SSL Report: sird.mkb.hu (213.253.215.39)
Assessed on:  Mon, 15 Sep 2025 10:24:42 UTC | Clear cache

Due to a recently discovered bug in Apple's code, your browser is exposed to MITM attacks. Click here for more information.

Summary
Overall Rating
A
0
20
40
60
80
100
Certificate
 
Protocol Support
 
Key Exchange
 
Cipher Strength
 

Visit our documentation page for more information, configuration guides, and books. Known issues are documented here.
This server's certificate is not trusted by Java trust store (see below for details).
This server supports TLS 1.3.  MORE INFO »
Certificate #1: EC 256 bits (SHA256withECDSA)
Server Key and Certificate #1
Subject sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=
Common names sird.mkb.hu
Alternative names sird.mkb.hu
Serial Number 05ba9591002bde016569f7cff80a
Valid from Thu, 11 Sep 2025 13:16:41 UTC
Valid until Mon, 12 Oct 2026 13:16:40 UTC (expires in 1 year)
Key EC 256 bits
Weak key (Debian) No
Issuer e-Szigno OV TLS CA 2023
AIA: http://eovtlsca2023-ca.e-szigno.hu/eovtlsca2023.crt
AIA: http://eovtlsca2023-ca.e-szigno.hu/eovtlsca2023-link-rootca2009.crt
Signature algorithm SHA256withECDSA
Extended Validation No
Certificate Transparency Yes (certificate)
OCSP Must Staple No
Revocation information CRL, OCSP
CRL: http://eovtlsca2023-crl.e-szigno.hu/eovtlsca2023.crl
OCSP: http://eovtlsca2023-ocsp.e-szigno.hu
Revocation status Good (not revoked)
DNS CAA No (more info)
Trusted Yes
Mozilla  Apple  Android  Java  Windows 


Additional Certificates (if supplied)
Certificates provided 2 (2317 bytes)
Chain issues None
#2
Subject e-Szigno OV TLS CA 2023
Fingerprint SHA256: bc75db1df88e0a11c1d432bc31ccf3369cdfbbc48bedac9ac41f31f03dede8a0
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=
Valid until Sat, 12 Feb 2028 10:59:59 UTC (expires in 2 years and 4 months)
Key EC 256 bits
Issuer Microsec e-Szigno Root CA 2009
Signature algorithm SHA256withRSA


Certification Paths
Path #1: Trusted
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Sent by server e-Szigno OV TLS CA 2023
Fingerprint SHA256: bc75db1df88e0a11c1d432bc31ccf3369cdfbbc48bedac9ac41f31f03dede8a0
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA256withRSA
3 In trust store Microsec e-Szigno Root CA 2009   Self-signed
Fingerprint SHA256: 3c5f81fea5fab82c64bfa2eaecafcde8e077fc8620a7cae537163df36edbf378
Pin SHA256: YWFnIBQzrqbI5eMHCvyvZ0kYj4FL0auxea6NrTq/Juw=

RSA 2048 bits (e 65537) / SHA256withRSA
Path #2: Not trusted (path does not chain to a trusted anchor)
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Extra download e-Szigno OV TLS CA 2023
Fingerprint SHA256: 663e65eb4eb152a8266a1bf475108b73abc90bc8ad98b58be16234b281279796
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA512withECDSA
3 Extra download
  Not in trust store
e-Szigno TLS Root CA 2023   Self-signed
Fingerprint SHA256: b49141502d00663d740f2e7ec340c52800962666121a36d09cf7dd2b90384fb4
Pin SHA256: R0h5AKG+ue4IzLwRFqjsVfRUtjiZQxnwUbmEAjztZCM=

EC 521 bits / SHA512withECDSA
Path #1: Trusted
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Sent by server e-Szigno OV TLS CA 2023
Fingerprint SHA256: bc75db1df88e0a11c1d432bc31ccf3369cdfbbc48bedac9ac41f31f03dede8a0
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA256withRSA
3 In trust store Microsec e-Szigno Root CA 2009   Self-signed
Fingerprint SHA256: 3c5f81fea5fab82c64bfa2eaecafcde8e077fc8620a7cae537163df36edbf378
Pin SHA256: YWFnIBQzrqbI5eMHCvyvZ0kYj4FL0auxea6NrTq/Juw=

RSA 2048 bits (e 65537) / SHA256withRSA
Path #2: Not trusted (path does not chain to a trusted anchor)
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Extra download e-Szigno OV TLS CA 2023
Fingerprint SHA256: 663e65eb4eb152a8266a1bf475108b73abc90bc8ad98b58be16234b281279796
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA512withECDSA
3 Extra download
  Not in trust store
e-Szigno TLS Root CA 2023   Self-signed
Fingerprint SHA256: b49141502d00663d740f2e7ec340c52800962666121a36d09cf7dd2b90384fb4
Pin SHA256: R0h5AKG+ue4IzLwRFqjsVfRUtjiZQxnwUbmEAjztZCM=

EC 521 bits / SHA512withECDSA
Path #1: Trusted
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Sent by server e-Szigno OV TLS CA 2023
Fingerprint SHA256: bc75db1df88e0a11c1d432bc31ccf3369cdfbbc48bedac9ac41f31f03dede8a0
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA256withRSA
3 In trust store Microsec e-Szigno Root CA 2009   Self-signed
Fingerprint SHA256: 3c5f81fea5fab82c64bfa2eaecafcde8e077fc8620a7cae537163df36edbf378
Pin SHA256: YWFnIBQzrqbI5eMHCvyvZ0kYj4FL0auxea6NrTq/Juw=

RSA 2048 bits (e 65537) / SHA256withRSA
Path #2: Not trusted (path does not chain to a trusted anchor)
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Extra download e-Szigno OV TLS CA 2023
Fingerprint SHA256: 663e65eb4eb152a8266a1bf475108b73abc90bc8ad98b58be16234b281279796
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA512withECDSA
3 Extra download
  Not in trust store
e-Szigno TLS Root CA 2023   Self-signed
Fingerprint SHA256: b49141502d00663d740f2e7ec340c52800962666121a36d09cf7dd2b90384fb4
Pin SHA256: R0h5AKG+ue4IzLwRFqjsVfRUtjiZQxnwUbmEAjztZCM=

EC 521 bits / SHA512withECDSA
Path #1: Not trusted (path does not chain to a trusted anchor)
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Sent by server e-Szigno OV TLS CA 2023
Fingerprint SHA256: bc75db1df88e0a11c1d432bc31ccf3369cdfbbc48bedac9ac41f31f03dede8a0
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA256withRSA
3 Extra download
  Not in trust store
Microsec e-Szigno Root CA 2009   Self-signed
Fingerprint SHA256: 3c5f81fea5fab82c64bfa2eaecafcde8e077fc8620a7cae537163df36edbf378
Pin SHA256: YWFnIBQzrqbI5eMHCvyvZ0kYj4FL0auxea6NrTq/Juw=

RSA 2048 bits (e 65537) / SHA256withRSA
Path #2: Not trusted (path does not chain to a trusted anchor)
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Extra download e-Szigno OV TLS CA 2023
Fingerprint SHA256: 663e65eb4eb152a8266a1bf475108b73abc90bc8ad98b58be16234b281279796
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA512withECDSA
3 Extra download
  Not in trust store
e-Szigno TLS Root CA 2023   Self-signed
Fingerprint SHA256: b49141502d00663d740f2e7ec340c52800962666121a36d09cf7dd2b90384fb4
Pin SHA256: R0h5AKG+ue4IzLwRFqjsVfRUtjiZQxnwUbmEAjztZCM=

EC 521 bits / SHA512withECDSA
Path #1: Trusted
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Sent by server e-Szigno OV TLS CA 2023
Fingerprint SHA256: bc75db1df88e0a11c1d432bc31ccf3369cdfbbc48bedac9ac41f31f03dede8a0
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA256withRSA
3 In trust store Microsec e-Szigno Root CA 2009   Self-signed
Fingerprint SHA256: 3c5f81fea5fab82c64bfa2eaecafcde8e077fc8620a7cae537163df36edbf378
Pin SHA256: YWFnIBQzrqbI5eMHCvyvZ0kYj4FL0auxea6NrTq/Juw=

RSA 2048 bits (e 65537) / SHA256withRSA
Path #2: Trusted
1 Sent by server sird.mkb.hu
Fingerprint SHA256: c1586df23a85259e18b87db11ed3c9ff37713a371dd2420f36d33d6ae93f0d4f
Pin SHA256: dVZ0jnuOt0S0JrbKbob1tO80O7AeFSRUnZ8K/zwiK44=

EC 256 bits / SHA256withECDSA
2 Extra download e-Szigno OV TLS CA 2023
Fingerprint SHA256: 663e65eb4eb152a8266a1bf475108b73abc90bc8ad98b58be16234b281279796
Pin SHA256: CBpKKUYnWuYNjyn6A4C6+fbIOhB5kbX1rkHpBJ+7g0Y=

EC 256 bits / SHA512withECDSA
3 In trust store e-Szigno TLS Root CA 2023   Self-signed
Fingerprint SHA256: b49141502d00663d740f2e7ec340c52800962666121a36d09cf7dd2b90384fb4
Pin SHA256: R0h5AKG+ue4IzLwRFqjsVfRUtjiZQxnwUbmEAjztZCM=

EC 521 bits / SHA512withECDSA

Click here to expand

Configuration
Protocols
TLS 1.3 Yes
TLS 1.2 No
TLS 1.1 No
TLS 1.0 No
SSL 3 No
SSL 2 No


Cipher Suites
# TLS 1.3 (suites in server-preferred order)
TLS_AES_256_GCM_SHA384 (0x1302)   ECDH x25519 (eq. 3072 bits RSA)   FS 256
TLS_CHACHA20_POLY1305_SHA256 (0x1303)   ECDH x25519 (eq. 3072 bits RSA)   FS 256
TLS_AES_128_GCM_SHA256 (0x1301)   ECDH x25519 (eq. 3072 bits RSA)   FS 128


Handshake Simulation
Android 8.1 Server sent fatal alert: handshake_failure
Android 9.0 Server sent fatal alert: handshake_failure
Chrome 69 / Win 7  R Server sent fatal alert: handshake_failure
Chrome 70 / Win 10 Server sent fatal alert: handshake_failure
Chrome 80 / Win 10  R Server sent fatal alert: handshake_failure
Firefox 62 / Win 7  R Server sent fatal alert: handshake_failure
Firefox 73 / Win 10  R Server sent fatal alert: handshake_failure
Java 11.0.3 Server sent fatal alert: handshake_failure
Java 12.0.1 Server sent fatal alert: handshake_failure
OpenSSL 1.1.0k  R Server sent fatal alert: handshake_failure
OpenSSL 1.1.1c  R Server sent fatal alert: handshake_failure
Safari 12.1.2 / MacOS 10.14.6 Beta  R Server sent fatal alert: handshake_failure
Safari 12.1.1 / iOS 12.3.1  R Server sent fatal alert: handshake_failure
# Not simulated clients (Protocol mismatch)
Android 2.3.7   No SNI 2 Protocol mismatch (not simulated)
Android 4.0.4 Protocol mismatch (not simulated)
Android 4.1.1 Protocol mismatch (not simulated)
Android 4.2.2 Protocol mismatch (not simulated)
Android 4.3 Protocol mismatch (not simulated)
Android 4.4.2 Protocol mismatch (not simulated)
Android 5.0.0 Protocol mismatch (not simulated)
Android 6.0 Protocol mismatch (not simulated)
Android 7.0 Protocol mismatch (not simulated)
Android 8.0 Protocol mismatch (not simulated)
Baidu Jan 2015 Protocol mismatch (not simulated)
BingPreview Jan 2015 Protocol mismatch (not simulated)
Chrome 49 / XP SP3 Protocol mismatch (not simulated)
Firefox 31.3.0 ESR / Win 7 Protocol mismatch (not simulated)
Firefox 47 / Win 7  R Protocol mismatch (not simulated)
Firefox 49 / XP SP3 Protocol mismatch (not simulated)
Googlebot Feb 2018 Protocol mismatch (not simulated)
IE 6 / XP   No FS 1   No SNI 2 Protocol mismatch (not simulated)
IE 7 / Vista Protocol mismatch (not simulated)
IE 8 / XP   No FS 1   No SNI 2 Protocol mismatch (not simulated)
IE 8-10 / Win 7  R Protocol mismatch (not simulated)
IE 11 / Win 7  R Protocol mismatch (not simulated)
IE 11 / Win 8.1  R Protocol mismatch (not simulated)
IE 10 / Win Phone 8.0 Protocol mismatch (not simulated)
IE 11 / Win Phone 8.1  R Protocol mismatch (not simulated)
IE 11 / Win Phone 8.1 Update  R Protocol mismatch (not simulated)
IE 11 / Win 10  R Protocol mismatch (not simulated)
Edge 15 / Win 10  R Protocol mismatch (not simulated)
Edge 16 / Win 10  R Protocol mismatch (not simulated)
Edge 18 / Win 10  R Protocol mismatch (not simulated)
Edge 13 / Win Phone 10  R Protocol mismatch (not simulated)
Java 6u45   No SNI 2 Protocol mismatch (not simulated)
Java 7u25 Protocol mismatch (not simulated)
Java 8u161 Protocol mismatch (not simulated)
OpenSSL 0.9.8y Protocol mismatch (not simulated)
OpenSSL 1.0.1l  R Protocol mismatch (not simulated)
OpenSSL 1.0.2s  R Protocol mismatch (not simulated)
Safari 5.1.9 / OS X 10.6.8 Protocol mismatch (not simulated)
Safari 6 / iOS 6.0.1 Protocol mismatch (not simulated)
Safari 6.0.4 / OS X 10.8.4  R Protocol mismatch (not simulated)
Safari 7 / iOS 7.1  R Protocol mismatch (not simulated)
Safari 7 / OS X 10.9  R Protocol mismatch (not simulated)
Safari 8 / iOS 8.4  R Protocol mismatch (not simulated)
Safari 8 / OS X 10.10  R Protocol mismatch (not simulated)
Safari 9 / iOS 9  R Protocol mismatch (not simulated)
Safari 9 / OS X 10.11  R Protocol mismatch (not simulated)
Safari 10 / iOS 10  R Protocol mismatch (not simulated)
Safari 10 / OS X 10.12  R Protocol mismatch (not simulated)
Apple ATS 9 / iOS 9  R Protocol mismatch (not simulated)
Yahoo Slurp Jan 2015 Protocol mismatch (not simulated)
YandexBot Jan 2015 Protocol mismatch (not simulated)

Click here to expand

(1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it.
(2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI.
(3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version.
(R) Denotes a reference browser or client, with which we expect better effective security.
(All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE).
(All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake.


Protocol Details
ROBOT (vulnerability) No (more info)
Forward Secrecy Yes (with most browsers)   ROBUST (more info)
ALPN Yes   http/1.1
Session resumption (tickets) No
OCSP stapling No
Strict Transport Security (HSTS) No
HSTS Preloading Not in: Chrome  Edge  Firefox  IE 
Public Key Pinning (HPKP) No (more info)
Public Key Pinning Report-Only No
Public Key Pinning (Static) No (more info)
Supported Named Groups x25519, secp256r1, secp384r1, secp521r1 (server preferred order)
SSL 2 handshake compatibility No
0-RTT enabled No


HTTP Requests
1 https://sird.mkb.hu/  (HTTP/1.1 200 OK)
1
Content-Type text/html
Last-Modified Tue, 11 Dec 2018 07:47:39 GMT
Accept-Ranges bytes
ETag "7e1adca2591d41:0"
Server Microsoft-IIS/10.0
X-Powered-By ASP.NET
Date Mon, 15 Sep 2025 10:24:39 GMT
Connection close
Content-Length 703


Miscellaneous
Test date Mon, 15 Sep 2025 10:24:07 UTC
Test duration 34.957 seconds
HTTP status code 200
HTTP server signature Microsoft-IIS/10.0
Server hostname -


SSL Report v2.4.1