Namecheap.com

SSL Checker

Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.

Report

Hostname: Matches Common Name or/and SAN
Expired: No (169 days till expiration)
Public Key: We were unable to find any issues in the public key of end-entity certificate
Trusted: Yes, we were able to verify the certificate
Self-Signed: No, the end-entity certificate is not self-signed
Chain Issues: No, we were unable to detect any issues in the certificate chain sent by the server
Weak signatures: No, certificates sent by the server were not signed utilizing a weak hash function
OCSP Status: OCSP Responder returned "good" status for the end-entity certificate

DNS Information

Resolves To: 167.40.79.24
Reverse IP lookup: DC03ADC007-008-PROD-VIP-79-24.infra.global.gc.ca.
Nameserver: ns1.d-zone.ca.
Nameserver: ns2.d-zone.ca.
Nameserver: dns2.nrc.ca.
Nameserver: xns-kedc.ssc-spc.gc.ca.
Nameserver: gocns-pdp.gc.ca.
Nameserver: gocns-kedc.gc.ca.
Nameserver: xns-kedc-1.ssc-spc.gc.ca.

General Information

Common Name: canada.ca
SANs: DNS:canada.caDNS:www.canada.caDNS:Canada.gc.caDNS:www.canada.gc.ca Total number of SANs: 4
Organization: Shared Services Canada
Locality: Gatineau
Signature Algorithm: sha256WithRSAEncryption
Key Type: RSA
Key size: 2048 bits
Serial Number: 3f92de9e6e1f9c5851c2f4f95d6b07a8
Not Before: Sep 13, 2023 17:39:23 GMT
Not After: Oct 13, 2024 17:39:22 GMT
Number of certs: 2
Revocation Status: good
OCSP Stapling: Not Supported
Server: BigIP
HSTS: max-age=31536000
HPKP: Not Supported

Chain Information

Certificate # 1 - Common Name: canada.ca

Decode this certificate for verbose information →
Subject Common Name canada.ca
Subject Organization Shared Services Canada
Issuer Common Name Entrust Certification Authority - L1K
Issuer Organization Entrust, Inc.
Not Before: Sep 13, 2023 17:39:23 GMT
Not After: Oct 13, 2024 17:39:22 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 3f92de9e6e1f9c5851c2f4f95d6b07a8
SHA1 Fingerprint: 24:19:A8:89:78:F9:52:91:6B:E3:AD:A5:31:9E:6F:D7:CE:97:9A:F7
MD5 Fingerprint: 4D:4A:82:49:CF:0B:1B:55:3F:A5:A0:C7:F4:68:B4:EE

Certificate # 2 - Common Name: Entrust Certification Authority - L1K

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name Entrust Certification Authority - L1K
Subject Organization Entrust, Inc.
Issuer Common Name Entrust Root Certification Authority - G2
Issuer Organization Entrust, Inc.
Not Before: Oct 05, 2015 19:13:56 GMT
Not After: Dec 05, 2030 19:43:56 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: ee94cc30000000051d37785
SHA1 Fingerprint: F2:1C:12:F4:6C:DB:6B:2E:16:F0:9F:94:19:CD:FF:32:84:37:B2:D7
MD5 Fingerprint: 35:94:F5:3C:2A:77:54:47:EB:95:67:4B:FF:6C:F2:8B

OpenSSL Handshake

depth=2 C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2009 Entrust, Inc. - for authorized use only", CN = Entrust Root Certification Authority - G2
verify return:1
depth=1 C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2012 Entrust, Inc. - for authorized use only", CN = Entrust Certification Authority - L1K
verify return:1
depth=0 C = CA, ST = Quebec, L = Gatineau, O = Shared Services Canada, CN = canada.ca
verify return:1
CONNECTED(00000003)
OCSP response: no response sent
---
Certificate chain
 0 s:C = CA, ST = Quebec, L = Gatineau, O = Shared Services Canada, CN = canada.ca
   i:C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2012 Entrust, Inc. - for authorized use only", CN = Entrust Certification Authority - L1K
-----BEGIN CERTIFICATE-----
MIIGpzCCBY+gAwIBAgIQP5Lenm4fnFhRwvT5XWsHqDANBgkqhkiG9w0BAQsFADCB
ujELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsT
H1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAy
MDEyIEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwG
A1UEAxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzAeFw0y
MzA5MTMxNzM5MjNaFw0yNDEwMTMxNzM5MjJaMGYxCzAJBgNVBAYTAkNBMQ8wDQYD
VQQIEwZRdWViZWMxETAPBgNVBAcTCEdhdGluZWF1MR8wHQYDVQQKExZTaGFyZWQg
U2VydmljZXMgQ2FuYWRhMRIwEAYDVQQDEwljYW5hZGEuY2EwggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQC1QNLAGISuv/cAMqjptPGn+yVK0bn88oXLBg4N
xN6QMr3nqHi3a9Cy4rx0ibuf/2TdEI4B6Yn2iGFLH3mY/h4VVaBOXyHiLRmd4cCY
a5Frv5NBMDlBWdChKn2P8jq8gRbsWnqrKdZyc4xvD0ykHU3J0OZ4t59yKGlopmUA
qo/H3Yb4wbOHjxDlbekmZMGtAG6nHcoHdpCTIDOgyka5oIiQvW+U9rXavBpVBpxK
mUnf60SyTl901iULjtaDBNqrSy2Ecp/eu9nq/4oJA1yfu5tc6MRE4icMhORRIvW9
Y1pfBM9E9yGIVA0o+bSHqAmU35TyA5fxXVMEUQghOu7mFyS3AgMBAAGjggL6MIIC
9jAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBT0uWW0mKRxO2R9s/nToFcTUKGLzTAf
BgNVHSMEGDAWgBSConB03bxTP8971PfNf6dgxgpMvzBoBggrBgEFBQcBAQRcMFow
IwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3QubmV0MDMGCCsGAQUFBzAC
hidodHRwOi8vYWlhLmVudHJ1c3QubmV0L2wxay1jaGFpbjI1Ni5jZXIwMwYDVR0f
BCwwKjAooCagJIYiaHR0cDovL2NybC5lbnRydXN0Lm5ldC9sZXZlbDFrLmNybDBD
BgNVHREEPDA6ggljYW5hZGEuY2GCDXd3dy5jYW5hZGEuY2GCDENhbmFkYS5nYy5j
YYIQd3d3LmNhbmFkYS5nYy5jYTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYI
KwYBBQUHAwEGCCsGAQUFBwMCMBMGA1UdIAQMMAowCAYGZ4EMAQICMIIBfAYKKwYB
BAHWeQIEAgSCAWwEggFoAWYAdQDuzdBk1dsazsVct520zROiModGfLzs3sNRSFlG
cR+1mwAAAYqPoFRoAAAEAwBGMEQCIAXvN6yV2OVGXMAEyNzPNxMMPgMIVBp2N6c3
z8wPTE+zAiAOlKoRYwkKOC/0a6PtG4unBcE1XZoJ8frCt10EraRtrgB1AD8XS0/X
IkdYlB1lHIS+DRLtkDd/H4Vq68G/KIXs+GRuAAABio+gVK0AAAQDAEYwRAIgKTmt
HKjuTF+ROcVpn+w+mZAYLgbaDh6XsHbhFaTPLoUCIFBcJX4qgHEQ+E3cyrdfdyiU
jOndICt8QBbLokSrar7gAHYASLDja9qmRzQP5WoC+p0w6xxSActW3SyB2bu/qznY
hHMAAAGKj6BVCAAABAMARzBFAiADX2cPVClaK0bxZDR2IklqcbwikS70For/ntfG
q5uX7gIhAPcpHYsTDnHuycvsXZviBcCXpSkbnpBN8f6Ywngs9P3BMA0GCSqGSIb3
DQEBCwUAA4IBAQA90z2DEa8rH88UIGwMyGsLc969By4daKYeNGQC4u6LQuCWSQIz
xNXTBx6Zd2xjFh90fmvTX0QVkFDeGTL/Np9jrMqLIStFJeYjLdeS0sAW0CmBHiGj
yTD4yl0bDt5xeE+g7nIR/i+sGXc8aULFT25aFLJVOutZMbxAc6Mz9XRvtwrwkVE+
Tgdq6zde4Qy4MCJ2HnDt/PkAPv8rsFqSGxBRVo1oZVCoDYu+s/B83942/WiNYEVo
WtsJJJU/QwuBL6ZhGvsboLFK9dN1wN0sHKkgcxKt7djcecUoAkW6ATW5Rk5QvHQu
6hPxf1sAdhKoGLyLzc2b4enjwJeTEVZgpSRN
-----END CERTIFICATE-----
 1 s:C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2012 Entrust, Inc. - for authorized use only", CN = Entrust Certification Authority - L1K
   i:C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2009 Entrust, Inc. - for authorized use only", CN = Entrust Root Certification Authority - G2
-----BEGIN CERTIFICATE-----
MIIFDjCCA/agAwIBAgIMDulMwwAAAABR03eFMA0GCSqGSIb3DQEBCwUAMIG+MQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjAeFw0x
NTEwMDUxOTEzNTZaFw0zMDEyMDUxOTQzNTZaMIG6MQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5l
dC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTIgRW50cnVzdCwgSW5jLiAt
IGZvciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRp
ZmljYXRpb24gQXV0aG9yaXR5IC0gTDFLMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA2j+W0E25L0Tn2zlem1DuXKVh2kFnUwmqAJqOV38pa9vH4SEkqjrQ
jUcj0u1yFvCRIdJdt7hLqIOPt5EyaM/OJZMssn2XyP7BtBe6CZ4DkJN7fEmDImiK
m95HwzGYei59QAvS7z7Tsoyqj0ip/wDoKVgG97aTWpRzJiatWA7lQrjV6nN5ZGhT
JbiEz5R6rgZFDKNrTdDGvuoYpDbwkrK6HIiPOlJ/915tgxyd8B/lw9bdpXiSPbBt
LOrJz5RBGXFEaLpHPATpXbo+8DX3Fbae8i4VHj9HyMg4p3NFXU2wO7GOFyk36t0F
ASK7lDYqjVs1/lMZLwhGwSqzGmIdTivZGwIDAQABo4IBDDCCAQgwDgYDVR0PAQH/
BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwMwYIKwYBBQUHAQEEJzAlMCMGCCsG
AQUFBzABhhdodHRwOi8vb2NzcC5lbnRydXN0Lm5ldDAwBgNVHR8EKTAnMCWgI6Ah
hh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2EuY3JsMDsGA1UdIAQ0MDIwMAYE
VR0gADAoMCYGCCsGAQUFBwIBFhpodHRwOi8vd3d3LmVudHJ1c3QubmV0L3JwYTAd
BgNVHQ4EFgQUgqJwdN28Uz/Pe9T3zX+nYMYKTL8wHwYDVR0jBBgwFoAUanImetAe
733nO2lR1GyNn5ASZqswDQYJKoZIhvcNAQELBQADggEBADnVjpiDYcgsY9NwHRkw
y/YJrMxp1cncN0HyMg/vdMNY9ngnCTQIlZIv19+4o/0OgemknNM/TWgrFTEKFcxS
BJPok1DD2bHi4Wi3Ogl08TRYCj93mEC45mj/XeTIRsXsgdfJghhcg85x2Ly/rJkC
k9uUmITSnKa1/ly78EqvIazCP0kkZ9Yujs+szGQVGHLlbHfTUqi53Y2sAEo1GdRv
c6N172tkw+CNgxKhiucOhk3YtCAbvmqljEtoZuMrx1gL+1YQ1JH7HdMxWBCMRON1
exCdtTix9qrKgWRs6PLigVWXUX/hwidQosk8WwBD9lu51aX8/wdQQGcHsFXwt35u
Lcw=
-----END CERTIFICATE-----
---
Server certificate
subject=C = CA, ST = Quebec, L = Gatineau, O = Shared Services Canada, CN = canada.ca

issuer=C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2012 Entrust, Inc. - for authorized use only", CN = Entrust Certification Authority - L1K

---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 3517 bytes and written 446 bytes
Verification: OK
---
New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES256-GCM-SHA384
    Session-ID: 42B8C45297FC38372B80D4A1FD45E0BEAC8BD7EAA33FD6C29C2F100DCED530CF
    Session-ID-ctx: 
    Master-Key: DE64694E41C8033CA4FBB21B4185176322DFC3FD0741399F15346B00C3E9A7B54E623AEE9B3D673B85EC05D3113326B9
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1714171990
    Timeout   : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: yes
---
DONE