SSL Report:
www.croix-rouge.fr
(185.94.140.73)
Assessed on: Fri, 12 Sep 2025 13:53:17 UTC
| Clear cache
Summary
0
20
40
60
80
100
Certificate
Protocol Support
Key Exchange
Cipher Strength
Visit our documentation page
for more information, configuration guides, and books. Known issues are documented
here.
This site works only in browsers with SNI support.
This server supports TLS 1.3. MORE INFO »
Certificate #1: RSA 4096 bits (SHA256withRSA)

Server Key and Certificate #1
|
|
Subject |
*.croix-rouge.fr
Fingerprint SHA256: 958b0b33eaa8ed6f22f2d290aad8c9e8cd25798994e234825d5ffbc79ea584d5 Pin SHA256: SfDBZjW2nrInd2CBSknOg43PLRq6emQuptyPCDHSvnk= |
Common names | *.croix-rouge.fr |
Alternative names | *.croix-rouge.fr croix-rouge.fr |
Serial Number | 0ee672d3dad17a964f4574c9b5c7059c |
Valid from | Wed, 18 Sep 2024 00:00:00 UTC |
Valid until | Fri, 17 Oct 2025 23:59:59 UTC (expires in 1 month and 5 days) |
Key | RSA 4096 bits (e 65537) |
Weak key (Debian) | No |
Issuer | Thawte TLS RSA CA G1
AIA: http://cacerts.thawte.com/ThawteTLSRSACAG1.crt |
Signature algorithm | SHA256withRSA |
Extended Validation | No |
Certificate Transparency | Yes (certificate) |
OCSP Must Staple | No |
Revocation information |
CRL, OCSP CRL: http://cdp.thawte.com/ThawteTLSRSACAG1.crl OCSP: http://status.thawte.com |
Revocation status | Good (not revoked) |
DNS CAA | No (more info) |
Trusted | Yes
Mozilla Apple Android Java Windows |


![]() ![]() |
Configuration

Protocols | |
TLS 1.3 | Yes |
TLS 1.2 | Yes |
TLS 1.1 | No |
TLS 1.0 | No |
SSL 3 | No |
SSL 2 | No |

Cipher Suites | ||
![]() ![]() # TLS 1.3 (server has no preference)
|
||
TLS_AES_128_GCM_SHA256 (0x1301 )
ECDH secp256r1 (eq. 3072 bits RSA) FS
|
128 | |
TLS_AES_256_GCM_SHA384 (0x1302 )
ECDH secp256r1 (eq. 3072 bits RSA) FS
|
256 | |
TLS_CHACHA20_POLY1305_SHA256 (0x1303 )
ECDH secp256r1 (eq. 3072 bits RSA) FS
|
256 | |
![]() ![]() # TLS 1.2 (suites in server-preferred order)
|
||
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f )
ECDH secp256r1 (eq. 3072 bits RSA) FS
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030 )
ECDH secp256r1 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8 )
ECDH secp256r1 (eq. 3072 bits RSA) FS
|
256 |

Handshake Simulation | |||
Android 4.4.2 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Android 5.0.0 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Android 6.0 | RSA 4096 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Android 7.0 | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Android 8.0 | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Android 8.1 | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
Android 9.0 | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
BingPreview Jan 2015 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Chrome 49 / XP SP3 | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Chrome 69 / Win 7 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Chrome 70 / Win 10 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Chrome 80 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Firefox 31.3.0 ESR / Win 7 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Firefox 47 / Win 7 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Firefox 49 / XP SP3 | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Firefox 62 / Win 7 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Firefox 73 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Googlebot Feb 2018 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
IE 11 / Win 7 R |
Server sent fatal alert: handshake_failure |
||
IE 11 / Win 8.1 R |
Server sent fatal alert: handshake_failure |
||
IE 11 / Win Phone 8.1 R |
Server sent fatal alert: handshake_failure |
||
IE 11 / Win Phone 8.1 Update R |
Server sent fatal alert: handshake_failure |
||
IE 11 / Win 10 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Edge 15 / Win 10 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Edge 16 / Win 10 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Edge 18 / Win 10 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Edge 13 / Win Phone 10 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Java 8u161 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Java 11.0.3 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Java 12.0.1 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
OpenSSL 1.0.1l R | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
OpenSSL 1.0.2s R | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
OpenSSL 1.1.0k R | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
OpenSSL 1.1.1c R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH secp256r1 FS |
Safari 6 / iOS 6.0.1 |
Server sent fatal alert: handshake_failure |
||
Safari 7 / iOS 7.1 R |
Server sent fatal alert: handshake_failure |
||
Safari 7 / OS X 10.9 R |
Server sent fatal alert: handshake_failure |
||
Safari 8 / iOS 8.4 R |
Server sent fatal alert: handshake_failure |
||
Safari 8 / OS X 10.10 R |
Server sent fatal alert: handshake_failure |
||
Safari 9 / iOS 9 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Safari 9 / OS X 10.11 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Safari 10 / iOS 10 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Safari 10 / OS X 10.12 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Safari 12.1.2 / MacOS 10.14.6 Beta R | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
Safari 12.1.1 / iOS 12.3.1 R | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
Apple ATS 9 / iOS 9 R | RSA 4096 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
Yahoo Slurp Jan 2015 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
YandexBot Jan 2015 | RSA 4096 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
![]() ![]() # Not simulated clients (Protocol mismatch)
|
|||
Android 2.3.7 No SNI 2 |
Protocol mismatch (not simulated) |
||
Android 4.0.4 |
Protocol mismatch (not simulated) |
||
Android 4.1.1 |
Protocol mismatch (not simulated) |
||
Android 4.2.2 |
Protocol mismatch (not simulated) |
||
Android 4.3 |
Protocol mismatch (not simulated) |
||
Baidu Jan 2015 |
Protocol mismatch (not simulated) |
||
IE 6 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
IE 7 / Vista |
Protocol mismatch (not simulated) |
||
IE 8 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
IE 8-10 / Win 7 R |
Protocol mismatch (not simulated) |
||
IE 10 / Win Phone 8.0 |
Protocol mismatch (not simulated) |
||
Java 6u45 No SNI 2 |
Protocol mismatch (not simulated) |
||
Java 7u25 |
Protocol mismatch (not simulated) |
||
OpenSSL 0.9.8y |
Protocol mismatch (not simulated) |
||
Safari 5.1.9 / OS X 10.6.8 |
Protocol mismatch (not simulated) |
||
Safari 6.0.4 / OS X 10.8.4 R |
Protocol mismatch (not simulated) |
||
(1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it. | |||
(2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI. | |||
(3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version. | |||
(R) Denotes a reference browser or client, with which we expect better effective security. | |||
(All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE). | |||
(All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake. |

Protocol Details | |
Secure Renegotiation | Supported |
Secure Client-Initiated Renegotiation | No |
Insecure Client-Initiated Renegotiation | No |
BEAST attack | Mitigated server-side (more info) |
POODLE (SSLv3) | No, SSL 3 not supported (more info) |
POODLE (TLS) | No (more info) |
Zombie POODLE | No (more info) |
GOLDENDOODLE | No (more info) |
OpenSSL 0-Length | No (more info) |
Sleeping POODLE | No (more info) |
Downgrade attack prevention | Yes, TLS_FALLBACK_SCSV supported (more info) |
SSL/TLS compression | No |
RC4 | No |
Heartbeat (extension) | No |
Heartbleed (vulnerability) | No (more info) |
Ticketbleed (vulnerability) | No (more info) |
OpenSSL CCS vuln. (CVE-2014-0224) | No (more info) |
OpenSSL Padding Oracle vuln. (CVE-2016-2107) |
No (more info) |
ROBOT (vulnerability) | No (more info) |
Forward Secrecy | Yes (with most browsers) ROBUST (more info) |
ALPN | Yes h2 http/1.1 |
NPN | No |
Session resumption (caching) | No (IDs assigned but not accepted) |
Session resumption (tickets) | Yes |
OCSP stapling | No |
Strict Transport Security (HSTS) | No |
HSTS Preloading | Not in: Chrome Edge Firefox IE |
Public Key Pinning (HPKP) | No (more info) |
Public Key Pinning Report-Only | No |
Public Key Pinning (Static) | No (more info) |
Long handshake intolerance | No |
TLS extension intolerance | No |
TLS version intolerance | No |
Incorrect SNI alerts | No |
Uses common DH primes | No, DHE suites not supported |
DH public server param (Ys) reuse | No, DHE suites not supported |
ECDH public server param reuse | No |
Supported Named Groups | secp256r1, secp384r1, x25519 (server preferred order) |
SSL 2 handshake compatibility | No |
0-RTT enabled | No |

![]() ![]() |
1 https://www.croix-rouge.fr/
(HTTP/1.1 200 OK)
| 1 | |
accept-ranges | bytes | |
age | 5076 | |
cache-control | public, s-max-age=21600, max-age=21600 | |
content-type | text/html; charset=utf-8 | |
date | Fri, 12 Sep 2025 12:28:00 GMT | |
etag | W/"b1e3e-QiZukfy8GTKr2NXCofdYV3q5COA" | |
vary | X-User-Agent, Accept-Encoding | |
via | 1.1 varnish (Varnish/6.6) | |
x-content-id | 3A5AXgxzmGFPgpK2ki93wd 6idpXafqOcgsaYAIBVhk2F 3QRAOzt3YViBqLlqVRAcvC 3huwvu8iPfPxTEd0GXY51p 7DqcVvCFYI6RXnrRBpl18I 29aUawkL4QbCdsOTgTiHMz 24HYaTpSQTZqamYZ5FTGFt 32PfeiYxRr97nIDRQYQBXV 2148IDKg95BwmRA9cT7oji 1WPKrtg9vlvihafSbMZqP8 1JMzJ0JE1S3ppcRZfaz68T 2d4iaVcRxpliavBATWkGw0 5BBeqDlKjoGVPZ2HtnbJwv 1UvQfXfuXl416XG8aK1sTk 2JHRAnlfXWmylFCRu7iAqH 4cRTLzvYGCUZSxXaDHfq2L 5usvPflhBgdfba9v6Ox6Yq qDutO81KXDPFKrnjDPHtR 2DT6pYyYxGByzXmOyEQ8ZY 6IztHRshUl4RbYUynRFaWw 5WbE7LiJa3lfF5Slu59jVN te4wqW1jv0TmqE6QASSGb 5qLCnDpMPm8fv1bw4M5AUY 3iAzJOai40MOcHKMSH3eBW 78gWQKIAWoFlDdrnIBlDKu 2uuxnNA285Kz1zdyWrzDCN mtN9V6f8hDaONKcEkoZ87 3QCTsJjHgNOMxk2kjEzYym 6VMeFf9zGVXnTtLGIOSEne 1TQDrkjaykOsrSMXNCQCDx 6eMVWfDz30qwLy1iZGpd4Q 7n8FHbVULIAclbFe02NXfZ 6MliH3Pad4fjHk1iRyLUB0 5yGQ0ApoawVYb5E6DRyyVq 7d2y7Bd5JJawSXzXEbrHy7 3XPMBpLP4Bt7avr0iTE5rP 24kgXk1CUfrncTeOaOwM8z tEu0pl2ZXZ3h0zEBP4tKp 3ajp8qapkC9zaSU1HROYRa 6ZtCo0FYm9LX37CbOH0MBc 3es1MRBx9xKdjr5pp6PPvV 2KOXTLsi1KnkLNYOgkTITK o1iCaKF355xSVI2F4CEwj 6BUtgz6AZD1oGRuANUsUpr 4iDpKK2B5XOOCHYiUoSOgq 4chciC1nYSxlmafya9IVQc 4lwv3VTMKttr2x4UsIwSTL 3Y0oArKPThuU0LyYdaCPiN m0gbjeJTSuJ76oKoq3INY 7cwng1LcL1Ktihzbqqjx8C 6HKj98jVvaR9G1yiO0O8xq 2elLUUqkmeCnkhHxl8gQKx 219SQNnzlLcRMC96l2AoIE 4gbTYIVmzXRkIrzxFXltO9 o6JvUEtYNjO4AZZfcuGW7 754TuJtEnO8LuPNAMmv6sW 2tQTGPA6wDXVJGVqnBjaUd 6OsSeYDiUH8GzA4fPtvSqw Yw4oCT8EI7v7tUVtDA9tJ 7rJwKSjP5lkXlyghxcGtER 3jkP2i4CKb6sW9TYjB9Mfg 72Bieozn3mj5uP4eLQwTM5 59riAeiEEhUasvHhov2dZl 6atn5ZkzGbM5x2R8zZ9GrE 30fli6k3Oy883fHVNIQcAW bcbygCRa9D6eQYA522LTn l8fM0h9vSL02bHdRCYbg2 6tL0aJCuoEX4tIYIov9Ld7 20Ai5ANHexZzAhTaf6hq1p 3BPf4dyHE7QopaztTovSYc 5LrRS0smsYeMxGZ8RWehE8 1PzyQAKDsmtbhocEv0DlsY 3RGJ4s9v9Tb0o85E0dKyR5 3DZD7DgMLtUJX1CiettwYP 16XQAZFVaR4KKRP2sdYp3S 2SAoUNm5Oavm1gm2d6pK35 0d6lGGm9PpanjP1Sleopu 1iw7Z8aDCMkMWI7Eo9hX7V 58QmD9PmNrAXmtQmLTaENf 7CSFrV8qx3tHOyiKLhKoPL 5lo4S90wcFaw8yjK1Cqr53 sHL7FqTQbNctZHG1FpAZ3 jltqAJU2F8sHVy07q5S8w 1c5THW0fluTSFRv6UVEydy 53t14sBykwafKysNcscshC 49VywxOAvCynvZ71u9R7Zq 1mNGqg8LOQGF37CUdsJTID 4ht64S9XP6zTazkOxiimPd 4Tn9V01BsqjfxpXyg1ZfvA 51TMkUOps5YPLoSxmMjqVg 44g2tXQjmnN1ThiCKOwG3n WuYKuVh7OsrBLmMj8KXsf 1CoryHIZkRW7JC6Vr2DDDK 2XiGCqqbXqT9mrX5hFDVQ0 26U0tKBEoEFdjFod0uL8BY | |
x-frontend-pod | frontend-nginx-nginx-frontend-1 | |
x-varnish | 10470798 12365201 | |
x-varnish-host | varnish-56d455cf59-tt2q2 | |
x-vary-mobile | true | |
x-envoy-upstream-service-time | 601 | |
x-volterra-location | sv10-sjc | |
server | volt-adc | |
connection | close | |
transfer-encoding | chunked |

Miscellaneous | |
Test date | Fri, 12 Sep 2025 13:52:29 UTC |
Test duration | 47.616 seconds |
HTTP status code | 200 |
HTTP server signature | volt-adc |
Server hostname | 185-94-140-73.acorus.net |
SSL Report v2.4.1