Open
Cached
·
just now
83/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=Florida, O=Ryder System, Inc., CN=aconnect.ryder.com
Issuer
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA
Valid From
April 23, 2025
Valid Until
April 23, 2026
112 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DF:88:E0:62:E0:D4:95:CD:B5:74:37:3D:C4:F5:91:FA:63:F3:AA:8C:6F:73:F4:7C:98:63:54:43:36:3F:42:F2
Alternative Names
Security Configuration
TLS Protocols
TLS 1.1
TLS 1.2
Forward Secrecy
Limited
(Check cipher configuration)
Warnings
- • TLS 1.3 is not supported (recommended)
- • TLS 1.1 is deprecated and should be disabled
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000;
Content-Security-Policy
Good
default-src; script-src; img-src; +1 more
default-src 'self'; script-src 'self' 'unsafe-inline'; img-src * data:; style-src 'self' 'unsafe-inline';
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
37 domains
aconnect.ryder.com
aconnectchi.ryder.com
aconnectmia.ryder.com
aconnectssc.ryder.com
aconnectva.ryder.com
cconnect.ryder.com
cconnectchi.ryder.com
cconnectmia.ryder.com
cconnectssc.ryder.com
cconnectva.ryder.com
connect.ryder.com
connectchi.ryder.com
connectmia.ryder.com
connectssc.ryder.com
connectva.ryder.com
econnect.ryder.com
econnectchi.ryder.com
econnectmia.ryder.com
econnectssc.ryder.com
econnectva.ryder.com
extranetmia.ryder.com
extranetssc.ryder.com
sbtconnect.ryder.com
sbtconnectchi.ryder.com
sbtconnectmia.ryder.com
sbtconnectssc.ryder.com
sbtconnectva.ryder.com
testaconnect.ryder.com
testcconnect.ryder.com
testconnect.ryder.com
testeconnect.ryder.com
testsbtconnect.ryder.com
ukconnect.ryder.com
ukconnectchi.ryder.com
ukconnectmia.ryder.com
ukconnectssc.ryder.com
ukconnectva.ryder.com