Namecheap.com

SSL Checker

Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.

Report

Hostname: Matches Common Name or/and SAN
Expired: No (78 days till expiration)
Public Key: We were unable to find any issues in the public key of end-entity certificate
Trusted: We were unable to verify this certificate
Self-Signed: No, the end-entity certificate is not self-signed
Chain Issues: No, we were unable to detect any issues in the certificate chain sent by the server
Weak signatures: No, certificates sent by the server were not signed utilizing a weak hash function
OCSP Status: OCSP Responder returned "good" status for the end-entity certificate

DNS Information

Resolves To: 107.20.176.212
Reverse IP lookup: ec2-107-20-176-212.compute-1.amazonaws.com.
Nameserver: ns1.ny.gov.
Nameserver: ns0.ny.gov.
Nameserver: ns2.ny.gov.

General Information

Common Name: *.ny.gov
SANs: DNS:*.ny.govDNS:bsc.ogs.ny.govDNS:coronavirus.health.ny.govDNS:covid19.health.ny.govDNS:covid19vaccine.health.ny.govDNS:data.labor.ny.govDNS:edit.nylottery.ny.govDNS:knowledgebank.criminaljustice.ny.govDNS:locallaws.dos.ny.govDNS:webapps.dot.ny.govDNS:www.agriculture.ny.govDNS:www.alert.ny.govDNS:www.amber.ny.govDNS:www.arts.ny.govDNS:www.bfsa.ny.govDNS:www.bsc.ogs.ny.govDNS:www.campaignfinancereform.ny.govDNS:www.collegegoal.ny.govDNS:www.coronavirus.health.ny.govDNS:www.covid19vaccine.health.ny.govDNS:www.ddpc.ny.govDNS:www.dfs.ny.govDNS:www.dhr.ny.govDNS:www.dhses.ny.govDNS:www.dmv.ny.govDNS:www.doccs.ny.govDNS:www.dos.ny.govDNS:www.dps.ny.govDNS:www.efc.ny.govDNS:www.empirestateplaza.ny.govDNS:www.esd.ny.govDNS:www.gearup.ny.govDNS:www.goer.ny.govDNS:www.governor.ny.govDNS:www.grantsmanagement.ny.govDNS:www.hcr.ny.govDNS:www.hudsongreenway.ny.govDNS:www.ig.ny.govDNS:www.industrialappeals.ny.govDNS:www.its.ny.govDNS:www.joinstatepolice.ny.govDNS:www.justicecenter.ny.govDNS:www.knowledgebank.criminaljustice.ny.govDNS:www.labor.ny.govDNS:www.lgpc.ny.govDNS:www.locallaws.dos.ny.govDNS:www.mariomcuomobridge.ny.govDNS:www.newyorkersvolunteer.ny.govDNS:www.oasas.ny.govDNS:www.ogs.ny.govDNS:www.omig.ny.govDNS:www.opdv.ny.govDNS:www.opwdd.ny.govDNS:www.ores.ny.govDNS:www.ovs.ny.govDNS:www.paidfamilyleave.ny.govDNS:www.policereform.ny.govDNS:www.regionalcouncils.ny.govDNS:www.sla.ny.govDNS:www.startheregetthere.ny.govDNS:www.stormrecovery.ny.govDNS:www.taste.ny.govDNS:www.troopers.ny.govDNS:www.uiappeals.ny.govDNS:www.veterans.ny.govDNS:www.woodproducts.ny.govDNS:www.youthincare.ny.govDNS:www.nics.ny.govDNS:www.nyess.ny.govDNS:boards.criminaljustice.ny.govDNS:www.scoc.ny.govDNS:www.dec.ny.govDNS:www.deferredcompboard.ny.govDNS:www.ecfsa.ny.govDNS:www.aging.ny.govDNS:ny.gov Total number of SANs: 76
Organization: New York State Office of Information Technology Services
Locality: Albany
Signature Algorithm: sha256WithRSAEncryption
Key Type: RSA
Key size: 2048 bits
Serial Number: 319b0ed8be68c84a0d8473e2
Not Before: Dec 01, 2023 14:54:03 GMT
Not After: Jul 07, 2024 17:56:12 GMT
Number of certs: 2
Revocation Status: good
OCSP Stapling: Not Supported
Server: nginx
HSTS: Not Supported
HPKP: Not Supported

Chain Information

Certificate # 1 - Common Name: *.ny.gov

Decode this certificate for verbose information →
Subject Common Name *.ny.gov
Subject Organization New York State Office of Information Technology Services
Issuer Common Name GlobalSign RSA OV SSL CA 2018
Issuer Organization GlobalSign nv-sa
Not Before: Dec 01, 2023 14:54:03 GMT
Not After: Jul 07, 2024 17:56:12 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 319b0ed8be68c84a0d8473e2
SHA1 Fingerprint: DC:DD:BD:3E:09:EE:4F:CC:E3:F8:38:15:F6:1D:79:F5:A5:6A:F1:86
MD5 Fingerprint: B4:05:EB:BF:A1:87:04:53:68:0A:F8:EF:A1:B3:BF:37

Certificate # 2 - Common Name: GlobalSign RSA OV SSL CA 2018

Decode this certificate for verbose information →
In place? Yes, this certificate directly certifies the preceding one
Subject Common Name GlobalSign RSA OV SSL CA 2018
Subject Organization GlobalSign nv-sa
Issuer Common Name GlobalSign
Issuer Organization GlobalSign
Not Before: Nov 21, 2018 00:00:00 GMT
Not After: Nov 21, 2028 00:00:00 GMT
Signature Algorithm: sha256WithRSAEncryption
Serial Number: 1ee5f221dfc623bd4333a8557
SHA1 Fingerprint: DF:E8:30:23:06:2B:99:76:82:70:8B:4E:AB:8E:81:9A:FF:5D:97:75
MD5 Fingerprint: A7:5D:8B:21:09:11:EE:17:3E:FD:25:E1:E0:0E:D6:FD

OpenSSL Handshake

depth=1 C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 C = US, ST = New York, L = Albany, O = New York State Office of Information Technology Services, CN = *.ny.gov
verify return:1
CONNECTED(00000003)
OCSP response: no response sent
---
Certificate chain
 0 s:C = US, ST = New York, L = Albany, O = New York State Office of Information Technology Services, CN = *.ny.gov
   i:C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
-----BEGIN CERTIFICATE-----
MIINDDCCC/SgAwIBAgIMMZsO2L5oyEoNhHPiMA0GCSqGSIb3DQEBCwUAMFAxCzAJ
BgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1H
bG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yMzEyMDExNDU0MDNaFw0y
NDA3MDcxNzU2MTJaMIGHMQswCQYDVQQGEwJVUzERMA8GA1UECBMITmV3IFlvcmsx
DzANBgNVBAcTBkFsYmFueTFBMD8GA1UEChM4TmV3IFlvcmsgU3RhdGUgT2ZmaWNl
IG9mIEluZm9ybWF0aW9uIFRlY2hub2xvZ3kgU2VydmljZXMxETAPBgNVBAMMCCou
bnkuZ292MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxdohhdZ2ZSmi
9G4+gyuX05KV28EqzXhXVJ/xH0JjdsOlqiEHs8rvq87YauC6mjcUujIQt81DRobZ
/jhjo4RXa7BF+hVRzIbpfG780kK1oQO8CtawItfEZMayQXAtQS10oVwhi7kuq6Re
+1h/ymm7zxUpMob20iKIGGIydca2HGhG40cqsPMuY9niUVNnp1rk5F0FmuJcUCDw
vDJxI+WPRwhUQbJ9LTYVh26C0XO/jl+u6xig0V1Lc4JlBe0fphENMXSG91H0hEOU
u3p1gJObxuiJREjbrjS0+0mOq0ybnsYvYjTAt6dDb4xWPRuUnxV5sKJMENOJAo5h
iKqW+Iu24QIDAQABo4IJrDCCCagwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQC
MAAwgY4GCCsGAQUFBwEBBIGBMH8wRAYIKwYBBQUHMAKGOGh0dHA6Ly9zZWN1cmUu
Z2xvYmFsc2lnbi5jb20vY2FjZXJ0L2dzcnNhb3Zzc2xjYTIwMTguY3J0MDcGCCsG
AQUFBzABhitodHRwOi8vb2NzcC5nbG9iYWxzaWduLmNvbS9nc3JzYW92c3NsY2Ey
MDE4MFYGA1UdIARPME0wQQYJKwYBBAGgMgEUMDQwMgYIKwYBBQUHAgEWJmh0dHBz
Oi8vd3d3Lmdsb2JhbHNpZ24uY29tL3JlcG9zaXRvcnkvMAgGBmeBDAECAjA/BgNV
HR8EODA2MDSgMqAwhi5odHRwOi8vY3JsLmdsb2JhbHNpZ24uY29tL2dzcnNhb3Zz
c2xjYTIwMTguY3JsMIIGegYDVR0RBIIGcTCCBm2CCCoubnkuZ292gg5ic2Mub2dz
Lm55LmdvdoIZY29yb25hdmlydXMuaGVhbHRoLm55LmdvdoIVY292aWQxOS5oZWFs
dGgubnkuZ292ghxjb3ZpZDE5dmFjY2luZS5oZWFsdGgubnkuZ292ghFkYXRhLmxh
Ym9yLm55LmdvdoIVZWRpdC5ueWxvdHRlcnkubnkuZ292giRrbm93bGVkZ2ViYW5r
LmNyaW1pbmFsanVzdGljZS5ueS5nb3aCFGxvY2FsbGF3cy5kb3MubnkuZ292ghJ3
ZWJhcHBzLmRvdC5ueS5nb3aCFnd3dy5hZ3JpY3VsdHVyZS5ueS5nb3aCEHd3dy5h
bGVydC5ueS5nb3aCEHd3dy5hbWJlci5ueS5nb3aCD3d3dy5hcnRzLm55LmdvdoIP
d3d3LmJmc2EubnkuZ292ghJ3d3cuYnNjLm9ncy5ueS5nb3aCIHd3dy5jYW1wYWln
bmZpbmFuY2VyZWZvcm0ubnkuZ292ghZ3d3cuY29sbGVnZWdvYWwubnkuZ292gh13
d3cuY29yb25hdmlydXMuaGVhbHRoLm55LmdvdoIgd3d3LmNvdmlkMTl2YWNjaW5l
LmhlYWx0aC5ueS5nb3aCD3d3dy5kZHBjLm55LmdvdoIOd3d3LmRmcy5ueS5nb3aC
Dnd3dy5kaHIubnkuZ292ghB3d3cuZGhzZXMubnkuZ292gg53d3cuZG12Lm55Lmdv
doIQd3d3LmRvY2NzLm55LmdvdoIOd3d3LmRvcy5ueS5nb3aCDnd3dy5kcHMubnku
Z292gg53d3cuZWZjLm55LmdvdoIbd3d3LmVtcGlyZXN0YXRlcGxhemEubnkuZ292
gg53d3cuZXNkLm55LmdvdoIRd3d3LmdlYXJ1cC5ueS5nb3aCD3d3dy5nb2VyLm55
LmdvdoITd3d3LmdvdmVybm9yLm55LmdvdoIbd3d3LmdyYW50c21hbmFnZW1lbnQu
bnkuZ292gg53d3cuaGNyLm55LmdvdoIZd3d3Lmh1ZHNvbmdyZWVud2F5Lm55Lmdv
doINd3d3LmlnLm55LmdvdoIcd3d3LmluZHVzdHJpYWxhcHBlYWxzLm55LmdvdoIO
d3d3Lml0cy5ueS5nb3aCGnd3dy5qb2luc3RhdGVwb2xpY2UubnkuZ292ghh3d3cu
anVzdGljZWNlbnRlci5ueS5nb3aCKHd3dy5rbm93bGVkZ2ViYW5rLmNyaW1pbmFs
anVzdGljZS5ueS5nb3aCEHd3dy5sYWJvci5ueS5nb3aCD3d3dy5sZ3BjLm55Lmdv
doIYd3d3LmxvY2FsbGF3cy5kb3MubnkuZ292ghx3d3cubWFyaW9tY3VvbW9icmlk
Z2UubnkuZ292gh53d3cubmV3eW9ya2Vyc3ZvbHVudGVlci5ueS5nb3aCEHd3dy5v
YXNhcy5ueS5nb3aCDnd3dy5vZ3MubnkuZ292gg93d3cub21pZy5ueS5nb3aCD3d3
dy5vcGR2Lm55LmdvdoIQd3d3Lm9wd2RkLm55LmdvdoIPd3d3Lm9yZXMubnkuZ292
gg53d3cub3ZzLm55LmdvdoIad3d3LnBhaWRmYW1pbHlsZWF2ZS5ueS5nb3aCF3d3
dy5wb2xpY2VyZWZvcm0ubnkuZ292ght3d3cucmVnaW9uYWxjb3VuY2lscy5ueS5n
b3aCDnd3dy5zbGEubnkuZ292ghx3d3cuc3RhcnRoZXJlZ2V0dGhlcmUubnkuZ292
ghh3d3cuc3Rvcm1yZWNvdmVyeS5ueS5nb3aCEHd3dy50YXN0ZS5ueS5nb3aCE3d3
dy50cm9vcGVycy5ueS5nb3aCFHd3dy51aWFwcGVhbHMubnkuZ292ghN3d3cudmV0
ZXJhbnMubnkuZ292ghd3d3cud29vZHByb2R1Y3RzLm55LmdvdoIWd3d3LnlvdXRo
aW5jYXJlLm55LmdvdoIPd3d3Lm5pY3MubnkuZ292ghB3d3cubnllc3MubnkuZ292
gh1ib2FyZHMuY3JpbWluYWxqdXN0aWNlLm55LmdvdoIPd3d3LnNjb2MubnkuZ292
gg53d3cuZGVjLm55LmdvdoIcd3d3LmRlZmVycmVkY29tcGJvYXJkLm55LmdvdoIQ
d3d3LmVjZnNhLm55LmdvdoIQd3d3LmFnaW5nLm55LmdvdoIGbnkuZ292MB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAfBgNVHSMEGDAWgBT473/yzXhnqN5v
jySNiPGHAwKz6zAdBgNVHQ4EFgQUAYHjt5XVkOqsoXO/Djz+/8++jk4wggF/Bgor
BgEEAdZ5AgQCBIIBbwSCAWsBaQB2AD8XS0/XIkdYlB1lHIS+DRLtkDd/H4Vq68G/
KIXs+GRuAAABjCXfdpQAAAQDAEcwRQIhAOh7fDNOZ/7KT8RTbQQod2eAX1vHKb1G
N61YWgL4YsJyAiAglTvdRcxJJQ5Q0Rh/4htMvoyVG7RmCiGPrbgOjaSMowB2ABmY
EHEJ8NZSLjCA0p4/ZLuDbijM+Q9Sju7fzko/FrTKAAABjCXfd2EAAAQDAEcwRQIh
APBQjBDB/y5yYvtFJcfe0e1qI4bIXjLoKe/EX51gsE2TAiArQUJA6bxMgizwgXwW
aivjaiXD6dVqZPEY6vfxUhJG9AB3AO7N0GTV2xrOxVy3nbTNE6Iyh0Z8vOzew1FI
WUZxH7WbAAABjCXfd48AAAQDAEgwRgIhALZkh5WohRT2AadBcrn+2QfXQayrqrHr
5A/gUnTue6hKAiEA7BoBp2M113wtrjH+ypf7eg455uPA5A2VbauAq+QAXDQwDQYJ
KoZIhvcNAQELBQADggEBADBGQEF3pjwRSNPkNSh2MWo+CTy3Qw4F3LcGUXryQAL3
fZmJnnIEfseKU3/NcmpxyldJ3dk7AOLHp20mA5rtkGxx+UBKJAVTE4gYJi9Y2hZk
WSAlgxD0Y7AVOxauYpxSNI3jH+gWrj8+sb4FAn3uR5kmnLaZ2vr+AzYIRoovFT2J
BXoMbkU6CAqRhfnuFxr0xqbQU8JWksId4irNH/1U4dkry7Ro2qsS9BLYlIkJHayj
x3svDwBvbezwV5dZ3K1Ezv6E9IcrxNGygrlJ85jwGL6fkpZsk5/ms36tCKS457Wu
14nsVw1+t+EHDRBz9+hKStHpC6EFC65BJJ7Y5LxDpww=
-----END CERTIFICATE-----
 1 s:C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
   i:OU = GlobalSign Root CA - R3, O = GlobalSign, CN = GlobalSign
-----BEGIN CERTIFICATE-----
MIIETjCCAzagAwIBAgINAe5fIh38YjvUMzqFVzANBgkqhkiG9w0BAQsFADBMMSAw
HgYDVQQLExdHbG9iYWxTaWduIFJvb3QgQ0EgLSBSMzETMBEGA1UEChMKR2xvYmFs
U2lnbjETMBEGA1UEAxMKR2xvYmFsU2lnbjAeFw0xODExMjEwMDAwMDBaFw0yODEx
MjEwMDAwMDBaMFAxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52
LXNhMSYwJAYDVQQDEx1HbG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKdaydUMGCEAI9WXD+uu3Vxoa2uP
UGATeoHLl+6OimGUSyZ59gSnKvuk2la77qCk8HuKf1UfR5NhDW5xUTolJAgvjOH3
idaSz6+zpz8w7bXfIa7+9UQX/dhj2S/TgVprX9NHsKzyqzskeU8fxy7quRU6fBhM
abO1IFkJXinDY+YuRluqlJBJDrnw9UqhCS98NE3QvADFBlV5Bs6i0BDxSEPouVq1
lVW9MdIbPYa+oewNEtssmSStR8JvA+Z6cLVwzM0nLKWMjsIYPJLJLnNvBhBWk0Cq
o8VS++XFBdZpaFwGue5RieGKDkFNm5KQConpFmvv73W+eka440eKHRwup08CAwEA
AaOCASkwggElMA4GA1UdDwEB/wQEAwIBhjASBgNVHRMBAf8ECDAGAQH/AgEAMB0G
A1UdDgQWBBT473/yzXhnqN5vjySNiPGHAwKz6zAfBgNVHSMEGDAWgBSP8Et/qC5F
JK5NUPpjmove4t0bvDA+BggrBgEFBQcBAQQyMDAwLgYIKwYBBQUHMAGGImh0dHA6
Ly9vY3NwMi5nbG9iYWxzaWduLmNvbS9yb290cjMwNgYDVR0fBC8wLTAroCmgJ4Yl
aHR0cDovL2NybC5nbG9iYWxzaWduLmNvbS9yb290LXIzLmNybDBHBgNVHSAEQDA+
MDwGBFUdIAAwNDAyBggrBgEFBQcCARYmaHR0cHM6Ly93d3cuZ2xvYmFsc2lnbi5j
b20vcmVwb3NpdG9yeS8wDQYJKoZIhvcNAQELBQADggEBAJmQyC1fQorUC2bbmANz
EdSIhlIoU4r7rd/9c446ZwTbw1MUcBQJfMPg+NccmBqixD7b6QDjynCy8SIwIVbb
0615XoFYC20UgDX1b10d65pHBf9ZjQCxQNqQmJYaumxtf4z1s4DfjGRzNpZ5eWl0
6r/4ngGPoJVpjemEuunl1Ig423g7mNA2eymw0lIYkN5SQwCuaifIFJ6GlazhgDEw
fpolu4usBCOmmQDo8dIm7A9+O4orkjgTHY+GzYZSR+Y0fFukAj6KYXwidlNalFMz
hriSqHKvoflShx8xpfywgVcvzfTO3PYkz6fiNJBonf6q8amaEsybwMbDqKWwIX7e
SPY=
-----END CERTIFICATE-----
---
Server certificate
subject=C = US, ST = New York, L = Albany, O = New York State Office of Information Technology Services, CN = *.ny.gov

issuer=C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018

---
No client certificate CA names sent
Peer signing digest: SHA512
Peer signature type: RSA
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 5143 bytes and written 443 bytes
Verification error: unable to get local issuer certificate
---
New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES128-GCM-SHA256
    Session-ID: 1FB5E74A596ADE7C03E47548E7F255A38AC71F2FB1BF57EE0BB0B330C57CA338
    Session-ID-ctx: 
    Master-Key: 3CF352B9D5D2FBC9284D9952E5DAC07C31C1AA4A286B88850620093B27ACF50FBFA603FE09C48AF9DBE3E8510423071F
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 600 (seconds)
    TLS session ticket:
    0000 - c7 55 46 18 51 7f bf ce-19 b1 19 ad 0b 87 16 20   .UF.Q.......... 
    0010 - 79 ec a0 b5 06 97 a9 d9-ae 44 91 83 e4 5f 2e ef   y........D..._..
    0020 - eb cb 47 65 50 7f a7 d4-43 f8 f3 09 ad 81 cd f6   ..GeP...C.......
    0030 - 27 ab 5e ec 5a a8 c9 7b-ec ba 1d 16 18 0f ef b7   '.^.Z..{........
    0040 - c1 d4 93 13 ca ea c8 2f-fb dc 6c f5 c6 c8 d0 9a   ......./..l.....
    0050 - 80 de 26 c5 50 b1 96 f7-f2 1b e1 72 72 89 02 e0   ..&.P......rr...
    0060 - bd c5 85 b8 2e 88 18 ce-ec e9 cc 8b 20 34 8e ce   ............ 4..
    0070 - 2a f3 df 44 e9 7b 44 fa-a2 f2 67 92 9f 59 fc ef   *..D.{D...g..Y..
    0080 - 13 22 ea de 8a 38 ee 77-8e 17 24 0a b2 1e 9d 00   ."...8.w..$.....
    0090 - 35 78 0d a8 59 26 21 7b-62 78 90 ae 19 58 87 f6   5x..Y&!{bx...X..
    00a0 - f4 bc b5 b4 e1 46 35 9d-4c 7e f6 9b 21 f3 6d 15   .....F5.L~..!.m.
    00b0 - b3 2f 08 d4 78 02 af 6b-ee 0b 34 1b 9d 47 03 4e   ./..x..k..4..G.N

    Start Time: 1713625690
    Timeout   : 7200 (sec)
    Verify return code: 20 (unable to get local issuer certificate)
    Extended master secret: no
---
DONE