palcomtech.ac.id
Score 95/100
Web site information
Web Address
IP Address
SEO data
Protocols
SSLv2
not offered
SSLv3
not offered
TLS 1.0
not offered
TLS 1.1
not offered
TLS 1.2
offered
TLS 1.3
offered with final
ALPN HTTP2
h2
ALPN
http/1.1
Vulnerabilities
heartbleed
not vulnerable, no heartbeat extension
CCS
not vulnerable
ticketbleed
no session ticket extension
ROBOT
not vulnerable
SSL renegotiation
supported
SSL client renegotiation
not vulnerable
CRIME TLS
not vulnerable
BREACH
potentially VULNERABLE, br HTTP compression detected - only supplied '/' tested
POODLE SSL
not vulnerable, no SSLv3
fallback SCSV
no protocol below TLS 1.2 offered
SWEET32
not vulnerable
FREAK
not vulnerable
DROWN
not vulnerable on this host and port
DROWN hint
Make sure you don't use this certificate elsewhere with SSLv2 enabled services, see https://censys.io/ipv4?q=5B4336693E12BC9995EAF962C8421472DDD1D0810D7B3926999D47867F9F36E7
LOGJAM
not vulnerable, no DH EXPORT ciphers,
LOGJAM-common primes
--
BEAST
not vulnerable, no SSL3 or TLS1
LUCKY13
potentially vulnerable, uses TLS CBC ciphers
RC4
not vulnerable
Header Responses
Status code
200 OK ('/')
Clock skew
0 seconds from localtime
HSTS
not offered
HPKP
No support for HTTP Public Key Pinning
Cache-Control
no-cache
Server Defaults
TLS extensions
'renegotiation info/#65281' 'server name/#0' 'EC point formats/#11' 'status request/#5' 'supported versions/#43' 'key share/#51' 'max fragment length/#1' 'application layer protocol negotiation/#16' 'encrypt-then-mac/#22' 'extended master secret/#23'
TLS session ticket
no -- no lifetime advertised
SSL sessionID support
yes
Session Ticket Resumption
not supported
Session ID Resumption
supported
cert numbers
1
Signature algorithm
SHA256 with RSA
Key size
RSA 2048 bits
Key usage
Digital Signature, Key Encipherment
Extended key usage
TLS Web Server Authentication, TLS Web Client Authentication
Serial number
0330D79959938B0D4C74FAC4F6C2E852AA39
cert serialNumberLen
18
Fingerprint SHA1
375CFCB215CC82D32E0A5CF206D5A634E1EBBD31
Fingerprint SHA256
5B4336693E12BC9995EAF962C8421472DDD1D0810D7B3926999D47867F9F36E7
Certificate details
-----BEGIN CERTIFICATE----- MIIFBDCCA+ygAwIBAgISAzDXmVmTiw1MdPrE9sLoUqo5MA0GCSqGSIb3DQEBCwUA MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD EwJSMzAeFw0yMzEwMTEwNzIwMTZaFw0yNDAxMDkwNzIwMTVaMB0xGzAZBgNVBAMM EioucGFsY29tdGVjaC5hYy5pZDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBAMCUw1TaDF/Z2q/NBdfyV1ZZHO0pKjoEIwLg0czBfJxboeo9WXlcx49fPMJp 4w1w2hw3cfV4K3AFBSx38qNavpSSsGGJsLLYlxAEeGwP2T5KiiBaKqiot5XVNsU3 NK7QmaFcWxSqY1pdwJjYz8dAyz07wVvq76TaPLNQsTNFlD/OEUYBedRT3VlDDpuM fXUDaklOjxPIlsMZhtgHmybpbgK3AFHLYQ7J82l2jELvfmCnjJaqTnVahv6uhO+E m04abndNUyjOYmfFSjvg4COwhH09hOtRsmewh/jrQapYQAVdLZ5i5dLBU4oXSzxu FbgTR6qU39Li7gi229IOg54tBxECAwEAAaOCAicwggIjMA4GA1UdDwEB/wQEAwIF oDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAd BgNVHQ4EFgQUgRKqlJ4He5urIUNxFQxs7k9JK5YwHwYDVR0jBBgwFoAUFC6zF7dY VsuuUAlA5h+vnYsUwsYwVQYIKwYBBQUHAQEESTBHMCEGCCsGAQUFBzABhhVodHRw Oi8vcjMuby5sZW5jci5vcmcwIgYIKwYBBQUHMAKGFmh0dHA6Ly9yMy5pLmxlbmNy Lm9yZy8wLwYDVR0RBCgwJoISKi5wYWxjb210ZWNoLmFjLmlkghBwYWxjb210ZWNo LmFjLmlkMBMGA1UdIAQMMAowCAYGZ4EMAQIBMIIBBQYKKwYBBAHWeQIEAgSB9gSB 8wDxAHYAO1N3dT4tuYBOizBbBv5AO2fYT8P0x70ADS1yb+H61BcAAAGLHdKAZgAA BAMARzBFAiEAzxIHDCccoqFQzQmg1dMi8hbVl7Yz4Sv3CmVTHwv4goQCIBTDaCrR tBY12PjIIWBRnUqTnF2Cd1wt/3TarvV1QNSgAHcAdv+IPwq2+5VRwmHM9Ye6NLSk zbsp3GhCCp/mZ0xaOnQAAAGLHdKAngAABAMASDBGAiEAq/1O4OPfFNWbm+O+hGCT FwWW74St3exywk4m75TuozYCIQDcSym8Br4qA/T27q16HQAxlnXjZWTQgEZDN2zO T8xd/zANBgkqhkiG9w0BAQsFAAOCAQEAEvBd+t5INONxwpNqTOMdNWBb1oC8zA0J 0Jp7A40FIb5dWkfBD6zpMRXtO5UyJOf7Ymmim2TLY34d/k20iimeACnjjNTRhysM UBDe44gSc12OLSn60PUj9tXLEx5eZGEDQGXRsGDnQEOOMC0cvJ9l7zlQXZfWlR71 FokniptbqNXA9LCqxY2dzNJPQdlWheg5OZcrwwKbK/LbRUKuE/k9AIbhCJgtZ3p0 f7M1xcrGZU31kP3XeJXl6VilziU+PsNZItNxwuqUJGS7nD1V6eUmf17LGcSfVEY4 f/qRmqmRBBXiIXh9xGUT8f98g62jynQTUI/IjqMILclA0c5UsaBFPA== -----END CERTIFICATE-----
Common names
*.palcomtech.ac.id
Service Name Indication
c19615.sgvps.net
SubjectAlternative Name
*.palcomtech.ac.id palcomtech.ac.id
Certificate authority issuers
R3 (Let's Encrypt from US)
Certificate trusted
Ok via SAN (SNI mandatory)
Certificate chain trusted
passed.
Is certificate Extended Validation
no
cert eTLS
not present
cert expirationStatus
45 >= 30 days
Valid from
2023-10-11 07:20
Valid until
2024-01-09 07:20
cert validityPeriod
No finding
Chain
3
certs list ordering problem
no
cert crlDistributionPoints
--
Online Certificate Status Protocol URL
http://r3.o.lencr.org
OCSP stapling
offered
cert ocspRevoked
not revoked
cert mustStapleExtension
--
DNS CAArecord
--
certificate transparency
yes (certificate extension)
Server Preferences
order
server
Which protocol negotiated
Default protocol TLS1.3
negotiated
TLS_AES_256_GCM_SHA384, 384 bit ECDH (P-384)
order TLSv1 2
ECDHE-RSA-AES256-GCM-SHA384
Perfect Forward Secrecy
PFS
offered
PFS s
DHE-RSA-AES128-GCM-SHA256 DHE-RSA-AES128-SHA256 DHE-RSA-AES128-SHA DHE-RSA-AES256-GCM-SHA384 DHE-RSA-AES256-SHA256 DHE-RSA-AES256-SHA DHE-RSA-CAMELLIA128-SHA256 DHE-RSA-CAMELLIA128-SHA DHE-RSA-CAMELLIA256-SHA256 DHE-RSA-CAMELLIA256-SHA ECDHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES128-SHA256 ECDHE-RSA-AES128-SHA ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES256-SHA384 ECDHE-RSA-AES256-SHA ECDHE-RSA-CAMELLIA128-SHA256 ECDHE-RSA-CAMELLIA256-SHA384
PFS ECDHE curves
secp384r1
Ciphers
ECDHE-RSA-AES256-GCM-SHA384 ECDH 384 AESGCM 256 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(0xc030)
ECDHE-RSA-AES256-SHA384 ECDH 384 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
(0xc028)
ECDHE-RSA-AES256-SHA ECDH 384 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
(0xc014)
DHE-RSA-AES256-GCM-SHA384 DH 4096 AESGCM 256 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
(0x9f)
DHE-RSA-AES256-SHA256 DH 4096 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
(0x6b)
DHE-RSA-AES256-SHA DH 4096 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
(0x39)
ECDHE-RSA-CAMELLIA256-SHA384 ECDH 384 Camellia 256 TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384
(0xc077)
DHE-RSA-CAMELLIA256-SHA256 DH 4096 Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
(0xc4)
DHE-RSA-CAMELLIA256-SHA DH 4096 Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
(0x88)
AES256-GCM-SHA384 RSA AESGCM 256 TLS_RSA_WITH_AES_256_GCM_SHA384
(0x9d)
AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
(0x3d)
AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
(0x35)
CAMELLIA256-SHA256 RSA Camellia 256 TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
(0xc0)
CAMELLIA256-SHA RSA Camellia 256 TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
(0x84)
ECDHE-RSA-AES128-GCM-SHA256 ECDH 384 AESGCM 128 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
(0xc02f)
ECDHE-RSA-AES128-SHA256 ECDH 384 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
(0xc027)
ECDHE-RSA-AES128-SHA ECDH 384 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
(0xc013)
DHE-RSA-AES128-GCM-SHA256 DH 4096 AESGCM 128 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
(0x9e)
DHE-RSA-AES128-SHA256 DH 4096 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
(0x67)
DHE-RSA-AES128-SHA DH 4096 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
(0x33)
ECDHE-RSA-CAMELLIA128-SHA256 ECDH 384 Camellia 128 TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
(0xc076)
DHE-RSA-CAMELLIA128-SHA256 DH 4096 Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
(0xbe)
DHE-RSA-CAMELLIA128-SHA DH 4096 Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
(0x45)
AES128-GCM-SHA256 RSA AESGCM 128 TLS_RSA_WITH_AES_128_GCM_SHA256
(0x9c)
AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256
(0x3c)
AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
(0x2f)
CAMELLIA128-SHA256 RSA Camellia 128 TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
(0xba)
CAMELLIA128-SHA RSA Camellia 128 TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
(0x41)
Browser Simulations
Android 4.4.2
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Android 5.0.0
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
Android 6.0
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
Android 7.0
TLSv1.2 AES128-SHA
clientsimulation-android 81
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
clientsimulation-android 90
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-android X
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-chrome 74 win10
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-chrome 79 win10
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-firefox 66 win81
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-firefox 71 win10
TLSv1.3 TLS_AES_256_GCM_SHA384
Windows XP Internet Explorer 6
No connection
Windows 7 Internet Explorer 8
No connection
Windows XP Internet Explorer 8
No connection
Windows 7 Internet Explorer 11
TLSv1.2 ECDHE-RSA-AES256-SHA384
Windows 8.1 Internet Explorer 11
TLSv1.2 ECDHE-RSA-AES256-SHA384
clientsimulation-ie 11 winphone81
TLSv1.2 ECDHE-RSA-AES128-SHA256
Windows 10 Internet Explorer 11
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
clientsimulation-edge 15 win10
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
clientsimulation-edge 17 win10
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
clientsimulation-opera 66 win10
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-safari 9 ios9
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
MacOSX 10.11 Safari 9
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
MacOSX 10.12 Safari 10
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
clientsimulation-safari 121 ios 122
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-safari 130 osx 10146
TLSv1.3 TLS_AES_256_GCM_SHA384
iOS 9 App Transport Security 9
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Java 6 update 45
No connection
Java 7 update 25
No connection
clientsimulation-java 8u161
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
clientsimulation-java1102
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-java1201
TLSv1.3 TLS_AES_256_GCM_SHA384
OpenSSL 1.0.2e
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
clientsimulation-openssl 110l
TLSv1.2 ECDHE-RSA-CHACHA20-POLY1305
clientsimulation-openssl 111d
TLSv1.3 TLS_AES_256_GCM_SHA384
clientsimulation-thunderbird 68 3 1
TLSv1.3 TLS_AES_256_GCM_SHA384