[GH-ISSUE #1119] Demo instance: certificate expired #926

Closed
opened 2026-02-27 11:14:18 +03:00 by kerem · 1 comment
Owner

Originally created by @elsbrock on GitHub (May 6, 2017).
Original GitHub issue: https://github.com/modoboa/modoboa/issues/1119

$ openssl s_client -connect demo.modoboa.org:443           
CONNECTED(00000003)
depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
verify return:1
depth=0 CN = demo.modoboa.org
verify error:num=10:certificate has expired
notAfter=May  5 22:01:00 2017 GMT
verify return:1
depth=0 CN = demo.modoboa.org
notAfter=May  5 22:01:00 2017 GMT
verify return:1
---
Certificate chain
 0 s:/CN=demo.modoboa.org
   i:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
 1 s:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
   i:/O=Digital Signature Trust Co./CN=DST Root CA X3
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFBDCCA+ygAwIBAgISAzDwJOwWd5FMs+XrgfrdgK1QMA0GCSqGSIb3DQEBCwUA
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0xNzAyMDQyMjAxMDBaFw0x
NzA1MDUyMjAxMDBaMBsxGTAXBgNVBAMTEGRlbW8ubW9kb2JvYS5vcmcwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDG7C9zW0LIDiMgQgmkm/upT9cdlgUu
CK7gbnchpvUBpKRigfDIf422gGDZKaILntGkVNtHEYPnp5ms2TPfyA9dtAgjq2rO
GO2D86hrZhNCQ+O81qqA9kxuVAzAvPOn6LEV2IAhEIxXsCbOeu893CNYrUvTKieL
MDQHx8orCAvNCItKfFiltgM9RTG6DwvmS0/Ip29sk4fEFR6nnEApXQsRfCBkKq4g
+gUsrqT4OIfXK6VLMCNLZ5BkcAX8DMW9DuR+jAPVnX1YhribWXgmuXEwAOOcvLNN
lGmk/+YE+6Kp8hVi95/z/pcEOWjIzgYnSvVihGWQGH8GxqFnEdA1KLCTAgMBAAGj
ggIRMIICDTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsG
AQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJIEgP09iaA7F0Yv8sqNaVUC
qo3nMB8GA1UdIwQYMBaAFKhKamMEfd265tE5t6ZFZe/zqOyhMHAGCCsGAQUFBwEB
BGQwYjAvBggrBgEFBQcwAYYjaHR0cDovL29jc3AuaW50LXgzLmxldHNlbmNyeXB0
Lm9yZy8wLwYIKwYBBQUHMAKGI2h0dHA6Ly9jZXJ0LmludC14My5sZXRzZW5jcnlw
dC5vcmcvMBsGA1UdEQQUMBKCEGRlbW8ubW9kb2JvYS5vcmcwgf4GA1UdIASB9jCB
8zAIBgZngQwBAgEwgeYGCysGAQQBgt8TAQEBMIHWMCYGCCsGAQUFBwIBFhpodHRw
Oi8vY3BzLmxldHNlbmNyeXB0Lm9yZzCBqwYIKwYBBQUHAgIwgZ4MgZtUaGlzIENl
cnRpZmljYXRlIG1heSBvbmx5IGJlIHJlbGllZCB1cG9uIGJ5IFJlbHlpbmcgUGFy
dGllcyBhbmQgb25seSBpbiBhY2NvcmRhbmNlIHdpdGggdGhlIENlcnRpZmljYXRl
IFBvbGljeSBmb3VuZCBhdCBodHRwczovL2xldHNlbmNyeXB0Lm9yZy9yZXBvc2l0
b3J5LzANBgkqhkiG9w0BAQsFAAOCAQEAC6CtZ0KFksrhzmFoIHd58YMizw+pPkvl
QfnkDEoYSMnK+eXItxqdCZ874STQVXjnf+a5N7uSi3Gp/9XDp9qBo6zw+/xyDYyp
Ur+Sy/pwYHZhqj9f4w4s8newROLRysRhhPZFAZnvDuchAX7HjUW+tJU4D+SqWqfD
uHRtLgF3AvZAqn+5VkZ8FGUdyr1BI+rg3sm0PNLo4hjcM17c7Pbh/2otyts0NZ24
iyEZLZmrhNRQxGfpLv452Q0ftOj0XPBJ73qaHrrlezZE7MRxTczJsqcrxqhGRTXK
VN1ya3yqbv9nkoqvuxsniL4VuoWA6o9XFnWYHW6XAuAN2+U0L2K0DQ==
-----END CERTIFICATE-----
subject=/CN=demo.modoboa.org
issuer=/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
---
No client certificate CA names sent
Peer signing digest: SHA512
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 3135 bytes and written 302 bytes
Verification error: certificate has expired
---
New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES256-GCM-SHA384
    Session-ID: 6BD9E42FA3AD140E75D477F092E64B22721566F5AA18CE9F3E305EA8F3ABE716
    Session-ID-ctx: 
    Master-Key: 26E80D7A8356C6126BF2959010CDDE4E4DAD3A669FAC77E8CD23E8BC8D20ABCC9F29FD074A28B79D9B7DA9EBC56AB4C8
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 300 (seconds)
    TLS session ticket:
    0000 - b5 1f 5a a1 e0 a8 c1 cf-fd a8 ef 49 60 be 92 d0   ..Z........I`...
    0010 - 9a 55 01 e0 a6 31 14 7c-14 53 0d ce a5 e9 aa b1   .U...1.|.S......
    0020 - ae 1a 71 d0 87 0f df 8a-0e 04 a9 97 be 10 a9 24   ..q............$
    0030 - f4 82 e4 fd 5c 26 c0 a6-df e4 ed 71 fa 68 4f f9   ....\&.....q.hO.
    0040 - 88 44 f2 c0 66 40 a6 14-81 1d ec b2 78 0e d1 88   .D..f@......x...
    0050 - de 23 67 42 28 a6 15 6c-f6 c7 0d 71 4f a9 de a4   .#gB(..l...qO...
    0060 - fd a3 63 35 0e 1a 9a 25-83 9b 60 c5 3a a9 9c fd   ..c5...%..`.:...
    0070 - 2f 05 a0 e6 f6 a9 a0 cf-a0 3f 07 20 5e 25 7c 7f   /........?. ^%|.
    0080 - 93 14 e3 50 7e 17 3b a5-92 f7 82 2e e3 d0 2a 8c   ...P~.;.......*.
    0090 - b3 d1 ed 33 c7 91 19 ba-a0 d9 43 09 b4 38 f1 9a   ...3......C..8..
    00a0 - 95 1e c9 14 9a 65 f1 30-41 a5 cc ce 36 ec 81 87   .....e.0A...6...

    Start Time: 1494107704
    Timeout   : 7200 (sec)
    Verify return code: 10 (certificate has expired)
    Extended master secret: no
---
Originally created by @elsbrock on GitHub (May 6, 2017). Original GitHub issue: https://github.com/modoboa/modoboa/issues/1119 ``` $ openssl s_client -connect demo.modoboa.org:443 CONNECTED(00000003) depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3 verify return:1 depth=1 C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3 verify return:1 depth=0 CN = demo.modoboa.org verify error:num=10:certificate has expired notAfter=May 5 22:01:00 2017 GMT verify return:1 depth=0 CN = demo.modoboa.org notAfter=May 5 22:01:00 2017 GMT verify return:1 --- Certificate chain 0 s:/CN=demo.modoboa.org i:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3 1 s:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3 i:/O=Digital Signature Trust Co./CN=DST Root CA X3 --- Server certificate -----BEGIN CERTIFICATE----- MIIFBDCCA+ygAwIBAgISAzDwJOwWd5FMs+XrgfrdgK1QMA0GCSqGSIb3DQEBCwUA MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0xNzAyMDQyMjAxMDBaFw0x NzA1MDUyMjAxMDBaMBsxGTAXBgNVBAMTEGRlbW8ubW9kb2JvYS5vcmcwggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDG7C9zW0LIDiMgQgmkm/upT9cdlgUu CK7gbnchpvUBpKRigfDIf422gGDZKaILntGkVNtHEYPnp5ms2TPfyA9dtAgjq2rO GO2D86hrZhNCQ+O81qqA9kxuVAzAvPOn6LEV2IAhEIxXsCbOeu893CNYrUvTKieL MDQHx8orCAvNCItKfFiltgM9RTG6DwvmS0/Ip29sk4fEFR6nnEApXQsRfCBkKq4g +gUsrqT4OIfXK6VLMCNLZ5BkcAX8DMW9DuR+jAPVnX1YhribWXgmuXEwAOOcvLNN lGmk/+YE+6Kp8hVi95/z/pcEOWjIzgYnSvVihGWQGH8GxqFnEdA1KLCTAgMBAAGj ggIRMIICDTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsG AQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFJIEgP09iaA7F0Yv8sqNaVUC qo3nMB8GA1UdIwQYMBaAFKhKamMEfd265tE5t6ZFZe/zqOyhMHAGCCsGAQUFBwEB BGQwYjAvBggrBgEFBQcwAYYjaHR0cDovL29jc3AuaW50LXgzLmxldHNlbmNyeXB0 Lm9yZy8wLwYIKwYBBQUHMAKGI2h0dHA6Ly9jZXJ0LmludC14My5sZXRzZW5jcnlw dC5vcmcvMBsGA1UdEQQUMBKCEGRlbW8ubW9kb2JvYS5vcmcwgf4GA1UdIASB9jCB 8zAIBgZngQwBAgEwgeYGCysGAQQBgt8TAQEBMIHWMCYGCCsGAQUFBwIBFhpodHRw Oi8vY3BzLmxldHNlbmNyeXB0Lm9yZzCBqwYIKwYBBQUHAgIwgZ4MgZtUaGlzIENl cnRpZmljYXRlIG1heSBvbmx5IGJlIHJlbGllZCB1cG9uIGJ5IFJlbHlpbmcgUGFy dGllcyBhbmQgb25seSBpbiBhY2NvcmRhbmNlIHdpdGggdGhlIENlcnRpZmljYXRl IFBvbGljeSBmb3VuZCBhdCBodHRwczovL2xldHNlbmNyeXB0Lm9yZy9yZXBvc2l0 b3J5LzANBgkqhkiG9w0BAQsFAAOCAQEAC6CtZ0KFksrhzmFoIHd58YMizw+pPkvl QfnkDEoYSMnK+eXItxqdCZ874STQVXjnf+a5N7uSi3Gp/9XDp9qBo6zw+/xyDYyp Ur+Sy/pwYHZhqj9f4w4s8newROLRysRhhPZFAZnvDuchAX7HjUW+tJU4D+SqWqfD uHRtLgF3AvZAqn+5VkZ8FGUdyr1BI+rg3sm0PNLo4hjcM17c7Pbh/2otyts0NZ24 iyEZLZmrhNRQxGfpLv452Q0ftOj0XPBJ73qaHrrlezZE7MRxTczJsqcrxqhGRTXK VN1ya3yqbv9nkoqvuxsniL4VuoWA6o9XFnWYHW6XAuAN2+U0L2K0DQ== -----END CERTIFICATE----- subject=/CN=demo.modoboa.org issuer=/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3 --- No client certificate CA names sent Peer signing digest: SHA512 Server Temp Key: ECDH, P-256, 256 bits --- SSL handshake has read 3135 bytes and written 302 bytes Verification error: certificate has expired --- New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384 Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES256-GCM-SHA384 Session-ID: 6BD9E42FA3AD140E75D477F092E64B22721566F5AA18CE9F3E305EA8F3ABE716 Session-ID-ctx: Master-Key: 26E80D7A8356C6126BF2959010CDDE4E4DAD3A669FAC77E8CD23E8BC8D20ABCC9F29FD074A28B79D9B7DA9EBC56AB4C8 PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 300 (seconds) TLS session ticket: 0000 - b5 1f 5a a1 e0 a8 c1 cf-fd a8 ef 49 60 be 92 d0 ..Z........I`... 0010 - 9a 55 01 e0 a6 31 14 7c-14 53 0d ce a5 e9 aa b1 .U...1.|.S...... 0020 - ae 1a 71 d0 87 0f df 8a-0e 04 a9 97 be 10 a9 24 ..q............$ 0030 - f4 82 e4 fd 5c 26 c0 a6-df e4 ed 71 fa 68 4f f9 ....\&.....q.hO. 0040 - 88 44 f2 c0 66 40 a6 14-81 1d ec b2 78 0e d1 88 .D..f@......x... 0050 - de 23 67 42 28 a6 15 6c-f6 c7 0d 71 4f a9 de a4 .#gB(..l...qO... 0060 - fd a3 63 35 0e 1a 9a 25-83 9b 60 c5 3a a9 9c fd ..c5...%..`.:... 0070 - 2f 05 a0 e6 f6 a9 a0 cf-a0 3f 07 20 5e 25 7c 7f /........?. ^%|. 0080 - 93 14 e3 50 7e 17 3b a5-92 f7 82 2e e3 d0 2a 8c ...P~.;.......*. 0090 - b3 d1 ed 33 c7 91 19 ba-a0 d9 43 09 b4 38 f1 9a ...3......C..8.. 00a0 - 95 1e c9 14 9a 65 f1 30-41 a5 cc ce 36 ec 81 87 .....e.0A...6... Start Time: 1494107704 Timeout : 7200 (sec) Verify return code: 10 (certificate has expired) Extended master secret: no --- ```
kerem closed this issue 2026-02-27 11:14:18 +03:00
Author
Owner

@tonioo commented on GitHub (May 8, 2017):

Fixed, thank you.

<!-- gh-comment-id:299977531 --> @tonioo commented on GitHub (May 8, 2017): Fixed, thank you.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/modoboa-modoboa#926
No description provided.