Namecheap.com

SSL Checker

Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.

Report

Hostname: Matches Common Name or/and SAN
Expired: No (85 days till expiration)
Public Key: We were unable to find any issues in the public key of end-entity certificate
Trusted: Yes, we were able to verify the certificate
Self-Signed: No, the end-entity certificate is not self-signed
Chain Issues: No, we were unable to detect any issues in the certificate chain sent by the server
Weak signatures: No, certificates sent by the server were not signed utilizing a weak hash function
OCSP Status: OCSP Responder returned "good" status for the end-entity certificate

DNS Information

Resolves To: 192.0.66.24
Reverse IP lookup: No records found
Nameserver: a6-64.akam.net.
Nameserver: a7-66.akam.net.
Nameserver: a1-204.akam.net.
Nameserver: a4-67.akam.net.
Nameserver: a24-65.akam.net.
Nameserver: a16-67.akam.net.

General Information

Common Name: metro.co.uk
SANs: DNS:metro.co.ukDNS:www.metro.co.uk Total number of SANs: 2
Signature Algorithm: sha256WithRSAEncryption
Key Type: RSA
Key size: 2048 bits
Serial Number: 331a50f76c9d5ff063e76a82b26e106e5ab
Not Before: Dec 01, 2021 22:36:25 GMT
Not After: Mar 01, 2022 22:36:24 GMT
Number of certs: 3
Revocation Status: good
OCSP Stapling: Supported
Server: nginx
HSTS: max-age=31536000
HPKP: Not Supported

Chain Information

Certificate # 1 - Common Name: metro.co.uk

Decode this certificate for verbose information →
Subject Common Name metro.co.uk
Issuer Common Name R3
Issuer Organization Let's Encrypt
Not Before: Dec 01, 2021 22:36:25 GMT
Not After: Mar 01, 2022 22:36:24 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 331a50f76c9d5ff063e76a82b26e106e5ab
SHA1 Fingerprint: 70:CA:00:F4:EB:E5:B6:64:BD:86:3E:68:84:7E:68:30:18:0D:A9:83
MD5 Fingerprint: 9D:D3:BA:C9:00:19:14:1B:2C:77:2B:32:D8:05:03:65

Certificate # 2 - Common Name: R3

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name R3
Subject Organization Let's Encrypt
Issuer Common Name ISRG Root X1
Issuer Organization Internet Security Research Group
Not Before: Sep 04, 2020 00:00:00 GMT
Not After: Sep 15, 2025 16:00:00 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 912b084acf0c18a753f6d62e25a75f5a
SHA1 Fingerprint: A0:53:37:5B:FE:84:E8:B7:48:78:2C:7C:EE:15:82:7A:6A:F5:A4:05
MD5 Fingerprint: E8:29:E6:5D:7C:43:07:D6:FB:C1:3C:17:9E:03:7A:36

Certificate # 3 - Common Name: ISRG Root X1

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name ISRG Root X1
Subject Organization Internet Security Research Group
Issuer Common Name DST Root CA X3
Issuer Organization Digital Signature Trust Co.
Not Before: Jan 20, 2021 19:14:03 GMT
Not After: Sep 30, 2024 18:14:03 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 4001772137d4e942b8ee76aa3c640ab7
SHA1 Fingerprint: 93:3C:6D:DE:E9:5C:9C:41:A4:0F:9F:50:49:3D:82:BE:03:AD:87:BF
MD5 Fingerprint: C1:E1:FF:07:F9:F6:88:49:82:74:D1:A1:80:53:EA:BF

OpenSSL Handshake

depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = R3
verify return:1
depth=0 CN = metro.co.uk
verify return:1
CONNECTED(00000003)
OCSP response: 
======================================
OCSP Response Data:
    OCSP Response Status: successful (0x0)
    Response Type: Basic OCSP Response
    Version: 1 (0x0)
    Responder Id: C = US, O = Let's Encrypt, CN = R3
    Produced At: Dec  4 11:36:00 2021 GMT
    Responses:
    Certificate ID:
      Hash Algorithm: sha1
      Issuer Name Hash: 48DAC9A0FB2BD32D4FF0DE68D2F567B735F9B3C4
      Issuer Key Hash: 142EB317B75856CBAE500940E61FAF9D8B14C2C6
      Serial Number: 0331A50F76C9D5FF063E76A82B26E106E5AB
    Cert Status: good
    This Update: Dec  4 11:00:00 2021 GMT
    Next Update: Dec 11 10:59:58 2021 GMT

    Signature Algorithm: sha256WithRSAEncryption
         90:aa:cc:2b:3e:32:37:08:ce:ff:7c:ce:4d:43:f5:54:2b:50:
         7b:93:7d:ab:e1:9a:46:43:f2:88:9b:c6:57:0e:55:ea:79:61:
         7c:d9:5d:28:f9:c3:f7:a4:7e:9c:36:e5:cd:8f:a8:ac:71:38:
         f0:99:93:f4:79:97:d3:2a:50:05:c1:88:55:a7:34:ad:91:cb:
         d5:79:b1:29:5e:d1:70:18:6b:3c:5e:af:de:f1:be:cd:18:fd:
         3e:58:f2:c5:0b:9e:37:e9:14:3e:91:2d:2a:6f:4b:88:51:58:
         c4:69:1d:1d:65:de:62:13:84:ce:55:8f:bc:3a:fc:12:ee:9d:
         85:6b:96:ee:82:a2:04:bb:bd:9b:af:40:f6:af:b7:74:5d:19:
         7b:34:6c:90:45:58:c5:78:24:c7:82:c7:ba:2e:18:17:4b:e7:
         e1:2a:05:53:c1:c2:9f:17:2c:06:55:84:cf:ea:6a:0e:7e:e4:
         29:a2:bf:a9:5b:ef:83:00:69:cf:eb:2b:ae:85:50:46:83:12:
         f4:d6:19:ac:87:b5:00:1d:fc:0d:3f:7e:c2:f5:dc:a8:e2:10:
         9a:bb:a3:dd:f7:e5:42:02:61:55:38:74:ec:a0:85:17:25:ea:
         58:44:80:e8:14:79:b7:0c:d6:89:89:39:98:b5:a5:a7:71:7c:
         f1:b7:11:ff
======================================
---
Certificate chain
 0 s:/CN=metro.co.uk
   i:/C=US/O=Let's Encrypt/CN=R3
-----BEGIN CERTIFICATE-----
MIIFLjCCBBagAwIBAgISAzGlD3bJ1f8GPnaoKybhBuWrMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yMTEyMDEyMjM2MjVaFw0yMjAzMDEyMjM2MjRaMBYxFDASBgNVBAMT
C21ldHJvLmNvLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsVwb
dcYLZ0v+YR2rpPS7jq7W4EUaGLAPIxO3WxX5D219F7+7oqqE6N8mvCo/0NTGYgRz
B8dXjSP9THCYVKtppslSzUZ/Zw6iNlGav8UElKlZFLB3DzPZmIKu/Cp1r/JgzfiB
cltPbFVdSm2WguHQnsG4/8dnZYsQNUHz5+OkS7+ilZrXKBiWGoLzMwbWror5GXfQ
xuRlImaeEBzQYJceclT5/P4ZPZbTk7jyqo7RTQZ9oFUyDJmCaloYu9wSeKxoqI7H
FIZLY1Pwa2IOWsvFQs4I3wcf6M0DQv4drdjv2IIanjeOFX8pIVD3cKCAHBXze/Ny
ZyjS/fRWxujelU3nqwIDAQABo4ICWDCCAlQwDgYDVR0PAQH/BAQDAgWgMB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQW
BBS2cv0XXUx5mzOJtnR1/+PTO+scLDAfBgNVHSMEGDAWgBQULrMXt1hWy65QCUDm
H6+dixTCxjBVBggrBgEFBQcBAQRJMEcwIQYIKwYBBQUHMAGGFWh0dHA6Ly9yMy5v
LmxlbmNyLm9yZzAiBggrBgEFBQcwAoYWaHR0cDovL3IzLmkubGVuY3Iub3JnLzAn
BgNVHREEIDAeggttZXRyby5jby51a4IPd3d3Lm1ldHJvLmNvLnVrMEwGA1UdIARF
MEMwCAYGZ4EMAQIBMDcGCysGAQQBgt8TAQEBMCgwJgYIKwYBBQUHAgEWGmh0dHA6
Ly9jcHMubGV0c2VuY3J5cHQub3JnMIIBBQYKKwYBBAHWeQIEAgSB9gSB8wDxAHYA
KXm+8J45OSHwVnOfY6V35b5XfZxgCvj5TV0mXCVdx4QAAAF9eFs9HQAABAMARzBF
AiA23h8HfGSRWU0ykBnOGZ8HpqlCnyZTg9dEZ8Mi3Ade1wIhAJ232L+w4qOsUKvj
kReM4FwRKTZq00PS4gI2OiRBDNdAAHcA36Veq2iCTx9sre64X04+WurNohKkal6O
OxLAIERcKnMAAAF9eFs/HgAABAMASDBGAiEA2SJvNrhHY0ktdxTgkbLNlgtGPeqD
PNlswNTl+QgZ5dECIQC4MvpayhPlT76qnP7FG6WOQ4HhhQrS4miwi3tQY4OC3jAN
BgkqhkiG9w0BAQsFAAOCAQEAeVJfWuM9NHl2+3K+szxDlLh3BGaPCXFcPNr1h17A
FmzCnU1s8+jIpzbnXZUBGSexFFJmpJJpf7IwyLu/RdPh8o1L4NfU+tslOQJ0JR84
r6OOF895XEbdkvDCAxEE1qCEWryEJCyGQMtcD9BC2Slr1MUlDswtPr875Nk4gbpU
VJEgVNqE8WtImQldhxeZwLfyMTk7BbuED7Hyd96InqRYftMqro7ELIXgZv3bkyqj
jaGapTmrQ89tACoS3BbPLKgLUvbfsv1h+fOUAGDff4FoXg81IxkoFzRiUC9Za7PW
WJWJI0rTZIPKkfcsgN7k3GmCMjek/WK3mI3E5RtehhtKHQ==
-----END CERTIFICATE-----
 1 s:/C=US/O=Let's Encrypt/CN=R3
   i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
-----BEGIN CERTIFICATE-----
MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw
WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg
RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP
R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx
sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm
NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg
Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG
/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC
AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB
Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA
FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw
AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw
Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB
gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W
PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl
ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz
CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm
lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4
avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2
yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O
yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids
hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+
HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv
MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX
nLRbwHOoq7hHwg==
-----END CERTIFICATE-----
 2 s:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
   i:/O=Digital Signature Trust Co./CN=DST Root CA X3
-----BEGIN CERTIFICATE-----
MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/
MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
DkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1ow
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEB
AQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XC
ov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpL
wYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+D
LtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK
4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5
bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5y
sR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZ
Xmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4
FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBc
SLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2ql
PRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TND
TwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYw
SwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1
c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx
+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEB
ATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQu
b3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9E
U1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26Ztu
MA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC
5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW
9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuG
WCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9O
he8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFC
Dfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5
-----END CERTIFICATE-----
---
Server certificate
subject=/CN=metro.co.uk
issuer=/C=US/O=Let's Encrypt/CN=R3
---
No client certificate CA names sent
Peer signing digest: SHA256
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 5195 bytes and written 290 bytes
Verification: OK
---
New, TLSv1.2, Cipher is ECDHE-RSA-CHACHA20-POLY1305
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-CHACHA20-POLY1305
    Session-ID: 905E5F2BB93F398D27748C15190213EA9E7978D3B1827F7E0EB23CB303DE1EB7
    Session-ID-ctx: 
    Master-Key: 3AAC0C431252AF4742448BDB75DFAE0FDC4897BF8E7CA2DA48285E2CFA5DC786F1DE3FF01FCC2B6D2C6B649BB1478712
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 3600 (seconds)
    TLS session ticket:
    0000 - 12 5d 05 3a 74 94 86 14-04 e7 8d 75 26 13 19 ae   .].:t......u&...
    0010 - 50 a2 15 2d c3 46 19 b8-db d1 f3 fd c3 e3 d9 c7   P..-.F..........
    0020 - 76 4d 2b ba c0 1e 4d 25-6f ac 79 da d0 2c 3d ef   vM+...M%o.y..,=.
    0030 - b5 aa 8e d7 59 ae 72 4b-7e 53 4e 42 77 92 ab 5e   ....Y.rK~SNBw..^
    0040 - 94 ab 9c f2 0d 2a f6 c4-4b 66 60 a0 65 14 ba 69   .....*..Kf`.e..i
    0050 - ef 2e 36 2e a2 fb bd dc-bb f6 f5 3d 7d 8f 92 96   ..6........=}...
    0060 - 59 29 a6 61 13 8e 40 d8-a7 67 1f 07 00 9c e0 28   Y).a..@..g.....(
    0070 - b2 fd fb ac 3b e9 c3 8f-90 cb 74 e6 39 0a 91 b5   ....;.....t.9...
    0080 - 21 dd f8 a8 d0 16 93 e9-9b cb 02 95 43 2e 4d 9c   !...........C.M.
    0090 - d8 6b 23 91 12 dc 77 0b-86 90 88 b3 e1 2f 3c 71   .k#...w....../<q
    00a0 - 44 f4 71 cd a6 34 fc a3-04 62 c4 be 29 ec f9 35   D.q..4...b..)..5
    00b0 - 0c d7 62 9b 14 ba 32 f6-b3 8e 6d 6a de 48 ad d3   ..b...2...mj.H..

    Start Time: 1638772212
    Timeout   : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: yes
---
DONE