SSL Report:
www.heisrema.com
(45.60.31.79)
Assessed on: Sat, 22 Nov 2025 23:37:34 UTC
| Clear cache
Summary
0
20
40
60
80
100
Certificate
Protocol Support
Key Exchange
Cipher Strength
Visit our documentation page
for more information, configuration guides, and books. Known issues are documented
here.
This site works only in browsers with SNI support.
This server supports TLS 1.3. MORE INFO »
Certificate #1: RSA 2048 bits (SHA256withRSA)
|
Server Key and Certificate #1
|
|
| Subject |
iga-wp1-elb-k.umg-wp.com
Fingerprint SHA256: ab500f12369b7d9a94bc6d1923695fa8a998fec86d358544cf302ceef992522e Pin SHA256: 28fB+H3VBOIx1HcQZwMAS3AztDoaXyr0gieUIfVBYd4= |
| Common names | iga-wp1-elb-k.umg-wp.com |
| Alternative names | iga-wp1-elb-k.umg-wp.com thatmexicanot.net www.thatmexicanot.net 42duggmusic.com www.42duggmusic.com 6lack.com www.6lack.com agreatchaos.com www.agreatchaos.com amaarae.world www.amaarae.world amalougistics.com www.amalougistics.com ambermarkmusic.com www.ambermarkmusic.com arilennox.com www.arilennox.com benplattmusic.com www.benplattmusic.com bigboogiemusic.com www.bigboogiemusic.com blackpinkmusic.com www.blackpinkmusic.com bornthisway.ladygaga.com www.bornthisway.ladygaga.com bradenbales.com www.bradenbales.com bts-official.us www.bts-official.us camilacabello.com www.camilacabello.com carlyraemusic.com www.carlyraemusic.com chinopacasofficial.com www.chinopacasofficial.com cucomusic.com www.cucomusic.com d4vd.io www.d4vd.io dawnofchromatica.com www.dawnofchromatica.com dermotkennedy.com www.dermotkennedy.com destroylonely.net www.destroylonely.net dreamacademyhq.com www.dreamacademyhq.com ebonyrileymusic.com www.ebonyrileymusic.com ellamai.com www.ellamai.com elpadrinitotoys.com www.elpadrinitotoys.com ericdoa.com www.ericdoa.com finneasofficial.com www.finneasofficial.com flatlandcavalry.com www.flatlandcavalry.com glaivemusic.com www.glaivemusic.com glorillaofficial.com www.glorillaofficial.com gracieabrams.com www.gracieabrams.com gwenstefani.com www.gwenstefani.com heisrema.com www.heisrema.com heyprentiss.com www.heyprentiss.com heyrolemodel.com www.heyrolemodel.com iamdstrct.com www.iamdstrct.com iamjustamirah.com www.iamjustamirah.com iheartnige.com www.iheartnige.com itslebrajolie.com www.itslebrajolie.com ivancornejoofficial.com www.ivancornejoofficial.com jaboukie.com www.jaboukie.com janadiab.com www.janadiab.com jawny.com www.jawny.com jenniferhudson.world www.jenniferhudson.world jeonsomiofficial.com www.jeonsomiofficial.com kaceymusgraves.com www.kaceymusgraves.com kaliuchis.com www.kaliuchis.com karriofficial.com www.karriofficial.com kendricklamar.com www.kendricklamar.com khea.com.ar www.khea.com.ar kingsofleon.com www.kingsofleon.com lacikayebooth.com www.lacikayebooth.com losprimosdeleste.com www.losprimosdeleste.com marshaambrosius.com www.marshaambrosius.com midwxst.com www.midwxst.com mozzymusic.com www.mozzymusic.com mudbabyru.com www.mudbabyru.com musicbywisp.com www.musicbywisp.com nightvisions.imaginedragonsmusic.com obaimusic.com www.obaimusic.com oceanxkungfu.com www.oceanxkungfu.com officialskillababy.com www.officialskillababy.com oliviarodrigo.com www.oliviarodrigo.com raesremmurd.com www.raesremmurd.com reneerapp.com www.reneerapp.com riovaz.com www.riovaz.com rob49official.com www.rob49official.com shenseeamusic.com www.shenseeamusic.com skyerileymusic.com www.skyerileymusic.com subaruboysworldwide.com www.subaruboysworldwide.com taeyangofficial.com www.taeyangofficial.com thefame.ladygaga.com thefamemonster.ladygaga.com thepartyneverends.com www.thepartyneverends.com tiacorine.world www.tiacorine.world tour.fantasygateway.io towabirdofficial.com www.towabirdofficial.com vegas.ladygaga.com vincentmasonmusic.com www.vincentmasonmusic.com vonniknoxville.com www.vonniknoxville.com vultureseatthemosttour.com www.vultureseatthemosttour.com weonlytalkaboutrealshitwhenwerefuckedup.com www.weonlytalkaboutrealshitwhenwerefuckedup.com westsideboogie.com www.westsideboogie.com yeatofficial.com www.yeatofficial.com yungbludofficial.com www.yungbludofficial.com www.karolgmusic.com karolgmusic.com cocash.net www.cocash.net groovyq.com www.groovyq.com icountfast.com www.icountfast.com jayrock.com www.jayrock.com rosemarieofficial.com www.rosemarieofficial.com strictly4thevoiceless.com www.strictly4thevoiceless.com xaviofficial.com www.xaviofficial.com xboygeniusx.com www.xboygeniusx.com yopierre.com www.yopierre.com yxngkaofficial.com www.yxngkaofficial.com zeddinthepark.com www.zeddinthepark.com jordanward.world wwww.jordanward.world shopau.carlyraemusic.com |
| Serial Number | 09b9fe20b95a60cd67f818f33c9df66f |
| Valid from | Wed, 09 Apr 2025 00:00:00 UTC |
| Valid until | Wed, 08 Apr 2026 23:59:59 UTC (expires in 4 months and 16 days) |
| Key | RSA 2048 bits (e 65537) |
| Weak key (Debian) | No |
| Issuer | DigiCert Global G2 TLS RSA SHA256 2020 CA1
AIA: http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt |
| Signature algorithm | SHA256withRSA |
| Extended Validation | No |
| Certificate Transparency | Yes (certificate) |
| OCSP Must Staple | No |
| Revocation information |
CRL, OCSP CRL: http://crl3.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl OCSP: http://ocsp.digicert.com |
| Revocation status | Good (not revoked)
CRL ERROR: IOException occurred |
| DNS CAA | No (more info) |
| Trusted | Yes
Mozilla Apple Android Java Windows |
|
|
Certificate #2: RSA 2048 bits (SHA256withRSA)
No SNI
|
|
Configuration
| Protocols | |
| TLS 1.3 | Yes |
| TLS 1.2 | Yes* |
| TLS 1.1 | No |
| TLS 1.0 | No |
| SSL 3 | No |
| SSL 2 | No |
| (*) Experimental: Server negotiated using No-SNI | |
| Cipher Suites | ||
|
# TLS 1.3 (suites in server-preferred order)
|
||
TLS_AES_128_GCM_SHA256 (0x1301)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
TLS_CHACHA20_POLY1305_SHA256 (0x1303)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_AES_256_GCM_SHA384 (0x1302)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
|
# TLS 1.2 (suites in server-preferred order)
|
||
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
256 | |
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
256 | |
TLS_RSA_WITH_AES_128_GCM_SHA256 (0x9c)
WEAK
|
128 | |
TLS_RSA_WITH_AES_256_GCM_SHA384 (0x9d)
WEAK
|
256 | |
TLS_RSA_WITH_AES_128_CBC_SHA256 (0x3c)
WEAK
|
128 | |
TLS_RSA_WITH_AES_256_CBC_SHA256 (0x3d)
WEAK
|
256 | |
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f)
WEAK
|
128 | |
TLS_RSA_WITH_AES_256_CBC_SHA (0x35)
WEAK
|
256 | |
| Handshake Simulation | |||
| Android 4.4.2 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 5.0.0 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 6.0 | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 7.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Android 8.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Android 8.1 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Android 9.0 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| BingPreview Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Chrome 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Chrome 69 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Chrome 70 / Win 10 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Chrome 80 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Firefox 31.3.0 ESR / Win 7 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 47 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 62 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Firefox 73 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Googlebot Feb 2018 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| IE 11 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win 8.1 R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win Phone 8.1 R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win Phone 8.1 Update R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Edge 15 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 16 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 18 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 13 / Win Phone 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 8u161 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 11.0.3 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 12.0.1 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.0.1l R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.0.2s R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.1.0k R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| OpenSSL 1.1.1c R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Safari 6 / iOS 6.0.1 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 7 / iOS 7.1 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 7 / OS X 10.9 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 8 / iOS 8.4 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 8 / OS X 10.10 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 9 / OS X 10.11 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / iOS 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / OS X 10.12 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 12.1.2 / MacOS 10.14.6 Beta R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Safari 12.1.1 / iOS 12.3.1 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Apple ATS 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Yahoo Slurp Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| YandexBot Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
|
# Not simulated clients (Protocol mismatch)
|
|||
| Android 2.3.7 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Android 4.0.4 |
Protocol mismatch (not simulated) |
||
| Android 4.1.1 |
Protocol mismatch (not simulated) |
||
| Android 4.2.2 |
Protocol mismatch (not simulated) |
||
| Android 4.3 |
Protocol mismatch (not simulated) |
||
| Baidu Jan 2015 |
Protocol mismatch (not simulated) |
||
| IE 6 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 7 / Vista |
Protocol mismatch (not simulated) |
||
| IE 8 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 8-10 / Win 7 R |
Protocol mismatch (not simulated) |
||
| IE 10 / Win Phone 8.0 |
Protocol mismatch (not simulated) |
||
| Java 6u45 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Java 7u25 |
Protocol mismatch (not simulated) |
||
| OpenSSL 0.9.8y |
Protocol mismatch (not simulated) |
||
| Safari 5.1.9 / OS X 10.6.8 |
Protocol mismatch (not simulated) |
||
| Safari 6.0.4 / OS X 10.8.4 R |
Protocol mismatch (not simulated) |
||
| (1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it. | |||
| (2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI. | |||
| (3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version. | |||
| (R) Denotes a reference browser or client, with which we expect better effective security. | |||
| (All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE). | |||
| (All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake. | |||
| Protocol Details | |
| Secure Renegotiation | Supported |
| Secure Client-Initiated Renegotiation | No |
| Insecure Client-Initiated Renegotiation | No |
| BEAST attack | Mitigated server-side (more info) |
| POODLE (SSLv3) | No, SSL 3 not supported (more info) |
| POODLE (TLS) | No (more info) |
| Zombie POODLE | No (more info)
TLS 1.2 : 0xc027
|
| GOLDENDOODLE | No (more info)
TLS 1.2 : 0xc027
|
| OpenSSL 0-Length | No (more info)
TLS 1.2 : 0xc027
|
| Sleeping POODLE | No (more info)
TLS 1.2 : 0xc027
|
| Downgrade attack prevention | Yes, TLS_FALLBACK_SCSV supported (more info) |
| SSL/TLS compression | No |
| RC4 | No |
| Heartbeat (extension) | No |
| Heartbleed (vulnerability) | No (more info) |
| Ticketbleed (vulnerability) | No (more info) |
| OpenSSL CCS vuln. (CVE-2014-0224) | No (more info) |
| OpenSSL Padding Oracle vuln. (CVE-2016-2107) |
No (more info) |
| ROBOT (vulnerability) | No (more info) |
| Forward Secrecy | Yes (with most browsers) ROBUST (more info) |
| ALPN | Yes h2 |
| NPN | Yes h2 http/1.1 |
| Session resumption (caching) | Yes |
| Session resumption (tickets) | Yes |
| OCSP stapling | Yes |
| Strict Transport Security (HSTS) | No |
| HSTS Preloading | Not in: Chrome Edge Firefox IE |
| Public Key Pinning (HPKP) | No (more info) |
| Public Key Pinning Report-Only | No |
| Public Key Pinning (Static) | No (more info) |
| Long handshake intolerance | No |
| TLS extension intolerance | No |
| TLS version intolerance | No |
| Incorrect SNI alerts | No |
| Uses common DH primes | No, DHE suites not supported |
| DH public server param (Ys) reuse | No, DHE suites not supported |
| ECDH public server param reuse | No |
| Supported Named Groups | x25519, secp256r1, x448, secp521r1, secp384r1 (server preferred order) |
| SSL 2 handshake compatibility | Yes |
| 0-RTT enabled | No |
|
|
|
1 https://www.heisrema.com/
(HTTP/1.1 403 Forbidden)
| 1 | |
| Content-Type | text/html | |
| Cache-Control | no-cache, no-store | |
| Connection | close | |
| Content-Length | 877 | |
| X-Iinfo | 41-8119967-0 0NNN RT(1763854582902 44) q(0 -1 -1 11) r(0 -1) B15(4,200,0) U18 | |
| Set-Cookie | visid_incap_3167356=uR8KKIy0S/SPSCO4GixJMPZIImkAAAAAQUIPAAAAAAD/SPtd70E/kzEBKylA844Q; expires=Sun, 22 Nov 2026 07:08:26 GMT; HttpOnly; path=/; Domain=.heisrema.com | |
| Set-Cookie | incap_ses_188_3167356=LODvDVDJdnI5vlL9DumbAvZIImkAAAAA/1CNrVvVfYD3wS6PuSGWjg==; path=/; Domain=.heisrema.com | |
| X-Robots-Tag | noimageai, noai | |
| Miscellaneous | |
| Test date | Sat, 22 Nov 2025 23:36:17 UTC |
| Test duration | 76.823 seconds |
| HTTP status code | 403 |
| HTTP server signature | - |
| Server hostname | - |
SSL Report v2.4.1
