  1. You may want to add a -CApath parameter to the check command, otherwise openssl will complain about “self signed certificate in certificate chain”.
    It took me several hours and lots of downloads of RapidSSL/Geotrust intermediate and CA certs to figure this one out.


    openssl s_client -connect -CApath /etc/ssl/certs smtp.theos.in:993

