Check Detail
example.com · SSL
Passed
Grade A
100.0%
Result Detail
SSL| Check name | Status | Value |
|---|---|---|
| certificate chain is complete | ✅ Passed | 5 |
| root CA is trusted | ✅ Passed | Trusted |
| cert valid for | ✅ Passed | 60 |
| chain certs are valid until | ✅ Passed | 16.03.2026 |
| CN matches Domainname | ✅ Passed | example.com |
| certificate subject | ✅ Passed | CN=example.com |
| certificate issuer | ✅ Passed | C=US, O=SSL Corporation, CN=Cloudflare TLS Issuing ECC CA 3 |
| signature algorithm | ✅ Passed | ecdsa-with-SHA256 |
| TLS protocol | ✅ Passed | TLSv1.3 TLS_AES_256_GCM_SHA384 |
| Subject Alternative Names | ✅ Passed | example.com, *.example.com |
| Public Key | ✅ Passed | EC 256 |
Certificate chain
| # | Common name | Issuer | Valid until | CA |
|---|---|---|---|---|
| 0 | example.com | C=US, O=SSL Corporation, CN=Cloudflare TLS Issuing ECC CA 3 | 16.03.2026 19:32:44 | No |
| 1 | example.com | C=US, O=SSL Corporation, CN=Cloudflare TLS Issuing ECC CA 3 | 16.03.2026 19:32:44 | No |
| 2 | Cloudflare TLS Issuing ECC CA 3 | C=US, O=SSL Corporation, CN=SSL.com TLS Transit ECC CA R2 | 27.05.2035 21:49:44 | Yes |
| 3 | SSL.com TLS Transit ECC CA R2 | C=US, O=SSL Corporation, CN=SSL.com TLS ECC Root CA 2022 | 17.10.2037 19:02:22 | Yes |
| 4 | SSL.com TLS ECC Root CA 2022 | C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services | 01.01.2029 00:59:59 | Yes |
TLS details
| Negotiated protocol | TLSv1.3 |
|---|---|
| Cipher suite | TLS_AES_256_GCM_SHA384 (256 bit) |
| Cipher version | TLSv1.3 |
| Perfect Forward Secrecy | Attention |
| Earliest chain expiry | 16.03.2026 19:32 |
Fingerprints
| SHA-256 | 73:4F:E7:8D:7E:FB:6F:83:4F:AA:76:5A:58:AB:7D:A8:CC:7D:FF:D3:E0:5C:EB:76:9D:C5:BD:65:0D:3C:9F:9B |
|---|---|
| SHA-1 | 95:7D:B6:33:05:63:85:E7:61:77:C9:41:19:EB:93:99:F2:3C:21:18 |
Revocation
OCSP URLs
http://o.cf-i.ssl.com
CRL URLs
Full Name:
URI:http://c.cf-i.ssl.com/ae801ed1c55bb579d79208b0d772acfb8cc3a208.crl
Issuer URLs (AIA)
http://i.cf-i.ssl.com/Cloudflare-TLS-I-E3.cer
OCSP Must-Staple
No
Trust evaluation
Attempted: Yes
Trusted: Yes
OpenSSL diagnostic command
openssl s_client -connect example.com:443 -servername example.com