SSL Analysis(TLSSLed)
SSL Analysis(TLSSLed)
SSL Analysis Description:
TLSSLed is a Linux shell script whose purpose is to evaluate the security of a target SSL/TLS (HTTPS) web server implementation. It is based on sslscan, a thorough SSL/TLS scanner that is based on the openssl library, and on the “openssl s_client” command line tool. The current tests include checking if the target supports the SSLv2 protocol, the NULL cipher, weak ciphers based on their key length (40 or 56 bits), the availability of strong ciphers (like AES), if the digital certificate is MD5 signed, and the current SSL/TLS renegotiation capabilities.
root@kali:~# tlssled
------------------------------------------------------
TLSSLed - (1.3) based on sslscan and openssl
by Raul Siles (www.taddong.com)
------------------------------------------------------
openssl version: OpenSSL 1.0.1e 11 Feb 2013
sslscan version 1.8.2
------------------------------------------------------
Date: 20140520-110731
------------------------------------------------------
[!] Usage: /usr/bin/tlssled <hostname or IP_address> <port>
TLSSLed Usage Example:
Server Key and Certificate #1
Subject: sscoetjalgaon.ac.in
Fingerprint SHA256: 911b1eea8717408d0dda055d5427d9f3e5daf54f821e745bb112dc42e4f8e096
Pin SHA256: rG8wxiFu6PltatcwbN2aWarm7tFHBmSlllzrI4FIfFw=
Common names: sscoetjalgaon.ac.in
Alternative names: sscoetjalgaon.ac.in www.sscoetjalgaon.ac.in
Serial Number: 0358165835f1a0adb990dbea42a81a1781cd
Valid from
Tue, 20 Apr 2021 04:15:30 UTC
Valid until
Mon, 19 Jul 2021 04:15:30 UTC (expires in 15 days, 19 hours)
Key: RSA 4096 bits (e 65537)
Weak key (Debian): No
Issuer: R3
AIA: http://r3.i.lencr.org/
Signature algorithm: SHA256withRSA
Extended Validation: No
Certificate Transparency: Yes (certificate)
OCSP Must Staple: No
Revocation information
OCSP
OCSP: http://r3.o.lencr.org
Revocation status
Good (not revoked)
DNS CAA
No (more info)
Trusted
Yes
Mozilla Apple Android Java Windows