| Certificate Information | ||
|---|---|---|
| signatureAlgorithm | OK | SHA256 with RSA |
| keySize | INFO | RSA 2048 bits |
| serialNumber | INFO | 6D15A9D05A75E3E8719B992D |
| commonName | OK | *.lghellovision.net |
| commonName wo SNI | INFO | *.lghellovision.net |
| subjectAltName | INFO | *.lghellovision.net lghellovision.net |
| caIssuers | INFO | GlobalSign GCC R3 DV TLS CA 2020 (GlobalSign nv-sa from BE) |
| trust | OK | Ok via SAN wildcard and CN wildcard (same w/o SNI) |
| chain of trust | OK | passed. |
| certificatePolicies EV | INFO | no |
| expirationStatus | OK | 214 >= 60 days |
| notBefore | INFO | 2022-11-07 16:52 |
| notAfter | OK | 2023-12-09 16:52 |
| OCSP stapling | LOW | not offered |
| DNS CAArecord | LOW | -- |
| certificate transparency | OK | yes (certificate extension) |
| Protocols Information biz070.lghellovision.net/103.21.200.8 | ||
|---|---|---|
| SSLv2 | OK | not offered |
| SSLv3 | HIGH | offered |
| TLS1 | INFO | offered |
| TLS1.1 | CRITICAL | TLSv1.1 is not offered, and downgraded to a weaker protocol |
| TLS1.2 | MEDIUM | not offered and downgraded to a weaker protocol |
| TLS1.3 | INFO | not offered and downgraded to a weaker protocol |
| ALPN | INFO | not offered |
| Server Information | ||
|---|---|---|
| cipher negotiated | LOW | DHE-RSA-AES256-SHA, 1024 bit DH (cbc) (limited sense as client will pick) |
| Cipher order | ||
|---|---|---|
| SSLv3 | INFO | DHE-RSA-AES256-SHA at SSLv3 (limited sense as client will pick) |
| TLSv1 | INFO | DHE-RSA-AES256-SHA at TLSv1 (limited sense as client will pick) |
| Cipher Suite |
|---|
| Client Handshake Simulation | ||
|---|---|---|
| android 422 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 442 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 500 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 60 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 70 | INFO | TLSv1.0 AES128-SHA |
| android 81 | INFO | TLSv1.0 AES128-SHA |
| android 90 | INFO | TLSv1.0 AES128-SHA |
| chrome 65 win7 | INFO | TLSv1.0 AES128-SHA |
| chrome 74 win10 | INFO | TLSv1.0 AES128-SHA |
| firefox 62 win7 | INFO | TLSv1.0 AES128-SHA |
| firefox 66 win81 | INFO | TLSv1.0 DHE-RSA-AES128-SHA |
| ie 6 xp | INFO | SSLv3 RC4-MD5 |
| ie 7 vista | INFO | TLSv1.0 AES128-SHA |
| ie 8 win7 | INFO | TLSv1.0 AES128-SHA |
| ie 8 xp | INFO | TLSv1.0 RC4-MD5 |
| ie 11 win7 | INFO | TLSv1.0 AES256-SHA |
| ie 11 win81 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| ie 11 winphone81 | INFO | TLSv1.0 AES128-SHA |
| ie 11 win10 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| edge 15 win10 | INFO | TLSv1.0 AES256-SHA |
| edge 17 win10 | INFO | TLSv1.0 AES256-SHA |
| opera 60 win10 | INFO | TLSv1.0 AES128-SHA |
| safari 9 ios9 | INFO | TLSv1.0 AES256-SHA |
| safari 9 osx1011 | INFO | TLSv1.0 AES256-SHA |
| safari 10 osx1012 | INFO | TLSv1.0 AES256-SHA |
| apple ats 9 ios9 | INFO | No connection |
| tor 1709 win7 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| java 6u45 | INFO | TLSv1.0 RC4-MD5 |
| java 7u25 | INFO | TLSv1.0 AES128-SHA |
| java 8u161 | INFO | TLSv1.0 AES256-SHA |
| java 904 | INFO | TLSv1.0 AES256-SHA |
| openssl 101l | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| openssl 102e | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| openssl 110j | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| openssl 111b | INFO | No connection |
| thunderbird 60 6 1 | INFO | TLSv1.0 AES128-SHA |
| Protocols Information biz070.lghellovision.net/103.21.200.6 | ||
|---|---|---|
| SSLv2 | OK | not offered |
| SSLv3 | HIGH | offered |
| TLS1 | INFO | offered |
| TLS1.1 | CRITICAL | TLSv1.1 is not offered, and downgraded to a weaker protocol |
| TLS1.2 | MEDIUM | not offered and downgraded to a weaker protocol |
| TLS1.3 | INFO | not offered and downgraded to a weaker protocol |
| ALPN | INFO | not offered |
| Server Information | ||
|---|---|---|
| cipher negotiated | LOW | DHE-RSA-AES256-SHA, 1024 bit DH (cbc) (limited sense as client will pick) |
| Cipher order | ||
|---|---|---|
| SSLv3 | INFO | DHE-RSA-AES256-SHA at SSLv3 (limited sense as client will pick) |
| TLSv1 | INFO | DHE-RSA-AES256-SHA at TLSv1 (limited sense as client will pick) |
| Cipher Suite |
|---|
| Client Handshake Simulation | ||
|---|---|---|
| android 422 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 442 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 500 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 60 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| android 70 | INFO | TLSv1.0 AES128-SHA |
| android 81 | INFO | TLSv1.0 AES128-SHA |
| android 90 | INFO | TLSv1.0 AES128-SHA |
| chrome 65 win7 | INFO | TLSv1.0 AES128-SHA |
| chrome 74 win10 | INFO | TLSv1.0 AES128-SHA |
| firefox 62 win7 | INFO | TLSv1.0 AES128-SHA |
| firefox 66 win81 | INFO | TLSv1.0 DHE-RSA-AES128-SHA |
| ie 6 xp | INFO | SSLv3 RC4-MD5 |
| ie 7 vista | INFO | TLSv1.0 AES128-SHA |
| ie 8 win7 | INFO | TLSv1.0 AES128-SHA |
| ie 8 xp | INFO | TLSv1.0 RC4-MD5 |
| ie 11 win7 | INFO | TLSv1.0 AES256-SHA |
| ie 11 win81 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| ie 11 winphone81 | INFO | TLSv1.0 AES128-SHA |
| ie 11 win10 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| edge 15 win10 | INFO | TLSv1.0 AES256-SHA |
| edge 17 win10 | INFO | TLSv1.0 AES256-SHA |
| opera 60 win10 | INFO | TLSv1.0 AES128-SHA |
| safari 9 ios9 | INFO | TLSv1.0 AES256-SHA |
| safari 9 osx1011 | INFO | TLSv1.0 AES256-SHA |
| safari 10 osx1012 | INFO | TLSv1.0 AES256-SHA |
| apple ats 9 ios9 | INFO | No connection |
| tor 1709 win7 | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| java 6u45 | INFO | TLSv1.0 RC4-MD5 |
| java 7u25 | INFO | TLSv1.0 AES128-SHA |
| java 8u161 | INFO | TLSv1.0 AES256-SHA |
| java 904 | INFO | TLSv1.0 AES256-SHA |
| openssl 101l | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| openssl 102e | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| openssl 110j | INFO | TLSv1.0 DHE-RSA-AES256-SHA |
| openssl 111b | INFO | No connection |
| thunderbird 60 6 1 | INFO | TLSv1.0 AES128-SHA |