SSL check results of oh.gov.hu

NEW You can also bulk check multiple servers.

Discover if the mail servers for oh.gov.hu can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Thu, 18 Mar 2021 12:29:59 +0000

The mailservers of oh.gov.hu can be reached through an encrypted connection.

However, we found problems that may affect the security.

Servers

Incoming Mails

These servers are responsible for incoming mails to @oh.gov.hu addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.oh.gov.hu
193.225.215.143
10
supported
*.oh.gov.hu
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s
mx2.oh.gov.hu
193.6.241.194
20
supported
*.oh.gov.hu
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s

Outgoing Mails

We have received emails from these servers with @oh.gov.hu sender addresses. Test mail delivery

Host TLS Version & Cipher
mail.oh.gov.hu (193.225.215.143)
TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256

Certificates

First seen at:

serialNumber=1.3.6.1.4.1.21528.2.3.2.2835,CN=*.oh.gov.hu,O=Oktatási Hivatal,L=Budapest,C=HU

Certificate chain
  • *.oh.gov.hu
    • remaining
    • 2048 bit
    • sha256WithRSAEncryption
    • Unknown Authority

      e-Szigno SSL CA 2014
Subject
Country (C)
  • HU
Locality (L)
  • Budapest
Organization (O)
  • Oktatási Hivatal
Common Name (CN)
  • *.oh.gov.hu
Serial number
  • 1.3.6.1.4.1.21528.2.3.2.2835
Alternative Names
  • *.oh.gov.hu
  • oh.gov.hu
Issuer
Country (C)
  • HU
Locality (L)
  • Budapest
Organization (O)
  • Microsec Ltd.
Common Name (CN)
  • e-Szigno SSL CA 2014
Email
  • info@e-szigno.hu
validity period
Not valid before
2020-10-22
Not valid after
2021-11-22
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Client Authentication
  • TLS Web Server Authentication
Fingerprints
SHA256
01:98:FA:92:DF:33:D1:D3:39:96:38:8A:20:89:BD:E9:EC:ED:7A:4C:63:52:32:18:39:E9:27:17:08:52:14:9B
SHA1
A2:0D:1B:A3:75:57:07:86:F2:9D:E7:56:70:57:29:67:64:D0:40:E1
X509v3 extensions
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : F6:5C:94:2F:D1:77:30:22:14:54:18:08:30:94:56:8E:
  • E3:4D:13:19:33:BF:DF:0C:2F:20:0B:CC:4E:F1:64:E3
  • Timestamp : Oct 22 08:08:49.403 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:BB:FD:0C:47:22:12:0A:FC:58:DB:21:
  • B6:5B:A9:0D:6E:83:59:25:E2:DC:FD:66:CB:A3:31:DB:
  • A6:7C:F0:2B:2F:02:21:00:F8:9A:23:3F:92:A0:E0:99:
  • 8F:38:FB:09:0C:29:60:22:F5:29:6F:B3:28:FA:F1:D1:
  • 5D:E3:9F:65:59:FB:F9:07
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 55:81:D4:C2:16:90:36:01:4A:EA:0B:9B:57:3C:53:F0:
  • C0:E4:38:78:70:25:08:17:2F:A3:AA:1D:07:13:D3:0C
  • Timestamp : Oct 22 08:08:50.234 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:4C:76:91:01:B9:C8:68:1C:9A:A2:82:BA:
  • 6A:49:BC:04:67:3F:F8:27:74:CB:C1:B3:48:0B:8E:BA:
  • D2:05:59:E2:02:21:00:F4:10:E4:7D:AE:B9:68:5C:5F:
  • 3A:8B:FD:9E:E3:33:5E:47:7F:C0:B4:75:B2:BB:B7:A0:
  • 79:C1:5E:50:7A:FF:B1
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 6F:53:76:AC:31:F0:31:19:D8:99:00:A4:51:15:FF:77:
  • 15:1C:11:D9:02:C1:00:29:06:8D:B2:08:9A:37:D9:13
  • Timestamp : Oct 22 08:08:50.507 2020 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:6D:87:F3:0F:E4:95:0E:0B:1C:86:47:AD:
  • 9F:9A:5D:7B:3D:BB:AF:9C:48:05:40:06:24:5C:D0:CB:
  • 09:79:02:C2:02:20:33:A8:2E:3D:3A:30:4A:B4:A8:58:
  • 61:80:7A:7B:CC:55:C8:35:73:83:5A:3D:08:E5:2B:C8:
  • 28:19:E9:DC:B4:75
certificatePolicies
  • Policy: 1.3.6.1.4.1.21528.2.1.1.159.2.16
  • CPS: http://cp.e-szigno.hu/acps
  • User Notice:
  • Explicit Text: Organizational validation certificate for website authentication. Issued via face-to-face registration.
  • User Notice:
  • Explicit Text: The certificate is associated with an organization.
  • User Notice:
  • Explicit Text: Szervezet-ellenőrzött weboldal-hitelesítő tanúsítvány. Regisztrációkor a személyes megjelenés kötelező.
  • User Notice:
  • Explicit Text: A tanúsítvány szervezethez kapcsolódik.
  • Policy: 0.4.0.2042.1.7
  • Policy: 2.23.140.1.2.2
subjectKeyIdentifier
  • 29:E9:16:14:37:C7:E5:01:48:14:E6:5C:F5:FA:E0:2D:AC:92:B0:08
authorityKeyIdentifier
  • keyid:DE:6A:B0:4E:43:AA:08:41:47:74:BF:A5:8A:81:54:4C:20:C5:75:28
crlDistributionPoints
  • Full Name:
  • URI:http://sslca2014-crl1.e-szigno.hu/sslca2014.crl
  • Full Name:
  • URI:http://sslca2014-crl2.e-szigno.hu/sslca2014.crl
  • Full Name:
  • URI:http://sslca2014-crl3.e-szigno.hu/sslca2014.crl
authorityInfoAccess
  • OCSP - URI:http://sslca2014-ocsp1.e-szigno.hu
  • OCSP - URI:http://sslca2014-ocsp2.e-szigno.hu
  • OCSP - URI:http://sslca2014-ocsp3.e-szigno.hu
  • CA Issuers - URI:http://sslca2014-ca1.e-szigno.hu/sslca2014.crt
  • CA Issuers - URI:http://sslca2014-ca2.e-szigno.hu/sslca2014.crt
  • CA Issuers - URI:http://sslca2014-ca3.e-szigno.hu/sslca2014.crt