Skip to content

--show-client-cas does not show lots of entries #344

@limpus64

Description

@limpus64
$ sslscan --no-colour --show-client-cas mail.mdv.de
Version: 2.2.0-static
OpenSSL 3.5.0 8 Apr 2025
…
  Acceptable client certificate CA names:
/C=de/O=Mitteldeutscher Verkehrsverbund/CN=MDV WebAccess Authority/emailAddress=post@mdv.de

Works perfectly for a single accepted client CA name. But here comes the problem:

sslscan --no-colour --show-client-cas bersy.perdata.de
Version: 2.2.0-static
OpenSSL 3.5.0 8 Apr 2025

Connected to 83.137.33.249
…

No acceptable CA names for client certificates are displayed, even though openssl s_client lists 66 of them.

$ openssl s_client bersy.perdata.de:443 < /dev/null
Connecting to 83.137.33.249
…
Acceptable client certificate CA names
C=DE, ST=NRW, …
… 
65 client certificate CA subjects omitted for brevity

Would you please list all those names?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions