Open
Cached
·
just now
86/100
SECURITY SCORE
Certificate Information
Subject
CN=outages.discovery.wisc.edu
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 23, 2025
Valid Until
March 23, 2026
68 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
65:D1:1B:60:D6:93:87:CF:33:44:A2:1A:26:D9:30:0A:BC:42:FC:D8:4B:5A:E7:ED:62:D4:98:AD:21:B2:81:3F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=259200
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
- • Consider adding 'issuewild' records to control wildcard certificate issuance
Subject Alternative Names
34 domains
status.backdrop.cloud
status.activix.ca
status.archlet.io
status.asurint.com
status.censys.com
status.censys.io
status.chainalysis.com
private-cloud-status.cloud-services.ltd
status.dochub.com
status.flipflopsystems.com
status.gastronovi.com
www.getbambustatus.com
status.getsidequest.app
status.occhdsupport.ironbow.com
status.isianalytics.com
status.kennasecurity.com
status.xs2a.banking.klarna.com
status.mastermind.com
status.memxtrading.com
status.nozominetworks.io
status.over-haul.com
status.salesdock.nl
status.searis.no
status.sitoo.com
status.spinupwp.com
status-us2.sysdig.com
status.techwolf.ai
status.thenational.academy
status.thrivist.com
www.traxostatus.com
status.unlimitedfinancials.care
status.veremark.com
status.welovroi.com
outages.discovery.wisc.edu
Other domains in certificate