Open
Cached
·
just now
84/100
SECURITY SCORE
Certificate Information
Subject
C=AT, ST=Wien, O=Wirtschaftsuniversität Wien, CN=www.wu.ac.at
Issuer
C=NL, O=GEANT Vereniging, CN=GEANT OV RSA CA 4
Valid From
December 16, 2024
Valid Until
December 16, 2025
8 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA384-RSA
SHA-256 Fingerprint
75:8C:C3:3A:16:E7:4F:28:2C:5C:94:25:34:01:AD:47:F6:99:3F:8F:65:9D:A3:CA:D2:8A:55:BE:60:7E:AA:0A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
default-src; img-src; script-src; +9 more
default-src 'self'; img-src https: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://chatbot.wu.ac.at https://static.ads-twitter.com https://*.licdn.com https://*.twitter.com https://www.googletagmanager.com https://demo.mindbreeze.com https://www.google.com/recaptcha/* https://www.googleadservices.com https://*.googlesyndication.com https://*.azurewebsites.net https://*.cloudflare.com https://s.ytimg.com https://www.youtube.com https://piwik.wu.ac.at https://ajax.googleapis.com https://maps.googleapis.com https://*.newrelic.com https://*.nr-data.net https://platform.twitter.com https://connect.facebook.net https://*.vo.msecnd.net/ https://newsletter.wu.ac.at/ https://wu.ac.at/typo3temp/hotfix/hotfix.js https://wu.ac.at/typo3temp/hotfix/extension.js https://wu.ac.at/typo3temp/hotfix/cooperationtemplate/cooperation.js https://www.wu.ac.at/typo3temp/hotfix/extension/readcsv.js https://www.wu.ac.at/typo3temp/hotfix/extension/bawiso.js https://www.wu.ac.at/typo3temp/chatbot/chatbot.js https://static.hotjar.com https://script.hotjar.com https://*.clickdimensions.com; style-src 'self' 'unsafe-inline' https://*.sms.ingress.wu.ac.at https://*.azurewebsites.net https://*.clickdimensions.com https://demo.mindbreeze.com https://*.fabasoft.com https://piwik.wu.ac.at/ https://wu.ac.at/typo3temp/hotfix/hotfix.css https://wu.ac.at/typo3temp/hotfix/cooperationtemplate/cooperation.css https://www.wu.ac.at/typo3temp/hotfix/extension/readcsv.css https://www.wu.ac.at/typo3temp/hotfix/extension/bawiso.css https://www.wu.ac.at/typo3temp/chatbot/chatbot.css https://www.googleadservices.com https://fonts.googleapis.com https://*.vo.msecnd.net/; frame-src https:; frame-ancestors 'self' https://wuvienna.atlassian.net https://jsm-survey.its.ingress.wu.ac.at https://servicekatalog-fe.wu.ac.at https://piwik.wu.ac.at/; font-src 'self' https://fonts.gstatic.com; connect-src 'self' wss://api.azure-cloud.aios.dev https://*.sms.ingress.wu.ac.at https://chatbot.wu.ac.at https://googleads.g.doubleclick.net https://www.google-analytics.com https://*.google-analytics.com https://www.googleadservices.com https://www.google.com https://maps.googleapis.com https://region1.analytics.google.com/* https://region1.analytics.google.com/g/collect https://*.azurewebsites.net https://*.googlesyndication.com https://vimeo.com https://bach.wu.ac.at https://apps.wu.ac.at https://cdn.linkedin.oribi.io https://facebook.com/tr/ https://puredata.wu.ac.at https://servicekatalog-fe.wu.ac.at https://jsm-survey.its.ingress.wu.ac.at wss://ws.hotjar.com https://content.hotjar.io https://metrics.hotjar.io https://my.zbp.at/de/jobs; form-action 'self' https:; media-src 'self'; object-src 'self'; manifest-src 'self'
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports