SSL Checker
Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.
Report
It's all good. We have not detected any issues.
Hostname: | done Matches Common Name or/and SAN |
Expired: | done No (72 days till expiration) |
Public Key: | done We were unable to find any issues in the public key of end-entity certificate |
Trusted: | done Yes, we were able to verify the certificate |
Self-Signed: | done No, the end-entity certificate is not self-signed |
Chain Issues: | done No, we were unable to detect any issues in the certificate chain sent by the server |
Weak signatures: | done No, certificates sent by the server were not signed utilizing a weak hash function |
OCSP Status: | done OCSP Responder returned "good" status for the end-entity certificate |
DNS Information
Resolves To: | 192.0.78.220 |
Reverse IP lookup: | No records found |
Nameserver: | jeff.ns.cloudflare.com. |
Nameserver: | sara.ns.cloudflare.com. |
General Information
Common Name: | tls.automattic.com |
SANs: | DNS:4matura.tech.blogDNS:alternatives.tech.blogDNS:beeprofessionalservices.comDNS:connectify.meDNS:dots.tech.blogDNS:flippingfitness.health.blogDNS:informaticasoftware.tech.blogDNS:marandaballardauthor.comDNS:newsletters.tech.blogDNS:ornaments.tech.blogDNS:peddiscostruzionimecca.comDNS:portland.tech.blogDNS:salvatore.tech.blogDNS:secondspace.workDNS:secubeezz.nlDNS:seeking-the-hypotenuse.caDNS:sergeizmusic.comDNS:serlibre.uyDNS:sewgr8ful.comDNS:sportsabsorbed.sport.blogDNS:thefeast.music.blogDNS:thehumblechair.comDNS:tls.automattic.comDNS:updo.tech.blogDNS:www.alternatives.tech.blogDNS:www.armstrong.tech.blogDNS:www.arrangements.tech.blogDNS:www.beeprofessionalservices.comDNS:www.canpack.tech.blogDNS:www.connectify.meDNS:www.dots.tech.blogDNS:www.newsletters.tech.blogDNS:www.peddiscostruzionimecca.comDNS:www.portland.tech.blogDNS:www.scottinscotland.comDNS:www.secondspace.workDNS:www.secubeezz.nlDNS:www.sergeizmusic.comDNS:www.serlibre.uyDNS:www.sportsabsorbed.sport.blogDNS:www.thefeast.music.blog Total number of SANs: 41 |
Signature Algorithm: | sha256WithRSAEncryption |
Key Type: | ECDSA (secp256r1) |
Key size: | 256 bits |
Serial Number: | 31cb0495425f8d9f3aa9729f921e47a5d3a |
Not Before: | Apr 05, 2024 22:37:43 GMT |
Not After: | Jul 04, 2024 22:37:42 GMT |
Number of certs: | 2 |
Revocation Status: | good |
OCSP Stapling: | Supported |
Server: | nginx |
HSTS: | max-age=31536000 |
HPKP: | Not Supported |
Chain Information
Certificate # 1 - Common Name: tls.automattic.com
Decode this certificate for verbose information → launchSubject Common Name | tls.automattic.com |
Issuer Common Name | R3 |
Issuer Organization | Let's Encrypt |
Not Before: | Apr 05, 2024 22:37:43 GMT |
Not After: | Jul 04, 2024 22:37:42 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 31cb0495425f8d9f3aa9729f921e47a5d3a |
SHA1 Fingerprint: | 95:08:D9:52:8B:20:D1:39:CB:C4:8D:51:AB:F4:F1:8D:70:29:EC:B8 |
MD5 Fingerprint: | 86:F7:29:BE:94:3E:03:3D:BD:92:9A:D3:26:E7:28:CC |
Certificate # 2 - Common Name: R3
Decode this certificate for verbose information → launchIn place? | Yes, this certificate directly certifies the preceding one |
Subject Common Name | R3 |
Subject Organization | Let's Encrypt |
Issuer Common Name | ISRG Root X1 |
Issuer Organization | Internet Security Research Group |
Not Before: | Sep 04, 2020 00:00:00 GMT |
Not After: | Sep 15, 2025 16:00:00 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 912b084acf0c18a753f6d62e25a75f5a |
SHA1 Fingerprint: | A0:53:37:5B:FE:84:E8:B7:48:78:2C:7C:EE:15:82:7A:6A:F5:A4:05 |
MD5 Fingerprint: | E8:29:E6:5D:7C:43:07:D6:FB:C1:3C:17:9E:03:7A:36 |
OpenSSL Handshake
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1 verify return:1 depth=1 C = US, O = Let's Encrypt, CN = R3 verify return:1 depth=0 CN = tls.automattic.com verify return:1 CONNECTED(00000003) OCSP response: ====================================== OCSP Response Data: OCSP Response Status: successful (0x0) Response Type: Basic OCSP Response Version: 1 (0x0) Responder Id: C = US, O = Let's Encrypt, CN = R3 Produced At: Apr 23 14:24:00 2024 GMT Responses: Certificate ID: Hash Algorithm: sha1 Issuer Name Hash: 48DAC9A0FB2BD32D4FF0DE68D2F567B735F9B3C4 Issuer Key Hash: 142EB317B75856CBAE500940E61FAF9D8B14C2C6 Serial Number: 031CB0495425F8D9F3AA9729F921E47A5D3A Cert Status: good This Update: Apr 23 14:24:00 2024 GMT Next Update: Apr 30 14:23:58 2024 GMT Signature Algorithm: sha256WithRSAEncryption 22:c5:9c:1b:46:a8:35:8f:25:cd:0c:51:80:a7:7b:8f:b3:88: 37:8f:87:15:6c:5c:ee:22:00:21:9a:de:7d:f9:58:0e:f9:c8: ca:90:38:10:95:e6:0c:13:26:89:61:69:ba:02:5c:94:d2:fa: 6d:25:e9:fc:4a:fa:cb:46:c7:be:4e:d5:3a:66:8b:f4:98:fd: 20:7e:df:74:01:05:78:dc:3b:bd:1b:80:8c:43:49:c4:ba:c6: 3d:80:3c:b8:17:30:8a:e6:24:b1:21:f6:09:85:7e:bc:f1:88: a2:fc:5b:ce:1c:05:d5:f4:07:82:2f:bb:ba:79:76:db:6d:83: 20:9c:77:c3:fe:84:47:2a:59:9a:d7:c1:24:4d:de:c0:b5:55: 12:db:01:cd:a4:62:03:eb:f8:76:60:91:6c:4e:a3:42:bb:23: 99:f5:e9:2a:fb:f4:7d:5c:47:a7:d6:ab:92:a8:02:a6:b8:c4: fe:81:73:65:d3:5f:4c:da:58:c3:ce:ba:f9:f0:85:87:6c:ec: 33:4f:90:70:20:e3:0f:5f:4a:24:c1:f6:57:3c:61:f8:ce:7d: 31:ee:b3:cc:c0:1b:fb:bd:c1:b2:8d:1e:56:9d:d8:1f:65:c2: d6:77:b1:eb:71:c4:77:ef:15:bb:d3:fa:5f:41:39:5a:5e:b7: d2:62:1f:28 ====================================== --- Certificate chain 0 s:CN = tls.automattic.com i:C = US, O = Let's Encrypt, CN = R3 -----BEGIN CERTIFICATE----- MIIHuTCCBqGgAwIBAgISAxywSVQl+Nnzqpcp+SHkel06MA0GCSqGSIb3DQEBCwUA MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD EwJSMzAeFw0yNDA0MDUyMjM3NDNaFw0yNDA3MDQyMjM3NDJaMB0xGzAZBgNVBAMT EnRscy5hdXRvbWF0dGljLmNvbTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABGau 7rtzcZmcYl5aSNyqQN9uVg1H3lF0MAQtA8lyKiZ37DzbeEHG6wkWENbGiiA5ktpA z/16lIRdV7mfNmJkMtijggWnMIIFozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYw FAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFOcU yPLGXpwx+uJsNhjTga4FgnLnMB8GA1UdIwQYMBaAFBQusxe3WFbLrlAJQOYfr52L FMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0cDovL3IzLm8ubGVu Y3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5jci5vcmcvMIIDrwYD VR0RBIIDpjCCA6KCETRtYXR1cmEudGVjaC5ibG9nghZhbHRlcm5hdGl2ZXMudGVj aC5ibG9nghtiZWVwcm9mZXNzaW9uYWxzZXJ2aWNlcy5jb22CDWNvbm5lY3RpZnku bWWCDmRvdHMudGVjaC5ibG9nghtmbGlwcGluZ2ZpdG5lc3MuaGVhbHRoLmJsb2eC HWluZm9ybWF0aWNhc29mdHdhcmUudGVjaC5ibG9nghhtYXJhbmRhYmFsbGFyZGF1 dGhvci5jb22CFW5ld3NsZXR0ZXJzLnRlY2guYmxvZ4ITb3JuYW1lbnRzLnRlY2gu YmxvZ4IacGVkZGlzY29zdHJ1emlvbmltZWNjYS5jb22CEnBvcnRsYW5kLnRlY2gu YmxvZ4ITc2FsdmF0b3JlLnRlY2guYmxvZ4IQc2Vjb25kc3BhY2Uud29ya4IMc2Vj dWJlZXp6Lm5sghlzZWVraW5nLXRoZS1oeXBvdGVudXNlLmNhghBzZXJnZWl6bXVz aWMuY29tggtzZXJsaWJyZS51eYINc2V3Z3I4ZnVsLmNvbYIZc3BvcnRzYWJzb3Ji ZWQuc3BvcnQuYmxvZ4ITdGhlZmVhc3QubXVzaWMuYmxvZ4ISdGhlaHVtYmxlY2hh aXIuY29tghJ0bHMuYXV0b21hdHRpYy5jb22CDnVwZG8udGVjaC5ibG9nghp3d3cu YWx0ZXJuYXRpdmVzLnRlY2guYmxvZ4IXd3d3LmFybXN0cm9uZy50ZWNoLmJsb2eC Gnd3dy5hcnJhbmdlbWVudHMudGVjaC5ibG9ngh93d3cuYmVlcHJvZmVzc2lvbmFs c2VydmljZXMuY29tghV3d3cuY2FucGFjay50ZWNoLmJsb2eCEXd3dy5jb25uZWN0 aWZ5Lm1lghJ3d3cuZG90cy50ZWNoLmJsb2eCGXd3dy5uZXdzbGV0dGVycy50ZWNo LmJsb2eCHnd3dy5wZWRkaXNjb3N0cnV6aW9uaW1lY2NhLmNvbYIWd3d3LnBvcnRs YW5kLnRlY2guYmxvZ4IXd3d3LnNjb3R0aW5zY290bGFuZC5jb22CFHd3dy5zZWNv bmRzcGFjZS53b3JrghB3d3cuc2VjdWJlZXp6Lm5sghR3d3cuc2VyZ2Vpem11c2lj LmNvbYIPd3d3LnNlcmxpYnJlLnV5gh13d3cuc3BvcnRzYWJzb3JiZWQuc3BvcnQu YmxvZ4IXd3d3LnRoZWZlYXN0Lm11c2ljLmJsb2cwEwYDVR0gBAwwCjAIBgZngQwB AgEwggEDBgorBgEEAdZ5AgQCBIH0BIHxAO8AdQA/F0tP1yJHWJQdZRyEvg0S7ZA3 fx+FauvBvyiF7PhkbgAAAY6woBFTAAAEAwBGMEQCIE/jM10cH9IS7oZ93wlQRVRr UneOgJpaQe49na6ntrq8AiA12ZtoFNJYMW4grWJQerqJ0q+Xgqjl2XL9xo9DAbVt fgB2AHb/iD8KtvuVUcJhzPWHujS0pM27KdxoQgqf5mdMWjp0AAABjrCgEaAAAAQD AEcwRQIhANHu963RXNhRJ+Hs4X+ZjWOEnRBoUAO0Iu+au7wvfjK+AiBkMferL4bq 2skx7ducamzKR4U0Jn8FwGyHUoMsllj6bTANBgkqhkiG9w0BAQsFAAOCAQEAAcQy T/lOQapZDc2WBcL0Y8ryxFO6DRupg55CIQ2J0xo0CwJxL9wK4AexLnSf2lQ167/h TPgRTtrqVTZnPmKXFLRh8dxt5EK/vzgUXolQp+Xq9NiBIdycVZLOqi5PDY4WTl38 d6CDoCNJ9P3L6ePOlid5i+bYTxm+ysZkuCGJvLZxWQxfNP/zZMs9Nv7sUViZj3jK BuIc6sSZZR147+3s82b7nukwxaGk58N6eP+Aw1+RAr3EHOCGgiDInoePNv4ZMJyu iffQcGd0QoVenCqZyRwM0E4/2pod+swimDl6OeHMafgQtefCEXbKSfzphErjH9pC muSbOUUH+/Qa8uB1fw== -----END CERTIFICATE----- 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1 -----BEGIN CERTIFICATE----- MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG /kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4 avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2 yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+ HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX nLRbwHOoq7hHwg== -----END CERTIFICATE----- --- Server certificate subject=CN = tls.automattic.com issuer=C = US, O = Let's Encrypt, CN = R3 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: ECDSA Server Temp Key: X25519, 253 bits --- SSL handshake has read 4178 bytes and written 404 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 256 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) --- DONE