I’ve added the pubsub hostname to the certificate. Connecting to beta.kontalk.net now returns this certificate:
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
03:e7:0e:2b:bc:e1:27:84:42:4b:0a:4d:ac:7f:e7:53:b4:27
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
Validity
Not Before: Apr 21 16:50:24 2020 GMT
Not After : Jul 20 16:50:24 2020 GMT
Subject: CN = beta.kontalk.net
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:c0:cb:9c:54:9f:ce:d9:02:99:e0:d4:5f:57:c0:
7b:96:59:f9:5c:0b:47:1d:47:39:fe:14:98:2c:d2:
75:07:e8:77:8d:a7:9f:a1:0f:db:b9:88:b4:3a:ec:
dd:ec:ac:2c:78:39:80:16:e8:69:c3:90:2a:06:34:
b7:67:4a:82:dd:29:c9:ed:5d:f1:ee:56:77:df:15:
ee:9d:0e:0a:5f:44:fe:cc:f7:49:57:21:fd:71:e9:
3a:d9:72:3c:6e:47:ee:98:1e:11:5a:7d:ca:5d:a0:
08:29:80:10:43:18:c2:48:f8:3a:d1:e2:c8:b7:5b:
ef:a3:81:2e:e2:03:38:36:7e:c1:a4:1a:52:25:23:
e7:70:00:98:8f:0d:89:f0:10:15:de:e7:93:d7:ec:
d5:2b:da:e5:a8:c7:76:8e:2b:3c:4a:39:25:a1:67:
9d:8b:eb:7f:c8:33:bc:1e:d9:29:8e:ee:96:35:18:
d8:2b:ec:fd:9c:40:2a:2c:3b:55:83:20:d3:d0:f2:
1e:1b:f7:5a:d2:59:b1:f5:12:e0:e6:18:27:6b:75:
dd:cd:d2:16:39:73:d6:e9:41:ba:06:f9:28:c5:19:
5a:0e:6e:7c:1c:7b:94:b1:45:4d:d8:6a:54:ad:40:
2f:7c:90:48:81:95:cf:0a:c5:ad:e7:df:72:81:c2:
0c:b7
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Key Identifier:
D3:FC:45:02:7C:A6:89:03:21:85:4F:A9:E6:B6:D9:CD:74:4B:B5:AB
X509v3 Authority Key Identifier:
keyid:A8:4A:6A:63:04:7D:DD:BA:E6:D1:39:B7:A6:45:65:EF:F3:A8:EC:A1
Authority Information Access:
OCSP - URI:http://ocsp.int-x3.letsencrypt.org
CA Issuers - URI:http://cert.int-x3.letsencrypt.org/
X509v3 Subject Alternative Name:
DNS:beta.kontalk.net, DNS:pubsub.beta.kontalk.net
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
Policy: 1.3.6.1.4.1.44947.1.1.1
CPS: http://cps.letsencrypt.org
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 6F:53:76:AC:31:F0:31:19:D8:99:00:A4:51:15:FF:77:
15:1C:11:D9:02:C1:00:29:06:8D:B2:08:9A:37:D9:13
Timestamp : Apr 21 17:50:24.195 2020 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:A1:E6:0C:21:AD:6C:3A:33:DF:14:39:
66:0F:2E:72:28:E8:FF:4B:47:F9:0A:50:EF:38:98:37:
B3:8C:86:B3:4D:02:20:63:A3:60:14:43:62:98:60:D6:
D3:AB:99:1D:6C:AE:0E:52:3E:5B:09:28:29:73:FC:91:
73:EF:50:50:3B:96:01
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 07:B7:5C:1B:E5:7D:68:FF:F1:B0:C6:1D:23:15:C7:BA:
E6:57:7C:57:94:B7:6A:EE:BC:61:3A:1A:69:D3:A2:1C
Timestamp : Apr 21 17:50:24.208 2020 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:E1:56:37:F9:1E:A7:1A:9A:87:37:B8:
52:9F:12:A7:1D:5E:C8:3E:40:41:9C:A8:2B:EF:81:3E:
0C:07:B5:84:CF:02:20:6C:B8:03:13:FF:19:88:5C:92:
84:AF:FD:21:90:5F:EA:64:12:41:45:46:BE:16:CB:68:
2D:36:6C:5F:22:A3:AB
Signature Algorithm: sha256WithRSAEncryption
4d:1d:e7:b1:8b:ef:29:8a:4d:66:5f:5c:c2:de:79:af:5f:0c:
be:79:21:11:50:56:83:d8:b5:b1:85:6d:ef:37:f5:8a:19:2c:
52:38:be:ce:c4:25:98:da:95:e3:cb:93:29:20:f5:f0:30:5f:
ef:71:62:90:cd:50:23:d9:f2:71:7d:7d:41:f5:b3:13:86:00:
9e:cf:6a:98:14:08:10:78:5e:0e:ca:01:ae:52:ae:be:f8:79:
18:84:9e:c4:0c:e4:cb:20:55:ab:f0:bf:4d:11:46:3d:46:64:
73:c5:2c:b7:ca:b1:f2:9d:90:46:45:89:af:60:db:7c:cb:ad:
73:b0:60:1b:fe:04:a0:b0:f2:e9:9c:ad:15:80:05:70:8a:97:
b8:b7:8f:40:66:14:1f:ea:a2:8d:fb:bf:ff:46:4a:49:ad:f9:
54:be:9f:41:3a:ec:86:61:2b:43:bb:76:71:c8:17:3b:f2:69:
f0:93:bb:b7:e5:cc:e1:eb:43:48:ac:f3:b8:e1:23:69:c9:7c:
70:75:62:c6:0c:7d:f1:bd:bd:0e:ad:04:86:68:72:4b:17:8b:
c9:64:3b:c9:2a:a3:2c:c2:4c:08:a8:ee:00:4c:67:37:bc:bb:
a7:d3:54:13:f8:e8:a5:63:83:9e:9b:47:27:9c:74:bd:28:1c:
04:97:69:e5