Open
Cached
·
just now
59/100
SECURITY SCORE
Certificate Information
Subject
UNKNOWN={:asn1_OPENTYPE, <<19, 2, 72, 85>>}, UNKNOWN={:asn1_OPENTYPE, "\f\bBudapest"}, UNKNOWN={:asn1_OPENTYPE, "\f\bBudapest"}, UNKNOWN={:asn1_OPENTYPE, <<12, 20, 80, 114, 105, 118, 97, 116, 101, 32, 79, 114, 103, 97, 110, 105, 122, 97, 116, 105, 111, 110>>}, UNKNOWN=0 1 1 0 0 4 8 6 6 8, C=HU, ST=Budapest, L=Budapest, UNKNOWN={:asn1_OPENTYPE, <<12, 4, 49, 48, 53, 52>>}, UNKNOWN={:asn1_OPENTYPE, <<12, 24, 72, 111, 110, 118, 101, 100, 32, 117, 116, 99, 97, 32, 56, 46, 32, 49, 46, 32, 101, 109, 46, 32, 50, 46>>}, O=Inepex Zrt., CN=inepex.com
Issuer
C=IL, O=StartCom Ltd., OU=StartCom Certification Authority, CN=StartCom Class 4 EV Server CA
Valid From
October 14, 2016
Valid Until
October 14, 2018
Expired
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E4:B1:DA:9F:C3:68:DD:BA:63:A6:25:9F:8E:90:E2:BD:D8:60:EF:D3:02:3F:AE:3F:99:65:FF:A6:30:B6:52:3B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
Forward Secrecy
Limited
(Check cipher configuration)
Warnings
- • TLS 1.3 is not supported (recommended)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports