Namecheap.com

SSL Checker

Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.

Report

Hostname: Matches Common Name or/and SAN
Expired: No (238 days till expiration)
Public Key: We were unable to find any issues in the public key of end-entity certificate
Trusted: We were unable to verify this certificate
Self-Signed: No, the end-entity certificate is not self-signed
Chain Issues: No, we were unable to detect any issues in the certificate chain sent by the server
Weak signatures: No, certificates sent by the server were not signed utilizing a weak hash function
OCSP Status: OCSP Responder returned "good" status for the end-entity certificate

DNS Information

Resolves To: 151.101.1.111
Reverse IP lookup: No records found
Nameserver: dns1.p08.nsone.net.
Nameserver: dns2.p08.nsone.net.
Nameserver: dns3.p08.nsone.net.
Nameserver: dns4.p08.nsone.net.
Nameserver: ns01.theguardiandns.com.
Nameserver: ns02.theguardiandns.com.
Nameserver: ns03.theguardiandns.com.
Nameserver: ns04.theguardiandns.com.

General Information

Common Name: theguardian.com
SANs: DNS:theguardian.comDNS:*.advertising.theguardian.comDNS:*.code.dev-guardianapis.comDNS:*.code.dev-theguardian.comDNS:*.dev-theguardian.comDNS:*.editorial.theguardian.comDNS:*.email.theguardian.comDNS:*.guardian.co.ukDNS:*.guardianapis.comDNS:*.guim.co.ukDNS:*.guimcode.co.ukDNS:*.ophan.co.ukDNS:*.qa.dev-guardianapis.comDNS:*.service.theguardian.comDNS:*.theguardian.co.ukDNS:*.theguardian.comDNS:*.theguardian.designDNS:api.nextgen.guardianapps.co.ukDNS:code.api.nextgen.guardianapps.co.ukDNS:dev-gutools.co.ukDNS:dev-theguardian.comDNS:guardian.co.ukDNS:guim.co.ukDNS:gutools.co.ukDNS:i.guimcode.co.ukDNS:media.guim.co.ukDNS:pasteup.guim.co.ukDNS:subscribe.theguardian.comDNS:theguardian.co.ukDNS:theguardian.designDNS:mta-sts.observer.co.ukDNS:*.wordiply.comDNS:wordiply.comDNS:theguardianfoundation.orgDNS:theguardian.org Total number of SANs: 35
Signature Algorithm: sha256WithRSAEncryption
Key Type: RSA
Key size: 2048 bits
Serial Number: 175070b2c7f269a0e607efefe249d74
Not Before: Nov 14, 2023 10:45:28 GMT
Not After: Dec 15, 2024 10:45:27 GMT
Number of certs: 2
Revocation Status: good
OCSP Stapling: Supported
Server: GitHub.com
HSTS: max-age=31536000; includeSubDomains; preload
HPKP: Not Supported

Chain Information

Certificate # 1 - Common Name: theguardian.com

Decode this certificate for verbose information →
Subject Common Name theguardian.com
Issuer Common Name GlobalSign Atlas R3 DV TLS CA 2023 Q4
Issuer Organization GlobalSign nv-sa
Not Before: Nov 14, 2023 10:45:28 GMT
Not After: Dec 15, 2024 10:45:27 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 175070b2c7f269a0e607efefe249d74
SHA1 Fingerprint: B7:33:5B:BE:95:30:97:40:D3:81:C4:3A:D2:39:DD:71:3A:2C:7D:5C
MD5 Fingerprint: 60:22:5D:E7:8C:FB:AF:5B:23:F0:11:F4:88:8E:E1:4F

Certificate # 2 - Common Name: GlobalSign Atlas R3 DV TLS CA 2023 Q4

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name GlobalSign Atlas R3 DV TLS CA 2023 Q4
Subject Organization GlobalSign nv-sa
Issuer Common Name GlobalSign
Issuer Organization GlobalSign
Not Before: Jul 19, 2023 03:42:29 GMT
Not After: Jul 19, 2025 00:00:00 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 7f1f2c49c60fc7562f5899d6cd6019b3
SHA1 Fingerprint: FC:74:84:17:07:45:DE:2D:53:68:9E:A2:05:38:42:1A:F2:A2:7A:76
MD5 Fingerprint: 73:C7:84:A6:26:55:DC:3F:20:42:04:4E:0B:33:BC:F9

OpenSSL Handshake

depth=1 C = BE, O = GlobalSign nv-sa, CN = GlobalSign Atlas R3 DV TLS CA 2023 Q4
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN = theguardian.com
verify return:1
CONNECTED(00000003)
OCSP response: 
======================================
OCSP Response Data:
    OCSP Response Status: successful (0x0)
    Response Type: Basic OCSP Response
    Version: 1 (0x0)
    Responder Id: 27597C9E2E8279A1260AE9051E0B58C6EEC0242B
    Produced At: Apr 20 11:55:00 2024 GMT
    Responses:
    Certificate ID:
      Hash Algorithm: sha1
      Issuer Name Hash: 5B64661103AEF249418283CC741D5A6B46246513
      Issuer Key Hash: AA11718F95C458988BB16E0F3B506824BCB819BC
      Serial Number: 0175070B2C7F269A0E607EFEFE249D74
    Cert Status: good
    This Update: Apr 20 11:00:00 2024 GMT
    Next Update: Apr 20 23:00:00 2024 GMT

    Signature Algorithm: sha256WithRSAEncryption
         be:6f:08:2c:05:54:d3:2c:fd:cc:9a:be:0c:c9:b7:52:19:7e:
         38:f4:7e:94:75:90:94:35:d1:99:db:2b:7d:9b:2e:51:28:1b:
         0f:2e:db:03:8e:3e:b8:0a:e8:da:7d:64:1a:7a:65:8e:fa:7c:
         b5:57:81:13:68:42:5d:61:38:3b:88:c3:3b:cc:74:32:0d:6b:
         77:8c:a0:ca:7a:76:db:e3:bc:49:4e:c6:66:a1:0f:ed:c5:77:
         0a:04:8f:4e:a0:3a:75:53:ee:86:f1:21:10:6d:1e:a5:cf:a8:
         e4:41:84:77:5b:f2:2e:8d:52:58:91:b8:ca:c8:23:eb:a1:97:
         f6:24:12:09:0a:c2:c0:10:50:e7:98:a3:36:2c:48:f9:51:48:
         bd:eb:56:ec:d4:9d:f5:a0:9c:f2:22:4e:85:9b:ad:b5:e1:37:
         3e:72:30:02:94:fa:9a:33:9d:6e:36:ec:cf:61:de:81:b6:92:
         71:8a:97:b7:59:74:06:98:d0:74:ed:1e:a7:b1:13:e4:d0:c5:
         10:8a:fb:3f:09:db:89:ff:92:97:7f:78:3e:7b:67:e3:bb:07:
         cb:f6:81:69:47:72:d2:d1:4c:b0:2a:8b:f6:4c:e5:ac:32:33:
         83:3c:ca:51:90:3d:e5:85:af:ce:4a:90:a4:08:a3:f8:49:03:
         43:e7:ae:01
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            01:ab:c5:74:d5:26:4f:51:d7:19:85:e8:64:92:28:8a
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q4
        Validity
            Not Before: Apr 19 13:03:04 2024 GMT
            Not After : Apr 26 13:03:04 2024 GMT
        Subject: C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q4 - OCSP Responder
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:d8:ae:d9:24:3c:b7:71:e6:7b:c4:e1:24:60:9c:
                    07:a5:71:3f:91:fc:82:ae:5b:61:4b:95:37:4c:c8:
                    d4:0b:67:c3:97:2f:12:f2:e4:93:a8:c9:8b:07:0d:
                    20:98:f8:81:44:7a:97:09:8e:b9:af:48:c3:d7:8f:
                    f5:35:e3:91:87:76:3b:2a:ee:a3:93:f6:cc:12:82:
                    1c:d5:d8:ef:44:68:5d:68:39:fe:d3:3b:7c:a8:03:
                    84:bf:3f:88:a5:5d:0f:e1:79:00:bf:89:ac:12:1a:
                    94:98:6b:36:73:a2:78:a5:7e:78:8c:18:de:f2:c8:
                    65:77:da:65:07:f5:09:ea:d4:ac:e0:e6:d1:f8:34:
                    e1:cd:86:3a:2d:80:df:dd:9a:a1:2b:2c:82:2e:4f:
                    18:f5:56:7f:ba:90:dc:87:c5:bc:f0:35:03:1d:72:
                    af:1f:11:32:6b:32:e5:89:52:34:3c:a5:4a:bc:c6:
                    15:0a:7e:95:5f:3b:54:2e:22:32:b7:d9:a8:df:73:
                    38:b5:a4:ff:6b:b1:30:2d:eb:5b:de:c6:7a:4e:2f:
                    e9:4c:b4:8e:03:70:3d:63:67:23:81:38:57:7c:66:
                    42:74:ad:f2:6c:2a:7d:d5:cd:9f:e2:47:18:ac:7f:
                    7e:cb:dd:9f:47:af:90:e7:c6:75:c3:43:48:a2:f7:
                    7b:b5
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            OCSP No Check: 

            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage: 
                OCSP Signing
            X509v3 Subject Key Identifier: 
                27:59:7C:9E:2E:82:79:A1:26:0A:E9:05:1E:0B:58:C6:EE:C0:24:2B
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Authority Key Identifier: 
                keyid:AA:11:71:8F:95:C4:58:98:8B:B1:6E:0F:3B:50:68:24:BC:B8:19:BC

    Signature Algorithm: sha256WithRSAEncryption
         55:c8:7f:dc:dc:7e:30:4b:42:21:89:b0:60:f1:52:de:2d:57:
         30:92:6b:a5:e8:3f:9c:74:a8:bc:8a:03:4e:7b:96:68:6a:69:
         a0:a3:35:b8:c1:dd:f2:3b:bd:52:50:9d:24:12:9b:cc:47:f3:
         0b:81:53:d2:92:b8:c6:3f:32:4c:ce:41:c4:ba:c5:e4:b2:94:
         c7:8e:35:a6:08:44:6a:70:0d:cc:38:67:a8:8e:de:30:ee:c7:
         26:24:d7:1d:55:e5:4b:9f:63:4f:87:57:8f:df:ce:14:02:48:
         b3:82:de:ab:40:c9:cb:50:c2:92:10:2a:54:2b:8c:c5:be:75:
         3c:05:9f:15:86:53:32:f9:e4:30:88:f2:42:d4:56:ab:5f:49:
         df:ec:4b:d7:af:92:47:43:e8:e6:84:14:0f:0c:dd:81:fa:1e:
         d5:64:d9:33:77:46:07:d2:2a:4a:7d:cf:2a:63:e5:05:7f:a6:
         72:96:bb:ed:08:34:da:03:3d:f6:d7:43:fd:ce:57:cc:46:79:
         69:6b:76:11:22:91:39:b5:a6:98:e9:aa:07:e2:33:9c:a6:93:
         cf:0a:7a:53:b5:ce:e7:b6:04:da:d9:f8:81:14:45:8c:2b:24:
         81:54:95:90:43:cb:a2:8e:ae:9f:4b:b4:10:70:72:37:59:78:
         bb:7d:b2:6f
-----BEGIN CERTIFICATE-----
MIID0zCCArugAwIBAgIQAavFdNUmT1HXGYXoZJIoijANBgkqhkiG9w0BAQsFADBY
MQswCQYDVQQGEwJCRTEZMBcGA1UEChMQR2xvYmFsU2lnbiBudi1zYTEuMCwGA1UE
AxMlR2xvYmFsU2lnbiBBdGxhcyBSMyBEViBUTFMgQ0EgMjAyMyBRNDAeFw0yNDA0
MTkxMzAzMDRaFw0yNDA0MjYxMzAzMDRaMGkxCzAJBgNVBAYTAkJFMRkwFwYDVQQK
DBBHbG9iYWxTaWduIG52LXNhMT8wPQYDVQQDDDZHbG9iYWxTaWduIEF0bGFzIFIz
IERWIFRMUyBDQSAyMDIzIFE0IC0gT0NTUCBSZXNwb25kZXIwggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQDYrtkkPLdx5nvE4SRgnAelcT+R/IKuW2FLlTdM
yNQLZ8OXLxLy5JOoyYsHDSCY+IFEepcJjrmvSMPXj/U145GHdjsq7qOT9swSghzV
2O9EaF1oOf7TO3yoA4S/P4ilXQ/heQC/iawSGpSYazZzonilfniMGN7yyGV32mUH
9Qnq1Kzg5tH4NOHNhjotgN/dmqErLIIuTxj1Vn+6kNyHxbzwNQMdcq8fETJrMuWJ
UjQ8pUq8xhUKfpVfO1QuIjK32ajfczi1pP9rsTAt61vexnpOL+lMtI4DcD1jZyOB
OFd8ZkJ0rfJsKn3VzZ/iRxisf37L3Z9Hr5DnxnXDQ0ii93u1AgMBAAGjgYcwgYQw
DwYJKwYBBQUHMAEFBAIFADAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYIKwYB
BQUHAwkwHQYDVR0OBBYEFCdZfJ4ugnmhJgrpBR4LWMbuwCQrMAwGA1UdEwEB/wQC
MAAwHwYDVR0jBBgwFoAUqhFxj5XEWJiLsW4PO1BoJLy4GbwwDQYJKoZIhvcNAQEL
BQADggEBAFXIf9zcfjBLQiGJsGDxUt4tVzCSa6XoP5x0qLyKA057lmhqaaCjNbjB
3fI7vVJQnSQSm8xH8wuBU9KSuMY/MkzOQcS6xeSylMeONaYIRGpwDcw4Z6iO3jDu
xyYk1x1V5UufY0+HV4/fzhQCSLOC3qtAyctQwpIQKlQrjMW+dTwFnxWGUzL55DCI
8kLUVqtfSd/sS9evkkdD6OaEFA8M3YH6HtVk2TN3RgfSKkp9zypj5QV/pnKWu+0I
NNoDPfbXQ/3OV8xGeWlrdhEikTm1ppjpqgfiM5ymk88KelO1zue2BNrZ+IEURYwr
JIFUlZBDy6KOrp9LtBBwcjdZeLt9sm8=
-----END CERTIFICATE-----
======================================
---
Certificate chain
 0 s:CN = theguardian.com
   i:C = BE, O = GlobalSign nv-sa, CN = GlobalSign Atlas R3 DV TLS CA 2023 Q4
-----BEGIN CERTIFICATE-----
MIIJRzCCCC+gAwIBAgIQAXUHCyx/JpoOYH7+/iSddDANBgkqhkiG9w0BAQsFADBY
MQswCQYDVQQGEwJCRTEZMBcGA1UEChMQR2xvYmFsU2lnbiBudi1zYTEuMCwGA1UE
AxMlR2xvYmFsU2lnbiBBdGxhcyBSMyBEViBUTFMgQ0EgMjAyMyBRNDAeFw0yMzEx
MTQxMDQ1MjhaFw0yNDEyMTUxMDQ1MjdaMBoxGDAWBgNVBAMMD3RoZWd1YXJkaWFu
LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALKyNsei1eql3CsS
TVzDv37Zanr88jU7d4YOXQfUAlbeoUvxhwFK8nFHhajasQAkppzBmPpcP2mVh8Fl
V+gbUz3AEOkNW6IWqoHuyq4lOBEpU4v3tshPPTm73tUrEreviNfs9myHjRo4cjBO
fNMmc0o7sNr+POCYXpibK6NK1yWSSupzfp8i8TXlpaqvVx1xtt025GLnS/r0Lbz+
JQjSRNVdze0qQDC+BuajvyoYFlZopB03XjrBXW1AjX9BFlqPlJ4iGDNqkTFbM8Ys
uSbECVpHvSW1HNtgAyN/yZBCRj964oqG2+l/peIYtJ+v+42+LBWCSzX2cKNirkNB
zdBV1UUCAwEAAaOCBkkwggZFMIIDAAYDVR0RBIIC9zCCAvOCD3RoZWd1YXJkaWFu
LmNvbYIdKi5hZHZlcnRpc2luZy50aGVndWFyZGlhbi5jb22CGyouY29kZS5kZXYt
Z3VhcmRpYW5hcGlzLmNvbYIaKi5jb2RlLmRldi10aGVndWFyZGlhbi5jb22CFSou
ZGV2LXRoZWd1YXJkaWFuLmNvbYIbKi5lZGl0b3JpYWwudGhlZ3VhcmRpYW4uY29t
ghcqLmVtYWlsLnRoZWd1YXJkaWFuLmNvbYIQKi5ndWFyZGlhbi5jby51a4ISKi5n
dWFyZGlhbmFwaXMuY29tggwqLmd1aW0uY28udWuCECouZ3VpbWNvZGUuY28udWuC
DSoub3BoYW4uY28udWuCGSoucWEuZGV2LWd1YXJkaWFuYXBpcy5jb22CGSouc2Vy
dmljZS50aGVndWFyZGlhbi5jb22CEyoudGhlZ3VhcmRpYW4uY28udWuCESoudGhl
Z3VhcmRpYW4uY29tghQqLnRoZWd1YXJkaWFuLmRlc2lnboIeYXBpLm5leHRnZW4u
Z3VhcmRpYW5hcHBzLmNvLnVrgiNjb2RlLmFwaS5uZXh0Z2VuLmd1YXJkaWFuYXBw
cy5jby51a4IRZGV2LWd1dG9vbHMuY28udWuCE2Rldi10aGVndWFyZGlhbi5jb22C
Dmd1YXJkaWFuLmNvLnVrggpndWltLmNvLnVrgg1ndXRvb2xzLmNvLnVrghBpLmd1
aW1jb2RlLmNvLnVrghBtZWRpYS5ndWltLmNvLnVrghJwYXN0ZXVwLmd1aW0uY28u
dWuCGXN1YnNjcmliZS50aGVndWFyZGlhbi5jb22CEXRoZWd1YXJkaWFuLmNvLnVr
ghJ0aGVndWFyZGlhbi5kZXNpZ26CFm10YS1zdHMub2JzZXJ2ZXIuY28udWuCDiou
d29yZGlwbHkuY29tggx3b3JkaXBseS5jb22CGXRoZWd1YXJkaWFuZm91bmRhdGlv
bi5vcmeCD3RoZWd1YXJkaWFuLm9yZzAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYw
FAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRVHFmoziBdh/K2mBXNtlQi
HhuuRTBXBgNVHSAEUDBOMAgGBmeBDAECATBCBgorBgEEAaAyCgEDMDQwMgYIKwYB
BQUHAgEWJmh0dHBzOi8vd3d3Lmdsb2JhbHNpZ24uY29tL3JlcG9zaXRvcnkvMAwG
A1UdEwEB/wQCMAAwgZ4GCCsGAQUFBwEBBIGRMIGOMEAGCCsGAQUFBzABhjRodHRw
Oi8vb2NzcC5nbG9iYWxzaWduLmNvbS9jYS9nc2F0bGFzcjNkdnRsc2NhMjAyM3E0
MEoGCCsGAQUFBzAChj5odHRwOi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2Vy
dC9nc2F0bGFzcjNkdnRsc2NhMjAyM3E0LmNydDAfBgNVHSMEGDAWgBSqEXGPlcRY
mIuxbg87UGgkvLgZvDBIBgNVHR8EQTA/MD2gO6A5hjdodHRwOi8vY3JsLmdsb2Jh
bHNpZ24uY29tL2NhL2dzYXRsYXNyM2R2dGxzY2EyMDIzcTQuY3JsMIIBfAYKKwYB
BAHWeQIEAgSCAWwEggFoAWYAdQA/F0tP1yJHWJQdZRyEvg0S7ZA3fx+FauvBvyiF
7PhkbgAAAYvNb6ygAAAEAwBGMEQCICoWpZDIEo2tX8EJ6yuc5s1dZDW50uZZbVvz
tdWe0GhhAiA2VK1V+aMk3JuO+NM6Ouc1ylYFtnJbA9vwc4lmexJFPgB1AO7N0GTV
2xrOxVy3nbTNE6Iyh0Z8vOzew1FIWUZxH7WbAAABi81vrJ0AAAQDAEYwRAIgV1iJ
t2bXoON3bWDzAX/u8A/agrBpzgcYcLVs8yrSTcgCID9cWjwYZ/qxevB78rhKby2P
YXBqyedpdMx1hu7Hb8YMAHYASLDja9qmRzQP5WoC+p0w6xxSActW3SyB2bu/qznY
hHMAAAGLzW+umAAABAMARzBFAiBYTLVldbcUHceRI0IlF/ZZ9/ULHi+TfZjCS1fC
IGkFpQIhAJWaQQFOIqx0JGSsNzNrXS5KRNF0AqE9yfJJQfZtobPAMA0GCSqGSIb3
DQEBCwUAA4IBAQAXglw/zCAN0N51I1HpC52K0KZ5PVd6r7wDLhxghYrgNy/TSHDx
rno6dI3imeU6ufb/fLceMYGXd0Ikzya45q4zHKzi6u6bvBierceBnuKLycWnFnQF
Paq9DJQJjqNymySKEH2DpuFY7E4wHvDWVfCe2g5NweCecl1pxNSyGXNDPSORPlET
a5FO3DSj2z4/Tc9kReKjIkaQPeyiNLURgzR1UbxfuHs/xf4V07AEn7DqIBqkWwzT
hpg9wUNKPm0owZEiPFVKBA6DFzjei+BKcbZW/AaEx7lX9FNBTFMDRsLFke6O8MUQ
WGiWk3jxeIDLL5Jdy9LdS9jFkdWqOd3/M7am
-----END CERTIFICATE-----
 1 s:C = BE, O = GlobalSign nv-sa, CN = GlobalSign Atlas R3 DV TLS CA 2023 Q4
   i:OU = GlobalSign Root CA - R3, O = GlobalSign, CN = GlobalSign
-----BEGIN CERTIFICATE-----
MIIEjzCCA3egAwIBAgIQfx8sScYPx1YvWJnWzWAZszANBgkqhkiG9w0BAQsFADBM
MSAwHgYDVQQLExdHbG9iYWxTaWduIFJvb3QgQ0EgLSBSMzETMBEGA1UEChMKR2xv
YmFsU2lnbjETMBEGA1UEAxMKR2xvYmFsU2lnbjAeFw0yMzA3MTkwMzQyMjlaFw0y
NTA3MTkwMDAwMDBaMFgxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWdu
IG52LXNhMS4wLAYDVQQDEyVHbG9iYWxTaWduIEF0bGFzIFIzIERWIFRMUyBDQSAy
MDIzIFE0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArn7MODS0pNF1
+r3pMVMb8tjOcHZEzqIqk+OU738JzxqkKKO6o4eMdPQn3wuKPHQKmJFEiMwYRYlP
zFqL5SJVfmDg2t47QPtrL5kPr/bU08qL0N3LDeuv4d7c5FmY535/3AqlZqcnp9EF
SHngn4ISG6EXp6s/LPdyObu6so4vApJbmm2xHHc1pgAeorBNsDRr9IgcODwI1U5o
3UtBP0F4oZFmIopTl1dbFKGYPr+xap3hAw+z5MnspBaDRkSiU3xfy0LngS73Vs52
eYdp11AEWlZzTyDYwc8zm/tRArLZzfqygl86AyydLvZ9tg8OzPx+Tzl5xLx5Ltwi
Ksxglnv2ewIDAQABo4IBXzCCAVswDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQG
CCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH/AgEAMB0GA1UdDgQW
BBSqEXGPlcRYmIuxbg87UGgkvLgZvDAfBgNVHSMEGDAWgBSP8Et/qC5FJK5NUPpj
move4t0bvDB7BggrBgEFBQcBAQRvMG0wLgYIKwYBBQUHMAGGImh0dHA6Ly9vY3Nw
Mi5nbG9iYWxzaWduLmNvbS9yb290cjMwOwYIKwYBBQUHMAKGL2h0dHA6Ly9zZWN1
cmUuZ2xvYmFsc2lnbi5jb20vY2FjZXJ0L3Jvb3QtcjMuY3J0MDYGA1UdHwQvMC0w
K6ApoCeGJWh0dHA6Ly9jcmwuZ2xvYmFsc2lnbi5jb20vcm9vdC1yMy5jcmwwIQYD
VR0gBBowGDAIBgZngQwBAgEwDAYKKwYBBAGgMgoBAzANBgkqhkiG9w0BAQsFAAOC
AQEAiLoUIGIiKDNmQ8cWRZv5BX3ChPqWie23uWZ1YaP/59gYVvM48TbQu7lA8ZeE
FieIUFE+B68wGtU4mxKamfkWhORTAl1OcQ2C2tfJ0t4v6TbtEgzS2CC7oDkr4+W5
QDuBbGgNIzBB7xbL9Uy/PJ602MFt46a8WYvr0Mp+Qn2buHQ8WaTi2PXiv8Z62YZ0
zz3yEpWzh7sVUS/4t6CdvccPnYq6c0wMIO4Dn+fO5HEy3M00y9BIXhG4WeMWhmIk
es+tp6LilOYT/ZV2WPebhvmi66VnDzRPwk98aWrMYzkV3pgkwLQIqzfp1N3gNAHe
ZCnzaCq5VstgX6g9l2vw5Qycag==
-----END CERTIFICATE-----
---
Server certificate
subject=CN = theguardian.com

issuer=C = BE, O = GlobalSign nv-sa, CN = GlobalSign Atlas R3 DV TLS CA 2023 Q4

---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 5569 bytes and written 385 bytes
Verification error: unable to get local issuer certificate
---
New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256
Server public key is 2048 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 20 (unable to get local issuer certificate)
---
DONE
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
    Protocol  : TLSv1.3
    Cipher    : TLS_AES_128_GCM_SHA256
    Session-ID: 17946D850F82751A4F6B3DD33546B67EA2617FFA676C8AB19E7FD5A7EAB729E9
    Session-ID-ctx: 
    Resumption PSK: 13C5343DC76F0030AE661014596D841F44E1998A3645ABDF12E972F9F6EF3BFF
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 3600 (seconds)
    TLS session ticket:
    0000 - 8f 2a e1 9c c9 99 90 37-64 ab 9e 0f 2f e8 20 db   .*.....7d.../. .
    0010 - 10 2e 53 fb 85 7a c8 7c-fd e1 5b 4d b5 d4 58 55   ..S..z.|..[M..XU
    0020 - 81 5b 05 62 0a 8e a1 81-dc 5d 0c 4c 97 25 dc 2b   .[.b.....].L.%.+
    0030 - d0 47 ba 33 e4 84 75 49-9f f7 f8 65 6c a9 44 15   .G.3..uI...el.D.
    0040 - c9 5f 6e da cd 94 62 18-1e 12 d0 9c fe 27 b5 b6   ._n...b......'..
    0050 - 71 83 03 ef 17 00 c0 87-18 7a 3b 27 01 14 fc 8e   q........z;'....
    0060 - ed b5 3d 7d ff 2e 00 de-3f 8b f7 05 18 c3 03 f0   ..=}....?.......
    0070 - 2c fc 1f 74 27 17 eb 6b-01 52 3c ca 25 43 06 94   ,..t'..k.R<.%C..
    0080 - 27 89 f4 d5 6e 20 8f 3a-6d 03 42 6c 1a 7c 5d 5d   '...n .:m.Bl.|]]
    0090 - a3 65 b3 eb 3c 70 26 14-50 94 25 e3 6e fe 70 a6   .e..<p&.P.%.n.p.

    Start Time: 1713626060
    Timeout   : 7200 (sec)
    Verify return code: 20 (unable to get local issuer certificate)
    Extended master secret: no
    Max Early Data: 0
---
read R BLOCK