The attached patch seems to fix the problem for me.
Francois
--
https://fmarier.org/
diff -u /usr/bin/ssl-cert-check ssl-cert-check
--- /usr/bin/ssl-cert-check 2019-02-26 21:24:00.000000000 -0800
+++ ssl-cert-check 2019-02-27 10:04:34.331729364 -0800
@@ -658,9 +658,9 @@
fi
if [ "${TLSSERVERNAME}" = "FALSE" ]; then
- TLSFLAG=(s_client -crlf -connect "${1}":"${2}" "${VERSION}")
+ TLSFLAG=(s_client -crlf -connect "${1}":"${2}")
else
- TLSFLAG=(s_client -crlf -connect "${1}":"${2}" -servername "${1}" "${VERSION}")
+ TLSFLAG=(s_client -crlf -connect "${1}":"${2}" -servername "${1}")
fi
echo "" | "${OPENSSL}" "${TLSFLAG[@]}" 2> "${ERROR_TMP}" 1> "${CERT_TMP}"