协议版本
TLS1.3
TLS1.2
TLS1.1
TLS1.0
SSL3.0
SSL2.0
加密套件
# TLS1.3 (服务端优先)
TLS_AES_128_GCM_SHA256(0x1301) 128 EDCH x25519(eq. 3072 bits RSA) FS
TLS_AES_256_GCM_SHA384(0x1302) 256 EDCH x25519(eq. 3072 bits RSA) FS
TLS_CHACHA20_POLY1305_SHA256(0x1303) 256 EDCH x25519(eq. 3072 bits RSA) FS
TLS_AES_128_CCM_SHA256(0x1304) 128 EDCH x25519(eq. 3072 bits RSA) FS
TLS_AES_128_CCM_8_SHA256(0x1305) 128 EDCH x25519(eq. 3072 bits RSA) FS
# TLS1.2 (服务端优先)
TLS_RSA_WITH_AES_128_GCM_SHA256(0x9C) 128 RSA WEAK
TLS_RSA_WITH_AES_256_GCM_SHA384(0x9D) 256 RSA WEAK
TLS_RSA_WITH_AES_128_CBC_SHA256(0x3C) 128 RSA WEAK
TLS_RSA_WITH_AES_256_CBC_SHA256(0x3D) 256 RSA WEAK
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256(0xC027) 128 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384(0xC028) 256 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256(0xC02F) 128 ECDH secp256r1(eq. 3072 bits RSA) FS
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384(0xC030) 256 ECDH secp256r1(eq. 3072 bits RSA) FS
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256(0xCCA8) 256 ECDH secp256r1(eq. 3072 bits RSA) FS
TLS_RSA_WITH_AES_128_CBC_SHA(0x2F) 128 RSA WEAK
TLS_RSA_WITH_AES_256_CBC_SHA(0x35) 256 RSA WEAK
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA(0xC013) 128 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA(0xC014) 256 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
协议详情
安全重协商
安全客户端重协商
不安全客户端重协商
不安全加密套件
SSL/TLS压缩属性
正向加密
Freak漏洞(cve-2015-0204)
Crime漏洞(cve-2012-4929)
Logjam漏洞(cve-2015-4000)
Sweet32漏洞(cve-2016-2183)
CCS Injection漏洞(cve-2014-0224)
Heartbleed漏洞(cve-2014-0160)
TicketBleed漏洞(cve-2016-9244)
降级攻击防御是,支持TLS_FALLBACK_SCSV
ALPN扩展是,h2,h2-14,http/1.1,http/1.0
NPN扩展是,h2,h2-14,http/1.1,http/1.0
sessionID会话复用否,sessionID被分配,但无法复用
Ticket会话复用
OCSP装订
心跳监测
不正确的SNI警告
不安全的DH的质数
DH密钥(Ys)参数重用
ECDH密钥参数重用
(EC)DH密钥交换曲线组是,secp256r1,x25519
超大ClientHello兼容
不合规TLS扩展兼容
非法TLS版本兼容
SSLv2协商握手兼容
0-RTT支持
证书1 (RSA 2048bits With SHA256) With SNI
  • # 1 (服务端返回)
  • 主体信息
证书状态 可 信
通用名称(CN)www.apple.com
国家(C)US
省份(S)California
城市(L)Cupertino
组织(O)Apple Inc.
部门(OU)
备用名(AN)images.apple.com www.apple.com.cn www.apple.com
颁发者信息
通用名称(CN)Apple Public EV Server RSA CA 2 - G1
国家(C)US
组织(O)Apple Inc.
证书信息
序列号7413c231334998895b07dbcbb3f42915
类别归档EV 增强型
密钥类型RSA (2048)
签名算法SHA256
颁发时间2025-03-05 05:24:01
过期时间2025-10-17 01:15:35
有效期97天
吊销状态正 常
DNS CAA
扩展验证
证书透明度
OCSP强制装订
指纹SHA1: 1e389111c5b1e22eb970d566f5c3a804964e3a7a
SHA256: 7b7d2e39dae1df6e5143ce4b7335247f1f75a872dff35cf1784dd9cabefe2cc8
ca_urlhttp://certs.apple.com/apevsrsa2g1.der
ocsp_urlhttp://ocsp.apple.com/ocsp03-apevsrsa2g101
crl_urlhttp://crl.apple.com/apevsrsa2g1.crl
证书链
  • 证书数量 2(3253 bytes)
  • 序列问题 否,证书链正确
# 2 (服务端返回)
序列号07177911005d2267f68892f68f8b5058
申请者Apple Public EV Server RSA CA 2 - G1
密钥类型RSA (2048)
签名算法SHA256
过期日期2030-04-11 07:59:59(还剩1735天)
指纹SHA1: 8ba88d2c0f20439fb7d00f3910159023cfe91dc8
SHA256: d6ef3e09ebe0d9370e51f5c09a532b3ac70d3ce822253f9fc84c28e9bfa550d5
颁发者DigiCert High Assurance EV Root CA
# 3 (系统内置根)
序列号02ac5c266a0b409b8f0b79f2ae462577
申请者DigiCert High Assurance EV Root CA
颁发者DigiCert High Assurance EV Root CA
密钥类型RSA (2048)
签名算法SHA1
过期日期2031-11-10 00:00:00(还剩2313天)
指纹SHA1: 5fb7ee0633e259dbad0c4c9ae6d38f1a61c7dc25
SHA256: 7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf
终端兼容
# 桌面系统
# 移动操作系统
Android 7.0.0
Android 6.0.1
Android 5.1.1
Android 5.0.2
IOS 17
IOS 16
IOS 15
IOS 14
IOS 13
IOS 12
IOS 11
IOS 10
IOS 9
IOS 8
IOS 7
HarmonyOS 5.0
HarmonyOS 4.0
HarmonyOS 3.0
HarmonyOS 2.0
# 后端服务
# 运行环境
Java 8.3611
# 浏览器
客户端模拟
Android 2.3.7Client/Server版本不匹配
Android 4.0.4Client/Server版本不匹配
Android 4.1.1Client/Server版本不匹配
Android 4.2.2Client/Server版本不匹配
Android 4.3Client/Server版本不匹配
Android 4.4.2RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Android 5.0.0RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 6.0RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 7.0RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256   ECDH   secp256r1    FS
Android 8.0RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256   ECDH   secp256r1    FS
Android 8.1-      TLS1.3        TLS_CHACHA20_POLY1305_SHA256   ECDH   x25519    FS
Android 9.0-      TLS1.3        TLS_CHACHA20_POLY1305_SHA256   ECDH   x25519    FS
Chrome 49/XP SP3RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Chrome 69/Win 7-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
Chrome 70/Win 10-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
Chrome 80/Win 10-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
Firefox 31.3.0 ESR/Win 7RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Firefox 47/Win 7RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Firefox 49/XP SP3RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Firefox 62/Win 7-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
Firefox 73/Win 10-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
IE 6/XPClient/Server版本不匹配
IE 7/VistaClient/Server版本不匹配
IE 8/XPClient/Server版本不匹配
IE 8-10/Win 7Client/Server版本不匹配
IE 11/Win 7RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   ECDH   secp256r1    FS
IE 11/Win 8.1RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   ECDH   secp256r1    FS
IE 11/Win 10RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Edge 15/Win 10RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Edge 16/Win 10RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Edge 18/Win 10RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Java 6u45Client/Server版本不匹配
Java 7u25Client/Server版本不匹配
Java 8u161RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Java 11.0.3-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Java 12.0.1-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   secp256r1    FS
OpenSSL 0.9.8yClient/Server版本不匹配
OpenSSL 1.0.1lRSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
OpenSSL 1.0.2sRSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
OpenSSL 1.1.0k-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
OpenSSL 1.1.1c-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
Safari 5.1.9/OS X 10.6.8Client/Server版本不匹配
Safari 6.0.4/OS X 10.8.4Client/Server版本不匹配
Safari 6/iOS 6.0.1RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   ECDH   secp256r1    FS
Safari 7/iOS 7.1RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   ECDH   secp256r1    FS
Safari 7/OS X 10.9RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   ECDH   secp256r1    FS
Safari 8/iOS 8.4RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   ECDH   secp256r1    FS
Safari 8/OS X 10.10RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   ECDH   secp256r1    FS
Safari 9/iOS 9RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Safari 9/OS X 10.11RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Safari 10/iOS 10RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Safari 10/OS X 10.12RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
Safari 12.1.2/MacOS 10.14.6 Beta-      TLS1.3        TLS_CHACHA20_POLY1305_SHA256   ECDH   x25519    FS
Safari 12.1.1/iOS 12.3.1-      TLS1.3        TLS_CHACHA20_POLY1305_SHA256   ECDH   x25519    FS
Apple ATS 9/iOS 9RSA 2048 (SHA256)      TLS1.2  h2      TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   ECDH   secp256r1    FS
HarmonyOS ≤ 4.2.0-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
HarmonyOS 5.0.1-      TLS1.3        TLS_AES_256_GCM_SHA384   ECDH   x25519    FS
响应数据
# GET / (HTTP/1.1 200 OK)
ServerApple
Content-Typetext/html; charset=utf-8
Set-Cookiegeo=CN; path=/; domain=www.apple.com.cn
Strict-Transport-Securitymax-age=31536000; includeSubdomains; preload
VaryAccept-Encoding
Content-Security-Policydefault-src 'self' blob: data: *.akamaized.net *.apple.com *.apple.com.cn *.apple-mapkit.com *.cdn-apple.com *.organicfruitapps.com; child-src blob: embed.music.apple.com embed.podcasts.apple.com https://recyclingprogram.apple.com.cn https://smb.apple.com swdlp.apple.com www.apple.com.cn www.instagram.com platform.twitter.com www.youtube-nocookie.com; img-src 'unsafe-inline' blob: data: *.apple.com *.apple.com.cn *.apple-mapkit.com *.cdn-apple.com *.mzstatic.com; script-src 'unsafe-inline' 'unsafe-eval' blob: apple.com *.apple.com *.apple.com.cn *.apple-mapkit.com www.instagram.com platform.twitter.com; style-src 'unsafe-inline' *.apple.com *.apple.com.cn
Referrer-Policyno-referrer-when-downgrade
X-XSS-Protection1; mode=block
X-Content-Type-Optionsnosniff
X-Frame-OptionsSAMEORIGIN
Content-Encodinggzip
Cache-Controlmax-age=0
ExpiresThu, 10 Jul 2025 11:17:36 GMT
DateThu, 10 Jul 2025 11:17:36 GMT
Content-Length34349
Connectionkeep-alive
增强项[可选]
X-Xss-Protection
Public Key Pinning (HPKP)
Public Key Pinning Report-Only
Public Key Pinning (Static)未知
HSTS Preloading应用于Chrome、FireFox、Opera、Safari、IE、Edge