SSL Report:
www.passpass.fr
(185.60.149.131)
Assessed on: Mon, 27 Oct 2025 14:07:18 UTC
| Clear cache
Summary
0
20
40
60
80
100
Certificate
Protocol Support
Key Exchange
Cipher Strength
Visit our documentation page
for more information, configuration guides, and books. Known issues are documented
here.
This site works only in browsers with SNI support.
This server supports TLS 1.3. MORE INFO »
Certificate #1: RSA 2048 bits (SHA256withRSA)
|
Server Key and Certificate #1
|
|
| Subject |
www.passpass.fr
Fingerprint SHA256: b7ac9036bcd143c16d8c2ac67186bbadcdd35b4938e24aa1de9335b6f5d97d7a Pin SHA256: i+LU7kVktVzVBHL+R/PPvoukM7kOVT7YlhIijRGlPgw= |
| Common names | www.passpass.fr |
| Alternative names | www.passpass.fr |
| Serial Number | 05e7689b6c5b6142cf042d94fc6d17127eca |
| Valid from | Thu, 09 Oct 2025 07:02:55 UTC |
| Valid until | Wed, 07 Jan 2026 07:02:54 UTC (expires in 2 months and 10 days) |
| Key | RSA 2048 bits (e 65537) |
| Weak key (Debian) | No |
| Issuer | R13
AIA: http://r13.i.lencr.org/ |
| Signature algorithm | SHA256withRSA |
| Extended Validation | No |
| Certificate Transparency | Yes (certificate) |
| OCSP Must Staple | No |
| Revocation information |
CRL CRL: http://r13.c.lencr.org/75.crl |
| Revocation status | Good (not revoked) |
| DNS CAA | No (more info) |
| Trusted | Yes
Mozilla Apple Android Java Windows |
|
|
Certificate #2: RSA 2048 bits (SHA256withRSA)
No SNI
|
Additional Certificates (if supplied)
|
|
| Certificates provided | 1 (884 bytes) |
| Chain issues | None |
|
|
Configuration
| Protocols | |
| TLS 1.3 | Yes |
| TLS 1.2 | Yes* |
| TLS 1.1 | No |
| TLS 1.0 | No |
| SSL 3 | No |
| SSL 2 | No |
| (*) Experimental: Server negotiated using No-SNI | |
| Cipher Suites | ||
|
# TLS 1.3 (suites in server-preferred order)
|
||
TLS_AES_256_GCM_SHA384 (0x1302)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_CHACHA20_POLY1305_SHA256 (0x1303)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_AES_128_GCM_SHA256 (0x1301)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
|
# TLS 1.2 (suites in server-preferred order)
|
||
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
| Handshake Simulation | |||
| Android 4.4.2 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 5.0.0 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 6.0 | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 7.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Android 8.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Android 8.1 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Android 9.0 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| BingPreview Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Chrome 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Chrome 69 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Chrome 70 / Win 10 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Chrome 80 / Win 10 R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Firefox 31.3.0 ESR / Win 7 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 47 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 62 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Firefox 73 / Win 10 R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Googlebot Feb 2018 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| IE 11 / Win 7 R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win 8.1 R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win Phone 8.1 R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win Phone 8.1 Update R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Edge 15 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 16 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 18 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 13 / Win Phone 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 8u161 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 11.0.3 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH secp256r1 FS |
| Java 12.0.1 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH secp256r1 FS |
| OpenSSL 1.0.1l R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.0.2s R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.1.0k R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| OpenSSL 1.1.1c R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Safari 6 / iOS 6.0.1 |
Server sent fatal alert: handshake_failure |
||
| Safari 7 / iOS 7.1 R |
Server sent fatal alert: handshake_failure |
||
| Safari 7 / OS X 10.9 R |
Server sent fatal alert: handshake_failure |
||
| Safari 8 / iOS 8.4 R |
Server sent fatal alert: handshake_failure |
||
| Safari 8 / OS X 10.10 R |
Server sent fatal alert: handshake_failure |
||
| Safari 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 9 / OS X 10.11 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / iOS 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / OS X 10.12 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 12.1.2 / MacOS 10.14.6 Beta R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Safari 12.1.1 / iOS 12.3.1 R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Apple ATS 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Yahoo Slurp Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| YandexBot Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
|
# Not simulated clients (Protocol mismatch)
|
|||
| Android 2.3.7 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Android 4.0.4 |
Protocol mismatch (not simulated) |
||
| Android 4.1.1 |
Protocol mismatch (not simulated) |
||
| Android 4.2.2 |
Protocol mismatch (not simulated) |
||
| Android 4.3 |
Protocol mismatch (not simulated) |
||
| Baidu Jan 2015 |
Protocol mismatch (not simulated) |
||
| IE 6 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 7 / Vista |
Protocol mismatch (not simulated) |
||
| IE 8 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 8-10 / Win 7 R |
Protocol mismatch (not simulated) |
||
| IE 10 / Win Phone 8.0 |
Protocol mismatch (not simulated) |
||
| Java 6u45 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Java 7u25 |
Protocol mismatch (not simulated) |
||
| OpenSSL 0.9.8y |
Protocol mismatch (not simulated) |
||
| Safari 5.1.9 / OS X 10.6.8 |
Protocol mismatch (not simulated) |
||
| Safari 6.0.4 / OS X 10.8.4 R |
Protocol mismatch (not simulated) |
||
| (1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it. | |||
| (2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI. | |||
| (3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version. | |||
| (R) Denotes a reference browser or client, with which we expect better effective security. | |||
| (All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE). | |||
| (All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake. | |||
| Protocol Details | |
| Secure Renegotiation | Supported |
| Secure Client-Initiated Renegotiation | No |
| Insecure Client-Initiated Renegotiation | No |
| BEAST attack | Mitigated server-side (more info) |
| POODLE (SSLv3) | No, SSL 3 not supported (more info) |
| POODLE (TLS) | No (more info) |
| Zombie POODLE | No (more info) |
| GOLDENDOODLE | No (more info) |
| OpenSSL 0-Length | No (more info) |
| Sleeping POODLE | No (more info) |
| Downgrade attack prevention | Yes, TLS_FALLBACK_SCSV supported (more info) |
| SSL/TLS compression | No |
| RC4 | No |
| Heartbeat (extension) | No |
| Heartbleed (vulnerability) | No (more info) |
| Ticketbleed (vulnerability) | No (more info) |
| OpenSSL CCS vuln. (CVE-2014-0224) | No (more info) |
| OpenSSL Padding Oracle vuln. (CVE-2016-2107) |
No (more info) |
| ROBOT (vulnerability) | No (more info) |
| Forward Secrecy | Yes (with most browsers) ROBUST (more info) |
| ALPN | Yes h2 http/1.1 |
| NPN | No |
| Session resumption (caching) | Yes |
| Session resumption (tickets) | No |
| OCSP stapling | No |
| Strict Transport Security (HSTS) | Yes TOO SHORT (less than 180 days)
max-age=1000 |
| HSTS Preloading | Not in: Chrome Edge Firefox IE |
| Public Key Pinning (HPKP) | No (more info) |
| Public Key Pinning Report-Only | No |
| Public Key Pinning (Static) | No (more info) |
| Long handshake intolerance | No |
| TLS extension intolerance | No |
| TLS version intolerance | No |
| Incorrect SNI alerts | No |
| Uses common DH primes | No, DHE suites not supported |
| DH public server param (Ys) reuse | No, DHE suites not supported |
| ECDH public server param reuse | No |
| Supported Named Groups | x25519, secp256r1, x448, secp521r1, secp384r1 (server preferred order) |
| SSL 2 handshake compatibility | No |
| 0-RTT enabled | No |
|
|
|
1 https://www.passpass.fr/
(HTTP/1.1 200 OK)
| 1 | |
| Date | Mon, 27 Oct 2025 14:06:17 GMT | |
| Content-Type | text/html; charset=UTF-8 | |
| Transfer-Encoding | chunked | |
| Connection | close | |
| X-Powered-By | PHP/8.3.21 | |
| Cache-Control | max-age=31536000, public | |
| X-DOESI | 1 | |
| Content-language | fr | |
| X-Content-Type-Options | nosniff | |
| X-Frame-Options | SAMEORIGIN | |
| Expires | Sun, 19 Nov 1978 05:00:00 GMT | |
| X-Cache-Debug | 1 | |
| X-Grace | 10 | |
| X-TTL | 2629746 | |
| X-Tag | 1k2y 1kc2 1kbg 1k8c 1k9w 1k8g 1k95 1kad 1kfe 1k8v 1k6b 3ue 1k8x 1k9a 1kbh 1k7q 1kal 1ka0 1kau 1k9n 1k8x 1kae 1ka2 1k88 1kb5 1kck 1k9w 1k8p 1kaw 1k9r 1kae 1kc7 1kch 1k8t 1k9x 1kds 1kbq 1kbl 1kak 1k8m 1kck 1kcg 1kay 1k6y 1k7h 1kat 1keo 1k8p 1kar 1kej 3u7 1keo 3u6 1keq 1k6f 1k9u 1k83 1kan 1kbb 1kap 1k56 1k5x 1c4 2x 1k9l 1k8x 2m 1f9 5o 16h 1fb 16j 1fa 16i 5r 1f1m 168j 1k3w 1k6b 1cku 1c13m 1c15j 1k7k 1c5k 1c10x 1cp 2j 1cjd 1b3n 1cjt 1ff 16u 3uf 1k79 2k 1cd 1ce 1cf 1chc 1c10s 1c10t 1c10u 1c10v 1c10w 1c10x 1c10y 1c10z 1c110 1c111 1c112 1c113 1c114 1c115 1c116 1c117 1c118 1c119 1c11a 1c11b 1c11c 1c11d 1c11e 1c11f 1c11g 1c11h 1c11i 1c11j 1c11k 1k7f 1v1f 1f1b 1k4k 1688 1b1 1f2q 16a8 1f2b 16a9 1f1q 168m 1b1u 1f2z 16a7 1f2y 16a6 1f1d 168p 1f1e 168r 1f1f 168s 1f1g 168t 1f1h 168u 1f1i 168v 1f1j 168w 1f1k 168x 1f1l 168y 1f1m 168z 1f1n 1690 1f1o 1691 1f1p 1692 1f1q 1693 1f1r 1694 1f1s 1695 1f1t 1696 1f1u 1697 1f1v 1698 1f1w 1699 1f1x 169a 1f1y 169b 1f1z 169c 1f20 169d 1f21 169e 1f22 169f 1f23 169g 3ua 3ud 1fe 16bd 1kck 16t 16q 16o 16n 16m 3uc 1k6t 1c4g 1f3m 16cp 1fc 16k 3u4 1c1nx 1c1ze 1c18r 1ckk 1v1m 6e 4h9 1k7j 1f16 1n17 1683 1k8b 1b4k 4hp 1f5e 1n1j 16el 1fc6 1n1x 161te 1fch 1n1p 161vk 1b88 3ub 1c13d 1c13e 1c13c 1f3c 16bv 1chd 1f3b 16bu 1c9 1f2m 16ak 1ca 1f3q 16bt 3ug 3u3 1cjk 1fau 1n12 161mu 1kcl 1k60 1k69 1k6i 1k6z 1bo 2p 1k57 1cg 1c6s 1c6t 1ch4 1c13l 1chv 1chs 1chu 1ckr 1c8 1c15e 1f3o 16cj 1f2t 16cg 1f2u 16ch 1f2r 16cf 1f2o 16cd 1f2m 16cy 1f2n 16cl 1f3u 16cq 1f2l 16cx 1f2j 16cu 1f2k 16cw 1f2x 16ct 1f2g 16cs 1f2e 16cq 1f2f 16cr 1f2d 16cp 1k8b 1f7 16f 2l 4z 1k6v 1k6c | |
| X-Adv-Varnish | Cache-enabled | |
| X-Deflate-Key | b91f02cf5af93c1c9141ba365d5852c9d12df6fd39f8b5d9c3b80dc1bc1428e1 | |
| X-XSS-Protection | 1 | |
| Strict-Transport-Security | max-age=1000 | |
| X-Cacheable | YES | |
| X-Varnish-Secret | dkxkpqd_6yhixeiimhwuq8dvigvkcrp-ttctuo35ltk | |
| X-TTL2 | 2629746.000 | |
| X-Varnish | 3773127 | |
| Age | 0 | |
| Via | 1.1 varnish (Varnish/6.0) | |
| X-Url | / | |
| X-Host | www.passpass.fr | |
| X-Requested-With | ||
| X-Forwarded-Proto | https | |
| X-Bin | role:anonymous | |
| X-Varnish-Cache | MISS | |
| Cache-Tags | MISS | |
| X-Cache-Hits | 0 | |
| Vary | X-Bin,Accept-Encoding, X-Device, Cookie | |
| Accept-Ranges | bytes | |
| Miscellaneous | |
| Test date | Mon, 27 Oct 2025 14:06:04 UTC |
| Test duration | 73.858 seconds |
| HTTP status code | 200 |
| HTTP server signature | - |
| Server hostname | - |
SSL Report v2.4.1
