SSL Report: 
            www.aft-dev.com
      (46.18.193.135)
    
 
        
            Assessed on:  Tue, 04 Nov 2025 08:31:54 UTC
            | Clear cache
        
        
        Summary
                0
                                20
                                40
                                60
                                80
                                100
                            Certificate
                                Protocol Support
                                Key Exchange
                                Cipher Strength
                                
                        Visit our documentation page
                        for more information, configuration guides, and books. Known issues are documented
                        here.
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                    
                        
                        
                    
                    
                    
                    
                    
                    
                                        
                        This server supports TLS 1.3.  MORE INFO »
                    
                    
                    
                    
                    
                Certificate #1: RSA 2048 bits (SHA256withRSA)
| 
                 Server Key and Certificate #1 
                
                    
                
             | 
		|
| Subject | 
                *.aft-dev.com
                 Fingerprint SHA256: 0ef70c4f6390d7ce319a2e0691f18dc00f46a007d80c77bf0d37b64f38f99173 Pin SHA256: gj974PixuhZBHokVfHHc7C2jDLPZ1aTaawFiSQyI5hw=  | 
        
| Common names | *.aft-dev.com | 
| Alternative names | *.aft-dev.com aft-dev.com | 
| Serial Number | 0a6018539144aab65d658d8e0dec3d5d | 
| Valid from | Wed, 23 Apr 2025 00:00:00 UTC | 
| Valid until | Sun, 24 May 2026 23:59:59 UTC (expires in 6 months and 20 days) | 
| Key | RSA 2048 bits (e 65537) | 
| Weak key (Debian) | No | 
| Issuer | GandiCert
                 AIA: http://cacerts.digicert.com/GandiCert.crt  | 
		
| Signature algorithm | SHA256withRSA | 
| Extended Validation | No | 
| Certificate Transparency | Yes (certificate) | 
| OCSP Must Staple | No | 
| Revocation information | 
 CRL, OCSP              CRL: http://crl3.digicert.com/GandiCert.crl OCSP: http://ocsp.digicert.com  | 
		
| Revocation status | Good (not revoked)
         CRL ERROR: IOException occurred  | 
		
| DNS CAA | No (more info) | 
| Trusted | Yes
			 Mozilla Apple Android Java Windows  | 
		
| 
				            	
                 | 
		
Configuration
                    | Protocols | |
| TLS 1.3 | Yes | 
| TLS 1.2 | Yes | 
| TLS 1.1 | No | 
| TLS 1.0 | No | 
| SSL 3 | No | 
| SSL 2 | No | 
| Cipher Suites | ||
| 
                 # TLS 1.3                                             (server has no preference)
 
             | 
                                    ||
                        TLS_AES_128_GCM_SHA256 (0x1301)
                                          ECDH x25519 (eq. 3072 bits RSA)   FS
                 | 
                                                                                        128 | |
                        TLS_AES_256_GCM_SHA384 (0x1302)
                                          ECDH x25519 (eq. 3072 bits RSA)   FS
                 | 
                                                                                        256 | |
                        TLS_CHACHA20_POLY1305_SHA256 (0x1303)
                                          ECDH x25519 (eq. 3072 bits RSA)   FS
                 | 
                                                                                        256 | |
| 
                 # TLS 1.2                                             (server has no preference)
 
             | 
                                    ||
                        TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x9e)
  
                                        
                                        DH 2048 bits   FS
                 | 
                                                                                        128 | |
                        TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
                                          ECDH secp521r1 (eq. 15360 bits RSA)   FS
                 | 
                                                                                        128 | |
                        TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x9f)
  
                                        
                                        DH 2048 bits   FS
                 | 
                                                                                        256 | |
                        TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
                                          ECDH secp521r1 (eq. 15360 bits RSA)   FS
                 | 
                                                                                        256 | |
                        TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8)
                                          ECDH secp521r1 (eq. 15360 bits RSA)   FS
                 | 
                                                                                        256 | |
| Handshake Simulation | |||
| Android 4.4.2 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp521r1 FS | 
| Android 5.0.0 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp521r1 FS | 
| Android 6.0 | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS | 
| Android 7.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS | 
| Android 8.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS | 
| Android 8.1 | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS | 
| Android 9.0 | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS | 
| BingPreview Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp521r1 FS | 
| Chrome 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS | 
| Chrome 69 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS | 
| Chrome 70 / Win 10 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS | 
| Chrome 80 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS | 
| Firefox 31.3.0 ESR / Win 7 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS | 
| Firefox 47 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS | 
| Firefox 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS | 
| Firefox 62 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS | 
| Firefox 73 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS | 
| Googlebot Feb 2018 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS | 
| IE 11 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 DH 2048 FS | 
| IE 11 / Win 8.1 R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 DH 2048 FS | 
| IE 11 / Win Phone 8.1 R | 
                                                            Server sent fatal alert: handshake_failure | 
                                                    
                                        ||
| IE 11 / Win Phone 8.1 Update R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 DH 2048 FS | 
| IE 11 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Edge 15 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH x25519 FS | 
| Edge 16 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH x25519 FS | 
| Edge 18 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH x25519 FS | 
| Edge 13 / Win Phone 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Java 8u161 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Java 11.0.3 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS | 
| Java 12.0.1 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS | 
| OpenSSL 1.0.1l R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp521r1 FS | 
| OpenSSL 1.0.2s R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| OpenSSL 1.1.0k R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH x25519 FS | 
| OpenSSL 1.1.1c R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS | 
| Safari 6 / iOS 6.0.1 | 
                                                            Server sent fatal alert: handshake_failure | 
                                                    
                                        ||
| Safari 7 / iOS 7.1 R | 
                                                            Server sent fatal alert: handshake_failure | 
                                                    
                                        ||
| Safari 7 / OS X 10.9 R | 
                                                            Server sent fatal alert: handshake_failure | 
                                                    
                                        ||
| Safari 8 / iOS 8.4 R | 
                                                            Server sent fatal alert: handshake_failure | 
                                                    
                                        ||
| Safari 8 / OS X 10.10 R | 
                                                            Server sent fatal alert: handshake_failure | 
                                                    
                                        ||
| Safari 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Safari 9 / OS X 10.11 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Safari 10 / iOS 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Safari 10 / OS X 10.12 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Safari 12.1.2 / MacOS 10.14.6 Beta R | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS | 
| Safari 12.1.1 / iOS 12.3.1 R | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS | 
| Apple ATS 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp256r1 FS | 
| Yahoo Slurp Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp384r1 FS | 
| YandexBot Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDH secp521r1 FS | 
| 
                                             # Not simulated clients (Protocol mismatch) 
                                         | 
                                    |||
| Android 2.3.7 No SNI 2 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Android 4.0.4 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Android 4.1.1 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Android 4.2.2 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Android 4.3 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Baidu Jan 2015 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| IE 6 / XP No FS 1 No SNI 2 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| IE 7 / Vista | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| IE 8 / XP No FS 1 No SNI 2 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| IE 8-10 / Win 7 R | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| IE 10 / Win Phone 8.0 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Java 6u45 No SNI 2 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Java 7u25 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| OpenSSL 0.9.8y | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Safari 5.1.9 / OS X 10.6.8 | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| Safari 6.0.4 / OS X 10.8.4 R | 
                                                            Protocol mismatch (not simulated) | 
                                                    
                                        ||
| (1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it. | |||
| (2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI. | |||
| (3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version. | |||
| (R) Denotes a reference browser or client, with which we expect better effective security. | |||
| (All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE). | |||
| (All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake. | |||
| Protocol Details | |
| Secure Renegotiation | Supported | 
| Secure Client-Initiated Renegotiation | No | 
| Insecure Client-Initiated Renegotiation | No | 
| BEAST attack | Mitigated server-side (more info) | 
| POODLE (SSLv3) | No, SSL 3 not supported (more info) | 
| POODLE (TLS) | No (more info) | 
| Zombie POODLE | No (more info) | 
| GOLDENDOODLE | No (more info) | 
| OpenSSL 0-Length | No (more info) | 
| Sleeping POODLE | No (more info) | 
| Downgrade attack prevention | Yes, TLS_FALLBACK_SCSV supported (more info) | 
| SSL/TLS compression | No | 
| RC4 | No | 
| Heartbeat (extension) | No | 
| Heartbleed (vulnerability) | No (more info) | 
| Ticketbleed (vulnerability) | No (more info) | 
| OpenSSL CCS vuln. (CVE-2014-0224) | No (more info) | 
| OpenSSL Padding Oracle vuln. (CVE-2016-2107)  | 
                                        No (more info) | 
| ROBOT (vulnerability) | No (more info) | 
| Forward Secrecy | Yes (with most browsers) ROBUST (more info) | 
| ALPN | Yes h2 http/1.1 | 
| NPN | No | 
| Session resumption (caching) | Yes | 
| Session resumption (tickets) | No | 
| OCSP stapling | No | 
| Strict Transport Security (HSTS) | No | 
| HSTS Preloading | Not in: Chrome Edge Firefox IE | 
| Public Key Pinning (HPKP) | No (more info) | 
| Public Key Pinning Report-Only | No | 
| Public Key Pinning (Static) | No (more info) | 
| Long handshake intolerance | No | 
| TLS extension intolerance | No | 
| TLS version intolerance | No | 
| Incorrect SNI alerts | No | 
| Uses common DH primes | No | 
| DH public server param (Ys) reuse | No | 
| ECDH public server param reuse | No | 
| Supported Named Groups | secp256r1, secp384r1, secp521r1, x25519, x448 (Server has no preference) | 
| SSL 2 handshake compatibility | No | 
| 0-RTT enabled | No | 
| 
                                         | 
                                
| 
                                         
                                            1 https://www.aft-dev.com/
                                                 (HTTP/1.1 200 OK)
                                         
                                     | 1 | |
| date | Tue, 04 Nov 2025 08:30:55 GMT | |
| cache-control | max-age=31536000, public | |
| x-drupal-dynamic-cache | UNCACHEABLE | |
| link | <https://www.aft-dev.com/>; rel="shortlink", <https://www.aft-dev.com/>; rel="canonical" | |
| x-ua-compatible | IE=edge | |
| content-language | fr | |
| x-content-type-options | nosniff | |
| x-frame-options | SAMEORIGIN | |
| expires | Sun, 19 Nov 1978 05:00:00 GMT | |
| vary | Cookie,Accept-Encoding | |
| x-generator | Drupal 8 (https://www.drupal.org) | |
| cache-tags | block:social_links block_content:1 block_content:2 block_content:5 block_content_view block_view config:block.block.aft_account_menu config:block.block.aft_branding config:block.block.aft_breadcrumbs config:block.block.aft_content config:block.block.aft_footer config:block.block.aft_local_actions config:block.block.aft_local_tasks config:block.block.aft_main_menu config:block.block.aft_messages config:block.block.aft_page_title config:block.block.aft_powered config:block.block.aft_tools config:block.block.blocpersonnalise config:block.block.decouvrirlaft config:block.block.discover_aft config:block.block.footer config:block.block.footercontact config:block.block.footerlogo config:block.block.header_global_filter config:block.block.header_search_block config:block.block.herobanner config:block.block.home_button config:block.block.main_menu config:block.block.partner_menu config:block.block.professional_menu config:block.block.searchfilter config:block.block.sitebranding config:block.block.social_links config:block.block.special_menu config:block.block.tabs config:block.block.tools config:block.block.top_global_filter config:block_list config:color.theme.aft config:core.entity_form_display.webform_submission.agenda_research.add config:filter.format.basic_html config:filter.format.full_html config:filter.format.plain_text config:image.style.actualites_teaser config:image.style.news_for_widget config:paragraphs.settings config:system.menu.footer config:system.site config:user.role.anonymous config:views.view.agenda config:views.view.social_view config:views.view.visitor_types config:webform.settings config:webform.webform.agenda_research file:1403 file:159 file:160 file:161 file:162 file:17546 file:17794 file:17809 http_response node:1069 node:1252 node:1769 node:4830 node:4831 node:642 node:7145 node:7163 node:7659 node:7779 node:7781 node_list node_view paragraph:1371 paragraph:1372 paragraph_view rendered search_api_autocomplete_search_list:views:search taxonomy_term:10 taxonomy_term:11 taxonomy_term:12 taxonomy_term:13 taxonomy_term:14 taxonomy_term:15 taxonomy_term:154 taxonomy_term:16 taxonomy_term:17 taxonomy_term:18 taxonomy_term:19 taxonomy_term:2 taxonomy_term:20 taxonomy_term:21 taxonomy_term:22 taxonomy_term:221 taxonomy_term:225 taxonomy_term:226 taxonomy_term:23 taxonomy_term:265 taxonomy_term:394 taxonomy_term:397 taxonomy_term:415 taxonomy_term:418 taxonomy_term:432 taxonomy_term:436 taxonomy_term:9 taxonomy_term_list taxonomy_term_view user:1280 user:52 webform:agenda_research | |
| set-cookie | visitor_type=0; path=/ | |
| set-cookie | region_id=0; path=/ | |
| last-modified | Tue, 04 Nov 2025 08:30:55 GMT | |
| etag | "1762245055" | |
| content-type | text/html; charset=UTF-8 | |
| age | 0 | |
| x-cache | MISS | |
| accept-ranges | bytes | |
| content-length | 106426 | |
| connection | close | |
| Miscellaneous | |
| Test date | Tue, 04 Nov 2025 08:30:41 UTC | 
| Test duration | 73.715 seconds | 
| HTTP status code | 200 | 
| HTTP server signature | - | 
| Server hostname | ds-193-135.dri-services.net | 
SSL Report v2.4.1
