Summary of webuydzstore.youcan.store:443 (HTTPS) SSL Security Test
Provided "as is" without any warranty of any kind.
This test was made 592 days ago and may be outdated
Refresh Test
Date/Time:Feb 5th, 2025 13:15 GMT+0
Source IP/Port:172.64.80.1:443
Protocol:HTTPS
Location:N/A, United States
Your final score:
- A
- B
- C
- F
A
The server has TLS 1.0 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 30th of June 2018.
Non-compliant with PCI DSS and NIST
The server has TLS 1.1 enabled. NIST recommends to drop TLS 1.1 support since SP 800-52 REV. 2
Information
The server supports the most recent and secure TLS protocol version of TLS 1.3.
Good configuration
Test Results Summary for webuydzstore.youcan.store
- 1 SSL/TLS end-entity certificate detected: the first certificate is a trusted ECDSA 256 bits certificate with issuer WE1 valid until April 10, 2025. 3 certificate chains detected. Show details.
- All 9 supported cipher suites are compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1, TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with PCI DSS: P-256, P-384, P-521 and X25519. No additional PCI DSS compliance issues were identified. Show details.
- All 9 supported cipher suites are compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.1, TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with HIPAA: P-256, P-384, P-521 and X25519. No additional HIPAA compliance issues were identified. Show details.
- 1 issue related to industry best practices was identified: server does not provide HSTS. Show details.
Compliance Summary for webuydzstore.youcan.store
- PCI DSS Compliance Failed: All 9 supported cipher suites are compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1, TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with PCI DSS: P-256, P-384, P-521 and X25519. No additional PCI DSS compliance issues were identified.
- HIPAA Compliance Failed: All 9 supported cipher suites are compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.1, TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with HIPAA: P-256, P-384, P-521 and X25519. No additional HIPAA compliance issues were identified.
- GDPR Compliance Failed: All 9 supported cipher suites are compliant with GDPR. The server supports GDPR compliant protocols (TLSv1.1, TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with GDPR: P-256, P-384, P-521 and X25519. No additional GDPR compliance issues were identified.


