LucyLee

서버 SSL/TLS 테스트 받아보기

· 2017-12-04 (월) 10:43:06 · 1698 · 1
Protocol Details
DROWN No, server keys and hostname not seen elsewhere with SSLv2
(1) For a better understanding of this test, please read this longer explanation
(2) Key usage data kindly provided by the Censys network search engine; original DROWN website here
(3) Censys data is only indicative of possible key and certificate reuse; possibly out-of-date and not complete
Secure Renegotiation Supported
Secure Client-Initiated Renegotiation No
Insecure Client-Initiated Renegotiation No
BEAST attack Not mitigated server-side (more info)   SSL 3: 0xa, TLS 1.0: 0xa
POODLE (SSLv3) Vulnerable   INSECURE (more info)   SSL 3: 0xa
POODLE (TLS) No (more info)
Downgrade attack prevention Yes, TLS_FALLBACK_SCSV supported (more info)
SSL/TLS compression No
RC4 Yes   INSECURE (more info)
Heartbeat (extension) Yes
Heartbleed (vulnerability) No (more info)
Ticketbleed (vulnerability) No (more info)
OpenSSL CCS vuln. (CVE-2014-0224) No (more info)
OpenSSL Padding Oracle vuln.
(CVE-2016-2107)
No (more info)
Forward Secrecy With some browsers (more info)

 

 

등등......

 

SSL 인증서랑 서버의 프로토콜 체크 해주네요

 

아파치 SSL 설정 보완해야 할거 같아요

 

|

댓글 1개

좋은 사이트네요 ㅎ
댓글을 작성하시려면 로그인이 필요합니다.

자유게시판

202,899건
+
제목 글쓴이 날짜 조회
17-12-04 조회 1,248
17-12-04 조회 1,930
17-12-04 조회 1,396
17-12-04 조회 1,290
17-12-04 조회 3,255
17-12-04 조회 1,290
17-12-04 조회 7,128
17-12-04 조회 1,302
17-12-04 조회 1,699
17-12-04 조회 1,418
17-12-03 조회 1,615
17-12-03 조회 1,262
17-12-03 조회 1,677
17-12-03 조회 1,377
17-12-03 조회 2,050
17-12-02 조회 1,331
17-12-02 조회 1,281
17-12-02 조회 1,533
17-12-02 조회 1,290
17-12-02 조회 1,372