IM Observatory client report for test.lrz.de
Test started 2020-09-11 09:22:40 UTC .
Show server to server result | Permalink to this report
|
jabber-test.srv.lrz.de:5222
Certificate is not trusted, grade capped to F. Ignoring trust: B.
Server uses Diffie-Hellman parameters of < 2048 bits. Grade capped to B.
jabber-test.srv.lrz.de:5222
- StartTLS
- REQUIRED
SASL
Pre-TLS
None
Post-TLS
SRV records
_xmpp-client._tcp.test.lrz.de DNSSEC
Priority |
Weight |
Port |
Server |
0 |
0 |
5222 |
jabber-test.srv.lrz.de |
TLSA records
Certificates
Subject
- commonName
- jabber-test.srv.lrz.de
- countryName
- DE
- localityName
- Muenchen
- organizationName
- Leibniz-Rechenzentrum
- stateOrProvinceName
- Bayern
Details
Error: certificate has expired.
- Signature algorithm
- sha256WithRSAEncryption
- Public key
- 2048 bit RSA
- Valid from
- 2014-09-30 08:52:11 UTC
- Valid to
- 2019-07-09 23:59:00 UTC
- CRL
- http://cdp2.pca.dfn.de/lrz-ca/pub/crl/cacrl.crl
- OCSP
- http://ocsp.pca.dfn.de/OCSP-Server/OCSP
- Valid for test.lrz.de
- YES
-
F3:88:77:1F:66:E4:DF:14:87:D8:F8:E9:48:55:32:85:C8:69:C1:AA
Subject Alternative Names
- DNSName
- jabber-test.srv.lrz.de
- DNSName
- test.lrz.de Matches
Subject
- commonName
- LRZ-CA - G01
- countryName
- DE
- emailAddress
- pki@lrz-muenchen.de
- localityName
- Muenchen
- organizationalUnitName
- LRZ-CA
- organizationName
- Leibniz-Rechenzentrum
- stateOrProvinceName
- Bayern
Details
Error: certificate has expired.
- Signature algorithm
- sha256WithRSAEncryption
- Public key
- 2048 bit RSA
- Valid from
- 2007-01-23 13:03:38 UTC
- Valid to
- 2019-07-09 23:59:00 UTC
- CRL
- http://cdp2.pca.dfn.de/global-root-ca/pub/crl/cacrl.crl
- OCSP
- http://ocsp.pca.dfn.de/OCSP-Server/OCSP
-
68:98:08:AA:CF:1C:9C:F7:4A:35:4A:0B:C4:CD:E5:CE:89:20:E0:2C
Subject
- commonName
- DFN-Verein PCA Global - G01
- countryName
- DE
- organizationalUnitName
- DFN-PKI
- organizationName
- DFN-Verein
Details
Error: certificate has expired.
- Signature algorithm
- sha256WithRSAEncryption
- Public key
- 2048 bit RSA
- Valid from
- 2014-07-22 12:08:26 UTC
- Valid to
- 2019-07-09 23:59:00 UTC
- CRL
- http://pki0336.telesec.de/rl/DT_ROOT_CA_2.crl
- OCSP
- http://ocsp0336.telesec.de/ocspr
-
F4:C5:38:C3:BB:99:4F:13:F8:FD:C2:40:B6:79:A6:4B:19:34:A1:B5
Subject
- commonName
- Deutsche Telekom Root CA 2
- countryName
- DE
- organizationalUnitName
- T-TeleSec Trust Center
- organizationName
- Deutsche Telekom AG
Details
- Signature algorithm
- sha1WithRSAEncryption
- Public key
- 2048 bit RSA
- Valid from
- 1999-07-09 12:11:00 UTC
- Valid to
- 2019-07-09 23:59:00 UTC
-
85:A4:08:C0:9C:19:3E:5D:51:58:7D:CD:D6:13:30:FD:8C:DE:37:BF
Protocols
SSLv2 |
No |
SSLv3 |
No |
TLSv1 |
Yes |
TLSv1.1 |
Yes |
TLSv1.2 |
Yes |
Ciphers
Server does respect the client's cipher ordering.
Cipher suite | Bitsize | Forward secrecy | Info |
ECDHE-RSA-AES256-GCM-SHA384 (0xc030) |
256
|
Yes
|
Curve: secp521r1
|
ECDHE-RSA-AES256-SHA384 (0xc028) |
256
|
Yes
|
Curve: secp521r1
|
ECDHE-RSA-AES256-SHA (0xc014) |
256
|
Yes
|
Curve: secp521r1
|
DHE-RSA-AES256-GCM-SHA384 (0x9f) |
256
|
Yes
|
Diffie-Hellman:
Bitsize: 1024
|
DHE-RSA-AES256-SHA256 (0x6b) |
256
|
Yes
|
Diffie-Hellman:
Bitsize: 1024
|
DHE-RSA-AES256-SHA (0x39) |
256
|
Yes
|
Diffie-Hellman:
Bitsize: 1024
|
AES256-GCM-SHA384 (0x9d) |
256
|
No
|
-
|
AES256-SHA256 (0x3d) |
256
|
No
|
-
|
AES256-SHA (0x35) |
256
|
No
|
-
|
ECDHE-RSA-AES128-GCM-SHA256 (0xc02f) |
128
|
Yes
|
Curve: secp521r1
|
ECDHE-RSA-AES128-SHA256 (0xc027) |
128
|
Yes
|
Curve: secp521r1
|
ECDHE-RSA-AES128-SHA (0xc013) |
128
|
Yes
|
Curve: secp521r1
|
DHE-RSA-AES128-GCM-SHA256 (0x9e) |
128
|
Yes
|
Diffie-Hellman:
Bitsize: 1024
|
DHE-RSA-AES128-SHA256 (0x67) |
128
|
Yes
|
Diffie-Hellman:
Bitsize: 1024
|
DHE-RSA-AES128-SHA (0x33) |
128
|
Yes
|
Diffie-Hellman:
Bitsize: 1024
|
AES128-GCM-SHA256 (0x9c) |
128
|
No
|
-
|
AES128-SHA256 (0x3c) |
128
|
No
|
-
|
AES128-SHA (0x2f) |
128
|
No
|
-
|
Badge
Want to show this result on your webpage? Add this:
<a href='https://xmpp.net/result.php?domain=test.lrz.de&type=client'><img src='https://xmpp.net/badge.php?domain=test.lrz.de' alt='xmpp.net score' /></a>