TLS1.3 | 是 |
TLS1.2 | 是 |
TLS1.1 | 否 |
TLS1.0 | 否 |
SSL3.0 | 否 |
SSL2.0 | 否 |
# TLS1.3 (服务端优先) | |||||
TLS_AES_128_GCM_SHA256(0x1301) | 128 | EDCH | x25519(eq. 3072 bits RSA) | FS | |
TLS_AES_256_GCM_SHA384(0x1302) | 256 | EDCH | x25519(eq. 3072 bits RSA) | FS | |
TLS_CHACHA20_POLY1305_SHA256(0x1303) | 256 | EDCH | x25519(eq. 3072 bits RSA) | FS | |
TLS_AES_128_CCM_SHA256(0x1304) | 128 | EDCH | x25519(eq. 3072 bits RSA) | FS | |
TLS_AES_128_CCM_8_SHA256(0x1305) | 128 | EDCH | x25519(eq. 3072 bits RSA) | FS | |
# TLS1.2 (服务端优先) | |||||
TLS_RSA_WITH_AES_128_GCM_SHA256(0x9C) | 128 | RSA | WEAK | ||
TLS_RSA_WITH_AES_256_GCM_SHA384(0x9D) | 256 | RSA | WEAK | ||
TLS_RSA_WITH_AES_128_CBC_SHA256(0x3C) | 128 | RSA | WEAK | ||
TLS_RSA_WITH_AES_256_CBC_SHA256(0x3D) | 256 | RSA | WEAK | ||
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256(0xC027) | 128 | ECDH | secp256r1(eq. 3072 bits RSA) | FS | WEAK |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384(0xC028) | 256 | ECDH | secp256r1(eq. 3072 bits RSA) | FS | WEAK |
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256(0xC02F) | 128 | ECDH | secp256r1(eq. 3072 bits RSA) | FS | |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384(0xC030) | 256 | ECDH | secp256r1(eq. 3072 bits RSA) | FS | |
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256(0xCCA8) | 256 | ECDH | secp256r1(eq. 3072 bits RSA) | FS | |
TLS_RSA_WITH_AES_128_CBC_SHA(0x2F) | 128 | RSA | WEAK | ||
TLS_RSA_WITH_AES_256_CBC_SHA(0x35) | 256 | RSA | WEAK | ||
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA(0xC013) | 128 | ECDH | secp256r1(eq. 3072 bits RSA) | FS | WEAK |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA(0xC014) | 256 | ECDH | secp256r1(eq. 3072 bits RSA) | FS | WEAK |
安全重协商 | 是 |
安全客户端重协商 | 否 |
不安全客户端重协商 | 否 |
不安全加密套件 | 否 |
SSL/TLS压缩属性 | 否 |
正向加密 | 是 |
Freak漏洞(cve-2015-0204) | 否 |
Crime漏洞(cve-2012-4929) | 否 |
Logjam漏洞(cve-2015-4000) | 否 |
Sweet32漏洞(cve-2016-2183) | 否 |
CCS Injection漏洞(cve-2014-0224) | 否 |
Heartbleed漏洞(cve-2014-0160) | 否 |
TicketBleed漏洞(cve-2016-9244) | 否 |
降级攻击防御 | 是,支持TLS_FALLBACK_SCSV |
ALPN扩展 | 是,h2,h2-14,http/1.1,http/1.0 |
NPN扩展 | 是,h2,h2-14,http/1.1,http/1.0 |
sessionID会话复用 | 否,sessionID被分配,但无法复用 |
Ticket会话复用 | 是 |
OCSP装订 | 否 |
心跳监测 | 否 |
不正确的SNI警告 | 否 |
不安全的DH的质数 | 否 |
DH密钥(Ys)参数重用 | 否 |
ECDH密钥参数重用 | 否 |
(EC)DH密钥交换曲线组 | 是,secp256r1,x25519 |
超大ClientHello兼容 | 否 |
不合规TLS扩展兼容 | 否 |
非法TLS版本兼容 | 否 |
SSLv2协商握手兼容 | 是 |
0-RTT支持 | 否 |
证书状态 | 可 信 |
通用名称(CN) | www.apple.com |
国家(C) | US |
省份(S) | California |
城市(L) | Cupertino |
组织(O) | Apple Inc. |
部门(OU) | |
备用名(AN) | images.apple.com www.apple.com.cn www.apple.com |
通用名称(CN) | Apple Public EV Server RSA CA 2 - G1 |
国家(C) | US |
组织(O) | Apple Inc. |
序列号 | 7413c231334998895b07dbcbb3f42915 |
类别归档 | EV 增强型 |
密钥类型 | RSA (2048) |
签名算法 | SHA256 |
颁发时间 | 2025-03-05 05:24:01 |
过期时间 | 2025-10-17 01:15:35 |
有效期 | 97天 |
吊销状态 | 正 常 |
DNS CAA | 否 |
扩展验证 | 是 |
证书透明度 | 是 |
OCSP强制装订 | 否 |
指纹 | SHA1: 1e389111c5b1e22eb970d566f5c3a804964e3a7a SHA256: 7b7d2e39dae1df6e5143ce4b7335247f1f75a872dff35cf1784dd9cabefe2cc8 |
ca_url | http://certs.apple.com/apevsrsa2g1.der |
ocsp_url | http://ocsp.apple.com/ocsp03-apevsrsa2g101 |
crl_url | http://crl.apple.com/apevsrsa2g1.crl |
序列号 | 07177911005d2267f68892f68f8b5058 |
申请者 | Apple Public EV Server RSA CA 2 - G1 |
密钥类型 | RSA (2048) |
签名算法 | SHA256 |
过期日期 | 2030-04-11 07:59:59(还剩1735天) |
指纹 | SHA1: 8ba88d2c0f20439fb7d00f3910159023cfe91dc8 SHA256: d6ef3e09ebe0d9370e51f5c09a532b3ac70d3ce822253f9fc84c28e9bfa550d5 |
颁发者 | DigiCert High Assurance EV Root CA |
序列号 | 02ac5c266a0b409b8f0b79f2ae462577 |
申请者 | DigiCert High Assurance EV Root CA |
颁发者 | DigiCert High Assurance EV Root CA |
密钥类型 | RSA (2048) |
签名算法 | SHA1 |
过期日期 | 2031-11-10 00:00:00(还剩2313天) |
指纹 | SHA1: 5fb7ee0633e259dbad0c4c9ae6d38f1a61c7dc25 SHA256: 7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf |
Android 7.0.0 | 是 |
Android 6.0.1 | 是 |
Android 5.1.1 | 是 |
Android 5.0.2 | 是 |
IOS 17 | 是 |
IOS 16 | 是 |
IOS 15 | 是 |
IOS 14 | 是 |
IOS 13 | 是 |
IOS 12 | 是 |
IOS 11 | 是 |
IOS 10 | 是 |
IOS 9 | 是 |
IOS 8 | 是 |
IOS 7 | 是 |
HarmonyOS 5.0 | 是 |
HarmonyOS 4.0 | 是 |
HarmonyOS 3.0 | 是 |
HarmonyOS 2.0 | 是 |
Java 8.3611 | 是 |
Android 2.3.7 | Client/Server版本不匹配 |
Android 4.0.4 | Client/Server版本不匹配 |
Android 4.1.1 | Client/Server版本不匹配 |
Android 4.2.2 | Client/Server版本不匹配 |
Android 4.3 | Client/Server版本不匹配 |
Android 4.4.2 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Android 5.0.0 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Android 6.0 | RSA 2048 (SHA256) TLS1.2 http/1.1 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Android 7.0 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
Android 8.0 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
Android 8.1 | - TLS1.3 TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
Android 9.0 | - TLS1.3 TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
Chrome 49/XP SP3 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Chrome 69/Win 7 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
Chrome 70/Win 10 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
Chrome 80/Win 10 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
Firefox 31.3.0 ESR/Win 7 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Firefox 47/Win 7 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Firefox 49/XP SP3 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Firefox 62/Win 7 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
Firefox 73/Win 10 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
IE 6/XP | Client/Server版本不匹配 |
IE 7/Vista | Client/Server版本不匹配 |
IE 8/XP | Client/Server版本不匹配 |
IE 8-10/Win 7 | Client/Server版本不匹配 |
IE 11/Win 7 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDH secp256r1 FS |
IE 11/Win 8.1 | RSA 2048 (SHA256) TLS1.2 http/1.1 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDH secp256r1 FS |
IE 11/Win 10 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Edge 15/Win 10 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Edge 16/Win 10 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Edge 18/Win 10 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Java 6u45 | Client/Server版本不匹配 |
Java 7u25 | Client/Server版本不匹配 |
Java 8u161 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Java 11.0.3 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Java 12.0.1 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH secp256r1 FS |
OpenSSL 0.9.8y | Client/Server版本不匹配 |
OpenSSL 1.0.1l | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
OpenSSL 1.0.2s | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
OpenSSL 1.1.0k | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
OpenSSL 1.1.1c | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
Safari 5.1.9/OS X 10.6.8 | Client/Server版本不匹配 |
Safari 6.0.4/OS X 10.8.4 | Client/Server版本不匹配 |
Safari 6/iOS 6.0.1 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDH secp256r1 FS |
Safari 7/iOS 7.1 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDH secp256r1 FS |
Safari 7/OS X 10.9 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDH secp256r1 FS |
Safari 8/iOS 8.4 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDH secp256r1 FS |
Safari 8/OS X 10.10 | RSA 2048 (SHA256) TLS1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDH secp256r1 FS |
Safari 9/iOS 9 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Safari 9/OS X 10.11 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Safari 10/iOS 10 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Safari 10/OS X 10.12 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Safari 12.1.2/MacOS 10.14.6 Beta | - TLS1.3 TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
Safari 12.1.1/iOS 12.3.1 | - TLS1.3 TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
Apple ATS 9/iOS 9 | RSA 2048 (SHA256) TLS1.2 h2 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS |
HarmonyOS ≤ 4.2.0 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
HarmonyOS 5.0.1 | - TLS1.3 TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
# GET / (HTTP/1.1 200 OK) | |
Server | Apple |
Content-Type | text/html; charset=utf-8 |
Set-Cookie | geo=CN; path=/; domain=www.apple.com.cn |
Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
Vary | Accept-Encoding |
Content-Security-Policy | default-src 'self' blob: data: *.akamaized.net *.apple.com *.apple.com.cn *.apple-mapkit.com *.cdn-apple.com *.organicfruitapps.com; child-src blob: embed.music.apple.com embed.podcasts.apple.com https://recyclingprogram.apple.com.cn https://smb.apple.com swdlp.apple.com www.apple.com.cn www.instagram.com platform.twitter.com www.youtube-nocookie.com; img-src 'unsafe-inline' blob: data: *.apple.com *.apple.com.cn *.apple-mapkit.com *.cdn-apple.com *.mzstatic.com; script-src 'unsafe-inline' 'unsafe-eval' blob: apple.com *.apple.com *.apple.com.cn *.apple-mapkit.com www.instagram.com platform.twitter.com; style-src 'unsafe-inline' *.apple.com *.apple.com.cn |
Referrer-Policy | no-referrer-when-downgrade |
X-XSS-Protection | 1; mode=block |
X-Content-Type-Options | nosniff |
X-Frame-Options | SAMEORIGIN |
Content-Encoding | gzip |
Cache-Control | max-age=0 |
Expires | Thu, 10 Jul 2025 11:17:36 GMT |
Date | Thu, 10 Jul 2025 11:17:36 GMT |
Content-Length | 34349 |
Connection | keep-alive |
X-Xss-Protection | 否 |
Public Key Pinning (HPKP) | 否 |
Public Key Pinning Report-Only | 否 |
Public Key Pinning (Static) | 未知 |
HSTS Preloading | 应用于Chrome、FireFox、Opera、Safari、IE、Edge |