Open
Cached
·
just now
92/100
SECURITY SCORE
Certificate Information
Subject
CN=app.snowcatcloud.com
Issuer
C=US, O=Amazon, CN=Amazon RSA 2048 M04
Valid From
August 01, 2025
Valid Until
August 30, 2026
218 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E0:06:5B:24:8D:47:F6:8F:2D:BD:57:DF:33:61:6C:7E:58:DB:6B:DD:76:09:78:30:B8:01:AB:19:16:82:E9:E7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
Content-Security-Policy
Basic
base-uri; script-src; style-src-elem; +4 more
base-uri 'self';script-src 'strict-dynamic' 'nonce-NJL3qOcApaBNzUUXoIdQ4TXXSPGaOJXU';style-src-elem 'sha256-cu8fsHifjOQhx0xopNUPdvE0GEYillVro+MwOzmE4Zo=' 'sha256-Tmq5y8yAJ/unTpx9N6W5LhQYW21ofTa1x2ES4DByAFg=' 'sha256-Rc2a7SfB50KoFAIR0X5+ul5uQbsJSujId4MzcmbUx8s=' 'sha256-qEpFNF1Fp0ubO1jN1GWZPNX0btdFLOmn1g2V0f1FnYs=' 'sha256-RbXap8DThrtn0GXWVWVLAiidfpCw+pWF6BZUhesiLg8=' 'sha256-WED0SddB76QKxvUxiNsC4yBV4q+h2VmeED+HOmw3QcE=' 'sha256-CJPT+JaP/VZGlmqOGSIvSZ7s4WH9hnAkfELvnF6pLdk=' 'sha256-8UEbNWwfRGt0BQWShmqS1bfXUsFG5gnX7KTPvl4wnK8=' 'sha256-32yG/vPEu13tQaT5V/q/1JGq8LS5XAcvWNKxWrmVbc4=' 'sha256-zEugRvDeDEgxiL8nYxezyeSYFteqIJ6dG+RROhbF2/8=' 'sha256-NGjP9FMu4ZSkfjwn7HYQQ7lDrzLQK2lv989DWs6xfRk=' 'sha256-ONFzDHhEcJeV7JXg3p3KH+z/ZUrWJXhpWMQHuesJ9yY=' fonts.googleapis.com https://app.snowcatcloud.com;object-src 'none';require-trusted-types-for 'script';upgrade-insecure-requests;report-uri https://app.snowcatcloud.com/api/csp-violation
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports