Open
Cached
·
just now
75/100
SECURITY SCORE
Certificate Information
Subject
CN=af3.internapp.no
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
October 13, 2025
Valid Until
January 11, 2026
50 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6B:29:BD:27:49:02:E8:13:4C:43:B4:46:0A:48:5D:8F:E2:7B:A5:3C:60:E6:08:12:B9:94:DA:52:7B:0F:38:FE
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
96 domains
internapp.no
af3-code.internapp.no
af3-dev.internapp.no
af3-staging.internapp.no
af3.internapp.no
bare-dev.internapp.no
bare-staging.internapp.no
bare.internapp.no
dev.internapp.no
gk-dev.internapp.no
gk-staging.internapp.no
gk.internapp.no
hi-e-dev.internapp.no
hi-e-staging.internapp.no
hi-e.internapp.no
hrl-dev.internapp.no
hrl-staging.internapp.no
hrl.internapp.no
idt-code.internapp.no
idt-dev.internapp.no
idt-staging.internapp.no
idt.internapp.no
mapei-dev.internapp.no
mapei-staging.internapp.no
mapei.internapp.no
oss-dev.internapp.no
oss-staging.internapp.no
oss.internapp.no
schuetz-dev.internapp.no
schuetz-staging.internapp.no
schuetz.internapp.no
staging.internapp.no
appfabrikken.no
dev.appfabrikken.no
staging.appfabrikken.no
support-dev.appfabrikken.no
support-staging.appfabrikken.no
support.appfabrikken.no
dev.dksapp.no
dksapp.no
staging.dksapp.no
api-dev.domsguiden.no
api-staging.domsguiden.no
api.domsguiden.no
domsguiden.no
larvik-dev.gjenbrukskommune.no
larvik.gjenbrukskommune.no
dev.lokalkortet.no
lokalkortet.no
staging.lokalkortet.no
api-dev.nettmonitor.no
api.nettmonitor.no
dev.rentehopp.no
rentehopp.no
svw-domsguiden.no
alstahaug-dev.ungapp.no
alstahaug-staging.ungapp.no
alstahaug.ungapp.no
bjerke-dev.ungapp.no
bjerke-staging.ungapp.no
bjerke.ungapp.no
demo-dev.ungapp.no
demo-staging.ungapp.no
demo.ungapp.no
dev.ungapp.no
haugen-code.ungapp.no
haugen-dev.ungapp.no
haugen-staging.ungapp.no
haugen.ungapp.no
headspace-dev.ungapp.no
headspace-staging.ungapp.no
headspace.ungapp.no
lokka-code.ungapp.no
lokka-dev.ungapp.no
lokka-staging.ungapp.no
lokka.ungapp.no
ostensjo-code.ungapp.no
ostensjo-dev.ungapp.no
ostensjo-staging.ungapp.no
ostensjo.ungapp.no
sagene-dev.ungapp.no
sagene-staging.ungapp.no
sagene.ungapp.no
sel-dev.ungapp.no
sel-staging.ungapp.no
sel.ungapp.no
sondre-land-dev.ungapp.no
sondre-land-staging.ungapp.no
sondre-land.ungapp.no
staging.ungapp.no
ungapp.no
vestby-dev.ungapp.no
vestby-staging.ungapp.no
vestby.ungapp.no
ungialstahaug.no
www.ungialstahaug.no
Other domains in certificate