The post 驗證SSL憑證是否有正確安裝?是否有漏洞? first appeared on 捕夢網 Blog.
]]>這幾年來,幾家科技大廠包含Google等在內,致力於推動為網站安裝SSL,作為資訊安全的第一步。
SSL憑證是否有正確安裝?是否有漏洞?當然如果您的憑證是由專業的工程師或主機商協助安裝,那基本是安全無虞的
捕夢網接下來要介紹幾個網站,只需輸入網站,即可幫您驗證SSL憑證是否有正確安裝?是否有漏洞?
SSL Labs by Qualys is one of the most popular SSL testing tools to check all latest vulnerability & misconfiguration. Ex:
SSL Checker let you quickly identify if a chain certificate is implemented correctly. Great idea to proactively test after SSL cert implementation to ensure chain certificate is not broken.
TLS Test – quickly find out which TLS protocol version is supported. As you can see, the tool is capable of testing the latest TLS 1.3 as well.
TLS Test是用來檢測TLS protocol是否太舊或不安全的用的
TLS Scanner – detailed testing to find out the common misconfiguration and vulnerabilities.
TLS Scanner則可以詳細檢測常見的設定錯誤或是漏洞是否存在
Web Server Tester by Wormly check for more than 65 metrics and give you a status of each including overall scores. The report contains certificate overview (CN, Expiry details, Trust chain), Encryption Ciphers details, Public key size, Secure Renegotiation, Protocols like SSLv3/v2, TLSv1/1.2.
DigiCert SSL Installation Diagnostics Tool is another fantastic tool to provide you DNS resolves IP address, Certificate details including Issuer, Serial number, key length, signature algorithm, SSL cipher supported by the server and expiry details.
Useful tool by High-Tech Bridge to perform scan against your https URL and provide in-depth technical information with an option to download the report in PDF format.
Observatory by Mozilla checks various metrics like TLS cipher details, certificate details, OWASP recommended secure headers, and more.
CryptCheck quickly scans the given site and show score for protocol, key exchange, and cipher. You get detailed cipher suites details so can be handy if you are troubleshooting or validating ciphers.
資料參考來源: https://geekflare.com/ssl-test-certificate/#SSL-Server-Security-Test
The post 驗證SSL憑證是否有正確安裝?是否有漏洞? first appeared on 捕夢網 Blog.
]]>