I want to scan for port 443 and get the certificate info
Sometimes nessus is not the appropriate tool. Simple tools work better for
simple tasks.
I'd use nmap to scan for the open port and then lwp-request (or something
similar) to probe the system and retrieve the SSL headers.
[11:34am dominic] nmap -p443 -oM - <SomeIPRange> | grep open
Host: 129.97.108.150 (ist.uwaterloo.ca) Ports: 443/open/tcp//https///
Get the list of IPs and then for each do
[11:35am dominic] lwp-request -e https://<SomeIPNumber> | grep
'^Client-SSL'
Client-SSL-Cert-Issuer: /C=ZA/ST=Western Cape/L=Cape Town/O=Thawte
Consulting cc/OU=Certification Services Division/CN=Thawte Premium Server
CA/[EMAIL PROTECTED]
Client-SSL-Cert-Subject: /C=CA/ST=Ontario/L=Waterloo Region/O=The University
of Waterloo/CN=ist.uwaterloo.ca
Client-SSL-Cipher: AES256-SHA
Client-SSL-Warning: Peer certificate not verified
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus