IM Observatory client report for tokmo.net

Test started 2018-10-10 04:34:38 UTC .

Show server to server result | Permalink to this report | Retest

tokmo.net:5222
Certificate is not trusted, grade capped to F. Ignoring trust: C.
Warning: Server allows RC4 when using TLS 1.1 and/or TLS 1.2. Grade capped to C.
tokmo.net:5222
StartTLS
REQUIRED

SASL

Pre-TLS

None

Post-TLS
DIGEST-MD5
EXTERNAL
PLAIN

SRV records _xmpp-client._tcp.tokmo.net NO DNSSEC

Priority Weight Port Server

TLSA records

Certificates

Subject
commonName
tokmo.net
Details
Error: certificate has expired.
Signature algorithm
sha256WithRSAEncryption
Public key
2048 bit RSA
Valid from
2017-01-28 14:36:00 UTC
Valid to
2017-04-28 14:36:00 UTC
OCSP
http://ocsp.int-x3.letsencrypt.org/
Valid for tokmo.net
YES
34:CB:CE:B8:F4:03:7C:B3:0C:4D:56:08:9C:57:21:EF:91:01:0A:5E
Subject Alternative Names
DNSName
mail.tokmo.net
DNSName
tokmo.net Matches
Subject
commonName
Let's Encrypt Authority X3
countryName
US
organizationName
Let's Encrypt
Details
Signature algorithm
sha256WithRSAEncryption
Public key
2048 bit RSA
Valid from
2016-03-17 16:40:46 UTC
Valid to
2021-03-17 16:40:46 UTC
CRL
http://crl.identrust.com/DSTROOTCAX3CRL.crl
OCSP
http://isrg.trustid.ocsp.identrust.com
E6:A3:B4:5B:06:2D:50:9B:33:82:28:2D:19:6E:FE:97:D5:95:6C:CB
Subject
commonName
DST Root CA X3
organizationName
Digital Signature Trust Co.
Details
Signature algorithm
sha1WithRSAEncryption
Public key
2048 bit RSA
Valid from
2000-09-30 21:12:19 UTC
Valid to
2021-09-30 14:01:15 UTC
DA:C9:02:4F:54:D8:F6:DF:94:93:5F:B1:73:26:38:CA:6A:D7:7C:13

Protocols

SSLv2 No
SSLv3 No
TLSv1 Yes
TLSv1.1 Yes
TLSv1.2 Yes

Ciphers

Server does respect the client's cipher ordering.

Cipher suiteBitsizeForward secrecyInfo
ECDHE-RSA-AES256-GCM-SHA384 (0xc030) 256 Yes Curve: sect571r1
ECDHE-RSA-AES256-SHA384 (0xc028) 256 Yes Curve: sect571r1
ECDHE-RSA-AES256-SHA (0xc014) 256 Yes Curve: sect571r1
DHE-RSA-AES256-GCM-SHA384 (0x9f) 256 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DHE-RSA-CAMELLIA256-SHA (0x88) 256 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DHE-RSA-AES256-SHA256 (0x6b) 256 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DHE-RSA-AES256-SHA (0x39) 256 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
AES256-GCM-SHA384 (0x9d) 256 No -
CAMELLIA256-SHA (0x84) 256 No -
AES256-SHA256 (0x3d) 256 No -
AES256-SHA (0x35) 256 No -
ECDHE-RSA-AES128-GCM-SHA256 (0xc02f) 128 Yes Curve: sect571r1
ECDHE-RSA-AES128-SHA256 (0xc027) 128 Yes Curve: sect571r1
ECDHE-RSA-AES128-SHA (0xc013) 128 Yes Curve: sect571r1
ECDHE-RSA-RC4-SHA (0xc011) 128 Yes Curve: sect571r1
DHE-RSA-AES128-GCM-SHA256 (0x9e) 128 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DHE-RSA-SEED-SHA (0x9a) 128 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DHE-RSA-AES128-SHA256 (0x67) 128 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DHE-RSA-CAMELLIA128-SHA (0x45) 128 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DHE-RSA-AES128-SHA (0x33) 128 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
RC4-MD5 (0x10080) 128 No -
AES128-GCM-SHA256 (0x9c) 128 No -
SEED-SHA (0x96) 128 No -
CAMELLIA128-SHA (0x41) 128 No -
AES128-SHA256 (0x3c) 128 No -
AES128-SHA (0x2f) 128 No -
IDEA-CBC-SHA (0x7) 128 No -
RC4-SHA (0x5) 128 No -
ECDHE-RSA-DES-CBC3-SHA (0xc012) WEAK 112 Yes Curve: sect571r1
EDH-RSA-DES-CBC3-SHA (0x16) WEAK 112 Yes Diffie-Hellman:
Group: RFC 3526 2048-bit MODP Group
Bitsize: 2048
DES-CBC3-SHA (0xa) WEAK 112 No -

Badge

xmpp.net score

Want to show this result on your webpage? Add this:

<a href='https://xmpp.net/result.php?domain=tokmo.net&amp;type=client'><img src='https://xmpp.net/badge.php?domain=tokmo.net' alt='xmpp.net score' /></a>