Re: NNTPS?
Adam Sjøgren <[email protected]>
| Newsgroups | gmane.discuss |
|---|---|
| Organization | koldfront - analysis & revolution, Copenhagen, Denmark |
| Message-ID | <[email protected]> |
Dmitry writes:
> Is NNTP over TLS supposed to be functional here?
It used to be on a separate host, snews.gmane,org, but I don't think
that exists any more.
You can use STARTTLS on news.gmane.org, however:
$ gnutls-cli --starttls-proto=nntp news.gmane.org
Processed 129 CA certificate(s).
Resolving 'news.gmane.org:nntp'...
Connecting to '195.159.176.226:119'...
- Certificate type: X.509
- Got a certificate list of 3 certificates.
- Certificate[0] info:
- subject `CN=news.gmane.org', issuer `CN=Let's Encrypt Authority X3,O=Let's Encrypt,C=US', serial 0x04d1958906e0428e801cf6618fb3a9f5afde, RSA key 2048 bits, signed using RSA-SHA256, activated `2019-01-21 17:01:44 UTC', expires `2019-04-21 17:01:44 UTC', pin-sha256="Ol79a9dR+kyrl8aGb9BrLW2+bDTx4EY/BUDmgYUGQHU="
Public Key ID:
sha1:10dfd650e4f5f4b493d289431ce3fac6316b0f6b
sha256:3a5efd6bd751fa4cab97c6866fd06b2d6dbe6c34f1e0463f0540e68185064075
Public Key PIN:
pin-sha256:Ol79a9dR+kyrl8aGb9BrLW2+bDTx4EY/BUDmgYUGQHU=
- Certificate[1] info:
- subject `CN=Let's Encrypt Authority X3,O=Let's Encrypt,C=US', issuer `CN=DST Root CA X3,O=Digital Signature Trust Co.', serial 0x0a0141420000015385736a0b85eca708, RSA key 2048 bits, signed using RSA-SHA256, activated `2016-03-17 16:40:46 UTC', expires `2021-03-17 16:40:46 UTC', pin-sha256="YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg="
- Certificate[2] info:
- subject `CN=DST Root CA X3,O=Digital Signature Trust Co.', issuer `CN=DST Root CA X3,O=Digital Signature Trust Co.', serial 0x44afb080d6a327ba893039862ef8406b, RSA key 2048 bits, signed using RSA-SHA1 (broken!), activated `2000-09-30 21:12:19 UTC', expires `2021-09-30 14:01:15 UTC', pin-sha256="Vjs8r4z+80wjNcr1YKepWQboSIRi63WsWXhIMN+eWys="
- Status: The certificate is trusted.
- Description: (TLS1.2)-(ECDHE-X25519)-(RSA-SHA512)-(AES-256-GCM)
- Session ID: B9:8A:00:F3:85:B6:6C:06:A5:AF:A2:10:7A:25:A7:13:10:DB:42:93:A7:AF:4B:1B:A3:E0:0C:8A:DE:71:D6:D0
- Options: extended master secret, safe renegotiation,
- Handshake was completed
- Simple Client Mode:
mode reader
200 news.gmane.org InterNetNews NNRP server INN 2.6.1 ready (posting ok)
quit
205 Bye!
- Peer has closed the GnuTLS connection
Gnus, at least, automatically uses STARTTLS.
Best regards,
Adam
--
"I wish *I* was a tiger!" Adam Sjøgren
"A common lament." [email protected]