sso.citrix.com, 23.29.105.149:443

TLS Test Results from June 05 2023 19:50:50 UTC. Scan took 179 seconds.

Summary

Finding Severity Result
HTTP Status Code WARN Unexpected 503 Service Unavailable @ '/'
Secure Renegotiation CRITICAL VULNERABLE
OCSP Revoked WARN
TLS 1.2 OK offered
TLS 1.3 INFO not offered + downgraded to weaker protocol
Perfect Forward Secrecy OK offered
Common Name (CN) OK *.citrix.com
Subject Alternative Name (SAN) INFO
  • *.citrix.com
  • *.citrix.de
  • *.cloud.com
  • *.sharefile.com
  • *.citrixonline.com
  • *.citrix.com.au
  • *.citrix.co.uk
  • citrix.com
  • cloud.com
  • citrixonline.com
  • citrix.com.au
  • citrix.co.uk
  • citrix.de
  • sharefile.com
CA Issuers INFO DigiCert TLS RSA SHA256 2020 CA1 (DigiCert Inc from US)
Valid Not After OK 2023-12-19 23:59

Protocols

Version Status
SSL v2 not offered
SSL v3 not offered
TLS 1.0 offered (deprecated)
TLS 1.1 offered (deprecated)
TLS 1.2 offered
TLS 1.3 not offered + downgraded to weaker protocol
ALPN / HTTP2 http/1.1

Cipher Categories

Category Status
NULL ciphers (no encryption) not offered
Anonymous NULL Ciphers (no authentication) not offered
Export ciphers (excluding ADH+NULL) not offered
LOW: 64 Bit + DES, RC[2,4] (excluding export) not offered
Triple DES Ciphers / IDEA not offered
Obsolete CBC ciphers (AES, ARIA etc.) offered
Strong encryption (AEAD ciphers) offered

Perfect Forward Secrecy

Category Status
Perfect Forward Secrecy offered
PFS Ciphers
  • ECDHE-RSA-AES128-GCM-SHA256
  • ECDHE-RSA-AES128-SHA256
  • ECDHE-RSA-AES128-SHA
  • ECDHE-RSA-AES256-GCM-SHA384
  • ECDHE-RSA-AES256-SHA384
  • ECDHE-RSA-AES256-SHA
PFS ECDHE Curves
  • secp224r1
  • prime256v1
  • secp384r1
  • secp521r1

Server Preferences

Category Finding
Cipher Order server
Protocol Negotiated Default protocol TLS1.2
Cipher Negotiated AES256-SHA (cbc)
Cipher Order TLS v1.0 AES256-SHA
Cipher Order TLS v1.1 AES256-SHA
Cipher Order TLS v1.2 AES256-SHA

Server Defaults

Category Finding
TLS Extensions
  • EC point formats/#11
  • application layer protocol negotiation/#16
TLS Session Ticket no -- no lifetime advertised
SSL Session-ID Support yes
Session Resumption Ticket not supported
Session Resumption ID supported
TLS Timestamp off by -120 seconds from your localtime
Number of Certificates 1

Certificate

Category Finding
Signature Algorithm SHA256 with RSA
Key Size RSA 2048 bits
Key Usage
  • Digital Signature
  • Key Encipherment
Extended Key Usage
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Serial Number 06D605E4383BAC22B2C6B464BEB71FC9
SHA1 Fingerprint 64439F7B2DAEE8A8C1C96FB2D3836B1F7DF1F713
SHA256 Fingerprint 9BF00393C33F5CFC353CFE4896800094E4A95A46D6ED932EE6C190CE9CCC2E24
X.509 Certificate Download sso.citrix.com_443_64439F7B.pem
Common Name (CN) *.citrix.com
Common Name w/o SNI *.citrix.com
Subject Alternative Name (SAN)
  • *.citrix.com
  • *.citrix.de
  • *.cloud.com
  • *.sharefile.com
  • *.citrixonline.com
  • *.citrix.com.au
  • *.citrix.co.uk
  • citrix.com
  • cloud.com
  • citrixonline.com
  • citrix.com.au
  • citrix.co.uk
  • citrix.de
  • sharefile.com
CA Issuers DigiCert TLS RSA SHA256 2020 CA1 (DigiCert Inc from US)
Certificate Trust Ok via SAN wildcard (same w/o SNI)
Chain Of Trust passed.
Extended-Validation Policies no
ETS (prev. "eTLS") not present
Expiration Status 197 >= 60 days
Valid Not Before 2022-12-20 00:00
Valid Not After 2023-12-19 23:59
Validity Period No finding
Certificate Count Server 3
Certs List Ordering Problem no
Leaked Key (pwnedkeys) not in database
CRL Revoked not revoked
CRL Distribution Points
  • http://crl3.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl
  • http://crl4.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl
OCSP Revoked
OCSP URL http://ocsp.digicert.com
OCSP Stapling not offered
OCSP Must Staple Extension --
DNS CAA Record
  • --
Certificate Transparency yes (certificate extension)

HTTP response

Category Finding
HTTP Status Code Unexpected 503 Service Unavailable @ '/'
HTTP Clock Skew Got no HTTP time, maybe try different URL?
HSTS not offered
Server Banner
Banner Application
Cookie Count
Secure Cookie
HTTP-only Cookie
Reverse Proxy Banner

Vulnerabilities

Category Finding
Heartbleed not vulnerable, no heartbeat extension
CCS not vulnerable
Ticketbleed no session ticket extension
ROBOT not vulnerable
Secure Renegotiation VULNERABLE
Secure Client Renegotiation not vulnerable
CRIME TLS not vulnerable
BREACH not vulnerable, no HTTP compression - only supplied '/' tested
POODLE SSL not vulnerable, no SSLv3
Fallback SCSV supported
SWEET32 not vulnerable
FREAK not vulnerable
DROWN not vulnerable on this host and port
DROWN Hint Make sure you don't use this certificate elsewhere with SSLv2 enabled services, see censys.io
LOGJAM not vulnerable, no DH EXPORT ciphers,
LOGJAM Common Primes no DH key with <= TLS 1.2
BEAST CBC TLS1
  • AES256-SHA
  • AES128-SHA
  • ECDHE-RSA-AES256-SHA
  • ECDHE-RSA-AES128-SHA
BEAST VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)
LUCKY13 potentially vulnerable, uses TLS CBC ciphers
RC4 not vulnerable

Ciphers

Name Key Exchange Encryption Key Length IANA ID
ECDHE-RSA-AES256-GCM-SHA384 ECDH 256 AESGCM 256 xc030
ECDHE-RSA-AES256-SHA384 ECDH 256 AES 256 xc028
ECDHE-RSA-AES256-SHA ECDH 256 AES 256 xc014
AES256-GCM-SHA384 RSA AESGCM 256 x9d
AES256-SHA256 RSA AES 256 x3d
AES256-SHA RSA AES 256 x35
ECDHE-RSA-AES128-GCM-SHA256 ECDH 256 AESGCM 128 xc02f
ECDHE-RSA-AES128-SHA256 ECDH 256 AES 128 xc027
ECDHE-RSA-AES128-SHA ECDH 256 AES 128 xc013
AES128-GCM-SHA256 RSA AESGCM 128 x9c
AES128-SHA256 RSA AES 128 x3c
AES128-SHA RSA AES 128 x2f

Client Simulation

Category Connection via
Android 4.4.2 TLSv1.2 AES256-SHA
Android 5.0 TLSv1.2 AES256-SHA
Android 6.0 TLSv1.2 AES256-SHA
Android 7.0 TLSv1.2 AES256-SHA
Android 8.1 TLSv1.2 AES256-SHA
Android 9.0 TLSv1.2 AES256-SHA
Android X TLSv1.2 AES256-SHA
Chrome 74 Windows 10 TLSv1.2 AES256-SHA
Chrome 79 Windows 10 TLSv1.2 AES256-SHA
Firefox 66 Windows 8.1/10 TLSv1.2 AES256-SHA
Firefox 71 Windows 10 TLSv1.2 AES256-SHA
IE 6 Windows XP No connection
IE 8 Windows 7 TLSv1.0 AES256-SHA
IE 8 Windows XP No connection
IE 11 Windows 7 TLSv1.2 AES256-SHA
IE 11 Windows 8.1 TLSv1.2 AES256-SHA
IE 11 Windows Phone 8.1 TLSv1.2 AES256-SHA
IE 11 Windows 10 TLSv1.2 AES256-SHA
Edge 15 Windows 10 TLSv1.2 AES256-SHA
Edge 17 Windows 10 TLSv1.2 AES256-SHA
Opera 66 Windows 10 TLSv1.2 AES256-SHA
Safari 9 IOS9 TLSv1.2 AES256-SHA
Safari 9 OSX 10.11 TLSv1.2 AES256-SHA
Safari 10 OSX 10.12 TLSv1.2 AES256-SHA
Safari 12.1 iOS 12.2 TLSv1.2 AES256-SHA
Safari 13.0 OSX 10.14.6 TLSv1.2 AES256-SHA
Apple ATS 9 IOS9 TLSv1.2 ECDHE-RSA-AES128-SHA
Java 6u45 TLSv1.0 AES128-SHA
Java 7u25 TLSv1.0 AES128-SHA
Java 8u161 TLSv1.2 AES256-SHA
Java 11.0.2 (OpenJDK) TLSv1.2 AES256-SHA
Java 12.0.1 (OpenJDK) TLSv1.2 AES256-SHA
OpenSSL 1.02e TLSv1.2 AES256-SHA
OpenSSL 1.10l (Debian) TLSv1.2 AES256-SHA
OpenSSL 1.11d (Debian) TLSv1.2 AES256-SHA
Thunderbird 68.3 TLSv1.2 AES256-SHA