SSL Checker
Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.
Report
It's all good. We have not detected any issues.
Hostname: | done Matches Common Name or/and SAN |
Expired: | done No (65 days till expiration) |
Public Key: | done We were unable to find any issues in the public key of end-entity certificate |
Trusted: | done Yes, we were able to verify the certificate |
Self-Signed: | done No, the end-entity certificate is not self-signed |
Chain Issues: | done No, we were unable to detect any issues in the certificate chain sent by the server |
Weak signatures: | done No, certificates sent by the server were not signed utilizing a weak hash function |
OCSP Status: | done OCSP Responder returned "good" status for the end-entity certificate |
DNS Information
Resolves To: | 173.239.79.196 |
Reverse IP lookup: | vm1.eff.org. |
Nameserver: | ns2.eff.org. |
Nameserver: | ns1.eff.org. |
Nameserver: | ns4.eff.org. |
General Information
Common Name: | eff.org |
SANs: | DNS:eff.org Total number of SANs: 1 |
Signature Algorithm: | sha256WithRSAEncryption |
Key Type: | RSA |
Key size: | 4096 bits |
Serial Number: | 3db4257173a673926cbd8a724b3bf64a5b5 |
Not Before: | Apr 01, 2024 18:42:06 GMT |
Not After: | Jun 30, 2024 18:42:05 GMT |
Number of certs: | 2 |
Revocation Status: | good |
OCSP Stapling: | Not Supported |
Server: | nginx |
HSTS: | max-age=63072000; includeSubdomains; preload |
HPKP: | Not Supported |
Chain Information
Certificate # 1 - Common Name: eff.org
Decode this certificate for verbose information → launchSubject Common Name | eff.org |
Issuer Common Name | R3 |
Issuer Organization | Let's Encrypt |
Not Before: | Apr 01, 2024 18:42:06 GMT |
Not After: | Jun 30, 2024 18:42:05 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 3db4257173a673926cbd8a724b3bf64a5b5 |
SHA1 Fingerprint: | A2:98:C5:AF:A7:A4:1B:6C:26:A9:BD:C0:BB:CF:12:0E:BB:96:E8:AB |
MD5 Fingerprint: | E4:F0:66:45:C0:50:54:60:6C:81:C7:4E:2B:94:D3:9D |
Certificate # 2 - Common Name: R3
Decode this certificate for verbose information → launchIn place? | Yes, this certificate directly certifies the preceding one |
Subject Common Name | R3 |
Subject Organization | Let's Encrypt |
Issuer Common Name | ISRG Root X1 |
Issuer Organization | Internet Security Research Group |
Not Before: | Sep 04, 2020 00:00:00 GMT |
Not After: | Sep 15, 2025 16:00:00 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 912b084acf0c18a753f6d62e25a75f5a |
SHA1 Fingerprint: | A0:53:37:5B:FE:84:E8:B7:48:78:2C:7C:EE:15:82:7A:6A:F5:A4:05 |
MD5 Fingerprint: | E8:29:E6:5D:7C:43:07:D6:FB:C1:3C:17:9E:03:7A:36 |
OpenSSL Handshake
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1 verify return:1 depth=1 C = US, O = Let's Encrypt, CN = R3 verify return:1 depth=0 CN = eff.org verify return:1 CONNECTED(00000003) OCSP response: no response sent --- Certificate chain 0 s:CN = eff.org i:C = US, O = Let's Encrypt, CN = R3 -----BEGIN CERTIFICATE----- MIIF2jCCBMKgAwIBAgISA9tCVxc6Zzkmy9inJLO/ZKW1MA0GCSqGSIb3DQEBCwUA MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD EwJSMzAeFw0yNDA0MDExODQyMDZaFw0yNDA2MzAxODQyMDVaMBIxEDAOBgNVBAMT B2VmZi5vcmcwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDgS76VAeW6 EVCslqrlHkvSoqfTTUTFD3a8Fodx+uR9oCYhRZ5TXHodoeffTTDU+6I8Zk0jRxcY pCysNkgKIKwRCv0vEMZjHcTrcWf8O1RIx4IgW2DlwkDf4Xm7WnE8IOj0eNLBr7nT YPFp0DjeniIkkcn6YWX0aUen38sL60H5tH8/bYE2duS30NKPOadVaNcq0qWEwJaX rbGd6k0t0xVevD/AZKj0Q/GnaqkuhGyBzcP12OWoVv5WVo/1liYRWF+na373bK84 4tXqoOytk4/o9nd0Mvr5sF0oWiYXnI38VvS34wzTnEgr8c7ACyvg97ddTs8KIKk6 Y6jRpqVddppBB9gGYVHy7T+cXZAt/ljripPk32OkOynmlOzmV8zU4urSRxEIiNI6 0Gu2VTYroiE0TgUyGk11zxf7UfiYU0hddeHX9FI7kvGsEeBwBvA0RMzvQfwx4Oh4 GX6vxpNohvz+51C81Wtghw+DAOeYFTLKy9Wh2/WSK2s/ak6I49jhxNMsF6tO/mZq XCuQ1H7EgxlGPnVffPMZ9uDOKqg6Tz86VFTIGPuSCN9wuqXDG55lqWTf2i8lKJDz 5yvVZDNAAJJ91N9WOz0FUNLXMhlvydyUKnxJmzpuKBNNTSMWJCbqShOkGYpLmslw zlgzuzKzsA6I7kcOWmvmBDUO8Q8xoQKGJQIDAQABo4ICCDCCAgQwDgYDVR0PAQH/ BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8E AjAAMB0GA1UdDgQWBBR4ijLWuVtCCXqdSjMVz024kHoPzTAfBgNVHSMEGDAWgBQU LrMXt1hWy65QCUDmH6+dixTCxjBVBggrBgEFBQcBAQRJMEcwIQYIKwYBBQUHMAGG FWh0dHA6Ly9yMy5vLmxlbmNyLm9yZzAiBggrBgEFBQcwAoYWaHR0cDovL3IzLmku bGVuY3Iub3JnLzASBgNVHREECzAJggdlZmYub3JnMBMGA1UdIAQMMAowCAYGZ4EM AQIBMIIBAwYKKwYBBAHWeQIEAgSB9ASB8QDvAHUASLDja9qmRzQP5WoC+p0w6xxS ActW3SyB2bu/qznYhHMAAAGOmy7oNwAABAMARjBEAiAv9TGyXnWAq1gMTCcU70Ru 0crx/UAtJbl1m1sjuqrydgIgft8keIEVMVmzfSh31pjNb1tHeIyfx0Yxc9h28Vg6 lbIAdgB2/4g/Crb7lVHCYcz1h7o0tKTNuyncaEIKn+ZnTFo6dAAAAY6bLuiEAAAE AwBHMEUCIGCaXZBA2Q89l38EkrQraCum+QqU3b0rBFalkRAHNo0KAiEA1TMpa4fb FR+RZqIn0dMkA/3ZgTIwbybkUlfwm2EmPRUwDQYJKoZIhvcNAQELBQADggEBAHZE 5IGE3t8EHXcTFdto+MSM9mdr4BmfqA3fZV0541OhFa1R8QrjypjnkHQmjyt78EoY 4RgWFzI8RskMrhuGc4RKtDXRRhQRgWd2i7RDBkANAQcFijDxUmlV7Us1qXeP/hBg 5B/qoBn6q8/zH+kr2UQ6xvG4+qATsKq6VNqJS8H8tWgVafbARIJZWF6X2sCBC72O sgbl5XKm8wSgfiQIdoqevJlVldybVlrW/dgGPHuNcIi/gk62NDBbbxaF9squzMY0 1KD8c0THc7vPb6OlBNsFvEgE7kgMKCkkG7pYXYGmL8RZiugqssX7g6/2tbGPUZMx ZHTdREvY+LGoYOlNl3c= -----END CERTIFICATE----- 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1 -----BEGIN CERTIFICATE----- MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG /kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4 avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2 yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+ HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX nLRbwHOoq7hHwg== -----END CERTIFICATE----- --- Server certificate subject=CN = eff.org issuer=C = US, O = Let's Encrypt, CN = R3 --- No client certificate CA names sent Peer signing digest: SHA512 Peer signature type: RSA Server Temp Key: X25519, 253 bits --- SSL handshake has read 3728 bytes and written 411 bytes Verification: OK --- New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384 Server public key is 4096 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES256-GCM-SHA384 Session-ID: BF943CDCCFCA49583587E80B552F0493E780409D1250DB52C22531A472769BBB Session-ID-ctx: Master-Key: 12F0CDDFA323366CE5ED67F355253E51D69F60D3D91821BCFD02F4EEE9D0B14089EE24508B36CBE0C288865CF0107956 PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 600 (seconds) TLS session ticket: 0000 - f2 4f 6b bc 5c d2 9d e0-dc a4 d6 4e cb 7f 93 c7 .Ok.\......N.... 0010 - d6 0b 09 21 99 f8 f7 1a-39 69 82 21 0f 77 ea ca ...!....9i.!.w.. 0020 - 73 b1 0a ba 53 ec 43 ec-19 8d 5a 3c 58 62 f8 7d s...S.C...Z<Xb.} 0030 - 17 22 48 d0 b5 4f 2e 07-4f 44 ea c6 97 9d 1d 87 ."H..O..OD...... 0040 - 5f ef 7c 4a 36 87 79 ba-28 83 b0 6a e9 3c 0c 68 _.|J6.y.(..j.<.h 0050 - 61 75 5f 51 3e 5c b1 d5-98 0f fc c2 fe 44 43 65 au_Q>\.......DCe 0060 - b8 fd 3a 3b 27 d5 64 3e-96 a7 13 9b 4f 36 77 c3 ..:;'.d>....O6w. 0070 - 73 22 77 56 55 c1 e6 cb-12 75 38 96 fd 4f 20 ac s"wVU....u8..O . 0080 - e9 e9 4c 18 86 23 e9 45-37 a4 55 04 a9 8d 7c 55 ..L..#.E7.U...|U 0090 - a8 5d 62 29 63 5e ed d1-50 33 84 8a ce 85 6f a5 .]b)c^..P3....o. 00a0 - 8f 43 9b 6f e2 49 a9 81-ae 0b f3 52 41 94 6e 6c .C.o.I.....RA.nl 00b0 - e5 b8 09 75 6c 7a 7f 9b-d6 54 2e 49 e8 f1 24 42 ...ulz...T.I..$B Start Time: 1714071723 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: yes --- DONE