Hallo woodfighter,
Mein Firefox zu Hause beschwert sich übrigens, dass er die Zertifizierungsstelle nicht kennt, lieferst du das Intermediate-Zertifikat aus?
Jup:
➜ ckruse@vali ~ % openssl s_client -connect forum.selfhtml.org:443 -showcerts -CAfile ./ca.pem
CONNECTED(00000003)
depth=2 /C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Certification Authority
verify return:1
depth=1 /C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Class 2 Primary Intermediate Server CA
verify return:1
depth=0 /C=DE/ST=Nordrhein-Westfalen/L=Steinfurt/O=Christian Kruse/CN=*.selfhtml.org/emailAddress=postmaster@selfhtml.org
verify return:1
---
Certificate chain
0 s:/C=DE/ST=Nordrhein-Westfalen/L=Steinfurt/O=Christian Kruse/CN=*.selfhtml.org/emailAddress=postmaster@selfhtml.org
i:/C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Class 2 Primary Intermediate Server CA
-----BEGIN CERTIFICATE-----
…
-----END CERTIFICATE-----
1 s:/C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Class 2 Primary Intermediate Server CA
i:/C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Certification Authority
-----BEGIN CERTIFICATE-----
…
-----END CERTIFICATE-----
---
Server certificate
subject=/C=DE/ST=Nordrhein-Westfalen/L=Steinfurt/O=Christian Kruse/CN=*.selfhtml.org/emailAddress=postmaster@selfhtml.org
issuer=/C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Class 2 Primary Intermediate Server CA
---
No client certificate CA names sent
---
SSL handshake has read 4661 bytes and written 712 bytes
---
New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : DHE-RSA-AES256-SHA
Session-ID: 368644E6348D65E6CDB2C41F5A855FD8910328CEA64DF5642349A64C8CD9B09A
Session-ID-ctx:
Master-Key: F961AC3F39755EC6EEFC9FCE0C35CA183BD4B86664E7847460EE9A97C6D533AB2E4A7A9341DC160110A895D97B7420F2
Key-Arg : None
Start Time: 1441741532
Timeout : 300 (sec)
Verify return code: 0 (ok)
---
LG,
CK