Namecheap.com

SSL Checker

Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.

Report

Hostname: Matches Common Name or/and SAN
Expired: No (28 days till expiration)
Public Key: We were unable to find any issues in the public key of end-entity certificate
Trusted: Yes, we were able to verify the certificate
Self-Signed: No, the end-entity certificate is not self-signed
Chain Issues: No, we were unable to detect any issues in the certificate chain sent by the server
Weak signatures: No, certificates sent by the server were not signed utilizing a weak hash function
OCSP Status: OCSP Responder returned "good" status for the end-entity certificate

DNS Information

Resolves To: 151.101.66.133
Reverse IP lookup: No records found
Nameserver: a11-67.akam.net.
Nameserver: a10-66.akam.net.
Nameserver: a6-66.akam.net.
Nameserver: a16-64.akam.net.
Nameserver: a1-171.akam.net.
Nameserver: a7-65.akam.net.

General Information

Common Name: harvard.edu
SANs: DNS:harvard.edu Total number of SANs: 1
Signature Algorithm: sha256WithRSAEncryption
Key Type: RSA
Key size: 2048 bits
Serial Number: 767fafcc124a561464f9e4e8a85f97ac2f41
Not Before: Apr 18, 2024 11:35:39 GMT
Not After: May 18, 2024 11:35:38 GMT
Number of certs: 2
Revocation Status: good
OCSP Stapling: Supported
Server: Varnish
HSTS: max-age=300
HPKP: Not Supported

Chain Information

Certificate # 1 - Common Name: harvard.edu

Decode this certificate for verbose information →
Subject Common Name harvard.edu
Issuer Common Name Certainly Intermediate R1
Issuer Organization Certainly
Not Before: Apr 18, 2024 11:35:39 GMT
Not After: May 18, 2024 11:35:38 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 767fafcc124a561464f9e4e8a85f97ac2f41
SHA1 Fingerprint: 7B:1B:4F:86:AA:86:2E:60:75:D7:58:DA:D7:1C:C8:AB:1A:67:54:89
MD5 Fingerprint: 33:10:ED:4B:EA:20:DB:6F:64:31:FB:FF:DB:A1:13:EB

Certificate # 2 - Common Name: Certainly Intermediate R1

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name Certainly Intermediate R1
Subject Organization Certainly
Issuer Common Name Starfield Root Certificate Authority - G2
Issuer Organization Starfield Technologies, Inc.
Not Before: Jun 22, 2022 00:00:00 GMT
Not After: Jun 21, 2032 23:59:59 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 11831cde4cb573e5
SHA1 Fingerprint: FE:DE:A3:AA:3B:69:BF:9B:84:DB:1F:BE:46:85:5A:F9:90:ED:BD:B1
MD5 Fingerprint: B9:9B:51:0F:43:63:11:00:93:5F:84:18:CA:8D:6B:E5

OpenSSL Handshake

depth=2 C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Root Certificate Authority - G2
verify return:1
depth=1 C = US, O = Certainly, CN = Certainly Intermediate R1
verify return:1
depth=0 CN = harvard.edu
verify return:1
CONNECTED(00000003)
OCSP response: 
======================================
OCSP Response Data:
    OCSP Response Status: successful (0x0)
    Response Type: Basic OCSP Response
    Version: 1 (0x0)
    Responder Id: C = US, O = Certainly, CN = Certainly Intermediate R1
    Produced At: Apr 18 12:35:00 2024 GMT
    Responses:
    Certificate ID:
      Hash Algorithm: sha1
      Issuer Name Hash: 3D0B2D39F2E1126FED1D7499B96EA5E516F7DB70
      Issuer Key Hash: BD979DDFA1D81B2599E30C0406896412D76524C7
      Serial Number: 767FAFCC124A561464F9E4E8A85F97AC2F41
    Cert Status: good
    This Update: Apr 18 12:35:00 2024 GMT
    Next Update: Apr 22 12:34:59 2024 GMT

    Signature Algorithm: sha256WithRSAEncryption
         0c:d5:4d:46:a2:bb:88:26:18:05:7f:b3:43:71:86:a0:df:8f:
         3b:b8:56:e0:fe:79:51:42:91:8b:ab:ec:d3:ea:1d:c4:fc:50:
         3d:54:40:df:d5:17:58:11:da:ac:22:7e:c5:5a:95:9e:83:b8:
         d0:4a:9a:46:9d:0d:73:38:ed:b8:18:0b:27:36:4a:21:ce:d5:
         59:83:d7:e4:57:6f:65:ac:6b:44:f5:54:ec:f9:6c:ff:c3:7f:
         af:af:45:54:ba:44:95:69:3e:d4:85:1b:79:31:42:29:81:c2:
         9f:04:93:4a:ec:db:0a:70:29:a9:ec:3d:b6:57:eb:41:94:64:
         e7:f0:31:90:59:ae:e9:58:6d:91:97:95:a4:a9:94:b0:2c:3f:
         f0:51:dc:0a:9e:b4:de:19:21:77:83:0b:5a:5a:73:f6:b8:93:
         8d:ed:09:57:5e:a2:f5:55:f7:1e:e9:ea:a4:6a:b1:fe:91:45:
         61:06:c6:c0:82:da:59:ec:49:bc:f4:bd:2f:59:cc:51:1a:26:
         8a:ec:35:55:90:92:db:07:e5:f6:be:e2:f9:bf:99:ef:11:e7:
         6c:bb:ca:0f:40:8b:2d:2e:14:62:0b:25:7f:31:fa:5e:23:17:
         99:70:6d:94:b7:3a:94:f0:b6:75:d7:7b:cf:52:ba:49:31:fb:
         43:52:77:d5
======================================
---
Certificate chain
 0 s:CN = harvard.edu
   i:C = US, O = Certainly, CN = Certainly Intermediate R1
-----BEGIN CERTIFICATE-----
MIIFBTCCA+2gAwIBAgISdn+vzBJKVhRk+eToqF+XrC9BMA0GCSqGSIb3DQEBCwUA
MEUxCzAJBgNVBAYTAlVTMRIwEAYDVQQKEwlDZXJ0YWlubHkxIjAgBgNVBAMTGUNl
cnRhaW5seSBJbnRlcm1lZGlhdGUgUjEwHhcNMjQwNDE4MTEzNTM5WhcNMjQwNTE4
MTEzNTM4WjAWMRQwEgYDVQQDEwtoYXJ2YXJkLmVkdTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAOrEGnG6OoPpb66iKMd7NCBZguEViA80rqaVYhpyc5/x
AS5pQR0uiCFbp4VdeK1jqCRSGy0juJUZT9Ccul7RkWW1DvTSmVDeCke0GsOTjXs5
/QGjEvCO16eieRN9EeYcZyMlNTgQa12EObWiiXLZQdvTFl0xO6ZVac6feXkpYEMY
2/ipEL7MQk4tw9cdN+1xGyDSRDs1+0nXrOQVfOdZG0uqfO2lLUSl71vmlg/0ijU0
f9F9NGiN69uir7K/nvAcfJTVV0CGZ7B+NSGrG+ichI8gXESvH0z6Rc6O4i+FO5FB
9px7wNyAJ9VPnB3c93wSQaanwqj7orM5BCg8IYjAJAsCAwEAAaOCAhwwggIYMA4G
A1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYD
VR0TAQH/BAIwADAdBgNVHQ4EFgQU2qXVkY/ilCnOyCQPa6j3h/FMzDIwHwYDVR0j
BBgwFoAUvZed36HYGyWZ4wwEBolkEtdlJMcwZQYIKwYBBQUHAQEEWTBXMCwGCCsG
AQUFBzABhiBodHRwOi8vb2NzcC5pbnQtcjEuY2VydGFpbmx5LmNvbTAnBggrBgEF
BQcwAoYbaHR0cDovL2ludC1yMS5jZXJ0YWlubHkuY29tMBYGA1UdEQQPMA2CC2hh
cnZhcmQuZWR1MBMGA1UdIAQMMAowCAYGZ4EMAQIBMIIBAwYKKwYBBAHWeQIEAgSB
9ASB8QDvAHYAO1N3dT4tuYBOizBbBv5AO2fYT8P0x70ADS1yb+H61BcAAAGO8TSY
zwAABAMARzBFAiEAgzzSJ5xCop4vsde0ruDAKtbPsAi9ygSKQke84b6k5EcCIHNK
2Vwvtyt+Djm4Tk27qYXy3Bv+7fyvzOE5gU79SLPTAHUA7s3QZNXbGs7FXLedtM0T
ojKHRny87N7DUUhZRnEftZsAAAGO8TSZHAAABAMARjBEAiBYToKFnqP1urmOYpXn
/K1R9D3YACO3B3VCTF7rZzI7pQIgElUpBrWMeXo8WKoLQ3WS8Z8kwNbXBUHdhapz
3PN2ZokwDQYJKoZIhvcNAQELBQADggEBABTCvx3Nv/1likKGslvNhfm9MYbJBGyc
tb9QII5N2FrG38gyJkomos1PcXsqyyYCDk9JQHhrEOt0rdj6JGuPEf2SPkY/65mR
+utVk8iu/GTlrjPJD0+Kxq45gdiChd+/zjxE/uxAhVjr4DBnVq2lwqWpzXhbi1qg
Umk5IzVlYZD8SBm67IKhNNmpj3wPQgHOOMBRbJcrvYQNNisdmvW4m2KlyPc1PBZ6
v+6TMa7kb6UUXqIcIsrYwerdoC45GpddNaKEdoH6ORz+5UBymcxgL5SG1ForUIcK
gnF8HUwTseblTvsucHoJJSC+lI8vrNE7DF4BrnzREvLZ28QatYry1P8=
-----END CERTIFICATE-----
 1 s:C = US, O = Certainly, CN = Certainly Intermediate R1
   i:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Root Certificate Authority - G2
-----BEGIN CERTIFICATE-----
MIIEoDCCA4igAwIBAgIIEYMc3ky1c+UwDQYJKoZIhvcNAQELBQAwgY8xCzAJBgNV
BAYTAlVTMRAwDgYDVQQIEwdBcml6b25hMRMwEQYDVQQHEwpTY290dHNkYWxlMSUw
IwYDVQQKExxTdGFyZmllbGQgVGVjaG5vbG9naWVzLCBJbmMuMTIwMAYDVQQDEylT
dGFyZmllbGQgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgLSBHMjAeFw0yMjA2
MjIwMDAwMDBaFw0zMjA2MjEyMzU5NTlaMEUxCzAJBgNVBAYTAlVTMRIwEAYDVQQK
EwlDZXJ0YWlubHkxIjAgBgNVBAMTGUNlcnRhaW5seSBJbnRlcm1lZGlhdGUgUjEw
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCW0khmsa1kAMrw6Q6kPsiZ
6LfWXQcpcDnu1+Ql7+FYYyBKT3zFSsjx+ZTI2yRG2sFOwbBMchtQf5MGUoQfNznR
ANlqUNXdWlMrkso93JburzqBEoNGy8utK0TNnepMbb1yc4YuXk/nMRZaBPA2Lh8u
twUG3vMvNQHsliV48CQ+4CJutM34rvI9AfJeI2CkcxBUlCyYatGcA12nvCr7dGdy
EKeG5G4XyBak48571FtQqNqkSkCQlqmv93LVoOHqzEQKcJWw8zPxZc0dnORZVmgL
l3Ws/QltCsIf6OTyQOfGHi81ehr6P4j1KQ56MfgWcqBqdeIANxVcb0ZVVb3SiEhT
AgMBAAGjggFHMIIBQzASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIB
hjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFL2Xnd+h
2BslmeMMBAaJZBLXZSTHMB8GA1UdIwQYMBaAFHwMMh+n2TB/xH1oo2Kooc6rB1sn
MF4GCCsGAQUFBwEBBFIwUDBOBggrBgEFBQcwAoZCaHR0cDovL2NlcnRpZmljYXRl
cy5zdGFyZmllbGR0ZWNoLmNvbS9yZXBvc2l0b3J5L3Nmcm9vdC1nMi5jcnQuY2Vy
MDsGA1UdHwQ0MDIwMKAuoCyGKmh0dHA6Ly9jcmwuc3RhcmZpZWxkdGVjaC5jb20v
c2Zyb290LWcyLmNybDAhBgNVHSAEGjAYMAgGBmeBDAECATAMBgorBgEEAYOGGQEB
MA0GCSqGSIb3DQEBCwUAA4IBAQBosoh/lcTPBVC36SxIqjmdnuKwHs4SUDa/o5+y
AJ22DaZDIFMJS+LLhslCVPAO9lQ5LR0AviC8atueKWOxPUw5aNDodEpIe988xSNa
LSuPXsAB93FJ5v2BxdCiDHlIZbJPAOVQAo+rP2WgaTcDFX6g6LvK1b/RS9kL+rCB
OebvFIbOmhfErkXjR7F6p759ftTQ23tT1qoTgegkySRgugEp0mtveWq87UIsGgdI
e3UVWONiA9l3hTmxRyHkaYLlBzDdVPt4MIUkFrxZAz/8ebh+x2KNfAO6Mxi/vdS0
9NEqn0ekjRmQK5UvHXoBNHVvZ1VrbMv6hlIMCt++bfb6UBoK
-----END CERTIFICATE-----
---
Server certificate
subject=CN = harvard.edu

issuer=C = US, O = Certainly, CN = Certainly Intermediate R1

---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 3670 bytes and written 407 bytes
Verification: OK
---
New, TLSv1.2, Cipher is ECDHE-RSA-CHACHA20-POLY1305
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-CHACHA20-POLY1305
    Session-ID: 8CE6FA2001D106A75021101DCA859658C25718AE7A7B0E36AC0948DCC77C9BBF
    Session-ID-ctx: 
    Master-Key: A2FC0F18E730D79E6EA9677920F7179FAEBD2472EAB3930455D71060502BF9BFE1D2ADA6800E3B954DC9C84C524B32AE
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - 70 0d 90 ac 2d bb 9e a5-3c e0 21 cd b2 82 27 48   p...-...<.!...'H
    0010 - be aa 81 aa a8 2e 32 d3-ed 17 00 ef 33 bc 20 93   ......2.....3. .
    0020 - 6e cc f7 95 e7 40 2d b7-41 ff 15 60 e3 78 5e 0f   n....@-.A..`.x^.
    0030 - db c3 0f 61 89 48 3e a3-af af 66 a8 0a ca 90 32   ...a.H>...f....2
    0040 - cb 45 88 3a bb 81 d5 fa-30 2e bd be cc 80 af a7   .E.:....0.......
    0050 - a3 9f 61 34 02 b8 18 15-9b c9 39 30 bb 30 4e be   ..a4......90.0N.
    0060 - 3a 76 b2 e0 d7 2a 51 cd-b0 91 e7 1d ea bd 47 2a   :v...*Q.......G*
    0070 - ba f0 af aa c9 d3 01 75-2b b7 44 55 0a 8d be 12   .......u+.DU....
    0080 - 33 c1 46 c8 84 ce 67 e6-a4 82 d2 2d 19 14 fc 89   3.F...g....-....
    0090 - 7a a9 82 5f eb d9 cb 91-d8 21 fc b6 80 b0 12 58   z.._.....!.....X
    00a0 - d1 2b 1a d1 80 11 0f 9b-12 9a 36 e6 d6 3d 51 d5   .+........6..=Q.
    00b0 - d4 b3 b0 67 cc 67 44 b2-04 1a 95 42 80 34 89 f4   ...g.gD....B.4..

    Start Time: 1713564706
    Timeout   : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: yes
---
DONE