isvsecwatch / httpstracker

Our main issue tracker for ISV security issues, such as the SSL/TLS configuration of their online stores.
3 stars 0 forks source link

runscope.com - api testing/uptime service #92

Closed isvsecwatch-report closed 8 years ago

isvsecwatch-report commented 8 years ago

SSL Server Test Results https://www.ssllabs.com/ssltest/analyze.html?d=runscope.com (B)

isvsecwatch-report commented 8 years ago

Cipherscan Results

Target: runscope.com:443

prio  ciphersuite                  protocols              pfs                 curves
1     ECDHE-RSA-AES256-GCM-SHA384  TLSv1.2                ECDH,P-256,256bits  prime256v1
2     ECDHE-RSA-AES128-GCM-SHA256  TLSv1.2                ECDH,P-256,256bits  prime256v1
3     ECDHE-RSA-AES256-SHA384      TLSv1.2                ECDH,P-256,256bits  prime256v1
4     ECDHE-RSA-AES128-SHA256      TLSv1.2                ECDH,P-256,256bits  prime256v1
5     ECDHE-RSA-RC4-SHA            TLSv1,TLSv1.1,TLSv1.2  ECDH,P-256,256bits  prime256v1
6     ECDHE-RSA-AES256-SHA         TLSv1,TLSv1.1,TLSv1.2  ECDH,P-256,256bits  prime256v1
7     ECDHE-RSA-AES128-SHA         TLSv1,TLSv1.1,TLSv1.2  ECDH,P-256,256bits  prime256v1
8     DHE-RSA-AES256-GCM-SHA384    TLSv1.2                DH,2048bits         None
9     DHE-RSA-AES256-SHA256        TLSv1.2                DH,2048bits         None
10    DHE-RSA-AES256-SHA           TLSv1,TLSv1.1,TLSv1.2  DH,2048bits         None
11    DHE-RSA-CAMELLIA256-SHA      TLSv1,TLSv1.1,TLSv1.2  DH,2048bits         None
12    DHE-RSA-AES128-GCM-SHA256    TLSv1.2                DH,2048bits         None
13    DHE-RSA-AES128-SHA256        TLSv1.2                DH,2048bits         None
14    DHE-RSA-AES128-SHA           TLSv1,TLSv1.1,TLSv1.2  DH,2048bits         None
15    DHE-RSA-SEED-SHA             TLSv1,TLSv1.1,TLSv1.2  DH,2048bits         None
16    DHE-RSA-CAMELLIA128-SHA      TLSv1,TLSv1.1,TLSv1.2  DH,2048bits         None
17    RC4-SHA                      TLSv1,TLSv1.1,TLSv1.2  None                None

Certificate: trusted, 2048 bits, sha256WithRSAEncryption signature
TLS ticket lifetime hint: 600
OCSP stapling: not supported
Cipher ordering: server
Curves ordering: server - fallback: no
Server supports secure renegotiation
Server supported compression methods: NONE
TLS Tolerance: yes
isvsecwatch-report commented 8 years ago

Poked via Twitter; https://twitter.com/isvsecwatch/status/693787502918963200

isvsecwatch-report commented 8 years ago

Fixed. Closing ticket.