Open
Cached
·
1h ago
85/100
SECURITY SCORE
Certificate Information
Subject
CN=opennms.org
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
November 05, 2025
Valid Until
February 03, 2026
76 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
0F:DB:68:05:27:AB:49:46:47:8B:40:5E:68:2B:5C:70:80:87:F9:82:57:44:25:C6:3C:57:61:C6:F7:71:13:4A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains;
Content-Security-Policy
Basic
default-src; script-src; img-src; +15 more
default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: *.opennms.com *.opennms.ca wpengine.com forms.hsforms.com secure.gravatar.com track.hubspot.com forms-na1.hsforms.com px.ads.linkedin.com dify.wpengine.com updates.theme-fusion.com www.googletagmanager.com googleads.g.doubleclick.net analytics.google.com alb.reddit.com stats.g.doubleclick.net www.google.com www.google-analytics.com www.facebook.com no-cache.hubspot.com perf.hsforms.com; font-src 'self' data: fonts.gstatic.com fonts.googleapis.com ray.st; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com www.googletagmanager.com ray.st; script-src-elem 'self' 'unsafe-inline' *.opennms.com *.opennms.ca www.google.com www.googletagmanager.com www.gstatic.com www.google-analytics.com www.googleadservices.com js.hs-scripts.com js.hsforms.net js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net snap.licdn.com js.hsadspixel.net ws.zoominfo.com www.redditstatic.com js.usemessages.com connect.facebook.net js.hscta.net cta-service-cms2.hubspot.com; frame-src 'self' www.google.com static.hsappstatic.net app.hubspot.com forms.hsforms.com www.facebook.com *.statuspage.io td.doubleclick.net cta-service-cms2.hubspot.com; connect-src 'self' forms.hubspot.com static.hsappstatic.net app.hubspot.com www.google-analytics.com js.hs-banner.com forms.hsforms.com hubspot-forms-static-embed.s3.amazonaws.com cdn.linkedin.oribi.io api.hubapi.com yoast.com my.wpengine.com forms.hscollectedforms.net ws.zoominfo.com analytics.google.com stats.g.doubleclick.net api.hubspot.com www.facebook.com www.redditstatic.com conversions-config.reddit.com px.ads.linkedin.com cta-service-cms2.hubspot.com; frame-ancestors 'self'; default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: *.opennms.com *.opennms.ca wpengine.com forms.hsforms.com secure.gravatar.com track.hubspot.com forms-na1.hsforms.com px.ads.linkedin.com dify.wpengine.com updates.theme-fusion.com www.googletagmanager.com googleads.g.doubleclick.net analytics.google.com alb.reddit.com stats.g.doubleclick.net www.google.com www.google-analytics.com www.facebook.com no-cache.hubspot.com perf.hsforms.com; font-src 'self' data: fonts.gstatic.com fonts.googleapis.com ray.st; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com www.googletagmanager.com ray.st; script-src-elem 'self' 'unsafe-inline' *.opennms.com *.opennms.ca www.google.com www.googletagmanager.com www.gstatic.com www.google-analytics.com www.googleadservices.com js.hs-scripts.com js.hsforms.net js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net snap.licdn.com js.hsadspixel.net ws.zoominfo.com www.redditstatic.com js.usemessages.com connect.facebook.net js.hscta.net; frame-src 'self' www.google.com static.hsappstatic.net app.hubspot.com forms.hsforms.com www.facebook.com *.statuspage.io td.doubleclick.net cta-service-cms2.hubspot.com; connect-src 'self' forms.hubspot.com static.hsappstatic.net app.hubspot.com www.google-analytics.com js.hs-banner.com forms.hsforms.com hubspot-forms-static-embed.s3.amazonaws.com cdn.linkedin.oribi.io api.hubapi.com yoast.com my.wpengine.com forms.hscollectedforms.net ws.zoominfo.com analytics.google.com stats.g.doubleclick.net api.hubspot.com www.facebook.com www.redditstatic.com conversions-config.reddit.com px.ads.linkedin.com cta-service-cms2.hubspot.com; frame-ancestors 'self';
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports