vpsFree mi jede pres wireguard na Fedore (server) a curl tam funguje! Vypada takhle...
# curl -v https://portal.stavebnisprava.gov.cz/
* Host portal.stavebnisprava.gov.cz:443 was resolved.
* IPv6: 2620:1ec:bdf::45
* IPv4: 13.107.246.45
* Trying [2620:1ec:bdf::45]:443...
* Connected to portal.stavebnisprava.gov.cz (2620:1ec:bdf::45) port 443
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* CAfile: /etc/pki/tls/certs/ca-bundle.crt
* CApath: none
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / secp256r1 / RSASSA-PSS
* ALPN: server accepted h2
* Server certificate:
* subject: CN=portal.stavebnisprava.gov.cz
* start date: Jun 14 00:00:00 2024 GMT
* expire date: Dec 12 23:59:59 2024 GMT
* subjectAltName: host "portal.stavebnisprava.gov.cz" matched cert's "portal.stavebnisprava.gov.cz"
* issuer: C=US; O=DigiCert, Inc.; CN=GeoTrust Global TLS RSA4096 SHA256 2022 CA1
* SSL certificate verify ok.
* Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
* Certificate level 1: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption
* Certificate level 2: Public key type RSA (2048/112 Bits/secBits), signed using sha1WithRSAEncryption
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://portal.stavebnisprava.gov.cz/
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: portal.stavebnisprava.gov.cz]
* [HTTP/2] [1] [:path: /]
* [HTTP/2] [1] [user-agent: curl/8.6.0]
* [HTTP/2] [1] [accept: */*]
> GET / HTTP/2
> Host: portal.stavebnisprava.gov.cz
> User-Agent: curl/8.6.0
> Accept: */*
>
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing
< HTTP/2 200
< date: Tue, 02 Jul 2024 13:30:08 GMT
< content-type: text/html
< content-length: 962
< cache-control: public, must-revalidate, max-age=30
< etag: "27988630"
< last-modified: Sun, 30 Jun 2024 06:11:08 GMT
< strict-transport-security: max-age=10886400; includeSubDomains; preload
< referrer-policy: same-origin
< x-content-type-options: nosniff
< x-xss-protection: 1; mode=block
< x-dns-prefetch-control: off
< x-azure-ref: 20240702T133008Z-17d856f5577k67n26f9ucb323c0000000bvg00000000k52p
< x-cache: CONFIG_NOCACHE
< accept-ranges: bytes
MTU wg rozhrani je 1420.
Diky za ochotu! Vypada, ze jsme na dobre stope.