Open
Cached
·
just now
90/100
SECURITY SCORE
Certificate Information
Subject
CN=*.gridgain.com
Issuer
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=GeoTrust TLS RSA CA G1
Valid From
August 11, 2025
Valid Until
August 06, 2026
196 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
ED:A0:E2:D0:E9:B5:BB:78:02:E6:DA:8C:F9:08:F0:98:88:69:EC:88:A4:D4:08:DA:54:EE:D4:FF:34:1A:2A:37
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
script-src; frame-src; img-src; +4 more
script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.redoc.ly *.clarity.ms *.claydar.com cdn.redocly.com cdn.jsdelivr.net js.zi-scripts.com feedback.fish *.licdn.com *.linkedin.oribi.io www.gstatic.com *.hs-banner.com cdn.cookielaw.org *.linkedin.com *.6sc.co *.6sense.com tag.clearbitscripts.com *.clearbitjs.com js.qualified.com js.hs-scripts.com js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net js.hsadspixel.net *.hsforms.net *.calendly.com calendly.com static.ads-twitter.com go.gridgain.com yastatic.net mc.yandex.ru mc.yandex.com polyfill.io widget.bugyard.io lltrck.com *.twitter.com *.bamboohr.com *.ampproject.org *.cloudflare.com agorbatchev.typepad.com *.youtube.com maps.gstatic.com *.googleapis.com *.google-analytics.com cdnjs.cloudflare.com assets.zendesk.com connect.facebook.net *.googletagmanager.com *.google.com *.marketo.com *.marketo.net munchkin.marketo.net *.drift.com *.driftt.com *.addtoany.com *.posthog.com *.redditstatic.com *.reddit.com *.googleadservices.com *.doubleclick.net *.webvisor.com *.sajari.com *.algolianet.com *.algolia.net blob:; frame-src 'self' *.calendly.com calendly.com feedback.fish *.youtube.com app.qualified.com *.hsforms.com www.googletagmanager.com assets.zendesk.com *.facebook.com s-static.ak.facebook.com tautt.zendesk.com *.driftt.com *.addtoany.com *.posthog.com *.redditstatic.com *.reddit.com *.marketo.com *.marketo.net *.doubleclick.net *.twitter.com www.youtube-nocookie.com *.google.com *.gridgain.com blob: https://mc.yandex.ru https://mc.yandex.com https://mc.webvisor.com https://mc.webvisor.org ; img-src 'self' 'unsafe-inline' *.bugyard.io https://mc.yandex.ru *.google-analytics.com *.google.com * data: ; connect-src 'self' https://gridgain.bamboohr.com *.clarity.ms *.posthog.com *.redditstatic.com *.reddit.com cdnjs.cloudflare.com js.zi-scripts.com cdn.cookielaw.org cdn.jsdelivr.net *.claydar.com *.hsappstatic.net *.onetrust.com secure.adnxs.com ws.zoominfo.com *.sajari.net *.algolianet.com *.algolia.net app.clearbit.com *.hubspot.com *.bugyard.io *.hs-banner.com *.linkedin.oribi.io *.linkedin.com *.6sc.co *.6sense.com *.qualified.com wss://*.qualified.com *.marketo.com *.hscollectedforms.net *.hsforms.com api.hubapi.com https://mc.yandex.ru https://mc.yandex.com *.mktoresp.com *.google-analytics.com *.google.com *.googlesyndication.com https://stats.g.doubleclick.net ; child-src 'self' blob: https://mc.yandex.ru https://mc.yandex.com https://mc.webvisor.com https://mc.webvisor.org ; object-src 'self'; report-uri /csp-report.php
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
comodoca.com
digicert.com
; cansignhttpexchanges=yes
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
ssl.com
Wildcard CAs
ssl.com
comodoca.com
digicert.com
; cansignhttpexchanges=yes
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 5 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
Subject Alternative Names
4 domains
gridgain.com
*.gridgain.com
gridgainsystems.com
www.gridgainsystems.com
Other domains in certificate