Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=asrar.info
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 08, 2025
Valid Until
March 08, 2026
47 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
79:38:B0:D4:5D:51:1B:75:C9:2E:41:73:1B:59:0D:22:EE:67:BC:77:D6:2B:FE:D9:DE:D9:9C:30:D9:99:3C:68
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
enersource.ca
*.enersource.ca
*.dashboard.enersource.ca
*.report.enersource.ca
*.superset-dev.enersource.ca
*.webmail.enersource.ca
2weeks.io
*.2weeks.io
*.ai.2weeks.io
*.chat.2weeks.io
*.flow.2weeks.io
*.startup.2weeks.io
*.test.2weeks.io
asrar.info
*.asrar.info
*.anyconnect.babadan.com
babadan.com
*.babadan.com
*.mobileconnect.babadan.com
*.random.babadan.com
*.remoto.babadan.com
*.secureconnect.babadan.com
*.studentsvpn.babadan.com
*.ww.babadan.com
*.ww1.babadan.com
*.www.babadan.com
*.af.lularoeleggings.org
*.am.lularoeleggings.org
*.az.lularoeleggings.org
*.bg.lularoeleggings.org
*.ceb.lularoeleggings.org
*.co.lularoeleggings.org
*.cy.lularoeleggings.org
*.da1.lularoeleggings.org
*.de.lularoeleggings.org
*.fr1.lularoeleggings.org
*.fy.lularoeleggings.org
*.gd.lularoeleggings.org
*.gl.lularoeleggings.org
*.ht.lularoeleggings.org
*.is.lularoeleggings.org
*.it.lularoeleggings.org
*.jw.lularoeleggings.org
*.ka.lularoeleggings.org
*.km.lularoeleggings.org
*.ko1.lularoeleggings.org
*.ku.lularoeleggings.org
*.ky.lularoeleggings.org
*.lb.lularoeleggings.org
*.lt1.lularoeleggings.org
lularoeleggings.org
*.lularoeleggings.org
*.lv1.lularoeleggings.org
*.mk.lularoeleggings.org
*.ml.lularoeleggings.org
*.mr.lularoeleggings.org
*.mt.lularoeleggings.org
*.ne.lularoeleggings.org
*.nl1.lularoeleggings.org
*.pa.lularoeleggings.org
*.ps.lularoeleggings.org
*.ro.lularoeleggings.org
*.si.lularoeleggings.org
*.so.lularoeleggings.org
*.sq.lularoeleggings.org
*.sr1.lularoeleggings.org
*.su.lularoeleggings.org
*.ta.lularoeleggings.org
*.te.lularoeleggings.org
*.th.lularoeleggings.org
*.tl.lularoeleggings.org
*.ur1.lularoeleggings.org
*.vi.lularoeleggings.org
*.xh.lularoeleggings.org
*.yi.lularoeleggings.org
*.zh.lularoeleggings.org
*.565b080d-22ff-4288-989c-f6a3a178da79.myshelton.com
*.flowise.myshelton.com
*.forums.myshelton.com
*.https.myshelton.com
myshelton.com
*.myshelton.com
*.rustore.myshelton.com
*.wildcard.myshelton.com
*.ww17.myshelton.com
*.ww38.myshelton.com
*.www.myshelton.com
*.ww16.xn--sosyalhalsaha-cbc.com
xn--sosyalhalsaha-cbc.com
*.xn--sosyalhalsaha-cbc.com
Other domains in certificate