15 January 2013

How To Grab a SSL Certificate From a Host

Again, lately I've been working on a project that requires the use of SSL and therefore certificates. This is just a note for my own posterity more than anything, but if you ever need to grab a SSL certificate from a host so that you can import it into your keystore, here's how to do so using the OpenSSL s_client:
$ openssl s_client -connect <host>:<port> > foo.cert
Just make sure to substitute the <host> with the DNS name of the host and the <port> with the actual port number. Once you have the foo.cert file, you will need to manually clean up the foo.cert file a little bit, but it works. Here's a quick example:
$ openssl s_client -connect yahoo.com:443 > yahoo.cert
depth=0 /serialNumber=2g8aO5wI1bKJ2ZD588UsLvDe3gTbg8DU/C=US/ST=California/L=Sunnyvale/O=Yahoo  Inc./CN=www.yahoo.com
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 /serialNumber=2g8aO5wI1bKJ2ZD588UsLvDe3gTbg8DU/C=US/ST=California/L=Sunnyvale/O=Yahoo  Inc./CN=www.yahoo.com
verify error:num=27:certificate not trusted
verify return:1
depth=0 /serialNumber=2g8aO5wI1bKJ2ZD588UsLvDe3gTbg8DU/C=US/ST=California/L=Sunnyvale/O=Yahoo  Inc./CN=www.yahoo.com
verify error:num=21:unable to verify the first certificate
verify return:1
^C
$ 
$
$
$
$ cat ./yahoo.cert
CONNECTED(00000003)
---
Certificate chain
 0 s:/serialNumber=2g8aO5wI1bKJ2ZD588UsLvDe3gTbg8DU/C=US/ST=California/L=Sunnyvale/O=Yahoo  Inc./CN=www.yahoo.com
   i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIE6jCCBFOgAwIBAgIDEIGKMA0GCSqGSIb3DQEBBQUAME4xCzAJBgNVBAYTAlVT
MRAwDgYDVQQKEwdFcXVpZmF4MS0wKwYDVQQLEyRFcXVpZmF4IFNlY3VyZSBDZXJ0
aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTAwNDAxMjMwMDE0WhcNMTUwNzAzMDQ1MDAw
WjCBjzEpMCcGA1UEBRMgMmc4YU81d0kxYktKMlpENTg4VXNMdkRlM2dUYmc4RFUx
CzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRIwEAYDVQQHEwlTdW5u
eXZhbGUxFDASBgNVBAoTC1lhaG9vICBJbmMuMRYwFAYDVQQDEw13d3cueWFob28u
Y29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6ZM1jHCkL8rlEKse
1riTTxyC3WvYQ5m34TlFK7dK4QFI/HPttKGqQm3aVB1Fqi0aiTxe4YQMbd++jnKt
djxcpi7sJlFxjMZs4umr1eGo2KgTgSBAJyhxo23k+VpK1SprdPyM3yEfQVdV7JWC
4Y71CE2nE6+GbsIuhk/to+jJMO7jXx/430jvo8vhNPL6GvWe/D6ObbnxS72ynLSd
mLtaltykOvZEZiXbbFKgIaYYmCgh89FGVvBkUbGM/Wb5Voiz7ttQLLxKOYRj8Mdk
TZtzPkM9scIFG1naECPvCxw0NyMyxY3nFOdjUKJ79twanmfCclX2ZO/rk1CpiOuw
lrrr/QIDAQABo4ICDjCCAgowDgYDVR0PAQH/BAQDAgTwMB0GA1UdDgQWBBSmrfKs
68m+dDUSf+S7xJrQ/FXAlzA6BgNVHR8EMzAxMC+gLaArhilodHRwOi8vY3JsLmdl
b3RydXN0LmNvbS9jcmxzL3NlY3VyZWNhLmNybDCCAVsGA1UdEQSCAVIwggFOgg13
d3cueWFob28uY29tggl5YWhvby5jb22CDHVzLnlhaG9vLmNvbYIMa3IueWFob28u
Y29tggx1ay55YWhvby5jb22CDGllLnlhaG9vLmNvbYIMZnIueWFob28uY29tggxp
bi55YWhvby5jb22CDGNhLnlhaG9vLmNvbYIMYnIueWFob28uY29tggxkZS55YWhv
by5jb22CDGVzLnlhaG9vLmNvbYIMbXgueWFob28uY29tggxpdC55YWhvby5jb22C
DHNnLnlhaG9vLmNvbYIMaWQueWFob28uY29tggxwaC55YWhvby5jb22CDHFjLnlh
aG9vLmNvbYIMdHcueWFob28uY29tggxoay55YWhvby5jb22CDGNuLnlhaG9vLmNv
bYIMYXUueWFob28uY29tggxhci55YWhvby5jb22CDHZuLnlhaG9vLmNvbTAfBgNV
HSMEGDAWgBRI5mj5K9KylddH2CMgEE8zmJCf1DAdBgNVHSUEFjAUBggrBgEFBQcD
AQYIKwYBBQUHAwIwDQYJKoZIhvcNAQEFBQADgYEAp9WOMtcDMM5T0yfPecGv5QhH
RJZRzgeMPZitLksr1JxxicJrdgv82NWq1bw8aMuRj47ijrtaTEWXaCQCy00yXodD
zoRJVNoYIvY1arYZf5zv9VZjN5I0HqUc39mNMe9XdZtbkWE+K6yVh6OimKLbizna
inu9YTrN/4P/w6KzHho=
-----END CERTIFICATE-----
subject=/serialNumber=2g8aO5wI1bKJ2ZD588UsLvDe3gTbg8DU/C=US/ST=California/L=Sunnyvale/O=Yahoo  Inc./CN=www.yahoo.com
issuer=/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
---
No client certificate CA names sent
---
SSL handshake has read 1392 bytes and written 456 bytes
---
New, TLSv1/SSLv3, Cipher is AES256-SHA
Server public key is 2048 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
SSL-Session:
    Protocol  : TLSv1
    Cipher    : AES256-SHA
    Session-ID: 
    Session-ID-ctx: 
    Master-Key: 6385A37EF8BA3E886A242E4F835C453BBE6740C2C240BF9C0F80ED7E0586500B87007EB839C57A8E5539C7CF21387C9F
    Key-Arg   : None
    Start Time: 1358267053
    Timeout   : 300 (sec)
    Verify return code: 21 (unable to verify the first certificate)
---
closed

How To List All Certificates in the JDK cacerts File

Lately I've been working on a project that requires the use of SSL and therefore certificates. While working though the necessary tasks, I became curious about the number of certificates that exist in the default truststore in the JDK for Mac OS X (it's named cacerts). Well using Java's keytool utility it's easy to take a peek at them. Here's how to list them:
$ echo 'changeit' | keytool -list -v -keystore $(find $JAVA_HOME -name cacerts) | grep 'Owner:'
Enter keystore password:  Owner: CN=TWCA Root Certification Authority, OU=Root CA, O=TAIWAN-CA, C=TW
Owner: OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US
Owner: CN=NetLock Uzleti (Class B) Tanusitvanykiado, OU=Tanusitvanykiadok, O=NetLock Halozatbiztonsagi Kft., L=Budapest, C=HU
Owner: CN=Certum Trusted Network CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL
Owner: CN=Wells Fargo Root Certificate Authority, OU=Wells Fargo Certification Authority, O=Wells Fargo, C=US
Owner: CN=Chambers of Commerce Root, OU=http://www.chambersign.org, O=AC Camerfirma SA CIF A82743287, C=EU
Owner: CN=Global Chambersign Root, OU=http://www.chambersign.org, O=AC Camerfirma SA CIF A82743287, C=EU
Owner: OU=RSA Security 2048 V3, O=RSA Security Inc
...
This results in a tremendous amount of output hence the grep to list just the owner. According to this method of listing the certs in the default truststore, there are 183. I just glanced through the list and they seem to come from CAs all over the world. I wonder how it was determined which certs to place in the default truststore?

28 December 2012

Painless Java Config and Install for Linux

If you need to install Java on a Debian based Linux distribution, do yourself a favor and use a little shell script named oab-java6.

The oab-java script completely automates the setup of the necessary items for the installation of Java, it's damn simple to use and it completes the set up in just a couple of minutes (depending on the speed of your internet connection). The best part is that nothing gets installed until you actually install it via apt-get.

If you want to know more, then read the doc for oab-java6. It's a very quick read.

19 December 2012

Outlook 2011 for Mac Misbehavior

Recently I upgraded my work computer from Mac OS X Lion to Mountain Lion. I also updated all the MS Office apps. Everything seemed to go off without a hitch as I experienced no issues during the upgrade and all the apps I use on a daily basis haven't seemed to experience any issues... until this week.

As much as I really, really dislike the Microsoft Office products and especially Outlook, I have to use them for my work on a daily basis. Suddenly just this week Outlook began misbehaving by no longer allowing me to search for messages. Any attempt to search my inbox resulted in nothing. This quickly became a pretty big problem because the inability to search made me realize how often I rely upon this feature every day.

Upon doing some research, I found many others with this same issue, but I couldn't find a definitive solution. Digging deeper, I discovered that Outlook relies upon Spotlight to perform searches. So the solution was to reindex the messages in my inbox, right? I tried forcing this by dragging and dropping the MS Office Identities directory into the Spotlight preferences' Privacy tab and then removing it. No dice. Then I tried to simply reindex everything using mdutil:
$ sudo mdutil -i on /
Spotlight server is disabled.
Hmm, I guess I need to enable the Spotlight server:
$ sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.metadata.mds.plist
Then I was able to run:
$ sudo mdutil -i on /
/:
 Indexing enabled. 
$ sudo mdutil -E /
/:
 Indexing enabled. 
This seemed to trigger some indexing, but nothing notable appeared in the Spotlight menu (cmd-space) like I've seen before when the drive is being reindexed. So the last thing I tried was to determine if there is a plist file for Spotlight. My guess was that the plist file had to become corrupted. In similar cases (I had to do this recently for the screensaver) when a plist file becomes corrupted you have to remove it and let it be recreated. So I found a plist file for Spotlight and removed it:
$ rm ~/Library/Preferences/com.apple.spotlight.plist
After rebooting the computer, I could see the reindexing immediately kick off via the Spotlight menu. After waiting three or four hours for the drive to be indexed, I can again search the inbox in Outlook. Yay!

06 December 2012

Hilarious: Devs vs. Ops

Today I stumbled upon an absolutely hilarious depiction of developer folks vs. operation folks, check it out:

05 December 2012

VIM Syntax Highlighting for Scala: A Bash One-Liner

Just for posterity, here is a Bash one-liner to download the VIM plugins to handle syntax highlighting for Scala:

mkdir -p ~/.vim/{ftdetect,indent,syntax} && for d in ftdetect indent syntax ; do wget --no-check-certificate -O ~/.vim/$d/scala.vim https://raw.githubusercontent.com/derekwyatt/vim-scala/master/syntax/scala.vim; done
Update

Here is a solution using cURL submitted by Joe:
mkdir -p ~/.vim/{ftdetect,indent,syntax} && for d in ftdetect indent syntax ; do curl -o ~/.vim/$d/scala.vim https://raw.githubusercontent.com/derekwyatt/vim-scala/master/syntax/scala.vim; done

06 September 2012

The Regenexx Stem Cell Procedure For My Left Knee



Since my last follow-up back in April I have actually had more Regenexx activity, only this time it's my left knee. So I can no longer refer to my right knee as my Regenexx knee because they have both been treated with Regenexx. The right knee was treated with Regenexx SD and the left knee was treated with Regenexx SCP. Here's the story on my left knee.

After the treatment of my right knee, Dr. Centeno demonstrated how tight the ACL is now in my right knee. It's nice and snug with no extra play in it and the tears in the meniscus have healed very well. This is exactly the result we were seeking and what allowed me to continue cycling throughout the summer. This summer my business schedule got in the way quite a bit but I still managed to ride the legendary Triple Bypasss and also my annual stop at Copper Mountain to ride in the Courage Classic.

Unfortunately we noticed how loose the ACL was in my left knee. Performing a simple Lachman test indicated a remarkable amount of slippage, so we decided to get a MRI on the left knee to check it out. After doing so, we were able to see that the ACL was definitely intact, but that there were some spots around the meniscus and the medial collateral ligament that were experiencing some wear and tear. I have never suffered any injury to my left knee, but I do experience stiffness in it. Given the success I had with Regenexx SD on my right knee, I decided to have my left knee treated with Regenexx SCP as well. I just had the final injection eight days ago. Right after the injection I experienced quite a bit of pain and discomfort and the range of motion in my left knee was far from 100%. Here's the breakdown of the treatment:

July 5 - Receive prolotherapy injection and micro-damage to the left ACL, MCL and meniscus. This is basically an injection of dextrose directly into the ACL along with some additional micro-damage using needles. This all causes irritation to the areas that are being targeted for treatment because it causes the red blood cells to flood into the area to heal the irritation and damage. Although it's a weird feeling during the injection right into the ACL, this treatment didn't slow me down one bit with regard to cycling.

August 1 - Receive another prolotherapy injection and micro-damage to the left ACL, MCL and meniscus again. Same thing as one month before.

August 28 - Blood draw to use for the stem cell plasma injection.

August 29 - Receive the stem cell plasma injection to the left ACL, MCL and meniscus. This injection was painful and immediately afterward I had a very difficult time putting any weight on my left leg. In fact, I went home and used crutches for two days until the pain subsided enough to begin walking.

Today, a little over one week after the injection, I have nearly 100% range of motion back and I am starting to walk longer distances. I am still having some trouble at night so I put a pillow between my knees to try to level out my left leg a bit. I've already started doing some light spinning on my road bike with it on my trainer. So far, everything is tracking similarly to my experience with my right knee. Now it's just a matter of following the regimen from the doctor and allowing the treatment take effect.

The Regenexx SCP procedure that I had performed on my left knee last week was less than half the cost of the Regenexx SD procedure. I had no injury in the my left knee, just wear and tear from getting older. But I'm hopeful that I will experience the same outcome as my right knee. I look forward to the day where I can run many miles without knee pain.