Guest session
Check Detail

demo.testfire.net · SSL

Passed Grade A
100.0%
Hostname demo.testfire.net
Check name SSL
last run 12/06/2026 16:35
Result
Incomplete Grade C 70.5%

Result Detail

SSL
Check name Status Value
certificate chain is complete ✅ Passed 5
root CA is trusted ✅ Passed Trusted
cert valid for ✅ Passed 9
chain certs are valid until ✅ Passed 22.06.2026
CN matches Domainname ✅ Passed demo.testfire.net
certificate subject ✅ Passed CN=demo.testfire.net
certificate issuer ✅ Passed C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA
signature algorithm ✅ Passed RSA-SHA256
TLS protocol ✅ Passed TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
Subject Alternative Names ✅ Passed demo.testfire.net
Public Key ✅ Passed RSA 2048
Certificate chain
# Common name Issuer Valid until CA
0 demo.testfire.net C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA 22.06.2026 01:59:59 No
1 demo.testfire.net C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA 22.06.2026 01:59:59 No
2 Sectigo RSA Domain Validation Secure Server CA C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority 01.01.2031 00:59:59 Yes
3 USERTrust RSA Certification Authority C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services 01.01.2029 00:59:59 Yes
4 AAA Certificate Services C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services 01.01.2029 00:59:59 Yes
TLS details
Negotiated protocol TLSv1.2
Cipher suite ECDHE-RSA-AES128-GCM-SHA256 (128 bit)
Cipher version TLSv1.2
Perfect Forward Secrecy OK
Earliest chain expiry 22.06.2026 01:59
Fingerprints
SHA-256 B0:EA:C2:25:50:1D:B5:94:A9:63:9F:9E:71:8B:C0:36:75:9B:9F:49:2C:7C:72:9A:60:C8:47:35:68:39:33:82
SHA-1 A1:E9:8D:60:38:8B:84:F4:BB:C5:50:D7:B6:1B:B2:B0:CC:89:61:FD
Revocation
OCSP URLs
http://ocsp.sectigo.com
CRL URLs
Issuer URLs (AIA)
http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt
OCSP Must-Staple No
Trust evaluation

Attempted: Yes

Trusted: Yes

OpenSSL diagnostic command
openssl s_client -connect demo.testfire.net:443 -servername demo.testfire.net