Open
Cached
·
just now
94/100
SECURITY SCORE
Certificate Information
Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2026 Q1
Valid From
January 22, 2026
Valid Until
July 21, 2026
178 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
95:B5:2F:23:98:3B:B7:D2:BE:38:08:5F:34:4E:BE:89:5D:21:7E:2E:01:5F:1C:25:81:42:E4:44:41:94:7B:8C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926; includeSubdomains
Content-Security-Policy
Basic
default-src; script-src; script-src-elem; +11 more
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.sans.org https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://cdn.jsdelivr.net https://cdn.cookielaw.org https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://bat.bing.com https://*.mountain.com https://www.buzzsprout.com https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/ https://www.redditstatic.com/ads/pixel.js https://zn5mzsmkpycxwsqpf-sans.siteintercept.qualtrics.com https://siteintercept.qualtrics.com https://html5.dcatalog.com/dcviewer.js https://cdn.evgnet.com https://*.cdn.optimizely.com https://*.optimizely.com https://addsearch.com https://*.youtube.com https://snap.licdn.com https://t.vibe.co https://s.vibe.co https://js.zi-scripts.com https://c.lytics.io https://*.hotjar.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://cdn.jsdelivr.net https://cdn.cookielaw.org https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://analytics.tiktok.com; style-src 'self' 'unsafe-inline' https://assets.buzzsprout.com/assets/players/ https://*.sans.org https://c.lytics.io/static/pathfora.min.css https://*.googleapis.com; img-src 'self' data: https: blob:; font-src 'self' data: https://script.hotjar.com https://*.gstatic.com; connect-src 'self' https://www.facebook.com/privacy_sandbox/topics/registration/ https://www.redditstatic.com/ads/conversions-config/v1/pixel/ https://pixel-config.reddit.com/pixels/ https://conversions-config.reddit.com/v1/pixel/ https://siteintercept.qualtrics.com https://*.optimizely.com https://sansccybersecurity.us-5.evergage.com https://*.onetrust.com https://personalize-edge.contentstack.com/user-attributes https://*.sans.org https://px.ads.linkedin.com https://ws.zoominfo.com https://js.zi-scripts.com https://t.vibe.co https://s.vibe.co https://*.hotjar.com https://*.hotjar.io wss://ws.hotjar.com https://www.google.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://cdn.cookielaw.org https://geolocation.onetrust.com https://stats.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.googletagmanager.com https://*.contentstack.io https://*.algolia.io https://*.algolia.net https://*.algolianet.com wss://*.algolia.net; frame-src 'self' https://survey.sans.org https://open.spotify.com https://www.buzzsprout.com https://app.smartsheet.com https://*.cdn.optimizely.com https://*.optimizely.com https://c.lytics.io https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://*.youtube.com https://*.google.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; media-src 'self' https://assets.contentstack.io; upgrade-insecure-requests;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
camera=(), microphone=(), geolocation=(), payment=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Wildcard CAs
Incident Reporting
mailto:[email protected]
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 5 CAs - consider limiting to only the CAs you actively use
Subject Alternative Names
34 domains
sans.org
*.sans.org
content.sans.org
qms.sans.org
*.cyberleaders.sans.org
*.cyberwarriorchallenge.sans.org
*.feedback.sans.org
*.innovation.sans.org
*.labs.sans.org
*.ukcyberteam.sans.org
cio.org
*.cio.org
giac.net
*.giac.net
giac.org
*.giac.org
imperva.com
ranges.io
*.ranges.io
dev.sans-foundations.com
*.dev.sans-foundations.com
qa.sans-foundations.com
*.qa.sans-foundations.com
sans-foundations.com
*.sans-foundations.com
uat.sans-foundations.com
*.uat.sans-foundations.com
sans.co
*.sans.co
isc.sans.edu
sans.edu
*.sans.edu
widgetxco.org
*.widgetxco.org
Other domains in certificate