SSL Checker
Submit the Hostname and Port in the fields below. This checker supports SNI and STARTTLS.
Report
It's all good. We have not detected any issues.
Hostname: | done Matches Common Name or/and SAN |
Expired: | done No (56 days till expiration) |
Public Key: | done We were unable to find any issues in the public key of end-entity certificate |
Trusted: | done Yes, we were able to verify the certificate |
Self-Signed: | done No, the end-entity certificate is not self-signed |
Chain Issues: | done No, we were unable to detect any issues in the certificate chain sent by the server |
Weak signatures: | done No, certificates sent by the server were not signed utilizing a weak hash function |
OCSP Status: | done OCSP Responder returned "good" status for the end-entity certificate |
DNS Information
Resolves To: | 185.50.52.200 |
Reverse IP lookup: | mini5.noma.fr. |
Nameserver: | dns102.ovh.net. |
Nameserver: | ns102.ovh.net. |
General Information
Common Name: | ophtalink.fr |
SANs: | DNS:ophtalink.comDNS:ophtalink.frDNS:www.ophtalink.comDNS:www.ophtalink.fr Total number of SANs: 4 |
Signature Algorithm: | sha256WithRSAEncryption |
Key Type: | ECDSA (secp256r1) |
Key size: | 256 bits |
Serial Number: | 304f2fb7fb05591f88efffb96489d62b8af |
Not Before: | Mar 24, 2024 05:47:08 GMT |
Not After: | Jun 22, 2024 05:47:07 GMT |
Number of certs: | 2 |
Revocation Status: | good |
OCSP Stapling: | Supported |
Server: | Apache/2.4.58 (Unix) OpenSSL/3.2.1 |
HSTS: | Not Supported |
HPKP: | Not Supported |
Chain Information
Certificate # 1 - Common Name: ophtalink.fr
Decode this certificate for verbose information → launchSubject Common Name | ophtalink.fr |
Issuer Common Name | R3 |
Issuer Organization | Let's Encrypt |
Not Before: | Mar 24, 2024 05:47:08 GMT |
Not After: | Jun 22, 2024 05:47:07 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 304f2fb7fb05591f88efffb96489d62b8af |
SHA1 Fingerprint: | B1:90:B0:D6:31:2A:3C:BA:86:D6:9C:53:02:60:74:9A:F8:8B:24:E5 |
MD5 Fingerprint: | 42:6E:43:99:7C:50:F8:33:71:C7:07:60:8E:E0:A7:C7 |
Certificate # 2 - Common Name: R3
Decode this certificate for verbose information → launchIn place? | Yes, this certificate directly certifies the preceding one |
Subject Common Name | R3 |
Subject Organization | Let's Encrypt |
Issuer Common Name | ISRG Root X1 |
Issuer Organization | Internet Security Research Group |
Not Before: | Sep 04, 2020 00:00:00 GMT |
Not After: | Sep 15, 2025 16:00:00 GMT |
Signature Algorithm: | sha256WithRSAEncryption |
Serial Number: | 912b084acf0c18a753f6d62e25a75f5a |
SHA1 Fingerprint: | A0:53:37:5B:FE:84:E8:B7:48:78:2C:7C:EE:15:82:7A:6A:F5:A4:05 |
MD5 Fingerprint: | E8:29:E6:5D:7C:43:07:D6:FB:C1:3C:17:9E:03:7A:36 |
OpenSSL Handshake
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1 verify return:1 depth=1 C = US, O = Let's Encrypt, CN = R3 verify return:1 depth=0 CN = ophtalink.fr verify return:1 CONNECTED(00000003) OCSP response: ====================================== OCSP Response Data: OCSP Response Status: successful (0x0) Response Type: Basic OCSP Response Version: 1 (0x0) Responder Id: C = US, O = Let's Encrypt, CN = R3 Produced At: Apr 25 11:00:00 2024 GMT Responses: Certificate ID: Hash Algorithm: sha1 Issuer Name Hash: 48DAC9A0FB2BD32D4FF0DE68D2F567B735F9B3C4 Issuer Key Hash: 142EB317B75856CBAE500940E61FAF9D8B14C2C6 Serial Number: 0304F2FB7FB05591F88EFFFB96489D62B8AF Cert Status: good This Update: Apr 25 11:00:00 2024 GMT Next Update: May 2 10:59:58 2024 GMT Signature Algorithm: sha256WithRSAEncryption 5f:9e:5a:cc:5d:aa:7c:3e:fe:52:0f:96:ae:61:88:30:43:dd: 84:ef:a8:bc:a8:5c:c6:05:29:f5:d2:76:33:c4:04:cf:f3:db: 49:bc:d3:82:b0:47:71:10:70:42:22:77:ec:17:ab:6b:80:a0: 5f:cc:7d:a5:ad:40:a5:c9:53:b5:2f:ab:b7:64:c8:81:5c:5d: 06:33:dd:cd:c4:cf:7a:b4:63:d7:26:5f:7b:03:74:60:98:65: 31:08:a2:a8:75:67:33:e1:8e:ef:05:29:cd:76:cd:f3:a1:ca: 47:05:ce:f5:db:77:e3:00:e1:0c:87:0b:4c:9e:a9:7b:70:62: e9:39:5a:f1:ad:be:71:8c:08:da:0c:ba:82:45:02:23:50:50: 4c:c6:90:9e:9c:0a:52:d1:17:e9:e1:c1:d4:d7:ec:55:3d:2e: 3f:70:d5:71:ce:dd:50:6f:3a:ba:d8:e5:00:c1:4c:7a:2e:35: d1:b2:32:e1:cd:aa:4d:a6:63:7b:d6:db:7a:d0:67:fb:08:40: 47:90:30:25:a6:29:88:c7:b0:cd:aa:35:f7:3b:d7:05:1f:b7: 54:3a:1d:38:70:f0:42:63:54:ac:41:00:cc:7c:56:ec:7d:21: d2:b3:53:87:0e:6f:64:bf:a5:ae:48:32:a8:a2:94:0b:00:c1: b4:2a:2d:30 ====================================== --- Certificate chain 0 s:CN = ophtalink.fr i:C = US, O = Let's Encrypt, CN = R3 -----BEGIN CERTIFICATE----- MIIETzCCAzegAwIBAgISAwTy+3+wVZH4jv/7lkidYrivMA0GCSqGSIb3DQEBCwUA MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD EwJSMzAeFw0yNDAzMjQwNTQ3MDhaFw0yNDA2MjIwNTQ3MDdaMBcxFTATBgNVBAMT DG9waHRhbGluay5mcjBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMW/79yxpyBx rKM2pfy7OE7gnNYhuF0vPAQALfiJHve5EJd0um1RJF/Ov+XWTACSG78+wgngX8I7 UfRxdue2QDejggJDMIICPzAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYB BQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFPfY730QlJ4P ua1aVG2QJzptEHwJMB8GA1UdIwQYMBaAFBQusxe3WFbLrlAJQOYfr52LFMLGMFUG CCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0cDovL3IzLm8ubGVuY3Iub3Jn MCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5jci5vcmcvMEsGA1UdEQREMEKC DW9waHRhbGluay5jb22CDG9waHRhbGluay5mcoIRd3d3Lm9waHRhbGluay5jb22C EHd3dy5vcGh0YWxpbmsuZnIwEwYDVR0gBAwwCjAIBgZngQwBAgEwggEFBgorBgEE AdZ5AgQCBIH2BIHzAPEAdgA/F0tP1yJHWJQdZRyEvg0S7ZA3fx+FauvBvyiF7Phk bgAAAY5vNojgAAAEAwBHMEUCIGYZ7Alo4Ljw+v7BpjrfCnE0Dvwi+5xExoJNVMn5 9eXfAiEA+Ju+Lx7v+Hfy1A4/2V8nph0QkFNaZ+yoP6XlIuH0XKUAdwCi4r/WHt4v Lweg1k5tN6fcZUOwxrUuotq3iviabfUX2AAAAY5vNojoAAAEAwBIMEYCIQCKNSf5 uQzMbOeDcVDeOKKTfuxD+xne/RtANrvYS9dwowIhALWnbr9rWDb2ksLg/+nYKfks Matc2FpQGTza99HbpCMNMA0GCSqGSIb3DQEBCwUAA4IBAQBcwcshU3mepsPr1+ya /G9sCytv+uxr+S4NqaEyvJGb34lhtAE4TfP4DDY1h8cR+CcdpWk14ys5WGacJDBA c9cYzXYaq7kK2sVNAzluPk1Vm6Oc/6gQ7l9O8jHqIChcsvxHZJbR31EaLPQMt4b/ M3nFQJWiOR3ncc/zv7mRv/3O3Qlrah0bHvypWgBUhdV0yTYWl/yiwoXqxg0+lL11 JTW/5NUWYgCmiXDlsaxvLPyWmhGHIQ2gk7iQ5FJcZDGgSrY/DOujBkZCNRzL4vlM JN4hU8PVcvh7ZxMjoFxhj+OeRKWS+KlghtZli8Rwq2MwVeDxzyBkhzTDDLJijvt6 YOie -----END CERTIFICATE----- 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1 -----BEGIN CERTIFICATE----- MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG /kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4 avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2 yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+ HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX nLRbwHOoq7hHwg== -----END CERTIFICATE----- --- Server certificate subject=CN = ophtalink.fr issuer=C = US, O = Let's Encrypt, CN = R3 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: ECDSA Server Temp Key: X25519, 253 bits --- SSL handshake has read 3233 bytes and written 417 bytes Verification: OK --- New, TLSv1.2, Cipher is ECDHE-ECDSA-AES256-GCM-SHA384 Server public key is 256 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-ECDSA-AES256-GCM-SHA384 Session-ID: 5FD04D90B9E45C14FD54C6E8E3876CDA6960ABCB92DD0C5B9B520713D564EC0F Session-ID-ctx: Master-Key: 74E88EB41B0B194693296F99586548F8646E73F711E29E6CBD213369740792EDAD953BA221088410A9FDE66F2E656B4A PSK identity: None PSK identity hint: None SRP username: None Start Time: 1714138972 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: yes --- DONE