协议版本
TLS1.3
TLS1.2
TLS1.1
TLS1.0
SSL3.0
SSL2.0
加密套件
# TLS1.2 (服务端优先)
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256(0xC027) 128 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256(0xC02F) 128 ECDH secp256r1(eq. 3072 bits RSA) FS
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA(0xC013) 128 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA(0xC014) 256 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
# TLS1.1 (服务端优先)
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA(0xC013) 128 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA(0xC014) 256 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
# TLS1.0 (服务端优先)
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA(0xC013) 128 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA(0xC014) 256 ECDH secp256r1(eq. 3072 bits RSA) FS WEAK
协议详情
安全重协商
安全客户端重协商
不安全客户端重协商
不安全加密套件
SSL/TLS压缩属性
正向加密
Beast漏洞(cve-2011-3389)是,TLS1.0 0xc014
TLS Poodle漏洞(cve-2014-8730)
Freak漏洞(cve-2015-0204)
Crime漏洞(cve-2012-4929)
Logjam漏洞(cve-2015-4000)
Sweet32漏洞(cve-2016-2183)
CCS Injection漏洞(cve-2014-0224)
Heartbleed漏洞(cve-2014-0160)
TicketBleed漏洞(cve-2016-9244)否,不支持ticket恢复
降级攻击防御-,未知
ALPN扩展是,h2,http/1.1
NPN扩展
sessionID会话复用
Ticket会话复用
OCSP装订
心跳监测
不正确的SNI警告
不安全的DH的质数
DH密钥(Ys)参数重用
ECDH密钥参数重用
(EC)DH密钥交换曲线组是,secp256r1,secp384r1
超大ClientHello兼容
不合规TLS扩展兼容
非法TLS版本兼容是,tls2.3,tls2.152
SSLv2协商握手兼容
证书1 (RSA 2048bits With SHA256) With SNI
  • # 1 (服务端返回)
  • 主体信息
证书状态 可 信
通用名称(CN)www.cmu.edu.cn
国家(C)CN
省份(S)辽宁省
城市(L)沈阳市
组织(O)中国医科大学
部门(OU)
备用名(AN)www.cmu.edu.cn cmu.edu.cn
颁发者信息
通用名称(CN)DigiCert Basic EV G2 TLS CN RSA4096 SHA256 2022 CA1
国家(C)US
组织(O)DigiCert, Inc.
证书信息
序列号08df0d219d1514da7af27f915ffaea96
类别归档EV 增强型
密钥类型RSA (2048)
签名算法SHA256
颁发时间2025-04-18 08:00:00
过期时间2026-05-13 07:59:59
有效期306天
吊销状态正 常
DNS CAA
扩展验证
证书透明度
OCSP强制装订
指纹SHA1: dba0b2a4bdf70ed2ca98ee035dca47801bbc172a
SHA256: a2694ee5ed1f74ddd1e4176c35994c1d0ed161cae6fc69d1c545232b01510f84
ca_urlhttp://cacerts.digicert.cn/DigiCertBasicEVG2TLSCNRSA4096SHA2562022CA1.crt
ocsp_urlhttp://ocsp.digicert.cn
crl_urlhttp://crl.digicert.cn/DigiCertBasicEVG2TLSCNRSA4096SHA2562022CA1.crl
证书链
  • 证书数量 3(5066 bytes)
  • 序列问题 是,证书链序列错误
# 2 (服务端返回)
序列号02618648254ce2af26619d994b06be4e
申请者DigiCert Basic EV G2 TLS CN RSA4096 SHA256 2022 CA1
密钥类型RSA (4096)
签名算法SHA256
过期日期2032-12-15 07:59:59(还剩2714天)
指纹SHA1: 02b86911e7b5e10320f8015132d7c12ce012aadf
SHA256: 8534345e71f5450b6bd2758cef8495547008a6e302ac8dac625361cb24dc6bd5
颁发者DigiCert Global Root G2
# 3 (服务端返回)
序列号02618648254ce2af26619d994b06be4e
申请者DigiCert Basic EV G2 TLS CN RSA4096 SHA256 2022 CA1
密钥类型RSA (4096)
签名算法SHA256
过期日期2032-12-15 07:59:59(还剩2714天)
指纹SHA1: 02b86911e7b5e10320f8015132d7c12ce012aadf
SHA256: 8534345e71f5450b6bd2758cef8495547008a6e302ac8dac625361cb24dc6bd5
颁发者DigiCert Global Root G2
# 4 (系统内置根)
序列号033af1e6a711a9a0bb2864b11d09fae5
申请者DigiCert Global Root G2
颁发者DigiCert Global Root G2
密钥类型RSA (2048)
签名算法SHA256
过期日期2038-01-15 12:00:00(还剩4571天)
指纹SHA1: df3c24f9bfd666761b268073fe06d1cc8d4f82a4
SHA256: cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
终端兼容
# 桌面系统
# 移动操作系统
Android 7.0.0
Android 6.0.1
Android 5.1.1
Android 5.0.2
IOS 17
IOS 16
IOS 15
IOS 14
IOS 13
IOS 12
IOS 11
IOS 10
IOS 9
IOS 8
IOS 7
HarmonyOS 5.0
HarmonyOS 4.0
HarmonyOS 3.0
HarmonyOS 2.0
# 后端服务
# 运行环境
Java 8.3611
# 浏览器
客户端模拟
Android 2.3.7程序异常错误
Android 4.0.4RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp256r1    FS
Android 4.1.1RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp384r1    FS
Android 4.2.2RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp384r1    FS
Android 4.3RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp384r1    FS
Android 4.4.2RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 5.0.0RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 6.0RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 7.0RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 8.0RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 8.1RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Android 9.0RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Chrome 49/XP SP3RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Chrome 69/Win 7RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Chrome 70/Win 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Chrome 80/Win 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Firefox 31.3.0 ESR/Win 7RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Firefox 47/Win 7RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Firefox 49/XP SP3RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Firefox 62/Win 7RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Firefox 73/Win 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
IE 6/XPClient/Server版本不匹配
IE 7/VistaRSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp256r1    FS
IE 8/XP程序异常错误
IE 8-10/Win 7RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp256r1    FS
IE 11/Win 7RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   ECDH   secp256r1    FS
IE 11/Win 8.1RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   ECDH   secp256r1    FS
IE 11/Win 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Edge 15/Win 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Edge 16/Win 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Edge 18/Win 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Java 6u45程序异常错误
Java 7u25RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA   ECDH   secp256r1    FS
Java 8u161RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Java 11.0.3RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Java 12.0.1RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
OpenSSL 0.9.8y程序异常错误
OpenSSL 1.0.1lRSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp384r1    FS
OpenSSL 1.0.2sRSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
OpenSSL 1.1.0kRSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
OpenSSL 1.1.1cRSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Safari 5.1.9/OS X 10.6.8RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp256r1    FS
Safari 6.0.4/OS X 10.8.4RSA 2048 (SHA256)      TLS1.0        TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA   ECDH   secp256r1    FS
Safari 6/iOS 6.0.1RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   ECDH   secp256r1    FS
Safari 7/iOS 7.1RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   ECDH   secp256r1    FS
Safari 7/OS X 10.9RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   ECDH   secp256r1    FS
Safari 8/iOS 8.4RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   ECDH   secp256r1    FS
Safari 8/OS X 10.10RSA 2048 (SHA256)      TLS1.2        TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   ECDH   secp256r1    FS
Safari 9/iOS 9RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Safari 9/OS X 10.11RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Safari 10/iOS 10RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Safari 10/OS X 10.12RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Safari 12.1.2/MacOS 10.14.6 BetaRSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Safari 12.1.1/iOS 12.3.1RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
Apple ATS 9/iOS 9RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
HarmonyOS ≤ 4.2.0RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
HarmonyOS 5.0.1RSA 2048 (SHA256)      TLS1.2  http/1.1      TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   ECDH   secp256r1    FS
响应数据
# GET / (HTTP/1.1 200 OK)
DateThu, 10 Jul 2025 12:48:24 GMT
Server*********
X-Frame-OptionsSAMEORIGIN
Strict-Transport-Securitymax-age=63072000; includeSubdomains; preload
X-XSS-Protection1; mode=block
X-Content-Type-Optionsnosniff
X-Download-Optionsnoopen
Referer-Policyno-referer-when-downgrade
X-Permitted-Cross-Domain-Policiesmaster-only
Last-ModifiedThu, 10 Jul 2025 06:36:30 GMT
Accept-Rangesbytes
VaryUser-Agent,Accept-Encoding
Cache-Controlprivate, max-age=600
ExpiresThu, 10 Jul 2025 12:58:24 GMT
Content-Encodinggzip
ETag"17309-6398d69e9739c-gzip"
Content-Length14612
Content-Typetext/html
Content-Languagezh-CN
增强项[可选]
X-Xss-Protection
Public Key Pinning (HPKP)
Public Key Pinning Report-Only
Public Key Pinning (Static)未知
HSTS Preloading应用于Chrome、FireFox、Opera、Safari、IE、Edge