SSL check results of hzg.de

NEW You can also bulk check multiple servers.

Discover if the mail servers for hzg.de can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Tue, 22 Mar 2016 10:14:49 +0000

The mailservers of hzg.de can be reached through an encrypted connection.

However, we found problems that may affect the security.

Servers

Incoming Mails

These servers are responsible for incoming mails to @hzg.de addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
iron1.hzg.de
141.4.217.10
20
supported
iron1.hzg.de
DANE
missing
PFS
unsupported
Heartbleed
not vulnerable
Weak ciphers
supported
  • SSL_RSA_WITH_RC4_128_SHA
  • TLSv1.0
  • SSLv3
1 s
iron2.hzg.de
141.4.217.11
30
supported
iron2.hzg.de
DANE
missing
PFS
unsupported
Heartbleed
not vulnerable
Weak ciphers
supported
  • SSL_RSA_WITH_RC4_128_SHA
  • TLSv1.0
  • SSLv3
1 s

Outgoing Mails

We have received emails from these servers with @hzg.de sender addresses. Test mail delivery

Host TLS Version & Cipher
iron1.hzg.de (141.4.217.10)
TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384

Certificates

First seen at:

CN=iron2.hzg.de,O=Helmholtz-Zentrum Geesthacht GmbH,L=Geesthacht,ST=Schleswig-Holstein,C=DE

Certificate chain
Subject
Country (C)
  • DE
State (ST)
  • Schleswig-Holstein
Locality (L)
  • Geesthacht
Organization (O)
  • Helmholtz-Zentrum Geesthacht GmbH
Common Name (CN)
  • iron2.hzg.de
Alternative Names
  • iron2.hzg.de
Issuer
Country (C)
  • DE
State (ST)
  • Schleswig-Holstein
Locality (L)
  • Geesthacht
Organization (O)
  • Helmholtz-Zentrum Geesthacht GmbH
Common Name (CN)
  • HZG CA
Email
  • ca@hzg.de
validity period
Not valid before
2014-09-17
Not valid after
2019-07-09
This certifcate has been verified for the following usages:
  • Digital Signature
  • Non Repudiation
  • Key Encipherment
  • TLS Web Client Authentication
  • TLS Web Server Authentication
Fingerprints
SHA256
A3:D9:74:02:8A:59:75:F8:1D:58:15:50:79:D3:4E:60:7D:9B:A2:D1:84:F7:80:34:C3:C4:4E:93:C8:27:E6:B0
SHA1
B0:A8:48:FD:2E:38:3C:9F:41:AD:A6:14:8B:07:E2:E7:03:2F:E1:47
X509v3 extensions
certificatePolicies
  • Policy: 1.3.6.1.4.1.22177.300.1.1.4.3.2
  • Policy: 1.3.6.1.4.1.22177.300.2.1.4.3.1
  • Policy: 1.3.6.1.4.1.22177.300.1.1.4
  • Policy: 1.3.6.1.4.1.22177.300.30
subjectKeyIdentifier
  • 30:70:7C:51:C1:67:C0:1F:27:F1:A9:48:80:93:C5:F4:96:DA:CB:9D
authorityKeyIdentifier
  • keyid:3B:DE:F7:A6:48:CD:37:81:87:3A:D0:9D:28:2D:58:AC:50:16:1B:63
crlDistributionPoints
  • Full Name:
  • URI:http://cdp1.pca.dfn.de/hzg-ca/pub/crl/cacrl.crl
  • Full Name:
  • URI:http://cdp2.pca.dfn.de/hzg-ca/pub/crl/cacrl.crl
authorityInfoAccess
  • OCSP - URI:http://ocsp.pca.dfn.de/OCSP-Server/OCSP
  • CA Issuers - URI:http://cdp1.pca.dfn.de/hzg-ca/pub/cacert/cacert.crt
  • CA Issuers - URI:http://cdp2.pca.dfn.de/hzg-ca/pub/cacert/cacert.crt
First seen at:

CN=iron1.hzg.de,O=Helmholtz-Zentrum Geesthacht GmbH,L=Geesthacht,ST=Schleswig-Holstein,C=DE

Certificate chain
Subject
Country (C)
  • DE
State (ST)
  • Schleswig-Holstein
Locality (L)
  • Geesthacht
Organization (O)
  • Helmholtz-Zentrum Geesthacht GmbH
Common Name (CN)
  • iron1.hzg.de
Alternative Names
  • iron1.hzg.de
Issuer
Country (C)
  • DE
State (ST)
  • Schleswig-Holstein
Locality (L)
  • Geesthacht
Organization (O)
  • Helmholtz-Zentrum Geesthacht GmbH
Common Name (CN)
  • HZG CA
Email
  • ca@hzg.de
validity period
Not valid before
2014-09-16
Not valid after
2019-07-09
This certifcate has been verified for the following usages:
  • Digital Signature
  • Non Repudiation
  • Key Encipherment
  • TLS Web Client Authentication
  • TLS Web Server Authentication
Fingerprints
SHA256
89:98:06:45:D0:F0:00:20:6E:3F:B1:67:61:FD:EA:F2:03:7C:75:F6:93:AF:93:F1:08:DA:96:52:19:C7:62:3C
SHA1
FC:E7:3D:C4:B7:C9:3A:67:06:92:03:A1:E0:AA:0F:F4:EE:D2:B0:0A
X509v3 extensions
certificatePolicies
  • Policy: 1.3.6.1.4.1.22177.300.1.1.4.3.2
  • Policy: 1.3.6.1.4.1.22177.300.2.1.4.3.1
  • Policy: 1.3.6.1.4.1.22177.300.1.1.4
  • Policy: 1.3.6.1.4.1.22177.300.30
subjectKeyIdentifier
  • 62:E0:2D:64:B2:69:F5:DA:6B:70:D1:B6:73:0C:24:3B:22:83:49:4E
authorityKeyIdentifier
  • keyid:3B:DE:F7:A6:48:CD:37:81:87:3A:D0:9D:28:2D:58:AC:50:16:1B:63
crlDistributionPoints
  • Full Name:
  • URI:http://cdp1.pca.dfn.de/hzg-ca/pub/crl/cacrl.crl
  • Full Name:
  • URI:http://cdp2.pca.dfn.de/hzg-ca/pub/crl/cacrl.crl
authorityInfoAccess
  • OCSP - URI:http://ocsp.pca.dfn.de/OCSP-Server/OCSP
  • CA Issuers - URI:http://cdp1.pca.dfn.de/hzg-ca/pub/cacert/cacert.crt
  • CA Issuers - URI:http://cdp2.pca.dfn.de/hzg-ca/pub/cacert/cacert.crt