Open
          
        
        
        
          
            
            Cached
            ·
            just now
          
        
      
    
        
          
        
        
          81/100
        
        
          SECURITY SCORE
        
      
    
  Certificate Information
        Subject
      
      
        
          C=DK, ST=Hovedstaden, O=Danmarks Tekniske Universitet, CN=*.dtu.dk
        
      
    
        Issuer
      
      
        
          C=NL, O=GEANT Vereniging, CN=GEANT OV RSA CA 4
        
      
    
        Valid From
      
      
        December 16, 2024
      
    
        Valid Until
      
      
        
          December 16, 2025
        
        
          
            42 days
          
        
      
    
        Public Key
      
      
        
          RSA
          
            2048 bit
          
          
        
        
          Adequate
        
      
    
        Signature Algorithm
      
      
        
          SHA384-RSA
        
        
      
    
        SHA-256 Fingerprint
      
      
        
          00:44:E3:0F:D2:9F:47:2C:8A:0B:2F:6D:D8:2C:41:8B:22:7B:29:DD:21:5D:69:F5:22:94:0A:C0:CE:DD:87:39
        
      
    
          Alternative Names
        
        
      Security Configuration
          TLS Protocols
        
        
          
            
              TLS 1.2
            
          
            
              TLS 1.3
            
          
        
      
          Forward Secrecy
        
        
          
            
              Supported
            
            
              (Modern clients use PFS)
            
          
        
        CAA Records (Certificate Authority Authorization)
CAA Records
        
          
            
              Not Configured
            
            (Any CA can issue certificates)
          
        
        
            
            CAA Issues
          
          - • No CAA records configured - any CA can issue certificates
 
            
            Recommendations
          
          - • Implement CAA records to restrict which CAs can issue certificates for your domain
 - • This adds an extra layer of security against unauthorized certificate issuance
 - • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
 - • Consider adding 'iodef' record to receive security incident reports