IM Observatory client report for nktalk.pl

Test started 2018-06-19 04:38:37 UTC .

Show server to server result | Permalink to this report | Retest

xmpp.nktalk.pl:5222
Server uses Diffie-Hellman parameters of < 2048 bits. Grade capped to B.
xmpp.nktalk.pl:5222
StartTLS
REQUIRED

SASL

Pre-TLS

None

Post-TLS
PLAIN

SRV records _xmpp-client._tcp.nktalk.pl NO DNSSEC

Priority Weight Port Server
5 0 5222 xmpp.nktalk.pl

TLSA records

Certificates

Subject
commonName
nktalk.pl
countryName
PL
localityName
Krakow
organizationalUnitName
IT Operations
organizationName
Onet S.A.
Details
Signature algorithm
sha256WithRSAEncryption
Public key
2048 bit RSA
Valid from
2018-03-08 00:00:00 UTC
Valid to
2019-05-07 12:00:00 UTC
CRL
http://cdp.geotrust.com/GeoTrustRSACA2018.crl
OCSP
http://status.geotrust.com
Valid for nktalk.pl
YES
C2:2E:0E:3F:7C:2A:24:0E:52:1F:A2:9E:1D:6A:4C:98:D3:EB:08:8F
Subject Alternative Names
DNSName
nktalk.pl Matches
DNSName
www.nktalk.pl
Subject
commonName
GeoTrust RSA CA 2018
countryName
US
organizationalUnitName
www.digicert.com
organizationName
DigiCert Inc
Details
Signature algorithm
sha256WithRSAEncryption
Public key
2048 bit RSA
Valid from
2017-11-06 12:23:45 UTC
Valid to
2027-11-06 12:23:45 UTC
CRL
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
OCSP
http://ocsp.digicert.com
7C:CC:2A:87:E3:94:9F:20:57:2B:18:48:29:80:50:5F:A9:0C:AC:3B
Subject
commonName
DigiCert Global Root CA
countryName
US
organizationalUnitName
www.digicert.com
organizationName
DigiCert Inc
Details
Signature algorithm
sha1WithRSAEncryption
Public key
2048 bit RSA
Valid from
2006-11-10 00:00:00 UTC
Valid to
2031-11-10 00:00:00 UTC
A8:98:5D:3A:65:E5:E5:C4:B2:D7:D6:6D:40:C6:DD:2F:B1:9C:54:36

Protocols

SSLv2 No
SSLv3 No
TLSv1 Yes
TLSv1.1 Yes
TLSv1.2 Yes

Ciphers

Server does not respect the client's cipher ordering.

Cipher suiteBitsizeForward secrecyInfo
ECDHE-RSA-AES256-GCM-SHA384 (0xc030) 256 Yes Curve: prime256v1
ECDHE-RSA-AES128-GCM-SHA256 (0xc02f) 128 Yes Curve: prime256v1
ECDHE-RSA-AES256-SHA384 (0xc028) 256 Yes Curve: prime256v1
ECDHE-RSA-AES128-SHA256 (0xc027) 128 Yes Curve: prime256v1
ECDHE-RSA-AES256-SHA (0xc014) 256 Yes Curve: prime256v1
ECDHE-RSA-AES128-SHA (0xc013) 128 Yes Curve: prime256v1
ECDHE-RSA-DES-CBC3-SHA (0xc012) WEAK 112 Yes Curve: prime256v1
DHE-RSA-AES256-GCM-SHA384 (0x9f) 256 Yes Diffie-Hellman:
Group: RFC 5114 1024-bit MODP Group with 160-bit Prime Order Subgroup
Bitsize: 1024
DHE-RSA-AES128-GCM-SHA256 (0x9e) 128 Yes Diffie-Hellman:
Group: RFC 5114 1024-bit MODP Group with 160-bit Prime Order Subgroup
Bitsize: 1024
DHE-RSA-AES256-SHA256 (0x6b) 256 Yes Diffie-Hellman:
Group: RFC 5114 1024-bit MODP Group with 160-bit Prime Order Subgroup
Bitsize: 1024
DHE-RSA-AES128-SHA256 (0x67) 128 Yes Diffie-Hellman:
Group: RFC 5114 1024-bit MODP Group with 160-bit Prime Order Subgroup
Bitsize: 1024
DHE-RSA-AES256-SHA (0x39) 256 Yes Diffie-Hellman:
Group: RFC 5114 1024-bit MODP Group with 160-bit Prime Order Subgroup
Bitsize: 1024
DHE-RSA-AES128-SHA (0x33) 128 Yes Diffie-Hellman:
Group: RFC 5114 1024-bit MODP Group with 160-bit Prime Order Subgroup
Bitsize: 1024
EDH-RSA-DES-CBC3-SHA (0x16) WEAK 112 Yes Diffie-Hellman:
Group: RFC 5114 1024-bit MODP Group with 160-bit Prime Order Subgroup
Bitsize: 1024
AES256-GCM-SHA384 (0x9d) 256 No -
AES128-GCM-SHA256 (0x9c) 128 No -
AES256-SHA256 (0x3d) 256 No -
AES128-SHA256 (0x3c) 128 No -
AES256-SHA (0x35) 256 No -
AES128-SHA (0x2f) 128 No -
DES-CBC3-SHA (0xa) WEAK 112 No -

Badge

xmpp.net score

Want to show this result on your webpage? Add this:

<a href='https://xmpp.net/result.php?domain=nktalk.pl&amp;type=client'><img src='https://xmpp.net/badge.php?domain=nktalk.pl' alt='xmpp.net score' /></a>