Summary of g.hass.tsukuba.ac.jp:443 (HTTPS) SSL Security Test
Provided "as is" without any warranty of any kind.
This test was made 2820 days ago and may be outdated
Refresh Test
Date/Time:Dec 30th, 2018 20:32 GMT+0
Source IP/Port:130.158.202.195:443
Protocol:HTTPS
Location:Tsukuba, Japan
Your final score:
- A
- B
- C
- F
F
The server configuration has a good protocol compatibility, allowing users with older browsers to access your website.
Information
The server supports encryption protocols that are insecure and have known security flaws or weaknesses.
Non-compliant with PCI DSS, NIST and HIPAA
The server supports cipher suites that are not approved by PCI DSS requirements, HIPAA guidance and NIST guidelines.
Non-compliant with PCI DSS, NIST and HIPAA
The server has TLS 1.0 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 30th of June 2018.
Non-compliant with PCI DSS requirements
The server is vulnerable to POODLE over SSL attack. Urgently disable support of SSLv3 protocol.
Non-compliant with PCI DSS requirements
Test Results Summary for g.hass.tsukuba.ac.jp
- 1 SSL/TLS end-entity certificate detected: the first certificate is a trusted RSA 2048 bits certificate with issuer Let's Encrypt Authority X3 valid until March 29, 2019. 1 certificate chain detected. Show details.
- 16 of 40 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (SSLv3 and TLSv1.0). There is 1 more issue which makes the server non-compliant with PCI DSS: poodle over ssl. Show details.
- 22 of 40 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.0, TLSv1.1 and TLSv1.2) as well as non-compliant protocols (SSLv3). There are 3 more issues which make the server non-compliant with HIPAA: server does not support OCSP stapling, no support for common curves, EC point format extension. Show details.
- 3 issues related to industry best practices were identified: server does not support TLS 1.3, server does not have cipher preference, server does not provide HSTS. Show details.
Compliance Summary for g.hass.tsukuba.ac.jp
- PCI DSS Compliance Failed: 16 of 40 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (SSLv3 and TLSv1.0). There is 1 more issue which makes the server non-compliant with PCI DSS: poodle over ssl.
- HIPAA Compliance Failed: 22 of 40 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.0, TLSv1.1 and TLSv1.2) as well as non-compliant protocols (SSLv3). There are 3 more issues which make the server non-compliant with HIPAA: server does not support OCSP stapling, no support for common curves, EC point format extension.
- GDPR Compliance Failed: 16 of 40 supported cipher suites are not compliant with GDPR. The server supports GDPR compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (SSLv3 and TLSv1.0). There is 1 more issue which makes the server non-compliant with GDPR: poodle over ssl.