vps111.rbx.freecycle.org, 51.83.28.234:443

TLS Test Results from April 09 2024 17:33:38 UTC. Scan took 68 seconds.

Summary

Finding Severity Result
Certificate Trust HIGH certificate does not match supplied URI (same w/o SNI)
Chain Of Trust CRITICAL failed (expired).
Expiration Status CRITICAL expired
Valid Not After CRITICAL 2024-01-16 23:59
TLS 1.2 OK offered
TLS 1.3 INFO not offered + downgraded to weaker protocol
Perfect Forward Secrecy OK offered
Common Name (CN) OK *.freecycle.org
Subject Alternative Name (SAN) INFO
  • *.freecycle.org
  • freecycle.org
CA Issuers INFO Sectigo RSA Domain Validation Secure Server CA (Sectigo Limited from GB)

Protocols

Version Status
SSL v2 not offered
SSL v3 not offered
TLS 1.0 offered (deprecated)
TLS 1.1 offered (deprecated)
TLS 1.2 offered
TLS 1.3 not offered + downgraded to weaker protocol
ALPN / HTTP2 http/1.1

Cipher Categories

Category Status
NULL ciphers (no encryption) not offered
Anonymous NULL Ciphers (no authentication) not offered
Export ciphers (excluding ADH+NULL) not offered
LOW: 64 Bit + DES, RC[2,4] (excluding export) not offered
Triple DES Ciphers / IDEA not offered
Obsolete CBC ciphers (AES, ARIA etc.) offered
Strong encryption (AEAD ciphers) offered

Perfect Forward Secrecy

Category Status
Perfect Forward Secrecy offered
PFS Ciphers
  • ECDHE-RSA-AES256-GCM-SHA384
  • ECDHE-RSA-AES256-SHA384
  • ECDHE-RSA-AES256-SHA
PFS ECDHE Curves
  • prime256v1
  • secp384r1
  • secp521r1

Server Preferences

Category Finding
Cipher Order server
Protocol Negotiated Default protocol TLS1.2
Cipher Negotiated ECDHE-RSA-AES256-GCM-SHA384, 256 bit ECDH (P-256)
Cipher Order TLS v1.0 ECDHE-RSA-AES256-SHA
Cipher Order TLS v1.1 ECDHE-RSA-AES256-SHA
Cipher Order TLS v1.2 ECDHE-RSA-AES256-GCM-SHA384

Server Defaults

Category Finding
TLS Extensions
  • renegotiation info/#65281
  • server name/#0
  • EC point formats/#11
  • session ticket/#35
  • next protocol/#13172
  • max fragment length/#1
  • application layer protocol negotiation/#16
  • encrypt-then-mac/#22
  • extended master secret/#23
TLS Session Ticket valid for 300 seconds only (<daily)
SSL Session-ID Support yes
Session Resumption Ticket supported
Session Resumption ID supported
TLS Timestamp random
Number of Certificates 1

Certificate

Category Finding
Signature Algorithm SHA256 with RSA
Key Size RSA 4096 bits
Key Usage
  • Digital Signature
  • Key Encipherment
Extended Key Usage
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Serial Number C38B7FB67291BB21265B04A5E18552C4
SHA1 Fingerprint 4B23C6DE5AF2DFED569F29C1C9A410D89A7325C9
SHA256 Fingerprint 32268A173F36009FBB6532C25361654814013909B62707D561385AB6EBB6A661
X.509 Certificate Download vps111.rbx.freecycle.org_443_4B23C6DE.pem
Common Name (CN) *.freecycle.org
Common Name w/o SNI *.freecycle.org
Subject Alternative Name (SAN)
  • *.freecycle.org
  • freecycle.org
CA Issuers Sectigo RSA Domain Validation Secure Server CA (Sectigo Limited from GB)
Certificate Trust certificate does not match supplied URI (same w/o SNI)
Chain Of Trust failed (expired).
Extended-Validation Policies no
ETS (prev. "eTLS") not present
Expiration Status expired
Valid Not Before 2022-12-16 00:00
Valid Not After 2024-01-16 23:59
Validity Period No finding
Certificate Count Server 4
Certs List Ordering Problem no
Leaked Key (pwnedkeys) not in database
CRL Distribution Points
  • --
OCSP URL http://ocsp.sectigo.com
OCSP Stapling not offered
OCSP Must Staple Extension --
DNS CAA Record
  • --
Certificate Transparency yes (certificate extension)

HTTP response

Category Finding
HTTP Status Code 301 Moved Permanently ('/')
HTTP Clock Skew 0 seconds from localtime
HSTS not offered
Server Banner
Banner Application
Cookie Count
Security Headers --
Reverse Proxy Banner

Vulnerabilities

Category Finding
Heartbleed not vulnerable, no heartbeat extension
CCS not vulnerable
Ticketbleed not vulnerable
ROBOT not vulnerable, no RSA key transport cipher
Secure Renegotiation supported
Secure Client Renegotiation not vulnerable
CRIME TLS not vulnerable
BREACH not vulnerable, no HTTP compression - only supplied '/' tested
POODLE SSL not vulnerable, no SSLv3
Fallback SCSV supported
SWEET32 not vulnerable
FREAK not vulnerable
DROWN not vulnerable on this host and port
DROWN Hint Make sure you don't use this certificate elsewhere with SSLv2 enabled services, see censys.io
LOGJAM not vulnerable, no DH EXPORT ciphers,
LOGJAM Common Primes no DH key with <= TLS 1.2
BEAST CBC TLS1
  • ECDHE-RSA-AES256-SHA
BEAST VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)
LUCKY13 potentially vulnerable, uses TLS CBC ciphers
RC4 not vulnerable

Ciphers

Name Key Exchange Encryption Key Length IANA ID
ECDHE-RSA-AES256-GCM-SHA384 ECDH 256 AESGCM 256 xc030
ECDHE-RSA-AES256-SHA384 ECDH 256 AES 256 xc028
ECDHE-RSA-AES256-SHA ECDH 256 AES 256 xc014

Client Simulation

Category Connection via
Android 4.4.2 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Android 5.0 TLSv1.2 ECDHE-RSA-AES256-SHA
Android 6.0 TLSv1.2 ECDHE-RSA-AES256-SHA
Android 7.0 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Android 8.1 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Android 9.0 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Android X TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Chrome 74 Windows 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Chrome 79 Windows 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Firefox 66 Windows 8.1/10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Firefox 71 Windows 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
IE 6 Windows XP No connection
IE 8 Windows 7 TLSv1.0 ECDHE-RSA-AES256-SHA
IE 8 Windows XP No connection
IE 11 Windows 7 TLSv1.2 ECDHE-RSA-AES256-SHA384
IE 11 Windows 8.1 TLSv1.2 ECDHE-RSA-AES256-SHA384
IE 11 Windows Phone 8.1 TLSv1.2 ECDHE-RSA-AES256-SHA
IE 11 Windows 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Edge 15 Windows 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Edge 17 Windows 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Opera 66 Windows 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Safari 9 IOS9 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Safari 9 OSX 10.11 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Safari 10 OSX 10.12 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Safari 12.1 iOS 12.2 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Safari 13.0 OSX 10.14.6 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Apple ATS 9 IOS9 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Java 6u45 No connection
Java 7u25 No connection
Java 8u161 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Java 11.0.2 (OpenJDK) TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Java 12.0.1 (OpenJDK) TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
OpenSSL 1.02e TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
OpenSSL 1.10l (Debian) TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
OpenSSL 1.11d (Debian) TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
Thunderbird 68.3 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384