sslscan icon indicating copy to clipboard operation
sslscan copied to clipboard

--show-client-cas does not show lots of entries

Open limpus64 opened this issue 3 months ago • 0 comments

$ sslscan --no-colour --show-client-cas mail.mdv.de
Version: 2.2.0-static
OpenSSL 3.5.0 8 Apr 2025
…
  Acceptable client certificate CA names:
/C=de/O=Mitteldeutscher Verkehrsverbund/CN=MDV WebAccess Authority/[email protected]

Works perfectly for a single accepted client CA name. But here comes the problem:

sslscan --no-colour --show-client-cas bersy.perdata.de
Version: 2.2.0-static
OpenSSL 3.5.0 8 Apr 2025

Connected to 83.137.33.249
…

No acceptable CA names for client certificates are displayed, even though openssl s_client lists 66 of them.

$ openssl s_client bersy.perdata.de:443 < /dev/null
Connecting to 83.137.33.249
…
Acceptable client certificate CA names
C=DE, ST=NRW, …
… 
65 client certificate CA subjects omitted for brevity

Would you please list all those names?

limpus64 avatar Oct 08 '25 12:10 limpus64