2021-10-02T23:11:30 unbound[38176] [38176:0] error: ssl handshake failed crypto error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed2021-10-02T23:11:30 unbound[38176] [38176:0] notice: ssl handshake failed 91.239.100.100 port 853
:~> dog google.com --tls @91.239.100.100:853Error [tls]: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:1914: (IP address mismatch)
:~> dog google.com --tls @9.9.9.9:853A google.com. 1m58s 142.250.187.238
echo | openssl s_client -connect 91.239.100.100:853 --showcerts
---Certificate chain 0 s:CN = rgnet-iad.anycast.censurfridns.dk i:C = US, O = Let's Encrypt, CN = R3-----BEGIN CERTIFICATE-----MIIFcTCCBFmgAwIBAgISBGl25rZca1TDey9ke6sjhSuDMA0GCSqGSIb3DQEBCwUAMDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQDEwJSMzAeFw0yMTA4MjYyMDUwNTZaFw0yMTExMjQyMDUwNTVaMCwxKjAoBgNVBAMTIXJnbmV0LWlhZC5hbnljYXN0LmNlbnN1cmZyaWRucy5kazB2MBAGByqGSM49AgEGBSuBBAAiA2IABCm2DNXRZevNbLyJJSuJ9JJqlfegxFF1Lv5lEiG6+EjW7yBpkEtFO7f3Uj8QyYLKdOJkBzc4E84SW4nFiZm1apNdqTvyWRWVdN5U6at/Kb6nHmD2tuXKgKuQmIBolnlEg6OCAzMwggMvMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUqlt0IKeuXrYLQaQO8XkgELZB8J0wHwYDVR0jBBgwFoAUFC6zF7dYVsuuUAlA5h+vnYsUwsYwVQYIKwYBBQUHAQEESTBHMCEGCCsGAQUFBzABhhVodHRwOi8vcjMuby5sZW5jci5vcmcwIgYIKwYBBQUHMAKGFmh0dHA6Ly9yMy5pLmxlbmNyLm9yZy8wggEBBgNVHREEgfkwgfaCF2FueWNhc3QuY2Vuc3VyZnJpZG5zLmRrghdhbnljYXN0LmNlbnN1cmZyaWRucy5udYIYYW55Y2FzdC51bmNlbnNvcmVkZG5zLmRrghlhbnljYXN0LnVuY2Vuc29yZWRkbnMub3JngiFyZ25ldC1pYWQuYW55Y2FzdC5jZW5zdXJmcmlkbnMuZGuCIXJnbmV0LWlhZC5hbnljYXN0LmNlbnN1cmZyaWRucy5udYIicmduZXQtaWFkLmFueWNhc3QudW5jZW5zb3JlZGRucy5ka4IjcmduZXQtaWFkLmFueWNhc3QudW5jZW5zb3JlZGRucy5vcmcwTAYDVR0gBEUwQzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYaaHR0cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdgD2XJQv0XcwIhRUGAgwlFaO400TGTO/3wwvIAvMTvFk4wAAAXuEcdDQAAAEAwBHMEUCIQDayjoq3M4yWH4VKgpm4XHyo94BMbURJsO4xWjOGvrybQIgFDw/p2p7xcyw88TKHWLPXemNaGpL9Hx8opTzoZw6hb8AdgCUILwejtWNbIhzH4KLIiwN0dpNXmxPlD1h204vWE2iwgAAAXuEcdDVAAAEAwBHMEUCIQCu/BwR/jMGDIJ6g18ebi70xMrf016MjqUl/ztKQv0pmwIgQ3d2xYM/PxFu69e6/kTkl7rSJAVfCU3s+CkrIymIGw8wDQYJKoZIhvcNAQELBQADggEBAFbWt5P7+1XFRXQlk5JGaKK03Zu8bQZMCnidU5sylEQj4tFA+S7KMd6xPkGwG7Ee+ySmzObUW4sdbY2TP5n5T/mIQ/yZmVS+fcwdFPNtSXTzViRPuhHWmJU4i/KoR8kDp5lBdUVeRMdw8tp8ZmLlM2BpNhojRvfSRQ0KHVt93AenLa2phBoSsm+WkgkP4O2McUyY/P8cIKqNCS+xoPjIbuRuC8bYfNVZC1R9xvhq+rk57J/DXZT6fKwYZkoV3UkXK9YjkAcAaDAdo6BlrNYi1sg3scxt1hJlWUz3VMizEj7aSBxMhtObp2jGSRsvhvbg2IUAxVt5+dAHRMUSB4G8Y4M=-----END CERTIFICATE----- 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1-----BEGIN CERTIFICATE-----MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAwTzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2VhcmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAwWhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3MgRW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cPR5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdxsxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8ZutmNHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxgZ3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaAFHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcwAoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRwOi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQBgt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6WPTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wlikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQzCkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BImlJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1OyK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90IdshCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6ZvMldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqXnLRbwHOoq7hHwg==-----END CERTIFICATE----- 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1 i:O = Digital Signature Trust Co., CN = DST Root CA X3-----BEGIN CERTIFICATE-----MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMTDkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1owTzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2VhcmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XCov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpLwYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+DLtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5ysR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZXmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBcSLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2qlPRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TNDTwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwSwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEBATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQub3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9EU1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26ZtuMA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuGWCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9Ohe8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFCDfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5-----END CERTIFICATE--------Server certificatesubject=CN = rgnet-iad.anycast.censurfridns.dkissuer=C = US, O = Let's Encrypt, CN = R3---No client certificate CA names sentPeer signing digest: SHA384Peer signature type: ECDSAServer Temp Key: X25519, 253 bits---SSL handshake has read 4496 bytes and written 375 bytesVerification error: certificate has expired---New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384Server public key is 384 bitSecure Renegotiation IS NOT supportedCompression: NONEExpansion: NONENo ALPN negotiatedEarly data was not sentVerify return code: 10 (certificate has expired)---
..<same certs as above snipped>..Server certificatesubject=CN = rgnet-iad.anycast.censurfridns.dkissuer=C = US, O = Let's Encrypt, CN = R3---No client certificate CA names sentPeer signing digest: SHA384Peer signature type: ECDSAServer Temp Key: X25519, 253 bits---SSL handshake has read 4495 bytes and written 381 bytesVerification: OK---New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384Server public key is 384 bitSecure Renegotiation IS NOT supportedCompression: NONEExpansion: NONENo ALPN negotiatedEarly data was not sentVerify return code: 0 (ok)---
git clone --depth 1 https://github.com/drwetter/testssl.sh.gitcd testssl.shmount -t fdescfs fdesc /dev/fd./testssl.sh --fast 91.239.100.100:853
... Server Certificate #1 (in response to request w/o SNI) Signature Algorithm SHA256 with RSA Server key size RSA 4096 bits (exponent is 65537) Server key usage Digital Signature, Key Encipherment Server extended key usage TLS Web Server Authentication, TLS Web Client Authentication Serial / Fingerprints 031A211648897F4AB8464EB2CA7356E3AC3F / SHA1 436C8F12BD9784FABD951D036311396C647D1524 SHA256 F9EAADFD781155620C1295C34E2E504E574597E77451D3EDF2C04D43E54B575F Common Name (CN) rgnet-iad.anycast.censurfridns.dk subjectAltName (SAN) anycast.censurfridns.dk anycast.censurfridns.nu anycast.uncensoreddns.dk anycast.uncensoreddns.org rgnet-iad.anycast.censurfridns.dk rgnet-iad.anycast.censurfridns.nu rgnet-iad.anycast.uncensoreddns.dk rgnet-iad.anycast.uncensoreddns.org Trust (hostname) certificate does not match supplied URI Chain of trust Ok EV cert (experimental) no Certificate Validity (UTC) 52 >= 30 days (2021-08-26 20:50 --> 2021-11-24 20:50) ETS/"eTLS", visibility info not present Certificate Revocation List -- OCSP URI http://r3.o.lencr.org OCSP stapling offered, not revoked OCSP must staple extension -- DNS CAA RR (experimental) not offered Certificate Transparency yes (certificate extension) Certificates provided 3 Issuer R3 (Let's Encrypt from US) Intermediate cert validity #1: ok > 40 days (2025-09-15 16:00). R3 <-- ISRG Root X1 #2: ok > 40 days (2024-09-30 18:14). ISRG Root X1 <-- DST Root CA X3 Intermediate Bad OCSP (exp.) Ok Server Certificate #2 (in response to request w/o SNI) Signature Algorithm SHA256 with RSA Server key size EC 384 bits (curve P-384) Server key usage Digital Signature Server extended key usage TLS Web Server Authentication, TLS Web Client Authentication Serial / Fingerprints 046976E6B65C6B54C37B2F647BAB23852B83 / SHA1 A0BC6997ED2AD84F1B9494FC5398517184267637 SHA256 060B69729CE6E55915EE342023756AA7FD26CE2EC11462525FD35F1E8CD30A5C Common Name (CN) rgnet-iad.anycast.censurfridns.dk subjectAltName (SAN) anycast.censurfridns.dk anycast.censurfridns.nu anycast.uncensoreddns.dk anycast.uncensoreddns.org rgnet-iad.anycast.censurfridns.dk rgnet-iad.anycast.censurfridns.nu rgnet-iad.anycast.uncensoreddns.dk rgnet-iad.anycast.uncensoreddns.org Trust (hostname) certificate does not match supplied URI Chain of trust Ok EV cert (experimental) no Certificate Validity (UTC) 52 >= 30 days (2021-08-26 20:50 --> 2021-11-24 20:50) ETS/"eTLS", visibility info not present Certificate Revocation List -- OCSP URI http://r3.o.lencr.org OCSP stapling offered, not revoked OCSP must staple extension -- DNS CAA RR (experimental) not offered Certificate Transparency yes (certificate extension) Certificates provided 3 Issuer R3 (Let's Encrypt from US) Intermediate cert validity #1: ok > 40 days (2025-09-15 16:00). R3 <-- ISRG Root X1 #2: ok > 40 days (2024-09-30 18:14). ISRG Root X1 <-- DST Root CA X3 Intermediate Bad OCSP (exp.) Ok...