I want to scan for port 443 and get the certificate info

Sometimes nessus is not the appropriate tool. Simple tools work better for simple tasks.

I'd use nmap to scan for the open port and then lwp-request (or something similar) to probe the system and retrieve the SSL headers.

[11:34am dominic] nmap -p443 -oM - <SomeIPRange> | grep open
Host: 129.97.108.150 (ist.uwaterloo.ca) Ports: 443/open/tcp//https///

Get the list of IPs and then for each do

[11:35am dominic] lwp-request -e https://<SomeIPNumber> | grep '^Client-SSL' Client-SSL-Cert-Issuer: /C=ZA/ST=Western Cape/L=Cape Town/O=Thawte Consulting cc/OU=Certification Services Division/CN=Thawte Premium Server CA/[EMAIL PROTECTED] Client-SSL-Cert-Subject: /C=CA/ST=Ontario/L=Waterloo Region/O=The University of Waterloo/CN=ist.uwaterloo.ca
Client-SSL-Cipher: AES256-SHA
Client-SSL-Warning: Peer certificate not verified

_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to