forrestjmorrison.com
Score 90/100
Web site information
Web Address
IP Address
SEO data
title
Protocols
SSLv2
not offered
SSLv3
not offered
TLS 1.0
not offered
TLS 1.1
not offered
TLS 1.2
offered
TLS 1.3
unexpected results
ALPN HTTP2
h2
ALPN
http/1.1
Vulnerabilities
heartbleed
not vulnerable, no heartbeat extension
CCS
not vulnerable
ticketbleed
not vulnerable
ROBOT
SSL renegotiation
SSL client renegotiation
CRIME TLS
BREACH
POODLE SSL
fallback SCSV
SWEET32
FREAK
Header Responses
Status code
200 OK ('/')
Clock skew
0 seconds from localtime
HSTS
not offered
HPKP
No support for HTTP Public Key Pinning
security headers
--
Server Defaults
TLS extensions
'session ticket/#35' 'renegotiation info/#65281' 'EC point formats/#11' 'extended master secret/#23' 'application layer protocol negotiation/#16'
TLS session ticket
no -- no lifetime advertised
SSL sessionID support
yes
Session Ticket Resumption
not supported
Session ID Resumption
not supported
cert numbers
1
Signature algorithm
SHA256 with RSA
Key size
RSA 2048 bits
Key usage
Digital Signature, Key Encipherment
Extended key usage
TLS Web Server Authentication, TLS Web Client Authentication
Serial number
52FC14DB63FD53D9
cert serialNumberLen
8
Fingerprint SHA1
8824697C5728D0B985D374863B2F2BAFC9AB4E3A
Fingerprint SHA256
0DC1468A946E6CF715CD40CEF11008B92443211A494AD7FBBC9C470AF407F0A0
Certificate details
-----BEGIN CERTIFICATE----- MIIGjzCCBXegAwIBAgIIUvwU22P9U9kwDQYJKoZIhvcNAQELBQAwgbQxCzAJBgNV BAYTAlVTMRAwDgYDVQQIEwdBcml6b25hMRMwEQYDVQQHEwpTY290dHNkYWxlMRow GAYDVQQKExFHb0RhZGR5LmNvbSwgSW5jLjEtMCsGA1UECxMkaHR0cDovL2NlcnRz LmdvZGFkZHkuY29tL3JlcG9zaXRvcnkvMTMwMQYDVQQDEypHbyBEYWRkeSBTZWN1 cmUgQ2VydGlmaWNhdGUgQXV0aG9yaXR5IC0gRzIwHhcNMjQxMTEwMTI1NzI3WhcN MjUxMTEwMTI1NzI3WjAfMR0wGwYDVQQDExRmb3JyZXN0am1vcnJpc29uLmNvbTCC ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMlDiv5gWoNVOo/QO5y/EBJY hlUsDPEYfzTzTCciXZsZ//2zhESWmzYoXGXqvYzgamTIbj/SD43eLkcp1r33PK2J fQPXimkGh/zH+ZrsoGDKYug8oFo0Ash8GAR0Tv6hCgmTIYLrfhZSvmtiK1NBbOhn Pdqu2SlUBR6iwN7lHNuFVrWy1ZgrqIf2lkaHKFId3dgc4jHWhQCnBVn/Soa1LoTn UHTCJqqa6wZ6fN7H4pOh5AWiLYx73bbngJ0MDC7TIzXvWQYSqoVMvhUJWYDEvlO6 OUWdpQ6kzxkX0UN1JNlm6lDSJzXQgsKQ0woSdoRNa0RknzZkKLPwTffVhvXeAyMC AwEAAaOCAzcwggMzMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEG CCsGAQUFBwMCMA4GA1UdDwEB/wQEAwIFoDA5BgNVHR8EMjAwMC6gLKAqhihodHRw Oi8vY3JsLmdvZGFkZHkuY29tL2dkaWcyczEtMzI0OTEuY3JsMF0GA1UdIARWMFQw SAYLYIZIAYb9bQEHFwEwOTA3BggrBgEFBQcCARYraHR0cDovL2NlcnRpZmljYXRl cy5nb2RhZGR5LmNvbS9yZXBvc2l0b3J5LzAIBgZngQwBAgEwdgYIKwYBBQUHAQEE ajBoMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5nb2RhZGR5LmNvbS8wQAYIKwYB BQUHMAKGNGh0dHA6Ly9jZXJ0aWZpY2F0ZXMuZ29kYWRkeS5jb20vcmVwb3NpdG9y eS9nZGlnMi5jcnQwHwYDVR0jBBgwFoAUQMK9J47MNIMwojPX+2yz8LQsgM4wHwYD VR0RBBgwFoIUZm9ycmVzdGptb3JyaXNvbi5jb20wHQYDVR0OBBYEFPoV6sBBo3Td TSYJV4qNQcciNP1JMIIBfwYKKwYBBAHWeQIEAgSCAW8EggFrAWkAdgAS8U40vVNy TIQGGcOPP3oT+Oe1YoeInG0wBYTr5YYmOgAAAZMWJpS1AAAEAwBHMEUCIHMxVNGJ YMVoUj80+Fgw9u8oFHs4EC33X1XjzftmBIHAAiEAtAbfM5P42EkWKg7OKStgruI0 Dn7VZKYoXZG7NjoSlXAAdgB9WR4S4XgqexxhZ3xe/fjQh1wUoE6VnrkDL9kOjC55 uAAAAZMWJpW/AAAEAwBHMEUCIA6Opfieq7UfQrf6T+wGkN0/c/RZ5FFlt3EUGvyG VAyOAiEAgkfC3jSTPDV5SxN1dqFpSIpVO6RFuYDxmVATIcB9yXIAdwDM+w9qhXEJ Zf6Vm1PO6bJ8IumFXA2XjbapflTA/kwNsAAAAZMWJqKsAAAEAwBIMEYCIQCPUX1b a5xqJCEF/W+wq+MhwgYJJyOfTQUzAeLa2xBOtgIhAOcvo70wqaPJREIc95Um9BKY hRWzKHpO3yjlQ67UdTTxMA0GCSqGSIb3DQEBCwUAA4IBAQAPmzLfPvWUaElVt5bb spNopDjI79fFn8k2QBRw2vnWTYCD1fkFx2GMrLJzjcrUrsSAHV2PjgRc+H0bVGw7 iKMkhsmYs0JyQ7qt9Qm6Ax6i6BfZ6dXjFtvUNjyRimVbuqG7aMqVkNZple9rWVME 3fYsAVJq0fY3QcM5G+YuizsDeAYb9F0Eo/wSkgmmphx+wcq5uiZEGptlr+q6EAxZ Uyl0ipA83b/qnmu3zYKafdtk4R2H8v1eDskMih8B/D2cO6unUgKISKuUpmE37jGJ dpcJIZG71vbxDSii8//tMhoG6cEChpkAQxX3kTznKeHZsjptN9Cm8A1pCIP2teTV LgwN -----END CERTIFICATE-----
Common names
forrestjmorrison.com
Service Name Indication
request w/o SNI didn't succeed
SubjectAlternative Name
forrestjmorrison.com
Certificate authority issuers
Go Daddy Secure Certificate Authority - G2 (GoDaddy.com, Inc. from US)
Certificate trusted
Ok via SAN (SNI mandatory)
Certificate chain trusted
passed.
Is certificate Extended Validation
no
cert eTLS
not present
cert expirationStatus
324 >= 60 days
Valid from
2024-11-10 12:57
Valid until
2025-11-10 12:57
cert validityPeriod
No finding
Chain
2
certs list ordering problem
no
cert crlDistributionPoints
http://crl.godaddy.com/gdig2s1-32491.crl
Online Certificate Status Protocol URL
http://ocsp.godaddy.com/
OCSP stapling
not offered
cert mustStapleExtension
--
DNS CAArecord
--
certificate transparency
yes (certificate extension)
Server Preferences
order
server
Which protocol negotiated
Default protocol TLS1.2
negotiated
ECDHE-RSA-AES128-GCM-SHA256, 521 bit ECDH (P-521)
order TLSv1 2
ECDHE-RSA-AES128-GCM-SHA256
Perfect Forward Secrecy
PFS
offered
PFS s
ECDHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES128-SHA ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES256-SHA
PFS ECDHE curves
prime256v1 secp384r1 secp521r1