Certificate Information | ||
---|---|---|
signatureAlgorithm | OK | SHA256 with RSA |
keySize | INFO | RSA 2048 bits |
serialNumber | INFO | 02F3070C20FA263E8856B081E405F500 |
commonName | OK | www.wincert.com |
commonName wo SNI | INFO | www.wincert.com |
subjectAltName | INFO | www.wincert.com wincert.com api.wincert.com m.wincert.com partner.wincert.com sandbox-api.wincert.com |
caIssuers | INFO | Thawte EV RSA CA 2018 (DigiCert Inc from US) |
trust | OK | Ok via SAN (same w/o SNI) |
chain of trust | WARN | Your /usr/bin/openssl <= 1.0.2 might be too unreliable to determine trust |
chain of trust | OK | passed. (Your /usr/bin/openssl <= 1.0.2 might be too unreliable to determine trust) |
certificatePolicies EV | OK | yes |
expirationStatus | OK | 144 >= 60 days |
notBefore | INFO | 2020-03-25 09:00 |
notAfter | OK | 2022-03-25 21:00 |
OCSP stapling | LOW | not offered |
DNS CAArecord | LOW | -- |
certificate transparency | OK | yes (certificate extension) |
Protocols Information | ||
---|---|---|
SSLv2 | OK | not offered |
SSLv3 | OK | not offered |
TLS1 TLS 1.0 was first defined in RFC 2246 in January 1999 as an upgrade of SSL Version 3.0, and written by Christopher Allen and Tim Dierks of Consensus Development. | INFO | offered |
TLS1.1 TLS 1.1 was defined in RFC 4346 in April 2006. It is an update from TLS version 1.0. Significant differences in this version include: | INFO | offered |
TLS1.2 TLS 1.2 was defined in RFC 5246 in August 2008. It is based on the earlier TLS 1.1 specification. | OK | offered |
TLS1.3 TLS 1.3 was defined in RFC 8446 in August 2018. It is based on the earlier TLS 1.2 specification. Major differences from TLS 1.2 include: | INFO | not offered and downgraded to a weaker protocol |
ALPN Application-Layer Protocol Negotiation (ALPN) is a Transport Layer Security (TLS) extension for application-layer protocol negotiation. | INFO | http/1.1 |
Server Information | ||
---|---|---|
cipher negotiated | OK | ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (prime256v1) |
Vulnerability Information |
---|
Cipher List |
---|
Cipher order | ||
---|---|---|
TLSv1 | INFO | ECDHE-RSA-AES128-SHA |
TLSv1.1 | INFO | ECDHE-RSA-AES128-SHA |
TLSv1.2 | INFO | ECDHE-RSA-AES128-GCM-SHA256 |
Cipher Suite |
---|
Client Handshake Simulation | ||
---|---|---|
android 422 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
android 442 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
android 500 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
android 60 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
android 70 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
android 81 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
android 90 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
chrome 65 win7 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
chrome 74 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
firefox 62 win7 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
firefox 66 win81 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
ie 6 xp | INFO | No connection |
ie 7 vista | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
ie 8 win7 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
ie 8 xp | INFO | TLSv1.0 DES-CBC3-SHA |
ie 11 win7 | INFO | TLSv1.2 DHE-RSA-AES128-GCM-SHA256 |
ie 11 win81 | INFO | TLSv1.2 DHE-RSA-AES128-GCM-SHA256 |
ie 11 winphone81 | INFO | TLSv1.2 ECDHE-RSA-AES128-SHA256 |
ie 11 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
edge 15 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
edge 17 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
opera 60 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
safari 9 ios9 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
safari 9 osx1011 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
safari 10 osx1012 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
apple ats 9 ios9 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
tor 1709 win7 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
java 6u45 | INFO | No connection |
java 7u25 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
java 8u161 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
java 904 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
openssl 101l | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
openssl 102e | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
openssl 110j | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
openssl 111b | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
thunderbird 60 6 1 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |