77/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=Illinois, L=Chicago, O=Jones Lang LaSalle IP, Inc., CN=sansites5.jll.com
Issuer
C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1
Valid From
November 18, 2025
Valid Until
September 08, 2026 289 days
Public Key
ECDSA 256 bit (P-256) Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
AF:BF:A1:F9:1D:74:00:30:BF:2F:4C:71:7E:9A:48:32:E7:2D:43:3F:87:DB:9E:AD:65:C2:65:CD:48:CB:3C:52
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

83 domains
101southmarengo.com dev.101southmarengo.com staging.101southmarengo.com tour.101southmarengo.com www.101southmarengo.com

Other domains in certificate

ar-aws-dfs2.awaremanager.com
green-api.dev.core.beifederation.com green-api.predev.core.beifederation.com green-web.dev.core.beifederation.com green-web.predev.core.beifederation.com insights.dev.prism.beifederation.com
green-api.stg.buildingengines.com green-web.stg.buildingengines.com
api-ca.envio.systems api-hyperloop-can.envio.systems api-hyperloop-us.envio.systems api-hyperloop.envio.systems api-prod-canada.envio.systems api-prod-frankfurt.envio.systems api-prod-virginia.envio.systems api-sandbox.envio.systems cbm-ca.envio.systems cbm-sandbox.envio.systems cbm-us.envio.systems cbm.envio.systems envio-backstage-api-zipline-ca.envio.systems envio-backstage-api-zipline-us.envio.systems envio-backstage-api-zipline.envio.systems gearbox-sol-sandbox.production-frankfurt03-cluster.envio.systems hyperloop-can.envio.systems hyperloop-us.envio.systems hyperloop.envio.systems prod-canada.envio.systems prod-frankfurt.envio.systems prod-virginia.envio.systems sandbox.envio.systems
ceoblog.jll.co.uk
sansites5.jll.com
residential.jll.com.au
ceoblog.jll.eu
jllrmeteam.jllstore.com jllstore.com www.jllrmeteam.jllstore.com
ae.officefinder.app be.officefinder.app ch.officefinder.app eg.officefinder.app es.officefinder.app fi.officefinder.app fr.officefinder.app ie.officefinder.app il.officefinder.app it.officefinder.app lu.officefinder.app next.officefinder.app nl.officefinder.app pl.officefinder.app pt.officefinder.app sa.officefinder.app se.officefinder.app uat-ae.officefinder.app uat-be.officefinder.app uat-ch.officefinder.app uat-eg.officefinder.app uat-es.officefinder.app uat-fi.officefinder.app uat-fr.officefinder.app uat-ie.officefinder.app uat-il.officefinder.app uat-it.officefinder.app uat-lu.officefinder.app uat-nl.officefinder.app uat-pl.officefinder.app uat-pt.officefinder.app uat-sa.officefinder.app uat-se.officefinder.app uat-uk.officefinder.app uat-za.officefinder.app uk.officefinder.app za.officefinder.app
doc.ruijiandata.com
dev-grafana.trepbi.com solr-eks-solrcloud.trepbi.com