lustrous-croquembouche-1e319c.netlify.app

Score 97/100

Web site information

IP Address
Advertising Networks
AdRiver
Ecommerce
IBM WebSphere Commerce
Web Servers
Netlify
Programming Languages
Java

SEO data

title
Welcome to nginx!

Protocols

SSLv2
not offered
SSLv3
not offered
TLS 1.0
not offered
TLS 1.1
not offered
TLS 1.2
offered
TLS 1.3
offered with final
ALPN HTTP2
h2
ALPN
http/1.1

Vulnerabilities

heartbleed
not vulnerable, no heartbeat extension
CCS
not vulnerable
ticketbleed
not vulnerable
ROBOT
not vulnerable, no RSA key transport cipher
SSL renegotiation
supported
SSL client renegotiation
not vulnerable
CRIME TLS
not vulnerable
BREACH
potentially VULNERABLE, br HTTP compression detected - only supplied '/' tested
POODLE SSL
not vulnerable, no SSLv3
fallback SCSV
no protocol below TLS 1.2 offered
SWEET32
not vulnerable
FREAK
not vulnerable
DROWN
not vulnerable on this host and port
DROWN hint
no RSA certificate, can't be used with SSLv2 elsewhere
LOGJAM
not vulnerable, no DH EXPORT ciphers,
LOGJAM-common primes
no DH key with <= TLS 1.2
BEAST
not vulnerable, no SSL3 or TLS1
LUCKY13
not vulnerable
RC4
not vulnerable

Header Responses

Status code
200 OK ('/')
Clock skew
0 seconds from localtime
HTTP headerAge
1 seconds
HSTS time
365 days (=31536000 seconds) > 15552000 seconds
HSTS subdomains
includes subdomains
HSTS preload
domain IS marked for preloading
HPKP
No support for HTTP Public Key Pinning
Cache-Control
public,max-age=0,must-revalidate

Server Defaults

TLS extensions
'session ticket/#35' 'renegotiation info/#65281' 'EC point formats/#11' 'supported versions/#43' 'key share/#51' 'extended master secret/#23' 'application layer protocol negotiation/#16'
TLS session ticket
no -- no lifetime advertised
SSL sessionID support
yes
Session Ticket Resumption
not supported
Session ID Resumption
not supported
TLS timestamp
random
cert numbers
1
Signature algorithm
SHA256 with RSA
Key size
EC 256 bits
Key usage
Digital Signature, Key Agreement
Extended key usage
TLS Web Server Authentication, TLS Web Client Authentication
Serial number
03ED167A2659DA278E7B21CDBEB33E32
cert serialNumberLen
16
Fingerprint SHA1
B08EE9A5C3D9B5C1FFB6517ADF98CF2D2818419B
Fingerprint SHA256
AA4D46AE959D1931CE8DDC9EB03CC053C05EDB943D04AECC9615B672B607A441
Certificate details
-----BEGIN CERTIFICATE----- MIIGGDCCBQCgAwIBAgIQA+0WeiZZ2ieOeyHNvrM+MjANBgkqhkiG9w0BAQsFADBZ MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMTMwMQYDVQQDEypE aWdpQ2VydCBHbG9iYWwgRzIgVExTIFJTQSBTSEEyNTYgMjAyMCBDQTEwHhcNMjQw MTE1MDAwMDAwWhcNMjUwMjE0MjM1OTU5WjBpMQswCQYDVQQGEwJVUzETMBEGA1UE CBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEVMBMGA1UEChMM TmV0bGlmeSwgSW5jMRYwFAYDVQQDDA0qLm5ldGxpZnkuYXBwMFkwEwYHKoZIzj0C AQYIKoZIzj0DAQcDQgAEZMOrg6Gfm/f/5QC/Qa7N0c0cXY1NYvsO5JAzEy21RZHm eiagXgGuJYT71YgjfhN+qdOl3mktkWnDEoZalAJCKKOCA5UwggORMB8GA1UdIwQY MBaAFHSFgMBmx9833s+9KTeqAx2+7c0XMB0GA1UdDgQWBBQ+ar5uJawSEKu+8eun qbxtiH1UjzAlBgNVHREEHjAcgg0qLm5ldGxpZnkuYXBwggtuZXRsaWZ5LmFwcDA+ BgNVHSAENzA1MDMGBmeBDAECAjApMCcGCCsGAQUFBwIBFhtodHRwOi8vd3d3LmRp Z2ljZXJ0LmNvbS9DUFMwDgYDVR0PAQH/BAQDAgOIMB0GA1UdJQQWMBQGCCsGAQUF BwMBBggrBgEFBQcDAjCBnwYDVR0fBIGXMIGUMEigRqBEhkJodHRwOi8vY3JsMy5k aWdpY2VydC5jb20vRGlnaUNlcnRHbG9iYWxHMlRMU1JTQVNIQTI1NjIwMjBDQTEt MS5jcmwwSKBGoESGQmh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEds b2JhbEcyVExTUlNBU0hBMjU2MjAyMENBMS0xLmNybDCBhwYIKwYBBQUHAQEEezB5 MCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdpY2VydC5jb20wUQYIKwYBBQUH MAKGRWh0dHA6Ly9jYWNlcnRzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbEcy VExTUlNBU0hBMjU2MjAyMENBMS0xLmNydDAMBgNVHRMBAf8EAjAAMIIBfQYKKwYB BAHWeQIEAgSCAW0EggFpAWcAdQBOdaMnXJoQwzhbbNTfP1LrHfDgjhuNacCx+mSx Ypo53wAAAY0Mu8dlAAAEAwBGMEQCIB7FL3xLGY4wUvKb3l9Q+ZjOP1pLEC2L4XpJ +nwXC+fHAiBp1IcuRkk+Ig6W5pq8iyJoPWJ4ejltwvH/crTsyrtz0AB1AH1ZHhLh eCp7HGFnfF79+NCHXBSgTpWeuQMv2Q6MLnm4AAABjQy7x2cAAAQDAEYwRAIgFGLu WY42+ip1EhACdAOTmmfTgJVNdcwuPv0k4xhDo88CICAKpid4QSG5gPsgYz5Lb6R1 FQKlXNK0OGQzINQ81UY3AHcA5tIxY0B3jMEQQQbXcbnOwdJA9paEhvu6hzId/R43 jlAAAAGNDLvHkQAABAMASDBGAiEAhp9eEk3bj4ys1YyA+OKF9jssIbHun/xp9yox NyNc7dICIQCzCxOD1tV6vnMuxnupZwo6D84IVaDd5gxQGugX6w1ODDANBgkqhkiG 9w0BAQsFAAOCAQEAhRBlqiMZRKCFcOwLCf/HyQY+2Bn2FKrzxbuh4e4c51FpoMYW w7/o5XWN9dicwSmmlCZq5iatn7OGTqiKkzwKaqfZtZJWUEOPfjDE3NJgJvX6hEom G2faOMSqORXmRcIFtCzN7WyW/l6Sy/XBitXCxXVZIID1y3WgIeVAKSPjgM0Jiaj2 YLD2dY61byzwQapiWQSDnEfJmwQQsJJDBMGVZ0DOyunP9h7YU9RqysH2Hd94DiBG vI46/vFaqT5oZgrWDbKwM0/U5c0SsOCj1StQOImrMpcPpoJK2KH3eASXFUQFgIQv 6+eBnQAu+jq7o+c7Iqtszs5lrZqkDGOzItaqhw== -----END CERTIFICATE-----
Common names
*.netlify.app
Service Name Indication
*.netlify.app
SubjectAlternative Name
*.netlify.app netlify.app
Certificate authority issuers
DigiCert Global G2 TLS RSA SHA256 2020 CA1 (DigiCert Inc from US)
Certificate trusted
Ok via SAN wildcard (same w/o SNI)
Certificate chain trusted
passed.
Is certificate Extended Validation
no
cert eTLS
not present
cert expirationStatus
287 >= 60 days
Valid from
2024-01-15 00:00
Valid until
2025-02-14 23:59
cert validityPeriod
No finding
Chain
2
certs list ordering problem
no
cert crlDistributionPoints
http://crl3.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl http://crl4.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl
Online Certificate Status Protocol URL
http://ocsp.digicert.com
OCSP stapling
not offered
cert mustStapleExtension
--
DNS CAArecord
iodef=mailto:[email protected], issue=digicert.com;account=2d83e9ac9b6776c3f215150f6ebceea8cefe3bc2e1fb5efffb1d71e200575226
certificate transparency
yes (certificate extension)

Server Preferences

order
server -- TLS 1.3 client determined
Which protocol negotiated
Default protocol TLS1.3
negotiated
TLS_AES_128_GCM_SHA256, 256 bit ECDH (P-256)
order TLSv1 2
ECDHE-ECDSA-AES128-GCM-SHA256

Perfect Forward Secrecy

PFS
offered
PFS s
ECDHE-ECDSA-AES128-GCM-SHA256 ECDHE-ECDSA-AES256-GCM-SHA384
PFS ECDHE curves
prime256v1

Ciphers

ECDHE-ECDSA-AES256-GCM-SHA384 ECDH 256 AESGCM 256 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
(0xc02c)
ECDHE-ECDSA-AES128-GCM-SHA256 ECDH 256 AESGCM 128 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
(0xc02b)

Browser Simulations

Android 4.4.2
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
Android 5.0.0
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
Android 6.0
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
Android 7.0
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-android 81
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-android 90
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-android X
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-chrome 74 win10
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-chrome 79 win10
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-firefox 66 win81
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-firefox 71 win10
TLSv1.3 TLS_AES_128_GCM_SHA256
Windows XP Internet Explorer 6
No connection
Windows 7 Internet Explorer 8
No connection
Windows XP Internet Explorer 8
No connection
Windows 7 Internet Explorer 11
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
Windows 8.1 Internet Explorer 11
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-ie 11 winphone81
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
Windows 10 Internet Explorer 11
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-edge 15 win10
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-edge 17 win10
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-opera 66 win10
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-safari 9 ios9
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
MacOSX 10.11 Safari 9
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
MacOSX 10.12 Safari 10
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-safari 121 ios 122
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
clientsimulation-safari 130 osx 10146
TLSv1.3 TLS_CHACHA20_POLY1305_SHA256
iOS 9 App Transport Security 9
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
Java 6 update 45
No connection
Java 7 update 25
No connection
clientsimulation-java 8u161
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-java1102
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-java1201
TLSv1.3 TLS_AES_128_GCM_SHA256
OpenSSL 1.0.2e
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-openssl 110l
TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256
clientsimulation-openssl 111d
TLSv1.3 TLS_AES_128_GCM_SHA256
clientsimulation-thunderbird 68 3 1
TLSv1.3 TLS_AES_128_GCM_SHA256