[aklug] TLS kudos to Tex R Us

From: Royce Williams <royce@tycho.org>
Date: Sat Aug 15 2015 - 21:29:39 AKDT

Assuming that some Tex R Us folks are still on the list ...

Nice work on your TLS! The 'mail' and 'cloud' hosts need a little more
tweaking, but dashboard and nanaportal are in great shape! Is the TLS on
these sites provided by Softlayer in some way, or are you hand-crafting
these configs?

HostTest dateGradeCert expiresRevocCert issuerCert chainSSLv2SSLv3TLS1.0
TLS1.1TLS1.2BEAST vulnCRIME vulnHeartbleed vulnCCS vulnPOODLE
SSLPOODLE TLSFREAK
vulnWeak DHDH primesReneg issuesMain sigAlgint SHA1RC4Key strFwd
SecSCSVHSTSServer
signatureRisk score â–¾Test ver*dashboard.texrus.com
<https://dashboard.texrus.com/>*
184.173.124.120
(184.173.124.120-static.reverse.softlayer.com)
Qualys <https://www.ssllabs.com/ssltest/analyze.html?d=dashboard.texrus.com>
 | JSON
<http://www.techsolvency.com/tls/data/json/dashboard.texrus.com.json.txt> |
dump
<http://www.techsolvency.com/tls/data/dump/dashboard.texrus.com.dump.txt> |
www <https://www.dashboard.texrus.com/>2015-08-14 10:26:08A+exp: 2018-07-24cert
not revoked (2)common issuer (Go Daddy)chain OK (0)no SSLv2no
SSLv3TLS1.0 onTLS1.1
onTLS1.2 onBEAST vulnno CRIMEno HeartbleedCCS OK (1)no POODLE SSLno POODLE
TLS (1)no FREAKno weak DHstrong custom(2) sec sv renegSHA256 RSAno SHA1 intno
RC4keystr 4096all FS (4)has SCSVmax-age 15552000nginx01.19.33*texrus.com
<https://texrus.com/>*
184.173.124.120
(184.173.124.120-static.reverse.softlayer.com)
Qualys <https://www.ssllabs.com/ssltest/analyze.html?d=texrus.com> | JSON
<http://www.techsolvency.com/tls/data/json/texrus.com.json.txt> | dump
<http://www.techsolvency.com/tls/data/dump/texrus.com.dump.txt> |www
<https://www.texrus.com/>2015-08-14 10:24:20A+exp: 2018-07-24cert not
revoked (2)common issuer (Go Daddy)chain OK (0)no SSLv2no SSLv3TLS1.0 onTLS1.1
onTLS1.2 onBEAST vulnno CRIMEno HeartbleedCCS OK (1)no POODLE SSLno POODLE
TLS (1)no FREAKno weak DHstrong custom(2) sec sv renegSHA256 RSAno SHA1 intno
RC4keystr 4096all FS (4)has SCSVmax-age
15552000nginx01.19.33*nanaportal.texrus.com
<https://nanaportal.texrus.com/>*
184.173.124.123
(no DNS PTR)
Qualys
<https://www.ssllabs.com/ssltest/analyze.html?d=nanaportal.texrus.com> |
JSON
<http://www.techsolvency.com/tls/data/json/nanaportal.texrus.com.json.txt>
 | dump
<http://www.techsolvency.com/tls/data/dump/nanaportal.texrus.com.dump.txt> |
www <https://www.nanaportal.texrus.com/>2015-08-14 10:26:49A+exp:
2018-07-24cert
not revoked (2)common issuer (Go Daddy)chain OK (0)no SSLv2no
SSLv3TLS1.0 onTLS1.1
onTLS1.2 onBEAST vulnno CRIMEno HeartbleedCCS OK (1)no POODLE SSLno POODLE
TLS (1)no FREAKno weak DHstrong custom(2) sec sv renegSHA256 RSAno SHA1 intno
RC4keystr 4096all FS (4)has SCSVmax-age 15552000nginx01.19.33*mail.texrus.com
<https://mail.texrus.com/>*
63.140.106.98
(mail.texrus.com)
Qualys <https://www.ssllabs.com/ssltest/analyze.html?d=mail.texrus.com> |
JSON <http://www.techsolvency.com/tls/data/json/mail.texrus.com.json.txt> |
dump <http://www.techsolvency.com/tls/data/dump/mail.texrus.com.dump.txt> |
www <https://www.mail.texrus.com/>2015-08-14 10:25:55Aexp: 2018-07-24cert
not revoked (2)common issuer (Go Daddy)chain OK (0)no SSLv2no
SSLv3TLS1.0 onTLS1.1
onTLS1.2 onBEAST vulnno CRIMEno HeartbleedCCS OK (1)no POODLE SSLno POODLE
TLS (1)no FREAKno weak DHno primes(2) sec sv renegSHA256 RSAno SHA1 intno
RC4keystr 4096modern FS (2)no SCSVno HSTSMicrosoft
IIS/8.531.19.33*cloud.texrus.com
<https://cloud.texrus.com/>*
216.126.46.105
(cloud.texrus.com)
Qualys <https://www.ssllabs.com/ssltest/analyze.html?d=cloud.texrus.com> |
JSON <http://www.techsolvency.com/tls/data/json/cloud.texrus.com.json.txt>
 | dump
<http://www.techsolvency.com/tls/data/dump/cloud.texrus.com.dump.txt> |www
<https://www.cloud.texrus.com/>2015-08-14 10:25:27Bexp: 2015-10-22cert not
revoked (2)common issuer (Go Daddy)chain: incomplete (2);no SSLv2no SSLv3TLS1.0
onTLS1.1 onTLS1.2 onBEAST vulnno CRIMEno HeartbleedCCS OK (1)no POODLE SSLno
POODLE TLS (1)no FREAKDH weak (1024)strong custom(6) sec cl reneg (DoS),
sec sv renegSHA256 RSAno SHA1 intno RC4keystr 2048all FS (4)has SCSVno
HSTSKerio
Connect 8.5.181.19.33

Royce

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Sat Aug 15 21:30:31 2015

This archive was generated by hypermail 2.1.8 : Sat Aug 15 2015 - 21:30:31 AKDT