Persistent report
pintelly.com SSL certificate report
Last analyzed:
Available again in 5:00
Score history
2 days · min 86 · max 86 · 0
CN
pintelly.com
Remaining
48d
Key
ec 256 bit
Signature
ecdsa-with-SHA256
TLS
TLSv1.3
Cipher
TLS_AES_256_GCM_SHA384
ALPN
h2
IP
188.114.97.7
Server
cloudflare
1
On
1.1
On
1.2
On
1.3
On
To-do, by priority
Fails first, then warnings. Tips are things this HTML fetch cannot see.
HTTPSPassHTTPS
+
HTTPS
Why it matters: Search and browsers treat HTTP as not secure.
Trusted certificatePassTrusted
+
Trusted
Why it matters: An untrusted chain is a browser warning, not a ranking bonus.
Name matches hostPasspintelly.com
+
pintelly.com
Why it matters: The certificate must cover this hostname (CN or SAN), including wildcards.
ExpiryPass48 days
+
48 days
Why it matters: An expired cert is an interstitial. Under 30 days is a calendar problem.
Self-signedPassCA-signed
+
CA-signed
Why it matters: A leaf that signs itself is not trusted by browsers.
Certificate chainPass3 certificates
+
3 certificates
Why it matters: The server must send intermediates. A missing WE1/GTS link is the usual 'works on my machine, fails on mobile' install bug.
Signature algorithmPassecdsa-with-SHA256
+
ecdsa-with-SHA256
Why it matters: SHA-1 and MD5 signatures are rejected by current browsers.
Public keyPassec · 256 bit · prime256v1
+
ec · 256 bit · prime256v1
Why it matters: RSA below 2048 bits, or a tiny curve, is too weak.
Negotiated protocolPassTLSv1.3 · h2 · TLS_AES_256_GCM_SHA384
+
TLSv1.3 · h2 · TLS_AES_256_GCM_SHA384
Why it matters: What this handshake actually spoke. A modern client will pick 1.2 or 1.3 when the server offers them.
TLS 1.0 / 1.1Error1.0 yes · 1.1 yes · 1.2 yes · 1.3 yes
+
1.0 yes · 1.1 yes · 1.2 yes · 1.3 yes
Why it matters: SSL Labs caps the grade at B if either protocol is still accepted — even when modern clients negotiate 1.3. That is a server offer, not this handshake.
What to do
Disable TLS 1.0 and 1.1 on the edge (Cloudflare: SSL/TLS → Edge Certificates → disable legacy, or the origin nginx/caddy config).
HSTSWarningNo HSTS
+
No HSTS
Why it matters: Without Strict-Transport-Security a first visit can still go via HTTP.
What to do
Send the HSTS header on HTTPS. Full scoring is on the security headers tool.
CAAInfoNo CAA
+
No CAA
Why it matters: DNS CAA lists which CAs may issue for the domain. Optional, but Labs and CAs honour it.
IssuerInfoGoogle Trust Services / WE1
+
Google Trust Services / WE1
Why it matters: Who signed the leaf. Informational.
Certificate chain
The chain the server sent. The root (GlobalSign, etc.) lives in the client store and is often omitted.
Certificate #1
- CN
- pintelly.com
- Issuer
- Google Trust Services / WE1
- Valid
- Aug 8 12:38:36 2026 GMT → Nov 6 13:36:03 2026 GMT
- Signature
- ecdsa-with-SHA256
- Key
- ec · 256 bit · prime256v1
- Serial
- C767C35727A132CB0E6A42A40E1E57EC
- SHA-256
- 8E:54:DA:5B:34:9E:D3:C7:AE:C2:A9:0D:E8:19:9C:B4:75:BC:36:E3:A3:C2:5C:23:ED:D7:47:12:D0:8D:92:DB
Certificate #2
- CN
- WE1
- Organization
- Google Trust Services
- Issuer
- Google Trust Services LLC / GTS Root R4
- Valid
- Dec 13 09:00:00 2023 GMT → Feb 20 14:00:00 2029 GMT
- Signature
- ecdsa-with-SHA384
- Key
- ec · 256 bit · prime256v1
- Serial
- 7FF31977972C224A76155D13B6D685E3
- SHA-256
- 1D:FC:16:05:FB:AD:35:8D:8B:C8:44:F7:6D:15:20:3F:AC:9C:A5:C1:A7:9F:D4:85:7F:FA:F2:86:4F:BE:BF:96
Certificate #3
- CN
- GTS Root R4
- Organization
- Google Trust Services LLC
- Issuer
- GlobalSign nv-sa / GlobalSign Root CA
- Valid
- Nov 15 03:43:21 2023 GMT → Jan 28 00:00:42 2028 GMT
- Signature
- sha256WithRSAEncryption
- Key
- ec · 384 bit · secp384r1
- Serial
- 7FE530BF331343BEDD821610493D8A1B
- SHA-256
- 76:B2:7B:80:A5:80:27:DC:3C:F1:DA:68:DA:C1:70:10:ED:93:99:7D:0B:60:3E:2F:AD:BE:85:01:24:93:B5:A7
SAN
pintelly.com, *.pintelly.com
Get this report by email on a schedule, with what changed since last time.

