• [^] # Re: HTTPS cassé ?

    Posté par . En réponse à la dépêche « Qui cherche à contrôler l'Internet ? » : la vidéo. Évalué à 2.

    Je sais pas mais le certificat de gmail me semble correcte :


    $ openssl x509 -text -noout -in www.google.com
    Certificate:
    Data:
    Version: 3 (0x2)
    Serial Number:
    01:2a:39:76:0d:3f:4f:c9:0b:e7:bd:2b:cf:95:2e:7a
    Signature Algorithm: sha1WithRSAEncryption
    Issuer: C=ZA, O=Thawte Consulting (Pty) Ltd., CN=Thawte SGC CA
    Validity
    Not Before: Mar 27 22:20:07 2009 GMT
    Not After : Mar 27 22:20:07 2010 GMT
    Subject: C=US, ST=California, L=Mountain View, O=Google Inc, CN=www.google.com
    Subject Public Key Info:
    Public Key Algorithm: rsaEncryption
    RSA Public Key: (1024 bit)
    Modulus (1024 bit):
    [ ... snip ... ]
    Exponent: 65537 (0x10001)
    X509v3 extensions:
    X509v3 Extended Key Usage:
    TLS Web Server Authentication, TLS Web Client Authentication, Netscape Server Gated Crypto
    X509v3 CRL Distribution Points:
    URI:http://crl.thawte.com/ThawteSGCCA.crl

    Authority Information Access:
    OCSP - URI:http://ocsp.thawte.com
    CA Issuers - URI:http://www.thawte.com/repository/Thawte_SGC_CA.crt

    X509v3 Basic Constraints: critical
    CA:FALSE
    Signature Algorithm: sha1WithRSAEncryption
    [ ... snip ...]

    "It was a bright cold day in April, and the clocks were striking thirteen" - Georges Orwell