$ openssl s_client -starttls smtp -crlf -ssl3 -connect front0.ok.de:25 CONNECTED(00000003) depth=1 C = BE, O = GlobalSign nv-sa, CN = GlobalSign Domain Validation CA - SHA256 - G2 verify error:num=20:unable to get local issuer certificate verify return:0 --- Certificate chain 0 s:/OU=Domain Control Validated/CN=*.ok.de i:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign Domain Validation CA - SHA256 - G2 1 s:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign Domain Validation CA - SHA256 - G2 i:/C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA --- Server certificate -----BEGIN CERTIFICATE----- MIIE4zCCA8ugAwIBAgISESFV742epyey7ewX/tZUTvBfMA0GCSqGSIb3DQEBCwUA MGAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTYwNAYD VQQDEy1HbG9iYWxTaWduIERvbWFpbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0g RzIwHhcNMTQwNDE0MDg0NzIzWhcNMTUwNzE5MDg1OTA3WjA1MSEwHwYDVQQLExhE b21haW4gQ29udHJvbCBWYWxpZGF0ZWQxEDAOBgNVBAMUByoub2suZGUwggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDEwHApSqQfC2oHxvHepN6Uhv0jPu1u oRSu9T+xq/CUPBSjBI/a7Jg+1iQOmFwLgPDqzsQitSfg5uv1EMEbt5mbZj0zGJGt tii0Kv/h+a3faXnbVOXBIcU2UxYVmPQrE8m0P0/RkC75wSpVImyY7XEy3eW34uvK OYdzVCyno2uoAOzB3CDmlqB6bsztMFS0Vde9QBOiisv/OnDwfub/TkVl7UVWLmny uRuX4DfpkcHgHNqWw2wGGL3k5m5XQVqDHjUqMaJjGDFmggV0naw/3zWbuc4K/SkR wzRQmUhANl/Jn23aPsHsnbPA/qqSppClnXkxZt2E9VKOWxNKwE86y4AVAgMBAAGj ggHAMIIBvDAOBgNVHQ8BAf8EBAMCBaAwSQYDVR0gBEIwQDA+BgZngQwBAgEwNDAy BggrBgEFBQcCARYmaHR0cHM6Ly93d3cuZ2xvYmFsc2lnbi5jb20vcmVwb3NpdG9y eS8wGQYDVR0RBBIwEIIHKi5vay5kZYIFb2suZGUwCQYDVR0TBAIwADAdBgNVHSUE FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwQwYDVR0fBDwwOjA4oDagNIYyaHR0cDov L2NybC5nbG9iYWxzaWduLmNvbS9ncy9nc2RvbWFpbnZhbHNoYTJnMi5jcmwwgZQG CCsGAQUFBwEBBIGHMIGEMEcGCCsGAQUFBzAChjtodHRwOi8vc2VjdXJlLmdsb2Jh bHNpZ24uY29tL2NhY2VydC9nc2RvbWFpbnZhbHNoYTJnMnIxLmNydDA5BggrBgEF BQcwAYYtaHR0cDovL29jc3AyLmdsb2JhbHNpZ24uY29tL2dzZG9tYWludmFsc2hh MmcyMB0GA1UdDgQWBBSIli+h9T1VoH2/+bie70NiSYWOaTAfBgNVHSMEGDAWgBTq TnzUgC3lFYGGJoyCbcCYpM+XDzANBgkqhkiG9w0BAQsFAAOCAQEAZf7c+7GDnH// ZIokQJZR+Of13hH5Kt8tuhF+0fk+aZxnPcAFW1ANpa1diIpaawnSwLzCS2R8Pdkn d2JiRLya7wm6iTJYWR3NzfL//VhyCpbXbmu7qEtCjMNvMMfD0tKQ8kmvYxg4A/2Z eMt4cJqq1VHRQr5PtlTnKmh9R/2+XrsD0UuAKcunwHHZHQzPxijHkDf2qIbna5QE t81f+4HGtiWdkoU6A6JM1JpHBN/vSqrzyXNag4Vx5HppiNH8+NwF1m4UN+jUWqDN tWvbryAAylNuhDmlgnxd4gZIqPKtI5I5brGBSwGEe2BY2U4+DvN9XyKRD1Xog/RI y0VE+UiXWg== -----END CERTIFICATE----- subject=/OU=Domain Control Validated/CN=*.ok.de issuer=/C=BE/O=GlobalSign nv-sa/CN=GlobalSign Domain Validation CA - SHA256 - G2 --- No client certificate CA names sent --- SSL handshake has read 3318 bytes and written 387 bytes --- New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE SSL-Session: Protocol : SSLv3 Cipher : DHE-RSA-AES256-SHA Session-ID: 1DFB6DB1F0D31348F74316A00ABF2ECDA9974B7349EC8EE97BEE7E06A88D8404 Session-ID-ctx: Master-Key: 2D62822403E33C2882D5F3790D88B34936C3B71B4AA6F8104F57EA202DD3AF38038710EB2EC527327D27A48E555B696F Key-Arg : None PSK identity: None PSK identity hint: None SRP username: None Start Time: 1413453386 Timeout : 7200 (sec) Verify return code: 20 (unable to get local issuer certificate) --- 250 DSN