cds-snc / tracker

Check whether a Government of Canada domain is adhering to best security practices.
Other
12 stars 9 forks source link

ITPIN shouldn't be compliant if crypto and cert don't have data i.e N/A #61

Open sayaHub opened 5 years ago

sayaHub commented 5 years ago

As shown in the picture below

na-bug

tallardyce commented 5 years ago

Hey, adding to this -- I don't think the ITPIN column is necessarily the concern but rather the N/A. another example:

image

This domain gets an A+ on SSL Labs and Hardenize passes all tests, including the certificates -- it reports a good chain.

I did notice that the domain uses a number of app-sec headers, which may be interrupting sslyze? AFAIK sslyze only checks the HTTPS endpoint, which is where the headers are set.

X-Content-Type-Options: nosniff, NOSNIFF X-Frame-Options: SAMEORIGIN, SAMEORIGIN X-Permitted-Cross-Domain-Policies: master-only X-Powered-By: PHP/5.6.18-1+deb.sury.org~trusty+1 X-UA-Compatible: IE=edge X-XSS-Protection: 1; mode=block