Namecheap.com

SSL Checker

Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.

Report

Hostname: Matches Common Name or/and SAN
Expired: No (66 days till expiration)
Public Key: We were unable to find any issues in the public key of end-entity certificate
Trusted: Yes, we were able to verify the certificate
Self-Signed: No, the end-entity certificate is not self-signed
Chain Issues: No, we were unable to detect any issues in the certificate chain sent by the server
Weak signatures: No, certificates sent by the server were not signed utilizing a weak hash function
OCSP Status: OCSP Responder returned "good" status for the end-entity certificate

DNS Information

Resolves To: 23.185.0.1
Reverse IP lookup: No records found
Nameserver: ns1.slicehost.net.
Nameserver: ns3.slicehost.net.
Nameserver: ns2.slicehost.net.

General Information

Common Name: mediamatters.org
SANs: DNS:mediamatters.orgDNS:mm4a.orgDNS:www.mediamatters.orgDNS:www.mm4a.org Total number of SANs: 4
Signature Algorithm: sha256WithRSAEncryption
Key Type: RSA
Key size: 2048 bits
Serial Number: 4ea6bf414ac538719c9400dc29760e8e988
Not Before: Apr 03, 2024 17:31:15 GMT
Not After: Jul 02, 2024 17:31:14 GMT
Number of certs: 2
Revocation Status: good
OCSP Stapling: Supported
Server: Varnish
HSTS: max-age=300
HPKP: Not Supported

Chain Information

Certificate # 1 - Common Name: mediamatters.org

Decode this certificate for verbose information →
Subject Common Name mediamatters.org
Issuer Common Name R3
Issuer Organization Let's Encrypt
Not Before: Apr 03, 2024 17:31:15 GMT
Not After: Jul 02, 2024 17:31:14 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 4ea6bf414ac538719c9400dc29760e8e988
SHA1 Fingerprint: EF:F6:5D:65:EF:C1:95:33:4B:00:02:10:F2:EC:E2:A1:01:E4:F3:BB
MD5 Fingerprint: 5F:72:E7:6F:3B:A9:B9:43:25:29:FE:8D:B5:F7:00:55

Certificate # 2 - Common Name: R3

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name R3
Subject Organization Let's Encrypt
Issuer Common Name ISRG Root X1
Issuer Organization Internet Security Research Group
Not Before: Sep 04, 2020 00:00:00 GMT
Not After: Sep 15, 2025 16:00:00 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 912b084acf0c18a753f6d62e25a75f5a
SHA1 Fingerprint: A0:53:37:5B:FE:84:E8:B7:48:78:2C:7C:EE:15:82:7A:6A:F5:A4:05
MD5 Fingerprint: E8:29:E6:5D:7C:43:07:D6:FB:C1:3C:17:9E:03:7A:36

OpenSSL Handshake

depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = R3
verify return:1
depth=0 CN = mediamatters.org
verify return:1
CONNECTED(00000003)
OCSP response: 
======================================
OCSP Response Data:
    OCSP Response Status: successful (0x0)
    Response Type: Basic OCSP Response
    Version: 1 (0x0)
    Responder Id: C = US, O = Let's Encrypt, CN = R3
    Produced At: Apr 21 12:27:00 2024 GMT
    Responses:
    Certificate ID:
      Hash Algorithm: sha1
      Issuer Name Hash: 48DAC9A0FB2BD32D4FF0DE68D2F567B735F9B3C4
      Issuer Key Hash: 142EB317B75856CBAE500940E61FAF9D8B14C2C6
      Serial Number: 04EA6BF414AC538719C9400DC29760E8E988
    Cert Status: good
    This Update: Apr 21 12:27:00 2024 GMT
    Next Update: Apr 28 12:26:58 2024 GMT

    Signature Algorithm: sha256WithRSAEncryption
         93:4c:a9:56:97:6d:c4:2b:c0:4c:c3:82:16:e9:de:23:4b:fc:
         0d:75:00:07:96:65:42:54:a2:4b:5a:94:40:d8:fe:18:7c:d3:
         65:67:cf:d0:f2:16:57:58:31:fd:94:9e:7b:ad:d7:e2:6e:a6:
         d6:7c:54:a9:ee:df:81:d7:c3:63:6f:4a:f2:44:ed:bf:82:52:
         8d:2d:9e:ee:5c:08:da:0a:da:92:10:a7:f4:19:c6:58:0e:f2:
         4c:30:f4:36:50:22:aa:25:86:b2:ce:31:39:17:ea:ae:c8:cd:
         07:db:1d:6d:3b:02:d0:2b:bc:4d:fc:60:53:f5:8c:c8:01:27:
         b5:ad:8b:49:e0:12:15:fa:80:bd:de:86:0c:5c:a6:8c:27:b9:
         ba:95:57:f1:65:81:2f:3f:8c:e1:9f:ae:d0:ef:66:8b:f8:9b:
         7c:d5:6c:c5:2b:d3:c0:68:00:ac:1b:42:f9:25:45:9a:bd:c9:
         a1:58:c3:3a:90:5e:e8:db:44:94:ce:32:5f:3d:40:d6:83:99:
         d6:a7:2b:f8:13:bd:30:96:78:d8:33:57:dd:be:6f:b3:b5:0d:
         bb:a5:eb:72:bb:ea:8b:1b:7b:3f:76:af:22:89:ae:c3:f3:35:
         c9:ae:2a:4f:1f:a4:99:61:4e:45:19:5d:a6:c3:f6:d6:4e:94:
         9d:fa:7d:d1
======================================
---
Certificate chain
 0 s:CN = mediamatters.org
   i:C = US, O = Let's Encrypt, CN = R3
-----BEGIN CERTIFICATE-----
MIIFGjCCBAKgAwIBAgISBOpr9BSsU4cZyUANwpdg6OmIMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yNDA0MDMxNzMxMTVaFw0yNDA3MDIxNzMxMTRaMBsxGTAXBgNVBAMT
EG1lZGlhbWF0dGVycy5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDAdKd6a/TBnNxcCAyQFBfO3CM0cWsekizlrGvPOt2XDtP4ZkBAs+JS9JmYXdJx
FDU2LvszvC++PxYqASbqSaQgayoSvU3BU7/0z5t8vh4/LXLBXztbHtk5VUrglYky
py061ZnKcnPeNfrs11rT70H77j83hMBoulSfG7zeYxpMv6X/zJiKfSIi3HFndhEy
8vygw70FaoWKCEJKzN8ilG58YeOkR6h0ll7touLsNx4+/DJdlaL9qXVhB4J0WSum
RyCTybKE/8A/NCOTdt0oCXApAN29BHhjdv5swlWJsNZWtWqMvP7JuloAmI6Mo6an
00MLotk8m6NWwT6a9hHzLZlVAgMBAAGjggI/MIICOzAOBgNVHQ8BAf8EBAMCBaAw
HQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYD
VR0OBBYEFPqnMCJguLsYsLVvaKPMOXITyyIUMB8GA1UdIwQYMBaAFBQusxe3WFbL
rlAJQOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0cDov
L3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5jci5v
cmcvMEkGA1UdEQRCMECCEG1lZGlhbWF0dGVycy5vcmeCCG1tNGEub3JnghR3d3cu
bWVkaWFtYXR0ZXJzLm9yZ4IMd3d3Lm1tNGEub3JnMBMGA1UdIAQMMAowCAYGZ4EM
AQIBMIIBAwYKKwYBBAHWeQIEAgSB9ASB8QDvAHUASLDja9qmRzQP5WoC+p0w6xxS
ActW3SyB2bu/qznYhHMAAAGOpTrF4QAABAMARjBEAiASTp+KZ82fWw6qkNNmXgnp
YhWKOWoYcegxFGlRhfPFxgIgIyTJrPP30EDVL9V7DTQ2eADRgrbNt+UHrHGL17oc
FR4AdgDuzdBk1dsazsVct520zROiModGfLzs3sNRSFlGcR+1mwAAAY6lOsXlAAAE
AwBHMEUCIDXLY+k8EyUzUJilN3dky3cl7rVS+VIusFJHesiCF922AiEA1jAWTYGu
BDNplRZreSJYa+ZLCf+JvleVpEFj0y3/eK8wDQYJKoZIhvcNAQELBQADggEBABz+
gBKygirQBPJR7y8AHgYX4C0aq9fshS3FJEIXEjnFy2i1/wqcXkpwLeaX5yCjFs1Z
VQKGWHYU+AUZy+tantpxOH0MeU2CwpBE2+cAL+99w6yoH6yAS1LbGMf9xPWFR59+
DX7poV1HQ/q3XtXI3q5NrwEvQWsyoUDHZV3t4ACziqJQOQh+gdYRVMmLLJ4YpsaD
xRt84W3V0YbWI4UPKeWDG16VgpVMOI9aqKbo35V20dPs/1J6RRSisI/GLYt/oqxv
aHngQk5jUVG02VFM4P98doJ/AQude6yspzz1SITa0WQVlsB1FRhbxCEinwlyvfsZ
t+TcaWq66tvm53TPQ3Q=
-----END CERTIFICATE-----
 1 s:C = US, O = Let's Encrypt, CN = R3
   i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
-----BEGIN CERTIFICATE-----
MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw
WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg
RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP
R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx
sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm
NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg
Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG
/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC
AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB
Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA
FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw
AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw
Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB
gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W
PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl
ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz
CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm
lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4
avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2
yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O
yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids
hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+
HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv
MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX
nLRbwHOoq7hHwg==
-----END CERTIFICATE-----
---
Server certificate
subject=CN = mediamatters.org

issuer=C = US, O = Let's Encrypt, CN = R3

---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 3676 bytes and written 391 bytes
Verification: OK
---
New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256
Server public key is 2048 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
DONE
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
    Protocol  : TLSv1.3
    Cipher    : TLS_AES_128_GCM_SHA256
    Session-ID: 31E49ECB54D4C1DAD6C828D913104E4A3B3BAF4C05D6F971BF5432F421C4C8FD
    Session-ID-ctx: 
    Resumption PSK: A2FCC6A02A868C6302A869E589AE1BCACC5D45EC074B783D3A76948822DC43EB
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 3600 (seconds)
    TLS session ticket:
    0000 - 52 51 9f 4b 0a 9a 35 d3-43 28 ce 66 78 9b 83 d1   RQ.K..5.C(.fx...
    0010 - 4b 58 2d 88 da 0a 79 a0-78 b6 73 d0 10 f7 91 5d   KX-...y.x.s....]
    0020 - f9 5f ac e5 78 a4 bf 9e-ca 13 70 9c ae bb 85 ac   ._..x.....p.....
    0030 - fb df 68 bb d0 1e 9d 7a-43 1b af b5 7f f1 c7 0f   ..h....zC.......
    0040 - 7b 57 d8 23 37 fb 75 18-82 a3 bc 9b da 69 b3 e7   {W.#7.u......i..
    0050 - 27 76 98 eb 8b 63 12 fe-99 1a ca 53 0b fa b5 43   'v...c.....S...C
    0060 - 6f ea 04 a9 c1 29 1e 0c-22 ed de fb 81 57 c1 e5   o....).."....W..
    0070 - 9e cb 16 ae 70 15 ad ae-42 19 c5 3f da bc 98 00   ....p...B..?....
    0080 - 65 b6 75 65 49 98 db a4-0f 4a c4 f0 c4 50 29 5c   e.ueI....J...P)\
    0090 - 74 fc 4d 45 9a 5f 23 01-ab 06 81 b5 40 bb 03 a1   t.ME._#.....@...

    Start Time: 1714182370
    Timeout   : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: no
    Max Early Data: 8192
---
read R BLOCK