| Certificate Information | ||
|---|---|---|
| signatureAlgorithm | OK | SHA256 with RSA |
| keySize | INFO | RSA 2048 bits |
| serialNumber | INFO | 02F3070C20FA263E8856B081E405F500 |
| commonName | OK | www.wincert.com |
| commonName wo SNI | INFO | www.wincert.com |
| subjectAltName | INFO | www.wincert.com wincert.com api.wincert.com m.wincert.com partner.wincert.com sandbox-api.wincert.com |
| caIssuers | INFO | Thawte EV RSA CA 2018 (DigiCert Inc from US) |
| trust | OK | Ok via SAN (same w/o SNI) |
| chain of trust | WARN | Your /usr/bin/openssl <= 1.0.2 might be too unreliable to determine trust |
| chain of trust | OK | passed. (Your /usr/bin/openssl <= 1.0.2 might be too unreliable to determine trust) |
| certificatePolicies EV | OK | yes |
| expirationStatus | OK | 144 >= 60 days |
| notBefore | INFO | 2020-03-25 09:00 |
| notAfter | OK | 2022-03-25 21:00 |
| OCSP stapling | LOW | not offered |
| DNS CAArecord | LOW | -- |
| certificate transparency | OK | yes (certificate extension) |
| Protocols Information | ||
|---|---|---|
| SSLv2 | OK | not offered |
| SSLv3 | OK | not offered |
| TLS1 TLS 1.0 was first defined in RFC 2246 in January 1999 as an upgrade of SSL Version 3.0, and written by Christopher Allen and Tim Dierks of Consensus Development. | INFO | offered |
| TLS1.1 TLS 1.1 was defined in RFC 4346 in April 2006. It is an update from TLS version 1.0. Significant differences in this version include: | INFO | offered |
| TLS1.2 TLS 1.2 was defined in RFC 5246 in August 2008. It is based on the earlier TLS 1.1 specification. | OK | offered |
| TLS1.3 TLS 1.3 was defined in RFC 8446 in August 2018. It is based on the earlier TLS 1.2 specification. Major differences from TLS 1.2 include: | INFO | not offered and downgraded to a weaker protocol |
| ALPN Application-Layer Protocol Negotiation (ALPN) is a Transport Layer Security (TLS) extension for application-layer protocol negotiation. | INFO | http/1.1 |
| Server Information | ||
|---|---|---|
| cipher negotiated | OK | ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (prime256v1) |
| Vulnerability Information |
|---|
| Cipher List |
|---|
| Cipher order | ||
|---|---|---|
| TLSv1 | INFO | ECDHE-RSA-AES128-SHA |
| TLSv1.1 | INFO | ECDHE-RSA-AES128-SHA |
| TLSv1.2 | INFO | ECDHE-RSA-AES128-GCM-SHA256 |
| Cipher Suite |
|---|
| Client Handshake Simulation | ||
|---|---|---|
| android 422 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
| android 442 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| android 500 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| android 60 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| android 70 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| android 81 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| android 90 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| chrome 65 win7 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| chrome 74 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| firefox 62 win7 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| firefox 66 win81 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| ie 6 xp | INFO | No connection |
| ie 7 vista | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
| ie 8 win7 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
| ie 8 xp | INFO | TLSv1.0 DES-CBC3-SHA |
| ie 11 win7 | INFO | TLSv1.2 DHE-RSA-AES128-GCM-SHA256 |
| ie 11 win81 | INFO | TLSv1.2 DHE-RSA-AES128-GCM-SHA256 |
| ie 11 winphone81 | INFO | TLSv1.2 ECDHE-RSA-AES128-SHA256 |
| ie 11 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| edge 15 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| edge 17 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| opera 60 win10 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| safari 9 ios9 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| safari 9 osx1011 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| safari 10 osx1012 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| apple ats 9 ios9 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| tor 1709 win7 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
| java 6u45 | INFO | No connection |
| java 7u25 | INFO | TLSv1.0 ECDHE-RSA-AES128-SHA |
| java 8u161 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| java 904 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| openssl 101l | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| openssl 102e | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| openssl 110j | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| openssl 111b | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |
| thunderbird 60 6 1 | INFO | TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 |