SSL check results of medis.cz

NEW You can also bulk check multiple servers.

Discover if the mail servers for medis.cz can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Tue, 02 Sep 2025 11:23:13 +0000

We can not guarantee a secure connection to the mailservers of medis.cz!

Please contact the operator of medis.cz and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/medis.cz

Servers

Incoming Mails

These servers are responsible for incoming mails to @medis.cz addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail.medis.cz
93.99.0.34
Results incomplete
0
unsupported
not checked
DANE
missing
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
6 s
mail3.medis.cz
91.245.14.146
20
supported
EX-B
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
backupmail.medis.cz
185.205.137.21
Results incomplete
30
supported
*.ebrana.cz
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s

Outgoing Mails

We have not received any emails from a @medis.cz address so far. Test mail delivery

Certificates

First seen at:

CN=*.ebrana.cz

Certificate chain
Subject
Common Name (CN)
  • *.ebrana.cz
Alternative Names
  • *.ebrana.cz
  • ebrana.cz
Issuer
Country (C)
  • US
Organization (O)
  • DigiCert Inc
Organizational Unit (OU)
  • www.digicert.com
Common Name (CN)
  • RapidSSL TLS RSA CA G1
validity period
Not valid before
2025-07-24
Not valid after
2026-08-24
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
  • TLS Web Client Authentication
Fingerprints
SHA256
81:D7:05:E4:2E:5C:C7:72:26:A5:14:79:5D:1A:49:51:3D:03:83:54:E8:EA:00:15:15:A0:37:4B:18:AA:4D:74
SHA1
AA:D6:9E:71:29:5B:E7:7B:4A:15:65:E5:F2:AE:A0:DB:86:65:2A:E7
X509v3 extensions
authorityKeyIdentifier
  • keyid:0C:DB:6C:82:49:0F:4A:67:0A:B8:14:EE:7A:C4:48:52:88:EB:56:38
subjectKeyIdentifier
  • E6:9D:1D:50:CF:61:DE:95:10:E7:86:52:77:2E:6E:B8:80:91:A4:01
certificatePolicies
  • Policy: 2.23.140.1.2.1
  • CPS: http://www.digicert.com/CPS
crlDistributionPoints
  • Full Name:
  • URI:http://cdp.rapidssl.com/RapidSSLTLSRSACAG1.crl
authorityInfoAccess
  • OCSP - URI:http://status.rapidssl.com
  • CA Issuers - URI:http://cacerts.rapidssl.com/RapidSSLTLSRSACAG1.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9:
  • 82:C9:33:5A:65:E1:D0:B3:01:73:17:C0:C8:C5:69:77
  • Timestamp : Jul 24 10:30:57.582 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:E8:46:4D:A9:13:8E:EF:7F:3B:0D:F4:
  • 37:B9:BD:27:A5:BF:CD:28:8C:6C:EB:CB:58:B7:1B:6F:
  • A8:30:01:B6:41:02:21:00:CD:0F:8C:D6:50:C7:03:CE:
  • 60:A6:44:8D:00:70:5A:42:83:6B:87:EB:79:3C:53:1C:
  • BE:5C:95:67:F5:34:1B:39
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:
  • C7:C2:21:5A:22:BF:7F:D5:B5:AD:76:9A:D9:0E:52:CD
  • Timestamp : Jul 24 10:30:57.506 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:24:9B:99:3E:A6:65:A4:52:F0:08:C3:1D:
  • B3:A6:E8:FD:32:52:C2:D4:5E:87:90:62:D4:11:0B:51:
  • C1:A1:27:E4:02:20:52:D1:F6:4B:5A:1C:89:E0:86:0B:
  • 2F:0F:12:3D:A0:12:0E:B0:22:3B:E6:05:A6:C3:B0:2A:
  • A1:AE:D5:F2:74:19
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:
  • 01:C7:D3:5F:38:02:01:3F:72:67:7D:55:37:2E:19:D8
  • Timestamp : Jul 24 10:30:57.524 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:A5:FF:10:9B:37:F2:30:97:3B:49:2D:
  • 7A:28:B1:93:A8:8D:6C:6F:83:83:B7:3F:01:D6:4F:FC:
  • B7:EE:51:4A:3D:02:20:10:CF:85:9A:86:EF:DE:7C:7E:
  • 82:60:00:92:BA:57:C4:A9:F1:2D:AB:4E:F3:39:6D:5D:
  • 1D:4A:6C:32:35:7A:94
First seen at:

CN=EX-B

Certificate chain
  • EX-B
    • remaining
    • 2048 bit
    • sha256WithRSAEncryption
    • Hostname Mismatch

      • fw.medis.cz (Certificate is self-signed.)
        • remaining
        • 2048 bit
        • sha256WithRSAEncryption
        • Unknown Authority

Subject
Common Name (CN)
  • EX-B
Issuer
Country (C)
  • CZ
State (ST)
  • CZ
Locality (L)
  • Hradec Kralove
Organization (O)
  • MIS Holding
Organizational Unit (OU)
  • IT
Common Name (CN)
  • fw.medis.cz
Email
  • pavel.skala@medis.cz
validity period
Not valid before
2022-11-24
Not valid after
2027-11-24
This certifcate has been verified for the following usages:
  • Digital Signature
  • Non Repudiation
  • Key Encipherment
Fingerprints
SHA256
70:65:A3:B0:72:C1:99:CF:64:4B:C7:67:BA:8A:CA:B6:17:D0:3B:19:96:B2:5C:B7:BB:21:39:A2:86:88:55:90
SHA1
55:8B:56:BE:4B:CE:5E:11:09:59:84:EB:90:3D:AF:2D:B5:EA:97:B2