Namecheap.com

SSL Checker

Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.

Report

Hostname: Matches Common Name or/and SAN
Expired: No (239 days till expiration)
Public Key: We were unable to find any issues in the public key of end-entity certificate
Trusted: We were unable to verify this certificate
Self-Signed: No, the end-entity certificate is not self-signed
Chain Issues: No, we were unable to detect any issues in the certificate chain sent by the server
Weak signatures: No, certificates sent by the server were not signed utilizing a weak hash function
OCSP Status: OCSP Responder returned "good" status for the end-entity certificate

DNS Information

CNAME: www-gov-uk.map.fastly.net.
Resolves To: 151.101.0.144
Reverse IP lookup: No records found
Nameserver: ns1.surfnet.nl.
Nameserver: auth00.ns.de.uu.net.
Nameserver: ns3.ja.net.
Nameserver: ns0.ja.net.
Nameserver: ns2.ja.net.
Nameserver: ns4.ja.net.
Nameserver: auth50.ns.de.uu.net.

General Information

Common Name: www.gov.uk
SANs: DNS:www.gov.ukDNS:*.businesslink.gov.ukDNS:*.direct.gov.ukDNS:*.publishing.service.gov.ukDNS:*.cabinet-office.gov.ukDNS:assets.digital.cabinet-office.gov.ukDNS:service.gov.ukDNS:data.gov.ukDNS:dfid.gov.ukDNS:cabinet-office.gov.ukDNS:api.gov.ukDNS:www.data.gov.ukDNS:gov.uk Total number of SANs: 13
Organization: Government Digital Service
Locality: London
Signature Algorithm: sha256WithRSAEncryption
Key Type: RSA
Key size: 2048 bits
Serial Number: eac5d99fc6c5cca479377f3
Not Before: Nov 14, 2023 10:31:12 GMT
Not After: Dec 15, 2024 10:31:11 GMT
Number of certs: 2
Revocation Status: good
OCSP Stapling: Supported
Server: nginx
HSTS: max-age=31536000; preload
HPKP: Not Supported

Chain Information

Certificate # 1 - Common Name: www.gov.uk

Decode this certificate for verbose information →
Subject Common Name www.gov.uk
Subject Organization Government Digital Service
Issuer Common Name GlobalSign RSA OV SSL CA 2018
Issuer Organization GlobalSign nv-sa
Not Before: Nov 14, 2023 10:31:12 GMT
Not After: Dec 15, 2024 10:31:11 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: eac5d99fc6c5cca479377f3
SHA1 Fingerprint: A9:AD:D4:38:B0:D0:49:75:E9:36:81:CD:97:CF:8E:EC:E5:C5:D3:35
MD5 Fingerprint: 6B:B9:69:AC:42:A3:17:77:C1:EC:97:8B:0D:FD:B8:E2

Certificate # 2 - Common Name: GlobalSign RSA OV SSL CA 2018

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name GlobalSign RSA OV SSL CA 2018
Subject Organization GlobalSign nv-sa
Issuer Common Name GlobalSign
Issuer Organization GlobalSign
Not Before: Nov 21, 2018 00:00:00 GMT
Not After: Nov 21, 2028 00:00:00 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 1ee5f221dfc623bd4333a8557
SHA1 Fingerprint: DF:E8:30:23:06:2B:99:76:82:70:8B:4E:AB:8E:81:9A:FF:5D:97:75
MD5 Fingerprint: A7:5D:8B:21:09:11:EE:17:3E:FD:25:E1:E0:0E:D6:FD

OpenSSL Handshake

depth=1 C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 C = GB, ST = Greater London, L = London, O = Government Digital Service, CN = www.gov.uk
verify return:1
CONNECTED(00000003)
OCSP response: 
======================================
OCSP Response Data:
    OCSP Response Status: successful (0x0)
    Response Type: Basic OCSP Response
    Version: 1 (0x0)
    Responder Id: D677FE585DB30E7D5A90EADAB153FFA8BA74CCA6
    Produced At: Apr 16 15:46:49 2024 GMT
    Responses:
    Certificate ID:
      Hash Algorithm: sha1
      Issuer Name Hash: 6B7064FE6A7443DC2D6D5B79ECACA7AE5C2EC33F
      Issuer Key Hash: F8EF7FF2CD7867A8DE6F8F248D88F1870302B3EB
      Serial Number: 0EAC5D99FC6C5CCA479377F3
    Cert Status: good
    This Update: Apr 16 15:46:49 2024 GMT
    Next Update: Apr 20 15:46:48 2024 GMT

    Signature Algorithm: sha256WithRSAEncryption
         20:91:e3:2b:8d:95:71:09:75:46:4a:a8:34:b7:7d:1f:c4:77:
         f0:e6:48:06:36:3f:6b:2c:b7:7e:4a:59:28:81:e4:64:fb:14:
         1c:9e:1a:7b:89:ab:f4:c4:38:7e:85:bb:77:01:7a:60:0e:f8:
         45:d7:b8:36:5f:9e:70:fc:84:54:dc:53:d2:d1:75:d9:3a:c0:
         af:9f:a1:dd:30:ba:67:5e:e0:95:ec:38:b4:38:ab:52:24:a2:
         c0:13:96:65:80:ad:a0:75:51:25:76:9f:5e:4b:53:a5:73:16:
         9a:6d:36:ad:8c:b0:0d:39:4a:ef:43:8b:24:ad:a9:4b:fd:0b:
         5f:4a:7b:4d:cc:da:59:66:a3:ae:c8:f8:9f:7b:f6:6c:33:db:
         e3:fb:ac:0e:b4:d7:ec:90:d1:10:55:ad:20:91:5d:be:60:1f:
         8b:bf:e7:09:c9:88:26:f0:e9:71:76:6d:0e:cb:6b:d4:ae:31:
         01:05:28:8e:10:15:20:76:22:98:b6:57:23:2a:4f:6b:31:e9:
         2c:5e:62:7e:15:6d:24:ff:30:3a:7a:48:cf:49:57:31:45:e1:
         fa:e2:11:34:de:64:66:70:ef:74:69:03:25:ef:9a:62:2e:1d:
         93:eb:3b:9c:c0:63:10:99:2c:ea:bd:be:01:dc:ec:37:01:73:
         16:fc:14:be
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            65:b0:13:79:fe:c8:87:1f:32:8b:22:9b
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018
        Validity
            Not Before: Jan 29 09:29:04 2024 GMT
            Not After : Apr 30 09:29:03 2024 GMT
        Subject: C=BE, O=GlobalSign nv-sa/serialNumber=201906110004, CN=gsrsaovsslca2018CA OCSP Responder
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:a1:ea:d9:b4:9d:b6:d1:ec:e8:e7:e8:e8:8e:4b:
                    dc:38:c7:65:01:0c:70:ad:ec:2a:32:fd:10:db:42:
                    bc:8c:08:8c:15:95:f9:76:51:ff:44:da:c5:32:d1:
                    4b:97:99:26:84:22:bc:28:ee:07:d6:db:5e:87:b3:
                    8f:49:2c:59:cc:d5:03:d2:29:a6:45:08:9a:48:ff:
                    44:5e:b6:a5:65:46:e0:f4:35:9c:16:91:a4:b1:ce:
                    d3:cc:ec:03:82:e7:03:e5:4c:b5:42:8d:e6:91:b2:
                    47:2b:ad:c9:43:c3:56:e6:8a:48:28:25:d7:dc:4e:
                    8c:38:d7:02:ce:af:2a:0a:44:1e:6d:ba:f5:7c:16:
                    20:4e:58:50:e0:a9:66:50:e8:a6:63:5c:cc:45:23:
                    16:5e:cb:93:74:81:5c:23:6a:76:f7:3e:d7:d2:2f:
                    59:e0:a6:01:e2:f3:58:ff:15:cd:61:e9:32:69:c6:
                    2c:f4:93:97:de:85:6f:1a:82:6f:ae:57:22:60:97:
                    88:f7:1e:d5:f1:2f:49:d7:ff:2c:43:94:1d:d1:3c:
                    dd:28:6c:8d:be:d0:b5:3c:a2:7e:45:9b:a7:f1:d6:
                    c7:f6:bf:82:47:8b:fa:78:58:72:e3:1c:b0:48:33:
                    22:0f:d9:e4:d1:43:3b:d8:32:21:01:30:f2:8d:f4:
                    be:f7
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:F8:EF:7F:F2:CD:78:67:A8:DE:6F:8F:24:8D:88:F1:87:03:02:B3:EB

            OCSP No Check: 

            X509v3 Extended Key Usage: 
                OCSP Signing
            X509v3 Subject Key Identifier: 
                D6:77:FE:58:5D:B3:0E:7D:5A:90:EA:DA:B1:53:FF:A8:BA:74:CC:A6
            X509v3 Key Usage: critical
                Digital Signature
    Signature Algorithm: sha256WithRSAEncryption
         6e:19:40:f7:12:f8:62:e9:a4:90:27:50:af:18:82:e9:34:85:
         43:a2:89:86:a2:80:f1:4f:4b:b6:8f:fa:1b:01:2d:da:3e:ca:
         3f:70:6c:a5:35:34:b6:19:6f:4d:2c:02:d4:75:da:b4:de:f7:
         eb:01:bd:d4:ae:04:04:09:48:3e:14:e5:27:82:f3:91:48:51:
         71:a5:a9:4a:32:f9:f7:51:af:ee:5d:8b:b1:35:2f:d2:a7:8e:
         d9:e0:6d:db:32:af:84:03:b5:03:a3:67:cb:8c:0f:07:48:bf:
         00:56:1e:90:c7:07:67:cb:73:7f:2e:d1:e1:af:9d:8a:aa:92:
         32:e9:fd:25:cf:ab:3c:95:b9:db:33:42:c3:d2:3a:a5:93:2f:
         2a:0c:8a:44:df:09:ec:6a:78:17:07:ce:9c:c7:5a:af:9b:c1:
         05:3e:a3:1d:84:b4:7f:45:4a:58:18:62:0e:19:46:7b:34:f0:
         2b:f3:fe:1e:bd:21:5d:01:9e:04:a6:c7:c5:d3:14:40:fd:8c:
         e6:4c:ee:f1:0a:f6:75:69:f0:3c:70:8f:37:9f:39:68:5f:56:
         38:c9:0a:7a:68:69:59:e0:2d:83:44:36:9d:e9:a3:b1:32:eb:
         7b:37:01:59:40:1f:fe:4d:10:35:bd:68:85:ac:20:74:69:ce:
         8b:e8:6f:e8
-----BEGIN CERTIFICATE-----
MIIDuTCCAqGgAwIBAgIMZbATef7Ihx8yiyKbMA0GCSqGSIb3DQEBCwUAMFAxCzAJ
BgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1H
bG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yNDAxMjkwOTI5MDRaFw0y
NDA0MzAwOTI5MDNaMGsxCzAJBgNVBAYTAkJFMRkwFwYDVQQKDBBHbG9iYWxTaWdu
IG52LXNhMRUwEwYDVQQFEwwyMDE5MDYxMTAwMDQxKjAoBgNVBAMMIWdzcnNhb3Zz
c2xjYTIwMThDQSBPQ1NQIFJlc3BvbmRlcjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAKHq2bSdttHs6Ofo6I5L3DjHZQEMcK3sKjL9ENtCvIwIjBWV+XZR
/0TaxTLRS5eZJoQivCjuB9bbXoezj0ksWczVA9IppkUImkj/RF62pWVG4PQ1nBaR
pLHO08zsA4LnA+VMtUKN5pGyRyutyUPDVuaKSCgl19xOjDjXAs6vKgpEHm269XwW
IE5YUOCpZlDopmNczEUjFl7Lk3SBXCNqdvc+19IvWeCmAeLzWP8VzWHpMmnGLPST
l96FbxqCb65XImCXiPce1fEvSdf/LEOUHdE83Shsjb7QtTyifkWbp/HWx/a/gkeL
+nhYcuMcsEgzIg/Z5NFDO9gyIQEw8o30vvcCAwEAAaN4MHYwHwYDVR0jBBgwFoAU
+O9/8s14Z6jeb48kjYjxhwMCs+swDwYJKwYBBQUHMAEFBAIFADATBgNVHSUEDDAK
BggrBgEFBQcDCTAdBgNVHQ4EFgQU1nf+WF2zDn1akOrasVP/qLp0zKYwDgYDVR0P
AQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4IBAQBuGUD3Evhi6aSQJ1CvGILpNIVD
oomGooDxT0u2j/obAS3aPso/cGylNTS2GW9NLALUddq03vfrAb3UrgQECUg+FOUn
gvORSFFxpalKMvn3Ua/uXYuxNS/Sp47Z4G3bMq+EA7UDo2fLjA8HSL8AVh6Qxwdn
y3N/LtHhr52KqpIy6f0lz6s8lbnbM0LD0jqlky8qDIpE3wnsangXB86cx1qvm8EF
PqMdhLR/RUpYGGIOGUZ7NPAr8/4evSFdAZ4EpsfF0xRA/YzmTO7xCvZ1afA8cI83
nzloX1Y4yQp6aGlZ4C2DRDad6aOxMut7NwFZQB/+TRA1vWiFrCB0ac6L6G/o
-----END CERTIFICATE-----
======================================
---
Certificate chain
 0 s:C = GB, ST = Greater London, L = London, O = Government Digital Service, CN = www.gov.uk
   i:C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
-----BEGIN CERTIFICATE-----
MIIHezCCBmOgAwIBAgIMDqxdmfxsXMpHk3fzMA0GCSqGSIb3DQEBCwUAMFAxCzAJ
BgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1H
bG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yMzExMTQxMDMxMTJaFw0y
NDEyMTUxMDMxMTFaMHExCzAJBgNVBAYTAkdCMRcwFQYDVQQIEw5HcmVhdGVyIExv
bmRvbjEPMA0GA1UEBxMGTG9uZG9uMSMwIQYDVQQKExpHb3Zlcm5tZW50IERpZ2l0
YWwgU2VydmljZTETMBEGA1UEAxMKd3d3Lmdvdi51azCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAKii2iR6rMRSVERB2gsUwU2DlZuJvtPwOmfFewPJQk/+
KmTYaQBVdbX02HEZ1yfTirY0W47JvF4nxOdVnNB0/uJwJpEm2uqAliiVhqqC35UC
DfEp4yLCSa9Od+TqYS1txdXnoe+TKHQI/aHy2/Bf+BMPMUSq7QI88WlC4MGFO68x
NufoBZ8fNyVSjYTQ0BArcaoAFfYnTuddyDEHirGJYhx0oHjbMz7RJUKKtXU0Yjhn
fnk16Mvf3Ksl5vYbbx0T4RLyTS9QFBL+nJgUEcTfN1iCgnFVuG2uoFzBAi6rOlR/
vv8G2ymvL+h/FutZlO3LA29QmwzwHL2zLsyfOlk7cbECAwEAAaOCBDIwggQuMA4G
A1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMIGOBggrBgEFBQcBAQSBgTB/MEQG
CCsGAQUFBzAChjhodHRwOi8vc2VjdXJlLmdsb2JhbHNpZ24uY29tL2NhY2VydC9n
c3JzYW92c3NsY2EyMDE4LmNydDA3BggrBgEFBQcwAYYraHR0cDovL29jc3AuZ2xv
YmFsc2lnbi5jb20vZ3Nyc2FvdnNzbGNhMjAxODBWBgNVHSAETzBNMEEGCSsGAQQB
oDIBFDA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9y
ZXBvc2l0b3J5LzAIBgZngQwBAgIwPwYDVR0fBDgwNjA0oDKgMIYuaHR0cDovL2Ny
bC5nbG9iYWxzaWduLmNvbS9nc3JzYW92c3NsY2EyMDE4LmNybDCCAQEGA1UdEQSB
+TCB9oIKd3d3Lmdvdi51a4IVKi5idXNpbmVzc2xpbmsuZ292LnVrgg8qLmRpcmVj
dC5nb3YudWuCGyoucHVibGlzaGluZy5zZXJ2aWNlLmdvdi51a4IXKi5jYWJpbmV0
LW9mZmljZS5nb3YudWuCJGFzc2V0cy5kaWdpdGFsLmNhYmluZXQtb2ZmaWNlLmdv
di51a4IOc2VydmljZS5nb3YudWuCC2RhdGEuZ292LnVrggtkZmlkLmdvdi51a4IV
Y2FiaW5ldC1vZmZpY2UuZ292LnVrggphcGkuZ292LnVrgg93d3cuZGF0YS5nb3Yu
dWuCBmdvdi51azAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHwYDVR0j
BBgwFoAU+O9/8s14Z6jeb48kjYjxhwMCs+swHQYDVR0OBBYEFK4QSlHIrfqojfAo
zh/9rCAvsnVkMIIBfgYKKwYBBAHWeQIEAgSCAW4EggFqAWgAdgBIsONr2qZHNA/l
agL6nTDrHFIBy1bdLIHZu7+rOdiEcwAAAYvNYpwxAAAEAwBHMEUCIDEUYZ2PRXH3
jVS+JXcZvMW+zeiAkVPUO+c6ZeiwcUJoAiEA5lPjSSlH6QG10K/e4j0BDzhPGknA
tj3P6X0AYC8w6KgAdwDuzdBk1dsazsVct520zROiModGfLzs3sNRSFlGcR+1mwAA
AYvNYp8gAAAEAwBIMEYCIQC3CUwygtiAl+Sd/OOI9Vk06XdwZC/LOmwCrQTS0/mA
9AIhAKIB1wsqXFWW7ZtenZq7nRvcxlP+y/jglGHBYaUp7R1WAHUAdv+IPwq2+5VR
wmHM9Ye6NLSkzbsp3GhCCp/mZ0xaOnQAAAGLzWKiAQAABAMARjBEAiA7kTi4O+n4
ISs5gFqV/Gsds9w+zT6NsGvDpFc8UFDrUQIgAPm3eaeWZw+fd1NXI5Ns50/cvQrD
5EIogrKVAJFmHSEwDQYJKoZIhvcNAQELBQADggEBAJNKO4ymd1HjzFKaoXtii5CS
BkiCIk8UMKKCRBXlj7uGaIhYS10RBU5y/tj9vwrqwcIJfhCAm/bXzYSivkXdnW9d
m9l/RIIigkk1vluF+lZYEgS1Es6y3XZk5CPDpYzceLP+sJ9V7XDsGLRjkdsdjEZ8
sXp1Nd3m5czrTCUWgB9vxDo4ke68TbwqM1eObH8YyBvecpWYDEYx7kubujk7jPVV
iN8yYbMvP3+5hIGUQHMe2JMdjAgmb9g841Ct5wLoFmiV3tsshU4B6vFcsXI655qA
s/WeRUA+K595vjuCoGKe7Od3Ur+N7UR3oK4COkp6NmV1QzzXuJFHAAz7VxrNZcI=
-----END CERTIFICATE-----
 1 s:C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
   i:OU = GlobalSign Root CA - R3, O = GlobalSign, CN = GlobalSign
-----BEGIN CERTIFICATE-----
MIIETjCCAzagAwIBAgINAe5fIh38YjvUMzqFVzANBgkqhkiG9w0BAQsFADBMMSAw
HgYDVQQLExdHbG9iYWxTaWduIFJvb3QgQ0EgLSBSMzETMBEGA1UEChMKR2xvYmFs
U2lnbjETMBEGA1UEAxMKR2xvYmFsU2lnbjAeFw0xODExMjEwMDAwMDBaFw0yODEx
MjEwMDAwMDBaMFAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52
LXNhMSYwJAYDVQQDEx1HbG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKdaydUMGCEAI9WXD+uu3Vxoa2uP
UGATeoHLl+6OimGUSyZ59gSnKvuk2la77qCk8HuKf1UfR5NhDW5xUTolJAgvjOH3
idaSz6+zpz8w7bXfIa7+9UQX/dhj2S/TgVprX9NHsKzyqzskeU8fxy7quRU6fBhM
abO1IFkJXinDY+YuRluqlJBJDrnw9UqhCS98NE3QvADFBlV5Bs6i0BDxSEPouVq1
lVW9MdIbPYa+oewNEtssmSStR8JvA+Z6cLVwzM0nLKWMjsIYPJLJLnNvBhBWk0Cq
o8VS++XFBdZpaFwGue5RieGKDkFNm5KQConpFmvv73W+eka440eKHRwup08CAwEA
AaOCASkwggElMA4GA1UdDwEB/wQEAwIBhjASBgNVHRMBAf8ECDAGAQH/AgEAMB0G
A1UdDgQWBBT473/yzXhnqN5vjySNiPGHAwKz6zAfBgNVHSMEGDAWgBSP8Et/qC5F
JK5NUPpjmove4t0bvDA+BggrBgEFBQcBAQQyMDAwLgYIKwYBBQUHMAGGImh0dHA6
Ly9vY3NwMi5nbG9iYWxzaWduLmNvbS9yb290cjMwNgYDVR0fBC8wLTAroCmgJ4Yl
aHR0cDovL2NybC5nbG9iYWxzaWduLmNvbS9yb290LXIzLmNybDBHBgNVHSAEQDA+
MDwGBFUdIAAwNDAyBggrBgEFBQcCARYmaHR0cHM6Ly93d3cuZ2xvYmFsc2lnbi5j
b20vcmVwb3NpdG9yeS8wDQYJKoZIhvcNAQELBQADggEBAJmQyC1fQorUC2bbmANz
EdSIhlIoU4r7rd/9c446ZwTbw1MUcBQJfMPg+NccmBqixD7b6QDjynCy8SIwIVbb
0615XoFYC20UgDX1b10d65pHBf9ZjQCxQNqQmJYaumxtf4z1s4DfjGRzNpZ5eWl0
6r/4ngGPoJVpjemEuunl1Ig423g7mNA2eymw0lIYkN5SQwCuaifIFJ6GlazhgDEw
fpolu4usBCOmmQDo8dIm7A9+O4orkjgTHY+GzYZSR+Y0fFukAj6KYXwidlNalFMz
hriSqHKvoflShx8xpfywgVcvzfTO3PYkz6fiNJBonf6q8amaEsybwMbDqKWwIX7e
SPY=
-----END CERTIFICATE-----
---
Server certificate
subject=C = GB, ST = Greater London, L = London, O = Government Digital Service, CN = www.gov.uk

issuer=C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018

---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 5014 bytes and written 385 bytes
Verification error: unable to get local issuer certificate
---
New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256
Server public key is 2048 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 20 (unable to get local issuer certificate)
---
DONE
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
    Protocol  : TLSv1.3
    Cipher    : TLS_AES_128_GCM_SHA256
    Session-ID: FF8695E33FBD06D75C0FA8424A3287FAD295DDB050E905ADBE93E136285C62C1
    Session-ID-ctx: 
    Resumption PSK: 1C5E904ED5A280DDD64FBEEA7F6857C7B445677FE7E04AC9EE8DE06EEA489C59
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 3600 (seconds)
    TLS session ticket:
    0000 - 35 b6 88 9e 79 a7 dc b4-7f 70 a7 c3 cb f3 34 e5   5...y....p....4.
    0010 - b9 2b 05 bc 5e 84 96 56-d2 f5 51 88 5c 10 ac bb   .+..^..V..Q.\...
    0020 - b4 7d c7 91 a6 0c b8 97-93 3e 30 32 7a 6b 05 74   .}.......>02zk.t
    0030 - 63 72 d8 8a 71 fc 01 10-3a b4 9e ca 21 30 38 e9   cr..q...:...!08.
    0040 - d9 05 d0 cd d1 cc 47 36-62 56 0b 82 39 2a bc e4   ......G6bV..9*..
    0050 - 46 be 4d aa 74 43 89 ae-55 c6 4e 2d 14 64 b6 6f   F.M.tC..U.N-.d.o
    0060 - f4 9d fc da 07 03 4a 80-5f 08 88 0f aa 70 a2 73   ......J._....p.s
    0070 - b3 1c 37 d9 f7 37 67 9d-03 cd a7 00 2c 77 1b 89   ..7..7g.....,w..
    0080 - 30 df 12 d5 79 6a 71 cf-6d 2a 15 be dd 94 27 8a   0...yjq.m*....'.
    0090 - d0 ab 92 63 a2 f9 c3 61-2c 89 de 14 57 40 ca 34   ...c...a,...W@.4

    Start Time: 1713531539
    Timeout   : 7200 (sec)
    Verify return code: 20 (unable to get local issuer certificate)
    Extended master secret: no
    Max Early Data: 0
---
read R BLOCK