Cached · just now
78/100 SECURITY SCORE

Certificate Information

Subject
C=DE, ST=Bayern, O=Friedrich-Alexander-Universitaet Erlangen-Nuernberg, CN=www.fau.info
Issuer
C=GR, O=Hellenic Academic and Research Institutions CA, CN=GEANT TLS ECC 1
Valid From
December 09, 2025
Valid Until
December 09, 2026 350 days
Public Key
ECDSA 384 bit (P-384) Strong
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
E6:37:99:E9:9A:F9:15:09:D1:8F:C3:89:84:C1:9C:71:A9:CB:5C:F6:9A:41:82:DA:FA:1A:4A:47:17:26:28:43
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15552000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

62 domains
fau.info www.fau.info

Other domains in certificate

fruehstudium.fau.de schlossgartenfest.fau.de universitaetsball.fau.de weltwassertag.fau.de www.fruehstudium.fau.de www.schlossgartenfest.fau.de www.universitaetsball.fau.de www.weltwassertag.fau.de www.xn--universittsball-8kb.fau.de xn--universittsball-8kb.fau.de
fau.digital www.fau.digital
fau.fm www.fau.fm
schlossgartenfest.com www.schlossgartenfest.com
uni-er.de www.uni-er.de
uni-erlangen-nuernberg.de www.uni-erlangen-nuernberg.de
uni-erlangen.bayern www.uni-erlangen.bayern
fruehstudium.uni-erlangen.de schlossgartenfest.uni-erlangen.de universitaetsball.uni-erlangen.de weltwassertag.uni-erlangen.de www.fruehstudium.uni-erlangen.de www.schlossgartenfest.uni-erlangen.de www.universitaetsball.uni-erlangen.de www.weltwassertag.uni-erlangen.de www.xn--universittsball-8kb.uni-erlangen.de xn--universittsball-8kb.uni-erlangen.de
uni-erlangen.eu www.uni-erlangen.eu
uni-erlangen.info www.uni-erlangen.info
uni-nuernberg.bayern www.uni-nuernberg.bayern
uni-nuernberg.de www.uni-nuernberg.de
uni-nuernberg.eu www.uni-nuernberg.eu
unierlangen.de www.unierlangen.de
universitaet-erlangen.de www.universitaet-erlangen.de
universitaet-nuernberg.de www.universitaet-nuernberg.de
universitaet-nuernberg.eu www.universitaet-nuernberg.eu
www.xn--uni-erlangen-nrnberg-2ec.de xn--uni-erlangen-nrnberg-2ec.de
www.xn--uni-nrnberg-xhb.de xn--uni-nrnberg-xhb.de
www.xn--uni-nrnberg-xhb.eu xn--uni-nrnberg-xhb.eu
www.xn--universitt-nrnberg-ttb79b.de xn--universitt-nrnberg-ttb79b.de
www.xn--universitt-nrnberg-ttb79b.eu xn--universitt-nrnberg-ttb79b.eu