Persistent report

pintelly.com SSL certificate report

Last analyzed:

Available again in 5:00

Score history

2 days · min 86 · max 86 · 0

025507510011 Sept · 86/100 (B)18 Sept · 86/100 (B)11 Sept18 Sept

CN

pintelly.com

Remaining

48d

Key

ec 256 bit

Signature

ecdsa-with-SHA256

TLS

TLSv1.3

Cipher

TLS_AES_256_GCM_SHA384

ALPN

h2

IP

188.114.97.7

Server

cloudflare

1

On

1.1

On

1.2

On

1.3

On

To-do, by priority

Fails first, then warnings. Tips are things this HTML fetch cannot see.

HTTPSPass

HTTPS

+

Why it matters: Search and browsers treat HTTP as not secure.

Trusted certificatePass

Trusted

+

Why it matters: An untrusted chain is a browser warning, not a ranking bonus.

Name matches hostPass

pintelly.com

+

Why it matters: The certificate must cover this hostname (CN or SAN), including wildcards.

ExpiryPass

48 days

+

Why it matters: An expired cert is an interstitial. Under 30 days is a calendar problem.

Self-signedPass

CA-signed

+

Why it matters: A leaf that signs itself is not trusted by browsers.

Certificate chainPass

3 certificates

+

Why it matters: The server must send intermediates. A missing WE1/GTS link is the usual 'works on my machine, fails on mobile' install bug.

Signature algorithmPass

ecdsa-with-SHA256

+

Why it matters: SHA-1 and MD5 signatures are rejected by current browsers.

Public keyPass

ec · 256 bit · prime256v1

+

Why it matters: RSA below 2048 bits, or a tiny curve, is too weak.

Negotiated protocolPass

TLSv1.3 · h2 · TLS_AES_256_GCM_SHA384

+

Why it matters: What this handshake actually spoke. A modern client will pick 1.2 or 1.3 when the server offers them.

TLS 1.0 / 1.1Error

1.0 yes · 1.1 yes · 1.2 yes · 1.3 yes

+

Why it matters: SSL Labs caps the grade at B if either protocol is still accepted — even when modern clients negotiate 1.3. That is a server offer, not this handshake.

1

What to do

Disable TLS 1.0 and 1.1 on the edge (Cloudflare: SSL/TLS → Edge Certificates → disable legacy, or the origin nginx/caddy config).

HSTSWarning

No HSTS

+

Why it matters: Without Strict-Transport-Security a first visit can still go via HTTP.

1

What to do

Send the HSTS header on HTTPS. Full scoring is on the security headers tool.

CAAInfo

No CAA

+

Why it matters: DNS CAA lists which CAs may issue for the domain. Optional, but Labs and CAs honour it.

IssuerInfo

Google Trust Services / WE1

+

Why it matters: Who signed the leaf. Informational.

Certificate chain

The chain the server sent. The root (GlobalSign, etc.) lives in the client store and is often omitted.

Certificate #1

CN
pintelly.com
Issuer
Google Trust Services / WE1
Valid
Aug 8 12:38:36 2026 GMT → Nov 6 13:36:03 2026 GMT
Signature
ecdsa-with-SHA256
Key
ec · 256 bit · prime256v1
Serial
C767C35727A132CB0E6A42A40E1E57EC
SHA-256
8E:54:DA:5B:34:9E:D3:C7:AE:C2:A9:0D:E8:19:9C:B4:75:BC:36:E3:A3:C2:5C:23:ED:D7:47:12:D0:8D:92:DB

Certificate #2

CN
WE1
Organization
Google Trust Services
Issuer
Google Trust Services LLC / GTS Root R4
Valid
Dec 13 09:00:00 2023 GMT → Feb 20 14:00:00 2029 GMT
Signature
ecdsa-with-SHA384
Key
ec · 256 bit · prime256v1
Serial
7FF31977972C224A76155D13B6D685E3
SHA-256
1D:FC:16:05:FB:AD:35:8D:8B:C8:44:F7:6D:15:20:3F:AC:9C:A5:C1:A7:9F:D4:85:7F:FA:F2:86:4F:BE:BF:96

Certificate #3

CN
GTS Root R4
Organization
Google Trust Services LLC
Issuer
GlobalSign nv-sa / GlobalSign Root CA
Valid
Nov 15 03:43:21 2023 GMT → Jan 28 00:00:42 2028 GMT
Signature
sha256WithRSAEncryption
Key
ec · 384 bit · secp384r1
Serial
7FE530BF331343BEDD821610493D8A1B
SHA-256
76:B2:7B:80:A5:80:27:DC:3C:F1:DA:68:DA:C1:70:10:ED:93:99:7D:0B:60:3E:2F:AD:BE:85:01:24:93:B5:A7

SAN

pintelly.com, *.pintelly.com

Get this report by email on a schedule, with what changed since last time.