SSL Report: draft-www.island.health (16.52.63.246)
Assessed on:  Tue, 14 Oct 2025 13:12:04 UTC | Clear cache

Due to a recently discovered bug in Apple's code, your browser is exposed to MITM attacks. Click here for more information.

Summary
Overall Rating
A
0
20
40
60
80
100
Certificate
 
Protocol Support
 
Key Exchange
 
Cipher Strength
 

Visit our documentation page for more information, configuration guides, and books. Known issues are documented here.
This site works only in browsers with SNI support.
This server supports TLS 1.3.  MORE INFO »
Certificate #1: EC 256 bits (SHA384withECDSA)
Server Key and Certificate #1
Subject draft-www.island.health
Fingerprint SHA256: 714b109640874559c872fdc7d98555ec8f5ff9e1c50b4dbfda0c61935b687582
Pin SHA256: qlkJZN4uLMVCuEOJer/+LpVQ1/JICICtW7Qkdnkb0fw=
Common names draft-www.island.health
Alternative names draft-www.island.health edit-draft-www.island.health
Serial Number 057fcff4d3eb8262b87671c805fa7a60460e
Valid from Fri, 03 Oct 2025 15:16:46 UTC
Valid until Thu, 01 Jan 2026 15:16:45 UTC (expires in 2 months and 17 days)
Key EC 256 bits
Weak key (Debian) No
Issuer E8
AIA: http://e8.i.lencr.org/
Signature algorithm SHA384withECDSA
Extended Validation No
Certificate Transparency Yes (certificate)
OCSP Must Staple No
Revocation information CRL
CRL: http://e8.c.lencr.org/15.crl
Revocation status Good (not revoked)
DNS CAA No (more info)
Trusted Yes
Mozilla  Apple  Android  Java  Windows 


Additional Certificates (if supplied)
Certificates provided 2 (2070 bytes)
Chain issues None
#2
Subject E8
Fingerprint SHA256: 83624fd338c8d9b023c18a67cb7a9c0519da43d11775b4c6cbdad45c3d997c52
Pin SHA256: iFvwVyJSxnQdyaUvUERIf+8qk7gRze3612JMwoO3zdU=
Valid until Fri, 12 Mar 2027 23:59:59 UTC (expires in 1 year and 4 months)
Key EC 384 bits
Issuer ISRG Root X1
Signature algorithm SHA256withRSA


Certification Paths
Path #1: Trusted
1 Sent by server draft-www.island.health
Fingerprint SHA256: 714b109640874559c872fdc7d98555ec8f5ff9e1c50b4dbfda0c61935b687582
Pin SHA256: qlkJZN4uLMVCuEOJer/+LpVQ1/JICICtW7Qkdnkb0fw=

EC 256 bits / SHA384withECDSA
2 Sent by server E8
Fingerprint SHA256: 83624fd338c8d9b023c18a67cb7a9c0519da43d11775b4c6cbdad45c3d997c52
Pin SHA256: iFvwVyJSxnQdyaUvUERIf+8qk7gRze3612JMwoO3zdU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Trusted
1 Sent by server draft-www.island.health
Fingerprint SHA256: 714b109640874559c872fdc7d98555ec8f5ff9e1c50b4dbfda0c61935b687582
Pin SHA256: qlkJZN4uLMVCuEOJer/+LpVQ1/JICICtW7Qkdnkb0fw=

EC 256 bits / SHA384withECDSA
2 Sent by server E8
Fingerprint SHA256: 83624fd338c8d9b023c18a67cb7a9c0519da43d11775b4c6cbdad45c3d997c52
Pin SHA256: iFvwVyJSxnQdyaUvUERIf+8qk7gRze3612JMwoO3zdU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Trusted
1 Sent by server draft-www.island.health
Fingerprint SHA256: 714b109640874559c872fdc7d98555ec8f5ff9e1c50b4dbfda0c61935b687582
Pin SHA256: qlkJZN4uLMVCuEOJer/+LpVQ1/JICICtW7Qkdnkb0fw=

EC 256 bits / SHA384withECDSA
2 Sent by server E8
Fingerprint SHA256: 83624fd338c8d9b023c18a67cb7a9c0519da43d11775b4c6cbdad45c3d997c52
Pin SHA256: iFvwVyJSxnQdyaUvUERIf+8qk7gRze3612JMwoO3zdU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Trusted
1 Sent by server draft-www.island.health
Fingerprint SHA256: 714b109640874559c872fdc7d98555ec8f5ff9e1c50b4dbfda0c61935b687582
Pin SHA256: qlkJZN4uLMVCuEOJer/+LpVQ1/JICICtW7Qkdnkb0fw=

EC 256 bits / SHA384withECDSA
2 Sent by server E8
Fingerprint SHA256: 83624fd338c8d9b023c18a67cb7a9c0519da43d11775b4c6cbdad45c3d997c52
Pin SHA256: iFvwVyJSxnQdyaUvUERIf+8qk7gRze3612JMwoO3zdU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Trusted
1 Sent by server draft-www.island.health
Fingerprint SHA256: 714b109640874559c872fdc7d98555ec8f5ff9e1c50b4dbfda0c61935b687582
Pin SHA256: qlkJZN4uLMVCuEOJer/+LpVQ1/JICICtW7Qkdnkb0fw=

EC 256 bits / SHA384withECDSA
2 Sent by server E8
Fingerprint SHA256: 83624fd338c8d9b023c18a67cb7a9c0519da43d11775b4c6cbdad45c3d997c52
Pin SHA256: iFvwVyJSxnQdyaUvUERIf+8qk7gRze3612JMwoO3zdU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA

Click here to expand

Certificate #2: EC 256 bits (SHA384withECDSA)
Server Key and Certificate #1
Subject edit-draft-www.island.health
Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440
Pin SHA256: 8k7V1yhEAUVHnD1I7cYnWumrfqExIb8J1I8w/4JT7g0=
Common names edit-draft-www.island.health
Alternative names edit-draft-www.island.health   MISMATCH
Serial Number 06dc3826f08bc3da8c574d35b594bdb6ca2b
Valid from Sat, 04 Oct 2025 05:39:22 UTC
Valid until Fri, 02 Jan 2026 05:39:21 UTC (expires in 2 months and 18 days)
Key EC 256 bits
Weak key (Debian) No
Issuer E7
AIA: http://e7.i.lencr.org/
Signature algorithm SHA384withECDSA
Extended Validation No
Certificate Transparency Yes (certificate)
OCSP Must Staple No
Revocation information CRL
CRL: http://e7.c.lencr.org/44.crl
Revocation status Good (not revoked)
Trusted No   NOT TRUSTED
Mozilla  Apple  Android  Java  Windows 


Additional Certificates (if supplied)
Certificates provided 2 (2050 bytes)
Chain issues None
#2
Subject E7
Fingerprint SHA256: aeb1fd7410e83bc96f5da3c6a7c2c1bb836d1fa5cb86e708515890e428a8770b
Pin SHA256: y7xVm0TVJNahMr2sZydE2jQH8SquXV9yLF9seROHHHU=
Valid until Fri, 12 Mar 2027 23:59:59 UTC (expires in 1 year and 4 months)
Key EC 384 bits
Issuer ISRG Root X1
Signature algorithm SHA256withRSA


Certification Paths
Path #1: Not trusted (invalid certificate [Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440])
1 Sent by server edit-draft-www.island.health
Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440
Pin SHA256: 8k7V1yhEAUVHnD1I7cYnWumrfqExIb8J1I8w/4JT7g0=

EC 256 bits / SHA384withECDSA
2 Sent by server E7
Fingerprint SHA256: aeb1fd7410e83bc96f5da3c6a7c2c1bb836d1fa5cb86e708515890e428a8770b
Pin SHA256: y7xVm0TVJNahMr2sZydE2jQH8SquXV9yLF9seROHHHU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Not trusted (invalid certificate [Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440])
1 Sent by server edit-draft-www.island.health
Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440
Pin SHA256: 8k7V1yhEAUVHnD1I7cYnWumrfqExIb8J1I8w/4JT7g0=

EC 256 bits / SHA384withECDSA
2 Sent by server E7
Fingerprint SHA256: aeb1fd7410e83bc96f5da3c6a7c2c1bb836d1fa5cb86e708515890e428a8770b
Pin SHA256: y7xVm0TVJNahMr2sZydE2jQH8SquXV9yLF9seROHHHU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Not trusted (invalid certificate [Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440])
1 Sent by server edit-draft-www.island.health
Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440
Pin SHA256: 8k7V1yhEAUVHnD1I7cYnWumrfqExIb8J1I8w/4JT7g0=

EC 256 bits / SHA384withECDSA
2 Sent by server E7
Fingerprint SHA256: aeb1fd7410e83bc96f5da3c6a7c2c1bb836d1fa5cb86e708515890e428a8770b
Pin SHA256: y7xVm0TVJNahMr2sZydE2jQH8SquXV9yLF9seROHHHU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Not trusted (invalid certificate [Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440])
1 Sent by server edit-draft-www.island.health
Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440
Pin SHA256: 8k7V1yhEAUVHnD1I7cYnWumrfqExIb8J1I8w/4JT7g0=

EC 256 bits / SHA384withECDSA
2 Sent by server E7
Fingerprint SHA256: aeb1fd7410e83bc96f5da3c6a7c2c1bb836d1fa5cb86e708515890e428a8770b
Pin SHA256: y7xVm0TVJNahMr2sZydE2jQH8SquXV9yLF9seROHHHU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA
Path #1: Not trusted (invalid certificate [Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440])
1 Sent by server edit-draft-www.island.health
Fingerprint SHA256: 2e54811d3385659e042ebb78c3d1ecf27b9f9beb77ffd0237a2339e2d4465440
Pin SHA256: 8k7V1yhEAUVHnD1I7cYnWumrfqExIb8J1I8w/4JT7g0=

EC 256 bits / SHA384withECDSA
2 Sent by server E7
Fingerprint SHA256: aeb1fd7410e83bc96f5da3c6a7c2c1bb836d1fa5cb86e708515890e428a8770b
Pin SHA256: y7xVm0TVJNahMr2sZydE2jQH8SquXV9yLF9seROHHHU=

EC 384 bits / SHA256withRSA
3 In trust store ISRG Root X1   Self-signed
Fingerprint SHA256: 96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
Pin SHA256: C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=

RSA 4096 bits (e 65537) / SHA256withRSA

Click here to expand

Click here to expand

Configuration
Protocols
TLS 1.3 Yes
TLS 1.2 Yes*
TLS 1.1 No
TLS 1.0 No
SSL 3 No
SSL 2 No
(*) Experimental: Server negotiated using No-SNI


Cipher Suites
# TLS 1.3 (server has no preference)
TLS_AES_128_GCM_SHA256 (0x1301)   ECDH x25519 (eq. 3072 bits RSA)   FS 128
TLS_AES_256_GCM_SHA384 (0x1302)   ECDH x25519 (eq. 3072 bits RSA)   FS 256
TLS_CHACHA20_POLY1305_SHA256 (0x1303)   ECDH x25519 (eq. 3072 bits RSA)   FS 256
# TLS 1.2 (server has no preference)
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b)   ECDH secp521r1 (eq. 15360 bits RSA)   FS 128
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a)   ECDH secp521r1 (eq. 15360 bits RSA)   FS   WEAK 256
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (0xc024)   ECDH secp521r1 (eq. 15360 bits RSA)   FS   WEAK 256
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02c)   ECDH secp521r1 (eq. 15360 bits RSA)   FS 256
TLS_ECDHE_ECDSA_WITH_AES_256_CCM (0xc0ad)   ECDH secp521r1 (eq. 15360 bits RSA)   FS 256
TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 (0xc0af)   ECDH secp521r1 (eq. 15360 bits RSA)   FS 256


Handshake Simulation
Android 4.4.2 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp521r1  FS
Android 5.0.0 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA   ECDH secp521r1  FS
Android 6.0 EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH secp256r1  FS
Android 7.0 EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH x25519  FS
Android 8.0 EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH x25519  FS
Android 8.1 -   TLS 1.3 TLS_CHACHA20_POLY1305_SHA256   ECDH x25519  FS
Android 9.0 -   TLS 1.3 TLS_CHACHA20_POLY1305_SHA256   ECDH x25519  FS
BingPreview Jan 2015 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp521r1  FS
Chrome 49 / XP SP3 Server sent fatal alert: handshake_failure
Chrome 69 / Win 7  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH x25519  FS
Chrome 70 / Win 10 -   TLS 1.3 TLS_AES_128_GCM_SHA256   ECDH x25519  FS
Chrome 80 / Win 10  R -   TLS 1.3 TLS_AES_128_GCM_SHA256   ECDH x25519  FS
Firefox 31.3.0 ESR / Win 7 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH secp256r1  FS
Firefox 47 / Win 7  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH secp256r1  FS
Firefox 49 / XP SP3 EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH secp256r1  FS
Firefox 62 / Win 7  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH x25519  FS
Firefox 73 / Win 10  R -   TLS 1.3 TLS_AES_128_GCM_SHA256   ECDH x25519  FS
Googlebot Feb 2018 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH x25519  FS
IE 11 / Win 7  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
IE 11 / Win 8.1  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
IE 11 / Win Phone 8.1  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDH secp256r1  FS
IE 11 / Win Phone 8.1 Update  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
IE 11 / Win 10  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
Edge 15 / Win 10  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH x25519  FS
Edge 16 / Win 10  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH x25519  FS
Edge 18 / Win 10  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH x25519  FS
Edge 13 / Win Phone 10  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
Java 8u161 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   ECDH secp256r1  FS
Java 11.0.3 -   TLS 1.3 TLS_AES_128_GCM_SHA256   ECDH secp256r1  FS
Java 12.0.1 -   TLS 1.3 TLS_AES_128_GCM_SHA256   ECDH secp256r1  FS
OpenSSL 1.0.1l  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp521r1  FS
OpenSSL 1.0.2s  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
OpenSSL 1.1.0k  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH x25519  FS
OpenSSL 1.1.1c  R -   TLS 1.3 TLS_AES_256_GCM_SHA384   ECDH x25519  FS
Safari 6 / iOS 6.0.1 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   ECDH secp256r1  FS
Safari 7 / iOS 7.1  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   ECDH secp256r1  FS
Safari 7 / OS X 10.9  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   ECDH secp256r1  FS
Safari 8 / iOS 8.4  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   ECDH secp256r1  FS
Safari 8 / OS X 10.10  R EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   ECDH secp256r1  FS
Safari 9 / iOS 9  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
Safari 9 / OS X 10.11  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
Safari 10 / iOS 10  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
Safari 10 / OS X 10.12  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
Safari 12.1.2 / MacOS 10.14.6 Beta  R -   TLS 1.3 TLS_CHACHA20_POLY1305_SHA256   ECDH x25519  FS
Safari 12.1.1 / iOS 12.3.1  R -   TLS 1.3 TLS_CHACHA20_POLY1305_SHA256   ECDH x25519  FS
Apple ATS 9 / iOS 9  R EC 256 (SHA384)   TLS 1.2 > http/1.1   TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp256r1  FS
Yahoo Slurp Jan 2015 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp384r1  FS
YandexBot Jan 2015 EC 256 (SHA384)   TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDH secp521r1  FS
# Not simulated clients (Protocol mismatch)
Android 2.3.7   No SNI 2 Protocol mismatch (not simulated)
Android 4.0.4 Protocol mismatch (not simulated)
Android 4.1.1 Protocol mismatch (not simulated)
Android 4.2.2 Protocol mismatch (not simulated)
Android 4.3 Protocol mismatch (not simulated)
Baidu Jan 2015 Protocol mismatch (not simulated)
IE 6 / XP   No FS 1   No SNI 2 Protocol mismatch (not simulated)
IE 7 / Vista Protocol mismatch (not simulated)
IE 8 / XP   No FS 1   No SNI 2 Protocol mismatch (not simulated)
IE 8-10 / Win 7  R Protocol mismatch (not simulated)
IE 10 / Win Phone 8.0 Protocol mismatch (not simulated)
Java 6u45   No SNI 2 Protocol mismatch (not simulated)
Java 7u25 Protocol mismatch (not simulated)
OpenSSL 0.9.8y Protocol mismatch (not simulated)
Safari 5.1.9 / OS X 10.6.8 Protocol mismatch (not simulated)
Safari 6.0.4 / OS X 10.8.4  R Protocol mismatch (not simulated)

Click here to expand

(1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it.
(2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI.
(3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version.
(R) Denotes a reference browser or client, with which we expect better effective security.
(All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE).
(All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake.


Protocol Details
Secure Renegotiation Supported
Secure Client-Initiated Renegotiation No
Insecure Client-Initiated Renegotiation No
BEAST attack Mitigated server-side (more info)  
POODLE (SSLv3) No, SSL 3 not supported (more info)
POODLE (TLS) No (more info)
Zombie POODLE No (more info)   TLS 1.2 : 0xc00a
GOLDENDOODLE No (more info)   TLS 1.2 : 0xc00a
OpenSSL 0-Length No (more info)   TLS 1.2 : 0xc00a
Sleeping POODLE No (more info)   TLS 1.2 : 0xc00a
Downgrade attack prevention Yes, TLS_FALLBACK_SCSV supported (more info)
SSL/TLS compression No
RC4 No
Heartbeat (extension) No
Heartbleed (vulnerability) No (more info)
Ticketbleed (vulnerability) No (more info)
OpenSSL CCS vuln. (CVE-2014-0224) No (more info)
OpenSSL Padding Oracle vuln.
(CVE-2016-2107)
No (more info)
ROBOT (vulnerability) No (more info)
Forward Secrecy Yes (with most browsers)   ROBUST (more info)
ALPN Yes   http/1.1
NPN Yes   http/1.1
Session resumption (caching) No (IDs assigned but not accepted)
Session resumption (tickets) Yes
OCSP stapling No
Strict Transport Security (HSTS) No
HSTS Preloading Not in: Chrome  Edge  Firefox  IE 
Public Key Pinning (HPKP) No (more info)
Public Key Pinning Report-Only No
Public Key Pinning (Static) No (more info)
Long handshake intolerance No
TLS extension intolerance No
TLS version intolerance No
Incorrect SNI alerts No
Uses common DH primes No, DHE suites not supported
DH public server param (Ys) reuse No, DHE suites not supported
ECDH public server param reuse No
Supported Named Groups secp256r1
SSL 2 handshake compatibility No
0-RTT enabled No


HTTP Requests
1 https://draft-www.island.health/  (HTTP/1.1 200 OK)
1
Date Tue, 14 Oct 2025 08:24:41 GMT
Server Apache/2.4.65 (Debian)
X-Content-Type-Options nosniff
Cache-Control max-age=28800, public, s-maxage=28800
X-Drupal-Dynamic-Cache UNCACHEABLE (poor cacheability)
Content-language en
X-Frame-Options SAMEORIGIN
Expires Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified Sun, 12 Oct 2025 16:41:33 GMT
Vary Cookie,Accept-Encoding
X-Generator Drupal 10 (https://www.drupal.org)
Cache-Tags block_view config:block.block.footer3 config:system.menu.footer-3 block_view:system_menu_block block_view:system_menu_block:footer-3 config:block.block.footer2 config:system.menu.footer-2 block_view:system_menu_block:footer-2 node:519 group_content_list:plugin:group_node:alert group_content_list:plugin:group_node:basic_page group_content_list:plugin:group_node:community group_content_list:plugin:group_node:custom_page group_content_list:plugin:group_node:events group_content_list:plugin:group_node:front_page_slideshow_item group_content_list:plugin:group_node:generic_page group_content_list:plugin:group_node:health_topics group_content_list:plugin:group_node:landing_level_two_secondary group_content_list:plugin:group_node:landing_page_level_one_type group_content_list:plugin:group_node:landing_page_level_one_type_seco group_content_list:plugin:group_node:landing_page_type group_content_list:plugin:group_node:locations group_content_list:plugin:group_node:news group_content_list:plugin:group_node:residences group_content_list:plugin:group_node:services node:826 node:3160 node:870 node:1066 config:block.block.contactus_4 config:system.menu.footer block_view:system_menu_block:footer node:108 node:1118 node:110 config:block.block.footerforprint block_view:block_content block_view:block_content:cd8eec9f-6b7c-428c-b01e-02acac697b2b block_content_view block_content:7 config:core.entity_view_display.block_content.basic.default config:filter.format.basic_html config:block.block.territorialacknowledgement block_view:block_content:5b24fa49-6672-47fe-a2b1-1b22abc4ad69 block_content:4 config:block.block.emergencies block_view:block_content:96a8ed85-3f22-4afe-a870-de988272cf4b block_content:2 config:block_list config:block.block.ih_main_branding config:block.block.breadcrumbs node:1 config:block.block.pagetitle config:block.block.views_block__front_page_slideshow_block_1 config:block.block.ih_main_local_actions config:block.block.ih_main_local_tasks config:block.block.ih_main_page_title config:block.block.mainpagecontent_2 config:block.block.ih_main_messages config:block.block.views_block__alert_block_block_1 config:block.block.communitymap config:block.block.views_block__landing_level_two_view_block_1 config:block.block.views_block__landing_level_one_view_block_1 config:block.block.views_block__news_events_front_block_1 config:block.block.views_block__featured_block_block_1 config:block.block.views_block__landing_level_two_view_location_block_1 config:block.block.views_block__landing_level_two_view_service_block_1 config:block.block.views_block__news_events_block_block_1 config:block.block.views_block__service_block_via_health_topic_block_1 config:block.block.views_block__news_events_block_via_community_block_1 config:block.block.views_block__service_block_via_community_block_1 config:block.block.views_block__events_via_events_block_block_1 config:block.block.views_block__landing_level_two_view_news_block_1 config:block.block.views_block__events_list_block_block_1 config:block.block.views_block__landing_level_two_view_events_block_1 config:block.block.views_block__locations_block_via_community_block_1 config:block.block.views_block__community_block_block_1_2 config:block.block.views_block__health_topics_via_health_topics_block_block_1 config:block.block.views_block__news_events_block_block_3 config:block.block.views_block__service_block_via_service_block_1 config:block.block.views_block__alert_list_block_1_2 config:block.block.views_block__alert_list_homepage_block_1 config:block.block.views_block__services_block_via_locations_block_1 config:block.block.pagetitle_2 config:block.block.views_block__health_topics_via_service_block_1 config:block.block.views_block__news_events_block_block_1_2 config:block.block.socialsharing config:block.block.mainnavigation config:block.block.secondarynavigation config:block.block.universalmenu config:block.block.universalmenu_3 config:block.block.contactus config:block.block.contactus_2 config:block.block.contactus_3 config:block.block.mainnavigation_2 config:block.block.secondarynavigation_4 config:block.block.views_block__alerts_via_location_block_1 config:block.block.mainnavigation_4 config:block.block.views_block__alerts_via_health_topics_block_1 config:block.block.views_block__alerts_via_services_block_1 config:block.block.views_block__locations_block_via_location_block_2 config:block.block.footer2_2 config:block.block.footer2_3 config:block.block.views_block__alerts_sidenav_list_block_1 config:block.block.footer2_7 config:block.block.footer2_6 config:block.block.footer2_5 config:block.block.footer2_4 config:block.block.footer2_8 config:block.block.views_block__community_block_block_1 config:block.block.views_block__news_list_block_1 config:block.block.views_block__alert_list_block_1 config:block.block.webform config:block.block.mainnavigation_3 config:block.block.secondarynavigation_2 config:block.block.universalmenu_2 config:block.block.views_block__location_node_block_block_1 config:block.block.searchpathcontextform config:block.block.searchform_3 config:asset_injector.js.compliments_form_force_styles config:asset_injector.css.accordion_styling_fix config:asset_injector.css.bc_sans_corrections config:asset_injector.css.bc_sans_font_load config:asset_injector.css.breadcrumb_issues_caused_by_drupal_10_upgrade_plus_additional_up config:asset_injector.css.care_kudos config:asset_injector.css.dfm_styles config:asset_injector.css.h4_remove_letter_spacing config:asset_injector.css.same_day_next_day_fixes config:asset_injector.css.search_bar_arial_bc_sans config:asset_injector.css.webform_description_styling config:extlink.settings config:google_analytics.settings config:field.storage.node.body config:field.storage.node.field_date_posted config:field.storage.node.field_teaser_image block_view:views_block block_view:views_block:news_events_front-block_1 config:views.view.news_events_front node_list node:3203 node:3201 node:3205 config:image.style.standard_image config:field.storage.node.field_date block_view:views_block:alert_list_homepage-block_1 config:views.view.alert_list_homepage node_view paragraph_view paragraph:15 config:paragraphs.settings paragraph:14 paragraph:13 paragraph:16 config:core.entity_view_display.paragraph.subhead.default paragraph:11 config:core.entity_view_display.paragraph.quick_links.default paragraph:12 paragraph:1070 paragraph:1072 paragraph:1071 config:core.entity_view_display.node.basic_page.default user:1 config:system.site block_view:local_tasks_block local_task config:workflows.workflow.editorial block_view:local_actions_block block_view:system_messages_block config:field.storage.node.field_slideshow_image config:field.storage.node.field_slideshow_link config:field.storage.node.field_slideshow_text block_view:views_block:front_page_slideshow-block_1 config:views.view.front_page_slideshow node:2106 node:2135 node:2269 config:image.style.slideshow_image_1285_ user:36 user:33 block_view:viha_addsearch_search_form_block CACHE_MISS_IF_UNCACHEABLE_HTTP_METHOD:form config:honeypot.settings config:system.menu.universal-menu block_view:system_menu_block:universal-menu config:system.menu.secondary-navigation block_view:system_menu_block:secondary-navigation node:67 node:69 node:74 node:72 node:70 node:1755 node:2730 node:3073 config:system.menu.main block_view:system_menu_block:main node:20 node:419 node:40 node:41 node:2 block_view:menu_block block_view:menu_block:universal-menu rendered http_response config:user.role.anonymous
X-IH-Cache-Override active
X-Drupal-Cache HIT
Content-Type text/html; charset=UTF-8
X-Varnish 98614 33133
Age 17199
Via 1.1 varnish (Varnish/7.1)
ETag W/"1760287293-gzip"
Accept-Ranges bytes
Content-Length 52664
Connection close


Miscellaneous
Test date Tue, 14 Oct 2025 13:11:12 UTC
Test duration 52.62 seconds
HTTP status code 200
HTTP server signature Apache/2.4.65 (Debian)
Server hostname ec2-16-52-63-246.ca-central-1.compute.amazonaws.com


SSL Report v2.4.1