Forum Discussion
Zainal_Abidin_1
Nimbostratus
Jul 02, 2014SSL make login slow
Hi, We're apache web server to host my application. At front we have F5 LTM 1600. Last engineer who setting this SSL is redirect on F5. On apache web server i did not find any SSL cert. It's usin...
Zainal_Abidin_1
Nimbostratus
Jul 04, 2014This is full error:
[root@vsvr-console ~] openssl s_client -connect host.to.our.system.com:443
CONNECTED(00000003)
depth=0 /OU=Domain Control Validated/CN=host.to.our.system.com
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 /OU=Domain Control Validated/CN=host.to.our.system.com
verify error:num=27:certificate not trusted
verify return:1
depth=0 /OU=Domain Control Validated/CN=host.to.our.system.com
verify error:num=21:unable to verify the first certificate
verify return:1
---
Certificate chain
0 s:/OU=Domain Control Validated/CN=host.to.our.system.com
i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFZjCCBE6gAwIBAgIHKz68rKQk1zANBgkqhkiG9w0BAQUFADCByjELMAkGA1UE
BhMCVVMxEDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNjb3R0c2RhbGUxGjAY
BgNVBAoTEUdvRGFkZHkuY29tLCBJbmMuMTMwMQYDVQQLEypodHRwOi8vY2VydGlm
aWNhdGVzLmdvZGFkZHkuY29tL3JlcG9zaXRvcnkxMDAuBgNVBAMTJ0dvIERhZGR5
IFNlY3VyZSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTERMA8GA1UEBRMIMDc5Njky
ODcwHhcNMTMxMjExMjI1NTA0WhcNMTQxMjAzMDQzOTQzWjBFMSEwHwYDVQQLExhE
b21haW4gQ29udHJvbCBWYWxpZGF0ZWQxIDAeBgNVBAMTF2Vjb3B5cmlnaHQubXlp
cG8uZ292Lm15MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4pTsKG/H
LjawDZEtXM+mwg6Vew3U3ngk/xDm+YEaRrPlKc/jOPzNF+AXfggnBjjux8oEgXhm
tZTi8srS//lvOPtZCmbrHlB0Xmyk2UFYZVzFIEbmmpvr7aWP3zkNdaHbL1bfWqk8
sjgQeT0kyCxIe9iXscHa3gdHiLTmu9sfvP1RnhicMKO9nO1euho6mx/fp2ma254z
PKMwDMljUljh0MaLjRdRxDybsP7qiHiAhJVvOkqjJyLzvCFvGLEhgJAxfCtv0gDs
+SLMfElhG1gmvrhJ1zVh0mEtrirwJT46E8Pyh0FvQr3b/SeSIb6ufPfgTRx19Chq
x2Fzy+cpOsXBdQIDAQABo4IB0zCCAc8wDwYDVR0TAQH/BAUwAwEBADAdBgNVHSUE
FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDgYDVR0PAQH/BAQDAgWgMDQGA1UdHwQt
MCswKaAnoCWGI2h0dHA6Ly9jcmwuZ29kYWRkeS5jb20vZ2RzMS0xMDQuY3JsMFMG
A1UdIARMMEowSAYLYIZIAYb9bQEHFwEwOTA3BggrBgEFBQcCARYraHR0cDovL2Nl
cnRpZmljYXRlcy5nb2RhZGR5LmNvbS9yZXBvc2l0b3J5LzCBgAYIKwYBBQUHAQEE
dDByMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5nb2RhZGR5LmNvbS8wSgYIKwYB
BQUHMAKGPmh0dHA6Ly9jZXJ0aWZpY2F0ZXMuZ29kYWRkeS5jb20vcmVwb3NpdG9y
eS9nZF9pbnRlcm1lZGlhdGUuY3J0MB8GA1UdIwQYMBaAFP2sYTKTbEXW4u6FX5q6
53aZaMznMD8GA1UdEQQ4MDaCF2Vjb3B5cmlnaHQubXlpcG8uZ292Lm15ght3d3cu
ZWNvcHlyaWdodC5teWlwby5nb3YubXkwHQYDVR0OBBYEFH+T4+FeLSP/lxy+6gYt
CHu4ycCrMA0GCSqGSIb3DQEBBQUAA4IBAQBCr4287/BAhdyA9MhN+MVrPjXtWNT0
gFgC/RXkvF6lviHEBZKwM4qH8nWMmskoH57/Devyy3D7HSqvgcSJf80koe+rxWVL
CKiOuT4dG6gJz5BwTN3iwO7dE/mtLXMfpdDXwdlk+sbeYEyfI+m6WjrkYSs4oy3j
iov4urctdAkWn7bjn+nwBcTJCSVfU3ijhDuHt1K5OwsuZrI69ZXyCzy+bBCDdBLC
DMRenBSvs+MJAzXu5UWEpBFAQ5ZzeK+Q2G87/vKaN4IlAWZ7mAK2kQKHslwWL7oh
gZsRcEzNpDWVZYwGtl3XD/m5lNiMOYFVu4/WQ6NZqsCeGOVngnxN5XCd
-----END CERTIFICATE-----
subject=/OU=Domain Control Validated/CN=host.to.our.system.com
issuer=/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
---
No client certificate CA names sent
---
SSL handshake has read 1556 bytes and written 447 bytes
---
New, TLSv1/SSLv3, Cipher is RC4-SHA
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : RC4-SHA
Session-ID: 4585C1DC2D5EF0A8197FC582D5DBCB5BC2648DDC1D33F741D3A6B13216E0875A
Session-ID-ctx:
Master-Key: CF968E8C26DB1215BE65614209DAE876995F57D0351A4DC3CCD272384E7AC3B0D99D6889A9960A1765C3B8DD80788CF4
Key-Arg : None
Krb5 Principal: None
Start Time: 1404440552
Timeout : 300 (sec)
Verify return code: 21 (unable to verify the first certificate)
---
read:errno=0
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects