SSL Checker
Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.
Report
It's all good. We have not detected any issues.
Hostname: | done Matches Common Name or/and SAN |
Expired: | done No (44 days till expiration) |
Public Key: | done We were unable to find any issues in the public key of end-entity certificate |
Trusted: | done Yes, we were able to verify the certificate |
Self-Signed: | done No, the end-entity certificate is not self-signed |
Chain Issues: | done No, we were unable to detect any issues in the certificate chain sent by the server |
Weak signatures: | done No, certificates sent by the server were not signed utilizing a weak hash function |
OCSP Status: | done OCSP Responder returned "good" status for the end-entity certificate |
DNS Information
Resolves To: | 151.101.66.137 |
Reverse IP lookup: | No records found |
Nameserver: | ns3.dnsmadeeasy.com. |
Nameserver: | ns4.dnsmadeeasy.com. |
Nameserver: | ns0.dnsmadeeasy.com. |
Nameserver: | ns1.dnsmadeeasy.com. |
Nameserver: | ns2.dnsmadeeasy.com. |
General Information
Common Name: | charitynavigator.org |
SANs: | DNS:charitynavigator.org Total number of SANs: 1 |
Signature Algorithm: | sha256WithRSAEncryption |
Key Type: | RSA |
Key size: | 2048 bits |
Serial Number: | 36604caa1aeb0ce6274fa0e9b8d9cf578a0 |
Not Before: | Mar 11, 2024 04:27:03 GMT |
Not After: | Jun 09, 2024 04:27:02 GMT |
Number of certs: | 3 |
Revocation Status: | good |
OCSP Stapling: | Supported |
Server: | Varnish |
HSTS: | Not Supported |
HPKP: | Not Supported |
Chain Information
Certificate # 1 - Common Name: charitynavigator.org
Decode this certificate for verbose information → launchSubject Common Name | charitynavigator.org |
Issuer Common Name | R3 |
Issuer Organization | Let's Encrypt |
Not Before: | Mar 11, 2024 04:27:03 GMT |
Not After: | Jun 09, 2024 04:27:02 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 36604caa1aeb0ce6274fa0e9b8d9cf578a0 |
SHA1 Fingerprint: | FF:F7:51:AE:79:5A:38:C1:39:C1:9F:E7:BA:42:C1:DB:41:2C:D8:C5 |
MD5 Fingerprint: | 79:B8:7D:E2:12:82:25:9F:62:F5:C9:F9:04:8F:CE:97 |
Certificate # 2 - Common Name: R3
Decode this certificate for verbose information → launchIn place? | Yes, this certificate directly certifies the preceding one |
Subject Common Name | R3 |
Subject Organization | Let's Encrypt |
Issuer Common Name | ISRG Root X1 |
Issuer Organization | Internet Security Research Group |
Not Before: | Sep 04, 2020 00:00:00 GMT |
Not After: | Sep 15, 2025 16:00:00 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 912b084acf0c18a753f6d62e25a75f5a |
SHA1 Fingerprint: | A0:53:37:5B:FE:84:E8:B7:48:78:2C:7C:EE:15:82:7A:6A:F5:A4:05 |
MD5 Fingerprint: | E8:29:E6:5D:7C:43:07:D6:FB:C1:3C:17:9E:03:7A:36 |
Certificate # 3 - Common Name: ISRG Root X1
Decode this certificate for verbose information → launchIn place? | Yes, this certificate directly certifies the preceding one |
Subject Common Name | ISRG Root X1 |
Subject Organization | Internet Security Research Group |
Issuer Common Name | DST Root CA X3 |
Issuer Organization | Digital Signature Trust Co. |
Not Before: | Jan 20, 2021 19:14:03 GMT |
Not After: | Sep 30, 2024 18:14:03 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 4001772137d4e942b8ee76aa3c640ab7 |
SHA1 Fingerprint: | 93:3C:6D:DE:E9:5C:9C:41:A4:0F:9F:50:49:3D:82:BE:03:AD:87:BF |
MD5 Fingerprint: | C1:E1:FF:07:F9:F6:88:49:82:74:D1:A1:80:53:EA:BF |
OpenSSL Handshake
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1 verify return:1 depth=1 C = US, O = Let's Encrypt, CN = R3 verify return:1 depth=0 CN = charitynavigator.org verify return:1 CONNECTED(00000003) OCSP response: ====================================== OCSP Response Data: OCSP Response Status: successful (0x0) Response Type: Basic OCSP Response Version: 1 (0x0) Responder Id: C = US, O = Let's Encrypt, CN = R3 Produced At: Apr 22 02:57:00 2024 GMT Responses: Certificate ID: Hash Algorithm: sha1 Issuer Name Hash: 48DAC9A0FB2BD32D4FF0DE68D2F567B735F9B3C4 Issuer Key Hash: 142EB317B75856CBAE500940E61FAF9D8B14C2C6 Serial Number: 036604CAA1AEB0CE6274FA0E9B8D9CF578A0 Cert Status: good This Update: Apr 22 02:57:00 2024 GMT Next Update: Apr 29 02:56:58 2024 GMT Signature Algorithm: sha256WithRSAEncryption 4b:ea:a0:c1:77:b1:cb:b9:c1:1f:73:15:24:4d:53:73:a4:b8: 6e:5f:b0:16:e1:dc:0a:70:59:dd:96:04:d0:00:1a:70:54:bd: c6:72:73:6a:c8:3a:44:fe:c8:1d:96:8d:9f:0e:8e:0c:33:2f: f8:49:7f:34:45:9a:e1:e4:cb:10:09:ec:ac:13:f5:75:82:56: b4:09:e5:72:cf:00:fc:71:2f:65:e8:90:bd:4d:d1:28:e1:aa: fa:a3:cb:93:1c:92:5d:d4:81:67:eb:e4:b6:41:09:53:18:c3: f0:e1:95:12:c3:af:c8:69:b2:c3:32:0b:0e:89:13:ad:98:2e: dd:48:a3:34:6c:ae:0b:c0:b4:e6:19:e5:94:e1:aa:4b:33:1a: e3:84:43:3e:91:1f:c9:4a:22:3e:1d:87:f2:d8:9d:db:4a:a4: d8:63:c3:19:8c:d4:11:5f:36:a2:94:1e:0d:a1:6b:9f:ff:81: 57:8e:1e:19:bb:bf:ee:90:b3:7b:58:58:4e:94:54:c3:40:d5: 51:95:fc:3d:4a:41:55:c9:16:58:ba:fb:e1:aa:70:71:59:92: e8:bd:7a:22:c0:e8:0f:db:2b:54:e7:c8:69:07:f1:3a:eb:bc: 65:dd:61:3c:75:a0:d6:04:1a:00:69:10:ec:63:47:79:c0:5c: 7c:73:41:e7 ====================================== --- Certificate chain 0 s:CN = charitynavigator.org i:C = US, O = Let's Encrypt, CN = R3 -----BEGIN CERTIFICATE----- MIIE9jCCA96gAwIBAgISA2YEyqGusM5idPoOm42c9XigMA0GCSqGSIb3DQEBCwUA MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD EwJSMzAeFw0yNDAzMTEwNDI3MDNaFw0yNDA2MDkwNDI3MDJaMB8xHTAbBgNVBAMT FGNoYXJpdHluYXZpZ2F0b3Iub3JnMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB CgKCAQEA8FDjmXIo6RSkBfg3tOZXl0Uq2elleS0uRFr7b5wMOxSTusxoI4y5iZG9 hBUJ3yFZAbOhSJPeBWEGRJka07zQHq1ybuHAN8P/F5iVC5xKiEsZmoT6TcDjrCjP Jb9dELEHMBaAy6GL4dF3zlXrKDymHEVAer6R8Pq+iVTwn6anUkouW+R71BgtEYPh p7Zop3mDXb1u4LJOcB151+bxvBNgye5wajO6/SppixvgSKw+JA08X+yFaYLIXCvU Hb0ux9/X1Hi3/0PDxP+qRmMJrCtD72nAZbd1heA0wvYmMiVyPSxuENnTYvpAXMfp DZHhDmPtuuhtOoLbj9TlYbRtvcjChwIDAQABo4ICFzCCAhMwDgYDVR0PAQH/BAQD AgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAA MB0GA1UdDgQWBBR5nzJQKvA3L/qiF0oROYimqXjgFTAfBgNVHSMEGDAWgBQULrMX t1hWy65QCUDmH6+dixTCxjBVBggrBgEFBQcBAQRJMEcwIQYIKwYBBQUHMAGGFWh0 dHA6Ly9yMy5vLmxlbmNyLm9yZzAiBggrBgEFBQcwAoYWaHR0cDovL3IzLmkubGVu Y3Iub3JnLzAfBgNVHREEGDAWghRjaGFyaXR5bmF2aWdhdG9yLm9yZzATBgNVHSAE DDAKMAgGBmeBDAECATCCAQUGCisGAQQB1nkCBAIEgfYEgfMA8QB2ADtTd3U+LbmA ToswWwb+QDtn2E/D9Me9AA0tcm/h+tQXAAABjiv6inwAAAQDAEcwRQIhANJO9HNl ePWs/P1fGmyMW9nMKmsAvd3UFDcVJrx71tm/AiAIsfb6JyPvza2HyAvoAq93ZxWH CbLgM/4CgvLYJKzYSQB3AKLiv9Ye3i8vB6DWTm03p9xlQ7DGtS6i2reK+Jpt9RfY AAABjiv6io4AAAQDAEgwRgIhAPBumsMNoBk81ukG5M6vAUKiKDrlrVbw10bQLBCC 0zh1AiEA1MLB0QTm/c+lIZ2Jx9/A1flF+ytjWoL83fI6lWuBdsUwDQYJKoZIhvcN AQELBQADggEBAH4NPzUV0CZQWQu0aDJhra3QlY+bWu7sVv5ovr2sSpBqvfbmK0ti nwNZn8TC/xyQ5fd93+De8EGJPEhehD0Ia8hMMr0SUQpKi3ab4PZd/P5YJfpoj/OT alvQdUUQQ2O/SBpSXXosGrv13knJLOrBeVW/v2AD+R9cpCpJuWc8aqkjIXAzY+T6 a7n92l+RZ8n0Oj2PT7QBNDjSW0frM9phzhuMGscaLewsLfY91/2Uu6K5eaRy0bxZ FCX4kCYYo3x5u8rtk8gal2Ito/Out8GWQqk5uEenXPvKguDgKHZ7/ajtH/d5KrtX SllY0YINvC0qsjvPZg3lbZ4jut2GF+h33U0= -----END CERTIFICATE----- 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1 -----BEGIN CERTIFICATE----- MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG /kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4 avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2 yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+ HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX nLRbwHOoq7hHwg== -----END CERTIFICATE----- 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1 i:O = Digital Signature Trust Co., CN = DST Root CA X3 -----BEGIN CERTIFICATE----- MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/ MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT DkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1ow TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEB AQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XC ov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpL wYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+D LtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK 4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5 bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5y sR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZ Xmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4 FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBc SLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2ql PRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TND TwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYw SwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1 c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx +tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEB ATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQu b3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9E U1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26Ztu MA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC 5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW 9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuG WCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9O he8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFC Dfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5 -----END CERTIFICATE----- --- Server certificate subject=CN = charitynavigator.org issuer=C = US, O = Let's Encrypt, CN = R3 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 5025 bytes and written 395 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) --- DONE --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_128_GCM_SHA256 Session-ID: F20F8A6463F40FCDE1B4C52FBF606620D0FAEB21BC0BDBC139A677419C01A081 Session-ID-ctx: Resumption PSK: FC80469ED7AE8F76EEA55A26C0396CB61A5D695C751E61DAFA779371E1578B46 PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 3600 (seconds) TLS session ticket: 0000 - 7c 0c cd 02 cc 50 2e e0-48 e1 8d 29 e6 99 15 57 |....P..H..)...W 0010 - 80 02 9f 51 10 9b cd 0a-11 a7 a6 7e c4 10 34 81 ...Q.......~..4. 0020 - 20 8d 16 f4 c9 99 b6 73-3f 63 ea 3e 88 bb 28 2b ......s?c.>..(+ 0030 - 89 de 45 83 d4 79 70 28-2f 80 d5 a7 09 32 dd 14 ..E..yp(/....2.. 0040 - 95 95 01 9b 4e 42 17 e4-fd b0 fc 9c 93 49 f4 1e ....NB.......I.. 0050 - 3e 72 3b af 20 d7 53 6f-3c ee 1f 3a 72 d1 f1 6e >r;. .So<..:r..n 0060 - 26 a3 e3 b4 e7 22 c9 e9-bd c6 a4 39 9a 86 9e 19 &....".....9.... 0070 - 9c 11 ef b9 20 7c 6e ad-c3 26 46 fe d8 cf ac ca .... |n..&F..... 0080 - b2 2b bd 45 12 f4 64 d3-86 f7 63 b6 c7 4a 3b a9 .+.E..d...c..J;. 0090 - 7e ae 3b a1 19 32 04 e1-e0 75 86 9f 2e a0 20 3f ~.;..2...u.... ? Start Time: 1714044389 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: no Max Early Data: 8192 --- read R BLOCK