Open Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=Pennsylvania, O=Carnegie Mellon University, CN=www.cmu.edu
Issuer
C=US, O=Internet2, CN=InCommon RSA Server CA 2
Valid From
October 31, 2025
Valid Until
December 01, 2026 385 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
53:83:E0:D9:97:7A:9D:E9:DA:7B:28:26:36:44:BF:9C:25:DB:73:9A:B5:9C:85:1D:47:19:8D:E7:47:7B:4A:36
Alternative Names

Security Configuration

TLS Protocols
TLS 1.0 TLS 1.1 TLS 1.2
Forward Secrecy
Limited (Check cipher configuration)
Warnings
  • TLS 1.3 is not supported (recommended)
  • TLS 1.1 is deprecated and should be disabled
  • TLS 1.0 is deprecated and should be disabled

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=300
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

109 domains
cmu.edu ai-sdm.cmu.edu alumni.cmu.edu blockchain.cmu.edu bme.cmu.edu box.cmu.edu carnegiemellontoday.cmu.edu cbd.cmu.edu cfa.cmu.edu cmtoday.cmu.edu cmutoday.cmu.edu compbio.cmu.edu covidcast.cmu.edu data.cmu.edu email.cmu.edu engage.cmu.edu english.cmu.edu giftplanning.cmu.edu giving.cmu.edu givingcmuday.cmu.edu google.cmu.edu googlepassword.cmu.edu hadr.cmu.edu help.cmu.edu ideate.cmu.edu ini.cmu.edu it-help.cmu.edu leadership.cmu.edu makepossible.cmu.edu metro21.cmu.edu music.cmu.edu my.cmu.edu psy.cmu.edu responsibleai.cmu.edu shift.cmu.edu social.cmu.edu sparcs.cmu.edu sv.cmu.edu timeline.cmu.edu today.cmu.edu vaccine.cmu.edu west.cmu.edu www.cmu.edu admission.enrollment.cmu.edu caps.web.cmu.edu ccsa.sv.cmu.edu cms.heinz.cmu.edu cooling.ce.cmu.edu disaster.sv.cmu.edu dmi.sv.cmu.edu email.alumni.cmu.edu infoserver.andrew.cmu.edu mail.alumni.cmu.edu metro21.heinz.cmu.edu msas.cbd.cmu.edu myapps.andrew.cmu.edu myotpapps.andrew.cmu.edu nexus.ece.cmu.edu playtest.etc.cmu.edu pmbook.ce.cmu.edu policy.andrew.cmu.edu quake.ce.cmu.edu reuse.cs.cmu.edu scs4all.cs.cmu.edu search.web.cmu.edu web-search.andrew.cmu.edu women.cs.cmu.edu www.alumni.cmu.edu www.arc.cmu.edu www.bme.cmu.edu www.ce.cmu.edu www.cfa.cmu.edu www.covidcast.cmu.edu www.epp.cmu.edu www.giftplanning.cmu.edu www.giving.cmu.edu www.help.cmu.edu www.ideate.cmu.edu www.ini.cmu.edu www.metro21.cmu.edu www.music.cmu.edu www.psy.cmu.edu www.r53.cmu.edu www.shift.cmu.edu www.sv.cmu.edu www.timeline.cmu.edu education.rec.ri.cmu.edu gollum.mac.cc.cmu.edu www.epp.cit.cmu.edu www.nrec.ri.cmu.edu www.rec.ri.cmu.edu www.scs4all.cs.cmu.edu www.store.cc.cmu.edu www.telecom.cc.cmu.edu www.women.cs.cmu.edu www.education.rec.ri.cmu.edu

Other domains in certificate

carnegiemellon.edu www.carnegiemellon.edu
carnegiemellon.org
cmuenergyweek.org www.cmuenergyweek.org
greenscienceinstitute.com www.greenscienceinstitute.com
greenscienceinstitute.net www.greenscienceinstitute.net
greenscienceinstitute.org www.greenscienceinstitute.org
metro21.org www.metro21.org