmV3cy5hbXMudXNlbmV0c2VydmVyLmNvbYIYbmV3cy5ldS51c2Vu
ZXRzZXJ2ZXIuY29tghluZXdzLmZyNy51c2VuZXRzZXJ2ZXIuY29tghluZXdzLmlh
ZC51c2VuZXRzZXJ2ZXIuY29tghhuZXdzLnVzLnVzZW5ldHNlcnZlci5jb22CFW5l
d3MudXNlbmV0c2VydmVyLmNvbYIWbmV3czYudXNlbmV0c2VydmVyLmNvbYIVbm50
cC51c2VuZXRzZXJ2ZXIuY29tghZubnRwMS51c2VuZXRzZXJ2ZXIuY29tghdubnRw
MTAudXNlbmV0c2VydmVyLmNvbYIWbm50cDIudXNlbmV0c2VydmVyLmNvbYIWbm50
cDMudXNlbmV0c2VydmVyLmNvbYIWbm50cDQudXNlbmV0c2VydmVyLmNvbYIWbm50
cDYudXNlbmV0c2VydmVyLmNvbYIWbm50cDcudXNlbmV0c2VydmVyLmNvbYIWbm50
cDgudXNlbmV0c2VydmVyLmNvbYIWbm50cDkudXNlbmV0c2VydmVyLmNvbYIXc2Vj
dXJlLnVzZW5ldHNlcnZlci5jb22CG3NlY3VyZWJldGEudXNlbmV0c2VydmVyLmNv
bYIVdGVzdC51c2VuZXRzZXJ2ZXIuY29tghV3ZXN0LnVzZW5ldHNlcnZlci5jb20w
gf4GA1UdIASB9jCB8zAIBgZngQwBAgEwgeYGCysGAQQBgt8TAQEBMIHWMCYGCCsG
AQUFBwIBFhpodHRwOi8vY3BzLmxldHNlbmNyeXB0Lm9yZzCBqwYIKwYBBQUHAgIw
gZ4MgZtUaGlzIENlcnRpZmljYXRlIG1heSBvbmx5IGJlIHJlbGllZCB1cG9uIGJ5
IFJlbHlpbmcgUGFydGllcyBhbmQgb25seSBpbiBhY2NvcmRhbmNlIHdpdGggdGhl
IENlcnRpZmljYXRlIFBvbGljeSBmb3VuZCBhdCBodHRwczovL2xldHNlbmNyeXB0
Lm9yZy9yZXBvc2l0b3J5LzANBgkqhkiG9w0BAQsFAAOCAQEASzUDIw+ehZGITrhs
/MDkjlvFeCrnC+tpn32FA4Ypnu+50kuuEg6zkNNx//ntgrW/PMdtD31JfKeUkPmQ
p3MZN6gCAI7ssdurHDrm953ZcvK21S2bGS55MZ2wf/KdfdVtJWLkBd8xJXUn0UdQ
X57uf0D4DajDuh8tU2cmOxDBCqr6qrXXJEWCzFMDxB1612HP3fRk8KNhTiWwXMRp
i01Igmzk5FmF/MHPJTD5KoxWeUIFrlknzUA6r0IUDh02hH1P/fpQrMeGGHYS/PjG
cHKHpCxJi96ah17nVNMikXIthL+K0Pfk5G+e0GiXlrOceeiR4ivh68BUBiZfA2x7
k97UUw==
-----END CERTIFICATE-----
subject=/CN=news.usenetserver.com
issuer=/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
---
No client certificate CA names sent
---
SSL handshake has read 3647 bytes and written 706 bytes
---
New, TLSv1/SSLv3, Cipher is AES128-SHA
Server public key is 4096 bit
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : AES128-SHA
Session-ID: 27FB570371C0E25817F506271D1FBA406FB78B975A09A8DEBAFFE40017831DFA
Session-ID-ctx:
Master-Key: 01B3520FEAA3166A20B5AD45AC9A7931166E17E76CCEA452FF3EA70D880D24D9
A2D34888BCA4F1CC81953597B0525BFC
Key-Arg : None
Start Time: 1498732902
Timeout : 300 (sec)
Verify return code: 20 (unable to get local issuer certificate)
---
200 news.usenetserver.com Welcome! (fx16.iad)
The problem is not intermittent. It started out that way. Now I can no longer connect to this server without the untrusted certificate error.