christoph@hepworth ~ :) % openssl s_client -connect oteiza.asgard:993 CONNECTED(00000003) depth=0 /CN=oteiza.siccegge.de verify error:num=20:unable to get local issuer certificate verify return:1 depth=0 /CN=oteiza.siccegge.de verify error:num=27:certificate not trusted verify return:1 depth=0 /CN=oteiza.siccegge.de verify error:num=21:unable to verify the first certificate verify return:1 --- Certificate chain 0 s:/CN=oteiza.siccegge.de i:/O=CAcert Inc./OU=http://www.CAcert.org/CN=CAcert Class 3 Root --- Server certificate -----BEGIN CERTIFICATE----- MIIFBTCCAu2gAwIBAgIDALfdMA0GCSqGSIb3DQEBBQUAMFQxFDASBgNVBAoTC0NB Y2VydCBJbmMuMR4wHAYDVQQLExVodHRwOi8vd3d3LkNBY2VydC5vcmcxHDAaBgNV BAMTE0NBY2VydCBDbGFzcyAzIFJvb3QwHhcNMTAwOTI3MTc1MDQwWhcNMTIwOTI2 MTc1MDQwWjAdMRswGQYDVQQDExJvdGVpemEuc2ljY2VnZ2UuZGUwggEiMA0GCSqG SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIE9wszRpeChtAx/TLaEhEZ/dXR+1H/o2z 6inALtxD5zScDFqcjhg30nqMS2XlG8vTZR+EzsyIESo5oKsDMHNTnooADpqtPDH3 7ROU3JlFONja+Sox3JkvLiXjr5vynOwovRkdVVlY9lTZzUSPyZWWt28T9Zn9yqK8 ESKKc6F3oRQt3w4xsVELkDn8AXQywaRNQxzq1aOjk7/CRK9LJe1NZ1qMEqGJn97u J5PwxU6WYFWN7VAc3kETI9Zv1sUws09bvk1bv1SYUXenbyrBBjPffcBIqCVDe/4O ck8QBioCa+nOt5vvP8Ed/owoEAqMOdKJed3ERiInYOMCuB7ZVo4dAgMBAAGjggEV MIIBETAMBgNVHRMBAf8EAjAAMDQGA1UdJQQtMCsGCCsGAQUFBwMCBggrBgEFBQcD AQYJYIZIAYb4QgQBBgorBgEEAYI3CgMDMAsGA1UdDwQEAwIFoDAzBggrBgEFBQcB AQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmNhY2VydC5vcmcvMIGIBgNV HREEgYAwfoISb3RlaXphLnNpY2NlZ2dlLmRloCAGCCsGAQUFBwgFoBQMEm90ZWl6 YS5zaWNjZWdnZS5kZYIbb3RlaXphLmlwdjYuc2llZ2xpdHpob2YubmV0oCkGCCsG AQUFBwgFoB0MG290ZWl6YS5pcHY2LnNpZWdsaXR6aG9mLm5ldDANBgkqhkiG9w0B AQUFAAOCAgEAdibl9laXbavmeOVg24I03gG0pDy23V6P8yDcqN3Q0ZsppwSwIyex o5f3rytKUwr1dE414VopP4hbOjJDyExrZMEXXJosDZa49apQTgsk4lVlVBCR664r D80ISykN7TRQ80pnvaZyyj/mOJZOQ1bGYXN+oQQDXR9mMT0RtWG7SlKz9SH6FrS/ 7HV+1QMim/t3+wqN68EARW1/iBaDxLWHPLcI3TVuZZMU8FieHv/EWlUAHt/BeGsi iDOMDrMXyuSjM8J/a0rfGAh6U95Y2eXi/H1EicjEjd0eHjSoUAoRC3ZACOW+FbMh BTkALRP5MBlkc15P+AOfmuj/WsBFnKmq8UcNlmJn9ShUt4f7CFCw0RIWeOGBfZ95 4zuyIZkFrYn0nGjnoftAT90JxNdBrhhLdotozxQUtq7eQhQ8cu0jK1yNttcXaFIF jMvCykrk3me0xkwhlofudFAPXq3CpywYXZRLIXFGJFQaxbieDAabWuGSWQ0/wwKx p8EH1uZqogcPIepoVoUEaX/WxZIPx1bvIYtWskh8k/VugvYQavgEDg2M3KYGu8hq ttAQNr+zuCUNAvYjUUQIvOQZwM3pFI20l3d/zDgj8r1WgElSVmH7WopOa89/r6oz xBSKNgYqznByNtz882AbwSDCOGQz7GcuWEsqObjSbjZ0m5HuSOwd2xI= -----END CERTIFICATE----- subject=/CN=oteiza.siccegge.de issuer=/O=CAcert Inc./OU=http://www.CAcert.org/CN=CAcert Class 3 Root --- No client certificate CA names sent --- SSL handshake has read 1988 bytes and written 319 bytes --- New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE SSL-Session: Protocol : TLSv1 Cipher : DHE-RSA-AES256-SHA Session-ID: 5FFB3E47AFFF3C07CEAF01BA5070D9EE58A8962BAB21F4D72FE7BCEB5D3FDB48 Session-ID-ctx: Master-Key: 1114D7EE88A0F8536FAA31AB20565F4BA2EC693637C988EDE97B4D76C950155758E368695D6A6AEAEAB2F1C2197229C8 Key-Arg : None Start Time: 1285623358 Timeout : 300 (sec) Verify return code: 21 (unable to verify the first certificate) --- * OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE AUTH=PLAIN] Dovecot ready. quit quit BAD Error in IMAP command received by server. exit exit BAD Error in IMAP command received by server. DONE christoph@hepworth ~ :) % openssl s_client -connect oteiza.siccegge.de:993 gethostbyname failure connect:errno=0