$ openssl s_client -ssl3 -connect web.de:443 CONNECTED(00000003) depth=2 C = DE, O = Deutsche Telekom AG, OU = T-TeleSec Trust Center, CN = Deutsche Telekom Root CA 2 verify error:num=19:self signed certificate in certificate chain verify return:0 --- Certificate chain 0 s:/C=DE/O=1&1 Mail & Media GmbH/ST=Rhineland-Palatinate/L=Montabaur/emailAddress=server-certs@1und1.de/CN=web.de i:/C=DE/O=T-Systems International GmbH/OU=T-Systems Trust Center/ST=Nordrhein Westfalen/postalCode=57250/L=Netphen/street=Untere Industriestr. 20/CN=TeleSec ServerPass DE-2 1 s:/C=DE/O=T-Systems International GmbH/OU=T-Systems Trust Center/ST=Nordrhein Westfalen/postalCode=57250/L=Netphen/street=Untere Industriestr. 20/CN=TeleSec ServerPass DE-2 i:/C=DE/O=Deutsche Telekom AG/OU=T-TeleSec Trust Center/CN=Deutsche Telekom Root CA 2 2 s:/C=DE/O=Deutsche Telekom AG/OU=T-TeleSec Trust Center/CN=Deutsche Telekom Root CA 2 i:/C=DE/O=Deutsche Telekom AG/OU=T-TeleSec Trust Center/CN=Deutsche Telekom Root CA 2 --- Server certificate -----BEGIN CERTIFICATE----- MIIHRzCCBi+gAwIBAgIIdSgkqnbIqR4wDQYJKoZIhvcNAQELBQAwgdkxCzAJBgNV BAYTAkRFMSUwIwYDVQQKExxULVN5c3RlbXMgSW50ZXJuYXRpb25hbCBHbWJIMR8w HQYDVQQLExZULVN5c3RlbXMgVHJ1c3QgQ2VudGVyMRwwGgYDVQQIExNOb3Jkcmhl aW4gV2VzdGZhbGVuMQ4wDAYDVQQREwU1NzI1MDEQMA4GA1UEBxMHTmV0cGhlbjEg MB4GA1UECRMXVW50ZXJlIEluZHVzdHJpZXN0ci4gMjAxIDAeBgNVBAMTF1RlbGVT ZWMgU2VydmVyUGFzcyBERS0yMB4XDTE0MDQwOTA5MzczNloXDTE3MDQxNDIzNTk1 OVowgZcxCzAJBgNVBAYTAkRFMR4wHAYDVQQKDBUxJjEgTWFpbCAmIE1lZGlhIEdt YkgxHTAbBgNVBAgTFFJoaW5lbGFuZC1QYWxhdGluYXRlMRIwEAYDVQQHEwlNb250 YWJhdXIxJDAiBgkqhkiG9w0BCQEWFXNlcnZlci1jZXJ0c0AxdW5kMS5kZTEPMA0G A1UEAxMGd2ViLmRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqYw4 p27EDegk47SIweuukCKUIJLKlK4DkBHy5QwS4jBv/VKTrtMgU6tgE3FneK722esF x7zOBJ5MGCLLx/8chul8TKg6oPA7zcK2T9V4ERSxbvOWdsjDxv9QRSoZNsE22Gge D9a5VM7d+hgsccWMvpdx+eAU6hvPZr1+eU7hxLtzoWgt8S0Zf8Zgzn2lqMfSOvmT xMekHr4eM6WY6KaperG7tJcvrWAEv/vHEfAdP8PubO/SFjvNaC/+HpKuz5bm17Mh hgqs6SH3NmjgWNaunCGVLixWT5cHWX2RhfhM5HqMVaic3c72jMIBH3OWvnNr9psj iXdi/oxxaW0MpRrhYQIDAQABo4IDUTCCA00wHwYDVR0jBBgwFoAUVAQpb6KTxpAx RcA93iviCmmAkl8wDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMC BggrBgEFBQcDATAdBgNVHQ4EFgQULB7JKJcrHAxn83hR1HdgHfKb2WIwWQYDVR0g BFIwUDBEBgkrBgEEAb1HDQIwNzA1BggrBgEFBQcCARYpaHR0cDovL3d3dy50ZWxl c2VjLmRlL3NlcnZlcnBhc3MvY3BzLmh0bWwwCAYGZ4EMAQICMIIBIQYDVR0fBIIB GDCCARQwRaBDoEGGP2h0dHA6Ly9jcmwuc2VydmVycGFzcy50ZWxlc2VjLmRlL3Js L1RlbGVTZWNfU2VydmVyUGFzc19ERS0yLmNybDCByqCBx6CBxIaBwWxkYXA6Ly9s ZGFwLnNlcnZlcnBhc3MudGVsZXNlYy5kZS9jbj1UZWxlU2VjJTIwU2VydmVyUGFz cyUyMERFLTIsb3U9VC1TeXN0ZW1zJTIwVHJ1c3QlMjBDZW50ZXIsbz1ULVN5c3Rl bXMlMjBJbnRlcm5hdGlvbmFsJTIwR21iSCxjPWRlP2NlcnRpZmljYXRlUmV2b2Nh dGlvbmxpc3Q/YmFzZT9jZXJ0aWZpY2F0ZVJldm9jYXRpb25saXN0PSowggE5Bggr BgEFBQcBAQSCASswggEnMDMGCCsGAQUFBzABhidodHRwOi8vb2NzcC5zZXJ2ZXJw YXNzLnRlbGVzZWMuZGUvb2NzcHIwTAYIKwYBBQUHMAKGQGh0dHA6Ly9jcmwuc2Vy dmVycGFzcy50ZWxlc2VjLmRlL2NydC9UZWxlU2VjX1NlcnZlclBhc3NfREUtMi5j ZXIwgaEGCCsGAQUFBzAChoGUbGRhcDovL2xkYXAuc2VydmVycGFzcy50ZWxlc2Vj LmRlL2NuPVRlbGVTZWMlMjBTZXJ2ZXJQYXNzJTIwREUtMixvdT1ULVN5c3RlbXMl MjBUcnVzdCUyMENlbnRlcixvPVQtU3lzdGVtcyUyMEludGVybmF0aW9uYWwlMjBH bWJILGM9ZGU/Y0FDZXJ0aWZpY2F0ZTAMBgNVHRMBAf8EAjAAMBEGA1UdEQQKMAiC BndlYi5kZTANBgkqhkiG9w0BAQsFAAOCAQEAaIvSbRGA3HCDQSkJw0K5quQUDD1i RZW8nsPC+sJbe3dyfSxxHxDnV/a8oiddaWdvckp3x9+sZaaZv8GzVc5Eus14V6yC UI3xinmWzyY2LNDEBXj5iIVHNPBFeh/PQDglM1pf6L+/0zDJVzAxsGWmSLC4w3qM P+qIB3L1D6xf2bNDgWVlavXX4PaWM9kl/qNZoNWkT3QzFK3P67oCVdPtLueCzz4A bYy1Nuel9IZdJf2JkHYSsV9BHn0qgl83OuK/GlTYsjE67Z0uZ9SyClUuHjnxm1ri FE+GIuDkn4isUpFVzx3f+MhfxthIwOQRN0m5fQsE2JO15b/Xl3Jn0yvH9g== -----END CERTIFICATE----- subject=/C=DE/O=1&1 Mail & Media GmbH/ST=Rhineland-Palatinate/L=Montabaur/emailAddress=server-certs@1und1.de/CN=web.de issuer=/C=DE/O=T-Systems International GmbH/OU=T-Systems Trust Center/ST=Nordrhein Westfalen/postalCode=57250/L=Netphen/street=Untere Industriestr. 20/CN=TeleSec ServerPass DE-2 --- No client certificate CA names sent --- SSL handshake has read 5037 bytes and written 288 bytes --- New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-SHA Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE SSL-Session: Protocol : SSLv3 Cipher : ECDHE-RSA-AES256-SHA Session-ID: 44182171C95FB8FFDE7CBD949E52CE7D1556FDCCF1C591DEA056AE8061DBCAEA Session-ID-ctx: Master-Key: 95E38A3AC47D2E4F2B056297FBBBD015BD776C17001C77D2F149D1738F46C9BA37FA69CF457ABA7DD38A076181B9F9D0 Key-Arg : None PSK identity: None PSK identity hint: None SRP username: None Start Time: 1413453770 Timeout : 7200 (sec) Verify return code: 19 (self signed certificate in certificate chain) ---