OpenSSL> s_client -connect s03qnkal7953.s4.chp.cba:9520 -servername int-kafka-v1-uat.service.syd.sd.nprod.cba CONNECTED(00000188) depth=0 C = AU, ST = NSW, L = Sydney, O = Commonwealth Bank of Australia, OU = Enterprise Services, CN = kafka.service.syd.sd.nprod.cba verify error:num=20:unable to get local issuer certificate verify return:1 depth=0 C = AU, ST = NSW, L = Sydney, O = Commonwealth Bank of Australia, OU = Enterprise Services, CN = kafka.service.syd.sd.nprod.cba verify error:num=21:unable to verify the first certificate verify return:1 --- Certificate chain 0 s:C = AU, ST = NSW, L = Sydney, O = Commonwealth Bank of Australia, OU = Enterprise Services, CN = kafka.service.syd1.sd.nprod.cba i:C = AU, ST = New South Wales, L = Sydney, O = Commonwealth Bank of Australia, OU = Enterprise Services, CN = CBA SHA2 Class 1 Prod - G1 --- Server certificate -----BEGIN CERTIFICATE----- MIINJzCCCw+gAwIBAgITUAAAw7r6dzH0QGZUsgAAAADDujANBgkqhkiG9w0BAQsF ADCBpDELMAkGA1UEBhMCQVUxGDAWBgNVBAgTD05ldyBTb3V0aCBXYWxlczEPMA0G A1UEBxMGU3lkbmV5MScwJQYDVQQKEx5Db21tb253ZWFsdGggQmFuayBvZiBBdXN0 cmFsaWExHDAaBgNVBAsTE0VudGVycHJpc2UgU2VydmljZXMxIzAhBgNVBAMTGkNC QSBTSEEyIENsYXNzIDEgUHJvZCAtIEcxMB4XDTIwMDQxOTIzMjIzMVoXDTIxMDQx OTIzMjIzMVowgaAxCzAJBgNVBAYTAkFVMQwwCgYDVQQIEwNOU1cxDzANBgNVBAcT BlN5ZG5leTEnMCUGA1UEChMeQ29tbW9ud2VhbHRoIEJhbmsgb2YgQXVzdHJhbGlh MRwwGgYDVQQLExNFbnRlcnByaXNlIFNlcnZpY2VzMSswKQYDVQQDEyJrYWZrYWFw aS5zZXJ2aWNlLnN5ZDEuc2QubnByb2QuY2JhMIIBIjANBgkqhkiG9w0BAQEFAAOC AQ8AMIIBCgKCAQEA2VOpfAFXLkRMgtJoD3puerl4WOdg4gQ0nX6qOyo+Ivqipwqt QthtiqWMVv582ZdHjXuB8eJELeZTvULY9dY9XQAsSYhKa3Y4RlQJr+0l66RoJNpl 5y1FmlcMUFW/tQplXYZ/C5cuLyStksS7MW3Yjtidu4/W83FG0Wb7kkueed3PR6j9 l4zxRWcwT9lJ2geMF5m04hsLOsZUdOpC72hAzpOJDZZJKdLMzB7txi45GHRAhwKa oofTNhnuelxbNsv05h5YnZ61VQ8C0sN//hkTgenmV+NJyUZQwQ9eLsoVzmWsLnZa oGvusit/5eh+MZfhZVJCP4r/df2pNkyIy/29vwIDAQABo4IIUjCCCE4wNgYJKwYB BAGCNxUKBCkwJzANBgsrBgEEAYGkZwoEATAKBggrBgEFBQcDAjAKBggrBgEFBQcD ATA+BgkrBgEEAYI3FQcEMTAvBicrBgEEAYI3FQiCvq1ihL+PNoT5iSGErO90g6e/ foFFgqqjbof6u2oCAWQCAQkwdAYIKwYBBQUHAQEEaDBmMD4GCCsGAQUFBzAChjJo dHRwOi8vdmEucHJvZC5jYmEvY3J0L0NCQS1TSEEyLUNsYXNzMS1Qcm9kLUcxLmNy dDAkBggrBgEFBQcwAYYYaHR0cDovL3ZhLnByb2QuY2JhL29jc3AvMB0GA1UdDgQW BBQDsJDPKc8F43GMKbnkWflVVR2XYDALBgNVHQ8EBAMCBaAwggaeBgNVHREEggaV MIIGkYIZc2VydmljZS5zeWQxLnNkLm5wcm9kLmNiYYItaW50LWthZmthYXBpLXYx LWRldi5zZXJ2aWNlLnN5ZDEuc2QubnByb2QuY2JhgjFpbnQta2Fma2FhcGktdjEt ZGV2LnNlcnZpY2UuczNiLnN5ZDEuc2QubnByb2QuY2JhgjFpbnQta2Fma2FhcGkt djEtZGV2LnNlcnZpY2UuczNuLnN5ZDEuc2QubnByb2QuY2JhgjJoYXN5ZDEtaW50 LWthZmthYXBpLXYxLWRldi5xdWVyeS5zeWQxLnNkLm5wcm9kLmNiYYI2aGFzeWQx LWludC1rYWZrYWFwaS12MS1kZXYucXVlcnkuczNiLnN5ZDEuc2QubnByb2QuY2Jh gjZoYXN5ZDEtaW50LWthZmthYXBpLXYxLWRldi5xdWVyeS5zM24uc3lkMS5zZC5u cHJvZC5jYmGCL2ludC1rYWZrYWFwaS12MS1zdGRldi5zZXJ2aWNlLnN5ZDEuc2Qu bnByb2QuY2JhgjNpbnQta2Fma2FhcGktdjEtc3RkZXYuc2VydmljZS5zM2Iuc3lk MS5zZC5ucHJvZC5jYmGCM2ludC1rYWZrYWFwaS12MS1zdGRldi5zZXJ2aWNlLnMz bi5zeWQxLnNkLm5wcm9kLmNiYYI0aGFzeWQxLWludC1rYWZrYWFwaS12MS1zdGRl di5xdWVyeS5zeWQxLnNkLm5wcm9kLmNiYYI4aGFzeWQxLWludC1rYWZrYWFwaS12 MS1zdGRldi5xdWVyeS5zM2Iuc3lkMS5zZC5ucHJvZC5jYmGCOGhhc3lkMS1pbnQt a2Fma2FhcGktdjEtc3RkZXYucXVlcnkuczNuLnN5ZDEuc2QubnByb2QuY2Jhgi1p bnQta2Fma2FhcGktdjEtdWF0LnNlcnZpY2Uuc3lkMS5zZC5ucHJvZC5jYmGCMWlu dC1rYWZrYWFwaS12MS11YXQuc2VydmljZS5zM2Iuc3lkMS5zZC5ucHJvZC5jYmGC MWludC1rYWZrYWFwaS12MS11YXQuc2VydmljZS5zM24uc3lkMS5zZC5ucHJvZC5j YmGCMmhhc3lkMS1pbnQta2Fma2FhcGktdjEtdWF0LnF1ZXJ5LnN5ZDEuc2QubnBy b2QuY2JhgjZoYXN5ZDEtaW50LWthZmthYXBpLXYxLXVhdC5xdWVyeS5zM2Iuc3lk MS5zZC5ucHJvZC5jYmGCNmhhc3lkMS1pbnQta2Fma2FhcGktdjEtdWF0LnF1ZXJ5 LnMzbi5zeWQxLnNkLm5wcm9kLmNiYYItaW50LWthZmthYXBpLXYxLW5mdC5zZXJ2 aWNlLnN5ZDEuc2QubnByb2QuY2JhgjFpbnQta2Fma2FhcGktdjEtbmZ0LnNlcnZp Y2UuczNiLnN5ZDEuc2QubnByb2QuY2JhgjFpbnQta2Fma2FhcGktdjEtbmZ0LnNl cnZpY2UuczNuLnN5ZDEuc2QubnByb2QuY2JhgjJoYXN5ZDEtaW50LWthZmthYXBp LXYxLW5mdC5xdWVyeS5zeWQxLnNkLm5wcm9kLmNiYYI2aGFzeWQxLWludC1rYWZr aW50LWthZmthYXBpLXYxLW5mdC5xdWVyeS5zM24uc3lkMS5zZC5ucHJvZC5jYmGC MmludC1rYWZrYWFwaS12MS1wcm9kc3VwcC5zZXJ2aWNlLnN5ZDEuc2QubnByb2Qu Y2JhgjZpbnQta2Fma2FhcGktdjEtcHJvZHN1cHAuc2VydmljZS5zM2Iuc3lkMS5z ZC5ucHJvZC5jYmGCNmludC1rYWZrYWFwaS12MS1wcm9kc3VwcC5zZXJ2aWNlLnMz c3VwcC5xdWVyeS5zeWQxLnNkLm5wcm9kLmNiYYI7aGFzeWQxLWludC1rYWZrYWFw aS12MS1wcm9kc3VwcC5xdWVyeS5zM2Iuc3lkMS5zZC5ucHJvZC5jYmGCO2hhc3lk MS1pbnQta2Fma2FhcGktdjEtcHJvZHN1cHAucXVlcnkuczNuLnN5ZDEuc2QubnBy VNbIo9TxcKV0GZ0drkPqagUI3qi+y3uDMW+/YNH+vXLu4vz0HtcUdPQqQ/ehrZhO RQy1Inz9cnaJ7v8= -----END CERTIFICATE----- subject=C = AU, ST = NSW, L = Sydney, O = Commonwealth Bank of Australia, OU = Enterprise Services, CN = kafka.service.syd1.sd.nprod.cba issuer=C = AU, ST = New South Wales, L = Sydney, O = Commonwealth Bank of Australia, OU = Enterprise Services, CN = CBA SHA2 Class 1 Prod - G1 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA Server Temp Key: DH, 1024 bits --- SSL handshake has read 4097 bytes and written 577 bytes Verification error: unable to verify the first certificate --- New, TLSv1.2, Cipher is DHE-RSA-AES256-SHA256 Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : DHE-RSA-AES256-SHA256 Session-ID: 5EFDF318D6A10B4EFADADA372A16860474B8273A5C895D6ED9F22905C6DBCAB6 Session-ID-ctx: Master-Key: 20381B65B0419064359BB05176A6AE3E0ADEE412F1F3BEE980238CD4F941C38030E916056674FF2DDADB7B85263DF45 PSK identity: None PSK identity hint: None SRP username: None Start Time: 1593701144 Timeout : 7200 (sec) Verify return code: 21 (unable to verify the first certificate) Extended master secret: yes ---