SSL check results of uohs.gov.cz

NEW You can also bulk check multiple servers.

Discover if the mail servers for uohs.gov.cz can be reached through a secure connection.

To establish a secure connection a mail server has to offer STARTTLS (SSL), a trustworthy SSL certificate, support for the Diffie-Hellman-Algorithm to guarantee Perfect Forward Secrecy and must not be vulnerable against the Heartbleed attack. Futhermore we recommend using end-to-end encryption with GnuPG.

Summary

Report created Sat, 26 Sep 2026 00:30:12 +0000

We can not guarantee a secure connection to the mailservers of uohs.gov.cz!

Please contact the operator of uohs.gov.cz and ask him or her to solve this problem. This result stays accessible under the following address:

/mailservers/uohs.gov.cz

Servers

Incoming Mails

These servers are responsible for incoming mails to @uohs.gov.cz addresses.

Hostname / IP address Priority STARTTLS Certificates Protocol
mail2.uohs.gov.cz
2001:718:800:7::11
Results incomplete
100 not checked
DANE
errors
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
11 s
mail2.uohs.gov.cz
195.113.171.11
100
supported
mail2.uohs.gov.cz
DANE
valid
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
mail3.uohs.gov.cz
90.183.33.227
Results incomplete
150
unsupported
not checked
DANE
errors
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
11 s
mail4.uohs.gov.cz
2001:718:800:7::12
Results incomplete
200 not checked
DANE
errors
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
11 s
mail4.uohs.gov.cz
195.113.171.12
Results incomplete
200 not checked
DANE
errors
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
11 s
mail5.uohs.gov.cz
90.183.33.228
Results incomplete
250 not checked
DANE
errors
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
11 s
utm-brno.uohs.gov.cz
195.113.171.3
300
supported
mail2.uohs.gov.cz
DANE
missing
PFS
supported
Heartbleed
not vulnerable
Weak ciphers
not found
  • TLSv1.2
  • SSLv3
1 s
utm-brno-o2.uohs.gov.cz
90.183.33.226
Results incomplete
350
unsupported
not checked
DANE
missing
PFS
not checked
Heartbleed
not checked
Weak ciphers
not checked
21 s

Outgoing Mails

We have not received any emails from a @uohs.gov.cz address so far. Test mail delivery

Certificates

First seen at:

CN=mail2.uohs.gov.cz

Certificate chain
Subject
Common Name (CN)
  • mail2.uohs.gov.cz
Alternative Names
  • mail2.uohs.gov.cz
  • mail3.uohs.gov.cz
  • mail4.uohs.gov.cz
  • mail5.uohs.gov.cz
Issuer
Country (C)
  • US
Organization (O)
  • DigiCert Inc
Organizational Unit (OU)
  • www.digicert.com
Common Name (CN)
  • GeoTrust TLS RSA CA G1
validity period
Not valid before
2026-09-24
Not valid after
2027-03-14
This certifcate has been verified for the following usages:
  • Digital Signature
  • Key Encipherment
  • TLS Web Server Authentication
Fingerprints
SHA256
15:E9:65:3C:9E:8A:B0:57:6C:99:E5:6B:CA:4C:6A:3E:E0:EF:34:74:DF:C2:A7:4D:34:6F:4D:0C:43:77:DF:13
SHA1
6F:6D:8B:AA:97:4C:8C:22:44:A8:13:C7:D4:00:6A:EA:02:9D:B0:97
X509v3 extensions
authorityKeyIdentifier
  • keyid:94:4F:D4:5D:8B:E4:A4:E2:A6:80:FE:FD:D8:F9:00:EF:A3:BE:02:57
subjectKeyIdentifier
  • C6:44:89:EC:DC:C3:B5:59:FD:88:9C:13:72:CD:A6:58:2D:0C:5F:CB
certificatePolicies
  • Policy: 2.23.140.1.2.1
  • CPS: http://www.digicert.com/CPS
crlDistributionPoints
  • Full Name:
  • URI:http://cdp.geotrust.com/GeoTrustTLSRSACAG1.crl
authorityInfoAccess
  • OCSP - URI:http://status.geotrust.com
  • CA Issuers - URI:http://cacerts.geotrust.com/GeoTrustTLSRSACAG1.crt
ct_precert_scts
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 4C:63:DC:98:E5:9C:1D:AB:88:F6:1E:8A:3D:DE:AE:8F:
  • AB:44:A3:37:7B:5F:9B:94:C3:FB:A1:9C:FC:C1:BE:26
  • Timestamp : Sep 24 07:26:56.495 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:8F:7E:B9:C2:DC:A4:B1:53:19:96:95:
  • 47:CA:72:4E:EA:7F:F5:FC:E6:A2:14:D3:7E:1F:E3:89:
  • A2:2F:6E:3B:04:02:20:6E:19:3D:FE:78:3D:97:BA:4B:
  • 15:72:35:B0:1F:95:C0:61:13:38:C6:C8:AA:F3:6D:EE:
  • D7:A6:6E:96:11:B8:52
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D6:D5:8D:A9:D0:17:53:F3:6A:4A:A0:C7:57:49:02:AF:
  • EB:C7:DC:2C:D3:8C:D9:F7:64:C8:0C:89:19:1E:9F:02
  • Timestamp : Sep 24 07:26:56.518 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:E5:52:AD:F8:F5:BB:2D:4E:BF:C8:0B:
  • 05:1B:41:36:07:06:5A:64:61:EB:0B:44:05:F4:41:01:
  • D7:B8:65:43:70:02:21:00:98:E9:D6:06:90:F5:C0:95:
  • A5:22:58:5B:48:91:92:09:23:48:86:A0:3E:51:CF:4F:
  • AF:A2:63:65:3F:79:8B:3D
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 44:C2:BD:0C:E9:14:0E:64:A5:C9:4A:01:93:0A:5A:A1:
  • BB:35:97:0E:00:EE:11:16:89:68:2A:1C:44:D7:B5:66
  • Timestamp : Sep 24 07:26:56.567 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:56:93:E3:27:99:97:FE:A5:54:82:52:95:
  • FC:0B:62:7F:0D:1C:5D:FC:51:14:DC:10:89:94:BC:6A:
  • 92:EA:7E:17:02:20:64:47:CB:0F:8E:CF:13:71:87:E9:
  • B5:90:F6:AF:7D:E2:BE:2A:DF:38:7A:E6:7D:EB:AF:4D:
  • D0:AB:CA:F3:4C:3B

DANE

DNS-based Authentication of Named Entities (DANE) is a protocol to allow X.509 certificates to be bound to DNS using TLSA records and DNSSEC.

Name Options DNSSEC Matches
_25._tcp.mail2.uohs.gov.cz
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-512 Hash
valid
valid
_25._tcp.mail3.uohs.gov.cz
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-512 Hash
valid
—
_25._tcp.mail4.uohs.gov.cz
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-512 Hash
valid
—
_25._tcp.mail5.uohs.gov.cz
  • DANE-EE: Domain Issued Certificate
  • Use subject public key
  • SHA-512 Hash
valid
—