scheissekonfiguriert.de


28. April 2025

Kubernetes Ingress Controller Fake Certificate

$ openssl s_client -connect picture-alliance.com:443
Connecting to 35.246.153.146
CONNECTED(00000003)
depth=2 C=US, O=Internet Security Research Group, CN=ISRG Root X1
verify return:1
depth=1 C=US, O=Let's Encrypt, CN=R10
verify return:1
depth=0 CN=picture-alliance.com
verify return:1
---
Certificate chain
 0 s:CN=picture-alliance.com
   i:C=US, O=Let's Encrypt, CN=R10
   a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
   v:NotBefore: Apr 28 10:23:07 2025 GMT; NotAfter: Jul 27 10:23:06 2025 GMT
 1 s:C=US, O=Let's Encrypt, CN=R10
   i:C=US, O=Internet Security Research Group, CN=ISRG Root X1
   a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
   v:NotBefore: Mar 13 00:00:00 2024 GMT; NotAfter: Mar 12 23:59:59 2027 GMT

$ openssl s_client -connect www.picture-alliance.com:443
Connecting to 35.246.153.146
CONNECTED(00000003)
depth=0 O=Acme Co, CN=Kubernetes Ingress Controller Fake Certificate
verify error:num=18:self-signed certificate
verify return:1
depth=0 O=Acme Co, CN=Kubernetes Ingress Controller Fake Certificate
verify return:1
---
Certificate chain
 0 s:O=Acme Co, CN=Kubernetes Ingress Controller Fake Certificate
   i:O=Acme Co, CN=Kubernetes Ingress Controller Fake Certificate
   a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
   v:NotBefore: Apr  3 08:32:33 2025 GMT; NotAfter: Apr  3 08:32:33 2026 GMT

© 2013 — 2025 WofFS CC-BY-SA