SSL check results of student.kit.edu

NEW You can also bulk check multiple servers.

Discover if the mail servers for student.kit.edu can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Wed, 08 Jul 2020 08:10:43 +0000

We can not guarantee a secure connection to the mailservers of student.kit.edu!

Please contact the operator of student.kit.edu and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/student.kit.edu

Servers

Incoming Mails

These servers are responsible for incoming mails to @student.kit.edu addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
scc-spamtrap-no-smtp-here.scc.kit.edu
2a00:1398:9:f710::9000:2
Results incomplete
5 not checked
DANE
missing
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
1 s
scc-spamtrap-no-smtp-here.scc.kit.edu
129.13.174.160
Results incomplete
5 not checked
DANE
missing
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
1 s
scc-mailin-cn-01.scc.kit.edu
2a00:1398:9:f711::8d34:d7d2
Results incomplete
10
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
scc-mailin-cn-01.scc.kit.edu
141.52.226.150
Results incomplete
10
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
scc-mailin-cs-01.scc.kit.edu
2a00:1398:9:f710::810d:ae8c
Results incomplete
10
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
scc-mailin-cs-01.scc.kit.edu
129.13.174.140
Results incomplete
10
supported
not checked
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
scc-spamtrap-always-defer.scc.kit.edu
2a00:1398:9:f710::9000:3
100
supported
scc-spamtrap-always-defer.scc.kit.edu
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
2 s
scc-spamtrap-always-defer.scc.kit.edu
129.13.174.161
100
supported
scc-spamtrap-always-defer.scc.kit.edu
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • TLSv1.1
  • TLSv1.0
  • SSLv3
3 s

Outgoing Mails

We have not received any emails from a @student.kit.edu address so far. Test mail delivery

Certificates

First seen at:

CN=scc-spamtrap-always-defer.scc.kit.edu,O=Karlsruhe Institute of Technology,L=Karlsruhe,ST=Baden-Wuerttemberg,C=DE

Certificate chain
Subject
Country (C)
  • DE
State (ST)
  • Baden-Wuerttemberg
Locality (L)
  • Karlsruhe
Organization (O)
  • Karlsruhe Institute of Technology
Common Name (CN)
  • scc-spamtrap-always-defer.scc.kit.edu
Alternative Names
  • scc-spamtrap-always-defer.scc.kit.edu
Issuer
Country (C)
  • DE
State (ST)
  • Baden-Wuerttemberg
Locality (L)
  • Karlsruhe
Organization (O)
  • Karlsruhe Institute of Technology
Common Name (CN)
  • KIT-CA
validity period
Not valid before
2017-08-19
Not valid after
2020-11-15
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Client Authentication
  • TLS Web Server Authentication
Fingerprints
SHA256
C1:07:F9:08:65:75:3E:DC:17:D5:F1:61:3F:58:03:61:A6:6B:CD:09:75:A6:40:5C:7F:64:6A:07:07:44:99:E1
SHA1
8C:AC:3F:F8:F6:E5:E0:FD:85:85:32:C4:5B:AB:D6:EC:80:EC:0A:60
X509v3 extensions
subjectKeyIdentifier
  • 27:88:E2:08:C2:C9:51:DC:79:24:10:24:FE:53:29:2B:F3:FB:2E:9D
authorityKeyIdentifier
  • keyid:04:1A:BF:1C:93:91:3D:D3:D9:3D:B0:DE:13:23:E5:9A:70:F4:2E:08
crlDistributionPoints
  • Full Name:
  • URI:http://cdp1.pca.dfn.de/kit-ca-g2/pub/crl/cacrl.crl
  • Full Name:
  • URI:http://cdp2.pca.dfn.de/kit-ca-g2/pub/crl/cacrl.crl
authorityInfoAccess
  • OCSP - URI:http://ocsp.pca.dfn.de/OCSP-Server/OCSP
  • CA Issuers - URI:http://cdp1.pca.dfn.de/kit-ca-g2/pub/cacert/cacert.crt
  • CA Issuers - URI:http://cdp2.pca.dfn.de/kit-ca-g2/pub/cacert/cacert.crt
certificatePolicies
  • Policy: 1.3.6.1.4.1.22177.300.1.1.4.3.5
  • Policy: 1.3.6.1.4.1.22177.300.2.1.4.3.1
  • Policy: 1.3.6.1.4.1.22177.300.1.1.4
  • Policy: 1.3.6.1.4.1.22177.300.30
  • Policy: 2.23.140.1.2.2