Open Cached · just now
94/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=California, L=Santa Clara, O=WSO2 LLC, CN=*.wso2.com
Issuer
C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
Valid From
June 30, 2025
Valid Until
December 20, 2025 45 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
94:E5:8B:F3:F9:90:30:EA:2D:A2:73:01:E6:6E:7B:42:94:59:67:A9:70:A7:07:CF:2F:FD:FE:AD:79:72:C6:21
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Weak
upgrade-insecure-requests; frame-ancestors
X-Frame-Options
Excellent
deny
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin
Permissions-Policy
Present
accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),xr-spatial-tracking=(),picture-in-picture=()
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Significantly strengthen CSP directives

CAA Records (Certificate Authority Authorization)

CAA Records
Configured (Restricts certificate issuance)
Current Issuer
Authorized (Matches CAA policy)
Recommendations
  • Consider using critical flag (flags=128) for stricter CAA enforcement
  • You have authorized 4 CAs - consider limiting to only the CAs you actively use
  • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
  • Consider adding 'issuewild' records to control wildcard certificate issuance

Subject Alternative Names

72 domains
wso2.com *.wso2.com access.wso2.com admin-certification.wso2.com allocations.wso2.com apis-dev-internal.wso2.com apis-dev.wso2.com apis-internal.wso2.com apis-stg-internal.wso2.com apis-stg.wso2.com apis.wso2.com apps.wso2.com assets.wso2.com ats-hris.wso2.com banking-hris.wso2.com careers.wso2.com certification.wso2.com deployment-certifier.wso2.com due-diligence.wso2.com ema.wso2.com email-group-manager.wso2.com employee-hris.wso2.com expense-claims.wso2.com leave-hris.wso2.com master-data-finance.wso2.com masterdata-hris.wso2.com mis.wso2.com opd-claims.wso2.com orgchart-hris.wso2.com par-hris.wso2.com pitstop-sales.wso2.com promotion-hris.wso2.com rancher-lk.wso2.com reporting-hris.wso2.com security-advisory.wso2.com staging-partners.wso2.com store.wso2.com subscription-dashboard.wso2.com subscriptions.wso2.com superapp-hris.wso2.com travel.wso2.com umt.wso2.com zkbiocvs.wso2.com a.content.wso2.com api-stg.updates.wso2.com api.updates.wso2.com apim.docs.wso2.com apk.docs.wso2.com b.content.wso2.com bi.docs.wso2.com c.content.wso2.com cdn.updates.wso2.com ciamcloud.docs.wso2.com cloud.docs.wso2.com d.content.wso2.com ei.docs.wso2.com healthcare.docs.wso2.com internal.docs.wso2.com internal.support.wso2.com is.docs.wso2.com mg.docs.wso2.com mi.docs.wso2.com ob.docs.wso2.com security.docs.wso2.com si.docs.wso2.com subscriptions.dv.wso2.com subscriptions.eu.wso2.com subscriptions.st.wso2.com updates.docs.wso2.com berlin.ob.docs.wso2.com cds.ob.docs.wso2.com uk.ob.docs.wso2.com